[
  {
    "node_id": "3d-printed-medical-devices-2026",
    "title": "3D-Printed / Additively Manufactured Medical Devices - Regulatory & Quality Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Additively manufactured (3D-printed) medical devices require specific regulatory controls covering design validation, material qualification, process validation, post-processing, sterility assurance, and patient-specific customization. Regulators treat them as custom or patient-specific devices with heightened requirements for traceability, reproducibility, and post-market surveillance. Point-of-care manufacturing adds additional oversight layers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-medical-qms",
      "iso-14971-medical-risk"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "3gpp-5g-nr-release-17-specifications",
    "title": "3GPP 5G NR Release 17 Technical Specifications - Sidelink, URLLC Enhancements, RedCap and NTN Integration",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "3GPP Release 17 mandates a set of technical specifications for 5G network equipment manufacturers and operators, introducing key enhancements such as direct device-to-device Sidelink (TS 38.331), improved Ultra-Reliable Low-Latency Communication (URLLC), support for Reduced Capability (RedCap) IoT devices (TS 38.213), and integration with Non-Terrestrial Networks (NTNs). Compliance requires implementing these features according to the detailed protocols defined across the 3GPP TS 23, 36, and 38 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itu-radio-regulations-2020-edition",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "3gpp-ims-ip-multimedia-subsystem-release-16",
    "title": "3GPP IMS IP Multimedia Subsystem Release 16 - SIP Signalling, P-CSCF Security and Emergency Call Procedures",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard mandates that telecommunications operators implementing IP Multimedia Subsystem (IMS) Release 16 must establish secure signalling interfaces using IPsec or TLS between the User Equipment (UE) and the P-CSCF, and between network nodes, to ensure confidentiality and integrity for all SIP communications, as specified in 3GPP TS 33.203.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-131a-rev-2-crypto-transitions",
      "nist-sp-800-57-key-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "aa1000ap-accountability",
    "title": "AA1000AP (AccountAbility)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with the AA1000AP framework is predicated upon a systematic and auditable application of its foundational principles, reinforced by assurance requirements aligned with both the AA1000 Assurance Standard and Directive (EU) 2022/2464. The Principle of Inclusivity, per Section 2.1, is implemented through an active stakeholder inclusivity framework, mandating a comprehensive stakeholder mapping review at least every 12 months. Adherence to the Principle of Materiality from Section 2.2 requires a formal materiality assessment with an identical 12-month frequency, executed under established ESG board oversight and consistent with double materiality concepts. An active responsiveness mechanism, governed by Section 2.3, ensures that stakeholder communications are addressed within a maximum response time of 30 days, supported by active grievance remediation tracking. Finally, the Principle of Impact, as articulated in Section 2.4, is substantiated through defined impact measurement metrics, including verifiable SDG impact alignment. The integrity of this entire process is confirmed by the requirement for independent assurance, enabled ESG data fidelity audits, and a commitment to an annual public ESG disclosure, ensuring robust, transparent, and defensible reporting on accountability performance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "gri-1-foundation",
      "iso-26000-social-resp-mgt",
      "un-guiding-principles-business-hr",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "aarhus-convention-1998-environmental-access",
    "title": "Aarhus Convention 1998 - Access to Environmental Information, Public Participation, and Access to Justice",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Aarhus Convention (UN ECE, 47 Parties) creates binding obligations on public authorities to provide environmental information within 1 month of request (Article 4), enable public participation in environmental decisions affecting the public (Article 6), and guarantee access to judicial review of environmental decisions (Article 9); businesses must comply with mandatory environmental disclosure obligations under EU implementing instruments (Directive 2003/4/EC, E-PRTR Regulation 166/2006), and are directly affected as either regulated parties subject to public scrutiny or as members of the public seeking access to environmental data held by authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csrd-2022-2464",
      "eu-corporate-sustainability-due-diligence-2024",
      "cites-convention-1973-endangered-species-trade",
      "un-paris-agreement-ndc-implementation-guidelines"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "aba-model-rules-conduct",
    "title": "ABA Model Rules (Conduct)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with fundamental ABA Model Rules of Professional Conduct is operationalized through a stringent set of configurable controls. The duty of competence, as articulated in ABA Model Rule 1.1, Comment 8, mandates continuous technical competence validation to understand technology's benefits and risks. Protecting client confidentiality pursuant to ABA Model Rule 1.6(c) is achieved by enabling unauthorized disclosure prevention and requiring client data encryption, a standard reinforced by ABA Formal Opinion 477R's guidance on securing protected information. Supervisory responsibilities under ABA Model Rule 5.3 are extended to technology, necessitating a comprehensive vendor risk assessment and ensuring supervisory review of automated output. Adhering to the communications duty in ABA Model Rule 1.4, the platform requires practitioners to obtain informed consent for AI tool usage. System-wide security is bolstered through mandatory multi-factor authentication and enforcing access control based on least privilege principles. In response to cybersecurity incidents, protocols derived from ABA Formal Opinion 483 are enforced, which requires an incident response plan and sets a maximum breach notification delay of 24 hours for prompt client disclosure. The system will also enforce conflict of interest checks automatically and manage data lifecycles according to a five-year client file retention policy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sra-code-conduct-uk",
      "bar-standards-board-uk",
      "cfa-ethics-standards",
      "aicpa-code-ethics",
      "pmi-code-ethics",
      "ifac-ethics-accountants"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "accounting-ias-38",
    "title": "AI Model Valuation (IAS 38)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "IAS 38 Intangible Assets, issued by the IASB, governs the recognition, measurement, and disclosure of intangible assets including internally developed AI models, training datasets, and software. An intangible asset must meet strict recognition criteria: identifiability, control, and probable future economic benefit. Development-phase AI expenditure may be capitalized only after technical feasibility is established under all six IAS 38.57 criteria, while research-phase costs must be expensed immediately. Failure to correctly distinguish research from development phases, or to apply impairment testing under IAS 36, results in materially misstated financial statements and potential regulatory action by securities authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "accounting-ifr-13"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "accounting-ifr-13",
    "title": "Digital Asset Fair Value (IFRS 13)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "IFRS 13 Fair Value Measurement establishes a single framework for measuring fair value across all IFRS standards that require or permit fair value measurement, including digital assets, AI-tokenized instruments, and crypto holdings. Fair value is defined as the exit price in an orderly transaction between market participants at the measurement date. Entities must classify inputs into a three-level hierarchy (Level 1: quoted prices in active markets; Level 2: observable inputs; Level 3: unobservable inputs) and maximize use of observable inputs. Digital and AI-linked assets with limited trading history frequently fall into Level 3, requiring robust valuation models and extensive disclosures; inadequate classification or disclosure triggers audit qualifications and securities regulator scrutiny.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "accounting-ias-38"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "acec-ethics-eng",
    "title": "Engineers Ethics (ACEC)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The American Council of Engineering Companies (ACEC) Code of Ethics establishes the binding professional obligations for licensed engineers and consulting firms. Engineers must hold paramount the safety, health, and welfare of the public above all client or employer interests. Core obligations include qualifications-based fee competition (Brooks Act compliance), professional seal authorization, conflict-of-interest disclosure, errors and omissions insurance, and continuing professional education. Violations expose firms to license revocation, civil liability, and federal debarment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ad-pdp-law-2021",
    "title": "Andorra Qualified Law No. 29/2021 on Personal Data Protection - AAPD",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Andorra's Qualified Law No. 29/2021 on Personal Data Protection (Llei qualificada de protecció de dades personals), adopted by the General Council (Consell General) of Andorra and entered into force in 2021, is Andorra's comprehensive personal data protection legislation establishing a fully GDPR-aligned rights-based framework for the protection of personal data. Andorra is a microstate co-principality between France and Spain that maintains close economic and institutional ties with the European Union; although not an EU member state, Andorra participates in the EU Customs Union and has progressively aligned its legal framework with EU standards. Andorra's Qualified Law No. 29/2021 is comprehensively aligned with the EU General Data Protection Regulation, and Andorra has been recognised by the European Commission as providing adequate data protection for the purposes of international data transfers from the EU. The supervisory authority is the Andorran Data Protection Agency (Agència Andorrana de Protecció de Dades - AAPD), an independent institution responsible for oversight, enforcement, and guidance on personal data protection standards in Andorra. Key features of Andorra's Qualified Law No. 29/2021 on Personal Data Protection: (1) Scope - applies to personal data processing by any person established in Andorra or processing data of individuals located in Andorra; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right to data portability; and right not to be subject to solely automated decisions; (6) Data Protection Officer - required for public authorities and organisations processing personal data on a large scale or systematically; (7) Breach notification - controllers must notify the AAPD of personal data breaches within 72 hours; high-risk breaches require data subject notification; (8) Data Protection Impact Assessment - required for high-risk processing; (9) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or using AAPD-approved safeguards; and (10) Administrative fines - graduated fines aligned with GDPR fine structures. Andorra's EU adequacy recognition and GDPR-equivalent framework position it as a European microstate fully integrated into the European data protection ecosystem.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ada-employment-title-1",
    "title": "ADA (Employment Title I)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Americans with Disabilities Act Title I (42 U.S.C. §12101-12117), as amended by the ADA Amendments Act of 2008 (ADAAA), is the primary U.S. federal law prohibiting employment discrimination against qualified individuals with disabilities. Covered employers with 15 or more employees must provide reasonable accommodations unless doing so causes undue hardship. Title I restricts all medical inquiries to post-conditional-offer only, mandates initiation of the interactive process upon disclosure of a disabling limitation, and requires accessible employment technology at WCAG 2.1 AA minimum. The EEOC enforces Title I through administrative charges; violations expose employers to back pay, compensatory and punitive damages, and injunctive relief requiring policy and structural changes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eeoc-employment-rule",
      "flsa-compliance-labor",
      "fmla-compliance-leave",
      "erisa-compliance-rep",
      "osha-work-safety-us",
      "modern-slavery-act-rep"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ada-hospitality-access",
    "title": "ADA (Hospitality Accessibility)",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "ADA Title III (42 U.S.C. §12181-12189) requires all places of public accommodation - including hotels, motels, restaurants, bars, and food service establishments - to provide equal access to individuals with disabilities. New construction and alterations commenced after January 26, 1992 must fully comply with the 2010 ADA Standards for Accessible Design. Existing facilities must remove architectural barriers where readily achievable. Hotels must provide a regulated percentage of accessible guest rooms, van-accessible parking at prescribed ratios, accessible routes of 36-inch minimum clear width, pool lifts for pools exceeding 300 linear feet of pool wall, and visual communication features for guests with hearing impairments. DOJ enforces Title III through civil investigations and pattern-or-practice suits; private plaintiffs may sue for injunctive relief and attorney fees. Non-compliant operators face structural modification orders and potential damages in states with enhanced state accessibility laws.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ada-employment-title-1"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "adr-agreement-1957-dangerous-goods-road",
    "title": "ADR Agreement 1957 - European Agreement Concerning the International Carriage of Dangerous Goods by Road",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-25",
    "bluf": "The European Agreement concerning the International Carriage of Dangerous Goods by Road (ADR, 1957 - 54 Contracting Parties as of 2025) creates a uniform regulatory framework for road transport of dangerous goods across signatory states; its Annexes A (classification, packaging, marking, documentation) and B (vehicle requirements, equipment, training) are updated every two years and incorporate nine hazard classes (explosives, flammable gases/liquids, toxic substances, oxidizers, infectious substances, radioactive materials, corrosives, miscellaneous dangerous goods); key obligations include: UN-number labelling and hazard placarding, dangerous goods transport documents (DGDN), driver ADR training certificate (ADR card), vehicle approval certificate (certificate of approval for tank vehicles), emergency information (TREMCARD), and load securing; shippers, packers, consignors, carriers, and recipients each bear specific ADR obligations under Chapter 1.4; non-compliance results in vehicle immobilisation, fines, and criminal liability under national implementing laws.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "rotterdam-convention-pic-chemicals-2004",
      "stockholm-convention-2001-persistent-organic-pollutants",
      "eu-csrd-2022-2464",
      "wto-tbt-agreement-1995-technical-barriers-trade"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ae-aml-cft-law-2018",
    "title": "United Arab Emirates Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organisations (the UAE AML/CFT Law) entered into force on 30 October 2018, replacing Federal Law No. 4 of 2002. Cabinet Decision No. 10 of 2019 on the Implementing Regulation of the AML/CFT Law provides detailed operational requirements. The law aligns with the Financial Action Task Force (FATF) 40 Recommendations and positions the UAE within the FATF's Mutual Evaluation framework. The UAE was placed on the FATF grey list of jurisdictions under increased monitoring in March 2022 following identified strategic AML/CFT deficiencies; following implementation of its action plan the UAE exited the grey list in February 2024. Supervisory structure: the Central Bank of the UAE (CBUAE) supervises licensed financial institutions (banks, insurance companies, exchange houses, finance companies, payment service providers). The Ministry of Economy supervises designated non-financial businesses and professions (DNFBPs) including real estate agents, dealers in precious metals and stones, corporate service providers, and auditors. Free zone financial supervisors (Dubai Financial Services Authority, Financial Services Regulatory Authority of ADGM) supervise entities licensed in DIFC and ADGM respectively. Financial intelligence: the UAE Financial Intelligence Unit (UAE FIU), established under the CBUAE pursuant to Federal Decree-Law No. 25 of 2020, is the national centre for receiving, analysing, and disseminating suspicious transaction reports (STRs) and currency transaction reports. STRs must be filed via the goAML system, the UAE's FATF-standard financial intelligence platform. Customer due diligence (CDD): obligated entities must identify and verify the identity of all customers, identify and verify beneficial owners holding 25% or more of the entity's ownership or voting rights, assess and document the customer's business profile and the source of funds, and conduct ongoing monitoring of the customer relationship. Enhanced due diligence (EDD) is mandatory for: politically exposed persons (PEPs) and their family members and close associates; correspondent banking relationships; customers or transactions involving high-risk jurisdictions identified by FATF or UAE Cabinet decisions; complex or unusually large transactions with no apparent economic purpose. Simplified due diligence is permitted in limited low-risk circumstances prescribed by Cabinet Decision No. 10 of 2019. STR/SAR obligations: obligated entities must file a suspicious transaction report with the UAE FIU without delay whenever they suspect or have reasonable grounds to suspect that funds constitute proceeds of crime or are connected to money laundering, terrorist financing, or financing of illegal organisations. Tipping-off prohibition: Art. 15 prohibits disclosure to the customer or any other person that a STR has been filed or that an AML/CFT investigation is underway. Record retention: all CDD records, transaction records, and STR records must be retained for a minimum of five years from the end of the business relationship or the date of the transaction. Targeted financial sanctions: the UAE implements UN Security Council sanctions and UAE Cabinet Decision No. 83 of 2021 on Terrorist Designation; obligated entities must screen all customers and transactions against UAE, UN, and applicable international sanctions lists in real time. Penalties: CBUAE may impose administrative fines up to AED 1,000,000 per violation for financial institutions; Ministry of Economy may impose similar fines for DNFBP violations. For systemic AML/CFT failures, the CBUAE has imposed penalties exceeding AED 50,000,000 and withdrawn licences. Criminal penalties: conviction for money laundering under Art. 22 carries imprisonment of 1 to 10 years and a fine of AED 300,000 to 10,000,000; property subject to money laundering is subject to mandatory confiscation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "bcbs-principles-operational-resilience",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ae-cbuae-payment-token-services-regulation-2024",
    "title": "UAE Central Bank Payment Token Services Regulation 2024, PTSR - Stablecoin Issuance, Conversion, Custody, and Transfer Licensing",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Entities providing Payment Token Services in or from the United Arab Emirates must obtain the relevant Central Bank of the UAE licence or registration under the Payment Token Services Regulation (issued 7 June 2024, effective 6 July 2024, one-year transitional period ended in June 2026), with Dirham Payment Token issuers requiring a full Issuer Licence, conversion providers requiring a Conversion Provider Licence, custody and transfer services requiring a Custodian and Transferor Licence, and Foreign Payment Tokens requiring registration with CBUAE, and with every Payment Token Issuer required to produce an audited white paper, submit it to CBUAE for acceptance, and publish it at least seven days before making the token available for sale or transfer to persons in the UAE.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uae-vara-virtual-assets-regulations-2023",
      "eu-markets-in-crypto-assets-regulation-mica-2023-1114"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ae-cybercrime-law-2021",
    "title": "United Arab Emirates Federal Decree-Law No. 34 of 2021 on Combating Rumours and Cybercrimes",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Federal Decree-Law No. 34 of 2021 Concerning Combating Rumours and Cybercrimes (the UAE Cybercrime Law) was issued on 26 September 2021 and entered into force on 2 January 2022, replacing Federal Law No. 5 of 2012 on Combating Cybercrimes. The Telecommunications and Digital Government Regulatory Authority (TDRA) is the primary regulatory authority, working alongside the UAE public prosecution and federal courts. UAE federal criminal law applies throughout all seven emirates and within the special economic zones - including the Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM) - for criminal matters, regardless of those zones' independent civil and commercial court jurisdiction. The UAE Cybercrime Law creates offences across two main categories: electronic access and data offences, and content offences including rumours and false information. Unauthorised access offences: Art. 2 criminalises basic unauthorised electronic access (imprisonment minimum one year and/or fine AED 100,000-300,000); Art. 3 criminalises access with intent to obtain, modify, disclose, destroy, or alter data (fine AED 200,000-500,000); Art. 4 imposes aggravated penalties for unauthorised access to government, banking, financial system, or critical infrastructure systems (imprisonment plus fine AED 500,000-3,000,000). Art. 6 criminalises destruction or disruption of electronic systems or data (fine AED 200,000-2,000,000 and/or imprisonment). Art. 7 criminalises illegal interception of electronic communications (imprisonment and/or fine AED 500,000-3,000,000). Electronic fraud and identity crime: Art. 9 criminalises electronic fraud - obtaining financial benefit by deception through electronic means - with imprisonment up to 10 years and fine AED 250,000-1,500,000; aggravated penalties apply where the fraud targets financial institutions or involves organised crime. Art. 12 criminalises electronic impersonation and identity fraud (imprisonment and/or fine AED 250,000-1,000,000). Art. 13 criminalises phishing and data theft by deception (imprisonment and/or fine AED 500,000-1,000,000). Content offences: Art. 26 criminalises electronic harassment and cyberbullying (imprisonment and/or fine AED 250,000-500,000). Art. 29 criminalises publication of content violating public order, public morals, or Islamic values. Art. 34 criminalises publication of false information or rumours via electronic means that is likely to harm public order, religious values, public decency, or the privacy of others (imprisonment and/or fine AED 100,000-500,000). Art. 35 imposes aggravated penalties where published false information affects the state's interests or national unity. Art. 40 provides that use of information technology to commit any other crime attracts enhanced penalties. Extra-territorial jurisdiction: Art. 43 establishes that the UAE Cybercrime Law applies to offences committed outside the UAE where: (a) the offence targets a UAE person or organisation; (b) the offence is committed via UAE information infrastructure; or (c) the offence has effects within the UAE. The UAE has extradition treaties with a number of states and can request extradition of suspected offenders. The TDRA operates the ecrime.ae portal for cybercrime incident reporting. UAE courts have applied the Cybercrime Law to social media posts, business communications, and news articles accessible to UAE audiences. Organisations with any UAE-facing digital presence must implement content moderation, access security, and incident response frameworks aligned with this law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ae-difc-dp-2020",
    "title": "UAE DIFC Data Protection Law 2020 - DIFC Law No. 5 of 2020 and Commissioner of Data Protection",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Dubai International Financial Centre (DIFC) Data Protection Law 2020 (DIFC Law No. 5 of 2020), enacted on 1 July 2020 and commencing on 1 October 2020, is the data protection framework governing personal data processing within the DIFC, which is a designated free zone in Dubai with its own independent legal and regulatory system based on common law principles. DIFC Law No. 5 of 2020 replaced the earlier DIFC Data Protection Law 2007 (DIFC Law No. 1 of 2007) and is specifically designed to align with the EU General Data Protection Regulation (GDPR) framework, making the DIFC one of the most GDPR-compatible jurisdictions in the Middle East and Africa region. The DIFC is a major international financial centre - home to over 5,000 registered companies including many of the world's largest banks, asset managers, law firms, and professional services firms. The enforcement authority for the DIFC Data Protection Law 2020 is the Commissioner of Data Protection (CDP), who is appointed by the DIFC Authority (DIFCA). The Commissioner investigates complaints, conducts audits, issues enforcement notices, and imposes fines. Key features of DIFC Law No. 5 of 2020: (1) Controllers and processors - GDPR-aligned controller/processor framework; (2) Six lawful bases for processing: consent, contract, legal obligation, vital interests, public task, and legitimate interests; (3) Special categories of personal data: race or ethnic origin, political opinion, religious or philosophical belief, trade union membership, physical or mental health, sexual life or orientation, biometric data used for identification, criminal convictions or allegations - processed only with explicit consent or in limited exceptions; (4) Data subject rights: access, rectification, erasure, portability, restriction, objection, and rights related to automated decision-making - aligned with GDPR Arts. 15-22; (5) Data Protection Officer (DPO): required where processing poses high risk to data subjects - controllers must assess DPO need based on processing profile; (6) Personal data breach notification: notify the CDP within 72 hours; notify affected data subjects without undue delay for high-risk breaches; (7) Data Protection Impact Assessment (DPIA): required for high-risk processing; (8) Cross-border data transfer: transfers only to adequate jurisdictions or with appropriate safeguards; the DIFC CDP maintains a list of adequate jurisdictions; (9) Fines: up to USD 100,000 per violation; (10) Privacy notices must be provided before collection in English (and Arabic where appropriate). The DIFC is a separate legal jurisdiction from mainland UAE - DIFC law applies to entities registered in the DIFC; mainland UAE entities are subject to the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (Federal PDPL). DIFC entities transferring data to mainland UAE entities must consider both DIFC and Federal PDPL requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ae-federal-decree-law-34-2021-cybercrimes",
    "title": "UAE Federal Decree-Law No. 34 of 2021 on Combatting Rumours and Cybercrimes - In Force 2 January 2022",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Individuals and organisations in the United Arab Emirates must comply with Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes (in force 2 January 2022), which provides a comprehensive legal framework to protect UAE government websites and databases, combat the spread of rumours and fake news, safeguard against electronic fraud, and maintain privacy and personal rights, by avoiding hacking, attacking or tampering with government information systems and data, refraining from disseminating false information or information that harms UAE interests or security, and verifying the credibility of information before sharing or forwarding, given that an online user could be punished or held liable under the law by merely sharing, forwarding, or distributing an article or comment containing inaccurate or misleading information even if the user is not the publisher.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ae-pdpl-2021-article-3-data-protection-principles"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "ae-federal-decree-law-45-2021-personal-data-protection",
    "title": "UAE Federal Decree-Law No. 45/2021 - Personal Data Protection Law",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data establishes lawful bases for processing, data subject rights, mandatory DPO appointment for large-scale or sensitive data processing, a 72-hour breach notification obligation to the UAE Data Office, enhanced conditions for sensitive and biometric data, cross-border transfer restrictions, and penalties up to AED 20 million for violations enforced by the UAE Data Office (UAEDO).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-6-lawful-basis-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ae-pdpl-2021",
    "title": "UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The UAE PDPL establishes a comprehensive data protection framework governing the processing of personal data for individuals within the UAE, applying to any controller or processor located in the UAE or located outside the UAE that processes data of UAE residents, as defined in Article 2. The law requires explicit consent for data processing unless a specific legal basis applies and mandates clear data governance, security measures, and breach notification procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ae-pdpl-2021-article-10-cross-border-data-transfer",
    "title": "UAE PDPL Federal Decree-Law 45/2021 - Article 10: Cross-Border Personal Data Transfer Conditions",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "UAE Federal Decree-Law No. 45/2021 Article 10 prohibits transferring personal data outside the UAE unless one of four conditions is met: the destination country provides an adequate level of protection determined by the UAE Data Office; the controller applies appropriate safeguards (contractual or binding corporate rules); the transfer is covered by an approved cross-border data sharing framework; or the data subject provides explicit consent to the transfer after being informed of the destination country's risk. UAE Data Office maintains a list of adequate countries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ae-pdpl-2021",
      "ae-pdpl-2021-article-3-data-protection-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ae-pdpl-2021-article-3-data-protection-principles",
    "title": "UAE PDPL Federal Decree-Law 45/2021 - Article 3: Seven General Principles of Personal Data Protection",
    "domain": "Data Protection & Privacy",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "UAE Federal Decree-Law No. 45/2021 Article 3 establishes seven mandatory general principles for personal data processing: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. Every processing activity by controllers or processors operating in the UAE or processing UAE residents' data must comply with all seven principles simultaneously.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ae-pdpl-2021",
      "ae-pdpl-2021-article-6-data-subject-rights"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ae-pdpl-2021-article-6-data-subject-rights",
    "title": "UAE PDPL Federal Decree-Law 45/2021 - Article 6: Rights of Data Subjects",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "UAE Federal Decree-Law No. 45/2021 Article 6 grants data subjects six enforceable rights: right to be informed of processing; right to access their personal data; right to correction of inaccurate data; right to erasure; right to restrict processing to their original consent purpose; and right to obtain a copy of their data. Controllers must respond within defined timelines set by Cabinet Resolution No. 33/2022 and may not charge a fee for standard requests.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ae-pdpl-2021",
      "ae-pdpl-2021-article-3-data-protection-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "af-atra-framework",
    "title": "Afghanistan ATRA Framework - Constitutional Privacy Obligations and ICT Regulatory Personal Data Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Afghanistan's telecommunications and ICT sector is regulated by the Afghanistan Telecom Regulatory Authority (ATRA). The Afghan Constitution of 2004 (which was in force under the Islamic Republic of Afghanistan) established fundamental rights including the right to privacy of personal life and freedom from arbitrary interference with correspondence and communications. The Electronic Transactions Law of Afghanistan and the Law on Access to Information (enacted under the Islamic Republic) provided a legal framework for electronic commerce and transparency that included provisions for the protection of personal data in digital systems. Following the change in government in August 2021, Afghanistan is governed by the Islamic Emirate of Afghanistan, which has taken a different approach to law and governance. The Islamic Emirate does not recognise the 2004 Constitution and has yet to formally promulgate a replacement constitutional or comprehensive statutory framework, creating significant legal uncertainty for all regulatory matters including personal data protection. ATRA continues to operate as the telecommunications regulator. Organisations processing personal data in Afghanistan face extreme governance uncertainty and should seek current guidance from legal counsel with specific expertise in the current Afghan regulatory environment before commencing or continuing personal data processing operations. The prior legal framework remains a reference point while the current legal status is uncertain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/af-atra-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "africa-union-ai-strategy-2024",
    "title": "African Union Continental AI Strategy - Harnessing AI for African Development and Digital Transformation",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-09-12",
    "bluf": "The African Union Continental AI Strategy provides a comprehensive framework for AU Member States to develop and implement national AI policies that are inclusive, ethical, and drive socio-economic development. It establishes seven strategic pillars, including human capital development (Pillar 1), infrastructure (Pillar 2), and governance (Pillar 4), to guide the creation of a unified African AI ecosystem.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "unesco-ethics-ai",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "africa-union-cdp-convention-2014",
    "title": "African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This convention establishes a unified legal framework for African Union member states to regulate electronic transactions, promote cybersecurity, and protect personal data. As per Article 1, its objective is to create a credible digital environment by harmonizing e-commerce laws, strengthening cybercrime legislation, and ensuring fundamental rights to privacy and data protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-popia-2013",
      "ke-dpa-2019",
      "ng-ndpr-2019",
      "eg-pdl-2020",
      "mu-dpa-2017"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "africa-union-digital-transformation-strategy-telecoms",
    "title": "African Union Digital Transformation Strategy 2020-2030 - Telecoms Pillar: National Broadband Plans, African Continental Backbone, Spectrum Harmonisation, Cross-Border Roaming Reduction, Digital Identity Infrastructure and Universal Access Fund Models",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This strategy requires AU Member States to implement national broadband plans, harmonise spectrum allocation, reduce cross-border roaming charges, and establish universal access funds by 2030 to support digital inclusion and infrastructure development across Africa. Key implementation obligations are outlined in the African Union Digital Transformation Strategy 2020-2030.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "3gpp-5g-nr-release-17-specifications",
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-broadband-cost-reduction-directive-2014-61",
      "eu-eidas-trust-services-telecoms-910-2014",
      "eu-roaming-regulation-2022-612"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ag-dpa-2013",
    "title": "Antigua and Barbuda Data Protection Act 2013",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Antigua and Barbuda enacted the Data Protection Act 2013, establishing a comprehensive framework for the protection of personal data held by public and private bodies. The Act is administered by the Data Protection Commissioner of Antigua and Barbuda. It establishes data protection principles governing the collection, processing, and disclosure of personal data, grants data subjects rights of access and correction, requires data controllers to implement security safeguards, and restricts cross-border transfers to jurisdictions with adequate data protection. The Act aligns with OECS and CARICOM data protection standards, ensuring consistency with the broader Caribbean legal framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ag-dpa-2013.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "agent-budget-cap",
    "title": "Agent Budgetary Controls & Ceiling Checks",
    "domain": "Workflow Automation",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Agentized financial controls (Action Boundaries) restrict an autonomous agent's spending power per session, task, or API call to prevent catastrophic loss or unbounded consumption. A properly implemented budget cap architecture requires: a durable spend counter initialized at agent boot, pre-call ceiling checks before every API invocation, fleet-level daily aggregation across all sessions, hard stops on breach with no retry path, mandatory human approval gates for high-value actions, full audit logging of every spend event, and MFA-gated emergency override procedures. Absent these controls, autonomous agents can exhaust allocated compute budgets, incur unexpected cloud costs, or trigger runaway API consumption within a single malformed task.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "agent-kill-switch",
      "iso-42001-risk-assess",
      "nist-ai-rmf-1-0",
      "sg-imda-agentic-ai",
      "owasp-agentic-top10",
      "iso-31000-risk-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "agent-kill-switch",
    "title": "Agent Emergency Stop (Kill-Switch) Design Patterns",
    "domain": "Workflow Automation",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "An AI Agent Kill-Switch is a deterministic safety mechanism designed to immediately terminate or throttle an autonomous agent's execution if it exceeds predefined behavioral, financial, or operational boundaries. A compliant kill-switch architecture requires: sub-50ms signal propagation to prevent runaway execution, a graceful shutdown window with hard-terminate fallback on timeout, state snapshot capture before forced termination, dead letter queue routing for incomplete tasks, rollback of reversible actions, mandatory human-in-loop approval before restart, and audit logging of every kill event with trigger classification. The corrigibility principle underlying kill-switch design - that agents must remain stoppable and correctable by authorized humans - is foundational to EU AI Act Article 9 risk management requirements and to NIST AI RMF MANAGE 4.1 incident response protocols.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "agent-budget-cap"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ai-action-summit-paris-statement-2025",
    "title": "AI Action Summit Paris - Statement on Inclusive and Sustainable AI for People and the Planet (February 11, 2025)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The AI Action Summit hosted in Paris by France co-chaired with India on February 10-11, 2025 produced the Statement on Inclusive and Sustainable Artificial Intelligence for People and the Planet, signed by 60 countries and international organisations. The United States and the United Kingdom did not sign the Statement. The Statement is the third in the AI Safety Summit series following Bletchley Park (UK, November 2023) and Seoul (Republic of Korea, May 2024). The Statement articulates five priorities: (1) Promoting AI accessibility to reduce digital divides; (2) Ensuring AI is open, inclusive, transparent, ethical, safe, secure and trustworthy taking into account international frameworks; (3) Making innovation in AI thrive by enabling conditions for its development and avoiding market concentration; (4) Encouraging AI deployment that positively shapes the future of work and labour markets; (5) Making AI sustainable for people and the planet. The Statement also launched the Current AI public-interest AI partnership and the International Network of AI Safety Institutes joint statement. The non-signature by the US and UK reflected concerns about regulatory burden and AI safety commitments; nevertheless the Statement is the consensus declaration of the majority of summit participants and informs subsequent multilateral AI work.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "international_alignment",
        "industry_mapping",
        "regulatory_overlay",
        "us_uk_position"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-2023-frontier-ai-safety",
      "uk-international-ai-safety-report-2025",
      "uk-frontier-ai-safety-commitments-seoul-2024",
      "council-of-europe-ai-treaty-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ai-agent-collision-logic",
    "title": "Multi-Agent Collision Resolution",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Multi-agent collision logic provides deterministic protocols for resolving conflicts when two or more autonomous AI agents simultaneously attempt to access the same resource, modify the same shared state, execute contradictory actions, or pursue incompatible goal trajectories within a swarm or orchestration framework. Without collision resolution, multi-agent systems produce race conditions, data corruption, deadlocks, and cascading failures that are difficult to audit or remediate. The resolution framework draws from distributed systems theory - consensus algorithms, vector clocks, conflict-free replicated data types (CRDTs), and resource arbitration - as well as emerging agentic safety standards. Properly implemented collision logic ensures predictable, auditable outcomes and maintains system safety invariants even when individual agents operate concurrently and autonomously.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "agent-kill-switch"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ai-dpa-2018",
    "title": "Anguilla Data Protection Act 2018",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Anguilla, a British Overseas Territory, enacted the Data Protection Act 2018 aligned with UK and EU data protection standards. Administered by the Anguilla Information Commissioner, the Act establishes data protection principles, confers rights on data subjects including access, correction, restriction, and objection, and requires appropriate security measures for personal data processing. Special categories of sensitive personal data require explicit consent or specific statutory conditions. Cross-border transfers require adequate protection or approved safeguards. The Act requires controllers to notify the Information Commissioner of personal data breaches likely to result in high risk. Enforcement is by the Information Commissioner, who may issue enforcement notices and civil monetary penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ai-dpa-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ai-ip-copyright",
    "title": "AI-IP: Guidance on Authorship",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The US Copyright Office's AI Policy Statement (February 2023) and subsequent guidance (March 2023) establish that copyright protection requires human authorship - purely AI-generated content without human creative control is not copyrightable in the United States. Works involving AI assistance may receive copyright protection for the human-authored elements, but only if a human author made sufficient creative choices that were expressed in the final output. The EU, UK, and other jurisdictions take varying positions, with the UK's Computer Generated Works doctrine providing limited protection for AI outputs. Misrepresenting AI-generated content as human-authored to obtain copyright registration constitutes fraud; failure to disclose AI involvement in patent applications may similarly invalidate those applications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-literary-artistic",
      "copyright-fair-use-us",
      "wipo-copyright-treaty",
      "paris-convention-industrial-property"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "ai-pharmacovigilance-governance-2026",
    "title": "AI-Enabled Pharmacovigilance Systems - Global Governance & Validation Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "AI systems used for signal detection, adverse event processing, literature monitoring, and risk assessment in pharmacovigilance must meet stringent validation, explainability, bias mitigation, human oversight, and auditability standards. Regulators (FDA, EMA, PMDA, SFDA, etc.) treat these as high-impact or high-risk systems requiring GxP compliance, performance qualification, change control, and continuous monitoring to ensure patient safety and data integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pharmacovigilance-ich-e2e-2026",
      "ich-e6-r3-gcp-2026",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "ai-radiology-imaging-governance-2026",
    "title": "AI in Radiology & Medical Imaging - Governance, Validation & Clinical Use (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Clinical governance framework for the deployment and ongoing use of Artificial Intelligence in radiology and medical imaging. It addresses algorithmic bias, continuous monitoring for model drift, physician-in-the-loop requirements, and the safe integration of AI diagnostic support tools into PACS/RIS systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-medical-qms",
      "eu-mdr-2017-745"
    ],
    "primary_citations_count": 2
  },
  {
    "node_id": "aia-a201-general-conditions-2017",
    "title": "AIA Document A201-2017 General Conditions of the Contract for Construction",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2024-08-15",
    "bluf": "This standard contract document from the American Institute of Architects (AIA) establishes the rights, responsibilities, and relationships of the Owner, Contractor, and Architect, governing the administration of the construction contract. It details critical procedures for project execution, including payments, submittals, insurance, and the formal process for handling Changes in the Work as defined in Article 7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "89.99",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pmbok-7-guide-pm",
      "icc-arbitration-rules-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "aicpa-code-ethics",
    "title": "AICPA Code of Ethics",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The AICPA Code of Professional Conduct (ET §0.300) establishes binding ethical standards for Certified Public Accountants in public practice and business. The Code requires CPAs to maintain independence in all attest engagements - any direct or material indirect financial interest in an audit client creates an impairment with no de minimis exception. The Conceptual Framework (ET §1.010.010) mandates evaluation of five threat categories (self-interest, self-review, advocacy, familiarity, and intimidation) and application of safeguards before accepting or continuing any engagement. Key operational requirements include: 40 hours of continuing professional education annually, 7-year documentation retention under PCAOB Rule 4003, engagement quality review by a second partner for all public company audits, prohibition on management functions and bookkeeping for audit clients under SOX §201, and confidentiality breach notification within 24 hours. Violations expose CPAs to AICPA Ethics Division investigation, state board disciplinary action, license revocation, and SEC or PCAOB enforcement proceedings for registered firms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifac-ethics-accountants",
      "pcaob-audit-standards",
      "sarbanes-oxley-act-sox",
      "gaap-us-framework",
      "sarbannes-oxley-404"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "aicpa-description-criteria-dc-2018",
    "title": "AICPA Description Criteria (DC Section 200) for a SOC 2 System Description",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The AICPA Description Criteria (DC section 200) define what a service organization must include when describing its system in a SOC 2 report. They are distinct from the Trust Services Criteria: the description criteria govern the completeness and accuracy of the system description (infrastructure, software, people, procedures, data, commitments, and system requirements), while the trust services criteria govern the controls. A SOC 2 examination evaluates the description against DC 200 and the controls against the trust services criteria.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "aicpa-soc2-cc-availability",
    "title": "AICPA SOC 2 Trust Services Criteria - Availability Category (Additional Criteria A1.1-A1.3)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-07-03",
    "bluf": "The AICPA SOC 2 Availability Trust Services Category requires an entity to maintain controls ensuring its information and systems are available for operation and use to meet its objectives, as committed or agreed. This is primarily achieved through processing capacity monitoring, environmental protections, data backup processes, recovery infrastructure, and recovery plan testing, as detailed in the additional availability criteria A1.1, A1.2, and A1.3, which supplement the common criteria including the Risk Mitigation criteria CC9.1 and CC9.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-53-cp2",
      "iso-27001-2022",
      "iso-31000-risk-mgt-std",
      "cyber-nist-csf-2"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "aicpa-soc2-cc-confidentiality",
    "title": "AICPA SOC 2 Trust Services Criteria - Confidentiality Category (C1.1-C1.2)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-07-03",
    "bluf": "The AICPA SOC 2 Confidentiality principle requires entities to protect information designated as confidential throughout its lifecycle, from creation to destruction, as committed or agreed. The Confidentiality category comprises criteria C1.1 (the entity identifies and maintains confidential information) and C1.2 (the entity disposes of confidential information), supported by the Logical and Physical Access Controls common criteria CC6.1 through CC6.8, which protect confidential information against unauthorized access and disclosure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0",
      "cis-controls-v8",
      "fips-197-advanced-encryption-standard"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "aicpa-soc2-cc-privacy",
    "title": "AICPA SOC 2 Trust Services Criteria - Privacy Category (P1.0-P8.0 Privacy Notice and Choice)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The AICPA SOC 2 Privacy Category requires service organizations to provide a clear privacy notice detailing their personal information practices (P1.0) and to offer choices to individuals regarding the collection, use, retention, and disclosure of their personal information (P2.0). This applies to any entity whose SOC 2 report scope includes the Privacy Trust Services Criterion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "gdpr-adequacy-decisions-article-45",
      "california-ccpa-v2",
      "uk-retained-gdpr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "aicpa-soc2-cc-processing-integrity",
    "title": "AICPA SOC 2 Trust Services Criteria - Processing Integrity Category (PI1.1-PI1.5)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation requires service organizations to implement controls ensuring that system processing is complete, valid, accurate, timely, and authorized to meet the entity's objectives. The core criteria, PI1.1 through PI1.5, mandate the establishment of policies and procedures, and controls over system inputs, data processing, system outputs, and data storage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "cyber-nist-800-53-ac2",
      "nist-800-53-au2",
      "cis-controls-v8"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "aicpa-ssae-21-direct-examination-engagements-2020",
    "title": "AICPA SSAE No. 21 (September 2020) - Direct Examination Engagements (AT-C Section 206)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "Statement on Standards for Attestation Engagements (SSAE) No. 21, Direct Examination Engagements, was issued by the AICPA Auditing Standards Board in September 2020. It creates AT-C section 206, Direct Examination Engagements, supersedes SSAE No. 18 AT-C section 205, Examination Engagements (which is recast as assertion-based examination engagements), and amends AT-C section 105, Concepts Common to All Attestation Engagements. In a direct examination engagement the practitioner measures or evaluates the underlying subject matter against the criteria and performs other procedures to obtain sufficient appropriate evidence to express an opinion in a written report that conveys the results of that measurement or evaluation; the responsible party does not provide an assertion about the results of the measurement or evaluation. Under AT-C 206 paragraph .05 the practitioner is not required to request a written assertion from the responsible party, but must apply the other requirements of AT-C section 205 unless a requirement cannot be applied because of the nature of a direct examination engagement. By contrast, in an assertion-based examination engagement (AT-C 205, the basis for SOC 1 and SOC 2 examinations) a party other than the practitioner measures or evaluates the underlying subject matter against the criteria and provides an assertion about the outcome, and the practitioner opines on the subject matter or the assertion. SSAE No. 21 amendments are effective for practitioners reports dated on or after June 15, 2022. Direct examination expands the attestation toolkit for engagements where the responsible party cannot or does not measure the subject matter itself, including emerging subject matter such as sustainability metrics, controls implementation, and compliance postures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "soc_examination_relationship",
        "ssae_18_lineage",
        "isae_3000_international_analogue",
        "industry_mapping",
        "enforcement_anchors",
        "effective_date_anchor"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ssae-18-attestation-standards-soc",
      "soc-2-type-ii-trust-services-criteria-2024",
      "isae-3000-revised-assurance-engagements"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "al-pdpa-2008",
    "title": "Albania Law on Protection of Personal Data No. 9887 of 2008 - IDPC",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Albania's Law on Protection of Personal Data No. 9887 - adopted by the Assembly of the Republic of Albania on 10 March 2008 and amended significantly through subsequent legislation (including the 2012 amendments on Law No. 48/2012 and the major GDPR-aligning amendments of 2017 and 2018 enacted as part of Albania's EU accession preparations) - is Albania's primary personal data protection legislation establishing a comprehensive rights-based framework for the protection of personal data. Albania received EU candidate status in 2014 and formally opened EU accession negotiations in 2022, driving progressive GDPR alignment. The supervisory authority is the Commissioner for the Right of Access to Information and Personal Data Protection (Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave - IDPC), an independent institution whose mandate covers both freedom of information and personal data protection in Albania. Key features of Albania's Law on Protection of Personal Data No. 9887 as amended: (1) Scope - applies to personal data processing by public authorities, legal entities, and individuals established in Albania or processing data of Albanian data subjects regardless of establishment; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation (proportionality); accuracy; storage limitation; security; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right not to be subject to solely automated decisions; and rights relating to data portability (introduced by GDPR-alignment amendments); (6) Data Protection Officer - required for public authorities and organisations processing personal data on a large scale or systematically; (7) Breach notification - controllers must notify the IDPC of personal data breaches within 72 hours of awareness, mirroring the GDPR timeline under the GDPR-alignment amendments; (8) Data Protection Impact Assessment - required for high-risk processing aligned with GDPR standards; (9) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or subject to IDPC-approved safeguards; (10) Penalties - administrative fines graduated by violation severity. Albania's Law is among the most GDPR-aligned data protection frameworks in the Western Balkans, supporting Albania's EU accession trajectory and its significant information technology and outsourcing sector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "alcohol-service-std",
    "title": "Responsible Alcohol Service",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Responsible alcohol service standards govern the legal and operational obligations of licensed on-premise alcohol retailers - bars, restaurants, hotels, event venues, and stadiums - to prevent service to minors and visibly intoxicated patrons. The National Minimum Drinking Age Act (23 U.S.C. §158) mandates a minimum legal drinking age of 21 in all U.S. states; service to minors exposes licensees to criminal liability, license revocation, and civil dram shop liability. State Dram Shop Acts impose third-party tort liability on servers who provide alcohol to visibly intoxicated persons who subsequently cause injury. Compliance requires: mandatory server certification through programs such as TIPS (Training for Intervention ProcedureS) or ServSafe Alcohol, documented ID verification procedures with a check-for-anyone-appearing-under-30 standard, written protocols for identifying signs of intoxication and executing patron cutoff, incident log maintenance, and manager override authorization for disputed service decisions. Licensees failing to enforce responsible service standards face ABC license suspension, criminal prosecution of servers, and civil judgments in dram shop actions that have exceeded $1 million in multiple U.S. jurisdictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hcll-hospitality-licensing",
      "pci-dss-hospitality",
      "haccp-food-safety",
      "ada-hospitality-access",
      "hotsec-hotel-security"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "alderney-egambling-regulations-2009",
    "title": "Alderney eGambling Regulations 2009 - Associate and Full Certificate Requirements, Technical Standards and AML Obligations",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Alderney eGambling Regulations 2009 establish licensing, technical, and anti-money laundering (AML) requirements for operators providing online gambling services from Alderney. It applies to all applicants and holders of Associate or Full Certificates under the Gambling Control (Licensing and Advertising) (Alderney) Law 2000, with key obligations in Regulation 7 (licensing), Regulation 12 (systems integrity), and Regulation 15 (AML/CFT).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l3",
      "eu-dora-articles-28-44-third-party-ict-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "allea-european-code-research-integrity-2023",
    "title": "The European Code of Conduct for Research Integrity (2023 Revised Edition)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This code establishes the foundational principles of research integrity-reliability, honesty, respect, and accountability-for all researchers, institutions, and stakeholders involved in EU-funded research. It applies across all scientific disciplines and mandates adherence to ethical standards in data management, publication, authorship, and institutional oversight as outlined in the 2023 ALLEA revision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-open-science-policy-fair-data-principles-2021",
      "eu-researcher-charter-code-of-conduct-2005",
      "eu-european-research-area-policy-agenda-2022",
      "oecd-recommendation-responsible-research-innovation-2021",
      "ilo-convention-111-discrimination-employment-education"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "am-pdp-law-2015",
    "title": "Armenia Law on Protection of Personal Data 2015 - Data Protection Agency",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Armenia's Law on Protection of Personal Data (Հայաստանի Հանրապետության «Անձնական տվյալների պաշտպանության մասին» օրենք, Law No. HO-49-N) - adopted on 18 May 2015 and entering into force on 1 July 2016 - is Armenia's primary personal data protection legislation, replacing the earlier 2002 law and establishing a more comprehensive rights-based framework aligned with European data protection standards. The law was enacted in the context of Armenia's membership in the Eurasian Economic Union (EAEU) and the EU-Armenia Comprehensive and Enhanced Partnership Agreement (CEPA, in force 2021), which includes obligations for progressive alignment with EU standards including data protection. The supervisory authority is the Agency for Personal Data Protection of the Republic of Armenia (Հայաստանի Հանրապետության Անձնական Տվյալների Պաշտպանության Գործակալություն - PDPA), established as an independent body under the Ministry of Justice framework. Key features of Armenia's Law on Protection of Personal Data 2015: (1) Scope - applies to personal data processing by state bodies, local self-governing bodies, legal entities, and individuals in Armenia; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; proportionality; accuracy; storage limitation; security; and confidentiality; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political views; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; and biometric data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to object; and right to complain to the PDPA; (6) Operator obligations - operators (data controllers) must notify the PDPA before commencing processing; implement security measures; and designate a responsible person; (7) Breach notification - operators must notify the PDPA of significant personal data security incidents; (8) Cross-border transfers - personal data transfers outside Armenia require adequate protection or PDPA-approved safeguards; (9) PDPA enforcement - investigates complaints; conducts inspections; issues binding orders; initiates administrative proceedings; (10) EU alignment - Armenia's CEPA obligations drive progressive alignment with GDPR standards; Council of Europe Convention 108+ ratification confirms Armenia's commitment to European data protection standards. Armenia's Law positions the country as a data-secure jurisdiction in the South Caucasus, supporting Armenia's significant IT services export sector which processes significant personal data of international clients.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ama-ethical-marketing",
    "title": "AMA (Ethical Marketing)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Adherence to this node's parameters ensures marketing communications embody the American Marketing Association's core ethical norms, primarily to do no harm, foster trust within the marketing system, and embrace foundational values. This framework operationalizes AMA principles through stringent technical controls and alignment with federal law. To uphold Honesty and Fairness, as mandated by the Federal Trade Commission Act, all content must pass `fact_verification`, and a `max_deceptive_pattern_score` of 0 is strictly enforced, alongside a requirement that any `competitor_comparison_fairness_verified` parameter is met. The principle of Transparency is systemically enforced through regulations like the FTC's Guides Concerning the Use of Endorsements and Testimonials, demanding `require_sponsorship_disclosure` is active and that disclosures achieve a `disclosure_prominence_score_min` of at least 0.85 for sufficient clarity, which complements the `require_pricing_transparency` rule. Respect for consumers is maintained by prohibiting coercive tactics, reflected in a `max_coercion_index` of 0, and by safeguarding consumer expression under the Consumer Review Fairness Act; these protections are further bolstered while `vulnerable_audience_protection_active` status is engaged, `privacy_consent_verified`, and a functional `require_opt_out_mechanism` is available. Finally, the value of Citizenship is addressed by confirming every `sustainability_claim_substantiated` in accordance with the FTC's Green Guides, ensuring environmental marketing is responsible and defensible.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-endorsement-guides",
      "can-spam-act-email",
      "coppa-marketing-kids",
      "ccpa-cpra-optout-sale",
      "gdpr-art-21-marketing-optout",
      "prsa-code-of-ethics"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "american-convention-human-rights-1969",
    "title": "American Convention on Human Rights 1969 - Pact of San José",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The American Convention on Human Rights (ACHR, Pact of San José, 1969 - 25 State Parties as of April 2026, in force 1978) is the primary human rights treaty in the Inter-American system, establishing a catalogue of civil and political rights enforceable before the Inter-American Commission on Human Rights (IACHR) and the Inter-American Court of Human Rights (IACtHR); businesses operating in Latin American Contracting States must account for IACtHR advisory opinions and judgments on State obligations that create supply chain due diligence responsibilities - the IACtHR's advisory opinion OC-23/17 (2017) on the environment and human rights confirmed that States must regulate corporate activities causing transboundary environmental harm affecting ACHR rights, and OC-29/22 (2022) recognised corporate accountability for supply chain human rights abuses as an emerging State obligation under the ACHR.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-iccpr-1966-civil-political-rights",
      "un-guiding-principles-business-human-rights",
      "echr-1950-european-convention-human-rights",
      "eu-corporate-sustainability-due-diligence-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "amqp-iso-iec-19464-messaging-iot",
    "title": "ISO/IEC 19464:2014 - Information technology - Advanced Message Queuing Protocol (AMQP) v1.0 specification",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This standard defines the Advanced Message Queuing Protocol (AMQP) v1.0, a binary wire-level protocol for reliable exchange of business messages in distributed systems, particularly applicable to Industrial IoT environments. It specifies the type system, transport layer, message format, transaction support, and security layers as defined in Parts 1 through 5 of ISO/IEC 19464:2014.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-4-2-component-security-2019",
      "iec-62351-power-systems-cybersecurity",
      "etsi-en-303-645-iot-cybersecurity-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "antarctic-treaty-1959-peaceful-purposes-territorial-claims",
    "title": "Antarctic Treaty 1959 - Peaceful Purposes, Scientific Cooperation and Territorial Claims Freeze (with 1991 Madrid Protocol)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Antarctic Treaty was signed in Washington DC on 1 December 1959 and entered into force on 23 June 1961. It is the foundational instrument of the Antarctic Treaty System (ATS) governing the area south of 60 degrees South latitude. Article 1 establishes Antarctica for peaceful purposes only, prohibiting any measures of military nature including establishment of military bases, military manoeuvres, weapons testing, and (under Article 5) nuclear explosions and disposal of radioactive waste. Article 2 maintains freedom of scientific investigation and cooperation. Article 3 requires exchange of information regarding plans for scientific programmes, exchange of scientific personnel, and exchange of scientific observations and results. Article 4 establishes the territorial claims freeze: neither asserting nor recognising claims; no new claims; no enlargement of existing claims. Article 7 establishes inspection rights enabling Consultative Parties to designate observers with complete freedom of access to all areas, ships, aircraft and stations of any Treaty Party. The Treaty is supplemented by the Madrid Protocol 1991 (Protocol on Environmental Protection, in force 1998) designating Antarctica as a natural reserve devoted to peace and science and prohibiting mineral resource activities except scientific research. Convention on Conservation of Antarctic Marine Living Resources (CCAMLR) 1980 manages marine resources.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unclos-part-vii-high-seas",
      "imo-polar-code-2017-msc-385-94-resolution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "anthropic-responsible-scaling-policy-2023",
    "title": "Anthropic Responsible Scaling Policy (RSP) 2023 - AI Safety Levels (ASL-2/ASL-3/ASL-4), Capability Thresholds Triggering Enhanced Safeguards, Deployment Restrictions at ASL-3, Third-Party Evaluations, Commitments to Model Cards and Interpretability Research",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Anthropic’s Responsible Scaling Policy establishes an AI Safety Level (ASL) framework to manage catastrophic risks from increasingly capable AI systems, requiring enhanced safety, security, and operational standards as models reach ASL-2, ASL-3, and beyond. Deployment of ASL-3 models is prohibited if they show any meaningful catastrophic misuse risk under adversarial testing by world-class red-teamers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-ai-safety-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "anthropic-responsible-scaling-policy-v2-1-2025",
    "title": "Anthropic Responsible Scaling Policy (Version 2.1, Effective 31 March 2025) - AI Safety Level Standards (ASL-2 Current Baseline; ASL-3 Required for Capability Thresholds in CBRN and Autonomous AI R&D); Capability Thresholds, Required Safeguards, and Governance Framework",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2025-03-31",
    "bluf": "Anthropic Responsible Scaling Policy version 2.1, effective 31 March 2025, is Anthropic PBC's public commitment not to train or deploy models capable of causing catastrophic harm unless safety and security measures keep risks below acceptable levels. The policy was first released in September 2023 (the original RSP) and updated in March 2025 to reflect lessons from the previous year. It is designed to be proportional (safeguards scale to risk), iterative (regularly measured and adjusted), and exportable (a prototype for other companies and a model for regulators). The core construct is AI Safety Level Standards (ASL Standards) - technical and operational measures for safely training and deploying frontier AI models - split into Deployment Standards and Security Standards. As of v2.1, all Anthropic models must meet the ASL-2 Deployment and Security Standards. The progression to ASL-3 (and beyond) is governed by Capability Thresholds and Required Safeguards: a Capability Threshold tells when protections must be upgraded, and the corresponding Required Safeguards specify what standard then applies. Version 2.1 provides specifications for Capability Thresholds in two domains: Chemical, Biological, Radiological, and Nuclear (CBRN) weapons, and Autonomous AI Research and Development (AI R&D), with the corresponding Required Safeguards identified. The capability assessment process is staged: a preliminary assessment first determines whether comprehensive evaluation is needed; comprehensive testing then evaluates whether the model is sufficiently below relevant Capability Thresholds absent surprising post-training enhancements; if Anthropic cannot make the required showing, it acts as though the model has surpassed the Threshold and upgrades to ASL-3 Required Safeguards while running follow-up assessment to confirm ASL-4 is not needed. The ASL-3 Deployment Standard requires robustness to persistent misuse attempts; the ASL-3 Security Standard requires being highly protected against non-state attackers attempting to steal model weights. Governance commitments include maintaining the position of Responsible Scaling Officer, an anonymous reporting channel for staff to notify the RSO of potential noncompliance, internal safety procedures for incident scenarios, and public release (with sensitive information removed) of key evaluation and deployment materials, soliciting input from external experts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "google-deepmind-frontier-safety-framework-v2-2025",
        "openai-preparedness-framework",
        "uk-aisi-ai-safety-evaluation-framework-2024",
        "us-aisi-ai-safety-institute-2024",
        "eu-ai-act-2024",
        "us-nist-sp-800-218a-secure-ai-development",
        "owasp-llm-top-10-2025"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nist-sp-800-218a-secure-ai-development"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "ao-pdp-law-2011",
    "title": "Angola Law No. 22/11 on Personal Data Protection",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Angola enacted Law No. 22/11 of 17 June 2011 on Personal Data Protection (Lei da Protecção de Dados Pessoais), establishing a comprehensive framework modelled on the Portuguese data protection regime and Council of Europe Convention 108. The law is administered by the Data Protection Authority (Agência de Protecção de Dados - APD). It requires registration of data processing activities, mandates consent or another lawful basis, grants data subjects ARCO rights (Acesso, Rectificação, Cancelamento, Oposição), and restricts cross-border transfers to countries with adequate protection. Sensitive personal data categories require APD authorisation and explicit consent. Penalties include fines and criminal sanctions for serious violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ao-pdp-law-2011.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "apache-airflow-workflow-dag-governance",
    "title": "Apache Airflow: Directed Acyclic Graph (DAG) Governance, Execution Contexts, RBAC, Connection Security and Task Idempotency",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Apache Airflow orchestrates complex data pipelines and automated tasks using Python-based DAGs, requiring strict governance over code structure, connection secrets, task idempotency, and role-based access to the Airflow UI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "apec-cbpr-cross-border-privacy-rules-system",
    "title": "APEC Cross-Border Privacy Rules (CBPR) System - Accountability Agent Certification, Nine Information Privacy Principles, Global CBPR Forum and Interoperability with GDPR and Other Frameworks",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The APEC CBPR System is a voluntary, accountability-based framework that facilitates cross-border data transfers for certified organizations operating within participating APEC economies. It requires organizations to implement data privacy policies consistent with the nine principles of the APEC Privacy Framework, verified by a third-party Accountability Agent, to ensure baseline protections for personal information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-privacy-guidelines-2013",
      "gdpr-article-46-transfer-mechanisms",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "apec-cbpr-system-2011",
    "title": "APEC Cross-Border Privacy Rules (CBPR) System",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The APEC CBPR System is a voluntary, accountability-based framework that facilitates privacy-respecting data transfers among APEC member economies by requiring certified organizations to implement data privacy policies consistent with the nine APEC Privacy Principles, as outlined in the APEC Privacy Framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "brazil-lgpd-compliance",
      "korea-pipa-standard",
      "nist-800-122-pii",
      "iso-37301-compliance-ms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "api-std-1164-scada-pipeline-security",
    "title": "API Standard 1164 - SCADA Security for the Oil and Natural Gas Pipeline Industry: Cyber Risk Assessment, Access Control and Patch Management",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "API Standard 1164 establishes cybersecurity requirements for Supervisory Control and Data Acquisition (SCADA) systems in the oil and natural gas pipeline industry, mandating risk assessments, role-based access controls, and patch management procedures. It applies to pipeline operators and system integrators managing OT environments, with key obligations defined in Section 5 (Risk Assessment), Section 6 (Access Control), and Section 7 (Patch Management).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-iacs",
      "nist-sp-800-82-r3-ot-ics-security-guide-2023",
      "ot-ics-purdue-model-zone-based-security",
      "iso-iec-27019-energy-utility-information-security",
      "nerc-cip-v6-cyber"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "appian-intelligent-automation-governance",
    "title": "Appian Intelligent Automation - Platform Governance: Process Modeller, Records Architecture, Security Groups, Environment Promotion and Compliance Reporting",
    "domain": "Cloud & SaaS",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes mandatory governance controls for Appian Intelligent Automation deployments, requiring documented process modeling standards, role-based access via Security Groups, auditable environment promotion workflows, and compliance reporting for automated records processing. Key requirements are defined in Appian Documentation Section 23.4, 'Platform Governance'.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "automation-bpmn-service-task",
      "automation-bpmn-error-boundary",
      "automation-bpmn-agent-handover",
      "mcp-enterprise-auth",
      "iso-15489-1-2016-records-management-workflow"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "apra-cps-230-resilience",
    "title": "APRA CPS 230 (Resilience)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "APRA CPS 230 (Operational Risk Management) is the new cross-industry standard for the Australian financial sector. it replaces several legacy standards (CPS 231, CPS 232) with a unified framework for operational risk, service provider management, and business continuity, placing increased accountability on the board for the firm's resilience.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "bcbs-principles-sound-management-operational-risk",
      "apra-cps-234",
      "iso-22301-biz-continuity",
      "eba-outsourcing-guide",
      "interagency-guidance-third-party-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "apra-cps-234",
    "title": "APRA Prudential Standard CPS 234 Information Security",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "A mandatory Australian regulatory standard ensuring that APRA-regulated entities maintain robust information security capabilities, with ultimate accountability residing at the Board level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "apra-cps-230-resilience",
      "iso-27001-2022",
      "iso-31000-risk-mgt",
      "nist-cybersecurity-framework-2-0",
      "iia-internal-audit-ippf"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ar-data-protection-act-25326-2000-personal-data",
    "title": "Argentina Law 25.326 Personal Data Protection Act 2000 AAIP Data Subject Rights Cross-Border Transfer and Registration of Databases Framework",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "Argentina Law 25.326 Personal Data Protection Act (Ley de Protección de los Datos Personales) enacted on 4 October 2000 administered by the Agencia de Acceso a la Información Pública (AAIP) establishes the comprehensive personal data protection framework organised in operative chapters including Chapter 1 General Provisions defining personal data and sensitive data Chapter 2 General Principles including section 4 quality of data section 5 consent section 7 categories of data and section 11 transfer of data Chapter 3 Rights of Data Subjects including section 13 right to information section 14 right of access section 15 right of rectification and section 16 right of deletion Chapter 4 Users and Persons Responsible for Data Processing Chapter 5 Control including registration of personal databases under section 21 with the AAIP Chapter 6 Sanctions including administrative sanctions and civil and criminal liability under sections 31 through 32 and Chapter 7 Habeas Data Action including procedural rules for judicial enforcement. Argentina received European Commission adequacy decision in 2003 facilitating cross-border data transfers with the European Union. Law is supplemented by Decree 1558/2001 implementing regulations and the AAIP Resolution on cross-border transfers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "ar-decision-administrativa-899-2024-mesa-interministerial-ai-aaip-resolucion-161-2023",
    "title": "Argentina Decisión Administrativa 899/2024 (Mesa Interministerial de IA) and AAIP Resolución 161/2023 (Programa Nacional de Transparencia y Protección de Datos Personales en el Uso de IA)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Argentina's national AI governance framework is structured through two operational instruments: (1) Decisión Administrativa 750/2023 of 7 September 2023 created the Mesa Interministerial de Inteligencia Artificial (Interministerial Board on AI) within the Jefatura de Gabinete de Ministros, and Decisión Administrativa 899/2024 published in the Boletín Oficial on 24 September 2024 (URN DA-2024-899-APN-JGM, expediente EX-2024-87114559-APN-DGDYD#JGM) amended arts 2, 3, and 4 of DA 750/2023 to restructure the Mesa under the Secretaría de Innovación, Ciencia y Tecnología; (2) AAIP (Agencia de Acceso a la Información Pública) Resolución 161/2023 established the Programa Nacional de Transparencia y Protección de Datos Personales en el Uso de la Inteligencia Artificial which advances analysis, regulation, and capacity-building for AI governance in the public and private sectors and is operationalised through the AAIP Guía para entidades públicas y privadas en materia de Transparencia y Protección de Datos Personales para una Inteligencia Artificial responsable (2025) published at argentina.gob.ar. The Mesa Interministerial has authority over the design of a comprehensive AI strategy applied by the Federal Government. Its members include the Jefatura de Gabinete de Ministros, the Ministerios de Defensa, Economía, Relaciones Exteriores Comercio Internacional y Culto, Salud, Seguridad, Capital Humano, Justicia, Desregulación y Transformación del Estado, the Secretaría de Asuntos Estratégicos and the Secretaría de Innovación Ciencia y Tecnología. The AAIP Guide imposes operational expectations on data controllers using AI including evaluaciones de impacto (impact assessments equivalent to DPIA), the principio de explicabilidad (explainability), data protection security measures, multidisciplinary review (technical and ethical), and comprehensive lifecycle review aligned with Ley 25.326 (Argentina Personal Data Protection Act) and the AI-relevant safeguards of the Constitución Nacional. Several AI bills (Proyecto de Ley 3003-D-2024 and 0805-D-2024) are in legislative process in the Cámara de Diputados; Buenos Aires City has issued its own decreto promoting AI in public administration; provincial AI strategies are emerging in parallel.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "mesa_interministerial_da_750_2023",
        "decision_administrativa_899_2024_amendment",
        "mesa_membership_structure",
        "aaip_resolucion_161_2023_programa_nacional",
        "aaip_guia_2025_operational_expectations",
        "ley_25326_personal_data_protection_basis",
        "pending_ai_legislation",
        "buenos_aires_city_ai_decree",
        "relationship_with_unesco_oas_ibero_american_frameworks",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ar-data-protection-act-25326-2000-personal-data",
      "ar-pdp-25326-2000",
      "eu-ai-act-article-50-transparency-obligations",
      "nist-ai-rmf-1-0-govern-function",
      "unesco-ai-ethics-work"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ar-decree-1023-2001-regimen-contrataciones-administracion-nacional-comprar",
    "title": "Argentina Decree 1023/2001 Regimen de Contrataciones de la Administracion Nacional and COMPR.AR Electronic Procurement Platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Argentine Decree of Necessity and Urgency No. 1023/2001 (Decreto de Necesidad y Urgencia 1023/2001) issued 13 August 2001 and effective 16 August 2001 ratifies and establishes the Regimen de Contrataciones de la Administracion Nacional (National Administration Contracting Regime), the principal Argentine federal-level regulatory framework governing procurement of goods, services, and works by the Argentine National Administration including the Centralized National Administration (Administracion Centralizada Nacional, ministries and dependencies) and the Decentralized National Administration (Administracion Descentralizada Nacional including autonomous agencies, deconcentrated administrative entities, and state companies). Decree 1023/2001 was complemented and supplemented by the implementing regulation Decree 1030/2016 (Reglamento del Regimen de Contrataciones de la Administracion Nacional) which prescribes detailed procedural requirements and modernised the procurement framework with electronic procurement as the default. The Oficina Nacional de Contrataciones (ONC / argentina.gob.ar/jefatura/innovacion-publica/onc) within the Chief of Cabinet Office (Jefatura de Gabinete de Ministros) is the central procurement policy authority. The COMPR.AR platform (comprar.gob.ar) is the mandatory federal electronic procurement platform for the procurement of goods and services, and CONTRAT.AR (contratar.gob.ar) is the platform for public works procurement. Procurement methods established by Decree 1023/2001 art. 25 comprise (a) Licitacion Publica or Concurso Publico (Public Tender, the default open public procedure), (b) Licitacion Privada or Concurso Privado (Private Tender, limited bidding with prequalification), (c) Contratacion Directa (Direct Contracting, sole-source under prescribed exceptions in art. 25 paragraph d, including low-value below thresholds, urgency, sole supplier for technical reasons, prior failed procurement, and prescribed-class exemptions), and (d) Subasta Publica (Public Auction). Provincial procurement is governed by parallel provincial regimes including the Buenos Aires Province Decree-Law 7764/71 and equivalent provincial statutes. Argentina is NOT a party to the WTO Government Procurement Agreement (GPA) but is an observer.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "ar-data-protection-act-25326-2000-personal-data",
      "ar-decision-administrativa-899-2024-mesa-interministerial-ai-aaip-resolucion-161-2023",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ar-ley-20247-semillas-creaciones-fitogeneticas-1973",
    "title": "Argentina Ley 20.247 - Ley de Semillas y Creaciones Fitogeneticas",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "Argentina Ley 20.247 (1973) establishes the legal framework for seed production commerce and plant breeders rights. The Act creates the Ministerio de Agricultura y Ganaderia as the competent authority and establishes the Comision Nacional de Semillas to advise on policy. Article 9 mandates that all seed exposed to public or delivered to users must be properly identified with species cultivar purity and germination data on the package label. Article 16 establishes the Registro Nacional de Cultivares (RNC) for variety registration prerequisite to commerce. Article 19 establishes the Registro Nacional de la Propiedad de Cultivares (RNPC) protecting plant breeders rights of creators and discoverers of new cultivars. Article 27 codifies the farmer's privilege exception: a person reserving seed for own use or using/selling the harvested product does not infringe plant breeder rights. Articles 35-46 establish administrative penalties from warnings through fines (one hundred pesos to one hundred thousand pesos at time of enactment) and merchandise seizure for identification and registration violations. The Act is supplemented by Decreto 2183/91 implementing regulations and INASE (Instituto Nacional de Semillas) is the operational regulator.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "implementing_decree",
        "upov_alignment",
        "biosafety_framework",
        "mercosur_overlap",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ar-ley-25326-proteccion-datos-personales",
    "title": "Argentina Ley 25.326 de Proteccion de los Datos Personales (Personal Data Protection Act)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Ley 25.326 de Proteccion de los Datos Personales (Argentine Personal Data Protection Act) was sancionada on 4 October 2000 and partially promulgada on 30 October 2000 by Decreto 995/2000. The Act gives constitutional effect to the habeas data action recognised in Art. 43 of the Constitucion Nacional. The Act is organised in 8 Capitulos. Capitulo I Disposiciones generales contains the scope of application and definitions: Art. 1 (objeto - integral protection of personal data in archivos, registros, bancos de datos and other technical means); Art. 2 (definiciones including dato personal as informacion de cualquier tipo referida a personas fisicas o de existencia ideal, dato sensible, archivo registro base o banco de datos, titular de los datos, usuario, responsable de archivo). Capitulo II Principios generales relativos a la proteccion de datos: Art. 4 (calidad de los datos - finality, accuracy, proportionality, retention limits); Art. 5 (consentimiento libre, expreso e informado in writing); Art. 6 (informacion previa al titular); Art. 7 (datos sensibles - special category data with prohibition on creation of databases revealing them); Art. 9 (medidas de seguridad - technical and organisational measures); Art. 11 (cesion - sharing requires titular consent except in 10 cases); Art. 12 (transferencia internacional - prohibited to countries that do not provide adequate protection levels). Capitulo III Derechos de los titulares (Arts. 14-16 - access, rectification, suppression) underpins the habeas data action. Capitulo IV regulates databases of private (Art. 21 registration) and public (Art. 23) sector. Capitulo V Control: AAIP (Agencia de Acceso a la Informacion Publica) since 2017 is the supervisory authority replacing the DNPDP. Capitulo VI Sanciones: Art. 31 administrative fines (currently up to ARS 5,000,000 plus other measures); Art. 32 criminal sanctions (1 month to 3 years for false data; 6 months to 3 years for unlawful access).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "br-lgpd-2018",
      "mx-lfpdppp-2010",
      "eu-gdpr-article-22-automated-decision-making-profiling"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "ar-pdp-25326-2000",
    "title": "Argentina Personal Data Protection Act - Ley 25.326 de Protección de los Datos Personales",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Argentina's Personal Data Protection Act (Ley 25.326 de Protección de los Datos Personales), enacted 4 October 2000 (promulgated 30 October 2000, published in the Official Gazette 2 November 2000), is Latin America's first comprehensive data protection law and remains the foundational data protection framework in Argentina as of April 2026. Argentina has been granted an EU adequacy finding (European Commission Decision 2003/490/EC of 30 June 2003), recognising Argentina as providing adequate protection for personal data transferred from EU member states - one of only two Latin American countries to hold EU adequacy (alongside Uruguay). Enforcement authority: the Agencia de Acceso a la Información Pública (AAIP), established by Decree 746/2017 as successor to the Dirección Nacional de Protección de Datos Personales (DNPDP), is the primary data protection enforcement authority. The habeas data action: Art. 43 of the Argentine Constitution provides a constitutional guarantee known as 'habeas data' - any person may bring a habeas data action before the courts to access, correct, or delete personal data held about them in public registries or in private databases of public utility. This constitutional protection reinforces the statutory framework of Ley 25.326. Key provisions: (1) Data quality principles: personal data must be accurate, adequate, relevant, not excessive for the purpose, and not kept longer than necessary; (2) Sensitive data: data revealing racial origin, political opinions, religious or moral beliefs, health or sexual life, and criminal records - may only be processed with express written consent or in defined exceptional circumstances; (3) Consent: prior, informed, express, and written consent is required for data processing, except where processing is necessary for a pre-contractual or contractual relationship, or required by law; (4) Database registration: all databases (public or private) containing personal data must be registered with the AAIP; unregistered databases may not be used; (5) Data subject rights: right of access (must be provided free of charge, within 30 calendar days), right to rectify or update, right to delete (within 5 business days), right to block, right to oppose; (6) Cross-border transfers: prohibited to countries that do not provide adequate protection, unless exempted by the AAIP or data subject consent; (7) Habeas data action: constitutional right enforceable by summary judicial procedure. Sanctions: the AAIP may impose fines of up to ARS 100 million (subject to periodic adjustment), order database closure, and initiate criminal proceedings. Reform: Argentina has been actively developing a new comprehensive data protection law (Proyecto de Nueva LPDP) to align with GDPR and modernise the 2000 framework - the reform was in advanced stages as of April 2026 but had not yet been enacted.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-adequacy-decisions-article-45",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ar-pdpa-2000",
    "title": "Ley de Protección de los Datos Personales N° 25.326",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Argentina's Personal Data Protection Law establishes the principles for processing personal data in public and private databases, requiring data controllers to obtain prior, express, and informed consent from the data subject for processing (Article 5) and guaranteeing rights of access, rectification, and deletion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-122-pii",
      "za-popia-2013",
      "brazil-lgpd-compliance"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "arbitration-uncitral-rules",
    "title": "UNCITRAL Arbitration Rules",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Invocation of the UNCITRAL Arbitration Rules establishes a specific procedural framework for dispute resolution, though several critical parameters remain undefined. The governing instrument currently lacks a designated appointing authority, a defined seat of arbitration, and a specified language for proceedings. While the agreement indicates zero arbitrators are specified, the established framework defaults to a default number of arbitrators of one for adjudicating the dispute. Procedurally, a party must provide its response to a notice within thirty days. Furthermore, the initiating party is required to submit a comprehensive statement of claim to commence the substantive phase. The Commission's text provides mechanisms for parties to seek relief; it explicitly allows for a request for interim measures and offers an optional expedited procedure option, which may be adopted by agreement. A significant compliance consideration is the absence of an explicit confidentiality clause, potentially impacting the privacy of hearings and related documents. Ultimately, any award rendered under these rules is considered final and binding upon all parties involved, as stipulated by relevant international conventions and the model law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-intl-commercial-arb-2006",
      "vclt-vienna-convention-law-of-treaties-1969"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "arctic-council-guidelines-resource-extraction",
    "title": "Arctic Resource Development Governance - Arctic Council Soft-Law Forum (Ottawa Declaration 1996), Arctic Offshore Oil and Gas Guidelines (PAME), and the Arctic Economic Council Responsible Resource Development Working Group",
    "domain": "Mining & Natural Resources",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "There is no binding Arctic Council instrument titled 'Guidelines for Responsible Resource Development'. The Arctic Council, established by the 1996 Ottawa Declaration, is a high-level intergovernmental forum that operates by consensus and is non-binding; it does not and cannot implement or enforce its guidelines, assessments, or recommendations - that responsibility rests with individual Arctic States or international bodies. The Arctic Council has issued the Arctic Offshore Oil and Gas Guidelines (released 1997, updated 2002 and 2009) through its Protection of the Arctic Marine Environment (PAME) Working Group; these are recommended practices and strategic actions, not enforceable thresholds. Separately, 'Responsible Resource Development' is the name of a Working Group of the Arctic Economic Council - a distinct body from the intergovernmental Arctic Council - which produces frameworks and reports to support responsible resource exploration and development. Project proponents should therefore treat Arctic Council outputs as soft-law best practice implemented through national regulation, apply the precautionary approach, conduct environmental impact assessment under applicable national law, and ensure full consultation and involvement of Arctic Indigenous communities consistent with the Ottawa Declaration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-26000-social-resp"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "argentina-anmat-md-2026",
    "title": "Argentina ANMAT Medical Device Registration - Disposicion ANMAT 2318/2002 (Mercosur Technical Regulation) and amendments, with Authorized Local Representative requirement",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "ANMAT requires medical devices to be registered before commercialisation in Argentina under Disposicion ANMAT 2318/2002 (the Mercosur technical regulation for registration of medical products) and its amendments. Foreign manufacturers must appoint an Argentine Authorized Representative who holds the registration certificate and assumes legal responsibility. Risk classification follows the Mercosur/IMDRF four-class system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-medical-qms"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "argentina-conae-space-activities-law-1991",
    "title": "Argentina CONAE Space Activities Framework - National Space Agency and Licensing (1991)",
    "domain": "Space & Satellite Law",
    "version": "1991-05",
    "last_updated": "2026-05-09",
    "bluf": "Argentina's national space activities framework, established by Executive Decree 995/1991 and subsequent implementing decrees, created the Comision Nacional de Actividades Espaciales (CONAE) as the sole national agency responsible for planning, executing, and regulating civilian space activities; CONAE operates under the Ministry of Science and Technology and implements Argentina's National Space Plan including the SAOCOM Earth observation satellite series, SABIA-Mar coastal/ocean observation mission, and international cooperation agreements with NASA, ESA, and CNES; the framework implements Argentina's obligations as signatory to the UN Outer Space Treaty (1967), Registration Convention (1976), and Liability Convention (1972).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967-article-i-freedom",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "argentina-ley-migraciones-25871-2004-migraciones",
    "title": "Argentina Ley de Migraciones 25.871 de 2004 - Direccion Nacional de Migraciones Visa and Residency Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Argentina's Ley de Migraciones No. 25.871 (2004), regulated by Decreto 616/2010, establishes one of Latin America's most comprehensive migrant rights frameworks, recognising migration as a human right (Articulo 4). The Direccion Nacional de Migraciones (DNM) under the Ministerio del Interior administers entry, residence, and regularisation. Argentina offers Temporary Residence (Residencia Temporaria) for workers, students, retirees, and investors, and Permanent Residence (Residencia Permanente) after 2 years temporary or by MERCOSUR/UNASUR facilitation. MERCOSUR nationals (Brazil, Chile, Uruguay, Bolivia, Ecuador, Colombia, Peru, Venezuela, Guyana, Suriname) obtain 2-year facilitated residence under the Acuerdo de Residencia MERCOSUR (2002). Argentina introduced a Remote Worker Visa (Nomada Digital) via Disposicion DNM 4334/2022 for freelancers earning from abroad. The Patria Grande Programme has regularised hundreds of thousands of undocumented migrants. Venezuela crisis response: Argentina has issued over 120,000 temporary residencies to Venezuelans under humanitarian grounds. Overstay is an administrative infraction, not a criminal offence (Article 94).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "mercosur_residency",
        "unasur_nationals",
        "refugee_framework",
        "labour_code",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "argentina-pdpa-25326-2000-amendment-2024",
    "title": "Argentina Personal Data Protection Act 25,326/2000 - AAIP (Agencia de Acceso a la Información Pública) Oversight, Sensitive Data, Public Registers, Automated Decisions, Cross-Border Transfer Only to Adequate Countries, Data Owner Rights and 2024 Draft Reform toward GDPR Standards",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes comprehensive data protection obligations for entities processing personal data in Argentina, including requirements for lawful processing, data subject rights, sensitive data handling, and cross-border data transfers only to countries with adequate protection. Key provisions include GDPR-aligned reforms introduced in the 2024 draft amendment, particularly around automated decision-making and data breach notification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ar-pdp-25326-2000",
      "aicpa-soc2-cc-privacy",
      "aicpa-soc2-cc-confidentiality",
      "uk-money-laundering-regulations-2017-amended"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "argentina-senasa-decree-1585-1996-agricultural-sanitation",
    "title": "Argentina SENASA Decree 1585/1996 - Agrifood Health, Quality and Phytosanitary Certification Framework",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Argentina's National Service for Agrifood Health and Quality (SENASA, Servicio Nacional de Sanidad y Calidad Agroalimentaria) was established by Decree 1585/1996. SENASA is Argentina's competent authority for animal health, plant health, food safety, organic product certification and phytosanitary export certification. Argentina is one of the world's largest agricultural exporters; SENASA certifications are essential for export to the EU, USA, Brazil and China. SENASA controls pesticide registrations (CASAFE system), approves GMO events for commercial release (in coordination with CONABIA and the Secretary of Biotech), certifies organic operators for export and manages the national plant and animal disease notification system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-biosecurity-act-2015-daff",
      "brazil-lei-biosseguranca-11105-2005-ctnbio"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "artemis-accords-2020-lunar-governance",
    "title": "Artemis Accords 2020 - Principles for Cooperative Civil Space Exploration",
    "domain": "Space & Satellite Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Artemis Accords are a set of bilateral agreements between the United States (acting through NASA) and individual partner nations, first established on 13 October 2020 with eight founding signatories. As of April 2026, 47 nations have signed. The Accords are not a multilateral treaty but a series of bilateral political commitments, legally grounded in the 1967 Outer Space Treaty (OST), the 1972 Registration Convention, the 1976 Registration Convention, the 1968 Rescue Agreement, and existing COPUOS (UN Committee on the Peaceful Uses of Outer Space) guidelines. Each Accord is a bilateral executive agreement between NASA and the relevant national space agency. The Accords establish ten operative principles: (1) peaceful purposes - all activities must be for peaceful purposes consistent with OST Article IV; (2) transparency - signatories must publicly describe their national space policies and lunar activities; (3) interoperability - systems must be designed for interoperability with international standards; (4) emergency assistance - obligation to provide assistance to personnel in distress consistent with the 1968 Rescue Agreement; (5) registration of space objects - commitment to register all space objects per the 1976 Registration Convention; (6) release of scientific data - timely open release of scientific data from the Moon and beyond; (7) protecting heritage - preserving historically significant sites (Apollo landing sites) from harmful interference; (8) space resources - recognition that extraction of space resources is permitted under the OST, relying on Article II non-appropriation interpretations (resources extracted from the Moon are not a sovereign claim to the Moon itself); (9) deconfliction of activities - operators must notify activities in zones of space operations and negotiate 'safety zones' to prevent harmful interference under OST Article IX; (10) orbital debris and spacecraft disposal - responsible behaviour to limit orbital debris consistent with COPUOS LTS Guidelines. The Accords are significant commercially: they establish a NASA-led framework for Artemis programme partners to return to the Moon under US-led governance norms, positioning competing frameworks (e.g., Russia-China ISLS - International Lunar Research Station) outside the Accords.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "copuos-lts-guidelines-2019-space-sustainability",
      "us-commercial-space-launch-act-1984-amendments"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "artemis-accords-2020-nasa-bilateral",
    "title": "Artemis Accords 2020 - NASA Bilateral Agreements: Peaceful Purposes, Transparency, Interoperability, Emergency Assistance, Registration, Release of Scientific Data, Preservation of Heritage Sites, Space Resources Extraction (Article 10), Deconfliction of Activities and Implementation",
    "domain": "Space & Satellite Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Artemis Accords establish a framework for international cooperation in civil space exploration, requiring participating nations to commit to peaceful purposes, transparency, interoperability, emergency assistance, registration of space objects, timely release of scientific data, preservation of heritage sites, and responsible extraction and utilization of space resources under Article 10. Applies to NASA and its bilateral partners engaged in Artemis Program activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "artemis-accords-2020-lunar-governance",
      "copuos-lts-guidelines-2019-space-sustainability",
      "iss-intergovernmental-agreement-1998"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "as-framework",
    "title": "American Samoa - Territorial Privacy Rights and Federal Data Protection Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "American Samoa is an unincorporated unorganised territory of the United States located in the South Pacific Ocean. Unlike other US territories such as Puerto Rico, Guam, and the US Virgin Islands, American Samoa is unorganised - Congress has not enacted an Organic Act for American Samoa, and the territory is governed largely by its own Constitution and laws administered by the American Samoa Government (ASG). Persons born in American Samoa are US nationals but not automatically US citizens - a unique status among US territories that has been the subject of ongoing legal proceedings. US federal statutes that are of general nationwide applicability generally extend to American Samoa unless specifically excluded. Accordingly, federal privacy statutes including HIPAA (for health data), COPPA (for children's online data), FERPA (for educational records), and the Federal Trade Commission Act (for consumer data protection) are generally understood to apply in American Samoa. The Revised Code of American Samoa provides the territorial legal framework, including provisions applicable to government records, privacy, and electronic transactions. American Samoa does not have a standalone comprehensive personal data protection law equivalent to the GDPR. The American Samoa Government's Department of Commerce and other agencies oversee regulatory compliance within the territory. Organisations processing personal data of individuals in American Samoa must comply with applicable federal privacy statutes, the Revised Code of American Samoa, and constitutional privacy protections, and implement appropriate technical and organisational security measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/as-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "as9100-rev-d",
    "title": "Aerospace Quality Management System (AS9100 Rev D)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The gold standard for quality management in the Aviation, Space, and Defense sectors, extending ISO 9001 with rigorous aerospace-specific safety and risk requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-31000-risk-mgt",
      "cmmc-2-audit",
      "nist-800-171-cui",
      "itar-license-check",
      "faa-part-21-certification"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "as9100-rev-d-qms",
    "title": "AS9100 Rev D (Aviation QMS)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "AS9100 Rev D is the international Quality Management System (QMS) standard for the Aviation, Space, and Defense (AS&D) industry. It incorporates the entire ISO 9001:2015 standard while adding specific requirements for product safety, counterfeit parts prevention, configuration management, and operational risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "dfars-7012-defense-cyber",
      "ear-dual-use-export",
      "itar-compliance-workflow",
      "faa-part-21-certification",
      "icao-safety-annex-19"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "as9110-maintenance-qms",
    "title": "AS9110 (Maintenance QMS)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "AS9110 is the international Quality Management System standard specifically designed for aviation maintenance, repair, and overhaul (MRO) organizations. It builds upon AS9100 requirements by incorporating specific civil aviation regulations (EASA/FAA) and focusing on maintenance-specific factors like human performance and airworthiness.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "as9100-rev-d-qms",
      "easa-part-145-maintenance",
      "iso-9001-quality-mgt",
      "icao-safety-annex-19"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "as9120-distributor-qms",
    "title": "AS9120 (Distributor QMS)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "AS9120 is the international Quality Management System standard for distributors and stockholders in the Aviation, Space, and Defense industry. It focuses on the chain of custody, traceability, and the control of records to ensure 'Certificate of Conformity' (CoC) and airworthiness documentation are maintained throughout the supply chain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "as9100-rev-d-qms",
      "dfars-7012-defense-cyber",
      "ear-dual-use-export",
      "itar-compliance-workflow"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "asa-advertising-codes-uk",
    "title": "ASA (Advertising Codes)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Evaluation against the UK Advertising Codes confirms this marketing communication satisfies all primary regulatory obligations. The content is explicitly identifiable as an advertisement, upholding the CAP Code Section 2 principle that marketing must be recognizable. In accordance with both CAP Code Section 3 and the broadcast-specific BCAP Code Section 3 on misleading advertising, which align with Consumer Protection from Unfair Trading Regulations 2008, the material contains no misleading omissions or claims. All objective assertions are supported by robust documentary substantiation, and pricing information is transparent without any unclear pricing or hidden fees. Adherence to CAP Code Section 4 standards on harm and offence is demonstrated by a harm and offense risk score of 0, comfortably below the maximum harm risk threshold of 0.3. The communication does not target children under 16, respecting special protections outlined in CAP Code Section 5. Since it avoids promoting restricted goods and ensures all promotional marketing terms are accessible as mandated by CAP Code Section 8, the asset meets its social responsibility standard and complies with relevant data protection rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eprivacy-cookie-directive",
      "gdpr-art-21-marketing-optout",
      "ftc-digital-advertising-disclosures",
      "ftc-endorsement-guides",
      "ama-ethical-marketing",
      "prsa-code-of-ethics"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "asce-7-22-minimum-design-loads-buildings",
    "title": "ASCE 7-22 Minimum Design Loads and Associated Criteria for Buildings and Other Structures - Seismic, Wind, Snow and Flood Load Requirements",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires that buildings and other structures be designed to withstand minimum loads due to seismic, wind, snow, and flood hazards, as specified in Section 1.4 of ASCE 7-22. It applies to all buildings and structures, including residential and commercial buildings, bridges, and other infrastructure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "asean-guide-ai-governance-ethics-2020",
    "title": "ASEAN Guide on AI Governance and Ethics (endorsed February 2024) - ASEAN AI Governance Framework: Seven Principles for Responsible AI Development, Consumer Protection, Transparency and Human Oversight",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "This non-binding guide, endorsed at the Fourth ASEAN Digital Ministers Meeting (ADGMIN) which concluded on 2 February 2024, provides a voluntary framework for ASEAN member states and organizations, outlining seven core principles for the ethical governance and deployment of AI systems. It emphasizes transparency, fairness, human-centricity, and accountability to build trust and foster innovation across the region, as detailed in Part 2: ASEAN AI Governance Framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "sg-model-ai-governance-v2",
      "g20-ai-principles-2019"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "asean-model-ai-governance-v2-2020",
    "title": "ASEAN Model AI Governance Framework Second Edition 2020 - Ethical and Accountable AI Deployment in Southeast Asia",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This non-binding framework provides guidance for organizations in ASEAN member states on deploying AI systems ethically and responsibly, focusing on principles of transparency, explainability, fairness, and human-centricity. It recommends implementing internal governance structures and measures, such as conducting risk and impact assessments, as detailed in Part 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-model-ai-governance-v2",
      "oecd-ai-principles",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "assessing-security-privacy-controls",
    "title": "Assessing Security and Privacy Controls in Information Systems and Organizations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-01-01",
    "bluf": "This publication provides a methodology and a set of procedures for conducting assessments of security and privacy controls employed within systems and organizations as part of an effective risk management framework. The assessment procedures are consistent with the security and privacy controls in NIST Special Publication 800-53, Revision 5. Security and privacy control assessments are the principal vehicle used to verify that selected controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting security and privacy requirements. The procedures are customizable and can be tailored to provide organizations with the flexibility to conduct assessments that support their risk management processes and align with their stated risk tolerance. Control assessment results provide organizational officials with evidence of control effectiveness, an indication of the quality of risk management processes, and information about the security and privacy strengths and weaknesses of systems. These findings are used to determine the overall effectiveness of controls and to provide credible inputs to the organization’s risk management process, facilitating a cost-effective approach to managing risk by identifying weaknesses and enabling appropriate risk responses.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "asyncapi-2-6-event-driven-api-specification",
    "title": "AsyncAPI 2.6 - Event-Driven API Specification Standard",
    "domain": "Workflow Automation",
    "version": "2.6.0 (September 2022)",
    "last_updated": "2026-05-09",
    "bluf": "AsyncAPI 2.6.0 (September 2022) is the open specification standard for event-driven APIs and message-driven workflow automation; it defines a machine-readable contract language for asynchronous API channels (Kafka, AMQP, MQTT, WebSocket, HTTP), operations (publish/subscribe), message schemas, bindings, and security schemes - enabling API governance, contract testing, documentation generation, and compliance-grade audit trails for event-driven microservice workflows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cncf-cloudevents-1-0-event-driven-workflow-specification",
      "oasis-xacml-3-0-access-control-policy-language"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "at-bvergg-2018-bundesvergabegesetz",
    "title": "Austria Bundesvergabegesetz 2018 (BVergG 2018)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Bundesvergabegesetz 2018 (BVergG 2018), enacted via the Vergaberechtsreformgesetz 2018 (BGBl. I Nr. 65/2018, published 20 August 2018), is Austria's federal Public Procurement Act, transposing EU Directives 2014/23/EU (concessions), 2014/24/EU (public procurement) and 2014/25/EU (utilities) into Austrian law. The Act is structured in Teile covering general provisions, procurement above EU thresholds, procurement in the special sectors, concession contract awards and review procedures before the Bundesverwaltungsgericht. Foundational provisions cover the purpose of the Act, definitions of contracting authority (oeffentlicher Auftraggeber) and sector contracting entity (Sektorenauftraggeber), thresholds (Schwellenwerte) aligned with EU values, the choice of procurement procedure including offenes Verfahren, nicht offenes Verfahren, Verhandlungsverfahren, wettbewerblicher Dialog and Innovationspartnerschaft, the selection criteria (Eignungspruefung), the mandatory and discretionary exclusion grounds, the application of the Bestbieterprinzip (best-bidder principle, equivalent to MEAT) as the standard award criterion, and the review procedure conducted before the Bundesverwaltungsgericht with interim relief and contract invalidation as available remedies. Implementing details are set out in the Bundesvergabeverordnung.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-public-procurement-construction-directive",
      "uncitral-model-law-public-procurement-2011"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "at-datenschutzgesetz-2018",
    "title": "Austria Data Protection Act 2018 (Datenschutzgesetz - DSG) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Austria's Data Protection Act (Datenschutzgesetz - DSG, Federal Act on the Protection of Natural Persons with Regard to the Processing of Personal Data), as amended by the Datenschutz-Anpassungsgesetz 2018 (Federal Law Gazette I No. 24/2018, published 31 July 2018) to align with the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), is Austria's primary national data protection legislation. The GDPR is directly applicable Austrian law by virtue of Austria's EU membership. Austria's DSG has a constitutional dimension - the fundamental right to data protection (Grundrecht auf Datenschutz) is established in para. 1 of the DSG, which provides that every natural person has the fundamental right to secrecy of personal data concerning that person, in particular with regard to respect for private and family life, insofar as there is a legitimate interest therein; this constitutional-level protection exists alongside and supplements GDPR rights. Enforcement: Datenschutzbehörde (DSB - Austrian Data Protection Authority) is Austria's independent data protection supervisory authority, headed by the Head of the DSB. The DSB is Austria's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Austria is notably home to the non-governmental organisation noyb - European Center for Digital Rights (None of Your Business), founded by privacy activist and lawyer Maximilian Schrems, which has filed thousands of GDPR complaints across the EU, resulting in significant enforcement actions coordinated through the DSB and other DPAs. Key Austrian national provisions: (1) Age of digital consent: Austria has set the age of consent for information society services at 14 years (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 14 require parental or guardian consent; (2) Constitutional fundamental right to data protection - the DSG's para. 1 right is a constitutional-level right enforceable beyond GDPR in Austrian courts; (3) Federal government processing - specific provisions for processing by Austrian federal authorities under Austria's constitutional federal structure; (4) Image processing (Bildverarbeitungsanlagen) - specific Austrian provisions on CCTV and video surveillance systems under the Bildverarbeitungsgesetz (BilschG - Image Processing Act), which provides additional rules beyond GDPR for image processing in public and private spaces; (5) Employment context: Austrian labour law (Arbeitsverfassungsgesetz - ArbVG, Works Constitution Act) provides for works council involvement in employee monitoring decisions; (6) Criminal data - restrictions on private entity processing of criminal conviction data. Fines: GDPR administrative fines apply in Austria - up to EUR 20 million or 4% of global annual turnover for the most serious violations. The DSB has enforced actively and Austria's courts have provided significant GDPR jurisprudence through Constitutional Court (Verfassungsgerichtshof - VfGH) and Administrative Court (Verwaltungsgerichtshof - VwGH) decisions on DSG and GDPR matters.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "at-university-act-2002-section-3-tasks-universities-austria",
    "title": "Universitätsgesetz 2002 (UG) § 3 Aufgaben",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This section outlines the core tasks of Austrian universities, including advancing science and arts, providing education and professional training, fostering young academics, promoting international cooperation, ensuring gender equality, and informing the public.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "at-uwg-bundesgesetz-1984",
    "title": "Austria Bundesgesetz gegen den unlauteren Wettbewerb 1984 (UWG, BGBl. Nr. 448/1984)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Bundesgesetz gegen den unlauteren Wettbewerb (UWG, BGBl. Nr. 448/1984 idgF) is Austria's principal unfair competition statute, transposing EU Directive 2005/29/EC Unfair Commercial Practices (UCPD) for B2C, EU Directive 2006/114/EC misleading and comparative advertising for B2B, and EU Omnibus Directive 2019/2161/EU (transposed by BGBl. I Nr. 110/2022). The Act is organised in three Abschnitte (I. Civil and Criminal Provisions; II. Administrative Provisions; III. Common and Final Provisions). Key sections: § 1 (Generalklausel - general prohibition of geschaftliche Handlungen contrary to den anstandigen Markt-Gepflogenheiten or contrary to the requirements of professional diligence and materially distorting the economic behaviour of the average consumer); § 1a (aggressive Geschaftspraktiken - harassment, coercion, undue influence); § 2 (irrefuhrende Geschaftspraktiken - misleading commercial practices including misleading actions and misleading omissions); § 2a (vergleichende Werbung - comparative advertising under conditions including objective comparison, no denigration, no exploitation of reputation); § 7 (herabsetzende Geschaftspraktiken - business disparagement and untrue factual assertions); § 9 (Missbrauch von Kennzeichen - imitation and passing-off); § 14 (Aktivlegitimation - active legitimation for Mitbewerber, Vereine zur Forderung wirtschaftlicher Interessen, Bundesarbeitskammer BAK, Wirtschaftskammer WKO, Verein fur Konsumenteninformation VKI and Schutzverband gegen unlauteren Wettbewerb); § 15 (Unterlassungs- und Beseitigungsanspruch); § 16 (Schadenersatz); § 16a (Gewinnabschopfung - skimming of profits); § 28a et seq. (criminal sanctions); Anhang (blacklist of 31 commercial practices always considered unfair, transposing the UCPD Annex I).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-uwg-gesetz-gegen-unlauteren-wettbewerb",
      "eu-unfair-commercial-practices-2005-29-2022-revision",
      "fr-code-consommation"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "athens-convention-2002-passenger-ship",
    "title": "Athens Convention 2002 - Passenger Ship Liability for Death, Injury, and Luggage",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Athens Convention relating to the Carriage of Passengers and their Luggage by Sea 1974 as amended by the 2002 Protocol (entered into force 23 April 2014) establishes the global liability regime for passenger ship operators. The 2002 Protocol introduces strict liability for shipping incidents and a mandatory insurance system through IMO's Blue Card scheme. For death and personal injury caused by a shipping incident (Art 3(1)), the carrier is strictly liable up to SDR 250,000 per passenger per voyage; above that limit, the carrier is liable unless it proves no fault or neglect (Art 3(1)(b)). The absolute liability ceiling for shipping incidents is SDR 400,000 per passenger (Art 7(1)). For incidents not constituting a shipping incident, the carrier is liable only on proof of fault or neglect (Art 3(2)), with the same Art 7(1) cap. Cabin luggage liability is SDR 2,250; vehicles and goods in them are SDR 12,700; other luggage is SDR 3,375 (Art 8). Compulsory insurance (Art 4bis) is required up to SDR 250,000 per passenger per voyage, with direct action rights against the insurer. The 2-year limitation period runs from disembarkation or the date when disembarkation should have taken place (Art 16). EU Regulation 392/2009 implemented the Athens 2002 regime across all EU sea voyages, including domestic, from 31 December 2012.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "imo-solas-consolidated-2020",
      "imo-llmc-1976-protocol-1996-limitation-liability",
      "imo-bunker-convention-2001-civil-liability"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "au-acl-competition-consumer-act-2010-schedule2-consumer-guarantees",
    "title": "Australian Consumer Law (ACL) - Consumer Guarantees and Unfair Contract Terms",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Schedule 2 of the Competition and Consumer Act 2010 (Cth) establishes non-excludable consumer guarantees for goods and services, prohibits unfair contract terms in standard-form consumer and small-business contracts, and provides remedies including repair, replacement, refund, and damages without requiring proof of fault.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988-app-3-collection-personal-info"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-ai-ethics-framework-2019",
    "title": "Australia AI Ethics Framework - National Principles for Ethical AI (2019) - Compliance Obligations for Australian AI Developers, Human-Centred AI Requirements, and Voluntary AI Ethics Principles for Australian Organisations",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This node outlines the Australia AI Ethics Framework (2019), focusing on voluntary principles for ethical AI development. Key compliance actions include ensuring human-centered values and transparency in AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "oecd-ai-principles",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-aml-ctf-act-2006",
    "title": "Australia Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act) establishes Australia's primary AML/CTF regulatory framework, requiring reporting entities (financial institutions, gambling services, bullion dealers, and others providing designated services) to: enrol with AUSTRAC; adopt and maintain an AML/CTF programme; conduct customer identification and verification (know your customer); conduct ongoing customer due diligence; report suspicious matters, threshold transactions of AUD 10,000 or more in physical currency, and international funds transfer instructions; and keep records for seven years. The Act is administered by the Australian Transaction Reports and Analysis Centre (AUSTRAC), which has broad enforcement powers including civil penalty orders, infringement notices, and enforceable undertakings. Section 53 requires reporting entities to submit suspicious matter reports (SMRs) to AUSTRAC if there are reasonable grounds to suspect that a customer is not who they claim to be, or that the transaction is connected to a serious offence. Section 55 requires reports of physical currency transactions of AUD 10,000 or more.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "au-aml-ctf-act-2006-part-2-customer-due-diligence",
    "title": "Anti-Money Laundering and Counter-Terrorism Financing Act 2006 - Part 2 Customer Due Diligence",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This regulation outlines the requirements for reporting entities to carry out customer identification, verification, and ongoing due diligence procedures before and during the provision of designated services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-40-recommendations-2023-consolidated",
      "basel-iii-capital"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "au-aml-ctf-act-2006-part-3-reporting-obligations",
    "title": "Anti-Money Laundering and Counter-Terrorism Financing Act 2006 - Part 3 Reporting Obligations",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This part of the Act mandates that reporting entities must report suspicious matters, threshold transactions, and international funds transfer instructions to the AUSTRAC CEO.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-40-recommendations-2023-consolidated",
      "basel-iii-capital"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-amlctf-act-2006-anti-money-laundering-counter-terrorism-financing",
    "title": "Australia Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) - AUSTRAC Designated Services, Reporting and Tranche 2 Expansion",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) is the principal Australian federal statute establishing AML/CTF obligations on reporting entities providing designated services. The Act establishes the Australian Transaction Reports and Analysis Centre (AUSTRAC) as the federal financial intelligence unit and regulator. Reporting entities are persons providing one or more designated services as listed in Section 6 of the Act (financial services, gambling, bullion, remittance, and from 2026 expanded tranche-2 services including legal, accountancy, real estate, dealers in precious metals and stones, trust and company service providers). Section 41 requires reporting of suspicious matters to AUSTRAC where reasonable grounds exist to suspect money laundering, terrorism financing or other serious crime, regardless of whether a transaction actually occurs, with the report submitted within three business days for general suspicion or twenty-four hours for terrorism financing suspicion. Sections 43-44 require reporting of threshold transactions at or above AUD 10,000 or equivalent. Sections 45-46 require reporting of international funds transfer instructions (IFTI) regardless of value. Part 1A and Part 7 require customer identification (KYC) before or in the course of providing a designated service, with ongoing customer due diligence under Sections 30-36. Part 8 requires reporting entities to develop, maintain and implement a written AML/CTF program (Part A risk assessment under Sections 26C-26E and Part B procedures under Section 26F). Part 2 covers correspondent banking relationships. Part 6A introduced by the AML/CTF Amendment Act 2024 (commenced 31 March 2026 for tranche 2 entities) extends obligations to virtual asset service providers (VASPs) and to the previously unregulated tranche 2 professions. Civil penalties for failure to comply reach AUD 22.2 million per contravention for a body corporate (calculated using the 100,000 penalty unit benchmark under Section 4AA of the Crimes Act 1914 as adjusted from 1 July 2025). Criminal penalties for false or misleading information under Section 136 include imprisonment up to ten years. The AML/CTF Act operates in conjunction with the Criminal Code Act 1995 (Cth) Division 400 money-laundering offences and the Charter of the United Nations Act 1945 sanctions regime administered by the Department of Foreign Affairs and Trade.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "designated_services_anchor",
        "suspicious_matter_reporting_anchor",
        "threshold_and_ifti_reporting_anchor",
        "kyc_and_program_anchor",
        "tranche_2_expansion_anchor",
        "industry_mapping",
        "enforcement_anchors",
        "fatf_alignment_anchor"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-40-recommendations-2023-consolidated",
      "ca-pcmltfa-aml-2000",
      "eu-aml-regulation-2024-1624"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "au-apra-cps-234-information-security-banking-insurance-superannuation",
    "title": "AU APRA CPS 234 - Information Security for APRA-Regulated Banking, Insurance, and Superannuation Entities",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2019-07-01",
    "bluf": "APRA Prudential Standard CPS 234 requires all APRA-regulated entities (banks, insurers, superannuation funds) to implement an information security capability commensurate with threats, classify and protect information assets, test controls through penetration testing and vulnerability assessments, and notify APRA of material information security incidents within 72 hours.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-apra-prudential-standard-cps-220",
      "au-privacy-act-1988-app-3-collection-personal-info"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-apra-insurance-act-1973-general-insurance",
    "title": "Insurance Act 1973 (Cth) - APRA Prudential Regulation of General Insurers (Australia)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "The Insurance Act 1973 (Cth) is the Commonwealth statute under which the Australian Prudential Regulation Authority (APRA) prudentially regulates general insurance in Australia. A body corporate or Lloyd's underwriter must not carry on insurance business in Australia unless authorised by APRA, and a person other than a body corporate is prohibited from carrying on such business. Authorisation is obtained from APRA and may be subject to conditions. A general insurer must hold sufficient assets to meet its liabilities, must comply with the prudential standards that APRA determines, and must have an appointed auditor and an appointed actuary. Directors and senior managers must meet fit and proper requirements, and APRA may remove a person who is disqualified or unsuitable. APRA may give directions, investigate a general insurer, and exercise statutory powers to protect policyholders, and contraventions including carrying on insurance business without authorisation are offences. The Act gives effect to a prudential framework comparable to international insurance supervision standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "au_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-apra-prudential-standard-cps-220",
      "au-apra-prudential-standard-gps-310-audit-2023",
      "eu-solvency-ii-directive-2009-138-ec-eiopa"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "au-apra-prudential-standard-aps-110-adi",
    "title": "Australia APRA Prudential Standard APS 110 - Capital Adequacy for Authorised Deposit-taking Institutions",
    "domain": "Banking & Global Finance",
    "version": "2025.1.0",
    "last_updated": "2025-01-01",
    "bluf": "APS 110 sets minimum capital ratios for Australian ADIs (banks, credit unions, building societies): CET1 ≥4.5%, Tier 1 ≥6%, Total Capital ≥8%, plus Capital Conservation Buffer 2.5% (effectively 10.5% Total); D-SIBs (ANZ, CBA, NAB, Westpac, Macquarie) carry +1% HLA surcharge; Basel III output floor of 72.5% applies from January 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-crr3-capital-requirements-regulation-2024-1623",
      "eu-brrd-bank-recovery-resolution-directive-2014-59"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-apra-prudential-standard-cps-220",
    "title": "Australia APRA Prudential Standard CPS 220 - Risk Management Framework",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "APRA Prudential Standard CPS 220 Risk Management (updated January 2023) requires all APRA-regulated entities - authorised deposit-taking institutions (ADIs), general insurers, life insurers, private health insurers, and RSE licensees (superannuation) - to maintain a Risk Management Framework (RMF) commensurate with the nature, scale, and complexity of their operations. The RMF must include a Board-approved Risk Appetite Statement (RAS), a three-lines-of-defence model, dedicated risk management function with direct Board reporting access, annual internal audit of the RMF, at least annual stress testing, and documented business continuity and crisis management plans. APRA supervises compliance through annual reporting, supervisory dialogue, and prudential reviews.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-brrd-bank-recovery-resolution-directive-2014-59",
      "eu-crr3-capital-requirements-regulation-2024-1623"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-apra-prudential-standard-gps-310-audit-2023",
    "title": "Prudential Standard GPS 310 Audit and Related Matters",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This standard requires Australian general insurers and Level 2 insurance groups to establish and maintain robust internal audit, external audit, and actuarial review functions, as mandated by the Board and its Audit Committee (BAC) under Clause 48. It sets out minimum requirements for the scope, independence, and reporting of these functions to ensure effective risk management and financial oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "au-aqf-australian-qualifications-framework-higher-education-standards",
    "title": "Australia AQF and Higher Education Standards Framework - Quality and Compliance Obligations",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Australian Qualifications Framework (AQF, 2013) and the Higher Education Standards Framework (Threshold Standards) 2021 require registered higher education providers (HEPs) to meet mandatory standards covering student admission, learning outcomes, quality assurance, and institutional governance. TEQSA (Tertiary Education Quality and Standards Agency) registers and regulates HEPs under the TEQSA Act 2011.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988-app-3-collection-personal-info"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-asd-essential-eight-2023",
    "title": "Australian Signals Directorate Essential Eight Maturity Model 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The ASD Essential Eight Maturity Model updated November 2023 defines eight prioritised cybersecurity mitigation strategies across four maturity levels - application control, patch applications, macro settings, application hardening, restrict admin privileges, patch operating systems, multi-factor authentication, and regular backups - with Maturity Level 3 mandated for Australian Commonwealth entities handling classified information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/au-asd-essential-eight-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-asic-act-2001",
    "title": "Australia Securities and Investments Commission Act 2001 - ASIC Powers Consumer Protection and Financial Services Conduct",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Australian Securities and Investments Commission Act 2001 establishes ASIC as Australia's corporate, markets, and financial services regulator, sets out ASIC functions and powers including investigation, examination, compulsory information gathering, civil and criminal enforcement, and surveillance, provides consumer protection rules for financial services including prohibitions on misleading or deceptive conduct, unconscionable conduct, and unfair contract terms, and operates alongside the Corporations Act 2001 to regulate Australian companies, financial markets, and financial services intermediaries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-corporations-act-2001-chapter-2d-directors-duties"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "au-asic-corporations-act-2001-financial-services-licence-obligations",
    "title": "Australia Corporations Act 2001 - AFSL Holder Obligations Under Chapter 7 Financial Services",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Corporations Act 2001 (Cth) Chapter 7, administered by ASIC, requires holders of an Australian Financial Services Licence (AFSL) to comply with general obligations including acting efficiently, honestly and fairly, maintaining competence, ensuring representatives are adequately trained, and maintaining dispute resolution systems. Failure to comply is a civil penalty provision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988-app-3-collection-personal-info"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-austrac-aml-ctf-act-2006",
    "title": "Australia AML/CTF Act 2006: Anti-Money Laundering and Counter-Terrorism Financing Act",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The Australian Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act) establishes the AUSTRAC-administered regulatory framework for anti-money laundering and counter-terrorism financing in Australia. The Act applies to \"reporting entities\" providing designated services including banking, gambling, remittance, bullion, and digital currency exchange. Obligations include enrolment with AUSTRAC, customer identification procedures, ongoing customer due diligence, threshold transaction reporting (10,000 AUD or more cash), suspicious matter reporting (SMR), international funds transfer instruction reporting, and maintaining an AML/CTF programme. Penalties include civil money penalties up to millions of AUD and criminal offences. Tranche 2 amendments (effective 2026-2027) extend coverage to lawyers accountants real estate agents and trust and company service providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "austrac",
        "fatf",
        "aml_ctf_rules",
        "fintrac_canada",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "au-australian-education-act-2013",
    "title": "Australian Education Act 2013: Federal Schools Funding Framework, Grants to States and Territories, Recurrent Funding Loadings, Approving Authorities, and Compliance and Enforcement",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Australian Education Act 2013, Act No. 67 of 2013, is the principal Commonwealth statute establishing the federal funding framework for government and non-government schools in Australia and is administered by the Department of Education. Part 1 contains the preliminary provisions including the definitions, interpretation, objects of the Act, and the provision binding the Crown. Part 2 governs grants of financial assistance to the States and Territories, including conditions requiring implementation of national policy initiatives and timing and amounts determined by the Minister. Australian Education Act 2013, section 21 provides for financial assistance for schools. Part 3 governs recurrent funding based on student numbers and loadings: the loadings include disability support, Aboriginal and Torres Strait Islander students, socio-educational disadvantage, English language proficiency, and location and size adjustments. Part 5 governs capital and other funding including capital allocations for infrastructure and special circumstances funding. Part 6 governs approving authorities, including the processes for approving government and non-government school authorities and block grant authority arrangements. Part 8 governs compliance and enforcement, including actions for non-compliance and recoverable payment provisions. Part 9 contains miscellaneous provisions including application procedures, review mechanisms through the Administrative Review Tribunal, and annual reporting requirements. The Act is the controlling Commonwealth instrument for federal schools funding compliance in Australia.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "au-autonomous-sanctions-act-2011",
    "title": "Australia Autonomous Sanctions Act 2011: Regulations to Apply Sanctions, Extraterritorial Effect, Injunctions, and Offences for Contravention or False Information",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Australian Autonomous Sanctions Act 2011, Act No. 38 of 2011, is the principal Commonwealth statute authorising Australian autonomous sanctions imposed independently of obligations under United Nations Security Council resolutions. Part 1 sets out the preliminary matters: section 1 the short title, section 2 commencement, section 3 the objects of the Act, section 4 definitions, section 5 specifying a Commonwealth entity as designated, section 6 specifying a provision as a sanction law, section 7 extension to external Territories, section 8 the Act binding the Crown, and section 9 the relationship with other laws. Part 2 establishes the regulation-making power for sanctions: section 10 enables the Governor-General to make regulations applying sanctions, section 10A provides for proscription relating to past circumstances, section 11 confirms that regulations may have extraterritorial effect, section 12 addresses effect on earlier Commonwealth Acts, section 13 provides that later Acts do not override Part 2, section 14 enables injunctions, and section 15 invalidates non-compliant authorisations. Part 3 sets the offences relating to sanctions: section 16 makes it an offence to contravene a sanction law, and section 17 makes it an offence to provide false or misleading information. Part 4 covers information sharing and disclosure powers in sections 18 through 27. Part 5 contains miscellaneous provisions including section 28 on regulations. The Act, together with the Autonomous Sanctions Regulations 2011 made under section 10, is the controlling Commonwealth instrument for the imposition, administration and enforcement of Australian autonomous sanctions and operates alongside the Charter of the United Nations Act 1945 for UN Security Council sanctions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "au-banking-act-1959",
    "title": "Australia Banking Act 1959 - Authorisation Supervision and Resolution of Authorised Deposit-Taking Institutions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Banking Act 1959 authorises the Australian Prudential Regulation Authority to grant and revoke authorisation to carry on banking business in Australia, requires authorised deposit-taking institutions to comply with prudential standards on capital, liquidity, governance, and risk management, gives APRA powers of investigation, direction, and statutory management over a failing institution, supports the Financial Claims Scheme protecting protected accounts up to the statutory cap, requires depositors to receive priority in winding up an Australian incorporated authorised deposit-taking institution, and authorises civil and criminal penalties for breach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-aml-ctf-act-2006-part-2-customer-due-diligence"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "au-biosecurity-act-2015",
    "title": "AU Biosecurity Act 2015",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The AU Biosecurity Act 2015 (Cth) is the Commonwealth law governing biosecurity in Australia replacing the Quarantine Act 1908. It provides for management of risks of disease and pest incursions at the border in postal and air cargo from international vessels and aircraft and during outbreak response. The Act regulates importation of goods conveyances and ballast water managed through Biosecurity Import Risk Analyses (BIRA) and conditions imposed by the Director of Biosecurity. Human biosecurity provisions (Chapter 2) provide for declaration of human health risks including listed human diseases. The Biosecurity Emergency response framework was activated during COVID-19 (March 2020-2022).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "au-broadcasting-services-act-1992",
    "title": "Australia Broadcasting Services Act 1992: Categories of Broadcasting Services, Planning of the Broadcasting Services Bands, Commercial Television and Radio Licences, Control Rules, and Community Broadcasting",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Australian Broadcasting Services Act 1992, Act No. 110 of 1992, is the principal Commonwealth statute governing the regulation of broadcasting services in Australia and is administered by the Australian Communications and Media Authority (ACMA). Broadcasting Services Act 1992, Part 1 contains the preliminary provisions including the objects of the Act and the regulatory policy framework. Broadcasting Services Act 1992, Part 2 sets the categories of broadcasting services including national, commercial, community, subscription, narrowcasting, and international broadcasting services. Broadcasting Services Act 1992, Part 3 governs the planning of the broadcasting services bands including frequency allocation planning, licence area designation, and capacity reservations for different broadcaster types. Broadcasting Services Act 1992, Part 4 governs commercial television broadcasting licences and Broadcasting Services Act 1992, Part 5 governs commercial radio broadcasting licences, including allocation systems, services authorised, licence conditions, and duration and renewal processes. Broadcasting Services Act 1992, Part 5 also covers the control of commercial broadcasting licences with ownership limits, directorship restrictions, media diversity rules, and cross-media disclosure requirements. Broadcasting Services Act 1992, Part 6 governs community broadcasting licences including allocation and condition frameworks. Schedule 5 covers online services and Schedule 7 covers content services. The Act establishes a regulatory framework balancing diverse and comprehensive broadcasting with efficient spectrum use and diverse ownership structures, with the ACMA administering enforcement and allocation responsibilities throughout the provisions. The Act is the controlling Commonwealth instrument for broadcasting regulation in Australia.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "au-commonwealth-procurement-rules-pgpa-act-2013-austender",
    "title": "Australia Commonwealth Procurement Rules (CPRs) under the Public Governance, Performance and Accountability Act 2013 + AusTender",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Commonwealth Procurement Rules (CPRs) are the principal procurement framework for Australian federal government entities, issued by the Minister for Finance under section 105B of the Public Governance, Performance and Accountability Act 2013 (PGPA Act). The CPRs are the binding rules with which non-corporate Commonwealth entities and prescribed corporate Commonwealth entities must comply when undertaking procurement; the current iteration includes substantive 2024 and 2025 updates reflecting reforms on supplier code of conduct, environmentally sustainable procurement, sovereign capability considerations, and the strengthened SME and First Nations procurement targets. The CPRs are organised in Divisions including Division 1 (Application of the CPRs), Division 2 (Procurement Principles - achieving value for money as the core principle), Division 3 (Procurement Process - including procurement methods of open tender, prequalified tender, limited tender, with mandatory open tender for procurements at or above the relevant procurement thresholds), Division 4 (Specific Procurement Requirements - including requirements for fairness and ethics, accountability and transparency, and reporting on AusTender), and additional Divisions on Australian Industry Capability and Indigenous Procurement Policy. The procurement thresholds are AUD 80,000 for non-corporate Commonwealth entities (other than for construction), AUD 7.5 million for construction, and AUD 400,000 for prescribed corporate Commonwealth entities (other than for construction). AusTender at tenders.gov.au is the mandatory central reporting and notification platform operated by the Department of Finance; all open tender opportunities, contract awards above AUD 10,000, and amendments must be published on AusTender. The framework intersects the Indigenous Procurement Policy (IPP) with the mandatory 3% First Nations supplier participation target, the Commonwealth SME Participation in Procurement Policy with the 35% SME target for contracts up to AUD 20 million, the Australian Industry Participation National Framework for major projects, and the strategic sourcing arrangements through Whole-of-Australian-Government coordinated procurement. The CPRs operate in parallel with the AU Defence Acquisition Procurement Strategy 2024 and the Defence Procurement Policy Manual for Defence-specific procurements, and with sectoral procurement frameworks for Department of Health, Department of Education, and other portfolio entities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "au-modern-slavery-act-2018",
      "au-irap-information-security-registered-assessors-program",
      "iso-iec-42001-2023-ai-management-system"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "au-competition-consumer-act-2010-acl-consumer-guarantees-misleading-conduct",
    "title": "AU Competition and Consumer Act 2010 - Australian Consumer Law Consumer Guarantees and Misleading Conduct",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "The Australian Consumer Law (ACL), Schedule 2 of the Competition and Consumer Act 2010 (CCA), provides consumer protection law applying uniformly across Australia. Consumer guarantees under the ACL entitle consumers to remedies when goods are not of acceptable quality, not fit for purpose, or not as described. Businesses are prohibited from engaging in misleading or deceptive conduct (Section 18), making false representations about goods or services (Section 29), and engaging in unconscionable conduct (Section 20-21). ACCC and state fair trading agencies enforce the ACL with penalties up to AUD 50 million per breach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-competition-consumer-act-2010-cca"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-competition-consumer-act-2010-part-iv-anti-competitive",
    "title": "Competition and Consumer Act 2010",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This legislation prohibits anti-competitive practices including cartel conduct, misuse of market power, anti-competitive mergers, and other arrangements that substantially lessen competition in the Australian market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "au-competition-consumer-act-2010-section-46-misuse-market-power",
    "title": "AU Competition and Consumer Act 2010 - Section 46 Misuse of Market Power and Concerted Practices",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2017-11-06",
    "bluf": "Section 46 of Australia's Competition and Consumer Act 2010 (as amended by the Competition and Consumer Amendment Act 2017) prohibits corporations with substantial market power from engaging in conduct that has the purpose, effect, or likely effect of substantially lessening competition, including predatory pricing, margin squeeze, refusal to deal, and exclusive dealing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-competition-consumer-act-2010-cca",
      "au-privacy-act-1988-app-3-collection-personal-info"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-copyright-act-1968-section-36-infringement-copyright-original-works",
    "title": "Copyright Act 1968 - Section 36 Infringement by doing acts comprised in copyright",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must not, without the license of the copyright owner, perform or authorize the performance in Australia of any act exclusively reserved for the copyright owner of a literary, dramatic, musical, or artistic work.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "au-corporations-act-2001-chapter-2d-directors-duties",
    "title": "Corporations Act 2001 - Federal Register of Legislation Version Management",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This node outlines the procedural requirements for managing, filtering, and accessing different versions and amendments of the Corporations Act 2001 as presented in the Federal Register of Legislation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "au-corporations-act-2001-directors-duties",
    "title": "Australia Corporations Act 2001 - Directors' Duties (Part 2D.1)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Part 2D.1 of the Corporations Act 2001 (Cth) prescribes the fundamental duties of officers and directors of corporations, applicable to directors, company secretaries, and other officers who participate in management decisions. Section 180 imposes a duty of care and diligence requiring directors to exercise powers and discharge duties with the degree of care and diligence that a reasonable person would exercise if they were a director in the company's circumstances. The business judgment rule in Section 180(2) provides a safe harbour for directors who make business judgments in good faith and in the rational belief that the judgment is in the best interests of the corporation. Section 181 requires directors to act in good faith in the best interests of the corporation and for a proper purpose. Section 182 prohibits improper use of a director's position to gain a personal advantage or cause detriment to the corporation. Section 183 prohibits improper use of information obtained as an officer to gain an advantage or cause detriment. Serious contraventions of these duties may also constitute criminal offences under Section 184.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "iso-22301-bcm-2019"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "au-corporations-act-2001-part-2d1-officers-duties",
    "title": "Corporations Act 2001 - Part 2D.1 Duties and powers of officers of corporations",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The provided source text is a generic homepage for the Federal Register of Legislation and contains no extractable compliance obligations from the Corporations Act 2001 Part 2D.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "au-crimes-act-1914",
    "title": "Australia Crimes Act 1914 - Federal Criminal Law Code",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Crimes Act 1914 (Commonwealth, Act No. 12 of 1914, originally enacted 29 October 1914 with extensive amendment since) is the foundational federal criminal statute of Australia, jointly administered by the Attorney-General's Department and the Department of Home Affairs. The Act establishes the general principles of federal criminal liability, the rules of investigation and arrest, the constitutional aspects of state offences with a federal nexus, and certain substantive federal offences not covered by the Criminal Code Act 1995. Part I (Preliminary) establishes foundational definitions and operational scope. Part IAA (Search, Information Gathering, Arrest and Related Powers) confers core federal law-enforcement powers including search warrants (Division 2), conveyance stop-and-search (Division 3), terrorism powers (Division 3A), airport identity requirements (Division 3B), and arrest procedures (Division 4). Part IAAA (Delayed Notification Search Warrants) governs warrants with deferred notification subject to Commonwealth Ombudsman oversight. Part IAAB (Monitoring of Compliance) addresses monitoring of Part 5.3 supervisory orders. Part IAB (Controlled Operations) authorises undercover operations with protection from criminal responsibility for participants. Part IABA (Integrity Testing) establishes the framework for testing official conduct. Subsequent Parts cover specific offences and procedural rules retained from the pre-Code era. AI-enabled investigative tools, data-collection systems, and digital evidence handling by Commonwealth agencies must operate within the Crimes Act 1914 procedural framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "au-criminal-code-act-1995-section-474-25a-using-carriage-service-procure-child",
    "title": "Australia Criminal Code Act 1995 Section 474.25A - Using a Carriage Service to Procure a Child",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 474.25A of the Criminal Code Act 1995 (Cth) makes it an offence to use a carriage service to engage in sexual activity with a person who is under 16 years of age. The offence requires (1) the person uses a carriage service; (2) the person engages in sexual activity (which includes asking the other person to engage in sexual activity, watching the other person engage in sexual activity, or causing the other person to engage in sexual activity) with another person; (3) the other person is under 16 years of age; and (4) the person is at least 18 years of age. Penalty: 15 years imprisonment. The offence captures the broad range of online sexual exploitation - including livestreaming, video calls, sexual messages, requests for explicit imagery. Section 474.25B further criminalises using a carriage service to procure a child for sexual activity. Section 474.27 (the parent online grooming offence) carries up to 12 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "sexual_activity_extended_definition_subsection_2",
        "carriage_service_definition_section_473_1",
        "penalty_15_years_imprisonment",
        "absolute_liability_for_age_section_474_29_a",
        "mistake_of_age_defence_section_474_29_b",
        "extended_geographical_jurisdiction_category_b_section_474_29",
        "interaction_with_section_474_25b_procuring_child",
        "interaction_with_section_474_27_grooming",
        "interaction_with_section_474_22_using_carriage_service_for_csam"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-online-safety-act-2021"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "au-critical-infrastructure-act-2018-part-2a-risk-management",
    "title": "Security of Critical Infrastructure Act 2018 - Part 2A - Critical Infrastructure Risk Management Program",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The provided text does not contain the specific compliance obligations for Part 2A, which pertains to risk management programs for critical infrastructure assets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-customs-act-1901",
    "title": "Australia Customs Act 1901: Customs Control of Goods, Importation, Exportation, Prohibited Imports and Exports, and Customs Penal Provisions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Australian Customs Act 1901, Act No. 6 of 1901, is the foundational Commonwealth statute governing the entry, examination, control, importation and exportation of goods across the Australian customs frontier and is administered by the Australian Border Force. Part I sets the short title, commencement, definitions and application provisions. Part II covers administration including the appointment of officials and delegation of powers. Part III establishes customs control of goods, including goods on ships and aircraft subject to customs control under section 31. Part IV governs the importation of goods through divisions covering importation preliminaries, prohibited imports under section 50, boarding of ships and aircraft, cargo reporting, entry and unshipment, examination of goods, and detention of goods in the public interest. Part V governs licensed warehouses for imported goods. Part VI governs the exportation of goods through divisions covering prohibited exports under section 112, entry and clearance procedures, and exportation under specific trade agreements. Part IVA provides for licensed depots. Parts VAAA, VA and VAA cover cargo terminals and special provisions for beverages and excise-equivalent goods. Part VB requires information about departing persons. The penal provisions of the Act, including offences relating to smuggling and unlawful importation or exportation, are enforced through prosecutions under sections including section 233. The Act is the controlling Commonwealth instrument for trade compliance at the Australian border.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "au-cyber-security-act-2024",
    "title": "Australia Cyber Security Act 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Australia's Cyber Security Act 2024, which received Royal Assent on November 29, 2024, mandates ransomware payment reporting to ASD within 72 hours for businesses with annual turnover of AUD 3 million or more, establishes minimum cybersecurity standards for smart devices, creates a Cyber Incident Review Board for post-incident analysis, and strengthens government assistance powers for responding to significant cyber incidents affecting Australian organisations and critical infrastructure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/au-cyber-security-act-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-soci-act-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "au-defence-export-controls-act-2012-military-dual-use-goods-permits",
    "title": "AU Defence Export Controls - Defence Trade Controls Act 2012 and Defence and Strategic Goods List",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "The Australian Defence Export Controls (DEC) regime under the Defence Trade Controls Act 2012 regulates the export, supply, brokering, and publication of goods and technology listed on the Defence and Strategic Goods List (DSGL). DSGL Part 1 covers military goods (equivalent to ITAR/USML) and Part 2 covers dual-use goods (equivalent to EAR/CCL). All exporters of DSGL-controlled items must register with Defence Export Controls and obtain permits, licences, or authorisations before export. Penalties include up to 10 years imprisonment for serious violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-far-itar-export-controls-defense-articles-technical-data"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-digital-id-act-2024",
    "title": "Australia Digital ID Act 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Australia's Digital ID Act 2024, which received Royal Assent on May 30, 2024, establishes a voluntary economy-wide digital identity accreditation framework administered by the Australian Competition and Consumer Commission, creates the Australian Government Digital ID System for federal services, prohibits identity providers from collecting or using biometric and identity data beyond the specific transaction requiring verification, and enforces strict data minimisation obligations to ensure individuals' digital identities cannot be tracked or profiled across services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/au-digital-id-act-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "au-digital-id-act-2024-agdis-trust-framework",
    "title": "Australia Digital ID Act 2024 (Cth) and Australian Government Digital ID System Trust Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-06-21",
    "bluf": "The Digital ID Act 2024 (Cth) is Australia's primary digital identity statute, replacing the prior administrative Trusted Digital Identity Framework (TDIF) with a binding legislative regime. The Act establishes the Australian Government Digital ID System (AGDIS) under the oversight of the Digital ID Regulator and applies a four-pillar trust framework covering accreditation of identity service providers, privacy safeguards, system governance, and enforcement. Accreditation is governed by Chapter 2 (Sections 13 to 31) and is required for entities seeking to operate as an Identity Service Provider, Credential Service Provider, Identity Exchange, or Attribute Service Provider within the AGDIS. Use of a digital ID by individuals is voluntary under Section 74, and the Crown is bound by the Act under Section 5.\n\nThe AGDIS framework is established by Chapter 4 (Sections 57 to 88) and requires the Digital ID Regulator under Section 58 to oversee and maintain the system. Privacy protections in Chapter 3 (Sections 32 to 56) include restrictions on biometric information handling, prohibitions on profiling using digital identity attributes, and specific consent requirements for restricted attributes such as biometric and health data. Enforcement is set out in Chapter 9, including civil penalty provisions, injunctions, and infringement notices. The Act commenced in phased tranches in 2024 to 2025 with full AGDIS operational scope expanding to private-sector relying parties under a staged onboarding model.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nist-sp-800-63-4-2025-digital-identity-guidelines",
      "au-privacy-act-1988",
      "w3c-verifiable-credentials-data-model-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "au-disability-standards-education-2005",
    "title": "Disability Standards for Education 2005",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Education providers must comply with standards to eliminate discrimination against students with disabilities across enrolment, participation, curriculum development, support services, and the prevention of harassment and victimisation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-rehabilitation-act-section-504"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "au-diverted-profits-tax-2017",
    "title": "Australian Diverted Profits Tax 2017 - 40% Tax on Artificially Diverted Australian Profits",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Australian entities with global turnover above AUD 1 billion that enter into schemes to divert profits from Australia may face a 40% Diverted Profits Tax on the diverted amount. The ATO issues a DPT assessment and the entity must pay within 21 days, with a 12-month review period before appeal rights arise. DPT applies where the scheme results in a tax benefit and the dominant purpose is to reduce Australian tax.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "income_tax_assessment_act",
        "part_iva",
        "australian_transfer_pricing",
        "uk_dpt",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-transfer-pricing-laws-amendment-2012",
      "oecd-beps-actions-8-10-transfer-pricing-value-creation",
      "oecd-pillar-two-global-minimum-tax-15-percent"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "au-environmental-protection-biodiversity-conservation-act-1999-project-approvals",
    "title": "AU EPBC Act 1999 - Environmental Impact Assessment and Federal Approval for Matters of National Environmental Significance",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2023-01-01",
    "bluf": "Australia's Environment Protection and Biodiversity Conservation Act 1999 (EPBC Act) requires referral and federal approval for any action likely to have a significant impact on Matters of National Environmental Significance (MNES) including World Heritage properties, nationally threatened species, Ramsar wetlands, and nuclear actions, with penalties up to AUD 825,000 per day for unlawful actions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-competition-consumer-act-2010-cca",
      "au-privacy-act-1988-app-3-collection-personal-info"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-export-control-act-2020-daff",
    "title": "Australia Export Control Act 2020 and Implementing Rules",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "The Australia Export Control Act 2020 modernised the Australian export-control framework for prescribed agricultural goods, replacing 17 separate legacy statutes (including the Export Control Act 1982). The Act establishes a single overarching framework for export controls on meat, dairy, eggs, fish, plants and plant products, organics, and live animals, with goods-specific implementing rules made under the relevant section. Exporters must hold an export licence per the relevant part; goods must be sourced from registered establishments per the relevant part; export documentation including phytosanitary or health certificates is issued by Department officers per the relevant part. Compliance is enforced through audits, sampling, suspension or revocation of licences/registrations, and prohibitions under the relevant part. The Act administered by the Department of Agriculture, Fisheries and Forestry (DAFF, formerly DAWE) is essential infrastructure for the AUD 50+ billion Australian agricultural export economy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "woah_terrestrial",
        "ippc_ispm_7",
        "codex_cxc_1",
        "biosecurity_act",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "woah-terrestrial-animal-health-code",
      "ippc-ispm-7-phytosanitary-certification-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "au-fair-work-act-2009",
    "title": "Fair Work Act 2009 - National Employment Standards, Enterprise Agreements and Unfair Dismissal Provisions",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Fair Work Act 2009 establishes Australia's national workplace relations system, mandating 11 National Employment Standards (NES) as minimum conditions for all national system employees (Part 2-2), regulating the bargaining and approval process for enterprise agreements (Part 2-4), and providing protections against unfair dismissal for eligible employees (Part 3-2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "iso-45001-work-safety",
      "au-privacy-act-1988"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "au-fair-work-act-2009-enterprise-bargaining-unfair-dismissal",
    "title": "Australia Fair Work Act 2009 - Enterprise Bargaining and Unfair Dismissal Framework",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Fair Work Act 2009 (Cth) governs employment relations in Australia, including enterprise bargaining (Part 2-4), unfair dismissal remedies (Part 3-2), general protections (Part 3-1), and the National Employment Standards (NES, Part 2-2). Employees with at least 6 months continuous employment (12 months for small business) may apply to the Fair Work Commission for unfair dismissal remedy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988-app-3-collection-personal-info"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-fair-work-act-2009-part-3-1-general-protections",
    "title": "Child Support (Registration and Collection) Act 1988 - Part III Registration of maintenance liabilities",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that payers and payees of registrable maintenance liabilities notify the Child Support Registrar of the liability's creation, variation, or cessation, and outlines the process for application-based registration and variation of entries in the Child Support Register.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "au-food-standards-australia-new-zealand-fsanz-code-standard-3-2-2",
    "title": "AU Food Standards Australia New Zealand - FSANZ Code Standard 3.2.2 Food Safety Practices and General Requirements",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2023-12-01",
    "bluf": "FSANZ Food Safety Standard 3.2.2 requires Australian and New Zealand food businesses to implement food safety practices covering food temperature control, hygiene, sanitation, pest control, skills and knowledge of food handlers, and health and hygiene requirements, with additional food safety program requirements for high-risk businesses under Standard 3.2.2A.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-competition-consumer-act-2010-cca",
      "au-privacy-act-1988-app-3-collection-personal-info"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-gst-act-1999-a-new-tax-system-goods-services-tax",
    "title": "AU GST Act 1999 - A New Tax System (Goods and Services Tax) Compliance for Digital Services and Imported Low-Value Goods",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2018-07-01",
    "bluf": "Australia's GST Act 1999 applies 10% GST to digital services supplied by non-resident suppliers to Australian consumers with annual turnover above AUD 75,000, with offshore suppliers registering under a simplified registration system and non-resident marketplaces liable for goods under AUD 1,000 sold to Australian consumers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-competition-consumer-act-2010-cca",
      "au-privacy-act-1988-app-3-collection-personal-info"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-higher-education-support-act-2003-hesa",
    "title": "Higher Education Support Act 2003",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This Act outlines the framework for Commonwealth funding for higher education providers, establishing quality and accountability requirements, and regulating student fees and support.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-higher-education-research-act-2017-ofs-conditions-registration"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-income-tax-assessment-act-1997",
    "title": "Australia Income Tax Assessment Act 1997 - Assessable Income Deductions and Tax Liability",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Income Tax Assessment Act 1997 sets out the core operative rules for Australian income tax including the assessability of ordinary income and statutory income, general and specific deductions, capital allowances and capital works deductions, capital gains tax through the CGT events framework, dividend imputation through the franking system, consolidated group rules, transfer pricing arm length conditions, controlled foreign company and foreign income rules, withholding obligations for residents and non-residents, and integrity rules including the general anti-avoidance provisions in conjunction with the Income Tax Assessment Act 1936.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-corporations-act-2001-chapter-2d-directors-duties"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "au-insurance-act-1973",
    "title": "Australia Insurance Act 1973 - Authorisation Supervision and Capital of General Insurers",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Insurance Act 1973 requires entities carrying on general insurance business in Australia to be authorised by the Australian Prudential Regulation Authority unless an exception applies, authorises APRA to make prudential standards governing capital adequacy, governance, risk management, reinsurance, conduct, and reporting, gives APRA powers of investigation, direction, and judicial management over a failing general insurer, requires authorised insurers to hold sufficient eligible assets in Australia to cover Australian liabilities, supports the Financial Claims Scheme for policyholders of failed general insurers, and creates civil and criminal penalties for breach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-corporations-act-2001-chapter-2d-directors-duties"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "au-interactive-gambling-act-2001-acma",
    "title": "Interactive Gambling Act 2001 (Cth) - ACMA Prohibition of Interactive Gambling and Advertising",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Interactive Gambling Act 2001 (Cth), administered by the Australian Communications and Media Authority (ACMA), prohibits the provision of prohibited interactive gambling services to customers in Australia under Section 15 and the provision of unlicensed regulated interactive gambling services to Australian customers under Section 15AA. Whether a service has an Australian customer link is determined under Section 8, and the meaning of regulated interactive gambling service is set in Section 8E. Part 7A prohibits the advertising of designated interactive gambling services in Australia, with Section 61DA covering broadcasting or datacasting and Section 61EA covering publication. ACMA enforces compliance through complaints, formal warnings, infringement notices, injunctions and civil penalty provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-austrac-aml-ctf-act-2006",
      "responsible-gambling-grb-standards-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "au-irap-information-security-registered-assessors-program",
    "title": "Australia IRAP — Information Security Registered Assessors Program (ASD ACSC)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Information Security Registered Assessors Program (IRAP) is the Australian government cybersecurity assessment programme administered by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre (ACSC). IRAP-endorsed assessors evaluate the implementation of the controls specified in the Australian Government Information Security Manual (ISM) against the security classification of the system under assessment. IRAP assessments cover Australian government cloud services, Defence systems, critical infrastructure under the Security of Critical Infrastructure Act 2018 (SOCI Act), and high-assurance enterprise systems handling Australian government data. The Australian security classifications covered include OFFICIAL (everyday business information), OFFICIAL:Sensitive (information requiring limited dissemination), PROTECTED (information whose compromise would cause damage to national interests), SECRET (serious damage), and TOP SECRET (exceptionally grave damage). IRAP-assessed services may receive Certified Cloud Services List placement at PROTECTED level under the previous IRAP Certified Cloud Services List and the successor Assured Cloud Services framework, and at OFFICIAL:Sensitive and lower under broader CSP self-assessment regimes. IRAP assessments follow a standard methodology spanning architecture review, control implementation testing, residual-risk evaluation, and consumer guide preparation; the assessment cycle is typically 24 months with annual surveillance for cloud services. IRAP-endorsed CSPs include AWS, Microsoft Azure, Google Cloud, Oracle Cloud Infrastructure, IBM Cloud, Vault Cloud, Macquarie Government, and several Australian sovereign cloud providers. The programme intersects the Hosting Certification Framework administered by the Digital Transformation Agency and the Protective Security Policy Framework (PSPF) administered by the Attorney-General's Department.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-iec-42001-2023-ai-management-system",
      "iso-iec-23894-ai-risk-management-2023",
      "nist-sp-800-53-r5",
      "fips-203-ml-kem-standard",
      "canada-protected-b-cloud-security-profile-cccs-itsp-50-105"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "au-migration-act-1958",
    "title": "Australia Migration Act 1958: Lawful and Unlawful Non-Citizens, Visa Authority, Decision to Grant or Refuse, Detention, Removal, Character Cancellation, and Review of Decisions",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Australian Migration Act 1958, Act No. 62 of 1958, is the principal Commonwealth statute governing the entry, presence, and removal of non-citizens from Australia and is administered by the Department of Home Affairs. Migration Act 1958, section 4 sets the object of the Act. Migration Act 1958, section 5 contains the interpretation including definitions of refugee status, character concerns, and personal identifiers. Migration Act 1958, section 13 defines lawful non-citizens and Migration Act 1958, section 14 defines unlawful non-citizens. Part 2 Division 3 governs visas for non-citizens: Migration Act 1958, section 29 establishes the visa authority and Migration Act 1958, section 65 governs the decision to grant or refuse to grant a visa. The Act establishes protection visas, bridging visas, and temporary safe haven visas. Part 2 Division 6 governs detention: Migration Act 1958, section 189 requires detention of unlawful non-citizens and Migration Act 1958, section 196 governs the period of detention. Part 2 Division 8 governs removal: Migration Act 1958, section 198 authorises removal from Australia. Migration Act 1958, section 200 governs deportation. Migration Act 1958, section 501 governs refusal or cancellation of visa on character grounds. Part 5 and Part 7 establish merits review of migration decisions and protection visa decisions, and Part 8 covers judicial review. Sections 119 through 127 govern cancellation procedures with procedural fairness requirements. The Act is the controlling Commonwealth instrument for immigration and border control compliance in Australia and operates alongside the Migration Regulations 1994.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "au-model-whs-laws-2011",
    "title": "Model Work Health and Safety (WHS) Act 2011 - Primary Duty of Care, PCBUs, Workers and Incident Notification",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Model WHS Act imposes a primary duty of care (Section 19) on a Person Conducting a Business or Undertaking (PCBU) to ensure, so far as is reasonably practicable, the health and safety of workers and others affected by its operations. This includes proactive risk management, worker consultation, and mandatory notification of 'notifiable incidents' to the regulator.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-work-safety",
      "iso-31000-risk-mgt-std",
      "osha-work-safety-us"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "au-model-work-health-safety-act-2011-pcbu-duties-whs-officers",
    "title": "AU Model Work Health and Safety Act 2011 - PCBU Primary Duty of Care, WHS Officer Due Diligence, and Notifiable Incidents",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2022-12-01",
    "bluf": "The Model Work Health and Safety Act 2011 (adopted by Commonwealth, ACT, NSW, NT, Qld, SA, Tas, WA) imposes a primary duty of care on Persons Conducting a Business or Undertaking (PCBU) to ensure health and safety of workers and others so far as is reasonably practicable, with officers required to exercise due diligence and notifiable incidents reported to regulator within 24 hours.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-health-safety",
      "australia-competition-consumer-act-2010-cca"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-modern-slavery-act-2018",
    "title": "Australia Modern Slavery Act 2018 (Cth) (No. 153 of 2018)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Modern Slavery Act 2018 (Cth) No. 153 of 2018 is Australia's principal supply-chain transparency statute targeting modern slavery practices. The Act was in force from 1 January 2019. The Act is organised in four Parts plus endnotes. Part 1 (ss. 1-10) contains preliminary matters including the definitions in s. 4 of modern slavery covering eight categories: trafficking in persons, slavery, servitude, forced labour, debt bondage, deceptive recruiting for labour or services, forced marriage and the worst forms of child labour; the reporting entity threshold in s. 5 is an Australian entity or an entity carrying on business in Australia with consolidated revenue of at least AUD 100 million for the financial year. Part 2 (ss. 11-16A) imposes the annual Modern Slavery Statement obligation: s. 13 mandates seven mandatory reporting criteria - identify the reporting entity, describe its structure, operations and supply chains, identify potential modern slavery risks in operations and supply chains, describe the actions taken to assess and address those risks (including due diligence and remediation), describe how the entity assesses the effectiveness of those actions, describe consultation with controlled entities, and provide any other information the reporting entity considers relevant; s. 14 provides for joint Modern Slavery Statements by a group of reporting entities; s. 16 requires submission to the Modern Slavery Statements Register maintained by the Anti-Slavery Commissioner. Part 3 (ss. 17-20) governs access to the Register. Part 3A (ss. 20A-20Y inserted by Modern Slavery Amendment (Australian Anti-Slavery Commissioner) Act 2024) establishes the Anti-Slavery Commissioner with engagement and reporting functions. Part 4 (ss. 21-25) addresses administrative provisions. From 1 January 2026 (post the 2024 amendments) the Commissioner has expanded powers and the threshold is set for review under s. 24.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-modern-slavery-act-2015-section-54-supply-chain-transparency",
      "eu-csddd-directive-2024-1760",
      "de-lksg-supply-chain-due-diligence-act-2021"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "au-my-health-records-act-2012",
    "title": "Australia My Health Records Act 2012 - National Digital Health Record System",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The My Health Records Act 2012 (Commonwealth, Act No. 63 of 2012) establishes Australia's national digital health record system administered by the Australian Digital Health Agency as System Operator under the Department of Health, Disability and Ageing. The Act regulates the collection, use, and disclosure of health information held in the My Health Record system, providing each healthcare recipient with a centralised record accessible to participating healthcare providers under documented access conditions. Part 2 establishes the System Operator role and the registration of healthcare recipients, registered healthcare provider organisations, and repository or portal operators. Part 3 governs the operational management of the records including security, integrity, and access. Part 4 sets out the collection, use, and disclosure framework with Division 2 prescribing consent and access controls, Division 3 authorising emergency access where the healthcare recipient is unable to consent, and Division 3A creating offences for use or disclosure for prohibited purposes including insurance underwriting, employment screening, and law-enforcement use absent specific exceptions. Part 5 establishes civil penalties; Part 6 establishes criminal offences. The Act operates alongside the Healthcare Identifiers Act 2010 and the Privacy Act 1988 to form Australia's federal digital-health regulatory regime, and is the operative framework for any AI-driven clinical decision support, telehealth, or virtual care offering interacting with My Health Record data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "au-national-ai-plan-vaiss-2025",
    "title": "Australia National AI Plan 2025 and Voluntary AI Safety Standard - DISR Technology-Neutral Approach, Unveiled 2 December 2025",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Organisations adopting AI in or affecting Australia should align with the National AI Plan 2025 unveiled by the Australian Government on 2 December 2025, coordinated by the Department of Industry, Science and Resources (DISR) as the central policy coordinator and lead steward for the whole-of-economy AI strategy, recognising that the Government has officially abandoned the proposed mandatory guardrails and will instead build on Australia's existing technology-neutral laws while introducing targeted reforms, and adopt the Voluntary AI Safety Standard (VAISS) published by the National Artificial Intelligence Centre (NAIC) in 2024 which outlines 10 key guardrails for organisations across the AI supply chain on safe and responsible AI adoption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-amendment-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-national-code-overseas-students-2018",
    "title": "National Code of Practice for Providers of Education and Training to Overseas Students 2018",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This code establishes national standards for Australian education and training providers to ensure quality outcomes and welfare for overseas students.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-teqsa-act-2011-higher-education-standards"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-nccp-act-2009-consumer-credit",
    "title": "Australia National Consumer Credit Protection Act 2009 (NCCP Act)",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The National Consumer Credit Protection Act 2009 (NCCP Act) regulates the provision of consumer credit and consumer leases in Australia, establishing a national licensing regime for credit activities administered by ASIC and prescribing responsible lending conduct obligations. Under Part 3-2, licensees must not enter into a credit contract with a consumer if the contract is unsuitable for the consumer. A credit contract is unsuitable if the consumer will be unable to comply with the financial obligations or could only comply with substantial hardship. Responsible lending obligations require licensees to make reasonable inquiries about a consumer's financial situation, requirements, and objectives, and to verify financial information. The National Credit Code (Schedule 1) prescribes the conduct of credit contracts, including disclosure requirements, interest rate caps, prohibition on unconscionable fees, and hardship provisions. ASIC holds extensive supervisory and enforcement powers including licence conditions, banning orders, and civil and criminal penalties for serious contraventions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-aml-ctf-act-2006"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "au-nvetr-act-2011-vocational-education-regulator",
    "title": "National Vocational Education and Training Regulator Act 2011",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This Act establishes the National Vocational Education and Training Regulator and outlines the requirements for registration, compliance, and quality assurance for vocational education and training organizations in Australia.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "au-offshore-petroleum-greenhouse-gas-storage-act-2006-section-29",
    "title": "Australia Offshore Petroleum and Greenhouse Gas Storage Act 2006 Section 29 - Exploration Licence Grant Criteria and Conditions for Offshore Petroleum",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Offshore Petroleum and Greenhouse Gas Storage Act 2006 (OPGGSA) is the principal Commonwealth legislation governing petroleum exploration and production in Commonwealth offshore areas (beyond 3 nautical miles from the Australian coastline). Section 29 and related provisions govern the grant of exploration licences for petroleum exploration. Licences are granted by the National Offshore Petroleum Titles Administrator (NOPTA) on behalf of the Joint Authority (comprising the relevant Commonwealth and State/Territory Minister). The Act also covers greenhouse gas storage activities, safety case requirements administered by the National Offshore Petroleum Safety and Environmental Management Authority (NOPSEMA), and environmental plan obligations under the Offshore Petroleum and Greenhouse Gas Storage (Environment) Regulations 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-safety-health-mines-convention-c176-1995"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-online-safety-act-2021",
    "title": "Australia Online Safety Act 2021 (Cth)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Online Safety Act 2021 (Cth) establishes Australia's comprehensive framework for online safety, replacing the Enhancing Online Safety Act 2015. The Act empowers the eSafety Commissioner to administer online safety schemes addressing cyberbullying, image-based abuse, illegal and restricted online content, and basic online safety expectations for large online platforms. Under Part 2, the Commissioner may publish online safety industry codes and industry standards. Under Part 9A, providers of designated internet services and relevant electronic services must comply with the Online Safety (Basic Online Safety Expectations) Declaration 2022, including expectations around content moderation, reporting mechanisms, and transparency reporting. Section 209 authorises the Minister to determine industry codes, and Section 215 authorises the Commissioner to make standards where codes are inadequate. The Act applies to social media services, relevant electronic services, and designated internet services used by Australians.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "au-online-safety-act-2021-removal-notice-scheme",
    "title": "Australia Online Safety Act 2021 - eSafety Commissioner Removal Notice Scheme",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "The Online Safety Act 2021 (Cth) establishes the eSafety Commissioner as the federal regulator with formal removal-notice powers across multiple harm schemes: Part 5 cyberbullying material targeted at an Australian child (section 65 removal-notice authority, 24-hour compliance window, end-user notice power under section 70); Part 6 non-consensual intimate images (sections 77-79 removal-notice authority to service providers and hosting service providers, 24-hour compliance window); Part 9 Online Content Scheme for Class 1 material (section 109 removal-notice authority to social media services, relevant electronic services, designated internet services, and hosting service providers regarding Class 1 material that depicts, expresses, or otherwise deals with matters such as crime, cruelty, sexual violence, gratuitous sexual or violent conduct, or detailed instruction in crime). Part 7 Adult Cyber Abuse adds removal-notice powers for material targeting an Australian adult that is menacing, harassing, or offensive. Service providers face civil penalty provisions under section 162 for non-compliance with removal notices, with the Commissioner empowered to issue formal warnings, accept enforceable undertakings, seek injunctions, and impose substantial civil penalties enforceable through the Federal Court of Australia.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "removal_scheme_taxonomy",
        "classification_anchor",
        "industry_mapping",
        "compliance_window",
        "civil_penalty_quantum",
        "enforcement_powers"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-part-5-pornographic-content-duties",
      "us-take-it-down-act-2025"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "au-online-safety-social-media-minimum-age-act-2024",
    "title": "Australia Online Safety Amendment (Social Media Minimum Age) Act 2024 - Prohibition of Under-16 Social Media Accounts, Effective 10 December 2025",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Designated social media platforms operating in Australia (initially Facebook, Instagram, Reddit, Snapchat, TikTok, Twitter, Threads, Twitch, Kick, and YouTube as of 10 December 2025, with more potentially added) must take reasonable steps to prevent persons under 16 located in Australia from holding accounts on their services under the Online Safety Amendment (Social Media Minimum Age) Act 2024 (passed by the Parliament of Australia on 29 November 2024, with the ban commencing on 10 December 2025), by creating age verification systems, with civil penalties of up to 30,000 penalty units for non-compliance increasing to 150,000 penalty units (currently AUD 49.5 million) for breach of the minimum age obligation, and with the Minister for Communications and eSafety Commissioner empowered to designate additional platforms over time.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-osa-phase-2-industry-codes-2025"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "au-osa-phase-2-industry-codes-2025",
    "title": "Australia Online Safety Act 2021 Phase 2 Industry Codes 2025 - Class 1C and Class 2 Material Age Assurance and Reporting",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Online service providers in scope of the Australian Online Safety Act 2021 must, from 27 December 2025 (hosting services, internet carriage services, internet search engine services) and from 9 March 2026 (equipment providers, app distribution services, designated internet services, relevant electronic services, and social media services), comply with the Phase 2 Online Safety Industry Codes registered by the eSafety Commissioner addressing class 1C and class 2 online material such as online pornography that is inappropriate for children, by applying appropriate age assurance measures for certain content and services, implementing end-user reporting mechanisms for breaches of prohibitions, and educating Australian end-users on the role and functions of the eSafety Commissioner and how to make a complaint.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-section-66-csea-reporting-nca"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "au-privacy-act-1988",
    "title": "Australia Privacy Act 1988 (2024 Reform - Privacy and Other Legislation Amendment Act)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Australia Privacy Act 1988, as amended, regulates the handling of personal information through the 13 Australian Privacy Principles (APPs) in Schedule 1. It applies to most Australian Government agencies and private sector organizations with an annual turnover of more than AUD $3 million, requiring them to manage data transparently, securely, and with respect for individual rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-122-pii",
      "gdpr-data-protection-officer",
      "za-popia-2013"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "au-privacy-act-1988-app-11-security-personal-information",
    "title": "AU Privacy Act 1988 - Australian Privacy Principle 11: Security of Personal Information",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "Australian Privacy Principle 11 (APP 11) in the Privacy Act 1988 (Commonwealth) requires APP entities to take reasonable steps to protect personal information from misuse interference and loss as well as from unauthorised access modification or disclosure. APP entities include Australian Government agencies and private sector organisations with annual turnover of more than AUD 3 million. The Notifiable Data Breaches (NDB) scheme in Part IIIC requires notification of eligible data breaches to the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable. The Privacy Act 2024 amendments introduced statutory tort for serious invasions of privacy and increased maximum civil penalties to AUD 50 million or 30% of adjusted turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "privacy_act_1988",
        "ndb_scheme",
        "privacy_2024",
        "gdpr",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "au-privacy-act-1988-app-3-collection-personal-info",
    "title": "Financial Transaction Reports Act 1988 - Part II Transaction reports and Part III Accounts",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This Act requires cash dealers, solicitors, and other entities to report significant cash transactions, international currency transfers, and suspect transactions to AUSTRAC, and to maintain identification and transaction records.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-aml-ctf-act-2006"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "au-privacy-amendment-2024",
    "title": "Australia Privacy and Other Legislation Amendment Act 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Australia's Privacy and Other Legislation Amendment Act 2024 introduces a statutory tort for serious invasions of privacy, strengthens children's online privacy protections, enhances OAIC enforcement powers, and creates a new direct marketing opt-out mechanism - the most significant reform to the Privacy Act 1988 in over a decade.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/au-privacy-amendment-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "au-security-legislation-amendment-critical-infrastructure-act-2021-part-2a",
    "title": "Security Legislation Amendment (Critical Infrastructure) Act 2021 - Part 2A",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This Act amends security legislation for critical infrastructure; however, the provided source text is a legislative landing page and does not contain the specific compliance obligations of Part 2A.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-iec-27001-2022-information-security-workflow"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-security-of-critical-infrastructure-act-2018-soci",
    "title": "Australia Security of Critical Infrastructure Act 2018 (SOCI) - Positive Security Obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Security of Critical Infrastructure Act 2018 (Cth) imposes positive security obligations on owners and operators of 22 critical infrastructure asset classes across 11 sectors. Responsible entities must register assets, implement Critical Infrastructure Risk Management Programs (CIRMPs), and report significant cyber incidents to the Australian Cyber Security Centre (ACSC) within 12 hours (for critical incidents) or 72 hours.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988-app-3-collection-personal-info"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-soci-act-2018",
    "title": "Australia Security of Critical Infrastructure Act 2018",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Australia's Security of Critical Infrastructure Act imposes mandatory cyber security incident reporting obligations - 12 hours for significant incidents, 72 hours for others - positive security obligations on operators of critical assets across 11 sectors, and government assistance and intervention powers for severe cyber attacks affecting Australia's critical infrastructure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/au-soci-act-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-amendment-2024"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "au-soci-act-2018-security-of-critical-infrastructure",
    "title": "Australia Security of Critical Infrastructure Act 2018 - 11-Sector CIRMP, Cyber Incident Reporting, and Government Assistance Powers",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "The Australian Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act), significantly expanded by the Security Legislation Amendment (Critical Infrastructure) Act 2021 (SLACI) and the Security Legislation Amendment (Critical Infrastructure Protection) Act 2022 (SLACIP), establishes Australia's primary regulatory framework for the protection of critical infrastructure across 11 sectors. Part 1 of the Act defines critical infrastructure asset and identifies the 11 covered sectors: communications, financial services and markets, data storage and processing, water and sewerage, energy (electricity, gas, liquid fuels), healthcare and medical, higher education and research, food and grocery, transport (ports, airports, freight, rail, road), space technology, and defence industry. A responsible entity is the entity that holds the critical infrastructure asset and bears compliance obligations. Part 2 establishes the Register of Critical Infrastructure Assets maintained by the Department of Home Affairs Cyber and Infrastructure Security Centre (CISC) - confidential under section 22. Part 2A requires every responsible entity to establish and maintain a Critical Infrastructure Risk Management Program (CIRMP) addressing cyber, supply chain, personnel, physical, and natural hazard risks; the CIRMP Rules under section 30AH specify mandatory risk management standards aligned to standards such as ISO 27001 and AESCSF. Part 2B requires mandatory cyber incident reporting to the Australian Cyber Security Centre (ASD ACSC) within 12 hours for a critical cyber security incident having a significant impact on the availability of the asset, and within 72 hours for any other cyber security incident having a relevant impact. Part 2C applies Enhanced Cyber Security Obligations to Systems of National Significance designated by the Minister - including statutory incident response plans, cyber security exercises, vulnerability assessments, and system information reporting. Part 3 grants ministerial Government Assistance powers - the Minister may issue an Authorisation to permit the Australian Signals Directorate to step in, install software, or take other action to respond to a serious cyber security incident. Maximum civil penalty 1,000 penalty units (approximately AUD 330,000 indexed) per contravention; criminal offences carry imprisonment penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "cirmp_rules_2023_risk_categories_section_30ah",
        "mandatory_cyber_incident_reporting_part_2b_12_72_hours",
        "government_assistance_part_3_step_in_powers_minister_authorisation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-directive-2022-2555-critical-infrastructure",
      "eu-critical-entities-resilience-directive-2022",
      "us-nerc-cip-standards-bulk-electric-system",
      "nist-csf-critical-infrastructure-cybersecurity-v2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "au-soci-cirmp-rules-2023",
    "title": "Australia SOCI Act Critical Infrastructure Risk Management Program Rules 2023 (LIN 23/210)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Security of Critical Infrastructure (Critical infrastructure risk management program) Rules LIN 23/210 commenced February 17, 2023 require responsible entities for critical infrastructure assets to adopt and maintain a risk management program addressing material risks from personnel, supply chain, ICT and OT systems, and physical and natural hazards, with annual board-level attestation to the responsible minister.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/au-soci-cirmp-rules-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-soci-act-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-space-activities-act-1998-launch-permit-authorisation",
    "title": "Australian Space Activities Act 1998 - Launch Permit Requirements, Operator Authorisation, and Third Party Liability Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Space Activities Act 1998 (Cth) (SAA) regulates Australian space launch activities and the activities of Australian nationals conducting space operations overseas. The Act requires launch operators to obtain a launch permit from the Minister for Space, administered by the Australian Space Agency (ASA). High power rockets and return of payload from space also require permits. The Act caps operator liability at AUD 750 million and requires third-party liability insurance up to that amount. The Australian Government indemnifies the operator for claims in excess of AUD 750 million and claims that are not covered by insurance. Australia implements its international obligations under the OST, Liability Convention, and Registration Convention through the SAA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967-article-vi-state-responsibility",
      "intl-outer-space-treaty-1967-article-7-liability-damage"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-spam-act-2003",
    "title": "Australia Spam Act 2003 (Cth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Australia's Spam Act 2003 (Cth) effective April 10, 2004 prohibits sending unsolicited commercial electronic messages to Australian electronic addresses without express or inferred consent, requires sender identification and a functional unsubscribe mechanism in every message, and applies to email, SMS, MMS, and instant messaging with ACMA civil penalty enforcement up to AUD 2.22 million per day for serious or repeated violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/au-spam-act-2003.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-spam-act-2003-commercial-electronic-messages-consent",
    "title": "Australia Spam Act 2003 - Commercial Electronic Message Consent and Unsubscribe Requirements",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Spam Act 2003 (Cth) prohibits sending unsolicited commercial electronic messages (CEMs) to Australian accounts without express or inferred consent, requires accurate sender identification in every CEM, mandates a functional unsubscribe mechanism, and imposes penalties up to $2.22M per day for serious or repeated contraventions enforced by the ACMA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-6-lawful-basis-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-tas-gaming-control-act-1993",
    "title": "Gaming Control Act 1993 (Tasmania) - Casino and Gaming Operator Licensing and Applicant Investigation",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Gaming Control Act 1993 (Tasmania) sets out the authority conferred by a gaming operator's licence in Section 12, including purchasing approved gaming equipment, conducting keno games and conducting gaming machine games at licensed premises. The granting of casino licences and gaming operator's licences is governed by Section 13. The Commission must conduct investigations and inquiries into a licence application under Section 24, including the power to require photographs, fingerprints and palm prints and to refer the application to the Commissioner of Police. Suitability of applicants and associates is assessed under Section 23, and amendment of licence conditions is governed by Section 14.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-austrac-aml-ctf-act-2006"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "au-telecommunications-act-1997-carrier-licence-conditions-nbn-access",
    "title": "AU Telecommunications Act 1997 - Carrier Licence Conditions, NBN Access, and Consumer Protection Obligations",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "Australia's Telecommunications Act 1997 requires carriers to hold an ACMA carrier licence, comply with customer service guarantee standards, provide access to declared services including NBN on non-discriminatory terms, register with the Telecommunications Industry Ombudsman, and comply with ACMA directions on network security and lawful interception.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988-app-3-collection-personal-info",
      "australia-competition-consumer-act-2010-cca"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-teqsa-act-2011-higher-education-standards",
    "title": "Tertiary Education Quality and Standards Agency Act 2011 - Higher Education Standards Framework",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This Act establishes the framework for regulating and assuring the quality of Australia's higher education sector through the Tertiary Education Quality and Standards Agency (TEQSA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "au-therapeutic-goods-act-1989",
    "title": "Australia Therapeutic Goods Act 1989 -- TGA Registration, Medical Device Conformity, and Advertising",
    "domain": "Medical & Healthcare",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "The Therapeutic Goods Act 1989 (TGA Act) establishes the Therapeutic Goods Administration (TGA) as Australia's regulator for medicines, medical devices, biologicals, and other therapeutic goods. No person may supply therapeutic goods in Australia unless they are entered in the Australian Register of Therapeutic Goods (ARTG) under Section 12, or a valid exemption or approval applies. Medicines are classified as Listed (lower-risk, self-assessed, listed on ARTG without full evaluation) or Registered (higher-risk, evaluated by TGA for quality, safety, and efficacy). Medical devices are classified into four risk classes - Class I (lowest, self-declaration), Class IIa, Class IIb, and Class III and Active Implantable Medical Devices (AIMD) (highest, requiring TGA conformity assessment or recognition of a comparable overseas authority certificate) - under the Therapeutic Goods (Medical Devices) Regulations 2002. Essential Principles (Therapeutic Goods Order No. 101) apply to all medical devices. Unique Device Identification (UDI) is mandatory for Class IIb and Class III devices. Criminal penalties under Section 19B for supplying unregistered goods can reach 5 years imprisonment or 4,000 penalty units (approximately AUD 1.1 million for individuals). Advertising therapeutic goods directly to consumers is prohibited for prescription medicines and regulated products under the Therapeutic Goods Advertising Code 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-medical-devices-regulation-2017-745"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "au-therapeutic-goods-act-1989-tga-medical-device-conformity-assessment",
    "title": "AU Therapeutic Goods Act 1989 (TGA) - Medical Device Conformity Assessment and ARTG Inclusion",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "The Therapeutic Goods Administration (TGA) regulates medical devices in Australia under the Therapeutic Goods Act 1989 and Therapeutic Goods (Medical Devices) Regulations 2002. Devices must be included in the Australian Register of Therapeutic Goods (ARTG) before supply. Class IIa, IIb, III, and AIMD devices require a TGA-issued or recognised conformity assessment certificate (ISO 13485-based). Class I sterile and measuring devices require a conformity assessment body certificate. TGA accepts certain international conformity assessment certificates (EU, USA, Japan, Canada).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-2016-medical-devices-quality-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "au-trusted-digital-identity-framework-tdif",
    "title": "Australia Trusted Digital Identity Framework TDIF Accreditation Rules Identity Proofing Authentication Federation and Fraud Control for Identity Service Providers",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "The Australian Government Trusted Digital Identity Framework (TDIF) administered by the Department of Finance through the Digital Transformation Agency establishes a voluntary federated accreditation scheme for digital identity service providers organised in 16 functional requirements documents covering Document 1 Overview and Principles, Document 2 TDIF Glossary, Document 3 Accreditation Process, Document 4 Functional Requirements for Identity Providers including identity proofing levels IP1 IP2 IP3 IP4 IP1+ and IP2+, Document 5 Functional Requirements for Credential Service Providers including authentication credential levels CL1 CL2 CL3 and CL4, Document 6 Functional Requirements for Identity Exchange providers, Document 7 Functional Requirements for Attribute Service Providers, Document 8 Functional Requirements for Identity Service Providers, Document 9 Functional Requirements for Information Security including ISMS implementation, Document 10 Functional Requirements for Fraud Control, Document 11 Functional Requirements for Privacy aligned with Privacy Act 1988, Document 12 Functional Requirements for Service Operations, Document 13 Functional Requirements for Risk Management, Document 14 Functional Requirements for Protective Marking, Document 15 Functional Requirements for Architecture, and Document 16 Functional Requirements for Federation. The TDIF supports the AustralianGovernment Digital Identity System enabling reusable digital identities across government and private sector relying parties with strong inclusion and accessibility commitments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "au-vic-gambling-regulation-act-2003",
    "title": "Gambling Regulation Act 2003 (Victoria) - Harm Minimisation, Venue Operator Licences and Responsible Gambling Conditions",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Gambling Regulation Act 2003 (Victoria) sets out its purpose, objectives and outline in Section 1.1, including fostering responsible gambling to minimise harm caused by problem gambling and ensuring minors are neither encouraged nor allowed to gamble. Venue operator licences (club and hotel venue operator licences) are granted under Chapter 3 Part 4 Division 2. Section 3.4.12A makes maintaining a self-exclusion program a condition of a venue operator licence, and Section 3.4.12B makes compliance with a Responsible Gambling Code of Conduct a condition of a venue operator licence. Ministerial directions about self-exclusion programs are made under Section 10.6.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "responsible-gambling-grb-standards-2023",
      "au-austrac-aml-ctf-act-2006"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "au-water-act-2007",
    "title": "AU Water Act 2007",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The AU Water Act 2007 (Cth) provides the federal framework for water resource management in Australia. The Act establishes the Murray-Darling Basin Authority (MDBA) as an independent statutory body; provides for the Basin Plan (2012) setting Sustainable Diversion Limits (SDLs) for surface water and groundwater in the Murray-Darling Basin (covering one-seventh of Australia's total water resources); environmental watering arrangements via the Commonwealth Environmental Water Holder (CEWH); water trading; and water resource management reporting via Bureau of Meteorology. The Productivity Commission 5-year reviews assess Basin Plan implementation including consequential 2024 Water Amendment (Restoring Our Rivers) Act extending recovery timelines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "au-work-health-safety-act-2011",
    "title": "Australian Work Health and Safety Act 2011",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2011-11-14",
    "bluf": "The Work Health and Safety Act 2011 (Cth) is Australia's model WHS legislation adopted across most jurisdictions, placing a primary duty of care on persons conducting a business or undertaking (PCBUs) to ensure health and safety so far as is reasonably practicable, with Category 1 penalties of AUD 3,000,000 for body corporates and mandatory immediate notification of notifiable incidents to the regulator.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "au-banking-act-1959",
        "eu-whistleblowing-directive-2019-1937",
        "au-therapeutic-goods-act-1989"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-whistleblowing-directive-2019-1937",
      "au-therapeutic-goods-act-1989"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "australia-accc-merger-review-guidelines-2023",
    "title": "Australia ACCC Informal Merger Review Guidelines 2023 - Market Concentration, Entry Barriers, Counterfactual Analysis and Coordinated Effects Assessment",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "These guidelines outline the Australian Competition and Consumer Commission’s (ACCC) informal process for assessing proposed mergers under the Competition and Consumer Act 2010 (Cth), focusing on whether a merger would substantially lessen competition (SLC) in any market, with analysis centered on market concentration, barriers to entry, counterfactual scenarios, and potential coordinated effects. Applies to all businesses proposing mergers in Australia where competition concerns may arise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-doj-ftc-merger-guidelines-2023",
      "eu-merger-regulation-139-2004-ecmr"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-acl-unfair-contract-terms-sch2-cca-small-business",
    "title": "Australia ACL Unfair Contract Terms - Schedule 2 CCA Extension to Small Business Contracts",
    "domain": "Sales, Marketing & PR",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Australia's Australian Consumer Law (Schedule 2, Competition and Consumer Act 2010) prohibits unfair terms in standard form consumer and small business contracts - ACCC/ASIC can void unfair terms; 2022 amendments effective November 2023 extend protections and add civil penalties up to AUD 50 million per breach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-acma-numbering-plan-2015",
    "title": "Australia Numbering Plan 2015 - ACMA Number Administration: Geographic Area Code Assignment, Mobile Number Ranges, Freephone and Local Rate Number Rules, Number Portability Technical Specifications, Quarantine Periods and Emergency Service Number Protection",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Australia Numbering Plan 2015, administered by the ACMA, governs the allocation, use, and portability of telecommunications numbers across geographic, mobile, freephone, and emergency services. It applies to all carriage service providers and number-issuing agencies under section 214 of the Telecommunications Act 1997, mandating compliance with technical specifications for number portability and quarantine periods for recycled numbers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "3gpp-ims-ip-multimedia-subsystem-release-16",
      "eu-5g-cybersecurity-toolbox-2020",
      "eu-net-neutrality-open-internet-2015-2120",
      "cisa-zero-trust-maturity-model-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-acsc-essential-eight-maturity-2023",
    "title": "Australian Cyber Security Centre Essential Eight Maturity Model 2023 - Patch Applications, MFA, Application Control and Daily Backups: Four Maturity Level Definitions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation outlines four maturity levels for implementing the Essential Eight mitigation strategies, with Maturity Level 2 requiring organisations to apply patches within 48 hours for internet-facing services and enforce multi-factor authentication (MFA) for administrative access and remote network access. It applies to all Australian government agencies and critical infrastructure entities as defined under the Security of Critical Infrastructure Act 2018 (as amended 2022), per ACSC guidance in Section 'Maturity Model'.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-essential-eight-2023",
      "cyber-nist-800-53-ac2",
      "nist-800-53-sc7",
      "c-scrm-practices-systems-organizations",
      "cyber-nist-csf-2"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-agvet-code-1994-apvma",
    "title": "Australia Agricultural and Veterinary Chemicals Code Act 1994 - APVMA Registration and Product Approval Framework",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The Agricultural and Veterinary Chemicals Code Act 1994 (AgVet Code, Schedule 1 to the Agricultural and Veterinary Chemicals Code Act 1994) establishes the national scheme for regulating agricultural and veterinary chemical products in Australia. The Australian Pesticides and Veterinary Medicines Authority (APVMA) administers product registration (including assessment of safety, efficacy and trade impacts), label approval, and permit issuance. No person may sell, supply or use an unregistered AgVet product. Maximum residue limits (MRLs) are set under the Australia New Zealand Food Standards Code. The AgVet Code also establishes recall powers, adverse experience reporting (AER) obligations, and the review system for registered products under the reconsideration provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-biosecurity-act-2015-daff",
      "new-zealand-biosecurity-act-1993-mpi"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-ai-ethics-framework-2019",
    "title": "Australia's Artificial Intelligence Ethics Framework: Eight AI Ethics Principles",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-11-13",
    "bluf": "This voluntary framework provides eight principles to guide Australian businesses and governments in the responsible design, development, and implementation of AI. It requires organizations to ensure AI systems uphold human-centred values, fairness, transparency, and accountability, as detailed in the 'Australia’s AI Ethics Principles' section.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "unesco-ethics-ai"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "australia-ai-ethics-principles-disr-2019",
    "title": "Australia's Artificial Intelligence Ethics Framework: Eight AI Ethics Principles",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This voluntary framework establishes eight core principles for ethical AI development and deployment in Australia, applicable to all organizations designing, developing, or deploying AI systems. Key obligations include ensuring human oversight, fairness, privacy protection, and contestability of AI-driven decisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-ai-ethics-framework-2019",
      "asean-model-ai-governance-v2-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-amsa-marine-safety-domestic-vessels-2012",
    "title": "Australia Marine Safety (Domestic Commercial Vessel) National Law Act 2012 - AMSA Framework",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2013-07-01",
    "bluf": "Australia's Marine Safety (Domestic Commercial Vessel) National Law Act 2012 creates a uniform national framework administered by AMSA (Australian Maritime Safety Authority) for all domestic commercial vessels operating in Australian waters, replacing eight separate state/territory marine safety acts with a single survey, registration, manning, and operator licensing regime effective 1 July 2013.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-consolidated-2020",
      "imo-stcw-convention-manila-2010",
      "ism-code-vessel-safety",
      "imo-marpol-pollution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "australia-apra-cps-220-risk-management",
    "title": "Prudential Standard CPS 220 - Risk Management",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "APRA Prudential Standard CPS 220 mandates that all general insurers and life companies establish and maintain a robust risk management framework overseen by the Board and a dedicated Risk Committee, with a formally appointed Chief Risk Officer (CRO) responsible for independent risk oversight, stress testing, and internal capital adequacy assessment processes. Key requirements are detailed in Sections 4-12 of CPS 220.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-gps-220-risk-management-general-insurers",
      "au-apra-prudential-standard-gps-310-audit-2023",
      "australia-apra-lps-110-capital-adequacy-life",
      "canada-osfi-e19-own-risk-solvency-2023",
      "eu-eiopa-guidelines-orsa-2015"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-apra-cps-234-information-security-insurance",
    "title": "Prudential Standard CPS 234 - Information Security",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "APRA CPS 234 mandates that regulated insurers maintain an information security capability commensurate with their risk profile, implement a formal policy framework, classify information security incidents as 'compromising' or 'material', and notify APRA within 72 hours of a material incident. It applies to all APRA-regulated entities including general insurers, life insurers, and private health insurers under Prudential Standard GPS 220 and LPS 110.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-gps-220-risk-management-general-insurers",
      "australia-apra-lps-110-capital-adequacy-life",
      "au-apra-prudential-standard-gps-310-audit-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-apra-gps-110-capital-adequacy-general",
    "title": "Prudential Standard GPS 110 Capital Adequacy",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard requires Australian general insurers to maintain a capital base that exceeds their Prescribed Capital Amount (PCA) at all times, ensuring sufficient capital is held to absorb unexpected losses. As per paragraph 10, a general insurer must ensure its capital base is adequate for its risks at all times, covering insurance risk, asset risk, and other material risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-apra-gps-220-risk-management-general-insurers",
    "title": "APRA Prudential Standard GPS 220 - Risk Management Requirements for General Insurers (2023 Update)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-07-01",
    "bluf": "This standard requires all APRA-regulated general insurers and Level 2 insurance groups to establish and maintain a comprehensive Risk Management Framework (RMF) and a Risk Management Strategy (RMS). The Board is ultimately responsible for the RMF and must ensure it is appropriate to the size, business mix, and complexity of the insurer's operations, as stipulated in Paragraph 14.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-apra-lps-110-capital-adequacy-life",
    "title": "Prudential Standard LPS 110 Capital Adequacy",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2023-06-29",
    "bluf": "This standard requires Australian life insurance companies to maintain a capital base that exceeds their Prescribed Capital Amount (PCA) at all times, as mandated by the Life Insurance Act 1995. The core requirement, detailed in paragraph 10, is that the 'capital base' must be greater than the 'Prescribed Capital Amount' to ensure solvency and protect policyholders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-biosecurity-act-2015-daff",
    "title": "Australia Biosecurity Act 2015 - DAFF Import, Biosecurity Risk Assessment, and Compliance Framework",
    "domain": "Agriculture & Agritech",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The Biosecurity Act 2015 (Cth) replaced the Quarantine Act 1908 and established Australia's modern biosecurity regime. The Department of Agriculture, Fisheries and Forestry (DAFF) administers the Act, supported by the Australian Border Force (ABF) at the border. The Act provides a risk-based framework: imported goods, vessels, aircraft, mail, and people must comply with biosecurity requirements to prevent pests and diseases entering or spreading in Australian territory. The BICON (Biosecurity Import Conditions) database specifies import conditions for all commodities. Biosecurity officers have broad powers including the right to inspect, detain, and destroy goods. Biosecurity emergency powers allow the Agriculture Minister to impose nationally binding emergency measures. Civil and criminal penalties apply to biosecurity contraventions. Biosecurity industry agreements (BIAs) allow industry to take responsibility for biosecurity risk management. Import permits are mandatory for all goods assessed as requiring conditions before entry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "wto_sps",
        "ippc",
        "bie_framework",
        "customs",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-competition-consumer-act-2010",
    "title": "Competition and Consumer Act 2010 - Part IV Cartel Conduct, Section 46 Misuse of Market Power, and Merger Review",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Prohibits corporations from engaging in cartel conduct such as price fixing (Part IV, Division 1), misusing substantial market power for anti-competitive purposes (Section 46), or undertaking mergers that would substantially lessen competition (Section 50). This applies to all corporations and individuals engaged in trade or commerce within Australia.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "oecd-corporate-governance-principles",
      "iso-37001-anti-bribery"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-competition-consumer-act-2010-accc-part-iv",
    "title": "Australia Competition and Consumer Act 2010 - ACCC Part IV Cartel Conduct & Merger Control",
    "domain": "Competition & Antitrust",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Australia's Competition and Consumer Act 2010 Part IV criminalises cartel conduct (price-fixing, bid-rigging) and requires ACCC merger review for acquisitions that would substantially lessen competition - maximum penalty AUD 50 million per contravention for corporations, 10 years imprisonment for individuals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-competition-consumer-act-2010-accc-part-iv"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-competition-consumer-act-2010-cca",
    "title": "Competition and Consumer Act 2010 - Part IV Competition Provisions: Cartel Conduct, Misuse of Market Power, Mergers, Exclusive Dealing and ACCC Authorisation and Notification",
    "domain": "Competition & Antitrust",
    "version": "1.1.0",
    "last_updated": "2026-07-03",
    "bluf": "This regulation prohibits anti-competitive conduct including cartels, misuse of market power, and exclusive dealing arrangements that substantially lessen competition. It applies to corporations and individuals engaged in trade or commerce within Australia under Part IV of the Competition and Consumer Act 2010.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-competition-consumer-act-2010-part-iv",
      "australia-accc-merger-review-guidelines-2023",
      "uk-cma-merger-assessment-guidelines-2021",
      "india-competition-act-2002-sections-3-4",
      "oecd-recommendation-hard-core-cartels-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "australia-competition-consumer-act-2010-part-iv",
    "title": "Competition and Consumer Act 2010 (Cth) Part IV - Provisions Relating to Cartels, Misuse of Market Power, Exclusive Dealing, Resale Price Maintenance and Mergers",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Prohibits anti-competitive conduct including cartel conduct (Section 45AA), misuse of substantial market power (Section 46), exclusive dealing (Section 47), and resale price maintenance (Section 48). Applies to corporations and individuals engaged in trade or commerce within Australia.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-consumer-law-acl-2010-cx",
    "title": "Australian Consumer Law 2010 - Consumer Guarantees (ACCC)",
    "domain": "Operations & CX",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Businesses must provide consumer guarantees such as acceptable quality, fit for purpose, accurate description and timely service; failure to meet these guarantees breaches the Australian Consumer Law (see ACCC consumer guarantees page).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-10002-2018-customer-satisfaction-complaints"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-copyright-act-1968-digital-amendments",
    "title": "Australia Copyright Act 1968 - Digital Amendments: Safe Harbour Scheme Extension (2018), Online Blocking Injunctions, Text and Data Mining Exception, Educational Statutory Licence Digital Delivery, Retransmission and Technological Measures Protection",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation amends the Copyright Act 1968 to extend the safe harbour scheme to carriage service providers, enable online copyright infringement blocking injunctions, introduce exceptions for text and data mining, facilitate digital delivery under the educational statutory licence, and strengthen protections for technological protection measures. Key provisions are found in Schedule 1 of the Telstra Corporation and Other Legislation Amendment Act 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dmca-safe-harbor",
      "australia-news-media-bargaining-code-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-defence-export-controls-des-2012",
    "title": "Defence and Strategic Goods List (DSGL) and Export Controls - Defence Export Control Act 2012",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Defence Export Controls Act 2012 requires any person or entity exporting, brokering, or transferring defence and strategic goods or technology listed in the Defence and Strategic Goods List (DSGL) to obtain a permit from the Defence Export Control (DEC) Office. This applies to physical goods, intangible technology transfers, and brokering activities involving DSGL items, under Section 9 and Section 10 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "as9100-rev-d-qms",
      "iso-27017-cloud-defence",
      "cmmc-2-audit",
      "nist-800-171-cui"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-education-services-overseas-students-act-2000",
    "title": "Australia Education Services for Overseas Students Act 2000 (ESOS Act) - CRICOS Registration",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Education Services for Overseas Students Act 2000 (ESOS Act) requires all Australian education providers enrolling students on student visas to be registered on the Commonwealth Register of Institutions and Courses for Overseas Students (CRICOS). Registered providers must comply with the National Code of Practice for Providers of Education and Training to Overseas Students 2018 (National Code), including obligations on course completion monitoring, student support, complaints handling, and marketing standards. Providers must notify the Department of Home Affairs when student visa conditions are not met.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "national_code_2018",
        "migration_act_1958",
        "teqsa_act_2011",
        "asqa",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-higher-education-support-act-2003",
      "australia-competition-consumer-act-2010-cca"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "australia-electronic-transactions-act-1999",
    "title": "Australia Electronic Transactions Act 1999 (Cth) - Electronic Equivalence and Digital Commerce",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Electronic Transactions Act 1999 (Cth) establishes the legal equivalence of electronic communications, signatures, records, and contracts with paper-based transactions under Commonwealth law. A writing requirement is satisfied if information is in electronic form that is accessible for later reference. An electronic signature satisfies a signature requirement where the method identifies the person and indicates their approval, and the method is reliable or consented to by the counterparty. The Act applies to transactions under Commonwealth laws; the states and territories have equivalent Acts. The Act was substantially amended in 2011 to align with the UNCITRAL Model Law on Electronic Commerce.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_esign_act_2000",
        "eu_eidas_910_2014",
        "uncitral_model_law",
        "eu_electronic_invoicing",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-esign-act-2000-electronic-signatures",
      "eu-eidas-trust-services-telecoms-910-2014",
      "eu-electronic-invoicing-directive-2014-55"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-environmental-protection-biodiversity-conservation-act-1999",
    "title": "Australia Environment Protection and Biodiversity Conservation Act 1999 - DCCEEW",
    "domain": "Mining & Natural Resources",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Environment Protection and Biodiversity Conservation Act 1999 (EPBC Act, Cth) is Australia's primary federal environmental law requiring referral and assessment of actions that have, or are likely to have, a significant impact on matters of national environmental significance (MNES) including threatened species, Ramsar wetlands, World Heritage Areas, and nuclear actions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "australia-epbc-act-1999-mining-biodiversity",
    "title": "Environment Protection and Biodiversity Conservation Act 1999 - Referral, Assessment and Approval of Actions that May Impact Matters of National Environmental Significance",
    "domain": "Mining & Natural Resources",
    "version": "1.1.0",
    "last_updated": "2026-07-03",
    "bluf": "The EPBC Act 1999 requires any mining project proponent whose action is likely to have a significant impact on a Matter of National Environmental Significance (MNES) to refer that action to the Australian Minister for the Environment so the Minister can decide, under Section 75, whether it is a controlled action requiring assessment and approval. This applies to all coal, mineral, and extractive industries operating in or near MNES-listed areas.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-26000-social-resp"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-essential-eight-2023",
    "title": "Australia ACSC Essential Eight Mitigation Strategies Maturity Model (2023 Update)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-11-22",
    "bluf": "The Australian Cyber Security Centre's (ACSC) Essential Eight is a prioritized baseline of eight mitigation strategies designed to help organizations protect their systems against a range of cyber threats. Compliance, measured across three maturity levels as detailed in the model, is mandatory for Australian Government non-corporate Commonwealth entities and strongly recommended for all other organizations to achieve a baseline security posture.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "cyber-nist-800-53-ac2",
      "nist-800-53-au2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "australia-fsanz-food-standards-code",
    "title": "Australia New Zealand Food Standards Code",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "All food sold in Australia and New Zealand must comply with the Australia New Zealand Food Standards Code, which sets requirements for food safety, labelling, premises, and specific product standards such as infant formula. The Code is administered by Food Standards Australia New Zealand (FSANZ) under the Food Standards Australia New Zealand Act 1991.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004",
      "eu-food-information-regulation-1169-2011-labelling"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-gene-technology-act-2000",
    "title": "Gene Technology Act 2000 - Regulation of Dealings with GMOs, Licensing, and Environmental Risk Management",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Gene Technology Act 2000 establishes a national framework for regulating dealings with genetically modified organisms (GMOs), requiring all such dealings to be licensed unless exempted, with strict liability for breaches. It mandates risk assessment and risk management planning for intentional releases into the environment under Section 50 and oversight by the Gene Technology Regulator.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-qms",
      "cartagena-protocol-biosafety-2000"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-gene-technology-act-2000-ogtr",
    "title": "Gene Technology Act 2000 (Cth)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The Act requires any person dealing with a genetically modified organism (GMO) to obtain a licence (Section 32) and to comply with licence conditions, including preparation of a risk assessment and risk management plan for intentional releases (Section 50) and public notification of those documents (Section 52).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "cbd-convention-biological-diversity-1992",
      "eu-biosafety-contained-use-directive-2009-41"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "australia-heavy-vehicle-national-law-2012-nhvr",
    "title": "Australia Heavy Vehicle National Law 2012 - NHVR Chain of Responsibility and Fatigue Management",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Australia's Heavy Vehicle National Law (HVNL) 2012 (Queensland Act No. 24 of 2012, adopted by most states and territories) administered by the National Heavy Vehicle Regulator (NHVR) establishes a Chain of Responsibility (CoR) framework making all parties in the supply chain (scheduler, consignor, consignee, packer, loader, operator) liable for breaches; mandates fatigue management schemes with maximum driving windows; sets mass, dimension, and loading standards; and imposes penalties up to AUD 300,000 for severe CoR breaches.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fmcsa-motor-carrier-safety-regulations-49-cfr"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "australia-higher-education-support-act-2003",
    "title": "Higher Education Support Act 2003",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Higher Education Support Act 2003 (HESA) establishes the legal framework for Commonwealth financial support of higher education in Australia, including student assistance through HELP loans, provider eligibility for grants, and performance-based funding. It applies to higher education providers, students, and the Department of Education, under Part 2-1 (Section 19) and Part 3-1 (Section 62).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-irap-cloud-assessment-2023",
    "title": "Information Security Registered Assessors Program: Cloud Service Assessment Methodology, PROTECTED/SECRET Level Controls, ISM Control Mapping, Continuous Monitoring Plan and ASD Endorsed Cloud Services List",
    "domain": "Cloud & SaaS",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires cloud service providers (CSPs) handling Australian Government data at PROTECTED or SECRET levels to undergo a formal security assessment by an ASD-accredited IRAP assessor. Compliance is mandated under the Australian Government Information Security Manual (ISM) and involves implementation of specific security controls mapped to ISM requirements, continuous monitoring, and inclusion on the ASD Endorsed Cloud Services List (ECSL). Key controls are defined in the IRAP Assessment Methodology v2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "cobit-2019-governance-framework",
      "enisa-cloud-security-guidelines-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-migration-act-1958-department-home-affairs",
    "title": "Australia Migration Act 1958 - Visa Framework, Detention and Removal",
    "domain": "Immigration & Border Control",
    "version": "4.1",
    "last_updated": "2026-05-10",
    "bluf": "The Migration Act 1958 (Cth) is Australia's principal immigration statute, governing all aspects of visas, border control, detention, and removal of non-citizens. Section 189 creates a duty for any officer to detain an unlawful non-citizen. Section 501 empowers the Minister to cancel any visa on character grounds, including a spent conviction for any offence. Australia operates mandatory immigration detention under s.196 until grant of a visa, removal or deportation. The offshore processing framework under ss.198AB-198AH permits transfer to Regional Processing Countries. The Australian Border Force (ABF) and Department of Home Affairs administer the Act. Over 100 visa subclasses are prescribed under the Migration Regulations 1994.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "unhcr",
        "icao_doc",
        "five_eyes",
        "privacy_act",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-motor-vehicle-standards-act-2018-mvsa",
    "title": "Australia Road Vehicle Standards Act 2018 (RVSA) - Type Approval and Register of Approved Vehicles",
    "domain": "Automotive & Mobility",
    "version": "2.0.0",
    "last_updated": "2026-07-03",
    "bluf": "Australia's Road Vehicle Standards Act 2018 (Cth) (RVSA, Act No. 163 of 2018, fully implemented 1 July 2021, replacing the Motor Vehicle Standards Act 1989) and the Road Vehicle Standards Rules 2019 establish the national framework for supplying road vehicles to the Australian market, administered by the Department of Infrastructure, Transport, Regional Development, Communications, Sport and the Arts. The Minister determines national road vehicle standards, the Australian Design Rules (ADRs), under section 12; the Secretary keeps the Register of Approved Vehicles (RAV) under section 14; and a road vehicle must be entered on the RAV, via the type approval pathway or the concessional RAV entry approval pathway (section 15), before it is provided for the first time in Australia (section 24). Importing a road vehicle requires cover under a type approval, an import approval, or a circumstance set out in the Rules (section 22). The RAV is publicly searchable and replaced the physical compliance (identification) plates required under the former 1989 Act. Recalls are governed by Part 3 and enforcement by Part 4 through the Regulatory Powers (Standard Provisions) Act 2014. Electric vehicles must additionally meet ADR 109 (Electric Power Train Safety Requirements), and all applications are lodged through the ROVER online portal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unece-r155-automotive-cybersecurity-2021",
      "eu-general-safety-regulation-2019-2144-automated-vehicles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-myhealthrecord-act-2012-2026",
    "title": "My Health Record Act 2012 (Australia) - Data Governance and Secondary Use Controls",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The My Health Record Act 2012 governs the collection, use, and disclosure of health information in Australia’s national digital health record system. It includes strict rules for primary use (healthcare delivery) and secondary use (research and public health) with opt-out mechanisms, authorised representative rules, and penalties for unauthorised access or disclosure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "australia-national-av-policy-framework-2023",
    "title": "Australia Automated Vehicle Safety Reform - NTC Regulatory Framework and Proposed Automated Vehicle Safety Law (AVSL): Automated Driving System Entity (ADSE) Safety Duties, Trials, Operational Design Domain and In-Service Safety on Public Roads",
    "domain": "Automotive & Mobility",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "Australia regulates automated vehicles through the National Transport Commission (NTC) reform program rather than a single 2023 instrument. The NTC policy paper 'The regulatory framework for automated vehicles in Australia' (February 2022) and the 'Guidelines for trials of automated vehicles in Australia' set the agreed national approach, and transport ministers have agreed to develop a new Commonwealth Automated Vehicle Safety Law (AVSL) to regulate in-service safety. Under the proposed AVSL an Automated Driving System Entity (ADSE) - a corporation - takes responsibility for the safety of the automated driving system across its design life through a general safety duty supported by reporting and information-management obligations. Cybersecurity and software-update obligations align with UN Regulations No. 155 and No. 156. Operators should treat the AVSL design and the NTC trial guidelines as the governing requirements, not a numbered set of 'Principles'.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-national-road-safety-strategy-2021-2030",
      "sae-j3016-levels-driving-automation-2021",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "oecd-regulatory-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-national-code-2018-international-students",
    "title": "National Code of Practice for Providers of Education and Training to Overseas Students 2018",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This code, established under the Education Services for Overseas Students (ESOS) Act 2000, imposes legally enforceable standards on registered providers of education to international students in Australia. It mandates specific obligations for marketing, enrolment, student support, and monitoring of course progress and attendance, as detailed in Standards 8 and 9, to ensure compliance with student visa conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-national-construction-code-2022",
    "title": "National Construction Code 2022 - Technical Design and Construction Provisions for Safety, Health, Amenity, Accessibility and Sustainability of Buildings",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The National Construction Code 2022 sets minimum technical requirements for the design, construction and performance of buildings in Australia, including safety, accessibility and energy efficiency. It applies to all new buildings and major renovations under Volume One (Classes 2-9), Volume Two (Class 1 and 10) and Volume Three (plumbing and drainage), with compliance assessed via Performance Requirements and Deemed-to-Satisfy Provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-national-construction-code-2022-ncc"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-national-construction-code-2022-ncc",
    "title": "Australian National Construction Code 2022 (NCC/BCA) - Performance Requirements, Deemed-to-Satisfy Provisions and Energy Efficiency Standards for Buildings",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Australian National Construction Code 2022 (NCC) requires that all building work in Australia complies with its Performance Requirements, as outlined in Section 1 of the NCC, and applies to all building practitioners, including builders, architects, and engineers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-national-energy-retail-law-2011",
    "title": "Australia National Energy Retail Law 2011 - AER Consumer Protections and Retailer Obligations",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The National Energy Retail Law 2011 (NERL), applied in most Australian states and territories, establishes the Australian Energy Regulator (AER) as the national retail energy regulator; mandates retailer authorisation, hardship programs, life support customer protections, explicit informed consent for contract variations, and the Electricity and Gas Retail Codes; with civil penalties up to AUD 1,000,000 for serious contraventions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-nem-electricity-national-law-2024"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "australia-national-road-safety-strategy-2021-2030",
    "title": "Australia National Road Safety Strategy 2021-30 - Safe System Approach, Themes and 2030 Targets (Non-Binding National Strategy)",
    "domain": "Automotive & Mobility",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "The National Road Safety Strategy 2021-30 (NRSS) is a non-binding national policy strategy endorsed by all of Australia's federal, state and territory governments and the Australian Local Government Association, coordinated by the Office of Road Safety within the Department of Infrastructure, Transport, Regional Development, Communications and the Arts. It is NOT a binding legal instrument and does not 'mandate' obligations on road authorities or fleet operators; it sets objectives, priorities and targets that governments commit to pursue. The NRSS continues Australia's commitment to the Safe System approach and is organised around three key themes - Safe Roads, Safe Vehicles, and Safe Road Use - with Speed Management embedded across all three themes (it is not a separate numbered section). The headline 2030 targets are a reduction in annual road fatalities by at least 50% and a reduction in serious injuries by at least 30%, against a baseline, on the path toward the long-term vision of zero deaths and serious injuries (Vision Zero). The strategy is delivered through successive National Road Safety Action Plans that set out specific actions and through state and territory implementation, with progress reported via the Office of Road Safety data hub. Binding requirements on vehicles arise separately from the strategy - principally the Australian Design Rules (ADRs) made under the Road Vehicle Standards Act 2018, which is where mandatory vehicle safety standards (such as autonomous emergency braking requirements as they are phased in) actually sit; ANCAP provides independent safety ratings but is not a regulator. This node describes the NRSS as the policy framework it is and points to the ADRs and Action Plans for any mandatory or time-bound measures, rather than to invented numbered Sections or an 'Appendix C - Vehicle Safety Technology Roadmap', which do not exist in the document.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-nem-electricity-national-law-2024",
    "title": "National Electricity Law (NEL) as applied in participating jurisdictions of the National Electricity Market (NEM)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The National Electricity Law (NEL) establishes the legislative framework for Australia's National Electricity Market (NEM), mandating open access to transmission and distribution networks and setting reliability obligations for market participants. The law empowers the Australian Energy Market Commission (AEMC) to make and amend the detailed National Electricity Rules (NER) in accordance with the National Electricity Objective (Section 7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "australia-news-media-bargaining-code-2021",
    "title": "News Media and Digital Platforms Mandatory Bargaining Code 2021",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Code requires designated digital platforms to negotiate in good faith with Australian news businesses for payment for the inclusion of news content on their platforms, or face compulsory arbitration under Part 4. It applies to platforms with significant bargaining power and news businesses producing content in or about Australia, as defined in Section 9 and Part 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "copyright-fair-use-us",
      "iptc-photo-metadata",
      "iptc-video-metadata",
      "doi-digital-object-id"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-nger-act-2007-greenhouse-energy-reporting",
    "title": "Australia National Greenhouse and Energy Reporting Act 2007 (NGER Act)",
    "domain": "Energy & Utilities",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Australia's National Greenhouse and Energy Reporting Act 2007 (Cth) requires corporations that meet threshold tests (scope 1+2 emissions ≥25,000 tCO2-e or energy production/consumption ≥100 TJ at corporate group level) to register with the Clean Energy Regulator, report annual greenhouse gas emissions and energy data for each facility and the corporate group, and comply with the NGER Measurement Determination - with civil penalties up to AUD 222,000 for non-disclosure and AUD 11,100 per day for continuing breaches.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-safeguard-mechanism-reform-act-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "australia-nger-act-2007-national-greenhouse-energy-reporting",
    "title": "Australia NGER Act 2007 - National Greenhouse and Energy Reporting Scheme",
    "domain": "Sustainability & ESG",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Australia's National Greenhouse and Energy Reporting Act 2007 requires corporations meeting energy production or consumption thresholds to register with and report annually to the Clean Energy Regulator - covering Scope 1 and Scope 2 greenhouse gas emissions and energy production/consumption data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-nhmrc-biobanks-information-paper-2010",
    "title": "Australia NHMRC Biobanks Information Paper and National Statement on Ethical Conduct in Human Research",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2018-07-01",
    "bluf": "The National Health and Medical Research Council (NHMRC) Biobanks Information Paper (2010) and the National Statement on Ethical Conduct in Human Research (issued jointly with the Australian Research Council and Universities Australia, most recently updated in 2018 with the 2023 update) together form the principal ethical and governance framework for biobanking and genomic research in Australia. The Biobanks Information Paper sets non-binding but authoritative guidance on the establishment and operation of biobanks including governance, consent, data and sample sharing, and return of results.\n\nThe National Statement requires institutional Human Research Ethics Committee (HREC) approval for all research involving humans, human tissue, or identifiable human data. Chapter 3.3 of the National Statement addresses Human Biospecimens including consent for collection, storage, and future research uses. Chapter 3.5 addresses Genomic Research including specific consent procedures for whole-genome sequencing and the management of incidental findings. Genomic research must comply with the Australian Privacy Principles under the Privacy Act 1988 (Cth) and the prohibitions on heritable genome editing under the Prohibition of Human Cloning for Reproduction Act 2002 (Cth) and the Research Involving Human Embryos Act 2002 (Cth). Cross-border sharing of biospecimens requires Material Transfer Agreement on the NHMRC-recommended template and may engage the Customs (Prohibited Imports) Regulations 1956 controls on human tissue.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-notifiable-data-breaches-scheme-2018",
    "title": "Notifiable Data Breaches (NDB) Scheme under Part IIIC of the Privacy Act 1988",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Notifiable Data Breaches (NDB) scheme, under Part IIIC of Australia's Privacy Act 1988, requires entities to notify individuals and the Office of the Australian Information Commissioner (OAIC) of any 'eligible data breach' likely to result in serious harm. Section 26WE mandates a swift assessment of a suspected breach within 30 days, and Section 26WK requires notification as soon as practicable if the breach is confirmed as eligible.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "australia-privacy-act-1988-2022-review",
    "title": "Australia Privacy Act 1988 and the Privacy Act Review Report 2022 Proposals",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Australian Government's 2022 Privacy Act Review proposes significant reforms, including a GDPR-style right to erasure (Proposal 18.2), an unqualified right to object to direct marketing (Proposal 19.3), mandatory Privacy Impact Assessments for high-risk activities (Proposal 22.1), removal of the small business exemption (Proposal 6.1), and a new statutory tort for serious invasions of privacy (Proposal 27.1). These proposals aim to modernize Australia's privacy framework, requiring organizations to enhance data handling practices, individual rights management, and accountability mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-privacy-act-1988",
      "gdpr-article-17-right-erasure",
      "gdpr-article-35-dpia",
      "apec-cbpr-system-2011",
      "oecd-privacy-guidelines-2013"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "australia-privacy-act-1988-app-notifiable-data-breaches",
    "title": "Australia Privacy Act 1988 - Australian Privacy Principles (APPs) and Notifiable Data Breaches (NDB) Scheme",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The Privacy Act 1988 (Cth) binds Australian Government agencies and APP entities (organisations with annual turnover >$3M plus specified smaller organisations) to 13 Australian Privacy Principles governing collection, use, disclosure, and security of personal information. The Notifiable Data Breaches (NDB) scheme (Part IIIC) requires notification to OAIC and affected individuals when a breach is likely to result in serious harm. Post-2024 amendments raised maximum penalties to $50M.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-renewable-energy-electricity-act-2000-ret",
    "title": "Australia Renewable Energy (Electricity) Act 2000 - RET Scheme, LGCs, STCs and Clean Energy Regulator",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Australia's Renewable Energy (Electricity) Act 2000 (Cth) (RET Act) established the Renewable Energy Target (RET) scheme to incentivise additional electricity generation from renewable sources; from 2011 the scheme was split into the Large-scale Renewable Energy Target (LRET) and Small-scale Renewable Energy Scheme (SRES); LRET requires electricity retailers and large users (liable entities) to surrender Large-scale Generation Certificates (LGCs) equal to a legislated percentage of their electricity acquisitions each year - target was 33,000 GWh of renewable electricity per year by 2020 (achieved); SRES creates Small-scale Technology Certificates (STCs) for eligible solar PV, solar water heater, and heat pump installations, with an upfront financial benefit to households; liable entities under LRET who fail to surrender sufficient LGCs pay a shortfall charge of AUD 65 per MWh (non-tax-deductible); the Clean Energy Regulator (CER) administers both schemes including accreditation of renewable power stations, the REC Registry, compliance reporting, and enforcement; the Safeguard Mechanism (reformed July 2023) complements the RET scheme for large industrial emitters.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-national-energy-retail-law-2011"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "australia-safeguard-mechanism-reform-act-2023",
    "title": "Safeguard Mechanism Reform: Declining Baseline Trajectories, Safeguard Mechanism Credits and Trade-Exposed Assistance",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-07-01",
    "bluf": "This regulation requires Australia's largest industrial facilities (over 100,000 tonnes CO2-e direct emissions annually) to progressively reduce their net emissions by adhering to declining baselines, with a default annual reduction rate of 4.9%. It establishes Safeguard Mechanism Credits (SMCs) for facilities emitting below their baseline, as detailed in the Safeguard Mechanism (Crediting) Amendment Rule 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-security-critical-infrastructure-act-2022",
    "title": "Australia Security of Critical Infrastructure Act 2018 (as Amended 2022) - Positive Security Obligations, Enhanced Cyber Security Obligations (Systems of National Significance), Government Assistance and 12-Hour Incident Reporting",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Act requires responsible entities of Australian critical infrastructure assets to adopt a risk management program (Part 2A), maintain a register of critical assets, and mandatorily report significant cyber security incidents to the Australian Cyber Security Centre within 12 hours of becoming aware (Part 2B, Section 30BC). It also establishes enhanced obligations for designated Systems of National Significance (SoNS) and provides government assistance powers to respond to serious incidents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-essential-eight-2023",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nis2-incident-reporting-article-23",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-security-legislation-amendment-2021",
    "title": "Offshore Petroleum and Greenhouse Gas Storage Amendment (Titles Administration and Other Measures) Act 2021",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Act amends the Offshore Petroleum and Greenhouse Gas Storage Act 2006 to introduce requirements relating to change in control of registered titleholders, trailing liability for decommissioning, digital readiness, and information gathering powers. It applies to offshore petroleum and greenhouse gas storage titleholders operating in Australian waters under Schedule 1, Part 1 and Schedule 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-essential-eight-2023",
      "c-scrm-practices-systems-organizations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-space-activities-act-1998",
    "title": "Communications Legislation Amendment (Online Content Services and Other Measures) Act 2018",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Act amends communications legislation to enhance online safety and regulate online content services in Australia, primarily through amendments to the Broadcasting Services Act 1992 and the Enhancing Online Safety Act 2015. Key obligations are established under Schedule 1, which introduces new regulatory powers for the Australian Communications and Media Authority (ACMA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "itu-radio-regulations-2020-edition"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-telecommunications-interception-act-1979",
    "title": "Australia Telecommunications (Interception and Access) Act 1979 - Lawful Interception: Warrant Types, ASIO Access, Data Retention Obligations (2-Year Metadata), Stored Communications Warrants and Oversight by Inspector-General",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation governs the interception of telecommunications, access to stored communications, and data retention obligations for service providers in Australia, primarily under warrant-based authorizations and oversight by the Inspector-General of Intelligence and Security. Key provisions include warrant requirements under Division 3 of Part 2 and data retention obligations under Section 187A.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-lawful-interception-etsi-standards",
      "cisa-zero-trust-maturity-model-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-tga-austl-r-medicine-registration",
    "title": "Australian Register of Therapeutic Goods (ARTG) - Requirements for AUST R and AUST L Medicine Registration: Product Information Approval, Risk Management Plans, Classification, Quality, Safety and Efficacy Evaluation, TGA Audit System and Post-Market Review",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation governs the inclusion of medicines in the Australian Register of Therapeutic Goods (ARTG) under AUST R (registered) or AUST L (listed) pathways, requiring sponsors to demonstrate quality, safety, and efficacy, comply with classification rules (prescription vs OTC), submit approved Product Information (PI), implement Risk Management Plans (RMPs) where applicable, and adhere to TGA audit and post-market surveillance requirements under the Therapeutic Goods Act 1989, Section 23.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-tga-therapeutic-goods-act-1989"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-tga-biologicals-framework",
    "title": "Regulation of Biologicals under the Therapeutic Goods Administration (TGA) - Classification, Manufacturing, and Clinical Evidence Requirements for Class 1-4 Biologicals",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The TGA Biologicals Framework requires all biologicals (Class 1-4) to be classified based on risk, manufactured under Good Manufacturing Practice (GMP), supported by clinical evidence appropriate to class, and included in the Australian Register of Therapeutic Goods (ARTG) prior to supply. Applies to sponsors and manufacturers of human biologicals under the Therapeutic Goods Act 1989, Section 20 and Biologicals Regulatory Framework guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-q5a-r2-viral-safety-biotech-2024",
      "isber-best-practices-biorepositories-2018",
      "australia-gene-technology-act-2000",
      "cbd-convention-biological-diversity-1992",
      "nagoya-protocol-genetic-resources-2010"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-tga-digital-health-guidance-2023",
    "title": "Guidance on Digital Health Technologies - Software as a Medical Device (SaMD) Classification, Advertising Rules and Post-Market Monitoring",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This guidance outlines the Therapeutic Goods Administration's (TGA) regulatory framework for Software as a Medical Device (SaMD) in Australia, including classification rules based on risk, advertising requirements under the Therapeutic Goods Advertising Code, and post-market monitoring obligations under the Therapeutic Goods Act 1989. It applies to sponsors and developers of digital health software intended for medical purposes, particularly those seeking inclusion in the Australian Register of Therapeutic Goods (ARTG). Key provisions are derived from the Therapeutic Goods (Medical Devices) Regulations 2002 and the TGA's interpretation of SaMD under the IMDRF framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mdr-2017-745-classification-rules",
      "eu-gdpr-health-data-article-9",
      "eu-ivdr-2017-746",
      "dicom-imaging-standard"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-tga-medical-device-regulation-2026",
    "title": "Australia TGA - Therapeutic Goods (Medical Devices) Regulations 2002 (2026 Reforms)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The Therapeutic Goods Administration (TGA) regulates medical devices and SaMD under the Therapeutic Goods Act 1989 and Regulations 2002. 2026 reforms introduce strengthened cybersecurity requirements, AI-specific guidance, mandatory unique device identification (UDI), enhanced post-market surveillance, and alignment with IMDRF principles. Devices are classified A-D with conformity assessment procedures scaled to risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-myhealthrecord-act-2012-2026"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "australia-tga-therapeutic-goods-act-1989",
    "title": "Therapeutic Goods Act 1989",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Therapeutic Goods Act 1989 requires that all therapeutic goods be included in the Australian Register of Therapeutic Goods (ARTG) before they can be supplied in Australia, as per Section 9 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-qms",
      "ich-gcp-e6-r3-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-transfer-pricing-laws-amendment-2012",
    "title": "Australia Transfer Pricing Laws Amendment Act 2012",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Australia Transfer Pricing Laws Amendment Act 2012 requires that Australian taxpayers ensure their cross-border transactions with related parties are conducted at arm's length, as per Section 815-130 of the Income Tax Assessment Act 1997. This applies to all Australian entities with international related party dealings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-attribution-profits-permanent-establishments-2010",
      "oecd-financial-transactions-transfer-pricing-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "australia-voluntary-ai-safety-standard-2024",
    "title": "Australia Voluntary AI Safety Standard (Department of Industry, Science and Resources, August 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The Australian Government Department of Industry, Science and Resources published the Voluntary AI Safety Standard on August 22, 2024. The Standard is non-mandatory practical guidance for Australian organisations developing or deploying AI systems, designed to support the Government's interim response to the Safe and Responsible AI in Australia consultation. The Standard establishes ten guardrails: (1) Establish, implement, and publish an accountability process including governance, internal capability, and a strategy for regulatory compliance; (2) Establish and implement a risk management process to identify and mitigate risks; (3) Protect AI systems and implement data governance measures to manage data quality and provenance; (4) Test AI models and systems to evaluate model performance and monitor the system once deployed; (5) Enable human control or intervention in an AI system to achieve meaningful human oversight; (6) Inform end-users regarding AI-enabled decisions, interactions with AI, and AI-generated content; (7) Establish processes for people impacted by AI systems to challenge use or outcomes; (8) Be transparent with other organisations across the AI supply chain about data, models, and systems to help them effectively address risks; (9) Keep and maintain records to allow third parties to assess compliance with the guardrails; (10) Engage your stakeholders and evaluate their needs and circumstances, with a focus on safety, diversity, inclusion, and fairness. The Standard is the precursor to mandatory guardrails for high-risk AI under the Australian Government's Safe and Responsible AI proposals, which align Australia with EU AI Act risk-based approach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "nist_framework",
        "iso_standard",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-ai-ethics-framework-2019",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "australia-wa-mineral-resources-act-1989",
    "title": "Australia - Western Australia Mineral Resources Act 1989 - Mining Tenement Framework",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2023-07-01",
    "bluf": "Western Australia's Mineral Resources Act 1989 (MRA) administered by the Department of Energy, Mines, Industry Regulation and Safety (DEMIRS) and the Mining Warden Courts governs the grant, transfer, renewal, and forfeiture of all WA mining tenements including Exploration Licences (ELs), Retention Licences (RLs), Mining Leases (MLs), and General Purpose Leases (GPLs) over WA's iron ore, gold, lithium, and nickel mining industry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "extractive-industries-transparency-eiti-standard",
      "gri-14-mining-sector-standard-2022",
      "gistm-global-tailings-management-standard-2020",
      "australia-epbc-act-1999-mining-biodiversity"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-water-act-2007-murray-darling-basin",
    "title": "Australia Water Act 2007 - Murray-Darling Basin Plan and Water Access Entitlement Framework",
    "domain": "Water & Environmental Resources",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The Water Act 2007 (Cth) established the Murray-Darling Basin Authority (MDBA) and the legal framework for the Murray-Darling Basin Plan. The Murray-Darling Basin - spanning Queensland, New South Wales, Victoria, South Australia, and the Australian Capital Territory - is Australia's most significant agricultural water catchment, producing approximately 40% of national food output. The Basin Plan 2012 (consolidated 2022) sets Sustainable Diversion Limits (SDLs) for both surface water and groundwater, requiring a net reduction in diversions from the Basin. Water access entitlements (WAEs) are separate from land rights and are allocated by state governments within the SDL framework. The Commonwealth Environmental Water Holder (CEWH) manages Commonwealth environmental water to maintain ecological values. Water markets allow WAEs to be traded. The Inspector-General of Water Compliance provides independent oversight of Basin Plan implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "national_water_initiative",
        "environment_protection",
        "state_water_law",
        "water_markets",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "australia-whs-act-2011-model-work-health-safety-pcbu-duties",
    "title": "Australia Work Health and Safety Act 2011 - PCBU Primary Duty of Care & Safe Work Method Statements",
    "domain": "Construction & Real Estate",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Australia's model Work Health and Safety Act 2011 (adopted by most jurisdictions) imposes a primary duty of care on Persons Conducting a Business or Undertaking (PCBUs) to ensure worker health and safety \"so far as is reasonably practicable\" - with Safe Work Method Statements mandatory for high-risk construction work and penalties up to AUD 3 million for body corporates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-model-work-health-safety-act-2011-pcbu-duties-whs-officers"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "austria-space-activities-act-2011",
    "title": "Austria Space Activities Act 2011 (Weltraumgesetz) - Austrian National Space Regulatory Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Austria's Space Activities Act (Bundesgesetz über Tätigkeiten im Weltraum - Weltraumgesetz, BGBl. I Nr. 132/2011) entered into force on 28 December 2011 and established a licensing regime for space activities conducted by Austrian legal persons or from Austrian territory. The Act requires authorisation from the Federal Minister for Transport, Innovation and Technology (BMVIT, now Bundesminister for Climate Action / BMK) for all qualifying space activities. Austria is an ESA member state and a founding member of EUMETSAT; the Austrian Space Applications Programme (ASAP) is administered by the Austrian Research Promotion Agency (FFG) under BMK. The Act implements Austria's obligations under the five UN space treaties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "esa_convention_1975",
        "copuos_lts_guidelines"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "esa-convention-1975-european-space-agency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "automated-fact-verification",
    "title": "Deterministic RAG Verification",
    "domain": "AI Governance & Law",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Deterministic RAG (Retrieval-Augmented Generation) verification is a systematic process for cross-referencing AI-generated claims against authoritative knowledge bases to detect and block hallucinated, fabricated, or unsupported outputs before they reach end users. The process extracts discrete factual claims from model outputs, retrieves supporting or contradicting evidence from verified knowledge sources, computes an entailment score for each claim, and either passes, flags, or blocks the response based on configurable confidence thresholds. This approach is aligned with NIST AI RMF MEASURE function requirements for AI output accuracy, the EU AI Act Article 13 transparency requirements, and emerging RAG security best practices addressing prompt injection and knowledge base poisoning. Failure to implement fact verification in high-stakes AI deployments (medical, legal, financial) can result in actionable misinformation, regulatory liability, and loss of user trust.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-high-risk",
      "iso-42001-risk-assess",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "automation-bpmn-agent-handover",
    "title": "Agent-to-Agent Handover Protocol (BPMN 2.0)",
    "domain": "Workflow Automation",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Enforcing a zero-trust model for state transitions within distributed business processes, the Agent-to-Agent Handover Protocol aligns with NIST SP 800-207's micro-segmentation principles. Secure communication is mandated through a `require_mutual_tls_auth` policy, preventing unauthorized interception. Conforming to IETF RFC 8725 best practices, decentralized authorization is enforced via an `enforce_oauth2_jwt_bearer` mechanism. The protocol upholds the BPMN 2.0 Specification's token execution semantics by ensuring a `bpmn_process_id_required` for every transfer, maintaining process context continuity. State integrity is guaranteed with a `require_state_integrity_hash` validation upon receipt. System security and resilience, as outlined in NIST AI 100-1, are addressed by limiting handover failures to a `max_retries_on_handover_fail` of 3 and capping `max_token_transfer_latency_ms` at 500 milliseconds. Furthermore, a `require_recipient_capacity_check` prevents resource exhaustion. Data protection by design, a cornerstone of GDPR Article 25, is implemented through a strict `require_pii_redaction_prior_to_transfer` rule and a transient `data_retention_in_transit_seconds` of 60 seconds. Following secure engineering guidelines from ISO/IEC 27001, the system must `enforce_least_privilege_context` for all exchanged data, and any cryptographic downgrade is forbidden as `allow_downgrade_encryption` is false. Comprehensive oversight is maintained with an `audit_log_level_minimum` set to 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-207",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "nist-sp-800-63b-authentication",
      "agent-kill-switch",
      "ieee-3931-discovery"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "automation-bpmn-error-boundary",
    "title": "Error Boundary Logic (BPMN 2.0)",
    "domain": "Workflow Automation",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Ensuring predictable failure prevention and operational resilience, this BPMN 2.0 configuration aligns with stringent international standards. To satisfy mandates within the EU Digital Operational Resilience Act (DORA) for deterministic automated failover, an active `interrupting_boundary_event` coupled with a defined `fallback_path` executes if a service task exceeds its `5000` millisecond timeout. This boundary defense mechanism supports NIST SP 800-53 requirements for failing to a known, secure state. Processes are limited to `3` retry attempts before initiating escalation, and critical faults mandate a `human_in_loop` for resolution, reflecting the Basel Committee's principles for robust incident management. In furtherance of ISO 27001's framework for ICT readiness, business continuity is bolstered by a `15`-minute maximum recovery time objective, directly supporting GDPR's mandate for timely data restoration. Adherence to PCI DSS is achieved by logging every `error_code` upon catch and issuing an immediate SOC alert on any authentication fault (`alert_soc_on_auth_fault`). Enabled `compensation_handling`, escalation on SLA breaches, and a `24`-hour termination for stale processes collectively create a resilient, auditable, and compliant execution environment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dora-ict-risk",
      "bcbs-principles-operational-resilience",
      "iso-22301-biz-continuity",
      "nist-sp-800-160-v2r1",
      "automation-bpmn-service-task",
      "nist-800-53-au2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "automation-bpmn-service-task",
    "title": "Service Task Execution Pattern (BPMN 2.0)",
    "domain": "Workflow Automation",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Standardized, deterministic service tasks for executing automated logic within a business process, ensuring interoperability between agents and external systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "automation-bpmn-error-boundary",
      "nist-sp-800-218-ssdf"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "automation-support-for-control-assessments",
    "title": "Automation Support for Control Assessments: Project Update and Vision",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2023-12-06",
    "bluf": "In 2017, the National Institute of Standards and Technology (NIST) published a methodology for supporting the automation of Special Publication (SP) 800-53 control assessments in the form of Interagency Report (IR) 8011. IR 8011 is a multi-volume series that proposes an approach for creating specific tests, denominated as 'defect checks,' that can be executed using automation to help verify that controls are in place and operating as expected. The methodology supports the NIST Risk Management Framework (RMF) and was developed to ultimately support information security continuous monitoring (ISCM) activities, including ongoing assessments and ongoing authorizations.\n\nFollowing an internal review in 2023, the IR 8011 Development Team identified opportunities to improve the current IR 8011 methodology and facilitate its adoption. This cybersecurity white paper summarizes the findings from this review, which include plans to restructure the IR 8011 workflow for readability, expand keyword search functions, and abstract the security framework so the model can be used with any control-based framework. The ultimate goal is the operationalization of IR 8011, transforming the NIST-produced 'blueprint' into a solution that can benefit agencies and organizations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-8011-v1-automated-assessments",
      "nist-sp-800-53-r5",
      "assessing-security-privacy-controls",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-cswp-30-automation-support"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "automotive-spice-pam-3-1",
    "title": "Automotive SPICE (ASPICE) PAM 3.1 - Process Assessment Model: SYS, SWE, SUP, MAN Process Areas, Capability Levels and Assessment Indicators for Automotive Software Engineering",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Automotive SPICE PAM 3.1 defines a process reference and assessment model for evaluating the capability of software and systems engineering processes in the automotive industry. It applies to suppliers and OEMs developing automotive electronics and embedded software, requiring conformance to capability levels 0-5 across 32 processes in SYS, SWE, SUP, and MAN groups as specified in Clause 8.3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "autonomous-trucking-v2v",
    "title": "Autonomous Trucking V2V Security",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with this node ensures secure vehicle-to-vehicle (V2V) communications for autonomous trucking platoons by enforcing a comprehensive suite of cybersecurity controls derived from established automotive and security standards. The framework mandates that all messages utilize authentication through a Security Credential Management System (SCMS) and require Elliptic Curve Digital Signature Algorithm (ECDSA) message signatures for integrity, a core principle of IEEE 1609.2-2016. All cryptographic operations must be executed within a hardware security module (HSM) validated against FIPS 140-3 security requirements, and sensitive data payloads demand AES-256 encryption. For operational integrity, Basic Safety Messages (BSMs), defined within the SAE J2735 message set dictionary, must maintain a minimum broadcast frequency of 10 Hz with a maximum V2V latency of 20 milliseconds. Platoon configurations are strictly governed by the SAE J3134 reference architecture, limiting formations to a maximum of 5 vehicles and stipulating a minimum following distance of 15 meters. To counter persistent threats and align with the cybersecurity engineering principles of ISO/SAE 21434, the system requires an active misbehavior detection system and jamming interference detection capabilities. Privacy is protected through a mandatory pseudonym certificate rotation every 5 minutes. These measures collectively satisfy the Cyber Security Management System (CSMS) mandates outlined in UNECE WP.29 Regulation No. 155, establishing a secure and trusted operational environment for connected autonomous vehicle fleets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "tisaq-auto-cyber",
      "iso-39001-road-traffic",
      "supply-chain-risk-triage",
      "nist-sp-800-161r1-csrm-practices"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "autosar-adaptive-platform-ara-standard",
    "title": "AUTOSAR Adaptive Platform 22-11 - Adaptive Application Architecture: Service-Oriented Communication, Execution Management, Update and Config Management and Cryptography APIs",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This standard defines the architecture and interfaces of the AUTOSAR Adaptive Platform, including service-oriented communication, runtime execution, and cryptographic services for adaptive automotive applications. It applies to automotive software developers and system integrators implementing adaptive vehicle systems using the AUTOSAR Runtime for Adaptive Applications (ARA). Key provisions include functional cluster requirements and dynamic service linking during runtime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "iso-26262-functional-safety-road-vehicles-2018",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "aw-lbp-2010",
    "title": "Aruba National Ordinance on Personal Records (Landsverordening Persoonsregistratie), 2011",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "Aruba, a constituent country of the Kingdom of the Netherlands, regulates personal data through the National Ordinance on Personal Records (Landsverordening Persoonsregistratie), the national ordinance of 19 May 2011, modelled on the former Dutch data-protection framework. Aruba does NOT have a dedicated independent data protection authority; oversight rests with the Minister of Justice (there is no body named 'Autoridad pa Supervishon di Dato Personal (ASD)'). The Ordinance establishes principles for the lawful processing of personal data, grants data subjects rights of access, correction, and objection, requires controllers to notify processing of personal records to the responsible authority, mandates appropriate security measures, and restricts cross-border transfers to countries providing adequate protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/aw-lbp-2010.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "aws-shared-responsibility-model-workloads",
    "title": "AWS Shared Responsibility Model - Customer Workload Obligations: Security IN the Cloud (OS Patching, Network Configuration, Application Security, Data Encryption), AWS Security OF the Cloud (Hypervisor, Physical Data Centres, Global Network) and Managed Service Boundary Variations",
    "domain": "Cloud & SaaS",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation outlines the division of security responsibilities between AWS and its customers, where AWS is responsible for Security 'of' the Cloud (infrastructure, hardware, facilities), and customers are responsible for Security 'in' the Cloud, including guest OS patching, application security, data encryption, and firewall configuration. Key obligations are defined in the AWS Shared Responsibility Model documentation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "cobit-2019-governance-framework",
      "enisa-cloud-security-guidelines-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "aws-step-functions-workflow-states",
    "title": "AWS Step Functions Workflow States and Governance",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "AWS Step Functions is a service that enables the creation of workflows, also called state machines, to build distributed applications, automate processes, orchestrate microservices, and create data and machine learning pipelines. It provides two workflow types: Standard and Express, each with its own execution characteristics, such as execution rate, state transition rate, and pricing. Step Functions integrates with multiple AWS services, supporting various integration patterns, including Request Response, Run a Job, and Wait for Callback. It also provides features like error handling, retry mechanisms, and human approval steps, allowing for flexible and robust workflow design. The service supports the creation of long-running, automated workflows for applications that require human interaction, and it provides a console for visualizing, editing, and debugging workflows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-32-security-of-processing",
      "iso-9001-quality-management-construction",
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ax-gdpr-2018",
    "title": "Åland Islands - EU GDPR and Finnish Data Protection Ombudsman Supervisory Framework",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Åland Islands (Ahvenanmaa in Finnish) is an autonomous, demilitarized, and monolingually Swedish-speaking province of Finland located in the Baltic Sea. As an autonomous province of an EU member state, Åland is fully subject to EU law including the General Data Protection Regulation (GDPR), which applies directly and with full force in Åland. The Finnish Data Protection Ombudsman (Tietosuojavaltuutettu / Dataskyddsombudsmannen) is the competent supervisory authority for data protection matters in Åland. The Finnish Data Protection Act (Tietosuojalaki 2018) implements GDPR-compatible national provisions applicable in Åland. While the Åland Parliament (Lagting) has legislative autonomy in certain areas under the Act on the Autonomy of Åland, data protection falls within EU competence and is governed by the GDPR directly applicable throughout Finnish territory including Åland. Åland's demilitarized status, established by international treaty, and its distinct Swedish-language administration make it a unique regulatory environment within the EU data protection framework. Organisations established in Åland or processing personal data of individuals located in Åland must comply with the GDPR and Finnish national data protection law, including requirements for lawful basis, data subject rights, data protection by design and by default, data protection impact assessments for high-risk processing, mandatory breach notification to the Finnish Data Protection Ombudsman within 72 hours, and appointment of a Data Protection Officer where required.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ax-gdpr-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "az-law-on-space-activity-2023",
    "title": "Azerbaijan Law No. 927-VIQ on Space Activity (2023)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Azerbaijan's Law on Space Activity governs space activity carried out through space objects registered in the State Registry of space objects of the Republic of Azerbaijan. Title and other property rights over space objects must be registered in the Registry (Article 8), and orbital positions and associated radio frequencies allocated to the Republic of Azerbaijan belong to the state and are allocated to space operators under the laws on licenses and permits and on telecommunications (Article 9). The amount of insurance or other financial guarantee covering the risk of damage to third parties by a space object is used to pay claims based on the relevant treaty, and operators and title holders must comply with third-party liability insurance terms (Article 12). The Law provides for a satellite system for remote Earth observation (Article 16) and enters into force 60 days after its publication (Article 24). It applies to subjects of space activity operating through the national space operator.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-registration-convention-1976-space",
      "un-liability-convention-1972-space-objects"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "az-pdp-law-2010",
    "title": "Azerbaijan Law on Personal Data 2010 - Supervisory Executive Authority",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Azerbaijan's Law on Personal Data (Fərdi məlumatlar haqqında Qanun) - Law No. 998-IIIQ, adopted by the Milli Majlis (National Assembly) of the Republic of Azerbaijan on 11 May 2010 and signed by President Ilham Aliyev, entering into force on 26 October 2010 - is Azerbaijan's primary personal data protection legislation, establishing a framework for the protection of personal data of natural persons in Azerbaijan. The law has been amended to reflect technological developments and to align Azerbaijan's data protection framework with international standards. The supervisory function for personal data protection in Azerbaijan is exercised by the relevant executive authority - in practice the Ministry of Digital Development and Transport and associated e-government bodies; the Law does not establish a single standalone commission as the supervisory body. Azerbaijan's data protection legislation was developed in the context of the country's broader e-government initiatives and digital economy strategy, reflecting Azerbaijan's position as a Caspian energy economy increasingly integrating into global digital infrastructure. Key features of Azerbaijan's Law on Personal Data 2010: (1) Scope - applies to the processing of personal data by state bodies, legal entities, and individuals in Azerbaijan; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; proportionality; accuracy; storage limitation; security; and confidentiality; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political views; religious or philosophical beliefs; trade union membership; health status; criminal convictions; biometric data; and financial data; (4) Data subject rights - right of access to personal data; right to rectification of inaccurate data; right to erasure; right to object to processing; and right to complain to the relevant executive authority; (5) Consent - required for personal data processing as the primary lawful basis; explicit consent for sensitive personal data; consent must be informed, voluntary, and expressed; (6) State registration - operators (data controllers) must register with the relevant executive authority before commencing personal data processing; (7) Cross-border transfers - personal data may be transferred to states providing equivalent protection; transfers to non-equivalent states require the relevant executive authority's consent or specific statutory basis; (8) Security obligations - operators must implement technical and organisational security measures to protect personal data; (9) Executive authority enforcement - the relevant executive authority investigates complaints; conducts inspections; issues binding orders; imposes administrative sanctions; (10) E-government context - Azerbaijan's digital government programmes (ASAN Service, ASAN Xidmət, electronic government portal) process significant personal data subject to the law. Azerbaijan's data protection framework intersects with the country's participation in the Council of Europe, Convention 108 obligations, and its Association Partnership with the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "azure-logic-apps-enterprise-integration",
    "title": "Azure Logic Apps: Enterprise Integration, Connectors, Managed Identity, VNet Integration and B2B EDI Governance",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Azure Logic Apps provide scalable workflow orchestration and enterprise integration, requiring strict governance over managed identities, VNet isolation, and custom API connectors to secure B2B data exchange.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ba-pdpa-2006",
    "title": "Bosnia and Herzegovina Law on Protection of Personal Data No. 49/06 - AZLP",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Bosnia and Herzegovina's Law on Protection of Personal Data (Zakon o zaštiti ličnih podataka / Zakon o zaštiti osobnih podataka), adopted by the Parliamentary Assembly of Bosnia and Herzegovina in 2006 (Official Gazette BiH No. 49/06) and amended through Official Gazette BiH No. 76/11 and subsequent legislative revisions, is Bosnia and Herzegovina's primary personal data protection legislation establishing a rights-based framework for the processing and protection of personal data across all three entities - the Federation of Bosnia and Herzegovina, the Republika Srpska, and the Brčko District. Bosnia and Herzegovina's complex constitutional structure under the Dayton Peace Agreement requires state-level legislation to govern matters that cross entity boundaries, making the Law the binding standard across all public and private sector controllers. The supervisory authority is the Agency for Personal Data Protection (Agencija za zaštitu ličnih podataka / Agencija za zaštitu osobnih podataka - AZLP), an independent state-level institution headquartered in Banja Luka, whose mandate covers oversight and enforcement of the Law across all entities. Key features of the Bosnia and Herzegovina Law on Protection of Personal Data: (1) Scope - applies to personal data processing by state bodies, public authorities, legal entities, and individuals in Bosnia and Herzegovina regardless of processing location where data subjects are located in BiH; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; proportionality (data minimisation); accuracy; storage limitation; and security; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual life; criminal convictions; and financial status; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to object; and rights relating to automated decision-making; (6) Controller registration - controllers must register processing activities with the AZLP before commencing processing; the AZLP maintains a publicly accessible Register of Personal Data Processing Activities; (7) Security obligations - controllers must implement technical and organisational security measures appropriate to the risk; (8) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or with specific AZLP authorisation using approved transfer mechanisms; (9) AZLP enforcement - investigates complaints, conducts inspections, issues binding orders, and imposes administrative fines; and (10) EU accession context - Bosnia and Herzegovina was granted EU candidate status in 2022 following the Stabilisation and Association Agreement; EU accession obligations are driving progressive harmonisation of the Law toward the EU acquis including GDPR standards. The Law predates the GDPR era and is less aligned with GDPR standards than some Western Balkan neighbours, including Serbia and Montenegro; the ongoing EU accession process is the primary driver for future GDPR-alignment amendments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bahamas-dare-act-2020-digital-assets",
    "title": "Bahamas Digital Assets and Registered Exchanges (DARE) Act, 2020",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Act establishes a comprehensive regulatory framework for digital asset businesses operating in or from The Bahamas, requiring mandatory registration with the Securities Commission for conducting specified activities (Part II, Section 7) and imposing strict obligations for capital, insurance, and client asset custody.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bahrain-cbb-rulebook-aml-cft-module",
    "title": "Central Bank of Bahrain (CBB) Rulebook, Volume 1: Conventional Banks, Module FC: Financial Crime - Customer Due Diligence, PEPs, and Suspicious Transaction Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The CBB Rulebook's Financial Crime (FC) Module mandates that all licensees in Bahrain implement a comprehensive, risk-based approach to AML/CFT, requiring detailed Customer Due Diligence (CDD), Enhanced Due Diligence (EDD) for high-risk customers including Politically Exposed Persons (PEPs), and mandatory reporting of suspicious transactions to the Financial Intelligence Directorate (FID) as stipulated in sections FC-1, FC-2, and FC-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "fatf-guidance-virtual-assets-vasp"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bahrain-pdp-law-30-2018",
    "title": "Bahrain Personal Data Protection Law No. 30 of 2018",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Bahrain's Personal Data Protection Law (PDPL) establishes a comprehensive data protection framework for organizations processing personal data, mandating adherence to eight core principles outlined in Article 4. It requires data controllers to notify the Personal Data Protection Authority (PDPA) before processing, sets strict conditions for international data transfers (Article 12), and grants specific rights to data subjects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-46-transfer-mechanisms",
      "oecd-privacy-guidelines-2013",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bangladesh-passport-travel-documents-ordinance-1973",
    "title": "The Bangladesh Passport Order, 1973 (President's Orders No. 9 of 1973) - BIDA Work Permit and Visa Framework",
    "domain": "Immigration & Border Control",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Bangladesh's Passport (Offences) Act 1952 and the Foreigners Act 1946 (as applied in Bangladesh) together with the Foreigners Order 1951 form the legislative basis for immigration control, supplemented by visa regulations issued by the Ministry of Home Affairs and Ministry of Foreign Affairs. The Bangladesh Investment Development Authority (BIDA) issues work permits to foreign nationals employed in private sector enterprises. No-objection certificates (NOC) are required from relevant ministries for certain categories. Work permits carry a ratio requirement: no more than 1 foreign employee per 20 Bangladeshi employees in manufacturing. VISA-on-arrival is available for selected nationalities. The passport authority is the Department of Immigration and Passports (DIP) under Ministry of Home Affairs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-foreigners-act-1946-bureau-of-immigration",
      "singapore-immigration-act-cap-133-ica"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bank-provisioning-emerging-market-economies",
    "title": "Moving in tandem: bank provisioning in emerging market economies",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2016-03-31",
    "bluf": "This study analyzes the determinants of loan loss provisions and delinquency ratios based on the balance sheets of 554 banks from emerging market economies (EMEs). The results show that provisions in EME banks respond mostly to aggregate variables, and very little to idiosyncratic factors. Specifically, bank-specific credit growth rates, often considered a measure of individual risk-taking, do not explain the level of loan loss provisions. The predominant effect observed is that provisions and actual losses are negatively related to past economic growth and positively related to past aggregate credit growth, indicating that EME banks' provisioning decisions are highly correlated.\n\nThe findings suggest that EME banks' provisioning behavior is procyclical, as provisions tend to fall when output grows. The paper also estimates the forward and backward-looking components of provisions, finding that provisions respond mainly to past reported losses and do not anticipate future increases in credit losses. This procyclical behavior, possibly driven by the difficulty of assessing economic cycle permanence in EMEs, suggests that macroprudential tools designed to counter this effect could be effective in dampening credit cycles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-9-impairment",
      "basel-ii-capital-framework",
      "basel-iii-global-regulatory-framework",
      "guidance-on-model-risk-management",
      "bcbs-sound-stress-testing-practices"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "bank-provisioning-emerging-markets",
    "title": "Moving in tandem: bank provisioning in emerging market economies",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2016-03-01",
    "bluf": "This study analyzes the determinants of loan loss provisions and delinquency ratios using balance sheet data from 554 banks in 18 emerging market economies (EMEs). The results show that provisions in EME banks respond mostly to aggregate variables and very little to idiosyncratic factors. Specifically, bank-specific credit growth rates, often considered a measure of individual risk-taking, do not explain the level of loan loss provisions. The predominant effect observed is that the level of provisions and actual losses is negatively related to past economic growth and positively related to past aggregate credit growth, suggesting that EME banks’ provisioning decisions are highly correlated.\n\nThe findings indicate that provisioning is mainly backward-looking, responding to past reported losses rather than anticipating future ones. This behavior is procyclical, as provisions tend to fall when output grows. There is also evidence supporting an \"income-smoothing\" hypothesis, where banks increase provisions when earnings are higher. The paper suggests that since provisioning decisions are highly correlated and procyclical, macroprudential tools based on aggregate variables could be effective in dampening credit cycles and procyclical behavior.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-9-impairment",
      "basel-iii-global-regulatory-framework",
      "bcbs-sound-stress-testing-practices",
      "sr-11-7-model-risk-management"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "bank-secrecy-act-suspicious",
    "title": "BSA SAR (Suspicious Activity)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Bank Secrecy Act (BSA) requires financial institutions to file a Suspicious Activity Report (SAR) for any transaction that is suspicious, appears to involve illegal activity, or has no logical business purpose. it is the primary reporting tool for the U.S. government to identify and combat money laundering, tax evasion, and terrorist financing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "wolfsberg-corresp-bank"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bar-standards-board-uk",
    "title": "Bar Standards Board (UK)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with Bar Standards Board regulations necessitates strict adherence to a framework governing professional conduct, data security, and financial integrity. Core Duty 6 establishes an uncompromising obligation to maintain client confidentiality, a principle reinforced by the UK General Data Protection Regulation and the Data Protection Act 2018. These data protection laws mandate registration with the Information Commissioner's Office as a data controller, require robust client data encryption, and impose a maximum 72-hour window for reporting significant data breaches. Furthermore, barristers must implement effective information barriers within chambers to prevent conflicts. Financially, Rule C73 explicitly prohibits the handling of client money, limiting financial transactions strictly to service payments. Practitioners must also secure and maintain adequate professional indemnity insurance with a minimum coverage of £2,500,000, as stipulated by Rule C76. Under The Money Laundering Regulations 2017, undertaking a formal anti-money laundering risk assessment is compulsory for specific practice areas like tax or property law. Professional obligations extend to continuous development, requiring annual CPD completion, and promoting transparency through mandatory diversity data collection. All records must be preserved for a minimum of seven years. Crucially, Core Duty 10 and Rule C110 impose an overarching requirement for individuals to report any serious misconduct to the BSB promptly, ensuring the profession's integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sra-code-conduct-uk",
      "compliance-gdpr-dpa",
      "uk-bribery-act-2010"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "basel-committee-financial-crisis-response",
    "title": "The Basel Committee’s response to the financial crisis: report to the G20",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2010-10-31",
    "bluf": "The Basel Committee on Banking Supervision developed a reform programme, referred to as “Basel III”, to address the lessons of the financial crisis and strengthen the resilience of banks and the global banking system. The reforms seek to improve the banking sector’s ability to absorb shocks arising from financial and economic stress, thus reducing the risk of spillover from the financial sector to the real economy. The reforms strengthen bank-level, or micro prudential, regulation to raise the resilience of individual banking institutions in periods of stress, and also have a macro prudential focus, addressing system wide risks.\n\nThe core obligations include raising the quality and level of capital to ensure banks are better able to absorb losses, including increasing the minimum common equity requirement from 2% to 4.5% and adding a capital conservation buffer of 2.5% for a total of 7%. The framework increases risk coverage for trading activities, securitisations, and counterparty credit exposures. It introduces an internationally harmonised leverage ratio as a backstop to the risk-based measures, introduces minimum global liquidity standards (a short term liquidity coverage ratio and a longer term net stable funding ratio), and promotes the build-up of capital buffers in good times that can be drawn down in periods of stress.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-ii-capital-framework",
      "basel-iii-global-regulatory-framework",
      "basel-iii-liquidity-lcr",
      "lcr-disclosure-standards"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "basel-committee-response-financial-crisis",
    "title": "The Basel Committee’s response to the financial crisis: report to the G20",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-10",
    "bluf": "In response to the financial crisis, the Basel Committee on Banking Supervision developed a reform programme, collectively referred to as “Basel III”, to address weaknesses in the banking sector such as excessive leverage, inadequate and low-quality capital, and insufficient liquidity buffers. The reforms seek to improve the banking sector’s ability to absorb shocks arising from financial and economic stress, whatever the source, thus reducing the risk of spillover from the financial sector to the real economy. The reforms strengthen bank-level, or micro prudential, regulation to raise the resilience of individual banking institutions in periods of stress, and also have a macro prudential focus, addressing system wide risks which can build up across the banking sector.\n\nThe key building blocks of Basel III include raising the quality, level, and risk coverage of the capital framework, with a minimum common equity requirement of 4.5% and a capital conservation buffer of 2.5%. It also introduces an internationally harmonised leverage ratio to serve as a backstop to the risk-based capital measure, and minimum global liquidity standards consisting of a short term liquidity coverage ratio and a longer term, structural net stable funding ratio. The reforms also promote the build up of capital buffers in good times that can be drawn down in periods of stress, including a countercyclical buffer. These new global standards apply to banking institutions and are designed to transform the global regulatory framework and promote a more resilient banking sector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-ii-capital-framework",
      "basel-iii-global-regulatory-framework",
      "basel-iii-liquidity-lcr"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "basel-convention-1989-hazardous-waste-transboundary",
    "title": "Basel Convention 1989 - Transboundary Movements of Hazardous Wastes & Their Disposal",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Basel Convention on the Control of Transboundary Movements of Hazardous Wastes and Their Disposal, adopted on 22 March 1989 in Basel, Switzerland, and entered into force on 5 May 1992, has 191 Parties and is the most comprehensive global agreement on hazardous and other wastes. The Convention controls transboundary movements of hazardous waste and requires that such movements be reduced, managed close to the source, and prevented from occurring if the receiving country cannot handle them in an environmentally sound manner (ESM). The Basel Ban Amendment (Decision III/1, adopted 1995, entered into force 5 December 2019 after 97 ratifications) prohibits all exports of hazardous wastes from OECD and EU countries (Annex VII Parties) to non-OECD and non-EU countries (non-Annex VII Parties) for any purpose including recycling. Prior Informed Consent (PIC, Articles 6 and 7) requires the exporter to notify and obtain written consent from competent authorities of importing and transit countries before any transboundary shipment. The Convention covers wastes defined as hazardous in Annex I (categorised by source) and Annex III (hazardous characteristics - explosive, flammable, toxic, corrosive, infectious), plus wastes listed by national law. The 2019 Plastic Waste Amendments (adopted 2019 COP14, in force 1 January 2021) added plastic wastes to the Convention's control regime under Annexes II, VIII, and IX. The Convention is part of the 'Basel, Rotterdam, Stockholm' (BRS Conventions) triple nexus administered jointly. Non-compliance may result in re-importation obligations (Article 8) and criminal prosecution under national law for illegal traffic.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csrd-2022-2464",
      "un-cbd-kunming-montreal-gbf-2022",
      "un-montreal-protocol-1987-ozone-kigali-2016"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "basel-ii-capital-framework",
    "title": "International Convergence of Capital Measurement and Capital Standards A Revised Framework Comprehensive Version",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2006-06-30",
    "bluf": "This framework presents the Basel Committee on Banking Supervision’s revisions to supervisory regulations governing the capital adequacy of internationally active banks. Its fundamental objective is to develop a framework that would further strengthen the soundness and stability of the international banking system while maintaining sufficient consistency that capital adequacy regulation will not be a significant source of competitive inequality among internationally active banks. The framework applies on a consolidated basis to internationally active banks, including any holding company that is the parent entity within a banking group, to ensure it captures the risk of the whole banking group.\n\nThe revised framework is based on three pillars: minimum capital requirements, supervisory review, and market discipline. It retains key elements of the 1988 capital adequacy framework, including the general requirement for banks to hold total capital equivalent to at least 8% of their risk-weighted assets. A significant innovation is the greater use of assessments of risk provided by banks’ internal systems as inputs to capital calculations. The framework provides a range of options for determining the capital requirements for credit risk and operational risk to allow banks and supervisors to select approaches that are most appropriate for their operations and their financial market infrastructure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "basel-iii-capital",
    "title": "Basel III Capital Requirements",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Basel III's framework, established by the Basel Committee on Banking Supervision's global regulatory framework and implemented through regulations such as the European Union's CRR and the US Federal Reserve's Regulation Q, mandates significantly strengthened capital and liquidity standards to enhance banking sector resilience. Institutions must maintain a minimum Common Equity Tier 1 ratio of at least 4.5 percent, a Tier 1 capital ratio of 6.0 percent or greater, and a Total Capital ratio equal to or exceeding 8.0 percent of risk-weighted assets. Beyond these minimums, a capital conservation buffer of at least 2.5 percent is required, alongside a calculated countercyclical capital buffer designed to protect against periods of excessive credit growth. Furthermore, a G-SIB surcharge is applied where applicable, consistent with the BCBS updated assessment methodology for higher loss absorbency by globally systemically important banks. A non-risk-weighted leverage ratio of 3.0 percent or more serves as a critical backstop. The framework also introduces two vital liquidity standards from dedicated BCBS publications: a Liquidity Coverage Ratio of at least 100 percent to ensure short-term survivability during stress, and a Net Stable Funding Ratio of 100 percent or greater to promote stable long-term funding structures. Compliance further necessitates meeting specific market risk capital requirements and applying the standardized approach for operational risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-committee-response-financial-crisis",
      "basel-ii-capital-framework",
      "basel-iii-global-regulatory-framework",
      "basel-iii-liquidity-lcr"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "basel-iii-global-regulatory-framework",
    "title": "Basel III: A global regulatory framework for more resilient banks and banking systems",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2011-06-01",
    "bluf": "This document presents the Basel Committee’s reforms to strengthen global capital and liquidity rules with the goal of promoting a more resilient banking sector. The objective of the reforms is to improve the banking sector’s ability to absorb shocks arising from financial and economic stress, whatever the source, thus reducing the risk of spillover from the financial sector to the real economy. The reforms address lessons from the financial crisis, where many countries' banking sectors had built up excessive on- and off-balance sheet leverage, accompanied by an erosion of the level and quality of the capital base and insufficient liquidity buffers.\n\nThe framework strengthens bank-level, or microprudential, regulation and also has a macroprudential focus, addressing system-wide risks. Core elements include raising both the quality and quantity of the regulatory capital base, where the predominant form of Tier 1 capital must be common shares and retained earnings. It enhances the risk coverage for counterparty credit exposures from derivatives, repo, and securities financing activities. The reforms are underpinned by a leverage ratio that serves as a backstop to the risk-based capital measures. The framework also introduces macroprudential elements to help contain systemic risks, including a capital conservation buffer and a countercyclical buffer to protect the banking sector from periods of excess credit growth.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-ii-capital-framework",
      "basel-iii-global-regulatory-framework"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "basel-iii-liquidity-lcr",
    "title": "Basel III Liquidity (LCR)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Liquidity Coverage Ratio (LCR) is a core component of the Basel III post-crisis reform. it ensures that banks maintain an adequate level of unencumbered high-quality liquid assets (HQLA) that can be converted into cash easily and immediately in private markets to meet their liquidity needs for a 30-day calendar day liquidity stress scenario.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-committee-response-financial-crisis",
      "basel-iii-global-regulatory-framework",
      "bcbs-sound-liquidity-risk-management",
      "bcbs-sound-stress-testing-practices",
      "lcr-disclosure-standards"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "basel-iv-credit-risk-standardised-approach",
    "title": "Basel III: Finalising post-crisis reforms - Standardised approach to credit risk (SA-CR)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes a more granular and risk-sensitive standardised approach (SA-CR) for calculating credit risk capital requirements for internationally active banks. As outlined in Section II, it revises risk weights for exposures to banks, corporates, and real estate, and reduces mechanistic reliance on external credit ratings by introducing a due diligence requirement for their use.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-ii-capital-framework",
      "basel-iii-global-regulatory-framework",
      "basel-iv-output-floor",
      "principles-effective-risk-data-aggregation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "basel-iv-crr3-eu-capital-requirements-2025",
    "title": "Regulation (EU) 2024/1623 (CRR3/Basel IV) - Revised Capital Requirements: Output Floor 72.5% from 2030, Revised Credit Risk Standardised Approach, Operational Risk New Standardised Approach, Fundamental Review of the Trading Book (FRTB) and SA-CCR Counterparty Credit Risk",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2024/1623 of 19 June 2024 (CRR3) amends Regulation (EU) No 575/2013 (CRR) to implement the final Basel IV capital standards in the EU, phased in from 1 January 2025; the cornerstone of CRR3 is the output floor requiring that internal model-based Risk-Weighted Assets (RWA) must not be less than 72.5% of RWA calculated under standardised approaches, phased in from 50% in 2025 to 72.5% in 2030; CRR3 also introduces a revised credit risk standardised approach (SA) with more granular risk weights, a new single standardised approach for operational risk (SMA replaced), requires EU implementation of the Fundamental Review of the Trading Book (FRTB) for market risk, and updates the Standardised Approach for Counterparty Credit Risk (SA-CCR); credit valuation adjustment (CVA) risk framework is also updated; small and non-complex institutions (SNCI) benefit from simplified reporting and proportionate approaches.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "BCBS_BASEL_IV",
        "CRD6",
        "DORA",
        "EU_BANKING_UNION"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-cloud-third-party-ict-2022-2554",
      "eu-aml-package-2021-regulation-proposal",
      "bis-pfmi-financial-market-infrastructure-2012"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "basel-iv-liquidity",
    "title": "Basel IV: Capital Floor & Liquidity",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The Basel IV framework (the final Basel III reforms) introduces a standardized output floor to prevent banks from using internal models to underestimate risk. It significantly tightens capital requirements for G-SIBs and harmonizes the calculation of Risk-Weighted Assets (RWA) across the global banking sector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "basel-iii-liquidity-lcr",
      "basel-iv-output-floor",
      "bcbs-sound-liquidity-risk-management",
      "fundamental-review-of-the-trading-book"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "basel-iv-operational-risk-sa",
    "title": "Basel III: Finalising post-crisis reforms - Operational risk framework (Revised Standardised Approach)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes a single, non-model-based method, the Standardised Approach (SA), for calculating operational risk capital requirements for all internationally active banks. As outlined in the framework (MAR30), banks must calculate their capital charge using a formula that combines a Business Indicator Component (BIC), derived from financial statement items, and an Internal Loss Multiplier (ILM), which is a function of the bank's historical internal operational loss experience.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "basel-iv-output-floor",
      "bcbs-principles-sound-management-operational-risk",
      "principles-effective-risk-data-aggregation",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "basel-iv-output-floor",
    "title": "Basel IV Output Floor",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Basel IV Output Floor is the centerpiece of the 2017 Basel III 'completion' reforms. It limits the reduction in risk-weighted assets (RWA) that can result from a bank's use of internal models by mandating that RWAs calculated using internal models cannot fall below 72.5% of the RWAs calculated using the standardized approach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "basel-ii-capital-framework",
      "ecb-guide-internal-models",
      "guidance-on-model-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bb-dpa-2019",
    "title": "Barbados Data Protection Act 2019",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Barbados enacted the Data Protection Act 2019, a GDPR-aligned statute administered by the Data Protection Commissioner. It mandates lawful bases for processing, grants data subjects rights of access, rectification, erasure, portability, restriction, and objection, and requires data breach notification to the Commissioner within 72 hours of becoming aware of a breach likely to result in high risk. Cross-border transfers require adequate protection or approved safeguards. Registration of certain processing operations with the Commissioner is required. The Act applies to all controllers established in Barbados and to controllers outside Barbados processing personal data of persons in Barbados.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/bb-dpa-2019.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bcbs-239-principles-risk-data-aggregation-reporting",
    "title": "BCBS 239 Principles for Effective Risk Data Aggregation and Risk Reporting",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Basel Committee on Banking Supervision Principles No. 239, published January 2013, establishes 14 principles for effective risk data aggregation and risk reporting applicable to global systemically important banks (G-SIBs) from January 2016 and to domestic SIBs as determined by national supervisors, requiring banks to achieve strong data governance, data architecture and IT infrastructure, accurate and complete risk data aggregation capabilities, and adaptable risk reporting practices that can scale to meet supervisory demands during stress.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dodd-frank-act-2010",
      "frb-sr-11-7-model-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bcbs-248-monitoring-tools-intraday-liquidity-management-2013",
    "title": "BCBS 248 - Monitoring tools for intraday liquidity management (Basel Committee, April 2013, Consolidated Basel Framework)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "BCBS 248 was published by the Basel Committee on Banking Supervision in April 2013 and has been integrated into the consolidated Basel Framework. It develops seven quantitative monitoring tools, designed in consultation with the Committee on Payment and Settlement Systems, that enable banking supervisors to monitor banks' intraday liquidity risk and their ability to meet payment and settlement obligations on a timely basis under both normal and stressed conditions, complementing Principle 8 of the September 2008 Sound Principles for Sound Liquidity Risk Management and Supervision. Internationally active banks must apply the tools - national supervisors determine the extent to which the tools apply to other banks. The standard groups the tools by applicability: Category A (applicable to all reporting banks) comprises four tools - A(i) Daily maximum intraday liquidity usage, A(ii) Available intraday liquidity at the start of the business day, A(iii) Total payments, and A(iv) Time-specific obligations. Category B (applicable to reporting banks that provide correspondent banking services) comprises two tools - B(i) Value of payments made on behalf of correspondent banking customers, and B(ii) Intraday credit lines extended to customers. Category C (applicable to reporting banks which are direct participants in a large-value payment system) comprises one tool - C(i) Intraday throughput. The standard also identifies four (non-exhaustive) intraday liquidity stress scenarios that banks must use to assess how their intraday liquidity profile in normal conditions would change in stress and discuss with supervisors: (i) own financial stress where the bank suffers or is perceived to be suffering from a stress event; (ii) counterparty stress where a major counterparty suffers an intraday stress event that prevents it from making payments; (iii) a customer bank's stress where a customer bank of a correspondent bank suffers a stress event; and (iv) market-wide credit or liquidity stress. The tools are for monitoring purposes only - banks and supervisors are not required to disclose these reporting requirements publicly. The standard prescribes a bottom-up, system-by-system reporting approach with reporting allowed across linked LVPS only where a direct real-time technical liquidity bridge exists or where the bank can demonstrate it regularly monitors positions and uses other formal arrangements to transfer liquidity intraday. Banks should report their three largest daily negative net cumulative positions and the daily average over the reporting period, with monthly reporting commenced from 1 January 2015 in line with the Liquidity Coverage Ratio reporting timeline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "scope_anchor",
        "category_a_tools_anchor",
        "category_b_tools_anchor",
        "category_c_tool_anchor",
        "stress_scenarios_anchor",
        "scope_of_application_anchor",
        "industry_mapping",
        "implementation_timeline_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-liquidity-lcr",
      "basel-iv-liquidity",
      "bcbs-sound-liquidity-risk-management",
      "bis-pfmi-financial-market-infrastructure-2012",
      "chaps-rtgs-high-val-london"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "bcbs-climate-related-financial-risks",
    "title": "Principles for the effective management and supervision of climate-related financial risks",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2021-11-01",
    "bluf": "Climate change may result in physical and transition risks that could affect the safety and soundness of individual banking institutions and have broader financial stability implications for the banking system. This document from the Basel Committee on Banking Supervision (BCBS) seeks to promote a principles-based approach to improving risk management and supervisory practices related to these risks. The consultative document includes 18 high-level principles: Principles 1 through 12 provide banks with guidance on effective management of climate-related financial risks, while principles 13 through 18 provide guidance for prudential supervisors.\n\nBanks are potentially exposed to climate-related financial risks regardless of their size, complexity or business model. They should therefore consider the potential impacts of climate-related risk drivers on their individual business models and assess the financial materiality of these risks. Banks should manage climate-related financial risks in a manner that is proportionate to the nature, scale and complexity of their activities and the overall level of risk that each bank is willing to accept. The principles are intended to provide a common baseline for internationally active banks and supervisors, while maintaining sufficient flexibility given the degree of heterogeneity and evolving practices in this area. The board of directors and senior management are expected to take a long-term consideration of climate-related financial risks, as their impacts could manifest over varying time horizons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-sound-management-operational-risk",
      "bcbs-sound-stress-testing-practices",
      "iso-31000-risk-mgt",
      "principles-effective-risk-data-aggregation",
      "tcfd-climate-related-financial-disclosures",
      "ifrs-s2-climate"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bcbs-cryptoasset-exposure-disclosure-d580-2024",
    "title": "Basel Committee on Banking Supervision - Disclosure of Cryptoasset Exposures (BCBS d580)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Published by the Basel Committee in July 2024 and to be implemented by 1 January 2026, this standard (DIS55 Cryptoasset exposures) establishes Pillar 3 disclosure requirements for banks' cryptoasset exposures through a qualitative disclosure table (Table CAEA) and quantitative templates, to be incorporated into the consolidated Basel Framework to support market discipline and reduce information asymmetry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fsb-crypto-asset-framework-2023",
      "basel-iii-global-regulatory-framework",
      "eu-markets-crypto-assets-regulation-2023-1114"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bcbs-fintech-sound-practices",
    "title": "Sound Practices: Implications of fintech developments for banks and bank supervisors",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2017-08-31",
    "bluf": "Interest is growing in financial technology, or 'fintech'. In response, the Basel Committee on Banking Supervision (BCBS) has analyzed the implications for supervisors and banks’ business models. As fintech developments remain fluid, the impact on banks is uncertain, but a common theme is that banks will find it increasingly difficult to maintain their current operating models given technological change and customer expectations. The nature and scope of banking risks as traditionally understood may significantly change over time with the growing adoption of fintech, in the form of both new technologies and business models. This Sound Practices paper combines historical research, product analysis, and scenario analysis to provide a forward-looking perspective on fintech's potential impact on the banking industry, identifying key observations and related recommendations.\n\nFor banks, the key risks associated with the emergence of fintech include strategic risk, operational risk, cyber-risk and compliance risk. The core recommendation is that banks should ensure they have effective governance structures and risk management processes to identify, manage and monitor these risks. This includes robust strategic planning, sound new product approval processes, implementation of operational risk principles, and appropriate due diligence and monitoring for any operations outsourced to third parties, including fintech firms. Ultimately, banks and bank supervisors are encouraged to balance ensuring the safety and soundness of the banking system with minimizing the risk of inadvertently inhibiting beneficial innovation in the financial sector, thereby promoting financial stability and consumer protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-sound-management-operational-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bcbs-large-exposures-framework",
    "title": "Supervisory framework for measuring and controlling large exposures",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2014-04-30",
    "bluf": "This framework was developed to limit the maximum loss a bank could face in the event of a sudden counterparty failure to a level that does not endanger the bank’s solvency. It complements the Committee’s risk-based capital standard because the latter is not designed specifically to protect banks from large losses resulting from the sudden default of a single counterparty. The framework is applicable to all internationally active banks and must apply at every tier within a banking group.\n\nThe core obligation is for banks to measure, aggregate, and control exposures to single counterparties or to groups of connected counterparties. The sum of all exposure values of a bank to a counterparty or to a group of connected counterparties is defined as a large exposure if it is equal to or above 10% of the bank’s eligible Tier 1 capital base. The sum of all exposure values to a single counterparty or group of connected counterparties must not be higher than 25% of the bank’s available eligible capital base at all times. A relatively tighter limit on exposures between global systemically important banks (G-SIBs) is included, set at 15% of the eligible capital base.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "basel-ii-capital-framework",
      "principles-effective-risk-data-aggregation",
      "bcbs-principles-sound-management-operational-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "bcbs-principles-operational-resilience",
    "title": "Principles for Operational Resilience",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2021-03-31",
    "bluf": "The Basel Committee on Banking Supervision promotes a principles-based approach to improving operational resilience, defined as the ability of a bank to deliver critical operations through disruption. This approach builds on the Committee’s Principles for the Sound Management of Operational Risk (PSMOR) and is intended to strengthen banks’ ability to absorb operational risk-related events such as pandemics, cyber incidents, and technology failures. The principles apply on a consolidated basis to banks consistent with the scope of the Basel Framework.\n\nThe core obligation is for a bank to establish an effective operational resilience approach that enables it to identify and protect itself from threats, respond and adapt to, and recover and learn from disruptive events to minimize their impact. This involves considering its overall risk appetite and tolerance for disruption. The principles are organized across seven categories: governance; operational risk management; business continuity planning and testing; mapping of interconnections and interdependencies of critical operations; third-party dependency management; incident management; and resilient information and communication technology (ICT), including cyber security. An operationally resilient bank is less prone to incur untimely lapses in its operations and losses from disruptions, thus lessening incident impact on critical operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-sound-management-operational-risk",
      "fsb-key-attributes-res"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "bcbs-principles-sound-management-operational-risk",
    "title": "Principles for the Sound Management of Operational Risk",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2011-06-01",
    "bluf": "This document details eleven principles of sound operational risk management covering governance, the risk management environment, and the role of disclosure. It replaces the 2003 Sound Practices for the Management and Supervision of Operational Risk, incorporating the evolution of sound practice and enhanced operational risk management practices now in use by the industry. The principles are relevant to all banks, which are expected to take account of the nature, size, complexity, and risk profile of their activities during implementation. Supervisors will evaluate a bank's policies, processes, and systems related to operational risk as part of their assessment of the bank's framework.\n\nThe core obligation is for banks to develop, implement, and maintain an operational risk management framework that is fully integrated into the bank’s overall risk management processes. This framework should be founded on a strong risk management culture led by the board of directors and senior management. It must be comprehensively documented in board-approved policies and include clear definitions and governance structures. A common industry practice for sound governance relies on three lines of defence: business line management, an independent corporate operational risk management function, and an independent review. The framework must also address business resiliency and continuity to ensure the bank can operate on an ongoing basis and limit losses in the event of severe business disruption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-ii-capital-framework",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "bcbs-sound-liquidity-risk-management",
    "title": "Principles for Sound Liquidity Risk Management and Supervision",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2008-09-01",
    "bluf": "Liquidity is the ability of a bank to fund increases in assets and meet obligations as they come due, without incurring unacceptable losses. The fundamental role of banks in the maturity transformation of short-term deposits into long-term loans makes banks inherently vulnerable to liquidity risk. This guidance outlines principles for the sound management of liquidity risk, prompted by market turmoil that re-emphasised the importance of liquidity to the functioning of financial markets and the banking sector. The difficulties highlighted that many banks had failed to take account of a number of basic principles of liquidity risk management, such as having an adequate framework that satisfactorily accounted for the liquidity risks posed by individual products and business lines. Many firms viewed severe and prolonged liquidity disruptions as implausible and did not conduct stress tests that factored in the possibility of market wide strain.\n\nThis guidance applies to all types of banks, with implementation tailored to the size, nature of business and complexity of a bank’s activities. The core obligation is that a bank is responsible for the sound management of liquidity risk. A bank should establish a robust liquidity risk management framework that ensures it maintains sufficient liquidity, including a cushion of unencumbered, high quality liquid assets, to withstand a range of stress events, including those involving the loss or impairment of both unsecured and secured funding sources. Supervisors should assess the adequacy of both a bank's liquidity risk management framework and its liquidity position and should take prompt action if a bank is deficient in either area.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-committee-response-financial-crisis",
      "basel-iii-global-regulatory-framework",
      "basel-iii-liquidity-lcr",
      "bcbs-sound-stress-testing-practices",
      "principles-effective-risk-data-aggregation",
      "bcbs-principles-sound-management-operational-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bcbs-sound-management-ml-ft-risks-2020",
    "title": "Sound management of risks related to money laundering and financing of terrorism (BCBS, July 2020 consolidated revision, d505)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "These Basel Committee guidelines describe how banks should manage money laundering and financing of terrorism risks within overall risk management, built on a comprehensive risk assessment (paragraphs 15 to 16), board governance and an appointed chief AML/CFT officer (paragraphs 17 to 18), and the three lines of defence (paragraphs 19 to 20). They set out an adequate transaction monitoring system (paragraphs 28 to 31), customer acceptance policy (paragraphs 32 to 34), customer and beneficial owner identification (paragraphs 35 to 37), ongoing monitoring (paragraph 45), record-keeping (paragraphs 51 to 52), reporting of suspicious transactions (paragraphs 56 to 58) and asset freezing (paragraphs 59 to 61). Part IV addresses the role of supervisors (paragraphs 84 to 85) and Annex 5 covers cooperation between prudential and AML/CFT supervisors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-40-recommendations-2023-consolidated",
      "fatf-recommendation-10-customer-due-diligence"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "bcbs-sound-stress-testing-practices",
    "title": "Principles for sound stress testing practices and supervision",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2009-05-31",
    "bluf": "Stress testing is an important risk management tool used by banks as part of their internal risk management and, through the Basel II capital adequacy framework, is promoted by supervisors. It alerts bank management to adverse unexpected outcomes related to a variety of risks and provides an indication of how much capital might be needed to absorb losses should large shocks occur. Stress testing plays a particularly important role in providing forward-looking assessments of risk, overcoming limitations of models and historical data, supporting communication, feeding into capital and liquidity planning, informing the setting of a bank's risk tolerance, and facilitating the development of risk mitigation plans.\n\nFollowing the financial crisis, which highlighted significant weaknesses in banks' stress testing practices, the Basel Committee developed these sound principles for banks and supervisors. The principles cover the overall objectives, governance, design, and implementation of stress testing programmes. The recommendations are aimed at deepening and strengthening banks’ stress testing practices and apply to banks on a proportionate basis, commensurate with their size, complexity, and risk profile. The core obligation is for a bank's stress testing to form an integral part of its overall governance, with results that are actionable and impact decision-making at the board and senior management levels.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-sound-liquidity-risk-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "bcbs-third-party-risk-principles-d605-2025",
    "title": "Basel Committee on Banking Supervision - Principles for the sound management of third-party risk (BCBS d605)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Published by the Basel Committee in December 2025, these twelve principles for the sound management of third-party risk are organised across the life cycle of third-party service provider (TPSP) arrangements - governance, risk management and strategy; risk assessment; due diligence; contracting; onboarding and ongoing monitoring; termination - with Principles 1 to 9 guiding banks and Principles 10 to 12 guiding prudential supervisors, broadening the traditional concept of outsourcing to the wider scope of TPSP arrangements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "basel-iv-crr3-eu-capital-requirements-2025",
      "eu-dora-2022-2554-article-28-ict-third-party-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bd-cyber-security-act-2023",
    "title": "Bangladesh Cyber Security Act 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Bangladesh's Cyber Security Act 2023, enacted in September 2023 to replace the Digital Security Act 2018, establishes a framework for cybercrime prevention and prosecution in Bangladesh, criminalises unauthorised access, digital fraud, identity theft, and online defamation, provides for critical information infrastructure designation by the Bangladesh Telecommunication Regulatory Commission, establishes the Cyber Security Agency of Bangladesh under the Digital Security Agency, and imposes penalties including fines and imprisonment for cybercrime offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/bd-cyber-security-act-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "be-code-droit-economique-livre-vi",
    "title": "Belgium Code de droit economique - Livre VI (Pratiques du marche et protection du consommateur)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Belgian Code de droit economique consolidates economic regulation in 19 Livres. Livre VI (Pratiques du marche et protection du consommateur) governs market practices and consumer protection, replacing the Loi du 6 avril 2010 sur les pratiques du marche et la protection du consommateur. Livre VI was inserted by the Loi du 21 decembre 2013 and entered into force on 31 May 2014. The Livre transposes EU Directive 2005/29/CE Unfair Commercial Practices (UCPD) and EU Directive 2011/83/UE Consumer Rights into Belgian law. Key articles: Art. VI.1 sets general principles. Art. VI.2 imposes the general pre-contractual information obligation. Art. VI.6 mandates the indication of prices toutes taxes comprises (all-taxes-included). Arts. VI.45 to VI.62 govern distance and off-premises contracts with a 14-day droit de retractation under Art. VI.47 (consumer may withdraw without justification or cost except return shipping). Arts. VI.93 to VI.96 prohibit unfair commercial practices contrary to professional diligence. Arts. VI.97 to VI.100 prohibit misleading actions and omissions including the Art. VI.100 blacklist of 31 commercial practices always considered unfair. Arts. VI.101 to VI.103 prohibit aggressive practices using harassment, coercion or undue influence. Arts. VI.104 to VI.109 regulate publicite comparative (comparative advertising) under conditions of objective and verifiable comparison. Arts. VI.116 to VI.117 prohibit ventes a perte (below-cost sales) outside the soldes period. Enforcement is by the Service Public Federal Economie (SPF Economie) via the Inspection economique under Arts. XV.1 et seq. with administrative fines and possible criminal sanctions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29-2022-revision",
      "eu-consumer-rights-directive-2011-83-eu",
      "fr-code-consommation"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "be-data-protection-act-2018",
    "title": "Belgium Data Protection Act 2018 (Loi du 30 juillet 2018) - GDPR National Implementation",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Belgium's Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data (Loi du 30 juillet 2018 relative à la protection des personnes physiques à l'égard des traitements de données à caractère personnel / Wet van 30 juli 2018 betreffende de bescherming van natuurlijke personen met betrekking tot de verwerking van persoonsgegevens), published in the Belgian Official Gazette (Belgisch Staatsblad / Moniteur Belge) on 5 September 2018, is Belgium's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Belgium. The GDPR is directly applicable Belgian law by virtue of Belgium's EU membership. Belgium's Act of 30 July 2018 provides national derogations, additions, and specifications for the Belgian GDPR implementation and repeals the prior Belgian Data Protection Act of 8 December 1992. Belgium is home to several EU institutions and international organisations whose data processing activities intersect with Belgian data protection law. Enforcement: Gegevensbeschermingsautoriteit / Autorité de protection des données (GBA/APD - Belgian Data Protection Authority) is Belgium's independent data protection supervisory authority, established by the Act of 3 December 2017. The GBA/APD is Belgium's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Belgian national provisions: (1) Age of digital consent: Belgium has set the age of consent for information society services at 13 years (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 13 require parental or guardian consent; (2) Employment context - Belgium's Act of 30 July 2018 provides significant provisions on employee data processing, which interact with Belgian labour law, the Act of 3 July 1978 on Employment Contracts, and collective bargaining agreements (CBAs); Belgium has a well-developed system of sector-level CBAs (Collective Labour Agreements / Collectieve arbeidsovereenkomsten - CAO) that govern employment data processing; (3) State security and intelligence - specific provisions for processing by Belgian state security and intelligence services (State Security Service / Veiligheid van de Staat); (4) Journalistic, scientific, and historical processing - exemptions aligned with GDPR Art. 85 and 89; (5) Criminal data - restrictions on private entity processing of criminal conviction data; (6) DPO obligations - public authorities and entities engaged in large-scale processing must appoint a DPO. Fines: GDPR administrative fines apply in Belgium - up to EUR 20 million or 4% of global annual turnover. The GBA/APD has imposed significant fines including against political parties for electoral data processing, telecommunications operators, and digital advertising companies. Belgium's courts have also considered GDPR matters including the Brussels Court of Appeal's landmark judgment on IAB Europe's Transparency and Consent Framework (TCF) and its interaction with GDPR.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "belgium-gambling-act-1999-online-amendments",
    "title": "Belgium Gambling Act 1999 (Online Amendments 2010) - Licence Categories, Player Protection, Advertising Prohibitions and Loot Box Classification",
    "domain": "Gaming & Gambling",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation governs online gambling activities in Belgium, establishing licensing requirements, player protection mechanisms, and advertising restrictions under the amended framework of the 1999 Act. Key obligations are derived from the Gaming Commission's legislative framework, including prohibitions on targeting minors and requirements for responsible gaming tools.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "fatf-recommendation-16-travel-rule-crypto"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "belgium-space-activities-act-2005",
    "title": "Belgium Space Activities Act 2005 - Wet van 17 September 2005 Betreffende de Activiteiten die Betrekking Hebben op de Ruimtevaart",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Belgian Law of 17 September 2005 on Activities Related to Space (Wet van 17 september 2005 betreffende de activiteiten die betrekking hebben op de ruimtevaart, published in Belgisch Staatsblad on 5 October 2005) is Belgium's national space activities law establishing a licensing and supervision regime for space operations conducted by entities under Belgian jurisdiction. Belgium was among the first EU Member States to adopt a national space law following adoption of the UN space treaties. The law grants licensing authority to the Belgian Minister of Science Policy (later transferred to competences under federal economic law), requires prior authorisation for space launches and operations from or by Belgian entities, mandates third-party liability insurance, and establishes Belgium's national register of space objects in accordance with the Registration Convention 1976. Belgium is an ESA Member State with significant industrial participation (Thales Alenia Space Belgium, Spacebel, QinetiQ Space) and the law applies to these commercial operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "un_outer_space_treaty_1967",
        "esa_framework",
        "eu_space_programme"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bermuda-bma-cissa-commercial-insurer-2023",
    "title": "Commercial Insurer Solvency Self-Assessment (CISSA): Framework, Methodology and Submission Requirements",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2023-08-01",
    "bluf": "This framework requires all Bermuda-registered commercial insurers (Classes 3A, 3B, 4, IGB, and Long-Term Classes C, D, and E) to conduct and document an annual Commercial Insurer Solvency Self-Assessment (CISSA). The CISSA is a comprehensive review of the insurer's risk profile, risk management systems, and capital adequacy, culminating in a formal report submitted to the Bermuda Monetary Authority (BMA) as mandated by Section 6C of the Insurance Act 1978.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bermuda-monetary-authority-insurance-prudential",
    "title": "Bermuda Monetary Authority Insurance Prudential Standards (Enhanced Capital Requirement, BSCR, and Group Supervision Rules)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires Bermuda-based commercial insurers (primarily Class 3B, 4, and insurance groups) to maintain available statutory capital and surplus at or above the Enhanced Capital Requirement (ECR), which is determined by the Bermuda Solvency Capital Requirement (BSCR) model. As mandated by the Insurance Act 1978 and associated Prudential Standards Rules, this framework ensures insurers can meet policyholder obligations under stress scenarios and establishes comprehensive group-wide supervision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "berne-convention-1886-2024-literary-artistic-works",
    "title": "Berne Convention for the Protection of Literary and Artistic Works (as amended up to the Paris Act of 1971 and incorporating subsequent developments through 2024)",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Berne Convention mandates automatic protection of literary and artistic works upon creation, without formalities, and grants national treatment to foreign authors from member states. It establishes minimum rights including reproduction, translation, public performance, and moral rights under Article 5 and Article 6bis, applicable to all signatory countries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iptc-photo-metadata",
      "iptc-video-metadata",
      "exif-standard-metadata",
      "isbn-book-standard",
      "isan-audiovisual-number"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "berne-convention-literary-artistic",
    "title": "Berne Convention (Copyright)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Berne Convention for the Protection of Literary and Artistic Works (1886) is the foundational international treaty for copyright. It provides 'Automatic Protection'-meaning copyright exists as soon as a work is fixed in a tangible medium, without the need for registration-and ensures that foreign authors receive the same rights as local ones.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ai-ip-copyright",
      "dmca-safe-harbor",
      "eu-copyright-directive-art-17",
      "paris-convention-industrial-property",
      "wipo-copyright-treaty",
      "wipo-performances-phonograms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bf-pdp-law-2004",
    "title": "Burkina Faso Personal Data Protection Law - CIL Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Burkina Faso Law No. 010-2004/AN on Protection of Personal Data (2004) established one of West Africa's earliest data protection frameworks, creating the Commission de l'Informatique et des Libertés (CIL) as the supervisory authority with powers of registration, prior authorization for sensitive processing, and enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bg-public-procurement-act-zop-2016-aop-cais-portal",
    "title": "Bulgaria Public Procurement Act (Zakon za obshtestvenite porychki / ZOP) of 13 February 2016 effective 15 April 2016 and AOP / CAIS EOP",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Republic of Bulgaria Public Procurement Act (Zakon za obshtestvenite porychki / ZOP) of 13 February 2016 (State Gazette No. 13 of 16 February 2016) effective 15 April 2016 as substantially amended over time (most recently by ZID-ZOP State Gazette No. 88/2023), is the principal Bulgarian statute governing procurement of goods, services, and works by contracting authorities including the central public administration (ministries, agencies, sub-agencies), the President's Administration, the National Assembly Administration, the Constitutional Court Administration, regional administrations and municipalities, sectoral contracting entities (utilities including water, energy, transport, postal services), public-sector enterprises and bodies governed by public law, public-sector universities, and other contracting authorities subject to EU procurement directive scope. ZOP 2016 transposed the EU procurement directives 2014/24/EU (classical), 2014/25/EU (utilities), 2014/23/EU (concessions), and Directive 89/665/EEC remedies into Bulgarian law. The Public Procurement Agency (Agentsia po obshtestveni porychki / AOP, aop.bg) under the Council of Ministers is the central regulatory authority responsible for procurement regulation, oversight, and procurement guidance. The Commission for the Protection of Competition (Komisiya za zashtita na konkurentsiyata / KZK) handles procurement complaints. The Centralized Automated Information System Electronic Procurement (CAIS EOP / app.eop.bg) operated by AOP is the mandatory federal e-procurement platform for in-scope procurement. The National Audit Office of the Republic of Bulgaria conducts ex-post procurement audit. Procurement methods established by ZOP 2016 art. 18 to 36 comprise (a) Open Procedure (Otkrita protsedura, the default open public procedure), (b) Restricted Procedure (Ogranichena protsedura, with prequalification), (c) Competitive Procedure with Negotiation (Sastezatelna protsedura s pregovori), (d) Competitive Dialogue (Sastezatelen dialog, for complex acquisitions), (e) Innovation Partnership (Inovatsionno partnyorstvo), (f) Negotiated Procedure without Prior Publication (Pregovorna protsedura bez predvaritelno obyavyavane, under prescribed exceptions in art. 79), (g) Design Contest (Konkurs za proekt), (h) Direct Negotiation Procedure (Pryako predogovaryane, for prescribed contexts), and (i) Public Negotiation Procedure (Publichno sastezanie, for lower-value contracts).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "eu-public-procurement-directive-2014-24-construction",
      "eu-directive-2014-25-utilities-procurement",
      "bg-zzld-gdpr-2019"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "bg-zzld-gdpr-2019",
    "title": "Bulgaria Personal Data Protection Act (ZZLD) - GDPR National Implementation",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Bulgaria's Закон за защита на личните данни (ZZLD - Personal Data Protection Act), as substantially amended by Darzhaven Vestnik (Official Gazette) Act SG 17/2019 of 26 February 2019 to align with the EU General Data Protection Regulation, is Bulgaria's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Bulgaria. The GDPR is directly applicable Bulgarian law by virtue of Bulgaria's EU membership. The 2019 amendments (SG 17/2019) restructured the ZZLD to incorporate national derogations and additions permitted by the GDPR, replacing provisions now governed directly by the GDPR. The ZZLD was originally enacted in 2002 and has been amended multiple times to reflect evolving EU data protection law. Enforcement: the Комисия за защита на личните данни (KZLD - Commission for Personal Data Protection) is Bulgaria's independent data protection supervisory authority. The KZLD is Bulgaria's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Bulgaria is a Southeastern European EU member state with a growing IT outsourcing sector and significant cross-border data flows; Bulgaria has not yet adopted the euro and operates under the lev (BGN), which is pegged to the euro. Key Bulgarian national provisions: (1) Age of digital consent: Bulgaria has set the age of consent for information society services at 14 years (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 14 require parental or guardian consent; (2) Employment - the Bulgarian Labour Code (Kodeks na Truda, State Gazette 26/1986 as amended) and the Act on Health and Safety at Work govern employment relationships and employee data processing alongside GDPR; (3) Freedom of expression - exemptions for journalistic, literary, and artistic processing aligned with GDPR Art. 85 and Bulgarian constitutional freedom of expression; (4) Health data - specific provisions for health data processing under Bulgarian health legislation supplementing GDPR Art. 9; (5) Criminal data - the ZZLD restricts private entity processing of criminal conviction and offence data; (6) Public sector - Bulgarian public authorities are subject to both the ZZLD and Bulgarian administrative law. Fines: GDPR administrative fines apply in Bulgaria - up to EUR 20 million or 4% of global annual turnover. The KZLD has imposed administrative fines and issued enforcement decisions, including in employment, public sector, and direct marketing contexts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bgp-security-ddos-mitigation",
    "title": "Resilient Interdomain Traffic Exchange: BGP Security and DDoS Mitigation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-12-31",
    "bluf": "This special publication on Resilient Interdomain Traffic Exchange (RITE) includes initial guidance on securing the interdomain routing control traffic, preventing IP address spoofing, and certain aspects of DoS/DDoS detection and mitigation. The primary focus of these recommendations are the points of interconnection between enterprise networks, or hosted service providers, and the public internet. The primary audience includes information security officers and managers of federal enterprise networks. The guidance also applies to the network services of hosting providers and internet service providers (ISPs) when they are used to support federal IT systems.\n\nThe core recommendations reduce the risk of accidental and malicious attacks in the routing control plane, and they help detect and prevent IP address spoofing and resulting DoS/DDoS attacks. Technologies recommended for securing interdomain routing control traffic include Resource Public Key Infrastructure (RPKI), BGP origin validation (BGP-OV), and prefix filtering. Additionally, technologies recommended for mitigating DoS/DDoS attacks include prevention of IP address spoofing using source address validation (SAV) with access control lists (ACLs) and unicast Reverse Path Forwarding (uRPF). Other technologies such as remotely triggered black hole (RTBH) filtering, flow specification (Flowspec), and response rate limiting (RRL) are also recommended as part of the overall security mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-1800-14-bgp-rov",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-207",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bh-pdpl-2018",
    "title": "Bahrain Personal Data Protection Law 2018 - PDPA",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Bahrain's Personal Data Protection Law (PDPL) - Legislative Decree No. 30 of 2018, issued by His Majesty King Hamad bin Isa Al Khalifa on 12 July 2018 and published in the Official Gazette - is Bahrain's comprehensive personal data protection legislation, making Bahrain the first Gulf Cooperation Council (GCC) member state to enact a standalone, comprehensive personal data protection law. The PDPL came into full force following the issuance of the Executive Regulations (Resolution No. 1 of 2019), and full compliance was required from 1 August 2019. The PDPL is broadly aligned with international data protection standards, particularly the European Union GDPR (Regulation (EU) 2016/679), and reflects Bahrain's position as a regional financial and technology hub seeking to align its regulatory framework with global best practice. The enforcement authority is the Personal Data Protection Authority (PDPA) - an independent statutory body established under the PDPL to regulate, supervise, and enforce personal data protection in Bahrain. Key features of the Bahrain PDPL: (1) Applies to any person (natural or legal) who controls the processing of personal data in Bahrain or where personal data of persons in Bahrain is processed, regardless of whether the controller is located in Bahrain; (2) Lawful processing conditions - personal data may be processed only where one of the following applies: the data subject's consent; contractual necessity; legal obligation; vital interests; public interest; or the legitimate interests of the controller (where not overridden by the data subject's interests); (3) Sensitive personal data - the PDPL designates categories of sensitive personal data requiring additional safeguards: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health or medical data; sexual life or orientation; biometric and genetic data; financial data; and data relating to criminal offences and convictions; (4) Data subject rights - right of access; right to rectification; right to erasure; right to restriction of processing; right to data portability; right to object; right not to be subject to automated decision-making with significant effects; (5) Data Controller obligations - maintain a record of processing activities; implement data protection by design and by default; designate a Data Protection Officer (DPO) where required; conduct Data Protection Impact Assessments (DPIAs) for high-risk processing; notify the PDPA and data subjects of personal data breaches; (6) Data Protection Officer - required for controllers: processing large volumes of personal data; processing sensitive personal data; or conducting systematic monitoring of individuals; (7) Breach notification - controllers must notify the PDPA of personal data breaches within a reasonable time (the PDPA has issued guidance on notification timelines); data subjects must be notified where the breach is likely to harm them; (8) Cross-border data transfer - personal data may only be transferred to a country or territory providing adequate protection for personal data; where adequacy is not established, transfers require PDPA approval or one of the specified safeguards (consent, contractual necessity, vital interests, or binding corporate rules); (9) Penalties - administrative sanctions including fines; criminal penalties for wilful violations including imprisonment; the PDPA may impose corrective orders, warnings, and temporary or permanent prohibitions on processing. Bahrain's PDPL was a pioneering instrument in the Gulf region and has influenced subsequent data protection law developments in other GCC states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bh-pdpl-2018-article-3-processing-conditions",
    "title": "Bahrain Personal Data Protection Law Decree No.30/2018 - Article 4: Conditions for Lawful Processing",
    "domain": "Legal & IP Sovereignty",
    "version": "2.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Bahrain Personal Data Protection Law (Legislative Decree No. 30 of 2018) Article 4 sets out the general conditions for legitimate processing of personal data: data subject's explicit consent; necessity for performance of a contract with the data subject; compliance with a legal obligation; protection of vital interests of the data subject; a task carried out in the public interest; and the legitimate interests of the controller or a third party provided these do not prejudice the data subject's rights. (Article 3 of the Law covers requirements for data quality control, and Article 5 governs sensitive personal data.) The Bahrain Personal Data Protection Authority (PDPA) enforces compliance and may impose administrative fines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bh-pdpl-2018",
      "bh-pdpl-2018-data-subject-rights"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "bh-pdpl-2018-data-subject-rights",
    "title": "Bahrain Personal Data Protection Law (Legislative Decree No. 30 of 2018) - Data Subject Rights: Notification/Access, Objection and Rectification/Blocking/Erasure",
    "domain": "Legal & IP Sovereignty",
    "version": "3.0.0",
    "last_updated": "2026-06-29",
    "bluf": "Bahrain's Personal Data Protection Law (Legislative Decree No. 30 of 2018) grants data subjects rights set out in Articles 18 to 23. Article 18 gives the right to be notified, on request and free of charge, whether their personal data is being processed (response within 15 working days). Article 19 requires controllers to inform data subjects of the right to object to direct marketing. Article 20 governs the controller's handling of a direct-marketing objection (response within 10 working days). Article 21 lets a data subject require the controller to cease processing causing unwarranted substantial material or moral damage (response within 10 working days). Article 22 allows a data subject to object to decisions based solely on automated processing (e.g. in employment, financial or credibility assessments). Article 23 gives the right to request rectification, blocking and erasure of data (response within 10 working days). The law does NOT provide a GDPR-style right to data portability. Enforcement is by the Personal Data Protection Authority (established under Article 27).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bh-pdpl-2018",
      "bh-pdpl-2018-article-3-processing-conditions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "bi-pdp-law-2020",
    "title": "Burundi Law on Personal Data Protection 2020",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Burundi enacted the Law on Personal Data Protection in 2020, establishing a comprehensive legal framework for the protection of personal data in the Republic of Burundi. The law is administered by the Agence de Régulation et de Contrôle des Télécommunications (ARCT). It establishes principles for the lawful processing of personal data, requires data controllers to obtain consent from data subjects before collecting personal data, grants data subjects rights of access, rectification, and erasure, mandates security safeguards, and restricts cross-border transfers to jurisdictions with adequate protection. Data controllers must register their processing activities with the ARCT. The law aligns with the African Union Malabo Convention on cyber security and personal data protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/bi-pdp-law-2020.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bimco-gencon-cp-2022-charter-party",
    "title": "BIMCO GENCON 2022 Charter Party - Voyage Charter Standard Terms: Laytime Calculation, Demurrage and Dispatch, Safe Port Warranty, Cargo Care Obligations, Lien on Cargo, General Average (York-Antwerp Rules), Arbitration Clause and BIMCO Dispute Resolution Clause",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This charter party governs voyage chartering arrangements between shipowners and charterers, establishing obligations for laytime, demurrage, safe port warranty, cargo care, lien on cargo, and dispute resolution under BIMCO standard terms. Key provisions include Clause 8 for laytime and demurrage, Clause 13 for safe port warranty, and Clause 17 for arbitration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "imo-marpol-pollution"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bimco-standard-charter-party-terms",
    "title": "BIMCO Standard Charter Party Clauses - GENCON 1994, NYPE 2015 and Laytime/Demurrage Standard Terms",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "BIMCO standard charter party clauses provide legally vetted, industry-accepted contractual frameworks for the hire of a vessel, defining the rights and responsibilities of shipowners and charterers. These clauses, such as the Laytime and Demurrage definitions or the NYPE 2015 Time Charter Party, govern critical operational aspects including cargo handling, payment, vessel seaworthiness, and risk allocation for unforeseen events.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hague-visby-rules",
      "imo-solas-safety-at-sea",
      "imo-marpol-pollution",
      "ism-code-vessel-safety",
      "isps-code-vessel-security"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "biobanking-gdpr-compliance-2026",
    "title": "Biobanking & Genomic Data Governance under GDPR & Global Standards (2026)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Biobanks and genomic data repositories must comply with GDPR Article 9 (special category data), Article 89 (research exemptions), strict purpose limitation, data minimisation, pseudonymisation/anonymisation techniques, dynamic consent where possible, and robust security. Additional requirements apply under the EU Data Governance Act and national biobank laws for secondary use, international transfers, and benefit sharing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-9-special-categories-sensitive-personal-data",
      "iso-9001-quality-management-construction",
      "us-fda-21-cfr-part-11-electronic-records-signatures"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "bis-ai-financial-services-2023",
    "title": "Artificial intelligence and machine learning in financial services",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-08-05",
    "bluf": "This joint BIS and FSB report outlines key considerations for financial institutions and supervisors regarding the use of AI and ML, emphasizing the need for robust governance, data quality, and model risk management frameworks to ensure operational resilience and financial stability. It highlights the importance of adapting existing risk management practices to address unique AI/ML challenges like explainability, fairness, and third-party dependencies, as detailed in Sections 3 and 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sr-11-7-model-risk-management",
      "bcbs-principles-operational-resilience",
      "bcbs-fintech-sound-practices",
      "interagency-guidance-third-party-risk-management",
      "fca-consumer-duty-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bis-bcbs-195-operational-risk-management",
    "title": "Principles for the Sound Management of Operational Risk",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must implement sound operational risk management that reflects the effectiveness of the board and senior management, covering the core areas of governance, the risk management environment, and disclosure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bis-bcbs-d498-climate-financial-risk",
    "title": "Principles for the effective management and supervision of climate-related financial risks",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This Basel Committee on Banking Supervision (BCBS) standard establishes principles to improve banks risk management and supervisors practices regarding climate-related financial risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "tcfd-recommendations-climate-related-financial-disclosures-financial-stability"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bis-bcbs-operational-resilience-2021",
    "title": "Principles for operational resilience",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This standard establishes a principles-based approach for banks to strengthen their operational resilience against events like pandemics, cyber incidents, and technology failures that could cause significant disruptions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-capital",
      "bcbs-239-principles-risk-data-aggregation-reporting"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bis-cbdcs-monetary-system",
    "title": "III. CBDCs: an opportunity for the monetary system",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2021-06-29",
    "bluf": "This chapter examines how central bank digital currencies (CBDCs) can contribute to an open, safe and competitive monetary system that supports innovation and serves the public interest. CBDCs are a form of digital money, denominated in the national unit of account, which is a direct liability of the central bank. They can be designed for use either among financial intermediaries only (wholesale CBDCs), or by the wider economy (retail CBDCs). The overriding criterion when evaluating a change to the monetary system should be whether it serves the public interest, encompassing economic benefits, governance quality, and basic rights such as data privacy. Digital money should be designed with this in mind, and retail CBDCs could ensure open payment platforms and a competitive level playing field conducive to innovation.\n\nThe ultimate benefits of adopting a new payment technology will depend on the competitive structure of the underlying payment system and data governance arrangements. The same technology that can encourage a virtuous circle of greater access, lower costs and better services might equally induce a vicious circle of data silos, market power and anti-competitive practices. The report argues that CBDCs are best designed as part of a two-tier system, where the central bank provides the foundational infrastructure and private payment service providers (PSPs) use their creativity to serve customers. Design choices regarding digital identification and architecture (hybrid vs. intermediated) are crucial for balancing innovation, financial stability, and user privacy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bis-principles-fmi-2012",
      "bcbs-principles-operational-resilience",
      "bcbs-fintech-sound-practices",
      "cpmi-iosco-cyber-resilience-fmi",
      "iso-20022-mx-messaging"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "bis-cpmi-cross-border-payments-2023",
    "title": "Considerations for the use of stablecoin arrangements in cross-border payments",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This report outlines key considerations and challenges regarding the use of stablecoin arrangements in cross-border payments, emphasizing that no existing stablecoin arrangement is currently deemed fully compliant with all relevant regulatory requirements. It applies to regulators, central banks, and payment system operators evaluating stablecoin integration into international payment infrastructures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bis-cpmi-principles-financial-market-infra-2012",
    "title": "Principles for Financial Market Infrastructures",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This standard establishes key principles for the design and operation of financial market infrastructures to promote safety, efficiency, and stability in the global financial system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bis-crypto-asset-prudential-standards",
    "title": "Prudential treatment of cryptoasset exposures (Standard SCO60)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-12-16",
    "bluf": "This standard requires internationally active banks to classify their cryptoasset exposures into two groups (Group 1 and Group 2) and apply specific, conservative capital requirements, risk management processes, and exposure limits to mitigate financial stability risks, as detailed in SCO60.20 and SCO60.36.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-fintech-sound-practices"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bis-etfs-illiquid-assets-fire-sales",
    "title": "ETFs, illiquid assets, and fire sales",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2021-11-01",
    "bluf": "This paper documents several novel facts about exchange-traded funds (ETFs) holding corporate bonds. Its main empirical finding is that the portfolio of bonds exchanged for new or existing ETF shares, known as creation or redemption baskets, often represents a small fraction of ETF holdings-a fact referred to as “fractional baskets.” For ETFs holding corporate bonds, roughly 10% of holdings are in creation baskets and 20% are in redemption baskets, on average. These baskets also exhibit high turnover; for instance, a bond in a creation basket has on average a 25% chance of being included in the next day’s creation basket. Consequently, ETFs with fractional baskets exhibit persistent premiums and discounts, which is related to the slow adjustment of Net Asset Value (NAV) returns to ETF returns.\nA simple model is developed to show that an ETF’s authorized participants (APs) can act as a buffer between the ETF market and the underlying illiquid assets, helping to mitigate fire sales. The key takeaway from the model is that an ETF discount arises because the AP acts as a buffer, allowing the ETF price to fall while avoiding selling bonds in quantities that would trigger a fire sale. The findings suggest that the delayed response of NAV, resulting from fractional baskets, can be a potential benefit for ETFs managing illiquid assets by absorbing panic selling in the liquid ETF market while mitigating the impact on the less liquid market for underlying assets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-liquidity-lcr",
      "bcbs-sound-liquidity-risk-management",
      "fsb-key-attributes-res",
      "gfsr-crypto-financial-stability-challenges",
      "guidance-on-model-risk-management",
      "mifid-ii"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "bis-etfs-illiquid-assets-firesales",
    "title": "ETFs, illiquid assets, and fire sales",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2021-07-14",
    "bluf": "This paper documents several facts about exchange-traded funds (ETFs) holding corporate bonds. The main empirical finding is that bond ETF baskets contain a small fraction of holdings, a fact referred to as 'fractional baskets,' which contributes to persistent discrepancies between ETF price and net asset value (NAV). For ETFs holding corporate bonds, roughly 10% of holdings are in creation baskets and 20% are in redemption baskets, on average. This challenges the common assumption that baskets are representative of holdings and has important implications for the ETF arbitrage process. These fractional baskets also exhibit high turnover, and their composition differs from overall holdings in terms of duration and bid-ask spreads.\n\nThe paper develops a model to show that these discrepancies may be a feature of ETFs holding illiquid assets. The model demonstrates that an ETF’s authorized participants (APs) can act as a buffer between the ETF market and the underlying illiquid assets, helping to mitigate fire sales. When facing redemptions, an AP holding bond inventory endogenously avoids a fire sale because selling bonds at fire sale prices would lead to large mark-to-market losses on their existing inventory. This allows the ETF price to fall while avoiding selling bonds in quantities that would trigger a fire sale, insulating non-redeeming investors and the underlying bond market from immediate pressure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bis-principles-fmi-2012",
      "gfsr-crypto-financial-stability-challenges",
      "iosco-bench-interest-rate",
      "mifid-ii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bis-fsb-key-attributes-resolution-regimes-2014",
    "title": "Key Attributes of Effective Resolution Regimes for Financial Institutions (2014 revised version)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This standard establishes the core attributes for effective resolution regimes for financial institutions, incorporating specific guidance for insurers, financial market infrastructures (FMIs), information sharing, and the protection of client assets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-capital"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bis-iosco-pfmi-applied-to-dlt-systems",
    "title": "Application of the Principles for financial market infrastructures to stablecoin arrangements",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This guidance clarifies that systemically important stablecoin arrangements (SAs) performing financial market infrastructure (FMI) functions must observe all relevant Principles for Financial Market Infrastructures (PFMI), focusing on robust governance (Principle 2), comprehensive risk management (Principles 4, 6, 7), and clear settlement finality (Principle 8) to ensure financial stability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mica-asset-referenced-tokens",
      "bis-crypto-asset-prudential-standards",
      "fsb-crypto-asset-regulatory-framework-2023",
      "eu-mica-regulation-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bis-iosco-stablecoin-guidance-pfmi-2022",
    "title": "Application of the Principles for Financial Market Infrastructures to Stablecoin Arrangements",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This guidance requires systemically important stablecoin arrangements (SAs) that perform transfer functions to comply with the Principles for Financial Market Infrastructures (PFMI), particularly regarding governance, risk management, settlement finality, and money settlements. It applies to entities integral to such arrangements as determined by relevant authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bis-iosco-pfmi-applied-to-dlt-systems",
      "bis-cpmi-cross-border-payments-2023",
      "eu-dlt-pilot-regime-2022-858"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bis-pfmi-financial-market-infrastructure-2012",
    "title": "Principles for Financial Market Infrastructures",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Principles for Financial Market Infrastructures (PFMI) establish 24 principles for systemically important financial market infrastructures (FMIs), including central counterparties (CCPs), central securities depositories (CSDs), and payment systems, to ensure robust legal, governance, risk management, and recovery frameworks. Key requirements include adherence to Principle 1 on legal basis, Principle 12 on default management, and Principle 22 on recovery planning.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "basel-iii-capital",
      "apra-cps-230-resilience",
      "apra-cps-234"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "bis-principles-fmi-2012",
    "title": "BIS Principles (FMI)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Principles for Financial Market Infrastructures (PFMI) are the international standards for the infrastructure that facilitates the clearing, settlement, and recording of monetary and other financial transactions. Developed by CPSS (now CPMI) and IOSCO, the 24 principles are designed to ensure the safety, efficiency, and resilience of systemically important payment systems and central counterparties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "bcbs-principles-sound-management-operational-risk",
      "bcbs-sound-liquidity-risk-management",
      "cpmi-iosco-cyber-resilience-fmi",
      "fsb-key-attributes-res",
      "principles-effective-risk-data-aggregation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bis-project-leap-quantum-proofing-payments",
    "title": "BIS Project Leap - Quantum-Proofing the Financial System (Central Bank Post-Quantum VPN Experiment)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2023-06-30",
    "bluf": "Project Leap: Quantum-proofing the financial system was published in June 2023 as a joint experiment by the BIS Innovation Hub Eurosystem Centre, the Bank of France and Deutsche Bundesbank. Unlike the national roadmaps that describe what should be done, this report records what was actually built and measured: a post-quantum virtual private network tunnel carrying a standard Pacs.008 payment message between two central banks, with timing and stability results.\n\nThe stated threat is that quantum computers represent a serious threat for the financial system, that quantum algorithms created in the mid-1990s could in theory and given a sufficiently powerful quantum computer break today's widely used public key cryptographic schemes, and that this would instantly obsolete many current cryptographic techniques. Because malicious actors can already intercept and store confidential, classically encrypted data with the intention of decrypting it later, data stored or transmitted today are exposed to harvest now, decrypt later attacks, and the long-term sensitivity of financial data means the potential future existence of a quantum computer effectively renders today's systems insecure.\n\nThe empirical findings are the value of the report. On cryptographic agility, a significant number of information systems suffer from a lack of it because they are not designed with easy replacement in mind, and systems with a high degree of cryptographic agility will be better equipped to handle the coming transition; central banks should identify where inflexible systems are used and plan their substitution, which the report says will most likely be the case for certain types of hardware such as hardware security modules, firewalls and smart cards. The key exchange mechanism could easily accept any post-quantum algorithm, whereas the digital signature standard configuration is not pre-configured to detect the algorithm. On performance, there was no impact at the performance level when sending data through the tunnel whatever the size of the data, because once the post-quantum tunnel is set up information is encrypted with traditional cryptography using AES-256; performance was impacted only when initially setting up the tunnel, which in real-world applications would happen only once or twice during a business day. Rekey testing repeated 100 times showed stable results with the impact confined to the key exchange and asynchronous for the client. On security, hybrid mode mitigates two risks: if legacy asymmetric cryptosystems are broken a post-quantum layer protects data transfer and prevents any regression, and hybridisation makes it easier to replace traditional schemes as they become outdated. There is always a trade-off between performance and security, so security must be configured according to application requirements. CRYSTALS-Kyber showed only a minuscule difference in speed between level 3 and level 5 and appears better suited than FrodoKEM where performance constraints are high; Falcon demonstrated better performance than CRYSTALS-Dilithium; and SPHINCS+ registered slower performance, though as a hash-based algorithm it does not have to be implemented in a hybrid mode because the reliability of that algorithm family is well known. The report's conclusion is that applying post-quantum protocols is already feasible, that migration planning should follow Mosca's model comparing the time needed to migrate plus the time data needs to remain protected against the time for a quantum computer to be ready, and that central banks need to allow for a transition phase in their cyber security roadmaps.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-mas-quantum-cybersecurity-risk-advisory",
      "ietf-rfc-9370-multiple-key-exchanges-ikev2",
      "fr-anssi-pqc-transition-position-follow-up",
      "de-bsi-post-quantum-cryptography-position-tr-02102-1"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "bis-project-mariana-cbdc-wholesale-fx-2023",
    "title": "BIS Project Mariana - Wholesale CBDC Cross-Border FX Settlement: Automated Market Maker (AMM) Design, DeFi Protocol Adaptation for Central Banks and Multi-CBDC Settlement Architecture",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2023-09-28",
    "bluf": "This BIS Innovation Hub project, in collaboration with the central banks of France, Singapore, and Switzerland, successfully tested a proof-of-concept for cross-border wholesale CBDC (wCBDC) foreign exchange settlement using a novel Automated Market Maker (AMM) protocol. The project demonstrates the technical feasibility of adapting DeFi concepts for central bank operations to improve the efficiency, speed, and transparency of international settlements, as detailed in the project's architectural design (Chapter 3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bis-crypto-asset-prudential-standards",
      "iso-20022-messaging"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bis-project-mbridge-cbdc-multi-central-bank-2024",
    "title": "BIS Project mBridge 2024 - Multi-CBDC Platform: Participating Central Banks (PBOC, HKMA, BOT, CBUAE), Minimum Viable Product Launch, Governance Model, Settlement Finality, Privacy Tiers and Potential Expansion to BIS Innovation Hub Members",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation outlines the operational and governance framework for the mBridge multi-central bank digital currency (CBDC) platform, which enables real-time, peer-to-peer cross-border payments and foreign exchange transactions via a distributed ledger. It applies to participating central banks, commercial banks, and observing institutions, with key provisions on jurisdictional preparedness for real-value transactions and platform compatibility with the Ethereum Virtual Machine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bis-cpmi-cross-border-payments-2023",
      "iso-20022-mx-messaging"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bis-sound-practices-ai-financial-stability-2023",
    "title": "BIS Sound Practices for the Use of AI in Financial Services - Compliance Obligations for AI Model Risk Management, Financial Stability AI Controls, and Supervisory Expectations for Bank AI Governance Frameworks",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations for AI model risk management, financial stability controls, and governance frameworks for banks as per BIS Sound Practices; it aligns with EU AI Act (Regulation 2024/1689) high-risk AI system requirements under Articles 9-15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bitcoin-lightning-l402",
    "title": "Bitcoin Lightning L402",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "L402 (formerly LSAT - Lightning Service Authentication Token) is a protocol standard developed by Lightning Labs that enables HTTP 402 Payment Required responses to be resolved via Bitcoin Lightning Network micropayments, allowing servers to monetize API access at the sub-cent level in a fully programmatic, machine-to-machine flow. The protocol combines Lightning Network invoice payment with macaroon-based access tokens (caveat-bearer tokens derived from macaroon cryptography), enabling pay-per-request, pay-per-session, and capability-scoped access models. L402 is foundational to AI agent commerce because it enables agents to autonomously purchase data, compute, or services without requiring pre-registered accounts or OAuth flows. Misconfigured L402 implementations can result in replay attacks (if preimage verification is skipped), privilege escalation (if macaroon caveats are not enforced server-side), or budget drain (if payment is accepted without corresponding service delivery).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fincen-cvc-business-models",
      "crypto-aml-travel-rule",
      "fatf-virtual-asset-redfl"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bj-pdp-law-2009",
    "title": "Benin Personal Data Protection Law - APDP Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Benin Law No. 2009-09 on Protection of Personal Data establishes data subject rights, mandatory controller registration, and prior authorization requirements for sensitive data processing. The Autorité de Protection des Données à Caractère Personnel (APDP) is the designated supervisory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bl-lil-framework",
    "title": "Saint Barthélemy - French Data Protection Law (Loi Informatique et Libertés) Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Saint Barthélemy is a French overseas collectivity located in the northeastern Caribbean Sea. Saint Barthélemy was part of Guadeloupe until 2007 when it became a separate French collectivity. Unlike Guadeloupe and Martinique (which are EU outermost regions where GDPR applies directly) and unlike Saint Martin (also an EU outermost region), Saint Barthélemy was reclassified as an EU Overseas Country and Territory (OCT) in 2012. As an EU OCT rather than an EU outermost region, the General Data Protection Regulation (GDPR) does not apply directly in Saint Barthélemy. The applicable data protection framework is the French Loi Informatique et Libertés (Law on Information Technology and Civil Liberties), which applies in Saint Barthélemy by extension of French sovereignty law. The Commission Nationale de l'Informatique et des Libertés (CNIL) exercises jurisdiction as the supervisory authority for data protection matters in Saint Barthélemy. The Collectivité de Saint-Barthélemy administers the territory. Saint Barthélemy is notable for its high-end tourism economy and significant international business activity, making data protection compliance particularly relevant for hospitality, financial services, and international commerce operating in the territory. Organisations processing personal data of individuals in Saint Barthélemy must comply with the Loi Informatique et Libertés as applicable in French overseas collectivities, implement appropriate security measures, and respect individual rights of access and rectification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/bl-lil-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bletchley-declaration-2023-frontier-ai-safety",
    "title": "Bletchley Declaration on AI Safety - First Global AI Safety Summit (November 2023)",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Bletchley Declaration establishes a global consensus among 28 countries, including the US, UK, EU, and China, to collaboratively address frontier AI risks, particularly catastrophic risks from advanced AI systems, through international safety research and state-led testing of frontier models. Key commitments are outlined in the declaration text agreed at the AI Safety Summit 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-ai-safety-2023",
      "australia-voluntary-ai-safety-standard-2024",
      "anthropic-responsible-scaling-policy-v2-1-2025"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bletchley-declaration-ai-safety-2023",
    "title": "Bletchley Declaration on AI Safety - First Global AI Safety Summit (November 2023)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The Bletchley Declaration, signed on 1-2 November 2023 at Bletchley Park (United Kingdom) at the inaugural AI Safety Summit hosted by the UK government, was the first multilateral statement on frontier AI safety risks - signed by 28 countries including the United States, United Kingdom, European Union, China, France, Germany, Australia, Canada, India, Japan, South Korea, Saudi Arabia, the UAE, and Singapore; the Declaration acknowledged that frontier AI models present potentially catastrophic and irreversible risks to human welfare and safety, particularly through misuse for biological, chemical, nuclear, or radiological weapons capability uplift, cyberattacks, and loss of human control over AI systems; it committed participating states to develop risk-based safety policies for frontier AI, to establish national AI safety institutions to conduct frontier AI safety research and testing, and to engage in ongoing international cooperation through the 'Bletchley Process'; the summit also produced the 'Frontier AI Safety Commitments' signed by 16 major AI companies including Anthropic, Google DeepMind, Meta, Microsoft, OpenAI, Amazon, and Mistral; the Bletchley Declaration initiated the series of international AI safety summits continued in Seoul (May 2024) and Paris (February 2025).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/bletchley-declaration-ai-safety-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-55-systemic-risk-gpai",
      "g7-hiroshima-ai-process-guiding-principles",
      "oecd-ai-principles-2024",
      "uk-ai-safety-institute-framework-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bm-digital-asset-business-act-2018",
    "title": "Digital Asset Business Act 2018 (Bermuda)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Bermuda's Digital Asset Business Act 2018 regulates digital asset business carried on in or from within Bermuda under the supervision of the Bermuda Monetary Authority (BMA). Section 2(2) defines digital asset business as providing any of five activities to the general public: issuing, selling or redeeming digital assets; operating as a payment service provider using digital assets; operating as an electronic exchange; providing custodial wallet services; and operating as a digital asset services vendor. Section 10 prohibits carrying on digital asset business without a licence and sets criminal penalties, Section 13 governs the BMA's grant or refusal of an application against the Schedule 1 minimum criteria, and Section 14 lets the BMA determine the class of licence (the classes under Section 12(3) being a Class F licence and a Class M licence).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-virtual-assets-vasp-2021",
      "bm-pipa-2016"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bm-pipa-2016",
    "title": "Bermuda Personal Information Protection Act 2016",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Bermuda enacted the Personal Information Protection Act 2016 (PIPA), which came into force on 1 January 2017. Administered by the Privacy Commissioner for Bermuda, PIPA establishes rights-based protections for individuals over their personal information held by organisations. Controllers must implement a privacy programme, issue privacy notices, obtain consent for collection and use, respond to access and correction requests, and report privacy breaches to the Privacy Commissioner and affected individuals within prescribed timeframes. PIPA takes an accountability-based approach requiring organisations to demonstrate compliance. Cross-border transfers require comparable protection or consent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/bm-pipa-2016.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bn-pdpo-2021",
    "title": "Brunei Personal Data Protection Order 2025 - AITI Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Brunei Darussalam Personal Data Protection Order 2025 (PDPO, Gazette S 1 of 2025, approved by the Sultan on 8 January 2025) establishes a consent-based framework of data subject rights, mandatory data user registration, lawful basis requirements, and cross-border transfer controls. The Authority for Info-communications Technology Industry of Brunei Darussalam (AITI) is the designated supervisory authority. The 2021 reference was an AITI public consultation paper, not an enacted law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bo-ds-0181-2009-normas-basicas-sabs-sistema-administracion-bienes-servicios",
    "title": "Bolivia Decreto Supremo 0181 of 28 June 2009 - Normas Basicas del Sistema de Administracion de Bienes y Servicios (NB-SABS) as amended",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Bolivian Decreto Supremo 0181 of 28 June 2009 - Normas Basicas del Sistema de Administracion de Bienes y Servicios (NB-SABS / Basic Norms of the Goods and Services Administration System) approved 28 June 2009 as substantially amended over time (most recently by DS 4774/2022) is the principal Bolivian regulatory instrument governing procurement of goods, services, and works by entities of the State Public Administration including the Central Government (Organo Ejecutivo) ministries, the Legislative Organ (Organo Legislativo), the Judicial Organ (Organo Judicial), the Electoral Organ (Organo Electoral), Decentralized Institutions, Autonomous Decentralized Institutions, public-sector enterprises, Departmental Autonomous Governments (Gobiernos Autonomos Departamentales), Municipal Autonomous Governments (Gobiernos Autonomos Municipales), Indigenous Autonomous Governments (Gobiernos Autonomos Indigena Originario Campesinos), and other entities of the public sector financed by the State budget. NB-SABS replaced the prior procurement regime under DS 27328 of 2004 and implements the Constitution of the Plurinational State of Bolivia 2009 procurement principles including transparency, equity, and Buen Vivir (Vivir Bien) sovereignty principles. The Ministerio de Economia y Finanzas Publicas through the Direccion General de Sistemas de Gestion de Informacion Fiscal (DGSGIF) and the Sistema de Contrataciones Estatales (SICOES / sicoes.gob.bo) operate the federal e-procurement platform. Procurement methods established by NB-SABS art. 33 to 71 comprise (a) Licitacion Publica (Public Tender, the default open public procedure for high-value acquisitions above Bs 1,000,000), (b) Apoyo Nacional a la Produccion y Empleo (ANPE / National Support to Production and Employment, for medium-value acquisitions between Bs 50,000 and Bs 1,000,000), (c) Contratacion Menor (Minor Procurement, for small-value below Bs 50,000), (d) Contratacion por Excepcion (Exception Procurement, sole-source under prescribed exceptions in art. 65), (e) Contratacion por Desastres o Emergencias (Disaster or Emergency Procurement), and (f) Contratacion Directa de Bienes y Servicios (Direct Procurement under prescribed exceptions). The Contraloria General del Estado conducts ex-post procurement audit. Bolivia is NOT a party to the WTO Government Procurement Agreement (GPA). Bolivia is a party to the Andean Community Decision 439, ALBA-TCP, and UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "bo-pdp-decree-2013",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "bo-pdp-decree-2013",
    "title": "Bolivia Supreme Decree No. 1793 on Protection of Personal Data in Information Systems (2013)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Bolivia enacted Supreme Decree No. 1793 of 13 November 2013 on the Protection of Personal Data in Information Systems, providing a regulatory framework for the processing of personal data by public and private entities operating information systems. The Decree is implemented within the framework of Law No. 164 (Ley General de Telecomunicaciones, Tecnologías de Información y Comunicación, 2011), which provides the overarching legislative basis. It establishes obligations for information system operators to implement security measures to protect personal data, obtain consent from data subjects before processing, restrict use of personal data to the declared purpose, and respect data subject rights of access and correction. The Authority of Supervision and Social Control for Telecommunications and Transport (ATT) oversees compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/bo-pdp-decree-2013.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bolivia-mining-metallurgy-law-535-2014-ajam",
    "title": "Bolivia Ley de Mineria y Metalurgia No. 535 de 28 de Mayo de 2014 (AJAM, Lithium and Potassium Strategic Elements, Cooperative Mining, Indigenous Participation, Royalty and Patente Regime)",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Bolivia's Ley de Mineria y Metalurgia No. 535, enacted 28 May 2014 and published 2 June 2014, comprehensively regulates mining-metallurgical activities throughout Bolivian territory. Article 2 confirms that mineral resources are the direct, indivisible, and imprescriptible property of the Bolivian people. The Autoridad Jurisdiccional Administrativa Minera (AJAM) is established under Article 39 as the autonomous entity responsible for the mining cadastre, contracts, and licensing through departmental and regional offices. Article 10 defines the regulated mining chain (cateo, prospeccion, exploracion, explotacion, beneficio, fundicion y refinacion, comercializacion, industrializacion). Article 26 declares lithium and potassium strategic elements reserved for exclusive state enterprise exploitation, which underpins Bolivia's lithium nationalization policy in the Salar de Uyuni. Article 34 defines cooperativas mineras as self-managed, non-profit social-economic institutions. Article 19 grants indigenous nations and peoples the right to participate in benefits from resource exploitation through royalty regimes and prior consultation mechanisms. Title VII establishes the Regalia Minera (royalty) and Patente Minera (licence fee) as fiscal mechanisms with automatic transfer to departmental and municipal accounts. The law is enforced through AJAM administrative procedures, with the Ministerio de Mineria y Metalurgia setting policy and YLB (Yacimientos de Litio Bolivianos) as the state lithium enterprise. The Plurinational Constitutional Court has supremacy over constitutional disputes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "key_institutions",
        "article_2_state_ownership",
        "article_10_mining_chain",
        "article_19_indigenous_participation",
        "article_26_lithium_potassium_strategic",
        "article_34_cooperative_mining",
        "article_39_ajam",
        "title_vii_fiscal_regime",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "chile-mining-code-1983",
      "peru-general-mining-law-ds-014-92-em",
      "colombia-mining-code-law-685-2001",
      "eu-critical-raw-materials-act-2024-1252"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "bologna-process-higher-education-area-2020",
    "title": "Bologna Process - European Higher Education Area (EHEA): Three-Cycle System (Bachelor/Master/Doctoral), ECTS Credits, Diploma Supplement, Recognition of Qualifications and Quality Assurance Standards",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes the framework for the European Higher Education Area (EHEA), requiring member states to implement a three-cycle degree system, use ECTS credits, issue Diploma Supplements, ensure recognition of qualifications, and adhere to quality assurance standards as defined in the 2015 Yerevan Communiqué and 2018 Paris Communiqué. It applies to all higher education institutions in EHEA member countries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-education-action-plan-2021-2027",
      "eu-european-research-area-policy-agenda-2022",
      "iso-21001-2018-educational-organizations-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "bonn-convention-1979-conservation-migratory-species",
    "title": "Convention on Migratory Species 1979 (Bonn Convention) - Appendix I-II Listed Species and Agreement Framework",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Convention on the Conservation of Migratory Species of Wild Animals (Bonn Convention or CMS) was adopted on 23 June 1979 in Bonn, Germany and entered into force on 1 November 1983. It is an environmental treaty under the United Nations Environment Programme (UNEP) providing a global framework for the conservation of terrestrial, aquatic and avian migratory species and their habitats. Migratory species under threat of extinction are listed on Appendix I (currently approximately 175 species); Parties are obligated to provide strict protection of these animals. Migratory species needing or that would significantly benefit from international cooperation are listed on Appendix II (currently approximately 750 species); for these CMS encourages Parties to conclude global or regional Agreements. Approximately 30 Agreements and Memoranda of Understanding (MoUs) operate under CMS framework including legally binding Agreements (e.g. ASCOBANS for small cetaceans of Baltic, AEWA for African-Eurasian Migratory Waterbirds, EUROBATS for European bats, ACCOBAMS for cetaceans of Black Sea/Mediterranean) and non-binding MoUs (e.g. Sharks MoU, Raptors MoU). 134 Parties to CMS as of 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cbd-convention-biological-diversity-1992",
      "ramsar-convention-1971-wetlands-international-importance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "botswana-mines-and-minerals-act-cap-66-01",
    "title": "Botswana Mines and Minerals Act Chapter 66:01 - Diamond and Mineral Mining Rights Framework",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Botswana's Mines and Minerals Act Chapter 66:01 (as amended) vests all mineral rights in the state regardless of land ownership; establishes a licensing regime for prospecting licences, mining licences, mineral concessions, and quarrying licences administered by the Department of Mines; requires environmental management plans approved by the Department of Environmental Affairs; imposes royalties on mineral production (10% for diamonds, 5% for base metals, 3% for coal); mandates citizen economic empowerment through the Mining Local Content Policy; and governs the Debswana joint venture framework that represents the world's largest diamond production operation by value.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icmm-mining-principles-2020",
      "ilo-c176-safety-health-mines-convention-1995"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bpmn-2-0-business-process-model-notation",
    "title": "Business Process Model And Notation (BPMN™) Version 2.0",
    "domain": "Operations & CX",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "BPMN 2.0 defines a standardized graphical notation and XML schema for modeling, executing, and exchanging business processes. It applies to organizations and stakeholders involved in business process design, automation, and interoperability, requiring compliance with its flow objects, connecting objects, swimlanes, artifacts, and execution semantics as specified in the OMG formal specification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-22301-bcm-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bpmn-2-0-omg-specification-workflow-notation",
    "title": "OMG Business Process Model and Notation 2.0 (BPMN) - Standard Workflow Notation: Flow Objects, Connecting Objects, Swimlanes and Process Diagrams",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This standard defines the syntax and semantics for modeling business processes using BPMN 2.0, including Flow Objects (Events, Activities, Gateways), Connecting Objects (Sequence Flows, Message Flows), Swimlanes (Pools, Lanes), and Artifacts. It applies to organizations and software vendors implementing workflow automation systems that require interoperable process modeling, as specified in Section 5.2 (Core Elements) and Section 7.3 (Process Diagrams).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "automation-bpmn-service-task",
      "automation-bpmn-error-boundary",
      "automation-bpmn-agent-handover"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bq-gdpr-framework",
    "title": "Caribbean Netherlands (Bonaire, Sint Eustatius, Saba) - Personal Data Protection Act BES (Wbp BES) Framework",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The Caribbean Netherlands - comprising the islands of Bonaire, Sint Eustatius, and Saba (collectively known as the BES Islands) - are special municipalities of the Netherlands located in the Caribbean Sea. Since 10 October 2010, when the Netherlands Antilles was dissolved, the BES Islands became direct special municipalities of the Netherlands. For European Union law purposes, however, the BES Islands have Overseas Countries and Territories (OCT) status and are NOT EU territory, so the EU General Data Protection Regulation (GDPR) does not apply directly there. Data protection in the Caribbean Netherlands is instead governed by the separate Personal Data Protection Act BES (Wet bescherming persoonsgegevens BES, Wbp BES), which provides GDPR-comparable - not GDPR-identical - protection. Organisations established in the Caribbean Netherlands or processing personal data of individuals located in Bonaire, Sint Eustatius, or Saba must comply with the Wbp BES, including requirements for a lawful basis, data subject rights, security measures, and breach handling. The Dutch GDPR Implementation Act (Uitvoeringswet AVG) and the GDPR's Article 30/32/13 obligations do not extend to the BES Islands as direct law. The Caribbean Netherlands use the US dollar as currency and have a distinct governance structure from European Netherlands.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/bq-gdpr-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "br-aml-law-9613-1998-anti-money-laundering-coaf-uif",
    "title": "Brazil Lei 9.613 de 3 de Marco de 1998 (Anti-Money Laundering Law) as Amended by Lei 12.683/2012 - Money Laundering Offence, Obliged Persons and COAF / UIF Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "Brazil's Lei 9.613 of 3 March 1998 (Lei de Lavagem de Dinheiro), as comprehensively amended by Lei 12.683 of 9 July 2012, is the principal federal statute criminalising money laundering in Brazil and imposing obligations on a broad list of obliged persons (pessoas obrigadas) to identify customers, maintain records and report suspicious transactions to the Conselho de Controle de Atividades Financeiras (COAF), now operating within the Banco Central do Brasil as the Unidade de Inteligência Financeira (UIF) following Lei Complementar 187/2021 and Decreto 10.270/2020. Article 1 of Lei 9.613/1998 criminalises money laundering as concealing or disguising the nature, origin, location, disposition, movement or ownership of assets, rights or values derived directly or indirectly from any criminal offence (the Lei 12.683/2012 amendment removed the prior closed list of predicate offences, making money laundering a derivative of any criminal offence including tax offences from Lei 8.137/1990); penalty is imprisonment from three to ten years and a fine, increased by one-third to two-thirds where the crime is committed in a systematic manner or through a criminal organisation. Article 9 lists the broad scope of obliged persons including: financial institutions and equivalents under Lei 4.595/1964 article 17, insurance companies and pension funds, securities and commodity brokers, distributors of lottery tickets, real estate transactions, dealers in jewellery, precious stones, precious metals and works of art, factoring companies, junkets and casinos in jurisdictions where authorised, electronic-asset and virtual-asset service providers (after the Lei 14.478/2022 cryptoassets framework), legal and accountancy professionals providing covered services, and dealers in luxury goods. Article 10 requires obliged persons to identify customers and beneficial owners, maintain records for at least five years, and adopt internal controls and policies. Article 11 requires reporting of suspicious transactions and operations meeting specified thresholds to COAF/UIF within twenty-four hours of identification, regardless of execution. Article 14 establishes COAF as the FIU (now operating in the Banco Central do Brasil under Lei Complementar 187/2021). Sanctions for failure to comply include administrative penalties up to BRL 20 million or twice the suspected operation value (whichever is greater), with the Banco Central, the Comissão de Valores Mobiliários (CVM), the Superintendência de Seguros Privados (SUSEP) and other functional regulators exercising sectoral supervisory powers under their respective enabling laws. Brazil is a FATF member and the AML regime aligns substantively with the FATF 40 Recommendations following the 2010 and 2023 mutual evaluations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "money_laundering_offence_anchor",
        "obliged_persons_anchor",
        "reporting_obligations_anchor",
        "coaf_uif_anchor",
        "sectoral_supervisor_anchor",
        "industry_mapping",
        "fatf_alignment_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-40-recommendations-2023-consolidated",
      "eu-aml-regulation-2024-1624",
      "us-bank-secrecy-act-1970"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "br-anpd-resolution-cd-15-incident-notification",
    "title": "Brazil ANPD Resolution CD/ANPD No. 15 - Security Incident Notification under the LGPD",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Controllers of personal data subject to the Lei Geral de Protecao de Dados (LGPD) in Brazil must apply Resolution CD/ANPD No. 15 to the communication of security incidents involving personal data, including notification to the National Data Protection Authority (ANPD) and to data subjects, with the ANPD's enforcement practice (including its action against the National Social Security Institute requiring public website disclosure and user notification) demonstrating the operational expectations, and with the ANPD's 2025-2026 regulatory agenda (Resolution CD/ANPD No. 23 of 9 December 2024) and 2026-2027 Priority Themes Map placing children's data protection, targeted advertising, public-sector data sharing, and artificial intelligence at the centre of enforcement scrutiny.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "br-lgpd-13709-2018-article-48-security-incident-notification"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "br-bacen-resolution-4966-credit-risk-2021",
    "title": "Brazil CMN Resolution 4,966/2021 - Credit Risk Classification and Provisioning (BACEN)",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "CMN Resolution No. 4,966 of 25 November 2021 (Conselho Monetário Nacional / Banco Central do Brasil) consolidated and replaced CMN Resolution 2,682/1999 as Brazil's primary credit risk classification and minimum provisioning framework. It mandates a nine-level rating scale (AA through H) with prescribed minimum provisions (AA=0%, A=0.5%, B=1%, C=3%, D=10%, E=30%, F=50%, G=70%, H=100%), mandatory reclassification timelines triggered by days-past-due, cross-default rules, write-off at 360 days, monthly reporting to the Central Credit Risk Registry (SCR), and ICAAP stress testing obligations for Type 3-4 institutions under BACEN Resolution 4,557/2017.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-brrd-bank-recovery-resolution-directive-2014-59",
      "eu-crr3-capital-requirements-regulation-2024-1623"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "br-cade-competition-act-2011",
    "title": "Brazil Competition Defense Law 2011 (Lei No. 12,529 of 30 November 2011 - Lei de Defesa da Concorrência)",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Lei de Defesa da Concorrência (Competition Defense Law - Law No. 12,529 of 30 November 2011) is Brazil's principal antitrust statute, which restructured Brazil's competition law framework and established the CADE (Conselho Administrativo de Defesa Econômica - Administrative Council for Economic Defense) as a consolidated, independent federal agency with three internal bodies: the Administrative Tribunal (Tribunal Administrativo - decision-making body); the Superintendent General (Superintendência-Geral - investigative and prosecutorial body); and the Department of Economic Studies (Departamento de Estudos Econômicos - economic analysis body). The Law No. 12,529/2011 replaced the prior fragmented framework under Laws 8,884/1994 and 8,137/1990 and aligned Brazilian competition law more closely with international standards. Anticompetitive conduct (Art. 36 of Law No. 12,529/2011): any conduct by one or more natural persons or legal entities, whether private or public, national or foreign, constitutes an antitrust violation if it: limits, reduces, or otherwise harms open competition; controls the relevant market for goods or services; arbitrarily increases profits; or abuses a dominant position. Market dominance is presumed when an undertaking or group holds 20% or more of the relevant market. Administrative fines for anticompetitive conduct range from 0.1% to 20% of the company's or group's gross revenues in Brazil in the year prior to the CADE investigation, with the fine floored at the advantage gained, the economic harm caused, or R$50,000 (for individuals). For cartels (horizontal price-fixing, market allocation, output restriction, bid rigging), CADE typically applies fines of 15-20% of gross revenues. Merger control: Law No. 12,529/2011 introduced a mandatory pre-merger notification (suspensory) system under Arts. 88-92. Pre-merger filing is mandatory where at least one economic group involved recorded gross revenues in Brazil in the year preceding the transaction of at least R$750 million (threshold updated by CADE Ordinance No. 994/2022, previously R$400 million) AND at least one other economic group recorded gross revenues in Brazil of at least R$75 million (previously R$30 million). The CADE's Merger Review Procedure: after filing, CADE has 240 calendar days to render a final decision (extendable to 330 days by CADE reasoned decision); CADE may approve, approve conditionally (with behavioural or structural remedies - consent decrees), or prohibit the merger. Closing a notifiable transaction before CADE clearance (gun-jumping) constitutes a separate antitrust violation subject to fines of R$60,000 to R$60 million for gun-jumping independent of the merger review outcome. Leniency program (Art. 86): the first undertaking to approach CADE and meet the leniency requirements before CADE has evidence of the cartel receives full immunity from administrative fines and, through coordination with the Prosecution General, from criminal prosecution under Law 8,137/1990; subsequent applicants may receive reductions of one-third to two-thirds of applicable fines. Criminal cartel sanctions under Law No. 8,137/1990 include imprisonment of two to five years (or fine) for individuals who participate in cartel conduct; criminal prosecution may proceed independently of CADE administrative proceedings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tfeu-article-102-abuse-of-dominance",
      "us-ftc-act-section-5-unfair-competition"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "br-decreto-11713-escola-conectada-connectivity-2023",
    "title": "DECRETO N� 11.713, DE 26 DE SETEMBRO DE 2023 - Institui a Estrat�gia Nacional de Escolas Conectadas.",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This decree establishes the National Strategy for Connected Schools (Enec) and its Executive Committee, which is obligated to define technical parameters, set goals, and monitor the universalization of quality internet connectivity for pedagogical and administrative use in public basic education schools.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brazil-marco-civil-internet-2014-law-12965"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "br-gov-br-platform-lgpd-digital-identity",
    "title": "Brazil gov.br Platform Digital Identity under LGPD and Digital Government Initiatives",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2024-12-01",
    "bluf": "Brazil's national digital identity platform is gov.br, operated by the Ministry of Management and Innovation in Public Services (MGI) with technical operations by the Federal Data Processing Service (Serpro). The gov.br digital identity provides federated authentication, electronic signing (gov.br Sign), and access to over 4,400 federal services through three account assurance levels: Bronze (self-asserted with CPF and basic data), Silver (federated with banking partners or facial biometric matching), and Gold (verified with biometric matching against the Federal Election Authority or with eID-compliant certified providers). Authentication is anchored in the CPF (Cadastro de Pessoas Físicas) issued by the Federal Revenue Service (Receita Federal do Brasil).\n\nThe Lei Geral de Proteção de Dados Pessoais (LGPD), Law No. 13,709 of 2018, supplies the personal data protection regime that governs all processing of personal data through gov.br services. The LGPD requires a lawful basis under Article 7 (for non-sensitive data) or Article 11 (for sensitive data including biometric data), gives data subjects the rights listed in Article 18, mandates accountability under Article 50 of the LGPD, and is enforced by the National Data Protection Authority (Autoridade Nacional de Proteção de Dados, ANPD). The General Data Protection Authority may issue warnings, fines up to 2 percent of revenue (capped at BRL 50 million per infraction), publication orders, blocking, and elimination orders under Article 52. ICP-Brasil (Infraestrutura de Chaves Publicas Brasileira) provides the qualified-certificate-based digital signing infrastructure under Provisional Measure No. 2,200-2 of 2001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nist-sp-800-63-4-2025-digital-identity-guidelines",
      "br-lgpd-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "br-law-6360-1976-anvisa-drug-registration",
    "title": "Brazil Law 6360 of 1976 Health Surveillance of Drugs Medicines Cosmetics and Sanitary Products ANVISA Drug Registration Manufacturing Authorisation and RDC Resolutions Framework",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "Brazil Law No. 6.360 of 23 September 1976 establishes the foundational legal framework for health surveillance of drugs medicines cosmetics sanitary products and related items administered by Agência Nacional de Vigilância Sanitária (ANVISA) under the Ministry of Health organised in operative chapters covering Chapter 1 General Provisions Chapter 2 Companies authorisation including authorisation of operation (autorização de funcionamento) and good practices certification Chapter 3 Registration of Products including drug registration (registro de medicamento) with mandatory specifications for safety efficacy and quality Chapter 4 Sale and Distribution Chapter 5 Labelling Chapter 6 Sanitary Inspection and Surveillance Chapter 7 Administrative Procedures and Chapter 8 Penalties including fines product seizure and authorisation revocation. Implementation through ANVISA Resolutions of the Collegiate Board (Resoluções da Diretoria Colegiada RDC) including RDC 753/2022 on Good Manufacturing Practices RDC 658/2022 on drug registration and successor resolutions on clinical trials biosimilars and orphan drugs. Brazil is a full member of ICH and PIC/S harmonising with international pharmaceutical standards while maintaining MERCOSUR pharmaceutical regulatory cooperation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "br-ldb-lei-9394-education-framework-digital-update",
    "title": "Lei N� 9.394, de 20 de Dezembro de 1996: Estabelece as diretrizes e bases da educa��o nacional",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes the State's duty to guarantee public education in Brazil, mandating free basic education from ages 4 to 17, specialized support for students with disabilities, and supplementary programs for materials, transport, food, and health.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "br-lei-14133-2021-new-public-procurement-law-nova-lei-licitacoes",
    "title": "Brazil Lei 14.133, de 1 de abril de 2021 — Nova Lei de Licitacoes e Contratos Administrativos (New Public Procurement Law)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "Lei 14.133, de 1 de abril de 2021 (the Nova Lei de Licitacoes e Contratos Administrativos / New Public Procurement Law) is the unified Brazilian federal procurement statute that consolidates and replaces the prior Lei 8.666/1993 (general procurement law), Lei 10.520/2002 (pregao electronic auction), and Lei 12.462/2011 (RDC differentiated procurement regime) after a transitional coexistence period that ended in April 2023. The law applies to direct federal administration, autarchies, public foundations, federal public companies and mixed-capital companies (with adaptations under Lei 13.303/2016 for state-owned enterprises), and is widely adopted by state and municipal procurement authorities through state-level implementing regulations. The statute is structured across seventeen Titles spanning the procurement lifecycle including Title I General Provisions and principles (Articles 5-13 setting the operative principles of legality, impersonality, morality, publicity, efficiency, public interest, probity, planning, transparency, competitive procurement, environmental sustainability, and economic development), Title II planning (Articles 14-19), Title III procurement modalities (arts. 28 to 32 including the modalities pregao electronic auction, concorrencia traditional competitive procedure, concurso for design and intellectual works, leilao public auction, dialogo competitivo competitive dialogue), Title IV procedural phases (Articles 17-21 including preparatory phase, public invitation phase, bid presentation, judgement, qualification, ratification and signing), Title V contracts (Articles 89-122 including form, duration, modification, performance guarantees, payment), Title VI nullities and appeals (Articles 147-155), Title VII alternative dispute resolution (Articles 151-154 including mediation, conciliation, and arbitration), Title VIII the Portal Nacional de Contratacoes Publicas / PNCP transparency portal (art. 174), and Title XIV administrative sanctions and integrity (Articles 155-163). Key innovations of Lei 14.133 include the dialogo competitivo (Articles 32-33) for high-complexity acquisitions where the administration cannot define the technical solution upfront, the integrity programme requirement (art. 25) for contracts above defined thresholds, the unified Portal Nacional de Contratacoes Publicas (art. 174) as the mandatory federal transparency and notification channel, the explicit treatment of sustainable procurement criteria (Article 11 paragraph III), and the unified administrative sanctions regime with a Cadastro Nacional de Empresas Inidoneas e Suspensas (CEIS) and Cadastro Nacional de Empresas Punidas (CNEP) coordination. The law operationalises Brazil's commitments under UNCITRAL Model Law principles and complements the broader anti-corruption regime under Lei 12.846/2013 (Lei Anticorrupcao) and Decreto 11.129/2022 implementing regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "br-lei-15352-2026-anpd-agencia-nacional-protecao-dados",
    "title": "Brazil Lei 15.352/2026: ANPD Becomes the Agencia Nacional de Protecao de Dados (Regulatory Agency)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "Lei No. 15.352 of 25 February 2026 (conversion of Medida Provisoria 1.317/2025) amends the LGPD (Lei 13.709/2018) to establish the Agencia Nacional de Protecao de Dados (ANPD). New Article 55-A of the LGPD creates the ANPD as an autarquia de natureza especial linked to the Ministry of Justice and Public Security, endowed with functional, technical, decision-making, administrative and financial autonomy, with its own assets and with seat and forum in the Federal District, under the terms of Lei 13.848/2019 (the regulatory agencies framework law). The law updates LGPD Article 5 definitions so the encarregado (data protection officer) is the communication channel between controller, data subjects and the ANPD as an agency, amends Lei 10.871/2004 to create the Carreira de Regulacao e Fiscalizacao de Protecao de Dados (data protection regulation and inspection career), amends Lei 15.211/2025 (Estatuto Digital da Crianca e do Adolescente) regarding the start of that statute's effectiveness, and revokes Medida Provisoria 1.319/2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "br-lgpd-2018",
      "br-lgpd-lei-13709-chapter-8-anpd-penalties"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "br-lei-9472-1997-lei-geral-telecomunicacoes",
    "title": "Lei No. 9.472/1997 (Lei Geral de Telecomunicacoes): ANATEL, Executive Competencies, Service Definition, Public Regime and Spectrum",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Lei No. 9.472, de 16 de julho de 1997 (Lei Geral de Telecomunicacoes, the General Telecommunications Law) is the principal Brazilian statute governing the organisation of telecommunications services and the creation of the sector regulator. Article 8 creates the Agencia Nacional de Telecomunicacoes (ANATEL) as an entity of the indirect federal public administration, under a special autarchic regime and linked to the Ministry of Communications, with the function of being the telecommunications regulatory body, seated in the Federal District. Article 18 sets out the competencies of the Executive Branch, which acts by decree to, among other things, institute or eliminate the provision of a service modality under the public regime, approve the general plan of service grants and exercise other functions reserved to the Executive. Article 60 defines a telecommunications service as the set of activities that enables the offer of telecommunication, and defines telecommunication as the transmission, emission or reception of symbols, characters, signals, writing, images, sounds or information of any nature by wire, radioelectricity, optical means or any other electromagnetic process. Article 64 establishes that telecommunications services of collective interest whose existence, universalisation and continuity the Union itself undertakes to ensure are provided under the public regime (regime publico), including the various modalities of the fixed telephone service. Article 157 declares that the radiofrequency spectrum is a limited resource constituting a public good administered by the Agency. The Law is the constitutional-level framework statute for telecommunications regulation, service classification and spectrum administration in Brazil.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brazil-marco-civil-internet-2014-law-12965"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "br-lei-inclusao-13146-digital-accessibility-obligations",
    "title": "Lei Nº 13.146, de 6 de Julho de 2015 - Institui a Lei Brasileira de Inclusão da Pessoa com Deficiência (Estatuto da Pessoa com Deficiência)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must understand the legal definitions of disability and accessibility, and when conducting a disability evaluation, it must be a biopsychosocial assessment performed by a multidisciplinary team considering specified physical, social, and functional factors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "br-lgpd-13709-2018-article-18-data-subject-rights",
    "title": "Lei Geral de Proteção de Dados Pessoais (LGPD) - Article 18: Rights of the Data Subject",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article establishes the fundamental right of data subjects to obtain information from the data controller about their personal data being processed, at any time and upon request.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "br-lgpd-13709-2018-article-48-security-incident-notification",
    "title": "Lei Geral de Proteção de Dados Pessoais (LGPD) - Article 48",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "The controller must notify the national authority and the data subject of any security incident that could result in significant risk or harm to the data subjects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "br-lgpd-13709-2018-article-7-lawful-basis-processing-personal-data",
    "title": "Lei Geral de Proteção de Dados Pessoais (LGPD) - Article 7: Lawful Bases for Processing Personal Data",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must ensure that any processing of personal data is conducted only under one of the lawful bases specified in the regulation, such as obtaining consent from the data subject.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "br-lgpd-2018",
    "title": "Brazil General Personal Data Protection Law 2018 (Lei Geral de Proteção de Dados Pessoais - LGPD, Law No. 13,709 of 14 August 2018)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The LGPD (Lei Geral de Proteção de Dados Pessoais - General Personal Data Protection Law, Law No. 13,709 of 14 August 2018, as amended by Law No. 13,853 of 8 July 2019 and Law No. 14,010 of 10 June 2020) is Brazil's comprehensive personal data protection statute, closely modelled on the EU General Data Protection Regulation (GDPR) while adapted to the Brazilian legal and economic context. The LGPD applies to any processing of personal data carried out in Brazilian territory, where the purpose is the offering or supply of goods or services to individuals located in Brazil, or where the personal data to be processed has been collected in Brazil, regardless of the location of the data controller or processor. The LGPD is administered and enforced by the ANPD (Autoridade Nacional de Proteção de Dados - National Data Protection Authority), established as an independent federal body by Law No. 13,853/2019. Ten legal bases for processing personal data are established under Art. 7 of the LGPD: (1) consent of the data subject (freely given, informed, specific, and unambiguous); (2) compliance with a legal obligation of the controller; (3) execution of public policies by the government; (4) for research bodies, for studies, guaranteed anonymisation where possible; (5) execution or preliminary procedures of a contract to which the data subject is a party; (6) regular exercise of rights in judicial, administrative, or arbitration proceedings; (7) protection of life or physical safety of the data subject or a third party; (8) protection of health, in procedures carried out by health professionals or health services; (9) legitimate interests of the controller or a third party (restricted interpretation - available only for specific processing purposes and subject to a balancing test); and (10) credit protection including fraud prevention. Special categories of personal data (Art. 11 LGPD) - racial or ethnic origin, religious belief, political opinion, trade union membership, religious, philosophical, or political organisation affiliation, health or sex life data, genetic or biometric data when linked to a natural person - require explicit specific consent or one of the exhaustive alternative legal bases (legal obligation, vital interests, public interest, public health, research, regular exercise of rights). Data subject rights under Art. 18 include: confirmation of existence of processing; access to data; correction of incomplete, inaccurate, or outdated data; anonymisation, blocking, or deletion of unnecessary or excessive data; data portability; deletion of data processed with consent; information about third-party sharing; possibility of denying consent and consequences; revocation of consent; and review of automated decisions affecting the data subject's interests. International data transfers (Art. 33) are permitted only: to countries or international organisations that provide adequate protection (ANPD adequacy decision); through specific contractual clauses or global corporate norms (standard contractual clauses or binding corporate rules) approved by the ANPD; through compliance with a seal or certification recognised by the ANPD; or on the basis of a narrow set of exceptions (consent, legal obligations, vital interests, public interest, contract). Administrative penalties under Art. 52 for LGPD violations include: warning with remediation period; simple fine of up to 2% of the revenues of the legal entity or group in Brazil in its last financial year, limited to R$50 million per infringement; daily fine, also capped at R$50 million; publication of the violation after conclusion of proceedings; temporary blocking of personal data to which the violation relates; deletion of the personal data to which the violation relates; partial or total suspension of the operation of the database; partial or total prohibition of processing-related activities. Penalties may be cumulated. The ANPD progressively implemented administrative sanctions from August 2021 (guidance period) with full enforcement from 2022.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "br-lgpd-article-41-data-protection-officer",
    "title": "Lei Geral de Proteção de Dados Pessoais (LGPD) - Article 41: Data Protection Officer",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations acting as data controllers must appoint a Data Protection Officer (encarregado) and publicly disclose their contact information, with this officer being responsible for handling communications from data subjects and the national authority, and providing internal guidance on data protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-37-dpo",
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "br-lgpd-law-13709-2018-data-protection-principles",
    "title": "Brazil LGPD (Lei Geral de Protecao de Dados) - Data Protection Principles and Subject Rights",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Brazil's Lei Geral de Protecao de Dados Pessoais (LGPD, Law 13,709/2018) establishes 10 lawful bases for processing personal data, grants data subjects rights of access, correction, deletion and portability, requires DPO appointment for high-risk controllers, mandates breach notification to ANPD within 2 working days, and imposes penalties up to 2% of Brazil revenue (capped at BRL 50 million per violation) enforced by the Autoridade Nacional de Protecao de Dados.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-6-lawful-basis-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "br-lgpd-lei-13709-article-5-definitions",
    "title": "Lei Nº 13.709/2018 (Lei Geral de Proteção de Dados Pessoais - LGPD) - Article 5: Definitions",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the official legal definitions for key terms used throughout the LGPD, such as personal data, sensitive data, controller, processor, and consent, which organizations must use to classify data and roles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "br-lgpd-lei-13709-chapter-2-personal-data-processing",
    "title": "Lei Nº 13.709, de 14 de Agosto de 2018 (General Personal Data Protection Law - LGPD) - Chapter I: Preliminary Provisions",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes the territorial and material scope of Brazil's data protection law, defining which data processing activities are covered and outlining specific exemptions for purposes such as journalism, state security, and certain international data flows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "br-lgpd-lei-13709-chapter-3-rights-of-data-subjects",
    "title": "Lei Nº 13.709, de 14 de Agosto de 2018 (Lei Geral de Proteção de Dados Pessoais - LGPD) - Chapter III Rights of the Data Subject",
    "domain": "Data Protection & Privacy",
    "version": "2.0.0",
    "last_updated": "2026-07-03",
    "bluf": "Chapter III of Brazil's data protection law guarantees data subjects nine enumerated rights against controllers, including confirmation of processing, access, correction, anonymization, blocking or deletion, portability, deletion of consented data, information about data sharing and consent refusal, and revocation of consent, plus the right to human-reviewable challenge of solely automated decisions and to petition the national authority or the courts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "br-lgpd-lei-13709-chapter-7-security-good-practices",
    "title": "Lei Nº 13.709, de 14 de Agosto de 2018 (Lei Geral de Proteção de Dados Pessoais - LGPD), Chapter VII (Articles 46-51)",
    "domain": "Data Protection & Privacy",
    "version": "2.0.0",
    "last_updated": "2026-07-03",
    "bluf": "Chapter VII of Brazil's General Data Protection Law (LGPD), titled Security and Good Practices (Articles 46 to 51), obliges processing agents to adopt technical and administrative security measures from product conception through execution, extends the information security duty to anyone intervening in processing even after it ends, requires controllers to communicate security incidents that may create relevant risk or damage to the national authority (ANPD) and to data subjects with defined minimum content, requires processing systems to be structured to meet security, good practice, governance and legal principle requirements, and allows controllers and operators to formulate published good practice and governance rules including a privacy governance program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "br-lgpd-lei-13709-chapter-8-anpd-penalties",
    "title": "Lei Nº 13.709, de 14 de Agosto de 2018 (Lei Geral de Proteção de Dados Pessoais - LGPD), Capítulo VIII, Da Fiscalização, Seção I, Das Sanções Administrativas (Artigos 52-54)",
    "domain": "Data Protection & Privacy",
    "version": "2.0.0",
    "last_updated": "2026-07-03",
    "bluf": "Chapter VIII, Section I of Brazil's LGPD establishes the administrative sanctions regime enforced by the national data protection authority (ANPD): Article 52 lists the sanctions (warning with corrective deadline, simple fine of up to 2% of the private entity's, group's or conglomerate's revenue in Brazil in its last fiscal year excluding taxes, capped at R$ 50,000,000.00 per infraction, daily fine subject to the same cap, publicization of the infraction, blocking and deletion of the affected personal data, and, as added by Lei 13.853/2019, partial suspension of the database, suspension of the processing activity, and partial or total prohibition of data processing activities) together with eleven gradation criteria; Article 53 requires the ANPD to define fine calculation methodologies through a regulation subject to public consultation; and Article 54 sets the justification and notice requirements for daily fines. Article 55-K assigns the application of these sanctions exclusively to the ANPD.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "br-pned-lei-14533-digital-education-policy-2023",
    "title": "Lei N� 14.533, de 11 de Janeiro de 2023 - Institui a Pol�tica Nacional de Educa��o Digital (PNED)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This law establishes the National Digital Education Policy (PNED), requiring relevant entities to implement strategies for digital inclusion and education, including promoting digital skills, providing accessible infrastructure, and ensuring digital rights and data protection in educational settings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "brazil-ai-bill-2023",
    "title": "Brazil Artificial Intelligence Framework (PL 2338/2023) - Federal AI Regulation Proposal",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-05-29",
    "bluf": "This bill establishes a risk-based framework for AI systems in Brazil, requiring providers and deployers to conduct impact assessments, implement governance measures, and ensure transparency, particularly for systems classified as high-risk (Article 15) or excessive-risk (Article 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "eu-ai-act-high-risk",
      "brazil-lgpd-compliance",
      "nist-ai-rmf-1-0",
      "nist-sp-1270-managing-ai-bias"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "brazil-ai-bill-2338-2023-senate",
    "title": "Brazil AI Bill 2338/2023 (Senate) - Risk-Based Framework for Artificial Intelligence Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Brazilian Senate Bill 2338/2023 establishes a risk-based framework for AI systems, categorising them into excessive (prohibited), high, limited, and minimal risk tiers with specific obligations for high-risk applications in employment, credit, health, biometric identification, and access to essential public services; providers of high-risk AI must conduct algorithmic-impact assessments, maintain technical documentation, and operate under human oversight, with sanctions enforced by the designated competent authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "gdpr-article-5-data-principles",
      "nist-ai-600-1-gen-ai-profile"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-ai-bill-plc-2338-2023",
    "title": "Projeto de Lei nº 2338, de 2023: Dispõe sobre o uso da Inteligência Artificial no Brasil (Marco Legal da Inteligência Artificial)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Brazil's AI Bill (PLC 2338/2023) establishes a risk-based regulatory framework for the development and use of AI systems, mandating risk assessments, governance measures, and transparency for providers and deployers, particularly for high-risk systems as defined in Article 7. The framework aims to protect fundamental rights and assigns enforcement powers to a competent authority, likely the National Data Protection Authority (ANPD).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "oecd-ai-principles",
      "iso-23894-ai-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "brazil-ai-framework-law-pl-2338-2023",
    "title": "Brazil Artificial Intelligence Framework Bill PL 2338/2023 - Risk Classification, Transparency Requirements and National AI Authority",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a national framework for the use of artificial intelligence in Brazil, mandating risk classification, transparency, and accountability for AI systems. It applies to developers, deployers, and operators of AI systems, with specific obligations under the approved Emenda nº 199-CCT (Substitutivo) as reported by the Comissão Temporária Interna sobre Inteligência Artificial no Brasil.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brazil-ai-bill-2023",
      "brazil-ai-bill-plc-2338-2023",
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "ai-agent-collision-logic"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-anatel-net-neutrality-decree-8771-2016",
    "title": "Decreto nº 8.771, de 11 de Maio de 2016 - Regulamenta a Lei nº 12.965, de 23 de Abril de 2014, para tratar das hipóteses admitidas de discriminação de pacotes de dados na internet e de degradação de tráfego, indicar procedimentos para guarda e proteção de dados por provedores de conexão e de aplicações, apontar medidas de transparência na requisição de dados cadastrais pela administração pública e estabelecer parâmetros para fiscalização e apuração de infrações",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation implements Brazil's Marco Civil da Internet (Law 12.965/2014) by defining permitted exceptions to net neutrality, requiring transparency in traffic management practices, mandating data protection measures for connection and application access logs, and establishing procedures for public authorities to request user registration data. It applies to internet connection and application providers under Article 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-net-neutrality-open-internet-2015-2120"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-anatel-satellite-licensing-regulations",
    "title": "Brazil ANATEL Satellite Licensing Regulations (Resolution 704/2018) - Brazilian Satellite Communications Regulatory Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Brazil's satellite communications regulatory framework is administered by ANATEL (Agência Nacional de Telecomunicações - National Telecommunications Agency) under the General Telecommunications Act (Lei Geral de Telecomunicações, LGT, Lei 9.472/1997) and ANATEL Resolution 704 of 24 September 2018, which sets the rules for satellite authorisations for geostationary and non-geostationary satellite systems. Brazilian satellite operations require ANATEL authorisation for the right to explore satellite capacity, ITU coordination managed through the Brazilian Institute for Geography and Statistics (IBGE) in coordination with ANATEL, and compliance with MCTI (Ministry of Science, Technology, and Innovation) for space activities under the Brazilian Space Activity Programme (PNAE). Brazil has significant domestic satellite manufacturing capacity and operates the Alcântara Launch Center in Maranhão state.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "un_registration_convention",
        "itu_radio_regulations"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "brazil-aneel-electricity-sector-regulation",
    "title": "Brazil ANEEL Electricity Sector Regulation - Concession Contracts, Tariff Revision and Power Quality Standards",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Brazil's National Electric Energy Agency (ANEEL - Agencia Nacional de Energia Eletrica), created by Law 9.427/1996, regulates the generation, transmission, distribution, and commercialisation of electric energy under the National Energy Policy (Law 10.848/2004); mandates a triennial tariff review (revisao tarifaria) for distribution concessionaires applying the WACC-based regulatory framework; enforces power quality standards through PRODIST (Distribution Quality and Service Procedures); and imposes sanctions up to BRL 2 million per violation for regulatory non-compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electricity-market-reform-regulation-2024-1747"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "brazil-anpd-regulation-2021-2023",
    "title": "Brazil ANPD Regulations 2021-2023 - DPO Nomination Obligations, Legitimate Interest Guidance, Simplified Regulations for Micro-Enterprises, Security Incident Reporting Rules (2-Day Window), International Transfer Clauses and Code of Conduct Accreditation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-29",
    "bluf": "This regulation establishes obligations for data protection officers, incident reporting within 2 days, and age assurance mechanisms for protecting children online. It applies to all agents of processing handling personal data in Brazil under ANPD oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-privacy",
      "aicpa-soc2-cc-confidentiality"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-antt-road-freight-law-10233-2001",
    "title": "Brazil ANTT Road Freight Transport Law 10.233/2001 - RNTRC Registration and TAC Driver Framework",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Brazil's Law 10.233 of 5 June 2001 created the National Land Transportation Agency (ANTT - Agencia Nacional de Transportes Terrestres) and established the legal framework for road freight transport authorisation; requires all carriers, transport operators (ETC - Empresa de Transporte de Cargas), and individual truck owner-operators (TAC - Transportador Autonomo de Cargas) to register in the National Register of Road Freight (RNTRC); mandates cargo manifest documentation (MDFE); and links freight contractor liability to RNTRC validity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mobility-package-i-road-transport-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "brazil-anvisa-food-regulation-resolution-2001",
    "title": "Brazil ANVISA Food Regulation RDC 259/2002 and RDC 360/2003 - Food Labelling and Nutritional Information: Mandatory Nutritional Table, Serving Size Standardisation, Front-of-Pack Warning Labels (RDC 429/2020), Trans Fat and Sodium Thresholds",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires food manufacturers and importers to provide standardized nutritional labelling, including mandatory nutritional tables, serving size declarations, and front-of-pack warning labels for high levels of critical nutrients such as sodium, sugars, and trans fats, in compliance with RDC 259/2002, RDC 360/2003, and RDC 429/2020. Applies to all packaged foods marketed in Brazil.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-food-labelling-regulation-1169-2011",
      "brc-food-safety-global"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-anvisa-good-manufacturing-practices-rdc-658-2022",
    "title": "Brazil ANVISA Good Manufacturing Practices RDC 658/2022 - Pharmaceutical GMP, AFE Certification and Inspection",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Brazil's Resolucao da Diretoria Colegiada RDC 658 of 30 March 2022 (ANVISA Good Manufacturing Practices for Medicines) established updated GMP requirements for finished pharmaceutical products aligned with ICH Q10 Pharmaceutical Quality System and WHO Technical Report Series 986 Annex 2 (TRS 986/2), replacing the previous RDC 17/2010; under RDC 658/2022, pharmaceutical companies must operate a Pharmaceutical Quality System (PQS) covering: management responsibility, change management, continued process verification, and product quality reviews; all facilities manufacturing medicinal products for the Brazilian market must hold an Autorização de Funcionamento de Empresa (AFE, Company Operating Authorisation) and a Certificado de Boas Praticas de Fabricacao (CBPF, GMP Certificate) from ANVISA's General Coordination of Medicines Inspection (GGFAR); ANVISA GMP inspections assess 20+ areas of GMP compliance; non-conforming facilities may receive a Warning Letter, AFE suspension, or CBPF denial; penalties for commercialising medicines without an AFE or CBPF: administrative fine up to BRL 1.5 million per violation under ANVISA Law 9782/1999.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brazil-anvisa-resolution-rdc-204-2017"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "brazil-anvisa-lgpd-health-2026",
    "title": "Brazil ANVISA & LGPD - Processing of Health Data and Medical Device Regulation (2026)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "ANVISA regulates medical devices and SaMD under RDC 751/2022 while LGPD (Law 13.709/2018) imposes strict rules for processing sensitive health data. Requirements include explicit consent or legal basis, data minimisation, security measures, breach notification within 2 working days, and accountability for controllers/processors handling health information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-anvisa-resolution-rdc-204-2017",
    "title": "Resolution RDC 204, 2017 - Good Manufacturing Practices for Pharmaceutical Inputs: Active Ingredients, Excipients and Primary Packaging",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires pharmaceutical manufacturers to comply with Good Manufacturing Practices (GMP) as outlined in Article 5, and applies to all establishments that manufacture, fractionate, assemble, package, and label pharmaceutical inputs in Brazil.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-bacen-resolution-4658-2018-cybersecurity",
    "title": "Brazil Central Bank Resolution No. 4,658, of 2018 - Cybersecurity Policy for Financial Institutions",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Mandates financial institutions operating in Brazil to establish a comprehensive cybersecurity policy, designate a Chief Information Security Officer (CISO), implement incident response and business continuity plans, and manage risks associated with outsourcing and cloud service providers. Key obligations derive from the requirement to maintain an adequate governance structure and risk management framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cisa-secure-by-design-guidance-2024",
      "us-fedramp-authorization-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-competition-law-12529-2011-cade",
    "title": "Lei n° 12.529, de 30 de Novembro de 2011 - Estrutura o Sistema Brasileiro de Defesa da Concorrência; dispõe sobre a prevenção e repressão às infrações contra a ordem econômica",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This law establishes the Brazilian Competition Defense System (SBDC), defining the structure and powers of the Administrative Council for Economic Defense (CADE), and governs the prevention and repression of anticompetitive conduct, including cartels, abuse of dominance, and merger control. It applies to all enterprises operating in Brazil or whose conduct produces or may produce effects in Brazil, under Article 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-merger-regulation-139-2004-ec-thresholds",
      "australia-competition-consumer-act-2010-cca",
      "eu-antitrust-compliance-programme-best-practice"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-consumer-defense-code-lei-8078-1990",
    "title": "Brazil Consumer Defense Code (CDC) Lei 8.078/1990 - Consumer Rights and Supplier Obligations",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Brazil's Consumer Defense Code (Codigo de Defesa do Consumidor - CDC, Lei 8.078 of 11 September 1990, as amended through 2022) establishes comprehensive consumer rights and supplier obligations enforced by PROCON (consumer protection offices in each state) and SENACON (Secretaria Nacional do Consumidor). Key provisions include strict product liability, 7-day cooling-off for remote purchases (CDC Article 49), mandatory product safety recalls, prohibition of abusive contract terms, 30-day warranty for non-durable goods and 90-day for durable goods, and reverse burden of proof in consumer disputes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "australia-consumer-law-acl-2010-cx"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "brazil-crypto-regulatory-framework-law-14478-2022",
    "title": "Regulamenta a Lei n° 14.478, de 21 de dezembro de 2022, para estabelecer competências ao Banco Central do Brasil",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Este decreto regulamenta a Lei n° 14.478/2022, atribuindo ao Banco Central do Brasil competência para regular, autorizar e supervisionar prestadoras de serviços de ativos virtuais, conforme estabelecido no art. 1°, incisos I a III. Aplica-se a entidades que prestam serviços com ativos virtuais, exceto ativos mobiliários sob jurisdição da CVM.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "eu-dlt-pilot-regime-2022-858"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-ctnbio-biosafety-law-11105-2005",
    "title": "Brazil Biosafety Law 11105/2005 - CTNBio GMO and Human Embryo Research Regulation",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Brazil's National Biosafety Law (Law 11105/2005) establishes CTNBio (National Technical Biosafety Commission) as the sole authority for risk assessment and commercial release approvals of genetically modified organisms (GMOs), regulates human embryonic stem cell research, and requires a Certificate of Quality in Biosafety (CQB) from MCTIC for all research and production activities involving LMOs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "eu-directive-2001-18-deliberate-release-gmo"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "brazil-fiocruz-biodiversity-biobank-cgen-genomics",
    "title": "Brazil Fiocruz Biodiversity Biobank and Genomic Resources Governance under Law 13,123/2015 (CGen)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2024-12-01",
    "bluf": "Brazil's principal biobank and genomic resources governance framework is established by Law 13,123/2015 (Lei da Biodiversidade), which regulates access to Brazilian genetic heritage and traditional knowledge associated with genetic heritage and the sharing of benefits arising from such access. The Council for the Management of Genetic Heritage (Conselho de Gestao do Patrimonio Genetico, CGen), under the Ministry of the Environment and Climate Change, administers the Brazilian National System of Genetic Heritage Management and Associated Traditional Knowledge (SisGen) for registration of access, shipment, and benefit-sharing. Fiocruz (Fundacao Oswaldo Cruz) operates the Biodiversity and Health Biobank and is a key institutional actor for human and pathogen genomic resources in Brazil, while the Botanical Garden of Rio de Janeiro (JBRJ) participates in the Global Genome Biodiversity Network (GGBN) for plant genomic resources.\n\nBiosafety governance is set out in Law 11,105/2005 (Lei de Biosseguranca) and implementing regulations administered by the National Biosafety Council (CNBS) and the National Biosafety Technical Commission (CTNBio). The Law regulates the construction, cultivation, production, manipulation, transport, transfer, import, export, storage, research, commercialisation, environmental release, and disposal of genetically modified organisms and their derivatives. Personal data protection under the Lei Geral de Proteção de Dados (LGPD) Law 13,709/2018 applies to processing of human genomic data including in biobanks. The Ministry of Science, Technology and Innovation (MCTI) and the Ministry of Health regulate human genomic research with ethics oversight by the National Research Ethics Commission (CONEP) and local research ethics committees.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brazil-ctnbio-biosafety-law-11105-2005",
      "nagoya-protocol-genetic-resources-2010",
      "cartagena-protocol-biosafety-2000",
      "br-lgpd-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "brazil-gaming-regulation-law-14790-2023",
    "title": "Brazil Gaming Regulation Law 14.790/2023 - Fixed-Odds Sports Betting Legalisation",
    "domain": "Gaming & Gambling",
    "version": "2023-12",
    "last_updated": "2026-05-09",
    "bluf": "Brazil's Law 14.790/2023 (effective December 2023) legalises fixed-odds sports betting and online gaming in Brazil, establishing a federal licensing regime administered by the Ministry of Finance (SPA/MF); operators must obtain a 5-year concession for BRL 30 million, comply with AML/CFT requirements, player protection rules including self-exclusion and deposit limits, and advertising restrictions; market opened 1 January 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021",
      "eu-aml-directive-5-gambling-sector"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "brazil-lei-4591-1964-incorporacoes-imobiliarias",
    "title": "Brazil Lei 4591/1964 - Real Estate Incorporation and Condominium Registration Framework",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Brazil's Lei 4591 of 16 December 1964 (Incorporacoes Imobiliarias e Condominios) regulates off-plan real estate sales (incorporacao imobiliaria) by requiring the incorporador (developer) to register a memorial de incorporacao at the Registro de Imoveis (Real Estate Registry) before marketing; establishes the quota system for condominium expenses; allows buyers to request destituicao do incorporador if construction is abandoned; and was amended by Lei 9785/1999 and Lei 13786/2018 (distrato rules).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brazil-consumer-defense-code-lei-8078-1990"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "brazil-lei-biosseguranca-11105-2005-ctnbio",
    "title": "Brazil Biosafety Law 11105/2005 - CTNBio GMO and Agricultural Biotechnology Regulation",
    "domain": "Agriculture & Agritech",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Lei No. 11.105 de 24 de Marco de 2005 (Biosafety Law) is Brazil's primary law governing genetically modified organisms (GMOs) and agricultural biotechnology. The Comissao Tecnica Nacional de Biosseguranca (CTNBio - National Biosafety Technical Commission) is the scientific regulatory body that assesses biosafety of GMOs and grants technical opinions (pareceres tecnicos) that authorise or prohibit commercial release of transgenic crops. CTNBio's positive opinion is prerequisite to any ministerial approval for commercialisation. Brazil is the world's second-largest GMO producer after the United States. The MAPA (Ministerio da Agricultura, Pecuaria e Abastecimento) and ANVISA (Agencia Nacional de Vigilancia Sanitaria) retain independent oversight roles. GMO labelling is mandatory under Decreto No. 4.680/2003 where GM content exceeds 1% in any ingredient. The National Biosafety Council (CNBS) has policy oversight. Criminal penalties under the Biosafety Law include imprisonment of up to 4 years for illegal research on or release of GMOs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cartagena_protocol",
        "codex_alimentarius",
        "consumer_protection",
        "mapa_registration",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "brazil-lei-migracao-13445-2017-policia-federal",
    "title": "Brazil Lei de Migracao 13445/2017 - Policia Federal Immigration Framework",
    "domain": "Immigration & Border Control",
    "version": "2.2",
    "last_updated": "2026-05-10",
    "bluf": "Lei de Migracao No.13,445 of 24 May 2017 (regulated by Decree No.9,199/2017) replaced the authoritarian Estatuto do Estrangeiro of 1980, establishing a rights-based migration framework grounded in human dignity and non-discrimination. The Federal Police (Policia Federal, PF) coordinates immigration inspection at borders and ports. Consular visas are issued by the Ministry of Foreign Affairs (Itamaraty). Brazil is a major destination for Venezuelan, Haitian, and Bolivian migrants. The Temporary Protection Status (TPS) for Venezuelan nationals (Portaria Interministerial No.9/2018, updated by Resolution No.45/2022) is internationally referenced as a model for large-scale displacement response. SINCRE (National Registry of Foreigners) centralises all immigration records. Digital Nomad Visa (Normative Resolution No.45/2022) allows remote workers earning USD 1,500/month to reside in Brazil for up to 2 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "unhcr",
        "mercosur",
        "lgpd",
        "icao_doc",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "brazil-lgpd-compliance",
    "title": "Brazil LGPD Compliance",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Lei Geral de Proteção de Dados (LGPD) is Brazil's comprehensive data protection law (Law No. 13,709/2018), modeled after GDPR but with distinct governance requirements for the ANPD (National Data Protection Authority) and mandatory DPO appointments for all controllers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "brazil-lgpd-law-13709-2018-depth",
    "title": "Lei Geral de Proteção de Dados Pessoais (LGPD) - Lei nº 13.709, de 14 de Agosto de 2018",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This law governs the processing of personal data in Brazil, applying to any natural or legal person conducting data processing operations within Brazilian territory or targeting individuals located in Brazil, as defined in Art. 3º. It establishes ten legal bases for processing, including legitimate interest, and mandates protection of sensitive data categories such as biometric, genetic, health, religious, and political data under strict conditions per Art. 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-privacy",
      "aicpa-soc2-cc-confidentiality"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-lgpd-marketing-consent-requirements-2021",
    "title": "Brazil LGPD Direct Marketing Requirements - ANPD Guidance: Consent as Lawful Basis for Marketing, Legitimate Interest for B2B, Data Subject Rights in Marketing Context, Children's Marketing Prohibition, Opt-Out Mechanisms and ANPD Enforcement Actions",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The LGPD, as interpreted by the ANPD, requires express consent for direct marketing to individuals, prohibits marketing directed at children and adolescents in digital environments under the ECA Digital framework, and mandates opt-out mechanisms. Key enforcement guidance is derived from ANPD public notices and decrees issued in 2026, particularly regarding age assurance and protection of minors online.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coppa-marketing-kids",
      "can-spam-act-email",
      "eu-ecommerce-directive-2000-31",
      "eu-unfair-commercial-practices-2005-29",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-mapa-decreto-9013-2017-riispoa-animal-origin-products",
    "title": "Brazil Decreto 9.013/2017 - RIISPOA (Industrial and Sanitary Inspection of Animal-Origin Products)",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "Decreto 9.013/2017 (RIISPOA, Regulamento da Inspeção Industrial e Sanitária de Produtos de Origem Animal) is Brazil's comprehensive regulation governing the industrial and sanitary inspection of products of animal origin including meat, poultry, eggs, milk, fish, honey and derivatives. Administered by MAPA through the Federal Inspection Service (SIF), RIISPOA mandates that establishments processing animal-origin products for interstate or international commerce hold a SIF registration (Title II, Articles 17-31), maintain hygiene and structural standards (Title IV), apply Self-Control Programmes including Good Manufacturing Practices and Hazard Analysis (Article 76 et seq.), undergo continuous federal inspector presence at slaughter facilities (Article 8), and comply with product-specific standards for each animal-origin category (Titles VI-X). Non-compliance triggers seizure of product, suspension of SIF registration, and administrative or criminal proceedings under Law 7.889/1989.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "woah_terrestrial",
        "woah_aquatic",
        "codex_haccp",
        "wto_sps",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "woah-terrestrial-animal-health-code",
      "codex-cxc-1-1969-general-principles-food-hygiene"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "brazil-marco-civil-internet-2014-law-12965",
    "title": "Lei Nº 12.965, de 23 de Abril de 2014 - Estabelece princípios, garantias, direitos e deveres para o uso da Internet no Brasil",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This law establishes foundational principles for internet use in Brazil, including network neutrality, user privacy, and data protection. It mandates that internet connection records be retained for 1 year (Art. 13) and requires a prior judicial order for access to user connection and application access logs (Art. 12).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-privacy",
      "aicpa-soc2-cc-confidentiality"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-national-water-resources-policy-9433-1997-ana",
    "title": "Brazil National Water Resources Policy Law 9.433/1997 - ANA Water Rights and River Basin Committee Framework",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Brazil's Lei 9.433 de 8 de janeiro de 1997 (Politica Nacional de Recursos Hidricos - PNRH) establishes the National Water Resources Policy and the National Water Resources Management System (SINGREH). Water is a public good and a scarce natural resource with economic value. The law creates four management instruments: water resources plans (planos de recursos hidricos), classification of water bodies by prevailing use (enquadramento), water rights grants (outorga de direito de uso), and water use charges (cobranca). The ANA (Agencia Nacional de Aguas e Saneamento Basico, created by Law 9.984/2000) regulates federal water bodies. River Basin Committees (Comites de Bacia Hidrográfica) are the decentralised participatory governance bodies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "south-africa-national-water-act-36-1998"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "brazil-pix-bacen-payment-system-2020",
    "title": "Brazil PIX Instant Payment System 2020 (BACEN)",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Mandates participation in the PIX instant payment system for financial institutions with 500+ active accounts, requiring 24/7/365 transaction clearing, adherence to QR code and PIX alias standards (CPF/CNPJ/phone), implementation of SPI security protocols for fraud prevention, and compliance with DICT directory registration. See source document for key obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-aml-ctf-act-2006",
      "bahrain-cbb-rulebook-aml-cft-module",
      "au-apra-prudential-standard-aps-110-adi"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-space-agency-act-8854-1994",
    "title": "Brazil Space Agency Act 8854/1994 - Agência Espacial Brasileira (AEB) Mandate and Launch Authorization Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Brazil's Law No. 8854 of 10 February 1994 established the Agência Espacial Brasileira (AEB - Brazilian Space Agency) as the central authority for Brazil's national space activities, implementing the Brazilian Complete Space Mission (MECB) and governing civilian space activities; AEB authorizes commercial satellite launches, issues launch licences for the Alcântara Launch Center (CLA), negotiates Technology Safeguards Agreements (TSAs) required for foreign launch services, manages Brazil's international space obligations under the Outer Space Treaty, and coordinates with ANATEL for satellite orbital slot and frequency assignments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "brazil-anatel-satellite-licensing-regulations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "brazil-sports-betting-law-14790-2023",
    "title": "Lei n° 14.790, de 29 de dezembro de 2023 - Dispõe sobre a modalidade lotérica denominada apostas de quota fixa; altera as Leis n°s 5.768, de 20 de dezembro de 1971, e 13.756, de 12 de dezembro de 2018, e a Medida Provisória n° 2.158-35, de 24 de agosto de 2001; revoga dispositivos do Decreto-Lei n° 204, de 27 de fevereiro de 1967; e dá outras providências",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This law establishes the legal framework for fixed-odds betting in Brazil, authorizing its operation under prior approval by the Ministry of Finance. It applies to corporate entities seeking to operate as betting operators, requiring compliance with strict licensing, consumer protection, anti-money laundering, and integrity controls under Art. 4 and Art. 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-susep-resolution-553-2023-insurance",
    "title": "Resolution CNSP 553/2023 - Open Insurance Framework: Data Sharing Obligation for Insurers, API Standards, Customer Consent Management, Regulatory Sandbox for Insurtechs and SUSEP Supervisory Technology Deployment",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "SUSEP Resolution 553 of 2023 establishes the Open Insurance Brazil (OPIN) framework, mandating insurers and brokers to share customer data via standardised APIs with prior, explicit customer consent; the rules cover customer-data, product-and-quotation, and policy-administration phases, with technical and security standards set by the OPIN governance structure and supervisory oversight by SUSEP.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brazil-susep-solvency-regulation-circular-2021",
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "brazil-susep-solvency-regulation-circular-2021",
    "title": "Circular SUSEP Nº 667, de 2 de julho de 2021: Dispõe sobre os critérios para cálculo do capital requerido baseado nos riscos de subscrição, de crédito, de mercado e operacional, e sobre o capital mínimo requerido das sociedades seguradoras, das entidades abertas de previdência complementar, das sociedades de capitalização e dos resseguradores locais.",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-07-02",
    "bluf": "This regulation establishes a Solvency II-based framework for Brazilian insurance companies, open private pension entities, capitalization companies, and local reinsurers, defining the methodology for calculating risk-based capital requirements. As per Article 4, supervised entities must maintain sufficient Adjusted Net Worth (Patrimônio Líquido Ajustado - PLA) to cover the Required Capital (Capital Requerido - CR), which is the greater of the Risk-Based Capital (Capital Baseado em Risco - CBR) and the Minimum Capital Requirement (Capital Mínimo Requerido - CMR).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "brc-food-safety-global",
    "title": "BRCGS Food Safety",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with the BRCGS Global Standard Food Safety Issue 9 mandates a comprehensive, proactive management system, fundamentally rooted in senior management commitment as defined in Section 1. This commitment is evidenced through formal management reviews conducted at a maximum 12-month interval and support for a continuously active internal audit program. The operational core is a fully active food safety plan based on HACCP principles, detailed in Section 2, which must be rigorously maintained. Supporting this system, Clause 3.2 on document control extends to digital infrastructure, requiring active IT system backup and cybersecurity protocols. The stringent traceability mandate in Clause 3.9 necessitates the capability to retrieve all relevant information within a four-hour maximum during exercises, with full product recall tests performed at a 12-month interval. Furthermore, Clause 4.2 requires an active food defense assessment to mitigate intentional adulteration, while Clause 5.4 on product authenticity compels a documented food fraud vulnerability assessment at least every 12 months, reinforced by an active supplier approval procedure. System integrity is also validated through an active environmental monitoring program and record retention policies that mandate keeping documents for a product's shelf life plus an additional 12 months.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "haccp-food-safety",
      "gfsi-benchmarking",
      "codex-alimentarius-gen",
      "iso-9001-quality-mgt",
      "iso-31000-risk-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "brc-food-safety-standard-issue-9",
    "title": "BRCGS Global Standard for Food Safety Issue 9",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The BRCGS Food Safety Standard Issue 9 requires food manufacturing sites to implement a comprehensive food safety management system, including a documented commitment from senior management (Clause 1.1), a fully implemented HACCP-based food safety plan (Clause 2), and a verified procedure for product release (Clause 5.7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brc-food-safety-global",
      "haccp-food-safety",
      "iso-22000-food-mgt",
      "gfsi-benchmarking",
      "codex-alimentarius-gen"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "breeam-2018-building-assessment-method",
    "title": "BREEAM 2018 - Building Research Establishment Environmental Assessment Method: Management, Health and Wellbeing, Energy, Transport, Water, Materials, Waste, Land Use and Ecology Credits",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "BREEAM New Construction Version 7 provides a science-driven framework for assessing the sustainability performance of newly designed and constructed buildings and new-build extensions, with emphasis on whole-life carbon, biodiversity, resilience, and material selection. It applies to developers, designers, owners, and sustainability professionals globally, excluding countries served by National Scheme Operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-19650-bim-information-management-construction",
      "iso-9001-2015-quality-management-construction",
      "iso-50001-2018-energy-management-systems",
      "eu-circular-economy-construction-demolition-waste-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "breeam-building-perf",
    "title": "BREEAM Building Performance",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Asset performance verification against the BREEAM framework necessitates a holistic assessment of environmental, social, and economic sustainability factors. Compliance requires demonstrating an overall target BREEAM score percentage of 70, aligning with an 'Excellent' rating under benchmarks such as the BREEAM In-Use International Commercial Version 6. This performance is substantiated through rigorous energy management, consistent with ISO 50001:2018, mandating that energy consumption does not exceed a maximum of 120 kWh per square meter and that sub-metering is installed for all major systems. Environmental management protocols, guided by ISO 14001:2015 and the life cycle assessment principles of EN 15978:2011, demand a minimum construction waste diversion of 85 percent and procurement of sustainable materials reaching at least 80 percent. Health and wellbeing standards, drawing from the BREEAM International New Construction Standard, require active indoor air quality sensors and a minimum daylight factor of 2 percent, promoting conditions consistent with ASHRAE Standard 55. Further operational integrity is confirmed by active water consumption monitoring, automated refrigerant leak detection, and a passed cybersecurity audit for the building management system. The provision of at least five EV charging points supports sustainable transport initiatives, completing the comprehensive compliance profile.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-50001-energy",
      "leed-green-building",
      "csrd-eu-sustainability",
      "eu-taxonomy-sustainable",
      "iso-45001-work-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "breeam-new-construction-2018",
    "title": "BREEAM New Construction 2018 Assessment Standard - Categories, Credits and Minimum Standards for Sustainability Performance",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard provides a framework for assessing the sustainability performance of new construction projects, requiring them to meet minimum performance standards across categories like Energy (Ene 01), Water (Wat 01), and Waste (Wst 01) to achieve a certified rating. It applies to developers, designers, contractors, and asset owners involved in the design, construction, and certification of new buildings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures",
      "iso-46001-water-eff"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "bs-dpa-2003",
    "title": "Bahamas Data Protection (Privacy of Personal Information) Act 2003",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Bahamas enacted the Data Protection (Privacy of Personal Information) Act, 2003 (Chapter 324A), one of the earliest comprehensive data protection statutes in the Caribbean. The Act is administered by the Data Protection Commissioner of The Bahamas. It establishes data protection principles governing the collection, use, storage, and disclosure of personal data by data controllers. Data subjects have rights of access and correction. Controllers must notify data subjects of the purposes for which personal data is collected, implement appropriate security measures, and restrict cross-border transfers to countries with adequate data protection. The Act aligns with CARICOM privacy standards and influenced subsequent data protection legislation across the Caribbean Community.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/bs-dpa-2003.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bsa-software-asset-management-iso-19770",
    "title": "ISO/IEC 19770-1:2017 IT Asset Management - Software Asset Management Processes and Requirements",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard specifies a tiered process framework for Software Asset Management (SAM) to enable organizations to prove they are performing SAM to a standard sufficient to satisfy corporate governance requirements and manage software assets effectively. It applies to all organizations using software, with Clause 4 outlining the core SAM system requirements for managing, controlling, and protecting software assets throughout their lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-20000-service-mgt",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "bt-ica-2018",
    "title": "Bhutan Information, Communications and Media Act 2018 - Data Privacy Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Bhutan enacted the Information, Communications and Media Act 2018 (ICMA 2018), which includes provisions for the protection of personal information in electronic communications and digital services. The Act is administered by the Bhutan InfoComm and Media Authority (BICMA). It requires ICT service providers and digital platform operators to protect user personal data, obtain user consent before collecting personal information for purposes beyond service delivery, implement security measures to safeguard personal data from unauthorised access, and restrict disclosure of user information to third parties. Data subjects have the right to access personal information held by service providers. The Act aligns with Bhutan's broader digital governance framework and the country's commitment to Gross National Happiness principles applied to the digital economy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/bt-ica-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "budapest-convention-cybercrime-2001",
    "title": "Budapest Convention on Cybercrime 2001 - International Cybercrime Cooperation Treaty (ETS No. 185)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Convention on Cybercrime (ETS No. 185, Budapest, 23 November 2001) is the first and primary international treaty harmonising cybercrime laws and enabling cross-border cooperation in cybercrime investigations. It entered into force 1 July 2004 and has 68 States party as of 2024, including the US (ratified 2006), Japan, Australia, Canada, Israel, and all EU member states. Chapter II Title 1 (Arts 2-10) defines substantive offences: illegal access (Art 2), illegal interception (Art 3), data interference (Art 4), system interference (Art 5), misuse of devices (Art 6), computer-related forgery (Art 7), computer-related fraud (Art 8), child sexual abuse material (Art 9), copyright offences (Art 10). Chapter II Title 2 (Arts 16-21) establishes procedural powers: expedited preservation of stored data (Art 16, 24-hour response expected), production orders (Art 18), search and seizure (Art 19), real-time collection of traffic data (Art 20), and interception of content data (Art 21). Chapter III (Arts 23-35) governs mutual legal assistance (MLA) including expedited preservation requests (Art 29, 20-day initial window + 40-day extension) and the 24/7 Network (Art 35) for real-time operational assistance. The Second Additional Protocol (CETS 224, 2022) enables direct cooperation with foreign service providers and enhanced joint investigations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "coe-convention-108-plus",
      "echr-1950-european-convention-human-rights",
      "un-iccpr-1966-civil-political-rights"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "business-process-maturity-model-bpmm-omg",
    "title": "Business Process Maturity Model (BPMM) - OMG Standard: Five Maturity Levels, Process Areas, Goals, Practices and Measurement for Workflow Process Improvement",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The Business Process Maturity Model (BPMM) Version 1.0 provides a framework for assessing and improving organizational business process maturity across five levels, with defined process areas, goals, and practices to enhance readiness for enterprise application deployment. It applies to organizations seeking structured process improvement as specified by the Object Management Group (OMG) in BPMM/1.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bw-dpa-2018",
    "title": "Botswana Data Protection Act No. 32 of 2018 - Information and Data Protection Commission",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Botswana's Data Protection Act No. 32 of 2018 (DPA) - assented to on 3 August 2018, published in the Botswana Government Gazette Extraordinary No. 64 of 3 August 2018, and brought into force through a Presidential Statutory Instrument - is Botswana's primary personal data protection legislation, establishing Botswana as one of the first Southern African countries to enact a comprehensive data protection law modelled on international standards. The supervisory authority is the Information and Data Protection Commission (the Commission), an independent public body established under the Act responsible for receiving notifications from data controllers, investigating complaints from data subjects, conducting audits, and enforcing the Act. Key features of Botswana's Data Protection Act No. 32 of 2018: (1) Scope - applies to data controllers who collect, process, store, or use personal data in Botswana; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation (relevance and adequacy); accuracy; storage limitation; security; and accountability; (3) Sensitive personal data - the Act designates categories requiring enhanced protection: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; genetic data; biometric data; and criminal record data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to object to processing; right not to be subject to solely automated decisions; right to complain to the Commission; (6) Data controller notification - data controllers must notify the Commission before commencing processing of personal data; (7) Data Protection Officer - designated for data controllers engaged in large-scale systematic monitoring or large-scale processing of sensitive personal data; (8) Breach notification - data controllers must notify the Commission of personal data breaches likely to adversely affect the rights of data subjects; (9) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or subject to Commission-approved safeguards; (10) Penalties - administrative fines and criminal penalties for contraventions of the Act. Botswana's Data Protection Act positions Botswana as a data-secure hub in Southern Africa, supporting the country's financial services, diamond industry, tourism, and emerging digital economy sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "bw-public-procurement-act-24-2021-ppra-eprocurement",
    "title": "Botswana Public Procurement Act 24 of 2021 (effective 1 April 2022) and the Public Procurement Regulatory Authority",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Republic of Botswana Public Procurement Act 24 of 2021 (Act No. 24 of 2021, Government Gazette of Botswana No. 53 of 12 October 2021) effective 1 April 2022 is the principal Botswanan statute governing procurement of goods, works, and services by procuring entities including the Government of Botswana (Central Government ministries, departments, and the Office of the President), parastatal organisations, public-sector enterprises, local authorities (district and city councils), public-sector universities, and other entities financed wholly or partly from the Consolidated Fund. Act 24 of 2021 replaced the prior Public Procurement and Asset Disposal Act 2001 and substantially modernised the Botswanan procurement regime aligning with international best practice including the UNCITRAL Model Law on Public Procurement and World Bank procurement guidelines. The Public Procurement Regulatory Authority (PPRA, ppra.org.bw, formerly Public Procurement and Asset Disposal Board PPADB) is the central regulatory authority responsible for procurement regulation, oversight, supplier debarment, complaint resolution, and procurement guidance. The Public Procurement Regulations 2022 prescribe detailed procedural requirements. The Botswana Government e-Procurement System (under rollout) is the federal e-procurement platform. The Independent Complaints Review Committee (ICRC) is the specialised body for procurement complaints. Procurement methods established by Act 24/2021 sec. 41 to 64 comprise (a) Open Bidding (the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Restricted Bidding (with prequalification), (c) Request for Proposals (for consulting services), (d) Request for Quotations (for medium-value goods and services), (e) Direct Procurement (sole-source under prescribed exceptions in sec. 55 including emergency, sole supplier for technical reasons, prior failed bidding, additional procurement under existing contract, and prescribed-class exemptions), (f) Two-Stage Bidding (for complex acquisitions), (g) Framework Agreement, (h) Government-to-Government Procurement (for prescribed international cooperation arrangements), and (i) Electronic Reverse Auction. The Auditor-General conducts ex-post procurement audit. The Directorate on Corruption and Economic Crime (DCEC) has investigative jurisdiction over procurement-related corruption. Botswana is NOT a party to the WTO Government Procurement Agreement (GPA). Botswana is a party to the Southern African Development Community (SADC), the Southern African Customs Union (SACU), AfCFTA, and UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "bw-dpa-2018",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "by-pdp-law-2021",
    "title": "Belarus Law on Personal Data Protection - NCPDP Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Belarus Law on Personal Data Protection (No. 99-Z, 2021, in force November 2021) establishes GDPR-influenced data subject rights, 72-hour breach notification, and mandatory registration for operators processing sensitive data. The National Centre for Personal Data Protection (NCPDP) is the supervisory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "bz-dpa-2021",
    "title": "Belize Data Protection Act 2021",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Belize enacted the Data Protection Act 2021, establishing a comprehensive data protection framework for the country. The Act is administered by the Data Protection Commissioner of Belize and establishes principles for the lawful processing of personal data by public and private bodies. Data subjects are granted rights of access, correction, and objection to processing. Controllers must identify a lawful basis for processing, issue privacy notices, implement appropriate security measures, and restrict cross-border transfers to jurisdictions providing adequate protection. The Act aligns with CARICOM data protection standards, bringing Belize into line with other Caribbean Community member states that have enacted comprehensive data protection legislation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/bz-dpa-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "c-scrm-practices-systems-organizations",
    "title": "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-11-01",
    "bluf": "This publication provides guidance to organizations on identifying, assessing, and mitigating cybersecurity risks throughout the supply chain at all levels of their organizations. It integrates cybersecurity supply chain risk management (C-SCRM) into risk management activities by applying a multilevel, C-SCRM-specific approach. Organizations are concerned about risks associated with products and services that may contain malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices. These risks arise from decreased visibility into how technology is developed, integrated, and deployed. The core obligation is for enterprises to implement a systematic process for managing exposure to these risks by developing appropriate response strategies, policies, procedures, and controls.\n\nThe guidance is intended for a diverse audience, including individuals with system, information security, risk management, system development, acquisition, procurement, and operational responsibilities. C-SCRM is presented as an enterprise-wide activity requiring coordination across various disciplines. This publication empowers enterprises to develop C-SCRM strategies tailored to their specific mission needs, threats, and operational environments, while balancing the costs and benefits of implementation. The guidance is not one-size-fits-all and should be adopted and tailored to the unique size, resources, and risk circumstances of each enterprise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-30-risk-assessment",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "c-tpat-minimum-security",
    "title": "C-TPAT Minimum Security Criteria",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Customs-Trade Partnership Against Terrorism (C-TPAT) is a voluntary public-private sector partnership program where members work with U.S. Customs and Border Protection (CBP) to protect the supply chain, identify security gaps, and implement specific security measures and best practices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-28000-supply-chain",
      "wco-safe-framework",
      "iso-31000-risk-mgt",
      "isps-code-vessel-security",
      "port-facility-security-isps",
      "nist-sp-800-161r1-csrm-practices"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "c2pa-content-provenance",
    "title": "C2PA (Provenance)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with this node mandates the immutable attachment of a C2PA manifest to all digital assets, establishing verifiable provenance and aligning with transparency obligations for AI-generated content as stipulated under the EU Artificial Intelligence Act and content authentication directives from US Executive Order 14110. The configuration strictly enforces that each manifest adhere to the C2PA Technical Specification with a `minimum_c2pa_version` of 1.3 and not exceed a `max_manifest_size_kb` of 2048. A mandatory `require_cryptographic_binding` is enforced through a `require_hard_binding_hash` using an algorithm with a `min_hash_algorithm_strength_bits` of 256, leveraging the JUMBF box structures from ISO/IEC 23000-22 for data encapsulation. Key assertions are non-negotiable: a `require_creator_identity_assertion`, based on the W3C Verifiable Credentials Data Model, must be present, alongside a `require_ai_generation_action_assertion` for any synthetic media. The chain of trust is further secured by a `require_certificate_revocation_check` and a `require_secure_timestamp_injection` for temporal integrity. Finally, a complete `require_ingredient_provenance_lineage` must trace the asset's history, while `allow_redaction_assertions` provides a mechanism for declared information removal, satisfying core governance and transparency tenets of the NIST Artificial Intelligence Risk Management Framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-high-risk",
      "nist-ai-rmf-1-0",
      "ai-ip-copyright",
      "berne-convention-literary-artistic",
      "wipo-copyright-treaty",
      "dmca-safe-harbor"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "c2pa-watermark-valid",
    "title": "C2PA Content Provenance",
    "domain": "AI Governance & Law",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The Coalition for Content Provenance and Authenticity (C2PA) specification defines a cryptographically signed metadata manifest standard that embeds verifiable provenance information directly into digital assets (images, video, audio, documents), enabling any consumer to verify who created the asset, what tools were used, and whether the content has been modified since signing. C2PA is backed by Adobe, Microsoft, Intel, BBC, Sony, and others and is increasingly required by news organizations, AI content platforms, and social media companies for AI-generated content labeling. The specification uses X.509 certificates for signer identity, COSE (CBOR Object Signing and Encryption) for manifest integrity, and defines a trust list maintained by the C2PA Trust List Authority. Organizations distributing AI-generated content without C2PA manifests risk regulatory non-compliance under the EU AI Act Article 50 transparency obligations and face reputational exposure from deepfake misattribution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-100-4-synthetic-content",
      "c2pa-content-provenance",
      "ai-ip-copyright"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ca-ab-pipa-2003",
    "title": "Alberta Personal Information Protection Act (PIPA) 2003",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Alberta's private-sector data protection law, substantially similar to federal PIPEDA, governs collection, use, and disclosure of personal information by private-sector organizations in Alberta under OIPC Alberta oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ca-ab-pipa-2003.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-pipeda-2000"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ca-accessible-canada-act-2019",
    "title": "Canada Accessible Canada Act 2019",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2021-01-01",
    "bluf": "The Accessible Canada Act (S.C. 2019, c. 10), in force 11 July 2019 with regulated entity obligations phased from 1 January 2021, requires federally regulated entities including Parliament, federal government departments, Crown corporations, CRTC-regulated communications providers, and CTA-regulated transportation providers to proactively identify, remove, and prevent barriers to accessibility across seven priority areas, publish triennial accessibility plans, issue annual progress reports, and establish public feedback processes, enforced by the Accessibility Commissioner with administrative monetary penalties up to CAD 250,000 per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ca-pipeda-2000",
        "ca-labour-code-employment",
        "eu-accessibility-act-2019"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-pipeda-2000",
      "ca-labour-code-employment",
      "eu-accessibility-act-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-accessible-canada-act-section-5-principles",
    "title": "Accessible Canada Act (S.C. 2019, c. 10) - Article 5: Purpose",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must contribute to a barrier-free Canada by January 1, 2040, by identifying, removing, and preventing barriers across key areas including employment, the built environment, and technology.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-bank-act-part-vii-consumer-provisions-banking",
    "title": "Bank Act (S.C. 1991, c. 46) - Part VI, Corporate Governance - Requisitioned and Court-Ordered Meetings",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "This regulation outlines the obligations for a bank's directors to call a meeting upon requisition by shareholders or members, the procedures for such meetings, and the recourse available through the courts for ordering meetings or resolving election disputes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-capital",
      "ifrs-9-financial-instruments"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-bankruptcy-insolvency-act",
    "title": "Canada Bankruptcy and Insolvency Act - Personal and Commercial Insolvency Framework",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Bankruptcy and Insolvency Act establishes Canada's general personal and commercial insolvency framework providing for assignments in bankruptcy, proposals to creditors as a reorganisation alternative, summary administration of small bankruptcies, the Office of the Superintendent of Bankruptcy oversight of licensed insolvency trustees, claim proof and ranking including preferred and secured claims, automatic discharge of first-time individual bankrupts after a statutory period subject to surplus income, and cross-border recognition of foreign proceedings consistent with the UNCITRAL Model Law on Cross-Border Insolvency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-bank-act-part-vii-consumer-provisions-banking"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ca-bc-pipa-2003",
    "title": "British Columbia Personal Information Protection Act (PIPA BC) 2003",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The British Columbia Personal Information Protection Act (PIPA BC) was enacted as SBC 2003 c. 63 and came into force on 1 January 2004. PIPA BC governs the collection, use, and disclosure of personal information by private sector organisations operating in British Columbia. The federal government has determined that PIPA BC is substantially similar to the Personal Information Protection and Electronic Documents Act (PIPEDA), which means that BC private sector organisations collecting, using, or disclosing personal information entirely within BC are exempt from PIPEDA and governed by PIPA BC. The Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) is the independent supervisory authority that oversees compliance with PIPA BC and FOIPPA (the Freedom of Information and Protection of Privacy Act). PIPA BC applies to every private sector organisation in BC - including corporations, partnerships, and sole proprietors - with the exception of employees' personal information in certain contexts. Key obligations include: collecting personal information for a reasonably identified purpose, obtaining meaningful consent for collection, use, and disclosure, using and disclosing information only for the purposes for which it was collected, implementing reasonable security safeguards, and enabling individuals to access and correct their own personal information. The OIPC BC can investigate complaints, conduct audits, and issue binding orders requiring compliance. BC is currently developing PIPA BC amendments to strengthen the Act and better align it with evolving data protection standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ca-bc-pipa-2003.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-adequacy-decisions-article-45",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-broadcasting-act-2023-online-streaming",
    "title": "Canada Broadcasting Act 2023 Online Streaming",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2023-04-27",
    "bluf": "The Online Streaming Act (S.C. 2023, c. 8), in force 27 April 2023, amends the Broadcasting Act (S.C. 1991, c. 11) to bring online streaming services directed at Canadians within CRTC jurisdiction, requiring online undertakings including audio and audiovisual streaming services to register with the CRTC and contribute to the Canadian broadcasting system through financial contributions to Canadian content funds at rates determined by the CRTC following public consultation, requiring the CRTC to exempt small online undertakings from full licensing requirements to reduce regulatory burden, directing that CRTC orders to online undertakings be proportionate and take the unique characteristics of online content into account, and preserving the rights of Canadians to share content online and produce user-generated content without CRTC regulation under new Section 2.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ca-telecommunications-act-1993",
        "ca-pipeda-2000",
        "eu-digital-services-act-2022"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-telecommunications-act-1993",
      "ca-pipeda-2000",
      "eu-digital-services-act-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-canada-health-act-1984",
    "title": "Canada Health Act 1984 (R.S.C. 1985, c. C-6) - National Health Insurance Criteria",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Canada Health Act (R.S.C. 1985, c. C-6) establishes the federal criteria and conditions that provincial and territorial health insurance plans must satisfy to receive full federal cash contributions under the Canada Health Transfer (CHT). The Act codifies five core principles that all provincial/territorial plans must satisfy: public administration (Section 8); comprehensiveness (Section 9); universality (Section 10); portability (Section 11); and accessibility (Section 12). Public administration requires that the health insurance plan be administered and operated on a non-profit basis by a public authority accountable to the provincial/territorial government. Comprehensiveness requires coverage of all medically necessary hospital, physician, and surgical-dental services. Universality requires that all insured persons in the province or territory be entitled to the insured services on uniform terms and conditions. Portability requires coverage for services provided outside the home province. Accessibility requires that no financial or other barriers be placed between patients and insured health services. Section 13 prohibits extra-billing by physicians and Section 14 prohibits user charges for insured services, with Section 15 imposing automatic dollar-for-dollar deductions from federal transfers for each dollar of extra-billing or user charges. Health Canada monitors and enforces compliance through annual reports to Parliament.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-gcp-e6-r3-2023",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "ca-canadian-environmental-protection-act-1999",
    "title": "Canada Canadian Environmental Protection Act 1999 - Toxic Substances Pollution Prevention and Federal Environmental Authority",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Canadian Environmental Protection Act 1999 provides the federal framework for protecting the environment and human health from risks posed by toxic substances, requires assessment of new substances before manufacture or import, supports prevention and management of pollution including air emissions, water releases, and waste, authorises the Minister of Environment and Climate Change to designate toxic substances and to make regulations on their use, release, and disposal, supports environmental emergencies planning and reporting, and authorises civil and criminal penalties for violations including ordering the take back and remediation of contaminated sites.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-bank-act-part-vii-consumer-provisions-banking"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ca-canadian-human-rights-act",
    "title": "Canadian Human Rights Act - Prohibited Grounds, Employment Discrimination and Pay Equity",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "Canada's Human Rights Act (R.S.C. 1985, c. H-6) prohibits discrimination on the grounds listed in section 3(1): race, national or ethnic origin, colour, religion, age, sex, sexual orientation, gender identity or expression, marital status, family status, genetic characteristics, disability and conviction for an offence for which a pardon has been granted or a record suspension ordered. Section 7 makes it discriminatory to refuse to employ or to differentiate adversely in employment on a prohibited ground; section 11 requires equal wages for work of equal value; and section 53 allows compensation up to $20,000 for pain and suffering and a further $20,000 for wilful or reckless conduct.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-cannabis-act-2018",
    "title": "Canada Cannabis Act 2018",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2022-06-23",
    "bluf": "The Cannabis Act (S.C. 2018, c. 16), in force 17 October 2018, establishes the federal framework for the legal production, distribution, sale, and possession of cannabis in Canada, requiring Health Canada licences for cultivation, processing, analytical testing, and sales activities under Section 8 and the Cannabis Regulations (SOR/2018-144), prohibiting the sale of cannabis products to persons under 18 years of age under Section 8(1)(b), requiring plain packaging with a standardized cannabis symbol and the THC and CBD content per serving under Section 26, limiting public possession of cannabis by individuals to 30 grams of dried cannabis or equivalent, restricting all advertising directed at youth or promoting cannabis in a way that could reasonably be seen as appealing to youth under Sections 17 to 23, and imposing penalties of up to 14 years imprisonment for production or distribution outside the licensing framework under Section 9(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ca-consumer-product-safety-act-2010",
        "ca-labour-code-employment",
        "ca-pipeda-2000"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-consumer-product-safety-act-2010",
      "ca-labour-code-employment",
      "ca-pipeda-2000"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-casl-2014",
    "title": "Canada Anti-Spam Legislation 2014 (CASL)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Canada's Anti-Spam Legislation (S.C. 2010, c. 23) effective July 1, 2014 prohibits sending commercial electronic messages to Canadians without express or implied consent, requires clear identification of the sender and an unsubscribe mechanism in every commercial message, and applies to computer programs and electronic address harvesting, with CRTC administrative monetary penalties of up to CAD 1 million for individuals and CAD 10 million for organizations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ca-casl-2014.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-casl-section-6-prohibition-commercial-messages",
    "title": "An Act to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying out commercial activities - Section 6: Unsolicited electronic messages",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations are prohibited from sending a commercial electronic message unless the recipient has provided consent and the message contains specific sender identification, contact information, and an unsubscribe mechanism.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-cbca-corporations-act-1985",
    "title": "Canada Business Corporations Act 1985 (R.S.C. 1985, c. C-44) - Corporate Governance",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Canada Business Corporations Act (CBCA, R.S.C. 1985, c. C-44) governs the formation, governance, and dissolution of federally incorporated companies in Canada, establishing the framework for corporate constitution, director duties, shareholder rights, and corporate transactions. Sections 122 and 122.1 impose the core duties on directors and officers: a duty of care requiring directors to act honestly and in good faith with a view to the best interests of the corporation, and to exercise the care, diligence, and skill that a reasonably prudent person would exercise in comparable circumstances. Section 120 governs conflicts of interest, requiring directors who have a material interest in a proposed contract or transaction to disclose the interest and refrain from voting on the matter. Shareholder rights are protected through Section 190 (dissent and appraisal rights), Section 239 (derivative actions), and Section 241 (oppression remedy), with Section 241 permitting courts to make broad orders where a shareholder's reasonable expectations have been fundamentally unfair. Section 160 addresses security holder communications and proxy solicitation. Significant recent amendments include: mandatory individual director elections (Section 106.1); enhanced diversity reporting for public companies (Section 172.1); amendments to facilitate hybrid meetings; and beneficial ownership transparency requirements under the register of individuals with significant control (ISC) in Section 21.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-pipeda-2000"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-cccs-itsm-40-001-pqc-migration-roadmap",
    "title": "Roadmap for the Migration to Post-Quantum Cryptography for the Government of Canada (ITSM.40.001)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2025-06-23",
    "bluf": "The Canadian Centre for Cyber Security published ITSM.40.001, Roadmap for the migration to post-quantum cryptography for the Government of Canada, on 23 June 2025. It sets dated obligations for federal departments and agencies rather than general advice. Departments are to develop an initial departmental PQC migration plan by April 2026, and to report on PQC migration progress from April 2026 onwards on an annual basis.\n\nTwo completion milestones follow. Migration of high priority systems is to be completed by the end of 2031, and migration of the remaining systems by the end of 2035. The structure separates planning and reporting from execution, and separates high priority systems from the remainder, so that departmental progress is measurable at each stage rather than only at the end. The instrument applies to Government of Canada departments and agencies and their IT systems; organisations outside that perimeter may use it as a reference model but are not bound by it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-203-ml-kem-standard",
      "fips-204-ml-dsa-standard",
      "nist-ir-8547-pqc-transition",
      "uk-ncsc-pqc-migration-timelines-2025"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ca-cccs-top-10-it-security-actions-action-1-patch-operating-systems",
    "title": "Top 10 IT security actions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations should implement a set of ten prioritized IT security actions, including patching systems, managing privileges, and segmenting information, to protect internet-connected networks and minimize the impact of cyber intrusions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-iec-27001-2022-information-security-workflow"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ca-cfpoa-corruption-foreign-public-officials-act",
    "title": "Canada Corruption of Foreign Public Officials Act 1998 (CFPOA)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Corruption of Foreign Public Officials Act of Canada (Statutes of Canada 1998 chapter 34, Royal Assent 10 December 1998, in force 14 February 1999) implements the OECD Convention on Combating Bribery of Foreign Public Officials in International Business Transactions and creates indictable Canadian offences for bribing foreign public officials and for accounting offences committed to facilitate or conceal such bribery. Section 3 prohibits any person from directly or indirectly giving, offering, or agreeing to give or offer a loan, reward, advantage, or benefit of any kind to a foreign public official in order to obtain or retain an advantage in the course of business; section 4 prohibits the establishment of off-the-books accounts, the recording of unrecorded or falsely recorded expenses, the entry of nonexistent liabilities, the use of false documents, and the intentional destruction of accounting records used to bribe or conceal bribery of foreign public officials. The Act defines a foreign public official broadly to include legislative, administrative, and judicial officeholders, persons performing public duties for a foreign state, and officials or agents of public international organizations. The maximum penalty for indictable bribery and accounting offences is imprisonment of not more than 14 years, with no maximum on the available fine. The Royal Canadian Mounted Police International Anti-Corruption Unit investigates CFPOA matters with extraterritorial nationality-based jurisdiction under section 5; AI agents conducting international business communications or transactions for Canadian-linked enterprises must record and screen the inputs that would expose the enterprise to CFPOA liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-anti-bribery-convention-1997",
      "us-fcpa-foreign-corrupt-practices-act-1977",
      "uk-bribery-act-2010"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ca-citizenship-act",
    "title": "Canada Citizenship Act (RSC 1985 c C-29): Citizenship by Birth and Descent, Grant, Revocation and Offences",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Citizenship Act (R.S.C. 1985, c. C-29) is Canada's principal statute governing who is a Canadian citizen and how citizenship is acquired, granted, revoked and protected, administered by Immigration, Refugees and Citizenship Canada (IRCC). Section 3 sets out who is a citizen, including a person born in Canada after February 14, 1977, persons who acquire citizenship by descent (subject to the first-generation limit on citizenship by descent), and persons to whom citizenship is granted. Section 5(1) sets the requirements for a grant of citizenship to a permanent resident, including that the applicant has been physically present in Canada for at least 1,095 days during the five years immediately before the date of the application, has met any applicable income tax filing obligations, has an adequate knowledge of one of the official languages of Canada (for applicants aged 18 to 54), demonstrates an adequate knowledge of Canada and of the responsibilities and privileges of citizenship, and (for applicants aged 14 and over) takes the oath of citizenship. Section 5(2) provides for the grant of citizenship to a minor child. Section 10 authorizes the Minister to revoke citizenship where the person obtained, retained, renounced or resumed citizenship by false representation or fraud or by knowingly concealing material circumstances. Section 22 sets out prohibitions that bar a grant of citizenship or the taking of the oath on specified grounds, including certain criminal charges and convictions and security grounds. Section 29 creates the offences and punishments: under section 29(2) certain offences (such as personation or possession of an unlawfully issued citizenship document) are punishable by imprisonment for a term of not more than five years; under section 29(3) the more serious offences of unlawfully issuing, altering, counterfeiting or trafficking in citizenship documents are punishable by imprisonment for a term of not more than fourteen years; and under section 29(4) a contravention of the Act for which no other penalty is provided is an offence punishable on summary conviction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "ca-competition-act-1985",
    "title": "Canada Competition Act 1985 (R.S.C. 1985, c. C-34) - Antitrust and Consumer Protection",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Canada Competition Act (R.S.C. 1985, c. C-34) promotes and maintains competitive markets in Canada, prohibits anti-competitive practices, and protects consumers from misleading conduct, administered by the Competition Bureau under the Commissioner of Competition. Section 45 prohibits conspiracies between competitors to fix prices, allocate markets, or restrict the supply of products or services as criminal per se offences without requiring proof of competitive harm - carrying penalties of up to 14 years imprisonment and CAD 25 million fines. Section 79 addresses abuse of dominant position, prohibiting conduct by dominant firms that has had, is having, or is likely to have the effect of substantially lessening or preventing competition. Mergers and acquisitions that would likely substantially prevent or lessen competition are reviewable by the Competition Tribunal under Section 92, with mandatory pre-merger notification required under Section 114 where the transaction exceeds specified asset and revenue thresholds (CAD 400 million in combined Canadian revenues and CAD 93 million target size threshold for 2025). Misleading advertising and deceptive marketing practices are addressed through criminal and civil provisions under Sections 74.01 to 74.07, including specific provisions for drip pricing, testimonials, and environmental claims. The Competition Bureau may seek administrative monetary penalties of up to 3% of gross revenues for civil competition offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-competition",
      "eu-tfeu-article-102-abuse-of-dominance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-competition-act-abuse-dominance-digital-markets-section-78",
    "title": "Canada Competition Act - Abuse of Dominance in Digital Markets (Sections 78-79)",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Sections 78-79 of the Canada Competition Act (R.S.C. 1985, c. C-34) prohibit abuse of dominant position by one or more persons substantially or completely controlling a market. The Competition Bureau has applied these provisions to digital platform markets. The 2024 amendments modernised the framework adding a new reviewable conduct provision for digital platforms and expanded the Bureau's market study powers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-pipeda-2000"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-competition-act-section-78-abuse-dominant-position",
    "title": "Competition Act (R.S.C., 1985, c. C-34) - Section 78: Definition of anti-competitive act",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must refrain from engaging in any act intended to have a predatory, exclusionary, or disciplinary negative effect on a competitor, or to adversely affect competition, as defined within this section.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "ca-conflict-of-interest-act",
    "title": "Canada Conflict of Interest Act - Duties of Public Office Holders, Gifts and Penalties",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "Canada's Conflict of Interest Act (S.C. 2006, c. 9, s. 2) governs the ethical conduct of public office holders. Section 5 requires every public office holder to arrange private affairs to prevent conflicts of interest; section 6(1) prohibits making decisions that would place the holder in a conflict of interest; section 8 prohibits using non-public insider information for private gain; section 11(3) requires forfeiture of gifts valued at $1,000 or more; and section 52 provides administrative monetary penalties not exceeding $500.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-consumer-product-safety-act-2010",
    "title": "Canada Consumer Product Safety Act 2010",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2011-06-20",
    "bluf": "The Canada Consumer Product Safety Act (S.C. 2010, c. 21), in force 20 June 2011, prohibits the manufacture, importation, advertising, and sale of consumer products that pose a danger to human health or safety under Section 7, requires manufacturers, importers, and sellers to report to Health Canada within 10 days any incident involving a product defect, malfunction, deterioration, or packaging problem that has caused or is reasonably likely to cause a serious adverse health or safety impact under Section 14, mandates maintenance of product documents sufficient to trace the origin and distribution chain for a minimum of 6 years under Section 13, requires cooperation with Minister-ordered recalls under Section 31, and imposes penalties of up to CAD 5 million per violation and 2 years imprisonment for serious violations, making it the primary pre-market and post-market safety framework for consumer products in Canada.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ca-competition-act-1985",
        "ca-canada-health-act-1984",
        "eu-product-liability-directive-2024-2853"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-competition-act-1985",
      "ca-canada-health-act-1984",
      "eu-product-liability-directive-2024-2853"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-controlled-drugs-substances-act-cdsa",
    "title": "Canada Controlled Drugs and Substances Act - Scheduling, Possession, Trafficking and Production Offences",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "Canada's Controlled Drugs and Substances Act (S.C. 1996, c. 19) controls substances listed in Schedules I to IX. Section 4(1) prohibits possession of a substance included in Schedule I, II or III; section 5(1) prohibits trafficking in a substance included in Schedule I, II, III, IV or V; section 6(1) prohibits importing into or exporting from Canada a scheduled substance; and section 7(1) prohibits production. Trafficking in or importing a Schedule I or II substance is punishable by imprisonment for life.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-copyright-act-1985",
    "title": "Canada Copyright Act 1985",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2022-06-23",
    "bluf": "The Copyright Act (R.S.C. 1985, c. C-42), last significantly amended by the Copyright Modernization Act 2012 and the Budget Implementation Act 2022, protects the original expression of literary, artistic, dramatic, and musical works plus performers' performances, sound recordings, and communication signals for a term of the life of the author plus 70 years under Section 6 (extended from life plus 50 years by the Canada-United States-Mexico Agreement Implementation Act 2020), grants copyright owners the exclusive rights to reproduce, perform, publish, and communicate works to the public over the Internet under Section 3, establishes fair dealing exceptions for research, private study, education, parody, satire, news reporting, and criticism under Sections 29 to 29.2, and provides statutory damages of CAD 500 to CAD 20,000 per infringed work for non-commercial infringement and CAD 500 to CAD 100,000 for commercial infringement under Section 38.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-copyright-dsm-directive-2019-790",
        "ca-casl-2014",
        "wipo-copyright-treaty-1996"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-dsm-directive-2019-790",
      "ca-casl-2014",
      "wipo-copyright-treaty-1996"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-cppa-bill-c27-2022",
    "title": "Canada Consumer Privacy Protection Act - Bill C-27 (Proposed, 2022)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Canada Bill C-27 tabled November 16, 2020 and reintroduced June 16, 2022 proposes replacing PIPEDA with the Consumer Privacy Protection Act (CPPA) establishing modern consent requirements, data portability rights, algorithmic transparency obligations, privacy management programs, and enforcement by a new Privacy Commissioner with order-making powers and penalties of up to CAD 25 million or 5% of global annual revenue; the bill had not yet received Royal Assent as of April 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ca-cppa-bill-c27-2022.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-pipeda-2000"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-criminal-code-162-1-intimate-image-without-consent",
    "title": "Canada Criminal Code Section 162.1 - Publication of an Intimate Image Without Consent and Section 162.2 Prohibition Order (Protecting Canadians from Online Crime Act SC 2014 c. 31)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Section 162.1 of the Criminal Code of Canada (R.S.C. 1985, c. C-46), enacted by the Protecting Canadians from Online Crime Act SC 2014 c. 31, criminalises the publication, distribution, transmission, sale, making available, or advertising of an intimate image of a person without that person's consent or with recklessness as to consent. Section 162.1(1) creates a hybrid offence: on indictment, the maximum penalty is imprisonment for a term of not more than 5 years; on summary conviction, the standard summary penalties apply. Section 162.1(2) defines intimate image as a visual recording of a person made by any means including photographic, film, or video recording in which (a) the person is nude, is exposing his or her genital organs or anal region or her breasts or is engaged in explicit sexual activity, (b) in respect of which at the time of the recording there were circumstances that gave rise to a reasonable expectation of privacy, and (c) in respect of which the person depicted retains a reasonable expectation of privacy at the time the offence is committed. Section 162.1(3) provides that no person shall be convicted if the conduct serves the public good and does not extend beyond what serves the public good (a narrow defence). Section 162.2 empowers the sentencing court (or court that discharges on probation under section 730) to make a prohibition order against the offender prohibiting use of the Internet or other digital network unless the offender complies with court-set conditions; section 162.2(1) permits the order in addition to any other punishment; section 162.2(2) sets the duration at any period the court considers appropriate including any period of imprisonment; section 162.2(3) provides for variation on application of the offender or the prosecutor after hearing where changed circumstances make variation desirable; section 162.2(4) makes breach of the prohibition order an offence punishable by indictment with imprisonment up to 4 years or summary conviction. Sections 162.1 and 162.2 sit alongside the civil intimate-image remedies in several provincial Intimate Images Protection Acts (BC, Manitoba, Newfoundland and Labrador, Nova Scotia, PEI, Saskatchewan, Alberta) and the federal Bill C-63 Online Harms Act regime that imposes platform takedown obligations. Online platforms operating in Canada are not directly liable under section 162.1 for user uploads in the absence of knowing or reckless conduct by platform operators themselves; however, civil takedown obligations and emerging federal Online Harms Act duties apply.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_162_1_offence_elements",
        "section_162_1_2_intimate_image_definition",
        "section_162_1_3_public_good_defence",
        "section_162_2_prohibition_order_authority",
        "section_162_2_4_breach_offence",
        "provincial_civil_remedies_taxonomy",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-vawa-violence-against-women-act-1994-pl-103-322",
      "uk-online-safety-act-2023-part-3-illegal-content-children-duties",
      "eu-dsa-article-28-online-protection-of-minors",
      "us-take-it-down-act-2025"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-criminal-code-section-151-sexual-interference-under-16",
    "title": "Canada Criminal Code Section 151 - Sexual Interference with a Person Under 16",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 151 of the Criminal Code of Canada makes it an offence for a person to, for a sexual purpose, touch, directly or indirectly, with a part of the body or with an object, any part of the body of a person under the age of 16 years. The age of consent is generally 16, but a close-in-age exception applies for those aged 14-15 with a consensual partner less than 5 years older. Penalty: indictable up to 14 years imprisonment (mandatory minimum 1 year before R v Bertrand Marchand 2023 SCC 26 invalidation); summary up to 2 years less a day (mandatory minimum 90 days). Section 151 is Canada's principal child sexual abuse offence and operates alongside Section 152 (invitation to sexual touching), Section 153 (sexual exploitation by person in position of trust 16-17), and the broader chapter 5 sexual offences framework (Sections 271-273).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_text",
        "age_of_consent_section_150_1",
        "sexual_purpose_objective_subjective_test",
        "direct_or_indirect_touching",
        "with_part_of_body_or_object",
        "interaction_with_section_271_sexual_assault",
        "no_mistake_of_age_defence_unless_reasonable_steps_section_150_1_4",
        "interaction_with_section_153_sexual_exploitation_position_trust_16_17",
        "sora_registration_mandatory_for_section_151_convictions",
        "interaction_with_us_18_usc_2243_a_and_uk_soa_section_9"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-criminal-code-section-163-obscene-matter",
      "ca-criminal-code-section-172-1-luring-a-child"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ca-criminal-code-section-163-obscene-materials",
    "title": "Canada Criminal Code Section 163 - Obscene Material Distribution and Possession Offences (R.S.C. 1985 c. C-46)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "Section 163 of the Canadian Criminal Code (R.S.C. 1985, c. C-46) is the principal federal criminal prohibition on the production, publication, distribution, circulation, sale, public exhibition and possession-for-distribution of obscene material in Canada. Subsection 163(1) criminalises any person who makes, prints, publishes, distributes, circulates or has in their possession for the purpose of publication, distribution or circulation any obscene written matter, picture, model, phonograph record or any other obscene thing. Subsection 163(2) prohibits knowingly selling, exposing to public view or possessing for that purpose any obscene material, and publicly exhibiting disgusting objects or indecent shows. Subsection 163(3) preserves a defence of public good where the public good was served by the alleged acts and the acts did not extend beyond what served that public good (artistic, educational, scientific or medical purposes). Subsection 163(8) defines obscene as any publication a dominant characteristic of which is the undue exploitation of sex, or of sex combined with crime, horror, cruelty or violence. Under Section 169, the Section 163 offence is a hybrid offence punishable by imprisonment up to two years on indictment or on summary conviction (with reference to the Section 787 general summary-conviction penalty for the upper limit). The Section 163(8) undue-exploitation test is interpreted through the Butler test (R. v. Butler, [1992] 1 S.C.R. 452) on the community standards of tolerance: content is obscene where the community would not tolerate exposure of others to it because of the harm it poses, particularly to women and children. Section 163 operates in parallel with Section 163.1 (child pornography, six months to fourteen years), Section 162.1 (publication of intimate images without consent, the Bill C-13 amendment of 2014, up to five years), and Section 162 (voyeurism, up to five years). For digital platforms accessible from Canada, Section 163 reaches extraterritorially under Sections 6 and 477 of the Criminal Code where the act has a real and substantial link to Canada (R. v. Libman, [1985] 2 S.C.R. 178). Enforcement is by the Royal Canadian Mounted Police, provincial and municipal police, and provincial Crown prosecutors; the Department of Justice maintains policy oversight. The Online Harms Act (Bill C-63 introduced 26 February 2024, in force in stages from 2025-2026) overlays Section 163 with platform safety duties on operators of social media and content platforms, including a duty to make non-consensual intimate content and content that sexually victimises children inaccessible within twenty-four hours of a credible complaint.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "criminal_code_neighbouring_anchors",
        "butler_test_anchor",
        "online_harms_act_overlay",
        "extraterritorial_reach_anchor",
        "industry_mapping",
        "enforcement_anchors",
        "charter_section_2_b_litigation_anchor"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-pcmltfa-aml-2000",
      "us-18-usc-2257-record-keeping-explicit-content",
      "au-online-safety-act-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ca-criminal-code-section-163-obscene-matter",
    "title": "Canada Criminal Code Section 163 - Offences Tending to Corrupt Morals (Obscene Matter)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Section 163 of the Canadian Criminal Code (R.S.C. 1985, c. C-46) creates federal criminal offences for the making, distribution, and possession-for-distribution of obscene matter: subsection (1) makes it an offence for every person who 'makes, prints, publishes, distributes, circulates or has in their possession for the purpose of publication, distribution or circulation any obscene written matter, picture, model, phonograph record or any other obscene thing'; subsection (2) creates the parallel offence for crime comics; subsection (3) provides the public good defence preventing conviction where the public good was served by the acts and the acts did not extend beyond what served the public good; subsection (8) defines obscene as material 'a dominant characteristic of which is the undue exploitation of sex, or of sex and any one or more of the following subjects, namely, crime, horror, cruelty and violence'; the Section 163 obscenity test was clarified by the Supreme Court of Canada in R v Butler [1992] 1 SCR 452 (community standards test focused on harm rather than mere offensiveness, particularly harm to women and equality); penalties on indictment up to 2 years imprisonment, on summary conviction lesser penalties; Section 163.1 (separate provision) addresses child pornography with significantly harsher penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "section_163_1_child_pornography_separate_offence",
        "leading_case_law",
        "charter_of_rights_intersection",
        "industry_mapping",
        "enforcement_anchors",
        "section_163_3_public_good_defence"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-obscene-publications-act-1959",
      "us-18-usc-1465-production-transportation-obscene-matter",
      "us-18-usc-1466a-obscene-visual-representations-csam"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-criminal-code-section-172-1-luring-a-child",
    "title": "Canada Criminal Code Section 172.1 - Luring a Child via Telecommunications",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 172.1 of the Criminal Code of Canada makes it an offence to communicate by a means of telecommunication with (a) a person who is, or who the accused believes is, under the age of 18 years, for the purpose of facilitating the commission of an offence under section 153, 155, 163.1, 170, 171 or 279.011 or subsection 279.02(2), 279.03(2), 286.1(2), 286.2(2) or 286.3(2) with respect to that person; or (b) a person who is, or who the accused believes is, under the age of 16 years, for the purpose of facilitating the commission of an offence under section 151 or 152, subsection 160(3) or 173(2) or section 271, 272, 273 or 280 with respect to that person; or (c) a person who is, or who the accused believes is, under the age of 14 years, for the purpose of facilitating the commission of an offence under section 281 with respect to that person. Reasonable steps defence available where the accused believed the victim was of age. Penalty: indictable up to 14 years; summary up to 2 years less a day. Mandatory minimum sentences apply.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "penalty_subsection_2_indictable_or_summary",
        "presumption_of_belief_subsection_3",
        "reasonable_steps_defence_subsection_4",
        "telecommunication_definition_broad",
        "predicate_sexual_offences_section_151_152_271_272_273",
        "predicate_csam_offences_section_163_1",
        "predicate_extraterritorial_section_170_171",
        "interaction_with_section_172_2_agreement_arrangement_for_sexual_offence_against_child",
        "interaction_with_us_18_usc_2422_b_and_uk_soa_section_15"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-criminal-code-section-163-obscene-matter"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ca-criminal-code-section-342-1-unauthorized-computer",
    "title": "Criminal Code (R.S.C., 1985, c. C-46), Section 342.1: Unauthorized use of computer",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "Organizations must prevent the fraudulent and unauthorized obtaining of computer services, interception of computer system functions, use of computer systems to commit related offenses, and the misuse of computer passwords.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ca-directive-automated-decision-making-2019-section-4-algorithmic-impact",
    "title": "Directive on Automated Decision-Making, Section 6: Requirements",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must complete, publish, and regularly update an Algorithmic Impact Assessment (AIA) for any automated decision system, provide transparent notices to clients before and meaningful explanations after a decision is made, and ensure access to all system components for audits and reviews.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-employment-equity-act-1995",
    "title": "Canada Employment Equity Act 1995",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2023-05-09",
    "bluf": "The Employment Equity Act (S.C. 1995, c. 44), in force 24 October 1996 and last amended in 2023, requires federally regulated private sector employers with 100 or more employees and federal contractors with 100 or more employees and contracts of CAD 1 million or more to implement employment equity for four designated groups - women, Indigenous peoples, persons with disabilities, and members of visible minorities - by identifying and eliminating barriers to their employment, establishing numerical goals for achieving workforce representation that reflects workforce availability, and reporting annually to the Minister of Labour on workforce composition and progress under Sections 18 and 19, enforced by Canadian Human Rights Commission audits with compliance orders and penalties of up to CAD 50,000 for federally regulated employers under Section 36.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ca-labour-code-employment",
        "ca-pipeda-2000",
        "ca-accessible-canada-act-2019"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-labour-code-employment",
      "ca-pipeda-2000",
      "ca-accessible-canada-act-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-employment-equity-act-section-5-employer-duties",
    "title": "Employment Equity Act, S.C. 1995, c. 44, Section 5 - Employer’s duty",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Employers must implement employment equity by identifying and eliminating employment barriers and instituting positive policies and practices to ensure representation of designated groups.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-occupational-safety-and-health-act"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-environmental-protection-act-part-5-toxics",
    "title": "Canadian Environmental Protection Act, 1999 - Part 5, Sections 74-76.1: Controlling Toxic Substances",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation outlines the process for any person to request a substance assessment from the Ministers, specifying the required form, manner, and information for such a request.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-toxic-substances-control-act",
      "iso-14001-environmental-management-construction"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-food-drugs-act-1985",
    "title": "Canada Food and Drugs Act 1985",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2019-05-09",
    "bluf": "The Food and Drugs Act (R.S.C. 1985, c. F-27), consolidated and continuously amended, prohibits the sale of a food that is adulterated, unfit for human consumption, or misleadingly labelled under Section 4, requires a New Drug Submission or Abbreviated New Drug Submission approved by Health Canada under Sections 30(1) and 55 before a new human or veterinary pharmaceutical drug may be sold in Canada, mandates that medical devices meet the applicable class-specific safety and effectiveness requirements under the Medical Devices Regulations (SOR/98-282) before sale, requires natural health products to hold a product licence issued by Health Canada under the Natural Health Products Regulations (SOR/2003-196), and imposes penalties of up to CAD 5 million and 2 years imprisonment for serious violations of the Act, making it the primary pre-market approval and post-market surveillance framework for drugs, food, medical devices, and natural health products in Canada.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ca-canada-health-act-1984",
        "ca-consumer-product-safety-act-2010",
        "eu-medical-devices-regulation-mdr-2017-745-implementation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-canada-health-act-1984",
      "ca-consumer-product-safety-act-2010",
      "eu-medical-devices-regulation-mdr-2017-745-implementation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-food-drugs-act-part-c-drugs-therapeutic",
    "title": "Food and Drugs Act, R.S.C., 1985, c. F-27 - Article 2: Interpretation and Application",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the legal definitions for key terms such as food, drug, cosmetic, and device, which determine the regulatory scope and obligations for products under the Food and Drugs Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-210-211-current-good-manufacturing-practice",
      "eu-medical-devices-regulation-2017-745"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-hazardous-products-act-whmis",
    "title": "Canada Hazardous Products Act - WHMIS Supplier Labels, Safety Data Sheets and Penalties",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "Canada's Hazardous Products Act (R.S.C. 1985, c. H-3) is the federal pillar of the Workplace Hazardous Materials Information System (WHMIS). Section 13 prohibits suppliers from selling a hazardous product intended for use in a workplace unless a compliant safety data sheet is provided and a compliant label is affixed; section 14 imposes equivalent obligations on importers; section 2 defines a hazardous product by reference to the hazard classes in Schedule 2; and section 28 sets fines up to $5,000,000 or imprisonment up to two years on indictment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-health-canada-medical-devices-regulations-sir-sor-98-282",
    "title": "CA Health Canada Medical Devices Regulations SOR/98-282 - Licence and Safety Requirements",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "Health Canada regulates medical devices in Canada under the Medical Devices Regulations (SOR/98-282) made under the Food and Drugs Act. Class II, III, and IV devices require a Medical Device Licence (MDL) from Health Canada before sale. Class I devices require manufacturer registration only. The regulatory framework requires safety and effectiveness evidence, a Quality Management System (ISO 13485), and mandatory incident reporting. Class III and IV devices require clinical evidence from clinical trials or post-market studies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-2016-medical-devices-quality-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-immigration-and-refugee-protection-act",
    "title": "Canada Immigration and Refugee Protection Act (IRPA): Entry, Inadmissibility, Protection and Offences",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Immigration and Refugee Protection Act (IRPA), S.C. 2001, c. 27, is the principal federal statute governing immigration to and refugee protection in Canada, administered by Immigration, Refugees and Citizenship Canada (IRCC) and the Canada Border Services Agency (CBSA), with the Immigration and Refugee Board adjudicating claims and appeals. Section 3 sets the objectives for immigration and for refugee protection, including economic and social benefit, family reunification, fulfilment of Canada's international obligations, and protection of public health and security. Section 18 requires every person seeking to enter Canada to appear for an examination to determine the right to enter, while section 19 confirms that Canadian citizens and registered Indians have the right to enter and that permanent residents are allowed entry once status is confirmed. Division 4 of Part 1 (sections 33-43) sets the grounds of inadmissibility, including security (s. 34), human or international rights violations (s. 35), serious criminality and criminality (s. 36), organized criminality (s. 37), health grounds (s. 38), financial grounds (s. 39) and misrepresentation (s. 40). Part 2 governs refugee protection: sections 96 and 97 define a Convention refugee and a person in need of protection (risk of persecution, torture, or risk to life or cruel and unusual treatment), and section 115 enacts the principle of non-refoulement, subject to limited exceptions. Part 3 creates the offences, including human smuggling (s. 117), trafficking in persons (s. 118), the general offences and contraventions (s. 124), and misrepresentation (s. 127), which are punishable by fines and imprisonment. The Act is supplemented by the Immigration and Refugee Protection Regulations (SOR/2002-227).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "ca-impact-assessment-act-2019-federal-environmental-review-major-projects",
    "title": "CA Impact Assessment Act 2019 - Federal Environmental and Impact Assessment for Designated Projects in Canada",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2019-08-28",
    "bluf": "Canada's Impact Assessment Act 2019 (IAA) requires federal impact assessment for Designated Projects (major mines, pipelines, nuclear facilities, interprovincial projects) through the Impact Assessment Agency of Canada, assessing effects on federal jurisdiction areas including fish and fish habitat, migratory birds, and Indigenous peoples' rights, with a unified Crown consultation process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-pipeda-2000",
      "ca-osfi-b-13-guideline-technology-cyber-risk-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-impact-assessment-act-2019-section-22-mining-factors",
    "title": "Canada Impact Assessment Act 2019 Section 22 - Mandatory Factors in Federal Impact Assessment of Designated Mining Projects",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Section 22 of Canada's Impact Assessment Act 2019 (IAA) specifies the mandatory and discretionary factors that the Impact Assessment Agency of Canada (IAAC) must consider when conducting a federal impact assessment of a designated project, including large mining and extraction projects listed under the Physical Activities Regulations. Mandatory factors include environmental effects, health effects, social and cultural effects, Indigenous rights impacts, gender effects, and changes to economies. The IAA replaced the Canadian Environmental Assessment Act 2012 (CEAA 2012) and introduced enhanced Indigenous consultation requirements, a sustainability lens, and consideration of designated projects' contribution to meeting climate change commitments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-safety-health-mines-convention-c176-1995"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-income-tax-act-section-247-transfer-pricing",
    "title": "Income Tax Act (R.S.C., 1985, c. 1 (5th Supp.)) - Section 247",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "This article defines key terms related to transfer pricing, including arm's length principles, qualifying cost contribution arrangements, and various types of tax adjustments, which form the basis for determining tax obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-transfer-pricing-guidelines-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ca-income-tax-act-transfer-pricing-s247",
    "title": "Canada Income Tax Act Transfer Pricing Section 247",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "Section 247 of the Income Tax Act (R.S.C. 1985, c. 1 (5th Supp.)), as amended by the Budget Implementation Act 2023, requires that transactions and arrangements between a Canadian taxpayer and a non-arm's length non-resident be priced consistent with the arm's length principle, empowers the Canada Revenue Agency to adjust the amounts of such transactions to reflect arm's length terms under Section 247(2), applies a penalty equal to 10% of the net upward transfer pricing adjustments exceeding CAD 5 million where the taxpayer did not make reasonable efforts to determine and use arm's length prices under Section 247(3), requires maintenance of contemporaneous documentation meeting the standards in Information Circular IC 87-2R and the OECD Transfer Pricing Guidelines under Section 247(4), and mandates reporting of controlled transactions on Schedule 25 of the T2 corporation income tax return and on Form T106 for non-arm's length transactions with non-residents exceeding CAD 1 million in the tax year.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "oecd-beps-action-13-cbc-reporting",
        "oecd-tp-financial-transactions-guidance-2020",
        "oecd-pillar-two-global-minimum-tax-15-percent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-cbc-reporting",
      "oecd-tp-financial-transactions-guidance-2020",
      "oecd-pillar-two-global-minimum-tax-15-percent"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-investment-canada-act-1985",
    "title": "Canada Investment Canada Act 1985",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-09-21",
    "bluf": "The Investment Canada Act (R.S.C. 1985, c. 28 (1st Supp.)), last significantly amended by the Budget Implementation Act 2023, requires non-Canadian investors to file a notification or application for review before completing direct acquisitions of Canadian businesses, subjects direct acquisitions of businesses with enterprise value exceeding CAD 1.287 billion (2024 threshold for WTO investors from non-state-controlled entities) to a net benefit to Canada review under Section 21, applies a national security review under Sections 25.1 to 25.4 to any foreign investment regardless of size or sector that could be injurious to Canada's national security, and enables the Minister of Innovation, Science and Industry to order divestiture, impose binding undertakings, or prohibit the investment on net benefit or national security grounds, with penalties of CAD 10,000 per day for contraventions of orders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ca-competition-act-1985",
        "ca-cbca-corporations-act-1985",
        "eu-digital-markets-act-2022"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-competition-act-1985",
      "ca-cbca-corporations-act-1985",
      "eu-digital-markets-act-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-labour-code-employment",
    "title": "Canada Labour Code (R.S.C. 1985, c. L-2) - Part III Standard Hours, Wages, and Employment Conditions",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Canada Labour Code (R.S.C. 1985, c. L-2) governs employment conditions for employees in federally regulated industries in Canada, including banking, telecommunications, broadcasting, interprovincial transportation, and federal Crown corporations. Part III of the Code (Standard Hours, Wages, Vacations and Holidays) establishes minimum employment standards applicable to approximately 6% of the Canadian workforce employed in the federal jurisdiction. Section 167 establishes the standard hours of work as 8 hours per day and 40 hours per week, with maximum hours of 48 per week. Section 169 requires overtime pay at a minimum of one and one-half times the regular rate for hours worked beyond the standard hours. Section 174 provides minimum annual vacation entitlements: 2 weeks after 1 year of continuous service, 3 weeks after 5 years, and 4 weeks after 10 years. Section 230 requires employers to provide minimum notice of termination of 2 weeks for employees with 3 or more months of service, escalating to 8 weeks for employees with 8 or more years of service. Section 240 provides that employees with 12 or more months of continuous service who are dismissed without just cause may file a complaint of unjust dismissal, with the adjudicator empowered to order reinstatement and compensation. The Employment Equity Act supplements Part III with positive obligations for federally regulated employers to achieve workforce diversity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998",
      "ilo-convention-155-occupational-safety-1981"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ca-lobbying-act",
    "title": "Canada Lobbying Act - Registration Deadlines, Code of Conduct and Penalties",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "Canada's Lobbying Act (R.S.C. 1985, c. 44 (4th Supp.)) requires lobbyists to register. Section 5 requires a consultant lobbyist to file a return not later than 10 days after entering into an undertaking to communicate with a public office holder; section 7 requires an organization with in-house lobbyists to file not later than two months after the requirement first arises; section 10.2 requires the Commissioner to develop a Lobbyists' Code of Conduct; and section 14 sets a fine up to $200,000 or imprisonment up to two years on indictment for failing to file or making false statements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-motor-vehicle-safety-regulations-crc-1038",
    "title": "Canada Motor Vehicle Safety Regulations CRC c 1038 - National Safety Mark Compliance Labels CMVSS Standards Recall and Importation",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-29",
    "bluf": "Canada Motor Vehicle Safety Regulations (CRC c 1038) implement the Motor Vehicle Safety Act and prescribe national safety mark requirements under Section 3 prescribed vehicle classes under Section 4 with Schedule III matrix the Canada Motor Vehicle Safety Standards CMVSS in Schedules IV V.1 and VI under Section 5 compliance label requirements under Section 6 manufactured in stages provisions under Sections 6.1 to 6.6 altered vehicle standards under Section 9 records maintenance under Section 10 importation provisions under Section 11 with Section 11.1 temporary imports and Section 12 for sections 7(2) and (2.1) of the Act applications for exemption under Section 13 notice of defect under Section 15 notice of non-compliance under Section 15.01 and Technical Standards Documents incorporated under Section 16 including TSD 110 and TSD 120 tire selection TSD 121 air brake systems and TSD 222 school bus seating with owner's manual requirements under Section 18. Transport Canada is the issuing authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "canada-motor-vehicle-safety-act-1985-cmvss",
      "us-fmvss-federal-motor-vehicle-safety-standards",
      "un-regulation-155-vehicle-cybersecurity"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "ca-official-languages-act",
    "title": "Canada Official Languages Act - Equality of English and French in Federal Institutions",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "Canada's Official Languages Act (R.S.C. 1985, c. 31 (4th Supp.)) ensures equality of status of English and French in federal institutions. Section 4 affirms the right to use either language in the proceedings of Parliament; section 21 gives any member of the public the right to communicate with and receive available services from federal institutions in either official language; section 34 makes English and French the languages of work in federal institutions; section 41 commits the government to enhancing the vitality of official-language minority communities; and section 49 provides for the Commissioner of Official Languages.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-on-phipa-2004",
    "title": "Ontario Personal Health Information Protection Act 2004",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Ontario's PHIPA governs the collection, use, and disclosure of personal health information by health information custodians across the province, enforced by the Information and Privacy Commissioner of Ontario with authority to issue binding orders and impose penalties up to CAD 100,000.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ca-on-phipa-2004.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-pipeda-2000",
      "ca-bc-pipa-2003"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ca-osfi-b-13-guideline-technology-cyber-risk-management",
    "title": "Canada OSFI Guideline B-13 - Technology and Cyber Risk Management for Federally Regulated Financial Institutions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "OSFI Guideline B-13 (effective January 2024) establishes technology and cyber risk management expectations for all federally regulated financial institutions (FRFIs) including banks, insurance companies, and federal credit unions. Key domains: governance, technology operations, cyber resilience, third-party and supply chain risk, and data risk management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-pipeda-2000"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-osfi-capital-adequacy-requirements-car-2023",
    "title": "Canada OSFI Capital Adequacy Requirements (CAR) Guideline - D-SIB Framework and Domestic Stability Buffer",
    "domain": "Banking & Global Finance",
    "version": "2023.1.0",
    "last_updated": "2023-11-01",
    "bluf": "OSFI's Capital Adequacy Requirements (CAR) Guideline implements Basel III for Canadian federally regulated deposit-taking institutions: minimum CET1 ≥7.0% (including 2.5% Capital Conservation Buffer); D-SIB surcharge 1.0% for Canada's Big Six (RBC, TD, BMO, Scotiabank, CIBC, National Bank); Domestic Stability Buffer (DSB) 3.5% effective February 2024 (countercyclical in nature); and an Output Floor of 72.5% from Q2 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-crr3-capital-requirements-regulation-2024-1623",
      "au-apra-prudential-standard-aps-110-adi"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-osfi-guideline-b-20-mortgage-underwriting",
    "title": "Canada OSFI Guideline B-20 - Residential Mortgage Underwriting Practices",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "OSFI (Office of the Superintendent of Financial Institutions) Guideline B-20 (Residential Mortgage Underwriting Practices and Procedures, updated January 2018 and revised 2023) establishes supervisory expectations for federally regulated financial institutions (FRFIs) - banks, trust companies, and credit unions with federal charters - on residential mortgage underwriting. Key requirements include: mandatory mortgage stress test (qualifying rate = greater of contract rate + 2% OR floor rate set by OSFI, currently 5.25%); maximum LTV ratios (80% uninsured, 95% insured); portfolio-level LTV and debt service monitoring; expectation that FRFIs avoid non-amortising mortgages; and OSFI's expectation of conservative credit risk management in response to housing market conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-mortgage-credit-directive-2014-17-real-estate",
      "eu-brrd-bank-recovery-resolution-directive-2014-59"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-osfi-insurance-companies-act-1991",
    "title": "Insurance Companies Act (S.C. 1991, c. 47) - OSFI Prudential Regulation of Federal Insurers (Canada)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "The Insurance Companies Act (S.C. 1991, c. 47) is the federal statute under which the Office of the Superintendent of Financial Institutions (OSFI) regulates federally incorporated and authorised insurance companies in Canada. A company is incorporated by letters patent, and it must not commence or carry on business until the Superintendent issues an order approving its commencement. A company must maintain adequate capital and adequate and appropriate forms of liquidity, must comply with the investment and lending portfolio limits, and must observe the self-dealing restrictions that prohibit and restrict transactions with related parties. The company must have an appointed actuary who values its liabilities and reports as required, and its directors and officers must discharge their duties and manage conflicts of interest. The company must prepare financial statements, and it is subject to OSFI supervision, directions of compliance, and reporting requirements. The Act establishes the prudential framework that protects policyholders and the stability of the Canadian financial system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ca_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-solvency-ii-directive-2009-138-ec-eiopa",
      "basel-iii-capital",
      "au-apra-prudential-standard-cps-220"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ca-osfi-liquidity-adequacy-requirements-lar-2023",
    "title": "Canada OSFI Liquidity Adequacy Requirements (LAR) Guideline 2023",
    "domain": "Banking & Global Finance",
    "version": "2026.1.1",
    "last_updated": "2026-04-30",
    "bluf": "OSFI's Liquidity Adequacy Requirements (LAR) Guideline implements Basel III Liquidity Coverage Ratio (LCR) and Net Stable Funding Ratio (NSFR) for Canadian deposit-taking institutions (DTIs), requiring daily LCR monitoring, monthly NSFR reporting, and additional Canadian-specific liquidity buffers to ensure DTIs can survive a 30-day stress scenario and maintain stable funding over a one-year horizon.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "basel_iii",
        "bcbs_sound_liquidity",
        "eu_crr",
        "ifrs"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-osfi-capital-adequacy-requirements-car-2023",
      "basel-iii-liquidity-lcr",
      "eu-nsfr-net-stable-funding-ratio-crr2-2019"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ca-patent-act-1985",
    "title": "Canada Patent Act 1985",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-12-30",
    "bluf": "The Patent Act (R.S.C. 1985, c. P-4), last substantially amended by the Comprehensive Economic and Trade Agreement Implementation Act 2017 and the Budget Implementation Act 2018, grants inventors a 20-year exclusive patent term from the filing date under Section 44 for inventions that are novel, non-obvious, and useful, requires examination of patent applications by the Commissioner of Patents within the prescribed examination request period under Section 35, establishes the patent office filing and prosecution process, provides for compulsory licensing of patented medicines for export to least-developed countries under Section 21.04, permits independent parallel development defences under Section 56, and confers on patent holders the exclusive right to make, use, and sell the patented invention in Canada under Section 42, with infringement remedies including injunctions, compensatory damages, and accounting of profits under Sections 55 and 57.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ca-copyright-act-1985",
        "ca-competition-act-1985",
        "wipo-copyright-treaty-1996"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-copyright-act-1985",
      "ca-competition-act-1985",
      "wipo-copyright-treaty-1996"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-pcmltfa-aml-2000",
    "title": "Canada Proceeds of Crime (Money Laundering) and Terrorist Financing Act 2000 (PCMLTFA)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA, S.C. 2000, c. 17) is Canada's primary AML/CTF legislation, establishing a mandatory compliance and reporting regime administered by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC). Section 5 prescribes the entities subject to the Act, including banks, credit unions, trust companies, securities dealers, money services businesses, life insurance companies, accountants, real estate brokers, dealers in precious metals, and casinos. Reporting entities must establish a compliance program, conduct client due diligence and identity verification (Section 9.1), report suspicious transactions to FINTRAC regardless of amount (Section 9.1(7)), report large cash transactions of CAD 10,000 or more to FINTRAC, and report terrorist property (Section 7). Section 12 requires beneficial ownership verification for corporations and trusts. The Office of the Superintendent of Financial Institutions (OSFI) and FINTRAC jointly administer AML obligations for federally regulated financial institutions, while provincial regulators administer compliance for their licensees. Violations may result in administrative monetary penalties under Part 1.1 or criminal prosecution under Part 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-pipeda-2000"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-pcmltfa-part-1-reporting-obligations-aml",
    "title": "Proceeds of Crime (Money Laundering) and Terrorist Financing Act, S.C. 2000, c. 17 - Interpretation",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the foundational definitions for key terms such as client, entity, money laundering offence, and terrorist activity financing offence, which are essential for interpreting compliance obligations throughout the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-40-recommendations-2023-consolidated",
      "basel-iii-capital"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-pest-control-products-act-2002",
    "title": "CA Pest Control Products Act 2002",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The Canadian Pest Control Products Act (PCPA) 2002 administered by Health Canada's Pest Management Regulatory Agency (PMRA) governs the import manufacture sale and use of pest control products (pesticides) in Canada. Active ingredients and products must be registered following risk assessment evaluating health and environmental risks. Re-evaluations are required for previously-registered active ingredients on a 15-year cycle. The Act mandates that risk to health or environment must be acceptable considering exposure scenarios for sensitive populations including aggregate and cumulative exposure to common mechanism groups.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-pipeda-2000",
    "title": "Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Canada's federal privacy law governing how private-sector organizations collect, use, and disclose personal information during commercial activities. The Act requires organizations to obtain an individual's consent for the collection, use, or disclosure of their personal information, as outlined in Schedule 1, Principle 4.3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-pipeda-schedule-1-privacy-principles",
    "title": "Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 - Part 1, Interpretation",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This act defines key terms governing the protection of personal information in the private sector, establishing foundational concepts for compliance, including the definition of a security breach which implies a requirement to establish security safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ca-pipeda-section-7-collection-without-consent",
    "title": "Personal Information Protection and Electronic Documents Act, Section 7",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations may collect, use, or disclose personal information without an individual's knowledge or consent only under specific, legally defined circumstances such as for investigations, emergencies, debt collection, or legal compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-privacy-act-public-sector",
    "title": "Canada Privacy Act - Collection, Use, Disclosure and Access for Government Institutions",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "Canada's Privacy Act (R.S.C. 1985, c. P-21) governs personal information held by federal government institutions. Section 4 bars collection unless the information relates directly to an operating program or activity; section 7 restricts use to the purpose for which the information was obtained or a consistent use; section 8 prohibits disclosure without consent except in enumerated circumstances; section 12(1) gives Canadian citizens and permanent residents a right of access to their own personal information; and section 53(1) provides for the Privacy Commissioner.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-qc-law25-2023",
    "title": "Quebec Law 25 - Modernisation de la Loi sur la protection des renseignements personnels dans le secteur privé (2021)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Quebec Law 25 (Loi 25 - La Loi modernisant des dispositions législatives en matière de protection des renseignements personnels) was enacted by the Assemblée nationale du Québec in September 2021 and amends both the Act respecting the protection of personal information in the private sector (Loi sur la protection des renseignements personnels dans le secteur privé, LPRPSP) and the Act respecting access to documents held by public bodies and the protection of personal information. Law 25 represents the most significant reform to Quebec's data protection framework since 1994 and introduces GDPR-equivalent obligations applicable to organisations processing personal data of Quebec residents. The law came into force in three successive phases: Phase 1 (22 September 2022) introduced mandatory privacy officer designation and incident reporting to the Commission d'accès à l'information (CAI); Phase 2 (22 September 2023) introduced rights of access, rectification, de-indexation, cessation of dissemination, and portability for individuals; and Phase 3 (22 September 2024) introduced privacy by default requirements. Key obligations include: designation of a Privacy Officer responsible for personal information protection; privacy impact assessments (PIAs) for personal information communicated outside Quebec; mandatory breach reporting to CAI within 72 hours and notification of affected individuals without delay; new consent requirements for sensitive information and for commercial prospecting; enhanced transparency requirements; the right to data portability; and administrative monetary penalties of up to $25,000,000 CAD or 4% of global annual turnover (whichever is greater). The Commission d'accès à l'information (CAI) is the regulatory authority. Quebec Law 25 applies in Quebec in addition to the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and its successor legislation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ca-qc-law25-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-adequacy-decisions-article-45",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ca-quarantine-act",
    "title": "Canada Quarantine Act - Communicable Disease Controls at Points of Entry",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "Canada's Quarantine Act (S.C. 2005, c. 20) aims to prevent the introduction and spread of communicable diseases. Section 15(2) requires a traveller who has reasonable grounds to suspect they have a listed communicable disease to disclose that fact to a screening or quarantine officer; section 16 allows isolation pending assessment; section 22 allows a quarantine officer to require a medical examination; and section 67(2) sets fines up to $1,000,000 or imprisonment up to three years for wilfully or recklessly causing a risk of death or serious bodily harm.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-species-at-risk-act-2002",
    "title": "CA Species at Risk Act 2002",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The Canadian Species at Risk Act (SARA) is the federal legislation providing for protection and recovery of species at risk of extinction including endangered threatened and special concern species. Listings are recommended by the Committee on the Status of Endangered Wildlife in Canada (COSEWIC) and decided by Cabinet on advice from the Minister. Listed species receive automatic protection on federal lands and in marine waters within Canada's jurisdiction; for terrestrial species on provincial lands the federal \"safety net\" provisions in Sections 34-36 apply if a province fails to provide effective protection. Recovery strategies action plans and management plans are required for listed species.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "ca-telecommunications-act-1993",
    "title": "Canada Telecommunications Act 1993",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2023-04-27",
    "bluf": "The Telecommunications Act (S.C. 1993, c. 38), in force 25 October 1993 and last amended by the Online Streaming Act 2023, establishes the CRTC's authority to regulate Canadian carriers and telecommunications services, requires that basic telecommunications services be available to all Canadians at affordable prices, prohibits unjust discrimination in service provision under Section 27, restricts direct foreign ownership of Canadian carrier facilities to 20% of voting shares under Section 16 and holding company ownership to 33.3% under Section 17 (with full foreign ownership permitted for carriers with less than 10% of Canadian telecom revenues), requires dominant carriers to file tariffs approved by the CRTC under Section 25, and provides the CRTC with powers to order interconnection, resolve disputes, and impose administrative monetary penalties of up to CAD 10 million per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ca-casl-2014",
        "ca-pipeda-2000",
        "ca-accessible-canada-act-2019"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-casl-2014",
      "ca-pipeda-2000",
      "ca-accessible-canada-act-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-tobacco-vaping-products-act",
    "title": "Canada Tobacco and Vaping Products Act - Youth Access, Promotion, Labelling and Penalties",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "Canada's Tobacco and Vaping Products Act (S.C. 1997, c. 13) regulates the manufacture, sale, labelling and promotion of tobacco and vaping products. Section 8(1) prohibits furnishing a tobacco or vaping product to a young person, defined in section 2 as a person under eighteen years of age; section 15 requires prescribed health information on packaging; section 19 prohibits promotion except as authorized; and section 45 sets a fine not exceeding $3,000 for a first sale-to-young-person offence and not exceeding $50,000 for a subsequent offence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-transportation-dangerous-goods-act-1992",
    "title": "Canada Transportation of Dangerous Goods Act 1992 - Safety Requirements, Marks, Containment and ERAP",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "Canada's Transportation of Dangerous Goods Act, 1992 (S.C. 1992, c. 34) governs the import, offering for transport, handling and transport of dangerous goods. Section 5 bars any of those activities unless the person complies with all applicable safety and security requirements; section 8 requires standardized means of containment to display applicable safety marks; section 7 requires an approved emergency response assistance plan for prescribed quantities; and section 33 sets fines up to $50,000 for a first offence on summary conviction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ca-treasury-board-contracting-policy-canadabuys-procurement",
    "title": "Canada Treasury Board Directive on the Management of Procurement + CanadaBuys Federal Procurement Platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Treasury Board of Canada Secretariat (TBS) Directive on the Management of Procurement (effective 13 May 2021, with subsequent amendments) is the principal procurement framework for federal departments and agencies under Schedule I, I.1, II, IV, and V of the Financial Administration Act (FAA). The Directive succeeded the prior Contracting Policy and the related contracting policy notices, consolidating the rules into an outcomes-focused directive supported by Treasury Board Standards including the Standard on Public Opinion Research, the Standard on Information Technology Architecture, and the various risk and reporting standards. The Directive is administered by the TBS Office of the Comptroller General and operationally delivered through Public Services and Procurement Canada (PSPC) as the central acquisitions organisation, with departmental procurement officers executing departmental acquisitions within delegated authorities. CanadaBuys at canadabuys.canada.ca is the central federal procurement platform launched in 2022 to replace the legacy Buyandsell.gc.ca system; CanadaBuys provides end-to-end electronic procurement including procurement notice publication, electronic bid submission, contract award notification, and integration with the Standing Offers and Supply Arrangements (SOSA) management. The framework intersects multiple trade agreement obligations including the WTO Agreement on Government Procurement (GPA 2012), the Canada-European Union Comprehensive Economic and Trade Agreement (CETA) government procurement chapter, the Comprehensive and Progressive Agreement for Trans-Pacific Partnership (CPTPP) government procurement chapter, the Canada-United States-Mexico Agreement (CUSMA, the renegotiated NAFTA) government procurement provisions, the Canadian Free Trade Agreement (CFTA) interprovincial procurement framework, and various bilateral free trade agreement procurement chapters. Procurement methods specified in the Directive and the supporting Standards include open competitive procurement (the default), selective competitive procurement (limited tender from a prequalified list), and non-competitive procurement (sole-source justified under one of the prescribed exceptions). The framework includes specific provisions for the Indigenous Business Directory (formerly Procurement Strategy for Aboriginal Business / PSAB) with the mandatory 5% federal procurement target from Indigenous businesses, the Build in Canada Innovation Program, the National Master Standing Offers and other consolidated procurement vehicles, and the Office of Small and Medium Enterprises (OSME) advocacy framework. Defence procurement is governed by the parallel Defence Procurement Strategy 2014 administered by PSPC with policy direction from the National Defence and the Treasury Board.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "canada-protected-b-cloud-security-profile-cccs-itsp-50-105",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "california-carb-advanced-clean-cars-ii",
    "title": "California CARB Advanced Clean Cars II (ACC II) - Zero-Emission Vehicle Mandate, PHEV Requirements, Battery Durability, Charging Standards and Data Tracking",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The CARB ACC II regulations mandate that by 2035, 100% of new light-duty vehicles sold in California must be Zero-Emission Vehicles (ZEVs) or Plug-in Hybrid Electric Vehicles (PHEVs).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-paris-agreement-ndc-implementation-guidelines",
      "iso-14001-ems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "california-ccpa-v2",
    "title": "CCPA/CPRA Enforcement",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The California Consumer Privacy Act (CCPA), as significantly enhanced by the California Privacy Rights Act (CPRA), provides comprehensive privacy rights to California residents. It introduces the CPPA (California Privacy Protection Agency) and grants the right to correct inaccurate data and limit use of sensitive personal information (SPI).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ccpa-cpra",
      "ccpa-cpra-optout-sale",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "california-cmia-health-data-2026",
    "title": "California Confidentiality of Medical Information Act (CMIA) - Civil Code §§ 56-56.245 (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The CMIA provides California-specific protections for medical information beyond HIPAA. It imposes strict consent requirements for disclosure, prohibits sale of medical information, requires breach notification within 15 days (or immediately if urgent), mandates reasonable security procedures, and creates private right of action with potential statutory damages. 2026 amendments strengthen genetic data protections and electronic disclosure rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-privacy-rule"
    ],
    "primary_citations_count": 3
  },
  {
    "node_id": "california-dmv-autonomous-vehicle-regulations",
    "title": "California DMV Autonomous Vehicle Regulations - Testing Permits, Driverless Testing, Deployment Permits, Manufacturer Obligations, Incident Reporting and Public Use Requirements",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires manufacturers to obtain permits from the California DMV to test or deploy autonomous vehicles on public roads, report disengagements annually, and file collision reports for any incident involving property damage, bodily injury, or death. Key obligations are defined in the Autonomous Vehicle Tester Program and Driverless Tester Program as administered by the DMV.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sae-j3016-levels-driving-automation-2021",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "iso-26262-functional-safety-road-vehicles-2018",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "california-telehealth-ccpa-2026",
    "title": "California Telehealth Requirements & CCPA Health Data Amendments 2026",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "California requires in-state licensure for physicians providing telehealth to CA patients. CCPA 2026 amendments strengthen protections for sensitive health data, including stricter consent for sharing, automated decision-making disclosures, and higher penalties for breaches involving PHI. Providers must maintain HIPAA + CCPA compliance for telehealth platforms, with explicit patient consent and data minimization rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-privacy-rule"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "can-spam-act-email",
    "title": "CAN-SPAM Act (Email)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003, commonly known as the CAN-SPAM Act, establishes national standards for sending commercial electronic mail. Compliance requires strict adherence to message content, sender identification, and consumer opt-out provisions. All commercial messages must contain a clear and conspicuous notice of the recipient's right to opt out of receiving future communications. Per this node's configuration, such unsubscribe requests must be processed within a 10-business-day window. Furthermore, communications must not feature deceptive subject lines or header information; both \"From\" and \"Reply-To\" fields must accurately represent the person or business initiating contact. The inclusion of a valid physical postal address for the sender is a mandatory data point for all outgoing commercial campaigns. It is also critical to distinguish between commercial messages, which have the primary purpose of advertising or promoting a product or service, versus transactional or relationship messages that facilitate an agreed-upon transaction. While certain requirements may differ, the core principles of truthfulness and transparency apply broadly. Failure to comply carries significant financial penalties for each separate email in violation of the federal statute. This node enforces these parameters to mitigate enterprise risk and ensure all email marketing activities align with established legal frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-digital-advertising-disclosures",
      "ftc-endorsement-guides",
      "gdpr-art-21-marketing-optout",
      "eprivacy-cookie-directive",
      "casl-anti-spam-canada",
      "ccpa-cpra-optout-sale"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-access-to-information-act",
    "title": "Canada Access to Information Act: Right of Access, Request and Notice Procedures, Time Limits, Mandatory Exemptions for Confidential, Personal and Third-Party Information, and Information Commissioner",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Canada Access to Information Act, R.S.C. 1985, c. A-1, is the principal Canadian statute providing a right of access to records under the control of federal government institutions and is administered by federal institutions subject to oversight by the Information Commissioner of Canada. Access to Information Act, section 2 states that the purpose of the Act is to enhance the accountability and transparency of federal institutions, including by providing a right of access to information in records under the control of a government institution with limited and specific exceptions. Access to Information Act, section 4 provides that every person who is a Canadian citizen or a permanent resident has a right to and shall, on request, be given access to any record under the control of a government institution. Access to Information Act, section 6 governs requests for access, which shall be made in writing to the government institution that has control of the record. Access to Information Act, section 7 requires the head of the institution to give written notice within thirty days as to whether or not access to the record will be given. Access to Information Act, section 8 governs the transfer of a request to another institution that has greater interest. Access to Information Act, section 9 governs extension of time limits. Access to Information Act, section 10 governs cases where access is refused, requiring the head to state the specific provision of the Act on which the refusal is based. Access to Information Act, section 13 requires refusal to disclose information obtained in confidence from foreign governments, provinces, municipalities, or aboriginal governments. Access to Information Act, section 19 requires refusal to disclose personal information subject to limited exceptions. Access to Information Act, section 20 requires refusal to disclose third-party trade secrets and confidential business information. Access to Information Act, section 30 establishes the role of the Information Commissioner of Canada in receiving and investigating complaints. Part 2 of the Act covers proactive publication of information. The Act is the controlling Canadian instrument for federal access-to-information compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-aeronautics-act",
    "title": "Canada Aeronautics Act (R.S.C. 1985, c. A-2): Aviation Regulation, Certification and Administrative Penalties",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Aeronautics Act (R.S.C. 1985, c. A-2) is the principal federal statute governing civil aviation in Canada, administered by the Minister of Transport through Transport Canada, with military aviation under the Minister of National Defence. Section 3 supplies the definitions, including aircraft (any machine capable of deriving support in the atmosphere from reactions of the air) and aerodrome. Section 4.2 sets out the powers, duties and functions of the Minister in respect of the development and regulation of aeronautics and the supervision of all matters connected with aeronautics, including constructing aerodromes, providing facilities, conducting research and investigating safety matters. Section 4.9 confers broad regulatory power on the Governor in Council to make regulations respecting aeronautics, including the accreditation and licensing of flight crew and maintenance personnel, the design and certification of aeronautical products, the operation and certification of aerodromes, airspace classification, aircraft noise, and accident investigation. Section 5.9 allows exemptions from regulations on terms and conditions where it is in the public interest and not likely to compromise aviation safety or security. Enforcement combines offences and an administrative monetary penalty scheme: section 7.3 prohibits false statements and related acts, sections 7.6 and 7.7 establish the designated-provisions administrative monetary penalty regime and the notice procedure, and section 8.4 sets the liability of the owner, operator and pilot in command. The Act is the legal foundation of Canadian aviation safety regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-ai-data-act-aida-bill-c-27",
    "title": "An Act to enact the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act and to make consequential and related amendments to other Acts (Bill C-27), Part 3: Artificial Intelligence and Data Act",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Bill C-27, Part 3 establishes the Artificial Intelligence and Data Act (AIDA), which imposes obligations on persons responsible for high-impact AI systems to assess and mitigate risks of harm and biased output, conduct algorithmic impact assessments, and comply with emergency orders for imminent harm, with administrative penalties of up to CAD 25 million or 3% of global revenue. It applies to developers and deployers of AI systems in international and interprovincial trade and commerce.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-voluntary-ai-safety-standard-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-aida-2022",
    "title": "Artificial Intelligence and Data Act (AIDA) - Bill C-27 Part 3 (2022)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-06-25",
    "bluf": "This Act requires persons responsible for high-impact AI systems in Canadian interprovincial or international trade to establish measures for risk identification and mitigation, monitoring, data anonymization, and public transparency. The core obligations, outlined in Part 1, Division 1, Sections 6-12, mandate a comprehensive risk management program for systems that could cause harm or biased output.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "nist-sp-1270-managing-ai-bias",
      "eu-ai-act-high-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "canada-aida-artificial-intelligence-data-act-c27",
    "title": "Artificial Intelligence and Data Act (AIDA) - Bill C-27 High-Impact AI System Obligations, Audits and ATIP Commissioner Role",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Canada's Artificial Intelligence and Data Act (AIDA), part of Bill C-27, mandates that persons responsible for a high-impact AI system must establish measures to identify, assess, and mitigate risks of harm or biased output, and publish a plain-language description of the system, as per Part 3, Sections 8-12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "canada-aida-2022",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "nist-sp-1270-managing-ai-bias",
      "eu-ai-act-high-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-anti-spam-legislation-casl-2014-pipeda",
    "title": "Canada Anti-Spam Legislation CASL 2014 - Commercial Electronic Message Consent, Unsubscribe Requirements and CRTC Enforcement",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Canada's Anti-Spam Legislation (CASL, S.C. 2010 c. 23, in force 1 July 2014) is one of the world's strictest anti-spam regimes, applying to Commercial Electronic Messages (CEMs) sent to or from Canada via email, SMS, instant message, and social media direct message; CASL requires prior express or implied consent before sending a CEM to a recipient in Canada; express consent requires a positive opt-in by the recipient (pre-ticked boxes are not valid); implied consent exists in limited circumstances including: an existing business relationship (purchase or contract within prior 24 months or inquiry within prior 6 months), conspicuous publication of an email address without a no-solicitation statement, or the recipient's disclosure of their address to the sender; CEMs must contain: the sender's name and contact information (including a mailing address and either a phone number, email, or web address), and an unsubscribe mechanism that must be honoured within 10 business days; the Canadian Radio-television and Telecommunications Commission (CRTC) is the primary enforcement authority and may impose Administrative Monetary Penalties (AMPs) up to CAD 1,000,000 per violation for individuals and up to CAD 10,000,000 per violation for corporations; CASL's private right of action provisions (allowing individuals to sue for CASL violations) were suspended by Order in Council in June 2017 pending further review and have not come into force as of 2026; CASL also prohibits: altering transmission data to misdirect messages (Section 7), installation of computer programs without consent (Section 8), and commercial electronic message harvesting (Section 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-casl-section-6-prohibition-commercial-messages"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-assisted-human-reproduction-act-2004",
    "title": "Assisted Human Reproduction Act",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Assisted Human Reproduction Act prohibits specific reproductive technologies and activities involving human cloning, chimeras, hybrids, and genetic modifications that can be transmitted to descendants. It applies to all persons in Canada engaging in assisted human reproduction procedures or related research, with key prohibitions outlined in Section 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-qms",
      "ich-gcp-e6-r3-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-bill-c26-critical-cyber-systems-2022",
    "title": "An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts - Part 2: Critical Cyber Systems Protection Act",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires operators of vital services or systems designated by the Governor in Council to establish and maintain cyber security programs, report cyber security incidents, mitigate supply-chain risks, and comply with cyber security directions. It applies to federally regulated private sector entities operating critical cyber systems under Part 2 of Bill C-26, specifically Section 8 and following.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-800-53-ac2",
      "c-scrm-practices-systems-organizations",
      "australia-essential-eight-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-broadcasting-act-1991",
    "title": "Canada Broadcasting Act (S.C. 1991, c. 11): Canadian Broadcasting Policy, CRTC Objects and Licensing, Regulations and Fees, Broadcasting Contrary to Act, and Continuation of the CBC",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Canada Broadcasting Act, S.C. 1991, c. 11, is the principal Canadian statute governing the Canadian broadcasting system and is administered by the Canadian Radio-television and Telecommunications Commission (CRTC), with the public broadcaster the Canadian Broadcasting Corporation continued under Part III. Broadcasting Act, section 2 contains the interpretation and key definitions used in the Act. Broadcasting Act, section 3 declares the broadcasting policy for Canada that the Canadian broadcasting system shall be effectively owned and controlled by Canadians, including elaborated policy objectives on programming, ownership, and cultural sovereignty. Broadcasting Act, section 5 sets the objects of the CRTC: subject to the Act and the Radiocommunication Act and to any directions to the Commission issued by the Governor in Council, the Commission shall regulate and supervise all aspects of the Canadian broadcasting system. Broadcasting Act, section 9 sets the CRTC's general licensing powers, including the establishment of classes of licences other than for online undertakings. Broadcasting Act, section 10 authorises the Commission, in furtherance of its objects, to make regulations on Canadian programs, advertising standards, political time allocation, network operations, dispute resolution, and related matters. Broadcasting Act, section 11 authorises regulations respecting licence fees with Treasury Board approval. Broadcasting Act, section 32 makes it an offence to contravene the prohibition on broadcasting contrary to the Act. Broadcasting Act, section 33 makes it an offence to contravene any regulation or order made under Part II. Broadcasting Act, section 35 sets the interpretation for Part III on the CBC. Broadcasting Act, section 36 continues the Canadian Broadcasting Corporation as a body corporate. Broadcasting Act, section 46 sets the objects and powers of the CBC to operate distinctly Canadian programming services as the national public broadcaster. The Act has been substantially amended by the Online Streaming Act of 2023 to bring online undertakings within the CRTC framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-broadcasting-act-online-streaming",
    "title": "Canada Broadcasting Act (as amended by the Online Streaming Act): Online Undertakings, Canadian Content and Discoverability",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Broadcasting Act (S.C. 1991, c. 11), as substantially amended by the Online Streaming Act (S.C. 2023, c. 8), governs the Canadian broadcasting system and, following the 2023 amendments, brings online undertakings (streaming services) within the jurisdiction of the Canadian Radio-television and Telecommunications Commission (CRTC). Section 3 sets the broadcasting policy for Canada, including that the system be effectively owned and controlled by Canadians, that it use radio frequencies that are public property, and that online undertakings clearly promote and recommend Canadian programming (section 3(1)(r)) and ensure the discoverability of Canadian programming services and original Canadian content (section 3(1)(q)). Section 2 defines 'broadcasting', 'broadcasting undertaking' (which now expressly includes an 'online undertaking') and 'online undertaking' (an undertaking for the transmission or retransmission of programs over the Internet for reception by the public). Section 5 charges the CRTC with regulating and supervising all aspects of the system and requires it to regulate in a flexible manner that accounts for the nature, diversity and size of services. Section 9.1 empowers the CRTC to make orders imposing conditions on broadcasting (including online) undertakings, including the proportion of programs that must be Canadian (section 9.1(1)(a)), the showcasing and discoverability of Canadian programs (section 9.1(1)(e)) and the provision of information about ownership, governance and control (section 9.1(1)(n)-(o)). Section 11.1 authorises regulations requiring expenditures to develop, finance, produce or promote Canadian programs, including a minimum share for original French-language programs (section 11.1(3)). Programs uploaded by users to a social media service are excluded from the Act, subject to exceptions (section 4.1). Compliance is backed by administrative monetary penalties (sections 34.4-34.6) and offences: broadcasting contrary to the Act carries fines of up to $25,000 per day for individuals and $250,000 per day for corporations (section 32), and contravening regulations or orders carries fines up to $25,000 (first) / $50,000 (subsequent) for individuals and $250,000 / $500,000 for corporations (section 33).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-canada-labour-code",
    "title": "Canada Labour Code (R.S.C. 1985, c. L-2): Industrial Relations, Occupational Health and Safety, and Labour Standards",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Canada Labour Code (R.S.C. 1985, c. L-2) governs labour relations, occupational health and safety, and employment standards for federally regulated workplaces, administered by the Canada Industrial Relations Board and the Labour Program of Employment and Social Development Canada. Section 2 supplies the definitions, including employee (which includes a dependent contractor), employer, trade union and the Board. Part I governs industrial relations: section 8 guarantees every employee the freedom to join the trade union of their choice and to participate in its lawful activities, section 36 gives a certified trade union the exclusive authority to bargain collectively on behalf of the bargaining unit, and section 89 sets the conditions that must be met before a lawful strike or lockout may occur. Part II governs occupational health and safety: section 124 imposes the general duty on the employer to ensure that the health and safety of every employee is protected, and section 128 confers the right of an employee to refuse dangerous work. Part III sets employment standards: section 169 sets the standard hours of work, section 174 governs overtime pay, and section 178 sets the minimum wage. The Code is the legal foundation of federal labour regulation in Canada across collective bargaining, workplace safety and minimum standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-canada-shipping-act-2001",
    "title": "Canada Shipping Act, 2001 (S.C. 2001, c. 26): Vessel Registration, Safety, Crewing and Pollution Prevention",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Canada Shipping Act, 2001 (S.C. 2001, c. 26) is the principal federal statute governing marine safety, vessel registration, crewing and the prevention of pollution from vessels in Canadian waters, administered chiefly by the Minister of Transport with marine-environment functions shared with the Minister of Fisheries and Oceans. Section 2 defines the core terms, including vessel (a boat, ship or craft designed, used or capable of being used solely or partly for navigation in, on, through or immediately above water), master (the person in command and charge of a vessel) and Canadian maritime document. Section 6 states the objectives of the Act, including protecting the health and well-being of persons, promoting safety in marine transportation, protecting the marine environment, and establishing an effective inspection and enforcement program. Section 9 makes the Minister of Transport responsible for the administration of the Act except as otherwise provided. Section 46 requires the registration of vessels that are not pleasure craft and are wholly owned by qualified persons. The Act regulates crewing and personnel and marine safety through its dedicated Parts, and Part 9 addresses pollution prevention, with section 187 prohibiting the discharge of a prescribed pollutant except in accordance with the regulations or a permit. Enforcement is direct: section 37 makes a contravention of specified provisions punishable on indictment by a fine of not more than 1,000,000 dollars or imprisonment for not more than 18 months, or both, section 38 applies the same scale to contraventions of the regulations, and section 40.1 applies a comparable penalty to contraventions of the environmental provisions. The Act is the legal foundation for Canadian vessel registration, marine safety and vessel-source pollution control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-canadian-agricultural-loans-act",
    "title": "Canada Canadian Agricultural Loans Act: Government Guarantee of Farm Loans and Farm Products Marketing Cooperative Loans",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Canadian Agricultural Loans Act (R.S.C. 1985, c. 25 (3rd Supp.)) establishes a federal loan-guarantee program that encourages lenders to extend credit to farmers and farm products marketing cooperatives by having the Minister of Agriculture and Agri-Food guarantee repayment of a portion of eligible loans, administered by Agriculture and Agri-Food Canada. Section 2 sets the definitions, including farmer, farming, farm products marketing cooperative, lender, loan and Minister. Section 3 applies the Act to loans made for the purposes set out in sections 4 or 6 and to losses sustained on such loans. Section 4 governs guaranteed farm loans: the Minister is liable to pay a lender the prescribed percentage (95 percent) of its loss on a loan made to a farmer for eligible purposes such as the purchase of equipment and livestock, the acquisition or improvement of land, the construction of buildings and the consolidation of debts, subject to conditions including a signed application, prescribed maximum principal amounts (an aggregate of 500,000 dollars, with a lower limit for certain purposes), prescribed repayment terms and security, and the lender exercising the same prudence as with an unguaranteed loan. Section 6 extends a comparable guarantee to loans made to farm products marketing cooperatives. Section 7 limits the Minister's aggregate liability, removing liability once the total principal of guaranteed loans registered in a fiscal year and the four preceding years exceeds the prescribed ceiling. Section 8 sets tiered loss-sharing limits for each lender, section 9 limits loss coverage by reference to a percentage of appraised value, and section 12 makes payment conditional on lender compliance and the payment of a prescribed loan-registration fee. The Act is the legal basis of the federal farm-credit guarantee that lowers the cost and risk of agricultural lending in Canada.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-canadian-dairy-commission-act",
    "title": "Canada Canadian Dairy Commission Act: Supply Management of Milk, Support Prices, Pooling and Levies",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Canadian Dairy Commission Act (R.S.C. 1985, c. C-15) establishes the federal Crown corporation that administers Canada's national supply management system for milk and cream, balancing producer returns against consumer supply, administered by the Canadian Dairy Commission. Section 3 continues the Canadian Dairy Commission as a corporation consisting of a Chairperson, a Chief Executive Officer and one other member. Section 8 sets the objects of the Commission: to provide efficient producers of milk and cream with the opportunity of obtaining a fair return for their labour and investment, and to provide consumers of dairy products with a continuous and adequate supply of dairy products of high quality. Section 9 confers the powers of the Commission, including to purchase and sell dairy products, to package, process, store and ship them, to import and export them, to make payments to producers in support of their income, to establish prices, and under section 9(1)(f) to establish and operate a pool or pools in respect of the marketing of milk or cream and to distribute the proceeds to producers. Section 12 empowers the Governor in Council to make regulations, including in respect of quota-based marketing, licensing requirements and the collection of levies. Section 15 establishes the Canadian Dairy Commission Account, a special account credited with the Commission's revenues, licence fees, levies, loans and payments under the Farm Income Protection Act. The Act is the legal backbone of Canadian dairy supply management: the mechanism by which national production quotas, support prices and pooled revenues sustain the dairy sector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-canadian-net-zero-emissions-accountability-act",
    "title": "Canada Canadian Net-Zero Emissions Accountability Act: The 2050 Net-Zero Target, Milestone Targets and the Accountability Cycle",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Canadian Net-Zero Emissions Accountability Act (S.C. 2021, c. 22) establishes a legislated framework requiring Canada to achieve net-zero greenhouse-gas emissions by 2050 and binds the federal government to a recurring cycle of targets, plans and reports, administered by the Minister of the Environment. Section 4 sets the purpose: to require the setting of national greenhouse-gas emissions targets based on the best scientific information and to promote transparency and accountability in achieving them. Section 5 designates the Minister of the Environment as the Minister responsible. Section 6 fixes the long-term target, providing that the national greenhouse-gas emissions target for 2050 is net-zero emissions. Section 7 requires the Minister to set national emissions targets for the milestone years 2030, 2035, 2040 and 2045, within the deadlines specified. Sections 9 and 10 require an emissions reduction plan for each target and prescribe its contents, including the target, the key measures and a description of relevant sectoral strategies. Section 14 requires a progress report on each plan no later than two years before the relevant milestone year, and section 15 requires an assessment report after each milestone year, within 30 days of Canada submitting its official greenhouse-gas inventory, stating whether the target was met and, if not, the reasons and the corrective measures. Section 20 establishes the Net-Zero Advisory Body to provide independent advice, and section 24 requires the Commissioner of the Environment and Sustainable Development to examine and report at least once every five years on the implementation of measures aimed at mitigating climate change. The Act is the statutory accountability spine of Canadian climate policy: it does not itself price or cap emissions but locks in the target-plan-report-assess discipline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-casl-sc-2010-c23-commercial-electronic-messages-consent",
    "title": "Canada CASL (An Act to promote the efficiency and adaptability of the Canadian economy) - SC 2010, c. 23 Commercial Electronic Message Consent Requirements",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "CASL (SC 2010, c. 23) requires express or implied consent before sending commercial electronic messages (CEMs - email, SMS, social media messages) to Canadian electronic addresses. Express consent is the gold standard; implied consent exists for existing business/non-business relationships. Mandatory identification and unsubscribe mechanism in every CEM. Administrative Monetary Penalties up to CAD 10M per violation for organisations; CRTC enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "canada-pipeda-sc-2000-c5-personal-information-protection"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-cepa-1999-new-substances-biotechnology-notification",
    "title": "Canada CEPA 1999 New Substances Notification - Biotechnology Living Organisms, ECCC Dual Assessment and Risk Management",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Canadian Environmental Protection Act 1999 (CEPA 1999, S.C. 1999, c. 33) Part 6 (New Substances) requires notification to the Government of Canada before manufacturing or importing any substance (including living organisms) not listed on the Domestic Substances List (DSL); the New Substances Notification (NSN) Regulations (Organisms) SOR/2005-248 apply specifically to all living organisms including bacteria, fungi, viruses, microorganisms, plants (non-domestic), animals, and genetically modified organisms (GMOs) for non-contained use; Environment and Climate Change Canada (ECCC) and Health Canada conduct a dual assessment of each notified organism for environmental and human health risk; assessment timelines range from 45 to 120 days depending on the notification schedule; if no risk assessment objection is raised within the assessment period, the substance may be manufactured or imported; the Minister can impose Ministerial Conditions or prohibit the substance if risk is identified; repeat notifiers and substances found toxic may have Significant New Activity (SNAc) notices applied under CEPA 1999 Sections 80-88; penalties for failing to notify before manufacture or import of a new organism: up to CAD 5 million per day under CEPA 1999 Section 272.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "canada-clean-electricity-regulations-2035",
    "title": "Clean Electricity Regulations",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "These regulations require electricity-generating units with a capacity of 25 MW or more to meet a carbon dioxide emissions intensity performance standard of 30 tonnes of CO2 per gigawatt-hour (GWh) starting January 1, 2035. This applies to units that are part of a system subject to the Canada-wide Industrial Greenhouse Gas Emissions Reporting Program, aiming to achieve a net-zero electricity grid.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "canada-clinical-trials-division-5-c02-262",
    "title": "Food and Drug Regulations PART B Foods (continued) DIVISION 26 Food Irradiation",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation prohibits the sale of irradiated food in Canada unless specifically authorized under B.26.003(2) and listed in the Table, with compliance to specified radiation type, source, and absorbed dose limits. It applies to manufacturers and importers of irradiated foods who must maintain records per B.26.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "canada-food-drug-regulations-division-5-clinical-trials"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-competition-act-2024-amendment-abuse-dominance",
    "title": "Competition Act, R.S.C. 1985, c. C-34 - Abuse of Dominance Provisions as Amended by Bill C-56 (2023) and Bill C-59 (2024)",
    "domain": "Competition & Antitrust",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Prohibits dominant firms from engaging in anti-competitive acts that prevent or lessen competition substantially in a market. Following the Bill C-56 (2023) and Bill C-59 (2024) amendments, administrative monetary penalties for abuse of dominance are the greater of $25 million for a first order ($35 million for each subsequent order), or three times the value of the benefit derived from the anti-competitive practice, or - where that value cannot be reasonably determined - 3 percent of the firm's annual worldwide gross revenues. Affected private parties may seek leave from the Competition Tribunal to bring an abuse-of-dominance application under Section 103.1. Applies to any person or entity with substantial or complete control over a market under Section 79(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeepers",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-competition-act-misleading-advertising-2024",
    "title": "Canada Competition Act Misleading Advertising 2024 - Drip Pricing Prohibition, Greenwashing Claims Enforcement (Section 74.01), Deceptive Reviews, Expanded Class Action for Misleading Conduct and CRTC/Competition Bureau Joint Action on Telemarketing",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation prohibits deceptive marketing practices under Section 74.01 of the Competition Act, including drip pricing, unsubstantiated environmental claims (greenwashing), and fake reviews. It applies to all businesses engaged in commercial advertising in Canada and mandates substantiation of claims with adequate and proper testing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-digital-advertising-disclosures",
      "eu-unfair-commercial-practices-2005-29",
      "casl-anti-spam-canada"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-controlled-goods-program-cgp-2001",
    "title": "Defence Production Act - Controlled Goods Regulations: Registration, Security Assessments, Designated Official Responsibilities, Examination Rights, and Exemptions for Allied Governments",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The Canada Controlled Goods Program (CGP) requires all companies and individuals in Canada that access, possess, or transfer controlled goods (as defined in the Defence Production Act and Schedule to the Controlled Goods Regulations) to register with the Controlled Goods Program and comply with security assessment requirements. The Designated Official (DO) within each registered organization must ensure compliance, facilitate examinations, and maintain records under Section 13 of the Controlled Goods Regulations (SOR/2001-319).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "as9100-rev-d-qms",
      "iso-27017-cloud-defence",
      "nist-800-171-cui"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-copyright-act-2012-digital-amendments",
    "title": "Copyright Modernization Act: Internet Service Provider Safe Harbours, Notice-and-Notice Regime, Technological Protection Measures, New Fair Dealing Categories (Education, Parody, Satire) and Private Copying Exemption",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a notice-and-notice regime for Internet Service Providers (ISPs) regarding alleged copyright infringement, provides safe harbours for ISPs, prohibits circumvention of technological protection measures, and expands fair dealing exceptions to include education, parody, and satire under Section 2.4 and related provisions of the Copyright Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dmca-safe-harbor",
      "copyright-fair-use-us",
      "berne-convention-1886-2024-literary-artistic-works"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-criminal-code-part-vi-invasion-of-privacy",
    "title": "Canada Criminal Code Part VI (Invasion of Privacy): Definitions of Private Communication and Intercept, Interception Offence, Bodily Harm and Exceptional Circumstances Exceptions, Judicial Authorisation, and Disclosure Restrictions",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Part VI of the Canadian Criminal Code, R.S.C. 1985, c. C-46, titled Invasion of Privacy, is the principal federal framework governing the interception of private communications in Canada, including wiretapping and electronic surveillance, and is enforced by federal, provincial, and municipal authorities with judicial oversight by superior courts. Criminal Code, section 183 contains the foundational definitions including private communication as any oral communication or any telecommunication made by persons who are in different places, and intercept as any action taken to seize or record such communications without authorisation. Criminal Code, section 184 creates the central offence of wilfully intercepting a private communication by means of any electro-magnetic, acoustic, mechanical or other device, subject to specified exceptions including authorisation by a judge. Criminal Code, section 184.1 permits interception with the consent of a party where the agent reasonably believes there is a risk of bodily harm to that party. Criminal Code, section 184.4 permits interception in exceptional circumstances where a peace officer believes on reasonable grounds that the urgency of the situation is such that an authorisation could not, with reasonable diligence, be obtained. Criminal Code, section 185 governs the application for authorisation. Criminal Code, section 186 sets the conditions for the judge to be satisfied before granting authorisation, including that the authorisation is in the best interests of the administration of justice and that other investigative procedures have been tried and failed, are unlikely to succeed, or that the urgency of the matter makes them impractical. Criminal Code, section 188 governs authorisations in emergencies through judges specially designated by the Chief Justice. Criminal Code, section 193 makes it an offence to disclose information obtained from intercepted private communications. The Part is the controlling Canadian federal instrument for lawful interception of private communications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-criminal-code-part-vii-gaming-betting",
    "title": "Canada Criminal Code Part VII (Disorderly Houses, Gaming and Betting): Common Gaming House, Betting and Book-making, Lottery Schemes, and Provincial Lottery Exemption",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Part VII of the Canadian Criminal Code, R.S.C. 1985, c. C-46, titled Disorderly Houses, Gaming and Betting, is the principal federal criminal framework regulating gaming and betting conduct in Canada and is enforced by federal, provincial, and municipal authorities. Criminal Code, section 197 contains the interpretation including foundational definitions of common gaming house and disorderly house. Criminal Code, section 201 creates the offence of keeping a common gaming house or common betting house. Criminal Code, section 202 creates offences relating to betting, pool-selling, book-making, and related conduct, including placing pool tickets. Criminal Code, section 203 creates the offence of placing bets on behalf of others. Criminal Code, section 204 provides an exemption for pari-mutuel wagering under the Race Tracks Supervision Regulations. Criminal Code, section 206 creates offences in relation to lotteries and games of chance, prohibiting unauthorised lottery schemes. Criminal Code, section 207 provides the central exemption: provincial lottery schemes conducted and managed by a province under provincial authority are not subject to the prohibitions, making lawful provincial casinos, lotteries, and gaming. Criminal Code, section 207.1 provides an exemption for international cruise ship lottery schemes. The Part operates alongside provincial gaming legislation (such as the Ontario Gaming Control Act 1992, the Alberta Gaming, Liquor and Cannabis Act, and equivalent legislation in other provinces) which licence and supervise lawful gaming under the section 207 exemption. The Part is the controlling federal criminal instrument for gaming and betting conduct in Canada.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-crtc-net-neutrality-isp-traffic-mgmt-2017",
    "title": "Framework for Assessing the Differential Pricing Practices of Internet Service Providers",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes a framework under subsection 27(2) of the Telecommunications Act for evaluating whether an Internet service provider's differential pricing practice, such as zero-rating or data discounting, constitutes unjust discrimination or undue preference. It applies to all ISPs offering retail Internet access services in Canada.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-net-neutrality-open-internet-2015-2120"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-customs-act",
    "title": "Canada Customs Act: Report of Goods, Liability for Duties, Release and Accounting, Determination and Re-determination of Value/Origin/Classification, Appeals to CITT, and False Statement Offence",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Canada Customs Act, R.S.C. 1985, c. 1 (2nd Supp.), is the principal Canadian statute governing the importation and exportation of goods across the Canadian customs frontier and is administered by the Canada Border Services Agency in coordination with the Canada Revenue Agency. Customs Act, section 12 requires that all goods that are imported shall, except in such circumstances and subject to such conditions as may be prescribed, be reported at the nearest customs office designated for that purpose. Customs Act, section 17 provides that imported goods are charged with duties thereon from the time of importation thereof until such time as the duties are paid or the charge is otherwise removed. Customs Act, section 18 provides that for the purposes of liability for duties reported, all goods reported under section 12 shall be deemed to have been imported. Customs Act, section 32 provides that subject to subsections (2) and (4), no goods shall be released until they have been accounted for by the importer or owner of the goods in the prescribed manner and all duties thereon have been paid. Customs Act, section 35 governs refund of duties. The Act sets out a valuation, origin, and tariff classification regime in sections 47 and following, with re-determination procedures in section 60 and appeals to the Canadian International Trade Tribunal in section 67. Customs Act, section 124 establishes civil monetary penalties under the Administrative Monetary Penalty System and Customs Act, section 153 creates the offence of false statement. The Act, together with the Customs Tariff Act and the Special Import Measures Act, is the controlling Canadian instrument for cross-border trade compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-defence-production-act",
    "title": "Canada Defence Production Act (R.S.C. 1985, c. D-1): Interpretation, Powers and Duties of the Minister, Acquisition of Defence Supplies, the Controlled Goods Program, Registration and Examination, Prohibited Activities, and Offences",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Defence Production Act, R.S.C. 1985, c. D-1, is the principal Canadian statute providing for the acquisition of defence supplies and the operation of the Controlled Goods Program restricting access to controlled goods including military and dual-use items, and is administered by the Minister of Public Services and Procurement Canada through the Controlled Goods Directorate. Defence Production Act, section 2 contains the interpretation provisions including the definitions of defence supplies (including arms, ammunition, equipment for Canada's defence) and defence projects (including buildings, aerodromes, military works, and production facilities). Defence Production Act, section 10 confers powers and duties on the Minister including exclusive authority to acquire defence supplies and to construct defence projects required for the Department of National Defence. Defence Production Act, section 16 confers procurement powers to buy, manufacture, construct, and dispose of defence supplies and projects. Defence Production Act, section 24 governs cost assessment and permits the Minister to review contracts and reduce compensation if costs exceed fair and reasonable amounts. Defence Production Act, section 35 defines controlled goods by reference to the Schedule. Defence Production Act, section 36 governs exemptions including for federal public administration employees and prescribed classes. Defence Production Act, section 37 governs prohibited activities and prohibits examining or possessing controlled goods without registration or exemption. Defence Production Act, section 45 sets offences and punishment, including fines up to two million dollars and imprisonment up to ten years for indictable offences. The Act is the controlling Canadian instrument for defence procurement and the Controlled Goods Program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-directive-automated-decision-making-2021",
    "title": "Directive on Automated Decision-Making",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This directive requires federal departments to assess, document, and publicly disclose the algorithmic impact of automated decision systems used in administrative decisions, ensuring transparency, human oversight, and compliance with procedural fairness. It applies to all automated decision systems developed or procured after April 1, 2020, under Section 5.1 and 6.1.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "australia-ai-ethics-framework-2019",
      "nist-ai-100-4-redteam"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-employment-equity-act-1995",
    "title": "Employment Equity Act, S.C. 1995, c. 44",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Employment Equity Act requires federally regulated employers with 100 or more employees to identify and eliminate employment barriers for designated groups-women, Aboriginal peoples, persons with disabilities, and members of visible minorities-and implement employment equity plans to achieve representation reflective of the Canadian workforce. Key obligations are defined under Section 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-fair-work-act-2009",
      "eeoc-employment-rule",
      "cipd-hr-standards"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-environmental-protection-act-1999",
    "title": "Canada Environmental Protection Act, 1999 (CEPA): Toxic Substances, Pollution Prevention and Offences",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Canadian Environmental Protection Act, 1999 (CEPA, S.C. 1999, c. 33) is Canada's principal federal pollution-prevention and toxic-substances statute, administered jointly by the Minister of the Environment and the Minister of Health. Section 64 sets the core test: a substance is toxic if it is entering or may enter the environment in a quantity or concentration or under conditions that have or may have an immediate or long-term harmful effect on the environment or its biological diversity, that constitute or may constitute a danger to the environment on which life depends, or that constitute or may constitute a danger in Canada to human life or health. Part 5 governs the assessment and management of substances, and substances found toxic are added to the List of Toxic Substances in Schedule 1 for control. Section 56 empowers the Minister to require any person to prepare and implement a pollution prevention plan in respect of a specified substance or group of substances on the List of Toxic Substances. The Act also requires the reporting of, and remedial measures for, unauthorized releases of toxic substances, and Part 8 requires environmental emergency plans for prescribed substances. Enforcement is set out in Part 10. Section 272 creates offences for contravening the Act, failing to comply with obligations, conditions, interim orders or directions, and providing false or misleading information, and prescribes a graduated penalty regime with statutory minimum and maximum fines that escalate by offender type and by whether the conviction is on summary conviction or on indictment. For an individual on indictment the fine is not less than $15,000 and not more than $1,000,000 or imprisonment for up to three years for a first offence; for a corporation (other persons) on indictment the fine is not less than $500,000 and not more than $6,000,000 for a first offence; and for a small-revenue corporation on indictment the fine is not less than $75,000 and not more than $4,000,000 for a first offence, with higher amounts for subsequent offences. CEPA is the foundational instrument an organization operating in Canada must map for chemicals management, releases and environmental emergencies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-environmental-protection-act-1999-eccc",
    "title": "Canada Environmental Protection Act 1999 - CEPA Toxic Substances and GHG Reporting Framework",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The Canadian Environmental Protection Act 1999 (CEPA 1999, S.C. 1999, c. 33) is Canada's primary federal environmental statute governing toxic substances, pollution prevention, greenhouse gas emissions reporting and environmental emergencies. Environment and Climate Change Canada (ECCC) and Health Canada jointly administer the Act. The Domestic Substances List (DSL) and New Substances Notification program control chemical risk. Substances can be assessed as toxic under CEPA and added to the Toxic Substances List (Schedule 1) triggering risk management regulations. The Greenhouse Gas Reporting Program (GHGRP) under CEPA requires annual GHG reporting from facilities above 10,000 tonnes CO2e. CEPA was significantly amended in 2023 (Bill S-5) to include the right to a healthy environment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "canada-estma-extractive-sector-transparency-measures-act",
    "title": "Canada ESTMA - Extractive Sector Transparency Measures Act Payments to Governments Reporting",
    "domain": "Mining & Natural Resources",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Canada's ESTMA requires extractive companies (mining, oil and gas) listed on Canadian stock exchange or operating in Canada to publicly disclose payments to domestic and foreign governments above CAD 100,000 - covering taxes, royalties, fees, dividends, bonuses, and infrastructure improvements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-explosives-act",
    "title": "Canada Explosives Act (R.S.C. 1985, c. E-17): Licensing of Explosives Manufacture, Storage and Penalties",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Explosives Act (R.S.C. 1985, c. E-17) regulates the manufacture, storage, sale, transport, importation and possession of explosives in Canada, administered by Natural Resources Canada through the Chief Inspector of Explosives. Section 2 defines explosive as anything that is made, manufactured or used to produce an explosion, a detonation or a pyrotechnic effect. Section 5 authorizes the Governor in Council to make regulations classifying explosives, prescribing safety standards, and controlling acquisition, possession, importation and exportation. Section 6 sets the core prohibitions: explosives may be manufactured only in a licensed factory, stored only in a licensed magazine, and sold or possessed only as authorized, and the processing of explosives is limited to licensed factories. Section 7 empowers the Minister to issue factory and magazine licences, permits for vehicles transporting explosives, and certificates for occasional explosive-related activities. The offence and penalty provisions are graduated: section 20 (acts likely to cause an explosion) and section 21 (unauthorized possession or manufacture) are each punishable on summary conviction by a fine of up to 250,000 dollars or two years imprisonment, and on indictment by a fine of up to 500,000 dollars or five years imprisonment, while section 22 (general contraventions) carries a fine of up to 50,000 dollars for a first offence and up to 100,000 dollars for a subsequent offence. The Act is the legal foundation of Canadian explosives safety and licensing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-export-import-permits-act-eipa",
    "title": "Canada Export and Import Permits Act (EIPA): Export Control List, Import Control List, Area Control List, Permits, and Prohibition on Unauthorized Export",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Canada Export and Import Permits Act, R.S.C. 1985, c. E-19, commonly cited as EIPA, is the principal Canadian statute governing the control of exports and imports of designated goods and technology. Section 3 authorises the Governor in Council to establish an Export Control List for purposes including ensuring that arms and strategic goods are not made available to destinations where their use would be detrimental to the security of Canada, supporting domestic processing of certain natural resources, maintaining supply adequacy, implementing intergovernmental arrangements or commitments, and collecting information relating to trade investigations. Section 5 authorises an Import Control List for purposes including ensuring supply adequacy, supporting agricultural programs, restricting the importation of arms, implementing dairy and agricultural policies, fulfilling intergovernmental commitments, and preventing circumvention of textile agreements. Section 6 authorises the Governor in Council to revoke, amend, vary or re-establish any Area Control List, Automatic Firearms Country Control List, Brokering Control List, Export Control List or Import Control List. Section 7 authorises the Minister to issue export permits to residents of Canada for controlled goods and technology, subject to specified quantities, qualities, recipients and conditions, and general permits applicable to all residents. Section 8 authorises issuance of import permits to residents of Canada for controlled goods, in specified quantities and under defined terms. Section 11 provides that holding a permit does not exempt the holder from obtaining other required licences or paying applicable taxes and duties under other laws. Section 13 sets out the central prohibition: no person shall export or transfer, or attempt to export or transfer, any goods or technology included in an Export Control List except under the authority of and in accordance with an export permit. EIPA is the controlling instrument for Canadian export and import controls under trade compliance law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-farm-debt-mediation-act",
    "title": "Canada Farm Debt Mediation Act: Stay of Proceedings, Financial Review and Mediation for Insolvent Farmers",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Farm Debt Mediation Act (S.C. 1997, c. 21) provides a federal mediation process between insolvent farmers and their creditors, giving farmers in financial difficulty a structured opportunity to reach a mutually acceptable arrangement before secured creditors enforce their remedies, administered by Agriculture and Agri-Food Canada through appointed administrators. Section 5 allows a farmer to apply to an administrator for either a stay of proceedings against all creditors together with a review of the farmer's financial affairs and mediation with all creditors, or for a review and mediation with secured creditors only. Section 6 limits eligibility to farmers who are unable to meet obligations as they generally become due, who have ceased paying current obligations in the ordinary course, or the aggregate of whose property is insufficient to pay all debts. Section 7 requires the administrator, on a completed application for a stay, to issue forthwith a stay of proceedings for a period of 30 days binding all creditors, and section 13 permits extension of that stay for a maximum of three further periods of thirty days each where essential to formulating an arrangement. Section 9 requires a detailed review of the farmer's financial affairs, section 10 provides for the appointment of an unbiased mediator free from conflict of interest, and section 16 provides for the appointment of a guardian of the farmer's assets on issuance of a stay. Section 21 requires every secured creditor intending to enforce a remedy against a farmer to give the farmer at least 15 business days' written notice of that intention. Section 27 makes contravention of the Act or regulations an offence punishable on summary conviction by a fine not exceeding fifty thousand dollars or imprisonment for a term not exceeding six months, or both. The Act is the principal federal safeguard that pauses creditor enforcement and brings a neutral mediator to the table to keep viable Canadian farms operating.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-farm-products-agencies-act",
    "title": "Canada Farm Products Agencies Act: National Farm Products Council, Marketing and Promotion-Research Agencies",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Farm Products Agencies Act (R.S.C., 1985, c. F-4) is the federal statute under which Canada regulates the orderly marketing and the promotion and research of farm products in interprovincial and export trade, administered through the National Farm Products Council and the Minister of Agriculture and Agri-Food. The Act establishes the National Farm Products Council to advise the Minister and to supervise the agencies created under the Act, with the object of promoting a strong, efficient and competitive agriculture and agri-food industry. Part II authorizes the establishment of marketing agencies, each operating under a marketing plan that may provide for the regulation of marketing, the fixing and allocation of quotas, and the imposition of levies or charges on the regulated product. Part III authorizes the establishment of promotion-research agencies empowered to promote the marketing and production of a farm product and to conduct or fund research, funded by levies on the product. The Act provides for inspection and enforcement: section 35(1) makes it an offence to obstruct or hinder an inspector engaged in carrying out their duties, and section 35(2) makes it an offence to knowingly make a false or misleading statement to an inspector. The penalty provisions impose summary-conviction liability for contraventions of the Act, a marketing plan, Council requirements, or agency orders and regulations: under section 37 (marketing agencies) a person who contravenes is guilty of an offence punishable on summary conviction by a fine not exceeding five thousand dollars, and under section 45 (promotion-research agencies) a person who contravenes is likewise liable on summary conviction to a fine not exceeding five thousand dollars, with a one-year limitation period for the commencement of a prosecution. The Act is the governing instrument for any producer, processor or dealer subject to a federal marketing plan or a promotion-research levy on a regulated farm product.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-feeds-act",
    "title": "Canada Feeds Act: Registration, Standards and Safety of Livestock Feeds",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Feeds Act (R.S.C. 1985, c. F-9) regulates the manufacture, sale and import of livestock feeds in Canada, administered by the Canadian Food Inspection Agency (CFIA). Section 2 defines 'feed' (a substance or mixture of substances containing amino acids, anti-oxidants, carbohydrates, condiments, enzymes, fats, minerals, non-protein nitrogen products, proteins or vitamins, manufactured, sold or represented for consumption by livestock, for their nutritional requirements, or for preventing or correcting nutritional disorders), 'sell' (including to agree to sell, offer or expose for sale, possess for sale or distribute), 'package' and 'label'. Section 3 sets the core prohibition: no person shall manufacture, sell or import a feed unless it has been approved by the Minister or registered in accordance with the regulations, conforms to prescribed standards, and is packaged and labelled in accordance with the regulations; section 3(3) further prohibits manufacturing, selling, importing or exporting a feed that presents a risk of harm to human or animal health or the environment. The Governor in Council may make regulations respecting applications, registration, approval, standards, packaging, labelling, sampling and analysis (section 5). Inspectors may enter any place, open packages, examine feed and take samples, and require the production of records, shipping bills and documents (sections 6-7); section 8 prohibits obstructing or hindering an inspector and making false or misleading statements. Inspectors may seize articles where a contravention is suspected, and on conviction or a finding of violation the articles may be forfeited to His Majesty (section 9). Offences are punishable on summary conviction by a fine not exceeding $50,000 or imprisonment for up to six months, or both, and on indictment by a fine not exceeding $250,000 or imprisonment for up to two years, or both (section 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-fertilizers-act",
    "title": "Canada Fertilizers Act: Standards, Safety and Labelling of Fertilizers and Supplements",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Fertilizers Act (R.S.C. 1985, c. F-10) regulates the sale and import of fertilizers and supplements in Canada, administered by the Canadian Food Inspection Agency (CFIA). Section 2 defines 'fertilizer' (any substance or mixture of substances containing nitrogen, phosphorus, potassium or other plant food, manufactured, sold or represented for use as a plant nutrient), 'supplement' (a substance other than a fertilizer manufactured, sold or represented for use in the improvement of the physical condition of soils or to aid plant growth or crop yield), 'sell' (including to offer or expose for sale, possess for sale and distribute) and 'label'. Section 3 sets the core prohibition: no person shall sell or import into Canada any fertilizer or supplement unless it has been approved by the Minister or registered in accordance with the regulations, conforms to prescribed standards, and is packaged and labelled in accordance with the regulations. Section 4 prohibits selling any fertilizer or supplement that contains destructive ingredients or properties harmful to plant growth when used according to directions. The Governor in Council may make regulations on registration, standards, packaging and labelling (section 5). Inspectors may enter any place, open packages, examine the article, take samples and remove things for examination (sections 6-7); section 8 prohibits obstructing or hindering an inspector and making false or misleading statements. Inspectors may seize articles where they believe on reasonable grounds that the Act or regulations have been contravened (section 9). Offences are punishable on summary conviction by a fine not exceeding $50,000 or imprisonment for up to six months, or both, and on indictment by a fine not exceeding $250,000 or imprisonment for up to two years, or both (section 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-fisheries-act-habitat-protection",
    "title": "Canada Fisheries Act: Fish and Fish Habitat Protection and the Deleterious-Substance Prohibition",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Fisheries Act (R.S.C. 1985, c. F-14), as substantially amended in 2019, is Canada's principal federal statute for the management of fisheries and the conservation and protection of fish and fish habitat, administered by the Department of Fisheries and Oceans (DFO) with Environment and Climate Change Canada enforcing the pollution-prevention provisions. Section 2.1 states the purpose of providing a framework for the proper management and control of fisheries and the conservation and protection of fish and fish habitat. Section 2 defines 'fish' (including parts of fish, shellfish, crustaceans, marine animals and their eggs, sperm, spawn and larvae), 'fish habitat' (water frequented by fish and areas on which fish depend to carry out their life processes), 'deleterious substance', and 'Indigenous peoples of Canada'. Section 34.4(1) prohibits carrying on any work, undertaking or activity, other than fishing, that results in the death of fish, and section 35(1) prohibits any that results in the harmful alteration, disruption or destruction of fish habitat (HADD), unless authorized by the Minister or conducted under the regulations (sections 34.4(2), 35(2)). Section 36(3) prohibits depositing a deleterious substance in water frequented by fish. In decision-making the Minister may consider the sustainability of fisheries, scientific information, the Indigenous knowledge of the Indigenous peoples of Canada and community knowledge (section 2.5), and must consider the factors in section 34.1 when exercising habitat powers. Persons must notify an inspector without delay of an unauthorized death of fish or deposit and take all reasonable corrective measures (section 38), failing which an inspector may act at the person's expense. The Act provides for ecologically significant areas (section 35.2) and time-limited fisheries management orders not exceeding 45 days (sections 9.1 and 9.3). Inspectors and fishery officers have inspection, search and seizure powers (sections 38(3) and 39). Offences are punishable under section 40 by significant minimum and maximum fines and imprisonment - for an individual on indictment, not less than $15,000 and not more than $1,000,000 for a first offence - with higher ranges for corporations and subsequent offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-food-drug-regulations-division-5-clinical-trials",
    "title": "Food and Drug Regulations Part C Division 5 - Clinical Trials",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires clinical trial sponsors to submit a Clinical Trial Application (CTA) to Health Canada, as outlined in Section C.05.005 of the Food and Drug Regulations, and to comply with the requirements for protocol amendments, safety reporting, and final study reports.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-gcp-e6-r3-2023",
      "iso-13485-qms"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-food-inspection-agency-act",
    "title": "Canada Food Inspection Agency Act: Establishment, Mandate and Enforcement of Federal Food, Animal and Plant Statutes",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Canadian Food Inspection Agency Act (S.C. 1997, c. 6) establishes the Canadian Food Inspection Agency (CFIA) and makes it the federal body responsible for administering and enforcing Canada's food safety, animal health and plant protection legislation. Section 3 establishes the Agency as a body corporate that may exercise powers only as an agent of His Majesty in right of Canada. Section 4(1) provides that the Minister is responsible for and has the overall direction of the Agency, a role held by the Minister of Agriculture and Agri-Food. Section 6(1) makes the President the chief executive officer of the Agency with supervision over and direction of its work and staff, and section 7 permits the President to delegate powers and duties. Section 11(1) charges the Agency with the enforcement and administration of a defined set of statutes: the Agriculture and Agri-Food Administrative Monetary Penalties Act, the Feeds Act, the Fertilizers Act, the Health of Animals Act, the Plant Breeders' Rights Act, the Plant Protection Act, the Safe Food for Canadians Act and the Seeds Act; and section 11(3) gives the Agency responsibility for the Food and Drugs Act as it relates to food. Section 13(3) authorizes the President to designate inspectors, analysts, graders, veterinary inspectors and other officers for the enforcement or administration of that legislation. The Act is the constitutional charter of the CFIA and the single point from which Canada's farm-gate-to-table inspection, import controls and disease and pest response are administered.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-grain-act",
    "title": "Canada Grain Act: Grain Quality Standards, Elevator Licensing and Producer Protection",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Canada Grain Act (R.S.C. 1985, c. G-10) establishes the Canadian Grain Commission and the framework for grain quality assurance and grain handling, operated in the interests of grain producers. Section 13 sets the Commission's objects: in the interests of producers, to establish and maintain standards of quality for Canadian grain and to regulate grain handling in Canada to ensure a dependable commodity for domestic and export markets. Section 2 defines 'grain' (any seed designated by regulation as a grain for the purposes of the Act), 'elevator' (premises for receiving and discharging grain from railway cars or ships), 'licensee' (a person holding a licence to operate an elevator or to carry on business as a grain dealer) and 'grade'. The Commission, established under section 3 with three commissioners, may by regulation establish grades, grade names and specifications for western and eastern grain (section 16). Section 42 establishes classes of licence and section 44 prohibits operating an elevator or carrying on business as a grain dealer without a licence, subject to specified exemptions. Licensees must issue elevator receipts or grain receipts and provide security having regard to their potential obligations to producers for payment or delivery of grain (section 45), which underpins the producer payment protection regime. The Commission provides for the official inspection and weighing of grain, and inspectors issue certificates assigning grades after inspection (sections 29 and 32). Prohibitions, offences and punishment are set out in the Act (sections 102-108), supporting enforcement of the quality, licensing and producer-protection requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-greenhouse-gas-pollution-pricing-act",
    "title": "Canada Greenhouse Gas Pollution Pricing Act: Federal Carbon Backstop, Fuel Charge and Output-Based Pricing System",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Greenhouse Gas Pollution Pricing Act (S.C. 2018, c. 12, s. 186) establishes Canada's federal carbon-pricing backstop, applying a price on greenhouse-gas emissions in provinces and areas that do not have an equivalent system of their own, administered by the Canada Revenue Agency (Part 1) and the Department of Environment (Part 2). Part 1 imposes the fuel charge: section 3 defines fuel broadly to include gasoline, diesel, natural gas, propane and coal listed in Schedule 2, the charge applies when fuel is produced, delivered or brought into a listed province, and section 40 fixes the amount by the formula A times B (quantity times the applicable rate), with the listed provinces set out in Schedule 1 and the rates in Schedule 2. Division 4 (sections 55 to 67) imposes registration obligations on distributors, importers, carriers, emitters and users, section 69 requires returns for each reporting period and section 71 requires payment of the positive net charge to the Receiver General. Part 2 establishes the output-based pricing system for industry: section 169 prices industrial greenhouse-gas emissions, section 171 requires registration of covered facilities with the Minister of the Environment, section 173 imposes the excess-emissions charge (again by a formula of excess emissions times the applicable rate) on facilities exceeding their benchmark, and section 185 establishes the compliance-unit tracking system. The Governor in Council lists the provinces to which the federal system applies, which is the legal mechanism of the backstop, applying the federal price wherever a province's own scheme does not meet the federal stringency benchmark. Offence and penalty provisions appear in Part 1 (including section 132) and Part 2 (including section 232 and the sentencing provisions). The Act is the constitutional backbone of carbon pricing in Canada and the instrument that gives the federal price its national reach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-health-of-animals-act",
    "title": "Canada Health of Animals Act: Disease Notification, Import/Export Controls and Quarantine Powers",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Health of Animals Act (R.S.C. 1985, c. 21 (4th Supp.)) is Canada's primary federal statute for protecting animal health and preventing the spread of diseases and toxic substances that affect animals or are transmissible to humans, administered by the Canadian Food Inspection Agency (CFIA). Section 2 defines 'animal' (including an embryo and a fertilized egg or ovum), 'disease', 'toxic substance' and 'inspector'. The Act imposes a mandatory duty under section 5 on any owner or person in possession or care of an animal, and on veterinarians and laboratory operators, to notify the nearest veterinary inspector immediately upon becoming aware of, or suspecting, the presence of a reportable disease or toxic substance. It prohibits concealing the existence of a reportable disease (section 8), and turning out, keeping or grazing an animal known to be affected or contaminated by a reportable disease (section 9). Diseased animals may not be taken to market or sold/transferred except under a licence issued by an inspector (sections 10-11). Importation is controlled by regulation (section 14); imported animals and things must be presented to an inspector, officer or customs officer (section 16), with non-compliant imports forfeited to His Majesty (section 17) or ordered removed or disposed of (section 18). Export of animals by vessel or aircraft requires prior notice and a veterinary inspector's certificate that prescribed requirements are met (section 19). Inspectors may declare a place infected (section 22), declare land within five kilometres infected (section 23), and prohibit movement into or out of an infected place without a licence (section 25); the Minister may establish a primary control zone with movement permits (section 27) and take all reasonable measures to remedy a dangerous condition (section 27.4). Inspector powers include entry, inspection, sampling, and seizure and detention (sections 38-44), with dwelling-houses protected by a consent or warrant requirement (section 39). The Minister may order disposal or destruction of diseased animals (section 48) and must pay compensation equal to the animal's market value minus the value of its carcass, subject to a regulatory maximum (section 51). Offences are punishable on summary conviction by a fine up to $50,000 or six months' imprisonment, and on indictment by a fine up to $250,000 or two years' imprisonment (sections 65-66).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-igaming-ontario-gaming-control-act-1992",
    "title": "Canada iGaming Ontario - Gaming Control Act 1992 and Online Market Framework",
    "domain": "Gaming & Gambling",
    "version": "2.3",
    "last_updated": "2026-05-10",
    "bluf": "Ontario's iGaming market, launched 4 April 2022 under the authority of the Gaming Control Act 1992 (GCA) and the iGaming Ontario (iGO) framework, is Canada's largest regulated online gambling market. iGaming Ontario (iGO) is a subsidiary of the Ontario Lottery and Gaming Corporation (OLG) that manages the commercial internet gaming market as the single Operator of Record. Private operators partner with iGO through the Operator Agreement, gaining access to the Ontario market under AGCO (Alcohol and Gaming Commission of Ontario) registration. As of 2024 over 50 operators are live. Operators must register with AGCO as Internet Gaming Operators under Registrar's Standards for Internet Gaming. Players may self-exclude through the GameSense self-exclusion programme. Criminal Code of Canada s.207(1)(a) authorises province-run and licensed online gambling; s.206 prohibits all other online gambling in Canada.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "pipeda",
        "aml",
        "fatf_recommendation",
        "criminal_code",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "canada-impact-assessment-act",
    "title": "Canada Impact Assessment Act: Designated Projects, the Section 7 Prohibition and the Public-Interest Decision",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Impact Assessment Act (S.C. 2019, c. 28, s. 1) establishes Canada's federal impact-assessment regime for major projects, administered by the Impact Assessment Agency of Canada. Section 6 sets out the purposes, including to prevent or mitigate significant adverse effects within federal jurisdiction, to foster sustainability, to respect the rights of the Indigenous peoples of Canada and to apply the precautionary principle. A designated project is a physical activity carried out in Canada or on federal lands that is prescribed by regulation or designated by ministerial order under section 9. Section 7 imposes the central prohibition: the proponent of a designated project must not do any act or thing that may cause an adverse effect within federal jurisdiction unless the Agency decides no impact assessment is required, the proponent complies with the conditions in a decision statement, or the Agency permits the act for the purpose of gathering information. The process runs through a planning phase (the initial project description under section 10, public participation under section 11, the Agency's offer to consult under section 12, and the Agency decision on whether an assessment is required under section 16) and then an impact assessment conducted by the Agency (sections 24 to 35) or referred to a review panel (sections 36 to 59). After the assessment, the public-interest decision is made: under section 60 the Minister (or Governor in Council) determines whether the adverse effects within federal jurisdiction are in the public interest, and section 65 requires the issuance of a decision statement setting out the determination and any conditions, without which federal authorities may not authorise or fund the project. Enforcement is provided through analysts and enforcement officers (section 120), notices of non-compliance (section 126) and orders (section 127), with offence provisions from section 142. The Act is the gateway that decides whether Canada's largest resource, energy and infrastructure projects may proceed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-impact-assessment-act-2019-major-projects",
    "title": "Canada Impact Assessment Act 2019 (IAA) - Federal Major Project Review and Environmental Assessment",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Canada's Impact Assessment Act (IAA, S.C. 2019, c. 28, s. 1, as amended by the Online Streaming Act 2023 and following the Supreme Court of Canada 2023 reference opinion requiring amendments to provincial jurisdiction provisions) establishes the federal impact assessment process administered by the Impact Assessment Agency of Canada (IAAC) for designated physical activities (major projects) listed in the Physical Activities Regulations (SOR/2019-285). The IAA requires comprehensive assessment of environmental, social, health, and economic impacts before federal approval of major mining, pipeline, nuclear, transmission, and offshore projects in Canada.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "undrip-free-prior-informed-consent-mining"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "canada-impact-assessment-act-2019-mining",
    "title": "Impact Assessment Act",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Impact Assessment Act requires federal impact assessments for designated mining projects carried out on federal lands or supported by federal authorities, with a focus on preventing or mitigating significant adverse effects within federal jurisdiction as defined in section 2. Compliance is triggered under subsection 9(1) and section 109(b) for designated projects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-26000-social-resp"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-international-river-improvements-act",
    "title": "Canada International River Improvements Act: Licensing of Works on Rivers Flowing Out of Canada",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The International River Improvements Act (R.S.C. 1985, c. I-20) controls the construction, operation and maintenance of works that alter the flow of rivers flowing from Canada to places outside Canada, administered by Environment and Climate Change Canada under the Governor in Council. Section 2 contains the key definitions: an international river is water flowing from any place in Canada to any place outside Canada, and an international river improvement is a dam, obstruction, canal, reservoir, pipeline or other work the purpose or effect of which is to increase, decrease or otherwise alter the natural flow of an international river and thereby affect its use outside Canada. Section 3 empowers the Governor in Council to make regulations respecting the construction, operation, maintenance and licensing of international river improvements. Section 4 imposes the central prohibition: except in accordance with a licence issued under the Act, no person shall construct, operate or maintain an international river improvement. Section 13 confers inspection powers on enforcement officers, who may enter and inspect places at reasonable times, subject to warrant requirements for dwellings. The enforcement provisions in sections 33 and 34 set out the offences for contravening the Act, with tiered penalties for individuals and corporations, and sections 35 to 50 provide continuing-offence rules, sentencing principles and court orders. The Act is the legal instrument by which Canada manages the international consequences of altering transboundary rivers and meets the obligations that flow from the Boundary Waters Treaty and related arrangements with the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-investment-canada-act",
    "title": "Canada Investment Canada Act: Net Benefit to Canada Review of Foreign Investment, Reviewable Investments, Notification, Section 25.1 National Security Review, and Offences",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Investment Canada Act, R.S.C. 1985, c. 28 (1st Supp.), is the principal Canadian statute governing the review of significant foreign investments in Canada and is administered by the Minister of Innovation, Science and Industry through the Investment Review Division, with national security review additional functions of the Minister of Public Safety and Emergency Preparedness. Investment Canada Act, section 2 sets the purposes of the Act: recognizing that increased capital and technology benefits Canada, and recognizing the importance of protecting national security, the purposes of this Act are to provide for the review of significant investments in Canada by non-Canadians. Investment Canada Act, section 3 contains the definitions including Canadian, non-Canadian, entity, voting interest, and state-owned enterprise. Investment Canada Act, section 14 lists the reviewable investments including investments to acquire control of a Canadian business where the limits set out in subsection (3) apply. Investment Canada Act, section 16 imposes the prohibition: a non-Canadian shall not implement an investment reviewable under this Part unless the investment has been reviewed and the Minister is satisfied or is deemed to be satisfied that the investment is likely to be of net benefit to Canada. Investment Canada Act, section 17 requires the non-Canadian to file an application with the Director in the manner prescribed. Investment Canada Act, section 21 sets the net benefit decision timeline: the Minister shall, within 45 days after the certified date referred to in subsection 18(1), send a notice that the investment is likely to be of net benefit to Canada. Investment Canada Act, section 25.1 sets the national security review scope on grounds of injury to national security. Investment Canada Act, section 25.3 governs national security review by the Governor in Council where the Minister considers an investment could be injurious to national security. Investment Canada Act, section 35 contains the regulation-making power. Investment Canada Act, section 39 sets the offences and punishment for violations of prohibitions and failure to comply with orders. Standard threshold for review is CAD $5 million in asset value with elevated thresholds for WTO Investors (CAD $1 billion) and Trade Agreement Investors (CAD $1.5 billion), each indexed annually for inflation. The Act is the controlling Canadian instrument for the review of significant foreign investment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-irpa-immigration-refugee-protection-act-2001",
    "title": "Canada Immigration and Refugee Protection Act 2001 - IRCC and CBSA Framework",
    "domain": "Immigration & Border Control",
    "version": "2.8",
    "last_updated": "2026-05-10",
    "bluf": "The Immigration and Refugee Protection Act (IRPA, SC 2001 c.27) is Canada's primary immigration statute, governing all classes of immigration (economic, family, refugee), admissibility determinations, the Express Entry points-based system, and refugee protection. Section 38 bars admission of persons who are or who will be a danger to public health; section 34 bars inadmissibility on security grounds. Sponsored refugees receive permanent residence on arrival. Under section 117-118, human smuggling carries a maximum of life imprisonment. CBSA enforces the Act at ports of entry while IRCC manages the domestic immigration programme. Non-compliance with reporting conditions under section 98 may result in loss of permanent residence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_article",
        "fatf_recommendation",
        "icao_doc",
        "five_eyes",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "canada-justice-victims-corrupt-foreign-officials-act",
    "title": "Canada Justice for Victims of Corrupt Foreign Officials Act (Sergei Magnitsky Law) (S.C. 2017, c. 21): Interpretation, Orders and Regulations, Prohibitions on Dealings, Duty to Determine, Disclosure Obligations, Rights of Foreign Nationals, and Offences",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Justice for Victims of Corrupt Foreign Officials Act (Sergei Magnitsky Law), S.C. 2017, c. 21, received Royal Assent on 18 October 2017 and is the principal Canadian statute providing for restrictive measures in respect of foreign nationals responsible for gross violations of internationally recognized human rights and acts of significant corruption, and is administered by the Minister of Foreign Affairs in coordination with the Minister of Public Safety and Emergency Preparedness. Justice for Victims of Corrupt Foreign Officials Act, section 2 contains the interpretation provisions including the definitions of foreign national, foreign public official, property, and other essential terms. Justice for Victims of Corrupt Foreign Officials Act, section 4 authorizes the Governor in Council to make orders and regulations imposing restrictions on dealings with property and financial activities related to designated individuals. Justice for Victims of Corrupt Foreign Officials Act, section 5 sets out the prohibitions on dealings with property of designated foreign nationals. Justice for Victims of Corrupt Foreign Officials Act, section 6 imposes the duty on financial institutions and regulated entities to determine whether they are in possession or control of property belonging to a sanctioned foreign national. Justice for Victims of Corrupt Foreign Officials Act, section 7 mandates disclosure of identified property to the relevant supervising agencies without delay, and once every three months. Justice for Victims of Corrupt Foreign Officials Act, section 8 permits affected individuals to apply to the Minister to cease being subject to sanctions orders. Justice for Victims of Corrupt Foreign Officials Act, section 11 establishes the offences and punishment for knowingly contravening orders. The Act operates alongside the Special Economic Measures Act and the Immigration and Refugee Protection Act, which it amended.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-metal-mining-effluent-regulations",
    "title": "Metal and Diamond Mining Effluent Regulations",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "These regulations establish effluent quality standards, monitoring requirements, and environmental effects monitoring for metal and diamond mining operations in Canada, as required under the Fisheries Act, Section 36(3). They apply to all mine sites that discharge effluent into water frequented by fish.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "canada-impact-assessment-act-2019-mining",
      "canada-national-instrument-43-101",
      "ifc-performance-standards-2012-mining",
      "gistm-global-tailings-management-standard-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-migratory-birds-convention-act-1994",
    "title": "Canada Migratory Birds Convention Act 1994: Protection, Permits and Harmful-Deposit Prohibition",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Migratory Birds Convention Act, 1994 (S.C. 1994, c. 22) implements Canada's obligations under the Migratory Birds Convention with the United States and is administered by Environment and Climate Change Canada (ECCC). Section 4 states its purpose: to protect and conserve migratory birds - as populations and as individual birds - and their nests. Section 2 defines 'migratory bird' (including sperm, eggs, embryos, tissue cultures and parts of the bird) and 'deposit' (discharging, spraying, releasing, spilling, leaking, seeping, pouring, emitting, emptying, throwing, dumping or placing). Section 5 prohibits, without lawful excuse, possessing a migratory bird or nest, and buying, selling, exchanging or otherwise dealing in migratory birds or nests except as authorized under the regulations. Section 5.1 prohibits depositing, or permitting the deposit of, a substance that is harmful to migratory birds in waters or areas frequented by them. The Governor in Council may make regulations granting permits and setting bag limits, hunting seasons and possession rules (section 12). Game officers have the powers of a peace officer, including arrest, and may inspect places, examine data systems, seize things and board vessels in Canadian waters or the exclusive economic zone (sections 6-7); vessels may be detained where a section 5.1 offence is suspected (section 8.1); seized things are forfeited to His Majesty where ownership cannot be ascertained within 30 days (section 9) and disposed of as the Minister directs (section 10). Compliance-order procedures allow officers to direct persons to cease a contravention or take remedial measures (sections 11.21-11.29). Offences carry substantial penalties under section 13: for an individual on indictment, a minimum $15,000 and maximum $1,000,000 (and up to three years' imprisonment) for a first offence; for other persons (such as corporations) on indictment, a minimum $500,000 and maximum $6,000,000 for a first offence, with higher minimums and maximums for subsequent offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-motor-vehicle-safety-act",
    "title": "Canada Motor Vehicle Safety Act: Standards Conformity, National Safety Mark and Recalls",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Motor Vehicle Safety Act (S.C. 1993, c. 16) regulates the manufacture and importation of motor vehicles and motor vehicle equipment to reduce the risk of death, injury and damage to property and the environment, administered by Transport Canada. Section 2 sets the purpose and defines 'vehicle' (a vehicle capable of being driven or drawn on roads other than by muscular power alone), 'national safety mark' (a prescribed expression, symbol or abbreviation) and 'prescribed' (by regulations under section 11). Section 3 prohibits using a national safety mark except as authorized by the Act. Section 5(1) prohibits a company from applying a national safety mark to, selling, or importing vehicles or equipment of a prescribed class unless they conform to the standards prescribed for that class at the time the main assembly of the vehicle was completed, the prescribed information is marked, and prescribed records and (for equipment) a purchaser registration system are maintained. Section 6 prohibits importing a prescribed-class vehicle unless the requirements of paragraphs 5(1)(a), (b), (d) and (e) are satisfied. On becoming aware of a defect in design, construction or functioning that affects or is likely to affect safety, or of a non-compliance, a company must give notice to the Minister and to current owners within the prescribed period (section 10); the Minister may order a company to correct a defect or non-compliance where it is in the interest of safety (section 10.5). Inspectors may enter places, examine, test, remove and seize vehicles, equipment or components (sections 14-15). Offences are punishable under section 17: a corporation is liable to a fine of up to $200,000 on summary conviction and up to $2,000,000 on indictment; an individual is liable to a fine of up to $4,000 or six months on summary conviction and up to $20,000 or two years on indictment. The Governor in Council may make regulations carrying out the Act (section 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-motor-vehicle-safety-act-1985-cmvss",
    "title": "Canada Motor Vehicle Safety Act 1985 - CMVSS Type Approval, Defect Investigation and Transport Canada Recall Obligations",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "The Canada Motor Vehicle Safety Act R.S.C. 1985 c. M-10.01 (MVSA) and the Motor Vehicle Safety Regulations SOR/94-693 (MVSR) establish Canada's mandatory safety standards regime for motor vehicles and associated equipment; Transport Canada administers the regime through its Motor Vehicle Safety directorate; the MVSR prescribes the Canadian Motor Vehicle Safety Standards (CMVSS) - a set of minimum technical safety requirements that every vehicle must meet before it can be sold in Canada; manufacturers and importers are required to issue a Declaration of Compliance (DoC) affirming that each vehicle conforms to all applicable CMVSS; the MVSA creates a mandatory defect investigation and recall regime: manufacturers must notify Transport Canada within 5 days of forming a reasonable belief that a vehicle has a defect constituting an unreasonable risk to safety; Transport Canada may conduct an independent defect investigation and order a mandatory recall if the manufacturer fails to act; the Act was substantially amended by the Making Canadians Safer Act (S.C. 2014 c. 20) which expanded defect investigation powers, introduced administrative monetary penalties up to CAD 200,000 per day, and added provisions for autonomous vehicle (AV) testing exemptions; Canada's vehicle safety standards are closely harmonised with US Federal Motor Vehicle Safety Standards (FMVSS) but are not identical - importers must ensure compliance with CMVSS rather than FMVSS for Canadian market vehicles; the Registrar of Imported Vehicles (RIV) programme administers vehicle importation from the United States under the 15-year vintage exemption rule.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fmvss-federal-motor-vehicle-safety-standards"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-national-building-code-2020",
    "title": "National Building Code of Canada 2020 (NBC 2020)",
    "domain": "Construction & Real Estate",
    "version": "2020 (6th Edition)",
    "last_updated": "2026-05-09",
    "bluf": "The National Building Code of Canada 2020 (NBC 2020) is the model building code developed by the National Research Council Canada (NRC) that sets minimum technical requirements for the design, construction, and occupancy of new buildings and additions across Canada; it addresses structural safety, fire protection, building services, energy efficiency, and accessibility across five parts (Compliance, General Requirements, Fire Protection/Occupant Safety, Structural Design, Environmental Separation, Building Services), and is adopted with provincial/territorial amendments as the legally enforced building code in all Canadian jurisdictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-19650-bim-information-management-construction",
      "breeam-2018-building-assessment-method"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-national-energy-regulator-cer-act-2019",
    "title": "Canada National Energy Regulator Act 2019 - Pipeline Certification, Tolls Regulation and Indigenous Consultation",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Canada's Canadian Energy Regulator Act (S.C. 2019, c. 28, s. 10), which replaced the National Energy Board Act, established the Canadian Energy Regulator (CER) as the federal regulator for interprovincial and international pipelines, power lines, and offshore renewable energy; requires Certificate of Public Convenience and Necessity (CPCN) or Leave to Open before constructing or operating a regulated pipeline; mandates a safety management system (SMS) and pipeline integrity management program under CSA Z662; imposes Indigenous consultation obligations as a condition of regulatory approval; and grants CER enforcement powers including facility shutdown orders and penalties up to CAD 100,000 per day.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brazil-aneel-electricity-sector-regulation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "canada-national-instrument-43-101",
    "title": "Canadian National Instrument 43-101 - Standards of Disclosure for Mineral Projects",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "NI 43-101 mandates that all public disclosures of scientific and technical information related to mineral projects in Canada must be prepared or supervised by a Qualified Person (QP) as defined under Section 1.2. It applies to issuers engaged in mineral exploration, development, or production activities disclosing information in Canada or to Canadian markets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-national-marine-conservation-areas-act",
    "title": "Canada National Marine Conservation Areas Act: Establishment, Management Plans and the Prohibition on Hydrocarbon and Mineral Exploitation",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Canada National Marine Conservation Areas Act (S.C. 2002, c. 18) provides for the establishment and management of a system of national marine conservation areas representative of Canada's oceans and Great Lakes, administered by Parks Canada under the Minister responsible for the Parks Canada Agency. Section 4 establishes marine conservation areas and sets the purpose of protecting and conserving representative marine areas for the benefit, education and enjoyment of the people of Canada and the world, managed on a sustainable-use basis, and provides for zones including zones that foster and encourage ecologically sustainable use and zones that fully protect special features or sensitive elements of ecosystems. Section 5 governs the establishment or enlargement of an area by adding land to a schedule. Section 9 requires the Minister to prepare a management plan for each area within a set period, addressing ecosystem protection, zoning and visitor use, and to review it at least every five years. The Act imposes core prohibitions: section 12 bars the disposition or use of public lands in an area without authority, section 13 prohibits any person from exploring for or exploiting hydrocarbons, minerals, aggregates or any other inorganic matter within a marine conservation area, and section 14 controls the disposal of substances. Section 15 provides for permits and authorizations. Enforcement runs through marine conservation area wardens designated under section 18 and enforcement officers designated under section 19, with the offence provisions in section 24 and the sentencing principles in section 24.7. The Act is the instrument that places representative ocean and Great Lakes areas under permanent protection while permanently closing them to oil, gas and mineral extraction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-national-parks-act",
    "title": "Canada National Parks Act: Ecological Integrity, Land Protection and Wildlife Offences",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Canada National Parks Act (S.C. 2000, c. 32) governs the establishment, protection and management of Canada's national parks, administered by the Parks Canada Agency. Section 4(1) dedicates the national parks to the people of Canada for their benefit, education and enjoyment, and requires that they be maintained and made use of so as to leave them unimpaired for future generations; section 8(2) provides that the maintenance or restoration of ecological integrity, through the protection of natural resources and natural processes, shall be the first priority of the Minister in park management. Section 2 defines 'ecological integrity' (a condition characteristic of the natural region, including abiotic components and the composition and abundance of native species and biological communities) and 'park' (a park named in Schedule 1). Section 11 requires a management plan within five years of a park's establishment, tabled in Parliament with ecological integrity objectives and indicators, and reviewed at least every ten years. Section 13 prohibits the disposal of, and unauthorized use or occupation of, public lands in a park, and section 16 confers the regulation-making power over preservation, protection of flora and fauna, fishing, fire prevention and the control of development. Section 25 prohibits trafficking in wild animals or plants taken in or from a park, and section 26 prohibits hunting, trafficking in or possessing wildlife species listed in Schedule 3. Park wardens designated under section 18 are peace officers who may arrest without warrant (section 21) and enter, search and seize (section 22). Offences under section 24 carry, for an individual, a fine of not less than $5,000 and not more than $300,000 on summary conviction (first offence) and not less than $15,000 and not more than $1,000,000 on indictment, with higher amounts for subsequent offences and specific ranges for trafficking (section 25) and protected-wildlife (section 26) offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-natural-health-products-regulations-2003-nhpr",
    "title": "Canada Natural Health Products Regulations 2003 - NPN Product Licence, GMP Site Licence and Health Canada Compliance",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Canada's Natural Health Products Regulations SOR/2003-196 (NHPR, in force January 1, 2004, under the Food and Drugs Act R.S.C. 1985 c. F-27) created a comprehensive licensing regime for natural health products (NHPs) including vitamins, minerals, herbal remedies, homeopathic medicines, traditional medicines, probiotics, and amino acids; every NHP sold in Canada must hold a Natural Product Number (NPN) or a Homeopathic Medicine Number (DIN-HM) granted by Health Canada's Natural and Non-prescription Health Products Directorate (NNHPD); market authorisation requires safety and efficacy evidence from pharmacopoeias, traditional use data, or clinical studies; manufacturers, packagers, labellers, and importers must hold a Site Licence (SL) and comply with GMP standards in Schedule 2 of the NHPR; adverse reaction reports must be filed with Health Canada within 15 days (serious unexpected) and 30 days (serious expected); label must bear NPN number, recommended use, recommended dose, risk information, storage conditions, and lot number; Health Canada may issue compliance orders, seize products, and require recalls for non-compliance; 2023 amendments under Bill S-5 (Strengthening Environmental Protection for a Healthier Canada Act) introduced new NHP oversight provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-food-drugs-act-1985"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "canada-navigable-waters-act",
    "title": "Canadian Navigable Waters Act: Approval of Works, Obstructions and Protection of Navigation",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Canadian Navigable Waters Act (R.S.C. 1985, c. N-22), formerly the Navigation Protection Act, protects the public right of navigation on navigable waters, administered by Transport Canada. Section 2 defines 'navigable water' (a body of water used, or where there is a reasonable likelihood that it will be used, by vessels for transport or travel) and 'work' (any structure, device or other thing made by humans, and any dumping of fill, excavation or dredging in navigable water). Section 3 sets the core prohibition: it is prohibited to construct, place, alter, rebuild, remove or decommission a work in, on, over, under, through or across any navigable water except in accordance with the Act. Minor works may proceed under section 4 in accordance with the Act's requirements, works that will not interfere with navigation may proceed on notice (section 4.1), and major works and works in scheduled navigable waters require approval (sections 5 and 7). Section 13 empowers the Minister to order the repair, alteration or removal of a work that interferes, or is likely to interfere, with navigation or causes a serious and imminent danger to navigation. The Act prohibits depositing sawdust and like rubbish liable to interfere with navigation (section 21), depositing stone, gravel, earth, cinders, ashes or other material in navigable waters of insufficient depth (section 22), and dewatering that would extinguish navigation (section 23). A person who creates an obstruction must give immediate notice, mark it with signals or lights and begin its removal diligently (section 15), and wrecks are addressed in section 16. Designated persons may enter and inspect places where a regulated activity is conducted (section 34), and owners must give all reasonable assistance (section 35). Offences are punishable under section 40 - for an individual on summary conviction, up to $100,000 for a first offence and up to $200,000 or six months for a subsequent offence; for a corporation, up to $500,000 (first) - and administrative monetary penalties up to $50,000 for an individual and $250,000 for others (section 39.1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-nuclear-safety-and-control-act",
    "title": "Canada Nuclear Safety and Control Act (S.C. 1997, c. 9): CNSC Licensing, Prohibitions and Penalties",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Nuclear Safety and Control Act (S.C. 1997, c. 9) is the federal statute governing the development, production and use of nuclear energy and the possession and use of nuclear substances in Canada, administered by the Canadian Nuclear Safety Commission (CNSC). Section 2 supplies the definitions, including nuclear substance (including deuterium, thorium, uranium, elements with an atomic number greater than 92, and prescribed radioactive nuclides) and nuclear facility (including reactors, particle accelerators and uranium or thorium mines). Section 3 states the purpose of limiting to a reasonable level the risks to national security, the health and safety of persons, and the environment associated with nuclear energy. Section 8 establishes the CNSC as a body corporate, and section 9 sets its objects, including preventing unreasonable risk to the environment, to health and safety, and to national security, and implementing Canada's international obligations. Licensing is mandatory: section 24 empowers the Commission to issue, renew, suspend, amend or revoke licences, and section 26 prohibits any person, except in accordance with a licence, from possessing, transferring, importing, exporting, using or abandoning a nuclear substance. Section 44 authorizes regulations governing nuclear activities, radiation doses and worker protection. Enforcement is direct: section 48 sets out the offences and section 51 provides the penalties, with a summary conviction punishable by a fine of up to 500,000 dollars or 18 months imprisonment, and an indictable offence punishable by a fine of up to 1,000,000 dollars or 5 years imprisonment. The Act is the legal foundation of Canadian nuclear regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-oceans-act",
    "title": "Canada Oceans Act: Maritime Zones, Integrated Management and Marine Protected Areas",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Oceans Act (S.C. 1996, c. 31) establishes Canada's maritime zones in domestic law and gives the Minister of Fisheries and Oceans the lead role in the integrated management and conservation of Canada's estuarine, coastal and marine waters. Section 4 provides that the territorial sea of Canada is a belt of sea whose outer limit is 12 nautical miles from the nearest point of the baselines. Section 13 establishes the exclusive economic zone as the area beyond and adjacent to the territorial sea extending to 200 nautical miles from the nearest point of the baselines, within which Canada exercises sovereign rights over living and non-living resources. Section 17 defines the continental shelf as the seabed and subsoil of the submarine areas that extend throughout the natural prolongation of Canada's land territory to the outer edge of the continental margin or to 200 nautical miles where the margin does not extend that far. Section 29 directs the Minister to lead the development and implementation of a national strategy for the management of estuarine, coastal and marine ecosystems, and section 31 directs the Minister to lead and facilitate the development and implementation of plans for the integrated management of all activities or measures in or affecting estuaries, coastal waters and marine waters. Section 35(1) defines a marine protected area as an area of the sea designated for special protection, including for the conservation of commercial and non-commercial fishery resources and of endangered or threatened marine species and their habitats. Section 40(1) confers on the Minister authority over the federal government's policies and programs respecting oceans. The Act is the statutory basis on which Canada asserts its maritime jurisdiction, designates marine protected areas and applies ecosystem-based integrated ocean management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-osfi-e19-own-risk-solvency-2023",
    "title": "OSFI Guideline E-19 - Own Risk and Solvency Assessment (ORSA)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "This guideline requires all federally regulated insurers (FRIs) in Canada to establish and maintain a comprehensive Own Risk and Solvency Assessment (ORSA) process. As per Section 1.1, the ORSA must assess the adequacy of the insurer's risk management framework and its current and future solvency position in relation to its risk profile and strategic plan.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "canada-personal-information-protection-electronic-documents-act-part-2",
    "title": "Canada PIPEDA Part 2: Electronic Documents and Secure Electronic Signatures",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Part 2 of the Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5), titled Electronic Documents, provides the legal framework for using electronic alternatives where federal laws contemplate the use of paper to record or communicate information or transactions, administered by Treasury Board / the Department of Justice for the federal statute book. Section 32 states this purpose. Section 31 defines 'electronic document' (data recorded or stored on any medium in or by a computer system that can be read or perceived by a person or system), 'electronic signature' (one or more letters, characters, numbers or other symbols in digital form incorporated in, attached to or associated with an electronic document), 'secure electronic signature' (an electronic signature resulting from a technology or process prescribed under subsection 48(1)) and 'data'. Section 40 makes the electronic provision of documents or information subject to the consent of both persons - nothing requires anyone to use or accept electronic documents without agreement. Part 2 then provides legal recognition of electronic documents to satisfy federal statutory requirements where the relevant provision is listed in Schedule 2 or 3: retention requirements (section 37), writing requirements (section 41), original-document requirements where a secure electronic signature is used (section 42), signature requirements (section 43), sworn statements (section 44) and certifying statements (section 45); seal requirements are satisfied by a secure electronic signature identified as the person's seal (section 39). Section 48 empowers the Governor in Council, on the recommendation of the Treasury Board, to prescribe technologies or processes for secure electronic signatures, which must satisfy four criteria: the signature is unique to the person, its use is under the sole control of the person, the technology identifies the person, and the signature is linked to the document so that any subsequent change is detectable (section 48(2)); removing a technology from the prescribed list does not invalidate signatures created while it was prescribed (section 48(3)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-pest-control-products-act",
    "title": "Canada Pest Control Products Act: Registration, Risk Evaluation and Maximum Residue Limits",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Pest Control Products Act (S.C. 2002, c. 28) is Canada's federal statute governing the regulation of pesticides, administered by Health Canada's Pest Management Regulatory Agency (PMRA). Section 4(1) states the Minister's primary objective is to prevent unacceptable risks to individuals and the environment from the use of pest control products, and section 2 defines 'pest control product', 'health risk' (the possibility of harm to human health from exposure or use) and 'environmental risk' (the possibility of harm to the environment, including its biological diversity). Section 6(1) prohibits any person from manufacturing, possessing, handling, storing, transporting, importing, distributing or using a pest control product that is not registered, except as authorised. Registration applications are made to the Minister (section 7(1)), who must conduct the evaluations necessary to assess the health and environmental risks and the value of the product (section 7(3)); in evaluating health risk the Minister must consider aggregate exposure - dietary plus other non-occupational sources - and cumulative effects, and must apply appropriate margins of safety to protect sensitive subpopulations including pregnant women, infants, children, women and seniors (section 7(7)(b)). On approval the Minister registers the product subject to conditions (section 8(1)) and specifies maximum residue limits where necessary (sections 9-11). Registered products must be re-evaluated no later than one year after fifteen years have elapsed since the most recent major decision (section 16(2)), and the Minister must initiate a special review where there are reasonable grounds to believe the risks or value are unacceptable (section 17(1)). The Minister may cancel or amend a registration (section 20) and require recall and disposal of stocks (section 21(5)). A public Register of Pest Control Products is maintained (section 42), with controlled access to confidential test data on affidavit application (section 43) and limited disclosure powers (section 44). Inspectors and analysts are appointed (section 45) with powers of entry, inspection and sampling (section 48), subject to consent or warrant for dwelling-houses (section 49). Contraventions are punishable on summary conviction by a fine up to $200,000 or six months' imprisonment, and on indictment by a fine up to $500,000 or three years' imprisonment (section 6(9)). The Governor in Council may make regulations (section 67) and interim orders (section 67.1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-phipa-federal-health-2026",
    "title": "Canada PHIPA / PIPEDA - Health Information Protection (Ontario & Federal Alignment 2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Ontario’s Personal Health Information Protection Act (PHIPA) and federal PIPEDA govern health information. Key obligations include consent, safeguards, breach notification (to affected individuals and OPC within 30 days), accountability, and transparency. Digital health and AI applications face heightened scrutiny.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-pipeda-sc-2000-c5-personal-information-protection",
    "title": "Canada PIPEDA (Personal Information Protection and Electronic Documents Act) - SC 2000, c. 5 Private Sector Data Protection Obligations",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "PIPEDA (SC 2000, c. 5) governs collection, use, and disclosure of personal information in the course of commercial activities across Canada (except in provinces with substantially similar legislation - Alberta, British Columbia, Quebec). Ten Fair Information Principles are codified in Schedule 1; organisations must designate a Privacy Officer; mandatory breach reporting to OPC and affected individuals applies when real risk of significant harm exists.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-plant-breeders-rights-act",
    "title": "Canada Plant Breeders' Rights Act: Variety Protection, Exclusive Rights and Farmers' Privilege",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Plant Breeders' Rights Act (S.C. 1990, c. 20) confers intellectual property protection on new plant varieties in Canada, administered by the Plant Breeders' Rights Office within the Canadian Food Inspection Agency (CFIA), implementing Canada's obligations under the UPOV Convention. Section 2 defines 'plant variety', 'plant breeder's rights' (the rights granted under section 27) and 'propagating material' (reproductive or vegetative material, including seeds for sowing). Section 4(2) sets the conditions for protection: the variety must be new, clearly distinguishable from all other varieties, stable in its essential characteristics, and sufficiently homogeneous (uniform). Section 7(1) limits applicants to breeders or their legal representatives who are citizens or residents of Canada or of a country of the Union or an agreement country. Section 5(1) grants the holder exclusive rights to produce and reproduce propagating material, condition it for propagation, sell it, export or import it, make repeated use of it to produce other varieties, use ornamental plants as propagating material, stock it, and to authorize those acts. Section 6(1) sets the duration at 25 years for a tree, vine or category specified by regulation, and 20 years in any other case, beginning on the day the certificate is issued. Section 5.3 preserves the farmers' privilege for harvested material grown and saved for the sole purpose of propagation, and section 32 allows the Commissioner to grant compulsory licences. Provisional protection applies from the filing date (section 19). Infringement makes a person liable to the holder for damages, with injunctions and other remedies available (section 41). The Commissioner maintains a register (section 63). Offences under section 53 are punishable, for an individual, by a fine up to $5,000 on summary conviction or up to $15,000 and three years' imprisonment on indictment, with higher fines for corporations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-plant-protection-act",
    "title": "Canada Plant Protection Act: Preventing the Import, Export and Spread of Plant Pests",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Plant Protection Act (S.C. 1990, c. 22) is Canada's federal statute for protecting plant life and the agricultural and forestry sectors by preventing the importation, exportation and spread of pests and by controlling or eradicating pests in Canada, administered by the Canadian Food Inspection Agency (CFIA). Section 2 states this purpose, and section 3 defines 'pest' (any thing injurious or potentially injurious, directly or indirectly, to plants or to products or by-products of plants), 'thing' (including a plant and a pest) and 'plant' (including a part of a plant). Section 6(1) prohibits moving, growing, raising, culturing or producing any thing that there are reasonable grounds to believe is a pest, is or could be infested, or could constitute a biological obstacle to pest control, except as permitted. Section 7 prohibits importing into, admitting into or exporting from Canada any pest, infested thing or biological obstacle unless permit, presentation and regulatory conditions are met. An inspector may order the removal from Canada or destruction of unlawfully imported things (section 8). Inspectors may declare a place infested (section 11), declare contiguous lands or buildings infested where a pest could spread (section 12), and prohibit or restrict movement within an infested place for up to ninety days (section 13); the Minister may by order declare a place infested, determine and vary the affected area, extend periods, and prohibit, restrict or permit movement (section 15(3)). The Minister may order compensation from the Consolidated Revenue Fund for treatment, storage, disposition or restrictions (section 39(1)), subject to exceptions for things imported in contravention or found infested on inspection (section 39(2)). Inspectors have powers of entry, inspection, sampling, seizure and detention (sections 25-27), with dwelling-houses protected by a consent or warrant requirement (section 26) and search warrants available from a justice (section 28). Seized things compliant with the Act must be released (section 32), and a court may order forfeiture (section 33) and disposal as the Minister directs (section 34). Offences are punishable on summary conviction by a fine up to $50,000 or six months' imprisonment, and on indictment by a fine up to $250,000 or two years' imprisonment (section 48). The Governor in Council may make regulations (section 47) and incorporate documents by reference (section 47.1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-pmprb-patented-medicine-prices-2021",
    "title": "Patented Medicine Prices Review Board Guidelines 2021",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Patented Medicine Prices Review Board (PMPRB) Guidelines 2021 require that the price of a patented medicine in Canada not exceed the median price of the same medicine in seven comparator countries, as per Section 4 of the Guidelines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "wipo-patent-cooperation-pct"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-protected-b-cloud-security-profile-cccs-itsp-50-105",
    "title": "Canada CCCS Protected B Cloud Security Profile - ITSP.50.105 Government Cloud Authorization and Security Control Assessment",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Government of Canada Security Control Profile for Cloud-Based IT Services (GC Cloud Security Control Profile), also referenced as ITSP.50.105 and published by the Canadian Centre for Cyber Security (CCCS), establishes the minimum security controls that Government of Canada (GC) departments and agencies must verify are implemented when procuring or deploying cloud-based IT services to process, store, or transmit Protected B information; Protected B is the Government of Canada's second-highest information sensitivity classification covering information that, if disclosed, could cause serious injury to an individual, organisation, or government; the Profile defines 327 controls derived from NIST SP 800-53 Rev 5 tailored to the GC context across 20 control families; cloud service providers (CSPs) seeking to host GC Protected B workloads must undergo a Security Assessment and Authorization (SA&A) process managed by the Treasury Board of Canada Secretariat (TBS) and CCCS; CSPs must demonstrate compliance with the GC Cloud Security Control Profile via a third-party Security Assessment Report (SAR) and must be listed on the GC Cloud Brokering Service (CBaaS) Qualified Vendor List before GC departments can contractually engage them for Protected B workloads; the Framework is aligned with the Government of Canada's Cloud Adoption Strategy (TBS Directive on Service and Digital, Appendix G), FedRAMP Moderate baseline (reciprocity exists for some controls), and the CSA Cloud Controls Matrix (CCM) v4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-radiocommunication-act",
    "title": "Canada Radiocommunication Act (R.S.C. 1985, c. R-2): Radio Authorization, Technical Standards and Offences",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Radiocommunication Act (R.S.C. 1985, c. R-2) governs the regulation of radio apparatus, the radio-frequency spectrum and radiocommunication in Canada, administered by the Minister of Industry through Innovation, Science and Economic Development Canada. Section 2 supplies the definitions, including radiocommunication (any transmission, emission or reception of intelligence by means of electromagnetic waves), radio apparatus and radio-sensitive equipment. Section 4 sets the core prohibitions: no person may install, operate or possess radio apparatus except under and in accordance with an authorization or a radio licence (with an exception for receive-only broadcasting apparatus), and no person may manufacture, import, distribute or offer for sale radio apparatus that does not meet the applicable technical standards or lacks the required technical acceptance certificate. Section 5 sets out the powers of the Minister, including issuing radio authorizations and spectrum licences, assigning frequencies, planning spectrum allocation, approving antenna sites, setting technical standards and addressing harmful interference. Section 9 sets out the offences, including causing harmful interference, sending false or fraudulent distress signals, and decoding an encrypted subscription programming signal without authorization. Section 10 provides the penalties, with summary conviction punishable by a fine of up to 5,000 dollars or one year imprisonment for an individual and up to 25,000 dollars for a corporation, and enhanced penalties of up to 20,000 dollars for an individual and 200,000 dollars for a corporation for encrypted-signal offences. The Act is the legal foundation of Canadian spectrum management and radio-equipment regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-safe-food-canadians-act-2012-cfia",
    "title": "Canada Safe Food for Canadians Act 2012 - CFIA Preventive Controls and Licensing Framework",
    "domain": "Agriculture & Agritech",
    "version": "2.1",
    "last_updated": "2026-06-14",
    "bluf": "The Safe Food for Canadians Act (SFCA, SC 2012, c. 24) and its implementing Safe Food for Canadians Regulations (SFCR, SOR/2018-108) consolidate and modernise Canada's food safety framework. The Canadian Food Inspection Agency (CFIA) administers the SFCA, which establishes a preventive-controls-based system requiring food businesses to identify and control food safety hazards before they occur rather than responding after contamination. Businesses that manufacture, process, treat, preserve, grade, package, label, store, or import food must hold a CFIA licence if they engage in interprovincial trade or export. A Preventive Control Plan (PCP) - equivalent to HACCP - is mandatory for most regulated activities. Traceability requirements mandate that businesses can trace food one step back (supplier) and one step forward (customer) within 24 hours. The SFCA replaces five predecessor Acts including the Meat Inspection Act and Fish Inspection Act. Criminal penalties include fines up to CAD 5,000,000 for individuals and up to CAD 5,000,000 for corporations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "haccp",
        "us_fsma",
        "wto_sps",
        "health_canada",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "canada-safe-food-canadians-regulations-2019",
    "title": "Safe Food for Canadians Regulations",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Safe Food for Canadians Regulations (SFCR) require food businesses involved in importing, exporting, manufacturing, or selling certain foods to hold a licence, develop a preventive control plan (PCP), and maintain traceability records (one-up, one-down). These requirements apply to all food commodities listed under the SFCR, including meat, dairy, eggs, fish, and fresh fruits and vegetables, as specified in sections 20(1), 85, and 122 of the Safe Food for Canadians Act and its regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-safe-food-for-canadians-act",
    "title": "Canada Safe Food for Canadians Act: Licensing, Traceability and Food Commodity Controls",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Safe Food for Canadians Act (S.C. 2012, c. 24) is Canada's consolidated federal food-safety statute, administered by the Canadian Food Inspection Agency (CFIA), governing the import, export and inter-provincial trade of food commodities. Section 2 defines 'food commodity' (any food as defined in the Food and Drugs Act, or any animal or plant from which food may be derived), 'licence' and 'prescribed'; section 3 makes the Act binding on the Crown. Core prohibitions bar manufacturing, preparing, packaging, labelling, selling, importing or advertising a food commodity in a manner that is false, misleading or deceptive (section 6(1)); tampering with a food commodity, its label or package with intent to render it injurious to human health (section 7); and selling a food commodity subject to a recall order under subsection 19(1) of the Canadian Food Inspection Agency Act (section 5). A prescribed food commodity may not be sent or conveyed from one province to another, imported or exported, without the required registration or licence (section 10(2)), and may not be possessed for those purposes unless it meets the regulations (section 12). The Minister may register a person or issue a non-transferable licence authorising inter-provincial trade, import or export (section 20). It is prohibited to make false or misleading statements to officials (section 15) or to obstruct them (section 16). Inspectors may enter regulated places to examine, test, sample, use computers and remove things (section 24), seize and detain (section 25), subject to a consent or warrant requirement for dwelling-houses (section 26); they may order non-compliant or illegally imported food removed from Canada or destroyed, with forfeiture to the Crown on default (section 32). Offences are punishable under section 39(1) on indictment by a fine up to $5,000,000 or two years' imprisonment, and on summary conviction by up to $250,000 or six months (first offence) or $500,000 or 18 months (subsequent), with higher penalties for tampering and reckless endangerment under section 39(3) (on indictment, a fine at the court's discretion or up to five years). The Governor in Council may make regulations, including traceability requirements (section 51).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-seeds-act",
    "title": "Canada Seeds Act: Seed Standards, Variety Registration and Grade-Name Controls",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Seeds Act (R.S.C. 1985, c. S-8) is Canada's federal statute regulating the quality, labelling and sale of agricultural seed, administered by the Canadian Food Inspection Agency (CFIA). Section 2 defines 'seed' (any plant part of any species belonging to the plant kingdom, represented, sold or used to grow a plant), 'sell' (including to agree to sell, or to offer, keep, expose, transmit, send, convey or deliver for sale) and 'grade name' (including any mark, description or designation of a grade). The principal prohibition in section 3(1) provides that no person shall sell, import into Canada or export seed unless it conforms to the prescribed standard and is marked, packed and labelled as prescribed, and unless the seed variety is registered in the prescribed manner where registration is required. Section 3(2) prohibits selling seed under a grade name so closely resembling an established grade name as to be likely to be mistaken for it. Inspectors appointed under the Act may enter any place, open any package, examine seed and take samples, and remove things for examination (sections 5-6); it is prohibited to obstruct or hinder an inspector (section 7(1)); and inspectors may seize seed where a contravention is believed, with courts empowered to order forfeiture of seized seed following a conviction or finding of violation (section 8). Offences are punishable on summary conviction by a fine not exceeding $50,000 or imprisonment for up to six months, or both, and on indictment by a fine not exceeding $250,000 or imprisonment for up to two years, or both (section 9). The Governor in Council may make regulations establishing grades, prescribing standards, setting packing and labelling requirements, and regulating importation and exportation (section 4(1)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-seeds-act-rsc-1985-c-s-8-cfia",
    "title": "Canada Seeds Act (R.S.C. 1985, c. S-8) - CFIA Variety Registration and Plant Breeders Rights Framework",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Canada's Seeds Act (R.S.C. 1985, c. S-8) governs the registration, quality, sale and import of seeds in Canada. The Canadian Food Inspection Agency (CFIA) administers the Act. Major field crops require variety registration through the CFIA's Variety Registration Office (VRO) before seed may be sold commercially; some crops are exempt. Canada participates in the OECD Seed Scheme for international certification. Seed quality standards are set in the Seeds Regulations (C.R.C., c. 1400). The Plant Breeders' Rights Act (R.S.C. 1990, c. 14) provides separate intellectual property protection. Canada is a member of UPOV 1978 (not 1991), meaning farmer privilege to save and replant seed is retained.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-plant-variety-protection-act-1970-usda-pvpo"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "canada-space-agency-act-1990",
    "title": "Canada Space Agency Act 1990 (SC 1990, c. 13) - Canadian Space Policy and Regulatory Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Space Agency Act (SC 1990, c. 13) established the Canadian Space Agency (CSA / Agence spatiale canadienne) as the federal institution responsible for Canada's civil space programme, including astronaut training, satellite development, and coordination of Canada's participation in international space activities. Canada's commercial space licensing is handled by Innovation, Science and Economic Development Canada (ISED) under the Radiocommunication Act for spectrum matters and under Transport Canada or CSA for launch licensing - Canada does not have a standalone Space Activities Act but regulates commercial space through multiple framework statutes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "radiocommunication_act",
        "remote_sensing_systems_act"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "canada-special-economic-measures-act-sema",
    "title": "Canada Special Economic Measures Act (SEMA): Sanctions Authority, Orders and Regulations, Permits, Ministerial Administration, and Parliamentary Reporting",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Canada Special Economic Measures Act, enacted as S.C. 1992, c. 17 and commonly cited as SEMA, is the principal Canadian statute authorising autonomous economic sanctions against foreign states, entities and persons. The short title is set out in section 1. Section 2 contains the interpretation and key definitions including Canadian, entity, foreign state, national, person, property and technical data. Section 3 binds the Act on Her Majesty in right of Canada or a province. Section 4 is the core operative provision: the Governor in Council may make orders and regulations to restrict or prohibit activities relating to a foreign state where one of the statutory triggers exists, including a decision of an international organization, a grave breach of international peace and security, gross and systematic human rights violations, or acts of significant corruption involving a national of a foreign state. The activities that may be restricted include dealings in property situated in Canada or held by Canadians outside Canada, exports of goods, supply of technical data, provision of financial or other services, and the entry into Canadian ports of vessels and aircraft registered to the foreign state. Section 5 addresses the costs of seizure, restraint or disposal of property forfeited under the Act. Section 6 confers administration on the Minister of Foreign Affairs with provision for delegation and for assessment of compensation claims. Section 7 requires every order and regulation made under section 4 to be tabled in each House of Parliament within five sitting days and provides for parliamentary motions to revoke or amend, and requires the Minister to submit a report on the operations of any sanctions measure within sixty days of its cessation. SEMA is the controlling instrument for Canadian autonomous sanctions enforcement under Canadian trade compliance law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-special-economic-measures-belarus-regulations-sor-2020-214",
    "title": "Canada Special Economic Measures Belarus Regulations SOR/2020-214 Designated Persons Asset Freeze Goods Controls and Five Schedule Designation Framework",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Special Economic Measures (Belarus) Regulations SOR/2020-214 establish Canada autonomous sanctions targeting Belarus made under the Special Economic Measures Act in response to a grave breach of international peace and security organised in operative sections covering interpretation defining designated person and Canada nexus, the List sections referencing five Schedules including Schedule 1 listing designated persons subject to the dealings prohibition Schedule 2 listing goods subject to export and supply prohibitions Schedule 3 listing goods and technologies subject to expanded export controls Schedule 4 and Schedule 5 establishing additional categories of goods and persons, prohibitions on dealing in any property of designated persons facilitating financial transactions providing financial services providing other goods or services to designated persons and exporting or supplying Schedule 2 and Schedule 3 goods to any person in Belarus, applications procedures for delisting and permits, application before publication transitional provisions, and coming into force provisions. The regulation is current to 2026-03-31 with the most recent amendment dated January 24 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "canada-special-economic-measures-act-sema"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-special-economic-measures-iran-regulations-sor-2010-165",
    "title": "Canada Special Economic Measures (Iran) Regulations SOR/2010-165 Asset Freeze Dual-Use Export Controls Nuclear and Ballistic Missile Provisions and Human Rights Designations",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Special Economic Measures (Iran) Regulations SOR/2010-165 are Canada's autonomous sanctions framework against Iran made under the Special Economic Measures Act in response to a Governor in Council determination that the situation in Iran constitutes a grave breach of international peace and security, organised across sections including a section 3 asset freeze prohibiting Canadians and Canadian entities from dealing in property owned or controlled by listed persons providing financial services to listed individuals or making goods available to designated persons, a section 4 export controls regime covering dual-use goods including aluminum products mass spectrometers and specialized equipment arms and military equipment technical data related to controlled items and items relevant to ballistic missiles or nuclear weapons delivery, Schedule 1 listed persons divided into Part 1 with entities involved in weapons development or grave breaches Part 1.1 entities linked to human rights violations Part 2 individuals connected to nuclear or weapons activities and Part 2.1 individuals cited for human rights concerns, exceptions covering pension payments diplomatic mission transactions international organization dealings legal service financing and civil nuclear cooperation activities, and financial institution continuous monitoring and reporting obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "canada-special-economic-measures-act-sema"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-special-economic-measures-russia-regulations-sor-2014-58",
    "title": "Canada Special Economic Measures (Russia) Regulations SOR/2014-58 - Asset Freeze Trade and Service Prohibitions and Restricted Goods List Against Russia",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Special Economic Measures (Russia) Regulations SOR/2014-58 are Canada's autonomous sanctions framework against Russia made under the Special Economic Measures Act and organised across sections defining listed persons in section 2 and listed ships in section 2.01, core prohibitions in section 3 covering asset freeze and dealings with listed persons, debt and equity restrictions for designated Russian entities in sections 3.01 to 3.02, an extensive set of trade restrictions in sections 3.03 to 3.14 covering oil and gas exports, petroleum imports, coal, jet fuel, restricted goods and technologies, luxury goods, industrial goods, insurance, gold, marine services, arms and chemical and biological precursors and metals, additional diamond and revenue-generating goods import bans in sections 3.15 to 3.16, exceptions for pensions, diplomatic and humanitarian categories in section 4, a broad facilitation prohibition in section 5, financial institution ongoing-monitoring duties in section 6, mandatory disclosure to the Royal Canadian Mounted Police or CSIS in section 7, and delisting and mistaken identity application procedures in sections 8 to 9, supported by Schedules listing 775+ designated persons plus restricted goods categories.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "canada-special-economic-measures-act-sema"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-special-economic-measures-venezuela-regulations-sor-2017-204",
    "title": "Canada Special Economic Measures Venezuela Regulations SOR/2017-204 Designated Persons Asset Freeze Dealings Prohibition and Schedule of Designated Individuals",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Special Economic Measures (Venezuela) Regulations SOR/2017-204 establish Canada autonomous sanctions targeting Venezuela in response to a grave breach of international peace and security made under the Special Economic Measures Act organised in operative sections covering interpretation defining designated person and Canada nexus, the List section referencing designated persons specified in the Schedule, prohibitions on dealing in any property of designated persons facilitating financial transactions or providing financial services for designated persons and providing other goods or services to designated persons, applications procedures for delisting and exemptions, application before publication transitional provisions, and coming into force provisions. The Regulations include a Schedule listing designated persons including senior Venezuelan officials and others identified by the Governor in Council as engaged in or supporting actions that constitute grave breaches of international peace and security. The regulation is current to 2026-03-31 with the most recent amendment dated March 20 2025 by SOR/2025-112.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "canada-special-economic-measures-act-sema"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-species-at-risk-act",
    "title": "Canada Species at Risk Act (SARA): Listing, General Prohibitions and Critical Habitat Protection",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Species at Risk Act (S.C. 2002, c. 29), known as SARA, is Canada's federal biodiversity-protection statute, administered chiefly by Environment and Climate Change Canada with the Department of Fisheries and Oceans and the Parks Canada Agency as competent authorities. Section 6 states its purposes: to prevent wildlife species from being extirpated or becoming extinct, to provide for the recovery of those that are extirpated, endangered or threatened, and to manage species of special concern. Section 2 defines 'wildlife species', 'extirpated', 'endangered', 'threatened' and 'special concern' species, 'critical habitat' (habitat necessary for the survival or recovery of a listed species) and 'residence' (a dwelling-place such as a den or nest). The Committee on the Status of Endangered Wildlife in Canada (COSEWIC) assesses species (sections 14-25), and the Governor in Council amends the List of Wildlife Species at Risk in Schedule 1, normally within nine months of receiving an assessment (section 27). Once a species is listed as extirpated, endangered or threatened, section 32 prohibits killing, harming, harassing, capturing or taking an individual, and possessing, collecting, buying, selling or trading an individual or its parts; section 33 prohibits damaging or destroying its residence. Section 58 prohibits destroying any part of the critical habitat of a listed endangered or threatened species on federal land, in the exclusive economic zone, or for aquatic and migratory bird species. Competent ministers must prepare recovery strategies (section 37), action plans (section 47) and, for species of special concern, management plans (section 65); the Governor in Council may make emergency orders where a species faces imminent threats (section 80). Otherwise-prohibited activities may proceed only under an agreement or permit that meets the conservation conditions in section 73. Enforcement officers have inspection, search and seizure powers (sections 85-89). Offences under sections 32, 33, 36, 58, 60 and 61 are punishable on summary conviction by a fine up to $300,000 or two years' imprisonment, and on indictment by a fine up to $500,000 or three years' imprisonment (section 97).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-student-financial-assistance-act-1994",
    "title": "Canada Student Financial Assistance Act, R.S.C. 1994, c. S-22.7",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Canada Student Financial Assistance Act establishes the framework for federal student financial aid, including Canada Student Loans and Grants, administered jointly by the Government of Canada and participating provinces and territories. It applies to eligible post-secondary students and institutions under Section 4(1) and sets out eligibility, disbursement, repayment, and forgiveness obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "canada-tbs-directive-automated-decision-making-2019",
    "title": "Canada Treasury Board Secretariat - Directive on Automated Decision-Making (in force April 1 2019, updated 2023, 2025)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The Treasury Board of Canada Secretariat (TBS) Directive on Automated Decision-Making (ADM Directive) is binding instrument-level policy for the Government of Canada governing the use of automated decision systems by federal departments and agencies. It took effect on April 1, 2019, was substantially updated effective April 1, 2023, and updated again in 2025. The Directive applies to any system used to recommend or make an administrative decision about a client by a federal institution. Core requirements include: (1) Complete an Algorithmic Impact Assessment (AIA) before producing or acquiring an automated decision system, using the TBS AIA tool, with the assessment publicly released on the Open Government portal; (2) Apply requirements proportionate to the AIA-determined impact level (Level I through Level IV); (3) Provide a notice of the use of the system to affected clients before and during the decision; (4) Provide explanations to clients of decisions made by the system, with detail proportionate to the impact level; (5) Conduct gender-based analysis plus, peer review of the system, and testing for unintended data biases; (6) Maintain quality assurance throughout the lifecycle including testing before production, monitoring outcomes, and ongoing data quality controls; (7) Apply licensing terms allowing the Government of Canada to access the source code, training data, and decision logic for review and audit; (8) Reporting and governance through the Chief Information Officer of Canada and the Designated Senior Official for the institution. The companion Algorithmic Impact Assessment Tool is the operational instrument; non-compliance triggers TBS escalation and potential withdrawal of authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "international_alignment",
        "regulatory_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "canada-aida-2022",
      "canada-aida-artificial-intelligence-data-act-c27"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-tcps2-research-ethics-policy-2018",
    "title": "Canada TCPS 2 (2018) - Tri-Council Policy Statement on Research Ethics",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Tri-Council Policy Statement: Ethical Conduct for Research Involving Humans (TCPS 2, 2018 edition) is the joint policy of Canada's three federal research agencies (CIHR, NSERC, SSHRC). It mandates Research Ethics Board (REB) review for all human subjects research at institutions receiving tri-council funding, establishes a proportionate review model, and contains dedicated chapters on clinical trials, genetic and biological materials, Indigenous Peoples research, and privacy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "canada-assisted-human-reproduction-act-2004",
      "cartagena-protocol-biosafety-2000"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "canada-telecommunications-act",
    "title": "Canada Telecommunications Act (S.C. 1993, c. 38): CRTC Regulation of Carriers, Tariffs, Rates and Canadian Ownership",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Telecommunications Act (S.C. 1993, c. 38) is the federal statute governing the regulation of telecommunications in Canada, administered by the Canadian Radio-television and Telecommunications Commission (CRTC). Section 2 defines the core terms, including Canadian carrier (a telecommunications common carrier subject to the legislative authority of Parliament), telecommunications (the emission, transmission or reception of intelligence by any wire, cable, radio, optical or other electromagnetic system) and telecommunications service. Section 7 declares the Canadian telecommunications policy objectives, including affordable, reliable and high-quality service in urban and rural areas, the promotion of Canadian ownership and control, market-driven provision with efficient regulation, and the protection of the privacy of persons. Section 16 requires a Canadian carrier to be Canadian-owned and controlled, with not less than 80 percent of its directors being individual Canadians and not less than 80 percent of its voting interests beneficially owned by Canadians, subject to exemptions for international submarine cables, earth stations and satellites. Section 24 makes the offering and provision of any telecommunications service subject to the conditions imposed by the Commission or in an approved tariff. Section 25 prohibits a carrier from providing a service except in accordance with a tariff filed with and approved by the Commission specifying the rate. Section 27 requires every rate to be just and reasonable and prohibits unjust discrimination or undue preference, placing the burden of proof on the carrier. Section 46.5 authorizes a contribution regime to support continuing access to basic services. Sections 71 and 72 provide for inspection and civil liability and section 73 creates offences, with administrative monetary penalty schemes in sections 72.001 to 72.01. The Act is the legal foundation for CRTC regulation of Canadian carriers, rates and ownership.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-trademarks-act",
    "title": "Canada Trademarks Act: Registrability, Confusion, Exclusive Rights and Infringement",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Trademarks Act (R.S.C. 1985, c. T-13) governs the registration and protection of trademarks in Canada, administered by the Canadian Intellectual Property Office (CIPO) and the Registrar of Trademarks. Section 2 defines 'trademark' (a sign or combination of signs used or proposed to be used to distinguish a person's goods or services from those of others), 'confusing' and 'distinctive'. Section 6 sets the test for confusion, requiring consideration of all the surrounding circumstances, including the inherent distinctiveness of the marks and the extent to which they have become known, the length of time in use, and the nature of the goods, services or business. Section 9 prohibits the adoption of certain marks (royal and official emblems, the Red Cross, and the national flags of WTO members) and section 12 lists marks that are not registrable, including those that are merely descriptive or deceptively misdescriptive or confusing with a registered mark. Applications must contain a statement of the goods or services in ordinary commercial terms in accordance with the Nice Classification (section 30), and proceed through examination, advertisement and opposition (sections 37-38). Registration gives the owner the exclusive right to the use of the trademark throughout Canada (section 19), and section 20 deems infringement to occur where a person uses a confusing trademark or trade name without authorization. Section 22 prohibits use of a registered trademark in a manner likely to depreciate the value of its goodwill. The term of registration is ten years, subject to renewal (section 46). Section 7 prohibits unfair competition and passing off, including false or misleading statements tending to discredit a competitor. Remedies are available in the Federal Court (sections 53-53.3), and section 51 addresses offences relating to selling or distributing goods bearing false trademarks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-transfer-pricing-income-tax-act-section-247",
    "title": "Income Tax Act, Section 247 - Arm's Length Transactions, Recharacterisation Power, Contemporaneous Documentation and Penalties",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires Canadian taxpayers to ensure arm's length transactions with non-resident related parties, as per Section 247 of the Income Tax Act, and maintain contemporaneous documentation to support transfer pricing, with penalties for non-compliance under subsection 247(3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-transfer-pricing-directive-proposal-2023",
      "oecd-attribution-profits-permanent-establishments-2010"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "canada-transportation-act-1996-cta-railway-freight",
    "title": "Canada Transportation Act 1996 - Railway Freight Access, Revenue Entitlement and Canadian Transportation Agency",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Canada's Canada Transportation Act (CTA, S.C. 1996, c. 10, as amended 2018 and 2023) administered by the Canadian Transportation Agency (CTA-Agency) and Transport Canada establishes the competitive framework for railway freight transport; mandates final offer arbitration (FOA) for shipper-railway freight rate disputes; provides for interswitching (level-of-service switching between competing railways) within prescribed distance limits; requires railways to meet adequate level of service obligations; establishes the Western Grain Railway Revenue Entitlement Cap (grain revenue cap) reviewed annually by CTA-Agency; and imposes administrative monetary penalties of up to CAD 100,000 per violation for railway and shipper compliance failures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-heavy-vehicle-national-law-2012-nhvr"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "canada-voluntary-code-conduct-genai-2023",
    "title": "Canada ISED Voluntary Code of Conduct on Responsible Development and Management of Advanced Generative AI",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "Canada's Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems was published by Innovation, Science and Economic Development (ISED) Canada in September 2023 as a voluntary industry commitment framework for organisations that develop, operate, or manage advanced generative AI systems; the Code establishes seven core commitments: (1) Safety - developers must assess, mitigate, and address safety risks including dual-use risks, before deploying advanced generative AI systems; conduct pre-deployment testing; implement post-deployment monitoring; (2) Security - organisations must protect against misuse, adversarial inputs, and prompt injection attacks; implement identity verification where appropriate; (3) Incident reporting - signatories commit to report to the relevant Canadian government authority incidents where advanced generative AI systems produce outputs resulting in significant harm; (4) Transparency - signatories must publicly disclose what advanced generative AI systems they have deployed; publish information about capabilities and known limitations; label AI-generated content where practicable; (5) Diversity, inclusion, and accessibility - ensure AI systems do not discriminate based on prohibited grounds under Canadian human rights law; conduct fairness testing across protected groups; (6) International engagement - support the development of international technical standards and interoperability; contribute to multilateral AI governance frameworks; (7) Accountability - establish clear internal accountability for AI governance; designate a responsible individual or office for AI safety oversight; the Code explicitly targets advanced generative AI systems with transformative potential including large language models, image/audio/video generation models, and multimodal foundation models; the Code preceded the Artificial Intelligence and Data Act (AIDA) which remains under parliamentary consideration; major signatories included OpenAI, Anthropic, Google, Microsoft, Meta, Amazon Web Services, Cohere, and numerous Canadian technology organisations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/canada-voluntary-code-conduct-genai-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "canada-aida-artificial-intelligence-data-act-c27",
      "us-ostp-blueprint-ai-bill-of-rights"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "canada-water-act-fisheries-act-section-36-pollution",
    "title": "Canada Water Act and Fisheries Act Section 36 - Federal Water Pollution Prevention and Deleterious Substances Prohibition",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "Federal water pollution control in Canada operates through two principal statutes. The Canada Water Act (R.S.C., 1985, c. C-11) provides for management of water resources of Canada, particularly in waters where there is a significant national interest, and for federal-provincial consultation through agreements under Section 4. The Fisheries Act (R.S.C., 1985, c. F-14) Section 36(3) is the primary federal prohibition: no person shall deposit or permit the deposit of a deleterious substance of any type in water frequented by fish or in any place under any conditions where the deleterious substance or any other deleterious substance that results from the deposit of the deleterious substance may enter any such water. Deleterious substance is defined at Section 34(1) by reference to substances that would alter or contribute to the alteration of the quality of water frequented by fish so as to render the water deleterious to fish or fish habitat, or to render water deleterious to use of fish by humans. Penalties under Section 40 include indictable offence with fines up to CAD 6 million for first offence (corporations) and CAD 12 million for second/subsequent. Section 35 prohibits causing serious harm to fish through carrying on of any work, undertaking or activity. Environment and Climate Change Canada (ECCC) administers Section 36; Fisheries and Oceans Canada (DFO) administers Section 35. The Wastewater Systems Effluent Regulations under Fisheries Act provide deemed authorisation for wastewater discharges meeting standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-1972-epa-corps-engineers",
      "australia-water-act-2007-murray-darling-basin"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "canada-water-act-quality-management-areas",
    "title": "Canada Water Act: Water Quality Management Areas and the Waste-Deposit Prohibition",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Canada Water Act (R.S.C. 1985, c. C-11) provides for the management of Canada's water resources, including research, planning and the implementation of programs, administered by Environment and Climate Change Canada (ECCC) largely through federal-provincial cooperation. Section 2 defines 'water resource management' (the conservation, development and utilization of water resources), 'water quality management' (any aspect relating to restoring, maintaining or improving water quality) and 'waste' (any substance that, if added to water, would degrade or alter its quality to an extent detrimental to use by people, animals, fish or plants). Sections 4-6 provide for intergovernmental committees and continuing consultation, federal-provincial agreements for comprehensive water resource management programs, and direct federal management of federal and inter-jurisdictional waters where a significant national interest exists. The Act's central regulatory control is the establishment of water quality management areas: section 9 prohibits any person from depositing or permitting the deposit of waste of any type in waters that compose a water quality management area, except in quantities and under conditions prescribed by regulation; section 11 provides for federal-provincial agreements to designate such areas and to establish water quality management agencies; and section 13 allows the Governor in Council to designate inter-jurisdictional waters as management areas, and to authorize federal agencies, where a provincial agreement cannot be reached and a significant national interest is affected. Regulations may prescribe effluent discharge fees payable for the deposit of waste (section 18(2)(d)). The Minister may designate inspectors and analysts (section 25), who may enter premises, examine waste, take samples and require production of documents (section 26). Contravening the section 9 deposit prohibition is an offence punishable on summary conviction by a fine not exceeding $5,000, with each day of a continuing contravention treated as a separate offence (section 30).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-wild-animal-and-plant-protection-trade-act",
    "title": "Canada Wild Animal and Plant Protection and Regulation of International and Interprovincial Trade Act (WAPPRIITA): CITES Implementation, Permits and Trade Prohibitions",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Wild Animal and Plant Protection and Regulation of International and Interprovincial Trade Act (WAPPRIITA, S.C. 1992, c. 52) is Canada's statute implementing the Convention on International Trade in Endangered Species of Wild Fauna and Flora (CITES) and regulating cross-border and interprovincial trade in wild animals and plants, administered by Environment and Climate Change Canada. Section 4 sets the purpose: to protect certain species of animals and plants, particularly by implementing the Convention and by regulating international and interprovincial trade. Section 6 imposes the core import and export prohibitions, providing that no person shall import into Canada or export from Canada any animal or plant, or any part or derivative, except under and in accordance with a permit, and prohibits import of specimens taken in contravention of the law of a foreign state. Section 7 prohibits interprovincial transport of an animal or plant taken or possessed in contravention of a provincial Act without provincial authorization. Section 8 prohibits knowingly possessing a specimen that was illegally imported or that is intended to be transported in contravention of the Act. Section 10 empowers the Minister to issue permits for importation, exportation or interprovincial transportation. Enforcement is provided through officers designated under section 12 (who, under subsection 12(2), have all the powers of a peace officer), inspection, search and seizure powers under section 14, and the offence and punishment provisions in section 22, which expose offenders to fines and imprisonment. The Act is the legal instrument by which Canada meets its CITES obligations and controls the wildlife trade across its international and provincial borders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "canada-wildlife-act",
    "title": "Canada Wildlife Act: National Wildlife Areas, Marine Protected Areas and Species Protection",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Canada Wildlife Act (R.S.C. 1985, c. W-9) authorizes the federal government to undertake wildlife research, conservation and interpretation, and to create and manage protected areas, administered by Environment and Climate Change Canada (ECCC). Section 2 defines 'wildlife' (any animal, plant or other organism of a species that is wild by nature) and 'public lands' (lands belonging to His Majesty in right of Canada, including waters and the territorial sea), and identifies the Minister of the Environment. Section 4 authorizes the Minister to take charge of wildlife research facilities and to carry out measures for the conservation of wildlife on those lands, and section 9 allows the Governor in Council to authorize the lease, purchase or acquisition of lands for wildlife research, conservation and interpretation - the basis for designating National Wildlife Areas. Section 4.1 empowers the Governor in Council to establish protected marine areas in the internal waters, territorial sea or exclusive economic zone of Canada. Section 8 empowers the Minister to take measures necessary for the protection of any species of wildlife in danger of extinction. Sections 5 and 7 authorize agreements with provinces, municipal authorities, other organizations and persons. Section 12 confers the regulation-making power, including the issuance, renewal, revocation and suspension of permits and the control of activities in wildlife areas. Enforcement is carried out by wildlife officers designated under section 11, who have the powers of a peace officer and may enter, inspect and seize (section 11.1). Offences under section 13 carry substantial penalties: for an individual on indictment, a minimum of $15,000 and a maximum of $1,000,000 (and up to five years' imprisonment) for a first offence; for a corporation on indictment, a minimum of $500,000 and a maximum of $6,000,000 for a first offence, with higher minimums and maximums for subsequent offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "cape-town-convention-2001-mobile-equipment",
    "title": "Cape Town Convention 2001 - International Interests in Mobile Equipment (Aircraft Protocol)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-25",
    "bluf": "The Cape Town Convention on International Interests in Mobile Equipment (2001) and its Aircraft Protocol create a self-contained international legal framework for secured financing and leasing of aircraft (airframes, aircraft engines, and helicopters), establishing an international registry at the Aviation Authority of Ireland (ICAO-designated), granting creditors swift default remedies including deregistration and export via IDERA (Irrevocable Deregistration and Export Request Authorisation), and ensuring recognition of international interests across all 89 Aircraft Protocol Contracting States - financiers, lessors, and airlines must register international interests in the International Registry (Capetown, IE) before first delivery to achieve priority over competing claims and insolvency administrators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "icsid-convention-1965-investment-disputes",
      "new-york-convention-1958-foreign-arbitral-awards",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cartagena-declaration-refugees-1984",
    "title": "Cartagena Declaration on Refugees 1984 - Latin American Expanded Refugee Definition and Regional Solidarity Framework",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Cartagena Declaration on Refugees, adopted by acclamation on 22 November 1984 at the Colloquium on the International Protection of Refugees in Central America, Mexico and Panama in Cartagena de Indias, Colombia, is the foundational regional refugee instrument for Latin America. Although a non-binding declaration, its central operative provision (Conclusion III) has been incorporated into the domestic refugee law of at least 15 Latin American States. Conclusion III provides an expanded refugee definition complementing the 1951 UN Refugee Convention: in addition to persons covered by the 1951 Convention and 1967 Protocol, the definition includes persons who have fled their country because their lives, safety or freedom have been threatened by generalised violence, foreign aggression, internal conflicts, massive violation of human rights or other circumstances which have seriously disturbed public order. This wider definition responds to mass displacement contexts that the individualised persecution test of the 1951 Convention may not adequately capture. The Cartagena process has been commemorated and updated through successive regional instruments: San Jose Declaration 1994, Mexico Declaration and Plan of Action 2004, Brasilia Declaration 2010, Brazil Declaration and Plan of Action 2014 (Cartagena+30) for 2014-2024, and Chile Declaration and Plan of Action 2024 (Cartagena+40) for 2024-2034. UNHCR provides ongoing implementation support to Latin American States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-refugee-convention-1951-protocol-1967-non-refoulement"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cartagena-protocol-biosafety-2000",
    "title": "Cartagena Protocol on Biosafety 2000 - Living Modified Organisms (LMO) Transboundary Movement, Risk Assessment and Advance Informed Agreement Procedure",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Cartagena Protocol on Biosafety regulates the transboundary movement of living modified organisms (LMOs) to protect biological diversity, requiring advance informed agreement (AIA) procedures under Article 7 for LMOs intended for intentional introduction into the environment. It applies to Parties involved in the export, import, or transit of LMOs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cbd-convention-biological-diversity-1992",
      "iso-14001-ems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cartagena-protocol-on-biosafety-2003",
    "title": "Cartagena Protocol on Biosafety to the Convention on Biological Diversity (2003)",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "The Cartagena Protocol on Biosafety is the global legally binding treaty governing the transboundary movement of Living Modified Organisms (LMOs, commonly called GMOs) resulting from modern biotechnology, with a focus on protecting biological diversity and human health. The Protocol establishes the Advance Informed Agreement (AIA) procedure for the first intentional transboundary movement of LMOs intended for environmental release (Articles 7-10), a separate procedure for LMOs intended for direct use as food, feed or processing (LMO-FFP; the relevant article), the Biosafety Clearing-House (Article 20) for sharing decisions and risk assessments, requirements for identification and documentation in shipments (Article 18), and the Nagoya-Kuala Lumpur Supplementary Protocol on Liability and Redress. Parties may impose stricter domestic measures consistent with the Protocol; non-Parties may import LMOs subject to bilateral agreements consistent with Protocol objectives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cbd",
        "nagoya_kuala_lumpur",
        "wto_sps",
        "codex_biotech",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "casl-anti-spam-canada",
    "title": "CASL (Anti-Spam Canada)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Canada's Anti-Spam Legislation, governed by CASL S.C. 2010, c. 23, mandates strict compliance for sending Commercial Electronic Messages (CEMs). A core tenet is the prohibition outlined in Section 6(1) against dispatching CEMs without recipient consent, which must be either express or implied, a parameter enforced by this system. In accordance with guidance from CRTC Compliance and Enforcement Information Bulletin CRTC 2012-548, the platform disallows pre-checked opt-in boxes to ensure affirmative consent. As defined by Section 10(9) and 10(10), implied consent is strictly time-limited, recognized for 730 days following an existing business relationship and for 183 days after a direct inquiry. All messages must fulfill sender identification requirements prescribed in Section 11(1), necessitating clear sender details alongside a valid physical mailing address. A functional unsubscribe mechanism is also compulsory; its availability must persist for a minimum of 60 days post-send, with opt-out requests processed inside a maximum of 10 business days, as stipulated by Section 11(2) and 11(3). While the Electronic Commerce Protection Regulations SOR/2013-221 provide specific exemptions for personal, family, and certain business-to-business communications, their applicability requires rigorous verification. Maintaining a robust consent audit trail is critical for demonstrating due diligence, especially given that non-compliance can trigger severe administrative monetary penalties, with a corporate maximum penalty potentially reaching 10 million Canadian dollars.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "can-spam-act-email",
      "eprivacy-cookie-directive",
      "gdpr-art-21-marketing-optout"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cbd-convention-biological-diversity-1992",
    "title": "Convention on Biological Diversity (CBD) 1992 - Sovereign Rights over Genetic Resources, Access and Benefit-Sharing (ABS) and Conservation Obligations",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Convention on Biological Diversity (CBD) requires sovereign states to conserve biological diversity, ensure sustainable use of its components, and promote fair and equitable sharing of benefits arising from genetic resources. Key obligations are established under Article 15 (Access to Genetic Resources) and Article 8 (In-situ Conservation).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-paris-agreement-ndc-implementation-guidelines",
      "nagoya-protocol-genetic-resources-2010"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cc-privacy-framework",
    "title": "Cocos (Keeling) Islands - Australian Privacy Act and OAIC Supervisory Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Cocos (Keeling) Islands are an Australian external territory comprising 27 small coral islands in the Indian Ocean. The territory has a resident population of approximately 600 people, primarily members of the Cocos Malay community on Home Island and Australian Government workers and their families on West Island. The islands are administered by the Australian Government through the Department of Infrastructure, Transport, Regional Development, Communications and the Arts. The Australian Privacy Act 1988 (Cth) applies in the Cocos (Keeling) Islands as an Australian external territory, and the Australian Privacy Principles (APPs) govern the handling of personal data by Australian Government agencies and private sector organisations with annual turnover exceeding AU$3 million operating in the territory. The Office of the Australian Information Commissioner (OAIC) is the competent supervisory authority for privacy matters in the Cocos (Keeling) Islands. The Cocos (Keeling) Islands Act 1955 provides the legislative basis for the territory's status. The territory has a distinct cultural identity centred on the Cocos Malay community, whose privacy interests and cultural data must be handled with particular sensitivity. Organisations processing personal data in the Cocos (Keeling) Islands must comply with the Australian Privacy Act 1988, the Australian Privacy Principles, the notifiable data breaches scheme, and relevant Commonwealth legislation applicable to Australian external territories.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/cc-privacy-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ccm-2008-cluster-munitions-convention",
    "title": "Convention on Cluster Munitions - CCM 2008 (Oslo Convention)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The CCM (112 State Parties as of April 2026) imposes a comprehensive ban on cluster munitions - their use, production, transfer, stockpiling, and assistance to others - enforced through Article 3 stockpile destruction deadlines (8 years from entry into force for each State Party) and Article 4 clearance obligations (10 years); defence manufacturers, institutional investors, and ESG-rated entities face disinvestment obligations and reputational risk from any association with cluster munitions production or trade, with the Cluster Munition Monitor tracking national implementation and financial institutions increasingly applying exclusionary screens aligned with the Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-arms-trade-treaty-2013",
      "opcw-cwc-1993-chemical-weapons-convention",
      "un-guiding-principles-business-human-rights",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ccpa-cpra",
    "title": "CCPA/CPRA - California Consumer Privacy Rights",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The California Consumer Privacy Act (CCPA, effective January 1, 2020) as substantially amended by the California Privacy Rights Act (CPRA, enforceable from March 29, 2024 following litigation delays; original date July 1, 2023) is the most comprehensive U.S. state privacy law and a de facto national standard for consumer data rights. The law applies to for-profit businesses meeting any of three thresholds: annual gross revenue exceeding $25 million; buying, selling, sharing, or receiving personal information of 100,000+ consumers or households per year; or deriving 50%+ of annual revenue from selling or sharing consumer data. CPRA added: a new sensitive personal information (SPI) category with dedicated rights to limit use; the right to correct inaccurate personal information; a data retention limitation requirement (3-year limit on retaining data beyond original purpose); and the California Privacy Protection Agency (CPPA) as an independent enforcement agency with rulemaking authority. Consumer rights: access (know), deletion, correction (CPRA), opt-out of sale/sharing, limit use of SPI (CPRA), portability, and non-discrimination. Penalties: $2,500 per unintentional violation, $7,500 per intentional violation - with no statutory maximum and class action exposure for data breaches.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ccpa-cpra-optout-sale",
      "nist-800-122-pii",
      "can-spam-act-email",
      "coppa-marketing-kids",
      "gdpr-art-21-marketing-optout"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ccpa-cpra-optout-sale",
    "title": "CCPA/CPRA (Opt-out Sale)",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "California Civil Code § 1798.120 establishes a consumer's fundamental right to direct a business to stop selling or sharing their personal information. Fulfilling this obligation, as detailed in California Civil Code § 1798.135, mandates providing clear notice and an accessible \"Do Not Sell or Share My Personal Information\" link, a control set by `require_do_not_sell_share_link`. Businesses must offer a `minimum_opt_out_methods` count of two distinct submission mechanisms. Crucially, the process must `allow_frictionless_opt_out` by honoring opt-out preference signals like the Global Privacy Control (GPC), a requirement under 11 California Code of Regulations § 7025 which the system configuration `honor_global_privacy_control_gpc` enables. Upon receiving a valid request, a business has 15 business days (`days_to_effectuate_opt_out`) to cease selling or sharing the consumer's data, pursuant to 11 California Code of Regulations § 7026. This directive also requires that the business `propagate_opt_out_to_third_parties`, notifying all downstream recipients within an identical 15-day window (`days_to_notify_third_parties`). The user experience must be straightforward, as `prohibit_dark_patterns` is enforced and identity verification is not a prerequisite for this request type (`require_identity_verification_opt_out`). For consumers under the `minor_opt_in_age_threshold` of 16, California Civil Code § 1798.120(c) prohibits any sale or sharing without affirmative authorization. After a consumer opts out, a business must wait 12 months (`months_before_opt_in_re_ask`) before asking for re-authorization, a rule stipulated by 11 California Code of Regulations § 7028. All opt-out requests must be documented and retained for a period of 24 months (`record_retention_months`) to demonstrate compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ccpa-cpra",
      "can-spam-act-email",
      "eprivacy-cookie-directive",
      "gdpr-art-21-marketing-optout"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ccpa-cpra-privacy-compliance-2026-22",
    "title": "CCPA/CPRA Privacy Enterprise Compliance Standard v22",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) establish comprehensive privacy rights for California residents. Key requirements include the right to know what personal information is collected, the right to delete personal information, and the right to opt-out of the sale of personal information. Businesses must implement reasonable security measures to protect personal data and are required to provide clear privacy notices. The CPRA also introduces the California Privacy Protection Agency (CPPA) to enforce compliance and impose penalties for violations. Organizations must conduct regular assessments and maintain records of data processing activities to ensure adherence to these regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-6-lawful-basis-marketing",
      "nist-csf-2-0-cybersecurity-framework-2024",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ccpa-cpra-privacy-compliance-2026-7",
    "title": "CCPA/CPRA Privacy Enterprise Compliance Standard v7",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) establish comprehensive privacy rights for California residents. Key requirements include the right to know what personal data is collected, the right to delete personal data, and the right to opt-out of the sale of personal data. Businesses must implement reasonable security measures to protect personal information and are required to provide clear privacy notices. The CPRA also introduces the California Privacy Protection Agency (CPPA) to enforce compliance and impose penalties for violations. Organizations must ensure transparency, accountability, and consumer control over personal data, aligning their practices with these regulations to avoid significant fines and legal repercussions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-cybersecurity-framework-2024",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cd-pdp-law-2020",
    "title": "Democratic Republic of Congo Law No. 20/017 on Electronic Communications - Personal Data Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Democratic Republic of Congo (DRC) enacted Law No. 20/017 of 25 November 2020 on Electronic Communications and Information Technology, which includes provisions regulating the protection of personal data in the electronic communications sector. Administered by the Autorité de Régulation des Postes et Télécommunications du Congo (ARPTC), the law requires electronic service providers to implement technical and organisational security measures to protect personal data, obtain user consent for collection and processing, ensure data confidentiality, and restrict access to personal data to authorised personnel. The DRC is developing a standalone data protection law; this instrument represents the primary operative framework pending that enactment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/cd-pdp-law-2020.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cdp-carbon-disclosure",
    "title": "CDP Carbon Disclosure Protocol",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Adherence to the CDP Carbon Disclosure Protocol necessitates annual disclosure via the mandatory ORS portal submission following a minimum reporting period of twelve months. Organizations must quantify greenhouse gas inventories consistent with the WRI/WBCSD Greenhouse Gas Protocol Corporate Accounting and Reporting Standard, which makes Scope 1 and Scope 2 emissions reporting compulsory. Additionally, any material Scope 3 categories exceeding a collective materiality threshold of five percent must be included. The protocol demands robust governance; mandated board-level oversight for climate strategy is a foundational element, and required alignment ensures disclosures are structured around the core Recommendations of the Task Force on Climate-related Financial Disclosures. This includes the required quantification of financial impacts from climate-related risks and opportunities. To earn a leadership score, as defined by the CDP Scoring Methodology, obtaining third-party assurance is an unconditional prerequisite for submitted data. The framework’s design enables Science Based Targets initiative (SBTi) target integration, encouraging validation against the SBTi Corporate Net-Zero Standard. Comprehensive disclosure also involves required supply chain engagement tracking, providing transparency into value chain management practices that align with principles found within ISO 14064-1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ghg-protocol-scope3",
      "iso-14064-ghg-reporting",
      "issb-s1-s2-standard",
      "sbti-carbon-target",
      "tcfd-climate-risk",
      "csrd-eu-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cdp-climate-questionnaire-2024",
    "title": "CDP Climate Change Questionnaire 2024 - Governance, Risk, Targets and Supply Chain Disclosure Framework",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-04-30",
    "bluf": "The CDP Climate Change Questionnaire is a comprehensive framework for companies to disclose environmental information on governance, risks, opportunities, targets, and performance to stakeholders. It requires detailed reporting on climate-related issues, including Scope 1, 2, and 3 GHG emissions, as specified in modules C0-C15, to meet investor and customer demands for transparency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "tcfd-climate-risk",
      "ghg-protocol-scope3",
      "sbti-carbon-target",
      "issb-ifrs-s2-climate-2023",
      "csrd-eu-sustainability"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cf-artp-framework",
    "title": "Central African Republic ARTP Framework - AU Malabo Convention and Constitutional Privacy Obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Central African Republic (CAR) has established the Autorité de Régulation des Télécommunications et des Postes (ARTP) as the national regulatory authority for electronic communications and postal services. The Constitution of the Central African Republic establishes fundamental rights including the right to privacy of private and family life and the inviolability of correspondence and private communications. As a member state of the African Union, the Central African Republic is subject to the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014), which provides the applicable regional standard for personal data protection. The CAR does not have a standalone comprehensive personal data protection law. The constitutional privacy framework, ARTP regulatory requirements for telecommunications operators, and AU Malabo Convention principles together constitute the reference legal framework for personal data protection obligations in the Central African Republic. Organisations processing personal data in the CAR must respect constitutional privacy rights, comply with ARTP regulatory obligations for licensed electronic communications services, and implement personal data processing practices consistent with the AU Malabo Convention. ARTP has enforcement authority over licensed telecommunications and electronic communications operators regarding subscriber data protection and network security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/cf-artp-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cfa-ethics-standards",
    "title": "CFA Ethics & Proficiency",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Operational adherence to this node establishes rigorous conformity with foundational principles of the CFA Institute Code of Ethics and Standards of Professional Conduct. The system mandates robust controls to uphold market integrity, including the enforcement of strict information barriers to prevent the misuse of material nonpublic information consistent with Standard II(A), alongside an absolute prohibition of market manipulation algorithms as dictated by Standard II(B). Duties to clients are paramount, with configurations requiring pro-rata fair dealing for investment actions pursuant to Standard III(B) and enforcing client trade priority. Additionally, continuous investment suitability verification is required for all recommendations to align with client mandates under Standard III(C). The preservation of confidentiality, a core tenet of Standard III(E), is maintained through a mandatory client data encryption requirement. To mitigate conflicts, a maximum acceptable gift value is set at 100 USD and full conflict of interest disclosure is compulsory. In accordance with Standard V(C) on Record Retention, all supporting documentation must be preserved for a minimum of seven years. Systemic integrity is further solidified by a mandatory annual professional conduct attestation and ensuring all performance presentation complies with GIPS standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gips-investment-perf-std",
      "finra-3110-supervision",
      "mifid-ii-best-execution",
      "sec-regulation-best-interest"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cfpb-udaap-dodd-frank-section-1031-unfair-deceptive-abusive",
    "title": "CFPB UDAAP Dodd-Frank Section 1031 Unfair Deceptive or Abusive Acts or Practices",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Dodd-Frank Act Section 1031 (12 USC 5531) prohibits covered persons and service providers from engaging in unfair, deceptive, or abusive acts or practices (UDAAP) in connection with consumer financial products or services, enforced by the CFPB with civil monetary penalties up to USD 1,000,000 per day for knowing violations, and operationalized through the CFPB Supervision and Examination Manual.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dodd-frank-act-2010"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cftc-part-49-swap-reporting",
    "title": "CFTC Part 49 (Swaps)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with CFTC Part 49 is predicated on maintaining an active registration as a Swap Data Repository (SDR) pursuant to procedures outlined in 17 CFR § 49.3. A designated Chief Compliance Officer, as mandated by 17 CFR § 49.22, administers the comprehensive compliance program and ensures an annual compliance report is filed. The SDR actively disseminates swap transaction data through real-time public reporting mechanisms consistent with 17 CFR § 49.15, while also providing the Commission with direct electronic access to all SDR data as required under 17 CFR § 49.17. Comprehensive swap data recordkeeping obligations are met per 17 CFR § 49.12; all data is maintained for a minimum of five years following swap termination. Strict privacy and confidentiality protocols are enforced over this information, adhering to requirements of 17 CFR § 49.16. Operational integrity and data security are further upheld through fully compliant system safeguards. These safeguards include the successful execution of an annual penetration test, robust disaster recovery plans targeting a two-hour Recovery Time Objective, and a formal procedure for cyber incident notification to the Commission within 24 hours of discovery, ensuring the protection and availability of critical market data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cg-digital-law-2019",
    "title": "Republic of Congo Law No. 29-2019 on Digital Economy - Personal Data Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Republic of Congo (Congo-Brazzaville) enacted Law No. 29-2019 of 30 December 2019 on the Digital Economy, which includes provisions for the protection of personal data in the digital environment. The law is administered by the Agence de Régulation des Postes et des Communications Electroniques (ARPCE). It requires electronic service providers and digital economy actors to obtain user consent before collecting personal data, implement security measures to protect personal data from unauthorised access, respect data subject rights of access and rectification, and restrict cross-border transfers to jurisdictions with adequate protection. The law aligns with the AU Malabo Convention as Congo is a member of the African Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/cg-digital-law-2019.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ch-amla-geldwaeschereigesetz-1997",
    "title": "Switzerland Anti-Money Laundering Act 1997 (GwG/AMLA) - SR 955.0",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Swiss Anti-Money Laundering Act (Geldwäschereigesetz, GwG; SR 955.0) establishes the due diligence and reporting obligations for financial intermediaries in Switzerland, administered jointly by FINMA and the self-regulatory organisations (SROs) approved under the Act. Financial intermediaries as defined in Art. 2 - including banks, securities dealers, fund management companies, insurance undertakings, money transmitters, and casinos - must comply with a trilogy of core obligations: identification of the contracting party (Art. 3), identification of the beneficial owner (Art. 4), and enhanced due diligence for business relationships posing heightened money laundering risk (Art. 6). Art. 9 imposes an obligation to report suspicious transactions to the Money Laundering Reporting Office Switzerland (MROS) and prohibits the financial intermediary from continuing the business relationship until authorised by MROS or a competent authority. Art. 10 prohibits the financial intermediary from informing the contracting party or beneficial owner that a report has been or may be filed. Financial intermediaries must also maintain adequate documentation (Art. 7), implement organisational measures (Art. 8), and affiliate with a recognised SRO or be directly supervised by FINMA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ch-finma-banking-act-bankengesetz-1934"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ch-dlt-act-ledger-based-securities-co-973d",
    "title": "Swiss DLT Act - Code of Obligations Art. 973d-973g (ledger-based securities)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.1.0",
    "last_updated": "2026-07-10",
    "bluf": "The Swiss DLT Act introduced ledger-based securities into the Code of Obligations (CO). Article 973d defines a ledger-based security as a right that, under a registration agreement, is registered in a securities ledger and may be exercised and transferred only via that ledger, and sets four requirements the ledger must meet, including giving creditors but not the obligor power of disposal and securing the ledger's integrity. Article 973e provides that the obligor must perform only to the creditor indicated in the ledger and protects good-faith acquirers, Article 973f makes transfer subject to the registration agreement, and Article 973g allows collateralisation without transfer where the collateral is visible in the ledger and only the collateral recipient can dispose of it on default.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ch-finsa-financial-services-act-2019",
      "ch-fmia-finfrastrukturgesetz-2015"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ch-fadp-2023",
    "title": "Switzerland nFADP 2023 - Revised Federal Act on Data Protection and FDPIC Enforcement",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Switzerland's revidiertes Bundesgesetz über den Datenschutz (revDSG) / loi fédérale révisée sur la protection des données (LPD révisée) / legge federale riveduta sulla protezione dei dati (LPD riveduta) - commonly referred to in English as the revised Federal Act on Data Protection (nFADP - new Federal Act on Data Protection, also abbreviated revFADP), came into force on 1 September 2023. The nFADP replaced the original Federal Act on Data Protection of 19 June 1992 (SR 235.1 - FADP 1992). Switzerland is not an EU member state but is closely integrated with the EU through a series of bilateral agreements. The nFADP was substantially revised to align with the EU General Data Protection Regulation (GDPR) framework, thereby protecting Switzerland's EU adequacy status (Switzerland first obtained EU adequacy in 2000; the new law protects against re-review of that adequacy status under GDPR). The enforcement authority is the Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB) / Préposé fédéral à la protection des données et à la transparence (PFPDT) / Incaricato federale della protezione dei dati e della trasparenza (IFPDT) - referred to in English as the Federal Data Protection and Information Commissioner (FDPIC). Key features of the nFADP: (1) Applies only to natural persons (unlike GDPR, which also covers legal persons in some Swiss cantons' laws); (2) 'Controller' (Verantwortlicher / responsable du traitement) and 'Processor' (Auftragsbearbeiter / sous-traitant) terminology; (3) Sensitive personal data: racial or ethnic origin; political opinions, activities, or beliefs; religious, ideological, or trade union-related views or activities; health and intimacy (including sexual orientation); administrative or criminal proceedings and sanctions; social welfare measures; (4) Eight principles: lawfulness, good faith, proportionality, purpose limitation, accuracy, data security, privacy by design and by default, and accountability; (5) Data subject rights: access, correction, erasure, portability, and objection to automated decision-making; (6) Data Protection Impact Assessment (DPIA) - required for high-risk processing; (7) Privacy notice - required before collection; (8) Mandatory breach notification to the FDPIC for breaches likely to cause a high risk to data subjects; (9) Data Processing Register - controllers and processors must maintain a register of processing activities (with exceptions for enterprises with fewer than 250 employees that do not process high-risk data); (10) Representative - overseas controllers who regularly process Swiss resident data must designate a Swiss representative; (11) Criminal penalties - intentional violations may result in personal criminal liability of up to CHF 250,000 (fine against individuals, not legal entities); (12) No administrative fines on legal entities - unlike GDPR, the nFADP imposes no fines on companies; fines are directed at responsible individuals. The nFADP does not contain an EU GDPR equivalent right to data portability as a standalone right - portability may be exercised but is conditional on the data being processed by automated means and the data subject having previously provided the data. Switzerland additionally has a distinct adequacy relationship with the EU and is not subject to GDPR Chapter V mechanisms for EU-to-Switzerland transfers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-adequacy-decisions-article-45",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ch-federal-act-on-public-procurement-boeb-revised-2021",
    "title": "Switzerland Federal Act on Public Procurement (Bundesgesetz uber das offentliche Beschaffungswesen / BoeB, revised version effective 1 January 2021)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Swiss Federal Act on Public Procurement (Bundesgesetz uber das offentliche Beschaffungswesen / BoeB in German, Loi federale sur les marches publics / LMP in French, Legge federale sugli acquisti pubblici / LAPub in Italian) in its revised version effective 1 January 2021 is the principal Swiss federal statute governing procurement of goods, services, and construction works by federal-level contracting authorities. The 2021 revision was a comprehensive modernisation of the prior 1994 Act aligning Switzerland with the WTO Government Procurement Agreement (GPA) 2012 and with the EU procurement directives 2014/24/EU and 2014/25/EU principles, and harmonising with the parallel cantonal Intercantonal Agreement on Public Procurement (Interkantonale Vereinbarung uber das offentliche Beschaffungswesen / IVoeB) which was revised in parallel and applies to cantonal and municipal procurement. The harmonised federal-cantonal framework is a distinctive Swiss feature ensuring procurement procedural consistency across the three levels of government. The revised BoeB introduced substantive reforms including (a) shift from price-focused award (lowest price) to quality-focused award (most advantageous tender / wirtschaftlich gunstigstes Angebot) considering price, quality, sustainability, and innovation, (b) mandatory consideration of sustainability criteria including environmental, social, and life-cycle costs, (c) mandatory dialogue procedures for complex acquisitions, (d) strengthened debarment regime for ethically problematic suppliers, (e) integrity programmes for high-value procurements, and (f) digitalisation provisions enabling full electronic procurement. The Act specifies procurement methods including open procedure (offenes Verfahren, default for at-threshold procurements), selective procedure (selektives Verfahren, with prequalification), competitive negotiation procedure (Verfahren mit Verhandlungen), competitive dialogue (Dialog), and free-hand procedure (Freihandiges Verfahren, sole-source under prescribed exceptions). The Bundesamt fuer Bauten und Logistik (BBL / Federal Office for Buildings and Logistics) is the central federal procurement authority operationally responsible for many federal acquisitions, with simap.ch as the federal e-procurement platform shared with cantons. Switzerland is a long-standing party to the WTO GPA 2012 and operates within the broader EFTA / EU bilateral framework on procurement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ch-finma-banking-act-bankengesetz-1934",
    "title": "Switzerland Banking Act (Bankengesetz) - SR 952.0 - FINMA Licensing and TBTF Requirements",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Switzerland's Banking Act (SR 952.0) requires FINMA authorisation for all banking activities in Switzerland (Art 3: CHF 10M minimum paid-up capital), mandates depositor protection via esisuisse (CHF 100,000 per person per bank), and imposes stringent too-big-to-fail (TBTF) capital, liquidity, and resolution requirements on systemically important banks (UBS, PostFinance, Raiffeisen, ZKB).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-brrd-bank-recovery-resolution-directive-2014-59",
      "switzerland-finma-crypto-guidance-2018-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ch-finma-circular-2018-3-outsourcing-banks-insurers",
    "title": "FINMA Circular 2018/3 - Outsourcing for Banks and Insurers (Switzerland)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "FINMA Circular 2018/3, Outsourcing - banks and insurers, is the Swiss Financial Market Supervisory Authority circular governing outsourcing by banks, securities dealers and, for the first time under this circular, insurance companies. It entered into force on 1 April 2018, replacing the previous outsourcing rules issued in 1999 when outsourcing was less widespread. The circular takes a principle-based and technology-neutral approach under which institutions must address their specific business models and risks: the institution itself assesses the materiality (significance) of an outsourcing through self-assessment, maintains a documented risk analysis of outsourced activities, selects and vets service providers carefully, and retains oversight together with audit and inspection rights over the outsourced function. Outsourcing beyond Switzerland attracts enhanced scrutiny, particularly regarding company restructuring and resolution, since Swiss resolution authorities must retain access to the outsourced functions and data. The circular permits principle-oriented treatment of intra-group outsourcing and clarifies the rules governing outsourcing of risk management and compliance functions. Banks received a five-year transition period for existing outsourcing arrangements, while insurers must comply from the effective date for newly licensed business or business-plan changes. For banks, the outsourcing requirements are supplemented by FINMA Circular 2023/1, Operational Risks and Resilience - banks, in force since 1 January 2024 with a two-year transition to the start of 2026. FINMA Circular 2018/3 is the Swiss anchor for cloud adoption by financial institutions and the reference against which Swiss banks and insurers assess cloud and BPO providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "scope_anchor",
        "materiality_self_assessment",
        "cross_border_outsourcing",
        "intra_group_and_control_functions",
        "circular_2023_1_supplement",
        "eu_peer_frameworks",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ch-finma-banking-act-bankengesetz-1934",
      "eu-eba-cloud-outsourcing-guidelines-2019",
      "eu-dora-cloud-third-party-ict-2022-2554"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ch-finsa-financial-services-act-2019",
    "title": "Switzerland Financial Services Act 2019 (FinSA) - Client Protection and Market Conduct",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Swiss Financial Services Act (FinSA - Finanzdienstleistungsgesetz, SR 950.1), in force January 2020, establishes harmonised conduct rules for all financial service providers in Switzerland, regardless of legal form. FinSA requires client classification (retail, professional, institutional), suitability and appropriateness assessment, prospectus and Key Information Document (BIB/KID) preparation for financial instruments offered to retail clients, registration in the Adviser Register (Beraterregister) for client-facing staff, affiliation with an ombudsman, and organisational conduct requirements. FinIA (Financial Institutions Act, SR 954.1) simultaneously established licensing for portfolio managers, trustees, fund management companies, and securities firms under FINMA supervision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-priips-regulation-1286-2014-kid",
      "eu-ucits-directive-2009-65"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ch-fmia-finfrastrukturgesetz-2015",
    "title": "Switzerland Financial Market Infrastructure Act 2015 (FinfraG/FMIA) - SR 958.1",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Swiss Financial Market Infrastructure Act (Finanzmarktinfrastrukturgesetz, FinfraG; SR 958.1) regulates the operation of financial market infrastructures and market conduct in securities and derivatives markets in Switzerland, with FINMA as the principal supervisory authority. Art. 2 defines the scope, covering stock exchanges, multilateral trading facilities, central counterparties, central securities depositories, trade repositories, and payment systems. Trading venues - including stock exchanges - must be authorised by FINMA under Art. 26 and meet ongoing requirements for market integrity, transparent and non-discriminatory access, and adequate risk management. The Act implements the G20 derivatives reform agenda in Switzerland: Art. 93 requires clearing of standardised OTC derivatives through a central counterparty; Art. 104 requires reporting of derivative transactions to a trade repository; and Art. 109 introduces risk mitigation obligations for uncleared derivatives. Art. 117 and Art. 142 address market manipulation and insider trading respectively, imposing criminal sanctions for serious market misconduct. Systemically important payment systems are subject to oversight by the Swiss National Bank (SNB) under Art. 16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ch-finma-banking-act-bankengesetz-1934",
      "ch-finsa-financial-services-act-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ch-gene-technology-act-gta-2003",
    "title": "Switzerland Federal Act on Non-Human Gene Technology (Gene Technology Act, GTA) of 21 March 2003, SR 814.91",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Swiss Gene Technology Act (SR 814.91) governs handling of genetically modified non-human organisms to protect humans, animals, the environment and biological diversity. Art 1 sets the protective purpose; Art 2 establishes the precautionary and polluter-pays principles; Art 6 requires that organisms be handled so they cannot endanger people, animals, the environment or biological diversity; Art 11 requires federal authorisation for release for experimental purposes; Art 12 requires Confederation authorisation before placing GMOs on the market; and Art 17 requires products to be labelled as genetically modified for the recipient.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "ch-kartellgesetz-wettbewerbsrecht-1995",
    "title": "Switzerland Cartel Act 1995 (KG/LCart) - SR 251 Competition Law",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Swiss Cartel Act (Kartellgesetz, KG; SR 251) prohibits anti-competitive agreements, abuse of dominant market positions, and regulates mergers that significantly impede effective competition in Switzerland, administered by the Competition Commission (Wettbewerbskommission, WEKO). Art. 5 prohibits agreements between undertakings that significantly restrict competition, with a distinction between per se illegal hardcore restrictions (price-fixing, market-sharing, and bid-rigging between competitors under Art. 5(3); resale price maintenance and absolute territorial protection between suppliers and distributors under Art. 5(4)) and other agreements that are illegal unless justified. Art. 7 prohibits abuse of a dominant market position, with examples including predatory pricing, tying, price discrimination, and refusal to deal. Art. 10 establishes a mandatory merger control regime for concentrations above the notification threshold (combined Swiss revenue of CHF 100 million and individual revenues of at least CHF 10 million each for both parties, or if one party has been the subject of an Art. 7 investigation). The Federal Council may impose direct sanctions up to 10% of turnover for serious competition law violations under Art. 49a without requiring a prior decision establishing the infringement. Art. 30 empowers WEKO to investigate suspected infringements and issue orders binding on the undertakings concerned.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tfeu-article-102-abuse-of-dominance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ch-kvg-krankenversicherungsgesetz-1994",
    "title": "Switzerland Federal Health Insurance Act 1994 (KVG/LAMal) - SR 832.10",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Swiss Federal Health Insurance Act (Krankenversicherungsgesetz, KVG; SR 832.10) establishes the compulsory basic health insurance (Grundversicherung/assurance de base) regime in Switzerland, requiring all persons domiciled in Switzerland to insure themselves for the basic benefit package within three months of establishing residence or birth. Art. 3 mandates that every person residing in Switzerland must take out and maintain basic health insurance coverage. Art. 8 specifies that eligible insurers (registered social health insurers, Krankenkassen) must accept all persons who apply and may not charge risk-differentiated premiums for the basic benefit package. The mandatory benefit catalogue is defined in Arts. 24-31, covering general practitioner and specialist consultations, inpatient hospital treatment, medications on the specialty list, and defined preventive services. Art. 44 prohibits social health insurers from generating profit on the basic insurance business and requires that premium revenue be returned to insured persons through benefits. Art. 61 permits insurers to set community-rated premiums by region and age group but prohibits differentiation by health status or sex. The Federal Office of Public Health (FOPH/BAG) approves the annual premium increases and administers the means-tested premium subsidy (Prämienverbilligung) regime for low-income households under Arts. 65-66.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-qms",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ch-ndsg-2023",
    "title": "Switzerland Federal Act on Data Protection 2023 (nDSG / revFADP) - National Data Protection",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Switzerland's revised Bundesgesetz über den Datenschutz (nDSG - neues Datenschutzgesetz / revFADP - revised Federal Act on Data Protection, SR 235.1), passed by the Swiss Federal Assembly on 25 September 2020 and entering into force on 1 September 2023, is Switzerland's primary federal data protection legislation replacing the prior Federal Act on Data Protection of 19 June 1992 (altDSG / SR 235.1 old). Switzerland is not an EU member state and is not subject to the EU GDPR directly; however, the nDSG was substantially redesigned to align with EU GDPR principles to preserve and strengthen the EU's adequacy decision for Switzerland. The European Commission has maintained Switzerland's adequacy status under both the old DSG and, following a review, under the nDSG. The nDSG applies to private persons (individuals and legal entities) and federal bodies (cantonal bodies are governed by cantonal data protection laws). Enforcement: the Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB - Federal Data Protection and Information Commissioner) is Switzerland's independent federal data protection and freedom of information authority. The EDÖB is not a member of the EU EDPB but engages in cooperation with EU data protection authorities through bilateral arrangements and the Council of Europe. The nDSG significantly strengthens Swiss data protection law compared to the prior altDSG: it introduces mandatory Data Protection Officers (for certain categories of controllers), mandatory Data Protection Impact Assessments (DPIA equivalent), mandatory breach notification to the EDÖB, new data subject rights (including right to explanation for automated decisions), stricter requirements for profiling, and substantially higher fines. Key differences from GDPR: (1) The nDSG does not apply to legal entities - only natural persons' data is protected (GDPR protects only natural persons; the nDSG alignment here is intentional); (2) Criminal sanctions: the nDSG provides criminal penalties (fines up to CHF 250,000) for wilful violations by responsible individuals, not administrative fines as under GDPR; (3) Age of consent: the nDSG does not have a specific age of consent for information society services equivalent to GDPR Art. 8 - consent capacity follows general Swiss civil law (capacity to act - Handlungsfähigkeit - from age 18, with minors of sufficient discernment capable of some consent); (4) Transfer mechanisms: Switzerland maintains its own adequacy country list for international data transfers; EU Standard Contractual Clauses may be used with Swiss-specific adaptations as transfer mechanisms for Switzerland; (5) Sensitive data: the nDSG protects a broader category of sensitive data than GDPR, including data on social assistance, administrative and criminal proceedings, and membership of religious organisations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-adequacy-decisions-article-45",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ch-nfadp-2023",
    "title": "Federal Act of 25 September 2020 on Data Protection (Data Protection Act, FADP)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The revised Swiss Federal Act on Data Protection (nFADP) governs the processing of personal data by private entities and federal bodies, strengthening data protection principles and aligning them more closely with the EU GDPR. It mandates that controllers and processors ensure data security appropriate to the risk through technical and organizational measures (Art. 8) and requires notification to the FDPIC for high-risk data security breaches (Art. 24).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ch-or-employment-code-of-obligations",
    "title": "Switzerland Code of Obligations - Employment Contract Law (Art. 319-362 OR) SR 220",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Swiss Code of Obligations (Obligationenrecht, OR; SR 220) governs individual employment contracts in Switzerland through Arts. 319 to 362, providing mandatory minimum standards for the formation, performance, and termination of employment relationships. Art. 319 defines the individual employment contract: the employee undertakes to perform work for the employer for a limited or indefinite period in return for a salary. Art. 328 imposes a comprehensive duty of care on the employer to protect the personality, health, and integrity of the employee, prohibiting harassment and requiring non-discriminatory working conditions. Art. 321d permits the employer to issue instructions concerning the performance of work, but limits the right to give instructions affecting the employee's personal life. Art. 335 governs termination with notice: indefinite employment contracts may be terminated by either party with statutory minimum notice periods (one month in the first year, two months in the second to ninth year, and three months thereafter) or longer contractual periods. Art. 336 voids dismissal that is abusive - including dismissal for exercising a constitutional right, for reasons personal to the employee, or in retaliation for good-faith complaints about workplace misconduct. Art. 337 permits immediate termination for good cause in exceptional circumstances. Arts. 361 and 362 identify the provisions that cannot be waived or modified to the detriment of the employee, providing a comprehensive list of mandatory employee protections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "chaps-rtgs-high-val-london",
    "title": "CHAPS RTGS (Payments)",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "CHAPS (Clearing House Automated Payment System) is the UK's high-value, real-time gross settlement (RTGS) payment system. it is used for critical financial transactions, such as the interbank house purchases and the corporate the trades, ensuring the immediate and the irrevocable settlement of the funds through the Bank of England's the reserve accounts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bis-principles-fmi-2012",
      "bcbs-principles-operational-resilience",
      "cpmi-iosco-cyber-resilience-fmi",
      "iso-20022-mx-messaging",
      "swift-csp-quality",
      "pra-ss1-21-resilience"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "chile-data-protection-bill-2024-new-law",
    "title": "Ley Chile - Biblioteca del Congreso Nacional Ley Chile - Biblioteca del Congreso Nacional Ley Chile Este proceso demora demasiado, es probable que su conexión esté muy lenta o que su navegador no sea compatible con nuestra aplicación",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Chile's 2024 personal data protection reform (Ley que regula la proteccion y el tratamiento de los datos personales y crea la Agencia de Proteccion de Datos Personales) updates Law 19.628 with lawful bases for processing, data-subject rights including access, rectification, erasure, and portability, cross-border transfer rules, and creates an independent Data Protection Agency; controllers must comply with consent, breach-notification, and DPIA obligations on penalty of administrative fines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "chile-ley-21383-2021-neurorights-constitutional-amendment",
    "title": "Chile Ley No. 21,383 (2021) Constitutional Amendment Establishing Neurorights",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2021-10-25",
    "bluf": "Ley No. 21,383 of 25 October 2021 amended Article 19 paragraph 1 of the Constitution of the Republic of Chile to recognise the development of science and technology at the service of persons and to confer constitutional protection of physical and mental integrity in respect of the increase of scientific and technological capacities. The reform makes Chile the first country in the world to establish constitutional protections for neurorights, recognising brain activity and the information derived from it as a protected dimension of personal integrity. The reform was the product of a multi-year process led by the Senate Committee on Future Challenges, Science, Technology and Innovation in collaboration with the Columbia University NeuroRights Foundation and was approved by the Chamber of Deputies on 7 September 2021.\n\nThe constitutional reform delegated detailed regulation of neurorights to ordinary law. Boletín 13.828-19 is the pending bill in the National Congress that would establish detailed rules on neurorights including the right to mental privacy, the right to personal identity, the right to free will, the right to equitable access to mental augmentation technologies, and the right to protection from algorithmic bias. The Supreme Court of Chile issued a precedent-setting decision on 9 August 2023 (Causa Rol 90.456-2022) ordering the manufacturer of a consumer brain-computer interface device (Emotiv Inc.) to delete neural data collected from a Chilean researcher and recognising neural data as protected under the Article 19 paragraph 1 constitutional amendment. The decision is the first global judicial application of constitutional neurorights protections to a commercial neurotechnology device.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles-2019-2024-update-trustworthy-ai"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "chile-mining-code-1983",
    "title": "Código de Minería (Ley N° 18.248), de 1983",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes the legal framework for the acquisition, maintenance, and forfeiture of mining concessions in Chile, including exploration and exploitation rights, environmental obligations, and oversight by SERNAGEOMIN. Key provisions are defined in Article 61 and Article 67 regarding concession renewal and abandonment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "chile-mining-safety-regulations-ds-132-2004",
    "title": "Reglamento sobre Orden, Higiene y Seguridad Minera, Decreto Supremo N° 132, de 2004, del Ministerio de Minería",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes mandatory safety, health, and operational protocols for all mining operations in Chile, including explosives handling, ground control, ventilation, and emergency response. It applies to all underground and surface mining activities under the jurisdiction of SERNAGEOMIN, with key requirements in Title III (Explosives), Title V (Ventilation), and Title VII (Emergency Plans).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "chile-mining-code-1983",
      "ifc-performance-standards-2012-mining",
      "gri-14-mining-sector-standard-2022",
      "eiti-standard-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "chile-sernac-consumer-protection-law-19496",
    "title": "Chile Law 19.496 on Consumer Protection - SERNAC Rights and Collective Actions",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Chile's Ley de Proteccion del Consumidor (Law 19.496, 1997, as amended through Law 21.398 of 2022) establishes consumer rights, prohibits abusive contract clauses, mandates information disclosure, and empowers the National Consumer Service (SERNAC) to file collective class actions; Law 21.081 (2019) granted SERNAC sanction powers of up to UF 750 per violation plus collective lawsuits; Law 21.398 (2022) introduced mandatory product recall and right of withdrawal for defective goods within 30 days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "chile-data-protection-bill-2024-new-law"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "china-algorithm-recommendation-2022",
    "title": "Internet Information Service Algorithmic Recommendation Management Provisions",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "These provisions require providers of algorithmic recommendation services within the People's Republic of China to uphold mainstream values, protect user rights, and prevent the generation of illegal or harmful information. Key requirements include obtaining user consent, providing options to disable algorithmic recommendations (Article 17), and filing algorithm details with the Cyberspace Administration of China (Article 24).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "nist-ai-rmf-1-0",
      "nist-sp-1270-managing-ai-bias"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "china-algorithm-recommendation-regulation-2022",
    "title": "Internet Information Service Algorithmic Recommendation Management Provisions (2022)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation applies to all providers of algorithmic recommendation services within the People's Republic of China, mandating transparency about the basic principles of their algorithms and providing users with options to select, modify, or delete user tags and to opt-out of personalized recommendations (Article 17). It also establishes strict prohibitions on content that endangers national security, disrupts economic order, or spreads false information (Article 6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "china-deep-synthesis-regulation-2022",
      "china-genai-regulation-2023",
      "iso-42001-transparency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "china-algorithm-recommendation-regulations-2022",
    "title": "China Algorithm Recommendation Regulations 2022 (CAC) - Algorithmic Recommendation Service Providers Registration, Prohibition on Illegal Price Discrimination, Addictive Algorithm Features Disabled for Minors, Transparent Recommendation Mechanisms and User Opt-Out Rights",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation applies to algorithmic recommendation service providers operating in China and mandates transparency in recommendation mechanisms, prohibits illegal price discrimination, requires user opt-out rights, disables addictive algorithm features for minors, and enforces registration with the Cyberspace Administration of China (CAC). Key obligations are derived from the instrument’s core provisions on fairness, accountability, and user protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "china-network-security-law-2017",
      "australia-ai-ethics-framework-2019",
      "eu-data-governance-act-2022-cloud-data-sharing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "china-anti-monopoly-law-amended-2022",
    "title": "Anti-Monopoly Law of the People's Republic of China (2022 Amendment)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This law strengthens China's antitrust regime by significantly increasing penalties for violations, introducing a 'safe harbor' for certain vertical agreements, and explicitly prohibiting undertakings from using data, algorithms, technology, or platform rules to engage in monopolistic acts, as stipulated in Article 9. It applies to all undertakings operating in or affecting the Chinese market, with a specific focus on the digital economy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-competition-assessment-principles-2019",
      "us-ftc-act-section-5-unfair-competition"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "china-cac-algorithm-recommendation-measures-2022",
    "title": "CAC Algorithm Recommendation Measures 2022 - Provisions on the Management of Algorithmic Recommendations",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The CAC Algorithm Recommendation Measures 2022 require algorithmic recommendation service providers to provide transparency, user opt-out rights, and prohibit price discrimination, as stated in Article 5. This regulation applies to all algorithmic recommendation service providers operating in China.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "asean-guide-ai-governance-ethics-2020",
      "australia-ai-ethics-framework-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "china-cac-deep-synthesis-provisions-2022",
    "title": "Provisions on the Management of Deep Synthesis Internet Information Services",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The CAC Deep Synthesis Provisions 2022 require internet information service providers to label deep synthesis content, register synthetic media, and prohibit the dissemination of illegal deepfakes, as stated in Article 5 and Article 10 of the provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-600-1-gen-ai-profile",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "china-cac-generative-ai-measures-2023",
    "title": "Interim Measures for the Management of Generative Artificial Intelligence Services",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The regulation applies to providers of generative AI services within China and mandates compliance with content security, algorithm transparency, training data legality, watermarking of AI-generated content, and registration with the Cyberspace Administration of China (CAC). Key obligations are established under Article 4 (content compliance), Article 7 (training data), Article 12 (algorithm transparency), and Article 15 (watermarking).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-42001-transparency",
      "iso-42001-risk-assess",
      "australia-ai-ethics-framework-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "china-cac-security-assessment-outbound-2022",
    "title": "China CAC Security Assessment for Outbound Data Transfers 2022",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires organizations transferring personal information of 100,000 or more individuals, or important data, outside of China to undergo a security assessment and file with the Cyberspace Administration of China (CAC), as stated in Article 3 of the Measures for Security Assessment of Outbound Data Transfers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "apec-cbpr-cross-border-privacy-rules-system",
      "iso-27002-2022-technological-controls"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "china-carbon-ets-administrative-regulations-2024",
    "title": "Interim Regulations on the Administration of Carbon Emissions Trading (State Council Decree No. 779)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "These regulations establish the legal framework for China's national carbon emissions trading scheme (ETS), mandating that key emitting entities annually emitting over 25,000 tonnes of CO2 equivalent must monitor, report, and verify their emissions, and surrender sufficient emission allowances to cover their verified emissions by a specified deadline (Article 10, Article 19).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "china-cbirc-c-ross-ii-solvency-2022",
    "title": "Solvency Regulatory Rules for Insurance Companies (II) - C-ROSS Phase II",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation establishes the China Risk-Oriented Solvency System (C-ROSS) Phase II, a comprehensive three-pillar framework mandating quantitative capital requirements, qualitative risk management supervision, and market discipline through public disclosure for all insurance companies in China. The core requirement, outlined in Rule No. 1, is to maintain a Core Solvency Adequacy Ratio of ≥50% and a Comprehensive Solvency Adequacy Ratio of ≥100%.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "china-construction-law-1997-amendment-2019",
    "title": "China Construction Law 1997 (2019 Amendment) - Jianzhufazhi",
    "domain": "Construction & Real Estate",
    "version": "2019 Amendment (effective April 23, 2019)",
    "last_updated": "2026-05-09",
    "bluf": "China's Construction Law (Zhonghua Renmin Gongheguo Jianzhu Fa, enacted 1997, most recently amended 2019) is the primary PRC legislation governing construction activities; it establishes mandatory qualification requirements for construction enterprises (Grade A/B/C/D), mandatory construction permits for projects above specified thresholds, safety supervision requirements, quality inspection obligations, contractor and subcontractor liability, and the legal framework for construction contracts - forming the mandatory legal baseline for all construction activities in mainland China including projects by foreign-invested enterprises.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-2015-quality-management-construction",
      "ilo-safety-health-construction-convention-167-1988"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "china-copyright-law-2021-amendment",
    "title": "Amendment to the Copyright Law of the People's Republic of China (2021)",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The 2021 amendment to China's Copyright Law strengthens protection for digital and AI-generated works, increases statutory damages from 500,000 RMB to 5 million RMB, introduces punitive damages up to five times actual damages for willful infringement (Article 54), and clarifies liability for network service providers in online content dissemination (Article 54, Article 24). It applies to all creators, rights holders, digital platforms, and AI developers operating in or targeting the Chinese market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-1886-2024-literary-artistic-works",
      "dmca-safe-harbor",
      "eu-copyright-directive-art-17"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "china-data-security-law-2021",
    "title": "Data Security Law of the People's Republic of China (2021)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This law establishes a mandatory data classification and grading system for all data handlers in China, imposing strict protection obligations for 'Important Data' and 'National Core Data' as defined by Article 21. It requires regular risk assessments, security reviews, and imposes restrictions on the cross-border transfer of Important Data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "china-deep-synthesis-provisions-2023",
    "title": "Provisions on Administration of Deep Synthesis Internet Information Services (2023)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Provisions require providers of deep synthesis (e.g., deepfake) services in China to label synthetic content, authenticate user identities, and prohibit dissemination of illegal information. Applies to all internet information service providers using deep learning or other AI to generate or edit text, audio, video, or images (Article 4, Article 6, Article 12).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-transparency",
      "nist-ai-100-4-redteam",
      "ai-agent-collision-logic"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "china-deep-synthesis-regulation-2022",
    "title": "Provisions on Administration of Deep Synthesis Internet Information Services",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This regulation requires providers of deep synthesis (e.g., deepfake) services in China to conspicuously label AI-generated content that may cause public confusion or misidentification, and to obtain separate consent from individuals whose biometric information is edited. As per Article 16 and 17, providers must add non-obstructive labels to generated content and enable functionality for such labeling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-42001-transparency",
      "nist-ai-100-4-synthetic-content",
      "in-meity-synthetic-content"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "china-deep-synthesis-regulations-2023",
    "title": "Provisions on the Administration of Deep Synthesis of Internet-based Information Services (China Deep Synthesis Regulations 2023)",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "These regulations require all providers of deep synthesis services in China to label AI-generated content, obtain explicit consent before using individuals' faces or voices, prohibit malicious deepfakes, enforce real-name registration, and conduct content reviews. Key obligations are derived from the requirement to ensure traceability and accountability of synthetic media.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "china-network-security-law-2017"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "china-express-delivery-service-regulations-2018",
    "title": "China Express Delivery Service Regulations 2018 - State Post Bureau Licensing, Consumer Rights and Last-Mile Delivery",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "China's Express Delivery Service Regulations 2018 (Order No. 697 of the State Council, effective 1 May 2018, revised 2022) administered by the State Post Bureau (SPB) regulate the fast-growing express delivery industry; require all express delivery enterprises to hold an SPB Express Delivery Business Licence (kuaidi jingying xukezheng); mandate real-name registration (shiming zhuce) for all senders; set 72-hour standard and 24-hour urgent delivery completion targets; impose package inspection requirements under Public Security cooperation; require enterprise-level complaint handling within 7 days; and impose fines up to CNY 100,000 for unlicensed operations and data security violations; express delivery sector handled 132.1 billion parcels in 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brazil-antt-road-freight-law-10233-2001"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "china-food-safety-law-2021-amendment",
    "title": "State Council Implementation Regulations on the Amendment to the People's Republic of China Food Safety Law (2021) - Provisions on Online Food Ordering Platform Liability, Special Dietary Food Registration, Agricultural Product Traceability, School Canteen Management and Administrative Penalty Increases",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation mandates online food ordering platforms to verify merchant资质 (business licenses and food operation permits), enforce traceability for agricultural products, require special dietary foods to undergo registration or filing, strengthen hygiene and supervision in school canteens, and increases administrative penalties for violations. Key obligations are established under Article 62 (platform liability), Article 80 (special dietary food), Article 34 (traceability), and Article 134 (penalty increases) of the amended Food Safety Law and its implementing regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004",
      "iso-13009-beach-mgmt",
      "alcohol-service-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "china-gb-18384-2020-electric-vehicle-safety-standard",
    "title": "China GB 18384-2020 - Electric Vehicle Safety Standard and GB Standards for New Energy Vehicles",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "China's GB 18384-2020 (Electric Vehicles Safety Requirements, effective 1 January 2021) is the mandatory national standard for battery electric vehicle (BEV) and fuel cell electric vehicle (FCEV) safety in China's domestic market and for vehicles exported from China. GB 18384-2020 replaced GB/T 18384-2015 and aligns with UN ECE R100 with China-specific requirements. The broader New Energy Vehicle (NEV) mandatory standard suite includes: GB 18384-2020 (EV safety), GB 18385-2021 (EV performance), GB 18386.1-2021 (EV energy consumption), GB/T 27930-2015 (DC charging interface CHAdeMO), GB/T 20234.2-2015 (AC charging), GB/T 20234.3-2015 (DC fast charging GB/T standard), and GB 38031-2020 (EV traction battery safety). Manufacturers exporting to China must obtain China Compulsory Certification (CCC) under the 3C certification scheme administered by CNCA (Certification and Accreditation Administration) covering all mandatory GB standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-general-safety-regulation-2019-2144-automated-vehicles",
      "unece-regulation-156-software-update-management-vehicles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "china-genai-regulation-2023",
    "title": "Interim Measures for the Management of Generative Artificial Intelligence Services",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This regulation applies to providers offering generative AI services to the public within the People's Republic of China, mandating adherence to socialist core values, ensuring the legality of training data, and implementing content labeling. Providers must conduct security assessments and file algorithms with the state before public deployment, as stipulated in Articles 4, 7, and 17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "nist-ai-100-4-synthetic-content",
      "eu-ai-act-high-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "china-generative-ai-interim-measures-2023",
    "title": "Interim Measures for the Administration of Generative Artificial Intelligence Services",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "These measures apply to providers offering generative AI services to the public within the People's Republic of China, mandating adherence to socialist core values, prevention of illegal content generation, clear labeling of AI-generated content, and a mandatory security assessment for services with public opinion attributes or social mobilization capabilities (Articles 4, 12, 17).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "china-algorithm-recommendation-2022",
      "china-deep-synthesis-regulation-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "china-generative-ai-measures-2023",
    "title": "Measures for the Management of Generative Artificial Intelligence Services",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "These Measures require all public-facing generative AI services operating in China to undergo security assessments, register algorithmic models, ensure training data respects intellectual property and factual accuracy, align outputs with Core Socialist Values, and implement real-time content moderation. Applies to all providers of generative AI services available to the public within China.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "china-network-security-law-2017"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "china-global-ai-governance-initiative-2023",
    "title": "China Global AI Governance Initiative 2023 - PRC International AI Governance Framework",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The Global AI Governance Initiative (全球人工智能治理倡议, GAIGI) was released by the People's Republic of China on October 18, 2023, coinciding with the Third Belt and Road Forum for International Cooperation in Beijing; the Initiative represents China's formal position on international AI governance and was subsequently promoted at international forums including the UN; the GAIGI sets out China's six core positions on global AI governance: (1) People-centred development - AI should be developed to enhance human well-being and not to threaten human existence or rights; AI development should be inclusive and benefit all countries; (2) Adherence to AI safety principles - AI systems must be controllable and correctable; humans must maintain oversight and control of AI; AI must not be used to undermine national sovereignty or territorial integrity; (3) Respecting national sovereignty in AI governance - each country has the sovereign right to choose its own AI development path and governance model; AI governance should not serve as a pretext for technological hegemony; (4) Bridging the AI development gap - developed countries should support developing nations in building AI capacity; AI benefits should not be monopolised by a few countries or companies; (5) AI used for good - AI should not be used for autonomous weapons that threaten international peace; nuclear weapons, biological weapons, chemical weapons, radiological weapons (NBC-R) must not be developed using AI; (6) International cooperation under the UN framework - global AI governance should primarily be conducted through the United Nations framework; the UN should play a central role in developing international AI governance norms; GAIGI directly positions China's approach in contrast to the US-led Bletchley Summit approach, emphasising multilateral UN-based governance over summit-based Western-led governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/china-global-ai-governance-initiative-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-ai-safety-2023",
      "un-global-digital-compact-ai-governance-2024",
      "china-generative-ai-interim-measures-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "china-hgrac-2019-state-council-order-717",
    "title": "China Regulations on the Management of Human Genetic Resources (State Council Order No. 717, 2019)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2019-06-10",
    "bluf": "China's Regulations on the Management of Human Genetic Resources were promulgated by the State Council as Order No. 717 on 28 May 2019 and entered into force on 1 July 2019. The Regulations are administered by the Human Genetic Resources Administration of China (HGRAC) under the Ministry of Science and Technology (MOST). The Regulations replace and consolidate the Interim Measures for the Administration of Human Genetic Resources (1998). They define human genetic resources as organs, tissues, cells, and other genetic materials containing the human genome, genes, and gene products from Chinese populations, and the derived data. The Regulations apply extraterritorially to any collection, preservation, research, utilisation, or external provision of human genetic resources of Chinese populations.\n\nThe Regulations establish four core administrative approvals: approval for collection of important human genetic resources (Article 11); approval for preservation of human genetic resources (Article 12); approval for international cooperative research (Article 22); and approval for external provision or open use (Article 27). Foreign entities are prohibited from collecting and preserving human genetic resources in China; international cooperation is permitted only through Chinese counterparts. Article 29 requires advance filing for cross-border information sharing (export of de-identified data) that may affect public health, national security, or public interest. The Implementing Rules issued by MOST on 1 July 2023 further specified procedural requirements including documentation, timelines, and penalties. Violations may result in fines, confiscation of materials and gains, and listing on credit registries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nagoya-protocol-genetic-resources-2010",
      "cartagena-protocol-biosafety-2000",
      "who-somatic-genome-editing-guidelines-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "china-intelligent-connected-vehicle-regulations-2022",
    "title": "China Intelligent Connected Vehicle (ICV) Access, Cybersecurity and OTA Regulation - MIIT Access Opinions (2021), MIIT/SAMR Admission and OTA Notice (2025) and GB Cybersecurity/OTA Standards",
    "domain": "Automotive & Mobility",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "China does not govern intelligent and connected vehicles (ICVs) through a single consolidated instrument titled 'SAC/TC 114, 2022' with internal clauses. Instead, ICV access, cybersecurity, functional safety, over-the-air (OTA) updates and data protection are governed by a combination of instruments: the MIIT 'Opinions on Strengthening the Access Management of Intelligent Connected Vehicle Manufacturers and Products' (2021); the subsequent MIIT/SAMR notices on product admission, recall and OTA software upgrade management (2024-2025); mandatory and recommended national standards developed through the National Technical Committee of Auto Standardization (SAC/TC 114), including GB 44495-2024 (vehicle cybersecurity technical requirements), GB 44496-2024 (OTA software update cybersecurity), GB/T 40861 (vehicle cybersecurity general requirements) and GB/T 40857 (telematics/OTA cybersecurity); and automotive data-security rules (the 2021 Several Provisions on Automobile Data Security and PIPL Article 40 on data localisation).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021",
      "nist-sp-1800-17-mfa-ecommerce",
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "china-interim-measures-generative-ai-2023",
    "title": "Interim Measures for the Management of Generative Artificial Intelligence Services",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "These Interim Measures, issued by the Cyberspace Administration of China, apply to providers of generative AI services within China and require compliance with content safety, data legitimacy, transparency, and registration obligations. Key obligations are established under Article 4 (content security), Article 7 (training data compliance), and Article 12 (service provider registration).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-transparency",
      "iso-42001-risk-assess",
      "nist-ai-100-4-redteam"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "china-maritime-safety-administration-msa-regulations",
    "title": "China Maritime Safety Administration (MSA) - Vessel Traffic Service, Pollution Response and Port State Control",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "China's Maritime Safety Administration (MSA - Haishi Ju) under the Ministry of Transport administers maritime safety through the Maritime Traffic Safety Law (2021 revision, effective 1 September 2021); mandates Vessel Traffic Service (VTS) participation for vessels in Chinese compulsory reporting zones; requires China-specific navigation permits for vessels in Chinese waters; enforces IMO conventions as incorporated into Chinese law; and imposes administrative penalties up to CNY 500,000 for navigation safety violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-consolidated-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "china-network-security-law-2017",
    "title": "Cybersecurity Law of the People's Republic of China (CSL)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-06-01",
    "bluf": "This law mandates broad cybersecurity obligations for all 'network operators' in China and imposes stricter requirements, including data localization and mandatory security reviews, on operators of 'Critical Information Infrastructure' (CII). Key provisions under Articles 31 and 37 require that personal information and important data collected by CII operators be stored within mainland China.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "cis-controls-v8",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "china-nmpa-ai-medical-devices-2026",
    "title": "China NMPA - Regulation on AI Medical Devices and SaMD (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The National Medical Products Administration (NMPA) regulates AI-enabled medical devices and Software as a Medical Device under the Medical Device Regulation and specific AI guidelines. Requirements include classification (Class II/III for most AI devices), clinical evaluation, algorithm transparency, training data quality, cybersecurity, change management for adaptive learning systems, and mandatory local data storage for certain health data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "japan-pmda-samd-ai-guidelines-2026",
      "south-korea-mfds-digital-medical-products-act-2026"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "china-nmpa-drug-registration-regulation-2020",
    "title": "China NMPA Drug Registration Regulation 2020 - Marketing Authorisation Holder System and Priority Review",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "China's Drug Registration Regulation (Order No. 27, 1 July 2020) issued by the National Medical Products Administration (NMPA - formerly CFDA) establishes the Marketing Authorisation Holder (MAH) system separating drug approval from manufacturing; introduces a priority review and approval pathway (youxian shenping) for breakthrough therapies, orphan drugs, and emergency public health drugs; requires full ICH CTD dossier submission; grants clinical data exclusivity of 6 years for new chemical entities; imposes GMP compliance as a condition of MAH licence; and applies administrative penalties of up to CNY 3 million for non-compliant drug marketing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-210-211-current-good-manufacturing-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "china-online-gaming-regulations-2023-nppa",
    "title": "China Online Gaming Regulations 2023 - NPPA Draft Rules: Playtime Limits, Spending Caps, Minor Protection, Real-Name Registration, Anti-Addiction System and Game Approval Process",
    "domain": "Gaming & Gambling",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation imposes strict playtime and spending limits on minors, mandates real-name registration, and requires implementation of an anti-addiction system for online gaming platforms operating in China. Key obligations are enforced under NPPA directives, though specific article numbers are not present in the provided source text.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "china-pipl-2021-personal-information-protection",
    "title": "Personal Information Protection Law of the People's Republic of China (PIPL)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-07-22",
    "bluf": "The China Personal Information Protection Law (PIPL) establishes a comprehensive data protection framework for organizations processing the personal information of individuals within the PRC, mandating a clear lawful basis for processing (primarily consent per Article 13), imposing strict requirements for sensitive data and cross-border transfers (Articles 28 & 38), and granting individuals extensive rights over their data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo",
      "eu-standard-contractual-clauses-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "china-pipl-cross-border-transfer-rules-2023",
    "title": "Measures for the Standard Contract for the Outbound Transfer of Personal Information & CAC Security Assessment Triggers",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under China's Personal Information Protection Law (PIPL), organizations transferring personal information outside mainland China must use one of three mechanisms: a mandatory Cyberspace Administration of China (CAC) security assessment for high-volume or sensitive data transfers, CAC-approved Standard Contractual Clauses (SCCs), or certification. All transfers require a prior Personal Information Protection Impact Assessment (PIPIA) as stipulated in Article 4 of the Measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-standard-contractual-clauses-2021",
      "gdpr-article-46-transfer-mechanisms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "china-pipl-personal-information-marketing-2021",
    "title": "Personal Information Protection Law of the People's Republic of China - Direct Marketing Obligations, Article 23-29: Opt-In Consent for Personalised Ads, Automated Decision-Making Transparency, Separate Consent for Sensitive Data, Right to Opt Out of Personalised Recommendations and Minor Protection Rules",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The PIPL requires entities conducting direct marketing in China to obtain separate, explicit opt-in consent before processing personal information for personalized advertising or automated decision-making, including profiling. Sensitive data and minors' data require additional safeguards under Articles 23-29, with mandatory transparency and opt-out mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coppa-marketing-kids",
      "ccpa-cpra-optout-sale",
      "eu-geo-blocking-regulation-2018-302",
      "ftc-digital-advertising-disclosures",
      "eprivacy-cookie-directive"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "china-yangtze-river-protection-law-2020-river-chief",
    "title": "China Yangtze River Protection Law (2020) and the River and Lake Chief System",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2021-03-01",
    "bluf": "The Yangtze River Protection Law (Yangzi Jiang Baohu Fa) of the People's Republic of China was adopted by the Standing Committee of the National People's Congress on 26 December 2020 and entered into force on 1 March 2021. The Law is China's first comprehensive river basin protection statute and applies to the entire Yangtze River Basin covering 19 provinces, autonomous regions, and municipalities. The Law establishes binding ecological protection priorities; sets fishing bans; restricts industrial layout near the river; codifies water resources management; and imposes administrative liability up to criminal sanctions for serious violations. It is administered by the Ministry of Ecology and Environment in coordination with the Ministry of Water Resources, the Ministry of Agriculture and Rural Affairs, and provincial governments along the basin.\n\nThe River Chief System (Hezhang Zhi) was introduced nationally on 11 December 2016 by the General Office of the Communist Party of China and the State Council. The System requires the appointment of a River Chief at each administrative level (provincial, municipal, county, and township) responsible for water resources protection, water environment governance, water pollution prevention, and water ecology restoration in the assigned river or lake segment. The Lake Chief System was added in 2017. By the end of 2018, more than 1.2 million River and Lake Chiefs had been appointed across China. The System is supervised by the Joint Conference for River and Lake Chiefs which includes officials from the Ministry of Water Resources, the Ministry of Ecology and Environment, the Ministry of Public Security, and other agencies. Performance evaluation of River and Lake Chiefs is incorporated into the leadership accountability system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "china-carbon-ets-administrative-regulations-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ci-code-des-marches-publics-decret-2009-259-anrmp-sygmaa",
    "title": "Cote d'Ivoire Code des Marches Publics Decret 2009-259 of 6 August 2009 as amended by Decret 2019-679 and ANRMP / SIGOMAP",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Cote d'Ivoire Code des Marches Publics (Public Procurement Code) approved by Decret 2009-259 of 6 August 2009 (Journal Officiel de la Republique de Cote d'Ivoire) as substantially amended and modernised by Decret 2019-679 of 31 July 2019 (modernisation amendments) and Decret 2024-247 of 27 March 2024 (further reforms), and supplemented by application orders (arretes d'application), is the principal Ivoirian regulatory instrument governing procurement of works, supplies, intellectual services, and consulting services by contracting authorities including the State, local collectivities (collectivites territoriales / regions, departements, communes), public establishments (etablissements publics), public-sector companies (societes a participation financiere publique majoritaire), and other contracting authorities subject to the Code. The 2009 Decree was issued to align the Ivoirian procurement regime with WAEMU Directive 04/2005/CM/UEMOA on public procurement (transposed across the WAEMU region). The Autorite Nationale de Regulation des Marches Publics (ANRMP / anrmp.ci) is the central regulatory authority responsible for procurement regulation, complaint resolution, supplier debarment, and procurement guidance. The Direction des Marches Publics (DMP) under the Ministry of Economy, Finance and Budget conducts ex-ante control of high-value procurement. The Systeme Integre de Gestion des Operations des Marches Publics (SIGOMAP / sigomap.gov.ci) is the federal e-procurement platform. Procurement methods established by the Code 2009/2019 art. 56 to 99 comprise (a) Appel d'offres ouvert (Open Call for Tenders, the default open public procedure), (b) Appel d'offres restreint (Restricted Call for Tenders, with prequalification), (c) Appel d'offres avec concours (Tender with Competition, for design works), (d) Procedure adaptee (Adapted Procedure, for medium-low value contracts), (e) Procedure simplifiee a competition restreinte (Simplified Procedure with Restricted Competition), (f) Gre a gre (Direct Negotiation, sole-source under prescribed exceptions in art. 96 to 99), (g) Demande de cotation (Request for Quotations, for small-value), and (h) Marche de prestations intellectuelles (Intellectual Services Procurement). The Cour des Comptes de Cote d'Ivoire conducts ex-post procurement audit. Cote d'Ivoire is a party to ECOWAS, WAEMU (UEMOA), AfCFTA, and UNCAC. Cote d'Ivoire is NOT a party to the WTO GPA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "ci-dp-law-2013",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ci-dp-law-2013",
    "title": "Côte d'Ivoire Personal Data Protection Law No. 2013-450 - ARTCI",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Côte d'Ivoire's Loi No. 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel (Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data) - published in the Journal Officiel de la République de Côte d'Ivoire and promulgated in 2013 - is Côte d'Ivoire's primary personal data protection legislation. The law was enacted in the context of Côte d'Ivoire's broader legal framework for the digital economy and information society, complementing the Law on Electronic Transactions and ICT regulations. The supervisory authority designated under the law is the Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI - Côte d'Ivoire Telecommunications/ICT Regulatory Authority), which exercises data protection oversight functions through a specialised committee or commission. Côte d'Ivoire's law was developed in alignment with the ECOWAS Supplementary Act on Personal Data Protection (adopted by ECOWAS in 2010) and draws on the French CNIL data protection model as a former French colonial territory within the Francophone West Africa legal tradition. Key features of Côte d'Ivoire's Law No. 2013-450: (1) Scope - applies to automated and non-automated processing of personal data by public and private entities established in Côte d'Ivoire or using processing means on Ivorian territory; (2) Data processing principles - processing must comply with: lawfulness (loyauté); purpose limitation (finalité); proportionality and relevance; accuracy (exactitude); storage limitation; security (sécurité); and confidentiality (confidentialité); (3) Sensitive personal data - the law prohibits processing without lawful basis for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual life; genetic data; and criminal history; (4) Lawful processing conditions - consent; legal obligation; contractual necessity; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to object; and right not to be subject to solely automated decisions; (6) Declaration and authorisation regime - controllers must file a declaration (déclaration) with ARTCI for standard processing or obtain an authorisation (autorisation) for sensitive or high-risk processing before commencing; (7) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or subject to ARTCI-approved safeguards; (8) Security obligations - controllers must implement technical and organisational security measures; (9) ARTCI enforcement - investigates complaints; conducts audits; issues formal notices; refers violations to judicial authorities; (10) ECOWAS context - the law aligns with the ECOWAS Supplementary Act on Personal Data Protection to facilitate cross-border data flows within the Economic Community of West African States. Côte d'Ivoire is the largest economy in Francophone West Africa and its data protection framework is significant for the UEMOA/WAEMU regional digital economy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cipd-hr-standards",
    "title": "CIPD (HR Standards)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Adherence to this node mandates rigorous alignment with Chartered Institute of Personnel and Development standards, structurally integrated with foundational UK legislation. An organization's human resources framework requires `require_cipd_profession_map_alignment`, ensuring all practices reflect the Core Knowledge areas of Ethical Practice plus Culture & Behaviour from the CIPD Profession Map. This alignment is operationally enforced via an `ethical_practice_framework_implemented` and verified through a minimum of two `culture_and_behavior_audits_per_year`. Professional Integrity and Competence, as stipulated within the CIPD Code of Professional Conduct, are sustained by a `min_annual_cpd_hours` of 30 for practitioners. Data processing activities must be `technology_people_analytics_compliant`, activating `employee_data_privacy_controls_active` to satisfy principles of the UK General Data Protection Regulation under Article 5. Systematically, `evidence_based_decision_tracking_enabled` supports transparent, justifiable people management decisions. Conformity with the UK Equality Act 2010 concerning Protected Characteristics and Prohibited Conduct necessitates that `diversity_inclusion_metrics_tracked` are continually monitored. Employee relations procedures must respect the UK Employment Rights Act 1996 baseline, with performance thresholds enforcing a `max_grievance_resolution_days` of 28. Consistent with ISO 30414:2018 guidelines for human capital reporting, a `workforce_reporting_frequency_days` not exceeding 90 is mandatory. Finally, the node requires that `mandatory_wellbeing_assessments_enabled` are active, ensuring a holistic and compliant people strategy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "un-guiding-principles-business-hr",
      "iso-30414-human-capital",
      "shrm-hr-competency",
      "modern-slavery-act-rep",
      "iso-45001-work-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-ai-least-privilege",
    "title": "Least Privilege for AI Agents (CIS Companion Guide)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Autonomous AI agents must be managed as Non-Human Identities (NHIs) with task-scoped, ephemeral privileges. The principle of Least Privilege ensures that an agent's access is restricted to the specific data and tools required for its current atomic task.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "nist-sp-800-207",
      "nist-ai-rmf-govern",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8",
    "title": "CIS Critical Security Controls Version 8",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with the Center for Internet Security (CIS) Critical Security Controls Version 8 provides a prioritized, risk-based framework for cyber defense, with this node mandating the foundational requirements of Implementation Group 1. Adherence necessitates maintaining a complete enterprise asset inventory and a detailed software asset inventory, alongside an active data classification program. The required operational security posture specifies automated vulnerability scans must occur at a maximum interval of 30 days, with critical patch deployment completed within a 14-day window. Secure access controls are paramount; multi-factor authentication is required for all administrative functions and any remote network access. For forensic and investigative readiness, audit logs must be preserved for a minimum of 90 days. Organizational resilience is further bolstered by requiring a formal incident response plan and ensuring all personnel complete security awareness training within a 365-day cycle. While this configuration does not explicitly require penetration testing, its implementation offers significant legal and regulatory advantages. Conformance may afford a legal safe harbor under state legislation like the Ohio Data Protection Act and Utah’s Cybersecurity Affirmative Defense Act. Moreover, these safeguards align heavily with federal enforcement under the FTC Safeguards Rule and are directly mapped to authoritative standards, including NIST Special Publication 800-53 and the NIST Cybersecurity Framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-csf-2",
      "nist-sp-800-53-r5",
      "nist-sp-1800-5-it-asset-management",
      "cyber-nist-800-53-ac2",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-01-inventory-and-control-of-enterprise-assets",
    "title": "CIS Controls v8.1 Control 1: Inventory and Control of Enterprise Assets",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 1: Inventory and Control of Enterprise Assets. CIS Controls 1 focuses on actively managing (inventory, track, and correct) all enterprise assets connected to the infrastructure. Control 1 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 5 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 1 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-02-inventory-and-control-of-software-assets",
    "title": "CIS Controls v8.1 Control 2: Inventory and Control of Software Assets",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 2: Inventory and Control of Software Assets. CIS Control 2 focuses on actively managing (inventory, track, and correct) all software (operating systems and applications) on the network. Control 2 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 7 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 2 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-03-data-protection",
    "title": "CIS Controls v8.1 Control 3: Data Protection",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 3: Data Protection. CIS Controls 3 focuses on developing processes and technical controls to identify, classify, securely handle, retain, and dispose of data. Control 3 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 14 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 3 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-04-secure-configuration-of-enterprise-assets-and-software",
    "title": "CIS Controls v8.1 Control 4: Secure Configuration of Enterprise Assets and Software",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 4: Secure Configuration of Enterprise Assets and Software. CIS Control 4 focuses on establishing and maintaining the secure configuration of enterprise assets and software. Control 4 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 12 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 4 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-05-account-management",
    "title": "CIS Controls v8.1 Control 5: Account Management",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 5: Account Management. CIIS Control 5 focuses on using processes and tools to assign and manage authorization to credentials for user accounts. Control 5 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 6 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 5 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-06-access-control-management",
    "title": "CIS Controls v8.1 Control 6: Access Control Management",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 6: Access Control Management. CIS Control 6 focuses on using processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts. Control 6 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 8 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 6 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-07-continuous-vulnerability-management",
    "title": "CIS Controls v8.1 Control 7: Continuous Vulnerability Management",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 7: Continuous Vulnerability Management. CIS Control 7 focusing on developing a plan to continuously assess & track vulnerabilities on all enterprise assets within the enterprise's infrastructure. Control 7 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 7 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 7 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-08-audit-log-management",
    "title": "CIS Controls v8.1 Control 8: Audit Log Management",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 8: Audit Log Management. CIS Controls 8 focuses on collecting, alerting, reviewing, and retaining audit logs of events that could help detect, understand, or recover from an attack. Control 8 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 12 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 8 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-09-email-and-web-browser-protections",
    "title": "CIS Controls v8.1 Control 9: Email and Web Browser Protections",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 9: Email and Web Browser Protections. CIS Control 9 focuses on improving protections and detections of threats from email and web vectors. Control 9 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 7 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 9 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-10-malware-defenses",
    "title": "CIS Controls v8.1 Control 10: Malware Defenses",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 10: Malware Defenses. CIS Control 10 focuses on preventing or controlling the installation, spread, & execution of malicious applications, code, or scripts on enterprise assets. Control 10 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 7 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 10 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-11-data-recovery",
    "title": "CIS Controls v8.1 Control 11: Data Recovery",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 11: Data Recovery. CIS Control 11 focuses on establishing and maintaining data recovery practices to restore in-scope enterprise assets to a pre-incident and trusted state. Control 11 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 5 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 11 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-12-network-infrastructure-management",
    "title": "CIS Controls v8.1 Control 12: Network Infrastructure Management",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 12: Network Infrastructure Management. CIS Control 12 focuses on establishing, implementing, and actively managing network devices to prevent attackers from exploiting vulnerable network services. Control 12 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 8 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 12 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-13-network-monitoring-and-defense",
    "title": "CIS Controls v8.1 Control 13: Network Monitoring and Defense",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 13: Network Monitoring and Defense. CIS Controls 13 focuses on processes and tooling to establish and maintain comprehensive network monitoring and defense against security threats. Control 13 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 11 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 13 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-14-security-awareness-and-skills-training",
    "title": "CIS Controls v8.1 Control 14: Security Awareness and Skills Training",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 14: Security Awareness and Skills Training. CIS Controls 14 focuses on establishing and maintaining a security awareness program to be security conscious to reduce cybersecurity risks. Control 14 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 9 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 14 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-15-service-provider-management",
    "title": "CIS Controls v8.1 Control 15: Service Provider Management",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 15: Service Provider Management. CIS Controls 15 focuses on developing a process to evaluate service providers to ensure platforms and data are protected appropriately. Control 15 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 7 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 15 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-16-application-software-security",
    "title": "CIS Controls v8.1 Control 16: Application Software Security",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 16: Application Software Security. CIS Controls 16 focuses on managing the security life cycle of software to prevent, detect, and remediate security weaknesses. Control 16 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 14 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 16 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-17-incident-response-management",
    "title": "CIS Controls v8.1 Control 17: Incident Response Management",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 17: Incident Response Management. CIS Controls 17 focuses on establishing a program to develop and maintain an incident response capability to prepare, detect, and respond to an attack. Control 17 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 9 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 17 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-1-control-18-penetration-testing",
    "title": "CIS Controls v8.1 Control 18: Penetration Testing",
    "domain": "Cybersecurity",
    "version": "8.1.0",
    "last_updated": "2024-06-01",
    "bluf": "CIS Controls v8.1 Control 18: Penetration Testing. CIS Controls 18 focuses on test the effectiveness and resiliency of enterprise assets through identifying and exploiting weaknesses in controls. Control 18 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 5 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 18 adoption in the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cis-controls-v8-2021",
    "title": "CIS Critical Security Controls Version 8 - 18 Safeguard Groups, Implementation Groups (IG1/IG2/IG3) and Mappings to NIST CSF, ISO 27001 and CMMC for Prioritised Security Actions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The CIS Critical Security Controls v8 provides a prioritized set of safeguards to defend against prevalent cyber attacks, applicable to organizations across all sectors seeking to improve their cybersecurity posture. It organizes 18 control families with implementation guidance across three Implementation Groups (IG1, IG2, IG3) based on organizational size and complexity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-csf-2",
      "c-scrm-practices-systems-organizations",
      "nist-800-53-sc7",
      "nist-800-53-au2",
      "cyber-nist-800-53-ac2"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cisa-cpgs-cross-sector-performance-goals-2023",
    "title": "CISA Cross-Sector Cybersecurity Performance Goals (CPGs) 2023 - 37 Baseline Security Practices for Critical Infrastructure Operators",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-10-27",
    "bluf": "The CISA Cross-Sector Cybersecurity Performance Goals (CPGs) establish a voluntary, common set of 37 baseline cybersecurity practices for critical infrastructure operators to meaningfully reduce risks to critical national functions. These goals, such as implementing phishing-resistant MFA (Goal 1.C) and maintaining an asset inventory (Goal 2.A), provide a prioritized, cost-effective path to improve security and resilience.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cis-controls-v8",
      "cyber-nist-800-53-ac2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cisa-cross-sector-cybersecurity-goals",
    "title": "Cross-Sector Cybersecurity Performance Goals",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-03-31",
    "bluf": "The Cross-Sector Cybersecurity Performance Goals (CPGs) provide an approachable common set of IT and OT cybersecurity protections that are clearly defined, straightforward to implement, and aimed at addressing some of the most common and impactful cyber risks. These goals are applicable across all critical infrastructure sectors and are informed by the most common and impactful threats and adversary tactics, techniques, and procedures (TTPs) observed by CISA and its government and industry partners. They are a minimum set of practices that all critical infrastructure entities-from large to small-should implement to get started on their path toward a strong cybersecurity posture. The CPGs are intended to be a floor, not a ceiling, for what cybersecurity protections organizations should implement to reduce their cyber risk.\n\nThe CPGs do not constitute a comprehensive cybersecurity program but rather represent a minimum baseline of cybersecurity practices with known risk-reduction value. They are designed to be easy to understand and communicate with non-technical audiences, including senior business leadership, to help organizations focus investment toward the most impactful security outcomes. The goals are voluntarily adopted and can be used as a quick-start guide, particularly for small and medium organizations, to prioritize security investments in conjunction with broader frameworks like the NIST Cybersecurity Framework (NIST CSF).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cis-controls-v8",
      "nist-sp-800-53-r5",
      "cyber-nist-csf-2",
      "nist-sp-800-40r4-enterprise-patch-management",
      "nist-sp-800-63b-authentication"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "cisa-ms-isac-ransomware-guide",
    "title": "RANSOMWARE GUIDE",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-09-01",
    "bluf": "This guide provides ransomware best practices and recommendations based on operational insight from the Cybersecurity and Infrastructure Security Agency (CISA) and the Multi-State Information Sharing and Analysis Center (MS-ISAC). It is intended for information technology (IT) professionals and others involved in developing or coordinating cyber incident response. Ransomware is a form of malware designed to encrypt files on a device, rendering them and the systems that rely on them unusable, after which malicious actors demand a ransom for decryption. Ransomware incidents have become increasingly prevalent and can severely impact business processes, leaving organizations without the data needed to operate and deliver mission-critical services.\nMalicious actors have adjusted tactics to include threatening to release stolen data and publicly naming victims as secondary forms of extortion. The monetary value of demands has also increased, with some exceeding $1 million. These actors often engage in lateral movement to target critical data, propagate ransomware across entire networks, and use tactics like deleting system backups to make restoration more difficult. This guide is composed of two parts: Ransomware Prevention Best Practices and a Ransomware Response Checklist.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-61r2-incident-handling",
      "nist-sp-800-34-r1",
      "nist-ir-8374-ransomware-risk-management",
      "data-integrity-detecting-responding-ransomware",
      "cis-controls-v8",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "cisa-ncsc-guidelines-secure-ai-system-development-2023",
    "title": "CISA-NCSC Joint Guidelines for Secure AI System Development (November 26, 2023)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On November 26, 2023 the UK National Cyber Security Centre (NCSC) and the US Cybersecurity and Infrastructure Security Agency (CISA), with co-sealing from 21 additional international cyber agencies including ACSC (Australia), CCCS (Canada), CCB (Belgium), CSEC (Canada), BSI (Germany), ANSSI (France), JPCERT/CC (Japan), NCSC-NL (Netherlands), NSM-NCSC (Norway), NCSC-NZ (New Zealand), SingCERT (Singapore), and others, jointly published the Guidelines for Secure AI System Development. The Guidelines apply to providers of AI systems - whether developing models from scratch or building on top of third-party tools - and structure secure-by-design AI development across four life cycle areas: (1) Secure Design - threat modelling, security considerations during requirements and design, AI-specific risks; (2) Secure Development - supply chain security, documentation, technical debt management; (3) Secure Deployment - infrastructure protection, model and asset protection, incident management procedures, responsible release; (4) Secure Operation and Maintenance - monitoring system behaviour and input, updates and patching, sharing lessons. Within each area the document enumerates specific recommended practices with rationale. The Guidelines are voluntary but represent the consensus position of the major Western cyber agencies on AI security baseline expectations and are referenced in subsequent national AI policy across the signatory jurisdictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping",
        "iso_standard",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-sp-800-218-ssdf",
      "nist-ai-100-2-adversarial-ml-taxonomy-2024",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cisa-sbom-minimum-elements-2021",
    "title": "The Minimum Elements For a Software Bill of Materials (SBOM)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Mandated by U.S. Executive Order 14028, this standard from the NTIA defines the minimum required data fields, formats, and practices for a Software Bill of Materials (SBOM). It requires all software producers to provide SBOMs that list components, versions, suppliers, and dependency relationships to enhance software supply chain transparency for consumers and operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "c-scrm-practices-systems-organizations",
      "pci-dss-v4-requirement-6",
      "iso-iec-5230-openchain",
      "nis2-supply-chain-security-article-22"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cisa-secure-by-design-guidance-2024",
    "title": "CISA Secure by Design Guidance 2024 - Software Manufacturer Obligations: Shift Liability from Customers to Vendors, Memory-Safe Languages, Default-Secure Configurations, Eliminate Default Passwords, Vulnerability Disclosure Programmes and CVE Remediation Commitments",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This guidance requires software manufacturers to implement Secure by Design principles by prioritizing customer security as a core business requirement, ensuring out-of-the-box secure configurations, eliminating default passwords, adopting memory-safe languages, and establishing vulnerability disclosure programs. Key commitments are aligned with the seven goals of the CISA Secure by Design Pledge.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "cisa-cross-sector-cybersecurity-goals",
      "cobit-2019-governance-framework",
      "bsa-software-asset-management-iso-19770"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cisa-zero-trust-maturity-model-2-0",
    "title": "CISA Zero Trust Maturity Model 2.0 - Identity, Devices, Networks, Applications and Data Pillars with Traditional, Advanced and Optimal Stages",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This model provides a roadmap for U.S. federal agencies and other organizations to implement a zero trust architecture, as directed by Executive Order 14028. It outlines a maturity continuum across five pillars (Identity, Devices, Networks, Applications, Data) and three stages (Traditional, Advanced, Optimal) to guide the transition from traditional network security to a more robust, identity-centric approach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cyber-nist-800-53-ac2",
      "nist-800-53-ia2",
      "cis-controls-v8",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "cites-convention-1973-endangered-species-trade",
    "title": "CITES 1973 - Convention on International Trade in Endangered Species of Wild Fauna and Flora",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Convention on International Trade in Endangered Species of Wild Fauna and Flora (CITES), signed on 3 March 1973 in Washington D.C. and entered into force 1 July 1975, has 183 Parties and is the international treaty governing trade in wildlife specimens to prevent overexploitation. CITES regulates trade through a three-tiered Appendix system: Appendix I (>37,000 species - threatened with extinction; commercial trade generally prohibited; trade only for non-commercial purposes with export and import permits); Appendix II (>35,000 species - not necessarily threatened but trade must be controlled to avoid threatening survival; requires export permit showing trade does not threaten survival - 'non-detriment finding'); Appendix III (species listed by individual countries for cooperation in controlling trade from that country). The Conference of the Parties (COP) meets every 3 years to amend Appendices; the most recent COP19 (Panama City, November 2022) listed 600+ species. Major commercial wildlife products requiring CITES permits include: ivory (elephant - Appendix I with specific exceptions), rhinoceros horn (Appendix I), tigers (Appendix I), pangolins (all 8 species Appendix I), tropical timber species (mahogany, rosewood - Appendix II and III), marine species (sharks, manta rays, seahorses, sea cucumbers - Appendix II), caviar (sturgeons - Appendix I and II), orchids, and cacti. Violations of CITES are a leading cause of wildlife trafficking prosecution and may give rise to criminal liability under national implementing law. The EU Wildlife Trade Regulations (Regulations 338/97 and 750/2021) implement CITES in the EU and in some areas apply stricter controls. Supply chain due diligence and CITES permit verification are mandatory for businesses trading in listed species and their derivatives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-cbd-kunming-montreal-gbf-2022",
      "eu-deforestation-regulation-2023",
      "eu-csrd-2022-2464",
      "eu-reach-regulation-1907-2006"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ck-privacy-act-2014",
    "title": "Cook Islands Privacy Act 2014",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Cook Islands enacted the Privacy Act 2014, a privacy and personal information protection statute aligned with New Zealand privacy law standards given the Cook Islands' free association status with New Zealand. The Act is administered by the Privacy Commissioner of the Cook Islands and establishes information privacy principles covering the collection, use, storage, disclosure, and correction of personal information. Data subjects have rights to access and correct personal information held about them. Agencies are required to use personal information only for the purpose for which it was collected, implement security safeguards, and make personal information available in accordance with the Act. The Act aligns with Pacific Islands privacy principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ck-privacy-act-2014.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cl-aml-law-19913",
    "title": "Chile Law No. 19.913 Creating the Financial Analysis Unit (Anti-Money Laundering)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "Chile's Law No. 19.913 creates the Financial Analysis Unit (UAF) (Article 1) and obliges listed reporting entities to report suspicious operations to the UAF (Article 3), report cross-border transport of cash exceeding ten thousand US dollars (Article 4), keep special records for a minimum of five years and report cash transactions over ten thousand US dollars (Article 5), and refrain from tipping off (Article 6); money laundering is the offence defined in Article 27.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cl-dp-law-2022",
    "title": "Chile Data Protection Law 21.719 - Ley Marco de Datos Personales and CPLT Enforcement",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Chile's Ley Marco de Datos Personales (Framework Law on Personal Data) - Law No. 21.719, published in the Diario Oficial de la República de Chile on 13 December 2024 and entering into force on 13 December 2026 (a two-year transition period) - is Chile's comprehensive modern data protection law, substantially replacing and modernising the prior Ley de Protección de la Vida Privada (Law No. 19.628 of 1999), which was one of Latin America's earliest data protection statutes. Law No. 21.719 represents a landmark reform of Chilean data protection, designed to bring Chile into alignment with international standards including the EU GDPR framework. Chile previously obtained EU GDPR adequacy status through European Commission Decision 2013/65/EU of 19 December 2012, which recognised Chile's 1999 framework as adequate - the new law is expected to strengthen and maintain this adequacy position. The enforcement authority under the new framework is the Consejo para la Transparencia (CPLT - Council for Transparency), which had been the transparency authority and will assume expanded data protection enforcement powers, and a newly established Agencia de Protección de Datos Personales (APDP - Personal Data Protection Agency) to be created under the new law. Key features of Law No. 21.719: (1) Controller (Responsable) and Processor (Mandatario) terminology; (2) Seven lawful bases for processing aligned with GDPR: consent, contract, legal obligation, vital interests, legitimate interests, public interest, and the controller's legitimate interests; (3) Sensitive personal data - broadly defined including: ideological, political, religious, or philosophical beliefs; trade union membership; physical or psychological health; ethnicity or race; life and sexual practices; genetic data; biometric data; criminal records; financial or economic data; (4) Data subject rights aligned with GDPR: right to information, access, rectification, erasure, portability, objection, and not to be subject to automated decision-making; (5) Data Protection Impact Assessment (DPIA) - required for high-risk processing; (6) Data Protection Officer (DPO) - required for large-scale or high-risk processing; (7) Mandatory breach notification to the APDP within 72 hours; (8) Cross-border data transfer restrictions aligned with GDPR adequacy framework; (9) Administrative fines up to 5% of annual income or UF 5,000 (approximately USD 200,000) whichever is greater. Note: as of April 2026, Law No. 21.719 is in its two-year transition period - full compliance obligations will take effect on 13 December 2026. Organisations should begin implementation planning immediately. The prior law (Law No. 19.628 of 1999) remains in force during the transition period. Chile is an OECD member and one of Latin America's most economically advanced nations, making data protection compliance particularly important for Chilean and multinational organisations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cl-ley-19886-bases-contratos-administrativos-suministro-servicios-chilecompra",
    "title": "Chile Ley 19.886 — Bases sobre Contratos Administrativos de Suministro y Prestacion de Servicios + ChileCompra / MercadoPublico Platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "Ley 19.886 de Bases sobre Contratos Administrativos de Suministro y Prestacion de Servicios (Law of the Foundations of Administrative Contracts of Supply and Provision of Services), published 30 July 2003, is the principal Chilean statute governing procurement of goods and services by public sector entities. The Law established the Direccion ChileCompra (the Directorate of Public Procurement and Contracting) as the central regulatory authority and the MercadoPublico platform at mercadopublico.cl as the mandatory electronic procurement system - widely cited internationally as one of the world's most mature and transparent government e-procurement systems alongside Ukraine's ProZorro and Korea's KONEPS. The Law is implemented through the Reglamento de la Ley 19.886 (Supreme Decree 250 of 2004) which specifies the operational procurement procedures. The principal procurement methods include licitacion publica (open public tender, the default method), licitacion privada (limited tender), trato directo (direct contracting, sole-source under prescribed exceptions in Article 8 such as emergency, sole supplier, low value), and convenio marco (framework agreement, the centralised purchasing arrangement through which ChileCompra negotiates and operates standing supply arrangements that individual public entities can access through quick orders). MercadoPublico processes the majority of Chilean public procurement transactions end-to-end including procurement notice publication, electronic bid submission, contract award, and supplier registry (ChileProveedores). The framework intersects multiple supporting regimes including the Ley 20.730 on Lobby Activities for the integrity dimension, the Ley 19.880 on Administrative Procedures for the procedural baseline, the Ley 19.628 on Personal Data Protection for supplier data, the various free trade agreement government procurement chapters (Chile-US FTA, Chile-EU AA, Pacific Alliance, CPTPP Chapter 15), and the OECD Recommendation on Public Procurement which Chile actively supports as an OECD member. ChileCompra publishes extensive transparency data through the MercadoPublico Datos Abiertos open data portal and operates an integrated supplier evaluation, dispute resolution (Tribunal de Contratacion Publica TCP), and integrity monitoring infrastructure. Chile's procurement framework is widely studied internationally as a leading reference for transparent, efficient e-procurement and serves as a model for Pacific Alliance and Latin American public procurement reform.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "cl-ley-21719-2024-data-protection-new-framework",
    "title": "Chile Ley 21.719/2024 - New Data Protection Framework and GDPR Alignment",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Chile's Ley 21.719 (enacted December 2024, effective December 2026) replaces the 1999 PDPA with a GDPR-aligned framework: 8 lawful bases including legitimate interests, data subject rights of access/correction/deletion/portability/objection, mandatory DPO for large processors, 72-hour breach notification to the new Agencia de Proteccion de Datos Personales (APDP), and penalties up to 10,000 UTM (approx. USD 750,000) for serious violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "br-lgpd-law-13709-2018-data-protection-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cl-personal-data-protection-law-21719-2024",
    "title": "Chile Law 21.719 on the Protection of Personal Data 2024 - GDPR-Aligned Reform with Personal Data Protection Agency, Full Effectiveness 1 December 2026",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Data controllers and processors operating in Chile or directing services at Chile must apply Law 21.719 on the Protection of Personal Data (approved by Congress on 26 August 2024, published on 13 December 2024, full effectiveness on 1 December 2026 after a 24-month transitional period) which sets out core principles for lawful data processing (lawfulness, purpose limitation, proportionality, data quality, accountability, security, transparency and information, and confidentiality), recognises and expands data subject rights, regulates special categories of sensitive data, introduces controller and processor obligations, creates an administrative enforcement and sanctioning regime including fines of up to 20,000 monthly tax units (approximately US$1,588,400) with recidivism, and creates the Personal Data Protection Agency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "clia-cruise-ship-safety",
    "title": "CLIA Cruise Ship Safety",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance for cruise ship operations mandates comprehensive adherence to multifaceted international and domestic regulations governing safety, security, health, and environmental protection. Pursuant to the International Ship and Port Facility Security (ISPS) Code under SOLAS Chapter XI-2, vessels must maintain a current security plan, operating here at a verified ISPS Security Threat Level of 1. This framework is augmented by robust cyber risk management protocols, as stipulated by IMO Resolution MSC.428(98), requiring full integration into the Safety Management System, enforced operational and informational technology network segmentation, plus strict authentication for bridge access. The Cruise Vessel Security and Safety Act of 2010 further imposes stringent obligations, including a maximum 24-hour timeline for incident reporting and a minimum CCTV data retention period of 30 days. Passenger safety remains paramount, with SOLAS Chapter III, Regulation 19 mandating that a muster drill be completed prior to any departure and that lifeboat capacity must exceed a 125 percent minimum of the vessel's total complement. Health standards are rigorously monitored under the Centers for Disease Control and Prevention’s Vessel Sanitation Program, which requires a minimum sanitation score of 85, complemented by onboard medical services providing at least one qualified medical staff member per 1000 passengers. Finally, environmental stewardship is confirmed through verified adherence to the International Convention for the Prevention of Pollution from Ships, MARPOL 73/78, ensuring all discharge and waste management practices are compliant.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "isps-code-vessel-security",
      "imo-marpol-pollution",
      "ism-code-vessel-safety",
      "imo-stcw-seafarer-training",
      "haccp-food-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "clinical-decision-support-ai-governance-2026",
    "title": "Clinical Decision Support (CDS) AI Systems - Global Governance & Regulatory Obligations (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "AI-powered Clinical Decision Support systems are subject to stringent oversight when they influence diagnosis, treatment, or patient management. Requirements include rigorous clinical validation, transparency/explainability, bias mitigation, human oversight, integration with EHR workflows, performance monitoring in real-world settings, and classification as medical devices or high-risk AI systems in multiple jurisdictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "cm-cybersec-dp-2010",
    "title": "Cameroon Cybersecurity and Personal Data Law - ANTIC Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Cameroon Law No. 2010/012 on Cybersecurity and Cybercriminality (2010) includes comprehensive personal data protection provisions governing consent, data subject rights, controller obligations, and cross-border transfer restrictions. The Agence Nationale des Technologies de l'Information et de la Communication (ANTIC) is the designated supervisory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cm-decret-2018-366-code-marches-publics-armp-coleps",
    "title": "Cameroon Decret 2018-366 of 20 June 2018 portant Code des Marches Publics and ARMP / COLEPS",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Republic of Cameroon Decret 2018-366 of 20 June 2018 portant Code des Marches Publics (Decree No. 2018-366 of 20 June 2018 establishing the Public Procurement Code) effective 20 June 2018 as supplemented by application orders (arretes d'application) issued by the Minister Delegate to the Presidency in charge of Public Procurement, is the principal Cameroonian regulatory instrument governing procurement of works, supplies, intellectual services, and consulting services by contracting authorities including the State (l'Etat), public administrative establishments (etablissements publics administratifs / EPA), local collectivities (communes and regions), public-sector companies (societes a capitaux publics), and other contracting authorities subject to the Code. Decret 2018-366 replaced the prior Decret 2004/275 of 24 September 2004 and substantially modernised the Cameroonian procurement framework aligning with CEMAC procurement directives and international best practice. The Agence de Regulation des Marches Publics (ARMP / armp.cm) under the Office of the Prime Minister is the central regulatory authority responsible for procurement regulation, supplier debarment, complaint resolution, and procurement guidance. The Ministry Delegate at the Presidency in charge of Public Procurement (MINMAP) is the operational central procurement authority. The Cameroon Online E-Procurement System (COLEPS / coleps.cm under rollout) is the federal e-procurement platform. Procurement methods established by Decret 2018-366 art. 35 to 89 comprise (a) Appel d'offres ouvert (Open Call for Tenders, the default open public procedure), (b) Appel d'offres restreint (Restricted Call for Tenders, with prequalification), (c) Appel d'offres national / international (National / International Call for Tenders), (d) Appel d'offres en deux etapes (Two-Stage Tender, for complex acquisitions), (e) Consultation simple (Simple Consultation, for low-value acquisitions), (f) Gre a gre (Direct Negotiation, sole-source under prescribed exceptions in art. 87 to 89 including emergency, sole supplier for technical reasons, prior unsuccessful tendering, and prescribed-class exemptions), (g) Demande de cotation (Request for Quotations, for small-value), and (h) Concours (Design Contest). The Chambre des Comptes of the Supreme Court conducts ex-post procurement audit. The Commission Nationale Anti-Corruption (CONAC) has investigative jurisdiction over procurement-related corruption. Cameroon is a party to CEMAC, ECCAS, AfCFTA, and UNCAC. Cameroon is NOT a party to the WTO Government Procurement Agreement (GPA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "cm-cybersec-dp-2010",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "cmmc-2-audit",
    "title": "CMMC 2.0 Level 2 Cybersecurity (Advanced)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "A mandatory US Department of Defense (DoD) certification for contractors handling Controlled Unclassified Information (CUI), based on the 110 practices of NIST SP 800-171.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-cui",
      "dfars-7012-defense-cyber"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cmmi-capability-maturity-model-integration-2-0",
    "title": "Capability Maturity Model Integration (CMMI) V2.0: Practice Areas, Capability Levels and Performance Management for Process Improvement",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "CMMI V2.0 establishes a framework for assessing and improving organizational processes across development, services, and supplier management. It applies to enterprises seeking process maturity certification and requires implementation of 16 core practice areas with defined performance expectations at each capability level (0-3), per Section 2.3 'Model Foundation'.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "automation-bpmn-service-task",
      "automation-bpmn-error-boundary",
      "kcs-evolve-loop"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cmr-convention-1956-road-carriage-goods",
    "title": "CMR Convention 1956 - Convention on the Contract for the International Carriage of Goods by Road",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-25",
    "bluf": "The CMR Convention (1956 - 58 Contracting States as of 2025) governs all contracts for the international carriage of goods by road for reward between two Contracting States (Article 1), mandatorily applying where loading or unloading is in a Contracting State regardless of parties' choice of law; the CMR consignment note is the primary contract evidence (Article 4-5), the carrier has strict liability for loss, damage, or delay (Article 17) subject to limited defences (inherent vice, acts of sender/consignee, war, public authority), and liability is capped at 8.33 SDR per kilogram of gross weight of goods lost (Article 23); the CMR e-note (e-CMR) under the 2008 Additional Protocol is increasingly used for digitised road transport; 2-year limitation period for all claims (Article 32); jurisdiction in carrier's state, claimant's state, or agreed forum (Article 31) - freight forwarders, carriers, shippers, and insurance underwriters must incorporate CMR provisions in carrier contracts as they override contractual liability limitations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hague-visby-rules-1968",
      "un-cisg-1980",
      "eu-csrd-2022-2464",
      "rotterdam-convention-pic-chemicals-2004"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cn-algorithm-recommendation-measures-2022",
    "title": "China Algorithm Recommendation Management Provisions 2022",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "China's Provisions on the Management of Algorithm Recommendation in Internet Information Services, effective March 1, 2022, impose transparency, labelling, and user rights obligations on internet services using algorithmic recommendation systems - prohibiting discrimination, manipulation of prices and markets, addiction-inducing design targeting minors, and requiring providers to allow users to view and opt out of personalised recommendations - making China the first jurisdiction globally to enact comprehensive mandatory algorithmic recommendation regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/cn-algorithm-recommendation-measures-2022.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cn-pipl-2021",
      "cn-csl-2017"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cn-biosecurity-law-2021",
    "title": "Biosecurity Law of the People's Republic of China (2021)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Biosecurity Law of the People's Republic of China (2021) maintains national security and safeguards public health, biological resources and the ecological environment (Article 1). Article 34 prohibits biotechnology research, development and application that endangers public health or undermines ecosystems and biological diversity; Article 36 divides biotechnology R&D into high-risk, medium-risk and low-risk levels; and Article 38 requires high-risk and medium-risk activities to be carried out by approved legal persons with risk assessments and prevention plans. Articles 42 and 43 set biosecurity management and categorical management for pathogenic microbiology laboratories and pathogenic microbes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "cn-cac-ai-generated-content-labelling-measures-2025",
    "title": "China CAC Measures for Labelling AI-Generated Synthetic Content 2025 - Explicit and Implicit Labels under GB 45438-2025",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Internet information service providers and providers of online content distribution services creating AI-generated content for the China market must, from 1 September 2025, apply explicit labels to AI-generated text, images, audios, videos and virtual scenes (such as the indicator 'AI-generated' or an 'AI' icon at the beginning or end of the content), apply implicit labels to the metadata of AI-generated content files, and propagation service providers must verify whether file metadata contains implicit labels, add their own company identifier and a unique content identifier to the metadata, and inform the public that the content is AI-generated by adding prominent noticing labels around the published content, in accordance with the Cyberspace Administration of China's final Measures and the mandatory national standard GB 45438-2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cn-cac-genai-measures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cn-cac-genai-measures",
    "title": "China CAC Generative AI & Algorithmic Registry",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Mandatory security assessment and algorithmic filing requirements for public-facing generative AI services and agents operating within or interacting with mainland China.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-global-digital-compact"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cn-csl-2017",
    "title": "China Cybersecurity Law 2017",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "China's Cybersecurity Law establishes a foundational network security framework requiring real-name registration for internet users, data localisation for critical information infrastructure operators, network security graded protection standards, and civil penalties of up to CNY 1 million with suspension of operations for serious violations effective June 1, 2017.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/cn-csl-2017.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cn-pipl-2021",
      "cn-dsl-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cn-deep-synthesis-measures-2022",
    "title": "China Provisions on the Administration of Deep Synthesis Internet Information Services 2022",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "China's CAC, MIIT and MPS mandate that deep synthesis service providers label all AI-generated synthetic media, implement real-name verification for users, prohibit non-consensual identity impersonation, and file new deep synthesis functions with regulators, effective January 10, 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/cn-deep-synthesis-measures-2022.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cn-pipl-2021",
      "cn-csl-2017"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cn-dsl-2021",
    "title": "China Data Security Law 2021",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "China's Data Security Law establishes a hierarchical national data classification system designating core data, important data, and general data with progressively stringent security requirements, restricts overseas provision of data that may affect national security, mandates security assessments for important data exports, and imposes civil penalties of up to CNY 10 million and criminal penalties for the most serious violations effective September 1, 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/cn-dsl-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cn-pipl-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cn-government-procurement-law-of-the-peoples-republic-of-china-2002-amended",
    "title": "China Government Procurement Law of the People's Republic of China (2002, as amended 2014) + Implementing Regulations",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Government Procurement Law of the People's Republic of China was adopted by the Standing Committee of the National People's Congress on 29 June 2002 and entered into force on 1 January 2003, with substantive amendments in 2014. The Law is the principal statute governing government procurement of goods, construction works, and services by state organs at all levels (central and local) using fiscal funds. The Law spans nine chapters covering General Provisions (Chapter I), Parties to Government Procurement (Chapter II), Government Procurement Methods (Chapter III), Procurement Procedures (Chapter IV), Government Procurement Contracts (Chapter V), Questions and Complaints (Chapter VI), Supervision and Inspection (Chapter VII), Legal Liability (Chapter VIII), and Supplementary Provisions (Chapter IX). The principal procurement methods specified in art. 26 are open tendering (the default method), invited tendering (limited supplier set), competitive negotiation, single-source procurement (sole-source justified), inquiry procurement (for standardised products), and other methods stipulated by the State Council; the 2018 implementing rules added competitive consultation as an additional method for service procurement. The Law operates alongside the Bidding Law of the PRC (1999, amended 2017) which governs tendering for construction, engineering, and other regulated investment projects (a related but distinct legal regime). Government procurement is administered through the Ministry of Finance at the central level and Finance Departments at the provincial and local levels, with operational delivery through centralised procurement agencies and through the China Government Procurement Network at ccgp.gov.cn as the mandatory transparency portal. The Law establishes preferences for domestic goods, construction, and services (art. 10) and supports Made in China industrial policy through procurement preferences. China is a long-standing observer of the WTO Agreement on Government Procurement (GPA) with accession negotiations ongoing since 2007; the Law is widely understood to remain non-compliant with several GPA provisions pending the political accession decision. The framework intersects the Cybersecurity Law of the PRC (2017), the Data Security Law (2021), the Personal Information Protection Law (PIPL 2021), and the Cyberspace Administration of China (CAC) cybersecurity review regime for cloud and IT procurement involving critical information infrastructure operators (CIIOs).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "cn-network-data-security-management-regulations-2024",
    "title": "China Network Data Security Management Regulations 2024 - State Council Decree Effective 1 January 2025",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Network data processors operating in China, including domestic and foreign-based entities that process data related to individuals or organizations in China when offering products or services, analysing or evaluating behavior within the country, or handling important domestic data, must apply the Network Data Security Management Regulations signed by Chinese Premier Li Qiang as a State Council decree on 30 September 2024 and effective 1 January 2025, which regulate network data processing activities, protect the legitimate rights and interests of individuals and organizations, safeguard national security and public interests, specify rules for personal information protection, fine-tune mechanisms for the management of important data, and clarify the conditions for cross-border provision of personal information to overseas parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cn-cac-genai-measures"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cn-network-data-security-regulations-2024",
    "title": "China Network Data Security Management Regulations 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "China's Network Data Security Management Regulations, promulgated by the State Council on September 24, 2024 and effective January 1, 2025, implement and operationalise the Data Security Law and Personal Information Protection Law by establishing detailed rules for cross-border data transfers, important data identification and management, data security obligations for internet platforms, and certification requirements for personal information handlers - applying to all organisations processing network data within China.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/cn-network-data-security-regulations-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cn-pipl-2021",
      "cn-dsl-2021",
      "cn-csl-2017"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cn-pipl-2021",
    "title": "China Personal Information Protection Law 2021",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "China's Personal Information Protection Law establishes a comprehensive personal data protection framework modelled partly on GDPR, requiring consent for processing, separate explicit consent for sensitive personal information, mandatory cross-border transfer mechanisms, and civil penalties of up to 5 percent of annual revenue or CNY 50 million for the most serious violations effective November 1, 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/cn-pipl-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ng-dpa-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cn-regulations-management-human-genetic-resources-2019-state-council-717",
    "title": "China Regulations on Management of Human Genetic Resources State Council Order No. 717 2019 Collection Preservation International Use and Cross-Border Sharing Approval Regime",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "The People's Republic of China Regulations on the Management of Human Genetic Resources promulgated by State Council Order No. 717 effective 1 July 2019 administered by the Ministry of Science and Technology Human Genetic Resources Administration of China establish a comprehensive approval and oversight regime for the collection preservation utilisation and international cooperation involving Chinese human genetic resources organised across operative chapters including Chapter 1 General Provisions establishing scope and definitions of human genetic resources covering organs tissues cells and derived DNA proteins and genetic information Chapter 2 Collection requiring approval from the Ministry of Science and Technology for collection of important genetic family resources and resources from specific regions Chapter 3 Preservation establishing requirements for preservation institutions including ethical review and data security Chapter 4 Utilisation requiring scientific research justification ethical review and reporting of intermediate results Chapter 5 International Cooperation prohibiting cross-border transfer of materials without approval and requiring data sharing review for cross-border data flows Chapter 6 Supervision and Administration establishing inspection and reporting authority and Chapter 7 Legal Liability including fines up to 10 times illegal gains or RMB 1 million for individuals and RMB 10 million for entities plus confiscation of resources and revocation of licenses. The 2023 implementing rules further detail the approval pathways.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "china-pipl-2021-personal-information-protection"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "cncf-cloudevents-1-0-event-driven-workflow-specification",
    "title": "CNCF CloudEvents 1.0 - Event-Driven Workflow Interoperability Specification",
    "domain": "Workflow Automation",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "CNCF CloudEvents 1.0 (CNCF Graduated Project, 2018, updated 2022) defines a vendor-neutral specification for describing event data in a common format to achieve interoperability across event-driven workflows, serverless platforms, and message brokers. Required envelope fields: specversion (must be '1.0'), id (unique per source), source (URI-reference), type (reverse-DNS identifier e.g. 'com.example.compliance.node.updated'), and datacontenttype (e.g. 'application/json'). Optional fields: subject, time (RFC 3339), dataschema, and extension attributes. Enables regulatory event streams (data changes, access logs, consent updates) to be produced and consumed across AWS EventBridge, Azure Event Grid, Google Cloud Pub/Sub, Apache Kafka, and NATS without platform lock-in.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_framework",
        "regulatory_mapping",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "w3c-prov-dm-provenance-data-model-workflow-audit-trail",
      "bpmn-2-0-business-process-model-notation"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "co-conpes-3975-2019-digital-transformation-ai-policy",
    "title": "Colombia CONPES 3975 (2019) - Política Nacional para la Transformación Digital e Inteligencia Artificial; MinCiencias 2025 Proyecto de Ley AI Framework; National AI Authority Designation",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Colombia's national artificial intelligence policy framework is anchored by Documento CONPES 3975 (Consejo Nacional de Política Económica y Social) Política Nacional para la Transformación Digital e Inteligencia Artificial approved on 8 November 2019 and published by the Departamento Nacional de Planeación (DNP) at colaboracion.dnp.gov.co/CDT/Conpes/Económicos/3975.pdf. CONPES 3975 establishes Colombia as the second LATAM country (after Argentina's earlier strategy) to publish a formal national AI policy and sets four strategic pillars: (1) reducing barriers to digital technology adoption in business and the State; (2) creating enabling conditions for digital innovation in both private and public sectors; (3) strengthening human capital competencies for the Fourth Industrial Revolution; (4) developing enabling conditions to prepare Colombia for the economic and social changes brought about by AI. The policy is operationalised through CONPES-mandated action plans coordinated by the Ministerio de las TIC (MinTIC), the Departamento Administrativo de la Función Pública (DAFP), and sector ministries. The Gobierno Nacional 2025 Proyecto de Ley for AI regulation led by the Ministerio de Ciencia Tecnología e Innovación (MinCiencias) under Minister Yesenia Olaya Requena (filed with Congress 2025 in coordination with MinTIC) consolidates several earlier projects (PL 059-23, PL 200/2023 C, and others) and designates MinCiencias as the National AI Authority. The Proyecto de Ley follows a four-tier risk-based regulatory approach (prohibited, high, limited, low) aligned with the EU AI Act structure and addresses ethical and sustainable AI development, positive social/economic/environmental impact, research and innovation, and fundamental rights protections. The Colombian framework operates alongside Ley 1581 de 2012 (Habeas Data - personal data protection) administered by the Superintendencia de Industria y Comercio (SIC) Delegatura para la Protección de Datos Personales, the UNESCO Recommendation on the Ethics of AI (2021), and the OAS Inter-American AI Network coordination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "conpes_3975_pillar_1_business_state_adoption",
        "conpes_3975_pillar_2_enabling_innovation_conditions",
        "conpes_3975_pillar_3_human_capital_4ir",
        "conpes_3975_pillar_4_economic_social_preparation",
        "conpes_3975_action_plan_and_governance",
        "2025_proyecto_de_ley_minciencias_consolidation",
        "2025_proyecto_de_ley_four_tier_risk_approach",
        "2025_proyecto_de_ley_pillars",
        "ley_1581_2012_habeas_data_underlying_basis",
        "international_alignment_unesco_oas",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "co-habeas-data-2012",
      "co-ley-1581-2012-habeas-data-personal-data-protection",
      "eu-ai-act-article-50-transparency-obligations",
      "nist-ai-rmf-1-0-govern-function",
      "unesco-ai-ethics-work"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "co-estatuto-general-contratacion-ley-80-1993-ley-1150-2007-ley-2069-2020",
    "title": "Colombia Estatuto General de Contratacion de la Administracion Publica (Ley 80 of 1993, Ley 1150 of 2007, Ley 2069 of 2020) and SECOP Electronic Procurement Platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Colombian Estatuto General de Contratacion de la Administracion Publica (General Statute on Public Administration Contracting) is comprised of Ley 80 of 28 October 1993 (foundational law), Ley 1150 of 16 July 2007 (modernisation amendment introducing electronic procurement and best-value criteria), Ley 2069 of 31 December 2020 (entrepreneurship promotion amendment), and Ley 2195 of 18 January 2022 (transparency amendment), together with implementing decrees including Decreto 1082 of 26 May 2015 (consolidated single decree on procurement) as the principal Colombian framework governing procurement of goods, services, and works by entities of the State Public Administration including ministries, administrative departments, governorates and departmental entities, municipalities and municipal entities, the National Civil Society (Sociedad Civil Nacional), public-sector enterprises, mixed-economy companies, special administrative units, public-sector universities, and other entities subject to the General Statute or to special procurement regimes. Colombia operates a hybrid procurement framework: the General Statute (Ley 80/1993 et seq.) governs the majority of public administration procurement, while certain entities operate under special regimes (regimenes especiales) including Ecopetrol, ISA, public-sector financial institutions, and entities of the social security and health system. Colombia Compra Eficiente (colombiacompra.gov.co) is the central public procurement authority responsible for procurement policy, procurement guidance, and operation of the SECOP electronic procurement platform. The Sistema Electronico para la Contratacion Publica (SECOP I and SECOP II) is the federal e-procurement platform with SECOP II as the transactional electronic procurement platform. Procurement methods established by the General Statute and Decreto 1082/2015 art. 2.2.1.2.1.1.1 to 2.2.1.2.1.5.4 comprise (a) Licitacion Publica (Public Tender, default open public procedure), (b) Seleccion Abreviada (Abbreviated Selection, for prescribed lower-value contracts and standardised goods/services), (c) Concurso de Meritos (Merit Competition, for consultancy services), (d) Contratacion Directa (Direct Contracting, sole-source under prescribed exceptions in Ley 1150/2007 art. 2 numeral 4), (e) Minima Cuantia (Minimum Amount, for very-low-value contracts below 10% of the Minor Amount threshold), and (f) Acuerdo Marco de Precios (Framework Agreement) and Subasta Inversa (Reverse Auction).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "co-ley-1581-2012-habeas-data-personal-data-protection",
      "co-conpes-3975-2019-digital-transformation-ai-policy",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "co-habeas-data-2012",
    "title": "Statutory Law 1581 of 2012 by which general provisions for the protection of personal data are dictated (Habeas Data)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This law establishes the general principles and provisions for the protection of personal data in Colombia, applying to any entity processing personal data within Colombian territory. It mandates that data controllers obtain prior, express, and informed consent from the data subject for processing (Article 9) and guarantees the subject's rights to access, update, and rectify their information (Article 8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-popia-2013",
      "brazil-lgpd-compliance",
      "gdpr-data-protection-officer",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "co-ley-1581-2012-habeas-data-personal-data-protection",
    "title": "Colombia Ley 1581/2012 - Habeas Data and Personal Data Protection (ARCO Rights)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Colombia's Ley Estatutaria 1581/2012 establishes fundamental ARCO data rights (Access, Rectification, Suppression, Opposition), requires prior authorisation (consent) before personal data collection, mandates SIC database registration, prohibits processing of sensitive personal information without explicit consent, grants a habeas data constitutional action for data subjects, and imposes penalties up to 2,000 monthly minimum wages enforced by the Superintendencia de Industria y Comercio (SIC).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "br-lgpd-law-13709-2018-data-protection-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "co-sic-directive-002-2024-ai-personal-data",
    "title": "Colombia SIC Directive 002 of 2024 - Processing of Personal Data in the Use of Artificial Intelligence, Issued 21 August 2024",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Data controllers, data processors, and users that develop or use AI based on information containing personal data in Colombia must comply with Directive 002 of 2024 issued by the Superintendence of Industry and Commerce (SIC) on 21 August 2024 under the Colombian personal data protection regime (Laws 1266 of 2008 and 1581 of 2012), ensuring that processing meets criteria of suitability, necessity, reasonableness, and proportionality, identifying, measuring, controlling, and monitoring risks associated with personal data, providing data subjects with a clear and understandable explanation of any automated decision that negatively impacts them, allowing individuals to contest AI-driven decisions, and carrying out a privacy impact study with the minimum information specified by the Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "co-slhc-2012",
    "title": "Colombia Statutory Law 1581 of 2012 - Ley de Habeas Data and SIC Enforcement",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Colombia's Ley Estatutaria de Protección de Datos Personales (Statutory Law on the Protection of Personal Data) - Ley Estatutaria 1581 of 2012, passed by the Colombian Congress and signed into law on 17 October 2012, published in the Diario Oficial No. 48.587 - is Colombia's primary comprehensive personal data protection legislation, establishing the legal framework for the collection, storage, use, circulation, and deletion of personal data. Ley 1581 of 2012 is constitutionally grounded in Colombia's habeas data right, recognised in Art. 15 of the 1991 Constitution of Colombia, which grants every person the right to know, update, and rectify information collected about them in databases and archives. Ley 1581 of 2012 was preceded by Law 1266 of 2008, which regulated financial, credit, commercial, and other data (commonly known as the 'Habeas Data Law for financial data'). Ley 1581 of 2012 operates alongside Law 1266/2008 - financial credit data is primarily governed by Law 1266/2008 while general personal data falls under Ley 1581/2012. The enforcement authority is the Superintendencia de Industria y Comercio (SIC - Superintendency of Industry and Commerce), which has a dedicated Personal Data Protection Division (Delegatura para la Protección de Datos Personales). Key features of Ley 1581/2012: (1) Responsible and Encargado - 'Responsible' (Responsable del Tratamiento - the data controller equivalent) and 'Encargado' (Encargado del Tratamiento - the data processor equivalent) terminology; (2) Eight principles: lawfulness, purpose, freedom, truthfulness/quality, transparency, restricted access and circulation, security, and accountability (Confidencialidad); (3) Sensitive data - race or ethnicity; political orientation; religious or philosophical convictions; trade union membership; social organisations membership; human rights organisations membership; data relating to health; sexual life; biometric data; (4) Consent - freely given, prior, and express consent is required for processing personal data; (5) Habeas data rights - individuals have the right to know, update, rectify, and suppress their personal data; (6) Registration - all databases containing personal data must be registered with the National Registry of Databases (Registro Nacional de Bases de Datos - RNBD) maintained by the SIC; (7) Privacy notice (Aviso de Privacidad) - mandatory before processing; (8) Data Processor Agreement - agreements between Responsible (controller) and Encargado (processor) are mandatory; (9) International data transfers - transfers to countries without adequate protection require prior SIC authorisation or data transfer agreements; (10) Administrative sanctions: up to COP 2,000 daily minimum wages (approximately COP 2.5 billion or USD 600,000 as of 2026) for violations; Colombia does not have EU GDPR adequacy recognition. Colombia is South America's third-largest economy and a major technology hub, particularly in fintech and digital commerce.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cobit-2019-governance-framework",
    "title": "COBIT 2019: A Business Framework for the Governance and Management of Enterprise Information and Technology (I&T)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "COBIT 2019 provides a comprehensive framework for governing and managing enterprise information and technology (I&T) to align with business goals. It establishes 40 core governance and management objectives, such as APO01 (Managed I&T Management Framework) and DSS05 (Managed Security Services), to help enterprises create optimal value from I&T by balancing benefit realization, risk optimization, and resource utilization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt",
      "csa-ccm-v4-cloud-controls",
      "nist-sp-800-39-managing-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cobit-2019-governance-workflow-processes",
    "title": "COBIT 2019 - Governance and Management Objectives for IT Workflow Processes: APO, BAI, DSS, MEA Domains and Process Capability Assessment",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "COBIT 2019 provides a comprehensive framework for the governance and management of enterprise IT, establishing structured workflow controls across Align, Plan, Organize (APO), Build, Acquire, Implement (BAI), Deliver, Service, Support (DSS), and Monitor, Evaluate, Assess (MEA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-27001-2022",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "codex-alimentarius-fish-fishery-products-standard",
    "title": "Code of Practice for Fish and Fishery Products (CAC/RCP 52-2003)",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes hygiene and safety requirements for the handling, processing, and distribution of fish and fishery products, with specific controls for pre-harvest, harvest, processing, cooling, and HACCP implementation. It applies to all operators in the fish and fishery products chain under CXC 52-2003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "codex-haccp-2022",
      "eu-food-hygiene-regulation-852-2004",
      "brc-food-safety-global",
      "iso-13009-beach-mgmt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "codex-alimentarius-gen",
    "title": "Codex Alimentarius Code",
    "domain": "Food & Hospitality",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Operational alignment with the Codex Alimentarius framework is achieved through stringent controls governing food safety, traceability, and international trade ethics. The configuration mandates adherence to the General Principles of Food Hygiene by requiring a minimum of eight hygiene training hours per employee and activating continuous HACCP sensor monitoring, which includes a temperature control polling interval set to 60 seconds. To support the Principles for Traceability/Product Tracing, the system enforces mandatory lot identification tracking coupled with an automated product recall capability; all related data must be retained for 1825 days within secure, tamper-evident digital logs. Compliance with the General Standard for Contaminants and Toxins in Food and Feed is managed via a strict maximum contaminant reporting latency of 24 hours. Furthermore, the node validates conformance with the General Standard for the Labelling of Prepackaged Foods by enabling active allergen labeling validation processes. System integrity and the efficacy of these measures are verified against the Guidelines for the Validation of Food Safety Control Measures through biannual supply chain audits and enabled OT/SCADA security controls. This entire schema operates under the ethical aegis of the Code of Ethics for International Trade in Food, with continuous monitoring of FAO/WHO guideline updates to ensure perpetual compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "haccp-food-safety",
      "iso-22000-food-mgt",
      "gfsi-benchmarking",
      "eu-food-law-178-2002",
      "fda-fsma-compliance",
      "food-allergen-label-law"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "codex-alimentarius-general-principles-hygiene-2020",
    "title": "Codex Alimentarius General Principles of Food Hygiene CAC/RCP 1-1969 (2020 Update) - HACCP System, Prerequisite Programmes and Good Hygienic Practice",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This standard establishes the foundational principles for ensuring food safety through the implementation of Good Hygienic Practices (GHP), prerequisite programmes, and the HACCP system, applicable to all actors in the food chain. It requires food businesses to identify, assess, and control hazards as per Principle 1 and Section IV of the Codex Alimentarius CAC/RCP 1-1969 (2020).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-gen",
      "eu-food-hygiene-regulation-852-2004",
      "brc-food-safety-global",
      "codex-haccp-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "codex-cxc-1-1969-general-principles-food-hygiene",
    "title": "Codex Alimentarius CXC 1-1969: General Principles of Food Hygiene (including HACCP Annex)",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "CXC 1-1969, the General Principles of Food Hygiene, is the foundational Codex Code of Practice underpinning all national food safety regulation worldwide. It sets out general hygiene principles covering primary production (Section 3), establishment design and facilities (Section 4), control of operation (Section 5), maintenance and sanitation (Section 6), personal hygiene (Section 7), transportation (Section 8), product information and consumer awareness (Section 9), and training (Section 10). The Annex on HACCP describes the seven HACCP principles (hazard analysis, CCP identification, critical limits, monitoring, corrective action, verification, documentation) and the twelve-step HACCP application logic sequence. CXC 1-1969 is referenced by WTO SPS and forms the basis of national food safety laws including EU Food Hygiene Regulation, the US FSMA preventive controls rule, the Canadian Safe Food regulations, the Australian Food Safety Practices Standard, the FSSAI Schedule of food categories. Non-compliance with HACCP-based preventive controls is the leading cause of food safety enforcement action globally.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_22000",
        "wto_sps",
        "eu_852",
        "us_fsma_117",
        "sfcr_canada",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "codex-cxs-1-1985-labelling-prepackaged-foods",
    "title": "Codex Alimentarius CXS 1-1985: General Standard for the Labelling of Prepackaged Foods",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "CXS 1-1985 is the global Codex baseline standard for mandatory labelling of prepackaged foods, adopted by the Codex Alimentarius Commission and referenced by the WTO SPS and TBT Agreements as the international benchmark. It mandates the name of the food, list of ingredients, net contents, name and address of the manufacturer, country of origin, lot identification, date marking, storage instructions, and language requirements. the relevant section lists mandatory labelling elements; the relevant section covers exemptions; the relevant section sets out optional declarations and the rules under which they may be made. Compliance is enforced through national food regulators that transpose the standard via domestic law (EU Food Information to Consumers Regulation, US FDA the US FDA food labelling rule, FSSAI Packaging and Labelling Regulations 2011, etc.). Non-compliance triggers product detention at borders, mandatory recall, and refusal of import.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "wto_sps",
        "wto_tbt",
        "eu_food_info",
        "us_fda",
        "fssai_india",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "codex-cxs-192-1995-food-additives-gsfa",
    "title": "Codex Alimentarius CXS 192-1995: General Standard for Food Additives (GSFA)",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "CXS 192-1995, the General Standard for Food Additives (GSFA), is the global Codex framework setting maximum use levels for permitted food additives across all food categories. The standard categorises foods using the Codex Food Category System (Annex B), assigns each permitted additive an International Numbering System (INS) number, and lists maximum permitted concentrations in mg/kg or g/kg for each additive/food-category pairing. the relevant section sets out general conditions for use; the relevant section lists carry-over from raw materials; the relevant section covers technological function classifications. Maximum levels are set on the basis of Joint FAO/WHO Expert Committee on Food Additives (JECFA) safety evaluations and Acceptable Daily Intake (ADI) values. National regulators (EU EFSA, US FDA, FSSAI, ANVISA, FSANZ) reference GSFA as the international baseline. Non-compliance triggers product detention, recall, and refusal of import.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "jecfa",
        "wto_sps",
        "eu_efsa",
        "us_fda",
        "fssai_india",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-cxs-1-1985-labelling-prepackaged-foods"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "codex-cxs-193-1995-contaminants-toxins-food-feed",
    "title": "Codex Alimentarius CXS 193-1995: General Standard for Contaminants and Toxins in Food and Feed",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "CXS 193-1995 sets the global Codex Maximum Levels (MLs) for contaminants and natural toxins in food and feed, including heavy metals (lead, cadmium, mercury, arsenic, tin), mycotoxins (aflatoxins, ochratoxin A, patulin, fumonisins, deoxynivalenol, zearalenone), process contaminants (acrylamide, 3-MCPD esters, glycidyl esters, chloropropanols), dioxins, PCBs, radionuclides, and natural toxins. Maximum levels are derived from Joint FAO/WHO Expert Committee on Food Additives (JECFA) and Joint FAO/WHO Meeting on Pesticide Residues (JMPR) evaluations using ALARA (As Low As Reasonably Achievable) principles. The standard is referenced by WTO SPS as the international benchmark and is transposed into EU Contaminants Regulation 2006, US FDA action levels, the FSSAI contaminants schedule, ANVISA RDC 487/2021, FSANZ Standard 1.4.1. Non-compliance triggers product detention at the border, recall, destruction order, and operator penalties under national food safety law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "jecfa_jmpr",
        "wto_sps",
        "eu_contaminants",
        "us_fda_action",
        "fssai_india",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-cxs-1-1985-labelling-prepackaged-foods"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "codex-haccp-2022",
    "title": "Codex Alimentarius General Principles of Food Hygiene (CXC 1-1969 Rev. 2022) - HACCP System and Application Guidelines",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard provides a systematic framework for food business operators to ensure food safety through the Hazard Analysis and Critical Control Point (HACCP) system. It mandates the application of the seven core principles detailed in Chapter Two, requiring the identification, evaluation, and control of significant food safety hazards throughout the production process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-gen",
      "haccp-food-safety",
      "iso-22000-food-mgt",
      "gfsi-benchmarking",
      "brc-food-safety-global"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "codex-stan-192-2023-general-food-additive-standard",
    "title": "Codex General Standard for Food Additives (GSFA) CODEX STAN 192-1995 (2023 Revision) - INS Numbering System, Functional Classes (Preservatives, Antioxidants, Emulsifiers), Maximum Use Levels by Food Category and Carry-Over Principle",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This standard establishes the conditions under which permitted food additives may be used in foods, specifying maximum use levels by food category, functional classes, and the carry-over principle. It applies to all food business operators involved in the production, processing, and distribution of food products intended for international trade. Key provisions are defined in the Preamble and Annex B of the GSFA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "codex-alimentarius-gen",
      "eu-food-hygiene-regulation-852-2004",
      "brc-food-safety-global",
      "codex-haccp-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "coe-convention-108-plus",
    "title": "Protocol amending the Convention for the Protection of Individuals with regard to the Processing of Personal Data (Convention 108+)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Convention 108+ is a binding international treaty requiring signatory nations to establish a legal framework for protecting personal data processed by both public and private entities. It mandates core principles for data processing, including lawfulness, fairness, purpose limitation, data minimization, and security, as detailed in Article 5, and establishes enhanced rights for data subjects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "brazil-lgpd-compliance",
      "za-popia-2013",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "coe-framework-convention-ai-human-rights-democracy",
    "title": "Council of Europe Framework Convention on AI, Human Rights, Democracy and the Rule of Law (CETS No. 225)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The Council of Europe's Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225), opened for signature on 5 September 2024 in Vilnius, is the world's first legally binding international treaty on AI - it applies to AI systems used in the public sector and private-sector contexts within the jurisdiction of its Parties (EU Member States, the US, UK, Canada, Japan, Israel, and others), requiring Parties to ensure that their domestic legal frameworks guarantee human rights, democracy, and the rule of law when AI systems are used; signatories include Council of Europe member states and non-European observer states, making it the primary binding international AI governance instrument applicable beyond EU borders; the Convention does not impose specific technical standards but requires legal safeguards for transparency, accountability, non-discrimination, privacy, and meaningful redress against AI-related harms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/coe-framework-convention-ai-human-rights-democracy.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-27-fria-fundamental-rights",
      "eu-ai-act-article-86-right-to-explanation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "coe-lanzarote-convention-2007-article-18-sexual-abuse",
    "title": "Council of Europe Lanzarote Convention 2007 Article 18 - Sexual Abuse of Children",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Article 18 of the Council of Europe Convention on the Protection of Children against Sexual Exploitation and Sexual Abuse (Lanzarote Convention, CETS No. 201, 2007) requires States Parties to criminalise intentional conduct constituting sexual abuse of children. Article 18(1)(a) covers engaging in sexual activities with a child who, according to the relevant provisions of national law, has not reached the legal age for sexual activities. Article 18(1)(b) covers engaging in sexual activities with a child where use is made of coercion, force, or threats; or abuse is made of a recognised position of trust, authority, or influence; or abuse is made of a particularly vulnerable situation. Article 18(2) preserves national discretion on consensual sexual activities between peers. Article 18(3) preserves national discretion regarding age of consent. The Lanzarote Convention is the most comprehensive international legal framework on child sexual abuse and is closely aligned with EU Directive 2011/93/EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "article_18_paragraph_1_a_sexual_activities_below_age_of_consent",
        "article_18_paragraph_1_b_coercion_force_threats_or_abuse_of_position",
        "article_18_paragraph_2_national_discretion_on_consensual_peer_activities",
        "article_18_paragraph_3_national_discretion_on_age_of_consent",
        "child_definition_article_3_a_under_18",
        "intentional_mens_rea_required_throughout",
        "convention_overall_framework_articles_18_to_23",
        "lanzarote_committee_monitoring_implementation",
        "interaction_with_eu_directive_2011_93_close_alignment",
        "extraterritorial_jurisdiction_article_25"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-directive-2011-93-article-3-sexual-abuse-offences",
      "eu-directive-2011-93-article-4-sexual-exploitation",
      "eu-directive-2011-93-article-5-offences-concerning-child-pornography"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "cold-chain-integrity-logic",
    "title": "Cold Chain Integrity Triage",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Automated compliance verification for temperature-sensitive assets is governed by a stringent rule set designed to meet international regulatory standards. The system enforces good distribution practice tenets outlined within EU GDP Guidelines and aligns with World Health Organization recommendations in Annex 9 for pharmaceutical storage, while also satisfying core requirements of the US FDA Food Safety Modernization Act for sanitary transportation and ISO 22000 food safety management principles. Shipments must maintain continuous product temperature between 2 and 8 degrees Celsius, with any excursion limited to a maximum deviation of 0.5 degrees Celsius. If a temperature breach occurs, it cannot persist beyond a 15-minute threshold before triggering an alert. To ensure data integrity and establish a secure, time-stamped audit trail consistent with FDA 21 CFR Part 11, continuous temperature monitoring is enabled, logging encrypted IoT sensor data at a 5-minute interval. The application of NIST SP 800-82 security principles is evident through active GPS tracking, the confirmed absence of detected cyber intrusions, and use of an immutable blockchain audit ledger for all telemetry records. Physical security is confirmed via verified tamper-evident seals, providing a holistic assessment of cold chain integrity from origin to destination for the immediate triage of non-conforming events.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-11-records",
      "fda-fsma-compliance",
      "gs1-epcis-transparency",
      "iso-28000-supply-chain",
      "nist-sp-800-82r3-ot-security"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "colombia-coljuegos-law-643-2001",
    "title": "Law 643 of 2001 - Regulation of Games of Chance and Creation of the National Gaming Authority (Coljuegos)",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "Law 643 of 2001 establishes the state monopoly over games of chance in Colombia, grants exclusive regulatory and supervisory authority to Coljuegos, and mandates that 50% of net gaming revenues be allocated to public health programs. It applies to all operators, licensees, and intermediaries involved in legal gaming activities under Article 1 and Article 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "colombia-coljuegos-online-gaming-regulations-2016",
    "title": "Colombia Coljuegos Online Gaming Regulations 2016 - Juegos de Azar Online",
    "domain": "Gaming & Gambling",
    "version": "2016-04",
    "last_updated": "2026-05-09",
    "bluf": "Colombia's Coljuegos (Empresa Industrial y Comercial del Estado Administradora del Monopolio Rentístico de los Juegos de Suerte y Azar) regulates online gaming under Decree 1966/2013 and Resolution 20161300028265/2016, requiring operators to obtain a 5-year online gaming licence, channel 15% of gross gaming revenue to public health, implement player protection including self-exclusion, and comply with AML obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021",
      "responsible-gambling-grb-standards-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "colombia-decreto-1067-2015-migracion-colombia",
    "title": "Colombia Decreto 1067 de 2015 - Migracion Colombia Visa and International Protection Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Decreto Unico Reglamentario 1067 de 2015 del Sector Administrativo de Relaciones Exteriores consolidates Colombia's immigration regulatory framework. Unidad Administrativa Especial Migracion Colombia (Migracion Colombia) under the Ministry of Foreign Affairs (Cancilleria) administers entry, stay, and departure of foreigners. Colombia's visa regime classifies visas as: Visitante (V - temporary visitor), Migrante (M - migrant for work or study), and Residente (R - permanent residency). The ETPV (Estatuto Temporal de Proteccion para Venezolanos, Decreto 216/2021) granted 10-year temporary protection status to over 2.5 million Venezuelan nationals in Colombia - the largest TPS programme in the Western Hemisphere. Colombia established a Digital Nomad visa option through Migracion Colombia in 2021. MERCOSUR citizens benefit from facilitated 2-year residence. Overstaying beyond authorised period results in administrative fines. Foreign nationals with MERCOSUR or other facilitating agreements apply for Residencia Permanente under simplified processes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "mercosur",
        "venezolan_protection",
        "data_protection",
        "labour_code",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "colombia-gambling-law-643-2001-coljuegos",
    "title": "Colombia Gambling Law 643 of 2001 - Coljuegos State Monopoly and Online Gaming Framework",
    "domain": "Gaming & Gambling",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Colombia's Ley 643 de 2001 (Law 643 of 2001) established the state's exclusive monopoly over games of chance (juegos de suerte y azar). Coljuegos (Empresa Industrial y Comercial del Estado Administradora del Monopolio Rentistico de los Juegos de Suerte y Azar) is the national government entity that administers, contracts, and supervises all gambling activities at the national level, while departmental lotteries operate at the regional level. Online gambling (juegos novedosos en linea) was formally regulated through Coljuegos resolutions beginning 2016, with operators required to hold a habilitacion (authorisation) from Coljuegos. Revenue from gambling monopoly funds the Colombian public health system (Saneamiento Fiscal de los Hospitales). Minimum gambling age is 18 years. AML obligations under Law 526 of 1999 (UIAF) apply to licensed operators. The sports betting market is the fastest-growing segment following Colombia becoming one of Latin America's first jurisdictions to formally regulate online sports betting and casino.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "aml",
        "fatf_recommendation",
        "data_protection",
        "consumer_protection",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "colombia-law-1480-2011-estatuto-consumidor",
    "title": "Colombia Estatuto del Consumidor (Law 1480/2011) - SIC Enforcement and Product Liability",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Colombia's Estatuto del Consumidor (Law 1480 of 12 October 2011) establishes a comprehensive consumer protection framework enforced by the Superintendencia de Industria y Comercio (SIC); mandates mandatory product warranties (minimum 1 year for goods), right of retracto (withdrawal within 5 business days for distance contracts), product safety obligations, unfair contract terms prohibition, and quality information duties; with fines up to COP 2,000 SMMLV (monthly minimum wages) for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "chile-sernac-consumer-protection-law-19496"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "colombia-mining-code-law-685-2001",
    "title": "Colombia Mining Code - Law 685 of 2001",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Colombia's Mining Code (Law 685/2001, amended by Laws 1382/2010 and 1753/2015) establishes the legal framework for exploration, exploitation, and transformation of mineral resources. It requires a single integrated mining title (titulo minero) through the SIMCO system, mandatory environmental licensing from ANLA, indigenous and Afro-Colombian community consultation, and a royalty regime administered by the National Royalty Fund (SGR).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "peru-general-mining-law-ds-014-92-em",
      "mexico-ley-minera-1992-mining-law"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "colombia-sic-habeas-data-law-1581-2012",
    "title": "Statutory Law 1581 of 2012 on the Protection of Personal Data - Habeas Data Rights and Obligations for Data Controllers and Processors in Colombia",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Colombia's Law 1581 of 2012 establishes the legal framework for the protection of personal data and enshrines the constitutional habeas data right, requiring all entities processing personal data to implement safeguards, notify data subjects, register data processing activities, and comply with strict rules for sensitive data and cross-border transfers. Applies to all public and private data controllers and processors operating in Colombia.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-privacy",
      "aicpa-soc2-cc-confidentiality",
      "uk-money-laundering-regulations-2017-amended"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "combination-products-drug-device-2026",
    "title": "Combination Products (Drug-Device) - Regulatory Governance & Lifecycle Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Combination products (e.g., drug-eluting stents, prefilled syringes, digital therapeutics with drug components) require coordinated regulatory oversight under primary mode of action (PMOA). Manufacturers must comply with both device and drug/biologic requirements, including integrated quality systems, human factors engineering, stability studies, post-market surveillance, and dual reporting obligations to FDA/EMA. 2026 updates emphasize digital elements and AI integration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-medical-qms",
      "eu-mdr-2017-745"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "companion-diagnostics-ivdr-2026",
    "title": "Companion Diagnostics (CDx) - IVDR & Global Regulatory Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Regulatory framework governing Companion Diagnostics (CDx) under the EU In Vitro Diagnostic Medical Devices Regulation (IVDR) 2017/746. It addresses the co-development of drugs and CDx, requiring Notified Body assessment of the CDx and mandatory consultation with a medicinal products competent authority (e.g., EMA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-medical-qms"
    ],
    "primary_citations_count": 2
  },
  {
    "node_id": "compliance-gdpr-dpa",
    "title": "GDPR Data Processing Agreement (DPA) Checklist",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "A compliant Data Processing Agreement establishes a legally binding contract defining the processor's obligations, consistent with European Data Protection Board Guidelines 07/2020. The processor must act exclusively upon documented controller instructions, a mandate under which `unauthorized_cross_border_transfers_blocked` is enforced. This requirement extends to personnel, for whom `personnel_confidentiality_verified` commitments are mandatory. Pursuant to Article 28(3)(c) and Article 32, security of processing is paramount, with `art_32_security_measures_active` representing a baseline condition. Engaging any sub-processor necessitates prior written authorization, as stipulated by Article 28(2); moreover, all data protection obligations must be flowed down contractually, ensuring `subprocessor_flow_down_liability_active`. The processor’s duty to assist its controller is fundamental. This includes enabling responses to data subject requests through `dsar_assistance_enabled` functionality and supporting Data Protection Impact Assessment consultations. Following a personal data breach, notification to the controller must occur without undue delay, respecting the `breach_notification_max_hours` threshold of 72 hours. Upon termination of services, `post_contract_data_deletion_required` is triggered, permitting a `retention_period_days_post_termination` of zero days to guarantee complete data removal. Finally, `controller_audit_rights_enabled` allows for verification of these ongoing compliance commitments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "connected-health-ecosystems-security-2026",
    "title": "Connected Health Ecosystems & IoMT Security Framework (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Comprehensive cybersecurity architecture for the Internet of Medical Things (IoMT) and connected health ecosystems. It addresses the vulnerabilities introduced when legacy medical devices, consumer wearables, and cloud infrastructure are integrated into a continuous patient monitoring network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-privacy-rule",
      "iso-27799-health-informatics-2026",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 2
  },
  {
    "node_id": "constitutional-ai-align",
    "title": "Constitutional AI Algorithm",
    "domain": "AI Governance & Law",
    "version": "1.2.0",
    "last_updated": "2026-07-03",
    "bluf": "Constitutional AI (CAI) is a voluntary alignment research methodology developed by Anthropic (Bai et al., 2022, arXiv:2212.08073), not a law or binding standard, that trains AI systems to be helpful, harmless, and honest using a set of explicit behavioral principles (the 'Constitution') rather than relying exclusively on human feedback labeling of individual outputs. The method operates in two phases: a Supervised Learning from Constitutional AI (SL-CAI) phase where the model critiques and revises its own harmful outputs using principles as guidance, and a Reinforcement Learning from AI Feedback (RL-CAI) phase where an AI-generated preference dataset replaces or supplements human preference labels. CAI has been shown to reduce the need for human labeling of harmful content while producing models that are less harmful and more transparent about their reasoning. As a voluntary research framework, CAI carries no regulatory force of its own; organizations adopting it commonly map the approach to AI governance requirements including EU AI Act Article 9 risk management and NIST AI RMF GOVERN function requirements for systematic safety assurance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "oecd-ai-principles",
      "unesco-ethics-ai",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "contingency-planning-federal-information-systems",
    "title": "Contingency Planning Guide for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2010-05-21",
    "bluf": "This guide provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to a coordinated strategy involving plans, procedures, and technical measures that enable the recovery of information systems, operations, and data after a disruption. It supports the requirement that identified services provided by information systems are able to operate effectively without excessive interruption. This guideline has been prepared for use by federal agencies but may be used by nongovernmental organizations on a voluntary basis and is not subject to copyright.\n\nThe core obligation for applicable organizations is to develop and maintain a viable contingency planning program through a seven-step process integrated into the system development life cycle. This process includes: 1) developing a formal contingency planning policy statement; 2) conducting a business impact analysis (BIA) to identify and prioritize critical systems; 3) identifying preventive controls to reduce disruption effects; 4) creating thorough recovery strategies; 5) developing a detailed information system contingency plan; 6) ensuring the plan is tested, personnel are trained, and exercises are conducted to validate capabilities; and 7) maintaining the plan as a living document. The guide presents sample formats based on low-, moderate-, or high-impact levels as defined by FIPS 199.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "contingency-planning-guide-federal-systems",
    "title": "Contingency Planning Guide for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2010-05-01",
    "bluf": "NIST Special Publication 800-34, Rev. 1, provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to interim measures to recover information system services after a disruption, which may include relocation to an alternate site, recovery using alternate equipment, or performance of functions using manual methods. The guide defines a seven-step contingency planning process for organizations to develop and maintain a viable program: 1) Develop the contingency planning policy statement; 2) Conduct the business impact analysis (BIA) to identify and prioritize critical systems; 3) Identify preventive controls to reduce disruption effects; 4) Create thorough recovery strategies; 5) Develop a detailed information system contingency plan; 6) Ensure plan testing, training, and exercises to validate capabilities and improve preparedness; and 7) Ensure the plan is a living document, updated regularly.\n\nThis guidance is for federal agencies and may be used by non-governmental organizations on a voluntary basis. It addresses specific contingency planning recommendations for client/server systems, telecommunications systems, and mainframe systems. The guidance presents sample formats for developing a contingency plan based on low-, moderate-, or high-impact levels as defined by FIPS 199. The core obligation is to establish thorough plans, procedures, and technical measures that enable a system to be recovered as quickly and effectively as possible following a service disruption, integrating these steps into each stage of the system development life cycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "fips-199-security-categorization"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "coppa-marketing-kids",
    "title": "COPPA (Marketing to Kids)",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "This operator's online service is explicitly designated as a child-directed service, thereby triggering stringent obligations under the Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501-6506. While a neutral age gate is implemented for users under the established `user_age_threshold_years` of 13 and a clear privacy policy is posted, the operation exhibits a critical compliance failure. Specifically, the operator's process neglects to provide direct notice to parents and subsequently does not obtain verifiable parental consent before collecting personal information from children, a direct contravention of core requirements stipulated within 16 CFR § 312.4 and 16 CFR § 312.5. This fundamental gap persists despite the presence of otherwise robust protective measures, such as enforced data minimization, a block on behavioral advertising, and a prohibition against third-party data sharing, which generally align with confidentiality principles in 16 CFR § 312.8. Additionally, the system enables parental review with deletion capabilities and adheres to a `data_retention_limit_days` of 180, consistent with data retention standards of 16 CFR § 312.10. Nevertheless, without foundational parental consent, these secondary controls are insufficient to cure the primary violation regarding collection and use of children's information as defined by 16 CFR § 312.3. The operator is not certified under any FTC-approved COPPA Safe Harbor program, placing full compliance liability upon the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "can-spam-act-email",
      "eprivacy-cookie-directive",
      "ftc-endorsement-guides",
      "ccpa-cpra",
      "gdpr-art-21-marketing-optout"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "copuos-lts-guidelines-2019-space-sustainability",
    "title": "Guidelines for the Long-term Sustainability of Outer Space Activities of the Committee on the Peaceful Uses of Outer Space",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The COPUOS Guidelines for the Long-term Sustainability of Outer Space Activities provide 21 voluntary measures to ensure the safe and sustainable use of outer space, focusing on space debris mitigation (including post-mission disposal within 25 years), space weather monitoring, space situational awareness data sharing, and regulatory transparency. These apply to all States and international intergovernmental organizations conducting space activities, as adopted in A/74/20, Annex II.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14090-climate-adapt",
      "iso-15489-1-2016-records-management-workflow",
      "nist-ir-8374-ransomware-risk-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "copyright-fair-use-us",
    "title": "Fair Use (U.S. Copyright)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "A proposed use of copyrighted material under these parameters presents a compelling case for the fair use affirmative defense, as delineated within 17 U.S.C. § 107, thereby not requiring mandatory legal review. The first statutory factor, the purpose and character of the use, weighs strongly in favor of fair use because the application is fundamentally transformative, consistent with the standard established in Campbell v. Acuff-Rose Music, Inc. This is reinforced by its non-commercial purpose and its function as parody or criticism, which serves statutory category discourse. Regarding the second factor, the nature of the copyrighted work, the subject material is published and not highly creative, making it more amenable to fair use than unpublished works, a principle highlighted in Harper & Row, Publishers, Inc. v. Nation Enterprises. The third factor, concerning the amount and substantiality of the portion used, also supports this determination; the use is limited to a mere 10 percent of the source and critically does not appropriate the qualitative heart of the work. Finally, the fourth factor, analyzing the effect on the potential market, is decisively favorable. With a market harm severity score of zero, the new creation does not act as a market substitute, preventing the usurpation of the original's value, a core concern that underpins the exclusive rights granted by 17 U.S.C. § 106. The application of these principles, also seen in transformative use contexts like Google LLC v. Oracle America, Inc. and Authors Guild v. Google, Inc., indicates a low-risk profile.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-literary-artistic",
      "wipo-copyright-treaty",
      "dmca-safe-harbor",
      "ai-ip-copyright"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "coso-erm-framework-mining-risk",
    "title": "Enterprise Risk Management-Integrating with Strategy and Performance: Application to Mining Operations for Commodity Price, Geopolitical, and Environmental Risks",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This framework requires mining enterprises to integrate enterprise risk management (ERM) into strategic planning and performance monitoring, specifically addressing commodity price volatility, geopolitical instability, and environmental risks, as defined in the COSO ERM Framework's 'Strategy and Objective-Setting' and 'Performance' components. Applies to all mining operators with material exposure to global commodity, regulatory, or climate-related risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eiti-standard-2023",
      "eu-conflict-minerals-regulation-2017-821",
      "canada-impact-assessment-act-2019-mining",
      "australia-epbc-act-1999-mining-biodiversity",
      "drc-mining-code-law-18-001-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cospar-planetary-protection-policy-2021-mission-categories",
    "title": "COSPAR Planetary Protection Policy 2021 - Mission Category Bioburden Requirements",
    "domain": "Space & Satellite Law",
    "version": "2.0.1",
    "last_updated": "2026-06-14",
    "bluf": "COSPAR Planetary Protection Policy (2021 revision) classifies all solar system missions into five protection categories based on contamination risk. Categories I-II (flyby, orbiters of low-risk bodies) require documentation only. Category III-IV (Mars orbiters and landers respectively) impose bioburden limits of ≤300,000 spores/m² (surface) and ≤500,000 total spores per spacecraft before sterilisation, with Viking Bioassay as the reference method. Category V (Earth-return) missions require collection container verified probability of containing no viable organisms ≤10⁻⁶. Missions to Europa, Enceladus, and Mars Special Regions are subject to enhanced Category IV (restricted) requirements including dry-heat microbial reduction to ≤300 spores per spacecraft.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_framework",
        "regulatory_mapping",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "copuos-lts-guidelines-2019-space-sustainability",
      "un-outer-space-treaty-1967"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "costa-rica-ley-8968-2011-personal-data",
    "title": "Law 8968 of 2011 on the Protection of Personal Data in Automated Files and Databases - Prodhab (Agencia de Protección de Datos de los Habitantes)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Costa Rica's Law 8968/2011 establishes the legal framework for the protection of personal data processed in automated systems, requiring data controllers to register databases with Prodhab, obtain consent for sensitive data processing, implement security safeguards, and comply with constitutional habeas data rights. Key obligations are derived from the law’s core principles and enforcement mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-privacy",
      "aicpa-soc2-cc-confidentiality",
      "aicpa-soc2-cc-availability",
      "aicpa-soc2-cc-processing-integrity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cotif-cim-1999-rail-carriage-goods",
    "title": "COTIF/CIM 1999 - Uniform Rules for International Rail Carriage of Goods (Appendix B)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Uniform Rules concerning the Contract for International Carriage of Goods by Rail (CIM) are Appendix B to the Convention concerning International Carriage by Rail (COTIF 1980) as amended by the Protocol of Vilnius 1999, administered by OTIF (Organisation for International Carriage by Rail). CIM entered into force 1 July 2006 and applies across 50 OTIF Member States spanning Europe, the Middle East, and North Africa. CIM governs the legal framework for all international rail freight consignments moving under a single CIM Consignment Note (CRN): Art 4 defines scope; Art 6 makes the CRN prima facie evidence of the contract; Arts 10-11 regulate acceptance and loading obligations; Arts 23-25 establish carrier liability for loss, damage, and delay; Art 23(1) imposes strict carrier liability from acceptance to delivery; Art 30(2) caps compensation at SDR 17 per kilogram of gross mass for total or partial loss; delay liability is capped at the amount of carriage charges (Art 33). Art 47 sets a 1-year limitation period (3 years for wilful misconduct or equivalent). Appendix C to COTIF (RID) governs dangerous goods by rail and is mandatory for CIM consignments containing RID-regulated substances. CIM is fully interoperable with CMR road carriage and SMGS (the equivalent rail freight agreement for CIS/Asian rail routes).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "cmr-convention-1956-road-carriage-goods",
      "adr-agreement-1957-dangerous-goods-road",
      "hague-visby-rules-1968"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "council-of-europe-ai-treaty-2024",
    "title": "Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-05-17",
    "bluf": "This treaty establishes a legal framework for Parties (ratifying countries) to regulate AI activities, ensuring they are consistent with human rights, democracy, and the rule of law. It requires Parties to implement measures for transparency, oversight, accountability, and risk management for AI systems used by both public authorities and private actors, as outlined in Articles 4, 5, and 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "unesco-ethics-ai",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "un-guiding-principles-business-hr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "council-of-europe-ai-treaty-2024-cets-225",
    "title": "Council of Europe Framework Convention on AI and Human Rights (CETS No. 225) 2024 - Obligations on Lifecycle, Transparency and Redress",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This convention requires signatory Parties to establish legal frameworks ensuring that AI systems are designed, developed, and used in a manner consistent with human rights, democracy, and the rule of law throughout their entire lifecycle. Key obligations under Chapters III and IV mandate transparency, human oversight, accountability, and the availability of effective remedies for individuals harmed by AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "council-of-europe-ai-treaty-2024",
      "oecd-ai-principles",
      "unesco-ethics-ai",
      "eu-ai-act-fundamental-rights-impact-assessment"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cpmi-iosco-cyber-resilience-fmi",
    "title": "Guidance on cyber resilience for financial market infrastructures",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2016-06-01",
    "bluf": "The purpose of this document is to provide guidance for Financial Market Infrastructures (FMIs) to enhance their cyber resilience. It provides supplemental guidance to the CPMI-IOSCO Principles for Financial Market Infrastructures (PFMI), primarily in the context of governance, risk management, settlement finality, operational risk, and FMI links. This guidance details preparations and measures that FMIs should undertake to enhance their cyber resilience capabilities, with the objective of limiting the escalating risks that cyber threats pose to financial stability. The guidance is directly aimed at FMIs, which are defined as systemically important payment systems, central securities depositories (CSDs), securities settlement systems (SSSs), central counterparties (CCPs), and trade repositories (TRs).\n\nThe guidance is structured around five primary risk management categories: governance, identification, protection, detection, and response and recovery, along with three overarching components: testing, situational awareness, and learning and evolving. A core expectation is that an FMI should design and test its systems and processes to enable the safe resumption of critical operations within two hours of a disruption and to enable itself to complete settlement by the end of the day of the disruption, even in the case of extreme but plausible scenarios. FMIs are expected to use a risk-based approach and develop concrete plans to meet these objectives within 12 months of the guidance's publication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "principles-financial-market-infrastructures"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cptpp-chapter-14-electronic-commerce-2018",
    "title": "Comprehensive and Progressive Agreement for Trans-Pacific Partnership, Chapter 14 - Electronic Commerce",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "Prohibits CPTPP member states from requiring data localization for cross-border electronic transactions and mandates recognition of electronic signatures and authentication methods in trade-related digital activities. Applies to customs, logistics, and supply chain operators engaged in digital trade under Article 14.13 and Article 14.8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-electronic-commerce-1996",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "cr-aml-law-7786",
    "title": "Costa Rica Law No. 7786 on Narcotics, Money Laundering and Terrorist Financing",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "Costa Rica's Law No. 7786 (as amended) lists the obliged subjects supervised by SUGEF, SUGEVAL, SUPEN and SUGESE (Articles 14 and 15) and other designated non-financial businesses (Article 15 bis), requires customer identification and know-your-customer measures with nominative accounts (Article 16), registration of transactions over ten thousand US dollars (Articles 20 and 21), retention of records for five years (Article 22), and confidential and immediate reporting of suspicious transactions to the Financial Intelligence Unit (Article 25).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cr-ley-general-contratacion-publica-9986-2021-effective-2022",
    "title": "Costa Rica Ley General de Contratacion Publica No. 9986 of 27 May 2021 effective 1 December 2022 and SICOP",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Costa Rican Ley General de Contratacion Publica No. 9986 (General Law of Public Procurement) approved 27 May 2021 (La Gaceta No. 103 of 31 May 2021) and effective 1 December 2022 is the principal Costa Rican statute governing procurement of goods, services, and works by entities of the Public Administration including the Executive Branch (Poder Ejecutivo), the Legislative Branch (Poder Legislativo), the Judicial Branch (Poder Judicial), the Supreme Election Tribunal (Tribunal Supremo de Elecciones), Decentralized Institutions (Instituciones Descentralizadas), public-sector enterprises, Municipalities, public-sector universities, autonomous bodies, and other entities of the public sector financed by the National Treasury. Ley 9986/2021 replaced the prior Ley de Contratacion Administrativa No. 7494 of 1995 and substantially modernised the Costa Rican procurement regime introducing (a) unified procurement framework across all branches of government, (b) mandatory use of the Sistema Integrado de Compras Publicas (SICOP / sicop.go.cr), (c) strengthened anti-corruption and integrity provisions including beneficial ownership disclosure and supplier debarment, (d) sustainability and innovation criteria, (e) framework agreements (Convenio Marco) and dynamic purchasing systems, and (f) strengthened complaint resolution through the Contraloria General de la Republica. The Reglamento a la Ley General de Contratacion Publica issued by Decreto Ejecutivo 43808-H of 22 November 2022 prescribes detailed procedural requirements. The Ministry of Finance Direccion General de Administracion de Bienes y Contratacion Administrativa (DGABCA) is the central procurement policy authority. SICOP operated by Radiografica Costarricense S.A. (RACSA) is the mandatory federal e-procurement platform. Procurement methods established by Ley 9986/2021 art. 24 to 37 comprise (a) Licitacion Mayor (Major Tender, the default open public procedure for prescribed-value acquisitions), (b) Licitacion Menor (Minor Tender, for medium-value acquisitions), (c) Contratacion Menor (Minor Procurement, for small-value acquisitions below prescribed thresholds), (d) Subasta a la Baja (Reverse Auction, for standardised products), (e) Procedimientos Especiales (Special Procedures including emergency, sole-source under prescribed exceptions, urgent need, sole supplier for technical reasons, prior failed tendering), and (f) Convenio Marco (Framework Agreement) and Sistema Dinamico de Adquisiciones (Dynamic Purchasing System). The Contraloria General de la Republica conducts procurement audit and acts as the procurement appeals authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "cr-pdp-law-2011",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "cr-pdp-law-2011",
    "title": "Costa Rica Personal Data Protection Law No. 8968 2011 - PRODHAB",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Costa Rica's Ley de Protección de la Persona frente al Tratamiento de sus Datos Personales (Personal Data Protection Law) - Law No. 8968 of 5 July 2011, published in La Gaceta (official gazette) No. 170 on 5 September 2011 and entered into force on 5 March 2012 - is Costa Rica's primary personal data protection legislation. The implementing regulation, Executive Decree No. 37554-JP of 30 October 2012, provides detailed rules for compliance. Law No. 9736 of 14 July 2020 amended Law No. 8968 to introduce mandatory breach notification obligations. The supervisory authority is the Agencia de Protección de Datos de los Habitantes (PRODHAB - Agency for the Protection of Residents' Data), an independent public body operating under the Ministry of Justice and Peace of Costa Rica. PRODHAB registers personal data databases, investigates complaints, and enforces Law No. 8968. Key features of Costa Rica's Law No. 8968: (1) Scope - applies to any individual or legal entity that collects, stores, transfers, or uses personal data of natural persons (habitantes) in Costa Rica; (2) Data processing principles - the law requires compliance with: purpose limitation; proportionality; informed consent; quality (accuracy); security; confidentiality; and transparency; (3) Sensitive personal data - the law establishes heightened protection for data revealing: racial or ethnic origin; political opinions; religious convictions; trade union membership; health status; sex life; (4) ARCO rights - data subjects (habitantes) have the rights of Acceso (access), Rectificación (rectification), Cancelación (cancellation/deletion), and Oposición (opposition); (5) Consent - processing personal data generally requires the data subject's free, informed, specific, and express consent; specific exceptions apply (legal obligation, contract necessity, vital interests, public interest); (6) Database registration - any individual or legal entity maintaining a personal data database must register it with PRODHAB through the Registro Nacional de Bases de Datos (National Database Registry) before processing commences; (7) Breach notification - Law No. 9736 of 2020 introduced mandatory notification to PRODHAB when a security breach occurs that may harm the fundamental rights of data subjects; notification must be made within five business days of discovering the breach; data subjects must also be notified; (8) Cross-border transfers - personal data may only be transferred to countries or organisations providing equivalent or superior protection; transfers to non-adequate countries require PRODHAB authorisation; (9) Administrative sanctions - PRODHAB may impose fines ranging from one to seventy-five base wages (salarios base, the Costa Rican judicial base salary unit) for violations of Law No. 8968; (10) Criminal penalties - violations of data protection rights may give rise to criminal liability under applicable criminal law provisions. Costa Rica occupies a significant position in Central American data governance as the most advanced economy in the region, with a growing technology sector, significant medical devices and pharmaceutical manufacturing, and an established free trade zone economy that processes large volumes of personal data of regional and international data subjects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "crirsco-international-reporting-template-2019",
    "title": "CRIRSCO International Reporting Template - Mineral Resource and Reserve Reporting",
    "domain": "Mining & Natural Resources",
    "version": "2019",
    "last_updated": "2026-05-09",
    "bluf": "The CRIRSCO International Reporting Template (2019) is the harmonised global standard for public reporting of Mineral Exploration Results, Mineral Resources, and Mineral Reserves, maintained by the Committee for Mineral Reserves International Reporting Standards; it aligns 12 national reporting codes (including JORC, SAMREC, NI 43-101, PERC, SME Guide) under shared definitions of the three Resource categories (Inferred, Indicated, Measured) and two Reserve categories (Probable, Proved), the Competent Person/Qualified Person requirement, and 10 fundamental principles including the 2019-added Transparency principle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "jorc-code-2012-australasian-mineral-resources-reporting",
      "canada-national-instrument-43-101"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "crpd-un-convention-rights-persons-disabilities-2006",
    "title": "UN CRPD 2006 - Convention on the Rights of Persons with Disabilities",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Convention on the Rights of Persons with Disabilities (CRPD), adopted by the UN General Assembly on 13 December 2006 (Resolution A/RES/61/106) and entering into force on 3 May 2008, has 185 Parties including the European Union (ratified 2011). The CRPD is the first comprehensive human rights treaty of the 21st century and fundamentally reframes disability from a medical model (deficit requiring treatment) to a social/human rights model: disability is the interaction between impairment and attitudinal and environmental barriers that hinder full and effective participation in society. The Convention establishes binding obligations across all domains of life including: equal recognition before the law (Article 12), access to justice (Article 13), living independently and being included in the community (Article 19), freedom of movement (Article 18), work and employment (Article 27 - comprehensive non-discrimination and reasonable accommodation obligations for employers), education (Article 24 - inclusive education at all levels), health (Article 25), habilitation and rehabilitation (Article 26), participation in political and public life (Article 29), and cultural life, recreation, leisure and sport (Article 30). Article 27 imposes obligations on States Parties and, through national implementing law, on private employers: prohibition on disability-based discrimination in recruitment, hiring, promotion, training, pay, and dismissal; obligation to provide 'reasonable accommodation' - the concept requires modifications and adjustments that do not impose a 'disproportionate or undue burden' on the employer; promotion of inclusive work environments; accessible workplaces. Article 9 on accessibility requires physical, communication, and information accessibility - affecting building design, ICT, and public services. The CRPD is monitored by the Committee on the Rights of Persons with Disabilities (18 independent experts); the Optional Protocol enables individual communications. Article 4.2 recognises that economic, social, and cultural rights are subject to progressive realisation. The EU implements CRPD through the European Accessibility Act (Directive 2019/882), the Strategy for the Rights of Persons with Disabilities 2021-2030, and national anti-discrimination laws.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "eu-employment-equality-directive-2000-78",
      "eu-accessibility-act-2019-882-digital-products",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "crr-iii-eu-implementation-2024",
    "title": "Regulation (EU) 2024/1623 of the European Parliament and of the Council of 14 May 2024 amending Regulation (EU) No 575/2013 as regards requirements for credit risk, credit valuation adjustment risk, operational risk, market risk and the output floor",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2025-01-01",
    "bluf": "This regulation implements the final Basel III reforms (often called 'Basel IV') in the European Union, establishing a harmonised 'output floor' to limit the reduction in capital requirements for banks using internal models, as detailed in Article 462a. It also introduces more risk-sensitive standardised approaches for credit risk and a new framework for operational risk, applying to all EU credit institutions and investment firms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "fundamental-review-of-the-trading-book",
      "ecb-guide-internal-models",
      "bcbs-principles-sound-management-operational-risk",
      "bcbs-climate-related-financial-risks"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "crs-oecd-tax-automatic",
    "title": "OECD CRS (Tax Exchange)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Common Reporting Standard (CRS) is the global benchmark for the automatic exchange of financial account information (AEOI) to combat tax evasion. Developed by the OECD, it requires financial institutions in participating jurisdictions to identify and report the account holders who are tax resident in other jurisdictions, ensuring the transparent flow of the tax data across the borders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatca-iga-compliance"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "crypto-aml-travel-rule",
    "title": "Crypto AML Travel Rule",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The FATF Travel Rule (Recommendation 16), as applied to Virtual Asset Service Providers (VASPs) through FATF Guidance on Virtual Assets (2019, updated 2021), requires that originating VASPs transmit specific identifying information about the sender and beneficiary alongside every virtual asset transfer above the applicable threshold (USD/EUR 1,000 for cross-VASP transfers; USD 3,000 for some jurisdictions). This information - analogous to the wire transfer travel rule in traditional finance - must be transmitted to the beneficiary VASP before or simultaneously with the transaction and must be securely stored. FATF member jurisdictions have implemented the Travel Rule through national legislation (EU: TFR/MiCA; US: FinCEN proposed rules; Singapore: MAS PSA; UK: FCA). VASPs failing to implement Travel Rule compliance face regulatory sanctions, license revocation, and banking relationship termination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "fatf-guidance-virtual-assets-vasp",
      "fatf-virtual-asset-redfl",
      "fincen-cvc-business-models",
      "mica-stablecoin-reserve"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "csa-ccm-v4-cloud-controls",
    "title": "CSA Cloud Controls Matrix (CCM) v4.0",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing, providing a comprehensive set of 197 security controls across 17 domains. It is designed for both cloud service providers and consumers to assess the overall security risk of a cloud environment, as detailed in its Governance, Risk Management and Compliance (GRC) domain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-145-cloud-computing",
      "iso-27017-cloud-controls",
      "soc2-availability-criteria",
      "fedramp-moderate-baseline"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "csa-star-attestation-soc2-ccm",
    "title": "CSA STAR Attestation - SOC 2 Examination Incorporating the Cloud Controls Matrix",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "CSA STAR Attestation is a Level 2 (third-party) assessment developed by the Cloud Security Alliance with the AICPA. It is a SOC 2 examination that incorporates the criteria of the CSA Cloud Controls Matrix (CCM) in addition to the trust services criteria, producing a report tailored to cloud service providers. It is distinct from CSA STAR Certification, which is based on ISO/IEC 27001. STAR Attestation lets a cloud provider demonstrate, through an independent CPA engagement, that its controls meet both the trust services criteria and cloud-specific CCM control objectives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "csa-star-certification-level-2-iso-27001"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "csa-star-certification-level-2-iso-27001",
    "title": "CSA STAR Certification Level 2 - Cloud Controls Matrix + ISO/IEC 27001: Third-Party Audit Combining CCM v4 Assessment with ISO 27001 Certification, STAR Registry Publication, Annual Surveillance Audits and Cloud-Specific Control Augmentation",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "CSA STAR Certification Level 2 requires cloud service providers to undergo a third-party audit that combines ISO/IEC 27001 certification with the CSA Cloud Controls Matrix (CCM) to validate cloud-specific security controls. This applies to organizations operating in medium to high-risk environments already adhering to ISO/IEC 27001, as defined in the STAR Level 2: Third-Party Audit section.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "cobit-2019-governance-framework",
      "eu-gdpr-cloud-data-processing",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "csrd-directive-article-1-amendments-to-accounting-directive",
    "title": "Directive (EU) 2022/2464 (CSRD) Article 1: Amendments to Directive 2013/34/EU",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article extends the application of specific coordination and reporting measures under Directive 2013/34/EU to large undertakings and certain small and medium-sized public-interest entities, regardless of their legal form.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-sfdr-regulation-2019-2088-sustainable-finance-disclosure",
      "iso-14001-environmental-management-construction"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "csrd-directive-article-10-digital-tagging-xbrl-requirements",
    "title": "DIRECTIVE (EU) 2022/2464 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 December 2022 amending Regulation (EU) No 537/2014, Directive 2004/109/EC, Directive 2006/43/EC and Directive 2013/34/EU, as regards corporate sustainability reporting",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This directive aims to transform the Union into a modern, resource-efficient, and competitive economy by reviewing and enhancing corporate sustainability reporting to support the European Green Deal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852",
      "eu-sfdr-regulation-2019-2088-sustainable-finance-disclosure"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "csrd-directive-article-11-third-country-parent-reporting",
    "title": "Directive (EU) 2022/2464 on corporate sustainability reporting - Article 11 (inserting Article 40a into Directive 2013/34/EU)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Requires large or listed EU subsidiaries or branches of a third-country parent undertaking to publish a consolidated sustainability report for the entire group, prepared in accordance with specific standards, and make it publicly accessible.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "csrd-directive-article-19-penalties-for-non-compliance",
    "title": "Directive (EU) 2022/2464 of the European Parliament and of the Council of 14 December 2022 as regards corporate sustainability reporting - Article 19 Penalties",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires Member States to establish rules on effective, proportionate, and dissuasive penalties for infringements of the national provisions adopted pursuant to the Corporate Sustainability Reporting Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "csrd-directive-article-2-scope-of-sustainability-reporting",
    "title": "Corporate Sustainability Reporting Directive (CSRD) Article 2: Definition of Net Turnover",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article establishes the specific definitions of 'net turnover' for different types of undertakings, including general companies, insurance undertakings, credit institutions, and those under specific financial reporting frameworks, which is critical for determining reporting obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "csrd-directive-article-21-transposition-timeline",
    "title": "DIRECTIVE (EU) 2022/2464 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 December 2022 as regards corporate sustainability reporting - Article 21",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the deadlines and requirements for Member States to adopt and publish the laws, regulations, and administrative provisions necessary to comply with this Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "csrd-directive-article-3-sustainability-reporting-standards",
    "title": "Directive (EU) 2022/2464 Article 3: Amendments to Directive 2006/43/EC regarding assurance of sustainability reporting",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article mandates that corporate sustainability reporting must undergo an assurance engagement by a statutory auditor or an accredited independent provider, following specific EU-adopted assurance standards, and resulting in a formal assurance report.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "csrd-directive-article-4-value-chain-reporting-due-diligence",
    "title": "DIRECTIVE (EU) 2022/2464 on corporate sustainability reporting - Value Chain and Due Diligence Obligations",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This directive requires undertakings to conduct and report on the due diligence process for sustainability matters across their operations and value chain, including the principal impacts, risks, opportunities, and mitigation actions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "csrd-directive-article-5-eu-taxonomy-reporting-obligations",
    "title": "Directive (EU) 2022/2464 of the European Parliament and of the Council of 14 December 2022 as regards corporate sustainability reporting - Article 5: EU Taxonomy Reporting Obligations",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article requires undertakings to disclose information on how and to what extent their activities are associated with economic activities that qualify as environmentally sustainable under the EU Taxonomy Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "csrd-directive-article-6-sme-sustainability-reporting",
    "title": "Directive (EU) 2022/2464 of the European Parliament and of the Council of 14 December 2022 amending Regulation (EU) No 537/2014, Directive 2004/109/EC, Directive 2006/43/EC and Directive 2013/34/EU, as regards corporate sustainability reporting - Article 6: Transitional provisions",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes specific transitional provisions, allowing certain undertakings temporary exemptions or options to omit specific information from their individual or consolidated sustainability reports for a limited period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "csrd-directive-article-7-consolidated-sustainability-reporting",
    "title": "Directive (EU) 2022/2464 Article 7: Consolidated sustainability reporting",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that parent undertakings must prepare a consolidated sustainability report covering the parent and all its subsidiaries, ensuring consistent and comprehensive disclosure of sustainability information across the entire group.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "csrd-directive-article-8-combined-management-report",
    "title": "Directive (EU) 2022/2464 - Article 19a: Sustainability reporting",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must include in their management report detailed information on their sustainability impacts, risks, and strategies, covering business models, targets, governance, policies, due diligence, and performance indicators, all in accordance with EU sustainability reporting standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "csrd-directive-article-9-limited-assurance-requirements",
    "title": "Directive (EU) 2022/2464 as regards corporate sustainability reporting - Article 9: Limited Assurance Requirements",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that a statutory auditor or audit firm must express an opinion based on a limited assurance engagement regarding the compliance of an undertaking's sustainability reporting with Union standards and requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "csrd-eu-sustainability",
    "title": "CSRD / ESRS (EU Sustainability)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Corporate Sustainability Reporting Directive (CSRD) is the landmark EU regulation mandating detailed sustainability disclosure for large and listed companies. It introduces the European Sustainability Reporting Standards (ESRS), requiring 'Double Materiality'-reporting on both financial and environmental/social impact.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-sustainable",
      "gri-universal-standards",
      "issb-s1-s2-standard",
      "tcfd-climate-risk",
      "un-guiding-principles-business-hr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cu-framework",
    "title": "Cuba - Constitutional Privacy Rights and Ministry of Communications Data Governance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Republic of Cuba is an independent socialist state in the Caribbean governed under the Constitution of Cuba (2019), which establishes fundamental rights including the inviolability of the home and correspondence, the right to personal privacy, and protections for personal communications and data. The Ministry of Communications (Ministerio de Comunicaciones - MINCOM) is the principal regulatory authority for telecommunications and digital services in Cuba. Empresa de Telecomunicaciones de Cuba (ETECSA) is the state-owned telecommunications monopoly. Cuba does not have a standalone comprehensive personal data protection law equivalent to the GDPR. The applicable framework for personal data governance consists of constitutional privacy rights, Decree-Law 370 of 2018 on the Informatization of Society (which regulates digital services and internet use), and related implementing regulations. Decree-Law 370 grants broad regulatory powers to MINCOM and has been subject to international criticism for restricting digital freedoms. Cuba's internet access is limited and subject to government control, and organisations operating digital services in Cuba must comply with MINCOM regulatory requirements, obtain applicable telecommunications licences, and respect constitutional privacy rights. Cuba is an observer state of the CARICOM regional framework but is not a full CARICOM member. Organisations processing personal data in Cuba must navigate significant regulatory complexity given Cuba's unique economic and political environment, including US embargo-related restrictions on technology exports and financial transactions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/cu-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "curacao-gaming-control-board-ordinance-2023",
    "title": "Curacao National Ordinance on Games of Chance (LOK / Landsverordening op de kansspelen) - Direct Licensing Regime, Operator Obligations and AML Requirements",
    "domain": "Gaming & Gambling",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "The National Ordinance on Games of Chance (Landsverordening op de kansspelen, LOK) was approved by the Curacao Parliament on 17 December 2024 and entered into force on 24 December 2024, replacing the old National Ordinance on Offshore Games of Hazard (NOOGH) master/sub-license regime. Under the LOK a single government regulator, the Curacao Gaming Authority (CGA), is the sole issuer of and supervisor over online gaming licences; it is prohibited to offer online gaming in or from Curacao without a CGA licence, and that prohibition extends to entities controlling player databases or player transactions. Operators must meet AML/CFT, economic-substance and compliance requirements. NOOGH-era licences remained valid until 24 June 2025 with a possible 6-month extension. There is no 'Curacao Gaming Control Board National Ordinance 2023'; this node is anchored to the LOK as enacted.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l3",
      "eu-dora-articles-28-44-third-party-ict-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "customs-tapa-transport-sec",
    "title": "TAPA Transport Security Requirements",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with Transported Asset Protection Association (TAPA) Trucking Security Requirements (TSR) at Level 1 is mandatory for all in-scope transport operations, demanding a multi-layered security posture as defined by established protocols. This stringent certification requires that all conveyances be equipped with active GPS tracking systems reporting at an interval not to exceed 15 minutes, a covert panic alarm for driver safety, and an independent alarm for the cargo area. To maintain shipment integrity and provide an auditable chain of custody, operations must use high-security seals compliant with the ISO 17712 standard. Personnel vetting is also critical, mandating that every driver has a currently valid background check and has completed up-to-date security training. Operationally, all transport routes demand pre-planning and formal approval before departure, supported by a comprehensive secure parking plan for any stops. Consistent oversight is enforced through mandatory communication checks between the driver and control center at a maximum interval of 4 hours. Concurrently, a thoroughly documented incident response plan must be in place, providing clear, actionable procedures to mitigate security breaches, theft, or other emergencies and ensure a coordinated, effective reaction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "tapa-tsr-2023",
      "iso-28000-supply-chain",
      "c-tpat-minimum-security",
      "fleet-telematic-audit",
      "smart-container-iot"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cv-pdp-law-2001",
    "title": "Cape Verde Personal Data Protection Law - CNPD Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Cape Verde Law No. 133/V/2001 on Protection of Personal Data establishes a Portuguese-influenced framework of consent-based processing, data subject rights, and mandatory controller registration. The Comissão Nacional de Proteção de Dados (CNPD) is the designated supervisory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cve-program-cna-record-format-5",
    "title": "CVE Program with CNA Hierarchy and Record Format 5.2.0 (CISA-Sponsored, MITRE Secretariat, 400+ CVE Numbering Authorities, JSON Schema, ADPs, CVE Services REST API)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "The Common Vulnerabilities and Exposures (CVE) Program is the canonical international vulnerability identifier system sponsored by the United States Cybersecurity and Infrastructure Security Agency (CISA) with The MITRE Corporation serving as the program Secretariat. Each CVE record is identified by a CVE ID in the format CVE-YYYY-NNNNN (year plus arbitrary-length sequence number) and represents a single publicly disclosed vulnerability. The program is governed by the CVE Board with operational governance through Working Groups including the CVE Quality Working Group (QWG). The CVE Record Format JSON Schema is maintained at github.com/CVEProject/cve-schema; the current production release is version 5.2.0 dated 29 October 2025 on the main branch. CVE Records use a cveMetadata block (cveId, assignerOrgId, state PUBLISHED or REJECTED or RESERVED, datePublished, dateUpdated) and one or more container blocks: the cna container submitted by the assigning CNA (containing affected product list with vendor/product/versions and version status affected/unaffected/unknown, descriptions in multiple languages, references with tags, problemTypes referencing CWE entries, metrics with CVSS v2/v3.0/v3.1/v4.0 scores) and optional adp containers from Authorized Data Publishers (CISA-ADP being the canonical ADP enriching records with CISA KEV and SSVC data). CVE Numbering Authorities are organisations authorised to assign CVE IDs and publish records: there are over 400 CNAs globally including Root CNAs (MITRE for the main pool), Top-Level Root CNAs (CISA-CERT/CC and JPCERT/CC), regional Root CNAs, vendor CNAs (Microsoft, Apple, Google, Cisco, Oracle, Red Hat, etc.), open-source project CNAs (GitHub, Linux Kernel, npm), bug-bounty CNAs (HackerOne, Bugcrowd), and CNA-LR (Last Resort) operated by MITRE for vulnerabilities outside other CNA scopes. The CVE Services REST API at cveawg.mitre.org handles ID reservation, record submission, and lookup; the canonical public view is cve.org and the legacy MITRE CVE List archive remains accessible at cve.mitre.org.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "program_basis",
        "key_institutions",
        "cve_record_format_5_x",
        "cna_container_fields",
        "adp_container_and_cisa_adp",
        "cna_hierarchy_roles",
        "cve_services_rest_api",
        "cve_to_cwe_problemtypes_mapping",
        "cve_to_nvd_enrichment_pipeline",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cisa-kev-catalog",
      "us-cisa-known-exploited-vulnerabilities-bod-22-01",
      "mitre-cwe-top-25-2024-most-dangerous-weaknesses",
      "oasis-stix-2-1-structured-threat-information"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "cw-lbp-2010",
    "title": "Curaçao National Ordinance on Personal Data Protection 2010",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Curaçao, a constituent country of the Kingdom of the Netherlands, enacted the National Ordinance on Personal Data Protection (Landsverordening bescherming persoonsgegevens, LBP) upon achieving autonomous status in 2010 following the dissolution of the Netherlands Antilles. The Ordinance is aligned with Kingdom of the Netherlands data protection standards and is administered by a designated supervisory authority in Curaçao. It establishes data protection principles for the lawful processing of personal data, grants data subjects rights of access, correction, and objection, requires notification of processing activities, mandates security safeguards, and restricts cross-border transfers to countries with adequate protection. Curaçao's framework mirrors the pre-GDPR Dutch data protection model applicable to Kingdom constituent countries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/cw-lbp-2010.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cx-privacy-framework",
    "title": "Christmas Island - Australian Privacy Act and OAIC Supervisory Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Christmas Island is an Australian external territory located in the Indian Ocean south of the Indonesian island of Java. The island is administered by the Australian Government through the Department of Infrastructure, Transport, Regional Development, Communications and the Arts. Christmas Island has a resident population of approximately 2,000 people, comprising primarily Chinese, Malay, and Australian communities. The Australian Privacy Act 1988 (Cth) applies in Christmas Island as an Australian external territory, and the Australian Privacy Principles (APPs) govern the handling of personal data by Australian Government agencies and private sector organisations with annual turnover exceeding AU$3 million operating in or from Christmas Island. The Office of the Australian Information Commissioner (OAIC) is the competent supervisory authority for privacy matters in Christmas Island. Christmas Island operates an immigration detention and processing facility, which creates heightened privacy obligations for organisations handling personal data of detainees and immigration applicants. Organisations processing personal data in Christmas Island must comply with the Australian Privacy Act 1988, the Australian Privacy Principles, and any applicable Commonwealth legislation. The Christmas Island Act 1958 provides the legislative basis for the territory's status as an Australian territory. Specific regulatory requirements applicable to immigration detention operations are subject to additional obligations under Commonwealth legislation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/cx-privacy-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cy-pdp-law-125-2018",
    "title": "Cyprus Processing of Personal Data Law No. 125(I)/2018 - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Cyprus's The Processing of Personal Data (Protection of Individuals) Law No. 125(I)/2018 (Ο περί Επεξεργασίας Δεδομένων Προσωπικού Χαρακτήρα (Προστασία του Ατόμου) Νόμος του 2018, Law No. 125(I)/2018), published in the Official Gazette of the Republic of Cyprus and in force from 31 July 2018, is Cyprus's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Cyprus. The GDPR is directly applicable Cypriot law by virtue of Cyprus's EU membership. Law No. 125(I)/2018 provides national derogations, additions, and specifications that the GDPR permits EU member states to adopt, replacing the prior Processing of Personal Data (Protection of Individuals) Law No. 138(I)/2001. Cyprus is an Eastern Mediterranean EU member state with particular strategic importance as a financial services and shipping hub; many international companies maintain registered offices and regional headquarters in Cyprus, making GDPR and Law No. 125(I)/2018 compliance significant for international operations. Cyprus's common law legal system (inherited from British administration) means Cypriot data protection law operates within a framework more familiar to common law practitioners than most other EU member states. Enforcement: the Commissioner for Personal Data Protection (CPDP, Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) is Cyprus's independent data protection supervisory authority. The CPDP is Cyprus's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Cypriot national provisions: (1) Age of digital consent: Cyprus has maintained the GDPR default of 16 years for information society services; data subjects under 16 require parental or guardian consent; (2) Employment - Cypriot employment law (including the Termination of Employment Law, Chapter 217 and the Equal Treatment in Employment Regulation) governs employment relationships; employee monitoring requires advance notification; (3) Freedom of expression - exemptions for journalistic, literary, and artistic processing aligned with GDPR Art. 85; (4) Health data - specific provisions for health data processing under Cypriot health legislation supplementing GDPR Art. 9; (5) Criminal data - Law No. 125(I)/2018 restricts private entity processing of criminal conviction data; (6) Financial services - the Cyprus Securities and Exchange Commission (CySEC) supervises financial services entities; CySEC regulations interact with GDPR compliance for Cypriot-licensed financial firms. Fines: GDPR administrative fines apply in Cyprus - up to EUR 20 million or 4% of global annual turnover. The CPDP has imposed administrative fines and issued enforcement guidance in employment, financial services, and public sector contexts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cyber-essentials-plus-uk",
    "title": "Cyber Essentials Plus (UK)",
    "domain": "Cloud & SaaS",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Cyber Essentials Plus (UK) certification establishes a high-assurance cybersecurity posture, validated through a mandatory independent technical audit as specified in the NCSC Cyber Essentials Plus: Illustrative Test Specification v3.1. This framework, frequently a prerequisite for UK government contracts under Procurement Policy Note 09/14, demonstrates technical controls that align with the security of processing obligations found in the UK Data Protection Act 2018. Compliance mandates stringent operational discipline across all in-scope devices, where the device compliance scope includes bring-your-own-device assets accessing organizational data. Critical security updates must be applied within a strict 14-day maximum patch application window, and the operation of unsupported software is strictly prohibited. The technical audit verifies that internet-facing services do not possess vulnerabilities exceeding a maximum CVSS score of 6.9. Access controls are rigorously enforced; multifactor authentication is mandatory for all cloud services, all default passwords must be changed from vendor settings, and user passwords require a minimum length of 8 characters. Furthermore, the daily use of administrative accounts for standard activities is disallowed. Protective measures, guided by NCSC's Requirements for IT Infrastructure v3.1 and IASME Consortium rules, necessitate that malware protection signatures are updated within a 24-hour frequency, and certification requires successful completion of both an external vulnerability scan and an internal vulnerability scan.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-800-53-sc7",
      "pci-dss-v4-requirement-5",
      "pci-dss-v4-requirement-6",
      "pci-dss-v4-requirement-7"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "cyber-mitre-t1082",
    "title": "System Information Discovery (MITRE ATT&CK T1082)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Adversaries attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-128-config-management",
      "cis-controls-v8",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "nist-sp-800-92-log-management",
      "nist-sp-800-40r4-enterprise-patch-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "cyber-nist-800-53-ac2",
    "title": "Account Management (NIST SP 800-53 AC-2)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Account Management control establishes a comprehensive framework, consistent with NIST Special Publication 800-53 AC-2, for managing the full lifecycle of information system accounts. This governance is essential for satisfying the identity management and access rights principles of ISO/IEC 27001, supporting the security of processing measures under GDPR Article 32, and meeting the logical access security criteria specified by SOC 2 CC6.3 and PCI DSS Requirement 8.1. System configuration mandates that all account provisioning actions must `require_manager_approval` and strictly `enforce_least_privilege`. To maintain operational integrity, the platform will `audit_account_creation_and_modification` activities, `alert_on_privileged_role_assignment`, and `enforce_separation_of_duties`. Access rights undergo a `periodic_review_interval_days` of every 90 days, while dormant accounts are subject to `auto_disable_inactive_days` after 35 days of inactivity. Temporary accounts are constrained by a `max_temporary_account_validity_hours` of 72 hours. Deprovisioning procedures are executed swiftly, with a mandate to `terminate_access_on_departure_hours` within 24 hours of notification and to `auto_remove_orphaned_accounts` systematically. Security is hardened by limiting `max_failed_login_attempts` to 3 and ensuring administrative functions `require_mfa_for_account_management`, thereby creating a robust, auditable system for managing identities and permissions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-53-r5",
      "nist-sp-800-63b-authentication",
      "nist-800-53-ia2",
      "cis-controls-v8"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cyber-nist-csf-2",
    "title": "Asset Management Strategy (NIST CSF 2.0 ID.AM)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Effective governance over the enterprise environment necessitates a comprehensive asset management strategy grounded in the NIST Cybersecurity Framework 2.0 Identify function. This approach mandates the maintenance of detailed hardware and software inventories, achieving a minimum coverage threshold of 95 percent for each category, consistent with CIS Controls v8. To ensure inventory integrity, asset discovery scans must execute at a maximum frequency of every 24 hours, and automated CMDB synchronization is required. Security posture is reinforced by enabling unauthorized asset alerting, with a strict mandate to quarantine any discovered rogue device within 60 minutes. In alignment with ISO/IEC 27001:2022 principles, mandatory data classification tags are required for all assets, facilitating risk-based management and supporting GDPR Article 30 record-keeping obligations. All designated critical assets must undergo a formal review at a maximum interval of 30 days. The strategy addresses the full asset lifecycle by requiring end-of-life and end-of-support tracking. Adherence to SOC 2 criteria and modern security practices like those in PCI DSS v4.0 is achieved through enforced mobile device management, enabled shadow IT discovery, and continuous external attack surface mapping, ensuring all logical and physical components are identified and managed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cis-controls-v8",
      "iso-27001-2022",
      "nist-sp-1800-5-it-asset-management",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "cybersecurity-profile-hsn",
    "title": "Cybersecurity Framework Profile for Hybrid Satellite Networks (HSN)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-11-03",
    "bluf": "This Cybersecurity Profile identifies an approach to assess the cybersecurity posture of Hybrid Satellite Networks (HSN) that provide services such as satellite-based systems for communications, position, navigation, and timing (PNT), remote sensing, weather monitoring, and imaging. The Profile will consider the cybersecurity of all the interacting systems that form the HSN rather than the traditional approach of a single organization acquiring the entire satellite system. It applies to organizations that have already adopted the NIST Cybersecurity Framework (CSF), are familiar with it, or are unfamiliar but need to implement HSN services in a risk-informed manner.\n\nThe purpose of the Profile is to provide practical guidance for organizations and stakeholders engaged in the design, acquisition, and operation of satellite buses or payloads that involve HSN. The core objectives are to help organizations identify systems, assets, data and threats that pertain to HSN; protect HSN services by adhering to basic principles of resiliency; detect cybersecurity-related disturbances or corruption of HSN services and data; respond to HSN service or data anomalies in a timely, effective, and resilient manner; and recover the HSN to proper working order at the conclusion of a cybersecurity incident.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-39-managing-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "cyclonedx-1-7-owasp-ecma-sbom-standard",
    "title": "CycloneDX Bill of Materials Specification Version 1.7 (OWASP Foundation + Ecma International TC54, Components, Services, Dependencies, Vulnerabilities VEX, Formulations, Declarations, JSON/XML/Protobuf)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "CycloneDX is a lightweight, full-stack Bill of Materials (BOM) standard developed by the OWASP Foundation and standardised through Ecma International's TC54 Technical Committee. The current version is CycloneDX 1.7, released on 21 October 2025. CycloneDX supports multiple BOM types beyond traditional SBOM: Software Bill of Materials (SBOM), Hardware Bill of Materials (HBOM), AI/ML Bill of Materials (ML-BOM, for models, datasets, parameters, training context), Software-as-a-Service Bill of Materials (SaaSBOM, for services and APIs), Operations Bill of Materials (OBOM, for runtime configuration), and Cryptography Bill of Materials (CBOM, for cryptographic assets and post-quantum risk). The specification supports first-party and third-party components with component types including application, framework, library, container, platform, operating-system, device, device-driver, firmware, file, machine-learning-model, and data. The dependency graph represents direct and transitive relationships including services-to-services dependencies. Services represent external APIs with endpoint URIs, authentication requirements, and trust boundary traversals. Vulnerabilities support Vulnerability Exploitability eXchange (VEX) for stating exploitability status of known vulnerabilities (affected, not_affected with justification, fixed, under_investigation). Formulations describe manufacturing and deployment processes via formulas, workflows, tasks, and steps. Declarations capture conformance attestations to standards including the EU Cyber Resilience Act (CRA), with claims, counter-claims, evidence, and digital signatures. CycloneDX serialisation formats are JSON, XML, and Protocol Buffers with registered IANA media types. CycloneDX is one of the two SBOM formats recognised by the US NTIA Minimum Elements for SBOM under EO 14028 and OMB Memorandum M-22-18, alongside SPDX.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standard_basis",
        "key_institutions",
        "bom_types_taxonomy",
        "component_types_supported",
        "dependencies_graph",
        "services_third_party_apis",
        "vulnerabilities_and_vex",
        "formulations_manufacturing_processes",
        "declarations_cra_compliance_attestations",
        "serialisation_formats",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "spdx-3-0-iso-iec-5962-2021-sbom-standard",
      "us-cisa-known-exploited-vulnerabilities-bod-22-01",
      "mitre-cwe-top-25-2024-most-dangerous-weaknesses",
      "eu-cyber-resilience-act-2024-2847-product-security-requirements"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "cz-act-134-2016-public-procurement-zzvz-effective-2016-10-01",
    "title": "Czech Republic Act No. 134/2016 Coll. on Public Procurement (Zakon o zadavani verejnych zakazek / ZZVZ) effective 1 October 2016",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Czech Act No. 134/2016 Coll. on Public Procurement (Zakon o zadavani verejnych zakazek / ZZVZ) approved 19 April 2016 and effective 1 October 2016 is the principal Czech statute governing procurement of supplies, services, and construction works by contracting authorities including the State, regional and municipal authorities, public-sector contracting authorities, sectoral contracting entities (utilities), and other contracting authorities subject to EU procurement directive scope. ZZVZ replaced the prior Act No. 137/2006 Coll. on Public Contracts and substantially modernised the Czech procurement regime transposing the EU procurement directives 2014/24/EU (classical), 2014/25/EU (utilities), 2014/23/EU (concessions), and 89/665/EEC remedies into Czech law. The Office for the Protection of Competition (Urad pro ochranu hospodarske souteze / UOHS) is the principal regulatory authority for procurement compliance monitoring and complaint resolution. The Ministry for Regional Development (Ministerstvo pro mistni rozvoj / MMR) is the principal policy and methodology authority. The National Electronic Tool (Narodni elektronicky nastroj / NEN, nen.nipez.cz) is the centralised federal e-procurement platform alongside certified commercial e-procurement systems. Procurement methods established by ZZVZ s. 53 to 65 comprise (a) Open Procedure (Otevrene rizeni, s. 56, the default open public procedure), (b) Restricted Procedure (Uzsi rizeni, s. 58, with prequalification), (c) Negotiated Procedure with Publication (Jednaci rizeni s uverejnenim, s. 60), (d) Competitive Dialogue (Souteze dialog, s. 68, for complex acquisitions), (e) Innovation Partnership (Rizeni o inovacnim partnerstvi, s. 70), (f) Negotiated Procedure without Publication (Jednaci rizeni bez uverejneni, s. 63, under prescribed exceptions including emergency and sole-source), (g) Simplified Below-Threshold Procedure (Zjednodusene podlimitne rizeni, s. 53), (h) Direct Award for Small-Value Contracts (Verejne zakazky maleho rozsahu, exempt from full ZZVZ regime above threshold of CZK 2 million for supplies/services or CZK 6 million for construction works), and (i) Dynamic Purchasing System and Framework Agreements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "eu-public-procurement-directive-2014-24-construction",
      "eu-directive-2014-25-utilities-procurement",
      "cz-uoou-act-2019"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "cz-uoou-act-2019",
    "title": "Czech Republic Personal Data Processing Act 2019 (Act No. 110/2019 Sb.) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Czech Republic's Act No. 110/2019 Coll. on Personal Data Processing (Zákon č. 110/2019 Sb., o zpracování osobních údajů), published in the Collection of Laws of the Czech Republic on 24 April 2019 and entering into force on 24 April 2019, is the Czech Republic's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in the Czech Republic. The GDPR is directly applicable Czech law by virtue of the Czech Republic's EU membership. Act No. 110/2019 provides national derogations, additions, and specifications that the GDPR permits EU member states to adopt and repeals the prior Personal Data Protection Act (Zákon č. 101/2000 Sb.). Act No. 110/2019 is complemented by Act No. 111/2019 Coll., which amends related Czech legislation to bring it into conformity with GDPR. Enforcement: Úřad pro ochranu osobních údajů (UOOU - Office for Personal Data Protection) is the Czech Republic's independent data protection supervisory authority. The UOOU is the Czech Republic's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Czech national provisions: (1) Age of digital consent: the Czech Republic has set the age of consent for information society services at 15 years (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 15 require parental or guardian consent; (2) Employment context - the Czech Labour Code (Zákoník práce, Act No. 262/2006 Sb.) contains specific provisions on employee monitoring and privacy in employment that interact with GDPR requirements; employers in the Czech Republic are prohibited from performing surveillance of employees without prior notice; (3) Criminal data - Act No. 110/2019 restricts private entity processing of criminal conviction and offence data; public authorities may process criminal data under applicable Czech legislation; (4) Health data research - scientific research using health data in the Czech Republic requires ethics committee approval and compliance with Czech health legislation; (5) Freedom of expression - exemptions for journalistic, literary, and artistic processing aligned with GDPR Art. 85; (6) Public sector - Czech public authorities are subject to Act No. 110/2019 and Czech administrative law; the Freedom of Information Act (Zákon č. 106/1999 Sb.) interacts with GDPR in the public sector context. Fines: GDPR administrative fines apply in the Czech Republic - up to EUR 20 million or 4% of global annual turnover. The UOOU has been an active enforcement authority, imposing fines and publishing guidance on GDPR compliance in employment, public administration, and digital services sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "czech-republic-gambling-act-186-2016",
    "title": "Czech Republic Act on Gambling No. 186/2016 Sb. - Ministry of Finance Online Licensing and Technical Standards",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Czech Act No. 186/2016 Sb. on Gambling (Zakon o hazardnich hrach), effective 1 January 2017, replaced all prior Czech gambling legislation and established a unified licensing regime for online and land-based gambling; requires online operators to hold a basic licence from the Ministry of Finance (CZK 10 million capital, 10-year term), comply with technical standards verified by the Czech Telecommunication Office, integrate with the national self-exclusion register (REAS), block excluded players in real-time, pay 23% GGR tax on online casino games and 23% on sports betting, and implement AMLD5-compliant AML controls; penalties include licence revocation and fines up to CZK 50 million.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "czech-republic-space-activities-act-189-2023",
    "title": "Czech Republic Space Activities Act 189/2023 Sb. - National Space Licensing",
    "domain": "Space & Satellite Law",
    "version": "2023-07",
    "last_updated": "2026-05-09",
    "bluf": "Czech Republic Act No. 189/2023 Sb. on Space Activities establishes the Czech Space Office (CSO) as national licensing authority for space activities, introduces a mandatory permit regime for satellite operations and launch services by Czech entities, implements UN space treaty registration obligations, and aligns with EU Space Programme requirements for Czech participation in Galileo, Copernicus, and SST programmes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967-article-i-freedom",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "data-integrity-detecting-responding-ransomware",
    "title": "NIST SPECIAL PUBLICATION 1800-26 Data Integrity: Detecting and Responding to Ransomware and Other Destructive Events",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-12-31",
    "bluf": "This guide focuses on data integrity: the property that data has not been altered in an unauthorized manner, covering data in storage, during processing, and while in transit. Destructive malware, ransomware, malicious insider activity, and even honest mistakes all necessitate that organizations detect and respond to an event that impacts data integrity in a timely fashion. Attacks against an organization’s data can compromise emails, employee records, financial records, and customer information-impacting business operations, revenue, and reputation. Examples of data integrity attacks include unauthorized insertion, deletion, or modification of data.\n\nThis NIST Cybersecurity Practice Guide demonstrates how organizations can develop and implement appropriate actions during a detected data integrity cybersecurity event. The National Cybersecurity Center of Excellence (NCCoE) at NIST built a laboratory environment to explore methods to effectively detect and respond to a data integrity event in various IT enterprise environments. The guide demonstrates a solution that incorporates multiple systems working in concert to detect an ongoing data integrity cybersecurity event and provides guidance on how to respond to the detected event, enabling organizations to have the necessary tools to act during a data integrity attack.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-61r2-incident-handling",
      "nist-sp-1800-25-data-integrity",
      "nist-sp-1800-11-data-integrity",
      "cisa-ms-isac-ransomware-guide"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "de-aktiengesetz-stock-corporation-act",
    "title": "Germany Aktiengesetz Stock Corporation Act - Two-Tier Board Governance and Shareholder Rights",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Aktiengesetz governs the legal form of the German stock corporation by setting out the two-tier board structure with management board running the day to day business and supervisory board appointing and overseeing the management board, statutory shareholder rights including participation in shareholder meetings and approval of major transactions, capital maintenance and disclosure requirements aligned with European Union company law, directors and officers liability and the business judgment rule, and remedies for shareholders and creditors against breaches of duty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-bdsg-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "de-aussenwirtschaftsgesetz-awg-foreign-trade-payments-act",
    "title": "Foreign Trade and Payments Act (Aussenwirtschaftsgesetz, AWG)",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The German Foreign Trade and Payments Act (Aussenwirtschaftsgesetz, AWG) is the primary statute governing foreign trade, export controls, and the implementation of restrictive measures in Germany. Section 4 authorises legal acts and orders to restrict foreign trade transactions in order to guarantee the essential security interests of the Federal Republic of Germany and to guarantee public order or security, and provides for foreign-investment screening, including in connection with projects or programmes of Union interest. Section 8 governs licences (authorisations) for restricted transactions and provides that a licence must be issued where it is to be expected that the transaction will not endanger the protected purpose. Sections 9a, 9b, 9c, and 9d establish powers in connection with European Union sanctions: Section 9a empowers authorities to trace money and economic assets of persons subject to EU sanctions, Section 9b authorises orders to freeze assets to prevent violations of EU sanctions, Section 9c sets out freezing modalities including impounding and sale procedures, and Section 9d governs the processing of personal data in tracing and freezing operations. Section 18 sets out the criminal provisions: violations are punishable by a prison sentence from three months up to five years, with enhanced penalties (a prison sentence of not less than one year) for acts benefiting a foreign intelligence service or committed for gain. Compliance requires classifying transactions against the licensing requirements, applying for licences under Section 8 where required, implementing EU-sanctions asset-freezing obligations, and recognising the criminal exposure under Section 18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-aussenwirtschaftsverordnung-awv-foreign-trade-payments-ordinance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "de-aussenwirtschaftsverordnung-awv-foreign-trade-payments-ordinance",
    "title": "Foreign Trade and Payments Ordinance (Aussenwirtschaftsverordnung, AWV)",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The German Foreign Trade and Payments Ordinance (Aussenwirtschaftsverordnung, AWV) implements the Foreign Trade and Payments Act (AWG) and sets out the detailed rules for export licensing and foreign-investment screening in Germany. Section 8 requires an export licence for goods listed in Part I Section A and Part I Section B of the Export List. Section 9 provides for licensing requirements for certain non-listed goods where the Federal Office for Economic Affairs and Export Control (BAFA) notifies the exporter that the goods are or may be intended for a nuclear facility or related end-use in specified countries. Section 21 provides that only the exporter can apply for an export licence. Section 55 governs the cross-sectoral investment review: the Federal Ministry for Economic Affairs may assess whether the direct or indirect acquisition by a non-EU resident of a domestic company, or of a stake in a domestic company, is likely to affect public order or security within the meaning of Regulation (EU) 2019/452, with an expanded acquisition concept covering a definable part of operations or all the essential operating equipment needed to maintain the operation, and with provisions addressing abusive or circumventing arrangements where the direct acquirer does not maintain significant business operations of its own. Section 56 defines acquisitions subject to review in the cross-sectoral review. Compliance requires classifying goods against the Export List, obtaining BAFA licences where required, observing BAFA catch-all notifications, and assessing investment-screening obligations for non-EU acquisitions of domestic companies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-aussenwirtschaftsgesetz-awg-foreign-trade-payments-act"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "de-bdsg-2018",
    "title": "Germany Federal Data Protection Act 2018 (Bundesdatenschutzgesetz, BDSG)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Federal Data Protection Act 2018 (Bundesdatenschutzgesetz, BDSG) is Germany's principal data protection statute, entering into force on 25 May 2018 to supplement and implement the EU General Data Protection Regulation 2016/679 (GDPR) at national level. The BDSG is enforced by the Federal Commissioner for Data Protection and Freedom of Information (Bundesbeauftragte für den Datenschutz und die Informationsfreiheit, BfDI) for federal public bodies and by the sixteen state (Land) data protection authorities (Landesdatenschutzbehörden) for state public bodies and private entities. § 1 confirms that the BDSG supplements GDPR and applies where Union law does not provide complete rules, or where Union law opens national scope for supplementary legislation under Article 6(2), Article 9(4), and Article 88 GDPR. § 22 opens the special categories of personal data prohibition in Article 9(1) GDPR for German-specific purposes including employment and social security law, vital interests, non-profit associations, medical treatment, public health, archiving, scientific research, and the administration of justice. § 26 is the principal German-specific provision governing data processing in employment relationships (implementing the Article 88 GDPR opening): employers may process personal data of employees where necessary for the establishment, implementation, or termination of the employment relationship; for detecting criminal offences where there is documented factual cause and processing is proportionate; or for compliance with obligations arising from collective agreements or works council agreements. Consent in employment contexts must be assessed for voluntariness given the dependency relationship, though consent may be valid in certain cases such as advantages for the employee. § 38 requires private sector controllers and processors to appoint a Data Protection Officer (DPO) where 20 or more persons are constantly engaged with automated personal data processing; the DPO must be appointed before processing begins, may be internal or external, must be expert in data protection law and practice, and has statutory independence. § 42 prescribes criminal penalties of imprisonment up to two years (or three years in aggravated cases) for intentional commercial disclosure of personal data of a large number of persons without authorisation, or for processing for personal or third-party enrichment or to cause harm. § 43 sets out administrative fines of up to EUR 50,000 for violations of BDSG-specific provisions (distinct from and in addition to GDPR Article 83 fines of up to EUR 20 million or 4% of worldwide annual turnover).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "de-berufsbildungsgesetz-vocational-training-act",
    "title": "Berufsbildungsgesetz (BBiG) - Vocational Training Act",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This act requires organizations to establish, manage, and document all aspects of vocational training relationships, including written contracts, minimum remuneration, trainer suitability, registration with competent authorities, and issuance of certificates upon completion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "de-bsi-c5-cloud-computing-compliance-criteria-catalogue",
    "title": "Germany BSI C5 — Cloud Computing Compliance Criteria Catalogue (C5:2026)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Cloud Computing Compliance Criteria Catalogue (C5) is the German federal cloud assurance standard issued by the Federal Office for Information Security (Bundesamt fuer Sicherheit in der Informationstechnik / BSI). The current revision C5:2026 was completed in 2025/26 to incorporate post-quantum cryptography migration considerations, AI workload security, supply-chain risk under EU NIS2 and the EU AI Act, and updated DORA third-party ICT risk alignment. C5 audits are conducted by qualified independent auditors (Wirtschaftspruefer or comparable) using an examination report aligned to the International Standard on Assurance Engagements ISAE 3402 and the German IDW Pruefungsstandard PS 951. C5 differentiates Basis Criteria (mandatory baseline for any C5-certified cloud service) and Additional Criteria (elective extensions including data residency in Germany / EU, high availability, and high confidentiality categories). The C5 control areas span the full information security and operations lifecycle including Organisation of Information Security (OIS), Security Policies and Procedures (COS), Human Resources Security (HR), Asset Management (AM), Physical Security (PS), Operations Security (RB), Communications Security (KOS), Identity and Access Management (IDM), Cryptography (CRY), System Acquisition Development and Maintenance (DEV), Supplier Relationships (PSS), Business Continuity Management (BCM), Compliance (COM), Incident Management (BEI), Privacy and Data Protection (PI), Customer Inquiries (BEI), and Cloud-Specific Architecture (KOS). C5 is mandatory or strongly preferred for German federal public-sector cloud procurements, KRITIS critical infrastructure operators under IT-SiG 2.0, and many BaFin-supervised financial institutions consuming third-party cloud services under DORA. C5 attestation reports are reusable across customers under a Type 1 (design) and Type 2 (operating effectiveness over period) framework, materially reducing repeat-audit burden for hyperscale CSPs and enterprise consumers. C5 also intersects with the European Cybersecurity Certification Scheme for Cloud Services (EUCS) as Germany's national basis for the harmonised EU-level scheme expected to enter force from 2025 onward.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-iec-42001-2023-ai-management-system",
      "iso-iec-23894-ai-risk-management-2023",
      "nist-sp-800-53-r5",
      "fips-203-ml-kem-standard",
      "us-cisa-secure-by-design-principles-2023"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "de-bsi-post-quantum-cryptography-position-tr-02102-1",
    "title": "BSI Post-Quantum Cryptography Position and Technical Guideline TR-02102-1 (Germany)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-01-23",
    "bluf": "The German Federal Office for Information Security (BSI) sets out its post-quantum cryptography position through its quantum technologies and post-quantum cryptography guidance and documents its concrete algorithm and key length recommendations in Technical Guideline BSI TR-02102-1, Cryptographic Mechanisms: Recommendations and Key Lengths, version 2026-01 dated 23 January 2026.\n\nThe distinguishing element of the German position is its treatment of hybrid deployment. BSI states that post-quantum schemes should only be used in combination with classical schemes, described as hybrid, if possible, and observes that a hybrid approach using two or more post-quantum schemes remains a possible solution even after the development of cryptographically relevant quantum computers. This is a stronger hybrid stance than a simple recommendation to adopt post-quantum algorithms, and it shapes how German-regulated deployments are expected to be configured. BSI records that first post-quantum algorithms have been selected by NIST for standardisation, and states that the migration to post-quantum cryptography should be pushed forward. It co-signed the joint European statement Securing Tomorrow, Today: Transitioning to Post-Quantum Cryptography in November 2024, urging industry, critical infrastructure providers and public administration to start the transition, and published the guideline Quantum-safe cryptography, fundamentals, current developments and recommendations in December 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-203-ml-kem-standard",
      "fips-204-ml-dsa-standard",
      "ietf-rfc-9794-pq-traditional-hybrid-terminology",
      "nist-ir-8547-pqc-transition"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "de-bsig-it-sig-2-2021",
    "title": "Germany BSI Act and IT Security Act 2.0 (IT-SiG 2.0) 2021",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Germany's IT Security Act 2.0 (IT-SiG 2.0), which came into force on May 28, 2021, significantly expands the BSI Act by broadening the definition of critical infrastructure operators, mandating attack detection systems for KRITIS operators since May 2023, requiring 72-hour incident reporting to the BSI for critical infrastructure, extending cybersecurity obligations to federal government IT systems, and imposing penalties of up to EUR 20 million for serious non-compliance by critical infrastructure operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/de-bsig-it-sig-2-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "de-bundesausbildungsfoerderungsgesetz-student-funding",
    "title": "Bundesgesetz über individuelle Förderung der Ausbildung (BAföG)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This regulation establishes the procedural requirements for educational institutions and funding bodies to administer federal training assistance, including verifying applicant eligibility based on nationality and suitability, processing applications, and cooperating with authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "de-collective-agreements-act-tvg",
    "title": "Collective Agreements Act (Tarifvertragsgesetz - TVG)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act governs collective agreements between trade unions and employers or employers associations. A collective agreement governs the rights and obligations of the parties to the agreement and contains legal norms regulating the content, conclusion and termination of employment relationships (Section 1), and must be in writing. The persons bound by a collective agreement are the members of the parties to it and the employer who is itself a party (Section 3). The normative terms of the agreement apply directly and mandatorily to employment relationships between bound persons (Section 4). On a joint application by the parties, the Federal Ministry of Labour and Social Affairs may declare a collective agreement to be of universal application (Section 5), and collective agreements are entered in a register (Section 6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-works-council-directive-2009-38",
      "de-works-constitution-act-betrvg"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-commercial-code-hgb",
    "title": "Commercial Code (Handelsgesetzbuch - HGB)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Code governs the law of merchants and commercial transactions in Germany. A merchant within the meaning of the Code is a person who carries on a commercial business (Section 1). The Code requires registration of merchants in the commercial register, which is maintained electronically and open to public inspection (Sections 8, 9 and 29), governs commercial powers of representation including the Prokura and general commercial power of agency (Sections 48 to 58), and regulates commercial agents and their entitlements (Sections 84 to 87d). Its later books govern commercial accounting and the duty to keep books and prepare financial statements, and the law of commercial transactions and trading companies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-aktiengesetz-stock-corporation-act",
      "de-gmbh-act-gmbhg"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-environmental-liability-act-umwelthg",
    "title": "Environmental Liability Act (Umwelthaftungsgesetz - UmweltHG)",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act imposes strict liability on the operator of a listed installation for death, personal injury or property damage caused by an environmental impact emanating from the installation (Section 1), including from installations no longer in operation (Section 2). It defines environmental impact and related terms (Section 3), provides defined exclusions and limitation of liability for property damage (Sections 4 and 5), and creates a rebuttable presumption that the installation caused the damage where it is inherently suited to cause that damage (Section 6), subject to exclusion of the presumption (Section 7). It grants rights to information (Sections 8 to 10), sets the extent of liability for death and bodily injury (Sections 12 and 13), a maximum amount of compensation (Section 15), and requires operators of installations listed in Annex 2 to maintain financial security to meet liabilities (Section 19).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-environmental-liability-directive-2004-35-ec",
      "germany-water-management-act-wasserhaushaltsgesetz-2009"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-federal-climate-action-act-ksg",
    "title": "Federal Climate Action Act (Bundes-Klimaschutzgesetz - KSG)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act provides protection from the effects of climate change by ensuring the achievement of national climate targets and compliance with European obligations under the Paris Agreement (Section 1). It sets national climate targets requiring a reduction of greenhouse gas emissions of at least 65 percent by 2030 compared to 1990 levels and net greenhouse gas neutrality by 2045 (Section 3). It establishes total annual emission budgets as a binding cross-sectoral mechanism for monitoring compliance with the climate targets across multiple years and sectors including energy, industry, buildings, transport, agriculture and waste (Section 4), with monitoring, reporting and corrective measures where a sector exceeds its budget.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eed-energy-efficiency-2023-1791",
      "eu-ets-directive-2003-87-emissions-trading-scheme"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-federal-mining-act-bbergg",
    "title": "Federal Mining Act (Bundesberggesetz - BBergG)",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act governs the prospecting, extraction and treatment of mineral resources in Germany (Section 1). It distinguishes freely mineable and freehold mineral resources (Section 3) and establishes the mining authorisations: an exploration licence accords the holder the exclusive right to explore for specified resources in a field (Section 7), and an extraction licence accords the exclusive right to extract them (Section 8), with mining proprietorship as a further title (Section 9). Exploration, extraction and treatment operations may be erected, carried out and terminated only on the basis of operating plans prepared by the entrepreneur and approved by the competent mining authority (Section 51), with field and mining royalties (Sections 30 to 32) and rules on responsible persons and mine plans.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "germany-water-management-act-wasserhaushaltsgesetz-2009",
      "de-federal-climate-action-act-ksg"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-fiscal-code-ao",
    "title": "Fiscal Code of Germany (Abgabenordnung - AO)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Code is the general tax code of Germany, governing the procedural framework common to all taxes (Section 1), subject to the primacy of international agreements (Section 2). It defines taxes as payments of money, other than payments in consideration of a particular activity, collected by a public body to raise revenue (Section 3), and establishes the connecting factors for tax liability and jurisdiction, including residence (Section 8), habitual abode (Section 9), the place of business management (Section 10), the registered office (Section 11), the permanent establishment (Section 12) and the permanent representative (Section 13). It allocates subject-matter and local jurisdiction among the revenue authorities (Sections 16 and 17).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-gwg-aml-2017",
      "de-gmbh-act-gmbhg"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-general-equal-treatment-act-agg",
    "title": "General Act on Equal Treatment (Allgemeines Gleichbehandlungsgesetz - AGG)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act seeks to prevent or stop discrimination on the grounds of race or ethnic origin, gender, religion or belief, disability, age or sexual orientation (Section 1). It defines direct and indirect discrimination and harassment (Section 3), prohibits discrimination of employees on any of those grounds (Section 7), and permits differences of treatment only where justified by occupational requirements, religion or belief, or age (Sections 8 to 10). Employers have duties to prevent discrimination and to act on complaints (Section 12), employees have a right of complaint and a right to refuse performance (Sections 13 and 14), and the Act provides for compensation and damages (Section 15), protection against victimisation (Section 16) and a shift in the burden of proof (Section 22).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-employment-equality-directive-2000-78",
      "eu-racial-equality-directive-2000-43"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-gmbh-act-gmbhg",
    "title": "Act on Limited Liability Companies (Gesetz betreffend die Gesellschaften mit beschraenkter Haftung - GmbHG)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act governs the German limited liability company (GmbH). The company is a legal person with independent rights and obligations that may hold property and sue and be sued (Section 13), and its share capital must amount to no less than 25,000 euros (Section 5). The Act regulates the formation of the company, the contributions of shareholders, and the preservation of share capital, prohibiting the payment to shareholders of assets required to maintain the share capital (Section 30). Managing directors must conduct the company affairs with the due care of a prudent businessperson and are jointly and severally liable to the company for damage arising from a breach of their duties (Section 43).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-aktiengesetz-stock-corporation-act",
      "de-insolvency-code-inso"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-gwb-competition-act",
    "title": "Germany Act against Restraints of Competition (Gesetz gegen Wettbewerbsbeschränkungen, GWB, as amended by 11th Amendment 2023)",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Act against Restraints of Competition (Gesetz gegen Wettbewerbsbeschränkungen, GWB) is Germany's principal competition law statute, originally enacted in 1957 and substantially modernised through twelve amendments, with the 10th Amendment (GWB-Digitalisierungsgesetz) entering into force on 19 January 2021 and the 11th Amendment entering into force on 7 November 2023. The GWB is administered by the Bundeskartellamt (Federal Cartel Office) in Bonn and the Bundesnetzagentur for certain regulated sectors. § 1 GWB prohibits agreements between undertakings, decisions by associations of undertakings, and concerted practices that restrict competition by object or effect, parallel to Article 101 TFEU. Horizontal cartels - price fixing, market sharing, output limitation, bid rigging - are treated as restrictions by object. § 19 GWB prohibits abuse of a dominant position, parallel to Article 102 TFEU; an undertaking is dominant where it has no substantial competition or holds a paramount market position. § 20 GWB extends the abuse prohibition to undertakings with relative market power (Marktmacht), prohibiting unfair hindrance or discriminatory treatment of small and medium-sized enterprises dependent on the undertaking. The 10th Amendment introduced § 19a GWB, which empowers the Bundeskartellamt to designate undertakings of 'paramount significance for competition across markets' (überragende marktübergreifende Bedeutung) and to prohibit them from engaging in self-preferencing, restricting interoperability, tracking users across platforms without consent, creating barriers to market entry, or denying access to competitively relevant data. Alphabet (Google), Apple, Amazon, Meta, and Microsoft have been designated under § 19a. § 35 GWB establishes merger control thresholds: the combined worldwide turnover of all participating undertakings must exceed EUR 500 million; the domestic German turnover of at least one undertaking must exceed EUR 25 million; and the domestic German turnover of at least one other undertaking must exceed EUR 5 million. The 9th Amendment introduced a second domestic threshold for transactions with a consideration exceeding EUR 400 million where the target has significant activities in Germany, capturing acquisitions of data-rich companies before the turnover thresholds are met. Concentrations meeting the thresholds must be notified to the Bundeskartellamt before implementation. § 81 GWB prescribes administrative fines of up to 10% of the total worldwide annual group turnover in the preceding business year for cartel and dominant abuse violations, with leniency available for first cartel disclosers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tfeu-article-102-abuse-of-dominance",
      "eu-merger-regulation-139-2004-ecmr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "de-gwb-part-4-public-procurement",
    "title": "Germany Gesetz gegen Wettbewerbsbeschränkungen (GWB) Part 4 - Public Procurement (§§97-184)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Part 4 (Teil 4) of the Gesetz gegen Wettbewerbsbeschränkungen (GWB) establishes the legal framework for award of public contracts (Vergabe öffentlicher Aufträge) above EU thresholds in Germany, transposing the EU public procurement directives. Sections 97-114 set out the principles and scope, including §97 (Grundsätze der Vergabe — principles of competition, transparency, equal treatment, proportionality and economy), §§98-105 (definitions of öffentliche Auftraggeber and types of contracts), §106 (thresholds), and §§110-112 (mixed procurement). Sections 115-135 cover award of public contracts, with §119 prescribing the procedure types (offenes Verfahren, nichtoffenes Verfahren, Verhandlungsverfahren, wettbewerblicher Dialog and Innovationspartnerschaft), §122 setting qualification requirements, §123 listing mandatory exclusion grounds and §124 listing discretionary exclusion grounds. Sections 136-154 contain sector-specific rules for utilities (Sektorenauftraggeber), defence and security (§§144-147) and concessions (§§148-154). Sections 155-184 establish the Nachprüfungsverfahren (review procedures), centred on the Vergabekammern (procurement review chambers) under §156 with immediate appeal to the higher regional courts under §§171-182.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-gwb-competition-act",
      "eu-public-procurement-construction-directive"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "de-gwg-aml-2017",
    "title": "Germany Money Laundering Act 2017 (Geldwäschegesetz, GwG, as amended)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Money Laundering Act 2017 (Geldwäschegesetz, GwG) is Germany's principal anti-money laundering and counter-terrorist financing statute, transposing the EU 4th Anti-Money Laundering Directive (2015/849) and subsequently amended to transpose the 5th Anti-Money Laundering Directive (2018/843). The GwG is supervised by BaFin (Bundesanstalt für Finanzdienstleistungsaufsicht) for financial sector obligated parties, by the Steuerberaterkammer for tax advisors, by state bar associations for lawyers, by local authorities for real estate agents, and by the Financial Intelligence Unit (FIU, Zentralstelle für Finanztransaktionsuntersuchungen) under the Bundeskriminalamt (BKA) for AML intelligence. § 2 GwG defines the broad range of obligated parties (Verpflichtete): credit institutions and financial services institutions regulated by the Kreditwesengesetz (KWG); insurance companies and insurance intermediaries; investment management companies; payment service providers; crypto asset service providers (extended by the 2020 amendment transposing 5AMLD); lawyers, notaries, and legal service providers when they engage in specified financial transactions or company formations; tax advisors, auditors, and accountants; real estate agents; art dealers and auction houses for transactions exceeding EUR 10,000; gambling operators; company service providers; and trust service providers. § 10 GwG prescribes general customer due diligence (CDD) measures that obligated parties must carry out before establishing a business relationship or executing a transaction: identification and verification of the customer's identity using reliable and independent sources; identification and verification of any beneficial owner; assessment of the purpose and intended nature of the business relationship; and ongoing monitoring of the business relationship. § 11 GwG prescribes simplified due diligence applicable to lower-risk customers (e.g., listed companies, credit institutions in equivalent jurisdictions). § 12 GwG prescribes enhanced due diligence (EDD) measures required for higher-risk situations including: business relationships or transactions involving politically exposed persons (PEPs) and their family members and close associates; business relationships or transactions involving high-risk third countries listed by the EU Commission; anonymous transactions; correspondent banking relationships; and any transaction that by its nature carries a higher risk of money laundering. § 43 GwG requires obligated parties to file a suspicious activity report (Verdachtsmeldung) with the FIU without delay, and in any event before executing the transaction, where they have knowledge, suspicion, or reasonable grounds to suspect that an asset is the proceeds of a criminal offence or is related to terrorist financing. A tipping-off prohibition applies; the obligated party may not disclose to the customer or any third party that a report has been made or is being considered. § 57 GwG prescribes administrative fines of up to EUR 1 million for serious, repeated, or systematic violations, or up to EUR 5 million or 10% of total annual turnover (whichever is higher) for credit institutions and financial services institutions for the most serious violations. The Transparenzregister (Transparency Register), mandated by § 18-26 GwG as supplemented by the Transparenzregistergesetz, requires all legal entities to register their beneficial owners (natural persons holding more than 25% ownership interest or exercising control by other means).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-bdsg-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "de-hochschulrahmengesetz-higher-education-framework",
    "title": "Hochschulrahmengesetz (HRG) - Higher Education Framework Act",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This regulation establishes the fundamental framework for higher education institutions in Germany, covering their tasks, student admissions, personnel, and legal status, including obligations for gender equality, research publication, and state supervision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "de-insolvency-code-inso",
    "title": "Insolvency Code (Insolvenzordnung - InsO)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Code governs insolvency proceedings, which serve the collective satisfaction of a debtor creditors by liquidation of the debtor assets or by an arrangement in an insolvency plan (Section 1). Proceedings are opened on the written application of a creditor or the debtor (Section 13). Legal entities that become insolvent must file for the opening of proceedings without undue delay and within three weeks of the onset of illiquidity, or within six weeks of the discovery of overindebtedness (Section 15a). The grounds for opening are illiquidity, where the debtor cannot meet mature payment obligations (Section 17), and overindebtedness, where assets no longer cover obligations unless continuation of the enterprise is highly likely (Section 19). On opening, the court appoints an insolvency administrator (Section 27).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-aktiengesetz-stock-corporation-act",
      "de-gmbh-act-gmbhg"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-insurance-contract-act-vvg",
    "title": "Insurance Contract Act 2008 (Versicherungsvertragsgesetz - VVG)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act governs the contract of insurance under which the insurer undertakes to cover a specific risk of the policyholder in exchange for premiums (Section 1). It requires the insurer to advise the policyholder according to their wishes and needs and to document that advice (Section 6), grants the policyholder a right of revocation within 14 days of the contractual agreement (Section 8), and imposes a pre-contractual duty of disclosure on the policyholder to declare known risk factors in writing, breach of which permits the insurer to withdraw or terminate under defined conditions (Section 19). It governs information provision, cross-selling, commencement and termination, premium payment and the consequences of breaches of duty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-insurance-distribution-directive-2016-97",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-jugendschutzgesetz-juschg-stgb-184-restricted-content-bzkj",
    "title": "Germany Jugendschutzgesetz (JuSchG) and StGB § 184 - Youth Protection Act §§ 1, 4, 12, 14, 15, 18, 24a, 24b, 24c, 27, 28; Strafgesetzbuch § 184; BzKJ (Bundeszentrale für Kinder- und Jugendmedienschutz) Enforcement",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "The German Jugendschutzgesetz (JuSchG - Youth Protection Act) and Strafgesetzbuch (StGB - Criminal Code) § 184 form the federal-level legal regime in Germany governing the distribution of media that may endanger or restrict minors. The JuSchG was last amended on 6 May 2024 (BGBl. 2024 I Nr. 149 Art. 12) and is published at gesetze-im-internet.de/juschg. Key sections include § 1 (Definitions - children are persons under 14, adolescents are persons aged 14 to under 18, media includes both physical carriers Trägermedien and digital services digitale Dienste); § 12 (age classification Altersfreigabe for films and computer games on physical carriers); § 14 (age labels - the five-tier system: ohne Altersbeschränkung, ab 6, ab 12, ab 16, keine Jugendfreigabe); § 15 (jugendgefährdende Medien - media that endanger minors - distribution to minors is prohibited); § 18 (the Liste jugendgefährdender Medien - the federal index of youth-endangering media maintained by the BzKJ); § 24a (Vorsorgemaßnahmen - precautionary measures for telemedia providers and digital service providers including age verification, complaint mechanisms, and privacy protections); § 24b and § 24c (enforcement by the BzKJ - Bundeszentrale für Kinder- und Jugendmedienschutz); § 27 (criminal penalties including imprisonment up to one year or fines for distribution offences); § 28 (administrative fines up to 5 million euro for non-compliance with BzKJ orders). The Strafgesetzbuch § 184 (Verbreitung pornographischer Inhalte) criminalises offering, supplying, or making available pornographic content to a person under 18 (an einer Person unter achtzehn Jahren anbietet, überläßt oder zugänglich macht) and parallel acts including unsolicited distribution, public promotion, public screenings for a fee, and certain export acts with imprisonment up to one year or a fine. The Jugendmedienschutz-Staatsvertrag (JMStV - Inter-State Treaty on the Protection of Minors in the Media) and the KJM (Kommission für Jugendmedienschutz) operate at the Länder level alongside the federal JuSchG and StGB regimes; an operator with German users must satisfy all three layers simultaneously.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "juschg_section_1_definitions",
        "juschg_section_12_age_classification",
        "juschg_section_14_age_labels",
        "juschg_section_15_endangering_media",
        "juschg_section_18_index_list",
        "juschg_section_24a_precautionary_measures",
        "juschg_section_24b_24c_enforcement",
        "juschg_section_27_criminal_penalties",
        "juschg_section_28_administrative_fines",
        "stgb_section_184_criminal_content_distribution",
        "jmstv_kjm_lander_layer",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-avmsd-article-28a-28b-video-sharing-platform-minors-protection",
      "eu-dsa-article-28-online-protection-of-minors",
      "eu-eidas-2-digital-identity-wallet-2024-1183",
      "it-caivano-decree-article-13-bis-agcom-96-25-cons-age-verification",
      "uk-ofcom-highly-effective-age-assurance-guidance-2025-osa-part-5"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "de-juschg-10b-entwicklungsbeeintraechtigende-medien",
    "title": "Germany JuSchG §10b - Entwicklungsbeeinträchtigende Medien (Development-Impairing Media Risk Factors)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Section 10b of the German Jugendschutzgesetz (JuSchG - Youth Protection Act of 23 July 2002 BGBl. I S. 2730 as amended by the Zweites Gesetz zur Änderung des Jugendschutzgesetzes of 9 April 2021 BGBl. I S. 742 in force 1 May 2021) provides the substantive risk-factor framework for classifying media as entwicklungsbeeinträchtigend (development-impairing) under §10a Nummer 1: §10b(1) provides the central scope definition - 'Zu den entwicklungsbeeinträchtigenden Medien nach § 10a Nummer 1 zählen insbesondere übermäßig ängstigende, Gewalt befürwortende oder das sozialethische Wertebild beeinträchtigende Medien' (development-impairing media include in particular excessively frightening, violence-glorifying, or sozialethical-values-impairing media); §10b(2) extends the assessment beyond static media content to account for usage circumstances that constitute permanent components of the offering and justify departure from the standard labeling regime; §10b(3) requires consideration of risks to the personal integrity (persönliche Integrität) of children and adolescents arising specifically from Kommunikations- und Kontaktfunktionen (communication and contact functions), Kauffunktionen (purchase functions), glücksspielähnliche Mechanismen (gambling-like mechanisms), exzessive Nutzung fördernde Mechanismen (excessive-use-promoting mechanisms), unbefugte Datenweitergabe (unauthorized data sharing), and altersgefährdende Werbung (age-inappropriate advertising); §10b operates as the substantive standard underlying §14 age-rating decisions, §14a platform labeling, §15 indexed-media list decisions, and §24a-24c platform precaution duties (Vorsorgemaßnahmen). The 2021 reform expanded §10b beyond traditional content depiction to include the interactive and economic features of modern online services - the substantive innovation that brings social media, gaming, gambling-adjacent loot box mechanics, and predatory micropurchase systems within the youth protection framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "juschg_classification_framework",
        "age_rating_integration_section_14",
        "platform_obligation_integration_section_14a",
        "precaution_duties_section_24a_24c",
        "industry_mapping",
        "enforcement_anchors",
        "interaction_with_eu_dsa",
        "twenty_twenty_one_reform_innovation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-juschg-14a-film-game-platform-labeling",
      "dsa-regulation-article-34-risk-assessment-vlop-vlose"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-juschg-14a-film-game-platform-labeling",
    "title": "Germany JuSchG §14a - Kennzeichnung bei Film- und Spielplattformen (Age Labeling on Film and Game Platforms)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Section 14a of the German Jugendschutzgesetz (JuSchG - Youth Protection Act of 23 July 2002 BGBl. I S. 2730, comprehensively reformed by the Zweites Gesetz zur Änderung des Jugendschutzgesetzes of 9 April 2021 BGBl. I S. 742 in force from 1 May 2021) extends age-labeling obligations from physical media into the digital streaming and gaming ecosystem: §14a(1) defines a Film- und Spielplattform (film/game platform) as 'Diensteanbieter, die Filme oder Spielprogramme in einem Gesamtangebot zusammenfassen und mit Gewinnerzielungsabsicht als eigene Inhalte zum individuellen Abruf zu einem von den Nutzerinnen und Nutzern gewählten Zeitpunkt bereithalten' - i.e., commercial on-demand catalogues of films or games offered as own content; the obligation to label content with age classifications under §14(2) applies to all such platforms, with labels sourced from one of three approval pathways: (a) the formal Obersten Landesjugendbehörden / KJM classification procedure, (b) recognised self-regulatory bodies such as Freiwillige Selbstkontrolle der Filmwirtschaft (FSK) or Unterhaltungssoftware Selbstkontrolle (USK), or (c) automated assessment systems recognised by the state authorities (typically IARC International Age Rating Coalition for games and equivalents for streaming); §14a(2) provides exemptions where platforms have 'nachweislich weniger als eine Million Nutzerinnen und Nutzer' (verifiably fewer than 1 million users) in Germany OR where content is restricted to adults via age verification (Altersverifikationssystem AVS); §14a(3) extends jurisdictional reach to non-German service providers serving German users (paralleling EU AVMSD country-of-destination principle in Article 28b); §10b and §14(2a) apply analogously, importing the development-impairment risk assessment framework into platform obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "juschg_framework_structure",
        "twenty_twenty_one_jusmod_reform",
        "recognised_classification_bodies",
        "automated_assessment_systems",
        "industry_mapping",
        "enforcement_anchors",
        "country_of_destination_jurisdiction_section_14a_3"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-avmsd-2018-1808-article-6a-minors-protection",
      "uk-online-safety-act-2023-part-5-pornographic-content-duties"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-lksg-supply-chain-due-diligence-act-2021",
    "title": "German LkSG - Lieferkettensorgfaltspflichtengesetz 2021: Supply Chain Due Diligence Obligations, Risk Analysis, Prevention and Remediation Measures, BAFA Enforcement, Annual Reporting, and Interaction with EU CSDDD",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The German Lieferkettensorgfaltspflichtengesetz (LkSG, Supply Chain Due Diligence Act), enacted 16 July 2021 (BGBl. I S. 2959), is the first major national EU-member supply chain due diligence law; applicable from 1 January 2023 for companies with ≥3,000 employees in Germany, and 1 January 2024 for companies with ≥1,000 employees in Germany; key obligations include: mandatory annual risk analysis of direct suppliers for human rights and environmental risks listed in §2(1) and §2(2) (covering 11 internationally recognised human rights instruments and 2 environmental conventions); prevention measures including policy statement, supplier codes of conduct, and contractual assurances from direct suppliers; remediation obligations when violations are identified at direct or indirect suppliers; an accessible complaints/grievance mechanism for affected parties globally; annual compliance report submitted to BAFA (Bundesamt für Wirtschaft und Ausfuhrkontrolle - Federal Office for Economic Affairs and Export Control) by 30 April each year; BAFA administrative oversight with fines up to EUR 8 million or 2% of average annual global group turnover for companies with annual global turnover above EUR 400 million; exclusion from public procurement for wilful or grossly negligent violations; obligations extend to indirect suppliers only where company has substantiated knowledge (konkretisierter Anlass) of violations; LkSG obligations run parallel to EU Corporate Sustainability Due Diligence Directive (CSDDD) 2024/1760 - companies must comply with the more stringent of the two frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_CSDDD",
        "EU_CSRD",
        "UN_GUIDING_PRINCIPLES",
        "OECD_MNE"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-corporate-sustainability-due-diligence-2024",
      "eu-csrd-2022-2464",
      "eu-deforestation-regulation-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "de-maritime-labour-act-seearbg",
    "title": "Maritime Labour Act (Seearbeitsgesetz - SeeArbG)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act transposes the Maritime Labour Convention 2006 into German law and governs the working and living conditions of crew members on seagoing ships (Section 1). The shipowner may employ a crew member only on the basis of a valid seafarer employment agreement (Section 28), and persons below the age of 16 or subject to compulsory full-time schooling may not be employed as crew members (Section 10). A crew member must document medical fitness for sea service before taking up activity through a certificate issued by an authorised physician (Section 12). The Act regulates hours of work and rest, with the hours of work at sea of crew members assigned to watchkeeping duties not to exceed eight hours per day as a rule (Sections 42 to 55), together with provisions on accommodation, food and the maritime labour certificate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-maritime-labour-convention-2006-mlc",
      "eu-maritime-passenger-rights-regulation-1177-2010"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-maternity-protection-act-muschg",
    "title": "Maternity Protection Act (Mutterschutzgesetz - MuSchG)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act protects the health of women at work during pregnancy, after childbirth and while breastfeeding, and their employment. The employer may not employ a pregnant woman in the last six weeks before delivery, and may not employ a woman until eight weeks after delivery (Section 3). The employer must not allow a pregnant or breastfeeding woman to carry out activities that expose her to hazardous substances or conditions posing an irresponsible risk to her or her child (Sections 11 and 12). The employer may not dismiss a woman during pregnancy or until at least four months after delivery, and after a miscarriage from the twelfth week, except in limited approved cases (Section 17), and the Act provides maternity benefits and protections (Sections 18 to 25).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-pregnant-workers-health-safety-directive-92-85",
      "eu-work-life-balance-directive-2019-1158"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-medicinal-products-act-amg",
    "title": "Medicinal Products Act (Gesetz ueber den Verkehr mit Arzneimitteln - Arzneimittelgesetz - AMG)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act governs trade in medicinal products to guarantee their safety, quality and efficacy (Section 1). It defines medicinal products, substances and related terms (Sections 2 to 4), prohibits unsafe and falsified medicinal products and products that deceive (Sections 5 and 8), and sets requirements on the party responsible for placing products on the market (Section 9), labelling (Section 10), the package leaflet (Section 11) and expert information (Section 11a). The commercial manufacture of medicinal products requires a manufacturing authorisation from the competent authority (Section 13), which is decided against defined criteria including a qualified person and suitable premises (Sections 14 and 15).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-medical-devices-regulation-2017-745",
      "eu-reinforced-role-ema-medicines-regulation-2022-123"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-minimum-wage-act-milog",
    "title": "Minimum Wage Act (Mindestlohngesetz - MiLoG)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act establishes a statutory minimum wage. Each worker is entitled to payment by their employer of remuneration of no less than the statutory minimum wage (Section 1), which is payable on the agreed due date and at the latest on the last bank working day of the month following the work (Section 2), and the entitlement is mandatory and cannot be waived or forfeited (Section 3). It establishes the Minimum Wage Commission to set the level (Sections 4 to 12), imposes liability on a contracting entity for its contractors compliance (Section 13), grants the customs authorities enforcement powers with employer cooperation, notification and record-keeping duties (Sections 14 to 17), and obliges employers in Germany and abroad to pay the minimum wage (Section 20), with administrative fines of up to 500,000 euros and possible exclusion from public procurement for violations (Sections 19 and 21).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-posting-of-workers-enforcement-directive-2014-67",
      "de-works-constitution-act-betrvg"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-nationality-act-stag",
    "title": "Nationality Act (Staatsangehoerigkeitsgesetz - StAG)",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act governs the acquisition and loss of German nationality. A child acquires German nationality by birth where one parent holds it, and a child of foreign parents born in Germany acquires it where one parent has been legally ordinarily resident in Germany for at least five years and holds an appropriate residence status (Section 4). Foreign nationals may be naturalised at the authority discretion where their identity and nationality are clarified and conditions on criminal record, housing and self-support are met (Section 8). A foreigner with five years lawful ordinary residence is entitled to naturalisation on application where the requirements are met, including a commitment to the free democratic constitutional order, German language proficiency at B1 level and knowledge of the legal and social order (Section 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "germany-residence-act-aufenthaltsgesetz-2004-bamf",
      "eu-long-term-residents-directive-2003-109-ec"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-netzdg-2017",
    "title": "Germany Network Enforcement Act 2017 (NetzDG)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Germany's Netzwerkdurchsetzungsgesetz (NetzDG) effective January 1, 2018 requires social network operators with more than 2 million registered users in Germany to establish accessible complaint procedures for manifestly unlawful content, remove obviously illegal content within 24 hours or non-obvious illegal content within 7 days, and submit bi-annual transparency reports, with BfJ fines up to EUR 50 million for systemic failures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/de-netzdg-2017.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-occupational-safety-health-act-arbschg",
    "title": "Occupational Safety and Health Act (Arbeitsschutzgesetz - ArbSchG)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act implements the EU framework directive on occupational safety and health and sets the basic obligations of employers to safeguard the safety and health of workers at work. The employer has a duty to take the necessary measures of occupational safety and health, taking account of the circumstances that affect the safety and health of workers (Section 3), applying general principles of prevention (Section 4). The employer must assess the conditions of work to determine the necessary measures (Section 5), document the outcome of the risk assessment and the measures taken (Section 6), take account of the workers capabilities when assigning tasks (Section 7), and give workers sufficient and appropriate instruction on safety and health during working hours (Section 12).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-health-safety-framework-directive-89-391",
      "eu-pregnant-workers-health-safety-directive-92-85"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-product-liability-act-prodhaftg",
    "title": "Act on Liability for Defective Products (Produkthaftungsgesetz - ProdHaftG)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act imposes strict liability on the producer of a defective product for death, personal injury or damage to private-use property caused by the defect (Section 1). It defines product, defect and producer (Sections 2 to 4), provides for joint and several liability of multiple parties (Section 5), and reduces or excludes liability in defined cases such as contributory fault (Sections 1 and 6). The extent of liability is set for death and bodily injury (Sections 7 and 8), with a maximum aggregate liability of 85 million euros for personal injuries caused by identical products with the same defect (Section 10) and a self-participation of 500 euros for damage to property (Section 11). The Act is mandatory and cannot be excluded in advance (Section 14).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-product-liability-directive-2024-2853",
      "eu-general-product-safety-regulation-2023-988"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-road-traffic-act-stvg",
    "title": "Road Traffic Act (Strassenverkehrsgesetz - StVG)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act governs the use of motor vehicles on public roads and the civil liability arising from their operation. It imposes liability on the keeper of a vehicle (Fahrzeughalter) for death, personal injury or property damage caused by the operation of the vehicle, including in cases of unauthorised use (Section 7), subject to exceptions (Section 8) and rules on contributory negligence (Section 9). It sets the extent of liability for damages in the case of death and bodily injury (Sections 10 and 11), maximum amounts of compensation including for the carriage of dangerous goods (Sections 12 and 12a), the driver liability (Section 18) and liability where trailers and combination vehicles are involved (Sections 19 and 19a).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "germany-autonomous-driving-law-2021-stvaendg",
      "de-stvzo-strassenverkehrs-zulassungs-ordnung"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-sgb-viii-kinder-jugendhilfe-child-youth-services",
    "title": "Sozialgesetzbuch (SGB) - Achtes Buch (VIII) - Kinder- und Jugendhilfe - Schutz von Kindern und Jugendlichen in Einrichtungen",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations operating child and youth care facilities must obtain an operating permit, comply with on-site and records-based inspections, and adhere to reporting, documentation, and record-keeping obligations to ensure child welfare.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "de-stgb-184a-gewalt-tierpornographische-inhalte",
    "title": "Germany StGB Section 184a - Distribution of Violence and Bestiality Pornographic Content",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "Section 184a of the German Strafgesetzbuch (StGB; Criminal Code) prohibits the distribution, public dissemination and supply-chain handling of pornographic content depicting violence or sexual acts involving animals (gewaltpornographische und tierpornographische Inhalte). The provision punishes with imprisonment up to three years or a monetary fine (Freiheitsstrafe bis zu drei Jahren oder Geldstrafe) any person who distributes such content, makes it publicly accessible, manufactures, obtains, supplies, stockpiles, offers, advertises or attempts to import or export it with intent to distribute or enable others' use. Attempted distribution under the first variant is criminalised. Section 184a sits alongside StGB Section 184 (general distribution of pornographic content with focus on protection of minors), Section 184b (kinderpornographische Inhalte - child sexual abuse material), Section 184c (jugendpornographische Inhalte - youth pornography depicting persons aged 14 to 18) and Section 184d (online distribution and accessibility offences) within the German Criminal Code's framework for sexual content offences. Enforcement is by the public prosecutor's office (Staatsanwaltschaft) and Federal Criminal Police Office (Bundeskriminalamt, BKA) with technical support from the Federal Office for Information Security (BSI) for digital evidence. Section 184a is the operational anchor that German prosecutors cite for criminal liability of platform operators, hosts and individual distributors of violence pornography and bestiality content; platform takedown duties under the German NetzDG (Netzwerkdurchsetzungsgesetz) and the EU Digital Services Act overlay this criminal provision with platform safety duties. The provision applies to online and offline distribution with extraterritorial reach where the criminal act has effect in Germany (Section 9 StGB).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "criminal_code_neighbouring_anchors",
        "platform_takedown_duty_overlay",
        "jugendmedienschutz_overlay",
        "industry_mapping",
        "enforcement_anchors",
        "extraterritorial_reach",
        "dsa_intersection"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-jugendschutzgesetz-juschg-stgb-184-restricted-content-bzkj",
      "dsa-regulation-article-16-notice-action-mechanisms-hosting-providers",
      "de-netzdg-2017"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "de-stgb-184b-kinderpornographische-inhalte",
    "title": "Germany StGB Section 184b - Distribution, Acquisition and Possession of Child Sexual Abuse Material (Kinderpornographische Inhalte)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "Section 184b of the German Strafgesetzbuch (StGB; Criminal Code) prohibits the distribution, public dissemination, manufacture, supply-chain handling, acquisition and possession of child sexual abuse material (kinderpornographische Inhalte) depicting sexual acts of, on or before a person under fourteen years of age, or sexually suggestive depictions of unclothed minors under fourteen. The standard offence (distribution, supply chain, manufacture of realistic depictions) is punished by imprisonment from six months to ten years (Freiheitsstrafe von sechs Monaten bis zu zehn Jahren). Non-realistic depictions (clearly fictional, drawn or computer-generated content not depicting an actual child) carry imprisonment of three months to five years. Aggravated cases of commercial operation or organised criminal association with realistic content carry minimum two years imprisonment as a Verbrechen (felony). Possession of realistic content is punished by imprisonment of three months to five years. Section 184b includes exemptions for legitimate government activities, official duties and lawful law enforcement investigations (Section 184b paragraph 5). The provision is the operational anchor for criminal liability of platform operators, hosts, individual users and supply-chain actors handling CSAM in Germany and underpins parallel administrative enforcement under JMStV by KJM and BzKJ, takedown duties under NetzDG and EU Digital Services Act, and reporting duties to the BKA. Section 184b is enforced extraterritorially under Section 9 StGB for acts having effect in Germany including online distribution accessible from German territory; foreign-established platforms face mutual legal assistance, European Arrest Warrant and joint investigation team mechanisms. Section 184b is the criminal-law baseline above which all hashed-match CSAM detection, NCMEC reporting equivalents and EU CSA Regulation duties layer.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "criminal_code_neighbouring_anchors",
        "platform_takedown_duty_overlay",
        "jugendmedienschutz_overlay",
        "industry_mapping",
        "enforcement_anchors",
        "extraterritorial_reach",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-jugendschutzgesetz-juschg-stgb-184-restricted-content-bzkj",
      "de-stgb-184a-gewalt-tierpornographische-inhalte",
      "dsa-regulation-article-16-notice-action-mechanisms-hosting-providers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "de-stgb-184c-jugendpornographische-inhalte",
    "title": "Germany StGB Section 184c - Distribution, Acquisition and Possession of Youth Pornographic Content (Persons Aged 14 to 18)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "Section 184c of the German Strafgesetzbuch (StGB; Criminal Code) prohibits the distribution, public dissemination, manufacture, supply-chain handling, acquisition and possession of youth pornographic content (jugendpornographische Inhalte) depicting sexual acts of, on, or before persons aged fourteen but not yet eighteen years, or sexually suggestive depictions of such minors. Material qualifies where it depicts sexuelle Handlungen von, an oder vor einer vierzehn, aber noch nicht achtzehn Jahre alten Person or comparable suggestive depictions. The standard offence is punished by imprisonment up to three years or a monetary fine (Freiheitsstrafe bis zu drei Jahren oder Geldstrafe); aggravated commercial or organised cases with realistic depictions carry imprisonment of three months to five years. Possession or retrieval (Besitz oder Abruf) of realistic content carries up to two years imprisonment or a fine. Section 184c includes exemptions for legitimate official duties and lawful investigations and contains a narrow self-creation exemption (paragraph 4) for content depicting the producer's own person where no third party is involved and where the content is not distributed beyond the depicted person's consent. Section 184c sits between Section 184b (kinderpornographische Inhalte, persons under fourteen) and Section 184 (general pornographic content protection of minors), distinguished by the 14-to-18 age cohort. Enforcement is by public prosecutor's offices, the BKA Zentralstelle fuer Kinderpornographie im Internet (ZSK) which also covers Section 184c cases, the Landeskriminalaemter, and parallel administrative enforcement by BzKJ and KJM under the JMStV. Platform takedown duties under NetzDG and EU Digital Services Act overlay the criminal provision. Section 184c is the criminal anchor for liability over peer-generated sexting content (where third parties are implicated), youth-onlyfans-style monetisation, and synthetic AI-generated content depicting persons in the 14 to 18 cohort, an increasingly common detection challenge.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "criminal_code_neighbouring_anchors",
        "self_creation_exemption_paragraph_4",
        "platform_takedown_duty_overlay",
        "jugendmedienschutz_overlay",
        "industry_mapping",
        "enforcement_anchors",
        "extraterritorial_reach_and_eu_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-stgb-184b-kinderpornographische-inhalte",
      "de-jugendschutzgesetz-juschg-stgb-184-restricted-content-bzkj",
      "dsa-regulation-article-16-notice-action-mechanisms-hosting-providers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "de-strafgesetzbuch-section-184b-distribution-csam",
    "title": "Germany Strafgesetzbuch (StGB) Section 184b - Distribution, Acquisition, and Possession of Child Pornographic Content",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 184b of the German Strafgesetzbuch (StGB - Criminal Code) criminalises the distribution, public availability, production, importation, exportation, acquisition, and possession of child pornographic content (kinderpornografischer Inhalt). Section 184b(1) imposes imprisonment from 6 months to 10 years for distribution and production-for-distribution offences. Section 184b(2) (commercial or gang aggravation) imposes imprisonment of not less than 2 years. Section 184b(3) imposes imprisonment from 3 months to 5 years for acquisition and possession. Section 184b(4) governs attempt liability for the listed numbered offences. Section 184b(5) provides an exception for law enforcement and other lawful official duties. 'Child pornographic content' is defined by reference to children under 14. Section 184c covers youth pornographic content (involving persons 14-17). Section 184b is the centerpiece of German CSAM criminal law and operates alongside Sections 176-176e (sexual abuse of children) and Section 184 (general distribution of pornographic content).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1_distribution_production_etc",
        "subsection_2_commercial_or_gang_aggravated",
        "subsection_3_acquisition_possession_realistic_content",
        "subsection_4_attempt_liability",
        "subsection_5_official_duties_exception",
        "definition_child_pornographic_content_under_14",
        "extraterritorial_jurisdiction_section_5_no_6",
        "interaction_with_section_184c_youth_pornographic_content_14_17",
        "interaction_with_section_176_sexual_abuse_of_children",
        "interaction_with_eu_directive_2011_93_transposition"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-directive-2011-93-article-5-offences-concerning-child-pornography",
      "de-netzdg-2017"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "de-stvzo-strassenverkehrs-zulassungs-ordnung",
    "title": "Germany Straßenverkehrs-Zulassungs-Ordnung (StVZO) - Vehicle Registration Type Approval Construction and Technical Inspection",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-29",
    "bluf": "The Straßenverkehrs-Zulassungs-Ordnung (StVZO) is the German federal road vehicle registration ordinance issued under the Straßenverkehrsgesetz (StVG) covering registration of motor vehicles and trailers under §§ 16 to 17, operating permits and type approval under §§ 19 to 22a including recognition of EU and international approvals under §§ 21a and 21b, technical construction and operating requirements under §§ 29 to 62, and the Hauptuntersuchung periodic technical inspection regime under § 29. The Bundesministerium für Digitales und Verkehr is the issuing authority and the Kraftfahrt-Bundesamt operates as the federal motor transport authority responsible for type approval recognition and central registration in Germany.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-type-approval-regulation-2018-858",
      "un-regulation-155-vehicle-cybersecurity",
      "un-regulation-156-software-updates-ota"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "de-telekommunikationsgesetz-tkg-2021",
    "title": "Telekommunikationsgesetz (TKG) vom 23. Juni 2021: Zweck und Anwendungsbereich, Marktregulierung, Frequenzzuteilung and Right to Supply of Telecommunications Services",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Telekommunikationsgesetz (TKG) of 23 June 2021 is the German federal statute that transposes the European Electronic Communications Code into national law and regulates the German telecommunications sector. Section 1 (Zweck des Gesetzes, Anwendungsbereich) states the purpose of the Act, which is to promote competition in the field of telecommunications through technology-neutral regulation, to ensure efficient infrastructure and to safeguard the interests of end-users, and fixes the scope of the Act. Part 2 (Teil 2 - Marktregulierung) sets out the market regulation framework administered by the Bundesnetzagentur, including market definition, market analysis, the designation of undertakings with significant market power and the imposition of access and price-control obligations. Part 6 (Teil 6 - Frequenzordnung) governs the spectrum order, and Section 91 (Frequenzzuteilung) provides that every use of a frequency requires a prior frequency assignment unless the Act provides otherwise. Section 156 (Recht auf Versorgung mit Telekommunikationsdiensten) establishes an end-user right to the supply of telecommunications services against undertakings designated by the Bundesnetzagentur, securing affordable access to an adequate internet access service and voice communications service at a fixed location, including a minimum quality of service. The TKG is the central regulatory instrument for licensing-equivalent authorisation, market regulation, spectrum management and universal service in Germany.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "de-trade-secrets-act-geschgehg",
    "title": "Act on the Protection of Trade Secrets (Gesetz zum Schutz von Geschaeftsgeheimnissen - GeschGehG)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act transposes the EU Trade Secrets Directive into German law and protects trade secrets against unlawful acquisition, use and disclosure (Section 1). It defines a trade secret, the holder and the infringer (Section 2), sets out permissible acts including reverse engineering and whistleblowing exceptions (Sections 3 and 5), and prohibits the unlawful acquisition, use or disclosure of a trade secret (Section 4). It grants civil claims for elimination and injunctive relief, destruction and recall, information and damages (Sections 6 to 11), provides for confidentiality in trade-secret litigation (Sections 16 to 20), and makes the breach of trade secrets a criminal offence punishable by imprisonment of up to three years or a fine (Section 23).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-trade-secrets-directive-2016-943",
      "de-uwg-gesetz-gegen-unlauteren-wettbewerb"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-ttdsg-2021",
    "title": "Germany Telecommunications and Telemedia Data Protection Act 2021 (TTDSG)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Germany's Telekommunikation-Telemedien-Datenschutz-Gesetz (TTDSG) effective December 1, 2021 consolidates telecommunications data protection rules from the Telekommunikationsgesetz and Telemediengesetz into a single statute, implementing the ePrivacy Directive requirement that cookie consent must be freely given and prohibiting use of tracking technologies in telecommunications services without subscriber consent, with BNetzA enforcement for telecommunications violations and state DPA enforcement for telemedia violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/de-ttdsg-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-bdsg-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "de-uwg-gesetz-gegen-unlauteren-wettbewerb",
    "title": "Germany Gesetz gegen den unlauteren Wettbewerb (UWG - Act against Unfair Competition)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Gesetz gegen den unlauteren Wettbewerb (UWG) is Germany's principal unfair competition statute, originally enacted on 3 July 2004 (Bundesgesetzblatt I S. 1414), recast on 2 December 2015 and last materially amended by the Gesetz zur Starkung des Verbraucherschutzes im Wettbewerbsrecht in 2022 to implement EU Omnibus Directive 2019/2161/EU. The UWG transposes EU Directive 2005/29/EC Unfair Commercial Practices (UCPD) and EU Directive 2006/114/EC misleading and comparative advertising. The Act is organised in four Kapitel. Kapitel 1 (§§1-7a) contains general provisions: §1 (purpose - dual protection of competitors, consumers and other market participants and the public interest in undistorted competition), §2 (definitions including geschaftliche Handlung, Marktteilnehmer, Mitbewerber and geschaftliche Entscheidung), §3 (general clause against unfair commercial practices and Anhang blacklist), §3a (Rechtsbruch - breach of statutory provision regulating market conduct), §4 (specific Mitbewerberschutz: disparagement, denigration, slavish imitation, targeted obstruction), §4a (aggressive commercial practices), §5 (misleading commercial practices - Irrefuhrung), §5a (misleading by omission), §5b (essential information for invitations to purchase including consumer reviews and personalised prices), §5c (Influencer disclosure of commercial purpose), §7 (unzumutbare Belastigungen including spam, unsolicited cold-calling, no-reply marketing email), §7a (consent records for telephone marketing). Kapitel 2 (§§8-11) sets civil law consequences: §8 (cease-and-desist and removal claims with active legitimation for Mitbewerber, qualifizierte Wirtschaftsverbande and Verbraucherzentralen), §9 (damages), §10 (Gewinnabschopfung - skimming of profits in favour of the federal budget), §11 (Verjahrung - 6-month limitation). Kapitel 3 (§§12-15a) procedural rules including Abmahnung and einstweilige Verfugung. Kapitel 4 (§§16-20) criminal and administrative penalties for misleading advertising, geheime Provisionen and trade secret betrayal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-gwb-competition-act",
      "eu-unfair-commercial-practices-2005-29-2022-revision",
      "fr-code-consommation"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "de-wissenschaftszeitvertragsgesetz-academic-fixed-term",
    "title": "Gesetz über befristete Arbeitsverträge in der Wissenschaft (WissZeitVG)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This act establishes the legal framework, duration limits, and specific conditions for fixed-term employment contracts for academic and artistic staff at German universities and research institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "de-works-constitution-act-betrvg",
    "title": "Works Constitution Act (Betriebsverfassungsgesetz - BetrVG)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Act governs the constitution of the workforce and the rights of works councils in German establishments. Works councils are elected in all establishments that normally have five or more permanent employees with voting rights (Section 1), with the number of members determined by the size of the workforce (Section 9). The Act sets the status of trade unions and employers associations (Section 2), defines employees (Section 5), and establishes principles of trustful collaboration between employer and works council (Section 74), principles for the treatment of persons employed (Section 75), the conciliation committee for resolving disputes (Section 76), the execution of works agreements (Section 77) and protective provisions for works council members (Section 78).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-works-council-directive-2009-38",
      "eu-transfer-of-undertakings-directive-2001-23"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "delaware-corporate-law-basics",
    "title": "Delaware Corporate Law",
    "domain": "Legal & IP Sovereignty",
    "version": "1.2.0",
    "last_updated": "2026-07-03",
    "bluf": "Delaware General Corporation Law (DGCL) is the leading U.S. corporate law, chosen by over 60% of Fortune 500 companies. It is defined by its enabling nature and the expertise of the Delaware Court of Chancery, which has developed a stable and predictable body of case law centered on the fiduciary duties of corporate directors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "sarbanes-oxley-act-sox",
      "fcpa-anti-bribery-compliance",
      "dtsa-trade-secret-protection",
      "sox-it-controls"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "denmark-gambling-act-2012-spillemyndigheden",
    "title": "Denmark Gambling Act (Act on Gambling) - Spillemyndigheden Licensing and Player Protection",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "The Danish Act on Gambling, in force from 1 January 2012, liberalised the Danish gambling market and requires operators of betting (Section 11) and online casinos (Section 18) to hold a licence granted by Spillemyndigheden, the regulatory authority (Section 4). Operators must restrict gambling to persons aged 18 and over (Sections 15 and 34), must not extend credit to players (Section 35), must comply with marketing restrictions (Section 36), must make game information accessible to players and authorities (Section 33), and are subject to regulatory supervision (Section 46). Players may self-exclude through the national ROFUS register administered by Spillemyndigheden.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sweden-gambling-act-2018-spelinspektionen",
      "eu-5amld-article-2-gambling-2018",
      "eu-gdpr-online-gaming-data-protection",
      "malta-gaming-authority-mga-regulations-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "denmark-space-activities-act-2016",
    "title": "Denmark Space Activities Act 2016 - Lov nr. 1400 af 27. November 2016 om Rumaktiviteter",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Danish Space Activities Act (Lov om rumaktiviteter, Lov nr. 1400 af 27. november 2016) establishes Denmark's national legal framework for the licensing, supervision, and registration of space activities conducted by entities under Danish jurisdiction. The Act designates the Danish Business Authority (Erhvervsstyrelsen) as the competent authority for licensing and national oversight of space operations. The law implements Denmark's obligations under the UN Outer Space Treaty 1967, the Liability Convention 1972, and the Registration Convention 1976 as an ESA Member State. The Act requires prior authorisation for space launches and in-orbit operations by Danish entities, mandates liability insurance or financial security, establishes a national space object register, and provides for ongoing supervision. Denmark hosts significant space sector activity including the Technical University of Denmark (DTU Space) and GomSpace (nanosatellite manufacturer in Aalborg).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "un_outer_space_treaty_1967",
        "esa_framework",
        "eu_space_programme"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "deterministic-lead-scoring-logic",
    "title": "Deterministic Lead Scoring Logic and Consent-Based Processing Governance",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "This logic establishes a compliant framework for evaluating individuals through auditable, rule-based processing. It mandates explicit consent for profiling (GDPR Art. 6(1)(a)), respects consumer opt-outs (CPRA Sec. 1798.140(z)), and prevents automated sole decision-making (GDPR Art. 22). Lead scores use a 0.4 demographic and 0.6 behavioral weight, requiring a minimum score of 75 for sales outreach. The data retention limit is 365 days with a 10-point decay per inactive month. Opt-outs and Do-Not-Contact lists always override the score.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "developing-security-plans-federal-systems",
    "title": "Guide for Developing Security Plans for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-02-01",
    "bluf": "The objective of system security planning is to improve the protection of information system resources. This guide provides an overview of the security requirements for a system and describes the controls, either in place or planned, for meeting those requirements. The completion of system security plans is a requirement under the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA), applicable to all federal systems which have some level of sensitivity and require protection. The system security plan delineates responsibilities and expected behavior of all individuals who access the system, and should reflect input from managers with system responsibilities, including information owners, the system owner, and the senior agency information security officer (SAISO).\n\nManagement authorization to operate a system is based on an assessment of management, operational, and technical controls, for which the system security plan forms the basis. By authorizing a system, a manager accepts its associated risk. This authorization must be periodically reviewed and re-authorization should occur whenever there is a significant change in processing, and at a minimum of every three years. The plan should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system and is a living document that requires periodic review and modification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "nist-sp-800-53-r5",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "dfars-7012-defense-cyber",
    "title": "DFARS 252.204-7012 (Cyber)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting) is the primary U.S. defense acquisition regulation for protecting CDI. It mandates the implementation of NIST SP 800-171 and requires rapid cyber incident reporting (within 72 hours) for all defense contractors handling sensitive military data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-cui",
      "cmmc-2-audit",
      "nist-800-61-incident-resp",
      "itar-compliance-workflow",
      "ear-dual-use-export"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dhs-ai-safety-security-board-guidance-2024",
    "title": "US Department of Homeland Security AI Safety and Security Board Guidance 2024 - Compliance Obligations for Critical Infrastructure AI Safety, AI Deployment Controls for National Security-Adjacent Systems, and DHS AI Risk Management",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations for AI safety in critical infrastructure and national security-adjacent systems under DHS guidance, aligning with EU AI Act 2024 high-risk system requirements (Article 6) and NIST AI RMF 1.0 risk management practices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dicom-imaging-standard",
    "title": "DICOM Imaging Standard",
    "domain": "Medical & Healthcare",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "DICOM (Digital Imaging and Communications in Medicine) is the international standard for medical imaging and related information. It specifies the network protocols for image exchange (PACS/RIS integration), the media format for storage (PS3.10), and the web services (WADO-RS) for image retrieval across the healthcare enterprise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "iso-27799-health-info-sec",
      "hl7-fhir-v4-interop",
      "iso-13485-medical-qms",
      "nist-sp-1800-24-securing-pacs",
      "gdpr-health-data"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dicom-medical-imaging",
    "title": "DICOM (Medical Imaging)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with the ISO 12052:2017 standard for medical imaging necessitates a robust security posture, mandating specific technical controls for handling DICOM objects. This configuration enforces secure transport channels through the mandatory use of TLS, with a minimum accepted protocol version of 1.2, thereby satisfying a core tenet of the HIPAA Security Rule at 45 CFR § 164.312. Node-to-node communications must be authenticated using X.509 certificates, a principle outlined in the IHE IT Infrastructure Technical Framework's ATNA Profile. To ensure data integrity and non-repudiation, the node requires digital signatures for objects, supported by a minimum RSA key length of 2048 bits, as specified within NEMA PS3.15. Comprehensive audit trails are enforced, capturing security-relevant events consistent with this DICOM security profile. For data protection, all electronic protected health information stored at rest must utilize AES-256-GCM encryption. Furthermore, the node enables de-identification of protected health information based on the Basic Application Level Confidentiality Profile's Appendix E. Operational controls include strict validation of Service-Object Pair (SOP) Class UIDs per the data structures defined in NEMA PS3.5, blocking unencrypted Implicit VR Little Endian transfers over a Wide Area Network, and terminating any inactive network association after a maximum idle timeout of 60 seconds. These collective measures ensure that Information Object Definitions from NEMA PS3.3 are managed securely throughout their lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "iso-27799-health-info-sec",
      "nist-sp-1800-24-securing-pacs",
      "nist-sp-800-52r2-tls-guidelines"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "difc-employment-law-4-2021",
    "title": "DIFC Employment Law No. 4 of 2021 - Employment Contract Requirements, Termination Notice Periods, Anti-Discrimination Provisions, DEWS End-of-Service Benefits Scheme and DIFC Courts Jurisdiction",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This law governs employment relationships within the Dubai International Financial Centre (DIFC), mandating written employment contracts (Article 14), establishing minimum termination notice periods (Article 62), prohibiting discrimination on specified protected characteristics (Article 58), and requiring employer contributions to the DIFC Employee Workplace Savings (DEWS) scheme for end-of-service benefits (Part 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "uk-equality-act-2010",
      "iso-26000-social-resp-mgt"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "digital-operational-resilience-act-dora--compliance-2026-0",
    "title": "Digital Operational Resilience Act (DORA) Enterprise Compliance Standard v0",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The Digital Operational Resilience Act (DORA) establishes a comprehensive framework for the management of ICT risks within the financial sector. It mandates that financial entities develop, implement, and maintain robust operational resilience strategies to withstand, respond to, and recover from ICT-related disruptions. Key requirements include conducting regular risk assessments, ensuring the security of ICT systems, and establishing incident reporting mechanisms. DORA also emphasizes the importance of third-party risk management, requiring entities to assess and monitor the resilience of their critical service providers. Compliance with DORA is essential for safeguarding the stability of the financial system and protecting consumers from the adverse effects of operational failures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "digital-operational-resilience-act-dora--compliance-2026-15",
    "title": "Digital Operational Resilience Act (DORA) Enterprise Compliance Standard v15",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The Digital Operational Resilience Act (DORA) establishes a comprehensive framework to ensure that financial entities within the EU can withstand, respond to, and recover from all types of ICT-related disruptions and threats. It mandates that firms implement robust risk management practices, conduct regular testing of their operational resilience, and maintain effective incident reporting mechanisms. DORA also emphasizes the importance of third-party risk management, requiring firms to assess and monitor the risks posed by their ICT service providers. Compliance with DORA is essential for safeguarding the integrity of the financial system and enhancing the overall cybersecurity posture of financial institutions across the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "digital-therapeutics-dtx-framework-2026",
    "title": "Digital Therapeutics (DTx) - US FDA Software as a Medical Device (SaMD) Regulatory Pathway, Quality System and Post-Market Surveillance",
    "domain": "Medical & Healthcare",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "There is no single binding instrument titled the 'Digital Therapeutics (DTx) Regulatory Framework - FDA, EMA and Global Convergence 2026'. Prescription digital therapeutics are regulated in the United States as Software as a Medical Device (SaMD) / medical devices by the U.S. Food and Drug Administration (FDA) under the Federal Food, Drug, and Cosmetic Act and FDA device regulations (including 21 CFR Part 820 Quality System Regulation and 21 CFR Part 11 electronic records), with clinical evaluation informed by the IMDRF SaMD framework and, for software functions, FDA digital health guidance. The Digital Therapeutics Alliance (DTA) is a non-profit industry association (merged into ATA Action in 2025), not a regulator or standards body issuing binding rules. This node summarises the FDA SaMD regulatory pathway, quality-system obligations, post-market surveillance and reimbursement considerations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "digital-therapeutics-dtx-regulation-2026",
    "title": "Digital Therapeutics (DTx) - Regulatory Classification & Market Access (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Digital Therapeutics are software-driven interventions that deliver evidence-based therapeutic treatments for medical conditions. They are regulated as medical devices (often SaMD) in most jurisdictions, requiring clinical evidence of safety and efficacy, quality management systems, cybersecurity, and post-market surveillance. Reimbursement pathways (FDA Breakthrough, German DiGA, etc.) increasingly require real-world evidence and health economic data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "digital-twin-fidelity",
    "title": "Digital Twin Fidelity Audit",
    "domain": "Industrial IoT & Energy",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Digital twin fidelity refers to the degree of accuracy with which a virtual model replicates the real-time state, behavior, and physical properties of its physical counterpart, encompassing sensor data synchronization latency, physics simulation accuracy, historical data concordance, and predictive model calibration. NIST defines digital twin as a 'virtual representation of a real-world entity or process' (NIST IR 8356), and fidelity auditing ensures the twin remains trustworthy for decision-making in industrial operations, predictive maintenance, process optimization, and safety monitoring. Low-fidelity twins produce incorrect predictions, missed maintenance events, and dangerous process control decisions. Digital twin fidelity standards draw from ISO 23247 (Digital Twin for Manufacturing), IEC 61360 (data element specifications), and IEC 62443 (ICS security for connected twins).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-50001-energy",
      "nerc-cip-v6-cyber",
      "nist-sp-800-82r3-ot-security",
      "nistir-7628-smartgrid"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dj-pdp-law-2020",
    "title": "Djibouti Law No. 108/AN/20 on Personal Data Protection",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Djibouti enacted Law No. 108/AN/20/8ème L on Personal Data Protection in 2020, establishing the first comprehensive data protection framework in the country. The law is administered by the Commission Nationale de l'Informatique et des Libertés (CNIL Djibouti). It establishes principles for lawful processing of personal data, requires data controllers to obtain consent from data subjects before collecting personal data, grants data subjects rights of access, rectification, and erasure, mandates security safeguards, and restricts cross-border transfers to jurisdictions with adequate protection. Data controllers must register with the CNIL before commencing processing. The law aligns with the African Union Malabo Convention and draws on francophone data protection traditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/dj-pdp-law-2020.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dk-databeskyttelsesloven-2018",
    "title": "Denmark Data Protection Act 2018 (Databeskyttelsesloven) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Denmark's Data Protection Act (Databeskyttelsesloven, Consolidated Act No. 502 of 23 May 2018, as amended by Act No. 1052 of 28 August 2018) is Denmark's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Denmark. The GDPR is directly applicable Danish law by virtue of Denmark's EU membership. The Databeskyttelsesloven provides the national derogations, additions, and specifications that the GDPR permits EU member states to adopt. Enforcement: Datatilsynet (the Danish Data Protection Agency) is Denmark's independent data protection supervisory authority. Datatilsynet is Denmark's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Danish national provisions: (1) Age of digital consent: Denmark has lowered the GDPR default age of 16 years - the age of consent for information society services in Denmark is 13 years; data subjects under 13 require parental or guardian consent for information society services; (2) CPR number (Det Centrale Personregister - Central Personal Register number): the Danish CPR number is a unique 10-digit civil registration number assigned to every person registered in Denmark; processing of CPR numbers is subject to special restrictions under the Databeskyttelsesloven - CPR numbers may only be processed where permitted by law, where the data subject has consented, or where the processing is for clearly legitimate purposes that outweigh the interests of the data subject; registration with a sector-specific authority may be required; CPR numbers are equivalent to a national identification number and require heightened protection; (3) Criminal data: restrictions on processing personal data relating to criminal convictions and offences by private entities; (4) Employment context: Danish data protection law interacts with Danish employment legislation including the Salaried Employees Act (Funktionærloven) and collective agreements; (5) Freedom of expression: Danish constitutional protections for freedom of expression and press freedom under the Danish Constitution (Grundloven) and the Danish Media Liability Act (Medieansvarslov) create exemptions for journalistic, artistic, and literary processing; (6) Public sector: significant provisions on processing by public authorities, including the Public Administration Act (Forvaltningsloven) and the Access to Public Administration Files Act (Offentlighedsloven); (7) Research and statistics: specific provisions permitting extended processing for scientific research, statistics, and archiving in the public interest. Fines: GDPR administrative fines apply in Denmark - up to EUR 20 million or 4% of global annual turnover for the most serious violations. Datatilsynet has imposed significant GDPR fines and issued enforcement guidance across multiple sectors. Datatilsynet publishes annual statistics on breach notifications, enforcement actions, and guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dm-dpa-2018",
    "title": "Dominica Data Protection Act 2018",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Dominica enacted the Data Protection Act 2018, a comprehensive statute aligned with CARICOM and OECS data protection standards. The Act is administered by the Data Protection Commissioner and establishes principles governing the collection, use, storage, and disclosure of personal data. Data subjects have rights of access and correction. Sensitive personal information categories (health, political opinions, religious beliefs, racial origin, criminal history) are subject to heightened protection and explicit consent requirements. Cross-border transfers require adequate protection or appropriate safeguards. The Act applies to controllers established in Dominica and those processing personal data of persons in Dominica.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/dm-dpa-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dma-regulation-article-10-notification-and-designation-procedure",
    "title": "Regulation (EU) 2022/1925 of the European Parliament and of the Council - Article 10: Exemption for grounds of public health and public security",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes a procedure for gatekeepers to request, or for the Commission to grant on its own initiative, a temporary exemption from specific obligations on the grounds of public health or public security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dma-regulation-article-13-obligations-potential-gatekeepers",
    "title": "Regulation (EU) 2022/1925 of the European Parliament and of the Council - Article 13: Anti-circumvention",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires gatekeepers to prevent circumvention of their obligations under Articles 5, 6, and 7, prohibiting practices like service fragmentation, undermining compliance through design, or degrading services for users exercising their rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dma-regulation-article-14-market-investigations",
    "title": "Regulation (EU) 2022/1925 - Digital Markets Act - Article 14: Obligation to inform about concentrations",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Gatekeepers must inform the European Commission of any intended concentration where the involved entities provide core platform services or other digital sector services, regardless of standard notification thresholds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dma-regulation-article-17-non-compliance-decisions",
    "title": "Regulation (EU) 2022/1925 of the European Parliament and of the Council - Article 17: Market investigation for designating gatekeepers",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article outlines the process, timelines, and procedures for the Commission to conduct a market investigation to determine if an undertaking should be designated as a gatekeeper.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dma-regulation-article-2-definitions",
    "title": "Regulation (EU) 2022/1925 (Digital Markets Act) - Article 2: Definitions",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article defines the term 'gatekeeper' and clarifies the regulation's scope in relation to other EU directives, national competition laws, and the powers of Member States and national authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "dma-regulation-article-22-interim-measures",
    "title": "REGULATION (EU) 2022/1925 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act) - Article 22: Interim measures",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article empowers the Commission to order interim measures against a gatekeeper in urgent cases to prevent serious and irreparable damage to users, and outlines the procedural requirements for such an order.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dma-regulation-article-26-access-to-data-evidence",
    "title": "REGULATION (EU) 2022/1925 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act) - Article 26",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article empowers the Commission to request information and access to data, algorithms, and premises from undertakings to verify compliance with the regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dma-regulation-article-28-compliance-officer-function",
    "title": "REGULATION (EU) 2022/1925 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act) - Article 28",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "The provided regulatory text does not contain Article 28, so the specific obligations for the compliance officer function could not be extracted and are represented as processing failures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dma-regulation-article-3-designation-as-gatekeeper",
    "title": "Regulation (EU) 2022/1925 on contestable and fair markets in the digital sector (Digital Markets Act) - Article 3",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must determine if their services qualify as 'core platform services' by assessing them against the specific definitions provided for services such as online search engines, social networking, and cloud computing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dma-regulation-article-30-fines",
    "title": "REGULATION (EU) 2022/1925 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act) - Article 30",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This regulation addresses unfair practices and weak contestability of core platform services provided by large undertakings designated as gatekeepers to ensure fair economic outcomes in the digital sector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "dma-regulation-article-33-periodic-penalty-payments",
    "title": "REGULATION (EU) 2022/1925 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act) - Article 33",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article's core compliance obligation concerning the imposition and calculation of periodic penalty payments for non-compliance cannot be extracted as the provided regulatory text does not contain Article 33.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "dma-regulation-article-35-remedies-effective-competition",
    "title": "REGULATION (EU) 2022/1925 on contestable and fair markets in the digital sector (Digital Markets Act) - Article 35: Remedies for failure to comply with certain obligations for gatekeepers",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article outlines the European Commission's authority to impose behavioural or structural remedies on a gatekeeper for non-compliance with specific obligations, detailing the conditions and procedures for such measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dma-regulation-article-38-cooperation-member-state-authorities",
    "title": "REGULATION (EU) 2022/1925 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act) - Article 38",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates the Commission and national competent authorities to cooperate closely and exchange information for the purpose of applying this Regulation effectively.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dma-regulation-article-5-obligations-gatekeepers-article5",
    "title": "Regulation (EU) 2022/1925 on contestable and fair markets in the digital sector (Digital Markets Act) - Article 5: Obligations for gatekeepers",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article prohibits gatekeepers from processing, combining, or cross-using end-user personal data across different services without obtaining explicit, GDPR-compliant user consent, and limits re-requesting consent to once per year after a refusal or withdrawal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dma-regulation-article-6-obligations-gatekeepers-article6",
    "title": "Regulation (EU) 2022/1925 on contestable and fair markets in the digital sector (Digital Markets Act) - Article 6: Obligations for gatekeepers susceptible of being further specified under Article 8",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires designated gatekeepers to comply with a specific set of obligations for each of their core platform services as listed in their designation decision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dma-regulation-article-7-updateable-gatekeeper-obligations",
    "title": "REGULATION (EU) 2022/1925 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act) - Article 7",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that designated gatekeepers must provide business users with access to data they generate, ensure interoperability with third-party services, and maintain transparency in advertising services to foster fair and contestable digital markets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dma-regulation-article-8-suspension-exemption-gatekeeper",
    "title": "REGULATION (EU) 2022/1925 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act) - Article 8",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the procedure for a gatekeeper to request a temporary suspension of specific obligations where its economic viability is threatened by exceptional circumstances, or an exemption on grounds of public morality, public security, or public health.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "dmca-safe-harbor",
    "title": "DMCA (Safe Harbor)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Qualification for liability limitations under the Digital Millennium Copyright Act safe harbor for information residing on systems at the direction of users necessitates strict adherence to several statutory conditions. Eligibility is predicated on satisfying requirements within 17 U.S.C. § 512(i), including the adoption and reasonable implementation of a published repeat infringer policy, under which subscriber accounts are terminated following a `3` strike threshold. Furthermore, the organization must accommodate standard technical measures. The platform qualifies for this safe harbor by ensuring it is a registered online service provider that does not receive a direct financial benefit attributable to infringing activity and lacks actual knowledge of it. A critical procedural component, mandated by 17 U.S.C. § 512(c)(2), is the designation of an active DMCA agent who is properly registered with the U.S. Copyright Office with publicly accessible contact information. Operationally, upon receipt of a takedown notice containing all statutory elements of notification outlined in 17 U.S.C. § 512(c)(3), the organization responds expeditiously to remove or disable access to specified material within a `72` hour service level agreement. Finally, pursuant to 17 U.S.C. § 512(g), the platform enables a compliant counter-notification process, mandating restoration of contested material in a window of not less than `10` but no more than `14` business days following receipt of a valid counter-notice, contingent upon the original complainant not filing for a court order.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-literary-artistic",
      "wipo-copyright-treaty",
      "copyright-fair-use-us",
      "eu-copyright-directive-art-17"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "do-178c-airborne-software-2011",
    "title": "RTCA DO-178C Software Considerations in Airborne Systems and Equipment Certification",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "DO-178C provides guidance for determining that airborne system software has an acceptable level of safety and integrity. It requires applicants for certification to follow a rigorous set of process objectives for software planning, development, verification, and configuration management, with the level of effort directly corresponding to the Software Level (A-E) assigned based on failure condition severity as defined in Section 2.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "faa-part-21-certification",
      "as9100-rev-d-qms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "do-ley-340-06-compras-y-contrataciones-amended-ley-47-20",
    "title": "Dominican Republic Ley 340-06 on Public Procurement of Goods, Services, Works and Concessions as amended by Ley 47-20 and DGCP portal",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Dominican Republic Ley 340-06 sobre Compras y Contrataciones de Bienes, Servicios, Obras y Concesiones (Law 340-06 on Procurement and Contracting of Goods, Services, Works and Concessions) promulgated 18 August 2006 as amended by Ley 449-06 of 6 December 2006 and substantially modernised by Ley 47-20 sobre Alianzas Publico-Privadas and the Reglamento de Aplicacion approved by Decreto 543-12 of 6 September 2012 is the principal Dominican procurement framework governing procurement of goods, services, works, and concessions by entities of the Public Administration including the Executive Branch (Poder Ejecutivo), the Legislative Branch (Poder Legislativo), the Judicial Branch (Poder Judicial), Autonomous and Decentralized Entities, municipalities (Ayuntamientos), public-sector enterprises, and other entities financed by the State budget. The Direccion General de Contrataciones Publicas (DGCP / dgcp.gob.do) under the Ministry of Finance (Ministerio de Hacienda) is the central regulatory authority responsible for procurement regulation, oversight, compliance monitoring, supplier debarment, and operation of the public procurement portal. The Portal Transaccional (transaccionales.comprasdominicana.gob.do) operated by DGCP is the mandatory federal transactional e-procurement platform for in-scope procurement. The Tribunal Superior Administrativo (TSA) handles judicial review of procurement decisions. Procurement methods established by Ley 340-06 art. 16 and Decreto 543-12 art. 9 to 38 comprise (a) Licitacion Publica Nacional o Internacional (Public Tender National or International, the default open public procedure for prescribed-value acquisitions), (b) Licitacion Restringida (Restricted Tender, with prequalification), (c) Sorteo de Obras (Public Works Lottery, for prescribed civil works), (d) Comparacion de Precios (Price Comparison, for medium-value acquisitions), (e) Compras Menores (Minor Procurement, for small-value acquisitions), (f) Compras por Debajo del Umbral Minimo (Below Minimum Threshold Procurement, for very low-value), (g) Procedimiento de Excepcion (Exception Procedure, sole-source under prescribed exceptions in art. 6), and (h) Subasta Inversa (Reverse Auction, for standardised products). The Camara de Cuentas (Chamber of Accounts) conducts ex-post procurement audit. The Dominican Republic is a party to the CAFTA-DR and operates within that procurement framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "do-pdpl-2013",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "do-pdpl-2013",
    "title": "Dominican Republic Law No. 172-13 on the Protection of Personal Data - ARCO Rights, Consent, Credit-Bureau Supervision and Distributed Oversight",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "Dominican Republic Law No. 172-13 on the comprehensive protection of personal data (enacted 13 December 2013) establishes a Latin American ARCO rights framework - access, rectification, cancellation and opposition - and requires a lawful basis, generally informed consent, for processing. There is no single dedicated national data-protection authority; oversight is distributed. The Superintendency of Banks (Superintendencia de Bancos) supervises and sanctions credit information bureaus (credit-data) under the law, and Pro Consumidor handles consumer-related data matters through conciliation without power to impose administrative fines. The Dominican Republic does not maintain a general registry of data controllers or databases; only credit bureaus register with the Superintendency of Banks. Organisations should map their obligations to these existing supervisors rather than to a single supervisory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dod-ai-ethics-principles-2020-responsible-ai",
    "title": "Department of Defense Artificial Intelligence Ethics Principles 2020 - Responsible, Equitable, Traceable, Reliable, and Governable AI",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The DoD AI Ethics Principles require all Department of Defense AI systems to adhere to five core ethical principles: responsible, equitable, traceable, reliable, and governable. These apply to all AI capabilities developed, acquired, or used by the DoD, particularly in operational contexts involving human-machine teaming and algorithmic decision support.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "anthropic-responsible-scaling-policy-v2-1-2025",
      "bletchley-declaration-ai-safety-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dodd-frank-volcker-rule",
    "title": "Volcker Rule (Prop Trading)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Volcker Rule (Section 619 of the Dodd-Frank Act) prohibits U.S. banking entities from engaging in proprietary trading or acquiring/sponsoring 'Covered Funds' (Hedge Funds or Private Equity). it is designed to separate commercial banking from high-risk investment activities, ensuring that deposit-taking institutions do not risk taxpayer-insured funds for their own gain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "doi-digital-object-id",
    "title": "DOI (Object ID)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Digital Object Identifier (DOI) validation enforces strict adherence to international standards for persistent and actionable identification of digital assets. Compliance with ISO 26324:2012 is mandatory, requiring a valid prefix/suffix structure where the prefix begins with the directory indicator `10`. Each full DOI string must utilize `enforce_utf8_encoding` and shall not exceed a `max_doi_length_bytes` of 2048. While the prefix designates the registrant, the system does `permit_opaque_suffix_strings`, allowing for flexible local identification schemes. The core functionality mandates that every identifier be resolvable through the Handle System framework described in IETF RFCs 3650, 3651, and 3652. This resolution process must complete within a `handle_resolution_timeout_ms` of 5000, and the target resolution endpoint must be secured via HTTPS. Per the IDF DOI Handbook, the node further stipulates that `require_persistent_metadata` be associated with each DOI, ensuring long-term context and utility consistent with the European Open Science Cloud (EOSC) PID Policy. To guarantee authenticity, the system will `verify_authority_source` for the registration agency. Furthermore, `enable_content_negotiation` is a required service capability, allowing clients to request specific data formats from the resolved resource, thereby enhancing interoperability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-literary-artistic",
      "wipo-copyright-treaty",
      "iso-16684-xmp-metadata",
      "iptc-photo-metadata"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dora-ai-ict-risk-management-2025",
    "title": "DORA ICT Risk Management Requirements Applied to AI Systems in Financial Entities - Compliance Obligations for EU Financial Sector AI Resilience, AI ICT Incident Reporting, and AI Third-Party Risk Under DORA Article 28",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This node outlines ICT risk management requirements for AI systems in EU financial entities under DORA Article 28, focusing on resilience, incident reporting, and third-party risk management. Key compliance actions include implementing robust risk frameworks and reporting mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dora-ict-risk",
    "title": "DORA - EU Digital Operational Resilience Act",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Regulation (EU) 2022/2554 (DORA - Digital Operational Resilience Act), published December 27, 2022 and directly applicable (no national transposition required) across all EU member states from January 17, 2025, establishes binding ICT risk management, incident reporting, resilience testing, and third-party risk oversight requirements for 20+ categories of EU financial entities. DORA applies to credit institutions, investment firms, payment institutions, e-money institutions, insurance/reinsurance undertakings, crypto-asset service providers (CASPs), central counterparties (CCPs), trade repositories, AIFMs, UCITS management companies, data reporting services providers, and more. Key obligations: (1) ICT risk management framework with governance, protection, detection, response, and recovery capabilities; (2) ICT-related incident classification and mandatory reporting - initial notification within 4 hours of classification as major incident, intermediate report within 72 hours, final report within 1 month; (3) Digital operational resilience testing including Threat-Led Penetration Testing (TLPT) every 3 years for significant entities; (4) ICT third-party risk management with contractual requirements for Critical ICT Third-Party Providers (CTPPs) who are directly supervised by an EU Lead Overseer (EBA, ESMA, or EIOPA depending on sector). DORA displaces NIS2 obligations for in-scope financial entities (lex specialis principle).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "eba-outsourcing-guide",
      "cpmi-iosco-cyber-resilience-fmi",
      "iso-22301-biz-continuity",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dora-ict-risk-management-articles-5-16",
    "title": "Digital Operational Resilience Act (DORA) - Chapter II: ICT Risk Management (Articles 5-16)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Requires EU financial entities to establish and maintain a comprehensive, well-documented ICT risk management framework, as mandated by Article 6. This framework, overseen by the management body (Article 5), must encompass strategies for identification, protection, detection, response, and recovery, including detailed policies for business continuity, disaster recovery, and incident management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "eba-outsourcing-guide",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dora-incident-reporting-articles-17-23",
    "title": "Regulation (EU) 2022/2554 (DORA) - ICT-Related Incident Management and Reporting (Articles 17-23)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Regulation (EU) 2022/2554 (DORA) requires financial entities to establish a comprehensive ICT-related incident management process, including detection, classification, and response. Per Articles 18 and 19, entities must classify all ICT-related incidents and report those deemed 'major' to their competent authority using a harmonized, multi-stage reporting timeline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "eba-outsourcing-guide",
      "cpmi-iosco-cyber-resilience-fmi",
      "pra-ss1-21-resilience"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dora-regulation-article-10-detection",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 10: Detection",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Financial entities must establish and maintain mechanisms to promptly detect anomalous activities, ICT-related incidents, and potential single points of failure, supported by multiple layers of control, defined alert thresholds, and sufficient monitoring resources.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dora-regulation-article-11-response-recovery",
    "title": "Digital Operational Resilience Act (DORA) - Article 11: Response and recovery",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Financial entities must establish and implement a comprehensive ICT business continuity policy and associated plans to ensure the continuity of critical functions and effectively respond to and recover from ICT-related incidents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dora-regulation-article-12-backup-policies-recovery-procedures",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 12",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the official definitions for key financial entities such as payment institutions, central counterparties, and trading venues, which must be used for classification and compliance purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "dora-regulation-article-13-learning-evolving",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, Article 13: Learning and evolving",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires financial entities to establish mechanisms for continuous learning from ICT incidents and technological developments, monitor their resilience strategy, conduct annual self-assessments, and establish a role for monitoring ICT third-party providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dora-regulation-article-14-communication",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 14: Communication",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Financial entities must establish and implement crisis communication plans and policies for disclosing major ICT-related incidents and vulnerabilities to clients, counterparts, the public, and internal staff, and must designate a person responsible for this function.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dora-regulation-article-17-ict-related-incident-management-process",
    "title": "Digital Operational Resilience Act (DORA) - Article 17: ICT-related incident management process",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Financial entities must define, establish, and implement a comprehensive ICT-related incident management process to detect, manage, notify, record, and analyze all incidents and significant cyber threats.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dora-regulation-article-18-classification-ict-related-incidents",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 18: Classification of ICT-related incidents and cyber threats",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires financial entities to establish procedures for managing ICT-related incidents and to classify these incidents and cyber threats based on specific criteria such as impact on clients, duration, data loss, and economic consequences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dora-regulation-article-19-reporting-major-ict-incidents",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 19: Reporting of major ICT-related incidents and voluntary notification of significant cyber threats",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires financial entities to report major ICT-related incidents to their designated competent authority using specified templates and procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dora-regulation-article-20-harmonisation-reporting-content-formats",
    "title": "Digital Operational Resilience Act (DORA) - Article 20: Harmonisation of reporting content and templates",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates European Supervisory Authorities (ESAs) to develop and submit harmonized technical standards establishing the content, templates, and procedures for financial entities to report major ICT-related incidents and notify significant cyber threats.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dora-regulation-article-28-third-party-ict-risk-management",
    "title": "REGULATION (EU) 2022/2554 on digital operational resilience for the financial sector - Article 28: Key principles for ICT third-party risk management",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires financial entities to manage ICT third-party risk as an integral part of their overall ICT risk framework, including maintaining a register of information, adopting a risk strategy, conducting due diligence, and ensuring contractual arrangements and exit strategies are in place.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dora-regulation-article-29-preliminary-assessment-ict-concentration-risk",
    "title": "REGULATION (EU) 2022/2554 on digital operational resilience for the financial sector - Article 29: Assessment of ICT concentration risk at Union level",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires the designated Lead Overseer to conduct and coordinate a preliminary assessment of ICT concentration risk at the Union level for each critical ICT third-party service provider.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dora-regulation-article-30-key-contractual-provisions",
    "title": "REGULATION (EU) 2022/2554 on digital operational resilience for the financial sector - Article 30, Key contractual provisions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that financial entities ensure their contractual arrangements for the use of ICT services contain specific provisions to manage ICT third-party risk, including clear descriptions of services, data processing locations, security measures, audit rights, and exit strategies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dora-regulation-article-5-ict-risk-management-framework",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 5: Governance and organisation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Financial entities must establish, implement, and maintain an internal governance and control framework to ensure the effective and prudent management of ICT risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dora-regulation-article-6-ict-risk-management-framework-simplified",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 6",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes mandatory and voluntary reporting requirements for financial entities concerning major ICT-related incidents and significant cyber threats to competent authorities and clients.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dora-regulation-article-8-identification-classification-ict-assets",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 8: Identification",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Financial entities must identify, classify, document, and continuously review all ICT-supported business functions, assets, and related risks as part of their ICT risk management framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dora-regulation-article-9-protection-prevention",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 9",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires financial entities to implement security measures to protect networks and data, and to develop detailed access management controls and human resource policies for monitoring ICT risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dora-resilience-testing-articles-24-27",
    "title": "Digital Operational Resilience Testing Programme (Articles 24-27) - Regulation (EU) 2022/2554 (DORA)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This regulation requires EU financial entities to establish and maintain a comprehensive, risk-based digital operational resilience testing programme to assess preparedness, identify vulnerabilities, and validate protective measures. As per Article 26, significant entities must conduct advanced threat-led penetration testing (TLPT) at least every three years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "eba-outsourcing-guide",
      "pra-ss1-21-resilience",
      "cpmi-iosco-cyber-resilience-fmi",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dora-third-party-risk-articles-28-44",
    "title": "DORA ICT Third-Party Risk Management and Oversight - Articles 28-44 (Regulation 2022/2554)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This regulation requires EU financial entities to manage risks associated with ICT third-party service providers by maintaining a register of information, conducting due diligence, and ensuring specific contractual provisions are in place (Article 30). It also establishes a Union Oversight Framework for critical ICT third-party service providers, granting Lead Overseers direct powers of investigation and enforcement (Article 31).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eba-outsourcing-guide",
      "bcbs-principles-operational-resilience",
      "nist-ir-8276-cyber-scrm-practices"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "drc-mining-code-2018-democratic-republic-congo",
    "title": "Law No. 18-001 of 9 March 2018 on the Mining Code of the Democratic Republic of the Congo",
    "domain": "Mining & Natural Resources",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The DRC Mining Code 2018 (Law No. 18-001 of 9 March 2018) establishes the legal framework for mineral exploration, exploitation, and artisanal mining in the Democratic Republic of the Congo, requiring all mining operators to obtain permits, disclose beneficial ownership, comply with royalty rates (including a royalty of up to 10% on substances declared strategic, such as cobalt and coltan), and adhere to EITI reporting standards. A separate windfall (superprofit) tax of 50% applies under Article 251 bis when commodity prices exceed the feasibility-study reference price by more than 25%; beneficial ownership is addressed under Article 233.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "drc-mining-code-law-18-001-2018",
      "eiti-standard-2023",
      "eu-conflict-minerals-regulation-2017-821"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "drc-mining-code-law-18-001-2018",
    "title": "Law No. 18-001 of 9 March 2018 on the Mining Code of the Democratic Republic of the Congo",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This law establishes royalty rates, state participation in mining projects, special regimes for strategic minerals, and environmental obligations for all mining operations in the Democratic Republic of the Congo. It applies to all holders of mining titles and requires compliance with Articles 193-207 for royalties, Article 210 for state participation, and Articles 232-244 for environmental protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "drone-delivery-corridor",
    "title": "Drone Delivery Corridor Security",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance within designated drone delivery corridors mandates a multi-layered approach to operational integrity and airspace safety, unifying stringent technical and procedural controls. Operations must strictly adhere to a maximum altitude of 400 feet AGL. In accordance with FAA 14 CFR Part 89 and technical specifications detailed in ASTM F3411-22, each unmanned aircraft system must broadcast Remote ID information at a minimum frequency of 1 Hz. Command and Control (C2) link security, conforming to RTCA DO-362A performance standards, is non-negotiable, requiring AES-256 encryption and limiting C2 latency to a maximum of 50 milliseconds. A C2 link loss condition is triggered after 3 seconds, necessitating redundant communication systems for operational continuity. Furthermore, systems must possess GNSS spoofing detection capabilities and execute an automatic return procedure upon jamming detection. The regulatory framework for the U-space, guided by EU Commission Implementing Regulation 2021/664, requires mandatory UTM integration and dynamic geofencing to ensure a minimum separation distance of 200 feet between aircraft. Finally, for any transit over people conducted under FAA 14 CFR Part 135 delivery exemptions, the maximum kinetic energy imparted upon impact must not exceed 80 joules, a critical safety threshold consistent with ISO 21384-3 operational procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "as9100-rev-d-qms",
      "iso-28000-supply-chain",
      "icao-annex-17-security",
      "icao-safety-mgt-system",
      "nist-sp-800-207"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-11-mere-conduit-liability-exemption",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 11",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Providers of intermediary services must designate, publish, and maintain a single point of contact to enable direct electronic communication with Member State authorities, the European Commission, and the European Board for Digital Services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-37-dpo",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-12-caching-conditions",
    "title": "REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 12",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Establishes the conditions under which providers of 'caching' intermediary services are exempt from liability for the automatic, intermediate, and temporary storage of information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dsa-regulation-article-13-hosting-liability-conditions",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 13: Points of contact for Member State authorities, the Commission and the Board",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires providers of intermediary services to designate, publish, and maintain a single point of contact for electronic communication with EU authorities and to specify the languages for such communication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-37-dpo",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-14-notice-and-action-mechanisms",
    "title": "Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 14: Notice and action mechanisms",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires hosting service providers to establish user-friendly electronic mechanisms for individuals and entities to report illegal content, and to process these notices in a timely, diligent, and objective manner.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-15-illegal-content-reporting",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 15: Reporting of criminal offences",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires providers of hosting services to promptly inform law enforcement or judicial authorities if they become aware of any information giving rise to a suspicion that a serious criminal offence involving a threat to life or safety has taken, is taking, or is likely to take place.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dsa-regulation-article-16-notice-action-mechanisms-hosting-providers",
    "title": "Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 16: Notice and action mechanisms",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Hosting service providers must establish and operate easy-to-use electronic mechanisms for individuals and entities to report illegal content, and must process these notices in a timely, diligent, and non-arbitrary manner.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-17-statements-of-reasons-content-moderation",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 17: Statement of reasons",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Hosting service providers must provide affected users with a clear, specific, and timely statement of reasons when they restrict content or accounts based on illegality or terms of service violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dsa-regulation-article-19-out-of-court-dispute-settlement",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 19: Out-of-court dispute settlement",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires online platforms to provide recipients of their service with access to certified out-of-court dispute settlement bodies to resolve disputes over content moderation decisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-20-internal-complaint-handling-system",
    "title": "REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 20: Internal complaint-handling system",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Providers of online platforms must establish and operate an easily accessible, free, and effective internal system for handling user complaints against content moderation decisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-22-trusted-flaggers",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 22 Trusted Flaggers",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Providers of intermediary services must adhere to harmonised diligence requirements to ensure a safe, predictable, and trustworthy online environment, fostering the internal market and protecting fundamental rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dsa-regulation-article-23-obligations-online-platforms-protection-minors",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 23: Protection of minors",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Providers of online platforms accessible to minors must implement appropriate and proportionate measures to ensure a high level of privacy, safety, and security for minors, and are prohibited from presenting profiled advertising to users known to be minors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-24-online-interface-restrictions",
    "title": "REGULATION (EU) 2022/2065 Article 24: Transparency reporting obligations for providers of intermediary services",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Providers of intermediary services must publish detailed annual transparency reports on their content moderation activities, including data on government orders, user notices, own-initiative actions, and the use of automated systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dsa-regulation-article-25-advertising-transparency",
    "title": "REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 25",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Providers of online platforms must ensure that for each advertisement, recipients can clearly identify it as an ad, who it's on behalf of, who paid for it, and the main parameters used for targeting them.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dsa-regulation-article-26-recommender-systems-transparency",
    "title": "REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 26",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Providers of online platforms using recommender systems must transparently disclose the main parameters used for recommendations and provide users with options to modify or influence them.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-27-targeted-advertising-obligations",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 27: Online protection of minors",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations providing online platforms accessible to minors must implement appropriate measures for their privacy, safety, and security, and are prohibited from presenting advertisements based on profiling using the personal data of minors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dsa-regulation-article-28-protection-of-minors-advertising",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 28: Protection of minors",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Providers of online platforms accessible to minors must implement measures for their privacy, safety, and security, and are prohibited from presenting profiled advertisements to users they know with reasonable certainty are minors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dsa-regulation-article-29-recommender-systems-online-marketplaces",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 29",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Providers of online platforms using recommender systems must transparently disclose the main parameters used for recommendations and provide any available options for users to modify or influence them.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dsa-regulation-article-30-online-marketplace-trader-obligations",
    "title": "REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 30",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Online marketplaces must collect, verify, and display specific identification and contact information from their business users (traders) to ensure traceability and compliance before allowing them to offer services to consumers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-33-vlop-vlose-designation",
    "title": "Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 33: Very large online platforms and very large online search engines",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article establishes the process by which the European Commission designates online platforms and search engines as 'very large' (VLOPs/VLOSEs) based on their number of average monthly active users in the Union, triggering additional, more stringent obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-34-risk-assessment-vlop-vlose",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 34",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs) must diligently conduct, document, and report on annual assessments of any significant systemic risks stemming from the design or functioning of their services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-36-data-access-research",
    "title": "REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 36 Data access and scrutiny",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that very large online platforms provide vetted researchers with access to platform data for the sole purpose of conducting research on systemic risks in the Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-37-independent-audit-vlop",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 37 Auditing",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Providers of very large online platforms (VLOPs) must undergo and pay for an independent audit at least once a year to assess their compliance with specific obligations under the Digital Services Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-38-vlop-recommender-system-additional-obligations",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 38 Recommender systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Very large online platforms (VLOPs) and very large online search engines (VLOSEs) using recommender systems must provide users with an accessible option to modify the main parameters of each system, including an option not based on profiling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dsa-regulation-article-39-online-advertising-transparency-vlop",
    "title": "REGULATION (EU) 2022/2065 (Digital Services Act) Article 39: Online advertising transparency",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Providers of online platforms, especially very large online platforms (VLOPs), must ensure transparency for all online advertising, including identifying ads, the advertiser, and the main targeting parameters, and for VLOPs, maintaining a public repository of ad information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-40-online-advertising-repository",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 39: Online advertising transparency",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Very large online platforms must compile and maintain a publicly accessible, searchable repository of all advertisements displayed on their service for one year after the ad was last presented.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dsa-regulation-article-42-systemic-risk-transparency-reporting",
    "title": "Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 42 Transparency reporting obligations for providers of online platforms and of very large online platforms",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Providers of online platforms, and especially very large online platforms (VLOPs), must publish detailed transparency reports on their content moderation activities, including orders from authorities, user notices, own-initiative moderation, complaints, and the use of automated systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-43-supervisory-fee-vlop",
    "title": "Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 43: Supervisory fees",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires the Commission to charge annual supervisory fees to providers of very large online platforms (VLOPs) and very large online search engines (VLOSEs) to cover the costs of its supervisory tasks under this Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "dsa-regulation-article-45-penalties-non-compliance",
    "title": "REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 45",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires Member States to establish effective, proportionate, and dissuasive penalties for non-compliance with the DSA, setting maximum fines based on the global annual turnover of the service provider.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "dsa-regulation-article-52-supervisory-fees",
    "title": "REGULATION (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 52 Supervisory fees",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires providers of very large online platforms (VLOPs) and very large online search engines (VLOSEs) to pay annual supervisory fees to the Commission to cover the costs of its supervisory tasks under this regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-56-exclusive-competence-commission-vlop",
    "title": "REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) - Article 56",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must acknowledge the principles of the Digital Services Act, which aims to harmonize rules for intermediary services to ensure a safe, predictable, and trustworthy online environment within the EU's internal market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-73-penalties-non-compliance",
    "title": "Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 73 Penalties",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires Member States to establish effective, proportionate, and dissuasive penalties for infringements of the Digital Services Act, setting maximum fines up to 6% of annual worldwide turnover for non-compliance and 5% of average daily turnover for periodic penalty payments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "dsa-regulation-article-74-independent-audit",
    "title": "Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) - Article 74: Independent audit",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Very large online platforms and search engines must undergo an independent audit at least once a year, at their own expense, to assess compliance with specific DSA obligations and commitments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dtsa-trade-secret-protection",
    "title": "DTSA (Trade Secret Protection)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.2.0",
    "last_updated": "2026-07-03",
    "bluf": "The Defend Trade Secrets Act (DTSA) of 2016 is a U.S. federal law extending the Economic Espionage Act of 1996 to provide a private right of action for trade secret misappropriation. It provides a standardized federal framework for protecting confidential business information, including 'Ex Parte Seizure' provisions to prevent the dissemination of trade secrets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-trade-secret-stds",
      "paris-convention-industrial-property",
      "sarbanes-oxley-act-sox",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "dz-pdpl-2018",
    "title": "Algeria Personal Data Protection Law - ANPDP Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Algeria Law No. 18-07 on Personal Data Protection (2018) establishes a CNIL-influenced framework of consent-based processing, mandatory prior authorization for sensitive data, and data subject rights. The Autorité Nationale de Protection des Données à Caractère Personnel (ANPDP) is the designated supervisory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ear-dual-use-export",
    "title": "EAR Dual-Use Export Control",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Export Administration Regulations (EAR) govern the export of 'Dual-Use' items-commercial commodities, software, and technology that also have potential military or proliferation applications. It is centered around the Commerce Control List (CCL) and the Export Control Classification Number (ECCN) to determine license requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itar-compliance-workflow",
      "dfars-7012-defense-cyber",
      "nist-800-171-cui",
      "uk-strategic-export-control"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "easa-ai-roadmap-2023",
    "title": "EASA Artificial Intelligence Roadmap 2.0 - AI Application in Aviation Safety",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-05-28",
    "bluf": "This strategic roadmap outlines the European Union Aviation Safety Agency's approach to integrating Artificial Intelligence (AI) into aviation, establishing a learning-based framework to ensure safety and trustworthiness. It introduces the AI Trustworthiness concept (Chapter 4) and a three-level AI assurance framework (Level 1A/1B, 2, 3) to guide the development of new certification standards for AI/ML applications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-safety-annex-19",
      "faa-part-21-certification",
      "easa-part-145-maintenance",
      "as9100-rev-d-qms"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "easa-cybersecurity-aviation-ed-202a-2022",
    "title": "Acceptable Means of Compliance (AMC) and Guidance Material (GM) to Commission Regulation (EU) No 1321/2014 - Issue 1, Amendment 4 - Cybersecurity Requirements for Aircraft (ED-202A AMC/GM)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes cybersecurity requirements for aircraft design, production, and continuing airworthiness, mandating risk-based protection of aircraft systems against unauthorized access. It applies to design organisations, maintenance organisations, and aircraft operators under Regulation (EU) No 1321/2014, with key provisions in AMC 145.A.30(d), AMC 147.A.01(d), and AMC 21.A.133B.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-800-53-ac2",
      "c-scrm-practices-systems-organizations",
      "nist-800-53-sc7",
      "iso-12207-2017-software-lifecycle-processes"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "easa-part-145-maintenance",
    "title": "EASA Part 145 (Maintenance)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "EASA Part 145 is the European standard for the approval of maintenance organizations in civil aviation. It specifies the requirements for the organization, personnel, facility, and procedures to ensure the airworthiness of aircraft and components through safe and standardized maintenance practices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "as9110-maintenance-qms",
      "icao-safety-annex-19",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eba-ai-machine-learning-risk-guidelines-2023",
    "title": "EBA Guidelines on the Use of Machine Learning for Internal Ratings-Based Models - Compliance Obligations for AI Model Risk Management, ML Validation Controls, and AI Governance for EU Banking Institutions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations for EU banking institutions under the EBA Guidelines for using machine learning in Internal Ratings-Based (IRB) models, focusing on AI model risk management, validation controls, and governance; it aligns with EU AI Act 2024 requirements for high-risk AI systems under Article 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eba-aml-cft-ml-tf-risk-factors-guidelines",
    "title": "EBA Guidelines on ML/TF Risk Factors (EBA/GL/2021/02 as amended) - Risk-Based Customer Due Diligence for EU Financial Sector Obliged Entities",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.0",
    "last_updated": "2026-07-10",
    "bluf": "The European Banking Authority (EBA) Guidelines on ML/TF Risk Factors (EBA/GL/2021/02, originally issued 1 March 2021 under Articles 17 and 18(4) of Directive (EU) 2015/849 (4AMLD) and Article 16 of Regulation (EU) 1093/2010, amended by EBA/GL/2023/03 of 31 March 2023, which added the annex on customers that are not-for-profit organisations, and by EBA/GL/2024/01 of 16 January 2024, which extended the Guidelines to crypto-asset service providers with application from 30 December 2024) operationalise the risk-based approach to customer due diligence (CDD) for credit and financial institutions across the EU. The Guidelines set out factors that obliged entities must consider when assessing money-laundering and terrorism-financing risk associated with a business relationship or occasional transaction: customer risk factors (legal form, ownership structure, beneficial ownership, politically exposed person (PEP) status, source of wealth), geographic risk factors (high-risk third countries, comprehensive sanctions jurisdictions, jurisdictions identified by FATF), product service and transaction risk factors (private banking, correspondent banking, trade finance, crypto-asset transfers above EUR 1,000, anonymous transactions), and channel or delivery risk factors (non-face-to-face onboarding, agent networks, third-party introducers). The Guidelines prescribe sector-specific guidance for retail banks, private banking, corporate banking, life insurance, asset management, investment firms, crowdfunding service providers under Regulation 2020/1503, e-money issuers, payment institutions, and crypto-asset service providers under MiCA (Regulation 2023/1114) and the recast Transfer of Funds Regulation 2023/1113. Obliged entities must document their methodology, calibrate enhanced due diligence (EDD) and simplified due diligence (SDD) thresholds against the Guidelines, and integrate the EBA risk-factor catalogue into their AML/CFT risk assessment. National competent authorities (NCAs) supervise compliance; the EU Anti-Money Laundering Authority (AMLA), established by Regulation (EU) 2024/1620 with its seat in Frankfurt, began operations on 1 July 2025 and is scheduled to begin direct supervision of selected high-risk cross-border credit and financial institutions in 2028, with the EBA Guidelines remaining in force until replaced. The Guidelines are the operational backbone of the 4AMLD / 5AMLD / 6AMLD risk-based approach and the carry-over framework into the 2024 EU AML Package (Regulation 2024/1624 AMLR, Directive 2024/1640 AMLD6 and Regulation 2024/1620 establishing AMLA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "directive_anchor_4amld_5amld_6amld",
        "eu_aml_package_2024_carry_over",
        "amla_supervision_transition",
        "fatf_alignment_recommendations",
        "transfer_of_funds_and_travel_rule",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-regulation-2024-1624",
      "eu-aml-authority-amla-2024",
      "fatf-40-recommendations-2023-consolidated"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eba-guidelines-ict-risk-2019",
    "title": "EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "These guidelines require EU financial institutions, including credit institutions, investment firms, and payment service providers, to establish a comprehensive and documented ICT and security risk management framework. This framework, as mandated by Title I, Guideline 1, must ensure the management body defines, approves, and oversees the implementation of the institution's ICT strategy and risk management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eba-outsourcing-guide",
      "bcbs-principles-sound-management-operational-risk",
      "psd2-sc-authentication"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eba-outsourcing-guide",
    "title": "EBA Outsourcing Guidelines",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The EBA Guidelines on Outsourcing Arrangements (EBA/GL/2019/02) apply a unified framework for the financial sector across the EU. it specifies the governance and the pre-outsourcing due diligence required for all credit institutions and the investment firms, with a specific focus on the 'Critical or Important' functions that affect the firm's the regulatory compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "bcbs-principles-sound-management-operational-risk",
      "dora-ict-risk",
      "interagency-guidance-third-party-risk-management",
      "iso-31000-risk-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ebrc-engineering-biology-safety-guidelines-2023",
    "title": "EBRC Engineering Biology Safety Guidelines 2023 - Biosafety by Design: Synthetic Biology Containment Strategies, Genetic Use Restriction, Horizontal Gene Transfer Risk Assessment, Dual-Use Research of Concern (DURC) Review and Institutional Biosafety Committee Obligations",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This guidance establishes biosafety and biosecurity best practices for engineering biology research, focusing on synthetic biology containment, genetic use restriction technologies (GURT), horizontal gene transfer risk assessment, and Dual-Use Research of Concern (DURC) review. It applies to academic, government, and nonprofit institutions conducting genetic engineering research, particularly those hosting student and postdoctoral biosecurity programs as referenced in the source material.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "eu-biosafety-contained-use-directive-2009-41",
      "cbd-convention-biological-diversity-1992",
      "australia-gene-technology-act-2000",
      "eu-directive-2001-18-deliberate-release-gmo"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ebsa-cybersecurity-best-practices",
    "title": "CYBERSECURITY PROGRAM BEST PRACTICES",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-12",
    "bluf": "ERISA-covered pension plans and health and welfare plans often hold millions of dollars or more in assets and store participant personally identifiable data, which can make them tempting targets for cyber-criminals. Responsible plan fiduciaries have an obligation to ensure proper mitigation of cybersecurity risks. This guidance provides best practices for use by recordkeepers and other service providers responsible for plan-related IT systems and data, and for plan fiduciaries making prudent decisions on the service providers they should hire. The core obligations include having a formal, well-documented cybersecurity program, conducting prudent annual risk assessments, obtaining a reliable annual third-party audit of security controls, and implementing strong technical controls and access procedures. Service providers must also ensure data stored in the cloud is subject to appropriate security reviews, conduct periodic cybersecurity awareness training, encrypt sensitive data, and appropriately respond to any cybersecurity incidents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "erisa-compliance-rep",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-30-risk-assessment",
      "cyber-nist-800-53-ac2",
      "nist-sp-800-50r1-learning-program",
      "iso-19011-audit-guidelines"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ebu-r128-audio-loudness",
    "title": "EBU R128 (Loudness)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with the EBU R 128 recommendation mandates rigorous audio loudness normalization to ensure content uniformity across broadcast platforms. The primary objective is achieving a Target Programme Loudness of -23.0 LUFS, with a standard tolerance of ±0.5 LU; for live material, this window is expanded to ±1.0 LU. A critical ceiling is the Maximum Permitted True Peak Level, which must never exceed -1.0 dBTP, demanding true peak metering as specified within the ITU-R BS.1770-4 standard. All loudness measurements must conform to this ITU algorithm, which employs a two-stage gating process. This mechanism includes an absolute gating threshold fixed at -70 LUFS alongside a relative gating block set -10 LU below the ungated measurement. To control dynamic peaks, particularly for short-form content as addressed by EBU R 128 s1, a Maximum Short-Term Loudness limit of -18.0 LUFS is enforced. Further analysis includes the measurement of Loudness Range (LRA), consistent with EBU Tech 3342, to characterize audio dynamics. The entire framework is supported by EBU Tech 3341 for metering specifications and EBU Tech 3343 for practical guidelines, culminating with the requirement to embed loudness metadata for signal chain integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itu-r-bt-709-hdtv",
      "itu-r-bt-2020-uhdtv",
      "smpte-st-2110-media"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ec-lopdp-2021",
    "title": "Ecuador Organic Personal Data Protection Law 2021 - SPDP",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Ecuador's Ley Orgánica de Protección de Datos Personales (LOPDP - Organic Personal Data Protection Law) - published in the Registro Oficial Suplemento No. 459 on 26 May 2021 - is Ecuador's comprehensive personal data protection legislation, enacted by the Asamblea Nacional (National Assembly) and entered into force on 26 May 2021 with a two-year transition period during which organisations were required to achieve full compliance (compliance deadline: 26 May 2023). The LOPDP is Ecuador's most advanced data protection instrument, repealing prior fragmented provisions and establishing a unified rights-based framework broadly aligned with the European Union's General Data Protection Regulation (GDPR - Regulation (EU) 2016/679). The supervisory authority is the Superintendencia de Protección de Datos Personales (SPDP - Personal Data Protection Superintendence), established under the LOPDP as a technically autonomous and independent public institution with regulatory, supervisory, and enforcement powers. The SPDP became operationally active following the enactment of the LOPDP and its implementing regulations. Key features of Ecuador's LOPDP: (1) Scope - applies to the processing of personal data of natural persons (titulares) located in Ecuador, regardless of where the responsible party (Responsable del Tratamiento) is located; also applies to processing carried out in Ecuador by entities located abroad; (2) Data processing principles - processing must comply with: lawfulness; consent; purpose limitation; proportionality; data quality; transparency; security; confidentiality; and accountability; (3) Sensitive personal data - ideología, afiliación política, filiación sindical, datos de salud, datos de vida sexual, datos genéticos, datos biométricos, datos de origen étnico o racial, creencias religiosas or filosóficas, origen étnico o racial, and datos relativos a condenas e infracciones penales; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests of the Responsable where not overriding data subject rights; (5) Data subject rights (Titular rights) - right of access; right to rectification; right to erasure; right to restriction; right to portability; right to oppose processing; and right not to be subject to automated decisions with legal or significantly similar effects; (6) Responsable del Tratamiento and Encargado del Tratamiento - data controller and processor distinction with processor contractual obligations; (7) Delegado de Protección de Datos (DPD/DPO) - mandatory appointment for certain controllers; (8) Evaluación de Impacto sobre Protección de Datos (EIPD/DPIA) - required for high-risk processing; (9) Breach notification - the Responsable must notify the SPDP within 72 hours of discovering a breach; affected data subjects notified where breach poses high risk; (10) Cross-border transfers - transfers outside Ecuador require equivalent protection or SPDP approval; (11) Administrative sanctions - infractions classified as minor, serious, and very serious; sanctions ranging from warnings to fines proportional to the severity of the violation. Ecuador's LOPDP incorporates the constitutional right to privacy and informational self-determination guaranteed by the Constitución de la República del Ecuador of 2008.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ec-losncp-ley-organica-sistema-nacional-contratacion-publica-2008-sercop",
    "title": "Ecuador Ley Organica del Sistema Nacional de Contratacion Publica (LOSNCP) of 4 August 2008 and SERCOP",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Ecuadorian Ley Organica del Sistema Nacional de Contratacion Publica (LOSNCP / Organic Law of the National System of Public Procurement) published in Registro Oficial Suplemento 395 of 4 August 2008 effective 4 August 2008 as substantially amended over time (most recently by Ley Organica Reformatoria a la LOSNCP published in Registro Oficial Suplemento 100 of 14 October 2013, Ley Organica Anticorrupcion Reformatoria de la LOSNCP, and the 2022 Codigo Organico Administrativo amendments), and the Reglamento General de la LOSNCP approved by Decreto Ejecutivo 1700 of 12 May 2009 effective 12 May 2009, is the principal Ecuadorian framework governing procurement of goods, works, services (including consulting services), and leases by entities of the National System of Public Procurement including the Executive Function ministries, the Legislative Function (Asamblea Nacional), the Judicial Function, the Electoral Function (CNE), the Transparency and Social Control Function (Consejo de Participacion Ciudadana y Control Social), Autonomous Decentralized Governments (Gobiernos Autonomos Descentralizados / GADs including provincial councils, municipal councils, parish boards), public-sector enterprises (Empresas Publicas), public-sector universities, and other entities financed by public funds. The Servicio Nacional de Contratacion Publica (SERCOP / sercop.gob.ec) is the central regulatory authority with rule-making, oversight, supplier debarment, and operation of the public procurement portal. The Sistema Oficial de Contratacion Publica del Ecuador (SOCE / portal compraspublicas.gob.ec) operated by SERCOP is the mandatory federal e-procurement platform for all in-scope procurement. Procurement methods established by LOSNCP art. 32 to 62 comprise (a) Subasta Inversa Electronica (Reverse Electronic Auction, for procurement of standardised goods and services with reference prices), (b) Licitacion (Public Tender, the default open public procedure for high-value acquisitions above prescribed thresholds), (c) Cotizacion (Quotation, for medium-value acquisitions), (d) Menor Cuantia (Minor Amount Procurement, for low-value acquisitions), (e) Concurso Publico (Public Competition, for consulting services above prescribed thresholds), (f) Lista Corta (Short List, for medium-value consulting services), (g) Contratacion Directa (Direct Procurement for consulting services below prescribed thresholds and for certain prescribed exceptions), (h) Regimen Especial (Special Regime, including sole-source under prescribed exceptions in art. 2 numeral 8 such as urgency, sole supplier for technical reasons, public health emergencies, and prescribed-class exemptions), and (i) Catalogo Electronico (Electronic Catalogue, for items contracted through Convenio Marco framework agreements). The Contraloria General del Estado conducts ex-post procurement audit. Ecuador is NOT a party to the WTO Government Procurement Agreement (GPA). Ecuador is a party to the Andean Community Decision 439 on procurement and UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "ec-lopdp-2021",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ecb-guide-internal-models",
    "title": "ECB Guide (Internal Models)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The ECB Guide to Internal Models (EGIM) provides the foundational standard for the supervised banks in the Eurozone to the use of the 'Internal Ratings Based' (IRB) approach for calculating the regulatory capital. it specifies the risk parameter estimation (PD, LGD, EAD) and the validation requirements for the credit risk models.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-ii-capital-framework",
      "basel-iii-global-regulatory-framework",
      "ifrs-9-impairment",
      "sr-11-7-model-risk-management",
      "dora-ict-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ecb-srep-2023-supervisory-guide",
    "title": "ECB Guide to Internal Models (TRIM) and SREP Pillar 2 Capital Requirements 2023",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This guide outlines the European Central Bank's supervisory expectations for banks using internal models to calculate risk-weighted assets (RWAs), specifying how model deficiencies identified during the Targeted Review of Internal Models (TRIM) will impact Pillar 2 capital requirements (P2R) as part of the Supervisory Review and Evaluation Process (SREP), as detailed in Chapter 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ecb-guide-internal-models",
      "basel-ii-capital-framework",
      "basel-iii-global-regulatory-framework",
      "sr-11-7-model-risk-management",
      "principles-effective-risk-data-aggregation"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ecb-tiber-eu-framework-2018-threat-intelligence-red-teaming",
    "title": "ECB TIBER-EU 2018 Threat Intelligence-Based Ethical Red Teaming Framework",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The European Central Bank's TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) framework, published May 2018, is a pan-European framework for financial entities to test and improve their cyber resilience by conducting controlled, intelligence-led red team tests against live production systems, requiring a threat intelligence phase, red team test phase, and closure phase with remediation, coordinated with national competent authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-2022-2554-article-15-ict-business-continuity-policy"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "echr-1950-european-convention-human-rights",
    "title": "European Convention on Human Rights - ECHR 1950",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The ECHR binds 46 Council of Europe member states to protect 15 fundamental rights enforceable before the ECtHR in Strasbourg; businesses in signatory jurisdictions must align employee monitoring, data practices, whistleblower channels, NDA scope, and supply chain conduct with ECHR rights as interpreted by Grand Chamber jurisprudence - with Bărbulescu v. Romania (2017) setting the definitive five-step proportionality test for workplace monitoring and Verein Klimaseniorinnen v. Switzerland (2024) establishing Article 8 climate obligations on states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-iccpr-1966-civil-political-rights",
      "un-guiding-principles-business-human-rights",
      "eu-corporate-sustainability-due-diligence-2024",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ecss-u-ast-10c-space-debris-mitigation-requirements",
    "title": "ECSS-U-AS-10C Space Debris Mitigation Requirements - ESA/European Standard",
    "domain": "Space & Satellite Law",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "ECSS-U-AS-10C (European Cooperation for Space Standardization, 2022) is the mandatory ESA debris mitigation standard adopted for all ESA-procured missions, implementing IADC and COPUOS guidelines. Key requirements: post-mission disposal (PMD) in Low Earth Orbit (LEO, ≤2,000km) within 5 years of end of mission (or ≤25 years with reliability ≥0.9 for missions before 2022 guideline update); Geostationary (GEO) spacecraft must be raised to graveyard orbit ≥300km above GEO arc; passivation (removal of all stored energy) mandatory at end of mission; fragmentation risk F(fragm) ≤0.001 per mission-year for on-orbit phase; re-entry demisability ≥0.999 (casualty expectation ≤10⁻⁴) for uncontrolled re-entry; debris objects ≥10cm creation probability ≤0.001 per mission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_framework",
        "regulatory_mapping",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iadc-space-debris-mitigation-guidelines-2007",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "edge-ai-security-nist",
    "title": "Edge AI Security (NIST)",
    "domain": "Industrial IoT & Energy",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Edge AI security encompasses the technical and operational controls required to securely deploy machine learning models on resource-constrained IoT and edge computing devices, where traditional cloud-based security architectures cannot be fully replicated due to limited compute, network, and power resources. NIST SP 800-213 (IoT Device Cybersecurity Guidance) and NIST IR 8259 (Foundational Cybersecurity Activities for IoT Device Manufacturers) provide the foundational requirements, supplemented by NIST SP 800-207 (Zero Trust Architecture) for network access control. Key risks include: AI model theft via physical device access, adversarial input attacks on on-device inference, insecure firmware update mechanisms, side-channel attacks on cryptographic operations, and supply chain compromise of edge AI hardware. Failure to secure edge AI creates attack vectors that bypass perimeter defenses entirely.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-213-iot-guidance",
      "nistir-8259-iot-device-manufacturers",
      "nist-sp-800-207",
      "nist-sp-800-193-firmware-resiliency",
      "iec-62443-iacs",
      "nist-sp-800-82r3-ot-security"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "edpb-guidelines-gdpr-educational-institutions",
    "title": "EDPB Guidelines on GDPR in Educational Institutions - Lawful Basis, Parental Consent, Learning Management Systems and Data Minimisation",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Educational institutions must establish a valid lawful basis under GDPR Article 6 for processing student data, which is typically 'public task' rather than consent. For children under the age specified by Member State law (per Article 8), verifiable parental consent is required for information society services offered directly to them, and data minimisation must be strictly applied, especially within Learning Management Systems (LMS).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "edpb-opinion-28-2024-ai-models",
    "title": "European Data Protection Board (EDPB) Opinion 28/2024 (Adopted 17 December 2024) - On Certain Data Protection Aspects Related to the Processing of Personal Data in the Context of AI Models (Article 64(2) GDPR Opinion Requested by the Irish Supervisory Authority on 4 September 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-12-17",
    "bluf": "EDPB Opinion 28/2024 'on certain data protection aspects related to the processing of personal data in the context of AI models', adopted by the European Data Protection Board on 17 December 2024, is the EDPB's authoritative consensus position on the application of the GDPR to AI model development and deployment. The Opinion was issued under Article 64(2) of the GDPR (Regulation (EU) 2016/679) following a request submitted by the Irish supervisory authority (IE SA) on 4 September 2024 - the IE SA being the lead supervisory authority for several major AI developers in the EU. The Opinion addresses four questions of general application: (1) when and how an AI model can be considered as 'anonymous'; (2) how controllers can demonstrate the appropriateness of legitimate interest as a legal basis for processing in the development phase; (3) how controllers can demonstrate the appropriateness of legitimate interest in the deployment phase; and (4) what consequences flow from unlawful processing of personal data in the development phase on the subsequent processing or operation of the AI model. Key holdings: on Question 1, the EDPB considers that AI models trained with personal data cannot, in all cases, be considered anonymous; SAs must assess anonymity claims case-by-case, requiring both that (a) the likelihood of direct (including probabilistic) extraction of personal data of training-data subjects, and (b) the likelihood of obtaining personal data from queries (intentionally or not), are insignificant taking into account 'all the means reasonably likely to be used'. On Questions 2 and 3, the Opinion reiterates that there is no hierarchy between GDPR legal bases and recalls the three-step legitimate-interest test: (i) identifying the legitimate interest pursued (which must be lawful, clearly and precisely articulated, and real and present - not speculative); (ii) the necessity test (whether processing pursues the interest, and whether less-intrusive alternatives exist); and (iii) the balancing test against the interests, fundamental rights and freedoms of data subjects, with particular weight given to data subjects' reasonable expectations and the possibility of mitigating measures. On Question 4, the Opinion analyses three scenarios: Scenario 1 (same controller, model retains personal data, develops then deploys), Scenario 2 (model retains personal data, deployed by a different controller - who must conduct an Article 5(1)(a)/Article 6 GDPR appropriateness assessment as part of accountability), and Scenario 3 (model is anonymised after unlawful initial processing - if the subsequent operation does not entail processing of personal data, the GDPR does not apply to that operation). The Opinion was adopted within the eight-week window from file completion specified by Article 64(3) GDPR / Article 10(2) of the EDPB Rules of Procedure (with a possible six-week extension based on complexity).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-gdpr-binding-corporate-rules",
        "eu-ai-act-2024",
        "uk-ico-ai-data-protection-guidance-2023",
        "fr-cnil-ai-action-plan-2023",
        "de-bfdi-ai-position-paper-2024",
        "uk-ico-explaining-decisions-with-ai-2022"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-ico-ai-data-protection-guidance-2023"
    ],
    "primary_citations_count": 15
  },
  {
    "node_id": "ee-ikus-2018",
    "title": "Estonia Personal Data Protection Act 2018 (IKÜS) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Estonia's Isikuandmete kaitse seadus (IKÜS - Personal Data Protection Act), adopted by the Riigikogu (Estonian Parliament) and published in the Riigi Teataja (RT I, 04.01.2019, 11), entered into force on 15 January 2019 and is Estonia's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Estonia. The GDPR is directly applicable Estonian law by virtue of Estonia's EU membership. The IKÜS provides national derogations, additions, and specifications that the GDPR permits EU member states to adopt and repeals the prior Estonian Personal Data Protection Act (RT I 2003, 26, 158). Enforcement: the Andmekaitse Inspektsioon (AKI - Data Protection Inspectorate) is Estonia's independent data protection supervisory authority. The AKI is Estonia's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Estonia is a uniquely digital jurisdiction: it operates X-Road, the world's most advanced distributed data exchange platform used by Estonian government services to securely share data between public sector databases; maintains an e-Residency programme allowing digital business identity for non-residents; and operates i-Voting (internet voting) for national elections since 2005. The volume and sensitivity of personal data processed through Estonian digital government infrastructure makes GDPR and IKÜS compliance particularly significant for both public authorities and private sector entities interacting with Estonian digital services. Key Estonian national provisions: (1) Age of digital consent: Estonia has set the age of consent for information society services at 13 years - the lowest age permitted under GDPR (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 13 require parental or guardian consent; (2) Employment - the Employment Contracts Act (Töölepingu seadus, as amended, Estonia) governs employment relationships and the processing of employee personal data alongside GDPR; the Occupational Health and Safety Act (Töötervishoiu ja tööohutuse seadus) governs health and safety data in employment; (3) Freedom of expression - the IKÜS contains exemptions for journalistic, academic, artistic, and literary processing aligned with GDPR Art. 85; Estonian constitutional freedom of expression (Estonian Constitution, § 45) supplements these exemptions; (4) Public sector - Estonian public authorities process significant personal data through X-Road integrated government services; the IKÜS provides specific rules for public authority processing supplementing GDPR Art. 6(1)(e); (5) Research and statistics - extended processing for scientific research, statistics, and archiving in the public interest is permitted with appropriate safeguards under the IKÜS. Fines: GDPR administrative fines apply in Estonia - up to EUR 20 million or 4% of global annual turnover. The AKI has been an active supervisory authority with enforcement actions in digital services, public sector processing, and employment data contexts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eeoc-employment-rule",
    "title": "EEOC (Employment Rule)",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Employers with 15 or more employees are subject to Title VII of the Civil Rights Act of 1964, which prohibits employment discrimination based on protected characteristics. This node enforces that prohibition, as platform configurations make protected class filtering impossible for candidate searches or other selection processes. Pursuant to guidelines on discrimination detailed in 29 CFR Part 1604, these protections extend to all aspects of employment, including sexual harassment. To comply with the Uniform Guidelines on Employee Selection Procedures (UGESP) in 29 CFR Part 1607 and recent EEOC technical assistance on AI, the system mandates an AI disparate impact audit. Such audits must demonstrate that selection rates for any subgroup are no less than an acceptable selection rate ratio minimum of 0.8, or four-fifths, of the rate for the highest-selected group. To support these audits while preventing misuse, demographic data isolation is required. Furthermore, based on EEOC Enforcement Guidance on retaliation, the system prevents any retaliatory action flags, meaning no adverse actions against individuals for engaging in protected activity are permissible. Recordkeeping obligations under 29 CFR Part 1602 are managed by retaining personnel records for one year and payroll records for three years. The platform supports the requirement for an annual EEO-1 filing and enforces a mandatory EEO policy acknowledgment for all users. Finally, it tracks the standard complaint filing limit of 180 days, which is extendable to 300 days in certain jurisdictions, for timely charge submission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ada-employment-title-1",
      "flsa-compliance-labor",
      "fmla-compliance-leave",
      "erisa-compliance-rep",
      "osha-work-safety-us",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eg-law-182-2018-regulating-government-contracts",
    "title": "Egypt Law 182 of 2018 Regulating Contracts Concluded by Public Entities (Public Tenders Law)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Egypt Law No. 182 of 2018 on Regulating Contracts Concluded by Public Entities (Qanun Tanzim al-Aqud al-Lati Tubrimuha al-Jihat al-Amma) issued 3 September 2018 and effective 4 October 2018 (with the Executive Regulations issued by Prime Ministerial Decree 692 of 2019 effective 30 March 2019) is the principal Egyptian statute governing procurement of goods, services, contracting works, and consultancy services by public entities including ministries, government departments, public administrative authorities, public service authorities, public-sector companies, and other entities financed by the State budget. Law 182/2018 replaced the prior Law 89 of 1998 (Public Tenders and Auctions Law) and substantially modernised the Egyptian procurement regime aligning with Egypt Vision 2030 and the broader anti-corruption agenda. The Ministry of Finance through the Government Services Sector (Qita al-Khidmat al-Hukumiyya) is the central procurement policy authority. The Egyptian Government Procurement Portal (etenders.gov.eg) is the federal e-procurement platform. Procurement methods established by Law 182/2018 art. 5 comprise (a) General Tender (Munaqasa Aamma, art. 6, the default open public tender), (b) Limited Tender (Munaqasa Mahduda, art. 7, with prequalification), (c) Local Tender (Munaqasa Mahalliyya, art. 8, restricted to local suppliers in prescribed circumstances), (d) Practice (Mumarasa, art. 13, negotiated procedure under prescribed exceptions), (e) Direct Order (Amr Mubasher, art. 13, sole-source under prescribed exceptions including emergency, sole supplier for technical reasons, prior failed tendering, and prescribed-class exemptions), and (f) Two-Stage Tender (art. 9). Law 182/2018 introduced strengthened integrity provisions including supplier debarment, conflict of interest disclosure, anti-bribery commitments, and mandatory beneficial ownership disclosure. The Administrative Prosecution Authority (Niyabat al-Idariyya) has investigative authority over public procurement integrity. Egypt is NOT a party to the WTO Government Procurement Agreement (GPA) but is an observer. Egypt is a party to the African Continental Free Trade Area (AfCFTA), the Greater Arab Free Trade Area (GAFTA), and the UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "egypt-data-protection-law-151-2020",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "eg-pdl-2020",
    "title": "Egypt Personal Data Protection Law No. 151 of 2020",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Egypt's Personal Data Protection Law (PDPL) establishes a comprehensive framework for the processing of personal data of individuals in Egypt, requiring explicit consent for data collection and processing and mandating specific obligations for data controllers and processors, as outlined in Article 2. The law applies to any entity processing personal data of individuals in Egypt, regardless of the entity's location.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "brazil-lgpd-compliance",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eg-pdpl-executive-regulations-2025",
    "title": "Egypt Personal Data Protection Law 151 of 2020 Executive Regulations - Ministerial Decree 816 of 2025, Full Enforcement October 2026",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "Data controllers and processors operating in Egypt must apply the Executive Regulations of the Personal Data Protection Law 151 of 2020, issued by the Minister of Communications and Information Technology as Ministerial Decree 816 of 2025 on 1 November 2025 and published in the Official Gazette and entering into force the day following publication, which detail operational rules for consent, licensing, record-keeping, breach notification, cross-border data transfers, special categories of data, children's data, and direct electronic marketing, with a one-year grace period meaning full enforcement is expected by October 2026, and require clear purpose specification, prior informed consent, purpose-aligned collection and processing, defined and limited retention periods, and confidentiality by design.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "egmont-group-financial-intelligence-unit-standards",
    "title": "Egmont Group Financial Intelligence Unit (FIU) Standards - Information Exchange Requirements, Operational Guidelines, Egmont Secure Web (ESW) SAR Sharing Protocols and FIU Membership Criteria",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-06-28",
    "bluf": "The Egmont Group establishes standards for its member Financial Intelligence Units (FIUs) to facilitate secure, timely, and effective international cooperation in combating money laundering and terrorist financing (ML/TF). This framework mandates the use of the Egmont Secure Web (ESW) for information exchange and requires FIUs to adhere to the 'Principles for Information Exchange' to ensure confidentiality, reciprocity, and proper use of shared intelligence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "bank-secrecy-act-suspicious"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "egypt-central-bank-fintech-law-194-2020",
    "title": "Egypt Central Bank and Banking Sector Law No. 194 of 2020 - Payment Systems, Services and Financial Technology (Part Four)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Law No. 194 of 2020 promulgating the Law of the Central Bank and the Banking Sector is Egypt's comprehensive banking statute (241 articles in seven parts), issued on 15 September 2020 and entering into force the day after publication; it repealed Law No. 88 of 2003 on the Central Bank, the Banking Sector and Monetary System. Part Four (Payment Systems, Services and Financial Technology, Articles 184 onward) provides the statutory basis for fintech and payments supervised by the Central Bank of Egypt (CBE): no person may operate a payment system or provide payment services without a CBE licence (Article 184); the Board of Directors sets licensing conditions and fees (Article 185) and rules for oversight, governance, risk management and client-fund safeguarding (Article 186); payment service providers may use registered agents but remain fully liable for them (Article 189); the CBE may establish a regulatory sandbox and temporarily exempt fintech and regtech pilots from certain licensing requirements (Article 201); the Board sets standards for electronic applications accessing customer accounts at banks or providers (Article 202, the open-banking-style access basis); and issuing, trading, promoting or operating cryptocurrency or electronic-money platforms is prohibited without a Board licence (Article 206). Detailed sandbox, BNPL, open-banking and incident-reporting requirements are set in CBE Board regulations and circulars issued under the Law, not in the Law's articles themselves.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "egypt-data-protection-law-151-2020",
    "title": "Egypt Personal Data Protection Law No. 151 of 2020 and its Executive Regulations",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2024-07-16",
    "bluf": "Egypt's Law No. 151 of 2020 establishes a comprehensive framework for personal data protection, requiring data controllers and processors to adhere to specific processing principles, obtain explicit consent for sensitive data, and register with the Data Protection Center. The law, supervised by the National Telecom Regulatory Authority (NTRA), mandates clear legal bases for processing and outlines obligations for data security and cross-border transfers, as detailed in Articles 2, 12, and 16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "africa-union-cdp-convention-2014",
      "gdpr-article-37-dpo",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "egypt-law-88-2005-entry-residence-foreigners",
    "title": "Egypt Law 88/2005 on Entry and Residence of Foreigners - Residency Permit and Overstay Framework",
    "domain": "Immigration & Border Control",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Egypt's Law No. 88 of 2005 on entry and residence of foreigners (Qanun raqam 88 li-sana 2005 bisha'n tanzim dakhal wa iqama al-ajanib) and its implementing Executive Regulations (Ministerial Decree 1/2006) govern visas, residence permits (iqama) and deportation. Tourist visas (30 days) and short stays are issued on arrival for most nationalities. Longer stays require a residence permit from the Passports, Immigration and Nationality Authority (PINA) at the Ministry of Interior. Residence permit categories include: annual renewable iqama for employment and investment, student iqama and special iqama for property owners. Overstay fines are EGP 1,500/month. Egypt-Arab League workers have facilitated bilateral arrangements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "saudi-arabia-iqama-residence-regulations-jawazat",
      "uae-entry-residence-law-6-1973-ica"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eidas2-regulation-2024-1183-article-12-interoperability-trust-services",
    "title": "Regulation (EU) 2024/1183 - Article 12: Interoperability",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article mandates that trust services must adhere to new interoperability requirements as specified in the amended provisions of Article 12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eidas2-regulation-2024-1183-article-6a-obligations-relying-parties",
    "title": "Regulation (EU) 2024/1183 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework - Article 6a: European Digital Identity Wallets",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article obliges relying parties required to use strong user authentication, and very large online platforms, to accept European Digital Identity Wallets for user authentication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eidas2-regulation-article-11-eu-digital-identity-wallet",
    "title": "Regulation (EU) 2024/1183 on electronic identification and trust services - Article 45k Legal effects of electronic ledgers",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations must recognize that an electronic ledger cannot be denied legal effect or admissibility as evidence in legal proceedings simply because it is in an electronic format or is not a 'qualified' electronic ledger.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eidas2-regulation-article-16-attributes-and-attestations",
    "title": "REGULATION (EU) 2024/1183 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework - Article 16",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that providers of electronic attestations of attributes establish secure and interoperable procedures for issuance, verification, and revocation, ensuring users retain sole control over the sharing of their personal data attributes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eidas2-regulation-article-20-requirements-qualified-electronic-signatures",
    "title": "Regulation (EU) 2024/1183 on electronic identification and trust services for electronic transactions in the internal market (eIDAS 2.0) - Article 20: Requirements for qualified trust service providers",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Qualified trust service providers must undergo and pay for an audit by a conformity assessment body at least every 24 months to confirm compliance with this Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eidas2-regulation-article-25-legal-effects-electronic-signatures",
    "title": "REGULATION (EU) 2024/1183 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework - Article 25: Legal effects of electronic signatures",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes that electronic signatures cannot be denied legal effect simply for being electronic, grants qualified electronic signatures the same legal standing as handwritten signatures, and mandates their recognition across all EU Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eidas2-regulation-article-3-definitions",
    "title": "Regulation (EU) 2024/1183 on electronic identification and trust services (eIDAS 2.0) - Article 3: Definitions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article defines 'electronic identification' as the process of using person identification data in electronic form to uniquely represent a natural or legal person, or a person representing another person or entity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eidas2-regulation-article-30-qualified-electronic-seal",
    "title": "Regulation (EU) 2024/1183 on electronic identification and trust services for electronic transactions in the internal market - Article 30",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations holding a certification for qualified electronic seal creation devices must ensure its validity does not exceed five years, conduct vulnerability assessments every two years, and remedy any identified vulnerabilities to prevent cancellation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eidas2-regulation-article-45-qualified-certificates-for-signatures",
    "title": "REGULATION (EU) 2024/1183 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework - Article 45",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes requirements for qualified certificates for electronic signatures; however, the specific obligations of Article 45 are not present in the provided regulatory text.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eidas2-regulation-article-47-eu-trusted-lists",
    "title": "Regulation (EU) 2024/1183 on European Digital Identity - Article 5d: Publication of a list of certified European Digital Identity Wallets",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article obligates Member States to inform the Commission about certified and cancelled European Digital Identity Wallets, providing specific details, so the Commission can establish, publish, and maintain a public list of these wallets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eidas2-regulation-article-5-electronic-identification-mutual-recognition",
    "title": "REGULATION (EU) 2024/1183 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes the European Digital Identity Framework, intended to provide all Europeans with a trusted, user-controlled digital identity via the European Digital Identity Wallet for secure access to public and private services across the Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eidas2-regulation-article-55-qualified-trust-service-providers",
    "title": "Regulation (EU) 2024/1183 amending Regulation (EU) No 910/2014 - Article 55: Qualified electronic ledgers",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article establishes the requirements for qualified electronic ledgers, which must be managed by qualified trust service providers and ensure the chronological ordering, integrity, origin, availability, and security of data records.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eidas2-regulation-article-6-notification-of-electronic-identification-schemes",
    "title": "REGULATION (EU) 2024/1183 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework - Article 6",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Member States must notify the Commission of their electronic identification schemes, including details on the issuing body, assurance levels, and liability arrangements, for publication and Union-wide recognition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eidas2-regulation-article-71-data-protection",
    "title": "Regulation (EU) 2024/1183 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework - Article 71: Protection of personal data",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations providing European Digital Identity Wallets must implement strict data protection measures, including data separation, purpose limitation for identifiers, and restrictions on data collection and combination, in compliance with GDPR.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eidas2-regulation-article-8-security-breaches-electronic-identification",
    "title": "Regulation (EU) 2024/1183 on European Digital Identity - Article 8: Assurance levels of electronic identification schemes",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "The European Commission is mandated to establish, by means of implementing acts, the minimum technical specifications, standards, and procedures for low, substantial, and high assurance levels for electronic identification means.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eiopa-guidelines-pension-stress-testing-2022",
    "title": "EIOPA Guidelines on Stress Testing for Institutions for Occupational Retirement Provision (IORPs) - 2022 Methodology and Scenarios",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "These guidelines mandate that National Competent Authorities (NCAs) ensure participating Institutions for Occupational Retirement Provision (IORPs) conduct a stress test to assess their resilience against adverse market scenarios, specifically focusing on inflation and interest rate shocks as detailed in the 2022 methodology (Guideline 1). The test requires IORPs to calculate the impact on their balance sheets and funding ratios under both a baseline and an adverse scenario.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "erisa-compliance-rep"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eiti-standard-2023",
    "title": "Extractive Industries Transparency Initiative (EITI) Standard 2023",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The EITI Standard 2023 requires implementing countries and extractive companies to disclose payments, production data, and beneficial ownership information to promote transparency and accountability in oil, gas, and mining sectors. Key requirements are established under EITI Requirements Section 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp",
      "un-sdg-corporate-mapping"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eiti-standard-2023-extractive-industries-transparency",
    "title": "EITI Standard 2023 - Extractive Industries Transparency Initiative Disclosures, Validation and Subnational Reporting",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Extractive Industries Transparency Initiative (EITI) Standard 2023 is the global voluntary standard for transparent and accountable management of oil, gas, and mineral resources. Adopted by the EITI Members at the 2023 EITI Global Conference and updated from the 2019 Standard, the 2023 Standard requires Implementing Country and Supporting Company disclosures across 8 thematic areas. Requirement 2 covers legal and institutional framework (license terms, ownership, contracts). Requirement 3 covers exploration and production (including project-level reporting). Requirement 4 covers revenue collection (payments, transfers, tax expenditure). Requirement 5 covers revenue allocations (sovereign wealth funds, subnational transfers). Requirement 6 covers social and environmental spending. Requirement 7 covers economic contribution (employment, value added). Requirements 1 and 8 cover multi-stakeholder oversight and effectiveness/disclosure systems. EITI Implementation requires Multi-Stakeholder Group (MSG) with government, industry, and civil society representation. EITI Validation under the 2023 Validation Model assesses progress against three components: Disclosures, Stakeholder Engagement, and Outcomes & Impact. As of 2024, 57 countries implement EITI with over 130 supporting companies and major investors. Beneficial ownership disclosure (Requirement 2.5) is mandatory.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-critical-raw-materials-act-2024-1252-strategic-projects",
      "iso-14046-2014-water-footprint-mining"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ema-guidelines-advanced-therapy-quality-2019",
    "title": "Guideline on Quality, Non-Clinical and Clinical Requirements for Marketing Authorisation of Advanced Therapy Medicinal Products",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This guideline sets out the quality, non-clinical, and clinical requirements for marketing authorisation of advanced therapy medicinal products (ATMPs) in the European Union, including gene therapy, somatic cell therapy, and tissue-engineered products, under Regulation (EC) No 1394/2007, Article 8. It applies to all applicants seeking centralised authorisation via the European Medicines Agency (EMA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-qms",
      "ich-gcp-e6-r3-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ema-gvp-module-v-risk-management-systems-2014",
    "title": "EMA Good Pharmacovigilance Practices Module V - Risk Management Systems 2014",
    "domain": "Biotech & Genomics",
    "version": "2017-11",
    "last_updated": "2026-05-09",
    "bluf": "EMA Good Pharmacovigilance Practices (GVP) Module V (Revision 2, 2017) requires marketing authorisation holders of EU medicinal products to maintain a Risk Management System throughout the product lifecycle, submitting and updating a Risk Management Plan documenting safety specifications, pharmacovigilance plans, and risk minimisation measures including additional measures such as educational programmes and restricted access schemes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ema-centralised-procedure-regulation-726-2004",
      "eu-gdpr-health-data-article-9"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "en-1998-eurocode-8-seismic-design",
    "title": "Eurocode 8: Design of structures for earthquake resistance - Part 1: General rules, seismic actions and rules for buildings (EN 1998-1:2004)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Eurocode 8 (EN 1998) requires that buildings and civil engineering works in seismic regions be designed and constructed to withstand specified earthquake actions without collapse, ensuring life safety and limiting structural damage. This is achieved by applying principles of capacity design, ductility, and energy dissipation, as detailed in Clause 2.1 (Fundamental Requirements) and Clause 4.4 (Design Criteria).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "enisa-ai-cybersecurity-guidelines-2023",
    "title": "ENISA Guidelines on AI Cybersecurity for the EU AI Act - Compliance Obligations for EU AI System Cybersecurity Controls, AI Attack Surface Mapping, and ENISA Technical Guidelines for Article 15 Cybersecurity Requirements",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines ENISA's cybersecurity guidelines for AI systems under the EU AI Act, focusing on compliance with Article 15 cybersecurity requirements, AI attack surface mapping, and multilayered security controls. It aligns with the EU AI Act (Regulation 2024/1689) and integrates with frameworks like NIST AI RMF 1.0 and ISO/IEC 42001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "enisa-cloud-security-compliance-2026-14",
    "title": "ENISA Cloud Security Enterprise Compliance Standard v14",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "The ENISA Cloud Security Enterprise Compliance Standard v14 outlines essential requirements for organizations utilizing cloud services to ensure robust cybersecurity measures. It emphasizes risk management, data protection, and incident response strategies tailored for cloud environments. Key areas include the implementation of security controls, continuous monitoring, and compliance with relevant legal frameworks. Organizations must conduct regular assessments to identify vulnerabilities and ensure that cloud service providers adhere to security best practices. The standard also highlights the importance of user awareness and training, as well as the necessity for clear governance structures to manage cloud security effectively. By adhering to these guidelines, organizations can enhance their resilience against cyber threats and maintain trust with stakeholders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "enisa-cloud-security-guidelines-2023",
    "title": "ENISA Good Practices for Security of Cloud Services",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This ENISA publication provides a comprehensive set of 263 good practice security measures across 11 domains for Cloud Service Providers (CSPs) and their customers to secure cloud services. It serves as a voluntary guide, aligning with the EU's cybersecurity framework, to address threats related to misconfigurations, access control, and insecure interfaces, as detailed in the report's introduction and threat landscape analysis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27017-cloud-controls",
      "nist-sp-800-145-cloud-computing",
      "nist-800-61-incident-resp"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "enisa-threat-landscape-2024",
    "title": "ENISA Threat Landscape 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The ENISA Threat Landscape 2024 is an annual intelligence report identifying the top 8 cybersecurity threats to the European Union, requiring organizations to use this analysis for their risk assessments and to prioritize security controls. The report highlights ransomware, AI abuse, and supply chain attacks as prime threats impacting critical sectors, as detailed in the 'Key Findings' section.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cisa-ms-isac-ransomware-guide",
      "c-scrm-practices-systems-organizations",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "environmental-noise-dir",
    "title": "Environmental Noise Directive",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with Directive 2002/49/EC, the Environmental Noise Directive (END), mandates a common framework for managing environmental noise to mitigate its adverse health effects. This obligation requires competent authorities to produce strategic noise maps for population agglomerations exceeding a 100,000 inhabitant threshold, major roads with traffic volumes over 3,000,000 vehicles per year, major railways seeing more than 30,000 train passages annually, and major airports with over 50,000 movements yearly. These maps must utilize the common assessment methods established in Commission Directive (EU) 2015/996 (CNOSSOS-EU), employing Lden and Lnight noise indicators. The assessment of harmful effects, as amended by Commission Directive (EU) 2020/367 and guided by World Health Organization evidence, specifically targets populations exposed to levels above an Lden indicator threshold of 55 dB and an Lnight indicator of 50 dB. Based on mapping results, a noise action plan is required, demanding the development of plans to manage noise issues. This process legally necessitates public consultation for transparency and also mandates that quiet areas preservation is addressed within these plans. The entire cycle of mapping and action planning operates on a reporting frequency of five years, with mandatory data submission to the European Environment Agency according to Regulation (EU) 2019/1010 and EEA Reportnet 3.0 guidelines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "csrd-eu-sustainability",
      "eu-taxonomy-sustainable",
      "iso-31000-risk-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "enx-tisax-automotive-information-security-assessment",
    "title": "TISAX - Trusted Information Security Assessment Exchange for the Automotive Industry (ENX Association / VDA ISA)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "TISAX, the Trusted Information Security Assessment Exchange, is the automotive industry mechanism for assessing and exchanging information security assessment results, governed by the ENX Association. The assessment basis is the Information Security Assessment (ISA) catalogue developed by the German Association of the Automotive Industry (Verband der Automobilindustrie, VDA) working group to tailor existing information security standards to automotive-specific needs. Participation follows three stages: registration (gathering company information and defining the assessment scope), assessment (conducted by approved TISAX audit providers), and exchange (sharing results with partners inside the TISAX community; results are used only within this closed community of trust and not published to the general public). Assessments are performed at defined assessment levels: AL 1 is a self-assessment only and is not used for TISAX labels; AL 2 involves plausibility checks with evidence review and interviews, typically via web conference; AL 3 is a comprehensive verification including on-site activities, document examination and interviews. Successful assessment against the selected assessment objectives leads to TISAX labels covering information security (including information with high and very high protection needs, and confidential and strictly confidential information), availability (high and very high), prototype protection (including proto parts, proto vehicles, test vehicles and events), and data protection objectives aligned to Article 28 GDPR processor requirements. TISAX assessment results are valid for three years. Automotive OEMs and tier suppliers require valid TISAX labels from suppliers and service providers handling protected information, making TISAX a de facto market-access requirement in the automotive supply chain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "vda_isa_basis",
        "iso_27001_relationship",
        "gdpr_article_28_anchor",
        "assessment_levels",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vda-6-3-2023-process-audit-standard",
      "gdpr-article-28-processor-obligations-and-contracts",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eprivacy-cookie-directive",
    "title": "ePrivacy (Cookie Directive)",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the ePrivacy Directive mandates a strict consent-first framework for accessing or storing information on user terminal equipment, directly reflecting Article 5(3) of Directive 2002/58/EC. This node operationalizes such a requirement by enforcing that `require_prior_consent_non_essential` is true for all non-essential cookies and tracking technologies. By default, `default_non_essential_status` must be false, ensuring no data processing occurs without user affirmation. Exceptions are narrowly defined: the system will `allow_strictly_necessary_without_consent` for essential functions and also `exempt_transmission_communication_cookies`. The standard for valid consent, as clarified by Recital 66 of Directive 2009/136/EC and the Court of Justice of the European Union's Planet49 judgment, is high, demanding that a `require_explicit_opt_in_action` be configured. Consequently, the system must `prohibit_pre_ticked_boxes`. In line with EDPB Guidelines 05/2020, passive actions like scrolling do not constitute valid affirmative action. To uphold confidentiality of communications per Article 5(1) and address joint controllership liabilities from the Fashion ID case, it is imperative to `block_third_party_scripts_pre_consent`. User control is paramount, necessitating configurations to `enable_granular_consent_categories` and `require_easy_consent_withdrawal`. All consent events must `log_consent_audit_trail` for demonstrability, with a maximum validity period set at a `cookie_consent_validity_days_max` of 180 days before re-consent is necessary.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-art-21-marketing-optout",
      "iab-tcf-v2-2-consent",
      "can-spam-act-email",
      "ccpa-cpra-optout-sale",
      "casl-anti-spam-canada"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "er-moict-framework",
    "title": "Eritrea MOICT Framework - AU Malabo Convention and Constitutional Privacy Obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Eritrea's Ministry of Information and Communication Technology (MOICT) oversees the regulation of telecommunications and ICT services in the State of Eritrea. The Eritrean Ratified Constitution of 1997 establishes fundamental rights including the inviolability of private life and correspondence, and the right to personal liberty and dignity; however, this Constitution has not been implemented and Eritrea operates under a system of rule by Presidential Decree and a series of Proclamations governing economic and regulatory matters. Eritrea does not have a standalone comprehensive personal data protection law. As a member state of the African Union, Eritrea is nominally subject to the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014), which provides the applicable regional standard for personal data protection in Africa. The telecommunications sector is regulated under the Eritrean Telecommunications Services Corporation (EriTel), the state-owned telecommunications operator. Organisations processing personal data in Eritrea must recognise the significant governance and compliance risks associated with operations there, including the absence of independent judicial oversight, the highly restrictive regulatory environment, and the limited rule of law. Legal counsel familiar with the specific operational context in Eritrea should be engaged before commencing personal data processing operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/er-moict-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "erisa-compliance-rep",
    "title": "ERISA (Retirement Security)",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with the Employee Retirement Income Security Act (ERISA) mandates a rigorous adherence to specific fiduciary, participation, vesting, reporting, and bonding standards to protect plan participants and beneficiaries. Plan fiduciaries must formally acknowledge their duty to act with the care, skill, and diligence of a prudent expert under 29 U.S.C. § 1104(a)(1)(B), a responsibility that now extends to maintaining robust cybersecurity controls as guided by the DOL EBSA. This includes conducting an annual cyber risk assessment, auditing third-party vendors, and enforcing multi-factor authentication for participant access. The plan's minimum participation standards are met, allowing employees entry upon attaining the maximum eligibility age of 21 and completing 1,000 minimum hours of annual service, consistent with 29 U.S.C. § 1052(a)(1)(A). Vesting schedules conform to 29 U.S.C. § 1053(a)(2)(B) by utilizing a maximum three-year cliff vesting period. Critical reporting and disclosure obligations are fulfilled through the annual filing of Form 5500 as required by 29 U.S.C. § 1023, and the proper distribution of a Summary Plan Description to all participants per 29 U.S.C. § 1022(a). Furthermore, the plan is secured by a fidelity bond in accordance with 29 U.S.C. § 1112(a), covering at least the minimum ten percent of funds handled, subject to a $500,000 maximum amount.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ebsa-cybersecurity-best-practices",
      "flsa-compliance-labor",
      "fmla-compliance-leave",
      "eeoc-employment-rule",
      "iso-45001-work-safety"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "es-aesia-ai-supervision-agency-2024",
    "title": "Spain AESIA Agencia Espanola de Supervision de Inteligencia Artificial - First EU National AI Supervisory Authority, Operational from 19 June 2024",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Organisations deploying AI in Spain subject to the EU AI Act must engage with the Agencia Espanola de Supervision de la Inteligencia Artificial (AESIA), the first European national agency dedicated to AI supervision (announced 22 August 2023, operational from 19 June 2024, headquartered in La Terraza building in La Coruna, Galicia), which acts as Spain's central market-surveillance authority for AI, supervises high-risk AI systems under the European AI Regulation, coordinates with other market surveillance authorities, promotes standards and best practices, evaluates AI models, and exercises inspection authority for prohibited practices from 2 February 2025 and full sanctioning authority for the EU AI Act from 2 August 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-automated-decision-workflows"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "es-ens-real-decreto-311-2022-esquema-nacional-seguridad",
    "title": "Spain ENS - Real Decreto 311/2022 Esquema Nacional de Seguridad (National Security Scheme)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "Real Decreto 311/2022, de 3 de mayo, regulates the Esquema Nacional de Seguridad (ENS), the Spanish National Security Scheme established in Article 156.2 of Ley 40/2015, and lays down the principios basicos y requisitos minimos (basic principles and minimum requirements) for the protection of information and services handled by public sector information systems. Published in BOE numero 106 of 4 May 2022 and in force from 5 May 2022, the ENS applies to the entire Spanish public sector as defined in Article 2 of Ley 40/2015 and also applies to the information systems of private sector entities when they provide services to public entities for the exercise of their administrative competences and powers; contracts with such suppliers must include all requirements necessary to ensure conformity with the ENS. Article 5 sets seven basic principles: seguridad como proceso integral (security as an integral process); gestion de la seguridad basada en los riesgos (risk-based security management); prevencion, deteccion, respuesta y conservacion (prevention, detection, response and preservation); existencia de lineas de defensa (existence of lines of defence); vigilancia continua (continuous monitoring); reevaluacion periodica (periodic re-evaluation); and diferenciacion de responsabilidades (differentiation of responsibilities). Systems are categorized under Article 40 and Annex I into the categories BASICA, MEDIA and ALTA based on the impact of security incidents on the organization objectives, assets and service continuity, and the security measures of Annex II are organized into the marco organizativo (organizational framework), marco operacional (operational framework) and medidas de proteccion (protection measures). Under Article 38, systems in categories MEDIA and ALTA require an audit for certification of conformity, while BASICA systems require a self-assessment for the declaration of conformity, and conformity declarations and certifications must be published. ENS conformity has become the gate for supplying cloud and IT services to Spanish public administrations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "legal_basis_anchor",
        "scope_private_suppliers",
        "categorization_model",
        "conformity_model",
        "peer_schemes_crosswalk",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "es-lopdpgdd-2018",
      "es-ley-9-2017-contratos-sector-publico",
      "eu-nis2-directive-2022-2555-critical-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "es-ley-10-2010-prevencion-blanqueo-capitales",
    "title": "Ley 10/2010 de prevencion del blanqueo de capitales y de la financiacion del terrorismo",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Spain's Ley 10/2010 sets out AML/CFT obligations for obliged entities. Article 1.2 defines money laundering (blanqueo de capitales) as the conversion or transfer of property knowing it derives from criminal activity; Article 3 requires customer due diligence and formal identification; Article 4 requires identification of the beneficial owner (more than 25 percent ownership or control); Article 18 requires reporting of suspicious operations to SEPBLAC; and Article 25 requires record keeping for ten years. Content is provided in English ASCII.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "es-ley-3-1991-competencia-desleal",
    "title": "Spain Ley 3/1991 de Competencia Desleal",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Ley 3/1991, de 10 de enero, de Competencia Desleal (LCD) is Spain's principal Unfair Competition Act, in force from 31 January 1991 and substantially amended in 2009 to transpose the EU Unfair Commercial Practices Directive 2005/29/EC. The Law is organised into five Chapters. Capitulo I (Arts. 1-3) contains general provisions on the purpose of the law, its market-activity scope and its broad personal application. Capitulo II (Arts. 4-18) defines acts of unfair competition - including Art. 4 the cláusula general prohibiting conduct objectively contrary to good faith, Art. 5 acts of deception, Art. 6 acts of confusion, Art. 7 deceptive omissions and Art. 8 aggressive practices. Capitulo III (Arts. 19-31) regulates pra-cticas comerciales con los consumidores or usuarios applying the UCPD black-list rules. Capitulo IV (Arts. 32-36) governs the legal actions available against unfair competition, with Art. 32 enumerating declaratory, cessation, removal-of-effects, rectification, damages and unjust enrichment remedies. Capitulo V regulates codes of conduct and industry self-regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "es-ley-34-1988-general-publicidad",
      "us-ftc-cfr-16-part-255-endorsement-testimonials-advertising"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "es-ley-34-1988-general-publicidad",
    "title": "Spain Ley 34/1988 General de Publicidad",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Ley 34/1988, de 11 de noviembre, General de Publicidad establishes the general legal framework for advertising activity in Spain. The Law is organised into four Titulos: Titulo I (Disposiciones Generales) covers scope, definitions and the relationship with related rules; Titulo II (De la publicidad ilicita y de las acciones para hacerla cesar) defines and prohibits unlawful advertising; Titulo III (De la contratacion publicitaria) regulates advertising contracts between advertisers, agencies and media; Titulo IV (De la accion de cesacion y rectificacion) was repealed by Ley 29/2009 with these actions now governed by the Ley de Competencia Desleal regime. Article 1 establishes the scope, providing that publicidad is governed by this Law, by the Ley de Competencia Desleal and by sector-specific rules. Article 2 defines publicidad as any form of communication realised by a natural or juridical person, public or private, in the exercise of a commercial, industrial, artisanal or professional activity, with the purpose of promoting directly or indirectly the contracting of goods or services. Article 3 lists categories of publicidad ilicita (advertising that infringes constitutional values and rights, misleading advertising, unfair advertising, aggressive advertising, subliminal advertising and breaches of sector-specific rules). Article 5 establishes sector-specific advertising restrictions for products such as medicinal products, tobacco, alcoholic beverages and dangerous activities. Article 6 governs the remedies regime through the Ley de Competencia Desleal. Article 8 defines the contractual subjects (anunciantes, agencias de publicidad, medios de publicidad).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-product-liability-directive-2024-2853",
      "us-ftc-cfr-16-part-255-endorsement-testimonials-advertising"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "es-ley-9-2017-contratos-sector-publico",
    "title": "Spain Ley 9/2017 de Contratos del Sector Público (LCSP)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Ley 9/2017, de 8 de noviembre, de Contratos del Sector Publico (LCSP) is Spain's consolidated public procurement statute, in force from 9 March 2018 and transposing EU Directives 2014/23/EU and 2014/24/EU. The Act is structured in four Libros: Libro Primero (general configuration and structural elements), Libro Segundo (contract preparation, contractor selection and adjudication, performance and termination), Libro Tercero (contracts by non-Administration public sector entities) and Libro Cuarto (administrative organisation for contract management). Art. 1 establishes the objeto and the principles of libertad de acceso, publicidad, transparencia, no discriminacion and uso eficiente de los fondos publicos. Art. 28 confirms the principios of public procurement. Art. 65 enumerates the procedural modalities: procedimiento abierto (open), procedimiento restringido (restricted), procedimiento negociado (negotiated), dialogo competitivo (competitive dialogue) and asociacion para la innovacion (innovation partnership). Art. 71 lists the prohibiciones para contratar. Art. 145 governs criterios de adjudicacion. Arts. 159 and 167 detail the open and restricted procedures. Art. 198 establishes payment terms. Art. 326 governs subastas electronicas. Art. 332 governs modificacion del contrato. Review is before the Tribunal Administrativo Central de Recursos Contractuales (TACRC) for state-level contracts and equivalent regional bodies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-directive-2014-23-concession-contracts",
      "eu-directive-2014-25-utilities-procurement"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "es-lopdpgdd-2018",
    "title": "Spain Data Protection and Digital Rights Act 2018 (LOPDPGDD) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Spain's Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales - LOPDPGDD), published in the Official State Gazette (BOE) No. 294 on 6 December 2018 and entering into force on 7 December 2018, is Spain's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Spain. The GDPR is directly applicable Spanish law by virtue of Spain's EU membership; the LOPDPGDD repeals the prior Spanish data protection law (LOPD, Ley Orgánica 15/1999) and provides national derogations and additions. A distinctive feature of the LOPDPGDD compared to other EU GDPR national implementations is its Chapter XI, which establishes a catalogue of digital rights in the workplace and online that go beyond GDPR - including the right to digital disconnect (derecho a la desconexión digital), the right to privacy in the use of digital devices in employment, the right to digital will (derechos digitales en el testamento - posthumous data rights), and the right to digital neutrality (neutralidad en Internet). Enforcement: Agencia Española de Protección de Datos (AEPD) is Spain's independent data protection supervisory authority. The AEPD is Spain's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Spanish national provisions: (1) Age of digital consent: Spain has set the age of consent for information society services at 14 years (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 14 require parental or guardian consent; (2) Digital rights in employment - employers must have a policy on digital device use and inform employees of monitoring scope; the right to digital disconnection requires employers to have an internal policy allowing employees to disconnect from digital communications outside working hours; (3) Right to digital will (testamento digital) - the LOPDPGDD allows the family of a deceased person to instruct data controllers to delete or transfer the deceased's personal data; (4) Whistleblower channels - the LOPDPGDD provides specific provisions on internal whistleblowing channels and their data protection implications; (5) Criminal data - restrictions on processing personal data relating to criminal convictions and offences; (6) Scientific research and statistics: specific provisions permitting extended processing with appropriate safeguards. Fines: GDPR administrative fines apply in Spain - up to EUR 20 million or 4% of global annual turnover for the most serious violations. The AEPD has been one of the most active EU DPAs, with major fines against Google Spain, BBVA, Amazon Spain Services, and Vodafone Spain, as well as enforcement across telecommunications, financial services, and political data processing sectors. The AEPD has also published specific guidance on data processing in political activities, election campaigns, and social media analytics.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "es-rdl-1-2007-defensa-consumidores",
    "title": "Spain Real Decreto Legislativo 1/2007 - Texto Refundido de la Ley General para la Defensa de los Consumidores y Usuarios (TRLGDCU)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Real Decreto Legislativo 16 noviembre 2007 n. 1 aprueba el Texto Refundido de la Ley General para la Defensa de los Consumidores y Usuarios (TRLGDCU), in force from 1 December 2007 and updated through 28 February 2026. The consolidated text is organised in four Libros: Libro I (general provisions, basic rights and information duties), Libro II (private contractual relations including distance and off-premises contracts, unfair terms and conformity guarantees), Libro III (product liability transposing Directive 85/374/CEE as recast by 2024/2853/UE), and Libro IV (package travel and linked travel arrangements). Art. 1 sets the regime juridico. Art. 3 defines consumidor as a natural person acting outside their commercial or professional activity. Art. 8 lists basic consumer rights (health and safety, economic and social, information, representation, judicial protection). Art. 18 governs etiquetado y presentacion to prevent consumer deception. Arts. 19-20 regulate commercial practices alongside the UCPD transposition. Arts. 60-67 set pre-contractual information duties. Arts. 68-79 establish the 14-day derecho de desistimiento for distance and off-premises contracts (with the unilateral 12-month extension under Art. 71 when information is omitted). Arts. 80-90 govern non-negotiated clauses and the abusiveness assessment. Arts. 114-127 set the legal conformity guarantee. Arts. 128-149 implement product liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011-83-eu",
      "eu-unfair-commercial-practices-2005-29-2022-revision",
      "eu-product-liability-directive-2024-2853"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "es-real-decreto-750-2010-homologacion-vehiculos",
    "title": "Spain Real Decreto 750/2010 - Reglamento de Homologación de Vehículos Sistemas Partes y Piezas y Conformidad de la Producción",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-29",
    "bluf": "Spain Real Decreto 750/2010 establishes the national homologation framework for vehicles systems parts and components through six Capítulos covering disposiciones generales in Articulos 1 to 3 homologación de vehículos sistemas partes y piezas in Articulos 4 to 6 ensayos de homologación in Articulos 7 and 8 conformidad de la producción in Articulos 9 and 10 servicios técnicos e inspección in Articulos 11 and 12 and régimen sancionador in Articulo 13. The Ministerio de Industria Turismo y Comercio acts as authority of homologation under Articulo 2.14 with four approval modalities including national type approval national small series individual approval and EC type approval and the Real Decreto incorporates Directives 2002/24/CE 2003/37/CE and 2007/46/CE now superseded by Reglamento (UE) 2018/858.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-type-approval-regulation-2018-858",
      "un-regulation-155-vehicle-cybersecurity",
      "un-regulation-156-software-updates-ota"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "esa-convention-1975-european-space-agency",
    "title": "Convention for the establishment of a European Space Agency (CSE/CS(73)19, rev.7)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes the European Space Agency and governs Member State contributions to mandatory and optional programmes, the structure of the Ministerial Council, industrial policy including the geographical return principle, intellectual property ownership of ESA developments, and the relationship with the EU space programme. Key provisions are defined in Article XVI and associated Resolutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "un-rescue-agreement-1968-astronauts"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "esa-essb-st-u-007-space-debris-mitigation-policy",
    "title": "ESA Space Debris Mitigation Policy and Requirements (ESSB-ST-U-007)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2023-03-28",
    "bluf": "The European Space Agency Space Debris Mitigation Policy and Requirements is an ESA Standardisation Board Standard (ESSB-ST-U-007 Issue 1) issued on 28 March 2023 and applies to all new ESA projects starting at Phase A and to existing ESA missions where technically and programmatically feasible. The Standard implements the ESA Space Debris Mitigation Policy approved by the ESA Director General and supersedes the previous ESA Requirements for Space Debris Mitigation (ESSB-ST-U-004 Issue 1). The Standard is consistent with the IADC Space Debris Mitigation Guidelines (2007 as revised), the UN COPUOS Long-Term Sustainability Guidelines (2019), and ISO 24113 (Space Systems - Space Debris Mitigation Requirements).\n\nKey technical provisions include: 25-year maximum orbital lifetime baseline for objects passing through Low Earth Region with operational provisions to align with the post-2024 5-year ambition; protection of the geostationary protected region with re-orbiting to graveyard orbits at least 235 km above the GEO ring; controlled re-entry casualty risk of less than 1 in 10,000; passivation of stored on-board energy at end of mission to prevent breakup; and on-orbit collision avoidance manoeuvres when the probability of collision exceeds 1 in 10,000. The Standard requires a Space Debris Mitigation Plan to be prepared at Phase B with technical justification at major milestones and a final Disposal and Reentry Verification Report. The Standard applies to ESA-developed and ESA-procured space systems and is referenced by ESA contracts as a mandatory technical requirement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iadc-space-debris-mitigation-guidelines-2007",
      "un-copuos-space-debris-mitigation-guidelines-2007",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "esa-zero-debris-charter-2023-space-safety",
    "title": "European Space Agency Zero Debris Charter (2023)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2023-06-22",
    "bluf": "The European Space Agency Zero Debris Charter is a voluntary multi-stakeholder commitment launched on 22 June 2023 at the Paris Air Show. The Charter sets out the ambition of being debris neutral in space by 2030 and is signed by space agencies, satellite operators, launch service providers, and component manufacturers. Signatories commit to a set of jointly developed technical and operational targets including post-mission disposal success rates, collision avoidance manoeuvre transparency, and active debris removal participation. The Charter is administered by ESA's Space Safety Programme and is open for signature by any organisation in the space sector worldwide.\n\nThe Charter's core targets are: 99 percent post-mission disposal success for all space objects with a minimum five-year disposal window; less than one percent residual orbital decay risk for launchers and upper stages; coordinated conjunction screening using accredited space situational awareness data; and active participation in active debris removal and on-orbit servicing missions. Signatories also commit to following the ESA Space Debris Mitigation Policy (ESSB-ST-U-007), the IADC Space Debris Mitigation Guidelines (2007 as updated), and the UN COPUOS Long-Term Sustainability Guidelines (2019). The Charter is complementary to legally binding national space laws and does not displace state obligations under the Outer Space Treaty 1967, the Liability Convention 1972, or national implementing legislation. As of May 2026, the Charter has been signed by over 100 organisations including national space agencies of ESA member states, major satellite operators, and commercial launch service providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iadc-space-debris-mitigation-guidelines-2007",
      "un-copuos-space-debris-mitigation-guidelines-2007",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "esma-ai-machine-learning-supervisory-convergence-2023",
    "title": "ESMA AI and Machine Learning in Financial Markets - Supervisory Convergence and Compliance Obligations for AI Model Risk in Capital Markets, Algorithmic Trading Governance, and AI Disclosure Requirements",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-07-03",
    "bluf": "This node outlines ESMA's supervisory convergence framework for AI and machine learning in financial markets, focusing on AI model risk management, algorithmic trading governance under MiFID II, and disclosure obligations aligned with EU AI Act Article 50 transparency obligations for providers and deployers of certain AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "espoo-convention-1991-transboundary-eia",
    "title": "Espoo Convention 1991 - Environmental Impact Assessment in a Transboundary Context",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Espoo Convention (Convention on Environmental Impact Assessment in a Transboundary Context, 1991 - 45 Parties as of April 2026, UNECE region) requires States to assess the environmental impacts of proposed activities likely to cause significant adverse transboundary effects before authorising them, and to notify and consult with the affected States; project developers and competent authorities must identify transboundary impacts at EIA screening stage, notify affected Party States, allow public participation in affected countries, and share the EIA documentation - non-compliance exposes project permits to legal challenge in both the originating and affected State and, for EU-based projects, triggers violation of EU EIA Directive 2014/52/EU obligations which incorporate Espoo Convention requirements directly.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aarhus-convention-1998-environmental-access",
      "eu-eia-directive-2014-52-environmental-assessment",
      "un-paris-agreement-ndc-implementation-guidelines",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "esrb-entertainment-software-rating-board-us",
    "title": "ESRB Entertainment Software Rating Board - US Video Game Age Ratings and Content Labeling",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "The Entertainment Software Rating Board (ESRB) is the United States self-regulatory body that assigns age-based ratings (Everyone, Everyone 10+, Teen, Mature 17+, Adults Only 18+, and Rating Pending) together with content descriptors and interactive-element notices to physical and digital video games. Publishers submit games for rating, must display the assigned rating and content/interactive-element labels on packaging and digital storefronts, must disclose in-game purchases (including random-item loot boxes), and must follow ESRB advertising and marketing principles. For digital storefronts the ESRB issues ratings through the International Age Rating Coalition (IARC) questionnaire.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pegi-pan-european-game-information-system",
      "eu-dsa-platform-obligations-gaming-2022",
      "us-ftc-loot-boxes-children-coppa-guidance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "estonia-gambling-act-hasartmanguseadus-2008-mta",
    "title": "Estonia Gambling Act 2008 (Hasartmanguseadus) - Maksu- ja Tolliamet (MTA) Licensing Framework",
    "domain": "Gaming & Gambling",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Estonia's Gambling Act (Hasartmanguseadus, RT I 2008, 47, 261, in force 1 January 2009) established one of the European Union's first comprehensively regulated online gambling frameworks. The Maksu- ja Tolliamet (MTA - Tax and Customs Board) under the Ministry of Finance is the sole licensing authority for all gambling activities. Five activity licence types are recognised: traditional casino (maakassiino), remote casino (maakassiino kaughasartmang), totalisator betting, remote totalisator, and lottery. Remote gambling operators must maintain their gambling servers on Estonian or EEA territory. The minimum gambling age is 21 years for all product types. Gambling tax (hasartmangumaks) is levied on gross gambling revenue at 5%. All licensed operators must integrate with the national self-exclusion register (Mangusooltuvuse Register) and check player eligibility before permitting play. AML/CTF obligations under the Rahapesu ja terrorismi rahastamise tormistamise seadus (AMLTFPA) apply to all operators. MTA supervises compliance and may revoke activity licences, impose financial penalties, or suspend operations for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_article",
        "aml",
        "eu_services",
        "fatf_recommendation",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "et-computer-crime-proclamation-2016",
    "title": "Ethiopia Computer Crime Proclamation No. 958/2016",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Ethiopia's Computer Crime Proclamation No. 958/2016, enacted in 2016, establishes cybercrime offences including illegal access to computer systems, illegal interception, data interference, computer fraud, identity theft, and dissemination of offensive content, places the Information Network Security Administration as the primary cybersecurity authority for critical infrastructure protection in Ethiopia, and imposes imprisonment penalties ranging up to 15 years for serious offences against critical infrastructure or government computer systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/et-computer-crime-proclamation-2016.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "et-pdp-proclamation-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "et-pdp-proclamation-2022",
    "title": "Ethiopia Personal Data Protection Proclamation No. 1321/2024",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Ethiopia enacted the Personal Data Protection Proclamation No. 1321/2024 (passed 4 April 2024 and gazetted in the Negarit Gazeta on 24 July 2024), establishing the first comprehensive data protection framework in the country. The supervisory and enforcement authority under the Proclamation is the Ethiopian Communications Authority (ECA), established under the Communications Service Proclamation No. 1148/2019. The Proclamation grants data subjects rights of access, rectification, erasure, and objection to processing. Controllers must identify a lawful basis for processing (consent, contract, legal obligation, vital interests, or legitimate interests), implement security safeguards, and restrict cross-border transfers to jurisdictions with adequate protection or with appropriate safeguards. Sensitive categories of personal data require explicit consent. Breach notification obligations apply where a breach is likely to result in high risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/et-pdp-proclamation-2022.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "et-public-procurement-property-administration-proclamation-1230-2020-ppa-fppa",
    "title": "Ethiopia Federal Public Procurement and Property Administration Proclamation 1230/2020 of 22 May 2020 and PPPDS",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Federal Democratic Republic of Ethiopia Public Procurement and Property Administration Proclamation No. 1230/2020 (Federal Negarit Gazette No. 32 of 22 May 2020) effective 22 May 2020 is the principal Ethiopian federal statute governing procurement of goods, works, and services and the administration of public property by federal public bodies including federal ministries, federal agencies and authorities, federal autonomous public enterprises, federal universities and public institutions, and other federal public bodies. Proclamation 1230/2020 replaced the prior Public Procurement and Property Administration Proclamation No. 649/2009 and substantially modernised the Ethiopian federal procurement regime aligning with Ethiopia's Homegrown Economic Reform and the broader public sector reform agenda. The Public Procurement and Property Administration Agency (PPPAA / Federal Public Procurement and Property Administration Agency) is the central regulatory authority responsible for procurement regulation, oversight, supplier debarment, and procurement guidance. The Government Procurement Information System (eGP / pppds.gov.et) is the federal e-procurement platform under rollout. The Procurement and Property Disposal Service (PPDS) provides centralised procurement services for federal public bodies. Procurement methods established by Proclamation 1230/2020 art. 49 to 67 comprise (a) Open Bidding (default open public procedure, both Open National Competitive Bidding and Open International Competitive Bidding), (b) Restricted Bidding (with prequalification), (c) Direct Procurement (sole-source under prescribed exceptions in art. 51 including emergency, sole supplier for technical reasons, prior failed tendering, additional procurement under existing contract, and prescribed-class exemptions), (d) Request for Quotations (for medium-value acquisitions), (e) Request for Proposals (for consulting services), (f) Two-Stage Bidding (for complex acquisitions), (g) Framework Agreements, and (h) Electronic Reverse Auction. The Federal Auditor-General conducts ex-post procurement audit. Regional state procurement is governed by parallel regional procurement laws. Ethiopia is NOT a party to the WTO Government Procurement Agreement (GPA) but is in WTO accession process. Ethiopia is a party to the African Continental Free Trade Area (AfCFTA), the Common Market for Eastern and Southern Africa (COMESA), and UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "et-pdp-proclamation-2022",
      "et-computer-crime-proclamation-2016",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ethereum-eip-4337",
    "title": "Account Abstraction (EIP-4337)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "EIP-4337 (Account Abstraction Using Alt Mempool) is an Ethereum Improvement Proposal finalized in March 2023 that enables programmable smart contract wallets to replace externally owned accounts (EOAs) as the primary transaction signing mechanism, without requiring changes to the Ethereum protocol consensus layer. The standard introduces a new transaction object called a UserOperation, a permissionless Bundler network that aggregates UserOperations into standard transactions, a singleton EntryPoint contract that validates and executes UserOperations, and a Paymaster contract that enables third-party gas sponsorship. For AI agents, EIP-4337 is foundational because it enables agents to operate programmable wallets with built-in spending limits, multi-signature authorization requirements, social recovery, and gas abstraction - removing the requirement for agents to hold ETH for gas fees and enabling human-readable authorization rules enforced by smart contract logic.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-virtual-assets-vasp",
      "fincen-cvc-business-models",
      "crypto-aml-travel-rule",
      "dora-ict-risk",
      "nist-sp-800-63b-authentication",
      "smart-contract-audit-swc"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ethiopia-immigration-proclamation-1110-2019",
    "title": "Ethiopia Immigration Regime - Immigration Proclamation No. 354/2003 (as amended by No. 1339/2024) - Entry, Residence and Work Permit Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "Ethiopia's immigration regime is governed by Immigration Proclamation No. 354/2003 (in force since 3 July 2003), as amended by the Immigration (Amended) Proclamation No. 1339/2024, supported by Council of Ministers Regulation No. 432/2018 on residence permits. It regulates entry, registration of foreigners, residence permits, departure and deportation. The administering authority is the Immigration and Citizenship Service (ICS), established by the Immigration and Citizenship Service Proclamation No. 1338/2024 (formerly the Immigration, Nationality and Vital Events Agency). Ethiopia operates a dual-permit system: a work permit issued by the Ministry of Labour and Social Affairs (MOLSA) and a residence permit issued by the immigration authority; neither is sufficient on its own. Note: Proclamation No. 1110/2019 is the Refugees Proclamation (a separate instrument administered by the Refugees and Returnees Service, RRS) and is NOT an immigration proclamation; refugee matters are distinguished from general immigration in this node.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "kenya-citizenship-immigration-act-2011-dis",
      "ghana-immigration-act-573-2000-ghana-immigration-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "etsi-en-303-645-iot-cybersecurity-2020",
    "title": "ETSI EN 303 645 V2.1.1 - CyberSecurity for Consumer Internet of Things: Baseline Requirements",
    "domain": "Industrial IoT & Energy",
    "version": "2.1.1",
    "last_updated": "2024-06-20",
    "bluf": "This European standard establishes a baseline for security in consumer Internet of Things (IoT) devices, applying to manufacturers and developers. It outlines 13 key provisions, most notably prohibiting universal default passwords (Clause 4.1) and requiring a public vulnerability disclosure policy (Clause 4.2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-57-key-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "etsi-en-304-223-sai",
    "title": "ETSI EN 304 223 - Securing AI (SAI)",
    "domain": "Cybersecurity",
    "version": "1.1.1",
    "last_updated": "2026-07-01",
    "bluf": "European telecommunications standards for mitigating attacks against AI models, including data poisoning, model evasion, and supply chain vulnerabilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-adversarial-machine-learning",
      "nist-ai-rmf-govern",
      "c-scrm-practices-systems-organizations"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "etsi-its-cooperative-intelligent-transport",
    "title": "ETSI ITS Standards - Cooperative Intelligent Transport Systems: ETSI EN 302 637-2 CAM, EN 302 637-3 DENM, EN 303 613 LTE-V2X and Security Standards for C-ITS",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes technical standards for Cooperative Intelligent Transport Systems (C-ITS) to enable secure, interoperable communication between vehicles and infrastructure using CAM and DENM messages over LTE-V2X. It applies to transport system developers, vehicle manufacturers, and infrastructure operators deploying C-ITS services in Europe, with core requirements defined in ETSI EN 302 637-2 and EN 302 637-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "unece-wp29-framework-connected-automated-vehicles",
      "iso-26262-functional-safety-road-vehicles-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "etsi-tr-103-619-quantum-safe-migration-strategies",
    "title": "ETSI TR 103 619 CYBER - Migration Strategies and Recommendations to Quantum Safe Schemes",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2020-07-31",
    "bluf": "ETSI TR 103 619 V1.1.1, published July 2020 under reference DTR/CYBER-QSC-0013, is a Technical Report of the ETSI CYBER technical committee titled Migration strategies and recommendations to Quantum Safe schemes. It addresses the problem of migration to an environment in a Fully Quantum Safe Cryptographic State (FQSCS) from a non-Quantum Safe Cryptographic State and provides recommendations and guidance to ensure safe transition between the two states. Its scope of attack is limited to attacks against the cryptographic elements of the system; all other elements that rely upon cryptography but are not susceptible to attack by a quantum computer are presumed secure. The document assumes an orderly, planned migration and states that emergency migration, where external events such as the immediate availability of a viable quantum computer require immediate transition, is not fully addressed.\n\nIt identifies a framework of three stages: inventory compilation, preparation of the migration plan, and migration execution. Stage 1 holds that migration cannot be planned without prior knowledge of the assets that will be impacted, so the first stage is to identify the set of cryptographic assets and processes in the system. Stage 2 sets out what the migration plan should include: a full inventory of assets; for each asset whether it will be migrated, when it will be migrated, an orderly sequence of migration of inter-dependent assets, and the migration solution chosen, being replacement by full quantum safe cryptography or a hybrid solution; and testing including dependency testing. Stage 3 implements the plan from stage 2 against the inventory from stage 1, tracking management checkpoints as metrics and conducting exercises to simulate and test the migration, which the report notes can uncover missing inventory elements because it is highly probable the inventory will be incomplete.\n\nThe report is distinctive for treating migration as a governed business process rather than a technical exercise. Each stage carries explicit business process requirements: a single migration inventory manager for stage 1 reporting to the migration planning manager, a single migration manager for stage 2 with access to all parts of the organization, allocated budget at every stage, approved management of downtime before stage 3 begins, and the direction that the migration manager should not stop partway through a phase of the migration plan. Roles are to be integrated to the existing organization such that it is clear the migration is a board level activity. It also sets substantive technical constraints, including that if any asset to be migrated depends on a Hardware Based Security Environment then that environment should be migrated before the depending asset, that a certificate chain relying on a classical trust anchor cannot be considered Quantum Safe, that if A depends on B then B should be migrated before A, and that where re-encrypting archived assets is economically infeasible those assets are physically moved to explicitly identified quarantine zones and risk managed there.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "etsi-ts-103-744-quantum-safe-hybrid-key-exchange",
      "nist-cswp-39-considerations-for-achieving-crypto-agility-2025",
      "nist-ir-8547-pqc-transition",
      "ietf-rfc-9794-pq-traditional-hybrid-terminology"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "etsi-ts-103-744-quantum-safe-hybrid-key-exchange",
    "title": "ETSI TS 103 744 CYBER - Quantum-safe Hybrid Key Exchanges (CatKDF and CasKDF)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2020-12-31",
    "bluf": "ETSI TS 103 744 V1.1.1, published December 2020 under reference DTS/CYBER-QSC-0015, is a Technical Specification of the ETSI CYBER technical committee titled Quantum-safe Hybrid Key Exchanges. It specifies several methods for deriving cryptographic keys from multiple shared secrets, where the shared secrets are established using existing classical key agreement schemes such as elliptic curve Diffie-Hellman in NIST SP 800-56Ar3 and new quantum-safe key encapsulation mechanisms. Unlike a technical report, it uses normative shall language and is therefore testable.\n\nThe assurance property it delivers is stated in clause 4.1: the quantum-safe hybrid key exchanges specified ensure that the derived key is at least as secure as the maximum security of the key exchange method, and the resulting hybrid scheme will remain secure if one of the key exchange methods remains secure. Its scope is limited to elliptic curve Diffie-Hellman and quantum-safe key encapsulation mechanisms; Quantum Key Distribution is identified as an alternative method of establishing a shared secret using quantum mechanics but is outside the scope, although a pre-shared key for the specified methods may be established using a previous session or an alternative key-establishment method such as QKD.\n\nTwo hybrid key agreement schemes are specified. The concatenate scheme with its key derivation function CatKDF exchanges all public keys in a single message and all response values in a single message, forms secret as the concatenation psk followed by k1 through kn, computes f_context from the context and the exchanged messages MA and MB using the context formatting function, and returns key_material from a single KDF invocation. The cascade scheme with its key derivation function CasKDF performs the exchanges in distinct messages, chaining them so that chain_secret0 is the pre-shared key or the empty octet string and for each round round_secret_i is computed by the PRF over the previous chain secret, the new shared secret and that round's messages, with the KDF then producing both the next chain secret and that round's key material. The KDF is run n times, each time injecting the shared secret from the next key exchange, and intermediate key material may be used to protect the messages of later rounds. Error handling is normative in both schemes: if any response function returns an error indicator the responder shall respond with an error message and terminate, and the initiator shall terminate on receiving an error message or on any receive function returning an error indicator. Approved hash functions are limited to SHA-256, SHA-384, SHA-512 and SHA-512/256 from FIPS PUB 180-4 and SHA3-256, SHA3-384 and SHA3-512 from FIPS PUB 202, and all key encapsulation mechanisms shall provide OW-CPA security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "etsi-tr-103-619-quantum-safe-migration-strategies",
      "ietf-rfc-9794-pq-traditional-hybrid-terminology",
      "ietf-rfc-9370-multiple-key-exchanges-ikev2",
      "fips-203-ml-kem-standard"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-5amld-article-2-gambling-2018",
    "title": "Directive (EU) 2018/843 of the European Parliament and of the Council of 30 May 2018 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (Fifth Anti-Money Laundering Directive), Article 2 - Obligations for providers of gambling services",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "EU 5AMLD Article 2 mandates that providers of gambling services, including online casinos and betting platforms, must conduct customer due diligence (CDD), implement risk-based AML/CFT measures, and report suspicious transactions to Financial Intelligence Units (FIUs). This applies to all gambling operators offering services within the EU, particularly when transactions equal or exceed €2,000.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l3",
      "eu-dora-articles-28-44-third-party-ict-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-5amld-real-estate-aml-due-diligence",
    "title": "Directive (EU) 2018/843 (5AMLD) - Real Estate Agent Customer Due Diligence and High-Value Transaction Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The EU's Fifth Anti-Money Laundering Directive (5AMLD) mandates that real estate agents, acting as intermediaries for both buyers and sellers, must perform Customer Due Diligence (CDD) for all property transactions and report suspicious activities to the relevant Financial Intelligence Unit (FIU), as established by Article 2(1)(3)(d) of the consolidated Directive (EU) 2015/849.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "iso-37001-anti-bribery",
      "eu-aml-regulation-2024"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-5g-cybersecurity-toolbox-2020",
    "title": "Cybersecurity of 5G networks: EU Toolbox of risk mitigating measures",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This toolbox requires EU Member States to assess the risk profile of 5G network suppliers and apply restrictions on high-risk suppliers for key assets, particularly in the core network, management functions, and radio access network (RAN), as outlined in Strategic Measures SM01 and SM02. It also mandates the implementation of a multi-vendor strategy to avoid dependency on a single supplier.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3",
      "iso-27017-cloud-defence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-5g-security-implementing-decision-2024",
    "title": "EU 5G Cybersecurity Framework - 5G Security Toolbox (2020), NIS2 Directive (EU) 2022/2555 and Radio Equipment Directive Delegated Regulation (EU) 2022/30 (high-risk vendor restrictions and core network security)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.2",
    "last_updated": "2026-07-01",
    "bluf": "The EU approach to 5G network security combines the non-binding EU 5G Cybersecurity Toolbox (2020), agreed by the NIS Cooperation Group, with binding measures under the NIS2 Directive (EU) 2022/2555 and Commission Delegated Regulation (EU) 2022/30 (cybersecurity essential requirements under the Radio Equipment Directive). Member States may restrict or exclude high-risk vendors from core 5G network functions and apply risk-based assessment. There is no single binding EU 5G Security Implementing Decision; obligations arise from the Toolbox as implemented in national law together with the NIS2 and RED instruments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5g-cybersecurity-toolbox-2020",
      "eu-nis2-telecoms-essential-services",
      "eu-eecc-2018-1972-electronic-communications-code"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-6amld-directive-2018-1673-anti-money-laundering-criminal-offences",
    "title": "EU 6th Anti-Money Laundering Directive (6AMLD) 2018/1673 - Criminal Liability for Money Laundering and Expanded Predicate Offences",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "6AMLD (Directive 2018/1673) harmonises the criminal definition of money laundering across EU Member States, expands the list of 22 predicate offences (including cybercrime, environmental crime, and tax offences), introduces criminal liability for legal persons (entities), sets minimum imprisonment terms of 4+ years for serious ML, and establishes grounds for mutual judicial cooperation between Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-6amld-sixth-anti-money-laundering-2018-1673",
    "title": "Directive (EU) 2018/1673 of the European Parliament and of the Council of 23 October 2018 on combating money laundering by criminal law",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The EU's Sixth Anti-Money Laundering Directive (6AMLD) harmonises the definition of 22 predicate criminal offenses for money laundering across all member states, extends criminal liability to legal persons (corporations), and mandates a minimum maximum term of imprisonment of at least four years for natural persons, as defined in Articles 2, 7, and 5 respectively.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-accessibility-act-2019",
    "title": "Directive (EU) 2019/882 of the European Parliament and of the Council of 17 April 2019 on the accessibility requirements for products and services",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This directive mandates common accessibility requirements for specific products and services placed on the EU market, ensuring they are usable by persons with disabilities. As per Article 4, economic operators must ensure their products and services, such as e-commerce websites, banking services, and smartphones, comply with the detailed accessibility requirements listed in Annex I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-accessibility-act-2019-882-digital-products",
    "title": "Directive (EU) 2019/882 of the European Parliament and of the Council of 17 April 2019 on the accessibility requirements for products and services",
    "domain": "Operations & CX",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Accessibility Act (EAA) establishes mandatory accessibility requirements for certain products and services, including digital products such as e-books, online banking, e-commerce platforms, and audiovisual media services, to ensure persons with disabilities can access them. It applies to providers operating in the EU internal market under Article 4 and Annex I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "eu-omnibus-directive-2019-2161",
      "eu-geo-blocking-regulation-2018",
      "iso-10002-2018-customer-satisfaction-complaints",
      "eu-p2b-regulation-2019-1150"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-accessibility-act-2019-882-digital-products-services-requirements",
    "title": "EU Accessibility Act 2019/882 - Digital Products and Services Accessibility Requirements",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2025-06-28",
    "bluf": "Directive (EU) 2019/882 (European Accessibility Act - EAA) requires manufacturers and service providers to ensure that a wide range of products and services meet accessibility requirements for persons with disabilities. Covered products include computers, smartphones, TVs, ATMs, e-readers, and ticketing machines. Covered services include electronic communications, banking, e-commerce, audiovisual media, e-books, and transport passenger services. EAA requirements become mandatory for new products and services from 28 June 2025. Member States must transpose the Directive and designate enforcement authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-services-act-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-accessibility-directive-cx-platforms-2016",
    "title": "Directive (EU) 2016/2102 of the European Parliament and of the Council of 26 October 2016 on the accessibility of the websites and mobile applications of public sector bodies",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Public sector websites and mobile applications must conform to WCAG 2.1 Level AA, publish an accessibility statement, establish a feedback mechanism, undergo regular monitoring, and assess disproportionate burden under Article 9. Applies to all public sector bodies across EU Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-accessibility-act-2019",
      "iso-10002-2018-customer-satisfaction-complaints",
      "eu-omnibus-directive-2019-2161",
      "eu-unfair-commercial-practices-directive",
      "iso-15489-1-2016-records-management-workflow"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-accounting-directive-2013-34",
    "title": "EU Accounting Directive 2013/34/EU - Annual Financial Statements and Consolidated Accounts Framework",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Directive 2013/34/EU of the European Parliament and of the Council of 26 June 2013 on the annual financial statements, consolidated financial statements and related reports of certain types of undertakings, repealing the Fourth (78/660/EEC) and Seventh (83/349/EEC) Company Law Directives, establishes the EU-wide accounting framework for companies other than those required to apply IFRS (as adopted by the EU for listed company consolidated accounts). The Directive introduces four company size categories - micro (balance sheet ≤€350,000, turnover ≤€700,000, ≤10 employees), small (≤€6M/€12M/50), medium (≤€20M/€40M/250), and large - each with progressively more detailed financial reporting requirements. Member States must permit micro-companies to use a simplified balance sheet and P&L and be exempt from the requirement to present notes and a management report. The Directive specifies mandatory balance sheet and profit and loss account formats, the content of notes to financial statements, management report requirements (including the non-financial information statement for large public-interest entities), and consolidated accounts thresholds. The Directive was significantly amended by the CSRD (Directive 2022/2464/EU) to incorporate sustainability reporting obligations into the management report framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_csrd_sustainability_reporting",
        "eu_statutory_audit_regulation",
        "eu_mica_regulation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-statutory-audit-regulation-537-2014",
      "eu-market-abuse-regulation-596-2014"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-adr-agreement-dangerous-goods-road-transport-un-classification",
    "title": "ADR Agreement 2023 - Dangerous Goods Road Transport Classification, Packaging & Documentation",
    "domain": "Logistics & Supply Chain",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The ADR Agreement (European Agreement concerning the International Carriage of Dangerous Goods by Road) governs classification, packaging, labelling, vehicle marking, driver training, and transport document requirements for hazardous materials in EU and European road transport - updated biennially.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-adr-consumer-disputes-2013",
    "title": "Directive 2013/11/EU of the European Parliament and of the Council of 21 May 2013 on alternative dispute resolution for consumer disputes and amending Regulation (EC) No 2006/2004 and Directive 2009/22/EC (Directive on consumer ADR)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This directive requires EU Member States to ensure that all contractual disputes between a consumer and a trader can be submitted to an Alternative Dispute Resolution (ADR) entity. As per Article 13, traders must inform consumers on their websites and in their general terms and conditions about the competent ADR entity or entities and whether they commit to using them.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fca-consumer-duty-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-adr-directive-2013-11-alternative-dispute",
    "title": "Directive 2013/11/EU of the European Parliament and of the Council of 21 May 2013 on alternative dispute resolution for consumer disputes and amending Regulation (EC) No 2006/2004 and Directive 2009/22/EC (Directive on consumer ADR)",
    "domain": "Operations & CX",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive requires all traders operating in the EU to inform consumers clearly and comprehensively about the existence of approved Alternative Dispute Resolution (ADR) entities and to provide contact details for such entities, where the trader is subject to an obligation to use ADR or may choose to do so. It applies to all consumer disputes arising from online and offline contracts for goods and services, under Article 3(1) and Article 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-adr-consumer-disputes-2013",
      "eu-consumer-rights-directive-2011",
      "iso-10003-2018-external-dispute-resolution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-adr-directive-2013-11-consumer-dispute-resolution",
    "title": "EU ADR Directive 2013/11 - Alternative Dispute Resolution and Online Dispute Resolution for Consumer Contracts",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Directive 2013/11/EU on Alternative Dispute Resolution (ADR Directive) and Regulation (EU) 524/2013 on Online Dispute Resolution (ODR Regulation) require EU member states to ensure that all disputes between consumers and traders arising from sales or service contracts can be submitted to a certified ADR entity; mandate traders to inform consumers about available ADR schemes and whether the trader will participate in ADR; require e-commerce traders and online marketplaces to display a link to the European Commission's ODR platform (ec.europa.eu/consumers/odr); and impose on ADR entities a 90-calendar-day dispute resolution deadline; the ADR Directive is under review (European Consumer Agenda 2020-2025) to expand scope to digital services and AI-generated harms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-adr-directive-consumer-2013-11-cx",
    "title": "Directive 2013/11/EU of the European Parliament and of the Council of 21 May 2013 on alternative dispute resolution for consumer disputes and amending Regulation (EC) No 2006/2004 and Directive 2009/22/EC (Directive on consumer ADR)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This Directive requires Member States to ensure that consumers have access to effective, transparent, and independent alternative dispute resolution (ADR) entities for resolving disputes with traders arising from sales or service contracts, both offline and online, under Article 3. It applies to all ADR entities handling consumer disputes in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "eu-omnibus-directive-2019-2161",
      "iso-10003-2018-external-dispute-resolution"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-adr-online-dispute-resolution-2013",
    "title": "Directive 2013/11/EU on alternative dispute resolution for consumer disputes and Regulation (EU) No 524/2013 on online dispute resolution for consumer disputes",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This framework requires EU-based traders in online sales or service contracts to inform consumers about available Alternative Dispute Resolution (ADR) entities and provide an easily accessible electronic link to the EU's Online Dispute Resolution (ODR) platform on their websites, as mandated by Article 13 of the ADR Directive and Article 14 of the ODR Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-representative-actions-directive-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-advanced-therapy-medicinal-products-1394-2007",
    "title": "Regulation (EC) No 1394/2007 of the European Parliament and of the Council of 13 November 2007 on advanced therapy medicinal products and amending Directive 2001/83/EC and Regulation (EC) No 726/2004",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes a harmonized EU framework for advanced therapy medicinal products (ATMPs), including gene therapies, somatic cell therapies, and tissue-engineered products. It mandates a single, centralized marketing authorisation procedure through the European Medicines Agency (EMA) for all ATMPs intended for the EU market, as stipulated in Article 8, and establishes the Committee for Advanced Therapies (CAT) to assess their quality, safety, and efficacy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice",
      "eu-mdr-2017-745"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-advanced-therapy-medicinal-products-2007-1394",
    "title": "Regulation (EC) No 1394/2007 of the European Parliament and of the Council of 13 November 2007 on Advanced Therapy Medicinal Products and Amending Directive 2001/83/EC and Regulation (EC) No 726/2004",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a centralized authorization pathway and specific safety, quality, and efficacy requirements for advanced therapy medicinal products (ATMPs), including gene therapy, somatic cell therapy, and tissue-engineered products, under Article 8 and Article 14. It applies to manufacturers, clinical developers, and healthcare providers involved in the production or administration of ATMPs in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ema-centralised-procedure-regulation-726-2004",
      "eu-medicinal-products-directive-2001-83-ec",
      "eu-gmp-annex-1-sterile-manufacture-2022",
      "eu-clinical-trials-eu-ctr-trials-regulation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-advanced-therapy-medicinal-products-regulation-1394-2007",
    "title": "EU Advanced Therapy Medicinal Products Regulation 1394/2007 - Gene Therapy, Cell Therapy, and Tissue Engineering Authorisation",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Regulation (EC) No 1394/2007 of 13 November 2007 establishes the EU regulatory framework for advanced therapy medicinal products (ATMPs). ATMPs are defined in Article 2 as gene therapy medicinal products (GTMPs), somatic cell therapy medicinal products (sCTMPs), and tissue-engineered products (TEPs), including combined ATMPs incorporating both cells or tissues and a medical device where the cellular component is the principal mode of action. The Regulation makes the centralised EMA marketing authorisation procedure mandatory for all ATMPs. The Committee for Advanced Therapies (CAT) at EMA conducts the primary scientific assessment and forwards its opinion to the CHMP which adopts the formal marketing authorisation recommendation. Article 28 provides a hospital exemption for non-routine ATMP preparations for individual patients prepared and used within the same Member State under exclusive medical professional responsibility. The Regulation imposes GMP manufacturing authorisation requirements, risk-adapted post-authorisation follow-up of long-term efficacy and safety, traceability obligations of at least 30 years for donation and procurement records, and a mandatory product classification procedure under Annex I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_21st_century_cures_act_2016",
        "eu_clinical_trials_regulation_2014_536",
        "eu_gmo_deliberate_release_directive_2001_18",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecn-plus-directive-2019-nca-powers",
      "eu-gmo-deliberate-release-directive-2001-18",
      "eu-services-directive-2006-123"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-advanced-therapy-medicinal-products-regulation-1394-2007-atmp",
    "title": "EU Advanced Therapy Medicinal Products Regulation 1394/2007 - Cell, Gene, and Tissue Therapies",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "Regulation (EC) No 1394/2007 establishes the regulatory framework for Advanced Therapy Medicinal Products (ATMPs) in the EU, covering gene therapy, somatic cell therapy, tissue-engineered products, and combined ATMPs. ATMPs require centralised marketing authorisation through EMA. The Committee for Advanced Therapies (CAT) provides scientific recommendations. Hospital exemption allows ATMPs manufactured in a hospital for use in the same member state on a named-patient basis, but this exemption is conditional on national competent authority oversight and does not permit commercial supply.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-clinical-trials-regulation-2014-536-ctr-investigational-medicinal-products",
      "eu-good-manufacturing-practice-gdp-2013-c-343-4-medicinal-products"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-afir-alternative-fuels-2023-1804",
    "title": "Regulation (EU) 2023/1804 of the European Parliament and of the Council of 13 September 2023 on the deployment of alternative fuels infrastructure, and repealing Directive 2014/94/EU (AFIR)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-09-13",
    "bluf": "Regulation (EU) 2023/1804 (AFIR) mandates that by 31 December 2025, EU Member States must deploy fast-charging pools for light-duty electric vehicles at least every 60 km along the TEN-T core network, with each pool offering a total power output of at least 400 kW and including at least one charging point with an individual power output of at least 150 kW (Article 3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "logistics-carbon-glec",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-agency-work-directive-2008",
    "title": "Directive 2008/104/EC of the European Parliament and of the Council of 19 November 2008 on temporary agency work",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This directive establishes the principle of equal treatment for temporary agency workers, ensuring their basic working and employment conditions are at least those that would apply if they had been recruited directly by the user undertaking to occupy the same job, as mandated by Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "iso-26000-social-resp-mgt",
      "eu-pay-transparency-directive-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-agricultural-forestry-vehicle-type-approval-167-2013",
    "title": "Regulation (EU) No 167/2013 of the European Parliament and of the Council of 5 February 2013 on the approval and market surveillance of agricultural and forestry vehicles",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation establishes the administrative and technical requirements for the type-approval and market surveillance of agricultural and forestry vehicles, systems, components and separate technical units (Article 1). It defines the vehicle categories T (tractors), C (track-laying tractors), R (trailers) and S (towed equipment) (Article 4), requires Member States to designate approval and market surveillance authorities (Article 5), and sets manufacturer obligations to ensure conformity and to act on non-conforming or seriously risky products (Articles 8 and 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-type-approval-framework-regulation-2018-858",
      "eu-market-surveillance-regulation-2019-1020-auto"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-2024",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The EU AI Act establishes a comprehensive, risk-based legal framework for AI systems placed on the Union market, prohibiting certain unacceptable-risk practices (Article 5), imposing strict conformity, transparency, and oversight requirements on high-risk systems (Title III), and setting transparency obligations for specific AI systems like chatbots and deepfakes (Article 50). It applies to providers, deployers, importers, and distributors of AI systems operating within the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026",
        "mitre_atlas"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-high-risk",
      "eu-ai-act-bias",
      "iso-42001-risk-assess",
      "nist-ai-rmf-1-0",
      "oecd-ai-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-16-obligations-providers-high-risk-ai",
    "title": "EU AI Act (EU) 2024/1689 - Article 16: Obligations of Providers of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 16 of the EU AI Act imposes seven mandatory obligations on providers of high-risk AI systems before and during placement on the EU market: (a) establish a compliant quality management system under Article 17; (b) maintain technical documentation per Annex IV; (c) implement automatically generated logs per Article 12; (d) carry out conformity assessment per Article 43 before placing on market; (e) register in the EU database per Article 60; (f) affix CE marking per Article 48; and (g) take corrective action on non-conforming systems per Article 21. Providers who place a high-risk AI system on the market but are later informed by a natural or legal person that the high-risk features were integrated by a third-party after placement bear obligations only from the point of knowledge.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-43-conformity-assessment-procedures-notified-bodies",
      "eu-ai-act-article-14-human-oversight",
      "eu-ai-act-article-5-prohibited-practices"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-17-quality-management-system-providers",
    "title": "EU AI Act (EU) 2024/1689 - Article 17: Quality Management System Requirements for Providers of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 17 mandates that every provider of a high-risk AI system document and implement a Quality Management System (QMS) proportionate to the organisation's size and the risk level of the AI system. The QMS must address at minimum: (a) regulatory compliance strategy; (b) design, development, and quality control techniques; (c) systematic review of design before and after market placement; (d) examination, testing, and validation of the AI system and data; (e) technical specifications including standards applied; (f) data management including training, validation, and testing datasets; (g) risk management per Article 9; (h) post-market monitoring per Article 72; (i) accountability, responsibility, and authority procedures; (j) procedures for reporting serious incidents per Article 73; (k) communication with authorities; (l) record-keeping; and (m) resource management. SMEs may apply a simplified approach proportionate to their size.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-article-62-serious-incident-reporting"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-18-technical-documentation-high-risk-ai",
    "title": "EU AI Act (EU) 2024/1689 - Article 18: Technical Documentation Requirements for High-Risk AI System Providers",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 18 requires providers of high-risk AI systems to draw up Annex IV-compliant technical documentation before placing the system on the market and to keep it up to date throughout the product lifecycle. The documentation must contain all information necessary to assess conformity with the AI Act requirements and must be maintained for 10 years after the last high-risk AI system is placed on the EU market. Technical documentation must be made available to national competent authorities and notified bodies on request. For high-risk AI systems that are also safety components under other EU legislation (MDR, Machinery Regulation, etc.), the technical documentation may be combined with documentation required under those instruments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-article-43-conformity-assessment-procedures-notified-bodies",
      "eu-ai-act-annex-iv-technical-documentation-requirements"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-20-automatically-generated-logs-high-risk",
    "title": "EU AI Act (EU) 2024/1689 - Article 20: Automatically Generated Logs and Audit Trail Requirements for High-Risk AI",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 20 requires providers of high-risk AI systems to design and build in automatic log-keeping capabilities that record the system's operation throughout the entire period of use. These logs must enable post-market monitoring and facilitate investigation of incidents and non-conformities. Deployers of high-risk AI systems must retain automatically generated logs for the period specified by the provider in instructions for use or - absent such specification - for at least 6 months. For high-risk AI systems subject to public authority use (credit institutions, law enforcement, public administration), deployers must retain logs for a minimum of 3 years or as required by sector-specific legislation. Logs must be made available to competent authorities on request.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-article-26-obligations-deployers-high-risk-ai"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-21-cooperation-competent-authorities-providers",
    "title": "EU AI Act (EU) 2024/1689 - Article 21: Cooperation with Competent Authorities by Providers of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 21 requires providers of high-risk AI systems to cooperate with national competent authorities (NCAs) and the AI Office upon request. Cooperation obligations include: providing authorities with all necessary information and documentation to demonstrate conformity with the AI Act requirements; granting access to the automatically generated logs per Article 20; and conducting testing and inspections as required. Providers must designate a point of contact for authority communications. Non-EU providers must ensure their authorised representative (Article 22) has the authority and resources to fulfil Article 21 cooperation obligations on their behalf. Refusal to cooperate is grounds for market surveillance action under Article 74.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-2024-1689-article-20-automatically-generated-logs-high-risk",
      "eu-ai-act-article-18-conformity-assessment-doc"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-22-obligations-authorised-representatives-providers",
    "title": "EU AI Act (EU) 2024/1689 - Article 22: Obligations of Authorised Representatives of Providers of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 22 requires non-EU providers of high-risk AI systems placed on the EU market to designate - by written mandate - an EU-established authorised representative before market placement. The authorised representative acts on behalf of the provider in all matters concerning AI Act compliance. The mandate must explicitly empower the representative to: (a) maintain a copy of the EU declaration of conformity and technical documentation for access by national competent authorities; (b) provide all information and documentation requested by competent authorities; (c) cooperate with competent authorities on corrective action; (d) register the provider in the EU AI Act database per Article 60. The authorised representative may be held liable alongside the provider for non-conformities and may terminate the mandate if the provider acts contrary to the AI Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-2024-1689-article-21-cooperation-competent-authorities-providers"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-23-obligations-importers-high-risk-ai",
    "title": "EU AI Act (EU) 2024/1689 - Article 23: Obligations of Importers of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 23 places specific obligations on importers - EU-established entities that place a high-risk AI system from a non-EU provider on the EU market. Before placing the system on the market, importers must verify: (a) the provider has completed the appropriate conformity assessment procedure; (b) the provider has drawn up the technical documentation per Article 18; (c) the system bears the required CE marking; (d) the provider has drawn up the EU declaration of conformity; and (e) the system includes instructions for use per Article 13. If an importer has reasons to believe a high-risk AI system does not conform to the AI Act requirements or poses a risk, they must not place it on the market until the non-conformity is remediated. Importers must indicate their name and contact details on the AI system or its documentation, maintain a copy of the declaration of conformity for 10 years, and cooperate with competent authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-article-43-conformity-assessment-procedures-notified-bodies",
      "eu-ai-act-2024-1689-article-22-obligations-authorised-representatives-providers"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-24-obligations-distributors-high-risk-ai",
    "title": "EU AI Act (EU) 2024/1689 - Article 24: Obligations of Distributors of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 24 requires distributors - entities in the supply chain that make a high-risk AI system available on the EU market without being the provider or importer - to verify before making the system available that: (a) the system bears the CE marking; (b) the provider has drawn up an EU declaration of conformity; and (c) instructions for use per Article 13 accompany the system. Distributors must not make a high-risk AI system available if they believe it is non-conforming or poses a serious risk. When a system is under the distributor's responsibility, storage and transport conditions must preserve conformity. If a distributor obtains information suggesting non-conformity or a serious risk, they must immediately inform the provider or importer and cooperate with competent authorities. A distributor who places a system on the market under their own name or substantially modifies it assumes provider obligations under Article 16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024-1689-article-23-obligations-importers-high-risk-ai",
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-2024-1689-article-25-responsibilities-along-ai-value-chain"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-25-responsibilities-along-ai-value-chain",
    "title": "EU AI Act (EU) 2024/1689 - Article 25: Responsibilities Along the AI Value Chain",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 25 establishes clear role transitions within the AI value chain that shift provider obligations to other economic operators. An importer or distributor becomes a provider - and assumes all Article 16 provider obligations - when they: (a) place a high-risk AI system on the market under their own name or trademark; (b) modify the intended purpose of a high-risk AI system already placed on the market; or (c) make a substantial modification to a high-risk AI system. Additionally, any provider who integrates a general-purpose AI (GPAI) model into a high-risk AI system becomes responsible for the high-risk AI system's compliance with the EU AI Act - even if the GPAI model was developed by a third party. Article 25 also addresses the case where a high-risk AI system is developed for a deployer's own internal use - the deployer becomes the provider.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-2024-1689-article-23-obligations-importers-high-risk-ai",
      "eu-ai-act-2024-1689-article-24-obligations-distributors-high-risk-ai"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-26-obligations-deployers-high-risk-ai",
    "title": "EU AI Act (EU) 2024/1689 - Article 26: Obligations of Deployers of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 26 is the primary compliance article for organisations that use (deploy) high-risk AI systems in their operations. Deployers must: (a) use the system in accordance with the provider's instructions for use; (b) assign qualified human oversight persons with the necessary authority; (c) ensure input data is relevant and sufficiently representative for the intended purpose; (d) monitor operation of the high-risk AI system for anomalies and risks; (e) inform the provider and market surveillance authority of serious incidents under Article 26(4); (f) where the high-risk AI system makes or assists decisions about natural persons, inform those persons under Article 26(11); (g) keep automatically generated logs of the system's operation for at least six months under Article 26(5), where the logs are under the deployer's control; (h) inform workers' representatives and the affected workers before putting a high-risk AI system into service or use in the workplace under Article 26(6). Separately, before deploying a high-risk AI system, public bodies (and private operators providing public services, or operators of credit-scoring or life/health insurance risk-pricing AI under Annex III(5)) must conduct a Fundamental Rights Impact Assessment under Article 27, which is a free-standing obligation distinct from Article 26. Deployers who substantially modify a high-risk AI system or develop one for internal use become providers under Article 25.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-14-human-oversight",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-2024-1689-article-25-responsibilities-along-ai-value-chain"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-40-harmonised-standards-presumption-conformity",
    "title": "EU AI Act (EU) 2024/1689 - Article 40: Harmonised Standards and Presumption of Conformity for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 40 establishes the presumption of conformity mechanism for high-risk AI systems: a system that complies with harmonised European standards (EN standards) published in the Official Journal of the EU is presumed to conform with the corresponding EU AI Act requirements covered by those standards. This is the primary conformity pathway for providers who want to avoid the cost and time of notified body assessment for requirements covered by harmonised standards. The European Commission mandates CEN/CENELEC to develop AI-specific harmonised standards. Where harmonised standards do not yet exist, providers may rely on Commission-adopted Common Specifications per Article 41. Standards applicable to other EU legislation (e.g., ETSI EN 303 645 for IoT cybersecurity) may also contribute to presumption of conformity for overlapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-article-43-conformity-assessment-procedures-notified-bodies"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk",
    "title": "EU AI Act (EU) 2024/1689 - Article 43: Conformity Assessment Procedures for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 43 specifies two conformity assessment routes for high-risk AI systems before market placement. Route 1 (internal control - Annex VI): providers self-assess against AI Act requirements; applies to all high-risk AI systems in Annex III EXCEPT biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration/asylum, and administration of justice categories. Route 2 (notified body assessment - Annex VII): mandatory third-party conformity assessment by an accredited EU notified body; applies to: (a) real-time remote biometric identification systems; (b) high-risk AI systems that differ substantially from any system for which conformity assessment was previously conducted under a harmonised standard. When a subsequent version of an already-certified system includes modifications not covered by the previous certificate, a new assessment is required. Providers may choose a more stringent procedure than the minimum required.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-article-17-quality-management-system",
      "eu-ai-act-2024-1689-article-18-technical-documentation-high-risk-ai",
      "eu-ai-act-article-40-harmonised-standards"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-44-certificates-eu-declaration-conformity",
    "title": "EU AI Act (EU) 2024/1689 - Article 44: Certificates and EU Declaration of Conformity for High-Risk AI",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 44 governs EU AI Act certificates issued by notified bodies following Route 2 conformity assessment under Article 43. Certificates must: (a) contain information required by Annex VII; (b) be issued for a maximum period of four years; (c) be subject to monitoring conditions; and (d) be renewable upon reassessment. Notified bodies must inform their national accreditation body and the European Commission of certificates issued, modified, suspended, or withdrawn. Notified bodies may impose conditions on certificates. A certificate issued by a notified body in one EU member state is recognised throughout the EU - there is no need for re-assessment in other member states. Certificates must be revoked, suspended, or made subject to conditions if the AI Act requirements are no longer met.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk",
      "eu-ai-act-article-16-provider-obligations"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-57-ai-office-tasks-responsibilities",
    "title": "EU AI Act (EU) 2024/1689 - Article 57: AI Office Tasks and Responsibilities for GPAI Model Oversight",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 57 establishes the AI Office - an EU-level body within the European Commission - as the primary supervisor of general-purpose AI (GPAI) model providers in the EU. The AI Office's core tasks include: (a) monitoring GPAI model market developments; (b) overseeing application of the GPAI model obligations in Chapter V of the AI Act; (c) conducting model evaluations and assessments including adversarial testing; (d) investigating non-compliance and taking enforcement action; (e) coordinating with national market surveillance authorities; (f) participating in international AI governance forums; (g) supporting the development of codes of practice for GPAI providers; (h) issuing guidance and recommendations on AI Act implementation. The AI Office operates under Commission administrative oversight and works alongside the AI Board (Article 65) and the Scientific Panel of Independent Experts (Article 68).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-50-gpai-transparency",
      "eu-ai-act-article-53-gpai-codes-of-practice",
      "eu-ai-act-article-55-systemic-risk-gpai"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-article-64-market-surveillance-enforcement-authorities",
    "title": "EU AI Act (EU) 2024/1689 - Article 64: Market Surveillance Authority Powers and Enforcement for High-Risk AI",
    "domain": "AI Governance & Law",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 64 grants national market surveillance authorities (NCAs) extensive investigative and corrective powers for high-risk AI system compliance. NCAs may: (a) access all documentation and source code of high-risk AI systems; (b) require providers, deployers, importers, and distributors to provide all necessary information; (c) carry out unannounced inspections; (d) request explanatory information about AI system logic including algorithms; (e) conduct testing including in real-world conditions; (f) order free-of-charge access to the AI system; (g) take corrective actions including prohibition, withdrawal, or recall of non-compliant AI systems. NCAs must cooperate with each other and with the AI Office. Market surveillance is free of charge for economic operators. Findings of non-compliance must be reported to the Commission via the EU SOLVIT/RAPEX equivalent for AI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024-1689-article-21-cooperation-competent-authorities-providers",
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-2024-1689-article-18-technical-documentation-high-risk-ai"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-2024-1689-prohibited-practices",
    "title": "EU AI Act Article 5 Prohibited AI Practices Compliance Node",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-16",
    "bluf": "Regulation (EU) 2024/1689 Article 5 prohibits specific AI practices deemed unacceptable. These include deploying AI systems using subliminal techniques to materially distort a person's behavior in a manner that causes significant harm; exploiting vulnerabilities due to age, disability, or social or economic situation; social scoring by public authorities based on collected social behavior data leading to detrimental treatment; real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, except for narrowly defined objectives such as searching for victims, preventing imminent threats, or investigating serious crimes, with prior judicial authorization; biometric categorization systems inferring sensitive attributes (race, ethnicity, political opinion, etc.); emotion recognition in workplaces and educational institutions; and untargeted scraping of facial images from the internet or CCTV footage to build facial recognition databases. The prohibitions take effect on 2 February 2025. Operators must cease using such prohibited AI systems by that date. Non-compliance can result in administrative fines up to a percentage of total worldwide annual turnover or a fixed amount, whichever is higher, as specified in Article 99. The regulation is directly applicable in all EU member states, with enforcement coordinated by the EU AI Office and national competent authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-2024-article-26-deployer-obligations-high-risk",
    "title": "EU AI Act 2024 Article 26 - Deployer Obligations for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Regulation (EU) 2024/1689 Article 26 sets out obligations for deployers of high-risk AI systems. Deployers must use systems in accordance with instructions of use, assign human oversight to qualified persons, monitor system performance, report incidents to providers and national authorities, and where applicable, conduct fundamental rights impact assessments before deployment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-2024-high-risk-educational-applications",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 March 2024 on Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act) - High-Risk AI Systems in Education: Automated Grading, Access Decisions and Student Assessment Tools",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The EU AI Act 2024 classifies AI systems used for automated grading, determining access to education or training programs, and evaluating students as high-risk under Article 6 and Annex III. Providers and deployers of such systems must comply with stringent requirements on data governance, transparency, human oversight, and conformity assessment before market placement or deployment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-education-action-plan-2021-2027-deap",
      "oecd-pisa-education-assessment-framework-2022",
      "iso-21001-2018-educational-organizations-management",
      "eu-open-science-policy-fair-data-principles-2021",
      "oecd-principles-ai-in-education-recommendation-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-accuracy-robustness-cybersecurity",
    "title": "EU AI Act - Accuracy, Robustness, and Cybersecurity Requirements for High-Risk AI Systems (Article 15)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 15 establishes mandatory accuracy, robustness, and cybersecurity requirements for high-risk AI systems; Article 15(1) - high-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and perform consistently in those respects throughout their lifecycle; Article 15(2) - the levels of accuracy and the relevant accuracy metrics of high-risk AI systems shall be declared in the accompanying instructions for use; Article 15(3) - high-risk AI systems shall be resilient as regards errors, faults, or inconsistencies that may occur within the system or the environment in which the system operates, in particular when interacting with natural persons or other systems; high-risk AI systems shall be resilient against attempts by unauthorised third parties to alter their use, outputs, or performance by exploiting the system vulnerabilities; Article 15(4) - the technical robustness of high-risk AI systems may be achieved through technical redundancy solutions, which may include backup or fail-safe plans; Article 15(5) - high-risk AI systems that continue to learn after being placed on the market or put into service shall be developed in such a way that the automatic updates to those systems do not have a negative effect on their overall performance and do not create risks to health and safety or fundamental rights; Article 15(1) accuracy level must be 'appropriate' to the intended purpose - the appropriateness standard is contextual: a biometric identification system used in law enforcement requires a different and higher accuracy standard than a general consumer recommendation system; Article 15 technical requirements must be reflected in the Article 13 instructions for use (performance metrics and thresholds), the Article 9 risk management system (accuracy risks), and the Article 11 Annex IV technical documentation (performance testing methodology and results).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-accuracy-robustness-cybersecurity.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-provider-obligations-high-risk",
      "eu-ai-act-technical-documentation-requirements",
      "eu-ai-act-transparency-instructions-for-use",
      "eu-ai-act-risk-management-system",
      "eu-ai-act-data-governance-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-ai-regulatory-sandboxes",
    "title": "EU AI Act - AI Regulatory Sandboxes for Innovative AI Development (Articles 57-60)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Articles 57-60 establish the AI regulatory sandbox framework - a controlled environment enabling providers and prospective providers to develop, train, test, and validate innovative AI systems under regulatory supervision before market placement; sandboxes are established and operated by national competent authorities and must be available in at least one Member State; Article 57(1) - Member States shall ensure that national competent authorities establish at least one AI regulatory sandbox within 24 months of the EU AI Act's entry into force (by 2 August 2026); Article 57(3) - national competent authorities must give priority access to SMEs and startups when determining sandbox participation; Article 58 - conditions for sandbox participation: participants must submit an application demonstrating innovative AI system characteristics; genuine regulatory supervision is required during sandbox operations; sandbox participation may not exceed 24 months extendable by a further 12 months in duly justified cases; During the sandbox period, participants operate under national competent authority supervision and guidance; the EU AI Act provides that violations committed in good faith in compliance with national competent authority sandbox guidance attract limited sanctions, providing a protected environment for regulatory learning; Article 60 - processing of personal data in sandboxes may be permitted where necessary to develop innovative AI systems in the public interest, subject to specific safeguards including: specific data protection measures; defined data retention limits; no access by third parties; no use of data for other purposes; applicable from 2 August 2026 (24 months after entry into force); sandbox frameworks provide a critical pathway for AI innovators to engage with regulators before full deployment requirements apply.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-ai-regulatory-sandboxes.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-sme-startup-provisions",
      "eu-ai-act-provider-obligations-high-risk",
      "eu-ai-act-conformity-assessment-procedure"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-annex-i-ai-techniques-definition",
    "title": "Regulation (EU) 2024/1689 Annex I: Artificial Intelligence Techniques and Approaches Referred to in Article 3, Point 1",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This node defines the specific machine learning, logic-based, and statistical techniques that qualify a system as an 'AI system' under the EU AI Act, as referenced in Article 3(1). Organizations must assess their systems against this list to determine if they fall within the Act's regulatory scope.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-annex-ii-union-harmonisation-legislation",
    "title": "EU AI Act Annex II - Union Harmonisation Legislation for Products in High-Risk AI Classification",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Annex II lists the Union harmonisation legislation applicable to safety-regulated products whose embedded AI components are automatically classified as high-risk under Article 6(1) - an AI system that is a safety component of, or itself constitutes, a product regulated by any of the listed sectoral instruments is subject to the full Chapter III high-risk AI system obligations; the Annex II list covers eleven product safety sectors including medical devices (MDR 2017/745, IVDR 2017/746), machinery (Regulation 2023/1230), radio equipment (RED 2014/53), civil aviation, marine equipment, railway interoperability, agricultural vehicles, and pressure equipment; providers of AI-embedded regulated products must satisfy both the Annex II sectoral legislation conformity requirements and the EU AI Act Chapter III requirements, with harmonised conformity assessment procedures available under Article 43(4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-annex-ii-union-harmonisation-legislation.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-annex-iii-high-risk-ai-list",
    "title": "EU AI Act Annex III - Exhaustive List of High-Risk AI Systems: Biometrics, Critical Infrastructure, Education, Employment and Public Services",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Annex III of the EU AI Act provides an exhaustive list of AI systems considered high-risk across eight critical domains, including biometrics, critical infrastructure, education, and employment. AI systems falling into these categories, as defined in Article 6(2), are subject to the stringent conformity, transparency, and risk management requirements outlined in Title III of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-high-risk",
      "eu-ai-act-fundamental-rights-impact-assessment",
      "iso-42001-risk-assess",
      "iso-23894-ai-risk-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-annex-iii-high-risk-ai-systems",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act)",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a harmonised framework for high-risk AI systems listed in Annex III, requiring strict compliance with risk management, data governance, transparency, and human oversight obligations under Article 16 and Annex III. It applies to providers, deployers, and importers of AI systems used in biometric identification, critical infrastructure, education, employment, law enforcement, and other sensitive domains within the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ai-agent-collision-logic"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-annex-iii-high-risk-classification",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council on Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act) - Annex III: AI Systems Considered High-Risk",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation defines eight categories of AI systems classified as high-risk under the EU AI Act, subjecting providers and deployers to strict conformity assessments, transparency obligations, and risk management requirements under Article 6 and Annex III. It applies to AI systems intended to be used as safety components in products covered by EU harmonisation legislation or standalone systems falling within the listed high-risk domains.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "nist-ai-100-4-redteam"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-annex-iii-high-risk-use-cases",
    "title": "EU AI Act Annex III - High-Risk AI System Use Cases Classification List",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Annex III enumerates eight categories of high-risk AI system use cases subject to the full requirements of Chapter III: (1) biometric identification and categorisation of natural persons; (2) AI systems as safety components of critical infrastructure; (3) education and vocational training (access, assessment, guidance); (4) employment and workers management (recruitment, task allocation, monitoring); (5) access to essential private and public services and benefits; (6) law enforcement use cases (risk assessment, evidence analysis, crime prediction); (7) migration, asylum, and border control management; and (8) administration of justice and democratic processes - any AI system whose intended purpose falls within one of these eight categories is classified as high-risk and subject to the full obligations of Chapter III.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-annex-iii-high-risk-use-cases.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-7-high-risk-classification-updates",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-annex-iv-technical-documentation-requirements",
    "title": "EU AI Act Annex IV - Technical Documentation Content Requirements for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Annex IV specifies the mandatory content that providers must include in the technical documentation for high-risk AI systems under Article 11, comprising ten categories of information: (1) general description of the AI system and its intended purpose; (2) a detailed description of the elements of the AI system and the process for its development; (3) information about the monitoring, functioning, and control of the AI system; (4) description of the appropriateness of the performance metrics; (5) description of any pre-determined changes to the AI system; (6) assessment of the human oversight measures; (7) detailed description of the validation and testing procedures; (8) cybersecurity measures; (9) a copy of the instructions for use; and (10) the EU declaration of conformity - the technical documentation must be maintained and updated throughout the AI system's lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-annex-iv-technical-documentation-requirements.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-11-technical-documentation",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-annex-ix-registration-eu-database",
    "title": "EU AI Act Annex IX - Information for Registration of High-Risk AI Systems in the EU Database",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Annex IX specifies the information that providers and deployers must submit when registering high-risk AI systems in the EU database established under Article 60 - the registration information for providers includes: system identification, provider identity, intended purpose, status on the market, the applicable Annex III category, summary in plain language, URL of instructions for use, conformity assessment certificate details, EU declaration of conformity reference, and whether the system interacts with vulnerable persons; deployers of high-risk AI systems in certain Annex III categories must also register their use, providing their identity, intended purpose and geographic scope of use; Annex IX registration is mandatory for Annex III high-risk AI systems before market placement and constitutes the primary public accountability mechanism for high-risk AI systems in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-annex-ix-registration-eu-database.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-60-eu-database-high-risk-ai",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-annex-iii-high-risk-use-cases",
      "eu-ai-act-article-48-ce-marking-affixation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-annex-v-eu-declaration-of-conformity",
    "title": "EU AI Act Annex V - Content Requirements for the EU Declaration of Conformity",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Annex V specifies the mandatory content that providers must include in the EU declaration of conformity required under Article 47 for high-risk AI systems - the declaration must include: (1) the AI system's name, type, and any additional identification information; (2) the name and address of the provider and the authorised representative; (3) a statement of sole responsibility for the declaration; (4) a statement of conformity with the Regulation and any other applicable Union legislation; (5) references to harmonised standards applied; (6) the notified body and certificate number where applicable; and (7) the place, date, and signature; the EU declaration of conformity must be kept updated and is also required as category 10 of the Annex IV technical documentation package, constituting the legally operative conformity claim that enables CE marking under Article 48.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-annex-v-eu-declaration-of-conformity.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-47-eu-declaration-of-conformity",
      "eu-ai-act-article-48-ce-marking-affixation",
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk",
      "eu-ai-act-annex-iv-technical-documentation-requirements"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-annex-vi-internal-control-conformity-assessment",
    "title": "EU AI Act Annex VI - Internal Control Conformity Assessment Procedure for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Annex VI establishes the internal control conformity assessment procedure under which providers of most high-risk AI systems listed in Annex III may self-certify conformity with Chapter III requirements without third-party notified body involvement - the provider draws up the Annex IV technical documentation, implements and maintains a quality management system under Article 17, ensures the high-risk AI system has undergone the Article 9 risk management process and meets Articles 8-15 requirements, and draws up the EU declaration of conformity under Article 47; internal control is the default conformity assessment route for Annex III high-risk AI systems other than biometric identification systems under Article 43(1), which require the Annex VII third-party procedure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-annex-vi-internal-control-conformity-assessment.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-17-quality-management",
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk",
      "eu-ai-act-annex-iv-technical-documentation-requirements"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-annex-vii-notified-body-conformity-assessment",
    "title": "EU AI Act Annex VII - Third-Party Conformity Assessment by Notified Bodies for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Annex VII establishes the third-party conformity assessment procedure based on assessment of quality management system and assessment of technical documentation, conducted by notified bodies designated under Articles 31-39 - this procedure applies mandatorily to high-risk AI systems intended for biometric identification under Article 43(1) and optionally to providers of other high-risk AI systems who choose third-party certification; the Annex VII procedure consists of two parts: Part A (quality management system assessment and certification), and Part B (assessment of technical documentation); successful completion of both parts results in the notified body issuing a certificate of conformity that supports the provider's EU declaration of conformity and CE marking.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-annex-vii-notified-body-conformity-assessment.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-31-notified-body-requirements",
      "eu-ai-act-article-33-tasks-notified-bodies",
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk",
      "eu-ai-act-article-17-quality-management",
      "eu-ai-act-annex-iv-technical-documentation-requirements",
      "eu-ai-act-annex-vi-internal-control-conformity-assessment"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-annex-viii-gpai-technical-documentation",
    "title": "EU AI Act Annex VIII - Technical Documentation Requirements for General-Purpose AI Models",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Annex VIII specifies the mandatory technical documentation that providers of general-purpose AI (GPAI) models must prepare and maintain under Article 53 - the documentation requirements are divided into two sections: Section 1 covering all GPAI models (general information, description of model elements and development process, information about training and testing processes and data used, energy consumption, intellectual property measures, known or foreseeable risks); and Section 2 adding supplementary requirements for GPAI models with systemic risk under Article 51 (capability evaluations, adversarial testing, incident response procedures, cybersecurity measures); the Annex VIII documentation differs from the Annex IV documentation for high-risk AI systems and is specific to the GPAI model layer, not the downstream deployer applications built on it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-annex-viii-gpai-technical-documentation.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-52-gpai-provider-obligations",
      "eu-ai-act-article-53-gpai-codes-of-practice",
      "eu-ai-act-article-55-systemic-risk-gpai",
      "eu-ai-act-article-51-gpai-systemic-risk-classification",
      "eu-ai-act-article-30-gpai-technical-doc"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-annex-viii-technical-documentation-gpai",
    "title": "EU AI Act Annex VIII - Technical Documentation Requirements for General Purpose AI Models - Compliance Obligations for GPAI Model Documentation, Training Data Disclosure, and Capability Evaluation Documentation Under EU AI Act",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations for General Purpose AI (GPAI) models under EU AI Act Annex VIII, focusing on technical documentation, training data disclosure, and capability evaluation as mandated by Regulation (EU) 2024/1689.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-1-subject-matter",
    "title": "EU AI Act Article 1 - Subject Matter and Purpose",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 1 establishes that the Regulation lays down harmonised rules on the placing on the market, putting into service, and use of AI systems in the Union, aiming to ensure a high level of protection of health, safety, and fundamental rights enshrined in the Charter of Fundamental Rights of the European Union, and to support innovation - while prohibiting certain AI practices, establishing requirements for high-risk AI systems, laying down transparency obligations for certain AI systems, and setting out rules on GPAI models; it also provides rules for market surveillance and enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-1-subject-matter.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-2-scope",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-6-classification-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-10-data-governance-training",
    "title": "Regulation (EU) 2024/1689 - Article 10: Data and data governance",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Article 10 of the EU AI Act, providers of high-risk AI systems must ensure their training, validation, and testing datasets are relevant, representative, complete, and error-free. This includes implementing robust data governance practices to detect, prevent, and mitigate potential biases to ensure the system performs as intended without discriminatory outcomes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-high-risk",
      "eu-ai-act-bias",
      "nist-sp-1270-managing-ai-bias",
      "iso-iec-24027-bias-fairness"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-article-100-transitional-provisions-notified-bodies",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Articles 111 and 113 (transitional provisions and application dates) and the Article 29 notification route for conformity assessment bodies",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "The final Artificial Intelligence Act contains no grandfathering article for notified bodies; conformity assessment bodies obtain notified body status through the application procedure in Article 29, under which documents and certificates linked to existing designations under other Union harmonisation legislation may be used to support the designation. Transitional relief for AI systems and general-purpose AI models already placed on the market is set out in Article 111, and the staggered application dates, including the early application of the notifying authority and notified body framework from 2 August 2025, are set out in Article 113.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-ai-act-article-101-prohibition-application-dates",
    "title": "REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Application date of the Article 5 prohibitions (Article 113, point (a))",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "Under Article 113, third paragraph, point (a) of Regulation (EU) 2024/1689, Chapters I and II apply from 2 February 2025, which means every prohibition on AI practices in Article 5 became applicable on that single date. The final Regulation does not phase in different Article 5 points on different dates. Non-compliance with the Article 5 prohibitions is subject to administrative fines under Article 99(3) of up to EUR 35,000,000 or, for an undertaking, up to 7 percent of total worldwide annual turnover for the preceding financial year, whichever is higher; Chapter XII on penalties applies from 2 August 2025 under Article 113, third paragraph, point (b). Article 5 applies to AI systems already on the market without benefit of the Article 111 transitional windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-102-gpai-application-date",
    "title": "EU AI Act (Regulation (EU) 2024/1689) Articles 113 and 111(3): Entry into Force, Application Dates and GPAI Transitional Compliance Deadlines",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "Regulation (EU) 2024/1689 applies in general from 2 August 2026, but under Article 113, point (b), Chapter V obligations for providers of general-purpose AI (GPAI) models apply from 2 August 2025, and under Article 111(3) providers of GPAI models placed on the market before 2 August 2025 must take the necessary steps to comply by 2 August 2027. Note that in the final adopted text, Article 102 is an amendment to Regulation (EC) No 300/2008 (aviation security); the GPAI application timeline is established by Article 113 read with Article 111(3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-103-high-risk-systems-transition-period",
    "title": "Regulation (EU) 2024/1689 (Artificial Intelligence Act) - Article 111: AI systems already placed on the market or put into service (transitional provisions)",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-07-02",
    "bluf": "Article 111 of Regulation (EU) 2024/1689 sets the transitional regime for AI systems and models already on the market. High-risk AI systems placed on the market or put into service before 2 August 2026 fall within scope only if, from that date, they are subject to significant changes in their designs; providers and deployers of high-risk systems intended to be used by public authorities must comply by 2 August 2030 in any case. AI components of large-scale IT systems established by the legal acts listed in Annex X and placed on the market before 2 August 2027 must be brought into compliance by 31 December 2030. Providers of general-purpose AI models placed on the market before 2 August 2025 must comply by 2 August 2027. The Article 5 prohibitions apply as referred to in Article 113, third paragraph, point (a), regardless of these transitional windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-104-derogations-specific-systems",
    "title": "REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 59",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "Article 59 of Regulation (EU) 2024/1689 (the EU AI Act) permits personal data lawfully collected for other purposes to be further processed in an AI regulatory sandbox established under Article 57, solely for developing, training and testing certain AI systems in the public interest, subject to the cumulative safeguard conditions of Article 59(1); processing for law enforcement purposes must additionally be based on a specific Union or national law under the control and responsibility of law enforcement authorities, as required by Article 59(2). This personal data processing derogation is distinct from Article 46, which governs derogation from the conformity assessment procedure for placing specific high-risk AI systems on the market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-ai-act-article-105-derogations-authorisation-defence",
    "title": "REGULATION (EU) 2024/1689 (Artificial Intelligence Act) - Article 46 Derogation from Conformity Assessment Procedure and Article 2 Scope Exclusions",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "Article 46 of the EU AI Act allows a market surveillance authority to authorise the placing on the market or putting into service of a specific high-risk AI system, within its territory and for a limited period, before conformity assessment is completed, for exceptional reasons of public security, protection of life and health of persons, environmental protection, or protection of key industrial and infrastructural assets; Article 46(2) adds an urgency path under which law enforcement or civil protection authorities may use the system first and request authorisation during or after use. Separately, Article 2 excludes from the Regulation's scope AI systems used exclusively for military, defence or national security purposes, systems developed solely for scientific research and development, purely personal non-professional use by natural persons, and free and open-source systems that are not high-risk or covered by Article 5 or 50.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "eu-ai-act-article-106-derogations-public-security",
    "title": "REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 46 Derogation from conformity assessment procedure",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "Article 46 of the EU AI Act permits a market surveillance authority to authorise the placing on the market or putting into service of a specific high-risk AI system, for exceptional reasons of public security or the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets, for a limited period while the necessary conformity assessment procedures are being carried out. In duly justified situations of urgency, law enforcement or civil protection authorities may put such a system into service without prior authorisation, provided authorisation is requested during or after the use without undue delay.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-article-107-derogations-biometric-systems",
    "title": "REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 5(2) to 5(7)",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "Article 5(2) to 5(7) of the EU AI Act sets the exception regime under which law enforcement may exceptionally use 'real-time' remote biometric identification systems in publicly accessible spaces: use is limited to the three objectives in Article 5(1)(h), must only confirm the identity of the specifically targeted individual, requires a fundamental rights impact assessment and EU database registration, prior authorisation by a judicial or independent administrative authority (with a 24-hour urgency procedure), an enabling Member State national law, notification to the market surveillance and data protection authorities, and annual reporting to the Commission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-article-108-derogations-critical-infrastructure",
    "title": "REGULATION (EU) 2024/1689 (Artificial Intelligence Act) - Article 46 and Annex III point 2: Derogation from conformity assessment procedure for critical infrastructure AI systems",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity are classified as high-risk under Annex III point 2 of Regulation (EU) 2024/1689. Article 46 permits a market surveillance authority, upon a duly justified request and for exceptional reasons of public security, the protection of life and health of persons, environmental protection, or the protection of key industrial and infrastructural assets, to authorise the placing on the market or putting into service of such a high-risk AI system for a limited period while the conformity assessment procedures under Article 43 are carried out.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-article-109-derogations-law-enforcement",
    "title": "Regulation (EU) 2024/1689 (Artificial Intelligence Act) - Article 46: Derogation from conformity assessment procedure",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "Article 46 of the EU AI Act permits a market surveillance authority, upon a duly justified request and for exceptional reasons of public security or the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets, to authorise the placing on the market or putting into service of a specific high-risk AI system for a limited period while conformity assessment procedures are carried out. In duly justified urgent situations, law-enforcement or civil protection authorities may put such a system into service before that authorisation is granted, provided the authorisation is requested during or after the use without undue delay; if refused, use must stop immediately and all results and outputs must be discarded.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-article-11-technical-documentation",
    "title": "EU AI Act Article 11 and Annex IV - Technical Documentation for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Article 11 of the EU AI Act, providers of high-risk AI systems must create and maintain comprehensive technical documentation as specified in Annex IV before placing the system on the market. This documentation must be detailed enough to allow conformity assessment bodies to evaluate the system's compliance with the Act's requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-high-risk",
      "eu-ai-act-bias",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-article-110-derogations-migration-asylum",
    "title": "REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Annex III point 7: Migration, asylum and border control management",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "Annex III, point 7 of the EU AI Act classifies AI systems used in migration, asylum and border control management as high-risk, in so far as their use is permitted under relevant Union or national law. Covered use cases are polygraphs and similar tools, entry risk assessments, assistance in examining asylum, visa and residence permit applications, and detection or identification of natural persons. Deployment by public bodies triggers a fundamental rights impact assessment under Article 27 and registration in a secure non-public section of the EU database under Article 49(4). Emergency use before conformity assessment is possible only under the Article 46 derogation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-ai-act-article-111-gpai-transitional-provisions",
    "title": "EU AI Act Article 111 - Transitional Provisions for GPAI Models Already on the Market",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 contains transitional provisions for general-purpose AI models that were already placed on the market before 2 August 2025 (12 months after entry into force) - providers of GPAI models already on the market before that date are not required to achieve full Chapter V compliance immediately upon the application date and instead benefit from a transitional period to bring existing models into conformity with the transparency, documentation, copyright, and systemic risk obligations; providers of GPAI models with systemic risk that were already on the market must comply with Article 55 systemic risk obligations (adversarial testing, incident reporting, cybersecurity) within the timeframes established by the AI Office; GPAI models placed on the market for the first time on or after 2 August 2025 must comply with all applicable Chapter V obligations from the date of market placement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-111-gpai-transitional-provisions.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-52-gpai-provider-obligations",
      "eu-ai-act-article-53-gpai-codes-of-practice",
      "eu-ai-act-article-55-systemic-risk-gpai",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-article-51-gpai-systemic-risk-classification"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-112-addressees",
    "title": "REGULATION (EU) 2024/1689 on Artificial Intelligence (Artificial Intelligence Act) - Final Provisions (Chapter XIII): Who the Regulation Binds, Entry into Force and Staged Application",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "The AI Act is binding in its entirety and directly applicable in all Member States without national transposition. It binds the operators in scope under Article 2(1), including providers, deployers, importers, distributors, product manufacturers, authorised representatives and affected persons located in the Union. Under Article 113 it applies in stages: Chapters I and II from 2 February 2025, Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 from 2 August 2025 (except Article 101), general application from 2 August 2026, and Article 6(1) with its corresponding obligations from 2 August 2027. Article 111 governs AI systems and general-purpose AI models already placed on the market, and Article 112 sets the Commission's ongoing evaluation and review checkpoints.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-ai-act-article-113-entry-into-force-application",
    "title": "EU AI Act Article 113 - Entry into Force and Phased Application Dates",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Article 113 establishes the Regulation's entry into force date of 1 August 2024 and the phased application schedule - prohibited AI practices (Article 5) and AI literacy (Article 4) apply from 2 February 2025; GPAI model obligations (Chapter V) and EU governance provisions (Chapter VI) apply from 2 August 2025; the full high-risk AI system requirements (Chapters III and IV) apply from 2 August 2026; a transitional extension to 2 August 2027 applies to high-risk AI systems that are safety components of Annex I sector-regulated products and to high-risk AI systems already lawfully placed on the market before 2 August 2026 that have not undergone substantial modification; providers and deployers must map their AI system portfolios against these application dates to build phased compliance programmes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-113-entry-into-force-application.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-1-subject-matter",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-52-gpai-provider-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-12-record-keeping",
    "title": "EU AI Act Article 12 - Automatic Log-Keeping for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "EU AI Act Article 12 requires providers of high-risk AI systems to ensure their systems automatically generate logs documenting operation including input data references, output results, and system events, retaining logs for a minimum of six months or as required by applicable Union law, with extended retention periods applying to biometric identification and other sensitive high-risk applications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-12-record-keeping.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-13-transparency-deployers",
    "title": "EU AI Act Article 13 - Transparency and Instructions for Use: Information for Deployers of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-06-13",
    "bluf": "Under Article 13 of the EU AI Act, providers of high-risk AI systems are mandated to furnish deployers with comprehensive, clear, and concise instructions for use. This documentation must detail the system's identity, intended purpose, capabilities, limitations, performance metrics, cybersecurity measures, and specific human oversight requirements to ensure proper and compliant deployment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-high-risk",
      "iso-42001-transparency",
      "nist-ai-rmf-map-function",
      "eu-ai-act-fundamental-rights-impact-assessment"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-13-transparency-high-risk",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) - Article 13: Transparency and provision of information to deployers",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "Article 13 of Regulation (EU) 2024/1689 requires providers to design and develop high-risk AI systems so that their operation is sufficiently transparent to enable deployers to interpret the system's output and use it appropriately, and to accompany them with instructions for use containing concise, complete, correct and clear information. The instructions must cover the provider's identity and contact details, the system's characteristics, capabilities and limitations of performance including its intended purpose and levels of accuracy, robustness and cybersecurity, human oversight measures under Article 14, computational and hardware resources needed, expected lifetime and maintenance measures, and mechanisms for collecting, storing and interpreting logs in accordance with Article 12. It applies to all providers placing high-risk AI systems on the EU market or putting them into service.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-cloud-third-party-ict-2022-2554"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-13-transparency-high-risk-ai-instructions-use",
    "title": "EU AI Act Article 13 - Transparency and Provision of Information for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-08-01",
    "bluf": "EU AI Act Article 13 requires providers of high-risk AI systems to ensure the systems are sufficiently transparent to enable deployers to interpret the output and use them appropriately. Providers must supply instructions for use that enable deployers to comply with their obligations under Article 26 and to understand the AI system's capabilities, limitations, intended purpose, and performance in specific conditions. Instructions must include accuracy, robustness, and cybersecurity metrics, as well as human oversight implementation guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system-high-risk-ai",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-14-human-oversight",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) - Article 14: Human Oversight",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "This regulation requires providers and deployers of high-risk AI systems to implement human oversight measures that enable effective monitoring, intervention, and control over AI system operation, as specified in Article 14 of Regulation (EU) 2024/1689. It applies to all operators placing or using high-risk AI systems in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "asean-guide-ai-governance-ethics-2020",
      "eu-dora-cloud-third-party-ict-2022-2554"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-15-robustness",
    "title": "EU AI Act Article 15 - Accuracy, Robustness, and Cybersecurity of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Article 15 requires that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle, with providers specifying accuracy metrics in technical documentation, implementing resilience against adversarial inputs, training data poisoning, and model errors, and maintaining fallback plans for failure modes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-15-robustness.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-16-provider-obligations",
    "title": "EU AI Act Article 16 - Obligations of Providers of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "EU AI Act Regulation 2024/1689 Article 16 establishes the comprehensive set of obligations for providers of high-risk AI systems including compliance with risk management, data governance, technical documentation, automatic logging, transparency, human oversight, accuracy and robustness requirements, registration in the EU database, affixing CE marking, and appointing an EU representative where the provider is established outside the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-16-provider-obligations.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-17-quality-management",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 February 2024 on harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 17: Quality Management System for Providers of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Article 17 of the EU AI Act requires providers of high-risk AI systems to establish, implement, document, and maintain a quality management system (QMS) that ensures compliance with the Act’s requirements. This applies to all providers placing or putting into service high-risk AI systems in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-cloud-third-party-ict-2022-2554"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-17-quality-management-system",
    "title": "Regulation (EU) 2024/1689 (EU AI Act) Article 17: Quality Management System for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Article 17 of the EU AI Act, providers of high-risk AI systems must establish, implement, document, and maintain a comprehensive quality management system (QMS). This system must ensure compliance with the Act throughout the AI system's lifecycle, incorporating risk management, post-market monitoring, data governance, technical documentation, and procedures for handling incidents and corrective actions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-high-risk",
      "eu-ai-act-incident-reporting-article-73",
      "iso-42001-risk-assess",
      "iso-23894-ai-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-17-quality-management-workflow",
    "title": "REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 17 Quality management system",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Providers of high-risk AI systems must establish, implement, document, and maintain a comprehensive quality management system covering the entire AI lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-18-conformity-assessment-doc",
    "title": "EU AI Act Article 18 - Technical Documentation Obligations for Conformity Assessment",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "EU AI Act Regulation 2024/1689 Article 18 requires providers of high-risk AI systems to draw up technical documentation in accordance with Annex IV before placing the system on the market, keep it updated throughout the system's lifetime, make it available to national competent authorities on request, and retain it for ten years after the last system placement on the market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-18-conformity-assessment-doc.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-2-scope",
    "title": "EU AI Act Article 2 - Scope of Application",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Article 2 defines the personal and territorial scope of the Regulation: it applies to providers placing AI systems on the market or putting them into service in the Union regardless of where the provider is established; to deployers of AI systems located in the Union; to providers and deployers of AI systems where the output is used in the Union; to importers and distributors of AI systems; and to product manufacturers that place AI systems on the market with their product - with specific exclusions for AI systems developed or used exclusively for military, national security, or defence purposes, for AI systems used exclusively for research and development purposes before placing on the market, and for Union institutions, bodies, offices and agencies acting as providers or deployers where separate Union rules apply.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-2-scope.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-83-defense-exclusion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-21-corrective-actions",
    "title": "EU AI Act Article 20 - Corrective Actions and Information Obligations for Non-Conforming High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 20 requires providers of high-risk AI systems that do not conform to applicable requirements to take corrective actions to bring the system into conformity, withdraw it, or recall it, and to immediately notify national competent authorities and distributors of the non-conformity and the corrective measures taken.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-21-corrective-actions.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-25-responsibilities",
    "title": "EU AI Act Article 25 - Responsibilities Along the AI Value Chain",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "EU AI Act Article 25 establishes that distributors or deployers who substantially modify a high-risk AI system beyond its intended purpose, or who place their name or trademark on a high-risk AI system, automatically assume all provider obligations under the Act including conformity assessment, CE marking, and technical documentation requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-25-responsibilities.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-26-deployer-obligations",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "This regulation imposes binding obligations on deployers of high-risk AI systems to implement provider instructions, ensure human oversight, maintain logs for 6 months to 3 years, conduct Fundamental Rights Impact Assessments (FRIA) when required, and provide transparency to affected persons, as specified in Article 26 of Regulation (EU) 2024/1689.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-26-obligations-deployers-high-risk-ai",
    "title": "REGULATION (EU) 2024/1689 (Artificial Intelligence Act) - Article 26: Obligations of deployers of high-risk AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article mandates that deployers of high-risk AI systems must use them according to the provider's instructions, ensure input data quality, monitor operations, maintain logs, inform workers, and cooperate with authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-article-27-fria-fundamental-rights",
    "title": "Regulation (EU) 2024/1689 (EU AI Act) Article 27 - Fundamental Rights Impact Assessment for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Article 27 of the EU AI Act, deployers that are public bodies, or private operators providing public services, must conduct and document a Fundamental Rights Impact Assessment (FRIA) before putting a high-risk AI system into use to evaluate its impact on fundamental rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-high-risk",
      "eu-ai-act-cloud-providers-article-25",
      "iso-42005-ai-impact-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-article-28-obligations-distributors",
    "title": "EU AI Act Article 24 - Obligations of Distributors of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 24 requires distributors of high-risk AI systems to verify that the CE marking is affixed, the EU declaration of conformity and instructions for use are available, and the provider has fulfilled all applicable obligations before making the system available on the market, and prohibits distributors from making available systems they know or should know do not conform to EU AI Act requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-28-obligations-distributors.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-29-obligations-importers",
    "title": "EU AI Act Article 23 - Obligations of Importers of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 23 requires importers placing high-risk AI systems on the EU market on behalf of non-EU providers to verify that the provider has conducted a conformity assessment, prepared technical documentation, affixed the CE marking, and appointed an EU representative, and prohibits importers from placing non-conforming systems on the market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-29-obligations-importers.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-3-definitions",
    "title": "EU AI Act Article 3 - Key Definitions for AI Governance Compliance",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Article 3 provides the definitional framework for the entire Regulation, including the core definitions of 'AI system' (a machine-based system designed to operate with varying levels of autonomy and generate outputs such as predictions, recommendations, decisions, or content that can influence real or virtual environments), 'provider', 'deployer', 'authorised representative', 'importer', 'distributor', 'operator', 'notified body', 'substantial modification', 'CE marking', 'GPAI model', 'GPAI model with systemic risk', 'placing on the market', 'putting into service', and 'intended purpose' - definitions that determine which entities bear which obligations under the Regulation and whether specific AI systems fall within the regulatory scope.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-3-definitions.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-1-subject-matter",
      "eu-ai-act-article-2-scope",
      "eu-ai-act-article-6-classification-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-30-gpai-technical-doc",
    "title": "EU AI Act Articles 49 and 71 - EU Database Registration for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 49 requires providers of high-risk AI systems listed in Annex III to register themselves and their systems in the EU database established under Article 71 before placing the system on the EU market or putting it into service, with the registration information specified in Annex VIII; Annex III point 2 critical infrastructure systems are instead registered at national level, law enforcement and migration systems are registered in a secure non-public section, and the database gives market surveillance authorities and the public access to registration information for oversight purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-30-gpai-technical-doc.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-31-notified-body-requirements",
    "title": "EU AI Act Article 31 - Requirements for Notified Bodies",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "EU AI Act Regulation 2024/1689 Article 31 establishes the mandatory requirements that conformity assessment bodies must meet before they can be designated as notified bodies to conduct third-party conformity assessments of high-risk AI systems, requiring that they be established under national law, be legally independent from the organisations they assess, have the necessary technical expertise and personnel competence, have appropriate quality management systems, maintain professional indemnity insurance, and not be subject to conflicts of interest that could affect their impartiality.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-31-notified-body-requirements.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk",
      "eu-ai-act-article-6-classification-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-32-notification-procedure",
    "title": "EU AI Act Article 30 - Notification Procedure for Conformity Assessment Bodies",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 30 establishes the notification procedure through which Member States formally designate and notify the Commission and other Member States about conformity assessment bodies authorised to conduct third-party conformity assessments for high-risk AI systems, requiring notification to be accompanied by the accreditation certificate issued by the national accreditation body, the scope of the assessment activities, and the assessment procedures to be used, and granting other Member States and the Commission a period to raise objections to the notification before the notified body may begin assessment activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-32-notification-procedure.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-31-notified-body-requirements",
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-33-tasks-notified-bodies",
    "title": "EU AI Act Article 34 - Tasks of Notified Bodies",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 34 establishes that notified bodies must carry out the conformity assessment activities for which they are notified, that they must assess provider applications for conformity assessment within prescribed timeframes, that they must conduct assessments with impartiality and independence from commercial pressures, that they must issue, refuse, suspend, or withdraw conformity assessment certificates based on the outcome of their assessment, and that they must report to notifying authorities and market surveillance authorities where they identify compliance risks or withdraw certificates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-33-tasks-notified-bodies.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-31-notified-body-requirements",
      "eu-ai-act-article-32-notification-procedure",
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-34-subsidiaries-subcontracting",
    "title": "EU AI Act Article 33 - Subsidiaries and Subcontracting of Notified Bodies",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 33 establishes that where a notified body subcontracts specific conformity assessment activities or uses a subsidiary to perform those activities, it must ensure that the subcontractor or subsidiary meets the same requirements as the notified body itself, that the notified body remains fully responsible for the work performed by its subcontractors and subsidiaries, that the notified body must inform the notifying authority and the provider of the subcontracting arrangements, and that assessment activities directly related to the AI system's core safety functions may not be subcontracted.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-34-subsidiaries-subcontracting.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-31-notified-body-requirements",
      "eu-ai-act-article-33-tasks-notified-bodies",
      "eu-ai-act-article-36-operational-obligations-notified-bodies"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-35-changes-to-notifications",
    "title": "EU AI Act Article 36 - Changes to Notifications of Notified Bodies",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 36 establishes that the notifying authority must notify the Commission and other Member States of any changes to the notification of a notified body including restrictions, extensions, suspensions, or withdrawals of the notification, that a notifying authority that suspends or withdraws the notification of a notified body must ensure the certificates issued by that body remain valid or are transferred to another notified body, and that the Commission must update the NANDO database to reflect notification changes and that providers relying on certificates issued by a notified body whose notification has changed must assess whether their conformity documentation remains valid.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-35-changes-to-notifications.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-31-notified-body-requirements",
      "eu-ai-act-article-32-notification-procedure",
      "eu-ai-act-article-36-operational-obligations-notified-bodies"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-36-operational-obligations-notified-bodies",
    "title": "EU AI Act Article 34 - Operational Obligations of Notified Bodies",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 34 establishes the operational obligations that notified bodies must comply with when conducting third-party conformity assessments of high-risk AI systems, requiring that they carry out assessments in a proportionate manner avoiding unnecessary burdens for providers, maintain appropriate documentation of assessment activities and decisions, report to the notifying authority and the Commission on their activities, and cooperate with other notified bodies and with national competent authorities in coordinating conformity assessment standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-36-operational-obligations-notified-bodies.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-31-notified-body-requirements",
      "eu-ai-act-article-32-notification-procedure",
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-37-eu-reference-laboratories",
    "title": "EU AI Act Article 84 - Union AI Testing Support Structures for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation (EU) 2024/1689 Article 84 requires the Commission to designate one or more Union AI testing support structures to perform the tasks listed under Article 21(6) of Regulation (EU) 2019/1020 in the area of AI, and provides that these structures shall also provide independent technical or scientific advice at the request of the Board, the Commission, or market surveillance authorities. This provision is the final Act counterpart to the draft-stage EU reference laboratories concept, which appeared as Article 37 in earlier drafts but was not retained under that number; in the final Regulation, Article 37 concerns the challenge to the competence of notified bodies. Providers of high-risk AI systems should monitor Commission designations of testing support structures, be prepared to support independent technical assessments arising within the Article 74 market surveillance framework, and rely on the Article 78 confidentiality obligations for information disclosed in such assessments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-37-eu-reference-laboratories.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-63-market-surveillance",
      "eu-ai-act-article-68-national-competent-authorities"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-article-38-nando-notification",
    "title": "EU AI Act Article 35 - NANDO Notification and Notified Body Identification Numbers",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 35 requires the Commission to maintain and make publicly available an updated list of notified bodies designated under the Regulation, including each notified body's identification number and the activities for which it has been notified, using the NANDO (New Approach Notified and Designated Organisations) information system - enabling providers of high-risk AI systems to identify authorised conformity assessment bodies, verify their active notification status and scope, and include the correct notified body identification number in the EU declaration of conformity and alongside the CE marking as required.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-38-nando-notification.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-31-notified-body-requirements",
      "eu-ai-act-article-32-notification-procedure",
      "eu-ai-act-article-33-tasks-notified-bodies"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-39-conformity-assessment-bodies-third-countries",
    "title": "EU AI Act Article 39 - Conformity Assessment Bodies from Third Countries",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 39 provides that conformity assessment bodies established in third countries may be designated as notified bodies under the Regulation only where a bilateral agreement between the Union and the third country exists that recognises the conformity assessment bodies of that country, subject to equivalent requirements to those set out in Chapter III Section 4 for EU notified bodies - ensuring that third-country conformity assessment bodies that perform EU AI Act assessments meet the same competence, impartiality, and operational requirements as EU-established notified bodies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-39-conformity-assessment-bodies-third-countries.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-31-notified-body-requirements",
      "eu-ai-act-article-32-notification-procedure",
      "eu-ai-act-article-38-nando-notification"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-4-ai-literacy",
    "title": "EU AI Act Article 4 - AI Literacy Obligations for Providers and Deployers",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Article 4 requires providers and deployers of AI systems to take measures to ensure, to the best of their ability, a sufficient level of AI literacy among their staff and all other persons dealing with the operation and use of AI systems on their behalf - taking into account their technical knowledge, experience, education and training, and the context in which the AI systems are to be used, as well as the persons or groups of persons on whom the AI systems are to be used.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-4-ai-literacy.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-article-26-deployer-obligations",
      "eu-ai-act-article-14-human-oversight"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-4-ai-literacy-obligations-providers-deployers",
    "title": "EU AI Act Article 4 - AI Literacy Obligations for Providers and Deployers",
    "domain": "Education & Research",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "EU AI Act Article 4 requires providers and deployers of AI systems to ensure their staff and agents have sufficient AI literacy - technical knowledge, contextual understanding, and awareness of risks - to operate, oversee, and make informed decisions about AI systems. Applicable from August 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-40-harmonised-standards",
    "title": "EU AI Act Article 40 - Harmonised Standards and Presumption of Conformity",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Article 40 establishes that high-risk AI systems complying with harmonised standards adopted pursuant to Regulation (EU) 1025/2012 and cited in the Official Journal are presumed to conform with the corresponding requirements of Chapter III Section 2 (Articles 8-15) - providers can use harmonised standards as the primary technical compliance pathway, with the Commission mandating European standardisation organisations (CEN/CENELEC) to develop AI-specific harmonised standards; where no relevant harmonised standards exist or where standards do not fully cover the requirements, common specifications under Article 41 may supplement or replace the harmonised standard pathway.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-40-harmonised-standards.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-8-compliance-with-requirements",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-41-common-specifications",
      "eu-ai-act-article-42-presumption-of-conformity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-41-common-specifications",
    "title": "EU AI Act Article 41 - Common Specifications for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Article 41 empowers the Commission to adopt implementing acts establishing common specifications for the requirements of Chapter III Title II where harmonised standards under Article 40 do not exist or are not yet available, that common specifications are legally mandatory compliance benchmarks for high-risk AI systems in the absence of relevant harmonised standards, that compliance with applicable common specifications gives rise to the presumption of conformity under Article 42, and that providers may depart from common specifications only where they can demonstrate their solution provides an equivalent or higher level of compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-41-common-specifications.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-harmonised-standards-article-40",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-42-presumption-of-conformity",
    "title": "EU AI Act Article 42 - Presumption of Conformity with Certain Requirements",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 42 establishes that high-risk AI systems that have been trained and tested on data reflecting the specific geographical, contextual, and functional settings in which they will be deployed are presumed to comply with the data and data governance requirements of Article 10, and that high-risk AI systems that have been developed in accordance with a specific regulatory framework relating to cybersecurity and that have received a European cybersecurity certificate under Regulation (EU) 2019/881 are presumed to comply with the cybersecurity requirements of Article 15 to the extent covered by the cybersecurity certificate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-42-presumption-of-conformity.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-15-robustness"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-43-conformity-assessment-procedures-notified-bodies",
    "title": "REGULATION (EU) 2024/1689 (Artificial Intelligence Act) - Article 43: Conformity assessment procedures for high-risk AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "This article mandates specific conformity assessment procedures for providers of high-risk AI systems, determining when an internal control assessment is sufficient versus when a third-party notified body must be involved.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-46-derogation-conformity-assessment",
    "title": "EU AI Act Article 46 - Derogation from Conformity Assessment Procedures",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 46 provides an exceptional derogation procedure allowing market surveillance authorities to authorise the placing on the market or putting into service of specific high-risk AI systems within their territory where it is justified for public security reasons or for the protection of life and health of persons, environmental protection, or key industrial and infrastructure assets - the derogation is granted by national market surveillance authorities for a limited period, does not replace the applicable conformity assessment obligations, and must be immediately notified to the Commission and other Member States through the Union Safeguard Mechanism.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-46-derogation-conformity-assessment.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk",
      "eu-ai-act-article-63-market-surveillance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-47-eu-declaration-of-conformity",
    "title": "EU AI Act Article 47 - EU Declaration of Conformity",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 47 requires providers of high-risk AI systems to draw up a written EU declaration of conformity confirming that the system fulfils all applicable EU AI Act requirements, that the declaration must contain the specified mandatory information including provider identity, system description, conformity assessment procedure applied, applicable standards, and notified body details where relevant, that the provider must retain the declaration for ten years after the system is placed on the market, and that the declaration must be updated whenever a substantial modification to the system is made.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-47-eu-declaration-of-conformity.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk",
      "eu-ai-act-article-48-ce-marking-affixation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-48-ce-marking-affixation",
    "title": "EU AI Act Article 48 - CE Marking Affixation Rules and Restrictions",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 48 establishes that the CE conformity marking for high-risk AI systems must be affixed visibly, legibly, and indelibly before the AI system is placed on the market or put into service; only providers who have completed the applicable conformity assessment procedure and met all requirements of Chapter III may affix the CE marking; the CE marking may not be affixed where the provider cannot ensure compliance, and affixing a false CE marking or misleading the market about CE marking status constitutes an infringement of the EU AI Act that triggers market surveillance authority corrective action.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-48-ce-marking-affixation.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-5-prohibited-overview",
    "title": "EU AI Act - Article 5 Prohibited AI Practices: Complete Framework Overview",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 5 establishes eight categories of prohibited AI practices that represent the highest tier of AI risk - practices so harmful to fundamental rights, safety, and human dignity that they are absolutely prohibited without exception or derogation; Article 5(1) prohibitions applicable from 2 February 2025 per Article 113(2): (a) AI systems that deploy subliminal techniques or purposefully manipulative or deceptive techniques to materially distort the behaviour of a person or group in a manner that causes or is likely to cause significant harm; (b) AI systems that exploit vulnerabilities of persons due to age, disability, or social or economic situation to materially distort their behaviour in a manner causing significant harm; (c) AI systems used for social scoring of natural persons by or on behalf of public authorities leading to detrimental treatment; (d) AI systems that make risk assessments of natural persons to assess or predict the risk of criminal offending based solely on profiling or personality traits; (e) AI systems that create or expand facial recognition databases through untargeted scraping of facial images from internet or CCTV footage; (f) AI systems that infer emotions of natural persons in workplaces or educational institutions, except for medical or safety reasons; (g) AI systems that categorise natural persons based on biometric data to infer race, political opinions, trade union membership, religious/philosophical beliefs, sex life, or sexual orientation; (h) real-time remote biometric identification systems used by law enforcement in publicly accessible spaces, subject to three narrow exceptions; the Article 5 prohibitions are enforced by national competent authorities and subject to the highest EU AI Act penalty tier: EUR 35 million or 7% of annual worldwide turnover under Article 99(3); national market surveillance authorities may require the immediate cessation of prohibited AI systems without prior warning.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-5-prohibited-overview.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-prohibited-subliminal-manipulation",
      "eu-ai-act-prohibited-social-scoring",
      "eu-ai-act-prohibited-predictive-policing",
      "eu-ai-act-prohibited-facial-scraping",
      "eu-ai-act-prohibited-emotion-recognition",
      "eu-ai-act-prohibited-biometric-categorisation",
      "eu-ai-act-prohibited-realtime-biometric-id",
      "eu-ai-act-penalties-and-enforcement"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-5-prohibited-practices",
    "title": "Regulation (EU) 2024/1689 (EU AI Act) Article 5: Prohibited Artificial Intelligence Practices",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "Article 5 of the EU AI Act establishes an absolute ban on placing on the market, putting into service, or using certain AI practices considered to pose an unacceptable risk to fundamental rights. This includes AI systems that deploy subliminal manipulation, exploit vulnerabilities of specific groups, conduct social scoring, and, with limited exceptions, use real-time remote biometric identification in publicly accessible spaces for law enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "iso-42001-risk-assess",
      "nist-ai-rmf-1-0",
      "eu-ai-act-fundamental-rights-impact-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-article-50-gpai-transparency",
    "title": "Regulation (EU) 2024/1689 on harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 50: Transparency obligations for providers and deployers of certain AI systems, and Article 53: Obligations for providers of general-purpose AI models",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "Article 50 of the EU AI Act imposes transparency obligations on providers and deployers of certain AI systems: providers must inform natural persons that they are interacting with an AI system unless this is obvious, providers must mark synthetic audio, image, video and text output in a machine-readable format detectable as artificially generated, deployers must inform persons exposed to emotion recognition or biometric categorisation systems, and deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest. Transparency obligations for providers of general purpose AI (GPAI) models are set out separately in Article 53, which requires technical documentation per Annex XI, information for downstream providers per Annex XII, a copyright compliance policy, and a publicly available summary of training content.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-data-governance-act-2022-cloud-data-sharing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-50-transparency-obligations",
    "title": "EU AI Act Article 50 - Transparency Obligations for Certain AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "EU AI Act Regulation 2024/1689 Article 50 requires providers of AI systems that interact directly with natural persons to ensure those persons are informed they are interacting with an AI system, requires providers and deployers of AI systems generating synthetic audio, image, video, or text content to disclose its artificial origin, and requires providers of GPAI systems generating synthetic content to implement machine-readable marking or watermarking to enable detection of artificially generated content.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-50-transparency-obligations.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-51-gpai-model-registration",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 on Artificial Intelligence (Artificial Intelligence Act) and amending certain Union Legislative Acts - Article 51: Classification of General-Purpose AI Models as General-Purpose AI Models with Systemic Risk",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "Article 51 of the EU AI Act classifies a general-purpose AI (GPAI) model as a GPAI model with systemic risk where it has high impact capabilities evaluated using appropriate technical tools and methodologies, including indicators and benchmarks, or where the European Commission decides it has equivalent capabilities or impact based on the criteria in Annex XIII. High impact capabilities are presumed where the cumulative amount of computation used for training, measured in floating point operations, is greater than 10^25 FLOPs. Under the Article 52 procedure, the provider must notify the Commission without delay and in any event within two weeks after the classification condition is met or it becomes known that it will be met, may submit substantiated arguments against classification, may request reassessment at the earliest six months after a designation decision, and the Commission publishes and maintains a list of GPAI models with systemic risk. Classification triggers the separate provider obligations under Article 55.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "anthropic-responsible-scaling-policy-v2-1-2025",
      "eu-data-governance-act-2022-cloud-data-sharing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-51-gpai-systemic-risk-classification",
    "title": "EU AI Act Article 51 - Classification of GPAI Models with Systemic Risk",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "EU AI Act Regulation 2024/1689 Article 51 establishes that a general-purpose AI model is classified as a GPAI model with systemic risk where it is trained using a total computing power of more than 10^25 floating point operations (FLOPs), that such models are presumed to have systemic risk and are subject to the enhanced obligations under Article 55, that the Commission may update the FLOPs threshold by delegated act after consulting the AI Board, that the AI Office may classify a GPAI model below the threshold as having systemic risk based on qualitative criteria including cross-sector impact, reach of the model, and the degree of autonomy and irreversibility of its outputs, and that providers may rebut the systemic risk presumption by demonstrating to the AI Office that their model does not pose systemic risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-51-gpai-systemic-risk-classification.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-53-general-purpose-ai-transparency",
      "eu-ai-act-article-55-systemic-risk-gpai",
      "eu-ai-act-article-56-ai-office"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-52-gpai-provider-obligations",
    "title": "EU AI Act Article 53 - Obligations for Providers of General-Purpose AI Models",
    "domain": "AI Governance & Law",
    "version": "1.0.2",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 53 establishes baseline obligations for all providers of general-purpose AI models placed on the EU market, requiring them to draw up and maintain technical documentation specified in Annex XI, to make available to downstream providers integrating the GPAI model into their AI systems the information and documentation necessary to comply with their EU AI Act obligations, to establish a policy to comply with Union copyright law including the text and data mining exception, and to publish a sufficiently detailed summary of the content used for training the model.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-52-gpai-provider-obligations.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-53-general-purpose-ai-transparency",
      "eu-ai-act-article-51-gpai-systemic-risk-classification",
      "eu-ai-act-article-55-systemic-risk-gpai"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-53-general-purpose-ai-transparency",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 February 2024 on harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 53: Transparency obligations for general-purpose AI models",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Article 53 of the EU AI Act requires providers of general-purpose AI (GPAI) models to publish detailed summaries of training data, comply with EU copyright law, respect opt-out signals from rights holders, maintain technical documentation, and implement watermarking for synthetic content. Applies to all GPAI model providers placing models on the EU market or whose outputs are used in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "berne-convention-1886-2024-literary-artistic-works",
      "c2pa-content-provenance",
      "exif-standard-metadata",
      "iptc-photo-metadata"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-53-gpai-codes-of-practice",
    "title": "EU AI Act Article 56 - GPAI Model Codes of Practice",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 56 requires the AI Office to facilitate the drawing up of codes of practice by providers of GPAI models and other stakeholders, covering the technical, operational, and governance obligations applicable to GPAI model providers under Chapter V - in particular compliance with Article 56's transparency and documentation obligations and Article 55's systemic risk evaluation, red-teaming, and incident reporting obligations for systemic risk GPAI models; compliance with a relevant code of practice creates a presumption of conformity with the applicable Chapter V obligations for providers participating in the code.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-53-gpai-codes-of-practice.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-52-gpai-provider-obligations",
      "eu-ai-act-article-55-systemic-risk-gpai",
      "eu-ai-act-article-56-ai-office"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-54-gpai-authorised-representatives",
    "title": "EU AI Act Article 54 - Authorised Representatives of GPAI Model Providers",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 54 requires providers of general-purpose AI models established outside the European Union who make their models available in the EU to appoint an authorised representative established in the EU before placing the model on the EU market, that the authorised representative is empowered to act on behalf of the non-EU provider in all matters relating to EU AI Act GPAI compliance including cooperation with the AI Office and national competent authorities, and that the AI Office and national competent authorities may address compliance communications and enforcement actions to the authorised representative in place of the non-EU provider.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-54-gpai-authorised-representatives.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-52-gpai-provider-obligations",
      "eu-ai-act-article-53-general-purpose-ai-transparency",
      "eu-ai-act-article-56-ai-office"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-55-systemic-risk-gpai",
    "title": "EU AI Act Article 55 - Obligations for General-Purpose AI Models with Systemic Risk",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "EU AI Act Regulation 2024/1689 Article 55 imposes additional obligations on providers of general-purpose AI models that are designated as posing systemic risk - specifically those trained with compute exceeding 10^25 floating point operations - requiring adversarial testing, incident reporting to the European AI Office, cybersecurity protections for model weights and infrastructure, and reporting of energy consumption during training.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-55-systemic-risk-gpai.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-56-ai-office",
    "title": "EU AI Act Article 64 - Establishment of the AI Office",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 64 establishes the AI Office within the European Commission as the central EU-level supervisory body responsible for monitoring and enforcing the rules applicable to general purpose AI models including GPAI models with systemic risk, coordinating with national competent authorities on cross-border AI enforcement, conducting evaluations and investigations of GPAI model providers, and contributing to the development of harmonised standards and codes of practice for the EU AI Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-56-ai-office.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-58-ai-board",
    "title": "EU AI Act Article 65 - European Artificial Intelligence Board",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 65 establishes the European Artificial Intelligence Board (EAIB) composed of one senior representative from each Member State's national competent authority, the European Data Protection Supervisor as observer, and chaired by a Commission representative, to advise and assist the Commission and Member States in ensuring consistent application of the EU AI Act, promote coordination between national supervisory authorities, and issue recommendations and opinions on AI governance matters.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-58-ai-board.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-56-ai-office"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-59-edps-authority",
    "title": "EU AI Act Article 70 - EDPS as Competent Authority for EU Institutions",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 70 designates the European Data Protection Supervisor as the competent authority responsible for supervising EU institutions, bodies, offices, and agencies in their compliance with the EU AI Act when they develop, deploy, or use AI systems, that the EDPS has the same supervisory powers over EU institutions as national competent authorities have over private sector entities under the EU AI Act, that EU institutions deploying high-risk AI systems must comply with the same obligations as other deployers under the EU AI Act, and that the EDPS coordinates with the AI Board and national competent authorities on cross-cutting AI governance matters.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-59-edps-authority.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-68-national-competent-authorities",
      "eu-ai-act-article-58-ai-board"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-6-classification-high-risk",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act)",
    "domain": "AI Governance & Law",
    "version": "1.0.2",
    "last_updated": "2026-07-02",
    "bluf": "This regulation establishes the criteria for classifying AI systems as high-risk under Article 6 of the EU AI Act, based on either integration into a product covered by Annex I safety legislation or falling within specific high-risk use cases listed in Annex III. Providers must self-classify their AI systems and comply with stringent conformity and documentation obligations under Articles 6 and 16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-cloud-third-party-ict-2022-2554"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-60-eu-database-high-risk-ai",
    "title": "EU AI Act Article 71 - EU Database for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 71 establishes an EU-wide database for stand-alone high-risk AI systems that providers must register their systems in before placing them on the market or putting them into service, with public authorities deploying high-risk AI systems in law enforcement, judicial, migration, and asylum contexts registered by the relevant market surveillance authority rather than the deploying authority itself, and the database publicly accessible to provide transparency for citizens and downstream users about high-risk AI systems operating on the EU market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-60-eu-database-high-risk-ai.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-16-provider-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-61-post-market-monitoring",
    "title": "EU AI Act Article 72 - Post-Market Monitoring for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 72 requires providers of high-risk AI systems to establish and document a post-market monitoring system that actively collects and analyses data on system performance throughout the system lifetime, that this post-market monitoring plan must be part of the technical documentation under Article 11, that deployers must cooperate with providers in post-market monitoring by providing access to relevant data and performance information, and that where malfunctions, performance deficiencies, or unforeseeable risks are identified through post-market monitoring, providers must take corrective actions and report serious incidents under Article 73.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-61-post-market-monitoring.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-11-technical-documentation",
      "eu-ai-act-article-62-serious-incident-reporting",
      "eu-ai-act-article-26-deployer-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-62-reporting-serious-incidents",
    "title": "EU AI Act Article 73 - Reporting Obligations for Serious Incidents",
    "domain": "AI Governance & Law",
    "version": "1.0.2",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 73 requires providers of high-risk AI systems placed on the Union market to report serious incidents to the market surveillance authorities of the Member States where the incident occurred - a serious incident being any incident or malfunction of a high-risk AI system that directly or indirectly leads to the death of a person, serious damage to a person's health, serious damage to property or the environment, a serious and irreversible disruption of a critical service or infrastructure, or a violation of obligations under Union law protecting fundamental rights - with the incident report submitted without undue delay and in any event no later than 15 days after the provider becomes aware of the incident.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-62-reporting-serious-incidents.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-61-post-market-monitoring",
      "eu-ai-act-article-63-market-surveillance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-62-serious-incident-reporting",
    "title": "Regulation (EU) 2024/1689 - Article 73: Reporting of serious incidents",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-06-14",
    "bluf": "Under Article 73 of the EU AI Act, providers of high-risk AI systems must report any serious incident or malfunctioning that breaches fundamental rights obligations to the market surveillance authorities of the Member States where the incident occurred. This involves a multi-stage reporting process with strict deadlines: an initial notification within 2 days, a follow-up within 8 days, and a final report within 15 days of establishing a causal link or a reasonable likelihood thereof.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-high-risk",
      "eu-ai-act-market-surveillance-chapter-viii",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-article-63-market-surveillance",
    "title": "EU AI Act Article 74 - Market Surveillance of AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 74 designates national competent authorities as market surveillance authorities for AI systems under Regulation (EU) 2019/1020, grants them powers to request technical documentation, conduct inspections and testing of AI systems, require access to training data and algorithms, and impose corrective measures including withdrawal, recall, and restrictions on market access for non-compliant high-risk AI systems, with cross-border coordination mechanisms for AI systems placed on markets in multiple Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-63-market-surveillance.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-68-national-competent-authorities"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-64-access-data-documentation-market-surveillance",
    "title": "Regulation (EU) 2024/1689 on artificial intelligence (Artificial Intelligence Act) - Article 74(12) and 74(13): Market surveillance access to data, documentation and source code",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-07-02",
    "bluf": "Providers of high-risk AI systems must grant market surveillance authorities full access to documentation and to the training, validation and testing data sets under Article 74(12), including through APIs or other remote-access means where appropriate and subject to security safeguards, and must grant access to source code under Article 74(13) upon a reasoned request only when both statutory conditions are fulfilled.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-64-testing-real-world-conditions",
    "title": "EU AI Act Article 60 - Testing of High-Risk AI Systems in Real World Conditions Outside AI Regulatory Sandboxes",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 60 permits providers or prospective providers of high-risk AI systems listed in Annex III to conduct testing in real world conditions outside AI regulatory sandboxes, alone or in partnership with deployers or prospective deployers, subject to strict conditions: a real-world testing plan submitted to the market surveillance authority of the Member State where testing will occur (tacit approval if the authority does not respond within 30 days, unless national law requires explicit approval), registration of the testing in the EU database with a Union-wide unique single identification number, establishment in the Union or an appointed legal representative, a maximum testing duration of six months extendable once by a further six months, appropriate protection of subjects belonging to vulnerable groups due to their age or disability, freely given informed consent of subjects under Article 61, effective oversight by suitably qualified persons, and the ability to effectively reverse and disregard the predictions, recommendations or decisions of the AI system; serious incidents during testing must be reported under Article 73 with immediate mitigation or suspension of testing, and market surveillance authorities supervise real-world testing under Article 76, including the power to require modification, suspension or termination of the testing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-64-testing-real-world-conditions.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-63-market-surveillance",
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-65-market-surveillance-corrective-actions",
    "title": "EU AI Act Article 79 - Procedure for Dealing with AI Systems Presenting a Risk at National Level",
    "domain": "AI Governance & Law",
    "version": "1.0.2",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 79 establishes the procedure by which national market surveillance authorities deal with high-risk AI systems presenting a risk to health, safety, or fundamental rights, requiring authorities to evaluate identified risks, require operators to take corrective measures including restriction or withdrawal from the market within a specified timeframe, notify the Commission and other Member States of the measures taken through the safety gateway, and that operators who fail to take required corrective measures may be subject to authority-imposed market restrictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-65-market-surveillance-corrective-actions.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-63-market-surveillance",
      "eu-ai-act-article-21-corrective-actions",
      "eu-ai-act-article-68-national-competent-authorities"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-66-formal-non-compliance",
    "title": "EU AI Act Article 83 - Formal Non-Compliance of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.2",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 83 establishes the procedure by which market surveillance authorities deal with high-risk AI systems that present formal non-compliance with the EU AI Act - such as the absence of CE marking, incorrect CE marking affixation, non-existent or incomplete EU declaration of conformity, or missing technical documentation - without those formal deficiencies necessarily indicating that the system presents an actual risk to health, safety, or fundamental rights, requiring the authority to notify the operator and the Commission of the formal non-compliance and to require remediation within a reasonable timeframe.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-66-formal-non-compliance.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-63-market-surveillance",
      "eu-ai-act-article-47-eu-declaration-of-conformity",
      "eu-ai-act-2024-1689-article-43-conformity-assessment-procedures-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-67-compliant-systems-presenting-risk",
    "title": "EU AI Act Article 82 - Compliant High-Risk AI Systems That Present a Risk",
    "domain": "AI Governance & Law",
    "version": "1.0.2",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 82 establishes the procedure for dealing with high-risk AI systems that are formally compliant with the EU AI Act - holding a valid conformity assessment and CE marking - but that nonetheless present a risk to health, safety, or fundamental rights, requiring the market surveillance authority to evaluate the risk, require the operator to take all appropriate measures to eliminate the risk within the required timeframe, and notify the Commission and other Member States through the safety gateway, with the Commission able to adopt implementing acts requiring all Member States to take similar measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-67-compliant-systems-presenting-risk.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-63-market-surveillance",
      "eu-ai-act-article-65-market-surveillance-corrective-actions",
      "eu-ai-act-article-61-post-market-monitoring"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-68-national-competent-authorities",
    "title": "EU AI Act Article 70 - National Competent Authorities",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 70 requires each Member State to designate at least one national competent authority responsible for implementing and enforcing the EU AI Act within its territory, to ensure the authority has sufficient resources and legal powers to carry out its functions including market surveillance and notified body oversight, to notify the Commission of the designated authority, and to ensure coordination between the national authority and other relevant national bodies including data protection supervisory authorities and sectoral regulators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-68-national-competent-authorities.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-56-ai-office"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-69-supervisory-authority-cooperation",
    "title": "EU AI Act Cross-Border Authority Cooperation and Mutual Assistance - Articles 74, 75 and 66 of Regulation (EU) 2024/1689",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation (EU) 2024/1689 establishes cross-border cooperation and mutual assistance between the authorities supervising AI systems through three final provisions. Article 74 applies Regulation (EU) 2019/1020 on market surveillance to AI systems, requires Member States to facilitate coordination between market surveillance authorities and other relevant national authorities, and permits market surveillance authorities to propose joint activities, including joint investigations, with coordination support from the AI Office. Article 75 governs mutual assistance for the market surveillance and control of general-purpose AI systems, including a duty on the AI Office to supply relevant information to a requesting authority without delay and in any event within 30 days. Article 66 tasks the European Artificial Intelligence Board with contributing to the coordination among national competent authorities and with collecting and sharing technical and regulatory expertise and best practices among Member States. Numbering note: in the final Act, Article 69 concerns access of Member States to the pool of experts of the scientific panel; the authority cooperation subject matter of this node is located in Articles 74, 75 and 66.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-69-supervisory-authority-cooperation.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-68-national-competent-authorities",
      "eu-ai-act-article-63-market-surveillance",
      "eu-ai-act-article-58-ai-board"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-article-7-high-risk-classification-updates",
    "title": "EU AI Act Article 7 - Amendments to the List of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "EU AI Act Regulation 2024/1689 Article 7 grants the European Commission power to amend Annex III of the EU AI Act through delegated acts to add, modify, or remove categories of high-risk AI systems, based on defined criteria including the severity and reversibility of harm, the number of persons affected, the degree of autonomy, and the dependency of vulnerable persons on the AI system, ensuring the high-risk classification list remains current as AI technology evolves.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-7-high-risk-classification-updates.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-70-confidentiality",
    "title": "EU AI Act Article 78 - Confidentiality Obligations",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 78 imposes confidentiality obligations on national competent authorities, notified bodies, the AI Board, the AI Office, and all persons involved in implementing the EU AI Act, requiring them to protect trade secrets and commercially sensitive information obtained during market surveillance and investigative activities, permitting information sharing between EU institutions and between Member State competent authorities subject to those confidentiality obligations, and establishing whistleblower protection for persons who report AI Act violations in good faith.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-70-confidentiality.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-63-market-surveillance",
      "eu-ai-act-article-68-national-competent-authorities"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-71-fines",
    "title": "EU AI Act Article 99 - Penalties and Fines for EU AI Act Violations",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 99 establishes the EU's penalty framework for AI Act violations including administrative fines up to EUR 35 million or 7% of total worldwide annual turnover for prohibited AI practices, EUR 15 million or 3% of turnover for violations of obligations including high-risk AI system requirements, and EUR 7.5 million or 1.5% of turnover for providing incorrect information to authorities, with reduced maximums for SMEs and higher maximums for GPAI model systemic risk violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-71-fines.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-72-ai-regulatory-sandboxes",
    "title": "EU AI Act Article 57 - AI Regulatory Sandboxes",
    "domain": "AI Governance & Law",
    "version": "1.0.2",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 57 requires Member States to establish at least one AI regulatory sandbox at national level, that sandboxes provide a controlled environment in which AI systems can be developed, trained, tested, and validated under real-world conditions before market placement with the facilitated supervision of the national competent authority, that sandbox participation does not exempt providers from EU AI Act obligations but enables innovative development with regulatory guidance, and that SMEs and startups are granted priority access to national AI regulatory sandboxes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-72-ai-regulatory-sandboxes.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-68-national-competent-authorities"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-72-eu-database-high-risk-ai-systems",
    "title": "REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 71: EU database for high-risk AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "This article mandates the European Commission to establish and maintain a publicly accessible EU database for high-risk AI systems, and requires providers to register specific information about their systems in it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-73-penalties",
    "title": "EU AI Act Article 99 - Penalties",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 99 requires Member States to lay down rules on penalties applicable to infringements of the EU AI Act, establishing maximum administrative fine levels as a floor for national penalty regimes - up to EUR 35 million or 7% of total worldwide annual turnover (whichever is higher) for violations of the prohibited AI practices under Article 5, up to EUR 15 million or 3% of worldwide annual turnover for infringements of other obligations, and up to EUR 7.5 million or 1.5% of worldwide annual turnover for the supply of incorrect, incomplete, or misleading information to authorities - with reduced maxima for SMEs and start-ups on a proportionality basis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-73-penalties.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-article-68-national-competent-authorities"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-74-gpai-administrative-fines",
    "title": "EU AI Act Article 101 - Administrative Fines for Providers of General-Purpose AI Models",
    "domain": "AI Governance & Law",
    "version": "1.0.2",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 101 grants the AI Office the power to impose administrative fines directly on providers of general-purpose AI models for infringements of the GPAI-specific obligations under Chapter V of the EU AI Act, establishing a maximum administrative fine of EUR 15 million or 3% of worldwide annual turnover (whichever is higher) for GPAI model provider infringements other than systemic risk violations, and establishing that the AI Office must follow the due process procedures including hearing the provider before imposing any fine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-74-gpai-administrative-fines.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-52-gpai-provider-obligations",
      "eu-ai-act-article-56-ai-office",
      "eu-ai-act-article-73-penalties"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-75-gpai-systemic-risk-penalties",
    "title": "EU AI Act Article 101 - Penalties for Providers of GPAI Models with Systemic Risk",
    "domain": "AI Governance & Law",
    "version": "1.0.2",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 101 establishes that providers of general-purpose AI models with systemic risk who infringe the obligations under Article 55 - including failure to conduct model evaluations, adversarial testing, incident reporting, cybersecurity measures, and energy efficiency reporting - are subject to administrative fines imposed by the AI Office of up to EUR 35 million or 7% of worldwide annual turnover (whichever is higher), reflecting the heightened compliance obligations and enforcement consequences that apply to GPAI models posing the greatest systemic risk to EU society and economy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-75-gpai-systemic-risk-penalties.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-55-systemic-risk-gpai",
      "eu-ai-act-article-51-gpai-systemic-risk-classification",
      "eu-ai-act-article-74-gpai-administrative-fines"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-76-real-world-testing-supervision",
    "title": "EU AI Act Article 76 - Supervision of Testing in Real-World Conditions",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 76 empowers market surveillance authorities to supervise testing of high-risk AI systems in real-world conditions, granting authorities the right to access testing premises, examine test plans and data, request documentation, and suspend or stop testing where the AI system presents a serious risk to health, safety, or fundamental rights - ensuring that real-world testing does not circumvent market surveillance obligations and that authorities can intervene before harmful systems cause damage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-76-real-world-testing-supervision.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-63-market-surveillance",
      "eu-ai-act-article-68-national-competent-authorities",
      "eu-ai-act-article-61-post-market-monitoring"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-77-fundamental-rights-public-authority-deployers",
    "title": "EU AI Act Articles 77 and 27 - Fundamental Rights Authority Powers and Impact Assessment for Public Authority Deployers",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 77 gives national public authorities or bodies that supervise or enforce obligations under Union law protecting fundamental rights, including the right to non-discrimination, the power to request and access any documentation created or maintained under the Regulation in relation to high-risk AI systems referred to in Annex III, and, where that documentation is insufficient, to make a reasoned request to the market surveillance authority to organise technical testing of the system; each Member State was required to identify and publish the list of these authorities by 2 November 2024. The related Article 27 requires deployers that are bodies governed by public law, private entities providing public services, and deployers of high-risk AI systems referred to in Annex III points 5(b) and (c) to perform a fundamental rights impact assessment before first use of the system and to notify the market surveillance authority of its results using the AI Office template.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-77-fundamental-rights-public-authority-deployers.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-26-deployer-obligations",
      "eu-ai-act-article-27-fria-fundamental-rights",
      "eu-ai-act-article-60-eu-database-high-risk-ai"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-78-access-to-data-evidence",
    "title": "EU AI Act Article 78 - Confidentiality Obligations in Market Surveillance",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act Regulation 2024/1689 Article 78 establishes confidentiality obligations for national competent authorities, the AI Board, the AI Office, and the Commission when exercising their powers under the Regulation - requiring them to protect commercial secrets and confidential professional information obtained in the course of their supervisory and enforcement activities, while also providing that the obligation to protect confidentiality does not prevent the disclosure of information necessary to carry out market surveillance activities and to ensure compliance, and that the confidentiality obligations are subject to Union and national law provisions on transparency, public access to documents, and freedom of information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-78-access-to-data-evidence.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-63-market-surveillance",
      "eu-ai-act-article-68-national-competent-authorities",
      "eu-ai-act-article-70-confidentiality"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-79-right-to-lodge-complaint",
    "title": "EU AI Act Article 85 - Right to Lodge a Complaint with a Market Surveillance Authority",
    "domain": "AI Governance & Law",
    "version": "1.0.2",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 85 grants any natural or legal person the right to lodge a complaint with a national market surveillance authority where they have reason to consider that there has been an infringement of the EU AI Act, that the market surveillance authority must investigate the complaint to the extent appropriate and inform the complainant of the outcome, and that this right complements but does not replace judicial remedies available to affected persons under Article 80 and Article 81, creating a non-judicial complaint pathway for individuals and civil society organisations to trigger regulatory oversight of potentially non-compliant AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-79-right-to-lodge-complaint.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-63-market-surveillance",
      "eu-ai-act-article-68-national-competent-authorities",
      "eu-ai-act-article-26-deployer-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-8-compliance-with-requirements",
    "title": "Regulation (EU) 2024/1689 (EU AI Act) Article 8 - Compliance with the requirements",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-06-13",
    "bluf": "Article 8 of Regulation (EU) 2024/1689 is the gateway provision for Chapter III Section 2 of the EU AI Act on high-risk AI systems. Article 8(1) requires that high-risk AI systems shall comply with the requirements laid down in this Section (Articles 9-15), taking into account their intended purpose as well as the generally acknowledged state of the art on AI and AI-related technologies. Article 8(2) addresses overlap with sectoral Union harmonisation legislation: where a product contains an AI system to which both the requirements of the AI Act and the requirements of the Union harmonisation legislation listed in Section A of Annex I apply, providers shall be responsible for ensuring that their product is fully compliant with all applicable requirements under applicable Union harmonisation legislation. Article 8(2) further permits providers to integrate the testing and reporting processes, information and documentation required by the AI Act into existing documentation and procedures already required under the Union harmonisation legislation listed in Section A of Annex I, in order to ensure consistency, avoid duplication and minimise additional burdens. Article 8 therefore acts as the legal hook that triggers the Article 9-15 compliance suite for high-risk AI systems and simultaneously coordinates the AI Act with pre-existing product-safety regimes (machinery, medical devices, in-vitro diagnostics, toys, lifts, radio equipment, etc.).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "article_8_1_scope_anchor",
        "article_8_2_dual_regime_anchor",
        "annex_i_section_a_anchor",
        "chapter_iii_section_2_triggered_requirements",
        "state_of_the_art_anchor",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-43-conformity-assessment-procedures-notified-bodies",
      "eu-machinery-regulation-2023-1230-safety-requirements",
      "eu-mdr-2017-745"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-80-judicial-remedy-supervisory-authority",
    "title": "EU AI Act Remedies - Article 85 Complaint to Market Surveillance Authority, Article 86 Right to Explanation, and Judicial Review of Authority Decisions",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-07-02",
    "bluf": "The draft EU AI Act provision granting a standalone right to an effective judicial remedy against a supervisory authority, modelled on GDPR Article 78, was not retained in the final Regulation (EU) 2024/1689; in the final Act, Article 80 is instead the procedure for dealing with AI systems classified by the provider as not high-risk in application of Annex III. The remedies actually available under the final Act are: Article 85, which allows any natural or legal person having grounds to consider that there has been an infringement of the Regulation to submit a complaint to the relevant market surveillance authority, handled in line with the procedures established under Regulation (EU) 2019/1020; Article 86, which gives persons affected by a decision taken by a deployer on the basis of output from an Annex III high-risk AI system, with the exception of systems listed under its point 2, the right to obtain clear and meaningful explanations of the role of the AI system in the decision-making procedure where the decision produces legal effects or similarly significantly affects them in a way they consider adverse to their health, safety or fundamental rights; judicial review of market surveillance authority measures under the national law of the Member State concerned, consistent with the Charter of Fundamental Rights Article 47 right to an effective remedy; and review by the Court of Justice of the European Union, which has unlimited jurisdiction under Article 101 to review Commission decisions fixing fines on providers of general-purpose AI models.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-80-judicial-remedy-supervisory-authority.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-63-market-surveillance",
      "eu-ai-act-article-68-national-competent-authorities",
      "eu-ai-act-article-79-right-to-lodge-complaint"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-article-81-judicial-remedy-provider-deployer",
    "title": "EU AI Act - Judicial Redress Against Providers and Deployers: Draft Article 81 Remedy Not Retained in Regulation (EU) 2024/1689",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-07-02",
    "bluf": "The standalone right to an effective judicial remedy against a provider or deployer that appeared in draft versions of the EU AI Act was not retained in the final Regulation (EU) 2024/1689; in the adopted text, Article 81 is the Union safeguard procedure, a Commission-level mechanism for reviewing contested national market surveillance measures, not an individual redress right. The individual-rights regime of the final Act consists of Article 85 (right to lodge a complaint with a market surveillance authority) and Article 86 (right to explanation of individual decision-making, exercisable against the deployer of a high-risk AI system). Private redress against providers and deployers for harm linked to EU AI Act non-compliance runs through national civil liability law, the revised Product Liability Directive (EU) 2024/2853 which expressly covers software including AI systems, and the Representative Actions Directive (EU) 2020/1828, to whose Annex I the EU AI Act is added by Article 110 of the Regulation, enabling consumer collective redress for AI Act infringements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-81-judicial-remedy-provider-deployer.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-16-provider-obligations",
      "eu-ai-act-article-26-deployer-obligations",
      "eu-ai-act-article-86-right-to-explanation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-article-82-representation-affected-persons",
    "title": "EU AI Act Collective Redress for Affected Persons - Representative Actions via Article 110 and Directive (EU) 2020/1828",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-07-02",
    "bluf": "The draft EU AI Act article that would have allowed affected persons to mandate not-for-profit bodies to act on their behalf, modelled on GDPR Article 80, was not retained in the final Regulation (EU) 2024/1689; in the final Act, Article 82 instead concerns compliant AI systems which present a risk. Collective redress for AI Act infringements runs through Directive (EU) 2020/1828 on representative actions for the protection of the collective interests of consumers: Article 110 of the AI Act adds Regulation (EU) 2024/1689 as point (68) of Annex I to that Directive, so qualified entities designated by Member States can bring representative actions seeking injunctive measures, redress measures, or both where AI Act infringements harm the collective interests of consumers. Individuals also hold the Article 85 right to lodge a complaint with a market surveillance authority and the Article 86 right to explanation of individual decision-making.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-82-representation-affected-persons.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-79-right-to-lodge-complaint",
      "eu-ai-act-article-80-judicial-remedy-supervisory-authority",
      "eu-ai-act-article-81-judicial-remedy-provider-deployer"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-83-defense-exclusion",
    "title": "EU AI Act Article 2(3) - AI Systems for Defense, National Security, and Military Purposes",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation (EU) 2024/1689 Article 2(3) excludes AI systems from the scope of the Regulation where and in so far they are placed on the market, put into service, or used with or without modification exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities, whether a Member State authority or a private defence contractor; AI systems with dual-use characteristics that are used for both excluded military purposes and covered commercial or public authority purposes are subject to the EU AI Act for their covered uses while retaining the exclusion for their military, defence and national security uses; and Member States retain full national sovereignty over national security under Article 4(2) TEU, the basis for the exclusion confirmed in recital 24 of the Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-83-defense-exclusion.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-5-prohibited-practices"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-84-exercise-of-delegation",
    "title": "EU AI Act Article 97 - Exercise of the Delegation for Delegated Acts",
    "domain": "AI Governance & Law",
    "version": "1.0.2",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 97 grants the Commission the power to adopt delegated acts and sets out the procedural framework governing that power: the delegation runs for five years from 1 August 2024 and is automatically renewed for identical periods unless the European Parliament or Council objects; either institution may revoke the delegation at any time; delegated acts enter into force only if neither the European Parliament nor the Council objects within a two-month period that may be extended by two months at the request of either institution; the Commission must notify delegated acts simultaneously to the European Parliament and the Council.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-84-exercise-of-delegation.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-7-high-risk-classification-updates",
      "eu-ai-act-article-85-committee-procedure",
      "eu-ai-act-article-6-classification-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-85-committee-procedure",
    "title": "EU AI Act Article 98 - Committee Procedure for Implementing Acts",
    "domain": "AI Governance & Law",
    "version": "1.0.2",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 98 establishes the committee procedure under which the Commission adopts implementing acts for the EU AI Act, providing that the Commission is assisted by a committee composed of representatives of Member States, that the committee follows the examination procedure under Article 5 of Regulation (EU) No 182/2011, and that the committee procedure applies to the adoption of implementing acts including common specifications under Article 41, standardised templates for EU declarations of conformity, and procedural rules for market surveillance coordination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-85-committee-procedure.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-41-common-specifications",
      "eu-ai-act-article-58-ai-board",
      "eu-ai-act-article-68-national-competent-authorities"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-86-right-to-explanation",
    "title": "EU AI Act Article 86 - Right to Explanation of Individual Decisions",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "EU AI Act Regulation 2024/1689 Article 86 grants natural persons who are subject to a decision taken by a deployer on the basis of output from a high-risk AI system listed under Annex III the right to request an explanation of the role of the AI system in the decision-making procedure and the principal reasons for the decision, that deployers must implement procedures to provide meaningful explanations to affected persons upon request, and that this right applies only to decisions producing significant effects on persons and does not override Member State law or overriding public interest exceptions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-86-right-to-explanation.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-26-deployer-obligations",
      "eu-ai-act-article-13-transparency-high-risk",
      "eu-ai-act-article-6-classification-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-87-confidentiality-of-reporting",
    "title": "REGULATION (EU) 2024/1689 (Artificial Intelligence Act) - Article 78: Confidentiality",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "Organizations must ensure that information submitted to competent authorities and conformity assessment bodies is properly managed for confidentiality, while understanding that certain information for high-risk AI systems will be made public.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training",
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-88-cooperation-national-authorities-operators",
    "title": "REGULATION (EU) 2024/1689 (Artificial Intelligence Act) Article 21: Obligation of cooperation",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "Operators of high-risk AI systems must cooperate with national competent authorities upon receiving a reasoned request regarding actions taken under this Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-89-evaluation-review",
    "title": "EU AI Act Article 112 - Evaluation and Review by the Commission",
    "domain": "AI Governance & Law",
    "version": "1.0.2",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Regulation 2024/1689 Article 112 requires the Commission to evaluate and review the application of the Regulation and submit reports to the European Parliament and the Council, including an evaluation of the impact on the market for AI systems and on the protection of fundamental rights - covering the effectiveness of penalties and enforcement approaches, the need to extend or modify the list of prohibited practices and high-risk use cases in the annexes, the adequacy of the provisions on GPAI models, and whether any additional measures are required to address emerging AI risks not covered by the Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-89-evaluation-review.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-56-ai-office"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-89-monitoring-actions-gpai",
    "title": "Regulation (EU) 2024/1689 (EU AI Act) Article 89 - Monitoring actions by the AI Office and downstream provider complaints concerning general-purpose AI models",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-06-13",
    "bluf": "Article 89 of Regulation (EU) 2024/1689 sits in Chapter IX Section 5 (Supervision, investigation, enforcement and monitoring in respect of providers of general-purpose AI models). Article 89(1) empowers the AI Office to take the necessary actions to monitor the effective implementation and compliance with the Regulation by providers of general-purpose AI models, including their adherence to approved codes of practice under Article 56. Article 89(2) creates a structured complaint channel: downstream providers (the operators that integrate a GPAI model into their AI systems) have the right to lodge a reasoned complaint with the AI Office alleging an infringement of the Regulation by the upstream GPAI provider. The complaint must indicate (a) the point of contact of the GPAI provider concerned; (b) a description of the relevant facts, the provisions of the Regulation concerned, and the reason why the downstream provider considers that the GPAI provider has infringed the Regulation; and (c) any other information the downstream provider considers relevant including information gathered on its own initiative. Article 89 is the operational gateway by which the AI Office discharges its supervisory mandate over GPAI providers (Articles 53 to 55), feeds into the AI Office investigation and enforcement powers (Articles 88, 91, 92, 93), and complements the Article 85 general right of complaint available to any natural or legal person.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "article_89_1_monitoring_mandate_anchor",
        "article_89_2_downstream_complaint_anchor",
        "gpai_provider_obligations_triggered_anchor",
        "ai_office_supervision_chain_anchor",
        "complementarity_with_article_85_general_complaint_anchor",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-53-gpai-codes-of-practice",
      "eu-ai-act-article-55-systemic-risk-gpai"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-9-risk-management-automated-systems",
    "title": "EU AI Act (EU) 2024/1689 Article 9 - Risk Management System for High-Risk AI Systems Used in Automated Compliance and Decision Workflows",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Providers of high-risk AI systems must establish, implement, document, and maintain a risk management system as a continuous iterative process throughout the entire lifecycle of the system. The system must identify and analyse all known and reasonably foreseeable risks to health, safety, and fundamental rights; adopt risk management measures to address identified risks; and conduct systematic testing to verify effectiveness. Risk measures must be technically feasible, ensure residual risks communicated to deployers, and for Annex I sector-specific systems must integrate sector regulatory requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-govern-function",
      "eu-nis2-directive-2022-2555",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-9-risk-management-system",
    "title": "Regulation (EU) 2024/1689 (EU AI Act) Article 9 - Risk Management System",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Article 9 of the EU AI Act, providers of high-risk AI systems must establish, implement, document, and maintain a continuous, iterative risk management system throughout the AI system's entire lifecycle. This system must identify, estimate, evaluate, and adopt suitable measures for known and reasonably foreseeable risks to health, safety, and fundamental rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-high-risk",
      "iso-23894-ai-risk-management",
      "nist-ai-rmf-1-0",
      "eu-ai-act-fundamental-rights-impact-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-article-9-risk-management-system-high-risk-ai",
    "title": "EU AI Act Article 9 - Risk Management System for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "EU AI Act Article 9 requires providers of high-risk AI systems to establish, implement, document, and maintain a risk management system throughout the AI system lifecycle. The risk management system must identify and analyse known and reasonably foreseeable risks, estimate and evaluate risks through testing under real-world conditions, and adopt risk mitigation measures giving due consideration to technical and operational safeguards. Article 9 applies to all AI systems classified as high-risk under Article 6 and Annex III of the EU AI Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-6-classification-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-90-administrative-fines-prohibited-practices",
    "title": "Regulation (EU) 2024/1689 (Artificial Intelligence Act) - Article 99: Administrative Fines",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "Organizations face administrative fines up to EUR 35,000,000 or 7% of total worldwide annual turnover for non-compliance with the prohibitions of AI practices laid down in this Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-91-administrative-fines-providers-deployers",
    "title": "REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 99 Administrative fines",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "This article establishes the framework for administrative fines for non-compliance with the AI Act, setting maximum penalties based on the type of infringement and the offender's annual turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-92-administrative-fines-third-party-conformity",
    "title": "Regulation (EU) 2024/1689 (Artificial Intelligence Act) - Article 101: Administrative fines on providers of GPAI models for infringements of this Regulation",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "This article empowers the AI Office to impose significant administrative fines on providers of general-purpose AI models for specific infringements, with amounts based on a percentage of worldwide annual turnover or a fixed sum, whichever is higher.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-93-administrative-fines-incorrect-information",
    "title": "REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 99: Administrative Fines for Incorrect, Incomplete or Misleading Information",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "Organizations must provide correct, complete, and non-misleading information to notified bodies and national competent authorities upon request, facing significant administrative fines for non-compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-94-penalties-member-states",
    "title": "REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 99: Penalties",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "This article requires Member States to establish rules on effective, proportionate, and dissuasive penalties, including specific tiers of administrative fines for infringements of the AI Act by operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-95-codes-of-conduct",
    "title": "EU AI Act Article 95 - Voluntary Codes of Conduct for Non-High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "EU AI Act Regulation 2024/1689 Article 95 encourages the development of voluntary codes of conduct for AI systems that are not classified as high-risk, allowing providers of non-high-risk AI systems to voluntarily apply some or all of the requirements applicable to high-risk AI systems including risk management, data governance, transparency, human oversight, and accuracy requirements, with the Commission facilitating and promoting the development of these codes across industry sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-article-95-codes-of-conduct.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-96-commission-guidance-implementation",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 96 Guidelines from the Commission",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations must monitor for, review, and incorporate guidelines issued by the European Commission on the practical implementation of the AI Act, particularly concerning high-risk AI requirements, prohibited practices, substantial modifications, and transparency obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-act-article-97-commission-evaluation-report",
    "title": "REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 112",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "This article establishes a recurring evaluation and review cycle for the AI Act, mandating the Commission to submit periodic reports to the European Parliament and the Council on the regulation's implementation, impact, and potential need for amendments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-article-98-review-and-amendment",
    "title": "REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - Article 112",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-02",
    "bluf": "This article mandates the European Commission to periodically evaluate and review the AI Act's application, report findings to the Parliament and Council, and propose amendments as necessary, with specific focus areas and timelines for review.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-article-99-entry-into-force-and-application",
    "title": "REGULATION (EU) 2024/1689 (Artificial Intelligence Act) - Article 113: Entry into force and application",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-07-02",
    "bluf": "This article establishes the timeline for the EU AI Act's entry into force and specifies the staggered application dates for its various titles, chapters, and specific obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-articles-57-63-regulatory-sandboxes",
    "title": "EU AI Act Articles 57-63 - AI Regulatory Sandboxes: Eligibility, Conditions, Supervision and Liability Treatment for Participants",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-06-13",
    "bluf": "The EU AI Act establishes AI regulatory sandboxes to provide a controlled environment for providers, particularly SMEs and start-ups, to develop, train, validate, and test innovative AI systems under the direct supervision of competent authorities. Participants must submit a detailed plan for approval, ensure safeguards against risks to fundamental rights and safety, and adhere to specific liability provisions as outlined in Articles 57 through 63.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-high-risk",
      "eu-ai-act-fundamental-rights-impact-assessment",
      "eu-ai-act-regulatory-sandboxes-article-57",
      "eu-ai-liability-directive-2024"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-articles-74-79-market-surveillance",
    "title": "EU AI Act Articles 74-79 - Market Surveillance and Enforcement: National Authority Powers, Penalties and Cross-Border Cooperation",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes the market surveillance framework for AI systems in the EU, granting national authorities extensive powers under Article 74 to investigate non-compliance, demand access to data and source code, and impose corrective measures. It outlines procedures for handling AI systems presenting a risk (Article 75) and sets the rules for penalties (Article 99) and cross-border cooperation (Article 78) to ensure consistent enforcement across the Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-high-risk",
      "eu-ai-act-incident-reporting-article-73"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-authorised-representative-importer",
    "title": "EU AI Act - Authorised Representatives and Importers of High-Risk AI Systems (Articles 22-25)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Articles 22-25 establish obligations for authorised representatives and importers who play a role in the supply chain for high-risk AI systems placed on the EU market by providers established outside the Union; Article 22(1) - before making a high-risk AI system available on the Union market, providers established outside the Union shall, by written mandate, appoint an authorised representative established in the Union; Article 22(2) - the authorised representative shall perform the tasks specified in the mandate received from the provider, and shall make the mandate available to national competent authorities upon request; Article 22(3) - the authorised representative shall be considered the provider's representative for the purposes of this Regulation and shall be liable for the provider's non-compliance under conditions established by Member State law; Article 23 - providers established outside the Union who appoint an authorised representative must ensure that the authorised representative has the necessary documentation; Article 24 - importers of high-risk AI systems shall verify before placing the system on the Union market that: (a) the provider has drawn up the EU declaration of conformity; (b) the provider has drawn up the technical documentation; (c) the high-risk AI system bears the CE marking and is accompanied by the instructions for use and the EU declaration of conformity; Article 25 - distributors of high-risk AI systems shall verify before making the system available that it bears the CE marking and is accompanied by the required documentation; providers established outside the Union who place high-risk AI systems on the EU market without appointing an EU-established authorised representative are in violation of Article 22 regardless of where the AI system is made available to end users.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-authorised-representative-importer.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-provider-obligations-high-risk",
      "eu-ai-act-conformity-assessment-procedure",
      "eu-ai-act-technical-documentation-requirements"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-automated-decision-workflows",
    "title": "EU AI Act: Automated Decision Workflows, High-Risk System Classification, Human Oversight, and Transparency Obligations",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The EU AI Act mandates stringent controls over automated decision-making workflows classified as high-risk, requiring demonstrable human oversight (human-in-the-loop), robust transparency, and active risk management to prevent fundamental rights violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "gdpr-article-35-dpia",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-bias",
    "title": "EU AI Act: Data Bias Mitigation (Article 10)",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Article 10 of the EU AI Act (2026 fully enforced) mandates strict controls to detect, prevent, and mitigate biases in training, validation, and testing datasets for high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-high-risk",
      "gdpr-health-data",
      "iso-iec-24027-bias-fairness",
      "nist-ai-rmf-1-0",
      "nist-sp-1270-managing-ai-bias",
      "oecd-ai-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-cloud-providers-article-25",
    "title": "EU AI Act: Obligations of Distributors, Importers, and Deployers (Article 25)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Under Article 25 of the EU AI Act, distributors, importers, and deployers of high-risk AI systems must verify the system's compliance, including the presence of CE marking and required documentation, before making it available or putting it into service. They are also responsible for ensuring that storage and transport conditions do not compromise the system's conformity and must cooperate with competent authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-high-risk",
      "eu-ai-act-market-surveillance-chapter-viii",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-commission-guidelines-article-6-2025",
    "title": "EU AI Act - Commission Guidelines on High-Risk AI Classification Under Article 6 (Article 96 Guidelines)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "Regulation (EU) 2024/1689 (EU AI Act) Article 96 mandates the European Commission to publish guidelines on the practical implementation of Article 6 - the high-risk AI system classification rules - to assist providers in determining whether their AI system constitutes a high-risk AI system subject to Chapter III obligations; Article 6 establishes two classification pathways: Article 6(1) - AI systems that are safety components of products covered by Union harmonisation legislation listed in Annex II (e.g., Machinery Regulation, Medical Devices Regulation, Aviation Regulation) and must undergo third-party conformity assessment under that legislation; Article 6(2) - AI systems falling within any of the eight Annex III use case categories (biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration/border, administration of justice); Article 6(3) provides the exception: an Annex III AI system is NOT high-risk if it does not pose significant risks to health, safety, or fundamental rights including by not significantly influencing the outcome of decision-making; Article 96 guidelines clarify: (a) the meaning of 'not significantly influencing the outcome of decision-making' in Article 6(3); (b) the scope and boundaries of each of the eight Annex III categories; (c) the interaction between Article 6(1) and Article 6(2) pathways; (d) how providers should document their classification reasoning; the Commission published guidelines pursuant to Article 96 within the first half of 2025; compliance with the guidelines creates a presumption that Article 6 classification has been conducted correctly but does not replace the provider's legal obligation to make their own classification determination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-commission-guidelines-article-6-2025.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-annex-iii-high-risk-ai-list",
      "eu-ai-act-annex-ii-union-harmonisation-legislation",
      "eu-ai-act-article-3-definitions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-conformity-assessment-chapter-5",
    "title": "Regulation (EU) 2024/1689 (EU AI Act) Chapter 5 - Conformity Assessment of High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This chapter mandates that providers of high-risk AI systems must conduct a conformity assessment to demonstrate compliance with the Act's requirements before placing the system on the market. Article 43 specifies two main procedures: an internal control assessment (Annex VI) or a third-party assessment by a notified body involving the quality management system and technical documentation (Annex VII).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-high-risk",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-conformity-assessment-procedure",
    "title": "EU AI Act - Conformity Assessment Procedures for High-Risk AI Systems (Articles 43-49)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Articles 43-49 establish the conformity assessment framework that high-risk AI system providers must complete before placing their systems on the EU market; two conformity assessment tracks apply: (1) Article 43(1) mandatory third-party notified body assessment - applies to high-risk AI systems listed in Annex III Point 1 (biometric identification and categorisation systems) and to high-risk AI systems governed by Union harmonisation legislation in Annex I (medical devices, machinery, civil aviation, vehicles, personal protective equipment, in vitro diagnostic devices, rail interoperability, maritime equipment, lifts) where the relevant sectoral legislation already requires third-party assessment; notified bodies are independent conformity assessment bodies accredited by national accreditation bodies and notified to the European Commission; (2) Article 43(2) internal control self-assessment - applies to all other Annex III high-risk AI systems not covered by Article 43(1); under internal control, the provider verifies the AI system's compliance with Articles 8-15 requirements and draws up the technical documentation without third-party review; Article 47 provides for the EU declaration of conformity - providers must draw up a signed written declaration stating the high-risk AI system complies with the EU AI Act requirements; Article 48 establishes CE marking obligations - CE marking must be affixed to high-risk AI systems (or their accompanying documentation) before market placement, visibly, legibly, and indelibly; Article 49 requires registration of high-risk AI systems in the EU database for high-risk AI systems before placing on the market; conformity assessment must be completed before first market placement; providers must initiate a new or updated conformity assessment where the AI system undergoes substantial modification after market placement; the conformity assessment framework applies to providers established outside the EU who place high-risk AI on the EU market, who must appoint an authorised representative under Article 22.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-conformity-assessment-procedure.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-provider-obligations-high-risk",
      "eu-ai-act-technical-documentation-requirements",
      "eu-ai-act-high-risk-biometric-systems",
      "eu-ai-act-sme-startup-provisions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-customer-facing-high-risk-annex-3",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes binding requirements for high-risk AI systems used in customer-facing contexts such as creditworthiness assessment, insurance risk scoring, and emotion recognition, mandating transparency, human oversight, and compliance with fundamental rights under Articles 5, 10, 14, and Annex III of Regulation (EU) 2024/1689.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "eu-geo-blocking-regulation-2018",
      "eu-omnibus-directive-2019-2161",
      "iso-10002-2018-customer-satisfaction-complaints",
      "bpmn-2-0-omg-specification-workflow-notation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-cyber-resilience-act-intersection",
    "title": "EU AI Act and Cyber Resilience Act - Dual Compliance for Connected AI Products",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "Providers of AI systems embedded in connected products face dual compliance obligations under Regulation (EU) 2024/1689 (EU AI Act) and Regulation (EU) 2024/2847 (EU Cyber Resilience Act, CRA); the CRA applies to products with digital elements (PDEs) that are directly or indirectly connected to a network - including IoT devices, industrial control systems, smart home products, medical devices (software as a medical device), and connected vehicles; where a connected product contains an AI system that is: (a) a safety component of a product covered by EU AI Act Annex II (e.g., Machinery Regulation, Medical Devices Regulation) - the AI system is automatically high-risk under EU AI Act Article 6(1); (b) within a CRA-covered product - the product must also comply with CRA essential cybersecurity requirements; the key dual compliance obligations are: (1) conformity assessment - both the EU AI Act conformity assessment (for high-risk AI systems) and the CRA conformity assessment (for products with digital elements) must be completed before CE marking; for some products, a single integrated conformity assessment covers both instruments; (2) vulnerability management - CRA Article 13 requires providers to address known vulnerabilities throughout the product lifecycle; EU AI Act Article 15 requires robustness against adversarial inputs and cybersecurity for high-risk AI systems; (3) incident reporting - CRA Article 14 requires notification of actively exploited vulnerabilities and security incidents to ENISA; EU AI Act Article 73 requires notification of serious incidents affecting high-risk AI systems to market surveillance authorities; (4) documentation - CRA requires technical documentation under CRA Annex V; EU AI Act Article 11 requires separate technical documentation - both must be maintained; the CRA applies from December 11, 2027 (with an 18-month transition for essential requirements); the EU AI Act high-risk provisions apply from August 2, 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-cyber-resilience-act-intersection.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-cyber-resilience-act-2024-connected-products",
      "eu-ai-act-accuracy-robustness-cybersecurity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-data-governance-high-risk",
    "title": "EU AI Act - Data Governance Requirements for High-Risk AI Training Data (Article 10)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 10 establishes mandatory data governance requirements for training, validation, and testing datasets used in high-risk AI systems; Article 10(1) - providers must implement data governance and management practices covering: the design choices regarding training, validation, and testing data including data collection processes, the labelling procedures, and the data preparation operations; Article 10(2) - training, validation, and testing datasets shall be subject to data governance and management practices covering: (a) the relevant design choices; (b) data collection processes and the origin of data, and in the case of personal data the original purpose of the data collection; (c) relevant data preparation operations such as annotation, labelling, cleaning, enrichment and aggregation; (d) the formulation of relevant assumptions, notably with respect to the information that the data is meant to measure and represent; (e) an assessment of the availability, quantity, and suitability of the datasets needed; (f) examination for possible biases that could affect health and safety or lead to discrimination prohibited under Union law; (g) identification of any possible data gaps or shortcomings and how those gaps and shortcomings are to be addressed; Article 10(3) - training, validation, and testing datasets must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete in view of the intended purpose; Article 10(4) - training, validation, and testing datasets must take into account, to the extent required by the intended purpose, the characteristics or elements particular to the specific geographical, contextual, behavioural, or functional setting within which the high-risk AI system is intended to be used; Article 10(5) - to the extent strictly necessary for the purposes of detecting and correcting biases in high-risk AI systems, providers may process special categories of personal data referred to in GDPR Article 9(1) and Article 10 of Directive 2016/680 subject to appropriate safeguards for the fundamental rights and freedoms of natural persons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-data-governance-high-risk.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-provider-obligations-high-risk",
      "eu-ai-act-technical-documentation-requirements",
      "eu-ai-act-risk-management-system",
      "eu-ai-act-conformity-assessment-procedure"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-deployer-obligations-high-risk",
    "title": "EU AI Act - Obligations of Deployers of High-Risk AI Systems (Article 26)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 26 establishes the obligations of deployers - the natural or legal persons who use a high-risk AI system under their authority - for high-risk AI systems listed in Annex III; Article 26 obligations are distinct from and complementary to provider obligations under Articles 16-27; key deployer obligations under Article 26 include: (1) Article 26(1) - assign human oversight to natural persons with the necessary competence, training, and authority; (2) Article 26(2) - ensure input data is relevant in view of the intended purpose of the high-risk AI system; (3) Article 26(3) - monitor the operation of the high-risk AI system and log relevant data to the extent under the deployer's control; (4) Article 26(4) - inform and obtain consent from individuals subject to real-time remote biometric identification systems where required; (5) Article 26(5) - notify the provider when the deployer detects risks or incidents involving the high-risk AI system; Article 27 - deployers who are public bodies or who use high-risk AI systems in the context of employment and workers management, access to essential services, or education must conduct a Fundamental Rights Impact Assessment (FRIA) before deploying high-risk AI systems; FRIA must include: a description of the processes where the high-risk AI will be used; the period of use; categories of natural persons and number of individuals affected; specific risks to fundamental rights identified; the measures taken to address those risks; the deployer must register the FRIA in the EU database under Article 49; the distinction between provider and deployer is critical - deployers are not providers unless they substantially modify the AI system or place it on the market under their own name, triggering the deployer-becomes-provider conditions in Article 25(4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-deployer-obligations-high-risk.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-high-risk-employment-recruitment",
      "eu-ai-act-high-risk-biometric-systems",
      "eu-ai-act-post-market-surveillance-monitoring",
      "eu-ai-act-sme-startup-provisions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-education-high-risk-systems-annex-3",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 March 2024 on Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act) - Annex III: AI Systems Intended to Be Used as Safety Components in Educational Institutions or for Educational Evaluation and Admission",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The EU AI Act designates certain AI systems used in education - including those for student admission, performance assessment, monitoring, and learning progress prediction - as high-risk under Annex III. These systems must undergo conformity assessment, ensure transparency, enable human oversight, and be registered in the EU database per Article 6 and Annex III.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-education-action-plan-2021-2027",
      "oecd-pisa-education-assessment-framework-2022",
      "iso-21001-2018-educational-organizations-management",
      "eu-digcomp-digital-competence-framework-2022",
      "oecd-principles-ai-in-education-recommendation-2023"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-ai-act-european-ai-board",
    "title": "EU AI Act - European Artificial Intelligence Board (Articles 65-68)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Articles 65-68 establish the European Artificial Intelligence Board (AI Board) as the coordination body for consistent application of the EU AI Act across Member States; Article 65(1) - a European Artificial Intelligence Board is established; Article 65(2) - the AI Board shall be composed of one representative from each Member State plus the European Data Protection Supervisor as a non-voting member; the Commission shall participate in the meetings of the AI Board and appoint a representative; the Chair of the AI Board shall be elected from among its members for a two-year renewable term; Article 65(3) - the AI Board shall have the following tasks: advising and assisting the Commission and Member States to ensure consistent and effective application of the EU AI Act; coordinating and contributing to guidance and analysis by the Commission and national competent authorities; contributing to harmonised administrative practices in Member States; issuing opinions, recommendations, or written contributions on matters related to the implementation of the EU AI Act; Article 66 - advisory bodies and committees advise the AI Board; Article 67 - the AI Board may establish subgroups including a scientific panel of independent experts; Article 68 - a secretariat shall be provided for the AI Board by the Commission; the AI Board coordinates national competent authorities and the European AI Office but does not itself conduct investigations or impose penalties; enforcement remains with national competent authorities and, for GPAI models, the European AI Office.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-european-ai-board.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-market-surveillance-framework",
      "eu-ai-act-gpai-systemic-risk-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-fundamental-rights-impact-assessment",
    "title": "EU AI Act: Fundamental Rights Impact Assessment for High-Risk AI Systems (Article 27)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Under Article 27 of the EU AI Act, deployers that are public bodies or private operators providing public services must conduct and document a Fundamental Rights Impact Assessment (FRIA) before putting a high-risk AI system into use to evaluate its impact on fundamental rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-high-risk",
      "iso-42001-risk-assess",
      "un-guiding-principles-business-hr",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-gpai-code-of-practice",
    "title": "EU AI Act - GPAI Model Code of Practice under Article 54",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 54 establishes the GPAI model code of practice as a voluntary compliance mechanism enabling providers of general-purpose AI models to demonstrate compliance with their Article 53 obligations; Article 54(1) - the AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to contribute to the proper application of this Regulation as regards GPAI models, taking into account international approaches; Article 54(2) - the AI Office and the Board shall aim to ensure that the codes of practice cover at least the obligations of providers pursuant to Article 53 and, for providers of GPAI models with systemic risk, the obligations pursuant to Article 55; codes of practice may also cover the obligations pursuant to Article 53(1)(b) regarding additional information for downstream providers; Article 54(3) - the AI Office shall invite all providers of general-purpose AI models to participate in the drawing up of codes of practice; Article 54(4) - the AI Office and the Board shall assess whether the codes of practice adequately cover the obligations referred to and shall monitor and assess compliance by providers with them; Article 54(5) - providers that comply with an approved code of practice shall be presumed to be in compliance with the obligations set out in this Regulation covered by the code of practice; the EU AI Office published a first draft of the GPAI Code of Practice in November 2024 through a multi-stakeholder process involving AI providers, civil society, and technical experts; the Code addresses: technical documentation requirements for GPAI models; copyright transparency and training data summaries; systemic risk thresholds and evaluation methodologies for models approaching the 10^25 FLOPs threshold; adversarial testing (red-teaming) methodologies for systemic risk models; incident reporting procedures; compliance with the Code creates a presumption of conformity with Article 53 and Article 55 obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-gpai-code-of-practice.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-gpai-model-obligations",
      "eu-ai-act-gpai-systemic-risk-obligations",
      "eu-ai-act-market-surveillance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-gpai-copyright-training-data",
    "title": "EU AI Act - GPAI Model Copyright Compliance and Training Data Summary Obligations (Article 53(1)(c)-(d))",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 53(1)(c)-(d) imposes two specific obligations on providers of general-purpose AI (GPAI) models relating to copyright and training data: Article 53(1)(c) - copyright compliance obligation: GPAI providers must put in place a policy to comply with Union law on copyright and related rights, in particular to identify and comply with opt-out reservations of rights expressed pursuant to Article 4(3) of Directive (EU) 2019/790 (Digital Single Market Directive); Article 4 of the DSM Directive permits text and data mining (TDM) of lawfully accessible content, but Article 4(3) allows rightsholders to reserve their rights against TDM for commercial AI training purposes (a machine-readable opt-out); GPAI providers must therefore: (1) identify content with Article 4(3) opt-outs in their training data; (2) exclude such content from training unless licensed; (3) document their copyright policy in a way that can be disclosed to the European AI Office; Article 53(1)(d) - training data summary obligation: GPAI providers must make publicly available a sufficiently detailed summary of the content used for training the GPAI model to enable understanding of training data scope; the open-source exception in Article 53(2) applies to obligations under Article 53(1)(a) and (b) (technical documentation and downstream information) but does NOT apply to obligations under Article 53(1)(c) and (d) - meaning open-source GPAI model providers still must comply with the copyright policy and training data summary obligations; the GPAI Code of Practice (Article 54) will provide further guidance on the implementation of Article 53(1)(c)-(d) obligations; these obligations apply from 2 August 2025 for GPAI models placed on the market after that date.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-gpai-copyright-training-data.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-gpai-model-obligations",
      "eu-ai-act-gpai-code-of-practice",
      "eu-ai-act-article-113-entry-into-force-application"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-gpai-model-obligations",
    "title": "EU AI Act - General-Purpose AI Model Obligations (Articles 53-54)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Articles 53-54 establish obligations for all providers of general-purpose AI (GPAI) models, regardless of whether the model poses systemic risk; Article 53(1) - providers of general-purpose AI models shall: (a) draw up and keep up-to-date technical documentation including information about the training computation measured in floating point operations (FLOPs), the training data used, the testing and evaluation procedures and their results, and the capabilities and limitations of the model; (b) draw up, keep up-to-date, and make available to providers of AI systems who intend to integrate the general-purpose AI model into their AI systems the information and documentation needed to comply with their obligations; (c) put in place a policy to comply with Union copyright law, including by putting in place a state-of-the-art policy to identify and comply with a rights reservation expressed pursuant to Article 4(3) of Directive 2019/790 (Digital Single Market Directive); (d) publish a sufficiently detailed summary about the content used for training the GPAI model in accordance with a template provided by the AI Office; Article 53(2) - the obligations under Article 53(1)(a) and (b) shall not apply to providers of GPAI models that are released under a free and open-source licence that allows access to, usage, modification, and distribution of the model; however, open-source providers are not exempt from the copyright policy obligation under Article 53(1)(c) or the training data summary under Article 53(1)(d); Article 54 - providers of GPAI models may rely on a code of practice to demonstrate compliance with the obligations in Article 53; the Commission shall facilitate the development of codes of practice by the AI Office; GPAI model obligations under Articles 53-54 are distinct from the systemic risk obligations under Articles 51 and 55 which apply only to GPAI models meeting the 10^25 FLOPs threshold or designated by the Commission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-gpai-model-obligations.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-gpai-systemic-risk-obligations",
      "eu-ai-act-market-surveillance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-gpai-obligations-chapter-v",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (European Union AI Act) - Chapter V: General-Purpose AI Models",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This regulation imposes transparency, documentation, and risk management obligations on all providers of general-purpose AI (GPAI) models placed on the EU market, as detailed in Article 53. It establishes stricter requirements, including model evaluation, systemic risk assessment, and incident tracking, for providers of GPAI models designated as having systemic risk under Article 51.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "eu-ai-act-high-risk",
      "oecd-ai-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-gpai-systemic-risk-obligations",
    "title": "EU AI Act - General-Purpose AI Models with Systemic Risk: Classification and Additional Obligations (Articles 51, 55)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 51 establishes that a general-purpose AI (GPAI) model is classified as posing systemic risk where the cumulative amount of compute used for its training, measured in floating-point operations (FLOPs), exceeds 10^25 - this threshold is the primary classification criterion under Article 51(1)(a); Article 51(2) grants the European Commission power to designate specific GPAI models as posing systemic risk based on qualitative criteria - including potential negative effects on public health, safety, or fundamental rights, significant reach, autonomy, or novelty of risks - even where a model has not reached the 10^25 FLOPs threshold; Article 55 establishes additional mandatory obligations for providers of GPAI models with systemic risk, beyond those applicable to all GPAI model providers under Articles 52-53: (1) adversarial testing (red-teaming) of the model to identify and mitigate systemic risks, conducted in accordance with the state of the art in the field, including through independent expert evaluation; (2) reporting of serious incidents and possible corrective measures to the AI Office without undue delay; (3) implementation of cybersecurity protection commensurate with the systemic risks of the model; (4) reporting to the AI Office of the energy consumption of the GPAI model where this information is known; GPAI model provisions became applicable on 2 August 2025, twelve months after the EU AI Act entered into force on 2 August 2024, per Article 113(3); providers of GPAI models already placed on the market before 2 August 2025 benefit from transitional provisions - Article 113(3) grants those providers until 2 August 2027 to comply with obligations under Article 53(1)(a) on technical documentation; the European AI Office within the European Commission is the primary EU-level supervisory authority for GPAI models including models with systemic risk, with enforcement powers applicable to providers across the single market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-gpai-systemic-risk-obligations.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-open-source-ai-exception",
      "eu-ai-act-post-market-surveillance-monitoring"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-harmonised-standards-article-40",
    "title": "EU AI Act Article 40 - Harmonised Standards and Presumption of Conformity",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "EU AI Act Regulation 2024/1689 Article 40 establishes that high-risk AI systems complying with harmonised standards whose references are published in the Official Journal of the European Union shall be presumed to conform with the corresponding requirements of the EU AI Act, that the Commission issues standardisation requests to European standardisation organisations including CEN and CENELEC to develop these harmonised standards, and that providers relying on harmonised standards must apply them in full to benefit from the presumption of conformity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-harmonised-standards-article-40.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-high-risk",
    "title": "EU AI Act: High-Risk Conformity (Title III)",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Title III of the EU AI Act (2026 fully enforced) mandates rigorous conformity assessments for \"High-Risk AI Systems,\" including mandatory requirements for data governance, technical documentation, and record-keeping.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-bias",
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "nist-ai-rmf-1-0",
      "oecd-ai-principles",
      "unesco-ethics-ai"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-high-risk-administration-justice",
    "title": "EU AI Act - High-Risk AI in Administration of Justice and Democratic Processes (Annex III Point 8)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Annex III Point 8 designates as high-risk AI systems used in the administration of justice and democratic processes, covering two distinct categories: (8a) AI systems intended to assist a judicial authority in researching and interpreting facts and the law, and in applying the law to a concrete set of facts - legal research AI, case outcome prediction AI, and sentencing support AI used by judges, prosecutors, or courts; (8b) AI systems intended to be used for influencing the outcome of an election or referendum, or the voting behaviour of natural persons in the exercise of their vote in elections or referendums, including systems that model individual voting preferences, target political advertising, or predict and influence electoral behaviour; this category addresses two distinct fundamental rights concerns: judicial independence under the rule of law (Article 47 EU Charter - right to a fair trial before an independent tribunal) and democratic participation (Article 39 EU Charter - right to vote); the electoral AI sub-category (8b) has particular significance for sovereign democratic processes and is subject to additional regulation under the Digital Services Act for very large online platforms and the European Media Freedom Act; EU AI Act Article 6(3)(b) explicitly states that AI systems intended to perform a narrow procedural task do not qualify as high-risk, meaning routine legal document formatting AI is excluded but substantive legal analysis AI is included.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-high-risk-administration-justice.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-14-human-oversight",
      "eu-ai-act-article-27-fria-fundamental-rights",
      "eu-ai-act-article-86-right-to-explanation",
      "eu-ai-act-annex-iii-high-risk-ai-systems",
      "eu-digital-services-act-ai-recommender-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-high-risk-biometric-systems",
    "title": "EU AI Act - High-Risk AI in Biometric Identification and Categorisation (Annex III Point 1)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Annex III Point 1 designates as high-risk certain biometric AI systems - specifically (1a) AI systems intended to be used for post-remote biometric identification of natural persons (identification after the event using stored biometric data to identify individuals from recordings or databases) and (1b) AI systems intended to be used for real-time remote biometric identification of natural persons in publicly accessible spaces by law enforcement, which is conditionally permitted subject to Article 5(1)(h) authorisation requirements; critically, real-time remote biometric identification (RTBRI) in publicly accessible spaces is the EU AI Act's most restricted permitted use case - subject to mandatory judicial or independent administrative authorisation for three purposes only: targeted search for specific crime victims, prevention of specific imminent threats to life, and criminal investigation of listed offences; biometric categorisation AI (AI attributing physical or physiological characteristics to individuals) is addressed separately under Article 5(1)(g) as prohibited for law enforcement purposes; the conformity assessment for biometric identification AI under Article 43(1) mandates third-party assessment by a notified body rather than self-certification, making this one of the few Annex III categories requiring mandatory independent conformity assessment; EU AI Act Recital 14 clarifies that biometric verification (confirming a person's claimed identity) is not the same as biometric identification (identifying who a person is) and does not necessarily qualify as high-risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-high-risk-biometric-systems.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-14-human-oversight",
      "eu-ai-act-annex-vii-notified-body-conformity-assessment",
      "eu-ai-act-annex-iii-high-risk-ai-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-high-risk-critical-infrastructure",
    "title": "EU AI Act - High-Risk AI in Critical Infrastructure Safety Components (Annex III Point 2)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Annex III Point 2 designates as high-risk AI systems intended to be used as safety components in the management and operation of critical infrastructure, covering: (2a) AI used as safety components in road traffic management and in the operation of road traffic, including traffic management centres and autonomous and connected vehicle AI systems; (2b) AI used as safety components in the supply of water, gas, heating, or electricity - including AI systems controlling distribution networks, flow management, or grid balancing; the critical infrastructure category is defined by the concept of 'safety component' - a component whose failure would put at risk the health or safety of persons or property; this requirement aligns with the NIS2 Directive (Directive 2022/2555) definition of critical infrastructure operators and creates a direct regulatory interface between EU AI Act Annex III Point 2 and NIS2 essential service obligations; AI systems used in critical infrastructure that are not safety components - for example AI used in administrative functions or non-safety optimisation - do not qualify as high-risk under Annex III Point 2; the high-risk classification triggers full Chapter III compliance including Article 15 robustness and cybersecurity requirements that overlap with NIS2 Article 21 cybersecurity risk management obligations, creating a dual compliance framework for critical infrastructure AI operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-high-risk-critical-infrastructure.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-14-human-oversight",
      "eu-ai-act-article-15-robustness",
      "eu-ai-act-article-26-deployer-obligations",
      "eu-ai-act-annex-iii-high-risk-ai-systems",
      "eu-nis2-essential-important-entities-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-high-risk-education-vocational",
    "title": "EU AI Act - High-Risk AI in Education and Vocational Training (Annex III Point 3)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Annex III Point 3 designates as high-risk all AI systems used in education and vocational training, covering: (3a) AI systems intended to determine access to educational institutions or to assign educational tracks for natural persons - including AI that evaluates applications for admission to higher education, allocates students to academic streams, or determines eligibility for specialised programmes; (3b) AI systems intended to evaluate and assess learning outcomes of persons in educational institutions, including when used to drive the learning process - AI-powered assessment, examination, and proctoring tools that generate scores or pass/fail determinations affecting educational progression; (3c) AI systems intended to assess the appropriate level of education that an individual will receive or will be able to access, in the context of or within educational institutions - AI systems used in special education needs assessment or career guidance; (3d) AI systems intended to monitor and detect and report on student behaviour in a digital learning environment - including AI surveillance tools that track student engagement, attention, or academic honesty during online examinations; education AI is particularly sensitive due to the impact on young people's life opportunities, the GDPR Article 8 parental consent requirements for children under 16, and the EU Charter rights to education (Article 14) and non-discrimination (Article 21) that are directly at stake in educational access and assessment decisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-high-risk-education-vocational.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-13-transparency-high-risk",
      "eu-ai-act-article-14-human-oversight",
      "eu-ai-act-article-27-fria-fundamental-rights",
      "eu-ai-act-article-86-right-to-explanation",
      "eu-ai-act-annex-iii-high-risk-ai-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-high-risk-employment-recruitment",
    "title": "EU AI Act - High-Risk AI in Employment, Workers Management, and Recruitment (Annex III Point 4)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Annex III Point 4 designates as high-risk all AI systems used in employment, workers management, and access to self-employment, covering four categories: (4a) AI for targeted advertising for job vacancies, or recruitment or selection of natural persons - in particular for posting targeted job advertisements, screening or filtering applications, and evaluating candidates during interviews or tests; (4b) AI for making decisions affecting terms of work, working conditions, promotion, or termination - in particular where these decisions affect performance monitoring, performance evaluation, and task allocation with behavioural impact; (4c) AI for monitoring and evaluating employee performance; (4d) AI for worker profiling to determine access to benefits or services; the high-risk designation triggers the full Chapter III compliance regime including Article 9 risk management, Article 10 data governance, Article 11 technical documentation, Article 13 transparency, Article 14 human oversight, Article 17 QMS, Article 27 FRIA for large employers or public bodies; importantly, Article 27(1) requires deployers using high-risk employment AI systems who are public bodies or private organisations employing more than 250 employees to conduct a Fundamental Rights Impact Assessment before putting the system into use.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-high-risk-employment-recruitment.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-13-transparency-high-risk",
      "eu-ai-act-article-14-human-oversight",
      "eu-ai-act-article-17-quality-management-system",
      "eu-ai-act-article-27-fria-fundamental-rights",
      "eu-ai-act-annex-iii-high-risk-ai-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-high-risk-essential-services",
    "title": "EU AI Act - High-Risk AI in Essential Private and Public Services (Annex III Point 5)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Annex III Point 5 designates as high-risk all AI systems used to determine access to or denial of essential private and public services and benefits, covering: (5a) AI systems used by public authorities or on behalf of public authorities to evaluate eligibility for public benefit services and social services, or to grant, reduce, revoke, or recover such benefits; (5b) AI systems used to evaluate the creditworthiness of natural persons or to establish their credit score, with the exception of AI systems put into service by small-scale providers for their own use; (5c) AI systems used for risk assessment and pricing in life and health insurance; (5d) AI systems used to evaluate and classify emergency calls or to dispatch or prioritise the dispatch of emergency services including police, firefighters, and medical assistance; the essential services category is particularly significant because it directly affects citizens' access to social welfare, credit, health insurance, and emergency protection, making it one of the highest-impact categories for consumer rights and fundamental rights; the creditworthiness AI exclusion for small-scale providers self-using the system is the only Article 6(3) exclusion explicitly codified in Annex III itself rather than in Article 6(3)'s general exclusion provision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-high-risk-essential-services.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-13-transparency-high-risk",
      "eu-ai-act-article-14-human-oversight",
      "eu-ai-act-article-26-deployer-obligations",
      "eu-ai-act-article-27-fria-fundamental-rights",
      "eu-ai-act-annex-iii-high-risk-ai-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-high-risk-law-enforcement",
    "title": "EU AI Act - High-Risk AI in Law Enforcement (Annex III Point 6)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Annex III Point 6 designates as high-risk AI systems used in law enforcement purposes by competent authorities, covering: (6a) AI systems intended to be used by competent law enforcement authorities for individual risk assessments to assess the risk of a natural person to offend or reoffend or for the risk of potential victims; (6b) AI for polygraph-like testing or lie detection; (6c) AI to evaluate the reliability of evidence in criminal proceedings; (6d) AI for crime analytics to search or match on biometric data from unstructured datasets (distinct from Article 5 real-time remote biometric ID prohibition); (6e) AI used in prevention, detection, or investigation of criminal offences to predict the occurrence or recurrence of a crime or offence; (6f) AI for profiling of natural persons in criminal investigations; (6g) AI analysis of audio, images, video, and text records to support criminal investigation; this domain is subject to both the EU AI Act's high-risk compliance regime and the Law Enforcement Directive (LED - Directive 2016/680) which applies to personal data processing for law enforcement purposes in place of GDPR; the EU AI Act Article 10(5) creates a specific exemption allowing law enforcement AI training on special category data where strictly necessary for bias detection and correction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-high-risk-law-enforcement.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-14-human-oversight",
      "eu-ai-act-article-27-fria-fundamental-rights",
      "eu-ai-act-annex-iii-high-risk-ai-systems",
      "eu-ai-act-article-83-defense-exclusion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-high-risk-medical-ai-2026",
    "title": "EU AI Act - High-Risk AI Systems in Medical Devices & Healthcare (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Under the EU AI Act, most AI systems used in medical devices, clinical decision support, patient risk assessment, and biometric categorization are classified as high-risk. Providers must comply with strict obligations including risk management, data governance (Article 10), transparency, human oversight, accuracy, robustness, cybersecurity, conformity assessment, CE marking, and post-market monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 3
  },
  {
    "node_id": "eu-ai-act-high-risk-migration-border",
    "title": "EU AI Act - High-Risk AI in Migration, Asylum, and Border Control (Annex III Point 7)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Annex III Point 7 designates as high-risk all AI systems used in migration, asylum, and border control management by competent authorities, covering: (7a) AI for individual risk assessment or lie detection for the purpose of border control or in support of asylum or visa applications; (7b) AI for examination of asylum applications and supporting assessments of the applicant's credibility and risk of irregular migration; (7c) AI for verification of authenticity of travel documents; (7d) AI for monitoring and surveillance of irregular migrants; these systems are among the most sensitive in the EU AI Act's high-risk classification given the direct impact on asylum seekers' fundamental rights, the risk of refoulement (return to persecution) where AI errors affect asylum decisions, and the overlap with EU Charter rights including the right to asylum (Article 18), prohibition of non-refoulement (Article 19), and right to human dignity (Article 1); the Regulation additionally excludes from EU AI Act scope migration AI used exclusively for national security purposes under Article 83, but this exclusion does not cover most border control and asylum assessment AI operated by national border and immigration authorities; EU Agency for Asylum (EUAA) and Frontex AI systems are subject to EU AI Act compliance as Union institutions from February 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-high-risk-migration-border.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-14-human-oversight",
      "eu-ai-act-article-26-deployer-obligations",
      "eu-ai-act-article-27-fria-fundamental-rights",
      "eu-ai-act-article-83-defense-exclusion",
      "eu-ai-act-annex-iii-high-risk-ai-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-high-risk-systems-compliance-2026-23",
    "title": "EU AI Act High-Risk Systems Enterprise Compliance Standard v23",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The EU AI Act establishes a regulatory framework for high-risk AI systems, mandating compliance with stringent requirements to ensure safety, transparency, and accountability. Organizations deploying high-risk AI must conduct risk assessments, maintain detailed documentation, and implement robust data governance practices. They are required to ensure human oversight, mitigate biases, and provide clear information to users about the AI system's capabilities and limitations. Regular audits and compliance checks are essential to demonstrate adherence to the Act. Non-compliance can result in significant penalties, emphasizing the importance of integrating these standards into organizational practices. The Act aims to foster trust in AI technologies while safeguarding fundamental rights and freedoms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-high-risk-systems-compliance-2026-8",
    "title": "EU AI Act High-Risk Systems Enterprise Compliance Standard v8",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-07-03",
    "bluf": "The EU AI Act establishes a regulatory framework for high-risk AI systems, mandating compliance with stringent requirements to ensure safety, transparency, and accountability. Organizations deploying such systems must conduct risk assessments, implement robust data governance, and ensure human oversight. Key obligations include maintaining detailed documentation, ensuring data quality, and conducting regular audits. The Act emphasizes the need for risk mitigation strategies and the establishment of a compliance management system. Non-compliance can lead to significant penalties, including fines and restrictions on market access. The regulation aims to foster trust in AI technologies while safeguarding fundamental rights and public interests.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 14
  },
  {
    "node_id": "eu-ai-act-human-oversight-design",
    "title": "EU AI Act - Human Oversight Requirements for High-Risk AI Systems (Article 14)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 14 requires providers of high-risk AI systems to design and develop systems in such a way that they can be effectively overseen by natural persons during the period in which the AI system is in use; Article 14(1) - high-risk AI systems shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which the high-risk AI system is in use; Article 14(2) - human oversight is aimed at preventing or minimising the risks to health, safety or fundamental rights that may emerge when a high-risk AI system is used in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, in particular when such risks persist despite the application of other requirements of Chapter III Section 2; Article 14(3) - the human oversight measures must enable the person(s) assigned to oversight to: (a) fully understand the capacities and limitations of the high-risk AI system and be able to duly monitor its operation; (b) be aware of the possible tendency of automatically biased reliance on the output produced by a high-risk AI system (automation bias) and of the risks this can entail; (c) correctly interpret the output of the high-risk AI system, taking into account, for example, the interpretation tools and methods available; (d) decide, in any particular situation, not to use the high-risk AI system or to disregard, override or reverse the output of the high-risk AI system; (e) intervene in the operation of the high-risk AI system or interrupt the system through a stop button or a similar procedure; Article 14(4) - for high-risk AI systems referred to in Annex III Points 1 to 6 with natural persons in the scope of their intended purpose, the human oversight measures shall ensure that no action or decision is taken by the deployer on the basis of the outputs of the high-risk AI system without appropriate consideration of the relevant output by natural persons; Article 14(5) - where the measures in Article 14(3) and (4) cannot be fully implemented by the provider because of technical reasons, the provider shall clearly inform the deployer thereof in the instructions for use.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-human-oversight-design.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-provider-obligations-high-risk",
      "eu-ai-act-deployer-obligations-high-risk",
      "eu-ai-act-transparency-instructions-for-use",
      "eu-ai-act-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-incident-reporting-article-73",
    "title": "EU AI Act: Reporting of Serious Incidents (Article 73)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Under Article 73 of the EU AI Act, providers of high-risk AI systems on the Union market must report any serious incidents involving their systems to the market surveillance authorities of the Member States where the incident occurred, without undue delay, and no later than 15 days after becoming aware of the incident.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-high-risk",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-act-market-surveillance-chapter-viii",
    "title": "EU AI Act: Market Surveillance and Enforcement (Chapter VIII)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This chapter establishes the post-market surveillance framework for AI systems within the EU, empowering national market surveillance authorities to investigate, demand corrective actions, and withdraw or recall non-compliant AI systems from the market, as detailed in Articles 80, 81, and 82.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-high-risk",
      "iso-42001-risk-assess",
      "iso-42001-improvement"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-market-surveillance-framework",
    "title": "EU AI Act - Market Surveillance, National Competent Authorities, and EU AI Office (Articles 70-86)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Articles 70-86 establish the market surveillance and enforcement governance structure; Article 70 - each Member State must designate one or more national competent authorities responsible for: market surveillance of AI systems; supervision of providers and deployers; enforcement of the EU AI Act including investigation and penalty imposition; Article 74 - market surveillance authorities have extensive investigation and corrective action powers including: requesting technical documentation; requiring providers and deployers to provide information; conducting on-site inspections; ordering corrective measures including product modification, withdrawal, or recall; imposing temporary restrictions on AI system use; Article 76 - where a national market surveillance authority concludes that an AI system presents an unacceptable risk, it must: notify the provider of the risk assessment; give the provider an opportunity to respond; issue a corrective measure requiring restriction, modification, withdrawal, or recall of the AI system; Article 78 - mutual assistance between Member State national competent authorities enables cross-border enforcement where AI systems are deployed across multiple Member States; the European AI Office - established within the European Commission by Regulation 2024/1689 Chapter VII - has supervisory authority specifically over GPAI model providers; the AI Office can: investigate GPAI model providers; request information and conduct evaluations; issue corrective measures and impose penalties for GPAI model violations; coordinate with national competent authorities on cross-border AI system issues; the European AI Board - Article 65 - provides coordination between national competent authorities across Member States; national competent authority designation must be complete within 12 months of the EU AI Act's entry into force (by 2 August 2025); many Member States designated existing digital regulatory authorities (data protection authorities, telecommunications regulators, digital economy ministries) as national competent authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-market-surveillance-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-gpai-systemic-risk-obligations",
      "eu-ai-act-post-market-surveillance-monitoring",
      "eu-ai-act-penalties-and-enforcement"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-medical-devices-mdr-intersection",
    "title": "EU AI Act and Medical Devices Regulation - Dual Compliance for AI Medical Devices",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "AI systems used as medical devices or embedded in medical devices are subject to dual compliance obligations under Regulation (EU) 2024/1689 (EU AI Act) and Regulation (EU) 2017/745 (Medical Devices Regulation, MDR); the intersection creates one of the most complex EU AI compliance scenarios: (1) EU AI Act Article 6(1) automatic high-risk classification - AI systems that are safety components of products covered by EU MDR (listed in EU AI Act Annex II) are automatically classified as high-risk AI systems subject to EU AI Act Chapter III obligations; (2) EU MDR Annex I safety and performance requirements - AI medical devices must additionally satisfy EU MDR's General Safety and Performance Requirements (GSPR) including clinical evaluation, post-market surveillance, and quality management system requirements; (3) Software as a Medical Device (SaMD) - AI software applications that qualify as medical devices under EU MDR (meeting the intended purpose criterion for diagnosis, prevention, monitoring, treatment, or compensation for disease) are subject to full EU MDR obligations including notified body involvement for Class IIa and above; (4) conformity assessment coordination - the EU AI Act's Article 43 conformity assessment for high-risk AI systems is conducted alongside the EU MDR's conformity assessment; for Class IIa and above medical device AI, the EU MDR notified body assessment is the primary pathway; (5) classification interface - EU MDR device classification (Class I, IIa, IIb, III) determines the conformity assessment pathway for the medical device; EU AI Act high-risk classification (Article 6(1)) applies automatically where the AI is a safety component; (6) the EU AI Act's Chapter III provisions (risk management, data governance, transparency, human oversight, accuracy/robustness, quality management, post-market monitoring) operate in addition to EU MDR obligations - not instead of them; the EU AI Act applies from August 2, 2026 and the EU MDR is already in full force.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-medical-devices-mdr-intersection.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-annex-ii-union-harmonisation-legislation",
      "eu-ai-act-quality-management-system",
      "eu-ai-act-accuracy-robustness-cybersecurity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-open-source-ai-exception",
    "title": "EU AI Act - Open-Source AI Model Exception Under Article 53(2) and Recital 102",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 53(2) creates a partial exception for providers of general-purpose AI (GPAI) models released under free and open-source licences - exempting them from Article 53(1)(a) technical documentation obligations and Article 53(1)(b) GPAI Code of Practice obligations, but NOT from Article 53(1)(c) copyright summary and policy obligations and Article 53(1)(d) obligations to provide downstream deployers with information about the model; critically, the open-source exception does NOT apply to GPAI models with systemic risk - any open-source model that exceeds the 10²⁵ FLOP training compute threshold remains fully subject to Article 55 systemic risk obligations including adversarial testing, capability evaluation, incident reporting, and cybersecurity measures; Recital 102 explains the rationale - open-source models enable wider access to AI and promote competition and innovation, but frontier AI models with systemic risk cannot be exempted because their risk profile does not depend on the licensing model; the open-source exception creates a two-tier obligation structure for GPAI providers: standard open-source models with reduced obligations; and open-source systemic risk models with full Article 55 compliance despite their licence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-open-source-ai-exception.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-52-gpai-provider-obligations",
      "eu-ai-act-article-53-gpai-codes-of-practice",
      "eu-ai-act-article-53-general-purpose-ai-transparency",
      "eu-ai-act-article-55-systemic-risk-gpai",
      "eu-ai-act-article-51-gpai-systemic-risk-classification"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-penalties-and-enforcement",
    "title": "EU AI Act - Penalties, Fines, and Enforcement Framework (Articles 99-101)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Articles 99-101 establish the penalty and enforcement framework for violations; Article 99 establishes the three-tier penalty structure: (1) up to EUR 35,000,000 or 7% of total worldwide annual turnover (whichever is higher) for violations of Article 5 prohibited AI practices; (2) up to EUR 15,000,000 or 3% of total worldwide annual turnover (whichever is higher) for violations of any other provisions of the Regulation, including violations of high-risk AI system requirements in Articles 6-49; (3) up to EUR 7,500,000 or 1.5% of total worldwide annual turnover (whichever is higher) for supply of incorrect, incomplete, or misleading information to national competent authorities or notified bodies; Article 99(6) - for SMEs including startups the relevant penalty cap is the lower amount (EUR 35M or 7% for prohibited practices; EUR 15M or 3% for other violations; EUR 7.5M or 1.5% for misleading information); Article 101 - violations of the provisions applicable to GPAI model providers are subject to fines up to EUR 15,000,000 or 3% of total worldwide annual turnover; the penalty amounts constitute maximum caps - national competent authorities must consider all relevant circumstances including the nature, gravity, and duration of the violation; the degree of responsibility of the responsible person; any action taken by the responsible person to mitigate harm; the degree of cooperation with national competent authorities; penalties apply to both providers and deployers for their respective obligations; penalties for Article 5 prohibited practice violations are the highest in the EU AI Act, reflecting the severity of absolute prohibitions on subliminal manipulation, social scoring, predictive policing based on profiling, facial scraping, emotion recognition, biometric categorisation, and real-time remote biometric identification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-penalties-and-enforcement.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-market-surveillance-framework",
      "eu-ai-act-gpai-systemic-risk-obligations",
      "eu-ai-act-sme-startup-provisions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-post-market-surveillance-monitoring",
    "title": "EU AI Act - Post-Market Surveillance, Monitoring, and Incident Reporting (Articles 61-62)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Articles 61 and 62 establish the post-market surveillance and serious incident reporting framework applicable to high-risk AI system providers - Article 61 requires providers to actively collect and review data on performance of their high-risk AI systems throughout the lifecycle, with a post-market monitoring plan documented in the technical documentation; Article 62 requires providers to report to national market surveillance authorities any serious incident or malfunctioning of a high-risk AI system that constitutes a breach of obligations under applicable EU law or that constitutes a risk to health and safety; the post-market surveillance framework mirrors the post-market surveillance obligations under EU medical device regulation (MDR - Regulation 2017/745) and product safety regulation, reflecting the EU AI Act's roots in the New Legislative Framework; the market surveillance authority receiving an Article 62 incident report must communicate it to other Member State authorities through the RAPEX-equivalent AI incident notification system; GPAI providers with systemic risk must implement additional post-deployment monitoring measures under Article 55(1)(d) covering training compute, testing results, adversarial testing findings, and capability evaluations - creating a more intensive monitoring regime than standard high-risk AI post-market surveillance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-post-market-surveillance-monitoring.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-55-systemic-risk-gpai",
      "eu-ai-act-article-61-post-market-monitoring",
      "eu-ai-act-article-62-reporting-serious-incidents",
      "eu-ai-act-article-63-market-surveillance",
      "eu-ai-act-article-65-market-surveillance-corrective-actions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-prohibited-ai-subliminal-manipulation",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 on harmonised rules on artificial intelligence (Artificial Intelligence Act) - Prohibition of AI Systems Using Subliminal Techniques or Exploiting Vulnerabilities",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The EU AI Act Article 5 prohibits AI systems that deploy subliminal techniques, exploit known vulnerabilities of individuals (based on age, disability, or social situation), or manipulate behavior in a way that causes or is likely to cause physical or psychological harm. This applies to all providers, deployers, and distributors of AI systems operating in the EU market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ama-ethical-marketing",
      "eu-unfair-commercial-practices-2005-29",
      "coppa-marketing-kids",
      "eprivacy-cookie-directive"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-prohibited-biometric-categorisation",
    "title": "EU AI Act - Prohibition on Biometric Categorisation AI Inferring Sensitive Attributes (Article 5(1)(g))",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 5(1)(g) prohibits the placing on the market, putting into service, or use of AI systems that categorise natural persons individually based on their biometric data to deduce or infer their race, ethnic origin, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation; applicable from 2 February 2025 (prohibited practices became enforceable under Article 113); the prohibition targets AI systems that use biometric inputs - facial geometry, gait analysis, voice patterns, physiological signals, iris patterns - as a basis for inferring or predicting the sensitive personal attributes listed in Article 5(1)(g); the Article 5(1)(g) prohibition is distinct from Article 5(1)(h) real-time remote biometric identification - Article 5(1)(g) prohibits the categorisation of individuals into sensitive attribute groups from biometric data, while Article 5(1)(h) restricts real-time identification of specific persons in public spaces; prohibited systems include: AI systems that predict political affiliation or religious belief from facial images; AI that infers sexual orientation from photographs or video; AI that classifies individuals by racial or ethnic group from biometric characteristics; AI that predicts trade union membership from voice patterns or facial expressions; a narrow exception exists in Article 5(1)(g) for AI systems used for law enforcement purposes to categorise biometric data that has been lawfully obtained - specifically, biometric data lawfully obtained directly from a natural person or from the open internet or from other sources - but this exception is narrowly construed and subject to the applicable law enforcement data protection frameworks under Directive 2016/680 (Law Enforcement Directive); the prohibition applies to all providers placing such AI on the EU market and all deployers using such AI in the EU regardless of where the AI system itself is located.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-prohibited-biometric-categorisation.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-high-risk-biometric-systems",
      "eu-ai-act-prohibited-emotion-recognition"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-prohibited-emotion-recognition",
    "title": "EU AI Act - Prohibition on Emotion Recognition AI in Workplaces and Educational Institutions (Article 5(1)(f))",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 5(1)(f) prohibits the placing on the market, putting into service, or use of AI systems intended to infer emotions of natural persons in the context of the workplace and educational institutions - applicable from 2 February 2025 (the date prohibited practices became enforceable under Article 113); 'emotion recognition system' is defined in Article 3(34) as an AI system intended to identify or infer emotions or intentions of natural persons on the basis of their biometric data; the prohibition covers AI systems that infer feelings, emotional states, or affective responses including happiness, distress, boredom, focus, arousal, or deceptiveness from facial expressions, voice patterns, body language, or physiological signals; two exceptions to the prohibition apply: (1) AI placed on the market or put into service for medical reasons - e.g., pain assessment tools for non-verbal patients, post-stroke facial muscle analysis; (2) AI placed on the market or put into service for safety reasons - e.g., drowsiness detection systems for vehicle operators or machine operators; the prohibition applies to providers placing emotion recognition AI on the EU market AND to deployers using such AI in workplace or educational contexts, making this one of the EU AI Act prohibitions with the most immediate direct applicability to HR technology, employee monitoring, and EdTech sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-prohibited-emotion-recognition.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-high-risk-employment-recruitment",
      "eu-ai-act-high-risk-education-vocational",
      "eu-ai-act-article-113-entry-into-force-application"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-prohibited-facial-scraping",
    "title": "EU AI Act - Prohibition on Untargeted Scraping of Facial Images to Create Facial Recognition Databases (Article 5(1)(e))",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 5(1)(e) prohibits AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage; applicable from 2 February 2025 per Article 113; the prohibition targets the data collection and database building practice rather than the use of existing lawfully assembled facial recognition databases - it specifically prohibits the creation or expansion of such databases through mass untargeted harvesting of facial images from publicly accessible online sources or physical surveillance infrastructure; 'untargeted scraping' means the mass collection of facial images without a specific individual identification target - collecting billions of facial images from social media, news archives, public websites, or CCTV footage to build a general-purpose facial recognition training dataset or reference database; the prohibition applies to: commercial facial recognition providers (such as Clearview AI and comparable services) that have built databases by scraping billions of faces from the internet without individual consent; law enforcement agencies building post-hoc facial identification databases by scraping social media at mass scale; government agencies building population-level facial recognition datasets from CCTV networks without specific investigation targets; private security companies building facial recognition reference datasets from online sources; the prohibition does not prohibit targeted collection of specific individual facial images for specific identified investigative purposes - it prohibits mass untargeted collection as a general database-building practice; the Article 5(1)(e) prohibition operates alongside existing GDPR restrictions on biometric data processing without consent and Directive 2016/680 law enforcement biometric data restrictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-prohibited-facial-scraping.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-high-risk-biometric-systems",
      "eu-ai-act-prohibited-biometric-categorisation",
      "eu-ai-act-prohibited-realtime-biometric-id"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-prohibited-practices-article-5",
    "title": "Prohibited Artificial Intelligence Practices (Article 5, Regulation (EU) 2024/1689)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Under Article 5 of the EU AI Act, it is strictly forbidden to place on the market, put into service, or use AI systems that deploy subliminal techniques, exploit vulnerabilities of specific groups, conduct social scoring by public authorities, or use real-time remote biometric identification in public spaces for law enforcement, subject to narrow exceptions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "oecd-ai-principles",
      "unesco-ethics-ai"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-prohibited-predictive-policing",
    "title": "EU AI Act - Prohibition on AI Individual Criminal Risk Assessment Based Solely on Profiling (Article 5(1)(d))",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 5(1)(d) prohibits AI systems used by or on behalf of competent authorities, or by Union institutions, bodies, offices or agencies, to make or assist in making individual risk assessments of natural persons in order to assess or predict the risk of a natural person committing a criminal offence - where the assessment is based solely on the profiling of a natural person or on assessing their personality traits and characteristics; applicable from 2 February 2025 per Article 113; the prohibition targets a specific category of predictive policing AI that generates individual criminal risk scores or classifications using only: (i) statistical profiling based on demographic, behavioural, or social characteristics without specific evidence of individual criminal intent; or (ii) personality trait or characteristic assessments without specific criminal intelligence; the prohibition does not prohibit AI systems used to assess risk based on specific factual indicators of criminal activity or specific intelligence linking an individual to criminal conduct - it prohibits assessments based solely on who a person is (their profile and characteristics), not assessments based on what a person has done or specific intelligence about what they may do; covered prohibited systems include: pure actuarial risk scoring tools that predict individual crime risk from demographic variables and social characteristics alone; AI that classifies individuals as high crime risk based on their network associations, past police contacts, or neighbourhood without specific evidential basis; personality-based threat assessment AI predicting criminal propensity from psychological trait assessments in the absence of specific criminal intelligence; the prohibition addresses a fundamental civil liberties concern that AI-driven profiling without specific evidence criminalises identity rather than conduct.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-prohibited-predictive-policing.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-high-risk-law-enforcement",
      "eu-ai-act-prohibited-social-scoring"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-prohibited-realtime-biometric-id",
    "title": "EU AI Act - Prohibition on Real-Time Remote Biometric Identification in Public Spaces for Law Enforcement (Article 5(1)(h))",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 5(1)(h) prohibits the use of real-time remote biometric identification (RTBRI) systems in publicly accessible spaces for law enforcement purposes, subject to three strictly defined exceptions; 'real-time remote biometric identification system' is defined in Article 3(36) as a remote biometric identification system where the capturing of biometric data, the comparison, and the identification all occur without a significant delay; the default rule is prohibition - RTBRI for law enforcement in publicly accessible spaces is presumptively banned; Article 5(1)(h) exceptions that permit RTBRI use are: (1) targeted search for a specific victim of abduction, trafficking in human persons, or sexual exploitation; (2) prevention of a specific, substantial, and imminent threat to the life of natural persons or a real and foreseeable terrorist attack; (3) detection, localisation, identification, or prosecution of a perpetrator or suspect of a criminal offence carrying a maximum penalty of at least four years of imprisonment in the Member State concerned; use of RTBRI under the exception in Article 5(1)(h) requires: prior authorisation from a judicial or other independent authority with power of judicial review in the Member State where the use is to take place, except in duly justified cases of urgency where authorisation is sought without undue delay; Member State law must expressly authorise the use of RTBRI systems in publicly accessible spaces for law enforcement purposes with defined rules, conditions, and safeguards; applicable from 2 February 2025 per Article 113; the Article 5(1)(h) framework is intended to prevent mass surveillance of the general public by law enforcement while preserving targeted biometric identification for the most serious law enforcement use cases.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-prohibited-realtime-biometric-id.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-high-risk-biometric-systems",
      "eu-ai-act-high-risk-law-enforcement",
      "eu-ai-act-prohibited-biometric-categorisation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-prohibited-social-scoring",
    "title": "EU AI Act - Prohibition on Social Scoring AI by Public Authorities (Article 5(1)(c))",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 5(1)(c) prohibits the placing on the market, putting into service, or use of AI systems by public authorities, or on their behalf, that evaluate or classify natural persons or groups of persons over a period of time based on their social behaviour or known, inferred, or predicted personal or personality characteristics, where that evaluation leads to: (1) detrimental or unfavourable treatment of those persons in social contexts unrelated to the context in which the data was originally generated or collected; or (2) detrimental or unfavourable treatment that is unjustified or disproportionate to the social behaviour or its gravity; applicable from 2 February 2025 (the date prohibited practices became enforceable under Article 113); the prohibition is absolute - Article 5(1)(c) contains no exceptions; covered AI systems include: citizen trust score platforms that aggregate behavioural data across multiple social domains (mobility, civic participation, financial conduct, online activity) to generate composite individual ratings; AI welfare eligibility systems that restrict access to public services based on inferred personality profiles or long-term behavioural histories; cross-agency AI platforms that share citizen behavioural scores between government departments for enforcement or priority purposes; the prohibition applies to public authorities directly deploying social scoring AI and to private entities - technology contractors, data analytics firms, behavioural analytics vendors - operating AI on behalf of public authorities; commercial credit scoring conducted by private banks applying established financial criteria to individual lending decisions within a single domain is not prohibited under Article 5(1)(c) - the prohibition targets AI systems that evaluate persons across diverse social contexts over time based on general behavioural characteristics, not AI systems applying sector-specific legal or commercial criteria to individual transactions; the prohibition directly addresses AI-powered systems analogous to the People's Republic of China social credit system but applies equally to any public authority AI system meeting the Article 5(1)(c) definitional criteria regardless of political context.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-prohibited-social-scoring.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-high-risk-administration-justice"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-prohibited-subliminal-manipulation",
    "title": "EU AI Act - Prohibition on Subliminal AI Manipulation and Exploitation of Vulnerabilities (Articles 5(1)(a) and 5(1)(b))",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 5(1)(a) prohibits AI systems that deploy subliminal techniques beyond a person's consciousness or deceptive techniques that materially distort the behaviour of a person or a group of persons in a manner that causes or is likely to cause that person or those persons significant harm; Article 5(1)(b) prohibits AI systems that exploit any of the vulnerabilities of a natural person or a specific group of persons due to their age, disability, or a specific social or economic situation they are in, in a manner that materially distorts the behaviour of that person or those persons in a manner that causes or is likely to cause that person or those persons or another person significant harm; both prohibitions are applicable from 2 February 2025 per Article 113; the Article 5(1)(a) subliminal manipulation prohibition covers: AI systems that use subliminal audio, visual, or haptic signals below the threshold of conscious perception to influence purchasing decisions, political choices, or behavioural patterns; dark pattern AI systems that use deceptive interface design to manipulate user decisions without transparent disclosure; persuasion AI systems that exploit psychological vulnerabilities identified through behavioural profiling to generate individually tailored manipulation; the Article 5(1)(b) exploitation of vulnerabilities prohibition covers: AI systems targeting minors with predatory engagement mechanics that override parental controls or rational decision-making; AI systems targeting individuals with mental health conditions, cognitive impairments, or dementia with manipulative content or engagement loops; AI systems exploiting individuals in social or economic vulnerability - addiction, debt, social isolation - to drive harmful commercial or behavioural outcomes; both prohibitions require causation of significant harm and material distortion of behaviour - they do not prohibit persuasive AI generally but prohibit AI that crosses the threshold of deceptive or vulnerability-exploiting manipulation with harmful effect.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-prohibited-subliminal-manipulation.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-provider-obligations-high-risk",
    "title": "EU AI Act - Obligations of Providers of High-Risk AI Systems (Articles 16-20)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Articles 16-20 establish the comprehensive obligations of providers - natural or legal persons who develop or have high-risk AI systems developed and place them on the market or put them into service under their own name or trademark - for high-risk AI systems listed in Annex III or covered by Annex I sector-specific legislation; core provider obligations under Articles 16-20 include: Article 16 - establish a quality management system under Article 17; draw up technical documentation under Article 11; ensure the high-risk AI system undergoes the applicable conformity assessment procedure under Articles 43-44; draw up the EU declaration of conformity under Article 47; affix CE marking under Article 48; register the system in the EU database under Article 49; Article 17 - implement a quality management system (QMS) covering: AI system development and testing; data governance; technical documentation procedures; post-market monitoring; risk management; conformity assessment; Article 18 - keep technical documentation for 10 years after placing on the market or putting into service (or for the period the system is in service where longer); Article 19 - cooperate with national competent authorities on all requests; Article 20 - implement automatic logging capabilities enabling re-tracing of AI system operation over a period appropriate to the AI system's purpose; the provider is responsible for compliance of the high-risk AI system throughout its lifecycle, including after sale - post-market monitoring obligations under Article 61 continue after the system has been placed on the market; where a high-risk AI system is embedded in a product covered by Union harmonisation legislation listed in Annex I (e.g., machinery, medical devices, automotive), providers must comply with both the EU AI Act and the applicable sectoral legislation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-provider-obligations-high-risk.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-conformity-assessment-procedure",
      "eu-ai-act-technical-documentation-requirements",
      "eu-ai-act-post-market-surveillance-monitoring",
      "eu-ai-act-deployer-obligations-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-quality-management-system",
    "title": "EU AI Act - Quality Management System Obligations for High-Risk AI Providers (Article 17)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 17 requires providers of high-risk AI systems to put in place a quality management system (QMS) that ensures compliance with the EU AI Act; Article 17(1) - providers of high-risk AI systems shall put in place a quality management system that ensures compliance with this Regulation; the quality management system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions, and shall cover at least: (a) a strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for managing modifications to the high-risk AI system; (b) techniques, procedures and systematic actions to be used for the design, design control and design verification of the high-risk AI system; (c) techniques, procedures and systematic actions to be used for the development, quality control and quality assurance of the high-risk AI system; (d) examination, test and validation procedures to be carried out before, during and after the development of the high-risk AI system and the frequency with which they have to be carried out; (e) technical specifications, including standards, to be applied and, where the relevant harmonised standards are not applied in full, the means to be used to ensure that the high-risk AI system meets the requirements set out in Chapter III Section 2; (f) systems and procedures for data management, including data collection, data analysis, data labelling, data storage, data filtration, data mining, data aggregation, data retention and any other operation regarding the data that is performed before and for the purposes of the placing on the market or the putting into service of high-risk AI systems; (g) the risk management system referred to in Article 9; (h) the setting up, implementation and maintenance of a post-market monitoring system, in accordance with Article 61; (i) procedures related to the reporting of serious incidents in accordance with Article 62 and of malfunctions; (j) the handling of communication with national competent authorities, other competent authorities, the European AI Office, notified bodies, other operators, customers or other interested parties; (k) systems and procedures for record keeping of all relevant documentation and information; (l) resource management, including measures related to supply chain security; (m) an accountability framework setting out the responsibilities of the management and other staff with regard to all aspects listed in this Article 17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-quality-management-system.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-provider-obligations-high-risk",
      "eu-ai-act-risk-management-system",
      "eu-ai-act-technical-documentation-requirements",
      "eu-ai-act-conformity-assessment-procedure",
      "eu-ai-act-post-market-surveillance-monitoring"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-regulatory-sandboxes-article-57",
    "title": "EU AI Act: Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox (Article 57)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Under Article 57 of the EU AI Act, AI regulatory sandboxes may permit the processing of special categories of personal data for developing and testing certain AI systems in the public interest, provided that specific safeguards, such as technical limitations and robust security measures, are implemented.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-high-risk",
      "iso-42001-risk-assess",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-right-to-complaint-remedy",
    "title": "EU AI Act - Right to Lodge Complaint and Effective Judicial Remedy (Articles 87-88)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Articles 87-88 establish procedural rights enabling natural persons to challenge AI systems that may violate the Regulation; Article 87 - right to lodge a complaint: any natural person, organisation, association or body mandated in accordance with Union or national law shall have the right to lodge a complaint with the relevant national competent authority (market surveillance authority) against AI system providers or deployers that they believe to be in breach of the EU AI Act; the national competent authority must acknowledge the complaint and follow up in accordance with Article 74 market surveillance powers; for complaints against GPAI model providers, the complaint should be addressed to the European AI Office; Article 88 - right to an effective judicial remedy against a national competent authority: persons affected by a national competent authority's decision have the right to an effective judicial remedy before a national court; Member States must ensure that any person whose rights have been adversely affected by a decision of a national competent authority has access to a court or tribunal for review; Article 88(3) - proceedings against providers or deployers may be brought before competent courts in the Member State where the provider or deployer has an establishment or where the affected natural person has their habitual residence; Article 87 complaint rights apply from 2 August 2026 per Article 113(3); the EU AI Act does not create direct private rights of action against providers for non-compliance - enforcement is through national competent authorities; however, individuals affected by prohibited AI practices may have direct claims under GDPR, national tort law, or the EU AI Liability Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-right-to-complaint-remedy.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-market-surveillance-framework",
      "eu-ai-act-penalties-and-enforcement",
      "eu-ai-act-deployer-obligations-high-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-right-to-explanation",
    "title": "EU AI Act - Right to Explanation for Decisions Made with High-Risk AI Assistance (Article 86)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 86 establishes a right to explanation for individuals significantly affected by decisions made on the basis of high-risk AI system outputs where those decisions produce legal effects or similarly significantly affect the person; Article 86(1) - any natural person subject to a decision taken by the deployer that is based to a significant extent on the output of a high-risk AI system listed in Annex III shall have the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken; Article 86(2) - the right to explanation does not apply where: (a) the high-risk AI system is subject to Union law providing for the right to explanation in a manner already satisfying the explanation requirement (including GDPR Article 22 right to explanation for automated decisions); (b) the use of the AI system is authorised by Union or Member State law for reasons of overriding public interest including crime prevention; (c) the explanation would reveal information that is confidential, in particular trade secrets; the right to explanation under Article 86 supplements GDPR Article 22 - it applies to AI-assisted decisions by human decision-makers (not only fully automated decisions); this distinguishes Article 86 from GDPR Article 22 which is limited to solely automated individual decisions; Article 86 applies to all Annex III high-risk AI categories - employment decisions (Annex III Point 4), essential service access (Point 5), law enforcement (Point 6), and others; deployers must establish a procedure for handling Article 86 explanation requests including: who receives requests; what information is provided; the timeline for response; applicable from 2 August 2026 per Article 113(3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-right-to-explanation.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-deployer-obligations-high-risk",
      "eu-ai-act-high-risk-employment-recruitment",
      "eu-ai-act-high-risk-essential-services",
      "eu-ai-act-technical-documentation-requirements"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-risk-management-system",
    "title": "EU AI Act - Risk Management System for High-Risk AI Systems (Article 9)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 9 requires providers of high-risk AI systems to establish, implement, document, and maintain a risk management system throughout the entire lifecycle of the high-risk AI system; the Article 9 risk management system must be a continuous iterative process running throughout the AI system's lifecycle - from design through development, testing, deployment, and post-market operation; Article 9(2) - the risk management system must cover: (a) identification and analysis of the known and reasonably foreseeable risks associated with the high-risk AI system; (b) estimation and evaluation of risks that may emerge when the AI system is used in accordance with its intended purpose and under conditions of reasonably foreseeable misuse; (c) evaluation of other possibly arising risks based on analysis of post-market monitoring data; (d) adoption of appropriate and targeted risk management measures; Article 9(3) - risk management measures must give due consideration to the effects and possible interaction of the measures implemented to minimise cumulative side effects; Article 9(4) - providers must implement testing to identify the most appropriate risk management measures; testing must be performed against predefined metrics and probabilistic thresholds appropriate to the intended purpose; Article 9(5) - the risk management system must specifically consider the risks to health, safety, and fundamental rights of persons who may be particularly vulnerable due to age, disability, or social/economic situation; Article 9(6) - providers must adopt measures to ensure adequate levels of accuracy, robustness, and cybersecurity and minimise risks arising from inaccuracies; the Article 9 risk management system documentation feeds directly into the technical documentation under Article 11 and Annex IV and is reviewed as part of conformity assessment under Article 43.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-risk-management-system.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-provider-obligations-high-risk",
      "eu-ai-act-technical-documentation-requirements",
      "eu-ai-act-conformity-assessment-procedure",
      "eu-ai-act-post-market-surveillance-monitoring"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-sme-startup-provisions",
    "title": "EU AI Act - SME and Startup-Specific Provisions: Reduced Fees, Sandbox Priority, and Proportionate Compliance",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) includes multiple provisions specifically designed to reduce the compliance burden on small and medium-sized enterprises (SMEs, as defined in Commission Recommendation 2003/361/EC - fewer than 250 employees and annual turnover ≤€50M or balance sheet ≤€43M) and startups, recognising that disproportionate compliance costs could stifle EU AI innovation and favour large incumbents: Article 57(3) requires Member States to give SMEs and startups priority access to regulatory sandboxes; Article 73(3) limits administrative fines for SMEs to lower maximums than those applicable to large enterprises (maximum €15M or 3% of global annual turnover for most violations by SMEs, versus €35M or 7% for violations involving prohibited practices); Article 55(3) requires the Commission to consider the specific interests of SMEs when adopting delegated acts; Recital 91 acknowledges the potential disproportionate impact of EU AI Act obligations on SMEs and instructs authorities to take proportionate enforcement approaches; Article 60(7) reduces fees charged by national competent authorities for EU AI database registration for SMEs; Article 72 provides that Member States shall ensure that regulatory sandboxes are accessible to SMEs without undue financial or administrative barriers; the EU AI Office must publish guidance specifically addressing SME compliance with the EU AI Act's requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-sme-startup-provisions.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-72-ai-regulatory-sandboxes",
      "eu-ai-act-article-71-fines",
      "eu-ai-act-article-73-penalties",
      "eu-ai-act-article-60-eu-database-high-risk-ai",
      "eu-ai-act-article-55-systemic-risk-gpai"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-technical-documentation-requirements",
    "title": "EU AI Act - Technical Documentation Requirements for High-Risk AI Systems (Article 11 and Annex IV)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 11 requires providers of high-risk AI systems to draw up technical documentation before the system is placed on the market or put into service and to keep it up-to-date throughout the AI system's lifecycle; Annex IV specifies the mandatory minimum content of the technical documentation; the technical documentation serves two functions: (1) enabling market surveillance authorities and notified bodies to assess whether the AI system complies with EU AI Act requirements; (2) providing a comprehensive record of the AI system's development, capabilities, limitations, and risk management measures; Annex IV technical documentation minimum content includes: a general description of the AI system including: intended purpose; the persons or groups it is intended to be used by; the contexts of intended use; the known or foreseeable circumstances where the system may be improperly used; the information sheet for the system including a summary for users; a detailed description of the system elements and its development process covering: design specifications; training methodologies; design choices and assumptions; design limitations; training data sources and characteristics; training data labelling and annotation procedures; data pre-processing operations; dataset validation; a description of monitoring, functioning, and control including: the measures for human oversight; the system's capabilities, limitations, and accuracy levels; a description of the risk management measures; a description of the changes made after the conformity assessment for systems that undergo a substantial modification; technical documentation must be retained for 10 years from the date of placing on the market or putting into service under Article 18 or for the period the system remains in service where longer; technical documentation must be provided to national competent authorities and notified bodies upon request.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-technical-documentation-requirements.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-provider-obligations-high-risk",
      "eu-ai-act-conformity-assessment-procedure",
      "eu-ai-act-high-risk-employment-recruitment",
      "eu-ai-act-high-risk-biometric-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-title-viii-gpai-obligations",
    "title": "Regulation (EU) 2024/1689 (EU AI Act) Title VIII - General-Purpose AI Models: Capability Thresholds, Technical Documentation and Systemic Risk Rules",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes a tiered compliance framework for providers of General-Purpose AI (GPAI) models, mandating transparency obligations for all GPAI models under Article 52 and imposing stricter requirements for models classified as having systemic risk based on high-impact capabilities or computational power thresholds defined in Article 51.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-gpai-obligations-chapter-v",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "eu-ai-act-incident-reporting-article-73"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-act-transparency-certain-ai-systems",
    "title": "EU AI Act - Transparency Obligations for AI Systems Interacting with Natural Persons (Article 50)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 50 establishes transparency obligations for specific categories of AI systems that interact with natural persons or generate content, applicable from 2 August 2026 (24 months after entry into force per Article 113); Article 50 transparency obligations apply to four categories: (1) Article 50(1) - providers of AI systems intended to interact directly with natural persons must design and develop the system so that natural persons are informed they are interacting with an AI system - this covers chatbots, virtual assistants, and AI customer service systems; an exception applies where the AI nature of the system is obvious from the context; (2) Article 50(2) - deployers of AI systems that interact with natural persons must inform those persons that they are interacting with an AI system, unless the AI nature is obvious from the context or has been disclosed by the provider through Article 50(1) design; (3) Article 50(3) - providers of AI systems that generate synthetic audio, video, image, or text content must ensure outputs are marked with a machine-readable format identifying the content as AI-generated (watermarking or equivalent technical solution); Article 50(4) - deployers of AI systems generating synthetic content must disclose to natural persons when the content they are exposed to has been AI-generated or manipulated, for: deep fakes (video or image bearing resemblance to existing persons, places, or events); audio deep fakes; AI-generated images, video, or audio published in the public interest; a limited exception applies under Article 50(4) for legally authorised journalism purposes; the Article 50 transparency obligations apply to all AI systems meeting the specified criteria regardless of whether they are high-risk AI systems - they represent a baseline transparency floor below the full Article 26 deployer obligation framework; compliance with Article 50(3) watermarking requires technical solutions that are interoperable, effective, and difficult to remove.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-transparency-certain-ai-systems.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-deployer-obligations-high-risk",
      "eu-ai-act-provider-obligations-high-risk",
      "eu-ai-act-prohibited-subliminal-manipulation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-transparency-instructions-for-use",
    "title": "EU AI Act - Transparency and Instructions for Use for High-Risk AI Systems (Article 13)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU AI Act (Regulation 2024/1689) Article 13 requires providers of high-risk AI systems to design and develop the systems in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret the system's output and use it appropriately; Article 13(1) - high-risk AI systems must be designed and developed in such a way that their operation is sufficiently transparent to enable deployers to interpret the system's output and use it appropriately; Article 13(2) - providers must accompany each high-risk AI system with instructions for use in an appropriate digital format or otherwise, including information needed to enable deployers to implement the obligations in Article 26 (deployer obligations for high-risk AI); Article 13(3) - the instructions for use shall contain at least: (a) the identity and contact details of the provider; (b) the characteristics, capabilities, and limitations of performance of the high-risk AI system including: (i) its intended purpose; (ii) the level of accuracy, robustness and cybersecurity as set out in Article 15 against which the high-risk AI system has been tested and validated, including its metrics; (iii) any known or foreseeable circumstance related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse that may lead to risks to health and safety or fundamental rights; (iv) where applicable, the technical capabilities and characteristics of the high-risk AI system to provide information relevant to its explainability; (v) where applicable, the computational and hardware resources needed; (vi) any performance limitation specific to the high-risk AI system relevant to its use case; (c) the changes to the high-risk AI system and its performance that have been pre-determined by the provider at the moment of the initial conformity assessment; (d) the human oversight measures referred to in Article 14, including the technical measures to facilitate the interpretation of the outputs of high-risk AI systems by the deployers; (e) the expected lifetime of the high-risk AI system and any necessary maintenance and care measures to ensure the proper functioning of that AI system, including for software updates; (f) where relevant, a description of the mechanisms for the logging of automatically generated data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-transparency-instructions-for-use.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-113-entry-into-force-application",
      "eu-ai-act-provider-obligations-high-risk",
      "eu-ai-act-deployer-obligations-high-risk",
      "eu-ai-act-technical-documentation-requirements",
      "eu-ai-act-right-to-explanation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-act-transparency-obligations-article-50",
    "title": "EU AI Act: Transparency Obligations for Certain AI Systems (Article 50)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Providers and deployers of certain AI systems must ensure natural persons are informed when they are interacting with an AI system or when content is artificially generated or manipulated, as mandated by Article 50 of Regulation (EU) 2024/1689. This includes chatbots, emotion recognition systems, biometric categorisation systems, and systems generating 'deep fakes'.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-transparency",
      "nist-ai-rmf-manage",
      "nist-ai-100-4-synthetic-content",
      "unesco-ethics-ai"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ai-coordinated-plan-2021-2024",
    "title": "EU Coordinated Plan on Artificial Intelligence 2021 - Member State AI Strategy Coordination Framework",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The EU Coordinated Plan on Artificial Intelligence (the Coordinated Plan) was first adopted in December 2018 and substantively revised in April 2021 by the European Commission to align with the EU AI Act regulatory framework; the 2021 Coordinated Plan establishes the framework for EU-level and Member State coordination of AI investments, regulatory implementation, and innovation ecosystems; the Plan operates alongside the EU AI Act as the strategic investment and coordination complement to the regulatory framework; the Coordinated Plan has four strategic objectives: (1) Conditions enabling AI development and uptake - Member States should create regulatory sandboxes, invest in data infrastructure, develop AI testing and experimentation facilities, and update national AI strategies to align with EU AI Act implementation; (2) Making the EU the right place for AI to thrive - attracting AI talent, investing in EU-based AI compute infrastructure (supercomputers, data spaces), supporting European AI startups, and developing EU AI benchmarks and evaluation tools; (3) Making AI work for people and be a source of growth - deploying AI in public services (healthcare, transport, energy, government), supporting SMEs in AI adoption, and using AI to address climate and sustainability challenges; (4) Building strategic leadership in high-impact sectors - developing AI in critical sectors including health, agriculture, climate, public administration, and mobility; national AI strategies - all 27 EU Member States are required to develop and update national AI strategies aligned with the Coordinated Plan and the EU AI Act; the European Commission reviews Member State strategies and publishes progress reports; the Coordinated Plan was further updated in 2024 to reflect EU AI Act enforcement timelines, AI Office establishment, and the GPAI Code of Practice process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-coordinated-plan-2021-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-ai-regulatory-sandboxes",
      "eu-data-governance-act-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-liability-directive-2022",
    "title": "Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on adapting non-contractual civil liability rules to artificial intelligence (AI Liability Directive)",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This proposal establishes fault-based liability rules for damage caused by AI systems, introducing a disclosure obligation for evidence related to high-risk AI systems and a rebuttable presumption of causality where certain conditions are met, as outlined in the explanatory memorandum. It applies to claimants seeking compensation for damage caused by AI-enabled products or services where national fault-based liability rules are insufficient due to AI's complexity and opacity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-product-liability-directive-2022-revision"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-liability-directive-2022-0303-article-4-disclosure-evidence-high-risk-ai",
    "title": "EU AI Liability Directive Proposal (2022/0303) - Article 4: Disclosure of Evidence for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 4 of the proposed EU AI Liability Directive (Commission Proposal COM(2022)496) establishes a mechanism for courts to order disclosure of relevant evidence from providers and users of high-risk AI systems where a claimant plausibly demonstrates that they have suffered damage and requests disclosure of evidence necessary to substantiate their claim. The court may order disclosure of evidence from the defendant where the claimant has done everything reasonably possible to obtain the evidence themselves and is unable to obtain it. The scope of disclosure is limited to what is necessary and proportionate for the claim. The defendant must preserve relevant evidence pending the disclosure order. Failure to comply with the court's disclosure order creates a rebuttable presumption that the defendant was non-compliant with the duty of care applicable to the AI system. The Directive is proposed - it is in the legislative process and has not yet been adopted as law; negotiation has resulted in proposed revisions and the legislative timeline may be affected by the EU AI Act's liability provisions. As of 2026, the Directive remains a Commission proposal. Companies deploying high-risk AI systems should track the legislative progress and prepare for evidence preservation and disclosure obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-liability-directive-2022-0303-article-5-rebuttable-presumption-causality"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-liability-directive-2022-0303-article-5-rebuttable-presumption-causality",
    "title": "EU AI Liability Directive Proposal (2022/0303) - Article 5: Rebuttable Presumption of Causality for Non-Compliant High-Risk AI",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 5 of the proposed EU AI Liability Directive (Commission Proposal COM(2022)496) establishes a rebuttable presumption of causal link between non-compliance with EU AI Act duties of care and damage caused by a high-risk AI system. The presumption applies where: (a) a national court has found, or it has been established through an Article 4 disclosure order, that the defendant failed to comply with a duty of care under EU law (including EU AI Act obligations); AND (b) it is reasonably likely, based on the circumstances, that the non-compliance influenced the output of the AI system that caused the damage. Once the presumption applies, the defendant bears the burden of proving that the non-compliance did not cause the damage. The presumption does not apply where the defendant demonstrates that sufficient evidence exists to make it excessively difficult for the claimant to prove the causal link. The Directive is proposed - it is in the legislative process and has not yet been adopted as law. As of 2026, the Directive remains a Commission proposal. Companies deploying high-risk AI systems should treat Article 5 as the liability consequence of Article 9-17 EU AI Act non-compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-liability-directive-2022-0303-article-4-disclosure-evidence-high-risk-ai"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-liability-directive-2022-proposed-burden-proof",
    "title": "EU AI Liability Directive (COM/2022/496) - Burden of Proof Reversal for AI System Damage",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The proposed EU AI Liability Directive (COM(2022) 496) complements the Product Liability Directive by addressing non-contractual fault-based civil liability for damage caused by AI systems: it introduces a disclosure obligation requiring AI providers and deployers to disclose evidence of high-risk AI system operation, creates a rebuttable presumption of causation where disclosure is refused or AI system output is proven faulty, and applies to natural and legal persons harmed by AI systems within EU jurisdiction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024-1689-article-26-obligations-deployers-high-risk-ai"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-liability-directive-2023-proposal",
    "title": "Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on adapting non-contractual civil liability rules to artificial intelligence (AI Liability Directive)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-09-28",
    "bluf": "This proposed directive facilitates civil liability claims for damages caused by AI systems by establishing a rebuttable presumption of a causal link between a provider's fault and the AI-produced output (Article 4) and empowering national courts to order the disclosure of evidence on high-risk AI systems (Article 3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-high-risk",
      "iso-42001-transparency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-liability-directive-2024",
    "title": "Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on adapting non-contractual civil liability rules to artificial intelligence (AI Liability Directive)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This directive establishes rules to ease the burden of proof for victims claiming compensation for damage caused by AI systems, applying to non-contractual civil liability claims within the EU. It introduces a rebuttable presumption of a causal link for high-risk AI systems (Article 4) and grants national courts the power to order the disclosure of evidence from providers (Article 3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-high-risk",
      "iso-42001-transparency",
      "iso-42001-risk-assess",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ai-liability-directive-proposal-2022",
    "title": "Proposal for a Directive of the European Parliament and of the Council on adapting non-contractual civil liability rules to artificial intelligence (AI Liability Directive)",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU AI Liability Directive Proposal COM(2022) 496 establishes a rebuttable presumption of causality in AI-related harm claims when claimants prove non-compliance with EU AI Act obligations and the defendant’s failure to disclose relevant evidence. It applies to providers and deployers of high-risk AI systems involved in civil liability cases before national courts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-transparency",
      "iso-42001-risk-assess",
      "eu-esrs-s1-workforce",
      "nist-ai-100-4-redteam"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-liability-directive-proposal-2022-workflow",
    "title": "Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on adapting non-contractual civil liability rules to artificial intelligence (AI Liability Directive)",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This proposal establishes a rebuttable presumption of causality in AI-related damage claims and enables disclosure of evidence from AI operators to claimants, supporting fault-based liability for high-risk AI systems under strict procedural safeguards. Key provisions include Article 3 (presumption of causality) and Article 4 (disclosure of evidence).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-automated-decision-workflows",
      "eu-nis2-directive-workflow-critical-operations",
      "agent-kill-switch"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-office-establishment-2024",
    "title": "European AI Office - Commission Decision Establishing the European Artificial Intelligence Office (January 24, 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On January 24, 2024 the European Commission adopted Commission Decision C(2024)390 establishing the European Artificial Intelligence Office within the Commission Directorate-General for Communications Networks, Content and Technology (DG CNECT). The AI Office is operational from February 21, 2024 and is the central EU body for the implementation and enforcement of the EU AI Act, particularly the provisions on general-purpose AI models with systemic risk. The AI Office tasks include: (1) Supporting implementation and enforcement of the EU AI Act across Member States and the European AI Board; (2) Conducting evaluations and investigations of general-purpose AI models including those with systemic risk; (3) Facilitating the development of codes of practice including the General-Purpose AI Code of Practice (July 2025); (4) Coordinating with national competent authorities, the European Data Protection Board, the European Data Protection Supervisor, and the European Centre for Algorithmic Transparency at the Joint Research Centre; (5) Engaging internationally with allied AI Safety Institutes including UK AISI, US CAISI, Japan AISI, Singapore AISI; (6) Supporting the European AI Pact voluntary commitments; (7) Issuing Guidelines on the application of the AI Act including the Guidelines on Prohibited AI Practices (February 2025). The AI Office is headed by an AI Office Head reporting through DG CNECT.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlay",
        "international_alignment",
        "us_comparative"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-56-ai-office",
      "eu-ai-office-gpai-code-of-practice-2025",
      "eu-commission-guidelines-prohibited-ai-practices-2025",
      "eu-ai-pact-voluntary-pre-commitments-2024"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-ai-office-gpai-code-of-practice-2025",
    "title": "EU AI Office - General-Purpose AI Code of Practice (Published July 2025, Effective August 2 2025)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The European AI Office published the General-Purpose AI Code of Practice on July 10, 2025, with effect aligned to the EU AI Act GPAI obligations becoming applicable on August 2, 2025. The Code of Practice operationalises the obligations of providers of general-purpose AI models under the EU AI Act, particularly Articles 53-55 covering all GPAI providers and the additional obligations for providers of GPAI models with systemic risk. The Code is structured in three commitments: (1) Transparency - GPAI providers must draw up and keep up to date technical documentation of the model, make information and documentation available to providers of AI systems integrating the GPAI model, and put in place a policy to comply with EU copyright law including the text and data mining opt-out under the DSM Directive 2019/790; (2) Copyright - dedicated commitments on copyright compliance and the implementation of opt-out mechanisms; (3) Safety and Security (for providers of GPAI models with systemic risk only) - perform model evaluation including adversarial testing, assess and mitigate possible systemic risks at Union level, track and report serious incidents, ensure adequate cybersecurity protection of the model and physical infrastructure. The Code was developed through a multi-stakeholder process led by the EU AI Office with 1000+ experts, 13 chairs and vice-chairs, and four working groups. Adherence to the Code creates a presumption of conformity with the underlying EU AI Act obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlay",
        "copyright_overlay",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-53-gpai-codes-of-practice",
      "eu-ai-act-article-55-systemic-risk-gpai",
      "eu-ai-act-article-50-gpai-transparency",
      "eu-ai-act-article-51-gpai-systemic-risk-classification",
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ai-pact-voluntary-pledges-2024",
    "title": "EU AI Pact 2024 - Voluntary Pledges Before AI Act Application: Early GPAI Code of Practice Implementation, Transparency Templates, Systemic Risk Assessment Commitments, 700+ Company Signatories, European AI Office Oversight and Basis for AI Act Code of Practice",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU AI Pact establishes a voluntary framework for organisations to proactively commit to early implementation of key AI Act requirements, particularly around governance, high-risk system identification, and staff awareness. It applies to providers and deployers of AI systems across all sectors, with over 230 companies already pledging under Pillar II to at least three core actions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-data-governance-act-2022-cloud-data-sharing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ai-pact-voluntary-pre-commitments-2024",
    "title": "EU AI Pact - Voluntary Pre-Commitments to the EU AI Act (Launched September 25, 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The European AI Office launched the EU AI Pact on September 25, 2024 as a voluntary initiative for companies to commit to early implementation of selected EU AI Act obligations ahead of mandatory application dates. The Pact is structured in two pillars. Pillar I provides for outreach and capacity building - information sessions, learning events, multi-stakeholder dialogue led by the AI Office to support implementation readiness. Pillar II is the formal voluntary pledge mechanism where organisations make written commitments to specified actions across three core areas: (1) Adopt an AI governance strategy to foster the uptake of AI in the organisation and prepare for AI Act compliance; (2) Identify and map AI systems likely to be categorised as high-risk under the AI Act; (3) Promote AI literacy and awareness among staff and others dealing with AI systems on behalf of the organisation. Signatories may also make additional voluntary pledges on specific AI Act obligations such as fundamental rights impact assessments, human oversight, content labelling for AI-generated material, or transparency about generative AI use. The launch involved 100+ companies including major US, EU, and Asian providers. The Pact does not replace EU AI Act compliance obligations but is intended to accelerate practical readiness and demonstrate good-faith engagement to the AI Office.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlay",
        "nist_framework",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-office-gpai-code-of-practice-2025",
      "eu-ai-act-article-4-ai-literacy",
      "eu-ai-act-article-6-classification-high-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-aifmd-2-directive-2024-927",
    "title": "EU AIFMD2 Directive 2024/927 - Loan-Originating Funds & Delegation Rules",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive 2024/927 (AIFMD2, amending AIFMD 2011/61/EU and UCITS Directive 2009/65/EC) introduces a harmonised EU framework for loan-originating Alternative Investment Funds (LO-AIFs): a 20% diversification limit per borrower, prohibition on lending to AIFMs/their managers, a 150% leverage limit for open-ended LO-AIFs, and a 300% leverage limit for closed-ended LO-AIFs. AIFMD2 harmonises delegation rules (requiring proportionate staffing in the EU vs third-country delegate), introduces substance requirements for AIFMs, and expands liquidity management tools (LMTs - gating, notice period, swing pricing, redemption fees). Member State transposition deadline: 16 April 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aifmd-directive-2011-61",
      "eu-esma-regulation-1095-2010"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-aifmd-directive-2011-61",
    "title": "EU Alternative Investment Fund Managers Directive (AIFMD) 2011/61/EU & AIFMD II 2024/927",
    "domain": "Banking & Global Finance",
    "version": "2.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive 2011/61/EU governs EU Alternative Investment Fund Managers (AIFMs) - managers of hedge funds, private equity, real estate, and other non-UCITS funds. Sub-threshold exemption: AIFMs with AUM below EUR 100M (leveraged) or EUR 500M (unleveraged, 5-year lock-up closed-end) register with their NCA only. Full-scope AIFMs require NCA authorisation, a single depositary per AIF (Article 21), minimum capital of EUR 125,000 plus 0.02% of AUM exceeding EUR 250M (capped at EUR 10M), an EU marketing passport (Article 31, 20 working days), and annual Annex IV regulatory reporting. AIFMD II (Directive 2024/927/EU, in force 15 April 2024) adds harmonised liquidity management tools (Annex V menu), mandatory rules for loan-originating AIFs (closed-ended structure required, 5% risk retention), and clarified delegation provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "MiFID_II",
        "UCITS",
        "SFDR",
        "PRIIPs",
        "EMIR",
        "AML",
        "CRD_VI",
        "AMLA"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-priips-regulation-1286-2014-kid",
      "eu-sfdr-2019-2088",
      "eu-emir-refit-2019-834-derivatives-reporting",
      "eu-aml-regulation-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-aifmd-directive-article-12-general-principles-and-operating-conditions",
    "title": "Alternative Investment Fund Managers Directive (AIFMD) 2011/61/EU - Article 12: General principles",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "AIFMs must at all times act honestly, with due skill, care, and diligence, and fairly in the conduct of their activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-aifmd-directive-article-13-remuneration-policies-and-practices",
    "title": "Alternative Investment Fund Managers Directive (AIFMD) 2011/61/EU Article 13: Remuneration",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "AIFMs must establish and maintain remuneration policies and practices for key staff that promote sound risk management and do not encourage excessive risk-taking inconsistent with the AIF's profile.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-aifmd-directive-article-14-conflicts-of-interest-prevention-management",
    "title": "Alternative Investment Fund Managers Directive (AIFMD) 2011/61/EU Article 14: Conflicts of interest",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "AIFMs must take all reasonable steps to identify, prevent, manage, and monitor conflicts of interest, and where these measures are insufficient, they must disclose the conflicts to investors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-aifmd-directive-article-17-liquidity-management-aif",
    "title": "Alternative Investment Fund Managers Directive (AIFMD) 2011/61/EU Article 17: Investment in securitisation positions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Mandates the European Commission to adopt delegated acts establishing requirements for AIFM investments in securitisation positions to ensure consistency and align the interests of originators and investors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-aifmd-directive-article-19-valuation-of-aif-assets",
    "title": "Alternative Investment Fund Managers Directive (AIFMD) 2011/61/EU - Article 19: Valuation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "AIFMs must establish and maintain appropriate, consistent procedures for each AIF they manage to ensure a proper and independent valuation of the AIF's assets, compliant with AIFMD, national law, and the AIF's own rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-aifmd-directive-article-22-annual-report-aif-obligations",
    "title": "Alternative Investment Fund Managers Directive (AIFMD) 2011/61/EU Article 22: Annual report",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "AIFMs must prepare and make available an annual report for each managed EU AIF and each marketed AIF within 6 months of the financial year-end, providing it to investors on request and to competent authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-aifmd-directive-article-23-disclosure-to-investors-requirements",
    "title": "Alternative Investment Fund Managers Directive (AIFMD) 2011/61/EU Article 23: Disclosure to investors",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "AIFMs must provide specific information to potential investors before they invest in an AIF and disclose any material changes to that information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-aifmd-directive-article-7-conditions-for-authorisation-aifms",
    "title": "Alternative Investment Fund Managers Directive (AIFMD) 2011/61/EU - Article 7: Application for authorisation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires Alternative Investment Fund Managers (AIFMs) to apply for and obtain authorisation from the competent authorities of their home Member State before commencing operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-aifmd-directive-article-8-application-for-authorisation-procedure",
    "title": "Alternative Investment Fund Managers Directive (AIFMD) 2011/61/EU - Article 8: Conditions for granting authorisation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article establishes the mandatory conditions that an Alternative Investment Fund Manager (AIFM) must meet for competent authorities to grant authorisation, including requirements for shareholder suitability, director experience, and structural transparency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-air-passenger-rights-regulation-261-2004",
    "title": "Regulation (EC) No 261/2004 of the European Parliament and of the Council of 11 February 2004 establishing common rules on compensation and assistance to passengers in the event of denied boarding and of cancellation or long delay of flights",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation establishes minimum rights for air passengers in the event of denied boarding, cancellation or long delay of flights (Article 1). It applies to passengers departing from an EU airport and to passengers on EU-carrier flights into the EU (Article 3). In cases of denied boarding (Article 4) and cancellation (Article 5), passengers are entitled to compensation under Article 7 of EUR 250 for flights of 1500 km or less, EUR 400 for intra-Community flights over 1500 km and other flights between 1500 and 3500 km, and EUR 600 for other flights, together with the right to reimbursement or re-routing (Article 8) and the right to care (Article 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-air-services-regulation-1008-2008",
      "eu-easa-basic-regulation-2018-1139-common-rules-civil-aviation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-air-quality-directive-2008-50-ec",
    "title": "EU Ambient Air Quality Directive 2008/50/EC",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Directive 2008/50/EC (the Ambient Air Quality Directive) establishes a framework for assessment and management of ambient air quality across the EU. It sets limit values for major pollutants (sulphur dioxide, nitrogen dioxide, particulate matter PM10 and PM2.5, lead, benzene, carbon monoxide, ozone) and requires Member States to assess air quality in zones and agglomerations, establish monitoring networks, develop air quality plans where limits are exceeded, and provide public information. Revised limit values per Directive (EU) 2024/2881 align EU standards more closely with WHO Air Quality Guidelines effective from 1 January 2030.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-air-services-regulation-1008-2008",
    "title": "Regulation (EC) No 1008/2008 of the European Parliament and of the Council of 24 September 2008 on common rules for the operation of air services in the Community",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation governs the licensing of Community air carriers, their right to operate intra-Community air services and the pricing of air services (Article 1). No undertaking may carry passengers, mail or cargo for remuneration without an operating licence (Article 3), granted only where the undertaking holds a valid air operator certificate, meets ownership and control conditions, and satisfies the financial conditions (Articles 4 to 6). Carriers must also be of good repute (Article 7), with rules on the validity, suspension and revocation of the operating licence (Articles 8 and 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-easa-basic-regulation-2018-1139-common-rules-civil-aviation",
      "eu-air-passenger-rights-regulation-261-2004"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-allergen-regulation-2021-382",
    "title": "Commission Delegated Regulation (EU) 2021/382 of 17 December 2020 amending the Annexes to Regulation (EC) No 852/2004 of the European Parliament and of the Council on the hygiene of foodstuffs as regards food allergen management, redistribution of food and food safety culture",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation amends EU Regulation 852/2004, mandating food business operators to implement specific procedures to prevent or limit the presence of allergens listed in Annex II of Regulation (EU) No 1169/2011. As per the new Chapter VA of Annex II, operators must use dedicated equipment and take measures to prevent cross-contamination at all stages of production, processing, and distribution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-law-178-2002",
      "haccp-food-safety",
      "iso-22000-food-mgt",
      "brc-food-safety-global"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-alternative-fuels-infrastructure-regulation",
    "title": "Regulation (EU) 2023/1804 on the deployment of alternative fuels infrastructure and amending Directive 2009/33/EC and Regulation (EU) No 1315/2013",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The EU Alternative Fuels Infrastructure Regulation (AFIR) mandates Member States to ensure the deployment of minimum levels of publicly accessible EV charging and hydrogen refuelling infrastructure along the TEN-T core and extended core network by 2025 and 2030, with specific requirements for smart charging, price transparency, and cross-border roaming. Key obligations are set out in Articles 3, 4, 5, and 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "eu-digital-education-action-plan-2021-2027-deap",
      "germany-autonomous-driving-law-2021-stvaendg",
      "uk-automated-electric-vehicles-act-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-alternative-fuels-infrastructure-regulation-2023-1804",
    "title": "Regulation (EU) 2023/1804 on the deployment of alternative fuels infrastructure",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Requires EU Member States to deploy minimum levels of publicly accessible electric vehicle (EV) charging and refuelling infrastructure along the Trans-European Transport Network (TEN-T), including high-power charging every 60 km and shore-side electricity supply at core ports. Applies to Member States and infrastructure operators under Articles 3, 4, and 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "germany-autonomous-driving-law-2021-stvaendg",
      "uk-automated-electric-vehicles-act-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-aml-6th-directive-2018-1673-criminal-liability-money-laundering",
    "title": "EU 6th Anti-Money Laundering Directive 2018/1673 - Criminal Liability and Predicate Offences",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive (EU) 2018/1673 (6AMLD) harmonises criminal law provisions for money laundering across EU Member States, expanding the list of predicate offences to 22 categories, extending liability to legal persons, and requiring Member States to criminalise aiding and abetting. Financial institutions must align AML programmes to address the expanded predicate offence list.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-6-lawful-basis-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-aml-authority-amla-2024",
    "title": "Regulation (EU) 2024/1620 of the European Parliament and of the Council of 31 May 2024 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010 and (EU) No 1095/2010",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2024-06-19",
    "bluf": "This regulation establishes the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) as the central EU authority for direct and indirect supervision of high-risk obliged entities to prevent the use of the financial system for money laundering and terrorist financing, as mandated by Article 1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "fatf-guidance-virtual-assets-vasp",
      "za-fica-2001"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-aml-directive-2024-1640-amld6-fius-beneficial-ownership-supervision",
    "title": "Directive (EU) 2024/1640 (AMLD6) - Mechanisms for the Prevention of Money Laundering and Terrorist Financing: FIUs, Beneficial Ownership Registers, Supervision and Cooperation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "Directive (EU) 2024/1640 of the European Parliament and of the Council of 31 May 2024 - the Sixth Anti-Money Laundering Directive (AMLD6) - is the directive component of the 2024 EU AML/CFT package alongside Regulation (EU) 2024/1624 (the AML Regulation), Regulation (EU) 2024/1620 (the AMLA Regulation), and Regulation (EU) 2023/1113 (the Wire Transfer Regulation). Article 1 lays down rules concerning (a) the measures applicable to sectors exposed to money laundering and terrorist financing at national level, (b) the requirements in relation to registration of, identification of, and checks on, senior management and beneficial owners of obliged entities, (c) the identification of money laundering and terrorist financing risks at Union and Member State level, (d) the set-up of and access to beneficial ownership and bank account registers and access to real estate information, (e) the responsibilities and tasks of Financial Intelligence Units (FIUs), (f) the responsibilities and tasks of bodies involved in the supervision of obliged entities, and (g) cooperation between competent authorities and cooperation with authorities covered by other Union legal acts. Article 4 requires Member States to ensure currency exchange and cheque cashing offices and trust or company service providers are licensed or registered, and gambling service providers are regulated. Article 6 requires fitness-and-propriety checks on senior management and beneficial owners of certain obliged entities and empowers supervisors to require removal of those convicted of money laundering, predicate offences, or terrorist financing. Article 10 establishes central beneficial ownership registers in machine-readable format in the Member State where the legal entity is created or where the trustee is established. Article 11 grants competent authorities, AMLA, EPPO, OLAF, Europol, Eurojust, tax authorities and authorities for Union restrictive measures unfiltered, direct and free access to the interconnected central registers. Article 18 establishes a single access point for real estate information including cadastral parcel, geographical location, area, type, owner identification, and acquisition price. Article 19 establishes the FIU as the single central national unit responsible for receiving and analysing reports submitted under Regulation (EU) 2024/1624, requiring operational independence and autonomy. Article 56 empowers supervisors to apply administrative measures including recommendations, compliance orders, public statements, cease-and-desist orders, business restrictions, authorisation withdrawal, and governance-structure changes. Article 57 authorises periodic penalty payments not exceeding 3% of daily turnover for legal persons or 2% of daily income for natural persons. Article 78 sets the transposition deadline of 10 July 2027 for the general regime (Article 74 by 10 July 2025, Articles 11, 12, 13 and 15 by 10 July 2026, Article 18 by 10 July 2029). Article 79 sets entry into force on the twentieth day following publication in the Official Journal on 19 June 2024 (i.e., 9 July 2024). Article 77 repeals Directive (EU) 2015/849 with effect from 10 July 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "package_anchor",
        "subject_matter_anchor",
        "service_provider_licensing_anchor",
        "fit_and_proper_anchor",
        "beneficial_ownership_register_anchor",
        "real_estate_register_anchor",
        "fiu_anchor",
        "supervisory_enforcement_anchor",
        "transposition_repeal_anchor",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-regulation-2024-1624",
      "eu-aml-authority-amla-2024",
      "eu-wire-transfer-regulation-2023-1113",
      "eu-aml-6th-directive-2018-1673-criminal-liability-money-laundering",
      "fatf-40-recommendations-2023-consolidated"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "eu-aml-directive-5-gambling-sector",
    "title": "Directive (EU) 2018/843 of the European Parliament and of the Council of 30 May 2018 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (Fifth Anti-Money Laundering Directive) - Gambling Sector Provisions",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Directive requires gambling service providers to apply customer due diligence for transactions equal to or above EUR 2,000 (Article 31), adopt a risk‑based approach (Article 33), identify beneficial owners (Article 34), screen politically exposed persons (Article 35), and file suspicious activity reports (Article 36).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "fatf-guidance-rba-gambling-2021",
      "germany-state-gambling-treaty-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-aml-package-2021-regulation-proposal",
    "title": "Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This proposal establishes directly applicable EU-wide rules to prevent money laundering and terrorist financing, expanding obligations to crypto-asset service providers, crowdfunding platforms, and migration operators, with enhanced due diligence requirements based on risk levels as outlined in the proposal. It forms part of the EU AML/CFT single rulebook under Article 17-level customer due diligence measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "bahrain-cbb-rulebook-aml-cft-module",
      "eu-electricity-directive-2019-944",
      "accounting-ifr-13"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-aml-regulation-2024",
    "title": "Regulation (EU) 2024/1624 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This regulation establishes a unified, directly applicable Anti-Money Laundering and Counter-Financing of Terrorism (AML/CFT) rulebook for the EU, mandating obliged entities to conduct risk assessments, perform customer due diligence (CDD), and implement robust internal controls. As per Article 1, it harmonises rules across the Union to prevent the misuse of the financial system for ML/TF.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "fatf-guidance-virtual-assets-vasp",
      "psd2-sc-authentication",
      "mica-stablecoin-reserve"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-aml-regulation-2024-1624",
    "title": "EU Anti-Money Laundering Regulation (EU) 2024/1624",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Regulation 2024/1624 (the AML Regulation) is part of the EU AML/CFT package adopted 31 May 2024 alongside Directive 2024/1640 (AMLD6) and Regulation 2024/1620 (AMLA Regulation). The AML Regulation creates the first directly applicable EU-wide AML rulebook covering customer due diligence (CDD) beneficial ownership transparency suspicious activity reporting (SAR) cash payment limits (EUR 10,000 EU-wide threshold) sanctions screening and crypto-asset service providers. The Regulation applies from 10 July 2027 (with some provisions earlier). Member State competent authorities (FIUs) and the Anti-Money Laundering Authority (AMLA) established in Frankfurt enforce directly under the Regulation. The single rulebook reduces divergence in national AML implementation under prior Directives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "amla_reg",
        "amld6",
        "eu_4amld_5amld",
        "fatf_recs",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-aml-regulation-2024-crypto-assets",
    "title": "Regulation (EU) 2024/1624 on preventing the use of the financial system for the purposes of money laundering or terrorist financing, and amending Regulation (EU) No 909/2014, Directive (EU) 2015/849 and other related acts - Crypto-Asset Service Providers as Obliged Entities",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes that all Crypto-Asset Service Providers (CASPs) are obliged entities under EU AML rules, requiring Customer Due Diligence (CDD) on all transactions without de minimis thresholds (Article 17), Enhanced Due Diligence (EDD) for anonymous hosted wallets (Article 20), beneficial ownership transparency for legal persons holding crypto-assets (Article 24), and direct supervision by the Anti-Money Laundering Authority (AMLA) (Article 45).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "eu-dlt-pilot-regime-2022-858",
      "eu-cbdc-digital-euro-legislative-proposal-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-aml-regulation-2024-single-rulebook",
    "title": "Regulation (EU) 2024/1624 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes a directly applicable single rulebook for Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) across the EU, imposing harmonised Customer Due Diligence (CDD) measures (Article 16), a unified definition of beneficial ownership (Article 45), and a Union-wide limit of EUR 10,000 on large cash payments (Article 59) for all obliged entities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-authority-amla-2024",
      "fatf-travel-rule-v2",
      "fatf-guidance-virtual-assets-vasp",
      "oecd-crs-automatic-exchange"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-amla-regulation-2024-1620-anti-money-laundering-authority",
    "title": "EU Regulation 2024/1620 - Establishment of the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "Regulation (EU) 2024/1620 of the European Parliament and of the Council of 31 May 2024 establishes the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), the new central EU agency responsible for direct supervision of selected high-risk cross-border obliged entities and for indirect oversight of national supervisors. Published in the Official Journal of the European Union on 19 June 2024, the Regulation is the third pillar of the 2024 EU AML Package alongside Regulation 2024/1624 (AMLR, the directly applicable single rulebook) and Directive 2024/1640 (the 6AMLD-style framework for Member State institutional architecture). AMLA was established on 1 January 2026 with headquarters in Frankfurt am Main, Germany. AMLA's mandate has three operational layers: (1) direct supervision from 2028 over a list of approximately forty selected cross-border obliged entities chosen on risk and scale criteria under Article 12 (credit institutions, financial institutions and crypto-asset service providers with significant cross-border exposure), with joint supervisory teams operating in cooperation with national supervisors; (2) indirect oversight of national AML supervisors at all times under Articles 32-39, including peer reviews, breach response mechanisms and the power to require national supervisors to act; (3) coordination of the EU FIU network, hosting the secure FIU.net successor system and conducting supranational risk assessments. AMLA's governance comprises an Executive Board, a General Board (Member State authorities, ECB, EBA, ESMA, EIOPA), a Chair appointed by the Council, and an Executive Director. Funding is partly through the EU budget and partly through fees on directly supervised entities. AMLA's powers include on-site inspection, requesting information, conducting joint inspections, and imposing administrative pecuniary sanctions on directly supervised entities up to ten percent of annual worldwide turnover for serious breaches. The Regulation interlocks with the European Central Bank for credit institutions where AML failings affect prudential soundness, with the European Banking Authority for prudential AML standards, and with Europol and Eurojust for criminal-investigation cooperation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "package_relationship_anchor",
        "direct_supervision_anchor",
        "indirect_oversight_anchor",
        "fiu_coordination_anchor",
        "sanctions_powers_anchor",
        "industry_mapping",
        "ecb_interaction_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-regulation-2024-1624",
      "eu-aml-authority-amla-2024",
      "fatf-40-recommendations-2023-consolidated"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-amld6-directive-2024-1640-aml-cft-mechanisms",
    "title": "EU Directive 2024/1640 (AMLD6 2024) - Member State Mechanisms for AML/CFT Supervision, Beneficial Ownership Registers and Financial Intelligence Units",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "Directive (EU) 2024/1640 of the European Parliament and of the Council of 31 May 2024 on the mechanisms to be put in place by Member States for the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (commonly referenced as AMLD6 within the 2024 EU AML Package, though distinct from the criminal-law harmonisation Directive 2018/1673 historically labelled 6AMLD). Published in the Official Journal on 19 June 2024 (OJ L 19.6.2024); transposition deadline 10 July 2027 for most provisions; repeals Directive (EU) 2015/849 (4AMLD as amended by 5AMLD); amends Directive (EU) 2019/1937 (Whistleblowing Directive). Sits in the 2024 EU AML Package alongside Regulation (EU) 2024/1624 (AMLR, directly applicable single rulebook for obliged entities), Regulation (EU) 2024/1620 (establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, AMLA), and Regulation (EU) 2023/1113 (Recast Transfer of Funds Regulation). The Directive governs the Member State supervisory and institutional architecture, while AMLR governs the substantive obligations of obliged entities directly. Key obligations: Member States must establish a single AML/CFT supervisor or coordinate multiple supervisors (subject to AMLA's selection list for direct EU supervision of cross-border high-risk obliged entities); operate centralised beneficial ownership registers with FIU and competent authority access and limited public access tested against the Sovim CJEU jurisprudence; operate a Financial Intelligence Unit with operational independence, access to financial and law-enforcement databases, and cross-border information exchange via the FIU.net successor (AMLA-hosted from 2027); establish central bank account registers and real-estate registers accessible to FIUs and law-enforcement; conduct national risk assessments and supranational risk assessment coordinated with AMLA; impose minimum administrative pecuniary sanctions for breaches and provide whistleblower protection. The Directive is the supervisory and institutional backbone of the 2024 EU AML Package and the operational anchor that national supervisors will cite for their post-July 2027 mandate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "repealed_4amld_5amld_anchor",
        "amlr_substantive_obligations_relationship",
        "amla_supervision_architecture",
        "beneficial_ownership_register_post_sovim",
        "fiu_architecture",
        "central_registers_anchor",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-regulation-2024-1624",
      "eu-aml-authority-amla-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-animal-health-law-2016-429",
    "title": "EU Regulation 2016/429 on transmissible animal diseases, prevention and control, and traceability",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "This regulation establishes a comprehensive legal framework for the prevention and control of transmissible animal diseases across the European Union. It replaces numerous earlier acts with a single, simplified set of rules aimed at improving animal health, public health, and the internal market. Key provisions include the creation of a harmonised list of transmissible animal diseases; categorisation of diseases based on their profile, impact, and risk of spread; mandatory notification of suspect or confirmed outbreaks of listed diseases to competent authorities by operators; and the obligation for Member States to establish surveillance systems, eradication programmes (compulsory or optional), and contingency plans for disease emergencies. Operators and animal professionals bear primary responsibility for biosecurity and disease prevention. The regulation also covers the registration and approval of establishments, traceability of animals and products, and rules for movements within the Union. It recognises the role of veterinarians and aquatic animal health professionals. The European Commission is granted delegated powers to adopt additional rules on biosecurity, surveillance design, disease-free status criteria, vaccination restrictions, and the establishment of Union antigen and vaccine banks. The regulation applies to both terrestrial and aquatic animals, and to wild animals when they are potential victims or vectors of disease. Zoonoses are covered only where specific rules do not already exist in other Union acts. Antimicrobial resistance is treated as a transmissible disease for the purpose of allowing action against resistant organisms. Provisions on official controls and financing are explicitly excluded, being covered by separate regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-anti-coercion-instrument-2023-2675",
    "title": "Regulation (EU) 2023/2675 of the European Parliament and of the Council of 22 November 2023 on the protection of the Union and its Member States from economic coercion by third countries (Anti-Coercion Instrument)",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "The Anti-Coercion Instrument empowers the European Commission to examine, determine, and respond to economic coercion by third countries that apply or threaten trade or investment measures to pressure the Union or a Member State into a particular act. Where engagement under Articles 5 and 6 fails to end the coercion within a reasonable period, the Commission may adopt proportionate Union response measures under Article 8 drawn from Annex I, which must not exceed the level of injury to the Union under Article 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dual-use-regulation-2021-821",
      "wto-gatt-1994-general-agreement-tariffs-trade"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-anti-dumping-regulation-2016-1036",
    "title": "Regulation (EU) 2016/1036 of the European Parliament and of the Council of 8 June 2016 on protection against dumped imports from countries not members of the European Union",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation governs the imposition of anti-dumping duties on dumped imports into the EU that cause injury to the Union industry. A product is dumped where its export price to the Union is below the comparable normal value in the exporting country (Articles 1 and 2). Following a complaint and investigation under Articles 5 and 6, provisional duties may be imposed under Article 7 and definitive duties under Article 9, subject to the Union interest test and the lesser-duty rule, with measures expiring after five years absent an expiry review under Article 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wto-anti-dumping-agreement-1994",
      "eu-anti-subsidy-regulation-2016-1037"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-anti-slapp-directive-2024-1069",
    "title": "Directive (EU) 2024/1069 of the European Parliament and of the Council of 11 April 2024 on protecting persons who engage in public participation from manifestly unfounded claims or abusive court proceedings (Strategic lawsuits against public participation)",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive provides safeguards against manifestly unfounded claims or abusive court proceedings against public participation (SLAPPs) in civil matters with cross-border implications (Articles 1 and 2). It allows more favourable national provisions (Article 3), defines public participation and abusive proceedings (Article 4), sets criteria for cross-border implications (Article 5), and establishes procedural safeguards including applications for early dismissal, accelerated treatment, security for costs, award of costs against the claimant, and penalties or remedies against abusive litigation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-media-freedom-act-2024",
      "eu-presumption-of-innocence-directive-2016-343"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-anti-subsidy-regulation-2016-1037",
    "title": "Regulation (EU) 2016/1037 of the European Parliament and of the Council of 8 June 2016 on protection against subsidised imports from countries not members of the European Union",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation allows the EU to impose countervailing duties on subsidised imports that cause injury to the Union industry. A countervailable subsidy exists where there is a financial contribution by a government conferring a benefit that is specific to certain enterprises under Articles 3 and 4. Following a complaint and investigation, the subsidy amount is calculated per unit under Articles 5 to 7, injury is determined under Article 8, and provisional and definitive countervailing duties may be imposed subject to the Union interest test and a five-year expiry review.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wto-scm-agreement-1994",
      "eu-anti-dumping-regulation-2016-1036"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-anti-tax-avoidance-directive-atad-1-2016-1164",
    "title": "Council Directive (EU) 2016/1164 of 12 July 2016 laying down rules against tax avoidance practices that directly affect the functioning of the internal market (ATAD 1)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive requires EU Member States to implement anti-abuse rules including a 30% EBITDA-based interest limitation rule (Article 4), controlled foreign company (CFC) rules (Article 7), general anti-abuse rule (GAAR) (Article 6), exit taxation (Article 5), and anti-hybrid mismatch rules (Article 9). It applies to all corporate taxpayers and transparent entities within the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-arm-length-principle-article-9-oecd-model",
      "eu-atad2-hybrid-mismatches-2017-952",
      "eu-dac6-mandatory-disclosure-cross-border"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-anti-tax-avoidance-directive-atad-2016-1164",
    "title": "Council Directive (EU) 2016/1164 of 12 July 2016 laying down rules against tax avoidance practices that directly affect the functioning of the internal market (ATAD)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This directive establishes minimum standards for EU Member States to counter corporate tax avoidance by implementing five legally binding anti-abuse measures: an interest limitation rule (Article 4), exit taxation rules (Article 5), a general anti-abuse rule (GAAR) (Article 6), controlled foreign company (CFC) rules (Articles 7 & 8), and rules to tackle hybrid mismatches (Article 9). It applies to all taxpayers subject to corporate tax in one or more Member States, including permanent establishments of third-country entities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015",
      "un-model-double-taxation-convention-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-anti-tax-avoidance-directive-atad1-2016",
    "title": "Council Directive (EU) 2016/1164 of 12 July 2016 laying down rules against tax avoidance practices that directly affect the functioning of the internal market",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive establishes binding anti-abuse rules for all EU Member States, including an interest limitation rule (Article 4), controlled foreign company (CFC) rules (Article 7), a general anti-abuse rule (GAAR) (Article 6), exit taxation (Article 5), and hybrid mismatch rules (Article 9), applicable to all corporate taxpayers and transparent entities within the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-atad2-hybrid-mismatches-2017-952",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two",
      "eu-dac6-mandatory-disclosure-hallmarks-2020",
      "canada-transfer-pricing-income-tax-act-section-247",
      "australia-transfer-pricing-laws-amendment-2012"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-anti-tax-avoidance-directive-atad2-2017",
    "title": "Council Directive (EU) 2017/952 of 29 May 2017 amending Directive (EU) 2016/1164 as regards hybrid mismatches with third countries",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "ATAD2 introduces rules to neutralize tax advantages arising from hybrid mismatch arrangements involving third countries, including imported hybrid mismatches and reverse hybrids. It applies to multinational enterprises and cross-border groups using hybrid instruments or entities to generate double non-taxation or double deductions under Article 1(1) and Article 2(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-dac6-mandatory-disclosure-hallmarks-2020",
      "australia-transfer-pricing-laws-amendment-2012",
      "canada-transfer-pricing-income-tax-act-section-247"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-anti-torture-trade-regulation-2019-125",
    "title": "Regulation (EU) 2019/125 of the European Parliament and of the Council of 16 January 2019 concerning trade in certain goods which could be used for capital punishment, torture or other cruel, inhuman or degrading treatment or punishment",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation governs EU trade with third countries in goods that could be used for capital punishment, torture or other cruel, inhuman or degrading treatment. It absolutely prohibits the export, import, transit, brokering, training, trade-fair display and advertising of Annex II goods that have no use other than such treatment, and requires prior export authorisation for Annex III and Annex IV goods that have legitimate uses but a torture risk, with authorisation decisions taken against the criteria in Articles 12 and 17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dual-use-regulation-2021-821"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-antitrust-competition-law",
    "title": "EU Antitrust & Competition Law",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "EU Antitrust and Competition Law (based on Articles 101 and 102 of the TFEU) is the primary framework for ensuring fair competition within the EU's internal market. It prohibits cartels, anti-competitive agreements, and the abuse of a dominant position by major firms, with massive enforcement powers held by the European Commission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tfeu-article-102-abuse-of-dominance",
      "us-ftc-act-section-5-unfair-competition"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-antitrust-compliance-programme-best-practice",
    "title": "EU Commission Best Practice on Antitrust Compliance Programmes - Commitment of Senior Management, Risk Assessment, Training, Communication, Monitoring and Reporting for Competition Compliance",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation outlines best practices for EU antitrust compliance programmes, emphasizing senior management commitment, risk assessment, training, and reporting mechanisms to prevent violations of Article 101 and Article 102 of the Treaty on the Functioning of the European Union. It applies to all undertakings operating within EU markets subject to European antitrust rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "india-competition-act-2002-sections-3-4",
      "uk-competition-act-1998-chapter-1-2-prohibitions",
      "oecd-recommendation-hard-core-cartels-2019",
      "japan-antimonopoly-act-2019-amendment-jftc"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-antitrust-damages-directive-2014-104",
    "title": "Directive 2014/104/EU of the European Parliament and of the Council of 26 November 2014 on certain rules governing actions for damages under national law for infringements of the competition law provisions of the Member States and of the European Union",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes the right for any person or business who has suffered harm from an infringement of EU or national competition law to claim full compensation from the infringing undertaking (Article 3). It harmonizes rules across Member States concerning the disclosure of evidence, limitation periods, and the passing-on of overcharges to facilitate such private damages actions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-arm-length-principle-article-9-oecd-model",
    "title": "OECD Model Tax Convention Article 9 - Associated Enterprises and Arm's Length Principle: Conditions for Adjustment, Primary Adjustment, Corresponding Adjustment, Mutual Agreement Procedure and Secondary Adjustments",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation requires that transactions between associated enterprises be priced as if they were conducted between independent parties (arm’s length principle) under Article 9(1) of the OECD Model Tax Convention. It applies to multinational enterprises and tax authorities in determining appropriate transfer pricing for cross-border transactions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-transfer-pricing-directive-proposal-2023",
      "canada-transfer-pricing-income-tax-act-section-247",
      "india-advance-pricing-agreement-rules-2012",
      "australia-transfer-pricing-laws-amendment-2012"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-artificial-intelligence-act-2024-1689",
    "title": "EU Artificial Intelligence Act 2024/1689",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-08-01",
    "bluf": "Regulation (EU) 2024/1689, the EU AI Act, entered into force on 1 August 2024 and establishes a risk-based framework for AI systems: prohibited practices apply from 2 August 2024; GPAI model obligations from 2 August 2025; high-risk AI system requirements from 2 August 2026; with penalties up to EUR 35,000,000 or 7% of global annual turnover for prohibited practice violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-nis2-directive-2022-2555",
        "uk-data-protection-act-2018",
        "eu-corporate-sustainability-reporting-directive-2022-2464"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-directive-2022-2555",
      "uk-data-protection-act-2018",
      "eu-corporate-sustainability-reporting-directive-2022-2464"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-artificial-intelligence-act-high-risk-industrial",
    "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 August 2024 on Artificial Intelligence (Artificial Intelligence Act) and amending certain Union Legislative Acts",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes binding requirements for high-risk AI systems used in industrial contexts, including safety components of machinery, critical infrastructure, and workplace monitoring. Compliance is mandatory for providers, deployers, and importers of such systems under Annex III, with strict obligations on risk management, data governance, transparency, and human oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cyber-resilience-act-iot-2024-products",
      "eu-data-act-2023-iot-data-sharing-obligations",
      "eu-atex-directive-2014-34-explosive-atmosphere",
      "etsi-en-303-645-iot-cybersecurity-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-asbestos-workers-directive-2009-148",
    "title": "Directive 2009/148/EC of the European Parliament and of the Council of 30 November 2009 on the protection of workers from the risks related to exposure to asbestos at work",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes a binding occupational exposure limit value (OELV) for asbestos fibres and mandates that EU employers implement comprehensive risk assessment, prevention, and health surveillance measures for workers exposed or likely to be exposed to dust from asbestos or asbestos-containing materials, as detailed in Article 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-asset-recovery-confiscation-directive-2024-1260",
    "title": "Directive (EU) 2024/1260 of the European Parliament and of the Council of 24 April 2024 on asset recovery and confiscation and amending Directive 2014/42/EU",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-07-22",
    "bluf": "This Directive requires EU Member States to establish harmonized rules for tracing, freezing, managing, and confiscating property derived from criminal activities. It mandates the establishment of Asset Recovery Offices (AROs) and Asset Management Offices (AMOs) and introduces stronger powers for extended confiscation (Article 10) and non-conviction-based confiscation (Article 12) to combat organized crime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-antitrust-competition-law",
      "iso-37001-anti-bribery-2016"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-atad-anti-tax-avoidance-2016",
    "title": "EU Anti-Tax Avoidance Directives - ATAD1 (Council Directive (EU) 2016/1164) and ATAD2 (Council Directive (EU) 2017/952)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The EU Anti-Tax Avoidance Directive 1 (ATAD1), adopted by the Council of the European Union on 12 July 2016 as Council Directive (EU) 2016/1164, establishes a minimum standard of anti-avoidance measures across all EU member states, with a transposition deadline of 31 December 2018 (extended to 31 December 2019 for the interest limitation rule where pre-existing national rules are equally effective). ATAD1 was amended by ATAD2 - Council Directive (EU) 2017/952, adopted 29 May 2017 - to address hybrid mismatches involving third-country jurisdictions; ATAD2 transposition deadline: 31 December 2019 (with 31 December 2021 for reverse hybrid rules). ATAD1 and ATAD2 together impose five categories of binding anti-avoidance rules on all EU member states: (1) Interest limitation rule (Art. 4): net borrowing costs are deductible only up to 30% of earnings before interest, taxes, depreciation and amortisation (EBITDA) for tax purposes; EUR 3 million de minimis threshold per standalone entity or group; standalone entities and entities not part of a consolidated group for accounting purposes may benefit from an equity escape clause; legacy debt grandfathering and long-term infrastructure project carve-outs available at member state election; aligns with OECD BEPS Action 4. (2) Exit taxation rule (Art. 5): member states must levy tax on unrealised capital gains when a taxpayer transfers assets, business, or tax residence outside the implementing state; 5-year instalment payment option for intra-EU and intra-EEA transfers to preserve free movement of capital; applies to assets transferred to a permanent establishment outside the member state, transfers of residence to another member state (with PE retained), and transfers from headquarters to PE outside the member state. (3) General Anti-Abuse Rule (GAAR, Art. 6): member states must disregard arrangements (or series thereof) that are not genuine - i.e., not put in place for valid commercial reasons reflecting economic reality - and whose main purpose (or one of the main purposes) is obtaining a tax advantage that defeats the object or purpose of applicable tax law; 'not genuine' is assessed by reference to whether the arrangement would have been entered into absent the tax advantage. (4) Controlled Foreign Company (CFC) rules (Arts. 7-8): profits of low-taxed foreign subsidiaries are allocated to EU parent; a CFC is an entity over which the taxpayer holds (directly or indirectly) >50% voting rights, capital, or entitlement to profits; low-tax test: CFC's actual tax paid is less than 50% of the tax that would have been charged under the member state's rules; member states may choose Approach A (include specific categories of passive income) or Approach B (include non-distributed non-genuine arrangements income); financial and trading companies with substantial economic activity may be excluded. (5) Hybrid mismatch rules (Arts. 9-9b, as amended and extended by ATAD2): member states must counteract hybrid mismatches arising from differences in characterisation of financial instruments or entities between jurisdictions that produce double deduction (DD) or deduction without inclusion (D/NI) outcomes; ATAD2 extended the rules to cover third-country hybrids, reverse hybrids, imported mismatches, and dual-resident situations. The European Commission has published an implementation report assessing member state transposition fidelity. As of April 2026, all EU member states have transposed ATAD1 and ATAD2 into national law, though implementation choices (particularly on CFC approach and interest limitation safe harbours) vary. The Pillar Two Directive (EU) 2022/2523 operates alongside ATAD - ATAD CFC inclusions may affect a group's GloBE income and covered taxes for Pillar Two purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-cbcr-guidance-2023-update",
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-atad1-directive-2016-1164",
    "title": "Council Directive (EU) 2016/1164 of 12 July 2016 laying down rules against tax avoidance practices that directly affect the functioning of the internal market (ATAD1)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes minimum standards for EU Member States to counter corporate tax avoidance by implementing five legally binding anti-abuse measures: an interest limitation rule (Article 4), exit taxation (Article 5), a general anti-abuse rule (GAAR) (Article 6), controlled foreign company (CFC) rules (Articles 7 & 8), and rules on hybrid mismatches (Article 9). It applies to all taxpayers subject to corporate tax in one or more Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-atad2-directive-2017-952-hybrids",
    "title": "Council Directive (EU) 2017/952 of 29 May 2017 amending Directive (EU) 2016/1164 as regards hybrid mismatches with third countries",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive (ATAD2) extends the EU's anti-tax avoidance rules to neutralize hybrid mismatch arrangements involving non-EU countries (third countries). It requires EU Member States to deny tax deductions for payments or include payments in taxable income where mismatches in the tax treatment of an entity or financial instrument lead to double deductions or deductions without inclusion, as specified in Article 9 and 9a.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-atad2-hybrid-mismatches-2017-952",
    "title": "Council Directive (EU) 2017/952 of 29 May 2017 amending Directive (EU) 2016/1164 as regards hybrid mismatches with third countries",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This directive amends the EU's Anti-Tax Avoidance Directive (ATAD) to neutralize tax mismatches arising from hybrid arrangements involving third countries. It requires EU Member States to deny a deduction for a payment or include the payment in the taxpayer's income to prevent double non-taxation or deduction/no inclusion outcomes, as mandated by Article 9a.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-atex-directive-2014-34",
    "title": "EU ATEX Equipment Directive 2014/34/EU",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2014-04-09",
    "bluf": "Directive 2014/34/EU governs the placing on the market of equipment and protective systems intended for use in potentially explosive atmospheres (ATEX), requiring conformity assessment by a notified body for Equipment Group II Category 1 and Category 2 products, CE marking, and the Ex marking system indicating zone suitability, with the complementary ATEX Workplace Directive 1999/92/EC governing employer obligations at hazardous sites.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-machinery-directive-2006-42",
        "eu-nis2-directive-2022-2555",
        "eu-ecodesign-sustainable-products-regulation-2024-1781"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-machinery-directive-2006-42",
      "eu-nis2-directive-2022-2555",
      "eu-ecodesign-sustainable-products-regulation-2024-1781"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-atex-directive-2014-34-explosive-atmosphere",
    "title": "Directive 2014/34/EU of the European Parliament and of the Council of 26 February 2014 on the harmonisation of the laws of the Member States relating to equipment and protective systems intended for use in potentially explosive atmospheres",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The EU ATEX Directive 2014/34/EU mandates that all equipment and protective systems intended for use in potentially explosive atmospheres must meet essential health and safety requirements (EHSRs) before being placed on the market or put into service, with classification into Equipment Groups (I for mining, II for surface industries) and Categories (1, 2, 3) based on zone risk level. Compliance is required under Article 5 and involves conformity assessment procedures defined in Annexes II to XI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-4-2-component-security-2019",
      "iec-62443-industrial-automation-security-standards",
      "isa-99-iec-62443-industrial-security-framework",
      "iso-14001-2015-environmental-management-industrial",
      "iso-55001-2014-asset-management-industrial"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-atmp-regulation-1394-2007",
    "title": "Regulation (EC) No 1394/2007 of the European Parliament and of the Council of 13 November 2007 on Advanced Therapy Medicinal Products and amending Directive 2001/83/EC and Regulation (EC) No 726/2004",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes a centralized authorization procedure for advanced therapy medicinal products (ATMPs), including gene therapy, somatic cell therapy, and tissue-engineered products, within the European Union. It applies to manufacturers, sponsors, and marketing authorization holders of ATMPs under Article 8 and requires compliance with specific quality, safety, and efficacy standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-qms",
      "ich-gcp-e6-r3-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-atmp-regulation-1394-2007-advanced-therapies",
    "title": "Commission Regulation (EC) No 1394/2007 of 13 November 2007 on Advanced Therapy Medicinal Products",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires manufacturers of advanced therapy medicinal products, including gene therapy, somatic cell therapy, and tissue-engineered products, to comply with the centralised authorisation procedure as outlined in Article 3. Citing Article 3 of Regulation 1394/2007, all such products must be authorised by the European Commission before being placed on the market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-qms",
      "ich-gcp-e6-r3-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-atmp-regulation-1394-pharma-gene-cell",
    "title": "Regulation (EC) No 1394/2007 of the European Parliament and of the Council of 13 November 2007 on Advanced Therapy Medicinal Products and Amending Directive 2001/83/EC and Regulation (EC) No 726/2004",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes a centralized authorization pathway for advanced therapy medicinal products (ATMPs), including gene therapy, somatic cell therapy, and tissue-engineered products, within the EU. It mandates compliance with specific quality, safety, and efficacy standards under Article 8 and requires risk management plans and post-authorization safety studies (PASS) under Article 14.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gmp-annex-1-sterile-manufacture-2022",
      "ich-q10-pharmaceutical-quality-system-2008",
      "fda-21-cfr-part-600-601-biologics-licensing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-audiovisual-media-services-directive-2018-1808",
    "title": "Directive (EU) 2018/1808 of the European Parliament and of the Council of 14 November 2018 amending Directive 2010/13/EU on the coordination of certain provisions laid down by law, regulation or administrative action in Member States concerning the provision of audiovisual media services (Audiovisual Media Services Directive)",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The EU Audiovisual Media Services Directive 2018/1808 imposes obligations on video-on-demand (VOD) providers and video sharing platforms (VSPs) to protect minors from harmful content, ensure transparency in advertising, promote European works through a 30% quota on VOD platforms, guarantee prominence for European productions, and clarify jurisdiction rules for satellite broadcasters. Key obligations are established under Articles 1, 3, 8a, 18, and 20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "berne-convention-1886-2024-literary-artistic-works",
      "dmca-safe-harbor",
      "eu-sports-data-rights-framework-media-2024",
      "iptc-photo-metadata"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-audiovisual-media-services-loot-boxes-2018",
    "title": "Directive (EU) 2018/1808 of the European Parliament and of the Council of 14 November 2018 amending Directive 2010/13/EU on the coordination of certain provisions laid down by law, regulation or administrative action in Member States concerning the provision of audiovisual media services (Audiovisual Media Services Directive)",
    "domain": "Gaming & Gambling",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The amendment requires video‑sharing platform services that provide programmes or user‑generated videos as an essential functionality to be subject to the Audiovisual Media Services Directive, including obligations to maintain provider records and protect minors (see Paragraph (5)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "india-meity-online-gaming-rules-2023",
      "belgium-gambling-act-1999-online-amendments"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-aviation-occurrence-reporting-regulation-376-2014",
    "title": "Regulation (EU) No 376/2014 of the European Parliament and of the Council of 3 April 2014 on the reporting, analysis and follow-up of occurrences in civil aviation",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation improves aviation safety by ensuring that relevant safety information relating to civil aviation occurrences is reported, collected, stored, protected, exchanged, analysed and followed up (Articles 1 and 3). It requires mandatory reporting of occurrences that may represent a significant risk (Article 4) and voluntary reporting systems (Article 5), with collection and storage by organisations and authorities (Article 6), quality and content requirements for reports (Article 7), storage in the European Central Repository (Article 8), and a just-culture approach protecting reporters from penalties save in cases of gross negligence or wilful misconduct.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-easa-basic-regulation-2018-1139-common-rules-civil-aviation",
      "easa-part-145-maintenance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-avmsd-2018-1808-article-6a-minors-protection",
    "title": "Directive (EU) 2018/1808 Article 6a - Protection of Minors from Harmful Audiovisual Content",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "Article 6a of the amended Audiovisual Media Services Directive (Directive 2010/13/EU as amended by Directive (EU) 2018/1808) requires EU Member States to ensure audiovisual media services that may impair the physical, mental or moral development of minors are restricted via scheduling, age verification tools or other technical measures; prohibits processing of minors' personal data collected under such measures for commercial purposes including direct marketing, profiling and behaviourally targeted advertising; requires sufficient viewer information about potentially harmful content; and encourages Commission-led co-regulatory codes of conduct.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "parent_directive_overlap",
        "vsp_overlap_article_28b",
        "gdpr_article_8_overlap",
        "industry_mapping",
        "enforcement_anchors",
        "co_regulation_anchor"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-audiovisual-media-services-directive-2018-1808"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-avmsd-article-28a-28b-video-sharing-platform-minors-protection",
    "title": "EU AVMSD Articles 28a and 28b Video-Sharing Platform Obligations (2018/1808 Amendments to 2010/13/EU) - Jurisdiction, Protection of Minors, Age Verification, Parental Control, Rating, Flagging, Media Literacy, Children's Personal Data Restriction",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Articles 28a and 28b of the EU Audiovisual Media Services Directive (AVMSD) - inserted by Directive (EU) 2018/1808 amending Directive 2010/13/EU and published in Official Journal L 303 of 28 November 2018 - establish the EU regulatory regime for video-sharing platforms (VSPs). Article 28a sets the jurisdictional test allocating each VSP to a single Member State based on establishment or parent/subsidiary location. Article 28b sets the substantive duty on VSP providers to take appropriate measures to protect (i) minors from content which may impair their physical, mental, or moral development; (ii) the general public from content containing incitement to violence or hatred and from public provocation to commit a terrorist offence, child sexual abuse material, and racist or xenophobic offences; (iii) the general public from audiovisual commercial communications that do not comply with the AVMSD advertising rules. Article 28b(3) lists ten measures VSP providers must consider implementing where appropriate to the size and nature of the service: (a) including in terms and conditions the prohibition of uploading the content categories listed in Article 28b(1); (b) including in terms and conditions the requirements on audiovisual commercial communications that are not marketed, sold, or arranged by the provider; (c) functionality for users to declare whether videos contain audiovisual commercial communications; (d) transparent and user-friendly mechanisms for users to flag or report content; (e) systems to assess the responses by VSP providers to user reports; (f) age verification systems for users of VSPs with content which may impair physical, mental, or moral development of minors; (g) easy-to-use systems allowing users to rate content; (h) parental control systems controlled by the end-user with respect to content which may impair the physical, mental, or moral development of minors; (i) transparent, easy-to-use and effective procedures for the handling and resolution of users' complaints; (j) effective media literacy measures and tools and user awareness about them. Article 28b(3) explicitly prohibits the personal data of minors collected or otherwise generated by VSP providers pursuant to the protective measures from being processed for commercial purposes such as direct marketing, profiling, and behaviourally targeted advertising. Implementation deadline for Member State transposition was 19 September 2020. The AVMSD operates alongside the Digital Services Act and the UK Online Safety Act in countries that subsequently left the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "article_28a_jurisdiction",
        "article_28b_substantive_duties",
        "article_28b_3_measures_list",
        "article_28b_proportionality",
        "article_28b_children_data_restriction",
        "article_28b_co_regulation_and_self_regulation",
        "transposition_deadline",
        "relationship_with_dsa_and_uk_osa",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-avmsd-2018-1808-article-6a-minors-protection",
      "eu-dsa-article-28-online-protection-of-minors",
      "uk-ofcom-highly-effective-age-assurance-guidance-2025-osa-part-5",
      "ie-online-safety-and-media-regulation-act-2022",
      "fr-loi-sren-2024-449-age-verification-pornography"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-avmsd-article-28b-video-sharing-platform-obligations",
    "title": "EU Audiovisual Media Services Directive Article 28b - Video-Sharing Platform Obligations to Protect Minors and the Public",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Article 28b of Directive 2010/13/EU (as inserted by Directive (EU) 2018/1808) requires Member States to ensure that video-sharing platform providers under their jurisdiction take appropriate measures to protect minors from content harmful to their physical, mental or moral development; protect the general public from incitement to violence or hatred and from criminal content (terrorism offences, child sexual abuse material, racism and xenophobia); and ensure compliance with audiovisual commercial communications standards. Measures must be proportionate to the size of the service and listed in Article 28b(3) including age verification, parental controls, reporting/flagging mechanisms, and transparency systems. Co-regulation and Member State stricter measures are permitted.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "article_28b_1_three_protective_obligations",
        "article_28b_2_proportionate_measures",
        "article_28b_3_ten_categories_of_appropriate_measures",
        "no_general_monitoring_obligation_subparagraph",
        "article_28b_4_co_regulation_encouraged",
        "article_28b_5_self_assessment_and_member_state_assessment",
        "article_28b_6_stricter_national_measures_permitted",
        "article_28b_7_court_access",
        "article_28b_10_union_level_codes_of_conduct",
        "transposition_deadline_19_september_2020",
        "interaction_with_digital_services_act_lex_specialis"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dsa-article-28-online-protection-of-minors"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-bank-recovery-resolution-directive-2014-59",
    "title": "EU Bank Recovery and Resolution Directive 2014/59 -- Bail-In, MREL, and Resolution Planning",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Directive 2014/59/EU (BRRD) establishes the EU framework for the recovery and resolution of credit institutions and investment firms. Institutions must prepare recovery plans with indicators and options for restoring viability (Articles 5-9), and resolution authorities prepare resolution plans including preferred resolution strategy and Minimum Requirement for Own Funds and Eligible Liabilities (MREL) targets (Articles 10-14 and 45). MREL is set institution-by-institution by the resolution authority; for Global Systemically Important Institutions (G-SIIs), the FSB Total Loss Absorbing Capacity (TLAC) standard requires 18 percent of Risk Weighted Assets (RWA) or 6.75 percent of total exposures by 1 January 2022 as implemented by BRRD2 Directive 2019/879. The four resolution tools are: sale of business (Article 38), bridge institution (Article 40), asset separation (Article 42), and bail-in (Articles 43-55). Bail-in allows the resolution authority to write down or convert eligible liabilities into equity; excluded liabilities include covered deposits (up to EUR 100,000 per depositor per institution), secured liabilities, short-term interbank claims of less than 7 days, employee wages due, and client assets. Before public funds from the Single Resolution Fund (SRF) can be used, losses equivalent to at least 8 percent of total liabilities including own funds must be absorbed by shareholders and eligible liability holders (Article 44(5)). The Single Resolution Board (SRB) under Regulation (EU) 806/2014 is the resolution authority for Eurozone significant institutions. The BRRD2 Directive 2019/879 enhanced MREL subordination requirements and introduced moratoria powers for resolution authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-regulation-2013-575",
      "eu-payment-services-directive-2-2015-2366"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-bathing-water-directive-2006-7-ec",
    "title": "EU Bathing Water Directive 2006/7/EC concerning management of bathing water quality and classification",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "This Directive lays down provisions for the monitoring, classification, management, and public information concerning bathing water quality across EU Member States. It applies to any surface water element where a competent authority expects a large number of people to bathe and has not imposed a permanent bathing prohibition or permanent advice against bathing. The Directive does not apply to swimming pools, spa pools, confined waters subject to treatment or used for therapeutic purposes, or artificially created confined waters separated from surface water and groundwater. Member States must annually identify all bathing waters and define the length of the bathing season, doing so for the first time before the start of the first bathing season after 24 March 2008. Monitoring of the parameters intestinal enterococci and Escherichia coli must take place in accordance with Annex IV, using reference methods specified in Annex I. Bathing water quality assessments are carried out after each bathing season based on data from that season and the three preceding seasons, comprising at least 16 samples (or 12 samples under special circumstances). After assessment, bathing waters are classified as poor, sufficient, good, or excellent according to criteria in Annex II. The first classification under this Directive must be completed by the end of the 2015 bathing season, and by that time all bathing waters must be at least sufficient. Bathing water profiles must be established by 24 March 2011 in accordance with Annex III. Member States must ensure timely management measures during unexpected situations, including information to the public and temporary bathing prohibitions. Cyanobacterial risks and other parameters such as macro-algae and waste pollution must be managed with appropriate monitoring and public alerts. Public participation must be encouraged, and the public must receive actively disseminated information via signs and the Internet, starting from the fifth bathing season after 24 March 2008. Member States report monitoring results and quality assessments annually to the Commission by 31 December. The Commission publishes an annual summary report on bathing water quality by 30 April each year. A review of the Directive is scheduled no later than 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-bathing-water-directive-2006-7-ec-recreational-quality",
    "title": "EU Bathing Water Directive 2006/7/EC - Bathing Water Classification, Management Measures and Public Information",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "Directive 2006/7/EC of the European Parliament and of the Council concerning the management of bathing water quality (revised Bathing Water Directive, BWD) replaced the original 1976 Directive 76/160/EEC with risk-based management of identified bathing waters across the EU. Member States identify bathing waters where many bathers are expected and the activity is not prohibited or permanently advised against under Article 3. Monitoring of two microbiological parameters - intestinal enterococci and Escherichia coli - drives a four-band classification (Excellent, Good, Sufficient, Poor) under Article 5 calculated over four consecutive bathing seasons. Bathing waters classified as Poor for five consecutive seasons trigger a permanent prohibition on bathing under Article 5(4). Article 6 requires Bathing Water Profiles describing physical and chemical characteristics, identifying pollution sources and risks of short-term pollution and cyanobacterial proliferation. Article 12 mandates real-time public information including the European bathing water symbols set out in Commission Implementing Decision 2011/321/EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-water-framework-directive-2000-60-ec",
      "eu-urban-wastewater-treatment-directive-91-271"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-batteries-amendment-2025-1561-due-diligence-postponement",
    "title": "Regulation (EU) 2025/1561 of the European Parliament and of the Council of 18 July 2025 amending Regulation (EU) 2023/1542 as regards obligations of economic operators concerning battery due diligence policies",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "This Regulation postpones the EU Batteries Regulation due diligence obligations on economic operators by two years, replacing the application date of 18 August 2025 with 18 August 2027 and moving the Commission guidelines deadline to 26 July 2026, to give battery manufacturers and raw-material supply chains time to adjust and to allow notification of conformity assessment bodies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-batteries-regulation-2023-1542",
      "eu-batteries-regulation-2023-1542-article-52-supply-chain-due-diligence",
      "oecd-due-diligence-minerals-supply-chains-2016"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-batteries-regulation-2023",
    "title": "Regulation (EU) 2023/1542 of the European Parliament and of the Council of 12 July 2023 concerning batteries and waste batteries, amending Directive 2008/98/EC and Regulation (EU) 2019/1020 and repealing Directive 2006/66/EC",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes a comprehensive lifecycle framework for all batteries placed on the EU market, mandating sustainability, safety, labelling, and end-of-life management. It requires economic operators to conduct supply chain due diligence for raw materials (Article 48), provide a carbon footprint declaration (Article 7), and implement a Digital Battery Passport for LMT, industrial, and EV batteries (Article 77).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-espr-ecodesign",
      "oecd-mineral-supply",
      "reach-chemical-comp",
      "weee-electronic-waste"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-batteries-regulation-2023-1542",
    "title": "EU Batteries Regulation 2023/1542",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2023-08-17",
    "bluf": "Regulation (EU) 2023/1542, in force from 17 August 2023 and replacing Directive 2006/66/EC, establishes the lifecycle framework for batteries placed on the EU market including mandatory carbon footprint declarations for industrial and EV batteries, a battery passport (phased from 2027), recycled content targets, end-of-life collection and recycling requirements, and supply chain due diligence for cobalt, natural graphite, lithium, and natural rubber.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-ecodesign-sustainable-products-regulation-2024-1781",
        "eu-corporate-sustainability-reporting-directive-2022-2464",
        "eu-corporate-sustainability-due-diligence-directive-2024-1760"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecodesign-sustainable-products-regulation-2024-1781",
      "eu-corporate-sustainability-reporting-directive-2022-2464",
      "eu-corporate-sustainability-due-diligence-directive-2024-1760"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-batteries-regulation-2023-1542-article-52-supply-chain-due-diligence",
    "title": "EU Batteries Regulation 2023/1542 Article 52 - Supply Chain Due Diligence for Cobalt, Nickel, Lithium, and Natural Graphite in Industrial, EV, and LMT Batteries",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 52 of the EU Batteries Regulation 2023/1542 requires economic operators placing industrial batteries, electric vehicle batteries, and light means of transport batteries on the EU market to implement supply chain due diligence policies covering cobalt, natural graphite, lithium, and nickel - including recycled content of these materials. Due diligence must follow the OECD Due Diligence Guidance for Responsible Business Conduct and cover environmental and social risks across the entire upstream supply chain from mining through processing. Operators must conduct third-party audits, report annually on supply chain due diligence, and register in the Battery Passport system. Non-compliance may trigger market withdrawal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-conflict-minerals-regulation-2017-821",
      "ilo-safety-health-mines-convention-c176-1995"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-batteries-regulation-2023-1542-ev",
    "title": "Regulation (EU) 2023/1542 on Batteries and Waste Batteries, Repealing Directive 2006/66/EC and Amending Regulations (EU) No 2019/1020 and (EU) 2019/944 - Sustainability and Environmental Compliance for Electric Vehicle Batteries",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation imposes mandatory carbon footprint declaration, due diligence for critical raw materials, battery passport with digital product record, state-of-health reporting, second-life assessment, and end-of-life recycling obligations on all manufacturers, importers, and distributors placing electric vehicle batteries on the EU market. Key requirements are established in Articles 6, 27, 40, 45, and 62.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "eu-digital-education-action-plan-2021-2027-deap"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-batteries-regulation-2023-1542-ev-batteries",
    "title": "Regulation (EU) 2023/1542 on Batteries and Waste Batteries, Amending Regulations (EU) 2019/1020 and (EU) 2018/848, and Repealing Directive 2006/66/EC",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation imposes mandatory carbon footprint declaration and performance class rating for electric vehicle (EV) batteries placed on the EU market from 2027, requires minimum recycled content of lithium, cobalt, nickel, and lead by 2031, mandates a digital Battery Passport for EV and industrial batteries, and establishes extended producer responsibility for collection and recycling. Key obligations are defined in Articles 6, 40, 41, 42, and 68.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-batteries-regulation-2023-1542-iot-storage",
    "title": "Regulation (EU) 2023/1542 on Batteries and Waste Batteries, Amending Regulations (EU) 2019/1020 and (EU) 2018/848, and Repealing Directive 2006/66/EC - Industrial and Energy Storage Batteries: Carbon Footprint, Recycled Content, Performance and Durability, Due Diligence and Battery Passport for IoT Energy Storage",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation imposes mandatory carbon footprint declarations, recycled content thresholds, performance and durability requirements, supply chain due diligence, and digital Battery Passport obligations for industrial and energy storage batteries placed on the EU market, including those used in IoT energy storage systems. Key obligations are established under Articles 6, 27, 28, 29, and 30.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-4-2-component-security-2019",
      "iso-14001-2015-environmental-management-industrial",
      "iso-55001-2014-asset-management-industrial",
      "etsi-en-303-645-iot-cybersecurity-2020",
      "iec-62351-power-systems-cybersecurity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-batteries-regulation-2023-1542-recycled-content-labelling",
    "title": "EU Batteries Regulation 2023/1542 - Lifecycle Requirements, Battery Passport, and Recycled Content Mandates",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Regulation (EU) 2023/1542 establishes end-to-end lifecycle requirements for all batteries placed on the EU market - covering carbon footprint, recycled content thresholds, a mandatory battery passport (from 2027), collection and recycling targets, and extended producer responsibility. Non-compliant batteries cannot bear CE marking or be placed on the market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852",
      "eu-critical-raw-materials-act-2024-1252"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-battery-passport",
    "title": "EU Digital Battery Passport",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with Regulation (EU) 2023/1542 mandates the creation of a unique Digital Battery Passport for specific battery categories placed on the market. This requirement applies if a product is an industrial, electric vehicle, or light means of transport (LMT) battery where `is_industrial_ev_or_lmt_battery` is true, and its capacity meets the `battery_capacity_kwh_min` of 2 kWh. Article 77 stipulates that each passport must be accessible through a `qr_code_permanently_affixed` to the unit, as detailed under labeling rules in Article 13. Economic operators are obligated to ensure `carbon_footprint_calculated_and_declared` information is available, fulfilling Article 7 provisions, while `recycled_content_percentages_documented` must align with directives from Article 8. Furthermore, a `supply_chain_due_diligence_active` policy is essential for responsible sourcing verification. The passport’s technical design and operation, governed by Article 78, demand a secure, interoperable system where `decentralized_data_registry_compliant` architecture is paramount. For operational transparency, `state_of_health_and_durability_metrics_live` data must be maintained and accessible. To protect sensitive information, robust `role_based_access_controls_implemented` are required, granting differential permissions to end-users, economic operators, and authorities. Crucially, the system architecture must embody data protection by design and default, enforcing principles like `gdpr_data_minimization_enforced` per Article 25 of Regulation (EU) 2016/679. Finally, comprehensive `end_of_life_dismantling_instructions_present` supports circular economy objectives by facilitating safe removal and recycling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-espr-ecodesign",
      "reach-chemical-comp",
      "rohs-hazardous-sub",
      "weee-electronic-waste",
      "oecd-mineral-supply"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-battery-regulation-2023-1542-ev",
    "title": "Regulation (EU) 2023/1542 of the European Parliament and of the Council of 12 July 2023 concerning batteries and waste batteries, amending Directive 2008/98/EC and Regulation (EU) 2019/1020 and repealing Directive 2006/66/EC",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires economic operators placing electric vehicle (EV) batteries on the EU market to establish supply chain due diligence policies (Article 48), declare a carbon footprint for each battery model (Article 7), meet minimum recycled content targets (Article 8), and provide a digital 'Battery Passport' (Article 77) accessible via a QR code.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "logistics-carbon-glec"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-befit-business-in-europe-framework-2023",
    "title": "Proposal for a Council Directive on Business in Europe: Framework for Income Taxation (BEFIT)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2024-09-12",
    "bluf": "The BEFIT directive proposes a common framework for EU-based multinational groups with annual combined revenues exceeding €750 million to calculate a single taxable base, replacing diverse national rules. As outlined in Chapter VII, this aggregated tax base is then allocated among Member States using a transitional formula based on the average taxable results of the three preceding fiscal years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015",
      "un-model-double-taxation-convention-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-benchmark-regulation-2016-1011",
    "title": "EU Benchmarks Regulation (BMR) 2016/1011 - EURIBOR, IBOR Transition, Critical Benchmark Framework",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2016/1011 (BMR) governs the provision of, contribution to, and use of financial benchmarks in the EU. Critical benchmarks (EURIBOR, formerly LIBOR) require NCA authorisation of the administrator. Three-tier classification: Critical (systemic risk - administrator authorised by home NCA, mandatory contribution if NCA orders); Significant (≥EUR 500M reference value); Non-significant. EONIA ceased 3 January 2022, replaced by €STR (Euro Short-Term Rate published by ECB). USD LIBOR ceased 30 June 2023 (synthetic panels to September 2024). Article 28 mandates fallback clauses in all contracts referencing benchmarks designated as critical or likely to cease. Article 29 restricts use of non-authorised third-country benchmarks by EU supervised entities. ESMA maintains a public register of authorised and equivalent benchmarks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EMIR_derivatives",
        "MiFID_II_best_execution",
        "MAR_benchmark_manipulation",
        "IOSCO_principles",
        "AIFMD_benchmark_use",
        "UCITS_benchmark_use"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-emir-refit-2019-834-derivatives-reporting",
      "eu-market-abuse-regulation-596-2014",
      "eu-aifmd-directive-2011-61"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-benchmarks-regulation-bmr-2016-1011",
    "title": "EU Benchmarks Regulation 2016/1011 (BMR) - Index Administration and IBOR Reform",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "EU Regulation 2016/1011 (BMR) establishes the regulatory framework for benchmark administrators and users in the EU. It requires administrators of critical benchmarks (EURIBOR, ESTR, SONIA) and significant benchmarks to be authorised or registered with their national competent authority and ESMA. Users of benchmarks in financial contracts and instruments must only use BMR-compliant benchmarks. BMR also governs the IBOR transition: Art 23a-23c empower ESMA to mandate a statutory replacement rate for a critical benchmark in cessation (Article 23a) or non-representativeness (Article 23b). Third-country benchmark recognition, equivalence, and endorsement provisions allow EU firms to use foreign benchmarks subject to ESMA assessment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-emir-regulation-648-2012",
      "eu-market-abuse-regulation-596-2014",
      "eu-capital-requirements-directive-iv-2013-36-crd4"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-better-internet-for-kids-strategy-bik-plus-2022",
    "title": "EU Better Internet for Kids+ (BIK+) Strategy 2022 - COM(2022) 212 final",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The EU Better Internet for Kids+ (BIK+) Strategy was adopted by the European Commission on 11 May 2022 as Communication COM(2022) 212 final. BIK+ updates the original 2012 BIK Strategy and structures EU child-online-safety policy around three pillars: (1) safe digital experiences to protect children from harmful and illegal online content conduct contact and consumer risks; (2) digital empowerment so children acquire the skills and competences to make sound choices and express themselves safely online; and (3) active participation so children have a say in the digital environment via child-led activities. Pillar 1 commitments include facilitation of an EU code of conduct on age-appropriate design by 2024 a standardisation request for a European age-verification standard from 2023 EU-wide digital proof of age based on date of birth from 2024 the 116 111 cyberbullying harmonised number support for Safer Internet Centres helplines and hotlines as trusted flaggers and neuro-marketing research mapping. Pillar 2 funds media literacy via BIK Portal MOOCs national-curricula best-practice exchange and tools for vulnerable children. Pillar 3 involves children in code-of-conduct creation expands BIK Youth Ambassadors and BIK Youth Panels and commits to child-led evaluations of BIK+ every two years. BIK+ is non-binding policy but anchors EU funding programmes Member State implementation expectations and downstream binding instruments including DSA Article 28 and the EU age-verification mini-wallet.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "bik_2012_predecessor",
        "dsa_article_28_overlap",
        "eu_ai_act_overlap",
        "eu_age_verification_mini_wallet",
        "safer_internet_programme",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dsa-regulation-article-28-protection-of-minors-advertising"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-bioeconomy-strategy-renewable-resources-2022",
    "title": "EU Bioeconomy Strategy: 2022 Progress Report on a Sustainable and Circular Bioeconomy for Europe",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This EU strategy update requires Member States and relevant industries to prioritize sustainable biomass sourcing and apply the cascading principle for its use, ensuring high-value applications are prioritized over energy use. As outlined in the 2022 Progress Report (COM(2022) 283 final), this framework guides policy and investment towards circular, bio-based value chains to reduce fossil fuel dependency and meet climate goals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify",
      "reach-chemical-comp"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-biosafety-contained-use-directive-2009-41",
    "title": "Directive 2009/41/EC of the European Parliament and of the Council of 6 May 2009 on the contained use of genetically modified micro-organisms (Recast) (Text with EEA relevance)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This Directive establishes a framework for the safe contained use of genetically modified micro-organisms (GMMs) in the EU, requiring risk classification, containment measures, and notification to competent authorities prior to first use in an installation, as specified in Article 14 and Annex II. It applies to all operators conducting contained use of GMMs in installations across Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "cartagena-protocol-biosafety-2000"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-biosimilars-guideline-ema-2014",
    "title": "Biosimilar Development: Comparability Exercise, Quality Comparability, Non-Clinical Studies, Clinical PK/PD Studies, Efficacy/Safety and Immunogenicity Assessment",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This guideline outlines the scientific principles for demonstrating biosimilarity between a proposed biosimilar and its reference biological medicinal product through a stepwise comparability exercise. It applies to marketing authorisation applicants for biosimilars in the EU and requires full justification of any deviation from the recommended approach as per the CHMP/437/04 Rev 1 guideline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-q10-pharmaceutical-quality-system-2008",
      "eu-gmp-annex-1-sterile-manufacture-2022",
      "fda-biosimilar-pathway-351k-biologics-competition-act"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-biotech-directive-98-44-ec-patents",
    "title": "Directive 98/44/EC of the European Parliament and of the Council of 6 July 1998 on the legal protection of biotechnological inventions",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive establishes the conditions under which biotechnological inventions are patentable in the European Union, including isolated gene sequences, provided they meet novelty, inventive step, and industrial applicability criteria under Article 53, and excludes patents on animal varieties, essentially biological processes, and uses of human embryos for industrial or commercial purposes under Article 6. It applies to patent applicants, biotech firms, research institutions, and EU national patent offices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-atmp-regulation-1394-2007",
      "nagoya-protocol-genetic-resources-2010",
      "cbd-convention-biological-diversity-1992",
      "ema-guidelines-advanced-therapy-quality-2019"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-birds-directive-2009-147-ec",
    "title": "EU Birds Directive 2009/147/EC",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Directive 2009/147/EC (the Birds Directive) provides for the conservation of all species of naturally occurring birds in the wild state in the European territory of EU Member States. It codifies the 1979 Birds Directive (79/409/EEC) and requires Member States to maintain populations of all species at ecologically appropriate levels through Special Protection Areas (SPAs) for Annex I species and regularly occurring migratory species; protection regimes prohibiting deliberate killing capturing destruction or disturbance during breeding season; and limited derogations under Article 9. SPAs together with Habitats Directive SACs form the Natura 2000 network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-blocking-statute-regulation-2271-96",
    "title": "Council Regulation (EC) No 2271/96 of 22 November 1996 protecting against the effects of the extra-territorial application of legislation adopted by a third country, and actions based thereon or resulting therefrom (EU Blocking Statute)",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "The EU Blocking Statute protects EU operators against the extra-territorial application of specified third-country laws listed in its Annex (principally certain United States sanctions on Cuba, Iran and Libya). It prohibits compliance with those laws or with foreign court or administrative decisions giving them effect under Article 5, denies recognition of such foreign judgments under Article 4, allows recovery of resulting damages under Article 6, and requires operators to inform the Commission within 30 days of effects on their interests under Article 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-helms-burton-libertad-act-22-usc-ch69a",
      "us-iran-sanctions-act-1996-pl-104-172"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-broadband-cost-reduction-directive-2014-61",
    "title": "Directive 2014/61/EU of the European Parliament and of the Council of 15 May 2014 on measures to reduce the cost of deploying high-speed electronic communications networks",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive requires network operators to grant reasonable requests for access to their physical infrastructure (e.g., ducts, poles) to facilitate the rollout of high-speed broadband networks, and mandates that new buildings and major renovations include high-speed-ready in-building physical infrastructure and an access point (Article 3 & Article 8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-brrd-amending-directive-2019-879-brrd2",
    "title": "EU BRRD2 Directive 2019/879 - MREL, Subordination & Resolution Planning",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive 2019/879 (BRRD2) amends the Bank Recovery and Resolution Directive (BRRD 2014/59/EU) to implement the FSB Total Loss-Absorbing Capacity (TLAC) standard for G-SIIs and introduce a new Minimum Requirement for Own Funds and Eligible Liabilities (MREL) applicable to all institutions. BRRD2 introduces subordination requirements for MREL-eligible instruments (internal MREL for significant subsidiaries), updated moratorium powers (preventing payments for up to 2 working days), and aligns the BRRD with the SRMR for Banking Union institutions. G-SII TLAC complies with FSB TLAC term sheet: minimum 16% RWA (18% from 2022) and 6% leverage ratio (6.75% from 2022).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-brrd-bank-recovery-resolution-directive-2014-59",
      "eu-single-resolution-mechanism-regulation-806-2014",
      "eu-crr3-capital-requirements-regulation-2024-1623"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-brrd-bank-recovery-resolution-directive-2014-59",
    "title": "EU BRRD - Bank Recovery and Resolution Directive 2014/59/EU",
    "domain": "Banking & Global Finance",
    "version": "2.0.0",
    "last_updated": "2021-12-28",
    "bluf": "Directive 2014/59/EU (BRRD) establishes an EU-wide framework enabling competent authorities to resolve failing credit institutions and investment firms without taxpayer bailout - through bail-in, sale of business, bridge institution, and asset separation tools - while requiring banks to maintain minimum own funds and eligible liabilities (MREL) and prepare credible recovery plans.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-emir-regulation-648-2012",
      "eu-csdr-regulation-909-2014"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-brussels-ia-regulation-1215-2012",
    "title": "EU Brussels Ia Regulation 1215/2012 - Jurisdiction and Recognition of Judgments",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 1215/2012 (Brussels Ia / Brussels Recast) sets unified EU rules for determining which member state's courts have jurisdiction in civil and commercial disputes and provides for automatic recognition and enforcement of judgments across all EU member states. It replaces Brussels I (Regulation 44/2001) and abolishes the exequatur procedure - judgments from any EU member state are directly enforceable in all others without a declaration of enforceability. Special rules protect consumers, employees, and policyholders regardless of jurisdiction clauses.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-trade-secrets-directive-2016-943",
      "eu-consumer-credit-directive-2023-2225",
      "eu-employment-equality-directive-2000-78",
      "eu-mortgage-credit-directive-2014-17-real-estate"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-brussels-iib-matrimonial-parental-jurisdiction-regulation-2019-1111",
    "title": "Council Regulation (EU) 2019/1111 of 25 June 2019 on jurisdiction, the recognition and enforcement of decisions in matrimonial matters and the matters of parental responsibility, and on international child abduction (recast)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This recast Regulation governs jurisdiction, recognition and enforcement of decisions in matrimonial matters and matters of parental responsibility, and international child abduction (Article 1). It sets general jurisdiction for divorce, legal separation and marriage annulment (Article 3), and jurisdiction in parental responsibility based primarily on the child habitual residence (Article 7), with continuing jurisdiction over access rights where a child moves lawfully (Article 8), provisions on prorogation, and rules ensuring decisions are recognised and enforced across Member States with safeguards for the child best interests.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-service-of-documents-regulation-2020-1784",
      "eu-taking-of-evidence-regulation-2020-1783"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-bus-coach-passenger-rights-regulation-181-2011",
    "title": "Regulation (EU) No 181/2011 of the European Parliament and of the Council of 16 February 2011 concerning the rights of passengers in bus and coach transport",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation establishes the rights of passengers in bus and coach transport (Articles 1 and 2). It requires non-discriminatory contract conditions and tickets (Article 4), provides for compensation and assistance in the event of death, personal injury, or loss of or damage to luggage (Article 7), addresses the immediate practical needs of passengers following an accident (Article 8), grants a right to transport for persons with disabilities or reduced mobility (Article 9) subject to limited exceptions (Article 10), and requires accessibility and information (Article 11) and assistance at designated terminals and on board (Articles 12 and 13).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-air-passenger-rights-regulation-261-2004",
      "eu-passenger-rights-regulation-pr-sales-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cap-strategic-plans-regulation-2021-2115",
    "title": "Rules on support for CAP strategic plans, direct payments, and rural development, repealing Regulations 1305/2013 and 1307/2013",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Regulation (EU) 2021/2115 establishes the legal framework for CAP Strategic Plans drawn up by Member States and financed by the European Agricultural Guarantee Fund (EAGF) and the European Agricultural Fund for Rural Development (EAFRD). It sets general and specific objectives including making the CAP more result-driven and market-oriented, boosting modernisation and sustainability, and reducing administrative burden. The regulation introduces a delivery model based on performance, enhanced subsidiarity, and a system of conditionality linking full receipt of CAP support to compliance with statutory management requirements (SMRs) and standards of good agricultural and environmental condition (GAEC). It provides framework definitions for agricultural activity, agricultural area, eligible hectare, active farmer, young farmer, and new farmer; Member States are to specify these in their CAP Strategic Plans. The regulation establishes types of intervention including basic income support for sustainability, complementary redistributive income support, eco-schemes for climate and environment, coupled income support, and sectoral interventions for fruit and vegetables, wine, apiculture, olives, hops, and others. Social conditionality is introduced, to be applied no later than 1 January 2025, linking CAP payments to compliance with labour and occupational safety standards under Directives 89/391/EEC, 2009/104/EC, and (EU) 2019/1152. Farm advisory services must be tailored to economic, environmental, and social dimensions, integrated within Agricultural Knowledge and Innovation Systems (AKIS). The regulation also provides for capping of direct payments, a mandatory redistributive payment of at least 10% of the direct payments envelope, and a specific intervention for small farmers. It sets a maximum allocation for coupled income support and allows additional support for protein crops. The regulation enters into force on 6 December 2021 and applies from 1 January 2023, with some provisions delayed until 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-capital-requirements-directive-iv-2013-36-crd4",
    "title": "CRD IV - EU Capital Requirements Directive 2013/36/EU (Basel III Implementation)",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive 2013/36/EU (CRD IV), which entered into force 17 July 2013 and applied from 1 January 2014, implements the Basel III accord within the European Union alongside the Capital Requirements Regulation (CRR, Regulation 575/2013). CRD IV establishes the legal framework for authorisation of credit institutions and investment firms, prudential supervision, governance requirements, remuneration policies, and macroprudential capital buffer requirements. The Directive introduced the Combined Buffer Requirement - comprising the Capital Conservation Buffer (2.5% CET1), Countercyclical Capital Buffer (0-2.5% CET1, jurisdictionally set), Global Systemically Important Institution buffer (G-SII, 1-3.5% CET1), Other Systemically Important Institution buffer (O-SII, 0-3% CET1), and Systemic Risk Buffer (SRB, up to 5% CET1 or higher with Commission approval). CRD IV Article 73 requires Internal Capital Adequacy Assessment Process (ICAAP); Article 74 imposes robust governance and risk appetite frameworks. Remuneration provisions (Articles 92-96) cap variable pay at 1:1 fixed-to-variable ratio (2:1 with shareholder approval) for material risk takers. The Directive also establishes the fit-and-proper requirements for board members (Article 91) and imposes on supervisors the obligation to conduct the Supervisory Review and Evaluation Process (SREP, Article 97). CRD V (Directive 2019/878/EU) and CRD VI (Directive 2024/1619/EU) have subsequently amended CRD IV; CRD VI applies from 11 January 2026 and introduces Basel IV Pillar 2 add-ons, ESG risk disclosure obligations, and enhanced third-country branch requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crr-iii-eu-implementation-2024",
      "ecb-srep-2023-supervisory-guide",
      "eu-aml-regulation-2024",
      "basel-iv-crr3-eu-capital-requirements-2025"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-capital-requirements-regulation-2013-575",
    "title": "EU Capital Requirements Regulation (CRR) -- Basel III Prudential Standards for Credit Institutions",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Regulation (EU) 575/2013 (CRR) implements Basel III prudential requirements for EU credit institutions and investment firms. Minimum capital ratios under Article 92 are: Common Equity Tier 1 (CET1) 4.5% of risk-weighted assets; Tier 1 capital 6%; Total capital 8%. The large exposures limit under Article 395 is 25% of eligible capital per single counterparty. The leverage ratio minimum is 3% (Article 429, binding from June 2021 via CRR2 Regulation 2019/876). The Liquidity Coverage Ratio (LCR) requirement of 100% is implemented via Delegated Regulation 2015/61 (Article 412). CRR2 (Regulation 2019/876) introduced the binding Net Stable Funding Ratio (NSFR) of 100%, the Standardised Approach for Counterparty Credit Risk (SA-CCR), and the Fundamental Review of the Trading Book (FRTB) framework. CRR3 (Regulation 2024/1623) completes Basel III finalisation with output floor transitional arrangements from January 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-solvency-ii-directive-2009-138",
      "eu-idd-insurance-distribution-directive-2016-97",
      "eu-services-directive-2006-123"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-carbon-border-adjustment-2023",
    "title": "Regulation (EU) 2023/956 of the European Parliament and of the Council of 10 May 2023 establishing a carbon border adjustment mechanism",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The EU Carbon Border Adjustment Mechanism (CBAM) requires EU-based importers of specific carbon-intensive goods (cement, iron, steel, aluminium, fertilisers, electricity, hydrogen) to report embedded greenhouse gas emissions quarterly during a transitional period and, from 2026, to purchase and surrender CBAM certificates corresponding to those emissions. The core reporting obligation for the transitional period is established in Article 35.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "ghg-protocol-scope3",
      "iso-14064-ghg-quantify",
      "eu-taxonomy-sustainable",
      "iso-20400-sustainable-proc"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-carbon-border-adjustment-mechanism-2023-956-cbam-certificates",
    "title": "EU Carbon Border Adjustment Mechanism (CBAM) Regulation 2023/956 - Carbon Price Certificates for Imported Goods",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Regulation (EU) 2023/956 establishes a Carbon Border Adjustment Mechanism (CBAM) requiring importers of cement, iron and steel, aluminium, fertilisers, electricity, and hydrogen to purchase CBAM certificates proportional to the embedded carbon in imported goods. This equalises the carbon cost between EU domestic production (subject to EU ETS) and imports, preventing carbon leakage. Reporting-only transitional phase 2023-2025; full financial CBAM from 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852-sustainable-finance-classification"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-carbon-removals-certification-framework-2024-3012",
    "title": "Regulation (EU) 2024/3012 - EU Carbon Removals Certification Framework (CRCF): Quality Criteria for Carbon Removal Activities, Certification Body Accreditation, Carbon Removal Certificates, Delegated Act Methodologies, and Integration with EU Net Zero and Voluntary Carbon Market Standards",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2024/3012 (EU Carbon Removals Certification Framework, CRCF), adopted 27 November 2024, establishes the EU's first regulatory framework for certifying carbon removal activities; key elements include: four QU.A.L.ITY certification criteria (Quantification, Additionality, Long-term storage, Sustainability) that all carbon removal activities must meet to receive EU certification; three categories of certified carbon removals - permanent carbon storage (geological CCS/CCU), temporary carbon storage in long-lasting products, and carbon farming (soil and forest carbon); certification by accredited certification bodies under Regulation (EC) No 765/2008; issuance of carbon removal certificates (CRCs) per tonne CO2e removed or stored; a Union registry managed by the Commission for tracking all CRCs; Commission delegated acts specifying activity-specific certification methodologies within 18 months of entry into force; and provisions to prevent double counting between CRCF certificates and EU ETS compliance or third-country carbon markets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_ETS",
        "EU_TAXONOMY",
        "EU_NET_ZERO",
        "VOLUNTARY_CARBON"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ets-revision-2023-fit-for-55",
      "eu-taxonomy-regulation-2020-852",
      "eu-net-zero-industry-act-2024-manufacturing-capacity",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cbam-2023-956-carbon-border-adjustment",
    "title": "Regulation (EU) 2023/956 of the European Parliament and of the Council of 10 May 2023 establishing a carbon border adjustment mechanism",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation requires EU importers of specific carbon-intensive goods (cement, iron, steel, aluminium, fertilisers, electricity, hydrogen) to report the embedded greenhouse gas emissions of their imports and, from 2026, purchase and surrender a corresponding number of 'CBAM certificates' to cover these emissions. During the transitional period (starting October 2023), importers must submit quarterly reports on embedded emissions without financial adjustment, as mandated by Article 35.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-cbam-calc",
    "title": "EU Carbon Border Adjustment (CBAM)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The EU Carbon Border Adjustment Mechanism (CBAM), established by Regulation (EU) 2023/956 and fully operational from January 2026, requires EU importers to purchase CBAM certificates corresponding to the carbon price that would have been paid under EU ETS rules if the goods had been produced in the EU. The mechanism applies to imports of cement, iron and steel, aluminium, fertilizers, electricity, and hydrogen, with potential expansion to additional sectors. During a transitional phase (October 2023 to December 2025), importers had quarterly reporting obligations without certificate purchase requirements. From 2026, importers must submit annual CBAM declarations and surrender CBAM certificates equivalent to the embedded emissions in their imports. The CBAM is designed to prevent carbon leakage and level the competitive playing field, and non-compliance results in penalties of EUR 10-50 per excess tonne of CO2 equivalent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-taxonomy-sustainable",
      "ghg-protocol-scope3",
      "iso-14064-ghg-quantify",
      "logistics-hs-codes",
      "reach-chemical-comp"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cbam-carbon-border-adjustment-2023",
    "title": "Regulation (EU) 2023/956 (CBAM) - Carbon Border Adjustment Mechanism: Transitional Reporting Phase 2023-2025, Certificate Purchase from January 2026, Covered Sectors (Cement, Steel, Aluminium, Fertilisers, Electricity, Hydrogen), Authorised CBAM Declarant and Embedded Emissions Calculation",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2023/956 of 10 May 2023 establishes a Carbon Border Adjustment Mechanism (CBAM) that prices the carbon content of imports of specific goods from third countries to prevent carbon leakage as the EU strengthens its Emissions Trading System (EU ETS); during the transitional phase from 1 October 2023 to 31 December 2025 importers must file quarterly CBAM reports declaring embedded greenhouse gas emissions but are not yet required to purchase CBAM certificates; from 1 January 2026 importers must be registered as authorised CBAM declarants, calculate and verify actual embedded emissions or apply CBAM default values, purchase CBAM certificates at a price linked to the EU ETS weekly average auction price, and surrender certificates equal to embedded GHG emissions by 31 May of the following year; covered goods are set out in Annex I: cement, iron and steel, aluminium, fertilisers, electricity, and hydrogen; third countries with a carbon price equivalent to the EU ETS (Switzerland, Iceland, Norway, Liechtenstein) are exempt.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_ETS",
        "EU_CSRD",
        "WTO",
        "UNFCCC_NDC"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ets-revision-2023-fit-for-55",
      "eu-taxonomy-regulation-2020-852"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cbam-carbon-border-adjustment-mechanism",
    "title": "Regulation (EU) 2023/956 of the European Parliament and of the Council of 10 May 2023 establishing a carbon border adjustment mechanism",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-05-17",
    "bluf": "This regulation requires EU importers of specific carbon-intensive goods (cement, iron/steel, aluminium, fertilisers, electricity, hydrogen) to report embedded greenhouse gas emissions quarterly during a transitional period and, from 2026, to purchase and surrender CBAM certificates equivalent to those emissions. The core reporting obligation for the transitional period is established in Article 35.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-cbam-regulation-2023-956-article-12-cbam-certificates-purchase-surrender",
    "title": "EU Carbon Border Adjustment Mechanism (EU) 2023/956 - Article 12: Purchase, Surrender and Repurchase of CBAM Certificates",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 12 of the EU CBAM Regulation (2023/956) governs the financial mechanism for CBAM compliance: the purchase, surrender and repurchase of CBAM certificates. CBAM certificates are sold by national competent authorities at a price equal to the weekly average auction price of EU ETS allowances (expressed in EUR/tonne CO2e). Authorised declarants purchase certificates through the national CBAM registry and must surrender certificates equal to embedded emissions declared in their annual CBAM declaration by 31 May each year. Certificates that were not surrendered and exceed one-third of total certificates surrendered in the previous year must be repurchased by the national competent authority at the purchase price. The certificate price tracks the EU ETS carbon price, creating a direct link between CBAM compliance costs and EU carbon market prices. Certificates have no fixed expiry date but are subject to the annual surrender and repurchase cycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cbam-regulation-2023-956-article-3-scope-covered-goods",
      "eu-cbam-regulation-2023-956-article-6-cbam-declarations-importers",
      "eu-cbam-2023-956-carbon-border-adjustment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-cbam-regulation-2023-956-article-3-scope-covered-goods",
    "title": "EU Carbon Border Adjustment Mechanism (CBAM) Regulation 2023/956 - Article 3: Scope and Covered Goods",
    "domain": "Sustainability & ESG",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 3 of the EU CBAM Regulation (2023/956) defines the scope of covered goods subject to the Carbon Border Adjustment Mechanism. CBAM applies to imports of goods listed in Annex I that originate from countries outside the EU (and EEA/countries with equivalent carbon pricing). Annex I covers six sectors: cement, iron and steel, aluminium, fertilisers, electricity, and hydrogen. The CBAM obligation applies to the import of these goods into the EU customs territory. CBAM applies to goods at the tariff sub-heading level specified in Annex I - some goods within a covered sector may be excluded based on specific CN code. The European Commission is empowered to extend CBAM to additional sectors by delegated act, with a review to assess extension by 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cbam-2023-956-carbon-border-adjustment",
      "eu-cbam-carbon-border-adjustment-mechanism"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-cbam-regulation-2023-956-article-6-cbam-declarations-importers",
    "title": "EU Carbon Border Adjustment Mechanism (EU) 2023/956 - Article 6: CBAM Declarations and Obligations of Importers",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 6 of the EU CBAM Regulation (2023/956) requires authorised CBAM declarants to file an annual CBAM declaration by 31 May each year, covering goods imported during the preceding calendar year. The declaration must specify: the total quantity of each type of CBAM good imported, the total embedded emissions in those goods (in tonnes of CO2 equivalent), the total number of CBAM certificates to be surrendered, and any credit for carbon prices already paid in the country of origin. Declarants must be authorised by the national competent authority before importing CBAM goods (from 1 January 2026). The declaration is filed through the CBAM registry. Non-authorised importers cannot place CBAM goods on the EU market under full CBAM. Embedded emissions must be calculated in accordance with Commission implementing regulations or, where actual emissions cannot be determined, at default values published by the Commission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cbam-regulation-2023-956-article-3-scope-covered-goods",
      "eu-cbam-regulation-2023-956-article-12-cbam-certificates-purchase-surrender",
      "eu-cbam-2023-956-carbon-border-adjustment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-cbdc-digital-euro-legislative-proposal-2023",
    "title": "Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro (COM/2023/0369)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-06-28",
    "bluf": "This legislative proposal establishes a framework for the digital euro as a central bank digital currency (CBDC), granting it legal tender status within the euro area (Article 7). It mandates acceptance by payees and outlines an intermediated distribution model through Payment Service Providers (PSPs), while empowering the European Central Bank (ECB) to set individual holding limits (Article 16) and implement privacy-enhancing features.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mica-regulation-2023",
      "eu-tfer-regulation-2023",
      "dora-ict-risk",
      "gdpr-article-17-right-erasure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ccp-recovery-resolution-regulation-2021-23",
    "title": "EU CCP Recovery and Resolution Regulation 2021/23 - CCP R&R Framework",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2021/23 establishes a framework for the recovery and resolution of central counterparties (CCPs). It requires CCPs to maintain recovery plans with loss allocation tools (variation margin gains haircutting - VMGH, initial margin haircutting - IMHA, and cash calls), mandates resolution plans by national resolution authorities, and grants special resolution powers including position transfers and write-down/conversion of equity and unsecured debt. CCPs must meet a minimum loss-absorbing capacity specified in their recovery plans.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-emir-regulation-648-2012",
      "eu-brrd-bank-recovery-resolution-directive-2014-59",
      "eu-csdr-regulation-909-2014",
      "eu-single-resolution-mechanism-regulation-806-2014"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-celex-31972l0418",
    "title": "Council Directive 72/418/EEC of 6 December 1972 amending the Directives of 14 June 1966 on the marketing of beet seed, of fodder-crop seed, of cereal seed, of seed potatoes, the Directive of 30 June 1969 on the marketing of oleaginous and fibrous plant seed, and the Directives of 29 September 1970 on the marketing of vegetable seed and on the Common Catalogue of Varieties of Agricultural Plant Species",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1972-12-06",
    "bluf": "Council Directive 72/418/EEC, adopted by the Council of the European Communities on 6 December 1972 and published in Official Journal L 287 on 26 December 1972, amends a series of earlier Directives governing the marketing of beet seed, fodder-crop seed, cereal seed, seed potatoes, oleaginous and fibrous plant seed, vegetable seed, and the Common Catalogue of Varieties of Agricultural Plant Species. The Directive applies to all Member States of the European Economic Community and imposes harmonised obligations on national competent authorities and market participants involved in the production, certification, labelling, packaging, and cross-border marketing of agricultural and vegetable seed and seed potatoes. The core obligations introduced include: ensuring that pre-basic seed of generations prior to basic seed is subject to no marketing restrictions provided it has been officially checked, packed in accordance with Directive provisions, and bears an official white label with a diagonal purple line containing specified particulars; harmonising the particulars that importers must present when marketing quantities exceeding 2 kg of seed from another Member State or third country; permitting Member States to authorise, for a specified period, the marketing of seed of inferior quality or of varieties not included in the Common Catalogue where temporary supply difficulties cannot be overcome within the Community; and requiring that official acceptances of varieties granted before 1 July 1972 expire not later than 30 June 1980 unless re-accepted under Directive principles. Member States were required to bring into force the necessary laws, regulations, or administrative provisions by 1 July 1972 for certain provisions and by 1 July 1973 at the latest for all remaining provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-31972r2351",
    "title": "Regulation (EEC) No 2351/72 of the Commission of 8 November 1972 supplementing Regulation (EEC) Nos 100/72 and 1574/72 as regards the denaturing process for sugar",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1972-11-09",
    "bluf": "This regulation supplements Regulations (EEC) No 100/72 and 1574/72 to provide a more precise description of the denaturing process for sugar intended for animal feed. It specifies the use of ferric oxide to ensure the sugar is colored dark red to brown, making it unsuitable for human consumption. The regulation applies to sugar producers and handlers within the European Economic Community and mandates the cancellation of denaturing premium certificates if applied for before 31 December 1972, with immediate release of the denaturing deposit upon cancellation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-31975h0004",
    "title": "75/4/EEC: Commission Recommendation of 27 November 1974 to the Danish Government concerning draft Orders implementing Council Regulations (EEC) No 2829/72, No 117/66/EEC, (EEC) No 516/72, (EEC) No 517/72 and Commission Regulations (EEC) No 1016/68 and (EEC) No 1172/72",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1975-01-04",
    "bluf": "This Commission Recommendation, issued on 27 November 1974 and published in Official Journal L 002 on 4 January 1975, addresses the Danish Government's draft Orders implementing a series of Council and Commission Regulations governing road transport within the European Communities. The Recommendation was triggered by a letter of 16 July 1974 from the Office of the Danish Permanent Representative, which forwarded three draft Orders covering: the Community quota for carriage of goods by road between Member States (Regulation (EEC) No 2829/72); common rules for international carriage of passengers by coach and bus (Regulation No 117/66/EEC and Commission Regulation (EEC) No 1016/68); and common rules for shuttle services, regular and special regular services by coach and bus between Member States (Regulations (EEC) No 516/72, (EEC) No 517/72, and Commission Regulation (EEC) No 1172/72). The Commission expresses regret that Denmark failed to implement Regulation (EEC) No 2829/72 by its entry into force on 1 January 1973, and did not meet the 1 April 1973 deadline specified in Articles 25(b) and 23(b) of Regulations (EEC) No 516/72 and (EEC) No 517/72. The Commission recommends that Denmark extend its draft Order on goods carriage to include penalty provisions, and further recommends that Denmark remedy the omission in Article 5(1) of the draft Order concerning shuttle and regular services by specifying whether, and under what conditions, the operation of a regular or special regular service can be transferred.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-31976d0963",
    "title": "76/963/EEC: Commission Decision of 7 December 1976 on the implementation of the reform of agricultural structures in the French Republic pursuant to Title I of Directive 72/161/EEC (Only the French text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1976-12-31",
    "bluf": "This Commission Decision of 7 December 1976 concerns the implementation of the reform of agricultural structures in the French Republic pursuant to Title I of Council Directive 72/161/EEC of 17 April 1972, which addresses the provision of socio-economic guidance for and the acquisition of occupational skills by persons engaged in agriculture. The Decision was adopted following notification by the French Government on 4 August 1976 of specific implementing provisions, including decree No 76-518 of 10 June 1976, the order of 8 January 1976 establishing a certificate of professional competence for socio-economic counsellors, and circular No 2811 of 20 May 1976. The core obligation established by this Decision is that the schemes for the provision of socio-economic guidance for the agricultural community as notified by the French Government satisfy the conditions for financial contribution from the Community to common measures as referred to in Article 8 of Directive 72/161/EEC. Member States are required to create and develop services providing socio-economic guidance and to introduce appropriate basic and advanced training programmes for socio-economic counsellors. The Guidance Section of the EAGGF is to refund to Member States 25% of a standard amount of 7,500 units of account per counsellor beginning duties for the first time, and 25% of training costs up to 4,500 units of account per trained counsellor providing such guidance. The Decision is addressed to the French Republic.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-31978d0945",
    "title": "78/945/EEC: Commission Decision of 31 October 1978 authorizing the Italian Republic not to apply Community treatment to essential oils, not terpeneless, of citrus fruit: orange oil, falling within subheading 33.01 ex A of the Common Customs Tariff (NIMEXE code 33.01-12), originating in Brazil and in free circulation in the other Member States",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1978-11-22",
    "bluf": "Commission Decision 78/945/EEC, adopted on 31 October 1978 and published in Official Journal L 327 on 22 November 1978, authorizes the Italian Republic not to apply Community treatment to essential oils, not terpeneless, of citrus fruit: orange oil, falling within subheading 33.01 ex A of the Common Customs Tariff (NIMEXE code 33.01-12), where those products originate in Brazil and are in free circulation in the other Member States. The authorization is granted under the first paragraph of Article 115 of the Treaty establishing the European Economic Community, following an application made on 23 October 1978 by the Italian Government. The Decision is grounded in the finding that importation of the products in question originating in Brazil is prohibited in Italy, and that disparities in commercial policy measures applied by Member States are causing deflection of trade, thereby preventing the execution of commercial policy measures in force. The Italian citrus oil industry, particular to certain economically unfavourable regions in southern Italy, faces a serious crisis caused both by the state of the market and the structure. The authorization applies specifically to products for which applications for import licences were lodged after 15 October 1978 and are, at the date of the Decision, pending with the Italian authorities. The Decision is addressed solely to the Italian Republic and is subject to the conditions laid down in Commission Decision 71/202/EEC of 12 May 1971, and in particular Article 1 thereof.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-31979d0068",
    "title": "79/68/EEC: Commission Decision of 12 December 1978 relating to a proceeding under Article 85 of the EEC Treaty (IV/29.430 - Kawasaki) (Only the English and German texts are authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1979-01-23",
    "bluf": "Commission Decision 79/68/EEC, adopted on 12 December 1978, concerns a proceeding under Article 85 of the EEC Treaty against Kawasaki Motors (UK) Ltd and Kawasaki Motoren GmbH. The Decision finds that Kawasaki Motors (UK) Ltd imposed an export prohibition on its network of approximately 80 appointed retail dealers in the United Kingdom through Clause 3(v) of the 'Kawasaki Motor Cycle Authorized Dealer Sales and Service Agreement', which required dealers not to supply products for export from the United Kingdom without prior written consent of the distributor. This prohibition, first imposed on 28 May 1975, constituted an infringement of Article 85(1) of the EEC Treaty by restricting competition and raising an artificial barrier to trade in goods between Community countries. Kawasaki Motoren GmbH, the wholly-owned German subsidiary of Kawasaki Heavy Industries Ltd, actively participated in the enforcement of the export prohibition by requesting Kawasaki Motors (UK) to stop exports and disclosing frame numbers of exported machines to identify offending dealers. The prohibition was designed to insulate national markets and maintain price differences of up to 55% between the United Kingdom and Germany at the wholesale level. As a result of the infringement, a fine of 100,000 European units of account (equivalent to 67,081,740 pounds sterling) was imposed on Kawasaki Motors (UK) Ltd, payable within three months of notification of the Decision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-31979d0638",
    "title": "79/638/EEC: Commission Decision of 4 July 1979 refusing to accept the scientific character of the apparatus described as 'PMS data acquisition system, model DAS-32'",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1979-07-04",
    "bluf": "This Commission Decision of 4 July 1979 (79/638/EEC) concerns the refusal to accept the scientific character of the apparatus described as the 'PMS data acquisition system, model DAS-32.' The Decision was adopted under Council Regulation (EEC) No 1798/75 of 10 July 1975 on the importation free of Common Customs Tariff duties of educational, scientific and cultural materials, and Commission Regulation (EEC) No 3195/75 of 2 December 1975 laying down provisions for the implementation of that Regulation, in particular Articles 4 and 5 thereof. The United Kingdom Government, by letter dated 19 December 1978, requested the Commission to invoke the procedure under Articles 4 and 5 of Regulation (EEC) No 3195/75 to determine whether the apparatus, intended for use in research on cloud physics and cloud droplet size measurement, should be considered a scientific apparatus and whether apparatus of equivalent scientific value was being manufactured in the Community. Following examination by a group of experts composed of representatives of all Member States on 28 May 1979, the Commission determined that the apparatus does not have the requisite objective characteristics making it specifically suited to scientific research, that it is an apparatus in current use including for measuring air pollution, and that its use in the case in question could not alone confer upon it the character of a scientific apparatus. Accordingly, the apparatus is not considered to be a scientific apparatus, and the Decision is addressed to the Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-31979l0007",
    "title": "Directive 79/7/EEC - Equal Treatment for Men and Women in Matters of Social Security",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Directive 79/7/EEC requires the progressive implementation of the principle of equal treatment for men and women in statutory social security schemes. It applies to the working population, including self-employed persons, those whose activity is interrupted by illness, accident or involuntary unemployment, persons seeking employment, and retired or invalided workers. It covers statutory schemes protecting against sickness, invalidity, old age, accidents at work and occupational diseases, and unemployment, together with social assistance that supplements or replaces those schemes. There must be no discrimination on grounds of sex, directly or indirectly by reference to marital or family status, as regards the scope of and conditions of access to schemes, the obligation to contribute and the calculation of contributions, and the calculation of benefits. Member States must abolish national provisions contrary to the principle and ensure that anyone who considers themselves wronged can pursue their claim by judicial process. The principle is without prejudice to provisions protecting women on grounds of maternity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_primary_law",
        "related_instruments",
        "charter_reference",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-equal-treatment-employment-2000-78",
      "eu-pay-transparency-directive-2023-970-article-7-right-to-information-workers"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-31980d0764",
    "title": "80/764/EEC: Commission Decision of 8 July 1980 establishing the schedule of tables and definitions relating to intermediate statistical surveys of are",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1980-08-16",
    "bluf": "Commission Decision 80/764/EEC, adopted on 8 July 1980 by the Commission of the European Communities, establishes the schedule of tables and definitions relating to intermediate statistical surveys of areas under vines. The Decision is addressed to the Member States of the European Economic Community and was published in Official Journal L 213 on 16 August 1980. Pursuant to Article 5(5) of Council Regulation (EEC) No 357/79 of 5 February 1979 on statistical surveys of areas under vines, Member States must submit the results of intermediate surveys in the form of a schedule of tables adopted in accordance with the procedure laid down in Article 8 of that Regulation. In order to ensure comparability of the data given in these tables, certain definitions relating to the intermediate surveys are laid down. Additionally, pursuant to Article 6(7) of Regulation (EEC) No 357/79, information referred to in Article 6 must be forwarded to the Commission in the form of a schedule of tables. The Decision prescribes in Annex I the form of the schedule of tables covering areas under wine-grape varieties, changes in those areas, production in hectolitres, and estimated production trends. Annex II establishes binding definitions for key terms including holding, area cultivated, wine-growing year, grubbing, planting, replanting right, and new planting, among others, to ensure uniform application across Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-31983d0610",
    "title": "83/610/EEC: Commission Decision of 5 December 1983 relating to a proceeding under Article 85 of the EEC Treaty (IV/30.668 - Murat) (Only the French text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1983-12-05",
    "bluf": "Commission Decision 83/610/EEC was adopted on 5 December 1983 by the Commission of the European Communities following a proceeding under Article 85 of the EEC Treaty. The decision concerns a notification made on 1 June 1982 by the jewellery manufacturer Murat SA, Viry-Chatillon, France, seeking negative clearance or, failing that, exemption of a proposed standard form agreement with the retailers of its products in a number of Community countries. The decision establishes that the notified standard form agreement governing the relations between Murat and its retailers embodies the terms of a selective distribution system set up by Murat at the retail level and constitutes an agreement between undertakings within the meaning of Article 85 of the Treaty. The Commission finds that agreements concerned with selective distribution systems are not caught by Article 85(1) of the Treaty when dealers are selected on objective, qualitative criteria related to the capacity of the dealer, his staff and premises, bearing in mind the genuine requirements of distribution of the products, and provided that such criteria are laid down in a uniform manner for all prospective dealers and applied in a non-discriminatory fashion. On the basis of the facts in its possession, the Commission concludes that the standard form distribution agreement does not contain any obligation having as its object or effect the prevention, restriction or distortion of competition within the common market or liable to affect trade between Member States, and accordingly grants negative clearance under Article 2 of Regulation No 17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-31984r2006",
    "title": "Council Regulation (EEC) No 2006/84 of 9 July 1984 providing for direct cooperation between the authorities of the Member States of the European Economic Community responsible for the prevention of fraud and the competent authorities in the Swiss Confederation",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1984-07-14",
    "bluf": "Council Regulation (EEC) No 2006/84, adopted on 9 July 1984 and published in the Official Journal of the European Communities on 14 July 1984, approves an exchange of letters between the European Economic Community and the Swiss Confederation founding direct cooperation between the authorities in the Member States of the Community responsible for the prevention of fraud and the competent Swiss authorities in the wine sector. The legal basis for this cooperation derives from the fourth subparagraph of Article 64(1) of Regulation (EEC) No 337/79 on the common organization of the market in wine, which provides for direct cooperation between the appropriate authorities in the Member States, and between them and the competent authorities in non-member countries having concluded an agreement or arrangement with the Community. The Community entered into contact in 1982 with the Swiss authorities, who agreed to introduce such cooperation on the basis of reciprocal undertakings by exchange of letters. The Regulation is binding in its entirety and directly applicable in all Member States, entering into force on the third day following its publication in the Official Journal of the European Communities. The President of the Council is authorized to designate the person empowered to sign the exchange of letters on behalf of the European Economic Community.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-31985d0208",
    "title": "85/208/EEC: Commission Decision of 25 March 1985 amending Decision 80/686/EEC setting up an Advisory Committee on the Control and Reduction of Pollution Caused by Hydrocarbons Discharged at Sea",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1985-03-25",
    "bluf": "The Commission Decision 85/208/EEC amends Decision 80/686/EEC to extend the terms of reference of the Advisory Committee on the Control and Reduction of Pollution Caused by Hydrocarbons Discharged at Sea to include other harmful substances. This decision applies from 25 March 1985 and is based on the Treaty establishing the European Economic Community, as well as previous Council Decisions and the expressed wishes of Parliament and the Economic and Social Committee.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-31985d0598",
    "title": "85/598/EEC: Commission Decision of 12 December 1985 on the implementation of the reform of agricultural structures in Belgium pursuant to Council Directive 75/268/EEC (Only the French and Dutch texts are authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1985-12-12",
    "bluf": "Commission Decision 85/598/EEC, adopted on 12 December 1985 by the Commission of the European Communities, concerns the implementation of the reform of agricultural structures in Belgium pursuant to Council Directive 75/268/EEC on mountain and hill farming and farming in certain less-favoured areas. The Decision was triggered by Belgium's notification, under Article 13 of Directive 75/268/EEC in conjunction with Article 17(4) of Council Directive 72/159/EEC, of a ministerial order of 20 August 1985 granting farmers in less-favoured areas an annual compensatory allowance to offset permanent natural handicaps. The core obligation established by this Decision is that the existing provisions in Belgium for the implementation of Directive 75/268/EEC continue to satisfy the conditions for financial contribution by the Community to common measures within the meaning of Article 13 of Directive 75/268/EEC. The Commission further noted that a revision of the application form for the compensatory allowance is indicated and that Belgium has agreed to follow this up in the year. The Decision is addressed to the Kingdom of Belgium and was signed by Frans Andriessen, Vice-President of the Commission. The measures were found to be in accordance with the opinion of the Standing Committee on Agricultural Structure, and the EAGGF Committee was consulted on the financial aspects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-31986d0596",
    "title": "Commission Decision on Anti-Competitive Cartels (MELDOC)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "This landmark Commission Decision under Article 85 of the EEC Treaty (now Article 101 TFEU) strictly prohibits cartel arrangements, price-fixing, and the division of markets. Specifically addressing the MELDOC dairy cartel, the ruling penalizes collusive agreements that restrict competition or artificially influence trade between Member States. It mandates strict antitrust governance, prohibiting competitors from sharing sensitive pricing data, establishing joint sales quotas, or engaging in coordinated actions intended to freeze out foreign competition or control domestic market shares.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "eu-celex-31987r2151",
    "title": "Council Regulation (Euratom, ECSC, EEC) No 2151/87 of 20 July 1987 adjusting the weightings applicable to the remuneration and pensions of officials and other servants of the European Communities",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1987-07-20",
    "bluf": "Council Regulation (Euratom, ECSC, EEC) No 2151/87, adopted on 20 July 1987 by the Council of the European Communities, adjusts the weightings applicable to the remuneration and pensions of officials and other servants of the European Communities. The regulation is grounded in Articles 63, 64, 65 and 82 of the Staff Regulations and the first paragraph of Article 20 and Article 64 of the Conditions of Employment, as established under Regulation (EEC, Euratom, ECSC) No 259/68. The regulation applies to officials and other servants of the European Communities employed in specified countries where the cost of living increased substantially in the second half of 1986. It establishes revised country-specific weightings effective from three distinct dates: 1 November 1986 (Brazil, Syria, Turkey, Yugoslavia), 16 November 1986 (Greece, Chile, Venezuela, Israel, Egypt), and 1 January 1987 (Italy/Varese, Spain, Portugal, Australia, India, Algeria, Tunisia, Jordan). Weightings applicable to pensions are to be determined in accordance with Article 82(1) of the Staff Regulations. The regulation entered into force on the day following its publication in the Official Journal of the European Communities (Official Journal L 202, 23/07/1987) and is binding in its entirety and directly applicable in all Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-31989d0208",
    "title": "89/208/EEC: Council Decision of 27 February 1989 on the conclusion of the Protocol to the Agreement establishing an association between the European economic community and Malta consequent on the accession of the kingdom of Spain and the Portuguese republic to the community",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1989-03-23",
    "bluf": "This Council Decision of 27 February 1989 approves, on behalf of the European Economic Community, the Protocol to the Agreement establishing an Association between the European Economic Community and Malta, consequent on the accession of the Kingdom of Spain and the Portuguese Republic to the Community. The original Association Agreement was signed at Valletta on 5 December 1970 and published in OJ No L 61, 14.3.1971. The Protocol was necessitated by the need to take into account the accession of Spain and Portugal to the Community, thereby adjusting the existing association framework between the EEC and Malta accordingly. The Decision was adopted by the Council of the European Communities having regard to the Treaty establishing the European Economic Community, in particular Article 238 thereof, following a recommendation from the Commission and the assent of the European Parliament. Under Article 1, the Protocol is formally approved on behalf of the Community, with the text of the Protocol attached to the Decision. Article 2 mandates that the President of the Council give the notification provided for in Article 26 of the Protocol. Article 3 specifies that the Decision takes effect on the day following its publication in the Official Journal of the European Communities, which occurred on 23 March 1989 at pages 0010 - 0010 of Official Journal L 081.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-31989y0524-01",
    "title": "Special Report No 1/89 on the agrimonetary system accompanied by the replies of the Commission",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1989-05-24",
    "bluf": "Special Report No 1/89, issued by the Court of Auditors pursuant to Article 206(a) paragraph 4 of the EEC Treaty, records the results of an examination of the agrimonetary system of the European Community. The report places particular emphasis on the consequences for the general budget of the system, and the extent to which it interferes with the sound management of the common agricultural markets, which provide the basis for the functioning of the common agricultural policy. The system involves the use of agricultural conversion rates (green rates) and Monetary Compensatory Amounts (MCAs) to bridge gaps between green rates and market rates of exchange, originally introduced in 1969 when the French franc was devalued and the Deutsche Mark was revalued. The Court finds that the annual decisions of the Council fixing the level of agricultural prices in ECU do not reflect real developments in institutional prices, and that the switchover mechanism introduced in 1984 effectively raises the common price level in line with the strongest currency in the EMS, the DM, while keeping these increases largely hidden. The full budgetary impact of the agrimonetary system for 1987 is assessed by the Court at at least 1,578.2 Mio ECU (10-month basis) and 1,824.6 Mio ECU on a full 12-month basis, equivalent to 7% of EAGGF expenditure, compared with only 636.9 Mio ECU recorded in chapter 28 of the EAGGF budget. The report applies to Community institutions, Member States, paying agencies, customs authorities, and all operators engaged in agricultural trade within and outside the Community.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-31991r2246",
    "title": "Commission Regulation (EEC) No 2246/91 of 26 July 1991 opening a standing invitation to tender for the sale of unprocessed dried grapes (sultanas) from the 1989 harvest intended for specific uses",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1991-07-26",
    "bluf": "Commission Regulation (EEC) No 2246/91, adopted on 26 July 1991, opens a standing invitation to tender for the sale of unprocessed dried grapes (sultanas) from the 1989 harvest held by Greek storage agencies. The regulation is grounded in Council Regulation (EEC) No 426/86 on the common organization of the market in products processed from fruit and vegetables, and Council Regulation (EEC) No 1206/90 laying down general rules for the system of production aid for processed fruit and vegetables. The Greek storage agencies still hold approximately 20,500 tonnes of unprocessed dried grapes (sultanas) from the 1989 harvest, and these currants cannot be marketed for human consumption as such without a risk of disrupting the market. Accordingly, the regulation directs the Greek storage agencies listed in the Annex to open a standing invitation to tender for the sale of a maximum of 20,500 tonnes of these sultanas in accordance with Regulations (EEC) No 626/85 and (EEC) No 3205/85. The closing date for the first partial invitation to tender is 5 August 1991 at 1 p.m. local time. A processing security of ECU 45/100 kg net is fixed for dried grapes (sultanas). The regulation entered into force on 1 August 1991 and is binding in its entirety and directly applicable in all Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-31991r3832",
    "title": "Council Regulation (ECSC, EEC, Euratom) No 3832/91 of 19 December 1991 amending the Staff Regulations of Officials and the Conditions of Employment of Other Servants of the European Communities with regard to the contribution to the pension scheme",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1991-12-19",
    "bluf": "Council Regulation (ECSC, EEC, Euratom) No 3832/91, adopted on 19 December 1991 by the Council of the European Communities, amends the Staff Regulations of Officials and the Conditions of Employment of Other Servants of the European Communities with regard to the contribution to the pension scheme. The regulation was adopted having regard to the Treaty establishing a Single Council and a Single Commission of the European Communities, and in particular Article 24 thereof, and following consultation with the Staff Regulations Committee, the European Parliament, the Court of Justice, and the Consultation Committee set up by the Council Decision of 23 June 1981. The core obligation established by this regulation is a mandatory increase in pension scheme contribution rates. As stated in the recitals, it was found desirable, in the interests of longer-term stability of the pension scheme, to increase the funds available to that scheme by raising the rate of contribution fixed in Article 83 (2) of the Staff Regulations. Specifically, Article 1(1) replaces the existing rate of 6.75% with 8.25% in Article 83(2) of the Staff Regulations, and Article 1(2) replaces 13.5% with 16.5% in the second paragraph of Article 42 of the Conditions of Employment of Other Servants. The regulation entered into force on 1 January 1993 and is binding in its entirety and directly applicable in all Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-31992r1597",
    "title": "Commission Regulation (EEC) No 1597/92 of 23 June 1992 amending Regulation (EEC) No 1822/77 laying down detailed rules for the collection of the co-responsibility levy introduced in respect of milk and milk products",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1992-06-23",
    "bluf": "Commission Regulation (EEC) No 1597/92, adopted on 23 June 1992, amends Regulation (EEC) No 1822/77 to update the detailed rules for the collection of the co-responsibility levy on milk and milk products for the 1992/93 milk year. The Regulation was adopted having regard to Council Regulation (EEC) No 1079/77 on a co-responsibility levy and on measures for expanding the markets in milk and milk products, and in particular Article 6 thereof. The core obligation established by this Regulation sets the levy per 100 kilograms of cow's milk at ECU 0.4021 for the general rate and ECU 0.2681 for the reduced rate during the 1992/93 milk year. The reduced rate applies to producers whose individual reference quantity is less than or equal to 60,000 kilograms on the first day of the ninth period of application of the additional levy arrangements. Similarly, for skimmed milk or buttermilk, the general rate levy is set at ECU 0.4423 and the reduced rate at ECU 0.2949 per 100 kilograms. The Regulation is binding in its entirety and directly applicable in all Member States, entering into force on the third day following its publication in the Official Journal of the European Communities, with effect from 1 June 1992.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-31993m0360",
    "title": "COMMISSION DECISION of 23.09.1993 declaring a concentration to be compatible with the common market (Case No IV/M.360 - ARVIN / SOGEFI) according to Council Regulation (EEC) No 4064/89 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1993-09-23",
    "bluf": "The European Commission declared the concentration between Arvin Industries Inc. and Sogefi S.p.A. compatible with the common market under Council Regulation (EEC) No 4064/89. The decision pertains to the formation of a joint venture combining their interests in the manufacture and sale of exhaust systems for the free aftermarket. The Commission concluded that the operation does not raise serious doubts as to its compatibility with the common market, given the market shares and competitive conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-31994d0050",
    "title": "94/50/ECSC: Commission Decision of 20 December 1993 concerning the conclusion on behalf of the European Coal and Steel Community of the Additional Protocol to the interim Agreement on trade and trade-related matters between the European Economic Community and the European Coal and Steel Community and the Republic of Poland and to the Europe Agreement between the European Communities and their Member States and the Republic of Poland",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1994-01-29",
    "bluf": "This Commission Decision, adopted on 20 December 1993 and published in Official Journal L 025 on 29 January 1994, concerns the conclusion on behalf of the European Coal and Steel Community (ECSC) of the Additional Protocol to the Interim Agreement on trade and trade-related matters between the European Economic Community and the European Coal and Steel Community and the Republic of Poland, and to the Europe Agreement between the European Communities and their Member States and the Republic of Poland. The Decision was adopted by the Commission of the European Communities having regard to the Treaty establishing the European Coal and Steel Community, in particular the first paragraph of Article 95 thereof, and following the conclusions of the European Council in Copenhagen on 21 and 22 June 1993. The Commission negotiated the Additional Protocol on behalf of the Communities, and the conclusion of the Protocol was deemed necessary to attain the objectives of the Community set out in Articles 2 and 3 of the Treaty establishing the European Coal and Steel Community. The Decision was taken after consulting the Consultative Committee and with the unanimous assent of the Council. Under Article 1, the Additional Protocol is approved on behalf of the ECSC, and under Article 2, the President of the Commission is mandated to give the notification provided for in Article 8 of the Additional Protocol on behalf of the ECSC. The Decision was signed by Commission President Jacques Delors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-31995d0115",
    "title": "95/115/EC: Council Decision of 30 March 1995 authorizing the Federal Republic of Germany to conclude with the Republic of Poland an agreement containing measures derogating from Articles 2 and 3 of the Sixth Directive 77/388/EEC on the harmonization of the laws of the Member States relating to turnover taxes",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1995-04-08",
    "bluf": "This Council Decision of 30 March 1995 authorizes the Federal Republic of Germany to conclude with the Republic of Poland an agreement containing measures derogating from Articles 2 and 3 of the Sixth Directive 77/388/EEC on the harmonization of the laws of the Member States relating to turnover taxes. The authorization is granted pursuant to Article 30 of Directive 77/388/EEC, which permits the Council, acting unanimously on a proposal from the Commission, to authorize any Member State to conclude with a non-member country or an international organization an agreement which may contain derogations from the said Directive. The derogations address the maintenance of frontier bridges linking German motorways to the main roads in Poland. Without a special measure, only maintenance work carried out on German territory would be subject to German VAT, while that carried out on Polish territory would be outside the scope of Directive 77/388/EEC, and each importation of goods from Poland into Germany used for the maintenance of frontier bridges would be subject to German VAT. The purpose of the derogations is to simplify the taxation rules for those responsible for carrying out the maintenance work on the frontier bridges. The derogations will have only a negligible effect on the Community's own resources arising from VAT. The Decision is addressed to the Federal Republic of Germany.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-31996d0004",
    "title": "96/4/EC: Commission Decision of 13 December 1995 authorizing a method for grading pig carcases in Austria (Only the German text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1995-12-13",
    "bluf": "The Commission Decision authorizes the use of the 'Zwei-Punkte-Meßverfahren (ZP)' method for grading pig carcases in Austria, as the only method compliant with Regulation (EEC) No 3220/84. It applies specifically to pig carcases weighing between 60 and 130 kilograms. The method involves calculating the lean meat content using a specific formula based on measurements of fat thickness and lumbar muscle thickness. The authorization is transitional, valid until 31 December 1997, and requires that pig carcases can be presented with flare fat, kidneys, and diaphragm attached during weighing and grading, with a 2.3% adjustment to the recorded weight for standard presentation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-31997d0754",
    "title": "97/754/ECSC: Commission Decision of 30 April 1997 concerning the application to the steel firm Ferdofin Srl of Italian Law No 95/1979 on receivership arrangements for large firms in crisis (Only the Italian text is authentic) (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1997-11-11",
    "bluf": "This Commission Decision of 30 April 1997, adopted under the Treaty establishing the European Coal and Steel Community (ECSC) and Commission Decision No 2496/96/ECSC, concerns the application of Italian Law No 95/1979 on receivership arrangements for large firms in crisis - known as the Prodi Law - to Ferdofin Siderurgica Srl, a steel producer subject to the rules of the ECSC Treaty. The Commission determined that the measures provided for by Law No 95/1979, as applied to Ferdofin, constitute State aid incompatible with the common market for coal and steel pursuant to Article 4(c) of the ECSC Treaty, which prohibits subsidies or aid granted by States in any form whatsoever. The aid took the form of suspension of payments on debts owed to public bodies, including Lit 10 786 million owed to the INPS, Lit 723 million owed to the INAIL, Lit 2 301 million owed to the tax authorities, and Lit 100 billion owed to banks controlled directly or indirectly by the State. The Decision requires Italy to recover the aid with interest calculated from the date it was granted, to immediately cease applying Law No 95/1979 to Ferdofin's unpaid debts to public bodies, and to inform the Commission within two months of the measures taken to comply. The aid does not qualify for any of the derogations - research and development, environmental protection, or closures - exhaustively set out in Decision No 2496/96/ECSC, and was granted in breach of Article 6(2) of that Decision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-31997m0975",
    "title": "COMMISSION DECISION of 13/11/1997 declaring a concentration to be compatible with the common market (Case No IV/M.975 - ALBACOM/BT/ENI/MEDIASET) according to Council Regulation (EEC) No 4064/89 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1997-11-13",
    "bluf": "This Commission Decision of 13 November 1997 declares a concentration compatible with the common market under Council Regulation (EEC) No 4064/89. The operation concerns the acquisition by ENI of a 35% equity stake in Albacom S.p.A. through a share increase for a consideration of 173 billion lire (ECU 88 million), together with the granting by SNAM S.p.A. to Albacom of the right to use its fibre infrastructure, and the acquisition by Albacom of the entire issued share capital of Nuova Società di Telecomunicazioni S.p.A. (NST). The Commission determined that Albacom is jointly controlled by BT, ENI, and Mediaset, with the Board of Directors consisting of 5 directors designated by Albacom Holdings, 2 by Mediaset, and 4 by ENI. The decision applies to the notifying parties - British Telecom plc, Ente Nazionale Idrocarburi S.p.A., Albacom S.p.A., and Mediaset S.p.A. - and establishes that the operation has a Community dimension given that the combined worldwide turnovers of all undertakings concerned exceed 5,000 million ECU. The Commission concluded that the proposed concentration will not create or strengthen a dominant position as a result of which competition will be significantly impeded in the common market or in a substantial part of it, and accordingly adopted an Article 6(1)(b) decision of non-opposition, declaring the operation compatible with the common market and with the functioning of the EEA Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-31997s1401",
    "title": "Commission Decision No 1401/97/ECSC of 7 July 1997 on administering certain restrictions on imports of certain steel products from Ukraine",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1997-07-07",
    "bluf": "Commission Decision No 1401/97/ECSC, adopted on 7 July 1997 under the Treaty establishing the European Coal and Steel Community, establishes the administrative framework for managing quantitative restrictions on imports of certain steel products originating in Ukraine into the European Community for the period 1997 to 2001. The Decision implements a bilateral agreement between the Community and Ukraine that establishes quantitative limits for the entry into free circulation of steel products, with a framework for the removal of such restrictions provided that certain conditions are met, including the establishment of equivalent disciplines in respect of competition, public aid, and environmental protection. The Decision applies to importers, Member State competent authorities, and the Commission, requiring that all imports of the listed steel products from Ukraine be subject to Community import licences issued by Member State authorities only upon prior confirmation from the Commission that quantities remain available within the relevant quantitative limit. A double-checking system of Ukrainian export licences and Community import authorizations is mandated, along with monthly statistical reporting obligations, anti-circumvention consultation procedures, and administrative cooperation mechanisms for origin verification. The Decision entered into force the day following its publication in the Official Journal of the European Communities and applies from 1 July 1997.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 12
  },
  {
    "node_id": "eu-celex-31997y1230-01",
    "title": "Council Resolution of 4 December 1997 concerning the report on the state of women's health in the European Community",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1997-12-30",
    "bluf": "The Council of the European Union, referring to the Commission report of 19 July 1995 on the state of health in the European Community and the Council's conclusions of 30 November 1995, welcomes the Commission's report of 22 May 1997 on the state of women's health in the European Community. The Resolution observes that this report highlights a lack of reliable, up-to-date and comparable data as well as a lack of data broken down according to gender, and notes a considerable increase in women's life expectancy since 1970 along with continuing differences between the life expectancy of women in different Member States. The Resolution calls upon Member States to proceed with the breakdown of health data by gender, account being taken of socio-economic factors, and to gather more data concerning health problems specific to women, paying particular attention to improving women's quality of life. It calls upon the Commission to take due account of this report in implementing programmes under way and in developing future action, to attach particular importance to improving the quality and comparability of health data and to their breakdown according to gender in the framework of the programme of Community action on health monitoring, and to consult Member States in an appropriate manner for the preparation of future reports. The specific problems linked to women's health should be taken into account when the new framework for action in the field of public health is being considered.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-31998d0693",
    "title": "Commission Decision 98/693/EC: Spanish Plan Renove Industrial Aid for Commercial Vehicles",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-23",
    "bluf": "The Commission Decision 98/693/EC concerns the Spanish Plan Renove Industrial system of aid for the purchase of commercial vehicles from August 1994 to December 1996. The aid consists of a subsidy of up to five percentage points of the interest payable on loans granted for purchasing vehicles. The system was set up under an Agreement between the Official Credit Institute and the Spanish Ministry of Industry and Energy. The Commission considers that the aid strengthens the financial position of recipient firms, giving them a competitive advantage, and that it may distort competition between carriers established in Spain and those operating in Spain but based in other Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-31999m1400",
    "title": "COMMISSION DECISION of 01/02/1999 declaring a concentration to be compatible with the common market (Case No IV/M.1400 - REXAM/PLM) according to Council Regulation (EEC) No 4064/89 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1999-02-01",
    "bluf": "The European Commission declared the acquisition of PLM AB by Rexam Plc compatible with the common market under Council Regulation No 4064/89. The operation involves Rexam acquiring sole control over PLM through a public bid. The Commission concluded that the transaction falls within the scope of the Regulation and does not raise serious doubts regarding its compatibility with the common market and the functioning of the EEA Agreement. The combined aggregate worldwide turnover of the undertakings exceeds EUR 2,500 million, and the operation meets the Community dimension thresholds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-31999m1479",
    "title": "COMMISSION DECISION of 05/05/1999 declaring a concentration to be compatible with the common market (Case No IV/M.1479 - THOMSON/BANCO ZARAGOZANO/CAJA MADRID/INDRA) according to Council Regulation (EEC) No 4064/89 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1999-05-05",
    "bluf": "On 31 March 1999, the Commission received a notification of a proposed concentration pursuant to Article 4 of Council Regulation (EEC) No 4064/89 by which the undertakings Thomson-CSF, Caja de Ahorros y Monte de Piedad de Madrid (Caja Madrid), and Banco Zaragozano acquire within the meaning of Article 3(1)(b) of the Council Regulation joint control of Indra Sistemas SA. The operation takes place in the context of the privatisation of Indra, following which the Spanish State ceased to have any participation in Indra. Thomson, Caja Madrid, and Banco Zaragozano agreed to coordinate their conduct in respect of important decisions at the Shareholders Meeting and at the Board of Directors of Indra, subject to unanimous approval of the notifying parties, relating inter alia to the appointment of members of the board of directors, the definition of the general strategy, and the approval of the business plans and annual budgets. After examination of the notification, the Commission concluded that the notified operation falls within the scope of Council Regulation (EEC) No 4064/89 and does not raise serious doubts as to its compatibility with the common market and with the EEA Agreement. The combined aggregate worldwide turnover of the parties exceeds EUR 5 billion, satisfying the Community dimension threshold. The Commission found that the proposed concentration does not create or strengthen a dominant position as a result of which effective competition would be significantly impeded in the EEA or any substantial part of that area, and accordingly decided not to oppose the notified operation, declaring it compatible with the common market and with the EEA Agreement under Article 6(1)(b) of Council Regulation (EEC) No 4064/89.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-31999m1484",
    "title": "COMMISSION DECISION of 02/06/1999 declaring a concentration to be compatible with the common market (Case No IV/M.1484 - ALSTOM/ABB) according to Council Regulation (EEC) No 4064/89 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1999-06-02",
    "bluf": "On 27 April 1999, the Commission received a notification of a proposed concentration pursuant to Article 4 of Council Regulation (EEC) No 4064/89, as amended by Council Regulation (EEC) No 1310/97, by which ABB Handels- und Verwaltungs AG ('ABB HV') and ALSTOM (France) create a joint venture on power generation equipment, ABB ALSTOM Power NV ('JV'). After examination of the notification, the Commission concluded that the notified operation falls within the scope of Council Regulation No 4064/89 and does not raise serious doubts as to its compatibility with the common market and the functioning of the EEA agreement. The JV will be jointly controlled by ALSTOM and ABB, each holding 50% of the shares, with each appointing one half of the members of the supervisory board. The JV's activities will include the design, manufacture, R&D, marketing, supply and servicing of turbines (gas, steam and hydro), generators, boilers, environmental control products and district heating systems. The creation of the JV is conditional upon ALSTOM completing the sale of its large heavy duty gas turbine (LHDGT) business to General Electric Company ('GE'), as referenced in Case IV/M.1404 - GE/ALSTOM, notified on 26/04/1999. ABB's nuclear power and distributed power business is excluded from the JV's scope.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-31999m1649",
    "title": "COMMISSION DECISION of 30/09/1999 declaring a concentration to be compatible with the common market (Case No IV/M.1649 - GEFCO/KN ELAN) according to Council Regulation (EEC) No 4064/89 (Only the German text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "1999-09-30",
    "bluf": "On 30 August 1999, the Commission received a notification of a proposed concentration pursuant to Article 4 of Council Regulation (EEC) No 4064/89 (Merger Regulation) by which the undertaking Gefco Deutschland GmbH (Gefco), ultimately controlled by Peugeot S.A., acquires within the meaning of Article 3(1)(b) of the Merger Regulation sole control of the whole of KN ELAN GmbH & Co. KG and of KN ELAN Verwaltungs-GmbH (together: KN ELAN). Gefco will take over a 60% participation in KN ELAN from Kühne & Nagel, with Kühne & Nagel retaining a 40% minority stake. After examination of the notification, the Commission concluded that the notified operation falls within the scope of Council Regulation (EEC) No 4064/89 and does not raise serious doubts as to its compatibility with the common market and with the EEA Agreement. The operation has a Community dimension, as the combined aggregate worldwide turnover of the parties exceeded EUR 5,000 million in 1998, and each of the undertakings concerned had a Community-wide turnover of more than EUR 250 million. The relevant markets concern national and international road-based freight forwarding, primarily in Germany, where KN ELAN operates a groupage and road transport network. The Commission found that the merger would only insignificantly alter the market position of the parties, given the presence of comparable competitors such as Schenker AG, the Deutsche Post group, and Dachser on the German freight forwarding markets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32000m1952",
    "title": "COMMISSION DECISION of 21/08/2000 declaring a concentration to be compatible with the common market (Case No IV/M.1952 - RWE/IBERDROLA/TARRAGONA POWER JV) according to Council Regulation (EEC) No 4064/89 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2000-08-21",
    "bluf": "On 14 July 2000, the Commission received a notification of a proposed concentration by which RWE AG (Germany) and Iberdrola S.A. (Spain) will establish a full-function joint venture, Tarragona Power S.L. (TPower), active in the electricity supply at interconnected level mainly in Spain. After examination of the notification, the Commission concluded that the notified operation falls within the scope of Council Regulation (EEC) No 4064/89 and does not raise serious doubts as to its compatibility with the common market and with the EEA Agreement. TPower will supply electricity at interconnected level (380/220 kV) to large industrial customers, building a gas-fired power plant adding 400 MW of generation capacity to the Spanish market - approximately 1% of currently installed capacity - generating approximately 3.2 TWh per year. RWE and Iberdrola each hold a 50% participation and jointly control TPower, with unanimous vote of the board of directors required for strategic business decisions. The Commission determined the proposed operation would not lead to the creation or strengthening of a dominant position on the market of electricity supply at interconnected level in Spain, and declared it compatible with the common market pursuant to Article 6(1)(b) of Council Regulation (EEC) No 4064/89.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32000m2095",
    "title": "COMMISSION DECISION of 29/08/2000 declaring a concentration to be compatible with the common market (Case No IV/M.2095 - SEXTANT/DIEHL) according to Council Regulation (EEC) No 4064/89 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2000-08-29",
    "bluf": "On 27 July 2000, the Commission received a notification of a proposed concentration pursuant to Article 4 of Council Regulation (EEC) No 4064/89 ('the Merger Regulation') by which the undertakings Thomson-CSF Sextant S.A. ('SEXTANT') and INTEGRA Vermögensverwaltungs- und Beteiligungsgesellschaft mbH ('INTEGRA'), a holding company controlled by DIEHL Stiftung & Co (Nuremberg, Germany) ('Diehl'), acquire within the meaning of Article 3(1)(b) of the Council Regulation joint control of a newly created company ('NEWCO'). NEWCO shall combine all the activities of the pre-existing Sextant/Diehl joint venture VDO-L as well as the activities of Bodenseewerk Gerätetechnik GmbH ('BGT', a subsidiary of the DIEHL group) in the area of control and navigation systems. After examination of the notification, the Commission concluded that the notified operation falls within the scope of application of Council Regulation No 4064/89 and does not raise serious doubts as to its compatibility with the common market and with the functioning of the EEA Agreement. The combined aggregate world-wide turnover of the undertakings concerned exceeds EUR 5000 million, satisfying the Community dimension threshold under Article 1.2 of the Merger Regulation. The Commission decided not to oppose the notified operation and declared it compatible with the common market and with the EEA Agreement, in application of Article 6(1)(b) of Council Regulation (EEC) No 4064/89.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32000m2105",
    "title": "Commission Decision of 30/11/2000 declaring a concentration to be compatible with the common market (Case No IV/M.2105 - 4* SJPC / SCP DE MILO / DE MILO) according to Council Regulation (EEC) No 4064/89 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2000-11-30",
    "bluf": "The Commission Decision of 30/11/2000 declares a concentration involving SJPC, SCP De Milo, and de Milo to be compatible with the common market under Council Regulation (EEC) No 4064/89. The concentration involves the acquisition of joint control of de Milo S.A. by SJPC and SCP De Milo through the purchase of shares in a newly created joint venture. The Commission concluded that the operation falls within the scope of the Regulation and applied a simplified procedure for treatment of certain concentrations. The decision not to oppose the operation and declare it compatible with the common market and the EEA Agreement was made under Article 6(1)(b) of Council Regulation (EEC) No. 4064/89.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32000m2115",
    "title": "COMMISSION DECISION of 28/09/2000 declaring a concentration to be compatible with the common market (Case No IV/M.2115 - CARREFOUR/GB) according to Council Regulation (EEC) No 4064/89 (Only the French text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2001-01-18",
    "bluf": "This is a Commission Decision dated 28 September 2000 declaring a concentration to be compatible with the common market under Case No IV/M.2115 - CARREFOUR/GB - pursuant to Council Regulation (EEC) No 4064/89. The decision was published in the Official Journal 016 on 18 January 2001, at page 0008. Only the French text is authentic. The decision applies to the notified concentration between CARREFOUR and GB, assessed by the European Commission under the merger control framework established by Council Regulation (EEC) No 4064/89. The full text of the decision is available through CLX, the French version of CELEX, and the paper version is available through the sales offices of the Office of Official Publications of the European Communities. The core obligation established by this decision is the formal compatibility finding, meaning the concentration between CARREFOUR and GB was reviewed and declared compatible with the common market by the Commission on the stated date.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32000y1014-01",
    "title": "Council Resolution on the Rights of Air Passengers",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "This Council Resolution establishes foundational principles for air passenger rights within the European Union, prompting airlines and airports to adopt voluntary commitments to improve service quality. It mandates transparency in ticketing, clear communication of delays, improved baggage handling, and assistance for passengers with reduced mobility. Although largely a precursor to binding regulations, it creates immediate expectations for operational complaint handling and passenger welfare during operational disruptions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "eu-celex-32001a0309-07",
    "title": "Council Opinion of 12 February 2001 on the 2000 update of Ireland's stability programme, 2001-2003",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2001-02-12",
    "bluf": "The Council of the European Union examined the 2000 update of Ireland's stability programme, covering the period 2001-2003. The Council noted Ireland's rapid economic growth, with real GDP growth of 10.7% expected in 2000, employment growth of 4.5%, and an unemployment rate declining to 4.1%. Inflationary pressures intensified, with average HICP inflation rising to 5.3%. The Council welcomed Ireland's substantial general government surplus of around 4.7% of GDP and the reduction in the general government debt ratio. Projections for 2001-2003 showed an average surplus ratio of 4.2%, with the debt ratio declining to less than one quarter of GDP by 2003. The Council expressed concerns about the stimulatory nature of the 2001 budget, which posed risks to growth and inflation. The Council recommended adjustments to ensure consistency with broad economic policy guidelines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32001a1218-01",
    "title": "Commission Opinion on Radioactive Waste Disposal from ASTRA Research Reactor",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-23",
    "bluf": "The European Commission received general data relating to the plan for the disposal of radioactive waste from the decommissioning and dismantling of the ASTRA research reactor in Austria. The Commission drew up an opinion based on the data and additional information provided by the Austrian Government, and following consultations with a group of experts. The opinion concludes that the implementation of the plan is not liable to result in radioactive contamination, significant from the point of view of health, of the water, soil or airspace of another Member State. The plan includes the storage of solid radioactive waste on site until 2012, and the release of solid material from dismantling for recycling or reuse is controlled to prevent significant health effects on the population of another Member State.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-celex-32001d0228-01",
    "title": "Decision of the Director of Europol of 3 July 2000 adapting the amounts mentioned in the Europol Staff Regulations to the euro",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2001-02-28",
    "bluf": "The Director of Europol, acting pursuant to the Council Decision of 2 December 1999 amending the Council Act of 3 December 1998 laying down the Staff Regulations applicable to Europol employees, issued this Decision on 3 July 2000 to effect the conversion into euro units of the different financial entitlements referred to in the Staff Regulations. The conversion is carried out on the basis of Council Regulation (EC) No 1103/97 of 17 June 1997 on certain provisions relating to the introduction of the euro, and Council Regulation (EC) No 2866/98 of 31 December 1998 on the conversion rates between the euro and the currencies of the Member States adopting the euro. With effect from 1 July 1999, subsequent to the Council Decision of 2 December 1999 adjusting the remuneration and allowances applicable to Europol employees, the Decision establishes specific euro-denominated values for financial entitlements across multiple articles of the Staff Regulations and Appendix 5 thereto, including amounts relating to Articles 59(3), 60(1), and Articles 2 through 7 of Appendix 5. The Director is further required to ensure that the values thus established are published in the Official Journal of the European Communities. This Decision entered into force the day following its adoption by the Director at The Hague.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 11
  },
  {
    "node_id": "eu-celex-32001d0287",
    "title": "2001/287/EC: Commission Decision of 2 April 2001 recognising in principle the completeness of the dossier submitted for detailed examination in view of the possible inclusion of mesosulfuron methyl in Annex I to Council Directive 91/414/EEC concerning the placing of plant-protection products on the market (Text with EEA relevance) (notified under document number C(2001) 1000)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2001-04-02",
    "bluf": "The Commission Decision of 2 April 2001 recognizes in principle the completeness of the dossier submitted by Aventis for the inclusion of mesosulfuron methyl in Annex I to Council Directive 91/414/EEC. The dossier, submitted to the French authorities on 15 December 2000, appears to satisfy the data and information requirements of Annex II and Annex III to the Directive for at least one plant-protection product containing the active substance. The decision allows for the detailed examination of the dossier and permits Member States to grant provisional authorisation for plant-protection products containing mesosulfuron methyl. France is tasked with conducting the detailed examination and reporting its conclusions within one year from the date of publication of this Decision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32001m2281",
    "title": "COMMISSION DECISION of 17/04/2001 declaring a concentration to be compatible with the common market (Case No IV/M.2281 - ENDESA/CDF/SNET (see ECSC.1352)) according to Council Regulation (EEC) No 4064/89 (Only the French text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2001-06-23",
    "bluf": "The Commission Decision of 17/04/2001 declares a concentration involving ENDESA, CDF, and SNET to be compatible with the common market under Council Regulation (EEC) No 4064/89. This decision applies to the parties involved in the concentration and confirms that the merger does not violate the common market principles. The French text is the authentic version, and the full text is available through CLX, the French version of CELEX.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32001m2513",
    "title": "COMMISSION DECISION of 02/08/2001 declaring a concentration to be compatible with the common market (Case No IV/M.2513 - RWE/KÄRNTNER ENERGIE HOLDING) according to Council Regulation (EEC) No 4064/89 (Only the German text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2001-10-12",
    "bluf": "This Commission Decision, issued on 02/08/2001, declares a concentration to be compatible with the common market under Council Regulation (EEC) No 4064/89. The case in question is Case No IV/M.2513, involving RWE and KÄRNTNER ENERGIE HOLDING. The decision was published in Official Journal 286 on 12/10/2001, at pages 0003 - 0003. Only the German text is authentic. The full text of the decision is available through CDE, the German version of CELEX, and the paper version is available through the sales offices of the Office of Official Publications of the European Communities. The decision applies to the parties involved in the notified concentration - RWE and KÄRNTNER ENERGIE HOLDING - and establishes that the proposed merger or acquisition is compatible with the common market as defined under the applicable European Community merger control regulation. The core obligation arising from this decision is that the concentration, as assessed by the European Commission, does not significantly impede effective competition within the common market or a substantial part of it, and is therefore permitted to proceed under the framework established by Council Regulation (EEC) No 4064/89.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32002q1130-01",
    "title": "Interinstitutional Agreement of 20 November 2002 between the European Parliament and the Council concerning access by the European Parliament to sensi",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2002-11-20",
    "bluf": "This Interinstitutional Agreement, concluded on 20 November 2002 between the European Parliament and the Council, governs access by the European Parliament to sensitive information - defined as information classified as TRÈS SECRET/TOP SECRET, SECRET or CONFIDENTIEL, whatever its origin, medium or state of completion - held by the Council in the field of security and defence policy, and the handling of documents so classified. The Agreement is grounded in Article 21 of the Treaty on European Union, which requires the Council Presidency to consult the European Parliament on the main aspects and basic choices of the common foreign and security policy and to keep it regularly informed of developments therein. The Agreement applies to the President of the European Parliament, the Chairman of the Committee on Foreign Affairs, Human Rights, Common Security and Defence Policy, and a special committee of four members designated by the Conference of Presidents. These persons may request that the Presidency of the Council or the Secretary-General/High Representative convey sensitive information required for the exercise of the powers conferred on the European Parliament. Information originating from a third State, international organisation, or Member State may only be transmitted with the agreement of that originator. Both institutions are required to take all necessary measures to ensure implementation, including steps required for the security clearance of the persons involved, and the Agreement is subject to review after two years at the request of either institution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32003b0408",
    "title": "European Parliament Decision 2003/408/EC on Discharge for 2001 Budget",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-23",
    "bluf": "The European Parliament Decision 2003/408/EC concerns the discharge of the European Commission in respect of the implementation of the general budget of the European Union for the 2001 financial year. The decision is based on the revenue and expenditure account, the consolidated balance sheet, and the annual report of the Court of Auditors. The Parliament grants discharge to the Commission, records its comments in an accompanying resolution, and instructs its President to forward the decision and resolution to relevant institutions. The decision is made in accordance with Articles 275 and 276 of the EC Treaty, Article 78g of the ECSC Treaty, and Articles 179a and 180b of the EAEC Treaty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32003d0036",
    "title": "2003/36/ECSC - Commission Decision of 7 May 2002 authorising RAG Aktiengesellschaft to acquire control of Saarbergwerke AG and Preussag Anthrazit GmbH (Case COMP/ECSC.1350 - RAG/Saarbergwerke/Preussag Anthrazit II) (Text with EEA relevance) (notified under document number C(2002) 1436)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2002-05-07",
    "bluf": "Commission Decision 2003/36/ECSC, adopted on 7 May 2002 and published in Official Journal L 012 on 17 January 2003, authorises RAG Aktiengesellschaft to acquire exclusive control of Saarbergwerke AG (SBW) and Preussag Anthrazit GmbH under Article 66(2) of the Treaty establishing the European Coal and Steel Community (ECSC Treaty). The decision follows the annulment by the Court of First Instance on 31 January 2001 of the original Commission authorisation of 29 July 1998, which had failed to assess whether the total assets of SBW transferred to RAG corresponded to the purchase price of DEM 2 or whether State resources had been implicitly transferred to RAG. The transaction, part of the 'coal compromise' (Kohlekompromiss) reached on 13 March 1997, merges the last three remaining German hard coal mining companies into a single entity, Deutsche Steinkohle AG, controlled by RAG. The Commission's renewed assessment concludes that, under current market conditions - including declining domestic coal production, rising import competition, low market entry barriers, and the absence of long-term anticompetitive procurement obligations - the merger does not give RAG the power to determine prices, control or restrict production or distribution, or hinder effective competition in a substantial part of the affected market, nor to evade the rules of competition under the ECSC Treaty by establishing an artificially privileged position. Even assuming a hypothetical maximum increase in RAG's financial strength of DEM [0 to 500] million resulting from the low purchase price for SBW, this would not be sufficient to enable anti-competitive conduct within the meaning of Article 66(2) of the ECSC Treaty. The Decision is addressed to RAG Aktiengesellschaft, Rellinghauser Straße 1-11, D-45128 Essen.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32003d0282",
    "title": "2003/282/EC: Commission Decision of 27 November 2002 on the State aid implemented by Germany for Doppstadt GmbH (notified under document number C(2002) 4482) (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2003-04-30",
    "bluf": "The European Commission's decision addresses the State aid implemented by Germany for Doppstadt GmbH, a company involved in the production of carrier vehicles and environmental-engineering equipment. The aid, amounting to EUR 39,244 million, was found to be compatible with the common market under Article 87(3)(c) of the EC Treaty. The decision outlines the restructuring plan for Doppstadt GmbH, which includes investments, modernization of production processes, and compliance with environmental standards. The Commission concluded that the aid was proportional to the restructuring costs and benefits, and that the investor's contribution was significant enough to ensure the company's long-term viability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32003d0753",
    "title": "2003/753/EC: Decision No 191 of 18 June 2003 concerning the replacement of forms E 111 and E 111 B by the European health insurance card (Text with relevance for the EEA and for the EU/Switzerland Agreement.)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2003-06-18",
    "bluf": "The decision introduces the European health insurance card to replace forms E 111 and E 111 B for accessing healthcare during temporary stays in Member States other than the competent State or State of residence. It applies to insured persons moving within the Community, with transitional provisions for Member States lacking health insurance cards. The card must indicate either 'E 111 +' for necessary care or 'E 111' for immediately necessary care. Member States must implement the card by 1 June 2004, with transitional periods ending by 31 December 2005.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32003m3139",
    "title": "Commission Decision of 10/04/2003 declaring a concentration to be compatible with the common market (Case No COMP/M.3139 - CARLYLE / BREED TECHNOLOGIES) according to Council Regulation (EEC) No 4064/89 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2003-04-10",
    "bluf": "The Commission Decision of 10/04/2003 declares the concentration between Carlyle Management Group I, L.P. and Breed Technologies, Inc. to be compatible with the common market. The notification was made pursuant to Article 4 of Council Regulation (EEC) No. 4064/89. Carlyle, a private investment group, acquired control of Breed Technologies, Inc., which designs, develops, produces, and sells components used in integrated occupant protection systems, steering wheels, car accessories, and electronics. After examination, the Commission concluded that the operation falls within the scope of Council Regulation (EEC) No. 4064/89 and decided not to oppose the notified operation, declaring it compatible with the common market and the EEA Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32003m3158",
    "title": "Commission Decision of 17/06/2003 declaring a concentration to be compatible with the common market (Case No COMP/M.3158 - DE AGOSTINI INVEST / TORO ASSICURAZIONI) according to Council Regulation (EEC) No 4064/89 (Only the Italian text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2003-06-17",
    "bluf": "The Commission Decision of 17/06/2003 declares the concentration between DE AGOSTINI INVEST and TORO ASSICURAZIONI to be compatible with the common market under Council Regulation (EEC) No 4064/89. This decision applies to the parties involved in the concentration and confirms that the transaction does not impede effective competition in the European Economic Area. The Italian text is the authentic version of the decision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32003m3250",
    "title": "Commission Decision of 09/09/2003 declaring a concentration to be compatible with the common market (Case No COMP/M.3250 - PERMIRA III / GOLDMAN SACHS GROUP / BLACKSTONE GROUP / DEBENHAMS) according to Council Regulation (EEC) No 4064/89 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2003-09-09",
    "bluf": "On 7 August 2003, the European Commission received notification of a proposed concentration pursuant to Article 4 of Council Regulation (EEC) No. 4064/89, by which Permira Europe III (UK), GS Capital Partners 2000 LP and affiliates belonging to the Goldman Sachs Group (USA), and Blackstone Capital Partners IV Merchant Banking Fund L.P. and affiliates belonging to the Blackstone Group (USA), acquire within the meaning of Article 3(1)(b) of the Council Regulation control of the whole of the undertaking Debenhams plc (UK) by way of public bid announced on 29 July 2003. The business activities of the acquiring undertakings are described as private equity funds, while Debenhams is engaged in retailing a range of consumer, household and food goods. After examination of the notification, the Commission concluded that the notified operation falls within the scope of Council Regulation (EEC) No. 4064/89 and of paragraph 4, subparagraph b, of the Commission Notice on a simplified procedure for treatment of certain concentrations under Council Regulation (EEC) No 4064/89. For the reasons set out in the Notice on a simplified procedure, the Commission decided not to oppose the notified operation and declared it compatible with the common market and with the EEA Agreement. This decision was adopted in application of Article 6(1)(b) of Council Regulation (EEC) No. 4064/89 and signed by Mario Monti, Member of the Commission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32003r1413",
    "title": "Commission Regulation (EC) No 1413/2003 of 7 August 2003 suspending Regulation (EC) No 935/2003 opening an invitation to tender for the refund on rye exports to certain third countries",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2003-08-07",
    "bluf": "Commission Regulation (EC) No 1413/2003, adopted by the Commission of the European Communities on 7 August 2003, suspends the tendering procedure established under Regulation (EC) No 935/2003, which had opened an invitation to tender for the refund on rye exports to certain third countries. The legal basis for this action is the Treaty establishing the European Community and Council Regulation (EEC) No 1766/92 on the common organisation of the markets in cereals, in particular Article 5 thereof. The regulation is grounded in the finding that, for economic reasons, the invitation to tender should be suspended. Commission Regulation (EEC) No 1501/95 lays down certain detailed rules for the application of Council Regulation (EEC) No 1766/92 covering the grant of export refunds on cereals and the measures to be taken in the event of disturbance in the sector. The Management Committee for Cereals did not deliver an opinion within the period set by its chairman. The regulation entered into force on the day of its publication in the Official Journal of the European Union (OJ L 201, 08/08/2003, p. 0015). It is binding in its entirety and directly applicable in all Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32004d0060",
    "title": "2004/60/EC: Commission Decision of 23 December 2003 on the continuation in the year 2004 of Community comparative trials and tests on propagating material of ornamental plants of Chamaecyparis, Ligustrum vulgare, Euphorbia fulgens and bulbs of flowers (Narcissus) under Council Directive 98/56/EC started in 2003",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2004-01-17",
    "bluf": "The Commission Decision 2004/60/EC mandates the continuation in 2004 of Community comparative trials and tests on propagating material of ornamental plants of Chamaecyparis, Ligustrum vulgare, Euphorbia fulgens, and bulbs of flowers (Narcissus). These trials and tests were initiated in 2003 under Council Directive 98/56/EC. The decision applies to entities involved in the marketing and propagation of these ornamental plants and bulbs, ensuring compliance with the arrangements set out in Decision 2002/744/EC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32004d0114",
    "title": "2004/114/EC: Commission Decision of 29 October 2003 on measures in favour of non-profit harbours for recreational crafts, the Netherlands (Text with EEA relevance) (notified under document number C(2003) 3890)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2004-02-06",
    "bluf": "The Commission Decision addresses measures in favour of non-profit harbours for recreational crafts in the Netherlands, specifically in Enkhuizen, Nijkerk, and Wieringermeer. The decision examines whether these measures constitute State aid under Article 87(1) of the EC Treaty. The Commission concludes that no State aid is at stake for the marinas in Wieringermeer, Enkhuizen, and Nijkerk, as no advantage is granted in Wieringermeer, and the measures in Enkhuizen and Nijkerk do not affect trade between Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32004d0811",
    "title": "Council Decision 2004/811/CFSP of 5 July 2004 concerning the conclusion of the Agreement between the European Union and the Kingdom of Norway on the participation of the Kingdom of Norway in the European Union Police Mission (EUPOL ‘Proxima’) in the former Yugoslav Republic of Macedonia",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2004-09-09",
    "bluf": "Council Decision 2004/811/CFSP of 5 July 2004 approves the Agreement between the European Union and the Kingdom of Norway on the participation of the Kingdom of Norway in the European Union Police Mission (EUPOL 'Proxima') in the former Yugoslav Republic of Macedonia. The Agreement was signed at Brussels on 9 September 2004 and published in the Official Journal of the European Union on 30 November 2004. The Agreement governs the terms under which the Kingdom of Norway associates itself with Joint Action 2003/681/CFSP on EUPOL 'Proxima', including the status of seconded personnel, chain of command, classified information protection, financial responsibilities, and dispute settlement. Norway must ensure its personnel undertake their mission in conformity with the Joint Action, the Operation Plan, and Implementing measures. Norway retains jurisdiction over its personnel, bears responsibility for claims arising from their participation, and assumes all costs associated with its participation apart from costs subject to EU common funding. The contribution of the Kingdom of Norway to EUPOL 'Proxima' is explicitly stated to be without prejudice to the decision-making autonomy of the European Union. Disputes are to be settled by diplomatic means, and either party may terminate the Agreement by serving a notice of one month in case of non-compliance, or denounce it with six months' written notice.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32004m3429",
    "title": "Commission Decision of 25/06/2004 declaring a concentration to be compatible with the common market (Case No COMP/M.3429 - NOKIA / METSO / AVANTONE (4064)) according to Council Regulation (EEC) No 4064/89 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2004-06-25",
    "bluf": "On 25 June 2004, the European Commission decided not to oppose the notified concentration involving NOKIA / METSO / AVANTONE and declared it compatible with the common market. This decision is based on Article 6(1)(b) of Council Regulation (EEC) No 4064/89. The full text of the decision is available only in English and will be made public after it is cleared of any business secrets it may contain. The decision can be accessed from the Europa competition web site free of charge or in electronic form in the ‘CEN’ version of the CELEX database under document number 304M3429.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32004m3525",
    "title": "Commission Decision of 18/08/2004 declaring a concentration to be compatible with the common market (Case No COMP/M.3525 - ALPINVEST / 3i / CID/JV) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2004-09-04",
    "bluf": "On 18 August 2004, the European Commission decided not to oppose a notified concentration involving ALPINVEST/3i/CID/JV and declared it compatible with the common market. This decision is based on Article 6(1)(b) of Council Regulation (EC) No 139/2004. The full text of the decision is available in English and will be made public after it is cleared of any business secrets it may contain. The decision can be accessed from the Europa competition web site free of charge or in electronic form in the ‘CEN’ version of the CELEX database under document number 32004M3525.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32005d0960",
    "title": "2005/960/EC,Euratom: Commission Decision of 15 November 2005 amending its Rules of Procedure",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2006-01-01",
    "bluf": "The Commission Decision of 15 November 2005 (2005/960/EC, Euratom) amends the Rules of Procedure of the European Commission, replacing Articles 1 to 28 with the text set out in the Annex to this Decision. The Rules entered into force on 1 January 2006 and were published in the Official Journal of the European Union on 30 December 2005. The Rules govern the internal functioning of the Commission of the European Communities, establishing that the Commission shall act collectively in accordance with these Rules of Procedure and in compliance with the political guidelines laid down by the President. They apply to all Members of the Commission, its departments (Directorates-General and equivalent bodies), the Secretary-General, and all officials operating under delegated or subdelegated powers. Core obligations include adherence to collective responsibility in decision-making, mandatory consultation of the Legal Service on all drafts or proposals for legal instruments and on all documents which may have legal implications, proper authentication of all instruments adopted, and ensuring continuity of service through defined deputising arrangements. Decision-making may occur by oral procedure at Commission meetings, by written procedure, by empowerment procedure, or by delegation procedure, each with specific conditions and authentication requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32005e0304",
    "title": "Council Common Position 2005/304/CFSP of 12 April 2005 concerning conflict prevention, management and resolution in Africa and repealing Common Position 2004/85/CFSP",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2005-04-12",
    "bluf": "The EU Common Position 2005/304/CFSP outlines the European Union's strategy for conflict prevention, management, and resolution in Africa. It emphasizes African ownership of these processes, coordination with the African Union (AU) and sub-regional organizations, and alignment with international law and UN Security Council responsibilities. The document establishes a framework for EU support in building African capacities, addressing root causes of conflicts, and implementing peace-building measures. Key focus areas include economic factors fueling conflicts, small arms trafficking, children in armed conflict, HIV/AIDS impacts, and post-conflict reconstruction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32005l0062",
    "title": "Commission Directive 2005/62/EC of 30 September 2005 implementing Directive 2002/98/EC of the European Parliament and of the Council as regards Community standards and specifications relating to a quality system for blood establishments (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2005-09-30",
    "bluf": "COMMISSION DIRECTIVE 2005/62/EC implements Directive 2002/98/EC by establishing Community standards and specifications for a quality system in blood establishments. It applies to all blood establishments involved in the collection, testing, processing, storage, and distribution of human blood and blood components. The directive ensures a high level of human health protection by preventing disease transmission and maintaining equivalent quality and safety standards. It mandates the implementation of a quality system encompassing quality management, assurance, and continuous improvement, including personnel, premises, equipment, documentation, and processes. Blood establishments must comply with these standards, and imported blood components must meet equivalent quality system requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32005m3797",
    "title": "Commission Decision of 15/06/2005 declaring a concentration to be compatible with the common market (Case No COMP/M.3797 - CGE/AMGA/SMAT/SAP) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2005-06-15",
    "bluf": "The Commission Decision of 15/06/2005 declares a concentration involving Compagnie Générale des Eaux (CGE), Azienda Mediterranea Gas e Acqua S.p.A (AMGA), Societa’ Metropolitana Acque Torino S.p.A. (SMAT), and Societa’ Azionaria per la Condotta di Acque potabili S.p.A (SAP) to be compatible with the common market. The decision is based on Article 6(1)(b) of Council Regulation (EC) No. 139/2004 and follows a simplified procedure outlined in the Commission Notice on a simplified procedure for treatment of certain concentrations. The concentration involves joint control of SAP by CGE, AMGA, and SMAT, and the Commission has concluded that the operation does not oppose the common market or the EEA Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32005m4006",
    "title": "Commission Decision on Concentration Compatibility",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The Commission received a notification of a proposed concentration by Credit Agricole SA and Banca Intesa SpA to acquire joint control of Nextra Investment Management SpA. The Commission concluded that the notified operation falls within the scope of Council Regulation (EC) No. 139/2004 and decided not to oppose the operation, declaring it compatible with the common market and the EEA Agreement. The decision was adopted in application of Article 6(1)(b) of Council Regulation (EC) No. 139/2004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-celex-32006d0314",
    "title": "2006/314/EC: Commission Decision of 16 March 2006 approving the Member States’ survey programmes for avian influenza in poultry and wild birds during 2006 (notified under document number C(2006) 780)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2006-03-16",
    "bluf": "Commission Decision 2006/314/EC, adopted on 16 March 2006 and published in the Official Journal of the European Union on 29 April 2006 (L 116/61), approves the Member States' survey programmes for avian influenza in poultry and wild birds for the period from 1 February 2006 to 31 December 2006. The Decision is grounded in Council Decision 90/424/EEC on expenditure in the veterinary field and implements Commission Decision 2006/101/EC, which established the framework for such surveys across EU Member States. All 25 Member States listed in Annex I are required to carry out surveys for avian influenza in poultry and wild birds in accordance with their approved programmes. Those surveys are to investigate the presence of infections in poultry, which could lead to a review of current Community legislation and contribute to the knowledge of the possible threats for animals and humans from the wildlife. The Community financial contribution is fixed at 50% of the costs incurred by each Member State for analysing samples, up to the maximum amounts specified per Member State in Annex I, with a total co-financing ceiling of EUR 1,964,800. To qualify for the financial contribution, Member States must bring into force the necessary implementing provisions, submit a final report by 31 March 2007 to the Commission and the Community Reference Laboratory for avian influenza, provide evidence of costs incurred, and implement the programme efficiently ensuring appropriate sampling is performed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32006d0335",
    "title": "Commission Decision 2006/335/EC: Authorisation for Poland to Prohibit Genetically Modified Maize",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "The European Commission has authorised the Republic of Poland to prohibit the use of 16 genetically modified varieties of maize with the genetic modification MON 810, listed in the Common catalogue of varieties of agricultural plant species, due to their unsuitability for cultivation in Poland. The decision is based on Article 16(2)(b) of Council Directive 2002/53/EC, which allows Member States to restrict the use of certain varieties. The Commission has considered the request from Poland and has determined that the varieties are not suitable for cultivation in the country due to their high maturity class. The decision requires Poland to notify the Commission when it makes use of the authorisation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32006d0747",
    "title": "2006/747/EC: Commission Decision of 26 April 2006 on State Aid which France is planning to implement for Euromoteurs (C 1/2005 (ex N 426/2004)) (notified under document number C(2006) 1540) (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2006-04-26",
    "bluf": "This Commission Decision (2006/747/EC), adopted on 26 April 2006 and published in the Official Journal of the European Union (L 307/213), declares incompatible with the common market the state aid which France was planning to implement for Euromoteurs S.A.S., a French electric motor manufacturer. The aid, notified by France on 5 October 2004, amounts to either €2 million, €2.25 million, or €2.65 million in the form of a government grant and debt write-offs by regional and general councils. The Decision is addressed to the French Republic and states unequivocally that 'the aid may accordingly not be implemented.' The Commission assessed the measure under Article 87(3)(c) of the Treaty and the 1999 Community guidelines on state aid for rescuing and restructuring firms in difficulty. Three principal grounds of incompatibility were identified: first, Euromoteurs had previously received unlawful and incompatible aid under Article 44 septies of the General Tax Code (estimated at approximately €1.7 million), which had not been repaid, creating cumulative undue distortions of competition under the Deggendorf case law; second, the French authorities failed to demonstrate that the restructuring plan was based on realistic assumptions capable of restoring the company's long-term viability, particularly given the unaccounted repayment obligation and underestimated financing needs; and third, France did not demonstrate that aid in excess of €2 million was necessary, meaning the aid was not limited to the minimum required. The Commission concluded that all three compatibility criteria under the 1999 guidelines were unmet.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32006m4283",
    "title": "Commission Decision of 18/08/2006 declaring a concentration to be compatible with the common market (Case No COMP/M.4283 - FOGECA / MAPFRE / JV) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2006-08-31",
    "bluf": "The European Commission decided not to oppose the notified concentration between Korsnäs and Assidomän Cartonboard, declaring it compatible with the common market. This decision is based on Article 6(1)(b) of Council Regulation (EC) No 139/2004. The full text of the decision is available in English and will be made public after it is cleared of any business secrets it may contain. It can be accessed from the Europa competition website or in electronic form on the EUR-Lex website under document number 32006M4057.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32006r0076",
    "title": "Commission Regulation (EC) No 76/2006 of 17 January 2006 amending for the 61st time Council Regulation (EC) No 881/2002 imposing certain specific restrictive measures directed against certain persons and entities associated with Usama bin Laden, the Al-Qaida network and the Taliban, and repealing Council Regulation (EC) No 467/2001",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2006-01-18",
    "bluf": "Commission Regulation (EC) No 76/2006, adopted on 17 January 2006 and published in the Official Journal of the European Union (L 12/7) on 18 January 2006, constitutes the 61st amendment to Council Regulation (EC) No 881/2002. That parent regulation imposes certain specific restrictive measures directed against certain persons and entities associated with Usama bin Laden, the Al-Qaida network and the Taliban, and repealing Council Regulation (EC) No 467/2001 prohibiting the export of certain goods and services to Afghanistan, strengthening the flight ban and extending the freeze of funds and other financial resources in respect of the Taliban of Afghanistan. The core obligation established by this amending regulation is the updating of Annex I to Regulation (EC) No 881/2002, which lists the persons, groups and entities covered by the freezing of funds and economic resources. On 20 December 2005, the Sanctions Committee of the United Nations Security Council decided to amend the list of persons, groups and entities to whom the freezing of funds and economic resources should apply. Annex I is therefore amended accordingly. The regulation is binding in its entirety and directly applicable in all Member States, entering into force on the day of its publication in the Official Journal of the European Union. It applies to all EU Member States and affects any natural or legal person, group, or entity whose identifying information appears in the amended Annex I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32006r2027",
    "title": "Council Regulation (EC) No 2027/2006 of 19 December 2006 on the conclusion of the Fisheries partnership agreement between the European Community and the Republic of Cape Verde",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2006-12-19",
    "bluf": "The Council Regulation (EC) No 2027/2006 approves the Fisheries Partnership Agreement between the European Community and the Republic of Cape Verde. This agreement provides Community fishermen with fishing opportunities in the waters under Cape Verde's sovereignty. The regulation outlines the allocation of fishing opportunities among Member States, the notification of catches, and the authorization for signing the agreement. It applies to all Member States and is directly applicable upon publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32007a0328-01",
    "title": "Council opinion of 27 February 2007 on the updated stability programme of Finland, 2006-2010",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2007-02-27",
    "bluf": "On 27 February 2007, the Council of the European Union examined the updated stability programme of Finland, covering the period 2006 to 2010, pursuant to Council Regulation (EC) No 1466/97 on the strengthening of the surveillance of budgetary positions and the surveillance and coordination of economic policies, and in particular Article 5(3) thereof. The programme was assessed against macroeconomic projections, budgetary targets, debt sustainability, and consistency with the Stability and Growth Pact. The main goal of the medium-term budgetary strategy in the programme is securing sustainability in general government finances and balanced central government finances under normal conditions of economic growth. The medium-term objective (MTO) for the budgetary position presented in the programme is a structural surplus of 2% of GDP, which Finland plans to maintain throughout the programme period. Government gross debt is estimated to have declined to 39% of GDP in 2006, well below the 60% of GDP Treaty reference value. The Council considers that the medium-term budgetary position is sound and the budgetary strategy provides a good example of fiscal policies conducted in compliance with the Stability and Growth Pact. Nevertheless, expenditure restraint will remain crucial in the coming years when the forecast cooling of the economy slows growth in the tax bases and the impact of ageing population kicks in.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32007d0332",
    "title": "2007/332/EC: Commission Decision of 23 April 2007 on public service obligations on certain routes to and from Sardinia under Article 4 of Council Regulation (EEC) No 2408/92 on access for Community air carriers to intra-Community air routes (notified under document number C(2007) 1712)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2007-04-23",
    "bluf": "The Commission Decision addresses public service obligations (PSOs) imposed by the Italian Republic on 16 routes connecting Sardinia with mainland Italy. These PSOs ensure adequate provision of scheduled air services, including continuity, regularity, capacity, and pricing, which air carriers would not assume based solely on commercial interest. The PSOs apply to Community air carriers operating or intending to operate these routes. The Decision outlines conditions for the application of PSOs, including the ability of carriers to operate routes regardless of notification timing, a maximum one-year duration for continuity of service, and reassessment of PSOs upon new carrier entry. The Decision also prohibits undue restrictions, such as grouping routes and applying preferential fares for non-resident Sardinians.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32007d0839",
    "title": "2007/839/EC: Council Decision of 29 November 2007 concerning the conclusion of the Agreement between the European Community and Ukraine on readmission of persons",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2007-12-18",
    "bluf": "The Agreement between the European Community and Ukraine on the readmission of persons establishes procedures for the identification and safe return of individuals who do not meet the conditions for entry or stay in the territories of Ukraine or EU Member States. It applies to nationals of the contracting parties, third-country nationals, and stateless persons. The Agreement includes provisions for readmission applications, evidence requirements, time limits, transit operations, and data protection. It aims to combat illegal immigration and facilitate cooperation between the parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32007m4704",
    "title": "Commission Decision of 26/06/2007 declaring a concentration to be compatible with the common market (Case No COMP/M.4704 - BRIDGEPOINT / GAMBRO HEALTHCARE) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2007-06-30",
    "bluf": "On 26 June 2007, the Commission decided not to oppose the above notified concentration and to declare it compatible with the common market. This decision concerns Case COMP/M.4704 - Bridgepoint/Gambro Healthcare and is based on Article 6(1)(b) of Council Regulation (EC) No 139/2004. The decision was published in the Official Journal of the European Union on 30 June 2007 (C 145/11) and carries EEA relevance. The full text of the decision is available only in English and will be made public after it is cleared of any business secrets it may contain. It will be available from the Europa competition website and in electronic form on the EUR-Lex website under document number 32007M4704. The decision applies to the notified merger concentration between Bridgepoint and Gambro Healthcare, confirming compatibility with the common market under EU merger control rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32007m4916",
    "title": "Commission Decision of 18/10/2007 declaring a concentration to be compatible with the common market (Case No COMP/M.4916 - GE MONEY / BPH) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2007-11-07",
    "bluf": "On 17 October 2007, the Commission decided not to oppose the above notified concentration and to declare it compatible with the common market. This decision concerns Case COMP/M.4879, involving Jabil Circuit, Inc and Nokia Siemens Networks S.p.A. The decision is based on Article 6(1)(b) of Council Regulation (EC) No 139/2004, which governs the assessment of concentrations under EU competition law. The full text of the decision is available only in English and will be made public after it is cleared of any business secrets it may contain. The decision applies to parties involved in the notified concentration and is of relevance to the European Economic Area (EEA). The decision is accessible from the Europa competition website and in electronic form on the EUR-Lex website under document number 32007M4879. EUR-Lex is the on-line access to European law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32008d0170",
    "title": "2008/170/EC: Commission Decision of 27 February 2008 on the adoption of the work plan for 2008 for the implementation of the second programme of Community action in the field of health (2008-2013), and on the selection, award and other criteria for financial contributions to the actions of this programme (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2008-02-27",
    "bluf": "Commission Decision 2008/170/EC, adopted on 27 February 2008, establishes the Annual Work Plan for 2008 for the implementation of the second programme of Community action in the field of health (2008-2013), as established by Decision No 1350/2007/EC of the European Parliament and of the Council. The Decision simultaneously serves as the financing decision for grants and contracts under the Programme, adopts selection, award and other criteria for financial contributions, and sets out the allocation of financial resources across financing mechanisms including calls for proposals, calls for tender, joint actions, operating grants, conferences, and cooperation with international organisations. The Programme applies to EU Member States, EFTA/EEA countries (Iceland, Liechtenstein, Norway), and candidate countries participating in the Programme (including Croatia). The total budget approved for 2008 is EUR 46,600,000, with an estimated total of EUR 47,833,463 when including contributions from EEA/EFTA and candidate countries. The Director-General for Health and Consumer Protection is responsible for overall implementation, while the Public Health Executive Agency (PHEA) is expected to carry out all operations necessary for management of the work plan. Priority areas for 2008 are structured around three strands: improving citizens' health security, promoting health, and generating and disseminating health information and knowledge. Within the maximum indicative budget, cumulated changes not exceeding 20% of the maximum Community contribution are not considered substantial provided they do not significantly affect the nature and objectives of the work plan.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 12
  },
  {
    "node_id": "eu-celex-32008d0189",
    "title": "2008/189/EC: Council Decision of 18 February 2008 on the conclusion of the Agreement between the European Community and the Government of Georgia on certain aspects of air services",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2008-02-18",
    "bluf": "The Council of the European Union, by Decision 2008/189/EC of 18 February 2008, approved the Agreement between the European Community and the Government of Georgia on certain aspects of air services. This decision was adopted having regard to the Treaty establishing the European Community, in particular Article 80(2) in conjunction with Article 300(2) and Article 300(3), first subparagraph, and following the opinion of the European Parliament. The Agreement originates from a Council decision of 5 June 2003 authorising the Commission to open negotiations with third countries on the replacement of certain provisions in existing bilateral agreements by a Community agreement. The Commission negotiated the Agreement on behalf of the Community in accordance with the mechanisms and directives in the Annex to that Decision. The Agreement had previously been signed on behalf of the Community subject to possible conclusion at a later date, in accordance with Council Decision 2006/357/EC. By Article 1 of the present Decision, the Agreement is formally approved on behalf of the Community. By Article 2, the President of the Council is authorised to designate the person empowered to make the notification provided in Article 8.1 of the Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32008d0305",
    "title": "Council Decision on the conclusion of the Agreement between the European Community and the Republic of Panama on certain aspects of air services",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "The Council Decision of 18 February 2008 concludes the Agreement between the European Community and the Republic of Panama on certain aspects of air services. The Agreement aims to establish a sound legal basis for air services between the European Community and the Republic of Panama, ensuring the continuity of such services. It covers aspects such as designation, authorisation, and revocation of air carriers, safety, taxation of aviation fuel, tariffs for carriage, and compatibility with competition rules. The Agreement also provides for the revision or amendment of its provisions by mutual consent and sets out the procedures for its entry into force and termination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32008r0782",
    "title": "Commission Regulation (EC) No 782/2008 of 5 August 2008 approving non-minor amendments to the specification for a name entered in the register of protected designations of origin and protected geographical indications (Laguiole (PDO))",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2008-08-05",
    "bluf": "Commission Regulation (EC) No 782/2008, adopted on 5 August 2008 by the Commission of the European Communities, approves non-minor amendments to the product specification for the protected designation of origin 'Laguiole', a cheese classified under Class 1.3 (Cheeses) in France. The regulation was adopted having regard to Council Regulation (EC) No 510/2006 of 20 March 2006 on the protection of geographical indications and designations of origin for agricultural products and foodstuffs, and in particular the first subparagraph of Article 7(4) thereof. The Commission examined France's application for the approval of amendments to the specification of the protected designation of origin 'Laguiole', which was originally registered on the basis of Commission Regulation (EC) No 1107/96. Since the amendments in question are not minor within the meaning of Article 9 of Regulation (EC) No 510/2006, the Commission published the amendment application in the Official Journal of the European Union as required by the first subparagraph of Article 6(2) of that Regulation. As no statement of objection within the meaning of Article 7 of Regulation (EC) No 510/2006 was sent to the Commission, the amendments were approved. This Regulation is binding in its entirety and directly applicable in all Member States, entering into force on the 20th day following its publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32009d0367",
    "title": "2009/367/EC: Commission Decision of 29 April 2009 on the clearance of the accounts of the paying agencies of Member States concerning expenditure financed by the European Agricultural Guarantee Fund (EAGF) for the 2008 financial year (notified under document number C(2009) 3217)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2009-04-29",
    "bluf": "The Commission Decision of 29 April 2009 addresses the clearance of accounts for Member States' paying agencies concerning expenditure financed by the European Agricultural Guarantee Fund (EAGF) for the 2008 financial year. It applies to Member States and their paying agencies, requiring them to submit annual accounts accompanied by necessary information and certificates for clearance. The Commission checks the submitted accounts and clears them based on completeness, accuracy, and veracity. Certain accounts require additional inquiries and are disjoined from this decision. The Decision also addresses reductions and suspensions of payments, recovery of irregularities, and financial consequences for non-recovery.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32009l0008",
    "title": "Commission Directive 2009/8/EC of 10 February 2009 amending Annex I to Directive 2002/32/EC of the European Parliament and of the Council as regards maximum levels of unavoidable carry-over of coccidiostats or histomonostats in non-target feed (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2009-02-10",
    "bluf": "The directive establishes maximum levels for unavoidable carry-over of coccidiostats and histomonostats in non-target feed to ensure animal and public health protection. It applies to feed business operators producing animal feed, requiring them to adhere to specified maximum contamination levels for various substances. The directive mandates that operators take all appropriate measures to avoid cross-contamination during production, storage, and transport, following the ALARA (As Low As Reasonably Achievable) principle. Maximum carry-over rates are set at approximately 3% for less sensitive non-target animal species and 1% for sensitive species and withdrawal feed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32009l0045",
    "title": "Directive 2009/45/EC of the European Parliament and of the Council of 6 May 2009 on safety rules and standards for passenger ships (Recast) (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2009-06-25",
    "bluf": "Directive 2009/45/EC establishes a uniform level of safety of life and property on new and existing passenger ships and high-speed passenger craft when engaged on domestic voyages within the European Community, and lays down procedures for negotiation at international level with a view to harmonisation of rules for passenger ships engaged on international voyages. The Directive applies to new passenger ships, existing passenger ships of 24 metres in length and above, and high-speed passenger craft, regardless of their flag, when engaged on domestic voyages. Each Member State, in its capacity as host State, must ensure that passenger ships and high-speed passenger craft flying the flag of a non-Member State fully comply with the requirements of this Directive before they may be engaged on domestic voyages. Passenger ships are divided into Classes A, B, C, and D according to the sea area in which they operate, with safety requirements calibrated to each class. The main reference framework for safety standards is the 1974 International Convention for the Safety of Life at Sea (the 1974 SOLAS Convention), as amended. Compliance must be certified by or on behalf of the Administration of the flag State, and surveys are required before service and periodically every 12 months. Member States must lay down effective, proportionate and dissuasive penalties for infringements of national provisions adopted pursuant to this Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32009l0055",
    "title": "Directive 2009/55/EC - Tax Exemptions on the Permanent Introduction of Personal Property from Another Member State",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Directive 2009/55/EC requires every Member State to exempt personal property permanently introduced from another Member State by a private individual from the consumption taxes that normally apply to such property. The exemption does not cover value added tax, excise duty, or use-related charges such as motor vehicle registration fees, road taxes and television licences. To qualify, the property must be for personal or household use and not reflect a commercial interest, must have been acquired under the general taxation conditions of a Member State without any exit exemption or refund, and must have been in the individual's actual use before the change of residence (at least six months generally, and up to twelve months for vehicles, caravans, pleasure boats and private aircraft where the Member State so requires). For those higher-value goods the exemption is granted only where the individual transfers normal residence (the place where the person usually lives for at least 185 days per calendar year) to the destination Member State. The individual must prove residence, draw up an inventory of the property (no value reference may be demanded), introduce the last of the property within twelve months of the transfer, and must not dispose of, hire out or lend exempted vehicles, boats or aircraft within twelve months of introduction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_primary_law",
        "related_instruments",
        "scope_exclusions",
        "tax_type"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-vat-directive-2006-112-consolidated",
      "eu-union-customs-code-952-2013"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32009r0573",
    "title": "Commission Regulation (EC) No 573/2009 of 29 June 2009 initiating a new exporter review of Council Regulation (EC) No 1338/2006 imposing a definitive anti-dumping duty on imports of chamois leather originating in the People’s Republic of China, repealing the duty with regard to imports from one exporting producer in this country and making these imports subject to registration",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2009-06-29",
    "bluf": "Commission Regulation (EC) No 573/2009, adopted on 29 June 2009, initiates a 'new exporter' review pursuant to Article 11(4) of Council Regulation (EC) No 384/96 (the basic Regulation) concerning the definitive anti-dumping duty of 58.9% imposed by Council Regulation (EC) No 1338/2006 on imports of chamois leather and combination chamois leather originating in the People's Republic of China. The review was triggered by an application from Henan Prosper Skins & Leather Enterprise Co., Ltd, an exporting producer in China, which alleges it did not export the product concerned to the Community during the original investigation period (1 April 2004 to 31 March 2005), is not related to any exporting producer subject to existing measures, and has begun exporting to the Community after the end of that period. The Regulation repeals the anti-dumping duty with respect to imports produced and sold for export to the Community by the applicant, and simultaneously directs customs authorities to register those imports pursuant to Article 14(5) of the basic Regulation, so that duties may be levied retroactively from the date of initiation if dumping is found. Interested parties must make themselves known, submit questionnaire replies, and present written views within 40 days of entry into force. Claims for market economy treatment or individual treatment must also reach the Commission within 40 days. Comments on the appropriateness of the United States of America as the analogue market-economy country must be submitted within 10 days. Non-cooperation or submission of false or misleading information may result in findings based on facts available under Article 18 of the basic Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32009r1176",
    "title": "Commission Regulation (EC) No 1176/2009 of 30 November 2009 entering a name in the register of protected designations of origin and protected geographical indications (Redykołka (PDO))",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2009-11-30",
    "bluf": "COMMISSION REGULATION (EC) No 1176/2009 enters the name 'Redykołka' into the register of protected designations of origin and protected geographical indications (PDO). This regulation applies to agricultural products intended for human consumption, specifically cheeses from Poland. The regulation was adopted after Poland’s application was published in the Official Journal of the European Union and no objections were received. The regulation is binding in its entirety and directly applicable in all Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32010d0107",
    "title": "2010/107/CFSP: Council Decision 2010/107/CFSP of 22 February 2010 extending the mandate of the European Union Special Representative for the Middle East peace process",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2010-02-22",
    "bluf": "Council Decision 2010/107/CFSP, adopted on 22 February 2010 and published in the Official Journal of the European Union (L 46/8), extends the mandate of Mr Marc OTTE as the European Union Special Representative (EUSR) for the Middle East peace process until 31 August 2010, with application from 1 March 2010. The mandate may be terminated earlier if the Council so decides, on a recommendation of the High Representative of the Union for Foreign Affairs and Security Policy (HR) following the entry into force of the decision establishing the European External Action Service. The EUSR shall act under the authority of the HR and in close coordination with the Political and Security Committee (PSC), which serves as the primary point of contact with the Council. Core obligations include: providing an active and efficient contribution to actions leading to a final settlement of the Israeli-Palestinian, Israeli-Syrian, and Israeli-Lebanese conflicts; facilitating contact with all parties to the peace process; observing and supporting peace negotiations; monitoring roadmap implementation; engaging on Security Sector Reform; and reporting regularly to the HR and PSC via oral, written, and COREU network reports. A financial reference amount of EUR 730 000 is allocated for the period 1 March 2010 to 31 August 2010, managed under a contract between the EUSR and the Commission, to whom the EUSR is fully accountable for all expenditure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32010d0352",
    "title": "2010/352/: Commission Decision of 22 June 2010 on a Union financial contribution towards Member States’ fisheries control, inspection and surveillance programmes for 2010 (notified under document C(2010) 3940)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2010-06-22",
    "bluf": "This Decision provides for a Union financial contribution for 2010 towards expenditure incurred by Member States for 2010 in implementing the monitoring and control systems applicable to the common fisheries policy (CFP), as referred to in Article 8(a) of Regulation (EC) No 861/2006. It establishes the maximum amount of the Union financial contribution for each Member State, the rate of the Union financial contribution and the conditions on which such contribution may be granted. Applications concerning actions listed in Article 8(a) of Regulation (EC) No 861/2006 may qualify for Union funding. Applications for Union funding are to comply with the rules set out in Commission Regulation (EC) No 391/2007.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32010d0357",
    "title": "2010/357/: Commission Decision of 2 December 2009 on the State aid C 39/08 (ex N 148/08) planned by Romania for training by Ford Craiova (notified under document C(2009) 9350) (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2009-12-02",
    "bluf": "The European Commission approved a EUR 57 million State aid from Romania to Ford Romania SA for a comprehensive 5-year training programme. The aid supports training for both existing and future employees at the Craiova car plant, aiming to enhance skills and employability. The training programme is divided into four main blocks: Safety, Core Skills, Business Fundamentals, and Industrial Skills. The aid is justified by its potential to redress underinvestment in training and generate positive externalities, particularly in a disadvantaged region. The Commission assessed the aid under Article 107(3)(c) TFEU, ensuring it does not adversely affect trading conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32010m5780",
    "title": "Commission Decision of 17/02/2010 declaring a concentration to be compatible with the common market (Case No COMP/M.5780 - ALLIANZ / ING / ALLEE CENTER) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2010-02-17",
    "bluf": "On 17 February 2010, the European Commission decided not to oppose the notified concentration involving Allianz, ING, and Allee Center, declaring it compatible with the common market. This decision is based on Article 6(1)(b) of Council Regulation (EC) No 139/2004. The full text of the decision is available only in English and will be made public after it is cleared of any business secrets it may contain. The decision can be accessed in the merger section of the Competition website of the Commission and in electronic form on the EUR-Lex website under document number 32010M5780.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32010m5794",
    "title": "Commission Decision of 26/03/2010 declaring a concentration to be compatible with the common market (Case No COMP/M.5794 - RAMSAY HEALTH CARE / PREDICA / GROUPE PROCLIF) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2010-03-25",
    "bluf": "On 25 March 2010, the Commission decided not to oppose the above notified concentration and to declare it compatible with the common market. This decision concerns Case COMP/M.5817 - Triton Fund III/Ambea and is published in the Official Journal of the European Union (C 90/1) dated 8 April 2010. The decision is based on Article 6(1)(b) of Council Regulation (EC) No 139/2004, which governs the control of concentrations between undertakings under EU competition law. The full text of the decision is available only in English and will be made public after it is cleared of any business secrets it may contain. The decision will be accessible in the merger section of the Competition website of the Commission and in electronic form on the EUR-Lex website under document number 32010M5817. This notice is of relevance to the European Economic Area (EEA). The core obligation established by this notice is transparency and public accessibility of merger decisions once business secrets have been removed, ensuring that affected parties and the public can locate and review the Commission's compatibility determination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32010m5826",
    "title": "Commission Decision of 09/08/2010 declaring a concentration to be compatible with the common market (Case No COMP/M.5826 - ANGLO IRISH BANK / RBS / ARNOTTS) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2010-08-09",
    "bluf": "The European Commission has declared a concentration involving Anglo Irish Bank, RBS, and Arnotts Holdings Limited to be compatible with the common market under Council Regulation (EC) No 139/2004. The decision, dated 09/08/2010, concludes that the transaction does not raise serious doubts as to its compatibility with the internal market and the EEA Agreement. The concentration involves the restructuring of Arnotts’ existing debt in return for warrants, call options, and associated control rights, resulting in joint control by Anglo Irish Bank and RBS over Arnotts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32010m5958",
    "title": "Commission Decision of 30/09/2010 declaring a concentration to be compatible with the common market (Case No COMP/M.5958 - GS / TPG / ONTEX) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2010-09-30",
    "bluf": "On 26 August 2010, the European Commission received a notification of a proposed concentration pursuant to Article 4 of Council Regulation (EC) No 139/2004, by which Goldman Sachs Group, Inc. and TPG Holdings I, L.P. acquire joint control of Ontex International N.V. by way of purchase of shares. Goldman Sachs and TPG each agreed to indirectly acquire 50% of the equity in Whitelabel IV, an acquisition vehicle formed for the purposes of the transaction, and will, on the basis of the corporate governance rules, indirectly exercise joint control over Ontex. The operation constitutes a concentration within the meaning of Article 3(1)(b) of the Merger Regulation. The undertakings concerned have a combined aggregate world-wide turnover of more than EUR 5,000 million, and each has an EU-wide turnover in excess of EUR 250 million, giving the notified operation an EU dimension pursuant to Article 1(2) of the Merger Regulation. The Commission assessed horizontal and vertical competitive effects, finding no horizontal overlaps and no serious doubts as to input or customer foreclosure arising from the vertical relationship between Vita (a nonwovens supplier controlled by TPG) and Ontex. The European Commission decided not to oppose the notified operation and declared it compatible with the internal market and with the EEA Agreement, in application of Article 6(1)(b) of the Merger Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32010r0260",
    "title": "Commission Regulation (EU) No 260/2010 of 25 March 2010 entering a name in the register of protected designations of origin and protected geographical indications (Chirimoya de la Costa tropical de Granada-Málaga (PDO))",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2010-03-25",
    "bluf": "The European Commission has adopted Regulation (EU) No 260/2010 to enter the name 'Chirimoya de la Costa tropical de Granada-Málaga' into the register of protected designations of origin and protected geographical indications (PDO). This regulation applies to agricultural products intended for human consumption, specifically fruit, vegetables, and cereals, fresh or processed, under Class 1.6. The name was published in the Official Journal of the European Union, and no objections were received, leading to its registration. The regulation is binding in its entirety and directly applicable in all Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32010r0372",
    "title": "Commission Regulation (EU) No 372/2010 of 30 April 2010 amending for the 126th time Council Regulation (EC) No 881/2002 imposing certain specific restrictive measures directed against certain persons and entities associated with Usama bin Laden, the Al-Qaida network and the Taliban",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2010-04-30",
    "bluf": "Commission Regulation (EU) No 372/2010, adopted on 30 April 2010, amends for the 126th time Council Regulation (EC) No 881/2002, which imposes certain specific restrictive measures directed against certain persons and entities associated with Usama bin Laden, the Al-Qaida network and the Taliban. The regulation is directly applicable in all Member States and entered into force on the day of its publication in the Official Journal of the European Union. The amendment updates Annex I to Regulation (EC) No 881/2002, which lists the persons, groups and entities covered by the freezing of funds and economic resources. On 22 April 2010, the Sanctions Committee of the United Nations Security Council decided to add two natural persons to its list and to remove one natural person from the list. Accordingly, this Regulation adds Mohamed Belkalem and Tayeb Nail - both identified as members of The Organization of Al-Qaida in the Islamic Maghreb and believed to be in Mali - to the list of designated individuals subject to asset freezing measures, and removes Ahmed Said Zaki Khedr, reportedly deceased in October 2003, from the list. In order to ensure that the measures provided for in this Regulation are effective, this Regulation entered into force immediately upon publication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32010r0791",
    "title": "Commission Regulation (EU) No 791/2010 of 6 September 2010 amending Regulation (EC) No 474/2006 establishing the Community list of air carriers which are subject to an operating ban within the Community Text with EEA relevance",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2010-09-06",
    "bluf": "Commission Regulation (EU) No 791/2010 amends Regulation (EC) No 474/2006, establishing the Community list of air carriers subject to an operating ban within the European Union. This regulation applies to air carriers identified as posing serious safety risks. The core obligation is to update the list of banned carriers based on safety assessments and exceptional measures taken by Member States. The regulation ensures that carriers failing to meet safety standards are prohibited from operating within the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32011d0286",
    "title": "2011/286/EU: Decision of the European Parliament and of the Council of 2 May 2011 on mobilisation of the European Union Solidarity Fund, in accordance with point 26 of the Interinstitutional Agreement of 17 May 2006 between the European Parliament, the Council and the Commission on budgetary discipline and sound financial management",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2011-05-19",
    "bluf": "The European Union has created a European Union Solidarity Fund (the 'Fund') to show solidarity with the population of regions struck by disasters. This Decision, adopted by the European Parliament and the Council on 2 May 2011 and published in the Official Journal of the European Union on 19 May 2011, mobilises the Fund in accordance with point 26 of the Interinstitutional Agreement of 17 May 2006 between the European Parliament, the Council and the Commission on budgetary discipline and sound financial management. The core obligation established by this Decision is that, for the general budget of the European Union for the financial year 2011, the European Union Solidarity Fund shall be mobilised to provide the sum of EUR 182 388 893 in commitment and payment appropriations. This mobilisation was triggered by applications submitted by Poland, Slovakia, Hungary, the Czech Republic, Croatia and Romania concerning disaster caused by landslides and heavy flooding. The Interinstitutional Agreement of 17 May 2006 allows the mobilisation of the Fund within the annual ceiling of EUR 1 billion, and the legal basis for mobilisation is provided by Council Regulation (EC) No 2012/2002 of 11 November 2002 establishing the European Union Solidarity Fund.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32011d0464",
    "title": "2011/464/EU: Council Decision of 18 July 2011 on the signing, on behalf of the Union, of the Agreement between the European Union and New Zealand amending the Agreement on mutual recognition in relation to conformity assessment between the European Community and New Zealand",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2011-07-18",
    "bluf": "Council Decision 2011/464/EU, adopted on 18 July 2011 and published in the Official Journal of the European Union (L 195/1) on 27 July 2011, authorises the signing, on behalf of the European Union, of the Agreement between the European Union and New Zealand amending the Agreement on mutual recognition in relation to conformity assessment between the European Community and New Zealand. The original Agreement on Mutual Recognition between the European Community and New Zealand entered into force on 1 January 1999. On 8 July 2002, the Council authorised the Commission to open negotiations with New Zealand with a view to amending that Agreement, and those negotiations were successfully concluded by the initialling of the amending Agreement in Brussels on 29 June 2009. As a consequence of the entry into force of the Treaty of Lisbon on 1 December 2009, the European Union replaced and succeeded the European Community. The Decision authorises the signing of the amending Agreement subject to its conclusion, designates the President of the Council to empower person(s) to sign on behalf of the Union, and entered into force on the day of its adoption. The text of the Agreement itself was to be published together with the Decision on its conclusion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32011d0683",
    "title": "Council Implementing Decision of 11 October 2011 amending Implementing Decision 2011/344/EU on granting Union financial assistance to Portugal",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2011-10-11",
    "bluf": "The Council of the European Union has amended Implementing Decision 2011/344/EU to extend maturities and reduce the interest rate margin for financial assistance granted to Portugal. The Union shall make available to Portugal a loan amounting to a maximum of EUR 26 billion, with a maximum average maturity of 12.5 years. The maturity of individual tranches of the loan may be of up to 30 years. Portugal shall pay the cost of funding of the Union for each tranche. These amendments apply to tranches disbursed before the entry into force of this Decision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32011d0702-01",
    "title": "Commission Implementing Decision of 1 July 2011 concerning the financing for the year 2011 of activities in the veterinary field related to the European Union's information policy, support of international organisations, disease notification and computerisation of veterinary procedures",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2011-07-01",
    "bluf": "This Commission Implementing Decision, adopted on 1 July 2011 and published in the Official Journal of the European Union (C 193/3), establishes the annual work programme and financing decision for European Union activities in the veterinary field for the year 2011. It is grounded in Council Decision 2009/470/EC of 25 May 2009 on expenditure in the veterinary field, and in particular Articles 20, 23, 35(2), 36(2) and 41 thereof, as well as Article 75 of the Financial Regulation and Article 90(1) of the Implementing Rules. The Decision authorises a maximum contribution of EUR 5 370 000 to be financed from budget line 17040201 of the General Budget of the European Union for 2011. The work programme contains eight implementing measures covering: grants for global conferences and regional seminars on animal health and welfare organised by the World Organisation for Animal Health (OIE), up to EUR 660 000; procurement contracts for publications and dissemination promoting the Animal Health Strategy (EUR 1 500 000); studies and events on animal welfare policy (EUR 575 000 and EUR 210 000); technical improvements to the Animal Disease Notification System (ADNS) (EUR 350 000); hosting, management and maintenance of the integrated computerised veterinary system TRACES (EUR 1 975 000); and studies supporting a report on animal health situation and cost-effectiveness of disease eradication programmes (EUR 100 000). Grants may be awarded directly to the OIE without a call for proposals, as it holds a de facto monopoly as standard-setting body under the WTO/SPS Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32011d0857",
    "title": "Council Decision 2011/857/CFSP of 19 December 2011 amending and extending Joint Action 2005/889/CFSP on establishing a European Union Border Assistance Mission for the Rafah Crossing Point (EU BAM Rafah)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2011-12-19",
    "bluf": "Council Decision 2011/857/CFSP, adopted on 19 December 2011 and published in the Official Journal of the European Union (L 338/52) on 21 December 2011, amends and extends Joint Action 2005/889/CFSP on establishing a European Union Border Assistance Mission for the Rafah Crossing Point (EU BAM Rafah). The Decision extends EU BAM Rafah from 1 January 2012 until 30 June 2012 on the basis of its current mandate, following a recommendation by the Political and Security Committee (PSC) on 8 November 2011 for a technical extension of a further 6 months. The Decision applies to EU BAM Rafah and its personnel, establishing obligations relating to security planning, compliance with minimum security requirements, and mandatory security training for all staff before taking up their duties. The Civilian Operation Commander is directed to plan security measures and ensure their proper and effective implementation, while the Head of Mission bears responsibility for the security of EU BAM Rafah. A financial reference amount of EUR 970 000 is set to cover expenditure for the period from 1 January 2012 to 30 June 2012, in addition to the EUR 21 570 000 covering the period from 25 November 2005 to 31 December 2011. The Decision enters into force on the date of its adoption and applies from 1 January 2012.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32011l0046",
    "title": "Commission Implementing Directive 2011/46/EU of 14 April 2011 amending Council Directive 91/414/EEC to include hexythiazox as active substance and amending Commission Decision 2008/934/EC Text with EEA relevance",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2011-04-14",
    "bluf": "Commission Implementing Directive 2011/46/EU, adopted on 14 April 2011 and published in the Official Journal of the European Union (L 101/20) on 15 April 2011, amends Council Directive 91/414/EEC to include hexythiazox as an active substance in Annex I, thereby enabling Member States to grant authorisations for plant protection products containing this substance. The Directive also amends Commission Decision 2008/934/EC by deleting the line concerning hexythiazox, which had previously provided for its non-inclusion and the withdrawal of authorisations for plant protection products containing that substance by 31 December 2011. The Directive applies to all Member States of the European Union and imposes specific obligations regarding the review, amendment, or withdrawal of existing authorisations for plant protection products containing hexythiazox. Member States must adopt and publish the necessary laws, regulations and administrative provisions by 30 November 2011 and apply those provisions from 1 December 2011. Only uses as acaricide may be authorised. Member States must pay particular attention to the protection of aquatic organisms and operators and workers safety. Confirmatory information on the toxicological relevance of metabolite PT-1-3, its potential occurrence in processed commodities, potential adverse effects on bee brood, and the possible impact of preferential degradation of the mixture of isomers must be submitted to the Commission by specified deadlines. The inclusion of hexythiazox in Annex I entered into force on 1 June 2011 and expires on 31 May 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 12
  },
  {
    "node_id": "eu-celex-32011m6357",
    "title": "Commission Decision of 23/11/2011 declaring a concentration to be compatible with the common market (Case No COMP/M.6357 - KONINKLIJKE PHILIPS / INDAL GROUP) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2011-11-23",
    "bluf": "On 17 October 2011, the European Commission received notification of a proposed concentration pursuant to Article 4 of the Merger Regulation by which Koninklijke Philips Electronics N.V. (Philips, the Netherlands) acquires within the meaning of Article 3(1)(b) of the Merger Regulation control of the whole of the undertaking Industrias Derivadas del Aluminio, S.A. (Indal, Spain) by way of purchase of shares. The transaction is structured as a stock purchase by virtue of which Philips will acquire all of the issued and outstanding capital stock of Indal, resulting in the acquisition of sole control of Indal by Philips, and therefore constitutes a concentration within the meaning of Article 3(1)(b) of the EU Merger Regulation. The undertakings concerned have a combined aggregate worldwide turnover of more than EUR 5,000 million (Philips: EUR 25,418 million; Indal EUR 156 million). The notified operation has an EU dimension pursuant to Article 1(3) of the EU Merger Regulation. The acquisition gives rise to horizontal overlaps in professional light fixtures across multiple EEA Member States and vertical integration between a producer of light sources and components (Philips) and a producer of fixtures (Indal). The Commission assessed competitive effects across professional indoor and outdoor light fixture markets, LED fixtures, general purpose lamps, horticultural lamps, LEDs and LED modules, and components for light fixtures, ultimately concluding pursuant to Article 6(1)(b) of Council Regulation No 139/2004 that the concentration is compatible with the common market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32011r0382",
    "title": "Commission Implementing Regulation (EU) No 382/2011 of 18 April 2011 entering a name in the register of traditional specialities guaranteed ( ‘Kiełbasa myśliwska’ (TSG))",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2011-04-18",
    "bluf": "Commission Implementing Regulation (EU) No 382/2011, adopted on 18 April 2011 and published in the Official Journal of the European Union (L 103/6), enters the name 'Kiełbasa myśliwska' into the register of traditional specialities guaranteed (TSG) under Council Regulation (EC) No 509/2006 on agricultural products and foodstuffs as traditional specialities guaranteed. The regulation is binding in its entirety and directly applicable in all Member States, entering into force on the 20th day following its publication in the Official Journal of the European Union. The registration follows Poland's application to register the name 'Kiełbasa myśliwska', which was published in the Official Journal of the European Union pursuant to Article 8(2) of Regulation (EC) No 509/2006. A statement of objection was submitted and, following consultations invited by the Commission in its letter dated 27 January 2010, an agreement was reached within 6 months without modification of the published details. The protection referred to in Article 13(2) of Regulation (EC) No 509/2006 has not been requested. The product is classified under Class 1.2 - Meat products (cooked, salted, smoked, etc.) among products listed in Annex I to the EC Treaty intended for human consumption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32011r0824",
    "title": "Council Implementing Regulation (EU) No 824/2011 of 12 August 2011 terminating the partial reopening of the anti-dumping interim review investigation concerning imports of polyethylene terephthalate (PET) film originating in India",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2011-08-12",
    "bluf": "The regulation terminates the partial reopening of the anti-dumping interim review investigation concerning imports of polyethylene terephthalate (PET) film originating in India, specifically manufactured by MTZ Polyfilms Ltd. The General Court had annulled the previous amending Regulation (EC) No 366/2006 as it applied to MTZ Polyfilms, finding it was adopted on an incorrect legal basis. The Council concludes that reimposing an anti-dumping duty on MTZ Polyfilms would be inappropriate due to the lack of recent imports and the unavailability of reliable export price data. The regulation directly applies to MTZ Polyfilms and relevant EU member states, ensuring no anti-dumping duties are imposed on their PET film imports under this proceeding.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32011r1295",
    "title": "Council Regulation (EU) No 1295/2011 of 13 December 2011 amending Regulation (EU) No 1284/2009 imposing certain specific restrictive measures in respect of the Republic of Guinea",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2011-12-13",
    "bluf": "Council Regulation (EU) No 1295/2011 amends Regulation (EU) No 1284/2009 to impose specific restrictive measures in respect of the Republic of Guinea. These measures are in response to the violent crackdown by security forces on political demonstrators in Conakry on 28 September 2009. The regulation modifies the scope of measures relating to military equipment and equipment capable of being used for internal repression. It authorizes, in duly justified cases, the sale, supply, transfer, or export of equipment for humanitarian or protective use, institution-building programmes of the United Nations and the European Union, and crisis management operations. The regulation also permits the provision of financing, financial assistance, technical assistance, brokering services, and other services related to such equipment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32012d0174",
    "title": "Council Decision 2012/174/CFSP of 23 March 2012 amending Joint Action 2008/851/CFSP on a European Union military operation to contribute to the deterrence, prevention and repression of acts of piracy and armed robbery off the Somali coast",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2012-03-23",
    "bluf": "Council Decision 2012/174/CFSP, adopted on 23 March 2012 and published in the Official Journal of the European Union (L 89/69, 27.3.2012), amends Joint Action 2008/851/CFSP governing the EU military operation known as 'Atalanta'. The Decision extends the operation until 12 December 2014, expands its area of operations to include Somali internal waters and Somali land territory, and sets the financial reference amount for common costs at EUR 14 900 000 for the period from 13 December 2012 to 12 December 2014. Atalanta is mandated to protect vessels of the World Food Programme delivering food aid to displaced persons in Somalia, protect vulnerable vessels cruising off the Somali coast, and deter, prevent and repress acts of piracy and armed robbery off the Somali coast, in accordance with UNSC Resolutions 1814 (2008), 1816 (2008), 1838 (2008), 1846 (2008) and 1851 (2008), and consistent with the United Nations Convention on the Law of the Sea. The Decision also establishes conditions for the transfer of arrested and detained suspects to competent authorities of Member States or third States, requiring that no person may be transferred unless conditions have been agreed consistent with relevant international law, notably international law on human rights, guaranteeing in particular that no one shall be subjected to the death penalty, to torture or to any cruel, inhuman or degrading treatment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32012d0257",
    "title": "2012/257/EU: Commission Decision of 11 May 2012 concerning the non-inclusion of naled for product type 18 in Annex I, IA or IB to Directive 98/8/EC of the European Parliament and of the Council concerning the placing of biocidal products on the market (notified under document C(2012) 3050) Text with EEA relevance",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2012-05-11",
    "bluf": "The European Commission has decided not to include naled for product type 18 in Annex I, IA or IB to Directive 98/8/EC, which concerns the placing of biocidal products on the market. This decision applies to biocidal products used as insecticides, acaricides, and products to control other arthropods containing naled. The assessment demonstrated that these products cannot satisfy the requirements laid down in Article 5 of Directive 98/8/EC, showing potential and unacceptable risks in human health and environmental risk assessments, as well as insufficient efficacy. Consequently, biocidal products of product type 18 containing naled shall no longer be placed on the market with effect from 1 November 2012.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32012d0535",
    "title": "2012/535/EU: Commission Implementing Decision of 26 September 2012 on emergency measures to prevent the spread within the Union of Bursaphelenchus xylophilus (Steiner et Buhrer) Nickle et al. (the pine wood nematode) (notified under document C(2012) 6543)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2012-09-26",
    "bluf": "Commission Implementing Decision 2012/535/EU, adopted on 26 September 2012 and published in the Official Journal of the European Union on 2 October 2012, establishes emergency measures to prevent the spread of Bursaphelenchus xylophilus (the pine wood nematode, hereinafter 'PWN') within the Union. The Decision repeals Commission Decision 2006/133/EC and extends the scope of PWN measures from Portugal to all Member States, in response to PWN outbreaks in Spain and repeated interceptions by other Member States of PWN-infested pine wood, wood packaging material and bark from Portugal. The economic, social and environmental impact of PWN spread across the Union is described as unacceptably large. The Decision is addressed to the Member States and imposes obligations including: annual surveys for PWN presence in areas where it is not known to occur; establishment of contingency plans by 31 December 2013; demarcation of infested and buffer zones upon confirmed PWN presence; implementation of eradication measures (including clear-cut zones with a minimum radius of 500 m) for a minimum of four years before containment may be considered; restrictions on movement of susceptible plants, susceptible wood and bark within and out of demarcated areas; authorisation and supervision of treatment facilities and wood packaging material producers; and communication of measures, survey results and demarcated areas to the Commission and other Member States. The Decision is to be reviewed by 31 July 2015 at the latest.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 12
  },
  {
    "node_id": "eu-celex-32012r0034",
    "title": "Commission Implementing Regulation (EU) No 34/2012 of 17 January 2012 amending for the 163rd time Council Regulation (EC) No 881/2002 imposing certain specific restrictive measures directed against certain persons and entities associated with the Al-Qaida network",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2012-01-18",
    "bluf": "This regulation amends Annex I to Council Regulation (EC) No 881/2002, updating the list of persons, groups, and entities associated with the Al-Qaida network subject to the freezing of funds and economic resources. The amendment follows a decision by the Sanctions Committee of the United Nations Security Council on 13 December 2011 to amend 101 entries on the list. The regulation is binding and directly applicable in all EU Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32012r0555",
    "title": "Commission Regulation (EU) No 555/2012 of 22 June 2012 amending Regulation (EC) No 184/2005 of the European Parliament and of the Council on Community statistics concerning balance of payments, international trade in services and foreign direct investment, as regards the update of data requirements and definitions",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2012-06-22",
    "bluf": "COMMISSION REGULATION (EU) No 555/2012 amends Regulation (EC) No 184/2005 concerning Community statistics on balance of payments, international trade in services, and foreign direct investment. The regulation updates data requirements and definitions to align with international standards. It applies to all Member States and enters into force on the 20th day following its publication in the Official Journal of the European Union, with application from 1 January 2014.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32012r0556",
    "title": "Commission Regulation (EU) No 556/2012 of 26 June 2012 amending Annex III to Regulation (EC) No 396/2005 of the European Parliament and of the Council as regards maximum residue levels for spinosad in or on raspberries Text with EEA relevance",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2012-06-26",
    "bluf": "The regulation amends Annex III to Regulation (EC) No 396/2005 to set temporary maximum residue levels (MRLs) for spinosad in or on raspberries. This amendment was necessitated by an unexpected outbreak of Drosophila suzukii in France, which required the temporary authorization of plant protection products containing spinosad. The European Food Safety Authority assessed the consumer risk and concluded that the temporary MRL of 0.9 mg/kg for raspberries does not pose a public health concern. The regulation applies to all Member States and is directly applicable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32012r0651",
    "title": "Regulation (EU) No 651/2012 of the European Parliament and of the Council of 4 July 2012 on the issuance of euro coins",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2012-07-27",
    "bluf": "Regulation (EU) No 651/2012 establishes binding rules for the issuance of euro coins by Member States whose currency is the euro, addressing the lack of mandatory provisions that previously resulted in different practices among Member States and failed to achieve a sufficiently integrated framework for the single currency. The Regulation covers three types of euro coin: circulation coins, commemorative coins, and collector coins, each subject to distinct legal requirements regarding issuance, volume limits, legal tender status, and physical characteristics. Member States may issue circulation coins at face value, with a minor proportion not exceeding 5% of the cumulated total net value and volume permitted to be sold above face value under specific conditions. Commemorative coins are limited to two issues per year per Member State, subject to volume ceilings tied to the cumulated total net number of 2-euro coins in circulation. Collector coins have legal tender status only in the issuing Member State, must be readily distinguishable from circulation coins through defined physical criteria, and Member States must take all appropriate measures to discourage their use as a means of payment. Prior to the destruction of fit circulation coins, Member States are required to consult each other via the relevant subcommittee of the Economic and Financial Committee and inform the mint directors of euro-area Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32012r0841",
    "title": "Commission Implementing Regulation (EU) No 841/2012 of 18 September 2012 concerning the authorisation of Lactobacillus plantarum (NCIMB 41028) and Lactobacillus plantarum (NCIMB 30148) as feed additives for all animal species Text with EEA relevance",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2012-09-18",
    "bluf": "Commission Implementing Regulation (EU) No 841/2012, adopted on 18 September 2012 and entering into force on 19 November 2012, authorises the micro-organisms Lactobacillus plantarum (NCIMB 41028) and Lactobacillus plantarum (NCIMB 30148) as feed additives for all animal species, classified in the additive category 'technological additives' and the functional group 'silage additives'. The authorisation is grounded in Regulation (EC) No 1831/2003 on additives for use in animal nutrition, and follows a positive opinion from the European Food Safety Authority (EFSA) of 13 December 2011, which concluded that under the proposed conditions of use these micro-organisms do not have an adverse effect on animal health, human health or the environment, and have the potential to improve the production of silage from all forages by increasing the preservation of dry matter and reducing the loss of protein. The Regulation applies to all operators placing feed containing these micro-organisms on the market within the European Union and in EEA-relevant territories. Core obligations include compliance with labelling requirements by 19 May 2013, adherence to minimum dose specifications of 1 × 10⁹ CFU/kg fresh material when used not in combination with other micro-organisms, inclusion of storage temperature and storage life in directions for use, and use of breathing protection and gloves during handling. Existing stocks labelled under previous conditions before 19 May 2013 may continue to be placed on the market until exhausted. The period of authorisation for both additives runs until 19 November 2022.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32013d0402",
    "title": "2013/402/EU: Commission Decision of 16 April 2013 on the measure SA.20112 (C 35/2006) implemented by Sweden for Konsum Jämtland Ekonomisk Förening (notified under document C(2013) 1913) Text with EEA relevance",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2013-04-16",
    "bluf": "The European Commission assessed whether the sale of a plot of land by the Municipality of Åre to Konsum Jämtland Ekonomisk Förening constituted illegal state aid under Article 107(1) of the Treaty on the Functioning of the European Union (TFEU). The complaint alleged that the sale was below market value and favored Konsum over competitors like Lidl. The Commission concluded that the sale did not constitute state aid, as the price paid by Konsum was within the market value range determined by expert valuations. The decision was based on the context of the transaction, which was part of a larger development plan aimed at creating a traffic-free zone around Åre Torg.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32013d0478",
    "title": "2013/478/EU: Commission Decision of 27 September 2013 amending Decision 1999/352/EC, ECSC, Euratom establishing the European Anti-fraud Office",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2013-09-27",
    "bluf": "The Commission Decision amends the 1999/352/EC, ECSC, Euratom Decision to update the European Anti-fraud Office's (OLAF) mandate and operational framework. It emphasizes the protection of the Union’s financial interests, fraud prevention, and the fight against illegal activities. Key amendments include the renaming of the 'Director' to 'Director-General', updates to the Office's tasks to include legislative and regulatory initiatives, and participation in international bodies for best practices exchange. The Decision also outlines the appointment process for the Director-General and their responsibilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32013m6921",
    "title": "Commission Decision of 19/06/2013 declaring a concentration to be compatible with the common market (Case No COMP/M.6921 - IBM ITALIA / UBIS) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2013-06-19",
    "bluf": "On 14 May 2013, the European Commission received notification of a proposed concentration pursuant to Article 4 of Council Regulation (EC) No 139/2004 by which the undertaking IBM Italia S.p.A., a wholly-owned indirect subsidiary of International Business Machines Corporation, acquires sole control over a business of the undertaking Unicredit Business Integrated Solutions S.c.p.a. (UBIS), a wholly owned subsidiary of UniCredit S.p.A., by way of purchase of shares. IBM Italia will acquire 51% of the shares of a newly-formed limited liability company (NewCo), to which UBIS will transfer as a going concern the Transferred Business. IBM will appoint the majority of the members of the Board of Directors of NewCo (four out of seven Directors, including the Chief Executive Officer), with the Board adopting all decisions by simple majority. The proposed concentration has an EU dimension, as the undertakings concerned have a combined aggregate world-wide turnover of more than EUR 5,000 million and each has EU-wide turnover in excess of EUR 250 million. The Parties' activities overlap in the provision of IT outsourcing services, namely data centre services and network outsourcing services, for the banking and securities sector. The European Commission concluded that the proposed concentration does not give rise to competition concerns under any alternative market definition and declared it compatible with the internal market and with the EEA Agreement pursuant to Article 6(1)(b) of the Merger Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32013r0107",
    "title": "Commission Regulation (EU) No 107/2013 of 5 February 2013 amending Annex I to Directive 2002/32/EC of the European Parliament and of the Council as regards maximum levels for melamine in canned pet food Text with EEA relevance",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2013-02-06",
    "bluf": "Commission Regulation (EU) No 107/2013, adopted on 5 February 2013 and published in the Official Journal of the European Union (L 35/1) on 6 February 2013, amends Annex I to Directive 2002/32/EC on undesirable substances in animal feed. The Regulation establishes a specific maximum level for melamine in canned wet pet food of 2,5 mg/kg on an 'as sold' basis, replacing the prior framework which expressed maximum levels relative to a feed with a moisture content of 12%. The regulatory action is grounded in scientific evidence that melamine, used in the coating of cans containing pet food, can migrate into that pet food. Information demonstrated that melamine can migrate in wet pet food from the can coating at a level above 2,5 mg/kg relative to a feed with a moisture content of 12% but below the specific migration limit (SML) of 2,5 mg/kg in the wet pet food. In light of this development in scientific and technical knowledge, the Commission established the maximum level of 2,5 mg/kg for melamine for canned wet pet food on an 'as sold' basis, in line with what is foreseen for canned food under Commission Regulation (EU) No 10/2011. The Regulation is binding in its entirety and directly applicable in all Member States, entering into force on the twentieth day following its publication in the Official Journal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32013r0269",
    "title": "Commission Implementing Regulation (EU) No 269/2013 of 18 March 2013 approving non-minor amendments to the specification for a name entered in the register of protected designations of origin and protected geographical indications (Danablu (PGI))",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2013-03-18",
    "bluf": "Commission Implementing Regulation (EU) No 269/2013, adopted on 18 March 2013 and published in the Official Journal of the European Union on 22 March 2013 (L 82/45), approves non-minor amendments to the product specification for 'Danablu', a Protected Geographical Indication (PGI) registered under Commission Regulation (EC) No 1107/96 and subsequently amended by Regulation (EC) No 828/2003. The regulation is grounded in Regulation (EU) No 1151/2012 of the European Parliament and of the Council of 21 November 2012 on quality schemes for agricultural products and foodstuffs, specifically Article 52(2), which entered into force on 3 January 2013 and repealed Council Regulation (EC) No 510/2006. The regulation applies to Denmark as the originating Member State and to all EU Member States, given that it is binding in its entirety and directly applicable across the Union. The core obligation established by this regulation is the formal approval of the non-minor specification amendments for the Danablu PGI - a cheese classified under Class 1.3 (Cheeses) of agricultural products intended for human consumption listed in Annex I to the Treaty. The Commission examined Denmark's application in accordance with Article 9(1) of Regulation (EC) No 510/2006, published the amendment application in the Official Journal as required by Article 6(2) of that Regulation, and, having received no statement of objection under Article 7, proceeded to approve the amendments. The regulation entered into force on the twentieth day following its publication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32013r0323",
    "title": "Commission Implementing Regulation (EU) No 323/2013 of 9 April 2013 adding to the 2013 fishing quotas certain quantities withheld in the year 2012 pursuant to Article 4(2) of Council Regulation (EC) No 847/96",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2013-04-09",
    "bluf": "This regulation adds certain quantities of fishing quotas withheld in 2012 to the 2013 fishing quotas, as per Article 4(2) of Council Regulation (EC) No 847/96. Member States may request the Commission to withhold up to 10% of their allocated fishing quota before 31 October of the application year, which can then be transferred to the following year. The regulation applies to EU Member States and specifies the quantities to be added to the 2013 quotas for various fish stocks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32013r1185",
    "title": "Commission Implementing Regulation (EU) No 1185/2013 of 21 November 2013 entering a name in the register of protected designations of origin and protected geographical indications (Pâté de Campagne Breton (PGI))",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2013-11-21",
    "bluf": "Commission Implementing Regulation (EU) No 1185/2013, adopted on 21 November 2013, enters the name 'Pâté de Campagne Breton' into the EU register of protected designations of origin and protected geographical indications (PGI) under Regulation (EU) No 1151/2012 on quality schemes for agricultural products and foodstuffs. The regulation is directly applicable in all Member States and entered into force on the twentieth day following its publication in the Official Journal of the European Union. The PGI designation applies to producers of 'Pâté de Campagne Breton', a pure pork pâté made from pigmeat and pig offal, whose production must be carried out within the defined geographical area comprising the departments of Côtes-d'Armor, Finistère, Ille-et-Vilaine, Loire-Atlantique and Morbihan in historic Brittany, France. Producers must comply with a detailed product specification governing mandatory meat ingredients (including skinned throats ≥ 25%, liver ≥ 20%, cooked rinds ≥ 5%, and fresh onions ≥ 5%), strict limits on non-meat ingredients, raw material requirements (including pig carcasses weighing more than 80 kilograms and freedom from specified alleles), and labelling obligations requiring the PGI name, certifying body details, and the European Union PGI logo. The registration followed an opposition by the Netherlands and a subsequent agreement with France resulting in amendments to the specification to introduce objective criteria establishing a causal link between the quality of the pigmeat and that of the end product.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32013r1186",
    "title": "Commission Implementing Regulation (EU) No 1186/2013 of 21 November 2013 entering a name in the register of protected designations of origin and protected geographical indications (Orkney Scottish Island Cheddar (PGI))",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2013-11-21",
    "bluf": "Commission Implementing Regulation (EU) No 1186/2013, adopted on 21 November 2013 and published in the Official Journal of the European Union (L 313/40), enters the name 'Orkney Scottish Island Cheddar' into the register of protected designations of origin and protected geographical indications (PGI) under Regulation (EU) No 1151/2012 of the European Parliament and of the Council on quality schemes for agricultural products and foodstuffs. The registration follows a United Kingdom application, objections lodged by Dairy Australia, the Dairy Companies Association of New Zealand, and the Consortium for Common Food Names, and subsequent consultations resulting in agreement between the United Kingdom and the objecting parties within the stipulated three-month period, notified to the Commission on 8 July 2013. The protection applies only to the composite name 'Orkney Scottish Island Cheddar' as a whole. Pursuant to the last subparagraph of Article 13(1) of Regulation (EU) No 1151/2012, the name 'Cheddar' may continue to be used within the territory of the Union provided that the principles and rules applicable under the Union's legal system are complied with. This Regulation is binding in its entirety and directly applicable in all Member States, entering into force on the twentieth day following its publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32014d0142",
    "title": "Council Implementing Decision 2014/142/CFSP of 14 March 2014 implementing Decision 2011/486/CFSP concerning restrictive measures directed against certain individuals, groups, undertakings and entities in view of the situation in Afghanistan",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2014-03-14",
    "bluf": "Council Implementing Decision 2014/142/CFSP, adopted on 14 March 2014 and published in the Official Journal of the European Union (L 76/46), implements Decision 2011/486/CFSP concerning restrictive measures directed against certain individuals, groups, undertakings and entities in view of the situation in Afghanistan. The Decision amends the Annex to Decision 2011/486/CFSP by replacing and updating the entries for listed persons following an amendment made on 31 December 2013 by the Committee of the United Nations Security Council, established pursuant to paragraph 30 of Security Council Resolution 1988 (2011), to the list of individuals, groups, undertakings and entities subject to restrictive measures. The Decision applies to all EU Member States and obligates them to give effect to the updated restrictive measures - including asset freezes and travel bans - against the listed individuals associated with the Taliban. The Annex sets out detailed entries for 41 individuals, including former Taliban ministers, governors, military commanders, and financial operatives, providing grounds for listing, aliases, dates and places of birth, nationality, addresses, passport and identification numbers, and additional narrative information from the UN Sanctions Committee. The Decision entered into force on the date of its publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32014d0517",
    "title": "2014/517/EU: Council Decision of 14 April 2014 on the signing, on behalf of the European Union and its Member States, and provisional application of the Protocol to the Stabilisation and Association Agreement between the European Communities and their Member States, of the one part, and the Republic of Serbia, of the other part, to take account of the accession of the Republic of Croatia to the European Union",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2014-04-14",
    "bluf": "This Council Decision (2014/517/EU), adopted at Luxembourg on 14 April 2014, authorises the signing on behalf of the European Union and its Member States of the Protocol to the Stabilisation and Association Agreement between the European Communities and their Member States, of the one part, and the Republic of Serbia, of the other part, to take account of the accession of the Republic of Croatia to the European Union. The legal basis for this Decision is the Treaty on the Functioning of the European Union, in particular Article 217, in conjunction with Article 218(5) and the second subparagraph of Article 218(8), as well as the Act of Accession of Croatia, in particular the second subparagraph of Article 6(2) thereof. The Protocol was initialled on 10 December 2013 following negotiations authorised by the Council on 24 September 2012. The Protocol is to be signed subject to its conclusion at a later date, and shall be applied on a provisional basis, in accordance with its Article 14, as from the first day of the second month following the date of its signature, pending the completion of the procedures for its conclusion. The conclusion of the Protocol is subject to a separate procedure as regards matters falling within the competence of the European Atomic Energy Community. The President of the Council is authorised to designate the person(s) empowered to sign the Protocol on behalf of the Union and its Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32014d0842",
    "title": "2014/842/EU, Euratom: Commission Implementing Decision of 26 November 2014 amending Decision 2005/818/EC, Euratom authorising the Republic of Hungary to use certain approximate estimates for the calculation of the VAT own resources base (notified under document C(2014) 8923)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2014-11-26",
    "bluf": "The European Commission has authorized Hungary to use a fixed percentage of 0.18% of the intermediate base for calculating the VAT own resources base for transactions related to passenger transport, as specified in point 10 of Annex X, Part B to Council Directive 2006/112/EC. This authorization applies from 1 January 2014 to 31 December 2020. The decision aims to simplify VAT own resources inspections and ensure transparency and legal certainty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32014h0117",
    "title": "2014/117/EU: Commission Recommendation of 3 March 2014 on the establishment and implementation of the Production and Marketing Plans pursuant to Regulation (EU) No 1379/2013 of the European Parliament and of the Council on the common organisation of the markets in fishery and aquaculture products",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2014-03-03",
    "bluf": "The Commission Recommendation provides detailed guidance on the structure, format, and implementation of production and marketing plans for fishery and aquaculture producer organisations under Regulation (EU) No 1379/2013. These plans are mandatory for producer organisations and must include information on production programmes, marketing strategies, measures to achieve common market objectives, financial schedules, and indicators for monitoring. The recommendation aims to ensure homogeneous implementation across Member States and facilitate the assessment of plans by competent national authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32014l0054",
    "title": "Directive 2014/54/EU - Measures Facilitating the Exercise of Rights of Workers in the Context of Freedom of Movement",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Directive 2014/54/EU requires Member States to ensure that Union workers and their family members can effectively exercise their right to free movement under Article 45 TFEU and Articles 1 to 10 of Regulation (EU) No 492/2011, free from discrimination on grounds of nationality. It covers equal treatment in access to employment, conditions of work, social and tax advantages, trade union membership, training, housing and education. Member States must make judicial procedures available for enforcement, allow associations to act on behalf of or in support of workers, protect workers from adverse treatment for asserting their rights, designate one or more bodies to promote equal treatment and provide independent legal assistance, establish a national contact point that cooperates with equivalent points in other Member States, promote dialogue with the social partners, and make clear, comprehensive information on these rights publicly available.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_primary_law",
        "related_instruments",
        "iso_standard",
        "support_networks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-posted-workers-directive-2018-957",
      "eu-equal-treatment-employment-2000-78"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32014l0091",
    "title": "Directive 2014/91/EU (UCITS V) - Depositary Functions, Remuneration Policies and Sanctions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Directive 2014/91/EU (UCITS V) amends the UCITS Directive 2009/65/EC to strengthen the depositary regime, introduce remuneration rules for management companies, and harmonise administrative sanctions. A single depositary must be appointed for each UCITS, evidenced by a written contract. The depositary must perform oversight duties (ensuring subscriptions, redemptions, valuation, instructions, remittance of consideration and application of income comply with national law and the fund rules), properly monitor the UCITS cash flows so that investor money is booked correctly, and safe-keep the UCITS assets by holding financial instruments in custody and verifying ownership of other assets. The depositary is liable to the UCITS and its unit-holders for the loss of financial instruments held in custody. Management companies must adopt remuneration policies that promote sound and effective risk management, cover fixed and variable components, and apply to senior management, risk takers and control functions whose activities materially affect risk profiles, applying the alignment principles in Article 14b. Member States must provide administrative penalties and measures, including public statements, cease-and-desist orders, suspension or withdrawal of authorisation, management bans, and pecuniary sanctions of at least EUR 5 000 000 or 10% of total annual turnover for legal persons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_primary_law",
        "related_instruments",
        "iso_standard",
        "supervisory_guidance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aifmd-directive-2011-61",
      "eu-esma-regulation-1095-2010"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32014r0154",
    "title": "Commission Implementing Regulation (EU) No 154/2014 of 19 February 2014 amending Implementing Regulation (EU) No 540/2011 as regards the conditions of approval of the active substance extract from tea tree Text with EEA relevance",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2014-02-19",
    "bluf": "The regulation amends the conditions of approval for the active substance extract from tea tree under Regulation (EC) No 1107/2009. It requires Member States to amend or withdraw existing authorisations for plant protection products containing this substance by 12 September 2014. The regulation also sets a grace period for such products, which must expire by 12 September 2015 at the latest. Specific provisions include the requirement for confirmatory information on plant metabolism, consumer exposure, toxicity of compounds, groundwater exposure, and effects on sewage treatment methods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32014r0656",
    "title": "Regulation (EU) No 656/2014 - Surveillance of the External Sea Borders in Frontex-Coordinated Operations",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Regulation (EU) No 656/2014 establishes the rules for the surveillance of the external sea borders during operational cooperation coordinated by Frontex. It applies to border surveillance operations carried out by Member States at their external sea borders under Agency coordination. All measures taken for a sea operation must, in all instances, ensure the safety of the persons intercepted or rescued, of the participating units and of third parties. No person may, in contravention of the principle of non-refoulement, be disembarked in, forced to enter, conducted to or otherwise handed over to the authorities of a country where there is a serious risk of the death penalty, torture, persecution or other inhuman or degrading treatment, or where life or freedom would be threatened, or from which there is a serious risk of onward refoulement; before any disembarkation in a third country the host Member State must assess that country's general situation and participating units must identify the persons, assess their circumstances and give them an opportunity to raise non-refoulement concerns. On detection, participating units approach and survey a suspect vessel at a prudent distance and report to the International Coordination Centre. Interception measures differ by zone: in the territorial sea and contiguous zone they require the coastal State's authorisation and must be proportionate; on the high seas they are subject to flag-State authorisation under the UN Protocol against the Smuggling of Migrants. Member States must render assistance to any vessel or person in distress regardless of nationality or status, following the uncertainty, alert and distress phases and cooperating with the responsible Rescue Coordination Centre. Disembarkation modalities must be set out in the operational plan: interception in the territorial sea or contiguous zone leads to disembarkation in the coastal Member State; interception on the high seas may lead to disembarkation in the third country of departure or, failing that, the host Member State; and in search and rescue situations the States cooperate with the Rescue Coordination Centre to identify a place of safety.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_primary_law",
        "related_instruments",
        "international_law",
        "agency_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-schengen-borders-code-regulation-2016-399",
      "eu-dublin-iii-regulation-604-2013-asylum-responsibility",
      "un-refugee-convention-1951-protocol-1967-non-refoulement"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32014r0827",
    "title": "Council Regulation (EU) No 827/2014 of 23 July 2014 amending Regulation (EC) No 974/98 as regards the introduction of the euro in Lithuania",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2015-01-01",
    "bluf": "Council Regulation (EU) No 827/2014, adopted by the Council of the European Union on 23 July 2014, amends Regulation (EC) No 974/98 to extend to Lithuania the existing provisions on the introduction of the euro. The regulation follows Council Decision 2014/509/EU of 23 July 2014, which determined that Lithuania fulfils the necessary conditions for the adoption of the euro and that the derogation in favour of Lithuania is to be abrogated with effect from 1 January 2015. Pursuant to Lithuania's National Euro Changeover Plan, euro banknotes and coins become legal tender in Lithuania on the day of the introduction of the euro as its currency. Consequently, both the euro adoption date and the cash changeover date are set as 1 January 2015, with no 'phasing-out' period applying. The regulation is binding in its entirety and directly applicable in all Member States, entering into force on 1 January 2015. The operative amendment inserts Lithuania into the Annex table of Regulation (EC) No 974/98, between the entries for Latvia and Luxembourg, specifying 1 January 2015 for both the euro introduction date and the cash changeover date, with no phasing-out period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32014r0906r-02",
    "title": "Corrigendum to Commission Delegated Regulation (EU) No 906/2014 of 11 March 2014 supplementing Regulation (EU) No 1306/2013 of the European Parliament and of the Council with regard to public intervention expenditure ( OJ L 255, 28.8.2014)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2014-07-10",
    "bluf": "The corrigendum to Commission Delegated Regulation (EU) No 906/2014 addresses specific textual errors in Annex I, part I, points 2 and 3. It replaces references to 'point (a)' with 'point 1' and 'point (b)' with 'point 2'. This correction ensures clarity and accuracy in the application of public intervention expenditure provisions under Regulation (EU) No 1306/2013.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32014r0921",
    "title": "Commission Implementing Regulation (EU) No 921/2014 of 25 August 2014 amending Implementing Regulation (EU) No 540/2011 as regards the conditions of approval of the active substance tebuconazole Text with EEA relevance",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2014-08-25",
    "bluf": "Commission Implementing Regulation (EU) No 921/2014, adopted on 25 August 2014 and published in the Official Journal of the European Union on 26 August 2014, amends Implementing Regulation (EU) No 540/2011 as regards the conditions of approval of the active substance tebuconazole. The Regulation extends the approval of tebuconazole to cover uses as a plant growth regulator without restriction, in addition to its existing authorisation as a fungicide, following an application submitted on 8 April 2010 and a risk assessment opinion issued by the European Food Safety Authority on 9 December 2013. The Regulation is binding in its entirety and directly applicable in all Member States, entering into force on the twentieth day following its publication in the Official Journal. Member States must pay particular attention to operator and worker safety, dietary exposure of consumers to tebuconazole (triazole) metabolites, the potential for groundwater contamination by the metabolite 1,2,4-triazole in regions with vulnerable soil or climatic conditions, the protection of granivorous birds and mammals and herbivorous mammals, and the protection of aquatic organisms. Additionally, Member States concerned shall ensure that the notifier submits to the Commission further information addressing the potential endocrine disrupting properties of tebuconazole within two years after the adoption of the OECD test guidelines on endocrine disruption or, alternatively, of Community agreed test guidelines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32014r1049",
    "title": "Commission Implementing Regulation (EU) No 1049/2014 of 30 July 2014 on technical characteristics of information and publicity measures pursuant to Regulation (EU) No 514/2014 of the European Parliament and of the Council laying down general provisions on the Asylum, Migration and Integration Fund and on the instrument for financial support for police cooperation, prevention and combating crime and crisis management",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2014-10-07",
    "bluf": "Commission Implementing Regulation (EU) No 1049/2014, adopted on 30 July 2014 and published in the Official Journal of the European Union on 7 October 2014, establishes the technical characteristics that must be applied to all information and publicity measures carried out under the Asylum, Migration and Integration Fund and the instrument for financial support for police cooperation, preventing and combating crime, and crisis management, as governed by Regulation (EU) No 514/2014. The Regulation applies to responsible authorities, beneficiaries, and potential beneficiaries across all bound Member States - explicitly including the United Kingdom and Ireland, while excluding Denmark. The core obligation is that all information and publicity measures aimed at beneficiaries, potential beneficiaries, and the general public must include: the emblem of the European Union in accordance with the graphic standards set out in the Annex, a reference to the European Union, a reference to the Fund supporting the project, and a statement chosen by the responsible authority highlighting the added value of the contribution from the European Union. For small promotional items, the EU emblem and the added-value statement requirements do not apply. The Annex provides binding technical specifications for the EU emblem including heraldic description, geometric proportions, Pantone colour standards, internet RGB/hexadecimal values, monochrome reproduction rules, coloured background rules, and typeface requirements for acknowledgement text.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32015d2096",
    "title": "Council Decision (CFSP) 2015/2096 of 16 November 2015 on the position of the European Union relating to the Eighth Review Conference of the Convention on the Prohibition of the Development, Production and Stockpiling of Bacteriological (Biological) and Toxin Weapons and on Their Destruction (BTWC)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2015-11-16",
    "bluf": "Council Decision (CFSP) 2015/2096, adopted by the Council of the European Union on 16 November 2015 and published in the Official Journal of the European Union on 20 November 2015, establishes the official position of the European Union in relation to the Eighth Review Conference of the Convention on the Prohibition of the Development, Production and Stockpiling of Bacteriological (Biological) and Toxin Weapons and on Their Destruction ('BTWC'), scheduled to be held in Geneva not later than 2016. The Decision applies to the Union and its Member States, directing them to work collectively to ensure that States Parties address four core priorities: building and sustaining confidence in compliance by a range of specific measures; supporting national implementation including by engaging more with non-governmental stakeholders; supporting the UN Secretary-General's Mechanism for investigation of alleged use of biological weapons; and promoting the universality of the BTWC. The Union's objective, as set out in Article 1, is to review the operation of the BTWC and the 2012-2015 Intersessional Process, promote concrete actions, and explore options to further strengthen the BTWC, with concrete proposals to be put forward to the Eighth Review Conference in 2016 with a view to their adoption by that Conference. Key obligations include promoting enhanced Confidence Building Measures (CBMs), supporting the Implementation Support Unit (ISU) mandate prolongation for a further five years, strengthening the UN Secretary-General's Mechanism, supporting a Ninth Review Conference no later than 2021, and advancing universalisation of the BTWC through an ISU-coordinated action plan.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32015d2251",
    "title": "Commission Implementing Decision (EU) 2015/2251 of 26 November 2015 confirming or amending the average specific emission of CO2 and specific emissions targets for manufacturers of passenger cars for the calendar year 2014 pursuant to Regulation (EC) No 443/2009 of the European Parliament and of the Council (notified under document C(2015) 8348)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2015-11-26",
    "bluf": "Commission Implementing Decision (EU) 2015/2251, adopted on 26 November 2015 and published in the Official Journal of the European Union (L 318/53), confirms or amends the average specific emissions of CO2 and specific emissions targets for manufacturers of passenger cars registered in the Union during the calendar year 2014, pursuant to Regulation (EC) No 443/2009. The Commission is required, pursuant to Article 8(5) of Regulation (EC) No 443/2009, to confirm each year the average specific emissions of CO2 and the specific emissions target for each manufacturer of passenger cars in the Union as well as for each pool of manufacturers formed in accordance with Article 7(1) of that Regulation. On the basis of that confirmation, the Commission is to determine whether manufacturers and pools have complied with the requirements of Article 4 of that Regulation. The Decision applies to 95 individual manufacturers and pools of manufacturers of passenger cars, covering entities across the EU and non-EU manufacturers represented in the Union. Manufacturers were notified of provisional calculations and given 3 months to verify data and notify errors. Where average emissions exceed the specific emissions target, an excess emission premium is to be imposed in accordance with Article 9 of Regulation (EC) No 443/2009, unless the manufacturer benefits from an exemption or is a member of a compliant pool. Notably, the Volkswagen pool and its members are excluded from this Decision pending further clarification following a statement by the Volkswagen Group on 3 November 2015 regarding irregularities found when determining type approval CO2 levels of some of their vehicles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32015r0722",
    "title": "Commission Implementing Regulation (EU) 2015/722 of 5 May 2015 concerning the authorisation of taurine as a feed additive for Canidae, Felidae, Mustelidae and carnivorous fish (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2015-05-05",
    "bluf": "The regulation authorizes taurine as a feed additive for Canidae, Felidae, Mustelidae, and carnivorous fish, classifying it under 'nutritional additives'. It specifies conditions for use, including maximum content levels in complete feedingstuffs and safety measures during handling. The authorization is based on the European Food Safety Authority's conclusion that taurine is efficacious and safe under proposed conditions, with no adverse effects on animal health, human health, or the environment. Transitional periods are provided for compliance with the new requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32015r1378",
    "title": "Commission Regulation (EU) 2015/1378 of 11 August 2015 amending Annex II to Regulation (EC) No 1333/2008 of the European Parliament and of the Council as regards the use of riboflavins (E 101) and carotenes (E 160a) in dried potato granules and flakes (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2015-08-11",
    "bluf": "The regulation amends Annex II to Regulation (EC) No 1333/2008 to authorize the use of riboflavins (E 101) and carotenes (E 160a) in dried potato granules and flakes. These additives are deemed safe and suitable alternatives to curcumin (E 100) for restoring the visual appearance of processed potato products. The amendment is based on safety evaluations by the European Food Safety Authority (EFSA), which concluded that the use of these additives at authorized levels does not pose a safety concern. The regulation applies to food producers and manufacturers of dried potato granules and flakes within the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32015r2082",
    "title": "Commission Implementing Regulation (EU) 2015/2082 of 18 November 2015 concerning the non-approval of Arctium lappa L. (aerial parts) as a basic substance in accordance with Regulation (EC) No 1107/2009 of the European Parliament and of the Council concerning the placing of plant protection products on the market (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2015-11-19",
    "bluf": "Commission Implementing Regulation (EU) 2015/2082, adopted at Brussels on 18 November 2015 and published in the Official Journal of the European Union on 19 November 2015, establishes the non-approval of Arctium lappa L. (aerial parts) as a basic substance under Regulation (EC) No 1107/2009 concerning the placing of plant protection products on the market. The Regulation is binding in its entirety and directly applicable in all Member States, entering into force on the twentieth day following its publication in the Official Journal. The non-approval follows an application submitted on 3 June 2014 by the Institut Technique de l'Agriculture Biologique (ITAB), which sought approval of Arctium lappa L. as a basic substance. The European Food Safety Authority (EFSA) provided a Technical Report on 27 November 2014, identifying specific concerns regarding exposure to arctigenin, chlorogenic and caffeic acids, as a result of which the assessment of the risk to operators, workers, bystanders, consumers and non-target organisms could not be finalised. Furthermore, the documentation provided by the applicant showed that not all aerial parts of Arctium lappa L. fulfil the criteria of a foodstuff as defined in Article 2 of Regulation (EC) No 178/2002. Despite the applicant's comments being carefully examined, the concerns related to the substance could not be eliminated, and it was therefore determined that the requirements laid down in Article 23 of Regulation (EC) No 1107/2009 are not satisfied. The Regulation does not prejudice the submission of a further application for approval in accordance with Article 23(3) of Regulation (EC) No 1107/2009.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32016d0107",
    "title": "Commission Implementing Decision (EU) 2016/107 of 27 January 2016 not approving cybutryne as an existing active substance for use in biocidal products for product-type 21 (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2016-01-27",
    "bluf": "The European Commission has decided not to approve cybutryne as an active substance for use in biocidal products for product-type 21, which includes antifouling products. This decision is based on the evaluation conducted by the Netherlands as the designated competent authority, which concluded that biocidal products containing cybutryne do not meet the requirements laid down in Article 5 of Directive 98/8/EC. The environmental risk assessment identified unacceptable risks, leading to the conclusion that cybutryne should not be approved for use in these products. The decision is in accordance with the opinion of the Standing Committee on Biocidal Products and enters into force twenty days after its publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32016d0109",
    "title": "Commission Implementing Decision (EU) 2016/109 of 27 January 2016 not to approve PHMB (1600; 1.8) as an existing active substance for use in biocidal products for product-types 1, 6 and 9 (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2016-01-27",
    "bluf": "Commission Implementing Decision (EU) 2016/109, adopted at Brussels on 27 January 2016 by the European Commission under authority of Regulation (EU) No 528/2012 concerning the making available on the market and use of biocidal products, formally declines to approve PHMB (1600; 1.8) (EC No: n.a., CAS No 27083-27-8 and 32289-58-0) as an existing active substance for use in biocidal products for product-type 1 (human hygiene), product-type 6 (preservatives for products during storage), and product-type 9 (fibre, leather, rubber and polymerised materials preservatives), as defined in Annex V to Regulation (EU) No 528/2012. The Decision follows evaluation by France as the designated evaluating competent authority, which submitted assessment reports on 5 September 2013, 8 October 2013, and 14 February 2014. The European Chemicals Agency's Biocidal Products Committee formulated its opinions on 16 and 17 June 2015, concluding that biocidal products containing PHMB (1600; 1.8) for product-types 1, 6 and 9 may not be expected to satisfy the requirements laid down in Article 19(1)(b) of Regulation (EU) No 528/2012, as the scenarios evaluated in the human health risk assessments and the environmental risk assessments identified unacceptable risks. The Decision entered into force on the twentieth day following its publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32016d0170",
    "title": "Commission Implementing Decision (EU) 2016/170 of 5 February 2016 authorising methods for grading pig carcasses in Finland (notified under document C(2016) 658)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2016-02-05",
    "bluf": "Commission Implementing Decision (EU) 2016/170, adopted on 5 February 2016 and published in the Official Journal of the European Union (L 32/163) on 9 February 2016, authorises specific methods for grading pig carcasses in Finland pursuant to point 1 of Section B.IV of Annex IV to Regulation (EU) No 1308/2013. The Decision is addressed to the Republic of Finland and applies from 1 February 2016. The Decision authorises two apparatus and their associated assessment methods: the 'Hennessy Grading Probe 4 (HGP4)' and the 'AutoFOM III' (fully automatic ultrasonic carcass grading). For the HGP4, lean meat content is calculated using a specified formula valid for carcasses weighing between 50 and 120 kg, based on physical measurements of back fat thickness and muscle thickness at defined anatomical positions. For the AutoFOM III, lean meat content is calculated using a separate formula also valid for carcasses weighing between 50 and 120 kilograms, derived from ultrasonic measurements across two selected cross-sections. Modifications of the authorised apparatus or grading methods shall not be allowed unless explicitly authorised by Commission Decision. Decision 96/550/EC, which previously authorised three grading methods in Finland, is repealed by this Decision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 11
  },
  {
    "node_id": "eu-celex-32016d0990",
    "title": "Decision on mobilisation of European Globalisation Adjustment Fund for Greece application EGF/2015/011 GR/Supermarket Larissa",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "Decision (EU) 2016/990 of the European Parliament and of the Council, adopted on 8 June 2016, mobilises the European Globalisation Adjustment Fund (EGF) to provide a financial contribution of EUR 6,468,000 in commitment and payment appropriations for the general budget of the European Union for the financial year 2016. This mobilisation follows application EGF/2015/011 GR/Supermarket Larissa submitted by Greece on 26 November 2015, concerning redundancies in Supermarket Larissa ABEE. The application was supplemented by additional information in accordance with Article 8(3) of Regulation (EU) No 1309/2013 and complies with requirements for determining a financial contribution under Article 13 of that regulation. In accordance with Article 6(2) of Regulation (EU) No 1309/2013, Greece decided to provide personalised services co-financed by the EGF also to 543 young persons not in employment, education or training (NEETs). The EGF aims to support workers made redundant and self-employed persons whose activity ceased due to major structural changes in world trade patterns from globalisation, the continuation of the global financial and economic crisis, or a new global financial and economic crisis, and to assist their reintegration into the labour market. The EGF shall not exceed a maximum annual amount of EUR 150 million (2011 prices) as per Article 12 of Council Regulation (EU, Euratom) No 1311/2013. The decision applies from 8 June 2016, the date of its adoption, and enters into force on the day of publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32016d1925",
    "title": "Commission Implementing Decision (EU) 2016/1925 of 31 October 2016 repealing Implementing Decision (EU) 2016/17 authorising the United Kingdom to prohibit on its territory the marketing of a variety of hemp listed in the Common Catalogue of varieties of agricultural plant species, pursuant to Council Directive 2002/53/EC (notified under document C(2016) 6860)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2016-10-31",
    "bluf": "Commission Implementing Decision (EU) 2016/1925, adopted at Brussels on 31 October 2016 by the European Commission, repeals Implementing Decision (EU) 2016/17, which had previously authorised the United Kingdom to prohibit on its territory the marketing of the hemp variety Finola listed in the Common Catalogue of varieties of agricultural plant species. The repeal is addressed to the United Kingdom of Great Britain and Northern Ireland and is grounded in Article 18 of Council Directive 2002/53/EC of 13 June 2002 on the common catalogue of varieties of agricultural plant species. The background to this Decision is as follows: Article 32(6) of Regulation (EU) No 1307/2013 provides that areas used for the production of hemp may only be eligible for support if the varieties used have a tetrahydrocannabinol (THC) content not exceeding 0,2 %. Article 45(3) of Commission Implementing Regulation (EU) No 809/2014 requires a Member State to request authorisation to prohibit marketing of a hemp variety if the average THC content exceeds that threshold for a second consecutive year. The United Kingdom had made such a request on 28 April 2015 regarding the variety Finola. However, on 15 March 2016, the United Kingdom officially informed the Commission that further testing revealed the THC content for 2014 did not in fact exceed the 0,2 % threshold, and accordingly requested repeal of the original authorisation. The measures in this Decision are in accordance with the opinion of the Standing Committee on Plants, Animals, Food and Feed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32016l1065",
    "title": "Directive (EU) 2016/1065 - VAT Treatment of Single-Purpose and Multi-Purpose Vouchers",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Directive (EU) 2016/1065 amends the VAT Directive 2006/112/EC to harmonise the VAT treatment of vouchers by inserting Articles 30a, 30b and 73a. A voucher is an instrument carrying an obligation to accept it as consideration for a supply of goods or services, where the goods or services or the potential suppliers are indicated on it or in related documentation. A single-purpose voucher (SPV) is one where the place of supply and the VAT due are known at issue; a multi-purpose voucher (MPV) is any other voucher. Each transfer of an SPV by a taxable person acting in his own name is treated as a supply of the underlying goods or services, and the actual handover against the SPV is not an independent transaction. For an MPV, VAT applies only on the actual handover of the goods or services, while preceding transfers are not subject to VAT, although identifiable distribution or promotion services are taxable. The taxable amount for an MPV equals the consideration paid for the voucher (or its stated monetary value) less the VAT. These rules apply only to vouchers issued after 31 December 2018.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_primary_law",
        "related_instruments",
        "transitional_rule",
        "tax_type"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-vat-directive-2006-112-consolidated"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32016m8217",
    "title": "Commission Decision of 17/11/2016 declaring a concentration to be compatible with the common market (Case No COMP/M.8217 - CPPIB / HAMMERSON / GRAND CENTRAL) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2016-11-17",
    "bluf": "On 21 October 2016, the European Commission received notification of a proposed concentration pursuant to Article 4 of the Merger Regulation by which the Canada Pension Plan Investment Board ('CPPIB', Canada) and Hammerson plc ('Hammerson', United Kingdom) acquire within the meaning of Article 3(1)(b) of the Merger Regulation joint control of a shopping center called Grand Central (United Kingdom), currently solely controlled by Hammerson, by way of purchase of shares. After examination of the notification, the European Commission concluded that the notified operation falls within the scope of the Merger Regulation and of paragraph 6 of the Commission Notice on a simplified procedure for treatment of certain concentrations under Council Regulation (EC) No 139/2004. For the reasons set out in the Notice on a simplified procedure, the European Commission decided not to oppose the notified operation and to declare it compatible with the internal market and with the EEA Agreement. This decision is adopted in application of Article 6(1)(b) of the Merger Regulation and Article 57 of the EEA Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32016m8218",
    "title": "Commission Decision of 30/11/2016 declaring a concentration to be compatible with the common market (Case No COMP/M.8218 - EGERIA INDUSTRIALS / CLONDALKIN) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2016-11-30",
    "bluf": "The European Commission has approved the acquisition of Clondalkin Group Holdings B.V. by Egeria Industrials AG under the simplified procedure of the Merger Regulation. The decision confirms the operation's compatibility with the internal market and the EEA Agreement. Egeria is a Swiss private equity firm, while Clondalkin specializes in flexible packaging products. The notification was received on 8 November 2016, and the Commission concluded its examination without opposition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32016r0930",
    "title": "Commission Implementing Regulation (EU) 2016/930 of 1 June 2016 entering a name in the register of protected designations of origin and protected geographical indications (Fogaça da Feira (PGI))",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2016-06-14",
    "bluf": "Commission Implementing Regulation (EU) 2016/930, adopted on 1 June 2016 and published in the Official Journal of the European Union on 14 June 2016, formally enters the name 'Fogaça da Feira' into the register of protected designations of origin and protected geographical indications (PGI) under the authority of the European Commission. The regulation is grounded in Regulation (EU) No 1151/2012 of the European Parliament and of the Council of 21 November 2012 on quality schemes for agricultural products and foodstuffs, specifically Article 52(2) thereof. Portugal submitted the application to register the name 'Fogaça da Feira' pursuant to Article 50(2)(a) of that same regulation, and the application was published in the Official Journal of the European Union. As no statement of opposition under Article 51 of Regulation (EU) No 1151/2012 was received by the Commission, the name was entered in the register. The registered name denotes a product in Class 2.3 - Bread, pastry, cakes, confectionery, biscuits and other baker's wares - in accordance with Annex XI to Commission Implementing Regulation (EU) No 668/2014. This Regulation is binding in its entirety and directly applicable in all Member States, entering into force on the twentieth day following its publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32016r1611",
    "title": "Commission Delegated Regulation (EU) 2016/1611 of 7 July 2016 on reviewing the scale for missions by officials and other servants of the European Union in the Member States",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2016-07-07",
    "bluf": "The Commission Delegated Regulation (EU) 2016/1611, adopted on 7 July 2016, reviews the scale for missions by officials and other servants of the European Union in the Member States. It replaces the scale of mission allowances in Article 13(2)(a) of Annex VII to the Staff Regulations with updated daily subsistence allowances and hotel ceilings for each Member State. This regulation is binding in its entirety and directly applicable in all Member States, aiming to adjust to the evolving economic and social context in Europe.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32017d1372",
    "title": "Decision (EU) 2017/1372 of the European Parliament and of the Council of 14 July 2017 on the mobilisation of the European Globalisation Adjustment Fund following an application from Spain - EGF/2017/001 ES/Castilla y León mining",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2017-07-14",
    "bluf": "Decision (EU) 2017/1372, adopted by the European Parliament and the Council on 14 July 2017 and published in the Official Journal of the European Union (L 193/2) on 25 July 2017, mobilises the European Globalisation Adjustment Fund (EGF) to provide a financial contribution of EUR 1 002 264 in commitment and payment appropriations from the general budget of the Union for the financial year 2017, in response to an application submitted by Spain on 20 January 2017. The application concerns redundancies in the economic sector classified under NACE Revision 2 Division 5 (Mining of coal and lignite) in the region of Castilla y León. The EGF aims to provide support for workers made redundant and self-employed persons whose activity has ceased as a result of major structural changes in world trade patterns due to globalisation, as a result of a continuation of the global financial and economic crisis, or as a result of a new global financial and economic crisis, and to assist them with their reintegration into the labour market. Spain has also decided to provide personalised services co-financed by the EGF to 125 young people not in employment, education or training (NEETs), in accordance with Article 6(2) of Regulation (EU) No 1309/2013. The application was found admissible under Article 4(2) of Regulation (EU) No 1309/2013 on the basis that the redundancies have a serious impact on employment and the local economy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32017d1967",
    "title": "Council Decision (EU) 2017/1967 of 23 October 2017 on the position to be adopted, on behalf of the European Union, within the EEA Joint Committee concerning an amendment to Protocol 31 to the EEA Agreement, on cooperation in specific fields outside the four freedoms (The Union's preparatory action on defence research)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2017-10-28",
    "bluf": "Council Decision (EU) 2017/1967, adopted on 23 October 2017 and published in the Official Journal of the European Union on 28 October 2017, establishes the position of the European Union within the EEA Joint Committee concerning an amendment to Protocol 31 to the EEA Agreement. The amendment extends cooperation of the Contracting Parties to the EEA Agreement to include the participation of the EFTA States in the Union's preparatory action on defence research, which is funded from the general budget of the European Union under budget line 02 04 77 03. The Decision applies from 11 April 2017, meaning that institutions, undertakings, organizations and nationals of the EFTA States are entitled to participate in activities which start before the entry into force of this Decision, with costs incurred for participation in activities whose implementation starts after 11 April 2017 considered eligible under the same conditions as those applicable to costs incurred by institutions, undertakings, organizations and nationals of the EU Member States. The EFTA States are required to contribute financially to the relevant activities in accordance with Article 82(1)(a) of the EEA Agreement. Notably, Iceland and Liechtenstein shall not participate in that preparatory action and shall not financially contribute to the activities. The EFTA States also declare that defence matters fall outside the scope of the EEA Agreement and that this Decision does not extend the scope of the EEA Agreement to include defence matters beyond participation in that preparatory action.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32017d2283",
    "title": "Council Decision (CFSP) 2017/2283 of 11 December 2017 in support of a global reporting mechanism on illicit small arms and light weapons and other illicit conventional weapons and ammunition to reduce the risk of their illicit trade (‘iTrace III’)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2017-12-11",
    "bluf": "The iTrace III project aims to combat the destabilizing impact of the diversion and trafficking of small arms and light weapons (SALW) and other conventional weapons. It focuses on providing policy-makers, arms control experts, and export control officers with systematically compiled information to develop evidence-based strategies against illicit arms trade. The project builds on previous initiatives (iTrace I and II) and supports international efforts like the UN Programme of Action and the Arms Trade Treaty (ATT). It includes field investigations, training for national authorities, and direct support to Member States' export control authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32017m8705",
    "title": "Commission Decision of 15/12/2017 declaring a concentration to be compatible with the common market (Case No COMP/M.8705 - BC PARTNERS / CERAMTEC) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2017-12-15",
    "bluf": "On 17 November 2017, the European Commission received notification of a proposed concentration pursuant to Article 4 of the Merger Regulation by which BC Partners Holdings Limited (United Kingdom) acquires - indirectly through the fund BC European Capital X, acting by its general partner BC European Capital Management X Limited (Guernsey) - within the meaning of Article 3(1)(b) of the Merger Regulation sole control over the whole of the undertaking CeramTec Holding GmbH (Germany) by way of purchase of shares. After examination of the notification, the European Commission concluded that the notified operation falls within the scope of the Merger Regulation and of paragraph 5(b) of the Commission Notice on a simplified procedure for treatment of certain concentrations under Council Regulation (EC) No 139/2004. For the reasons set out in the Notice on a simplified procedure, the European Commission decided not to oppose the notified operation and to declare it compatible with the internal market and with the EEA Agreement. This decision is adopted in application of Article 6(1)(b) of the Merger Regulation and Article 57 of the EEA Agreement. The decision was signed by Johannes Laitenberger, Director-General, on 15 December 2017 under Commission document reference C(2017) 8904 final.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32017r1184",
    "title": "Commission Implementing Regulation (EU) 2017/1184 - Union Carcass Classification Scales and Market Price Reporting for Beef, Pig and Sheep",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Commission Implementing Regulation (EU) 2017/1184 lays down rules for applying Regulation (EU) No 1308/2013 (the common organisation of agricultural markets) as regards the Union scales for the classification of beef, pig and sheep carcasses and the reporting of market prices. Slaughterhouses, classification agencies or qualified classifiers must communicate the classification results to the supplier of the animal, in paper or electronic form, indicating per carcass the classification letters and figures under Annex IV to Regulation (EU) No 1308/2013, the established carcass weight (warm or cold), the carcass presentation applied, and whether an automated grading technique was used. On-the-spot checks must be carried out in all slaughterhouses applying compulsory carcass classification, without prior warning, by a body independent of the slaughterhouses, classification agencies and qualified classifiers (unless the competent authority itself carries out the controls). Where no risk assessment is used, fixed minimum frequencies apply: slaughterhouses handling 150 or more bovine animals aged eight months or more per week must be checked at least twice every three months on at least 40 carcasses, and those handling 500 or more pigs per week at least twice every three months. Competent authorities must keep reports of the checks and may revoke licences or approvals of classifiers or automated grading techniques where significant incorrect classification is found. For market-price recording, carcass presentation differing from the standard must be adjusted by corrective factors, Member States divide their territory into price-recording regions, beef prices are recorded for specified categories and conformation and fat cover classes, and designated operators (including slaughterhouses handling 20 000 or more bovine animals a year) must record the market prices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_primary_law",
        "related_instruments",
        "classification_scales",
        "scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-common-agricultural-policy-regulation-2021-2115",
      "eu-food-safety-regulation-178-2002"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32018d0010-01",
    "title": "European Central Bank Decision on Delegation of Power to Adopt Own Funds Decisions",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The European Central Bank has made a decision regarding the delegation of power to adopt own funds decisions. This decision, dated 15 March 2018, is identified as Decision (EU) 2018/546 and is also known as ECB/2018/10. The decision is related to the European Central Bank's role in banking supervision and the adoption of own funds decisions. The European Central Bank is responsible for ensuring the stability of the financial system and this decision is a part of that effort. The decision is available on the EUR-Lex website, which is the official website for European Union law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-celex-32018d1675",
    "title": "Decision (EU) 2018/1675 of the European Parliament and of the Council of 2 October 2018 on the mobilisation of the European Globalisation Adjustment Fund following an application from the Netherlands - EGF/2018/001 NL/Financial service activities",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-10-12",
    "bluf": "Decision (EU) 2018/1675, adopted by the European Parliament and the Council on 2 October 2018 and published in the Official Journal of the European Union on 12 November 2018, authorises the mobilisation of the European Globalisation Adjustment Fund (EGF) to provide a financial contribution of EUR 1 192 500 in commitment and payment appropriations from the general budget of the Union for the financial year 2018. The EGF aims to provide support for workers made redundant and self-employed persons whose activity has ceased as a result of major structural changes in world trade patterns due to globalisation, as a result of a continuation of the global financial and economic crisis, or as a result of a new global financial and economic crisis, and to assist them with their reintegration into the labour market. The mobilisation follows an application submitted by the Netherlands on 23 February 2018, in respect of redundancies in 20 enterprises operating in the Financial services sector in the regions of Friesland, Drenthe and Overijssel. The application was found to comply with the requirements for determining a financial contribution from the EGF as laid down in Article 13 of Regulation (EU) No 1309/2013. The EGF is not to exceed a maximum annual amount of EUR 150 million (2011 prices), as laid down in Article 12 of Council Regulation (EU, Euratom) No 1311/2013. This Decision entered into force on the day of its publication and applies from 2 October 2018.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32018d1985",
    "title": "Commission Implementing Decision (EU) 2018/1985 of 13 December 2018 not approving Willaertia magna c2c maky as an active substance for use in biocidal products of product-type 11 (Text with EEA relevance.)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-12-14",
    "bluf": "Commission Implementing Decision (EU) 2018/1985, adopted on 13 December 2018 and published in the Official Journal of the European Union on 14 December 2018, formally declines to approve the microorganism Willaertia magna c2c maky as an active substance for use in biocidal products of product-type 11 (preservatives for liquid cooling and processing systems), as described in Annex V to Regulation (EU) No 528/2012. The decision follows an application received on 17 March 2014 by the evaluating competent authority of France, an assessment report submitted on 15 March 2017, and a Biocidal Products Committee opinion formulated by the European Chemicals Agency on 26 April 2018 (ECHA/BPC/206/2018). According to that opinion, biocidal products of product-type 11 containing Willaertia magna c2c maky may not be expected to meet the criteria laid down in Article 19(1)(b) of Regulation (EU) No 528/2012. In particular, the scenarios evaluated in the human health risk assessment identified unacceptable risks and no safe use could be identified. Moreover, the innate efficacy of Willaertia magna c2c maky to control Legionella pneumophila was not sufficiently demonstrated. Taking into account the opinion of the European Chemicals Agency, the Commission considers it not appropriate to approve Willaertia magna c2c maky for use in biocidal products of product-type 11. The Decision entered into force on the twentieth day following its publication in the Official Journal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32018l0958",
    "title": "Directive (EU) 2018/958 - Proportionality Test Before Adoption of New Regulation of Professions",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Directive (EU) 2018/958 establishes a common framework that Member States must follow before introducing new, or amending existing, legislative, regulatory or administrative provisions that restrict access to, or the pursuit of, regulated professions falling within the scope of Directive 2005/36/EC. Member States must conduct an ex ante proportionality assessment whose depth is proportionate to the impact of the measure, ensure the measure is non-discriminatory on grounds of nationality or residence, demonstrate that it is justified by a public interest objective (purely economic or administrative grounds are not acceptable), and show that it is suitable and does not go beyond what is necessary, including by considering less restrictive means. Before adoption they must inform and involve stakeholders, guarantee an effective remedy, and record the reasons the measure is justified and proportionate in the EU database of regulated professions, which the Commission makes publicly available.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_primary_law",
        "related_instruments",
        "charter_reference",
        "internal_market"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-equal-treatment-employment-2000-78",
      "eu-posted-workers-directive-2018-957"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32018m8597",
    "title": "Commission Decision on Concentration Compatibility with the Common Market",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The European Commission received notification of a proposed concentration by APG Asset Management N.V. and Ardian S.A.S. to acquire joint control of a portfolio of ten undertakings. The Commission concluded that the notified operation falls within the scope of the Merger Regulation and declared it compatible with the internal market and the EEA Agreement. The decision was adopted in application of Article 6(1)(b) of the Merger Regulation and Article 57 of the EEA Agreement. The undertakings concerned are active in the transport infrastructure sector, energy infrastructure sector, and hospital concession operation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-celex-32018m8848",
    "title": "Commission Decision of 06/04/2018 declaring a concentration to be compatible with the common market (Case No COMP/M.8848 - CATHAY CAPITAL PRIVATE EQUITY / EQUISTONE PARTNERS EUROPE / E WINKEMANN) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-04-06",
    "bluf": "On 12 March 2018, the European Commission received notification of a proposed concentration pursuant to Article 4 of the Merger Regulation by which Cathay Capital Private Equity SAS (CCPE) (France) and Equistone Partners Europe Ltd (Equistone) (UK) acquire, within the meaning of Article 3(1)(b) and Article 3(4) of the Merger Regulation, joint control over the whole of E. Winkemann GmbH (Winkemann) (Germany) by way of purchase of shares. After examination of the notification, the European Commission concluded that the notified operation falls within the scope of the Merger Regulation and of paragraph 5(a) of the Commission Notice on a simplified procedure for treatment of certain concentrations under Council Regulation (EC) No 139/2004. For the reasons set out in the Notice on a simplified procedure, the European Commission decided not to oppose the notified operation and to declare it compatible with the internal market and with the EEA Agreement. This decision is adopted in application of Article 6(1)(b) of the Merger Regulation and Article 57 of the EEA Agreement. The decision was signed by Johannes Laitenberger, Director-General, on behalf of the Commission, dated Brussels, 6.4.2018, reference C(2018) 2168 final.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32018m8866",
    "title": "Commission Decision of 04/07/2018 declaring a concentration to be compatible with the common market (Case No COMP/M.8866 - MEC / MITSUI / SDPSK / JV) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-07-04",
    "bluf": "The European Commission received notification of a proposed concentration involving Mitsubishi Estate Co. Ltd. (MEC), Mitsui & Co., Ltd. (Mitsui), and Sime Darby Property (Sungai Kapar) Sdn Bhd (SDPSK) acquiring joint control of Sime Darby MIT Development Sdn Bhd (the JV) through the purchase of shares. The JV will develop property as a built-to-suit logistics/industrial park in Selangor, Malaysia. After examination, the Commission concluded that the operation falls within the scope of the Merger Regulation and decided not to oppose the notified operation, declaring it compatible with the internal market and the EEA Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32018m9074",
    "title": "Commission Decision of 11/09/2018 declaring a concentration to be compatible with the common market (Case No COMP/M.9074 - TOTAL S.A. / PONT SUR SAMBRE AND TOUL POWER) according to Council Regulation (EC) No 139/2004 (Only the English text is authentic)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-09-11",
    "bluf": "On 20 August 2018, the European Commission received notification of a proposed concentration pursuant to Article 4 of the Merger Regulation by which Total S.A. ('Total', France) acquires, within the meaning of Article 3(1)(b) of the Merger Regulation, sole control of the whole of Pont Sur Sambre Power SAS ('PSS Power', France), indirectly controlled by KKR & Co. Inc. ('KKR', USA) and Toul Power SAS ('Toul Power', France), indirectly controlled by KKR & Co. Inc. ('KKR', USA) by way of purchase of shares. PSS Power operates one combined cycle gas turbine ('CCGT') power plant located in the north of France and is active in the electricity and gas sectors; Toul Power operates one CCGT power plant located in the north of France and is active in the electricity and gas sectors. After examination of the notification, the European Commission concluded that the notified operation falls within the scope of the Merger Regulation and of paragraph 5(c) of the Commission Notice on a simplified procedure for treatment of certain concentrations under Council Regulation (EC) No 139/2004. For the reasons set out in the Notice on a simplified procedure, the European Commission decided not to oppose the notified operation and to declare it compatible with the internal market and with the EEA Agreement. This decision is adopted in application of Article 6(1)(b) of the Merger Regulation and Article 57 of the EEA Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32018r0012r-01",
    "title": "Corrigendum to Council Implementing Regulation (EU) 2018/12 of 8 January 2018 implementing Regulation (EU) 2017/1509 concerning restrictive measures against the Democratic People's Republic of Korea (OJ L 4, 9.1.2018)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-02-09",
    "bluf": "This corrigendum, published in the Official Journal of the European Union on 9 February 2018 (L 36/38), corrects an error in Council Implementing Regulation (EU) 2018/12 of 8 January 2018, which implements Regulation (EU) 2017/1509 concerning restrictive measures against the Democratic People's Republic of Korea. The correction applies to page 3 of the Annex, Part (a), entry 75, third column of the original regulation published in Official Journal L 4 of 9 January 2018. Specifically, the corrigendum replaces an incorrect date of birth and passport expiry date for the individual listed in entry 75. The erroneous entry stated a date of birth of 20.8.1965 and a passport expiry of 11.3.2019; the corrected entry reads a date of birth of 21.8.1957 and a passport expiry of 9.5.2018, with the passport number 563233049 remaining unchanged. All entities and competent authorities operating under the DPRK restrictive measures framework must apply this corrected identifying information when implementing and enforcing the relevant sanctions obligations under Regulation (EU) 2017/1509.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32018r0455",
    "title": "Commission Regulation (EU) 2018/455 of 16 March 2018 laying down additional responsibilities and tasks for the European Union reference laboratory for fish and crustacean diseases and amending Annex VII to Regulation (EC) No 882/2004 of the European Parliament and of the Council (Text with EEA relevance.)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-03-16",
    "bluf": "Commission Regulation (EU) 2018/455, adopted on 16 March 2018 and entering into force on 1 July 2018, designates Danmarks Tekniske Universitet, Veterinærinstituttet Afdeling for Diagnostik og Beredskab - Fiskesygdomme, 2800 Kgs. Lyngby, Denmark, as the European Union reference laboratory for crustacean diseases for the period from 1 July 2018 to 30 June 2023. This Regulation is binding in its entirety and directly applicable in all Member States. The Regulation arises from the United Kingdom's notification in accordance with Article 50 of the Treaty on European Union, which meant that the Centre for Environment, Fisheries & Aquaculture Science (Cefas), Weymouth, United Kingdom - previously designated as the EU reference laboratory for crustacean diseases under Commission Regulation (EC) No 737/2008 for the period from 1 July 2008 until 30 June 2018 - could not continue in that function for a further period starting on 1 July 2018. In view of the synergies in technical expertise, laboratory capacity and networking with national reference laboratories, the EU reference laboratory for fish diseases is designated to also take over the tasks and functions of the EU reference laboratory for crustacean diseases. Accordingly, Part II of Annex VII to Regulation (EC) No 882/2004 is amended to reflect the new combined EU reference laboratory for fish and crustacean diseases, and point 15 of that Annex, which previously listed Cefas, is deleted.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32018r0507",
    "title": "Commission Implementing Regulation (EU) 2018/507 of 26 March 2018 amending Annex I to Council Regulation (EEC) No 2658/87 on the tariff and statistical nomenclature and on the Common Customs Tariff",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-03-27",
    "bluf": "Commission Implementing Regulation (EU) 2018/507, adopted on 26 March 2018 and published in the Official Journal of the European Union on 27 March 2018, amends Annex I to Council Regulation (EEC) No 2658/87 by inserting a new Additional note 5 into Chapter 15 of Part Two of the Combined Nomenclature. The regulation is binding in its entirety and directly applicable in all Member States. The core obligation established by this regulation is that food preparations made from products of Chapter 15 - such as animal or vegetable oils - when presented in measured doses in the form of capsules, tablets, pastilles, or pills and intended for use as food supplements, are excluded from Chapter 15 and must instead be classified under heading 2106 ('Food preparations not elsewhere specified or included'). This classification rule reflects the jurisprudence of the Court of Justice of the European Union in Joined Cases C-410/08 to C-412/08 (Swiss Caps AG, judgment of 17 December 2009), which held that the form of presentation is a decisive factor revealing the function of the goods as a food supplement, determining dosage, absorption, and the place where the preparation is supposed to become active. The regulation applies to all economic operators, customs authorities, and Member States classifying such goods under the Combined Nomenclature, ensuring uniform interpretation throughout the Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32018r1559",
    "title": "Commission Implementing Regulation (EU) 2018/1559 of 17 October 2018 concerning the authorisation of cumin tincture (Cuminum cyminum L.) as a feed additive for all animal species (Text with EEA relevance.)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-10-18",
    "bluf": "Commission Implementing Regulation (EU) 2018/1559, adopted on 17 October 2018 and published in the Official Journal of the European Union on 18 October 2018, authorises cumin tincture (Cuminum cyminum L.) as a feed additive for all animal species under the additive category 'sensory additives' and functional group 'flavouring compounds'. The authorisation is subject to the conditions laid down in the Annex to this Regulation and remains valid until 7 November 2028. The European Food Safety Authority concluded in its opinion of 17 April 2018 that, under the proposed conditions of use, cumin tincture does not have adverse effects on animal health, human health or the environment. However, the Authority noted that a potential to be dermal/eye irritant cannot be excluded, and that the additive contains a variety of compounds known to cause allergic reactions in sensitive persons, meaning sensitisation may occur. Consequently, feed business operators must establish operational procedures and organisational measures to address potential risks by inhalation, dermal contact or eye contact, and where those risks cannot be eliminated or reduced to a minimum, the additive and premixtures shall be used with personal protective equipment, including breathing protection, safety glasses and gloves. The additive must be incorporated into feed in the form of a premixture, and the label must indicate a recommended maximum content of the active substance of 0.03 ml/kg of complete feedingstuff with a moisture content of 12%.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32018r1709",
    "title": "Commission Implementing Regulation (EU) 2018/1709 of 13 November 2018 specifying the technical characteristics of the 2020 ad hoc module on accidents at work and other work-related health problems as regards the labour force sample survey pursuant to Council Regulation (EC) No 577/98 (Text with EEA relevance.)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-11-13",
    "bluf": "This regulation specifies the technical characteristics of the 2020 ad hoc module on accidents at work and other work-related health problems as part of the labour force sample survey. It applies to Member States and requires the collection and transmission of data on work-related accidents, health problems, and risk factors. The regulation outlines the filters, codes, and deadlines for data submission to the Commission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32018r1785",
    "title": "Commission Implementing Regulation (EU) 2018/1785 of 15 November 2018 concerning the classification of certain goods in the Combined Nomenclature",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-11-15",
    "bluf": "The regulation concerns the classification of certain goods in the Combined Nomenclature, specifically insulated cables used in telecommunication networks. It applies to goods described in the Annex, ensuring uniform application of the Combined Nomenclature. The core obligation is to classify the goods under the specified CN codes, with binding tariff information that does not conform to this Regulation being invokable for three months from its entry into force.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32018r1847",
    "title": "Commission Regulation (EU) 2018/1847 of 26 November 2018 amending Annex V to Regulation (EC) No 1223/2009 of the European Parliament and of the Council on cosmetic products (Text with EEA relevance.)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-11-27",
    "bluf": "Commission Regulation (EU) 2018/1847, adopted on 26 November 2018 and published in the Official Journal of the European Union on 27 November 2018, amends Annex V to Regulation (EC) No 1223/2009 on cosmetic products. The Regulation specifically replaces entry 7 of Annex V, governing the use of Biphenyl-2-ol (o-phenylphenol) and its salts as preservatives in cosmetic products placed on the Union market. The Scientific Committee on Consumer Safety (SCCS) concluded that a maximum concentration of 0,2 % of o-phenylphenol in leave-on cosmetic products is not safe, while a maximum concentration of 0,15 % in such products can be considered safe, and that a maximum concentration of 0,2 % in rinse-off cosmetic products is considered safe. The SCCS also concluded that there might be a potential of injury to the vision system attributable to o-phenylphenol. Furthermore, the SCCS stated that sodium o-phenylphenate, potassium o-phenylphenate and MEA o-phenylphenate may have potentially more potent toxic effects than o-phenylphenol due to greater skin penetration, and that a potential risk to human health from the use of these substances as preservatives in cosmetic products cannot be excluded. Accordingly, the use of sodium o-phenylphenate, potassium o-phenylphenate and MEA o-phenylphenate as preservatives is no longer permitted. From 17 June 2019, non-compliant products shall not be placed on the Union market, and from 17 September 2019, they shall not be made available on the Union market. Contact with eyes must be avoided for all permitted uses.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32018r2004",
    "title": "Council Regulation (EU) 2018/2004 of 17 December 2018 amending Regulation (EU) 2016/44 concerning restrictive measures in view of the situation in Libya",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2018-12-17",
    "bluf": "This regulation amends Regulation (EU) 2016/44 to implement updated restrictive measures against Libya as per UN Security Council Resolution 2441 (2018). It targets natural or legal persons designated by the UN Security Council or its Sanctions Committee, reflecting new examples of conduct threatening international peace and security in Libya. The measures are binding and directly applicable in all EU Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32019d0874",
    "title": "Commission Implementing Decision (EU) 2019/874 of 22 May 2019 on the clearance of the accounts of the paying agencies of Member States concerning expenditure financed by the European Agricultural Guarantee Fund (EAGF) for financial year 2018 (notified under document C(2019) 3820)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2019-05-22",
    "bluf": "Commission Implementing Decision (EU) 2019/874, adopted on 22 May 2019 and published in the Official Journal of the European Union (L 140/115), clears the accounts of the paying agencies of EU Member States concerning expenditure financed by the European Agricultural Guarantee Fund (EAGF) for financial year 2018. The Decision is addressed to all Member States and is grounded in Article 51 of Regulation (EU) No 1306/2013, which requires the Commission to clear the accounts of paying agencies prior to 31 May of the year following the budget year in question, on the basis of annual accounts submitted by Member States accompanied by audit opinions on completeness, accuracy, and veracity. The financial year 2018 covers expenditure incurred between 16 October 2017 and 15 October 2018, as provided for in Article 11(1) of Commission Implementing Regulation (EU) No 908/2014. The Decision establishes the amounts recoverable from, or payable to, each Member State, including reductions for overrun of payment deadlines during August, September and October 2018, reductions or suspensions applied under Article 41 of Regulation (EU) No 1306/2013, and financial consequences of non-recovery of irregularities under Article 54(2) of that Regulation. Where recovery has not taken place within four years from the date of the recovery request, or within eight years where recovery is taken before national courts, 50% of the financial consequences of non-recovery of irregularities shall be borne by the Member State concerned. This Decision is explicitly without prejudice to future conformity clearance decisions the Commission may take pursuant to Article 52 of Regulation (EU) No 1306/2013.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32019d1578",
    "title": "Council Decision (EU) 2019/1578 of 20 September 2019 on the position to be adopted on behalf of the European Union within the Committee on Trade and Sustainable Development established by the Free Trade Agreement between the European Union and its Member States, of the one part, and the Republic of Korea, of the other part, as regards the Panel of Experts referred to in Article 13.15 of the Agreement",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2019-09-20",
    "bluf": "The Council Decision (EU) 2019/1578 establishes the position to be adopted on behalf of the European Union within the EU-Korea Committee on Trade and Sustainable Development regarding the list of experts willing and able to serve as panellists in accordance with Article 13.15 of the Free Trade Agreement between the European Union and its Member States and the Republic of Korea. The decision was made to ensure the effective implementation of the Agreement, particularly in response to the Republic of Korea's request to replace several Korean experts on the list. The revised list of experts must be approved by the Committee to take effect.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32019d2172",
    "title": "Council Decision (EU) 2019/2172 of 5 December 2019 establishing that no effective action has been taken by Hungary in response to the Council Recommendation of 14 June 2019",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2019-12-05",
    "bluf": "Council Decision (EU) 2019/2172, adopted on 5 December 2019 and published in the Official Journal of the European Union (L 329/91) on 19 December 2019, formally establishes that Hungary has not taken effective action in response to the Council Recommendation of 14 June 2019. That Recommendation was issued after the Council found that in 2018 a significant observed deviation from the adjustment path toward Hungary's medium-term budgetary objective had again occurred. The Recommendation required Hungary to ensure that the nominal growth rate of net primary government expenditure does not exceed 3,3 % in 2019 and 4,7 % in 2020, corresponding to an annual structural adjustment of 1,0 % of GDP in 2019 and 0,75 % of GDP in 2020. The Decision applies to Hungary as the sole addressee and is grounded in Council Regulation (EC) No 1466/97, specifically the fourth subparagraph of Article 10(2). Based on the Commission's 2019 autumn forecast, the growth of net primary government expenditure in 2019 is projected at 6,8 %, well above the recommended rate of 3,3 %, representing a deviation of 1,3 % of GDP. The structural balance is set to improve by only 0,5 % of GDP against the recommended 1,0 % of GDP. The Council concludes that Hungary's fiscal effort falls short of the required adjustment for 2019, while the planned fiscal effort for 2020 is overall consistent with the recommended adjustment. The Decision is addressed to Hungary and was signed at Brussels by Council President M. Lintilä.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32019r0149",
    "title": "Commission Implementing Regulation (EU) 2019/149 of 30 January 2019 amending Implementing Regulations (EU) 2015/1108 and (EU) No 540/2011 as regards the conditions of use of vinegar as a basic substance (Text with EEA relevance.)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2019-01-31",
    "bluf": "Commission Implementing Regulation (EU) 2019/149, adopted on 30 January 2019 and published in the Official Journal of the European Union on 31 January 2019, amends Implementing Regulations (EU) 2015/1108 and (EU) No 540/2011 as regards the conditions of use of vinegar as a basic substance under Regulation (EC) No 1107/2009 concerning the placing of plant protection products on the market. The Regulation extends the approved uses of vinegar beyond its previously restricted application as a fungicide and bactericide to now include use as a herbicide, following an application submitted by Charbonneaux-Brabant SA in November 2016 and a technical report issued by the European Food Safety Authority on 4 August 2017. It revokes the current restriction for use only as a fungicide and a bactericide, and permits other possible uses of vinegar as referred to in the latest version of the review report. The Regulation is binding in its entirety and directly applicable in all Member States, entering into force on the twentieth day following its publication in the Official Journal. Vinegar must be used in accordance with the specific conditions included in the conclusions of the review report on vinegar (SANCO/12896/2014) and in particular Appendices I and II thereof.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32019r0473",
    "title": "Regulation (EU) 2019/473 of the European Parliament and of the Council of 19 March 2019 on the European Fisheries Control Agency (codification)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2019-03-25",
    "bluf": "Regulation (EU) 2019/473 establishes the European Fisheries Control Agency ('the Agency'), the objective of which is to organise the operational coordination of fisheries control and inspection activities by the Member States and to assist them to cooperate so as to comply with the rules of the common fisheries policy in order to ensure its effective and uniform application. The Agency is a Union body with legal personality, seated in Vigo, Spain, and is granted legal, financial and administrative autonomy while maintaining close links with the Union institutions and the Member States. The Regulation applies to Member States of the European Union, the European Commission, and the Agency itself. Core obligations include: Member States must notify the Agency annually before 15 October of available means of control and inspection, and no later than one month from notification of any specific or international control and inspection programme of the means with which they intend to execute it. The Agency coordinates joint deployment plans, operates an emergency unit where a serious risk to the common fisheries policy is identified, conducts annual assessments of joint deployment plan effectiveness, and cooperates with the European Border and Coast Guard Agency and the European Maritime Safety Agency on coast guard functions. The Agency shall not have the power to impose additional obligations through joint deployment plans or to sanction Member States. Regulation (EC) No 768/2005 is repealed and replaced by this codification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32019r0816",
    "title": "Regulation (EU) 2019/816 of the European Parliament and of the Council of 17 April 2019 establishing a centralised system for the identification of Member States holding conviction information on third-country nationals and stateless persons (ECRIS-TCN) to supplement the European Criminal Records Information System and amending Regulation (EU) 2018/1726",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2019-05-22",
    "bluf": "Regulation (EU) 2019/816 establishes ECRIS-TCN, a centralised system at the Union level for identifying which Member States hold criminal records information on third-country nationals and stateless persons. The system is designed to supplement the existing European Criminal Records Information System (ECRIS) by enabling central authorities to rapidly and efficiently determine which Member States possess conviction data on a given third-country national, thereby eliminating the need for 'blanket requests' to all Member States - a practice described in the Regulation as imposing a disproportionate administrative burden. The Regulation applies to the processing of identity information - including alphanumeric data, fingerprint data, and facial images - of third-country nationals who have been subject to convictions in the Member States. It also applies to citizens of the Union who additionally hold the nationality of a third country. Central authorities are obliged to use ECRIS-TCN when criminal records information is requested for the purposes of criminal proceedings, security clearance, employment vetting, visa and migration procedures, and other specified purposes. eu-LISA is entrusted with the development and operational management of ECRIS-TCN. The Regulation establishes strict rules on data entry, retention, modification, erasure, data security, liability, and the rights of individuals to access, rectification, and redress, in conformity with applicable Union data protection rules including Directive (EU) 2016/680 and Regulation (EU) 2016/679.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32019r1243",
    "title": "Regulation (EU) 2019/1243 of the European Parliament and of the Council of 20 June 2019 adapting a number of legal acts providing for the use of the regulatory procedure with scrutiny to Articles 290 and 291 of the Treaty on the Functioning of the European Union (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2019-06-20",
    "bluf": "This Regulation adapts a number of legal acts providing for the use of the regulatory procedure with scrutiny to Articles 290 and 291 of the Treaty on the Functioning of the European Union. It applies to legislative acts adopted before the entry into force of the Treaty of Lisbon that confer powers on the Commission to adopt measures under the regulatory procedure with scrutiny. The Regulation ensures that these acts are aligned with the legal framework introduced by the Treaty of Lisbon, distinguishing between delegated acts and implementing acts. It also removes unnecessary empowerments in certain basic acts and provides for the exercise of implementing powers in accordance with Regulation (EU) No 182/2011.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32019r2117r-02",
    "title": "Corrigendum to Commission Regulation (EU) 2019/2117 of 29 November 2019 amending Council Regulation (EC) No 338/97 on the protection of species of wild fauna and flora by regulating trade therein (Official Journal of the European Union L 320 of 11 December 2019)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2019-12-20",
    "bluf": "The corrigendum amends Commission Regulation (EU) 2019/2117, which regulates international trade in fibre from vicuñas and their derivative products. It applies to any person or entity processing vicuña fibre to manufacture cloth and garments. The core obligation is to request authorization from the relevant authorities of the country of origin to use the 'vicuña country of origin' wording, mark, or logo. Additionally, marketed cloth or garments must be marked or identified in accordance with specific provisions, ensuring the country of origin is clearly indicated.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32019r2171",
    "title": "Commission Implementing Regulation (EU) 2019/2171 of 17 December 2019 initiating an investigation concerning possible circumvention of anti-dumping measures imposed by Implementing Regulation (EU) 2019/1267 on imports of tungsten electrodes originating in the People’s Republic of China by imports of tungsten electrodes consigned from India, Laos and Thailand, whether declared as originating in India, Laos and Thailand or not, and making such imports subject to registration",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2019-12-17",
    "bluf": "The European Commission, acting on its own initiative pursuant to Articles 13(3) and 14(5) of Regulation (EU) 2016/1036 (the basic Regulation), has initiated an investigation into the possible circumvention of anti-dumping measures imposed by Implementing Regulation (EU) 2019/1267 on imports of tungsten welding electrodes originating in the People's Republic of China. The investigation targets imports of the same product consigned from India, Laos and Thailand, whether declared as originating in those countries or not, falling under CN codes ex 8101 99 10 and ex 8515 90 80 (TARIC codes 8101991011, 8101991012, 8101991013 and 8515908011, 8515908012 and 8515908013). The Commission has at its disposal sufficient evidence of a significant change in the pattern of trade involving exports from the People's Republic of China and India, Laos and Thailand to the Union following the imposition of measures, which appears to stem from transhipment via those countries. The Commission has also established that there are no facilities to produce tungsten electrodes in any of these countries, that the remedial effects of existing measures are being undermined in terms of quantity and price, and that imports of the product under investigation are made at prices below the non-injurious price and are dumped in relation to the normal value previously established. All imports of the product under investigation are made subject to registration, and the investigation will be concluded within nine months of the date of entry into force of this Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32020d0457",
    "title": "Council Decision (EU) 2020/457 of 27 March 2020 on the position to be taken on behalf of the European Union in the International Grains Council concerning the accession of the Republic of Serbia to the Grains Trade Convention, 1995",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2020-03-27",
    "bluf": "Council Decision (EU) 2020/457, adopted on 27 March 2020 and published in the Official Journal of the European Union (L 97/12) on 30 March 2020, establishes the position to be taken on the Union's behalf in the International Grains Council concerning the accession of the Republic of Serbia to the Grains Trade Convention, 1995. The Decision directs that the Union's position shall be to approve the accession of the Republic of Serbia to the Convention. The Grains Trade Convention, 1995 was concluded by the Union by means of Council Decision 96/88/EC and entered into force on 1 July 1995. Pursuant to Article 27(2) of the Convention, it is open for accession by the Governments of all States upon such conditions as the International Grains Council considers appropriate. The Republic of Serbia formally applied for accession to the Convention on 23 January 2020, and is noted as a major producer of cereals, in particular maize. The Convention was last extended by decision of the International Grains Council on 10 June 2019 and remains in force until 30 June 2021. The Decision entered into force on the date of its adoption, 27 March 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32020d1268",
    "title": "Decision (EU) 2020/1268 of the European Parliament and of the Council of 15 July 2020 on the mobilisation of the Contingency Margin in 2020 to provide continued humanitarian support to refugees in Turkey",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2020-07-15",
    "bluf": "Decision (EU) 2020/1268, adopted by the European Parliament and the Council on 15 July 2020 and published in the Official Journal of the European Union on 11 September 2020, mobilises the Contingency Margin established under Article 13 of Council Regulation (EU, Euratom) No 1311/2013 to provide continued humanitarian support to refugees in Turkey. The Contingency Margin, which may amount to up to 0,03 % of the Gross National Income of the Union, is activated as a last-resort instrument after all other financial possibilities to react to unforeseen circumstances within the 2020 commitment ceiling for heading 4 (Global Europe) of the multiannual financial framework (MFF) were examined and no other special instruments were found available. The core obligation established by this Decision is the mobilisation of EUR 481 572 239 in commitment appropriations over and above the commitment ceiling of heading 4 (Global Europe) of the MFF for the financial year 2020. This total amount is offset against margins under the commitment ceilings of heading 5 (Administration) to the amount of EUR 16 248 368, and heading 2 (Sustainable growth: natural resources) to the amount of EUR 465 323 871. The Decision is directly linked to Amending Budget No 5 to the general budget of the European Union for 2020 and applies from the date of its adoption, 15 July 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32020d2049",
    "title": "European Council Decision 2020/2049: Appointment of ECB Executive Board Member",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The European Council Decision 2020/2049 appoints Mr Frank ELDERSON as a member of the Executive Board of the European Central Bank for a term of eight years, starting from 15 December 2020. The decision was made in accordance with Article 283(2) of the Treaty on the Functioning of the European Union, following recommendations from the Council of the European Union and opinions from the European Parliament and the Governing Council of the European Central Bank. The appointment is necessary due to the expiration of Mr Yves MERSCH's term of office on 14 December 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-celex-32020d2060",
    "title": "Council Decision (EU) 2020/2060 of 7 December 2020 on the position to be taken on behalf of the European Union within the Trade Committee established under the Interim Partnership Agreement between the European Community, of the one part, and the Pacific States, of the other part, as regards the amendment to that Agreement to take account of the accession of the Independent State of Samoa and of Solomon Islands",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2020-12-07",
    "bluf": "Council Decision (EU) 2020/2060, adopted at Brussels on 7 December 2020 and published in the Official Journal of the European Union (L 424/23) on 15 December 2020, establishes the position to be taken on behalf of the European Union within the Trade Committee established under the Interim Partnership Agreement between the European Community and the Pacific States. The Agreement, which establishes a framework for an economic partnership agreement, was signed in London on 30 July 2009 and has been provisionally applied by Papua New Guinea and Fiji since 20 December 2009 and 28 July 2014 respectively. Following the accession of the Independent State of Samoa on 21 December 2018 (provisionally applied since 31 December 2018) and the accession of Solomon Islands on 7 May 2020 (provisionally applied since 17 May 2020), it is necessary to amend Annex II to the Agreement to add those countries' market access offers. Article 13 of the Agreement provides that the Trade Committee by agreement may modify Annex II in any manner deemed appropriate. Accordingly, the Union's position at the Trade Committee's eighth meeting shall be based on the draft Decision of the Trade Committee (document ST 11630/20), authorising the introduction of the technical amendment to account for the accessions of Samoa and Solomon Islands. This Decision entered into force on the date of its adoption, 7 December 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32020r0116r-01",
    "title": "Corrigendum to Council Implementing Regulation (EU) 2020/116 of 27 January 2020 implementing Article 12(1) of Regulation (EU) 2017/1770 concerning restrictive measures in view of the situation in Mali (Official Journal of the European Union L 22 of 28 January 2020)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2020-02-20",
    "bluf": "This corrigendum, published in the Official Journal of the European Union on 20 February 2020 (LI 47/8), corrects a typographical error in Council Implementing Regulation (EU) 2020/116 of 27 January 2020, which itself implements Article 12(1) of Regulation (EU) 2017/1770 concerning restrictive measures in view of the situation in Mali. The original regulation was published in the Official Journal of the European Union L 22 of 28 January 2020. The correction applies to page 26 of the Annex, first entry, heading. The alias of the listed individual AHMED AG ALBACHAR is corrected from the erroneous spelling 'Intahmado Ag Albachar' to the correct spelling 'Intahmadou Ag Albachar'. This amendment is binding on all parties and competent authorities responsible for implementing and enforcing the EU restrictive measures (sanctions) regime relating to Mali, ensuring that the designation list accurately identifies the listed person by their correct alias.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32020r0686",
    "title": "Commission Delegated Regulation (EU) 2020/686 of 17 December 2019 supplementing Regulation (EU) 2016/429 of the European Parliament and of the Council as regards the approval of germinal product establishments and the traceability and animal health requirements for movements within the Union of germinal products of certain kept terrestrial animals (Text with EEA relevance) (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2020-06-03",
    "bluf": "This Regulation supplements Regulation (EU) 2016/429 as regards the approval of germinal product establishments and the traceability and animal health requirements for movements within the Union of germinal products of certain kept terrestrial animals. It applies to operators of germinal product establishments for bovine, porcine, ovine, caprine, and equine animals, and lays down detailed rules for the approval of such establishments, record-keeping obligations, traceability requirements, and animal health certification for movements between Member States. The Regulation aims to prevent the spread of transmissible animal diseases through germinal products by ensuring high standards of animal health and hygiene.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32020r1318",
    "title": "Commission Implementing Regulation (EU) 2020/1318 of 22 September 2020 amending Implementing Regulations (EU) 2020/21 and (EU) No 2020/194 as regards the dates of application in response to the COVID‐19 pandemic",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2020-09-22",
    "bluf": "Commission Implementing Regulation (EU) 2020/1318 amends Implementing Regulations (EU) 2020/21 and (EU) No 2020/194 to postpone the dates of application in response to the COVID-19 pandemic. The regulation affects Member States implementing VAT-related administrative cooperation and fraud prevention measures. Key changes include postponing the application of tax rates for supplies of goods and services under special schemes from 1 January 2021 to 1 July 2021. Additionally, corrections to VAT returns for supplies carried out before 1 July 2021 can be made until 10 August 2024. The regulation ensures continuity in VAT return corrections and aligns with amendments to Directive 2006/112/EC and Regulation (EU) No 904/2010.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32020r2235",
    "title": "Commission Implementing Regulation (EU) 2020/2235 of 16 December 2020 laying down rules for the application of Regulations (EU) 2016/429 and (EU) 2017/625 of the European Parliament and of the Council as regards model animal health certificates, model official certificates and model animal health/official certificates, for the entry into the Union and movements within the Union of consignments of certain categories of animals and goods, official certification regarding such certificates and repealing Regulation (EC) No 599/2004, Implementing Regulations (EU) No 636/2014 and (EU) 2019/628, Directive 98/68/EC and Decisions 2000/572/EC, 2003/779/EC and 2007/240/EC (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2020-12-16",
    "bluf": "This Regulation lays down rules regarding animal health certificates, official certificates, and animal health/official certificates required for the entry into the Union, movements within the Union, and between Member States of certain consignments of animals and goods. It establishes standard models for these certificates and specifies the conditions for their issuance and replacement. The Regulation applies to consignments of animals, products of animal origin, composite products, germinal products, animal by-products, sprouts for human consumption, and seeds intended for the production of sprouts for human consumption. It repeals several existing regulations and directives, consolidating their provisions into this single Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32021d0331-01",
    "title": "Commission Decision of 15 December 2020 instructing the central administrator to enter changes into the international credit entitlement tables in the European Union Transaction Log 2021/C 115/01",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2020-12-15",
    "bluf": "This Commission Decision, adopted on 15 December 2020 and published in the Official Journal of the European Union (C 115/1) on 31 March 2021, instructs the central administrator of the Union Registry to enter changes into the international credit entitlement tables in the European Union Transaction Log (EUTL). The Decision is grounded in Directive 2003/87/EC of the European Parliament and of the Council of 13 October 2003 establishing a system for greenhouse gas emission allowance trading within the Union, and in Commission Regulation (EU) No 389/2013 establishing a Union Registry, in particular Article 59(3) thereof. The Decision applies to operators of stationary installations and aircraft operators across multiple EU Member States - including Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Germany, Greece, Hungary, Ireland, Italy, Luxembourg, the Netherlands, Poland, Portugal, Romania, Slovakia, Spain, Sweden, and the United Kingdom - whose international credit entitlements are determined in accordance with Commission Regulation (EU) No 1123/2013. Member States notified changes to their international credit entitlement tables for the period from 2008 to 2020 pursuant to Article 59(3) of Regulation (EU) No 389/2013. The central administrator is obligated to enter the corresponding changes into the international credit entitlement tables in the EUTL, as set out in the Annex to the Decision. The changes notified are confirmed to be in conformity with Directive 2003/87/EC and with measures adopted pursuant to Article 11a(8) of that Directive, including Regulation (EU) No 1123/2013.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32021d0353",
    "title": "Council Decision (CFSP) 2021/353 of 25 February 2021 amending Decision 2012/642/CFSP concerning restrictive measures against Belarus",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2021-02-25",
    "bluf": "COUNCIL DECISION (CFSP) 2021/353 amends Decision 2012/642/CFSP concerning restrictive measures against Belarus. The decision extends the restrictive measures until 28 February 2022 and amends the title of Decision 2012/642/CFSP. It also updates the statements of reasons for nine natural and three legal persons included in the list of natural and legal persons, entities, and bodies subject to restrictive measures set out in the Annex to that Decision. The date of listing for all natural persons included in that Annex is added. The decision applies to entities and individuals involved in the situation in Belarus and is effective from the day following its publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32021d0908-01",
    "title": "Council Decision of 6 September 2021 adopting the Council’s position on the draft general budget of the European Union for the financial year 2022 2021/C 360 I/01",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2021-09-06",
    "bluf": "On 6 September 2021, the Council of the European Union adopted its position on the draft general budget of the European Union for the financial year 2022, as submitted by the Commission on 9 July 2021 (COM(2021) 300 final). The Council examined the Commission proposal with a view to defining a position consistent, on the revenue side, with Council Decision (EU, Euratom) 2020/2053 of 14 December 2020 on the system of own resources of the European Union and repealing Decision 2014/335/EU, Euratom, and, on the expenditure side, with Council Regulation (EU, Euratom) 2020/2093 of 17 December 2020 laying down the multiannual financial framework for the years 2021 to 2027. The legal basis for this decision is the Treaty on the Functioning of the European Union, in particular Article 314(3) thereof, in conjunction with the Treaty establishing the European Atomic Energy Community and in particular Article 106a thereof. The full text of the Council's position is accessible for consultation or downloading on the Council's website at This decision was published in the Official Journal of the European Union on 8 September 2021 as document 2021/C 360 I/01.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32021d0925",
    "title": "Council Decision (EU) 2021/925 of 7 June 2021 on the position to be taken on behalf of the European Union in the World Forum for Harmonisation of Vehicle Regulations of the United Nations Economic Commission for Europe as regards the proposals for modifications to UN Regulations Nos 13, 13-H, 24, 30, 41, 49, 79, 83, 95, 101, 124, 129, 134, 137 and 157, and the proposals for modifications to Global Technical Regulations Nos 4 and 9",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2021-06-07",
    "bluf": "Council Decision (EU) 2021/925, adopted at Luxembourg on 7 June 2021, establishes the position to be taken on behalf of the European Union in the 184th session of the UNECE World Forum for Harmonisation of Vehicle Regulations (UNECE WP.29), to be held between 22 and 24 June 2021. The Decision directs the Union to vote in favour of the proposals for modifications to UN Regulations Nos 13, 13-H, 24, 30, 41, 49, 79, 83, 95, 101, 124, 129, 134, 137 and 157, and the proposals for modifications to Global Technical Regulations Nos 4 and 9. The legal basis for this Decision rests on the Treaty on the Functioning of the European Union, in particular Article 114 in conjunction with Article 218(9), and flows from the Union's prior accession to the Revised 1958 Agreement (via Council Decision 97/836/EC) and the Parallel Agreement (via Council Decision 2000/125/EC). The UN Regulations are binding on the Union and, together with the UN GTRs, are capable of decisively influencing the content of Union law in the field of vehicle type-approval, as governed by Regulation (EU) 2018/858. The modifications are required because, in the light of experience and technical developments, the requirements relating to certain elements or features covered by the listed UN Regulations need to be amended, corrected or supplemented, and certain provisions in UN GTRs Nos 4 and 9 need to be amended.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32021r0115",
    "title": "Commission Delegated Regulation (EU) 2021/115 of 27 November 2020 amending Annex I to Regulation (EU) 2019/1021 of the European Parliament and of the Council as regards perfluorooctanoic acid (PFOA), its salts and PFOA-related compounds (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2021-02-02",
    "bluf": "Commission Delegated Regulation (EU) 2021/115, adopted on 27 November 2020 and published in the Official Journal of the European Union on 2 February 2021 (L 36/7), amends Annex I to Regulation (EU) 2019/1021 on persistent organic pollutants. The amendment specifically modifies the fourth column ('Specific exemption on intermediate use or other specification') of the entry for perfluorooctanoic acid (PFOA), its salts and PFOA-related compounds in Part A of Annex I. The regulation addresses three key changes: first, it introduces an Unintentional Trace Contaminant (UTC) limit of 2 mg/kg (0,0002 % by weight) for PFOA, its salts and/or PFOA-related compounds present in medical devices other than invasive devices and implantable devices, subject to a Commission review no later than 22 February 2023; second, it removes the reference to the 400 kilograys threshold for ionising irradiation in the production of PTFE micropowders, setting a UTC limit of 1 mg/kg (0,0001 % by weight) for PFOA and its salts in PTFE micropowders produced by ionising irradiation or by thermal degradation; and third, it clarifies that the UTC limit for PFOA-related compounds used as transported isolated intermediates applies to fluorochemicals with a 'perfluoro carbon chain equal to or shorter than 6 atoms'. This Regulation is binding in its entirety and directly applicable in all Member States, entering into force on the twentieth day following its publication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32021r0125",
    "title": "Commission Implementing Regulation (EU) 2021/125 of 28 January 2021 entering a name in the register of protected designations of origin and protected geographical indications (‘Huile de noix du Périgord’ (PDO))",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2021-01-28",
    "bluf": "Commission Implementing Regulation (EU) 2021/125, adopted at Brussels on 28 January 2021, enters the name 'Huile de noix du Périgord' into the register of protected designations of origin and protected geographical indications (PDO) under the authority of Regulation (EU) No 1151/2012 of the European Parliament and of the Council on quality schemes for agricultural products and foodstuffs. The registration was initiated pursuant to Article 50(2)(a) of Regulation (EU) No 1151/2012, following France's application to register the name, which was published in the Official Journal of the European Union (OJ C 308, 17.9.2020, p. 22). As no statement of opposition under Article 51 of Regulation (EU) No 1151/2012 was received by the Commission, the name was entered in the register without contest. The name 'Huile de noix du Périgord' (PDO) denotes a product in Class 1.5 - Oils and fats (butter, margarine, oil, etc.), as listed in Annex XI to Commission Implementing Regulation (EU) No 668/2014. This Regulation is binding in its entirety and directly applicable in all Member States, entering into force on the twentieth day following its publication in the Official Journal of the European Union. The core obligation established by this Regulation is the formal legal protection of the geographical indication 'Huile de noix du Périgord' as a PDO across the entire European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32021r0522",
    "title": "Regulation (EU) 2021/522 of the European Parliament and of the Council of 24 March 2021 establishing a Programme for the Union’s action in the field of health (‘EU4Health Programme’) for the period 2021-2027, and repealing Regulation (EU) No 282/2014 (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2021-03-24",
    "bluf": "The EU4Health Programme, established by Regulation (EU) 2021/522, aims to improve public health across the European Union for the period 2021-2027. It focuses on enhancing health systems' resilience, addressing cross-border health threats, and promoting health equity. The Programme supports actions such as health promotion, disease prevention, and the digital transformation of health services. It also aims to strengthen cooperation among Member States, improve access to medicinal products, and enhance crisis preparedness and response. The Programme is funded with a financial envelope of EUR 2,446,000,000, with specific allocations for health promotion, procurement of crisis-relevant products, and global health initiatives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32021r1379",
    "title": "Commission Implementing Regulation (EU) 2021/1379 of 19 August 2021 concerning the non-renewal of approval of the active substance famoxadone, in accordance with Regulation (EC) No 1107/2009 of the European Parliament and of the Council concerning the placing of plant protection products on the market, and amending Commission Implementing Regulation (EU) No 540/2011 (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2021-08-19",
    "bluf": "The European Commission has decided not to renew the approval of the active substance famoxadone under Regulation (EC) No 1107/2009 concerning the placing of plant protection products on the market. This decision is based on the European Food Safety Authority's conclusion that famoxadone poses a high risk to workers during crop hand-harvesting, a high long-term risk for mammals, and a high risk for aquatic organisms. Member States are required to withdraw authorizations for plant protection products containing famoxadone by 16 March 2022, with any grace periods not exceeding 12 months from the regulation's entry into force.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32021r1917",
    "title": "Commission Regulation (EU) 2021/1917 of 3 November 2021 amending Annex I to Regulation (EC) No 1334/2008 of the European Parliament and of the Council as regards the inclusion of 2-(4-methylphenoxy)-N-(1H-pyrazol-3-yl)-N-(thiophen-2-ylmethyl)acetamide in the Union list of flavourings (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2021-11-03",
    "bluf": "Commission Regulation (EU) 2021/1917, adopted on 3 November 2021 and published in the Official Journal of the European Union (L 389/15) on 4 November 2021, amends Annex I to Regulation (EC) No 1334/2008 to include the flavouring substance 2-(4-methylphenoxy)-N-(1H-pyrazol-3-yl)-N-(thiophen-2-ylmethyl)acetamide (FL No 16.133) in the Union list of flavourings and source materials approved for use in and on foods. The regulation applies to food business operators and flavouring manufacturers across all EU Member States who produce, place on the market, or use FL No 16.133 as a flavouring substance in specified food categories. The European Food Safety Authority (EFSA), in its opinion adopted on 12 September 2018 (EFSA Journal 2018;16(10):5421), concluded that the use of FL No 16.133 does not give rise to safety concerns when limited to specified maximum levels across defined food categories, provided the substance is only added to opaque foods and packed in containers protected from light, as the substance can be subject to photo-transformation in non-opaque beverages. The substance is not authorised for sale to the final consumer. Labelling of packages or containers must include the statement 'Contains substance FL 16.133. Protect from light to avoid its photo-transformation.' and an indication such as 'keep away from light'. The regulation entered into force on the twentieth day following its publication in the Official Journal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32021r2103",
    "title": "Commission Delegated Regulation (EU) 2021/2103 of 19 August 2021 laying down detailed rules on the operation of the web portal, pursuant to Article 49(6) of Regulation (EU) 2019/818 of the European Parliament and of the Council",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2021-12-01",
    "bluf": "This regulation lays down detailed rules on the operation of a web portal established by Regulation (EU) 2019/818. The web portal facilitates the exercise of rights to information, access, rectification, erasure, or restriction of processing of personal data for individuals whose data are processed in the multi-identity detector. It applies to EU Member States, except Ireland, and includes provisions for secure operation, data protection, and user interface requirements. The regulation specifies responsibilities for eu-LISA, the Commission, and Member States in managing the web portal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32022d2003",
    "title": "Council Decision (EU) 2022/2003 of 13 October 2022 on the position to be adopted on behalf of the European Union in the International Grains Council with respect to amending the Rules of Procedure under the Grains Trade Convention, 1995, as regards the external auditor’s contract period",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2022-10-13",
    "bluf": "Council Decision (EU) 2022/2003, adopted on 13 October 2022 and published in the Official Journal of the European Union (L 274/67) on 24 October 2022, establishes the position to be adopted on behalf of the European Union in the International Grains Council with respect to amending the Rules of Procedure under the Grains Trade Convention, 1995. The core obligation is that the Union shall vote in favour of amending Rule 31, point (a), of the Rules of Procedure, in accordance with the proposal submitted by the Secretariat of the International Grains Council on 14 April 2022. The proposed amendment increases the period of designation of the independent external auditor from three to five years, which may be renewed once for a maximum of three years, replacing the existing provision of three years renewable once for a maximum of two years. The objective of the amendment is to offer a longer contract period for potential auditors, who would in return offer more competitive prices for their services, thereby improving the financial sustainability of the International Grains Council. The Decision applies to the Council of the European Union acting under Article 207(4), first subparagraph, in conjunction with Article 218(9) of the Treaty on the Functioning of the European Union, and entered into force on the date of its adoption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32022r0270",
    "title": "Commission Implementing Regulation (EU) 2022/270 of 23 February 2022 correcting Implementing Regulation (EU) 2021/1410 concerning the authorisation of a preparation of Bacillus licheniformis DSM 28710 as a feed additive for laying hens, minor poultry species for laying, poultry species for breeding and ornamental birds (holder of authorisation Huvepharma NV) (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2022-02-23",
    "bluf": "Commission Implementing Regulation (EU) 2022/270, adopted on 23 February 2022 and published in the Official Journal of the European Union (L 43/7), corrects a prior authorisation instrument - Implementing Regulation (EU) 2021/1410 - which had incorrectly identified the species for which the feed additive Bacillus licheniformis DSM 28710 is authorised, specifically excluding turkeys for breeding from the column 'Species or category of animal'. The correcting Regulation replaces the entire Annex to Implementing Regulation (EU) 2021/1410 for the sake of clarity, restoring the correct species scope: laying hens, minor poultry species for laying, poultry species for breeding (including turkeys for breeding), and ornamental birds. The Regulation applies to feed business operators who produce, label, or place on the market the preparation of Bacillus licheniformis DSM 28710 (identification number 4b1828, held by Huvepharma NV) and any premixtures or compound feed containing it. Operators are granted a transitional period: preparations and premixtures produced and labelled before 25 August 2022 under the prior rules may continue to be placed on the market until existing stocks are exhausted; feed materials and compound feed produced and labelled before 25 February 2023 under the prior rules may similarly continue until stocks are exhausted. The Regulation entered into force on the day following its publication and is binding in its entirety and directly applicable in all Member States. The authorisation period for the additive runs until 19 September 2031.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32022r0877",
    "title": "Council Regulation (EU) 2022/877 of 3 June 2022 amending Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2022-06-03",
    "bluf": "COUNCIL REGULATION (EU) 2022/877 amends Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine. The regulation prohibits the provision of specialised financial messaging services to entities listed in Annex XV or any Belarusian entity owned more than 50% by an entity listed in Annex XV. Member States are required to implement penalties for infringements, which must be effective, proportionate, and dissuasive. The regulation also expands the list of entities subject to restrictions on dual-use goods and technology, and Belarusian credit institutions subject to restrictive measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32022r0958",
    "title": "Commission Implementing Regulation (EU) 2022/958 of 14 June 2022 entering a name in the register of protected designations of origin and protected geographical indications (‘Äkta Gränna Polkagrisar’ (PGI))",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2022-06-14",
    "bluf": "The Commission Implementing Regulation (EU) 2022/958 enters the name ‘Äkta Gränna Polkagrisar’ into the register of protected geographical indications (PGI). This regulation applies to Sweden’s application for the registration of the name ‘Äkta Gränna Polkagrisar’, which denotes a product in Class 2.3, including bread, pastry, cakes, confectionery, biscuits, and other baker’s wares. The regulation is binding and directly applicable in all Member States, and it enters into force on the twentieth day following its publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32022r0992",
    "title": "Regulation (EU) 2022/992 of the European Parliament and of the Council of 8 June 2022 amending Regulation (EU) 2016/1628 as regards the extension of the empowerment of the Commission to adopt delegated acts (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2022-06-08",
    "bluf": "Regulation (EU) 2022/992 amends Regulation (EU) 2016/1628 to extend the empowerment of the Commission to adopt delegated acts. This regulation applies to the European Union and its Member States, focusing on the emission of gaseous and particulate pollutants and type-approval for internal combustion engines for non-road mobile machinery. The core obligation is to extend the Commission's power to adopt delegated acts for a period of 10 years from 6 October 2016, with provisions for further extensions. The Commission is required to draw up a report on the delegation of power by 6 January 2026 and nine months before the end of each following five-year period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32022r1359",
    "title": "Commission Implementing Regulation (EU) 2022/1359 of 27 July 2022 amending Council Regulation (EC) No 2368/2002 implementing the Kimberley Process certification scheme for the international trade in rough diamonds",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2022-08-05",
    "bluf": "Commission Implementing Regulation (EU) 2022/1359, adopted on 27 July 2022 and published in the Official Journal of the European Union (L 205/99), amends Council Regulation (EC) No 2368/2002, which implements the Kimberley Process certification scheme (KP certification scheme) for the international trade in rough diamonds. The regulation enters into force on the twentieth day following its publication in the Official Journal of the European Union and is binding in its entirety and directly applicable in all Member States. The core obligations effected by this implementing regulation are twofold. First, Annex II to Regulation (EC) No 2368/2002 - which lists the participants in the KP certification scheme and their respective competent authorities - is replaced in full to reflect the admission of Kyrgyzstan, Mozambique and Qatar to the KP certification scheme, as agreed at the Seventeenth Kimberley Process Plenary Meeting held in Moscow, Russian Federation, in November 2021, and to update the addresses of competent authorities of several participants. Second, Annex III - which lists Community authorities maintained by the Commission as referred to in Article 19 of Regulation (EC) No 2368/2002 - is likewise replaced in full to reflect updated addresses of Community authorities. The regulation applies to all participants in the KP certification scheme and to Member States' competent authorities responsible for controlling imports and exports of rough diamonds and issuing Community certificates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32022r2047",
    "title": "Commission Implementing Regulation (EU) 2022/2047 of 24 October 2022 correcting Implementing Regulation (EU) 2021/2325 as regards the recognition of certain control authorities and control bodies for the purpose of importing organic products into the Union",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2022-10-25",
    "bluf": "This regulation corrects Implementing Regulation (EU) 2021/2325 regarding the recognition of certain control authorities and control bodies for importing organic products into the European Union. It addresses errors in the recognition of 'Ecocert SA' for Bahrain and 'Florida Certified Organic Growers and Consumers, Inc. (FOG), DBA as Quality Certification Services (QCS)' for Costa Rica. The corrections are retroactively applied from the date of entry into force of Implementing Regulation (EU) 2021/2325. The regulation is binding and directly applicable in all Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32022r2049",
    "title": "Commission Implementing Regulation (EU) 2022/2049 of 24 October 2022 amending Implementing Regulation (EU) 2021/2325 as regards the recognition of certain control authorities and control bodies for the purpose of importing organic products into the Union",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2022-10-24",
    "bluf": "This regulation amends Implementing Regulation (EU) 2021/2325 to update the list of recognized control authorities and control bodies for importing organic products into the European Union. It addresses specific cases of non-compliance, including contamination of organic products with substances not allowed in organic production, and failures by certain control bodies to demonstrate compliance with equivalent production rules and control arrangements. The regulation withdraws recognition from several control bodies due to these violations and updates information for others based on notifications received by the Commission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32022r2579",
    "title": "Commission Delegated Regulation (EU) 2022/2579 of 10 June 2022 supplementing Directive 2013/36/EU of the European Parliament and of the Council with regard to regulatory technical standards specifying the information to be provided by an undertaking in the application for authorisation in accordance with Article 8a of that Directive (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2022-12-29",
    "bluf": "Commission Delegated Regulation (EU) 2022/2579, adopted on 10 June 2022 and published in the Official Journal of the European Union on 29 December 2022, establishes regulatory technical standards specifying the information that investment firms must provide when applying for authorisation as credit institutions under Article 8a of Directive 2013/36/EU. The Regulation applies to investment firms that meet the conditions set out in Article 4(1), point (1)(b), of Regulation (EU) No 575/2013 - that is, those which are required to seek authorisation as credit institutions - and is directly applicable in all EU Member States. The core obligation requires that any application for authorisation comply with the information requirements for credit institutions laid down in Articles 3 to 10 of Delegated Regulation (EU) 2022/2580, covering identification details, historical information, existing licensing, proposed activities, current financial situation, programme of operations, and initial capital. Competent authorities may require additional information that is proportionate and relevant for the authorisation assessment, and may also waive certain requirements taking into account the size, nature, scale and complexity of the applicant's activities and the principle of proportionality. The applicant credit institution must ensure that all submitted information remains up to date, complete, and accurate as of the date of submission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32023d0252",
    "title": "Council Decision (CFSP) 2023/252 of 4 February 2023 amending Decision 2014/512/CFSP concerning restrictive measures in view of Russia’s actions destabilising the situation in Ukraine",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-02-04",
    "bluf": "Council Decision (CFSP) 2023/252, adopted on 4 February 2023 and published in the Official Journal of the European Union (LI 32/11), amends Decision 2014/512/CFSP concerning restrictive measures in view of Russia's actions destabilising the situation in Ukraine. The Decision introduces two additional price caps for petroleum products originating in or exported from Russia: one for petroleum products traded at a discount to crude oil (set at USD 45 per barrel) and one for petroleum products traded at a premium to crude oil (set at USD 100 per barrel). These price caps apply as of 5 February 2023 to petroleum products falling under CN code 2710. The Decision applies to any natural or legal person involved in the purchase, import, transfer, maritime transport, technical assistance, brokering services, financing, or financial assistance related to Russian crude oil or petroleum products. It prohibits such activities unless the purchase price per barrel does not exceed the prices laid down in Annex XI to Decision 2014/512/CFSP. A transitional period of 55 days is introduced for vessels carrying petroleum products originating in Russia which are purchased and loaded onto the vessel prior to 5 February 2023 and unloaded prior to 1 April 2023. The price cap mechanism shall be reviewed by mid-March 2023 and every 2 months thereafter, with the price cap required to be at least 5% below the average market price for Russian oil and petroleum products as calculated on the basis of data provided by the International Energy Agency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32023d0601-01",
    "title": "Council Decision Appointing EU-OSHA Management Board Members for Luxembourg",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "The Council of the European Union appointed one member and one alternate member of the Management Board of the European Agency for Safety and Health at Work for Luxembourg, as per Council Decision of 30 May 2023. The appointments are for the period ending on 31 March 2027. The member appointed is Mr Hernani GOMES and the alternate member is Mr Christophe KNEBELER. The decision was made in accordance with the Treaty on the Functioning of the European Union and Regulation (EU) 2019/126 of the European Parliament and of the Council of 16 January 2019. The Council shall appoint the remaining members and alternate members at a later date.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32023d1112",
    "title": "Commission Decision (Euratom) 2023/1112 of 17 July 2020 on the notification of changes to the Euratom delineated peaceful nuclear programme in Annex A to the Agreement for cooperation in the peaceful uses of nuclear energy between the European Atomic Energy Community and the United States of America",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-06-07",
    "bluf": "Commission Decision (Euratom) 2023/1112, adopted on 17 July 2020 and published in the Official Journal of the European Union on 7 June 2023 (L 147/156), approves the notification of changes to the Euratom delineated peaceful nuclear programme set out in Annex A to the Agreement for cooperation in the peaceful uses of nuclear energy between the European Atomic Energy Community and the United States of America. The Agreement was signed at Brussels on 7 November 1995 and entered into force on 12 April 1996. The Decision applies to the European Commission, the Commissioner responsible for Energy, and the Director-General of the Directorate-General for Energy, authorising them to transmit a formal notification to the US Department of State. The core obligation is twofold: first, to add the RECUMO facility - a new installation for recycling highly radioactive residues resulting from the production of radioactive isotopes for medical purposes, to be operated by SCK.CEN at its site in Mol, Belgium - to the list of facilities in Annex A, as required by Article 8(2) of the Agreement, since the irradiated materials to be processed are of US origin; and second, to delete two decommissioned nuclear facilities from the Euratom delineated peaceful nuclear programme. The procedure for these changes, including the requirement for a written notification and a written acknowledgment by the appropriate authorities, is governed by paragraph 6 and paragraph 7(A) and (C) of the Agreed Minute to the Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32023d1212",
    "title": "Commission Implementing Decision (EU) 2023/1212 of 21 June 2023 renewing the authorisation for placing on the market of products containing, consisting of or produced from genetically modified soybean MON 87701 pursuant to Regulation (EC) No 1829/2003 of the European Parliament and of the Council (notified under document C(2023) 3944) (Only the text in Dutch is authentic) (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-06-21",
    "bluf": "The European Commission has renewed the authorisation for placing on the market of products containing, consisting of, or produced from genetically modified soybean MON 87701. This decision applies to foods, food ingredients, feed, and other products containing or consisting of this soybean, with the exception of cultivation. The authorisation holder, Bayer CropScience LP, must ensure compliance with labelling requirements, implement a monitoring plan for environmental effects, and submit annual reports on the results of this plan. The decision is valid for 10 years from the date of notification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32023d1306",
    "title": "Council Decision (CFSP) 2023/1306 of 26 June 2023 in support of a project on a zone free of weapons of mass destruction in the Middle East (ME WMDFZ) in an evolving regional security environment",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-06-26",
    "bluf": "Council Decision (CFSP) 2023/1306, adopted on 26 June 2023, authorises the European Union to support a project implemented by the United Nations Institute for Disarmament Research (UNIDIR) aimed at advancing the establishment of a zone free of weapons of mass destruction in the Middle East (ME WMDFZ). The Decision is grounded in the 2016 EU Global Strategy, the 2003 EU Strategy against WMD proliferation, and the 1995 Barcelona Declaration, and reflects the Union's longstanding policy to uphold, implement, and strengthen disarmament and non-proliferation treaties, agreements, and norms. The core obligations established by this Decision are: the High Representative (HR) is responsible for implementation and shall enter into the necessary arrangements with UNIDIR; the Commission shall conclude a contribution agreement with UNIDIR and supervise proper management of expenditure; a financial reference amount of EUR 2 099 969 is allocated; UNIDIR shall prepare 12-monthly narrative reports forming the basis for Council evaluation; and the Decision expires 36 months after conclusion of the contribution agreement, or six months after entry into force if no financing agreement has been concluded. The project runs across three workstreams covering research and threat perception analysis, regional capacity building, and support for effective, verifiable, inclusive, and sustainable ME WMDFZ negotiations and implementation, with a projected timeline from mid-July 2023 to July 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32023d2821",
    "title": "Council Decision (EU) 2023/2821 of 4 December 2023 on the position to be adopted, on behalf of the European Union, within the EEA Joint Committee concerning the amendment to Annexes V (Free movement of workers) and VI (Social security) and Protocol 31 (On cooperation in specific fields outside the four freedoms) to the EEA Agreement (ELA Regulation)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-12-14",
    "bluf": "Council Decision (EU) 2023/2821, adopted at Brussels on 4 December 2023 and published in the Official Journal of the European Union on 14 December 2023, establishes the position to be adopted on behalf of the European Union within the EEA Joint Committee concerning the amendment to Annexes V (Free movement of workers) and VI (Social security) and Protocol 31 (On cooperation in specific fields outside the four freedoms) to the EEA Agreement. The Decision mandates the incorporation of Regulation (EU) 2019/1149 of the European Parliament and of the Council of 20 June 2019 establishing a European Labour Authority (ELA) into the EEA Agreement, and provides that Regulation (EU) 2019/1149 repeals, with effect from 1 August 2021, Decision (EU) 2016/344. The Decision applies to the European Union and the EFTA States party to the EEA Agreement. Core obligations include amending Annex V to incorporate the ELA Regulation with specific EEA adaptations - including that EFTA States shall participate fully in the Platform and the Management Board with the same rights and obligations as EU Member States except for the right to vote, that EFTA States shall grant privileges and immunities to the Authority and its staff equivalent to those in Protocol No 7, and that an EFTA State may designate the National Liaison Officer of another EFTA State or EU Member State as its own. The Decision enters into force on the date of its adoption, while the attached draft Decision of the EEA Joint Committee enters into force provided that all notifications under Article 103(1) of the EEA Agreement have been made.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32023r0167",
    "title": "Commission Delegated Regulation EU 2023/167 amending multiannual rolling planning",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Commission Delegated Regulation EU 2023/167 amends Delegated Regulation EU 2020/256 to establish a multiannual rolling planning for the collection of data under Regulation EU 2019/1700 from 2021 to 2028. The adaptations of the multiannual rolling planning are to enter into force no later than 24 months before the beginning of each data collection period. The regulation amends Annex I to Delegated Regulation EU 2020/256 to specify the ad hoc subject to be covered by the ad hoc module for 2025 of the European Survey on Income and Living Conditions EU-SILC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-celex-32023r0216",
    "title": "Commission Implementing Regulation (EU) 2023/216 of 1 February 2023 approving the low-risk active substance Trichoderma atroviride AGR2 in accordance with Regulation (EC) No 1107/2009 of the European Parliament and of the Council concerning the placing of plant protection products on the market, and amending Commission Implementing Regulation (EU) No 540/2011 (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-02-01",
    "bluf": "Commission Implementing Regulation (EU) 2023/216, adopted on 1 February 2023 and published in the Official Journal of the European Union (L 30/7) on 2 February 2023, approves the active substance Trichoderma atroviride AGR2 as a low-risk active substance pursuant to Article 22 of Regulation (EC) No 1107/2009 concerning the placing of plant protection products on the market. The approval is effective from 22 February 2023 and expires on 21 February 2038. The Regulation applies to all Member States of the European Union, is binding in its entirety, and is directly applicable in all Member States. The approval was initiated by an application submitted on 24 April 2018 by Agrolor to France as rapporteur Member State. The Commission established that Trichoderma atroviride AGR2 is not a microorganism of concern and fulfils the conditions set in Annex II point 5.2 to Regulation (EC) No 1107/2009. Member States are required to implement uniform principles as referred to in Article 29(6) of Regulation (EC) No 1107/2009, taking into account the conclusions of the review report and in particular Appendices I and II thereof. Specific attention must be paid to the specification of the technical material as commercially manufactured, including full characterisation of relevant secondary metabolites, and to the protection of operators and workers, given that microorganisms are per se considered as potential sensitizers, with use of PPE/RPE recommended to reduce dermal and inhalation exposure. Commission Implementing Regulation (EU) No 540/2011 is amended accordingly by adding Trichoderma atroviride AGR2 as entry No. 42 in Part D of its Annex.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32023r0851",
    "title": "Regulation (EU) 2023/851 of the European Parliament and of the Council of 19 April 2023 amending Regulation (EU) 2019/631 as regards strengthening the CO2 emission performance standards for new passenger cars and new light commercial vehicles in line with the Union’s increased climate ambition (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-04-19",
    "bluf": "The regulation amends Regulation (EU) 2019/631 to strengthen CO2 emission performance standards for new passenger cars and light commercial vehicles, aligning with the EU's increased climate ambition. It sets stricter EU fleet-wide targets for CO2 emissions reductions, aiming for a 100% reduction by 2035. The regulation applies to manufacturers of new passenger cars and light commercial vehicles registered in the EU. Core obligations include achieving specific emissions targets, promoting zero-emission vehicles, and ensuring a just transition towards climate neutrality.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32023r0972",
    "title": "Commission Implementing Regulation (EU) 2023/972 of 10 May 2023 authorising the placing on the market of aqueous ethanolic extract of Labisia pumila as a novel food and amending Implementing Regulation (EU) 2017/2470 (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-05-17",
    "bluf": "Commission Implementing Regulation (EU) 2023/972, adopted on 10 May 2023 and entering into force on the twentieth day following its publication in the Official Journal of the European Union (effective 6 June 2023), authorises the placing on the market within the Union of aqueous ethanolic extract of Labisia pumila as a novel food under Regulation (EU) 2015/2283. The novel food is authorised exclusively for use in food supplements as defined in Directive 2002/46/EC, intended for the adult population excluding pregnant and lactating women, at a maximum use level of 350 mg per day. Only the company Medika Natura Sdn. Bhd. is authorised to place the novel food on the Union market for a period of five years from 6 June 2023, unless a subsequent applicant obtains authorisation without reference to the protected scientific data or with the agreement of Medika Natura Sdn. Bhd. The scientific data contained in the application file - including pharmacokinetic study in rats, bacterial reverse mutation test, in vitro mammalian chromosome aberration test, mammalian erythrocyte micronucleus test in mice, repeated dose (90 days) oral toxicity study in rats, solubility test, in vitro micronucleus test, and one year chronic toxicity test - shall not be used for the benefit of a subsequent applicant for a period of five years from the date of entry into force of this Regulation without the agreement of Medika Natura Sdn. Bhd. Labelling of food supplements containing the novel food must bear a statement that they should only be consumed by persons above 18 years of age excluding pregnant and lactating women.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32023r0996",
    "title": "Commission Delegated Regulation (EU) 2023/996 of 23 February 2023 amending Regulation (EU) 2021/821 of the European Parliament and of the Council as regards the list of dual-use items",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-05-25",
    "bluf": "Commission Delegated Regulation (EU) 2023/996, adopted on 23 February 2023 and published in the Official Journal of the European Union on 25 May 2023, amends Regulation (EU) 2021/821 by replacing Annex I thereto with an updated common list of dual-use items subject to Union export controls. Pursuant to Regulation (EU) 2021/821, dual-use items are to be subject to effective control when they are exported from or in transit through the Union, or are delivered to a third country as a result of brokering services provided by a broker resident or established in the Union. The list of dual-use items contained in the Annex implements internationally agreed dual-use controls including the Australia Group, the Missile Technology Control Regime (MTCR), the Nuclear Suppliers Group (NSG), the Wassenaar Arrangement, and the Chemical Weapons Convention (CWC). The update was necessitated because the control lists adopted by the international non-proliferation regimes and export control arrangements were changed during 2022, and therefore Annex I to Regulation (EU) 2021/821 was amended to include items subject to control under the Australia Group. The Regulation is binding in its entirety and directly applicable in all Member States, entering into force on the day following that of its publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32023r1139",
    "title": "Commission Implementing Regulation (EU) 2023/1139 of 8 June 2023 amending for the 336th time Council Regulation (EC) No 881/2002 imposing certain specific restrictive measures directed against certain persons and entities associated with the ISIL (Da'esh) and Al-Qaida organisations",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-06-09",
    "bluf": "This regulation amends Annex I to Council Regulation (EC) No 881/2002, which imposes specific restrictive measures against persons and entities associated with ISIL (Da'esh) and Al-Qaida. The amendment updates the identifying data for one entry in the list of persons, groups, and entities subject to the freezing of funds and economic resources. The regulation applies to all Member States of the European Union and is directly applicable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32023r2117",
    "title": "Commission Implementing Regulation (EU) 2023/2117 of 12 October 2023 laying down the necessary rules and detailed requirements for the functioning and management of a repository of information pursuant to Regulation (EU) 2018/1139 of the European Parliament and of the Council",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-10-13",
    "bluf": "This Regulation lays down the rules and procedures for the functioning and management of a repository of information necessary to ensure effective cooperation between the European Union Aviation Safety Agency (the Agency) and the national competent authorities concerning the exercise of their tasks relating to certification, oversight and enforcement under Regulation (EU) 2018/1139. The repository is composed of Storage, Exchange, and User Access interfaces, and the Agency is responsible for its operational management, maintenance, and security. The Regulation also establishes requirements for the classification of information, dissemination of information to interested parties, and protection of personal data stored in the repository.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32023r2462",
    "title": "Commission Delegated Regulation EU 2023/2462 supplementing Regulation EU 2019/1022",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "Commission Delegated Regulation EU 2023/2462 specifies details of the landing obligation for certain demersal stocks in the western Mediterranean Sea, supplementing Regulation EU 2019/1022. The regulation provides for survivability exemptions and de minimis exemptions for various species, including scallop, carpet clams, red sea bream, lobster, and crawfish. The exemptions apply to Union waters of the Western Mediterranean Sea and are subject to certain conditions, including the submission of additional discard data and research results by Member States. The regulation enters into force on January 1, 2024, and applies until December 31, 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32023r2465",
    "title": "Commission Delegated Regulation (EU) 2023/2465 of 17 August 2023 supplementing Regulation (EU) No 1308/2013 of the European Parliament and of the Council as regards marketing standards for eggs, and repealing Commission Regulation (EC) No 589/2008",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-11-08",
    "bluf": "This Regulation supplements Regulation (EU) No 1308/2013 with rules on the marketing standards for eggs of hens of the Gallus gallus species, except eggs for hatching. It covers classification criteria, preservation and handling, marking and packing requirements, use of optional reserved terms, tolerance levels, and conditions for imports and exports. The regulation applies to operators involved in the marketing of eggs, including producers, collectors, and packing centers. Core obligations include maintaining quality characteristics for Class A eggs, prohibiting washing or cleaning of Class A eggs except under specific conditions, and specifying weight grading and marking requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32024d05871",
    "title": "Commission Decision of 30 September 2024 approving on behalf of the European Union, the position to be taken as regards amendments to Annexes 10-A and 10-B to the Free Trade Agreement between the European Union and the Republic of Singapore",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-09-30",
    "bluf": "Commission Decision C/2024/5871, adopted on 30 September 2024 and published in the Official Journal of the European Union on 1 October 2024, approves on behalf of the European Union the position to be taken by the EU-Singapore Trade Committee regarding amendments to Annexes 10-A and 10-B to the Free Trade Agreement between the European Union and the Republic of Singapore, which entered into force on 21 November 2019. The Decision authorises EU representatives in the Trade Committee to approve the adoption of a Trade Committee Decision that amends the lists of Geographical Indications (GIs) protected under the Agreement. The core obligation flows from Articles 10.17.3 and 10.18 of the Agreement. Article 10.17.3 requires the Trade Committee to list in Annex 10-B (Protected Geographical Indications) the names from Annex 10-A after the conclusion of protection procedures. The Republic of Singapore has completed protection procedures for four names previously listed in Annex 10-A ('Bayerisches Bier', 'Guijuelo', 'Siurana', 'Utiel-Requena') and twenty-one additional names not listed in Annex 10-A. Consequently, Annexes 10-A and 10-B are to be replaced in their entirety, adding twenty-five names as protected GIs of the Union in Annex 10-B, removing four names from Annex 10-A, and updating two name changes ('Alsace' to 'Alsace / Vin d'Alsace' and 'Jamón de Teruel' to 'Jamón de Teruel / Paleta de Teruel') in Annex 10-A.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32024d1470",
    "title": "Council Decision (CFSP) 2024/1470 of 21 May 2024 amending Decision 2014/512/CFSP concerning restrictive measures in view of Russia’s actions destabilising the situation in Ukraine",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-05-22",
    "bluf": "Council Decision (CFSP) 2024/1470, adopted on 21 May 2024 and published in the Official Journal of the European Union on 22 May 2024, amends Decision 2014/512/CFSP to introduce additional exceptional measures directing extraordinary revenues generated by central securities depositories (CSDs) - accruing as a result of the immobilisation of assets and reserves of the Central Bank of Russia - toward the support of Ukraine and its recovery, reconstruction, and self-defence against Russia's war of aggression. The Decision applies to central securities depositories within the meaning of Regulation (EU) No 909/2014 that hold assets and reserves of the Central Bank of Russia, or those of any legal person, entity or body acting on behalf of, or at the direction of, the Central Bank of Russia, with a total value exceeding EUR 1 million. As of 15 February 2024, such CSDs are required to account for and manage extraordinary cash balances separately, register revenues separately in their financial accounts, and contribute a financial contribution equivalent to 99.7% of the resulting net profits to the Union. These net profits shall not be distributed as dividends or in any form to shareholders or third parties. The financial contribution is to be allocated 90% to the European Peace Facility and 10% to Union programmes financed from the Union budget, with payments made in biannual instalments. CSDs may provisionally retain up to 10% of the financial contribution to meet statutory capital and risk management requirements, with any unused retained amounts to be transferred to the Union within five years or upon discontinuation of the restrictive measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32024d2549",
    "title": "Commission Decision (EU) 2024/2549 of 29 November 2023 on State aid SA.57543 and SA.58342 (2020/NN) (ex 2020/N), implemented by the Kingdom of Denmark and the Kingdom of Sweden for Scandinavian Airlines System AB (notified under document C(2023) 8356)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-10-01",
    "bluf": "Commission Decision (EU) 2024/2549, adopted on 29 November 2023 and published in the Official Journal of the European Union on 1 October 2024, concerns State aid cases SA.57543 and SA.58342 implemented by the Kingdom of Denmark and the Kingdom of Sweden for Scandinavian Airlines System AB ('SAS'). The Measure comprised two recapitalisation instruments: the subscription by Denmark and Sweden to State hybrid notes (the 'hybrid capital instrument') and the subscription by those two Member States of new common shares (the 'equity instrument'), with a total maximum notified amount of approximately SEK 11 billion (EUR 1.069 billion). The Measure was originally notified under Article 107(3), point (b), TFEU as interpreted by section 3.11 of the Temporary Framework for State aid measures to support the economy in the COVID-19 pandemic. The initial decision of 17 August 2020 was subsequently annulled by the General Court in Case T-238/21 (the 'SAS II judgment') of 10 May 2023, on the ground that the Commission had failed to require the inclusion of a step-up or an alternative mechanism regarding the equity instrument, contrary to points 61 and 62 of the Temporary Framework. Following that annulment, the Commission initiated the procedure under Article 108(2) TFEU, collected comments from interested parties including SAS and Ryanair, and re-assessed the Measure based on the facts and elements prevailing at the time the aid was granted on 26 October 2020. Denmark and Sweden ultimately paid SEK 9.54 billion (EUR 907 million) in aid. The Decision applies to Denmark and Sweden as granting Member States and to SAS as the sole beneficiary.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32024d2846",
    "title": "Council Decision (CFSP) 2024/2846 of 5 November 2024 amending Decision (CFSP) 2021/509 establishing a European Peace Facility",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-11-05",
    "bluf": "Council Decision (CFSP) 2024/2846, adopted on 5 November 2024 at Brussels and signed by Council President VARGA M., amends Decision (CFSP) 2021/509 establishing a European Peace Facility. The Decision enters into force on the date of its adoption. It applies to EU Member States participating in military missions, operations, and exercises under the Common Security and Defence Policy (CSDP), and to the EU Rapid Deployment Capacity (EU RDC), including EU Battlegroups, strategic enablers, and modules. The core obligations introduced by this amendment expand and extend the scope of common costs financed through the European Peace Facility. Key changes include: a revised definition of 'exercise' as a Union military CSDP exercise or the military component of a civilian CSDP exercise, agreed in the EU Programme of Exercises and Exercise-Related Activities under the CFSP; updated rules for financing exercise common costs following procedures similar to those for operations; expanded common cost categories under Annex IV covering medical services, force protection, transport for deployment and redeployment of the EU RDC, running costs, deployment readiness packages, barracks and infrastructure, and transportation within the theatre of operations for non-executive military missions. The Committee retains case-by-case authority to approve incremental costs beyond those listed in the Annexes for both operations and exercises.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32024d2911",
    "title": "Council Decision (EU) 2024/2911 of 5 November 2024 on the position to be taken on behalf of the European Union within the Council of Members of the International Olive Council (IOC) as regards one method of analysis and the IOC trade standard for olive oils and olive pomace oils",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-11-05",
    "bluf": "Council Decision (EU) 2024/2911, adopted on 5 November 2024 and published in the Official Journal of the European Union (L series), establishes the position to be taken on behalf of the European Union within the Council of Members of the International Olive Council (IOC) at its 120th session, to be held in November 2024. The Decision authorises the EU to support two specific amendments: the revision of the IOC trade standard for olive oils and olive pomace oils (COI/T.15/NC No. 3), and the revision of the method for determining the content of waxes and ethyl esters of fatty acids by capillary column gas chromatography (COI/T.20/Doc. No. 28/Rev. 3). The Decision applies to EU representatives participating in the IOC Council of Members and is grounded in Article 207(4) and Article 218(9) of the Treaty on the Functioning of the European Union. The core obligation is that EU representatives shall support the adoption of the specified IOC decisions, which will contribute to international harmonisation of standards for olive oils and establish a framework ensuring fair competition in the trading of products of the olive oil sector. The decisions are capable of decisively influencing the content of Union law, namely the marketing standards for olive oil adopted pursuant to Article 75 of Regulation (EU) No 1308/2013. If adoption is postponed, the same position applies within any exchange-of-correspondence procedure initiated before the next regular session in June 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32024d2998",
    "title": "Council Decision (EU) 2024/2998 of 5 November 2024 on the position to be taken on behalf of the European Union within the Joint Committee established by the Convention on a common transit procedure as regards the adoption of a decision amending Appendices III and IIIa to that Convention concerning the accession of Georgia",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-11-05",
    "bluf": "Council Decision (EU) 2024/2998, adopted at Brussels on 5 November 2024, establishes the position to be taken on behalf of the European Union within the Joint Committee established by the Convention on a common transit procedure (the 'EU-CTC Joint Committee') concerning amendments to Appendices III and IIIa to that Convention. The decision is grounded in Article 207(4) in conjunction with Article 218(9) of the Treaty on the Functioning of the European Union, and responds to Georgia's expressed wish to accede to the Convention, having been invited to do so by the EU-CTC Joint Committee. The accession of Georgia requires the adaptation of guarantee documents provided for by Title II of the Convention, as well as the insertion of certain technical terms in the Georgian language. All Member States of the Union expressed their positive opinion as regards the proposed amendments in the EU-Common Transit Countries Working Group. The Union is to be represented by the Commission within the EU-CTC Joint Committee in accordance with Article 17(1) of the Treaty on European Union. The position of the Union is based on the attached draft decision, and minor changes to that draft may be agreed to by Union representatives without further Council decision. After adoption, the EU-CTC Joint Committee decision shall be published in the Official Journal of the European Union. This Decision entered into force on the date of its adoption, 5 November 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32024d3030",
    "title": "Council Decision (Euratom) 2024/3030 of 2 December 2024 approving the position to be taken on behalf of Euratom in the Energy Charter Conference",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-12-09",
    "bluf": "Council Decision (Euratom) 2024/3030, adopted on 2 December 2024 and published in the Official Journal of the European Union on 9 December 2024, approves the position to be taken on behalf of Euratom in the Energy Charter Conference regarding the designation of a new depositary for the Energy Charter Treaty (ECT) and its Protocol on Energy Efficiency and Related Environmental Aspects (PEEREA). The decision arises from the withdrawal of the Portuguese Republic from the ECT and PEEREA, effective 2 February 2025, which necessitates the designation of a new depositary to replace the Government of the Portuguese Republic. The Decision applies to Euratom and to the Member States that are Contracting Parties to the ECT. In accordance with Article 36(7) of the ECT, Euratom shall not exercise its right to vote at the Energy Charter Conference. Instead, Member States that are Contracting Parties, acting jointly, shall exercise their vote at the Energy Charter Conference on 3 December 2024 so as not to prevent the adoption of proposed amendments to Article 49 ECT and Article 21 PEEREA, designating the Energy Charter Secretariat as the new depositary. The Secretariat is required to take all necessary measures to ensure the transition of depositary functions from the Government of the Portuguese Republic and assume these functions on an interim basis as of 2 February 2025, pending the entry into force of the formal amendments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32024l3019",
    "title": "Directive (EU) 2024/3019 of the European Parliament and of the Council of 27 November 2024 concerning urban wastewater treatment (recast) (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-12-12",
    "bluf": "Directive (EU) 2024/3019, published in the Official Journal of the European Union on 12 December 2024, recasts Council Directive 91/271/EEC and establishes a comprehensive legal framework for the collection, treatment, and discharge of urban wastewater across the European Union. The Directive applies to all agglomerations of 1,000 population equivalent (p.e.) and above, requiring that urban wastewater from such agglomerations be collected in collecting systems and subjected to secondary, tertiary, and where applicable, quaternary treatment before discharge into the environment. It introduces obligations for integrated urban wastewater management plans for agglomerations of 100,000 p.e. and above, and for agglomerations of between 10,000 p.e. and 100,000 p.e. where storm water overflows or urban runoff pose a risk for the environment or public health. The Directive further mandates quaternary treatment for all urban wastewater treatment plants of 150,000 p.e. and above to remove micropollutants, introduces an extended producer responsibility system requiring pharmaceutical and cosmetic producers to finance the costs of quaternary treatment, and sets an energy neutrality objective requiring that total annual energy used by all urban wastewater treatment plants treating a load of 10,000 p.e. and above does not exceed renewable energy production by those plants. Member States are required to ensure access to sanitation for all, monitor health parameters including SARS-CoV-2 and antimicrobial resistance in urban wastewater, and establish national implementation programmes with long-term investment financing strategies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32024l3101",
    "title": "Directive (EU) 2024/3101 of the European Parliament and of the Council of 27 November 2024 amending Directive 2005/35/EC as regards ship-source pollution and on the introduction of administrative penalties for infringements (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-11-27",
    "bluf": "The Directive (EU) 2024/3101 amends Directive 2005/35/EC to strengthen the enforcement of international standards on pollution from ships and introduce administrative penalties for infringements. It applies to companies and legal or natural persons liable for illegal discharges of polluting substances. The core obligation is to ensure that such entities are subject to effective, proportionate, and dissuasive administrative penalties to improve maritime safety and protect the marine environment. The Directive also extends the scope of Directive 2005/35/EC to cover additional Annexes of the International Convention for the Prevention of Pollution from Ships (Marpol 73/78) and introduces measures for the detection, verification, and enforcement of penalties for ship-source pollution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32024r1081",
    "title": "Commission Regulation (EU) 2024/1081 of 8 May 2024 correcting certain language versions of Annex II to Regulation (EC) No 1333/2008 of the European Parliament and of the Council on food additives",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-05-13",
    "bluf": "Commission Regulation (EU) 2024/1081, adopted on 8 May 2024 and published in the Official Journal of the European Union on 13 May 2024, is a correcting act targeting specific language versions of Annex II to Regulation (EC) No 1333/2008 on food additives. The regulation addresses errors found in the Danish, Slovak, and Slovenian language versions of that Annex, specifically concerning the dates of application of the measures and, in the case of the Slovak and Slovenian versions, errors in the identification of meat products. These errors were introduced by Commission Regulation (EU) 2023/2108 of 6 October 2023 and are stated to alter the meaning of the provisions. The correcting regulation is binding in its entirety and directly applicable in all Member States, entering into force on the twentieth day following its publication in the Official Journal of the European Union. The Commission adopted this correcting act based on powers awarded by the European Parliament and the Council under Article 10(3) of Regulation (EC) No 1333/2008, and in accordance with the opinion of the Standing Committee on Plants, Animals, Food and Feed. The other language versions of Annex II are explicitly stated to be unaffected by this correction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32024r1258",
    "title": "Regulation (EU) 2024/1258 of the European Parliament and of the Council of 24 April 2024 amending Regulation (EC) No 561/2006 as regards minimum requirements on minimum breaks and daily and weekly rest periods in the occasional passenger transport sector and as regards Member States’ power to impose penalties for infringements of Regulation (EU) No 165/2014 committed in another Member State or in a third country",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-05-14",
    "bluf": "Regulation (EU) 2024/1258 amends Regulation (EC) No 561/2006 to introduce specific rules for minimum breaks and rest periods for drivers engaged in occasional road passenger transport services. The regulation aims to adapt these requirements to better fit the unique characteristics of occasional passenger transport, such as high seasonality and varying driving distances. It allows drivers to split their mandatory break into two breaks of at least 15 minutes each, provided the total break duration remains at least 45 minutes. Drivers may also postpone their daily rest period by up to one hour under specific conditions. The regulation ensures that these flexible rules do not compromise road safety or driver working conditions. It also mandates that drivers carry a journey form on board the vehicle, which includes key information about the journey.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32024r1401",
    "title": "Commission Delegated Regulation (EU) 2024/1401 of 7 March 2024 amending Delegated Regulation (EU) 2022/2104 supplementing Regulation (EU) No 1308/2013 of the European Parliament and of the Council as regards marketing standards for olive oil",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "Commission Delegated Regulation (EU) 2024/1401 amends Delegated Regulation (EU) 2022/2104, which supplements Regulation (EU) No 1308/2013 regarding marketing standards for olive oil. The regulation updates the limit values for the characteristics of olive oil to align with the International Olive Council (IOC) Trade Standard, particularly focusing on the parameter Δ-7-stigmastenol. The regulation applies to all categories of olive oil and olive-pomace oil within the European Union. The core obligation is to ensure that olive oil products meet the updated purity and quality characteristics specified in the amended Annexes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32024r1922",
    "title": "Commission Implementing Regulation (EU) 2024/1922 of 12 July 2024 setting out the template for the collection by the Member States of the data and the information referred to in Article 6(5), points (a) to (d), of Regulation (EU) 2023/1230 of the European Parliament and of the Council",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-07-15",
    "bluf": "Commission Implementing Regulation (EU) 2024/1922, adopted on 12 July 2024 and published in the Official Journal of the European Union on 15 July 2024, establishes a standardised template to be used by Member States for the collection of data and information referred to in Article 6(5), points (a) to (d), of Regulation (EU) 2023/1230 on machinery. The Regulation enters into force on the twentieth day following its publication in the Official Journal of the European Union and is binding in its entirety and directly applicable in all Member States. The standardised template ensures uniform conditions for the collection of data and information for the purpose of adding a category of machinery or related products to Annex I of Regulation (EU) 2023/1230, or withdrawing a category of machinery or related products from that Annex. In order to rationalise the reporting requirements, the standardised template limits the data and information to be provided to what is strictly necessary, in particular by requiring only specific data and information in relation to specific machinery or related products and for the specific purposes of Article 6(10), first subparagraph, of Regulation (EU) 2023/1230, given that such specific information and data for those specific purposes are not required by any other Union legislation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32025d0429",
    "title": "Commission Decision (EU) 2025/429 of 30 April 2024 on the measure State aid SA.58207 (2021/N) which Czechia is planning to implement to support the construction and operation of a new nuclear power plant at the Dukovany site (notified under document C(2024) 2858)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2025-03-12",
    "bluf": "The European Commission has approved a state aid measure by Czechia to support the construction and operation of a new nuclear power plant (NPP) at the Dukovany site. The aid consists of a Purchase Contract (PC) for electricity offtake, a repayable financial assistance (RFA) loan, and a Change of Law or Policy Protection mechanism. The PC guarantees revenue stability for the beneficiary, EDU II, a subsidiary of ČEZ, over 40 years of operation, with a Strike Price mechanism to ensure a target return on equity. The measure aims to address Czechia's energy security, decarbonization goals, and replace aging coal and lignite plants. The Commission's decision follows an in-depth investigation and modifications by Czechia to address competition concerns.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32025d05171",
    "title": "Council Decision of 16 September 2025 replacing a full member of the Advisory Committee on Safety and Health at Work for the Netherlands",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2025-09-16",
    "bluf": "This Council Decision of 16 September 2025 (C/2025/5171), adopted by the Council of the European Union, replaces a full member of the Advisory Committee on Safety and Health at Work for the Netherlands. The decision is made having regard to the Treaty on the Functioning of the European Union and to the Council Decision of 22 July 2003 setting up the Advisory Committee on Safety and Health at Work, in particular Article 3 thereof. The replacement arises because a seat as full member in the representatives of employers' organisations category fell vacant as a result of the resignation of Ms Naomi COLVOORT. The Netherlands submitted a candidate for the vacant seat. Accordingly, Mr Pascal BOUGIE is appointed full member of the Advisory Committee on Safety and Health at Work in place of Ms Naomi COLVOORT for the remainder of the current term of office, ending on 5 March 2028. The Decision entered into force on the date of its adoption, 16 September 2025, and was done at Brussels under the presidency of M. BJERRE.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32025d1228",
    "title": "Decision (EU) 2025/1228 of the European Parliament and of the Council of 17 June 2025 amending Council Decision 2003/17/EC as regards the equivalence of field inspections carried out in the Republic of Moldova on seed-producing fodder plant crops and on the equivalence of fodder plant seed produced in the Republic of Moldova, and as regards the equivalence of field inspections carried out in Ukraine on seed-producing beet crops and seed-producing oil plant crops and on the equivalence of beet seed and oil plant seed produced in Ukraine (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2025-06-20",
    "bluf": "This Decision amends Council Decision 2003/17/EC to grant equivalence to field inspections and seed certification systems in the Republic of Moldova and Ukraine. Specifically, it recognizes the equivalence of field inspections for seed-producing fodder plant crops in Moldova and beet, sunflower, swede rape, and soya bean crops in Ukraine. The Decision also acknowledges the equivalence of seed produced and certified in these countries, provided they meet Union law requirements. The Decision is addressed to EU Member States and enters into force 20 days after its publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32025d1483",
    "title": "Commission Implementing Decision (EU) 2025/1483 of 31 July 2025 amending Implementing Decision (EU) 2025/1160 concerning certain emergency measures relating to sheep pox and goat pox in Bulgaria (notified under document C(2025) 5466)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2025-07-31",
    "bluf": "The European Commission has amended Implementing Decision (EU) 2025/1160 to address the spread of sheep pox and goat pox in Bulgaria. This decision mandates the establishment of restricted zones, including protection, surveillance, and further restricted zones, to prevent the disease from spreading within Bulgaria and to other Member States or third countries. Bulgaria is required to prohibit the movement of sheep and goats from these zones to areas outside their external perimeters until specified dates. The measures are based on the epidemiological situation and international standards, aiming to control the disease and prevent unjustified trade barriers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32025d1555",
    "title": "Council Decision (CFSP) 2025/1555 of 25 July 2025 amending Decision (CFSP) 2021/1277 concerning restrictive measures in view of the situation in Lebanon",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2025-07-28",
    "bluf": "Council Decision (CFSP) 2025/1555, adopted at Brussels on 25 July 2025, amends Decision (CFSP) 2021/1277 concerning restrictive measures in view of the situation in Lebanon. The original Decision (CFSP) 2021/1277 was adopted on 30 July 2021 and was set to apply until 31 July 2025. On the basis of a review of that Decision, the restrictive measures set out therein are renewed until 31 July 2026. The operative amendment is narrow and precise: in Article 9, first paragraph, of Decision (CFSP) 2021/1277, the date '31 July 2025' is replaced by that of '31 July 2026'. This Decision entered into force on the day following its publication in the Official Journal of the European Union, which occurred on 28 July 2025. The Decision was adopted by the Council of the European Union having regard to the Treaty on European Union, and in particular Article 29 thereof, and having regard to the proposal from the High Representative of the Union for Foreign Affairs and Security Policy. All entities and individuals subject to the restrictive measures established under Decision (CFSP) 2021/1277 remain bound by those measures for the extended period through 31 July 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32025d1886",
    "title": "Commission Implementing Decision (EU) 2025/1886 of 17 September 2025 on the clearance of the accounts of paying agencies in Italy and Slovakia concerning expenditure financed by the European Agricultural Guarantee Fund (EAGF) for financial year 2020 (notified under document C(2025) 6267)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2025-09-19",
    "bluf": "Commission Implementing Decision (EU) 2025/1886, adopted at Brussels on 17 September 2025 and published in the Official Journal of the European Union on 19 September 2025, clears the accounts of two specific paying agencies - the Italian paying agency 'Agenzia della Regione Calabria per le Erogazioni in Agricoltura' and the Slovak paying agency 'Pôdohospodárska platobná agentúra' - as regards expenditure financed by the European Agricultural Guarantee Fund (EAGF) for financial year 2020. These agencies had been excluded from the earlier general clearance decision, Commission Implementing Decision (EU) 2021/870 of 28 May 2021, pending transmission of new information and additional checks by the Commission. The Decision establishes the amounts recoverable from or payable to Italy and Slovakia, including amounts resulting from the application of Article 54(2) of Regulation (EU) No 1306/2013, which provides that 50% of the financial consequences of non-recovery of irregularities is to be borne by the Member State concerned if recovery has not taken place within four years from the date of the recovery request, or within eight years where recovery is taken in the national courts. The Decision is addressed to the Italian Republic and to the Slovak Republic, and is explicitly without prejudice to future conformity clearance decisions the Commission may take pursuant to Article 52 of Regulation (EU) No 1306/2013 to exclude from Union financing expenditure not effected in conformity with Union rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32025d2465",
    "title": "Council Decision (EU) 2025/2465 of 24 November 2025 on the signing, on behalf of the Union, of the Agreement on Digital Trade between the European Union and the Republic of Korea",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2025-12-03",
    "bluf": "Council Decision (EU) 2025/2465, adopted on 24 November 2025 and published in the Official Journal of the European Union on 3 December 2025, authorises the signing of the Agreement on Digital Trade between the European Union and the Republic of Korea on behalf of the Union. The Council acted having regard to the Treaty on the Functioning of the European Union, and in particular Article 207(4), first subparagraph, in conjunction with Article 218(5) thereof, and having regard to the proposal from the European Commission. Negotiations were authorised by the Council on 27 June 2023, and were successfully concluded by the Commission on behalf of the Union on 10 March 2025. The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 and delivered an opinion on 3 November 2025. The Decision entered into force on the date of its adoption, 24 November 2025. The text of the Agreement itself will be published together with the decision on its conclusion. The core obligation established by this Decision is the formal authorisation of the signing of the Agreement on Digital Trade between the European Union and the Republic of Korea, subject to the conclusion of the said Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32025r0300",
    "title": "Commission Delegated Regulation (EU) 2025/300 of 10 October 2024 supplementing Regulation (EU) 2023/1114 of the European Parliament and of the Council with regard to regulatory technical standards on information to be exchanged between competent authorities",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2025-03-31",
    "bluf": "This regulation establishes the technical standards for the exchange of information between competent authorities in the European Union regarding crypto-assets. It applies to competent authorities responsible for supervising entities involved in the issuance, offering, and trading of crypto-assets, including asset-referenced tokens, e-money tokens, and crypto-asset service providers. The regulation specifies the types of information that must be exchanged to ensure effective investigation, supervision, and enforcement activities under Regulation (EU) 2023/1114. This includes general information, documents, penalties, enforcement actions, and compliance history related to crypto-assets and their issuers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32025r0623",
    "title": "Commission Implementing Regulation (EU) 2025/623 of 28 March 2025 establishing, pursuant to Regulation (EU) 2024/573 of the European Parliament and of the Council minimum requirements for certificates of natural persons and the conditions for the mutual recognition of such certificates as regards the recovery of fluorinated greenhouse gas-based solvents from equipment and repealing Commission Regulation (EC) No 306/2008",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2025-03-31",
    "bluf": "This Regulation establishes minimum requirements for certificates of natural persons recovering fluorinated greenhouse gas-based solvents from equipment and specifies the conditions for mutual recognition of such certificates. It applies to natural persons involved in these activities. The Regulation requires certification for natural persons, with exemptions for those enrolled in training courses under supervision. Certification bodies must issue certificates based on theoretical and practical examinations, and Member States must ensure mutual recognition of certificates issued by other Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32025r2190",
    "title": "Commission Delegated Regulation (EU) 2025/2190 of 22 September 2025 amending Annex I to Regulation (EU) 2021/1060 of the European Parliament and of the Council as regards the nomenclature for the dimensions and codes for the types of intervention for the ERDF, the ESF+, the Cohesion Fund and the JTF",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2025-09-22",
    "bluf": "This regulation amends Annex I to Regulation (EU) 2021/1060 to include new types of intervention for the European Regional Development Fund (ERDF), the European Social Fund Plus (ESF+), the Cohesion Fund, and the Just Transition Fund (JTF). It introduces specific objectives aimed at boosting the EU's competitiveness, strategic autonomy, territorial and social cohesion, resilience, and preparedness. The regulation mandates Member States to provide consistent information on the programmed use of these Funds, enabling the Commission to monitor and report on their utilization effectively.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-celex-32025r2509",
    "title": "Regulation (EU) 2025/2509 - Safety of Toys (repealing Directive 2009/48/EC)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Regulation (EU) 2025/2509 is the new EU Toy Safety Regulation. It entered into force and starts to apply on 1 January 2026, progressively replacing Directive 2009/48/EC, which is fully repealed from 1 August 2030. Toys placed on the EU market must meet the essential safety requirements - the general safety requirement and the particular safety requirements set out in Annex II covering physical and mechanical, flammability, chemical, electrical, hygiene and radioactivity hazards. Before placing a toy on the market, manufacturers must carry out a safety assessment of the hazards the toy may present, draw up the technical documentation, carry out the applicable conformity assessment procedure, affix the CE marking, and create a digital product passport with its data carrier. Importers must verify, before placing a toy on the market, that the manufacturer has done these things; distributors must verify that the CE marking, digital product passport and required documentation are present before making a toy available.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_primary_law",
        "related_instruments",
        "conformity_framework",
        "application"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-general-product-safety-regulation-2023-988-gpsr-consumer-products",
      "eu-general-product-safety-regulation-2023-988-market-surveillance"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32025r2537",
    "title": "Commission Implementing Regulation (EU) 2025/2537 of 16 December 2025 designating a European Union reference laboratory for public health on respiratory viruses",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2025-12-17",
    "bluf": "Commission Implementing Regulation (EU) 2025/2537, adopted on 16 December 2025 and published in the Official Journal of the European Union on 17 December 2025, designates a consortium of laboratories as the European Union reference laboratory for public health on respiratory viruses (EURL) until 18 December 2032. The designation is made pursuant to Article 15(1) of Regulation (EU) 2022/2371 of the European Parliament and of the Council on serious cross-border threats to health. The EURL, led by Erasmus Medical Center in Rotterdam and composed of seven additional institutions across the Netherlands, France, Germany, Greece, Denmark, and Portugal, is mandated to provide support to national reference laboratories and promote good practice and quality to strengthen public health microbiology in the field of respiratory viruses. Priority respiratory viruses covered include influenza virus (seasonal, emerging/pandemic and human infections of zoonotic influenza), SARS-CoV-2, and respiratory syncytial virus (RSV). The EURL must ensure sufficient qualified staff, adequate training, confidentiality and cybersecurity policies, and capacity for enhanced laboratory support in case of escalation of a serious cross-border threat or recognition of a public health emergency at Union level. The Regulation is binding in its entirety and directly applicable in all Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-celex-32025r2599",
    "title": "Commission Implementing Regulation (EU) 2025/2599 of 11 December 2025 opening a tariff quota for the year 2026 for the import into the Union of certain goods originating in Norway resulting from the processing of agricultural products covered by Regulation (EU) No 510/2014 of the European Parliament and of the Council",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2025-12-17",
    "bluf": "Commission Implementing Regulation (EU) 2025/2599, adopted on 11 December 2025 and published in the Official Journal of the European Union on 17 December 2025, opens a duty-free tariff quota for the year 2026 for the import into the Union of certain goods originating in Norway resulting from the processing of agricultural products. The regulation applies from 1 January to 31 December 2026 and covers products classified under CN codes 2202 10 00, ex 2202 91 00, and ex 2202 99, including waters containing added sugar or flavouring, non-alcoholic beer containing sugar, soya-based beverages, and other non-alcoholic beverages containing sugar. The total quota volume is 23.029 million litres under Order No 09.0709. The legal basis for this regulation is Regulation (EU) No 510/2014 and Council Decision 2004/859/EC concerning the Agreement in the form of an Exchange of Letters between the European Community and the Kingdom of Norway on Protocol 2 to the bilateral Free Trade Agreement. Duty-free imports of the listed goods originating in Norway are permitted only within the quota limits, with a preferential duty of 0.047 EUR/litre applicable for quantities imported above the quota volume. The quota is to be managed by the Commission in accordance with Articles 49 to 54 of Implementing Regulation (EU) 2015/2447, on the basis of the chronological order of dates of acceptance of customs declarations for release for free circulation. Rules of origin laid down in Protocol 3 to the bilateral Free Trade Agreement between the European Economic Community and the Kingdom of Norway shall apply.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32026r0096",
    "title": "Commission Implementing Regulation (EU) 2026/96 of 15 January 2026 concerning the authorisation of celery seed essential oil from Apium graveolens L. and caraway essential oil from Carum carvi L. as feed additives for certain animal species",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-01-15",
    "bluf": "Commission Implementing Regulation (EU) 2026/96, adopted on 15 January 2026 and published in the Official Journal of the European Union (L series, 2026/96, 16.1.2026), authorises celery seed essential oil from Apium graveolens L. and caraway essential oil from Carum carvi L. as feed additives belonging to the additive category 'sensory additives' and the functional group 'flavouring compounds', subject to the conditions laid down in the Annex. The authorisation applies to a defined list of animal species and categories including turkeys for fattening, chickens for fattening and minor poultry for fattening, all poultry reared for laying or breeding, ornamental birds, pigs for fattening, piglets, Suidae for reproduction, calves for fattening, sheep and goats, cattle for fattening, other ruminants, Camelidae, Equidae, Leporidae, salmonids, minor finfish, and dogs. The use of these additives in water for drinking is not permitted, as Regulation (EC) No 1831/2003 does not allow the authorisation of 'flavouring compounds' for such use. Feed business operators are required to incorporate the additives into feed in the form of a premixture, indicate storage conditions and stability to heat treatment in directions for use, and establish operational procedures and organisational measures to address potential risks. Where risks cannot be eliminated, personal skin, eye and breathing protective equipment must be used. Maximum content thresholds are set per species in mg of additive per kg of complete feed with a moisture content of 12%. The additives are simultaneously withdrawn from the market for all animal species and categories not covered by the Annex. Transitional periods are provided for existing stocks, premixtures, and compound feed, with deadlines ranging from 5 February 2027 to 5 February 2028. The period of authorisation ends on 5 February 2036.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-celex-32026r0372",
    "title": "Commission Implementing Regulation (EU) 2026/372 of 20 February 2026 amending Implementing Regulation (EU) No 540/2011 as regards the extension of the approval periods of the active substances 1-decanol, 1-naphthylacetamide, 1-naphthylacetic acid, 6-benzyladenine, aluminium sulfate, boscalid, dodine, esfenvalerate, eugenol, fenpyroximate, fluazifop-P, fluazinam, fluometuron, fluopyram, flutolanil, geraniol, malathion, penoxsulam, pinoxaden, prohexadione, proquinazid, prosulfuron, pyrethrins, pyridaben, pyrimethanil, sintofen, spiroxamine, sulphur and thymol",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-02-20",
    "bluf": "Commission Implementing Regulation (EU) 2026/372, adopted on 20 February 2026 and published in the Official Journal of the European Union (L series, 23.2.2026), amends Implementing Regulation (EU) No 540/2011 to extend the approval periods of 29 active substances used in plant protection products. The Regulation is adopted pursuant to Regulation (EC) No 1107/2009 of the European Parliament and of the Council of 21 October 2009 concerning the placing of plant protection products on the market, and in particular Article 17, first paragraph, thereof. The Regulation applies to all EU Member States and is binding in its entirety and directly applicable in all Member States. The core obligation is the amendment of the Annex to Implementing Regulation (EU) No 540/2011 to replace the expiration dates in the sixth column (expiration of approval) for each of the 29 named active substances across Parts A, B, and E of that Annex. Extensions are granted because it is likely that no decision on the renewal of the approval can be taken before the expiry of the respective approval periods, between 15 April and 31 July 2026, and the Commission considers that the reasons for the delays in each of these renewal procedures are beyond the control of the respective applicants. Extension durations vary by substance: 12 months for flutolanil, penoxsulam, pyrimethanil and sulphur; 19 months and 15 days for fenpyroximate, fluazinam and proquinazid; 22 months and 15 days for pyrethrins; 23 months and 15 days for 1-decanol, boscalid, dodine, eugenol, fluopyram, geraniol, malathion, prohexadione and thymol; and 42 months for 1-naphthylacetamide, 1-naphthylacetic acid, 6-benzyladenine, aluminium sulfate, esfenvalerate, fluazifop-P, fluometuron, pinoxaden, prosulfuron, pyridaben, sintofen and spiroxamine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 12
  },
  {
    "node_id": "eu-celex-32026r0525",
    "title": "Commission Implementing Regulation (EU) 2026/525 of 11 March 2026 amending Implementing Regulation (EU) 2023/2834 as regards fixing representative prices in the poultrymeat and egg sectors and for egg albumin",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-03-12",
    "bluf": "Commission Implementing Regulation (EU) 2026/525, adopted on 11 March 2026 and published in the Official Journal of the European Union on 12 March 2026, amends Implementing Regulation (EU) 2023/2834 by inserting a new Article -43b into Chapter 4a, which establishes the methodology for fixing representative prices in the poultrymeat and egg sectors and for egg albumin. The Regulation is binding in its entirety and directly applicable in all Member States, entering into force on the twentieth day following its publication. The core obligation introduced is a structured, data-driven methodology for determining representative prices per product (by CN code line) and per origin, based on the average import price of the latest month with a minimum volume of 20 tonnes of imports, subject to specific consecutive-month sequencing conditions. The Commission retains the power to calculate and, where necessary, adjust these prices - but only where the adjusted prices differ by at least 5% from the determined prices. Publication of representative prices is modernised away from the Official Journal and instead directed through the Integrated Tariff of the European Union database (TARIC) and the dedicated page of the Commission website, with the stated aims of increasing transparency for economic operators and national authorities and reducing administrative burden on Union institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-celex-32026r0530",
    "title": "Commission Implementing Regulation (EU) 2026/530 of 10 March 2026 on exceptional support measures for the sheepmeat and pigmeat sectors in Hungary",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-03-11",
    "bluf": "This regulation provides Union part-financing equivalent to 60% of the expenditure borne by Hungary to support the sheepmeat and pigmeat markets affected by outbreaks of foot and mouth disease between 6 March 2025 and 17 April 2025. The support applies to sheep and pig holdings located in regulated zones and subject to animal health and veterinary measures. Expenditure is eligible only if paid by Hungary to beneficiaries by 31 August 2026 and if no compensation has been received from State aid, insurance, or Union financial contributions under Regulation (EU) 2021/690. The maximum Union part-financing is EUR 434,970, with specific flat rates and maximum numbers of animals eligible for compensation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-celex-32026r0705",
    "title": "Commission Implementing Regulation (EU) 2026/705 of 20 March 2026 establishing model identification documents and model declarations for non-commercial movements of pet animals",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-03-27",
    "bluf": "Commission Implementing Regulation (EU) 2026/705, adopted on 20 March 2026 and published in the Official Journal of the European Union on 27 March 2026, establishes model identification documents and model declarations for non-commercial movements of pet animals of the species listed in Annex I to Regulation (EU) 2016/429 into a Member State from another Member State or from a third country or territory. The Regulation applies from 22 April 2026, the same date on which the continued application of the repealed Regulation (EU) No 576/2013 ends and Delegated Regulation (EU) 2026/131 applies, and simultaneously repeals Implementing Regulations (EU) No 577/2013 and (EU) 2021/1938. The core obligation is that pet animals are not to be moved into a Member State from another Member State or from a third country or territory for non-commercial purposes unless they are accompanied by specific identification documents and declarations. This Regulation establishes: model passports for non-commercial movements of pet dogs, pet cats or pet ferrets between Member States (Annex I) and from certain third countries or territories (Annex II); model animal health certificates for non-commercial movements of pet dogs, pet cats or pet ferrets (Annex III) and pet birds (Annex IV) into the Union from third countries or territories; and model declarations accompanying those documents (Annex V). Transitional measures allow passports issued under the previous regime before 1 January 2028 to remain valid, and animal health certificates issued before 1 October 2026 to remain valid until 31 March 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 12
  },
  {
    "node_id": "eu-cer-directive-2022-2557-article-13-resilience-measures-critical-entities",
    "title": "Directive (EU) 2022/2557 on the resilience of critical entities - Article 13: Resilience measures of critical entities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Critical entities must implement appropriate and proportionate technical, security, and organisational measures to ensure their resilience, based on both Member State and internal risk assessments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cer-directive-2022-2557-article-9-critical-entity-designation",
    "title": "Directive (EU) 2022/2557 on the resilience of critical entities - Article 9: Competent authorities and single point of contact",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Member States are required to designate or establish one or more competent authorities to apply and enforce the rules of this Directive at a national level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cer-directive-2022-2557-critical-entity-resilience",
    "title": "Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-10-18",
    "bluf": "This directive requires EU Member States to identify critical entities across 11 sectors and mandates these entities to conduct all-hazard risk assessments and implement appropriate technical, security, and organisational measures to ensure their resilience. Critical entities must notify competent authorities of incidents that significantly disrupt their services, as detailed in Articles 13 and 14.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-chips-act-2023-1781",
    "title": "EU Chips Act 2023/1781 - Semiconductor Supply Chain Resilience & Crisis Response",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2023/1781 (European Chips Act) establishes a framework to strengthen Europe's semiconductor ecosystem, targeting 20% global chip production share by 2030 (from ~8% in 2022) through EUR 43 billion in public and private investment. Pillar I designates 'Integrated Production Facilities' (IPFs) and 'Open EU Foundries' as first-of-a-kind facilities eligible for accelerated permitting (9-month maximum for new facilities) and State aid under Article 107(3)(b/c) TFEU. Pillar II funds research and innovation through the Chips Joint Undertaking. Pillar III establishes a semiconductor supply chain monitoring and crisis response mechanism: Member States must map critical supply chains (Article 20), companies with EU critical infrastructure may be obligated to provide supply data (Article 23), and during a 'semiconductor crisis' the Commission may prioritise orders for defence/critical sectors. Integrated circuits, raw materials, and EDA/IP tools are all within scope.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-critical-raw-materials-act-2024-1252",
      "eu-net-zero-industry-act-2024-manufacturing-capacity",
      "eu-nis2-cloud-essential-services-2022-2555"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-chips-act-2023-1781-article-12-integrated-production-facilities",
    "title": "EU Chips Act (EU) 2023/1781 - Article 12: Integrated Production Facilities and Open EU Foundries - First-of-a-Kind Designation",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 12 of the EU Chips Act (Regulation 2023/1781) establishes the designation framework for Integrated Production Facilities (IPFs) and Open EU Foundries (OEFs) - the manufacturing pillar of the EU Chips Act. IPFs are semiconductor manufacturing facilities of strategic importance that are integrated across design, manufacturing, and advanced packaging and that bring new technology or production capacity to Europe for the first time. OEFs are open-access foundries providing manufacturing services to third-party customers (fabless companies) on a non-discriminatory basis. Both IPF and OEF designations unlock expedited permitting, priority access to public funding, and state aid beyond normal de minimis thresholds through Important Projects of Common European Interest (IPCEI) mechanisms. The designation requires: a first-of-a-kind technology or capacity claim, a genuine contribution to EU supply chain security, and financial viability. An IPF may be exclusively used by the operator; an OEF must provide open foundry services to EU fabless customers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-chips-act-2023-1781-article-5-union-facilities-semiconductor",
      "eu-chips-act-2023-1781-article-20-monitoring-supply-chain-semiconductor"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-chips-act-2023-1781-article-20-monitoring-supply-chain-semiconductor",
    "title": "EU Chips Act (EU) 2023/1781 - Article 20: Monitoring the Semiconductor Supply Chain and Crisis Stage Response Measures",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 20 of the EU Chips Act (Regulation 2023/1781) establishes the semiconductor supply chain monitoring and crisis response mechanism. The Commission, assisted by the European Semiconductor Board, continuously monitors indicators of supply chain disruption including: production capacity utilisation, inventory levels, delivery lead times, and demand trends. When a significant disruption risk is identified, the Commission may activate a 'crisis stage' by implementing act. In a crisis stage, the Commission may: (a) require IPFs and OEFs to report production and inventory data within 2 weeks; (b) issue 'priority rated orders' requiring IPFs and OEFs to accept specific customer orders at the expense of commercial queue position; (c) coordinate demand aggregation among member states; (d) activate strategic reserves. Priority rated orders are legally binding on IPFs and OEFs and override normal commercial queuing. The crisis stage mechanism reflects lessons from the 2020-2023 semiconductor shortage that disrupted automotive, electronics, and defence supply chains across Europe.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-chips-act-2023-1781-article-12-integrated-production-facilities",
      "eu-chips-act-2023-1781-article-5-union-facilities-semiconductor"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-chips-act-2023-1781-article-5-union-facilities-semiconductor",
    "title": "EU Chips Act (EU) 2023/1781 - Article 5: Union Facilities of Excellence for Semiconductor Research and Innovation",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 5 of the EU Chips Act (Regulation 2023/1781) establishes the framework for designating Union Facilities of Excellence (UFEs) in the Chips for Europe Initiative. UFEs are world-class research and technology organisations that provide semiconductor researchers and companies with access to advanced equipment, design tools, and pilot line capabilities not otherwise available in Europe. The designation is granted by the Commission to entities meeting criteria including: frontier semiconductor research capability, open access to equipment and expertise, legal establishment in an EU member state, and financial viability. UFEs receive public funding through Horizon Europe and the Digital Europe Programme. Access to UFE facilities by companies is provided on a non-discriminatory, transparent basis with published access conditions. The Chips for Europe Initiative, funded at EUR 3.3 billion from the EU budget (total EUR 11 billion including member state contributions), supports UFE operations and the pilot line network that Article 5 anchors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-chips-act-2023-1781-article-12-integrated-production-facilities",
      "eu-chips-act-2023-1781-article-20-monitoring-supply-chain-semiconductor"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-chips-act-2023-regulation-1781",
    "title": "Regulation (EU) 2023/1781 of the European Parliament and of the Council of 13 September 2023 establishing a framework of measures for strengthening Europe’s semiconductor ecosystem and amending Regulation (EU) 2021/694 (Chips Act)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The EU Chips Act establishes a framework to strengthen Europe’s semiconductor ecosystem through public-private investment, crisis response mechanisms, and support for Integrated Production Facilities (IPFs) and open EU foundries. It applies to semiconductor manufacturers, design centres, and critical infrastructure operators involved in chip supply chains, with key obligations under Article 18 for crisis monitoring and reporting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "enisa-cloud-security-guidelines-2023",
      "eu-cloud-certification-scheme-eucs-2024",
      "cisa-cpgs-cross-sector-performance-goals-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-chips-act-article-12-crisis-mechanism-semiconductor",
    "title": "Regulation (EU) 2023/1781 of the European Parliament and of the Council (EU Chips Act) - Article 12: Implementation",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article outlines the implementation framework for the Chips Initiative, assigning responsibilities to the Chips Joint Undertaking and the Commission for operational objectives, reporting, and adapting to technological changes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-chips-act-article-2-definitions",
    "title": "Regulation (EU) 2023/1781 on establishing a framework of measures for strengthening Europe’s semiconductor ecosystem (Chips Act) - Article 2",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes key definitions for terms such as 'first-of-a-kind facility', 'critical sector', and 'key market actors' which are essential for interpreting and applying the obligations throughout the EU Chips Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-chips-act-article-20-monitoring-global-semiconductor-supply",
    "title": "Regulation (EU) 2023/1781 (EU Chips Act) Article 20: Monitoring and anticipation",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "The Commission, in consultation with the European Semiconductor Board, must conduct regular monitoring of the semiconductor value chain to identify potential disruptions, compromises, or negative effects on supply and trade.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-chips-act-article-24-strategic-coordination",
    "title": "EU Chips Act (EU) 2023/1781 - Article 24 Emergency toolbox",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article grants the European Commission discretionary power to take measures from an 'Emergency toolbox' to address a semiconductor crisis in the Union, contingent upon the activation of a crisis stage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-chips-act-article-27-reporting-obligations",
    "title": "Regulation (EU) 2023/1781 of the European Parliament and of the Council (EU Chips Act) - Article 27: Common purchasing",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes a voluntary mechanism where the Commission, upon request from Member States during a crisis, may act as a central purchasing body for crisis-relevant semiconductor products, outlining the procedures for requests, agreements, and procurement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-chips-act-article-31-penalties",
    "title": "Regulation (EU) 2023/1781 (EU Chips Act) - Article 31: Designation of national competent authorities and single points of contact",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Member States must designate and resource one or more national competent authorities and a single point of contact to ensure the application and implementation of this Regulation, and notify the Commission of these designations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-chips-act-article-4-european-chips-infrastructure",
    "title": "Regulation (EU) 2023/1781 (EU Chips Act) Article 4: Objectives of the Initiative",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the general and operational objectives for the 'Chips for Europe' Initiative, focusing on building technological capacity, supporting research and innovation, and facilitating financing across the Union's semiconductor value chain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-chips-act-article-7-funding-research-innovation",
    "title": "Regulation (EU) 2023/1781 (EU Chips Act) Article 7: European chips infrastructure consortiums",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article outlines the requirements for establishing and operating a European Chips Infrastructure Consortium (ECIC) to implement actions funded under the Initiative, including its legal status, membership, and application process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-circular-economy-construction-demolition-waste-2020",
    "title": "EU Circular Economy Action Plan 2020 - Construction and Demolition Waste: Recycling Targets, Pre-Demolition Audits and Material Passports",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Circular Economy Action Plan 2020 requires construction and demolition waste to be recycled, with a minimum of 70% of non-hazardous waste to be recycled by 2025, as stated in Article 11 of the Waste Framework Directive. This applies to all EU member states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "un-paris-agreement-ndc-implementation-guidelines"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-clean-vehicles-directive-2019-1161",
    "title": "Directive (EU) 2019/1161 of the European Parliament and of the Council of 20 June 2019 amending Directive 2009/33/EC on the promotion of clean and energy-efficient road transport vehicles",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive mandates that public authorities, contracting entities, and certain public service operators across EU Member States meet minimum national targets for the procurement of clean and zero-emission light-duty vehicles, trucks, and buses. As detailed in Article 4 and the Annex, these targets are set for two reference periods (ending 2025 and 2030) to stimulate the market for sustainable transport solutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-clean-vehicles-directive-2019-1161-public-procurement",
    "title": "Directive (EU) 2019/1161 of the European Parliament and of the Council of 5 June 2019 on the promotion of clean mobility through the procurement of clean vehicles by public authorities",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Public contracting authorities in EU member states must ensure that a minimum percentage of newly procured buses, trucks, and light commercial vehicles are clean vehicles, as defined by low CO₂ emissions and zero-emission propulsion. The targets are set in Article 4 and apply from 2 August 2019 onward.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "iso-26262-functional-safety-road-vehicles-2018",
      "eu-digital-education-action-plan-2021-2027-deap"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-clinical-trials-eu-ctr-trials-regulation",
    "title": "Clinical Trials in Human Medicines | European Medicines Agency (EMA)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "All clinical trials included in marketing authorisation applications for human medicines in the EU/EEA must be conducted in accordance with Annex 1 of Directive 2001/83/EC. Trials in the EU/EEA must comply with EU clinical trial legislation, while those outside must adhere to ethical principles equivalent to those in the EEA, including international good clinical practice and the Declaration of Helsinki.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gmp-annex-1-sterile-manufacture-2022",
      "fda-21-cfr-part-312-ind-investigational-new-drug",
      "ich-q10-pharmaceutical-quality-system-2008"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-clinical-trials-regulation-2014-536",
    "title": "EU Clinical Trials Regulation 2014/536 - Clinical Trial Authorisation, CTIS, and Informed Consent",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Regulation (EU) No 536/2014 of the European Parliament and of the Council on clinical trials on medicinal products for human use replaced Directive 2001/20/EC and became applicable from 31 January 2022. The Regulation establishes a single EU-wide authorisation procedure for clinical trials conducted in one or more Member States via the Clinical Trials Information System (CTIS). Article 5 requires sponsors to submit a single clinical trial application (CTA) via CTIS covering all participating Member States. The assessment is divided into Part I (scientific and technical assessment coordinated by the reporting Member State) and Part II (ethical and national compliance assessment conducted by each Member State individually). Sponsors may not start a clinical trial until they receive combined authorisation under Article 8. Articles 28 to 35 govern informed consent requirements including specific protections for vulnerable populations (children, incapacitated adults, emergency situations). Article 41 requires reporting of all adverse events to the EMA EudraVigilance database. The CTIS portal (managed by the EMA) is the single entry point for CTA submissions, authorisation decisions, modifications, and safety reporting. The Regulation introduces transparency obligations including mandatory public disclosure of clinical trial results in the EU Clinical Trials Register within 12 months of the end of the trial.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_advanced_therapy_medicinal_products_regulation_1394_2007",
        "eu_gdpr_2016_679",
        "us_fda_21_cfr_part_312_ind_regulations",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-advanced-therapy-medicinal-products-regulation-1394-2007",
      "eu-gmo-deliberate-release-directive-2001-18",
      "eu-ecn-plus-directive-2019-nca-powers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-clinical-trials-regulation-2014-536-article-58-safety-reporting",
    "title": "Regulation (EU) No 536/2014 on clinical trials on medicinal products for human use - Article 58: Archiving of the clinical trial master file",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Sponsors and investigators must archive the content of the clinical trial master file for a minimum of 25 years after the trial's conclusion, while ensuring subjects' medical files are archived in compliance with national laws.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-clinical-trials-regulation-2014-536-ctr-investigational-medicinal-products",
    "title": "EU Clinical Trials Regulation 2014/536 - Authorisation and Conduct of Clinical Trials for Investigational Medicinal Products",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Regulation (EU) No 536/2014 (Clinical Trials Regulation, CTR) replaced Directive 2001/20/EC and establishes a harmonised procedure for clinical trial authorisation across the EU via the Clinical Trials Information System (CTIS). Sponsors must obtain Ethics Committee and Member State authority approval; apply consistent GCP standards; report serious adverse events; and register trials on the EU Clinical Trials Register.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-advanced-therapy-medicinal-products-regulation-1394-2007"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-clinical-trials-regulation-2022",
    "title": "Regulation (EU) No 536/2014 on clinical trials on medicinal products for human use (CTR), focusing on AI-Assisted Clinical Trials and Data Management",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This regulation harmonizes the processes for clinical trials in the EU, requiring that all electronic systems, including AI/ML models, used for generating, processing, or storing trial data be validated, secure, and maintain a complete audit trail to ensure data integrity and reliability (Article 52). It mandates the use of the centralized EU Portal and EU Database (CTIS) for all trial submissions and communications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-clinical-practice",
      "gdpr-health-data",
      "eu-mdr-2017-745",
      "iso-14971-medical-risk",
      "iec-62304-medical-software"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-clinical-trials-regulation-536-2014",
    "title": "Regulation (EU) No 536/2014 of the European Parliament and of the Council of 16 April 2014 on clinical trials on medicinal products for human use, and repealing Directive 2001/20/EC",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation harmonises the assessment and supervision processes for clinical trials throughout the European Union, mandating a single application via the EU Portal and Database for all interventional clinical trials on medicinal products for human use. It establishes a coordinated assessment procedure by Member States, as detailed in Chapter II, to streamline trial authorisations and enhance transparency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-clinical-practice",
      "gdpr-health-data",
      "eu-mdr-2017-745",
      "iso-13485-medical-qms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-clinical-trials-regulation-536-2014-ctr-investigational-medicinal-products",
    "title": "EU Clinical Trials Regulation 536/2014 (CTR) - Investigational Medicinal Products and Trial Authorisation",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2024-01-31",
    "bluf": "Regulation (EU) No 536/2014 establishes a harmonised EU-wide authorisation procedure for clinical trials on investigational medicinal products via the Clinical Trials Information System (CTIS). Sponsors must obtain a single authorisation from Member State authorities through CTIS within 30 days (45 days for trials involving certain populations). Ethics committee opinions are mandatory, and serious adverse event reporting must occur within 7-15 days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-good-manufacturing-practice-gdp-2013-c-343-4-medicinal-products",
      "eu-advanced-therapy-medicinal-products-regulation-1394-2007"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cloud-certification-scheme-eucs",
    "title": "ENISA European Cybersecurity Certification Scheme for Cloud Services (EUCS)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2024-04-16",
    "bluf": "The EUCS establishes a voluntary, EU-wide cybersecurity certification framework for Cloud Service Providers (CSPs), defining three assurance levels (Basic, Substantial, High) to verify security and enhance trust in cloud services across the single market, as mandated by the EU Cybersecurity Act (Regulation (EU) 2019/881). The scheme requires CSPs to implement a comprehensive set of security controls, undergo independent audits, and demonstrate compliance with requirements for data sovereignty and protection, particularly at the 'High' assurance level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27017-cloud-controls",
      "iso-27018-pii-cloud",
      "gdpr-health-data"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cloud-certification-scheme-eucs-2024",
    "title": "European Cybersecurity Certification Scheme for Cloud Services (EUCS)",
    "domain": "Cloud & SaaS",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This draft certification scheme establishes cybersecurity requirements for cloud service providers seeking European Union cybersecurity certification under ENISA’s EUCS framework, with three defined assurance levels (Basic, Substantial, High). It applies to cloud infrastructure and platform services and mandates EU-based processing for High-level certifications per Article 48.2 of the Cybersecurity Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cloud-rulebook-2021",
      "eu-gdpr-cloud-data-processing",
      "csa-ccm-v4-cloud-controls",
      "enisa-cloud-security-guidelines-2023",
      "eu-dora-ict-third-party-cloud"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cloud-rulebook-2021",
    "title": "ENISA European Cybersecurity Certification Scheme for Cloud Services (EUCS)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The European Cybersecurity Certification Scheme for Cloud Services (EUCS) establishes a voluntary, EU-wide certification framework for Cloud Service Providers (CSPs) to demonstrate cybersecurity assurance. It defines three distinct assurance levels-Basic, Substantial, and High-each with progressively stringent security requirements, as detailed in Section 5, to enhance trust and transparency for cloud customers across the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cloud-certification-scheme-eucs",
      "csa-ccm-v4-cloud-controls",
      "iso-27017-cloud-security-2015",
      "iso-27018-cloud-privacy-2019",
      "nist-sp-800-145-cloud-definition"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cloud-rulebook-2021-swipo-portability",
    "title": "EU Cloud Switching and Porting (SWIPO) Codes of Conduct 2021 - Customer Portability: Infrastructure-as-a-Service and Software-as-a-Service Codes, Data Export Formats, Functional Portability Requirements, Transition Assistance Obligations and Data Act 2023 Legal Reinforcement",
    "domain": "Cloud & SaaS",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes binding codes of conduct for cloud service providers to ensure customer data portability, functional interoperability, and transition assistance during switching between IaaS and SaaS providers. It applies to all EU-based and EU-serving cloud providers offering Infrastructure-as-a-Service or Software-as-a-Service, with enforceable obligations under Article 15 of the EU Data Act 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-data-act-2023",
      "eu-gdpr-cloud-data-processing",
      "csa-ccm-v4-cloud-controls",
      "enisa-cloud-security-guidelines-2023",
      "eu-cloud-certification-scheme-eucs"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-clp-regulation-1272-2008",
    "title": "Regulation (EC) No 1272/2008 - EU CLP Regulation: Classification, Labelling and Packaging of Substances and Mixtures - GHS Implementation, Hazard Pictograms, Harmonised Classification, C&L Inventory, Poison Centre Notification, and UFI Requirements",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EC) No 1272/2008 (CLP - Classification, Labelling and Packaging of Substances and Mixtures), applicable since 1 December 2010 for substances and 1 June 2015 for mixtures, implements the UN Globally Harmonised System (GHS) for hazard classification and labelling in the EU; key obligations include: self-classification of substances and mixtures using hazard criteria in Annex I (28 hazard classes covering physical, health, and environmental hazards); harmonised classification and labelling (CLH) for the most hazardous substances (Annex VI, Table 3 - approximately 4,500 harmonised entries) which manufacturers must apply mandatorily; minimum labelling elements - hazard pictograms (9 GHS pictograms), signal word ('Danger' or 'Warning'), hazard statements (H-statements), precautionary statements (P-statements), supplier identification, and UFI (Unique Formula Identifier) for mixtures; mandatory notification to the ECHA Classification and Labelling (C&L) Inventory for hazardous substances placed on the market; mandatory poison centre notification under Annex VIII (UFI on label and submission to ECHA PCN portal from 1 January 2021 for consumers, 1 January 2024 for professional use, 1 January 2025 for industrial use); and CLP Revision (Regulation (EU) 2023/707) amending hazard class criteria for endocrine disruptors, persistent/mobile substances, and nanomaterials.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_REACH",
        "US_OSHA_HCS",
        "EU_PPWR",
        "EU_BIOCIDES"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecodesign-sustainable-products-regulation-2024-1781",
      "eu-csrd-2022-2464",
      "eu-packaging-packaging-waste-regulation-2025-40"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-co2-cars-vans-regulation-2023-851",
    "title": "Regulation (EU) 2023/851 of the European Parliament and of the Council of 12 April 2023 on CO₂ emission performance standards for new passenger cars and for new light commercial vehicles, and repealing Regulations (EC) No 443/2009 and (EU) No 510/2011",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Requires 100% reduction in average CO₂ emissions from new passenger cars and light commercial vehicles by 31 December 2034, effectively mandating zero-emission vehicle sales from 2035, with interim targets of 55% reduction for cars and 50% for vans by 2030, as set out in Article 3(1) and Article 4(1). Applies to vehicle manufacturers placing new type-approved vehicles on the EU market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "germany-autonomous-driving-law-2021-stvaendg"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-co2-standards-cars-2023-851-zero-emission",
    "title": "Regulation (EU) 2023/851 of the European Parliament and of the Council of 19 April 2023 amending Regulation (EU) 2019/631 as regards the strengthening of the CO2 emission performance standards for new passenger cars and new light commercial vehicles in line with the Union’s increased climate ambition",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-04-19",
    "bluf": "This regulation mandates EU fleet-wide CO2 emission reduction targets for new passenger cars and vans, requiring a 55% reduction for cars and 50% for vans by 2030, and a 100% reduction for both from 2035 onwards, effectively phasing out new internal combustion engine vehicle sales. The targets are detailed in Article 1(4), which amends Annex I of Regulation (EU) 2019/631.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cohesion-fund-education-infrastructure-2021-2027",
    "title": "Regulation (EU) 2021/1060 of the European Parliament and of the Council of 24 June 2021 on the establishment of the Common Provisions Regulation and laying down common rules on the European Regional Development Fund, the European Social Fund Plus, the Cohesion Fund, the Just Transition Fund and the European Maritime, Fisheries and Aquaculture Fund and financial rules for those funds, with specific focus on education infrastructure investments under shared management 2021-2027",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes the legal framework for EU Cohesion Policy funding through the European Regional Development Fund (ERDF) and European Social Fund Plus (ESF+) to modernize education infrastructure, including digital schools, vocational education and training (VET) centers, universities, and lifelong learning facilities. It applies to all Member States receiving cohesion funds and requires compliance with Article 13 (eligibility of expenditure), Article 77 (investment in education, training and research), and Annex IX (priority axes for education infrastructure) for project approval and disbursement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-collective-redundancies-directive-98-59",
    "title": "Council Directive 98/59/EC of 20 July 1998 on the approximation of the laws of the Member States relating to collective redundancies",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive approximates Member State laws on collective redundancies (Article 1). Where an employer is contemplating collective redundancies, it must begin consultations with the workers representatives in good time with a view to reaching an agreement, covering ways of avoiding or reducing redundancies and mitigating the consequences (Article 2). The employer must notify the competent public authority in writing of any projected collective redundancies (Article 3), and projected collective redundancies notified to the authority take effect not earlier than 30 days after the notification, a period the authority uses to seek solutions (Article 4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-transfer-of-undertakings-directive-2001-23",
      "eu-works-council-directive-2009-38"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-combating-violence-against-women-directive-2024-1385",
    "title": "Directive (EU) 2024/1385 of the European Parliament and of the Council of 14 May 2024 on combating violence against women and domestic violence",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive lays down rules to prevent and combat violence against women and domestic violence (Article 1). It requires Member States to criminalise specified conduct including female genital mutilation (Article 3), forced marriage (Article 4), the non-consensual sharing of intimate or manipulated material (Article 5), cyber stalking, cyber harassment (Article 7) and cyber incitement to violence or hatred (Article 8), and sets rules on penalties, victim protection, support services, access to justice and prevention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-presumption-of-innocence-directive-2016-343",
      "eu-legal-aid-directive-2016-1919"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-commercial-agents-directive-1986",
    "title": "Council Directive 86/653/EEC of 18 December 1986 on the coordination of the laws of the Member States relating to self-employed commercial agents",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This directive harmonizes EU Member State laws for self-employed commercial agents, establishing their rights and obligations regarding remuneration, and mandating a system for either indemnity or compensation upon termination of the agency contract as outlined in Article 17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-vertical-block-exemption-regulation-2022-720"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-commission-gpai-training-content-summary-template-2025",
    "title": "EU Template for the Public Summary of Training Content for GPAI Models (AI Act Article 53(1)(d))",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "The European Commission adopted the Explanatory Notice and Template for the Public Summary of Training Content for general-purpose AI models required by Article 53(1)(d) of Regulation (EU) 2024/1689 (AI Act); the template was first presented by the AI Office on 24 July 2025 and the Communication C(2025) 8311 final of 5 December 2025 sets out the current Explanatory Notice and Template. Providers of general-purpose AI models must make the summary publicly available according to the template, which contains three sections: General information (including modalities and overall training data size), List of data sources (including a list of internet domain names for crawled and scraped online data and information on user data), and Relevant data processing aspects. The obligation applies as of 2 August 2025; for models placed on the market before 2 August 2025, providers should make the corresponding summary publicly available no later than 2 August 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-53-gpai-codes-of-practice",
      "eu-ai-office-gpai-code-of-practice-2025"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-commission-guidelines-ai-system-definition-2025",
    "title": "EU Commission Guidelines on the Definition of an AI System (AI Act Article 3(1), February 2025)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "On 6 February 2025 the European Commission published the Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act), developed under Article 96(1)(f), which requires the Commission to issue guidelines on the application of the AI system definition set out in Article 3(1). The Guidelines identify seven main elements of the definition: (1) a machine-based system; (2) designed to operate with varying levels of autonomy; (3) that may exhibit adaptiveness after deployment; (4) that, for explicit or implicit objectives; (5) infers, from the input it receives, how to generate outputs; (6) such as predictions, content, recommendations, or decisions; (7) that can influence physical or virtual environments. The definition adopts a lifecycle-based perspective with a pre-deployment building phase and a post-deployment use phase, the seven elements are not required to be present continuously in both phases, the definition must not be applied mechanically, and the Guidelines are not binding; authoritative interpretation of the AI Act may ultimately only be given by the Court of Justice of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-3-definitions",
      "eu-commission-guidelines-prohibited-ai-practices-2025"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-commission-guidelines-prohibited-ai-practices-2025",
    "title": "EU Commission Guidelines on Prohibited Artificial Intelligence Practices (February 4, 2025)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On February 4, 2025 the European Commission published Guidelines on Prohibited Artificial Intelligence Practices to support the application of the EU AI Act prohibited practices that became binding on February 2, 2025. The Guidelines interpret the eight categories of prohibited AI practices under the EU AI Act: (1) Subliminal techniques beyond a person's consciousness or purposefully manipulative or deceptive techniques causing significant harm; (2) Exploitation of vulnerabilities of natural persons due to age, disability, or specific social or economic situation causing significant harm; (3) Social scoring leading to detrimental or unfavourable treatment of natural persons in social contexts unrelated to the data generation context or unjustified to the context's severity; (4) Predictive policing based solely on profiling or personality traits; (5) Untargeted scraping of facial images from the internet or CCTV footage to create or expand facial recognition databases; (6) Emotion recognition systems in workplaces and educational institutions, except for medical or safety reasons; (7) Biometric categorisation systems inferring race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation; (8) Real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes, with narrow exceptions for specific serious offences. The Guidelines run 140+ pages and provide use case examples, interpretation criteria, the harm threshold definition, and the relationship with other EU instruments. National competent authorities and the EU AI Office use the Guidelines as the operative interpretation for enforcement under EU AI Act Articles 5 and 99.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlay",
        "us_comparative",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-prohibited-social-scoring",
      "eu-ai-act-prohibited-predictive-policing",
      "eu-ai-act-prohibited-biometric-categorisation",
      "eu-ai-act-prohibited-emotion-recognition",
      "eu-ai-act-prohibited-realtime-biometric-id"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-commission-implementing-regulation-2015-2452-solvency",
    "title": "Commission Implementing Regulation (EU) 2015/2452 of 2 December 2015 laying down implementing technical standards with regard to the procedures, formats and templates for the solvency and financial condition report in accordance with Directive 2009/138/EC of the European Parliament and of the Council",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation establishes the mandatory procedures, formats, and quantitative reporting templates (QRTs) that insurance and reinsurance undertakings must use for their annual and quarterly Solvency and Financial Condition Report (SFCR) and Regular Supervisory Report (RSR) as required under the Solvency II Directive (2009/138/EC). The core requirements are detailed in Annexes I, II, and III, which specify the exact structure and content for all supervisory reporting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-commission-recommendation-2024-1101-pqc-coordinated-roadmap",
    "title": "Commission Recommendation (EU) 2024/1101 on a Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-04-11",
    "bluf": "Commission Recommendation (EU) 2024/1101 of 11 April 2024, published in the Official Journal on 12 April 2024 under CELEX 32024H1101, asks Member States to move to Post-Quantum Cryptography in a synchronised way rather than nation by nation. Its operative part runs in four numbered sections: Scope and Objectives, Coordinated Implementation Roadmap Addressing the Transition to Post-Quantum Cryptography, Actions at Union Level, and Review, with points numbered (1) to (11).\n\nPoint (1) defines a Post-Quantum Cryptography Coordinated Implementation Roadmap aimed at synchronising the efforts of Member States. Point (4) encourages Member States to coordinate their actions at Union level through a dedicated Member States forum, and point (6) invites them to establish a sub-group on Post-Quantum Cryptography pursuant to a Commission Implementing Decision. Point (5) states that the sub-group should consider appropriate, effective and proportionate measures for defining and coordinating the work. Point (7) sets the timing of the deliverable: the Roadmap should be available after a period of two years following publication. Under the heading Actions at Union Level the Commission may request Member States representatives to submit relevant information so progress can be monitored, and point (11) asks Member States to cooperate with the Commission to assess the effects of the Recommendation a maximum of three years after publication. The Coordinated Implementation Roadmap contemplated by this instrument was published on 23 June 2025. Being a Recommendation, it is not binding in the way a Regulation is; it establishes the coordination mechanism and the expectation of national plans.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-203-ml-kem-standard",
      "fips-204-ml-dsa-standard",
      "nist-ir-8547-pqc-transition",
      "uk-ncsc-pqc-migration-timelines-2025"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-commission-regulation-773-2004-antitrust-procedures",
    "title": "EU Commission Regulation 773/2004 - Antitrust Enforcement Procedures",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Commission Regulation (EC) No 773/2004 sets out the procedural rules governing how the European Commission conducts antitrust enforcement proceedings under Articles 101 and 102 TFEU. It governs the rights of parties under investigation, access to the Commission file, oral hearings, the handling of confidential information, complaints, and the settlement procedure for cartel cases (added by Regulation (EC) 622/2008). The Regulation implements Regulation (EC) 1/2003 and is the operational rulebook for EU competition enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_1_2003",
        "cartel_settlement",
        "fining_guidelines_2006",
        "leniency_notice_2006",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-competition-regulation-1-2003",
      "eu-tfeu-article-101-cartels-prohibition",
      "eu-tfeu-article-102-abuse-dominance"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-common-agricultural-policy-2021-2115",
    "title": "EU Common Agricultural Policy Strategic Plans Regulation (EU) 2021/2115",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Regulation 2021/2115 (the CAP Strategic Plans Regulation) is part of the post-2022 reform of the Common Agricultural Policy applicable from 1 January 2023 to 31 December 2027. Each Member State produces a national CAP Strategic Plan combining direct payments rural development and sector-specific interventions under European Agricultural Guarantee Fund (EAGF) and European Agricultural Fund for Rural Development (EAFRD). The reform introduces enhanced conditionality (replacing cross-compliance and greening) with Good Agricultural and Environmental Conditions (GAEC), Statutory Management Requirements (SMR), and eco-schemes as new voluntary climate and environment payments under Pillar 1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-common-agricultural-policy-regulation-2021-2115",
    "title": "EU Common Agricultural Policy Regulation 2021/2115 - CAP Strategic Plans and Conditionality",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "EU Regulation 2021/2115 establishes the framework for CAP Strategic Plans 2023-2027, requiring Member States to define interventions meeting EU objectives through a new delivery model. AI-driven precision farming platforms, crop monitoring systems, and farm management software must comply with Good Agricultural and Environmental Condition (GAEC) standards (Annex III) to ensure farmers receiving CAP payments remain eligible. Data governance for farm-level AI is shaped by the Data Act 2023 and GDPR, with specific derogations under Article 67 for agricultural data sharing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standards",
        "frameworks",
        "regulations",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-water-framework-directive-2000-60-ec"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-common-rules-imports-certain-third-countries-2015-755",
    "title": "Regulation (EU) 2015/755 of the European Parliament and of the Council of 29 April 2015 on common rules for imports from certain third countries",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down common rules for imports from certain third countries that are not WTO members, based on freedom of import subject to surveillance and safeguard measures. Member States inform the Commission where import trends call for action (Article 2). The Commission may set quantitative limits or take protective action where imports cause or threaten serious injury to Union producers (Article 9), introduce import surveillance (Article 10), and adopt safeguard measures where the conditions are met (Article 15), in accordance with the relevant committee procedure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-common-rules-imports-safeguard-regulation-2015-478",
      "wto-agreement-on-safeguards-1994"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-common-rules-imports-safeguard-regulation-2015-478",
    "title": "Regulation (EU) 2015/478 of the European Parliament and of the Council of 11 March 2015 on common rules for imports",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation establishes common rules for imports into the EU based on the principle of freedom of import, together with surveillance and safeguard mechanisms. Member States inform the Commission where import trends call for surveillance or safeguard measures (Article 2). The Commission may introduce prior Union or regional import surveillance (Article 12) and, where increased imports cause or threaten serious injury to Union producers, may adopt safeguard measures such as quotas or duties in accordance with the examination procedure (Article 16).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wto-agreement-on-safeguards-1994",
      "eu-anti-dumping-regulation-2016-1036"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-company-law-digitalisation-directive-2019-1151",
    "title": "Directive (EU) 2019/1151 of the European Parliament and of the Council of 20 November 2019 on a framework for the cross-border conversion, merger and division of companies, and on the cross-border transfer of the registered office of companies with limited liability",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Directive establishes harmonised rules for cross-border conversions, mergers, divisions, and registered office transfers of limited liability companies within the EU, ensuring legal certainty and protection of shareholders and creditors. Key obligations are set out in Article 3 regarding notification, information, and objection rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-directive-workflow-critical-operations",
      "azure-logic-apps-enterprise-integration",
      "apache-airflow-workflow-dag-governance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-competition-article-102-tfeu-abuse-dominant-position-digital",
    "title": "EU Article 102 TFEU - Abuse of Dominant Position in Digital Markets",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Article 102 TFEU prohibits undertakings holding a dominant position in the EU from abusing that position to restrict competition. The European Commission has applied Art. 102 to digital platform markets including search, e-commerce, and advertising. Cases such as Google Shopping (EUR 2.42B fine, 2017) and Google Android (EUR 4.34B, 2018) have expanded the framework for digital abuse including self-preferencing and tying.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeeper-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-competition-regulation-1-2003",
    "title": "Council Regulation (EC) No 1/2003 on the Implementation of the Rules on Competition (Articles 101 and 102 TFEU): NCA Powers, Commission Investigation Authority, 10% Worldwide Turnover Fines, European Competition Network, and Burden of Proof for Exemption Claims",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Council Regulation (EC) No 1/2003 (OJ L 1, 4.1.2003, p. 1), effective 1 May 2004, is the cornerstone of EU competition enforcement, replacing Regulation 17/62; it decentralises enforcement of Articles 101 and 102 TFEU by empowering national competition authorities (NCAs) to apply EU competition law in full, establishes the European Competition Network (ECN) for case allocation and parallel proceedings coordination, grants the European Commission broad investigation powers including document inspections (Article 20) and premises searches (Article 21), imposes fines up to 10% of an undertaking's total worldwide annual turnover for substantive violations (Article 23(2)), creates a 5-year limitation period for infringement proceedings (Article 25), reverses the pre-notification system by making Articles 101(1) and 102 directly applicable with the burden of proof for Article 101(3) exemptions placed on the undertaking invoking the benefit, and prohibits NCAs and national courts from adopting decisions incompatible with Commission decisions (Article 16).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_MERGER_REGULATION",
        "EU_DMA",
        "ECN_PLUS_DIRECTIVE",
        "EU_SETTLEMENT_PROCEDURE"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-merger-regulation-139-2004",
      "eu-digital-markets-act-2022-1925"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-conditional-marketing-authorisation-507-2006",
    "title": "Commission Regulation (EC) No 507/2006 of 29 March 2006 on the conditional marketing authorisation for medicinal products for human use falling within the scope of Regulation (EC) No 726/2004 of the European Parliament and of the Council",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes a framework for granting conditional marketing authorisation (CMA) to medicinal products that address an unmet medical need, based on a positive risk-benefit balance with less than comprehensive clinical data, provided the applicant commits to completing specific post-authorisation obligations. As per Article 4, this authorisation is valid for one year and is subject to annual reassessment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-conflict-minerals-regulation-2017-821",
    "title": "Regulation (EU) 2017/821 of the European Parliament and of the Council of 23 May 2017 laying down supply chain due diligence obligations for Union importers of tin, tantalum and tungsten, their ores, and gold originating from conflict-affected and high-risk areas",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires EU-based importers of tin, tantalum, tungsten, and gold (3TG) to conduct mandatory due diligence on their supply chains to ensure minerals do not finance armed conflict or contribute to human rights abuses. Compliance is mandated under Article 4 through a due diligence system aligned with the OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp",
      "oecd-due-diligence-minerals-supply-chains-2016"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-construction-products-regulation-2011-305",
    "title": "EU Construction Products Regulation 2011/305",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2011-04-04",
    "bluf": "Regulation (EU) No 305/2011 establishes harmonised conditions for the marketing of construction products in the EU, requiring manufacturers to draw up a Declaration of Performance and affix CE marking when a harmonised product standard or European Technical Assessment exists, with third-party notified body involvement required for AVCP systems 1+, 1, 2+, and 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-machinery-directive-2006-42",
        "eu-general-product-safety-regulation-2023-988",
        "eu-corporate-sustainability-reporting-directive-2022-2464"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-machinery-directive-2006-42",
      "eu-general-product-safety-regulation-2023-988",
      "eu-corporate-sustainability-reporting-directive-2022-2464"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-construction-products-regulation-2011-305-ce-marking",
    "title": "EU Construction Products Regulation 305/2011/EU - CE Marking and Declaration of Performance Requirements",
    "domain": "Construction & Real Estate",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Construction Products Regulation (CPR) 305/2011/EU requires manufacturers to affix the CE marking to construction products covered by a harmonised European standard (hEN) or European Technical Assessment (ETA) before placing them on the EU market. CE marking is conditional on the manufacturer drawing up a Declaration of Performance (DoP) specifying the essential characteristics of the product assessed against the hEN or ETA. The system of assessment and verification of constancy of performance (AVCP) determines whether a notified body must be involved. The European Commission has proposed a revised CPR to strengthen sustainability and circular economy requirements. Non-compliance with CE marking requirements can result in market withdrawal, fines, and criminal sanctions under national law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-construction-products-regulation-305-2011",
      "eu-energy-performance-buildings-directive-2024-recast"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-construction-products-regulation-2011-305-ce-marking-performance",
    "title": "EU Construction Products Regulation 2011/305 - CE Marking, Declaration of Performance, and Essential Requirements",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2013-07-01",
    "bluf": "Regulation (EU) 305/2011 requires construction product manufacturers to produce a Declaration of Performance (DoP) and affix CE marking when a harmonised European standard (hEN) covers their product, demonstrating performance against essential characteristics relevant to construction works' basic requirements for structural safety, fire safety, hygiene, and energy performance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-market-surveillance-regulation-2019-1020-auto",
      "eu-type-approval-regulation-2018-858-whole-vehicle-technical-requirements"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-construction-products-regulation-2022",
    "title": "Proposal for a Regulation of the European Parliament and of the Council laying down harmonised conditions for the marketing of construction products, amending Regulation (EU) 2019/1020 and repealing Regulation (EU) No 305/2011",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation revises the 2011 CPR to establish harmonised rules for placing construction products on the EU market, introducing mandatory environmental, safety, and digital information requirements through a Declaration of Performance (DoP) and CE marking. It applies to all economic operators (manufacturers, importers, distributors) in the construction product supply chain, as detailed in Articles 4, 9, and 19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate-related-disclosures",
      "iso-14064-ghg-reporting-2018",
      "logistics-carbon-glec"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-construction-products-regulation-2024-3110",
    "title": "Regulation (EU) 2024/3110 of the European Parliament and of the Council of 27 November 2024 laying down harmonised rules for the marketing of construction products and repealing Regulation (EU) No 305/2011",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "Regulation (EU) 2024/3110 is the new EU Construction Products Regulation (CPR), adopted on 27 November 2024 and published in the Official Journal on 18 December 2024, repealing the predecessor Regulation (EU) No 305/2011. It lays down harmonised rules for the marketing of construction products placed on the EU internal market and applies to manufacturers, importers, distributors and online marketplaces. Article 11 requires manufacturers to draw up a combined declaration of performance and conformity in a uniform, machine-readable format before placing a construction product on the market. Article 17 restricts CE marking to construction products for which that declaration of performance and conformity has been drawn up. Article 22 empowers the Commission to establish a construction Digital Product Passport (DPP) system aligned to the extent possible with the Ecodesign for Sustainable Products Regulation (EU) 2024/1781. The Regulation introduces sustainability and environmental performance requirements (including life-cycle assessment), strengthens market surveillance powers, and addresses obligations of online marketplaces and used or remanufactured construction products. Certain products already regulated under sectoral Union harmonisation legislation (notably the Low Voltage Directive 2014/35/EU, the EMC Directive 2014/30/EU, the Radio Equipment Directive 2014/53/EU and the General Product Safety Directive 2001/95/EC) are excluded from scope where this would lead to duplication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "subject_matter_and_scope_anchor",
        "declaration_of_performance_and_conformity_anchor",
        "ce_marking_anchor",
        "digital_product_passport_anchor",
        "sustainability_and_environmental_performance_anchor",
        "market_surveillance_and_online_marketplaces_anchor",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecodesign-regulation-2024-sustainable-products",
      "eu-market-surveillance-regulation-2019-1020",
      "eu-digital-services-act-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-construction-products-regulation-305-2011",
    "title": "Regulation (EU) No 305/2011 of the European Parliament and of the Council of 9 March 2011 laying down harmonised conditions for the marketing of construction products",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes a common framework for the marketing of construction products in the EU, requiring manufacturers to affix CE marking and issue a Declaration of Performance (DoP) based on harmonised technical specifications. It applies to all construction product manufacturers, importers, and distributors placing products on the EU market under Article 4 and Article 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-19650-bim-information-management-construction",
      "asce-7-22-minimum-design-loads-buildings",
      "australia-national-construction-code-2022-ncc",
      "iso-9001-2015-quality-management-construction",
      "nfpa-13-installation-sprinkler-systems-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-construction-safety-temporary-mobile-sites",
    "title": "Council Directive 92/57/EEC of 24 June 1992 on the minimum safety and health requirements for the temporary or mobile construction sites",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This Directive requires all Member States to ensure that minimum safety and health requirements are implemented on temporary or mobile construction sites, including the appointment of a competent coordinator for safety and health during both design and execution phases. It applies to all contractors, subcontractors, and employers operating on such sites under Article 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-safety-health-construction-convention-167-1988",
      "iso-19650-bim-information-management-construction",
      "iso-21500-project-management-construction-guidance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-construction-sector-emissions-buildings-renovation",
    "title": "EU Buildings and Construction Sector Decarbonisation 2050 - Long-Term Renovation Strategies, Minimum Energy Performance Standards and Social Housing Finance",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires EU member states to establish long-term renovation strategies to reduce greenhouse gas emissions from buildings, as outlined in Article 2a of the Energy Efficiency Directive. It applies to all new and existing buildings, with a focus on social housing and public buildings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeepers"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-consumer-credit-directive-2023-2225",
    "title": "EU Consumer Credit Directive 2023/2225 - BNPL Coverage, AI Scoring Transparency, 14-Day Withdrawal",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive (EU) 2023/2225 of 18 October 2023 repeals and replaces Directive 2008/48/EC (Consumer Credit Directive). Key changes: scope extended to cover credit agreements from EUR 200 to EUR 100,000 (down from EUR 75,000 upper limit); Buy-Now-Pay-Later (BNPL) arrangements above EUR 200 with deferred payment beyond 50 days are brought in scope (Article 2(5) narrow BNPL exemption requires disclosure even for exempt products); Article 14 preserves a 14-day unconditional withdrawal right; Article 10 mandates pre-contractual disclosure via the Standard European Consumer Credit Information (SECCI) form; Article 18 requires creditworthiness assessment using verified income data and prohibits approval where affordability cannot be confirmed; AI-based scoring decisions must be explainable on request under Article 18(5) (data categories used must be disclosed). Member States must transpose by 20 November 2025 and apply from 20 November 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "AML_CDD",
        "PSD2_SCA",
        "GDPR_scoring_data",
        "AI_Act_automated_decisions",
        "MCD_mortgage_credit"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-regulation-2024",
      "eu-psd2-strong-customer-authentication"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-consumer-rights-directive-2011",
    "title": "Directive 2011/83/EU of the European Parliament and of the Council of 25 October 2011 on consumer rights, amending Council Directive 93/13/EEC and Directive 1999/44/EC of the European Parliament and of the Council and repealing Council Directive 85/577/EEC and Directive 97/7/EC of the European Parliament and of the Council (as amended by Directive (EU) 2019/2161)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This directive harmonizes consumer protection across the EU for distance and off-premises contracts, requiring traders to provide comprehensive pre-contractual information (Article 6) and granting consumers a standard 14-day right of withdrawal from such contracts (Article 9). It applies to businesses selling goods, services, and digital content to consumers within the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-consumer-rights-directive-2011-83-cx",
    "title": "Directive 2011/83/EU of the European Parliament and of the Council of 25 October 2011 on consumer rights, amending Council Directive 93/13/EEC and Directive 1999/44/EC",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The Directive requires traders to provide clear pre‑contractual information (Art. 6), grant a 14‑day withdrawal right for distance contracts (Art. 16), ensure delivery of goods within the agreed time and transfer risk at delivery (Art. 17‑18), prohibit additional charges unless expressly agreed (Art. 6), and set specific obligations for digital content supply (Art. 23). It applies to all business‑to‑consumer contracts within the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "eu-adr-consumer-disputes-2013",
      "eu-omnibus-directive-2019-2161",
      "eu-unfair-commercial-practices-directive",
      "eu-accessibility-act-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-consumer-rights-directive-2011-83-distance-sales",
    "title": "EU Consumer Rights Directive 2011/83/EU - Distance Sales Information Requirements, 14-Day Right of Withdrawal and Digital Content Rules",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "Directive 2011/83/EU of the European Parliament and of the Council of 25 October 2011 on consumer rights, amending Council Directive 93/13/EEC and Directive 1999/44/EC and repealing Council Directive 85/577/EEC and Directive 97/7/EC (Consumer Rights Directive, CRD) harmonises consumer protection for distance contracts, off-premises contracts, and on-premises contracts. Article 6 establishes mandatory pre-contractual information requirements for distance and off-premises contracts including main characteristics, trader identity, total price, payment and delivery arrangements, complaint handling, right of withdrawal, legal guarantees, after-sales services, contract duration. Article 9 establishes the 14-day right of withdrawal for distance and off-premises contracts running from delivery of goods or conclusion of service contract. Article 10 extends withdrawal period to 12 months if information not provided. Article 16 sets out exceptions to withdrawal (customised goods, sealed audiovisual recordings, perishable goods, etc.). The Directive was amended by the Modernisation Directive (EU) 2019/2161 (Omnibus Directive) effective 28 May 2022 introducing online marketplace transparency rules, ranking parameter disclosure, fake reviews protections, and consumer remedies for unfair commercial practices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-consumer-law-acl-2010-cx",
      "brazil-consumer-defense-code-lei-8078-1990"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-consumer-rights-directive-2011-83-eu",
    "title": "EU Consumer Rights Directive 2011/83/EU - Pre-contractual Information & Right of Withdrawal",
    "domain": "Operations & CX",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Directive 2011/83/EU grants consumers a 14-day right of withdrawal for distance and off-premises contracts, mandates pre-contractual information disclosure, and prohibits hidden charges - a core consumer protection measure applicable to all EU e-commerce and service operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-consumer-rights-directive-2011-83-online-returns",
    "title": "Directive 2011/83/EU of the European Parliament and of the Council of 25 October 2011 on consumer rights, amending Council Directive 93/13/EEC and Directive 1999/44/EC of the European Parliament and of the Council and repealing Council Directive 85/577/EEC and Directive 97/7/EC of the European Parliament and of the Council",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The EU Consumer Rights Directive 2011/83 grants consumers a 14-day unconditional right to withdraw from online and distance contracts without penalty, requiring businesses to provide clear pre-contractual information, refund all payments including delivery costs, and not charge restocking fees. Applies to all traders offering goods or services to consumers in the EU under Article 6 and Article 16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "eu-omnibus-directive-2019-2161",
      "eu-unfair-commercial-practices-directive",
      "iso-10002-2018-customer-satisfaction-complaints",
      "eu-adr-consumer-disputes-2013"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-consumer-sales-directive-2019-771",
    "title": "Directive (EU) 2019/771 of the European Parliament and of the Council of 20 May 2019 on the sale of goods, amending Regulations (EU) 2017/2394 and (EU) 2018/858, and repealing Directive 1999/44/EC",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This Directive establishes a harmonized 2-year legal guarantee for consumer goods, requiring sellers to ensure conformity at the time of delivery. Consumers have a hierarchy of remedies-repair or replacement first, then price reduction or refund-under Articles 7-11, applicable to all B2C sales of tangible and digital goods within the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29",
      "eu-ecommerce-directive-2000-31",
      "eu-geo-blocking-regulation-2018-302",
      "eprivacy-cookie-directive",
      "eu-price-indication-directive-1998"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-contaminants-regulation-2023-915-food-safety",
    "title": "Commission Regulation (EU) 2023/915 of 27 April 2023 amending Regulation (EC) No 1881/2006 as regards maximum levels of contaminants in foodstuffs",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes legally binding maximum levels for mycotoxins, heavy metals (lead, cadmium, mercury, inorganic arsenic), nitrates, polycyclic aromatic hydrocarbons (PAHs), per- and polyfluoroalkyl substances (PFAS), and acrylamide in various foodstuffs, including specific limits for processed foods and baby food. It applies to all food business operators placing such products on the EU market under Article 2 of Regulation (EC) No 1881/2006 as amended.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-law-178-2002",
      "eu-food-hygiene-regulation-852-2004",
      "brc-food-safety-standard-issue-9",
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-allergen-regulation-2021-382"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-control-of-acquisition-possession-of-weapons-directive-2021-555",
    "title": "Directive (EU) 2021/555 of the European Parliament and of the Council of 24 March 2021 on control of the acquisition and possession of weapons (codification)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This codifying Directive establishes harmonised minimum rules on the control of the acquisition and possession of firearms across Member States, while allowing more stringent national measures (Articles 1 and 3). It governs the conditions under which Member States allow the acquisition and possession of firearms (Article 5), requires measures to allow tracing and to monitor authorised dealers and brokers, and prohibits the acquisition and possession of the most dangerous firearms except under strict conditions (Article 9 and related provisions). It requires Member States to establish data filing systems, control intra-Union transfers and lay down penalties for infringements (Article 23).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-27-cfr-part-478-atf-commerce-firearms-ammunition",
      "eu-dual-use-regulation-2021-821"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cookie-directive-consent-operations",
    "title": "Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)",
    "domain": "Operations & CX",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive requires providers of publicly available electronic communications services to obtain users' informed consent before storing or accessing information on their devices, such as through cookies, and mandates specific privacy safeguards for traffic data and subscriber information under Article 5(3). It applies to all organizations offering electronic communications services in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "eu-omnibus-directive-2019-2161",
      "iso-10002-2018-customer-satisfaction-complaints"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-copyright-article-17-upload-filters-implementation",
    "title": "Directive (EU) 2019/790 of the European Parliament and of the Council on Copyright and Related Rights in the Digital Single Market, Article 17 - Obligations for Online Content Sharing Service Providers",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Online Content Sharing Service Providers (OCSSPs) must make best efforts to obtain authorisation from rightsholders and prevent the availability of unauthorised content on their platforms, including through the use of effective content recognition technologies, while ensuring safeguards for user rights, complaints, and redress. Applies to OCSSPs under Article 17(4) of the EU Copyright Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "berne-convention-1886-2024-literary-artistic-works",
      "dmca-safe-harbor",
      "copyright-fair-use-us"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-copyright-collective-management-directive-2014-26",
    "title": "Directive 2014/26/EU of the European Parliament and of the Council of 26 February 2014 on collective management of copyright and related rights and multi-territorial licensing of rights in musical works for online use in the internal market",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This directive establishes binding governance, transparency, and financial management standards for Collective Management Organizations (CMOs) in the EU, mandates multi-territorial licensing for online music use, and ensures fair representation of rightholders. It applies to all CMOs managing rights in musical works for online exploitation under Articles 11 and 12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "berne-convention-1886-2024-literary-artistic-works",
      "eu-resale-right-directive-2001-84-droit-de-suite",
      "dmca-safe-harbor",
      "iptc-photo-metadata"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-copyright-directive-2019-790",
    "title": "EU Digital Single Market Copyright Directive 2019/790 -- Online Platform Obligations and Creator Rights",
    "domain": "Creative, Content & Media IP",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Directive (EU) 2019/790 (DSM Copyright Directive) modernises EU copyright law for the digital environment. Member States were required to implement it by 7 June 2021. Article 3 introduces a mandatory exception for text and data mining (TDM) by research organisations for scientific research. Article 4 introduces a TDM exception for any purpose unless rights holders have opted out using machine-readable means. Article 15 creates a press publishers' neighbouring right (2 years duration) entitling press publishers to remuneration when online platforms reproduce their press publications; single words, individual words, and very short extracts used as hyperlinks are exempt. Article 17 holds Online Content Sharing Service Providers (OCSSPs - platforms like YouTube and TikTok that store and give access to large volumes of user-uploaded content) directly liable for copyright infringement unless they obtain authorisation or demonstrate they made best efforts to obtain authorisation, made best efforts to ensure unavailability of notified content, and acted expeditiously on notice to disable or prevent re-upload. Article 18 requires appropriate and proportionate remuneration for creators licensing their rights. Article 19 imposes a transparency obligation on licensees to report to creators at least annually on all modes of exploitation and revenue generated.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-trademark-regulation-2017-1001",
      "eu-digital-content-services-directive-2019-770",
      "eu-data-governance-act-2022-868"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-copyright-directive-2019-790-text-data-mining",
    "title": "Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market and amending Directives 96/9/EC and 2001/29/EC - Articles 3 and 4: Text and Data Mining Exceptions",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Articles 3 and 4 of Directive (EU) 2019/790 establish a mandatory exception to copyright for text and data mining (TDM) by research organisations and cultural heritage institutions for scientific research purposes (Article 3), and a separate TDM exception for any lawful user for any purpose, provided rightsholders have not expressly reserved their rights (Article 4). These provisions apply to EU member states and require national implementation to ensure lawful access and opt-out mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-open-science-policy-fair-data-principles-2021",
      "eu-european-research-area-policy-agenda-2022",
      "eu-digital-education-action-plan-2021-2027-deap",
      "oecd-principles-ai-in-education-recommendation-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-copyright-directive-art-17",
    "title": "EU Copyright (Art 17)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Article 17 of Directive (EU) 2019/790 establishes a specific liability regime for platforms classified as Online Content-Sharing Service Providers (OCSSPs), which perform an act of communication to the public when giving access to copyright-protected works uploaded by their users. To avoid direct liability for copyright infringement, OCSSPs must demonstrate having made 'best efforts' to obtain authorization from rightholders. In the absence of such authorization, liability can be exempted by making 'best efforts' in accordance with high industry standards of professional diligence to ensure the unavailability of specific works for which rightholders have provided relevant and necessary information. Furthermore, platforms must act expeditiously upon receiving a notice to take down notified works and implement 'notice and stay-down' procedures. A lighter liability regime applies to new micro and small enterprises that have been providing services in the Union for less than three years with an annual turnover below EUR 10,000,000 and fewer than 5,000,000 average unique monthly visitors. Importantly, these measures must not prevent the availability of user uploads that constitute legitimate uses under mandatory exceptions for quotation, criticism, review, caricature, parody, or pastiche. To safeguard user rights, as clarified by European Commission Guidance COM/2021/288, OCSSPs are mandated to provide users with an effective and expeditious complaint and redress mechanism for disputes over content removal, which must include provisions for human review.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-literary-artistic",
      "wipo-copyright-treaty",
      "dmca-safe-harbor",
      "copyright-fair-use-us"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-copyright-dsm-directive-2019-790",
    "title": "Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market and amending Directives 96/9/EC and 2001/29/EC",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This directive modernizes EU copyright law, establishing a mandatory exception for text and data mining (TDM) for scientific research (Article 3) and creating a new liability regime for online content-sharing service providers (OCSSPs) that requires them to obtain authorization from rightholders or demonstrate best efforts to ensure the unavailability of specific unauthorized works (Article 17).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-literary-artistic",
      "wipo-copyright-digital-agenda",
      "eu-trade-secrets-directive-2016"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-copyright-term-directive-2011-77-eu",
    "title": "Directive 2011/77/EU of the European Parliament and of the Council of 25 October 2011 amending Directive 2006/116/EC on the term of protection of copyright and certain related rights",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Extends the term of protection for phonogram producers and performers from 50 to 70 years from first publication or performance. Requires member states to ensure session musicians receive equitable remuneration through a 20% levy on exploitation rights and establishes a contractual reversion right after 50 years under the 'clean slate' principle. Key provisions are in Articles 3, 4, and 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-1886-2024-literary-artistic-works",
      "eu-copyright-directive-art-17",
      "eu-resale-right-directive-2001-84-droit-de-suite"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-copyright-text-data-mining-article-3-4-dsmcd",
    "title": "Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market and amending Directives 96/9/EC and 2001/29/EC - Articles 3 and 4: Text and Data Mining Exceptions",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Articles 3 and 4 of the EU Copyright Directive (DSMCD) establish a mandatory exception to copyright for text and data mining (TDM) by research organisations for scientific research (Article 3), and a broader exception for any lawful user for TDM purposes, provided rightsholders have not expressly reserved their rights via machine-readable means such as robots.txt or an opt-out database (Article 4). These provisions apply to online content protected by copyright and require compliance with technical opt-out mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "berne-convention-1886-2024-literary-artistic-works",
      "dmca-safe-harbor",
      "eu-data-governance-act-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-corporate-sustainability-due-diligence-2024",
    "title": "Directive (EU) 2024/1760 of the European Parliament and of the Council of 24 May 2024 on corporate sustainability due diligence and amending Directives (EU) 2019/1937 and (EU) 2022/2555",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This directive requires large EU and non-EU companies to conduct risk-based human rights and environmental due diligence across their own operations, their subsidiaries, and their value chains. As outlined in Article 5, companies must identify, prevent, mitigate, and account for adverse impacts, and establish a climate transition plan in line with the Paris Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-20400-sustainable-procure",
      "iso-26000-social-resp-mgt",
      "iso-31000-risk-mgt-std",
      "eu-whistleblower-directive-2019",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-corporate-sustainability-due-diligence-directive-2024-1760",
    "title": "EU Corporate Sustainability Due Diligence Directive 2024/1760",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-07-25",
    "bluf": "Directive (EU) 2024/1760 (CS3D) requires large companies to conduct human rights and environmental due diligence across their own operations, subsidiaries, and business partners in their chain of activities, with Phase 1 applying to companies with over 5,000 employees and EUR 1,500,000,000 turnover from 26 July 2027, civil liability under Article 22 for actual adverse impacts, and maximum penalties of 5% of net worldwide turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-corporate-sustainability-reporting-directive-2022-2464",
        "eu-taxonomy-regulation-2020-852",
        "eu-general-product-safety-regulation-2023-988"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-corporate-sustainability-reporting-directive-2022-2464",
      "eu-taxonomy-regulation-2020-852",
      "eu-general-product-safety-regulation-2023-988"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-corporate-sustainability-reporting-directive-2022-2464",
    "title": "EU Corporate Sustainability Reporting Directive (CSRD) 2022/2464 -- Mandatory ESG Reporting and Double Materiality",
    "domain": "Sustainability & ESG",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Directive (EU) 2022/2464 (CSRD) replaces the Non-Financial Reporting Directive (NFRD 2014/95/EU) and significantly expands the scope and quality of mandatory corporate sustainability reporting. It applies in four phases: FY2024 reports (large public-interest entities with more than 500 employees); FY2025 reports (all large EU companies with more than 250 employees or EUR 40 million turnover or EUR 20 million total assets, meeting 2 of 3 thresholds); FY2026 reports (listed SMEs with opt-out until FY2028); and FY2028 reports (non-EU companies with EU net turnover exceeding EUR 150 million and an EU subsidiary or branch). CSRD requires a double materiality assessment under ESRS 1: financial materiality (sustainability risks and opportunities material to the company's financial performance) and impact materiality (actual and potential impacts on people and environment). Sustainability statements must be included in the management report and subject to limited assurance (moving to reasonable assurance by 2028). The European Sustainability Reporting Standards (ESRS) adopted via Delegated Regulation 2023/2772 set the disclosure framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852",
      "eu-waste-framework-directive-2008-98",
      "uk-climate-change-act-2008"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-corporate-sustainability-reporting-directive-2022-2464-csrd",
    "title": "EU Corporate Sustainability Reporting Directive 2022/2464 (CSRD) - ESG Disclosure and ESRS Standards",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive (EU) 2022/2464 (CSRD) replaces the Non-Financial Reporting Directive (NFRD) and requires large EU companies and listed SMEs to disclose sustainability information under the European Sustainability Reporting Standards (ESRS). Companies must report on environmental (climate, biodiversity, water), social (workforce, supply chain, affected communities), and governance topics using a double materiality assessment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-corporate-sustainability-reporting-directive-csrd-2022",
    "title": "EU Corporate Sustainability Reporting Directive (Directive EU 2022/2464 CSRD) amending accounting, transparency, audit instruments",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-16",
    "bluf": "Directive EU 2022/2464 Corporate Sustainability Reporting Directive CSRD replaces the Non-Financial Reporting Directive NFRD strengthening and expanding sustainability reporting obligations for large undertakings and listed SMEs in the EU. Published 16 December 2022 with transposition deadline 6 July 2024. Phased application starts from financial year 2024 for large public-interest entities with over 500 employees already subject to NFRD; from FY 2025 for other large undertakings meeting size thresholds; from FY 2026 for listed SMEs and small non-complex credit institutions with a two-year opt-out option; from FY 2028 for non-EU parent groups with EU turnover above EUR 150 million. Reporting must follow European Sustainability Reporting Standards ESRS adopted via Commission Delegated Regulation 2023/2772 effective 1 January 2024 covering environmental social and governance topics. Mandatory third-party assurance begins at limited assurance level with potential transition to reasonable assurance subject to a Commission feasibility study. Digital tagging of reports using XBRL taxonomy under European Single Electronic Format ESEF is required. The directive amends Accounting Directive 2013/34/EU Transparency Directive 2004/109/EC Audit Directive 2006/43/EC and Audit Regulation 537/2014.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-accounting-directive-2013-34"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-covered-bonds-directive-2019-2162",
    "title": "EU Covered Bonds Directive 2019/2162 - European Covered Bond Framework",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2022-07-08",
    "bluf": "Directive (EU) 2019/2162 harmonises the legal framework for covered bonds across the EU - defining covered bond structural requirements (dual recourse, dynamic cover pool, special public supervision) to qualify for preferential capital treatment under CRR and UCITS investment limits. Member States transposed by 8 July 2022.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-ucits-directive-2009-65",
      "mifid-ii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cra-2024-2847-article-10-obligations-importers",
    "title": "Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act) - Article 10: Enhancing skills in a cyber resilient digital environment",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires Member States to promote measures and strategies for enhancing cybersecurity skills, which indirectly obligates importers to ensure their professionals are aware of and can participate in these initiatives to support the implementation of the Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-10-data-governance-training",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cra-2024-2847-article-11-obligations-distributors",
    "title": "Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act) - Article 11: General product safety",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article mandates that for products with digital elements, specific safety provisions from the General Product Safety Regulation (EU) 2023/988 apply to any risks not covered by this Regulation, provided no other specific Union safety legislation is applicable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cra-2024-2847-article-13-vulnerability-handling-requirements",
    "title": "Regulation (EU) 2024/2847 (Cyber Resilience Act) Article 13: Obligations of manufacturers",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Manufacturers must ensure that products with digital elements are designed, developed, and produced in compliance with the essential cybersecurity requirements outlined in Annex I before placing them on the market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cra-2024-2847-article-20-conformity-assessment-procedures",
    "title": "REGULATION (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) - Article 20 Conformity assessment procedures",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Manufacturers must follow specified conformity assessment procedures to demonstrate that their products with digital elements meet the essential cybersecurity requirements before being placed on the market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cra-2024-2847-article-3-essential-requirements-products-digital-elements",
    "title": "Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements - Article 3: Definitions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article defines 'product with digital elements' as any software or hardware product, including its remote data processing solutions and components placed on the market separately, establishing the scope of items subject to the regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cra-2024-2847-article-56-market-surveillance-enforcement",
    "title": "REGULATION (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) - Article 56 Market surveillance and control of products with digital elements in the Union market",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article mandates Member State market surveillance authorities to conduct checks on products with digital elements to ensure they comply with this Regulation, including powers to require information, perform evaluations, and take restrictive measures against non-compliant products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cra-2024-2847-article-6-obligations-manufacturers",
    "title": "Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) No 910/2014 and Directive (EU) 2019/882 - Article 6",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article establishes the fundamental pre-market compliance obligation that products with digital elements may only be made available on the EU market if they meet all specified requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cra-2024-2847-article-64-administrative-fines",
    "title": "Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act) - Article 64: General conditions for imposing administrative fines",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article establishes the conditions, criteria, and maximum amounts for administrative fines that can be imposed by market surveillance authorities for non-compliance with the Cyber Resilience Act's obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cra-2024-2847-article-9-end-of-life-policy-manufacturers",
    "title": "Regulation (EU) 2024/2847 on cybersecurity requirements for products with digital elements - Article 9: Stakeholder consultation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article establishes the European Commission's obligation to consult with relevant stakeholders, including private sector undertakings, when preparing implementation measures for this Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cra-essential-cybersecurity-requirements",
    "title": "EU Cyber Resilience Act - Regulation (EU) 2024/2847 of 23 October 2024 on Horizontal Cybersecurity Requirements for Products with Digital Elements (Annex I Essential Cybersecurity Requirements; Application from 11 December 2027 with Earlier Phase-in for Reporting and Conformity-Assessment-Body Provisions)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Cyber Resilience Act, Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 (published in the Official Journal of the European Union L series on 20.11.2024), establishes horizontal cybersecurity requirements for products with digital elements placed on the EU market, amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828. Article 1 (Subject matter) sets out that the Regulation lays down (a) rules for making products with digital elements available on the market to ensure their cybersecurity, (b) essential cybersecurity requirements for design, development and production of those products and obligations for economic operators, (c) essential cybersecurity requirements for the vulnerability handling processes put in place by manufacturers during the time products are expected to be in use, and (d) rules on market surveillance, monitoring, and enforcement. The essential cybersecurity requirements are split across Annex I, with Part I (security-property requirements applicable to the products) and Part II (vulnerability handling requirements applicable to the manufacturer's processes). Manufacturers must ensure both the product and the underlying processes comply with the relevant Part. The Regulation defines 'actively exploited vulnerability' as 'a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner', and 'support period' as the period during which a manufacturer is required to ensure that vulnerabilities are handled effectively in accordance with Part II of Annex I. The application timetable is staged: the bulk of the Regulation applies from 11 December 2027; the reporting obligations concerning actively exploited vulnerabilities and severe incidents apply from 11 September 2026; and the provisions on notification of conformity assessment bodies apply from 11 June 2026. Manufacturers must simultaneously notify the CSIRT designated as coordinator and ENISA via a single reporting platform, with an early-warning notification deadline of 24 hours from awareness for actively exploited vulnerabilities and severe incidents. The CE marking attaches when conformity with Annex I and other applicable Union harmonisation legislation is achieved.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-nis2-directive-2022-2555",
        "eu-ai-act-2024-1689",
        "eu-machinery-regulation-2023-1230",
        "eu-radio-equipment-directive-delegated-2022-30",
        "eu-product-liability-directive-2024-2853"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-essential-important-entities-obligations",
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 15
  },
  {
    "node_id": "eu-cra-technical-description-products-2025-2392",
    "title": "Commission Implementing Regulation (EU) 2025/2392 on the technical description of the categories of important and critical products with digital elements pursuant to Regulation (EU) 2024/2847 (Cyber Resilience Act)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This Implementing Regulation provides the technical description of the important (class I and class II) and critical product categories with digital elements under the Cyber Resilience Act, where the core functionality of a product determines the category it falls into and therefore which conformity assessment procedure the manufacturer must follow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cyber-resilience-act-regulation-2024-2847",
      "eu-cra-2024-2847-article-20-conformity-assessment-procedures",
      "eu-cra-2024-2847-article-6-obligations-manufacturers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-crd-vi-2024",
    "title": "Directive (EU) 2024/1619 of the European Parliament and of the Council of 31 May 2024 amending Directive 2013/36/EU as regards supervisory powers, sanctions, third-country branches, and environmental, social and governance risks, and amending Directive 2014/59/EU",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-06-14",
    "bluf": "This directive, part of the EU's Basel IV implementation, strengthens bank resilience by refining supervisory powers and introducing explicit requirements for institutions to identify, manage, and disclose short, medium, and long-term Environmental, Social, and Governance (ESG) risks as part of their risk management framework and the Supervisory Review and Evaluation Process (SREP) under Article 98(8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "bcbs-climate-related-financial-risks",
      "ecb-srep-2023-supervisory-guide",
      "dora-ict-risk-management-articles-5-16"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-credit-rating-agencies-regulation-1060-2009",
    "title": "EU CRA Regulation - Credit Rating Agencies Regulation 1060/2009",
    "domain": "Banking & Global Finance",
    "version": "2.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Regulation (EC) No 1060/2009 (CRA Regulation) establishes binding rules for credit rating agencies operating in the EU - requiring registration with ESMA, mandatory disclosure of methodologies, management of conflicts of interest, rotation of analysts, and civil liability for negligent or intentional ratings infringements. As amended by CRA II (2011) and CRA III (2013).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mifid-ii",
      "eu-capital-requirements-directive-iv-2013-36-crd4"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-crisis-force-majeure-migration-regulation-2024-1359",
    "title": "Regulation (EU) 2024/1359 addressing situations of crisis and force majeure in the field of migration and asylum - reasoned request, Council implementing decision and three-month derogation period",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Regulation (EU) 2024/1359, adopted 14 May 2024 as part of the EU Pact on Migration and Asylum, sets out temporary measures a Member State may apply when facing a situation of crisis or force majeure in migration and asylum. A Member State submits a reasoned request to the Commission; the Commission must adopt an implementing decision no later than two weeks from submission; and a Council implementing decision sets the period for derogations and solidarity measures, which is to be three months. All temporary measures must meet the requirements of necessity and proportionality.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-reception-conditions-directive-2024-1346",
      "eu-dublin-iii-regulation-604-2013-asylum-responsibility",
      "eu-ai-act-high-risk-migration-border"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-crisis-relevant-medical-countermeasures-regulation-2022-2372",
    "title": "Council Regulation (EU) 2022/2372 of 24 October 2022 on a framework of measures for ensuring the supply of crisis-relevant medical countermeasures in the event of a public health emergency at Union level",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation establishes a framework of measures for ensuring the supply of crisis-relevant medical countermeasures in the event of a public health emergency at Union level (Article 1). The emergency framework is activated by Council implementing regulation (Article 3) and may be prolonged, deactivated or allowed to expire (Article 4). It establishes the Health Crisis Board (Article 5) with declarations of interest (Article 6), a mechanism for monitoring crisis-relevant medical countermeasures (Article 7), provisions for the procurement, purchase and manufacturing of countermeasures (Article 8), and inventories of production capacities and raw materials (Articles 10 and 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-reinforced-role-ema-medicines-regulation-2022-123",
      "eu-medical-devices-regulation-2017-745"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-critical-entities-resilience-2022",
    "title": "Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-22",
    "bluf": "The EU Critical Entities Resilience (CER) Directive requires designated critical entities across 11 sectors to implement technical, security, and organizational measures to enhance their physical resilience against non-cyber threats. As per Article 13, these entities must conduct regular risk assessments and establish a resilience plan to prevent, protect against, respond to, resist, mitigate, absorb, accommodate, and recover from disruptive incidents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-28000-supply-chain",
      "iso-27005-risk-management-2022",
      "nist-contingency-planning-federal-systems"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-critical-entities-resilience-directive-2022",
    "title": "Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC (Text with EEA relevance)",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Directive establishes a Union framework to enhance the resilience of critical entities in sectors essential to societal and economic functions, requiring Member States to identify such entities and ensure they implement risk assessments, preventive and protective measures, incident reporting, and background checks on personnel. Key obligations are set out in Articles 7, 8, 9, 10, and 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-radio-equipment-directive-2014-53-iot",
      "eu-batteries-regulation-2023-1542-iot-storage",
      "iec-60870-telecontrol-scada-protocols",
      "eu-pressure-equipment-directive-2014-68"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-critical-entities-resilience-directive-2022-nis2-telecoms",
    "title": "Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of security of network and information systems across the Union (NIS2 Directive), as it applies to telecoms operators designated as essential or important entities",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The EU CER Directive 2022/2557, as implemented through the NIS2 framework, requires telecoms operators designated as essential or important entities to conduct mandatory physical and cybersecurity risk assessments, report significant incidents to national authorities within 24 hours of awareness and provide follow-up reports within 72 hours, implement baseline security controls, conduct background checks on personnel with privileged access, and participate in EU-level cross-border resilience planning. Key obligations are established in Articles 21, 22, and 26.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-nis2-telecoms-essential-services",
      "eu-5g-cybersecurity-toolbox-2020",
      "eu-radio-equipment-directive-2014-53-red",
      "eu-broadband-cost-reduction-directive-2014-61"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-critical-raw-materials-act-2024",
    "title": "Regulation (EU) 2024/1252 of the European Parliament and of the Council of 11 April 2024 establishing a framework for ensuring a secure and sustainable supply of critical raw materials and amending Regulations (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1724 and (EU) 2019/1020",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes a framework to ensure the EU's secure and sustainable supply of critical and strategic raw materials by setting clear benchmarks for domestic capacities and supply chain diversification. It requires the Union to develop capacities for extraction, processing, and recycling to meet specific targets by 2030, as outlined in Article 1(2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate-related-disclosures",
      "iso-14064-ghg-reporting-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-critical-raw-materials-act-2024-1252",
    "title": "Regulation (EU) 2024/1252 - Critical Raw Materials Act (CRMA): 10/40/25% Extraction/Processing/Recycling Benchmarks, 65% Single-Country Concentration Cap, Strategic Projects Fast-Track Permitting, and Large Company Supply Chain Audits for 17 Strategic Raw Materials",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2024/1252 (Critical Raw Materials Act, CRMA), in force from 23 May 2024, establishes a framework to ensure the EU's access to critical raw materials by setting 2030 benchmarks: EU domestic extraction of at least 10% of annual consumption, processing of at least 40%, and recycling of at least 25% of each strategic raw material (Annex I: 17 materials including lithium, cobalt, manganese, graphite, nickel, silicon metal, magnesium, titanium, tungsten); no single third country may supply more than 65% of any strategic CRM at any processing stage; the Act creates Strategic Projects (accelerated permitting: 24 months for extraction/27 months total, 12 months for processing) recognised by the European Critical Raw Materials Board; large companies (companies manufacturing strategic technologies using strategic raw materials (large companies per EU Accounting Directive)) must conduct annual supply chain audits and strategic stock assessments by 24 May 2025; Member States must establish national exploration programmes and Critical Raw Materials national contact points.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_NZIA",
        "EU_BATTERIES",
        "EU_IRA_COMPETITION",
        "EU_TAXONOMY"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-net-zero-industry-act-2024-manufacturing-capacity",
      "eu-taxonomy-regulation-2020-852",
      "eu-batteries-regulation-2023-1542-ev",
      "eu-renewable-energy-directive-red-iii-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-critical-raw-materials-act-2024-1252-strategic-projects",
    "title": "EU Critical Raw Materials Act 2024/1252 - Strategic Project Designation, 2030 Capacity Benchmarks and Supply Chain Diversification",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "Regulation (EU) 2024/1252 of the European Parliament and of the Council of 11 April 2024 establishing a framework for ensuring a secure and sustainable supply of critical raw materials (Critical Raw Materials Act, CRMA) entered into force on 23 May 2024. The Regulation establishes the first EU-level framework specifically targeting critical raw materials supply security. Article 2 designates 34 Critical Raw Materials and a subset of 17 Strategic Raw Materials in Annexes I-II covering minerals critical to renewable energy, digital technologies, defence and aerospace including lithium, cobalt, nickel, manganese, graphite, rare earths, copper, gallium, germanium, magnesium, and silicon metal. Article 5 sets binding 2030 capacity benchmarks: at least 10% of EU annual consumption extracted within EU, at least 40% processed within EU, at least 25% from recycled materials, and no more than 65% from any single third country for any strategic raw material at any stage. Article 6 establishes Strategic Project designation enabling streamlined permitting (max 27 months for extraction, 15 months for processing/recycling). Article 22 introduces Joint Purchase Mechanism for critical raw materials. Article 36 requires Member State exploration plans by 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cbam-2023-956-carbon-border-adjustment",
      "iso-14046-2014-water-footprint-mining"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-critical-raw-materials-act-2024-1252-strategic-supply-chain",
    "title": "EU Critical Raw Materials Act 2024/1252 - Strategic Raw Materials Supply Chain and Benchmarks",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Regulation (EU) 2024/1252 (Critical Raw Materials Act) establishes a list of 34 critical and 17 strategic raw materials, sets 2030 supply chain benchmarks (domestic extraction 10%, processing 40%, recycling 25%), requires large companies to conduct supply chain audits for strategic raw materials, mandates Member State permitting timelines, and creates a European Critical Raw Materials Board to coordinate strategic projects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csddd-corporate-sustainability-due-diligence-2024-1760"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-critical-raw-materials-act-2024-crma",
    "title": "Regulation (EU) 2024/1252 of the European Parliament and of the Council of 11 April 2024 establishing a framework for ensuring a secure and sustainable supply of critical raw materials and amending Regulations (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1724 and (EU) 2019/1020 (Text with EEA relevance)",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-29",
    "bluf": "This regulation establishes benchmarks for domestic extraction, processing, and recycling of critical raw materials within the EU, mandates diversification of supply chains, and designates strategic raw materials projects to ensure resilience of the internal market. It applies to operators involved in the critical raw materials value chain under Article 6 and Article 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-conflict-minerals-regulation-2017-821",
      "eiti-standard-2023",
      "canada-national-instrument-43-101",
      "australia-epbc-act-1999-mining-biodiversity",
      "chile-mining-code-1983"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-critical-raw-materials-act-2024-strategic-minerals",
    "title": "Regulation (EU) 2024/1252 of the European Parliament and of the Council of 11 April 2024 establishing a framework for ensuring a secure and sustainable supply of critical raw materials and amending Regulations (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1724 and (EU) 2019/1020",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The EU Critical Raw Materials Act establishes a framework to secure the Union's supply of strategic and critical raw materials by setting clear benchmarks for 2030: at least 10% of annual consumption from domestic extraction, 40% from processing, and 25% from recycling, while ensuring no more than 65% of any strategic raw material comes from a single third country (Article 1(2)). This applies to EU Member States and large companies operating within these supply chains.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-161r1-csrm-practices",
      "iso-14064-ghg-quantify",
      "reach-chemical-comp"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-cross-border-parcel-delivery-regulation-2018-644",
    "title": "Regulation (EU) 2018/644 of the European Parliament and of the Council of 18 April 2018 on cross-border parcel delivery services",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down specific provisions to foster better cross-border parcel delivery services, in addition to the Postal Services Directive (Article 1). Parcel delivery service providers must submit information about their business and services to the national regulatory authority (Article 4), and cross-border providers must provide their public list of tariffs for single-piece parcels (Article 5), which the Commission publishes and assesses for unreasonably high tariffs (Article 6). Traders must inform consumers about cross-border delivery options and prices (Article 7), with penalties for infringement (Article 8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-international-road-haulage-regulation-1072-2009",
      "eu-general-product-safety-regulation-2023-988"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cross-border-road-safety-traffic-offences-directive-2015-413",
    "title": "Directive (EU) 2015/413 of the European Parliament and of the Council of 11 March 2015 facilitating cross-border exchange of information on road-safety-related traffic offences",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive facilitates the cross-border exchange of information on road-safety-related traffic offences to ensure penalties are applied to non-resident offenders (Article 1). It applies to the road-safety-related traffic offences listed in Article 2, including speeding, non-use of a seat belt, failing to stop at a red light and drink-driving (Article 2). Member States grant each other access through national contact points to vehicle registration data using an automated search procedure (Article 4), and the offence Member State decides whether to send an information letter to the holder of the vehicle (Article 5), subject to data-protection safeguards (Article 7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-road-safety-policy-framework-2021-2030",
      "eu-data-governance-act-2022-868"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-crowdfunding-regulation-2020-1503",
    "title": "EU European Crowdfunding Service Providers Regulation (ECSPR) 2020/1503 - EUR 5M Threshold, KIIS, EU Passport",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2020/1503 (ECSPR) creates a harmonised EU framework for crowdfunding platforms facilitating business financing. Crowdfunding Service Providers (CSPs) must be authorised by their home NCA (Article 12) and benefit from an EU passport (Article 13) to offer services across all Member States. Scope ceiling: EUR 5M per project over 12 months from EEA investors - projects above this threshold require a MiFID prospectus. Non-sophisticated investors benefit from a 4-day pre-contractual reflection period and a EUR 1,000 per project default investment limit (Article 21(7)). Every crowdfunding offering must have a Key Investor Information Sheet (KIIS) (Article 23), a maximum 6-page document replacing the KID in this context. Platforms must conduct a creditworthiness assessment of project owners (Articles 4-5). The Regulation applies from 10 November 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "MiFID_II_threshold",
        "AML_KYC",
        "PRIIPs_KID_alternative",
        "PSD2_payment_services",
        "GDPR_investor_data"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-regulation-2024",
      "eu-psd2-strong-customer-authentication",
      "eu-priips-regulation-1286-2014-kid"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-crr3-capital-requirements-regulation-2024-1623",
    "title": "EU CRR3 Capital Requirements Regulation 2024/1623 - Basel IV / Output Floor 72.5%",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2024/1623 (CRR3) implements the Basel IV reforms in the EU. It introduces a 72.5% output floor limiting the benefit of internal models for capital calculation, revises standardised approaches for credit, market, and operational risk, replaces the Advanced Measurement Approach for OpRisk with the Standardised Measurement Approach, and implements FRTB market risk rules. Phase-in of the output floor runs from January 2025 to January 2030.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-brrd-bank-recovery-resolution-directive-2014-59",
      "eu-emir-regulation-648-2012",
      "eu-csdr-regulation-909-2014"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-csddd-corporate-sustainability-due-diligence-2024-1760",
    "title": "EU Corporate Sustainability Due Diligence Directive (CSDDD) 2024/1760 - Value Chain Human Rights and Environmental Obligations",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "CSDDD (Directive 2024/1760) requires large EU companies and qualifying non-EU companies to identify, prevent, mitigate, and account for adverse human rights and environmental impacts across their own operations and established business relationships throughout the value chain. Phased enforcement begins 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852",
      "eu-csrd-directive-2022-2464-corporate-sustainability-reporting"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-csddd-directive-2024-1760",
    "title": "EU Corporate Sustainability Due Diligence Directive 2024/1760, CSDDD - Human Rights and Environmental Due Diligence",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Large enterprises with more than 500 employees and global net turnover exceeding EUR 150 million, and enterprises in high-risk sectors such as mining, textiles, and agriculture as identified by the CSDDD, must (after Member State transposition by 26 July 2027, with national measures published by 26 July 2028 and applied from 26 July 2029, except Article 16 reporting measures which apply for financial years starting on or after 1 January 2030) identify and assess actual and potential adverse human rights and environmental impacts arising from their own operations, those of their subsidiaries, and where related to their chains of activities those of their business partners, implement preventive and remedial measures, conduct continuous monitoring and evaluation, publicly disclose due diligence, and review and update due diligence policies without undue delay after a significant change and in any event at least every 24 months.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ghg-protocol-scope3"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-csddd-directive-2024-1760-article-10-remediation-adverse-impacts",
    "title": "EU Corporate Sustainability Due Diligence Directive (EU) 2024/1760 - Article 10: Remediation of Actual Adverse Impacts",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 10 of the EU Corporate Sustainability Due Diligence Directive (CSDDD, 2024/1760) requires companies subject to the Directive to take appropriate measures to provide remediation for actual adverse impacts on human rights and the environment that the company has caused or contributed to, or that are directly linked to its value chain operations through a business relationship. Remediation must be commensurate with the adverse impact - it must restore the affected person or environment to the state they would have been in had the impact not occurred, as far as possible. Where full restoration is not possible, the company must take appropriate alternative remediation measures. Companies must implement an accessible grievance mechanism through which affected persons, their representatives, or trade unions can raise concerns about actual or potential adverse impacts. The grievance mechanism must provide effective access to remediation and must be established in cooperation with workers and their representatives. Companies must also cooperate with other companies in the same value chain on joint remediation where multiple entities contributed to the same impact. Civil liability for failure to remediate is established by Article 29.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csddd-directive-2024-1760-article-8-prevention-adverse-impacts"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-csddd-directive-2024-1760-article-12-stakeholder-engagement-consultation",
    "title": "EU Corporate Sustainability Due Diligence Directive (EU) 2024/1760 - Article 12: Stakeholder Engagement and Meaningful Consultation",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 12 of the EU Corporate Sustainability Due Diligence Directive (CSDDD, 2024/1760) requires companies to engage in meaningful consultation with stakeholders when carrying out due diligence under the Directive. Companies must consult with potentially affected persons and groups, including workers and their representatives, before taking measures to prevent potential adverse impacts (Article 8), implementing remediation measures (Article 10), developing their transition plan (Article 16), and preparing their annual due diligence communication. Meaningful consultation requires that: (a) stakeholders have access to timely, relevant, and understandable information about the company's due diligence approach and its potential impacts; (b) stakeholders are given a genuine opportunity to comment before decisions are taken; (c) the company genuinely considers and incorporates stakeholder input; (d) consultation is conducted in good faith without a predetermined outcome. Where potentially affected persons cannot be directly reached (e.g., in conflict-affected areas or where direct access is restricted), companies may consult with civil society organisations or other relevant proxies. The consultation obligation applies to both own operations and value chain business relationships.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csddd-directive-2024-1760-article-8-prevention-adverse-impacts",
      "eu-csddd-directive-2024-1760-article-10-remediation-adverse-impacts"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-csddd-directive-2024-1760-article-16-climate-transition-plan",
    "title": "EU Corporate Sustainability Due Diligence Directive (EU) 2024/1760 - Article 16: Adoption and Implementation of Climate Transition Plan",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 16 of the EU Corporate Sustainability Due Diligence Directive (CSDDD, 2024/1760) requires in-scope companies to adopt and put into effect a climate transition plan. The transition plan must be designed to ensure, through best efforts, that the company's business model and strategy are compatible with the transition to a sustainable economy, limiting global warming to 1.5 degrees Celsius in line with the Paris Agreement, and achieving EU climate neutrality by 2050. The plan must include: (a) time-bound targets for reducing greenhouse gas emissions for 2030 and, where relevant, for intermediate steps including 2035, 2040, 2045; (b) a description of decarbonisation levers the company intends to use to meet its targets; (c) an explanation of the role of carbon offsets and removals; (d) an investment and financing plan for the implementation of the transition plan; and (e) an explanation of how executive remuneration is linked to the transition plan. The plan must be updated annually. Where the company reports a climate transition plan under CSRD, it satisfies the Article 16 adoption obligation. Article 16 does not require companies to guarantee the transition plan will be achieved, but requires best efforts and genuine implementation. Director liability applies if the board fails to adopt a transition plan without objective justification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csddd-directive-2024-1760-article-8-prevention-adverse-impacts",
      "eu-csddd-directive-2024-1760-article-12-stakeholder-engagement-consultation"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-csddd-directive-2024-1760-article-8-prevention-adverse-impacts",
    "title": "EU Corporate Sustainability Due Diligence Directive (EU) 2024/1760 - Article 8: Prevention of Potential Adverse Impacts",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 8 of the EU Corporate Sustainability Due Diligence Directive (CSDDD, 2024/1760) requires companies subject to the Directive to take appropriate measures to prevent, or where prevention is not possible, adequately mitigate potential adverse impacts on human rights and the environment that have been identified in their operations, subsidiaries, and value chain business relationships. Where a potential adverse impact cannot be prevented or adequately mitigated through the company's own measures, the company must seek contractual assurances from business partners regarding their conduct, and - where the impact is not prevented - must terminate or suspend the business relationship as a last resort. Article 8 also requires companies to develop and implement a prevention action plan covering medium-term and long-term measures. Companies must provide financial and non-financial support to SME business partners to enable their compliance. Measures must be reasonable and proportionate to the probability and severity of the potential adverse impact. Phased transposition applies: companies with 5,000+ employees and EUR 1.5bn turnover from 26 July 2027; 3,000+ employees and EUR 900m turnover from 26 July 2028; 1,000+ employees and EUR 450m turnover from 26 July 2029.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csddd-directive-2024-1760-article-10-remediation-adverse-impacts"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-csddd-directive-article-10-complaints-procedure",
    "title": "Directive (EU) 2024/1760 on Corporate Sustainability Due Diligence - Article 10",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires organizations to consider how provisions of Article 10(1) and Article 11(1) may indirectly raise the level of protection afforded by Article 8(1) and (2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-csddd-directive-article-11-monitoring-effectiveness",
    "title": "Directive (EU) 2024/1760 of the European Parliament and of the Council on Corporate Sustainability Due diligence - Article 11",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "As part of their due diligence obligations, companies must take action to bring actual adverse impacts to an end and minimize their extent in accordance with the requirements of this article.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-csddd-directive-article-22-civil-liability",
    "title": "Directive (EU) 2024/1760 on corporate sustainability due diligence and amending Directive (EU) 2019/1937 and Regulation (EU) 2023/2859 - Article 22 Civil liability",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article's text, concerning the conditions under which a company can be held liable for damages, was not present in the provided regulatory source material.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-csddd-directive-article-26-fines",
    "title": "Directive (EU) 2024/1760 on corporate sustainability due diligence - Article 26: Pecuniary penalties",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires Member States to establish rules for effective, proportionate, and dissuasive pecuniary penalties for infringements, with a maximum fine of at least 5% of the company's net worldwide turnover, and mandates the public disclosure of such penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-csddd-directive-article-5-risk-based-due-diligence-obligation",
    "title": "EU Corporate Sustainability Due Diligence Directive (CSDDD) - Article 5: Due diligence",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Companies must conduct risk-based human rights and environmental due diligence by integrating it into policies, identifying and mitigating impacts, engaging stakeholders, establishing complaints procedures, monitoring effectiveness, and publicly communicating on these efforts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-csddd-directive-article-6-identification-of-adverse-impacts",
    "title": "Directive (EU) 2024/1760 on Corporate Sustainability Due Diligence - Article 6: Due diligence support at a group level",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article permits parent companies to fulfill specific due diligence obligations on behalf of their subsidiaries, provided this ensures effective compliance and specific conditions for information sharing and policy adherence are met.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-csddd-directive-article-7-prevention-of-adverse-impacts",
    "title": "EU Corporate Sustainability Due Diligence Directive (CSDDD) - Article 7: Integrating due diligence into company policies and risk management systems",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires companies to integrate due diligence into all relevant policies and risk management systems, develop a comprehensive due diligence policy in consultation with employees, and regularly review and update it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-csddd-directive-article-8-bringing-to-an-end-and-minimising",
    "title": "Directive (EU) 2024/1760 on Corporate Sustainability Due Diligence - Article 5: Due diligence",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires companies to conduct risk-based human rights and environmental due diligence by integrating it into policies and risk management systems, and by identifying, assessing, and prioritising adverse impacts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-csdr-regulation-909-2014",
    "title": "EU CSDR - Central Securities Depositories Regulation 909/2014",
    "domain": "Banking & Global Finance",
    "version": "2.1.0",
    "last_updated": "2023-01-01",
    "bluf": "Regulation (EU) No 909/2014 (CSDR) harmonises rules for central securities depositories (CSDs) in the EU - requiring ESMA authorisation, T+2 settlement discipline, mandatory buy-in and cash penalties for settlement fails, and dematerialisation of transferable securities. CSDR Refit (2023) replaced the mandatory buy-in regime with optional buy-in.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mifid-ii",
      "eu-emir-regulation-648-2012",
      "eu-capital-requirements-directive-iv-2013-36-crd4"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-csrd-2022-2464",
    "title": "Directive (EU) 2022/2464 of the European Parliament and of the Council of 14 December 2022 amending Regulation (EU) No 537/2014, Directive 2004/109/EC, Directive 2006/43/EC and Directive 2013/34/EU, as regards corporate sustainability reporting",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The EU Corporate Sustainability Reporting Directive (CSRD) mandates that large undertakings, listed SMEs, and certain non-EU companies report on sustainability issues in line with the European Sustainability Reporting Standards (ESRS), as stipulated in the amended Article 19a of Directive 2013/34/EU. This reporting must cover environmental, social, and governance (ESG) matters and be subject to third-party assurance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-taxonomy-sustainable",
      "eu-sfdr-reporting",
      "gri-universal-standards",
      "tcfd-climate-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-csrd-directive-2022-2464",
    "title": "EU Corporate Sustainability Reporting Directive (EU) 2022/2464 (CSRD)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Directive (EU) 2022/2464 (the Corporate Sustainability Reporting Directive CSRD) significantly expands sustainability reporting obligations for EU companies. CSRD applies to: (i) large EU companies (any 2 of: 250+ employees EUR 50M turnover EUR 25M balance sheet); (ii) listed SMEs (transitional 2026-2028); (iii) third-country undertakings generating EUR 150M EU turnover with a large EU subsidiary or branch. Reporting follows European Sustainability Reporting Standards (ESRS) adopted by Commission in July 2023. Application phased: large public-interest entities (FY 2024 report 2025); large companies (FY 2025 report 2026); listed SMEs (FY 2026 report 2027 with opt-out to 2028); non-EU companies (FY 2028 report 2029). Limited assurance required transitioning to reasonable assurance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-csrd-directive-2022-2464-corporate-sustainability-reporting",
    "title": "EU Corporate Sustainability Reporting Directive (CSRD) 2022/2464 - ESRS Sustainability Statement Obligations",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "CSRD (Directive 2022/2464) extends mandatory sustainability reporting to ~50,000 EU companies, requiring a sustainability statement in the annual report using European Sustainability Reporting Standards (ESRS). Reporting covers double materiality: financial impacts on the company AND company impacts on society/environment. Phased implementation: large PIEs from 2025 (FY2024); other large companies from 2026; listed SMEs from 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852-sustainable-finance-classification",
      "eu-sfdr-regulation-2019-2088-sustainable-finance-disclosure"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ctis-clinical-trials-information-system-2022",
    "title": "EU Clinical Trials Information System (CTIS) Under CTR 536/2014 - Centralised Submission Portal, Transparency Publication Rules and Multi-Member State Trial Coordination and Assessment",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Clinical Trials Information System (CTIS) is the mandatory single entry point for sponsors and regulators to submit, assess, and supervise clinical trials in the European Economic Area (EEA) under Regulation (EU) No 536/2014. It harmonises submission processes and enforces public transparency of trial information and results, as mandated by Articles 81a and 81d of the Clinical Trial Regulation (CTR).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice",
      "eu-mdr-2017-745"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ctr-536-2014-2026",
    "title": "Regulation (EU) No 536/2014 - Clinical Trials Regulation (CTR) - Key Obligations (2026 Full Application)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The EU Clinical Trials Regulation 536/2014 harmonises the assessment and supervision of clinical trials across the EU/EEA through a single submission via the Clinical Trials Information System (CTIS). It mandates risk-proportionate oversight, enhanced transparency, robust informed consent, safety reporting, and sponsor responsibilities. Since 31 January 2025, all new and ongoing trials must fully comply with CTR using CTIS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-e6-r3-gcp-2026"
    ],
    "primary_citations_count": 3
  },
  {
    "node_id": "eu-ctr-regulation-article-10-authorisation-clinical-trial",
    "title": "Regulation (EU) No 536/2014 on clinical trials on medicinal products for human use - Article 10: Specific considerations for vulnerable populations",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must give specific consideration to the assessment of clinical trial authorisation applications involving vulnerable populations such as minors, incapacitated subjects, pregnant or breastfeeding women, and other specific groups.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ctr-regulation-article-2-definitions",
    "title": "Regulation (EU) No 536/2014 on clinical trials on medicinal products for human use - Article 2: Definitions",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations must apply the specific definitions for key terms such as 'medicinal product' and 'adverse reaction' from Directive 2001/83/EC when complying with this regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ctr-regulation-article-28-informed-consent",
    "title": "Regulation (EU) No 536/2014 of the European Parliament and of the Council on clinical trials on medicinal products for human use - Article 28: General rules",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must ensure that for any clinical trial, the anticipated benefits justify the foreseeable risks, this balance is constantly monitored, and subjects or their legally designated representatives are properly informed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ctr-regulation-article-35-safety-of-subjects",
    "title": "Regulation (EU) No 536/2014 of the European Parliament and of the Council on clinical trials on medicinal products for human use - Article 35: Clinical trials in emergency situations",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article establishes the specific conditions under which informed consent for a clinical trial may be obtained after the first intervention in an emergency situation, derogating from standard consent procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ctr-regulation-article-38-serious-breach",
    "title": "Regulation (EU) No 536/2014 of the European Parliament and of the Council on clinical trials on medicinal products for human use - Article 38: Temporary halt or early termination by the sponsor for reasons of subject safety",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Sponsors must notify Member States concerned via the EU portal without undue delay, and no later than 15 days, of any temporary halt or early termination of a clinical trial due to a change in the benefit-risk balance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ctr-regulation-article-41-unexpected-serious-adverse-reactions",
    "title": "Regulation (EU) No 536/2014 on clinical trials on medicinal products for human use - Article 41: Reporting of adverse events and serious adverse events by the investigator to the sponsor",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that clinical trial investigators must record, document, and report adverse events and serious adverse events to the sponsor within specified timeframes, and that sponsors must maintain detailed records of these reports.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ctr-regulation-article-44-annual-safety-reporting",
    "title": "Regulation (EU) No 536/2014 of the European Parliament and of the Council on clinical trials on medicinal products for human use - Article 44: Assessment by Member States",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires Member States to cooperate in assessing safety information received from the Agency and to involve responsible ethics committees in this assessment where mandated by national law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ctr-regulation-article-5-rules-for-submission-of-application",
    "title": "Regulation (EU) No 536/2014 on clinical trials on medicinal products for human use - Article 5: Submission of an application",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Sponsors seeking authorisation for a clinical trial must submit a complete application dossier to the relevant Member States via the central EU portal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ctr-regulation-article-58-traceability",
    "title": "Regulation (EU) No 536/2014 of the European Parliament and of the Council on clinical trials on medicinal products for human use - Article 58: Archiving of the clinical trial master file",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "The sponsor and investigator must archive the clinical trial master file for at least 25 years after the trial's end, ensuring it is accessible, legible, secure, and that all alterations are traceable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ctr-regulation-article-6-validation-of-application",
    "title": "REGULATION (EU) No 536/2014 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 16 April 2014 on clinical trials on medicinal products for human use, and repealing Directive 2001/20/EC - Article 6: Validation of Application",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article outlines the mandatory procedures and timelines for a Member State to validate a clinical trial application dossier submitted via the single submission portal, ensuring its completeness before assessment begins.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ctr-regulation-article-79-eu-portal-and-database",
    "title": "Regulation (EU) No 536/2014 on clinical trials on medicinal products for human use - Article 79",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the European Commission's authority to conduct controls to verify Member State supervision and the compliance of non-EU clinical trial regulatory systems, requiring cooperation and the reporting of findings via the EU portal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ctr-regulation-article-8-assessment-by-reporting-member-state",
    "title": "Regulation (EU) No 536/2014 on clinical trials on medicinal products for human use - Article 8: Decision on the clinical trial",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations sponsoring a clinical trial must receive and process the decision notification from each Member State concerned, delivered via the EU portal, which will state whether the trial is authorised, authorised with conditions, or refused.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-customs-code-implementing-regulation-2015",
    "title": "Commission Implementing Regulation (EU) 2015/2447 of 24 November 2015 laying down detailed rules for implementing certain provisions of Regulation (EU) No 952/2013 of the European Parliament and of the Council laying down the Union Customs Code",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The regulation requires electronic storage, exchange and processing of customs information, designates the competent authority for assigning a single EORI number per operator, obliges full computerisation of transit procedures and sets procedural rules for binding tariff information and the right to be heard before adverse decisions (see Recitals (2), (5), (10) and (11)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cyber-resilience-act-2024-2847-product-security-requirements",
    "title": "EU Cyber Resilience Act (CRA) 2024/2847 - Cybersecurity Requirements for Products with Digital Elements and Vulnerability Handling",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Regulation (EU) 2024/2847 establishes mandatory cybersecurity requirements for hardware and software products with digital elements placed on the EU market. Manufacturers must implement security by design, default secure configurations, vulnerability handling processes, and report actively exploited vulnerabilities to ENISA and national CSIRTs within 24 hours. CE marking required. Fines up to EUR 15M or 2.5% of worldwide turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-directive-2022-2555-cybersecurity-essential-entities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cyber-resilience-act-2024-3194-product-security-requirements",
    "title": "EU Cyber Resilience Act 2024/3194 - Cybersecurity Requirements for Products with Digital Elements",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "Regulation (EU) 2024/3194 (Cyber Resilience Act, CRA) establishes mandatory cybersecurity requirements for all products with digital elements (PDEs) placed on the EU market. Manufacturers must implement security-by-design, patch vulnerabilities within specified timeframes, and provide security support for the expected product lifetime or a minimum 5-year period. Critical products face conformity assessment requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-product-liability-directive-2024-2853"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cyber-resilience-act-2024-connected-products",
    "title": "Regulation (EU) 2024/2847 of the European Parliament and of the Council on the Cyber Resilience of Connected Products",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Cyber Resilience Act 2024 requires connected product manufacturers to ensure security by design, disclose vulnerabilities, and report incidents to ENISA within 24 hours, as outlined in Article 17. This regulation applies to all connected product manufacturers placing products on the EU market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5g-cybersecurity-toolbox-2020",
      "eu-eidas-trust-services-telecoms-910-2014",
      "eu-net-neutrality-open-internet-2015-2120"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cyber-resilience-act-2024-essential-requirements",
    "title": "Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "The EU Cyber Resilience Act (CRA) mandates that manufacturers of hardware and software products ensure cybersecurity by design and default, manage vulnerabilities throughout the product lifecycle, and provide security support for a defined period. Compliance, demonstrated via CE marking, is based on the essential security and vulnerability handling requirements detailed in Annex I of the regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nis2-supply-chain-security-article-22",
      "eu-cybersecurity-act-2019",
      "iso-27001-2022",
      "pci-dss-v4-requirement-6"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cyber-resilience-act-2024-iot-products",
    "title": "Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Cyber Resilience Act 2024 establishes mandatory cybersecurity requirements for all IoT products with digital elements placed on the EU market, requiring manufacturers to implement security by design, vulnerability handling processes, and CE marking compliance. Key obligations are defined in Article 6 (security by design), Article 7 (vulnerability handling), and Article 10 (conformity assessment).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "etsi-en-303-645-iot-cybersecurity-2020",
      "eu-data-act-2023-iot-data-sharing-obligations",
      "eu-critical-entities-resilience-directive-2022",
      "eu-batteries-regulation-2023-1542-iot-storage"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cyber-resilience-act-article-10-obligations-of-manufacturers",
    "title": "Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements - Article 10: Enhancing skills in a cyber resilient digital environment",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires Member States to promote measures and strategies for developing cybersecurity skills and increasing collaboration with the private sector, including manufacturers, to support the implementation of the regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cyber-resilience-act-article-11-vulnerability-handling",
    "title": "Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements - Article 11: General product safety",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that for products with digital elements, specific chapters of the General Product Safety Regulation (EU) 2023/988 apply to safety risks not covered by the Cyber Resilience Act, provided no other specific Union harmonisation legislation already addresses those risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cyber-resilience-act-article-13-reporting-obligations",
    "title": "REGULATION (EU) 2024/2847 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) - Article 13",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article's specific obligations cannot be determined as the provided regulatory text does not contain the text of Article 13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cyber-resilience-act-article-14-incident-vulnerability-reporting",
    "title": "REGULATION (EU) 2024/2847 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) - Article 14",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This regulation establishes a uniform legal framework for essential cybersecurity requirements for products with digital elements placed on the Union market to address widespread vulnerabilities and improve security throughout a product's lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cyber-resilience-act-article-17-conformity-assessment",
    "title": "REGULATION (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements - Article 17: Obligations of importers",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires importers to ensure that products with digital elements placed on the EU market comply with essential cybersecurity requirements, including verifying manufacturer conformity assessments, providing their contact details, and taking corrective action for non-compliant products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cyber-resilience-act-article-19-ce-marking",
    "title": "Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements, Article 19: CE marking",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that manufacturers affix the CE marking to products with digital elements to indicate their conformity with the essential cybersecurity requirements of this Regulation before they are placed on the market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cyber-resilience-act-article-33-additional-technical-requirements",
    "title": "REGULATION (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) - Article 33",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes additional technical requirements for manufacturers of products with digital elements to ensure a higher level of cybersecurity throughout the product lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cyber-resilience-act-article-40-market-surveillance-and-enforcement",
    "title": "Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act) - Article 40: Market Surveillance and Enforcement",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the framework for market surveillance authorities to monitor and enforce compliance with the cybersecurity requirements for products with digital elements placed on the Union market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cyber-resilience-act-article-6-essential-cybersecurity-requirements",
    "title": "Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements - Article 6: Requirements for products with digital elements",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Products with digital elements can only be placed on the market if both the products and the manufacturer's processes meet the essential cybersecurity requirements detailed in Annex I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cyber-resilience-act-iot-2024-products",
    "title": "Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes mandatory cybersecurity requirements for all products with digital elements placed on the EU market, requiring manufacturers to ensure secure design, vulnerability handling, and timely security updates throughout the product lifecycle, as per Article 5 and Article 8. It applies to all hardware and software products with digital components, including industrial IoT devices used in energy and critical infrastructure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "etsi-en-303-645-iot-cybersecurity-2020",
      "eu-radio-equipment-directive-2014-53-iot",
      "iec-61131-3-programmable-logic-controllers",
      "iec-60870-telecontrol-scada-protocols"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cyber-resilience-act-regulation-2024-2847",
    "title": "EU Cyber Resilience Act Regulation 2024/2847 - Horizontal Cybersecurity Requirements for Products with Digital Elements, In Force 10 December 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "Manufacturers, importers, and distributors placing products with digital elements (PDEs) on the EU market must comply with Regulation (EU) 2024/2847 (Cyber Resilience Act), which entered into force on 10 December 2024, by meeting the essential cybersecurity requirements set out in Annex I, performing conformity assessment under one of the procedures in Annex VIII, drawing up EU technical documentation per Annex VII, applying the CE marking, providing the user information required in Annex II, and complying with the vulnerability handling and incident notification duties to ENISA and national CSIRTs, with the main obligations becoming applicable on 11 December 2027 (Article 71(2)) and the reporting obligations under Article 14 applicable from 11 September 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-directive-2022-2555"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cyber-solidarity-act-2024",
    "title": "Regulation (EU) 2025/38 of the European Parliament and of the Council of 19 December 2024 laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents (EU Cyber Solidarity Act)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "This regulation establishes a European Cyber Shield and a Cyber Emergency Mechanism to enhance the EU's collective ability to detect, prepare for, and respond to significant cybersecurity threats. It mandates the deployment of a network of Security Operations Centres (SOCs) and creates a Cyber Reserve of trusted private providers to support Member States during major incidents, as outlined in Articles 3 and 13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cyber-solidarity-act-regulation-2025-38",
    "title": "EU Cyber Solidarity Act Regulation 2025/38 - European Cybersecurity Alert System, Emergency Mechanism, and Incident Review",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "EU Member States, national and cross-border Security Operations Centres (Cyber Hubs), critical infrastructure operators, trusted cybersecurity service providers, and ENISA must operate under Regulation (EU) 2025/38, the Cyber Solidarity Act (adopted 19 December 2024, published in the Official Journal on 15 January 2025, in force 4 February 2025), which establishes a European cyber shield of National and Cross-Border Cyber Hubs using AI and data analytics to detect and share warnings on threats across borders, a Cybersecurity Emergency Mechanism that supports preparedness, response, and mutual assistance among Member States including a European cybersecurity reserve of trusted providers, and a Cybersecurity Incident Review Mechanism under which ENISA reviews significant or large-scale cybersecurity incidents and delivers a report with lessons learned and recommendations to improve Union cyber response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-directive-2022-2555"
    ],
    "primary_citations_count": 3
  },
  {
    "node_id": "eu-cybersecurity-act-2019",
    "title": "Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This regulation establishes a permanent mandate for ENISA, the EU Agency for Cybersecurity, and creates a voluntary, EU-wide cybersecurity certification framework for ICT products, services, and processes as outlined in Title III. The framework aims to harmonize certification schemes across Member States to enhance trust and security in the Digital Single Market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0",
      "c-scrm-practices-systems-organizations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cybersecurity-act-2019-881",
    "title": "EU Cybersecurity Act 2019/881",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-06-07",
    "bluf": "Regulation (EU) 2019/881 gives ENISA a permanent mandate and establishes the EU cybersecurity certification framework, creating voluntary (and progressively mandatory) EU certification schemes at three assurance levels (basic, substantial, high) for ICT products, services, and processes, with the EUCC scheme for ICT hardware and software as the first adopted candidate scheme.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-nis2-directive-2022-2555",
        "eu-eidas-regulation-2014-910",
        "eu-general-product-safety-regulation-2023-988"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-directive-2022-2555",
      "eu-eidas-regulation-2014-910",
      "eu-general-product-safety-regulation-2023-988"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cybersecurity-act-article-2-definitions",
    "title": "Regulation (EU) 2019/881 on ENISA (the European Union Agency for Cybersecurity) and on information and communication technology cybersecurity certification - Article 2",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the official definitions for key terms such as 'conformity assessment', 'assurance level', and 'technical specification' that must be used when interpreting and applying the EU Cybersecurity Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cybersecurity-act-article-4-mandate-of-enisa",
    "title": "Regulation (EU) 2019/881 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification (Cybersecurity Act) - Article 4: Objectives",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the core objectives for ENISA, mandating it to act as the EU's center of expertise on cybersecurity, assist in policy implementation, support capacity-building, promote cooperation and awareness, and contribute to the European cybersecurity certification framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cybersecurity-act-article-46-european-cybersecurity-certification-framework",
    "title": "Regulation (EU) 2019/881 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification (Cybersecurity Act) - Article 46: European cybersecurity certification framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the European cybersecurity certification framework to provide a mechanism for creating harmonised certification schemes that attest ICT products, services, and processes comply with specified security requirements throughout their lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cybersecurity-act-article-47-national-cybersecurity-certification-authorities",
    "title": "Regulation (EU) 2019/881 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification (Cybersecurity Act) - Article 47",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article obligates the European Commission to publish and regularly update a Union rolling work programme that identifies strategic priorities and a list of ICT products, services, and processes for future European cybersecurity certification schemes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cybersecurity-act-article-49-european-cybersecurity-certification-scheme",
    "title": "Regulation (EU) 2019/881 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification - Article 49: Preparation, adoption and review of a European cybersecurity certification scheme",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article outlines the process for the European Union Agency for Cybersecurity (ENISA) to prepare, and for the Commission to adopt, European cybersecurity certification schemes, including mandatory requirements for stakeholder consultation, cooperation with the ECCG, and periodic review.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cybersecurity-act-article-51-issuance-of-certificates",
    "title": "Regulation (EU) 2019/881 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification (Cybersecurity Act) - Article 51",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that European cybersecurity certification schemes must be designed to achieve specific security objectives, including data protection, access control, vulnerability management, and security by design.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cybersecurity-act-article-54-vendor-self-assessment",
    "title": "Regulation (EU) 2019/881 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification (Cybersecurity Act) - Article 58(7)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Article 58(7) of Regulation (EU) 2019/881 mandates national cybersecurity certification authorities to monitor and enforce compliance for ICT products, services, and processes, particularly for those carrying out conformity self-assessment, and to manage complaints and the authorisation of conformity assessment bodies. (Article 54, by contrast, sets out the minimum elements of European cybersecurity certification schemes.)",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cybersecurity-act-article-55-vulnerability-disclosure",
    "title": "EU Cybersecurity Act (Regulation (EU) 2019/881) - Article 55: Supplementary cybersecurity information for certified ICT products, ICT services and ICT processes",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Manufacturers or providers of certified ICT products, services, or processes must publicly provide supplementary cybersecurity information, including secure usage guidance, support periods, vulnerability reporting contacts, and links to vulnerability repositories.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-cybersecurity-act-article-56-assurance-levels",
    "title": "Regulation (EU) 2019/881 on ENISA and on information and communications technology cybersecurity certification (Cybersecurity Act) - Article 56",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the obligations for national cybersecurity certification authorities, including supervising scheme compliance, monitoring manufacturers, assisting accreditation bodies, authorizing conformity assessment bodies, and handling complaints.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cybersecurity-act-article-58-ncca-tasks",
    "title": "Regulation (EU) 2019/881 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) - Article 58: Tasks of the national cybersecurity certification authorities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article outlines the mandatory tasks and powers of national cybersecurity certification authorities (NCCAs), including supervising certification schemes, enforcing compliance, handling complaints, and cooperating with other authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-cybersecurity-act-article-65-penalties",
    "title": "REGULATION (EU) 2019/881 (Cybersecurity Act) Article 65 - Penalties",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Member States must establish and notify the Commission of effective, proportionate, and dissuasive penalties for infringements related to ICT cybersecurity certification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cybersecurity-act-article-9-enisa-tasks-cybersecurity-certification",
    "title": "Regulation (EU) 2019/881 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification - Article 9: Knowledge and information",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "ENISA is required to perform strategic analyses of threats and technologies, provide guidance and best practices, and make cybersecurity information publicly available through a dedicated portal to support citizens, organizations, and businesses across the Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-cybersecurity-act-enisa-certification-framework",
    "title": "EU Cybersecurity Act - ENISA Certification Schemes: EUCS (Cloud), EUCC (Common Criteria) and Candidate Scheme Development Process",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-10-27",
    "bluf": "The EU Cybersecurity Act (Regulation (EU) 2019/881) establishes a voluntary, EU-wide cybersecurity certification framework for ICT products, services, and processes. Under Title III, Articles 46-56, ENISA is mandated to develop and maintain specific certification schemes, such as the EUCS for cloud services and EUCC for ICT products, to harmonize security standards and enhance trust across the EU Digital Single Market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cybersecurity-act-2019",
      "iso-27001-2022",
      "iso-27017-cloud-security-2015"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dac-7-platform-economy-reporting-2021-514",
    "title": "Council Directive (EU) 2021/514 of 22 March 2021 amending Directive 2011/16/EU as regards mandatory automatic exchange of information in the field of taxation in relation to reportable digital platform transactions",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Digital platform operators must report annual information on sellers engaged in immovable property rentals, personal services, sale of goods, and vehicle rentals to tax authorities under Article 10a of DAC7. This data is automatically exchanged among EU Member States by 31 January each year following the reporting period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac2-automatic-exchange-financial-info",
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-dac7-digital-platform-reporting-2021-514"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dac2-automatic-exchange-financial-info",
    "title": "Council Directive 2014/107/EU of 9 December 2014 amending Directive 2011/16/EU as regards mandatory automatic exchange of information in the field of taxation",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Directive mandates EU Member States to automatically exchange information on financial accounts held by tax residents of other Member States, based on the OECD Common Reporting Standard (CRS). It requires Financial Institutions to perform due diligence and report account information under Article 8 of Directive 2011/16/EU, as amended.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-hallmarks-2020",
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dac6-mandatory-disclosure-2018",
    "title": "Council Directive (EU) 2018/822 (DAC6) - Mandatory Disclosure of Reportable Cross-Border Tax Arrangements: Hallmark Categories A-E, 30-Day Reporting Window, Intermediary and Taxpayer Obligations, Main Benefit Test and Automatic Competent Authority Exchange",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Intermediaries (advisers, banks, accountants) who design, market, organise, or implement cross-border arrangements with at least one hallmark indicating potential tax avoidance must report to their Member State competent authority within 30 days; hallmarks A-C require the Main Benefit Test (MBT) to be satisfied before reporting is triggered; hallmarks D (CRS circumvention) and E (transfer pricing) are reportable per se without MBT; taxpayers self-report where no intermediary exists or where intermediary claims legal privilege; Member States exchange reported information automatically via OECD Common Transmission Network on a quarterly basis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "DAC1",
        "OECD_BEPS",
        "EU_PILLAR_TWO",
        "CRS"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-cbcr-guidance-2023-update"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-dac6-mandatory-disclosure-2018-822",
    "title": "Council Directive (EU) 2018/822 (DAC6) - Mandatory Disclosure of Cross-Border Tax Arrangements: Hallmarks A-E, Intermediary and Taxpayer Reporting, 30-Day Reporting Deadline, Automatic Exchange Between EU Member States and 50% EBIT Threshold for Hallmark E Transfer Pricing Arrangements",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Council Directive (EU) 2018/822 of 25 May 2018 (DAC6) amends Directive 2011/16/EU to require mandatory disclosure to national tax authorities of potentially aggressive cross-border tax arrangements; primary reporting obligation falls on intermediaries (advisors, promoters, banks, accountants, lawyers) who must report within 30 days of the arrangement being made available, implemented, or being ready for implementation; where professional privilege applies or no intermediary is in scope, the reporting obligation shifts to the relevant taxpayer; reportable arrangements are identified by Hallmarks A through E, some of which require a main benefit test (MBT) - that obtaining a tax advantage is the main benefit or one of the main benefits; automatic exchange of information between all EU Member States occurs through the Common Communication Network within 30 days of the filing deadline; EU member states were required to transpose DAC6 by 31 December 2019 with reporting applicable from 1 July 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "OECD_BEPS_ACTION_12",
        "PILLAR_TWO",
        "DAC7",
        "OECD_CRS"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-pillar-two-global-minimum-tax",
      "oecd-transfer-pricing-guidelines-2022",
      "eu-anti-tax-avoidance-directive-atad-1-2016-1164"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dac6-mandatory-disclosure-cross-border",
    "title": "Council Directive (EU) 2018/822 of 25 May 2018 amending Directive 2011/16/EU as regards mandatory automatic exchange of information in the field of taxation in relation to reportable cross-border arrangements",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Directive requires intermediaries and, in certain cases, taxpayers to report cross-border arrangements that meet one or more of the hallmarks listed in Article 4 within 30 days of the arrangement being made available for implementation, implemented, or made available. It applies to intermediaries and taxpayers involved in reportable cross-border arrangements as defined in Article 4 and Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-atad2-hybrid-mismatches-2017-952",
      "eu-dac7-digital-platform-reporting-2021-514"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dac6-mandatory-disclosure-hallmarks-2020",
    "title": "Council Directive (EU) 2018/822 (DAC6) on mandatory automatic exchange of information in the field of taxation in relation to reportable cross-border arrangements",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This directive, known as DAC6, requires EU intermediaries (e.g., tax advisors, lawyers, banks) or, in some cases, the relevant taxpayer, to report potentially aggressive cross-border tax planning arrangements to their national tax authorities. An arrangement is reportable if it meets one or more of the specific 'hallmarks' listed in Annex IV of the Directive, with a strict 30-day reporting deadline from when the arrangement is made available for implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015",
      "un-model-double-taxation-convention-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dac6-mandatory-disclosure-hallmarks-compliance",
    "title": "EU DAC6 Mandatory Disclosure Regulation 2018/822 - Hallmarks, Intermediary Obligations, and Cross-Border Reporting",
    "domain": "Tax & Transfer Pricing",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Council Directive 2018/822 (DAC6) requires intermediaries (primarily tax advisors, accountants, lawyers, and financial institutions) to report cross-border tax arrangements that meet one or more of the defined hallmarks to their home member state tax authority within 30 days of the arrangement becoming available. The arrangement information is automatically exchanged between all EU member state tax authorities via the Common Communication Network. Category D hallmarks (arrangements undermining reporting obligations) require disclosure regardless of the main benefit test. Legal professional privilege may exempt certain categories of lawyer-intermediary from direct reporting; in such cases the reporting obligation shifts to the taxpayer. Reports are submitted via the national tax authority's reporting portal; first-mover intermediaries must report retrospective arrangements from 25 June 2018.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018-822",
      "oecd-beps-action-12-mandatory-disclosure-rules"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-dac7-digital-platform-reporting-2021-514",
    "title": "Council Directive (EU) 2021/514 of 22 March 2021 amending Directive 2011/16/EU on administrative cooperation in the field of taxation (DAC7)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "EU Directive 2021/514 (DAC7) requires digital platform operators to collect, verify, and report information on income earned by sellers for relevant activities to EU Member State tax authorities. This obligation, detailed in the amended Directive 2011/16/EU, Section IIA, Article 8ac, aims to increase tax transparency and ensure sellers pay their fair share of tax.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gdpr-binding-corporate-rules",
      "oecd-beps-action-3-cfc-rules-2015"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-dac7-platform-economy-reporting-2021",
    "title": "Council Directive (EU) 2021/514 of 22 March 2021 amending Directive 2011/16/EU as regards mandatory automatic exchange of information in the field of taxation in relation to reportable digital platform transactions",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "DAC7 requires digital platform operators to conduct due diligence on sellers providing accommodation, personal services, goods, or vehicle rentals via their platforms, report seller income annually to tax authorities, and automatically exchange this data across EU Member States. Applies to all platform operators facilitating such transactions, regardless of location, under Article 8a and Article 10a of Directive 2011/16/EU as amended.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-dac6-mandatory-disclosure-hallmarks-2020",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two",
      "eu-dac8-crypto-asset-tax-reporting-2023-2226"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dac7-platform-economy-reporting-2021-514",
    "title": "Council Directive (EU) 2021/514 of 22 March 2021 amending Directive 2011/16/EU on administrative cooperation in the field of taxation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Requires digital platform operators to collect, verify, and report information on income earned by sellers for relevant activities to EU Member State tax authorities for automatic exchange. Key due diligence and reporting obligations are specified in Annex V, Sections I and II.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dac8-crypto-asset-tax-reporting-2023-2226",
    "title": "Council Directive (EU) 2023/2226 of 17 October 2023 amending Directive 2011/16/EU on administrative cooperation in the field of taxation (DAC8)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive (EU) 2023/2226 (DAC8) mandates that Crypto-Asset Service Providers (CASPs) and Crypto-Asset Operators in the EU must perform due diligence on their users and report transactional data concerning crypto-assets, e-money, and CBDCs to the tax authorities of EU Member States, effective from January 1, 2026, as specified in the amended Directive 2011/16/EU, Article 8ac and Annex V.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gdpr-binding-corporate-rules"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-damages-directive-2014-104-private-enforcement",
    "title": "Directive 2014/104/EU of the European Parliament and of the Council of 26 November 2014 on certain rules governing actions for damages under national law for infringements of the competition law provisions of the Member States and of the European Union",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This Directive establishes a harmonized framework across EU Member States for private enforcement of competition law, requiring national courts to ensure full compensation for harm caused by infringements of EU or national competition rules under Article 101 or 102 TFEU. It mandates rules on evidence disclosure, joint and several liability, limitation periods, and protection for leniency applicants under Article 5 and Article 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "uk-competition-act-1998-chapter-1-2-prohibitions",
      "india-competition-act-2002-sections-3-4",
      "oecd-recommendation-hard-core-cartels-2019",
      "icn-recommended-practices-merger-notification-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-act-2023",
    "title": "Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2024-09-12",
    "bluf": "The EU Data Act requires manufacturers of connected products and providers of related services to make product- and service-generated data accessible to users and designated third parties under fair, reasonable, and non-discriminatory terms (Chapter II, Article 4). It also establishes rules to facilitate switching between cloud and other data processing services, mandating the removal of commercial, technical, and organisational obstacles (Chapter VI, Article 23).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27017-cloud-controls",
      "iso-27018-pii-cloud",
      "soc2-availability-criteria",
      "soc2-confidentiality-crit"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-data-act-2023-1257-data-sharing-iot-switching",
    "title": "EU Data Act 2023/2854 - IoT Data Sharing, Cloud Switching Rights, and B2B Data Access",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Regulation (EU) 2023/2854 (Data Act, applicable from September 2025) establishes rules for data generated by connected products (IoT) and related services: users have a right to access and share their data with third parties, cloud service customers have a right to switch providers without disproportionate cost, prohibits unfair B2B data sharing contract terms, requires cloud service providers to implement minimum technical interoperability, and mandates data access for public bodies in exceptional need.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-data-governance-act-2022-868-intermediation-services"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-act-2023-2854",
    "title": "EU Data Act Regulation 2023/2854 data sharing cloud switching and public sector access",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-16",
    "bluf": "Regulation EU 2023/2854 of the European Parliament and of the Council on harmonised rules on fair access to and use of data, known as the Data Act. Published on 22 December 2023, it applies from 12 September 2025. Chapter II establishes rights for users of connected products to access and share data generated by such products. Chapter III requires business-to-business data sharing on fair, reasonable, and non-discriminatory (FRAND) terms. Chapter IV addresses unfair contractual terms in B2B data contracts. Chapter V provides for public sector bodies to access data held by private entities in exceptional necessity. Chapter VI mandates cloud switching rights, requiring providers to eliminate switching charges by 12 January 2027, and imposes interoperability obligations for data processing services. Chapter VII protects non-personal data from unlawful third-country government access. Penalties align with GDPR levels, up to EUR 20 million or 4% of total annual worldwide turnover, whichever is higher. Enforcement rests with designated national competent authorities and the European Commission DG CONNECT.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-data-act-2023-2854-cloud-switching-data-sharing",
    "title": "EU Data Act 2023/2854 - Cloud Switching, Data Sharing and Smart Contracts",
    "domain": "Cloud & SaaS",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Regulation (EU) 2023/2854 (Data Act) creates rights to share and access data generated by connected products and services; establishes cloud switching portability requirements with maximum 30-day notice and maximum 3-month switching period; prohibits switching fees from September 2027 and standardised exit obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-data-act-2023-2854-machine-generated-data",
    "title": "Regulation (EU) 2023/2854 of the European Parliament and of the Council of 14 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2019/770",
    "domain": "Cloud & SaaS",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Data Act establishes rights and obligations regarding access to and use of machine-generated data, particularly in business-to-business (B2B) and business-to-government (B2G) contexts. It applies to manufacturers, providers of data processing services, and public sector bodies, with key provisions including data sharing obligations, cloud switching rights, and safeguards for trade secrets under Article 11 and Article 15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-automated-decision-workflows",
      "eu-nis2-directive-workflow-critical-operations",
      "azure-logic-apps-enterprise-integration"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-act-2023-ai-system-implications",
    "title": "EU Data Act (Regulation 2023/2854) - Data Access and Sharing Obligations for AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU Regulation 2023/2854 on harmonised rules on fair access to and use of data (the Data Act), which applied from 12 September 2025, establishes data access and sharing obligations with significant implications for AI systems - it grants users of connected products and related services the right to access data generated by their use, including data generated by AI-enabled connected products; requires data holders (including AI system providers) to share data with third parties upon user request under fair, reasonable, and non-discriminatory (FRAND) terms; restricts the use of trade secrets as barriers to mandatory data sharing; and establishes contractual fairness requirements for data sharing agreements; the Data Act intersects with the EU AI Act where AI systems are embedded in connected products (data generation, training data access) and where AI-generated data from shared datasets is used to train or improve AI models.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-data-act-2023-ai-system-implications.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-annex-ii-union-harmonisation-legislation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-act-2023-article-11-switching-process-requirements",
    "title": "Regulation (EU) 2023/2854 (Data Act) - Article 11: Unfair terms concerning access to and use of data between enterprises",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article renders non-binding any unfair contractual term unilaterally imposed by one enterprise on another concerning data access and use, and establishes specific conditions under which a term is considered or presumed to be unfair.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-data-act-2023-article-17-data-altruism-public-interest",
    "title": "REGULATION (EU) 2023/2854 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act) - Article 17",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must make non-personal data available to public sector bodies or Union institutions upon a justified request demonstrating an exceptional need for performing a task in the public interest.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-data-act-2023-article-21-unfair-contractual-terms-data-sharing",
    "title": "REGULATION (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act) - Article 21",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article renders unilaterally imposed, unfair contractual terms related to data access and use between enterprises non-binding, particularly those that grossly deviate from good commercial practice or unfairly limit liability and remedies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-data-act-2023-article-8-technical-protection-measures-data",
    "title": "Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act) - Article 8: Conditions under which data holders make data available to data recipients",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "In business-to-business relations, data holders obligated to share data must establish arrangements with data recipients under fair, reasonable, non-discriminatory, and transparent terms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-act-2023-competition-data-access",
    "title": "Regulation (EU) 2023/2854 of the European Parliament and of the Council of 14 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2019/771 (Data Act)",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The EU Data Act 2023 establishes mandatory data-sharing obligations for manufacturers and service providers of IoT-connected products and related services, requiring them to provide users and third parties with access to usage data under fair, transparent, and non-discriminatory terms. It applies to all providers of smart devices and data holders in the EU, with key obligations under Article 7 (user access), Article 8 (B2B data sharing), Article 10 (cloud switching), and Article 13 (public sector access).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "uk-cma-merger-assessment-guidelines-2021",
      "india-competition-act-2002-sections-3-4",
      "canada-competition-act-2024-amendment-abuse-dominance",
      "oecd-competition-digital-economy-roundtable-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-act-2023-iot-data-sharing",
    "title": "Regulation (EU) 2023/2854 of the European Parliament and of the Council of 14 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2019/771 (Data Act)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The EU Data Act 2023 grants users of connected products and related services the right to access data generated by their use, requires manufacturers to enable secure data sharing with third parties upon user request, and imposes obligations on cloud providers to facilitate switching. Key obligations are defined in Articles 3, 4, 10, 11, and 16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-nis2-telecoms-essential-services",
      "eu-eidas-trust-services-telecoms-910-2014",
      "eu-data-act-2023-competition-data-access"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-act-2023-iot-data-sharing-obligations",
    "title": "Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act)",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Data Act 2023 grants users of connected products the right to access and share data generated by their use, imposes fair, reasonable, and non-discriminatory (FRAND) data sharing obligations on data holders, and enables switching between data processing services. Key obligations are defined in Article 3 (user access), Article 4 (B2B data sharing), and Article 6 (switching rights).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "etsi-en-303-645-iot-cybersecurity-2020",
      "eu-radio-equipment-directive-2014-53-iot",
      "iec-61131-3-programmable-logic-controllers",
      "amqp-iso-iec-19464-messaging-iot"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-act-2023-regulation-2854",
    "title": "Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The EU Data Act 2023 establishes harmonised rules for fair access to and use of data generated by connected devices, requiring manufacturers and service providers to enable users to access and share data under fair, transparent, and non-discriminatory conditions. It applies to manufacturers, providers of data processing services, and public sector bodies requesting data under Article 11, with key obligations in Articles 3, 10, 11, 13, and 17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cloud-rulebook-2021-swipo-portability",
      "csa-ccm-v4-cloud-controls",
      "enisa-cloud-security-guidelines-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-act-article-12-switching-cloud-service-providers",
    "title": "Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act) - Article 12",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article mandates that providers of data processing services must remove commercial, technical, and contractual obstacles to allow customers to effectively switch to another provider.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-data-act-article-13-portability-of-data",
    "title": "REGULATION (EU) 2023/2854 (Data Act) Article 13: Unfair contractual terms unilaterally imposed on an SME",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article renders unfair contractual terms non-binding when they are unilaterally imposed by an enterprise on a small or medium-sized enterprise (SME) concerning data access, use, liability, or termination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-data-act-article-20-international-access-transfers",
    "title": "REGULATION (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act) - Article 20: International and third-country governmental access and transfer",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Data processing services must implement measures to prevent international governmental access to or transfer of non-personal data held in the Union that would conflict with EU or Member State law, unless specific legal conditions are met.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-act-article-3-right-to-access-data-from-connected-products",
    "title": "Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act) - Article 3: Right of the user to access and use data generated by the use of a connected product or related service",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes that entities defined as gatekeepers under Regulation (EU) 2022/1925 are prohibited from soliciting or commercially incentivizing users to provide data that those users have accessed from connected products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-act-article-4-obligation-to-make-data-available-third-parties",
    "title": "Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act) - Article 4",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes obligations for data holders and third parties regarding data access requests, including prohibitions on coercive tactics and data misuse, and requirements for data minimization and legal bases for personal data processing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-data-act-article-5-conditions-for-data-sharing",
    "title": "Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act) - Article 5",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article obligates data holders to make a user's personal data available to the user or a designated third party upon the user's request, for data already processed under a valid legal basis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-act-article-6-compensation-for-data-sharing",
    "title": "Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act) - Article 6: Obligations of third parties receiving data at the request of the user",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes strict obligations and prohibitions for third parties that receive data at a user's request, including purpose limitation, data erasure, and restrictions on sharing or using the data for anti-competitive purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-data-act-article-9-obligations-for-data-holders",
    "title": "Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act) - Article 9",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires data holders to ensure any compensation for making data available is reasonable, non-discriminatory, and calculated based on specific costs and investments, with special provisions for SMEs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-act-regulation-2023-2854",
    "title": "EU Data Act Regulation 2023/2854 - IoT Data Access, Business-to-Business Fairness, and Cloud Switching Rights, Applicable 12 September 2025",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Manufacturers of connected products and providers of related digital services placed on the EU market, plus IaaS, PaaS, and SaaS providers, must comply with the EU Data Act (Regulation (EU) 2023/2854) which entered into force on 11 January 2024 and applies from 12 September 2025 (with enhanced interoperability requirements for cloud services from 12 September 2026 and full data portability standards from 12 September 2027), by ensuring users (consumers and businesses) can access usage data generated by connected products and related services such as smart home products, connected vehicles, and industrial equipment, making data available to users and to third parties designated by the user, reassessing data processing service agreements in light of new switching rights (with most switching-related charges such as fees for data transfer or reformatting to be phased out entirely from January 2027 except in limited multicloud scenarios), with enforcement by national authorities ranging from warnings and compliance orders to administrative fines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-data-border-transfers-schrems-ii",
    "title": "Judgment of the Court (Grand Chamber) of 16 July 2020, Data Protection Commissioner v Facebook Ireland Limited and Maximillian Schrems, Case C-311/18 (Schrems II)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Court of Justice of the European Union (CJEU) invalidated the EU-US Privacy Shield framework for transatlantic data transfers, finding it did not provide adequate protection from US surveillance laws. The judgment upheld the validity of Standard Contractual Clauses (SCCs) but mandated that data exporters must conduct a case-by-case Transfer Impact Assessment (TIA) to verify that the recipient country's laws provide a level of data protection essentially equivalent to that in the EU, and implement supplementary measures if necessary (Paragraphs 134, 203).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-adequacy-decisions-article-45",
      "eu-standard-contractual-clauses-2021",
      "eu-gdpr-binding-corporate-rules",
      "us-cloud-act-2018",
      "eu-us-dpf-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-data-governance-act-2022",
    "title": "Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance and amending Regulation (EU) 2018/1724 (Data Governance Act)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The EU Data Governance Act (DGA) establishes a framework to increase data availability by regulating the reuse of public sector data, creating a new business category of neutral data intermediation services, and promoting data altruism. It applies to public sector bodies, data intermediation providers, and data altruism organizations operating within the EU, as detailed in Chapters II, III, and IV.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27017-cloud-controls",
      "iso-27018-pii-cloud",
      "gdpr-health-data",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-data-governance-act-2022-868",
    "title": "EU Data Governance Act 2022/868 - Data Intermediation Services, Data Altruism, and Public Sector Data Re-use",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Regulation (EU) 2022/868 of the European Parliament and of the Council on European data governance (Data Governance Act, DGA) became applicable on 24 September 2023. The DGA establishes a framework for the re-use of certain categories of public sector data, the notification and supervision of data intermediation service providers, and the registration of recognised data altruism organisations. Article 3 sets out the conditions for re-use of protected public sector data including personal data subject to GDPR protections, commercially confidential data, and data protected by intellectual property rights. Article 10 requires providers of data intermediation services (which include data marketplaces, data brokers, and data spaces) to submit a notification to the competent authority before commencing operations. Article 11 specifies the requirements for data intermediation service providers including an obligation of neutrality, a prohibition on using data for commercial purposes beyond providing the intermediation service, and organisational separation between data intermediation and other commercial activities. Articles 16 to 22 establish the regime for recognised data altruism organisations, which are entities that collect and share data for general interest purposes on a not-for-profit basis. Article 23 establishes the European Data Innovation Board (EDIB). The European Data Innovation Board coordinates across Member States on cross-border data spaces, common data standards, and the interoperability of data intermediation services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_gdpr_2016_679",
        "eu_open_data_directive_2019_1024",
        "eu_data_act_2023_2854",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electronic-communications-code-2018-1972",
      "eu-services-directive-2006-123",
      "eu-ecn-plus-directive-2019-nca-powers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-data-governance-act-2022-868-data-sharing",
    "title": "Regulation (EU) 2022/868 on European data governance, and amending Regulation (EU) 2018/1724 and Directive 94/46/EC",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Data Governance Act establishes a framework for facilitating data sharing across sectors and Member States, including through data intermediation services and data altruism organizations. It applies to public sector bodies, private entities offering data sharing services, and organizations enabling voluntary data donation, with key obligations under Article 8 for data intermediaries and Article 12 for data altruism.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-automated-decision-workflows",
      "eu-nis2-directive-workflow-critical-operations",
      "azure-logic-apps-enterprise-integration"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-governance-act-2022-868-intermediation-services",
    "title": "EU Data Governance Act (DGA) 2022/868 - Data Intermediation Services, Data Altruism, and Public Sector Data Reuse",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Regulation (EU) 2022/868 (Data Governance Act) creates a regulatory framework for data intermediation services (trusted third-party data brokers), establishes data altruism organisations (not-for-profit collective data sharing), and facilitates reuse of public sector data protected by confidentiality, IP, or privacy constraints. Data intermediaries must notify national competent authorities and operate under strict neutrality obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-data-governance-act-2022-cloud-data-sharing",
    "title": "Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance and amending Regulation (EU) 2018/1724 (Data Governance Act)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The EU Data Governance Act 2022 establishes a framework for cloud-based data intermediaries to facilitate secure, neutral, and transparent data sharing across sectors, requiring registration with national authorities and strict neutrality obligations under Article 8. It applies to providers of cloud data sharing services operating in the EU that enable data exchange between data holders and data users.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-data-governance-act-2022",
      "eu-gdpr-cloud-data-processing",
      "csa-ccm-v4-cloud-controls",
      "eu-cloud-certification-scheme-eucs",
      "enisa-cloud-security-guidelines-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-debt-equity-bias-reduction-allowance-debra-2023",
    "title": "Proposal for a COUNCIL DIRECTIVE on laying down rules on a debt-equity bias reduction allowance and on limiting the deductibility of interest for corporate income tax purposes",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2024-05-11",
    "bluf": "This proposed EU directive aims to equalize the tax treatment of debt and equity financing by introducing a notional interest deduction on increases in equity (Article 4) and a new limitation on interest deductibility (Article 6) for corporate income taxpayers in EU Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015",
      "un-model-double-taxation-convention-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-decision-91-305-state-aid-belgium",
    "title": "Commission Decision 91/305/EEC - State Aid to Mactac SA",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "This Commission Decision addresses investment aid proposed by the Belgian Government for Mactac SA, a manufacturer of self-adhesive products. The European Commission assessed the aid under Article 93(2) (now Art 108 TFEU) to determine its compatibility with the common market. It establishes strict guidelines on regional aid, sectoral impact, and the distortion of competition. The decision reinforces the principle that state subsidies cannot be granted simply to modernize facilities or support general investments unless they serve a recognized regional development purpose or address a specific market failure without unduly affecting intra-community trade.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 3
  },
  {
    "node_id": "eu-decision-m1683-coca-cola-merger-control",
    "title": "Commission Decision (Case No IV/M.1683) - Coca-Cola/Kar-Tess Group Merger",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "This Commission Decision under the EU Merger Regulation evaluates the concentration involving the acquisition of Coca-Cola Beverages plc by Hellenic Bottling Company S.A. It applies strict antitrust scrutiny to ensure that the merger does not create or strengthen a dominant position that would significantly impede effective competition in the common market. The node establishes the procedural governance for notifying large-scale corporate concentrations, defining relevant product and geographic markets, and securing regulatory clearance prior to transaction consummation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 3
  },
  {
    "node_id": "eu-defense-industrial-strategy-2024-edip",
    "title": "European Defence Industrial Strategy (EDIS)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The European Defence Industrial Strategy (EDIS) sets a vision for European defence industrial policy until 2035, requiring Member States to strengthen the European Defence Technological and Industrial Base (EDTIB) through increased, collaborative investment and improved industry responsiveness. It applies to EU Member States, defence industry stakeholders, and entities involved in defence procurement and dual-use technology development.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-deforestation-regulation-2023",
    "title": "Regulation (EU) 2023/1115 of the European Parliament and of the Council of 31 May 2023 on the making available on the Union market and the export from the Union of certain commodities and products associated with deforestation and forest degradation and repealing Regulation (EU) No 995/2010",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2024-06-29",
    "bluf": "This regulation prohibits placing relevant commodities (cattle, cocoa, coffee, oil palm, rubber, soya, wood) and derived products on the EU market or exporting them unless they are deforestation-free, produced in accordance with the relevant legislation of the country of production, and covered by a due diligence statement. As per Article 3, operators must prove products did not originate from land deforested after December 31, 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "logistics-hs-classification",
      "gs1-epcis-transparency",
      "iso-28000-supply-chain",
      "supply-chain-risk-triage",
      "iso-26000-social-resp"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-deforestation-regulation-2023-1115",
    "title": "EU Deforestation Regulation (EU) 2023/1115 (EUDR)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Regulation 2023/1115 (EUDR) prohibits placing on the EU market or exporting from the EU certain commodities and products associated with deforestation or forest degradation after 31 December 2020. Covered commodities are cattle cocoa coffee oil palm rubber soya and wood and products derived from these commodities (e.g., chocolate furniture leather paper tyres). Operators and large traders must conduct due diligence including: (1) information gathering (legal harvest geolocation supplier identification); (2) risk assessment of deforestation and illegal harvest; (3) risk mitigation. Due diligence statements submitted via TRACES system before products placed on market. Application date amended to 30 December 2025 (large operators) and 30 June 2026 (SMEs) by Regulation 2024/3234.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eutr",
        "eu_cs3d",
        "cbam",
        "glasgow_decl",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-deforestation-regulation-2023-1115-article-3-prohibition-placing-market",
    "title": "EU Deforestation Regulation 2023/1115 - Article 3: Prohibition on Placing Relevant Commodities on the Market",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Regulation (EU) 2023/1115 Article 3 prohibits placing relevant commodities and products on the EU market or exporting them unless three cumulative conditions are met: the commodity is deforestation-free (reference cut-off 31 December 2020), produced in accordance with country-of-production legislation, and covered by a submitted due diligence statement. Prohibited acts apply equally to market placement and export.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csddd-directive-2024-1760-article-8-prevention-adverse-impacts",
      "eu-deforestation-regulation-2023-1115-article-8-due-diligence-operators"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-deforestation-regulation-2023-1115-article-8-due-diligence-operators",
    "title": "EU Deforestation Regulation 2023/1115 - Article 8: Due Diligence Obligations for Operators",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Regulation (EU) 2023/1115 Article 8 requires operators to establish and maintain a due diligence system with three sequential steps before market placement or export: information collection per Article 9 (geolocation, supplier details, volume), risk assessment per Article 10 (probability of non-compliance), and risk mitigation per Article 11 (audits, surveys, spot checks). Records must be retained for 5 years; systems reviewed at least annually.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-deforestation-regulation-2023-1115-article-3-prohibition-placing-market",
      "eu-csddd-directive-2024-1760-article-8-prevention-adverse-impacts"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-deforestation-regulation-2023-1115-supply-chain-due-diligence",
    "title": "EU Deforestation Regulation 2023/1115 - Zero-Deforestation Supply Chain Due Diligence for Commodities and Products",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Regulation (EU) 2023/1115 prohibits placing on the EU market (or exporting from it) products linked to deforestation or forest degradation after 31 December 2020. Operators and traders must perform due diligence covering geolocation of land, country legislation compliance, risk assessment, and mitigation. Fines up to 4% of EU annual turnover for violations. Applies to cattle, cocoa, coffee, palm oil, soya, wood, and their derived products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csddd-corporate-sustainability-due-diligence-2024-1760"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-delegated-regulation-2016-2067-spread-market-risk",
    "title": "Commission Delegated Regulation (EU) 2016/2067 of 2 September 2016 amending Delegated Regulation (EU) 2015/35 concerning the calculation of regulatory capital requirements for several categories of assets held by insurance and reinsurance undertakings",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation amends the Solvency II framework (Delegated Regulation 2015/35) by specifying updated standard parameters for calculating the Solvency Capital Requirement (SCR) for spread risk on bonds and loans, and for market risk concentrations. It primarily impacts insurance and reinsurance undertakings by adjusting the risk factors they must apply to their asset portfolios, particularly for qualifying infrastructure investments and European Long-Term Investment Funds (ELTIFs), as detailed in the amended Annexes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-delegated-regulation-2016-467-non-life-premium-risk",
    "title": "Commission Delegated Regulation (EU) 2016/467 of 30 September 2015 amending Commission Delegated Regulation (EU) 2015/35 concerning the calculation of regulatory capital requirements for several categories of assets held by insurance and reinsurance undertakings",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation amends the Solvency II framework (Delegated Regulation 2015/35) by updating the standard formula for calculating the Solvency Capital Requirement (SCR) for non-life premium and reserve risk. It specifically revises the correlation parameters and standard deviations for various lines of business, as detailed in the amended Annexes II and IV.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-deliberate-release-of-gmos-directive-2001-18-ec",
    "title": "EU Directive 2001/18/EC on deliberate release into the environment of genetically modified organisms and repealing Directive 90/220/EEC",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Directive 2001/18/EC establishes a harmonised regulatory framework for the deliberate release into the environment of genetically modified organisms (GMOs) and the placing on the market of GMOs as or in products within the European Community. It replaces Council Directive 90/220/EEC and is grounded in the precautionary principle. The Directive applies to two main categories: Part B covers deliberate release for any purpose other than placing on the market (e.g., field trials), requiring prior notification to the competent authority of the Member State where the release is to take place, submission of a technical dossier including an environmental risk assessment (ERA), a monitoring plan, and emergency response plans; release may only proceed after written consent is granted within 90 days of notification. Part C covers placing on the market of GMOs as or in products, requiring an extended notification containing ERA, conditions of use, labelling (including the phrase 'this product contains genetically modified organisms'), packaging proposals, a monitoring plan per Annex VII, and a consent period not exceeding ten years. The Directive mandates case-by-case environmental risk assessment according to Annex II, phasing out of antibiotic resistance markers by 31 December 2004 for Part C and 31 December 2008 for Part B, traceability at all stages of placing on the market, public consultation, and a safeguard clause for risk to human health or the environment. Exemptions exist for organisms obtained through techniques listed in Annex I B and for carriage by rail, road, inland waterway, sea, or air. The Directive also provides for differentiated procedures, renewal of consents, exchange of information between competent authorities and the Commission, and coordination with sectoral legislation (e.g., medicinal products under Regulation 2309/93).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-deposit-guarantee-schemes-directive-2014-49",
    "title": "EU Deposit Guarantee Schemes Directive 2014/49/EU (DGSD)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2022-12-19",
    "bluf": "Directive 2014/49/EU (DGSD) harmonises deposit guarantee schemes (DGS) across the EU - mandating €100,000 per depositor per institution coverage, 7-business-day payout deadlines (phased to 2024), target fund levels of 0.8% of covered deposits, and ex-ante funding collected from member institutions through risk-weighted contributions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-emir-regulation-648-2012",
      "eu-short-selling-regulation-236-2012"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-detergents-surfactants-regulation-2026-405",
    "title": "Regulation (EU) 2026/405 on detergents and surfactants - market availability conditions, surfactant biodegradability, manufacturer conformity assessment and micro-organism cleaning products",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Regulation (EU) 2026/405, adopted 11 February 2026, establishes rules for the free movement of detergents and surfactants in the internal market while protecting human health and the environment, and repeals Regulation (EC) No 648/2004. Detergents and surfactants may only be made available on the market if they comply with the Regulation, surfactants must meet the biodegradability requirements in Annex I, and manufacturers must draw up technical documentation and carry out conformity assessment. Detergents containing micro-organisms must comply with Annex II.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-clp-regulation-1272-2008",
      "eu-reach-regulation-1907-2006",
      "eu-empowering-consumers-green-transition-directive-2024-825"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-digcomp-digital-competence-framework-2022",
    "title": "EU DigComp 2.2: A Digital Competence Framework for Citizens 2022",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The EU DigComp 2.2 framework defines 21 competences across 5 areas of digital literacy for citizens, establishing 8 proficiency levels and integrating AI-specific examples to guide education, training, and workforce development across EU member states. It applies to individuals, educators, policymakers, and institutions involved in digital skills development (JRC Technical Report, Section 1.1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-digital-content-services-directive-2019-770",
    "title": "EU Digital Content and Digital Services Directive 2019/770 - Consumer Contracts",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Directive (EU) 2019/770 harmonises EU rules on contracts for the supply of digital content and digital services to consumers, covering music, films, apps, games, cloud storage, and social media. Digital content and services must conform to the contract in terms of functionality, compatibility, interoperability, and security. Consumers have rights to repair or replacement, price reduction, and termination. Suppliers have a 2-year minimum liability period (Member States may extend to 10 years for durables). Data as payment (personal data provided in lieu of a price) is explicitly covered.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "sale_of_goods_directive_2019_771",
        "consumer_rights_directive_2011_83",
        "gdpr_personal_data",
        "digital_single_market",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011-83-cx",
      "eu-gdpr-educational-institutions-data",
      "eu-digital-services-act-consumer-redress-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-digital-education-action-plan-2021-2027",
    "title": "Communication on the Digital Education Action Plan 2021-2027: Resetting education and training for the digital age",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The EU Digital Education Action Plan is a European Commission policy initiative to support the adaptation of education and training systems in EU Member States for the digital age. It outlines two strategic priorities: fostering a high-performing digital education ecosystem (Priority 1) and enhancing digital skills and competences for the digital transformation (Priority 2), supported by 14 specific actions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-digital-education-action-plan-2021-2027-deap",
    "title": "EU Digital Education Action Plan 2021-2027 (DEAP) - Priority Actions: High-Performance Digital Connectivity, AI Literacy and Digital Competence Frameworks",
    "domain": "Education & Research",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Digital Education Action Plan 2021-2027 (DEAP) establishes binding commitments for EU Member States to ensure high-performance digital connectivity in all educational institutions by 2025 and to integrate AI literacy and digital competence frameworks into national curricula by 2027, as outlined in Section 2.1 and Section 3.2 of the official communication. Applies to all public and private education providers receiving EU funding or operating under national education systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeepers",
      "thailand-pdpa-2019-personal-data-protection",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-digital-markets-act-2022",
    "title": "Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The EU Digital Markets Act (DMA) designates large online platforms providing core platform services (CPS) as 'gatekeepers' and imposes a set of specific obligations to ensure market contestability and fairness. Key prohibitions and requirements, outlined in Articles 5, 6, and 7, address issues like self-preferencing, data combination restrictions, and interoperability to prevent gatekeepers from leveraging their dominant position unfairly.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-dpdp-act",
      "california-ccpa-v2",
      "iab-tcf-v2-2-consent"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-digital-markets-act-2022-1925",
    "title": "Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Digital Markets Act establishes ex ante rules for gatekeeper-designated digital platforms to ensure fair and contestable markets in the EU. It applies to large online platforms meeting specific quantitative and qualitative thresholds under Article 3 and imposes obligations on Core Platform Services under Article 5 and Article 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "apec-cbpr-cross-border-privacy-rules-system",
      "au-privacy-act-1988",
      "australia-competition-consumer-act-2010",
      "oecd-guidelines-consumer-protection-2016"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-digital-markets-act-2022-1925-gatekeeper-obligations",
    "title": "Regulation (EU) 2022/1925 on Contestable and Fair Markets in the Digital Sector (Digital Markets Act)",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The Digital Markets Act imposes specific obligations on designated 'gatekeepers' - large digital platforms with entrenched and durable market power - to ensure fair and contestable markets in the digital sector. These obligations include prohibitions on self-preferencing, data portability mandates, and interoperability requirements under Articles 5, 6, and 7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "oecd-competition-digital-economy-roundtable-2023",
      "uk-digital-markets-competition-consumers-act-2024-dmcc",
      "india-competition-act-2002-sections-3-4",
      "korea-fair-trade-act-revisions-2020-monopoly"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-digital-markets-act-2022-1925-gatekeepers",
    "title": "Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-09-14",
    "bluf": "The EU Digital Markets Act (DMA) designates large online platforms providing core platform services (CPS) as 'gatekeepers' if they meet specific quantitative thresholds, such as an annual EEA turnover of at least €7.5 billion and at least 45 million monthly active EU end-users. Per Article 3, such undertakings must notify the European Commission and subsequently comply with a set of obligations and prohibitions to ensure market fairness and contestability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "gdpr-article-5-data-principles",
      "eu-tfeu-article-102-abuse-of-dominance"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-digital-markets-act-2022-ai-gatekeepers",
    "title": "EU Digital Markets Act (Regulation 2022/1925) - AI Obligations for Designated Gatekeepers",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU Regulation 2022/1925 on contestable and fair markets in the digital sector (Digital Markets Act - DMA), which designated its first gatekeepers in September 2023, imposes specific obligations on designated gatekeepers whose core platform services use AI and algorithmic systems - in particular: Article 6(5) prohibits self-preferencing by gatekeepers in search rankings (relevant to AI-powered search); Article 6(11) requires gatekeepers to provide interoperability with third-party software including AI-powered tools and assistants; Article 6(12) prohibits gatekeepers from technically restricting end-users from switching between AI systems in the gatekeeper's platform; Article 12 requires notification to the Commission before any acquisitions of AI companies; and Article 19 establishes the Commission's power to order gatekeepers to take specific interoperability measures for AI systems; the DMA applies to designated gatekeepers only (currently Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft) and does not create general AI governance obligations for non-gatekeepers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-digital-markets-act-2022-ai-gatekeepers.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-50-transparency-obligations",
      "eu-digital-services-act-ai-recommender-systems",
      "eu-ai-act-article-5-prohibited-practices"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-digital-markets-act-gatekeeper-obligations",
    "title": "Regulation (EU) 2022/1925 on Contestable and Fair Markets in the Digital Sector (Digital Markets Act)",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The EU Digital Markets Act (DMA) imposes specific obligations and prohibitions on designated 'gatekeepers' - large digital platforms with entrenched and durable market power - to ensure fair and contestable markets. Key obligations are set out in Articles 5, 6, and 7, including prohibitions on self-preferencing, data combining, and blocking interoperability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-antitrust-compliance-programme-best-practice",
      "eu-damages-directive-2014-104-private-enforcement",
      "eu-data-act-2023-competition-data-access",
      "eu-merger-regulation-139-2004"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-digital-product-passport-vehicles-2024",
    "title": "Regulation (EU) 2024/1781 on the Digital Product Passport for Vehicles - Requirements for Battery Passport Integration, Recyclability Information and QR Code Accessibility",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation mandates vehicle manufacturers placing electric vehicles on the EU market to integrate a Battery Passport into the Digital Product Passport (DPP), provide verified recyclability data, and ensure machine-readable QR codes are affixed to vehicles by 2026. Applies to all manufacturers of type-approved electric and hybrid vehicles under Article 5(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "iso-26262-functional-safety-road-vehicles-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-digital-services-act-2022",
    "title": "Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The EU Digital Services Act (DSA) imposes harmonized due diligence obligations on online intermediaries and platforms to combat illegal content, disinformation, and other societal risks. Obligations are tiered, with the most stringent requirements for Very Large Online Platforms (VLOPs) and Search Engines (VLOSEs) concerning risk assessment, mitigation, and transparency (Chapter III, Section 5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "nist-ai-100-4-synthetic-content",
      "un-guiding-principles-business-hr",
      "eu-ai-act-bias"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-digital-services-act-2022-2065-illegal-content-notice-action",
    "title": "EU Digital Services Act 2022/2065 - Illegal Content Notice-and-Action, Transparency & VLOP Obligations",
    "domain": "Creative, Content & Media IP",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "EU DSA Regulation 2022/2065 imposes tiered obligations on digital service providers - all providers must handle illegal content notices expeditiously; Very Large Online Platforms (VLOPs) with 45M+ EU users face additional systemic risk assessments, algorithmic transparency, and annual independent audits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-digital-services-act-advertising-2022",
    "title": "Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and Amending Directive 2000/31/EC - Article 26: Transparency and Risks Related to Online Advertising",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Digital service providers designated as Very Large Online Platforms (VLOPs) must maintain a publicly accessible, real-time repository of all published ads, disclose the main parameters determining ad display, prohibit targeted advertising based on profiling of minors or sensitive data, and conduct annual independent audits of their advertising practices. Applies to VLOPs under Article 33(4) and Article 26 of the DSA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coppa-marketing-kids",
      "eu-ecommerce-directive-2000-31",
      "eu-eprivacy-directive-2002-58",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-digital-services-act-ai-recommender-systems",
    "title": "EU Digital Services Act (Regulation 2022/2065) - AI Recommender Systems and Algorithmic Transparency",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU Regulation 2022/2065 on a Single Market for Digital Services (Digital Services Act - DSA), which has applied to Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs) since 17 February 2023 and to all other platforms since 17 February 2024, imposes specific AI-related obligations on online platforms using algorithmic content recommendation and moderation systems - platforms must: provide users with at least one non-profiling content recommendation option; disclose in their terms of service the main parameters of recommender system algorithms and how users can influence those parameters; grant vetted researchers access to data for algorithmic accountability studies; and for VLOPs/VLOSEs conduct annual risk assessments of systemic risks including amplification of harmful content through algorithmic recommendation; these AI transparency obligations apply independently of and in addition to EU AI Act obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-digital-services-act-ai-recommender-systems.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-50-transparency-obligations",
      "eu-ai-act-article-5-prohibited-practices",
      "eu-ai-act-article-27-fria-fundamental-rights"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-digital-services-act-consumer-redress-2022",
    "title": "Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and Amending Directive 2000/31/EC (Digital Services Act)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Digital service providers in the EU must establish accessible, transparent, and timely complaints mechanisms, enable out-of-court dispute settlement, provide legal redress for users affected by algorithmic content moderation decisions, recognize trusted flaggers, and ensure accountability for systemic risks. Applies to all intermediary service providers under Title II, III, and IV, with heightened obligations for Very Large Online Platforms (VLOPs) under Article 33-35.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-adr-consumer-disputes-2013",
      "eu-consumer-rights-directive-2011",
      "eu-omnibus-directive-2019-2161",
      "eu-p2b-regulation-2019-1150",
      "iso-10002-2018-customer-satisfaction-complaints"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-digital-single-market-copyright-cross-border-portability",
    "title": "Regulation (EU) 2017/1128 of the European Parliament and of the Council of 14 June 2017 on cross-border portability of online content services in the internal market",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Online content service providers must enable subscribers to access their subscribed content when temporarily present in another EU Member State. This obligation applies to both audiovisual and audio content services under Article 3. Verification of residence and temporary presence must comply with Article 4 and Recital 18, using only existing subscriber data or authentication methods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "berne-convention-1886-2024-literary-artistic-works",
      "dmca-safe-harbor"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dir-2018-1972-corrigendum-to-directive-eu-2018-1972-of-11-december-2018-es",
    "title": "Corrigendum to Directive (EU) 2018/1972 establishing the European Electronic Communications Code",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This document is a corrigendum to Directive (EU) 2018/1972 of the European Parliament and of the Council of 11 December 2018 establishing the European Electronic Communications Code, published in the Official Journal of the European Union L 321 of 17 December 2018. The corrigendum appears in the Official Journal of the European Union L 419/36 on 11 December 2020. It corrects a textual error on page 205, Annex XI, point 3. The original text read: 'Any car radio receiver integrated in a new vehicle of category M which is made available on the market for sale or rent in the Union from 21 December 2020 shall comprise …'. The corrected text replaces the phrase 'made available on the market' with 'placed on the market', so the corrected provision reads: 'Any car radio receiver integrated in a new vehicle of category M which is placed on the market for sale or rent in the Union from 21 December 2020 shall comprise …'. The corrigendum addresses only this specific wording change in Annex XI, point 3 concerning interoperability for car radio receivers; no other articles or annexes of the Directive are modified by this corrigendum.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "eu-dir-2022-0993-on-the-minimum-level-of-training-of-seafarers-codification",
    "title": "Directive (EU) 2022/993 of the European Parliament and of the Council of 8 June 2022 on the minimum level of training of seafarers (codification)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Directive codifies Directive 2008/106/EC on the minimum level of training of seafarers, incorporating the STCW Convention into Union law. It applies to seafarers serving on seagoing ships flying the flag of a Member State, excluding warships, fishing vessels, pleasure yachts not engaged in trade, and wooden ships of primitive build. Member States must ensure seafarers are trained at least in accordance with the STCW Convention as laid down in Annex I and hold certificates of competency or certificates of proficiency. Certificates for masters, officers and radio operators must be endorsed by the Member State. A mutual recognition scheme for seafarers' certificates issued by Member States is established, requiring host Member States to accept certificates of proficiency and documentary evidence and to recognise certificates of competency via endorsement. Medical certificates issued under the authority of another Member State must also be accepted. Member States must maintain registers of certificates and information and submit yearly data to the Commission for policy-making and statistical purposes. The Directive sets principles for near-coastal voyages, training requirements, and provisions for the recognition of certificates issued by third countries. The Commission is empowered to adopt delegated acts to align the Directive with amendments to the STCW Convention and Part A of the STCW Code, including digital certificates for seafarers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dir-2022-1999-on-uniform-procedures-for-checks-on-the-transport-of-dangero",
    "title": "Directive (EU) 2022/1999 on uniform procedures for checks on the transport of dangerous goods by road (codification)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Directive (EU) 2022/1999 codifies and replaces Council Directive 95/50/EC, establishing uniform procedures for Member States to carry out checks on the transport of dangerous goods by road. The Directive applies to vehicles travelling in Member State territory or entering from a third country, but does not apply to vehicles belonging to or under the responsibility of the armed forces. Checks must cover a representative proportion of consignments and use the checklist set out in Annex I. A copy of the checklist or a certificate showing the result must be given to the driver. Checks are random and should cover an extensive portion of the road network. Vehicles with infringements, especially those listed in Annex II, may be immobilised and required to be brought into conformity before continuing, or may be refused entry to the Union. Checks may also be carried out at the premises of undertakings as a preventive measure or when serious roadside infringements have been recorded. Member States shall assist one another, and serious or repeated infringements by a non-resident vehicle or undertaking must be reported to the competent authorities of the Member State of registration or establishment. The Commission is empowered to adopt delegated acts to amend Annexes I, II and III to adapt them to scientific and technical progress, particularly to take account of amendments to Directive 2008/68/EC. Member States must send annual reports to the Commission using the model standard form in Annex III.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dir-2022-2381-on-improving-the-gender-balance-among-directors-of-listed-co",
    "title": "Directive 2022/2381 on improving gender balance among directors of listed companies",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Directive (EU) 2022/2381 aims to improve gender balance on boards of listed companies in the EU by setting minimum requirements. By 30 June 2026, listed companies must ensure that members of the underrepresented sex hold at least 40% of non-executive director positions or at least 33% of all director positions (including executive and non-executive). The number of positions needed is the closest to these proportions but not exceeding 49%. Where the objective is not met, selection procedures must apply: priority is given to an equally qualified candidate of the underrepresented sex unless exceptional objective reasons override. Candidates may request information on comparative assessment. Member States may suspend certain requirements if their own binding national measures are equally effective. Listed companies must set individual quantitative objectives for executive directors (unless pursuing the 33% all-director target) and report annually on gender composition and progress. Penalties must be effective, proportionate, and dissuasive. The Directive applies to publicly listed companies, excluding micro, small and medium-sized enterprises. It is based on Article 157(3) TFEU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-dir-2022-2561-on-the-initial-qualification-and-periodic-training-of-driver",
    "title": "Directive (EU) 2022/2561 on the initial qualification and periodic training of drivers of certain road vehicles for the carriage of goods or passengers (codification)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Directive (EU) 2022/2561 codifies and replaces Directive 2003/59/EC on the initial qualification and periodic training of drivers of certain road vehicles for the carriage of goods or passengers. It applies to nationals of Member States and third-country nationals employed by an undertaking established in a Member State who drive vehicles requiring categories C1, C1+E, C, C+E, D1, D1+E, D, or D+E driving licences on roads open to the public within the Union. The Directive establishes a compulsory system of initial qualification (either course attendance plus a test or tests only) and periodic training (compulsory course attendance every five years). Drivers must hold a Certificate of Professional Competence (CPC) certifying their initial qualification or periodic training. Exemptions apply to drivers of vehicles with maximum speed not exceeding 45 km/h, emergency services, vehicles undergoing road tests, certain non-commercial carriage, and drivers in rural areas supplying their own business under specific conditions, among others. Acquired rights exempt drivers who held specified driving licences issued no later than 9 September 2008 (for categories D) or 9 September 2009 (for categories C). The Directive requires Member States to mark the Union code '95' on the driving licence or a driver qualification card, and to exchange information on CPCs via an electronic network. The Commission is empowered to adopt delegated acts to amend Annexes I and II to adapt to scientific and technical progress.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-dir-2024-1203-corrigendum-to-directive-eu-2024-1203-of-11-april-2024-on-th",
    "title": "Corrigendum to Directive (EU) 2024/1203 on protection of environment through criminal law and replacing Directives 2008/99/EC and 2009/123/EC",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This corrigendum corrects an error on page 15 of the original Directive (EU) 2024/1203, specifically in Article 3(2), point (g). The original text incorrectly referenced Article 2, point (26) of Regulation (EU) 2024/1157, while the corrected version correctly references Article 3, point (26) of the same Regulation. The provision concerns the shipment of waste, as defined in the referenced Regulation, where such conduct involves a non-negligible quantity, whether executed in a single shipment or in several linked shipments. The corrigendum was published in the Official Journal of the European Union on 15 April 2025 under the L series reference 2025/90336. The original Directive was adopted on 11 April 2024 and published on 30 April 2024. This corrigendum does not alter the substance of the obligation but fixes a cross-reference error to ensure legal clarity and uniformity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-dir-2024-1203-on-the-protection-of-the-environment-through-criminal-law-an",
    "title": "Directive (EU) 2024/1203 of the European Parliament and of the Council of 11 April 2024 on the protection of the environment through criminal law and replacing Directives 2008/99/EC and 2009/123/EC",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Directive establishes minimum rules concerning the definition of criminal offences and penalties for the protection of the environment. It repeals and replaces Directives 2008/99/EC and 2009/123/EC. The Directive requires Member States to criminalise certain unlawful conduct, including the discharge of substances or energy into air, soil, or water that causes or is likely to cause substantial damage or serious injury; the unlawful collection, transport, or treatment of waste; the placing on the market of a product whose use on a larger scale results in discharge of materials or energy that causes or is likely to cause substantial damage; and the execution of a project without development consent that causes substantial damage. The Directive introduces qualified criminal offences, comparable to ecocide, for conduct that causes the destruction of or widespread and substantial irreversible damage to an ecosystem of considerable size or a habitat within a protected site. Penalties for natural persons include maximum terms of imprisonment of at least ten years for qualified offences causing death. For legal persons, fines must be set either as a maximum of at least 5% of total worldwide turnover or fixed amounts of at least EUR 40 million for qualified offences. The Directive provides for aggravating circumstances such as the continuation of illegal activity after inspections and mitigating circumstances such as restoration of the environment. It includes provisions on jurisdiction, limitation periods of at least ten years for serious offences, and the liability of legal persons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dir-2024-1233-on-a-single-application-procedure-for-a-single-permit-for-th",
    "title": "Directive (EU) 2024/1233 on a single application procedure for a single permit and a common set of rights for third-country workers",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Directive lays down a single application procedure for issuing a single permit for third-country nationals to reside for the purpose of work in a Member State, simplifying admission procedures and facilitating control of their status. It also establishes a common set of rights for third-country workers legally residing in a Member State, based on equal treatment with nationals, irrespective of the initial purpose of admission. The Directive applies to third-country nationals who apply to reside for work, have been admitted for other purposes and are allowed to work, or have been admitted for work. It does not apply to family members of Union citizens exercising free movement, posted workers, intra-corporate transferees, seasonal workers, au pairs, those under temporary or international protection, long-term residents, persons whose removal is suspended, self-employed workers, or seafarers. Member States must designate a competent authority to receive applications and issue the single permit, with a decision deadline of 90 days from submission of a complete application. The single permit combines a residence and work permit. Third-country workers enjoy equal treatment with nationals regarding working conditions, social security, recognition of qualifications, and access to goods and services. Member States must provide information free of charge and ensure effective legal redress and monitoring mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dir-2024-2810-on-multiple-vote-share-structures-in-companies-that-seek-adm",
    "title": "Directive (EU) 2024/2810 on multiple-vote share structures in companies that seek admission to trading on a multilateral trading facility",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Directive (EU) 2024/2810 requires Member States to ensure that companies whose shares are not already admitted to trading on a regulated market or an MTF have the right to adopt or modify a multiple-vote share (MVS) structure for the purpose of seeking admission to trading on an MTF, including SME growth markets. The adoption or modification must be approved by the general meeting by at least a qualified majority as specified in national law, with a separate vote in each affected class of shares. Member States must introduce at least one safeguard: either a maximum ratio of votes attached to MVSs to shares with the lowest voting rights, or a requirement that certain qualified majority decisions (excluding appointment and dismissal of administrative, management and supervisory bodies and their operational decisions) be calculated on the basis of the total votes cast and either share capital or shares represented, or on total votes cast and a separate vote in each affected class. Member States may impose additional safeguards such as transfer-based, time-based or event-based sunset clauses. Companies with MVS structures must disclose detailed information on share structure, restrictions on transfer and voting rights, and identity of large shareholders (holding more than 5% of voting rights) in prospectuses, admission documents or annual financial reports. Investment firms and market operators must clearly identify shares of companies with MVS structures according to regulatory technical standards to be developed by ESMA by 5 December 2025. The Commission must review the Directive by 5 December 2028. Member States must transpose the Directive by 5 December 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-dir-2024-2823-on-the-legal-protection-of-designs-recast",
    "title": "Directive (EU) 2024/2823 on the legal protection of designs (recast) - harmonizing registered design rights across Member States",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Directive (EU) 2024/2823 recasts Directive 98/71/EC to harmonize substantive and procedural design law across Member States. It defines a 'design' as the appearance of a product resulting from features including lines, colours, shape, texture, decoration, and animation, and a 'product' as any industrial or handicraft item other than a computer program, regardless of physical or non-physical form. Protection requires novelty and individual character. Novelty means no identical design was made available to the public before the filing or priority date; individual character is assessed by the overall impression on an informed user. Design rights do not subsist in features solely dictated by technical function or in features that must be reproduced exactly for mechanical interconnection (except for modular systems). Protection lasts up to 25 years from filing, renewable in five-year periods. Grounds for non-registrability include any design contrary to public policy or morality, or improper use of certain official symbols. The directive requires offices to limit ex officio examination to those grounds. It introduces a repair clause exemption for component parts of complex products used to restore original appearance, subject to consumer information duties. The directive also grants right holders the right to prevent third parties from bringing infringing products from third countries into the Member State where the design is registered. A commonly accepted notice symbol 'D' is established.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-dir-2024-2831-corrigendum-to-directive-eu-2024-2831-of-23-october-2024-on",
    "title": "Corrigendum to Directive (EU) 2024/2831 on improving working conditions in platform work",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This instrument is a corrigendum issued by the European Union to correct a textual error in Directive (EU) 2024/2831 of the European Parliament and of the Council of 23 October 2024 on improving working conditions in platform work, as published in the Official Journal of the European Union L series (2024/2831) on 11 November 2024. The corrigendum appears in Official Journal L series document 2025/90196 dated 28 February 2025. The correction specifically amends Article 2(1), point (g), which originally read: '\"representatives of persons performing platform work\" means workers' representatives and, insofar as provided for in national law and practice,'. The corrected version reads: '\"representatives of persons performing platform work\" means workers' representatives and, insofar as provided for in national law and practice, representatives of persons performing platform work other than platform workers;'. The corrigendum includes the electronic ELI identifier and notes ISSN 1977-0677 (electronic edition). No other provisions, obligations, thresholds, or implementation dates are provided in the text.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-dir-2024-2841-establishing-the-european-disability-card-and-the-european-p",
    "title": "Directive (EU) 2024/2841 establishing the European Disability Card and the European Parking Card for persons with disabilities",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Directive establishes a framework of common rules and conditions, including a common standardised model, for a European Disability Card as proof of recognised disability status or entitlement to specific services based on a disability, and for a European Parking Card for persons with disabilities as proof of their recognised right to parking conditions and facilities reserved for persons with disabilities. The Directive aims to facilitate the exercise by persons with disabilities of the right to access special conditions or preferential treatment offered by public authorities or private operators when travelling to or visiting another Member State for a short stay without discrimination on grounds of nationality on the same basis as persons with disabilities in that Member State, and to facilitate access to parking conditions and facilities reserved for persons with disabilities on the same basis as in that Member State. The mutual recognition of these cards is intended to remove barriers and difficulties in travelling to or visiting another Member State due to the lack of mutual recognition of disability status or entitlement to specific services based on a disability. Member States are to issue the European Disability Card free of charge, and may provide for a digital version after technical specifications are set by implementing acts. The Directive does not apply to social security benefits under Regulations (EC) No 883/2004 and (EC) No 987/2009, or to services for long-term inclusion, habilitation or rehabilitation of persons with disabilities. Member States must take steps to prevent forgery or fraud in relation to these cards and must consult persons with disabilities and their representative organisations in the design and implementation of those measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dir-2024-3019-corrigendum-to-directive-eu-2024-3019-of-27-november-2024-co",
    "title": "Corrigendum to Directive (EU) 2024/3019 of the European Parliament and of the Council of 27 November 2024 concerning urban wastewater treatment",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This is a corrigendum to Directive (EU) 2024/3019 of the European Parliament and of the Council of 27 November 2024 concerning urban wastewater treatment, published in the Official Journal of the European Union L series on 16 January 2025 (document 2025/90038). The corrigendum corrects a date error on page 48, in Annex I, Part C. Specifically, in Note 3 of that annex, the original text referenced a deadline of '31 December 2037' for taking into account natural nitrogen retention in the calculation of the minimum percentage reduction of nitrogen in Member States where such retention was previously considered under Directive 91/271/EEC and where it is demonstrated that part of the nitrogen from urban wastewater can be eliminated in receiving waters. The corrected text replaces '31 December 2037' with '31 December 2045', extending the transition period by eight years. The note continues to require that all specified conditions are fulfilled for this exceptional local circumstance allowance to apply. The corrigendum is sourced from the Official Journal of the European Union with electronic edition ISSN 1977-0677 and has the ELI identifier",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dir-2026-0799-harmonising-certain-aspects-of-insolvency-law",
    "title": "Directive (EU) 2026/799 of the European Parliament and of the Council of 30 March 2026 harmonising certain aspects of insolvency law",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Directive harmonises certain aspects of insolvency law across Member States to improve the functioning of the internal market and the Capital Markets Union by removing obstacles to free movement of capital and freedom of establishment. It sets minimum requirements for avoidance actions aimed at voiding, voiding or rendering unenforceable legal acts detrimental to creditors, with specific grounds for congruent and incongruent coverage and a limitation period. The Directive mandates access for insolvency practitioners to bank account registers through designated courts or administrative authorities, and to beneficial ownership registers and other national databases for tracing assets. It introduces pre-pack proceedings for the sale of a business as a going concern, with a confidential preparation phase and a liquidation phase under judicial or competent authority supervision. The pre-pack process must be governed by statutory provisions, include a monitor independent from the debtor, and ensure high standards of competitiveness, transparency and fairness. The Directive is without prejudice to workers’ rights under Directives 98/59/EC, 2001/23/EC, 2002/14/EC, 2008/94/EC and 2009/38/EC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-directive-2001-18-deliberate-release-gmo",
    "title": "Directive 2001/18/EC of the European Parliament and of the Council of 12 March 2001 on the deliberate release into the environment of genetically modified organisms and repealing Council Directive 90/220/EEC",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive establishes a harmonized framework for the deliberate release of genetically modified organisms (GMOs) into the environment for research, field trials, or market authorization within the EU. It mandates risk assessment, monitoring plans, public consultation, and traceability under Article 5 and Annex II-IV.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "eu-biosafety-contained-use-directive-2009-41",
      "eu-gmo-regulation-1829-2003"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-directive-2004-23-human-tissues-cells",
    "title": "Directive 2004/23/EC of the European Parliament and of the Council of 31 March 2004 on setting standards of quality and safety for the donation, procurement, testing, processing, preservation, storage and distribution of human tissues and cells",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This Directive establishes binding quality and safety standards for all stages of the human tissues and cells lifecycle across EU Member States, including donation, procurement, testing, processing, storage, and traceability. It applies to tissue establishments and healthcare providers involved in the handling of human tissues and cells for human application, under Article 3 and Article 17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-atmp-regulation-1394-2007",
      "ema-guidelines-advanced-therapy-quality-2019",
      "uk-human-tissue-act-2004",
      "isber-best-practices-biorepositories-2018",
      "oecd-guidelines-human-biobanks-2009"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-directive-2009-41-contained-use-gmo",
    "title": "Directive 2009/41/EC of the European Parliament and of the Council of 6 May 2009 on the contained use of genetically modified micro-organisms (recast)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This Directive requires all EU member states to ensure that genetically modified microorganisms (GMMs) are used only under contained conditions that prevent adverse effects on human health and the environment. It mandates risk assessment, classification into containment levels Class 1-4, prior notification to competent authorities, and immediate reporting of accidents, as specified in Article 8 and Annex II.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "eu-gmo-regulation-1829-2003",
      "eu-atmp-regulation-1394-2007",
      "ich-q5a-r2-viral-safety-biotech-2024",
      "isber-best-practices-biorepositories-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-directive-2009-81-defence-security-procurement",
    "title": "EU Directive 2009/81/EC on procurement in the fields of defence and security",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Directive 2009/81/EC of the European Parliament and of the Council of 13 July 2009 on the coordination of procedures for the award of certain works contracts, supply contracts and service contracts by contracting authorities or entities in the fields of defence and security establishes EU-level procurement rules tailored to sensitive defence and security acquisitions. Article 2 sets the scope (military equipment supply, sensitive equipment supply, related works and services); Article 8 establishes financial thresholds aligned with the general procurement regime; Article 13 reserves specific exclusions for protection of essential security interests; Article 18 governs technical specifications using performance and functional requirements; Article 21 covers subcontracting with non-discrimination; Articles 25-28 set out the procedures (restricted, negotiated with publication, competitive dialogue, negotiated without publication); Article 22 imposes security of information requirements and Article 23 imposes security of supply requirements; Article 39 governs selection criteria; Article 47 restricts award criteria to lowest price or most economically advantageous tender; Articles 55-64 establish independent review and standstill procedures, with ineffectiveness remedies available where essential defence and security interests permit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-defence-security-public-contracts-regulations-2011",
      "wto-revised-government-procurement-agreement-2012"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-directive-2011-93-article-3-sexual-abuse-offences",
    "title": "EU Directive 2011/93/EU Article 3 - Offences Concerning Sexual Abuse",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Article 3 of Directive 2011/93/EU on combating the sexual abuse and sexual exploitation of children and child pornography requires EU Member States to criminalise specified intentional sexual abuse conduct against children. Article 3(2)-(6) establishes graduated penalties for: causing a child below the age of sexual consent to witness sexual activities (minimum 1 year); causing a child below age of consent to witness sexual abuse (minimum 2 years); engaging in sexual activities with a child below age of consent (minimum 5 years); engaging in sexual activities by abuse of recognised position of trust, authority, or particular vulnerability (minimum 8 years); engaging in sexual activities by coercion, force, or threat (minimum 10 years). Member States must transpose the directive into national law and ensure effective, proportionate, and dissuasive sanctions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "article_3_paragraph_2_witnessing_sexual_activity",
        "article_3_paragraph_3_witnessing_sexual_abuse",
        "article_3_paragraph_4_sexual_activity_with_child_below_consent",
        "article_3_paragraph_5_abuse_of_position_of_trust",
        "article_3_paragraph_6_coercion_force_threats_serious_harm",
        "age_of_sexual_consent_article_2_b",
        "child_definition_article_2_a",
        "intentional_mens_rea_required",
        "minimum_maxima_floor_not_ceiling",
        "transposition_deadline_18_december_2013"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-directive-2011-93-article-5-offences-concerning-child-pornography",
      "uk-sexual-offences-act-2003-section-9-sexual-activity-with-child"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-directive-2011-93-article-4-sexual-exploitation",
    "title": "EU Directive 2011/93/EU Article 4 - Offences Concerning Sexual Exploitation",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Article 4 of Directive 2011/93/EU on combating the sexual abuse and sexual exploitation of children requires EU Member States to criminalise intentional conduct concerning the sexual exploitation of children. Article 4(2)-(7) establishes graduated penalties: causing or recruiting a child to participate in pornographic performances (minimum 5 years if child has not reached the age of sexual consent / 2 years above); coercing, forcing, or threatening a child into such performances (minimum 8 years / 5 years); knowingly attending pornographic performances involving a child (minimum 2 years / 1 year); causing or recruiting a child into prostitution (minimum 8 years / 5 years); coercing/forcing/threatening into prostitution (minimum 10 years / 5 years); engaging in sexual activities with a child where recourse is had to child prostitution (minimum 5 years / 2 years). Article 4 complements Articles 3 (sexual abuse) and 5 (child pornography), forming the trinity of EU child sexual exploitation criminal law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "article_4_paragraph_2_causing_recruiting_pornographic_performance",
        "article_4_paragraph_3_coercing_forcing_threatening_pornographic_performance",
        "article_4_paragraph_4_knowingly_attending_pornographic_performance",
        "article_4_paragraph_5_causing_recruiting_into_prostitution",
        "article_4_paragraph_6_coercing_forcing_threatening_into_prostitution",
        "article_4_paragraph_7_engaging_in_sexual_activities_with_child_prostitution_recourse",
        "child_prostitution_definition_article_2_e",
        "pornographic_performance_definition_article_2_d",
        "intentional_mens_rea_required",
        "transposition_deadline_18_december_2013"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-directive-2011-93-article-3-sexual-abuse-offences",
      "eu-directive-2011-93-article-5-offences-concerning-child-pornography",
      "uk-sexual-offences-act-2003-section-47-paying-for-sexual-services-of-child"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-directive-2011-93-article-5-offences-concerning-child-pornography",
    "title": "EU Directive 2011/93/EU Article 5 - Offences Concerning Child Pornography",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Article 5 of Directive 2011/93/EU requires EU Member States to criminalise intentional conduct concerning child pornography. Article 5(2)-(8) sets minimum maximum penalties: acquisition or possession of child pornography (minimum 1 year); knowingly obtaining access to child pornography via information and communication technology (minimum 1 year); distribution, dissemination, or transmission (minimum 2 years); offering, supplying, or making available (minimum 2 years); production (minimum 3 years). 'Child pornography' is defined broadly in Article 2(c) to include material depicting children engaged in sexually explicit conduct, realistic representations of a child engaged in such conduct, and material depicting a person appearing to be a child engaged in such conduct. Member States must transpose the directive into national law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "article_5_paragraph_2_acquisition_or_possession",
        "article_5_paragraph_3_knowingly_obtaining_access_via_ict",
        "article_5_paragraph_4_distribution_dissemination_transmission",
        "article_5_paragraph_5_offering_supplying_making_available",
        "article_5_paragraph_6_production",
        "article_5_paragraph_7_exception_for_real_child_consensual_adult_representations",
        "article_5_paragraph_8_exception_for_realistic_representations_simulated_pornography",
        "child_pornography_definition_article_2_c",
        "child_definition_article_2_a",
        "interaction_with_article_25_blocking_or_removal_of_csam_websites"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-directive-2011-93-article-3-sexual-abuse-offences",
      "uk-protection-of-children-act-1978-section-1-indecent-photographs-children",
      "us-18-usc-2252a-child-pornography-material"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-directive-2011-93-article-6-solicitation-of-children-sexual-purposes",
    "title": "EU Directive 2011/93/EU Article 6 - Solicitation of Children for Sexual Purposes (Grooming)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Article 6 of Directive 2011/93/EU requires EU Member States to criminalise the solicitation of children for sexual purposes via information and communication technology. Article 6(1) covers the proposal by means of ICT by an adult to meet a child who has not reached the age of sexual consent for the purpose of committing offences under Article 3(4) (sexual activity) or Article 5(6) (child pornography production), where the proposal is followed by material acts leading to such a meeting - minimum maximum 1 year imprisonment. Article 6(2) covers the attempt to commit Article 5(2)-(3) offences (acquisition/possession or knowingly obtaining access to child pornography) by means of ICT. Article 6 is the EU's 'online grooming' provision - paralleling national offences such as UK SOA 2003 Section 15 (meeting a child following sexual grooming) and US 18 USC § 2422(b) (coercion and enticement).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "article_6_paragraph_1_proposal_to_meet_child_for_sexual_purposes",
        "article_6_paragraph_2_attempt_to_obtain_csam_via_ict",
        "online_grooming_provision_overarching_purpose",
        "ict_definition_broad_scope",
        "material_acts_following_proposal_required_for_paragraph_1",
        "adult_perpetrator_requirement",
        "child_below_age_of_sexual_consent_required",
        "interaction_with_uk_soa_2003_section_15_grooming",
        "interaction_with_us_18_usc_2422_b_coercion_enticement",
        "interaction_with_council_of_europe_lanzarote_convention_article_23"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-directive-2011-93-article-3-sexual-abuse-offences",
      "eu-directive-2011-93-article-5-offences-concerning-child-pornography",
      "uk-sexual-offences-act-2003-section-15a-sexual-communication-with-child"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "eu-directive-2011-95-recognition-professional-qualifications",
    "title": "Directive 2005/36/EC of the European Parliament and of the Council on the recognition of professional qualifications, as amended by Directive 2013/55/EU",
    "domain": "Education & Research",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive establishes the legal framework for the automatic recognition of certain regulated professional qualifications (e.g., doctors, nurses, architects) across EU Member States, and sets out procedures for general recognition, establishment, and temporary provision of services. Key provisions are found in Articles 3, 4, 12, 13, and 55.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-education-action-plan-2021-2027-deap",
      "eu-open-science-policy-fair-data-principles-2021",
      "eu-researcher-charter-code-of-conduct-2005",
      "iso-21001-2018-educational-organizations-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-directive-2014-23-concession-contracts",
    "title": "EU Directive 2014/23/EU on the award of concession contracts",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Directive 2014/23/EU of the European Parliament and of the Council of 26 February 2014 on the award of concession contracts establishes the EU-level framework for awarding works and services concession contracts by contracting authorities and contracting entities. Art. 5 contains the definitions, including the operational risk transfer requirement that distinguishes a concession from a public contract. Art. 8 sets the financial threshold for application of the Directive (currently 5.382 million euro after Regulation 2023/2497, calculated by reference to the estimated total turnover of the concessionaire over the duration of the concession excluding VAT). Art. 18 establishes the principles of equal treatment, non-discrimination, transparency and proportionality, with maximum concession duration of five years unless justified. Arts. 28 and 29 govern technical and functional requirements for concession specifications. Art. 30 establishes general principles of award procedure flexibility while requiring basic guarantees of transparency and equal treatment. Art. 31 governs concession notice publication in the Official Journal. Arts. 37 and 38 cover procedural guarantees and selection criteria. Art. 41 covers award criteria. Art. 42 governs subcontracting. Art. 43 governs modification of contracts during their term. Art. 46 establishes the review and remedy regime by reference to Directive 89/665/EEC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-directive-2009-81-defence-security-procurement",
      "eu-public-procurement-construction-directive"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "eu-directive-2014-25-utilities-procurement",
    "title": "EU Directive 2014/25/EU on procurement by entities operating in the water, energy, transport and postal services sectors",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Directive 2014/25/EU of the European Parliament and of the Council of 26 February 2014 (the Utilities Directive) establishes EU-level procurement rules for contracting entities operating in the water, energy, transport and postal services sectors. Arts. 7 to 13 define the covered activities and the categories of contracting entities (contracting authorities, public undertakings and private entities with special or exclusive rights). Art. 15 sets the financial thresholds aligned with the GPA and adjusted periodically. Art. 36 establishes the principles of equal treatment, non-discrimination, transparency and proportionality. Art. 44 governs the choice of procedure. Arts. 45 to 48 define the procedures: open procedure (Art. 45), restricted procedure (Art. 46), negotiated procedure with prior call for competition (Art. 47) and competitive dialogue (Art. 48). Innovation partnership and negotiated procedure without prior call for competition are also available under stringent conditions. Art. 80 governs selection criteria. Art. 82 governs award criteria, requiring contract award based on the most economically advantageous tender (MEAT). The Directive provides more flexibility than the general procurement Directive 2014/24/EU because utilities entities operate in competitive sectors and need procedural flexibility.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-directive-2014-23-concession-contracts",
      "eu-public-procurement-construction-directive"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "eu-directive-2014-45-roadworthiness-testing",
    "title": "EU Directive 2014/45/EU - Periodic Roadworthiness Testing of Motor Vehicles",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Directive 2014/45/EU harmonises periodic roadworthiness testing across EU Member States, establishing minimum inspection standards, item lists, deficiency classification (minor, major, dangerous), test centre requirements, inspector qualifications, and vehicle category-specific test intervals to ensure road safety and environmental compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-general-safety-regulation-2019-2144-vehicles",
      "un-regulation-r13-heavy-vehicle-braking-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-directive-2019-771-consumer-goods-digital-content",
    "title": "EU Directive 2019/771 - Sale of Goods and Digital Content Conformity",
    "domain": "Operations & CX",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Directive 2019/771 on the sale of goods and 2019/770 on digital content contracts establish conformity requirements and mandatory remedies for defective goods (including those with embedded digital elements), requiring sellers to deliver goods conforming to both subjective and objective standards, granting consumers a two-year minimum guarantee period, and mandating free repair, replacement, or price reduction before refund - with the burden of proof reversed for 12 months after delivery.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011-83-cx"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-directive-combating-corruption-2024-1760",
    "title": "Directive (EU) 2024/1760 of the European Parliament and of the Council of 13 June 2024 on combating corruption, replacing Council Framework Decision 2003/568/JHA and the Convention on the fight against corruption involving officials of the European Communities or officials of Member States of the European Union and amending Directive (EU) 2017/1371 of the European Parliament and of the Council",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-07-19",
    "bluf": "This directive establishes minimum EU-wide rules for defining criminal offences and penalties for corruption, applying to both public and private sectors. It mandates Member States to criminalise a wide range of corrupt acts, including bribery, misappropriation, trading in influence, and obstruction of justice, as detailed in Articles 7 to 14, and sets minimum levels for maximum imprisonment penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-bribery-act-2010",
      "fcpa-anti-bribery-compliance",
      "iso-37001-anti-bribery-2016",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-dispute-resolution-directive-2017-1852",
    "title": "Council Directive (EU) 2017/1852 of 10 October 2017 on tax dispute resolution mechanisms in the European Union",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes a mandatory and binding dispute resolution mechanism for tax disputes between EU Member States arising from double taxation agreements. It requires that if a Mutual Agreement Procedure (MAP) does not resolve a dispute within two years, the taxpayer can request the setup of an Advisory Commission to issue an opinion, leading to a binding final decision (Article 6 & 15).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-distance-selling-insurance-directive-2002-92",
    "title": "Directive 2002/92/EC of the European Parliament and of the Council of 9 December 2002 on insurance mediation",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This directive requires insurance intermediaries to provide consumers with specific, clear pre-contractual information and grants a 14-day right of cancellation for insurance contracts concluded at a distance, as mandated by Articles 12 and 13. It aims to ensure a high level of consumer protection and a single market for insurance mediation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-dlt-pilot-regime-2022-858",
    "title": "Regulation (EU) 2022/858 of the European Parliament and of the Council of 30 May 2022 on a pilot regime for market infrastructures based on distributed ledger technology, and amending Regulations (EU) No 600/2014 and (EU) No 909/2014 and Directive 2014/65/EU",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes a temporary EU-wide 'sandbox' (pilot regime) for market infrastructures using distributed ledger technology (DLT) to trade and settle crypto-assets classified as financial instruments. It allows approved DLT Multilateral Trading Facilities (MTFs), DLT Settlement Systems (SS), and DLT Trading and Settlement Systems (TSS) to request specific, temporary exemptions from existing financial regulations like MiFID II and CSDR, as detailed in Articles 4, 5, and 6, subject to conditions and oversight by national competent authorities and ESMA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mica-regulation-2023",
      "eu-mica-casp-obligations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dlt-pilot-regime-2022-858-live-operations",
    "title": "Regulation (EU) 2022/858 of the European Parliament and of the Council of 30 May 2022 on a pilot regime for market infrastructures based on distributed ledger technology, and amending Regulations (EU) No 600/2014 and (EU) No 909/2014 and Directive 2014/65/EU",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a temporary pilot regime allowing eligible firms to operate DLT-based market infrastructures-specifically DLT Multilateral Trading Facilities (MTFs), DLT Settlement Systems (SSs), and DLT Trading and Settlement Systems (TSSs)-under relaxed MiFID II and CSDR requirements for up to six years, provided they meet strict authorisation, governance, and operational thresholds defined in Articles 4-10. It applies to investment firms, market operators, and central securities depositories seeking to innovate within EU capital markets using DLT.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dlt-pilot-regime-2022-858",
      "bis-iosco-pfmi-applied-to-dlt-systems",
      "eu-cbdc-digital-euro-legislative-proposal-2023",
      "crypto-aml-travel-rule",
      "ethereum-eip-4337"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dma-article-5-obligations-gatekeepers-core-platform",
    "title": "Regulation (EU) 2022/1925 on contestable and fair markets in the digital sector (Digital Markets Act) - Article 5: Obligations for gatekeepers",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "A designated gatekeeper must comply with all obligations outlined in Article 5 for each of its core platform services identified in its designation decision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dma-article-6-obligations-gatekeepers-susceptible-specification",
    "title": "Regulation (EU) 2022/1925 (Digital Markets Act) Article 6: Obligations for gatekeepers susceptible of being further specified under Article 8",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Gatekeepers must comply with all obligations specified in Article 6 for each of their core platform services that are listed in the designation decision under Article 3(9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dma-article-8-compliance-enforcement-gatekeepers",
    "title": "Regulation (EU) 2022/1925 on contestable and fair markets in the digital sector (Digital Markets Act) - Article 8: Compliance with obligations for gatekeepers",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Gatekeepers must ensure, demonstrate, and implement effective measures to comply with the obligations in Articles 5, 6, and 7, while also ensuring these measures adhere to other applicable laws like GDPR, ePrivacy, and consumer protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dma-articles-5-7-gatekeeper-obligations",
    "title": "Regulation (EU) 2022/1925 (Digital Markets Act) Articles 5-7: Obligations for Gatekeepers",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The EU Digital Markets Act (DMA) imposes direct, non-negotiable obligations on designated 'gatekeeper' platforms to ensure fair and contestable digital markets. Key prohibitions under Article 5 include self-preferencing and tying, while Article 6 mandates actions such as allowing third-party interoperability, providing data access to business users, and enabling app uninstallation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeepers",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dora-2022-2554-article-10-detection-anomalous-activities",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 10: Detection",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Financial entities must establish and maintain mechanisms to promptly detect anomalous activities, including ICT network performance issues and incidents, and to identify potential material single points of failure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dora-2022-2554-article-15-ict-business-continuity-policy",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 15 Further harmonisation of ICT risk management tools, methods, processes and policies",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article mandates the European Supervisory Authorities (ESAs) to develop common draft regulatory technical standards to further harmonise ICT risk management tools, methods, processes, and policies for financial entities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dora-2022-2554-article-17-ict-related-incident-classification",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 17: ICT-related incident management process",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Financial entities must define, establish, and implement a comprehensive ICT-related incident management process designed to detect, manage, and notify ICT-related incidents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dora-2022-2554-article-19-incident-reporting-competent-authorities",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 19: Reporting of major ICT-related incidents and voluntary notification of significant cyber threats",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Financial entities are required to report all major ICT-related incidents to their designated competent authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dora-2022-2554-article-26-digital-operational-resilience-testing",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 26: Advanced testing of ICT tools, systems and processes based on TLPT",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Mandates that specific financial entities conduct advanced Threat Led Penetration Testing (TLPT) at least every three years, with the frequency subject to adjustment by the competent authority based on the entity's risk profile.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dora-2022-2554-article-28-ict-third-party-risk-management",
    "title": "REGULATION (EU) 2022/2554 on digital operational resilience for the financial sector - Article 28: Principle of sound management of ICT third-party risk",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Financial entities must manage ICT third-party risk as an integral part of their overall ICT risk framework, including maintaining a register of all ICT service contracts, performing due diligence before engagement, and establishing clear exit strategies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dora-2022-2554-article-30-key-contractual-provisions-ict-third-party",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 30: Key contractual provisions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Financial entities must ensure that contractual arrangements for the use of ICT services include specific, detailed provisions covering service descriptions, data management, security, incident response, audit rights, and exit strategies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-dora-2022-2554-article-5-governance-arrangements-ict-risk",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector - Article 5: Governance and organisation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Financial entities must establish and maintain an internal governance and control framework to effectively and prudently manage all ICT risk, ensuring a high level of digital operational resilience.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dora-2022-2554-article-8-identification-classification-ict-assets",
    "title": "Regulation (EU) 2022/2554 (DORA) Article 8: Identification and Classification of ICT Supported Business Functions and Assets",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Financial entities must identify, classify, document, and annually review all ICT-supported business functions, information assets, and ICT assets as part of their ICT risk management framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-dora-article-17-23-incident-classification",
    "title": "Regulation (EU) 2022/2554 (DORA) Articles 17-23: ICT-Related Incident Management, Classification, and Reporting",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "EU DORA Articles 17-23 mandate that financial entities establish a robust ICT-related incident management process, classify incidents (especially major ones) based on specific criteria defined in Article 18, and adhere to a strict multi-stage reporting timeline to competent authorities as outlined in Article 19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nis2-incident-reporting-article-23",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dora-articles-28-44-third-party-ict-risk",
    "title": "EU Digital Operational Resilience Act (DORA) - Chapter V, Section I & II: Management of ICT Third-Party Risk (Articles 28-44)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Articles 28-44 of the EU DORA mandate that financial entities manage ICT third-party risk through a comprehensive lifecycle approach, including pre-contract due diligence, mandatory contractual provisions (Article 30), exit strategies, and ongoing monitoring, while establishing a Union-level oversight framework for designated critical ICT third-party service providers (CTPPs).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nis2-supply-chain-security-article-22",
      "c-scrm-practices-systems-organizations",
      "iso-27001-2022",
      "nist-ir-8276-cyber-scrm-practices"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dora-cloud-third-party-ict-2022-2554",
    "title": "Regulation (EU) 2022/2554 of the European Parliament and of the Council of 16 November 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2018/286",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "EU DORA mandates financial entities to manage risks from ICT third-party providers, particularly cloud services, by implementing contractual safeguards, exit strategies, multi-vendor policies, and subcontracting controls. Critical ICT Third-Party Providers (CTPPs) are subject to direct oversight by the European Supervisory Authorities (ESAs) under Articles 26-28.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-ict-third-party-cloud",
      "eu-gdpr-cloud-data-processing",
      "csa-ccm-v4-cloud-controls",
      "enisa-cloud-security-guidelines-2023",
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dora-ict-risk-management-articles-5-16",
    "title": "EU DORA Articles 5-16 ICT Risk Management Framework - ICT Risk Governance, Protection, Detection, Recovery and Communication for Financial Entities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Mandates that EU financial entities establish, maintain, and annually review a comprehensive, documented ICT risk management framework, with ultimate responsibility resting with the management body (Article 5), to ensure resilience against all types of ICT-related disruptions and threats across the protection, detection, response, and recovery lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "cpmi-iosco-cyber-resilience-fmi",
      "nis2-security-measures-article-21"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dora-ict-third-party-cloud",
    "title": "EU DORA Subcontracting Chain Provisions - ICT Third-Party Risk for Cloud and Managed Service Providers in Financial Services",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Under Article 30(3) of EU DORA, financial entities must ensure their contractual arrangements with ICT third-party service providers, such as cloud providers, explicitly govern the entire subcontracting chain, requiring prior notification of any changes and granting the financial entity the right to object to or terminate the contract based on such changes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "iso-27017-cloud-controls",
      "iso-22301-bcm-2019"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dora-ict-third-party-workflow-outsourcing",
    "title": "Regulation (EU) 2022/2554 on digital operational resilience for financial entities (DORA) - ICT Third-Party Risk in Automated Workflows: Contractual Requirements, Concentration Risk and Oversight of Critical Providers",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "DORA mandates financial entities to establish robust governance, risk assessment, and oversight mechanisms for ICT third-party service providers, particularly those supporting critical or important functions. Key obligations include contractual safeguards, concentration risk monitoring, and exit strategies as outlined in Article 29 and Article 30.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-directive-workflow-critical-operations",
      "eu-ai-act-automated-decision-workflows",
      "cobit-2019-governance-workflow-processes",
      "azure-logic-apps-enterprise-integration"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dora-its-register-of-information-2024-2956",
    "title": "Commission Implementing Regulation (EU) 2024/2956 - DORA Implementing Technical Standards for the standard templates for the register of information on ICT third-party arrangements",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This Commission Implementing Regulation lays down the standard templates that financial entities must use to maintain the DORA register of information on all contractual arrangements for the use of ICT services provided by ICT third-party service providers. Each template is a table with a predefined number of columns, the direct ICT third-party service provider is always ranked '1' in the ICT service supply chain, and financial entities must identify counterparties using a valid and active legal entity identifier (LEI) or the European Unique Identifier (EUID). The register data must satisfy data quality criteria of accuracy, completeness, consistency, integrity, uniformity and validity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-regulation-2022-2554-digital-operational-resilience-financial-sector",
      "eu-dora-2022-2554-article-28-ict-third-party-risk-management",
      "eu-dora-rts-ict-risk-management-framework-2024-1774"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-dora-regulation-2022-2554-digital-operational-resilience-financial-sector",
    "title": "EU DORA Regulation 2022/2554 - Digital Operational Resilience for Financial Sector Entities",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) became applicable on 17 January 2025. It imposes ICT risk management, incident reporting, digital operational resilience testing, and third-party ICT risk management obligations on approximately 22,000 EU financial entities including banks, insurers, investment firms, payment institutions, and crypto-asset service providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-directive-2022-2555-network-information-security"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dora-rts-ict-risk-management-framework-2024-1774",
    "title": "Commission Delegated Regulation (EU) 2024/1774 - Regulatory Technical Standards Specifying ICT Risk Management Tools, Methods, Processes, and Policies and the Simplified ICT Risk Management Framework (DORA Level 2 RTS, Articles 15 and 16(3))",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-06-25",
    "bluf": "Commission Delegated Regulation (EU) 2024/1774 of 13 March 2024 supplements DORA (Regulation (EU) 2022/2554) by setting out regulatory technical standards on the harmonised ICT risk management framework that financial entities must implement (Title II, under DORA Article 15) and the simplified ICT risk management framework for entities listed in DORA Article 16(1) (Title III, under DORA Article 16(3)). Adopted under DORA Article 15 fourth subparagraph and Article 16(3) fourth subparagraph and published in the Official Journal on 25 June 2024 (entering into force 20 days after publication), the RTS imposes proportionality (Article 1 - five elements: encryption/cryptography, ICT operations security, network security, ICT project and change management, impact on data confidentiality/integrity/availability and continuity). Title II Chapter I covers ICT security policies, procedures, protocols and tools (Article 2), the ICT risk management framework (Article 3), ICT asset management policy and procedure (Articles 4-5), encryption and cryptographic controls including post-quantum considerations (Article 6) and cryptographic key management (Article 7), policies and procedures for ICT operations (Article 8), capacity and performance management (Article 9), vulnerability and patch management with responsible disclosure (Article 10), data and system security (Article 11), logging (Article 12), network security management (Article 13), securing information in transit (Article 14), ICT project management with reporting to the management body (Article 15), ICT systems acquisition, development and maintenance including source-code review (Article 16), ICT change management with separation of approval/request/implementation duties and fall-back procedures (Article 17), physical and environmental security (Article 18), human resources policy (Article 19), identity management with unique identification (Article 20), and access control (Article 21). Chapter II adds ICT-related incident management policy (Article 22) and anomalous activities detection criteria (Article 23). Chapter III sets ICT business continuity policy components (Article 24), business continuity plan testing (Article 25), and ICT response and recovery plans (Article 26). Article 27 specifies the format and content of the management body's annual report on the ICT risk management framework review. Title III (Articles 28-41) sets the simplified framework for Article 16 entities, covering governance, information security policy, classification of information assets, ICT risk management, physical and environmental security, access control, ICT operations security, data/system/network security, ICT security testing, ICT systems acquisition/development/maintenance, ICT project and change management, business continuity components, and business continuity plan testing. Article 42 sets entry into force at 20 days after OJ publication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "dora_level_1",
        "gdpr",
        "iso_iec_27001_2022",
        "nist_csf_2_0",
        "european_standardisation_regulation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-articles-28-44-third-party-ict-risk",
      "eu-dora-rts-ict-third-party-policy-2024-1773",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 15
  },
  {
    "node_id": "eu-dora-rts-ict-third-party-policy-2024-1773",
    "title": "Commission Delegated Regulation (EU) 2024/1773 - Regulatory Technical Standards on the Detailed Content of the Policy Regarding Contractual Arrangements on the Use of ICT Services Supporting Critical or Important Functions Provided by ICT Third-Party Service Providers (DORA Level 2 RTS, Article 28(10))",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-06-25",
    "bluf": "Commission Delegated Regulation (EU) 2024/1773 of 13 March 2024 supplements DORA (Regulation (EU) 2022/2554) by setting out regulatory technical standards on the detailed content of the policy that financial entities must adopt regarding contractual arrangements on the use of ICT services supporting critical or important functions provided by ICT third-party service providers. Adopted under DORA Article 28(10) third subparagraph and published in the Official Journal on 25 June 2024 (entering into force 20 days after publication), the RTS treats ICT intra-group service providers and subcontractors that provide material parts of critical or important functions as ICT third-party service providers (Recital 5). The RTS requires financial entities to: tailor the policy to entity size, risk profile, and complexity using ten enumerated factors (Article 1: type of ICT service, provider location, third-country status, data nature, group affiliation, EU/third-country authorisation, oversight framework status, concentration, transferability, business continuity impact); apply the policy consistently across groups (Article 2); establish governance with at-least-annual management body review (Article 3(1)) and an identified senior management role for contractual oversight (Article 3(5)); cover six lifecycle phases (Article 4: management body responsibilities, planning, business unit involvement, implementation/monitoring, documentation/record-keeping, exit); conduct an ex-ante risk assessment covering nine specific risk categories (Article 5: operational, legal, ICT, reputational, data protection, data availability, data location, provider location, ICT concentration); perform due diligence on six assessment criteria (Article 6); identify and manage conflicts of interest (Article 7); include the elements of DORA Article 30(2) and (3) plus audit and inspection rights in contractual clauses (Article 8); monitor performance via KPIs/KCIs and incident notification (Article 9); and maintain a documented, periodically tested exit plan covering unforeseen interruptions, failed delivery, and unexpected termination (Article 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "dora_level_1",
        "gdpr",
        "dora_ict_risk_framework",
        "esma_eba_eiopa_consultation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-articles-28-44-third-party-ict-risk",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-dora-rts-incident-classification-2024-1772",
    "title": "Commission Delegated Regulation (EU) 2024/1772 - Regulatory Technical Standards Specifying the Criteria for the Classification of ICT-Related Incidents and Cyber Threats, Setting Out Materiality Thresholds and Specifying the Details of Reports of Major Incidents (DORA Level 2 RTS, Article 18(4))",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-06-25",
    "bluf": "Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 supplements DORA (Regulation (EU) 2022/2554) by setting out regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, the materiality thresholds for determining major incidents, the high materiality thresholds for determining significant cyber threats, and the details of reports of major incidents. Adopted under DORA Article 18(4) third subparagraph and published in the Official Journal on 25 June 2024. Chapter I (Articles 1-7) defines the seven classification criteria: (1) clients, financial counterparts and transactions; (2) reputational impact; (3) duration and service downtime; (4) geographical spread; (5) data losses; (6) criticality of services affected; (7) economic impact. Chapter II (Articles 8-9) defines major incidents and their materiality thresholds. Per Article 8(1), an incident is a major incident where it has affected critical services per Article 6 AND either (a) the data losses threshold in Article 9(5)(b) is met, OR (b) two or more of the other materiality thresholds in Articles 9(1)-(6) are met. Article 8(2) treats recurring incidents (≥2 occurrences in 6 months with the same apparent root cause per DORA Art 20(b)(i)) collectively as one major incident; this rule does not apply to microenterprises or Article 16(1) entities. Article 9 sets the specific numeric thresholds: clients/counterparts/transactions threshold (Art 9(1)) - >10% of clients OR >100,000 affected clients OR >30% of financial counterparts OR >10% of daily transaction count OR >10% of daily transaction value OR affected clients/counterparts identified as relevant per Article 1(3); reputational impact threshold (Art 9(2)) - any condition in Article 2(a)-(d); duration and downtime (Art 9(3)) - incident duration >24 hours OR service downtime >2 hours for ICT services supporting critical or important functions; geographical spread (Art 9(4)) - impact in 2+ Member States; data losses (Art 9(5)) - adverse impact on business objectives/regulatory compliance OR successful unauthorised access; economic impact (Art 9(6)) - costs and losses exceed or likely to exceed €100,000. Chapter III (Article 10) defines a significant cyber threat as one where (a) it could affect critical/important functions of the entity or others, AND (b) it has a high probability of materialisation considering applicable vulnerabilities, threat actor capabilities and intent, and similar incidents at financial or non-financial entities. Chapter IV (Articles 11-12) covers cross-border relevance and details to be shared with competent authorities in other Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "dora_level_1",
        "psd2_security_incident",
        "nis2_directive",
        "gdpr_breach_notification",
        "ecb_target_incidents"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-articles-28-44-third-party-ict-risk",
      "eu-dora-rts-ict-risk-management-framework-2024-1774",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "eu-dora-rts-incident-reporting-2025-301",
    "title": "Commission Delegated Regulation (EU) 2025/301 supplementing Regulation (EU) 2022/2554 with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This DORA regulatory technical standard sets the content and time limits for reporting major ICT-related incidents: an initial notification within four hours of classification (and no later than 24 hours from awareness), an intermediate report within 72 hours, and a final report no later than one month, and it specifies the content of the voluntary notification for significant cyber threats; it supplements DORA Article 20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dora-incident-reporting-articles-17-23",
      "dora-regulation-article-10-detection",
      "dora-regulation-article-11-response-recovery"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dora-rts-subcontracting-ict-2025-532",
    "title": "Commission Delegated Regulation (EU) 2025/532 supplementing Regulation (EU) 2022/2554 with regard to regulatory technical standards specifying the elements a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This DORA regulatory technical standard sets the elements a financial entity must determine and assess before and during the subcontracting of ICT services that support critical or important functions, including due diligence on the ICT provider's ability to oversee subcontractors, risk assessment of the subcontracting chain, equivalent access and audit rights down the chain, and termination rights where unapproved material changes occur; it supplements DORA Article 30(5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-2022-2554-article-28-ict-third-party-risk-management",
      "dora-ict-risk-management-articles-5-16",
      "dora-regulation-article-13-learning-evolving"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-dora-rts-tlpt-2025-1190",
    "title": "Commission Delegated Regulation (EU) 2025/1190 supplementing Regulation (EU) 2022/2554 with regard to regulatory technical standards specifying the criteria for identifying financial entities required to perform threat-led penetration testing (TLPT)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This DORA regulatory technical standard sets the criteria by which TLPT authorities identify the financial entities required to perform threat-led penetration testing, combining size and systemic-importance thresholds with a qualitative assessment of ICT risk profile, and specifies the governance of testing including a control team, test managers, an active red team testing phase of at least 12 weeks, and external tester involvement; it supplements DORA Article 26(11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dora-ict-risk-management-articles-5-16",
      "eu-dora-2022-2554-article-28-ict-third-party-risk-management",
      "dora-incident-reporting-articles-17-23"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-drinking-water-directive-2020-2184-construction",
    "title": "Directive (EU) 2020/2184 of the European Parliament and of the Council of 16 December 2020 on the quality of water intended for human consumption",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive establishes requirements for materials and products in contact with drinking water, including mandatory positive lists, migration testing, and installation standards to prevent contamination. It applies to manufacturers, importers, and installers of construction products used in drinking water systems under Article 10 and Annex II.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-19650-bim-information-management-construction",
      "iso-9001-2015-quality-management-construction",
      "eu-circular-economy-construction-demolition-waste-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-drinking-water-directive-2020-2184-quality-standards",
    "title": "EU Drinking Water Directive 2020/2184 - Quality Standards, Risk Assessment, and Access to Water",
    "domain": "Energy & Utilities",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Drinking Water Directive (DWD) 2020/2184 (recast) establishes binding parametric values for 33 microbiological and chemical parameters and 26 indicator parameters for water intended for human consumption; introduces a risk-based approach (supply chain risk assessment + domestic distribution risk assessment) aligned with WHO Water Safety Plans; requires member states to ensure at least 99% of the population has access to safe drinking water; creates obligations for water suppliers to provide online access to real-time water quality data; and introduces specific obligations for large food business operators and water suppliers serving more than 50,000 consumers. Transposition deadline: 12 January 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-energy-union-governance-regulation-2018-1999",
      "eu-energy-efficiency-directive-2023-article-11-audits"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-drinking-water-directive-2020-2184-recast",
    "title": "Directive (EU) 2020/2184 of the European Parliament and of the Council of 16 December 2020 on the quality of water intended for human consumption (recast)",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Directive (EU) 2020/2184 recasts Council Directive 98/83/EC to protect human health from contamination of water intended for human consumption and to improve access to such water across the Union. It lays down minimum Union requirements, including parametric values for microbiological, chemical, and indicator parameters. New parametric values are introduced for enteric pathogens, Legionella, and six chemical parameters or parameter groups; for lead, a transitional period of 15 years applies before a more stringent value of 5 μg/l becomes effective, with an aspirational target for existing domestic distribution systems. A complete risk-based approach covering the whole supply chain must be implemented, comprising three components: risk assessment of catchment areas for abstraction points, risk assessment of the supply system, and risk assessment of domestic distribution systems, with special focus on priority premises such as hospitals and schools. For materials in contact with drinking water, the Directive establishes minimum hygiene requirements, European positive lists for starting substances and constituents managed with the involvement of the European Chemicals Agency (ECHA), and testing standards to be developed by CEN. A watch list mechanism for emerging compounds such as endocrine disruptors and pharmaceuticals is introduced. Member States must establish monitoring programmes for compliance; in case of non-compliance, immediate investigation and remedial action is required, with supply prohibition or restriction if there is a potential danger to human health. Exemptions for small water suppliers (10-100 m³/day or 50-500 people) from supply system risk assessment are allowed. Derogations are permitted under certain conditions provided no danger to human health. Consumer information obligations are strengthened, requiring online access to up-to-date monitoring results, exceedances, treatment details, and leakage rates for larger suppliers. Member States must take actions to improve access to water for all, particularly for vulnerable and marginalised groups. Reporting obligations to the Commission and the European Environment Agency (EEA) are established. The Directive respects the Charter of Fundamental Rights and aims at environmental and health protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-drivers-driving-time-regulation-561-2006",
    "title": "Regulation (EC) No 561/2006 of the European Parliament and of the Council of 15 March 2006 on the harmonisation of certain social legislation relating to road transport (drivers driving times, breaks and rest periods)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation harmonises rules on driving times, breaks and rest periods for drivers engaged in the carriage of goods and passengers by road (Article 1). Daily driving time must not exceed nine hours, extendable to ten hours at most twice a week; weekly driving must not exceed 56 hours, and driving over any two consecutive weeks must not exceed 90 hours (Article 6). A driver must take an uninterrupted break of at least 45 minutes after four and a half hours of driving (Article 7), and daily and weekly rest periods under Article 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tachograph-regulation-165-2014",
      "iso-39001-road-traffic-safety-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-driving-licence-directive-2006-126",
    "title": "Directive 2006/126/EC of the European Parliament and of the Council of 20 December 2006 on driving licences",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive establishes a Community model driving licence (Article 1), provides for mutual recognition of driving licences issued by Member States (Article 2), and sets anti-forgery measures (Article 3). It defines the licence categories, their definitions and minimum ages (Article 4), and conditions for issue, validity and renewal including passing theoretical and practical tests and meeting medical standards (Article 7), with rules on the exchange, withdrawal, replacement and recognition of licences (Article 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-road-traffic-act-1988",
      "iso-39001-road-traffic-safety-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-drone-operations-regulation-2019-947",
    "title": "Commission Delegated Regulation (EU) 2019/947 of 12 March 2019 on the rules and procedures for the operation of unmanned aircraft",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the operational framework for drone flights in the EU under three categories: Open, Specific, and Certified. It mandates remote pilot registration for drones over 250g, defines competency requirements for subcategories A1/A2/A3, requires operational authorisation for Specific category flights, and introduces the Light UAS Operator Certificate (LUC) for qualified operators. Key provisions are detailed in Articles 6-14 and Annexes I-V.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "easa-ai-roadmap-2023",
      "as9100-rev-d-qms",
      "iso-27017-cloud-defence"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dsa-article-28-online-protection-of-minors",
    "title": "EU Digital Services Act Article 28 - Online Protection of Minors (Regulation 2022/2065, Profiling-Based Advertising Ban, Appropriate Measures, No Additional Personal Data)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Article 28 of Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market for Digital Services (the Digital Services Act, DSA) imposes three operative obligations on providers of online platforms accessible to minors: (1) under Article 28(1), providers must put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security of minors on their service; (2) under Article 28(2), providers must not present advertisements on their interface based on profiling as defined in Article 4(4) of Regulation (EU) 2016/679 (GDPR) using personal data of the recipient of the service when they are aware with reasonable certainty that the recipient of the service is a minor; (3) under Article 28(3), compliance with these obligations shall not oblige providers of online platforms to process additional personal data in order to assess whether the recipient of the service is a minor. Article 28 applies to all online platforms accessible to minors regardless of size, not only to Very Large Online Platforms (VLOPs) under Article 33. The European Commission may issue guidelines under Article 28 to assist providers in applying the appropriate measures obligation; Commission guidelines on the protection of minors under Article 28 were adopted in 2025. Enforcement is by the Digital Services Coordinator of the establishment Member State under Article 49 and by the Commission for VLOPs under Article 56(2). Penalties under Article 52 may reach up to 6% of the provider's annual worldwide turnover for the preceding financial year. The Article 28 obligation is additional to (and may overlap with) GDPR Article 8 (consent of a child in relation to information society services), the Audiovisual Media Services Directive (Directive 2010/13/EU as amended by Directive 2018/1808) provisions on protection of minors from harmful content, and national-law transpositions of those directives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "article_28_text",
        "scope_of_application",
        "commission_guidelines_power",
        "enforcement_taxonomy",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-10-data-governance-training",
      "eu-gdpr-article-22-automated-decision-making-profiling",
      "eu-avmsd-2018-1808-article-6a-minors-protection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-dsa-illegal-content-trusted-flaggers",
    "title": "Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and Amending Directive 2000/31/EC (Digital Services Act)",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Online platforms must establish a transparent, accessible notice and action mechanism for reporting illegal content under Article 16, prioritize notices from trusted flaggers designated under Article 20, ensure human review of automated content moderation decisions under Article 18, and provide users with a complaint handling system and right to appeal to a dispute settlement body under Article 21. Applies to intermediary service providers, especially online platforms and hosting services operating in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "dmca-safe-harbor",
      "berne-convention-1886-2024-literary-artistic-works",
      "iptc-photo-metadata",
      "exif-standard-metadata"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dsa-platform-obligations-gaming-2022",
    "title": "Regulation (EU) 2022/2065 on a Single Market for Digital Services (Digital Services Act)",
    "domain": "Gaming & Gambling",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The DSA obliges gaming platforms that provide intermediary services to remove illegal content, prohibit targeted advertising to minors, disclose algorithmic recommendation logic, and, if classified as Very Large Online Platforms (VLOPs), undergo independent audits (Article X - obligations for VLOPs).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "india-meity-online-gaming-rules-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dsm-directive-text-data-mining-education",
    "title": "Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market and amending Directives 96/9/EC and 2001/29/EC (Text with EEA relevance)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This Directive establishes mandatory exceptions to copyright for text and data mining (TDM) in research and educational contexts. Article 3 permits TDM by research organisations and cultural heritage institutions for scientific research, while Article 4 allows TDM for any purpose if content is lawfully accessed, subject to rightsholders' opt-out. It applies to universities, research bodies, and educational platforms using digital content mining technologies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-2019-790-text-data-mining",
      "allea-european-code-research-integrity-2023",
      "eu-digital-education-action-plan-2021-2027-deap",
      "eu-european-research-area-policy-agenda-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dual-use-control-list-update-2025-2003",
    "title": "Commission Delegated Regulation (EU) 2025/2003 of 8 September 2025 amending Regulation (EU) 2021/821 of the European Parliament and of the Council as regards the list of dual-use items",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "This Delegated Regulation replaces Annex I (the EU control list of dual-use items) of Regulation (EU) 2021/821 to align it with the changes adopted in 2024 by the multilateral export control regimes (Wassenaar Arrangement, Nuclear Suppliers Group, Missile Technology Control Regime, Australia Group, and Chemical Weapons Convention), and entered into force on the day following its publication on 14 November 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dual-use-regulation-2021-821",
      "us-export-control-reform-act-2018",
      "uk-export-control-act-2002"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-dual-use-regulation-2021-821",
    "title": "Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes a comprehensive EU-wide framework for controlling the export, brokering, technical assistance, transit, and transfer of dual-use items, including both tangible goods and intangible technology transfers. It applies to all natural and legal persons within the EU and requires prior authorization for listed items under Annex I, as well as catch-all controls for items not listed but intended for weapons of mass destruction or military use under Article 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-deforestation-regulation-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-dublin-iii-regulation-604-2013-asylum-responsibility",
    "title": "EU Dublin III Regulation 604/2013 - Member State Responsibility for Asylum Applications and Take Charge/Take Back Procedures",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "Regulation (EU) No 604/2013 of the European Parliament and of the Council of 26 June 2013 establishing the criteria and mechanisms for determining the Member State responsible for examining an application for international protection lodged in one of the Member States by a third-country national or a stateless person (Dublin III Regulation) is the third iteration of the Dublin system, replacing Council Regulation (EC) No 343/2003. The Regulation establishes a hierarchy of criteria in Chapter III (Articles 7-17) to determine which Member State is responsible for examining an asylum application, with the aim of preventing 'asylum shopping' (multiple applications) and 'refugees in orbit' (no Member State accepting responsibility). Article 3(2) introduces the principle that asylum-seekers cannot be transferred to a Member State where there are substantial grounds for believing they would face inhuman or degrading treatment within the meaning of Article 4 of the Charter of Fundamental Rights of the European Union. Articles 21-30 set out detailed procedures for take-charge (initial responsibility transfer) and take-back (return after lodging elsewhere) requests, with strict time limits. The proposed Pact on Migration and Asylum 2024 will reform the system into a Common European Asylum System with a new Asylum and Migration Management Regulation replacing Dublin III.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-refugee-convention-1951-protocol-1967-non-refoulement",
      "germany-residence-act-aufenthaltsgesetz-2004-bamf"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-e-evidence-legal-representatives-directive-2023-1544",
    "title": "Directive (EU) 2023/1544 of the European Parliament and of the Council of 12 July 2023 laying down harmonised rules on the designation of designated establishments and the appointment of legal representatives for the purpose of gathering electronic evidence in criminal proceedings",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive lays down harmonised rules on the designation of designated establishments and the appointment of legal representatives by service providers offering services in the Union, for the purpose of receiving, complying with and enforcing decisions and orders for the gathering of electronic evidence in criminal proceedings (Article 1). Service providers established in the Union must designate at least one establishment, and providers not established in the Union must appoint at least one legal representative, in the Member States where they offer services (Article 3), with notification and language obligations (Article 4), penalties for non-compliance (Article 5), and designated central authorities (Article 6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-european-production-orders-e-evidence-regulation-2023-1543",
      "cyber-nist-csf-2"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-e-money-directive-2009-110",
    "title": "EU E-Money Directive 2009/110/EC - Second E-Money Directive (EMD2) Electronic Money Institution Framework",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Directive 2009/110/EC of the European Parliament and of the Council of 16 September 2009 on the taking up, pursuit and prudential supervision of the business of electronic money institutions (the Second E-Money Directive, EMD2), repealing and replacing Directive 2000/46/EC, establishes the legal framework for electronic money institutions (EMIs) in the European Economic Area. EMD2 defines electronic money (e-money) as electronically stored monetary value represented by a claim on the issuer which is issued on receipt of funds and accepted by a natural or legal person other than the issuer. EMD2 establishes initial capital requirements of €350,000, ongoing own funds requirements (2% of average outstanding e-money), safeguarding obligations for client funds, passporting rights, and prudential supervision by national competent authorities. EMD2 introduced waiver provisions for small e-money issuers and established the principle that e-money issuers must redeem e-money at par value at any time. EMD2 has been substantially modified by PSD2 (Directive 2015/2366) in respect of payment services conducted by e-money institutions, and is being transitioned within the EU3 regulatory framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_psd2_payment_services",
        "eu_mica_regulation",
        "eu_aml_directives"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-psd2-strong-customer-authentication",
      "eu-mica-regulation-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-easa-basic-regulation-2018-1139-common-rules-civil-aviation",
    "title": "EU EASA Basic Regulation 2018/1139 - Common Rules for Civil Aviation Safety",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "Regulation (EU) 2018/1139 (EASA Basic Regulation) establishes the common rules for civil aviation safety in the EU and defines the role of the European Union Aviation Safety Agency (EASA). It covers airworthiness, environmental compatibility, pilot licensing, air operations, aerodromes, air traffic management, unmanned aircraft systems (UAS/drones), and third-country operators. Member States' competent authorities implement EASA regulations through national oversight, while EASA acts as the EU-level safety authority with certification, standardisation inspection, and enforcement powers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-chicago-convention-1944-civil-aviation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-easa-regulation-2042-2003-part-m-continuing-airworthiness",
    "title": "EU EASA Regulation 2042/2003 Part-M - Continuing Airworthiness Management & Maintenance",
    "domain": "Aviation, Defense & Quantum",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "EASA Regulation 2042/2003 Part-M (now Commission Regulation 1321/2014) establishes continuing airworthiness requirements for all EU-registered aircraft - covering maintenance programme approval, airworthiness review certificates, component management, and CAMO (Continuing Airworthiness Management Organisation) approval.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-eba-cloud-outsourcing-guidelines-2019",
    "title": "EU EBA Guidelines on Cloud Outsourcing 2019 - Banking Cloud Procurement: Critical vs Non-Critical Function Classification, SLA Minimum Requirements, Right of Access for Competent Authorities, Exit Strategy, Sub-Outsourcing Approval and Register of Outsourcing Arrangements",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "These EBA Guidelines apply to credit institutions, investment firms under CRD, and payment/e-money institutions, requiring robust governance of outsourcing arrangements, including cloud services. Key obligations include classification of critical or important functions (Guideline 1), SLA requirements (Guideline 5), exit strategies (Guideline 7), sub-outsourcing controls (Guideline 8), and maintenance of an outsourcing register (Guideline 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-ict-third-party-cloud",
      "eu-gdpr-cloud-data-processing",
      "csa-ccm-v4-cloud-controls"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-eba-mica-guidelines-art-emt-authorisation",
    "title": "EBA Guidelines and Technical Standards under MiCA for Asset-Referenced and E-Money Token Issuers - Governance, Own Funds, Recovery Plans (EBA/GL/2024/07) and Redemption Plans (EBA/GL/2024/13)",
    "domain": "Crypto & Sovereign Finance",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "Issuers of Asset-Referenced Tokens (ARTs) and E-Money Tokens (EMTs) under MiCA (Regulation (EU) 2023/1114) must meet authorisation, governance, own-funds, recovery-plan and redemption-plan requirements. The content of an ART authorisation application (including governance arrangements, suitability of the management body, qualifying holdings and own funds) is set out in the regulatory technical standards adopted under Article 18(6) of MiCA. Recovery plans are governed by the EBA Guidelines on recovery plans under Articles 46 and 55 of MiCA (EBA/GL/2024/07), and redemption plans by the EBA Guidelines on redemption plans under Articles 47 and 55 of MiCA (EBA/GL/2024/13). The prior single citation to EBA/GL/2024/04 was incorrect: EBA/GL/2024/04 concerns the resubmission of historical data and is unrelated to ART/EMT authorisation, recovery or redemption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mica-regulation-2023",
      "eu-mica-asset-referenced-tokens",
      "eu-mica-e-money-tokens"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-eba-srep-guidelines-2018",
    "title": "EU EBA SREP Guidelines 2018 (EBA/GL/2018/03) - Supervisory Review and Evaluation Process",
    "domain": "Banking & Global Finance",
    "version": "2023.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The European Banking Authority's SREP Guidelines (EBA/GL/2018/03, updated 2023) establish a common EU-wide methodology for competent authorities to assess banks' business model viability, internal governance, capital adequacy (Pillar 2 requirement), and liquidity adequacy through annual supervisory review and evaluation, with outcomes including Pillar 2 capital add-ons, liquidity measures, and early intervention triggers under the BRRD.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "crd_iv",
        "basel_iii",
        "brrd",
        "eu_eba_stress"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-brrd-bank-recovery-resolution-directive-2014-59",
      "basel-iii-capital",
      "eu-irrbb-bcbs-standards-2016"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ec-merger-implementing-regulation-1269-2013",
    "title": "Commission Implementing Regulation (EU) No 1269/2013 of 5 December 2013 amending Regulation (EC) No 802/2004 implementing Council Regulation (EC) No 139/2004 on the control of concentrations between undertakings",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation specifies the procedural rules and information requirements for notifying mergers and acquisitions to the European Commission. It defines the content of the mandatory notification forms (Form CO and Short Form CO) and sets out the criteria for transactions eligible for the simplified merger review procedure, as detailed in its Annexes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-merger-regulation-139-2004-ecmr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ec-merger-regulation-139-2004-article-2-concentrations-appraisal",
    "title": "Council Regulation (EC) No 139/2004 - Article 2: Appraisal of concentrations",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must appraise concentrations falling within the scope of this Regulation to establish their compatibility with the common market, in accordance with the Regulation's objectives and provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ecall-regulation-2015-758-in-vehicle-emergency-call",
    "title": "EU eCall Regulation 2015/758 - In-Vehicle Emergency Call System Requirements",
    "domain": "Automotive & Mobility",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Regulation 2015/758 mandates type-approval of pan-European eCall via 112 in all new M1/N1 passenger vehicles (≤3.5t) produced from 31 March 2018. On-board system must transmit Minimum Set of Data (MSD) including GNSS position (±150m accuracy), vehicle type, fuel, number of passengers, and direction of travel within 10 seconds of airbag deployment or manual trigger. Privacy mandated: eCall system may not transmit location data during normal driving; MSD deleted within 26 seconds after call completion; data not retained or transferable to third parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_framework",
        "regulatory_mapping",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-general-safety-regulation-2019-2144-vehicles",
      "eu-type-approval-framework-regulation-2018-858"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ecb-digital-euro-investigation-phase-2024",
    "title": "ECB Digital Euro Investigation Phase 2024 - Design Decisions: Offline Functionality, Privacy by Design (Anonymity for Low-Value), Holding Limits, Waterfall Mechanism to Bank Accounts, EPI Distribution Role and ECB Regulation Proposal",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The digital euro would be a central bank-issued digital currency, available free of charge and accessible to all in the euro area, designed to complement cash and coexist with private payment solutions. It would support offline payments, ensure high privacy standards, and be subject to holding limits to mitigate financial stability risks, as outlined in the ECB's investigation phase updates through 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cbdc-digital-euro-legislative-proposal-2023",
      "bis-project-mariana-cbdc-wholesale-fx-2023",
      "iso-20022-mx-messaging"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ecn-plus-directive-2019-nca-powers",
    "title": "EU ECN+ Directive 2019/1 - Empowering National Competition Authorities",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Directive (EU) 2019/1 (ECN+ Directive) requires EU Member States to equip their national competition authorities (NCAs) with the independence, resources, and enforcement tools necessary to apply Articles 101 and 102 TFEU effectively. NCAs must be able to impose fines up to 10% of an undertaking's total worldwide turnover, conduct unannounced inspections, grant immunity or reduction under leniency programmes, and award interim measures. The Directive ensures a level playing field for competition enforcement across the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_1_2003",
        "tfeu_101_102",
        "national_transposition",
        "eu_merger_regulation",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-competition-regulation-1-2003",
      "eu-tfeu-article-101-cartels-prohibition",
      "eu-tfeu-article-102-abuse-dominance"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ecodesign-regulation-2009-125-energy-products",
    "title": "Directive 2009/125/EC of the European Parliament and of the Council of 21 October 2009 establishing a framework for the setting of ecodesign requirements for energy-related products (recast)",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive establishes a framework for setting mandatory ecodesign requirements for energy-related products placed on the EU market, aiming to reduce their environmental impact throughout their lifecycle. It applies to manufacturers, importers, and distributors of such products under Article 16 and implementing measures adopted pursuant to Article 15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-radio-equipment-directive-2014-53-iot",
      "eu-pressure-equipment-directive-2014-68",
      "eu-atex-directive-2014-34-explosive-atmosphere",
      "etsi-en-303-645-iot-cybersecurity-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ecodesign-regulation-2024-1781",
    "title": "EU Ecodesign for Sustainable Products Regulation (EU) 2024/1781 (ESPR)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Regulation (EU) 2024/1781 (the Ecodesign for Sustainable Products Regulation ESPR) replaces Directive 2009/125/EC providing a framework for setting ecodesign requirements for almost all physical products placed on the EU market. The Regulation expands beyond energy-related products to include textiles furniture mattresses tyres detergents paint chemicals. Delegated Acts will set product-specific requirements covering durability reusability repairability upgradability presence of substances of concern recyclability recycled content carbon footprint environmental footprint. Key innovations: Digital Product Passport (DPP) mandatory across product groups; ban on destruction of unsold consumer goods (apparel and footwear effective 19 July 2026); public procurement criteria.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ecodesign-regulation-2024-sustainable-products",
    "title": "Regulation (EU) 2024/1781 on ecodesign for sustainable products and repealing Directive 2009/125/EC",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Sustainable Products Regulation 2024 establishes mandatory ecodesign requirements for a wide range of products sold in the EU, including digital product passports, repairability and durability mandates, and bans on destroying unsold durable goods. It applies to manufacturers, importers, and distributors placing relevant products on the EU market under Article 5 and Article 18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29",
      "eu-ecommerce-directive-2000-31",
      "eu-geo-blocking-regulation-2018-302",
      "ifrs-s2-climate",
      "eu-data-governance-act-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ecodesign-regulation-energy-related-products-2009",
    "title": "Directive 2009/125/EC of the European Parliament and of the Council of 21 October 2009 establishing a framework for the setting of ecodesign requirements for energy-related products (recast)",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a framework to improve the environmental performance of energy-related products by setting mandatory ecodesign requirements, focusing on energy efficiency, material use, and lifecycle impacts. It applies to manufacturers, importers, and distributors placing industrial pumps, motors, transformers, and process equipment on the EU market, with key obligations under Article 16 for implementing measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecodesign-regulation-2009-125-energy-products",
      "eu-cyber-resilience-act-iot-2024-products",
      "eu-data-act-2023-iot-data-sharing-obligations",
      "etsi-en-303-645-iot-cybersecurity-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ecodesign-sustainable-products-regulation-2024-1781",
    "title": "Regulation (EU) 2024/1781 - Ecodesign for Sustainable Products Regulation (ESPR): Digital Product Passport, Durability/Repairability Minimum Requirements, Destruction of Unsold Products Ban, and Priority Product Category Framework to Replace Directive 2009/125/EC",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2024/1781 (Ecodesign for Sustainable Products Regulation, ESPR), applicable from 18 July 2024, replaces Directive 2009/125/EC (Ecodesign Directive) and creates a horizontal framework for setting ecodesign requirements for almost all physical products sold in the EU market; key mechanisms include: mandatory Digital Product Passport (DPP) containing life-cycle data on materials, repairability, recyclability, and environmental footprint, accessible via QR code or RFID; delegated regulations setting product-specific minimum performance requirements for durability, reliability, reusability, upgradeability, reparability, maintenance, and end-of-life treatment; a ban on destruction of unsold consumer textiles and footwear from 19 July 2026 (SME exemption until 2030); priority product categories for first delegated acts include textiles, furniture, electronics, iron/steel, aluminium, and tyres; Green Public Procurement (GPP) criteria linked to ESPR product requirements; Member State market surveillance and penalties for non-compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_CRMA",
        "EU_BATTERIES",
        "EU_TAXONOMY",
        "EU_REACH"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-critical-raw-materials-act-2024-1252",
      "eu-batteries-regulation-2023-1542-ev",
      "eu-taxonomy-regulation-2020-852",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ecodesign-tyre-labelling-regulation-2020-740",
    "title": "Regulation (EU) 2020/740 of the European Parliament and of the Council of 18 May 2020 on energy labelling of tyres, amending Regulation (EU) 2017/1377 and repealing Regulation (EC) No 1222/2009",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation mandates that all new tyres placed on the EU market must display standardized labels indicating performance in wet grip, rolling resistance, and external rolling noise. It applies to manufacturers, importers, and distributors of C1, C2, C3, and B-class tyres, as specified in Article 3 and Annexes I-VII.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "iso-26262-functional-safety-road-vehicles-2018",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ecommerce-directive-2000-31",
    "title": "Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market ('Directive on electronic commerce')",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This directive establishes the 'country of origin' principle for online services in the EU, meaning providers are subject to the laws of the Member State where they are established, not where the service is accessed (Article 3). It also sets harmonized rules for provider transparency, commercial communications (e.g., spam), electronic contracts, and limits the liability of intermediary service providers (caching, hosting).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eprivacy-cookie-directive",
      "eu-consumer-rights-directive-2011",
      "eu-omnibus-directive-2019-2161"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ecommerce-directive-2000-31-platform-liability",
    "title": "Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market ('Directive on electronic commerce')",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive establishes limited liability for intermediary service providers (e.g., hosting platforms) when they act as mere conduits, cache, or hosts, provided they do not initiate transmissions, select recipients, or modify content (Article 12-14). It applies to all information society service providers operating within the EU, particularly those hosting user-generated content, and mandates transparency in commercial communications (Article 5) and electronic contract formation (Article 9-11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecommerce-directive-2000-31",
      "eu-eprivacy-directive-2002-58",
      "eu-unfair-commercial-practices-2005-29",
      "eprivacy-cookie-directive",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ecommerce-directive-article-6-commercial-communications-identification",
    "title": "EU e-Commerce Directive 2000/31/EC Article 6 Information Requirements for Commercial Communications",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Directive 2000/31/EC Article 6 requires that commercial communications forming part of or constituting an information society service must be clearly identifiable as commercial, identify the legal or natural person on whose behalf they are made, and disclose any promotional offers or competitions clearly and unambiguously with easily accessible conditions - forming the baseline transparency obligation for all digital marketing and commercial content in the EU single market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-eecc-2018-1972-electronic-communications-code",
    "title": "Directive (EU) 2018/1972 of the European Parliament and of the Council of 11 December 2018 establishing the European Electronic Communications Code",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes a harmonised framework for the regulation of electronic communications networks and services across the EU, imposing obligations on providers concerning market access, interconnection, and end-user rights, including detailed contract requirements and rights to switch providers (Article 102). It requires providers to take appropriate technical and organisational measures to manage security risks to their networks and services (Article 40).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-eecc-end-user-rights-universal-service",
    "title": "Directive (EU) 2018/1972 (European Electronic Communications Code) - Title III, Chapter V: End-User Rights",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The European Electronic Communications Code (EECC), under Articles 102 to 115, mandates that providers of public electronic communications services grant specific rights to end-users, including transparent contract information, simplified provider switching with number portability, minimum service quality levels, and reliable access to emergency services through the single European emergency number '112'.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-eecc-spectrum-peer-review-5g-2023",
    "title": "EU 5G Spectrum Peer Review 2023 - RSPG Findings on Pioneer Bands (700 MHz, 3.5 GHz, 26 GHz): Authorisation Timelines, Licence Conditions for Coverage Obligations, Outdoor-to-Indoor Propagation and Coexistence with Incumbent Services",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This RSPG 2023 peer review report provides non-binding guidance to EU Member States on harmonised spectrum authorisation timelines, coverage obligations, and technical conditions for 5G pioneer bands (700 MHz, 3.5 GHz, 26 GHz), with emphasis on ensuring outdoor-to-indoor propagation and coexistence with incumbent services. It applies to national regulatory authorities (NRAs) and spectrum management bodies overseeing 5G deployment under Article 8 and Article 9 of Directive (EU) 2018/1972 (EECC).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-radio-spectrum-policy-programme-decision",
      "eu-eecc-spectrum-small-area-wireless-access",
      "eu-5g-cybersecurity-toolbox-2020",
      "3gpp-5g-nr-release-17-specifications"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-eecc-spectrum-small-area-wireless-access",
    "title": "Directive (EU) 2018/1972 Article 57: Deployment and operation of small-area wireless access points",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "This regulation mandates that EU Member States must allow the deployment of small-area wireless access points (SAWAPs) that meet specific technical characteristics without requiring individual prior permits, as detailed in Article 57. This is intended to streamline the rollout of dense wireless networks like 5G, subject to exceptions for protected sites and compliance with EMF exposure limits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "itu-radio-regulations-2020-edition"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-eed-energy-efficiency-2023-1791",
    "title": "EU Energy Efficiency Directive (EU) 2023/1791 (EED recast)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Directive (EU) 2023/1791 (the Energy Efficiency Directive EED recast) is the central piece of EU energy efficiency legislation. It sets a binding EU energy consumption reduction target of 11.7% by 2030 vs 2020 reference scenario (corresponding to maximum primary energy 992.5 Mtoe and final energy 763 Mtoe). Member State contributions notified in National Energy and Climate Plans. The Directive includes the Energy Savings Obligation (1.49% new annual energy savings 2024-2030), public sector lead by example (annual 1.9% energy consumption reduction and 3% renovation rate of public buildings >250 m2), energy audits for large enterprises and energy management systems for high-consumption enterprises, district heating and cooling provisions, and metering and billing requirements for consumers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-eets-electronic-toll-service-directive-2019-520",
    "title": "EU Electronic European Toll Service Directive 2019/520 - EETS Interoperability",
    "domain": "Automotive & Mobility",
    "version": "2019-04",
    "last_updated": "2026-05-09",
    "bluf": "Directive 2019/520/EU on the interoperability of electronic road toll systems requires all new EETS service areas to be accessible to EETS providers by 2021, mandating a single contract and single in-vehicle device for road users crossing EU national boundaries; EETS providers must obtain type approval for on-board units (OBUs) and vehicle classification declarations across all EU toll domains.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-type-approval-framework-2018-858",
      "unece-r155-automotive-cybersecurity-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ehds-regulation-2024",
    "title": "Regulation on the European Health Data Space (EHDS)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The European Health Data Space (EHDS) Regulation establishes a harmonized framework for the secondary use of electronic health data for research, innovation, and public policy across the EU, mandating secure processing environments and a permit-based access system managed by Health Data Access Bodies (HDABs) as outlined in Chapter IV. It applies to data holders (e.g., hospitals), data users (e.g., researchers), and manufacturers of EHR systems and wellness applications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-health-data",
      "eu-mdr-2017-745",
      "hl7-fhir-v4-interop",
      "iso-27799-health-info-sec"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ehds-regulation-2025",
    "title": "Regulation (EU) 2025/327 - European Health Data Space - Data Governance & Secondary Use",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The Regulation (EU) 2025/327 establishes the European Health Data Space (EHDS) to create a common framework for the primary and secondary use of electronic health data across EU Member States. For primary use, it mandates that natural persons have access to their electronic health data in a structured, commonly used format and that such data can be shared across borders for healthcare provision. It requires the use of the FHIR standard for interoperability and establishes national contact points for cross-border data exchange. For secondary use, the regulation sets conditions for data processing in secure processing environments for research, innovation, and policy-making. It mandates an opt-out mechanism for individuals regarding their data being used for secondary purposes, with exceptions for public interest research. The regulation imposes strict data quality and provenance requirements and includes additional safeguards when high-risk AI systems process health data. It establishes a governance structure with competent authorities in each Member State and the European Health Data Space Board responsible for consistency. The regulation entered into force on June 15, 2025, and applies from July 1, 2025, with certain provisions having phased application dates. It does not specify particular article numbers for these obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-data-governance-act-2022-868"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-eia-directive-2014-52-environmental-assessment",
    "title": "Directive 2014/52/EU of the European Parliament and of the Council of 16 April 2014 amending Directive 2011/92/EU on the assessment of the effects of certain public and private projects on the environment",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive requires Member States to ensure that certain construction and development projects undergo an Environmental Impact Assessment (EIA) before consent is granted, based on screening and scoping procedures defined in Articles 4 and 5. It applies to developers, public authorities, and environmental regulators involved in project approval processes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-circular-economy-construction-demolition-waste-2020",
      "iso-19650-bim-information-management-construction",
      "us-clean-water-act-section-404-construction"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-eia-directive-construction-2011-92",
    "title": "Directive 2011/92/EU of the European Parliament and of the Council of 13 December 2011 on the assessment of the effects of certain public and private projects on the environment",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive requires Member States to ensure that projects listed in Annex I and II undergo an Environmental Impact Assessment (EIA) before consent is granted, including scoping, public consultation, and post-decision monitoring. It applies to developers, competent authorities, and environmental regulators under Article 4 and Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-circular-economy-construction-demolition-waste-2020",
      "iso-19650-bim-information-management-construction",
      "us-clean-water-act-section-404-construction",
      "ilo-safety-health-construction-convention-167-1988",
      "australia-national-construction-code-2022-ncc"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-eidas-2-0-digital-identity-regulation-2024",
    "title": "Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a Union-wide framework for secure, user-controlled digital identities through the European Digital Identity Wallet (EUDIW), mandating Member States to issue digital identities and requiring large platforms to accept them. Key obligations are defined in Article 4 and Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "budapest-convention-cybercrime-2001",
      "eu-nis2-directive-workflow-critical-operations",
      "assessing-security-privacy-controls"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-eidas-2-digital-identity-wallet-2024-1183",
    "title": "eIDAS 2 Regulation 2024/1183 - EU Digital Identity Wallet & Electronic Attestation Framework",
    "domain": "Cloud & SaaS",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2024/1183 amending eIDAS (Regulation 910/2014) establishes the EU Digital Identity Wallet (EUDI Wallet) framework. Every EU Member State must provide at least one EUDI Wallet to all citizens and residents by November 2026 (Article 5a). Very Large Online Platforms (VLOPs) and specified private sector relying parties must accept EUDI Wallets for authentication where law or contract requires identity proof (Article 5b). The regulation introduces Electronic Attestations of Attributes (EAAs) - digitally verifiable credentials issued by trust service providers covering qualifications, licences, and attributes. Qualified Electronic Attestations of Attributes (QEAAs) carry equivalent legal weight to paper documents. Trust service providers issuing QEAAs must be listed in Member State Trusted Lists and audited by conformity assessment bodies. The Wallet Architecture Reference Framework (ARF) v1.4+ governs technical interoperability, selective disclosure (ISO/IEC 18013-5 mdoc format), and offline authentication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-cloud-essential-services-2022-2555",
      "eu-aml-regulation-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-eidas-2-regulation-2024-1183",
    "title": "EU eIDAS 2 Regulation 2024/1183 - European Digital Identity Framework and EUDI Wallet",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "EU Member States must, by December 2026, provide citizens and residents with European Digital Identity Wallets (EUDI Wallets), public bodies that require electronic identification and authentication to access an online public service must accept the EUDI Wallet, and (by late December 2027) Very Large Online Platforms designated under the Digital Services Act and private services legally required to authenticate their users must also accept the wallet for user authentication at the user's request, while EUDI Wallet providers must ensure the unobservability of user transactions (no collection or insight into transactions, with access only on explicit prior user consent for each individual case), and qualified trust service providers must continue to comply with existing rules for qualified electronic signatures, electronic seals, time stamps, registered electronic delivery services, and qualified certificates for website authentication, plus the new qualified trust services for electronic archiving, electronic ledgers, and management of remote electronic signature and seal creation devices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-eidas-2-regulation-2024-electronic-identity",
    "title": "Regulation (EU) 2024/1183 on electronic identification and trust services for electronic transactions in the European Union (eIDAS 2)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Establishes a framework for the European Digital Identity Wallet (EUDI Wallet), enabling secure, cross-border digital identification and authentication across public and private services. Applies to Member States, wallet providers, relying parties, and trust service providers. Key obligations include compliance with Article 7 on wallet issuance, Article 12 on personal data protection, and Article 23 on qualified electronic signatures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-directive-workflow-critical-operations",
      "eu-ai-act-automated-decision-workflows",
      "azure-logic-apps-enterprise-integration"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-eidas-impl-reg-2024-2977-pid-eaa-issuance-wallets",
    "title": "Commission Implementing Regulation (EU) 2024/2977 - eIDAS rules on person identification data and electronic attestations of attributes issued to European Digital Identity Wallets",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This Commission Implementing Regulation lays down rules for the issuance of person identification data (PID) and electronic attestations of attributes (EAA) to European Digital Identity Wallet units under the eIDAS framework. Member States must enrol wallet users at assurance level high, issued PID must be cryptographically bound to the wallet unit and unique within the Member State, and EAA must comply with at least one of the standards listed in Annex I. Only the providers that issued PID or EAA may revoke them, and providers must make the validity status publicly available in a privacy-preserving manner.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eidas2-regulation-2024-1183-digital-identity-wallet",
      "eu-eidas-regulation-910-2014-electronic-identification",
      "eidas2-regulation-article-16-attributes-and-attestations"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-eidas-impl-reg-2024-2979-wallet-integrity-core-functionalities",
    "title": "Commission Implementing Regulation (EU) 2024/2979 - eIDAS rules on the integrity and core functionalities of European Digital Identity Wallets",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This Commission Implementing Regulation specifies the integrity and core functionalities that European Digital Identity Wallets must provide under the eIDAS framework. Wallet instances must use at least one wallet secure cryptographic device to manage critical assets and protect private keys, log all transactions with relying parties and other wallet units, and support privacy-preserving pseudonyms unique to each relying party. Wallet providers must inform affected users within 24 hours of any revocation of their wallet unit, including the reason and consequences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eidas2-regulation-2024-1183-digital-identity-wallet",
      "eu-eidas-impl-reg-2024-2977-pid-eaa-issuance-wallets",
      "eidas2-regulation-article-71-data-protection"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-eidas-impl-reg-2024-2980-wallet-ecosystem-notifications",
    "title": "Commission Implementing Regulation (EU) 2024/2980 - eIDAS rules on notifications to the Commission concerning the European Digital Identity Wallet ecosystem",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This Commission Implementing Regulation establishes the obligations for Member States to notify the Commission about the European Digital Identity Wallet ecosystem, including wallet providers, person identification data providers, wallet-relying party access certificate providers and registrars of wallet-relying parties. The Commission must provide a secure electronic notification system, and Member States submit the information specified in Annex II at least in English. The Commission then compiles and publishes lists of the notified information that can be read without registration or authentication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eidas2-regulation-2024-1183-digital-identity-wallet",
      "eu-eidas-impl-reg-2024-2977-pid-eaa-issuance-wallets",
      "eidas2-regulation-article-47-eu-trusted-lists"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-eidas-impl-reg-2024-2981-wallet-certification",
    "title": "Commission Implementing Regulation (EU) 2024/2981 - eIDAS rules on the certification of European Digital Identity Wallets",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This Commission Implementing Regulation sets out the reference standards, specifications and procedures for the certification of European Digital Identity Wallets under the eIDAS framework. National certification schemes must cover functional, cybersecurity and data protection requirements, with the object of certification being the provision and operation of wallet solutions and their electronic identification schemes. Certificate holders must operate a vulnerability management policy, certification bodies must be accredited under Regulation (EC) No 765/2008, and the validity of certificates is subject to regular evaluation activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eidas2-regulation-2024-1183-digital-identity-wallet",
      "eu-eidas-impl-reg-2024-2979-wallet-integrity-core-functionalities",
      "eidas2-regulation-article-5-electronic-identification-mutual-recognition"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-eidas-impl-reg-2024-2982-wallet-protocols-interfaces",
    "title": "Commission Implementing Regulation (EU) 2024/2982 - eIDAS rules on protocols and interfaces to be supported by the European Digital Identity Framework",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This Commission Implementing Regulation lays down the protocols and interfaces that wallet solutions must support under the European Digital Identity Framework, covering issuance of person identification data, presentation of attributes, authentication and validation of wallet-relying party access certificates, and user reporting of relying parties. Wallet providers must ensure their solutions support these standardised protocols and interfaces, and must not present requested attributes to relying parties until defined requirements are met. The Regulation enters into force on the twentieth day following its publication in the Official Journal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eidas2-regulation-2024-1183-digital-identity-wallet",
      "eu-eidas-impl-reg-2024-2977-pid-eaa-issuance-wallets",
      "eu-eidas-impl-reg-2024-2979-wallet-integrity-core-functionalities"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-eidas-regulation-2014-910",
    "title": "EU eIDAS Regulation 2014/910 -- Electronic Identification and Trust Services for Digital Transactions",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Regulation (EU) 2014/910 (eIDAS) establishes the EU legal framework for electronic identification and trust services. Qualified Electronic Signatures (QES) have the same legal effect as handwritten signatures under Article 25(2) and must be based on a qualified certificate for electronic signatures held on a qualified electronic signature creation device (QESCD). Qualified Electronic Seals (QeSeal) under Article 35 enjoy a presumption of data integrity and authenticity for legal persons. Qualified Time Stamps (QTS) under Article 41 are presumed accurate as to the date and time they indicate. Qualified Trust Service Providers (QTSPs) must be audited every 24 months by accredited conformity assessment bodies under Article 20(1) and are listed on national EU Trusted Lists published under Article 22. Cross-border mutual recognition of notified electronic identification schemes is mandatory under Article 6: a relying party accepting eID at a given assurance level (low, substantial, high) in one Member State must accept notified schemes from all other Member States at the same or higher level. eIDAS 2.0 - Regulation (EU) 2024/1183 - introduces the European Digital Identity Wallet (EUDI Wallet): Member States must provide a free EUDI Wallet to all natural persons and legal entities by 26 May 2026; relying parties in 17 mandatory use cases (banking, government services, mobile driving licences, qualified electronic signatures) must accept the EUDI Wallet; Wallets operate at high assurance level and must comply with the Architecture and Reference Framework (ARF).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-payment-services-directive-2-2015-2366",
      "eu-nis2-directive-2022-2555",
      "eu-trademark-regulation-2017-1001"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-eidas-regulation-2024",
    "title": "Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 amending Regulations (EU) No 910/2014 and (EU) 2018/1724 as regards the establishment of a European Digital Identity Framework",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-21",
    "bluf": "This regulation establishes a legal framework for a European Digital Identity Wallet (EUDI Wallet), requiring EU Member States to issue at least one EUDI Wallet to citizens and residents free of charge. The wallet enables users to securely store and share personal identification data and electronic attestations of attributes for online and offline services across the EU, as mandated by Article 6a.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-sp-800-56b-key-establishment",
      "fips-197-advanced-encryption-standard"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-eidas-regulation-910-2014-electronic-identification",
    "title": "EU eIDAS Regulation 910/2014 - Electronic Identification and Trust Services for Workflow Compliance",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Regulation 910/2014 on Electronic Identification and Trust Services (eIDAS, effective 1 July 2016, amended by Regulation 2024/1183 introducing the EU Digital Identity Wallet) establishes the legal framework for electronic identification (eID), qualified electronic signatures (QES), electronic seals, timestamps, registered delivery, and website authentication certificates across the EU. Qualified electronic signatures carry the same legal effect as handwritten signatures (Article 25(2)) and must be accepted cross-border by all EU Member States. Trust Services are supervised by Member State supervisory bodies and listed on national Trusted Lists (TSLs) published by each Member State.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "w3c-verifiable-credentials-data-model-2-0",
      "ietf-rfc-9110-http-semantics-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-eidas-trust-services-telecoms-910-2014",
    "title": "Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes a pan-European legal framework for electronic identification (eID) and trust services (e-signatures, e-seals, timestamps, electronic registered delivery services, and website authentication). It ensures that electronic transactions are secure, trustworthy, and legally recognized across all EU member states, with 'qualified' trust services (Article 24) granted the highest level of legal equivalence to their paper-based counterparts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-46-transfer-mechanisms",
      "eu-psd2-strong-customer-authentication"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-eidas2-regulation-2024-1183-digital-identity-wallet",
    "title": "EU eIDAS 2 Regulation 2024/1183 - European Digital Identity (EUDI) Wallet, Trust Services, and Identity Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Regulation (EU) 2024/1183 (amending eIDAS Regulation 910/2014) requires all EU Member States to issue a free European Digital Identity (EUDI) Wallet by 2026, allowing citizens and businesses to use verified digital identities across EU Member States. Large online platforms must accept EUDI Wallet for authentication. New trust services include electronic attestations of attributes, remote qualified signature creation devices, and electronic archiving services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-directive-2022-2555-cybersecurity-essential-entities"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-eiopa-guidelines-orsa-2015",
    "title": "Guidelines on the own risk and solvency assessment",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "These guidelines require all insurance and reinsurance undertakings under the Solvency II Directive to implement and maintain an Own Risk and Solvency Assessment (ORSA) process to continuously assess their overall solvency needs and risk profile. As mandated by Guideline 14, the administrative, management, or supervisory body must approve the ORSA policy, process, and the results of each assessment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-electricity-directive-2019-944",
    "title": "Directive (EU) 2019/944 of the European Parliament and of the Council of 5 June 2019 on common rules for the internal market for electricity and amending Directive 2012/27/EU",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes common rules for the EU's internal electricity market, mandating clear consumer rights, transparent billing, and the rollout of smart metering systems to empower 'active customers' and 'citizen energy communities' (Articles 10, 15, 16, 19). It applies to electricity undertakings, final customers, and Member State regulatory authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-electricity-market-directive-2019-944",
    "title": "Directive (EU) 2019/944 of the European Parliament and of the Council of 5 June 2019 on common rules for the internal market for electricity and repealing Directive 2009/75/EC",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This directive establishes consumer rights, smart meter deployment, demand response mechanisms, and recognition of independent aggregators and energy communities in the EU internal electricity market. It applies to all Member States, electricity suppliers, distribution system operators (DSOs), and new market participants under Articles 3, 8, 11, and 14.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-renewable-energy-directive-2023-2413",
      "etsi-en-303-645-iot-cybersecurity-2020",
      "iec-60870-telecontrol-scada-protocols",
      "eu-batteries-regulation-2023-1542-iot-storage"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-electricity-market-reform-regulation-2024-1747",
    "title": "Regulation (EU) 2024/1747 of the European Parliament and of the Council of 13 June 2024 amending Regulations (EU) 2019/943 and (EU) 2019/942 as well as Directives (EU) 2018/2001 and (EU) 2019/944 to improve the Union’s electricity market design",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-07-01",
    "bluf": "This regulation reforms the EU's electricity market to protect consumers from price volatility and accelerate the transition to renewable energy by promoting long-term contracts, such as Power Purchase Agreements (PPAs) and two-way Contracts for Difference (CfDs), for new power-generating facilities (Article 1, amending Regulation (EU) 2019/943, Articles 19a and 19b). It applies to Member States, national regulatory authorities, transmission system operators, and energy market participants across the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-electricity-regulation-2019-943",
    "title": "Regulation (EU) 2019/943 of the European Parliament and of the Council of 5 June 2019 on the internal market for electricity",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes key rules for an integrated, competitive, and non-discriminatory internal electricity market within the EU, mandating that all market participants are financially responsible for their imbalances and that balancing markets are organized to ensure security of supply without discriminating between resources, as outlined in Article 3 and Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-electricity-regulation-article-15-operational-security-standards",
    "title": "Regulation (EU) 2019/943 on the internal market for electricity - Article 15",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates the continuation of priority dispatch for certain existing power-generating facilities, specifies that this privilege is revoked upon significant modification, and ensures that priority dispatch does not compromise the secure operation of the electricity system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-electricity-regulation-article-18-electricity-balancing",
    "title": "Regulation (EU) 2019/943 on the internal market for electricity - Article 18 and Article 43",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the procedures for transmission system operators (TSOs) to interact with regional coordination centres (RCCs), including reporting non-implementation of actions, justifying deviations from recommendations, and the governance structure of RCCs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-electricity-regulation-article-26-regional-coordination-centres",
    "title": "Regulation (EU) 2019/943 on the internal market for electricity - Article 26: Tasks of regional coordination centres",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates Regional Coordination Centres (RCCs) to support transmission system operators in identifying transmission capacity needs and outlines the specific procedure for assigning new advisory tasks to them.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-electricity-regulation-article-3-definitions",
    "title": "Regulation (EU) 2019/943 on the internal market for electricity - Article 3: Definitions",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes key definitions for the regulation, requiring organizations to apply terms as defined herein, including those incorporated by reference from other directives such as Directive (EU) 2018/2001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-electricity-regulation-article-57-delegated-acts-for-grid-codes",
    "title": "Regulation (EU) 2019/943 on the internal market for electricity - Article 57: Delegated acts",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article empowers the European Commission to adopt and amend delegated acts, specifically network codes and guidelines, covering critical areas of electricity market operation such as network security, capacity allocation, trading rules, and demand response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-electricity-regulation-article-59-penalties",
    "title": "Regulation (EU) 2019/943 on the internal market for electricity - Article 59 Penalties",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Member States must establish, implement, and notify the Commission of effective, proportionate, and dissuasive penalties for infringements of this regulation, ensuring national regulatory authorities are empowered to impose them on key electricity market entities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-electricity-regulation-article-6-free-flow-of-electricity",
    "title": "Regulation (EU) 2019/943 of the European Parliament and of the Council on the internal market for electricity - Article 6 Balancing market",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires that electricity balancing markets are organized to be non-discriminatory, transparent, and market-based, allowing participation from all market participants including demand response, energy storage, and aggregators, with specific rules for pricing, settlement, and information publication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-electricity-regulation-article-9-network-access-and-congestion-management",
    "title": "Regulation (EU) 2019/943 on the internal market for electricity - Article 9: Forward markets",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires transmission system operators to provide long-term transmission rights or equivalent measures for price risk hedging across bidding zones, and ensures market operators are free to develop forward hedging products without undue national restrictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-electromagnetic-compatibility-directive-2014-30",
    "title": "EU Electromagnetic Compatibility Directive 2014/30/EU",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2014-02-26",
    "bluf": "Directive 2014/30/EU harmonises the laws of Member States relating to electromagnetic compatibility (EMC) of electrical and electronic equipment, requiring all apparatus placed on the EU market to generate only tolerable electromagnetic disturbance and to have adequate immunity to disturbance to function as intended, with CE marking and an EU Declaration of Conformity required before market placement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-atex-directive-2014-34",
        "eu-machinery-directive-2006-42",
        "eu-cybersecurity-act-2019-881"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-atex-directive-2014-34",
      "eu-machinery-directive-2006-42",
      "eu-cybersecurity-act-2019-881"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-electronic-communications-code-2018-1972",
    "title": "EU European Electronic Communications Code 2018/1972 - General Authorisation, Spectrum, End-User Rights, and SMP Regulation",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Directive (EU) 2018/1972 of the European Parliament and of the Council of 11 December 2018 establishing the European Electronic Communications Code (EECC) consolidates and replaces the 2002 EU telecoms regulatory framework (Framework Directive, Access Directive, Authorisation Directive, and Universal Service Directive). Article 12 establishes the general authorisation regime: providers of electronic communications networks or services (ECNS) are entitled to provide those networks and services without prior individual authorisation, subject only to a notification to the national regulatory authority (NRA). Article 40 requires providers to implement appropriate technical and organisational measures to manage security risks to their networks. Articles 67-68 empower NRAs to impose regulatory obligations on operators with significant market power (SMP) following market analysis. Articles 79-107 provide an expanded end-user rights chapter covering pre-contractual information, contract terms, switching, and emergency communications. Article 108 defines the universal service obligations to be financed by Member States. Articles 117-131 strengthen BEREC (Body of European Regulators for Electronic Communications). Member States were required to implement the EECC by 21 December 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_nis2_directive_2022_2555",
        "eu_open_internet_regulation_2015_2120",
        "uk_communications_act_2003",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecn-plus-directive-2019-nca-powers",
      "eu-services-directive-2006-123",
      "eu-late-payment-directive-2011-7"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-electronic-communications-code-2018-competition",
    "title": "Directive (EU) 2018/1972 establishing the European Electronic Communications Code",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The European Electronic Communications Code (EECC) establishes a harmonized regulatory framework across EU member states for electronic communications markets, requiring national regulatory authorities (NRAs) to assess Significant Market Power (SMP) under Article 61 and impose proportionate remedies under Articles 62-68. It applies to providers of publicly available electronic communications services and networks, with enforceable obligations on net neutrality (Article 3), spectrum allocation (Article 106), and consumer protection (Articles 109-112).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "uk-cma-merger-assessment-guidelines-2021",
      "india-competition-act-2002-sections-3-4",
      "canada-competition-act-2024-amendment-abuse-dominance",
      "oecd-competition-digital-economy-roundtable-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-electronic-identification-eidas-regulation-910-2014-trust-services",
    "title": "EU eIDAS Regulation 910/2014 - Electronic Identification and Trust Services for Electronic Transactions",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Regulation (EU) No 910/2014 (eIDAS) establishes a cross-border framework for electronic identification and trust services in the EU, including qualified electronic signatures (QES), qualified electronic seals, qualified time stamps, and website authentication certificates. Only qualified electronic signatures have equivalent legal effect to handwritten signatures across the EU. eIDAS 2.0 (Regulation (EU) 2024/1183) introduces the EU Digital Identity Wallet (EUDI Wallet).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-6-lawful-basis-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-electronic-invoicing-directive-2014-55",
    "title": "EU Electronic Invoicing Directive 2014/55/EU - Public Procurement E-Invoicing",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Directive 2014/55/EU requires all EU contracting authorities and contracting entities to be able to receive and process electronic invoices complying with the European standard EN 16931-1. The obligation applied from 18 April 2019 for central government entities and from 18 April 2020 for sub-central contracting authorities. The Directive does not mandate suppliers to send electronic invoices but creates the infrastructure for interoperable B2G (business-to-government) e-invoicing across all EU Member States using a single European semantic data model and XML syntax.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "en_16931_standard",
        "eu_public_procurement_directive",
        "peppol",
        "eu_vat_digitisation",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-public-procurement-directive-2014-24-construction",
      "eu-dac7-platform-economy-reporting-2021-514",
      "eu-data-act-2023-competition-data-access"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-electronic-money-directive-2009-110",
    "title": "EU Electronic Money Directive 2009/110 (EMD2)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2011-04-30",
    "bluf": "Directive 2009/110/EC of the European Parliament and of the Council, in force 30 October 2009 with Member State transposition required by 30 April 2011, establishes the authorisation regime for electronic money institutions (EMIs) in the EU, requiring minimum initial capital of EUR 350,000, own funds of at least 2% of average outstanding e-money, ring-fenced safeguarding of e-money holders' funds in approved low-risk assets or insurance policies, and prohibiting e-money from bearing interest, while granting EMIs passport rights to operate across the EU single market through the PSD2 framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-payment-services-directive-2-2015-2366",
        "eu-capital-requirements-regulation-2013-575",
        "eu-aml-regulation-2024"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-payment-services-directive-2-2015-2366",
      "eu-capital-requirements-regulation-2013-575",
      "eu-aml-regulation-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-eltif-long-term-investment-funds-regulation-2015-760",
    "title": "Regulation (EU) 2015/760 of the European Parliament and of the Council of 29 April 2015 on European long-term investment funds",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down uniform rules on the authorisation, investment policies and operating conditions of EU alternative investment funds marketed as European long-term investment funds (ELTIFs) (Article 1). Only an authorised EU AIF may use the ELTIF designation, and authorisation and a central public register are required (Articles 3 and 4). It sets the conditions for granting authorisation (Article 6), the categories of eligible investments and eligible investment assets (Articles 9 and 10), the definition of qualifying portfolio undertakings (Article 11), and rules on conflicts of interest (Article 12), portfolio composition and diversification (Article 13) and the borrowing of cash (Article 16).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aifmd-directive-2011-61",
      "eu-mifid-ii-directive-2014-65-investment-firm-conduct-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ema-centralised-procedure-regulation-726-2004",
    "title": "Regulation (EC) No 726/2004 of the European Parliament and of the Council of 31 March 2004 laying down Community procedures for the authorisation and supervision of medicinal products for human and veterinary use and establishing a European Medicines Agency (Text with EEA relevance)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the centralised procedure for authorising medicinal products in the European Union, mandating its use for high-technology products (e.g., biotech-derived), orphan medicinal products, and new active substances for specific serious diseases, as outlined in Article 3 and Annex. It applies to marketing authorisation applicants and the European Medicines Agency (EMA), which conducts scientific assessments via the Committee for Medicinal Products for Human Use (CHMP).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-314-nda-new-drug-application",
      "fda-biosimilar-pathway-351k-biologics-competition-act",
      "eu-gmp-annex-1-sterile-manufacture-2022",
      "ich-q10-pharmaceutical-quality-system-2008"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ema-crispr-genome-editing-reflection-paper",
    "title": "EMA Reflection Paper on CRISPR Genome Editing - Quality Considerations, Off-Target Analysis, Manufacturing Controls, Non-Clinical Studies and Regulatory Classification for Gene-Edited Products",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This reflection paper provides scientific considerations for the development of CRISPR-based gene-edited medicinal products, focusing on quality, off-target analysis, manufacturing controls, and non-clinical evaluation. It applies to applicants developing advanced therapy medicinal products (ATMPs) in the EU and references the framework established in Directive 2001/83/EC and Regulation (EC) No 1394/2007.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-atmp-regulation-1394-2007",
      "ema-guidelines-advanced-therapy-quality-2019",
      "ich-q5a-r2-viral-safety-biotech-2024",
      "eu-gmo-regulation-1829-2003",
      "fda-guidance-human-gene-therapy-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ema-prime-scheme-priority-medicines",
    "title": "EMA PRIME Scheme - Priority Medicines (PRIority MEdicines): Early Dialogue for Unmet Medical Need Products, Dedicated Point of Contact, Free Scientific Advice, Proactive Support during Development, CHMP Appointment of Rapporteur and Rolling Review Option",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EMA PRIME scheme provides enhanced regulatory support to developers of medicines targeting unmet medical needs in the EU, based on preliminary clinical or non-clinical evidence of significant therapeutic potential. It applies to sponsors in the exploratory clinical trial phase seeking early scientific advice, rapporteur appointment, and potential eligibility for accelerated assessment under Regulation (EC) No 726/2004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ema-centralised-procedure-regulation-726-2004",
      "eu-clinical-trials-eu-ctr-trials-regulation",
      "eu-atmp-regulation-1394-2007-advanced-therapies"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-emir-refit-2019-834-derivatives-reporting",
    "title": "Regulation (EU) 2019/834 of the European Parliament and of the Council of 20 May 2019 amending Regulation (EU) No 648/2012 as regards the clearing obligation, the suspension of the clearing obligation, the reporting requirements, the risk-mitigation techniques for OTC derivative contracts not cleared by a central counterparty, the registration and supervision of trade repositories and the requirements for trade repositories (Text with EEA relevance)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation amends EMIR to refine the clearing obligation, reporting requirements, and risk-mitigation techniques for OTC derivatives, particularly focusing on small financial counterparties and trade repository oversight. It applies to financial counterparties, CCPs, and trade repositories under Article 4 and Article 11 of Regulation (EU) No 648/2012 as amended by Regulation (EU) 2019/834.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "eu-electricity-directive-2019-944"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-emir-refit-regulation-2019-834",
    "title": "EU EMIR Refit Regulation 2019/834 - Streamlined Derivatives Reporting & Pension Exemption",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation 2019/834 (EMIR Refit) amends EMIR 648/2012 to reduce disproportionate compliance burdens. Key changes: small financial counterparties (SFCs, below EMIR clearing thresholds) are exempt from clearing obligations; pension scheme arrangements (PSAs) received a further temporary clearing exemption (renewed periodically, most recently to June 2023, then June 2025); non-financial counterparties (NFCs) above threshold (NFC+) are subject to clearing and reporting only for the asset class that breaches threshold; small NFC-below-threshold entities (NFC-) are exempt from clearing and have reduced reporting; third-country CCPs are reclassified as Tier 1 (non-systemic, recognition only) or Tier 2 (systemic, enhanced ESMA requirements) under EMIR 2.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-emir-regulation-648-2012",
      "eu-sftr-securities-financing-transactions-2015-2365",
      "mifid-ii"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-emir-regulation-648-2012",
    "title": "EU EMIR - European Market Infrastructure Regulation 648/2012",
    "domain": "Banking & Global Finance",
    "version": "2.1.0",
    "last_updated": "2024-06-01",
    "bluf": "Regulation (EU) No 648/2012 (EMIR) mandates central clearing of standardised OTC derivatives through authorised CCPs, bilateral risk mitigation for non-cleared trades, and trade reporting to registered trade repositories - applicable to financial and non-financial counterparties in the EU trading derivatives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mifid-ii",
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-csdr-regulation-909-2014"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-emir-regulation-648-2012-otc-derivatives-clearing-reporting",
    "title": "EU EMIR Regulation 648/2012 - OTC Derivatives Clearing, Reporting & Risk Mitigation",
    "domain": "Banking & Global Finance",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "EMIR Regulation 648/2012 requires central clearing of standardised OTC derivatives by CCPs, bilateral risk mitigation for non-cleared derivatives, and reporting of all derivative contracts to trade repositories - applicable to all EU financial and non-financial counterparties above clearing threshold.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-emission-standards-euro-7",
    "title": "Regulation (EU) 2024/1257 - Emission Limits for Light and Heavy-Duty Vehicles, Real Driving Emissions, Tyre and Brake Particle Emission Limits and Battery Durability Requirements",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Regulation (EU) 2024/1257 establishes stricter emission limits for light and heavy-duty vehicles, including real driving emissions (RDE) for NOx and particulate matter, introduces limits on non-exhaust emissions from brakes and tyres, and mandates minimum battery durability for electric vehicles. It applies to all manufacturers placing new vehicles on the EU market, effective from 1 July 2026 for light vehicles and 1 July 2027 for heavy-duty vehicles under Article 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-emissions-trading-shipping-extension-2023",
    "title": "Directive (EU) 2023/959 amending Directive 2003/87/EC to include maritime transport activities in the EU Emissions Trading System (ETS)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-05-10",
    "bluf": "This regulation extends the EU Emissions Trading System (ETS) to maritime transport, requiring shipping companies with ships over 5000 gross tonnage calling at EU/EEA ports to monitor, report, and surrender EU allowances (EUAs) for their greenhouse gas emissions. As per Article 3ga of the amended Directive 2003/87/EC, compliance is phased in, starting with 40% of verified emissions in 2024, rising to 100% by 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-employment-equality-directive-2000-78",
    "title": "Council Directive 2000/78/EC of 27 November 2000 establishing a general framework for equal treatment in employment and occupation",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This Directive establishes a framework for equal treatment in employment and occupation on the grounds of religion or belief, disability, age, or sexual orientation. It applies to all public and private sector employers within EU Member States and requires reasonable accommodation for disabled persons under Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eeoc-employment-rule",
      "au-fair-work-act-2009",
      "difc-employment-law-4-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-empowering-consumers-green-transition-directive-2024-825",
    "title": "EU Empowering Consumers for the Green Transition Directive (Directive 2024/825) - Amending UCPD 2005/29/EC and Consumer Rights Directive 2011/83/EU on Greenwashing and Early Obsolescence",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "Directive (EU) 2024/825 of the European Parliament and of the Council of 28 February 2024 amends the Unfair Commercial Practices Directive 2005/29/EC and the Consumer Rights Directive 2011/83/EU to strengthen protection against greenwashing, early obsolescence and misleading sustainability information. Member States must transpose by 27 March 2026 and apply national measures from 27 September 2026. Key substantive changes: Article 6(1)(b) UCPD adds environmental or social characteristics and circularity aspects (durability, reparability, recyclability) to the list of product characteristics that cannot be misleadingly presented; new Article 6(2)(d) UCPD prohibits future-performance environmental claims (carbon-neutrality by year X, climate-positive, climate-neutral) without clear objective publicly available verifiable commitments with detailed implementation plan and independent third-party verification; new Article 7 transparency duties require traders to disclose comparison methods, products compared, suppliers and update schedules whenever a product comparison is made on environmental, social or circularity criteria; Annex I (the blacklist of practices considered unfair in all circumstances) is extended with new entries banning generic environmental claims (such as eco-friendly, green, natural without demonstrated excellent environmental performance), sustainability labels that are not based on a certification scheme or established by a public authority, greenhouse-gas offset claims (carbon-neutral solely on the basis of offsets), full-product or business-level environmental claims when only one aspect is environmentally improved, durability-limiting features not disclosed, false durability claims, deceptive repairability claims, and consumable replacement manipulation. Consumer Rights Directive 2011/83/EU is amended to require pre-contractual information on commercial guarantees of durability, software-update commitments, repairability scores where mandated, spare-parts availability, and right-to-repair information. The Directive forms the operational layer beneath the proposed Green Claims Directive (substantiation regime, ex-ante verification) and is enforced through national consumer-protection authorities, the Consumer Protection Cooperation (CPC) network, and private civil actions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "amended_ucpd_anchor",
        "amended_consumer_rights_directive_anchor",
        "green_claims_directive_proposal_relationship",
        "ecodesign_for_sustainable_products_relationship",
        "industry_mapping",
        "enforcement_anchors",
        "remedies_and_penalties_anchor"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-directive-2005-29-ec-advertising",
      "uk-cma-green-claims-code-2021",
      "eu-omnibus-directive-2019-2161-consumer-protection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-emsa-regulation-1406-2002-maritime-safety-agency",
    "title": "EU EMSA Regulation 1406/2002 European Maritime Safety Agency Technical Assistance and Inspections",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Regulation (EC) No 1406/2002 establishes the European Maritime Safety Agency (EMSA) to provide technical assistance and coordinate EU-level responses to maritime safety, pollution prevention, and response - including conducting inspections of flag state administrations and class societies acting on their behalf, operating the EU Integrated Maritime Services, and providing pollution response vessels under the CleanSeaNet satellite monitoring system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ship-recycling-regulation-1257-2013",
      "eu-port-waste-reception-facilities-directive-2019-883"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-end-of-life-vehicles-directive-2000-53",
    "title": "Directive 2000/53/EC of the European Parliament and of the Council of 18 September 2000 on end-of life vehicles",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive requires vehicle producers to establish systems for the take-back of end-of-life vehicles (ELVs) at no cost to the last owner, meet stringent reuse, recovery, and recycling targets (Article 7), and restricts the use of hazardous substances like lead, mercury, cadmium, and hexavalent chromium in vehicle components (Article 4). A Certificate of Destruction must be issued to deregister a vehicle, ensuring it enters a proper treatment facility (Article 5(3)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-end-of-life-vehicles-directive-2000-53-ec",
    "title": "EU End-of-Life Vehicles Directive 2000/53/EC",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Directive 2000/53/EC on End-of-Life Vehicles (ELV) implements producer responsibility for vehicles at the end of their useful life. Vehicle manufacturers must achieve minimum reuse/recovery and reuse/recycling targets (85%/80% from 2006 then 95%/85% from 2015 by weight per vehicle and year). The Directive restricts use of lead mercury cadmium and hexavalent chromium in vehicles and components (with Annex II exemptions for specific applications). End-of-life vehicles must be delivered to Authorised Treatment Facilities (ATFs) where free take-back is provided to last holder/owner. A 2024 proposed ELV Regulation would replace this Directive with a more comprehensive product-end-of-life framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-end-of-life-vehicles-directive-revision-2023",
    "title": "Proposal for a Directive of the European Parliament and of the Council on end-of-life vehicles - Recycled Content Mandates, Dismantling Information, Collector Obligations and Depollution Standards",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes mandatory recycled content targets for new vehicles, requires manufacturers to provide standardized dismantling and depollution information, and imposes obligations on treatment facilities to meet high recovery and recycling rates. It applies to all automotive manufacturers, recyclers, and treatment operators placing vehicles on the EU market under Article 5 and Article 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26262-functional-safety-road-vehicles-2018",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "unece-wp29-framework-connected-automated-vehicles",
      "sae-j3016-levels-driving-automation-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-energy-efficiency-directive-2023-1791",
    "title": "Directive (EU) 2023/1791 of the European Parliament and of the Council of 13 September 2023 on energy efficiency and amending Regulation (EU) 2023/955 (recast)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-10-11",
    "bluf": "This directive establishes a binding EU-level target to reduce final energy consumption by 11.7% by 2030, imposing an annual energy savings obligation on Member States (Article 8), requiring a 3% annual renovation rate for buildings owned by public bodies (Article 6), and mandating regular energy audits for large enterprises (Article 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-energy-efficiency-directive-2023-1791-article-4-target",
    "title": "EU Energy Efficiency Directive 2023/1791 - Article 4: Binding Energy Efficiency Target and Member State Contributions",
    "domain": "Energy & Utilities",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Energy Efficiency Directive (EED) 2023/1791 (recast) establishes a binding EU-level energy efficiency target of at least 11.7% reduction in energy consumption by 2030 compared to 2020 reference projections (equivalent to 763 Mtoe final energy consumption or 993 Mtoe primary energy consumption). Each EU member state must set an indicative national energy efficiency contribution consistent with the EU target trajectory; member states falling short of their trajectory must notify the Commission and implement compensating measures. The Directive substantially strengthens public sector exemplar obligations, energy saving obligations (Art.8), and energy audit requirements (Art.11-12). ENTSO-E and ENTSO-G provide data infrastructure for monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-energy-efficiency-directive-2023-1791",
      "eu-renewable-energy-directive-2023-2413-red-iii"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-energy-efficiency-directive-2023-1791-buildings-industry-targets",
    "title": "EU Energy Efficiency Directive 2023/1791 - Energy Savings Targets and Audit Obligations",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive (EU) 2023/1791 (recast EED) sets a binding EU-level energy efficiency target of 11.7% reduction in final energy consumption by 2030 compared to 2020 projections, requires Member States to achieve 1.9% annual energy savings from 2024, mandates energy audits for large non-SME enterprises every 4 years, establishes an energy efficiency first principle in all policy and investment decisions, and requires public sector exemplary role with 3% annual renovation of government buildings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852-sustainable-finance-classification"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-energy-efficiency-directive-2023-1791-recast",
    "title": "EU Energy Efficiency Directive 2023/1791/EU - Recast EED",
    "domain": "Energy & Utilities",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive (EU) 2023/1791 (recast EED) sets a binding EU-level energy efficiency target of at least 11.7% reduction in final energy consumption by 2030 compared to 2020 projections; requires public sector 1.9% annual primary energy consumption reduction; introduces mandatory energy audits for large enterprises every 4 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-energy-efficiency-directive-2023-article-11-audits",
    "title": "Directive (EU) 2023/1791 Article 11: Mandatory Energy Audits for Large Enterprises",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-10-11",
    "bluf": "Under Article 11 of the EU Energy Efficiency Directive (2023/1791), large enterprises must undergo a high-quality, cost-effective energy audit at least every four years, covering a minimum of 80% of their total energy consumption. Exemptions are available for enterprises implementing a certified energy or environmental management system, such as ISO 50001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-energy-efficiency-directive-article-11-metering",
    "title": "Directive (EU) 2018/2002 on energy efficiency - Article 11: Cost of access to metering and billing information for electricity and gas",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations must provide final customers with free energy bills and billing information, offer an electronic option, and supply clear explanations of bill calculations upon request.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-energy-efficiency-directive-article-12-billing-information",
    "title": "DIRECTIVE (EU) 2018/2002 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 11 December 2018 amending Directive 2012/27/EU on energy efficiency, Article 12",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations must prioritize and consider energy efficiency in all energy system planning, financing, and infrastructure investment decisions, implementing improvements where they are more cost-effective than supply-side solutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-energy-efficiency-directive-article-20-availability-qualification-schemes",
    "title": "Directive (EU) 2018/2002 amending Directive 2012/27/EU on energy efficiency - Article 20: Availability of qualification, accreditation and certification schemes",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires Member States to ensure the availability of transparent and reliable certification, accreditation, or equivalent qualification schemes for providers of energy services, energy audits, and installers of energy-related building elements, and to make information about these schemes publicly available.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-energy-efficiency-directive-article-24-energy-efficiency-obligation-schemes",
    "title": "Directive (EU) 2018/2002 of the European Parliament and of the Council on energy efficiency - Article 24",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires the European Commission to report on the functioning of the carbon market, considering the effects of this Directive, within the State of the Energy Union report.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-energy-efficiency-directive-article-3-energy-efficiency-targets",
    "title": "Directive (EU) 2018/2002 on energy efficiency - Article 3: Entry into force",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the legal effective date for the Directive, specifying that it enters into force on the third day following its publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-energy-efficiency-directive-article-5-exemplary-role-public-bodies",
    "title": "Directive (EU) 2018/2002 amending Directive 2012/27/EU on energy efficiency - Article 5: Exemplary role of public bodies' buildings",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that Member States ensure public bodies fulfill an exemplary role in energy efficiency by renovating a percentage of their building stock annually and procuring highly efficient products, services, and buildings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-energy-efficiency-directive-article-6-renovation-of-public-buildings",
    "title": "DIRECTIVE (EU) 2018/2002 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 11 December 2018 amending Directive 2012/27/EU on energy efficiency",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations involved in energy system planning, financing, or infrastructure investment must prioritize and consider energy efficiency improvements, especially when they are more cost-effective than supply-side solutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-energy-efficiency-directive-article-8-energy-audits-and-management-systems",
    "title": "Directive (EU) 2018/2002 on energy efficiency - Article 8: Energy audits and management systems",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that non-SME enterprises must undergo regular, independent energy audits or implement a certified energy management system to identify and promote energy-saving opportunities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-energy-labelling-regulation-2017-1369-marketing",
    "title": "Regulation (EU) 2017/1369 of the European Parliament and of the Council of 4 July 2017 setting a framework for energy labelling and repealing Directive 2010/30/EU",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation mandates that energy-related products placed on the EU market must display a rescaled A-G energy efficiency label both on the physical product and in all online and offline advertising and technical promotional materials. It applies to manufacturers, importers, dealers, and retailers of energy-related products under Articles 3 and 4, with specific obligations for label presentation in marketing contexts under Article 3(3) and Annex VII.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29",
      "eu-ecommerce-directive-2000-31",
      "eu-price-indication-directive-1998",
      "ama-ethical-marketing",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-energy-performance-buildings-directive-2024",
    "title": "Directive (EU) 2024/1275 of the European Parliament and of the Council of 17 April 2024 on the energy performance of buildings",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This Directive establishes minimum energy performance standards for buildings, mandates the development of renovation passports, and introduces a Smart Readiness Indicator (SRI) to promote nearly zero-energy buildings (nZEBs). It applies to all new and existing buildings in EU Member States, with specific requirements under Articles 2, 7, and 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-construction-sector-emissions-buildings-renovation",
      "iso-19650-bim-information-management-construction",
      "iso-50001-2018-energy-management-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-energy-performance-buildings-directive-2024-recast",
    "title": "Directive (EU) 2024/1275 of the European Parliament and of the Council of 13 March 2024 on the energy performance of buildings",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The recast EPBD 2024 mandates that all new buildings must be zero-emission as of 2028, with public buildings leading by 2026. It requires Member States to establish renovation passports, enforce Minimum Energy Performance Standards (MEPS) for existing buildings by 2030, and implement solar readiness or installation on suitable rooftops. Compliance is governed under Article 2 and Article 17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-construction-sector-emissions-buildings-renovation",
      "iso-19650-bim-information-management-construction",
      "iso-50001-2018-energy-management-systems",
      "australia-national-construction-code-2022-ncc",
      "icc-700-national-green-building-standard-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-energy-poverty-directive-2023-communities",
    "title": "EU Energy Efficiency Directive Article 22 Energy Poverty and EU Electricity Directive Articles 26-27 Energy Communities - Member State Obligations",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires EU Member States to define, assess, and implement measures to alleviate energy poverty, prioritizing energy efficiency improvements for vulnerable households under Article 22 of the Energy Efficiency Directive (EU) 2023/1791. It also mandates the protection of vulnerable customers from electricity disconnection and the provision of information via single points of contact, as per Articles 26-27 of the Electricity Directive (EU) 2019/944.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-sdg-corporate-mapping",
      "iso-14064-ghg-reporting-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-energy-poverty-vulnerable-consumers-directive-2023",
    "title": "Directive (EU) 2019/944 on common rules for the internal market for electricity: Articles 28 (Vulnerable Customers) and 29 (Energy Poverty)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-06-12",
    "bluf": "This directive requires EU Member States to define the concepts of 'vulnerable customers' and 'energy poverty' and to implement appropriate, targeted measures to protect these groups. Key obligations under Articles 28 and 29 include ensuring access to electricity, prohibiting disconnections during critical periods, and developing action plans to tackle the root causes of energy poverty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-paris-agreement-ndc-implementation-guidelines",
      "iso-14001-ems"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-energy-union-governance-regulation-2018-1999",
    "title": "Regulation (EU) 2018/1999 of the European Parliament and of the Council of 11 December 2018 on the Governance of the Energy Union and Climate Action",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation establishes a governance mechanism for the EU's Energy Union and Climate Action goals, requiring each Member State to develop, submit, and regularly update an integrated National Energy and Climate Plan (NECP) outlining their 10-year objectives and policies (Articles 3 & 14), and to report on progress biennially (Article 17).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify",
      "iso-14090-climate-adapt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-enisa-cybersecurity-act-2019-1881-article-49-certification-schemes",
    "title": "Regulation (EU) 2019/881 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification ('Cybersecurity Act') - Article 49: Preparation, adoption and review of a European cybersecurity certification scheme",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article obligates the European Union Agency for Cybersecurity (ENISA) to prepare a candidate European cybersecurity certification scheme upon request from the Commission, ensuring it meets the requirements of Articles 51, 52, and 54.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-enisa-cybersecurity-act-2019-1881-article-8-enisa-mandate-tasks",
    "title": "Regulation (EU) 2019/881 (Cybersecurity Act) - Article 8: Market, cybersecurity certification, and standardisation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article mandates the European Union Agency for Cybersecurity (ENISA) to support and promote Union policy on cybersecurity certification for ICT products, services, and processes through specific tasks including monitoring, providing guidelines, preparing certification schemes, and maintaining a public repository of schemes and certificates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-entry-exit-system-regulation-2017-2226",
    "title": "EU Entry/Exit System Regulation 2017/2226 - Automated Border Management and Third-Country National Biometrics",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "EU Regulation 2017/2226 establishes the Entry/Exit System (EES) for systematic electronic registration of entry and exit data (including facial images and fingerprints) of third-country nationals crossing EU external Schengen borders. EES replaces manual passport stamping and enables automated detection of overstayers. AI border management systems at Schengen points of entry must interface with the EES central system via eu-LISA; biometric data collected is stored for 3 years (or 5 for overstayers). The EES intersects with the EU AI Act high-risk biometric system requirements and GDPR Article 9 special category processing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standards",
        "frameworks",
        "regulations",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-environmental-impact-assessment-directive-2011-92-eu",
    "title": "Directive 2011/92/EU on the assessment of the effects of certain public and private projects on the environment",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Directive 2011/92/EU of the European Parliament and of the Council, dated 13 December 2011, codifies and replaces Council Directive 85/337/EEC concerning the assessment of the effects of certain public and private projects on the environment. It applies to projects likely to have significant effects on the environment by virtue of their nature, size, or location. The directive requires that development consent for such projects must be preceded by an environmental impact assessment (EIA). Projects listed in Annex I, such as crude-oil refineries, thermal power stations over 300 MW, nuclear power stations, certain waste disposal installations, and large infrastructure projects like motorways and airports, must always undergo an EIA. For projects listed in Annex II, Member States must determine, through case-by-case examination or thresholds/criteria, whether an EIA is required, taking into account the selection criteria in Annex III. The developer must supply information specified in Annex IV, including a description of the project, measures to avoid significant adverse effects, an outline of main alternatives studied, and a non-technical summary. The public concerned and relevant authorities must be consulted, with early and effective opportunities to participate. Transboundary consultations are required when a project may have significant effects on another Member State. The competent authority must consider all gathered information and consultations before granting consent, and make the decision and reasons public. Members of the public concerned with sufficient interest have access to a review procedure before a court or independent body to challenge the legality of decisions, acts, or omissions subject to the directive's public participation provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-environmental-liability-directive-2004-35",
    "title": "Directive 2004/35/EC of the European Parliament and of the Council of 21 April 2004 on environmental liability with regard to the prevention and remedying of environmental damage",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes a 'polluter pays' framework, holding operators of specified occupational activities strictly liable for preventing and remedying environmental damage to water, land, and protected species/habitats. Operators must take immediate preventive action at their own cost upon an imminent threat of damage (Article 5) and remediate any actual damage caused (Article 6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-environmental-liability-directive-2004-35-ec",
    "title": "Environmental Liability Directive 2004/35/EC: Preventing and Remedying Environmental Damage via Polluter Pays",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Directive 2004/35/EC establishes a framework for environmental liability based on the polluter-pays principle to prevent and remedy environmental damage. Environmental damage is defined as damage to protected species and natural habitats (significant adverse effects on favourable conservation status), water damage (significant adverse effects on ecological, chemical, or quantitative status per Directive 2000/60/EC), and land damage (contamination creating significant risk to human health). The Directive applies to environmental damage caused by occupational activities listed in Annex III, and to damage to protected species and natural habitats from other occupational activities only if the operator is at fault or negligent. Operators must take immediate preventive measures when there is an imminent threat of damage and inform the competent authority, which can require information, take measures, or give instructions. Operators must also take remedial measures when damage occurs, including controlling contaminants and implementing primary, complementary, and compensatory remediation as per Annex II. The competent authority assesses significance, identifies the liable operator, determines remedial measures, and can take actions itself if the operator fails. The Directive does not apply to armed conflict, natural phenomena, certain international conventions, nuclear risks, or activities for national defense. It has a five-year limitation period for cost recovery from completion of measures or identification of liable party, whichever is later. Member States were required to implement by 30 April 2007. The Directive does not cover personal injury, private property damage, or economic loss and does not give private parties a right of compensation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-epa-market-access-acp-states-regulation-2016-1076",
    "title": "Regulation (EU) 2016/1076 of the European Parliament and of the Council of 8 June 2016 applying the arrangements for products originating in certain states which are part of the African, Caribbean and Pacific (ACP) Group of States provided for in agreements establishing, or leading to the establishment of, Economic Partnership Agreements",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation applies the trade arrangements for products originating in certain African, Caribbean and Pacific (ACP) States provided for in agreements establishing, or leading to the establishment of, Economic Partnership Agreements (Article 1). It grants market access by eliminating customs duties on imports of products originating in the listed regions and states (Articles 2 and 4), subject to the rules of origin (Article 5) and administrative cooperation (Article 6), and provides for safeguard measures, including provisional safeguard measures, where imports cause or threaten to cause serious injury (Articles 11, 12 and 14).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dual-use-regulation-2021-821",
      "eu-foreign-subsidies-regulation-2022-2560"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-epbd-2024-energy-performance-certificates-nzeb",
    "title": "EU Energy Performance of Buildings Directive 2024/1275 - Energy Performance Certificates and NZEB Standards",
    "domain": "Construction & Real Estate",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Energy Performance of Buildings Directive (EPBD) recast 2024/1275 mandates energy performance certificates (EPCs) for all buildings sold, rented, or undergoing major renovation; requires all new buildings to be zero-emission buildings (ZEB) from 2028 (public) and 2030 (all); establishes minimum energy performance standards (MEPS) requiring member states to ensure the worst-performing building stock (bottom 16% non-residential by 2030, bottom 26% residential by 2033) is renovated to at least energy performance class E; and introduces renovation passports as voluntary long-term renovation roadmaps. National building renovation plans must target an 'emission free' building stock by 2050.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-energy-performance-buildings-directive-2024-recast",
      "eu-energy-efficiency-directive-2023-1791"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-epbd-energy-performance-buildings-2024-1275",
    "title": "EU Energy Performance of Buildings Directive (EU) 2024/1275 (EPBD recast)",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Directive (EU) 2024/1275 (the Energy Performance of Buildings Directive EPBD recast) sets out the EU framework for reducing greenhouse gas emissions and final energy consumption in the building sector with a target of climate-neutral building stock by 2050. Key provisions: zero-emission buildings (ZEB) standard for new buildings (new public buildings from 1 Jan 2028 all new buildings from 1 Jan 2030); national renovation roadmaps; mandatory minimum energy performance standards (MEPS) for worst-performing buildings residential 16% by 2030 and 20-22% by 2035 non-residential 16% by 2030 and 26% by 2033; energy performance certificates (EPC) framework strengthened with harmonised scale A-G and additional information including solar potential; mandatory solar deployment on new buildings and major renovations; smart readiness indicator (SRI).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-epbd-nearly-zero-energy-buildings-definition",
    "title": "Directive 2010/31/EU of the European Parliament and of the Council on the energy performance of buildings (recast) - Articles 9-11: Nearly Zero-Energy Buildings, Cost-Optimal Methodology and Requirements for New Buildings",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "EU Member States must define and implement national standards for nearly zero-energy buildings (NZEBs) for all new buildings by 31 December 2020, and for new public buildings by 31 December 2018, in accordance with Article 9. The definition must include very high energy performance, a nearly zero or very low amount of energy from renewable sources, and be based on cost-optimal methodologies per Article 5. Applies to all new buildings and public building owners.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-construction-sector-emissions-buildings-renovation",
      "iso-50001-2018-energy-management-systems",
      "iso-19650-bim-information-management-construction"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-epbd-recast-2024-energy-performance-buildings",
    "title": "Directive (EU) 2024/1275 of the European Parliament and of the Council of 24 April 2024 on the energy performance of buildings (recast)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This directive mandates that all new buildings be zero-emission buildings (ZEBs) by 2030 (2028 for public buildings) and requires EU Member States to establish national building renovation plans to achieve a fully decarbonised building stock by 2050, including phasing out fossil fuel boilers by 2040 (Article 7 & 9). It also strengthens requirements for Energy Performance Certificates (EPCs) and introduces a voluntary Renovation Passport scheme.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate-related-disclosures",
      "iso-14064-ghg-reporting-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-eprivacy-directive-2002-58",
    "title": "Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This directive, often called the 'Cookie Law,' requires providers of electronic communications services to obtain prior, informed consent from users before storing or accessing information on their terminal equipment (e.g., cookies, pixels), as mandated by Article 5(3). It also establishes rules for the processing of traffic and location data and unsolicited communications (direct marketing).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-art-21-marketing-optout",
      "iab-tcf-v2-2-consent"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-eprivacy-directive-2002-58-marketing",
    "title": "Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU ePrivacy Directive 2002/58/EC requires prior opt-in consent for electronic direct marketing via email, SMS, or automated calls, with a limited 'soft opt-in' exception for existing customers under Article 13(1). It applies to all organizations sending marketing messages to individuals in the EU using electronic communications services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eprivacy-directive-2002-58",
      "eu-ecommerce-directive-2000-31",
      "eu-unfair-commercial-practices-2005-29",
      "coppa-marketing-kids",
      "can-spam-act-email"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-eprivacy-regulation-proposed-2017",
    "title": "Proposal for a Regulation of the European Parliament and of the Council concerning the respect for private life and the protection of personal data in electronic communications and repealing Directive 2002/58/EC (Regulation on Privacy and Electronic Communications)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The proposed ePrivacy Regulation strengthens the confidentiality of electronic communications and modernizes rules for tracking technologies, requiring user consent for processing communications data and for using cookies, unless strictly necessary for service provision (Articles 5, 6 & 8). It applies to all providers of electronic communications services and networks within the EU, including over-the-top services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-46-transfer-mechanisms"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-eqf-council-recommendation-2017-nqf-referencing",
    "title": "Council recommendation of 22 May 2017 on the European Qualifications Framework for lifelong learning and repealing the recommendation of the European Parliament and of the Council of 23 April 2008 on the establishment of the European Qualifications Framework for lifelong learning (2017/C 189/03)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This recommendation requires EU Member States to reference their national qualifications frameworks to the European Qualifications Framework (EQF) to improve the transparency, comparability, and portability of qualifications across the Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-eqf-european-qualifications-framework-2017",
    "title": "Council Recommendation of 22 May 2017 on the European Qualifications Framework for lifelong learning and repealing the recommendation of the European Parliament and of the Council of 23 April 2008 on the establishment of the European Qualifications Framework for lifelong learning",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This EU Council Recommendation establishes a common reference framework of eight qualification levels defined by learning outcomes (knowledge, skills, and responsibility/autonomy) to improve the transparency, comparability, and portability of qualifications across Europe. It calls on Member States to reference their national qualifications frameworks (NQFs) to the EQF and ensure quality assurance mechanisms are in place, as detailed in Annexes I and II.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-equal-treatment-employment-2000-78",
    "title": "Council Directive 2000/78/EC of 27 November 2000 establishing a general framework for equal treatment in employment and occupation",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This Directive establishes a general framework for combating discrimination on the grounds of religion or belief, disability, age or sexual orientation as regards employment and occupation, with a view to putting into effect in the Member States the principle of equal treatment (Article 1). It applies to all persons, as regards both the public and private sectors, including public bodies, in relation to conditions for access to employment, vocational guidance, employment and working conditions, and membership of organisations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "eu-pay-transparency-directive-2023",
      "eu-work-life-balance-directive-2019",
      "eu-whistleblower-directive-2019"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-erasmus-charter-higher-education-2021",
    "title": "Erasmus Charter for Higher Education (ECHE) 2021-2027",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The ECHE 2021-2027 sets mandatory conditions for higher education institutions (HEIs) in Erasmus+ participating countries to engage in mobility and cooperation activities, requiring formal commitment to principles including Learning Agreement use, recognition of study periods abroad, language support via OLS, and inclusion. Compliance is verified under Article 10 of Regulation (EU) 2021/817.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-erasmus-programme-regulation-2021-817",
      "bologna-process-higher-education-area-2020",
      "eu-european-qualifications-framework-eqf",
      "eu-digital-education-action-plan-2021-2027-deap"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-erasmus-programme-regulation-2021-817",
    "title": "Regulation (EU) 2021/817 of the European Parliament and of the Council of 20 May 2021 establishing the Erasmus+ Programme and repealing Regulations (EU) No 1288/2013 and (EU) No 1293/2013",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Establishes the Erasmus+ Programme for 2021-2027, governing mobility and cooperation in higher education, vocational training, school education, and adult learning. Requires participating organisations to hold an Erasmus Charter for Higher Education (ECHE) and comply with grant conditions under Article 11 and Annex I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-education-action-plan-2021-2027-deap",
      "eu-european-research-area-policy-agenda-2022",
      "eu-open-science-policy-fair-data-principles-2021",
      "iso-21001-2018-educational-organizations-management",
      "oecd-principles-ai-in-education-recommendation-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-erasmus-regulation-2021-817",
    "title": "EU Erasmus Regulation 2021/817 - Erasmus Plus Programme 2021-2027, Key Actions, and National Agency Implementation",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Regulation (EU) 2021/817 of the European Parliament and of the Council establishing the Erasmus+ programme for education, training, youth and sport for 2021-2027 was published on 20 May 2021 and applies from 1 January 2021. Article 1 establishes the Erasmus+ programme covering higher education, vocational education and training (VET), school education, adult education, youth, and sport. Article 6 allocates a budget of EUR 26.2 billion for the 2021-2027 period, compared to EUR 14.7 billion for the 2014-2020 programme. The programme is structured around three Key Actions: Key Action 1 (KA1) - Learning Mobility of Individuals including exchanges of students, staff, apprentices, and youth workers; Key Action 2 (KA2) - Cooperation Partnerships between educational institutions, youth organisations, and other relevant bodies; and Key Action 3 (KA3) - Support for Policy Reform and Development, including the European Education Area, European Student Card, and Euroguidance. Higher education institutions (HEIs) participating in KA1 student and staff mobility must hold an Erasmus Charter for Higher Education (ECHE) awarded by the European Commission. The programme is implemented by National Agencies in each participating country under the supervision of the European Commission and EACEA (European Education and Culture Executive Agency).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_higher_education_act_1965",
        "eu_digital_education_action_plan",
        "eu_european_higher_education_area_bologna",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ferpa-family-educational-rights-privacy-1974",
      "us-idea-individuals-disabilities-education-act-2004",
      "eu-services-directive-2006-123"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-erasmus-regulation-2021-817-mobility-obligations",
    "title": "Regulation (EU) 2021/817 of the European Parliament and of the Council of 20 May 2021 establishing Erasmus+: the Union Programme for education and training, youth and sport and repealing Regulation (EU) No 1288/2013",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This regulation establishes the Erasmus+ Programme to promote learning mobility, cooperation, and innovative policy development in education, training, youth, and sport to strengthen European identity and build inclusive, cohesive, and resilient societies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-esef-regulation-2019-815",
    "title": "EU ESEF Regulation 2019/815 - European Single Electronic Format iXBRL Tagging and Annual Financial Report Digital Submission",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Commission Delegated Regulation (EU) 2019/815 on the European Single Electronic Format (ESEF) was published on 17 December 2019 and became mandatory for financial years beginning on or after 1 January 2020 for issuers whose securities are admitted to trading on an EU regulated market; the Regulation implements Article 4(7) of the Transparency Directive 2013/50/EU which required the European Securities and Markets Authority (ESMA) to develop a single electronic format for annual financial reports; ESEF mandates that annual financial reports filed with the official mechanism in each EU member state must be prepared in Inline XBRL (iXBRL) format - a machine-readable format that embeds XBRL tags within a human-readable HTML document; the tagging must use the ESMA ESEF XBRL Taxonomy (an extension of the IFRS Foundation's IFRS Taxonomy) with three phases of implementation: Phase 1 (financial years beginning on or after 1 January 2020) - consolidated IFRS financial statements primary financial statements tagged in iXBRL; Phase 2 (financial years beginning on or after 1 January 2022) - all notes to the consolidated financial statements also tagged; Phase 3 (financial years beginning on or after 1 January 2024) - non-IFRS financial information including ESG disclosures to be tagged under ESRS (European Sustainability Reporting Standards); ESMA publishes updated versions of the ESEF Taxonomy annually; the ESEF Reporting Manual is published by ESMA as non-binding guidance on tagging methodology.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electronic-invoicing-directive-2014-55"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-esfri-research-infrastructure-roadmap-2021",
    "title": "EU ESFRI Roadmap 2021 - European Research Infrastructures: Landmark and Project Status, Implementation Stages, Governance, Access Policy and Financial Sustainability Requirements",
    "domain": "Education & Research",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The ESFRI Roadmap 2021 identifies research infrastructures of pan-European relevance and outlines their implementation stages, governance models, access policies, and financial sustainability requirements. It applies to EU Member States, associated countries, and entities involved in the development and operation of large-scale research infrastructures across Europe.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-european-research-area-policy-agenda-2022",
      "eu-open-science-policy-fair-data-principles-2021",
      "eu-digital-education-action-plan-2021-2027-deap"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-esg-rating-activities-regulation-2024-3005",
    "title": "Regulation (EU) 2024/3005 on the transparency and integrity of ESG rating activities - ESMA authorisation of ESG rating providers, methodology disclosure and supervision",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Regulation (EU) 2024/3005, adopted 27 November 2024, introduces a common regulatory approach for ESG rating activities in the EU and amends Regulations (EU) 2019/2088 and (EU) 2023/2859. It applies to ESG ratings issued by ESG rating providers operating in the Union, requires providers to be authorised by ESMA, and obliges Union-established providers to apply to ESMA for authorisation. Providers must publicly disclose the methodologies, models and key rating assumptions they use, and ESMA may require all information necessary for its supervisory tasks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-sfdr-regulation-2019-2088-sustainable-finance-disclosure",
      "eu-taxonomy-regulation-2020-852-sustainable-finance-classification",
      "iosco-esg-ratings-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-esma-mica-rts-technical-standards-2024",
    "title": "ESMA Final Report: Draft Regulatory Technical Standards under Markets in Crypto-Assets Regulation (MiCA) specifying requirements for CASP supervisory college composition, crypto-asset whitepaper templates, reverse solicitation, and conflicts of interest management",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This package of Regulatory Technical Standards (RTS) under MiCA specifies detailed operational requirements for Crypto-Asset Service Providers (CASPs), including the precise format and content for crypto-asset whitepapers (Article 6(10)), criteria for determining reverse solicitation (Article 61(7)), and procedures for identifying, preventing, managing, and disclosing conflicts of interest (Article 72(5)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mica-regulation-2023",
      "eu-mica-casp-obligations",
      "eu-mica-asset-referenced-tokens",
      "eu-mica-e-money-tokens"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-esma-regulation-1095-2010",
    "title": "EU ESMA Regulation 1095/2010 - European Securities and Markets Authority Powers & Supervisory Convergence",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation 1095/2010 established the European Securities and Markets Authority (ESMA) as the EU supervisory authority for securities and capital markets. ESMA has binding direct supervisory authority over: credit rating agencies (CRAs), trade repositories (TRs), EU-wide systemic financial market infrastructures, and (under EMIR 2.2) Tier 2 third-country CCPs. ESMA issues binding technical standards (RTS/ITS), guidelines, Q&As, and opinions to promote supervisory convergence. ESMA may take emergency action to restrict or prohibit financial activities threatening EU market integrity. The ESRB-ESMA interface governs macro-prudential signals to securities markets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-emir-regulation-648-2012",
      "eu-esrb-regulation-1092-2010",
      "eu-credit-rating-agencies-regulation-1060-2009"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-espr-ecodesign",
    "title": "Ecodesign for Sustainable Prod",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Regulation (EU) 2024/1781 establishes a comprehensive framework for setting ecodesign requirements for sustainable products, significantly expanding upon its predecessor, Directive 2009/125/EC. As a cornerstone of the Circular Economy Action Plan, this regulation mandates stringent performance and information criteria to promote durability, reusability, and environmental transparency. Compliance necessitates meeting specific performance thresholds, including achieving a `minimum_recycled_content_percentage` of 25 percent and ensuring `energy_efficiency_class_threshold_met` targets are satisfied. Durability is centrally addressed through obligations for a `minimum_spare_parts_availability_years` of 10 and a `minimum_firmware_support_years` of 5, supported by a calculated `reparability_score_calculated`. A critical information requirement, detailed within ESPR Articles 8-13, is that a `digital_product_passport_generated` must be produced, with its associated `dpp_data_carrier_accessible` for consumers and authorities. This passport discloses data from a required `lifecycle_assessment_completed`, a declared `product_carbon_footprint_declared`, and confirms `substances_of_concern_present_tracked` in alignment with frameworks like Regulation (EC) No 1907/2006 (REACH). Furthermore, under ESPR Article 25, a strict prohibition on the destruction of unsold consumer products, particularly apparel, is enforced; compliance is verified by the `unsold_consumer_goods_destroyed` metric being false. These integrated requirements ensure products placed on the Union market adhere to a holistic standard of environmental sustainability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-battery-passport",
      "eu-taxonomy-sustainable",
      "reach-chemical-comp",
      "rohs-hazardous-sub",
      "weee-electronic-waste"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-esrb-regulation-1092-2010",
    "title": "EU ESRB Regulation 1092/2010 - European Systemic Risk Board Macro-Prudential Framework",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 1092/2010 establishes the European Systemic Risk Board (ESRB) responsible for macro-prudential oversight of the EU financial system. The ESRB monitors systemic risk, issues risk warnings and recommendations (comply-or-explain), and coordinates macro-prudential policies across member states. Its recommendations are non-binding but create a formal comply-or-explain obligation for the recipient. The ESRB Secretariat is hosted at the ECB. Revised by Regulation 2019/2176 to incorporate the banking union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-emir-regulation-648-2012",
      "eu-brrd-bank-recovery-resolution-directive-2014-59",
      "eu-single-resolution-mechanism-regulation-806-2014"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-esrs-1-general-requirements",
    "title": "European Sustainability Reporting Standards 1 (ESRS 1) - General Requirements",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ESRS 1 is the foundational cross-cutting standard under the EU Corporate Sustainability Reporting Directive (CSRD). It sets the mandatory architecture for all sustainability statements: the double materiality assessment (impact materiality and financial materiality), the qualitative characteristics of information, sustainability due diligence, value-chain coverage, the short/medium/long-term time horizons, and the four reporting areas (governance; strategy; impact, risk and opportunity management; metrics and targets). ESRS 1 sets no disclosure requirements of its own; it governs how every topical standard (E1-E5, S1-S4, G1) is applied.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-esrs-e1-climate-change",
      "eu-csddd-corporate-sustainability-due-diligence-2024-1760",
      "eu-taxonomy-regulation-2020-852"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-esrs-2-general-disclosures",
    "title": "European Sustainability Reporting Standards 2 (ESRS 2) - General Disclosures",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ESRS 2 sets the disclosure requirements that every undertaking reporting under the CSRD must provide regardless of which topical standards are material. It covers the basis for preparation (BP-1, BP-2), governance (GOV-1 to GOV-5 including the statement on due diligence), strategy and business model (SBM-1 to SBM-3), and the processes to identify and assess material impacts, risks and opportunities (IRO-1, IRO-2). ESRS 2 is mandatory in full and is applied together with ESRS 1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-esrs-e1-climate-change",
      "eu-esrs-s1-workforce",
      "eu-esrs-g1-business-conduct"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-esrs-e1-climate-change",
    "title": "European Sustainability Reporting Standards E1 (ESRS E1) - Climate Change",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "ESRS E1 requires undertakings under the EU's Corporate Sustainability Reporting Directive (CSRD) to disclose their climate-related impacts, risks, and opportunities, including a transition plan for climate change mitigation (E1-1), policies (E1-2), actions (E1-3), targets (E1-4), energy consumption (E1-5), and detailed GHG emissions for Scopes 1, 2, and 3 (E1-6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "ghg-protocol-scope3",
      "tcfd-climate-risk",
      "issb-ifrs-s2-climate-2023",
      "iso-14064-ghg-reporting"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-esrs-e2-pollution",
    "title": "European Sustainability Reporting Standards (ESRS) E2: Pollution",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "ESRS E2 requires undertakings subject to the Corporate Sustainability Reporting Directive (CSRD) to disclose their policies, actions, targets, and metrics concerning the prevention, control, and reduction of pollution of air, water, and soil, and concerning substances of very high concern (SVHCs) and other hazardous substances. This includes quantitative reporting on pollutants and disclosure of potential financial effects from pollution-related impacts, risks, and opportunities, as outlined in Disclosure Requirements E2-1 to E2-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-taxonomy-sustainable",
      "reach-chemical-comp",
      "gri-universal-standards"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-esrs-e3-water-marine-resources",
    "title": "European Sustainability Reporting Standards E3 (ESRS E3) - Water and Marine Resources",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ESRS E3 requires undertakings under the CSRD to disclose their material impacts, risks and opportunities related to water and marine resources, including policies (E3-1), actions and resources (E3-2), measurable targets (E3-3), water consumption metrics including water withdrawal, discharge and consumption in areas of water stress (E3-4), and the anticipated financial effects from water and marine resources-related risks and opportunities (E3-5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-esrs-e1-climate-change",
      "eu-esrs-e2-pollution",
      "iso-14046-water-footprint"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-esrs-e4-biodiversity-ecosystems",
    "title": "European Sustainability Reporting Standards E4 (ESRS E4) - Biodiversity and Ecosystems",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ESRS E4 requires undertakings under the CSRD to disclose their material impacts, dependencies, risks and opportunities related to biodiversity and ecosystems. It covers a transition plan and the consideration of biodiversity in the business model (E4-1), policies (E4-2), actions and resources (E4-3), measurable targets (E4-4), impact metrics on biodiversity and ecosystem change including land-use and species (E4-5), and anticipated financial effects (E4-6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "un-cbd-kunming-montreal-gbf-2022",
      "tnfd-nature-disclosure",
      "eu-nature-restoration-regulation-2024-1991"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-esrs-e5-resource-use-circular-economy",
    "title": "European Sustainability Reporting Standards E5 (ESRS E5) - Resource Use and Circular Economy",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ESRS E5 requires undertakings under the CSRD to disclose material impacts, risks and opportunities related to resource use and the circular economy. It covers policies (E5-1), actions and resources (E5-2), measurable targets (E5-3), resource inflows including the mass of products and materials and the share of secondary reused or recycled content (E5-4), resource outflows including waste and durable, repairable and recyclable products (E5-5), and anticipated financial effects (E5-6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-esrs-e2-pollution",
      "eu-waste-framework-directive-2008-98",
      "eu-taxonomy-regulation-2020-852"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-esrs-g1-business-conduct",
    "title": "ESRS G1 Business Conduct",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard requires undertakings subject to the CSRD to disclose their strategies, policies, actions, metrics, and targets related to business conduct. As per Disclosure Requirement G1-1, this includes corporate culture, management of relationships with suppliers, and prevention and detection of corruption or bribery.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "gri-universal-standards",
      "uk-bribery-act-2010",
      "iso-26000-social-resp"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-esrs-s1-workforce",
    "title": "EU ESRS S1 - Own Workforce: Working Conditions, Equal Treatment, Wages and Social Protection",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard requires undertakings under the CSRD to disclose information on material impacts, risks, and opportunities related to their own workforce, covering working conditions, equal treatment, and other social matters. As per ESRS S1 paragraph 1, the objective is to enable users to understand how the undertaking affects its own workforce and the related governance, strategy, and performance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "gri-universal-standards",
      "ilo-fundamental-rights-work",
      "iso-30414-human-capital",
      "iso-26000-social-resp"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-esrs-s2-value-chain-workers",
    "title": "European Sustainability Reporting Standards S2 (ESRS S2) - Workers in the Value Chain",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ESRS S2 requires undertakings under the CSRD to disclose how they affect workers in their upstream and downstream value chain and how material impacts, risks and opportunities are managed. It covers the consideration of value-chain workers in strategy (SBM-2, SBM-3), policies (S2-1), engagement processes (S2-2), remediation and grievance channels (S2-3), action taken on material impacts (S2-4), and measurable targets (S2-5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-esrs-s1-workforce",
      "eu-csddd-corporate-sustainability-due-diligence-2024-1760",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-esrs-s3-affected-communities",
    "title": "European Sustainability Reporting Standards S3 (ESRS S3) - Affected Communities",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ESRS S3 requires undertakings under the CSRD to disclose how their operations and value chain affect communities, including local, indigenous and other affected communities, and how material impacts, risks and opportunities are managed. It covers the consideration of affected communities in strategy (SBM-2, SBM-3), policies (S3-1), engagement processes (S3-2), remediation and grievance channels (S3-3), action taken on material impacts (S3-4), and measurable targets (S3-5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-esrs-s1-workforce",
      "eu-csddd-corporate-sustainability-due-diligence-2024-1760",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-esrs-s4-consumers-end-users",
    "title": "European Sustainability Reporting Standards S4 (ESRS S4) - Consumers and End-users",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ESRS S4 requires undertakings under the CSRD to disclose how their products and services affect consumers and end-users and how material impacts, risks and opportunities are managed. It covers the consideration of consumers and end-users in strategy (SBM-2, SBM-3), policies (S4-1), engagement processes (S4-2), remediation and grievance channels (S4-3), action taken on material impacts (S4-4), and measurable targets (S4-5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-esrs-s1-workforce",
      "eu-csddd-corporate-sustainability-due-diligence-2024-1760",
      "eu-esrs-g1-business-conduct"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ets-directive-2003-87",
    "title": "EU Emissions Trading System Directive 2003/87/EC",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Directive 2003/87/EC established the EU Emissions Trading System (EU ETS) the world's first major carbon market and a cornerstone of EU climate policy. The EU ETS operates on a cap-and-trade basis covering ~10,000 power stations and industrial plants in 30 European countries (EU 27 + Iceland Liechtenstein Norway) plus aviation. EU ETS Phase 4 (2021-2030) reformed via Directive (EU) 2023/959 (\"Fit for 55\"): -62% emissions by 2030 vs 2005; ETS extended to maritime transport (2024); separate ETS2 created for road transport buildings (2027); Carbon Border Adjustment Mechanism (CBAM) per Regulation 2023/956 transitional 2023-2025 definitive from 2026; free allocation phase out for CBAM sectors and aviation; Market Stability Reserve enhanced.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ets-directive-2003-87-emissions-trading-scheme",
    "title": "EU Emissions Trading System Directive 2003/87/EC - Cap-and-Trade Carbon Market Compliance",
    "domain": "Energy & Utilities",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive 2003/87/EC establishes the EU Emissions Trading System (EU ETS), the world's first major cap-and-trade scheme for greenhouse gas emissions and the world's largest carbon market by volume. Covered installations - power plants, industrial facilities above capacity thresholds, aviation operators, and (since 2024) maritime operators - must hold EU Allowances (EUAs) equal to their verified annual emissions (Article 12). Phase IV (2021-2030) tightens the linear reduction factor (LRF) to 4.2% per year (amended to 4.3% from 2024 per Directive 2023/959), reducing the total cap annually. Free allocations are phased out for power generators and partially maintained for industry based on benchmarks (Annex I activities). The Market Stability Reserve (MSR), operational since January 2019, absorbs surplus allowances when total number of allowances in circulation (TNAC) exceeds 833 million. The EU ETS 2 (Directive 2023/958) covers buildings, road transport, and additional sectors from 2027. Installations must surrender allowances by 30 April each year for prior-year emissions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ets-reform-2023-phase-iv-market-stability",
      "eu-cbam-2023-956-carbon-border-adjustment",
      "eu-renewable-energy-directive-2023-2413-red-iii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ets-phase-iv-2021-2030-rules",
    "title": "Directive (EU) 2018/410 of the European Parliament and of the Council of 14 March 2018 amending Directive 2003/87/EC to enhance cost-effective emission reductions and low-carbon investments, and Decision (EU) 2015/1814",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes the rules for Phase IV (2021-2030) of the EU Emissions Trading System, requiring stationary installations, aviation operators, and maritime transport to surrender allowances for their verified greenhouse gas emissions. It introduces a steeper annual emissions cap reduction (Linear Reduction Factor of 2.2%), updated free allocation benchmarks, and enhanced rules for the Market Stability Reserve (MSR) as detailed in the amended Article 9 of Directive 2003/87/EC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ets-reform-2023-phase-iv-market-stability",
    "title": "Directive (EU) 2023/959 of the European Parliament and of the Council of 10 May 2023 amending Directive 2003/87/EC establishing a system for greenhouse gas emission allowance trading within the Union and Decision (EU) 2015/1814 concerning the establishment and operation of a market stability reserve for the Union greenhouse gas emission trading scheme",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This directive mandates a steeper reduction in the EU-wide emissions cap, strengthens the Market Stability Reserve (MSR) by increasing the intake rate and invalidating allowances, and phases out free emission allowances for sectors covered by the Carbon Border Adjustment Mechanism (CBAM) between 2026 and 2034. These changes, amending Directive 2003/87/EC (Article 9 and 10a), apply to all stationary installations, aviation operators, and maritime transport companies under the EU Emissions Trading System.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ets-revision-2023-fit-for-55",
    "title": "Directive (EU) 2023/959 (Fit for 55 ETS Revision) - Revised EU Emissions Trading System: 62% Reduction Target by 2030, Maritime Inclusion from 2024, ETS2 for Buildings and Road Transport from 2027, Phase-Out of Free Allowances, Linear Reduction Factor 4.3-4.4% and Social Climate Fund",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive (EU) 2023/959 of 10 May 2023 significantly amends Directive 2003/87/EC (the EU Emissions Trading System) to align the ETS with the EU's 2030 climate target of at least 55% net GHG reduction under the European Climate Law; key changes include: a 2030 ETS reduction target of 62% below 2005 levels; extension to maritime shipping from 2024; creation of a separate ETS2 for buildings and road transport from 2027 (or 2028 if energy prices remain exceptionally high); an increased Linear Reduction Factor (LRF) of 4.3% (2024-2027) and 4.4% (2028-2030); a one-off deletion of 90 million allowances in 2024; phased elimination of free aviation allowances (2026-2033) aligned with CBAM implementation; and establishment of the Social Climate Fund funded by ETS2 auction revenues to support vulnerable households and transport users through the green transition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_CBAM",
        "EU_CSRD",
        "EU_SOCIAL_CLIMATE_FUND",
        "EU_CLIMATE_LAW"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cbam-carbon-border-adjustment-2023",
      "eu-taxonomy-regulation-2020-852",
      "eu-renewable-energy-directive-red-iii-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-eu-drone-regulation-uas-2019-945",
    "title": "Commission Delegated Regulation (EU) 2019/945 on unmanned aircraft systems and on third-country operators of unmanned aircraft systems",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Establishes safety and environmental requirements for the design, production, and operation of unmanned aircraft systems (UAS) in the European Union, categorizing operations into Open, Specific, and Certified. Applies to manufacturers, operators, and remote pilots under Articles 10 and 11, with remote identification mandated under Article 14a.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-education-action-plan-2021-2027-deap",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-eu-ets-maritime-2024-shipping",
    "title": "Regulation (EU) 2023/957 of the European Parliament and of the Council of 10 May 2023 amending Directive 2003/87/EC so as to improve and extend the EU Emissions Trading System to include maritime transport, and Regulation (EU) 2023/1805 on the use of renewable and low-carbon fuels in maritime transport and amending Directive 2009/16/EC",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation requires ship operators of vessels above 5,000 gross tonnage (GT) conducting voyages within, to, or from EU ports to monitor, report, and surrender EU ETS allowances for CO2 emissions starting at 40% coverage in 2024, increasing to 100% by 2026, under Article 26a of Directive 2003/87/EC as amended by Regulation (EU) 2023/957. It applies to all relevant intra-EU, incoming, and outgoing voyages, including calls at non-EU ports.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14090-climate-adapt",
      "iso-15489-1-2016-records-management-workflow"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-eudamed-functionality-decision-2025-2371",
    "title": "Commission Decision (EU) 2025/2371 of 26 November 2025 on the notice regarding the functionality and the fulfilment of the functional specifications of certain electronic systems included in the European Database on Medical Devices (EUDAMED) referred to in Article 34(1) of Regulation (EU) 2017/745",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "This Commission Decision confirms that four EUDAMED electronic systems (registration of economic operators, UDI/device registration, notified bodies and certificates, and market surveillance) have achieved functionality and meet the functional specifications, which starts the transition periods under MDR Article 123(3) points (d) to (ec) and IVDR Article 113(3) points (f) to (fd) as from the date of publication of this Decision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mdr-2017-745",
      "eu-in-vitro-diagnostics-regulation-2017-746",
      "eu-mdr-2017-745-post-market-surveillance"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-eudr-amendment-2025-2650-deforestation-simplification",
    "title": "Regulation (EU) 2025/2650 of the European Parliament and of the Council of 19 December 2025 amending Regulation (EU) 2023/1115 as regards certain obligations of operators and traders",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "This Regulation postpones the EU Deforestation Regulation application for large operators and non-SME traders to 30 December 2026 (and to 30 June 2027 for micro and small operators established by 31 December 2024), introduces a 'downstream operator' category with simplified obligations, lets micro and small primary operators file a one-time simplified declaration instead of full due diligence, and permits a postal address in place of geolocation in defined cases.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-deforestation-regulation-2023-1115",
      "eu-deforestation-regulation-2023-1115-article-8-due-diligence-operators",
      "eu-deforestation-regulation-2023-1115-article-3-prohibition-placing-market"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-eudr-deforestation-regulation-2023-1115",
    "title": "EU Deforestation Regulation 2023/1115 (EUDR) - Deforestation-Free Supply Chain Due Diligence",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "EU Regulation 2023/1115 prohibits placing on the EU market or exporting from the EU any products associated with deforestation or forest degradation after 31 December 2020. Covers 7 commodity groups: cattle, cocoa, coffee, palm oil, soya, wood, and rubber, plus derived products. Operators must conduct due diligence including geolocation of all relevant plots, satellite monitoring compliance verification, and country risk classification. AI-driven supply chain traceability platforms, satellite deforestation monitoring tools, and agricultural sourcing analytics must produce EUDR-compliant geolocation data and due diligence statements. Applies from 30 December 2024 (large operators); 30 June 2025 (SMEs).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standards",
        "frameworks",
        "regulations",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-common-agricultural-policy-regulation-2021-2115",
      "eu-water-framework-directive-2000-60-ec"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-euro-7-emission-regulation-proposal-2022",
    "title": "Proposal for a Regulation of the European Parliament and of the Council on type-approval requirements for motor vehicles and engines with respect to emissions from light and heavy-duty vehicles (Euro 7)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Establishes unified Euro 7 emission limits for light- and heavy-duty vehicles, including brake and tyre particle emissions, and mandates enhanced on-board diagnostic (OBD) systems for real-world monitoring. Applies to all manufacturers placing new vehicles on the EU market under Article 5 and Annex I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-iec-15031-on-board-diagnostic-obd-standards"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-eurodac-regulation-2024-1358",
    "title": "Regulation (EU) 2024/1358 establishing 'Eurodac' for the comparison of biometric data - collection from age six, 72-hour transmission, ten-year retention and law-enforcement access",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Regulation (EU) 2024/1358, adopted 14 May 2024, re-establishes the Eurodac system for the comparison of biometric data and repeals Regulation (EU) No 603/2013. Member States must take the biometric data of applicants for international protection who are at least six years of age, transmit the data to Eurodac no later than 72 hours after apprehension, and store data of applicants for a maximum of ten years. Designated law-enforcement authorities may request comparison only where reasonable grounds exist that it will assist law enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dublin-iii-regulation-604-2013-asylum-responsibility",
      "eu-reception-conditions-directive-2024-1346",
      "eu-fdi-screening-regulation-2019-452"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-european-accessibility-act-2019-882-digital-product-service-requirements",
    "title": "EU European Accessibility Act 2019/882 - Accessibility Requirements for Digital Products and Services",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive (EU) 2019/882 (European Accessibility Act) mandates accessibility requirements for a broad range of products and services sold or provided in the EU from 28 June 2025, covering computers, smartphones, e-commerce, banking, e-books, transport services, and audiovisual media. Non-compliant products and services must not be placed on the EU market, with penalties determined by Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-european-citizens-initiative-regulation-2019-788",
    "title": "Regulation (EU) 2019/788 of the European Parliament and of the Council of 17 April 2019 on the European citizens initiative",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation sets the procedures and conditions for a European citizens initiative, by which one million citizens of the Union who are nationals of a significant number of Member States may invite the Commission to submit a proposal for a legal act (Article 1). An initiative requires signatories from at least one quarter of Member States, with a minimum number of signatories in each (Article 3). It requires a group of organisers (Article 5), registration by the Commission (Article 6), a 12-month collection period (Article 8), collection through a central online system (Articles 9 and 10), verification and certification of statements of support by Member States (Article 12), and examination by the Commission (Article 15).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-data-governance-act-2022-868",
      "eidas2-regulation-article-11-eu-digital-identity-wallet"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-european-cloud-computing-strategy-gaia-x-data-portability",
    "title": "EU Data Act 2023/2854 - Cloud Data Portability, Vendor Lock-in Prevention, and Switching Obligations",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2024-09-12",
    "bluf": "EU Data Act (Regulation 2023/2854) imposes on cloud service providers obligations to enable customers to switch to alternative providers within maximum 30 days, eliminate switching charges by 2027, ensure data portability in interoperable formats, and comply with international data transfer restrictions for cloud-processed data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-nis2-directive-2022-2555-network-information-security"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-european-electronic-communications-code-2018-1972",
    "title": "EU European Electronic Communications Code (EECC) Directive 2018/1972",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive (EU) 2018/1972 (EECC) consolidates EU telecoms regulation into a single framework, requiring providers of electronic communications networks and services to register with national regulatory authorities (NRAs), comply with end-user rights, contribute to universal service, and meet security and resilience obligations under ENISA coordination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-european-electronic-communications-code-directive-2018-1972-eecc",
    "title": "EU European Electronic Communications Code Directive 2018/1972 - Telecoms Authorisation, Net Neutrality, and Consumer Rights",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2020-12-21",
    "bluf": "EU Directive 2018/1972 (EECC) establishes the regulatory framework for electronic communications networks and services, requiring general authorisation notification, spectrum access coordination, wholesale access remedies, net neutrality compliance, and enhanced consumer protection including contract summaries, comparison tools, and end-user switching rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-nis2-directive-2022-2555-network-information-security"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-european-electronic-communications-code-retail",
    "title": "Directive (EU) 2018/1972 of the European Parliament and of the Council of 11 December 2018 establishing the European Electronic Communications Code - Retail End-User Provisions: Contract Information Requirements, Switching and Number Portability, Emergency Services Access, Tariff Transparency, Roaming Retail Caps and Vulnerable Consumer Protection Measures",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes binding requirements for public communications providers to ensure transparent, comparable, and accessible retail contracts, facilitate number portability within one working day, guarantee access to emergency services, enforce tariff transparency, cap retail roaming charges, and protect vulnerable end-users. Key obligations are defined in Articles 106-113 and Article 115 of the EECC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-eecc-end-user-rights-universal-service",
      "eu-net-neutrality-open-internet-2015-2120",
      "eu-roaming-regulation-2022-612",
      "eu-radio-equipment-directive-2014-53-red"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-european-health-data-space-regulation-2024",
    "title": "Regulation (EU) 2025/327 of the European Parliament and of the Council of 11 February 2025 on the European Health Data Space and amending Directive 2011/24/EU and Regulation (EU) 2024/2847 (Text with EEA relevance)",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the European Health Data Space (EHDS) to enable individuals' access and control over their electronic health data across EU Member States, and to facilitate secondary use of health data for research, innovation, and policymaking under strict governance. It applies to healthcare providers, health data access bodies (HDABs), and data users relying on Article 16 and Article 114 of the Treaty on the Functioning of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gdpr-health-data-article-9",
      "eu-ehds-regulation-2024",
      "eu-health-data-space-2024",
      "eu-clinical-trials-regulation-2022",
      "eu-ctis-clinical-trials-information-system-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-european-health-data-space-regulation-2025-327",
    "title": "EU European Health Data Space Regulation (Regulation (EU) 2025/327)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2025-02-11",
    "bluf": "Regulation (EU) 2025/327 of the European Parliament and of the Council establishes the European Health Data Space (EHDS). It was published in the Official Journal of the European Union on 5 March 2025 and entered into force on 26 March 2025. Application is phased: core provisions begin to apply from 26 March 2027, with later milestones in 2029, 2031 (when secondary use of genomic data and other priority categories applies), and 2035. The EHDS Regulation creates a horizontal legal framework for the use of electronic health data including genomic data across two pillars: primary use of electronic health data for the provision of healthcare to natural persons (MyHealth@EU); and secondary use of electronic health data for research, innovation, policy-making, regulatory activities, patient safety, personalised medicine, official statistics, and education and training (HealthData@EU).\n\nThe Regulation establishes the Health Data Access Bodies (HDABs) in each Member State to grant data permits and data requests for secondary use. Chapter II creates rights for natural persons including the right to receive electronic health data, the right to transmit data to a recipient of choice, and the right to opt out of secondary use processing in accordance with national law. Chapter III establishes mandatory interoperability and security requirements through the European Electronic Health Record Exchange Format. Chapter IV creates the secondary use framework with HDABs evaluating data permit applications, processing data through secure processing environments, and ensuring de-identification or pseudonymisation. Genomic data is covered as a category of electronic health data and is subject to enhanced safeguards with secondary use applying from March 2031. The Regulation complements the General Data Protection Regulation (EU) 2016/679 and does not derogate from it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gdpr-health-data-article-9",
      "eu-ai-act-2024-1689-article-16-obligations-providers-high-risk-ai",
      "eu-eidas-2-0-digital-identity-regulation-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-european-production-orders-e-evidence-regulation-2023-1543",
    "title": "Regulation (EU) 2023/1543 of the European Parliament and of the Council of 12 July 2023 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down the rules under which an authority of a Member State may, in criminal proceedings, issue a European Production Order or European Preservation Order directly to a service provider offering services in the Union to obtain or preserve electronic evidence (Articles 1 and 2). It sets the issuing authorities and conditions, including thresholds by data category (Articles 4 and 5), the certificates (EPOC and EPOC-PR) transmitted to addressees (Articles 7 to 9), execution obligations including preservation upon receipt (Articles 10 and 11), and grounds for refusal (Article 12), with safeguards for fundamental rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-presumption-of-innocence-directive-2016-343",
      "eu-data-governance-act-2022-868"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-european-qualifications-framework-eqf",
    "title": "Council Recommendation of 22 May 2017 on the European Qualifications Framework for lifelong learning and repealing the recommendation of the European Parliament and of the Council of 23 April 2008 on the establishment of the European Qualifications Framework for lifelong learning",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This recommendation establishes the European Qualifications Framework (EQF) as an eight-level reference framework based on learning outcomes to improve transparency, comparability, and portability of qualifications across EU Member States. It applies to all education and training systems, qualifications authorities, and stakeholders involved in recognition, validation, and mobility of learning outcomes under Article 165 and 166 of the Treaty on the Functioning of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digcomp-digital-competence-framework-2022",
      "eu-digital-education-action-plan-2021-2027-deap",
      "eu-european-research-area-policy-agenda-2022",
      "eu-open-science-policy-fair-data-principles-2021",
      "iso-21001-2018-educational-organizations-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-european-research-area-policy-agenda-2022",
    "title": "EU European Research Area (ERA) Policy Agenda 2022-2024 - Priorities: Researcher Mobility, Knowledge Transfer, Research Assessment Reform and Open Science",
    "domain": "Education & Research",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The ERA Policy Agenda 2022-2024 establishes binding priorities for EU Member States and associated countries to strengthen the European Research Area by enhancing researcher mobility, enabling seamless knowledge transfer, reforming research assessment to reward quality and societal impact, and advancing Open Science practices. Key obligations are outlined in the Communication COM(2022) 69 final, with implementation monitored through national action plans under Article 21 of the Horizon Europe Regulation (EU) 2021/694.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-excise-duty-general-arrangements-directive-2020-262",
    "title": "Council Directive (EU) 2020/262 of 19 December 2019 laying down the general arrangements for excise duty (recast)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive lays down the general arrangements for excise duty levied on the consumption of energy products, alcohol and tobacco (Article 1). It defines the taxable event as the production or importation of excise goods, with duty becoming chargeable at release for consumption (Article 6), identifies the persons liable to pay (Article 7), and governs the holding and movement of excise goods under duty suspension between authorised warehouse keepers and registered consignees, with irregularities during movement triggering chargeability in the Member State where they occurred (Article 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-union-customs-code-952-2013",
      "crr-iii-eu-implementation-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-export-cultural-goods-regulation-116-2009",
    "title": "Council Regulation (EC) No 116/2009 of 18 December 2008 on the export of cultural goods",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation requires an export licence for the export of cultural goods listed in its Annex outside the EU customs territory (Article 2), to be presented in support of the export declaration when customs formalities are completed (Article 4). Member States notify the competent licence-issuing authorities to the Commission (Article 3), may limit the customs offices handling such exports (Article 5), and must lay down effective penalties for infringements (Article 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-import-cultural-goods-regulation-2019-880",
      "hague-convention-1954-cultural-property-armed-conflict"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-f-gas-regulation-2024-573",
    "title": "Regulation (EU) 2024/573 on fluorinated greenhouse gases - containment, leak checks, leakage detection, recovery and record-keeping obligations",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Regulation (EU) 2024/573, adopted 7 February 2024, lays down rules on the containment, use, recovery, recycling, reclamation and destruction of fluorinated greenhouse gases (F-gases) and repeals Regulation (EU) No 517/2014. It prohibits intentional release that is not technically necessary, mandates leak checks above defined CO2-equivalent thresholds, requires leakage detection systems on larger installations, and obliges operators to recover F-gases on decommissioning and keep records. It applies in tandem with the EU's HFC phase-down quota system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-montreal-protocol-1987-ozone-kigali-2016",
      "eu-weee-directive-2012-19",
      "eu-rohs-directive-2011-65"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-falsified-medicines-directive-2011-62",
    "title": "Directive 2011/62/EU of the European Parliament and of the Council of 8 June 2011 amending Directive 2001/83/EC on the Community code relating to medicinal products for human use, as regards the prevention of the entry into the legal supply chain of falsified medicinal products",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Directive 2011/62/EU mandates that prescription medicines bear safety features, specifically a unique identifier (UI) in a 2D barcode and an anti-tampering device (ATD), to prevent falsified products from entering the legal supply chain, as required by Article 54a. This system requires end-to-end verification, from manufacturer to the point of dispensing, via the European Medicines Verification System (EMVS).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-falsified-medicines-directive-2011-62-article-54a-safety-features",
    "title": "Directive 2011/62/EU amending Directive 2001/83/EC on the Community code relating to medicinal products for human use, as regards the prevention of the entry into the legal supply chain of falsified medicinal products - Article 54a",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must place safety features, including a unique identifier and an anti-tampering device, on the packaging of most prescription medicinal products and certain high-risk non-prescription medicinal products to allow for their identification and authentication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-falsified-medicines-directive-2011-62-ec",
    "title": "Directive 2011/62/EU of the European Parliament and of the Council of 8 June 2011 on the prevention of the entry into the legal supply chain of falsified medicinal products for human use, amending Directive 2001/83/EC and Regulation (EC) No 726/2004 of the European Parliament and of the Council and repealing Directive 2004/27/EC",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive mandates that all prescription medicines placed on the EU market must bear a unique identifier (UI) and tamper-evident feature (TEF), with verification at the point of dispensing. It applies to marketing authorisation holders, manufacturers, wholesale distributors, and pharmacies. Key requirements are established in Article 54a and Article 54b of Directive 2001/83/EC, as amended by Directive 2011/62/EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gmp-annex-1-sterile-manufacture-2022",
      "ich-q10-pharmaceutical-quality-system-2008"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-falsified-medicines-directive-2011-62-eu-serialisation-track-trace",
    "title": "EU Falsified Medicines Directive 2011/62/EU - Serialisation and Track-and-Trace Requirements",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "Directive 2011/62/EU and Commission Delegated Regulation (EU) 2016/161 require manufacturers, importers, and distributors of prescription medicines in the EU to implement a two-component safety feature system: a unique identifier (2D barcode containing product code, serial number, batch number, and expiry date) and an anti-tampering device. The European Medicines Verification System (EMVS) enables pharmacies to verify authenticity at point of dispensing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-good-manufacturing-practice-gdp-2013-c-343-4-medicinal-products",
      "eu-medicinal-products-directive-2001-83-ec"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-farm-to-fork-strategy-f2f-2030-targets",
    "title": "EU Farm to Fork Strategy 2030 Targets - Commission Communication COM(2020) 381 final (Non-Binding Strategy)",
    "domain": "Food & Hospitality",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "The EU Farm to Fork Strategy is a non-binding European Commission Communication - 'A Farm to Fork Strategy for a fair, healthy and environmentally-friendly food system', Communication COM(2020) 381 final of 20 May 2020 (CELEX 52020DC0381) - issued as a central element of the European Green Deal. It is a strategy and policy framework, not a regulation, and therefore has no articles; references to an 'Article 1 of the Farm to Fork Strategy' are incorrect. The Strategy sets four headline policy targets to be reached by 2030: at least 25% of EU agricultural land under organic farming; a 50% reduction in the use and risk of chemical pesticides (and a 50% reduction in the use of more hazardous pesticides); a reduction of at least 20% in the use of fertilisers; and a 50% reduction in the sales of antimicrobials used for farmed animals and aquaculture. These are political/policy targets pursued through an accompanying Action Plan of around 27 legislative and non-legislative measures (2020-2024), not directly enforceable obligations on individual food-business operators. The legally binding obligations relevant to these objectives are delivered through separate EU instruments - for example Regulation (EU) 2018/848 on organic production, Regulation (EC) No 1107/2009 and Directive 2009/128/EC on the sustainable use of pesticides, and Regulation (EU) 2019/6 on veterinary medicinal products (antimicrobials) - rather than through the Strategy itself. This node states the targets accurately, anchors them to COM(2020) 381 final as a non-binding Commission Communication, and points to the binding instruments where enforceable obligations actually sit, with no invented article numbers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-hygiene-regulation-852-2004",
      "eu-food-information-regulation-1169-2011-labelling",
      "eu-food-law-178-2002"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-faster-directive-2025-50-withholding-tax",
    "title": "Council Directive (EU) 2025/50 of 10 December 2024 on faster and safer relief of excess withholding taxes (FASTER)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "FASTER establishes a common EU digital tax residence certificate (eTRC) issued within 14 calendar days, two fast-track procedures for relieving excess withholding tax on cross-border dividend and interest income (relief at source and quick refund), national registers of certified financial intermediaries, and standardised reporting obligations; Member States must transpose it by 31 December 2028.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac-7-platform-economy-reporting-2021-514",
      "oecd-model-tax-convention-2017-mfn",
      "un-model-double-taxation-convention-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-fdi-screening-regulation-2019-452",
    "title": "Regulation (EU) 2019/452 - EU FDI Screening Framework: Critical Infrastructure and Technology Protection, Member State Cooperation Mechanism, Security and Public Order Grounds, and Mandatory Screening Requirements Under Revised 2024 Regulation",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2019/452 (EU FDI Screening Regulation), applicable from 11 October 2020, establishes the first EU-wide framework for Member States to screen foreign direct investments (FDI) on grounds of security and public order; key mechanisms include: voluntary screening by Member States using national mechanisms on grounds of security or public order, considering critical infrastructure (energy, transport, water, health, communications, media), critical technologies (AI, robotics, semiconductors, cybersecurity, defence, space, nuclear), supply of critical inputs, access to sensitive information, and media freedom; a cooperation mechanism requiring Member States with screening mechanisms to notify the Commission and other Member States of ongoing FDI reviews within 5 working days; the Commission and Member States may issue opinions or observations but cannot block FDI directly under the 2019/452 framework; the European Commission proposed in 2024 (Regulation (EU) 2024/1197) a revised framework requiring all Member States to establish national screening mechanisms by July 2026, significantly expanding the mandatory screening scope.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "US_CFIUS",
        "EU_CRMA",
        "EU_CHIPS_ACT_EU",
        "EU_FOREIGN_SUBSIDIES"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-competition-regulation-1-2003",
      "eu-merger-regulation-139-2004",
      "eu-critical-raw-materials-act-2024-1252"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-fertilising-products-regulation-2019-1009",
    "title": "EU Fertilising Products Regulation 2019/1009: rules on making available on the market of EU fertilising products",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Regulation (EU) 2019/1009 lays down rules on the making available on the market of EU fertilising products. It applies to EU fertilising products, defined as fertilising products which are CE marked when made available on the market. The regulation does not apply to animal by-products or derived products subject to Regulation (EC) No 1069/2009 when made available on the market, nor to plant protection products covered by Regulation (EC) No 1107/2009. It also does not affect the application of 16 other listed Union legal acts. EU fertilising products are divided into different product function categories, each subject to specific safety and quality requirements. Component materials are divided into different categories with specific process requirements and control mechanisms. Contaminants such as cadmium must be limited. The regulation includes rules on economic operator obligations, conformity assessment procedures, CE marking, notified bodies, and market surveillance. Manufacturers are responsible for conformity assessment. Importers must ensure compliance and that appropriate procedures have been carried out. Conformity assessment modules are based on Decision No 768/2008/EC. The regulation is based on Article 114 TFEU and amends Regulations (EC) No 1069/2009 and (EC) No 1107/2009, and repeals Regulation (EC) No 2003/2003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-financial-conglomerates-directive-2002-87",
    "title": "EU Financial Conglomerates Directive 2002/87 (FICOD) - Supplementary Supervision",
    "domain": "Banking & Global Finance",
    "version": "1.2.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive 2002/87/EC (FICOD) establishes supplementary supervision of credit institutions, insurance undertakings, and investment firms that form part of a financial conglomerate - a group with significant cross-sector activity (>10% in the smaller sector or >40% of total balance sheet). It requires consolidated capital adequacy, intra-group transaction monitoring, risk concentration limits, and appointment of a group-level supervisor coordinator. Amended by FICOD I (2011/89/EU) and updated by Omnibus II (2014/51/EU).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-solvency-ii-directive-2009-138",
      "mifid-ii",
      "eu-brrd-bank-recovery-resolution-directive-2014-59"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-flag-state-requirements-directive-2009-21",
    "title": "Directive 2009/21/EC of the European Parliament and of the Council of 23 April 2009 on compliance with flag State requirements",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive ensures that Member States effectively and consistently discharge their obligations as flag States. Before allowing a ship to fly its flag, the flag State must take measures it considers appropriate to ensure compliance with international rules (Article 4), and must take action when informed that a ship is detained by a port State (Article 5). Member States must undergo an IMO audit of their administration at least once every seven years (Article 7) and develop and maintain a quality management system for the operational parts of their flag State activities (Article 8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-port-state-control-directive-2009-16",
      "eu-ship-recycling-regulation-1257-2013"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-floods-directive-2007-60-ec",
    "title": "Directive 2007/60/EC of the European Parliament and of the Council on the assessment and management of flood risks",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The EU Floods Directive 2007/60/EC establishes a framework for the assessment and management of flood risks to reduce adverse consequences for human health, the environment, cultural heritage, and economic activity. It requires Member States to undertake a preliminary flood risk assessment (by 22 December 2011) for each river basin district or unit of management, based on available information including past floods and climate change impacts. From these assessments, Member States must identify areas where potential significant flood risks exist. For those areas, flood hazard maps and flood risk maps must be prepared (by 22 December 2013) showing flood extent, water depths, flow velocity, and potential adverse consequences such as number of inhabitants affected, economic activity, and installations that could cause accidental pollution. Flood risk management plans must be established (by 22 December 2015), coordinated at river basin district level, focusing on prevention, protection, and preparedness, including measures like flood forecasts and early warning systems. These plans must not increase flood risks upstream or downstream in other Member States without coordination. Coordination with the Water Framework Directive (2000/60/EC) is required for efficiency, information exchange, and common synergies. Public information and active involvement of interested parties are mandated. All assessments, maps, and plans must be reviewed and updated by 22 December 2018, 2019, and 2021 respectively, and every six years thereafter, taking climate change impacts into account. The Directive entered into force on 26 November 2007, and Member States were to transpose it into national law by 26 November 2009.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-floods-directive-2007-60-ec-flood-risk-management",
    "title": "EU Floods Directive 2007/60/EC - Preliminary Flood Risk Assessment, Flood Hazard Maps and Flood Risk Management Plans",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "Directive 2007/60/EC of the European Parliament and of the Council on the assessment and management of flood risks (the Floods Directive) establishes a framework for Member States to assess and manage flood risks aimed at reducing adverse consequences for human health, the environment, cultural heritage and economic activity. The directive operates on a six-year cycle coordinated with the Water Framework Directive 2000/60/EC and proceeds in three stages. Article 4 requires Preliminary Flood Risk Assessment (PFRA) identifying Areas of Potential Significant Flood Risk (APSFR). Article 6 requires Flood Hazard Maps and Flood Risk Maps showing extent and consequences for low, medium and high probability scenarios. Article 7 requires Flood Risk Management Plans (FRMPs) with measures addressing prevention, protection, preparedness and emergency response. Article 9 requires coordination with WFD River Basin Management Plans. The first cycle ran 2009-2015, the second 2016-2021, the third 2022-2027. Climate change is to be considered in subsequent cycles under Article 14(4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-water-framework-directive-2000-60-ec",
      "germany-water-management-act-wasserhaushaltsgesetz-2009"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-fmd-delegated-regulation-2016-161-safety-features",
    "title": "EU FMD Delegated Regulation 2016/161 - Safety Features and Unique Identifier for Medicinal Products",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Commission Delegated Regulation (EU) 2016/161 of 2 October 2015 supplementing Directive 2001/83/EC, applicable from 9 February 2019 in most EU/EEA Member States (with derogations for Greece and Italy until February 2025), establishes the detailed technical and operational requirements for the safety features on medicinal product packaging within the Falsified Medicines Directive (FMD) framework. The Regulation mandates two safety features on the outer packaging of prescription medicinal products: (1) a unique identifier (UI) - a 2D data matrix code containing the product code, serial number, batch number, expiry date, and optionally a national reimbursement number - and (2) a tamper-evident device (TED) on the packaging. The Regulation establishes the European Medicines Verification System (EMVS) through a network of national medicines verification organisations (NMVOs) connected to the European hub, and defines the obligations of manufacturers, wholesale distributors, pharmacists, dispensers, and parallel importers for uploading, verifying, and decommissioning the unique identifier along the pharmaceutical supply chain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_falsified_medicines_directive",
        "eu_good_distribution_practice_gdp",
        "who_gmp_guidelines"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-falsified-medicines-directive-2011-62-ec",
      "eu-good-distribution-practice-gdp-guidelines-2013",
      "who-gmp-good-manufacturing-practices-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-food-additives-regulation-1333-2008",
    "title": "EU Food Additives Regulation 1333/2008 - Positive List, E-Numbers, Conditions of Use, and EFSA Safety Assessment",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Regulation (EC) No 1333/2008 of the European Parliament and of the Council on food additives establishes a positive list system for food additives permitted in the European Union and the conditions under which they may be used. Article 4 provides that only food additives included in the Union lists in Annex II (additives permitted in foods) and Annex III (additives permitted in food additives and enzymes) may be placed on the market and used. Annex II uses the E-number designation system and specifies each permitted additive, the food categories in which it may be used, and the maximum permitted level (MPL) or quantum satis condition. Article 6 sets out the conditions for inclusion in the Union lists: the additive must not pose a safety concern, there must be a reasonable technological need, and the use must not mislead the consumer. The European Food Safety Authority (EFSA) conducts the safety assessment for new or modified additives under Article 10. Regulation (EC) No 1331/2008 establishes the common authorisation procedure for food additives. Article 20 provides that food additives listed in Annex II must be indicated on the label with the functional class name followed by the specific name or E-number. The use of a food additive at quantum satis means the additive is used at no more than the quantity necessary to achieve the intended technological purpose.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_food_information_consumers_regulation_1169_2011",
        "au_nz_food_standards_code",
        "us_fda_food_additive_regulations_21cfr",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-information-consumers-regulation-1169-2011",
      "eu-organic-farming-regulation-2018-848",
      "eu-novel-foods-regulation-2015-2283"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-food-contact-materials-regulation-1935-2004",
    "title": "Regulation (EC) No 1935/2004 of the European Parliament and of the Council of 27 October 2004 on materials and articles intended to come into contact with food",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation sets general requirements for materials and articles intended to come into contact with food to ensure the functioning of the internal market and a high level of protection of human health (Article 1). Such materials must be manufactured so that, under normal use, they do not transfer constituents to food in quantities that could endanger health, change the food unacceptably, or deteriorate its organoleptic characteristics (Article 3), with special requirements for active and intelligent materials (Article 4), specific measures for listed groups (Article 5), and authorisation of substances assessed by the European Food Safety Authority (Articles 8 to 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-hygiene-regulation-852-2004",
      "eu-novel-food-regulation-2015-2283"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-food-hygiene-regulation-852-2004",
    "title": "Regulation (EC) No 852/2004 of the European Parliament and of the Council of 29 April 2004 on the hygiene of foodstuffs",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation mandates that all food business operators (FBOs) in the EU implement, maintain, and provide evidence of a permanent food safety management system based on the seven principles of Hazard Analysis and Critical Control Point (HACCP), as stipulated in Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-law-178-2002",
      "haccp-food-safety",
      "iso-22000-food-mgt",
      "brc-food-safety-global",
      "ifs-food-standard"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-food-information-consumers-regulation-1169-2011",
    "title": "EU Food Information to Consumers Regulation 1169/2011 - Mandatory Labelling, Allergen Disclosure, and Nutrition Declaration",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Regulation (EU) No 1169/2011 of the European Parliament and of the Council on the provision of food information to consumers (FIC Regulation) establishes mandatory labelling and information requirements for pre-packaged food placed on the EU market. Article 9 sets out the mandatory particulars that must appear on all pre-packaged food including the name of the food, the list of ingredients, allergen information, net quantity, minimum durability date, storage conditions, contact details of the responsible business operator, country of origin for specified foods, and the nutritional declaration. Annex II lists 14 allergens that must be highlighted in the ingredients list and identified in all forms of presentation. Article 30 requires a mandatory nutrition declaration (energy, fat, saturates, carbohydrates, sugars, protein, salt) per 100g or 100ml for most pre-packaged foods. Article 13 sets minimum font size requirements (1.2mm x-height) for mandatory particulars. The FIC Regulation also governs distance selling information requirements, voluntary nutrition information, and protected designation of origin claims. Non-pre-packaged food and food supplied by caterers is subject to allergen information requirements under Article 44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "uk_food_information_regulations_2014",
        "eu_food_safety_regulation_178_2002",
        "us_fdas_nutrition_labeling_education_act_1990",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-services-directive-2006-123",
      "eu-gmo-deliberate-release-directive-2001-18"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-food-information-consumers-regulation-1169-2011-labelling-allergens",
    "title": "EU Food Information to Consumers Regulation 1169/2011 - Mandatory Labelling and Allergen Disclosure Requirements",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2014-12-13",
    "bluf": "Regulation (EU) 1169/2011 requires mandatory food labelling disclosures including 14 allergens, nutrition information per 100g, country of origin, date marking, and net quantity, with equivalent obligations for pre-packed and non-pre-packed foods sold in the EU and UK food services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-law-178-2002",
      "eu-market-surveillance-regulation-2019-1020-auto"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-food-information-regulation-1169-2011-fir-labelling-allergens",
    "title": "EU Food Information Regulation 1169/2011 - Mandatory Labelling, Allergen Declaration & Nutrition",
    "domain": "Food & Hospitality",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Regulation 1169/2011 mandates mandatory food information for packaged and non-prepacked food sold in EU - including allergen declarations for 14 major allergens, net quantity, best before/use-by dates, country of origin, nutrition declaration, and legibility requirements (minimum 1.2mm font).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-food-information-regulation-1169-2011-labelling",
    "title": "Regulation (EU) No 1169/2011 of the European Parliament and of the Council of 25 October 2011 on the provision of food information to consumers",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation mandates that all prepacked and non-prepacked foods sold to consumers in the EU must provide mandatory food information, including clear nutrition labelling, allergen highlighting, and country of origin for certain products. It applies to food business operators placing food on the market in the EU, with key requirements under Articles 9, 10, 21, 26, and 29.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-labelling-regulation-1169-2011",
      "eu-food-hygiene-regulation-852-2004",
      "eu-allergen-regulation-2021-382",
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-standard-issue-9"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-food-labelling-regulation-1169-2011",
    "title": "Regulation (EU) No 1169/2011 of the European Parliament and of the Council of 25 October 2011 on the provision of food information to consumers",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation harmonises food labelling across the EU, requiring food business operators to provide clear, legible, and accurate information to consumers, with a primary focus on mandatory nutrition declarations, allergen highlighting, and country of origin for specific products as outlined in Article 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-law-178-2002",
      "codex-alimentarius-gen",
      "haccp-food-safety",
      "iso-22000-food-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-food-law-178-2002",
    "title": "EU General Food Law (178/2002)",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Regulation (EC) No 178/2002 establishes the foundational principles and requirements of general food law, prioritizing a high level of protection for human health. Compliance hinges on strict adherence to the food safety requirements outlined in Article 14, which explicitly prohibits placing unsafe food on the market; this node's configuration requires that unsafe_food_quarantine_enforced is active. A cornerstone of this regulation is the traceability mandate from Article 18, requiring a fully active system with both one_step_back_tracking_enabled and one_step_forward_tracking_enabled capabilities, along with a traceability_data_retention_years period of at least five years. In the event of a food safety incident, Article 19 imposes clear responsibilities upon food business operators. This includes executing a documented withdrawal procedure, having a consumer_recall_notification_ready framework, and notifying competent authorities within an incident_notification_sla_hours of 24 hours. The entire framework operates on the principle of risk analysis as detailed in Article 6, necessitating a formal risk assessment with a minimum risk_assessment_frequency_months of 12. Finally, transparency obligations under Article 10 are met through measures such as a public_transparency_portal_active and RASFF_api_integration_active, facilitating effective risk communication. The SANCO/1628/2008 guidance document further clarifies implementation across these critical articles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brc-food-safety-global",
      "codex-alimentarius-gen",
      "fda-fsma-compliance",
      "gfsi-benchmarking",
      "haccp-food-safety",
      "iso-22000-food-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-food-safety-regulation-178-2002",
    "title": "EU General Food Law Regulation 178/2002",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2002-01-28",
    "bluf": "Regulation (EC) 178/2002 establishes the general principles and requirements of EU food law, creates the European Food Safety Authority (EFSA), and sets up the Rapid Alert System for Food and Feed (RASFF), requiring all food business operators to implement traceability one-step-back and one-step-forward and to withdraw or recall unsafe food from the market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-general-product-safety-regulation-2023-988",
        "eu-corporate-sustainability-reporting-directive-2022-2464",
        "eu-union-customs-code-2013-952"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-general-product-safety-regulation-2023-988",
      "eu-corporate-sustainability-reporting-directive-2022-2464",
      "eu-union-customs-code-952-2013"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-forced-labour-regulation-2024",
    "title": "Regulation (EU) 2024/3015 of the European Parliament and of the Council of 24 October 2024 on prohibiting products made with forced labour on the Union market",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation prohibits economic operators from placing or making available products made with forced labour on the EU market or exporting them, as mandated by Article 3. It establishes a framework for authorities to investigate and enforce this ban, requiring companies to withdraw prohibited products and dispose of them.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp",
      "iso-28000-supply-chain",
      "supply-chain-risk-triage",
      "wco-safe-framework"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-forced-labour-regulation-2024-3015",
    "title": "EU Forced Labour Regulation 2024/3015 - Prohibition on Products Made with Forced Labour on the Union Market",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Economic operators must not place or make available on the Union market any product that is made with forced labour, nor export such products, with the prohibition applying from 14 December 2027 to all products regardless of sector, type, or origin (domestic or imported), including where only part of the product was made with forced labour at any stage of production, manufacture, harvest, extraction, or processing, using the ILO Convention No. 29 definition of forced labour, and with Articles 5(3), 7, 8, 9(2), 11, 33, 35 and 37(3) of Regulation (EU) 2024/3015 already applying from 13 December 2024, supported by European Commission guidance for economic operators to be issued within 18 months of entry into force.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csddd-directive-2024-1760"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-foreign-subsidies-regulation-2022-2560",
    "title": "Regulation (EU) 2022/2560 of the European Parliament and of the Council of 14 December 2022 on foreign subsidies distorting the internal market",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires undertakings to notify the European Commission of concentrations (mergers and acquisitions) and participation in public procurement procedures when they have received significant financial contributions from non-EU governments. The key notification thresholds are an EU turnover of the target/joint venture of at least EUR 500 million and aggregate foreign financial contributions over EUR 50 million for concentrations (Article 20), and a contract value of at least EUR 250 million for public procurements (Article 28).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-foreign-subsidies-regulation-2022-2560-competition",
    "title": "Regulation (EU) 2022/2560 of the European Parliament and of the Council of 14 December 2022 on foreign subsidies distorting the internal market in the context of concentrations and public procurement",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Foreign Subsidies Regulation (FSR) requires undertakings receiving foreign financial contributions exceeding €4 million over three years from non-EU governments to notify the European Commission of mergers, acquisitions, or public procurement bids above specified thresholds. It empowers the Commission to investigate, impose remedies, or prohibit transactions where foreign subsidies distort competition in the internal market, under Articles 5 and 26.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "icn-recommended-practices-merger-notification-2023",
      "uk-cma-merger-assessment-guidelines-2021",
      "australia-accc-merger-review-guidelines-2023",
      "india-competition-act-2002-sections-3-4"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-free-flow-non-personal-data-regulation-2018-1807",
    "title": "Regulation (EU) 2018/1807 of the European Parliament and of the Council of 14 November 2018 on a framework for the free flow of non-personal data in the European Union",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation ensures the free flow of data other than personal data within the EU by prohibiting data localisation requirements unless justified on grounds of public security and proportionate (Articles 1 and 4). It preserves the powers of competent authorities to access data for official purposes (Article 5), encourages self-regulatory codes of conduct to facilitate the porting of data between service providers (Article 6), and requires each Member State to designate a single point of contact for cooperation (Article 7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-data-governance-act-2022-868",
      "eu-data-act-2023-2854"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-freezing-confiscation-mutual-recognition-regulation-2018-1805",
    "title": "Regulation (EU) 2018/1805 of the European Parliament and of the Council of 14 November 2018 on the mutual recognition of freezing orders and confiscation orders",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down the rules under which a Member State recognises and executes freezing orders and confiscation orders issued by another Member State in criminal matters (Article 1). For a list of offences punishable by at least three years it removes double-criminality verification (Article 3). Freezing orders are transmitted by a certificate (Articles 4 and 5) and confiscation orders likewise, with the executing authority recognising and executing them (Article 7) subject to limited grounds for non-recognition (Article 8) and strict time limits (Article 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-wire-transfer-regulation-2023-1113",
      "eu-non-cash-payment-fraud-directive-2019-713"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-fueleu-maritime-2023",
    "title": "Regulation (EU) 2023/1805 of the European Parliament and of the Council of 13 September 2023 on the use of renewable and low-carbon fuels in maritime transport, and amending Directive 2009/16/EC (FuelEU Maritime)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation requires shipping companies operating vessels over 5000 gross tonnage within the EU to progressively reduce the yearly average greenhouse gas (GHG) intensity of the energy used on-board, starting with a 2% reduction by 2025 and reaching an 80% reduction by 2050, as mandated by Article 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "iso-14064-ghg-quantify",
      "ghg-protocol-scope3"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-gas-decarbonisation-package-2024",
    "title": "Regulation (EU) 2024/1469 and Directive (EU) 2024/1474 on common rules for the internal markets in renewable and natural gases and in hydrogen",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "This package establishes a comprehensive regulatory framework for the EU's gas and hydrogen markets, creating rules for a dedicated hydrogen infrastructure, phasing out long-term contracts for unabated fossil gas by 2049, and promoting the uptake of renewable gases like biomethane. It mandates unbundling for hydrogen network operators and integrated network planning for gas, hydrogen, and electricity, as outlined in Regulation (EU) 2024/1469, Article 51.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify",
      "nist-sp-800-161r1-csrm-practices"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-gas-directive-2009-73",
    "title": "EU Gas Directive 2009/73/EC - Common Rules for the Internal Market in Natural Gas",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "EU member states must ensure non-discriminatory third-party access to gas transmission and distribution networks, unbundle gas transmission system operators from supply and production activities, designate independent regulatory authorities, and protect consumer rights including supplier switching and vulnerable customer safeguards - with the Gas Decarbonisation Package 2024 progressively extending obligations to hydrogen networks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "gas_regulation",
        "decarbonisation_successor",
        "storage_regulation",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gas-decarbonisation-package-2024",
      "eu-energy-efficiency-directive-2023-article-11-audits"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-gas-hydrogen-market-regulation-2024-1789",
    "title": "EU Gas and Hydrogen Market Regulation 2024/1789 - Internal Market Rules for Renewable and Natural Gas",
    "domain": "Energy & Utilities",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Gas and Hydrogen Market Regulation 2024/1789 (recast of Regulation 715/2009) establishes rules for access to natural gas and hydrogen transmission networks, LNG facilities, and storage facilities; requires non-discriminatory third-party access (TPA) to transmission systems; mandates unbundled transmission system operators (TSOs) to operate independently of gas supply and production interests; sets capacity allocation and congestion management rules; introduces new obligations for hydrogen network operators and requires member states to designate hydrogen network operators by 2033; and establishes ENTSO-G planning rules including the hydrogen network planning role. The accompanying Gas and Hydrogen Markets Directive 2024/1788 applies at the national level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-renewable-energy-directive-2023-2413-red-iii",
      "eu-energy-efficiency-directive-2023-1791"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-gas-regulation-2021-1119-hydrogen-market",
    "title": "Directive (EU) 2023/2413 of the European Parliament and of the Council of 18 October 2023 amending Directive (EU) 2018/2001 as regards the promotion of energy from renewable sources",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "This Directive amends the Renewable Energy Directive (RED II) to align with the 2030 climate target, notably by increasing the overall EU target for renewable energy to at least 40% by 2030. It introduces specific sub-targets for renewable fuels of non-biological origin (RFNBOs), including renewable hydrogen, in the transport and industry sectors, as outlined in Article 1, which amends Articles 25 and 22a of Directive (EU) 2018/2001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-gas-storage-filling-regulation-2022-1032",
    "title": "Regulation (EU) 2022/1032 of the European Parliament and of the Council of 29 June 2022 amending Regulations (EU) 2017/1938 and (EC) No 715/2009 with regard to gas storage",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation mandates EU Member States to ensure their underground gas storage facilities are filled to at least 90% of their capacity by 1 November each year to guarantee security of gas supply, and introduces a mandatory certification process for all storage system operators to mitigate security-of-supply risks (Article 6a of Regulation (EU) 2017/1938).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-22301-biz-continuity"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-gas-storage-regulation-2022-1032",
    "title": "EU Gas Storage Regulation 2022/1032 - 90% Underground Gas Storage Fill Target",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "EU member states with underground gas storage facilities must achieve at least 90% fill levels by November 1 each year under Regulation 2022/1032. Member states must implement certification schemes for storage system operators, establish mandatory storage targets enforceable by national regulators, and share storage data with the European Commission and ACER to ensure EU-wide energy security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "gas_directive",
        "gas_security_regulation",
        "gas_decarbonisation",
        "energy_union_governance",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gas-directive-2009-73",
      "eu-gas-decarbonisation-package-2024",
      "eu-energy-union-governance-regulation-2018-1999"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-gdpr-article-22-automated-decision-making-profiling",
    "title": "EU General Data Protection Regulation (GDPR) 2016/679 Article 22 - Automated Individual Decision-Making Including Profiling: Right Not to Be Subject to Solely Automated Decisions",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations deploying automated decision systems that produce legal or similarly significant effects on individuals must either invoke a valid Article 22(2) exception (contract necessity, legal authorization, or explicit consent) or cease the automated processing. Where exceptions apply, human review mechanisms and the right to contest must be implemented. Automated processing of special category data is prohibited unless Article 9(2)(a) or (g) also applies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-9-special-categories-sensitive-personal-data",
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-gdpr-article-22-automated-processing-profiling",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) - Article 22: Automated individual decision-making, including profiling",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "GDPR Article 22 grants data subjects the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. This right applies to all controllers using AI-driven or algorithmic decision systems in the EU, requiring either human intervention, safeguards, or explicit consent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-automated-decision-workflows",
      "agent-kill-switch",
      "eu-nis2-directive-workflow-critical-operations",
      "agent-budget-cap"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gdpr-article-8-childrens-consent-information-society-services",
    "title": "EU GDPR (Regulation 2016/679) Article 8 - Children's Consent and Parental Authorization for Online Services",
    "domain": "Data Protection & Privacy",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "GDPR Article 8 requires parental or guardian consent for processing personal data of children under 16 (or lower member state threshold) using information society services - applicable to apps, games, social media, and online educational platforms targeting or likely to be accessed by children.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gdpr-binding-corporate-rules",
    "title": "GDPR Binding Corporate Rules (BCR) Framework - Articles 46-47 and EDPB Guidelines on BCRs",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Binding Corporate Rules (BCRs) are legally binding internal rules and policies for data protection within a corporate group, allowing for the transfer of personal data internationally to members in countries without an adequacy decision, as defined under GDPR Article 47. BCRs must be approved by a competent data protection authority and create enforceable rights for data subjects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-gdpr-cloud-data-processing",
    "title": "Regulation (EU) 2016/679 (General Data Protection Regulation) - Article 28: Processor Responsibilities in Cloud Environments",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Under EU GDPR Article 28, data controllers must only engage cloud service providers (processors) that offer sufficient guarantees for data protection, and this relationship must be governed by a legally binding Data Processing Agreement (DPA) that explicitly details the processing activities, obligations, and technical/organizational measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "iso-27017-cloud-security-2015",
      "iso-27018-cloud-privacy-2019",
      "eu-data-act-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-gdpr-cloud-standard-contractual-clauses-2021",
    "title": "Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Establishes binding contractual obligations for data transfers from EU controllers to processors and sub-processors outside the EEA, including cloud providers. Applies to all organizations processing EU personal data under Modules 2 (Controller-to-Processor) and 3 (Processor-to-Sub-Processor), requiring adherence to Article 28 and Chapter V of GDPR.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gdpr-cloud-data-processing",
      "csa-ccm-v4-cloud-controls",
      "enisa-cloud-security-guidelines-2023",
      "eu-data-governance-act-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gdpr-educational-institutions-data",
    "title": "General Data Protection Regulation (GDPR) - Safeguards and Derogations Relating to Processing for Archiving Purposes in the Public Interest, Scientific or Historical Research Purposes or Statistical Purposes",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires educational institutions processing personal data for scientific research, historical research, or statistical purposes to implement appropriate safeguards, including data minimisation and pseudonymisation, and permits limited derogations from data subject rights under Articles 15, 16, 18, 19, 20, and 21 where necessary and proportionate. Compliance is mandated under Article 89 GDPR.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-education-action-plan-2021-2027-deap",
      "eu-european-research-area-policy-agenda-2022",
      "eu-open-science-policy-fair-data-principles-2021",
      "oecd-recommendation-responsible-research-innovation-2021",
      "iso-21001-2018-educational-organizations-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gdpr-health-data-article-9",
    "title": "Regulation (EU) 2016/679 (General Data Protection Regulation) - Article 9: Processing of special categories of personal data",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Under Article 9(1) of the EU GDPR, the processing of special categories of personal data-including health, genetic, and biometric data-is prohibited for all controllers and processors. Processing is only lawful if it meets one of the specific, explicit conditions for derogation outlined in Article 9(2), such as explicit consent or for the purposes of preventive or occupational medicine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-health-data-space-2024",
      "iso-27799-health-info-sec",
      "eu-clinical-trials-regulation-2022",
      "hipaa-security-rule"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-gdpr-online-gaming-data-protection",
    "title": "General Data Protection Regulation (EU) 2016/679 - Article 4 Definitions for Online Gaming Data Protection",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "GDPR Art. 4 defines personal data, processing, profiling and related concepts; any online gaming controller or processor handling player data in the EU must treat such data as personal data and comply with the definitions when designing tracking, profiling and retention mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "alderney-egambling-regulations-2009",
      "belgium-gambling-act-1999-online-amendments",
      "curacao-gaming-control-board-ordinance-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gender-equal-access-goods-services-directive-2004-113",
    "title": "Council Directive 2004/113/EC of 13 December 2004 implementing the principle of equal treatment between men and women in the access to and supply of goods and services",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive implements the principle of equal treatment between men and women in the access to and supply of goods and services available to the public (Articles 1 and 3). It defines direct and indirect discrimination and harassment (Article 2), prohibits discrimination in access to and supply of goods and services (Article 4), addresses the use of actuarial factors in insurance and related financial services (Article 5), permits positive action (Article 6), and provides for the defence of rights (Article 8), a shift in the burden of proof (Article 9), protection against victimisation (Article 10) and effective, proportionate and dissuasive penalties (Article 14).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-insurance-distribution-directive-2016-97",
      "eu-employment-equality-directive-2000-78"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-general-block-exemption-regulation-gber-2023",
    "title": "Commission Regulation (EU) 2023/1315 of 18 July 2023 on the application of Articles 107 and 108 of the Treaty on the Functioning of the European Union to certain categories of horizontal cooperation agreements",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes a block exemption for certain categories of horizontal cooperation agreements between undertakings that meet specific conditions, ensuring they do not violate Article 101(1) of the TFEU due to efficiency gains and consumer benefits. It applies to R&D, production, and standardisation agreements under Articles 4-7, provided market share thresholds and information exchange safeguards are respected.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "icn-recommended-practices-merger-notification-2023",
      "oecd-competition-digital-economy-roundtable-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-general-data-protection-regulation-education-research-exemptions",
    "title": "EU GDPR - Research and Education Exemptions (Articles 85-91)",
    "domain": "Data Protection & Privacy",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "GDPR Articles 85-91 establish member-state derogation authority for journalistic, academic, artistic, and research processing; scientific and historical research processing is permitted under Article 89 subject to appropriate safeguards (pseudonymisation, data minimisation) without requiring individual consent where consent would render research impossible or seriously impair it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-general-data-protection-regulation-research-exemptions-article-89",
    "title": "EU GDPR Article 89 - Research, Scientific, and Statistical Processing Exemptions",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "GDPR Article 89 permits Member States to provide derogations from certain data subject rights (access, rectification, restriction, objection) for scientific research, statistical purposes, and public interest archiving, provided the processing is subject to appropriate safeguards (pseudonymisation, purpose limitation, data minimisation). Research institutions must implement technical and organisational measures to protect research participants.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-6-lawful-basis-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-general-data-protection-research-article-89",
    "title": "GDPR Article 89 - Safeguards and Derogations Relating to Processing for Archiving Purposes in the Public Interest, Scientific or Historical Research Purposes or Statistical Purposes",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-07-03",
    "bluf": "This regulation requires that personal data processed for archiving in the public interest, scientific or historical research, or statistical purposes must be subject to appropriate safeguards ensuring data minimisation and, where possible, pseudonymisation or non-identifiability. Under Article 89(2), Union or Member State law may provide derogations from Articles 15, 16, 18 and 21 for scientific or historical research or statistical purposes; under Article 89(3), derogations from Articles 15, 16, 18, 19, 20 and 21 for archiving in the public interest, in each case only where such rights are likely to render achievement of the specific purposes impossible or seriously impaired and the derogations are necessary. Article 89(4) provides that where processing also serves another purpose, the derogations apply only to processing for the purposes referred to in paragraphs 2 and 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-open-science-policy-fair-data-principles-2021",
      "eu-european-research-area-policy-agenda-2022",
      "oecd-recommendation-responsible-research-innovation-2021",
      "ich-e6-r3-good-clinical-practice-pharma-2023",
      "eu-digital-education-action-plan-2021-2027"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-general-food-law-regulation-178-2002-efsa-novel-food",
    "title": "EU General Food Law Regulation 178/2002/EC - EFSA Risk Assessment",
    "domain": "Food & Hospitality",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Regulation (EC) No 178/2002 establishes the general principles and requirements of EU food law including the precautionary principle, the obligation to withdraw unsafe food from the market, and the European Food Safety Authority (EFSA) as the independent risk assessment body; traceability is mandatory for all food and feed at all stages of production.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-general-product-safety-regulation-2023-988",
    "title": "EU General Product Safety Regulation 2023/988 (GPSR) - Consumer Product Safety",
    "domain": "Operations & CX",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2023/988 (GPSR) replaces the General Product Safety Directive 2001/95/EC and extends EU consumer product safety rules to online marketplace operators and direct-to-consumer sales from outside the EU. All consumer products placed on the EU market must be safe; manufacturers must conduct risk assessments, maintain technical documentation, issue safety declarations, and register high-risk products in the Safety Gate portal. Online marketplaces must implement safety checks and cooperate with market surveillance authorities. Applies from 13 December 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-regulation-2024",
      "eu-consumer-credit-directive-2023-2225",
      "eu-employment-equality-directive-2000-78"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-general-product-safety-regulation-2023-988-gpsr-consumer-products",
    "title": "EU General Product Safety Regulation 2023/988 (GPSR) - Consumer Product Safety Requirements",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2024-12-13",
    "bluf": "Regulation (EU) 2023/988 (GPSR) replaces the General Product Safety Directive (GPSD) from 13 December 2024, establishing updated safety requirements for all consumer products placed on the EU market. GPSR introduces new obligations for online marketplaces, requires economic operators (manufacturers, importers, distributors) to implement product safety recalls electronically, and aligns with the General Product Safety Recall Portal. Economic operators must notify EU authorities within 3 business days of discovering a serious risk product. Digital products and products with digital elements are now explicitly covered.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-market-surveillance-regulation-2019-1020-auto"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-general-product-safety-regulation-2023-988-market-surveillance",
    "title": "EU General Product Safety Regulation (GPSR) 2023/988 - Consumer Product Safety, Traceability, and Online Marketplace Obligations",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The GPSR (Regulation EU 2023/988), which replaced the General Product Safety Directive 2001/95/EC from December 2024, extends product safety obligations to online marketplaces, requires unique product identifiers and traceability, mandates business-to-consumer accident and injury reporting, and grants market surveillance authorities enhanced corrective powers. Products placed on the EU market must be safe as a general principle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-general-product-safety-regulation-2023-gpsr",
    "title": "EU General Product Safety Regulation (GPSR) - Regulation 2023/988",
    "domain": "Operations & CX",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Regulation 2023/988 (GPSR), applicable from 13 December 2024, establishes a general safety requirement for all consumer products placed on the EU market, mandates product safety notices via the Safety Gate portal within 3 business days of serious risk identification, requires online marketplace operators to implement product safety due diligence, and supersedes Directive 2001/95/EC - imposing traceability obligations, economic operator duties, and market surveillance cooperation on manufacturers, importers, and distributors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011-83-cx"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-general-product-safety-regulation-cx-2023",
    "title": "Regulation (EU) 2023/988 of the European Parliament and of the Council of 10 May 2023 on general product safety, amending Regulation (EU) No 1025/2012 of the European Parliament and of the Council and Directive (EU) 2020/1828 of the European Parliament and the Council, and repealing Directive 2001/95/EC of the European Parliament and of the Council and Council Directive 87/357/EEC (Text with EEA relevance)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes a horizontal framework for the safety of all consumer products in the EU, requiring economic operators to ensure that no unsafe products are placed or made available on the market (Article 4). It applies to all consumer products not covered by specific harmonisation legislation and mandates risk assessment, traceability, incident reporting, recalls, and cooperation with market surveillance authorities via the Safety Gate (RAPEX) system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-omnibus-directive-2019-2161",
      "eu-p2b-regulation-2019-1150",
      "eu-consumer-rights-directive-2011",
      "eu-geo-blocking-regulation-2018",
      "eu-unfair-commercial-practices-directive"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-general-safety-regulation-2019-2144",
    "title": "Regulation (EU) 2019/2144 of the European Parliament and of the Council of 27 November 2019 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users, amending Regulation (EU) 2018/858 and repealing Regulations (EC) No 78/2009, (EC) No 79/2009 and (EC) No 661/2009",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation mandates a suite of advanced vehicle safety features for all new motor vehicles type-approved in the European Union to reduce accidents and protect vehicle occupants and vulnerable road users. As detailed in Article 6, required systems include Intelligent Speed Assistance (ISA), Advanced Emergency Braking (AEB), Event Data Recorders (EDR), and Driver Drowsiness and Attention Warning systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-general-safety-regulation-2019-2144-automated-vehicles",
    "title": "EU General Safety Regulation 2019/2144 - Advanced Driver Assistance and Vehicle Type Approval",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Regulation 2019/2144 on General Safety Requirements for Motor Vehicles (GSR, applicable from July 2022 for new type approvals and July 2024 for all new vehicles) mandates fitment of advanced driver assistance systems (ADAS) on new passenger cars, vans, trucks, and buses type-approved in the EU. Mandatory systems include: intelligent speed assistance (ISA), lane keeping assist, autonomous emergency braking (AEB), driver drowsiness monitoring, reversing detection, and data recorder (event data recorder - EDR). The Regulation also establishes requirements for automated vehicle systems tested in the EU up to SAE Level 4 (L4), requiring specific technical requirements for automated lane keeping systems (ALKS) approved under UN Regulation 157.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unece-r155-automotive-cybersecurity-2021",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-general-safety-regulation-2019-2144-vehicle-type-approval",
    "title": "EU General Safety Regulation 2019/2144 - Vehicle Type Approval Safety",
    "domain": "Automotive & Mobility",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Regulation (EU) 2019/2144 mandates advanced vehicle safety systems as type-approval requirements from 2022 (new types) and 2024 (all new vehicles), including Intelligent Speed Assistance (ISA), Emergency Lane Keeping (ELKS), Autonomous Emergency Braking (AEB), and Event Data Recorder (EDR) for all new M1/N1 category vehicles sold in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-general-safety-regulation-2019-2144-vehicles",
    "title": "Regulation (EU) 2019/2144 of the European Parliament and of the Council of 27 November 2019 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Mandates the installation of advanced driver assistance systems (ADAS) including Automated Emergency Braking (AEB), Intelligent Speed Assistance (ISA), Driver Drowsiness and Attention Warning (DDAW), and a mandatory data recorder (Event Data Recorder) in all new type-approved vehicles in the EU from July 2022 (Category M1/N1) and July 2024 (all new vehicles). Applies to manufacturers and type-approval authorities under Article 5 and Annexes I-VII.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "un-regulation-r157-automated-lane-keeping-alks",
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-geneva-act-geographical-indications-regulation-2019-1753",
    "title": "Regulation (EU) 2019/1753 of the European Parliament and of the Council of 23 October 2019 on the action of the Union following its accession to the Geneva Act of the Lisbon Agreement on Appellations of Origin and Geographical Indications",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down the rules on the action of the Union following its accession to the Geneva Act of the Lisbon Agreement on Appellations of Origin and Geographical Indications (Article 1). It governs the international registration of geographical indications originating in the Union through the Geneva Act (Article 2), the cancellation of such registrations (Article 3), the publication, assessment and opposition procedures for third-country geographical indications registered under the Geneva Act (Articles 4, 5 and 6), the decision on protection in the Union (Article 7), the use of geographical indications (Article 8), and the relationship with trade marks (Article 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-geographical-indications-regulation-2024-1143",
      "eu-trademark-regulation-2017-1001"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-geo-blocking-regulation-2018",
    "title": "Regulation (EU) 2018/302 of the European Parliament and of the Council of 28 February 2018 on addressing unjustified geo-blocking and other forms of discrimination based on customers' nationality, place of residence or place of establishment within the internal market and amending Regulations (EC) No 2006/2004 and (EU) 2017/2394 and Directive 2009/22/EC",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This regulation prohibits traders from blocking or limiting a customer's access to their online interfaces (websites, apps) and from automatically redirecting them to a different version of the interface based on their nationality, place of residence, or establishment, without the customer's explicit consent, as mandated by Article 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeepers",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-geo-blocking-regulation-2018-302",
    "title": "Regulation (EU) 2018/302 of the European Parliament and of the Council of 28 February 2018 on addressing unjustified geo-blocking and other forms of discrimination based on customers' nationality, place of residence or place of establishment within the internal market and amending Regulations (EC) No 2006/2004 and (EU) 2017/2394 and Directive 2009/22/EC",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation prohibits traders in the EU from discriminating against customers based on their nationality, place of residence, or place of establishment. As per Article 3, traders cannot block or limit a customer's access to their online interfaces or automatically redirect them to a different version of the interface for reasons related to their location without explicit consent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "gdpr-art-21-marketing-optout",
      "eprivacy-cookie-directive"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-geo-blocking-regulation-2018-302-competition",
    "title": "Regulation (EU) 2018/302 of the European Parliament and of the Council of 28 February 2018 on addressing unjustified geo-blocking and other forms of discrimination based on customers’ nationality, place of residence or place of establishment within the internal market",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Prohibits unjustified geo-blocking and other forms of discrimination based on customers’ nationality, place of residence, or place of establishment when selling goods or providing services within the EU. Applies to businesses offering cross-border e-commerce and online access to services under Articles 1-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "uk-cma-merger-assessment-guidelines-2021",
      "india-competition-act-2002-sections-3-4",
      "canada-competition-act-2024-amendment-abuse-dominance",
      "oecd-competition-digital-economy-roundtable-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-geo-blocking-regulation-2018-302-services",
    "title": "Regulation (EU) 2018/302 of the European Parliament and of the Council of 28 February 2018 on addressing unjustified geo-blocking and other forms of discrimination based on customers' nationality, place of residence or place of establishment within the internal market and amending Regulations (EC) No 2006/2004 and (EU) 2017/2394 and Directive 2009/22/EC",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Prohibits unjustified geographic discrimination against consumers in the EU based on nationality, residence, or establishment when accessing or purchasing goods and electronically supplied services. Applies to all traders offering cross-border e-commerce services in the Single Market under Article 1 and Article 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "eu-unfair-commercial-practices-directive",
      "eu-omnibus-directive-2019-2161"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-geo-blocking-regulation-review-2023",
    "title": "Regulation (EU) 2018/302 of the European Parliament and of the Council of 28 February 2018 on addressing unjustified geo-blocking and other forms of discrimination based on customers’ nationality, place of residence or place of establishment within the internal market, and on amending Regulations (EC) No 2006/2004 and (EU) 2017/2394 and Directive 2009/22/EC - 2023 Review: Audiovisual Services Exclusion Assessment, Electronically Supplied Services Passive Sale Rules, Price Transparency, Prohibited Country Discrimination and Recommendations for Copyright Licensing Reforms",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The EU Geo-Blocking Regulation 2018/302 prohibits unjustified discrimination against customers based on nationality, residence, or establishment when accessing or purchasing goods and services, including electronically supplied services, within the EU. It mandates equal access and price transparency under Article 3 and Article 6, but explicitly excludes audiovisual services from its scope under Article 3(4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "berne-convention-1886-2024-literary-artistic-works",
      "eu-sports-data-rights-framework-media-2024",
      "dmca-safe-harbor",
      "iptc-photo-metadata"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-geographical-indications-regulation-2024-1143",
    "title": "Regulation (EU) 2024/1143 on Geographical Indications for Food, Wine and Spirits: Single Application Gateway, Enhanced Online Enforcement, Third-Country GI Recognition, Digital Product Passport and Strengthened Producer Group Rights",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a unified EU framework for the protection and enforcement of Protected Designations of Origin (PDO), Protected Geographical Indications (PGI), and Traditional Specialities Guaranteed (TSG) for food, wine, and spirit products. It mandates a Single Application Gateway (Article 12), introduces a Digital Product Passport for GI products (Article 23), strengthens rights of producer groups (Article 31), enhances online enforcement against misuse (Article 45), and formalizes recognition procedures for third-country GIs (Article 52). Applies to all producers, importers, and distributors placing GI-labeled products on the EU market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-law-178-2002",
      "eu-food-hygiene-regulation-852-2004",
      "eu-food-information-regulation-1169-2011-labelling",
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gigabit-infrastructure-act-2024",
    "title": "EU Gigabit Infrastructure Act 2024",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Gigabit Infrastructure Act 2024 requires Member States to facilitate the rollout of symmetrical gigabit-capable networks, as outlined in Article 3, and to ensure the coordination of physical infrastructure, as stated in Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-broadband-cost-reduction-directive-2014-61"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-global-minimum-tax-directive-2022-2523",
    "title": "Council Directive (EU) 2022/2523 of 14 December 2022 on ensuring a global minimum level of taxation for multinational enterprise groups and large-scale domestic groups in the Union",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-12-31",
    "bluf": "This directive implements the OECD's Pillar Two rules, requiring multinational enterprise (MNE) and large-scale domestic groups with annual consolidated revenues of EUR 750 million or more to pay a minimum effective tax rate of 15% on their profits in each jurisdiction of operation (Article 2). It establishes the Income Inclusion Rule (IIR) and Undertaxed Profit Rule (UTPR) to collect a top-up tax when the effective tax rate in a jurisdiction falls below this minimum (Article 5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-global-minimum-tax-directive-2022-2523-pillar-two",
    "title": "Council Directive (EU) 2022/2523 of 14 December 2022 on ensuring a global minimum level of taxation for multinational enterprise groups and large-scale domestic groups in the Union",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This directive requires EU Member States to implement the OECD's Pillar Two rules, ensuring that multinational enterprise (MNE) and large-scale domestic groups with annual consolidated revenues of €750 million or more are subject to a minimum 15% effective tax rate (ETR) on their profits in each jurisdiction. As per Article 1, this is achieved through the application of an Income Inclusion Rule (IIR) and an Undertaxed Profit Rule (UTPR).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015",
      "un-model-double-taxation-convention-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-gm-food-and-feed-regulation-1829-2003",
    "title": "Regulation (EC) No 1829/2003 on genetically modified food and feed - authorisation and labelling",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Regulation (EC) No 1829/2003 establishes a harmonised Community procedure for the authorisation, supervision, and labelling of genetically modified (GM) food and feed. The regulation applies to GMOs for food use; food containing or consisting of GMOs; food produced from or containing ingredients produced from GMOs; and feed containing, consisting of, or produced from GMOs. No person may place such products on the market unless covered by an authorisation granted under the regulation. Authorisation requires a scientific safety assessment by the European Food Safety Authority (EFSA), which must verify that the food or feed does not have adverse effects on human health, animal health, or the environment; does not mislead the consumer; and does not differ from its conventional counterpart to an extent that normal consumption would be nutritionally disadvantageous. Applications must be submitted to a national competent authority and include a dossier with the applicant's name, product specification, transformation event(s), method of production, safety studies, detection and sampling methods, control samples, and, where applicable, a post-market monitoring plan and an environmental risk assessment conforming to Directive 2001/18/EC. EFSA has six months to issue an opinion. The Commission then has three months to submit a draft decision to the Regulatory Committee. Authorisation is valid for 10 years throughout the Community and is renewable. Labelling requirements apply to foods delivered to final consumers or mass caterers that contain, consist of, or are produced from GMOs, with a 0.9% threshold for adventitious or technically unavoidable presence. The regulation also covers the status of existing products lawfully on the market before its application date, requiring notification and re-application within specified periods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-gmo-deliberate-release-directive-2001-18",
    "title": "EU GMO Deliberate Release Directive 2001/18/EC - Environmental Risk Assessment and Market Authorisation",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Directive 2001/18/EC of the European Parliament and of the Council on the deliberate release into the environment of genetically modified organisms (GMOs) establishes the regulatory framework for the controlled and uncontrolled environmental release of GMOs in the EU. Part B covers deliberate release for research and development purposes, requiring prior written consent from the competent authority after a case-by-case environmental risk assessment (ERA). Part C covers market authorisation for GMOs as or in products, implemented through the centralised EFSA assessment procedure and Commission decision. Article 4 establishes the general obligations including a precautionary approach and step-by-step assessment. Annex II prescribes the mandatory ERA methodology. The Directive requires post-market monitoring, public consultation, and mandatory labelling. Authorisations are granted for a maximum of 10 years and are renewable. The Directive does not cover contained use of GMOs, which is governed by Directive 2009/41/EC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_gmo_food_feed_regulation_1829_2003",
        "cartagena_protocol_biosafety",
        "eu_contained_use_directive_2009_41",
        "eu_novel_foods_regulation_2015_2283",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecn-plus-directive-2019-nca-powers",
      "eu-services-directive-2006-123"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-gmo-directive-2001-18-article-13-notification-for-placing-on-market",
    "title": "Directive 2001/18/EC on the deliberate release into the environment of genetically modified organisms - Article 13: Notification procedure",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must submit a detailed notification to the competent authority of the first Member State where a genetically modified organism (GMO) product is to be placed on the market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gmo-directive-2001-18-article-15-consent-for-placing-on-market",
    "title": "Directive 2001/18/EC of the European Parliament and of the Council on the deliberate release into the environment of genetically modified organisms - Article 15",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article outlines the standard procedure for competent authorities and the Commission to review, object to, or grant consent for placing Genetically Modified Organisms (GMOs) on the market, including specific timeframes and conditions for consent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-gmo-directive-2001-18-article-2-definitions",
    "title": "Directive 2001/18/EC on the deliberate release into the environment of genetically modified organisms - Article 2 Definitions",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires organizations to classify their biological entities, genetic modification techniques, and market activities according to the specific legal definitions provided for 'GMO', 'deliberate release', and 'placing on the market' to determine the applicability of the Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-gmo-directive-2001-18-article-20-monitoring-plan",
    "title": "Directive 2001/18/EC of the European Parliament and of the Council on the deliberate release into the environment of genetically modified organisms - Article 20: Monitoring and handling of new information",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Notifiers must ensure post-market monitoring and reporting for GMOs are conducted according to the conditions specified in the consent, submitting reports to the Commission and Member State competent authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gmo-directive-2001-18-article-23-safeguard-clause",
    "title": "Directive 2001/18/EC on the deliberate release into the environment of genetically modified organisms - Article 23: Safeguard clause",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article outlines the safeguard clause allowing a Member State to provisionally restrict or prohibit a consented GMO product if new information indicates a risk to human health or the environment, and details the required notification and review process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-gmo-directive-2001-18-article-26-labelling",
    "title": "Directive 2001/18/EC on the deliberate release into the environment of genetically modified organisms - Article 26: Labelling of GMOs referred to in Article 2(4), second subparagraph",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must ensure that GMOs intended for specific operations are clearly labelled with the words 'This product contains genetically modified organisms' on a label or in an accompanying document, in line with Annex IV.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gmo-directive-2001-18-article-4-general-obligations",
    "title": "Directive 2001/18/EC on the deliberate release into the environment of genetically modified organisms - Article 4: General obligations",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must conduct a comprehensive environmental risk assessment before notifying authorities for the deliberate release or marketing of GMOs, with specific requirements for phasing out certain antibiotic resistance markers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-gmo-directive-2001-18-article-6-experimental-releases",
    "title": "Directive 2001/18/EC of the European Parliament and of the Council on the deliberate release into the environment of genetically modified organisms - Article 6",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the procedural requirements for Member States and the Commission regarding the notification, summary forwarding, observation period, and final decision reporting for the experimental release of GMOs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gmo-regulation-1829-2003",
    "title": "Regulation (EC) No 1829/2003 of the European Parliament and of the Council of 22 September 2003 on genetically modified food and feed",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a centralized authorization procedure for placing genetically modified food and feed on the EU market, requiring pre-market risk assessment by EFSA, traceability, and mandatory labelling of all GMO-derived products. It applies to all operators placing GM food or feed on the EU market under Articles 4, 13, and 44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "iso-14001-ems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gmo-regulation-1829-2003-genetically-modified-food-feed",
    "title": "EU GMO Regulation 1829/2003 - Authorisation, Labelling & Traceability of GM Food and Feed",
    "domain": "Biotech & Genomics",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Regulation 1829/2003 establishes a centralised EU authorisation procedure for genetically modified food and feed, mandatory labelling above 0.9% GMO threshold, and a 10-year renewable authorisation with ongoing post-market monitoring - essential for agricultural biotech, food manufacturers, and feed producers operating in EU markets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gmp-annex-1-sterile-manufacture-2022",
    "title": "EU GMP Annex 1 - Manufacture of Sterile Medicinal Products (2022)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires manufacturers of sterile medicinal products to implement a contamination control strategy, as outlined in Article 17 of the EU GMP Guidelines, and to maintain a cleanroom environment that meets the standards specified in Article 32.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gmp-annex-3-radiopharmaceuticals",
    "title": "EU GMP Annex 3: Manufacture of Radiopharmaceuticals",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU GMP Annex 3 covers the manufacture of radiopharmaceuticals for human use, including positron emission tomography (PET) products, generator-derived products such as Tc-99m, and therapeutic radiopharmaceuticals. The Annex addresses the short half-life of many products (sometimes minutes), the need for parametric or near-real-time release, radiation safety integration with Euratom Basic Safety Standards, hot cell containment, validated aseptic processing under high dose rates, and the special role of the Qualified Person where final test results may post-date batch administration. It applies to commercial manufacturers, hospital radiopharmacies operating under MIA, and IMP manufacturers under Annex 13. Compliance is verified by national competent authority inspections coordinated with the national radiation protection authority; non-compliance triggers MIA conditions, recall where clinically possible, and EudraGMDP reporting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_dir_2001_83",
        "euratom_bss",
        "ph_eur",
        "ich_q9",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-good-distribution-practice-gdp-guidelines-2013",
    "title": "EU Good Distribution Practice (GDP) Guidelines 2013 - European Commission Guideline 2013/C 343/01",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The European Commission Guidelines on Good Distribution Practice of Medicinal Products for Human Use (2013/C 343/01), published in the Official Journal of the EU on 23 November 2013, set binding quality standards for the wholesale distribution of authorised medicinal products within the European Economic Area. The GDP Guidelines implement Article 84 of Directive 2001/83/EC and require wholesale distributors to hold a Wholesale Distribution Authorisation (WDA), operate a quality system based on quality risk management principles, and maintain the storage and transport conditions required by the marketing authorisation. The 2013 Guidelines replaced the 1994 GDP guidelines and added new chapters on transportation (Chapter 9) and brokers (Chapter 10), reflecting the requirements of Directive 2011/62/EU (Falsified Medicines Directive) to combat counterfeit and falsified medicinal products in the supply chain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_falsified_medicines_directive",
        "who_gmp_guidelines",
        "eu_pharmacovigilance_regulation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-falsified-medicines-directive-2011-62-ec",
      "eu-pharmacovigilance-regulation-1235-2010",
      "who-gmp-good-manufacturing-practices-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-good-manufacturing-practice-gdp-2013-c-343-4-medicinal-products",
    "title": "EU GDP Good Distribution Practice 2013/C 343/01 - Medicinal Products Wholesale Distribution",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "EU GDP Guidelines 2013/C 343/01 establish Good Distribution Practice standards for wholesale distribution of medicinal products - covering temperature control, supply chain integrity, falsified medicine detection, pharmacovigilance obligations, and qualified person for distribution requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gpai-code-of-practice-2025",
    "title": "EU General-Purpose AI Code of Practice 2025 - Transparency, Copyright, and Safety and Security Chapters for GPAI Providers, In Force 2 August 2025",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Providers of general-purpose AI (GPAI) models placed on the EU market may use the voluntary EU GPAI Code of Practice (published 10 July 2025) to comply with the EU AI Act obligations applicable from 2 August 2025 with Commission enforcement powers from 2 August 2026, with all GPAI model providers subject to the Transparency and Copyright chapters, and providers of GPAI models with systemic risk (currently a small group of 5-15 companies worldwide whose models cross the 10^25 FLOPs threshold) additionally subject to the Safety and Security chapter requiring a state-of-the-art Safety and Security Framework, continuous systemic-risk assessment and mitigation including external evaluations, red teaming, stress-testing, incident reporting, and notification to the European Commission's AI Office within two weeks of meeting the systemic risk threshold.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-gpai-code-of-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-green-bond-standard-2023",
    "title": "Regulation (EU) 2023/2631 on European green bonds and optional disclosures for bonds marketed as environmentally sustainable and for sustainability-linked bonds",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-12-21",
    "bluf": "This regulation establishes a voluntary 'European green bond' (EuGB) designation for issuers, requiring that bond proceeds be fully allocated to economic activities aligned with the EU Taxonomy for Sustainable Activities (Article 4). It mandates specific transparency, reporting, and external review requirements for any issuer choosing to use the EuGB label.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-sustainable",
      "csrd-eu-sustainability",
      "eu-sfdr-reporting",
      "icma-green-bond"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-green-public-procurement-gpp-voluntary-criteria",
    "title": "EU Green Public Procurement (GPP) - European Commission Voluntary Criteria + Transition to Mandatory Sectoral Requirements",
    "domain": "Public Sector & Government Procurement",
    "version": "1.1.0",
    "last_updated": "2026-07-10",
    "bluf": "Green Public Procurement (GPP) is the European Commission's framework, managed by DG Environment, defined as a process whereby public authorities seek to procure goods, services and works with a reduced environmental impact throughout their life cycle when compared to goods, services and works with the same primary function that would otherwise be procured. The framework was operationalised by Commission Communication COM(2008) 400 ('Public procurement for a better environment') and is mainstreamed in EU procurement law through Directive 2014/24/EU (in particular Article 67 most economically advantageous tender, Article 68 life-cycle costing, Article 42 technical specifications referencing eco-labels under Article 43, and Article 18(2) on environmental, social and labour law compliance). DG Environment publishes voluntary GPP criteria sets for product and service groups (current criteria sets cover computers, monitors, tablets and smartphones; data centres, server rooms and cloud services; electricity; food catering services and vending machines; furniture; imaging equipment, consumables and print services; indoor cleaning services; office building design, construction and management; paints, varnishes and road markings; public space maintenance; road design, construction and maintenance; road lighting and traffic signals; road transport; and textile products and services; earlier criteria sets, including copying and graphic paper, sanitary tapware, and toilets and urinals, are published but marked outdated), structured at two levels: Core Criteria for any contracting authority and Comprehensive Criteria for authorities seeking best-in-class environmental performance. Each criteria set provides subject matter language, technical specifications, selection criteria, award criteria and contract performance clauses ready to drop into a tender notice. Following the 2020 Circular Economy Action Plan (COM(2020) 98), the Commission is transitioning from voluntary to minimum mandatory GPP requirements embedded in sectoral legislation: examples include the Clean Vehicles Directive 2019/1161 (mandatory minima for clean and zero-emission vehicles in public fleets), the Ecodesign for Sustainable Products Regulation 2024/1781 (mandatory GPP requirements per delegated act), and the Construction Products Regulation 2024/3110. GPP is voluntary at the framework level but becomes binding for contracting authorities once a sectoral instrument crosses it into mandatory minima.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "procurement_directive_anchor",
        "circular_economy_upgrade_path",
        "mandatory_sectoral_crossover",
        "industry_mapping",
        "enforcement_anchors",
        "label_anchor_article_43"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-clean-vehicles-directive-2019-1161-public-procurement",
      "eu-public-procurement-construction-2014-24",
      "eu-directive-2014-25-utilities-procurement"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-groundwater-directive-2006-118-ec",
    "title": "Directive 2006/118/EC on the protection of groundwater against pollution and deterioration",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "This Directive establishes specific measures under Article 17(1) and (2) of Directive 2000/60/EC to prevent and control groundwater pollution. It includes criteria for assessing good groundwater chemical status using Annex I quality standards (nitrates 50 mg/l; active substances in pesticides 0.1 micrograms per litre individually and 0.5 micrograms per litre total) and threshold values set by Member States under Article 3 and Annex II for pollutants like arsenic, cadmium, lead, mercury, ammonium, chloride, sulphate, trichloroethylene, tetrachloroethylene, and conductivity. Member States must establish threshold values by 22 December 2008 and publish them in river basin management plans. Article 4 sets out a procedure for assessing chemical status: a body is of good status if monitoring shows compliance with Annex V conditions or if standards are not exceeded, or if exceedances are investigated per Annex III and show no significant environmental risk. Article 5 requires identification of significant and sustained upward trends in bodies at risk and definition of starting points for trend reversals (when concentration reaches 75% of standards or threshold values, with exceptions). Article 6 mandates measures to prevent inputs of hazardous substances and limit inputs of non-hazardous pollutants, with exemptions allowed under strict conditions, provided efficient monitoring is in place. The Directive also has transitional arrangements between 16 January 2009 and 22 December 2013, and technical adaptations may be made via regulatory procedure with scrutiny. The Commission must review Annexes I and II by 16 January 2013 and every six years thereafter, and Member States must transpose by 16 January 2009.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-groundwater-directive-2006-118-ec-quality-standards",
    "title": "EU Groundwater Directive 2006/118/EC - Groundwater Quality Standards, Pollution Prevention and Trend Reversal",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "Directive 2006/118/EC of the European Parliament and of the Council on the protection of groundwater against pollution and deterioration (the Groundwater Directive, GWD) is a daughter directive of the Water Framework Directive 2000/60/EC. Article 3 establishes Union-wide quality standards for nitrates (50 mg/l) and active substances in pesticides including their relevant metabolites, degradation and reaction products (0.1 µg/l individual, 0.5 µg/l total). Member States must establish national threshold values for additional pollutants of concern under Annex II Part B. Article 4 sets the criteria for assessment of good chemical status of groundwater bodies. Article 5 requires identification and reversal of significant and sustained upward trends in pollutant concentrations. Article 6 requires measures to prevent or limit inputs of pollutants into groundwater, distinguishing hazardous substances (prevent) from non-hazardous pollutants (limit to prevent pollution). Directive 2014/80/EU amended Annex II Part B (minimum list of pollutants) to add nitrites and total phosphorus/phosphates. Commission Directive 2022/1733 of 9 September 2022 amended Annex II to update the minimum list of pollutants and the methodologies for setting threshold values.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-water-framework-directive-2000-60-ec",
      "eu-drinking-water-directive-2020-2184-quality-standards"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-gsr-2019-2144-article-6-automated-driving-requirements",
    "title": "EU General Safety Regulation 2019/2144 Article 6 - Type-Approval Requirements for Automated and Fully Automated Road Vehicles",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 6 of Regulation (EU) 2019/2144 (General Safety Regulation, GSR) mandates that motor vehicles be equipped with Intelligent Speed Assistance (ISA), Emergency Lane Keeping Systems (ELKS), and other advanced driver assistance technologies, establishing a regulatory pathway for type-approval of automated and fully automated vehicles. Article 6 requires the Commission to adopt delegated acts specifying performance requirements for automated driving systems, particularly addressing UNECE Working Party 29's regulation-setting work. The GSR creates the legal basis for the EU type-approval system to cover SAE Level 3 and higher automated vehicles, complementing UNECE Regulations R155 (cybersecurity) and R156 (software updates).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-gvp-module-vi-adverse-reaction-reporting",
    "title": "Guideline on good pharmacovigilance practices (GVP) Module VI - Management and reporting of suspected adverse reactions to medicinal products (Rev 3)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires Marketing Authorisation Holders (MAHs) in the EU to record all suspected adverse reactions and report them electronically to the EudraVigilance database. As per section VI.C., serious suspected adverse reactions must be reported within 15 days and non-serious reactions within 90 days of receipt, using the specified ICSR format and MedDRA terminology.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-h2-delegated-act-renewable-fuels-industry",
    "title": "Commission Delegated Regulation (EU) 2023/1184 of 13 March 2023 supplementing Directive (EU) 2018/2001 of the European Parliament and of the Council as regards the definition of renewable fuels of non-biological origin, the method for calculating their greenhouse gas emissions, and the rules on additionality, temporal and geographic correlation for renewable hydrogen",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes binding criteria for renewable hydrogen production under the EU Renewable Energy Directive, requiring additionality (new renewable capacity), hourly temporal correlation between production and renewable generation, and geographic correlation within the same bidding zone. It applies to hydrogen producers, fuel suppliers, and energy-intensive industries using RFNBOs, per Article 4 and Annexes I-III.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-renewable-energy-directive-2023-2413",
      "iso-50001-energy",
      "eu-batteries-regulation-2023-1542-iot-storage",
      "iec-61131-3-programmable-logic-controllers",
      "etsi-en-303-645-iot-cybersecurity-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-habitability-directive-renovation-wave",
    "title": "EU Renovation Wave Strategy 2020 - Minimum Energy Performance Standards for Existing Buildings: Worst Performing Buildings Phase-Out, National Renovation Plans and Financing Mechanisms",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Renovation Wave Strategy aims to renovate 35 million buildings in the EU by 2030, at least doubling the annual rate of energy renovations, with a focus on improving energy efficiency, reducing energy poverty, and decarbonising heating and cooling systems. It applies to public and private building owners, EU Member States, and regional/local authorities responsible for implementing building renovation policies and accessing EU funding mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-construction-sector-emissions-buildings-renovation",
      "eu-circular-economy-construction-demolition-waste-2020",
      "iso-50001-2018-energy-management-systems",
      "iso-19650-bim-information-management-construction"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-habitat-directive-construction-biodiversity",
    "title": "Council Directive 92/43/EEC on the Conservation of Natural Habitats and of Wild Fauna and Flora - Article 6: Assessment of Plans and Projects Likely to Affect Natura 2000 Sites",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Construction projects likely to significantly affect Natura 2000 sites must undergo an Appropriate Assessment under Article 6(3) of the EU Habitats Directive. If adverse effects are identified, the project may only proceed under Article 6(4) based on Imperative Reasons of Overriding Public Interest (IROPI), provided compensatory measures are secured.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-circular-economy-construction-demolition-waste-2020",
      "iso-19650-bim-information-management-construction",
      "us-clean-water-act-section-404-construction"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-habitats-directive-92-43-eec",
    "title": "Council Directive 92/43/EEC of 21 May 1992 on the conservation of natural habitats and of wild fauna and flora; establishing the Natura 2000 network",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Council Directive 92/43/EEC, adopted 21 May 1992, establishes a framework for the conservation of natural habitats and wild fauna and flora within the European territory of Member States to which the Treaty applies, aiming to maintain or restore natural habitats and species of Community interest at a favourable conservation status. It defines key terms including conservation, natural habitats, priority natural habitat types (indicated by an asterisk in Annex I), species of Community interest, priority species (indicated by an asterisk in Annex II), conservation status (favourable when natural range is stable or increasing, structure and functions exist for long-term maintenance, and typical species are favourable), site of Community importance, and special area of conservation. The Directive creates the Natura 2000 network, a coherent European ecological network of special areas of conservation, which also includes special protection areas classified under Directive 79/409/EEC. Member States must propose lists of sites based on Annex III criteria within three years of notification; the Commission establishes a draft list of sites of Community importance within six years; Member States then designate these as special areas of conservation within six years. Article 6 requires conservation measures, avoidance of deterioration, appropriate assessment of plans or projects likely to have significant effects, and compensatory measures for imperative reasons of overriding public interest, with stricter rules for priority habitats/species. Articles 12-15 establish strict protection systems for Annex IV species and exploitation rules for Annex V species, with derogations possible under Article 16 (no satisfactory alternative, not detrimental to favourable conservation status). Member States must report every six years on implementation and surveillance (Article 11). Annexes I and II list habitat types and species requiring special area conservation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-habitats-directive-92-43-eec-natura-2000",
    "title": "EU Habitats Directive 92/43/EEC - Natura 2000 SAC Designation and Appropriate Assessment Framework",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Council Directive 92/43/EEC on the conservation of natural habitats and of wild fauna and flora (Habitats Directive) is the cornerstone of EU nature conservation law, together with the Birds Directive (2009/147/EC). It requires Member States to designate Special Areas of Conservation (SACs) as part of the Natura 2000 ecological network. Any plan or project likely to have significant effects on a Natura 2000 site must undergo Appropriate Assessment (AA) under Article 6(3). The AA is only passed if the competent authority can ascertain that the plan or project will not adversely affect the site's integrity. Under Article 6(4), if adverse effects are confirmed, imperative reasons of overriding public interest (IROPI) may justify a derogation with compensatory measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-water-framework-directive-2000-60-ec"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-health-data-space-2024",
    "title": "Regulation on the European Health Data Space (EHDS)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The EHDS Regulation establishes a framework for the primary use (patient care) and secondary use (research, innovation, policy-making) of electronic health data across the EU. It mandates interoperability for Electronic Health Record (EHR) systems and creates a secure infrastructure for data access, requiring data holders to make specific categories of data available for secondary use through Health Data Access Bodies (HDABs) under strict conditions (Chapter IV, Article 33).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-health-data",
      "eu-mdr-2017-745",
      "iso-27799-health-info-sec",
      "hl7-fhir-v4-interop",
      "iec-62304-medical-software"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-health-safety-framework-directive-89-391",
    "title": "EU Health and Safety Framework Directive 89/391 - Employer Obligations, Risk Assessment, and Worker Rights",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Council Directive 89/391/EEC of 12 June 1989 on the introduction of measures to encourage improvements in the safety and health of workers at work (the Framework Directive) is the cornerstone of EU occupational health and safety law. Article 5 imposes a general duty on employers to ensure the safety and health of workers in every aspect related to the work. Article 6 requires employers to implement preventive measures based on nine general principles of prevention, including avoiding risks, evaluating unavoidable risks, combating risks at source, adapting work to the individual, and giving priority to collective protective measures over individual protective measures. Article 9 requires employers to carry out a risk assessment of the hazards to safety and health of workers (including those facing particular risks), keep an updated record of the results, designate one or more workers to carry out protective and preventive activities, and arrange for first aid, fire-fighting, and evacuation of workers. Article 10 requires employers to provide workers with comprehensible and relevant information on the risks to their health and safety and the preventive and protective measures adopted. Article 11 requires consultation of workers or their representatives on all questions relating to health and safety at work. Directive 89/391/EEC applies to all sectors of activity, both public and private, with the exception of certain specific civil protection, armed forces, and police activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nz_health_safety_work_act_2015",
        "uk_health_safety_work_act_1974",
        "eu_working_time_directive_2003_88",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-hswa-2015-health-safety-work",
      "eu-working-time-directive-2003-88",
      "eu-services-directive-2006-123"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-herbal-medicinal-products-directive-2004-24",
    "title": "Directive 2004/24/EC of the European Parliament and of the Council of 31 March 2004 amending, as regards traditional herbal medicinal products, Directive 2001/83/EC on the Community code relating to medicinal products for human use",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Establishes a simplified registration procedure for traditional herbal medicinal products (THMPs) in the EU based on at least 30 years of traditional use, including 15 years within the EU, under Article 16a of Directive 2001/83/EC as inserted by this Directive. Applies to herbal product manufacturers and marketing authorization holders seeking market access without full clinical trial data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gmp-annex-1-sterile-manufacture-2022",
      "ich-q10-pharmaceutical-quality-system-2008",
      "fda-21-cfr-210-211-current-good-manufacturing-practice"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-horizon-europe-regulation-2021-695-research",
    "title": "Regulation (EU) 2021/695 of the European Parliament and of the Council of 28 April 2021 establishing the framework programme for research and innovation, Horizon Europe, and repealing Regulations (EU) No 1290/2013 and (EU) No 1291/2013",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Horizon Europe Regulation 2021/695 establishes the EU’s multiannual funding framework for research and innovation (2021-2027), mandating open science practices, ethical standards, and mission-oriented research under Pillars I-IV. It applies to all entities receiving EU funding, requiring compliance with Article 23.3 on open access, Article 29 on research integrity, and Article 32 on data management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-open-science-policy-fair-data-principles-2021",
      "eu-european-research-area-policy-agenda-2022",
      "eu-researcher-charter-code-of-conduct-2005",
      "oecd-recommendation-responsible-research-innovation-2021",
      "iso-21001-2018-educational-organizations-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-horizon-europe-regulation-2021-695-research-ethics",
    "title": "EU Horizon Europe Regulation 2021/695 - Research Ethics and Open Science",
    "domain": "Education & Research",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Regulation (EU) 2021/695 establishing Horizon Europe (2021-2027) mandates ethics review for all funded research projects, requires Open Access to peer-reviewed publications and research data (FAIR principles), and conditions funding on compliance with EU Charter of Fundamental Rights and applicable data protection law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-general-data-protection-regulation-education-research-exemptions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-horizon-europe-research-grant-rules-2021",
    "title": "Horizon Europe Model Grant Agreement (MGA) - General",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Horizon Europe Model Grant Agreement (MGA) establishes the contractual conditions for EU research and innovation funding, requiring beneficiaries to ensure costs are eligible (Article 6), manage intellectual property (Article 16), provide open access to publications and research data (Article 17), and comply with strict ethics and research integrity principles (Article 14).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-46-transfer-mechanisms"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-horizontal-block-exemption-regulations-2023",
    "title": "Commission Regulations (EU) 2023/1066 on Research & Development Agreements and (EU) 2023/1067 on Specialisation Agreements (Horizontal Block Exemption Regulations)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-07-01",
    "bluf": "These regulations provide a 'safe harbour' under Article 101(3) TFEU, exempting certain horizontal cooperation agreements from EU competition rules, provided the parties' combined market share does not exceed 25% for R&D agreements (Regulation 2023/1066, Art. 4) or 20% for specialisation agreements (Regulation 2023/1067, Art. 4) and the agreement does not contain any hardcore restrictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tfeu-article-102-abuse-of-dominance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-hta-regulation-2021-782",
    "title": "Regulation (EU) 2021/782 of the European Parliament and of the Council of 29 April 2021 on rail passengers’ rights and obligations (recast) (Text with EEA relevance)",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes enforceable rights for rail passengers within the European Union, including rights to information, assistance, compensation, and re-routing in cases of delay or cancellation, as defined in Articles 17, 19, and 20. It applies to all domestic and international rail passenger services operating within the Union, with limited exemptions permitted under Article 2(3) and Article 2(4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-human-medicines-directive-2001-83-ec",
    "title": "Directive 2001/83/EC of the European Parliament and of the Council of 6 November 2001 on the Community code relating to medicinal products for human use (Consolidated)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes the comprehensive EU regulatory framework for medicinal products for human use, mandating that no product can be placed on the market without a valid Marketing Authorisation (Article 6). It defines the requirements for authorisation, data exclusivity (the '8+2+1' rule under Article 10), manufacturing, labelling, pharmacovigilance, and advertising.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-hydrogen-bank-auction-rules-2023",
    "title": "Terms & Conditions for the Innovation Fund Pilot Auction for Renewable Hydrogen Production (H2-Auction-1-2023)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation establishes the rules for the first EU Hydrogen Bank pilot auction, requiring project developers to bid for a fixed premium per kilogram of certified renewable hydrogen produced over a 10-year period. Eligibility, as defined in Section 4 of the Terms & Conditions, mandates projects be located in the European Economic Area (EEA), utilize new electrolyser capacity of at least 5 MWe, and produce hydrogen compliant with the Renewable Energy Directive's criteria for Renewable Fuels of Non-Biological Origin (RFNBOs).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-hydrogen-delegated-acts-2023",
    "title": "Commission Delegated Regulations (EU) 2023/1184 and 2023/1185 supplementing Directive (EU) 2018/2001 on Renewable Hydrogen (RFNBO) Definition, Additionality, and GHG Savings Methodology",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "These Delegated Acts establish the detailed rules for producing renewable hydrogen and other Renewable Fuels of Non-Biological Origin (RFNBOs) within the EU, defining criteria for 'additionality', 'temporal correlation', and 'geographical correlation' to ensure the electricity used is from new renewable sources. The rules, supplementing Article 27(3) of the Renewable Energy Directive (RED II), apply to all producers and consumers seeking to have their hydrogen count towards EU renewable energy targets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-hydrogen-strategy-2020-investment-framework",
    "title": "A hydrogen strategy for a climate-neutral Europe (COM/2020/301 final)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This strategy establishes a phased investment framework for the EU to scale up renewable hydrogen, targeting the installation of at least 6 GW of renewable hydrogen electrolysers by 2024 and 40 GW by 2030. As outlined in Section 2, it creates the European Clean Hydrogen Alliance to channel investments and build a project pipeline to achieve these goals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-idd-insurance-distribution-directive-2016-97",
    "title": "EU Insurance Distribution Directive 2016/97/EU - Insurance Intermediary Registration, Conduct of Business, and IBIPs",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Directive (EU) 2016/97 of the European Parliament and of the Council on insurance distribution (IDD), in force from 1 October 2018, replaces the Insurance Mediation Directive 2002/92/EC. The IDD extends conduct of business requirements to all insurance distributors including direct sellers, insurance undertakings selling directly, and insurance intermediaries. Article 10 requires insurance intermediaries to register with their home Member State national competent authority. Article 17 establishes the general conduct of business principles: distributors must always act honestly, fairly, and professionally in accordance with the best interests of their customers. Articles 20-24 require the provision of standardised pre-sale information to customers including the Insurance Product Information Document (IPID) for non-life products. For insurance-based investment products (IBIPs) under Articles 25-30, the Directive imposes suitability and appropriateness assessment requirements analogous to MiFID II for investment products. Article 20 prohibits inducements that conflict with the customer's best interests. The IDD is supplemented by Commission Delegated Regulations on product oversight and governance (POG), the IPID format, and IBIP conduct of business requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_mifid_ii_directive_2014_65",
        "uk_fca_icobs_sourcebook",
        "eu_solvency_ii_directive_2009_138",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-services-directive-2006-123",
      "eu-late-payment-directive-2011-7"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-immigration-liaison-officers-network-regulation-2019-1240",
    "title": "Regulation (EU) 2019/1240 of the European Parliament and of the Council of 20 June 2019 on the creation of a European network of immigration liaison officers (recast)",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation establishes a European network of immigration liaison officers and lays down rules to enhance coordination and optimise the use of liaison officers deployed to third countries by Member States, the Commission and Union agencies (Article 1). It defines the tasks of immigration liaison officers (Article 3), requires notification of their deployment (Article 4), provides for joint deployment (Article 6), establishes a Steering Board (Article 7) with defined tasks (Article 8), an information exchange platform (Article 9), and rules on the processing of personal data (Article 10) and consular cooperation (Article 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-schengen-borders-code-regulation-2016-399",
      "eu-returns-directive-2008-115"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-import-cultural-goods-regulation-2019-880",
    "title": "Regulation (EU) 2019/880 of the European Parliament and of the Council of 17 April 2019 on the introduction and the import of cultural goods",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation sets the conditions for introducing and importing cultural goods into the EU to safeguard cultural heritage and prevent illicit trade. It prohibits the introduction of Part A cultural goods unlawfully removed from their country of creation or discovery (Article 3), requires an import licence for Part B goods issued by the competent Member State authority (Article 4), and an importer statement for Part C goods (Article 5), with information exchanged through a centralised electronic system (Article 8) and effective, proportionate and dissuasive penalties (Article 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hague-convention-1954-cultural-property-armed-conflict",
      "eu-conflict-minerals-regulation-2017-821"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-in-vitro-diagnostics-regulation-2017-746",
    "title": "EU In Vitro Diagnostics Regulation 2017/746 -- IVD Classification, Performance Evaluation, and Market Authorisation",
    "domain": "Medical & Healthcare",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Regulation (EU) 2017/746 (IVDR) replaces Directive 98/79/EC and establishes a stricter classification and conformity assessment framework for in vitro diagnostic medical devices placed on the EU market. IVDR applied from 26 May 2022 with transitional periods extended by Regulation 2022/112 and Regulation 2024/1860. The four risk classes are: Class A (lowest risk, sterile Class A requires notified body involvement), Class B, Class C, and Class D (highest risk including devices for blood transfusion and organ transplantation). Unlike the IVD Directive, which required notified body involvement only for a small subset of devices, the IVDR requires notified body involvement for all Class B, C, and D devices. Class D devices require batch verification at notified body level under Article 48(7). A Performance Evaluation Report (PER) and Post-Market Performance Follow-Up (PMPF) plan are mandatory for all devices; Class C and D devices must submit annual PMPF updates. Companion diagnostics for medicinal products require mandatory consultation with the European Medicines Agency (EMA) or national competent authorities under Article 48(3). EUDAMED registration is required before placing devices on the market under Article 30. Unique Device Identification (UDI) is mandatory with class-dependent phased implementation from 2022 onwards. Serious incident reporting timelines mirror the MDR: immediately (life-threatening), 2 calendar days (serious public health threat), 10 calendar days (serious deterioration in health), 15 calendar days (trend report) under Article 82.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-medical-devices-regulation-2017-745",
      "us-hipaa-privacy-security-rules-1996",
      "eu-corporate-sustainability-reporting-directive-2022-2464"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-industrial-emissions-directive-2010-75-best-available",
    "title": "Directive 2010/75/EU of the European Parliament and of the Council of 24 November 2010 on industrial emissions (integrated pollution prevention and control)",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Directive requires industrial installations above specified thresholds to obtain environmental permits based on Best Available Techniques (BAT) conclusions, which establish emission limit values and associated monitoring and reporting obligations. It applies to sectors including energy, metals, minerals, chemicals, waste, and intensive livestock farming across EU Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cyber-resilience-act-iot-2024-products",
      "etsi-en-303-645-iot-cybersecurity-2020",
      "eu-data-act-2023-iot-data-sharing-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-industrial-emissions-directive-2010-75-construction",
    "title": "Directive 2010/75/EU of the European Parliament and of the Council of 24 November 2010 on industrial emissions (integrated pollution prevention and control)",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This Directive establishes emission limit values (ELVs) and mandates the use of Best Available Techniques (BAT) for industrial installations, including cement kilns, lime and glass production facilities, under Article 13 and Annex VI. It applies to operators of large-scale industrial plants in the construction materials sector across EU Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-circular-economy-construction-demolition-waste-2020",
      "iso-19650-bim-information-management-construction",
      "iso-9001-2015-quality-management-construction",
      "iso-50001-2018-energy-management-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-industrial-emissions-directive-2010-75-eu",
    "title": "Directive 2010/75/EU on industrial emissions - integrated pollution prevention and control - recast",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Directive 2010/75/EU establishes an integrated approach to pollution prevention and control for industrial activities, requiring that no installation, combustion plant, waste incineration plant, or waste co-incineration plant operates without a permit or, for certain installations covered only by Chapter V, registration. Permits must include emission limit values for polluting substances set on the basis of Best Available Techniques (BAT) and BAT conclusions drawn from reference documents (BAT reference documents), which are reviewed and updated no later than 8 years after the previous version. Operators must submit applications describing the installation, raw materials, energy use, emission sources, site conditions, and, where applicable, a baseline report on soil and groundwater contamination (Article 12). Permit conditions must be reconsidered regularly and updated, particularly when new or updated BAT conclusions are adopted; Member States may set a longer period than 4 years if justified. In the event of non-compliance with permit conditions, the operator must immediately inform the competent authority, take measures to restore compliance, and the competent authority may require complementary measures; if the breach poses an immediate danger to human health or the environment, operation must be suspended until compliance is restored (Article 8). The Directive sets specific emission limit values for large combustion plants, waste incineration and co-incineration plants, and installations producing titanium dioxide, and allows for temporary derogations from emission levels associated with BAT for testing emerging techniques. It also establishes general binding rules that Member States may use to set requirements for categories of installations, and requires environmental inspections to check and promote compliance with permit conditions. The Directive recasts and replaces seven earlier directives, including those on integrated pollution prevention and control, large combustion plants, waste incineration, and volatile organic compounds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-industrial-strategy-2030-deep-tech-sovereignty",
    "title": "EU Industrial Strategy 2030 Update - Deep Tech Sovereignty, Strategic Dependencies, Industrial Alliances and Single Market Emergency Instrument",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This communication outlines the European Union’s updated industrial strategy for 2030, focusing on deep tech sovereignty, reducing strategic dependencies, strengthening industrial alliances, and establishing a Single Market Emergency Instrument. It applies to EU Member States, industrial operators in critical sectors, and public authorities responsible for industrial policy and crisis preparedness.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-critical-entities-resilience-directive-2022",
      "eu-cyber-resilience-act-iot-2024-products",
      "eu-data-act-2023-iot-data-sharing-obligations",
      "etsi-en-303-645-iot-cybersecurity-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-insolvency-regulation-2015-848",
    "title": "EU Insolvency Regulation (Recast) 2015/848",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2017-06-26",
    "bluf": "Regulation (EU) 2015/848 of the European Parliament and of the Council on insolvency proceedings (Recast), applicable from 26 June 2017, establishes the rules for determining which Member State's courts have jurisdiction to open insolvency proceedings against debtors with their Centre of Main Interests (COMI) in the EU under Article 3, provides for automatic recognition of insolvency proceedings opened in one Member State in all other Member States under Article 19 without requiring any further formality, permits secondary proceedings to be opened in any Member State where the debtor has an establishment under Article 3(2), requires insolvency practitioners to publish notice of opened proceedings in the Insolvency Register interconnected through the European e-Justice Portal under Article 24, enables courts to order a temporary stay of opening or enforcement proceedings in secondary proceedings under Article 38 to protect the estate, establishes priority rules for creditors in main and secondary proceedings, and provides for pre-insolvency restructuring frameworks under Member State law to be recognised as insolvency proceedings within the Regulation's scope where listed in Annex A.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "sg-insolvency-restructuring-dissolution-act-2018",
        "ca-cbca-corporations-act-1985",
        "eu-gdpr-cloud-data-processing"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-insolvency-restructuring-dissolution-act-2018",
      "ca-cbca-corporations-act-1985",
      "eu-gdpr-cloud-data-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-instant-payments-regulation-2024",
    "title": "Regulation (EU) 2024/886 of the European Parliament and of the Council of 13 March 2024 amending Regulations (EU) No 260/2012 and (EU) 2021/1230 and Directives 98/26/EC and (EU) 2015/2366 as regards instant credit transfers in euro",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2025-10-09",
    "bluf": "This regulation mandates that Payment Service Providers (PSPs) in the SEPA area offering standard euro credit transfers must also offer the service of sending and receiving instant credit transfers 24/7/365, at a cost no higher than standard transfers, as stipulated in Article 5a. It also introduces a mandatory service for verifying the payee's name against their IBAN before payment authorization to prevent fraud, per Article 5c.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "psd2-sc-authentication",
      "iso-20022-mx-messaging"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-instant-payments-regulation-2024-886",
    "title": "EU Instant Payments Regulation 2024/886 - Mandatory SCT Inst, 10-Second Execution",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2024/886 amends the SEPA Regulation (260/2012) to make instant credit transfers in euros mandatory for all EU PSPs. PSPs must be able to send and receive instant payments within 10 seconds, 24/7/365, and must not charge more for SCT Inst than for standard SCT. Verification of Payee (IBAN-name check) is required before payment execution. Sanctions screening moves from transaction-by-transaction to daily batch against the EU asset freeze list. Phased mandatory application: euro-area PSPs from October 2025, non-euro-area from January 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-psd2-strong-customer-authentication",
      "eu-aml-regulation-2024",
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-brrd-bank-recovery-resolution-directive-2014-59"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-insurance-anti-discrimination-gender-test-achats",
    "title": "Judgment of the Court (Grand Chamber) of 1 March 2011 in Case C-236/09, Association belge des Consommateurs Test-Achats ASBL and Others v Conseil des ministres (Test-Achats Ruling)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This European Court of Justice ruling invalidates the derogation in Article 5(2) of Directive 2004/113/EC, prohibiting insurers from using an individual's gender as a risk factor in calculating premiums and benefits for new insurance and related financial service contracts. The ruling mandates unisex pricing across the EU, effective from 21 December 2012.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-insurance-distribution-directive-2016-97",
    "title": "Directive (EU) 2016/97 of the European Parliament and of the Council of 20 January 2016 on insurance distribution (recast)",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Directive establishes harmonized rules for insurance distribution across the EU, requiring distributors to provide pre-contractual information via the Insurance Product Information Document (IPID), conduct suitability or appropriateness assessments for non-advised sales, manage conflicts of interest, and comply with inducement and training obligations under Articles 23, 24, 25, and 26.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-distance-selling-insurance-directive-2002-92",
      "eu-delegated-regulation-2016-2067-spread-market-risk",
      "eu-delegated-regulation-2016-467-non-life-premium-risk",
      "eiopa-guidelines-pension-stress-testing-2022",
      "australia-apra-lps-110-capital-adequacy-life"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-insurance-distribution-directive-2016-97-idd",
    "title": "Directive (EU) 2016/97 of the European Parliament and of the Council of 20 January 2016 on insurance distribution (recast)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The EU Insurance Distribution Directive (IDD) mandates that all distributors of insurance products, including insurers and intermediaries, must act in the customer's best interests (Article 17), implement robust product oversight and governance (POG) arrangements (Article 25), and provide a standardized Insurance Product Information Document (IPID) for non-life products before a contract is concluded (Article 20).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fca-consumer-duty-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-insurance-recovery-resolution-directive-2021",
    "title": "Proposal for a Directive of the European Parliament and of the Council establishing a framework for the recovery and resolution of insurance and reinsurance undertakings and amending Directives 2002/47/EC, 2004/25/EC, 2007/36/EC, 2014/59/EU and (EU) 2017/1132",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This Directive requires EU insurance and reinsurance undertakings to create and maintain pre-emptive recovery plans to address scenarios of significant financial distress, and establishes a harmonised framework for resolution authorities to manage failures in an orderly manner. The core requirement for undertakings is the development of a comprehensive recovery plan as mandated by Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "iso-27031-dr-readiness",
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-integrated-national-energy-climate-plans-2030",
    "title": "EU Integrated National Energy and Climate Plans (NECPs) 2030 - Sector Coverage, Governance Obligations and EC Assessment Methodology",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "EU Member States are required to establish, submit, and regularly update integrated national energy and climate plans (NECPs) to the European Commission, detailing policies and measures across five dimensions of the Energy Union to meet 2030 targets, as mandated by Article 3 of Regulation (EU) 2018/1999.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14090-climate-adapt",
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-intelligent-transport-systems-directive-2010",
    "title": "Directive 2010/40/EU of the European Parliament and of the Council of 7 July 2010 on the framework for the deployment of Intelligent Transport Systems in the field of road transport and for interfaces with other modes of transport",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU ITS Directive 2010/40/EU mandates Member States to develop and implement National ITS Action Plans to ensure interoperable deployment of intelligent transport systems (ITS) across road transport and multimodal interfaces. It requires coordinated traffic management, real-time travel information services, and data sharing frameworks under Article 4 and Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "iso-26262-functional-safety-road-vehicles-2018",
      "oecd-regulatory-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-intelligent-transport-systems-directive-2010-40",
    "title": "Directive 2010/40/EU of the European Parliament and of the Council of 7 July 2010 on the framework for the deployment of Intelligent Transport Systems in the field of road transport and for interfaces with other modes of transport",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This Directive establishes a framework for the coordinated deployment of Intelligent Transport Systems (ITS) across the EU, mandating interoperability and common specifications in priority areas including multimodal journey planning, traffic management, emergency eCall, and freight tracking. Key obligations are set out in Articles 4, 5, and 6, applying to Member States and relevant service providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "iso-26262-functional-safety-road-vehicles-2018",
      "germany-autonomous-driving-law-2021-stvaendg"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-interchange-fees-regulation-2015-751",
    "title": "EU Interchange Fees Regulation 2015/751 - 0.2%/0.3% Interchange Fee Caps",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2015/751 caps interchange fees for consumer card-based payment transactions: 0.2% of transaction value for debit cards and 0.3% for credit cards. It prohibits unilateral limitations on acquirer geographic licensing and mandates co-badging on payment cards. Commercial card interchange fees are not capped. Three-party schemes processing <0.1% of total EU payment volume are temporarily exempt.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-psd2-strong-customer-authentication",
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-aml-regulation-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-interest-royalties-directive-2003-49",
    "title": "Council Directive 2003/49/EC of 3 June 2003 on a common system of taxation applicable to interest and royalty payments made between associated companies of different Member States",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Directive eliminates withholding taxes on interest and royalty payments between associated companies in different EU Member States, provided the beneficial owner is a qualifying associated company and the arrangement is not abusive under Article 5. It applies to companies resident in EU Member States with a minimum 25% direct or indirect ownership.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-atad2-hybrid-mismatches-2017-952",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-interest-royalties-directive-2003-49-reform",
    "title": "Council Directive 2003/49/EC of 3 June 2003 on a common system of taxation applicable to interest and royalty payments made between associated companies of different Member States",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This directive eliminates withholding taxes on cross-border interest and royalty payments between associated companies within the EU, provided the recipient is the beneficial owner of the income as stipulated in Article 1. It applies to companies linked by a direct minimum holding of 25% for an uninterrupted period of at least two years, and includes anti-abuse provisions to deny benefits in cases of tax evasion, fraud, or abuse.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-model-double-taxation-convention-2021",
      "oecd-beps-action-3-cfc-rules-2015"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-international-coach-bus-services-regulation-1073-2009",
    "title": "Regulation (EC) No 1073/2009 of the European Parliament and of the Council of 21 October 2009 on common rules for access to the international market for coach and bus services",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation governs access to the international market for coach and bus passenger transport (Article 1). International carriage of passengers requires a Community licence (Article 4); regular services require an authorisation issued in agreement with the Member States concerned (Articles 5 to 8), while occasional services are carried out under a journey form (Article 12). It sets the nature, submission, issue, renewal and lapse of authorisations (Articles 6 to 10) and obligations of carriers operating regular services (Article 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-road-transport-operator-access-regulation-1071-2009",
      "eu-drivers-driving-time-regulation-561-2006"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-international-procurement-instrument-regulation-2022-1031",
    "title": "Regulation (EU) 2022/1031 of the European Parliament and of the Council of 23 June 2022 on the access of third-country economic operators, goods and services to the Union public procurement and concession markets and procedures supporting negotiations on access of Union economic operators, goods and services to the public procurement and concession markets of third countries (International Procurement Instrument - IPI)",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation, the International Procurement Instrument, allows the Commission to investigate alleged measures or practices of a third country that restrict access of Union economic operators, goods and services to that country procurement market, and to adopt IPI measures (Articles 1, 5 and 6). IPI measures take the form of a score adjustment of tenders or the exclusion of tenders, and apply to procurement procedures with an estimated value at or above EUR 15 000 000 net of VAT for works and concessions, and at or above EUR 5 000 000 net of VAT for goods and services (Articles 1 and 6). Successful tenderers face sub-contracting obligations limiting goods or services from the targeted country (Article 8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-public-procurement-directive-2014-24-construction",
      "eu-foreign-subsidies-regulation-2022-2560"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-international-road-haulage-regulation-1072-2009",
    "title": "Regulation (EC) No 1072/2009 of the European Parliament and of the Council of 21 October 2009 on common rules for access to the international road haulage market",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation governs access to the international road haulage market and to cabotage. International carriage for hire or reward requires possession of a Community licence (Articles 3 and 4) and, where the driver is a third-country national, a driver attestation (Article 5). It sets the conditions for issue, refusal and withdrawal of the licence (Articles 6 and 7) and the rules applicable to cabotage operations (Article 9), backed by mutual assistance and sanctioning of serious infringements by the Member States of establishment and of operation (Articles 11 to 13).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-road-transport-operator-access-regulation-1071-2009",
      "eu-drivers-driving-time-regulation-561-2006"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-interoperable-europe-act-2024-903",
    "title": "Regulation (EU) 2024/903 - EU Interoperable Europe Act: Mandatory Interoperability Assessments for Cross-Border Public Services, European Interoperability Framework, Interoperable Europe Board, GovTech Sandbox, Open Source Preference, and Reusable Interoperability Solutions",
    "domain": "Cloud & SaaS",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2024/903 (Interoperable Europe Act), entered into force 11 April 2024 and applicable from 12 July 2024, establishes the first EU-wide legally binding framework for public sector digital interoperability; key obligations include: mandatory interoperability assessments before implementing or significantly modifying network and information systems supporting trans-European digital public services (Article 3); application of the European Interoperability Framework (EIF) by EU institutions and bodies and public sector entities managing trans-European services (Article 4); sharing of interoperability solutions as 'Interoperable Europe solutions' in the Interoperable Europe Portal (Article 8); establishment of the Interoperable Europe Board as the EU governance body chaired by the Commission (Article 15); an Interoperable Europe Community for multi-stakeholder cooperation (Article 16); a GovTech innovation workspace (regulatory sandbox) for testing new interoperability approaches (Article 11); preference for open source software in cross-border public sector ICT (Article 9); and peer review mechanisms for Member State interoperability maturity assessment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_DATA_GOVERNANCE",
        "EU_NIS2",
        "EU_DATA_ACT",
        "EU_DSA"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-data-governance-act-2022",
      "eu-nis2-cloud-essential-services-2022-2555",
      "eu-digital-services-act-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-investment-firm-regulation-2019-2033",
    "title": "EU Investment Firm Regulation (IFR) 2019/2033 - K-Factor Capital Requirements",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2019/2033 establishes a bespoke prudential regime for EU investment firms, replacing CRR/CRD IV for most investment firms. It introduces three firm classes, K-factor capital requirements calibrated to risk-to-client, risk-to-market, and risk-to-firm, and a fixed overhead requirement equal to 25% of prior year fixed overheads. Class 1 systemic firms (≥€15B assets) remain under CRR/CRD IV.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "mifid-ii",
      "eu-aifmd-directive-2011-61",
      "eu-ucits-directive-2009-65"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-iorp-ii-cross-border-transfers-2016",
    "title": "Directive (EU) 2016/2341 of the European Parliament and of the Council of 14 December 2016 on the activities and supervision of institutions for occupational retirement provision (IORPs) (recast)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-06-27",
    "bluf": "This directive establishes harmonized EU rules for Institutions for Occupational Retirement Provision (IORPs), focusing on governance, risk management, investment freedom, and information disclosure to members. It facilitates cross-border pension fund activities by requiring host Member States to accept the prudential rules of the home Member State, as detailed in Article 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "erisa-compliance-rep"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-iorp-ii-directive-2016-2341-occupational-pensions",
    "title": "Directive (EU) 2016/2341 of the European Parliament and of the Council of 14 December 2016 on the activities and supervision of institutions for occupational retirement provision (IORPs)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes a risk-based supervisory framework for Institutions for Occupational Retirement Provision (IORPs) in the EU, mandating robust governance systems, effective risk management, and enhanced transparency for members and beneficiaries. A key requirement under Article 29 is the regular performance of an Own-Risk Assessment (ORA) to evaluate the overall solvency needs and risk profile.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ip-enforcement-directive-2004-48-article-13-damages-ip-infringement",
    "title": "Directive 2004/48/EC of the European Parliament and of the Council on the enforcement of intellectual property rights - Article 13: Damages",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations found to have knowingly engaged in intellectual property infringement must, upon court order initiated by the injured party, pay damages appropriate to the actual prejudice suffered by the rightholder.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ip-enforcement-directive-2004-48-article-6-evidence-disclosure",
    "title": "Directive 2004/48/EC on the enforcement of intellectual property rights - Article 6 Evidence",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must be prepared to present evidence within their control when ordered by a judicial authority in an intellectual property dispute, provided the requesting party has substantiated their claims and subject to the protection of confidential information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-irrbb-bcbs-standards-2016",
    "title": "EU Interest Rate Risk in the Banking Book (IRRBB) - BCBS Standards 368 and EBA Guidelines",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "IRRBB standards (BCBS April 2016 and EBA/GL/2018/02) require banks to measure, manage, and report interest rate risk in the banking book using Economic Value of Equity (EVE) and Net Interest Income (NII) metrics under 6 prescribed shock scenarios; a supervisory outlier test flags banks where EVE declines by >15% of Tier 1 capital or >20% (EBA threshold) triggering mandatory review.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-single-supervisory-mechanism-regulation-1024-2013",
      "eu-crr3-capital-requirements-regulation-2024-1623"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-its-directive-2010-40-delegated-regulations",
    "title": "Directive 2010/40/EU on the framework for the deployment of Intelligent Transport Systems in the field of road transport and for interfaces with other modes of transport, and its associated Delegated Regulations",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes a framework for the coordinated EU-wide deployment of Intelligent Transport Systems (ITS) for road transport. It mandates, via delegated regulations adopted under Article 6, that Member States, public authorities, and private operators implement common specifications for priority areas, including multimodal travel information, real-time traffic data, road safety services like eCall, and secure parking information for trucks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-46-transfer-mechanisms",
      "nist-800-171-rev-3"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-iuu-fishing-regulation-1005-2008",
    "title": "Council Regulation (EC) No 1005/2008 (IUU Fishing)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Council Regulation (EC) No 1005/2008 establishes a Community system to prevent, deter and eliminate illegal, unreported and unregulated (IUU) fishing. Article 12 prohibits importing IUU fishery products and requires every import into the Community to be accompanied by a flag-State-validated catch certificate. Article 27 directs the Commission to establish a Community IUU vessel list of vessels engaged in IUU fishing, and Article 31 empowers the Commission to identify non-cooperating third countries (the carding process) on transparent, clear and objective criteria after prior notification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-port-state-control-directive-2009-16"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ivd-regulation-2017-746-article-10-general-obligations-manufacturers",
    "title": "Regulation (EU) 2017/746 on in vitro diagnostic medical devices - Article 10: General obligations of manufacturers",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Manufacturers must ensure that any in vitro diagnostic medical devices they place on the market or put into service have been designed and manufactured in full accordance with the requirements of Regulation (EU) 2017/746.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ivd-regulation-2017-746-genomic-diagnostics",
    "title": "Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices and repealing Directive 98/79/EC and Commission Decision 2010/227/EU - Genomic Diagnostics: Class D High-Risk Devices, Performance Studies, Companion Diagnostics, Notified Body Review and EUDAMED Registration",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Regulation (EU) 2017/746 establishes stringent requirements for high-risk in vitro diagnostic devices, including genomic diagnostics classified as Class D, mandating Notified Body involvement, performance evaluation studies under Article 61, and companion diagnostic co-development with medicinal products under Article 37. It applies to manufacturers, authorized representatives, and clinical investigators placing IVDs on the EU market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-atmp-regulation-1394-2007",
      "ema-guidelines-advanced-therapy-quality-2019",
      "ich-e8-r1-general-considerations-clinical-2021",
      "isber-best-practices-biorepositories-2018",
      "nagoya-protocol-genetic-resources-2010"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ivdr-2017-746",
    "title": "EU IVDR 2017/746 (Diagnostics)",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "EU Regulation 2017/746 (In-Vitro Diagnostic Medical Device Regulation - IVDR) is the primary framework for diagnostic devices in the European Union. It replaces the previous 98/79/EC directive and dramatically increases the oversight of IVDs, requiring nearly 80% of devices to undergo notified body audit (vs. 20% previously).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mdr-2017-745",
      "iso-13485-medical-qms",
      "iso-14971-medical-risk",
      "iec-62304-medical-software",
      "iso-15189-medical-labs",
      "gxp-clinical-practice"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-ivdr-2017-746-2026",
    "title": "Regulation (EU) 2017/746 - In Vitro Diagnostic Medical Devices Regulation (IVDR) - Key Obligations (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The EU IVDR establishes a risk-based classification (Class A-D) for in vitro diagnostic medical devices with stringent requirements for performance evaluation, clinical evidence, quality management systems, post-market surveillance, and conformity assessment by notified bodies (especially for Class C and D). Full application with extended transition periods for legacy devices continues through 2026-2028.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "eu-ivdr-2017-746-in-vitro-diagnostic-devices",
    "title": "Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The EU In Vitro Diagnostic Regulation 2017/746 requires manufacturers of in vitro diagnostic medical devices to comply with the requirements outlined in Article 17, including the conduct of performance studies and the establishment of a quality management system. This regulation applies to all manufacturers of in vitro diagnostic medical devices that are placed on the EU market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-joint-cyber-unit-framework-2021",
    "title": "Commission Recommendation (EU) 2021/1052 of 23 June 2021 on building a Joint Cyber Unit",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This framework establishes a platform for structured cooperation between EU bodies (ENISA, CERT-EU), Member States' authorities, and private sector partners to ensure a coordinated response to large-scale cybersecurity incidents and threats, as outlined in Article 1 of the Recommendation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cybersecurity-act-2019",
      "eu-cyber-solidarity-act-2024",
      "enisa-threat-landscape-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-l-category-vehicle-type-approval-168-2013",
    "title": "Regulation (EU) No 168/2013 of the European Parliament and of the Council of 15 January 2013 on the approval and market surveillance of two- or three-wheel vehicles and quadricycles",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation sets the administrative and technical requirements for the type-approval and market surveillance of L-category vehicles, namely powered two- and three-wheel vehicles and quadricycles intended to travel on public roads (Articles 1 and 2). It defines the L1e to L7e categories including mopeds, motorcycles and quads (Article 4), requires Member States to designate approval and market surveillance authorities (Article 6), and imposes manufacturer obligations for conformity and for handling non-conforming or seriously risky products (Articles 9 and 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-type-approval-framework-regulation-2018-858",
      "eu-market-surveillance-regulation-2019-1020-auto"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-large-exposures-crr-article-395",
    "title": "EU Large Exposures Framework - CRR Articles 387-403",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "EU CRR Articles 387-403 cap a credit institution's exposure to any single client or connected clients group at 25% of eligible capital (15% for G-SIIs and O-SIIs on an intra-financial-sector basis); large exposures (≥10% of eligible capital) must be reported to the competent authority; exposures must be calculated after credit risk mitigation and include both on- and off-balance-sheet items and derivatives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-crr3-capital-requirements-regulation-2024-1623",
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-single-supervisory-mechanism-regulation-1024-2013"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-late-payment-directive-2011",
    "title": "Directive 2011/7/EU of the European Parliament and of the Council of 16 February 2011 on combating late payment in commercial transactions",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This directive establishes harmonized EU rules for commercial transactions between undertakings (B2B) and between undertakings and public authorities, mandating payment periods generally not exceeding 60 days and entitling creditors to statutory interest and fixed compensation for late payments, as outlined in Articles 3, 4, and 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-37301-compliance-ms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-late-payment-directive-2011-7",
    "title": "EU Late Payment Directive 2011/7/EU - B2B and B2G Payment Terms and Statutory Interest",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Directive 2011/7/EU of the European Parliament and of the Council on combating late payment in commercial transactions establishes mandatory payment terms, statutory interest rates, and recovery cost compensation throughout the EU. Article 3 sets the default B2B payment period at 30 days with a contractual maximum of 60 days; any agreement deviating beyond 60 days requires express agreement and must not be grossly unfair to the creditor. Article 4 sets a 30-day default for public authority debtors with a maximum contractual extension to 60 days. The statutory interest rate for late payment is the European Central Bank reference rate plus 8 percentage points. Article 6 entitles the creditor to a minimum EUR 40 fixed-sum compensation for recovery costs when statutory interest becomes payable, without the need to prove actual costs. Article 7 renders unfair contract terms or practices that exclude or restrict the creditor's rights unenforceable. The Directive repealed and replaced Directive 2000/35/EC and applied from March 16, 2013.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_electronic_invoicing_2014_55",
        "eu_services_directive_2006_123",
        "uk_late_payment_legislation",
        "eu_procurement_directives",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electronic-invoicing-directive-2014-55",
      "eu-services-directive-2006-123",
      "eu-tax-dispute-resolution-directive-2017-1852"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-late-payment-directive-2011-7-business-operations",
    "title": "Directive 2011/7/EU of the European Parliament and of the Council of 16 February 2011 on combating late payment in commercial transactions",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive mandates that public authorities pay undisputed invoices within 30 days and private sector businesses within 60 days unless otherwise agreed in writing, requires statutory interest at 8 percentage points above the European Central Bank's reference rate for late payments, and grants creditors the right to claim a minimum fixed compensation of €40 and reasonable recovery costs. Key obligations are established under Article 4 (payment terms), Article 5 (interest), and Article 6 (compensation).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "iso-15489-1-2016-records-management-workflow",
      "bpmn-2-0-omg-specification-workflow-notation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-lawful-interception-etsi-standards",
    "title": "EU Lawful Interception Framework - ETSI ES 201 671 and TS 101 331 Handover Interface Standards for Electronic Communications",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "These ETSI standards mandate that Communications Service Providers (CSPs) implement a standardized Handover Interface (HI) to securely deliver intercepted communications content (CC) and intercept related information (IRI) to authorized Law Enforcement Agencies (LEAs) upon receipt of a legal warrant. The framework, particularly ES 201 671 Clause 4, defines the general requirements for the interception system and the HI architecture.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0",
      "coe-convention-108-plus"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-legal-aid-directive-2016-1919",
    "title": "Directive (EU) 2016/1919 of the European Parliament and of the Council of 26 October 2016 on legal aid for suspects and accused persons in criminal proceedings and for requested persons in European arrest warrant proceedings",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive lays down common minimum rules on the right to legal aid for suspects and accused persons in criminal proceedings and for requested persons in European arrest warrant proceedings (Article 1). Member States must ensure legal aid for those who lack sufficient resources, applying a means test, a merits test or both (Article 4), ensure legal aid in European arrest warrant proceedings (Article 5), require timely decisions on granting legal aid (Article 6), ensure the quality of legal aid services and lawyer training (Article 7), and provide effective remedies (Article 8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-presumption-of-innocence-directive-2016-343",
      "eu-procedural-safeguards-children-directive-2016-800"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-leniency-programme-2006-cartel-immunity",
    "title": "Commission Notice on Immunity from fines and reduction of fines in cartel cases (2006/C 298/11)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This notice grants total immunity from fines to the first undertaking to disclose its participation in a secret cartel to the European Commission, provided it submits decisive evidence (Point 8(a)). Subsequent cooperators can receive fine reductions of up to 50%, 30%, and 20% respectively, contingent on providing significant added value and meeting strict, continuous cooperation requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "iso-37001-anti-bribery"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-long-term-residents-directive-2003-109-ec",
    "title": "EU Long-Term Residents Directive 2003/109/EC - Third-Country National Status, Equal Treatment and Mobility Rights",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "Council Directive 2003/109/EC of 25 November 2003 concerning the status of third-country nationals who are long-term residents establishes a common EU framework granting long-term resident status to third-country nationals who have legally and continuously resided in the territory of a Member State for five years. The Directive applies in all Member States except Denmark and Ireland (Denmark opted out under Protocol 22; Ireland did not opt in under Protocol 21); the United Kingdom did not opt in before Brexit. The Directive was substantially amended by Directive 2011/51/EU extending its scope to beneficiaries of international protection (refugees and subsidiary protection beneficiaries). Article 4 establishes the 5-year continuous legal residence requirement with absences not exceeding 6 consecutive months and 10 months in total over the 5-year period. Article 5 conditions include stable and regular resources, sickness insurance, and where Member States require, integration conditions. Article 7 sets out the application procedure with Member State decision within 6 months. Article 11 provides equal treatment with nationals in employment, education, social protection, tax benefits, access to goods and services, freedom of association, free access to entire territory of Member State subject to security restrictions. Articles 14-23 grant the right to reside in a second Member State for employment, study or other purposes subject to that State's procedures. Article 9 sets out withdrawal grounds. Article 12 provides enhanced protection against expulsion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-schengen-borders-code-regulation-2016-399"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-low-voltage-directive-2014-35",
    "title": "Directive 2014/35/EU of the European Parliament and of the Council of 26 February 2014 on electrical equipment designed for use within certain voltage limits (Low Voltage Directive)",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "The Low Voltage Directive ensures that electrical equipment within defined voltage limits on the EU market meets a high level of protection of health and safety while allowing free movement (Articles 1 and 4). Electrical equipment may be made available only if it complies with the safety objectives set out in Annex I (Article 3), and the Directive imposes obligations on manufacturers (Article 6), authorised representatives (Article 7), importers (Article 8) and distributors (Article 9), with traceability through identification of economic operators (Article 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-market-surveillance-regulation-2019-1020-auto",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-machinery-directive-2006-42",
    "title": "EU Machinery Directive 2006/42/EC -- CE Marking and Safety Requirements for Machinery",
    "domain": "Industrial IoT & Energy",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Directive 2006/42/EC (the Machinery Directive) sets out Essential Health and Safety Requirements (EHSRs) for machinery placed on the EU market or put into service. It applies to machinery (a product with at least one moving part, driven by an energy source other than direct human or animal effort), interchangeable equipment, safety components, lifting accessories, chains, ropes and webbing, detachable mechanical transmission devices, and partly completed machinery. Manufacturers must: conduct a risk assessment under Annex I Section 1; design machinery to comply with EHSRs; prepare Technical Documentation; issue a Declaration of Conformity (DoC); and affix CE marking. For high-risk Annex IV machinery (including power presses, chainsaw guards, woodworking machinery, and vehicle service lifts), conformity assessment requires either Notified Body examination (Annex IX EC type-examination) or full quality assurance (Annex X). The Directive will be replaced by Machinery Regulation (EU) 2023/1230 from 14 January 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-health-safety-framework-directive-89-391",
      "eu-reach-regulation-1907-2006"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-machinery-directive-2006-42-construction",
    "title": "Directive 2006/42/EC of the European Parliament and of the Council of 17 May 2006 on machinery, and amending Directive 95/16/EC",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive establishes essential health and safety requirements (EHSRs) for machinery placed on the EU market, including construction equipment. It mandates CE marking, technical file creation, Declaration of Conformity, and involvement of a Notified Body for high-risk machines under Annex IV, per Article 8 and Article 12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-2015-quality-management-construction",
      "iso-19650-bim-information-management-construction",
      "eu-circular-economy-construction-demolition-waste-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-machinery-regulation-2023",
    "title": "Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery and repealing Directive 2006/42/EC of the European Parliament and of the Council and Council Directive 73/361/EEC",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes harmonised safety requirements for machinery and related products placed on the EU market, addressing new risks from digital technologies like AI and collaborative robots. It mandates that manufacturers conduct a comprehensive risk assessment and complete the relevant conformity assessment procedure as detailed in Article 25 and Annex III before affixing the CE marking.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-market-surveillance-chapter-viii",
      "eu-data-act-2023",
      "iso-27005-risk-management-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-machinery-regulation-2023-1230-article-10-technical-file",
    "title": "Regulation (EU) 2023/1230 on machinery - Article 10: Obligations of distributors",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article outlines the obligations for distributors to ensure machinery and related products conform to safety requirements, including halting distribution, taking corrective actions, and cooperating with authorities for non-compliant products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-machinery-regulation-2023-1230-article-6-essential-requirements",
    "title": "Regulation (EU) 2023/1230 on machinery - Article 6: Categories of machinery and related products listed in Annex I subject to relevant conformity assessment procedures",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article mandates that machinery and related products listed in Annex I must undergo specific conformity assessment procedures, with different options available depending on whether the product is listed in Part A or Part B of Annex I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-machinery-regulation-2023-1230-safety",
    "title": "Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery, amending Regulations (EU) No 1025/2012 and (EU) 2017/745, and repealing Directive 2006/42/EC - Safety of Machinery Including Connected and AI-Enabled Machines: Essential Health and Safety Requirements, CE Marking, Technical File and Notified Body Assessment",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes mandatory safety requirements for machinery placed on or put into service in the EU, including machines with connectivity, AI functions, and digital interfaces. It applies to manufacturers, importers, and authorized representatives, requiring compliance with Essential Health and Safety Requirements (EHSRs), technical documentation, risk assessment, and conformity assessment procedures under Article 5 and Annex I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cyber-resilience-act-iot-2024-products",
      "etsi-en-303-645-iot-cybersecurity-2020",
      "eu-data-act-2023-iot-data-sharing-obligations",
      "edge-ai-security-nist"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-machinery-regulation-2023-1230-safety-requirements",
    "title": "Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery, amending Regulations (EU) No 1025/2012 and (EU) 2019/1020, and repealing Directive 2006/42/EC - Safety Requirements for Machinery with AI/ML Components: Risk Assessment, Safe Design and Substantial Modification",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes mandatory safety requirements for machinery placed on or put into service in the EU, with specific provisions for machinery integrating AI/ML components. It requires manufacturers to conduct comprehensive risk assessments, ensure safe design and construction, and assess whether modifications constitute substantial changes triggering re-evaluation under Article 13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cyber-resilience-act-iot-2024-products",
      "eu-data-act-2023-iot-data-sharing-obligations",
      "etsi-en-303-645-iot-cybersecurity-2020",
      "edge-ai-security-nist"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mandatory-disclosure-rules-dac6-2018-65-eu",
    "title": "EU Mandatory Disclosure Rules - DAC6 Directive 2018/822/EU",
    "domain": "Tax & Transfer Pricing",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "EU Directive 2018/822/EU (DAC6) requires intermediaries and taxpayers to report cross-border tax arrangements bearing specified hallmarks to national tax authorities within 30 days; information is automatically exchanged across EU member states via the Common Communication Network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mar-regulation-article-10-unlawful-disclosure-inside-information",
    "title": "Market Abuse Regulation (EU) No 596/2014 (MAR) - Article 10: Unlawful disclosure of inside information",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article prohibits any person possessing inside information from unlawfully disclosing it to any other person, except when such disclosure is a normal part of their employment, profession, or duties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mar-regulation-article-14-prohibition-insider-dealing-market-manipulation",
    "title": "Market Abuse Regulation (EU) No 596/2014 - Article 14: Prohibition of insider dealing and of unlawful disclosure of inside information",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article prohibits any person from engaging in or attempting to engage in insider dealing, recommending or inducing others to engage in insider dealing, and unlawfully disclosing inside information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mar-regulation-article-15-market-soundings-obligations",
    "title": "Regulation (EU) No 596/2014 on market abuse (market abuse regulation) - Article 15: Prohibition of market manipulation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article establishes a strict and absolute prohibition for any person to engage in, or attempt to engage in, market manipulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mar-regulation-article-17-public-disclosure-of-inside-information",
    "title": "Market Abuse Regulation (EU) No 596/2014 (MAR) Article 17: Public disclosure of inside information",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Issuers must publicly disclose inside information that directly concerns them as soon as possible.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mar-regulation-article-18-insider-lists-maintenance-obligations",
    "title": "Market Abuse Regulation (EU) No 596/2014 (MAR) Article 18: Insider lists",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Issuers and their agents must create and maintain a list of all individuals who have access to inside information, known as an insider list.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mar-regulation-article-19-managers-transactions-disclosure",
    "title": "Market Abuse Regulation (EU) No 596/2014 - Article 19: Managers’ transactions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires persons discharging managerial responsibilities (PDMRs) and their closely associated persons (PCAs) to notify both the issuer or emission allowance market participant and the competent authority of their transactions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mar-regulation-article-20-investment-recommendations-fair-presentation",
    "title": "Regulation (EU) No 596/2014 on market abuse (market abuse regulation) - Article 20: Investment recommendations and statistics",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations producing or disseminating investment recommendations must ensure objective presentation and disclose any interests or conflicts of interest related to the financial instruments involved.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mar-regulation-article-7-definition-inside-information",
    "title": "Market Abuse Regulation (EU) No 596/2014 (MAR) Article 7: Inside information",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article establishes the comprehensive definition of 'inside information' for financial instruments, commodity derivatives, and emission allowances, specifying the criteria of precision, non-public nature, and potential price sensitivity that trigger disclosure and trading prohibitions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mar-regulation-article-8-insider-dealing-prohibition",
    "title": "Market Abuse Regulation (EU) No 596/2014 (MAR) Article 8: Insider dealing",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article prohibits persons who possess inside information from using it to acquire or dispose of related financial instruments, cancel or amend prior orders, or submit, modify, or withdraw bids in certain auctions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-marine-equipment-directive-2014-90",
    "title": "Directive 2014/90/EU of the European Parliament and of the Council of 23 July 2014 on marine equipment",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive enhances safety at sea and prevents marine pollution through the uniform application of international instruments to marine equipment placed on board EU ships (Articles 1 and 3). Marine equipment must meet the requirements of the applicable international instruments and testing standards (Articles 4 and 8), bear the wheel mark of conformity (Articles 9 and 10), and may carry an electronic tag (Article 11). Manufacturers take responsibility for conformity by affixing the wheel mark (Article 12), with obligations also on authorised representatives and importers (Articles 13 and 14).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-port-state-control-directive-2009-16",
      "imo-ballast-water-management-convention-2004-bwm"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-marine-strategy-framework-directive-2008-56-ec",
    "title": "EU Marine Strategy Framework Directive 2008/56/EC - Good Environmental Status, 11 Descriptors and Marine Strategy Cycle",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "Directive 2008/56/EC of the European Parliament and of the Council establishing a framework for community action in the field of marine environmental policy (Marine Strategy Framework Directive, MSFD) is the integrative environmental pillar of the EU Integrated Maritime Policy. The Directive requires Member States to develop a marine strategy for each Marine Region or Subregion (Baltic Sea, North-east Atlantic Ocean, Mediterranean Sea, Black Sea) to achieve Good Environmental Status (GES) of marine waters by 2020 and maintain it thereafter. GES is defined under Article 3(5) by reference to 11 qualitative descriptors set out in Annex I: biological diversity, non-indigenous species, commercially exploited fish and shellfish, food webs, eutrophication, sea-floor integrity, hydrographical conditions, contaminants, contaminants in seafood, marine litter, and energy including underwater noise. Article 5 establishes a six-year marine strategy cycle covering initial assessment (Article 8), determination of GES (Article 9), environmental targets (Article 10), monitoring programmes (Article 11) and programmes of measures (Article 13). Commission Decision (EU) 2017/848 sets criteria and methodological standards for GES.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-water-framework-directive-2000-60-ec",
      "imo-marpol-73-78-annex-i-oil-pollution-prevention-oily-water"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-maritime-accident-investigation-directive-2009-18",
    "title": "Directive 2009/18/EC of the European Parliament and of the Council of 23 April 2009 establishing the fundamental principles governing the investigation of accidents in the maritime transport sector",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive establishes fundamental principles for the safety investigation of marine casualties and incidents to improve maritime safety and prevent pollution. It requires a safety investigation for very serious casualties involving ships flying a Member State flag or in its waters (Articles 2 and 5), conducted by an impartial permanent investigative body independent of criminal or liability proceedings (Articles 4 and 8). It provides for notification (Article 6), a single lead investigation (Article 7), preservation of evidence (Article 13), and a published safety report (Article 14).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-port-state-control-directive-2009-16",
      "eu-flag-state-requirements-directive-2009-21"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-maritime-passenger-rights-regulation-1177-2010",
    "title": "Regulation (EU) No 1177/2010 of the European Parliament and of the Council of 24 November 2010 concerning the rights of passengers when travelling by sea and inland waterway",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation establishes the rights of passengers travelling by sea and inland waterway (Articles 1 and 2). It requires non-discriminatory contract conditions and tickets (Article 4), a right to transport for persons with disabilities or reduced mobility and prohibits refusal of carriage except on justified safety grounds (Articles 7 and 8), and a right to assistance in ports and on board ships (Articles 10 and 11). Carriers must meet quality standards for assistance (Article 13), provide training (Article 14), and ensure compensation for mobility equipment (Article 15), with provisions on cancellations and delays, information and complaint handling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-air-passenger-rights-regulation-261-2004",
      "imo-maritime-labour-convention-2006-mlc"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-maritime-single-window-regulation-2019-1239",
    "title": "EU Maritime Single Window Regulation (EU) 2019/1239 - eMSW Digital Reporting Framework",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Regulation (EU) 2019/1239 establishes the European Maritime Single Window environment (eMSW), requiring EU Member States to operate a national single window portal by 15 August 2025 through which ships calling at EU ports must submit all mandatory FAL (Facilitation of International Maritime Traffic) reporting digitally. The Regulation harmonises the 42 mandatory reporting datasets across all EU ports, eliminates duplicate reporting to different authorities, and mandates data sharing between national competent authorities and the EMSA-operated EMSWe system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-maritime-spatial-planning-directive-2014-89",
    "title": "Directive 2014/89/EU (Maritime Spatial Planning)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Directive 2014/89/EU establishes a framework for maritime spatial planning across EU marine waters. Article 4 requires each Member State to establish and implement maritime spatial planning, taking into account land-sea interactions. Article 8 requires Member States to set up maritime spatial plans that identify the spatial and temporal distribution of relevant existing and future activities and uses in their marine waters, and Article 15(3) sets the deadline that those plans be established as soon as possible and at the latest by 31 March 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-maritime-transport-strategy-2021",
    "title": "EU Maritime Transport Strategy 2021-2030 - Decarbonisation Pathway and FuelEU Maritime Regulation Proposals",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This EU strategy mandates a progressive reduction in the greenhouse gas (GHG) intensity of energy used by ships calling at EU ports, regardless of their flag. As implemented by Regulation (EU) 2023/1805 (FuelEU Maritime), it requires ship operators to meet specific GHG intensity limits starting in 2025 and imposes obligations for certain ships to use on-shore power supply in major EU ports by 2030.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ghg-protocol-scope3",
      "iso-14064-ghg-quantify",
      "eu-taxonomy-sustainable",
      "csrd-eu-sustainability"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-market-abuse-regulation-596-2014",
    "title": "Regulation (EU) 596/2014 - Market Abuse Regulation (MAR): Insider Dealing Prohibition, Market Manipulation Ban, Article 17 Inside Information Disclosure Delay, EUR 20,000 PDMR Notification Threshold (as amended by Listing Act 2024/2809), Insider Lists, and Suspicious Transaction Reporting",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 596/2014 (Market Abuse Regulation, MAR), applicable from 3 July 2016, is the primary EU instrument prohibiting market abuse and ensuring market integrity; it prohibits: (i) insider dealing - trading on inside information or tipping off others with inside information (Articles 8, 14); (ii) market manipulation - false impressions of supply/demand, price-fixing, spreading false information (Articles 12, 15); MAR requires: issuers to disclose inside information to the public as soon as possible under Article 17(1), with a delay option under Article 17(4) if disclosure would prejudice legitimate interests; maintenance of insider lists (Article 18); notification of managers'/PDMRs' transactions within three business days when cumulative transactions exceed EUR 20,000 per calendar year (threshold raised from EUR 5,000 by Regulation (EU) 2024/2809 - Listing Act, in force 4 December 2024); suspicious transaction and order reporting (STOR) to national competent authorities within 24 hours (Article 16); maximum administrative fines: EUR 15M or 15% of annual turnover for legal persons, EUR 5M for natural persons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_MiFID_II",
        "EU_CSMAD",
        "EU_TRANSPARENCY",
        "EU_LISTING_ACT"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mifid-ii",
      "mifir-transaction-report",
      "eu-aml-regulation-2024-crypto-assets",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-market-surveillance-regulation-2019-1020",
    "title": "Regulation (EU) 2019/1020 of the European Parliament and of the Council of 20 June 2019 on market surveillance and compliance of products and amending Directive 2004/42/EC and Regulation (EC) No 765/2008",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes obligations for economic operators, including online marketplace operators, to ensure product traceability and compliance with EU safety rules. It mandates that importers and distributors verify product conformity, affix contact information, and cooperate with market surveillance authorities under Article 4 and Article 27.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecommerce-directive-2000-31",
      "eu-unfair-commercial-practices-2005-29",
      "eu-geo-blocking-regulation-2018-302",
      "coppa-marketing-kids",
      "can-spam-act-email"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-market-surveillance-regulation-2019-1020-auto",
    "title": "Regulation (EU) 2019/1020 on market surveillance and compliance of products - Provisions for automotive components and related obligations for economic operators",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Regulation (EU) 2019/1020 establishes binding obligations for economic operators (manufacturers, importers, authorised representatives, distributors) placing automotive components on the EU market, requiring traceability, appointment of EU representatives for non-EU manufacturers, and corrective actions for non-compliant products under Article 4 and Article 15. It applies to all automotive parts covered by EU type-approval or harmonisation legislation such as Regulation (EU) 2018/858.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-markets-crypto-assets-regulation-2023-1114",
    "title": "EU Markets in Crypto-Assets Regulation (MiCA) 2023/1114 -- Crypto-Asset Authorisation and Consumer Protection",
    "domain": "Crypto & Sovereign Finance",
    "version": "2024.1.0",
    "last_updated": "2024-12-30",
    "bluf": "Regulation (EU) 2023/1114 (MiCA) establishes the first comprehensive EU regulatory framework for crypto-assets. Title III (Asset-Referenced Tokens, ARTs) and Title IV (E-Money Tokens, EMTs) applied from 30 June 2024. Titles I, II, V, VI, and VII applied from 30 December 2024. Issuers of ARTs (crypto-assets referencing multiple currencies, commodities, or assets) must be authorised by a national competent authority (NCA) and comply with whitepaper requirements under Article 19 and reserve asset requirements under Article 36. EMT issuers must be authorised credit institutions or e-money institutions. Crypto-Asset Service Providers (CASPs) must obtain authorisation from the NCA of their home Member State under Article 59 and can passport EU-wide. Significant ARTs and EMTs exceeding EUR 1 billion reserve or 10 million daily transactions are supervised by EBA. Market abuse provisions in Title VI prohibit insider dealing, market manipulation, and unlawful disclosure. The EU passporting regime allows CASPs authorised in one Member State to provide services across the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-payment-services-directive-2-2015-2366",
      "eu-capital-requirements-regulation-2013-575",
      "eu-data-governance-act-2022-868"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-markets-crypto-assets-regulation-mica-title-ii-iii-asset-referenced-e-money",
    "title": "EU MiCA Regulation 2023/1114 - Asset-Referenced Tokens and E-Money Tokens (Titles II and III)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-06-30",
    "bluf": "Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA) Titles II and III, applicable from 30 June 2024, establish the regulatory framework for issuers of asset-referenced tokens (ARTs) and e-money tokens (EMTs) in the EU. ART issuers require authorisation from national competent authorities unless the aggregate ART value is below EUR 5 million per year. EMT issuers must be licensed as credit institutions or e-money institutions and comply with prudential requirements including own funds, redemption rights, and reserve asset requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-psd2-rts-strong-customer-auth-2018",
      "eu-6amld-directive-2018-1673-anti-money-laundering-criminal-offences"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-markets-in-crypto-assets-regulation-mica-2023-1114",
    "title": "EU Markets in Crypto-Assets Regulation (MiCA) 2023/1114 - ESMA/EBA",
    "domain": "Crypto & Sovereign Finance",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Regulation (EU) 2023/1114 (MiCA) establishes a harmonised EU framework for crypto-asset markets, covering issuers of asset-referenced tokens (ARTs) and e-money tokens (EMTs), and crypto-asset service providers (CASPs); CASPs require authorisation from national competent authority; ART/EMT issuers face prudential and reserve requirements from June 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-marrakesh-cross-border-accessible-copies-regulation-2017-1563",
    "title": "Regulation (EU) 2017/1563 of the European Parliament and of the Council of 13 September 2017 on the cross-border exchange between the Union and third countries of accessible format copies of certain works and other subject matter protected by copyright and related rights for the benefit of persons who are blind, visually impaired or otherwise print-disabled",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation implements the Marrakesh Treaty obligations on the cross-border exchange of accessible format copies of works for the benefit of persons who are blind, visually impaired or otherwise print-disabled (Article 1). It permits authorised entities established in a Member State to export accessible format copies to a beneficiary person or authorised entity in a third country that is party to the Marrakesh Treaty (Article 3), and permits the import of such copies from third countries (Article 4), subject to obligations on authorised entities including practices to distribute only to beneficiaries and to respect the integrity of works (Article 5) and personal data protection (Article 6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-marrakesh-treaty-2013",
      "eu-copyright-directive-2019-790"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-maximum-residue-levels-regulation-396-2005",
    "title": "Establishing maximum residue levels of pesticides in or on food and feed of plant and animal origin and amending Directive 91/414/EEC",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Regulation (EC) No 396/2005 of the European Parliament and of the Council of 23 February 2005 establishes maximum residue levels (MRLs) for pesticides in or on food and feed of plant and animal origin. The regulation applies to products listed in Annex I, including fresh, processed and composite food and feed, and sets MRLs to ensure a high level of consumer protection. MRLs are set based on good agricultural practice (GAP) and the lowest consumer exposure necessary to protect vulnerable groups such as children and the unborn. Default MRLs are set at 0.01 mg/kg for active substances not listed in Annexes II, III, or IV, with possibility of different default values in Annex V. Applications for new or modified MRLs are submitted to a Member State (rapporteur), which evaluates the application and forwards it to the European Food Safety Authority (EFSA) and the Commission. EFSA issues a reasoned opinion within three months (extendable to six). The Commission then prepares a regulation or decision within three months, taking into account scientific knowledge, cumulative and synergistic effects, Codex Alimentarius MRLs (CXLs), and third country GAP. Temporary MRLs (Annex III) are set for active substances not yet evaluated under Directive 91/414/EEC and are reassessed periodically. Products placed on the market must not exceed established MRLs. Member States must carry out official controls, including sampling and analysis, to enforce compliance. A multiannual Community control programme is coordinated by the Commission to assess consumer exposure and application of the legislation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-plant-protection-products-regulation-1107-2009",
      "eu-official-controls-regulation-2017-625"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-mcd-mortgage-credit-directive-2014-17",
    "title": "EU Mortgage Credit Directive 2014/17/EU (MCD) - Responsible Mortgage Lending",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive 2014/17/EU (MCD) harmonises EU standards for residential mortgage credit. It mandates a European Standardised Information Sheet (ESIS) for pre-contractual disclosure, creditworthiness assessment before mortgage grant, a minimum 7-day reflection period before contract conclusion, and regulated early repayment rights. The MCD regulates credit intermediaries and requires their registration and professional competence. Foreign currency loans require risk disclosure, periodic review, and switching rights. The EBA issues technical standards on creditworthiness assessment, ESIS format, and lender registration across Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-deposit-guarantee-schemes-directive-2014-49",
      "eu-payment-accounts-directive-2014-92"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mdr-2017-745",
    "title": "EU MDR 2017/745 (Devices)",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "EU Regulation 2017/745 (Medical Device Regulation - MDR) is the primary framework for medical device compliance in the European Union. It replaces the previous MDD/AIMDD directives, introducing more rigorous requirements for pre-market clinical evaluation, post-market surveillance (PMS), and traceability through the UDI system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-medical-qms",
      "iso-14971-medical-risk",
      "iec-62304-medical-software",
      "fda-21-cfr-part-820-qsr",
      "gxp-clinical-practice",
      "iso-27799-health-info-sec"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mdr-2017-745-classification-rules",
    "title": "Regulation (EU) 2017/745 Annex VIII: Classification Rules for Medical Devices",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Regulation (EU) 2017/745 requires manufacturers to classify medical devices into one of four risk classes (I, IIa, IIb, III) according to the 22 rules outlined in Annex VIII, which determines the required conformity assessment procedure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mdr-2017-745",
      "iso-14971-medical-risk",
      "iso-13485-medical-qms",
      "eu-medical-device-ai-guidance-2021",
      "imdrf-samd-risk-framework"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-mdr-2017-745-clinical-evaluation",
    "title": "Regulation (EU) 2017/745 on Medical Devices (MDR) - Article 61 & Annex XIV: Clinical Evaluation",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Under EU MDR Article 61, manufacturers must conduct a systematic and planned clinical evaluation for all medical devices to confirm conformity with General Safety and Performance Requirements (GSPRs), focusing on the device's intended purpose and including a benefit-risk analysis. The process, detailed in Annex XIV, requires the evaluation to be documented in a Clinical Evaluation Report (CER) and updated throughout the device's lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mdr-2017-745",
      "iso-13485-medical-qms",
      "iso-14971-medical-risk",
      "gxp-clinical-practice"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mdr-2017-745-post-market-surveillance",
    "title": "Regulation (EU) 2017/745 on medical devices, Chapter VII: Post-Market Surveillance, Vigilance and Market Surveillance (Articles 83-99)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation requires manufacturers of medical devices placed on the EU market to establish, document, and maintain a post-market surveillance (PMS) system for each device. As outlined in Article 83, this system must actively and systematically gather, record, and analyze relevant data on the quality, performance, and safety of a device throughout its entire lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mdr-2017-745",
      "iso-13485-medical-qms",
      "iso-14971-medical-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mdr-annex-ix-2026",
    "title": "EU MDR Annex IX - Conformity Assessment Procedures for High-Risk Devices",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "Detailed procedures for Class IIb and III devices including QMS audits, technical documentation review, and clinical evaluation consultation. 2026 amendments strengthen scrutiny for AI/ML components under Rule 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mdr-annex-xiv-clinical-investigation-2026",
    "title": "EU MDR Annex XIV - Clinical Investigation Requirements for Medical Devices (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Legal framework under Annex XIV of the EU Medical Device Regulation (MDR) governing how clinical investigations must be designed, authorized, and conducted to demonstrate the safety and clinical performance of medical devices. Emphasizes scientific validity, ethical patient protection, and stringent reporting of serious adverse events.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mdr-article-61-clinical-evaluation-2026"
    ],
    "primary_citations_count": 2
  },
  {
    "node_id": "eu-mdr-article-61-clinical-evaluation-2026",
    "title": "EU MDR Article 61 - Clinical Evaluation Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Under the EU Medical Device Regulation (MDR) 2017/745, Article 61 dictates that clinical evaluation must be a continuous process throughout the lifecycle of a medical device. It mandates that manufacturers systematically collect, appraise, and analyse clinical data to verify the safety and performance, including clinical benefits, of the device.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "eu-mdr-clinical-evaluation-2026",
    "title": "EU MDR Clinical Evaluation & Clinical Investigation Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Strict requirements under the EU Medical Device Regulation (MDR) for conducting clinical evaluations. It mandates a continuous, methodologically sound process to collect, appraise, and analyze clinical data to verify the safety and performance of a device, severely limiting the historical reliance on 'equivalence' to predicate devices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "eu-mdr-post-market-clinical-follow-up-pmcf-2026",
    "title": "EU MDR Post-Market Clinical Follow-up (PMCF) - Detailed Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "PMCF under the EU MDR is a continuous, proactive process to collect and evaluate clinical data from the use of a CE-marked device. It confirms the safety and performance throughout the device's expected lifetime, ensures the continued acceptability of identified risks, and detects emerging risks on the basis of factual evidence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mdr-regulation-2017-745-medical-device-conformity-assessment",
    "title": "EU Medical Device Regulation 2017/745 - Conformity Assessment and Post-Market Surveillance",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Regulation (EU) 2017/745 (MDR) replaces the Medical Devices Directive 93/42/EEC and imposes stricter requirements for medical device conformity assessment, clinical evaluation, unique device identification (UDI), and post-market surveillance. Class IIa, IIb, and III devices require notified body involvement; Class III devices require clinical investigations. EUDAMED registration is mandatory.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ivdr-2017-746-in-vitro-diagnostic-devices"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mdr-regulation-article-1-subject-matter-and-scope",
    "title": "Regulation (EU) 2017/745 on medical devices - Article 1: Subject matter and scope",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the scope of the regulation by defining which products are covered and explicitly excluding certain categories such as advanced therapy medicinal products, cosmetics, food, and specific biological products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-mdr-regulation-article-10-general-obligations-of-manufacturers",
    "title": "Regulation (EU) 2017/745 on medical devices - Article 10: General obligations of manufacturers",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Manufacturers must ensure their medical devices are designed and manufactured in compliance with this Regulation, maintaining a risk management system, technical documentation, and fulfilling UDI and registration requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mdr-regulation-article-11-authorized-representatives",
    "title": "REGULATION (EU) 2017/745 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 5 April 2017 on medical devices - Article 11 Authorised representative",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Requires non-EU medical device manufacturers to designate a sole authorised representative within the Union, defining their specific legal and administrative responsibilities for regulatory compliance and liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-mdr-regulation-article-13-general-obligations-authorized-representative",
    "title": "REGULATION (EU) 2017/745 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 5 April 2017 on medical devices - Article 13: General obligations of authorised representatives",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that non-EU medical device manufacturers must appoint a sole authorised representative within the Union, and specifies the representative's obligations to verify manufacturer compliance, maintain documentation, and cooperate with competent authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mdr-regulation-article-14-general-obligations-of-importers",
    "title": "REGULATION (EU) 2017/745 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 5 April 2017 on medical devices - Article 14: General obligations of importers",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Importers must verify that medical devices comply with EU regulations, including CE marking, labeling, and UDI assignment, before placing them on the Union market, and must maintain records and cooperate with authorities on non-conforming devices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mdr-regulation-article-15-general-obligations-of-distributors",
    "title": "Regulation (EU) 2017/745 of the European Parliament and of the Council on medical devices, Article 15: Person responsible for regulatory compliance",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Manufacturers and authorised representatives must appoint or have permanent access to a person responsible for regulatory compliance who meets specific expertise qualifications and is tasked with overseeing key compliance activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mdr-regulation-article-16-cases-in-which-obligations-of-manufacturers-apply",
    "title": "REGULATION (EU) 2017/745 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 5 April 2017 on medical devices - Article 16: Cases in which obligations of manufacturers apply to importers, distributors or other persons",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article specifies the conditions under which importers, distributors, or other persons assume the full legal obligations of a medical device manufacturer when they modify, rebrand, or change the intended purpose of a device.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mdr-regulation-article-17-eu-declaration-of-conformity",
    "title": "Regulation (EU) 2017/745 on medical devices - Article 17: EU declaration of conformity",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must draw up, maintain, and continuously update an EU declaration of conformity for any medical device placed on the market, affirming it meets all requirements of this Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mdr-regulation-article-18-ce-marking-of-conformity",
    "title": "Regulation (EU) 2017/745 on medical devices - Article 18: Implant card and information to be supplied to the patient with an implanted device",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Manufacturers of implantable medical devices must provide specific device and safety information, including an implant card, with the device, and health institutions must make this information available to the patient.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mdr-regulation-article-2-definitions",
    "title": "Regulation (EU) 2017/745 on medical devices, Article 2 - Definitions",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article defines 'common specifications' (CS) as a specific set of technical or clinical requirements, distinct from a standard, that provides a method for complying with legal obligations for a device, process, or system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mdr-regulation-article-22-systems-and-procedure-packs",
    "title": "Regulation (EU) 2017/745 on medical devices - Article 22: Systems and procedure packs",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Natural or legal persons must draw up a statement when combining CE-marked devices with other devices or products to be placed on the market as a system or procedure pack.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mdr-regulation-article-26-classification-of-devices",
    "title": "Regulation (EU) 2017/745 on medical devices - Article 26: Medical devices nomenclature",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "The European Commission must ensure an internationally recognised medical devices nomenclature is available free of charge for manufacturers and others required to use it to facilitate the functioning of the Eudamed database.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mdr-regulation-article-60-performance-evaluation-and-pmcf",
    "title": "Regulation (EU) 2017/745 of the European Parliament and of the Council on medical devices - Article 60: Derogation from the conformity assessment procedures",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes a derogation process allowing competent authorities to authorize the placing on the market or putting into service of a specific device for which conformity assessment procedures have not been carried out but whose use is in the interest of public health or patient safety.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mdr-regulation-article-61-common-specifications",
    "title": "Regulation (EU) 2017/745 on medical devices - Article 61: Clinical evaluation",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations must plan, conduct, and document a clinical evaluation for medical devices to confirm conformity with safety and performance requirements, based on sufficient clinical evidence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mdr-regulation-article-63-clinical-investigations",
    "title": "REGULATION (EU) 2017/745 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 5 April 2017 on medical devices - Article 63: Clinical investigations",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the fundamental requirement that clinical investigations must be designed, conducted, recorded, and reported in accordance with this Regulation and scientific and ethical principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mdr-regulation-article-83-registration-of-manufacturers",
    "title": "REGULATION (EU) 2017/745 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 5 April 2017 on medical devices - Article 83 Analysis of serious incidents and field safety corrective actions",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Manufacturers must cooperate with competent authorities and notified bodies to perform a centrally coordinated analysis of serious incidents, providing all necessary documentation to assess health risks, identify root causes, and determine the need for corrective actions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mdr-regulation-article-87-unique-device-identification",
    "title": "Regulation (EU) 2017/745 on medical devices - Article 87: Unique Device Identification system",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must establish and maintain a Unique Device Identification (UDI) system for all applicable medical devices to ensure traceability and transparency throughout the supply chain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mdr-technical-documentation-2026",
    "title": "EU MDR Annex II & III - Technical Documentation Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Comprehensive requirements for compiling the Technical Documentation (TD) file required to demonstrate a medical device conforms to the General Safety and Performance Requirements (GSPR) under the EU MDR. Annex II dictates the static device specifications, while Annex III mandates the dynamic post-market surveillance documentation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "eu-media-freedom-act-2024",
    "title": "Regulation (EU) 2024/1083 of the European Parliament and of the Council of 14 May 2024 on the protection, safety and independence of the media and journalists, and on media pluralism and transparency of media ownership",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The EU Media Freedom Act 2024 establishes binding safeguards for media independence, including transparency of state advertising, protection of editorial independence, mandatory media pluralism monitoring, and safeguards for journalistic sources. It applies to Member States, public authorities, and Very Large Online Platforms (VLOPs) under Article 32 of the Digital Services Act, with key obligations in Articles 5, 7, 9, 11, and 13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "eu-data-governance-act-2022",
      "australia-news-media-bargaining-code-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-media-services-directive-2018-1808",
    "title": "EU Audiovisual Media Services Directive 2018/1808 -- Streaming Quotas, VSP Obligations, and Broadcaster Rules",
    "domain": "Creative, Content & Media IP",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Directive (EU) 2018/1808 (AVMSD) amends Directive 2010/13/EU and modernises EU audiovisual regulation for streaming, on-demand, and video-sharing platforms. Member States were required to transpose AVMSD by 19 September 2020. On-demand audiovisual media services (SVOD, AVOD, TVOD) must ensure at least 30 percent of their catalogue consists of European works and must promote them by giving them prominence under Article 13. Video-sharing platform providers (VSPs) - including platforms like YouTube and TikTok whose main purpose or a separable part provides significant user-uploaded audiovisual content - must take appropriate measures to protect minors from harmful content and all users from illegal content inciting violence or hatred under Articles 28a-28b, implemented through co-regulatory or self-regulatory frameworks. The country-of-origin principle under Article 3 determines which single Member State regulates a broadcaster or on-demand service: the provider established in that Member State is regulated under its law, and other Member States cannot restrict reception without following the procedure in Article 3(3)-(4). The advertising cap for linear television is revised to 20 percent of the clock hour for commercial communications under Article 23. The European Regulators Group for Audiovisual Media Services (ERGA) coordinates national regulatory authorities (NRAs) under Article 30b. Audiovisual commercial communications must be transparent, not use subliminal techniques, not promote tobacco or weapons, and comply with restrictions on alcohol and products harmful to children under Article 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-2019-790",
      "eu-unfair-commercial-practices-directive-2005-29",
      "eu-nis2-directive-2022-2555"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-medical-device-ai-guidance-2021",
    "title": "MDCG 2019-11 Guidance on Qualification and Classification of Software in Regulation (EU) 2017/745 - MDR and Regulation (EU) 2017/746 - IVDR",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This guidance provides criteria for qualifying software as a Medical Device (MDSW) or In Vitro Diagnostic (IVD) Medical Device and outlines the risk-based classification rules under EU MDR and IVDR. Manufacturers must apply MDR Annex VIII, Rule 11, which classifies software based on the significance of the information provided and the healthcare situation, to determine if their AI/ML software is Class I, IIa, IIb, or III.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mdr-2017-745",
      "eu-ivdr-2017-746",
      "iec-62304-medical-software",
      "iso-14971-medical-risk",
      "imdrf-samd-risk-framework"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-medical-devices-regulation-2017-745",
    "title": "EU Medical Devices Regulation (MDR) 2017/745 -- CE Marking and Market Surveillance for Medical Devices",
    "domain": "Medical & Healthcare",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Regulation (EU) 2017/745 (MDR) governs the placing on the EU market of medical devices and accessories. It replaced MDD 93/42/EEC and AIMD 90/385/EEC and applied fully from 26 May 2021 (with extended transition periods to 2027-2028 for legacy devices under Regulation 2023/607). Devices are classified into Classes I, IIa, IIb, and III under Annex VIII classification rules (1-22). Classes IIa and above require conformity assessment involving a Notified Body designated under Article 42. All devices must bear CE marking and comply with General Safety and Performance Requirements (GSPR) in Annex I. The Unique Device Identifier (UDI) system under Article 27 mandates labelling and registration in the EUDAMED database (Article 33). Serious incident reporting timelines under Article 87 are: immediately (life-threatening or death), 2 days (serious public health threat), 10 days (serious deterioration of health), and 15 days for trend reporting. Non-EU manufacturers must appoint an Authorised Representative in the EU under Article 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-reach-regulation-1907-2006",
      "eu-clinical-trials-regulation-2014-536"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-medical-devices-regulation-2017-745-article-10-general-obligations-manufacturers",
    "title": "Regulation (EU) 2017/745 on medical devices - Article 10: General obligations of manufacturers",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Manufacturers must ensure that any medical device they place on the market or put into service has been designed and manufactured in full compliance with the requirements of Regulation (EU) 2017/745.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-medical-devices-regulation-2017-745-article-83-post-market-surveillance",
    "title": "Regulation (EU) 2017/745 on medical devices - Article 83: Post-market surveillance system of the manufacturer",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Manufacturers must establish, document, implement, and maintain a post-market surveillance system for each medical device, proportionate to its risk class, to actively collect and analyze data on its quality, performance, and safety throughout its lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-medical-devices-regulation-2017-745-mdr-ce-marking",
    "title": "EU Medical Devices Regulation 2017/745 - CE Marking, Clinical Evaluation & Post-Market Surveillance",
    "domain": "Medical & Healthcare",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "EU MDR 2017/745 (fully applicable May 2021) replaces MDD/AIMDD with a risk-based classification system (Class I-III), mandatory clinical evaluation, post-market clinical follow-up, and EUDAMED registration for all medical devices placed on the EU market - manufacturers face up to EUR 100 million product liability exposure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-medical-devices-regulation-2017-745-mdr-conformity-assessment",
    "title": "EU Medical Devices Regulation 2017/745 (MDR) - Conformity Assessment and CE Marking",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-05-26",
    "bluf": "Regulation (EU) 2017/745 (MDR) replaced Directive 93/42/EEC from May 2021, establishing enhanced conformity assessment requirements for medical devices placed on the EU market. Higher-risk devices (Class IIa, IIb, Class III, implantables) require involvement of a Notified Body for CE marking. Manufacturers must implement a Quality Management System (ISO 13485), conduct clinical evaluations, establish post-market surveillance, and register in EUDAMED. Unique Device Identification (UDI) is mandatory for all classes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-2016-medical-devices-quality-management",
      "iso-14971-medical-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-medical-devices-regulation-mdr-2017-745-implementation",
    "title": "Regulation (EU) 2017/745 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The EU Medical Devices Regulation (MDR) 2017/745 establishes a comprehensive framework for the safety and performance of medical devices in the EU, requiring manufacturers to classify devices (Annex VIII), generate robust clinical evidence (Article 61), implement Post-Market Surveillance (Article 83), and register devices in EUDAMED (Article 29). It applies to all manufacturers, authorized representatives, importers, and distributors placing medical devices on the EU market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gmp-annex-1-sterile-manufacture-2022",
      "ich-q10-pharmaceutical-quality-system-2008",
      "fda-21-cfr-part-312-ind-investigational-new-drug",
      "fda-real-world-evidence-program-guidance-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-medicinal-products-directive-2001-83-ec",
    "title": "Directive 2001/83/EC of the European Parliament and of the Council of 6 November 2001 on the Community code relating to medicinal products for human use",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This Directive establishes the legal framework for the authorization, manufacturing, labelling, advertising, and pharmacovigilance of medicinal products for human use within the European Union. It applies to all entities placing medicinal products on the EU market and mandates compliance with requirements under Article 67, Article 46, and Annex I, among others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gmp-annex-1-sterile-manufacture-2022",
      "ich-q10-pharmaceutical-quality-system-2008",
      "fda-21-cfr-210-211-current-good-manufacturing-practice"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-medicinal-products-human-directive-2001-83",
    "title": "EU Medicinal Products for Human Use Directive 2001/83/EC",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2022-01-13",
    "bluf": "Directive 2001/83/EC, as the core EU pharmaceutical legislation, requires a marketing authorisation (MA) for all medicinal products for human use before they may be placed on the EU market, establishes Good Manufacturing Practice obligations, mandates pharmacovigilance including periodic safety update reports and risk management plans, and creates an 8+2+1 year data and market exclusivity framework for innovative medicines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-in-vitro-diagnostics-regulation-2017-746",
        "eu-medical-devices-regulation-2017-745",
        "eu-corporate-sustainability-reporting-directive-2022-2464"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-in-vitro-diagnostics-regulation-2017-746",
      "eu-medical-devices-regulation-2017-745",
      "eu-corporate-sustainability-reporting-directive-2022-2464"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-medium-combustion-plants-emissions-directive-2015-2193",
    "title": "Directive (EU) 2015/2193 of the European Parliament and of the Council of 25 November 2015 on the limitation of emissions of certain pollutants into the air from medium combustion plants",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive controls emissions of sulphur dioxide, nitrogen oxides and dust into the air from medium combustion plants, defined as plants with a rated thermal input equal to or greater than 1 MW and less than 50 MW (Articles 1, 2 and 3). It sets aggregation rules for combinations of plants (Article 4), requires medium combustion plants to be permitted or registered (Article 5), imposes emission limit values (Article 6) and operator obligations including monitoring (Article 7), requires compliance checks (Article 8), and governs changes to plants (Article 9), competent authorities (Article 10) and reporting (Article 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-industrial-emissions-directive-2010-75-eu",
      "eu-ets-directive-2003-87-emissions-trading-scheme"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-merger-regulation-139-2004",
    "title": "Council Regulation (EC) No 139/2004 on the control of concentrations between undertakings",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the EU-wide merger control regime requiring mandatory pre-notification of concentrations that meet specified turnover thresholds under Article 4. The European Commission assesses whether such mergers significantly impede effective competition, particularly through the creation or strengthening of a dominant position, under Article 7(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icn-recommended-practices-merger-notification-2023",
      "uk-cma-merger-assessment-guidelines-2021",
      "eu-state-aid-articles-107-108-tfeu-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-merger-regulation-139-2004-ec-european-commission",
    "title": "EU Merger Regulation 139/2004/EC - European Commission Competition Review",
    "domain": "Competition & Antitrust",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Council Regulation (EC) No 139/2004 (EU Merger Regulation, EUMR) requires mandatory pre-merger notification to the European Commission for concentrations with EU dimension (combined worldwide turnover EUR 5 billion+; Community-wide turnover of each of at least two parties EUR 250 million+); standstill obligation applies until clearance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-merger-regulation-139-2004-ec-thresholds",
    "title": "Council Regulation (EC) No 139/2004 on the control of concentrations between undertakings",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the EU-wide merger control regime requiring mandatory pre-notification to the European Commission for concentrations exceeding specified turnover thresholds under Article 1. It applies to all undertakings whose combined activities meet the EU-wide effect criterion and trigger jurisdiction under Article 1(2) and (3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icn-recommended-practices-merger-notification-2023",
      "uk-cma-merger-assessment-guidelines-2021",
      "eu-state-aid-articles-107-108-tfeu-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-merger-regulation-139-2004-ecmr",
    "title": "Council Regulation (EC) No 139/2004 of 20 January 2004 on the control of concentrations between undertakings (the EC Merger Regulation)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires undertakings to notify the European Commission of concentrations (mergers, acquisitions) that meet specific turnover thresholds, establishing a 'Community dimension' (Article 1). The Commission then assesses whether the concentration would significantly impede effective competition (SIEC) in the internal market, particularly by creating or strengthening a dominant position (Article 2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tfeu-article-102-abuse-of-dominance",
      "us-doj-ftc-merger-guidelines-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-merger-regulation-139-2004-filing-thresholds-procedure",
    "title": "EU Merger Regulation 139/2004 - Notification Thresholds, Phase I/II Procedure, and Remedies",
    "domain": "Competition & Antitrust",
    "version": "2.0.0",
    "last_updated": "2026-05-10",
    "bluf": "EU Council Regulation 139/2004 (ECMR) establishes the one-stop-shop EU merger control regime: concentrations with EU dimension must be notified to the European Commission before completion. EU dimension thresholds: (1) combined worldwide turnover above EUR 5 billion AND each of at least two parties has EU-wide turnover above EUR 250 million (unless each party generates more than two-thirds of its EU turnover in the same member state); OR (2) combined worldwide turnover above EUR 2.5 billion AND combined turnover in each of at least three member states above EUR 100 million AND in each of those three member states each of at least two parties has turnover above EUR 25 million AND EU-wide turnover of at least two parties exceeds EUR 100 million. Phase I (25 working days) results in clearance, conditional clearance, or Phase II referral. Phase II (90 working days, extendable to 125) culminates in clearance, conditional clearance, or prohibition. The 2023 Merger Filing Fee Regulation introduced mandatory filing fees for the first time.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-merger-regulation-139-2004",
      "eu-tfeu-article-102-abuse-of-dominance"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-methane-regulation-2024-1787",
    "title": "EU Methane Regulation 2024/1787 - Fossil Fuel Methane Emission Monitoring and Reduction",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Regulation (EU) 2024/1787 on the reduction of methane emissions in the energy sector requires operators of oil, gas, and coal facilities in the EU to conduct mandatory leak detection and repair (LDAR) surveys, measure and report methane emissions, and prohibit routine venting and flaring. Quarterly LDAR surveys are required at well sites and other gathering facilities; component-level surveys at least annually. Detected leaks must be repaired within 5 days for large leaks. Importers of fossil fuels into the EU must verify that exporting country operators meet equivalent standards from 2030.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ets_methane",
        "eu_fit_for_55",
        "iea_methane_tracker",
        "eu_energy_union_governance",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ets-directive-2003-87-emissions-trading-scheme",
      "eu-energy-union-governance-regulation-2018-1999",
      "eu-renewable-energy-directive-2023-2413-red-iii"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-methane-regulation-2024-1787-energy-sector",
    "title": "EU Methane Regulation 2024/1787 - Energy Sector Methane Emissions Reduction, LDAR Surveys and Import Standards",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "Regulation (EU) 2024/1787 of the European Parliament and of the Council of 13 June 2024 on the reduction of methane emissions in the energy sector and amending Regulation (EU) 2019/942 (Methane Regulation) is the EU's first dedicated legislation to reduce methane emissions across the oil, gas and coal sectors. The Regulation entered into force on 4 August 2024 with progressive obligations applying from 2025 onwards. Article 4 requires operators to submit verified annual reports on methane emissions at source level using Tier 3 methodology (direct measurement) by 2027. Article 14 prohibits routine venting and flaring except under specific operational and safety circumstances enumerated in Article 17. Articles 12-13 require Leak Detection and Repair (LDAR) surveys at progressively shorter intervals: Type 1 LDAR (basic) every 12 months from 5 August 2025, Type 2 LDAR (advanced) every 24 months; major equipment intervals reduced over time. Article 28 (the critical import provisions) requires from 1 January 2027 that importers of oil, gas and coal demonstrate equivalent measurement, reporting and verification (MRV) standards in producer countries, and from 1 January 2030 also equivalent reduction efforts with maximum methane intensity values. Article 31 establishes the EU Methane Transparency Database hosted by the European Commission JRC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-renewable-energy-directive-iii-2023-2413",
      "eu-cbam-2023-956-carbon-border-adjustment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-methane-regulation-energy-2024-1787",
    "title": "Regulation (EU) 2024/1787 of the European Parliament and of the Council of 13 June 2024 on methane emissions reduction in the energy sector and amending Regulation (EU) 2019/942",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-06-13",
    "bluf": "This regulation imposes strict rules on the EU energy sector (oil, gas, and coal) for measuring, reporting, and verifying methane emissions. It mandates comprehensive Leak Detection and Repair (LDAR) programmes (Article 14) and introduces stringent limits and eventual prohibitions on routine venting and flaring (Article 15).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mica-2023-1114-article-16-obligations-issuers-asset-referenced-tokens",
    "title": "Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA) - Article 16: Authorisation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article prohibits any person from offering an asset-referenced token to the public or seeking its admission to trading within the EU unless they are the authorized issuer of that token.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mica-2023-1114-article-35-issuers-e-money-tokens-obligations",
    "title": "REGULATION (EU) 2023/1114 on markets in crypto-assets - Article 35: Governance arrangements",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires issuers of e-money tokens to establish and maintain robust governance arrangements, including a clear organizational structure, risk management processes, internal controls, and specific policies for business continuity and information security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mica-2023-1114-article-45-obligations-crypto-asset-service-providers",
    "title": "REGULATION (EU) 2023/1114 on markets in crypto-assets - Article 45: General obligations for crypto-asset service providers",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article establishes the general obligations for crypto-asset service providers to act honestly, fairly, and professionally in the best interests of their clients, and to maintain effective organizational and governance arrangements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-mica-2023-1114-article-70-market-abuse-crypto-assets",
    "title": "REGULATION (EU) 2023/1114 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 31 May 2023 on markets in crypto-assets - Article 70: Prevention and detection of market abuse",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires any person professionally arranging or executing transactions in crypto-assets to establish, maintain, and apply effective arrangements, systems, and procedures to prevent, detect, and report suspected market abuse to the competent authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mica-asset-referenced-tokens",
    "title": "EU MiCA Title III - Asset-Referenced Token (ART) Issuance and Supervision (Regulation 2023/1114)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This regulation requires issuers of Asset-Referenced Tokens (ARTs) offered to the public or seeking admission to trading in the EU to be an authorized legal entity, publish a crypto-asset white paper approved by a competent authority, and maintain a fully segregated reserve of assets backing the token's value, as mandated by Articles 16, 17, and 36.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mica-stablecoin-reserve",
      "crypto-aml-travel-rule"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-mica-casp-obligations",
    "title": "EU MiCA Title V: Authorisation and Operating Conditions for Crypto-Asset Service Providers (CASPs)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-06-30",
    "bluf": "Title V of EU Regulation 2023/1114 (MiCA) mandates that any entity providing crypto-asset services in the EU must obtain authorization as a Crypto-Asset Service Provider (CASP) and comply with stringent prudential, governance, and operational requirements, including rules on conflicts of interest, custody, and client protection, as detailed in Articles 59 through 85.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mica-casp-third-country-equivalence-2025",
    "title": "Regulation (EU) on Markets in Crypto-Assets (MiCA) - Third-Country Crypto-Asset Service Providers (CASP) Equivalence Framework: Reverse Solicitation, ESMA Equivalence Register, and Prohibition on Passporting Rights for Non-EU CASPs",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes the conditions under which third-country Crypto-Asset Service Providers (CASP) may provide services in the EU solely on the initiative of professional clients or eligible counterparties (reverse solicitation), without passporting rights. It requires ESMA to maintain an equivalence register under Article 77 of MiCA and prohibits circumvention through indirect access to EU markets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dlt-pilot-regime-2022-858",
      "eu-eba-mica-guidelines-art-emt-authorisation",
      "crypto-aml-travel-rule"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mica-e-money-tokens",
    "title": "Regulation (EU) 2023/1114 Title IV - Electronic Money Tokens (EMT)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Title IV of the EU's Markets in Crypto-Assets (MiCA) regulation mandates that issuers of e-money tokens (EMTs) must be authorized as a credit institution or an electronic money institution. Per Articles 48 and 55, they must issue EMTs at par value upon receipt of funds and guarantee holders the right to redeem their tokens at any moment and at par value.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mica-stablecoin-reserve",
      "crypto-aml-travel-rule"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mica-regulation-2023",
    "title": "Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The EU Markets in Crypto-Assets Regulation (MiCA) establishes a harmonized framework for crypto-asset issuers and service providers (CASPs) in the EU, requiring authorization, transparency, and consumer protection measures. As per Article 4, crypto-assets other than asset-referenced or e-money tokens generally require a published and notified crypto-asset white paper before being offered to the public or admitted to trading.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-mica-rts-casp-authorisation-2025-305",
    "title": "Commission Delegated Regulation (EU) 2025/305 - MiCA Regulatory Technical Standards on the information to be included in an application for authorisation as a crypto-asset service provider",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This Commission Delegated Regulation specifies the information that an applicant must include in an application for authorisation as a crypto-asset service provider (CASP) under the Markets in Crypto-Assets Regulation (MiCA), Regulation (EU) 2023/1114. Applications must set out the applicant's identifying details, the list of crypto-asset services and the types of crypto-assets concerned, the amount and calculation of prudential safeguards, staff awareness arrangements, a tested business continuity plan, a sound and well-documented ICT risk management framework, and best-execution factors. The RTS standardises authorisation dossiers so competent authorities can assess CASP applicants consistently.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-micar-crypto-gaming-platforms-2023",
      "eu-dora-regulation-2022-2554-digital-operational-resilience-financial-sector",
      "eu-dora-2022-2554-article-28-ict-third-party-risk-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-mica-rts-continuity-crypto-services-2025-299",
    "title": "Commission Delegated Regulation (EU) 2025/299 supplementing Regulation (EU) 2023/1114 with regard to regulatory technical standards on continuity and regularity in the performance of crypto-asset services",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This MiCA regulatory technical standard requires crypto-asset service providers to maintain a business continuity policy endorsed and annually reviewed by the management body, business continuity plans that protect client data and define recovery deadlines and maximum resumption times, annual scenario-based testing, and a self-assessment proportionate to the scale and range of services; it supplements MiCA Article 68.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-markets-crypto-assets-regulation-2023-1114",
      "eu-mica-2023-1114-article-45-obligations-crypto-asset-service-providers",
      "dora-ict-risk-management-articles-5-16"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mica-rts-liquidity-management-2025-1264",
    "title": "Commission Delegated Regulation (EU) 2025/1264 of 27 June 2025 supplementing Regulation (EU) 2023/1114 with regard to regulatory technical standards specifying the minimum contents of the liquidity management policy and procedures for certain issuers of asset-referenced tokens and e-money tokens",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "This MiCA regulatory technical standard sets the minimum contents of the liquidity management policy for in-scope issuers of asset-referenced tokens and e-money tokens, requiring adequate reserve-asset levels for redemptions under normal and stress conditions, liquidity stress testing with a reverse stress test element, custodian concentration limits, and calibrated early-warning signals; it supplements Article 45(7) of Regulation (EU) 2023/1114.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-markets-crypto-assets-regulation-2023-1114",
      "eu-mica-2023-1114-article-16-obligations-issuers-asset-referenced-tokens",
      "eu-esma-mica-rts-technical-standards-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mica-title-i-ii-crypto-asset-categories",
    "title": "Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets - Titles I & II: Subject Matter, Scope, Definitions, and Public Offerings of Non-ART/EMT Crypto-Assets",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-06-30",
    "bluf": "This regulation defines categories of crypto-assets and establishes rules for their public offering within the EU. It mandates that issuers of crypto-assets (other than asset-referenced or e-money tokens) must publish and notify a detailed crypto-asset white paper to their National Competent Authority (NCA) at least 20 working days before publication, as stipulated in Article 8, unless a specific exemption under Article 4 applies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mica-regulation-2023",
      "eu-mica-asset-referenced-tokens",
      "eu-mica-e-money-tokens",
      "eu-mica-casp-obligations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mica-title-iii-asset-referenced-tokens",
    "title": "Regulation (EU) 2023/1114 Title III - Authorisation and Operating Conditions of Issuers of Asset-Referenced Tokens",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Title III of the EU's Markets in Crypto-Assets (MiCA) regulation requires issuers of Asset-Referenced Tokens (ARTs) to be authorized legal entities within the EU, publish a compliant crypto-asset white paper, and maintain own funds of at least 2% of the average value of their reserve assets, as stipulated in Article 35. The regulation also imposes strict governance, reserve asset management, custody, and redemption right obligations, with significant ARTs subject to direct EBA supervision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mica-regulation-2023",
      "eu-mica-casp-obligations",
      "eu-tfer-regulation-2023",
      "bis-crypto-asset-prudential-standards"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-mica-title-iv-e-money-tokens",
    "title": "Regulation (EU) 2023/1114 Title IV - Electronic Money Tokens (EMT)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Title IV of the EU's Markets in Crypto-Assets (MiCA) Regulation, issuers of e-money tokens (EMTs) must be authorized as either a credit institution or an electronic money institution. EMTs must be redeemable at par value on demand and be fully backed 1:1 by a reserve of assets denominated in a single official EU member state currency, with specific rules for custody and segregation of these reserves (Articles 48 & 54).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mica-regulation-2023",
      "eu-mica-casp-obligations",
      "eu-tfer-regulation-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mica-title-v-crypto-asset-service-providers",
    "title": "Regulation (EU) 2023/1114 Title V: Authorisation and Operating Conditions for Crypto-Asset Service Providers (CASPs)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires any entity providing crypto-asset services (CASPs) in the EU to obtain authorization from a national competent authority (NCA). As per Articles 67 and 68, CASPs must implement robust governance, prudential safeguards, segregate client assets, maintain effective custody policies, and establish transparent complaints-handling procedures, with all authorized providers listed in a public register maintained by ESMA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mica-regulation-2023",
      "crypto-aml-travel-rule",
      "eu-tfer-regulation-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mica-title-vi-market-abuse-crypto",
    "title": "Regulation (EU) 2023/1114 Title VI: Prevention and Prohibition of Market Abuse Involving Crypto-Assets",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes a framework to prevent and prohibit market abuse in crypto-asset markets within the EU, specifically targeting insider dealing, unlawful disclosure of inside information, and market manipulation. As outlined in Articles 89, 90, and 91, these prohibitions apply to any person involved in any transaction, order, or behavior concerning crypto-assets admitted to trading or for which a request for admission to trading has been made.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mica-regulation-2023",
      "eu-mica-casp-obligations"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-micar-crypto-gaming-platforms-2023",
    "title": "Regulation (EU) 2023/1114 of the European Parliament and of the Council on markets in crypto‑assets (MiCA)",
    "domain": "Gaming & Gambling",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Recital (6) of Regulation (EU) 2023/1114 establishes a Union‑wide framework that obliges issuers of crypto‑assets - including in‑game tokens and NFTs offered by gaming platforms - to publish a white paper and requires crypto‑asset service providers to obtain authorisation, thereby applying directly to gaming economies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "fatf-guidance-rba-gambling-2021",
      "alderney-egambling-regulations-2009"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mifid-ii-delegated-regulation-2017-589-algo-trading",
    "title": "EU MiFID II Delegated Regulation (EU) 2017/589 (RTS 6) - Organisational Requirements for Investment Firms Engaged in Algorithmic Trading",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Investment firms and trading venues engaging in algorithmic trading must implement a full lifecycle governance framework under RTS 6: pre-deployment testing (conformance, integration, stress), production risk controls (price collars, volume limits, kill functionality), annual self-assessment, market making agreements where applicable, and immediate competent authority notification. Kill functionality enabling immediate order cancellation is mandatory. Records of all algorithmic strategies must be retained for five years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-govern-function",
      "eu-nis2-directive-2022-2555"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mifid-ii-directive-2014-65-investment-firm-conduct-obligations",
    "title": "EU MiFID II Directive 2014/65 - Investment Firm Conduct of Business and Client Protection Obligations",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive 2014/65/EU (MiFID II) and Regulation (EU) 600/2014 (MiFIR) establish the regulatory framework for investment firms providing investment services in the EU. Key obligations include client categorisation (retail/professional/eligible counterparty), suitability and appropriateness assessments, best execution, transaction reporting, and product governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-emir-regulation-648-2012-otc-derivatives-clearing-reporting"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mifid2-2014-65-article-16-organisational-requirements-investment-firms",
    "title": "Directive 2014/65/EU on markets in financial instruments (MiFID II) Article 16: Organisational requirements",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires investment firms to establish and maintain robust organisational, administrative, and governance arrangements to ensure compliance with regulations, manage conflicts of interest, and safeguard client assets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mifid2-2014-65-article-24-general-principles-client-protection",
    "title": "DIRECTIVE 2014/65/EU on markets in financial instruments, Article 24: General principles and information to clients",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires investment firms to act honestly, fairly, and professionally in accordance with the best interests of their clients, ensuring all information provided is fair, clear, and not misleading.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mifid2-2014-65-article-25-assessment-suitability-appropriateness",
    "title": "Directive 2014/65/EU on markets in financial instruments (MiFID II), Article 25: Assessment of suitability and appropriateness and reporting to clients",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires investment firms to assess the suitability or appropriateness of financial instruments and services for their clients, based on the client's knowledge, experience, financial situation, and objectives, and to provide adequate reports.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mifid2-2014-65-article-27-best-execution-client-orders",
    "title": "Directive 2014/65/EU on markets in financial instruments (MiFID II), Article 27: Obligation to execute orders on terms most favourable to the client",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Investment firms must take all sufficient steps to obtain the best possible result for their clients when executing orders, considering factors like price, costs, speed, and likelihood of execution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mifid2-directive-article-17-algorithmic-trading-requirements",
    "title": "Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments, Article 17: Algorithmic trading",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Investment firms engaging in algorithmic trading must implement effective systems, risk controls, and business continuity arrangements to ensure system resilience, prevent disorderly markets, and comply with regulatory notifications and record-keeping.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mifid2-directive-article-23-conflicts-of-interest-investment-firms",
    "title": "Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments (MiFID II), Article 23: Conflicts of interest",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Investment firms must take all appropriate steps to identify, prevent, or manage conflicts of interest, and where these measures are insufficient, they must disclose the nature and sources of such conflicts to clients before undertaking business.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mifid2-directive-article-24-conduct-of-business-obligations-clients",
    "title": "Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments (MiFID II), Article 24: General principles and information to clients",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires investment firms to act honestly, fairly, and professionally in the best interests of their clients, providing clear information on services, instruments, costs, and risks, and assessing the suitability or appropriateness of investments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mifid2-directive-article-28-systematic-internalisers-quoting-obligations",
    "title": "Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments - Article 28: Obligation for systematic internalisers to make public firm quotes",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires investment firms acting as systematic internalisers to make public firm quotes for liquid shares up to a standard market size and to execute client orders at those quoted prices under specified conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mifid2-directive-article-36-authorisation-regulated-markets",
    "title": "Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments, Article 36: Authorisation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article establishes the core requirements for obtaining and maintaining authorisation as a regulated market, focusing on the legal status, organisational structure, risk management, and fitness of the market operator and its management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mineral-water-directive-2009-54-natural-spring",
    "title": "Directive 2009/54/EC of the European Parliament and of the Council of 18 June 2009 on the exploitation and marketing of natural mineral waters",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive establishes the criteria for recognizing natural mineral waters, including their origin, composition stability, and permitted treatments. It applies to all operators exploiting and marketing natural mineral waters in the EU, requiring compliance with microbiological standards, labelling rules, and protection of source integrity under Article 4 and Annex I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-hygiene-regulation-852-2004",
      "eu-food-labelling-regulation-1169-2011",
      "codex-alimentarius-general-principles-hygiene-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-minimum-tax-directive-2022-2523-pillar2",
    "title": "Council Directive (EU) 2022/2523 of 14 December 2022 on ensuring a global minimum level of taxation for multinational enterprise groups and large-scale domestic groups in the Union",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Directive establishes a global minimum tax regime requiring multinational enterprise (MNE) groups and large-scale domestic groups with consolidated revenue of at least EUR 750 000 000 to pay a minimum effective tax rate of 15% in each jurisdiction where they operate, applying the Income Inclusion Rule (IIR) and Undertaxed Profit Rule (UTPR) as set out in Article 3 and Article 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-dac7-digital-platform-reporting-2021-514",
      "eu-public-cbcr-directive-2021-2101-tax-transparency"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-minimum-wage-directive-2022-2041",
    "title": "Directive (EU) 2022/2041 of the European Parliament and of the Council of 19 October 2022 on adequate minimum wages in the European Union and amending Regulation (EU) 2019/1150",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The EU Adequate Minimum Wages Directive 2022/2041 requires Member States to ensure that statutory or collectively agreed minimum wages are adequate and allow for a decent standard of living, with biennial reviews and targets to increase collective bargaining coverage to at least 80% by 2029. Applies to all Member States and employers setting wages within EU jurisdictions, per Article 3(1) and Article 7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-fair-work-act-2009",
      "difc-employment-law-4-2021",
      "eeoc-employment-rule"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mining-waste-directive-2006-21",
    "title": "EU Mining Waste Directive 2006/21/EC - Extractive Industry Waste Facility Management and Financial Security",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Directive 2006/21/EC of the European Parliament and of the Council on the management of waste from extractive industries establishes requirements for waste facilities at mining, quarrying, and mineral processing operations in the EU. The Directive requires a waste management plan for each extractive industry operation. Waste facilities are classified as Category A (where failure could cause major accident), non-Category A, or inert waste. Category A facilities require an emergency plan and a financial guarantee (financial security) adequate to restore the site after closure. The competent authority must inspect facilities at least annually for Category A sites and every three years for others. The Directive was the EU legislative response to the 1998 Aznalcollar dam failure in Spain and the 2000 Baia Mare gold mine cyanide spill in Romania. The characterisation of waste (Annex II) and the water management requirements (Annex III) are core technical standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_smcra_1977",
        "eu_water_framework_directive_2000_60",
        "eu_seveso_iii_directive_2012_18",
        "eu_environmental_liability_directive_2004_35",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-services-directive-2006-123"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mining-waste-directive-2006-21-ec",
    "title": "Directive 2006/21/EC of the European Parliament and of the Council on the management of waste from extractive industries and amending Directive 2004/35/EC",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Directive requires that waste from land‑based extractive industries be managed to prevent adverse effects on the environment and human health, mandating waste characterisation, permitting, financial guarantees and closure plans for facilities handling such waste (Recital (1)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-mining-sustainable-activities",
      "eiti-standard-2023",
      "eu-conflict-minerals-regulation-2017-821"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mobility-package-i-road-transport-2020",
    "title": "EU Mobility Package I (Regulations 2020/1054, 2020/1055, 2020/1056) - Cabotage, Driving Time and eCMR",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Mobility Package I, comprising Regulations (EU) 2020/1054 (driving time and tachograph), 2020/1055 (access to market for road transport) and 2020/1056 (electronic consignment notes - eCMR), entered into force from February 2022; limits cabotage to 3 operations within 7 days after an international delivery with a 4-day cooling-off period; requires drivers to return home within 4 weeks; mandates smart tachographs in all new vehicles from 2023 and retrofitting in older vehicles; and introduces mandatory electronic CMR consignment notes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cmr-convention-1956-road-carriage-goods"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-modernisation-directive-consumer-law-2019",
    "title": "Directive (EU) 2019/2161 of the European Parliament and of the Council of 27 November 2019 amending Council Directive 93/13/EEC and Directives 98/6/EC, 2005/29/EC and 2011/83/EU of the European Parliament and of the Council as regards the better enforcement and modernisation of Union consumer protection rules (Text with EEA relevance)",
    "domain": "Operations & CX",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Directive amends key EU consumer protection directives to strengthen enforcement, requiring Member States to impose effective, proportionate and dissuasive penalties for widespread or cross-border infringements of consumer law, particularly under Directives 98/6/EC, 2005/29/EC, 2011/83/EU and Council Directive 93/13/EEC. It introduces common criteria for penalty imposition, including the nature, gravity, scale and duration of the infringement, as per Article 7 of the Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-directive",
      "eu-consumer-rights-directive-2011",
      "eu-geo-blocking-regulation-2018",
      "eu-adr-consumer-disputes-2013"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-money-market-funds-regulation-2017-1131",
    "title": "EU Money Market Funds Regulation 2017/1131/EU (MMFR)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2018-07-21",
    "bluf": "Regulation (EU) 2017/1131 (MMFR) establishes a harmonised EU framework for money market funds (MMFs) - prescribing four authorised MMF types (VNAV, LVNAV, Public Debt CNAV, Standard VNAV), portfolio maturity limits (WAM ≤60 days, WAL ≤120 days for short-term MMFs), liquidity buffers (daily: 7.5%; weekly: 15%), stress testing, and transparency reporting to ESMA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ucits-directive-2009-65",
      "eu-emir-regulation-648-2012",
      "eu-csdr-regulation-909-2014"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mortgage-credit-directive-2014-17-real-estate",
    "title": "Directive 2014/17/EU of the European Parliament and of the Council of 4 February 2014 on credit agreements for consumers relating to residential immovable property and amending Directives 2008/48/EC and 2013/36/EU and Regulation (EU) No 1093/2010",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive establishes harmonised rules for creditworthiness assessment, pre-contractual information (ESIS), early repayment rights, and arrears management for consumer mortgage credit agreements related to residential real estate across EU Member States. It applies to lenders, intermediaries, and credit providers under Article 5 and Article 22.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-circular-economy-construction-demolition-waste-2020",
      "iso-19650-bim-information-management-construction",
      "eu-construction-sector-emissions-buildings-renovation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-motor-insurance-directive-2009-103-revised",
    "title": "Directive 2009/103/EC of the European Parliament and of the Council of 16 September 2009 relating to insurance against civil liability in respect of the use of motor vehicles, and the enforcement of the obligation to insure against such liability, as amended by Directive (EU) 2021/2118",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Directive mandates compulsory third-party liability insurance for all motor vehicles based in the EU, ensuring minimum coverage amounts and establishing mechanisms to protect victims in cases of accidents or insurer insolvency, as outlined in Article 3. The 2021 revision clarifies rules for automated vehicles, cross-border claims, and insurer insolvency protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-motor-insurance-directive-2021-2118-revision",
    "title": "Directive (EU) 2021/2118 of the European Parliament and of the Council of 24 November 2021 amending Directive 2009/103/EC relating to insurance against civil liability in respect of the use of motor vehicles, and the enforcement of the obligation to insure against such liability",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This directive amends the EU Motor Insurance framework to enhance protection for victims of traffic accidents, particularly in cases of insurer insolvency, by establishing harmonized compensation mechanisms and minimum coverage amounts. It requires Member States to set up or authorise a body to compensate injured parties resident within their territory if an insurance undertaking becomes insolvent (Article 10a).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-motor-insurance-sixth-directive-2021-2118",
    "title": "Directive (EU) 2021/2118 of the European Parliament and of the Council of 2 December 2021 on the approximation of the laws of the Member States relating to insurance against civil liability in respect of the use of motor vehicles and the enforcement of the obligation to insure such liability",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Directive establishes minimum insurance coverage amounts for civil liability arising from motor vehicle use, mandates coverage for electric vehicle battery fire risks, requires Member States to establish Insurers of Last Resort Guarantee Bodies, implements the Motor Insurance Information Centre (MIIC) for cross-border data exchange, and ensures passenger coverage and compensation mechanisms for victims of accidents involving uninsured drivers. Key obligations are set out in Articles 3, 4, 5, 7, and 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-commission-implementing-regulation-2015-2452-solvency",
      "eu-delegated-regulation-2016-2067-spread-market-risk",
      "eu-eiopa-guidelines-orsa-2015",
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-motor-vehicle-block-exemption-regulation-2023",
    "title": "Commission Regulation (EU) 2023/822 of 21 March 2023 on the application of Article 101(3) of the Treaty on the Functioning of the European Union to categories of vertical agreements and concerted practices in the motor vehicle sector",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a block exemption for vertical agreements in the motor vehicle aftermarket, ensuring independent repairers and spare parts manufacturers have fair access to technical information, tools, and original spare parts. It applies to agreements between vehicle manufacturers, dealers, authorised repairers, and parts suppliers, with key obligations under Article 4 (technical information access), Article 5 (spare parts rights), and Article 6 (warranty clause restrictions).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "uk-competition-act-1998-chapter-1-2-prohibitions",
      "india-competition-act-2002-sections-3-4",
      "canada-competition-act-2024-amendment-abuse-dominance",
      "icn-recommended-practices-merger-notification-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-motor-vehicle-block-exemption-regulation-2023-1080",
    "title": "Commission Regulation (EU) No 461/2010 of 27 May 2010 on the application of Article 101(3) of the Treaty on the Functioning of the European Union to categories of vertical agreements and concerted practices in the motor vehicle sector, as extended to 31 May 2028 by Commission Regulation (EU) 2023/822",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "This regulation establishes a block exemption for vertical agreements in the motor vehicle sector, including selective distribution and repair & maintenance networks, provided they do not contain hardcore restrictions under Article 4 and meet market share thresholds in Article 7. It applies to agreements between vehicle manufacturers, dealers, repairers, and spare parts suppliers operating within the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "uk-cma-merger-assessment-guidelines-2021",
      "india-competition-act-2002-sections-3-4",
      "australia-competition-consumer-act-2010-part-iv",
      "uk-competition-act-1998-chapter-1-2-prohibitions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-motor-vehicle-block-exemption-regulation-461",
    "title": "Commission Regulation (EU) No 461/2010 of 27 May 2010 on the application of Article 101(3) of the Treaty on the Functioning of the European Union to categories of vertical agreements and concerted practices in the motor vehicle sector",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Regulation (EU) No 461/2010 establishes competition rules for the EU motor vehicle aftermarket, ensuring independent operators have fair access to spare parts, technical information, and repair tools. It applies to vertical agreements between vehicle manufacturers, dealers, and repairers, with key obligations under Articles 2, 3, and 4 regarding parts equivalence, information access, and non-discrimination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mrv-regulation-2015-757-maritime-ghg-monitoring",
    "title": "EU MRV Regulation 2015/757 - Maritime CO2 Emissions Monitoring, Reporting and Verification Framework",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Regulation (EU) 2015/757 (MRV Regulation) requires ships of 5,000 GT and above calling at EU/EEA ports to monitor and report CO2 emissions, fuel consumption, distance travelled, and cargo carried on a per-voyage and per-year basis; annual emissions reports must be verified by an accredited verifier before 30 April each year; ships must hold a Document of Compliance (DoC) issued by the flag state; the MRV framework feeds data into the EU ETS for maritime (from 2024) and aligns with IMO CII and Data Collection System requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-marpol-annex-vi-air-pollution",
      "imo-cii-carbon-intensity-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mrv-shipping-regulation-article-11-annual-reporting-obligations",
    "title": "Regulation (EU) 2015/757 of the European Parliament and of the Council - Article 11: Content of the emissions report",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Companies must annually submit a verified emissions report for each ship by 30 April, containing specific ship and company data, monitoring method information, and annual monitoring results.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mrv-shipping-regulation-article-13-verification-by-accredited-verifier",
    "title": "Regulation (EU) 2015/757 Article 13: Scope of verification activities and verification report",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must have their monitoring plan and emissions report assessed by a verifier, correct any identified non-conformities, and obtain a satisfactory verification report.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-mrv-shipping-regulation-article-19-document-of-compliance",
    "title": "Regulation (EU) 2015/757 on the monitoring, reporting and verification of carbon dioxide emissions from maritime transport, Article 19",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Member States must ensure ships flying their flag comply with monitoring and reporting requirements, using the Document of Compliance as evidence, and must check for this document during port inspections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mrv-shipping-regulation-article-20-enforcement",
    "title": "Regulation (EU) 2015/757 on the monitoring, reporting and verification of carbon dioxide emissions from maritime transport - Article 20",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates Member States to establish and enforce a system of penalties, including potential expulsion orders, for ships failing to comply with monitoring and reporting obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mrv-shipping-regulation-article-3-definitions",
    "title": "Regulation (EU) 2015/757 of the European Parliament and of the Council - Article 3 Definitions",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article establishes the official definition of 'CO2 emissions' as the release of CO2 into the atmosphere by ships, which must be used for all purposes of this Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-mrv-shipping-regulation-article-5-monitoring-methodology",
    "title": "Regulation (EU) 2015/757 on the monitoring, reporting and verification of carbon dioxide emissions from maritime transport - Article 5: Methods for monitoring CO2 emissions and other relevant information",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Companies must determine CO2 emissions for each of their ships using one of the methods specified in Annex I and monitor other relevant information according to the rules in Annex II.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-mrv-shipping-regulation-article-8-monitoring-plan",
    "title": "Regulation (EU) 2015/757 of the European Parliament and of the Council - Article 8: Monitoring of activities within a reporting period",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Companies must monitor CO2 emissions for each ship on both a per-voyage and annual basis, using an assessed monitoring plan and specified methods from Annex I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-natural-catastrophe-insurance-framework-2024",
    "title": "EU Natural Catastrophe Insurance Protection Gap - Climate Resilience Dialogue Final Report (July 2024) and EIOPA-ECB Work (non-binding)",
    "domain": "Insurance & Risk",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "There is no discrete European Commission instrument titled the 'EU Natural Catastrophe Insurance Gap Framework' with binding numbered Sections 3.1 to 3.7. The actual material is the Climate Resilience Dialogue Final Report (published 30 July 2024), a non-binding report structured in chapters, supported by the joint EIOPA-ECB work on insuring climate catastrophes. These provide non-binding recommendations for EU Member States and insurers to close the natural catastrophe (NatCat) insurance protection gap through risk prevention, better data and modelling, risk-adequate pricing, public-private partnerships and use of the single market. The seven themes referenced as 'Section 3.x' in this node correspond to the recommendation areas of the Climate Resilience Dialogue Final Report, not to numbered binding provisions of an EC legal act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "iso-14090-climate-adapt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-nature-restoration-law-2024-1991-article-11-national-restoration-plans",
    "title": "EU Nature Restoration Law (EU) 2024/1991 - Article 11: National Restoration Plans - Content and Submission Requirements",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 11 of the EU Nature Restoration Law (Regulation 2024/1991) requires EU member states to prepare and submit National Restoration Plans (NRPs) to the European Commission by 1 September 2026. The NRP is the primary planning and accountability instrument through which member states commit to achieving the specific restoration targets in Articles 4-10. Each NRP must include: a comprehensive assessment of the current condition of habitats and species, quantified restoration measures for each Article target, a financing plan, a monitoring methodology, stakeholder consultation documentation, and a conflict management plan where restoration objectives interact with economic activities. Plans cover the period to 2050 and must be revised every 10 years. The Commission assesses NRP adequacy within 18 months of submission. Inadequate plans trigger a recommendation procedure. The NRP is the document against which member states' compliance with the EU's first legally binding nature restoration regulation is assessed, making it central to both domestic regulatory compliance and EU enforcement proceedings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nature-restoration-law-2024-1991-article-4-restoration-targets-terrestrial",
      "eu-nature-restoration-law-2024-1991-article-6-urban-ecosystem-restoration"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-nature-restoration-law-2024-1991-article-4-restoration-targets-terrestrial",
    "title": "EU Nature Restoration Law (EU) 2024/1991 - Article 4: Restoration Targets for Terrestrial, Riparian and Freshwater Ecosystems",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 4 of the EU Nature Restoration Law (Regulation 2024/1991) sets legally binding restoration targets for terrestrial, riparian, and freshwater ecosystems listed in Annex I of the Habitats Directive (92/43/EEC). EU member states must put in place restoration measures on: at least 30% of Annex I habitat types in poor condition (each habitat type at national level) by 2030; at least 60% by 2040; and at least 90% by 2050. Additionally, member states must not deteriorate restored habitat areas. A non-deterioration obligation applies to all currently favourable habitats from the regulation's entry into force. The regulation covers grasslands, peatlands, heathlands, dunes, forests, river and lake habitats, and other Annex I ecosystem types. Member states have flexibility in selecting which specific areas receive restoration measures to meet the percentage targets, but must demonstrate measurable improvement using biodiversity indicators including bee populations, farmland bird indices, and riparian forest coverage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nature-restoration-law-2024-1991-article-11-national-restoration-plans",
      "eu-nature-restoration-law-2024-1991-article-6-urban-ecosystem-restoration"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-nature-restoration-law-2024-1991-article-6-urban-ecosystem-restoration",
    "title": "EU Nature Restoration Law (EU) 2024/1991 - Article 6: Restoration of Urban Ecosystems and Green Urban Space Targets",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 6 of the EU Nature Restoration Law (Regulation 2024/1991) establishes legally binding targets for the restoration and expansion of urban green spaces and urban ecosystems across EU cities and towns. Member states must ensure: (a) no net loss of urban green space in urban areas by 2030 compared to 2021; (b) a net gain in the total national urban green space area and in urban tree canopy cover in urban areas by 2040; (c) a net gain in urban green space integrated into buildings and infrastructure in urban areas by 2050; and (d) an increase in urban tree canopy cover of 3% by 2050 in each city and town. The article creates obligations on member states to measure, plan, and increase urban biodiversity through green infrastructure in cities. The targets apply to all EU urban areas (cities and towns as defined in DEGURBA methodology) and require member states to integrate urban green space expansion into spatial planning and building regulations. Article 6 is particularly relevant for construction, real estate, and urban planning sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nature-restoration-law-2024-1991-article-4-restoration-targets-terrestrial",
      "eu-nature-restoration-law-2024-1991-article-11-national-restoration-plans"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-nature-restoration-regulation-2024-1991",
    "title": "Regulation (EU) 2024/1991 - EU Nature Restoration Regulation: Legally Binding Ecosystem Restoration Targets, National Restoration Plans, Urban Green Space Obligations, Agricultural Biodiversity Indicators, and Free-Flowing River Restoration Requirements",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2024/1991 (Nature Restoration Regulation), entered into force 18 August 2024, establishes the EU's first legally binding nature restoration law; key obligations include: legally binding targets requiring Member States to restore habitats listed in Annexes I and II to good ecological condition - covering at least 30% of land and marine habitats not in good condition by 2030, 60% by 2040, and 90% by 2050; restoration of 25,000 km of rivers to free-flowing state by 2030 (Article 7); no deterioration obligation preventing backsliding of restored areas (Article 12); mandatory National Restoration Plans (NRPs) to be submitted to the Commission by 18 August 2026 (Article 14); agricultural ecosystem obligations including upward trends in the Farmland Bird Index, Grassland Butterfly Index, and High Diversity Landscape Features by 2030; urban green space and urban tree canopy cover requirements (Article 6); peatland rewetting targets for drained agricultural peatlands (Article 11); and six-yearly progress reports to the Commission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_TAXONOMY",
        "EU_CSRD",
        "EU_CAP",
        "EU_DEFORESTATION"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852",
      "eu-csrd-2022-2464",
      "eu-habitat-directive-construction-biodiversity",
      "eu-deforestation-regulation-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-net-neutrality-open-internet-2015-2120",
    "title": "Regulation (EU) 2015/2120 of the European Parliament and of the Council of 25 November 2015 laying down measures concerning open internet access and amending Directive 2002/22/EC on universal service and users’ rights relating to electronic communications networks and services and Regulation (EU) No 531/2012 on roaming on public mobile communications networks within the Union",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires providers of internet access services (IAS) in the EU to treat all traffic equally, without discrimination, restriction, or interference, regardless of sender, receiver, content, application, service, or terminal equipment. As mandated by Article 3, providers are prohibited from blocking, throttling, or engaging in paid prioritization of internet traffic, subject to limited and clearly defined exceptions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-net-neutrality-review-regulation-2015-2120-2025",
    "title": "Regulation (EU) 2015/2120 of the European Parliament and of the Council of 25 November 2015 laying down measures concerning open internet access and amending Directive 2002/22/EC on universal service and users’ rights relating to electronic communications networks and services and Regulation (EU) No 531/2012 on roaming on public mobile communications networks within the Union - 2025 Review Framework on Zero-Rating, Specialised Services, Satellite Broadband and BEREC Guidelines",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes the EU’s open internet framework, requiring internet service providers (ISPs) to treat all traffic equally, prohibiting blocking, throttling, and discrimination, while allowing reasonable traffic management under Article 3(3). The 2025 review assesses zero-rating practices, the evolution of specialised services, inclusion of satellite broadband, updated BEREC guidelines, and alignment with the Gigabit Infrastructure Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-net-neutrality-open-internet-2015-2120",
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-5g-cybersecurity-toolbox-2020",
      "3gpp-5g-nr-release-17-specifications",
      "eu-broadband-cost-reduction-directive-2014-61"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-net-zero-industry-act-2024-1735-clean-tech-manufacturing-targets",
    "title": "EU Net-Zero Industry Act (NZIA) 2024/1735 - Strategic Net-Zero Technology Manufacturing Targets and Streamlined Permitting",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Regulation (EU) 2024/1735 (Net-Zero Industry Act) aims to scale up EU manufacturing of strategic clean technologies (solar, wind, heat pumps, batteries, electrolyzers, CCS, biogas, grid infrastructure, sustainable fuels) to meet 40% of EU deployment needs domestically by 2030. Strategic net-zero projects receive streamlined permits within 18 months; renewable energy auctions must include non-price sustainability criteria up to 30% of score.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-critical-raw-materials-act-2024-1252"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-net-zero-industry-act-2024-manufacturing-capacity",
    "title": "Regulation (EU) 2024/1735: Establishing a framework of measures for strengthening Europe’s net-zero technology products manufacturing ecosystem (Net-Zero Industry Act)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The EU Net-Zero Industry Act establishes a benchmark for the Union's manufacturing capacity of strategic net-zero technologies, such as solar, wind, batteries, and heat pumps, to meet at least 40% of the Union's annual deployment needs for these technologies by 2030 (Article 1(2)). This applies to public and private entities involved in the manufacturing and deployment of these technologies within the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14090-climate-adapt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-network-code-cybersecurity-electricity-2024",
    "title": "Commission Regulation (EU) on sector-specific rules for cybersecurity aspects of cross-border electricity flows (Network Code on Cybersecurity)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-04-23",
    "bluf": "This regulation establishes a harmonized EU framework requiring entities involved in cross-border electricity flows to conduct comprehensive cybersecurity risk assessments for their critical assets, implement baseline security measures, and report significant incidents to competent authorities. The core obligation, outlined in Article 6, mandates a detailed risk assessment process to identify and mitigate cyber threats to the European electricity grid's stability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-161r1-csrm-practices",
      "iso-27031-dr-readiness"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-network-codes-electricity-operations",
    "title": "EU Network Codes for Electricity - ENTSO-E Grid Connection, Capacity Allocation, Balancing and Operational Security: Technical Requirements, Compliance Monitoring and TSO Obligations",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes binding technical and operational requirements for Transmission System Operators (TSOs) and connected entities across the EU electricity network, ensuring secure, interoperable, and efficient cross-border electricity operations under the Network Code on Electricity System Operations and the Network Code on Electricity Balancing. Key obligations are defined in Articles of the respective Network Codes, including compliance with emergency restoration procedures and balancing capacity allocation rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cyber-resilience-act-iot-2024-products",
      "etsi-en-303-645-iot-cybersecurity-2020",
      "eu-data-act-2023-iot-data-sharing-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-network-information-security-nis-directive-2016",
    "title": "Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 on measures for a high common level of security of network and information systems across the Union",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU NIS Directive establishes a framework for ensuring a high common level of network and information security across essential service operators in energy, transport, health, banking, and digital infrastructure. It mandates risk management measures and incident reporting obligations under Article 14.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cyber-resilience-act-iot-2024-products",
      "etsi-en-303-645-iot-cybersecurity-2020",
      "api-std-1164-scada-pipeline-security",
      "eu-critical-entities-resilience-directive-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-nfrd-non-financial-reporting-directive-2014-95",
    "title": "EU NFRD - Non-Financial Reporting Directive 2014/95/EU",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2017-12-06",
    "bluf": "Directive 2014/95/EU (NFRD) required large public-interest entities (PIEs) with >500 employees to publish non-financial statements covering environmental matters, social/employee matters, anti-corruption/bribery, human rights, and diversity policy - applicable from financial year 2017. NFRD was substantially repealed and replaced by the Corporate Sustainability Reporting Directive (CSRD) 2022/2464 from financial year 2024 onwards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-accounting-directive-2013-34",
      "eu-csrd-2022-2464",
      "csrd-eu-sustainability"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-nis2-cloud-essential-services-2022-2555",
    "title": "Directive (EU) 2022/2555 of the European Parliament and of the Council of 16 November 2022 on measures for a high common level of cybersecurity across the Union, amending and repealing Directive (EU) 2016/1148 (NIS2 Directive)",
    "domain": "Cloud & SaaS",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The NIS2 Directive imposes mandatory risk management and incident reporting obligations on Cloud Service Providers (CSPs) classified as Essential or Important Entities under Articles 21 and 23. These entities must implement 10 minimum security measures (Article 21), report significant incidents within 24 hours (early warning) and 72 hours (formal notification) per Article 24, ensure supply chain security (Article 22), and cooperate with national authorities and ENISA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gdpr-cloud-data-processing",
      "eu-cloud-certification-scheme-eucs",
      "enisa-cloud-security-guidelines-2023",
      "csa-ccm-v4-cloud-controls",
      "eu-dora-ict-third-party-cloud"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-nis2-critical-infrastructure-operators",
    "title": "Directive (EU) 2022/2555 of the European Parliament and of the Council of 16 December 2022 on measures for a high common level of cybersecurity across the Union, amending Directive (EU) 2016/1148 and repealing Directive (EU) 2016/1148",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU NIS2 Directive establishes binding cybersecurity and incident reporting requirements for essential and important entities operating critical infrastructure in sectors including energy, transport, health, and digital infrastructure. It mandates risk management measures, supply chain security, and cooperation among Member States’ supervisory authorities under Article 21 and Article 23.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cyber-resilience-act-iot-2024-products",
      "etsi-en-303-645-iot-cybersecurity-2020",
      "api-std-1164-scada-pipeline-security",
      "eu-data-act-2023-iot-data-sharing-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-nis2-directive-2022-2555",
    "title": "EU NIS2 Directive 2022/2555 -- Cybersecurity Requirements for Essential and Important Entities",
    "domain": "Cybersecurity",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Directive (EU) 2022/2555 (NIS2) replaces the original NIS Directive 2016/1148 and significantly expands the scope of mandatory EU cybersecurity requirements. Member States were required to transpose NIS2 into national law by 17 October 2024. NIS2 creates two tiers of regulated entities: essential entities (Annex I sectors including energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management B2B, public administration, and space) and important entities (Annex II sectors including postal services, waste management, chemicals, food, manufacturing of medical devices and electronics, digital providers, and research). The size cap rule generally applies: medium enterprises with 50 or more employees or EUR 10 million or more in annual turnover in Annex I or II sectors are in scope, and large enterprises with 250 or more employees or EUR 50 million or more in turnover are essential entities if in Annex I sectors. Article 21 mandates 10 categories of security measures including risk analysis, incident handling, business continuity, supply chain security, and multi-factor authentication. Incident notification requirements under Article 23 impose a 24-hour early warning to CSIRTs, a 72-hour incident notification with initial assessment, and a 1-month final report. Maximum penalties for essential entities are at least EUR 10 million or 2 percent of total worldwide annual turnover (whichever is higher) under Article 34(4), and for important entities at least EUR 7 million or 1.4 percent of total worldwide annual turnover under Article 34(3). Management body members can be held personally liable under Article 20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eidas-regulation-2014-910",
      "eu-capital-requirements-regulation-2013-575",
      "eu-corporate-sustainability-reporting-directive-2022-2464"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-nis2-directive-2022-2555-critical-infrastructure",
    "title": "Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Directive (EU) 2016/1148 and repealing Directive (EU) 2016/1148 (NIS2 Directive)",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The NIS2 Directive establishes binding cybersecurity and incident reporting obligations for essential and important entities in critical sectors including energy, transport, and digital infrastructure. It mandates risk management measures, supply chain security, and notification of significant incidents within 24 hours of awareness, under Article 23.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cyber-resilience-act-iot-2024-products",
      "etsi-en-303-645-iot-cybersecurity-2020",
      "api-std-1164-scada-pipeline-security",
      "eu-data-act-2023-iot-data-sharing-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-nis2-directive-2022-2555-cybersecurity-essential-entities",
    "title": "EU NIS2 Directive 2022/2555 - Cybersecurity Obligations for Essential & Important Entities",
    "domain": "Cybersecurity",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "NIS2 Directive 2022/2555 (effective October 2024) expands EU cybersecurity obligations to 18 critical sectors, requires risk management measures, 24-hour initial incident notifications, board-level accountability, and sanctions up to 10 million EUR or 2% of global turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-nis2-directive-2022-2555-network-information-security",
    "title": "EU NIS2 Directive 2022/2555 - Network and Information Security for Essential and Important Entities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive (EU) 2022/2555 (NIS2) replaces the original NIS Directive and imposes mandatory cybersecurity risk management measures and 24/72-hour incident reporting obligations on essential and important entities across 18 sectors. Member States transposed NIS2 by 17 October 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-32-security-of-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-nis2-directive-workflow-critical-operations",
    "title": "EU NIS2 Directive - Workflow Security in Critical Operations: Incident Response Workflows, Reporting Obligations, Supply Chain Security and Governance Requirements",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The EU NIS2 Directive requires essential and important entities to implement secure, automated incident response workflows, strict supply chain risk management, and mandatory 24-hour early warning reporting mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-nis2-essential-important-entities-obligations",
    "title": "EU NIS2 Directive: Cybersecurity Obligations for Essential and Important Entities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Articles 20 and 21 of the NIS2 Directive, essential and important entities must implement comprehensive cybersecurity risk-management measures, including policies on risk analysis, incident handling, supply chain security, and the use of multi-factor authentication. Management bodies are required to approve these measures, undergo training, and are held liable for infringements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nis2-security-measures-article-21",
      "nis2-supply-chain-security-article-22",
      "c-scrm-practices-systems-organizations",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-nis2-health-sector-2026",
    "title": "Directive (EU) 2022/2555 (NIS2) - Cybersecurity Requirements for Health Sector Entities (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "NIS2 Directive classifies hospitals, clinics, manufacturers of critical medical devices, and other health entities as essential or important entities. It mandates comprehensive cybersecurity risk management, incident reporting within 24 hours, supply chain security, crisis response plans, and board-level accountability. Health sector organisations face heightened requirements due to the critical nature of patient safety and data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "eu-nis2-implementing-regulation-2024",
    "title": "Commission Implementing Regulation (EU) 2024/2690 laying down rules for the application of Directive (EU) 2022/2555 as regards the technical and methodological requirements for cybersecurity risk-management measures",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-10-17",
    "bluf": "This regulation establishes the specific technical and methodological requirements for the cybersecurity risk-management measures that essential and important entities must implement under Article 21 of the NIS2 Directive. It mandates a minimum set of ten baseline measures, covering areas from risk analysis and incident handling to supply chain security and cryptography, as detailed in Article 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nis2-security-measures-article-21",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-nis2-implementing-regulation-2024-2690",
    "title": "EU Commission Implementing Regulation (EU) 2024/2690 - NIS2 Technical and Methodological Cybersecurity Risk-Management Measures and Significant Incident Criteria (17 October 2024)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 lays down rules for the application of NIS2 Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and the cases in which an incident is considered significant. It applies to the relevant entities listed in NIS2 Annex II point 8: DNS service providers; TLD name registries; cloud computing service providers; data centre service providers; content delivery network (CDN) providers; managed service providers (MSPs); managed security service providers (MSSPs); online marketplaces; online search engines; social networking services platforms; and trust service providers. Article 1 sets scope; Article 2 incorporates the Annex's technical and methodological requirements implementing NIS2 Article 21(2)(a)-(j); Article 3 specifies significant-incident criteria including (a) direct financial loss exceeding EUR 500,000 or 5% of preceding-year turnover (whichever lower), (b) trade secret exfiltration, (c) death of a natural person, (d) considerable health damage, plus entity-type specific criteria in Articles 4-15. Article 16 sets entry into force on the twentieth day after publication in the OJEU. The Annex draws on ISO/IEC 27001, ISO/IEC 27002, ETSI EN 319401 and CEN/TS 18026:2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_nis2_essential_important_entities_obligations",
        "iso_iec_27001_2022",
        "etsi_en_319401_trust_service_providers",
        "eu_cyber_resilience_act_2024_essential_requirements",
        "eu_eidas_2_amending_910_2014_2024_1183"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-essential-important-entities-obligations",
      "iso-iec-27001-2022-information-security-workflow",
      "eu-cyber-resilience-act-2024-essential-requirements"
    ],
    "primary_citations_count": 20
  },
  {
    "node_id": "eu-nis2-implementing-regulation-2024-2690-digital-infrastructure",
    "title": "EU NIS2 Implementing Regulation 2024/2690 - 150+ Cybersecurity Controls for Digital Infrastructure Providers, In Force 17 October 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online marketplaces, online search engines, social networking services platforms, and trust service providers in the EU must comply with Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024, which lays down technical and methodological requirements of cybersecurity risk-management measures under NIS2 Directive (EU 2022/2555) by implementing the more than 150 specific cybersecurity controls in the regulation's Annex (13 titles covering governance, policies, supply chain security, incident handling, physical protection, and related thematic areas), and applies the regulation's specification of when an incident is considered significant (excluding scheduled interruptions and planned maintenance operations), supported by ENISA technical implementation guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-directive-2022-2555"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-nis2-telecoms-essential-services",
    "title": "Directive (EU) 2022/2555 (NIS2) for Telecom Operators as Essential Entities: Incident Reporting, Security Measures and Competent Authority Cooperation",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The EU NIS2 Directive mandates that telecom operators, classified as 'essential entities' under Annex I, implement comprehensive cybersecurity risk-management measures (Article 21) and adhere to strict multi-stage incident reporting obligations to their national competent authority or CSIRT for any significant incident (Article 23).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3",
      "iso-22301-biz-continuity",
      "us-sec-cybersecurity-disclosure-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-nitrates-directive-91-676-eec",
    "title": "Council Directive 91/676/EEC of 12 December 1991 concerning the protection of waters against pollution caused by nitrates from agricultural sources",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "This EU Directive requires Member States to reduce and prevent water pollution caused by nitrates from agricultural sources. Member States must identify waters affected by pollution or that could be affected, using criteria in Annex I, and designate Nitrate Vulnerable Zones (NVZs) within two years of notification, with revisions every four years. For all waters, a general level of protection is required through a code of good agricultural practice, established within two years, to be implemented voluntarily by farmers. Within two years of NVZ designation, action programmes must be established and implemented within four years, containing mandatory measures from Annex III: these include rules on fertilizer application periods, storage capacity for livestock manure, and a limit on livestock manure application to 170 kg N per hectare per year (with a possible 210 kg N for the first four-year programme and the ability to fix different amounts based on objective criteria such as long growing seasons or high nitrogen uptake crops). Monitoring of nitrate concentration in freshwaters must be conducted over one year within two years, then every four years (or every eight years if nitrate remains below 25 mg/l). Eutrophic state of fresh surface waters, estuarial, and coastal waters must be reviewed every four years. Member States must submit reports every four years containing information outlined in Annex V, including a map of waters and vulnerable zones, summary of monitoring results, and summary of action programmes. The Commission publishes summary reports within six months of receiving Member State reports.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-nitrates-directive-91-676-eec-agricultural-pollution",
    "title": "EU Nitrates Directive 91/676/EEC - Nitrate Vulnerable Zones, Action Programmes and Code of Good Agricultural Practice",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "Council Directive 91/676/EEC concerning the protection of waters against pollution caused by nitrates from agricultural sources (Nitrates Directive) is one of the earliest pieces of EU water legislation and remains a cornerstone of agricultural water pollution control. Article 3 requires Member States to designate Nitrate Vulnerable Zones (NVZs) covering all areas of land draining into waters identified as polluted (or could become polluted) by nitrates from agricultural sources, with nitrate concentrations above 50 mg/l or showing eutrophication. Member States may alternatively designate the whole national territory as NVZ (Austria, Denmark, Finland, Germany, Ireland, Lithuania, Luxembourg, Malta, Netherlands and Slovenia have done so in full or substantially). Article 4 requires Code of Good Agricultural Practice (CGAP) for voluntary application across whole territory. Article 5 requires mandatory Action Programmes in NVZs every four years covering periods when fertiliser application prohibited, storage capacity for livestock manure, limits on application based on crop requirements and an upper limit of 170 kg/ha/year of nitrogen from livestock manure (with derogations possible under Annex III conditions). The Directive is implemented in close coordination with the Water Framework Directive and Common Agricultural Policy conditionality.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-water-framework-directive-2000-60-ec",
      "eu-groundwater-directive-2006-118-ec-quality-standards"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-noise-directive-construction-2002-49",
    "title": "Directive 2002/49/EC of the European Parliament and of the Council of 25 June 2002 relating to the assessment and management of environmental noise",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive requires EU Member States to produce strategic noise maps for major urban agglomerations, major roads, railways, airports, and major construction projects, and to develop action plans to reduce noise exposure where necessary. Key obligations are defined in Article 7 (noise mapping) and Article 8 (action plans), with specific reference to Lden (day-evening-night) and Lnight (night-time) noise indicators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-circular-economy-construction-demolition-waste-2020",
      "iso-19650-bim-information-management-construction",
      "iso-21500-project-management-construction-guidance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-non-cash-payment-fraud-directive-2019-713",
    "title": "Directive (EU) 2019/713 of the European Parliament and of the Council of 17 April 2019 on combating fraud and counterfeiting of non-cash means of payment",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive establishes minimum rules on the definition of criminal offences and sanctions in the area of fraud and counterfeiting of non-cash means of payment (Article 1). It criminalises the fraudulent use of corporeal and non-corporeal non-cash payment instruments (Articles 3 to 5), fraud related to information systems (Article 6), the use of tools for committing such offences (Article 7), and incitement, aiding, abetting and attempt (Article 8), with effective, proportionate and dissuasive penalties for natural and legal persons (Articles 9 to 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-wire-transfer-regulation-2023-1113",
      "eu-freezing-confiscation-mutual-recognition-regulation-2018-1805"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-northern-ireland-retail-goods-movement-regulation-2023-1231",
    "title": "Regulation (EU) 2023/1231 of the European Parliament and of the Council of 14 June 2023 on specific rules relating to the entry into Northern Ireland from other parts of the United Kingdom of certain consignments of retail goods, plants for planting, seed potatoes, machinery and certain vehicles operated for agricultural or forestry purposes, as well as non-commercial movements of certain pet animals into Northern Ireland",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down specific rules relating to the entry into Northern Ireland from other parts of the United Kingdom of certain consignments of retail goods, plants for planting, seed potatoes, machinery and certain vehicles, and non-commercial movements of certain pet animals (Article 1). It sets specific rules for consignments of retail goods (Articles 4 and 5), the marking of retail goods (Article 6), the monitoring of retail goods (Article 7), the listing of establishments for dispatch (Article 8), and includes a prohibition against onward movement to or placing on the market in a Member State (Article 13) and a safeguard suspension mechanism (Article 14).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-official-controls-regulation-2017-625",
      "eu-plant-health-regulation-2016-2031"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-novel-food-catalogue-regulation-2015-2283",
    "title": "Regulation (EU) 2015/2283 of the European Parliament and of the Council of 25 November 2015 on novel foods, amending Regulation (EU) No 1169/2011 of the European Parliament and of the Council and repealing Regulation (EC) No 258/97 and Commission Regulation (EC) No 1852/2001",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a pre-market authorisation system for novel foods, defined as foods not consumed significantly in the EU before 15 May 1997, requiring a safety assessment by EFSA under Article 10. It applies to food business operators placing novel foods on the EU market, including traditional foods from third countries under Article 14 and emerging categories such as CBD and cultured meat.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-law-178-2002",
      "eu-food-hygiene-regulation-852-2004",
      "eu-food-information-regulation-1169-2011-labelling",
      "brc-food-safety-global",
      "codex-alimentarius-general-principles-hygiene-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-novel-food-regulation-2015-2283",
    "title": "Regulation (EU) 2015/2283 of the European Parliament and of the Council of 25 November 2015 on novel foods, amending Regulation (EU) No 1169/2011 of the European Parliament and of the Council and repealing Regulation (EC) No 258/97 of the European Parliament and of the Council and Commission Regulation (EC) No 1852/2001",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation requires food business operators to obtain pre-market authorization from the European Commission before placing a 'novel food' on the EU market. As defined in Article 3, this includes foods from new production processes like cellular agriculture or newly developed sources, which must undergo a rigorous safety assessment by the European Food Safety Authority (EFSA) before being added to the Union list of authorized novel foods (Article 6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-law-178-2002",
      "haccp-food-safety",
      "iso-22000-food-mgt",
      "fda-food-labeling-guide"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-novel-foods-regulation-2015-2283",
    "title": "EU Novel Foods Regulation 2015/2283 - Pre-Market Authorisation and Union List of Authorised Novel Foods",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Regulation (EU) 2015/2283 of the European Parliament and of the Council on novel foods replaced Regulation (EC) No 258/97 and became applicable from 1 January 2018. The Regulation defines a novel food in Article 3(2)(a) as any food not used for human consumption to a significant degree within the Union before 15 May 1997. Categories of novel food under Article 3(2)(a) include food from cell culture or tissue culture, food produced from animals or plants using new production processes, food consisting of or produced from insects, food consisting of engineered nanomaterials, vitamins and minerals produced by new production processes, and food previously used exclusively in food supplements. Article 6 prohibits the placement of novel foods on the Union market unless they are authorised and included in the Union list of authorised novel foods. Article 10 requires applicants to submit an authorisation application to the European Commission, which then requests a safety assessment from the European Food Safety Authority (EFSA). Article 14 specifies that EFSA must deliver its opinion within 9 months of the validity of the application. Article 26 provides a simplified notification procedure for traditional foods from third countries that have a history of safe use of at least 25 years as part of the normal diet in a third country. The Union list specifies the conditions of use, the designation for labelling, and any specific labelling requirements for each authorised novel food.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_food_information_consumers_regulation_1169_2011",
        "eu_gmo_deliberate_release_directive_2001_18",
        "us_fda_gras_framework",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-information-consumers-regulation-1169-2011",
      "eu-gmo-deliberate-release-directive-2001-18",
      "eu-services-directive-2006-123"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-npl-credit-servicers-regulation-2021-2167",
    "title": "EU NPL Credit Servicers Directive 2021/2167 - Non-Performing Loan Secondary Market",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive (EU) 2021/2167 creates a harmonised EU framework for credit servicers and credit purchasers of non-performing loans (NPLs) issued by EU credit institutions. Credit servicers must be authorised by the NCA of their home member state; credit purchasers (non-bank buyers of NPL portfolios) may operate without authorisation but must appoint an authorised credit servicer. The directive requires transparent borrower communication, data templates for NPL transfers, and supervisory information sharing between member states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-brrd-bank-recovery-resolution-directive-2014-59",
      "eu-mortgage-credit-directive-2014-17-real-estate"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-nsfr-net-stable-funding-ratio-crr2-2019",
    "title": "EU Net Stable Funding Ratio (NSFR) - CRR2 Articles 428b-428at",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "The EU NSFR (CRR2 Articles 428b-428at, applicable from 28 June 2021) requires credit institutions and investment firms to maintain a ratio of Available Stable Funding (ASF) to Required Stable Funding (RSF) of at least 100%, ensuring a stable funding profile over a 1-year horizon; institutions must report NSFR quarterly and disclose publicly annually.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-crr3-capital-requirements-regulation-2024-1623",
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-single-supervisory-mechanism-regulation-1024-2013"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-nuclear-safety-directive-2014-87-euratom",
    "title": "Council Directive 2014/87/Euratom of 8 July 2014 amending Directive 2009/71/Euratom establishing a Community framework for the nuclear safety of nuclear installations",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive amends the EU's nuclear safety framework, requiring Member States to ensure licence holders for nuclear installations implement a high-level safety objective to prevent accidents and mitigate their consequences, including conducting periodic safety reviews at least every 10 years (Article 8c). It applies to all civilian nuclear installations within the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-nuclear-safety-directive-2014-87-euratom-energy",
    "title": "Council Directive 2014/87/Euratom of 8 July 2014 amending Directive 2009/71/Euratom establishing a Community framework for the nuclear safety of nuclear installations",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-07-09",
    "bluf": "This directive amends the EU's nuclear safety framework, requiring Member States to ensure nuclear installation operators conduct periodic safety reviews at least every 10 years and implement robust on-site emergency preparedness and response plans. It strengthens the independence and resources of national regulatory authorities, as mandated by the revised Articles 6, 8a, and 8c.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-nutrition-health-claims-regulation-1924-2006",
    "title": "Regulation (EC) No 1924/2006 of the European Parliament and of the Council of 20 December 2006 on nutrition and health claims made on foods",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes harmonised rules for nutrition and health claims made on foods in the EU, requiring all claims to be authorised, substantiated by scientific evidence, and not misleading to consumers. It applies to all commercial communications, including labelling and advertising, under Article 3 and Article 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-labelling-regulation-1169-2011",
      "eu-food-hygiene-regulation-852-2004",
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-food-law-178-2002"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-occupational-pensions-iorp-ii-2016-2341",
    "title": "Directive (EU) 2016/2341 of the European Parliament and of the Council of 14 December 2016 on the activities and supervision of institutions for occupational retirement provision (IORPs) (recast)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This directive establishes prudential, governance, and transparency requirements for Institutions for Occupational Retirement Provision (IORPs) across the EU, including mandatory Own Risk Assessment (Article 17), prudent person investment policy (Article 20), cross-border transfer conditions (Article 27), and Key Information Document (KID) for members (Article 25). It applies to all occupational pension schemes operating in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eiopa-guidelines-orsa-2015",
      "eiopa-guidelines-pension-stress-testing-2022",
      "eu-commission-implementing-regulation-2015-2452-solvency"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-occupational-pensions-iorp-investment-limits-2016",
    "title": "Directive (EU) 2016/2341 (IORP II) Article 18: Investment Rules for Institutions for Occupational Retirement Provision",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "Under Article 18 of the IORP II Directive, EU Member States must ensure that Institutions for Occupational Retirement Provision (IORPs) invest their assets according to the 'prudent person' principle, diversifying investments to avoid excessive risk concentration and ensuring assets are appropriate to the nature and duration of their expected future retirement benefit liabilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "erisa-compliance-rep"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-odp-open-data-directive-2019-1024-operations",
    "title": "Directive (EU) 2019/1024 of the European Parliament and of the Council of 20 June 2019 on open data and the re-use of public sector information",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This Directive requires EU member state public sector bodies to make high-value datasets openly available in machine-readable formats via APIs, under reuse-friendly conditions, with dynamic data updated in real-time or near real-time, and to apply marginal-cost-based charging for data reuse. Key obligations are established in Articles 10, 11, and 12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-geo-blocking-regulation-2018",
      "eu-omnibus-directive-2019-2161",
      "iso-15489-1-2016-records-management-workflow",
      "bpmn-2-0-omg-specification-workflow-notation",
      "eu-p2b-regulation-2019-1150"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-official-controls-regulation-2017-625",
    "title": "Regulation (EU) 2017/625 of the European Parliament and of the Council of 15 March 2017 on official controls and other official activities performed to ensure the application of food and feed law, rules on animal health and welfare, plant health and plant protection products",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes a harmonized EU framework for official controls performed by Member State competent authorities to verify business operator compliance with the agri-food chain legislation, including food/feed safety, animal health, and plant health. It mandates a risk-based approach for all inspections, audits, and enforcement actions as outlined in Article 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-law-178-2002",
      "haccp-food-safety",
      "iso-22000-food-mgt",
      "brc-food-safety-global",
      "codex-alimentarius-gen"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-offshore-oil-gas-safety-directive-2013-30",
    "title": "Directive 2013/30/EU of the European Parliament and of the Council of 12 June 2013 on safety of offshore oil and gas operations and amending Directive 2004/35/EC",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes minimum requirements for preventing major accidents in offshore oil and gas operations and limiting their consequences, applying to operators and owners. It mandates the creation and submission of a comprehensive 'report on major hazards' (safety case) for acceptance by the competent authority before any installation can operate, as stipulated in Article 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-22301-biz-continuity",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-offshore-renewable-energy-strategy-2020",
    "title": "An EU Strategy to harness the potential of offshore renewable energy for a climate neutral future (COM/2020/741 final)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This EU strategy establishes ambitious targets for deploying at least 60 GW of offshore wind and 1 GW of ocean energy by 2030, and 300 GW of offshore wind and 40 GW of ocean energy by 2050. It requires Member States to collaborate on long-term planning, maritime spatial planning, grid infrastructure development, and streamlined environmental assessments to facilitate this large-scale expansion, as outlined in Communication COM(2020) 741 final.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-omnibus-directive-2019-2161",
    "title": "Directive (EU) 2019/2161 on the better enforcement and modernisation of Union consumer protection rules",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This directive modernizes EU consumer protection law, requiring online traders and marketplaces to provide greater transparency on personalized pricing, the authenticity of consumer reviews, and the main parameters determining search result rankings, as mandated by amendments to Directives 2005/29/EC and 2011/83/EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fca-consumer-duty-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-omnibus-directive-2019-2161-consumer-protection",
    "title": "Directive (EU) 2019/2161 of the European Parliament and of the Council of 27 November 2019 on the better enforcement and modernisation of Union consumer protection rules",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The EU Omnibus Directive 2019/2161 strengthens consumer protection in digital services by mandating transparency on price formation, disclosure of personalised pricing, and prohibition of fake reviews. It applies to all traders offering goods or services to consumers in the EU, with key obligations under Articles 6, 7, and 8 amending the Unfair Commercial Practices Directive (2005/29/EC).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-directive",
      "eu-consumer-rights-directive-2011",
      "eu-geo-blocking-regulation-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-omnibus-directive-digital-product-reviews-2022",
    "title": "Directive (EU) 2019/2161 of the European Parliament and of the Council of 27 November 2019 amending Directive 2005/29/EC and Regulation (EU) No 2006/2004 as regards enforcement, modernisation and clarification of Union consumer protection rules",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Prohibits fake online reviews and requires digital platforms to verify the authenticity of consumer reviews, disclose incentivised or AI-generated content, and prevent fake social media followers. Applies to all online marketplaces and review platforms operating in the EU under Article 8a of Directive 2005/29/EC as amended by Directive (EU) 2019/2161.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29",
      "eprivacy-cookie-directive",
      "eu-ecommerce-directive-2000-31",
      "ama-ethical-marketing",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-omnibus-i-directive-2026-470-csrd-csddd-simplification",
    "title": "Directive (EU) 2026/470 amending Directives 2006/43/EC, 2013/34/EU, (EU) 2022/2464 and (EU) 2024/1760 as regards certain corporate sustainability reporting and corporate sustainability due diligence requirements (Omnibus I)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "Omnibus I raises the corporate sustainability reporting (CSRD) scope thresholds to net turnover above EUR 450 million and an average of 1,000 employees, raises the due diligence (CSDDD) thresholds to EUR 1,500 million turnover and 5,000 employees, postpones CSDDD application for all companies to 26 July 2029, and mandates a revision of the ESRS within six months of entry into force.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-corporate-sustainability-due-diligence-directive-2024-1760",
      "csrd-directive-article-2-scope-of-sustainability-reporting",
      "eu-esrs-1-general-requirements",
      "eu-accounting-directive-2013-34"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-online-dispute-resolution-regulation-524-2013",
    "title": "Regulation (EU) No 524/2013 of the European Parliament and of the Council of 21 May 2013 on online dispute resolution for consumer disputes and amending Regulation (EC) No 2006/2004 and Directive 2009/22/EC (Regulation on consumer ODR)",
    "domain": "Operations & CX",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes an EU-wide online dispute resolution (ODR) platform for consumers and traders to resolve disputes arising from online sales or service contracts concluded within the Union. It applies to traders established in the Union offering goods or services via websites or other electronic means, where disputes are initiated by consumers resident in the Union, under Article 3(1) and Article 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-adr-consumer-disputes-2013",
      "eu-consumer-rights-directive-2011",
      "eu-geo-blocking-regulation-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-online-gambling-services-4amld-aml-due-diligence",
    "title": "EU Online Gambling Services - Anti-Money Laundering (AML) Due Diligence Under 4AMLD",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive (EU) 2015/849 (4AMLD) Article 2(1)(f) includes \"providers of gambling services\" as obliged entities subject to anti-money laundering and counter-terrorist financing (AML/CTF) requirements. The Directive requires customer due diligence (CDD) for transactions of EUR 2,000 or more, risk-based monitoring, and suspicious transaction reporting to the national Financial Intelligence Unit. Member States may exempt low-risk gambling services under Article 2(2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-6th-directive-2018-1673-criminal-liability-money-laundering"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-open-access-mandate-horizon-europe",
    "title": "EU Horizon Europe Open Access Mandate - Immediate Open Access for Publications (CC BY), Data Management Plans, FAIR Data Principles, Open Research Data Pilot and Beneficiary Obligations",
    "domain": "Education & Research",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Horizon 2020 beneficiaries must ensure open access to all peer-reviewed scientific publications relating to their results under Article 29.2 of the Model Grant Agreement. This includes depositing the final peer-reviewed manuscript in a repository upon publication and enabling reuse rights such as mining and distribution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-education-action-plan-2021-2027",
      "eu-european-research-area-policy-agenda-2022",
      "eu-open-science-policy-fair-data-principles-2021",
      "eu-researcher-charter-code-of-conduct-2005"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-open-internet-berec-guidelines-2020",
    "title": "BEREC Guidelines on the Implementation of the Open Internet Regulation",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "These BEREC Guidelines provide guidance to National Regulatory Authorities (NRAs) on implementing Regulation (EU) 2015/2120, specifically Articles 3 and 4, to ensure equal and non-discriminatory treatment of internet traffic and protect end-user rights. They apply to internet access service providers and specialised service offerings across the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-net-neutrality-open-internet-2015-2120",
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-eecc-end-user-rights-universal-service"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-open-research-data-policy-eosc",
    "title": "EU Open Research Data Policy and European Open Science Cloud (EOSC) Framework - FAIR Data Principles and Data Management Plans",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This framework mandates that research data from EU-funded projects, particularly under Horizon Europe, must be managed according to FAIR principles (Findable, Accessible, Interoperable, Reusable) and documented in a Data Management Plan (DMP). As stipulated in the Horizon Europe Model Grant Agreement (Article 17), data must be 'as open as possible, as closed as necessary,' and deposited in a trusted repository.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-open-science-policy-fair-data-principles-2021",
    "title": "EU Open Science Policy 2021 - FAIR Data Principles, Open Access Mandates, Open Peer Review and Research Data Management Plans for Horizon Europe",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This policy mandates that all research data generated under Horizon Europe must be Findable, Accessible, Interoperable, and Reusable (FAIR), deposited in trusted repositories, and accompanied by a Data Management Plan (DMP) as per Article 29.1 of the Horizon Europe Regulation (EU) 2021/694. It applies to all beneficiaries of Horizon Europe funding, including universities, research institutions, and private consortia.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-organic-farming-regulation-2018-848",
    "title": "Regulation (EU) 2018/848 of the European Parliament and of the Council of 30 May 2018 on organic production and labelling of organic products and repealing Council Regulation (EC) No 834/2007",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes a comprehensive legal framework for organic production and labelling within the EU, applying to all operators involved in the production, preparation, and distribution of organic products. It mandates adherence to specific principles such as sustainable systems, high animal welfare standards, and the prohibition of GMOs and ionising radiation, as outlined in Article 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-law-178-2002",
      "haccp-food-safety",
      "iso-22000-food-mgt",
      "fda-food-labeling-guide"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-organic-production-regulation-2018-848",
    "title": "Regulation (EU) 2018/848 on organic production and labelling of organic products and repealing Regulation (EC) No 834/2007",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Regulation (EU) 2018/848 establishes the legal framework for organic production and labelling of organic products within the European Union. It applies to products originating from agriculture, including aquaculture and beekeeping, as listed in Annex I to the TFEU, as well as processed agricultural products for food or feed. Sea salt and other food-grade salts are also included. Hunting or fishing of wild animals are excluded from organic certification because control of the production process is not possible. Mass caterers' food prepared on their premises is excluded from the regulation. The regulation requires all agricultural holdings aiming for organic certification to be entirely managed under organic production rules after a conversion period, but permits split holdings under strict separation conditions. Use of genetically modified organisms, ionising radiation, animal cloning, and artificially induced polyploid animals is prohibited. Organic plant production must be soil-related, nourishing plants primarily through the soil ecosystem; hydroponic production is not allowed. Demarcated beds are prohibited from the date of application except for existing operators in Finland, Sweden, and Denmark for 10 years. Livestock production must be land-related; landless production is prohibited except for beekeeping. Animals must be fed organic feed, preferably from the farmer's own holding. Preventive use of chemically synthesized allopathic medicinal products, including antibiotics, is not permitted; curative use requires double the normal withdrawal period (minimum 48 hours). Livestock must have permanent access to open-air areas. The regulation mandates a conversion period before products can be labelled as organic. In-conversion labelling is allowed only for plant reproductive material, food products of plant origin, and feed products of plant origin with one agricultural crop ingredient after at least 12 months before harvest. Operators must take preventive and proportionate precautionary measures to avoid contamination with non-authorised substances. A control system under Regulation (EU) 2017/625 is required. Suspected non-compliance must be reported and investigated. The organic production logo of the European Union is mandatory for all organic prepacked food produced in the Union and its use requires indication of where agricultural raw materials were farmed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-organic-regulation-2018-848-implementing-rules",
    "title": "Regulation (EU) 2018/848 of the European Parliament and of the Council of 30 May 2018 on organic production and labelling of organic products and repealing Council Regulation (EC) No 834/2007",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes the rules for organic production, labelling, and control systems within the EU, including permitted substances (Annexes I and II), conversion periods (Article 9), management of mixed farms (Article 23), aquaculture and beekeeping standards (Articles 25-26), third-country equivalence (Article 30), and group certification for small farmers (Article 31). It applies to all operators involved in the production, processing, distribution, import, or labelling of organic products in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-law-178-2002",
      "eu-food-hygiene-regulation-852-2004",
      "eu-food-information-regulation-1169-2011-labelling",
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-orphan-medicinal-products-141-2000",
    "title": "Regulation (EC) No 141/2000 of the European Parliament and of the Council of 16 December 1999 on orphan medicinal products",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes the criteria and procedure for designating medicinal products as 'orphan medicinal products' for rare diseases, defined as those affecting not more than five in 10,000 persons in the European Union (Article 3). Designated products are eligible for incentives, including a ten-year period of market exclusivity (Article 8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-orphan-regulation-141-2000-designation-criteria",
    "title": "Commission Regulation (EC) No 141/2000 of 16 December 1999 on Orphan Medicinal Products",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires that medicinal products intended for the diagnosis, prevention or treatment of life-threatening or chronically debilitating conditions affecting not more than 5 in 10,000 persons in the European Union at the time of application, meet specific criteria for orphan status as outlined in Article 3. The European Medicines Agency's Committee for Orphan Medicinal Products (COMP) is responsible for assessing applications for orphan designation, as stated in Article 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-gcp-e6-r3-2023",
      "iso-13485-qms"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-orphan-regulation-141-2000-rare-diseases",
    "title": "Regulation (EC) No 141/2000 of the European Parliament and of the Council of 16 December 1999 on Orphan Medicinal Products",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the framework for the designation of orphan medicinal products in the EU for the diagnosis, prevention, or treatment of life-threatening or chronically debilitating conditions affecting no more than 5 in 10,000 persons in the EU, or where there is no return on investment without incentives (Article 3). It grants 10 years of market exclusivity, protocol assistance, and fee reductions upon designation and authorisation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-atmp-regulation-1394-2007",
      "ich-e8-r1-general-considerations-clinical-2021",
      "ema-guidelines-advanced-therapy-quality-2019",
      "fda-guidance-human-gene-therapy-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-orphan-works-directive-2012-28-eu",
    "title": "Directive 2012/28/EU of the European Parliament and of the Council of 25 October 2012 on certain permitted uses of orphan works",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Requires cultural heritage institutions to conduct a 'diligent search' in accordance with Article 3 to determine if a work's rightholder is unlocatable before digitizing and making it available online for non-commercial purposes across the EU, with mutual recognition of orphan status under Article 5 and obligation to pay fair compensation upon rediscovery under Article 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-1886-2024-literary-artistic-works",
      "eu-copyright-directive-art-17",
      "doi-digital-object-id",
      "iptc-photo-metadata",
      "exif-standard-metadata"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-p2b-platform-regulation-2019-ranking-transparency",
    "title": "Regulation (EU) 2019/1150 of the European Parliament and of the Council of 20 June 2019 on promoting fairness and transparency for business users of online intermediation services and online search engines",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Online platforms must provide business users with clear, effective, and timely information about the main parameters determining ranking of products or services, including the relative importance of those parameters and whether paid prominence influences ranking. Applies to online intermediation services and online search engines operating in the EU. Key requirement under Article 6(1) and Article 6(5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecommerce-directive-2000-31",
      "eu-unfair-commercial-practices-2005-29",
      "eu-geo-blocking-regulation-2018-302",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-p2b-platform-to-business-regulation-2019-1150-transparency",
    "title": "EU Platform-to-Business (P2B) Regulation 2019/1150 - Terms, Ranking, and Mediation Obligations for Online Intermediation Services",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Regulation (EU) 2019/1150 requires online intermediation services (app stores, marketplaces, price comparison sites, social media with commercial functions) and online search engines to provide business users with transparent and predictable terms and conditions, explain main ranking parameters, disclose differentiated treatment, provide internal complaint handling (for platforms with >10 employees), and facilitate access to mediation for disputes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeeper-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-p2b-regulation-2019-1150",
    "title": "Regulation (EU) 2019/1150 on promoting fairness and transparency for business users of online intermediation services",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This regulation requires providers of online intermediation services (e.g., marketplaces, app stores) and online search engines to ensure fairness and transparency for their business users. Key requirements under Articles 3 and 5 mandate clear, easily available terms and conditions, and disclosure of the main parameters determining ranking.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-package-travel-directive-2015-2302",
    "title": "Directive (EU) 2015/2302 of the European Parliament and of the Council of 25 November 2015 on package travel and linked travel arrangements",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive harmonises rules on package travel and linked travel arrangements (Article 1). It requires the provision of pre-contractual information using standard forms (Article 5) which is binding (Article 6), sets the content of the package travel contract (Article 7), governs transfer of the contract to another traveller (Article 9), price alterations (Article 10) and other contract changes (Article 11), the right of the traveller to terminate including without termination fee in cases of unavoidable and extraordinary circumstances (Article 12), the organiser responsibility for performance of the package (Article 13), and price reduction and compensation for damages (Article 14), together with insolvency protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011-83-eu",
      "eu-air-passenger-rights-regulation-261-2004"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-packaging-packaging-waste-regulation-2025-40",
    "title": "Regulation (EU) 2025/40 - EU Packaging and Packaging Waste Regulation (PPWR): Recyclability Requirements, Recycled Content Targets, Reusability Obligations, Deposit Return Systems, Prohibited Packaging Formats, Extended Producer Responsibility, and Repeal of Directive 94/62/EC",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2025/40 (EU Packaging and Packaging Waste Regulation, PPWR), entered into force in early 2025, replaces Directive 94/62/EC and establishes the EU's first regulation (directly applicable in all Member States without national transposition) on packaging and packaging waste; key obligations include: all packaging placed on the EU market must be recyclable by 2030 (with full recyclability at scale by 2035); mandatory minimum recycled content targets for plastic packaging (graduated by packaging type, from 10-30% by 2030 rising to 25-50% by 2040); reusability requirements for industrial, transport, and consumer packaging including mandatory reusable format availability in HoReCa and e-commerce contexts; prohibition of specific packaging formats deemed unnecessary or non-recyclable; mandatory deposit return systems (DRS) for plastic beverage bottles up to 3 litres and metal cans up to 1 litre by 2029; packaging minimisation requirements limiting void space (50% for e-commerce, 40% for grouped packaging); harmonised extended producer responsibility (EPR) fees modulated by recyclability; and PFAS and other hazardous substance restrictions for food-contact packaging.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_ESPR",
        "EU_SINGLE_USE_PLASTICS",
        "EU_TAXONOMY",
        "EU_REACH"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecodesign-sustainable-products-regulation-2024-1781",
      "eu-taxonomy-regulation-2020-852",
      "eu-csrd-2022-2464",
      "eu-critical-raw-materials-act-2024-1252"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-paediatric-regulation-1901-2006",
    "title": "Regulation (EC) No 1901/2006 of the European Parliament and of the Council of 12 December 2006 on medicinal products for paediatric use and amending Regulation (EEC) No 1768/92, Directive 2001/20/EC, Directive 2001/83/EC and Regulation (EC) No 726/2004",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires pharmaceutical companies to submit a Paediatric Investigation Plan (PIP) detailing the development of a medicine for children as part of their marketing authorisation application for new medicinal products in the EU, unless a waiver or deferral is granted (Article 7). It also establishes rewards, such as a six-month extension of the Supplementary Protection Certificate (SPC), for compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-paediatric-regulation-1901-2006-pharma",
    "title": "Regulation (EC) No 1901/2006 of the European Parliament and of the Council of 12 December 2006 on medicinal products for paediatric use and amending Regulation (EEC) No 1768/92, Directive 2001/20/EC, Directive 2001/83/EC and Regulation (EC) No 726/2004",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation mandates that pharmaceutical developers submit a Paediatric Investigation Plan (PIP) to the European Medicines Agency's Paediatric Committee (PDCO) before initiating clinical trials for new medicines, unless a waiver or deferral applies. Compliance with the agreed PIP is required for marketing authorisation and may qualify the sponsor for a 6-month extension of the Supplementary Protection Certificate (SPC) under Article 36.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-312-ind-investigational-new-drug",
      "fda-21-cfr-part-314-nda-new-drug-application",
      "fda-biosimilar-pathway-351k-biologics-competition-act",
      "ich-q10-pharmaceutical-quality-system-2008"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-paediatric-regulation-1901-2006-pip-paediatric-investigation-plan",
    "title": "EU Paediatric Regulation 1901/2006 - Paediatric Investigation Plan and Waiver Requirements",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "Regulation (EC) No 1901/2006 requires all applications for new marketing authorisations (MAs) and extensions of indication to include a Paediatric Investigation Plan (PIP) agreed with EMA's Paediatric Committee (PDCO), or an agreed waiver/deferral. PIPs must be submitted early in development and agreed before completion of Phase 2 adult trials. Compliance is rewarded with a 6-month patent/SPC extension (10 years market exclusivity for orphan medicines). Non-compliance prevents MA approval.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-clinical-trials-regulation-2014-536-ctr-investigational-medicinal-products"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-paediatric-regulation-1901-2006-pips",
    "title": "Regulation (EC) No 1901/2006 of the European Parliament and of the Council on Medicinal Products for Paediatric Use",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires pharmaceutical companies to submit a Paediatric Investigation Plan (PIP) for new medicinal products, as outlined in Article 7 of the regulation, and provides rewards for compliance, including a 6-month patent extension.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-gcp-e6-r3-2023",
      "iso-13485-qms"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-parent-subsidiary-directive-2011-96-anti-hybrid",
    "title": "Council Directive 2011/96/EU of 16 November 2011 on the common system of taxation applicable to parent companies and subsidiaries of different Member States, as amended by Council Directive 2014/86/EU to prevent double non-taxation arising from hybrid mismatch arrangements",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive ensures that qualifying dividend distributions between EU parent and subsidiary companies are exempt from withholding tax, provided certain conditions are met, including anti-abuse rules introduced by Directive 2014/86/EU to prevent double non-taxation via hybrid mismatch arrangements. It applies to corporate entities resident in EU Member States with direct or indirect shareholding of at least 10%. Key provisions are in Article 4 and Article 5, as amended.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-atad2-hybrid-mismatches-2017-952",
      "eu-transfer-pricing-directive-proposal-2023",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-parent-subsidiary-directive-2011-96-eu",
    "title": "Council Directive 2011/96/EU of 16 November 2011 on the common system of taxation applicable to parent companies and subsidiaries of different Member States",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This Directive eliminates withholding taxes on dividends paid between qualifying parent companies and subsidiaries within the EU, provided the parent holds at least 10% of the subsidiary’s capital for an uninterrupted period of at least one year, and the arrangement does not constitute abuse under the general anti-abuse rule (GAAR) in Article 5. It applies to EU-resident corporate entities in cross-border group structures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-atad2-hybrid-mismatches-2017-952",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two",
      "eu-transfer-pricing-directive-proposal-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-part-is-information-security-delegated-2022-1645",
    "title": "Commission Delegated Regulation (EU) 2022/1645 of 14 July 2022 laying down rules for the application of Regulation (EU) 2018/1139 regarding requirements for the management of information security risks with potential impact on aviation safety for organisations covered by Commission Regulations (EU) No 748/2012 and (EU) No 139/2014 (Part-IS)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "This Part-IS delegated rule requires design and production organisations and aerodrome operators and apron management service providers to set up, implement and maintain an information security management system that identifies and reviews information security risks with potential impact on aviation safety, treats those risks, and reports significant incidents to the competent authority within 72 hours; it applies from 16 October 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-easa-basic-regulation-2018-1139-common-rules-civil-aviation",
      "faa-part-21-certification",
      "easa-cybersecurity-aviation-ed-202a-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-part-is-information-security-implementing-2023-203",
    "title": "Commission Implementing Regulation (EU) 2023/203 of 27 October 2022 laying down rules for the application of Regulation (EU) 2018/1139 regarding requirements for the management of information security risks with potential impact on aviation safety for organisations and competent authorities (Part-IS)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "Part-IS (Implementing Regulation 2023/203) requires civil aviation organisations and competent authorities to set up, implement and maintain an information security management system (ISMS) that identifies and manages information security risks with potential impact on aviation safety, detects and responds to incidents, and reports significant incidents or vulnerabilities to the competent authority; it applies from 22 February 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-easa-basic-regulation-2018-1139-common-rules-civil-aviation",
      "easa-cybersecurity-aviation-ed-202a-2022",
      "tsa-aviation-cybersecurity-amendment-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-passenger-rights-regulation-pr-sales-2021",
    "title": "EU Air, Rail and Sea Passenger Rights Regulations - Sales Obligations: Clear Price Display (All Taxes Included), Cancellation Refund Rights (7-14 Days), Voucher Alternative Conditions, Re-routing Obligations, Rebooking for Disruptions and Enforcement by National Bodies",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes enforceable passenger rights across air, rail, road, and ship travel in the EU, requiring carriers to provide non-discriminatory access, timely information, assistance during disruptions, and compensation under certain conditions. Key obligations include reimbursement within 14 days for cancelled flights via intermediaries and assistance for passengers with reduced mobility during multimodal journeys as outlined in the proposed revisions to Regulations (EC) No 261/2004 and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-geo-blocking-regulation-2018-302",
      "eu-unfair-commercial-practices-2005-29",
      "eu-ecommerce-directive-2000-31",
      "eu-price-indication-directive-1998"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-pay-transparency-directive-2023",
    "title": "Directive (EU) 2023/970 of the European Parliament and of the Council of 10 May 2023 to strengthen the application of the principle of equal pay for equal work or work of equal value between men and women through pay transparency and enforcement mechanisms",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "This directive requires EU employers to provide pay information to job candidates and employees, report on gender pay gaps, and conduct a joint pay assessment with worker representatives if the unexplained gender pay gap exceeds 5% (Article 10). It applies to all employers in the public and private sectors, with specific reporting obligations for those with over 100 employees.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "iso-30414-human-capital-rep",
      "iso-26000-social-resp-mgt",
      "shrm-hr-competency"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-pay-transparency-directive-2023-970",
    "title": "Directive (EU) 2023/970 of the European Parliament and of the Council of 10 May 2023 to strengthen the application of the principle of equal pay for equal work or work of equal value between men and women through pay transparency and enforcement mechanisms",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "This EU directive mandates pay transparency measures for employers, requiring them to provide salary range information to job candidates and disclose pay gap data. As per Article 9, employers with 100 or more workers must report on their gender pay gap, and if a gap of over 5% is identified and not justified, they must conduct a joint pay assessment with workers' representatives under Article 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-30414-human-capital-rep",
      "ilo-core-conventions",
      "eu-whistleblower-directive-2019"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-pay-transparency-directive-2023-970-article-10-joint-pay-assessment",
    "title": "EU Pay Transparency Directive (EU) 2023/970 - Article 10: Joint Pay Assessment Obligation",
    "domain": "Workplace",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 10 of the EU Pay Transparency Directive (2023/970) requires employers to conduct a joint pay assessment with workers' representatives where the Article 9 pay gap report reveals an unjustified gender pay gap exceeding 5% in any category of workers. The joint pay assessment is a structured process carried out in cooperation with workers' representatives. It must identify the causes of the pay gap, assess proportions of male and female workers in different categories, compare pay levels and career development, assess the impact of flexible working and career breaks, and develop measures to address the gaps. The assessment must result in corrective measures with a specific implementation plan agreed with workers' representatives. The corrective measures must be implemented within a reasonable period and their impact monitored in subsequent Article 9 reports. Workers and their representatives must have access to all data and methodology used in the joint pay assessment. Member state transposition deadline is 7 June 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-pay-transparency-directive-2023-970-article-9-pay-reporting-obligations",
      "eu-pay-transparency-directive-2023-970-article-7-right-to-information-workers"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-pay-transparency-directive-2023-970-article-7-right-to-information-workers",
    "title": "EU Pay Transparency Directive (EU) 2023/970 - Article 7: Right of Workers to Receive Pay Information",
    "domain": "Workplace",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 7 of the EU Pay Transparency Directive (2023/970) grants workers an individual right to receive information about their own pay and about the average pay levels for workers performing the same work or work of equal value, broken down by sex. Workers may request this information at any time. Employers must respond in writing within a reasonable period not exceeding two months. Employers must annually inform all workers of their right to receive this information and of the procedure to request it. Workers who have requested pay information are protected against victimisation. The pay information right applies to all workers covered by the Directive - including those engaged through agencies or intermediaries. Employers must not contractually restrict workers from disclosing their own pay to other workers. Pay secrecy clauses preventing workers from revealing their salary are void. Member states must transpose by 7 June 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-pay-transparency-directive-2023-970-article-9-pay-reporting-obligations"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-pay-transparency-directive-2023-970-article-9-pay-reporting-obligations",
    "title": "EU Pay Transparency Directive (EU) 2023/970 - Article 9: Pay Reporting Obligations for Employers",
    "domain": "Workplace",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 9 of the EU Pay Transparency Directive (2023/970) establishes mandatory pay gap reporting obligations for employers, tiered by workforce size. Employers with 250 or more workers must report annually. Employers with 150-249 workers must report every three years. Employers with 100-149 workers must report every three years starting from 7 June 2031. Employers with fewer than 100 workers may be required to report under national law. Reports must cover: (1) the gender pay gap; (2) the gender pay gap in complementary or variable pay components; (3) the median gender pay gap; (4) the median gender pay gap in complementary or variable components; (5) the proportion of female and male workers receiving complementary or variable pay; (6) the proportion of female and male workers in each quartile pay band; (7) the gender pay gap between female and male workers per each category of workers, broken down by ordinary basic wage or salary and complementary or variable pay components. Reports are published and made accessible to workers, their representatives, and the public. Where a pay gap exceeds 5% in any worker category and cannot be justified by objective, gender-neutral criteria, a joint pay assessment must be conducted.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-pay-transparency-directive-2023-970-article-7-right-to-information-workers"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-pay-transparency-directive-2023-970-gender-pay-gap-reporting",
    "title": "EU Pay Transparency Directive 2023/970 - Gender Pay Gap Reporting, Right to Pay Information, and Equal Pay Enforcement",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Directive (EU) 2023/970 strengthens the right to equal pay for equal work by requiring workers' right to information on individual pay and pay ranges, mandatory gender pay gap reporting (250+ employees annually; 150+ biannually; 100+ every 3 years), joint pay assessments triggered by unexplained gaps >5%, prohibition on pay secrecy clauses, and ban on asking about pay history during recruitment. Member states must transpose by 7 June 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-payment-accounts-directive-2014-92",
    "title": "EU Payment Accounts Directive 2014/92/EU (PAD) - Basic Bank Account Right & Fee Transparency",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive 2014/92/EU (PAD) guarantees EU residents the right to open a basic payment account at a credit institution regardless of nationality, residence status, or financial situation. It mandates an 18-business-day switching service between payment accounts within the same Member State, requires standardised fee terminology (list of most representative services, Fee Information Document, Statement of Fees), and prohibits discrimination on grounds of nationality or place of residence. The EBA maintains a standardised list of terms across the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-psd2-strong-customer-authentication"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-payment-accounts-directive-2014-92-fee-disclosure",
    "title": "Directive 2014/92/EU of the European Parliament and of the Council of 23 October 2014 on transparent and comparable information on retail banking services, amending Directive 2009/110/EC and repealing Directive 2007/64/EC",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive requires credit institutions to provide clear, standardized, and comparable information on fees for payment accounts to retail customers across the EU. It mandates the provision of a Fee Information Document (Article 5), a comparison website (Article 6), access to basic bank accounts (Article 11), and a fast account switching service (Article 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "eu-omnibus-directive-2019-2161",
      "iso-10002-2018-customer-satisfaction-complaints",
      "bpmn-2-0-omg-specification-workflow-notation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-payment-services-directive-2-2015-2366",
    "title": "EU Payment Services Directive 2 (PSD2) -- Open Banking and Strong Customer Authentication",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-13",
    "bluf": "Directive (EU) 2015/2366 (PSD2) governs payment services in the EU, replacing PSD1 (2007/64/EC). It introduces mandatory open banking access-to-account (XS2A) for licensed Payment Initiation Service Providers (PISPs) and Account Information Service Providers (AISPs) via Article 66-67. Strong Customer Authentication (SCA) under Article 97 requires two independent elements from knowledge, possession, and inherence, implemented via Commission Delegated Regulation 2018/389 (RTS on SCA and CSC). Liability for unauthorised transactions is limited to EUR 50 for the payer except where the payer acted fraudulently or with gross negligence (Article 74). ASPSPs must provide a dedicated open banking interface or fallback access under Article 32 of RTS 2018/389. Payment service providers must acknowledge complaints within 15 business days and resolve within 35 business days (exceptional circumstances) under Article 101. The 13-month look-back rule for disputed transactions applies under Article 72.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-regulation-2013-575",
      "eu-electronic-communications-code-2018-1972",
      "eu-data-governance-act-2022-868"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-payment-services-directive-2-gaming-deposits",
    "title": "Directive (EU) 2015/2366 on payment services (PSD2) - Requirements for Gaming Deposit Transactions",
    "domain": "Gaming & Gambling",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive (EU) 2015/2366 (PSD2) obliges payment service providers to apply Strong Customer Authentication (SCA) to all electronic payments including online gaming deposits under Article 97, and to refund unauthorised or incorrectly executed transactions under Articles 73 and 88; exemptions to SCA are listed in the Commission Delegated Regulation (EU) 2018/389 Regulatory Technical Standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-pepp-regulation-2019-1238",
    "title": "EU PEPP Regulation 2019/1238 - Pan-European Personal Pension Product",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2019/1238 creates a standardised pan-European personal pension product (PEPP) with a 1% annual cost cap on the Basic PEPP, portability across EU member states without loss of tax treatment, switching rights after 5 years, and mandatory KID disclosure of maximum 3 pages. EIOPA maintains a central PEPP register. PEPP became available from 22 March 2022.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-iorp-ii-directive-2016-2341-occupational-pensions",
      "eu-ucits-directive-2009-65",
      "eu-priips-regulation-1286-2014-kid"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-personal-protective-equipment-regulation-2016-425",
    "title": "Regulation (EU) 2016/425 of the European Parliament and of the Council of 9 March 2016 on personal protective equipment",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down requirements for the design and manufacture of personal protective equipment (PPE) to be made available on the market, to ensure protection of the health and safety of users and free movement (Articles 1 and 4). PPE must meet the essential health and safety requirements set out in Annex II (Article 5), is classified by risk category determining the conformity assessment, and the Regulation imposes obligations on manufacturers (Article 8), authorised representatives (Article 9), importers (Article 10) and distributors (Article 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-market-surveillance-regulation-2019-1020-auto",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-pesticides-mrls-regulation-396-2005-depth",
    "title": "Regulation (EC) No 396/2005 of the European Parliament and of the Council of 23 February 2005 on maximum residue levels of pesticides in or on food and feed of plant and animal origin and amending Council Directive 91/414/EEC",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes maximum residue levels (MRLs) for pesticides in food and feed of plant and animal origin across the EU, ensuring a high level of consumer protection and facilitating internal market functionality. It applies to all operators involved in the production, import, and distribution of food and feed, requiring compliance with MRLs set in accordance with good agricultural practice and risk assessments by the European Food Safety Authority under Article 6 and Article 22.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-law-178-2002",
      "eu-food-hygiene-regulation-852-2004",
      "codex-alimentarius-general-principles-hygiene-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-pesticides-regulation-1107-2009",
    "title": "EU Pesticides Regulation (EC) 1107/2009",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Regulation (EC) 1107/2009 establishes the framework for the authorisation of active substances and the placing on the EU market of plant protection products (PPPs / pesticides). Active substances are approved at EU level by Commission Implementing Regulation following EFSA scientific opinion; products are authorised at Member State level under zonal procedure (Northern Central Southern). Approval is subject to safety criteria including human and animal health environmental criteria and exclusion criteria for substances classified as carcinogenic mutagenic toxic for reproduction or endocrine disruptors. Authorisations expire and are renewed periodically.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-pharma-gcp-directive-2005-28-clinical-trials-conduct",
    "title": "EU GCP Directive 2005/28/EC and Clinical Trials Regulation 536/2014 - Good Clinical Practice in Clinical Trials",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Good Clinical Practice (GCP) requirements established under Directive 2005/28/EC and now primarily governed by Clinical Trials Regulation (CTR) 536/2014 set the ethical and scientific quality standards for clinical trials in the EU. Core requirements include: ethics committee opinion and member state authorisation before trial commencement; informed consent from participants; trial conduct in compliance with the approved protocol; trial master file and investigator site file maintenance; serious adverse event (SAE) and suspected unexpected serious adverse reactions (SUSARs) reporting; GCP compliance inspections by national competent authorities; and registration in the EU Clinical Trials Information System (CTIS).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-pharma-regulation-2022-0134-article-5-marketing-authorisation",
      "eu-gdpr-health-data-article-9"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-pharma-regulation-2022-0134-article-5-marketing-authorisation",
    "title": "EU Pharmaceutical Regulation (2022/0134) - Article 5: Marketing Authorisation Requirements",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Pharmaceutical Regulation (proposed, replacing Directive 2001/83/EC) Article 5 maintains the core requirement that no medicinal product may be placed on the EU market without a marketing authorisation (MA) granted by the European Medicines Agency (EMA) under the centralised procedure or by a national competent authority under national procedures. The MA application must include full pharmaceutical, non-clinical, and clinical data demonstrating quality, safety, and efficacy. The revised Regulation introduces environmental risk assessment as a mandatory MA application component and strengthens post-authorisation monitoring obligations. EMA and national competent authorities jointly enforce MA compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ema-centralised-procedure-regulation-726-2004",
      "eu-gmp-annex-1-sterile-manufacture-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-pharmacovigilance-directive-2010-84-eu",
    "title": "Directive 2010/84/EU of the European Parliament and of the Council of 19 January 2010 amending, as regards pharmacovigilance, Directive 2001/83/EC on the Community code relating to medicinal products for human use",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive establishes a robust pharmacovigilance system for medicinal products in the EU, mandating marketing authorization holders (MAHs) to monitor, report, and manage adverse drug reactions. Key obligations include submission of Individual Case Safety Reports (ICSRs), Periodic Safety Update Reports (PSURs), Risk Management Plans (RMPs), and participation in signal detection activities via the Pharmacovigilance Risk Assessment Committee (PRAC) under Article 107c of Directive 2001/83/EC as amended.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gmp-annex-1-sterile-manufacture-2022",
      "ich-q10-pharmaceutical-quality-system-2008",
      "fda-21-cfr-part-314-nda-new-drug-application"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-pharmacovigilance-implementing-regulation-2025-1466",
    "title": "Commission Implementing Regulation (EU) 2025/1466 of 22 July 2025 amending Implementing Regulation (EU) No 520/2012 on the performance of pharmacovigilance activities provided for in Regulation (EC) No 726/2004 and Directive 2001/83/EC",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "This Implementing Regulation amends the pharmacovigilance performance rules in Regulation (EU) No 520/2012: it limits Pharmacovigilance System Master File deviation documentation to major or critical deviations, strengthens audit and inspection duties over subcontractors and third parties, clarifies signal validation timelines and EudraVigilance monitoring, updates the ISO IDMP electronic standards and requires DOIs for literature references, and applies from 12 February 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-pharmacovigilance-directive-2010-84-eu",
      "eu-pharmacovigilance-regulation-1235-2010",
      "ich-e2e-pharmacovigilance-planning-2004"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-pharmacovigilance-regulation-1235-2010",
    "title": "Regulation (EU) No 1235/2010 of the European Parliament and of the Council of 15 December 2010 amending, as regards pharmacovigilance of medicinal products for human use, Regulation (EC) No 726/2004 laying down Community procedures for the authorisation and supervision of medicinal products for human and veterinary use and establishing a European Medicines Agency, and Regulation (EC) No 1394/2007 on advanced therapy medicinal products",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation strengthens and rationalizes the EU system for monitoring the safety of medicines by establishing the Pharmacovigilance Risk Assessment Committee (PRAC) and mandating centralized procedures for signal detection, single assessments for Periodic Safety Update Reports (PSURs), and post-authorisation safety studies (PASS). It applies to marketing authorisation holders and competent authorities within the EU, as detailed in the amendments to Regulation (EC) No 726/2004, particularly Article 57.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-pharmacovigilance-regulation-1235-2010-psur",
    "title": "Commission Regulation (EU) No 1235/2010 of 15 December 2010 amending, as regards pharmacovigilance of medicinal products for human use, Regulation (EC) No 726/2004, Regulation (EC) No 1394/2007, Directive 2001/83/EC and Directive 2001/82/EC",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires marketing authorisation holders to submit periodic safety update reports (PSURs) to the European Medicines Agency, as outlined in Article 28a of Directive 2001/83/EC. It applies to all medicinal products for human use authorised in the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-gcp-e6-r3-2023",
      "iso-13485-qms"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-plant-health-regulation-2016-2031",
    "title": "EU Plant Health Regulation 2016/2031 on protective measures against pests of plants",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "This regulation establishes rules to determine phytosanitary risks posed by pests (including pathogenic agents, animals, or parasitic plants) and measures to reduce those risks to an acceptable level. It covers the identification and classification of Union quarantine pests and protected zone quarantine pests, as well as priority pests for which the most severe economic, social, or environmental impact is expected. Professional operators must notify competent authorities upon suspicion or confirmation of a Union quarantine pest and take eradication measures such as withdrawal or recall. Member States must carry out surveys and establish multiannual survey programmes for early detection. The regulation requires phytosanitary certificates for introduction of certain plants, plant products, or other objects from third countries, and plant passports for movement within the Union territory for listed items. It mandates registration of professional operators, record-keeping for at least three years, and traceability protocols. The Commission is empowered to adopt delegated acts for listing priority pests, establishing protected zones, and setting requirements for wood packaging material in line with ISPM15. The regulation repeals several earlier directives (69/464/EEC, 74/647/EEC, 93/85/EEC, 98/57/EC, 2000/29/EC, 2006/91/EC, 2007/33/EC) and amends Regulations No 228/2013, No 652/2014, and No 1143/2014. It respects fundamental rights including respect for private and family life, right to property, and protection of personal data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-plant-protection-products-regulation-1107-2009",
    "title": "Regulation 1107/2009 concerning the placing of plant protection products on the market and repealing Directives 79/117/EEC and 91/414/EEC",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Regulation (EC) No 1107/2009 establishes a harmonised framework for the approval of active substances, safeners, synergists, and co-formulants, and for the authorisation, placing on the market, use, and control of plant protection products within the European Union. The regulation aims to ensure a high level of protection for human and animal health and the environment, while improving the functioning of the internal market and agricultural production. It is underpinned by the precautionary principle, requiring that substances or products placed on the market do not adversely affect health or the environment. The regulation defines clear approval criteria for active substances (Article 4), establishes a detailed approval procedure including application submission (Article 7), dossier requirements (Article 8), and evaluation by a rapporteur Member State and the European Food Safety Authority (EFSA). First approval for an active substance is for a period not exceeding 10 years (Article 5), with renewal possible for up to 15 years (recital 15). Authorisation of plant protection products is granted by Member States (Article 1), with mutual recognition facilitated across three defined zones (Annex I). The regulation also includes specific rules for low-risk substances, candidates for substitution, data protection (Article 59), minimisation of vertebrate animal testing, record-keeping, advertising, and parallel trade. It repeals and replaces Council Directives 79/117/EEC and 91/414/EEC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-plastic-pellet-losses-prevention-regulation-2025-2365",
    "title": "Regulation (EU) 2025/2365 of the European Parliament and of the Council of 12 November 2025 on preventing plastic pellet losses to reduce microplastic pollution",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down requirements for the handling of plastic pellets at installations and in transport to prevent and reduce losses of plastic pellets to the environment (Article 1). It imposes general obligations on economic operators handling plastic pellets to prevent, contain and clean up spills (Article 3), requires non-EU carriers to designate authorised representatives (Article 4), provides for compliance through certification (Article 6), permits (Article 7) or environmental management systems (Article 8), and sets specific obligations for the transport of plastic pellets by sea in freight containers (Article 12), with verification, reporting, incident handling and penalties (Articles 13, 14 and 20).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-sup-single-use-plastics-2019-904",
      "eu-deforestation-regulation-2023-1115"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-platform-to-business-regulation-2019-1150",
    "title": "Regulation (EU) 2019/1150 of the European Parliament and of the Council of 20 June 2019 on promoting fairness and transparency for business users of online intermediation services",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires providers of online intermediation services (e.g., marketplaces, app stores) and online search engines to ensure fairness and transparency for their business users. Key obligations include clear terms and conditions (Article 3), disclosure of main ranking parameters (Article 5), and the establishment of an internal complaint-handling system (Article 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeepers",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-platform-to-business-regulation-2019-1150-p2b",
    "title": "Regulation (EU) 2019/1150 on promoting fairness and transparency for business users of online intermediation services and online search engines",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The EU P2B Regulation 2019/1150 requires online platforms and search engines to provide clear, transparent, and non-discriminatory terms to business users, including disclosure of ranking parameters (Article 6), prior notice of changes (Article 4), and effective internal complaint handling systems (Article 9). It applies to providers of online intermediation services and online search engines operating in the EU that enable business users to offer goods or services to consumers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-digital-markets-competition-consumers-act-2024-dmcc",
      "oecd-competition-digital-economy-roundtable-2023",
      "eu-state-aid-articles-107-108-tfeu-framework"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-platform-work-directive-2024",
    "title": "Directive (EU) 2024/2831 of the European Parliament and of the Council of 24 September 2024 on improving working conditions in platform work and amending Directive (EU) 2019/1152",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This directive establishes a legal presumption of an employment relationship for platform workers when facts indicating control and direction are present (Article 4) and introduces new rights regarding algorithmic management, including human review of significant decisions and enhanced transparency for workers (Articles 6-12). It applies to all digital labour platforms providing services in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "iso-45001-work-safety",
      "iso-30414-human-capital-rep",
      "unesco-ai-ethics-work"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-platform-work-directive-2024-2831",
    "title": "EU Platform Work Directive 2024/2831",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2024-12-01",
    "bluf": "Directive (EU) 2024/2831, entered into force 1 December 2024 with a transposition deadline of 2 December 2026, establishes a rebuttable presumption of employment status for platform workers where the digital labour platform controls the work relationship, and imposes mandatory algorithmic management transparency, human review rights for automated decisions, and information obligations for platform-based work.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-whistleblowing-directive-2019-1937",
        "uk-data-protection-act-2018",
        "eu-artificial-intelligence-act-2024-1689"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-whistleblowing-directive-2019-1937",
      "uk-data-protection-act-2018",
      "eu-artificial-intelligence-act-2024-1689"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-platform-work-directive-2024-2831-algorithmic-management-transparency",
    "title": "EU Platform Work Directive 2024/2831 - Algorithmic Management and Transparency for Platform Workers",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive (EU) 2024/2831 on improving working conditions in platform work establishes an employment status presumption for platform workers and imposes obligations on digital labour platforms regarding algorithmic management transparency, human oversight of automated decisions, and restrictions on processing sensitive personal data of platform workers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-6-lawful-basis-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-platform-work-directive-2024-2831-article-5-rebuttable-presumption-employment",
    "title": "EU Platform Work Directive (EU) 2024/2831 - Article 5: Rebuttable Presumption of Employment Relationship for Platform Workers",
    "domain": "Workplace",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 5 of the EU Platform Work Directive (2024/2831) establishes a rebuttable presumption of an employment relationship between a digital labour platform and a person performing platform work, when the facts indicating control and direction are met. Member states must ensure that the legal presumption applies when a platform meets at least two out of five control indicators: (1) effectively determining the level of remuneration or setting upper limits; (2) requiring the person to comply with specific binding rules on appearance, conduct, or performance; (3) supervising performance or verifying quality including by electronic means; (4) effectively restricting freedom to organise work including as to time or location; (5) effectively restricting the ability to build a client base or work for third parties. When the presumption applies, the burden of proof shifts to the platform to demonstrate the relationship is not employment. The presumption is activated in legal and administrative proceedings related to the classification of platform workers. Member state transposition deadline is 2 December 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-platform-work-directive-2024-2831-article-7-human-oversight-algorithmic-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-platform-work-directive-2024-2831-article-7-human-oversight-algorithmic-management",
    "title": "EU Platform Work Directive (EU) 2024/2831 - Article 7: Algorithmic Management Transparency and Human Oversight for Platform Workers",
    "domain": "Workplace",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 7 of the EU Platform Work Directive (2024/2831) imposes transparency and human oversight obligations on digital labour platforms using automated monitoring or decision-making systems. Platforms must inform platform workers (and their representatives) of: (a) the use of automated monitoring systems that collect data about workers' conduct, location, or performance; (b) automated decision-making systems capable of taking or supporting decisions materially affecting working conditions, access to work assignments, earnings, safety, or legal status. The required information includes the main parameters used by algorithmic systems, the weight and importance of those parameters, and how they affect workers. Platforms must designate at least one contact person for human review of automated decisions. Workers have the right to request human review of any decision significantly affecting them, to receive an explanation of that decision, and to contest it. Platforms cannot take any decision solely by automated means where it significantly affects the legal or employment status of a platform worker - these decisions require human review and explanation. Member state transposition deadline is 2 December 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-platform-work-directive-2024-2831-article-5-rebuttable-presumption-employment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-platform-workers-directive-2024",
    "title": "Directive (EU) 2024/2831 of the European Parliament and of the Council of 24 September 2024 on improving working conditions in platform work and amending Directive (EU) 2019/1152",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-07-22",
    "bluf": "This Directive establishes a legal presumption of an employment relationship for platform workers when control is exercised by the digital labour platform, and introduces new rights for workers regarding the use of automated monitoring and decision-making systems. Key provisions include the rebuttable legal presumption (Article 4) and rights to information, human review, and contestation of automated decisions (Articles 6-11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gdpr-binding-corporate-rules",
      "eu-whistleblower-directive-2019",
      "us-nlra-section-7-ai-monitoring",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-platform-workers-directive-2024-operations",
    "title": "Directive (EU) 2024/2831 of the European Parliament and of the Council of 14 November 2024 on improving the working conditions of platform workers and amending Council Directive 91/533/EEC",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The EU Platform Work Directive 2024 establishes a legal presumption of employment for platform workers where algorithmic management is used and specific control criteria are met, applies to digital labour platforms operating in the EU, and mandates transparency in automated decision-making, human oversight of significant algorithmic decisions, and clear communication of system functionality to workers under Article 4 and Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-p2b-regulation-2019-1150",
      "eu-consumer-rights-directive-2011",
      "iso-15489-1-2016-records-management-workflow",
      "bpmn-2-0-omg-specification-workflow-notation",
      "iso-10002-2018-customer-satisfaction-complaints"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-pnr-passenger-name-record-directive-2016-681",
    "title": "Directive (EU) 2016/681 of the European Parliament and of the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive regulates the transfer by air carriers of passenger name record (PNR) data of extra-EU flights and its processing by Member States for the prevention, detection, investigation and prosecution of terrorist offences and serious crime (Article 1). Each Member State must establish a Passenger Information Unit (Article 4) with a data protection officer (Article 5), process PNR data only for the defined purposes against pre-determined criteria and databases (Article 6), restrict access to designated competent authorities (Article 7), and impose transfer obligations on air carriers (Article 8), with strict retention limits and data-protection safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-schengen-borders-code-regulation-2016-399",
      "eu-data-governance-act-2022-868"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-political-advertising-transparency-regulation-2024-900",
    "title": "Regulation (EU) 2024/900 of the European Parliament and of the Council of 13 March 2024 on the transparency and targeting of political advertising",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down harmonised transparency and targeting rules for political advertising in the EU (Article 1). It applies to political advertising prepared, placed, promoted, published or disseminated in the Union (Article 2), requires that political advertising be clearly identifiable as such with a transparency notice (Articles 7 and 8), imposes transparency and due-diligence obligations on political advertising service providers (Article 6), requires record-keeping (Article 9), and restricts targeting and ad-delivery techniques based on personal data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-dsm-directive-2019-790",
      "eu-data-governance-act-2022-868"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-port-services-regulation-article-11-charges-for-port-infrastructure",
    "title": "Regulation (EU) 2017/352 - Article 11: Transparency of financial relations",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations receiving public funds for port services must maintain a transparent accounting system that clearly separates and identifies the source, allocation, and use of those funds across different port-related activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-port-services-regulation-article-13-transparency-financial-relations",
    "title": "Regulation (EU) 2017/352 - Article 13: Port infrastructure charges",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that Member States levy a port infrastructure charge, sets rules for its structure and level, and requires port managing bodies to transparently inform users about charges and any changes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-port-services-regulation-article-17-complaints-procedure",
    "title": "Regulation (EU) 2017/352 of the European Parliament and of the Council - Article 17 Relevant authorities",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Member States must ensure port users and stakeholders are informed of relevant authorities, notify the Commission of these authorities and any subsequent changes, and the Commission must publish this information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-port-services-regulation-article-21-workers-rights",
    "title": "Regulation (EU) 2017/352 on establishing a framework for the provision of port services and common rules on the financial transparency of ports - Article 21: Transitional measures",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must amend any port service contracts concluded before 15 February 2017 that are not limited in time to ensure they comply with this Regulation by the deadline of 1 July 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-port-services-regulation-article-24-penalties",
    "title": "REGULATION (EU) 2017/352 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 15 February 2017 establishing a framework for the provision of port services and common rules on the financial transparency of ports - Article 24 Penalties",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations must be aware of and comply with the effective, proportionate, and dissuasive penalties established by Member States for infringements of this Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-port-services-regulation-article-3-definitions",
    "title": "Regulation (EU) 2017/352 on establishing a framework for the provision of port services and common rules on the financial transparency of ports - Article 3: Organisation of port services",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article outlines the potential conditions that may be imposed on port service providers for market access and mandates that terms of access to port facilities must be fair, reasonable, and non-discriminatory.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-port-services-regulation-article-4-freedom-to-provide-port-services",
    "title": "Regulation (EU) 2017/352 on port services and financial transparency of ports - Article 4: Minimum requirements",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article allows port authorities to set transparent, objective, and non-discriminatory minimum requirements for port service providers, covering areas like professional qualifications, financial capacity, equipment, safety, and environmental compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-port-services-regulation-article-6-market-access-port-services",
    "title": "Regulation (EU) 2017/352 on establishing a framework for the provision of port services and common rules on the financial transparency of ports - Article 6: Limitations on the number of providers of port services",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article permits the managing body of a port or a competent authority to optionally limit the number of port service providers based on specific reasons, such as scarcity of space or obstruction of public service obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-port-services-regulation-article-8-requirements-public-service-obligations",
    "title": "Regulation (EU) 2017/352 on establishing a framework for the provision of port services and common rules on the financial transparency of ports - Article 8: Internal operator",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article outlines the conditions under which a port's managing body or competent authority may provide port services through an 'internal operator', defining the necessary control and operational limitations for such an entity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-port-state-control-directive-2009-16",
    "title": "Directive 2009/16/EC of the European Parliament and of the Council of 23 April 2009 on port State control",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Directive establishes a harmonized EU-wide port State control (PSC) regime requiring all ships calling at EU ports to undergo risk-based inspections based on their ship risk profile (Article 5). It mandates expanded inspection powers, priority inspection for high-risk vessels (Article 7), and potential banning orders for repeated non-compliance (Article 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "imo-marpol-pollution"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-port-waste-reception-facilities-directive-2019-883",
    "title": "EU Port Reception Facilities Directive 2019/883 Ship Waste Delivery and No-Special-Fee System",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Directive (EU) 2019/883 requires EU ports to provide adequate reception facilities for all ship-generated waste, mandates a no-special-fee system for MARPOL Annex V waste (garbage) making delivery to port financially neutral, requires ships to pre-notify waste quantities 24 hours before arrival, and compels delivery of all waste before departure, with penalties for ships that discharge waste at sea to avoid port fees.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ship-recycling-regulation-1257-2013"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-postal-services-directive-1997-67-cx-obligations",
    "title": "EU Postal Services Directive 97/67/EC - Universal Service Obligation and Quality Standards",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Directive 97/67/EC on common rules for the development of the internal market of Community postal services, as amended by Directives 2002/39/EC and 2008/6/EC (full liberalisation by 2011), mandates that each Member State designate a universal service provider (USP) ensuring delivery of letters and parcels at least 5 days per week; requires D+1 quality targets of at least 85% for intra-national priority letters; sets consumer rights for lost or damaged postal items; and establishes national regulatory authorities (NRAs) for postal markets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-adr-directive-2013-11-alternative-dispute"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-posted-workers-directive-2018-957",
    "title": "Directive (EU) 2018/957 of the European Parliament and of the Council of 28 June 2018 amending Directive 96/71/EC on the posting of workers in the framework of the provision of services",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This directive requires employers posting workers from one EU Member State to another for service provision to comply with the host country’s hard-core working conditions, including minimum rates of pay, working time, and accommodation rules. Applies to all cross-border service providers under Article 3 and long-term postings exceeding 12 months under Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-fair-work-act-2009",
      "difc-employment-law-4-2021",
      "eeoc-employment-rule"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-posted-workers-directive-96-71-ec-amendment-2018-957",
    "title": "EU Posted Workers Directive 96/71/EC as Amended by 2018/957 - Equal Pay & Terms for Posted Workers",
    "domain": "Workplace",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "EU Posted Workers Directive 96/71/EC (amended 2018/957 from August 2020) ensures workers posted temporarily to another EU member state receive the same remuneration and working conditions as local workers - including collective agreements, after-12-month equal treatment, and host-state labour law protections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-posting-of-workers-enforcement-directive-2014-67",
    "title": "Directive 2014/67/EU of the European Parliament and of the Council of 15 May 2014 on the enforcement of Directive 96/71/EC concerning the posting of workers in the framework of the provision of services",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive establishes a framework to enforce the posting of workers Directive 96/71/EC and prevent abuse and circumvention (Article 1). It requires competent authorities and liaison offices (Article 3), criteria to identify a genuine posting and prevent abuse and letterbox practices (Article 4), improved access to information on terms and conditions of employment (Article 5), mutual assistance between Member States (Articles 6 and 7), administrative requirements and control measures (Article 9), inspections (Article 10), facilitation of complaints and back-payment of remuneration (Article 11), and sub-contracting liability for outstanding remuneration (Article 12).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-posted-workers-directive-2018-957",
      "eu-transparent-predictable-working-2019-1152"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ppwr-packaging-waste-2025-40",
    "title": "EU Packaging and Packaging Waste Regulation (EU) 2025/40 (PPWR)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Regulation (EU) 2025/40 (the Packaging and Packaging Waste Regulation PPWR) replaces Directive 94/62/EC with a comprehensive framework for packaging placed on the EU market. PPWR sets recyclability requirements (all packaging recyclable by 2030 with grade A/B/C performance grades) minimum recycled content (e.g., 30% rPET in plastic beverage bottles by 2030) packaging reduction targets (15% per capita by 2040) re-use targets by sector ban on certain single-use packaging formats (e.g., hotel mini toiletries from 2030 fruit/vegetable wrapping under 1.5kg in retail) and deposit-return scheme (DRS) for single-use plastic bottles and aluminium cans (90% separate collection by 2029).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-pregnant-workers-health-safety-directive-92-85",
    "title": "Council Directive 92/85/EEC of 19 October 1992 on the introduction of measures to encourage improvements in the safety and health at work of pregnant workers and workers who have recently given birth or are breastfeeding",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive introduces measures to improve the safety and health at work of pregnant workers and workers who have recently given birth or are breastfeeding (Article 1). It requires the assessment and communication of risks from agents, processes and working conditions (Articles 4 and 5), prohibits exposure to certain agents where there is a risk (Article 6), provides protection in respect of night work (Article 7), guarantees a continuous period of maternity leave (Article 8), grants time off for ante-natal examinations (Article 9), prohibits dismissal connected with the worker condition (Article 10), and safeguards employment rights including pay or an adequate allowance (Article 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-health-safety-framework-directive-89-391",
      "eu-work-life-balance-directive-2019-1158"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-press-publishers-right-directive-article-15",
    "title": "Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market and amending Directives 96/9/EC and 2001/29/EC - Article 15: Use of Protected Press Publications by Online Service Providers",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Article 15 of the EU Copyright Directive grants press publishers a two-year neighbouring right to authorize or prohibit online use of their press publications by information society service providers (e.g., news aggregators). Licensing is required unless the use consists solely of individual words or very short extracts, such as hyperlinks with minimal context. The right does not apply to private or non-commercial use, and journalists retain an inalienable right to equitable remuneration for reuse of their contributions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "berne-convention-1886-2024-literary-artistic-works",
      "dmca-safe-harbor",
      "iptc-photo-metadata"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-pressure-equipment-directive-2014-68",
    "title": "Directive 2014/68/EU of the European Parliament and of the Council of 15 May 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of pressure equipment",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Pressure Equipment Directive (PED) 2014/68 requires manufacturers, importers, and authorized representatives to ensure that pressure equipment (vessels, piping, safety accessories, and pressure accessories) with a maximum allowable pressure greater than 0.5 bar conforms to essential safety requirements before being placed on the EU market. Compliance is determined through categorization by hazard level (Article 4) and application of appropriate conformity assessment modules involving Notified Bodies where required.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-4-2-component-security-2019",
      "iec-62443-industrial-automation-security-standards",
      "isa-99-iec-62443-industrial-security-framework",
      "iso-55001-2014-asset-management-industrial",
      "iec-62351-power-systems-cybersecurity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-presumption-of-innocence-directive-2016-343",
    "title": "Directive (EU) 2016/343 of the European Parliament and of the Council of 9 March 2016 on the strengthening of certain aspects of the presumption of innocence and of the right to be present at the trial in criminal proceedings",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive lays down common minimum rules on the presumption of innocence and the right to be present at trial (Article 1). It applies to natural persons who are suspects or accused in criminal proceedings (Article 2), requires that they be presumed innocent until proven guilty (Article 3), prohibits public references to guilt before conviction (Article 4), governs the presentation of suspects (Article 5), places the burden of proof on the prosecution (Article 6), and protects the right to remain silent and not to incriminate oneself (Article 7) and the right to be present at trial (Article 8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-legal-aid-directive-2016-1919",
      "eu-procedural-safeguards-children-directive-2016-800"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-preventive-restructuring-directive-2019-1023",
    "title": "Directive (EU) 2019/1023 on Preventive Restructuring Frameworks (EU Restructuring Directive): Pre-Insolvency Moratorium, Cross-Class Cram-Down, 3-Year Debt Discharge for Entrepreneurs, and Second Chance Framework for Honest Debtors",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive (EU) 2019/1023 (Restructuring Directive), transposition deadline 17 July 2021 (with extensions to 17 July 2022 and, for specific provisions, 17 July 2024), harmonises preventive restructuring frameworks across the EU; key mechanisms include: preventive restructuring available to debtors not yet insolvent (likelihood of insolvency test); automatic moratorium on individual creditor enforcement actions for 4 months (extendable up to 12 months and up to 12+4 months with judicial authorisation); cross-class cram-down allowing a restructuring plan to bind dissenting creditor classes (Article 11) if confirmed by national court applying the best interest of creditors test and at least one non-out-of-the-money class approves; entrepreneurs discharged from all remaining debts within 3 years of commencement of discharge proceedings (Article 21); best interest of creditors test requires that no creditor be worse off under the plan than under the relevant alternative (liquidation value); Member States may maintain or introduce procedures more favourable to debtors where consistent with the Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_INSOLVENCY_REGULATION",
        "EU_CORPORATE_GOVERNANCE",
        "UNCITRAL_INSOLVENCY",
        "EU_COMPETITION"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-competition-regulation-1-2003",
      "eu-merger-regulation-139-2004"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-price-indication-directive-1998",
    "title": "Directive 98/6/EC of the European Parliament and of the Council of 16 February 1998 on consumer protection in the indication of the prices of products offered to consumers, as amended by Directive (EU) 2019/2161",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This directive requires traders in the EU to clearly indicate the selling price and the price per unit of measurement (unit price) for products offered to consumers. Following the 2022 updates via the Omnibus Directive, any announcement of a price reduction must now also display the lowest price charged for the product in the 30 days prior to the discount (Article 6a).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-omnibus-directive-2019-2161",
      "eu-consumer-rights-directive-2011"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-price-indication-directive-1998-2022-update",
    "title": "Directive 98/6/EC of the European Parliament and of the Council of 16 February 1998 on consumer protection in the indication of the prices of products offered to consumers, as amended by Directive (EU) 2019/2161 (Omnibus Directive on better enforcement and modernisation of Union consumer protection rules)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This directive requires all traders offering goods or services to consumers in the EU to display a mandatory 30-day reference price alongside any sale price (Article 6a as inserted by Directive (EU) 2019/2161), show per-unit prices for products of variable measure (Article 3 and Article 4), and applies to all businesses operating in the internal market as amended by Directive (EU) 2019/2161.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-price-indication-directive-1998",
      "eu-unfair-commercial-practices-2005-29",
      "eu-ecommerce-directive-2000-31",
      "eu-geo-blocking-regulation-2018-302"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "eu-priips-regulation-1286-2014-kid",
    "title": "Regulation (EU) No 1286/2014 of the European Parliament and of the Council of 26 November 2014 on key information documents for packaged retail and insurance-based investment products (PRIIPs)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires manufacturers of Packaged Retail and Insurance-based Investment Products (PRIIPs) to produce a standardized, pre-contractual Key Information Document (KID) for retail investors in the European Economic Area. As mandated by Article 5, the KID must enable investors to understand and compare the key features, risks, costs, and potential gains and losses of the product.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fca-consumer-duty-2023"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-procedural-safeguards-children-directive-2016-800",
    "title": "Directive (EU) 2016/800 of the European Parliament and of the Council of 11 May 2016 on procedural safeguards for children who are suspects or accused persons in criminal proceedings",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive lays down common minimum rules on the rights of children who are suspects or accused in criminal proceedings (Article 1), applying to persons under 18 (Article 3). Children have the right to information (Article 4), the right to have the holder of parental responsibility informed (Article 5), mandatory assistance by a lawyer (Article 6), the right to an individual assessment of their needs (Article 7), a right to a medical examination where deprived of liberty (Article 8), and audiovisual recording of questioning (Article 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-legal-aid-directive-2016-1919",
      "eu-presumption-of-innocence-directive-2016-343"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-product-liability-directive-2022-revision",
    "title": "Proposal for a Directive of the European Parliament and of the Council on liability for defective products - Revision of Directive 85/374/EEC",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The revised EU Product Liability Directive establishes strict liability for producers of defective products, including software and AI systems, where damage arises from a defect. It extends liability coverage to include data corruption and certain types of pure economic loss (Article 1), and introduces a rebuttable presumption of causation where AI system opacity prevents claimants from proving fault (Article 7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "eu-omnibus-directive-2019-2161",
      "iso-10002-2018-customer-satisfaction-complaints",
      "iso-15489-1-2016-records-management-workflow"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-product-liability-directive-2024",
    "title": "Directive (EU) 2024/2853 of the European Parliament and of the Council of 11 September 2024 on liability for defective products",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This directive establishes a strict, no-fault liability regime for economic operators whose defective products, including software and AI systems, cause material damage to a natural person, as defined in Article 4. It introduces rules for the disclosure of evidence and alleviates the burden of proof for claimants in complex cases, particularly those involving AI systems (Article 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-high-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-product-liability-directive-2024-2853",
    "title": "Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products and repealing Council Directive 85/374/EEC (Text with EEA relevance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Directive establishes strict liability for economic operators for damage caused by defective products, including software and AI systems, and introduces reversal of the burden of proof in cases of technical complexity under Article 7. It applies to all producers, importers, and authorized representatives placing products on the EU market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-open-science-policy-fair-data-principles-2021",
      "ai-ip-copyright"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-product-liability-directive-2024-2853-defective-products-ai",
    "title": "EU Product Liability Directive 2024/2853 - Defective Product Liability Including AI and Software",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive (EU) 2024/2853 modernises the original 1985 Product Liability Directive to cover digital products including AI systems, software, and connected devices, introduces a rebuttable presumption of defectiveness for disclosure failures, extends the liability period to 10 years, removes the 500 EUR damage threshold, broadens the concept of damage to include psychological harm and data destruction, and grants courts power to order defendant disclosure of technical evidence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-product-liability-directive-2024-revision",
    "title": "Directive (EU) 2024/2853 of the European Parliament and of the Council of 24 October 2024 on liability for defective products, amending Regulation (EU) 2023/988 and repealing Council Directive 85/374/EEC",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Directive expands product liability to cover software, AI systems, and digital services, imposes a reversed burden of proof in cases involving complex technologies (Article 8), removes financial caps on damages, establishes a 10-year limitation period (Article 15), and holds non-EU economic operators liable if their products are placed on the EU market (Article 12). It applies to all producers, importers, and distributors placing digital or physical goods into the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29",
      "eu-ecommerce-directive-2000-31",
      "eprivacy-cookie-directive",
      "ama-ethical-marketing",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-products-liability-directive-2022-iot-update",
    "title": "Proposal for a Directive of the European Parliament and of the Council on liability for defective products, repealing Council Directive 85/374/EEC",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive establishes strict liability for producers of defective products, including software and digital services when integrated into physical goods, and extends liability coverage to include damage caused by defective digital products and AI-enabled IoT devices in the energy and industrial sectors. Key provisions include liability for AI-driven malfunctions and data corruption under Article 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cyber-resilience-act-iot-2024-products",
      "etsi-en-303-645-iot-cybersecurity-2020",
      "eu-data-act-2023-iot-data-sharing-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-professional-qualifications-directive-2005-36",
    "title": "EU Professional Qualifications Directive 2005/36 - Recognition of Qualifications, Sectoral Professions, and IMI System",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Directive 2005/36/EC of the European Parliament and of the Council on the recognition of professional qualifications (the PQD) establishes the framework for the recognition of professional qualifications among EU Member States. The Directive allows EU citizens to have their professional qualifications recognised in a Member State other than the one in which they obtained their qualifications in order to pursue a regulated profession. The Directive operates through three main systems: automatic recognition under Articles 21 to 49a for seven sectoral professions (doctors, dentists, nurses, midwives, pharmacists, veterinary surgeons, and architects), for which minimum training requirements are harmonised; the general system under Articles 10 to 15 for all other regulated professions, which involves recognition based on the principle of substantial equivalence; and the European Professional Card (EPC) under Article 4a, a voluntary electronic procedure for recognition in selected professions (nurses, pharmacists, physiotherapists, real estate agents, mountain guides). The Internal Market Information System (IMI) is the electronic platform used by competent authorities to exchange information on professional qualifications under Article 56. Directive 2013/55/EU amended the PQD to introduce the EPC, partial access under Article 4f, and to require Member States to complete a proportionality assessment before introducing or modifying a regulated profession.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_services_directive_2006_123",
        "uk_recognition_overseas_qualifications_act_2022",
        "eu_working_time_directive_2003_88",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-services-directive-2006-123",
      "eu-working-time-directive-2003-88",
      "eu-health-safety-framework-directive-89-391"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-prospectus-regulation-2017-1129",
    "title": "EU Prospectus Regulation 2017/1129 - Securities Offering and Admission to Trading Disclosure Framework",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Regulation (EU) 2017/1129 of the European Parliament and of the Council of 14 June 2017 on the prospectus to be published when securities are offered to the public or admitted to trading on a regulated market (the Prospectus Regulation), applicable from 21 July 2019, replaced the Prospectus Directive (2003/71/EC) with a directly applicable EU Regulation. The Prospectus Regulation requires issuers to publish a prospectus approved by the national competent authority (NCA) when making a public offer of securities or seeking admission to trading on a regulated market within the EEA, unless an exemption applies. Key exemptions include offers to fewer than 150 persons per Member State, offers to qualified investors, offers of securities worth less than €1 million (and optionally up to €8 million under national exemption), and secondary issuance simplifications. The Regulation introduces the EU Growth Prospectus for SMEs and secondary issuers, a simplified prospectus for secondary issuances by listed companies, a standardised EU Recovery Prospectus format, and passporting of approved prospectuses across the EEA without further approval by host NCAs. ESMA maintains a database of approved prospectuses accessible to investors throughout the EEA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_market_abuse_regulation",
        "eu_mifid_ii_markets",
        "eu_accounting_directive_2013_34"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-market-abuse-regulation-596-2014",
      "eu-accounting-directive-2013-34"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-psd2-api-open-banking-workflow-2015-2366",
    "title": "Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC (Text with EEA relevance)",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU PSD2 Directive mandates strong customer authentication (SCA) for electronic payments, grants third-party providers (AISPs and PISPs) access to bank account data and payment initiation via APIs (XS2A), and applies to all payment service providers operating in the European Economic Area. Key obligations are established under Article 97 and Article 98.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-directive-workflow-critical-operations",
      "eu-ai-act-automated-decision-workflows",
      "azure-logic-apps-enterprise-integration"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-psd2-open-banking-api-standards",
    "title": "EU PSD2 Open Banking API Access Standards - XS2A Framework and Berlin Group NextGenPSD2",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Berlin Group NextGenPSD2 framework provides a standardized API specification for European banks (ASPSPs) to grant Third-Party Providers (TPPs) secure access to customer accounts for information and payment initiation, fulfilling the Access to Account (XS2A) requirements under Article 30 of the EU's Regulatory Technical Standards (RTS) for PSD2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "psd2-sc-authentication",
      "eba-guidelines-ict-risk-2019",
      "dora-ict-risk-management-articles-5-16"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-psd2-rts-strong-customer-auth-2018",
    "title": "Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The regulation mandates that every remote electronic payment must be protected by strong customer authentication (SCA) that dynamically links the authentication code to the transaction amount and payee (see paragraph (3)) and sets detailed security requirements for knowledge, possession and inherence elements (see paragraph (6)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-psd2-strong-customer-authentication",
    "title": "Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation requires Payment Service Providers (PSPs) in the EU to apply Strong Customer Authentication (SCA) when a customer initiates an electronic payment, accesses their payment account online, or performs any action through a remote channel that may imply a risk of payment fraud. As per Article 4, SCA must use at least two independent elements from the categories of knowledge (something only the user knows), possession (something only the user possesses), and inherence (something the user is).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dora-ict-risk-management-articles-5-16",
      "eba-guidelines-ict-risk-2019",
      "eu-psd3-proposal-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-psd3-proposal-2023",
    "title": "Proposal for a Regulation on payment services in the internal market (PSR) and a Directive on payment services and electronic money services in the Internal Market (PSD3)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This proposal evolves PSD2 to enhance consumer protection, improve open banking competition, and strengthen enforcement by introducing stricter Strong Customer Authentication (SCA) rules, expanding data access for third-party providers (TPPs), and merging the legal frameworks for electronic money and payment services (PSR Article 1, PSD3 Article 1). It applies to all payment service providers (PSPs), including banks, e-money institutions, and payment institutions operating within the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "psd2-sc-authentication",
      "eba-outsourcing-guide",
      "bcbs-principles-operational-resilience",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-psr-2023",
    "title": "Proposal for a Regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes directly applicable rules for payment service providers (PSPs) in the EU, replacing PSD2 to combat payment fraud through enhanced Strong Customer Authentication (SCA) and new liability rules, and to improve open banking by clarifying access to payment accounts data (Article 86). It aims to level the playing field between banks and non-bank PSPs while strengthening consumer rights and information requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "psd2-sc-authentication",
      "dora-ict-risk-management-articles-5-16",
      "eu-aml-regulation-2024",
      "eba-guidelines-ict-risk-2019"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-public-cbcr-directive-2021-2101",
    "title": "Directive (EU) 2021/2101 of the European Parliament and of the Council of 24 November 2021 amending Directive 2013/34/EU as regards disclosure of income tax information by certain undertakings and branches",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-06-22",
    "bluf": "This directive mandates public country-by-country reporting (CbCR) of income tax information for multinational enterprises (MNEs) and standalone undertakings with total consolidated revenue exceeding EUR 750 million in each of the last two consecutive financial years, whether their ultimate parent is in the EU or not, as specified in Article 48b.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-public-cbcr-directive-2021-2101-tax-transparency",
    "title": "Directive (EU) 2021/2101 of the European Parliament and of the Council of 24 November 2021 amending Directive 2013/34/EU as regards disclosure of income tax information by certain undertakings and branches",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This directive requires multinational enterprises (MNEs) and standalone undertakings with total consolidated revenue exceeding €750 million for two consecutive financial years to publicly disclose corporate income tax information on a country-by-country basis. As per Article 48b, the report must detail revenues, profits, tax paid, and employee numbers for each EU jurisdiction and for jurisdictions on the EU's non-cooperative list.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-public-procurement-construction-2014-24",
    "title": "Directive 2014/24/EU of the European Parliament and of the Council of 26 February 2014 on public procurement and repealing Directive 2004/18/EC",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes harmonized rules for public procurement by contracting authorities in EU Member States for public works contracts exceeding specified financial thresholds. It mandates that contract awards must be based on the most economically advantageous tender (MEAT), which includes criteria like quality, price, technical merit, and life-cycle costing, as outlined in Article 67.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37001-anti-bribery"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-public-procurement-construction-directive",
    "title": "Directive 2014/24/EU of the European Parliament and of the Council of 26 February 2014 on public procurement and repealing Directive 2004/18/EC - Works Contracts Above Threshold: Technical Specifications, Selection Criteria, Award Criteria, Design Contests and Concession Contracts",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive governs public procurement of construction works above the EU threshold (€5,679,000 as of 2024) by requiring transparent technical specifications, objective selection and award criteria, and structured design contests. It applies to contracting authorities in EU member states awarding works contracts, as defined in Article 2(1) and detailed in Articles 24-67.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-21500-project-management-construction-guidance",
      "asce-7-22-minimum-design-loads-buildings",
      "iso-19650-bim-information-management-construction",
      "eu-circular-economy-construction-demolition-waste-2020",
      "ilo-safety-health-construction-convention-167-1988"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-public-procurement-directive-2014-24-construction",
    "title": "Directive 2014/24/EU of the European Parliament and of the Council of 26 February 2014 on public procurement and repealing Directive 2004/18/EC - Title III: Rules for Public Contracts, Chapter 2: Technical Specifications and Chapter 3: Award Criteria, specifically as applied to construction works contracts",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive establishes harmonized rules for public procurement of construction works contracts above EU-wide thresholds, requiring contracting authorities to define clear technical specifications (Article 40), ensure non-discrimination, apply objective award criteria (Article 67), and consider innovation and sustainability. It applies to all contracting authorities in EU Member States awarding construction contracts valued at or above EUR 5,595,000 (as of 2026, adjusted for inflation under Article 7(1)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-19650-bim-information-management-construction",
      "iso-21500-project-management-construction-guidance",
      "eu-circular-economy-construction-demolition-waste-2020",
      "iso-9001-2015-quality-management-construction",
      "us-ada-accessibility-guidelines-2010-aba"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-racial-equality-directive-2000-43",
    "title": "Council Directive 2000/43/EC of 29 June 2000 implementing the principle of equal treatment between persons irrespective of racial or ethnic origin",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive implements the principle of equal treatment between persons irrespective of racial or ethnic origin (Article 1). It defines direct and indirect discrimination and harassment (Article 2), applies to employment, vocational training, social protection, education and access to goods and services (Article 3), permits genuine and determining occupational requirements (Article 4) and positive action (Article 5), and provides for the defence of rights (Article 7), a shift in the burden of proof to the respondent (Article 8), protection against victimisation (Article 9), and effective, proportionate and dissuasive sanctions (Article 15).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-employment-equality-directive-2000-78",
      "un-icerd-1965-racial-discrimination"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-radiation-protection-bss-directive-2013-59",
    "title": "Council Directive 2013/59/Euratom of 5 December 2013 laying down basic safety standards for protection against the dangers arising from exposure to ionising radiation",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This directive establishes uniform basic safety standards for the protection of the health of individuals subject to occupational, medical and public exposures against the dangers arising from ionising radiation. It requires EU Member States to implement a system of radiation protection based on the principles of justification, optimisation and dose limitation, and mandates authorisation for practices involving radiation sources, as detailed in Chapter III.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "osha-work-safety-us"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-radio-equipment-directive-2014",
    "title": "Directive 2014/53/EU on Radio Equipment (RED) - Cybersecurity, Privacy, and Fraud Protection Requirements (Article 3.3 d, e, f)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The EU Radio Equipment Directive (RED), through Delegated Regulation (EU) 2022/30 activating Article 3.3 (d), (e), and (f), mandates that internet-connected radio equipment and certain wearables incorporate safeguards to protect network integrity, personal data, privacy, and prevent monetary fraud before being placed on the EU market, with enforcement beginning August 1, 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cybersecurity-act-2019",
      "iso-27001-2022",
      "nist-ir-8425-iot-core-baseline-profile"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-radio-equipment-directive-2014-53",
    "title": "EU Radio Equipment Directive 2014/53 - Essential Requirements, CE Marking, and Market Surveillance",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Directive 2014/53/EU of the European Parliament and of the Council on the harmonisation of the laws of Member States relating to the making available on the market of radio equipment (RED) became applicable on 13 June 2016 and replaced Directive 1999/5/EC (R&TTE Directive). The RED applies to all radio equipment - any electrical or electronic product that intentionally emits or receives radio waves for the purpose of radio communication or radio determination. Article 3 establishes the essential requirements that all radio equipment must meet: protection of health and safety of persons and domestic animals (EN 62368-1 and other harmonised standards), electromagnetic compatibility (EMC), and effective use of the radio spectrum. Article 10 sets out the obligations of manufacturers including preparation of technical documentation, application of the CE marking, drawing up an EU declaration of conformity, and ensuring that each item of radio equipment is accompanied by a copy of the EU declaration of conformity. Article 30 requires that the CE marking is affixed before the radio equipment is placed on the market. Where radio equipment uses frequency bands not harmonised in all Member States, Article 10(10) requires the equipment to be registered in a central database maintained by the Commission. Notified bodies may conduct conformity assessment for radio equipment where the manufacturer chooses to use a notified body under Annex III or Annex IV procedures instead of the manufacturer's own internal production control under Annex II.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_electronic_communications_code_2018_1972",
        "uk_radio_equipment_regulations_2017",
        "eu_emc_directive_2014_30",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electronic-communications-code-2018-1972",
      "eu-services-directive-2006-123",
      "uk-communications-act-2003"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-radio-equipment-directive-2014-53-cybersecurity",
    "title": "Commission Delegated Regulation (EU) 2022/30 of 12 November 2021 supplementing Directive 2014/53/EU of the European Parliament and of the Council as regards cybersecurity requirements for radio equipment",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Radio equipment placed on the EU market, including IoT devices, mobile phones, and wearables, must implement robust cybersecurity safeguards to ensure network resilience, protect user privacy, and prevent fraud, as required under Article 3(3) of Directive 2014/53/EU, as detailed in Commission Delegated Regulation (EU) 2022/30. Compliance is mandatory from August 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-radio-equipment-directive-2014-53-red",
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-nis2-telecoms-essential-services",
      "eu-5g-cybersecurity-toolbox-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-radio-equipment-directive-2014-53-iot",
    "title": "EU Radio Equipment Directive 2014/53/EU - Essential Requirements for IoT Wireless Devices and Cybersecurity Delegated Regulation (EU) 2022/30",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Directive requires that all IoT radio equipment placed on the EU market meet the essential health, safety and electromagnetic compatibility requirements (Article 3, Annex I) and, per Delegated Regulation (EU) 2022/30, incorporate a risk‑based cybersecurity design, documented risk assessment and a secure software‑update mechanism (Annex I, points 1.1‑1.3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "etsi-en-303-645-iot-cybersecurity-2020",
      "iec-62443-4-2-component-security-2019",
      "iec-62443-industrial-automation-security-standards",
      "edge-ai-security-nist"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "eu-radio-equipment-directive-2014-53-iot-wireless",
    "title": "Directive 2014/53/EU of the European Parliament and of the Council of 6 May 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of radio equipment",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive establishes essential requirements for radio equipment placed on the EU market, including IoT and wireless devices, covering efficient spectrum use, electromagnetic compatibility, safety, and cybersecurity. Key obligations are set out in Article 3, requiring equipment to support effective spectrum use, and Article 3a, mandating baseline cybersecurity protections for networked devices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "etsi-en-303-645-iot-cybersecurity-2020",
      "eu-cyber-resilience-act-iot-2024-products",
      "eu-data-act-2023-iot-data-sharing-obligations",
      "eu-batteries-regulation-2023-1542-iot-storage"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-radio-equipment-directive-2014-53-red",
    "title": "Directive 2014/53/EU of the European Parliament and of the Council on the harmonisation of the laws of the Member States relating to the making available on the market of radio equipment (RED), including Commission Delegated Regulation (EU) 2022/30 on cybersecurity",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes a regulatory framework for placing radio equipment on the EU market, mandating compliance with essential requirements for health, safety, electromagnetic compatibility (EMC), and efficient radio spectrum use under Article 3. A key 2022 delegated act introduces mandatory cybersecurity, personal data protection, and anti-fraud requirements for internet-connected radio equipment under Articles 3(3)(d), (e), and (f).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-radio-spectrum-policy-programme-decision",
    "title": "Decision No 243/2012/EU of the European Parliament and of the Council of 14 March 2012 establishing a multiannual radio spectrum policy programme (RSPP)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2024-03-14",
    "bluf": "This decision establishes a multiannual radio spectrum policy programme (RSPP) requiring EU Member States to cooperate with the Commission to develop a strategic framework for managing radio spectrum, ensuring its efficient use to support the internal market and key policy objectives like wireless broadband for all. As per Article 1, it aims to create a roadmap for spectrum availability and harmonisation to foster innovation in areas like 5G, Wi-Fi, and IoT.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itu-radio-regulations-2020-edition",
      "eu-eecc-2018-1972-electronic-communications-code"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-railway-safety-directive-2016-798",
    "title": "Directive (EU) 2016/798 of the European Parliament and of the Council of 11 May 2016 on railway safety (recast)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This recast Directive ensures the development and improvement of safety of the Union rail system and improved access to the market for rail transport services (Article 1). It defines the roles of actors in developing railway safety (Article 4), sets common safety indicators, methods and targets (Articles 5, 6 and 7), governs national safety rules (Article 8), and requires railway undertakings and infrastructure managers to establish safety management systems (Article 9). It introduces the single safety certificate for railway undertakings (Article 10), safety authorisation for infrastructure managers (Article 12), and rules on the maintenance and certification of entities in charge of maintenance (Articles 14 and 15).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "cyber-nist-csf-2"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-reach-chemicals-1907-2006-svhc-authorisation",
    "title": "EU REACH Regulation 1907/2006 - Chemical Registration, SVHC Authorisation, and Restriction Obligations",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "REACH (Registration, Evaluation, Authorisation and Restriction of Chemicals) - Regulation 1907/2006 - requires manufacturers and importers of chemical substances to register with ECHA when quantities exceed 1 tonne/year, identifies Substances of Very High Concern (SVHCs) on the Candidate List, controls SVHCs through an Authorisation system, and imposes sector-specific Restrictions via Annex XVII.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-reach-regulation-1907-2006",
    "title": "Regulation (EC) No 1907/2006 - EU REACH: Registration, Evaluation, Authorisation and Restriction of Chemicals - No Data No Market Principle, SVHC Candidate List, Authorisation Obligation, Restriction Procedure, and Supply Chain Communication Requirements",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EC) No 1907/2006 (REACH - Registration, Evaluation, Authorisation and Restriction of Chemicals), in force since 1 June 2007 and extensively amended, is the EU's primary chemicals regulatory framework; key obligations include: the 'no data, no market' principle (Article 5) requiring registration with ECHA before manufacturing or importing any substance at ≥1 tonne/year in the EU; phased data requirements by tonnage (Annex VII at 1t/year rising to Annex X at 1000t/year); a Candidate List of Substances of Very High Concern (SVHC) - substances meeting CMR Cat 1A/1B, PBT, vPvB, or equivalent concern criteria (Article 57) - currently approximately 240 substances; authorisation obligation requiring suppliers to obtain ECHA authorisation for uses of Annex XIV substances (approximately 60 substances on the Authorisation List); restriction procedure under Title VIII and Annex XVII imposing conditions or bans on specific substances or uses; mandatory downstream user notification obligations and Safety Data Sheet (SDS) communication requirements in supply chains; articles containing SVHCs above 0.1% w/w triggering SVHC notification requirements in supply chains and consumer information duties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_CLP",
        "US_TSCA",
        "EU_ESPR",
        "EU_PPWR"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecodesign-sustainable-products-regulation-2024-1781",
      "eu-packaging-packaging-waste-regulation-2025-40",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-real-estate-aml-5amld-professional-obligations",
    "title": "Directive (EU) 2018/843 of the European Parliament and of the Council of 30 May 2018 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (Fifth Anti-Money Laundering Directive)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Real estate professionals acting in property transactions involving the purchase or sale of real estate must conduct customer due diligence (CDD) when the transaction involves a cash payment of €10,000 or more, or when there are suspicions of money laundering or terrorist financing, per Article 17(3) and Article 32(2). This applies to estate agents, property developers, and intermediaries providing services related to high-value property deals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-circular-economy-construction-demolition-waste-2020",
      "iso-19650-bim-information-management-construction",
      "iso-9001-2015-quality-management-construction"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-reception-conditions-directive-2024-1346",
    "title": "Directive (EU) 2024/1346 of the European Parliament and of the Council of 14 May 2024 laying down standards for the reception of applicants for international protection (recast)",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This recast Directive lays down standards for the reception of applicants for international protection (Article 1), applying to all third-country nationals and stateless persons who make an application on the territory, including at the border, in territorial waters or in transit zones (Article 3). It requires applicants to be informed of reception conditions (Article 5) and documented (Article 6), governs the organisation of reception systems and any allocation to a geographical area (Articles 7 and 8), and sets standards on material reception conditions, healthcare, the reception of vulnerable persons and detention safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-returns-directive-2008-115",
      "eu-schengen-borders-code-regulation-2016-399"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-recognition-professional-qualifications-2005-36",
    "title": "Directive 2005/36/EC of the European Parliament and of the Council of 7 September 2005 on the recognition of professional qualifications",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This Directive establishes automatic recognition of professional qualifications for regulated professions in seven sectors (e.g. nursing, midwifery, medicine, dentistry, veterinary medicine, architecture, and pharmaceuticals) across EU Member States, based on harmonized minimum training requirements under Articles 3-10. It also creates a general system for recognition of other qualifications under Articles 11-16, including partial access and compensation measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digcomp-digital-competence-framework-2022",
      "eu-open-science-policy-fair-data-principles-2021",
      "eu-researcher-charter-code-of-conduct-2005",
      "iso-21001-2018-educational-organizations-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-red-ii-renewable-energy-2018-2001",
    "title": "EU Renewable Energy Directive (EU) 2018/2001 (RED II)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Directive (EU) 2018/2001 (the Renewable Energy Directive II) provides the binding overall EU renewable energy target of at least 32% renewable energy in final consumption by 2030 (revised to 42.5% by RED III 2023/2413). Member State integrated national energy and climate plans (NECPs) set national contributions. RED II includes provisions on origin guarantees support schemes self-consumption renewable energy communities transport sector targets (14% renewable by 2030 with sub-targets for advanced biofuels and renewable fuels of non-biological origin RFNBO) sustainability criteria for biomass and biofuels and administrative procedures for permitting renewable energy installations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-red3-directive-article-15-permit-granting-procedures",
    "title": "EU Renewable Energy Directive 3 (2023/2413) - Article 15: Permit-Granting Procedures",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations must comply with national rules for renewable energy project authorization, which are required to be proportionate, necessary, and aligned with the 'energy efficiency first' principle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-red3-directive-article-16-go-of-origin",
    "title": "Directive (EU) 2023/2413 - Article 16: Organisation and main principles of the permit-granting procedure",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article requires the establishment of an organized permit-granting procedure for renewable energy projects, based on clearly defined main principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-red3-directive-article-2-definitions",
    "title": "Directive (EU) 2023/2413 - Article 2 - Definitions",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the official definitions for key terms such as 'innovative renewable energy technology', 'smart metering system', and 'domestic battery' that must be used for the interpretation and application of this Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-red3-directive-article-20-heating-and-cooling",
    "title": "Directive (EU) 2023/2413 amending Directive (EU) 2018/2001 as regards the promotion of energy from renewable sources (Note: Provided text does not contain Article 20)",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "The provided text outlines the Union's increased renewable energy targets, such as the 42.5% overall goal, but does not contain the specific operative text of Article 20 concerning heating and cooling obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-red3-directive-article-29-sustainability-criteria-biofuels",
    "title": "Directive (EU) 2023/2413 of the European Parliament and of the Council of 18 October 2023 amending Directive (EU) 2018/2001 as regards the promotion of energy from renewable sources - Article 29",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations must ensure their energy policies contribute to the Union's increased renewable energy targets, accelerating the green transition and reducing dependence on imported fossil fuels.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-red3-directive-article-3-binding-target-42-5-percent-2030",
    "title": "Directive (EU) 2023/2413 - Article 3: Binding Union target for the overall share of energy from renewable sources in 2030",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Member States must collectively ensure a minimum 42.5% share of renewable energy in the Union's gross final consumption by 2030 and implement measures for sustainable biomass production.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-red3-directive-article-31-renewable-fuels-transport",
    "title": "DIRECTIVE (EU) 2023/2413 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 18 October 2023 amending Directive (EU) 2018/2001, Regulation (EU) 2018/1999 and Directive 98/70/EC as regards the promotion of energy from renewable sources",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This directive establishes an increased binding Union target for the share of energy from renewable sources in the Union’s gross final consumption of energy for 2030, raising it to a minimum of 42.5% to accelerate the green transition and reduce fossil fuel dependency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-red3-directive-article-4-renewable-energy-support-schemes",
    "title": "DIRECTIVE (EU) 2023/2413 amending Directive (EU) 2018/2001 as regards the promotion of energy from renewable sources - Article 4: Renewable Energy Support Schemes",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article outlines the requirements for Member States to design and implement support schemes for energy from renewable sources that contribute to the Union's binding 2030 target of at least a 42.5% share of renewable energy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-red3-directive-article-9-go-disclosure-scheme",
    "title": "DIRECTIVE (EU) 2023/2413 - Article 9: Guarantees of origin for energy from renewable sources",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates Member States to establish a system for issuing, transferring, and cancelling electronic guarantees of origin (GOs) to prove to final customers the renewable source of a given quantity of energy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-refueleu-aviation-regulation-2023-2405",
    "title": "Regulation (EU) 2023/2405 of the European Parliament and of the Council of 18 October 2023 on ensuring a level playing field for sustainable air transport (ReFuelEU Aviation)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "ReFuelEU Aviation lays down harmonised rules on the uptake and supply of sustainable aviation fuels (SAF) (Article 1). It applies to aircraft operators, Union airports and aviation fuel suppliers (Article 2). Aviation fuel suppliers must ensure a minimum share of SAF, including a sub-target for synthetic aviation fuels, is made available at Union airports (Article 4); aircraft operators must uplift at least a defined yearly share of their fuel at each Union airport to prevent tankering (Article 5); and airport managing bodies must facilitate access to SAF and to hydrogen and electricity supply (Articles 6 and 7), with reporting obligations (Article 8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-easa-basic-regulation-2018-1139-common-rules-civil-aviation",
      "eu-red-ii-renewable-energy-2018-2001"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-reg-2018-1971-berec-establishing-regulation",
    "title": "Regulation (EU) 2018/1971 - Establishing BEREC and the BEREC Office: Board of Regulators, Functions, Working Groups and Director",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Regulation (EU) 2018/1971 establishes the Body of European Regulators for Electronic Communications (BEREC) and the Agency for Support for BEREC (the BEREC Office), and repeals the earlier Regulation (EC) No 1211/2009. It provides the institutional architecture through which national regulatory authorities cooperate to ensure consistent application of the European Electronic Communications Code across the internal market. Article 7 governs the composition of the Board of Regulators, the principal decision-making body of BEREC, which is composed of one member per Member State drawn from the national regulatory authority primarily responsible for overseeing the day-to-day operation of the electronic communications markets. Article 9 sets out the functions of the Board of Regulators, including adopting opinions, guidelines, recommendations and best practices and providing assistance to national regulatory authorities, the Commission and Union institutions. Article 13 provides for the establishment of working groups to carry out BEREC's technical work, in which experts from national regulatory authorities participate. Article 32 governs the appointment of the Director of the BEREC Office, who is the legal representative and head of the Office and is appointed by the Management Board following an open and transparent selection procedure. The Regulation is the operative instrument that gives BEREC its legal personality, governance and tasks within the Union electronic communications framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2022-0585-amending-regulations-eu-no-514-2014-laying-down-general-prov",
    "title": "Regulation (EU) 2022/585 amending Regulations (EU) No 514/2014, (EU) No 516/2014 and (EU) 2021/1147 on Asylum, Migration and Integration Fund",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Regulation (EU) 2022/585 of the European Parliament and of the Council, adopted on 6 April 2022, amends Regulations (EU) No 514/2014, (EU) No 516/2014, and (EU) 2021/1147 to address urgent migration, border management and security needs following the mass influx of displaced persons from Ukraine after the invasion by the Russian Federation on 24 February 2022. The regulation extends the implementation period of the Home Affairs Funds 2014-2020 by one year, allowing expenditure to be eligible if incurred and fully disbursed between 1 January 2014 and 30 June 2024. Member States must submit final implementation reports by 31 December 2024 and ex-post evaluation reports by 31 December 2024. The European Commission must submit an ex-post evaluation report by 30 June 2025. For the 2014-2020 period, Member States may, in light of new or unforeseen circumstances, use earmarked resources under Article 16(3) and Article 17(9) of Regulation (EU) No 516/2014 for other actions, after consulting the Commission. For the 2021-2027 period, Article 10 of Regulation (EU) 2021/1147 is amended to allow contributions from Member States and other public or private donors as external assigned revenue. The regulation entered into force on the day following publication in the Official Journal, which occurred on 11 April 2022. Ireland and Denmark are not participating in the adoption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2022-1280-laying-down-specific-and-temporary-measures-in-view-of-russi",
    "title": "Regulation (EU) 2022/1280 laying down specific and temporary measures concerning driver documents issued by Ukraine in view of Russia's invasion of Ukraine",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Regulation lays down specific and temporary measures applicable to driver documents issued by Ukraine and held by persons enjoying temporary protection or adequate protection under national law in accordance with Directive 2001/55/EC and Council Implementing Decision (EU) 2022/382, in view of Russia's invasion of Ukraine. It requires Member States to recognise valid driving licences issued by Ukraine without requiring a certified translation or an international driving permit, and allows Member States to issue driver qualification cards or mark a special temporary Union code '95.01 (max 06.03.2025)' on driving licences or driver attestations for holders of Ukrainian driver qualification cards who undergo complementary compulsory training of at least 35 hours and not exceeding 60 hours. In case of lost or stolen driving licences, Member States may issue temporary driving licences with the special code '99.01 (max 06.03.2025)' after verification with Ukrainian authorities. The Regulation requires Member States to prevent fraud and forgery, and to refuse recognition if authenticity cannot be verified. The Commission must inform the European Parliament and Council of implementation every six months. The Regulation entered into force on the fifth day after publication in the Official Journal and ceases to apply when the period of temporary protection ends.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2022-2192-laying-down-specific-provisions-for-the-2014-2020-cooperatio",
    "title": "Regulation (EU) 2022/2192 of the European Parliament and of the Council of 9 November 2022 laying down specific provisions for the 2014-2020 cooperation programmes supported by the European Neighbourhood Instrument and under the European territorial cooperation goal, following programme implementation disruption",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Regulation lays down specific provisions for thirteen cross-border cooperation programmes governed by Regulation (EU) No 232/2014 and two transnational cooperation programmes governed by Regulation (EU) No 1299/2013, listed in the Annex, with regard to programme implementation disruption following Russia's military aggression against Ukraine and the involvement of Belarus. The disruption is defined as problems resulting from suspension or termination of a financing agreement due to restrictive measures under Article 215 TFEU, or from military aggression or substantial flows of displaced persons into a partner country. Articles 3 to 14 apply to the cross-border programmes, Article 15 to the transnational programmes. Key provisions include: no co-financing of the Union contribution for accounting years starting 1 July 2021, 2022, and 2023 (Article 3); simplified programming adjustments (Article 4); eligibility of expenditure for projects addressing migratory challenges from 24 February 2022 (Article 5); managing authority may amend project documents without prior Joint Monitoring Committee approval (Article 6); verifications may be limited to administrative verifications (Article 7); cross-border cooperation impact assessed in three phases (Article 8); projects may continue without a partner country beneficiary (Article 9); lead beneficiary obligations adjusted (Article 10); direct award possible without prior call for proposals for projects addressing migratory challenges (Article 11); direct payments to beneficiaries other than lead beneficiary allowed (Article 12); retroactive change of euro conversion method allowed (Article 13); recovery procedures adapted (Article 14); and derogations from Regulation (EU) No 1299/2013 for transnational programmes (Article 15). The Regulation entered into force on the day following its publication in the Official Journal of the European Union on 11 November 2022.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2022-2463-establishing-an-instrument-for-providing-support-to-ukraine",
    "title": "Regulation (EU) 2022/2463 establishing an instrument for providing support to Ukraine for 2023 (macro-financial assistance +)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Regulation establishes the Instrument for providing Union support to Ukraine (macro-financial assistance +) for 2023, in the form of loans up to EUR 18 billion for the period from 1 January 2023 to 31 December 2023, with possible disbursement until 31 March 2024. The general objective is to provide short-term financial relief to Ukraine, financing rehabilitation, and initial support towards post-war reconstruction, with a view to supporting Ukraine's path towards European integration. Specific objectives include supporting macro-financial stability, a reform agenda for pre-accession, and rehabilitation of critical infrastructure. Support is conditional on Ukraine upholding democratic mechanisms, rule of law, and human rights. A precondition for support is that Ukraine continues to respect effective democratic mechanisms, including a multi-party parliamentary system, the rule of law, and human rights. The Commission must conclude a memorandum of understanding (MoU) with Ukraine setting policy conditions, including anti-corruption commitments. Loans have a maximum duration of 35 years, with repayment of principal not starting before 2033, and interest rate costs may be covered by voluntary Member State contributions. Member States may provide irrevocable, unconditional, and on-demand guarantees up to EUR 18 billion. The Regulation provides for a mid-term review of the MoU. Support is released in instalments subject to Ukraine's submission of a request and a report, and the Commission's assessment of the precondition, reporting requirements, and progress towards policy conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2023-0588-establishing-the-union-secure-connectivity-programme-for-the",
    "title": "Regulation (EU) 2023/588 establishing the Union Secure Connectivity Programme for the period 2023-2027",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Regulation (EU) 2023/588 of the European Parliament and of the Council of 15 March 2023 establishes the Union Secure Connectivity Programme for the period 2023-2027. The Programme aims to provide resilient, global, secure, protected, uninterrupted, guaranteed and flexible satellite communication solutions for evolving governmental needs, built on a Union technological and industrial base. It integrates and complements existing and future national and European capacities in the framework of the GOVSATCOM component and develops the European Quantum Communication Infrastructure (EuroQCI) initiative. The Programme includes definition, design, development, validation and deployment of initial space and ground infrastructure by 2024, with full operational capability by 2027. It prioritises governmental services and allows commercial services by the European private sector. The Programme is funded from a financial envelope laid down in the Regulation, with additional contributions from other Union programmes including Horizon Europe, Digital Europe Programme, NDICI - Global Europe, Connecting Europe Facility and the European Defence Fund. The Commission is responsible for overall implementation, with support from the European Union Agency for the Space Programme and the European Space Agency. Key principles include security, sustainability, innovation, open standards and protection of financial interests. The Regulation requires the Commission to monitor government-authorised user needs and adjust the service portfolio regularly, and to ensure the protection of integrity, security and resilience of operational systems. Member States may designate a competent secure connectivity authority and may host infrastructure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2023-0657-laying-down-rules-for-the-exercise-of-the-union-s-rights-in",
    "title": "Regulation (EU) 2023/657 laying down rules for the exercise of the Union's rights in the implementation and enforcement of the Withdrawal Agreement and the Trade and Cooperation Agreement with the United Kingdom",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Regulation (EU) 2023/657 lays down rules and procedures to ensure effective and timely exercise of the Union's rights under the Withdrawal Agreement and the Trade and Cooperation Agreement between the EU and the United Kingdom. It applies to a range of measures including temporary suspension of preferential treatment, remedial measures, rebalancing measures, countermeasures, and restrictions on trade, investment, or other activities. The Commission is empowered to adopt, amend, suspend, or repeal these measures through implementing acts, except for the suspension of access to Union waters for fisheries, which is decided by the Council under Article 43(3) TFEU. The Commission must follow the examination procedure under Regulation (EU) No 182/2011, with immediate applicability allowed in duly justified urgent cases. The UK Committee assists the Commission, and the European Parliament and Council are kept informed. The Regulation takes precedence over any other Union law provisions on the same subject matter. By 12 April 2026, the Commission must review the application of the Regulation and report to the European Parliament, the Council, the European Economic and Social Committee, and the Committee of the Regions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2023-0675-laying-down-conservation-and-management-measures-for-the-con",
    "title": "Regulation (EU) 2023/675 of the European Parliament and of the Council of 15 March 2023 laying down conservation and management measures for the conservation of southern bluefin tuna",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Regulation implements into Union law conservation and management measures established under the Convention for the Conservation of Southern Bluefin Tuna (CCSBT) that are binding on the Union. It applies to Union fishing vessels carrying out fishing in the area of distribution of southern bluefin tuna (SBF) and to Member States importing, exporting or re-exporting SBF. The targeting of SBF by Union fishing vessels is prohibited; any SBF retained on board counts exclusively as by-catch. Union fishing vessels must be on the Record of Vessels; those not included may not retain on board, tranship or export SBF. Tagging, catch documentation scheme (CDS) documents and catch tagging forms are required for trade. Transhipments must take place in port with prior notification. Member States must submit lists of authorised vessels, report by-catch monthly and annually, and designate points of contact for port inspections. Personal data may be stored for 10 years, or up to 20 years for follow-up on infringements. The Commission is empowered to adopt delegated acts to amend the Regulation in strictly limited areas. The Regulation entered into force on the twentieth day following its publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2023-2418-on-establishing-an-instrument-for-the-reinforcement-of-the-e",
    "title": "Regulation (EU) 2023/2418 establishing a short-term instrument for reinforcing the European defence industry through common procurement (EDIRPA)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Regulation (EU) 2023/2418 establishes a short-term Instrument for the Reinforcement of the European Defence Industry through Common Procurement (EDIRPA) for the period from 27 October 2023 to 31 December 2025, with a financial envelope of EUR 300 million in current prices. The Instrument aims to foster competitiveness and efficiency of the European Defence Technological and Industrial Base (EDTIB) and to foster cooperation in defence procurement between Member States, addressing the most urgent and critical needs revealed or exacerbated by Russia's war of aggression against Ukraine. Eligible actions must involve a consortium of at least three Member States, new cooperation or extension of existing cooperation to a new Member State or associated country, and a common procurement to fill the most urgent and critical gaps. Grants take the form of financing not linked to cost, capped at 15% of the overall budget per action and 15% of the estimated contract value, with a possible increase to 20% if Ukraine or Moldova are recipients of additional quantities or at least 15% of the estimated contract value is allocated to SMEs or mid-caps. Contractors must be established in the Union or associated countries, not controlled by a non-associated third country, with strict conditions for derogation and requirements on restriction-free use. The procurement agent must be designated by unanimity, and retroactive eligibility from 24 February 2022 is possible.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2023-2841-laying-down-measures-for-a-high-common-level-of-cybersecurit",
    "title": "Regulation (EU, Euratom) 2023/2841 of the European Parliament and of the Council of 13 December 2023 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Regulation (EU, Euratom) 2023/2841 requires each Union entity to establish an internal cybersecurity risk-management, governance and control framework. Each entity must implement appropriate and proportionate technical, operational and organisational measures addressing the domains specified in the Regulation. The Framework must be reviewed at least every four years and the cybersecurity plan revised every two years. The Regulation establishes the Interinstitutional Cybersecurity Board (IICB) to monitor and support implementation and to supervise CERT-EU, which is renamed Cybersecurity Service for the Union institutions, bodies, offices and agencies but keeps the short name CERT-EU. Union entities must report significant incidents to CERT-EU within 24 hours of becoming aware of them and inform relevant Member State counterparts. Compliance measures range from a reasoned opinion to a recommendation of temporary suspension of data flows for serious infringements. The Regulation does not apply to network and information systems handling EU classified information, except for Article 13(8). It aims to ensure consistency with Directive (EU) 2022/2555 and applies to all Union institutions, bodies, offices and agencies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2023-2859-establishing-a-european-single-access-point-providing-centra",
    "title": "Regulation (EU) 2023/2859 establishing a European single access point providing centralised access to publicly available information of relevance to financial services, capital markets and sustainability",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Regulation establishes a European single access point (ESAP) to provide centralised electronic access to publicly available information of relevance to financial services, capital markets and sustainability. ESMA is tasked with establishing and operating ESAP by 10 July 2027. The ESAP provides access to information made public under Union legislative acts listed in the Annex, as well as information voluntarily submitted by entities governed by the law of a Member State from 10 January 2030. Information is collected by designated collection bodies, which perform automated validations and store information. The ESAP must offer free access, a search function in all official Union languages, machine translation, and data extraction. ESMA may impose fees for specific high-volume services but not for academia or civil society. Personal data must not be retained for longer than five years unless otherwise provided. The ESAs (EBA, EIOPA, ESMA) through the Joint Committee develop implementing technical standards for metadata and formats. The Commission may adopt delegated acts to postpone inclusion of certain information. The Regulation does not create new disclosure requirements; it builds on existing ones and avoids double reporting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2024-0792-establishing-the-ukraine-facility",
    "title": "Regulation (EU) 2024/792 of the European Parliament and of the Council of 29 February 2024 establishing the Ukraine Facility",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Regulation establishes the Ukraine Facility, an exceptional medium-term single instrument for the period 2024 to 2027, providing bilateral Union support to Ukraine. The Facility's overall maximum amount is EUR 50 billion in current prices. Support is organised around three pillars: a financial support pillar for reforms and investments and to maintain macro-financial stability as set out in the Ukraine Plan; a Ukraine Investment Framework pillar to mobilise investments and enhance access to finance; and an accession assistance pillar to mobilise technical expertise and capacity building. Support other than in the form of loans is financed up to EUR 17 billion for 2024 to 2027 via the Ukraine Reserve, with an annual maximum amount of EUR 5 billion for that type of support. The Facility aims to help Ukraine address social, economic, psychological and environmental consequences of the war; contribute to reconstruction, recovery, restoration and modernisation; foster social and territorial cohesion; and prepare Ukraine for future Union membership by supporting its accession process. It is underpinned by a Ukraine Plan prepared by the Government of Ukraine with involvement of the Verkhovna Rada and civil society. Support is preconditioned on Ukraine respecting effective democratic mechanisms, the rule of law and human rights. Exceptional financing may be provided for periods of up to three months via Council implementing decision if Ukraine cannot fulfil conditions. At least 20% of the overall amount under the Ukraine Investment Framework and Ukraine Plan should contribute to climate and environmental objectives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2024-0897-amending-regulation-eu-2017-2107-laying-down-management-cons",
    "title": "Regulation (EU) 2024/897 amending management, conservation and control measures for ICCAT area and bluefin tuna plan",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Regulation (EU) 2024/897, adopted on 13 March 2024, amends Regulation (EU) 2017/2107 and Regulation (EU) 2023/2053 to implement ICCAT conservation and enforcement recommendations from 2017, 2018, 2019, 2021 and 2022 annual meetings into Union law. For Regulation (EU) 2017/2107, the amendments introduce definitions for billfish, support vessel, floating object, fish-aggregating device (FAD), FAD set, shallow-set longlines, circle hook, and operational buoy. They establish capacity limitations for tropical tuna: Member States must submit annual fishing and capacity management plans by 31 January, cannot increase support vessel numbers from June 2023 levels, and report catch limits to the Commission. A prohibition on discards of tropical tunas by Union purse seiners is introduced with specific exceptions. Underage and overage rules are set for bigeye tuna, North and South Atlantic albacore, and North and South Atlantic swordfish, with carry-over limits not exceeding amounts permitted by ICCAT. Observer coverage requirements mandate 100% for purse seiners and 10% for longline vessels 20 metres or greater. New articles cover safe handling and release of blue marlin, white marlin, roundscale spearfish, North and South Atlantic shortfin mako sharks, and sea turtles. A vessel monitoring system provision is included. For Regulation (EU) 2023/2053, amendments address bluefin tuna management including quota transfers, retention prohibition, recreational fisheries, vessel lists, traps and farms, observer programmes, and control of caging and harvesting operations. The Commission is delegated power to adopt acts under Article 290 TFEU for future technical amendments. The regulation entered into force on 19 March 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-reg-2024-0903-laying-down-measures-for-a-high-level-of-public-sector-inter",
    "title": "Regulation (EU) 2024/903 of the European Parliament and of the Council of 13 March 2024 laying down measures for a high level of public sector interoperability across the Union (Interoperable Europe Act)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Regulation establishes a legal framework for cross-border interoperability of network and information systems used to provide or manage public services in the Union, aiming to enable public administrations to cooperate and make public services function across borders. It replaces existing informal cooperation with a structured governance framework centered on the Interoperable Europe Board, composed of one representative from each Member State and one from the Commission. The Regulation introduces mandatory interoperability assessments for Union entities or public sector bodies that set binding requirements for trans-European digital public services, evaluating effects on legal, organisational, semantic, technical, and governance dimensions of cross-border interoperability. It promotes the sharing of interoperability solutions as a default, the development of the European Interoperability Framework (EIF) as a single point of reference, and the establishment of an Interoperable Europe portal as a single point of entry for interoperability solutions, assessments, knowledge, and community. The Regulation also provides for interoperability regulatory sandboxes, a peer review process on a voluntary basis, and support for GovTech cooperation and innovation measures. It complements and is without prejudice to Union data protection law, including Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive 2002/58/EC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2024-1435-implementing-regulation-eu-2024-1435-of-24-may-2024-laying-d",
    "title": "Commission Implementing Regulation (EU) 2024/1435 of 24 May 2024 laying down rules for the application of Regulation (EU) 2023/988 as regards establishing the template for a recall notice",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Commission Implementing Regulation (EU) 2024/1435, adopted on 24 May 2024, establishes the template for a product safety recall notice under Article 36 of Regulation (EU) 2023/988 on general product safety. The template is set out in the Annex to this Regulation. The Commission is required to publish this template on its website. The Regulation applies from 13 December 2024. It is binding in its entirety and directly applicable in all Member States. The Regulation aims to ensure that recall notices are clear, transparent, and clearly describe the hazard at stake. A single, standardised template should facilitate consumers in identifying and understanding recall notices, and ensure easier and more uniform compliance by economic operators and providers of online marketplaces with Articles 35 and 36 of Regulation (EU) 2023/988. The Regulation also requires that recall notices be in accessible formats for people with disabilities, including web accessibility standards when shared online, and that important information in pictures be spelled out in machine-readable form. The Regulation was adopted after consulting the General Product Safety Regulation Committee, and has EEA relevance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-reg-2024-1449-on-establishing-the-reform-and-growth-facility-for-the-weste",
    "title": "Regulation (EU) 2024/1449 of the European Parliament and of the Council of 14 May 2024 on establishing the Reform and Growth Facility for the Western Balkans",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Regulation (EU) 2024/1449 establishes the Reform and Growth Facility for the Western Balkans for the period 2024 to 2027. The Facility aims to support the enlargement process by accelerating alignment with Union values, laws, rules, standards, policies and practices (acquis), accelerating regional economic integration and progressive integration of the beneficiaries in the Union single market, and accelerating their socio-economic convergence with the Union. Beneficiaries are Albania, Bosnia and Herzegovina, Kosovo, Montenegro, North Macedonia and Serbia. The overall maximum amount for Union support through the Facility is EUR 6 billion in current prices, of which up to EUR 2 billion in the form of non-repayable support and EUR 4 billion in concessional loans provisioned from the EUR 2 billion. At least half of the total amount is to be allocated through the Western Balkan Investment Framework (WBIF). Disbursement is conditional on compliance with payment conditions and measurable progress in implementing reforms set out in each beneficiary's Reform Agenda, assessed and formally approved by the Commission. Payment conditions are linked to preconditions including upholding democratic mechanisms, rule of law, human rights, and constructive engagement by Serbia and Kosovo in normalising their relations. Pre-financing of up to 7% of the total amount per beneficiary is available. The Facility complements Regulation (EU) 2021/1529 and does not support activities that undermine peace agreements in the region.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2024-1487-regulation-eu-2024-1487-of-29-may-2024-defining-data-require",
    "title": "Commission Regulation (EU) 2024/1487 defining data requirements for approval of safeners and synergists and establishing a work programme for gradual review",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Regulation establishes a work programme for the gradual review of safeners and synergists already on the market and defines data requirements for their approval. By 19 July 2024, the Commission shall publish a list of substances known to be used as safeners or synergists in plant protection products authorised in at least one Member State on 19 June 2024. Interested parties may notify further substances by 19 December 2024. Applicants wishing to submit an application for approval must request inclusion in the work programme by 19 June 2025. The Commission shall adopt the work programme by 19 December 2025, designating a rapporteur and co-rapporteur Member State for each substance. Applications for approval must be submitted by 19 June 2028 in standard IUCLID format via a central submission system. Data requirements include those for active substances under Regulation (EU) No 283/2013, for plant protection products under Regulation (EU) No 284/2013, plus supplementary data listed in Annex III covering intended use, efficacy evaluation, and specific studies for safeners and synergists. Applicants must take measures to minimise animal testing and notify the Authority of studies. The Regulation is based on Article 25(3) and Article 26 of Regulation (EC) No 1107/2009.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2024-2773-establishing-the-ukraine-loan-cooperation-mechanism-and-prov",
    "title": "Regulation (EU) 2024/2773 establishing the Ukraine Loan Cooperation Mechanism and providing exceptional macro-financial assistance to Ukraine",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Regulation establishes the Ukraine Loan Cooperation Mechanism (the Mechanism) to provide Ukraine with non-repayable financial support to assist it in repaying the principal, interest, and any other related costs of the MFA Loan and eligible bilateral loans. The Mechanism is financed by amounts transferred from central securities depositories holding Russian sovereign assets (external assigned revenue under the Financial Regulation) and voluntary contributions from Member States, third countries, or other sources. The MFA Loan is exceptional macro-financial assistance of up to EUR 35 billion in the form of a loan, with the total principal of all supported loans not exceeding EUR 45 billion. Bilateral loans are eligible if the agreement was not signed before 20 September 2024, the counterparty acts under the G7 Extraordinary Revenue Acceleration Loans for Ukraine initiative, and the loan is fully disbursed by 31 December 2027. Ukraine must submit bilateral loan agreements by 1 June 2025, and they must enter into force by 30 June 2025. Disbursement of non-repayable support requires a Commission positive assessment based on Ukraine's compliance with the precondition of upholding democratic mechanisms (Article 11(1)) and obligations under the ULCM Agreement. The MFA Loan is provided on highly concessional terms, with no provisioning rate and no guarantee from the External Action Guarantee, and is linked to policy conditions in a memorandum of understanding. The Commission manages the support and reports to the European Parliament and Council.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-reg-2024-3012-establishing-a-union-certification-framework-for-permanent-c",
    "title": "Regulation (EU) 2024/3012 establishing a Union certification framework for permanent carbon removals, carbon farming and carbon storage in products",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Regulation establishes a voluntary Union certification framework for permanent carbon removals, carbon farming and carbon storage in products. Its aim is to facilitate and encourage high-quality carbon removals and soil emission reductions, complementing emission reductions across all sectors, in full respect of biodiversity and zero-pollution objectives. The framework defines quality criteria: activities must generate a net carbon removal benefit or net soil emission reduction benefit (quantified against standardised baselines updated at least every five years), be additional (beyond statutory requirements and financially viable due to the incentive effect of certification), and ensure long-term storage (permanent carbon removals must store carbon for several centuries; carbon farming sequestration units and carbon storage in product units have an expiry date at the end of the monitoring period, which must cover at least 35 years for carbon storage in products). Activities must do no significant harm to the environment and may generate co-benefits. Certification requires independent third-party auditing by accredited certification bodies, with initial audits before implementation and re-certification audits at least every five years. Certified units must be accounted for to avoid double counting and cannot contribute to third-party NDCs. The Commission will adopt delegated acts establishing detailed certification methodologies. The framework is voluntary; existing and new schemes may apply for Commission recognition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-0020-corrigendum-to-commission-delegated-regulation-eu-2025-20-of",
    "title": "Corrigendum to Commission Delegated Regulation (EU) 2025/20 on safe provision of ground handling services",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "This is a Corrigendum to Commission Delegated Regulation (EU) 2025/20 of 19 December 2024, which supplements Regulation (EU) 2018/1139 by laying down requirements for the safe provision of ground handling services and for organisations providing them. The corrigendum was published in the Official Journal of the European Union L series on 10 February 2026 (document 2026/90081). It corrects a date in Article 5 of the original regulation. The original text stated: 'Organisations already providing ground handling services on 27 March 2025 shall submit a declaration in accordance with point ORGH.DEC.100 of Annex I to this Regulation from 27 March 2024, in accordance with a plan established and agreed with their competent authority as identified in point ORGH.GEN.105 of Annex I to this Regulation.' The corrigendum changes the date '27 March 2024' to '27 March 2027', so the correct wording reads: 'Organisations already providing ground handling services on 27 March 2025 shall submit a declaration in accordance with point ORGH.DEC.100 of Annex I to this Regulation from 27 March 2027, in accordance with a plan established and agreed with their competent authority as identified in point ORGH.GEN.105 of Annex I to this Regulation.' The corrigendum's ELI is http://data.europa.eu/eli/reg_del/2025/20/corrigendum/2026-02-10/oj.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-0023-corrigendum-to-commission-implementing-regulation-eu-2025-23",
    "title": "Corrigendum to Commission Implementing Regulation (EU) 2025/23 on oversight of ground handling services and organisations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "This corrigendum corrects Commission Implementing Regulation (EU) 2025/23 of 19 December 2024, which lays down rules for the application of Regulation (EU) 2018/1139 as regards requirements for the oversight of ground handling services and organisations providing them. The corrigendum, published in the Official Journal of the European Union L series on 10 February 2026, amends a specific date in Article 6, first paragraph. The original text required competent authorities to perform at least one comprehensive oversight of all declaring organisations in their Member State by 27 March 2030 at the latest. The corrigendum changes that date to 27 March 2033 at the latest. The instrument is identified by CELEX number 32025R0023R(02) and is electronically published under ISSN 1977-0677.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-reg-2025-0216-implementing-regulation-eu-2025-216-of-6-february-2025-layin",
    "title": "Commission Implementing Regulation (EU) 2025/216 of 6 February 2025 laying down technical information for the calculation of technical provisions and basic own funds for reporting with reference dates from 31 December 2024 until 30 March 2025 in accordance with Directive 2009/138/EC",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "This Commission Implementing Regulation (EU) 2025/216, adopted on 6 February 2025, provides technical information for the calculation of technical provisions and basic own funds by insurance and reinsurance undertakings for reporting reference dates from 31 December 2024 until 30 March 2025, in accordance with Directive 2009/138/EC (Solvency II). The technical information is based on market data from the end of December 2024, provided by the European Insurance and Occupational Pensions Authority (EIOPA) on 8 January 2025 and published the same day under Article 77e(1) of Directive 2009/138/EC. The Regulation specifies three sets of technical data: (a) relevant risk-free interest rate term structures set out in Annex I; (b) fundamental spreads for the calculation of the matching adjustment set out in Annex II; and (c) volatility adjustments for each relevant national insurance market set out in Annex III. These are used to calculate the best estimate (Article 77 of Directive 2009/138/EC), the matching adjustment (Article 77c), and the volatility adjustment (Article 77d). The Regulation applies from 31 December 2024 and enters into force on the day following its publication in the Official Journal of the European Union, which occurred on 7 February 2025. Insurance and reinsurance undertakings must use the same technical information regardless of their reporting date to their competent authorities, ensuring uniform conditions across the EU and EEA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-0292-delegated-regulation-eu-2025-292-of-26-september-2024-supple",
    "title": "Commission Delegated Regulation (EU) 2025/292 supplementing Regulation (EU) 2023/1114 with regulatory technical standards establishing a template document for cooperation arrangements between competent authorities and supervisory authorities of third countries",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "This Commission Delegated Regulation (EU) 2025/292, adopted on 26 September 2024, supplements Regulation (EU) 2023/1114 on markets in crypto-assets by establishing a template document for cooperation arrangements between competent authorities of Member States and supervisory authorities of third countries. The template is set out in the Annex to this Regulation and covers exchange of information and enforcement of obligations under Regulation (EU) 2023/1114 in third countries. The template includes sections on introduction, definitions, type of assistance (e.g., obtaining information, statements, documents, data traffic records, freezing assets, temporary cessation of practices), general provisions on denial of assistance, sending and processing requests, permissible uses of information, processing of personal data in compliance with Regulation (EU) 2016/679, confidentiality restrictions, identification of a contact point, and a revision clause. The Regulation requires that where competent authorities rely on an administrative arrangement under Article 46(3)(b) of Regulation (EU) 2016/679 for personal data transfers to third country authorities, that arrangement must be annexed to the cooperation arrangement. The Regulation entered into force on the twentieth day following its publication in the Official Journal of the European Union. It is binding in its entirety and directly applicable in all Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-reg-2025-0302-implementing-regulation-eu-2025-302-of-23-october-2024-layin",
    "title": "Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for standard forms, templates and procedures for financial entities to report major ICT-related incidents and notify significant cyber threats",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 lays down implementing technical standards for the application of Regulation (EU) 2022/2554 (DORA). It specifies the standard forms, templates and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat. Financial entities must use the template in Annex I for initial notifications, intermediate reports and final reports under DORA Article 19(4). The template includes data fields for general information about the financial entity, content of the initial notification (e.g. detection date, classification date, description), content of the intermediate report (e.g. occurrence date, recovery date, number of affected clients) and content of the final report (e.g. root cause classification, incident resolution summary). Financial entities must follow the data glossary and instructions in Annex II. Joint submission of initial notification, intermediate and final reports is allowed where regular activities have recovered or root cause analysis is complete, provided time limits in Delegated Regulation (EU) 2025/301 are met. Recurring ICT-related incidents that cumulatively meet the conditions for a major incident under Delegated Regulation (EU) 2024/1772 Article 8(2) must be reported in aggregated form. Financial entities must use secure electronic channels made available by their competent authority. Reclassification of a major ICT-related incident to non-major requires notification using Annex II fields 'type of report' and 'other information'. Outsourcing of reporting obligations must be communicated to the competent authority prior to the first notification. Aggregated reporting by a third-party provider is permitted under certain conditions, but does not apply to significant credit institutions, operators of trading venues and central counterparties. Notification of significant cyber threats must use the template in Annex III and follow Annex IV. The Regulation entered into force on the twentieth day after publication in the Official Journal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-0304-implementing-regulation-eu-2025-304-of-31-october-2024-layin",
    "title": "Commission Implementing Regulation (EU) 2025/304 laying down standard forms templates and procedures for notification by financial entities of intention to provide crypto-asset services",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Implementing Regulation (EU) 2025/304, adopted on 31 October 2024 and published on 20 February 2025, lays down implementing technical standards for the application of Regulation (EU) 2023/1114 regarding standard forms, templates and procedures for notifications by certain financial entities of their intention to provide crypto-asset services. The Regulation requires competent authorities to designate and publish on their websites a contact point for receiving such notifications (Article 1). The notifying entity must submit the notification using the form set out in the Annex, in a manner that enables future reference and unchanged reproduction (Article 2). Competent authorities must send an acknowledgement of receipt within five working days of receipt, including contact details of the handling department or staff member (Article 3). The notifying entity must notify any changes to the information without undue delay using the same form (Article 4). The Annex contains the notification form, which requires declarations of accuracy and completeness, and requests information on programme of operations, business continuity, anti-money laundering, ICT systems, segregation of client assets, custody policy, trading platform rules, exchange services, execution policy, advice or portfolio management, and transfer services, referencing Delegated Regulation (EU) 2025/303.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-reg-2025-0339-implementing-regulation-eu-2025-339-of-19-february-2025-layi",
    "title": "Commission Implementing Regulation (EU) 2025/339 of 19 February 2025 laying down rules for implementation of Article 6a of Regulation (EU) 2020/2220 as regards monitoring and evaluation, presentation of rural development programmes and annual implementation reports",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Implementing Regulation (EU) 2025/339, adopted on 19 February 2025, lays down rules for implementing Article 6a of Regulation (EU) 2020/2220, which introduced a new measure providing exceptional temporary support in response to the impact of natural disasters funded under the European Agricultural Fund for Rural Development (EAFRD) within the legal framework applicable in the programming period 2014-2020. The regulation specifies that for inclusion in rural development programmes, the measure and sub-measure code referred to in Part 5 of Annex I to Implementing Regulation (EU) No 808/2014 shall be 23 (M23). For implementing the derogation in Article 1(2) of Regulation (EU) 2020/2220, information on the total Union contribution reallocated to the measure in Article 18(1)(b) of Regulation (EU) No 1305/2013 shall be provided in point (c) of the financing plan referred to in Part I, point 10, of Annex I to Implementing Regulation (EU) No 808/2014. The regulation mandates the use of RD Output indicator O.4, established in point 3 of Annex IV to Implementing Regulation (EU) No 808/2014, for the new measure. Annual implementation reports under Articles 50 of Regulation (EU) No 1303/2013 and 75 of Regulation (EU) No 1305/2013 must include a breakdown as in Table C of Annex VII to Implementing Regulation (EU) No 808/2014 relating to the Article 6a measure. The regulation entered into force on the day of its publication in the Official Journal of the European Union and applies from 23 December 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-reg-2025-0341-implementing-regulation-eu-2025-341-of-20-february-2025-layi",
    "title": "Commission Implementing Regulation (EU) 2025/341 of 20 February 2025 laying down rules for the implementation of Article 6a of Regulation (EU) 2020/2220 as regards checks and penalties",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Implementing Regulation (EU) 2025/341, adopted on 20 February 2025, lays down rules for the implementation of Article 6a of Regulation (EU) 2020/2220 as regards checks and penalties. The measure introduced by Article 6a provides exceptional temporary support in response to natural disasters, funded under the European Agricultural Fund for Rural Development (EAFRD) within the legal framework of the 2014-2020 programming period. For the purpose of checks and penalties, this measure is to be considered as a non-area-related and non-animal-related rural development measure under Title IV of Implementing Regulation (EU) No 809/2014. The regulation enters into force on the day of its publication in the Official Journal of the European Union and applies from 23 December 2024. It is binding in its entirety and directly applicable in all Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-reg-2025-0486-implementing-regulation-eu-2025-486-of-17-march-2025-laying",
    "title": "Commission Implementing Regulation (EU) 2025/486 of 17 March 2025 laying down rules for the application of Regulation (EU) 2023/956 as regards the conditions and procedures related to the status of authorised CBAM declarant",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Implementing Regulation (EU) 2025/486, adopted on 17 March 2025 and published on 18 March 2025, lays down detailed rules for the application of Regulation (EU) 2023/956 establishing a carbon border adjustment mechanism (CBAM). It specifies the conditions and procedures for obtaining and maintaining the status of authorised CBAM declarant. The regulation covers the submission of applications via the CBAM registry in electronic format, adjustments to applications, assessment by competent authorities within 120 calendar days (extended to 180 days for applications submitted before 15 June 2025), and the possibility to request additional information. It defines criteria for authorisation, including absence of serious or repeated infringements in the preceding three years and no serious criminal offences related to economic activities in the preceding five years, as well as financial and operational capacity. For importers of electricity allocated explicit capacity, specific identification procedures are provided. The regulation establishes a consultation procedure between competent authorities and the Commission, with deadlines of 5 working days for estimated yearly imports of 1 tonne or less and 15 working days for imports exceeding 1 tonne. It covers the provision and monitoring of guarantees, reassessment of authorisation status, and revocation procedures upon request of the declarant or initiated by the competent authority. The regulation applies from 28 March 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-0535-establishing-the-reform-and-growth-facility-for-the-republic",
    "title": "Regulation (EU) 2025/535 of the European Parliament and of the Council of 18 March 2025 establishing the Reform and Growth Facility for the Republic of Moldova",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Regulation establishes the Reform and Growth Facility for the Republic of Moldova for 2025-2027. The Facility provides assistance for Union-related reforms, including inclusive and sustainable socio-economic reforms and reforms concerning fundamentals of the enlargement process, aligned with Union values, as well as investments to implement Moldova's Reform Agenda. The Facility is supported with resources from NDICI-Global Europe, primarily from the Neighbourhood East allocation, amounting to EUR 520 million in non-repayable support and a maximum of EUR 1,500 million in loans for the period 2025-2027. The non-repayable support covers 9% provisioning for loans (EUR 135 million), support for projects under the Neighbourhood Investment Platform, and complementary support. At least 37% of the non-repayable financial support for investment projects under the Neighbourhood Investment Platform must be attributed to climate objectives. Disbursement is conditional on Moldova upholding effective democratic mechanisms, rule of law, human rights, and respect for the rights of persons belonging to minorities. Decisions on loan fund releases must be adopted between 1 January 2025 and 30 June 2029. The Facility aims to support Moldova in facing challenges related to Russia's war of aggression against Ukraine, including economy, energy, food, and value chains, and to strengthen resilience against foreign information manipulation. Loans have a maximum duration of 40 years with principal repayment starting no earlier than 2034.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-0606-delegated-regulation-eu-2025-606-of-21-march-2025-supplement",
    "title": "Commission Delegated Regulation (EU) 2025/606 of 21 March 2025 supplementing Regulation (EU) 2023/1542 by establishing the methodology for calculation and verification of rates for recycling efficiency and recovery of materials from waste batteries, and the format for the documentation",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Delegated Regulation (EU) 2025/606, adopted on 21 March 2025, supplements Regulation (EU) 2023/1542 by establishing the methodology for calculation and verification of rates for recycling efficiency and recovery of materials from waste batteries, and the format for the documentation. The Regulation applies to lead-acid, lithium-based, nickel-cadmium, and other waste batteries. It defines input, intermediate, and output fractions, and sets formulas for calculating recycling efficiency (rRE) as (moutput / minput) x 100 mass percent, and recovery of materials (rRM) as (mTM,output-point / mTM,input) x 100 mass percent. The methodology requires calculation by battery chemistry, and specifies that emissions to air, water, and soil are not taken into account. It establishes a verification process covering overall calculations, auditing, documentary evidence, and self-auditing. The documentation format is split into two parts for each battery chemistry: Part 1 for overall recycling efficiency and recovery rates, and Part 2 for individual recycling steps. Recyclers must provide annual data broken down by Member State of collection. The first recycler is responsible for collating information when recycling occurs at multiple facilities. The Regulation also mandates documentation of mercury and cadmium streams. It enters into force on the twentieth day following publication in the Official Journal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-0655-implementing-regulation-eu-2025-655-of-2-april-2025-laying-d",
    "title": "Commission Implementing Regulation (EU) 2025/655 of 2 April 2025 laying down rules for application of Regulation (EU) 2023/1804 as regards specifications and procedures relating to availability and accessibility of data on alternative fuels infrastructure",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Implementing Regulation (EU) 2025/655, adopted on 2 April 2025 and applicable from 14 April 2025, lays down specifications and procedures for the availability and accessibility of data on alternative fuels infrastructure under Article 20 of Regulation (EU) 2023/1804. Operators or owners of publicly accessible recharging and refuelling points must make static and dynamic data available in accordance with the format, frequency, and quality specifications set out in the Annex and Articles 1-3. Static data must be updated no later than twenty-four hours after a change; dynamic data no later than one minute after a change. Data must be provided in DATEX II format including at least CEN/TS 16157-10:2022 from 14 April 2026. Member States must monitor data made accessible through their National Access Points (NAPs), facilitate information exchange, and address widespread data quality issues. The Annex contains detailed tables of static and dynamic data types, categories, descriptions, and formats for recharging and refuelling infrastructure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-reg-2025-1093-implementing-regulation-eu-2025-1093-of-22-may-2025-laying-d",
    "title": "Commission Implementing Regulation (EU) 2025/1093 of 22 May 2025 laying down rules for the application of Regulation (EU) 2023/1115 as regards a list of countries presenting low or high risk of producing non-compliant relevant commodities",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Implementing Regulation (EU) 2025/1093, adopted on 22 May 2025 and published on 23 May 2025, lays down rules for applying Regulation (EU) 2023/1115 regarding a list of countries that present a low or high risk of producing relevant commodities for which the relevant products do not comply with Article 3, point (a) of that Regulation. The classification is based on an objective and transparent assessment by the Commission, taking into account the latest scientific evidence and internationally recognised sources, primarily from the Global Forest Resources Assessment by the Food and Agriculture Organization of the United Nations. The Annex to the Regulation lists low-risk countries (e.g., Afghanistan, Albania, Australia, Canada, China, Germany, India, Japan, United Kingdom, United States) and high-risk countries (Belarus, Democratic People's Republic of Korea, Myanmar, Russian Federation). A standard level of risk is maintained for all countries not listed in the Annex. Operators and traders sourcing from low-risk countries benefit from simplified due diligence obligations under Article 13 of Regulation (EU) 2023/1115. The classification also guides competent authorities' checks under Article 16(3) and operators' risk assessments under Article 10(2), point (a) of that Regulation. The Regulation entered into force on the third day following publication in the Official Journal of the European Union and is binding in its entirety and directly applicable in all Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-reg-2025-1127-implementing-regulation-eu-2025-1127-of-6-june-2025-laying-d",
    "title": "Commission Implementing Regulation (EU) 2025/1127 of 6 June 2025 laying down rules for identifying neighbouring container transhipment ports",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Implementing Regulation (EU) 2025/1127, adopted on 6 June 2025, lays down rules for identifying neighbouring container transhipment ports under Article 2(2) of Regulation (EU) 2023/1805 on the use of renewable and low-carbon fuels in maritime transport. It lists two ports as neighbouring container transhipment ports: East Port Said in Egypt and Tanger Med in Morocco. A port qualifies if its share of container transhipment (in 20-foot equivalent units) exceeds 65% of total container traffic during the most recent 12-month period for which data are available, and it is located outside the Union but within 300 nautical miles of a port under Member State jurisdiction. Ports in third countries that effectively apply equivalent measures to Regulation (EU) 2023/1805 are excluded. The regulation uses the same data and analyses as Implementing Regulation (EU) 2023/2297 for coherence. Egypt does not apply equivalent measures for East Port Said, and Morocco does not apply equivalent measures for Tanger Med. The regulation enters into force on the third day after publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-reg-2025-1165-implementing-regulation-eu-2025-1165-of-13-june-2025-laying",
    "title": "Commission Implementing Regulation (EU) 2025/1165 laying down specific rules for pet travel document and declaration for non-commercial movements of pet animals into Northern Ireland from other parts of the United Kingdom",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Implementing Regulation (EU) 2025/1165, adopted on 13 June 2025, lays down specific rules for the application of Regulation (EU) 2023/1231 concerning the information to be included in the pet travel document and the declaration for non-commercial movements of certain pet animals (pet dogs, cats, and ferrets) entering into Northern Ireland from other parts of the United Kingdom. The Regulation is based on written guarantees provided by the United Kingdom in a letter of 15 April 2025, stating that such movements do not increase animal health risks on the island of Ireland or the internal market, and that the United Kingdom will carry out effective documentary and identity checks from 4 June 2025, implement early detection systems for Echinococcus multilocularis and rabies, and notify the Commission. Article 2 specifies that the pet travel document must contain the transponder location (with implantation or reading date and unique alphanumeric code), animal identification details (name, species, breed, sex, colour, date of birth as stated by the owner, and notable features), owner name/contact/signature, name/contact/signature of a representative of the competent UK authority issuing the document, and a document number consisting of the UK ISO code followed by a unique alphanumeric code. Article 3 requires the declaration to include the name and signature of the owner or authorised person, place and date of issuance, the transponder code for each animal, the pet travel document number, and a commitment that the animal will not be subsequently moved from Northern Ireland to a Member State. The Regulation entered into force the day after publication in the Official Journal (16 June 2025) and applies retroactively from 4 June 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-1310-implementing-regulation-eu-2025-1310-of-3-july-2025-laying-d",
    "title": "Commission Implementing Regulation (EU) 2025/1310 of 3 July 2025 laying down technical specifications of data requirements for ICT usage and e-commerce for reference year 2026",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Implementing Regulation (EU) 2025/1310, adopted on 3 July 2025 and published on 4 July 2025, lays down the technical specifications of data requirements and deadlines for submission of annual metadata and quality reports for the topic 'ICT usage and e-commerce' for reference year 2026, pursuant to Regulation (EU) 2019/2152. Article 1 requires Member States to transmit data complying with the Annex technical specifications. Article 2 sets deadlines: annual metadata report by 31 May 2026, annual quality report by 5 November 2026. The Annex lists mandatory and optional variables (e.g., enterprise economic activity, ICT specialists, AI use, cloud computing, security measures) with scope filters, measurement units (absolute figures, percentages), statistical population (NACE Rev. 2.1 sections C-K, M-O, group 95.1; size class 10+ employees and self-employed persons), activity breakdowns including aggregates for NACE divisions and groups, size class breakdowns (10+, 10-49, 50-249, 250+), and data transmission deadline of 5 October 2026. The regulation is binding in entirety and directly applicable in all Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-1328-corrigendum-to-commission-implementing-regulation-eu-2025-13",
    "title": "Corrigendum to Commission Implementing Regulation (EU) 2025/1328 on templates for building stock data transfer",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "This is a Corrigendum to Commission Implementing Regulation (EU) 2025/1328 of 30 June 2025, which implements Directive (EU) 2024/1275 of the European Parliament and of the Council. The regulation establishes common templates for the transfer of information from national energy performance of buildings databases to the EU Building Stock Observatory. The corrigendum was published in the Official Journal of the European Union L series on 2 October 2025 (OJ L, 2025/90759). Specifically, on page 29, Annex I, point 4, 'BUILDING RENOVATION PASSPORTS', Table 22 is replaced. Table 22 contains indicators related to renovation passports, including number issued in the reported year, average current energy performance of buildings (kWh/(m2.yr)), average estimated energy performance class after completion of all steps (kWh/(m2.yr)), total estimated energy savings in primary and final energy consumption (MWh/yr), average estimated energy savings in primary and final energy consumption (%), total estimated operational GHG emission reduction (tCO2eq/yr), average estimated operational GHG emission reduction (kgCO2eq/yr), average estimated savings on energy bills (EUR/building or building unit/yr), and average estimated investment to complete all steps (thou. EUR/m2). The table breaks down data by building types: total residential, single family houses, multi-family buildings, total non-residential, offices, educational buildings, hospitals, and other non-residential. Footnotes (25), (26), and (27) provide clarifications on energy performance class estimation and percentage improvement calculations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-reg-2025-1328-implementing-regulation-eu-2025-1328-of-30-june-2025-impleme",
    "title": "Commission Implementing Regulation (EU) 2025/1328 of 30 June 2025 establishing common templates for transfer of information from national energy performance of buildings databases to the EU Building Stock Observatory",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Implementing Regulation (EU) 2025/1328, adopted on 30 June 2025, implements Directive (id) 2024/1275 by establishing common templates for transferring information from national energy performance of buildings databases to the EU Building Stock Observatory. The Regulation sets out the structure, format, technical details, and process for annual transfers, with the first transfer due by 15 March 2027 covering data from the period between 29 May 2026 (transposition deadline) and 31 December 2026. Member States must transfer aggregated, anonymised data at country level, excluding personal data under Regulation (EU) 2016/679. Information categories are classified as mandatory (M), mandatory if available (Miav), mandatory if applicable (Miap), or voluntary (V). Data to be transferred includes: share of buildings covered by valid energy performance certificates (EPCs), number and floor area of buildings with issued EPCs, average primary and final energy use, cumulative energy consumption and on-site renewable production, operational GHG emissions, life-cycle GWP, building smart readiness indicator scores, number of issued renovation passports with estimated savings, number of inspections of heating/ventilation/air-conditioning systems, and public information on total national building stock. Templates in Annex I cover general information, EPC scheme descriptions, building stock totals by type and energy class, and formulas in Annex II govern aggregation. The Regulation is binding in its entirety and directly applicable in all Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-1338-implementing-regulation-eu-2025-1338-of-10-july-2025-laying",
    "title": "Commission Implementing Regulation (EU) 2025/1338 of 10 July 2025 laying down implementing technical standards for the functionalities of the European single access point",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Implementing Regulation (EU) 2025/1338 of 10 July 2025 lays down implementing technical standards for the application of Regulation (EU) 2023/2859 with regard to the functionalities of the European single access point (ESAP). It specifies the characteristics of the data publication API, the legal entity identifier (LEI), the classification of types of information, the categories of the size of entities, and the characterisation of industry sectors. The API must support distribution of information in the format received, search and download functions, unrestricted access to free services, and incorporate changes or updates requested by ESMA. Entities submitting information must be identified with an LEI compliant with ISO 17442 and included in the Global Legal Entity Identifier Foundation database. Information must be classified according to types set out in Table 1 of the Annex. Size categories for entities are specified in Table 2 of the Annex, or 'other size' for other Union acts. Industry sectors are classified per Table 3 of the Annex or by NACE main sections. The Regulation applies from 10 July 2026. It requires ESAs to re-assess the LEI technical standards by 31 December 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-1420-implementing-regulation-eu-2025-1420-of-17-july-2025-laying",
    "title": "Commission Implementing Regulation (EU) 2025/1420 laying down rules for the establishment and operation of interoperability regulatory sandboxes",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "Commission Implementing Regulation (EU) 2025/1420 of 17 July 2025 lays down rules for the application of Regulation (EU) 2024/903 (Interoperable Europe Act), specifically regarding the establishment and operation of interoperability regulatory sandboxes. An interoperability regulatory sandbox must be established through a specific agreement between at least three Union entities or public sector bodies, for an initial period not exceeding three years. The regulatory sandbox must meet criteria including a description of objectives, a governance plan, risk management, and evaluation framework. Before formalising the agreement, the sandbox must be notified to and authorised by the Commission. Regulatory sandbox coordinators must designate a single point of contact, manage operations, and ensure periodic reporting to the Commission and the Interoperable Europe Board at least once every six months. Participants may include GovTech actors such as SMEs and startups. Risk management requires a specific risk management plan for each project, with a designated risk manager. Participants must assume full responsibility for the legality of activities. The Commission will maintain a dedicated interface on the Interoperable Europe Portal. Renewal or substantial changes require a new notification procedure. Closing requires submission of a final report within three months.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-1467-implementing-regulation-eu-2025-1467-of-18-july-2025-laying",
    "title": "Commission Implementing Regulation (EU) 2025/1467 laying down technical specifications for the EU SoHO Platform to exchange information concerning substances of human origin",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-18",
    "bluf": "This Commission Implementing Regulation (EU) 2025/1467 of 18 July 2025 lays down rules for the application of Regulation (EU) 2024/1938 as regards the technical specifications for the EU SoHO Platform. The EU SoHO Platform is a digital platform to facilitate efficient and effective exchange of information concerning substances of human origin (SoHO) activities in the Union. The Regulation defines actors, authorised actors, and local administrators; sets requirements for platform maintenance, accessibility via a dedicated website, and minimum modules and functionalities as listed in Annex I. Access is controlled via authentication and authorisation tools, with local administrators managing access rights. Personal data, including data concerning health, pseudonymised when necessary, is processed for obligations under Article 76(1)-(5) of Regulation 2024/1938. Categories of personal data and retention periods are specified in Annex II: up to 5 years after an authorised actor loses capacity, up to 30 years after donation or human application for safety/quality data, and up to 15 years for SoHO Coordination Board members. The general public can view publicly available information without registration. Member States, SoHO competent authorities, the SoHO Coordination Board, the Commission, and SoHO entities must use English for information exchanged when appropriate. The Regulation applies from 7 August 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-1566-implementing-regulation-eu-2025-1566-of-29-july-2025-laying",
    "title": "Commission Implementing Regulation (EU) 2025/1566 of 29 July 2025 laying down rules for application of Regulation (EU) No 910/2014 as regards reference standards for identity and attribute verification for qualified certificates and qualified electronic attestations of attributes",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Commission Implementing Regulation (EU) 2025/1566, adopted on 29 July 2025, establishes reference standards for verifying the identity and attributes of the person to whom a qualified certificate or a qualified electronic attestation of attributes is to be issued under Regulation (EU) No 910/2014 (the eIDAS Regulation). The regulation prescribes the methods and procedures that trust service providers must follow when performing verification of natural and legal persons before issuing qualified certificates or qualified attestations. It covers in-person and remote identity verification, the use of electronic identification schemes, and the reliance on existing identity data from public registers. The rules also address the verification of specific attributes, such as professional qualifications or organizational roles, and set standards for the security and reliability of the verification process. The regulation aims to harmonize identity verification practices across Member States to ensure mutual recognition and high assurance of qualified electronic trust services. The regulation entered into force on the twentieth day following its publication in the Official Journal of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-reg-2025-1929-implementing-regulation-eu-2025-1929-of-29-september-2025-la",
    "title": "Commission Implementing Regulation (EU) 2025/1929 laying down rules for binding date and time to data and establishing accuracy of time sources for qualified electronic time stamps",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Commission Implementing Regulation (EU) 2025/1929 of 29 September 2025 lays down rules for the application of Regulation (EU) No 910/2014 regarding the binding of date and time to data and establishing the accuracy of time sources for qualified electronic time stamps. The regulation sets out reference standards and specifications in an Annex, adopting ETSI EN 319 421 V1.3.1 and ETSI EN 319 422 V1.1.1 with specific adaptations. Key requirements include that generation and protection of TSU keys must occur within secure cryptographic devices certified to Common Criteria EAL 4 or higher, EUCC EAL 4 or higher, or until 31 December 2030 FIPS PUB 140-3 level 3. The regulation mandates compliance with the European Cybersecurity Certification Group's Agreed Cryptographic Mechanisms for key generation, signature algorithms, hash algorithms, and key lengths. Network security requires vulnerability scans at least once per quarter and penetration tests at least once per year. Firewalls must block all non-required protocols. Qualified electronic time stamps must contain a qcStatements extension with the statement 'esi4-qtstStatement-1' not marked as critical. The regulation presumes compliance with relevant requirements of Regulation (EU) No 910/2014 if a trust service provider adheres to the Annex. The regulation entered into force on the twentieth day after publication in the Official Journal of the European Union and is binding in its entirety.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-2455-establishing-a-common-data-platform-on-chemicals-laying-down",
    "title": "Regulation (EU) 2025/2455 establishing a common data platform on chemicals and a monitoring and outlook framework",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Regulation establishes a common data platform on chemicals, managed by the European Chemicals Agency (ECHA), to increase protection of human health and the environment from chemical risks and to facilitate the internal market for chemicals. The platform brings together chemicals data and information generated under Union chemicals acquis, including data from the European Commission and Union agencies (EU-OSHA, ECHA, EEA, EFSA, EMA). It lays down rules to ensure data are findable, accessible, interoperable, and reusable, and establishes a monitoring and outlook framework for chemicals. The Regulation mandates specific data types: environmental monitoring data, human biomonitoring data (hosted by EEA), workplace monitoring data (hosted by ECHA), and data on active substances from medicinal products in a stepwise approach (only data from procedures finalised after entry into force initially, with older data to be incorporated after six years). It creates dedicated services: IPCHEM, a repository of reference values, a database of study notifications, a database on regulatory processes, a database on legal obligations, a repository of standard formats and controlled vocabularies, a database on environmental sustainability, a database on chemicals in articles or products, a database on alternatives to substances of concern, and a dashboard of indicators. Access rights differ: Authorities have full access including confidential information; other parties do not access confidential data via the platform but can request access under Regulation (EC) No 1049/2001. Business operators and laboratories must notify to ECHA's study database studies commissioned for regulatory compliance under Annex I, Part 1 legal acts (obligation starts 22 months after entry into force). The Commission adopts an implementation plan and governance scheme via implementing acts. The Regulation includes provisions on processing human biomonitoring data constituting personal data for substantial public interest, with safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2025-2643-establishing-the-european-defence-industry-programme-and-a-f",
    "title": "Regulation (EU) 2025/2643 establishing the European Defence Industry Programme and a framework of measures to ensure the timely availability and supply of defence products",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Regulation (EU) 2025/2643, adopted on 16 December 2025, establishes the European Defence Industry Programme (EDIP) and a framework of measures to ensure the timely availability and supply of defence products. The Programme provides Union financial support for the period 2025-2027 to reinforce the competitiveness, responsiveness and ability of the European Defence Technological and Industrial Base (EDTIB). It also establishes a Ukraine Support Instrument to incentivise cooperation between Member States and Ukraine to ramp up Ukrainian defence manufacturing capacities and foster common procurement from the Ukrainian DTIB. The Regulation builds on earlier emergency instruments (Regulations 2023/1525 and 2023/2418) and extends their logic into a more long-term perspective. Key actions include common procurement of defence products, industrial reinforcement actions (such as ramping up production capacities, reservation of manufacturing capacities, and reconditioning of expired products), and supporting actions like training and reskilling. Eligibility criteria require recipients to be established and have executive management in the Union, an associated country, or Ukraine, and not be controlled by non-associated third countries. Minimum requirements mandate that components originating outside the Union or associated countries shall not exceed 35% of the cost of the end-product, with raw materials excluded. Derogations are possible for ammunition and missiles under strict conditions. The Regulation sets maximum Union co-financing rates: up to 35% of eligible costs for industrial reinforcement actions, up to 100% for supporting actions and for actions with Ukraine under the Ukraine Support Instrument, and up to 15% of the estimated value for common procurement contracts (up to 25% under certain conditions). At least 15% of the Programme envelope is reserved for common procurement actions and at least 30% for industrial reinforcement actions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2026-0002-implementing-regulation-eu-2026-2-of-9-february-2026-laying",
    "title": "Commission Implementing Regulation (EU) 2026/2 of 9 February 2026 laying down rules for the application of Regulation (EU) 2024/1781 as regards the details and format for the disclosure of information on discarded unsold consumer products",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This Regulation establishes the details and format for the disclosure of information on discarded unsold consumer products, applicable to large enterprises and, from 19 July 2030, medium-sized enterprises that discard unsold consumer products or have them discarded on their behalf. The disclosure obligation concerns discarding as waste for any type of waste treatment operation, including preparing for reuse, recycling, other recovery (e.g. energy recovery), and disposal. Donated products are not covered. Economic operators must disclose annually within 12 months after the end of the financial year, starting from the first full financial year after the date of application (2 March 2027). The visual presentation and content of the disclosure must comply with the format set out in Annex I. Product categories are delimited using the first two digits of the combined nomenclature (CN) codes, except for products listed in Annex II which require four-digit CN codes. Information and documentation necessary to demonstrate delivery and reception of discarded unsold consumer products must be kept for five years after disclosure. Competent national authorities verify compliance using the principles and procedure in Annex III, including a risk-based approach. The Commission must review the Regulation by 2 March 2031. The Regulation entered into force on the twentieth day after publication in the Official Journal and applies from 2 March 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2026-0059-delegated-regulation-eu-2026-59-of-6-january-2026-establishi",
    "title": "Commission Delegated Regulation (EU) 2026/59 of 6 January 2026 establishing a derogation from Article 43(1) of Regulation (EU) 2016/2031 as regards import conditions for wood packaging material in the form of ammunition boxes originating in the United States of America",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Commission Delegated Regulation (EU) 2026/59, adopted on 6 January 2026, establishes a derogation from Article 43(1) of Regulation (EU) 2016/2031 for wood packaging material in the form of ammunition boxes originating in the United States of America, under the control of the United States Department of Defense, and manufactured before 1 September 2007. The derogation exempts these boxes from the ISPM 15 phytosanitary treatment requirements provided they meet specific conditions set out in the Annex. Importers must notify competent authorities at least five working days before introduction, including the date, inventory, importer details, point of entry, and first place of storage. Competent authorities check a representative sample for marks confirming manufacture by 31 August 2007 and treatment with a US EPA-approved wood preservative, repair compliance, absence of bark (bark pieces under 3 cm width or under 50 cm²), and moisture content not more than 20%. Boxes must be stored in closed buildings and moved only in closed containers or under full protective cover. A document from the US Department of Defense must accompany each consignment. Non-compliance must be notified to the Commission and other Member States within three working days. Annual reporting on imports is due by 31 January each year. The Regulation expires on 31 December 2030.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2026-0344-implementing-regulation-eu-2026-344-of-6-october-2025-laying",
    "title": "Commission Implementing Regulation (EU) 2026/344 of 6 October 2025 laying down rules for the application of Regulation (EU) No 1308/2013 as regards marketing standards for poultrymeat",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "This implementing regulation lays down common rules for the application of marketing standards for poultrymeat under Delegated Regulation (EU) 2026/343. It sets out rules on checks of anatomical conformity, with sampling tables specifying batch sizes (100-500, 501-3,200, >3,200), sample sizes (30, 50, 80), and tolerable defective units (total 5,7,10; specific for certain articles 2,4,2). For class B poultrymeat, the tolerable defective units are doubled. Non-compliant batches are prohibited from marketing or import until rectified. It requires special registration for operators using optional reserved terms and mandates inspections at farms, feed manufacturers and suppliers, slaughterhouses, and hatcheries. The regulation defines the chemical method for analysing technically unavoidable water content in chicken carcasses (Annex I) and for poultrymeat cuts (Annex II). It sets up a monitoring system for water absorption in slaughterhouses (Annex III) and for total water content in frozen and quick-frozen carcasses and cuts, with provisions for counter-analysis and reference laboratories (Annex IV). Cooperation and assistance between Member States on water content controls is established, including non-discriminatory random checks, notifications within two working days, and escalation to the Commission for repeated irregularities. Operators must keep records for one year and mark each batch with its date of production. The regulation enters into force on the twentieth day after publication in the Official Journal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-reg-2026-0387-implementing-regulation-eu-2026-387-of-23-february-2026-esta",
    "title": "Commission Implementing Regulation (EU) 2026/387 of 23 February 2026 establishing the format of the European technical assessment pursuant to Regulation (EU) 2024/3110 of the European Parliament and of the Council",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Commission Implementing Regulation (EU) 2026/387, adopted on 23 February 2026, establishes the format of the European technical assessment (ETA) under Regulation (EU) 2024/3110 on construction products. The format is divided into a general part (covering identification and administrative information) and a specific part (covering technical information). The ETA must include fields for a printable ETA (e.g., logos, signature) and for machine-readable ETA (e.g., schema identification, permalink to data template, digital signature). The general part includes fields such as reference to Regulation (EU) 2024/3110, ETA code, version number, date of issue, language, identification number and name/address of the technical assessment body, trade name of the product, full code and title of the European Assessment Document (EAD), manufacturer details, manufacturing plant addresses with optional confidentiality code, page count, number of non-confidential and confidential annexes, and references to confidential annexes. The specific part includes technical description of the product, further specification of intended uses, performance assessment results for each essential characteristic (with name, reference to assessment method, physical quantity per SI metric system, expression as level/class/description, units or dimensionless, additional interpretation information), assessment and verification system(s), technical details not in EAD, reference to legal base, and technical details for implementation. The Regulation also requires fields for the responsible person in the technical assessment body (name and position). Confidential information may be placed in separate annexes not disclosed publicly. The Regulation entered into force on the twentieth day following publication in the Official Journal and is binding in its entirety.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-regulation-1197-98-ecb-staff-tax",
    "title": "Council Regulation (EC) 1197/98 - ECB Staff Taxation",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "This Council Regulation amends the conditions and procedures for applying the tax for the benefit of the European Communities. Specifically, it extends the application of this internal EU tax to the salaries, wages, and emoluments of the members of the Governing Council, the General Council, and the staff of the newly established European Central Bank (ECB). By doing so, it ensures tax harmonization across EU institutions and transitions the tax obligations previously applied to the European Monetary Institute over to the ECB upon the Institute's liquidation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 3
  },
  {
    "node_id": "eu-regulation-1829-2003-gmo-food-feed-authorisation",
    "title": "Regulation (EC) No 1829/2003 - Authorisation and Labelling of Genetically Modified Food and Feed",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Regulation (EC) No 1829/2003 requires that all genetically modified food and feed placed on the EU market receive a centralised authorisation from the European Commission, preceded by a scientific risk assessment by the European Food Safety Authority (EFSA). Authorised products must be labelled, entered in the EU GM food and feed register, subject to post-market monitoring, and comply with a 0.9% threshold for adventitious or technically unavoidable GM presence below which labelling is not required.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "cartagena-protocol-biosafety-2000"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-regulation-1830-2003-gmo-traceability-labelling",
    "title": "Regulation (EC) No 1830/2003 - Traceability and Labelling of Genetically Modified Organisms",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Regulation (EC) No 1830/2003 establishes a mandatory traceability and labelling system for GMOs and food and feed produced from GMOs throughout the EU supply chain. Operators must transmit and retain unique identifiers for authorised GM events at each stage of placing a product on the market, maintain traceability records for five years, and label products indicating they contain or were produced from GMOs, enabling withdrawal in the event of adverse effects on health or the environment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-regulation-1829-2003-gmo-food-feed-authorisation",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-regulation-2004-726-ema-centralised-procedure-marketing-authorisation",
    "title": "EU Regulation 726/2004 - EMA Centralised Procedure for Marketing Authorisation of Medicinal Products",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "Regulation (EC) No 726/2004 establishes the centralised procedure for European Medicines Agency (EMA) marketing authorisation (MA) of medicines for human and veterinary use. Centralised MAs grant simultaneous marketing rights across all EU/EEA member states. The centralised procedure is mandatory for biotechnology-derived medicines, orphan drugs, advanced therapy medicinal products, and certain new active substances. The 210-day assessment procedure involves CHMP and CAT scientific committees, with a 30-day referral to the European Commission for final decision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-clinical-trials-regulation-2014-536-ctr-investigational-medicinal-products"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-regulation-2019-2171-anti-dumping-tungsten",
    "title": "Commission Implementing Regulation (EU) 2019/2171 - Anti-Dumping Investigation",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "This Implementing Regulation initiates an ex-officio investigation into the possible circumvention of anti-dumping measures on tungsten electrodes originating in the People's Republic of China. It targets imports consigned from India, Laos, and Thailand to determine if they are bypassing the established duties. The regulation requires national customs authorities to subject all imports of the specified tungsten electrodes from these countries to mandatory registration, ensuring that retroactive anti-dumping duties can be applied if circumvention is proven.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "eu-regulation-2022-1426-ads-testing-provisions",
    "title": "EU Regulation 2022/1426 - Automated Driving System Type-Approval",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Commission Implementing Regulation (EU) 2022/1426 establishes uniform procedures and technical specifications for type-approval of automated driving systems (ADS) for fully automated vehicles under Article 11 of Regulation (EU) 2019/2144, including simulation-based testing protocols, operational design domain validation, and minimal risk condition requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-general-safety-regulation-2019-2144-vehicles",
      "un-regulation-r157-automated-lane-keeping-alks"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-regulation-2023-1115-deforestation-regulation",
    "title": "EU Deforestation Regulation 2023/1115 - Supply Chain Due Diligence for Deforestation-Free Commodities",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2023-06-29",
    "bluf": "EU Regulation 2023/1115 prohibits placing on or exporting from the EU market seven commodities (cattle, cocoa, coffee, palm oil, soya, wood, rubber) and derived products unless produced on land not deforested after 31 December 2020, with operators required to conduct due diligence and submit statements via EU Information System.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-supply-chain-due-diligence-directive-2024-1760-csddd",
      "csrd-directive-article-2-scope-of-sustainability-reporting"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-regulation-2023-2631-eu-green-bonds-auto",
    "title": "Commission Delegated Regulation (EU) 2021/2139 of 4 June 2021 supplementing Regulation (EU) 2020/852 by establishing the detailed rules for determining the conditions under which an economic activity qualifies as environmentally sustainable for the purposes of the EU Taxonomy, in the sector of transport, including low-emission mobility thresholds for motor vehicles",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation sets technical screening criteria for automotive manufacturers and fleet operators to classify vehicle production and sales as environmentally sustainable under the EU Taxonomy, requiring new passenger cars and light commercial vehicles to emit less than 50 g CO2/km (well-to-wheel) on average across their fleet by 2025, in compliance with Article 20 of Regulation (EU) 2020/852 and Annex I of Delegated Regulation (EU) 2021/2139.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "iso-26262-functional-safety-road-vehicles-2018",
      "australia-national-road-safety-strategy-2021-2030",
      "sae-j3016-levels-driving-automation-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-regulation-511-2014-nagoya-abs-compliance",
    "title": "Regulation (EU) No 511/2014 of the European Parliament and of the Council of 16 April 2014 on compliance measures for users from the Nagoya Protocol on Access to Genetic Resources and the Fair and Equitable Sharing of Benefits Arising from their Utilisation in the Union",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Regulation (EU) No 511/2014 implements the Nagoya Protocol access and benefit-sharing compliance obligations for users of genetic resources in the EU. Article 4 requires users to exercise due diligence to ascertain that genetic resources were accessed lawfully and benefits shared, and to keep the information relevant to access and benefit-sharing for twenty years after the end of the period of utilisation. Article 7 requires due-diligence declarations at research funding and final product development stages, and Article 9 requires competent authorities to carry out risk-based checks on user compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-regulation-ec-178-2002-general-food-law",
    "title": "Regulation (EC) No 178/2002 of the European Parliament and of the Council of 28 January 2002 laying down the general principles and requirements of food law, establishing the European Food Safety Authority and laying down procedures in matters of food safety",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes the foundational principles of EU food law, mandating that food placed on the market must be safe and that food and feed business operators are responsible for ensuring compliance at all stages of production, processing, and distribution. Key requirements include comprehensive traceability (Article 18) and the prohibition of unsafe food (Article 14).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "haccp-food-safety",
      "iso-22000-food-mgt",
      "codex-alimentarius-gen"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-regulation-markets-crypto-2023-title-vi-market-abuse",
    "title": "Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA), Title VI - Market Abuse for Crypto Assets",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Prohibits insider trading and market manipulation in crypto assets and mandates suspicious transaction reporting by Crypto Asset Service Providers (CASPs). Applies to all CASPs operating in the EU under Article 53 and Article 54 of MiCA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dlt-pilot-regime-2022-858",
      "crypto-aml-travel-rule",
      "eu-eba-mica-guidelines-art-emt-authorisation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-reinforced-role-ema-medicines-regulation-2022-123",
    "title": "Regulation (EU) 2022/123 of the European Parliament and of the Council of 25 January 2022 on a reinforced role for the European Medicines Agency in crisis preparedness and management for medicinal products and medical devices",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation reinforces the role of the European Medicines Agency in crisis preparedness and management for medicinal products and medical devices (Article 1). It establishes the Executive Steering Group on Shortages and Safety of Medicinal Products (Article 3), provides for monitoring of events and preparedness for public health emergencies and major events (Article 4), the evaluation of information and recommendations (Article 5), the drawing up of lists of critical medicinal products (Article 6), and the monitoring and reporting of shortages of critical medicines (Articles 7 and 8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-official-controls-regulation-2017-625",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-reinsurance-directive-2005-68-ec-consolidated",
    "title": "Directive 2005/68/EC of the European Parliament and of the Council of 16 November 2005 on Reinsurance",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This directive establishes the prudential and supervisory framework for reinsurance undertakings operating within the EU, including requirements for authorisation, capital adequacy, governance, and cross-border activity under Articles 7, 11, and 17. It applies to all EU-based and third-country reinsurers providing services or establishing branches in the Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-commission-implementing-regulation-2015-2452-solvency",
      "eu-delegated-regulation-2016-2067-spread-market-risk",
      "eu-delegated-regulation-2016-467-non-life-premium-risk",
      "eu-eiopa-guidelines-orsa-2015",
      "eu-insurance-recovery-resolution-directive-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-reinsurance-directive-2005-68-framework",
    "title": "Directive 2005/68/EC of the European Parliament and of the Council of 16 November 2005 on reinsurance and amending Council Directives 73/239/EEC, 92/49/EEC as well as Directives 98/78/EC and 2002/83/EC",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes a harmonised prudential framework for reinsurance undertakings within the European Union, requiring them to obtain a single official authorisation from their home Member State to operate throughout the Community (Article 3) and mandating specific financial guarantees, including a minimum capital requirement and a solvency margin (Title IV).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-remit-wholesale-energy-market-integrity-1227-2011",
    "title": "Regulation (EU) No 1227/2011 of the European Parliament and of the Council of 25 October 2011 on wholesale energy market integrity and transparency (REMIT)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "REMIT establishes rules prohibiting abusive practices on wholesale energy markets. It prohibits insider trading in wholesale energy products by persons possessing inside information (Article 3), requires market participants to publicly disclose inside information in an effective and timely manner (Article 4), and prohibits market manipulation and attempted manipulation (Article 5). The Agency for the Cooperation of Energy Regulators monitors trading to detect abuse (Article 7), collects transaction data (Article 8), and market participants must register with the national regulatory authority (Article 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electricity-regulation-2019-943",
      "crr-iii-eu-implementation-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-renewable-energy-directive-2023-2413",
    "title": "Directive (EU) 2023/2413 on the Promotion of the Use of Energy from Renewable Sources",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Establishes a binding EU-wide target of 42.5% renewable energy by 2030 under Article 3, requiring Member States to accelerate permitting for renewable energy projects, designate 'Go-To Areas' for streamlined deployment, enable Renewable Energy Communities (Article 21), strengthen Guarantees of Origin (Article 19), and set sectoral targets for industry (Article 23). Applies to EU Member States, energy producers, grid operators, and industrial energy users.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-4-2-component-security-2019",
      "iec-62443-industrial-automation-security-standards",
      "iso-14001-2015-environmental-management-industrial",
      "iso-55001-2014-asset-management-industrial",
      "iec-62351-power-systems-cybersecurity"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-renewable-energy-directive-2023-2413-red-iii",
    "title": "Directive (EU) 2023/2413 of the European Parliament and of the Council of 18 October 2023 amending Directive (EU) 2018/2001, Regulation (EU) 2018/1999 and Directive 98/70/EC as regards the promotion of energy from renewable sources, and repealing Council Directive (EU) 2015/652",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This directive (RED III) mandates that by 2030, the share of energy from renewable sources in the EU's gross final consumption of energy must be at least 42.5%, with Member States collectively striving for 45% (Article 3). It applies to EU Member States and impacts energy producers, industrial consumers, and transport fuel suppliers by establishing accelerated permitting procedures and specific sub-targets for renewable hydrogen and other sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-renewable-energy-directive-iii-2023-2413",
    "title": "Directive (EU) 2023/2413 of the European Parliament and of the Council of 18 October 2023 amending Directive (EU) 2018/2001, Regulation (EU) 2018/1999 and Directive 98/70/EC as regards the promotion of energy from renewable sources, and repealing Council Directive (EU) 2015/652",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive (RED III) mandates EU Member States to collectively ensure that the share of energy from renewable sources in the Union's gross final consumption of energy in 2030 is at least 42.5%, with a collective aim for 45%, and introduces accelerated permitting procedures for renewable energy projects (Article 3). It applies to EU Member States, energy producers, and large energy consumers across transport, industry, and building sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-renewable-energy-directive-red-iii-2023",
    "title": "Directive (EU) 2023/2413 (RED III) - Revised Renewable Energy Directive: 42.5% Binding 2030 Target, Accelerated Permitting for Renewables, 42% Renewable Hydrogen in Industry, 14.5% Transport GHG Reduction, Renewable Energy Communities and Member State Contributions",
    "domain": "Energy & Utilities",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive (EU) 2023/2413 of 18 October 2023 amends Directive (EU) 2018/2001 (RED II) to substantially strengthen the EU's renewable energy ambition as part of the Fit for 55 package; the binding 2030 renewable energy target is raised to 42.5% of gross final energy consumption with a non-binding indicative aspiration of 45%; new accelerated permitting provisions designate 'go-to areas' where renewables may be deployed with streamlined 12-month permit processes; sectoral sub-targets include: industry must increase annual renewables share by 1.6 percentage points, hydrogen used in industry must be 42% renewable hydrogen by 2030 rising to 60% by 2035, district heating must increase renewable share by 2.2 percentage points per year, and road and maritime transport fuel must achieve 14.5% GHG intensity reduction from renewable fuels by 2030; Member States must transpose the amended Directive by 21 May 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_ETS",
        "EU_CBAM",
        "EU_TAXONOMY",
        "REPowerEU"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ets-revision-2023-fit-for-55",
      "eu-taxonomy-regulation-2020-852",
      "eu-energy-efficiency-directive-2023-1791"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-rental-lending-directive-2006-115-ec",
    "title": "Directive 2006/115/EC of the European Parliament and of the Council of 12 December 2006 on the rental and lending right and on certain rights related to copyright in the field of intellectual property",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This directive grants authors and performers exclusive rights to authorize or prohibit the rental and lending of their works and phonograms. It mandates equitable remuneration for lending of phonograms and harmonizes the term of protection for related rights at 50 years from fixation or first publication. Key provisions are established in Articles 1, 6, and 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-1886-2024-literary-artistic-works",
      "eu-copyright-directive-art-17",
      "eu-resale-right-directive-2001-84-droit-de-suite"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-representative-actions-directive-2020",
    "title": "Directive (EU) 2020/1828 of the European Parliament and of the Council of 25 November 2020 on representative actions for the protection of the collective interests of consumers and repealing Directive 2009/22/EC",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This directive establishes a harmonised EU-wide mechanism for consumer collective redress, allowing designated 'qualified entities' to bring representative actions against traders for infringements of EU consumer protection laws. As outlined in Articles 5 and 6, these actions can seek both injunctive measures to stop unlawful practices and redress measures, such as compensation or repair, for affected consumers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-antitrust-competition-law",
      "oecd-guidelines-multinational-ent",
      "un-guiding-principles-business-hr"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-resale-right-directive-2001-84-droit-de-suite",
    "title": "Directive 2001/84/EC of the European Parliament and of the Council of 27 September 2001 on the resale right for the benefit of the author of an original work of art",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Establishes a mandatory droit de suite, allowing visual artists or their heirs to receive a royalty on the resale of original works of art when the sale is conducted by a professional art market actor and exceeds EUR 1,000. Applies to galleries, auction houses, and dealers under Article 1(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-1886-2024-literary-artistic-works"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-researcher-charter-code-of-conduct-2005",
    "title": "European Charter for Researchers and Code of Conduct for the Recruitment of Researchers (2005)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes the rights and responsibilities of researchers and research employers in the European Union, mandating transparent, merit-based recruitment and career development under Article II of the Charter and Principle 10 of the Code of Conduct. It applies to all public and private research institutions receiving EU funding or participating in EU research programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-researchers-students-entry-directive-2016-801",
    "title": "Directive (EU) 2016/801 of the European Parliament and of the Council of 11 May 2016 on the conditions of entry and residence of third-country nationals for the purposes of research, studies, training, voluntary service, pupil exchange schemes or educational projects and au pairing",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive lays down the conditions of entry and residence of third-country nationals for research, studies, training, voluntary service, pupil exchange and au pairing (Article 1). Admission is subject to verification of supporting documents and the general and specific conditions (Articles 5, 7 and 8), with an approval procedure for research organisations (Article 9). It provides rights including equal treatment, mobility within the EU for researchers and students, and the ability to stay to seek work or set up a business after completion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-visa-code-regulation-810-2009",
      "eu-long-term-residents-directive-2003-109-ec"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-restructuring-insolvency-directive-2019-1023",
    "title": "EU Directive 2019/1023 on Preventive Restructuring Frameworks, Discharge of Debt and Disqualifications (Restructuring and Insolvency Directive)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Directive (EU) 2019/1023 of the European Parliament and of the Council of 20 June 2019 on preventive restructuring frameworks, on discharge of debt and disqualifications, and on measures to increase the efficiency of procedures concerning restructuring, insolvency and discharge of debt, was in force from 16 July 2019 with transposition deadline 17 July 2021 (extended to 17 July 2022). The Directive is organised in four Titles and 36 Articles. Title I (Arts. 1-19) establishes preventive restructuring frameworks: Art. 1 (subject matter and scope), Art. 2 (definitions including debtor in financial difficulties and stay of individual enforcement actions), Art. 4 (availability of preventive restructuring frameworks for debtors in likelihood of insolvency), Art. 6 (stay of individual enforcement actions for an initial period of up to 4 months extendable to a maximum total of 12 months), Art. 8 (mandatory content of restructuring plans including identity of debtor, assets and liabilities, affected parties classified by classes, restructuring measures and durations), Art. 9 (adoption of plans by affected parties voting in classes), Art. 10 (confirmation by judicial or administrative authority), Art. 11 (cross-class cram-down where the plan is confirmed despite a dissenting class meeting the best-interest-of-creditors test and the absolute priority rule), Art. 12 (treatment of equity holders), Art. 17 (protection of new financing and interim financing including ring-fencing from clawback), Art. 19 (duties of directors when there is a likelihood of insolvency to take steps to avoid insolvency and to minimise loss to creditors). Title II (Arts. 20-26) covers discharge of debt and disqualifications: Art. 20 (access for honest insolvent entrepreneur to a discharge of all debts), Art. 21 (discharge period of no more than 3 years), Art. 22 (disqualifications limited to 3 years), Art. 23 (national derogations including for fraud). Title III (Arts. 27-34) provides common procedural rules including Art. 27 on electronic communication. Title IV (Arts. 35-36) covers final provisions including Art. 31 transposition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-insolvency-regulation-2015-848",
      "uk-insolvency-act-1986-section-214-wrongful-trading-director-liability",
      "fr-code-consommation"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "eu-returns-directive-2008-115",
    "title": "Directive 2008/115/EC of the European Parliament and of the Council of 16 December 2008 on common standards and procedures in Member States for returning illegally staying third-country nationals",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive sets common standards and procedures for returning illegally staying third-country nationals in accordance with fundamental rights (Article 1). When implementing it, Member States must respect non-refoulement, the best interests of the child, family life and health (Article 5). A return decision must be issued to illegally staying persons (Article 6), generally providing an appropriate period for voluntary departure (Article 7), with removal enforced where necessary (Article 8), postponement in defined cases (Article 9), and specific safeguards for unaccompanied minors (Article 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-schengen-borders-code-regulation-2016-399",
      "eu-visa-code-regulation-810-2009"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-revised-product-liability-directive-2024-ai",
    "title": "EU Revised Product Liability Directive 2024/2853 - Liability for AI-Caused Harm",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "EU Directive 2024/2853 on liability for defective products (the revised Product Liability Directive - rPLD), which entered into force on 9 December 2024 and must be transposed by Member States by 9 December 2026, significantly modernises the EU's product liability framework by explicitly covering software and AI systems as 'products' subject to strict liability - manufacturers and importers of AI systems are strictly liable for damage caused by defective AI systems without the injured person needing to prove fault; the Directive introduces a rebuttable presumption of defectiveness where the manufacturer fails to comply with EU AI Act mandatory safety requirements or fails to cooperate with disclosure obligations; it also introduces a rebuttable presumption of causation where technical complexity makes establishing the causal link excessively difficult for the claimant.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-revised-product-liability-directive-2024-ai.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-15-robustness",
      "eu-ai-act-annex-iv-technical-documentation-requirements"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-right-to-repair-directive-2024-1799",
    "title": "Directive (EU) 2024/1799 on common rules promoting the repair of goods - manufacturer repair obligation, European Repair Information Form and European online platform for repair",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Directive (EU) 2024/1799 (the EU Right to Repair Directive), adopted 13 June 2024, requires manufacturers to repair goods on a consumer's request where repairability requirements are set by Union legal acts listed in Annex II. Repairers may issue a European Repair Information Form whose conditions cannot be altered for 30 calendar days, and a European online platform for repair must be established so consumers can find repairers. Member States must transpose the Directive by 31 July 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecodesign-sustainable-products-regulation-2024-1781",
      "eu-empowering-consumers-green-transition-directive-2024-825",
      "eu-weee-directive-2012-19"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-road-infrastructure-safety-management-directive-2008-96",
    "title": "Directive 2008/96/EC of the European Parliament and of the Council of 19 November 2008 on road infrastructure safety management",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive requires Member States to establish and implement road infrastructure safety procedures (Article 1). It mandates road safety impact assessments for infrastructure projects (Article 3), road safety audits at design and operational stages (Article 4), safety ranking and management of the network in operation (Article 5), safety inspections of roads in operation (Article 6), accident reporting and data management for fatal accidents (Article 7), and the appointment and training of qualified road safety auditors (Article 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-39001-road-traffic-safety-management",
      "eu-intelligent-transport-systems-directive-2010-40"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-road-safety-policy-framework-2021-2030",
    "title": "EU Road Safety Policy Framework 2021-2030 - Next steps towards 'Vision Zero'",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This EU policy framework requires Member States to adopt a 'Safe System' approach and implement national strategies to achieve the 'Vision Zero' target of a 50% reduction in road deaths and serious injuries by 2030, monitored through a set of Key Performance Indicators (KPIs) as outlined in the Commission Staff Working Document SWD(2019) 283 final.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-road-transport-operator-access-regulation-1071-2009",
    "title": "Regulation (EC) No 1071/2009 of the European Parliament and of the Council of 21 October 2009 establishing common rules concerning the conditions to be complied with to pursue the occupation of road transport operator",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation governs admission to and pursuit of the occupation of road transport operator (Article 1). An undertaking must have an effective and stable establishment, be of good repute, have appropriate financial standing, and have the requisite professional competence (Article 3), and must designate a transport manager who effectively and continuously manages the transport activities (Article 4). It sets the conditions for each requirement (Articles 5 to 8) and procedures for authorisation, monitoring, suspension and withdrawal (Articles 11 to 13).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tachograph-regulation-165-2014",
      "eu-drivers-driving-time-regulation-561-2006"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-roaming-regulation-2022-612",
    "title": "Regulation (EU) 2022/612 of the European Parliament and of the Council of 6 April 2022 on roaming on public mobile communications networks within the Union (recast)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation extends the 'Roam Like at Home' scheme until 2032, requiring mobile network operators to provide roaming services at domestic prices within the EU and ensuring customers receive the same quality of service abroad as at home (Article 4). It also establishes new, lower wholesale roaming caps and enhances transparency measures for value-added services (Article 14).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-rohs-directive-2011-65",
    "title": "EU RoHS Directive 2011/65 (RoHS 2)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2015-07-22",
    "bluf": "Directive 2011/65/EU on the restriction of the use of certain hazardous substances in electrical and electronic equipment (RoHS 2), in force from 2 January 2013 and extended to all EEE categories from 22 July 2019, prohibits the placing on the EU market of EEE containing more than 0.01% cadmium or more than 0.1% lead, mercury, hexavalent chromium, polybrominated biphenyls (PBB), polybrominated diphenyl ethers (PBDE), or four restricted phthalates (DEHP, BBP, DBP, DIBP) by weight in homogeneous materials, with manufacturers required to draw up technical documentation, affix CE marking, and issue an EU Declaration of Conformity, subject to time-limited exemptions in Annexes III and IV for applications where substitution is technically impracticable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-reach-regulation-1907-2006",
        "eu-ecodesign-sustainable-products-regulation-2024-1781",
        "eu-batteries-regulation-2023-1542"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-reach-regulation-1907-2006",
      "eu-ecodesign-sustainable-products-regulation-2024-1781",
      "eu-batteries-regulation-2023-1542"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-rohs-directive-2011-65-eu",
    "title": "EU Restriction of Hazardous Substances Directive 2011/65/EU (RoHS)",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Directive 2011/65/EU (RoHS recast) restricts the use of ten hazardous substances in electrical and electronic equipment (EEE) placed on the EU market: lead mercury cadmium hexavalent chromium polybrominated biphenyls (PBB) polybrominated diphenyl ethers (PBDE) bis(2-ethylhexyl) phthalate (DEHP) butyl benzyl phthalate (BBP) dibutyl phthalate (DBP) and diisobutyl phthalate (DIBP). Manufacturers must ensure compliance with concentration limits (0.1% by weight except cadmium at 0.01%) and provide CE marking declaration of conformity and technical documentation. Annex III provides exemptions for specific applications time-limited and reviewable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-rome-i-regulation-593-2008",
    "title": "EU Rome I Regulation 593/2008 - Applicable Law for Contractual Obligations",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EC) 593/2008 (Rome I) determines which national law governs contractual obligations in cross-border civil and commercial matters within the EU. It allows parties to freely choose the applicable law (party autonomy), subject to mandatory rules and public policy overrides. In the absence of choice, contracts are governed by the law of the country where the seller/service provider has habitual residence, with specific rules for consumer contracts (law of consumer's country), employment contracts (law of habitual workplace), insurance contracts, and carriage of goods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-trade-secrets-directive-2016-943",
      "eu-consumer-credit-directive-2023-2225",
      "eu-employment-equality-directive-2000-78",
      "eu-posted-workers-directive-2018-957"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-rome-ii-regulation-864-2007",
    "title": "EU Rome II Regulation 864/2007 - Applicable Law for Non-Contractual Obligations",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EC) 864/2007 (Rome II) establishes uniform EU rules for determining which country's law governs non-contractual obligations - principally tort (delict), unjust enrichment, negotiorum gestio (agency without authority), and culpa in contrahendo (pre-contractual liability). The general rule is the law of the country where the damage occurs (lex loci damni), not where the act causing it occurred. Special rules apply to product liability (habitual residence of victim/place of sale), IP infringement (lex protectionis), and unfair competition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-trade-secrets-directive-2016-943",
      "eu-consumer-credit-directive-2023-2225",
      "eu-employment-equality-directive-2000-78",
      "eu-posted-workers-directive-2018-957"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-satellite-cable-directive-1993-83-ec",
    "title": "Council Directive 93/83/EEC of 27 September 1993 on the coordination of certain rules concerning copyright and rights related to copyright applicable to satellite broadcasting and cable retransmission",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive establishes the 'country of origin' principle for satellite broadcasting, meaning that authorization for transmission is governed solely by the law of the Member State from which the broadcast originates (Article 2). It mandates collective licensing for cable retransmission of broadcast programs and harmonizes territorial copyright clearance rules across EU Member States (Article 6). Applies to broadcasters, cable operators, and rights management organizations operating within the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-1886-2024-literary-artistic-works",
      "eu-copyright-directive-art-17",
      "eu-resale-right-directive-2001-84-droit-de-suite",
      "iptc-photo-metadata",
      "exif-standard-metadata"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-schengen-borders-code-regulation-2016-399",
    "title": "EU Schengen Borders Code Regulation 2016/399 - Internal Border Abolition, External Border Checks and Reintroduction Triggers",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "Regulation (EU) 2016/399 of the European Parliament and of the Council of 9 March 2016 on a Union Code on the rules governing the movement of persons across borders (Schengen Borders Code, SBC, codified version) consolidates the legal framework for the Schengen area without internal border checks. Title II governs external borders (Articles 3-22): all persons crossing external borders are subject to checks, with third-country nationals undergoing thorough checks under Article 8(3) for entry conditions per Article 6, while EU citizens and beneficiaries of free movement undergo minimum checks under Article 8(2). Title III governs internal borders (Articles 22-35): Article 22 prohibits checks on persons at internal borders, regardless of their nationality. Articles 25-30 establish exceptions allowing temporary reintroduction of internal border controls in case of serious threat to public policy or internal security, for renewable periods totalling up to two years (Article 25(4)) or, exceptionally, two years and six months under Article 29 for serious deficiencies in external border control. The 2024 amendment by Regulation (EU) 2024/1717 modernised reintroduction procedures and extended the maximum period to three years in exceptional circumstances. The Code applies in all 27 EU Member States except Ireland, plus Iceland, Liechtenstein, Norway and Switzerland (Schengen Associated Countries).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dublin-iii-regulation-604-2013-asylum-responsibility",
      "eu-entry-exit-system-regulation-2017-2226"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-screening-regulation-2024-1356",
    "title": "Regulation (EU) 2024/1356 introducing the screening of third-country nationals at the external borders - scope, seven-day external-border screening and three-day in-territory screening",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Regulation (EU) 2024/1356, adopted 14 May 2024 as part of the EU Pact on Migration and Asylum, establishes a mandatory screening at the external borders of third-country nationals who do not fulfil entry conditions. The screening applies to those apprehended in connection with unauthorised border crossing and must be completed within seven days from apprehension at the external border, or three days for screening within the territory. It comprises preliminary health and vulnerability checks, identification, biometric registration, security checks and referral to the appropriate procedure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dublin-iii-regulation-604-2013-asylum-responsibility",
      "eu-reception-conditions-directive-2024-1346",
      "eu-ai-act-high-risk-migration-border"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-securitisation-regulation-2017-2402",
    "title": "EU Securitisation Regulation 2017/2402 - STS Framework, 5% Risk Retention, ESMA Repository",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2021-04-06",
    "bluf": "Regulation (EU) 2017/2402 establishes a common EU securitisation framework and creates the Simple, Transparent and Standardised (STS) label. Key requirements: Article 6 - mandatory 5% risk retention by the originator, sponsor, or original lender (no hedging, no sale); Article 7 - transparency: originators, sponsors, and SSPEs must make loan-level data, transaction documents, investor reports, and inside information available via a securitisation repository registered with ESMA; Articles 19-26 - STS criteria for non-ABCP (asset-backed commercial paper) securitisations, including true sale, homogeneous portfolio, no re-securitisation, AAA-equivalent underlying credit quality; Article 18 - STS notification to ESMA public list; Regulation (EU) 2021/557 adds STS criteria for synthetic balance sheet securitisations. Institutional investors (Article 5) must conduct due diligence before investing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "CRR2_capital_treatment",
        "AIFMD_STS_investment",
        "SFDR_ESG_CLO",
        "AML_SSPE",
        "MAR_inside_information"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-regulation-2024",
      "eu-market-abuse-regulation-596-2014",
      "eu-aifmd-directive-2011-61"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-security-gas-supply-regulation-2017-1938",
    "title": "Regulation (EU) 2017/1938 of the European Parliament and of the Council of 25 October 2017 concerning measures to safeguard the security of gas supply and repealing Regulation (EU) No 994/2010",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires EU Member States to ensure a high level of gas supply security by meeting the N-1 infrastructure standard, conducting risk assessments, and establishing national and regional Preventive Action Plans, Emergency Plans, and a solidarity mechanism to assist neighboring states during a severe gas crisis (Articles 5, 7, 8, and 13).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-22301-biz-continuity"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-seeds-directive-2002-53-ec",
    "title": "EU Common Catalogue of Varieties of Agricultural Plant Species Directive 2002/53/EC",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Directive 2002/53/EC establishes the EU Common Catalogue of Varieties of Agricultural Plant Species which lists all varieties of agricultural plant species (cereals fodder plants oil and fibre plants beet potatoes etc.) whose seeds and propagating material may be marketed in the EU. Varieties must be registered in at least one Member State catalogue based on DUS (distinct uniform stable) and VCU (value for cultivation and use) tests before entry to the Common Catalogue. The 2024 Plant Reproductive Material Regulation proposal would modernise and unify the eight seeds and propagating material directives into a single framework but Directive 2002/53/EC remains in force pending adoption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-sepa-regulation-260-2012",
    "title": "EU SEPA Regulation 260/2012 - Single Euro Payments Area Credit Transfers and Direct Debits",
    "domain": "Banking & Global Finance",
    "version": "1.2.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 260/2012 establishes technical and business requirements for SEPA credit transfers (SCT) and SEPA direct debits (SDD) in euros, mandating IBAN as the sole account identifier, ISO 20022 XML messaging, and T+1 execution time for SCT. All EU PSPs must be reachable for SEPA transactions. National credit transfer and direct debit schemes were replaced by SEPA by August 2014. Amended by Regulation (EU) 2024/886 to add mandatory instant payment reachability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-psd2-strong-customer-authentication",
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-aml-regulation-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-service-of-documents-regulation-2020-1784",
    "title": "Regulation (EU) 2020/1784 of the European Parliament and of the Council of 25 November 2020 on the service in the Member States of judicial and extrajudicial documents in civil or commercial matters (service of documents) (recast)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This recast Regulation governs the cross-border service of judicial and extrajudicial documents in civil or commercial matters between Member States (Article 1). Each Member State designates transmitting and receiving agencies and a central body (Articles 3 and 4), with documents transmitted through a secure decentralised IT system whose electronic documents have legal effect (Articles 5 and 6). It provides assistance in address enquiries (Article 7), fast transmission of documents (Article 8), and safeguards including the right of the addressee to refuse a document not in an understood language.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taking-of-evidence-regulation-2020-1783",
      "eu-brussels-iib-matrimonial-parental-jurisdiction-regulation-2019-1111"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-services-directive-2006-123",
    "title": "EU Services Directive 2006/123/EC - Internal Market for Services and Point of Single Contact",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Directive 2006/123/EC of the European Parliament and of the Council (the Services Directive) establishes the legal framework for the internal market for services in the European Union. Article 9 requires that authorisation schemes for service providers be non-discriminatory, justified by an overriding reason of public interest, and proportionate. Article 13 requires competent authorities to process licence applications within a reasonable period and provides for administrative silence to operate as approval where the deadline is exceeded. Articles 14 and 15 prohibit or require evaluation of specific requirements applicable to service providers. Article 16 guarantees freedom to provide services temporarily in another Member State without establishment. Articles 28 to 36 require each Member State to establish a Point of Single Contact (PSC) where service providers can complete all procedures and formalities electronically. The Services Directive was implemented in all EU Member States by December 28, 2009.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ecn_plus_directive",
        "eu_digital_single_market",
        "eu_professional_qualifications_2005_36",
        "eu_e_commerce_directive_2000_31",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecn-plus-directive-2019-nca-powers",
      "eu-consumer-credit-directive-2023-2225",
      "eu-digital-content-services-directive-2019-770"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-seveso-iii-directive-2012-18-eu",
    "title": "EU Seveso III Directive 2012/18/EU on control of major-accident hazards involving dangerous substances",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Directive 2012/18/EU (Seveso III) establishes rules for the prevention of major accidents involving dangerous substances and the limitation of their consequences for human health and the environment across the European Union. It applies to establishments where dangerous substances are present in quantities at or above thresholds defined in Annex I, distinguishing between lower-tier and upper-tier establishments. Operators are required to take all necessary measures to prevent major accidents, to submit notifications to competent authorities containing details such as operator name, address, dangerous substances present, quantities, activities, and immediate environment including neighbouring establishments. They must also draw up a Major Accident Prevention Policy (MAPP) proportionate to hazards, reviewed at least every five years, and for upper-tier establishments, produce a safety report demonstrating hazard identification, risk analysis, and adequate safety measures. Domino effect risks must be assessed where establishments are in proximity, requiring operator cooperation on information exchange and public information. Internal and external emergency plans must be prepared for upper-tier establishments, reviewed and tested at intervals no longer than three years. Land-use policies must ensure appropriate safety distances between hazardous establishments and residential areas, public use zones, and sensitive natural areas. Competent authorities conduct routine and non-routine inspections to verify compliance, and information on major accidents is forwarded to the Commission for analysis and lessons learned. The directive aligns classification of dangerous substances with Regulation (EC) No 1272/2008.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-seveso-iii-directive-2012-18-major-hazard",
    "title": "Directive 2012/18/EU of the European Parliament and of the Council of 4 July 2012 on the control of major-accident hazards involving dangerous substances, amending and subsequently repealing Council Directive 96/82/EC",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Seveso III Directive requires operators of industrial sites handling dangerous substances above threshold quantities to implement a Safety Management System, develop emergency plans, and ensure land-use planning and public information measures are in place to prevent major accidents and limit their consequences. Key obligations are established under Articles 8, 9, 10, and 12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-4-2-component-security-2019",
      "iso-14001-2015-environmental-management-industrial",
      "iso-55001-2014-asset-management-industrial",
      "iec-62443-industrial-automation-security-standards",
      "isa-99-iec-62443-industrial-security-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-sfdr-2019-2088",
    "title": "Regulation (EU) 2019/2088 of the European Parliament and of the Council of 27 November 2019 on sustainability‐related disclosures in the financial services sector",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The EU Sustainable Finance Disclosure Regulation (SFDR) mandates that EU-based financial market participants and financial advisers disclose how they integrate sustainability risks and consider adverse sustainability impacts in their investment processes and financial products, as outlined in Articles 3, 4, and 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-sustainable",
      "csrd-eu-sustainability",
      "tcfd-climate-risk",
      "un-pri-investment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-sfdr-2019-2088-article-4-adverse-sustainability-impacts-disclosure",
    "title": "Regulation (EU) 2019/2088 on sustainability-related disclosures in the financial services sector - Article 4: Transparency of adverse sustainability impacts at entity level",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Financial market participants must publish and maintain information on their websites regarding the principal adverse impacts of investment decisions on sustainability factors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-sfdr-insurance-based-investment-products-2022",
    "title": "Regulation (EU) 2019/2088 of the European Parliament and of the Council of 27 November 2019 on sustainability-related disclosures in the financial services sector",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation requires providers of Insurance-Based Investment Products (IBIPs), including unit-linked and with-profit policies, to classify financial products under Article 6, 8, or 9 of SFDR and disclose sustainability-related information at pre-contractual and periodic reporting stages. It applies to EU insurance undertakings offering IBIPs integrated with PRIIPs obligations under Regulation (EU) No 1286/2014.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-commission-implementing-regulation-2015-2452-solvency",
      "eu-delegated-regulation-2016-2067-spread-market-risk",
      "eu-delegated-regulation-2016-467-non-life-premium-risk",
      "eu-eiopa-guidelines-orsa-2015",
      "ifrs-s2-climate"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-sfdr-regulation-2019-2088-sustainable-finance-disclosure",
    "title": "EU SFDR (Sustainable Finance Disclosure Regulation) 2019/2088 - ESG Disclosure Obligations for Financial Market Participants and Financial Advisers",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "SFDR (Regulation EU 2019/2088) requires financial market participants (investment managers, insurance companies, pension funds, banks with portfolio management) and financial advisers to make standardised sustainability disclosures at entity level (website) and product level (pre-contractual documents, periodic reports). Products are classified as Article 6 (no sustainability claims), Article 8 (promotes environmental/social characteristics), or Article 9 (has sustainable investment as objective).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852-sustainable-finance-classification"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-sfdr-reporting",
    "title": "SFDR: Sustainable Finance Disclosure",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "As a financial market participant and financial adviser under Regulation (EU) 2019/2088, this entity is subject to comprehensive sustainability-related disclosure obligations. Exceeding the 500-employee count makes compliance with SFDR Article 4 mandatory, requiring a published statement on due diligence policies for principal adverse impacts on sustainability factors, an obligation which is fulfilled. All financial products are classified under SFDR Article 6, indicating sustainability risks are integrated into investment decisions, but the products do not promote environmental or social characteristics as defined by Article 8, nor do they pursue a sustainable investment objective per Article 9. Consequently, disclosures confirm a zero percent alignment with the EU Taxonomy’s environmental objectives. The entity meets its transparency duties through published website information and completed pre-contractual documents, whose content and presentation adhere to the detailed requirements of Commission Delegated Regulation (EU) 2022/1288. Periodic reporting is also required, and the firm’s remuneration policy has been properly updated to reflect how it integrates sustainability risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-sustainable",
      "csrd-eu-sustainability"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-sftr-2015-2365",
    "title": "EU SFTR - Securities Financing Transactions Regulation 2015/2365",
    "domain": "Banking & Global Finance",
    "version": "2.0.0",
    "last_updated": "2021-04-11",
    "bluf": "Regulation (EU) 2015/2365 (SFTR) introduces mandatory reporting of all securities financing transactions (repos, securities lending, buy-sell backs, total return swaps) to registered trade repositories, requires disclosure of SFT use in UCITS and AIF fund documents, and imposes collateral reuse conditions - targeting shadow banking transparency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-emir-regulation-648-2012",
      "eu-csdr-regulation-909-2014",
      "eu-ucits-directive-2009-65"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-sftr-securities-financing-transactions-2015-2365",
    "title": "EU Securities Financing Transactions Regulation 2015/2365 (SFTR) - Transparency and Reporting",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "EU Regulation 2015/2365 (SFTR) requires counterparties to securities financing transactions (SFTs) - including repos, reverse repos, securities lending, securities borrowing, buy-sell-backs, sell-buy-backs, and margin loans - to report SFT details to a registered trade repository within one business day of conclusion, modification, or termination. SFTR also establishes reuse conditions for received collateral, requires disclosure of SFTs in prospectuses and periodic reports for UCITS and AIFs, and applies to EU counterparties plus EU branches of third-country firms. The ESMA coordinates TRs and publishes aggregated SFT statistics for systemic risk monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-emir-regulation-648-2012",
      "eu-ucits-directive-2009-65",
      "eu-aifmd-directive-2011-61"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-shareholder-rights-directive-ii-2017-828",
    "title": "EU Shareholder Rights Directive II - Directive 2017/828/EU (SRD II)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2020-09-03",
    "bluf": "Directive (EU) 2017/828 (SRD II) strengthens shareholder engagement in listed EU companies by requiring institutional investors and asset managers to develop and publicly disclose stewardship/engagement policies, mandating executive remuneration policy shareholder votes (binding or advisory), and creating a right for companies to identify their shareholders through intermediary chains - with a 3-business-day shareholder identification response deadline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csrd-2022-2464",
      "eu-market-abuse-regulation-596-2014",
      "eu-accounting-directive-2013-34"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ship-recycling-regulation-1257-2013",
    "title": "Regulation (EU) No 1257/2013 on ship recycling and amending the Regulation (EC) No 1013/2006 and Directive 2009/16/EC",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Ship Recycling Regulation 1257/2013 establishes strict requirements for the safe and environmentally sound recycling of ships flying the flag of EU Member States. It mandates the creation of an Inventory of Hazardous Materials (IHM) compliant with Article 5, requires pre-cleaning of hazardous substances before recycling under Article 8, mandates notification to the flag State authority prior to recycling under Article 12, and restricts ship recycling to facilities listed on the European List of Approved Facilities under Article 3(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14090-climate-adapt",
      "gstc-tourism-criteria",
      "iso-15489-1-2016-records-management-workflow"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ship-recycling-regulation-1257-2013-hong-kong-convention",
    "title": "EU Ship Recycling Regulation 1257/2013 - Hazardous Materials Inventory & Approved Facility",
    "domain": "Maritime & Shipping",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "EU Ship Recycling Regulation 1257/2013 (mirroring Hong Kong Convention) requires EU-flagged ships to maintain an Inventory of Hazardous Materials (IHM) certified by flag state, and ensures ship recycling at EU-approved or equivalent facilities - prohibiting toxic dumping on developing country beaches.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-short-selling-regulation-236-2012",
    "title": "EU Short Selling Regulation 236/2012 - Short Selling and CDS Restrictions",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2022-01-01",
    "bluf": "Regulation (EU) No 236/2012 (SSR) imposes transparency obligations on significant short positions in EU-listed shares (0.2%/0.5% thresholds), net short positions in EU sovereign debt, restrictions on uncovered short selling, and prohibitions on uncovered sovereign CDS - with ESMA emergency powers to temporarily restrict short selling during adverse market conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mifid-ii",
      "eu-emir-regulation-648-2012",
      "eu-market-abuse-regulation-596-2014"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-single-cmo-regulation-1308-2013",
    "title": "EU Single CMO Regulation 1308/2013 - Common organisation of agricultural product markets, including market intervention, marketing standards, wine and school schemes",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Regulation (EU) No 1308/2013, adopted on 17 December 2013 by the European Parliament and the Council, establishes a replacement common organisation of the markets (CMO) for agricultural products listed in Annex I to the TFEU, repealing and replacing Council Regulation (EC) No 1234/2007 and others. It covers all basic elements of a market common organisation, including public intervention and private storage aid for sectors such as cereals, rice, sugar, beef, veal, pigmeat, sheepmeat, goatmeat, milk, olive oil, fruit and vegetables, wine, and hops. The regulation sets Union scales for carcass classification to improve price recording and market transparency. It provides for a differentiated market support system including fixed intervention prices for certain quantities and tendering for others, and rules for disposal of bought-in products, including use for food distribution to the most deprived. It establishes school fruit and vegetables and school milk schemes with Union aid for supply to children, with provisions against replacing national funding and for publicising Union subsidisation. For the olive oil and table olives sector, Union financing supports work programmes by producer and interbranch organisations. For fruit and vegetables, operational funds and programmes financed jointly by producers and the Union are established, with crisis management measures. The wine sector includes national support programmes for promotion, restructuring, innovation, investments, harvest insurance, mutual funds, and green harvesting, plus a new system of authorisations for vine plantings from 2016 to 2030 (capped at 1% per year, with replanting authorisations automatic). Beekeeping programmes are established, partly Union-financed. Marketing standards are set for many sectors, including obligatory rules and optional reserved terms; products must be sound, fair, marketable, and for fresh fruit and vegetables country of origin must be indicated. For wine, oenological practices, classification of wine grape varieties, and rules for protected designations of origin and geographical indications are established. The European Commission is delegated power to adopt non-essential amendments via delegated acts under Article 290 TFEU. Compliance is governed by Regulation (EU) No 1306/2013 for checks and penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-single-digital-gateway-regulation-2018-1724",
    "title": "Regulation (EU) 2018/1724 of the European Parliament and of the Council of 28 November 2018 on establishing a Single Digital Gateway to provide access to information, procedures and assistance and problem-solving services for citizens and businesses",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EU Single Digital Gateway Regulation requires Member States to provide a single digital entry point for citizens and businesses to access information, procedures, and assistance related to rights and obligations under EU law. It applies to all public administrative procedures affecting cross-border movement of people, goods, services, and capital, as established under Article 5 and Article 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-automated-decision-workflows",
      "eu-nis2-directive-workflow-critical-operations",
      "azure-logic-apps-enterprise-integration"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-single-european-sky-air-navigation-services-regulation-2024-2803",
    "title": "Regulation (EU) 2024/2803 of the European Parliament and of the Council of 23 October 2024 on the implementation of the Single European Sky (recast)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This recast Regulation lays down rules for the implementation of the Single European Sky to enhance the safety and performance of air traffic management and air navigation services in the Union (Article 1). It provides for functional airspace blocks (Article 3), requires Member States to nominate or establish national supervisory authorities with the required independence (Article 4) and defines their tasks (Article 5). It governs the provision of services by air navigation service providers (Article 7), the designation of air traffic service providers (Article 8) and of MET providers (Article 10), the provision of common information services (Article 12), and establishes a Performance Review Board and a performance scheme with Union-wide performance targets (Articles 13, 21 and 22).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-easa-basic-regulation-2018-1139-common-rules-civil-aviation",
      "eu-u-space-regulation-2021-664-drone-atm"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-single-resolution-mechanism-regulation-806-2014",
    "title": "EU Single Resolution Mechanism Regulation 806/2014 (SRMR)",
    "domain": "Banking & Global Finance",
    "version": "2.0.0",
    "last_updated": "2021-12-28",
    "bluf": "Regulation (EU) No 806/2014 (SRMR) establishes the Single Resolution Mechanism (SRM) - the second pillar of the EU Banking Union - creating the Single Resolution Board (SRB) as the central resolution authority for systemic banks in the Banking Union, operating the Single Resolution Fund (SRF) of approximately €78 billion, and applying BRRD resolution tools through a centralised decision-making procedure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-emir-regulation-648-2012",
      "eu-csdr-regulation-909-2014"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-single-supervisory-mechanism-regulation-1024-2013",
    "title": "EU Single Supervisory Mechanism Regulation 1024/2013 (SSMR) - ECB Banking Supervision",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation 1024/2013 confers on the ECB specific tasks concerning prudential supervision of credit institutions in the euro area and participating non-euro Member States. The ECB directly supervises Significant Institutions (SIs) - institutions meeting any of: total assets >€30 billion, assets >20% of GDP (with >€5B), cross-border activity, or public financial assistance - through Joint Supervisory Teams (JSTs). Less Significant Institutions (LSIs) are supervised by national competent authorities (NCAs) under ECB oversight. The SREP (Supervisory Review and Evaluation Process) is the ECB's primary supervisory tool for assessing SI risk profiles and capital and liquidity adequacy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-brrd-bank-recovery-resolution-directive-2014-59",
      "eu-single-resolution-mechanism-regulation-806-2014"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-single-use-plastics-directive-2019-904-hospitality",
    "title": "Directive (EU) 2019/904 of the European Parliament and of the Council of 5 June 2019 on the reduction of the impact of certain plastic products on the environment",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive prohibits the placing on the market of specific single-use plastic items in the hospitality sector, including tableware, expanded polystyrene food and beverage containers, and plastic straws and stirrers, effective from 3 July 2021. It applies to all food service operators in EU member states providing takeaway or on-site consumption under Article 5(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-hygiene-regulation-852-2004",
      "eu-food-labelling-regulation-1169-2011",
      "codex-alimentarius-general-principles-hygiene-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-sis-return-illegally-staying-third-country-nationals-regulation-2018-1860",
    "title": "Regulation (EU) 2018/1860 of the European Parliament and of the Council of 28 November 2018 on the use of the Schengen Information System for the return of illegally staying third-country nationals",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation governs the use of the Schengen Information System (SIS) for the return of illegally staying third-country nationals (Article 1). Member States must enter an alert on return into SIS following a return decision (Article 3), defining the categories of data (Article 4) and the authority responsible for the exchange of supplementary information (Article 5). It sets procedures for hits at the external borders on exit confirming return (Article 6), handling of non-compliance with return decisions (Article 7), hits on entry (Article 8), prior consultation before granting a residence permit (Article 9), and deletion of alerts once return is confirmed (Article 14).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-returns-directive-2008-115",
      "eu-schengen-borders-code-regulation-2016-399"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-smart-metering-directive-obligations",
    "title": "Smart Metering Obligations under Directive (EU) 2019/944 on common rules for the internal market for electricity",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive requires EU Member States to ensure the rollout of smart metering systems for electricity consumers, contingent upon a positive long-term cost-benefit analysis (CBA). It establishes consumer rights regarding data access, privacy, interoperability, and transparent billing, as detailed in Articles 19-22 and Annex II.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-46-transfer-mechanisms",
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-smart-metering-implementation-directive-2022",
    "title": "Implementation of Smart Metering Systems under the Internal Market for Electricity Directive (EU) 2019/944",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This framework mandates EU Member States to ensure the large-scale rollout of smart electricity meters for at least 80% of consumers by 2024, contingent upon a positive national cost-benefit analysis. It establishes consumer rights for near real-time data access, mandates system interoperability, and enforces robust data protection and security safeguards, as detailed in Articles 19-24 of Directive (EU) 2019/944.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gdpr-binding-corporate-rules",
      "eu-cybersecurity-act-enisa-certification-framework",
      "nist-sp-800-161r1-csrm-practices"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-smd-services-market-directive-accessibility-2022",
    "title": "Directive (EU) 2016/2102 of the European Parliament and of the Council of 26 October 2016 on the accessibility of the websites and mobile applications of public sector bodies",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive requires all public sector websites and mobile applications within the EU to conform to WCAG 2.1 Level AA standards, publish an accessibility statement, and undergo regular monitoring and reporting. It applies to all public sector bodies except for certain exemptions defined in Article 3, with key obligations outlined in Articles 4, 9, and 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-accessibility-act-2019",
      "iso-10002-2018-customer-satisfaction-complaints",
      "eu-omnibus-directive-2019-2161",
      "eu-consumer-rights-directive-2011",
      "eu-geo-blocking-regulation-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-soil-monitoring-resilience-directive-2025-2360",
    "title": "Directive (EU) 2025/2360 of the European Parliament and of the Council of 12 November 2025 on soil monitoring and resilience (Soil Monitoring Directive)",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive establishes a framework for soil monitoring and the resilience of soils, with the objective of achieving healthy soils across the Union (Articles 1 and 2). Member States must establish soil districts and soil units (Article 4), set up a monitoring framework for soil health and for soil sealing and soil removal (Article 6), apply soil descriptors and criteria for healthy soil condition (Article 7), carry out measurements and soil health assessments (Articles 9 and 10), and identify, investigate and manage potentially contaminated and contaminated sites following a risk-based and stepwise approach (Articles 13 to 16), maintaining a register of contaminated sites (Article 17).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-deforestation-regulation-2023-1115",
      "eu-sup-single-use-plastics-2019-904"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-solar-energy-strategy-accelerated-permitting-2022",
    "title": "Communication from the Commission: EU Solar Energy Strategy",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This EU strategy mandates accelerated permitting for solar energy projects, establishing 'renewables go-to areas' with permit decisions within one year and a maximum two-year process elsewhere, as outlined in the Commission Recommendation C(2022) 3219. It also introduces phased-in obligations for rooftop solar installations on new and existing public, commercial, and residential buildings under the European Solar Rooftops Initiative.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-solar-strategy-2022-rooftop-obligation",
    "title": "EU Solar Energy Strategy (REPowerEU): Rooftop Solar Obligation",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "As part of the REPowerEU plan, this strategy mandates the installation of solar photovoltaic systems on certain buildings by specific deadlines, amending the Energy Performance of Buildings Directive (EPBD). The obligation applies to new public and commercial buildings by 2026, existing public and commercial buildings (over 250 m²) by 2027, and all new residential buildings by 2029.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate-related-disclosures",
      "iso-14064-ghg-reporting-2018",
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-solvency-ii-2009-138-pillar-2-governance",
    "title": "Directive 2009/138/EC (Solvency II) - Pillar 2: System of Governance (Articles 40-50)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "EU Solvency II Pillar 2 (Articles 40-50) mandates that all EU insurance and reinsurance undertakings establish and maintain an effective system of governance. This system must ensure sound and prudent management, including a clear organizational structure, fit and proper requirements for key personnel (Article 42), and robust risk management, compliance, internal audit, and actuarial functions (Articles 44, 46, 47, 48).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-solvency-ii-2023-review-omnibus-ii-amend",
    "title": "Directive of the European Parliament and of the Council amending Directive 2009/138/EC as regards proportionality, quality of supervision, reporting, long-term guarantee measures, macro-prudential tools, sustainability risks, group and cross-border supervision",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive amends Solvency II (2009/138/EC) to refine capital requirements and risk management for EU insurers, notably by recalibrating the Volatility Adjustment (VA) to better absorb market shocks (Amending Article 77d) and introducing a more robust proportionality framework to reduce the burden on low-risk undertakings (Amending Article 29). It also mandates the integration of sustainability and macro-prudential risks into governance and investment strategies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-solvency-ii-directive-2009-138",
    "title": "Directive 2009/138/EC of the European Parliament and of the Council of 25 November 2009 on the taking-up and pursuit of the business of Insurance and Reinsurance (Solvency II)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes a risk-based capital and governance framework for EU insurance and reinsurance undertakings, requiring them to maintain a Solvency Capital Requirement (SCR) and a Minimum Capital Requirement (MCR) as defined in Articles 101 and 129, respectively, and to implement a comprehensive system of governance under Article 41.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-solvency-ii-directive-2009-138-ec-eiopa",
    "title": "EU Solvency II Directive 2009/138/EC - EIOPA Prudential Supervision",
    "domain": "Insurance & Risk",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive 2009/138/EC (Solvency II) establishes the EU prudential framework for insurance and reinsurance undertakings, requiring risk-based capital adequacy (Solvency Capital Requirement), the Own Risk and Solvency Assessment (ORSA), and Pillar 3 supervisory disclosure obligations under EIOPA oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-solvency-ii-directive-2009-138-ec-insurance-capital-scr",
    "title": "EU Solvency II Directive 2009/138/EC - Solvency Capital Requirement & Own Funds for Insurers",
    "domain": "Insurance & Risk",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Solvency II Directive 2009/138/EC establishes a three-pillar risk-based capital framework for EU insurers: Pillar 1 quantitative requirements (SCR, MCR), Pillar 2 governance and ORSA, Pillar 3 reporting and disclosure - mandatory for all life, non-life, and reinsurance undertakings operating in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-solvency-ii-directive-2009-138-insurance-capital-requirements",
    "title": "EU Solvency II Directive 2009/138 - Insurance Capital Requirements and Risk-Based Supervision",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive 2009/138/EC (Solvency II) establishes a risk-based capital framework for EU insurance and reinsurance undertakings, comprising three pillars: quantitative requirements (Pillar 1), governance and risk management (Pillar 2), and reporting and disclosure (Pillar 3). The 2023 Solvency II Review (Omnibus II) updated provisions for long-term guarantees, proportionality, and sustainability risk integration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-corporate-sustainability-reporting-directive-2022-2464-csrd"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-solvency-ii-directive-pillar-2-governance-risk",
    "title": "EU Solvency II Directive 2009/138/EC - Pillar 2: System of Governance and Risk Management",
    "domain": "Insurance & Risk",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Solvency II Directive (2009/138/EC) Pillar 2 requires insurers to maintain an effective system of governance proportionate to the nature, scale, and complexity of their business. Core requirements include: four prescribed control functions (risk management, compliance, internal audit, actuarial); an Own Risk and Solvency Assessment (ORSA) conducted at least annually; written policies for each governance area approved by the administrative or management body; and fit-and-proper requirements for persons running the undertaking. EIOPA provides supervisory oversight and issues binding guidelines. Non-compliance can trigger supervisory intervention and capital add-ons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-solvency-ii-directive-2009-138",
      "eu-solvency-ii-level-2-delegated-regulation-2015-35"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-solvency-ii-directive-pillar-3-reporting-disclosure",
    "title": "EU Solvency II Directive 2009/138/EC - Pillar 3: Supervisory Reporting and Public Disclosure",
    "domain": "Insurance & Risk",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Solvency II Directive (2009/138/EC) Pillar 3 requires insurers to submit regular supervisory reports to national competent authorities and to publish annual public disclosures. Core documents are: the Regular Supervisory Report (RSR) submitted to the supervisor at least triennially (annually for significant entities); the Quantitative Reporting Templates (QRTs) submitted quarterly and annually; and the Solvency and Financial Condition Report (SFCR) published annually on the insurer's website. All reports must comply with EIOPA technical standards and templates. Material misstatements or late submission trigger supervisory sanctions and reputational damage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-solvency-ii-directive-2009-138",
      "eu-solvency-ii-directive-pillar-2-governance-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-solvency-ii-level-2-delegated-regulation-2015-35",
    "title": "Commission Delegated Regulation (EU) 2015/35 of 10 October 2014 supplementing Directive 2009/138/EC of the European Parliament and of the Council on the taking-up and pursuit of the business of Insurance and Reinsurance (Solvency II)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation provides detailed implementing rules for the Solvency II Directive, specifying the standard formula for calculating the Solvency Capital Requirement (SCR), methods for calculating the Minimum Capital Requirement (MCR), and detailed requirements for governance systems, including the 'prudent person principle' for investments (Article 132). It applies to all insurance and reinsurance undertakings operating within the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "dora-third-party-risk-articles-28-44",
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-solvency-ii-pillar-1-scr-mcr-capital-requirements",
    "title": "EU Solvency II Directive 2009/138/EC - Pillar 1: Solvency Capital Requirement (SCR) and Minimum Capital Requirement (MCR)",
    "domain": "Insurance & Risk",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "EU Solvency II Directive 2009/138/EC (as amended by Omnibus II Directive 2014/51/EU and the 2023 Solvency II Review Directive 2025/2) establishes a risk-based Pillar 1 framework for insurance and reinsurance undertakings: the Solvency Capital Requirement (SCR) calibrated to a 99.5% Value-at-Risk over a one-year period, and the Minimum Capital Requirement (MCR) as the absolute floor (25-45% of SCR with hard EUR minimums). The Standard Formula SCR aggregates six risk modules: market risk, counterparty default risk, life underwriting risk, non-life underwriting risk, health underwriting risk, and operational risk. Insurers may apply for Supervisory Authority approval to use an Internal Model for SCR calculation. The 2023 Review introduces a new long-term equity asset class, a revised extrapolation methodology for risk-free rate curves, and proportionality measures for small and low-risk undertakings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-solvency-ii-directive-2009-138",
      "eu-solvency-ii-level-2-delegated-regulation-2015-35"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-solvency-ii-pillar-2-orsa-governance",
    "title": "Solvency II: Governance System, Risk Management, and Own Risk and Solvency Assessment (ORSA)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Article 45 of the Solvency II Directive, all EU insurance and reinsurance undertakings must conduct and document an Own Risk and Solvency Assessment (ORSA) as part of an effective risk-management system. This forward-looking process requires firms to continuously assess their overall solvency needs in relation to their specific risk profile, approved risk tolerance limits, and business strategy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-solvency-ii-pillar-3-qrt-reporting-2024",
    "title": "Implementing Technical Standards on Supervisory Reporting under Solvency II Directive (EU) 2023/894 and Disclosure Requirements (EU) 2023/895 - Quantitative Reporting Templates for Pillar 3",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation mandates all insurance and reinsurance undertakings, special purpose vehicles, and third-country branches subject to Solvency II to submit standardized quantitative and qualitative disclosures using the XBRL taxonomy and templates defined in (EU) 2023/894 and (EU) 2023/895. Key reporting includes Balance Sheet (S.02), Own Funds (S.23), SCR (S.25), MCR (S.28), and Technical Provisions (S.12-S.16), with validation via the List of Validations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-commission-implementing-regulation-2015-2452-solvency",
      "eu-delegated-regulation-2016-2067-spread-market-risk",
      "eu-delegated-regulation-2016-467-non-life-premium-risk",
      "eu-eiopa-guidelines-orsa-2015",
      "eiopa-guidelines-pension-stress-testing-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-solvency-ii-pillar-3-reporting-sfcr",
    "title": "Solvency II Directive 2009/138/EC: Pillar 3 - Public Disclosure and Supervisory Reporting (SFCR, RSR, QRTs)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Mandates European (re)insurance undertakings to publicly disclose an annual Solvency and Financial Condition Report (SFCR) and submit a Regular Supervisory Report (RSR) with Quantitative Reporting Templates (QRTs) to national supervisors, ensuring market transparency and regulatory oversight as required by Articles 51-56 and 256 of the Solvency II Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-solvency-ii-pillar-3-sfcr-rsf-reporting",
    "title": "Directive 2009/138/EC (Solvency II) Pillar 3: Public Disclosure (Solvency and Financial Condition Report - SFCR) and Supervisory Reporting (Regular Supervisory Report - RSR)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "Under Solvency II Pillar 3, EU insurance and reinsurance undertakings must annually disclose a public Solvency and Financial Condition Report (SFCR) detailing their business performance, governance, risk profile, and capital management, as mandated by Article 51 of Directive 2009/138/EC. They must also submit a confidential and more comprehensive Regular Supervisory Report (RSR) to their national supervisory authority, as required by Article 35.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-solvency-ii-review-2025-directive",
    "title": "Directive (EU) 2023/2 of the European Parliament and of the Council of 15 December 2022 amending Directive 2009/138/EC as regards the long-term equity investment category, the extrapolation method, group supervision, cross-border business, run-off and proportionality for small insurers",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive amends Solvency II to introduce a new long-term equity investment capital treatment, revise the extrapolation method for longevity risk, enhance group supervision, facilitate cross-border operations, establish a run-off regime, and improve proportionality for smaller insurers. It applies to all insurance and reinsurance undertakings operating in the EU under Article 1 of Directive (EU) 2023/2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-delegated-regulation-2016-2067-spread-market-risk",
      "eu-delegated-regulation-2016-467-non-life-premium-risk",
      "eu-commission-implementing-regulation-2015-2452-solvency",
      "eu-eiopa-guidelines-orsa-2015",
      "canada-osfi-e19-own-risk-solvency-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-solvency2-directive-article-256-group-solvency-calculation-governance",
    "title": "DIRECTIVE 2009/138/EC OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 25 November 2009 on the taking-up and pursuit of the business of Insurance and Reinsurance (Solvency II) - Article 256",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article's compliance obligations regarding group solvency calculation governance cannot be determined as the provided regulatory text does not contain the enacted provisions of Article 256.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-solvency2-directive-article-37-capital-add-on-supervisory-powers",
    "title": "Solvency II Directive 2009/138/EC - Article 37 Capital add-on",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Supervisory authorities may, in exceptional circumstances following a supervisory review, impose a capital add-on for an insurance or reinsurance undertaking, provided the decision states the reasons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-solvency2-directive-article-44-risk-management-system-requirements",
    "title": "Solvency II Directive 2009/138/EC - Article 44: Risk management",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Insurance and reinsurance undertakings must establish and maintain an effective, continuous risk-management system to identify, measure, monitor, manage, and report all individual and aggregated risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-solvency2-directive-article-48-actuarial-function-requirements",
    "title": "Directive 2009/138/EC of the European Parliament and of the Council on the taking-up and pursuit of the business of Insurance and Reinsurance (Solvency II) - Article 48: Actuarial function",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Insurance and reinsurance undertakings must establish and maintain an effective actuarial function responsible for coordinating technical provision calculations, ensuring methodology appropriateness, assessing data quality, and informing management on the reliability of these calculations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-space-programme-article-10-components-of-union-space-programme",
    "title": "EU Space Programme Regulation (EU) 2021/696, Article 10: Warranty",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "The European Commission must ensure users are informed that services, data, and information from the Union Space Programme's components are provided without any warranty as to their quality, accuracy, availability, reliability, speed, or suitability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-space-programme-article-2-definitions",
    "title": "Regulation (EU) 2021/696 of the European Parliament and of the Council on establishing the Union Space Programme - Article 2 Definitions",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article defines key terms such as 'legal entity' and 'fiduciary entity', establishing the criteria for entities handling data or participating in financial mechanisms under the Union Space Programme.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-space-programme-article-31-galileo-safety-architecture",
    "title": "REGULATION (EU) 2021/696 establishing the Union Space Programme and the European Union Agency for the Space Programme - Article 31 Galileo services",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the four official Galileo services (Open Service, High-Accuracy Service, Signal Authentication Service, and Public Regulated Service) and defines their core characteristics, accessibility, and in the case of PRS, its restricted and controlled nature.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-space-programme-article-62-copernicus-data-and-information-policy",
    "title": "Regulation (EU) 2021/696 on the Union Space Programme, Article 62: Copernicus Data and Information Policy",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article establishes that Copernicus data and information must be provided on a full, free, and open basis, subject to specific conditions and potential restrictions necessary for the security of the Union or its Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-space-programme-article-77-space-traffic-management",
    "title": "REGULATION (EU) 2021/696 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 28 April 2021 establishing the Union Space Programme and the European Union Agency for the Space Programme - Article 77 Space Traffic Management",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "The Commission is empowered to support Space Traffic Management (STM) activities, including establishing a collision avoidance service, promoting STM standards, and ensuring the safety and sustainability of outer space activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-space-programme-article-85-ssa-space-surveillance-tracking",
    "title": "REGULATION (EU) 2021/696 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 28 April 2021 establishing the Union Space Programme and the European Union Agency for the Space Programme - Article 85",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes obligations for the Union Space Programme related to space surveillance and tracking (SSA) to protect space assets and ensure the safety and security of space activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-space-programme-article-91-governance-eu-agency-space-programme",
    "title": "Regulation (EU) 2021/696 establishing the Union Space Programme and the European Union Agency for the Space Programme, Article 91: Security Committee",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article mandates the establishment of a Security Committee to assist the Commission in ensuring a harmonised and consistent approach to the security of the Union Space Programme, defining its composition, tasks, and operational procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-space-programme-article-96-security-provisions",
    "title": "Regulation (EU) 2021/696 of the European Parliament and of the Council establishing the Union Space Programme, Article 96",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article establishes the core strategic and operational obligations for the Union Space Programme, including supporting innovation, ensuring service continuity, exploiting security applications while maintaining a civil nature, and promoting autonomous access to space.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-space-programme-regulation-2021-696",
    "title": "Regulation (EU) 2021/696 of the European Parliament and of the Council of 28 April 2021 on the Union Space Programme and on the establishment of the Union Space Programme Agency, and repealing Council Regulation (EC) No 1321/2004",
    "domain": "Space & Satellite Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Establishes the legal framework for the EU Space Programme, including Galileo, Copernicus, GOVSATCOM, and SST services, and defines the governance, operational responsibilities, and third-party access rules for EUSPA. Applies to EU institutions, Member States, EUSPA, service providers, and authorised users under Articles 7, 15, and 32.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14090-climate-adapt",
      "nist-ir-8374-ransomware-risk-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-space-programme-regulation-2021-696-galileo-copernicus",
    "title": "EU Space Programme Regulation 2021/696 - Galileo PRS Access, Copernicus Data Policy, and EU Space Agency Governance",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Regulation (EU) 2021/696 (EU Space Programme Regulation) establishes the governance, funding, and operational framework for EU space programmes including Galileo (European GNSS), Copernicus (Earth observation), EGNOS (safety of life augmentation), GOVSATCOM (governmental satellite communications), and SST (Space Surveillance and Tracking). The European Union Agency for the Space Programme (EUSPA) manages service provision and security accreditation. Galileo's Public Regulated Service (PRS) is restricted to government-authorised users. Copernicus data and information are provided free, full, and open access subject to certain limitations. The EU Space Programme is funded under the 2021-2027 MFF at approximately EUR 14.88 billion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "intl-outer-space-treaty-1967-article-1-exploration-freedom",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-space-regulation-2021-696-eu-space-programme-galileo-copernicus",
    "title": "EU Space Regulation 2021/696 - EU Space Programme, Galileo Encryption, and Copernicus Data Access Rules",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2021-04-22",
    "bluf": "Regulation (EU) 2021/696 establishes the EU Space Programme covering Galileo (navigation), Copernicus (earth observation), EGNOS, SST, and Govsatcom, setting security requirements for Galileo Public Regulated Service access, governing Copernicus full, free, and open data access principles, and establishing the European Union Agency for the Space Programme (EUSPA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-nis2-directive-2022-2555-network-information-security"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-space-surveillance-tracking-decision-2014",
    "title": "EU Space Surveillance and Tracking (SST) Framework Decision 541/2014/EU",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "EU member states with SST sensors or space object data join the EU SST Consortium to pool collision avoidance, re-entry prediction, and fragmentation event warnings for EU satellite operators. Under the EU Space Programme Regulation 2021, SST services are provided free of charge to EU institutional and commercial operators through the European Union Space Programme Agency (EUSPA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_space_programme",
        "iadc_debris_guidelines",
        "copuos_lts",
        "eu_esa_cooperation",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-space-programme-regulation-2021-696",
      "copuos-lts-guidelines-2019-space-sustainability",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-spectrum-700-mhz-decision-2017-899",
    "title": "Decision (EU) 2017/899 of the European Parliament and of the Council of 17 May 2017 on the use of the 470-790 MHz frequency band in the Union",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This decision requires EU Member States to make the 694-790 MHz (700 MHz) frequency band available for terrestrial systems capable of providing wireless broadband electronic communications services, such as 5G, by 30 June 2020, and to conclude cross-border coordination agreements by 31 December 2017, as mandated by Article 1 and Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itu-radio-regulations-2020-edition",
      "eu-eecc-2018-1972-electronic-communications-code"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-spirits-drinks-regulation-2019-787-gi",
    "title": "Regulation (EU) 2019/787 of the European Parliament and of the Council of 17 April 2019 on the definition, description, presentation, labelling and protection of geographical indications of spirit drinks, repealing Regulation (EC) No 110/2008",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes legally binding definitions, labelling requirements, and geographical indication (GI) protections for spirit drinks sold in the EU. It applies to all producers, importers, and distributors of spirit drinks within the EU market, with key obligations under Articles 9, 10, 16, and 21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-labelling-regulation-1169-2011",
      "eu-food-hygiene-regulation-852-2004",
      "codex-alimentarius-general-principles-hygiene-2020",
      "alcohol-service-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-sports-betting-integrity-macolin-convention",
    "title": "Council of Europe Convention on the Manipulation of Sports Competitions (Macolin Convention) 2014",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The Macolin Convention obliges all Council of Europe member states to criminalise the manipulation of sports competitions (Article 3), establish national betting monitoring systems and reporting mechanisms (Article 5), and exchange information with other states (Article 6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "fatf-guidance-rba-gambling-2021",
      "germany-state-gambling-treaty-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-sports-data-rights-framework-media-2024",
    "title": "EU Sports Data Rights and Audiovisual Transmission 2024 - Clip Rights, Venue Operator Restrictions, Short News Reporting Exceptions and OTT Licensing",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.2",
    "last_updated": "2026-07-01",
    "bluf": "This regulation establishes exclusive rights for sports event organizers over real-time data and audiovisual content captured at venues, restricts venue operators from granting third-party transmission rights without consent, permits limited use of sports clips under short news reporting exceptions, and mandates licensing for over-the-top (OTT) platforms redistributing sports content. Key obligations are defined in Article 8 (Clip Rights), Article 12 (Venue Operator Restrictions), Article 15 (News Reporting Exceptions), and Article 19 (OTT Licensing).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "iptc-video-metadata",
      "c2pa-content-provenance",
      "doi-digital-object-id",
      "isan-audiovisual-number"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-standard-contractual-clauses-2021",
    "title": "Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "These Standard Contractual Clauses (SCCs) provide a legal mechanism under GDPR for transferring personal data from the EU/EEA to third countries lacking an adequacy decision. Data exporters and importers must contractually commit to specific data protection safeguards and conduct a Transfer Impact Assessment (TIA) to ensure data is protected to a standard essentially equivalent to that in the EU, as mandated by Clause 14.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-state-aid-article-107-108-tfeu-framework",
    "title": "EU State Aid TFEU Articles 107-108 - Selective Advantage Test, Notification Obligation, General Block Exemption Regulation (GBER), De Minimis Thresholds and Recovery of Unlawful Aid with Interest",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Article 107(1) of the Treaty on the Functioning of the European Union (TFEU), any aid granted by an EU Member State or through state resources which distorts or threatens to distort competition by favouring certain undertakings is incompatible with the internal market. Member States must notify the European Commission of any plans to grant or alter aid, as per the standstill obligation in Article 108(3) TFEU, unless it falls under a block exemption or de minimis threshold.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tfeu-article-102-abuse-of-dominance"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-state-aid-articles-107-108-tfeu-framework",
    "title": "Treaty on the Functioning of the European Union - Articles 107 and 108: Prohibition of State Aid and Procedural Obligations for Notification and Commission Review",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Articles 107-108 of the Treaty on the Functioning of the European Union (TFEU) prohibit member states from granting selective state aid that distorts competition and affects trade between EU countries, unless authorized by the European Commission under specific exemptions. All proposed state aid must be notified to the Commission prior to implementation under Article 108(3) TFEU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-state-aid-rules-article-107-tfeu",
    "title": "Treaty on the Functioning of the European Union - Article 107: Prohibition of State Aid",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Article 107 of the Treaty on the Functioning of the European Union (TFEU) prohibits state aid granted by EU Member States that distorts or threatens to distort competition by favoring certain undertakings or the production of certain goods, where such aid affects trade between Member States. The prohibition applies unless the aid falls under an exemption in Article 107(2) or is authorized by the European Commission under Article 107(3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "uk-cma-merger-assessment-guidelines-2021",
      "india-competition-act-2002-sections-3-4",
      "australia-competition-consumer-act-2010-part-iv",
      "canada-competition-act-2024-amendment-abuse-dominance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-statutory-audit-regulation-537-2014",
    "title": "EU Statutory Audit Regulation 537/2014 - Specific Requirements for Statutory Audit of Public-Interest Entities",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Regulation (EU) No 537/2014 of the European Parliament and of the Council of 16 April 2014, applicable from 17 June 2016, establishes specific requirements for statutory audits of public-interest entities (PIEs) - including listed companies, banks, and insurance undertakings - in the European Union. The Regulation is directly applicable in all EU Member States without transposition and works in conjunction with Directive 2014/56/EU (amending Audit Directive 2006/43/EC). Key requirements include: mandatory audit firm rotation after a maximum engagement of 10 years (extensible to 20 or 24 years in certain circumstances); prohibition on provision of certain non-audit services (NAS) to audit clients; a 70% cap on fees from non-audit services as a proportion of audit fees averaged over 3 years; enhanced audit committee oversight including prior approval of non-audit services; mandatory reporting to audit committees; transparency reporting by audit firms; and joint audit provisions for credit institutions in some Member States. The Regulation significantly strengthened auditor independence requirements across EU PIE audits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_audit_directive_2006_43",
        "eu_accounting_directive_2013_34",
        "eu_banking_union_supervision"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-market-abuse-regulation-596-2014"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-sulphur-content-marine-fuels-directive-2016-802",
    "title": "EU Sulphur Directive 2016/802 Marine Fuel Sulphur Content Limits and Compliance",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Directive (EU) 2016/802 sets maximum sulphur content limits in marine fuels used in EU territorial waters and ports: 0.10% m/m in EU Sulphur Emission Control Areas (SECAs) including Baltic Sea, North Sea, and English Channel, and 0.50% m/m globally from 1 January 2020 (aligned with MARPOL Annex VI), with Member States responsible for sampling, testing, and enforcement including fuel documentation verification by port state control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ship-recycling-regulation-1257-2013"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-sup-single-use-plastics-2019-904",
    "title": "EU Single-Use Plastics Directive 2019/904",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Directive 2019/904 (the Single-Use Plastics Directive, SUPD) addresses single-use plastic items and fishing gear that frequently appear in marine litter. The Directive bans certain products from 3 July 2021 (cotton bud sticks cutlery plates straws stirrers expanded polystyrene food containers and cups beverage containers expanded polystyrene oxo-degradable plastics). Other measures include consumption reduction for food containers and cups marking requirements (e.g., tampon applicators wet wipes tobacco filters cups) extended producer responsibility tethered caps (from July 2024) recycled content 25% in PET beverage bottles by 2025 30% by 2030 and separate collection target 90% for bottles by 2029.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-supply-chain-due-diligence-directive-2024-1760-csddd",
    "title": "EU Corporate Sustainability Due Diligence Directive 2024/1760 - Supply Chain Human Rights and Environmental Risk Management",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2024-07-25",
    "bluf": "EU Directive 2024/1760 (CSDDD) requires large companies to identify, prevent, mitigate, and account for actual and potential human rights and environmental adverse impacts in their own operations and supply chains, establish complaints mechanisms, adopt transition plans for climate alignment, and face civil liability and administrative penalties of up to 5% of global net turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-directive-article-2-scope-of-sustainability-reporting",
      "eu-regulation-2023-1115-deforestation-regulation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-tachograph-regulation-165-2014",
    "title": "Regulation (EU) No 165/2014 of the European Parliament and of the Council of 4 February 2014 on tachographs in road transport",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation sets the obligations and requirements for the construction, installation, use, testing and control of tachographs used in road transport to verify compliance with driving-time rules (Article 1). Tachographs must be installed and used in vehicles within the scope of Regulation (EC) No 561/2006 (Article 3), digital tachographs must perform defined functions including speed, distance and driver-activity monitoring (Article 5), record vehicle position at defined points using a satellite system (Article 8), and support remote early detection of manipulation for targeted roadside checks (Article 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-intelligent-transport-systems-directive-2010-40",
      "eu-type-approval-framework-regulation-2018-858"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-takeover-directive-2004-25",
    "title": "EU Takeover Directive 2004/25/EC - Mandatory Bid and Squeeze-Out",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2004-04-30",
    "bluf": "Directive 2004/25/EC harmonises EU rules on public takeover bids for companies listed on EU regulated markets - mandating a mandatory bid obligation when acquiring 30% or more of voting rights (threshold set by Member States), requiring equal treatment of all shareholders, establishing the board neutrality (passivity) rule during bid period, prescribing the fair price standard for mandatory bids, and granting squeeze-out and sell-out rights above 90% threshold.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-market-abuse-regulation-596-2014",
      "eu-prospectus-regulation-2017-1129",
      "mifid-ii"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-taking-of-evidence-regulation-2020-1783",
    "title": "Regulation (EU) 2020/1783 of the European Parliament and of the Council of 25 November 2020 on cooperation between the courts of the Member States in the taking of evidence in civil or commercial matters (taking of evidence) (recast)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This recast Regulation governs cooperation between courts of the Member States in the taking of evidence in civil or commercial matters (Article 1). Requests are transmitted directly between courts (Article 3), supported by a central body (Article 4), using standard forms (Article 5) through the secure decentralised IT system, whose electronic documents have legal effect (Articles 7 and 8). It enables both the taking of evidence by the requested court and the direct taking of evidence by the requesting court, with safeguards and time limits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-service-of-documents-regulation-2020-1784",
      "eu-brussels-iib-matrimonial-parental-jurisdiction-regulation-2019-1111"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-tax-dispute-resolution-directive-2017-1852",
    "title": "EU Tax Dispute Resolution Directive 2017/1852 - Double Taxation Dispute Mechanism",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Council Directive (EU) 2017/1852 on tax dispute resolution mechanisms in the European Union requires Member States to resolve double taxation disputes between EU Member States within 2 years of a complaint being accepted. Where the mutual agreement procedure (MAP) fails to resolve the dispute, the case must be referred to an Advisory Commission within 50 days. The Advisory Commission issues an opinion within 6 months. The Directive applies to disputes arising from 1 January 2018 and income years from 2018.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "oecd_map_beps_action_14",
        "eu_arbitration_convention_1990",
        "eu_atad1_2016",
        "oecd_transfer_pricing_guidelines",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-1-2016-1164",
      "oecd-transfer-pricing-guidelines-2022",
      "oecd-beps-action-15-multilateral-instrument"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-taxonomy-construction-activities-2022-criteria",
    "title": "Commission Delegated Regulation (EU) 2021/2139 of 4 June 2021 supplementing Directive 2014/95/EU and Regulation (EU) 2020/852 by establishing the technical screening criteria for climate change mitigation and adaptation",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes technical screening criteria under the EU Taxonomy for determining when construction and renovation activities in the real estate sector qualify as environmentally sustainable, specifically requiring new buildings to meet primary energy demand thresholds and major renovations to trigger energy performance upgrades. Key requirements are defined in Article 18 and Annex I, Section 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-construction-sector-emissions-buildings-renovation",
      "iso-50001-2018-energy-management-systems",
      "australia-national-construction-code-2022-ncc"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-taxonomy-construction-green-finance-2021",
    "title": "Commission Delegated Regulation (EU) 2021/2139 of 4 June 2021 supplementing Directive 2014/89/EU and Regulation (EU) 2020/852 by establishing the content and presentation of information in the European Union Taxonomy for environmentally sustainable economic activities in the field of climate change mitigation and adaptation",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes technical screening criteria for construction and renovation activities to qualify as environmentally sustainable under the EU Taxonomy, requiring new buildings to meet nearly zero-energy building (NZEB) standards and major renovations to achieve a minimum 30% improvement in primary energy demand. It applies to undertakings subject to the Corporate Sustainability Reporting Directive (CSRD) and financial market participants offering financial products in the EU, per Article 17 of Regulation (EU) 2020/852 and Annex I of Delegated Act (EU) 2021/2139.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-construction-sector-emissions-buildings-renovation",
      "iso-50001-2018-energy-management-systems",
      "iso-19650-bim-information-management-construction"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-taxonomy-delegated-act-energy-2022-sustainable",
    "title": "Commission Delegated Regulation (EU) 2021/2139: Technical Screening Criteria for Energy Sector Activities' Substantial Contribution to Climate Change Mitigation",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation establishes the technical screening criteria (TSC) for energy sector activities to be classified as environmentally sustainable under the EU Taxonomy. As detailed in Annex I, activities must meet specific greenhouse gas (GHG) emissions thresholds (e.g., <100g CO2e/kWh for electricity generation) and satisfy rigorous \"Do No Significant Harm\" (DNSH) criteria for other environmental objectives to qualify as making a substantial contribution to climate change mitigation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify",
      "iso-14090-climate-adapt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-taxonomy-environmental-delegated-act-2023-2486",
    "title": "Commission Delegated Regulation (EU) 2023/2486 - EU Taxonomy Environmental Delegated Act establishing technical screening criteria for the four non-climate environmental objectives",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This Commission Delegated Regulation establishes the technical screening criteria under which economic activities qualify as contributing substantially to the four non-climate environmental objectives of the EU Taxonomy Regulation (EU) 2020/852: sustainable use and protection of water and marine resources (Annex I), transition to a circular economy (Annex II), pollution prevention and control (Annex III), and protection and restoration of biodiversity and ecosystems (Annex IV). For each objective the criteria also determine whether the activity causes no significant harm to any of the other environmental objectives laid down in Article 9 of Regulation (EU) 2020/852. It applies from 1 January 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852-sustainable-finance-dnsh",
      "eu-taxonomy-sustainable",
      "eu-csrd-directive-2022-2464"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-taxonomy-mining-activities-sustainable",
    "title": "Commission Delegated Regulation (EU) 2021/2139 of 4 June 2021 supplementing Regulation (EU) 2020/852 of the European Parliament and of the Council by establishing the technical screening criteria for the environmental sustainability of economic activities in the mining and extractive sector",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation sets out the technical screening criteria, including do no significant harm (DNSH) conditions and minimum social safeguards, for extractive activities related to critical raw materials to qualify as environmentally sustainable under the EU Taxonomy. It applies to undertakings engaged in mining operations enabling the low-carbon transition, as defined in Article 10 of Delegated Act (EU) 2021/2139.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-mining-sustainable-activities",
      "eu-conflict-minerals-regulation-2017-821",
      "eu-mining-waste-directive-2006-21-ec",
      "eiti-standard-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-taxonomy-mining-sustainable-activities",
    "title": "Commission Delegated Regulation (EU) 2021/2139 of 4 June 2021 supplementing Regulation (EU) 2020/852 of the European Parliament and of the Council by establishing the technical screening criteria for the environmental sustainability of economic activities in the mining and extractive sector",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes technical screening criteria under the EU Taxonomy for determining when mining and extractive activities substantially contribute to environmental sustainability without causing significant harm (DNSH), including adherence to minimum safeguards under Article 20 of Regulation (EU) 2020/852. It applies to undertakings subject to disclosure obligations under the Sustainable Finance Disclosure Regulation (SFDR) that engage in extractive activities for metallic and non-metallic minerals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "un-paris-agreement-ndc-implementation-guidelines"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-taxonomy-regulation-2020-852",
    "title": "Regulation (EU) 2020/852 of the European Parliament and of the Council of 18 June 2020 on the establishment of a framework to facilitate sustainable investment, and amending Regulation (EU) 2019/2088",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes a classification system (the 'Taxonomy') to identify environmentally sustainable economic activities for investment purposes. It requires financial market participants and large companies subject to the CSRD to disclose the proportion of their turnover, CapEx, and OpEx aligned with specific technical screening criteria across six environmental objectives, as defined in Article 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-sfdr-reporting",
      "eu-green-bond-standard-2023",
      "ghg-protocol-scope3",
      "iso-14001-ems"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-taxonomy-regulation-2020-852-article-12-technical-screening-criteria",
    "title": "EU Taxonomy Regulation (EU) 2020/852 - Article 12: Technical Screening Criteria and Do No Significant Harm Conditions",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 12 of the EU Taxonomy Regulation (2020/852) establishes the legal basis for Technical Screening Criteria (TSC) that determine whether economic activities qualify as environmentally sustainable. The Commission adopts TSC by delegated acts for each of the six environmental objectives. TSC specify: (a) the quantitative or qualitative thresholds an activity must meet to substantially contribute to an environmental objective; and (b) the Do No Significant Harm (DNSH) conditions the activity must satisfy for each of the other five environmental objectives. TSC must be based on available scientific evidence and updated as technology and knowledge evolve. The criteria balance environmental ambition with economic feasibility, and must not create undue compliance burdens for SMEs. Article 12 TSC are operationalised through the Climate Delegated Regulation (2021/2139) covering climate mitigation and adaptation, and the Environmental Delegated Regulation (2023/2485) covering the remaining four objectives (water, circular economy, pollution, and biodiversity). TSC are the technical heart of the EU Taxonomy system, determining which investments qualify as green.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852-article-6-disclosure-financial-products",
      "eu-taxonomy-regulation-2020-852-article-8-disclosure-non-financial-undertakings"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-taxonomy-regulation-2020-852-article-6-disclosure-financial-products",
    "title": "EU Taxonomy Regulation (EU) 2020/852 - Article 6: Disclosure Obligations for Financial Products Investing in Taxonomy-Aligned Activities",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 6 of the EU Taxonomy Regulation (2020/852) imposes disclosure obligations on financial market participants that market financial products (investment funds, pension products, insurance-based investment products) in the EU. Products NOT marketed as environmentally sustainable must include a disclaimer stating they do not take into account EU Taxonomy criteria for environmentally sustainable economic activities. Products that DO take Taxonomy criteria into account must disclose: the Taxonomy-alignment objectives pursued, how and to what extent those objectives are taken into account, and the proportion of investments in economic activities classified as environmentally sustainable per the Taxonomy. These disclosures are required in: (a) pre-contractual documents (prospectus, KID, KIID); (b) periodic reports; and (c) on the financial market participant's website. Article 6 disclosures must quantify the proportion of Taxonomy-aligned investments using the Key Performance Indicators (revenue, capex, opex) of underlying investee companies pursuant to Article 8 disclosures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852-article-8-disclosure-non-financial-undertakings",
      "eu-taxonomy-regulation-2020-852-article-12-technical-screening-criteria"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-taxonomy-regulation-2020-852-article-8-disclosure-non-financial-undertakings",
    "title": "EU Taxonomy Regulation (EU) 2020/852 - Article 8: Disclosure by Non-Financial Undertakings on Taxonomy-Aligned Revenue, Capex and Opex",
    "domain": "Sustainability & ESG",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 8 of the EU Taxonomy Regulation (2020/852) requires non-financial undertakings subject to the Non-Financial Reporting Directive (NFRD, now superseded by CSRD) to disclose, in their non-financial or sustainability statement, the proportion of their revenue, capital expenditure (capex), and operating expenditure (opex) associated with economic activities that qualify as environmentally sustainable under the EU Taxonomy. The three mandatory Key Performance Indicators (KPIs) are: (1) Revenue KPI - the share of net turnover from Taxonomy-aligned activities; (2) Capex KPI - the share of capital expenditure associated with Taxonomy-aligned activities or plans to expand such activities; (3) Opex KPI - the share of operating expenditure from Taxonomy-aligned activities. The disclosure methodology is specified in Commission Delegated Regulation 2021/4987. Taxonomy alignment requires meeting Technical Screening Criteria, Do No Significant Harm (DNSH) conditions for all six environmental objectives, and minimum social safeguards. Article 8 disclosures are the primary data source that financial market participants use for Article 6 portfolio-level Taxonomy alignment calculations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-regulation-2020-852-article-6-disclosure-financial-products",
      "eu-taxonomy-regulation-2020-852-article-12-technical-screening-criteria"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-taxonomy-regulation-2020-852-sustainable-finance-classification",
    "title": "EU Taxonomy Regulation 2020/852 - Sustainable Finance Classification System and DNSH Criteria",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Regulation (EU) 2020/852 establishes a unified EU classification system determining whether economic activities qualify as environmentally sustainable. Financial market participants and large companies subject to CSRD must disclose what proportion of their CapEx, OpEx, and Turnover is taxonomy-aligned, providing investors with standardised, comparable ESG data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-sfdr-regulation-2019-2088-sustainable-finance-disclosure",
      "eu-csrd-directive-2022-2464-corporate-sustainability-reporting"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-taxonomy-regulation-2020-852-sustainable-finance-dnsh",
    "title": "EU Taxonomy Regulation 2020/852 - Sustainable Finance Classification & DNSH Criteria",
    "domain": "Sustainability & ESG",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "EU Taxonomy Regulation 2020/852 establishes a unified classification system for environmentally sustainable economic activities - requiring financial market participants and large companies to disclose what proportion of activities are Taxonomy-aligned using six environmental objectives and Do No Significant Harm (DNSH) criteria.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-taxonomy-regulation-article-10-climate-change-mitigation-criteria",
    "title": "REGULATION (EU) 2020/852 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 18 June 2020 on the establishment of a framework to facilitate sustainable investment, and amending Regulation (EU) 2019/2088 - Article 10",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes that an economic activity qualifies as contributing substantially to climate change mitigation if it contributes to stabilizing greenhouse gas concentrations by avoiding or reducing emissions, enhancing removals, or is a transitional activity leading to a climate-neutral economy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-taxonomy-regulation-article-11-climate-change-adaptation-criteria",
    "title": "Regulation (EU) 2020/852 on the establishment of a framework to facilitate sustainable investment - Article 11: Substantial contribution to climate change adaptation",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the criteria for an economic activity to qualify as making a substantial contribution to climate change adaptation, either by implementing solutions to reduce its own climate risks or by providing solutions that help others adapt.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-taxonomy-regulation-article-12-biodiversity-and-ecosystems-criteria",
    "title": "REGULATION (EU) 2020/852 on the establishment of a framework to facilitate sustainable investment - Article 12: Substantial contribution to the protection and restoration of biodiversity and ecosystems",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the criteria for an economic activity to be considered as contributing substantially to the protection and restoration of biodiversity and ecosystems under the EU Taxonomy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-taxonomy-regulation-article-14-delegated-acts-technical-criteria",
    "title": "Regulation (EU) 2020/852 on the establishment of a framework to facilitate sustainable investment - Article 14: Substantial contribution to pollution prevention and control",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article obligates the European Commission to establish and adopt, via a single delegated act, technical screening criteria for determining when an economic activity substantially contributes to pollution prevention and control and does not cause significant harm to other environmental objectives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-taxonomy-regulation-article-17-do-no-significant-harm",
    "title": "Regulation (EU) 2020/852 on the establishment of a framework to facilitate sustainable investment - Article 17: Significant harm to environmental objectives",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the criteria for determining when an economic activity is considered to cause significant harm to six key environmental objectives, requiring assessments to consider the full life cycle of products and services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-taxonomy-regulation-article-2-definitions",
    "title": "Regulation (EU) 2020/852 of the European Parliament and of the Council - Article 2: Definitions",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the official definitions for key terms such as 'environmentally sustainable investment', 'climate change mitigation', and 'circular economy', which must be used consistently when applying the requirements of this Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-taxonomy-regulation-article-20-minimum-social-safeguards",
    "title": "REGULATION (EU) 2020/852 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 18 June 2020 on the establishment of a framework to facilitate sustainable investment, and amending Regulation (EU) 2019/2088 - Article 20",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires undertakings to implement due diligence and remedy procedures to ensure their economic activities align with minimum social safeguards based on international standards, including the OECD Guidelines for Multinational Enterprises and the UN Guiding Principles on Business and Human Rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-taxonomy-regulation-article-3-six-environmental-objectives",
    "title": "Regulation (EU) 2020/852 on the establishment of a framework to facilitate sustainable investment - Article 3: Criteria for environmentally sustainable economic activities",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the four mandatory criteria an economic activity must meet to qualify as environmentally sustainable: substantial contribution to an environmental objective, doing no significant harm to others, complying with minimum social safeguards, and meeting technical screening criteria.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-taxonomy-regulation-article-5-technical-screening-criteria",
    "title": "Regulation (EU) 2020/852 Article 5: Transparency of environmentally sustainable investments in pre-contractual disclosures and in periodic reports",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Financial products investing in environmentally sustainable economic activities must disclose in pre-contractual and periodic reports the specific environmental objectives, how and to what extent investments are sustainable, and the precise percentage of those investments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-taxonomy-regulation-article-8-disclosure-obligations-financial-market",
    "title": "Regulation (EU) 2020/852 (EU Taxonomy Regulation) - Article 8: Transparency of financial products promoting environmental characteristics in pre-contractual disclosures and in periodic reports",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that financial products promoting environmental characteristics must include a specific, verbatim statement in their disclosures clarifying the application of the 'do no significant harm' principle and the alignment of underlying investments with EU criteria for environmentally sustainable economic activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-taxonomy-regulation-article-9-substantial-contribution-to-objectives",
    "title": "Regulation (EU) 2020/852 (EU Taxonomy Regulation) - Article 9: Conditions for Environmentally Sustainable Economic Activities",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the core conditions an economic activity must meet to be considered environmentally sustainable, including not significantly harming environmental objectives, complying with minimum safeguards, and meeting technical screening criteria.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-taxonomy-sustainable",
    "title": "EU Taxonomy for Sustainable Finance",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Regulation (EU) 2020/852 establishes a classification system to determine whether an economic activity is environmentally sustainable, imposing stringent disclosure obligations on entities subject to NFRD/CSRD (`is_subject_to_nfrd_csrd`:true). An activity qualifies as sustainable only if it meets four cumulative conditions under Article 3. First, it must make a substantial contribution to at least one of six environmental objectives defined in Article 9, a requirement demanding the targeting of a minimum of one such objective (`min_environmental_objectives_targeted`:1). Currently, the necessary substantial contribution criteria are not fulfilled (`substantial_contribution_criteria_met`:false). Second, it must not significantly harm any of the other five environmental objectives, a test which permits zero violations (`do_no_significant_harm_violations`:0). Commission Delegated Regulation (EU) 2021/2139 specifies the technical screening criteria for this assessment, including a mandatory climate risk assessment that remains incomplete (`climate_risk_assessment_completed`:false). Third, compliance with minimum social safeguards stipulated in Article 18 is required, a condition presently failed (`minimum_social_safeguards_passed`:false). Due to these deficiencies, all key performance indicators, including Taxonomy-aligned revenue, CapEx, and OpEx, report at zero percent (`taxonomy_aligned_revenue_percentage`:0). The entity is therefore not prepared for its transparency obligations (`article_8_disclosure_ready`:false) under Article 8, which are operationalized by Commission Delegated Regulation (EU) 2021/2178 concerning KPI calculation and reporting templates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "tcfd-climate-risk",
      "un-guiding-principles-business-hr",
      "oecd-guidelines-multinational-ent",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-technical-regulations-information-procedure-directive-2015-1535",
    "title": "Directive (EU) 2015/1535 of the European Parliament and of the Council of 9 September 2015 laying down a procedure for the provision of information in the field of technical regulations and of rules on Information Society services (codification)",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This codifying Directive lays down a procedure for the provision of information in the field of technical regulations and rules on Information Society services to safeguard the free movement of goods and services in the internal market (Article 1). Member States must communicate to the Commission any draft technical regulation before its adoption (Article 5), and must then postpone the adoption of the draft for three months from the date of receipt by the Commission of the communication, a standstill period that is extended where the Commission or another Member State delivers a detailed opinion (Article 6). Adopted technical regulations must reference the Directive (Article 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-foreign-subsidies-regulation-2022-2560",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-technical-roadside-inspection-directive-2014-47",
    "title": "Directive 2014/47/EU of the European Parliament and of the Council of 3 April 2014 on the technical roadside inspection of the roadworthiness of commercial vehicles circulating in the Union",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive establishes minimum requirements for a regime of technical roadside inspections of commercial vehicles with a design speed exceeding 25 km/h (Articles 1 and 2). It requires a system of initial and more detailed roadside inspections (Article 4), a risk rating system to target inspections (Article 6), inspection of cargo securing (Article 13), and follow-up where major or dangerous deficiencies are found (Article 14), assessing deficiencies by severity against Annex II (Article 12).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-directive-2014-45-roadworthiness-testing",
      "iso-39001-road-traffic-safety-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-technology-transfer-block-exemption-2014-316-article-3-safe-harbour",
    "title": "Commission Regulation (EU) No 316/2014 on the application of Article 101(3) of the Treaty on the Functioning of the European Union to categories of technology transfer agreements - Article 3",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "For competing undertakings, a technology transfer agreement exemption applies only if their combined market share on the relevant market(s) does not exceed 20%.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-technology-transfer-block-exemption-2022-316",
    "title": "Commission Regulation (EU) No 316/2014 of 21 March 2014 on the Application of Article 101(3) of the Treaty on the Functioning of the European Union to Categories of Technology Transfer Agreements",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "This regulation establishes a safe harbor for technology transfer agreements between competing and non-competing undertakings under EU competition law, provided that the combined market share of the parties does not exceed 20% for competitors or 30% for non-competitors, and that no hardcore restrictions are present. It applies to licensing agreements involving patents, know-how, and other IP rights used in production or R&D (Article 1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "uk-competition-act-1998-chapter-1-2-prohibitions",
      "india-competition-act-2002-sections-3-4",
      "oecd-recommendation-hard-core-cartels-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-technology-transfer-block-exemption-316-2014",
    "title": "Commission Regulation (EU) No 316/2014 of 21 March 2014 on the application of Article 101(3) of the Treaty on the Functioning of the European Union to categories of technology transfer agreements",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation provides a 'safe harbour' from EU competition law for technology transfer agreements (e.g., patent and know-how licensing) between parties whose market shares do not exceed 20% for competitors or 30% for non-competitors, as specified in Article 3. The exemption does not apply if the agreement contains any 'hardcore restrictions' listed in Article 4, such as price fixing or market allocation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "paris-convention-industrial-property"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-ten-e-cross-border-energy-regulation-2022-869",
    "title": "EU TEN-E Regulation 2022/869 - Trans-European Energy Infrastructure Projects",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Regulation (EU) 2022/869 on guidelines for trans-European energy infrastructure (TEN-E recast) replaces Regulation (EU) 347/2013 and removes natural gas infrastructure from the Projects of Common Interest (PCI) list, instead prioritising electricity, hydrogen, smart electricity grids, and CO2 infrastructure. PCIs benefit from a one-stop-shop permitting process with a maximum 3.5-year permitting period. Offshore renewable energy grid developments and smart gas grids involving hydrogen are eligible categories. The Regulation implements the EU's Green Deal infrastructure obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ten_e_347_2013_repealed",
        "eu_electricity_market_reform_2024",
        "eu_hydrogen_strategy",
        "eu_taxonomy_energy",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electricity-regulation-2019-943",
      "eu-electricity-directive-2019-944",
      "eu-hydrogen-strategy-2020-investment-framework"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-ten-t-permit-granting-streamlining-directive-2021-1187",
    "title": "Directive (EU) 2021/1187 of the European Parliament and of the Council of 7 July 2021 on streamlining measures for advancing the realisation of the trans-European transport network (TEN-T)",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive lays down streamlining measures for the permit-granting procedure required to authorise the implementation of projects on the core network of the trans-European transport network (Article 1). It grants priority status to certain projects to ensure faster administrative treatment (Article 3), requires Member States to identify a designated authority acting as a point of contact for the project promoter (Article 4), and sets a maximum duration for the permit-granting procedure that should not exceed four years (Article 5). It governs the organisation of the permit-granting procedure (Article 6), the coordination of cross-border procedures (Article 7), and public procurement in cross-border projects (Article 8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-public-procurement-directive-2014-24-construction",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-terrorist-content-online-regulation-2021-784",
    "title": "Regulation (EU) 2021/784 of the European Parliament and of the Council of 29 April 2021 on addressing the dissemination of terrorist content online",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down uniform rules to address the misuse of hosting services for the dissemination of terrorist content online (Article 1). Competent authorities may issue removal orders requiring hosting service providers to remove or disable access to terrorist content within one hour of receipt (Article 3), with a cross-border procedure (Article 4). Providers exposed to terrorist content must take specific measures (Article 5) and comply with transparency obligations (Article 7), redress and complaint mechanisms (Articles 9 and 10), and information duties to content providers (Article 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-dsm-directive-2019-790",
      "eu-media-freedom-act-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-tfer-regulation-2023",
    "title": "Regulation (EU) 2023/1113 of the European Parliament and of the Council of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets and amending Directive (EU) 2015/849",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This regulation extends the financial 'travel rule' to crypto-asset transfers, requiring Crypto Asset Service Providers (CASPs) to collect, verify, and exchange comprehensive originator and beneficiary information for all transactions, regardless of amount, to prevent money laundering and terrorist financing, as detailed in Articles 14 and 16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "mica-stablecoin-reserve"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-tfeu-article-101-cartel-prohibition",
    "title": "Treaty on the Functioning of the European Union (TFEU) Article 101 - Prohibition of Anti-Competitive Agreements",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-10-27",
    "bluf": "Article 101(1) of the TFEU prohibits all agreements, decisions, and concerted practices between undertakings which may affect trade between EU Member States and which have as their object or effect the prevention, restriction, or distortion of competition. This includes price-fixing, market sharing, and bid-rigging cartels, rendering such agreements automatically void under Article 101(2) unless they qualify for an exemption under Article 101(3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-tfeu-article-101-cartels-prohibition",
    "title": "Treaty on the Functioning of the European Union - Article 101: Prohibition of Anti-Competitive Agreements, Decisions and Concerted Practices",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Article 101 of the Treaty on the Functioning of the European Union (TFEU) prohibits agreements between undertakings, decisions by associations of undertakings, and concerted practices that prevent, restrict, or distort competition within the EU internal market, particularly those involving price-fixing, market sharing, output limitation, or bid rigging (Article 101(1)). Exemptions may apply if agreements contribute to improving production or distribution without eliminating competition (Article 101(3)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-recommendation-hard-core-cartels-2019",
      "india-competition-act-2002-sections-3-4",
      "uk-competition-act-1998-chapter-1-2-prohibitions",
      "eu-state-aid-articles-107-108-tfeu-framework",
      "icn-recommended-practices-merger-notification-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-tfeu-article-102-abuse-dominance",
    "title": "Treaty on the Functioning of the European Union - Article 102: Abuse of Dominant Position",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Prohibits undertakings in a dominant position within the EU internal market from abusing that position through exploitative or exclusionary practices that distort competition, as defined under Article 102 of the Treaty on the Functioning of the European Union (TFEU). Applies to all companies operating in the EU with significant market power.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-antitrust-compliance-programme-best-practice",
      "eu-damages-directive-2014-104-private-enforcement",
      "eu-digital-markets-act-2022-1925-gatekeeper-obligations",
      "eu-merger-regulation-139-2004"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-tfeu-article-102-abuse-of-dominance",
    "title": "Guidance on the Commission's enforcement priorities in applying Article 102 of the Treaty on the Functioning of the European Union to abusive exclusionary conduct by dominant undertakings",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Article 102 of the TFEU, undertakings holding a dominant position within the EU internal market are prohibited from abusing that position, particularly through conduct that excludes competitors and harms consumer welfare. This guidance outlines the European Commission's enforcement priorities, establishing a rebuttable presumption of dominance for market shares exceeding 50% and focusing on an effects-based analysis of conduct like predatory pricing, tying, and refusal to supply.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-horizontal-block-exemption-regulations-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-timber-regulation-995-2010-construction-wood",
    "title": "Regulation (EU) No 995/2010 of the European Parliament and of the Council of 20 October 2010 laying down the obligations of operators who place timber and timber products on the market",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Operators placing timber or timber products on the EU market, including in construction projects, must implement a due diligence system to minimize the risk of illegal logging. This includes risk assessment, risk mitigation, and traceability of species, country of harvest, and compliance with applicable legislation under Article 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-circular-economy-construction-demolition-waste-2020",
      "iso-19650-bim-information-management-construction",
      "iso-9001-2015-quality-management-construction"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-timeshare-directive-2008-122",
    "title": "Directive 2008/122/EC of the European Parliament and of the Council of 14 January 2009 on the protection of consumers in respect of certain aspects of timeshare, long-term holiday product, resale and exchange contracts",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive protects consumers in respect of timeshare, long-term holiday product, resale and exchange contracts (Article 1). It regulates advertising (Article 3), requires pre-contractual information to be provided in good time (Article 4) and to form an integral part of the contract (Article 5), grants the consumer a right of withdrawal within the period set in Article 6 with defined modalities (Articles 6 and 7) and effects (Article 8), prohibits any advance payment during the withdrawal period (Article 9), sets specific rules for long-term holiday product contracts (Article 10), and makes the Directive imperative so consumers cannot waive their rights (Article 12).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011-83-eu",
      "eu-unfair-commercial-practices-2005-29"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-tobacco-advertising-sponsorship-directive-2003-33",
    "title": "Directive 2003/33/EC of the European Parliament and of the Council of 26 May 2003 on the approximation of the laws, regulations and administrative provisions of the Member States relating to the advertising and sponsorship of tobacco products",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive approximates Member State rules on the advertising and sponsorship of tobacco products in media other than television (Article 1). It prohibits tobacco advertising in the press and other printed publications, except those intended exclusively for professionals in the tobacco trade and those printed and published in third countries not principally intended for the Union market, and prohibits tobacco advertising in information society services (Article 3). It prohibits radio advertising and sponsorship of radio programmes (Article 4) and the sponsorship of cross-border events or activities (Article 5), and requires penalties and enforcement (Article 7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tobacco-product-directive-2014-40-eu-hospitality",
      "who-fctc-2003-tobacco-control"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-tobacco-product-directive-2014-40-eu-hospitality",
    "title": "Directive 2014/40/EU of the European Parliament and of the Council of 3 April 2014 on the approximation of the laws, regulations and administrative provisions of the Member States concerning the manufacture, presentation and sale of tobacco and related products and repealing Directive 2001/37/EC",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive mandates that tobacco product packaging display combined health warnings and information messages covering 65% of the front and back, prohibits characterising flavours in tobacco products, and regulates cross-border distance sales and e-cigarette notification. It applies to all manufacturers, importers, and retailers of tobacco and related products in EU Member States, including hospitality venues selling such products, under Articles 7, 8, and 20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-information-regulation-1169-2011-labelling",
      "eu-food-hygiene-regulation-852-2004",
      "codex-alimentarius-general-principles-hygiene-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-trade-barriers-regulation-2015-1843",
    "title": "Regulation (EU) 2015/1843 of the European Parliament and of the Council of 6 October 2015 laying down Union procedures in the field of the common commercial policy in order to ensure the exercise of the Union’s rights under international trade rules (Trade Barriers Regulation)",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "The Trade Barriers Regulation provides EU procedures to respond to obstacles to trade maintained by third countries that are actionable under international trade rules (Article 1). The Union industry (Article 3) or Union enterprises (Article 4) may lodge a complaint, or a Member State may request action (Article 6). The Commission conducts an examination procedure (Article 9) assessing injury or adverse trade effects (Article 11) and, where the Union interest requires, adopts commercial policy measures (Article 13).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-trade-enforcement-regulation-654-2014",
      "wto-gatt-1994-general-agreement-tariffs-trade"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-trade-enforcement-regulation-654-2014",
    "title": "Regulation (EU) No 654/2014 of the European Parliament and of the Council of 15 May 2014 concerning the exercise of the Union's rights for the application and enforcement of international trade rules",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down rules and procedures for the Union to exercise its rights to suspend or withdraw concessions or other obligations under international trade agreements (Article 1). It applies following WTO dispute adjudication, trade-agreement dispute settlement, and certain safeguard situations (Article 3). The Commission adopts commercial policy measures by implementing act under Article 4, which under Article 5 may include suspension of tariff concessions, increased customs duties, and restrictions on goods, services or public procurement, with measures suspended where the third country grants adequate compensation under Article 7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-coercion-instrument-2023-2675",
      "wto-gatt-1994-general-agreement-tariffs-trade"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-trade-marks-approximation-directive-2015-2436",
    "title": "Directive (EU) 2015/2436 of the European Parliament and of the Council of 16 December 2015 to approximate the laws of the Member States relating to trade marks (recast)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This recast Directive approximates the laws of the Member States relating to trade marks (Article 1). It defines the signs of which a trade mark may consist (Article 3), the absolute grounds for refusal or invalidity (Article 4), the relative grounds for refusal or invalidity based on earlier rights (Article 5), the rights conferred by a trade mark including the right to prevent unauthorised use (Article 10), the right to prohibit preparatory acts in relation to packaging (Article 11), the limitation of the effects of a trade mark (Article 14), the exhaustion of rights (Article 15), and the requirement of genuine use of the trade mark.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-trademark-regulation-2017-1001",
      "eu-copyright-directive-2019-790"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-trade-secrets-directive-2016",
    "title": "Directive (EU) 2016/943 of the European Parliament and of the Council of 8 June 2016 on the protection of undisclosed know-how and business information (trade secrets) against their unlawful acquisition, use and disclosure",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This directive establishes a harmonized EU-wide legal framework for protecting trade secrets by defining what constitutes a trade secret (Article 2) and outlining what constitutes unlawful acquisition, use, and disclosure (Article 4). It applies to any natural or legal person lawfully controlling information that meets the criteria of a trade secret.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dtsa-trade-secret-protection",
      "paris-convention-industrial-property"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-trade-secrets-directive-2016-943",
    "title": "Directive (EU) 2016/943 of the European Parliament and of the Council of 8 June 2016 on the protection of undisclosed know-how and business information (trade secrets) against their unlawful acquisition, use and disclosure",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This directive establishes a harmonized legal framework across the EU for protecting trade secrets against unlawful acquisition, use, and disclosure. It applies to any natural or legal person lawfully controlling information that meets the definition of a 'trade secret' under Article 2(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "paris-convention-industrial-property",
      "dtsa-trade-secret-protection",
      "eu-antitrust-competition-law"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-trade-secrets-directive-2016-943-article-10-remedies-infringement",
    "title": "Directive (EU) 2016/943 on the protection of undisclosed know-how and business information (trade secrets) against their unlawful acquisition, use and disclosure - Article 10",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations holding trade secrets may request judicial authorities to order provisional and precautionary measures against alleged infringers, including cessation of use, prohibition of infringing goods, and seizure of such goods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-trade-secrets-directive-2016-943-article-4-lawful-acquisition-trade-secrets",
    "title": "Directive (EU) 2016/943 on the protection of undisclosed know-how and business information (trade secrets) against their unlawful acquisition, use and disclosure - Article 4",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article establishes the right for trade secret holders to apply for legal measures, procedures, and remedies to prevent or obtain redress for the unlawful acquisition, use, or disclosure of their trade secrets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-trade-secrets-directive-2016-943-ip-protection",
    "title": "EU Trade Secrets Directive 2016/943 - Unlawful Acquisition, Disclosure & Civil Remedies",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Directive 2016/943 harmonizes EU trade secret protection by defining lawful secrecy standards, prohibiting unlawful acquisition or disclosure, and providing civil injunction and damages remedies - critical for tech companies, pharma R&D, and AI model protection strategies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-trade-secrets-directive-2016-943-misappropriation-protection-civil-remedies",
    "title": "EU Trade Secrets Directive 2016/943 - Protection Against Misappropriation and Civil Remedies",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "Directive (EU) 2016/943 harmonises trade secret protection across EU Member States, defining trade secrets as information that is secret, has commercial value because it is secret, and has been subject to reasonable steps to keep it secret. The Directive establishes the concept of lawful and unlawful acquisition, use, and disclosure, and requires Member States to provide civil remedies including injunctions, seizure of infringing goods, damages (actual loss or royalty-based), and publication of judgments. Trade secret holders must demonstrate reasonable protection measures to qualify for protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-trademark-regulation-2017-1001",
    "title": "EU Trade Mark Regulation 2017/1001 -- EUTM Registration and Enforcement at EUIPO",
    "domain": "Legal & IP Sovereignty",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Regulation (EU) 2017/1001 (the EU Trade Mark Regulation, EUTMR) codifies the EU Trade Mark (EUTM) system administered by the European Union Intellectual Property Office (EUIPO) in Alicante. A single EUTM registration protects the mark across all 27 EU Member States simultaneously. The registration procedure involves: application to EUIPO; absolute grounds examination by EUIPO (Article 7 - marks that are descriptive, generic, deceptive, or contrary to public policy refused); publication for 3-month opposition period (Article 43-53); registration valid for 10 years from filing date (renewable indefinitely, Article 49). EUTM holders must put the mark into genuine use within 5 years of registration and maintain genuine use thereafter, failing which the EUTM is liable to revocation under Article 58. Non-EU manufacturers and applicants must appoint an EU representative before EUIPO unless established in the EU/EEA (Article 119). The Madrid Protocol (Madrid System, Article 182) allows international trademark applications designating the EU. EUIPO maintains the EUTM register publicly accessible at euipo.europa.eu.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-services-directive-2006-123",
      "eu-ecn-plus-directive-2019-nca-powers",
      "eu-digital-markets-act-2022-1925"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-trans-european-energy-infrastructure-2022-869",
    "title": "Regulation (EU) 2022/869 of the European Parliament and of the Council of 14 June 2022 on guidelines for trans-European energy infrastructure, amending Regulations (EC) No 715/2009, (EU) 2019/942 and (EU) 2019/943 and Directives 2009/73/EC and (EU) 2019/944, and repealing Regulation (EU) No 347/2013",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-06-27",
    "bluf": "This regulation establishes a framework for identifying and developing Projects of Common Interest (PCIs) and Projects of Mutual Interest (PMIs) to build an integrated trans-European energy infrastructure. It mandates a streamlined permit granting process, cross-border cost allocation mechanisms, and sustainability assessments for energy projects, as outlined in Article 1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate-related-disclosures",
      "iso-14064-ghg-reporting-2018",
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-transfer-funds-regulation-2023-1113-crypto",
    "title": "Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets (Recast TFR)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-12-30",
    "bluf": "This regulation extends the Financial Action Task Force (FATF) 'Travel Rule' to crypto-asset transfers within the EU, requiring Crypto Asset Service Providers (CASPs) to collect, verify, and exchange detailed information on the originator and beneficiary for all transactions, with no minimum threshold (Article 14). This applies from 30 December 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "fatf-guidance-virtual-assets-vasp",
      "eu-aml-regulation-2024",
      "mica-stablecoin-reserve"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-transfer-of-criminal-proceedings-regulation-2024-3011",
    "title": "Regulation (EU) 2024/3011 of the European Parliament and of the Council of 27 November 2024 on the transfer of proceedings in criminal matters",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down rules on the transfer of criminal proceedings between Member States to ensure the proper administration of justice and avoid duplication or conflicts of jurisdiction (Article 1). It addresses jurisdiction of the requested State (Article 3), the waiver, suspension or discontinuation of proceedings by the requesting State (Article 4), the criteria for requesting a transfer (Article 5), the rights of the victim (Article 7), and the procedure and time limits for requesting and deciding on the transfer (Article 8), with fundamental-rights safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-european-production-orders-e-evidence-regulation-2023-1543",
      "eu-presumption-of-innocence-directive-2016-343"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-transfer-of-funds-regulation-2023-1113-travel-rule",
    "title": "Regulation (EU) 2023/1113 on information accompanying transfers of crypto-assets and amending Regulation (EU) No 2015/847",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Crypto-Asset Service Providers (CASPs) must collect, verify, and transmit originator and beneficiary information for all crypto-asset transfers, including those to self-hosted wallets, with no de minimis threshold. Applies to intra-EU and cross-border transfers under Article 4 and Article 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "eu-dlt-pilot-regime-2022-858",
      "iso-20022-mx-messaging"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-transfer-of-undertakings-directive-2001-23",
    "title": "Council Directive 2001/23/EC of 12 March 2001 on the approximation of the laws of the Member States relating to the safeguarding of employees rights in the event of transfers of undertakings, businesses or parts of undertakings or businesses",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive safeguards employees rights in the event of the transfer of an undertaking, business or part of an undertaking or business to another employer (Article 1). On a transfer, the transferor rights and obligations arising from existing contracts of employment pass to the transferee (Article 3), and the transfer does not in itself constitute grounds for dismissal (Article 4), subject to specific rules where the transferor is the subject of insolvency proceedings (Article 5). It preserves the status and function of employee representatives (Article 6) and requires both transferor and transferee to inform and, where measures are envisaged, consult the representatives of the employees affected (Article 7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-collective-redundancies-directive-98-59",
      "eu-works-council-directive-2009-38"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-transfer-pricing-directive-proposal-2023",
    "title": "Proposal for a Council Directive on Transfer Pricing",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2024-09-12",
    "bluf": "This proposed directive requires multinational enterprises operating in the EU to ensure that the terms and conditions of their cross-border transactions between associated enterprises are consistent with the arm's length principle (ALP), as defined in Article 3. It aims to create a common EU framework for applying the ALP, including rules on primary, corresponding, and compensating adjustments, to prevent profit shifting and ensure fair taxation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-model-double-taxation-convention-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-transparency-directive-2013-50",
    "title": "EU Transparency Directive 2013/50/EU - Listed Company Disclosure",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2015-11-27",
    "bluf": "Directive 2013/50/EU (amending TD 2004/109/EC) harmonises periodic financial reporting and major shareholding disclosure requirements for companies admitted to trading on EU regulated markets - requiring half-yearly and annual financial reports, major shareholding notifications (5%/10%/15%/20%/25%/30%/50%/75% thresholds), and home Member State designation for third-country issuers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-market-abuse-regulation-596-2014",
      "eu-prospectus-regulation-2017-1129",
      "mifid-ii"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-transparent-predictable-working-2019-1152",
    "title": "Directive (EU) 2019/1152 of the European Parliament and of the Council of 20 June 2019 on transparent and predictable working conditions in the European Union",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This EU directive requires employers to provide all workers with a written statement of their essential working conditions within the first week of employment (Article 5) and establishes new minimum rights regarding probationary periods, parallel employment, minimum work predictability, and mandatory training (Articles 8-13). It applies to all workers in the EU with an employment contract or relationship, including those in non-standard forms of work.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-platform-work-directive-2024",
      "eu-pay-transparency-directive-2023",
      "eu-work-life-balance-directive-2019",
      "ilo-core-conventions",
      "eu-agency-work-directive-2008"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-type-approval-framework-2018-858",
    "title": "Regulation (EU) 2018/858 of the European Parliament and of the Council of 30 May 2018 on the approval and market surveillance of motor vehicles and their trailers, and of systems, components and separate technical units intended for such vehicles, amending Regulations (EC) No 715/2007 and (EC) No 595/2009 and repealing Directive 2007/46/EC",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes a comprehensive EU framework for the type-approval and market surveillance of motor vehicles, trailers, and their components. It mandates that manufacturers obtain an EU Whole Vehicle Type-Approval (WVTA) before placing products on the market, strengthens post-market surveillance by national authorities, and defines clear obligations for recalls and ensuring Conformity of Production (CoP) as detailed in Articles 8, 9, and 31.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-type-approval-framework-regulation-2018-858",
    "title": "Regulation (EU) 2018/858 of the European Parliament and of the Council of 30 May 2018 on the approval and market surveillance of motor vehicles and their trailers, and of systems, components and separate technical units intended for such vehicles, and repealing Directive 2007/46/EC",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the EU framework for whole vehicle type-approval ( WVTA ), requiring manufacturers to obtain certification before placing vehicles on the market, mandates ongoing market surveillance by national authorities, and imposes mandatory recall obligations for non-compliant vehicles under Article 33. It applies to all manufacturers, importers, and authorized representatives placing motor vehicles, trailers, and related components into the EU market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "un-regulation-r157-automated-lane-keeping-alks",
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-type-approval-regulation-2018-858",
    "title": "Regulation (EU) 2018/858 of the European Parliament and of the Council of 30 May 2018 on the approval and market surveillance of motor vehicles and their trailers, and of systems, components and separate technical units intended for such vehicles, and repealing Directive 2007/46/EC",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes a harmonized framework for whole vehicle type approval ( WVTA ), conformity of production (CoP), market surveillance, and post-market remedial measures for motor vehicles and their components in the EU. It applies to manufacturers, technical services, and national type-approval authorities under Articles 10, 42, and 54.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-type-approval-regulation-2018-858-whole-vehicle-technical-requirements",
    "title": "EU Type-Approval Regulation 2018/858 - Whole Vehicle Market Surveillance and Technical Requirements",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "Regulation (EU) 2018/858 establishes the framework for type-approval and market surveillance of motor vehicles in the EU, requiring manufacturers to demonstrate conformity of production, provide on-board diagnostics access, and enable independent repair and maintenance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-market-surveillance-regulation-2019-1020-auto",
      "eu-general-safety-regulation-2019-2144-automated-vehicles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-u-space-regulation-2021-664-drone-atm",
    "title": "Commission Implementing Regulation (EU) 2021/664 of 7 April 2021 on the airworthiness and environmental certification of unmanned aircraft systems (UAS) and on common rules for the operation of UAS, laying down detailed rules for U-space and amending Regulations (EU) No 923/2012 and (EU) No 1321/2014",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the operational and technical requirements for U-space services in the European Union, including flight authorisation, network identification, geo-awareness, and traffic information services. It applies to UAS operators, drone service providers, and air navigation service providers operating in designated U-space airspace under Articles 6, 9, 11, and 15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "as9100-rev-d-qms",
      "easa-part-145-maintenance",
      "easa-ai-roadmap-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-ucits-directive-2009-65",
    "title": "EU Undertakings for Collective Investment in Transferable Securities Directive (UCITS) 2009/65/EC",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Directive 2009/65/EC (UCITS IV, consolidated) establishes the EU framework for retail collective investment schemes. UCITS may be marketed to retail investors across the EU via a passport: the management company submits a notification to the home NCA, which transmits to host NCA within 10 working days. Investment restrictions under Articles 50-57 cap single issuer exposure at 5% (raised to 10% for certain issuers, 35% for government bonds) and prohibit investments in physical commodities, real estate, or unquoted securities exceeding 10%. UCITS must publish a Key Information Document (KID) under PRIIPs Regulation (EU) No 1286/2014 (replacing the KIID from 1 January 2023). Management companies must hold minimum capital of EUR 125,000 plus 0.02% of AUM exceeding EUR 250M (capped at EUR 10M). UCITS V (Directive 2014/91/EU) added depositary obligations, remuneration rules, and sanctions framework. AIFMD II (Directive 2024/927/EU) amends UCITS liquidity management provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "AIFMD",
        "PRIIPs_KID",
        "SFDR",
        "AML",
        "MiFID_II_distribution"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-priips-regulation-1286-2014-kid",
      "eu-sfdr-2019-2088",
      "eu-aml-regulation-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-un-r100-electric-vehicle-construction",
    "title": "UN Regulation No. 100 - Uniform Provisions Concerning the Approval of Battery Electric Vehicles with Regard to Specific Requirements for Electric Power Train Systems",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "UN Regulation No. 100 (Rev. 3, 2022) establishes mandatory safety requirements for battery electric vehicles (BEVs) regarding electrical safety, protection against electric shock, thermal management, and high-voltage component integrity. It applies to all new BEVs of categories M and N approved under UNECE WP.29 framework, requiring compliance with insulation resistance, electrical isolation monitoring, and thermal propagation prevention per Article 5.2.1 and Annex 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26262-functional-safety-road-vehicles-2018",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-unfair-commercial-practices-2005-29",
    "title": "Directive 2005/29/EC of the European Parliament and of the Council of 11 May 2005 concerning unfair business-to-consumer commercial practices in the internal market and amending Council Directive 84/450/EEC, Directives 97/7/EC, 98/27/EC and 2002/65/EC of the European Parliament and of the Council and Regulation (EC) No 2006/2004 of the European Parliament and of the Council (‘Unfair Commercial Practices Directive’)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This EU directive prohibits traders from using unfair business-to-consumer commercial practices that are likely to materially distort the economic behavior of the average consumer. It specifically bans misleading actions and omissions (Articles 6-7), aggressive practices like harassment or coercion (Articles 8-9), and provides a blacklist of practices that are considered unfair in all circumstances (Annex I).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-omnibus-directive-2019-2161",
      "eu-consumer-rights-directive-2011",
      "asa-advertising-codes-uk",
      "ftc-endorsement-guides"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-unfair-commercial-practices-2005-29-2022-revision",
    "title": "Directive 2005/29/EC of the European Parliament and of the Council of 11 May 2005 concerning unfair business-to-consumer commercial practices in the internal market, as amended by Directive (EU) 2019/2161 (better enforcement and modernisation of Union consumer protection rules) and Directive (EU) 2024/825 (empowering consumers for the green transition)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.2",
    "last_updated": "2026-07-01",
    "bluf": "Prohibits unfair business-to-consumer commercial practices in the EU internal market. The Modernisation Directive (EU) 2019/2161 (applicable from 28 May 2022) added transparency duties for online marketplace ranking, individual consumer remedies, and new blacklisted practices (hidden search advertising, fake consumer reviews, ticket bots); the Empowering Consumers Directive (EU) 2024/825 added rules against greenwashing and unsubstantiated environmental claims. Applies to all traders targeting EU consumers under Article 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29",
      "eu-ecommerce-directive-2000-31",
      "eu-eprivacy-directive-2002-58",
      "eu-geo-blocking-regulation-2018-302",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-unfair-commercial-practices-directive",
    "title": "Directive 2005/29/EC of the European Parliament and of the Council of 11 May 2005 concerning unfair business-to-consumer commercial practices in the internal market ('Unfair Commercial Practices Directive')",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This directive prohibits unfair business-to-consumer commercial practices, including misleading and aggressive tactics, across the EU. It establishes a general prohibition against conduct that materially distorts the economic behavior of the average consumer (Article 5) and provides a specific blacklist of 31 practices in Annex I that are always considered unfair, which is now interpreted to include many forms of digital 'dark patterns'.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fca-consumer-duty-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-unfair-commercial-practices-directive-2005-29",
    "title": "EU Unfair Commercial Practices Directive 2005/29 -- B2C Marketing and Consumer Protection",
    "domain": "Sales, Marketing & PR",
    "version": "2024.1.0",
    "last_updated": "2024-05-28",
    "bluf": "Directive 2005/29/EC (UCPD) prohibits unfair commercial practices in business-to-consumer (B2C) transactions throughout the EU. A commercial practice is unfair if it is contrary to professional diligence AND is likely to materially distort the economic behaviour of the average consumer. The Directive establishes two categories of unfair practices: misleading practices (Articles 6-7) and aggressive practices (Articles 8-9). Annex I contains a blacklist of 31 practices that are always unfair regardless of context. Following the Omnibus Directive 2019/2161, the UCPD was amended to: prohibit fake consumer reviews (from 28 May 2022); require disclosure of personalised pricing (algorithmic ranking of commercial offers); mandate that displayed prices reflect the lowest price in the prior 30 days for promotional pricing; extend consumer rights in the digital context. Penalties for UCPD violations must be at least 4% of the trader's annual turnover in the relevant Member State (Omnibus Directive amendment) or EUR 2 million where turnover is unknown.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-content-services-directive-2019-770"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-unfair-commercial-practices-directive-2005-29-ec-advertising",
    "title": "EU Unfair Commercial Practices Directive 2005/29/EC - Misleading Advertising & Aggressive Practices",
    "domain": "Sales, Marketing & PR",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Directive 2005/29/EC prohibits unfair business-to-consumer commercial practices including misleading actions, misleading omissions, and aggressive practices that materially distort consumers' transactional decisions - the Omnibus Directive 2019/2161 added greenwashing and fake review prohibitions with fines up to 4% of annual turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-unfair-terms-directive-93-13-article-4-unfairness-assessment",
    "title": "EU Unfair Terms Directive 93/13/EEC Article 4 Assessment Criteria for Contractual Unfairness",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Council Directive 93/13/EEC Article 4 establishes the assessment criteria for determining whether a contractual term is unfair: evaluating the nature of the goods or services, all circumstances at conclusion of contract, and all other terms of the contract, while exempting core price and subject-matter terms from unfairness review provided they are in plain, intelligible language.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011-83-cx"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-unfair-trading-practices-agri-food-directive-2019-633",
    "title": "Directive (EU) 2019/633 of the European Parliament and of the Council of 17 April 2019 on unfair trading practices in business-to-business relationships in the agricultural and food supply chain",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive combats unfair trading practices in the agricultural and food supply chain that grossly deviate from good commercial conduct (Article 1). It prohibits a list of unfair practices outright, such as late payments for perishable products and last-minute cancellations, and conditionally prohibits others unless clearly agreed (Article 3). Member States must designate enforcement authorities (Article 4), provide confidential complaint mechanisms (Article 5), grant the authorities investigation and sanction powers (Article 6), and ensure cooperation between authorities (Article 8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-official-controls-regulation-2017-625",
      "eu-food-information-consumers-regulation-1169-2011"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-unified-patent-court-agreement-2012",
    "title": "EU Unified Patent Court Agreement - UPCA 2012 and Unitary Patent System",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Unified Patent Court (UPC) became operational on 1 June 2023, creating a specialist pan-European patent court with jurisdiction over European patents and EU Unitary Patents across 18 participating EU member states; businesses with European patent portfolios must decide whether to opt out of UPC jurisdiction during the sunrise/transitional period (opt-out available until 1 June 2030 for existing European patents), as UPC judgments on validity and infringement apply simultaneously across all participating states - a single UPC ruling can revoke a European patent in all 18 jurisdictions at once, creating both an enforcement advantage for patent holders and a centralised revocation risk requiring portfolio strategy review.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-patent-cooperation-pct",
      "trips-agreement-wto-copyright-patents-ip-1994",
      "eu-csrd-2022-2464",
      "un-guiding-principles-business-human-rights"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-union-customs-code-952-2013",
    "title": "Regulation (EU) No 952/2013 of the European Parliament and of the Council of 9 October 2013 laying down the Union Customs Code (recast)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes the legal framework for customs procedures in the European Union, including customs declarations, customs debt, authorised economic operator (AEO) status, and binding decisions. It applies to all economic operators, customs representatives, and customs authorities involved in the movement of goods across EU borders under Article 77 and Article 133.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-deforestation-regulation-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-universal-service-directive-2009-136-consumer",
    "title": "Directive 2009/136/EC of the European Parliament and of the Council of 25 November 2009 amending Directive 2002/22/EC on universal service and users’ rights relating to electronic communications networks and services",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive mandates that providers of electronic communications services ensure transparent, accurate, and timely billing, clear contract terms, and effective complaint handling mechanisms for end-users. Key obligations are established under Article 30 (billing accuracy), Article 31 (contract information), and Article 32 (complaints procedures).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "eu-adr-consumer-disputes-2013",
      "iso-10002-2018-customer-satisfaction-complaints",
      "iso-10003-2018-external-dispute-resolution"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-urban-waste-water-treatment-directive-91-271-eec",
    "title": "Council Directive 91/271/EEC of 21 May 1991 concerning urban waste-water treatment and discharge",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Council Directive 91/271/EEC, adopted on 21 May 1991 and published in the Official Journal L 135 on 30 May 1991, governs the collection, treatment, and discharge of urban waste water, as well as the treatment and discharge of industrial waste water from certain sectors. Its primary objective is to protect the environment from adverse effects caused by insufficiently treated waste water. The Directive defines key terms: 'urban waste water' as domestic waste water mixed with industrial waste water and/or run-off rain water; '1 p.e. (population equivalent)' as the organic biodegradable load with a BOD5 of 60 g of oxygen per day; 'primary treatment' as a physical/chemical process reducing BOD5 by at least 20% and total suspended solids by at least 50%; and 'secondary treatment' as a biological process meeting Annex I Table 1 requirements. Member States are required to ensure all agglomerations have collecting systems by 31 December 2000 for those over 15000 p.e. and by 31 December 2005 for those between 2000 and 15000 p.e.; sensitive areas require systems by 31 December 1998 for agglomerations over 10000 p.e. Secondary treatment deadlines are set for discharges from agglomerations over 15000 p.e. by 31 December 2000, and between 10000 and 15000 p.e. by 31 December 2005. Industrial waste water entering collecting systems must have prior regulations or specific authorizations by 31 December 1993. Sludge disposal to surface waters must be phased out by 31 December 1998. A committee assists the Commission on implementation. Member States must adopt implementing laws by 30 June 1993.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-urban-wastewater-treatment-directive-91-271",
    "title": "Council Directive 91/271/EEC of 21 May 1991 concerning urban waste-water treatment",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive requires EU Member States to ensure that urban agglomerations provide collecting systems for all wastewater and subject it to at least secondary treatment before discharge. For construction projects affecting discharges into designated 'sensitive areas', more stringent treatment to remove nitrogen and/or phosphorus is mandated under Article 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-46001-water-eff",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-urban-wastewater-treatment-directive-construction",
    "title": "Council Directive 91/271/EEC concerning urban wastewater treatment, as recast in 2024",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive requires EU Member States to ensure the collection, treatment, and discharge of urban wastewater in accordance with specified capacity thresholds and nutrient removal standards, particularly for agglomerations above 2,000 population equivalents (p.e.) and sensitive areas. Key obligations are set out in Articles 3, 4, and 5 regarding system design, treatment levels, and compliance timelines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-circular-economy-construction-demolition-waste-2020",
      "iso-19650-bim-information-management-construction",
      "iso-21500-project-management-construction-guidance",
      "eu-construction-sector-emissions-buildings-renovation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-urban-wastewater-treatment-directive-revised-2024",
    "title": "EU Urban Wastewater Treatment Directive (Revised) 2024/3019 - Quaternary Treatment, Energy Neutrality and Extended Producer Responsibility",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "Directive (EU) 2024/3019 of the European Parliament and of the Council of 27 November 2024 concerning urban wastewater treatment (recast UWWTD) replaces the 1991 Urban Wastewater Treatment Directive 91/271/EEC and entered into force on 1 January 2025 with progressive transposition deadlines extending to 2045. The recast directive expands secondary treatment obligations to all agglomerations of 1,000 population equivalent (p.e.) or more by 2035 (down from 2,000 p.e. in the 1991 directive). Article 8 requires tertiary treatment for nutrient removal in agglomerations of 150,000 p.e. by 2039 and 10,000 p.e. by 2045 in sensitive catchment areas. Article 9 introduces the new quaternary treatment requirement to remove micropollutants in 200,000 p.e. agglomerations by 2045 and 150,000 p.e. by 2039 where significant pharmaceutical, cosmetic or chemical pollution. Article 10 imposes Extended Producer Responsibility on producers of pharmaceutical and cosmetic products to fund at least 80% of additional quaternary treatment costs. Article 11 requires energy neutrality of urban wastewater treatment plants by 2045. Article 21 introduces individual sanitation system regulation for non-connected dwellings. Sludge management, climate change adaptation, and overflow event management strengthened throughout.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-water-framework-directive-2000-60-ec",
      "eu-urban-wastewater-treatment-directive-91-271"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-us-dpf-2023",
    "title": "Commission Implementing Decision (EU) 2023/1795 on the adequate level of protection of personal data under the EU-US Data Privacy Framework",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This adequacy decision under GDPR Article 45 establishes the EU-US Data Privacy Framework (DPF) as a valid mechanism for transferring personal data from the EU/EEA to US organizations that self-certify their adherence to the DPF Principles, ensuring an adequate level of data protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-validation-non-formal-informal-learning",
    "title": "Council Recommendation of 20 December 2012 on the validation of non-formal and informal learning",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This EU Recommendation requires Member States to establish national validation systems for non-formal and informal learning by aligning them with national qualifications frameworks (NQFs) and the European Qualifications Framework (EQF), ensuring recognition of learning outcomes for employability and lifelong learning, as outlined in paragraphs (7), (9), and (16). It applies to education and training providers, employment services, and national authorities responsible for qualifications and validation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-european-qualifications-framework-eqf",
      "bologna-process-higher-education-area-2020",
      "eu-erasmus-programme-regulation-2021-817"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-variation-regulation-1234-2008-centralised",
    "title": "Commission Regulation (EC) No 1234/2008 of 24 November 2008 concerning the examination of variations to the terms of marketing authorisations for medicinal products for human use and veterinary medicinal products",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes the procedures and conditions for managing post-approval changes (variations) to marketing authorisations for medicinal products in the EU, classifying them as minor (Type IA/IB), major (Type II), or extensions. It applies to Marketing Authorisation Holders (MAHs) of centrally authorised products, requiring them to submit applications to the European Medicines Agency (EMA) according to the classification, grouping, and worksharing rules defined in Articles 3, 7, and 20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-vat-directive-2006-112",
    "title": "EU VAT Directive 2006/112 - Standard Rate, Deduction, Intra-EU Supply, and One-Stop-Shop",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Council Directive 2006/112/EC on the common system of value added tax (the Principal VAT Directive) consolidates previous EU VAT directives and establishes the common framework for VAT across all EU Member States. Article 9 defines a taxable person as any person who independently carries out an economic activity; Member States may extend taxable person status to entities engaged in transactions specified in Article 12. Article 96 requires each Member State to apply a standard VAT rate of not less than 15%. Articles 98 to 110 permit Member States to apply up to two reduced rates of not less than 5% to categories of goods and services listed in Annex III, and from the 2022 amendments, zero rates for certain specific categories. Article 138 exempts the intra-Community supply of goods from VAT where the goods are dispatched or transported from one Member State to another and the buyer is a taxable person registered for VAT. Article 167 provides that the right to deduct input VAT arises at the time the deductible tax becomes chargeable. Article 178 specifies the conditions for exercising the right of deduction, including holding a valid VAT invoice complying with Articles 219a to 240. Directive 2017/2455 introduced the One-Stop-Shop (OSS) mechanism (applicable from 1 July 2021), enabling suppliers of telecommunications, broadcasting, and electronic services to non-taxable persons in multiple Member States to register and declare VAT in a single Member State. The reverse charge mechanism under Article 194 shifts VAT liability to the recipient for specified cross-border supplies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nz_goods_services_tax_act_1985",
        "au_goods_services_tax_act_1999",
        "uk_vat_act_1994",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-goods-services-tax-act-1985",
      "eu-services-directive-2006-123",
      "eu-ecn-plus-directive-2019-nca-powers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-vat-directive-2006-112-consolidated",
    "title": "Council Directive 2006/112/EC of 28 November 2006 on the common system of value added tax",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive establishes the common system of value added tax (VAT) for EU Member States, defining who is a taxable person, what constitutes a taxable transaction (supply of goods/services), the place of supply rules, and the framework for rates and exemptions. As per Article 2(1), VAT is levied on the supply of goods or services for consideration within the territory of a Member State by a taxable person acting as such, and on the importation of goods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018",
      "oecd-beps-action-13-cbcr-guidance-2023-update"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-vat-directive-2006-112-ec-cross-border-digital-services-oss",
    "title": "EU VAT Directive 2006/112/EC - Cross-Border Digital Services and One-Stop Shop (OSS) Registration",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2021-07-01",
    "bluf": "EU VAT Directive 2006/112/EC as amended by Directive 2017/2455 requires suppliers of digital services to EU consumers to charge VAT at the consumer's member state rate, with the One-Stop Shop (OSS) scheme allowing single-country registration to file and remit EU-wide VAT from July 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-services-act-2022",
      "gdpr-article-6-lawful-basis-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-vat-oss-ioss-digital-services-2021",
    "title": "EU VAT Modernisation for Cross-Border B2C E-Commerce: One Stop Shop (OSS) and Import One Stop Shop (IOSS) Schemes, Abolition of Distance Selling Thresholds, and Deemed Supplier Rules for Online Platforms",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-07-10",
    "bluf": "Effective July 1, 2021, this EU VAT package simplifies compliance for B2C e-commerce by abolishing previous national distance selling thresholds and introducing a single EU-wide €10,000 threshold for intra-EU supplies of TBE services and distance sales of goods. It establishes the One Stop Shop (OSS) and Import One Stop Shop (IOSS) portals for single VAT registration, declaration, and payment, and makes online platforms 'deemed suppliers' responsible for VAT collection in specific cross-border transactions (as per VAT Directive 2006/112/EC, Articles 14a, 59c, 369l-369x).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-vber-2022-330-vertical-agreements-block-exemption",
    "title": "Commission Regulation (EU) 2022/720 on the application of Article 101(3) of the Treaty on the Functioning of the European Union to categories of vertical agreements and concerted practices - Article 2: Exemption",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article establishes a block exemption declaring that the prohibition on anti-competitive agreements under Article 101(1) of the TFEU does not apply to vertical agreements, provided they contain vertical restraints and comply with the other provisions of this Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-vehicle-emissions-type-approval-regulation-715-2007",
    "title": "Regulation (EC) No 715/2007 of the European Parliament and of the Council of 20 June 2007 on type approval of motor vehicles with respect to emissions from light passenger and commercial vehicles (Euro 5 and Euro 6)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation establishes the Euro 5 and Euro 6 common technical requirements for the type approval of M1, M2, N1 and N2 motor vehicles up to 2 610 kg reference mass with respect to emissions (Articles 1 and 2). Manufacturers must demonstrate that new vehicles and replacement pollution control devices are type approved (Article 4), must not use defeat devices that reduce emission control effectiveness except in narrowly permitted cases (Article 5), and must provide unrestricted standardised access to vehicle repair and maintenance information to independent operators (Article 6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-type-approval-framework-regulation-2018-858",
      "eu-emission-standards-euro-7"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-vehicle-registration-documents-directive-1999-37",
    "title": "Council Directive 1999/37/EC of 29 April 1999 on the registration documents for vehicles",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive harmonises the registration documents issued by Member States at the time of vehicle registration (Article 1). It defines the registration certificate and its harmonised content set out in the Annexes (Article 2), requires that registration certificates issued by one Member State be recognised by the others for the identification of the vehicle in international traffic and for re-registration (Article 4), provides for adaptation of the Annexes to technical progress (Article 6), and for mutual assistance and information exchange between Member States (Article 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-type-approval-framework-regulation-2018-858",
      "eu-directive-2014-45-roadworthiness-testing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-vehicle-type-approval-regulation-2018-858",
    "title": "EU Vehicle Type Approval Regulation 2018/858 -- Whole Vehicle Type Approval and Market Surveillance",
    "domain": "Automotive & Mobility",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Regulation (EU) 2018/858 establishes the EU framework for whole vehicle type approval (WVTA), individual vehicle approval (IVA), and market surveillance of motor vehicles, trailers, and their systems and components. It replaced Framework Directive 2007/46/EC and directly applies across all EU Member States. Type approval is granted by a national approval authority (NSA) and recognised across the EU via the EC type approval certificate. Manufacturers must demonstrate conformity of production (CoP) through ongoing quality audits. National market surveillance authorities have mandatory recall powers under Article 54 if a vehicle poses a serious risk. EU-wide recall orders may be issued by the Commission under Article 54(4). Third-country vehicles must comply with equivalent standards or obtain EU type approval before sale in the EU. UNECE World Forum for Harmonization of Vehicle Regulations (WP.29) regulations are incorporated by reference through the UNECE 1958 Agreement. The regulation covers M-category passenger cars, N-category trucks/vans, L-category motorcycles/mopeds, O-category trailers, and T-category agricultural tractors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-health-safety-framework-directive-89-391"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-vehicle-weights-and-dimensions-directive-96-53",
    "title": "Council Directive 96/53/EC of 25 July 1996 laying down for certain road vehicles circulating within the Community the maximum authorised dimensions in national and international traffic and the maximum authorised weights in international traffic",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Directive sets the maximum authorised dimensions for certain road vehicles in national and international traffic and the maximum authorised weights in international traffic, to ensure interoperability and fair competition. The Annex I limits include a maximum width of 2,55 m and a maximum length of 18,75 m for road trains when fully extended, with an intermodal weight allowance referencing 44 tonnes; Member States may permit higher weights or dimensions on certain roads or engineering structures under Article 7 and within the conditions of the Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-type-approval-framework-regulation-2018-858",
      "iso-39001-road-traffic-safety-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-vertical-block-exemption-regulation-2022",
    "title": "Commission Regulation (EU) 2022/720 of 31 March 2022 on the application of Article 101(3) of the Treaty on the Functioning of the European Union to categories of vertical agreements and concerted practices",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes a safe harbour for vertical agreements between suppliers and distributors where the combined market share of the parties does not exceed 30% in the relevant market, provided that the agreements do not contain hardcore restrictions listed in Article 4. It applies to all vertical agreements in the EU, including those governing online sales and dual distribution, under Article 101(3) TFEU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "uk-competition-act-1998-chapter-1-2-prohibitions",
      "india-competition-act-2002-sections-3-4",
      "oecd-recommendation-hard-core-cartels-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-vertical-block-exemption-regulation-2022-720",
    "title": "Commission Regulation (EU) 2022/720 of 10 May 2022 on the application of Article 101(3) of the Treaty on the Functioning of the European Union to categories of vertical agreements and concerted practices",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation provides a 'safe harbour' for vertical agreements between suppliers and buyers, exempting them from the EU's prohibition on anti-competitive agreements under Article 101(1) TFEU. The exemption applies if the market share of both the supplier and the buyer does not exceed 30% (Article 3) and the agreement does not contain any 'hardcore restrictions' as defined in Article 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tfeu-article-102-abuse-of-dominance"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-vertical-block-exemption-regulation-2022-720-vaber",
    "title": "Commission Regulation (EU) 2022/720 of 8 April 2022 on the Application of Article 101(3) of the Treaty on the Functioning of the European Union to Categories of Vertical Agreements and Concerted Practices",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes a safe harbour for vertical agreements between non-competing undertakings if their combined market share does not exceed 30% at both the supplier and buyer level, under Article 101(3) TFEU. It specifies hardcore restrictions-including resale price maintenance, territorial and customer resale restrictions in online sales-that remove agreements from the block exemption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-state-aid-articles-107-108-tfeu-framework",
      "uk-competition-act-1998-chapter-1-2-prohibitions",
      "india-competition-act-2002-sections-3-4",
      "oecd-recommendation-hard-core-cartels-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-very-high-capacity-networks-eecc-definition",
    "title": "Commission Implementing Regulation (EU) 2020/764 of 29 May 2020 laying down detailed rules concerning the definition of very high-capacity networks",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Defines Very High Capacity Networks (VHCNs) under the European Electronic Communications Code (EECC) as networks capable of providing symmetric 100 Mbps or higher, including FTTP, DOCSIS 3.1 HFC, fixed wireless with >100 Mbps downlink, and 5G outdoor deployments. Applies to national regulatory authorities (NRAs) and electronic communications providers for infrastructure investment reporting and access obligations under Article 2(2) of EECC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-broadband-cost-reduction-directive-2014-61",
      "eu-eecc-spectrum-small-area-wireless-access",
      "3gpp-5g-nr-release-17-specifications",
      "eu-net-neutrality-open-internet-2015-2120"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-vessel-traffic-monitoring-directive-2002-59",
    "title": "Directive 2002/59/EC (Vessel Traffic Monitoring)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Directive 2002/59/EC establishes a Community vessel traffic monitoring and information system. Article 6a requires fishing vessels with an overall length of more than 15 metres flying a Member State flag to be fitted with a Class A AIS and to keep it in operation at all times, save in exceptional circumstances at the master's judgement. Article 16 designates ships involved in incidents, reporting failures or pollution violations as ships posing a potential hazard, triggering inter-Member-State communication, while Article 20 obliges Member States to designate competent authorities empowered to take independent decisions on accommodating ships in need of assistance (places of refuge).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-port-state-control-directive-2009-16"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-visa-code-regulation-810-2009",
    "title": "Regulation (EC) No 810/2009 of the European Parliament and of the Council of 13 July 2009 establishing a Community Code on Visas (Visa Code)",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "The Visa Code establishes the procedures and conditions for issuing visas for transit through or intended short stays in the territory of the Member States (Article 1). It identifies third-country nationals requiring an airport transit visa (Article 3), the authorities competent for applications (Article 4), the Member State competent to examine an application (Article 5), consular territorial competence (Article 6), representation arrangements between Member States (Article 8), and the practical modalities and general rules for lodging applications no more than a set period before the intended visit (Articles 9 and 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-schengen-borders-code-regulation-2016-399",
      "eu-long-term-residents-directive-2003-109-ec"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-visa-requirement-lists-regulation-2018-1806",
    "title": "Regulation (EU) 2018/1806 of the European Parliament and of the Council of 14 November 2018 listing the third countries whose nationals must be in possession of visas when crossing the external borders and those whose nationals are exempt from that requirement",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation determines the third countries whose nationals are subject to, or exempt from, the requirement to hold a visa when crossing the external borders for short stays (Article 1). Annex I lists the third countries whose nationals must hold a visa, and Annex II lists those whose nationals are exempt for stays of no more than 90 days in any 180-day period (Article 4). It includes a reciprocity mechanism where a listed exempt country imposes a visa requirement on nationals of a Member State (Article 7) and a suspension mechanism.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-visa-code-regulation-810-2009",
      "eu-schengen-borders-code-regulation-2016-399"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-waste-construction-demolition-directive",
    "title": "Directive 2008/98/EC of the European Parliament and of the Council of 19 November 2008 on waste and repealing certain Directives (Text with EEA relevance)",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This directive establishes a mandatory 70% by weight recovery target for construction and demolition waste (CDW) by 2020, requires adherence to the waste hierarchy (Article 4), mandates pre-demolition removal of hazardous materials (Article 13), and obliges Member States to implement digital waste tracking systems for CDW. Applies to all construction and demolition operators, waste management facilities, and national regulatory bodies within the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-circular-economy-construction-demolition-waste-2020",
      "iso-19650-bim-information-management-construction",
      "us-clean-water-act-section-404-construction"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-waste-framework-directive-2008-98",
    "title": "EU Waste Framework Directive 2008/98/EC - Waste Management Hierarchy and Extended Producer Responsibility",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Directive 2008/98/EC of the European Parliament and of the Council of 19 November 2008 on waste (the Waste Framework Directive, WFD), as amended by Directive 2018/851/EU, establishes the overarching legal framework for waste management in the European Union, setting out the five-step waste hierarchy (prevention, re-use, recycling, recovery, disposal) and requiring Member States to treat waste in a manner consistent with the hierarchy. The WFD defines key concepts including waste, hazardous waste, by-product, end-of-waste, producer, holder, dealer, broker, and waste management. The Directive requires Member States to achieve a minimum 55% recycling rate for municipal waste by 2025 (rising to 65% by 2035), to establish extended producer responsibility (EPR) schemes for packaging, batteries, WEEE, and end-of-life vehicles, and to adopt national waste management plans and waste prevention programmes. The 2018 amendment introduced mandatory minimum requirements for EPR schemes, added requirements for food waste reduction, and strengthened deposit return systems. The WFD is the parent directive for specific waste streams including WEEE Directive, Batteries Regulation, Packaging Directive, and End-of-Life Vehicles Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_circular_economy_action_plan",
        "eu_esg_taxonomy_regulation",
        "eu_industrial_emissions_directive"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-circular-economy-construction-demolition-waste-2020",
      "eu-industrial-emissions-directive-2010-75-construction"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-waste-framework-directive-2008-98-ec",
    "title": "Directive 2008/98/EC of the European Parliament and of the Council of 19 November 2008 on waste and repealing certain Directives",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "Directive 2008/98/EC establishes the legal framework for waste management in the EU, aiming to protect the environment and human health by preventing or reducing the adverse impacts of waste generation and management and by reducing overall impacts of resource use. The Directive defines key concepts including waste, hazardous waste, waste oils, bio-waste, waste producer, waste holder, dealer, broker, waste management, collection, separate collection, prevention, re-use, treatment, recovery, preparing for re-use, recycling, regeneration of waste oils, disposal, and best available techniques. It sets out a five-step waste hierarchy as a priority order: prevention, preparing for re-use, recycling, other recovery (e.g., energy recovery), and disposal. Member States must ensure waste management without endangering human health or harming the environment, with specific protections for water, air, soil, plants, animals, and against nuisance from noise or odours. The Directive introduces extended producer responsibility, allowing Member States to impose obligations on product producers for acceptance of returned products and subsequent waste management. Targets are set: by 2020, preparing for re-use and recycling of household waste materials (paper, metal, plastic, glass) must reach at least 50% by weight, and non-hazardous construction and demolition waste must reach 70% by weight. Separate collection for paper, metal, plastic, and glass must be set up by 2015. Waste prevention programmes must be established, and the Commission must report on waste generation and prevention by specified deadlines. The Directive also covers waste management plans, permitting and registration requirements for establishments or undertakings carrying out waste management, and provisions on hazardous waste, waste oils, and bio-waste.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-waste-shipment-regulation-2024-1157",
    "title": "Regulation (EU) 2024/1157 on shipments of waste - notification and consent, general information requirements, export prohibitions for disposal and non-OECD recovery",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Regulation (EU) 2024/1157, adopted 11 April 2024, governs shipments of waste within and from the EU and repeals Regulation (EC) No 1013/2006. Shipments of waste destined for disposal are prohibited unless consent is obtained, shipments for recovery are subject to general information requirements, and exports of waste for disposal to third countries other than EFTA countries are prohibited. It implements Basel Convention obligations and circular-economy principles, with delayed application dates for certain provisions including the plastic-waste export prohibition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-convention-1989-hazardous-waste-transboundary",
      "eu-waste-framework-directive-2008-98",
      "eu-weee-directive-2012-19"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-water-framework-directive-2000-60-ec",
    "title": "EU Water Framework Directive 2000/60/EC - River Basin Management and Good Water Status",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "EU Directive 2000/60/EC establishes a framework for Community action in the field of water policy. Member States must achieve 'good status' for all surface waters and groundwaters by 2027 through River Basin Management Plans (RBMPs), with permitted exceptions under Article 4(4)-(7). Applies to AI water-monitoring systems, smart irrigation platforms, and any digital platform collecting or processing water quality data under GDPR Article 9 special categories.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standards",
        "frameworks",
        "regulations",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-14001-ems"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-water-reuse-regulation-2020-741",
    "title": "EU Water Reuse Regulation 2020/741 - Minimum Requirements for Reclaimed Water in Agricultural Irrigation",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "EU Regulation 2020/741 establishes minimum water quality requirements for reclaimed water used in agricultural irrigation and groundwater recharge, applying from 26 June 2023. The Regulation introduces a risk management approach requiring Reclaimed Water Quality Classes (Class A-D) validated through a Water Reuse Risk Management Plan (WRRMP). AI-driven smart irrigation systems using reclaimed water must incorporate online monitoring of microbiological and chemical quality parameters against Class-specific thresholds. Directly relevant to AgriTech platforms, digital water utilities, and circular economy water infrastructure deploying IoT sensor networks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standards",
        "frameworks",
        "regulations",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-water-framework-directive-2000-60-ec",
      "eu-common-agricultural-policy-regulation-2021-2115"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-weee-directive-2012-19",
    "title": "EU WEEE Directive 2012/19",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2012-07-24",
    "bluf": "Directive 2012/19/EU of the European Parliament and of the Council on waste electrical and electronic equipment (WEEE), in force from 13 August 2012 with full transposition required by 14 February 2014, imposes extended producer responsibility on manufacturers and importers of electrical and electronic equipment placed on the EU market, requiring registration with national producer registers, financing of collection and treatment systems for WEEE from private households and commercial users, achieving minimum collection rates of 65% of average EEE placed on the market in the preceding three years under Article 7, meeting treatment recovery and recycling targets by EEE category under Annex V, ensuring WEEE treatment facilities comply with minimum treatment standards under Article 8 and Annex VII for hazardous substances including the ten RoHS-restricted substances, and providing consumers with free take-back at the point of sale under Article 5(2) for like-for-like exchanges of small WEEE at retail outlets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-rohs-directive-2011-65",
        "eu-reach-regulation-1907-2006",
        "eu-ecodesign-sustainable-products-regulation-2024-1781"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-rohs-directive-2011-65",
      "eu-reach-regulation-1907-2006",
      "eu-ecodesign-sustainable-products-regulation-2024-1781"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-weee-directive-2012-19-eu",
    "title": "EU Waste Electrical and Electronic Equipment Directive 2012/19/EU (WEEE)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "EU Directive 2012/19/EU (WEEE recast) implements producer responsibility for waste electrical and electronic equipment in the EU. Producers (defined broadly to include manufacturers importers and distance sellers) must finance collection treatment recovery and environmentally sound disposal of WEEE from their products. Member States must achieve minimum collection rates (45% from 2016 then 65% of EEE placed on market or 85% of WEEE generated from 2019) and recovery/recycling targets per Annex V by EEE category. Collection rates from private households are met through retailer take-back (1:1 free of charge) and collection points.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-western-mediterranean-demersal-fisheries-regulation-2023-2124",
    "title": "Regulation (EU) 2023/2124 of the European Parliament and of the Council of 4 October 2023 on certain provisions for fishing in the General Fisheries Commission for the Mediterranean (GFCM) Agreement area",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-06-23",
    "bluf": "This Regulation lays down certain provisions for fishing in the General Fisheries Commission for the Mediterranean (GFCM) Agreement area, transposing GFCM recommendations into Union law (Articles 1 and 2). It establishes fisheries restricted areas (Article 5), technical measures (Article 6) and additional measures (Article 7), and sets requirements on fishing authorisations (Article 9), designated landing points (Article 11), the recording of catches (Article 12), scientific monitoring (Article 14) and the maintenance of lists of authorised and active vessels (Article 15).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fao-code-conduct-responsible-fisheries-1995",
      "eu-official-controls-regulation-2017-625"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-whistleblower-directive-2019",
    "title": "Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report on breaches of Union law",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This directive establishes EU-wide minimum standards to protect persons who report breaches of Union law, applying to private sector companies with 50 or more workers and most public sector entities. It mandates the establishment of secure and confidential internal and external reporting channels and prohibits any form of retaliation against whistleblowers, as outlined in Articles 8, 11, and 19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "iso-37001-anti-bribery-mgt",
      "iso-26000-social-resp-mgt",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-whistleblower-directive-2019-1937",
    "title": "Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report on breaches of Union law",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This directive mandates legal entities in the private and public sectors across the EU to establish secure and confidential internal reporting channels for individuals to report breaches of Union law. It establishes a robust framework under Article 19 to protect whistleblowers from any form of retaliation, such as dismissal, demotion, or intimidation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "iso-31000-risk-mgt-std",
      "iso-27701-privacy-information-management",
      "shrm-hr-competency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-whistleblower-directive-2019-1937-article-13-conditions-protection-external-reporting",
    "title": "EU Whistleblower Protection Directive (EU) 2019/1937 - Article 13: Conditions for Protection in External Reporting",
    "domain": "Workplace",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 13 of the EU Whistleblower Protection Directive (2019/1937) establishes the conditions under which reporting persons who report to competent external authorities (rather than through internal channels) are entitled to the full protection of the Directive. Reporting persons are protected in external reporting if: (a) they had reasonable grounds to believe the information reported was true at the time of reporting; and (b) they reported through the external reporting channels set up by member states (typically regulatory authorities, law enforcement, or sector-specific supervisory authorities). Reporting persons who report externally without first using internal channels are still protected, as long as they had reasonable grounds for believing the information was true. Reporting persons may bypass internal channels and go directly to external authorities in specific circumstances: where they had reasonable grounds to believe the violation may not be effectively addressed internally; where they feared retaliation; where they reasonably believed internal reporting could lead to concealment or destruction of evidence; or where the subject of the internal report is the head of the reporting entity. The protection covers the reporting person's identity, freedom from retaliation, and access to legal and judicial remedies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-whistleblower-directive-2019-1937-article-19-prohibition-retaliation"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-whistleblower-directive-2019-1937-article-19-prohibition-retaliation",
    "title": "EU Whistleblower Protection Directive (EU) 2019/1937 - Article 19: Prohibition of Retaliation",
    "domain": "Workplace",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 19 of the EU Whistleblower Protection Directive (2019/1937) establishes a comprehensive prohibition on retaliation against reporting persons who report violations of EU law in good faith. The prohibition covers any direct or indirect retaliatory acts or omissions, including: dismissal, suspension, demotion, transfer, withholding of promotion, change of working hours, negative performance assessment, imposition of disciplinary measures, coercion, intimidation, harassment, discrimination, failure to convert temporary contracts, non-renewal of fixed-term contracts, damage to reputation or financial harm, blacklisting, and early termination of contracts for goods or services. The prohibition extends to facilitators, third parties connected to the reporting person, and legal entities associated with or owned by the reporting person. Article 21 establishes a reversed burden of proof in proceedings concerning retaliation - once the reporting person establishes that they made a report and suffered detriment, the burden shifts to the employer or entity responsible for the detriment to prove the detriment was not connected to the report. Interim measures to prevent retaliation during legal proceedings must be available. Effective penalties including compensation for the reporting person are required.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-whistleblower-directive-2019-1937-article-9-reporting-channels-internal",
    "title": "EU Whistleblower Protection Directive (EU) 2019/1937 - Article 9: Requirements for Internal Reporting Channels",
    "domain": "Workplace",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 9 of the EU Whistleblower Protection Directive (2019/1937) establishes mandatory requirements for internal reporting channels that legal entities in the private and public sector must set up for receiving reports of violations of EU law. Private sector entities with 50 or more workers and all public sector entities must establish internal reporting channels. The channels must: (a) allow reporting in writing (including electronically), orally (by telephone or voice message), or in person at the request of the reporting person; (b) ensure the confidentiality of the reporting person's identity and any third party named in the report; (c) be designated to a dedicated person or department; (d) acknowledge receipt within 7 days; (e) diligently follow up on reports; (f) provide feedback to the reporting person on the action taken within a reasonable period not exceeding 3 months; (g) provide clear and accessible information about external reporting channels to public authorities. Private sector entities with 50-249 workers may share resources for receiving and investigating reports. The internal reporting channel must be designed, established, and operated in a secure manner ensuring confidentiality. Member states must ensure compliance through effective, proportionate, and dissuasive penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlap",
        "use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-whistleblower-directive-2019-1937-article-13-conditions-protection-external-reporting",
      "eu-whistleblower-directive-2019-1937-article-19-prohibition-retaliation"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-whistleblower-directive-2019-1937-reporting-channels-protection",
    "title": "EU Whistleblower Protection Directive 2019/1937 - Internal Reporting Channels, Anti-Retaliation, and Competent Authority Procedures",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Directive (EU) 2019/1937 requires private entities with 50+ employees and public sector bodies to establish secure internal reporting channels for EU law violations, protects whistleblowers from all forms of retaliation, mandates feedback within 3 months, and requires Member States to establish independent external reporting channels with equivalent protections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gdpr-article-8-childrens-consent-information-society-services"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-whistleblower-protection-directive-2019-1937",
    "title": "EU Whistleblower Protection Directive 2019/1937 - Reporting Channels, Retaliation Prohibition and Workplace Protection",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report breaches of Union law (Whistleblower Directive) entered into force on 16 December 2019 with transposition deadline 17 December 2021 for Member States and 17 December 2023 for legal entities in private sector with 50-249 workers. The Directive establishes minimum standards for protecting whistleblowers reporting breaches of Union law in specific areas listed in Article 2 including public procurement, financial services, money laundering, product safety, transport safety, environmental protection, radiation protection, food/feed safety, animal health/welfare, public health, consumer protection, privacy, network and information security, EU financial interests, internal market, and Treaty Articles 101/102 competition. Article 8 requires private sector entities with 50+ workers and public sector entities to establish internal reporting channels with confidentiality. Article 11 mandates external reporting channels through designated competent authorities. Article 19 prohibits all forms of retaliation against whistleblowers including dismissal, demotion, withholding of training, negative performance assessment. Article 21 sets out support measures including legal advice, financial assistance, psychological support. Article 23 provides effective and proportionate penalties for retaliation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-employment-equality-directive-2000-78",
      "ilo-c190-violence-harassment-2019"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-whistleblowing-directive-2019-1937",
    "title": "EU Whistleblowing Directive 2019/1937",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2021-12-17",
    "bluf": "Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law requires private sector organisations with 50 or more workers and all public sector entities to establish internal reporting channels, prohibits retaliation against whistleblowers, and obliges Member States to ensure effective, proportionate, and dissuasive penalties for retaliation and obstruction of protected reports, with a transposition deadline of 17 December 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-corporate-sustainability-reporting-directive-2022-2464",
        "eu-nis2-directive-2022-2555",
        "uk-health-safety-at-work-act-1974"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-corporate-sustainability-reporting-directive-2022-2464",
      "eu-nis2-directive-2022-2555",
      "uk-health-safety-at-work-act-1974"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-whistleblowing-directive-cx-complaints-2019",
    "title": "Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report breaches of Union law",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This directive requires private and public sector organizations with 50 or more employees to establish internal reporting channels for whistleblowers, ensure confidentiality, prohibit retaliation, and follow up on reports related to breaches of Union law, including in customer experience (CX) functions. Key obligations are set out in Articles 8, 9, and 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-10002-2018-customer-satisfaction-complaints",
      "bpmn-2-0-omg-specification-workflow-notation",
      "eu-omnibus-directive-2019-2161",
      "eu-consumer-rights-directive-2011"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-wifi4eu-public-wireless-connectivity-2021",
    "title": "WiFi4EU - free Wi-Fi in public spaces",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The WiFi4EU initiative provides municipalities across the European Union with €15,000 vouchers to install free Wi-Fi in public spaces not already equipped with a free hotspot. Recipient municipalities must ensure the service remains operational for at least three years after installation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-eecc-spectrum-small-area-wireless-access",
      "eu-eprivacy-regulation-proposed-2017",
      "eu-data-act-2023-competition-data-access",
      "eu-nis2-telecoms-essential-services"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-wire-transfer-regulation-2015-847",
    "title": "EU Wire Transfer Regulation 2015/847 - Funds Transfer Information Requirements (Travel Rule)",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation (EU) 2015/847 requires payment service providers to transmit complete originator and beneficiary information with every transfer of funds, implementing FATF Recommendation 16 ('Travel Rule') in the EU. It mandates full payer name, account number, and address for transfers ≥€1,000. Updated by Regulation 2023/1113, which extends the Travel Rule to crypto-assets from 30 December 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-regulation-2024",
      "eu-psd2-strong-customer-authentication",
      "eu-capital-requirements-directive-iv-2013-36-crd4"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-wire-transfer-regulation-2023-1113",
    "title": "EU Transfer of Funds Regulation 2023/1113 (TFR2) - Travel Rule & Crypto-Asset Transfers",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation 2023/1113 (TFR2, in force 30 December 2024) extends the EU Travel Rule to crypto-asset transfers, requiring payment service providers (PSPs) and crypto-asset service providers (CASPs) to transmit originator and beneficiary information with every transfer of funds or crypto-assets. TFR2 replaces the 2015 Wire Transfer Regulation (Reg 847/2015). For crypto-assets, full name, account address/DLT address, and national identification number must accompany every transfer regardless of value. A de minimis threshold of €1,000 applies for fund transfers between EEA PSPs only. PSPs and CASPs must screen for and reject transfers from unhosted wallets that cannot be identified.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-authority-amla-2024",
      "eu-6amld-sixth-anti-money-laundering-2018-1673"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-work-life-balance-directive-2019",
    "title": "Directive (EU) 2019/1158 of the European Parliament and of the Council of 20 June 2019 on work-life balance for parents and carers and repealing Council Directive 2010/18/EU",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This EU Directive requires Member States to establish minimum rights for workers concerning paternity leave, parental leave, and carers' leave, as well as the right to request flexible working arrangements. It aims to promote gender equality and better work-life balance by setting standards such as a minimum of 10 working days for paternity leave (Article 4) and four months of parental leave, with two months being non-transferable (Article 5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "iso-30414-human-capital-rep",
      "shrm-hr-competency",
      "sa8000-social-account"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-work-life-balance-directive-2019-1158",
    "title": "EU Work-Life Balance Directive 2019/1158 - Parental Leave and Flexible Working",
    "domain": "Workplace",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive (EU) 2019/1158 on work-life balance for parents and carers establishes minimum rights to paternity leave (10 working days), parental leave (4 months per parent, 2 non-transferable), and carers leave (5 days per year); workers have the right to request flexible working arrangements including part-time and remote work for caring responsibilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "eu-working-time-directive-2003-88",
    "title": "Directive 2003/88/EC of the European Parliament and of the Council of 4 November 2003 concerning certain aspects of the organisation of working time",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This directive establishes minimum safety and health requirements for the organisation of working time in EU member states, mandating a maximum average 48-hour working week (including overtime) over a reference period, as stipulated in Article 6. It also sets minimum daily rest, weekly rest, and paid annual leave entitlements for all workers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-work-safety",
      "ilo-core-conventions",
      "eu-work-life-balance-directive-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "eu-working-time-directive-2003-88-maximum-hours-rest-periods",
    "title": "EU Working Time Directive 2003/88 - Maximum Working Hours, Rest Periods, and Annual Leave",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Directive 2003/88/EC on the organisation of working time sets EU-wide minimum requirements: maximum 48 working hours per week (including overtime) averaged over a reference period, 11 consecutive hours daily rest, 24 consecutive hours weekly rest, 15-minute break after 6 hours of work, and 4 weeks paid annual leave. Individual opt-outs from the 48-hour limit are permitted in Member States that allow them.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-platform-work-directive-2024-2831-algorithmic-management-transparency"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eu-works-council-directive-2009",
    "title": "Directive 2009/38/EC of the European Parliament and of the Council of 6 May 2009 on the establishment of a European Works Council or a procedure in Community-scale undertakings and Community-scale groups of undertakings for the purposes of informing and consulting employees (Recast)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This directive requires Community-scale undertakings (≥1,000 employees in the EU/EEA, with ≥150 in at least two Member States) to establish a European Works Council (EWC) or an equivalent procedure for informing and consulting employees on transnational matters, including the introduction of new working methods or production processes like AI-driven monitoring systems (Article 1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "eu-whistleblower-directive-2019",
      "iso-30414-human-capital-rep"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "eu-works-council-directive-2009-38",
    "title": "Directive 2009/38/EC of the European Parliament and of the Council of 6 May 2009 on the establishment of a European Works Council or a procedure in Community-scale undertakings and Community-scale groups of undertakings for the purposes of informing and consulting employees (Recast)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This directive requires Community-scale undertakings or groups of undertakings (at least 1,000 employees within Member States and at least 150 employees in each of at least two Member States) to establish a European Works Council (EWC) or an alternative procedure for informing and consulting employees on transnational matters. The core obligation, as defined in Article 1, is to improve employees' rights to information and consultation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "eu-whistleblower-directive-2019",
      "iso-26000-social-resp-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "euro-ncap-safety-assessment-protocol-2024",
    "title": "Euro NCAP Safety Assessment Protocol 2024 - Adult Occupant, Child Occupant, Vulnerable Road Users, Safety Assist Testing Methods and Rating Criteria for Vehicle Safety Assessment",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This protocol defines the testing and rating methodology used by Euro NCAP for assessing vehicle safety performance across adult occupant protection, child occupant protection, vulnerable road user protection, and safety assist technologies. It applies to all new vehicles submitted for Euro NCAP rating under the 2024 assessment framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "un-regulation-r157-automated-lane-keeping-alks",
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "eurocode-en-1990-basis-structural-design",
    "title": "Eurocode EN 1990:2002 Basis of Structural Design - Principles for Load Combinations, Limit States and Reliability",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard establishes the fundamental principles and requirements for the safety, serviceability, and durability of structures within the European Union, mandating the use of limit state design and partial factor methods for verification. As per Clause 3.1(1)P, all structures must be designed to sustain all likely actions and influences during their intended life with appropriate reliability and economy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "exif-standard-metadata",
    "title": "EXIF Standard (Metadata)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the Exchangeable image file format standard is rigorously enforced to ensure data integrity and interoperability for all digital still-camera image assets. This validation mandates strict adherence to the CIPA DC-008-2023 specification, requiring a valid Exif Version 3.0 signature for all processed files. The underlying file structure must conform to the TIFF/EP image data format described in ISO 12234-2:2001, with the TIFF header offset not exceeding a maximum of 8 bytes. Consistent byte order, whether little or big endian, must be maintained throughout the file structure to prevent data corruption. The node enforces the complete Section 4 image data structure, which includes the mandatory presence of a GPS Info IFD as specified in section 4.3 and an Interoperability IFD index to align with standards like the ISO/IEC 23000-3:2007 photo player application format. All textual metadata must use UTF-8 character encoding. Furthermore, critical photographic parameters are required, making the FNumber (aperture), ExposureTime, and PhotographicSensitivity (ISO) tags mandatory for validation. To mitigate security risks, any execution of proprietary MakerNote code is explicitly disallowed. The total metadata payload is constrained to a maximum size of 65536 bytes, with its storage and handling governed by principles analogous to those in NIST SP 800-111 for safeguarding sensitive information. This comprehensive approach ensures that image metadata is not only structurally sound per RFC 3950 but also complete, secure, and universally interpretable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iptc-photo-metadata",
      "iso-16684-xmp-metadata",
      "c2pa-content-provenance",
      "dmca-safe-harbor",
      "wipo-copyright-treaty",
      "berne-convention-literary-artistic"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "extractive-industries-transparency-eiti-standard",
    "title": "Extractive Industries Transparency Initiative (EITI) Standard 2023",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The EITI Standard 2023 requires implementing countries and extractive companies to disclose revenues, production, contracts, beneficial ownership, and revenue distribution to promote transparency and accountability in oil, gas, and mining sectors. Key requirements are established under EITI Requirement 4 and Requirement 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eiti-standard-2023",
      "eu-conflict-minerals-regulation-2017-821",
      "drc-mining-code-law-18-001-2018",
      "chile-mining-code-1983",
      "canada-national-instrument-43-101"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "faa-part-107-uas-2021",
    "title": "Title 14 CFR Part 107 - Small Unmanned Aircraft Systems (2021 Update)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes the operational and certification rules for commercial use of small unmanned aircraft systems (sUAS) weighing less than 55 pounds within the U.S. National Airspace System. As outlined in Subparts B and C, it mandates remote pilot certification, sUAS registration, and adherence to strict operational limitations, including maintaining visual line-of-sight (VLOS) unless a waiver is granted.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "faa-part-21-certification"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "faa-part-135-air-taxi-commuter-operations",
    "title": "Operating Requirements: Commuter and on Demand Operations and Rules Governing Persons on Board Such Aircraft (FAR Part 135)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes operating requirements for commuter and on-demand air carriers using small aircraft, including crew qualifications, aircraft equipment, flight operations, and emergency procedures. It applies to operators conducting for-hire flights under 14 CFR Part 135, including air taxi and charter services, and mandates compliance with §§ 135.23 (manual contents), 135.87 (cargo carriage), 135.128 (safety belts), 135.177 (emergency equipment), and 135.209 (VFR fuel supply).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "as9100-rev-d-qms",
      "do-178c-airborne-software-2011",
      "cmmc-2-audit",
      "nist-800-171-cui",
      "dfars-7012-defense-cyber"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "faa-part-141-pilot-school-certification",
    "title": "Pilot Schools (14 CFR Part 141)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes the requirements for certificating pilot schools under Title 14 of the Code of Federal Regulations, including curriculum approval, instructor qualifications, training facilities, and recordkeeping. It applies to any person or organization seeking to operate as a certified pilot school under § 141.3 and § 141.5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "as9100-rev-d-qms",
      "do-178c-airborne-software-2011",
      "easa-part-145-maintenance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "faa-part-21-certification",
    "title": "FAA Part 21 (Certification)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "FAA Part 21 (Certification Procedures for Products and Articles) is the primary U.S. regulation for the certification of aircraft, engines, propellers, and parts. it encompasses the entire life cycle from initial type certificate (TC) through production certificate (PC) and final airworthiness certificate issuance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "as9100-rev-d-qms",
      "icao-safety-annex-19",
      "dfars-7012-defense-cyber",
      "itar-compliance-workflow",
      "ear-dual-use-export",
      "nist-800-171-rev-3"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "faa-part-450-commercial-space-launch-operations",
    "title": "FAA 14 CFR Part 450 - Launch and Reentry Vehicle Operations",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "14 CFR Part 450 establishes the FAA's unified licensing and safety framework for commercial launch and reentry operations, requiring vehicle operators to obtain a mission-specific or operator licence, conduct pre-mission flight safety analyses, maintain certified flight safety systems, and demonstrate that the expected loss of life (ELS) to uninvolved public does not exceed 1.00E-04 per mission and the expected number of casualties to critical assets (ENSC) does not exceed 1.00E-03.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "faa-remote-id-rule-2021",
    "title": "Remote Identification of Unmanned Aircraft",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This rule requires most unmanned aircraft (drones) operating in United States airspace to be equipped with Remote ID technology, which broadcasts identification and location information of the drone and its control station. As specified in 14 CFR Part 89, this applies to drone pilots, who must operate a compliant drone, and manufacturers, who must produce Standard Remote ID or broadcast module-equipped drones.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "faa-part-21-certification",
      "as9100-rev-d-qms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fair-trade-tourism",
    "title": "Fair Trade Tourism Audit",
    "domain": "Food & Hospitality",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Fair Trade Tourism Audit evaluates an entity's operational alignment with established international standards for ethical and sustainable tourism. The protocol mandates strict adherence to core labor practices, demanding verifiable minimum_wage_compliance and an absolute prohibition on child labor, principles reinforced by the ILO Declaration on Fundamental Principles and Rights at Work. It further stipulates that working schedules must not exceed a maximum_of_48_hours_per_week. Consistent with the Universal Declaration of Human Rights, the node requires active anti_discrimination_policies and upholds the right to freedom_of_association. Socio-economic contributions are quantified through specific thresholds, requiring a local_employment_ratio_min_pct of sixty and a local_procurement_ratio_min_pct of at least fifty, reflecting goals within the Global Sustainable Tourism Council Industry Criteria. As envisioned by the UNWTO Global Code of Ethics, entities must demonstrate a tangible commitment to host communities by establishing a community_benefit_sharing_fund and ensuring cultural_heritage_protection. The Fair Trade Tourism Standard v5.1 core criteria are further met through the implementation of a formal grievance_mechanism, a comprehensive environmental_sustainability_plan, and the provision of no less than twelve annual health_and_safety_training_hours. These requirements, guided by ISO 26000's framework on social responsibility, collectively ensure a holistic approach to fair trade principles, community involvement, and human rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gstc-tourism-criteria",
      "ilo-core-conventions",
      "iso-21401-tourism-sustain",
      "iso-26000-social-resp",
      "sa8000-social-account",
      "un-guiding-principles-business-hr"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fao-code-conduct-responsible-fisheries-1995",
    "title": "FAO Code of Conduct for Responsible Fisheries 1995 - Ecosystem Approach, Precautionary Principle and Voluntary Compliance",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Code of Conduct for Responsible Fisheries (CCRF) was unanimously adopted by the FAO Conference at its 28th Session on 31 October 1995. The Code is the foundational voluntary international instrument providing principles and standards for the conservation, management and development of all fisheries, encompassing capture fisheries, aquaculture, fishing operations, fishery research, integration into coastal area management, and post-harvest practices and trade. Article 1.1 establishes the Code as voluntary, with provisions to be interpreted and applied in conformity with the relevant rules of international law including UNCLOS 1982. Article 6 establishes the General Principles including 19 sub-principles covering: management measures based on best scientific evidence (Article 6.4), precautionary approach to conservation (Article 6.5), use of selective and environmentally safe fishing practices (Article 6.6), aquaculture development consistent with national plans (Article 6.19), integrated coastal area management (Article 6.9). The Code is supported by FAO Technical Guidelines for Responsible Fisheries (currently 25+ titles), International Plans of Action (IPOA) covering management of fishing capacity, illegal/unreported/unregulated (IUU) fishing, sharks, and seabirds, and the Port State Measures Agreement (PSMA) 2009 (binding instrument complementing CCRF).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-fish-stocks-agreement-1995",
      "unclos-part-vii-high-seas"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fatca-iga-compliance",
    "title": "FATCA IGA (Tax Compliance)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Foreign Account Tax Compliance Act (FATCA) is a U.S. federal law requiring foreign financial institutions (FFIs) to report the assets of U.S. account holders. The legislation is primarily implemented through Intergovernmental Agreements (IGAs) (Model 1 & Model 2), which provide a legal framework for FFIs to report to their national authority or the IRS, ensuring global tax transparency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bank-secrecy-act-suspicious",
      "crs-oecd-tax-automatic",
      "wolfsberg-corresp-bank"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fatf-40-recommendations-2023-consolidated",
    "title": "FATF 40 Recommendations 2023 Consolidated - AML/CFT/CPF International Standards: Risk-Based Approach, Customer Due Diligence, Beneficial Ownership, Correspondent Banking, Wire Transfer Rules and VASP Supervision",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This comprehensive set of international standards requires countries and their financial institutions to implement a risk-based approach (Recommendation 1) to combat money laundering, terrorist financing, and proliferation financing, mandating specific measures such as customer due diligence (Recommendation 10), beneficial ownership transparency (Recommendations 24 & 25), and supervision of virtual asset service providers (Recommendation 15).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-virtual-assets-vasp",
      "fatf-travel-rule-v2",
      "fatf-pf-risk-assessment-mitigation",
      "eu-aml-regulation-2024",
      "bank-secrecy-act-suspicious"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fatf-aml-agent",
    "title": "AI Agent Anti-Money Laundering (AML) Compliance",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Autonomous agents performing financial functions are subject to the same FATF risk-based approach as traditional entities. Compliance requires 'Neural AML' - embedding real-time traceability, KYC verification, and transaction monitoring directly into the agentic workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-virtual-assets-vasp",
      "fatf-travel-rule-v2",
      "crypto-aml-travel-rule",
      "fincen-cvc-business-models",
      "bank-secrecy-act-suspicious",
      "fatf-virtual-asset-redfl"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fatf-guidance-beneficial-ownership-2023",
    "title": "FATF Guidance on Beneficial Ownership of Legal Persons and Arrangements 2023 - Ultimate Beneficial Owner Definition, National Registry Requirements, Nominee Shareholders and Verification Mechanisms",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This FATF guidance mandates countries to ensure competent authorities have timely access to adequate, accurate, and up-to-date information on the ultimate beneficial owners (UBOs) of legal persons, as required by the updated Recommendation 24. It necessitates a multi-pronged approach, including establishing a public beneficial ownership registry, defining UBOs through both ownership and control tests, and implementing robust verification mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-regulation-2024",
      "eu-aml-authority-amla-2024",
      "fatf-travel-rule-v2",
      "bank-secrecy-act-suspicious"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fatf-guidance-rba-gambling-2021",
    "title": "FATF Guidance on the Risk-Based Approach for the Gambling Sector 2021",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This guidance requires gambling operators and financial intelligence units to implement risk-based anti-money laundering and counter-terrorist financing (AML/CFT) controls, including customer due diligence, ongoing monitoring, and suspicious transaction reporting, in accordance with FATF Recommendation 15 and the interpretive notes specific to the gambling sector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fatf-guidance-virtual-assets-vasp",
    "title": "UPDATED GUIDANCE FOR A RISK-BASED APPROACH VIRTUAL ASSETS AND VIRTUAL ASSET SERVICE PROVIDERS",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2021-10-01",
    "bluf": "In October 2018, the Financial Action Task Force (FATF) adopted changes to its Recommendations to explicitly clarify that they apply to financial activities involving virtual assets (VAs) and introduced definitions for 'virtual asset' and 'virtual asset service provider' (VASP). The amended FATF Recommendation 15 requires that VASPs be regulated for anti-money laundering and countering the financing of terrorism (AML/CFT) purposes, be licensed or registered, and subject to effective systems for monitoring or supervision. This guidance is intended to help national authorities develop regulatory and supervisory responses to VA activities and VASPs, and to assist private sector entities in understanding and complying with their AML/CFT obligations.\n\nThe guidance outlines the need for countries and VASPs to understand and mitigate money laundering and terrorist financing (ML/TF) risks associated with VA activities. It details the full range of obligations applicable to VASPs, which are the same full set of obligations as financial institutions, including customer due diligence (CDD), recordkeeping, suspicious transaction reporting (STR), and the implementation of the 'travel rule' (Recommendation 16). The travel rule mandates that VASPs must obtain, hold, and transmit required originator and beneficiary information during VA transfers. The guidance also clarifies the specific requirement for VASPs to conduct customer due diligence for occasional transactions above a USD/EUR 1,000 threshold.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "fatf-travel-rule-v2",
      "fatf-virtual-asset-redfl",
      "fincen-cvc-business-models"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fatf-guidance-virtual-assets-vasp-2021",
    "title": "FATF Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers (2021)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This updated FATF guidance clarifies and expands the definition of Virtual Asset Service Providers (VASPs) to potentially include DeFi arrangements and requires member countries to implement Recommendation 16 (the 'Travel Rule') for VA transfers over a USD/EUR 1,000 threshold, mandating the collection and exchange of originator and beneficiary information to combat money laundering and terrorist financing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-virtual-assets-vasp",
      "fatf-travel-rule-v2",
      "fatf-virtual-asset-redfl",
      "eu-aml-regulation-2024",
      "mica-stablecoin-reserve"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fatf-methodology-mutual-evaluation-2022",
    "title": "FATF Methodology for assessing technical compliance with the FATF Recommendations and the effectiveness of AML/CFT systems (2022)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This methodology establishes the global standard for peer-review mutual evaluations of a country's anti-money laundering and counter-terrorist financing (AML/CFT) framework. It assesses both technical compliance with the 40 FATF Recommendations and the practical effectiveness of the system based on 11 Immediate Outcomes, applying to all FATF and FSRB member jurisdictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "fatf-guidance-virtual-assets-vasp",
      "fatf-pf-risk-assessment-mitigation",
      "eu-aml-regulation-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fatf-pf-risk-assessment-mitigation",
    "title": "GUIDANCE ON PROLIFERATION FINANCING RISK ASSESSMENT AND MITIGATION",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2021-06-30",
    "bluf": "This non-binding Guidance from the Financial Action Task Force (FATF) aims to develop a common understanding of the amendments to FATF Recommendation 1, which require countries and private sector entities to identify, assess, understand, and mitigate their proliferation financing (PF) risks. In the context of this Guidance, proliferation financing risk refers strictly and only to the potential breach, non-implementation, or evasion of the targeted financial sanctions (TFS) obligations outlined in Recommendation 7, specifically concerning regimes for the Democratic People’s Republic of Korea (DPRK) and Iran. The document is intended for countries, competent authorities, supervisors, financial institutions, Designated Non-Financial Businesses and Professions (DNFBPs), and Virtual Asset Service Providers (VASPs).\n\nThe core obligation for private sector entities is to have processes in place to identify, assess, monitor, manage, and mitigate these risks. These processes may be integrated within existing targeted financial sanctions and/or compliance programmes, and entities are not expected to establish duplicative processes. The Guidance recognizes that there is no one-size-fits-all approach and encourages countries and private sector entities to implement measures proportionate to the risks they face, having regard to their specific context, risk profile, and the materiality of different sectors. Full application of targeted financial sanctions as required by Recommendation 7 remains mandatory in all cases.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-aml-agent"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fatf-recommendation-10-customer-due-diligence",
    "title": "The FATF Recommendations",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This standard requires countries to implement a comprehensive and consistent framework of measures to combat money laundering, terrorist financing, and the financing of proliferation of weapons of mass destruction, adapted to their particular circumstances.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "fatf-recommendation-15-new-technologies-virtual-assets",
    "title": "The FATF Recommendations - Recommendation 15: New Technologies",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Countries should identify and assess the money laundering and terrorist financing risks that may arise in relation to the development of new products and new business practices, and take appropriate measures to manage and mitigate those risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "fatf-recommendation-15-vasps-travel-rule-2025",
    "title": "FATF Recommendation 15 Virtual Asset Service Provider Travel Rule - 2025 Targeted Update and Best Practices Guidance",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Virtual Asset Service Providers (VASPs) operating in any of the 85 jurisdictions (of 117 surveyed in the 2025 FATF targeted update, up from 65 in 2024) that have passed legislation implementing the FATF Recommendation 15 Travel Rule for AML/CFT on virtual assets must comply with their local implementation including transmitting required originator and beneficiary information with VA transfers, submit to risk assessment and supervisory inspections (where only 33 percent of 138 assessed jurisdictions satisfactorily require VASP licensing or registration as of 2025, with only one jurisdiction fully compliant with Recommendation 15 as of April 2025), and apply the FATF Best Practices on Travel Rule Supervision to operationalise compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-aml-agent"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fatf-recommendation-16-travel-rule-crypto",
    "title": "FATF Recommendation 16: Wire Transfers (Interpretive Note for Virtual Assets) - The Travel Rule",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2023-10-27",
    "bluf": "This regulation requires Virtual Asset Service Providers (VASPs) to obtain, hold, and transmit required originator and beneficiary information for virtual asset transfers at or above USD/EUR 1,000 to combat money laundering and terrorist financing, as detailed in the Interpretive Note to Recommendation 15, paragraph 7(b).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tfer-regulation-2023",
      "crypto-aml-travel-rule",
      "fincen-cvc-business-models"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fatf-recommendation-16-travel-rule-va",
    "title": "FATF Recommendation 16 - Wire Transfers and Virtual Assets Travel Rule: Originator/Beneficiary Information Requirements and VASP-to-VASP Data Transmission",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "FATF Recommendation 16 requires virtual asset service providers (VASPs) to obtain, hold, and transmit accurate originator and beneficiary information for virtual asset transfers above USD/EUR 1,000, mirroring the wire transfer rules for banks. This applies to all VASPs, including cryptocurrency exchanges and custodial wallet providers, when facilitating transfers between customers and other VASPs or financial institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "accounting-ifr-13",
      "basel-iii-global-regulatory-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fatf-recommendation-20-reporting-suspicious-transactions",
    "title": "The FATF Recommendations",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "The FATF Recommendations establish a comprehensive and consistent framework of measures for countries to implement in order to combat money laundering, terrorist financing, and the financing of proliferation of weapons of mass destruction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "fatf-recommendation-26-regulation-supervision-fi",
    "title": "The FATF Recommendations",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Countries must implement a comprehensive and consistent framework of measures, adapted to their particular circumstances, to combat money laundering, terrorist financing, and the financing of proliferation of weapons of mass destruction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "fatf-recommendation-3-money-laundering-offence",
    "title": "The FATF Recommendations: Recommendation 3 - Money Laundering Offence",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Countries must implement a comprehensive and consistent framework of measures to combat money laundering, terrorist financing, and proliferation financing, adapting these measures to their particular circumstances.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "fatf-recommendation-6-targeted-sanctions-terrorism",
    "title": "The FATF Recommendations - Recommendation 6: Targeted Financial Sanctions Related to Terrorism & Terrorist Financing",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Countries must implement the FATF's comprehensive and consistent framework of measures for combating terrorist financing, adapting them to their particular legal, administrative, and operational circumstances.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "fatf-risk-based-approach-banking-sector-2014",
    "title": "FATF Risk-Based Approach Guidance for the Banking Sector",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2024-10-26",
    "bluf": "This guidance requires banks to implement a risk-based approach (RBA) to anti-money laundering and counter-terrorist financing (AML/CFT), mandating the identification, assessment, and mitigation of risks. It provides specific criteria for customer risk profiling, triggers for Enhanced Due Diligence (EDD), conditions for Simplified Due Diligence (SDD), and procedures for identifying Politically Exposed Persons (PEPs) and conducting sanctions screening, in line with FATF Recommendation 1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "eu-aml-regulation-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fatf-travel-rule-v2",
    "title": "FATF Recommendation 16 (Travel Rule)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "FATF Recommendation 16, also known as the 'Travel Rule', is the global AML/CFT standard for virtual assets. It requires Virtual Asset Service Providers (VASPs) to collect and transmit originator and beneficiary information for all virtual asset transfers exceeding $1,000 to prevent money laundering and terrorist financing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-virtual-assets-vasp",
      "fatf-virtual-asset-redfl"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fatf-virtual-asset-redfl",
    "title": "FATF Virtual Asset Red Flags",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The FATF Virtual Asset Red Flag Indicators (2020) provides a report to assist financial institutions and Virtual Asset Service Providers (VASPs) in identifying potential money laundering and terrorist financing activity. it categorizes indicators into transaction patterns, anonymity, and sender/recipient behavior to enhance risk-based monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "fatf-guidance-virtual-assets-vasp",
      "fatf-travel-rule-v2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fatf-virtual-assets-travel-rule-recommendation-16",
    "title": "FATF Recommendation 16 - Travel Rule for Virtual Assets 2019 (Updated 2023): Originator and Beneficiary Information Transmission Requirement (Name/Account/Address) for Transfers over USD/EUR 1,000, VASP-to-VASP Obligations, Sunrise Issue Guidance and Technical Solutions",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "FATF Recommendation 16 requires Virtual Asset Service Providers (VASPs) to collect, verify, and transmit originator and beneficiary information for virtual asset transfers exceeding USD/EUR 1,000, including name, account number, and physical or digital address. This applies to all VASP-to-VASP transactions and is a core anti-money laundering (AML) and counter-terrorist financing (CFT) obligation under the FATF framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "bis-iosco-stablecoin-guidance-pfmi-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fatf-virtual-currencies-gaming-guidance-2019",
    "title": "FATF Guidance on Virtual Assets and Gaming 2019 - Travel Rule, Customer Due Diligence, Risk Assessment and AML/CFT Programme Requirements for Virtual Asset Service Providers and Gaming Platforms",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The FATF Guidance 2019 obliges all Virtual Asset Service Providers (VASPs) and crypto-gaming platforms to implement the Travel Rule for crypto transfers (Section 3), conduct comprehensive Customer Due Diligence (Section 4), maintain a documented risk-assessment and AML/CFT programme (Section 5), and retain transaction records for at least five years (Section 6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021",
      "eu-5amld-article-2-gambling-2018",
      "alderney-egambling-regulations-2009"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fca-ai-model-risk-financial-services-2023",
    "title": "FCA Artificial Intelligence in Financial Services - Compliance Obligations for UK Firms Using AI, AI Model Risk Governance, and Consumer Protection Requirements for AI-Driven Financial Products",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines FCA compliance obligations for UK financial firms using AI, focusing on AI model risk governance and consumer protection for AI-driven products. It aligns with EU AI Act (Regulation 2024/1689) high-risk system requirements under Articles 9 and 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fca-consumer-duty-2023",
    "title": "FCA Consumer Duty (2023)",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The FCA Consumer Duty (PS22/9) is a major U.S.-style 'fiduciary' reform for the UK retail financial sector. It introduces a new 'Consumer Principle' (Principle 12), requiring firms to act to deliver good outcomes for retail customers, setting higher and clearer standards of consumer protection across all financial services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mifid-ii-best-execution",
      "iso-10002-complaints-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fca-sysc-8-1-outsourcing-requirements",
    "title": "FCA SYSC 8.1 Outsourcing Requirements for FCA-Regulated Firms",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "FCA Handbook SYSC 8.1, implementing MiFID II Article 16(5) outsourcing requirements for investment firms and supplemented by FCA SS1/21 for non-MiFID firms, requires FCA-regulated firms that outsource critical or important operational functions to take all reasonable steps to avoid additional operational risk, retain full responsibility for all regulatory obligations, ensure service continuity, and maintain documented arrangements enabling the FCA to monitor the outsourced functions - with enhanced requirements for cloud and other technology outsourcing following FCA's 2019 outsourcing and operational resilience guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fca-ps21-3-operational-resilience-policy"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fcc-emergency-alert-system-part-11",
    "title": "Emergency Alert System (EAS) Rules Part 11",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The FCC Emergency Alert System (EAS) requires EAS participants, including broadcast stations and cable systems, to comply with specific technical standards and operational procedures, as outlined in 47 CFR Part 11, particularly § 11.1 and § 11.51, to ensure public safety during national emergencies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "3gpp-ims-ip-multimedia-subsystem-release-16",
      "eu-eecc-2018-1972-electronic-communications-code"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fcc-net-neutrality-open-internet-2024",
    "title": "FCC Open Internet Order 2024 - Restoring Net Neutrality: Broadband as Title II Telecommunications Service, No Blocking/Throttling/Paid Prioritisation, Reasonable Network Management, ISP Transparency and FCC Enforcement Authority",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The FCC Open Internet Order 2024 requires ISPs to not block, throttle, or engage in paid prioritization, as stated in Section 8 of the Order, and applies to all broadband internet service providers in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-net-neutrality-open-internet-2015-2120",
      "eu-eecc-2018-1972-electronic-communications-code"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fcc-part-64-cpni-customer-proprietary-network",
    "title": "FCC Part 64 CPNI Rules - Customer Proprietary Network Information: Opt-In/Opt-Out Consent, Account Authentication, Annual Compliance Certification, Breach Notification to FBI and Secret Service within 7 Days, Pretexting Prohibitions",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation requires telecommunications carriers to protect customer proprietary network information (CPNI) and to obtain opt-in or opt-out consent from customers for the use of their CPNI, as stated in § 64.201 and § 64.630.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fcc-robocall-mitigation-stir-shaken-2023",
    "title": "FCC Robocall Mitigation and STIR/SHAKEN Call Authentication Rules - 47 CFR Part 64, Subpart HH (TRACED Act)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "The FCC's caller ID authentication rules require voice service providers to implement the STIR/SHAKEN framework (signing calls with attestation levels A, B or C) in the IP portions of their networks and to file a certification and robocall mitigation plan in the FCC Robocall Mitigation Database. These obligations are codified in 47 CFR Part 64, Subpart HH (Caller ID Authentication), including 47 CFR 64.6301 (definitions), 64.6302 (caller ID authentication), and 64.6305 (robocall mitigation and certification), and are mandated by the TRACED Act of 2019. Note: FCC rules are codified as CFR sections, not 'Articles'; the prior 'Article 4-12' references were incorrect and have been replaced with the correct Subpart HH structure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "3gpp-5g-nr-release-17-specifications",
      "3gpp-ims-ip-multimedia-subsystem-release-16",
      "eu-eecc-2018-1972-electronic-communications-code"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fcpa-anti-bribery-compliance",
    "title": "FCPA Anti-Bribery (US)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The Foreign Corrupt Practices Act (FCPA) of 1977 is a U.S. federal law prohibiting the payment of bribes to foreign officials to assist in obtaining or retaining business. It applies to all U.S. persons, issuers, and foreign firms operating within the U.S., enforced jointly by the SEC and the Department of Justice (DOJ).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37001-anti-bribery-2016",
      "uk-bribery-act-2010",
      "oecd-guidelines-multinational-ent",
      "sarbanes-oxley-act-sox",
      "iso-37301-compliance-ms",
      "un-guiding-principles-business-hr"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fda-21-cfr-210-211-current-good-manufacturing-practice",
    "title": "Current Good Manufacturing Practice for Finished Pharmaceuticals",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation, specifically 21 CFR 211.22, requires pharmaceutical manufacturers to establish and follow written procedures for quality control, and applies to all finished pharmaceuticals, as stated in 21 CFR 210.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fda-21-cfr-part-11-records",
    "title": "FDA 21 CFR Part 11 (Records)",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "FDA 21 CFR Part 11 establishes the U.S. requirements for electronic records and electronic signatures. It defines the criteria under which the FDA considers electronic records, electronic signatures, and handwritten signatures executed to electronic records to be trustworthy, reliable, and generally equivalent to paper records.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-820-qsr",
      "iso-13485-medical-qms",
      "gxp-clinical-practice",
      "gxp-mfg-practice",
      "iec-62304-medical-software",
      "iso-14971-medical-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fda-21-cfr-part-312-ind-investigational-new-drug",
    "title": "Investigational New Drug Application: IND Content, Phases of Investigation, Safety Reporting and Annual Reports",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires sponsors of investigational new drugs to submit an Investigational New Drug Application (IND) to the FDA, as outlined in 21 CFR 312.20-312.33, and to conduct investigations in accordance with 21 CFR 312.50-312.53.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fda-21-cfr-part-314-nda-new-drug-application",
    "title": "New Drug Applications: Chemistry-Manufacturing-Controls, Clinical Data Requirements, Labelling and Post-Marketing Commitments",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires new drug applicants to submit a New Drug Application (NDA) that includes chemistry, manufacturing, and controls information, as well as clinical data, labeling, and post-marketing commitments, as outlined in 21 CFR 314.50. It applies to any person who intends to market a new drug in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fda-21-cfr-part-600-601-biologics-licensing",
    "title": "Biological Products: General; and Licensing",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The FDA 21 CFR Parts 600-601 regulation requires manufacturers of biological products to submit a Biologics License Application (BLA) and comply with lot release testing and approval standards, as outlined in Section 600.3 and 601.2. This regulation applies to all establishments engaged in the manufacture, preparation, propagation, compounding, or processing of biological products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "fda-21-cfr-part-820-qsr",
    "title": "FDA 21 CFR Part 820 (QSR)",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "FDA 21 CFR Part 820 is the Quality System Regulation (QSR) governing the manufacture and design of medical devices in the United States. It requires medical device manufacturers to establish a quality system to ensure that their products consistently meet applicable requirements and specifications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-11-records",
      "gxp-mfg-practice",
      "iec-62304-medical-software",
      "iso-13485-medical-qms",
      "iso-14971-medical-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fda-21cfr-part11-2026",
    "title": "FDA 21 CFR Part 11 - Electronic Records and Electronic Signatures",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "21 CFR Part 11 establishes criteria under which the FDA considers electronic records, electronic signatures, and handwritten signatures executed to electronic records to be trustworthy, reliable, and equivalent to paper records. It applies to all FDA-regulated activities including clinical trials, manufacturing, and laboratory records.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "fda-21st-century-cures-act-digital-health-provisions",
    "title": "21st Century Cures Act",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The 21st Century Cures Act, Section 3060, requires the FDA to prioritize the review of certain medical devices, including Software as a Medical Device (SaMD), and to establish a process for the regulation of interoperable medical devices. This regulation applies to manufacturers of medical devices, including SaMD.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fda-adaptive-clinical-trial-design-guidance-2019",
    "title": "Adaptive Designs for Clinical Trials of Drugs and Biologics Guidance for Industry",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This guidance provides recommendations for the use of adaptive designs in clinical trials, as outlined in Section III: Pre-Specified Adaptations, and applies to sponsors of clinical trials for drugs and biologics, as stated in Section I: Introduction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "fda-ai-ml-samd-action-plan",
    "title": "Artificial Intelligence/Machine Learning (AI/ML)-Based Software as a Medical Device (SaMD) Action Plan",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2021-01-31",
    "bluf": "This Action Plan outlines the U.S. Food and Drug Administration's (FDA) multi-pronged approach to advance its oversight of Artificial Intelligence/Machine Learning (AI/ML)-Based Software as a Medical Device (SaMD). Developed in response to stakeholder feedback on a 2019 discussion paper, the plan applies to medical device manufacturers utilizing AI/ML technologies. Its core objective is to establish a total product lifecycle-based regulatory oversight framework that allows SaMD to learn from real-world use and improve its performance while ensuring safety and effectiveness. A central component of this framework is the \"Predetermined Change Control Plan\" to be included in premarket submissions.\n\nThis plan consists of two key elements: the \"SaMD Pre-Specifications\" (SPS), which describe the anticipated modifications, and the \"Algorithm Change Protocol\" (ACP), which details the methodology for implementing changes in a controlled manner that manages patient risks. The document details a five-part action plan: (1) issuing a Draft Guidance on the Predetermined Change Control Plan; (2) encouraging the harmonization of Good Machine Learning Practice (GMLP); (3) promoting a patient-centered approach that incorporates transparency to users through device labeling; (4) supporting regulatory science to develop methods for addressing algorithm bias and robustness; and (5) advancing real-world performance monitoring through pilot programs with stakeholders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-820-qsr",
      "good-machine-learning-practice-medical-devices",
      "imdrf-samd-risk-framework",
      "iso-13485-medical-qms",
      "iso-14971-medical-risk",
      "iec-62304-medical-software"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "fda-aiml-samd-action-plan",
    "title": "Artificial Intelligence/Machine Learning (AI/ML)-Based Software as a Medical Device (SaMD) Action Plan",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2021-01-31",
    "bluf": "This Action Plan from the U.S. Food & Drug Administration (FDA) outlines a five-part strategy to regulate Artificial Intelligence/Machine Learning (AI/ML)-Based Software as a Medical Device (SaMD). Developed in response to stakeholder feedback on a 2019 discussion paper, the plan aims to ensure that AI/ML-based SaMD is safe and effective while supporting innovation. The core of the proposed framework is a \"Predetermined Change Control Plan\" submitted by manufacturers, which includes the \"SaMD Pre-Specifications\" (SPS) detailing anticipated modifications and an \"Algorithm Change Protocol\" (ACP) explaining how changes will be implemented and validated. The plan applies to medical device manufacturers utilizing AI/ML technologies in SaMD. The five key actions are: 1) updating the regulatory framework, including issuing draft guidance on the Predetermined Change Control Plan; 2) encouraging the harmonization of Good Machine Learning Practices (GMLP); 3) promoting a patient-centered approach that incorporates transparency for users; 4) supporting regulatory science to address algorithm bias and robustness; and 5) advancing Real-World Performance (RWP) monitoring through pilot programs. This approach is intended to provide a total product lifecycle-based regulatory oversight, enabling the FDA to monitor software from premarket development through postmarket performance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "good-machine-learning-practice-medical-devices",
      "imdrf-samd-risk-framework",
      "fda-21-cfr-part-820-qsr",
      "iso-14971-medical-risk",
      "iec-62304-medical-software",
      "fda-clinical-decision-support"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fda-biosimilar-pathway-351k-biologics-competition-act",
    "title": "Biologics Price Competition and Innovation Act of 2009",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The FDA 351(k) biosimilar pathway requires that an applicant demonstrate biosimilarity to a reference product, as outlined in Section 351(k) of the Public Health Service Act. This applies to manufacturers of biosimilar products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "fda-breakthrough-devices-program-2026",
    "title": "FDA Breakthrough Devices Program - Expedited Pathways & Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The FDA Breakthrough Devices Program provides expedited development, assessment, and review for devices that provide more effective treatment or diagnosis of life-threatening or irreversibly debilitating diseases. Benefits include priority review, interactive communication, and senior management engagement. Devices must still meet applicable safety and effectiveness standards with robust clinical evidence and post-market commitments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "fda-breakthrough-therapy-designation-guidance-2018",
    "title": "Guidance for Industry: Breakthrough Therapies",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The FDA Breakthrough Therapy Designation Guidance 2018 requires sponsors to submit a breakthrough therapy designation request, as outlined in Section 506(a) of the Federal Food, Drug, and Cosmetic Act, and provides intensive guidance on the designation process, including the criteria for eligibility and the process for rolling review and cross-disciplinary collaboration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-312-ind-investigational-new-drug",
      "ich-gcp-e6-r3-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fda-cds-software-2026",
    "title": "FDA Clinical Decision Support (CDS) Software Guidance Update - January 2026 Final",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The FDA issued the final Clinical Decision Support Software guidance in January 2026, refining the 21st Century Cures Act criteria for when CDS functions are excluded from the definition of a medical device. Key updates include expanded enforcement discretion for single clinically appropriate recommendations, strengthened transparency requirements, and clarification on automation bias risks. This directly affects AI-driven diagnostic aids, treatment recommendation tools, and population health software. Non-device CDS must still meet four criteria: intended for HCPs, not for time-critical diagnosis/treatment in certain cases, and transparent sourcing. Organisations deploying CDS in the US must conduct risk assessments, implement human oversight, and maintain documentation for potential FDA review. The guidance aligns with broader digital health policy including SaMD and cybersecurity expectations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "fda-clinical-decision-support",
    "title": "FDA Clinical Decision Software",
    "domain": "Medical & Healthcare",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The FDA Guidance on Clinical Decision Support (CDS) Software (2022) provides the criteria under which software functions are NOT considered medical devices under Section 520(o)(1)(E) of the FD&C Act. It focus on ensuring that the healthcare professional (HCP) can independently review the basis for the software's recommendations to ensure patient safety.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-820-qsr",
      "fda-ai-ml-samd-action-plan",
      "good-machine-learning-practice-medical-devices",
      "iec-62304-medical-software",
      "imdrf-samd-risk-framework",
      "iso-14971-medical-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fda-cybersecurity-for-medical-devices-compliance-2026-12",
    "title": "FDA Cybersecurity for Medical Devices Enterprise Compliance Standard v12",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The FDA Cybersecurity for Medical Devices guidelines require manufacturers to implement a comprehensive cybersecurity risk management program throughout the device lifecycle. This includes identifying and mitigating risks associated with device vulnerabilities, ensuring secure software updates, and maintaining robust data protection measures. Manufacturers must provide a detailed cybersecurity plan during premarket submissions, including threat modeling and post-market surveillance strategies. Additionally, they are required to establish a process for reporting cybersecurity incidents and vulnerabilities to the FDA. Compliance with these guidelines is essential to safeguard patient safety and maintain the integrity of medical devices in a rapidly evolving digital landscape.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "fda-cybersecurity-medical-devices-524b-2026",
    "title": "FDA Section 524B - Cybersecurity in Medical Devices (2026 Enforcement)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Section 524B of the FD&C Act requires manufacturers of cyber devices to design, develop, and maintain processes to ensure cybersecurity throughout the device lifecycle. Key obligations include cybersecurity risk management in the QMS, Software Bill of Materials (SBOM), vulnerability disclosure plans, coordinated disclosure, and postmarket cybersecurity management. Applies to all devices with software or connectivity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "fda-cybersecurity-medical-devices-premarket",
    "title": "Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-02-03",
    "bluf": "With the increasing integration of wireless, Internet- and network-connected capabilities, the need for robust cybersecurity controls to ensure medical device safety and effectiveness has become more important. Cybersecurity threats to the healthcare sector have become more frequent and severe, with incidents rendering medical devices and hospital networks inoperable. This guidance applies to devices with cybersecurity considerations, including those with software or programmable logic, across various premarket submission types such as 510(k), PMA, DeNovo, IDE, and HDE. It outlines the Food and Drug Administration's (FDA) recommendations for the cybersecurity information to be submitted to demonstrate a reasonable assurance of safety and effectiveness.\n\nThe guidance emphasizes that cybersecurity is a shared responsibility and a key part of device safety and the Quality Management System Regulation (QMSR). It encourages manufacturers to adopt a Secure Product Development Framework (SPDF) to manage cybersecurity risks throughout the total product lifecycle (TPLC). For devices that meet the definition of a 'cyber device' under section 524B of the FD&C Act, sponsors are required to submit specific information. This includes a plan to monitor, identify, and address postmarket cybersecurity vulnerabilities; processes to provide reasonable assurance of device cybersecurity; and a Software Bill of Materials (SBOM) for all software components.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-820-qsr",
      "iso-13485-medical-qms",
      "iso-14971-medical-risk",
      "iec-62304-medical-software",
      "hipaa-security-rule"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fda-de-novo-classification-2026",
    "title": "FDA De Novo Classification Process for Novel Medical Devices (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The FDA De Novo classification process provides a pathway to classify novel medical devices for which there is no legally marketed predicate device, but whose risk profile is low to moderate (Class I or II). Successful De Novo requests establish a new classification regulation and permit the device to serve as a predicate for future 510(k) submissions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "fda-electronic-source-data",
    "title": "Guidance for Industry Electronic Source Data in Clinical Investigations",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2013-09-30",
    "bluf": "This guidance provides recommendations to sponsors, Contract Research Organizations (CROs), clinical investigators, and others involved in the capture, review, and retention of electronic source data in FDA-regulated clinical investigations. To streamline and modernize clinical investigations, the guidance promotes capturing source data in electronic form, intending to assist in ensuring the reliability, quality, integrity, and traceability of data from the electronic source to electronic regulatory submission. The core recommendations address the identification and specification of authorized source data originators; the creation of data element identifiers to facilitate audit trail examination; methods to capture source data into an electronic case report form (eCRF) either manually or electronically; and the responsibilities of clinical investigators regarding the review, signature, and retention of electronic data. The guidance emphasizes that source data must be attributable, legible, contemporaneous, original, and accurate (ALCOA) and meet all regulatory requirements for recordkeeping. It is intended to be used in conjunction with other FDA guidance on computerized systems and regulations on electronic records and signatures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-11-records"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fda-ema-ai-pv-2026",
    "title": "FDA-EMA-CIOMS AI in Pharmacovigilance Principles 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "Joint principles and CIOMS WG XIV guidance emphasize human oversight, bias mitigation, and validation of AI for signal detection and adverse event processing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "fda-food-labeling-guide",
    "title": "Guidance for Industry A Food Labeling Guide",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-12",
    "bluf": "This guidance is a summary of the required statements that must appear on food labels under the Federal Food, Drug, and Cosmetic Act (FD&C Act) and the Fair Packaging and Labeling Act. The Food and Drug Administration (FDA) is responsible for assuring that foods sold in the United States, whether produced domestically or imported, are safe, wholesome, and properly labeled. This guidance applies to manufacturers, distributors, and importers of food products and uses a question-and-answer format to address the most frequently raised labeling questions. It is the responsibility of the food industry to remain current with all legal requirements for food labeling.\n\nThe core obligations detailed include the placement of required statements on either the Principal Display Panel (PDP) or the information panel. Mandatory statements include the statement of identity (name of the food), the net quantity of contents, the name and address of the manufacturer, packer, or distributor, a complete ingredient list in descending order of predominance, and nutrition labeling as required by the Nutrition Labeling and Education Act (NLEA). Additionally, the Food Allergen Labeling and Consumer Protection Act (FALCPA) requires specific labeling for the eight major food allergens.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-gen",
      "fda-fsma-compliance",
      "food-allergen-label-law",
      "iso-22000-food-mgt",
      "haccp-food-safety",
      "gfsi-benchmarking"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fda-fsma-compliance",
    "title": "FDA Food Safety Modernization",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the FDA Food Safety Modernization Act is established through the implementation of several key regulatory programs. A compliant Hazard Analysis and Risk-Based Preventive Controls food safety plan is operational under the authority of 21 CFR Part 117, developed and managed by a certified Preventive Controls Qualified Individual, with current staffing at one such expert. This framework mandates active allergen cross-contact controls, requisite environmental monitoring, and annually completed cGMP training. For import operations, an active Foreign Supplier Verification Program ensures supplier compliance pursuant to 21 CFR Part 1, Subpart L. Protection against intentional adulteration is addressed through a functioning food defense plan, consistent with the mitigation strategies required by 21 CFR Part 121. The operation demonstrates advanced traceability preparedness under FSMA Section 204, capable of providing critical tracking event records within a twenty-four-hour maximum response window. Logistics protocols adhere to the Sanitary Transportation of Human and Animal Food rule, with transport logs retained for a minimum of twelve months as stipulated by 21 CFR Part 1, Subpart O. Where applicable, agricultural practices align with standards in 21 CFR Part 112, including a mandated agricultural water testing frequency of every thirty days. All programs are supported by a documented and tested recall plan, and all requisite records are preserved for a minimum of two years to ensure comprehensive regulatory oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "haccp-food-safety",
      "iso-22000-food-mgt",
      "codex-alimentarius-gen",
      "gfsi-benchmarking",
      "food-allergen-label-law",
      "fda-food-labeling-guide"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fda-guidance-human-gene-therapy-2020",
    "title": "Guidance for Human Gene Therapy Investigational New Drug Applications (INDs): CMC, Preclinical, and Clinical Considerations",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This FDA guidance outlines chemistry, manufacturing, and controls (CMC), preclinical, and clinical requirements for gene therapy INDs under 21 CFR Part 312. It applies to sponsors developing human gene therapy products and mandates detailed characterization, safety testing, and long-term follow-up per Section III-V of the guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-312-ind-investigational-new-drug",
      "ich-gcp-e6-r3-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fda-guidance-process-validation-lifecycle-approach-2011",
    "title": "FDA Process Validation Guidance - Lifecycle Approach 2011",
    "domain": "Biotech & Genomics",
    "version": "2011-01",
    "last_updated": "2026-05-09",
    "bluf": "FDA's 2011 Process Validation guidance establishes a lifecycle approach in three stages - process design, process qualification, and continued process verification - requiring manufacturers to collect and evaluate data to ensure a process consistently produces product meeting specifications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ema-centralised-procedure-regulation-726-2004",
      "ich-q10-pharmaceutical-quality-system-2008"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fda-pdufa-vii-goals-letter-2022",
    "title": "FDA PDUFA VII Performance Goals and Procedures 2023-2027",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The FDA PDUFA VII requires prescription drug manufacturers to meet specific performance goals and procedures for the review of new drug applications, as outlined in Section 735(1) of the Federal Food, Drug, and Cosmetic Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fda-predetermined-change-control-2024",
    "title": "Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence/Machine Learning (AI/ML)-Enabled Device Software Functions",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-04-16",
    "bluf": "This FDA guidance enables manufacturers of AI/ML-based medical devices to pre-authorize a set of planned modifications within a Predetermined Change Control Plan (PCCP) as part of a premarket submission (510(k), De Novo, PMA), allowing for device evolution without requiring a new submission for each change covered by the approved plan.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-820-qsr",
      "iso-13485-medical-qms",
      "iso-14971-medical-risk",
      "iec-62304-medical-software",
      "good-machine-learning-practice-medical-devices"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fda-real-world-evidence-program",
    "title": "FRAMEWORK FOR FDA’S REAL WORLD EVIDENCE PROGRAM",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2018-12-31",
    "bluf": "Pursuant to the 21st Century Cures Act, which added section 505F to the Federal Food, Drug, and Cosmetic Act (FD&C Act), the Food and Drug Administration (FDA) has created a framework for evaluating the potential use of real-world evidence (RWE). This framework is designed to help support the approval of a new indication for a drug already approved under section 505(c) of the FD&C Act, or to help support or satisfy drug postapproval study requirements. The framework applies to drugs and biological products but does not cover medical devices. Real-World Data (RWD) are defined as data relating to patient health status and/or the delivery of health care routinely collected from a variety of sources, such as electronic health records (EHRs) and medical claims. RWE is the clinical evidence about the usage and potential benefits or risks of a medical product derived from analysis of RWD.\n\nThe core of the FDA's evaluation approach under this framework consists of a three-part assessment for any RWE submission. The considerations are: 1. Whether the RWD are fit for use, which involves assessing data reliability (data accrual and data assurance) and relevance. 2. Whether the trial or study design used to generate RWE can provide adequate scientific evidence to answer the regulatory question. 3. Whether the study conduct meets FDA regulatory requirements, such as for study monitoring and data collection. The FDA's RWE Program is multifaceted, involving demonstration projects, stakeholder engagement, internal processes for senior leadership input, and the development of guidance documents to assist developers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-11-records",
      "fda-electronic-source-data",
      "gxp-clinical-practice",
      "hipaa-security-rule",
      "hl7-fhir-v4-interop"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fda-real-world-evidence-program-guidance-2018",
    "title": "Framework for Real-World Evidence Program Guidance 2018",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The FDA Real-World Evidence Program Guidance 2018 requires sponsors to submit real-world evidence (RWE) studies that meet specific standards for data sources, study design, and fit-for-purpose, as outlined in Section II of the guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fda-samd-action-plan-2022",
    "title": "FDA Software as a Medical Device (SaMD) Action Plan and AI/ML-Based SaMD Guidance 2022 - Predetermined Change Control Plan (PCCP) and Algorithmic Transparency Requirements",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This guidance establishes principles for the regulation of Software as a Medical Device (SaMD), including risk categorization, quality management, and clinical evaluation, as developed by the International Medical Device Regulators Forum (IMDRF) with leadership from the FDA. It applies to standalone software intended for medical purposes without being part of a hardware medical device, as defined by the IMDRF and referenced in FDA policy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-qms",
      "eu-ai-act-2024",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fda-samd-premarket-review-2026",
    "title": "FDA Software as a Medical Device (SaMD) Premarket Review Framework (2026 Update)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The FDA regulates Software as a Medical Device (SaMD), including AI/ML-enabled software, using a risk-based approach for premarket submissions (510(k), De Novo, or PMA). Manufacturers must provide comprehensive documentation on software design, risk management, clinical evaluation, cybersecurity per Section 524B and the February 2026 guidance, Software Bill of Materials (SBOM), and lifecycle processes under the QMSR (21 CFR Part 820, aligned with ISO 13485). Higher-risk SaMD requires enhanced evidence where failure could cause serious harm or death.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "fda-samd-risk",
    "title": "FDA Software as a Medical Device (SaMD) Risk Matrix",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "A risk-based framework for classifying software intended for medical purposes independently of hardware, based on IMDRF categorizations and FDA safety standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imdrf-samd-risk-framework",
      "fda-21-cfr-part-820-qsr",
      "iso-14971-medical-risk",
      "iec-62304-medical-software",
      "fda-ai-ml-samd-action-plan",
      "hl7-fhir-interop"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fda-software-as-medical-device-2019",
    "title": "Proposed Regulatory Framework for Modifications to Artificial Intelligence/Machine Learning (AI/ML)-Based Software as a Medical Device (SaMD)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This FDA discussion paper outlines a Total Product Lifecycle (TPLC) approach for AI/ML-based medical software, proposing a Predetermined Change Control Plan (PCCP) that allows manufacturers to manage algorithm modifications without requiring a new premarket submission for every change, provided the changes stay within the approved plan's scope. This framework applies to manufacturers of AI/ML-based Software as a Medical Device (SaMD) seeking to leverage adaptive algorithms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-820-qsr",
      "iso-13485-medical-qms",
      "iso-14971-medical-risk",
      "iec-62304-medical-software",
      "good-machine-learning-practice-medical-devices"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fdic-part-370-recordkeep",
    "title": "FDIC Part 370 (Records)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "FDIC Part 370 (Recordkeeping for Timely Deposit Insurance Determination) is a critical compliance standard for large U.S. banks (over 2 million deposit accounts). it requires institutions to maintain the account records in a specific format that allows the FDIC determine the insurance the amount for the account holder within 24 hours of a failure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "bcbs-principles-sound-management-operational-risk",
      "fsb-key-attributes-res",
      "iso-22301-biz-continuity",
      "nist-sp-800-34-contingency-planning-guide",
      "principles-effective-risk-data-aggregation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fedramp-authorization",
    "title": "FedRAMP - US Federal Cloud Authorization",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Federal Risk and Authorization Management Program (FedRAMP), established by OMB Memorandum M-11-33 (June 2011) and codified into law by the FedRAMP Authorization Act (December 2022, part of NDAA FY2023), is the US federal government's standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. All cloud services (IaaS, PaaS, SaaS) used by federal agencies must be FedRAMP authorized. FedRAMP defines three impact levels based on FIPS 199 categorization: Low (125 controls), Moderate (325 controls, most common - covers 80%+ of federal use cases), and High (421 controls, for sensitive unclassified data including law enforcement, financial, and health data). Two authorization paths: (1) Agency ATO (Authority to Operate) - a federal agency sponsors and issues an ATO, usable government-wide; (2) JAB (Joint Authorization Board) P-ATO - reviewed by GSA, DoD, and DHS CIOs, highest prestige. Third-Party Assessment Organizations (3PAOs) - accredited by the American Association for Laboratory Accreditation (A2LA) - conduct independent assessments. FedRAMP Rev 5 baselines (aligned to NIST SP 800-53 Rev 5) released January 2024. Continuous monitoring: monthly vulnerability scanning, annual penetration testing, and significant change reporting are mandatory post-authorization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fedramp-moderate-baseline",
    "title": "FedRAMP Moderate (NIST)",
    "domain": "Cloud & SaaS",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Adherence to the FedRAMP Moderate authorization baseline ensures cloud service offerings meet the stringent security and privacy controls defined in NIST Special Publication 800-53, Revision 5, for protecting controlled unclassified information. This compliance framework mandates the implementation of FIPS PUB 140-3 validated cryptographic modules, requiring all data in transit plus data at rest to be encrypted. System access controls are rigorously enforced; multi-factor authentication is mandatory for network access, and user sessions will automatically terminate following a 15-minute idle timeout period. Consistent with FedRAMP Vulnerability Scanning Requirements, systems must undergo comprehensive vulnerability scans at a minimum frequency of every 30 days. The remediation timeline for identified vulnerabilities is strict: high-risk findings must be resolved within 30 days, whereas moderate-risk findings are allotted 90 days. Incident response protocols demand immediate action, with a reporting window of just one hour from detection. Furthermore, a robust continuous monitoring program, guided by the Continuous Monitoring Strategy Guide and OMB Circular A-130's principles for managing information resources, must be maintained. This includes the retention of audit logs for a full 365 days and the submission of updated Plan of Action and Milestones (POAM) documentation at least every 30 days, coinciding with continuous monitoring reporting cycles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-53b-control-baselines",
      "fips-140-3-cryptographic-modules",
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ferc-order-1000-transmission-planning",
    "title": "Transmission Planning and Cost Allocation by Transmission Owning and Operating Public Utilities",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This order requires public utility transmission providers to participate in regional transmission planning processes that consider transmission needs driven by public policy requirements and evaluate potential solutions on a comparable basis. It also mandates a cost allocation method for new transmission facilities and removes the federal right of first refusal (ROFR) for certain transmission projects to encourage competition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ferc-order-2222-distributed-energy-resources-2020",
    "title": "Participation of Distributed Energy Resource Aggregations in Markets Operated by Regional Transmission Organizations and Independent System Operators",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "FERC Order No. 2222 requires Regional Transmission Organizations (RTOs) and Independent System Operators (ISOs) to revise their tariffs to establish Distributed Energy Resource (DER) aggregators as a type of market participant, thereby removing barriers to their participation in wholesale capacity, energy, and ancillary service markets. This rule, under section 206 of the Federal Power Act, mandates that RTOs/ISOs ensure their market rules are just, reasonable, and not unduly discriminatory or preferential towards DERs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "ferc-order-841-electric-storage-participation",
    "title": "Electric Storage Participation in Markets Operated by Regional Transmission Organizations and Independent System Operators",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This order requires each Regional Transmission Organization (RTO) and Independent System Operator (ISO) to revise its tariff to establish a participation model for Electric Storage Resources (ESRs) in wholesale energy, capacity, and ancillary service markets, ensuring they can participate on a comparable basis to other resources as mandated by 18 C.F.R. § 35.28(g)(9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ferc-order-881-transmission-line-ratings-2021",
    "title": "Managing Transmission Line Ratings: Ambient-Adjusted Ratings, Transmission Owner Obligations and OASIS Posting Requirements",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-12-03",
    "bluf": "This final rule requires public utility transmission providers to implement Ambient-Adjusted Ratings (AAR) for near-term transmission service to improve the accuracy and transparency of transmission line ratings. As mandated in 18 C.F.R. § 35.28(g)(16), providers must use AARs for scheduling transmission service expected to be completed within 10 days and also establish and use seasonal and emergency ratings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "ferc-order-887-internal-network-security-monitoring",
    "title": "FERC Order No. 887: Reliability Standard CIP-007-7, Internal Network Security Monitoring for High and Medium Impact BES Cyber Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This order directs the North American Electric Reliability Corporation (NERC) to implement Reliability Standard CIP-007-7, which mandates Internal Network Security Monitoring (INSM) for all high and medium impact Bulk Electric System (BES) Cyber Systems to detect and respond to anomalous network activity, including unauthorized lateral movement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-53-au2",
      "nist-800-53-sc7",
      "cis-controls-v8",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ffiec-business-continuity-management-booklet-2019",
    "title": "FFIEC Business Continuity Management Booklet 2019",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The FFIEC Business Continuity Management (BCM) Booklet, updated November 2019, provides comprehensive guidance for financial institutions on managing business continuity risk across the full BCM lifecycle - business impact analysis, risk assessment, strategy development, plan development, training and testing, and program maintenance - with heightened expectations for technology service providers, third-party dependencies, and cyber-event recovery scenarios, replacing the 2008 Business Continuity Planning Booklet.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "occ-bulletin-2023-17-third-party-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ffiec-it-handbook-audit-information-systems",
    "title": "FFIEC IT Examination Handbook Audit Booklet Information Systems Audit",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The FFIEC IT Examination Handbook Audit Booklet establishes supervisory expectations for financial institution IT audit programs, requiring risk-based audit scoping, independence from audited functions, qualified staffing, documented working papers, timely reporting to the audit committee, and systematic follow-up on audit findings to ensure IT risks are identified and managed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "frb-sr-11-7-model-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fi-tietosuojalaki-2018",
    "title": "Finland Data Protection Act 2018 (Tietosuojalaki, Act No. 1050/2018) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Finland's Data Protection Act (Tietosuojalaki, Act No. 1050/2018 of 5 December 2018), published in the Finnish Statutes (Suomen Säädöskokoelma) and entering into force on 1 January 2019, is Finland's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Finland. The GDPR is directly applicable Finnish law by virtue of Finland's EU membership. The Tietosuojalaki provides national derogations, additions, and specifications that the GDPR permits EU member states to adopt and repeals the prior Personal Data Act (Henkilötietolaki, Act No. 523/1999). Finland has a distinctive legal tradition of openness and transparency - the Act on the Openness of Government Activities (Julkisuuslaki, Act No. 621/1999) is a constitutionally underpinned principle ensuring public access to governmental documents and information, which interacts with GDPR in the Finnish public sector context. The Finnish Constitution (Perustuslaki, Act No. 731/1999) protects the right to privacy in its fundamental rights chapter. Enforcement: Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman - TDPO) is Finland's independent data protection supervisory authority. The Data Protection Ombudsman (Tietosuojavaltuutettu) is supported by a collegial body (the Data Protection Board, Tietosuojalautakunta) for certain decisions. The TDPO is Finland's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Finnish national provisions: (1) Age of digital consent: Finland has set the age of consent for information society services at 13 years (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 13 require parental or guardian consent; (2) Openness and transparency - the Julkisuuslaki creates strong public access rights to official documents that interact with GDPR; personal data in official documents is subject to both the GDPR right of access and the Julkisuuslaki regime; (3) Employment context - Finnish labour law, particularly the Act on the Protection of Privacy in Working Life (Laki yksityisyyden suojasta työelämässä, Act No. 759/2004 - Working Life Privacy Act), provides specific rules on employee data processing, workplace monitoring, and drug testing that apply alongside the Tietosuojalaki and GDPR; (4) Health and social data - specific provisions on processing health data in Finnish healthcare (kunta, hyvinvointialue - wellbeing services county) and social services contexts under the Act on the Electronic Processing of Client Data in Social and Health Care (Act No. 159/2007, as amended); (5) Journalistic and research processing - exemptions for journalistic, literary, artistic, and research processing aligned with GDPR Arts. 85 and 89; (6) Criminal data - restrictions on private entity processing of criminal conviction data. Fines: GDPR administrative fines apply in Finland - up to EUR 20 million or 4% of global annual turnover. The TDPO has issued enforcement decisions and administrative fines across multiple sectors including healthcare, employment, and digital services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fidic-gold-book-dbo-2008",
    "title": "Conditions of Contract for Design, Build and Operate Projects (DBO Contract), 1st Edition 2008",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The FIDIC Gold Book establishes a contractual framework for long-term Design-Build-Operate (DBO) projects, requiring the Contractor to meet specified Operation Service Requirements and Performance Guarantees throughout a defined operational period. It grants the Employer significant 'step-in' rights under Clause 15.6 to take over operations in the event of serious Contractor default.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-31000-risk-mgt-std",
      "iso-14001-ems"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fidic-rainbow-suite-2017-contracts",
    "title": "FIDIC 2017 Rainbow Suite - Red, Yellow and Silver Book Contract Obligations, Risk Allocation and Dispute Resolution",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The FIDIC 2017 Rainbow Suite provides standardized international construction contract forms (Red, Yellow, Silver Books) that define party obligations, allocate project risks, and mandate a multi-tiered dispute resolution process, requiring the appointment of a standing Dispute Avoidance/Adjudication Board (DAAB) as the first formal tier for all disputes under Clause 21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37001-anti-bribery",
      "icc-arbitration-rules-2021",
      "pmbok-7-guide-pm"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "finance-tax-logic",
    "title": "Cross-Border VAT/GST Calculation Logic",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Cross-border VAT/GST calculation logic for services and intangibles operates strictly under the destination principle for business-to-consumer (B2C) supplies, aligning with Chapter 3 of the OECD International VAT/GST Guidelines and mirrored in national legislation such as Australia's Tax and Superannuation Laws Amendment from 2016 and Singapore's Goods and Services Tax (Amendment) Act 2018. The place of supply determination for these B2C transactions hinges on robust customer location verification. Pursuant to frameworks like EU Council Implementing Regulation No 1042/2013, the system mandates collection of a minimum of two non-contradictory pieces of location evidence; transactions are automatically blocked if conflicting location data is presented. For auditability, both customer IP and billing addresses are stored. Within the European Union, a specific €10,000 annual turnover threshold exists for micro-businesses, below which B2C supplies may remain subject to home country VAT rules. For business-to-business (B2B) transactions, the system enforces the reverse charge mechanism as stipulated by regulations like the EU VAT Directive 2006/112/EC and Section 7A of the UK Value Added Tax Act 1994. This requires mandatory real-time validation of customer VAT numbers through systems like VIES, which the platform will attempt up to a maximum of three retries before failure. The logic disallows any exemptions for digital services, and should a conclusive tax jurisdiction not be determined, a default tax rate fallback of zero percent is applied to prevent erroneous charges.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-pillar2-minimum"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fincen-cdd-beneficial-ownership-rule-2016",
    "title": "FinCEN Customer Due Diligence (CDD) Final Rule 2016 - Beneficial Ownership Identification, Verification Procedures and 25% Ownership Threshold for Legal Entity Customers",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The CDD Final Rule requires covered financial institutions to identify and verify the identity of beneficial owners of legal entity customers who own 25 percent or more of the entity or who control the entity, as part of customer due diligence under Bank Secrecy Act regulations. This applies to banks, mutual funds, brokers or dealers in securities, futures commission merchants, and introducing brokers in commodities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "bahrain-cbb-rulebook-aml-cft-module"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fincen-cvc-business-models",
    "title": "Application of FinCEN’s Regulations to Certain Business Models Involving Convertible Virtual Currencies",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2019-05-09",
    "bluf": "The Financial Crimes Enforcement Network (FinCEN) is issuing this interpretive guidance to remind persons subject to the Bank Secrecy Act (BSA) how FinCEN regulations relating to money services businesses (MSBs) apply to certain business models involving money transmission denominated in value that substitutes for currency, specifically, convertible virtual currencies (CVCs). This guidance does not establish any new regulatory expectations or requirements; rather, it consolidates current FinCEN regulations and related administrative rulings and guidance issued since 2011, applying these rules to common business models involving CVC. The guidance clarifies that whether a person is a money transmitter is a matter of facts and circumstances, not labels. Exchangers and administrators of CVC generally qualify as money transmitters under the BSA, while users who obtain CVC to purchase goods or services on their own behalf do not. The core obligations for applicable persons include registering with FinCEN as an MSB within 180 days of engaging in money transmission and developing, implementing, and maintaining an effective written anti-money laundering (AML) program that is reasonably designed to prevent the MSB from being used to facilitate money laundering and the financing of terrorist activities. This program must be risk-based, approved by senior leadership, and include policies, a designated compliance officer, training, and independent review.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bank-secrecy-act-suspicious",
      "crypto-aml-travel-rule",
      "fatf-guidance-virtual-assets-vasp",
      "fatf-travel-rule-v2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "finland-space-activities-act-2018",
    "title": "Finland Space Activities Act 2018 (Laki avaruustoiminnasta 273/2018) - Finnish National Space Regulatory Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Finland's Act on Space Activities (Laki avaruustoiminnasta, 273/2018) entered into force on 17 April 2018 and applies to space activities conducted by Finnish legal persons or from Finnish territory. The Act requires a permit from the Ministry of Economic Affairs and Employment (TEM / Työ- ja elinkeinoministeriö) for all qualifying space activities and implements Finland's obligations under the five UN space treaties. Finland is home to a growing commercial space sector, operates the EISCAT Svalbard Radar (part of the incoherent scatter radar network for space weather monitoring), and hosts Arctic satellite ground stations. The Finnish Transport and Communications Agency (Traficom) coordinates spectrum and ITU matters for Finnish satellite operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "esa_convention_1975",
        "copuos_lts_guidelines"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "finra-2111-suitability",
    "title": "FINRA Rule 2111 (Suitability)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-07-18",
    "bluf": "FINRA Rule 2111 (Suitability) is a rule of the Financial Industry Regulatory Authority (FINRA), the self-regulatory organization for U.S. broker-dealers overseen by the U.S. Securities and Exchange Commission. A member or an associated person must have a reasonable basis to believe that a recommended transaction or investment strategy involving a security or securities is suitable for the customer, based on the information obtained through the reasonable diligence of the member or associated person to ascertain the customer's investment profile. This node operationalises each obligation of FINRA Rule 2111 into a deterministic verification workflow, with every obligation quoted verbatim from and traceable to the rule text at https://www.finra.org/rules-guidance/rulebooks/finra-rules/2111 (most recently amended by SR-FINRA-2020-007 effective June 30, 2020).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sec-regulation-best-interest",
      "finra-3110-supervision",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "finra-3110-supervision",
    "title": "FINRA Rule 3110 (Supervision)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "FINRA Rule 3110 is the foundational U.S. standard for the supervision of the registered representatives and the offices of broker-dealers. it requires firms to establish and maintain a system of the supervisory procedures (WSPs) to ensure the compliance with the applicable securities laws and the FINRA rules, with a specific focus on the regular inspection and the oversight of the 'Offices of Supervisory Jurisdiction' (OSJ).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sec-regulation-best-interest",
      "sec-regulation-s-p-safeguarding",
      "bank-secrecy-act-suspicious",
      "fcpa-anti-bribery-compliance",
      "iso-37301-compliance-mgt",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "finra-3120-supervisory-control-system",
    "title": "FINRA Rule 3120 (Supervisory Control System)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-07-18",
    "bluf": "FINRA Rule 3120 (Supervisory Control System) is a rule of the Financial Industry Regulatory Authority (FINRA), the self-regulatory organization for U.S. broker-dealers overseen by the U.S. Securities and Exchange Commission. Each member shall designate and specifically identify to FINRA one or more principals who shall establish, maintain, and enforce a system of supervisory control policies and procedures that: test and verify that the member's supervisory procedures are reasonably designed to achieve compliance with applicable securities laws and regulations and FINRA rules, and create additional or amend supervisory procedures where the need is identified by such testing and verification. This node operationalises each obligation of FINRA Rule 3120 into a deterministic verification workflow, with every obligation quoted verbatim from and traceable to the rule text at https://www.finra.org/rules-guidance/rulebooks/finra-rules/3120 (most recently amended by SR-FINRA-2013-025 effective December 1, 2014).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "finra-3110-supervision",
      "iso-37301-compliance-mgt",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "finra-3130-annual-certification-of-compliance-and-supervisory-processes",
    "title": "FINRA Rule 3130 (Annual Certification of Compliance and Supervisory Processes)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-07-18",
    "bluf": "FINRA Rule 3130 (Annual Certification of Compliance and Supervisory Processes) is a rule of the Financial Industry Regulatory Authority (FINRA), the self-regulatory organization for U.S. broker-dealers overseen by the U.S. Securities and Exchange Commission. Each member shall designate and specifically identify to FINRA on Schedule A of Form BD one or more principals to serve as a chief compliance officer, and shall have its chief executive officer(s) certify annually that the member has in place processes to establish, maintain, review, test and modify written compliance policies and written supervisory procedures reasonably designed to achieve compliance with applicable FINRA rules, MSRB rules and federal securities laws and regulations. This node operationalises each obligation of FINRA Rule 3130 into a deterministic verification workflow, with every obligation quoted verbatim from and traceable to the rule text at https://www.finra.org/rules-guidance/rulebooks/finra-rules/3130 (most recently amended by SR-FINRA-2008-057 effective December 15, 2008).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "finra-3110-supervision",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "finra-3310-anti-money-laundering-compliance-program",
    "title": "FINRA Rule 3310 (Anti-Money Laundering Compliance Program)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-07-18",
    "bluf": "FINRA Rule 3310 (Anti-Money Laundering Compliance Program) is a rule of the Financial Industry Regulatory Authority (FINRA), the self-regulatory organization for U.S. broker-dealers overseen by the U.S. Securities and Exchange Commission. Each member shall develop and implement a written anti-money laundering program reasonably designed to achieve and monitor the member's compliance with the requirements of the Bank Secrecy Act (31 U.S.C. 5311, et seq.), and the implementing regulations promulgated thereunder by the Department of the Treasury. Each member's anti-money laundering program must be approved, in writing, by a member of senior management. The anti-money laundering programs required by this Rule shall, at a minimum, This node operationalises each obligation of FINRA Rule 3310 into a deterministic verification workflow, with every obligation quoted verbatim from and traceable to the rule text at https://www.finra.org/rules-guidance/rulebooks/finra-rules/3310 (most recently amended by SR-FINRA-2018-016 effective May 11, 2018).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bank-secrecy-act-suspicious",
      "fcpa-anti-bribery-compliance",
      "finra-3110-supervision",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "finra-cybersecurity-practices-2018",
    "title": "Report on Selected Cybersecurity Practices - 2018",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2018-12-31",
    "bluf": "This report continues FINRA’s efforts to share information that can help broker-dealer firms further develop their cybersecurity programs. Firms routinely identify cybersecurity as one of their primary operational risks, and this report presents FINRA’s observations regarding effective practices that firms have implemented to address selected cybersecurity risks, recognizing that there is no one-size-fits-all approach. The topics covered include strengthening cybersecurity controls in branch offices, limiting phishing attacks, identifying and mitigating insider threats, the elements of a strong penetration testing program, and establishing controls on mobile devices.\n\nThe report highlights practices that should be evaluated in the context of a holistic firm-level cybersecurity program. It is intended for broker-dealer firms, with specific guidance for small firms provided in an appendix titled “Core Cybersecurity Controls for Small Firms.” The core obligations involve implementing robust controls across various domains, such as developing written supervisory procedures (WSPs) for branches, conducting regular training, maintaining asset inventories, establishing technical controls like multi-factor authentication and encryption, conducting penetration tests, and managing mobile device security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "finra-3110-supervision",
      "sec-regulation-s-p-safeguarding",
      "nist-cybersecurity-framework-2-0",
      "cis-controls-v8",
      "sec-cybersecurity-risk-incident-disclosure"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fio-annual-report-insurance-us-market-2023",
    "title": "US Federal Insurance Office Annual Report 2023 - Insurance Market Competitiveness, Climate Risks and Affordability Assessment",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This annual report, mandated by the Dodd-Frank Act, assesses the U.S. insurance market, providing key findings and recommendations to Congress and state regulators on climate-related financial risk, insurance affordability, and market competitiveness. It highlights the increasing impact of climate change on property and casualty insurance availability and recommends enhanced data collection and supervisory practices to address these emerging risks (Recommendation 1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nfip-national-flood-insurance-program-rules",
      "iso-14090-climate-adapt",
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fips-140-3-cryptographic-modules",
    "title": "SECURITY REQUIREMENTS FOR CRYPTOGRAPHIC MODULES",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2019-03-22",
    "bluf": "This standard specifies the security requirements for a cryptographic module utilized within a security system protecting sensitive but unclassified information. It is applicable to all federal agencies that use cryptographic-based security systems and shall be used in designing and implementing cryptographic modules that federal departments and agencies operate or that are operated for them under contract. The standard provides four increasing, qualitative levels of security (Level 1, Level 2, Level 3, and Level 4) intended to cover a wide range of potential applications and environments.\n\nThe core obligation is for federal agencies to use cryptographic modules that have been validated by the Cryptographic Module Validation Program (CMVP), a joint effort between the National Institute of Standards and Technology (NIST) and the Canadian Centre for Cyber Security. The security requirements cover areas related to the secure design, implementation, and operation of a cryptographic module, including its specification, interfaces, roles, services, authentication, software/firmware security, operating environment, physical security, non-invasive security, sensitive security parameter management, self-tests, life-cycle assurance, and mitigation of other attacks. In the CMVP, vendors use independent, accredited Cryptographic and Security Testing (CST) laboratories to have their modules tested for conformance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-197-advanced-encryption-standard",
      "fips-202-sha-3-standard",
      "nist-sp-800-57-key-management",
      "nist-sp-800-63b-authentication",
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fips-197-advanced-encryption-standard",
    "title": "Advanced Encryption Standard (AES)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-05-09",
    "bluf": "The Advanced Encryption Standard (AES) specifies a FIPS-approved cryptographic algorithm that can be used to protect electronic data. The AES algorithm is a symmetric block cipher that can encrypt (encipher) and decrypt (decipher) digital information. The standard specifies three members of the Rijndael family: AES-128, AES-192, and AES-256. Each transforms data in blocks of 128 bits, and the numerical suffix indicates the bit length of the associated cryptographic keys. The algorithm is capable of using cryptographic keys of 128, 192, and 256 bits to encrypt and decrypt data in blocks of 128 bits.\n\nThis standard applies to information systems used or operated by federal agencies, a contractor of an agency, or other organization on behalf of an agency, but not to national security systems. It may be used by federal agencies to protect information when they have determined that encryption is appropriate. The algorithm specified in this Standard may be implemented in software, firmware, hardware, or any combination thereof and shall be used in conjunction with a FIPS-approved or NIST-recommended mode of operation. This standard may also be adopted and used by non-Federal Government organizations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-140-3-cryptographic-modules",
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-53-r5",
      "nist-sp-800-57-key-management",
      "nist-sp-800-131a-rev-2-crypto-transitions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fips-199-security-categorization",
    "title": "Standards for Security Categorization of Federal Information and Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2004-02-01",
    "bluf": "FIPS Publication 199 establishes standards for categorizing federal information and information systems to provide a common framework for expressing security. The categorization is based on the objectives of providing appropriate levels of information security according to a range of risk levels. This is accomplished by assessing the potential impact (Low, Moderate, or High) on organizational operations, assets, or individuals should a breach of security occur, defined as a loss of confidentiality, integrity, or availability. These standards apply to all information within the federal government (other than classified national security information) and all federal information systems. The core obligation for agency officials is to use these security categorizations whenever a federal requirement exists to categorize information or systems. The security category for an information system is determined by taking the highest potential impact value ('high water mark') from all information types resident on that system for each of the three security objectives: confidentiality, integrity, and availability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-200-minimum-security-requirements",
      "nist-sp-800-53-r5",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-18-r1-security-plans",
      "nist-sp-800-30-risk-assessment",
      "nist-sp-800-53b-control-baselines"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fips-200-minimum-security-requirements",
    "title": "Minimum Security Requirements for Federal Information and Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-03-09",
    "bluf": "This standard, mandated by the Federal Information Security Management Act (FISMA) of 2002, specifies minimum security requirements for information and information systems supporting the executive agencies of the federal government. It is applicable to all federal information and information systems, excluding those designated as national security systems or containing classified information. The core obligation for federal agencies is to develop, document, and implement an enterprise-wide program to provide information security for their systems and assets. This involves a risk-based process that begins with categorizing information systems as low, moderate, or high impact based on the security objectives of confidentiality, integrity, and availability, as defined in FIPS Publication 199.\n\nFollowing categorization, agencies must meet the minimum security requirements across seventeen security-related areas, including access control, incident response, configuration management, and contingency planning. The standard mandates the use of security controls from NIST Special Publication 800-53. Agencies must select and tailor a baseline of security controls corresponding to their system's impact level (low, moderate, or high). The goal is to establish minimum levels of due diligence for information security and facilitate a more consistent, comparable, and repeatable approach for selecting and specifying security controls for information systems that meet these minimum requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fips-201-3-piv-federal-employees",
    "title": "Personal Identity Verification (PIV) of Federal Employees and Contractors",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-01-01",
    "bluf": "This document establishes a standard for a Personal Identity Verification (PIV) system that meets the control and security objectives of Homeland Security Presidential Directive-12 (HSPD-12). It is based on secure and reliable forms of identity credentials issued by the Federal Government to its employees and contractors. These credentials are used by mechanisms that authenticate individuals who require access to federally controlled facilities, information systems, and applications. The standard is applicable to all federal departments and agencies for identification issued to federal employees and contractors, except for national security systems.\n\nThe core obligation is to implement a PIV system that issues credentials based on sound criteria for verifying an individual's identity, including prerequisite background investigations and in-person identity proofing. The credentials must be strongly resistant to fraud and tampering, be rapidly authenticated electronically, and be issued only by providers whose reliability has been established by an official accreditation process. The Standard specifies implementation and processes for binding identities to authenticators, such as integrated circuit cards (PIV Cards) and derived PIV credentials, and outlines the lifecycle activities for PIV identity accounts, from initial proofing and registration to issuance, maintenance, and termination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-200-minimum-security-requirements",
      "nist-sp-800-63b-authentication",
      "nist-sp-1800-12-derived-piv"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fips-202-sha-3-standard",
    "title": "SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2015-08-01",
    "bluf": "This Standard specifies the Secure Hash Algorithm-3 (SHA-3) family of functions on binary data, based on the KECCAK algorithm selected by NIST. The SHA-3 family consists of four cryptographic hash functions (SHA3-224, SHA3-256, SHA3-384, and SHA3-512) and two extendable-output functions or XOFs (SHAKE128 and SHAKE256). These functions supplement the SHA-1 and SHA-2 families specified in FIPS 180-4, providing resilience against future advances in hash function analysis through fundamentally different design principles.\n\nThis standard is applicable to all Federal departments and agencies for protecting sensitive unclassified information. The core obligation is that either this Standard or FIPS 180 must be implemented wherever a secure hash algorithm is required for Federal applications, including as a component within other cryptographic algorithms and protocols. Implementations may be in software, firmware, hardware, or any combination thereof, but only implementations validated by the Cryptographic Algorithm Validation Program (CAVP) will be considered compliant. This standard may also be adopted and used by non-Federal Government organizations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "secure-hash-standard-fips-180-4"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fips-203-ml-kem-standard",
    "title": "Module-Lattice-Based Key-Encapsulation Mechanism Standard",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-08-13",
    "bluf": "This standard specifies a key-encapsulation mechanism (KEM) called ML-KEM, which is a set of algorithms that can be used by two parties to establish a shared secret key over a public channel. The security of ML-KEM is related to the computational difficulty of the Module Learning with Errors problem, and it is presently believed to be secure, even against adversaries who possess a quantum computer. The standard specifies three parameter sets, ML-KEM-512, ML-KEM-768, and ML-KEM-1024, which offer different trade-offs in security strength versus performance. All three are approved to protect sensitive, non-classified communication systems of the U.S. Federal Government.\n\nThis standard applies to information systems used or operated by federal agencies or by a contractor of an agency on behalf of an agency, but not to national security systems. It shall be used wherever the establishment of a shared secret key is required for federal applications, including for use with symmetric-key cryptographic algorithms. The core obligation is for implementations to conform to the specified algorithms and employ other approved cryptographic functions. Conforming implementations may replace the given set of steps with any mathematically equivalent set of steps, but must not use the component public-key encryption scheme (K-PKE) as a stand-alone scheme.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-140-3-cryptographic-modules",
      "fips-202-sha-3-standard",
      "nist-ir-8413-pqc-third-round",
      "pqc-migration-logic",
      "quantum-readiness-checklist",
      "ietf-hybrid-pqc-drafts"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fips-204-ml-dsa-quantum",
    "title": "FIPS 204 (ML-DSA Quantum)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "FIPS 204 (Module-Lattice-Based Digital Signature Algorithm) is the final NIST standard for quantum-resistant digital signatures. Based on the CRYSTALS-Dilithium algorithm, it is designed to ensure authenticity and non-repudiation in a post-quantum world, replacing or augmenting RSA and ECDSA signatures for core internet infrastructure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-203-ml-kem-standard",
      "fips-205-slh-dsa-quantum",
      "nist-ir-8413-pqc-third-round",
      "pqc-migration-logic",
      "nist-fips-186-5-dss",
      "dfars-7012-defense-cyber"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fips-204-ml-dsa-standard",
    "title": "Module-Lattice-Based Digital Signature Standard",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-08-13",
    "bluf": "This standard specifies ML-DSA, a set of algorithms that can be used to generate and verify digital signatures which are used to detect unauthorized modifications to data and to authenticate the identity of the signatory. ML-DSA is a lattice-based digital signature algorithm believed to be secure, even against adversaries in possession of a large-scale quantum computer, and provides for non-repudiation. The standard specifies the mathematical steps that need to be performed for key generation, signature generation, and signature verification. ML-DSA can be used in electronic mail, electronic funds transfer, software distribution, data storage, and other applications that require data integrity assurance and data origin authentication.\n\nThis standard is applicable to all federal departments and agencies for the protection of sensitive unclassified information. The core obligation is that either this standard, FIPS 205, FIPS 186-5, or NIST Special Publication 800-208 shall be used in designing and implementing public-key-based signature systems that federal departments and agencies operate or that are operated for them under contract. Implementations must employ cryptographic algorithms approved for protecting Federal Government-sensitive information. The security of a digital signature system depends on maintaining the secrecy of the signatory’s private keys, and signatories shall guard against the disclosure of their private keys. The adoption and use of this standard are also available to private and commercial organizations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-140-3-cryptographic-modules",
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-fips-186-5-dss",
      "nist-ir-8413-pqc-third-round",
      "pqc-migration-logic"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "fips-205-slh-dsa-quantum",
    "title": "FIPS 205: Stateless Hash-Based Digital Signature Standard",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "FIPS 205 (Stateless Hash-Based Digital Signature Algorithm) is a NIST-standardized quantum-resistant signature mechanism based on the SPHINCS+ construction. Unlike lattice-based schemes, it relies solely on the security of cryptographic hash functions, providing a robust backup against potential cryptanalytic breakthroughs in other PQC families.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-140-3-cryptographic-modules",
      "fips-202-sha-3-standard",
      "nist-sp-800-90a-rev1-drbg",
      "pqc-migration-logic",
      "quantum-readiness-checklist",
      "nist-ir-8547-pqc-transition"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "first-tlp-2-0-traffic-light-protocol",
    "title": "FIRST Traffic Light Protocol Version 2.0 (TLP:RED, TLP:AMBER, TLP:AMBER+STRICT, TLP:GREEN, TLP:CLEAR, August 2022 authoritative replacement for TLP 1.0 WHITE)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "The Traffic Light Protocol (TLP) Version 2.0, maintained by the Forum of Incident Response and Security Teams (FIRST), is the canonical four-label classification scheme for restricting the onward sharing of sensitive information in incident response and threat intelligence communities. TLP 2.0 became authoritative in August 2022, replacing TLP 1.0 by renaming TLP:WHITE to TLP:CLEAR and adding TLP:AMBER+STRICT. The four labels and their handling instructions are: TLP:RED - for the eyes and ears of individual recipients only with no further disclosure, used when information cannot be effectively acted upon without significant risk to privacy, reputation, or operations; TLP:AMBER - limited disclosure where recipients can spread only on a need-to-know basis within their organisation and its clients, used when the information requires support to be effectively acted upon but carries risk if shared outside the organisations involved; TLP:AMBER+STRICT - the same as TLP:AMBER but restricted to the organisation only and excluding clients, used when client-side onward sharing is itself a risk; TLP:GREEN - limited disclosure where recipients can spread within their community of peers and partner organisations but not via publicly accessible channels, used when information is useful to increase awareness within their wider community; TLP:CLEAR - recipients can spread to the world with no limit on disclosure, used when the information carries minimal or no foreseeable risk of misuse in accordance with applicable rules and procedures for public release. TLP labels are applied at the sender's discretion and operate by convention and trust within FIRST member communities, ISACs, ISAOs, CERTs, ISACs, and the wider CTI ecosystem. TLP markings are embedded in STIX 2.1 as marking-definition objects referenced via object_marking_refs and granular_markings. TLP 2.0 is openly available at first.org/tlp/ and is the operative version; TLP 1.0 documents should be migrated to TLP 2.0 vocabulary and labels.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standard_basis",
        "key_institutions",
        "tlp_red_definition",
        "tlp_amber_definition",
        "tlp_amber_strict_definition",
        "tlp_green_definition",
        "tlp_clear_definition",
        "tlp_2_0_changes_from_tlp_1_0",
        "stix_tlp_marking_definition_pairing",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oasis-stix-2-1-structured-threat-information",
      "cyber-nist-csf-2",
      "us-cisa-kev-catalog"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fisma-compliance-compliance-2026-24",
    "title": "FISMA Compliance Enterprise Compliance Standard v24",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The Federal Information Security Management Act (FISMA) mandates that federal agencies develop, document, and implement an information security program to protect government information, operations, and assets. FISMA requires agencies to conduct annual assessments of their information security programs, implement security controls based on NIST standards, and report on the effectiveness of these controls. Compliance with FISMA is essential for safeguarding sensitive data against cyber threats and ensuring the integrity, confidentiality, and availability of federal information systems. Agencies must also ensure that their contractors and third-party service providers adhere to FISMA requirements, thereby extending the security framework across all operational facets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "fisma-compliance-compliance-2026-9",
    "title": "FISMA Compliance Enterprise Compliance Standard v9",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The Federal Information Security Management Act (FISMA) mandates federal agencies to secure their information systems. It requires the development, documentation, and implementation of an information security program that includes risk assessments, security controls, continuous monitoring, and incident response. Agencies must comply with standards set by the National Institute of Standards and Technology (NIST), including the Risk Management Framework (RMF) and Special Publication 800-53 for security controls. FISMA emphasizes the importance of protecting government information and ensuring the integrity, confidentiality, and availability of data. Regular audits and assessments are required to ensure compliance and to identify vulnerabilities. Non-compliance can lead to significant penalties and risks to national security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "fj-financial-transactions-reporting-act-2004",
    "title": "Fiji Financial Transactions Reporting Act 2004",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-18",
    "bluf": "Fiji's Financial Transactions Reporting Act 2004 requires financial institutions to verify customer identity (Section 4), maintain records (Section 8), monitor transactions (Section 10), conduct due diligence (Section 11), report prescribed financial transactions (Section 13) and suspicious transactions (Section 14) to the Financial Intelligence Unit established under Section 22, with statutory protection for persons who report (Section 20).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fj-osa-2018",
    "title": "Fiji Online Safety Act 2018 - Personal Data and Privacy Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Fiji enacted the Online Safety Act 2018, which establishes the Online Safety Commission (OSC) and creates a regulatory framework governing harmful online content and conduct, including provisions for the protection of personal data and privacy in online environments. The Fiji Constitution 2013 establishes a constitutional right to privacy in Section 24, protecting individuals from unlawful searches, entries, surveillance, and interception of communications. The Online Safety Act 2018 supplements these constitutional protections in the digital context by establishing obligations for online service providers to remove harmful content including non-consensual intimate imagery and personal information used to cause harm, providing remedies for individuals whose personal information has been misused online, and granting the Online Safety Commission authority to investigate complaints, issue take-down notices, and refer matters for prosecution. The OSC is the primary regulatory authority for online privacy and safety matters in Fiji. Organisations operating digital services in Fiji must respect constitutional privacy rights and comply with Online Safety Act 2018 obligations concerning the handling and removal of personal information when it is used to cause harm.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/fj-osa-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fk-dpo-2018",
    "title": "Falkland Islands Data Protection Ordinance 2018",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Falkland Islands, a British Overseas Territory, enacted the Data Protection Ordinance 2018 aligned with UK data protection standards. The Ordinance is administered by the Falkland Islands Government and establishes principles for the lawful processing of personal data. It grants data subjects rights of access and correction, requires appropriate security measures, and restricts cross-border transfers to jurisdictions providing adequate protection. The Ordinance applies to data controllers established in the Falkland Islands and mirrors the UK data protection framework to ensure consistency for businesses operating across UK Overseas Territories. Compliance is overseen by the designated government authority responsible for information governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/fk-dpo-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fleet-telematic-audit",
    "title": "Fleet Telematics Audit Protocol",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Fleet Telematics Audit Protocol establishes a comprehensive framework for verifying compliance with critical cybersecurity, data privacy, and operational mandates. The system enforces stringent cybersecurity controls aligned with ISO/SAE 21434, requiring that CAN bus network isolation is enabled to mitigate internal threats. In-transit data integrity is protected through mandatory AES-256 IoT transmission encryption, a standard advocated by NIST SP 800-213 for device security. To address lifecycle management principles within UNECE WP.29 Regulation 155 and Regulation 156, this protocol mandates that over-the-air firmware updates must have digital signatures and that continuous monitoring is performed with vulnerability scans at an interval not exceeding 30 days. Regarding data protection, the protocol adheres to GDPR Article 5 and Article 32, enforcing a strict 180-day maximum for telemetry data retention and utilizing data anonymization for aggregate reports. California Privacy Rights Act provisions are met through an active driver data access portal, and where applicable, ensuring that explicit driver biometric consent is logged. Operationally, this protocol guarantees full adherence to the FMCSA Electronic Logging Device Rule; systems are confirmed to be ELD mandate compliant, Hours of Service tamper detection is enabled, and the GPS polling interval has a minimum of 30 seconds. A critical alert latency maximum of 500 milliseconds ensures timely notifications consistent with safety obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-sp-800-213-iot-guidance",
      "iso-39001-road-traffic",
      "supply-chain-risk-triage",
      "fips-197-advanced-encryption-standard",
      "iso-28000-supply-chain"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "flsa-compliance-labor",
    "title": "FLSA (Fair Labor)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Fair Labor Standards Act (FLSA) establishes critical nationwide standards for wages and hours, recordkeeping obligations, and youth employment. Under 29 U.S.C. § 206, covered non-exempt employees are entitled to a federal minimum wage of at least $7.25 per hour. Furthermore, 29 U.S.C. § 207 mandates overtime compensation for work exceeding a standard forty-hour work week, requiring payment at a rate of one and one-half times the employee's regular rate; private sector compensatory time off is not a permissible substitute. Specific classifications of employees may be exempt from these wage and hour provisions if they meet criteria outlined in 29 CFR Part 541, which includes a minimum weekly salary threshold of $844. Employers must adhere to stringent data collection and recordkeeping rules pursuant to 29 U.S.C. § 211(c) and detailed in 29 CFR Part 516. This includes maintaining accurate time tracking for all non-exempt personnel and requires secure data storage for personally identifiable information. Payroll records must be preserved for three years, whereas timekeeping data mandates a two-year retention period. The child labor provisions of 29 U.S.C. § 212 set the minimum working age at fourteen for most occupations but increase that minimum age to eighteen for designated hazardous roles. Compliance also necessitates the prominent display of a workplace poster detailing these employee rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "flsa-coverage",
      "ilo-core-conventions",
      "osha-work-safety-us",
      "fmla-compliance-leave",
      "ada-employment-title-1",
      "eeoc-employment-rule"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "flsa-coverage",
    "title": "Coverage under the Fair Labor Standards Act (FLSA)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2009-07-01",
    "bluf": "The Fair Labor Standards Act (FLSA) establishes standards for minimum wage, overtime pay, recordkeeping, and child labor. This guidance, provided in Fact Sheet #14, explains the coverage of the FLSA, detailing which employers and employees are covered by the law. Coverage can be established on an enterprise basis, covering all employees of a business, or on an individual basis, covering specific employees whose work involves interstate commerce. The guidance clarifies that certain exemptions may apply to specific positions, removing them from minimum wage or overtime protections.\n\nIn addition to defining coverage, the fact sheet emphasizes the recordkeeping requirements for employers. Under the FLSA, employers must maintain accurate records of hours worked and wages paid for all covered, non-exempt employees. Compliance with these provisions is crucial, as misclassification of employees or failure to adhere to wage, hour, and recordkeeping standards can result in liability for back wages and other penalties. The act's protections ensure that workers receive proper compensation for their labor, including premium pay for overtime hours worked.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "flsa-compliance-labor"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fm-framework",
    "title": "Micronesia (FSM) - Constitutional Privacy Rights and Pacific Islands Forum Data Protection Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Federated States of Micronesia (FSM) is an independent nation in the western Pacific Ocean governed under a federal constitutional system established by the Constitution of the Federated States of Micronesia (1978). The FSM Constitution establishes fundamental rights including the right to privacy and freedom from unreasonable searches and intrusions into personal privacy and correspondence. FSM entered into a Compact of Free Association with the United States; however, the Compact provides for US defense obligations and economic assistance and does not extend US federal law to the FSM - the FSM exercises full sovereignty over its own legal and regulatory affairs. The Department of Transportation, Communications and Infrastructure (DOTCI) oversees telecommunications and ICT services in the FSM. FSM does not have a standalone comprehensive personal data protection law. The applicable framework for personal data protection in the FSM consists of the constitutional privacy rights established by the FSM Constitution, Pacific Islands Forum regional guidelines on cybersecurity and data protection, and common law privacy principles. Organisations processing personal data in the FSM must respect constitutional privacy rights, implement appropriate security measures to protect personal data from unauthorised access and disclosure, and limit the collection and use of personal data to specified, legitimate purposes. As a Pacific Islands Forum member and Commonwealth of Nations observer, FSM participates in regional frameworks for cybersecurity and data governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/fm-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fmla-compliance-leave",
    "title": "FMLA (Family Leave)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Family and Medical Leave Act mandates that covered employers provide eligible employees with job-protected, unpaid leave for specified family and medical reasons. A covered employer under 29 U.S.C. § 2611 is one employing 50 or more individuals. To qualify as an \"eligible employee\" pursuant to 29 CFR § 825.110, an individual must have worked for the employer for at least 12 months, which need not be consecutive, and for a minimum of 1,250 hours during the 12-month period preceding the leave. Qualifying employees are entitled to a total of 12 workweeks of leave in a 12-month period. This entitlement extends to 26 workweeks during a single 12-month period for military caregiver leave under 29 U.S.C. § 2612. While this is an unpaid leave standard, the statute permits intermittent leave usage when medically necessary. Critical protections under 29 U.S.C. § 2614 require that employers maintain the employee's group health benefits during leave and ensure job restoration to an equivalent position upon return. For foreseeable leave, an employee must provide 30 days' advance notice. Following a leave request, the employer must furnish eligibility notice within 5 business days as part of its comprehensive notice obligations outlined in 29 CFR § 825.300. Because medical certification is required, the employee generally has 15 calendar days to provide sufficient documentation of a serious health condition as stipulated by 29 CFR § 825.305.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "flsa-coverage",
      "ada-employment-title-1",
      "eeoc-employment-rule",
      "erisa-compliance-rep"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fo-dp-law-2018",
    "title": "Faroe Islands Lov um Persónupplýsingar (Personal Data Protection Law) 2018",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Faroe Islands, an autonomous territory of the Kingdom of Denmark, enacted the Lov um Persónupplýsingar (Law on Personal Data) 2018, aligned with the European Union's General Data Protection Regulation (GDPR). The law is administered by Teldatryggi, the Faroese Data Protection Authority. It establishes data protection principles for the lawful processing of personal data, grants data subjects rights of access, rectification, erasure, portability, and objection to processing, requires controllers to implement security measures and appoint Data Protection Officers where required, mandates breach notification to Teldatryggi and affected individuals, and restricts cross-border transfers. The law reflects the Faroe Islands' alignment with European data protection standards despite not being a member of the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/fo-dp-law-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "food-allergen-label-law",
    "title": "Food Allergen Labeling Law",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Regulatory frameworks governing food allergen labeling establish non-negotiable compliance obligations for manufacturers. The primary U.S. authority, the Food Allergen Labeling and Consumer Protection Act of 2004 (FALCPA), as amended by the FASTER Act of 2021, mandates explicit declaration of nine major food allergens, a requirement which now includes sesame. This legislation requires plain language naming for allergens and permits disclosure using either an inline parenthetical format within the ingredient list or an adjacent “Contains” statement format. Meanwhile, European Union regulations, chiefly Regulation (EU) No 1169/2011, are more expansive, identifying a total of fourteen major allergens requiring declaration. The EU uniquely mandates typographical emphasis, such as bolding or underlining, for allergenic ingredients listed and specifies a minimum font size of 1.2mm for mandatory particulars. While FALCPA generally exempts highly refined oils derived from major allergens, such specific carve-outs are narrowly defined. Beyond finished product labeling detailed in 21 CFR Part 101.9, broader food safety mandates under 21 CFR Part 117 compel manufacturers to implement robust preventive controls. This operational requirement mandates cross-contact prevention measures throughout production and also necessitates a rigorous supplier allergen verification program to ensure the integrity of raw materials and mitigate undeclared allergen risks from the supply chain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-gen",
      "eu-food-law-178-2002",
      "fda-food-labeling-guide",
      "fda-fsma-compliance",
      "haccp-food-safety",
      "iso-22000-food-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fr-anssi-pqc-transition-position-follow-up",
    "title": "France ANSSI Views on the Post-Quantum Cryptography Transition (2023 Follow-Up) - Mandatory Hybridation and Security Visa Phases",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2023-12-21",
    "bluf": "ANSSI views on the Post-Quantum Cryptography transition (2023 follow up), dated December 21, 2023, is the French national cybersecurity agency's updated position on the post-quantum transition. It is an addendum to ANSSI's 2022 position paper and details recommendations on post-quantum algorithms and hybridation techniques. Its defining feature is that hybridation is not advisory but a condition of French security visa evaluation.\n\nANSSI strongly emphasises the necessity of hybridation wherever post-quantum mitigation is needed, both in the short and medium term, on the reasoning that post-quantum algorithms have gained attention but are still not mature enough to solely ensure the security, several post-quantum schemes having suffered from classical attacks in recent years. It encourages all industries to include the quantum threat in their risk analysis and to define a progressive transition strategy, recommending hybrid post-quantum mitigation especially for security products aimed at offering a long-lasting protection of information until after 2030, or that will potentially be used after 2030 without updates.\n\nThe security visa process gives the position its force. ANSSI follows a three-phase roadmap for delivering security visas. In the second phase, the cryptographic evaluation tasks of security visa evaluation comprise an analysis of all cryptographic algorithms including the post-quantum algorithms with mandatory hybridation, and the security visa report can mention the presence of state-of-the-art post-quantum protection. ANSSI accelerated the original agenda, with first phase-2 security visas for products implementing hybrid post-quantum cryptography expected around 2024-2025. The requirement differentiates by product type. For end products, meaning final products, any product that includes post-quantum mitigation shall implement hybridation, except where the quantum mitigation only relies on hash-based signatures such as XMSS, LMS or SPHINCS+, for which hybridation is optional. For intermediate products, meaning platform products that provide raw cryptographic functionality to an upper applicative layer, implementing post-quantum cryptography without hybridation can sometimes be relevant, but ANSSI evaluation teams will require an implementation of a hybridation mode for test purposes and the inclusion in the user guidance documentation of a recommendation to exclusively use the provided post-quantum algorithm in combination with a recognised classical algorithm as part of a hybridation mode.\n\nOn algorithms, ANSSI traditionally does not provide a closed list of recommended algorithms, in order to avoid proscribing innovative state-of-the-art algorithms. Where CRYSTALS-Kyber, also called ML-KEM, is chosen, ANSSI recommends avoiding modification of the parameters of the standardised instance, using the highest NIST security level possible and preferably level 5 equivalent to AES-256 or level 3 equivalent to AES-192, using ephemeral keys as much as possible because systematic use of ephemeral private keys prevents many attacks such as decryption failure attacks, and using the actively secure IND-CCA version. On symmetric cryptography ANSSI is expressly more conservative than both NIST and BSI, encouraging parameters that ensure in practice at least the same security level as AES-256 for block ciphers and at least the same security level as SHA2-384 for hash functions. On combiners it warns that concatenating keys would not ensure security against passive attackers, and that xoring keys provides security against passive attackers but not against active attackers because of mix and match attacks, so a key derivation function is an essential building block.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-bsi-post-quantum-cryptography-position-tr-02102-1",
      "ietf-rfc-9370-multiple-key-exchanges-ikev2",
      "ietf-rfc-9794-pq-traditional-hybrid-terminology",
      "fips-203-ml-kem-standard"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "fr-anssi-secnumcloud-qualification-cloud-service-providers",
    "title": "France ANSSI SecNumCloud — Qualification for Cloud Service Providers (Sovereign Cloud Reference)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "SecNumCloud is the French national qualification scheme administered by the Agence Nationale de la Securite des Systemes d'Information (ANSSI) under which qualified cloud service providers (IaaS, PaaS, SaaS) receive an official ANSSI Visa de securite. The qualification embeds three sovereignty / immunity criteria designed to protect against extraterritorial law application and adversarial state interference: (i) immunity from non-EU extraterritorial law (the CSP and the legal entity providing the service must not be subject to extraterritorial regulation that would compel disclosure of customer data including the US CLOUD Act and the US FISA Section 702), (ii) capital ownership thresholds requiring EU-controlled corporate structure (typically constructed so that no extra-EU shareholder holds blocking minority or controlling rights over the qualified entity), and (iii) physical hosting and operational control within the EU including data residency, administrative access, and key management. SecNumCloud version 3.2 (March 2022) is the operative reference for current qualification decisions; the criteria framework spans organisational, physical, technical, cryptographic, identity and access management, incident response, business continuity, and supplier-management dimensions. SecNumCloud underpins France's Cloud au centre doctrine that mandates SecNumCloud-qualified offerings for sovereign-grade public sector workloads, sensitive non-classified data of state importance, and critical infrastructure operators classified as Operators of Vital Importance (OIV) and Essential Service Operators (OSE) under the French transposition of the EU NIS2 Directive. SecNumCloud is widely treated by EU institutions and member state procurement teams as the high-assurance benchmark for sovereign cloud and has been awarded to a small number of CSPs (notably 3DS Outscale, OVHcloud, Cloud Temple, NumSpot, S3NS Bleu in development as a Google-Capgemini-Orange JV, Sens by Orange, and Microsoft / Bleu pending). The scheme intersects the harmonised European Cybersecurity Certification Scheme for Cloud Services (EUCS) under negotiation and serves as one of the principal national references shaping the EUCS high-assurance level requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-iec-42001-2023-ai-management-system",
      "iso-iec-23894-ai-risk-management-2023",
      "nist-sp-800-53-r5",
      "eu-cra-2024-2847-article-3-essential-requirements-products-digital-elements",
      "fips-203-ml-kem-standard"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "fr-cmf-aml-cft-obligations-l561",
    "title": "Code monetaire et financier - AML/CFT obligations (Articles L561-1 et seq., Tracfin regime)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.0",
    "last_updated": "2026-07-10",
    "bluf": "France's AML/CFT obligations are set out in the Code monetaire et financier at Articles L561-1 and following. Article L561-2 lists the obliged entities (personnes assujetties) such as credit and payment institutions; Article L561-15 requires a declaration of suspicion to Tracfin for sums or operations suspected of arising from serious offences or terrorist financing; Article L561-22 provides good-faith immunity to declarants; and Article L561-23 establishes the national financial intelligence cell, the unit that operates under the name Tracfin. This node scopes the suspicious-transaction reporting regime to Tracfin.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "fr-code-commande-publique-2019",
    "title": "France Code de la Commande Publique (2019 Consolidation)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Code de la Commande Publique, the consolidated French public procurement code that entered into force on 1 April 2019, codifies prior legislation including EU Directives 2014/24/EU and 2014/25/EU into a single instrument. The Code is structured as a Preliminary Title (Articles L1 to L6) containing foundational principles and definitions, a First Part (Articles L1100 to L1481) on the definition and scope of public contracts (marchés publics) and concessions, and a Second Part (Articles L2000 to L2728) on the rules and procedures applicable to marchés publics, with parallel regulatory provisions (R articles). Article L3 establishes the constitutional procurement principles of liberté d'accès à la commande publique, égalité de traitement des candidats and transparence des procédures. Procurement procedures are codified in Articles L2120-x to L2124-x and include the open procedure (appel d'offres ouvert), restricted procedure (appel d'offres restreint), procedure with negotiation (procédure avec négociation), competitive dialogue (dialogue compétitif) and unpublished negotiated procedure (marché négocié sans publicité). Award criteria are governed by Article L2152-x, subcontracting by Article L2193-x and L2192-x, and review by Article L6 and the Code de justice administrative.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-public-procurement-construction-directive",
      "wto-revised-government-procurement-agreement-2012"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "fr-code-consommation",
    "title": "France Code de la Consommation (Consumer Code)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The French Code de la consommation is the consolidated codification of French consumer protection law, applying the EU Unfair Commercial Practices Directive 2005/29/CE, Consumer Rights Directive 2011/83/UE and successor instruments. The Code is organised in eight Livres. Livre Ier covers consumer information and commercial practices. Arts. L111-1 to L111-7 set the general pre-contractual information obligation (trader identity, essential characteristics, total price including taxes, payment and delivery terms, withdrawal rights, after-sales services, applicable guarantees). Art. L121-1 defines pratiques commerciales deloyales as practices contrary to professional diligence that materially distort the average consumer's behaviour. Arts. L121-2 to L121-5 prohibit pratiques commerciales trompeuses (misleading actions and omissions). Arts. L121-6 to L121-7 prohibit pratiques commerciales agressives (harassment, coercion, undue influence). Arts. L122-1 to L122-22 contain the blacklist of practices always deemed misleading or aggressive and sector-specific rules. Arts. L221-1 to L221-29 govern contrats conclus a distance et hors etablissement, with Arts. L221-18 to L221-28 establishing the 14-day droit de retractation. Arts. L511-1 to L532-1 establish DGCCRF enforcement powers including injonctions, transactions and amendes administratives. Criminal sanctions appear at Arts. L132-1 to L132-26.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011-83-eu",
      "eu-unfair-commercial-practices-2005-29-2022-revision",
      "it-d-lgs-206-2005-codice-del-consumo"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "fr-code-penal-article-227-23-csam-distribution",
    "title": "France Code Pénal Article 227-23 - Distribution, Recording, and Possession of Child Pornographic Imagery",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Article 227-23 of the French Code Pénal criminalises the recording, transmission, distribution, importation, exportation, offering, making available, acquisition, viewing, and possession of pornographic images of a minor. The first paragraph covers production-stage offences: recording, transmission, or attempting to record/transmit (5 years imprisonment, EUR 75,000 fine). The second paragraph covers distribution-stage: distribution, importation, exportation (5 years, EUR 75,000 fine; 7 years and EUR 100,000 fine if via electronic communication network). The third paragraph covers consultation/possession (2 years, EUR 30,000 fine; 5 years and EUR 75,000 fine for habitual consultation). Where the victim is under 15 or there is organised conduct, aggravated penalties apply. The 2021 amendment extended scope to apparent-minor imagery. Article 227-23 is France's central CSAM provision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "paragraph_1_recording_transmission",
        "paragraph_2_distribution_aggravated_via_electronic_network",
        "paragraph_3_consultation_possession",
        "paragraph_4_aggravated_offences_organised_or_under_15",
        "scope_extended_to_apparent_minor_imagery_2021",
        "definitions_pornographic_imagery_minor",
        "extraterritorial_jurisdiction_article_227_27_1",
        "interaction_with_article_227_22_corruption_of_minor",
        "interaction_with_article_227_22_1_solicitation_via_electronic_communication",
        "professional_disqualification_complementary_penalty_article_222_45"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-directive-2011-93-article-5-offences-concerning-child-pornography",
      "eu-directive-2011-93-article-6-solicitation-of-children-sexual-purposes"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "fr-hds-certification-hebergement-donnees-sante",
    "title": "France HDS Certification - Hebergement de Donnees de Sante (Health Data Hosting, CSP Art. L1111-8)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "HDS (Hebergeur de Donnees de Sante) certification is the mandatory French certification for hosting personal health data, established by Article L.1111-8 of the Code de la sante publique as modified by loi numero 2016-41 du 26 janvier 2016. Any public or private organization that hosts personal health data collected in the course of prevention, diagnosis, care or medico-social follow-up activities on behalf of health establishments or third parties must hold HDS certification; establishments managing their own systems internally for their own account are exempt. Decret numero 2018-137 du 26 fevrier 2018 defines the certification procedure and organized the transition from the former agrement (approval) regime to certification. Certification is structured around two certificate types covering six activities: the hebergeur d infrastructure physique certificate (provision and operational maintenance of hardware and physical hosting sites) and the hebergeur infogereur certificate (virtual infrastructure, application platform hosting, system administration and exploitation, and externalized data backup); a provider is certified only for the activities it actually performs. Certification bodies must be accredited by COFRAC (Comite francais d accreditation) or an equivalent European accreditation body, and conduct a two-stage audit against the certification referentiel; certificates are issued for three years with annual surveillance audits. The arrete du 26 avril 2024 approved the updated accreditation and certification referentiels, and under the updated framework the physical hosting of health data must be carried out exclusively within the European Economic Area. HDS certification is the market-access gate for cloud and hosting providers serving the French health sector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_anchor",
        "decree_procedure_anchor",
        "referentiel_2024_update",
        "certificate_types_and_activities",
        "gdpr_relationship",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-28-processor-obligations-and-contracts",
      "eu-ehds-regulation-2024",
      "fr-anssi-secnumcloud-qualification-cloud-service-providers"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fr-loi-2017-399-devoir-de-vigilance",
    "title": "France Loi n° 2017-399 du 27 mars 2017 relative au devoir de vigilance des societes meres et des entreprises donneuses d'ordre (Duty of Vigilance Law)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Loi n° 2017-399 du 27 mars 2017 (Duty of Vigilance Law) inserts Articles L. 225-102-4 and L. 225-102-5 into the French Code de commerce, creating the first parent-company duty of vigilance in the world. The Law applies to French societes that employ, at the close of two consecutive financial years, at least 5,000 salaries directly or through filiales whose registered office is in France, or at least 10,000 salaries worldwide including filiales whose registered office is in France or abroad. Article L. 225-102-4 requires the in-scope company to establish, publish and implement a plan de vigilance covering five mandatory components: (1) une cartographie des risques destinee a leur identification, analyse et hierarchisation; (2) des procedures d'evaluation reguliere de la situation des filiales, des sous-traitants ou fournisseurs avec lesquels est entretenue une relation commerciale etablie; (3) des actions adaptees d'attenuation des risques ou de prevention des atteintes graves; (4) un mecanisme d'alerte et de recueil des signalements relatifs a l'existence ou a la realisation des risques, etabli en concertation avec les organisations syndicales representatives; (5) un dispositif de suivi des mesures mises en oeuvre et d'evaluation de leur efficacite. The vigilance plan must cover risks of atteintes graves to human rights and fundamental freedoms, health and safety of persons, and the environment, resulting from the activities of the company, of the companies it controls within the meaning of II of Article L. 233-16, and of the activities of the sous-traitants or fournisseurs with whom the company has an established commercial relationship, when those activities are linked to that relationship. Article L. 225-102-5 establishes civil liability under Articles 1240 and 1241 of the Code civil for damages resulting from a breach of the vigilance obligations. Article 3 of the original Loi creating an administrative fine of up to 10 million EUR (raised to 30 million EUR with intentional fault) was struck down by Conseil constitutionnel Decision 2017-750 DC of 23 March 2017 as insufficiently precise. The Tribunal Judiciaire de Paris has exclusive jurisdiction since Loi 2021-1729 du 22 decembre 2021. The Loi is the precursor to EU CSDDD Directive 2024/1760.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csddd-directive-2024-1760",
      "de-lksg-supply-chain-due-diligence-act-2021",
      "uk-modern-slavery-act-2015-section-54-supply-chain-transparency"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "fr-loi-devoir-de-vigilance-2017",
    "title": "France Duty of Vigilance Law 2017 (Loi No. 2017-399 relative au devoir de vigilance des sociétés mères et des entreprises donneuses d'ordre)",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Duty of Vigilance Law (Loi No. 2017-399 of 27 March 2017 on the Duty of Vigilance of Parent Companies and Instructing Entities) makes France the first country in the world to legally mandate corporate supply chain human rights and environmental due diligence, predating the EU Corporate Sustainability Due Diligence Directive (CSDDD) by seven years. The law is codified at Articles L.225-102-4 and L.225-102-5 of the French Commercial Code (Code de commerce) and at Articles L.22-10-36 and L.22-10-37 following the PACTE Law reform of 2019. The law applies to sociétés anonymes (SAs) incorporated under French law that, at the close of two consecutive fiscal years, employ either: at least 5,000 employees in France (within the company and its French and foreign direct and indirect subsidiaries), or at least 10,000 employees worldwide (within the company and all of its direct and indirect subsidiaries globally). The fundamental obligation is the annual publication of a plan de vigilance (vigilance plan) that must include: first, a risk mapping identifying, analysing, and ranking the risks to human rights, fundamental freedoms, the health and safety of persons, and the environment that may result from the company's activities and those of the companies it controls, its subcontractors, and its suppliers with which it has an established commercial relationship; second, procedures for the regular assessment of the situation of subsidiaries, subcontractors, and suppliers with which the company has an established commercial relationship, based on the risk mapping; third, appropriate actions to mitigate risks and prevent serious violations; fourth, an alert and collection mechanism to report the existence or realisation of risks, established in conjunction with the trade union representatives of the company; and fifth, a system for monitoring the actions and measures implemented and for evaluating their effectiveness. The vigilance plan must be included in the company's annual management report or a dedicated document published on the company's website and must be prepared in consultation with stakeholders including trade unions. Enforcement: any interested person (including NGOs and trade unions) may give the company formal notice to comply with its obligations; if the company fails to comply within three months, the interested person may refer the matter to a civil court, which may order the company to comply under penalty payment (astreinte). Companies may also be held liable in civil damages under general tort law (Article 1240 Code civil) where a failure to establish or implement the vigilance plan causes damage that a properly implemented plan could have prevented. Several landmark cases have been initiated against Total Energies (climate and human rights in Uganda), EDF (Carmichael coal mine, Australia), TotalEnergies SA (Mozambique LNG), Yves Rocher, Teleperformance, and others. The EU Corporate Sustainability Due Diligence Directive 2024/1760 (CSDDD), which France must transpose by 26 July 2026, extends similar obligations to EU companies meeting turnover and employee thresholds and adds a civil liability regime harmonised at EU level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-lksg-supply-chain-due-diligence-act-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fr-loi-informatique-liberte-1978",
    "title": "France Loi Informatique et Libertés 1978 (Law No. 78-17, as amended by Law No. 2018-493 implementing GDPR)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Loi Informatique et Libertés (Law No. 78-17 of 6 January 1978 on Data Processing, Data Files, and Individual Liberties) is France's foundational data protection statute, one of the world's first such laws. It was substantially reformed by Law No. 2018-493 of 20 June 2018 to adapt French data protection law to the EU General Data Protection Regulation 2016/679 (GDPR), effective 25 May 2018. The law is administered and enforced by the Commission Nationale de l'Informatique et des Libertés (CNIL), an independent administrative authority established under Article 11. Article 1 of the law declares that 'computing must be at the service of every citizen' and that it must not 'harm human identity, human rights, privacy, or individual or public freedoms'. Article 8 extends the GDPR Article 9 prohibition on processing sensitive categories of personal data with French-specific derogations including for employment law, medical purposes established by law, statistical surveys authorised by law, and scientific research. Article 11 confers on CNIL broad powers: to receive complaints and conduct investigations; to carry out on-site inspections; to issue formal notices requiring compliance; to impose sanctions of up to EUR 20 million or 4% of the worldwide annual turnover of the preceding financial year for serious infringements, and up to EUR 10 million or 2% for other infringements (aligned with GDPR Article 83); to publish sanction decisions; and to refer matters to the competent criminal courts. CNIL has imposed significant fines including EUR 50 million against Google (2019, consent to personalised advertising), EUR 35 million against Amazon (2021, cookie consent), and EUR 60 million each against Facebook/Meta (2022) and Microsoft (2024) for cookie consent violations. Articles 84 to 86 create French-specific rights for deceased persons: individuals may give instructions concerning the processing of their personal data after their death, including whether such data should be communicated to a third party, deleted, or used for historical, statistical, or scientific research. French criminal sanctions for data protection violations are contained in Articles 226-16 to 226-24 of the Code pénal (Penal Code): Article 226-17 prescribes imprisonment of up to five years and a fine of up to EUR 300,000 for natural persons (EUR 1.5 million for legal persons) for failure to comply with security obligations; Article 226-22 prescribes the same penalties for unauthorised disclosure of personal data to a third party. The DPDP Rules governing specific sectors - health data, genetic data, and biometric data - are established by decree (décret) in consultation with CNIL.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fr-loi-republique-numerique-2016",
    "title": "France Digital Republic Act 2016 (Loi pour une République numérique)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "France's Loi n° 2016-1321 pour une République numérique signed October 7, 2016 modernises French digital law by establishing rights to digital portability, introducing open data obligations for public sector bodies, mandating loyalty and transparency for online platforms, strengthening privacy protections including a right to digital death, and creating a framework for electronic communications neutrality applicable to French digital services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/fr-loi-republique-numerique-2016.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fr-loi-sren-2024-449-age-verification-pornography",
    "title": "France LOI n° 2024-449 du 21 mai 2024 (Loi SREN) - Age Verification for Online Pornography (ARCOM Enforcement)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Loi n° 2024-449 du 21 mai 2024 visant à sécuriser et à réguler l'espace numérique (Loi SREN; JORF n°0117 du 22 mai 2024; NOR: ECOI2309270L) overhauls the French regulatory regime for online services, with Title I dedicated to the protection of minors against online pornography. Article 1 modifies Article 10 of the LCEN (Loi pour la confiance dans l'économie numérique n°2004-575) to mandate that ARCOM (Autorité de régulation de la communication audiovisuelle et numérique) publishes a binding technical referential ('référentiel technique') defining minimum technical requirements for age verification systems on pornographic sites and requires editors to display an interstitial screen with no pornographic content pending age verification; Article 2 inserts new Articles 10-1 and 10-2 establishing the administrative enforcement procedure: ARCOM may, after a 15-day observation period and a 15-day compliance deadline (mise en demeure), notify ISPs and DNS providers to block access within 48 hours, with sanctions capped at €250,000 or 4% of worldwide turnover for a first offence and €500,000 or 6% for repeat offences within 5 years; Article 3 inserts Article 6-8 enabling app-store removal requests for non-compliant services; Article 10-2 extends ARCOM jurisdiction to EU-based operators targeting French users via the country-of-destination principle (carve-out from the country-of-origin rule in the e-Commerce Directive). The technical referential was published by ARCOM in October 2024, with a 3-month implementation window after publication. Loi SREN is the headline French statute for age-gating online pornography and the operational anchor that ARCOM cites in every blocking decision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "modified_lcen_anchor",
        "arcom_authority",
        "country_of_destination_carve_out",
        "industry_mapping",
        "enforcement_anchors",
        "technical_referential_october_2024"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-50-transparency-obligations",
      "uk-online-safety-act-2023-part-5-pornographic-content-duties",
      "dsa-regulation-article-33-vlop-vlose-designation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fr-loi-sren-2024-449-digital-space",
    "title": "France Loi SREN No. 2024-449 of 21 May 2024 - Securing and Regulating the Digital Space, Cloud Sovereignty, and Cloud Interoperability Obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Online service operators, cloud computing service providers, public administration bodies, and operators of sensitive data hosting services in France must comply with the Loi SREN (Loi No. 2024-449 of 21 May 2024 visant a securiser et a reguler l'espace numerique, voted by the French National Assembly on 10 April 2024 and enacted 21 May 2024), which focuses on protecting citizens (particularly minors), ensuring European economic and digital sovereignty, and adapting French law to European regulations, including Article 10 bis A obligations for public administration bodies, operators, and public interest groups (GIP) handling sensitive data, and cloud computing obligations to ensure interoperability with customer and competitor services for similar functionalities, provide free access to customers and designated third-party providers to the necessary application programming interfaces (APIs) for interoperability and portability, and clarify which jurisdictions cover infrastructure especially under extraterritorial laws such as the US Cloud Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-data-act-regulation-2023-2854"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fr-lpm-cybersecurity-oiv-2013",
    "title": "France LPM 2013 - Cybersecurity Obligations for Operators of Vital Importance",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "France's Military Programming Law 2014-2019 (Loi n° 2013-1168 du 18 décembre 2013), Article 22, creates the legal framework for protecting critical information systems operated by Operators of Vital Importance (Opérateurs d'Importance Vitale - OIV), requiring OIVs to implement ANSSI-mandated security rules for each vital sector, undergo mandatory security audits, report cybersecurity incidents to ANSSI, and comply with binding ANSSI security directives, under the authority of the Prime Minister and ANSSI as the national cybersecurity agency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/fr-lpm-cybersecurity-oiv-2013.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-essential-important-entities-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fr-sapin-ii-anticorruption-2016",
    "title": "France Sapin II Anti-Corruption Law 2016 (Law No. 2016-1691 of 9 December 2016 on Transparency, Fight against Corruption, and Modernisation of Economic Life)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Sapin II Anti-Corruption Law (Law No. 2016-1691 of 9 December 2016 on Transparency, Fight against Corruption, and Modernisation of Economic Life - Loi relative à la transparence, à la lutte contre la corruption et à la modernisation de la vie économique) is France's principal corporate anti-corruption statute, modelled in part on the UK Bribery Act 2010 and the US Foreign Corrupt Practices Act 1977. The law created the Agence Française Anticorruption (AFA) as an independent supervisory authority responsible for monitoring companies' compliance programmes and issuing anti-corruption compliance guidelines (Recommandations). Article 17 of the Sapin II Law imposes mandatory anti-corruption compliance programme obligations on companies and groups meeting two cumulative thresholds: at least 500 employees AND annual turnover or group annual turnover of at least EUR 100 million. Article 17 applies to sociétés anonymes, sociétés par actions simplifiées, sociétés en commandite par actions, sociétés européennes, and their subsidiaries where the group meets the thresholds. The Article 17 compliance programme must include eight cumulative elements: (1) a code of conduct annexed to the company's internal rules (règlement intérieur) describing prohibited behaviour; (2) an internal whistleblowing system enabling employees and external parties to report risks or violations; (3) a risk mapping identifying, analysing, and ranking anti-corruption risks specific to the company, updated regularly; (4) third-party due diligence procedures assessing the anti-corruption risk profile of customers, first-tier suppliers, and intermediaries based on the risk mapping; (5) accounting controls to ensure records accurately and fairly reflect transactions and are not used to conceal bribery or corruption; (6) training for managers and employees most exposed to corruption risks; (7) a disciplinary regime applicable to employees who violate the code of conduct; and (8) an internal monitoring and evaluation mechanism to assess the effectiveness of the compliance programme. AFA may audit a company's compliance programme without prior notice, and if found deficient, may issue injunctions requiring remediation within three months. Non-compliance with an AFA injunction is subject to administrative sanctions: up to EUR 200,000 for the company and up to EUR 100,000 for the company's executives personally. Sanctions are published on AFA's website (sanction publication). Criminal sanctions for acts of corruption (bribery - Article 433-1 Code pénal) and influence peddling (Article 434-9 Code pénal) include imprisonment of up to ten years and fines of up to EUR 1,000,000 (or twice the benefit obtained) for natural persons, and fines of up to EUR 5,000,000 (or twice the benefit) for legal persons, together with the obligation to implement a compliance programme under judicial supervision. The CJIP (Convention Judiciaire d'Intérêt Public, French deferred prosecution agreement) under Article 41-1-2 of the Code de procédure pénale (introduced by Sapin II) allows companies to settle corporate corruption investigations without conviction in exchange for a fine and implementation of an AFA-monitored compliance programme.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "oecd-beps-action-13-cbcr-guidance-2023-update"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "france-anj-online-gambling-loi-2010-476",
    "title": "France Loi 2010-476 / ANJ - Online Gambling Regulation (Autorité Nationale des Jeux)",
    "domain": "Gaming & Gambling",
    "version": "2.0.0",
    "last_updated": "2020-01-01",
    "bluf": "France's online gambling framework (Loi n° 2010-476) opened sports betting, horse racing, and online poker to competition under ANJ licensing while maintaining La Francaise des Jeux's monopoly on casino games and slot machines; operators must hold an ANJ license, comply with MARIANNE self-exclusion, TRACFIN AML reporting above EUR 2,000, and LNE technical certification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021",
      "responsible-gambling-grb-standards-2023",
      "eu-5amld-article-2-gambling-2018",
      "eu-gdpr-online-gaming-data-protection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "france-ceseda-code-entree-sejour-etrangers",
    "title": "France Code de l'Entree et du Sejour des Etrangers - CESEDA Immigration Framework",
    "domain": "Immigration & Border Control",
    "version": "3.1",
    "last_updated": "2026-05-10",
    "bluf": "The Code de l'entree et du sejour des etrangers et du droit d'asile (CESEDA) consolidates all French immigration and asylum law. The 2023 Immigration Act (Loi Asile-Immigration) substantially amended the Code, introducing faster deportation procedures, mandatory 24-hour administrative detention following release from criminal custody, and a stricter framework for irregular migrants. Titre de sejour (residence permits) are issued under CESEDA L311-1 onwards in eight main categories. The Office Francais de Protection des Refugies et Apatrides (OFPRA) decides asylum claims with appeal to the Cour Nationale du Droit d'Asile (CNDA). Administrative detention under L742-1 is limited to 90 days. Deportation without prior administrative procedure is possible under L631-3 for threats to public order following criminal conviction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_directive",
        "schengen",
        "gdpr_article",
        "unhcr",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric",
      "eu-entry-exit-system-regulation-2017-2226"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "france-cnil-ai-recommendations-2024",
    "title": "France CNIL AI Development Recommendations (Phases 1 + 2, April-June 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The French data protection authority Commission Nationale de l'Informatique et des Libertes (CNIL) published its first set of AI development recommendations on April 8, 2024 (Phase 1) and an extended set on June 4, 2024 (Phase 2), with subsequent updates through the CNIL AI How-To Sheets program. The recommendations operationalise the GDPR for the design and development phases of AI systems and clarify lawful basis selection, purpose specification, lawful data collection and re-use, data subject information, security, and fundamental rights impact assessment. Key recommendations include: (1) Define a sufficiently precise purpose for the AI system at the development phase consistent with GDPR Article 5 purpose limitation; (2) Determine the legal qualification of the actors involved in development to allocate GDPR controller and processor responsibilities; (3) Identify a lawful basis under Article 6 - acknowledging that legitimate interests can lawfully underpin AI development provided rigorous balancing tests are performed and additional safeguards are implemented for high-risk processing; (4) Conduct a Data Protection Impact Assessment for high-risk AI development under Article 35; (5) Take into account fundamental rights affected by the AI system; (6) Apply data minimisation and security from the outset (privacy by design under Article 25); (7) Implement specific safeguards for training data sourced from public web scraping including respect for opt-out signals and robots exclusion. The recommendations are the French regulator operational baseline for AI compliance with GDPR.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlay",
        "nist_framework",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-10-data-governance-training",
      "eu-ai-act-article-13-transparency-high-risk-ai-instructions-use",
      "eu-ai-act-article-27-fria-fundamental-rights"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "france-code-construction-habitation-building-regulation",
    "title": "France Code de la Construction et de l'Habitation (CCH) - Building Regulation",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "France's Code de la Construction et de l'Habitation (CCH) consolidates all building, housing, and construction regulations. It governs building permits (permis de construire) through the Code de l'Urbanisme, sets energy performance requirements (RE2020 thermal regulation), fire safety, accessibility standards, and housing habitability requirements, administered by the Ministere de la Transition Ecologique and local urban planning authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-energy-performance-buildings-directive-2024",
      "eu-construction-products-regulation-2011-305"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "france-code-des-transports-maritime-seafarer-employment",
    "title": "France Code des Transports Maritime - Seafarer Employment, DGTM Flag Registration and Cabotage",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "France's Code des transports (Transport Code, consolidated in 2010) governs maritime activities in its 5th Book (Activites maritimes, Articles L5000 onwards); the maritime employment provisions (Articles L5541-L5552 for seafarer contracts, Articles L5521-L5535 for social protection) establish mandatory written seafarer employment contracts (contrats d'engagement maritime), collective bargaining agreement coverage, and ENIM (Etablissement National des Invalides de la Marine) pension and social security; the Direction generale des affaires maritimes, de la peche et de l'aquaculture (DGAMPA) is the primary authority responsible for seafarer certification, vessel registration, safety inspections, and STCW implementation; France maintains two ship registers: the Registre International Francais (RIF, created by Loi 2005-412) for flag competition with international standards, and the French Domestic Register (RF) for coastal and domestic vessels; EU cabotage Regulation 3577/92/EEC governs intra-Community maritime transport; Articles L5621-L5624 cover ship mortgages (hypotheque maritime); French-registered vessels must comply with MLC 2006 under Ordonnance 2015-1736 and SOLAS under national enforcement orders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-mlc-2006"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "france-digital-services-tax-law-2019-759",
    "title": "Loi 2019-759 du 24 juillet 2019 portant création d'une taxe sur les services numériques",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires large tech companies to pay a 3% tax on their French digital revenue, as stated in Article 1 of the law. It applies to companies with global revenues exceeding €750 million and French revenues exceeding €25 million, as specified in Article 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-atad2-hybrid-mismatches-2017-952"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "france-loi-evin-alcohol-advertising-1991",
    "title": "France Loi Evin Alcohol Advertising Restrictions 1991 - Article L3323-2 and Health Warning Requirements",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "France's Loi Evin (Law No. 91-32 of 10 January 1991 on the fight against tobacco use and alcoholism) codified in the Public Health Code Articles L3323-1 to L3323-6 restricts alcohol advertising to permitted media only (press, radio during permitted hours, hoardings/billboards, internet directed at adults) and completely prohibits alcohol advertising on television, in cinemas, in sports venues, in educational establishments, and on goods primarily purchased by minors; requires a mandatory health warning 'L'abus d'alcool est dangereux pour la sante'; enforced by the Autorite de Regulation Professionnelle de la Publicite (ARPP).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "france-pillar-two-implementation-loi-finances-2024",
    "title": "Loi de Finances pour 2024 (Loi n° 2023-1322, art. 33) - Transposition en droit français du régime GloBE (Pilier Deux de l'OCDE) : impôt complémentaire codifié aux articles 223 VJ à 223 WZ du CGI, IIR, QDMTT et déclaration d'information GloBE auprès de la DGFiP",
    "domain": "Tax & Transfer Pricing",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "Article 33 of Loi n° 2023-1322 du 29 décembre 2023 de finances pour 2024 transposes EU Directive (UE) 2022/2523 (the OECD Pillar Two GloBE rules) into French law, effective for fiscal years opened on or after 31 December 2023. The rules are codified in the French General Tax Code (CGI) at Articles 223 VJ to 223 WZ. They impose a 15% minimum effective tax rate, computed by jurisdiction, on constituent entities of multinational and large domestic groups with consolidated revenue of at least EUR 750 million in at least two of the four preceding fiscal years, through a supplementary tax (impot complementaire). France applies the Income Inclusion Rule (IIR), a Qualified Domestic Minimum Top-up Tax (QDMTT) and the Undertaxed Profits Rule (UTPR), with an annual GloBE Information Return filed with the DGFiP. Note: CGI Article 238 bis governs corporate mecenat (charitable donations) and is unrelated to the global minimum tax.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-global-minimum-tax-directive-2022-2523-pillar-two",
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "australia-transfer-pricing-laws-amendment-2012"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "france-psan-crypto-registration-amf-2023",
    "title": "France PSAN Digital Asset Service Provider Registration 2023 - AMF-Enforced: Mandatory Registration for AML/CFT, Optional Licence for Full Activities, Travel Rule Compliance, Consumer Warnings, MiCA Transition Plan and Grandfathering Arrangements",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Digital Asset Service Providers (DASPs) providing custody, trading, or exchange services involving legal tender or operating a trading platform must mandatorily register with the AMF under Article L. 54-10-2 of the Monetary and Financial Code. Foreign and domestic entities established in France may also seek optional licensing subject to organisational, financial, and conduct requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "eu-dlt-pilot-regime-2022-858",
      "bis-iosco-pfmi-applied-to-dlt-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "france-right-to-disconnect-2017",
    "title": "Labour Code Article L2242-17 - Right to Disconnect (Loi Travail / El Khomri Law, 2017)",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "French companies with 50 or more employees must negotiate and implement a policy defining the right to disconnect from digital tools outside working hours. This obligation is established under Article L2242-17 of the French Labour Code, introduced by the El Khomri Law of 2017.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-fair-work-act-2009",
      "cipd-hr-standards",
      "ebsa-cybersecurity-best-practices"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "france-space-operations-act-2008-loi-078",
    "title": "Loi n° 2008-518 du 3 juin 2008 relative aux opérations spatiales",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The France Space Operations Act 2008 (Loi 2008-518) establishes a legal framework for authorizing and supervising all space operations launched from French territory or by French operators abroad, including launch, in-orbit operation, and re-entry. It mandates prior authorization from CNES (Article L. 233-1), imposes strict liability on operators for third-party damage (Article L. 233-6), and requires financial guarantees and risk mitigation plans.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-liability-convention-1972-space-objects",
      "esa-convention-1975-european-space-agency"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "frb-sr-11-7-model-risk-management",
    "title": "FRB SR 11-7 Supervisory Guidance on Model Risk Management",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Federal Reserve and OCC joint supervisory guidance SR 11-7 requires banking organizations to implement comprehensive model risk management covering model inventory, risk tiering, independent validation with three core elements (conceptual soundness, ongoing monitoring, outcomes analysis), and board-level governance for all quantitative models used in decision-making.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dodd-frank-act-2010"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "frb-sr-21-19-counterparty-credit-risk",
    "title": "The Federal Reserve reminds firms of safe and sound practices for counterparty credit risk management in light of the Archegos Capital Management default",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-01-09",
    "bluf": "In light of the Archegos Capital Management default, which caused over $10 billion in losses across several large banks, the Federal Reserve is issuing guidance to remind firms of supervisory expectations for counterparty credit risk management. This letter is intended for use by banking organizations with large derivatives portfolios and relationships with investment funds, as well as for supervisors. It is generally not applicable to community banking organizations. The guidance addresses concerns with practices where firms accept incomplete and unverified information from investment funds, particularly regarding strategy, concentrations, and relationships with other market participants.\n\nThe core obligations emphasize that firms should obtain and verify critical information regarding a fund's size, leverage, and concentrated positions. If a client refuses to provide this information, firms should reconsider the relationship or apply strong compensating measures, such as more stringent contractual terms. The Federal Reserve also reminds firms that poor communication frameworks, inadequate risk management functions, and ineffective governance hamper their ability to identify and address risk. Firms must ensure risk management functions have the experience and stature to control risks, and that margin terms are appropriate, risk-sensitive, and do not prevent the firm from improving its margin position or closing out positions quickly.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-large-exposures-framework",
      "principles-effective-risk-data-aggregation",
      "bcbs-principles-sound-management-operational-risk",
      "interagency-guidance-third-party-risk-management",
      "sr-11-7-model-risk-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "freight-forwarder-fiata",
    "title": "Freight Forwarding Ethics (FIATA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Freight forwarding operations must exhibit strict adherence to a comprehensive ethical framework grounded in international standards. All engagements mandate `requires_fiata_standard_documents`, with the legal basis for the FIATA FBL established by the UNCTAD/ICC Rules for Multimodal Transport Documents, and all electronic versions necessitate `digital_fbl_signature_validation`. In accordance with the FIATA Model Rules for Freight Forwarding Services, carrier liability for goods is strictly circumscribed, establishing a `max_permitted_liability_sdr_per_kg` of 2. A robust anti-corruption posture is non-negotiable, evidenced by an `anti_bribery_certification_active` status and conformance with principles from the FIATA Code of Business Conduct and Anti-Corruption Advisory. This posture must account for the extraterritorial reach of the US Foreign Corrupt Practices Act and UK Bribery Act 2010, demanding a rigorous `subcontractor_audit_frequency_months` cycle of 12. Security protocols must align with the WCO SAFE Framework of Standards, necessitating diligent `requires_kyc_shipper_verification` for all clients. To prevent illicit trade, continuous screening of all parties against the United Nations Security Council Consolidated Sanctions List must occur within a `sanctions_screening_interval_hours` of 24. Further operational prerequisites include mandatory `hazardous_materials_declaration_required` submissions, verification that `antitrust_compliance_training_completed` is current, and ensuring `environmental_impact_reporting_enabled` is active. For auditability, all commercial records are subject to a `data_retention_commercial_docs_years` term of 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wco-safe-framework",
      "iso-37001-anti-bribery-2016",
      "iso-28000-supply-chain",
      "c-tpat-minimum-security",
      "iata-dangerous-goods",
      "icc-incoterms-master"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fsb-ai-machine-learning-financial-services-2017",
    "title": "FSB Artificial Intelligence and Machine Learning in Financial Services - Compliance Obligations for Systemic Risk from AI Adoption, AI Concentration Risk, and Financial Stability AI Governance for Global Systemically Important Institutions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations for financial institutions adopting AI and machine learning, focusing on systemic risk mitigation, concentration risk management, and governance as per FSB guidelines. It aligns with EU AI Act (Regulation 2024/1689) high-risk AI system requirements under Articles 9 and 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fsb-cross-border-payments-roadmap-g20-crypto",
    "title": "Assessment of Risks to Financial Stability from Crypto-assets",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation assesses risks to global financial stability arising from crypto-asset markets and outlines the Financial Stability Board's framework for monitoring and supervising such risks, particularly for systemically important stablecoins. It applies to financial authorities and international standard-setting bodies overseeing crypto-asset activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bis-iosco-pfmi-applied-to-dlt-systems",
      "bis-cpmi-cross-border-payments-2023",
      "eu-dlt-pilot-regime-2022-858"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fsb-crypto-asset-framework-2023",
    "title": "FSB High-Level Recommendations for the Regulation, Supervision, and Oversight of Crypto-Asset Activities and Markets (2023)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a global framework for the prudential regulation and oversight of crypto-asset activities, particularly targeting global stablecoins (GSCs), requiring comprehensive supervision, cross-border cooperation, and mitigation of concentration risks and conflicts of interest in crypto-asset conglomerates. Key requirements are derived from the 'same risk, same regulation' principle as articulated in the FSB's 2023 finalised recommendations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bis-cpmi-cross-border-payments-2023",
      "bis-iosco-stablecoin-guidance-pfmi-2022",
      "bis-crypto-asset-prudential-standards",
      "crypto-aml-travel-rule",
      "bahamas-dare-act-2020-digital-assets"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fsb-crypto-asset-regulatory-framework-2023",
    "title": "FSB Global Regulatory Framework for Crypto-Asset Activities: High-Level Recommendations",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This framework establishes nine high-level recommendations for the regulation, supervision, and oversight of crypto-asset activities and markets, applying the principle of 'same activity, same risk, same regulation' to crypto-asset issuers and service providers (CASPs) to address financial stability risks. Recommendation 1 mandates that regulatory frameworks should be comprehensive and risk-based.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mica-stablecoin-reserve",
      "crypto-aml-travel-rule",
      "gfsr-crypto-financial-stability-challenges"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fsb-crypto-regulatory-framework-2023",
    "title": "FSB Global Regulatory Framework for Crypto-Asset Activities 2023 - High-Level Recommendations for Crypto-Asset Markets, Activities and Global Stablecoin Arrangements",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes a global framework for the regulation, supervision, and oversight of crypto-asset activities and global stablecoin arrangements, based on the principle of 'same activity, same risk, same regulation'. It applies to crypto-asset issuers, service providers, and global stablecoin arrangements posing potential financial stability risks, with strengthened requirements on client asset safeguarding, conflict of interest management, and cross-border cooperation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "accounting-ifr-13"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "fsb-key-attributes-res",
    "title": "FSB Key Attributes (Resolution)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The FSB Key Attributes of Effective Resolution Regimes for Financial Institutions are the international standards for the orderly resolution of failing systemically important financial institutions (SIFIs). it provides the mandatory powers and tools for national authorities to resolve banks without taxpayer bailouts, ensuring the continuity of the critical functions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-committee-response-financial-crisis",
      "basel-iii-global-regulatory-framework",
      "dodd-frank-volcker-rule",
      "bcbs-principles-operational-resilience",
      "ifrs-9-impairment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fsb-nbfi-leverage-recommendations-2025",
    "title": "Financial Stability Board - Leverage in Nonbank Financial Intermediation: Final Report",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Published by the Financial Stability Board on 9 July 2025, this final report sets nine policy recommendations to address financial stability risks from leverage in nonbank financial intermediation, organised across risk identification and monitoring, leverage in core markets, counterparty credit risk, regulatory incongruencies, and cross-border cooperation, on the basis that leverage in NBFI can be an important amplifier of stress.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fsb-key-attributes-res",
      "basel-iii-global-regulatory-framework",
      "basel-iii-liquidity-lcr"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fsb-tcfd-banking-disc",
    "title": "FSB TCFD (Banking)",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The TCFD (Task Force on Climate-related Financial Disclosures) Banking Sector Disclosures provide a specific framework for banks to report on the financial implications of the climate change. it requires detailed transparency on how banks identify, assess, and manage the 'Physical' and 'Transition' risks within their lending and investment portfolios, ensuring the global market stability during the green transition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "tcfd-climate-risk",
      "bcbs-climate-related-financial-risks",
      "ifrs-s2-climate",
      "ghg-protocol-scope3",
      "csrd-eu-sustainability",
      "sec-climate-disclosure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "fsc-chain-of-custody",
    "title": "FSC Chain of Custody (STD-40-004)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with the Forest Stewardship Council's standard for Chain of Custody Certification, FSC-STD-40-004 V3-1, necessitates a verifiable control system for tracking certified materials throughout production and trade. Organizations must implement a `management_system_documented` in full, encompassing a `material_accounting_system_active` and a clearly `fsc_volume_control_method_defined` to manage inputs and outputs. Critical to this system is the monitoring of conversion factors, where variance cannot exceed a `max_conversion_factor_variance_percent` of five. Comprehensive record-keeping is mandated, with a `record_retention_years_min` of five years, and an `annual_volume_summary_required` must be compiled for reconciliation. All `sales_documents_include_fsc_claim` information must accurately reflect product status, supported by a robust `nonconforming_product_procedure_active`. Adherence extends to external requirements, including `fsc_trademark_use_approved` as specified in FSC-STD-50-001 V2-1, and risk mitigation for uncertified inputs per FSC-STD-40-005 V3-1 for Sourcing Controlled Wood. As stipulated by Part IV of the core standard and the Directive on Chain of Custody Certification, FSC-DIR-40-004, firms must ensure `core_labor_requirements_met` status and maintain an `occupational_health_safety_active` program. The successful implementation of a `supply_chain_due_diligence_active` system is foundational, aligning with evolving regulations like the European Union Deforestation Regulation (EUDR) 2023/1115.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-14001-ems",
      "iso-28000-supply-chain",
      "ilo-core-conventions",
      "iso-45001-work-safety",
      "iso-20400-sustainable-procure"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fssc-22000-food-pack",
    "title": "FSSC 22000 (Food Packaging)",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "FSSC 22000 certification for food packaging manufacturers establishes a comprehensive framework for food safety management, recognized by the Global Food Safety Initiative. Compliance necessitates an organization's full implementation and certification of a Food Safety Management System (FSMS) according to the requirements of ISO 22000:2018. This system must be built upon a foundation of prerequisite programs (PRPs) specifically designed for packaging, as detailed in ISO/TS 22002-4:2013. A core operational component is an active, continually validated HACCP plan developed from Codex Alimentarius principles. Beyond these core standards, FSSC 22000 Scheme Version 6 mandates several additional requirements for demonstrable control. These include an active allergen management control program to mitigate cross-contact risks and an active, risk-based environmental monitoring program. Organizations must also execute a TACCP-based food defense threat assessment and a corresponding VACCP-based food fraud vulnerability assessment. Operational integrity requires a robust traceability system, tested for effectiveness at least every 12 months, alongside formal supplier performance reviews conducted with a minimum frequency of every 12 months. Reflecting modern risks, active security controls for ICT and SCADA systems are mandatory, supported by data integrity protocols ensuring backups occur at least every 24 hours. The entire framework is underpinned by a formal, implemented Food Safety Culture Plan designed to influence positive behavioral change across the organization, aligning with GFSI Benchmarking Requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-22000-food-mgt",
      "haccp-food-safety",
      "gfsi-benchmarking",
      "codex-alimentarius-gen",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "fssc-22000-v6-food-safety",
    "title": "FSSC 22000 Version 6 (2023) - ISO 22000 Based Food Safety System Certification Scheme Requirements",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "FSSC 22000 Version 6 is a GFSI-recognized certification scheme requiring food supply chain organizations to implement a robust Food Safety Management System (FSMS). It integrates ISO 22000:2018, sector-specific Prerequisite Programs (PRPs), and additional requirements focusing on food safety and quality culture, allergen management, and food fraud prevention, as detailed in FSSC 22000 Scheme Part 2, Section 2.5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-22000-food-mgt",
      "haccp-food-safety",
      "gfsi-benchmarking",
      "codex-alimentarius-gen",
      "food-allergen-label-law"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ftc-ai-enforcement-guidance",
    "title": "FTC Artificial Intelligence Enforcement Guidance - Deceptive and Unfair AI Practices (Section 5 FTC Act)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This guidance clarifies that the Federal Trade Commission (FTC) will apply Section 5 of the FTC Act to combat deceptive or unfair practices involving AI, holding companies accountable for false claims about AI capabilities and for AI-driven outcomes that cause substantial, unavoidable consumer injury.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-language-of-trustworthy-ai",
      "nistir-8312-explainable-ai-principles",
      "iso-42001-improvement"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ftc-digital-advertising-disclosures",
    "title": "How to Make Effective Disclosures in Digital Advertising",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2013-03-12",
    "bluf": "The general principles of advertising law apply online, and this guidance addresses how businesses can develop ads for online media in compliance with the law. The same consumer protection laws applicable to other media apply online, including the mobile marketplace. The FTC Act’s prohibition on “unfair or deceptive acts or practices” encompasses all online advertising, marketing, and sales. The core obligation for advertisers is to ensure that products and services are described truthfully and that consumers understand what they are paying for.\n\nRequired disclosures must be clear and conspicuous. To meet this standard, advertisers must consider a disclosure's placement and proximity to the relevant claim, its prominence, and whether it is unavoidable. Other factors include whether distractions in the ad diminish the disclosure's effectiveness, the need for repetition, the adequacy of volume and cadence for audio disclosures, sufficient duration for visual disclosures, and the use of understandable language. If a disclosure is necessary to prevent an ad from being deceptive or unfair, and it is not possible to make that disclosure clearly and conspicuously on a particular platform, then that platform should not be used to disseminate the advertisement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-endorsement-guides",
      "can-spam-act-email",
      "coppa-marketing-kids",
      "ama-ethical-marketing",
      "prsa-code-of-ethics",
      "iab-tcf-v2-2-consent"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ftc-endorsement-guides",
    "title": "FTC (Endorsement Guides)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "An evaluation of this endorsement content reveals a significant compliance failure under Federal Trade Commission authority, as established by Section 5(a) of the FTC Act, which prohibits unfair or deceptive practices. Pursuant to 16 CFR § 255.5, the existing material connection between the endorser and advertiser necessitates a disclosure that is both clear and conspicuous. This content violates that standard because the `material_connection_disclosed` parameter is false, constituting a deceptive omission. Furthermore, the analysis indicates the `disclosure_clear_and_conspicuous` requirement has not been met, as any potential disclosure is not `unavoidable_before_engagement` for consumers and the language used is ambiguous. Operational guidance from documents like the FTC's 'Disclosures 101 for Social Media Influencers' demands explicit markers which are difficult to miss; the confirmed absence of a `video_includes_superimposed_disclosure` or an `audio_includes_spoken_disclosure` exemplifies this critical deficiency. While the review confirms the message `reflects_honest_opinion_or_experience` from an `endorser_bona_fide_user` and that `substantiated_performance_claims` are present, consistent with principles in 16 CFR § 255.1 and 16 CFR § 255.2, these positive factors do not mitigate the primary violation. The communication satisfies the 'endorsement' definition from 16 CFR § 255.0, but its lack of proper disclosure renders it misleading. Despite an `advertiser_monitoring_program_active` status, this specific execution remains non-compliant and poses significant regulatory risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-digital-advertising-disclosures",
      "can-spam-act-email",
      "coppa-marketing-kids",
      "ccpa-cpra-optout-sale",
      "prsa-code-of-ethics",
      "ama-ethical-marketing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ftc-endorsement-guides-2023",
    "title": "Guides Concerning the Use of Endorsements and Testimonials in Advertising (16 C.F.R. Part 255) - 2023 Update",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The FTC's 2023 updated Endorsement Guides (16 C.F.R. § 255.5) require advertisers and endorsers, including social media influencers and review platforms, to clearly and conspicuously disclose any material connections that might affect the weight or credibility of an endorsement, ensuring all endorsements are honest, not misleading, and substantiated.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-endorsement-guides",
      "ftc-digital-advertising-disclosures",
      "eu-omnibus-directive-2019-2161",
      "coppa-marketing-kids"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ftc-facing-facts-facial-recognition",
    "title": "Facing Facts: Best Practices For Common Uses of Facial Recognition Technologies",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2012-10-31",
    "bluf": "In October 2012, the Federal Trade Commission's Bureau of Consumer Protection issued a staff report titled 'Facing Facts: Best Practices For Common Uses of Facial Recognition Technologies.' This report establishes recommended best practices for companies that use facial recognition technologies to promote consumer protection and safeguard consumer privacy. The guidance addresses key issues within privacy and security, focusing on responsible data handling and transparency for common commercial uses of these technologies. It encourages businesses to implement privacy-by-design, be transparent about their data practices, provide consumers with appropriate choices, and secure the data they collect and maintain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-122-pii",
      "sec-regulation-s-p-safeguarding"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ftc-negative-option-rule-2024-click-to-cancel",
    "title": "FTC Negative Option Rule 2024 Subscription Cancellation and Disclosure Requirements",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The FTC Negative Option Rule (16 CFR Part 425, finalized October 2024, effective January 2025) prohibits deceptive negative option marketing by requiring clear and conspicuous disclosure of all material subscription terms before consumer consent, express informed written consent before any charge, a simple click-to-cancel mechanism as easy as sign-up, and annual reminders for continuous subscriptions - with civil penalties up to USD 51,744 per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "fundamental-review-of-the-trading-book",
    "title": "Fundamental review of the trading book",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2012-05-31",
    "bluf": "This consultative document presents the initial policy proposals emerging from the Basel Committee’s fundamental review of trading book capital requirements, intended to strengthen capital standards for market risk and contribute to a more resilient banking sector. The review was initiated because the financial crisis exposed material weaknesses in the design of the framework for capitalising trading activities, where the level of capital proved insufficient to absorb losses. The proposals address shortcomings in the overall design of the regime as well as weaknesses in risk measurement under both the internal models-based and standardised approaches.\n\nThe Committee's key areas of focus include a reassessment of the trading book/banking book boundary, with proposals for a \"trading evidence-based\" or a \"valuation-based\" boundary. It intends to move to a capital framework that is calibrated to a period of significant financial stress. A significant proposal is moving from Value-at-Risk (VaR) to Expected Shortfall (ES) to better capture \"tail risk\". The proposals also seek a comprehensive incorporation of the risk of market illiquidity, using \"liquidity horizons\" defined as the time required to exit or hedge a risk position in a stressed market. The Committee is also considering the treatment of hedging and diversification, and strengthening the relationship between the standardised and internal models-based approaches, potentially by introducing the standardised approach as a floor.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-committee-response-financial-crisis",
      "basel-ii-capital-framework",
      "basel-iii-global-regulatory-framework",
      "dodd-frank-volcker-rule",
      "sr-11-7-model-risk-management",
      "principles-effective-risk-data-aggregation"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "g20-ai-principles-2019",
    "title": "G20 AI Principles: Human-Centred AI Values, Accountability and International Co-operation",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-06-09",
    "bluf": "Endorsed by G20 leaders at the 2019 Osaka Summit, these non-binding principles provide a framework for the responsible stewardship of trustworthy AI, based on the OECD AI Principles. They call on AI actors to respect human-centred values and the rule of law (Principles 1.1-1.5) and recommend that governments foster a policy environment that supports trustworthy AI through investment, co-operation, and enabling frameworks (Principles 2.1-2.5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "g7-hiroshima-ai-process-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "g20-ai-principles-osaka-track-2019",
    "title": "G20 AI Principles (Osaka Track) - International Compliance Obligations for Responsible AI, AI Transparency and Explainability, and G20 Member State Commitments to OECD-Aligned AI Governance Frameworks",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations under the G20 AI Principles (Osaka Track 2019) for responsible AI development, focusing on transparency, explainability, and human-centric values, with overlapping requirements in the EU AI Act (Regulation (EU) 2024/1689, Articles 13 and 50). It aligns with OECD AI governance frameworks for G20 member states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "oecd-ai-principles",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "g7-hiroshima-ai-process-2023",
    "title": "G7 Hiroshima AI Process International Code of Conduct for Organizations Developing Advanced AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2023-10-30",
    "bluf": "This voluntary code of conduct establishes 11 guiding principles for organizations developing the most advanced AI systems, including foundation models and generative AI, to promote safety, security, and trustworthy AI. It requires organizations to take appropriate measures throughout the AI lifecycle, from design to deployment, to identify, evaluate, and mitigate risks, as outlined in Principles 1 through 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "unesco-ethics-ai",
      "nist-ai-100-2-aml-taxonomy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "g7-hiroshima-ai-process-2023-code-conduct",
    "title": "G7 Hiroshima AI Process - International Guiding Principles and Code of Conduct 2023: 11 Principles for Advanced AI Developers, Voluntary Code of Conduct (11 Actions), Incident Reporting, Watermarking, Bias/Discrimination Mitigation and Cross-Border AI Governance Cooperation",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes 11 voluntary guiding principles and a corresponding Code of Conduct for advanced AI developers within G7 nations, focusing on risk mitigation, transparency, and international cooperation. It applies to organizations developing foundational or frontier AI systems with significant societal impact potential.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-ai-safety-2023",
      "australia-voluntary-ai-safety-standard-2024",
      "anthropic-responsible-scaling-policy-v2-1-2025"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "g7-hiroshima-ai-process-guiding-principles",
    "title": "G7 Hiroshima AI Process - Guiding Principles and Code of Conduct for Advanced AI",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The G7 Hiroshima AI Process, launched at the May 2023 G7 Leaders' Summit and producing the International Guiding Principles on Advanced AI Systems and the G7 Code of Conduct for AI Developers published in October 2023, established the first G7-level voluntary governance framework for advanced AI - the eleven Guiding Principles cover transparency, accountability, information sharing on AI incidents, identification of AI-generated content, cybersecurity of AI systems, trustworthy AI research, AI governance frameworks, reporting and monitoring, risk management, protection of intellectual property, and promotion of responsible AI globally; the voluntary Code of Conduct operationalises these principles for AI developers through specific commitments on safety testing, bias and fairness, data protection, risk management, and stakeholder engagement; while voluntary, the Hiroshima Process commitments are significant for AI providers seeking to demonstrate international responsible AI leadership and are increasingly referenced in procurement and enterprise AI governance frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/g7-hiroshima-ai-process-guiding-principles.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-53-gpai-codes-of-practice",
      "eu-ai-act-article-55-systemic-risk-gpai",
      "eu-ai-act-article-15-robustness",
      "coe-framework-convention-ai-human-rights-democracy"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ga-pdp-law-2011",
    "title": "Gabon Personal Data Protection Law - CNPDP Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Gabon Law No. 001/2011 on Protection of Personal Data establishes consent-based processing obligations, data subject rights, and mandatory data controller registration. The Commission Nationale pour la Protection des Données Personnelles (CNPDP) is the designated supervisory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ga4gh-framework-v2-genomics-standards",
    "title": "GA4GH Framework for Responsible Sharing of Genomic and Health-Related Data (Version 2)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2019-10-01",
    "bluf": "The Global Alliance for Genomics and Health (GA4GH) is an international, non-profit standards body that produces technical and policy standards for the responsible sharing of genomic and health-related data. The GA4GH Framework for Responsible Sharing of Genomic and Health-Related Data (the Framework) was first published in 2014 and revised as Version 2 in 2019 and is the foundational policy document for GA4GH standards work. The Framework establishes five core foundational principles (respect individuals, families and communities; advance research and scientific knowledge; promote health, wellbeing and the fair distribution of benefits; foster trust, integrity and reciprocity; recognise and address ethical, legal and social issues) and operational principles for transparency, accountability, engagement, risk-benefit analysis, quality and security, and privacy.\n\nGA4GH technical standards used worldwide include the Variant Call Format (VCF), the GA4GH Data Use Ontology (DUO), the Beacon API for federated discovery, the Data Repository Service (DRS), the Workflow Execution Service (WES), the Tool Registry Service (TRS), the htsget protocol for streaming genomic data, the Phenopackets v2 standard, and the Refget standard for reference sequences. GA4GH operates a working-group based standards process across eight Work Streams: Clinical and Phenotypic Data Capture; Cloud; Data Security; Data Use and Researcher Identities; Discovery; Genomic Knowledge Standards; Large Scale Genomics; and Regulatory and Ethics. GA4GH standards are increasingly referenced in national biobanking and genomic data frameworks including the NIH Genomic Data Sharing Policy, the EU Health Data Space, the UK Genome UK Strategy, and Japan AMED BioBank Japan.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nih-genomic-data-sharing-policy-2014-2024-update",
      "oecd-guidelines-human-biobanks-2009"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "gaap-us-framework",
    "title": "US GAAP Framework",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "United States Generally Accepted Accounting Principles establish the definitive standards for financial accounting and reporting as promulgated by the Financial Accounting Standards Board. This framework mandates a systematic evaluation of an entity's adherence to core tenets through a series of qualitative verifications and quantitative assessments. Compliance requires confirmation that the `revenueRecognitionPrincipleMet` aligns with performance obligations and that the `matchingPrincipleApplied` correctly aligns expenses with revenues. Furthermore, the evaluation validates whether the `fullDisclosurePrincipleFollowed` ensures transparency and if the `historicalCostPrincipleUsed` is appropriately maintained for asset valuation. Specific procedural checks confirm if `inventoryValuationMethodConsistent` application is present and that `assetDepreciationCalculated` follows acceptable methodologies. The framework’s integrity also rests on foundational assumptions, such as verifying the `goingConcernAssumptionValid` status for the reporting entity. A critical output is the boolean determination `isMaterialMisstatementDetected`, which signals significant reporting inaccuracies. The node quantifies compliance through several metrics, including the total `requiredFinancialStatementsGenerated`, an `internalControlsEffectivenessRating` score, and a final `auditTrailIntegrityScore` to measure the immutability and completeness of financial records. These combined checks provide a comprehensive attestation of conformity with authoritative accounting standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-code-ethics",
      "pcaob-audit-standards",
      "sarbannes-oxley-404",
      "ifrs-global-accounting"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gcc-health-data-harmonization-2026",
    "title": "GCC Health Data Harmonization Framework & Cross-Border Sharing (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The Gulf Cooperation Council (GCC) Health Data Harmonization Framework promotes interoperability, unified standards for electronic health records, and secure cross-border data sharing while respecting national sovereignty. It aligns with UAE, Saudi, and other member state laws on sensitive health data, requiring explicit consent, minimum necessary sharing, strong encryption, and breach coordination through the GCC Health Council.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "saudi-arabia-sfda-digital-health-2026"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "gcc-unified-cybersecurity-framework",
    "title": "GCC Unified Gulf Strategy for Cybersecurity - Gulf Cooperation Council Regional Cybersecurity Cooperation: Five-Pillar Strategy and Cross-Border Cyber Coordination",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The Gulf Cooperation Council (GCC) does not maintain a single binding, GCC-wide cybersecurity framework with numbered controls. Its regional instrument is the non-binding Unified Gulf Strategy for Cybersecurity, built on five pillars: strong and resilient defences; effective governance and standards; awareness; collective defence (partnership and cooperation); and cyber workforce development. The strategy is complemented by regional coordination initiatives such as joint cyber exercises and early-warning platforms (reaffirmed through the 2025 Doha Forum cybersecurity initiative). Because the strategy is advisory at the GCC level, binding cybersecurity obligations are set by each member state's national authority (for example Saudi Arabia's NCA Essential Cybersecurity Controls, the UAE, Qatar, Bahrain, Kuwait and Oman national authorities). This node maps organisational practices to the five strategy pillars; it does not assert binding GCC-wide control numbers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "c-scrm-practices-systems-organizations",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gd-money-laundering-prevention-act",
    "title": "Grenada Money Laundering (Prevention) Act (Cap. 197A)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "Grenada's Money Laundering (Prevention) Act (Cap. 197A) creates the offence of money laundering (Section 3) and prohibits tipping off (Section 6), establishes a Supervisory Authority with powers and functions (Sections 11 and 12) and a Code of Practice (Section 13), imposes obligations on financial institutions (Section 14), requires reporting of suspicious business transactions (Section 15) and other measures to avoid money laundering (Section 19), and requires currency declarations (Section 20).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gd-pia-2014",
    "title": "Grenada Personal Information Act 2014",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Grenada enacted the Personal Information Act 2014, a CARICOM and OECS-aligned statute establishing a rights-based framework for the protection of personal information held by organisations. The Act is administered by a Privacy Commissioner and establishes principles of fair collection, purpose limitation, accuracy, retention limits, security safeguards, and individual participation. Data subjects have rights of access and correction. Sensitive personal information (health, racial origin, political opinions, religious beliefs, criminal history) requires explicit consent or a statutory condition. Cross-border transfers are restricted to jurisdictions providing comparable protection. The Act applies to organisations established in Grenada or processing personal information of persons in Grenada.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/gd-pia-2014.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gd-proceeds-of-crime-act",
    "title": "Grenada Proceeds of Crime Act (Cap. 256A)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "Grenada's Proceeds of Crime Act (Cap. 256A) provides for confiscation of the proceeds of drug trafficking and relevant offences (Sections 9 and 10), restraint and charging orders to preserve realisable property (Sections 27 to 29), protection of third party rights (Section 16), disclosure of knowledge or suspicion of money laundering (Section 46) with penalties for money laundering (Section 49), and seizure and detention of cash imported or exported with forfeiture orders (Sections 51 and 52).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-3-money-laundering-offence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-10-customer-due-diligence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-adequacy-decisions-article-45",
    "title": "General Data Protection Regulation (GDPR) - Article 45: Transfers on the basis of an adequacy decision",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Under GDPR Article 45, personal data may be transferred from the EU/EEA to a third country or international organization without specific authorization if the European Commission has formally decided that the recipient country ensures an adequate level of data protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brazil-lgpd-compliance",
      "korea-pipa-standard",
      "za-popia-2013"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-art-21-marketing-optout",
    "title": "GDPR Art 21 (Opt-out)",
    "domain": "Data Protection & Privacy",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "GDPR Article 21 grants data subjects an absolute right to object to the processing of their personal data for direct marketing purposes. When a `data_subject_objected` flag is triggered within a context where `is_direct_marketing_context` is true, which explicitly includes instances of `is_profiling_for_marketing`, the organization must cease all related processing activities. As stipulated by GDPR Recital 70 and Article 21(3), this right is unconditional; consequently, the schema configuration `allow_legitimate_interest_override` is set to false, meaning no compelling legitimate grounds can supersede the data subject's objection. The cessation must be immediate, reflected by the `halt_processing_immediate` parameter being true. Compliance with the request, as mandated by GDPR Article 12(3), must occur without undue delay and within a maximum timeframe of `max_response_time_days` set to 30. Reinforcing GDPR Recital 70 and principles from the ePrivacy Directive, no charge may be levied, with `fee_applicable_euros` fixed at 0. To ensure the objection's effectiveness, the data subject's details must be placed on a suppression list (`add_to_suppression_list` is true) and their marketing consent state must be locked (`lock_marketing_consent_state` is true) to prevent future processing for these purposes. Furthermore, the obligation extends to downstream entities, requiring that organizations `notify_third_party_processors` of the objection. The obligation to explicitly and clearly present this right, separate from other information per GDPR Article 21(4), underscores its importance, and for this specific action, `require_strict_identity_verification` is configured as false to minimize friction in exercising this fundamental right.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eprivacy-cookie-directive",
      "iab-tcf-v2-2-consent",
      "can-spam-act-email",
      "casl-anti-spam-canada",
      "ccpa-cpra-optout-sale"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-10-personal-data-criminal-convictions-offences",
    "title": "General Data Protection Regulation (GDPR) - Article 10: Processing of personal data relating to criminal convictions and offences",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations must only process personal data on criminal convictions and offences if it is under the control of an official authority or authorized by Union or Member State law with appropriate safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-11-processing-not-requiring-identification",
    "title": "General Data Protection Regulation (GDPR) Article 11: Processing which does not require identification",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations are not required to obtain or maintain identifying information on data subjects solely to comply with the GDPR if their processing purposes do not otherwise require such identification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-12-transparent-information-communication",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 12: Transparent information, communication and modalities for the exercise of the rights of the data subject",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must provide data subjects with clear, concise, and easily accessible information about data processing and facilitate the exercise of their rights in a timely and generally free-of-charge manner.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-article-13-information-data-collected-directly",
    "title": "General Data Protection Regulation (GDPR) - Article 13: Information to be provided where personal data are collected from the data subject",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Controllers must provide data subjects with specific information about the processing of their personal data at the time of collection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-37-dpo",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-article-14-information-data-not-obtained-directly",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 14: Information to be provided where personal data have not been obtained from the data subject",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations must provide data subjects with specific information about the processing of their personal data when that data has been obtained from a source other than the data subject themselves.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-article-15-right-of-access",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, Article 15",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article grants data subjects the right to obtain confirmation from the controller as to whether or not personal data concerning them is being processed, and, where that is the case, access to that personal data and related information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-16-right-to-rectification",
    "title": "REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) - Article 16 Right to rectification",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "The data subject has the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-17-right-erasure",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) - Article 17: Right to erasure (‘right to be forgotten’)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Under Article 17 of the EU GDPR, data subjects have the right to obtain from the controller the erasure of their personal data without undue delay, provided one of several specific grounds applies, such as the data no longer being necessary for its original purpose or the withdrawal of consent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "california-ccpa-v2",
      "uk-retained-gdpr",
      "brazil-lgpd-compliance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-article-18-right-to-restriction-of-processing",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation), Article 18",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article grants data subjects the right to obtain from the controller the restriction of processing of their personal data under specific circumstances, requiring the data to be marked and its processing limited.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-19-notification-obligation-rectification-erasure-restriction",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, Article 19",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "The controller must communicate any rectification, erasure, or restriction of processing to each recipient to whom personal data was disclosed, unless this is impossible or involves disproportionate effort, and must inform the data subject about these recipients upon request.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-20-right-to-data-portability",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data - Article 20 - Right to data portability",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article grants data subjects the right to receive their personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller without hindrance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-21-right-to-object",
    "title": "REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) - Article 21: Right to object",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must provide data subjects with the right to object to the processing of their personal data in specific situations, such as for direct marketing or processing based on legitimate interests, and must cease processing unless compelling legitimate grounds override the data subject's interests.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-22-automated-decision-cx",
    "title": "GDPR Article 22 - Automated Decision-Making in Customer Experience: Individual Rights, Profiling Restrictions, Meaningful Human Review, Safeguards for Sensitive Categories and Controller Transparency Obligations",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them. This right applies under Article 22 of the GDPR and binds all data controllers processing personal data within the EU or concerning EU residents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "eu-omnibus-directive-2019-2161",
      "iso-10002-2018-customer-satisfaction-complaints",
      "iso-10003-2018-external-dispute-resolution",
      "bpmn-2-0-omg-specification-workflow-notation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-22-automated-decision-workflow",
    "title": "GDPR Article 22 - Automated Individual Decision-Making in Workflows: Prohibition, Exceptions, Safeguards, Right to Human Review and Controller Obligations",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-29",
    "bluf": "Data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. This prohibition under Article 22 GDPR applies to controllers using automated decision-making workflows unless one of the three exceptions in paragraph 2 applies, and requires implementation of safeguards such as human intervention, the ability to express a viewpoint, and contestation of the decision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-automated-decision-workflows",
      "agent-kill-switch"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-23-restrictions-on-data-subject-rights",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, Article 23",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article allows for national or Union legislative measures to restrict the scope of data subject rights and controller obligations for specific, important objectives of general public interest, such as national security or law enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-24-controller-responsibility-accountability",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 24: Responsibility of the controller",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "The controller must implement and be able to demonstrate appropriate technical and organisational measures to ensure processing complies with GDPR, including implementing data protection policies where proportionate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-25-privacy-by-design-and-by-default",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 25: Data protection by design and by default",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must implement appropriate technical and organisational measures to effectively integrate data protection principles into processing activities (privacy by design) and ensure that only necessary personal data is processed by default (privacy by default).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-26-joint-controllers",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 26: Joint controllers",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "When two or more controllers jointly determine the purposes and means of data processing, they must establish a transparent arrangement defining their respective responsibilities for GDPR compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-27-representatives-of-non-eu-controllers",
    "title": "Regulation (EU) 2016/679 - Article 27: Representatives of controllers or processors not established in the Union",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Controllers or processors not established in the EU, whose processing activities relate to offering goods or services to EU data subjects, must designate in writing a representative within the Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-28-processor-obligations-and-contracts",
    "title": "Regulation (EU) 2016/679 - Article 28: Processor",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Controllers must only use data processors that provide sufficient guarantees to implement appropriate technical and organisational measures, and all processing must be governed by a binding contract outlining specific data protection obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-29-processing-under-authority-of-controller-processor",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 29: Processing under the authority of the controller or processor",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Ensures that any processor, or person acting under the authority of the controller or processor, only processes personal data based on documented instructions from the controller, unless legally required to do otherwise by Union or Member State law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-30-records-processing",
    "title": "EU GDPR Article 30 - Records of Processing Activities: Mandatory Documentation Requirements for Controllers and Processors",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Under Article 30 of the GDPR, data controllers and processors must maintain a detailed, written record of their data processing activities (RoPA). This obligation applies to all organizations, with a limited exemption for those with fewer than 250 employees, unless their processing is risky, not occasional, or involves special categories of data as defined in Article 30(5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "uk-retained-gdpr",
      "iso-27701-privacy-information-management",
      "brazil-lgpd-compliance",
      "california-ccpa-v2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-31-cooperation-with-supervisory-authority",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 31: Cooperation with the supervisory authority",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "The controller, processor, and their representatives must cooperate with the supervisory authority in the performance of its tasks upon request.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-32-security-of-processing",
    "title": "Regulation (EU) 2016/679 (General Data Protection Regulation) - Article 32: Security of processing",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "The controller and processor must implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, considering factors like the state of the art, costs, and the nature of the processing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026",
        "mitre_attack",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-article-33-breach-notification-to-supervisory-authority",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 33: Notification of a personal data breach to the supervisory authority",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must notify the competent supervisory authority of a personal data breach without undue delay, and where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-34-communication-of-breach-to-data-subjects",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 34: Communication of a personal data breach to the data subject",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must communicate a personal data breach to the affected data subjects without undue delay if the breach is likely to result in a high risk to their rights and freedoms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-37-dpo",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-35-dpia",
    "title": "Regulation (EU) 2016/679 (General Data Protection Regulation) - Article 35: Data protection impact assessment",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Under Article 35(1) of the GDPR, data controllers must conduct a Data Protection Impact Assessment (DPIA) prior to processing personal data that is likely to result in a high risk to the rights and freedoms of individuals. This assessment is mandatory for specific types of processing, such as systematic and extensive evaluation of personal aspects based on automated processing, large-scale processing of special categories of data, or systematic monitoring of a publicly accessible area on a large scale.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "uk-retained-gdpr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-article-36-prior-consultation-supervisory-authority",
    "title": "REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) - Article 36",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must consult the relevant supervisory authority before processing personal data if a Data Protection Impact Assessment (DPIA) indicates a high risk that cannot be mitigated by the controller's own measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo",
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-37-dpo",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) - Articles 37, 38, 39",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Under Article 37 of the EU GDPR, public authorities and bodies, as well as controllers or processors whose core activities involve large-scale, regular and systematic monitoring of individuals or large-scale processing of special categories of data, are required to designate a Data Protection Officer (DPO) to oversee their data protection strategy and implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-retained-gdpr",
      "iso-27701-privacy-information-management",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-38-position-of-data-protection-officer",
    "title": "Regulation (EU) 2016/679 (General Data Protection Regulation) - Article 38: Position of the data protection officer",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must ensure the Data Protection Officer (DPO) is involved in all data protection matters, operates independently without penalty, and reports directly to the highest level of management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-37-dpo",
      "gdpr-article-35-dpia",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-39-tasks-of-data-protection-officer",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 39: Tasks of the data protection officer",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that the Data Protection Officer (DPO) is tasked with informing and advising the controller or processor on their GDPR obligations, monitoring compliance, providing advice on data protection impact assessments, and acting as the contact point for the supervisory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-37-dpo",
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-40-codes-of-conduct",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data - Article 40 Codes of conduct",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article obligates Member States and supervisory authorities to encourage the creation of codes of conduct by associations and other bodies to contribute to the proper application of this Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-41-monitoring-of-approved-codes-of-conduct",
    "title": "Regulation (EU) 2016/679 (General Data Protection Regulation), Article 41: Monitoring of approved codes of conduct",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "A monitoring body accredited by a supervisory authority may oversee compliance with an approved code of conduct, taking action against infringements, but this does not apply to public authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-article-42-certification-seals-and-marks",
    "title": "Regulation (EU) 2016/679 (General Data Protection Regulation), Article 42: Certification",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article establishes a framework for voluntary data protection certification mechanisms, seals, and marks to help controllers and processors demonstrate compliance with the GDPR for their processing operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-article-44-general-principle-for-transfers",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 44: General principle for transfers",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Any transfer of personal data to a third country or an international organisation may only take place if the conditions laid down in Chapter V of the regulation are complied with by the controller and processor.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-45-transfers-on-basis-of-adequacy-decision",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 45: Transfers on the basis of an adequacy decision",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations may transfer personal data to a third country or international organization if the European Commission has formally decided that the recipient ensures an adequate level of data protection, without needing any further specific authorization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-46-transfer-mechanisms",
    "title": "EU GDPR Article 46 - International Data Transfer Mechanisms: SCCs, BCRs, Codes of Conduct and Certification",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "In the absence of an adequacy decision under Article 45, GDPR Article 46 permits the transfer of personal data to a third country or international organization only if the controller or processor provides appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies are available. These safeguards include mechanisms like Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and approved codes of conduct or certification mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-adequacy-decisions-article-45",
      "eu-standard-contractual-clauses-2021",
      "eu-gdpr-binding-corporate-rules",
      "eu-data-border-transfers-schrems-ii",
      "eu-us-dpf-2023"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "gdpr-article-47-binding-corporate-rules",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council - Article 47: Binding corporate rules",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires that Binding Corporate Rules (BCRs) used for international data transfers must be legally binding, apply to and be enforced by every member of the group of undertakings, and expressly confer enforceable rights on data subjects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-48-transfers-not-authorised-by-eu-law",
    "title": "General Data Protection Regulation (GDPR) - Article 48: Transfers or disclosures not authorised by Union law",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "A judgment from a third-country court or a decision from a third-country administrative authority requiring data transfer is only recognizable or enforceable if it is based on an international agreement, such as a mutual legal assistance treaty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-5-data-principles",
    "title": "Regulation (EU) 2016/679 (General Data Protection Regulation) - Article 5: Principles relating to processing of personal data",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Article 5 of the EU GDPR establishes the seven core principles that must govern all processing of personal data for data subjects in the European Union. These principles-lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability-require data controllers to be able to demonstrate compliance with all of them.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026",
        "mitre_atlas"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-privacy-guidelines-2013",
      "iso-27701-privacy-information-management",
      "uk-retained-gdpr",
      "brazil-lgpd-compliance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-article-51-establishment-and-independence-supervisory-authority",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 51: Supervisory authority",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article mandates that each Member State establish one or more independent public supervisory authorities responsible for monitoring the application of this Regulation to protect the fundamental rights and freedoms of natural persons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-57-tasks-of-supervisory-authority",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 57",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article outlines the mandatory tasks and responsibilities of the supervisory authority within its territory, including monitoring and enforcing the regulation, handling complaints, promoting public awareness, and cooperating with other authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-58-supervisory-authority-powers",
    "title": "REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) - Article 58 Powers",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires organizations to comply with the investigative, corrective, and advisory powers of supervisory authorities, including providing access to information, premises, and processing equipment, and adhering to orders, warnings, bans, and fines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-6",
    "title": "General Data Protection Regulation (GDPR) Article 6 - Lawfulness of processing",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-19",
    "bluf": "Processing of personal data is only lawful if and to the extent that at least one of six specific legal bases applies under the General Data Protection Regulation (GDPR), such as consent, performance of a contract, legal obligation, vital interests, public interest, or legitimate interests.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 3
  },
  {
    "node_id": "gdpr-article-6-lawful-basis-marketing",
    "title": "EU General Data Protection Regulation (GDPR) Article 6 and Recital 47 - Lawful Basis for Processing Personal Data for Direct Marketing",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Under GDPR Article 6(1), processing personal data for marketing is only lawful if a valid basis is established, typically either explicit consent (Art. 6(1)(a)) or legitimate interest (Art. 6(1)(f)). Recital 47 clarifies that direct marketing may be considered a legitimate interest, but this requires a documented Legitimate Interest Assessment (LIA) that balances the controller's interests against the data subject's rights and freedoms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-art-21-marketing-optout",
      "eprivacy-cookie-directive",
      "iab-tcf-v2-2-consent"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-article-60-cooperation-between-lead-other-supervisory-authorities",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, Article 60",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article outlines the mandatory cooperation procedures between a lead supervisory authority and other concerned supervisory authorities to reach consensus on cross-border data processing issues, including information exchange, draft decision review, and objection handling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-63-consistency-mechanism",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 63: Consistency mechanism",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article has been repealed and no longer has effect under the UK GDPR, creating no active compliance obligations regarding the consistency mechanism.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-7-conditions-for-consent",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 7: Conditions for consent",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must ensure that when processing is based on consent, that consent is demonstrable, clearly distinguishable, easy to withdraw, and freely given.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-77-right-to-lodge-complaint-with-supervisory-authority",
    "title": "Regulation (EU) 2016/679, Article 77: Right to lodge a complaint with a supervisory authority",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations must recognize and not impede a data subject's right to lodge a complaint with a supervisory authority if they believe their data protection rights under the regulation have been infringed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-78-right-to-judicial-remedy-against-supervisory-authority",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 78: Right to an effective judicial remedy against a supervisory authority",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article grants natural and legal persons the right to an effective judicial remedy against a supervisory authority's legally binding decisions, or its failure to handle or provide timely updates on a complaint.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-79-right-to-judicial-remedy-against-controller-processor",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 79: Right to an effective judicial remedy against a controller or processor",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article establishes the right for data subjects to seek an effective judicial remedy against a controller or processor if they believe their GDPR rights have been infringed by non-compliant data processing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-8-child-consent-digital-services",
    "title": "Regulation (EU) 2016/679 Article 8: Conditions applicable to child's consent in relation to information society services",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations offering online services to children must obtain verifiable parental consent for processing the personal data of children under a specific age, which is 16 by default but can be lowered to 13 by Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-82-right-to-compensation-and-liability",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 82: Right to compensation and liability",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations must compensate any person who has suffered material or non-material damage due to an infringement of this Regulation, with liability assigned to the controller or processor responsible for the damaging processing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-article-83-conditions-for-administrative-fines",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council - Article 83 General conditions for imposing administrative fines",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes that administrative fines for GDPR infringements must be effective, proportionate, and dissuasive, and outlines the specific criteria supervisory authorities must consider when deciding whether to impose a fine and its amount.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-article-85-processing-freedom-of-expression-and-information",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 85: Processing and freedom of expression and information",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations must comply with national laws that reconcile data protection obligations with the right to freedom of expression and information, allowing for specific exemptions when processing personal data for journalistic, academic, artistic, or literary purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "gdpr-article-88-processing-in-employment-context",
    "title": "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, Article 88",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations must utilize the features of the legislative portal to ascertain the specific rules for processing employee personal data, as the direct text of Article 88 is not provided in the source document.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-article-9-special-categories-sensitive-personal-data",
    "title": "General Data Protection Regulation (GDPR) - Article 9: Processing of special categories of personal data",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations are prohibited from processing personal data that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, health data, or data on sex life or sexual orientation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-data-processing-compliance-2026-17",
    "title": "GDPR Data Processing Enterprise Compliance Standard v17",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The General Data Protection Regulation (GDPR) mandates strict guidelines for the processing of personal data within the European Union. Organizations must ensure lawful processing, obtain explicit consent from data subjects, and implement appropriate technical and organizational measures to safeguard data. Data subjects have rights to access, rectify, and erase their data, and organizations must report data breaches within 72 hours. Data protection impact assessments (DPIAs) are required for high-risk processing activities. Non-compliance can result in significant fines, making adherence to GDPR essential for any entity handling personal data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-data-processing-compliance-2026-2",
    "title": "GDPR Data Processing Enterprise Compliance Standard v2",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The General Data Protection Regulation (GDPR) mandates strict guidelines for the processing of personal data within the European Union (EU) and the European Economic Area (EEA). Organizations must ensure lawful processing, which includes obtaining explicit consent from data subjects, implementing data protection by design and by default, and ensuring transparency in data handling practices. Data controllers and processors are required to maintain records of processing activities, conduct Data Protection Impact Assessments (DPIAs) when necessary, and report data breaches within 72 hours. Additionally, individuals have rights to access, rectify, and erase their data, and organizations must facilitate these rights. Non-compliance can result in significant fines, making adherence to GDPR essential for any entity handling personal data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "gdpr-data-protection-officer",
    "title": "GDPR DPO Requirements",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The EU GDPR (General Data Protection Regulation) requires certain organizations to designate a Data Protection Officer (DPO) (Article 37). The DPO acts as an independent compliance champion, advising the organization on its data protection obligations and serving as a contact point for data subjects and supervisory authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "compliance-gdpr-dpa",
      "gdpr-art-21-marketing-optout",
      "gdpr-health-data-compliance",
      "nist-800-122-pii",
      "sec-regulation-s-p-safeguarding"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gdpr-health-data",
    "title": "GDPR: Health Data (Art. 9)",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "GDPR Article 9 establishes a general prohibition on processing special categories of personal data, with 'data concerning health' (including mental health, genetic data, and biometric data used for identification) receiving the highest level of protection. Processing is only permitted under ten exhaustive exemptions including explicit consent, vital interests, medical purposes under professional secrecy, public health, and scientific research under appropriate safeguards. AI systems processing health data - including medical AI, diagnostic tools, health chatbots, and research analytics platforms - must identify a specific Article 9(2) exemption, implement appropriate technical and organizational measures, and in most cases conduct a Data Protection Impact Assessment (DPIA) under Article 35. Violations involving special category health data attract the highest GDPR fines: up to €20 million or 4% of global annual turnover under Article 83(5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "compliance-gdpr-dpa",
      "gdpr-data-protection-officer",
      "iso-27799-health-info-sec",
      "hipaa-security-rule",
      "nist-ir-8432-genomic-data",
      "fda-21-cfr-part-11-records"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-health-data-compliance",
    "title": "GDPR Health Data (EU)",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The EU GDPR 2016/679 (General Data Protection Regulation) classifies health data as a 'special category' of personal data. Article 9 generally prohibits the processing of such data unless a specific legal exemption is met, necessitating a high level of security and stricter compliance requirements compared to general personal data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "compliance-gdpr-dpa",
      "gdpr-data-protection-officer",
      "iso-27799-health-info-sec",
      "iso-14971-medical-risk",
      "hipaa-security-rule",
      "nist-ir-8432-genomic-data"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gdpr-hospitality-nuance",
    "title": "GDPR (Hospitality Specifics)",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Significant compliance deficiencies exist regarding the lawful basis for processing personal data within a hospitality context. Current configuration confirms `guest_consent_marketing_obtained` is false, violating GDPR Article 6(1)(a) requirements for consent in marketing communications, a gap mirrored by the `loyalty_program_explicit_opt_in` also being false. More critically, explicit consent for special categories of data under Article 9(2)(a), such as guest health information, is not being obtained, since `special_category_data_consent_obtained` registers false. While essential controls like enabling `pii_encryption_at_rest_enabled` and meeting processor stipulations per Article 28 through a signed `ota_data_sharing_agreement_signed` are in place, these consent failures present substantial regulatory risk. Positive measures include adherence to data minimisation principles from Article 5(1)(c), evidenced by `passport_copy_deleted_after_verification` being true and a defined `guest_data_retention_days_limit` of 1095 days. Furthermore, the framework correctly supports an individual's right to erasure under Article 17, as `right_to_erasure_supported` is confirmed true, `guest_profiling_automated_opt_out_honored` procedures are operational, and `minor_guest_data_processing_restricted` is active. Breach notification protocols align with Article 33, mandating supervisory authority contact within the `breach_notification_max_hours` threshold of 72. Immediate remediation must focus on implementing compliant consent collection mechanisms to rectify these critical gaps.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-art-21-marketing-optout",
      "compliance-gdpr-dpa",
      "gdpr-health-data",
      "pci-dss-hospitality",
      "eprivacy-cookie-directive",
      "hotsec-hotel-security"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ge-aml-ctf-law-facilitating-prevention",
    "title": "Georgia Law on Facilitating the Prevention of Money Laundering and the Financing of Terrorism",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-18",
    "bluf": "Georgia's Law on Facilitating the Prevention of Money Laundering and the Financing of Terrorism obliges accountable persons (Article 3) to evaluate and manage risk (Article 8), implement preventive customer due diligence measures (Article 10), identify the beneficial owner (Article 13), apply additional measures to politically active persons (Article 21), submit information to the Financial Monitoring Service (Article 25), retain information for five years (Article 27), and operate a compliance control system (Article 29).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ge-law-on-higher-education-2004-article-5-state-accreditation-higher-education",
    "title": "Law on Higher Education of Georgia: Article 5 - Analogy of law and justice",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must apply the legal norm governing the most similar circumstance to regulate any relationship not expressly provided for by law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ge-law-state-procurement-2005-1388-iis-spa",
    "title": "Georgia Law on State Procurement No. 1388-IIs of 20 April 2005 (Sakhelmtsipo Shesqidvebis Shesakheb) as amended and State Procurement Agency",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Georgia Law on State Procurement No. 1388-IIs of 20 April 2005 (Sakhelmtsipo Shesqidvebis Shesakheb / Law on State Procurement) effective 1 January 2006 as substantially amended over time (most recently by Law of Georgia No. 2675-XVIs of 13 December 2022 effective 1 January 2023 modernisation amendments aligning with EU procurement principles), is the principal Georgian statute governing procurement of goods, works, and services by procuring entities including the central government bodies (ministries, agencies, sub-agencies), legal entities of public law (Sajaro Samartlis Iuridiuli Pirebi / SSIP), state-owned enterprises and limited liability companies with majority state participation, autonomous republic and local self-government bodies (municipalities), and other entities financed by the State Budget. Law 1388-IIs modernised the Georgian procurement regime aligning with the EU procurement directives 2014/24/EU and the EU-Georgia Association Agreement (provisionally applied 2014, in force 2016) DCFTA procurement provisions. The State Procurement Agency (SPA, procurement.gov.ge) under the Office of the Prime Minister is the central regulatory authority responsible for procurement regulation, oversight, electronic procurement platform operation, complaint resolution, and procurement guidance. The Georgian Electronic Government Procurement System (Ge-GP / tenders.procurement.gov.ge) operated by SPA is the mandatory federal e-procurement platform for all in-scope procurement. The Dispute Resolution Board (DRB) handles procurement complaints. Procurement methods established by Law 1388-IIs art. 10 to 21 comprise (a) Electronic Tender (Eltsernuli Tender, the default open electronic public tender for prescribed-value acquisitions), (b) Simplified Electronic Tender (Gamartivebuli Eltsernuli Tender, for medium-low value), (c) Two-Stage Tender (for complex acquisitions), (d) Consolidated Tender (for centralised category procurement), (e) Direct Procurement (Pirdapiri Shesqidva, sole-source under prescribed exceptions in art. 10 paragraph 3 including emergency, sole supplier for technical reasons, prior failed tendering, and prescribed-class exemptions), (f) Simplified Procurement (Gamartivebuli Shesqidva, for low-value below prescribed threshold), and (g) Concession Procurement (Koncessia). The State Audit Office of Georgia conducts ex-post procurement audit. Georgia is in WTO accession in the procurement chapter and is NOT yet a party to the WTO Government Procurement Agreement (GPA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "ge-pdp-law-2011",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ge-pdp-law-2011",
    "title": "Georgia Law on Personal Data Protection 2011 - Personal Data Protection Inspector",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Georgia's Law on Personal Data Protection (საქართველოს კანონი პერსონალური მონაცემების დაცვის შესახებ) - adopted by the Parliament of Georgia on 28 December 2011 and entering into force on 1 May 2012, subsequently amended multiple times most significantly in 2023 and 2024 to align with the European Union General Data Protection Regulation (GDPR) as part of Georgia's EU accession preparations - is Georgia's primary personal data protection legislation establishing a rights-based framework for the protection of personal data in Georgia. Georgia received EU candidate status in December 2023, and the progressive GDPR alignment of the Law reflects this EU integration trajectory under the EU-Georgia Association Agreement (in force since 2016). The supervisory authority is the Personal Data Protection Inspector (Პერსონალური მონაცემების დაცვის ინსპექტორი - PDPI), an independent institution established under the Law, whose mandate has expanded progressively to align with GDPR supervisory authority powers. Key features of Georgia's Law on Personal Data Protection: (1) Scope - applies to personal data processing by public institutions and private persons in Georgia; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation (proportionality); accuracy; storage limitation; security; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political views; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; and biometric data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to object; and right to complain to the PDPI; (6) Data processor oversight - controllers must implement written agreements with processors; (7) Breach notification - controllers must notify the PDPI of significant personal data security incidents; (8) Cross-border transfers - personal data transfers to third countries require adequate protection or approved safeguards; (9) PDPI enforcement - investigates complaints; conducts inspections; issues binding orders; initiates administrative proceedings; (10) EU alignment - amendments through 2023-2024 introduced GDPR-equivalent provisions including enhanced data subject rights, DPO obligations, DPIA requirements, and strengthened breach notification consistent with Georgia's EU candidacy obligations. Georgia's Constitution (Конституция) guarantees the right to privacy providing the constitutional basis for the Law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "germany-autonomous-driving-law-2021-stvaendg",
    "title": "Act on the Amendment of the Road Traffic Act and Other Acts to Permit Highly Automated Driving in Regular Traffic (Automated Driving Act - StVÄndG)",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Germany Autonomous Driving Act 2021 (StVÄndG) permits Level 4 autonomous driving systems to operate in defined operating domains (ODDs) without a human driver present, provided a technical supervisor is available remotely and all approval conditions under §1b of the StVG are met. Applies to manufacturers and operators of automated driving systems in public road traffic.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "germany-digig-diga-2026",
    "title": "Germany Digital Act (DigiG) & DiGA Framework - Digital Health Applications (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The Digital Act (DigiG) and Digital Healthcare Act (DVG) expand reimbursement for Digital Health Applications (DiGA) under statutory health insurance. Manufacturers must demonstrate safety, performance, and quality; conduct accompanying success measurement (AbEM) with quarterly data reporting from Q3 2026; and comply with performance-linked pricing (at least 20% variable component).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "germany-enwg-energy-industry-act-2005",
    "title": "Germany Energiewirtschaftsgesetz (EnWG 2005) - Energy Industry Act and Grid Access Regulation",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Germany's Energiewirtschaftsgesetz (EnWG, Energy Industry Act, last amended 2023) is the primary law governing electricity and gas network regulation, grid access, balancing obligations, and consumer protection in Germany. It implements EU electricity and gas market directives, establishes the Bundesnetzagentur (Federal Network Agency) as the independent energy regulator, mandates unbundling of network operations from generation and supply, and provides the framework for the Energiewende (energy transition) including the expansion of renewable energy grid connections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electricity-market-reform-regulation-2024-1747",
      "india-electricity-amendment-act-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "germany-federal-building-code-baugesetzbuch",
    "title": "Germany Federal Building Code (Baugesetzbuch - BauGB) 2023 Consolidated Version",
    "domain": "Construction & Real Estate",
    "version": "BauGB 2023 (last amended May 3, 2021 via BauLandmobilisierungsgesetz; 2023 consolidated text)",
    "last_updated": "2026-05-09",
    "bluf": "Germany's Federal Building Code (Baugesetzbuch - BauGB, 2023 consolidated version) is the primary federal law governing spatial planning, land use, and building permit eligibility in Germany; it establishes the planning hierarchy (Federal Spatial Planning Act / Landesplanung / Bebauungsplan / Flachennutzungsplan), regulates urban development projects (stadtebauliche Vertrage, Sanierungsgebiet, Entwicklungsmassnahmen), sets rules for building within and outside designated development areas (Section 34 in-fill, Section 35 outside development areas), and implements the 2021 BauLandmobilisierungsgesetz reforms for housing mobilisation and faster planning procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eia-directive-construction-2011-92",
      "eu-noise-directive-construction-2002-49"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "germany-online-access-act-2017-ozg",
    "title": "Germany Online Access Act 2017 (Onlinezugangsgesetz - OZG) - Digital Government Services Obligation",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The German Online Access Act 2017 (Onlinezugangsgesetz, OZG) required all federal, state (Länder), and municipal authorities to make 575 administrative services digitally accessible via a nationwide IT infrastructure portal (Portalverbund) and the central service platform SDG (Single Digital Gateway) by 31 December 2022. The OZG Änderungsgesetz 2024 (OZG-Änderungsgesetz) extended the framework, mandating online-only processing capability and machine-readable data exchange via standards-based APIs by 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-single-digital-gateway-regulation-2018-1724"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "germany-residence-act-aufenthaltsgesetz-2004-bamf",
    "title": "Germany Residence Act (Aufenthaltsgesetz 2004) - BAMF and Auslaenderbehoerde Framework",
    "domain": "Immigration & Border Control",
    "version": "3.5",
    "last_updated": "2026-05-10",
    "bluf": "The Aufenthaltsgesetz (Residence Act, AufenthG) of 30 July 2004 (as substantially amended by the Skilled Immigration Act 2020 and subsequent 2023 reforms) is Germany's primary immigration law. It establishes five categories of residence permit (temporary, settlement, EU long-term residence, EU Blue Card, residence permit for family reunification), prescribes the grounds for expulsion under ss.53-55, and codifies the Chancenkarte (Opportunity Card) points-based system for job-seekers from third countries introduced in 2024. The Federal Office for Migration and Refugees (BAMF) determines asylum claims and coordinates integration courses. Local Auslaenderbehoerde (foreigners' offices) issue and manage residence permits. Section 95 provides criminal penalties of up to 3 years imprisonment for unauthorised residence and document fraud.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_directive",
        "schengen",
        "gdpr_article",
        "asylum_procedure",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric",
      "eu-entry-exit-system-regulation-2017-2226"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "germany-state-gambling-treaty-2021",
    "title": "Germany Interstate Gambling Treaty (Glücksspielstaatsvertrag GlüStV 2021) - Licence Regime, Online Slots and Sports Betting Rules, GGL Supervision",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The regulation establishes a unified licensing and supervisory framework for cross-border online gambling offers in Germany, enforced by the Gemeinsame Glücksspielbehörde der Länder (GGL). It applies to all operators providing online sports betting and slot games to German residents and mandates strict compliance with player protection, youth protection, and anti-addiction measures under the GlüStV 2021 framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "fatf-recommendation-16-travel-rule-crypto"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "germany-uwg-unfair-competition-act-2004",
    "title": "Germany Act against Unfair Competition (UWG) 2004 - Abmahnung and Injunction Framework",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Germany's Gesetz gegen den unlauteren Wettbewerb (UWG, BGBl. 2004 I S. 1414, last amended 2022) prohibits unfair commercial practices using a general clause (Section 3), an Annex of 30 per se prohibited acts, and specific prohibitions on aggressive and deceptive conduct; empowers competitors, consumer associations, and chambers of commerce to issue Abmahnungen (cease-and-desist letters) and seek injunctions and damages before ordinary courts; and incorporates EU Directive 2005/29/EC (UCPD) and Directive 2019/2161 (Omnibus).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-directive-2005-29"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "germany-water-management-act-wasserhaushaltsgesetz-2009",
    "title": "Germany Water Management Act 2009 (Wasserhaushaltsgesetz) - Federal Water Permitting and EU WFD Implementation",
    "domain": "Water & Environmental Resources",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Germany's Wasserhaushaltsgesetz (WHG - Water Management Act), BGBl. I S. 2585 of 31 July 2009 (as amended), is the federal framework statute for water protection and use. The WHG transposes the EU Water Framework Directive (WFD, 2000/60/EC) and associated directives into German federal law, while detailed implementation is primarily a matter for the 16 Laender (states). The WHG covers surface water, coastal waters, groundwater, and flood protection. All significant water uses require a permit (Erlaubnis) or authorisation (Bewilligung) from the Laender water authority (Wasserbehorde). The Act establishes the precautionary, user-pays, and polluter-pays principles. The WHG prohibits discharge of substances that may cause changes to water properties without a permit. Germany participates in the international river basin districts for Rhine, Elbe, Danube, Ems, Weser, Maas, and Oder. Flood risk management plans (Hochwasserrisikomanagementplane) are mandatory under WHG ss.73-75.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_wfd",
        "eu_gwfd",
        "eu_floods_directive",
        "eu_drinking_water",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "gf-gdpr-2018",
    "title": "French Guiana - EU General Data Protection Regulation (GDPR) and CNIL Supervisory Framework",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "French Guiana is a French overseas department and an EU outermost region located on the northeastern coast of South America, forming an integral part of the French Republic and the European Union. As an EU outermost region, French Guiana is fully subject to EU law including the General Data Protection Regulation (GDPR), which applies directly and with full force in French Guiana in the same manner as in metropolitan France and all other EU member states and outermost regions. The Commission Nationale de l'Informatique et des Libertés (CNIL) is the competent data protection supervisory authority for French Guiana. The French national adaptation law - Law No. 2018-493 of 20 June 2018 on the Protection of Personal Data - implements GDPR-compatible national provisions applicable in French Guiana. All organisations established in French Guiana or processing personal data of individuals located in French Guiana must comply with the GDPR, including the requirements for lawful basis for processing, data subject rights (access, rectification, erasure, portability, restriction, and objection), data protection by design and by default, data protection impact assessments for high-risk processing, mandatory breach notification to CNIL within 72 hours, and appointment of a Data Protection Officer where required. CNIL enforcement, corrective powers, and administrative fines of up to €20 million or 4% of global annual turnover apply in French Guiana.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/gf-gdpr-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gfsi-benchmarking",
    "title": "GFSI Benchmarking Requirements",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Global Food Safety Initiative (GFSI) Benchmarking Requirements Version 2020.1 mandates a comprehensive framework for food safety, ensuring organisations implement and maintain a robust Food Safety Management System (FSMS). Compliance necessitates that all FSMS documentation is approved, with a fully operational HACCP system founded on principles from the Codex Alimentarius General Principles of Food Hygiene. Beyond traditional hazards, the framework integrates preventative controls against intentional contamination, requiring an active food defense plan consistent with frameworks like BSI PAS 96:2017 and regulations such as the FDA Food Safety Modernization Act's rule on Mitigation Strategies to Protect Food Against Intentional Adulteration. Similarly, an active food fraud mitigation program must be in place. Critical operational controls specified by ISO 22000:2018 must be demonstrably effective, including an active supplier approval program, a documented allergen control plan, and continuous environmental monitoring. The system's traceability capabilities must permit full retrieval within a maximum timeframe of four hours. Continuous improvement and verification are enforced through a strict cadence: internal audits and management reviews must occur at a minimum frequency of 365 days, with product recall tests also conducted within that same 365-day period. Any identified non-conformities require corrective action resolution within a maximum of 30 days. These rigorous standards, defined in Part III, are upheld by certification organisations adhering to the governance structure detailed in GFSI Benchmarking Requirements Version 2020.1, Part IV.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-gen",
      "haccp-food-safety",
      "iso-22000-food-mgt",
      "brc-food-safety-global",
      "sqf-edition-9-safety",
      "ifs-food-standard"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gfsr-crypto-financial-stability-challenges",
    "title": "Global Financial Stability Report, October 2021: COVID-19, Crypto, and Climate",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2021-10-12",
    "bluf": "This report assesses global financial stability, noting that while risks have been contained due to ongoing policy support and economic rebound, vulnerabilities remain elevated in several sectors. Optimism has faded due to concerns about the strength of the global recovery, supply chain disruptions, and inflation. Stretched asset valuations persist, and there are pockets of vulnerabilities in the nonbank financial sector.\n\nChapter 2 specifically discusses the opportunities and challenges of the crypto ecosystem. Key risks identified include those to consumers arising from crypto asset providers’ lack of operational or cyber resilience. Additionally, significant data gaps, stemming from anonymity and limited global standards, pose risks to financial integrity. For emerging markets and developing economies, the adoption of crypto assets and stablecoins may accelerate dollarization risks. The chapter concludes by noting it provides a set of actionable policy recommendations to address these challenges.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-virtual-assets-vasp",
      "cpmi-iosco-cyber-resilience-fmi",
      "bcbs-principles-operational-resilience",
      "prudential-treatment-cryptoasset-exposures",
      "fincen-cvc-business-models",
      "fatf-travel-rule-v2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "gg-dpa-2017",
    "title": "Guernsey Data Protection (Bailiwick of Guernsey) Law 2017 - ODPA",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Guernsey's Data Protection (Bailiwick of Guernsey) Law 2017, which came into force on 25 May 2018 (the same date as the EU General Data Protection Regulation), is Guernsey's primary personal data protection legislation establishing a GDPR-equivalent rights-based framework for the protection of personal data throughout the Bailiwick of Guernsey, which comprises the islands of Guernsey, Alderney, and Sark. Guernsey is a Crown Dependency of the United Kingdom and a self-governing jurisdiction that is not a member of the European Union or subject to the UK Data Protection Act 2018; however, Guernsey has aligned its data protection framework with EU standards to maintain EU adequacy recognition that is foundational to Guernsey's position as a leading international financial and fund administration centre. The European Commission has recognised Guernsey as providing adequate data protection for the purposes of international data transfers from the EU. The supervisory authority is the Office of the Data Protection Authority (ODPA), an independent institution established under the Law whose mandate covers oversight, enforcement, and guidance on data protection standards throughout the Bailiwick. Key features of Guernsey's Data Protection (Bailiwick of Guernsey) Law 2017: (1) Scope - applies to personal data processing by controllers established in the Bailiwick of Guernsey or processing data of individuals in the Bailiwick; (2) Data processing principles - processing must comply with: lawfulness; fairness; transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right to data portability; and right not to be subject to solely automated decisions; (6) Data Protection Officer - required for public authorities and organisations conducting large-scale systematic processing or processing sensitive data at scale; (7) Breach notification - controllers must notify the ODPA within 72 hours of becoming aware of a qualifying personal data breach; (8) Data Protection Impact Assessment - required for high-risk processing; (9) Cross-border transfers - personal data may only be transferred outside the Bailiwick where adequate protection or appropriate safeguards exist; and (10) Administrative fines - the ODPA may impose significant fines for violations. Guernsey's GDPR-equivalent framework and EU adequacy recognition underpin its role as a leading European offshore investment fund administration and financial services centre.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-retained-gdpr",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gh-cybersecurity-act-2020",
    "title": "Ghana Cybersecurity Act 2020 (Act 1038)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Ghana's Cybersecurity Act 2020 (Act 1038), assented December 2020, establishes the Cyber Security Authority as the national cybersecurity regulatory body responsible for designating Critical Information Infrastructure, licensing cybersecurity service providers, mandating cybersecurity measures for regulated entities, requiring breach notification to the Cyber Security Authority within 72 hours, and creating cybercrime offences with penalties including fines and imprisonment for violations of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/gh-cybersecurity-act-2020.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gh-dpa-2012"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gh-data-protection-act-843-2012-section-17-rights-data-subject",
    "title": "Data Protection Act, 2012 (Act 843) - General Data Protection Principles",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must comply with Ghana's eight data protection principles, including accountability, lawfulness, purpose specification, data quality, security safeguards, and data subject participation, and must register with the Data Protection Commission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "gh-dpa-2012",
    "title": "Data Protection Act, 2012 (Act 843)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Ghana Data Protection Act 2012 (Act 843) governs the processing of personal data by establishing the Data Protection Commission and mandating compliance with eight core data protection principles outlined in Section 17. It applies to any data controller established in Ghana or processing personal data within the country.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-popia-2013",
      "ke-dpa-2019",
      "ng-ndpr-2019",
      "mu-dpa-2017"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gh-food-and-drugs-authority-act-1992-pndc-law-305b",
    "title": "Ghana Food and Drugs Authority Act 1992 PNDC Law 305B Public Health Act 851 Drug Registration GMP Inspection Pharmacovigilance and African Medicines Agency Alignment",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "Ghana's Food and Drugs Authority (FDA Ghana) administered under the Public Health Act 851 of 2012 (which consolidates the Food and Drugs Law PNDC Law 305B of 1992) operates as the National Regulatory Authority for food drugs cosmetics medical devices household chemical substances tobacco products and clinical trials organised across operative parts including Part 6 of Public Health Act 851 covering Food and Drugs administration including section 118 establishing FDA Ghana section 122 functions of the Authority including drug registration section 125 prohibition on unregistered drugs section 128 registration of drugs and pharmaceutical products section 135 advertisement of food drugs cosmetics and medical devices section 137 control of advertisements section 141 clinical trial authorisation section 145 export and import of regulated products and section 149 inspection powers. Implementation through FDA Ghana Guidelines on Good Manufacturing Practices aligned with WHO Technical Report Series the Common Technical Document format the FDA Pharmacovigilance Guidelines aligned with ICH E2E and the African Medicines Regulatory Harmonisation initiative. Ghana achieved WHO Maturity Level 3 designation in 2020 and is participating actively in the African Medicines Agency (AMA) preparation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "gh-public-procurement-act-663-2003-as-amended-act-914-2016-ppa-ghana",
    "title": "Ghana Public Procurement Act 2003 (Act 663) as amended by Public Procurement (Amendment) Act 2016 (Act 914) and Ghana Electronic Procurement System (GHANEPS)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Ghana Public Procurement Act 2003 (Act 663) assented to 31 December 2003 as substantially amended by the Public Procurement (Amendment) Act 2016 (Act 914) assented to 6 May 2016 is the principal Ghanaian statute governing procurement of goods, works, and services by procurement entities (Entities) including ministries, departments and agencies (MDAs), Metropolitan, Municipal and District Assemblies (MMDAs), statutory bodies, state-owned enterprises, public-sector universities, and other entities funded in whole or in part by public funds. Act 663/2003 established the Public Procurement Authority (PPA) as the central regulatory body and modernised the Ghanaian procurement regime aligning with international best practice including the UNCITRAL Model Law on Public Procurement. The 2016 Act 914 amendments strengthened the integrity regime including supplier debarment, the criminalisation of procurement misconduct, and the requirement for electronic procurement. The Ghana Electronic Procurement System (GHANEPS / ghaneps.gov.gh) operated by the PPA is the federal e-procurement platform. Procurement methods established by Act 663/2003 sec. 35 to 47 comprise (a) Competitive Tendering (sec. 35, also called National Competitive Tendering NCT for domestic procurement and International Competitive Tendering ICT for cross-border procurement), (b) Two-Stage Tendering (sec. 37, for complex acquisitions), (c) Restricted Tendering (sec. 38, with prequalification), (d) Single-Source Procurement (sec. 40, sole-source under prescribed exceptions including emergency, sole supplier for technical reasons, prior failed tendering, and prescribed-class exemptions), (e) Request for Quotations (sec. 42, for low-value goods and services), (f) Request for Proposals (sec. 43, for consultancy services), and (g) Low-Value Procurement (sec. 47, for very low-value contracts below prescribed thresholds). The Internal Audit Agency (IAA), Auditor-General, and Office of the Special Prosecutor (OSP) have audit and prosecution jurisdiction over procurement misconduct. Ghana is NOT a party to the WTO Government Procurement Agreement (GPA). Ghana is a party to the African Continental Free Trade Area (AfCFTA), the Economic Community of West African States (ECOWAS), and UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "gh-dpa-2012",
      "gh-cybersecurity-act-2020",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ghana-data-protection-act-843-2012",
    "title": "Ghana Data Protection Act 2012 (Act 843) - Data Controller Registration with Data Protection Commission, Sensitive Data Categories, Data Subject Rights, Transborder Data Flow Restrictions, Commissioner Enforcement Powers and Criminal Liability Provisions",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "All data controllers and processors in Ghana must register with the Data Protection Commission (DPC) and comply with data protection principles under the Data Protection Act, 2012 (Act 843), including lawfulness, purpose specification, data subject rights, and security safeguards. Non-compliance may result in enforcement actions and criminal liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-confidentiality",
      "aicpa-soc2-cc-privacy",
      "assessing-security-privacy-controls"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ghana-data-protection-health-2026",
    "title": "Ghana Data Protection Act Health Sector Guidelines 2026",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "Data Protection Commission guidelines require explicit consent, security certifications, and DPIAs for electronic health records and telemedicine platforms operating in Ghana.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ghana-immigration-act-573-2000-ghana-immigration-service",
    "title": "Ghana Immigration Act 573 of 2000 - Ghana Immigration Service Permit and Residency Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Ghana's Immigration Act 573 of 2000 (as amended by Immigration (Amendment) Act 2000 No. 573 and subsequent instruments) governs the entry, stay, and departure of non-Ghanaian nationals. The Ghana Immigration Service (GIS) under the Ministry of the Interior administers visas, permits, and border management. Ghana introduced free visa-on-arrival for all African nationals in 2019 as part of the Africa Continental Free Trade Area (AfCFTA) integration initiative, headquartered in Accra. ECOWAS nationals from all 15 member states may stay in Ghana for up to 90 days without a visa under the ECOWAS Protocol on Free Movement (1979). Non-African nationals require a visa prior to arrival unless from visa-exempt countries (USA, UK, EU nationals are not visa-exempt as of 2020). The Residence Permit system includes: Indefinite Leave to Remain (ILR) Permit, Temporary Residence Permit (TRP) for work and study, and Diplomatic Permits. The Ghana Card (national biometric ID) has been linked to residence registration since 2021. Work permit applications require approval from the Ghana Investment Promotion Centre (GIPC) for investors and from SSNIT (Social Security and National Insurance Trust) for employed foreign workers. Overstay is an administrative violation with fines and deportation authority under s.23.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ecowas_free_movement",
        "gipc_investment",
        "african_continental_free_trade",
        "labour_act",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ghana-minerals-mining-act-703-2006",
    "title": "Ghana Minerals and Mining Act 703 of 2006",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Ghana's Minerals and Mining Act 703 (2006), amended by Act 900 (2015), vests all minerals in the President in trust for the people of Ghana, establishes the Minerals Commission as regulator, and governs exploration licences (5-year initial, 2-year renewal), mining leases (30-year initial term), and small-scale mining licences. Environmental permits from EPA and community development agreements with affected communities are mandatory before operations commence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "peru-general-mining-law-ds-014-92-em",
      "colombia-mining-code-law-685-2001"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ghg-protocol-scope3",
    "title": "GHG Scope 3 Accounting Strategy",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Standardized methodology for measuring and reporting greenhouse gas emissions across the entire corporate value chain (Categories 1-15), accounting for 70-90% of total enterprise footprint.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "ifrs-s1-general",
      "ifrs-s2-climate",
      "iso-14064-ghg-reporting",
      "sbti-carbon-target",
      "tcfd-climate-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gi-dpa-2004",
    "title": "Gibraltar Data Protection Act 2004 (GDPR-Equivalent) - Gibraltar ICO",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Gibraltar's data protection framework, established through the Data Protection Act 2004 and progressively updated to achieve GDPR-equivalence with effect from 25 May 2018 when Gibraltar applied the EU General Data Protection Regulation as part of the United Kingdom's EU membership, and subsequently maintained through post-Brexit legislation maintaining a GDPR-equivalent standard, is Gibraltar's primary personal data protection regime governing the processing and protection of personal data throughout the British Overseas Territory. Gibraltar is a British Overseas Territory at the southern tip of the Iberian Peninsula; it has its own Parliament (Parliament of Gibraltar) and legal system based on English common law and is distinct from the United Kingdom in terms of data protection legislation, though it has aligned its framework with both UK GDPR and EU GDPR standards. The European Commission has recognised Gibraltar as providing adequate data protection for the purposes of international data transfers from the EU. The supervisory authority is the Gibraltar Information Commissioner, an independent statutory office responsible for overseeing compliance with Gibraltar's data protection legislation and handling freedom of information matters throughout the Territory. Key features of Gibraltar's GDPR-equivalent data protection framework: (1) Scope - applies to personal data processing by controllers established in Gibraltar or processing data of individuals in Gibraltar; (2) Data processing principles - processing must comply with: lawfulness; fairness; transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right to data portability; and right not to be subject to solely automated decisions; (6) Data Protection Officer - required for specified controller categories; (7) Breach notification - controllers must notify the Gibraltar Information Commissioner within 72 hours of becoming aware of a qualifying personal data breach; (8) Data Protection Impact Assessment - required for high-risk processing; (9) Cross-border transfers - personal data may only be transferred outside Gibraltar where adequate protection or appropriate safeguards exist; and (10) Administrative fines - the Gibraltar Information Commissioner may impose significant fines for violations. Gibraltar's GDPR-equivalent framework and EU adequacy recognition underpin Gibraltar's position as a regulated financial services and gaming jurisdiction with significant cross-border data flows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gibraltar-gambling-act-2005",
    "title": "Gibraltar Gambling Act 2005 - Remote Gambling Licensing, Responsible Gambling and Advertising Standards",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Gibraltar Gambling Act 2005 establishes a licensing regime for remote gambling operators, requiring compliance with responsible gambling measures, anti-money laundering protocols, and advertising standards under the oversight of the Gibraltar Regulatory Authority. Key obligations are set forth in Part 3 (Licensing), Part 4 (Responsible Gambling), and Part 5 (Advertising).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l3",
      "eu-dora-articles-28-44-third-party-ict-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gibraltar-gambling-act-2005-gla",
    "title": "Gibraltar Gambling Act 2005 - GLA Licensing: Remote Gambling, Responsible Gambling Requirements, Advertising Standards, Financial Crime Obligations, Technical Standards and GLA Annual Compliance Reports",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The Gibraltar Gambling Act 2005 establishes a licensing regime for remote gambling operators under the supervision of the Gibraltar Licensing Authority (GLA), requiring compliance with responsible gambling measures, anti-money laundering controls under Section 17, technical integrity standards, and annual compliance reporting. It applies to all remote gambling operators licensed in Gibraltar.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "alderney-egambling-regulations-2009",
      "eu-aml-directive-5-gambling-sector"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gibraltar-vasp-dlt-regulatory-framework-2018",
    "title": "Financial Services (Distributed Ledger Technology Providers) Regulations 2018",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a licensing regime for Distributed Ledger Technology (DLT) providers operating in Gibraltar, requiring compliance with nine regulatory principles including systems integrity, customer asset protection, and AML/CFT obligations under the Gibraltar Financial Services Commission (GFSC). It applies to any entity conducting DLT business activities from or within Gibraltar under Principle 1 and Regulation 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "eu-dlt-pilot-regime-2022-858",
      "bis-iosco-pfmi-applied-to-dlt-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gips-investment-perf-std",
    "title": "GIPS (Investment Perf)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Asserting compliance with the Global Investment Performance Standards (GIPS) signifies a firm-wide commitment to fair representation and full disclosure of investment performance, a claim this node validates as true. Adherence requires firms to maintain rigorously documented composite definitions, a foundational element within the GIPS Standards for Firms. The calculation methodology must be systematic and verifiable, mandating trade-date accounting for all transactions and accrual accounting for fixed-income securities. Furthermore, portfolio valuations must occur on a monthly frequency, with established policies for large cash flow adjustments to ensure temporal accuracy of time-weighted returns. Performance presentation necessitates calculation and disclosure of both gross-of-fees and net-of-fees returns. A compliant presentation must show a minimum track record of five years, annually adding performance until a ten-year target is achieved. To bolster this assertion, independent verification is required, ensuring a third party attests that compliance policies are designed and implemented correctly. Comprehensive supporting records must be maintained for a retention period of ten years, substantiating all historical data. Adherence to this comprehensive framework not only provides global comparability but also aligns with the SEC Advisers Act Rule 206(4)-1 by establishing a disciplined process for producing performance advertising that is not materially misleading.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cfa-ethics-standards",
      "sec-regulation-best-interest",
      "mifid-ii-best-execution",
      "iso-31000-risk-mgt-std",
      "soc-1-type-2-finance"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gistm-global-tailings-management-standard-2020",
    "title": "Global Industry Standard on Tailings Management (GISTM) 2020 - Consequence Classification, Design, Operation and Closure Requirements for Tailings Facilities",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Global Industry Standard on Tailings Management requires Operators to implement zero tolerance for human fatalities and strive for zero harm to people and the environment across all lifecycle phases of tailings facilities, in accordance with the 15 Principles and 77 auditable Requirements organized under six Topic Areas. Compliance is mandatory for all existing and to-be-built tailings facilities under Operator control, as defined in the Standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gl-dp-law-2019",
    "title": "Greenland Personal Data Protection - Danish Royal Decree (Anordning) extending the Danish Act on Processing of Personal Data to Greenland (in force 1 December 2016)",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "Personal data protection in Greenland (Kalaallit Nunaat), an autonomous territory of the Kingdom of Denmark, is governed not by a 2019 Inatsisartutlov (Greenland-Parliament law) but by a Danish Royal Decree (anordning) extending the Danish Act on Processing of Personal Data (the pre-GDPR Act No. 429 of 31 May 2000) to Greenland, which entered into force on 1 December 2016 (with a transition period). Because Greenland is outside the European Union, the EU General Data Protection Regulation (GDPR) does not apply directly; the applicable regime is the extended Danish Act. Supervision is exercised by the Danish Data Protection Agency (Datatilsynet). The regime establishes principles for lawful processing, grants data subjects rights of access, rectification, erasure and objection, requires appropriate security safeguards, and restricts cross-border transfers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/gl-dp-law-2019.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "glba-safeguards-rule-compliance-2026-10",
    "title": "GLBA Safeguards Rule Enterprise Compliance Standard v10",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The GLBA Safeguards Rule mandates that financial institutions implement a comprehensive information security program to protect customer information. This includes conducting risk assessments, implementing security measures, and regularly monitoring and testing the effectiveness of these measures. Institutions must also ensure that third-party service providers adhere to similar security standards. The rule emphasizes the importance of employee training and the development of incident response plans. Institutions are required to designate a qualified individual to oversee the security program and to regularly update the program to address new risks. Compliance with the Safeguards Rule is essential to safeguard sensitive customer data and maintain consumer trust.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "glba-safeguards-rule-compliance-2026-25",
    "title": "GLBA Safeguards Rule Enterprise Compliance Standard v25",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The GLBA Safeguards Rule mandates that financial institutions implement comprehensive security programs to protect customer information. Institutions must assess risks to customer data, implement safeguards to mitigate those risks, and regularly monitor and test the effectiveness of these safeguards. The rule requires the designation of a qualified individual to oversee the security program, employee training, and the establishment of procedures for responding to security breaches. Institutions must also ensure that third-party service providers maintain appropriate safeguards. Compliance with the Safeguards Rule is essential for protecting consumer privacy and maintaining trust in financial services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "global-alliance-pr-ethics",
    "title": "Global Alliance (PR Ethics)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Operational adherence to this node's framework necessitates stringent compliance with the Global Alliance Code of Ethics, beginning with the foundational directive of Working in the public interest and creating societal value. Systemic verification, confirming public_interest_alignment_verified is true, underpins this mandate. Concurrently, Guiding Principle 2, which demands respect for diversity and local customs, is procedurally enforced through a mandatory cross_cultural_sentiment_review_required for all communications. The professional standard of Integrity, outlined in Principle of Professional Practice 1, is maintained via continuously active system controls where integrity_safeguards_active is confirmed. All external messaging must exhibit unwavering commitment to Honesty and Accuracy per Principle of Professional Practice 2. This is algorithmically validated through a compulsory accuracy_fact_check_required, a validated honesty_in_communication_validated status, and a strict remediation protocol allowing a max_time_to_correct_inaccuracies_hrs of 24. Upholding Principle of Professional Practice 3, Confidentiality, requires that all sensitive data be secured with confidential_data_encryption_bits of at least 256. To mitigate risks under Principle of Professional Practice 4, Conflict of Interest, every engagement undergoes a systematic review where conflict_of_interest_scanned is affirmed. Transparency obligations are met by maintaining a transparency_disclosure_level of 1 and ensuring any third_party_sponsorship_disclosed is explicitly declared. Sustained compliance also requires personnel to complete recurrent training, as reflected by the ethics_training_validity_days cycle of 365.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "prsa-code-of-ethics",
      "ama-ethical-marketing",
      "ftc-endorsement-guides",
      "oecd-guidelines-multinational-ent",
      "un-guiding-principles-business-hr"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "global-anti-spam-legislation-casl-gdpr-comparison",
    "title": "Global Anti-Spam Legislation Comparison Framework - CASL (Canada), CAN-SPAM (US), PECR (UK), GDPR Article 6 Email (EU), SPAM Act (Australia) and India IT Rules: Consent Standards, Opt-Out Windows, Penalties and B2B Exemption Variations",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This framework compares core email marketing compliance obligations across major jurisdictions, focusing on consent requirements (e.g., GDPR Article 6, CASL Section 6), opt-out enforcement (CAN-SPAM 15 U.S.C. § 7703(a)(3)), penalty structures, and B2B exemptions. Applies to any organization conducting cross-border digital outreach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "can-spam-act-email",
      "casl-anti-spam-canada",
      "eprivacy-cookie-directive",
      "eu-ecommerce-directive-2000-31",
      "eu-unfair-commercial-practices-2005-29"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "global-clinical-trial-data-sharing-2026",
    "title": "Global Clinical Trial Data Sharing & Transparency Obligations (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Sponsors must comply with increasing requirements for clinical trial data transparency, including registration, summary results posting (ClinicalTrials.gov, EudraCT, etc.), individual participant data (IPD) sharing policies, and redaction strategies for privacy. Many funders and journals now mandate data sharing plans, with timelines for posting results and mechanisms for controlled access to IPD.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "global-pharmacovigilance-database-interoperability-2026",
    "title": "Global Pharmacovigilance Database Interoperability & Data Sharing (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Regulatory requirements for the electronic exchange of pharmacovigilance information, specifically Individual Case Safety Reports (ICSRs), between pharmaceutical companies, national regulators, and global databases (e.g., EudraVigilance, WHO VigiBase) using the ICH E2B(R3) standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "globalg-a-p-certification-standard-v6-2023",
    "title": "GLOBALG.A.P. Integrated Farm Assurance Standard v6 2023 - Crop Base Module: Food Safety, Traceability, Environmental Management, Worker Welfare, Integrated Pest Management, Water Efficiency and Chain of Custody Certification Requirements",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This standard requires agricultural producers to implement a certified Integrated Farm Assurance system covering food safety, environmental protection, worker welfare, and traceability, in accordance with GLOBALG.A.P. v6 2023 Crop Base Module controls. Applies to primary producers supplying retail and food service supply chains globally.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004",
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-food-labelling-regulation-1169-2011"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gm-dpa-2021",
    "title": "Gambia Data Protection Act 2021",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Gambia enacted the Data Protection Act 2021 as part of comprehensive post-2017 digital governance reforms following the country's democratic transition. The Act is administered by the Public Utilities Regulatory Authority (PURA), which oversees ICT regulation in The Gambia. The Act establishes data protection principles governing the collection, processing, storage, and disclosure of personal data. Data subjects have rights of access and correction. Controllers must obtain consent before collecting personal data, implement security measures, and restrict cross-border transfers to jurisdictions with adequate protection. As an ECOWAS member state, the Act aligns with the ECOWAS Supplementary Act on Personal Data Protection (A/SA.1/01/10, 2010).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/gm-dpa-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gn-pdp-law-2016",
    "title": "Guinea Law No. L/2016/037/AN on Cybersecurity and Personal Data Protection",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Guinea enacted Law No. L/2016/037/AN on Cybersecurity and Personal Data Protection, consolidating cybersecurity and privacy obligations in a single instrument. Article 47 of the Law provides for an independent personal-data-protection authority to be established by regulation; as of this writing that authority has not been formally established and made operational, and the Law does not itself name an 'ANPDP'. The Law requires registration of processing activities, mandates consent or another lawful basis, grants data subjects rights of access, rectification, opposition, and erasure, and prohibits cross-border transfers to countries without adequate protection. Sensitive personal data categories require explicit consent and prior authorisation by the data protection authority once established. The Law aligns with the ECOWAS Supplementary Act on Personal Data Protection as Guinea is a member of ECOWAS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/gn-pdp-law-2016.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gold-standard-carbon",
    "title": "Gold Standard Carbon Credits",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with this node ensures carbon credits adhere to the rigorous Gold Standard for the Global Goals framework. Project validation requires that `project_additionality_verified` is true, demonstrating emission reductions beyond a business-as-usual scenario as guided by the UNFCCC Clean Development Mechanism’s Additionality Tool. Furthermore, each project must deliver a `minimum_sdg_contributions` of three, where `includes_sdg_13_climate_action` is a mandatory component to ensure holistic environmental and social co-benefits. Adherence to Gold Standard Safeguarding Principles is confirmed through mandatory `local_stakeholder_consultation_completed` and an operational `continuous_grievance_mechanism_active`. An `independent_vvb_audit_passed` is compulsory, aligning with ISO 14064-2:2019 specifications for project-level greenhouse gas quantification and monitoring. To meet CORSIA Emissions Unit Eligibility Criteria, a `double_counting_safeguard_active` must be functional, preventing any single credit's duplicative use. Issuance is governed by a `standard_crediting_period_years_max` of five years, necessitating subsequent re-evaluation for continued validity. Systemic integrity requires that `mrv_telemetry_encryption_enabled` protects all monitoring data streams, while secure registry communications must utilize a `registry_api_tls_version_minimum` of 1.2. Lastly, market access and participation are contingent upon a verified `kyc_aml_clearance_for_trading` for all transacting entities, upholding financial probity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify",
      "un-sdg-alignment",
      "iso-14001-ems"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "good-machine-learning-practice-medical-devices",
    "title": "Good Machine Learning Practice for Medical Device Development: Guiding Principles",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2021-10-01",
    "bluf": "The U.S. Food and Drug Administration (FDA), Health Canada, and the United Kingdom’s Medicines and Healthcare products Regulatory Agency (MHRA) have jointly identified 10 guiding principles that can inform the development of Good Machine Learning Practice (GMLP). These principles aim to promote safe, effective, and high-quality medical devices that use artificial intelligence and machine learning (AI/ML). AI/ML technologies have the potential to transform health care by deriving new insights from vast amounts of data, but they also present unique considerations due to their complexity and the iterative, data-driven nature of their development.\n\nThese 10 guiding principles are intended to lay the foundation for developing GMLP that addresses the unique nature of these products and to cultivate future growth in this rapidly progressing field. They identify areas where international bodies could work to advance GMLP, including research, creating educational tools, international harmonization, and consensus standards. The principles may be used to adopt good practices from other sectors, tailor them for medical technology, or create new practices specific to the healthcare sector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-820-qsr",
      "iso-13485-medical-qms",
      "iso-14971-medical-risk",
      "iec-62304-medical-software",
      "fda-ai-ml-samd-action-plan",
      "imdrf-samd-risk-framework"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "google-cloud-compliance-offerings-2024",
    "title": "Google Cloud Compliance and Security Offerings 2024 - Assured Workloads for Regulatory Requirements, Sovereignty Controls (EU/US Data Residency), BeyondCorp Enterprise Zero Trust, VPC Service Controls, Access Transparency Logs and Compliance Reports Manager",
    "domain": "Cloud & SaaS",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation outlines Google Cloud’s compliance posture and technical capabilities supporting customer adherence to global standards, laws, and frameworks. It applies to organizations leveraging Google Cloud for regulated workloads and requires implementation of specific controls mapped to certifications including ISO/IEC 27001, SOC 2, GDPR, HIPAA, and PCI DSS as referenced in the source documentation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "eu-gdpr-cloud-data-processing",
      "eu-dora-ict-third-party-cloud",
      "nist-ir-8011-v1-automated-assessments",
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "google-deepmind-frontier-safety-framework-v2-2025",
    "title": "Google DeepMind Frontier Safety Framework - Second Iteration (4 February 2025) - Critical Capability Levels (CCLs), Security Level Recommendations, Updated Deployment Mitigation Procedure, and Industry-Leading Approach to Deceptive Alignment Risk",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2025-02-04",
    "bluf": "The Google DeepMind Frontier Safety Framework (FSF), second iteration published on 4 February 2025, is Google DeepMind's authoritative public framework for staying ahead of possible severe risks from powerful frontier AI models. The first iteration was introduced in May 2024; the second iteration (this version) was published in February 2025; subsequent strengthening was published in September 2025 ('Strengthening our Frontier Safety Framework'). The Framework has been implemented in DeepMind's safety and governance processes for evaluating frontier models such as Gemini 2.0. The core construct is Critical Capability Levels (CCLs) - the minimum level of capabilities a model must have to play a role in causing severe harm, identified by researching the paths through which a model could cause severe harm in high-risk domains and determining the threshold capabilities for each. Three key updates distinguish the second iteration: (1) Security Level recommendations for each of DeepMind's CCLs, identifying where the strongest efforts to curb model-weight exfiltration risk are needed - with particularly high security levels recommended for CCLs in the domain of machine learning research and development (R&D) given the risk of uncontrolled proliferation accelerating AI development; (2) a more consistent procedure for applying deployment mitigations - preparing a set of mitigations through iterative safeguards development, building an assessable safety case showing severe risks have been minimised to acceptable levels, with the appropriate corporate governance body reviewing the safety case and general availability deployment occurring only if approved, with continued post-deployment review and update; (3) an industry-leading approach to deceptive alignment risk - addressing the risk of an autonomous system deliberately undermining human control, initially by detecting baseline instrumental reasoning ability through automated monitoring and committing to further research as models reach stronger instrumental-reasoning capabilities. The Framework commits to sharing information with appropriate government authorities where a model is assessed to have reached a CCL posing unmitigated and material risk to public safety. Authors include Lewis Ho, Celine Smith, Claudia van der Salm, Joslyn Barnhart, Rohin Shah; leadership Allan Dafoe, Anca Dragan, Andy Song, Demis Hassabis, Four Flynn, Jennifer Beroshi, Helen King, Nicklas Lundblad, and Tom Lue. The Framework is anchored on Google's broader AI Principles and intersects with the Seoul Frontier AI Safety Commitments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "anthropic-responsible-scaling-policy-v2-1-2025",
        "openai-preparedness-framework",
        "uk-aisi-ai-safety-evaluation-framework-2024",
        "us-aisi-ai-safety-institute-2024",
        "seoul-frontier-ai-safety-commitments-2024",
        "eu-ai-act-2024",
        "us-nist-sp-800-218a-secure-ai-development"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "anthropic-responsible-scaling-policy-v2-1-2025",
      "us-nist-sp-800-218a-secure-ai-development"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "govramp-state-local-cloud-security-verification",
    "title": "GovRAMP (formerly StateRAMP) - Cloud Security Verification for US State and Local Government",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "GovRAMP, formerly StateRAMP, is a nonprofit membership organization that brings governments and technology providers together to improve cybersecurity, protect public data, and enable trusted technology adoption. It establishes a common framework for verifying the security of cloud services and third-party technologies for US state and local government, reducing duplicative security reviews and standardizing assessments across government through a standardized, NIST-aligned framework. GovRAMP recognizes three verified statuses: Ready, which meets minimum security requirements and documentation baselines; Provisionally Authorized, which exceeds minimum requirements and includes a government sponsor; and Authorized, the highest verification level, which requires a complete security package including a System Security Plan and boundary diagram plus an independent Security Assessment Report conducted by a GovRAMP Third Party Assessment Organization evaluating compliance with required NIST SP 800-53 controls together with penetration testing and other reviews. GovRAMP Core Verification validates the implementation of 60 foundational controls aligned to NIST SP 800-53 Rev. 5 and the Moderate impact baseline. A Program Management Office administers verification and continuous monitoring, guided by a community of public and private sector leaders through board and committee governance. State programs increasingly accept GovRAMP status for procurement (for example TX-RAMP grants provisional certification to services holding an accepted StateRAMP status), making GovRAMP a reuse vehicle for providers already holding FedRAMP or equivalent evidence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_800_53_alignment",
        "fedramp_relationship",
        "state_program_reciprocity",
        "verification_statuses",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fedramp-moderate-baseline",
      "us-fedramp-authorization-framework",
      "us-44-usc-3614-fedramp-authorization-program"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gp-gdpr-2018",
    "title": "Guadeloupe - GDPR and French Data Protection Law (Loi Informatique et Libertés)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Guadeloupe, as an outermost region of France and the European Union under the TFEU outermost regions framework, is fully subject to the EU General Data Protection Regulation (GDPR) and the French Loi Informatique et Libertés (Law No. 78-17 of 6 January 1978), as modified by Law No. 2018-493 of 20 June 2018 to incorporate GDPR obligations into French national law. The supervisory authority for data protection in Guadeloupe is the Commission Nationale de l'Informatique et des Libertés (CNIL), which exercises full enforcement jurisdiction across all French overseas departments including Guadeloupe. Organisations processing personal data in Guadeloupe must comply with all GDPR obligations: establishing a documented lawful basis for processing, maintaining a Record of Processing Activities (RoPA), fulfilling data subject rights (access, rectification, erasure, restriction, portability, and objection), notifying personal data breaches to CNIL within 72 hours where required, conducting data protection impact assessments for high-risk processing activities, appointing a Data Protection Officer (DPO) where mandated, and applying safeguards for cross-border data transfers outside the European Economic Area. CNIL may investigate complaints and impose administrative fines of up to EUR 20 million or 4% of global annual turnover for significant GDPR violations affecting individuals in Guadeloupe.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/gp-gdpr-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gq-angtic-framework",
    "title": "Equatorial Guinea ANGTIC Framework - AU Malabo Convention and Constitutional Privacy Obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Republic of Equatorial Guinea has established the Agencia Nacional de Tecnologías de la Información y Comunicaciones de Guinea Ecuatorial (ANGTIC) as the national authority for information and communications technology, with regulatory responsibility for ICT infrastructure, digital services, and electronic communications. The Constitution of the Republic of Equatorial Guinea establishes fundamental rights including the right to privacy of personal life, family, home, and correspondence. As a member state of the African Union, Equatorial Guinea is subject to the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014), which constitutes the primary applicable regional standard for personal data protection. Equatorial Guinea does not have a standalone comprehensive personal data protection law. The constitutional privacy framework, ANGTIC regulatory requirements, and AU Malabo Convention principles together constitute the reference legal framework for personal data protection obligations in Equatorial Guinea. Organisations processing personal data in Equatorial Guinea must respect constitutional privacy rights, comply with ANGTIC regulatory obligations for ICT services, and implement data processing practices consistent with the AU Malabo Convention framework. Equatorial Guinea is also a member of the Economic and Monetary Community of Central Africa (CEMAC) and its regional regulatory frameworks for communications are informed by the Central African region.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/gq-angtic-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gr-law-4412-2016-public-procurement-eu-directives-transposition",
    "title": "Greece Law 4412/2016 on Public Procurement (Nomos 4412 - Dimosies Symvaseis Ergon, Promitheion kai Ypiresion) as amended by Law 4782/2021",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Greek Law 4412/2016 on Public Procurement of Works, Supplies and Services (Nomos 4412/2016 - Dimosies Symvaseis Ergon, Promitheion kai Ypiresion / FEK A' 147/8.8.2016) effective 8 August 2016 as substantially amended by Law 4782/2021 (FEK A' 36/9.3.2021) is the principal Greek statute governing procurement of works, supplies, and services by contracting authorities including the State, regions, municipalities, local government entities, public-sector organisations, public bodies and bodies governed by public law, and other entities subject to EU procurement directive scope. Law 4412/2016 transposed into Greek law the EU procurement directives 2014/24/EU (classical), 2014/25/EU (utilities), 2014/23/EU (concessions), and Directive 89/665/EEC and 92/13/EEC on procurement remedies. The 2021 amendments by Law 4782/2021 implemented Hellenic Recovery and Resilience Plan (Greece 2.0) procurement modernisation including simplified procedures, increased centralisation of procurement, and strengthened anti-corruption provisions. The Hellenic Single Public Procurement Authority (Eniaia Anexartiti Archi Dimosion Symvaseon / EAADHSY) is the central regulatory authority responsible for procurement policy, oversight, and complaint resolution. The Electronic National Public Procurement System (Ethniko Systima Ilektronikon Dimosion Symvaseon / ESIDIS, eprocurement.gov.gr) is the mandatory federal e-procurement platform. The Authority for Examination of Pre-contractual Appeals (Archi Exetasis Proxidikastikon Prosfygon / AEPP) is the specialised tribunal for procurement pre-contractual appeals. Procurement methods established by Law 4412/2016 art. 26 to 32 comprise (a) Open procedure (Anoichti diadikasia, the default open public procedure), (b) Restricted procedure (Kleisti diadikasia, with prequalification), (c) Competitive procedure with negotiation (Antagonistiki diadikasia me diapragmateusi), (d) Competitive dialogue (Antagonistikos dialogos, for complex acquisitions), (e) Innovation partnership (Etairiki kainoto-mias), (f) Negotiated procedure without prior publication (Diadikasia me diapragmateusi xoris prodimosieusi, under prescribed exceptions), (g) Direct negotiated procedure (Apefthias anathesis, sole-source for small-value below thresholds), and (h) Electronic auctions (Ilektronikos pleistiriasmos).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "eu-public-procurement-directive-2014-24-construction",
      "eu-directive-2014-25-utilities-procurement",
      "gr-law-4624-2019"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "gr-law-4624-2019",
    "title": "Greece Data Protection Law 4624/2019 - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Greece's Data Protection Law 4624/2019 (Νόμος 4624/2019, published in Government Gazette I/137 of 29 August 2019, 'On Personal Data Protection and Implementation of EU Regulation 2016/679') is Greece's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Greece. The GDPR is directly applicable Greek law by virtue of Greece's EU membership. Law 4624/2019 provides national derogations, additions, and specifications that the GDPR permits EU member states to adopt and repeals the prior Greek Personal Data Protection Act (Law 2472/1997). Enforcement: the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα - APDPCH, in English: HDPA - Hellenic Data Protection Authority) is Greece's independent data protection supervisory authority. The HDPA is Greece's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Greek national provisions: (1) Age of digital consent: Greece has set the age of consent for information society services at 15 years (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 15 require parental or guardian consent; (2) Criminal data - Law 4624/2019 provides that processing of personal data relating to criminal convictions and offences by private entities is permitted in limited circumstances specified by law; public authorities may process criminal data under applicable Greek legislation; (3) Employment context - Law 4624/2019 contains specific provisions on processing personal data in employment contexts, including the processing of employee data by employers subject to Greek labour law; (4) Special categories - processing of sensitive personal data (health, biometric, genetic, racial, religious, political, sexual orientation, trade union membership) in Greece is subject to additional safeguards under Law 4624/2019 beyond GDPR's baseline; (5) Public sector - Greek public authorities are subject to Law 4624/2019 provisions on public authority processing, including specific rules for judicial, law enforcement, and intelligence processing; (6) Research and statistics - specific provisions permitting extended processing for scientific research, statistics, and archiving in the public interest. Fines: GDPR administrative fines apply in Greece - up to EUR 20 million or 4% of global annual turnover for the most serious violations. The HDPA has imposed significant GDPR fines across multiple sectors including banking, telecommunications, and insurance. The HDPA is one of the more active EU data protection authorities and has issued landmark enforcement decisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "graphql-specification-2021-query-language",
    "title": "GraphQL Specification October 2021 - Query Language and Runtime Execution Standard for API Workflow",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The GraphQL October 2021 specification (graphql.github.io) defines a query language and runtime for APIs enabling clients to request exactly the data they need; specifies type system (Schema Definition Language), query execution semantics, mutation and subscription operations, introspection, and error handling; adopted as primary API layer in workflow automation platforms, AI agent tool interfaces, and compliance data query systems requiring flexible, typed data retrieval without over-fetching.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-7519-json-web-token-jwt",
      "ietf-oauth-2-1-authorization-framework"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "greece-hellenic-gaming-commission-law-4002-2011",
    "title": "Greece Law 4002/2011 - Hellenic Gaming Commission Online Gambling Licensing and Regulation",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2021-01-01",
    "bluf": "Greece Law 4002/2011 (as amended through Law 4772/2021) establishes the Hellenic Gaming Commission (HGC/ΕΕΕΠ) as an independent regulator, requires Type 1 (sports betting) and Type 2 (online casino) B2C licences, imposes a 35% GGR tax, mandates the National Self-Exclusion Register (ΝΜΕΠ), and requires RNG certification by accredited testing laboratory.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "nist_csf",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "france-anj-online-gambling-loi-2010-476",
      "portugal-srij-online-gambling-decree-66-2015"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "green-key-tourism-eco",
    "title": "Green Key Eco-Rating",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with the Green Key Eco-Rating standard requires adherence to stringent environmental management and operational benchmarks, harmonized with recognized frameworks like the Global Sustainable Tourism Council Industry Criteria. The node validates implementation of an environmental management system, reflecting principles within ISO 14001:2015, which must include a publicly available environmental policy and active guest communications. Water conservation mandates are strict, stipulating maximum flow rates for taps at 8 liters per minute, showers at 9 liters per minute, and toilets at 6 liters per flush. Energy efficiency measures, contextualized by commitments under the Glasgow Declaration on Climate Action in Tourism, demand a minimum of 75% of all lighting be high-efficiency LED technology and that HVAC systems utilize active automatic shutoff sensors. Waste management protocols necessitate sorting into at least three distinct categories. Procurement policies must demonstrate a minimum of 70% of cleaning chemicals are certified with a recognized eco-label, a standard echoed by the EU Ecolabel for Tourist Accommodation Establishments. Furthermore, a complete elimination of single-use plastic toiletries is required, supporting the objectives of the Global Tourism Plastics Initiative. The standard also mandates annual staff sustainability training conducted within a 12-month cycle and requires providing at least two local or organic food options, fulfilling a comprehensive set of the Foundation for Environmental Education’s mandatory criteria.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "gstc-tourism-criteria",
      "iso-21401-tourism-sustain",
      "iso-50001-energy",
      "iso-46001-water-eff",
      "haccp-food-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gri-1-foundation",
    "title": "GRI 1: Foundation (2021)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "GRI 1: Foundation 2021 is the core standard in the Global Reporting Initiative (GRI) framework that establishes the foundational concepts, principles, and requirements organizations must follow when reporting on their environmental, social, and governance (ESG) impacts. GRI 1 introduces the concept of 'double materiality' through its impact materiality focus - organizations must report on their significant impacts on the economy, environment, and people, regardless of whether those impacts are financially material to the organization. GRI is used by over 10,000 organizations globally and is required or referenced by the EU Corporate Sustainability Reporting Directive (CSRD), the UN SDGs monitoring framework, and stock exchange ESG disclosure requirements in over 50 markets. Organizations using GRI must make a statement of use specifying which GRI Standards were used and the reporting period covered; false or misleading GRI claims expose organizations to greenwashing liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gri-universal-standards",
      "csrd-eu-sustainability",
      "un-guiding-principles-business-hr",
      "ifrs-s1-general",
      "sasb-conceptual-framework",
      "tcfd-climate-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gri-14-mining-sector-standard-2022",
    "title": "GRI 14 Mining Sector Standard 2022 - Sector-Specific Material Topics, Disclosures and Reporting Requirements for Mining and Quarrying Companies",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This standard requires mining and quarrying companies to report on sector-specific impacts including biodiversity, water, tailings management, and community relations, with mandatory disclosures under GRI 14, particularly Disclosure 14-1 (biodiversity protection) and Disclosure 14-3 (water withdrawal). It applies to all organizations in the mining sector that use the GRI Standards for sustainability reporting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp",
      "un-sdg-corporate-mapping"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "gri-305-emissions-2016",
    "title": "GRI 305: Emissions 2016",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard requires organizations to publicly report their direct (Scope 1), energy indirect (Scope 2), and other indirect (Scope 3) greenhouse gas (GHG) emissions, as well as emissions intensity, to provide a comprehensive inventory of their climate impact. The core requirements are detailed in Disclosures 305-1, 305-2, 305-3, and 305-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gri-1-foundation",
      "ghg-protocol-scope3",
      "iso-14064-ghg-quantify",
      "tcfd-climate-risk",
      "issb-ifrs-s2-climate-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gri-306-waste-2020",
    "title": "GRI 306: Waste 2020",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-05-19",
    "bluf": "This standard requires organizations to report on their waste-related impacts, detailing waste generation, management practices, and circularity measures. It mandates disclosures on the management approach (306-1), waste-related actions (306-2), total waste generated (306-3), waste diverted from disposal (306-4), and waste directed to disposal (306-5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gri-1-foundation",
      "iso-14001-ems",
      "csrd-eu-sustainability",
      "weee-electronic-waste"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gri-401-employment-2016",
    "title": "GRI 401: Employment 2016",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard requires organizations to report on their employment practices, including the rate of new employee hires and employee turnover (Disclosure 401-1), benefits provided to full-time employees that are not extended to temporary or part-time employees (Disclosure 401-2), and parental leave policies and return-to-work rates (Disclosure 401-3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gri-1-foundation",
      "gri-universal-standards",
      "iso-30414-human-capital",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gri-403-ohs-2018",
    "title": "GRI 403: Occupational Health and Safety 2018",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard requires organizations to report on their occupational health and safety (OHS) management system, processes for hazard identification and risk assessment, and performance metrics. Key disclosures include reporting on the OHS management system (Disclosure 403-1), work-related injuries (Disclosure 403-9), and work-related ill health (Disclosure 403-10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gri-1-foundation",
      "gri-universal-standards",
      "iso-26000-social-resp",
      "ilo-fundamental-rights-work",
      "iso-30414-human-capital"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gri-universal-standards",
    "title": "GRI Universal Standards",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Global Reporting Initiative (GRI) Universal Standards 2021 are the global baseline for modular sustainability reporting. They cover impact materiality-how an organization impacts the economy, environment, and people-ensuring consistent, high-quality disclosure for stakeholders and communities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-guiding-principles-business-hr",
      "oecd-guidelines-multinational-ent",
      "iso-26000-social-resp",
      "csrd-eu-sustainability",
      "issb-s1-s2-standard"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "grid-code-entsoe",
    "title": "ENTSO-E Grid Code Compliance",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Entities connecting to the European interconnected grid must demonstrate rigorous adherence to harmonized technical and security standards. This compliance framework, principally defined by Commission Regulation (EU) 2016/631 on requirements for grid connection of generators, mandates stringent operational performance. Power-generating modules must ensure continuous operation between 49 Hz and 51 Hz and prove fault-ride-through capability for a minimum of 150 ms. The system validates that active power control is enabled (`active_power_control_enabled`) and that reactive power capability is verified (`reactive_power_capability_verified`), consistent with protocols from the ENTSO-E Implementation Guidance Document on Compliance Testing and Monitoring. Similar obligations for other participants are outlined within Commission Regulation (EU) 2016/1388 on Demand Connection and Commission Regulation (EU) 2016/1447 for HVDC systems. Augmenting these operational rules, Delegated Regulation (EU) 2024/1183, the Network Code on Cybersecurity, alongside the overarching Directive (EU) 2022/2555 (NIS2 Directive), establishes critical digital resilience criteria. These mandates necessitate a certified ISMS (`cybersecurity_isms_certified`), enforced SCADA access MFA (`scada_access_mfa_enforced`), and required communication encryption (`communication_encryption_required`). Organizations are further obligated to complete an annual cyber risk assessment (`annual_cyber_risk_assessment_required`) and report significant incidents within a 24-hour maximum timeframe. This verification extends to critical system restoration, confirming that black start capability is tested (`black_start_capability_tested`).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dora-ict-risk",
      "eu-taxonomy-sustainable",
      "iso-50001-energy",
      "nist-sp-800-82r3-ot-security"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gs1-epcis-transparency",
    "title": "GS1 EPCIS: Supply Chain Visibility",
    "domain": "Logistics & Supply Chain",
    "version": "1.2.0",
    "last_updated": "2026-07-03",
    "bluf": "Compliance with global supply chain visibility mandates requires strict adherence to standardized data exchange protocols and security controls. This node enforces alignment with the GS1 EPC Information Services (EPCIS) Standard, Release 2.0, also codified as ISO/IEC 19987:2024, which forms the technical backbone for interoperable electronic tracing as required by regulations such as the US FDA Drug Supply Chain Security Act (DSCSA) and the Food Safety Modernization Act (FSMA) Section 204. It also supports compliance with the European Union Falsified Medicines Directive. All inbound data transmissions must be EPCIS 2.0 compliant, utilize TLS 1.2 or higher for transport security, and require OAuth2 authentication for access control. Data integrity is paramount; the system validates all XML and JSON-LD submissions against the official schema, enforces the GS1 Core Business Vocabulary standard, and verifies GS1 check digits. To ensure event uniqueness and non-repudiation, each event must possess a hash ID generated using the SHA-256 algorithm. System performance is managed by limiting event payloads to a maximum of 10 MB and maintaining a data capture error rate below a 1 percent threshold. Furthermore, strict redaction is enabled for unauthorized queries to protect sensitive business information. All captured event data is subject to a 2190-day retention period, fulfilling long-term record-keeping obligations under these diverse regulatory frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-fsma-compliance",
      "iso-28000-supply-chain",
      "c-tpat-minimum-security",
      "wco-safe-framework"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gsma-common-api-framework-capif-5g",
    "title": "GSMA Common API Framework (CAPIF) for 5G Networks - API Exposure: 3GPP TS 23.222, API Invoker Onboarding, API Provider Domain, Security Policies, Monitoring, Logging and North-Bound Interface for Third-Party Application Access to Network Capabilities",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The GSMA CAPIF standard defines secure, interoperable API exposure mechanisms for third-party application access to 5G network capabilities via standardized north-bound interfaces, requiring API providers and invokers to implement mutual authentication, audit logging, and policy enforcement per 3GPP TS 23.222 and GSMA Open Gateway specifications. It applies to mobile network operators, API providers, and application developers integrating with 5G core services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "3gpp-5g-nr-release-17-specifications",
      "3gpp-ims-ip-multimedia-subsystem-release-16",
      "eu-5g-cybersecurity-toolbox-2020",
      "eu-nis2-telecoms-essential-services",
      "cisa-zero-trust-maturity-model-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gsma-fraud-security-group-nir-recommendations",
    "title": "Mobile Network Operator Fraud Controls for SIM Swap, Account Takeover and CLI Spoofing (GSMA Fraud and Security Group practices; PSD2 Strong Customer Authentication)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "Mobile Network Operators (MNOs) implement controls against identity-related fraud such as SIM swap, account takeover and Calling Line Identification (CLI) spoofing using risk-based authentication, customer notification and inter-operator information sharing. This guidance is informed by the work of the GSMA Fraud and Security Group (FASG), the mobile industry's working group for fraud and security, and by the strong-customer-authentication requirements of EU PSD2 (Commission Delegated Regulation (EU) 2018/389) where mobile authentication channels support payment authentication. Note: GSMA document FS.33 is the Network Function Virtualisation (NFV) Threats Analysis and does not address SIM swap; there is no GSMA recommendation series numbered NIR.01 to NIR.12 - those identifiers have been removed and the controls below are stated as MNO fraud-control practices grounded in FASG guidance and applicable payment-authentication law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-psd2-strong-customer-authentication",
      "nist-800-171-rev-3"
    ],
    "primary_citations_count": 3
  },
  {
    "node_id": "gsma-mvno-roaming-framework-best-practice",
    "title": "GSMA Mobile Virtual Network Operator (MVNO) and International Roaming Framework - Inter-Operator Tariff, Steering of Roaming Rules, CAMEL and GPRS Roaming Exchange (GRX), Wholesale Roaming Agreement Templates and Fraud Management",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This GSMA framework establishes best practices for MVNOs and MNOs engaging in international roaming, including tariff transparency, steering of roaming, fraud prevention, and technical interoperability via CAMEL and GRX. It applies to mobile operators and virtual operators entering wholesale roaming agreements, with key guidance in GSMA PRD IR.62, IR.21, and FS.11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-roaming-regulation-2022-612",
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-nis2-telecoms-essential-services",
      "3gpp-ims-ip-multimedia-subsystem-release-16",
      "cisa-zero-trust-maturity-model-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gsma-nesas-network-equipment-security-assurance",
    "title": "GSMA NESAS Network Equipment Security Assurance Scheme - Security Evaluation Methodology and Audit Requirements",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "3.2.0",
    "last_updated": "2024-05-15",
    "bluf": "The GSMA Network Equipment Security Assurance Scheme (NESAS) mandates that network equipment vendors undergo a comprehensive security audit of their development and product lifecycle processes, and a security evaluation of their network equipment against 3GPP Security Assurance Specifications (SCAS), as detailed in NESAS Security Evaluation Methodology Section 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27017-cloud-defence",
      "nist-800-171-rev-3"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "gstc-tourism-criteria",
    "title": "GSTC Sustainability Criteria",
    "domain": "Food & Hospitality",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with the Global Sustainable Tourism Council (GSTC) framework necessitates a comprehensive approach to operational sustainability, integrating key principles from international agreements. This node validates the implementation of an active sustainable management system (has_sustainable_management_system: true), subject to a mandatory annual reporting cycle (sustainability_reporting_frequency_months: 12). Socio-economic responsibilities, reflecting the UNWTO Global Code of Ethics for Tourism, demand a local_purchasing_and_employment_policy_active is maintained and that measures for commercial_exploitation_prevention_enforced are effective. Cultural integrity is paramount, requiring that cultural_heritage_protection_documented procedures are in place and the trade of sensitive items is strictly controlled, wherein historical_artifact_sales_prohibited is enforced consistent with the Convention on International Trade in Endangered Species of Wild Fauna and Flora. Environmental performance, aligned with the ISO 14001:2015 standard and United Nations Sustainable Development Goals, mandates that greenhouse_gas_emissions_measured are tracked against a minimum ghg_reduction_target_percentage of 5. Furthermore, water_consumption_monitoring_active systems must be operational, alongside policies confirming single_use_plastics_eliminated from operations and a solid_waste_reduction_policy_active is implemented to promote responsible consumption. Finally, ethical wildlife interactions are confirmed by ensuring captive_animal_welfare_standards_met are upheld.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-21401-tourism-sustain",
      "iso-14001-ems",
      "un-sdg-alignment",
      "fair-trade-tourism",
      "green-key-tourism-eco",
      "iso-45001-work-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gt-decreto-57-92-ley-contrataciones-estado-guatecompras",
    "title": "Guatemala Decreto 57-92 Ley de Contrataciones del Estado (1992) as amended and GUATECOMPRAS",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Guatemala Decreto 57-92 (Decreto Numero 57-92 del Congreso de la Republica) of 21 October 1992 known as Ley de Contrataciones del Estado is the principal Guatemalan statute governing procurement of goods, services, and works by the State Public Administration including the Executive Branch (Organismo Ejecutivo) ministries, the Legislative Branch (Organismo Legislativo), the Judicial Branch (Organismo Judicial), Decentralized Entities (Entidades Descentralizadas), Autonomous Entities (Entidades Autonomas), Departmental Governments, Municipalities (Municipalidades), and other entities of the public sector. Decreto 57-92 has been substantially amended multiple times including by Decreto 46-2016 (transparency reforms), Decreto 27-2021 (further modernisation including beneficial ownership disclosure), and Acuerdo Gubernativo 122-2016 (regulation). The Direccion General de Adquisiciones del Estado (DGAE) under the Ministry of Public Finance (Ministerio de Finanzas Publicas) is the central procurement policy authority. The Sistema de Informacion de Contrataciones y Adquisiciones del Estado (GUATECOMPRAS / guatecompras.gt) operated by the Ministry of Finance is the mandatory federal e-procurement platform. Procurement methods established by Decreto 57-92 art. 16 to 44 comprise (a) Licitacion Publica (Public Tender, the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Cotizacion (Quotation, for medium-value acquisitions), (c) Compra Directa con Oferta Electronica (Direct Procurement with Electronic Offer, for medium-low-value acquisitions), (d) Compra de Baja Cuantia (Low-Value Procurement, for small-value below prescribed thresholds), (e) Subasta Electronica Inversa (Reverse Electronic Auction, for standardised products), (f) Contrato Abierto (Open Contract / Framework Agreement), and (g) Casos de Excepcion (Exception Cases under art. 44 including emergency, sole-source for technical reasons, prior failed tendering, and prescribed-class exemptions). The Contraloria General de Cuentas conducts procurement audit. The Comision Presidencial Contra la Corrupcion (CPCC) coordinates anti-corruption oversight. Guatemala is a party to CAFTA-DR (in force 2006), the EU-Central America Association Agreement (in force 2013), the SIECA framework, and UNCAC. Guatemala is NOT a party to the WTO GPA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "gt-laip-2008",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "gt-laip-2008",
    "title": "Guatemala Law on Access to Public Information 2008 - Personal Data Protection Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Guatemala enacted the Law on Access to Public Information (Ley de Acceso a la Información Pública, LAIP, Decree 57-2008), which includes provisions for the protection of personal data held by public bodies. The law is administered by the Procurador de los Derechos Humanos (PDH) and the Comisión de Acceso a la Información Pública. It designates personal data held by public entities as confidential information, prohibits unauthorised disclosure of personal information, grants individuals the right to access and correct their personal data held by public bodies, and requires public institutions to implement appropriate security measures for the personal data they hold. The LAIP establishes Guatemala's foundational framework for personal data protection in the public sector, providing a right of habeas data consistent with Article 31 of the Guatemalan Constitution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/gt-laip-2008.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gu-framework",
    "title": "Guam - Federal and Territorial Privacy Rights Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Guam is an unincorporated organised territory of the United States located in the western Pacific Ocean. Guam has its own Organic Act and constitution-equivalent instrument establishing a civilian government with a Governor, legislature (Guam Legislature), and judicial branch. US federal law applies to Guam as a territory. Accordingly, the primary federal privacy statutes - including the Health Insurance Portability and Accountability Act (HIPAA), the Children's Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), the Gramm-Leach-Bliley Act (GLBA), and the Federal Trade Commission Act - apply in Guam and govern the handling of personal data by organisations operating in the territory. The Federal Trade Commission exercises jurisdiction over unfair or deceptive acts or practices relating to personal data in Guam. The Guam Code Annotated contains provisions relevant to privacy in government records and personal information. Guam does not have a standalone comprehensive personal data protection law equivalent to the GDPR. Organisations processing personal data of individuals in Guam must comply with all applicable US federal privacy statutes, the Guam Code Annotated privacy provisions, and implement appropriate technical and organisational security measures. As a Pacific Island territory, Guam engages with Pacific regional digital governance frameworks through its participation in the region.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/gu-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "guidance-on-model-risk-management",
    "title": "Guidance on Model Risk Management",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2011-04-04",
    "bluf": "This supervisory guidance, issued by the Federal Reserve and the Office of the Comptroller of the Currency (OCC), is intended for use by banking organizations and supervisors to assess the management of model risk. It applies to all banking organizations supervised by the Federal Reserve, taking into account each organization’s size, nature, complexity, and the extent of its use of models. The guidance defines a model as a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories to process input data into quantitative estimates. The core obligation is for banking organizations to be attentive to the possible adverse consequences of decisions based on models that are incorrect or misused. Organizations must address these consequences through active model risk management, which includes robust model development, implementation, and use; effective validation; and sound governance, policies, and controls. Model risk is the potential for adverse consequences from decisions based on incorrect or misused model outputs, which can lead to financial loss, poor business and strategic decision-making, or damage to a banking organization’s reputation. A guiding principle is the 'effective challenge' of models, which involves critical analysis by objective, informed parties that can identify model limitations and produce appropriate changes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sr-11-7-model-risk-management",
      "supervisory-guidance-model-risk-management",
      "basel-ii-capital-framework",
      "ecb-guide-internal-models",
      "principles-effective-risk-data-aggregation",
      "bcbs-principles-sound-management-operational-risk"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "guide-computer-security-log-management",
    "title": "Guide to Computer Security Log Management",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-09-01",
    "bluf": "A log is a record of the events occurring within an organization’s systems and networks. Logs are composed of log entries; each entry contains information related to a specific event that has occurred within a system or network. This document provides guidance on computer security log management-the process for generating, transmitting, storing, analyzing, and disposing of computer security log data. Log management is essential to ensuring that computer security records are stored in sufficient detail for an appropriate period of time. Routine log analysis is beneficial for identifying security incidents, policy violations, fraudulent activity, and operational problems. Logs are also useful when performing auditing and forensic analysis, supporting internal investigations, establishing baselines, and identifying operational trends and long-term problems. \n\nThis guidance is primarily for Federal agencies to comply with legislation like the Federal Information Security Management Act of 2002 (FISMA), but may also be useful for non-governmental organizations subject to regulations like the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Sarbanes-Oxley Act of 2002 (SOX), the Gramm-Leach-Bliley Act (GLBA), and the Payment Card Industry Data Security Standard (PCI DSS). A fundamental problem with log management is effectively balancing limited resources with a continuous supply of log data. This involves challenges in log generation and storage, protection, and analysis. Implementing the recommendations should assist in facilitating more efficient and effective log management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-800-53-au2",
      "nist-cybersecurity-framework-2-0",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "guide-developing-security-plans",
    "title": "Guide for Developing Security Plans for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-02-01",
    "bluf": "The objective of system security planning is to improve protection of information system resources. The protection of a system must be documented in a system security plan, a requirement of the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA). The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The system security plan also delineates responsibilities and expected behavior of all individuals who access the system.\n\nThis guidance applies to federal agencies and is designed for program managers, system owners, and security personnel. It provides basic information on how to prepare a system security plan, which should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system. Since the system security plan establishes and documents the security controls, it should form the basis for the authorization to operate, supplemented by an assessment report and a plan of actions and milestones. Management authorization should be based on an assessment of management, operational, and technical controls. Re-authorization should occur whenever there is a significant change in processing, but at least every three years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "guide-developing-security-plans-federal",
    "title": "Guide for Developing Security Plans for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-02-01",
    "bluf": "The objective of system security planning is to improve protection of information system resources. This guidance is a requirement of the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA). All federal systems have some level of sensitivity and require protection as part of good management practice, and the protection of a system must be documented in a system security plan.\n\nThe purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The system security plan also delineates responsibilities and expected behavior of all individuals who access the system. It should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system. The plan establishes and documents security controls, forming the basis for authorization by a senior management official, who accepts the associated risk by authorizing the system to operate. This authorization should be based on an assessment of management, operational, and technical controls. Re-authorization should occur whenever there is a significant change in processing, but at least every three years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "guide-developing-security-plans-federal-information-systems",
    "title": "Guide for Developing Security Plans for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-02-01",
    "bluf": "The objective of system security planning is to improve protection of information system resources. All federal systems have some level of sensitivity and require protection, which must be documented in a system security plan as required by OMB Circular A-130 and the Federal Information Security Management Act (FISMA). The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The plan also delineates responsibilities and expected behavior of all individuals who access the system. It should reflect input from various managers with responsibilities concerning the system, including information owners, the system owner, and the senior agency information security officer (SAISO).\n\nManagement authorization for a system to operate is based on an assessment of management, operational, and technical controls documented in the system security plan. By authorizing processing, a manager accepts the system's associated risk. The plan forms the basis for this authorization, supplemented by an assessment report and a plan of actions and milestones. Re-authorization should occur whenever there is a significant change in processing, but at least every three years. This guidance applies to federal agencies, program managers, system owners, and security personnel, and may be used by non-governmental organizations on a voluntary basis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "guide-developing-security-plans-federal-systems",
    "title": "Guide for Developing Security Plans for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-02-01",
    "bluf": "The objective of system security planning is to improve protection of information system resources, as all federal systems have some level of sensitivity and require protection. The protection of a system must be documented in a system security plan, a requirement of the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA). The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The plan also delineates responsibilities and expected behavior of all individuals who access the system, reflecting input from various managers including information owners, the system owner, and the senior agency information security officer (SAISO).\n\nManagement authorization to operate a system is based on an assessment of management, operational, and technical controls documented in the system security plan. By authorizing processing, a manager accepts the associated risk. The system security plan, supplemented by an assessment report and a plan of actions and milestones, forms the basis for this authorization. Re-authorization should occur whenever there is a significant change in processing, but at least every three years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-200-minimum-security-requirements"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "guide-for-developing-security-plans",
    "title": "Guide for Developing Security Plans for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-02-01",
    "bluf": "The objective of system security planning is to improve protection of information system resources. The protection of a system must be documented in a system security plan, a requirement of the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA). The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The system security plan also delineates responsibilities and expected behavior of all individuals who access the system. It should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system and reflect input from various managers, including information owners, the system owner, and the senior agency information security officer (SAISO).\n\nThis guidance is for federal agencies and is intended for program managers, system owners, and security personnel. The system security plan establishes and documents the security controls and forms the basis for the authorization to operate, granted by a management official who accepts the associated risk. A senior management official must authorize a system to operate based on an assessment of management, operational, and technical controls. Re-authorization should occur whenever there is a significant change in processing, but at least every three years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "guide-mapping-information-types-security",
    "title": "Volume I: Guide for Mapping Types of Information and Information Systems to Security Categories",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2008-08-01",
    "bluf": "This guideline has been developed to assist Federal government agencies to categorize information and information systems. The guideline’s objective is to facilitate application of appropriate levels of information security according to a range of levels of impact or consequences that might result from the unauthorized disclosure, modification, or use of the information or information system. It addresses the Federal Information Security Management Act (FISMA) direction to develop guidelines recommending the types of information and information systems to be included in each category of potential security impact. This guideline applies to all Federal information systems other than national security systems.\n\nThis publication is intended to serve a diverse federal audience of information system and information security professionals including individuals with oversight responsibilities (e.g., chief information officers), organizational officials (e.g., mission and business area owners), individuals with development responsibilities, and individuals with implementation and operational responsibilities. It provides a structured, yet flexible framework for satisfying the requirements of FISMA. Security categorization is the key first step in the Risk Management Framework because of its effect on all other steps, from the selection of security controls to the level of effort in assessing security control effectiveness.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "guide-telework-remote-access-byod",
    "title": "Guide to Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Security",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2016-07-01",
    "bluf": "For many organizations, their employees, contractors, business partners, vendors, and other users utilize enterprise telework technologies to perform work from external locations, using remote access technologies to interface with an organization’s non-public computing resources. The nature of telework and remote access technologies-permitting access to protected resources from external networks and often externally controlled hosts-generally places them at higher risk. All components of these solutions, including organization-issued and bring your own device (BYOD) client devices, remote access servers, and internal resources, should be secured against expected threats as identified through threat models. Major security concerns include the lack of physical security controls, the use of unsecured networks, the connection of infected devices to internal networks, and the availability of internal resources to external hosts.\n\nThis publication provides information on security considerations for several types of remote access solutions and makes recommendations for securing telework, remote access, and BYOD technologies. It also gives advice on creating related security policies, which should be based on the assumption that external environments contain hostile threats. An organization should assume that external facilities, networks, and devices contain hostile threats that will attempt to gain access to the organization’s data and resources. Organizations should plan policies that define permitted forms of remote access, restrictions on client devices, and how servers are secured and configured to enforce these policies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-113-guide-ssl-vpns",
      "nist-sp-800-123-server-security"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "guide-to-storage-encryption-technologies",
    "title": "Guide to Storage Encryption Technologies for End User Devices",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2007-11-01",
    "bluf": "This publication assists organizations in understanding, planning, implementing, and maintaining storage encryption technologies for end user devices, including personal computers, consumer devices like smart phones, and removable storage media. It addresses threats to information confidentiality such as device loss or theft, insider attacks, and malware. The primary security controls discussed for restricting access to sensitive information, particularly personally identifiable information (PII), are encryption and authentication. The guide provides practical, real-world guidance for three classes of storage encryption: full disk encryption, volume and virtual disk encryption, and file/folder encryption. It makes recommendations for implementing and using each type.\n\nKey recommendations for Federal departments and agencies include using centralized management for most deployments to ensure policy verification, key management, and data recovery. Organizations should ensure all cryptographic keys are secured and managed properly throughout their lifecycle, from generation to destruction, to support data recovery. Appropriate user authenticators should be selected, with a preference for two-factor authentication, as using a single-factor authenticator for both OS login and encryption significantly weakens protection. Storage encryption by itself is considered insufficient; it must be complemented by other security controls, such as securing device operating systems, revising organizational policies, and making users aware of their responsibilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-60-v2r1-appendices",
      "fips-199-security-categorization"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "guidelines-securing-wireless-local-area-networks",
    "title": "Guidelines for Securing Wireless Local Area Networks (WLANs)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2012-02-01",
    "bluf": "A wireless local area network (WLAN) is a group of wireless networking devices within a limited geographic area that exchange data through radio communications, based on the IEEE 802.11 standard. The security of each WLAN is heavily dependent on how well each WLAN component-including client devices, access points (APs), and wireless switches-is secured throughout the WLAN lifecycle. This publication provides recommendations for improving the security of their WLANs through security configuration and monitoring, supplementing other NIST publications by consolidating and strengthening their key recommendations. Core obligations for organizations include having standardized security configurations for common WLAN components, considering how a WLAN may affect the security of other networks, and implementing logically separated WLANs for internal and guest use.\nOrganizations should have policies that clearly state which forms of dual connections are permitted or prohibited for WLAN client devices and enforce these policies through appropriate security controls. It is crucial to ensure that the organization’s WLAN client devices and APs have configurations at all times that are compliant with the organization’s WLAN policies. To support this, organizations must perform both attack monitoring and vulnerability monitoring, and conduct regular periodic technical security assessments for their WLANs, at least annually, to evaluate overall security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-115-security-testing",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "gulf-cooperation-council-vat-framework-2016",
    "title": "Gulf Cooperation Council VAT Unified Agreement 2016",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a unified value-added tax framework across GCC member states, mandating a standard 5% VAT rate, zero-rating for international services, and exemptions for healthcare and education services. Key obligations are derived from the GCC VAT Agreement, though specific article references are not present in the provided source text.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-cbcr-guidance-2023-update"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "gw-arn-ecowas",
    "title": "Guinea-Bissau ARN Framework - ECOWAS Data Protection Obligations and Telecommunications Personal Data",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Guinea-Bissau's legal framework for personal data protection is anchored in the ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection, which is binding on Guinea-Bissau as a member state of the Economic Community of West African States (ECOWAS), and in the constitutional right to privacy established by the Constitution of the Republic of Guinea-Bissau. The Autoridade Reguladora Nacional (ARN) is the national regulatory authority for electronic communications in Guinea-Bissau and has oversight of personal data obligations in the telecommunications sector. The ECOWAS Supplementary Act requires ECOWAS member states to establish a comprehensive national data protection framework including principles of lawful processing, consent, purpose limitation, data quality, proportionality, security, and data subject rights of access and correction. Guinea-Bissau does not have a standalone comprehensive data protection law in force that fully implements the ECOWAS Supplementary Act, but the Act is the binding regional standard applicable to personal data processing in Guinea-Bissau. Organisations processing personal data in Guinea-Bissau must comply with ECOWAS Supplementary Act principles, ARN telecommunications regulatory requirements for subscriber data protection, and the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014) as an African Union member.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/gw-arn-ecowas.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gxp-clinical-practice",
    "title": "Good Clinical Practice (GCP)",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Good Clinical Practice (GCP) is an international ethical and scientific quality standard for designing, conducting, recording, and reporting trials that involve human subjects. Based on the ICH E6(R2) guideline, compliance provides public assurance that the rights, safety, and well-being of trial subjects are protected and that the clinical trial data are credible.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-11-records",
      "iso-14971-medical-risk",
      "gdpr-health-data-compliance",
      "hipaa-privacy-rule",
      "iso-13485-medical-qms",
      "ismp-medication-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gxp-mfg-practice",
    "title": "Good Mfg Practice (GMP)",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Good Manufacturing Practice (GMP) (21 CFR Parts 210 and 211) is the primary U.S. and global standard for ensuring that pharmaceutical and medical device products are consistently produced and controlled according to high-quality standards. it is designed to minimize the risks involved in production that cannot be eliminated through testing the final product.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-11-records",
      "fda-21-cfr-part-820-qsr",
      "iso-13485-medical-qms",
      "iso-14971-medical-risk",
      "iso-9001-quality-mgt",
      "gxp-clinical-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "gy-dpa-2024",
    "title": "Guyana Data Protection Act 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Guyana enacted the Data Protection Act 2024, establishing the first comprehensive data protection framework in the country following years of digital economy growth driven by the oil and gas sector. The Act is administered by the Data Protection Commissioner of Guyana. It establishes principles for the lawful processing of personal data, grants data subjects rights of access, rectification, and erasure, requires data controllers to identify a lawful basis for processing and implement security safeguards, and restricts cross-border transfers to jurisdictions with adequate protection. The Act aligns with CARICOM data protection standards, bringing Guyana into line with neighbouring Caribbean jurisdictions that have long had data protection legislation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/gy-dpa-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "haccp-food-safety",
    "title": "HACCP (Food Safety)",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with Hazard Analysis and Critical Control Point (HACCP) systems mandates a systematic, science-based approach to food safety management, aligning with global standards like Codex Alimentarius CXC 1-1969 and specific regulatory frameworks such as the EU's Regulation (EC) No 852/2004. This methodology is also codified in United States regulations, including 21 CFR Part 117 for human food under FSMA, 9 CFR Part 417 governing meat and poultry, 21 CFR Part 120 for juice processing, and 21 CFR Part 123 pertaining to fish products. Conformance requires that a multidisciplinary HACCP team is assembled and that robust prerequisite programs are implemented. A comprehensive, documented hazard analysis must be conducted, leading to the identification of at least one Critical Control Point (CCP) for which validated critical limits are established. Continuous process control is demonstrated through monitoring procedures executed at a maximum frequency of 24 hours, supported by an active corrective action plan to address any deviations. System integrity is validated through annual verification audits conducted within a 365-day cycle, frequent sensor calibration at 30-day intervals, and confirmation that the product recall plan is tested. All relevant documentation must be maintained according to a record retention period of 2 years, while personnel competency is upheld with a minimum of 8 annual employee training hours.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-gen",
      "eu-food-law-178-2002",
      "fda-fsma-compliance",
      "iso-22000-food-mgt",
      "gfsi-benchmarking",
      "brc-food-safety-global"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hague-adoption-convention-1993-intercountry-adoption",
    "title": "Hague Adoption Convention 1993 - Intercountry Adoption Subsidiarity Principle and Central Authority Cooperation",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Convention on Protection of Children and Co-operation in respect of Intercountry Adoption (Hague Adoption Convention) was adopted by the Hague Conference on Private International Law on 29 May 1993 and entered into force on 1 May 1995. The Convention establishes legal safeguards and cooperation between Contracting States to ensure intercountry adoptions are made in the best interests of the child and respect the child's fundamental rights as recognised in international law. Article 4 sets out essential requirements that must be met before intercountry adoption can take place including: confirmation that child is adoptable, determination after due consideration of subsidiary placement options that intercountry adoption is in child's best interests (subsidiarity principle), informed consents obtained without payment, and child's consent where appropriate. Article 5 sets requirements applicable to receiving State including agreement that prospective adoptive parents are eligible and suited to adopt, ensuring child is or will be authorised to enter and reside permanently. Article 6 requires each Contracting State to designate a Central Authority to discharge duties; Article 11 establishes Accredited Bodies framework for cooperation. The Convention has 105 Contracting States as of 2024 with the United States, Canada, Australia, UK, France, Germany, Brazil, China, India, South Africa among ratifying states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-convention-rights-of-child-1989-article-3-best-interests",
      "hague-service-convention-1965"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hague-apostille-convention-1961",
    "title": "Hague Apostille Convention 1961 - Abolishing the Requirement of Legalisation for Foreign Public Documents",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Apostille Convention (125 State Parties, the largest Hague Conference convention as of April 2026) abolishes the multi-step legalisation chain for public documents exchanged between Contracting States, replacing it with a single apostille certificate issued by the designated authority in the issuing state; businesses operating internationally must obtain apostilles for public documents (company extracts, notarial acts, certified copies, judicial decisions) used in foreign jurisdictions - the e-Apostille programme enables electronic verification via the Hague Apostille Section's electronic register, with 70+ states issuing e-Apostilles as of 2026 - and failure to apostille documents correctly results in rejection by foreign authorities and legal delays.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "new-york-convention-1958-foreign-arbitral-awards",
      "un-singapore-convention-mediation-2019",
      "hague-choice-of-court-convention-2005",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hague-child-abduction-convention-1980",
    "title": "Hague Child Abduction Convention 1980 - Civil Aspects of International Child Abduction",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-25",
    "bluf": "The Hague Convention on the Civil Aspects of International Child Abduction (1980) - 103 Contracting States - creates a Central Authority network and mandatory prompt-return mechanism for children wrongfully removed or retained across international borders: courts in the state of refuge must return the child to the state of habitual residence unless one of the five narrow Article 13 exceptions is established (child's own objection with sufficient age/maturity, grave risk of physical/psychological harm, fundamental freedoms violation, consent/acquiescence, and one year + settlement); the Convention does not determine custody merits - return to habitual residence restores the status quo so custody is resolved by the courts there; applications must be made through Central Authorities (direct court applications available in some states); the grave risk exception (Article 13(1)(b)) is frequently litigated and must be construed narrowly to preserve Convention effectiveness.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hague-apostille-convention-1961",
      "hague-service-convention-1965",
      "hague-choice-of-court-convention-2005",
      "un-iccpr-1966-civil-political-rights"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hague-choice-of-court-convention-2005",
    "title": "Hague Convention on Choice of Court Agreements 2005 - Exclusive Jurisdiction Clauses, Recognition and Enforcement of Foreign Judgments in Civil and Commercial Matters",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This Convention requires courts in Contracting States to respect exclusive choice of court agreements in international civil or commercial matters and to recognize and enforce judgments from the chosen court, unless specific limited exceptions apply under Article 6 or Article 9. It applies to parties with exclusive jurisdiction clauses designating courts in Contracting States, provided the agreement meets the formal requirements of Article 3(c).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "apec-cbpr-cross-border-privacy-rules-system",
      "eu-eecc-spectrum-small-area-wireless-access"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "hague-convention-1954-cultural-property-armed-conflict",
    "title": "Hague Convention 1954 Protection of Cultural Property in Armed Conflict (with 1999 Second Protocol)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Convention for the Protection of Cultural Property in the Event of Armed Conflict (Hague Convention 1954) was adopted in The Hague on 14 May 1954 and entered into force on 7 August 1956. It is the foundational instrument of international humanitarian law specifically protecting cultural property during armed conflict. The Convention is supplemented by two Protocols: First Protocol 1954 (entered into force 7 August 1956) addresses cultural property in occupied territory; Second Protocol 1999 (entered into force 9 March 2004) strengthens protections including new system of 'enhanced protection' for cultural property of greatest importance, individual criminal responsibility for serious violations, and intergovernmental Committee for Protection. Cultural property is defined in Article 1 to include movable or immovable property of great importance to cultural heritage including monuments, archaeological sites, works of art, manuscripts, books, scientific collections, and buildings whose main purpose is to preserve cultural property (museums, archives, refuges). Article 4 requires States Parties to refrain from use of cultural property for purposes likely to expose it to destruction during armed conflict and to refrain from acts of hostility directed against such property. The Convention has 135 States Parties; First Protocol has 113; Second Protocol has 86 States Parties as of 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unesco-world-heritage-convention-1972",
      "un-genocide-convention-1948-prevention-punishment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hague-convention-evidence-1970",
    "title": "Hague Evidence Convention 1970 - Taking of Evidence Abroad in Civil or Commercial Matters",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Hague Evidence Convention (Convention on the Taking of Evidence Abroad in Civil or Commercial Matters, 1970 - 64 Contracting Parties as of April 2026) establishes the primary international mechanism for obtaining evidence located in a foreign country for use in civil or commercial litigation, requiring judicial authorities to transmit Letters of Request (Letters Rogatory) to the Central Authority of the evidence-holding state; US litigation counsel seeking evidence from EU member states and other Hague Parties must comply with the Convention or risk diplomatic objection and evidence suppression, while foreign parties resisting US pre-trial discovery must leverage Article 23 blocking reservations and the Aérospatiale comity analysis to limit intrusive discovery demands - making Convention compliance and its interaction with US Federal Rules the central evidence strategy issue in all major cross-border commercial disputes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hague-service-convention-1965",
      "hague-choice-of-court-convention-2005",
      "new-york-convention-1958-foreign-arbitral-awards",
      "hague-apostille-convention-1961"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hague-convention-service-abroad",
    "title": "Hague Convention on the Service Abroad of Judicial and Extrajudicial Documents in Civil or Commercial Matters (1965)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This international treaty establishes a standardized and efficient method for serving legal documents between signatory countries in civil or commercial matters. It requires each state to designate a Central Authority (Article 2) to receive, review, and arrange for the service of documents from other member states, bypassing slower diplomatic channels.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-arbitration",
      "isds-investor-state-dispute"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hague-evidence-convention-1970-letters-of-request",
    "title": "Hague Evidence Convention 1970 - Taking of Evidence Abroad in Civil or Commercial Matters and Letters of Request",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Convention on the Taking of Evidence Abroad in Civil or Commercial Matters (Hague Evidence Convention) was adopted by the Hague Conference on Private International Law on 18 March 1970 and entered into force on 7 October 1972. The Convention establishes uniform procedures for transnational evidence gathering through (1) Letters of Request (Chapter I, Articles 1-14), (2) Diplomatic or Consular Officers (Chapter II, Articles 15-22), and (3) Commissioners (Chapter II, Articles 17-22). Chapter I Letters of Request are the principal mechanism: a judicial authority of a Contracting State may request the competent authority of another Contracting State to obtain evidence or perform another judicial act. Article 23 permits Contracting States to declare they will not execute Letters of Request issued for the purpose of pre-trial discovery of documents as known in common law countries, a declaration made by most civil law States Parties limiting US-style discovery in their jurisdictions. The Convention has 65 Contracting States including major economies (US, UK, France, Germany, China, India, Japan, Russia, Brazil, Mexico, Australia). The Permanent Bureau of the Hague Conference publishes Practical Handbook and Guides to Good Practice supporting implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hague-service-convention-1965",
      "hague-choice-of-court-convention-2005"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hague-judgments-convention-2019",
    "title": "Hague Judgments Convention 2019 - Recognition and Enforcement of Foreign Civil Judgments",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Hague Convention on the Recognition and Enforcement of Foreign Judgments in Civil or Commercial Matters 2019 (HCCH Judgments Convention) entered into force 1 September 2023 - the first multilateral treaty since the New York Convention 1958 to create a broad recognition and enforcement (R&E) framework for civil and commercial judgments. As of 2024, the Convention is in force for the EU (38 States through EU accession), Ukraine, and Uruguay; the UK is in the process of accession. The Convention applies to civil and commercial judgments (Art 1) - excluding family law, employment, consumer contracts, insolvency, intellectual property (with carve-outs for copyright/related rights in Art 2), arbitration, and revenue/customs/administrative matters. Art 4 establishes the principle: a judgment given in a Contracting State shall be recognised and enforced in other Contracting States in accordance with the Convention. Recognition/enforcement may only be refused on the Art 7 grounds: the judgment was obtained by fraud; recognition would violate fundamental principles of procedural fairness (public policy); the proceedings were incompatible with a previous judgment; the judgment conflicts with the choice of court agreement of the parties; or the judgment is inconsistent with an earlier judgment in the recognising State. Art 5 limits eligibility to judgments from courts with a specified jurisdictional basis (defendant's habitual residence, consent, commercial establishment, counterclaims). Provisional and protective measures are excluded (Art 2(3)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "hague-choice-of-court-convention-2005",
      "hague-apostille-convention-1961",
      "uncitral-model-law-cross-border-insolvency-1997"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hague-service-convention-1965",
    "title": "Hague Service Convention 1965 - Service of Documents Abroad in Civil or Commercial Matters",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Hague Service Convention (Convention on the Service Abroad of Judicial and Extrajudicial Documents in Civil or Commercial Matters, 1965 - 83 Contracting Parties as of April 2026) is the primary international instrument governing service of legal process across borders in civil and commercial matters; it creates a Central Authority system in each Contracting State that receives and executes service requests, eliminating the need for direct consular or diplomatic service in Contracting States - businesses and counsel involved in cross-border litigation, arbitration-related court proceedings, M&A disputes, and commercial enforcement actions must comply with the Convention's service procedures or risk having service declared invalid and default judgments set aside, resulting in unlimited delays and jurisdictional challenges in foreign courts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hague-apostille-convention-1961",
      "hague-choice-of-court-convention-2005",
      "new-york-convention-1958-foreign-arbitral-awards",
      "un-singapore-convention-mediation-2019"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hague-system-designs",
    "title": "Hague System (Designs)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with the Hague System for international design registration necessitates strict adherence to the Geneva Act of the Hague Agreement (1999), mandating the filing of a WIPO international application. Entitlement to file, as stipulated by Article 3, requires an applicant maintain a genuine connection through nationality, domicile, or industrial establishment within a Contracting Party. The international application itself, governed by Article 5 and Common Regulations Rule 7, may contain up to 100 distinct designs, provided they all belong within a single Locarno class. A critical component involves furnishing standardized reproductions of the industrial design, which must conform to the specifications outlined in Common Regulations Rule 9 and the data formats prescribed by Administrative Instructions Section 401. Applicants can request a deferment of publication for a period not exceeding 30 months from the filing or priority date, a provision found in Article 11 that also enforces pre-publication confidentiality. Upon registration, an initial protection term of five years is granted, with subsequent renewals ensuring a minimum total protection term of fifteen years in each designated Contracting Party. All associated fee payments must be made in Swiss francs (CHF), as currency settlement is mandated. This framework provides a centralized, cost-effective mechanism for securing multinational design protection through a single procedural submission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "paris-convention-industrial-property",
      "wipo-industrial-designs"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hague-visby-rules",
    "title": "Hague-Visby Rules",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Hague-Visby Rules are a set of international rules for the carriage of goods by sea. They define the rights and duties of the carrier and holder of a bill of lading, particularly regarding the liability for loss or damage to goods. They updating the original 1924 Hague Rules and are widely adopted globally for sea freight contracts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "rotterdam-rules-maritime",
      "imo-solas-safety-at-sea",
      "ism-code-vessel-safety",
      "imo-marpol-pollution",
      "supply-chain-incoterms",
      "imo-stcw-seafarer-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hague-visby-rules-1968",
    "title": "Protocol to amend the International Convention for the Unification of certain Rules of Law relating to Bills of Lading (Hague-Visby Rules 1968)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Hague-Visby Rules establish a mandatory international framework governing the liability of sea carriers for loss or damage to cargo under a bill of lading. It defines the carrier's minimum duties, such as exercising due diligence to make the ship seaworthy (Article III, Rule 1), and sets financial limits on liability per package or kilogram (Article IV, Rule 5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "ism-code-vessel-safety",
      "incoterms-2020-fob-logic",
      "logistics-hs-classification",
      "rotterdam-rules-maritime"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "halal-ms1500-2019-malaysia-standard",
    "title": "Malaysia Halal Standard MS 1500:2019 - General Requirements for Halal Certification",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This standard sets mandatory requirements for halal certification in Malaysia, including the prohibition of non-halal ingredients (Section 4.1), adherence to zabiha slaughter methods (Section 5.2), prevention of cross-contamination (Section 6.3), audit of halal premises (Section 7.1), and proper use of the JAKIM Halal logo (Section 8.4). It applies to all food and hospitality operators seeking or maintaining Halal certification under JAKIM.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "hcll-hospitality-licensing",
    "title": "Hospitality Liquor Licensing",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance within this domain mandates adherence to stringent federal, state, and international alcohol service regulations. A foundational requirement is maintaining a valid_liquor_license_active status per Title 27 CFR Part 1 of the Federal Alcohol Administration Act, supported by an active liability insurance policy. Operational controls are paramount, restricting service hours between 0800 and 0200 military time and prohibiting any self_service_alcohol dispensing. Transactions are limited to a maximum_drinks_per_transaction of two. Staffing protocols require a minimum_server_age_required of 18 and that mandatory_staff_training_certification_completed status is maintained. The protection of children from harm, a principle underscored by the UK Licensing Act 2003, is enforced through a strict minimum_customer_age_required of 21. This is operationalized by the requirement to perform ID verification for any patron appearing under age 30. Furthermore, prohibitions against selling alcohol to minors are explicitly governed by statutes like California Business and Professions Code Section 25658. Responsible vendor obligations extend to refusing service to intoxicated persons, as stipulated by New York State ABC Law Section 65, with all such actions recorded in a required incident log for refusals to mitigate civil liability under general Dram Shop Act standards. All liquor purchase records must be retained for 36 months, and any point-of-sale data, including age verification scans and payment details, must comply with Payment Card Industry Data Security Standard v4.0 for secure handling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "alcohol-service-std",
      "haccp-food-safety",
      "pci-dss-hospitality",
      "ada-hospitality-access",
      "hotsec-hotel-security"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "health-ai-bias-mitigation-2026",
    "title": "Health AI Bias Detection, Mitigation & Fairness Assurance (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Regulatory expectations and technical standards for detecting and mitigating algorithmic bias in medical AI. Prevents discriminatory health outcomes by mandating representative training datasets, continuous equity monitoring, and algorithmic fairness audits across diverse demographic groups.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "health-ai-cybersecurity-adversarial-2026",
    "title": "Adversarial Robustness & Cybersecurity for Health AI Systems (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Specialized cybersecurity framework addressing vulnerabilities unique to AI in healthcare, such as adversarial attacks (pixel perturbations altering diagnoses), data poisoning, and model inversion. It mandates continuous threat modeling tailored to machine learning pipelines in clinical settings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "health-ai-lifecycle-management-2026",
    "title": "AI/ML Model Lifecycle Management in Healthcare (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Total Product Lifecycle (TPLC) management for AI/ML-based Medical Devices, incorporating Good Machine Learning Practice (GMLP). It covers requirements for continuous post-market surveillance, algorithmic bias monitoring, and strict change control protocols for adaptive learning algorithms in clinical environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "health-ai-transparency-explainability-2026",
    "title": "Health AI Transparency & Explainability Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "AI systems in healthcare must provide appropriate transparency and explainability to clinicians, patients, and regulators. This includes model cards, technical documentation, local and global interpretability methods, uncertainty quantification, and clear communication of limitations. High-risk systems require detailed explanations of individual decisions and human oversight mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "health-blockchain-interoperability-2026",
    "title": "Blockchain for Health Data Interoperability & Patient-Controlled Records (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Blockchain and distributed ledger technologies enable secure, patient-controlled health records with verifiable provenance, immutable audit trails, and selective disclosure. Governance must address data privacy (off-chain sensitive data), regulatory compliance, interoperability with FHIR, consent management on-chain, and legal recognition of blockchain records. Hybrid on/off-chain architectures are standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "health-data-anonymisation-pseudonymisation-2026",
    "title": "Health Data Anonymisation, Pseudonymisation & De-identification Techniques (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Technical and legal standards for stripping health data of identifiable markers to enable secondary research and AI training without violating patient privacy. Distinguishes between pseudonymisation (reversible, still regulated data) and true anonymisation (irreversible, unregulated data).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "health-data-breach-notification-2026",
    "title": "Health Data Breach Notification - Global Timelines & Obligations (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Regulatory requirements for managing, investigating, and reporting breaches of Protected Health Information (PHI). Dictates strict reporting timelines to authorities (e.g., 72 hours under GDPR, 60 days under HIPAA) and mandates immediate, individualized notification to affected patients when the breach poses a high risk to their rights and freedoms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "health-data-ethics-committees-governance-2026",
    "title": "Health Data Ethics Committees & Oversight Governance (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Governance framework for Institutional Review Boards (IRBs) and specialized Health Data Access Committees (DACs) overseeing the secondary use of clinical data. Ensures that research and AI model training using patient data align with ethical principles, patient consent models, and societal benefit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "health-data-quality-framework-2026",
    "title": "Health Data Quality Framework & Governance (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "A comprehensive framework ensuring that health data utilized for clinical care, secondary research, and AI model training meets strict quality dimensions including completeness, consistency, accuracy, and timeliness. Poor data quality in healthcare leads to patient harm and algorithmic bias.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "helcom-convention-1992-baltic-sea",
    "title": "HELCOM Helsinki Convention 1992 - Protection of the Marine Environment of the Baltic Sea Area, Baltic Sea Action Plan and Recommendations",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Convention on the Protection of the Marine Environment of the Baltic Sea Area (1992 Helsinki Convention) was signed at Helsinki on 9 April 1992 and entered into force on 17 January 2000, replacing the original 1974 Helsinki Convention. It is the principal regional treaty governing protection of the Baltic Sea marine environment. The ten Contracting Parties are Denmark, Estonia, Finland, Germany, Latvia, Lithuania, Poland, Russia, Sweden, and the European Union; Russian implementation has been complicated by political tensions since 2022, with HELCOM continuing to function without active Russian participation. The Convention covers 36 articles and 7 Annexes: Annex I harmful substances; Annex II BAT and BEP; Annex III prevention of pollution from land-based sources; Annex IV prevention of pollution from ships; Annex V exemptions from the general prohibition of dumping; Annex VI prevention of pollution from offshore activities; Annex VII response to pollution incidents. The Baltic Marine Environment Protection Commission (HELCOM, Helsinki Commission) is the governing body, supported by the HELCOM Secretariat in Helsinki. The Baltic Sea Action Plan (BSAP, originally adopted 2007, updated 2021) sets quantitative environmental targets for eutrophication reduction, hazardous substances, biodiversity, and sea-based activities. HELCOM Recommendations (over 250 adopted) provide detailed implementation guidance and are politically binding through reporting obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-marine-strategy-framework-directive-2008-56-ec"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hipaa-breach-notification",
    "title": "HIPAA Breach Notification Rule",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "A breach of unsecured protected health information, as defined under 45 CFR § 164.402, has been confirmed following a risk assessment that did not demonstrate a low probability of compromise. Given this event affects 500 individuals, immediate and specific notification obligations are triggered for the covered entity, which retains the burden of proof for compliance according to 45 CFR § 164.414. Pursuant to 45 CFR § 164.404, individual notifications must be issued without unreasonable delay and, at 60 days since discovery, are now due; the content of this notification must adhere to prescribed federal requirements. Concurrently, because the number of affected persons meets the threshold, 45 CFR § 164.408 requires immediate notice to the Secretary of Health and Human Services. This action is separate from the annual logging of smaller breaches. Furthermore, with 500 individuals affected within a single jurisdiction, compliance with 45 CFR § 164.406 is mandatory, necessitating notice to prominent media outlets serving the relevant State or locality within the same 60-day timeframe. These stringent timelines underscore the importance of prompt reporting from business associates to covered entities, a process governed by 45 CFR § 164.410 that enables downstream regulatory adherence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-privacy-rule",
      "hipaa-security-rule"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hipaa-omnibus-rule-compliance-2026-19",
    "title": "HIPAA Omnibus Rule Enterprise Compliance Standard v19",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The HIPAA Omnibus Rule enhances the privacy and security protections for health information under the Health Insurance Portability and Accountability Act (HIPAA). It mandates that covered entities and business associates implement stringent safeguards to protect electronic protected health information (ePHI). Key requirements include ensuring that business associates comply with HIPAA regulations, enhancing patient rights regarding their health information, and establishing breach notification protocols. The rule also emphasizes the need for risk assessments and the implementation of appropriate administrative, physical, and technical safeguards. Compliance is critical to avoid significant penalties and to ensure the confidentiality, integrity, and availability of sensitive health data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "hipaa-omnibus-rule-compliance-2026-4",
    "title": "HIPAA Omnibus Rule Enterprise Compliance Standard v4",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The HIPAA Omnibus Rule enhances the privacy and security protections for health information under the Health Insurance Portability and Accountability Act (HIPAA). It mandates that covered entities and business associates implement stringent safeguards to protect electronic protected health information (ePHI). Key requirements include ensuring patient consent for the use of their health data, enhancing breach notification protocols, and extending liability to business associates. The rule also emphasizes the need for risk assessments, employee training, and the establishment of comprehensive privacy policies. Compliance is essential to avoid significant penalties and to maintain the trust of patients and stakeholders in the healthcare system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "hipaa-privacy-rule",
    "title": "HIPAA Privacy Rule",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The HIPAA Privacy Rule establishes national standards governing the use and disclosure of protected health information (PHI) by covered entities and their business associates. General rules articulated within 45 CFR § 164.502 mandate the implementation of appropriate safeguards and require formal business associate agreements for any third-party handling PHI. A foundational principle is the minimum necessary standard, enforced pursuant to 45 CFR § 164.514, which limits PHI use or disclosure to the minimum required for a specific purpose. Specific authorizations from individuals are mandated under 45 CFR § 164.508 for certain uses, including nearly all marketing communications, while the unauthorized sale of PHI is strictly prohibited. The regulation further grants individuals significant rights over their health information. Covered entities must provide a clear Notice of Privacy Practices as specified in 45 CFR § 164.520. Individuals have a right to access their designated record set, with such provision required within a maximum of 30 days per 45 CFR § 164.524. An accounting of disclosures must also be furnished upon request within 60 days, according to 45 CFR § 164.528. Entities have up to 60 days to act upon an individual’s amendment request. Compliance requires appointing a privacy officer, conducting workforce training, and retaining all related documentation for a period of six years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "hipaa-breach-notification",
      "gdpr-health-data",
      "iso-27799-health-info-sec"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hipaa-security-rule",
    "title": "HIPAA Security Rule",
    "domain": "Medical & Healthcare",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The HIPAA Security Rule (45 CFR Part 160 and Part 164) establishes U.S. national standards for the protection of Electronic Protected Health Information (ePHI). It focuses on ensure the confidentiality, integrity, and availability of ePHI through three pillars: Administrative, Physical, and Technical Safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-privacy-rule",
      "hipaa-breach-notification",
      "nist-sp-800-53-r5",
      "iso-27799-health-info-sec",
      "nist-sp-800-30-risk-assessment",
      "nist-sp-1800-8-infusion-pumps"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hitech-act-2009",
    "title": "Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The HITECH Act strengthens HIPAA privacy and security rules by requiring public notification for breaches of unsecured Protected Health Information (PHI), increasing penalties for non-compliance, and promoting the adoption of certified Electronic Health Records (EHRs). It applies to all HIPAA Covered Entities and their Business Associates, with key breach notification requirements detailed in Section 13402.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "us-21st-century-cures-act-2016"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hitrust-csf-r2-cloud-healthcare",
    "title": "HITRUST Common Security Framework (CSF) r2 2023 - Healthcare Cloud: 19 Control Categories, 75 Control Objectives, 156 Control Specifications, Implemented 1-Year and Certified 2-Year Assessments, HIPAA, NIST and ISO 27001 Control Mapping",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The HITRUST CSF provides a comprehensive, integrated control framework for managing cybersecurity and compliance risk in cloud-based healthcare environments, harmonizing over 60 authoritative sources including HIPAA, NIST 800-53 Rev 5, and ISO/IEC 27001. It enables organizations to achieve validated, quantifiable assurance through assessment and certification. Key controls are structured across 19 control categories and 75 control objectives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "eu-gdpr-cloud-data-processing",
      "nist-ir-8011-v1-automated-assessments"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "hk-amlo-cap-615",
    "title": "Hong Kong Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap 615)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap 615, Ordinance No. 27 of 2011) is Hong Kong's principal AML / CTF statute. The Ordinance was in force from 1 April 2012 and has been materially extended by the Anti-Money Laundering and Counter-Terrorist Financing (Amendment) Ordinance 2022 which came into force on 1 June 2022 introducing the VASP (Virtual Asset Service Provider) licensing regime, a designated non-financial business and profession (DNFBP) regime for dealers in precious metals and stones (DPMS), and recalibrating customer due diligence obligations to align with FATF Recommendation 16. The Ordinance is organised in five Parts and two Schedules. Part 1 sets the interpretation including definitions of financial institution (banks, deposit-takers, money services operators, stored-value-facility licensees, securities and futures brokers, insurance entities), DNFBP (legal professionals, accountants, real estate agents, TCSPs trust or company service providers, DPMS dealers), money laundering, terrorist financing and politically exposed person. Part 2 sets the customer due diligence and record-keeping requirements (Schedule 2 specifies the operational rules including identify customer, identify beneficial owner, understand purpose and intended nature of business relationship, ongoing monitoring, simplified vs enhanced due diligence triggers, PEP screening, source of funds, suspicious transaction report STR to the Joint Financial Intelligence Unit JFIU). Part 2A (inserted 2022) sets the SFC licensing regime for VASPs. Part 3 vests supervisory authority in the HKMA (for AIs), SFC (for licensed corporations and VASPs), Insurance Authority (for insurers), and Companies Registry (for DNFBPs other than legal/accounting). Part 4 sets the search and seizure powers. Part 5 sets criminal offences for breach (failure to perform CDD up to HKD 1 million fine + 2 years imprisonment; defraud the supervisor / obstruction with higher penalties). The Drug Trafficking (Recovery of Proceeds) Ordinance Cap 405 and Organised and Serious Crimes Ordinance Cap 455 provide the predicate STR offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-1970",
      "eu-6amld-directive-2018-1673-anti-money-laundering-criminal-offences",
      "fatf-40-recommendations-2023-consolidated"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "hk-companies-ordinance-cap-622",
    "title": "Hong Kong Companies Ordinance (Cap 622)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Companies Ordinance (Cap 622, Ordinance No. 28 of 2012) is Hong Kong's principal corporate law statute. The Ordinance was in force from 3 March 2014, replacing the predecessor Companies Ordinance (Cap 32) (which is partially retained as the Companies (Winding Up and Miscellaneous Provisions) Ordinance). The Ordinance is organised in twenty-one Parts and twelve Schedules. Part 2 governs incorporation and the three principal types of company: limited by shares, limited by guarantee, and unlimited. Part 4 governs share capital including the abolition of par value. Part 5 governs transactions involving share capital including reductions of capital under the alternative court-free procedure with a solvency statement. Part 9 sets the accounts and audit framework including the directors' duty to prepare annual financial statements and to keep accounting records. Part 10 governs directors and company secretaries including s. 465 (general duty of care, skill and diligence applying a dual objective + subjective standard mirroring UK Companies Act 2006 s. 174), s. 462 (duties owed to the company), s. 466 (duty to avoid conflicts of interest), ss. 469-470 (declaration of interest in proposed and existing transactions). Part 11 contains fair dealing by directors provisions including the prohibition of loans, quasi-loans and credit transactions to directors (with shareholder approval exceptions), and the disclosure of price-sensitive information by directors. Part 13 governs arrangements, amalgamations and compulsory share acquisitions. Part 14 provides s. 724 unfair prejudice remedy and the statutory derivative action under ss. 731-738. Part 18 governs corporate communications including authorised use of websites. Schedule 11 sets transitional and savings provisions for companies migrating from Cap 32.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-companies-act-2006-directors-duties-sections-170-177",
      "jp-companies-act-2005",
      "za-companies-act-2008"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "hk-competition-ordinance-cap-619",
    "title": "Hong Kong Competition Ordinance (Cap 619)",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Competition Ordinance (Cap 619, Ordinance No. 14 of 2012) is Hong Kong's first cross-sector competition statute. The substantive Conduct Rules came into force on 14 December 2015 (the Competition Commission and Competition Tribunal were established earlier). The Ordinance is organised in ten Parts and three Schedules. Part 2 contains the two substantive Conduct Rules: s. 6 First Conduct Rule prohibits agreements between undertakings, decisions by associations of undertakings, and concerted practices that have as their object or effect the prevention, restriction or distortion of competition in Hong Kong (mirroring TFEU Art. 101); s. 21 Second Conduct Rule prohibits abuse by an undertaking with a substantial degree of market power by engaging in conduct that has as its object or effect the prevention, restriction or distortion of competition in Hong Kong (Hong Kong-specific market-power test rather than TFEU Art. 102 dominance). Section 8 distinguishes Serious Anti-competitive Conduct (hardcore cartels: price fixing, market sharing, output restriction, bid-rigging) which is not eligible for warning notices. Sections 12-14 set exclusions: agreements of lesser significance (de minimis turnover threshold of HKD 200 million for First Conduct Rule, HKD 40 million for Second), economic efficiency block exemption order, and services of general economic interest. Part 3 vests investigation powers in the Competition Commission. Part 4 establishes the Competition Tribunal as a superior court of record. Part 5 governs Tribunal review of Commission decisions. Part 6 contains follow-on private actions under s. 110 inserted in 2017. Section 93 sets pecuniary penalties at up to 10 percent of the group's Hong Kong turnover in each year of contravention, capped at three years. Section 91 provides disqualification of director up to five years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-commerce-act-1986",
      "eu-tfeu-article-101-cartel-prohibition",
      "eu-tfeu-article-102-abuse-of-dominance"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "hk-hkma-banking-ordinance-cap-155",
    "title": "Hong Kong Banking Ordinance (Cap. 155) - HKMA Authorisation and Prudential Supervision",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Hong Kong's Banking Ordinance (Cap. 155) establishes the three-tier authorisation system (licensed banks, restricted licence banks, deposit-taking companies) supervised by the Hong Kong Monetary Authority (HKMA); minimum capital ratio 8% (Basel III implemented); liquidity coverage ratio; D-SIB designation; resolution planning under the Financial Institutions (Resolution) Ordinance (FIRO); and criminal penalties for unlicensed deposit-taking.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-brrd-bank-recovery-resolution-directive-2014-59",
      "eu-single-supervisory-mechanism-regulation-1024-2013"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "hk-pcpd-ai-model-personal-data-protection-framework-2024",
    "title": "Hong Kong PCPD Model Personal Data Protection Framework for AI 2024 and Generative AI Employee Use Checklist 2025",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Hong Kong organisations that procure, implement or use AI systems including predictive AI and generative AI, processing personal data in their operation or customisation of an AI system, must apply the PCPD Model Personal Data Protection Framework (published 11 June 2024) in their compliance with the Personal Data (Privacy) Ordinance, properly classify their role as data user (controller, joint controller or processor), impose contractual security and retention obligations on AI system providers acting as processors, ensure joint controller relationships clearly allocate data protection responsibilities, and develop internal employee policies for generative AI consistent with the PCPD Checklist on Guidelines for the Use of Generative AI by Employees (2025).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-automated-decision-workflows"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hk-pdpo-1996",
    "title": "Hong Kong Personal Data (Privacy) Ordinance Cap. 486 - PCPD",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Hong Kong's Personal Data (Privacy) Ordinance (PDPO) - Cap. 486 of the Laws of Hong Kong - was enacted by the Legislative Council in 1995 and came into operation on 20 December 1996, making Hong Kong one of the first jurisdictions in Asia to enact comprehensive personal data protection legislation. The PDPO continues in force as Hong Kong law under the 'one country, two systems' constitutional arrangement, which preserves Hong Kong's distinct common law legal system and independent regulatory institutions under the Basic Law. The enforcement authority is the Office of the Privacy Commissioner for Personal Data (PCPD), an independent statutory body established under the PDPO. Privacy Commissioner Ada Chung Lai-ling was appointed in October 2020 and reappointed in 2023. The PDPO has been amended significantly twice: the 2012 amendments (Personal Data (Privacy) (Amendment) Ordinance 2012) introduced direct marketing restrictions requiring opt-in consent for sensitive personal data marketing, data processor accountability obligations, and enhanced PCPD enforcement powers including administrative fines; and the 2021 amendments (Personal Data (Privacy) (Amendment) Ordinance 2021) introduced criminal doxxing offences, cessation notices empowering the PCPD to compel platforms and service providers to remove doxxing content, and significantly enhanced criminal penalties. Key features of Hong Kong PDPO: (1) Six Data Protection Principles (DPPs) - the PDPO prescribes six principles for all personal data processing: DPP 1 (Purpose and manner of collection of personal data - data must be collected for a lawful purpose, limited to what is necessary, and collected by fair and lawful means with the data subject's knowledge); DPP 2 (Accuracy and retention - data must be accurate, not retained longer than necessary for the purpose); DPP 3 (Use of personal data - data may only be used for the purpose for which it was collected or a directly related purpose, unless the data subject has voluntarily provided written consent); DPP 4 (Security of personal data - data controllers must take practicable steps to protect personal data against unauthorised or accidental access, use, or disclosure); DPP 5 (Information to be generally available - data controllers must make a privacy policy available); DPP 6 (Access to personal data - data subjects have the right to access and correct personal data held about them); (2) Direct marketing - use of personal data for direct marketing requires: opt-out notification at first contact; explicit opt-in consent for sensitive personal data (including health, financial, and certain biometric data) used for direct marketing; data controllers must inform data subjects of their right to opt out at no charge; (3) Data processor obligations - data controllers must adopt contractual or other means to prevent unauthorised or accidental access, processing, or disclosure by data processors; data processors are subject to criminal liability for certain breaches; (4) Doxxing offences - the 2021 amendments created specific criminal offences for doxxing (disclosing personal data of a data subject without consent with intent to cause harm): penalties up to HKD 1 million and 5 years imprisonment; the PCPD may issue cessation notices requiring platforms to remove doxxing content; (5) Enforcement notices - the PCPD may issue enforcement notices requiring data controllers to cease or remedy contravention; non-compliance with an enforcement notice is a criminal offence; (6) Data subject rights - data subjects may access personal data using a data access request (PCPD Form OPS003) and request correction of inaccurate personal data; data controllers must respond within 40 days; (7) Criminal penalties - specific offences under the PDPO carry criminal penalties including fines and imprisonment; (8) Cross-border data transfer - the PDPO empowers the PCPD to specify countries or territories to which personal data may not be transferred; the PCPD may issue prohibition notices for transfers to jurisdictions without adequate protection. Hong Kong's PCPD is an active regulator, issuing investigation reports, codes of practice (including the Employee Monitoring Code, the Credit Reference Agency Code), and guidance on emerging topics including AI, cloud computing, and children's privacy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hk-pdpo-2021-amendment",
    "title": "Hong Kong Personal Data (Privacy) (Amendment) Ordinance 2021",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Hong Kong's Personal Data (Privacy) (Amendment) Ordinance 2021, effective October 8, 2021, criminalises doxxing by making the disclosure of others' personal data without consent with intent to cause harm a criminal offence carrying up to 5 years imprisonment and HKD 500,000 fines for repeat offenders, empowers the Privacy Commissioner to issue cessation notices requiring platforms to remove doxxing content, and extends extraterritorial jurisdiction to protect Hong Kong residents from doxxing conducted outside the territory.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/hk-pdpo-2021-amendment.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hk-pdpo-1996"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hk-prevention-of-bribery-cap-201",
    "title": "Hong Kong Prevention of Bribery Ordinance (Cap 201)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Prevention of Bribery Ordinance (Cap 201) is Hong Kong's principal anti-corruption statute. Originally enacted as Ordinance No. 102 of 1970 it was in force from 14 May 1971 and has been consolidated as Cap 201 of the Laws of Hong Kong with numerous amendments. The Ordinance is organised in five Parts. Part I provides interpretation including s. 2 definitions of advantage (broadly drafted to include money, gift, loan, fee, reward, commission, contract for services, employment, favour or discount), agent, principal, public servant, prescribed officer (civil servants in the employ of the Hong Kong Government) and public body. Part II creates the substantive offences: s. 3 (a prescribed officer who, without permission, solicits or accepts any advantage commits an offence); s. 4 (offering or accepting an advantage in connection with a public servant performing or refraining from performing an act in their official capacity); s. 5 (bribery for giving assistance in regard to contracts with the Government or public bodies); s. 6 (bribery for procuring withdrawal of tenders); s. 7 (bribery in relation to auctions); s. 8 (bribery in connection with Government affairs by persons having dealings with the Government); s. 9 (corrupt transactions with agents - the catch-all private-sector bribery offence covering both giving and accepting an advantage by an agent without the principal's permission); s. 10 (possession of unexplained property by a prescribed officer, where pecuniary resources or property are disproportionate to known sources of income). Part III sets out ICAC investigation powers in conjunction with the Independent Commission Against Corruption Ordinance Cap 204. Section 12 provides penalties: on indictment up to HKD 500,000 fine and 7 years imprisonment for ss. 3, 4-8, 10; HKD 100,000 and 1 year for s. 9; on summary trial reduced penalties. Section 14 creates a statutory presumption of corruption where an advantage is proved to have been received by a public servant or agent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-bribery-act-2010",
      "us-fcpa-foreign-corrupt-practices-act-1977",
      "fr-sapin-ii-anticorruption-2016"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "hk-securities-and-futures-ordinance-cap-571",
    "title": "Hong Kong Securities and Futures Ordinance (Cap 571)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Securities and Futures Ordinance (Cap 571, Ordinance No. 5 of 2002) is Hong Kong's principal securities and derivatives regulatory statute. The Ordinance was in force from 1 April 2003 and has consolidated 10 predecessor ordinances. It is organised in seventeen Parts. Part I sets interpretation including s. 1 short title, s. 2 (definitions of regulated activity, intermediary, licensed person, registered institution, market misconduct, listing rules) and Schedule 5 listing the regulated activities (Type 1 dealing in securities, Type 2 dealing in futures contracts, Type 3 leveraged foreign exchange trading, Type 4 advising on securities, Type 5 advising on futures contracts, Type 6 advising on corporate finance, Type 7 providing automated trading services, Type 8 securities margin financing, Type 9 asset management, Type 10 providing credit rating services, Type 11 dealing in OTC derivative products and clearing services, Type 12 providing client clearing services for OTC derivative transactions). Part II establishes the Securities and Futures Commission (SFC) with functions, governance and inspection powers. Part III establishes the licensing regime for the twelve regulated activities including the fit and proper test and the responsible officer regime. Part XIII establishes the Market Misconduct Tribunal (MMT) with civil jurisdiction over the six categories of market misconduct (insider dealing, false trading, price rigging, stock market manipulation, disclosure of false or misleading information inducing transactions, disclosure of information about prohibited transactions). Part XIV provides the parallel criminal offences for the same six categories. Section 213 grants the SFC remedial powers before the Court of First Instance. Section 281 sets the penalty framework (criminal up to HKD 10 million fine and 10 years imprisonment; MMT civil orders including disgorgement, disqualification, cease-and-desist and cold-shoulder).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-securities-exchange-act-1934",
      "eu-mifid-ii-directive-2014-65-investment-firm-conduct-obligations",
      "eu-market-abuse-regulation-596-2014"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "hk-sfc-securities-futures-ordinance-2003",
    "title": "Hong Kong Securities and Futures Ordinance (SFO) Cap. 571 - Licensing and Market Conduct",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The Hong Kong Securities and Futures Ordinance (SFO, Cap. 571) is the primary statute governing securities and futures markets in Hong Kong. It requires intermediaries to be licensed under one of ten Regulated Activities (RAs) by the Securities and Futures Commission (SFC), prohibits insider dealing (Parts XIII-XIV), prohibits market misconduct (false trading, price rigging, stock market manipulation), mandates short position reporting above 0.02% of outstanding shares or HKD 30 million, and regulates collective investment schemes (funds). The SFC supervises licensed intermediaries through ongoing supervision, inspections, and enforcement. Hong Kong Exchanges and Clearing Limited (HKEX) is the recognised exchange operator.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-market-abuse-regulation-596-2014",
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-aifmd-directive-2011-61"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "hk-sfc-virtual-asset-trading-platform-vatps-licensing-requirements",
    "title": "HK SFC Virtual Asset Trading Platform (VATP) Licensing - Securities and Futures Ordinance",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-06-01",
    "bluf": "Hong Kong's Securities and Futures Commission (SFC) introduced a mandatory licensing regime for Virtual Asset Trading Platforms (VATPs) under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO), effective 1 June 2023. All platforms facilitating virtual asset trading in Hong Kong or targeting Hong Kong investors must hold an SFC VATP licence. Licensees must maintain minimum liquid capital of HKD 3 million, segregate client assets, implement robust cybersecurity, and restrict services to professional investors and eligible retail investors based on suitability assessments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-40-recommendations-2023-consolidated"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "hk-stablecoins-ordinance-2025",
    "title": "Hong Kong Stablecoins Ordinance - Fiat-Referenced Stablecoin (FRS) Licensing Regime (May 2025)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Hong Kong Stablecoins Ordinance was passed by the Legislative Council on 21 May 2025 and establishes a Hong Kong Monetary Authority (HKMA) licensing regime for issuers of fiat-referenced stablecoins (FRS) - including FRS pegged to Hong Kong dollars whether issued in or outside Hong Kong. Licensed issuers must maintain proper segregation of client assets, a robust stabilisation mechanism, redeem stablecoin holders at par value, comply with AML/CFT obligations, risk management protocols, disclosure and audit requirements, and meet fitness and propriety assessments. Only licensed institutions may offer FRS in Hong Kong; retail investors may receive FRS only from licensed issuers; only advertisements of licensed FRS issuance are allowed during implementation and the six-month non-contravention period. The HKMA is the designated Monetary Authority overseeing the regime and conducting further consultations on detailed requirements. Transitional arrangements apply to permit industry restructuring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "hkma_stablecoin_consultation_2023",
        "mica_stablecoin_reserve",
        "singapore_mas_stablecoin_regulatory_framework_2023",
        "us_genius_act_stablecoin_2025_framework",
        "fatf_r15_virtual_asset_service_providers"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hkma-stablecoin-consultation-2023",
      "hong-kong-vasp-licensing-sfc-2023",
      "fatf-recommendation-16-travel-rule-crypto",
      "mica-stablecoin-reserve",
      "singapore-mas-stablecoin-regulatory-framework-2023"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "hk-trade-descriptions-ordinance-cap-362",
    "title": "Hong Kong Trade Descriptions Ordinance (Cap 362)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Trade Descriptions Ordinance (Cap 362, Ordinance No. 75 of 1980) is Hong Kong's principal consumer-protection statute regulating misleading and aggressive commercial practices. The Ordinance was in force from 16 May 1981 and was substantially amended by the Trade Descriptions (Unfair Trade Practices) (Amendment) Ordinance 2012 which came into force on 19 July 2013, extending the scope from goods to services and introducing a comprehensive UCPD-style framework. The Ordinance is organised in five Parts. Part I (s. 2) provides interpretation including trade description, false trade description, services, commercial practice, average consumer, and to materially distort. Part II contains the substantive prohibitions. Section 4 prohibits applying a false trade description to goods or selling goods to which a false trade description has been applied. Section 7 prohibits false trade descriptions in advertising. Section 7A prohibits misleading omissions in commercial practices for goods. Section 13B prohibits false trade descriptions in respect of services. Section 13D prohibits misleading omissions in respect of services. Section 13E prohibits aggressive commercial practices (harassment, coercion or undue influence) significantly impairing the average consumer's freedom of choice. Section 13F prohibits bait advertising (offering products at a specified price knowing supply cannot be at that price). Section 13G prohibits bait and switch. Section 13H prohibits wrongly accepting payment. Part III vests investigative powers in the Customs and Excise Department. Part IV provides on indictment a fine of HKD 500,000 and 5 years imprisonment; on summary trial HKD 100,000 and 2 years. Part V provides compensation orders to the affected consumers in addition to fine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-cput-regulations-2008-consumer-protection-unfair-trading",
      "au-acl-competition-consumer-act-2010-schedule2-consumer-guarantees",
      "nz-fair-trading-act-1986"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "hkma-ai-banking-supervisory-policy-2023",
    "title": "HKMA Supervisory Policy on AI Use in Banking - Compliance Obligations for Hong Kong AI Banking Governance, AI Model Validation Requirements, and AI Risk Management for Authorised Institutions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations for AI governance, model validation, and risk management in banking under HKMA guidelines, with overlapping requirements from the EU AI Act (Regulation 2024/1689, Articles 9-15) for high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "hkma-stablecoin-consultation-2023",
    "title": "HKMA Consultation Conclusions on Regulatory Regime for Stablecoin Issuers 2023 - Licensing Requirements, Reserve Assets and Redemption Rights for HKD-pegged Stablecoins",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This consultation outlines a proposed licensing regime for fiat-referenced stablecoin (FRS) issuers in Hong Kong, requiring licensing by the Monetary Authority (MA) for entities issuing FRS in Hong Kong, issuing Hong Kong dollar-referenced stablecoins, or actively marketing FRS to the Hong Kong public. The regime prohibits unlicensed FRS issuance and advertising, and includes a sandbox for supervisory engagement under the legislative proposal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "hkma-tm-g-1-tech-risk",
    "title": "HKMA TM-G-1 (Tech Risk)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "HKMA TM-G-1 (General Principles for Technology Risk Management) is a Supervisory Policy Manual (SPM) issued by the Hong Kong Monetary Authority. it provides minimum standards for the management of the technology risks that institutions face, specifically covering the oversight of the e-banking, the logical access controls, and the third-party providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "bcbs-principles-sound-management-operational-risk",
      "iso-27001-2022",
      "iso-31000-risk-mgt",
      "mas-tr-management-sg",
      "eba-outsourcing-guide"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hl7-fhir-interop",
    "title": "HL7 FHIR Interoperability (Release 4)",
    "domain": "Medical & Healthcare",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Standardized RESTful API architecture for electronic health information exchange, using modular Resources to enable computable healthcare data across disparate systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "hipaa-privacy-rule",
      "hipaa-breach-notification",
      "gdpr-health-data",
      "iso-13485-medical-qms",
      "iec-62304-medical-software"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hl7-fhir-r4-implementation",
    "title": "HL7 FHIR R4 (4.0.1) Implementation Guide - RESTful API Specification for Health Data Exchange and Resource Types",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard requires healthcare systems to implement a RESTful API for exchanging electronic health information using a defined set of data structures called 'Resources'. Conformance, as defined in Section 2.1, mandates proper use of HTTP verbs, status codes, and resource representations (e.g., Patient, Observation) to ensure system interoperability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "us-21st-century-cures-act-2016",
      "us-cms-interoperability-rule-2020",
      "iso-27799-health-info-sec",
      "hitech-act-2009"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hl7-fhir-r5-governance-2026",
    "title": "HL7 FHIR Release 5 (R5) - Governance, Interoperability, and Compliance Obligations",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "HL7 FHIR R5 is the global standard for exchanging healthcare information electronically. Organisations implementing FHIR must ensure semantic interoperability, security (OAuth2, SMART-on-FHIR), privacy (Consent resource), validation against Implementation Guides, and governance for data mapping, versioning, and audit trails.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "hl7-fhir-v4-interop",
    "title": "HL7 FHIR v4 (Interoperability)",
    "domain": "Medical & Healthcare",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "HL7 FHIR (Fast Healthcare Interoperability Resources) Release 4 is the global standard for electronic healthcare data exchange. It defines a set of 'Resources' that represent granular clinical and administrative data, accessible via a RESTful API to enable seamless interoperability between EHRs, mobile apps, and analytics platforms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "hipaa-privacy-rule",
      "fda-21-cfr-part-11-records",
      "iso-27799-health-info-sec",
      "gdpr-health-data-compliance",
      "dicom-imaging-standard"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hn-ley-contratacion-estado-decreto-74-2001-oncae-honducompras",
    "title": "Honduras Ley de Contratacion del Estado Decreto 74-2001 of 31 May 2001 and ONCAE / HonduCompras",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Honduras Ley de Contratacion del Estado (Law of State Contracting) approved by Decreto 74-2001 of 31 May 2001 (published in La Gaceta No. 29.575 of 1 September 2001 effective 1 October 2001), as amended by Decreto 25-2002 and Decreto 36-2013, and supplemented by the Reglamento de la Ley de Contratacion del Estado approved by Acuerdo Ejecutivo PCM-009-2007 of 6 March 2007 as amended, is the principal Honduran statute governing procurement of goods, services, and works by entities of the State Public Administration including the Executive Branch ministries, the Legislative Branch (Congreso Nacional), the Judicial Branch, the Public Ministry, the Court of Accounts (Tribunal Superior de Cuentas), the Electoral Tribunal (Tribunal de Justicia Electoral), decentralized institutions (Instituciones Descentralizadas), departmental and municipal governments, public-sector enterprises, and other entities financed by the State budget. The Oficina Normativa de Contratacion y Adquisiciones del Estado (ONCAE / oncae.gob.hn) under the Secretaria de Estado en los Despachos de Finanzas is the central regulatory authority responsible for procurement regulation, oversight, supplier debarment, and procurement guidance. The HonduCompras portal (honducompras.gob.hn) operated by ONCAE is the mandatory federal e-procurement platform for in-scope procurement. Procurement methods established by LCE art. 38 to 75 comprise (a) Licitacion Publica (Public Tender, the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Licitacion Privada (Private Tender, with prequalification for medium-value acquisitions), (c) Concurso (Competition, for consulting services), (d) Compra Menor (Minor Procurement, for low-value acquisitions below prescribed thresholds), (e) Contratacion Directa (Direct Procurement, sole-source under prescribed exceptions in art. 63 including emergency, sole supplier for technical reasons, prior failed tendering, and prescribed-class exemptions), and (f) Subasta Electronica Inversa (Reverse Electronic Auction). The Tribunal Superior de Cuentas conducts procurement audit. Honduras is a party to CAFTA-DR (in force 2006), the EU-Central America Association Agreement (in force 2013), the SIECA framework, and UNCAC. Honduras is NOT a party to the WTO GPA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "hn-pdpl-2020",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "hn-ley-fundamental-educacion-2011-article-3-principles-education-honduras",
    "title": "Honduras Ley Fundamental de Educacion (Decreto 262-2011) - Purpose of the Law (Article 3) and Principles of National Education (Article 13)",
    "domain": "Education & Research",
    "version": "2.0.0",
    "last_updated": "2026-07-03",
    "bluf": "The Ley Fundamental de Educacion of Honduras, enacted by the National Congress as Decreto No. 262-2011 and published in La Gaceta No. 32,754 on 22 February 2012, guarantees the human right to education and establishes the principles, guarantees, purposes and general guidelines of national education. Article 3 states the purpose of the law: to guarantee equitable access for all persons, without discrimination, to an integral education of quality. Article 13 grounds the Sistema Nacional de Educacion in principles including calidad de la educacion, gratuidad, imperatividad, equidad e inclusion, educacion permanente, democracia, dialogicidad, participacion, libertad, flexibilidad, multiculturalidad e interculturalidad, internacionalidad de la educacion, pluralidad, laicidad, libertad de catedra, responsabilidad ambiental, transparencia, and educacion y trabajo. The law governs educational activities carried out within the national territory by natural or juridical persons, public, private or mixed, national or foreign (Article 1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "hn-pdpl-2020",
    "title": "Honduras Personal Data Protection Framework - Constitutional Privacy and Transparency Law",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Honduras has not enacted a dedicated comprehensive personal data protection statute and has no general data protection regulator. Personal data protection rests on the constitutional guarantees of personal and family privacy and honour (Constitution of the Republic of Honduras, Article 76) together with the habeas data action, and on the Law on Transparency and Access to Public Information (Decree No. 170-2006), which is administered by the Instituto de Acceso a la Información Pública (IAIP) and governs the handling of personal data held by public bodies. A comprehensive data protection bill has been under legislative consideration since 2015 but is not yet in force. The workflow below sets out aligned good-practice controls (lawful basis, transparency notices, ARCO rights, security, and cross-border safeguards) consistent with these constitutional guarantees and the transparency framework pending dedicated legislation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/hn-pdpl-2020.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hong-kong-buildings-ordinance-cap-123-bda",
    "title": "Hong Kong Buildings Ordinance Cap. 123 - Building Approval, Registered Contractor Requirements and Minor Works Control",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Hong Kong's Buildings Ordinance (Cap. 123, enacted 1955, substantially revised to 2024) administered by the Buildings Department (BD) requires approved building plans (BP) and Consent to Commence Works from BD before construction of any new building or major alteration; mandates appointment of Authorised Person (AP - architect, engineer, or surveyor) and Registered Structural Engineer (RSE) for all regulated works; applies the Minor Works Control System (MWCS, 2010) for Category 1-3 minor works with simplified approval; enforces structural safety of existing buildings via the Mandatory Building Inspection Scheme (MBIS) targeting buildings over 30 years old; and imposes fines up to HKD 400,000 and imprisonment up to 2 years for unauthorised building works (UBW).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "singapore-building-control-act-cap-29"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hong-kong-ia-prudential-standards-insurers-2023",
    "title": "Hong Kong Insurance Authority - Risk-based Capital (RBC) Regime for Authorised Insurers (Insurance (Amendment) Ordinance 2023; commenced 1 July 2024)",
    "domain": "Insurance & Risk",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Hong Kong's Risk-based Capital (RBC) regime under the Insurance (Amendment) Ordinance 2023 and its subsidiary RBC Rules, which commenced on 1 July 2024, requires authorised insurers to establish and maintain a comprehensive risk-based capital adequacy and risk management system across a three-pillar approach: quantitative requirements, governance, and public disclosure. An insurer's capital base must be not less than each of the Prescribed Capital Amount (PCA), the Minimum Capital Amount (MCA), and HK$20,000,000. Insurers must implement a robust governance framework, including a clear organizational structure, effective risk management, and internal control systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hong-kong-pdpo-2021-amendment",
    "title": "Personal Data (Privacy) Ordinance (Cap. 486) as amended by the Personal Data (Privacy) (Amendment) Ordinance 2021",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This amendment to Hong Kong's Personal Data (Privacy) Ordinance (PDPO) introduces a two-tiered anti-doxxing regime under Section 64, criminalizing the non-consensual disclosure of personal data with intent to cause specified harm. It also grants the Privacy Commissioner for Personal Data (PCPD) enhanced powers to conduct criminal investigations, demand the removal of doxxing content, and prosecute offenders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-privacy-guidelines-2013",
      "apec-cbpr-system-2011"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hong-kong-vasp-licensing-sfc-2023",
    "title": "Hong Kong VASP Licensing Regime: Guidelines for Virtual Asset Trading Platform Operators under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regime requires centralized virtual asset trading platforms (VATPs) operating in or marketing to Hong Kong to be licensed by the Securities and Futures Commission (SFC). Mandated by Part 5B of the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO), it imposes stringent requirements on financial resources, risk management, custody of assets, token admission, and conduct of business, including specific rules for serving retail investors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "eu-mica-casp-obligations",
      "fsb-crypto-asset-regulatory-framework-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hotel-stars-union-crit",
    "title": "Hotelstars Union Criteria",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with Hotelstars Union (HSU) Classification Criteria for the 2020-2025 period mandates adherence to a harmonized set of operational, digital, and quality management standards across member countries. Establishments must achieve a minimum point threshold, starting from 90 points for one-star classification and reaching 600 points for a five-star rating. Foundational service obligations require daily room cleaning, and that the reception is reachable 24 hours. Digital infrastructure is critically assessed, demanding mandatory internet access in public areas and ensuring hotel websites are accurate and bilingual, consistent with information requirements under Directive 2011/83/EU on Consumer Rights. Financial and data security protocols are paramount; cashless payment acceptance is required and must align with Strong Customer Authentication per Directive (EU) 2015/2366 (PSD2), while any enabled secure online booking system dictates guest data privacy be GDPR-compliant in accordance with security of processing principles found in Regulation (EU) 2016/679. For \"Superior\" status, evidence of a formal quality management system is obligatory, often referencing frameworks like ISO 9001:2015. Furthermore, four- and five-star properties are subject to mandatory mystery guest audits to validate service consistency under the European Hospitality Quality framework from HOTREC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-hospitality-nuance",
      "pci-dss-hospitality",
      "green-key-tourism-eco",
      "gstc-tourism-criteria"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hotsec-hotel-security",
    "title": "HOTSEC Hotel Security Logic",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "HOTSEC Hotel Security Logic enforces a comprehensive security posture for hospitality environments by integrating critical controls from leading standards and regulations. In alignment with NIST SP 800-153 guidelines, network segmentation is mandated, requiring that guest WiFi be logically isolated from the Property Management System (PMS) and all Internet-of-Things (IoT) devices must operate on a separate VLAN. Full adherence to Payment Card Industry Data Security Standard version 4.0 is necessary for securing cardholder data, which means any vendor remote access must utilize a required VPN connection and PMS access itself mandates multi-factor authentication. Physical and logical access controls, reflecting ISO/IEC 27001:2022 principles, are strictly defined: keycard encryption must be AES-128 or higher, access is revoked after a maximum of five failed keycard attempts, and every electronic safe override procedure must be fully audited. Data governance adheres to data minimization principles outlined in GDPR Article 5(1)(c), setting a maximum retention period of 90 days for guest personally identifiable information, a policy which also supports the consumer right to deletion under the California Consumer Privacy Act. For physical surveillance, a minimum CCTV retention of 30 days is required. The framework, consistent with the AHLA 5-Star Promise concerning employee safety, also dictates that annual staff security training is mandatory. Finally, an operational readiness component requires that a formal incident response plan must be activated within a 60-minute service level agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pci-dss-hospitality",
      "gdpr-hospitality-nuance",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "nist-800-122-pii",
      "nist-sp-800-207"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "hr-act-on-education-in-primary-secondary-schools-2019-article-4-education-principles",
    "title": "Opći uvjeti korištenja i Zaštita privatnosti (General Terms of Use and Privacy Protection)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This regulation outlines the terms of use and privacy protection obligations for the Narodne novine d.d. website, including commitments to respect user anonymity, use voluntarily provided personal data only for its intended purpose, and not share it with third parties without explicit consent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hr-gdpr-implementation-2018",
    "title": "Croatia GDPR Implementation Act 2018 (NN 42/2018) - National Data Protection Implementation",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Croatia's Zakon o provedbi Opće uredbe o zaštiti podataka (GDPR Implementation Act - Act on the Implementation of the General Data Protection Regulation), published in the Croatian Official Gazette (Narodne novine No. 42/2018) and entering into force on 25 May 2018, is Croatia's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Croatia. The GDPR is directly applicable Croatian law by virtue of Croatia's EU membership (Croatia acceded to the EU on 1 July 2013). The GDPR Implementation Act provides national derogations, additions, and specifications that the GDPR permits EU member states to adopt and complements the prior Croatian Personal Data Protection Act (Zakon o zaštiti osobnih podataka, NN 103/2003, 118/2006, 41/2008, 130/2011, 106/2012). Croatia has been an EU member since 2013 and adopted the euro in January 2023, making it a growing economy with increasing digital sector development. Enforcement: the Agencija za zaštitu osobnih podataka (AZOP - Personal Data Protection Agency) is Croatia's independent data protection supervisory authority. The AZOP is Croatia's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Croatian national provisions: (1) Age of digital consent: Croatia has maintained the GDPR default of 16 years for information society services; data subjects under 16 require parental or guardian consent; (2) Employment - the Croatian Labour Act (Zakon o radu, NN 93/14, 127/17, 98/19, 151/22 and subsequent amendments) governs employment relationships and the processing of employee personal data alongside GDPR; employer monitoring requires advance employee notification; (3) Freedom of expression - exemptions for journalistic, academic, artistic, and literary processing aligned with GDPR Art. 85 and Croatian constitutional freedom of expression; (4) Health data - specific provisions for health data processing under Croatian health legislation supplementing GDPR Art. 9; (5) Public sector - Croatian public authorities are subject to the GDPR Implementation Act and Croatian administrative law; the Act on Right of Access to Information (Zakon o pravu na pristup informacijama, NN 25/13, 85/15, 69/22) governs public access to information and intersects with GDPR. Fines: GDPR administrative fines apply in Croatia - up to EUR 20 million or 4% of global annual turnover. The AZOP has imposed fines and issued enforcement decisions in employment, public sector, and digital services contexts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hsn-cybersecurity-framework-profile",
    "title": "Cybersecurity Framework Profile for Hybrid Satellite Networks (HSN)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-11-03",
    "bluf": "The objective of this Cybersecurity Profile is to identify an approach to assess the cybersecurity posture of Hybrid Satellite Networks (HSN) that provide services such as satellite-based systems for communications, position, navigation, and timing (PNT), remote sensing, weather monitoring, and imaging. The Profile considers the cybersecurity of all the interacting systems that form the HSN rather than the traditional approach of a single organization acquiring the entire satellite system. It is intended to provide practical guidance for organizations and stakeholders engaged in the design, acquisition, and operation of satellite buses or payloads that involve HSN.\n\nThe Profile applies to organizations that have already adopted the NIST Cybersecurity Framework (CSF), are familiar with the CSF and want to improve their cybersecurity postures, or are unfamiliar with the CSF but need to implement HSN services in a risk-informed manner. Use of the HSN Profile will help organizations identify systems, assets, data and threats that pertain to HSN; protect HSN services by adhering to basic principles of resiliency; detect cybersecurity-related disturbances; respond to service anomalies in a timely manner; and recover the HSN to proper working order following a cybersecurity incident. The Profile does not prescribe regulations or mandatory practices, nor does it carry any statutory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-ir-8441-hsn-profile"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ht-conatel-2000",
    "title": "Haiti CONATEL Framework - Constitutional Privacy Rights and Telecommunications Personal Data Obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Haiti's legal framework for personal data protection is grounded in the constitutional right to privacy established by the Haitian Constitution of 1987, which protects individuals from unreasonable interference with their private life, family, home, and correspondence, and provides for the inviolability of private communications. The Conseil National des Télécommunications (CONATEL), established under telecommunications legislation, is the national regulator for electronic communications and digital services in Haiti. CONATEL's regulatory framework establishes obligations for licensed telecommunications and electronic service operators to protect the confidentiality of subscriber personal data, to prevent unauthorised access to or disclosure of communications data, and to implement security measures proportionate to the risks of the personal data processed. Haiti does not have a standalone comprehensive data protection law, and the constitutional privacy framework, CONATEL's regulatory requirements, and the provisions of the Haitian Penal Code on invasion of privacy and interception of communications together constitute the primary legal framework for personal data protection in Haiti. CONATEL has authority to investigate complaints and enforce compliance with consumer data protection obligations in the telecommunications sector. Haiti is a member of CARICOM and the Ibero-American Data Protection Network (RIPD), and applies regional guidelines for data protection in digital services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ht-conatel-2000.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hu-act-cxliii-2015-public-procurement",
    "title": "Hungary Act CXLIII of 2015 on Public Procurement (Közbeszerzési törvény, Kbt.)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Act CXLIII of 2015 on Public Procurement (Közbeszerzési törvény, Kbt.) is Hungary's principal public procurement statute, in force from 1 November 2015 and transposing EU Directives 2014/23/EU, 2014/24/EU and 2014/25/EU. The Act is structured in Részek (Parts) covering general provisions, EU-threshold procurement (Second Part), national-threshold procurement (Third Part), concessions (Fourth Part) and dispute resolution. The fundamental principles set out in §2 require contracting authorities to ensure clean competition, transparency and publicity among economic operators, with equal treatment, proportionate procedures, good faith and integrity. §5 lists the in-scope contracting authorities including ministries, local governments and public institutions. Special exclusions cover defence and security procurement, in-house contracts where the controlled entity meets the 80%-revenue criterion, intermunicipal cooperation in the public interest, and central purchasing body services. Procurement procedures vary by threshold: EU-threshold contracts follow the detailed Second Part; below-EU but above-national threshold contracts follow the simplified Third Part; concessions follow the Fourth Part. Conflict-of-interest rules prevent planning participants from bidding and bar high-ranking state officials from participation. The Közbeszerzési Döntőbizottság (Public Procurement Arbitration Board) reviews disputed procedures and awards remedies, with judicial review available before the Metropolitan Court.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-directive-2014-23-concession-contracts",
      "eu-directive-2014-25-utilities-procurement"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "hu-act-lvii-1996-competition-act",
    "title": "Hungary Act LVII of 1996 on the Prohibition of Unfair and Restrictive Market Practices (Versenytörvény, Tpvt.)",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Act LVII of 1996 on the Prohibition of Unfair and Restrictive Market Practices (Versenytörvény, Tpvt.) is Hungary's principal competition law statute, in force from 1 January 1997 and amended to align with the EU competition framework. The Act is structured in three Parts. Part One (Substantive Provisions) is organised in Fejezetek (Chapters): Fejezet I sets the scope of application including extraterritorial conduct affecting Hungarian markets; Fejezet II prohibits unfair competition including denigration (§3), product imitation without consent (§6) and bid-rigging (§7); Fejezet III prohibits misleading commercial practices against business partners (§8); Fejezet IV prohibits anti-competitive agreements with the core cartel prohibition in §11 and the de minimis and exemption regime in §§12-17; Fejezet V prohibits abuse of dominant position (§§21-22); Fejezet VI governs merger control (§§23-31). Part Two (Enforcement Authority) establishes the Gazdasagi Versenyhivatal (GVH - Competition Authority) and the independent Versenytanacs (Competition Council). Part Three (Procedural Provisions) governs sector inquiries (§§43/C-43/F) and complaint procedures (§§43/G-43/I).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-gwb-competition-act",
      "it-legge-287-1990-antitrust"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "hu-infotv-2011",
    "title": "Hungary Information Self-Determination and Freedom of Information Act 2011 (Infotv) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Hungary's Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Az információs önrendelkezési jogról és az információszabadságról szóló 2011. évi CXII. törvény - Infotv), published in the Hungarian Official Gazette (Magyar Közlöny) on 26 July 2011 and subsequently substantially amended to align with the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) by Act LIV of 2018 and subsequent amendments, is Hungary's primary national data protection legislation. The GDPR is directly applicable Hungarian law by virtue of Hungary's EU membership. The Infotv was significantly restructured by the 2018 amendments to remove provisions now covered directly by GDPR while retaining national derogations and additions. Hungary's Infotv is distinctive in combining personal data protection (informational self-determination - információs önrendelkezési jog) with freedom of information (information freedom - információszabadság) in a single legislative framework. Enforcement: the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH - National Authority for Data Protection and Freedom of Information) is Hungary's independent data protection and freedom of information supervisory authority. The NAIH is Hungary's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Hungarian national provisions: (1) Age of digital consent: Hungary has maintained the GDPR default of 16 years for information society services; data subjects under 16 require parental or guardian consent; (2) Freedom of information - the Infotv's freedom of information provisions govern public access to information held by public bodies, which interacts with GDPR for personal data in public documents; the constitutional right to access public data (közérdekű adatok) under the Hungarian Fundamental Law (Alaptörvény) supplements GDPR; (3) Employment context - Hungarian labour law, particularly the Labour Code (Munka Törvénykönyve - Mt., Act I of 2012), contains provisions on employee monitoring and privacy in employment that apply alongside the Infotv and GDPR; (4) Health data - the processing of health data in Hungary is subject to specific Hungarian health legislation in addition to GDPR; (5) Criminal data - the Infotv restricts private entity processing of criminal conviction data; (6) Sensitive data - special category data processing is subject to GDPR Art. 9 conditions and any additional Hungarian statutory requirements. Fines: GDPR administrative fines apply in Hungary - up to EUR 20 million or 4% of global annual turnover. The NAIH has imposed significant fines and issued enforcement decisions, including in the areas of employment data, healthcare data, and public authority processing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "hydrogen-safety-iso",
    "title": "Hydrogen Safety (ISO 22734)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Adherence to ISO 22734:2019 establishes a comprehensive safety and operational framework for hydrogen generators utilizing water electrolysis. This regimen necessitates stringent control over process variables, including a hydrogen concentration alarm limit not exceeding 4000 ppm and a maximum permissible oxygen impurity in produced hydrogen of 20000 ppm. Functional safety integrity, as defined by IEC 61508, mandates an emergency shutdown system achieving a Safety Integrity Level of 2, a requirement substantiated by having fail_safe_valves_verified. For operation within potentially explosive environments, equipment must be atex_zone_certified under Directive 2014/34/EU. Installation safety, guided by principles from NFPA 2 and basic considerations within ISO/TR 15916:2015, requires continuous mechanical ventilation providing a minimum of 10 air changes per hour. System integrity is maintained through active system pressure monitoring and the use of feed water with conductivity below 5 µS/cm. Furthermore, purge gas systems must operate with a minimum pressure of 5 bar. Cybersecurity for the industrial control system is validated because iec_62443_compliance_met standards are satisfied, which includes having telemetry_encryption_enabled to secure operational data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iaasb-isqm-1-quality",
    "title": "Audit Quality (ISQM 1)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with International Standard on Quality Management 1 requires the establishment and operation of a comprehensive System of Quality Management (SOQM). Central to this framework is governance and leadership, mandating that ultimate responsibility and accountability for the SOQM are explicitly assigned. The firm must implement a dynamic risk assessment process, inclusive of an active client acceptance and continuance policy, to establish quality objectives and to identify and assess quality risks. A foundational component involves fulfilling all responsibilities under relevant ethical requirements, ensuring independence is continually tracked per the IESBA Code. The standard further dictates that technological resources, including those from managed service providers, necessitate robust controls; IT applications require enforced security and appropriate environmental controls must be established to maintain audit data confidentiality. A critical, ongoing element is the active monitoring and remediation process, which includes mandated engagement quality reviews to evaluate system effectiveness. Findings from these monitoring activities are evaluated to identify deficiencies, which then enter a remediation workflow that must be completed within a maximum of 60 days. The entire SOQM is subject to a holistic evaluation at least annually, based on a 365-day cycle, to confirm its continued suitability and operational effectiveness.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifac-ethics-accountants",
      "iia-internal-audit-ippf",
      "iso-31000-risk-mgt",
      "iso-9001-quality-mgt",
      "pcaob-audit-standards",
      "sarbannes-oxley-404"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iab-ads-txt-authorization",
    "title": "IAB Ads.txt (Auth)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with the IAB Tech Lab's Ads.txt Specification Version 1.1 is a mandatory control under the Trustworthy Accountability Group's Certified Against Fraud Guidelines. The BIDDA platform enforces strict validation, requiring the file's location exclusively at the domain root path per Uniform Resource Identifier generic syntax. Secure delivery over HTTPS is mandatory, with server responses conforming to a 5000-millisecond timeout threshold, a 100-kilobyte maximum file size, and no more than five sequential redirects. Per IETF RFC 7231, the HTTP Content-Type header must be explicitly 'text/plain', and file contents must utilize UTF-8 encoding. Syntactically, each record requires a minimum of three fields and must not exceed four, while comments initiated by a hash symbol are permitted. Field-level validation enforces a strict relationship boolean, where the relationship field must contain either 'DIRECT' or 'RESELLER'; case-insensitive processing is applied to this field. These declarations are critical for programmatic verification, mapping the publisher ID against the Sellers.json specification and validating cryptographic nodes within the OpenRTB SupplyChain Object to ensure a transparent, fraud-free advertising ecosystem.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iab-sellers-json-standard",
      "iab-openrtb-standard",
      "iab-tcf-v2-2-consent"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iab-ai-transparency-disclosure-framework-2026",
    "title": "IAB AI Transparency and Disclosure Framework (January 2026) - Materiality-Based Disclosure for AI in Digital Advertising",
    "domain": "Sales, Marketing & PR",
    "version": "2.0.0",
    "last_updated": "2026-07-10",
    "bluf": "The IAB (Interactive Advertising Bureau) AI Transparency and Disclosure Framework, published on 15 January 2026, is voluntary industry guidance for brands, agencies, publishers and ad platforms on when artificial intelligence use in digital advertising requires consumer-facing disclosure. The Framework adopts a materiality-driven rather than universal disclosure standard: disclosure is required only when AI materially affects authenticity, identity, or representation in ways that could mislead consumers. Under the Framework, disclosure is required for AI-generated content depicting real-world events, AI-generated voices of deceased persons making new statements, AI-generated voices of living persons describing events or actions that never occurred, digital twins of deceased individuals, digital twins of living individuals placed in scenarios that never happened, and synthetic avatars or AI chatbots simulating human interaction in advertisements. The Framework carves out exceptions including scripted commercial endorsements, brand messaging and standard product endorsements. It prescribes a two-layer disclosure model: consumer-facing disclosure via standardized text labels, visual indicators such as watermarks or badges, interactive elements, or adjacent placement; and machine-readable metadata using C2PA protocols. The Framework is voluntary industry guidance and does not displace statutory disclosure duties, including the FTC Endorsement Guides (16 CFR Part 255), the FTC clear-and-conspicuous standard for digital ad disclosures, EU AI Act Article 50 transparency obligations for synthetic content and deepfakes (applicable from 2 August 2026), the EU Digital Services Act advertising transparency duties, and state synthetic-media statutes such as the Tennessee ELVIS Act 2024. Entities applying the Framework should document each AI use and the materiality analysis supporting the disclosure decision, since the statutory regimes continue to apply and regulators can request the basis for a no-disclosure outcome.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ftc_endorsement_guides_anchor",
        "ftc_com_disclosures_anchor",
        "eu_ai_act_article_50_anchor",
        "dsa_advertising_transparency_anchor",
        "industry_mapping",
        "enforcement_anchors",
        "c2pa_content_credentials_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-endorsement-guides-2023",
      "eu-ai-act-article-50-transparency-obligations",
      "c2pa-content-provenance"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "iab-ccpa-compliance-us-privacy-technical-spec",
    "title": "IAB CCPA Compliance Framework - US Privacy Technical Specification: Global Privacy Control (GPC) Signal Honouring, Opt-Out of Sale/Sharing, Privacy Signal Pass-Through in RTB Auctions, CCPA/CPRA String and Publisher Liability Protections",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a standardized contractual and technical framework for honoring consumer privacy rights under U.S. state privacy laws, particularly regarding opt-out of sale/sharing of personal information in digital advertising. It applies to advertisers, publishers, technology vendors, and agencies participating in digital ad transactions, and operates via the IAB Multi-State Privacy Agreement (MSPA) as a springing contract effective upon data flow, with mandatory adherence to privacy signaling through the Global Privacy Protocol (GPP) for publishers. Key provisions are defined in the Fourth Amended and Restated MSPA effective July 7, 2025, and its amendments effective January 1, 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ccpa-cpra-optout-sale",
      "eu-geo-blocking-regulation-2018-302",
      "ftc-digital-advertising-disclosures",
      "can-spam-act-email",
      "eprivacy-cookie-directive"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iab-europe-tcf-v2-2-gdpr-consent",
    "title": "IAB Europe Transparency and Consent Framework v2.2 - GDPR Consent for Digital Advertising: CMP Requirements, Vendor List, TC String Encoding, Legitimate Interest Assertions, Special Feature Opt-Ins and Belgian DPA Audit Requirements",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes technical and policy requirements for obtaining, recording, and transmitting user consent and legitimate interest signals in digital advertising under the GDPR, specifically mandating compliance with user preferences for cookies and data processing via standardized signals. Key obligations are derived from the IAB Europe TCF v2.0 specification, particularly regarding consent management platform (CMP) implementation and vendor transparency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eprivacy-cookie-directive",
      "eu-ecommerce-directive-2000-31",
      "eu-unfair-commercial-practices-2005-29",
      "coppa-marketing-kids",
      "ccpa-cpra-optout-sale"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iab-mraid-mobile-ads",
    "title": "IAB MRAID (Mobile Ads)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with this node mandates strict adherence to the IAB Mobile Rich Media Ad Interface Definition (MRAID) v3.0 specification and pertinent data privacy regulations. All ad creatives must support a `min_mraid_version_supported` of 3.0 and complete the `mraid_ready_timeout_ms` within 5000 milliseconds, following a `require_mraid_js_initialization` of true. Security is paramount; therefore, the node will `enforce_https_all_assets` loading via HTTPS as stipulated in Section 5.3 of the MRAID v3.0 specification. To align with IAB LEAN Ads Program principles for non-invasive ads, this configuration sets `allow_auto_expand_ads` to false and `require_user_interaction_for_audio` as true. Furthermore, creatives must not use a custom close button when expanded (`allow_custom_close_button_on_expand` is false) and are limited to a `max_resize_width_percentage` and `max_resize_height_percentage` of 100 percent. Performance optimization is enforced, as the policy will `block_background_network_requests_when_hidden`. The standardized API, detailed in MRAID v3.0 Section 7, governs functionality, with the node requiring that implementations `enforce_viewability_exposure_api` for accurate measurement. Regarding data privacy, the configuration mandates `require_explicit_location_consent` before accessing geolocation data, a control directly informed by GDPR Article 6(1)(a) and Article 7 on valid consent, MRAID v3.0 Section 4.5 on location privacy, and the Children's Online Privacy Protection Act (COPPA), which prohibits precise location data collection for ads targeting children.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iab-tcf-v2-2-consent",
      "gdpr-art-21-marketing-optout",
      "ccpa-cpra-optout-sale",
      "eprivacy-cookie-directive",
      "mrc-viewability-standard",
      "iab-openrtb-standard"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iab-openrtb-standard",
    "title": "IAB OpenRTB",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Enforcement of the IAB OpenRTB protocol ensures rigorous adherence to technical specifications and global privacy regulations. This configuration mandates compliance with key structural elements from the OpenRTB API Specification Version 2.5, requiring that every bid request contain a unique identifier (`require_bid_request_id`) and an impression array (`require_impression_array`), with a corresponding bid response ID (`require_bid_response_id`). The maximum auction timeout is strictly limited to 120 milliseconds. Security of processing, a core tenet of GDPR Article 32, is upheld through the mandatory use of Transport Layer Security encryption (`require_tls_encryption`) consistent with RFC 8446 standards. Further aligning with GDPR Article 5(1)(f), user IP addresses undergo pseudonymization by masking 24 bits from IPv4 and 56 bits from IPv6 addresses. Regulatory compliance is managed through the strict interpretation of specific flags and consent mechanisms. The node enforces the `regs.coppa` flag when its value is 1, which aligns with the Children's Online Privacy Protection Act per 16 CFR § 312.5. It also processes the IAB Tech Lab US Privacy String for CCPA/CPRA compliance and parses the IAB Europe Transparency and Consent Framework v2.2 consent string from `user.ext.consent`. User-level privacy choices are respected by enforcing the Limit Ad Tracking `lmt` flag. To ensure creative quality and brand safety, the node validates all ad markup (`validate_ad_markup_adm`) and blocks prohibited advertiser categories (`block_bcat_categories`).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iab-tcf-v2-2-consent",
      "coppa-marketing-kids",
      "ccpa-cpra-optout-sale",
      "gdpr-art-21-marketing-optout"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iab-sellers-json-standard",
    "title": "IAB Sellers.json",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Adherence to the IAB Tech Lab Sellers.json Final Specification v1.0 is a critical mechanism for promoting transparency and combating fraud within the programmatic advertising ecosystem, a concern underscored by the Association of National Advertisers' Programmatic Media Supply Chain Transparency Study. This compliance node validates that exchange-provided files align with industry best practices, including the Trustworthy Accountability Group's Certified Against Fraud Guidelines and the General Data Protection Regulation's Article 5(1)(a) principle of transparency. Key structural mandates require publishing the file at the domain root, enforcing TLS/HTTPS encryption, and serving it with a proper `http_content_type_json` header. The schema verifies that each seller entry contains a mandatory `seller_id` and a `seller_type`, with an allowance for three distinct enumerated values. For any transparent entities, the configuration enforces the inclusion of both `name` and `domain` fields, while also supporting the `is_confidential` flag for parties choosing anonymity. This framework, which complements the OpenRTB SupplyChain Object and ads.txt specifications, further requires that either a contact email or address is provided, respects a `max_cache_duration_seconds` of 86400, and allows for vendor-specific data through a passthrough `ext` object.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iab-ads-txt-authorization",
      "iab-openrtb-standard"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iab-simid-interactive-ads",
    "title": "IAB SIMID (Interactive)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Configuration within this compliance node mandates rigorous security controls for interactive advertisements employing the IAB's Secure Interactive Media Interface Definition (SIMID), with a `minimum_simid_version` of 1. Pursuant to IAB Tech Lab guidance on the SIMID protocol, all communication between a media player and interactive creative must utilize the standardized `postMessage` protocol, a policy enforced by the `require_postmessage_protocol` parameter. To mitigate cross-site scripting (XSS) vulnerabilities in alignment with OWASP prevention rules and W3C HTML5 specifications for the iframe element, this node activates a strict sandboxed environment through `enforce_iframe_sandbox`. This configuration explicitly forbids the `allow_same_origin_sandbox` token while permitting necessary script execution via `allow_scripts_sandbox` to maintain ad functionality. The integrity of cross-document messaging is paramount; therefore, `validate_message_origin` is enabled, ensuring all communications are authenticated against their source origin as stipulated by W3C Web Messaging standards. The player and ad initialization handshake, critical for VAST 4.2 SIMID integration, must complete within a `max_initialization_timeout_ms` of 2000 milliseconds. Further security layers include `require_cors_headers` for all resource requests, a stringent Content Security Policy via `enforce_strict_csp`, and a control to `block_top_navigation_without_activation` which safeguards user experience from unsolicited redirects, while `enable_asset_prefetching` is permitted to optimize performance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iab-vast-video-ads"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iab-tcf-v2-2-consent",
    "title": "IAB TCF v2.2 (Consent)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with IAB Europe's Transparency and Consent Framework v2.2 is enforced according to its governing TCF Policy Version 4, establishing a valid legal basis for data processing pursuant to General Data Protection Regulation Article 6(1)(a) and ePrivacy Directive Article 5(3). This configuration directly reflects critical mandates from the Belgian Data Protection Authority’s decision against IAB Europe, which fundamentally reshaped the framework’s lawful processing requirements. Consequently, the node implements a mandatory block on legitimate interest as a legal basis for purposes three through six. Upholding the strict conditions for consent under GDPR Article 7, this module prohibits manipulative interface designs by disallowing pre-ticked boxes and mandates an accessible mechanism for users to revoke consent at any time. A requirement for explicit consent is enforced for Purpose 1, covering the storage or access of information on a device. Technical specifications are rigorously applied, mandating CMP API version 2, using TC String header version 2, and blocking the deprecated getTCData call. For enhanced transparency, a disclosure of the vendor count is required on the first layer. Ongoing vendor list integrity is maintained through a mandatory check for GVL updates. Finally, consent signal duration is strictly limited, enforcing a maximum retention period of 390 days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eprivacy-cookie-directive"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iab-tcf-v2-consent-framework",
    "title": "IAB Europe Transparency and Consent Framework (TCF) v2.2 - GDPR-Compliant Consent Signalling for Online Advertising",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The IAB TCF provides a standardized mechanism for websites, advertisers, and ad tech vendors to obtain, manage, and signal user consent for processing personal data in compliance with GDPR and the ePrivacy Directive. It requires Consent Management Platforms (CMPs) to provide granular transparency and choice to users regarding data processing purposes and vendors, as mandated by TCF Policy, Chapter II, Section 1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-art-21-marketing-optout",
      "eprivacy-cookie-directive",
      "iab-openrtb-standard"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iab-vast-video-ads",
    "title": "IAB VAST (Video Ads)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "This configuration establishes rigorous compliance standards for digital video advertising by mandating strict adherence to the IAB Tech Lab's VAST 4.3 specification. It requires every creative to contain a `UniversalAdId` for unique tracking and expressly disallows the obsolete VPAID architecture, instead favoring modern SIMID and OMID frameworks. To satisfy Media Rating Council viewability guidelines, each ad response must include an `AdVerifications` node and declare support for the Open Measurement SDK. Performance is strictly governed by capping the ad serving chain at a maximum of 5 wrapper redirects and enforcing a total ad resolution latency under 1500 milliseconds. Security protocols demand that all URIs utilize secure HTTPS, a requirement that supports data protection principles outlined in GDPR Article 5(1)(f), while any tracking pixels must operate under the consent framework of GDPR Article 7. For Server-Side Ad Insertion, a high-bitrate mezzanine file of at least 15000 kbps is mandatory. Accessibility, in accordance with the FCC's CVAA rules, is addressed by requiring a `ClosedCaptionFiles` node in all responses. Finally, the use of server-side macros for dynamic parameter substitution is compulsory.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iab-simid-interactive-ads",
      "mrc-viewability-standard"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iadc-space-debris-mitigation-guidelines-2007",
    "title": "IADC Space Debris Mitigation Guidelines 2007 (Revised 2021)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes international best practices for mitigating space debris, requiring post-mission disposal of spacecraft from LEO within 25 years, re-orbiting of GEO satellites to a graveyard orbit 300 km above GEO, passivation of propellant and pressure systems, execution of collision avoidance manoeuvres, and controlled re-entry where applicable. Key provisions are outlined in IADC-02-01 Rev_4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-registration-convention-1976-space",
      "itu-radio-regulations-2020-edition"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iaea-gsr-part-3-radiation-protection-2014",
    "title": "IAEA General Safety Requirements GSR Part 3 - Radiation Protection and Safety of Radiation Sources: International Basic Safety Standards",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard establishes a system of radiation protection for all facilities and activities giving rise to radiation risks, requiring the application of justification, optimization (ALARA), and dose limitation principles. Per Schedule III, the effective dose for occupational exposure shall not exceed an average of 20 mSv per year over five consecutive years and shall not exceed 50 mSv in any single year.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iaea-gsr-part-3-radiation-protection-energy-2014",
    "title": "IAEA Safety Standards GSR Part 3 - Radiation Protection and Safety of Radiation Sources: International Basic Safety Standards",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-07-18",
    "bluf": "This standard establishes the fundamental safety principles and requirements for protecting people and the environment from harmful effects of ionizing radiation in planned, existing, and emergency exposure situations. It applies to all parties with responsibilities for radiation protection in the energy sector, requiring the application of justification, optimization, and dose limitation as mandated by Requirement 1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "osha-work-safety-us"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iaea-nss-13-physical-protection-nuclear-material",
    "title": "IAEA Nuclear Security Series No. 13 - Nuclear Security Recommendations on Physical Protection of Nuclear Material and Nuclear Facilities (INFCIRC/225/Revision 5)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This IAEA recommendation provides guidance to States for establishing and maintaining a national physical protection regime for nuclear material and facilities to prevent theft, sabotage, and other malicious acts. It mandates a graded approach, detailed in Chapter 4, where the stringency of protection measures is commensurate with the categorization of nuclear material (Table 1) and the potential consequences of a security event.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iaea-nuclear-cyber-security-nst048",
    "title": "IAEA Nuclear Security Series No. 33-T - Computer Security of Instrumentation and Control Systems at Nuclear Facilities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This IAEA technical guidance requires nuclear facility operators to establish, implement, and maintain a comprehensive Computer Security Programme (CSP) for all Instrumentation and Control (I&C) systems. The CSP must protect against unauthorized acts that could compromise nuclear safety or security, incorporating principles like defence in depth and a graded approach to security controls, as detailed in Section 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-800-53-sc7",
      "c-scrm-practices-systems-organizations",
      "nist-800-53-cp2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iaea-safety-fundamentals-sf-1-2006",
    "title": "IAEA Safety Fundamentals No. SF-1: Fundamental Safety Principles",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard establishes the fundamental safety objective and ten associated principles for protecting people and the environment from the harmful effects of ionizing radiation. As stated in Principle 1, it requires all facilities and activities giving rise to radiation risks to ensure that individuals and the environment are adequately protected, now and in the future.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iaea-ssg-52-radiation-protection-uranium-mining",
    "title": "IAEA Safety Guide SSG-52 - Radiation Protection and Safety in Uranium Mining and Processing",
    "domain": "Mining & Natural Resources",
    "version": "SSG-52 (2019)",
    "last_updated": "2026-05-09",
    "bluf": "IAEA Safety Guide No. SSG-52 (2019) provides the international technical standard for radiation protection and safety in uranium mining and processing operations, covering radon and radon progeny exposure control (annual effective dose limit 20 mSv per IAEA BSS GSR Part 3), external gamma radiation monitoring, radioactive dust and aerosol control, individual dosimetry requirements, medical surveillance, environmental discharge limits, and radiological characterisation obligations applicable to all uranium mining modalities (underground, open-pit, in-situ leach, heap leach, and conventional milling).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iaea-safety-fundamentals-sf-1-2006",
      "ilo-c176-safety-health-mines-convention-1995"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iais-application-paper-climate-risk-insurance-2021",
    "title": "IAIS Application Paper on the Supervision of Climate-Related Risks in the Insurance Sector",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This paper provides guidance for insurance supervisors to encourage and assess how insurers manage climate-related risks, focusing on the use of scenario analysis to evaluate resilience (Section 4) and the enhancement of public disclosures in line with frameworks like the TCFD (Section 5). It applies to insurance supervisors globally and, by extension, the insurance undertakings they regulate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "iso-14090-climate-adapt",
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iais-comframe-internationally-active-groups",
    "title": "IAIS ComFrame for Internationally Active Insurance Groups (IAIGs) - Supervisory Cooperation, ICS 2.0 Capital Standard and Liquidity",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Common Framework (ComFrame) establishes a comprehensive set of international supervisory requirements for Internationally Active Insurance Groups (IAIGs) to facilitate effective group-wide supervision. It mandates robust governance, enterprise risk management, and adherence to the Insurance Capital Standard (ICS) to ensure financial stability, as detailed in ComFrame Module 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fsb-key-attributes-res",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iais-comframe-pcr-quantitative-requirements-2023",
    "title": "IAIS ComFrame Prescribed Capital Requirement (PCR) - Group Capital Calculation for Internationally Active Insurance Groups (IAIGs) 2023",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-07-18",
    "bluf": "This regulation establishes the Prescribed Capital Requirement (PCR), a consolidated group-level quantitative capital standard for Internationally Active Insurance Groups (IAIGs), ensuring they hold sufficient capital to absorb significant, unforeseen losses. The core methodology, outlined in ComFrame Module 2, Section 2.1, uses a risk-based approach covering insurance, market, credit, and operational risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iais-holistic-framework-systemic-risk-insurance-2022",
    "title": "IAIS Holistic Framework for Systemic Risk in the Insurance Sector - Activities-Based and Entity-Based Measures (2022 Update)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This framework requires insurance supervisors to implement a comprehensive, activities-based approach to monitor and mitigate systemic risk across the entire insurance sector, complemented by an entity-based assessment to identify Globally Systemically Important Insurers (G-SIIs). As outlined in Section 1, the framework integrates supervisory policy measures, a global monitoring exercise, and resolvability assessments to address both microprudential and macroprudential risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iais-icp-1-objectives-powers-responsibilities",
    "title": "Insurance Core Principles (ICP) 1 - Objectives, Powers and Responsibilities of the Supervisor: Insurance Supervisory Authority Legal Basis, Operational Independence, Accountability, Transparency, Professional Standards and International Cooperation",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "ICP 1 establishes the foundational requirements for an effective insurance supervisory authority, mandating a clear legal basis, operational independence, accountability, transparency, professional competence, and international cooperation. It applies to all jurisdictions establishing or assessing their insurance supervisory framework under IAIS standards, per ICP 1.1-1.15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "eu-eiopa-guidelines-orsa-2015",
      "brazil-susep-solvency-regulation-circular-2021",
      "china-cbirc-c-ross-ii-solvency-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iais-icp-14-valuation-solvency-2023",
    "title": "IAIS Insurance Core Principle 14: Valuation",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This principle requires insurance supervisors to establish requirements for the valuation of assets and liabilities for solvency purposes, ensuring they reflect their economic value. As per ICP 14.1, this valuation must be market-consistent, providing a realistic view of the insurer's financial position and enabling effective risk management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iais-icp-17-group-wide-supervision",
    "title": "Insurance Core Principle 23 - Group-Wide Supervision: Insurance Group Identification, Scope of Group-Wide Supervision, Group Supervisor Designation, Supervisory College Coordination, Intragroup Transaction Monitoring, Contagion Risk Assessment and Crisis Management Group Cooperation",
    "domain": "Insurance & Risk",
    "version": "2.0.0",
    "last_updated": "2026-07-03",
    "bluf": "IAIS ICP 23 requires the group-wide supervisor, in cooperation and coordination with other involved supervisors, to identify the insurance group and determine the scope of group-wide supervision: identifying all legal entities in the group (Standard 23.1), determining the supervisory scope (Standard 23.2) and not narrowing that scope due to lack of legal authority over particular entities (Standard 23.3). The operational elements of group-wide supervision are anchored in related IAIS requirements: designation of the group-wide supervisor, supervisory colleges, written coordination agreements and crisis management preparation under ICP 25 (Supervisory Cooperation and Coordination); group-wide capital adequacy assessment under ICP 17 (Capital Adequacy); and group-wide risk management including intragroup transactions under ICP 16 (Enterprise Risk Management for Solvency Purposes). ComFrame, integrated into the ICPs, adds requirements for Internationally Active Insurance Groups (IAIGs), identified under CF 23.0.a where premiums are written in three or more jurisdictions with at least 10 percent of gross written premiums outside the home jurisdiction, and total assets are at least USD 50 billion or total gross written premiums are at least USD 10 billion on a three-year rolling average.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-lps-110-capital-adequacy-life",
      "canada-osfi-e19-own-risk-solvency-2023",
      "china-cbirc-c-ross-ii-solvency-2022",
      "eu-delegated-regulation-2016-2067-spread-market-risk",
      "eu-eiopa-guidelines-orsa-2015"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iais-icp-25-supervisory-cooperation-2023",
    "title": "IAIS Insurance Core Principle 25: Supervisory Cooperation and Coordination",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-11-15",
    "bluf": "This principle requires insurance supervisors to cooperate and coordinate with other domestic and international supervisors, particularly for internationally active insurance groups (IAIGs). As per ICP 25.1, supervisors must have the legal power and practical ability to engage in this cooperation, including establishing and participating in supervisory colleges and sharing confidential information under strict safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iais-icp-4-licensing-insurers",
    "title": "Insurance Core Principle 4 - Licensing: Criteria for Authorisation of Insurers, Fit and Proper Assessment, Business Plan Requirements, Initial Capital, Qualified Shareholders and Ongoing Licence Conditions",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "IAIS ICP 4 establishes the minimum requirements for the authorisation and ongoing supervision of insurers, including fit and proper assessments of controllers and key personnel, business plan viability, initial capital adequacy, and ongoing compliance with licensing conditions. Applies to all insurers seeking or holding authorisation in jurisdictions adhering to IAIS standards. See ICP 4.1-4.15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "eu-delegated-regulation-2016-2067-spread-market-risk",
      "china-cbirc-c-ross-ii-solvency-2022",
      "bermuda-bma-cissa-commercial-insurer-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iais-icp-8-risk-management-internal-controls",
    "title": "Insurance Core Principle 8 - Risk Management and Internal Controls",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "IAIS ICP 8 requires insurers to establish and maintain a comprehensive enterprise risk management (ERM) framework, including an Own Risk and Solvency Assessment (ORSA), internal control systems, an independent internal audit function, and an actuarial function, all overseen by the board. Applies to all insurance undertakings and groups under supervisory oversight, per ICP 8.1-8.15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eiopa-guidelines-orsa-2015",
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "bermuda-bma-cissa-commercial-insurer-2023",
      "brazil-susep-solvency-regulation-circular-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iais-insurance-core-principles-2019",
    "title": "IAIS Insurance Core Principles (ICPs) 2019 - Supervisory Framework, Governance, Capital Adequacy and Market Conduct",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The IAIS Insurance Core Principles (ICPs) establish a globally accepted framework for the supervision of the insurance sector, requiring supervisors to ensure insurers implement robust corporate governance, risk management, and internal control frameworks (ICP 7 & 8) to maintain financial stability and protect policyholders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "iso-37301-compliance-mgt",
      "fsb-key-attributes-res"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iais-supervisory-material-cyber-risk-insurance-2022",
    "title": "IAIS Issues Paper on Cyber Risk to the Insurance Sector (August 2016) - Cyber Threats, Insurer Cyber Resilience and Supervisory Response",
    "domain": "Insurance & Risk",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The IAIS Issues Paper on Cyber Risk to the Insurance Sector, published August 2016 and prepared by the IAIS Financial Crime Task Force, raises awareness of cyber risk to insurers and describes current and contemplated supervisory approaches. It is expressly descriptive: Issues Papers 'provide background', 'are primarily descriptive and not meant to create expectations on how supervisors should implement supervisory material', and may form preparatory work for future standards. Its scope is cyber risk to insurers and the mitigation of that risk; it explicitly does NOT cover the underwriting or selling of cyber-insurance products, broader IT security risk, or cyber incidents involving supervisors. The paper covers the cyber risk landscape, cyber threats and example incidents in the insurance sector, insurer cyber resilience (governance, risk management, recovery), the applicability of the Insurance Core Principles (ICPs) to cybersecurity, and supervisory responses observed across jurisdictions. Because it sets no binding supervisory expectations, organisations should treat its content as background guidance and look to applicable ICPs and local supervisory rules for binding obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "dora-third-party-risk-articles-28-44",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-161r1-csrm-practices"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iasb-ifrs-17-amendments-2020-transition",
    "title": "Amendments to IFRS 17 Insurance Contracts: Transition Relief, Risk Mitigation Option and Annual Cohort Exemption (June 2020)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "These amendments to IFRS 17 provide optional reliefs for entities during the initial transition to the standard, primarily concerning the grouping of contracts into annual cohorts and the accounting for risk mitigation. As detailed in Appendix C, entities can choose between a full retrospective, modified retrospective, or fair value approach, with specific exemptions available to reduce implementation complexity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iasb-ifrs-17-insurance-effective-date-2023",
    "title": "IFRS 17 Insurance Contracts - Effective Implementation (January 2023): Measurement Models, Contractual Service Margin and Onerous Contracts",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "Effective for annual reporting periods beginning on or after January 1, 2023, IFRS 17 mandates that all entities issuing insurance contracts adopt a new accounting model for their recognition, measurement, presentation, and disclosure. This standard, as per Appendix C, replaces IFRS 4 and requires insurers to measure insurance liabilities using current assumptions, explicitly identify profits in the Contractual Service Margin (CSM), and recognize losses from onerous contracts immediately.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "iata-cargo-regulations-perishable-chapter-17",
    "title": "IATA Perishable Cargo Regulations - Chapter 17: Temperature Control Categories (Frozen/Chilled/Ambient), Packaging Standards, Pre-Cooling Requirements, Cool Chain Audit, Time-Temperature Indicators and Acceptance Checklist for Air Freight",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes mandatory requirements for temperature control, packaging, pre-cooling, and monitoring of perishable cargo during air transport to ensure product integrity. It applies to all shippers, carriers, and ground handlers involved in the air shipment of perishable goods under IATA standards, with key provisions in section 1.5 and chapter 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brc-food-safety-global",
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-food-hygiene-regulation-852-2004",
      "iso-20022-messaging"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iata-dangerous-goods",
    "title": "IATA Dangerous Goods Regulations (DGR)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Assessment against the International Air Transport Association Dangerous Goods Regulations (DGR) confirms the consignment's adherence to standards derived from ICAO Annex 18. Compliance is predicated on personnel holding valid certification under the competency-based training and assessment approach specified in IATA DGR Section 1.5. The article is correctly identified with an assigned UN number per the List of Dangerous Goods found within Section 4.2. Based on criteria from Section 3, it falls under Hazard Class 9 with a low danger Packing Group III designation. Packaging meets all UN specification requirements mandated by Section 5, which outlines general packing provisions alongside specific Packing Instructions. Although the declared quantity per package is zero kilograms, the consignment is forbidden on passenger aircraft, necessitating a Cargo Aircraft Only label. A fully compliant Shipper's Declaration for Dangerous Goods has been provided as stipulated by documentation rules in Section 8. Furthermore, all relevant state and operator variations have been checked, required emergency response information is available for immediate use, and the digital Notification to Captain (NOTOC) has been successfully transmitted to the flight crew. This comprehensive validation ensures every facet of the shipment meets the stringent international framework for the safe air transport of dangerous goods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-annex-17-security",
      "icao-safety-mgt-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iata-passenger-svcs",
    "title": "IATA Passenger Service (Reso)",
    "domain": "Food & Hospitality",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with International Air Transport Association (IATA) passenger service resolutions is mandated to ensure operational uniformity and data integrity across the global air transport system. This framework requires mandatory electronic ticketing for all carriers, a principle reinforced by Resolution 722f, which also necessitates support for interline electronic ticketing to facilitate seamless multi-carrier journeys. Conformance with Resolution 792 dictates that all Passenger Name Record (PNR) data require a standardized PNR format and secure data exchange protocols; the system must also enable EDIFACT to XML conversion for interoperability. Under Resolution 700 concerning passenger acceptance, handling procedures for passengers with reduced mobility (PRM) demand that PRM data encryption is required, and all Special Service Request (SSR) communications must adhere to a maximum SSR code length of four characters. Resolution 735d establishes a maximum ticket validity of 12 months for transport documents and governs the auto-cancellation for no-show process, while Resolution 740 specifies the form of interline baggage tags, mandating the baggage tag barcode standard be Code 128. Finally, operational procedures must align with Recommended Practice 1708, which provides guidelines for Advanced Passenger Information (API) systems and stipulates a maximum API data retention period of 30 days post-travel to balance security needs with privacy obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-hospitality-nuance",
      "pci-dss-hospitality"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iatf-16949-2016-automotive-quality-management-system",
    "title": "IATF 16949:2016 - International Automotive Quality Management System Standard",
    "domain": "Automotive & Mobility",
    "version": "2016",
    "last_updated": "2026-05-09",
    "bluf": "IATF 16949:2016 (International Automotive Task Force) is the global quality management system standard for automotive production and service parts organisations; built on ISO 9001:2015, it adds automotive-specific requirements for customer-specific requirements (CSRs), special characteristics, manufacturing feasibility assessment, production trial run, embedded use of the five AIAG Core Tools (APQP, PPAP, SPC, MSA, FMEA), and mandatory third-party certification through IATF-recognized CBs on a three-year cycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ibc-2021-international-building-code",
    "title": "International Building Code (IBC) 2021 - Occupancy Classifications, Structural Requirements and Fire-Resistance Ratings",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The International Building Code (IBC) 2021 establishes minimum requirements for building safety, health, and welfare by regulating the design, construction, and occupancy of new and existing buildings. It mandates specific criteria for occupancy classification (Chapter 3), structural design loads (Chapter 16), and fire-resistance ratings for structural elements based on construction type (Chapter 7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "155.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "icao-annex-17-security",
    "title": "ICAO Annex 17: Aviation Security",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with ICAO Annex 17 mandates each Contracting State establish a National Civil Aviation Security Programme (NCASP) managed by an appropriate authority, consistent with Standard 3.1.1. The programme's effectiveness hinges upon the rigorous implementation of preventive security measures across all aviation operations. Fundamental preventive measures as detailed in Chapter 4 include comprehensive access control, where `airport_security_restricted_areas_controlled` must be true to safeguard Security Restricted Areas, a status contingent upon a `background_checks_completed_percent` rate of 100 for personnel. Standard 4.4.1 prescribes a universal screening mandate, requiring both `passenger_screening_rate_percent` and `hold_baggage_screening_rate_percent` to equal 100. In parallel, Standard 4.6.1 directs that security controls apply to airfreight, validating compliance when `cargo_supply_chain_security_validated` is true. Addressing modern risks, Standard 4.9.1 requires protection of critical aviation information systems; compliance stipulates that `avsec_cybersecurity_measures_implemented` is true, supported by a `cyber_risk_assessment_frequency_months` cycle not exceeding 12. Overall programme integrity is maintained through a national aviation security quality control programme as required by Standard 3.4.1, demonstrated when `quality_control_audits_active` is true and reinforced by a `national_threat_assessment_frequency_months` interval of 12 and confirmation that the `incident_response_plan_tested_annually` is performed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-safety-mgt-system",
      "iso-28000-supply-chain",
      "wco-safe-framework"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "icao-annex-19-safety-management-system-second-edition",
    "title": "ICAO Annex 19 Safety Management (Second Edition 2016) - State Safety Programme and Service Provider SMS",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "ICAO Annex 19 to the Convention on International Civil Aviation 1944 (Chicago Convention) is the first ICAO Annex devoted entirely to safety management, adopted by the ICAO Council on 25 February 2013 (First Edition) and amended in November 2016 (Second Edition, applicable 7 November 2019). Annex 19 consolidates and harmonises safety management provisions previously distributed across multiple Annexes (1, 6, 8, 11, 13, 14). Chapter 3 establishes State Safety Programme (SSP) requirements for ICAO Contracting States covering: State safety policy and objectives, State safety risk management, State safety assurance, and State safety promotion. Chapter 4 establishes Safety Management System (SMS) requirements applicable to service providers including approved training organisations, aeroplane and helicopter operators conducting international commercial air transport operations, approved maintenance organisations, organisations responsible for type design and manufacture, ATS providers, certified aerodromes. Appendix 1 provides framework for State Safety Programme. Appendix 2 provides framework for SMS. State Safety Plans must include hazard identification, safety risk assessment and mitigation, safety performance measurement, and continuous improvement. Aligns with broader Global Aviation Safety Plan (GASP) Doc 10004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-chicago-convention-1944-civil-aviation",
      "icao-doc-9859-sms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "icao-chicago-convention-1944-civil-aviation",
    "title": "Convention on International Civil Aviation (Chicago Convention 1944)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Convention on International Civil Aviation (ICAO Doc 7300), signed at Chicago on 7 December 1944 and in force since 4 April 1947, is the constitutional instrument of international civil aviation binding 193 Contracting States. Art 1 establishes complete and exclusive State sovereignty over national airspace; Art 6 requires special permission for scheduled international air services; Arts 17-18 assign aircraft nationality to the State of registration and prohibit dual registration; Art 33 mandates mutual recognition of airworthiness certificates meeting ICAO minimum standards; Art 37 empowers ICAO to adopt Standards and Recommended Practices (SARPs) across Annexes 1-19; Art 38 requires States to notify ICAO of differences from SARPs; and Arts 87-88 authorise denial of airspace access and suspension of Assembly voting rights as sanctions for default.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "icao-annex-17-security",
      "icao-safety-annex-19",
      "montreal-convention-1999-air-carriage"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "icao-corsia-carbon-offsetting-aviation",
    "title": "ICAO CORSIA Carbon Offsetting and Reduction Scheme for International Aviation - Baseline, Eligible Units and Monitoring Plan",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Carbon Offsetting and Reduction Scheme for International Aviation (CORSIA) requires international airline operators to monitor, report, and verify their annual CO2 emissions and offset any emissions exceeding the 2019 baseline by purchasing and cancelling eligible carbon units. This global market-based measure is detailed in ICAO Annex 16, Volume IV, and aims to stabilize net CO2 emissions from international civil aviation at 2019 levels.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "icao-doc-10084-cybersecurity-action-plan-2022",
    "title": "ICAO Aviation Cybersecurity Strategy and Cybersecurity Action Plan (CyAP) - National Cybersecurity Strategies, CERT Coordination and AVSEC Integration",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The ICAO Aviation Cybersecurity Strategy and its Cybersecurity Action Plan (CyAP) require Member States to develop and implement a national civil aviation cybersecurity strategy and policy framework, as outlined under the Strategy's first pillar. They call for the establishment of designated authorities, coordination with national CERTs, and the integration of cybersecurity measures into existing Aviation Security (AVSEC) programs to protect critical aviation systems. (Note: ICAO Doc 10084 is the Risk Assessment Manual for Civil Aircraft Operations Over or Near Conflict Zones and is unrelated to cybersecurity; the cybersecurity Strategy and CyAP are separate, unnumbered ICAO documents.)",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "icao-doc-9303-travel-document-standards-biometric",
    "title": "ICAO Doc 9303 - Machine Readable Travel Documents and Biometric Data Standards",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "ICAO Document 9303 (8th Edition 2021) establishes the global standard for Machine Readable Travel Documents (MRTDs) including e-Passports with biometric chips (Part 9), biometric data specifications (Part 9: LDS and PKI), and machine readable zones (Part 3-7). All 193 ICAO Contracting States are obligated to implement these standards. AI-based identity verification, border management systems, and passport scanning tools must comply with ICAO 9303 biometric data specifications. Facial recognition accuracy requirements in border AI intersect with EU AI Act Annex III high-risk system requirements and GDPR biometric data processing under Article 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standards",
        "frameworks",
        "regulations",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-10-data-governance-training",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "icao-doc-9859-sms",
    "title": "ICAO Doc 9859 Safety Management Manual (SMM), 4th Edition",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "ICAO Doc 9859 provides comprehensive guidance for States and aviation service providers on developing, implementing, and maintaining a Safety Management System (SMS) in compliance with ICAO Annex 19. The manual details the four core components and twelve elements of the SMS framework (Chapter 5), which are essential for the proactive management of safety risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "285.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-safety-annex-19",
      "as9100-rev-d-qms",
      "mil-std-882e-system-safety",
      "easa-part-145-maintenance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "icao-safety-annex-19",
    "title": "ICAO Annex 19 (Safety Management)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "ICAO Annex 19 establishes the international standard for Safety Management Systems (SMS) and State Safety Programmes (SSP) in civil aviation. It focuses on the proactive management of safety risks through the collection, analysis, and exchange of safety data and safety information, ensuring absolute flight safety integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "faa-part-21-certification",
      "easa-part-145-maintenance"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "icao-safety-mgt-system",
    "title": "ICAO safety management system (SMS)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "An organization's compliance with the International Civil Aviation Organization (ICAO) safety management system framework mandates a systematic approach to managing safety, including necessary organizational structures, accountabilities, policies, and procedures. As detailed in ICAO Annex 19 and supported by guidance within ICAO Doc 9859, a compliant SMS is a fundamental requirement for service providers. This system necessitates that an accountable executive is appointed, ensuring ultimate responsibility for safety performance resides at the highest level, and a safety policy is documented, clearly stating the organization's commitment. The core of the SMS involves a robust safety risk management process where a hazard identification system is active, enabling proactive identification of potential dangers before they result in incidents. Subsequently, risks are assessed, and mitigation actions are triggered when their severity exceeds a defined risk mitigation threshold score of 3. Safety assurance, a critical component detailed in regulations like EASA Part-ORO and 14 CFR Part 5, is maintained through continuous monitoring. This requires that safety performance indicators are defined and a safety data collection system is implemented, providing data to measure performance against targets. A formal management of change process must be active to manage risks associated with operational changes. The system's effectiveness is verified through internal audits, with an audit frequency of 12 months, and at least one annual continuous improvement review conducted by management. Furthermore, safety promotion activities are essential, demanding that safety training compliance achieves 100 percent to ensure all personnel are competent. Finally, an emergency response plan must be active, ensuring readiness for accidents and incidents, a requirement echoed across Annex 6 and Annex 14 for aircraft operators and aerodromes respectively.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-annex-17-security",
      "iata-dangerous-goods",
      "iso-31000-risk-mgt-std",
      "iso-45001-health-safety",
      "as9100-rev-d"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "icc-700-national-green-building-standard-2020",
    "title": "ICC 700 National Green Building Standard (NGBS) 2020",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The ICC 700 National Green Building Standard (NGBS) provides a voluntary framework and rating system for new and renovated residential buildings to achieve sustainability goals. Compliance requires meeting all mandatory provisions in Chapters 5-10 and accumulating sufficient points from elective practices to attain one of four certification levels: Bronze, Silver, Gold, or Emerald, as outlined in Chapter 4, Scoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-46001-water-eff"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "icc-arbitration-rules-2021",
    "title": "ICC Rules of Arbitration (2021)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The ICC Rules of Arbitration provide a comprehensive framework for conducting international commercial arbitrations, governing the entire process from the initial request to the final award. These rules, which apply when parties have agreed to them in writing (Article 1), establish procedures for constituting the arbitral tribunal, managing proceedings, and obtaining emergency relief through an Emergency Arbitrator (Article 29).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-arbitration"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "icc-incoterms-master",
    "title": "Incoterms 2020 Master",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Adherence to the eleven official trade terms within the International Chamber of Commerce Incoterms® 2020 rules is systematically enforced, defining critical obligations, costs, and the transfer of risk consistent with principles in the United Nations Convention on Contracts for the International Sale of Goods. The node's configuration mandates mode-specific rule application, such as requiring FCA for containerized shipments, while also formally recognizing the transition from DAT to DPU by blocking the former. Insurance obligations are strictly validated, requiring minimum coverage at 110 percent of contract value under Institute Cargo Clauses (A) for CIP transactions and Institute Cargo Clauses (C) for CIF. Furthermore, the system mandates a precisely specified named place to prevent ambiguity in risk transfer. Security-related clearance costs and responsibilities are allocated according to the A9/B9 provisions within each rule, reflecting standards from the World Customs Organization SAFE Framework. The configuration permits parties to utilize their own transport where applicable. To mitigate compliance failures, the node flags significant liabilities associated with EXW and DDP terms, particularly concerning export and import declarant status under frameworks like the Union Customs Code, offering a clear delineation from domestic commercial law such as the U.S. Uniform Commercial Code Article 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "arbitration-uncitral-rules"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "icc-model-contract-creative-agency-client-2022",
    "title": "ICC Model Contracts for Advertising and Marketing Communications 2022 - Creative Agency/Client Agreement",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This ICC model contract governs intellectual property assignment, usage rights duration, territory, approval workflows, talent residuals, confidentiality, and termination in creative agency-client relationships. Key obligations are defined in Clause 5 (IP Assignment), Clause 6 (Usage Rights), and Clause 9 (Confidentiality).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-asa-cap-code-2010",
      "berne-convention-1886-2024-literary-artistic-works",
      "eu-copyright-directive-art-17",
      "dmca-safe-harbor",
      "iptc-photo-metadata"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "icd-11-classification-2022",
    "title": "WHO International Classification of Diseases 11th Revision (ICD-11) 2022 - Global Standard for Diagnostic Coding",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The ICD-11 is the global standard for diagnostic health information, requiring WHO Member States and healthcare entities to use its updated coding system for recording and reporting mortality and morbidity data. As mandated by the World Health Assembly resolution WHA72.6, its implementation ensures consistent, comparable health statistics worldwide and supports clinical care, health services management, and research.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hl7-fhir-v4-interop",
      "iso-27799-health-info-sec",
      "gdpr-health-data",
      "hipaa-security-rule",
      "eu-health-data-space-2024"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-e11-r1-clinical-investigation-pediatric-population",
    "title": "ICH E11(R1): Clinical Investigation of Medicinal Products in the Pediatric Population",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "ICH E11(R1) sets the framework for clinical investigation of medicinal products in the paediatric population (birth to 18 years). The R1 addendum (2017) added specific guidance on extrapolation, modelling and simulation, paediatric formulations, ethical considerations, neonatal studies, and the role of paediatric expertise. The guideline divides the paediatric population into preterm newborns, term newborns (0-27 days), infants and toddlers (28 days to 23 months), children (2-11 years), and adolescents (12-18 years). Compliance supports paediatric drug development programmes per US Pediatric Research Equity Act (PREA) and EU Paediatric Regulation 1901/2006.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_pediatric_reg",
        "us_prea",
        "us_bpca",
        "ich_e6",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-e2e-pharmacovigilance-planning-2004",
    "title": "ICH E2E - Pharmacovigilance Planning: Safety Specification and Pharmacovigilance Plan (2004)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2004-11-18",
    "bluf": "ICH E2E (Step 4, November 2004) requires a Safety Specification and Pharmacovigilance Plan to be submitted with marketing authorisation applications, defining important potential risks, missing safety information, and the proactive and routine pharmacovigilance activities planned to characterise and minimise those risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "nist_csf",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ema-gvp-module-v-risk-management-systems-2014",
      "fda-21-cfr-part-312-ind-investigational-new-drug"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-e6-r3-gcp-2026",
    "title": "ICH E6(R3) Good Clinical Practice Guideline (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "ICH E6(R3) provides the international ethical and scientific quality standard for designing, conducting, recording, and reporting clinical trials involving human participants. It emphasises quality-by-design, risk-based monitoring, proportionality, data governance, decentralised trial designs, and use of technology while protecting participant rights, safety, and well-being. Adopted January 2025 and effective in most ICH regions from early 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-e6-r3-good-clinical-practice-2023",
    "title": "ICH Harmonised Guideline Good Clinical Practice (GCP) E6(R3)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-11-15",
    "bluf": "This guideline establishes unified standards for clinical trials to protect human subjects and ensure data integrity, applying to sponsors, investigators, and institutions. It mandates a quality-by-design and risk-proportionate approach to trial conduct, as outlined in the Principles section (e.g., Principle 1.1) and Annex 1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ich-e6-r3-good-clinical-practice-pharma-2023",
    "title": "ICH E6(R3) Good Clinical Practice Revision 2023 - Risk-Proportionate Approaches, Decentralised Trials, Remote Monitoring and Data Integrity Standards",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires sponsors to implement risk-proportionate approaches to clinical trials, as outlined in Article 1.61, and to ensure data integrity, as specified in Article 1.62. It applies to all clinical trials conducted in the pharmaceutical industry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ich-e8-r1-general-considerations-clinical-2021",
    "title": "ICH E8(R1) General Considerations for Clinical Studies",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-10-06",
    "bluf": "This guideline requires sponsors of clinical studies to proactively build quality into study design and conduct using a risk-based approach, focusing on factors critical to ensuring patient safety and the reliability of trial results. Per Section 3, this involves prospectively identifying 'critical to quality' factors and managing risks to them throughout the study lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice",
      "eu-mdr-2017-745"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-e8-r1-general-considerations-clinical-studies-2021",
    "title": "ICH E8(R1) - General Considerations for Clinical Studies 2021: Quality, Risk-Based Approaches and Fit-for-Purpose Clinical Study Design",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires that clinical studies be designed to ensure the quality, safety, and efficacy of investigational products, as outlined in Article 1 of the ICH E8(R1) guideline, and applies to all clinical studies conducted to support regulatory submissions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "ich-e9-r1-estimands-sensitivity-analysis-2019",
    "title": "ICH E9(R1) Addendum on Estimands and Sensitivity Analysis in Clinical Trials to the Guideline on Statistical Principles for Clinical Trials",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This addendum requires clinical trial sponsors to precisely define the 'estimand' (the treatment effect to be estimated) using a structured framework and conduct sensitivity analyses to assess the robustness of results. This framework, detailed in Section A.3, applies to all clinical trials intended for regulatory submission to ensure alignment between trial objectives, design, conduct, and analysis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-e9-r1-estimands-sensitivity-analysis-pharma-2019",
    "title": "ICH E9(R1) - Addendum on Estimands and Sensitivity Analysis in Clinical Trials: Estimand Framework, Intercurrent Events and Missing Data Strategies",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires sponsors of clinical trials to identify and justify the estimand of interest, as stated in Section 1.1, and to conduct sensitivity analyses to assess the robustness of the results, as outlined in Section 4.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-gcp-e6-r3-2023"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "ich-gcp-e6-r3-2023",
    "title": "ICH Harmonised Guideline Good Clinical Practice (GCP) E6(R3)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This guideline provides a unified standard for the European Union, Japan, USA, and other regions on the conduct of clinical trials, emphasizing a quality-by-design and risk-based approach to protect human subjects and ensure the integrity of trial data. It applies to sponsors, investigators, and ethics committees involved in clinical research of pharmaceutical products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-clinical-practice",
      "fda-21-cfr-part-11-records",
      "eu-clinical-trials-regulation-2022",
      "gdpr-health-data",
      "hipaa-security-rule"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-m12-drug-interaction-studies-2023",
    "title": "ICH M12 - Drug Interaction Studies: In Vitro and In Vivo Assessment, Clinical Pharmacokinetic Studies and Product Labelling Recommendations",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires sponsors to conduct in vitro and in vivo drug interaction studies, as outlined in Article 3, and to include the results in the product labeling, as stated in Article 7, to ensure the safe and effective use of drugs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-m3-r2-nonclinical-safety-studies",
    "title": "ICH M3(R2): Nonclinical Safety Studies for the Conduct of Human Clinical Trials and Marketing Authorization for Pharmaceuticals",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "ICH M3(R2) sets the framework for nonclinical safety studies required to support human clinical trials and marketing authorisation. The guideline addresses general toxicology, safety pharmacology, genotoxicity, carcinogenicity, reproductive and developmental toxicity, juvenile toxicity, and immunotoxicity, with timing aligned to clinical trial phases. Specific provisions cover microdosing, exploratory clinical trials, and biopharmaceutical exemptions per ICH S6. Compliance is foundational to every IND, CTA, and NDA submission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ich_s6",
        "ich_s7",
        "ich_s2",
        "ich_s1",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-m4-common-technical-document-2002",
    "title": "ICH M4 - Common Technical Document (CTD): 5-Module Structure for Global Regulatory Submissions (2002)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2016-11-01",
    "bluf": "ICH M4 (Step 4, 2001-2004) defines the 5-module Common Technical Document format - the universal standard for marketing authorisation applications in EU, US, Japan, Canada, and all ICH Member jurisdictions - covering administrative data (Module 1), quality summaries (Module 2), quality/CMC (Module 3), non-clinical reports (Module 4), and clinical study reports (Module 5), implemented as eCTD electronic submission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "nist_csf",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-q14-analytical-procedure-development-2023",
      "ich-e6-r3-good-clinical-practice-pharma-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-m7-r1-mutagenic-impurities-2017",
    "title": "Assessment and Control of DNA Reactive (Mutagenic) Impurities in Pharmaceuticals to Limit Potential Carcinogenic Risk",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires pharmaceutical manufacturers to assess and control DNA reactive (mutagenic) impurities in their products, as outlined in Section 1 of the ICH M7(R1) guideline, to limit potential carcinogenic risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-gcp-e6-r3-2023",
      "iso-13485-qms"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ich-q10-pharmaceutical-quality-system",
    "title": "ICH Q10 Pharmaceutical Quality System - Design, Development, Manufacturing and Discontinuation: Quality System Elements and Enablers",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires pharmaceutical manufacturers to establish a quality system that includes design, development, manufacturing, and discontinuation, as outlined in Clause 1.1. It applies to all pharmaceutical companies, as stated in Clause 1.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "ich-q10-pharmaceutical-quality-system-2008",
    "title": "ICH Q10 Pharmaceutical Quality System",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This guideline provides a model for a pharmaceutical quality system (PQS) that applies throughout the product lifecycle, complementing regional GMPs by enhancing product quality and availability. It requires companies to establish and maintain a PQS with key elements including management responsibility, continual improvement processes, and management of outsourced activities, as outlined in Section 1.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ich-q10-pharmaceutical-quality-system-lifecycle-management",
    "title": "ICH Q10 Pharmaceutical Quality System - Product Lifecycle Management",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2023-06-01",
    "bluf": "ICH Q10 describes a comprehensive pharmaceutical quality system (PQS) model covering the entire product lifecycle from development through discontinuation. It builds on Good Manufacturing Practice (GMP) requirements and supplements ICH Q8 and Q9, establishing four PQS elements: management responsibilities, process performance and product quality monitoring, change management, and continual improvement. The framework enables pharmaceutical companies to implement science-based quality systems that assure product quality, safety, and efficacy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-210-211-current-good-manufacturing-practice",
      "iso-9001-2015-quality-management-systems-operations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-q11-drug-substance-development-manufacture",
    "title": "ICH Q11: Development and Manufacture of Drug Substances: Design Space, Control Strategy and Manufacturing Process Development",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires drug manufacturers to establish a control strategy that includes design space, and to develop a manufacturing process that meets the requirements of ICH Q11, Article 1. According to Article 2, the control strategy should include a description of the manufacturing process and its associated risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-gcp-e6-r3-2023",
      "iso-13485-qms"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ich-q12-lifecycle-management-2019",
    "title": "ICH Q12 Technical and Regulatory Considerations for Pharmaceutical Product Lifecycle Management",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This guideline provides a framework for managing post-approval Chemistry, Manufacturing, and Controls (CMC) changes for pharmaceutical products, enabling a more predictable and efficient regulatory process. It introduces tools like Established Conditions (ECs), Post-Approval Change Management Protocols (PACMPs), and the Product Lifecycle Management (PLCM) document to facilitate risk-based regulatory oversight, as detailed in Chapter 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-q12-pharmaceutical-product-lifecycle-management",
    "title": "ICH Q12: Technical and Regulatory Considerations for Pharmaceutical Product Lifecycle Management: Established Conditions and Post-Approval Changes",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "ICH Q12 requires pharmaceutical manufacturers to establish and maintain a pharmaceutical quality system, as outlined in Article 1 of the guideline, and to implement post-approval changes in accordance with Article 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-q13-continuous-manufacturing-2022",
    "title": "ICH Q13 - Continuous Manufacturing of Drug Substances and Drug Products: Regulatory Expectations, Control Strategy and Real-Time Release Testing",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "ICH Q13 requires pharmaceutical manufacturers to implement a control strategy for continuous manufacturing, as outlined in Section 3, and to conduct real-time release testing, as specified in Section 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-q14-analytical-procedure-development-2023",
    "title": "ICH Q14 - Analytical Procedure Development and Lifecycle Management (2023)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2023-11-07",
    "bluf": "ICH Q14 (Step 4, November 2023) establishes a science- and risk-based framework for analytical procedure development, defining Analytical Target Profiles (ATP) and Analytical Procedure Performance Indicators (APPIs) to support enhanced lifecycle management under ICH Q12 and validated performance under ICH Q2(R2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "nist_csf",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-q10-pharmaceutical-quality-system-2008",
      "ich-q12-lifecycle-management-2019"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-q1a-stability-testing-new-drugs-2003",
    "title": "ICH Q1A(R2) Stability Testing of New Drug Substances and Drug Products",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This guideline defines the core stability data package required for a new drug substance or drug product registration application within the ICH regions, specifying storage conditions, study durations, and data evaluation to establish a re-test period or shelf life. It applies to pharmaceutical manufacturers submitting New Drug Applications (NDAs) or Marketing Authorisation Applications (MAAs), as detailed in Section 2.1 General Principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-q2-r2-validation-analytical-procedures-2022",
    "title": "ICH Q2(R2) - Validation of Analytical Procedures: Methodology and Acceptance Criteria (2022)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2022-11-16",
    "bluf": "ICH Q2(R2) (Step 4, November 2022) updates the 1994 Q2(R1) validation guideline by integrating life sciences analytical techniques (biological assays, spectroscopic methods, multivariate analysis), defining validation performance parameters with numerical acceptance criteria, and aligning validation strategy with ICH Q14 Analytical Target Profile principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "nist_csf",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-q14-analytical-procedure-development-2023",
      "ich-q10-pharmaceutical-quality-system-2008"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-q3a-r2-impurities-new-drug-substances",
    "title": "ICH Q3A(R2): Impurities in New Drug Substances",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "ICH Q3A(R2) sets reporting, identification, and qualification thresholds for organic impurities in new drug substances based on maximum daily dose. The guideline applies to chemically synthesised new drug substances and covers impurities arising from the synthesis process, intermediates, or degradation. It excludes biotechnology, peptides, oligonucleotides, and fermentation products (covered by Q6B/Q11). Thresholds are 0.05 percent for reporting at doses ≤2g/day, with proportionally lower thresholds at higher doses. Qualification requires safety data establishing biological safety at the proposed level. Compliance is foundational to ICH region marketing applications including EU CTD Module 3, FDA NDA, and PMDA application.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ph_eur",
        "us_fda",
        "ich_q3b",
        "ich_q3c",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-q3b-r2-impurities-new-drug-products",
    "title": "ICH Q3B(R2): Impurities in New Drug Products",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "ICH Q3B(R2) sets thresholds for degradation products in new drug products based on maximum daily dose. The guideline addresses impurities arising during manufacture, storage, or stability testing of the drug product but excludes impurities already present in the drug substance (covered by Q3A). Reporting, identification, and qualification thresholds are dose-dependent. Compliance is foundational to ICH region marketing applications and to stability protocol design.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ich_q3a",
        "ich_q1a",
        "ich_q1b",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-q4b-pharmacopoeial-texts",
    "title": "ICH Q4B: Evaluation and Recommendation of Pharmacopoeial Texts for Use in the ICH Regions",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "ICH Q4B provides a framework for evaluating Ph. Eur., USP, and JP pharmacopoeial general chapters to determine interchangeability across ICH regions, reducing duplicative testing. Annex 1 through Annex 16 cover specific topics (residue on ignition, particulate contamination, microbial limits, etc.). Interchangeability declarations are accepted by EU, FDA, PMDA, and Health Canada. Compliance reduces regulatory complexity for global drug development by allowing use of any approved compendial method.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ph_eur",
        "usp_nf",
        "jp",
        "ich_q6",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-q5a-r2-viral-safety-biotech-2024",
    "title": "ICH Q5A(R2) Viral Safety Evaluation of Biotechnology-Derived Products 2024 - Viral Clearance Studies, Testing Strategy and Risk Assessment Framework",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires manufacturers of biotechnology-derived products to conduct viral clearance studies using validated methods to demonstrate removal or inactivation of potential viral contaminants, particularly for products derived from human or animal cell lines. Key requirements are specified in ICH Q5A(R2), Section 3.2 on viral clearance validation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-qms",
      "ich-gcp-e6-r3-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-q5d-cell-substrates-biological-products",
    "title": "ICH Q5D - Derivation and Characterisation of Cell Substrates for Biological Products",
    "domain": "Biotech & Genomics",
    "version": "Q5D (1998, current)",
    "last_updated": "2026-05-09",
    "bluf": "ICH Q5D (adopted by ICH Step 4 in November 1997, implemented globally in 1998) establishes the international standard for derivation, characterisation, and ongoing management of cell substrates (Master Cell Banks and Working Cell Banks) used in the production of biotechnological and biological products; it defines cell bank testing requirements - including sterility, mycoplasma, adventitious viruses, identity authentication, and passage limit validation - and is cross-referenced in ICH Q5A (viral safety), Q5E (comparability), and US FDA/EMA biologics licensing requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-q5a-r2-viral-safety-biotech-2024",
      "fda-guidance-human-gene-therapy-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-q5e-comparability-biotech-products",
    "title": "ICH Q5E: Comparability of Biotechnological/Biological Products Subject to Changes in their Manufacturing Process",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "ICH Q5E sets the framework for demonstrating that a biotech or biological product remains the same when its manufacturing process changes. The guideline applies to facility moves, cell line changes, fermentation scale-up, purification process changes, and formulation changes. Comparability is established by direct physicochemical and biological characterisation; nonclinical and clinical bridging studies are required only where analytical comparability is insufficient. Compliance enables manufacturing process improvements without full re-development.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ich_q5c",
        "ich_q6b",
        "ich_q11",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-q7-gmp-active-pharmaceutical-ingredients-2000",
    "title": "ICH Q7 Good Manufacturing Practice Guide for Active Pharmaceutical Ingredients",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-11-10",
    "bluf": "This guide provides Good Manufacturing Practice (GMP) principles for manufacturing Active Pharmaceutical Ingredients (APIs), requiring a comprehensive quality management system to ensure APIs meet purity and quality standards. It applies to all manufacturers of APIs for human drug products, with the core requirement being the establishment of an independent Quality Unit as mandated by Section 2.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ich-q8-r2-pharmaceutical-development-2009",
    "title": "ICH Harmonised Tripartite Guideline Q8(R2) Pharmaceutical Development",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This guideline requires pharmaceutical manufacturers to implement a systematic, science- and risk-based approach to product development, known as Quality by Design (QbD). This involves defining a Quality Target Product Profile (QTPP) and identifying Critical Quality Attributes (CQAs) to ensure the final product meets its intended quality, safety, and efficacy, as detailed in Section 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-q9-r1-quality-risk-management-2023",
    "title": "ICH Harmonised Guideline Q9(R1) Quality Risk Management",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This guideline requires pharmaceutical manufacturers to implement a systematic, science-based Quality Risk Management (QRM) process throughout the product lifecycle to ensure patient safety and product quality. As mandated by Section 3, QRM principles must be integrated into existing quality systems to support risk-based decision-making.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-q9-r1-quality-risk-management-pharma-2023",
    "title": "ICH Q9(R1) Quality Risk Management",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ICH Q9(R1) requires pharmaceutical manufacturers to implement a quality risk management system, as outlined in Section 1.1, to ensure the quality of their products. This applies to all pharmaceutical companies, as stated in Article 1 of the ICH Q9(R1) guideline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-q9-r1-quality-risk-management-pharmaceutical",
    "title": "ICH Q9(R1) Quality Risk Management - Risk Assessment, Risk Control and Risk Communication in Pharmaceutical Manufacturing",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "ICH Q9(R1) Quality Risk Management is the revised version of the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use (ICH) Q9 guideline, reached Step 4 of the ICH process on 18 January 2023 and entered into force on 26 July 2023 in the EU (EMA/CHMP/ICH/24235/2006 R1), 30 May 2023 in Japan, and similar timeline in US FDA. ICH Q9(R1) provides a systematic approach to Quality Risk Management (QRM) applicable to the pharmaceutical lifecycle including pharmaceutical development, manufacturing, distribution, inspection, and submission/review processes. The Guideline articulates two primary principles: (1) the evaluation of the risk to quality should be based on scientific knowledge and ultimately link to the protection of the patient; and (2) the level of effort, formality and documentation of the QRM process should be commensurate with the level of risk. The QRM process is structured as: Risk Assessment (identification, analysis, evaluation), Risk Control (reduction, acceptance), Risk Communication, and Risk Review. The R1 revision strengthens guidance on (a) high levels of subjectivity in risk assessments, (b) management of supply chain risks, (c) ensuring availability of medicinal products, and (d) formality in QRM activities scaled to risk level. Common QRM tools include FMEA (Failure Mode and Effects Analysis), HACCP (Hazard Analysis and Critical Control Points), and FTA (Fault Tree Analysis).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-q10-pharmaceutical-quality-system",
      "us-fda-21-cfr-211-cgmp-finished-pharmaceuticals"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ich-s10-photosafety-evaluation-pharmaceuticals-2013",
    "title": "ICH S10: Photosafety Evaluation of Pharmaceuticals",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2013-11-13",
    "bluf": "ICH S10 provides a tiered approach to photosafety assessment for pharmaceuticals: starting with photochemical characterisation (molar absorption coefficient, quantum yield, photodegradation), proceeding to the 3T3 NRU phototoxicity in vitro assay, and requiring in vivo photoallergy or photocarcinogenicity studies when clinical exposure and photochemical risk triggers exceed defined thresholds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-s7a-safety-pharmacology-human-pharmaceuticals-2001",
      "ich-s8-immunotoxicity-studies-human-medicines-2005",
      "ich-s6-r1-preclinical-safety-biotech-pharmaceuticals-2011",
      "eu-atmp-regulation-1394-2007"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-s12-nonclinical-biodistribution-gene-therapy-2023",
    "title": "ICH S12 - Nonclinical Biodistribution Considerations for Gene Therapy Products (2023)",
    "domain": "Biotech & Genomics",
    "version": "2023-09",
    "last_updated": "2026-05-09",
    "bluf": "ICH Guideline S12 (finalized September 2023, Step 4) establishes the nonclinical biodistribution study design principles for gene therapy products, specifying when biodistribution studies are required, acceptable animal models and tissue sampling approaches, integration of biodistribution data with pharmacology and toxicology studies, evaluation of germline transmission risk, and the use of biodistribution data to support clinical dose selection and patient monitoring; S12 applies to all gene therapy products including viral vectors, non-viral delivery systems, ex vivo gene-modified cell therapies, and gene editing approaches when submitted to ICH member regulatory agencies (FDA, EMA, PMDA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-guidance-human-gene-therapy-2020",
      "eu-atmp-regulation-1394-2007"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-s2-r1-genotoxicity-testing-data-interpretation",
    "title": "ICH S2(R1): Genotoxicity Testing and Data Interpretation for Pharmaceuticals Intended for Human Use",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "ICH S2(R1) defines the standard battery of genotoxicity tests for pharmaceuticals intended for human use, supporting first-in-human trials and marketing applications. The R1 revision rationalised the testing strategy from previous separate ICH S2A and S2B guidelines into a unified framework. The standard battery consists of: (1) a test for gene mutation in bacteria (Ames test, OECD TG 471); (2) an in vivo assessment of genotoxicity in rodents (e.g. micronucleus or comet assay, OECD TG 474 or 489); plus either (3a) an in vitro mammalian cell test for chromosomal damage or (3b) integration of the in vivo assay with general toxicology. Compliance is foundational to safety evaluation and feeds into ICH M7 mutagenic impurity assessment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ich_s2a",
        "ich_s2b",
        "ich_m7",
        "oecd_tg",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-s5-r3-reproductive-developmental-toxicity-2020",
    "title": "ICH S5(R3): Detection of Reproductive and Developmental Toxicity for Human Pharmaceuticals",
    "domain": "Biotech & Genomics",
    "version": "3.0.0",
    "last_updated": "2020-11-17",
    "bluf": "ICH S5(R3) mandates species-specific DART study designs for all new human pharmaceuticals, requiring fertility, embryo-fetal development, and pre/postnatal development studies, with extended one-generation reproductive toxicity studies triggered by endocrine disruption alerts or regulatory requirements aligned to OECD TG 443.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-s8-immunotoxicity-studies-human-medicines-2005",
      "ich-s9-nonclinical-anticancer-pharmaceutical-2010",
      "fda-guidance-human-gene-therapy-2020",
      "eu-atmp-regulation-1394-2007"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ich-s6-r1-preclinical-safety-biotech-pharmaceuticals-2011",
    "title": "ICH S6(R1): Preclinical Safety Evaluation of Biotechnology-Derived Pharmaceuticals",
    "domain": "Biotech & Genomics",
    "version": "1.1.0",
    "last_updated": "2011-06-12",
    "bluf": "ICH S6(R1) establishes the framework for preclinical safety assessment of biologics including monoclonal antibodies, recombinant proteins, and gene therapies, requiring pharmacologically relevant species selection, integrated immunogenicity monitoring, tissue cross-reactivity studies, and risk-based determination of carcinogenicity and genotoxicity study requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-atmp-regulation-1394-2007",
      "fda-guidance-human-gene-therapy-2020",
      "ich-s12-nonclinical-biodistribution-gene-therapy-2023",
      "ich-s8-immunotoxicity-studies-human-medicines-2005"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ich-s7a-safety-pharmacology-human-pharmaceuticals-2001",
    "title": "ICH S7A: Safety Pharmacology Studies for Human Pharmaceuticals",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2001-11-08",
    "bluf": "ICH S7A mandates a core safety pharmacology battery assessing cardiovascular (hERG, telemetry), CNS (Irwin/FOB), and respiratory function for all new pharmaceutical candidates before first human dosing, with follow-up studies required when signals are detected or when the drug mechanism raises concern for any vital organ system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-s8-immunotoxicity-studies-human-medicines-2005",
      "ich-s6-r1-preclinical-safety-biotech-pharmaceuticals-2011",
      "ich-s5-r3-reproductive-developmental-toxicity-2020",
      "fda-guidance-human-gene-therapy-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ich-s8-immunotoxicity-studies-human-medicines-2005",
    "title": "ICH S8 - Immunotoxicity Studies for Human Pharmaceuticals: Non-Clinical Safety Assessment Guideline",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "ICH S8 (November 2005, adopted by EMA, FDA, PMDA) provides guidance for non-clinical evaluation of immunotoxic potential of new human pharmaceuticals using a tiered testing approach; the standard battery of toxicology studies (ICH S1-S7 series) often captures immunotoxic signals but ICH S8 defines when additional immunotoxicity studies are required based on weight of evidence from standard studies, structural alerts, and mechanistic concerns; key studies addressed include TDAR (T-cell Dependent Antibody Response), NK cell activity, lymphocyte subset analysis, host resistance studies, and macrophage/neutrophil function assays; directly applicable to small molecules, biologics, and gene therapy products requiring regulatory-grade immunotoxicity characterisation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ema-centralised-procedure-regulation-726-2004",
      "ich-q10-pharmaceutical-quality-system-2008"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ich-s9-nonclinical-anticancer-pharmaceutical-2010",
    "title": "ICH S9 - Nonclinical Evaluation for Anticancer Pharmaceuticals: Timing of Studies, General Toxicology, Genotoxicity and Reproductive Toxicology",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires that nonclinical studies for anticancer pharmaceuticals be conducted in accordance with ICH S9, specifically Section 3, to ensure the safety and efficacy of these products. It applies to pharmaceutical companies developing anticancer treatments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-gcp-e6-r3-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ich-s9-nonclinical-evaluation-anticancer-2009",
    "title": "ICH S9 Nonclinical Evaluation for Anticancer Pharmaceuticals",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This guideline provides recommendations on the necessary nonclinical studies to support the development of anticancer pharmaceuticals in patients with advanced disease and limited therapeutic options. It outlines a streamlined approach, including potential waivers for certain safety pharmacology and reproductive toxicology studies, based on the unique risk-benefit considerations for this patient population as described in Section 1.3 (General Principles).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "icma-green-bond",
    "title": "Green Bond Principles (ICMA)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with the International Capital Market Association's Green Bond Principles mandates a rigorous framework for ensuring transparency and integrity in the green bond market. Issuers must demonstrate that `require_eligible_green_project_mapping` is satisfied, with `environmental_objectives_documented` clearly and specifically, often utilizing the ICMA Guidance Handbook for mapping to Sustainable Development Goals. A `project_evaluation_process_formalized` within the issuer's operations is critical, under which `esg_risk_mitigation_assessed` for nominated projects must be conducted. The management of proceeds demands that funds are `proceeds_tracked_via_dedicated_sub_account` or managed via an equivalent formal internal process, and any `unallocated_proceeds_strategy_disclosed` transparently to investors. Post-issuance, `annual_allocation_reporting_required` must occur at a minimum `reporting_frequency_months` of twelve, supplemented by disclosures on `material_developments_ad_hoc_reporting` when necessary. This reporting should include `impact_reporting_metrics_defined` as recommended by the Harmonised Framework for Impact Reporting. To bolster credibility, the voluntary guidelines strongly recommend that a `pre_issuance_external_review_obtained` from an independent party, followed by a `post_issuance_allocation_verification_required` to confirm the use of funds. These practices, detailed in the Guidelines for External Reviews, align with stricter frameworks such as the Climate Bonds Standard Version 4.0 and form the foundational architecture for mandatory regimes like the European Union's Regulation 2023/2631 on European Green Bonds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-taxonomy-sustainable",
      "un-sdg-alignment",
      "tcfd-climate-risk",
      "csrd-eu-sustainability",
      "ifrs-s2-climate",
      "iso-14001-ems"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "icmm-mining-principles-2020",
    "title": "International Council on Mining and Metals (ICMM) Mining Principles 2020 - Position Statements on Environment, People and Ethics for Member Companies",
    "domain": "Mining & Natural Resources",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The ICMM Mining Principles 2020 comprise 10 Principles supported by 38 Performance Expectations across environment, social responsibility, and ethical governance, with mandatory adherence to Principle 1 on ethical business (including anti-corruption), Principle 3 on human rights, and Principle 10 on stakeholder engagement. Tailings management is addressed by ICMM Performance Expectations and the Global Industry Standard on Tailings Management (GISTM), not by a numbered Principle. Applies to all ICMM member companies operating globally.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-26000-social-resp",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "icn-merger-guidelines-framework",
    "title": "ICN Merger Working Group - Recommended Practices for Merger Notification and Review: Notification Triggers, Timing, Substantive Test, Remedies and Coordination Between Jurisdictions",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This framework outlines recommended practices for merger notification and review procedures to enhance effectiveness, promote procedural convergence, and reduce costs in multijurisdictional reviews. It applies to competition authorities engaged in merger review and references the ICN Recommended Practices for Merger Notification and Review Procedures and Framework for Merger Review Cooperation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icn-recommended-practices-merger-notification-2023",
      "uk-cma-merger-assessment-guidelines-2021",
      "australia-accc-merger-review-guidelines-2023",
      "canada-competition-act-2024-amendment-abuse-dominance",
      "eu-state-aid-articles-107-108-tfeu-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "icn-recommended-practices-merger-notification-2023",
    "title": "ICN Recommended Practices for Merger Notification and Review 2023 - Jurisdictional Triggers, Pre-Notification Contacts and Procedure Convergence",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This guidance establishes best practices for merger notification and review processes across jurisdictions, focusing on jurisdictional thresholds, pre-notification consultations, procedural transparency, and convergence in review timelines. It applies to competition authorities and merging parties engaging in cross-border transactions, with key provisions outlined in Sections II-IV covering jurisdictional triggers, pre-filing engagement, and procedural harmonization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-doj-ftc-merger-guidelines-2023",
      "eu-merger-regulation-139-2004-ecmr"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "icp-19-conduct-business-insurance-iais",
    "title": "IAIS Insurance Core Principle 19: Conduct of Business - Disclosure, Complaints, Anti-Mis-Selling and Claims Settlement",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This principle requires insurance supervisors to establish standards for insurers and intermediaries to treat customers fairly before, during, and after the point of sale. As per ICP 19.1, this includes providing clear information, managing conflicts of interest, handling complaints and claims effectively, and protecting customer data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "uk-fca-consumer-duty-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "icpc-recommendations-submarine-cable-protection",
    "title": "ICPC Recommendations - International Cable Protection Committee Best Practices: Submarine Cable Route Planning, Burial Depth Guidelines, Fishermen Liaison Programs, Cable Fault Repair Procedures, and National Legislation grounded in UNCLOS Articles 113-115",
    "domain": "Maritime & Shipping",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "This regulation outlines best practices for the protection of submarine telecommunications and power cables through route planning, burial depth, stakeholder engagement, and repair protocols. It applies to cable operators, maritime authorities, fishing industries, and coastal states, with key guidance derived from ICPC publications and collaborations with UNEP-WCMC and CIL, particularly the 2025 report on submarine cables and marine biodiversity and the 2024 ICPC-CIL Workshop Report.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unclos-part-ii-territorial-sea-contiguous-zone",
      "itu-radio-regulations-2020-edition"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "icpr-rhine-protection-convention-1999",
    "title": "ICPR Bern Convention 1999 - International Commission for the Protection of the Rhine, Rhine 2040 Programme and Sustainable Development",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Convention on the Protection of the Rhine, signed at Bern on 12 April 1999 and entered into force on 1 January 2003, is the foundational treaty governing transboundary cooperation on the Rhine River basin among the five riparian states: France, Germany, Luxembourg, the Netherlands, and Switzerland, together with the European Union as a Contracting Party. The 1999 Convention replaces the 1976 Bern Convention on the Protection of the Rhine against Chemical Pollution and the 1963 Bern Convention establishing the International Commission for the Protection of the Rhine (ICPR/IKSR). The Convention contains 19 articles and adopts an integrated approach including ecology, water quality, flood protection, sediment management, and groundwater. The ICPR is the principal coordination body, with its Secretariat in Koblenz, Germany; the Commission adopts decisions by consensus. The current strategic framework is the Rhine 2040 Programme adopted by the 16th Rhine Ministerial Conference in February 2020, replacing the Rhine 2020 Programme. Key priorities include: continuation of climate adaptation; further reduction of micropollutants (pharmaceuticals, biocides, plant protection products) by at least 30% by 2040; restoration of fish migration with reopening of Rhine to Salmon Stretch up to Basel; restoration of natural floodplain functions; and improved coordination with the Water Framework Directive 2000/60/EC and Floods Directive 2007/60/EC. The 1999 Convention coexists with EU obligations through the Rhine International River Basin District established under WFD international river basin district provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-water-framework-directive-2000-60-ec"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "icsid-convention-1965-investment-disputes",
    "title": "ICSID Convention 1965 - Settlement of Investment Disputes",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-25",
    "bluf": "The ICSID Convention establishes the International Centre for Settlement of Investment Disputes under World Bank auspices, providing the primary international arbitration framework for investor-state disputes. 164 Contracting States are bound to recognise and enforce ICSID awards as final court judgments under Article 54, bypassing the New York Convention. Jurisdiction requires written consent, an investment, and a cross-border party (Article 25). Article 52 annulment on five grounds only; Article 53 awards are final and not subject to appeal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "new-york-convention-1958-foreign-arbitral-awards",
      "trips-agreement-wto-copyright-patents-ip-1994",
      "un-convention-against-corruption-uncac-2003"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "id-bpom-drug-registration-regulations-badan-pengawas-obat-makanan",
    "title": "Indonesia BPOM Drug Registration Regulations Badan Pengawas Obat dan Makanan Marketing Authorisation GMP Pharmacovigilance and Halal Certification Framework",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "The Indonesia Badan Pengawas Obat dan Makanan (BPOM) National Agency of Drug and Food Control administered under Presidential Regulation No. 80 of 2017 (as amended) establishes the comprehensive pharmaceutical regulation framework organised through BPOM Regulations including BPOM Regulation No. 24 of 2017 on Criteria and Procedures for Drug Registration BPOM Regulation No. 26 of 2018 on Online Drug Registration BPOM Regulation No. 34 of 2018 on Good Manufacturing Practices BPOM Regulation No. 13 of 2019 on Distribution of Drugs and BPOM Regulation No. 27 of 2018 on Pharmacovigilance organised across operative chapters covering Chapter 1 General Provisions Chapter 2 Pre-Registration including pre-submission consultation Chapter 3 Drug Registration covering New Drug Registration Variation Registration and Renewal Registration with mandatory Common Technical Document format submission Chapter 4 Good Manufacturing Practices Chapter 5 Pharmacovigilance Chapter 6 Distribution and Logistics including Marketing Authorisation Holder requirements and local representation Chapter 7 Pricing for Essential Medicines Chapter 8 Inspection and Surveillance and Chapter 9 Sanctions including administrative sanctions warning suspension and revocation. Integrated with the National Halal Product Assurance Agency (BPJPH) for halal certification of medicines under Law No. 33 of 2014 effective October 2024 for over-the-counter products with phased implementation for prescription drugs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "id-ite-law-amendment-2024",
    "title": "Indonesia Electronic Information and Transactions Law Amendment 2024 (UU ITE Amendment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Indonesia's Law No. 1 of 2024 amending Law No. 11 of 2008 on Electronic Information and Transactions (UU ITE) signed January 2, 2024 revises provisions on online defamation and hate speech, strengthens data protection for electronic systems, expands the scope of prohibited content including electronic access to illegal gambling and CSAM, and strengthens Kominfo's authority over electronic system providers operating in Indonesia including mandatory registration and content moderation obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/id-ite-law-amendment-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "id-pdp-law-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "id-pdp-law-2022",
    "title": "Indonesia Personal Data Protection Law (UU PDP) No. 27 of 2022",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Indonesia's Personal Data Protection (PDP) Law establishes a comprehensive framework for processing the personal data of Indonesian subjects, applicable to entities both within and outside Indonesia. It mandates obtaining explicit consent for data processing (Article 20), defines data subject rights, and requires data controllers to conduct data protection impact assessments (Article 34) for high-risk processing activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "id-perpres-16-2018-government-procurement-lkpp-lpse",
    "title": "Indonesia Presidential Regulation No. 16 of 2018 on Government Procurement of Goods and Services (as amended by Presidential Regulation No. 12 of 2021) + LKPP and LPSE",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "Presidential Regulation (Peraturan Presiden / Perpres) No. 16 of 2018 on Government Procurement of Goods/Services (Pengadaan Barang/Jasa Pemerintah) is the principal Indonesian instrument governing procurement by central government ministries, agencies, regional governments, and certain state-owned enterprises that procure with State Budget (APBN) or Regional Budget (APBD) funding. Perpres 16/2018 was substantially amended by Presidential Regulation No. 12 of 2021 introducing reforms on local product preferences, MSME participation strengthening, sustainable procurement, and electronic procurement consolidation. The framework is administered by the Lembaga Kebijakan Pengadaan Barang/Jasa Pemerintah (LKPP - National Public Procurement Agency) at lkpp.go.id which sets policy, develops standard procurement documents, certifies procurement personnel, and operates the centralised supplier registry. Operationally, procurement is conducted through the Layanan Pengadaan Secara Elektronik (LPSE) system - the electronic procurement platform deployed at the national level and replicated at agency, ministry, and regional government levels with shared core infrastructure. Procurement methods specified in Perpres 16/2018 include Tender (open competitive tender, default for at-threshold or above procurements), Tender Cepat (rapid tender for standardised products through e-catalogue), Seleksi (open competitive selection for consulting services), Penunjukan Langsung (direct appointment, sole-source under prescribed exceptions), Pengadaan Langsung (direct procurement for low-value acquisitions), and E-Purchasing through the e-catalogue managed by LKPP. The framework operationalises Indonesia's commitments under multiple supporting regimes including the Undang-Undang No. 28 Tahun 1999 on Clean and Free of Corruption Practices state governance baseline, the Undang-Undang No. 11 Tahun 2008 on Electronic Information and Transactions (UU ITE) for electronic procurement signature validity, the Undang-Undang Perlindungan Data Pribadi (PDP Law) No. 27 of 2022 for supplier personal data, the various free trade agreement government procurement provisions (Regional Comprehensive Economic Partnership / RCEP, ASEAN Trade in Services Agreement, Indonesia-Australia CEPA), and the Sustainable Public Procurement Framework supporting Indonesia's SDG commitments. LKPP has consistently prioritised the Indonesia Bangkit (Indonesia Rises) digital transformation including AI-assisted bid screening, supplier risk analysis, and catalogue normalisation on the consolidated e-procurement platform.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "identity-and-access-management-electric-utilities",
    "title": "Identity and Access Management for Electric Utilities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2018-07-01",
    "bluf": "The National Cybersecurity Center of Excellence (NCCoE) developed this example solution for electric utilities to more securely and efficiently manage access to the networked devices and facilities on which power generation, transmission, and distribution depend. The guidance is informed by best practices from standards organizations, including the North American Electric Reliability Corporation’s (NERC’s) Critical Infrastructure Protection (CIP) Version 5 standards. As the electric power industry increases operational technology (OT) and information technology (IT) convergence, it challenges departments to efficiently manage identities and access. Many utilities run fragmented Identity and Access Management (IdAM) systems, leading to a lack of traceability, increased risk of attack, and an inability to identify problem sources.\n\nThis NIST Cybersecurity Practice Guide demonstrates how to implement a converged IdAM platform using multiple commercially available products. The goal is to provide a comprehensive view of all users within the electric utility, across all silos (OT, IT, and physical access), and of the access rights that they have been granted. The core objective is to provide the right person with the right degree of access to the right resources at the right time. This allows for rapid provisioning and de-provisioning of access from a converged platform, reducing the risk of malicious or untrained people gaining unauthorized access to critical infrastructure components.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nerc-cip-v6-cyber",
      "nist-sp-800-82r3-ot-security",
      "nist-sp-800-63b-authentication",
      "cyber-nist-800-53-ac2",
      "nist-sp-800-53-r5",
      "cis-ai-least-privilege"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ie-cja-2010-aml-ctf",
    "title": "Criminal Justice (Money Laundering and Terrorist Financing) Act 2010",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-18",
    "bluf": "The Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 (No. 6 of 2010) is Ireland's principal AML/CFT statute. It requires designated persons to apply customer due diligence (Section 33), enhanced measures including for politically exposed persons (Section 37), to report suspicious transactions (Section 42), keep records (Section 55), and maintain internal policies, procedures and training (Section 54), under the supervision of competent authorities (Sections 60-63).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ie-coimisiun-na-mean-online-safety-code-2024",
    "title": "Ireland Coimisiún na Meán Online Safety Code (October 2024) - Part A General Obligations and Part B Specific Obligations for Designated Video-Sharing Platform Services; Section 12.10 Effective Age Assurance for Adult-Only Video Content; Section 14 Parental Controls; Section 15 Terms and Conditions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "The Coimisiún na Meán Online Safety Code (the Code) is the statutory online safety code made by Coimisiún na Meán (Ireland's audiovisual and online media regulator, the Commission) under Section 139K of the Broadcasting Act 2009 as amended by the Online Safety and Media Regulation Act 2022 (the Act). The Code was published in October 2024 with Part A and Part B obligations and gives effect in Ireland to Article 28b of the Audiovisual Media Services Directive (2010/13/EU as amended by Directive 2018/1808). The Code applies to designated video-sharing platform services under the State's jurisdiction within the meaning of Section 2B of the Act - a list of designated services published by the Commission. Part A sets the legislative and regulatory context and the general obligations of VSP service providers (Sections 1 to 10). Part B sets specific obligations covering definitions (Section 11), specific obligations of VSP service providers (Section 12 including 12.10 effective age assurance for adult-only video content and 12.11 content rating), audiovisual commercial communications (Section 13), parental controls (Section 14), terms and conditions and related obligations (Section 15), procedures for handling user reports and complaints (Sections 16 and 17). Section 12.10 explicitly states an age assurance measure based solely on self-declaration of age by users of the service shall not be an effective measure for the purposes of this section. Failure to comply with the Code is a contravention within the meaning of Section 139Q of the Act, attracting administrative financial sanctions of up to 20 million euro or 10 percent of relevant turnover (whichever is higher), and the Commission can apply for content-limitation notices, blocking, and senior accountability sanctions. The Code aligns with EU AVMSD Article 28b, EU Digital Services Act, and the UK Online Safety Act 2023 - a VSP operating in multiple jurisdictions must satisfy all applicable codes simultaneously.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "code_structure_part_a_part_b",
        "part_a_sections_1_to_10",
        "part_b_section_11_definitions",
        "part_b_section_12_specific_obligations",
        "part_b_section_13_audiovisual_commercial_communications",
        "part_b_section_14_parental_controls",
        "part_b_section_15_terms_and_conditions",
        "part_b_sections_16_17_complaints_and_user_reports",
        "age_assurance_self_declaration_explicitly_not_effective",
        "enforcement_powers_section_139q_act",
        "relationship_with_avmsd_dsa_uk_osa",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ie-online-safety-and-media-regulation-act-2022",
      "eu-avmsd-article-28a-28b-video-sharing-platform-minors-protection",
      "eu-dsa-article-28-online-protection-of-minors",
      "uk-ofcom-highly-effective-age-assurance-guidance-2025-osa-part-5",
      "payment-processing-restricted-content-visa-virp-mastercard-an-5196"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "ie-competition-act-2002",
    "title": "Ireland Competition Act 2002 (No. 14 of 2002, as amended by Competition (Amendment) Acts 2012 and 2022)",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Competition Act 2002 (No. 14 of 2002) is Ireland's principal competition statute. The Act was in force from 1 July 2002 (commencement order SI 199/2002) and has been materially amended by the Competition (Amendment) Act 2012 (criminal cartel penalties) and the Competition (Amendment) Act 2022 (transposition of EU ECN+ Directive 2019/1 including the introduction of administrative fines for the first time in Irish competition law). The Act is organised in five Parts. Part 2 contains the competition rules: s. 4 prohibits all agreements between undertakings, decisions by associations of undertakings and concerted practices which have as their object or effect the prevention, restriction or distortion of competition in trade in any goods or services in the State or in any part of the State, mirroring TFEU Article 101 including a four-condition exemption regime; s. 5 prohibits any abuse by one or more undertakings of a dominant position in trade for any goods or services in the State or in any part of the State, mirroring TFEU Article 102; ss. 6-7 establish criminal offences for breach of ss. 4 and 5; s. 8 sets penalties of up to 10 percent of turnover of the undertaking for the financial year preceding the verdict on conviction on indictment, with individuals facing up to EUR 50,000 and 10 years imprisonment for hardcore cartels; s. 14 provides for a right of action for any aggrieved party including injunction and damages. Part 3 (ss. 18-22) governs merger control with the Competition and Consumer Protection Commission (CCPC) as the notification authority; the post-2022 amendments introduced administrative fines under ss. 15F-15H of up to EUR 10 million or 10 percent of worldwide group turnover for substantive breaches imposed by the CCPC subject to High Court confirmation. Part 4 (ss. 30-44) establishes the CCPC investigative powers including dawn raids under judicial warrant. Sections 45-47 introduced by the 2022 Act provide an enhanced leniency programme.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-gwb-competition-act",
      "eu-tfeu-article-101-cartel-prohibition",
      "eu-tfeu-article-102-abuse-of-dominance"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "ie-consumer-protection-act-2007",
    "title": "Ireland Consumer Protection Act 2007 (No. 19 of 2007)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Consumer Protection Act 2007 (No. 19 of 2007) is Ireland's principal consumer protection statute transposing EU Directive 2005/29/EC on Unfair Commercial Practices (UCPD). The Act was enacted on 21 March 2007 and came into operation on 1 May 2007 by S.I. No. 178 of 2007. The Act is organised in six Parts and eight Schedules. Part 1 (ss. 1-5) contains preliminary matters including the average consumer concept in s. 2. Part 2 (ss. 6-40) originally established the National Consumer Agency (NCA), now functioning as the Competition and Consumer Protection Commission (CCPC) following the Competition and Consumer Protection Act 2014. Part 3 (ss. 41-62) contains the substantive prohibitions: s. 41 (general prohibition on unfair commercial practices), s. 43 (prohibition on misleading commercial practices regarding product, price, trader identity), s. 46 (prohibition on misleading commercial practices by omission of material information), s. 52 (general prohibition on aggressive commercial practices using harassment, coercion or undue influence), with Schedule 3 listing 32 commercial practices always deemed unfair (the blacklist). Part 4 (ss. 64-66) specifically prohibits pyramid promotional schemes. Part 5 (ss. 67-86) covers proceedings, remedies and penalties including civil fines, fixed payment notices, and on indictment imprisonment up to 2 years or fines up to EUR 150,000 plus daily defaults. Part 6 (ss. 87-102) contains miscellaneous provisions including the private right of action under s. 74.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29-2022-revision",
      "eu-consumer-rights-directive-2011-83-eu",
      "uk-cput-regulations-2008-consumer-protection-unfair-trading"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ie-data-protection-act-2018",
    "title": "Ireland Data Protection Act 2018 - GDPR National Implementation and Lead EU DPA for Big Tech",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Ireland's Data Protection Act 2018 (Acts of the Oireachtas 2018, No. 7), signed into law on 24 May 2018, is Ireland's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Ireland. The GDPR is directly applicable Irish law by virtue of Ireland's EU membership. The Data Protection Act 2018 repeals the prior Data Protection Acts 1988 and 2003 and provides national derogations, additions, and specifications for the Irish GDPR implementation. Enforcement: Data Protection Commission (DPC) is Ireland's independent data protection supervisory authority, headed by a commissioner appointed by Government. The DPC is of critical strategic importance beyond Ireland's borders because Ireland is the EU headquarters location for many of the world's largest technology companies. Under the GDPR one-stop-shop mechanism, the DPC acts as the lead supervisory authority (LSA) for cross-border personal data processing by organisations with their EU main establishment in Ireland - this includes Meta Platforms (Facebook, Instagram, WhatsApp), Google, Apple, Microsoft, LinkedIn, Twitter/X, TikTok, Airbnb, and numerous other global technology companies. Accordingly, the DPC handles major cross-border GDPR complaints from data subjects across all 27 EU member states against these companies, making it one of the most consequential data protection authorities in the world. The DPC has issued the largest GDPR fines in EU history: Meta Ireland (EUR 1.2 billion, May 2023 - for EU-US data transfers without adequate safeguards, the largest GDPR fine ever issued), Instagram/Meta (EUR 405 million, September 2022 - children's data handling), WhatsApp Ireland (EUR 225 million, September 2021 - transparency), and Meta Ireland (EUR 265 million, November 2022 - data scraping). Key Irish national provisions: (1) Age of digital consent: Ireland has maintained the GDPR default of 16 years for information society services; (2) Journalistic privilege - specific exemptions for journalistic, research, statistical, and historical processing; (3) Employment context - specific national provisions on employee data processing interacting with Irish employment law including the Workplace Relations Act 2015; (4) Public access to information - the Freedom of Information Act 2014 interacts with GDPR in the Irish public sector context; (5) Health research - the Health Research Regulations 2018 provide a specific consent-based framework for health research in Ireland. Fines: GDPR administrative fines apply - up to EUR 20 million or 4% of global annual turnover, and the DPC has demonstrated willingness to apply maximum fines to global technology companies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ie-international-protection-act-2015",
    "title": "Ireland International Protection Act 2015: Single Procedure, Refugee and Subsidiary Protection, Non-Refoulement",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The International Protection Act 2015 (No. 66 of 2015) is the principal Irish statute governing applications for international protection, administered by the International Protection Office and the Minister for Justice, with appeals to the International Protection Appeals Tribunal. Section 2 contains the definitions, including 'refugee' by reference to the Geneva Convention (the 1951 Convention relating to the Status of Refugees and its 1967 Protocol, the texts of which are set out in Schedules 1 and 2), and the criteria for a person eligible for subsidiary protection (a person who faces a real risk of suffering serious harm - the death penalty or execution, torture or inhuman or degrading treatment or punishment, or a serious and individual threat to a civilian's life by reason of indiscriminate violence in armed conflict). The Act introduced a single procedure: under section 15 a person makes one application for international protection, which is examined first for refugee status and, if that is not established, for subsidiary protection, before any consideration of permission to remain. Sections 11 and 12 provide for cessation of, and exclusion from, eligibility for subsidiary protection (mirroring the refugee cessation and exclusion clauses). Section 50 enacts the prohibition of refoulement, barring expulsion or return to the frontier of a territory where, in the Minister's opinion, the life or freedom of the person would be threatened or the person would be at risk of serious harm. Part 8 (sections 53-58) sets out the content of international protection - the permission to reside, the rights of beneficiaries, travel documents and family reunification. The Act operates alongside the Immigration Act 2004 and the Refugee Act framework it replaced.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "ie-online-safety-and-media-regulation-act-2022",
    "title": "Ireland Online Safety and Media Regulation Act 2022 (No. 41 of 2022, Coimisiún na Meán, Online Safety Codes, Designated Online Services, Section 139A Harmful Online Content Categories)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "The Online Safety and Media Regulation Act 2022 (No. 41 of 2022) of Ireland establishes Coimisiún na Meán (the Media Commission) and confers on it powers to regulate broadcasting services, audiovisual on-demand media services, video-sharing platform services, and designated online services. The Act amends the Broadcasting Act 2009 (No. 18 of 2009) to insert new Parts dealing with online safety, transposes Directive 2010/13/EU (Audiovisual Media Services Directive, AVMSD) as amended by Directive (EU) 2018/1808, and dissolves the Broadcasting Authority of Ireland with transfer of functions and staff to Coimisiún na Meán. The Online Safety Commissioner, established within Coimisiún na Meán, may designate online services under the Act and impose binding Online Safety Codes that require designated services to take measures to protect users (and in particular children) from categories of harmful online content listed in section 139A of the Broadcasting Act 2009 (as inserted by section 46 of the 2022 Act), including offence-specific categories such as content constituting child sexual abuse material, content inciting violence or hatred, terrorist content, content related to incitement to suicide and self-harm, content depicting non-consensual intimate imagery (image-based sexual abuse), and content related to bullying and harassment. Coimisiún na Meán may issue compliance notices, content limitation notices, end-user access blocking orders, and may impose administrative financial sanctions of up to EUR 20 million or 10 percent of the relevant turnover of the service provider in the preceding financial year, whichever is greater. The Act also implements the EU AVMSD video-sharing platform service regime, requiring providers of VSPS established in Ireland to comply with the country-of-origin principle and to take appropriate measures to protect minors from harmful content. Designated online services include large social media, video-sharing, messaging, and content-hosting platforms. The Act came into operation in stages from 2023 with the Online Safety Code first commenced in 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "key_institutions",
        "section_139a_harmful_content_categories",
        "designated_online_services_taxonomy",
        "online_safety_code_obligations",
        "vsps_regime_under_avmsd",
        "enforcement_taxonomy",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dsa-article-28-online-protection-of-minors",
      "eu-avmsd-2018-1808-article-6a-minors-protection",
      "uk-online-safety-act-2023-part-3-illegal-content-children-duties",
      "uk-online-safety-act-2023-part-5-pornographic-content-duties"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iea-clean-energy-technology-tracking-2024",
    "title": "Tracking Clean Energy Progress 2024 - Net Zero Pathway Milestones, Technology Readiness and Policy Gap Analysis",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The International Energy Agency's (IEA) 2024 report assesses over 500 clean energy technology and policy components against its Net Zero Emissions by 2050 (NZE) Scenario, providing a critical gap analysis for policymakers and investors. The report categorizes technologies by Technology Readiness Level (TRL) and progress status (e.g., 'On track', 'More effort needed'), highlighting areas requiring accelerated policy and investment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate-related-disclosures",
      "iso-14064-ghg-reporting-2018",
      "tcfd-status-report-2022",
      "un-sdg-corporate-mapping"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iea-emergency-response-oil-disruptions-iep",
    "title": "IEA International Energy Programme Emergency Response - Oil Stockholding Obligations, Demand Restraint and Oil Release Procedures",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The International Energy Program (IEP) Agreement requires International Energy Agency (IEA) member countries to maintain emergency oil stocks equivalent to at least 90 days of their prior year's net oil imports and to have established programs for demand restraint and coordinated stock release to be activated during a severe oil supply disruption, as outlined in Chapter II of the agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-22301-bcm-2019",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iea-net-zero-2050-critical-milestones",
    "title": "Net Zero by 2050: A Roadmap for the Global Energy Sector",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "The International Energy Agency's (IEA) Net Zero by 2050 (NZE) roadmap outlines a global pathway to achieve net-zero CO2 emissions by 2050, requiring immediate cessation of new unabated fossil fuel supply projects, massive scaling of clean energy technologies, and specific phase-out milestones for existing infrastructure. This influential, though non-binding, scenario is used by governments and corporations for strategic planning and climate-related financial disclosures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify",
      "iso-14090-climate-adapt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iec-60870-telecontrol-scada-protocols",
    "title": "IEC 60870-5 Telecontrol Equipment and Systems - SCADA Transmission Protocols",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "IEC 60870-5 (Telecontrol equipment and systems - Part 5: Transmission protocols), developed by IEC Technical Committee 57, specifies the transmission protocols used in SCADA systems for power-grid telecontrol and energy-infrastructure monitoring. The series defines companion standards for serial transmission (IEC 60870-5-101:2003) and network access over standard transport profiles using TCP/IP (IEC 60870-5-104:2006), conformance test cases (IEC 60870-5-601 and IEC 60870-5-604), and security extensions (IEC 60870-5-7:2025, applying IEC 62351). Operators of energy telecontrol systems implement these protocols to achieve interoperable, time-synchronised and secured data exchange between control centres and field devices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "etsi-en-303-645-iot-cybersecurity-2020",
      "eu-nis2-directive-2022-2555",
      "eu-cyber-resilience-act-iot-2024-products"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iec-61131-3-programmable-logic-controllers",
    "title": "IEC 61131-3:2013 - Programmable controllers - Part 3: Programming languages",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "IEC 61131-3:2013 defines the mandatory syntax and semantics for the five IEC programming languages (LD - Ladder Diagram, FBD - Function Block Diagram, ST - Structured Text, IL - Instruction List, SFC - Sequential Function Chart) and introduces extended data types, namespaces, and object-oriented features (classes, methods, interfaces); compliance is required for all programmable controller software development projects targeting IEC 61131-3 conformance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-4-2-component-security-2019",
      "iec-62351-power-systems-cybersecurity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iec-61850-power-utility-automation-security",
    "title": "IEC 61850: Communication Networks and Systems for Power Utility Automation - Security Requirements",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "IEC 61850, in conjunction with its security standard IEC 62351, mandates robust cybersecurity controls for power utility automation systems. It requires operators of Intelligent Electronic Devices (IEDs) and substation networks to implement strong authentication, role-based access control (RBAC), and encrypted communications to ensure the integrity and availability of critical grid control data, as specified in IEC 62351-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27031-dr-readiness",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-92-log-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iec-61851-ev-charging-system-standard",
    "title": "IEC 61851:2017 - Electric Vehicle Conductive Charging System: Mode 1-4 Charging, Control Pilot Signal, PWM Duty Cycle, Safety Requirements and Connector Requirements",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "IEC 61851:2017 defines the conductive charging system for electric vehicles, specifying safety, control pilot signaling, and connector requirements for charging modes 1 to 4. It applies to EV manufacturers, charging infrastructure providers, and system integrators, with key requirements in Clause 6 (General Requirements), Clause 8 (Control Pilot Circuit), and Clause 10 (Safety).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-alternative-fuels-infrastructure-regulation-2023-1804",
      "eu-batteries-regulation-2023-1542-ev-batteries",
      "etsi-its-cooperative-intelligent-transport"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iec-62304-medical-device-software-lifecycle-2026",
    "title": "IEC 62304 - Medical Device Software Lifecycle Processes (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The globally recognized foundational standard defining the lifecycle processes required for developing medical device software. It mandates a rigorous, risk-based approach to software architecture, detailed requirement tracing, and verification, scaling the documentation burden based on the software's Safety Class (A, B, or C).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 1
  },
  {
    "node_id": "iec-62304-medical-software",
    "title": "IEC 62304 (Medical Software)",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "IEC 62304 is the international standard for medical device software lifecycle processes. It defines the framework of processes, activities, and tasks for the safe design and maintenance of medical software, regardless of whether the software is a standalone product (SaMD) or embedded within a hardware device.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14971-medical-risk",
      "iso-13485-medical-qms",
      "eu-mdr-2017-745",
      "fda-21-cfr-part-820-qsr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iec-62304-medical-software-lifecycle",
    "title": "IEC 62304:2006+AMD1:2015 Medical Device Software - Software Life Cycle Processes for Safety Classification",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This international standard defines the life cycle requirements for medical device software, mandating a risk-based approach where all software is assigned a safety class (A, B, or C) based on its potential to cause harm (Clause 4.3). This classification dictates the rigor of the required software development, risk management, and maintenance processes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14971-medical-risk",
      "iso-13485-medical-qms",
      "eu-mdr-2017-745",
      "fda-21-cfr-part-820-qsr"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iec-62351-power-systems-cybersecurity",
    "title": "IEC 62351 Power Systems Management and Information Exchange Security - Authentication, Encryption and Role-Based Access for Substation Protocols",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The IEC 62351 series mandates end-to-end cybersecurity controls for operational technology (OT) communication protocols within power system infrastructures, requiring robust authentication, encryption, and integrity checks to protect against data interception and unauthorized commands. Key requirements include implementing Transport Layer Security (TLS) for TCP/IP-based protocols (Part 3) and establishing a framework for Role-Based Access Control (RBAC) for power system automation (Part 7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-140-3-cryptographic-modules",
      "nist-ir-7628-smart-grid-cybersecurity",
      "iso-27001-2022",
      "identity-and-access-management-electric-utilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iec-62443-4-1-product-security-development",
    "title": "IEC 62443-4-1:2018 Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "IEC 62443-4-1 mandates that product developers and maintainers implement a secure product development lifecycle covering requirements definition, secure design, implementation, verification, defect management, patch management and end‑of‑life activities (see Annex B summary list).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-4-2-component-security-2019",
      "iec-62351-power-systems-cybersecurity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iec-62443-4-2-component-security-2019",
    "title": "IEC 62443-4-2:2019 Security for industrial automation and control systems - Part 4-2: Technical security requirements for IACS components",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This standard defines technical security requirements for Industrial Automation and Control System (IACS) components based on seven foundational requirements (FRs) such as identification and authentication control, system integrity, and data confidentiality, and establishes component-specific security capability levels (SL-C). It applies to vendors, developers, and integrators of IACS components. Key provisions are defined in Clause 5 and associated technical control system component requirements (CRs).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-800-53-ac2",
      "nist-800-53-sc7",
      "iso-12207-2017-software-lifecycle-processes"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iec-62443-iacs",
    "title": "Industrial Automation Security (IEC 62443)",
    "domain": "Industrial IoT & Energy",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Operationalizing a comprehensive Industrial Automation and Control Systems (IACS) security program, in accordance with IEC 62443-2-1, demands adherence to a stringent set of technical and procedural controls that align closely with guidance in NIST Special Publication 800-82 Revision 3. A foundational element is the security risk assessment for system design, detailed in IEC 62443-3-2, which requires that high-level risk assessments possess a maximum age of 12 months and mandates strict enforcement of network partitioning into Zones and Conduits. System security requirements defined by IEC 62443-3-3 necessitate that all components achieve a minimum Target Security Level (SL-T) of 2. To secure access, multi-factor authentication is mandatory for all remote access, with account lockout triggered after a maximum of 3 consecutive failed login attempts and interactive sessions terminating after 15 minutes of inactivity; moreover, the principle of least privilege must be implemented through enforced role-based access control. The technical security requirements for IACS components, drawn from IEC 62443-4-2, stipulate that cryptographic encryption is required for all data in transit, and continuous visibility is supported through enabled automated asset discovery plus centralized security information and event monitoring (SIEM). Supporting the secure product development lifecycle requirements of IEC 62443-4-1, a 30-day service level agreement for patching critical vulnerabilities is enforced, while system resilience is bolstered by an IACS backup retention period of no less than 90 days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nerc-cip-v6-cyber",
      "nist-sp-1800-32-securing-ders"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iec-62443-industrial-automation-security-standards",
    "title": "IEC 62443 Industrial Automation and Control Systems Security - Security Levels, Zones and Conduits, and IACS Security Management",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The IEC 62443 series provides a comprehensive framework for securing Industrial Automation and Control Systems (IACS) by establishing requirements for asset owners, system integrators, and product suppliers. It mandates a risk-based approach, segmenting systems into zones and conduits and assigning Security Levels (SLs) to protect against specific threats, as detailed in IEC 62443-3-2 and IEC 62443-3-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0",
      "nist-800-53-sc7",
      "c-scrm-practices-systems-organizations"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iec-82304-1-health-software",
    "title": "IEC 82304-1 (Health Software)",
    "domain": "Medical & Healthcare",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "IEC 82304-1:2016 is the international standard for general health software product safety. It is designed for software products that do not have dedicated hardware and are used in health environments (e.g., lifestyle, wellness, or administrative software), ensuring safety, reliability, and security across the product lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62304-medical-software",
      "iso-14971-medical-risk",
      "iso-13485-medical-qms",
      "eu-mdr-2017-745"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ieee-2817-agent-ethics",
    "title": "Ethical Design of Agents (IEEE)",
    "domain": "Industrial IoT & Energy",
    "version": "1.1.1",
    "last_updated": "2026-07-01",
    "bluf": "IEEE 2817-2024 is the IEEE Standard for Pilot Qualification and Assessment of Autonomous Systems in Safety-Critical Applications, providing a framework for qualifying autonomous AI agents operating in safety-critical domains including transportation, industrial automation, healthcare, and public safety. The standard draws on the broader IEEE Ethically Aligned Design framework (EAD1e) which establishes that autonomous and intelligent systems must be designed to prioritize human wellbeing, be transparent in their decision-making, be accountable, avoid harm, and be controllable by humans. For AI agents, the standard requires demonstration that the agent's behavior aligns with its stated ethical commitments across a range of operational scenarios, that potential harms can be detected and mitigated, that the agent can be overridden by human operators, and that the agent's decision-making can be audited.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ieee-ethics-ai-system",
      "iec-62443-iacs",
      "nist-ai-rmf-1-0",
      "iso-31000-risk-mgt",
      "nerc-cip-v6-cyber",
      "nist-sp-800-82r3-ot-security"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ieee-3931-discovery",
    "title": "Agent Discovery & Capability Registry (IEEE P3931 ADDR)",
    "domain": "Workflow Automation",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The IEEE P3931 standard for Agent Description, Discovery, and Registry (ADDR) defines a universal, platform-agnostic framework for how autonomous agents describe their capabilities and how they are discovered within cross-platform ecosystems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-high-risk",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "cn-cac-genai-measures",
      "sg-imda-agentic-ai",
      "us-co-sb205-high-risk-ai"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ieee-7000-2021-ethical-ai-system-design",
    "title": "IEEE 7000-2021 - Model Process for Addressing Ethical Concerns During System Design: Value Elicitation, Concept of Operations with Ethical Values, Ethical Risk Assessment, Value Stories and Value Scenarios Methodology, Traceability Requirements and Audit Trail for AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "IEEE 7000-2021 establishes a model process for integrating ethical values throughout system design, requiring organizations to elicit, prioritize, and trace ethical values through concept of operations, requirements, and risk-based design. It applies to all organizations regardless of size or lifecycle model, as stated in the standard's scope.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-ai-ethics-framework-2019",
      "asean-model-ai-governance-v2-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ieee-7000-2021-ethically-aligned-design",
    "title": "IEEE 7000-2021 Ethically Aligned Design for Autonomous and Intelligent Systems - Value Elicitation, Ethical Risk Assessment and Transparency",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard provides a process model for developers of autonomous and intelligent systems (A/IS) to analyze and address ethical considerations throughout the design lifecycle. It mandates specific processes for value elicitation, ethical risk assessment, and transparency to ensure systems align with human values and avoid negative societal impacts, as detailed in Clause 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-23894-ai-risk-management",
      "iso-42005-ai-impact-assessment",
      "oecd-ai-principles",
      "unesco-ethics-ai"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ieee-7010-2020-ai-wellbeing-impact",
    "title": "IEEE 7010-2020 Recommended Practice for Assessing the Impact of Autonomous and Intelligent Systems on Human Well-Being",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This standard provides a recommended practice for assessing the impact of autonomous and intelligent systems (A/IS) on human well-being, using scientifically valid well-being indices and stakeholder engagement. It applies to developers, manufacturers, and deployers of A/IS seeking to evaluate intended and unintended impacts on human well-being as outlined in IEEE 7010-2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "nist-ai-100-4-redteam",
      "australia-ai-ethics-framework-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ieee-ethics-ai-system",
    "title": "IEEE Ethics (AI Systems)",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance verification for this node mandates adherence to a comprehensive framework of IEEE standards governing ethical AI system development and deployment. The process begins by prioritizing human well-being, a principle central to Ethically Aligned Design, requiring both an approved human_rights_impact_assessment_approved and active wellbeing_metrics_defined_and_tracked. Stakeholder values are integrated through a formal process, outlined in IEEE 7000-2021, which necessitates no fewer than the stakeholder_engagement_sessions_min of three completed sessions. System transparency, a core tenet of IEEE 7001-2021, is quantitatively enforced by a transparency_explainability_score_min threshold of 0.85, supported by enabled accountability_traceability_logging_enabled and an available automated_decision_appeal_mechanism. In alignment with the IEEE 7002-2022 standard, data privacy is upheld by ensuring data_agency_user_control_enabled is active. To address fairness, algorithmic bias considerations from IEEE 7003-2023 impose a strict algorithmic_bias_variance_max of 0.05 between specified groups. Finally, system safety and reliability are governed by IEEE 7009-2024 principles for fail-safe design, mandating a human_override_capability_active, a completed misuse_risk_simulation_completed analysis, and a validated system performance achieving a system_competence_validation_score_min of 0.9 before operational clearance is granted.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "oecd-ai-principles",
      "unesco-ethics-ai",
      "iso-42001-risk-assess",
      "nist-sp-1270-managing-ai-bias",
      "nistir-8312-explainable-ai-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ietf-hybrid-pqc-drafts",
    "title": "IETF Hybrid PQC Drafts",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "IETF Hybrid PQC Drafts define the mechanisms for combining 'Classical' cryptography (e.g., X25519, Ed25519) with 'Post-Quantum' algorithms (e.g., ML-KEM, ML-DSA). This 'Defense-in-Depth' approach ensures security even if a quantum-resistant algorithm is found to be vulnerable or if the classical algorithm is broken by a quantum computer.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-203-ml-kem-standard",
      "fips-204-ml-dsa-quantum",
      "pqc-migration-logic"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ietf-oauth-2-1-authorization-framework",
    "title": "IETF OAuth 2.1 Authorization Framework - Consolidated Secure Authorization for Workflow APIs",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "OAuth 2.1 (IETF draft-ietf-oauth-v2-1, consolidating OAuth 2.0 RFC 6749 with security best practices from RFC 8252, RFC 8707, RFC 9068, RFC 9126, and RFC 9449) is the definitive authorization framework for modern API security in workflow automation, AI agent systems, and enterprise software. OAuth 2.1 removes insecure grant types (Resource Owner Password Credentials and Implicit grants), mandates PKCE (RFC 7636) for all authorization code flows including confidential clients, mandates exact redirect URI matching, and incorporates sender-constrained tokens (DPoP - RFC 9449) as best practice. Organizations implementing AI agent orchestration, microservices authorization, B2B API integrations, or enterprise workflow platforms must implement OAuth 2.1 to meet current security standards for token-based authorization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-7519-json-web-token-jwt",
      "openid-connect-core-1-0-identity-workflow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ietf-rfc-6238-totp-time-based-one-time-password",
    "title": "IETF RFC 6238 TOTP Time-Based One-Time Password Algorithm - Time Step T Equals Floor of Unix Time Minus T0 Over X HMAC-SHA-1 Dynamic Truncation 30 Second Default Step Clock Drift Tolerance and Multi-Factor Authentication",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "IETF RFC 6238 specifies TOTP the Time-Based One-Time Password Algorithm extending HOTP RFC 4226 by replacing the event counter with a time-derived value computed as T equals the floor of current Unix time minus T0 divided by X where T0 defaults to zero the Unix epoch and X represents the time step in seconds with a default of thirty seconds, with security resting on HMAC-SHA-1 from RFC 2104 with permitted alternatives of HMAC-SHA-256 or HMAC-SHA-512 and the dynamic truncation process converting HMAC output into user-friendly numeric values, recommending a default time-step size of thirty seconds balancing security and usability, addressing clock drift by accepting OTPs from multiple time steps backward and forward, requiring rejection of duplicate submissions within a given time-step window, and providing the basis for authenticator apps and hardware tokens used in multi-factor authentication workflows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-6749-oauth-2-0-authorization-framework-2012"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ietf-rfc-6241-netconf-network-configuration-protocol",
    "title": "IETF RFC 6241 NETCONF Network Configuration Protocol - XML RPC Configuration Management Datastore Operations Capability Exchange and SSH Transport",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "IETF RFC 6241 specifies the Network Configuration Protocol NETCONF as a standards-track XML-based remote procedure call protocol for installing manipulating and deleting the configuration of network devices, structured across sections covering an RPC-based introduction in section 1, transport requirements mandating reliable sequenced delivery and SSH transport via RFC 6242 in section 2, XML message encoding requirements in section 3, the rpc and rpc-reply message structure with mandatory message-id attributes and rpc-error elements in section 4, the running candidate and startup datastore configuration model in section 5, subtree filtering for selective data retrieval in section 6, the nine base operations get get-config edit-config copy-config delete-config lock unlock close-session and kill-session in section 7, capability exchange enabling servers to advertise supported features in section 8, notification mechanisms in section 9, and security considerations addressing authentication confidentiality and access control in section 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-6749-oauth-2-0-authorization-framework-2012"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ietf-rfc-6455-websocket-protocol-2011",
    "title": "IETF RFC 6455 - WebSocket Protocol: Full-Duplex Real-Time Communication Standard",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "RFC 6455 (2011) defines the WebSocket protocol enabling persistent, full-duplex communication over a single TCP connection upgraded from HTTP; mandates TLS-encrypted WSS for production deployments; requires server-side origin validation, client-side frame masking, and orderly close-frame handshake; governs real-time workflow automation channels, AI agent bidirectional message streams, and event-driven compliance notification pipelines serving regulated industries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-7519-json-web-token-jwt",
      "w3c-activitypub-2018-decentralized-social-protocol"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ietf-rfc-6749-oauth-2-0-authorization-framework-2012",
    "title": "IETF RFC 6749 - OAuth 2.0 Authorization Framework: Core Delegated Authorization Protocol",
    "domain": "Workflow Automation",
    "version": "2012-10",
    "last_updated": "2026-05-09",
    "bluf": "IETF RFC 6749 (October 2012) defines the OAuth 2.0 authorization framework, establishing four authorization grant types (authorization code, implicit, resource owner password credentials, client credentials), authorization server and resource server roles, client registration requirements, bearer token usage per RFC 6750, and the extensibility model that underpins delegated authorization for web applications, mobile applications, and API ecosystems; RFC 6749 is the foundational standard superseded in part by OAuth 2.1 (RFC draft) but remains the normative reference for all deployed OAuth 2.0 implementations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-oauth-2-1-authorization-framework",
      "ietf-rfc-7519-json-web-token-jwt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ietf-rfc-6902-json-patch",
    "title": "IETF RFC 6902 JSON Patch - Six Operation Document Format for HTTP PATCH and Programmatic Modification of JSON Documents with JSON Pointer Path Syntax",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "IETF RFC 6902 specifies JSON Patch as the format for expressing a sequence of operations to apply to a target JSON document, organised around six operations add remove replace move copy and test where add inserts values into arrays at specified indices or adds or replaces object members, remove deletes the value at the target location which must exist, replace substitutes the value at an existing target location, move relocates a value from a source to a target location, copy duplicates a value from a source to a target, and test validates that a target location's value matches a specified value using type-specific equality rules, with documents structured as JSON arrays of operation objects each carrying mandatory op and path members, paths referenced via JSON Pointer per RFC 6901, atomic semantics requiring that a normative requirement violation terminates evaluation without partial application and security considerations addressing CSRF risk for sensitive patch documents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-9110-http-semantics-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ietf-rfc-7009-oauth-2-0-token-revocation-2013",
    "title": "IETF RFC 7009 - OAuth 2.0 Token Revocation: Explicit Token Invalidation Protocol",
    "domain": "Workflow Automation",
    "version": "2013-08",
    "last_updated": "2026-05-09",
    "bluf": "RFC 7009 defines the OAuth 2.0 Token Revocation endpoint protocol allowing clients to notify the authorization server that a previously obtained token (access token or refresh token) is no longer needed, enabling logout flows, compromised token invalidation, and session termination in OAuth-based systems without waiting for natural token expiry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-oauth-2-1-authorization-framework",
      "ietf-rfc-7519-json-web-token-jwt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ietf-rfc-7396-json-merge-patch",
    "title": "IETF RFC 7396 JSON Merge Patch - Recursive Merge Algorithm Application Merge Patch JSON Media Type and Object-Oriented Partial Update Semantics for HTTP PATCH",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "IETF RFC 7396 specifies the JSON Merge Patch format which describes modifications to a target JSON document using syntax that mirrors the target document with null values given special meaning to indicate the removal of existing values, processed via a recursive MergePatch algorithm where an object patch iterates through name-value pairs replacing or recursing into matching members and removing members where the patch value is null while non-object patches replace the entire target, registers the media type application-slash-merge-patch+json, references HTTP PATCH method security guidance from RFC 5789 and the JSON format from RFC 7159, with a notable limitation that JSON Merge Patch is best suited to JSON documents that primarily use objects and is not appropriate for documents that use explicit nulls or rely on arrays for modification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-9110-http-semantics-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ietf-rfc-7519-json-web-token-jwt",
    "title": "IETF RFC 7519 - JSON Web Token (JWT) for Secure Workflow API Authentication",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "IETF RFC 7519 (JSON Web Token, May 2015) defines a compact, URL-safe means of representing claims to be transferred between two parties as a JSON object that may be digitally signed (JWS - RFC 7515) or encrypted (JWE - RFC 7516). JWTs are the de facto standard for API authentication tokens, OAuth 2.0 access tokens, OpenID Connect ID tokens, and workflow automation service-to-service authorization. The JWT payload carries registered claim names (iss, sub, aud, exp, nbf, iat, jti) and private claims. Organizations implementing workflow automation, AI agent orchestration, microservices, or API gateways must implement RFC 7519 correctly to prevent token forgery, algorithm confusion attacks, and authorization bypass vulnerabilities that are among the most common causes of security breaches in automated systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-9110-http-semantics-2022",
      "openid-connect-core-1-0-identity-workflow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ietf-rfc-7523-jwt-profile-oauth2-client-authentication-2015",
    "title": "IETF RFC 7523 - JWT Profile for OAuth 2.0 Client Authentication and Authorization Grants",
    "domain": "Workflow Automation",
    "version": "2015-05",
    "last_updated": "2026-05-09",
    "bluf": "IETF RFC 7523 (May 2015) defines how JSON Web Tokens (JWT) can be used as OAuth 2.0 client authentication credentials and as authorization grants, enabling machine-to-machine API authentication without shared secrets by using JWT assertions signed with private keys; the RFC specifies required JWT claims (iss, sub, aud, exp, jti), the client_assertion_type and grant_type parameter URNs, and the authorization server validation rules that must be applied before issuing access tokens in response to JWT assertions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-oauth-2-1-authorization-framework",
      "ietf-rfc-7519-json-web-token-jwt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ietf-rfc-7591-oauth-2-0-dynamic-client-registration",
    "title": "IETF RFC 7591 OAuth 2.0 Dynamic Client Registration Protocol - Client Metadata Registration Endpoint Initial Access Tokens Software Statement and Self-Service Client Provisioning",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "IETF RFC 7591 specifies the OAuth 2.0 Dynamic Client Registration Protocol enabling clients to register with an OAuth 2.0 authorization server at runtime instead of through manual configuration covering client metadata fields including redirect_uris token_endpoint_auth_method grant_types and response_types as optional unless stated otherwise, the client registration request as an HTTP POST with JSON-encoded parameters to the registration endpoint optionally bearing an initial access token for authorized registration scenarios, the client information response returning HTTP 201 with the assigned client_id optional client_secret and all registered metadata, error responses using HTTP 400 with JSON error objects including invalid_redirect_uri invalid_client_metadata and invalid_software_statement, security considerations mandating TLS 1.2 transport protection and restricting registered redirect URI values to TLS-protected web sites local-machine HTTP URIs or non-HTTP application-specific URLs, and enables self-service registration for distributed agent systems where deployment details are unknown at build time.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-6749-oauth-2-0-authorization-framework-2012",
      "ietf-rfc-8414-oauth-2-0-authorization-server-metadata-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ietf-rfc-7636-pkce-proof-key-code-exchange-2015",
    "title": "IETF RFC 7636 - Proof Key for Code Exchange (PKCE): OAuth 2.0 Authorization Code Security Extension",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "RFC 7636 (September 2015) defines Proof Key for Code Exchange (PKCE), a security extension to the OAuth 2.0 Authorization Code Grant that prevents authorization code interception attacks for public clients (mobile apps, single-page apps, CLI tools); the client generates a cryptographic code_verifier (random string 43-128 characters), derives a code_challenge (SHA-256 hash, base64url-encoded), sends the challenge at authorization time, and proves possession of the verifier at token exchange time; PKCE is mandatory in OAuth 2.1, recommended by current IETF security BCP for all OAuth clients including confidential clients, and required by AI agent tool authentication flows where redirect URIs cannot be reliably protected.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-oauth-2-1-authorization-framework",
      "ietf-rfc-7519-json-web-token-jwt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ietf-rfc-7642-scim-2-0-user-provisioning-2015",
    "title": "IETF RFC 7642/7643/7644 - SCIM 2.0: System for Cross-Domain Identity Management Protocol for Workflow Automation",
    "domain": "Workflow Automation",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "SCIM 2.0 (RFC 7642 concepts, RFC 7643 schema, RFC 7644 protocol - September 2015) defines a standardized REST API and JSON schema for automated user and group lifecycle management (provisioning, deprovisioning, and synchronization) across enterprise systems; defines core schema resources (User, Group, EnterpriseUser extension), CRUD operations via HTTP (POST, GET, PUT, PATCH, DELETE) with filtering and pagination, and bulk operations; adopted by all major identity providers (Azure AD, Okta, OneLogin, Google Workspace) as the standard for just-in-time provisioning and automated deprovisioning; directly applicable to AI agent identity lifecycle management in regulated environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-oauth-2-1-authorization-framework",
      "ietf-rfc-7519-json-web-token-jwt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ietf-rfc-7662-oauth-2-0-token-introspection-2015",
    "title": "IETF RFC 7662 - OAuth 2.0 Token Introspection: Active Token Validation Protocol",
    "domain": "Workflow Automation",
    "version": "2015-10",
    "last_updated": "2026-05-09",
    "bluf": "RFC 7662 defines the OAuth 2.0 Token Introspection protocol enabling protected resource servers to query an authorization server to determine the state and metadata of a presented access token or refresh token, including active status, scope, subject, expiration, client_id, and token type, allowing stateless token validation across distributed microservice architectures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-oauth-2-1-authorization-framework",
      "ietf-rfc-7519-json-web-token-jwt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ietf-rfc-7807-problem-details-http-apis",
    "title": "IETF RFC 7807 - Problem Details for HTTP APIs: Standardized Error Response Format for Workflow Integration",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "RFC 7807 (March 2016) defines a standard machine-readable format for HTTP API error responses using Problem Detail objects in application/problem+json or application/problem+xml media types; specifies five standard members (type URI, title, status, detail, instance) with extension member support; enables interoperable error handling across workflow automation systems, AI agent tool calls, and microservice integrations in regulated environments requiring consistent error semantics.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-7519-json-web-token-jwt",
      "w3c-activitypub-2018-decentralized-social-protocol"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ietf-rfc-7950-yang-1-1-data-modeling-language",
    "title": "IETF RFC 7950 YANG 1.1 Data Modeling Language - Module Container Leaf List Grouping Augment Choice Action and Notification Statements for Network Management Configuration State and Operations",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "IETF RFC 7950 defines YANG 1.1 the data modeling language for the NETCONF Network Configuration Protocol and adjacent network management protocols including RESTCONF and CoAP Management Interface, organised around module and submodule structure with header and revision statements, four primary data definition node types leaf leaf-list container and list with key statements, a built-in type system covering integer variants string boolean enumeration bits binary decimal64 leafref identityref empty union and instance-identifier with custom typedef derivation, structural statements including grouping with uses for reusable templates augment for extending existing models and choice with case for mutually exclusive alternatives, operation statements including top-level rpc statements action statements newly introduced in 1.1 for data-node-tied operations and notification statements for event definitions, three conformance approaches covering basic client server behavioural contracts optional features via feature and if-feature statements and deviation statements for implementation variations, plus 1.1 enhancements such as mandatory yang-version statement extended if-feature boolean expressions and the new anydata statement preferred over anyxml.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-6241-netconf-network-configuration-protocol"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ietf-rfc-8391-xmss-hash-based-signatures",
    "title": "IETF RFC 8391 XMSS eXtended Merkle Signature Scheme - Stateful Hash-Based Signature Specification",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2018-05-31",
    "bluf": "RFC 8391, XMSS: eXtended Merkle Signature Scheme, is an Informational document published in May 2018 by A. Huelsing, D. Butin, S. Gazdag, J. Rijneveld and A. Mohaisen. It is not an Internet Standards Track specification; it is published for informational purposes and represents the consensus of the Crypto Forum Research Group of the Internet Research Task Force. It specifies Winternitz One-Time Signature Plus (WOTS+), a one-time signature scheme; XMSS, a single-tree scheme; and XMSS^MT, a multi-tree variant of XMSS. XMSS provides cryptographic digital signatures without relying on the conjectured hardness of mathematical problems; instead it is proven that it only relies on the properties of cryptographic hash functions.\n\nThe controlling operational obligation in this specification is state management. The schemes described are stateful, meaning the secret key changes over time, and if a secret key state is used twice, no cryptographic security guarantees remain and it becomes feasible to forge a signature on a new message. The document states that developers should not use the schemes described except in systems that prevent the reuse of secret key states, that the API MUST be able to handle a secret key state and MUST allow an updated secret key state to be returned, and that an implementation MUST NOT output the signature before the private key is updated. Where partial private keys or copies of private keys are used, for example for load balancing or delegation of signing rights, applications MUST establish means that guarantee that each index, and thereby each WOTS+ key pair, is used to sign only a single message. Parameter selection is governed by Section 5: parameters with n = 32 provide a classical security level of 256 bits and parameters with n = 64 provide 512 bits, which considering quantum-computer-aided attacks yield post-quantum security of 128 and 256 bits respectively. The REQUIRED parameter sets all use SHA2-256 to instantiate all functions and are distinguished by the tree height parameter h, which determines the number of signatures that can be done with a single key pair, and the number of layers d. This node covers the specification of the scheme itself. The separate United States federal recommendation on approved use of stateful hash-based signatures is held elsewhere in the registry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-208-stateful-hbs",
      "ietf-rfc-8554-lms-hash-based-signatures",
      "fips-205-slh-dsa-quantum",
      "ietf-rfc-9794-pq-traditional-hybrid-terminology"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ietf-rfc-8414-oauth-2-0-authorization-server-metadata-2018",
    "title": "IETF RFC 8414 - OAuth 2.0 Authorization Server Metadata: Discovery Protocol",
    "domain": "Workflow Automation",
    "version": "2018-06",
    "last_updated": "2026-05-09",
    "bluf": "RFC 8414 defines the OAuth 2.0 Authorization Server Metadata discovery protocol enabling clients to automatically discover authorization server capabilities - including endpoint URLs, supported grant types, scopes, algorithms, and PKCE support - by fetching a well-known JSON document, eliminating manual configuration and enabling seamless multi-tenant and federated authorization architectures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-oauth-2-1-authorization-framework",
      "ietf-rfc-7519-json-web-token-jwt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ietf-rfc-8554-lms-hash-based-signatures",
    "title": "IETF RFC 8554 Leighton-Micali Hash-Based Signatures - LM-OTS, LMS and HSS Specification",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2019-04-30",
    "bluf": "RFC 8554, Leighton-Micali Hash-Based Signatures, is an Informational document published in April 2019 by D. McGrew, M. Curcio and S. Fluhrer of Cisco Systems. It is not an Internet Standards Track specification; it is published for informational purposes and represents the consensus of the Crypto Forum Research Group of the Internet Research Task Force. It describes a digital-signature system based on cryptographic hash functions, following the seminal work of Lamport, Diffie, Winternitz and Merkle as adapted by Leighton and Micali in 1995, and specifies a one-time signature scheme and a general signature scheme. The systems provide asymmetric authentication without using large integer mathematics, are suitable for compact implementations and are naturally resistant to side-channel attacks. The document notes that it is based on U.S. Patent 5,432,852, which was issued over twenty years ago and is thus expired.\n\nThe specification defines three layers. LM-OTS is the one-time signature scheme, parameterised by n, the number of bytes of hash function output, and w, the width in bits of the Winternitz coefficients, which is a member of the set {1, 2, 4, 8}; the four defined parameter sets are LMOTS_SHA256_N32_W1, W2, W4 and W8, with signature lengths of 8516, 4292, 2180 and 1124 bytes respectively. LMS is the tree scheme, parameterised by tree height h and node size m, with the defined sets LMS_SHA256_M32_H5 through H25, giving 2^h leaves. HSS, the Hierarchical Signature System described in Section 6, uses a sequence of L LMS trees where each LMS private key signs the next LMS public key and the last signs the actual message, and exists for scenarios where the time taken by public key generation must be minimised.\n\nThe binding operational constraint is statefulness. The LMS signing algorithm modifies and updates the private key as a side effect of generating a signature, and once a particular value of the private key is used to sign one message it MUST NOT be used to sign another. The API MUST be able to handle a dynamic secret key state, that is the API MUST allow the signature-generation algorithm to update the secret key state, and developers should not use the schemes except in systems that prevent the reuse of secret key states. Section 9.2 makes the persistence requirement concrete: after a signature is generated the updated private key must actually be written to nonvolatile storage past any intervening memory caches, and where hierarchical signatures are used implementations SHOULD keep the second-level private key resident in RAM only and generate a new second-level key pair whenever the application restarts. This node covers the specification itself; the United States federal recommendation on approved deployment of stateful hash-based signatures is held separately in the registry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-208-stateful-hbs",
      "ietf-rfc-8391-xmss-hash-based-signatures",
      "fips-205-slh-dsa-quantum",
      "ietf-rfc-9794-pq-traditional-hybrid-terminology"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ietf-rfc-8615-well-known-uris",
    "title": "IETF RFC 8615 Well-Known Uniform Resource Identifiers - Reserved Slash Dot Well Known Slash Path Suffix Registry Discovery Mechanism for Site-Wide Metadata Across HTTP HTTPS WebSocket and CoAP",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "IETF RFC 8615 establishes the standardized framework for discovering site-wide metadata through reserved URI paths obsoleting RFC 5785 by defining a well-known URI as one whose path component begins with the characters slash dot well known slash and reserving this path prefix for schemes that explicitly support the mechanism including HTTP HTTPS WebSocket WSS CoAP and CoAPS, registering new suffixes through IANA with applicants providing the suffix name change controller information specification document reference status designation as permanent or provisional and related documentation, with security considerations covering write-access control to prevent unauthorized well-known resource modification browser interaction awareness for HTTP and HTTPS deployments clear application scoping to prevent cross-host policy misapplication and administrator visibility of hidden dot well known directories, and supporting widely-used suffixes including security.txt openid-configuration host-meta change-password and traffic-advice.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-9110-http-semantics-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ietf-rfc-8628-device-authorization-grant-2019",
    "title": "IETF RFC 8628 - OAuth 2.0 Device Authorization Grant: Browserless and Input-Constrained Device Authentication",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "RFC 8628 (August 2019) defines the OAuth 2.0 Device Authorization Grant (formerly Device Flow) enabling devices with limited input capabilities (CLI tools, IoT devices, smart TVs, AI agents without browser access) to obtain OAuth tokens; the device requests a device_code and user_code from the authorization server, displays the user_code and verification_uri to the user who authorizes on a secondary device, and then polls the token endpoint with exponential backoff until authorization is granted, expired, or denied; widely used for CLI authentication (GitHub CLI, AWS CLI, Terraform), AI agent out-of-band authorization in agentic workflows, and IoT device provisioning.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-oauth-2-1-authorization-framework",
      "ietf-rfc-7519-json-web-token-jwt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ietf-rfc-8725-jwt-best-current-practices",
    "title": "IETF RFC 8725 - JSON Web Token Best Current Practices: Security Hardening for Workflow Authentication",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "RFC 8725 (February 2020) is an IETF Best Current Practice that supersedes and corrects security deficiencies identified in RFC 7519 (JWT); prohibits algorithm confusion attacks by mandating algorithm allowlists, banning 'none' algorithm, requiring explicit audience validation, mandating short-lived token lifetimes, restricting sensitive data in claims, and enforcing strict key management; directly applicable to all workflow automation tokens, AI agent bearer credentials, and OAuth 2.x access tokens in regulated environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-7519-json-web-token-jwt",
      "ietf-oauth-2-1-authorization-framework"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ietf-rfc-9068-jwt-profile-access-tokens-2021",
    "title": "IETF RFC 9068 - JSON Web Token (JWT) Profile for OAuth 2.0 Access Tokens: Self-Contained Token Standard",
    "domain": "Workflow Automation",
    "version": "2021-10",
    "last_updated": "2026-05-09",
    "bluf": "IETF RFC 9068 (October 2021) defines a standardized JSON Web Token (JWT) profile for OAuth 2.0 access tokens, specifying required claims (iss, exp, aud, sub, client_id, iat, jti), the at+JWT content type header, optional authorization claims (scope, groups, roles, entitlements, authorization_details), and resource server validation procedures; the profile enables self-contained access tokens that resource servers can validate locally using the authorization server's public key without calling the introspection endpoint on every request, reducing latency and improving resilience for distributed API architectures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-oauth-2-1-authorization-framework",
      "ietf-rfc-7519-json-web-token-jwt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ietf-rfc-9110-http-semantics-2022",
    "title": "IETF RFC 9110 - HTTP Semantics (2022) Web Service Workflow Standard",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "IETF RFC 9110 (June 2022) is the authoritative specification for HTTP semantics, defining request methods, status codes, headers, content negotiation, authentication, and caching. It supersedes RFC 7231/7235 and forms the normative foundation for all RESTful API and web service workflows, including API gateway compliance, microservice communication, and machine-to-machine automation pipelines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "openid-connect-core-1-0-identity-workflow",
      "oasis-xacml-3-0-access-control-policy-language"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ietf-rfc-9309-robots-exclusion-protocol-2022",
    "title": "IETF RFC 9309 - Robots Exclusion Protocol (Standards Track, September 2022)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "IETF RFC 9309 standardises the Robots Exclusion Protocol as an IETF Standards Track document published in September 2022, formalising the de facto robots.txt convention used since 1994. The protocol defines how website operators communicate access rules to automated clients (crawlers, scrapers, AI training data collectors) via a robots.txt file at the site root. RFC 9309 specifies the file format, parsing requirements, and rule precedence for the User-Agent and Disallow/Allow directives. The Protocol is voluntary at the protocol level - it expresses publisher intent but technical enforcement depends on the requesting client honouring the file. In AI governance, RFC 9309 has become the foundation for AI training data opt-out signalling: publishers use robots.txt to express that named AI crawlers (GPTBot, Google-Extended, ClaudeBot, CCBot, anthropic-ai, PerplexityBot, etc.) should not crawl their site for training data collection. Companion mechanisms include the IETF AI Preferences Working Group proposed standard (under development) and the W3C Text and Data Mining Reservation Protocol. The CNIL AI development recommendations (April-June 2024), the EU AI Office GPAI Code of Practice (July 2025) copyright commitment, and the OpenAI, Google, Anthropic, and Common Crawl crawler operator policies all reference robots.txt opt-out honour as the baseline AI training data opt-out mechanism.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlay",
        "ai_governance_overlay",
        "operator_practice"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "france-cnil-ai-recommendations-2024",
      "eu-ai-office-gpai-code-of-practice-2025"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ietf-rfc-9370-multiple-key-exchanges-ikev2",
    "title": "IETF RFC 9370 Multiple Key Exchanges in IKEv2 - Hybrid Post-Quantum Key Establishment for IPsec",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2023-05-31",
    "bluf": "RFC 9370, Multiple Key Exchanges in the Internet Key Exchange Protocol Version 2 (IKEv2), is a Standards Track document of the Internet Engineering Task Force published in May 2023 by CJ. Tjhai, M. Tomlinson, G. Bartlett, S. Fluhrer, D. Van Geest, O. Garcia-Morchon and V. Smyslov. It updates RFC 7296. It describes how to extend IKEv2 to allow multiple key exchanges to take place while computing a shared secret during a Security Association setup, which is the mechanism by which post-quantum key establishment is introduced into IPsec without abandoning the classical exchange.\n\nThe problem it addresses is stated directly: IKEv2 as specified in RFC 7296 uses Diffie-Hellman or Elliptic Curve Diffie-Hellman to establish a shared secret, it is believed that general-purpose quantum computers will be able to solve the underlying discrete logarithm problem, and this implies that the security of IKEv2 is compromised. The extension allows one or more post-quantum key exchanges to be performed alongside the classical exchange so that the final shared secret is computed from all of the component key exchange secrets; so that where both peers do not support and agree the additional exchanges, a shared secret equivalent to that specified in RFC 7296 is still obtained; and so that if any part of the component key exchange method is a post-quantum algorithm, the final shared secret is post-quantum secure.\n\nMechanically, the specification utilises the IKE_INTERMEDIATE exchange of RFC 9242 to carry the additional key exchanges, because post-quantum key exchange payloads may exceed the maximum transmission unit and IKE_SA_INIT has no inherent fragmentation support. It introduces a new exchange, IKE_FOLLOWUP_KE, registered as IKEv2 Exchange Type 44, for the same purpose when the IKE SA is being rekeyed or additional Child SAs are being created. Seven new Transform Types are registered, ADDKE1 through ADDKE7 with values 6 to 12, sharing the Transform ID space of Transform Type 4 so that additional exchanges may be either post-quantum or classical. It renames Transform Type 4 from Diffie-Hellman Group (D-H) to Key Exchange Method (KE), renames the Key Exchange Payload field from Diffie-Hellman Group Num to Key Exchange Method, and renames the corresponding IANA registry, generalising the key exchange algorithms usable in IKEv2. The stated main focus is preventing a passive harvest-and-decrypt attack; the specification is explicit that the authentication step remains classical and that other attacks involving an active attacker using a quantum computer are not completely solved by this document.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-9794-pq-traditional-hybrid-terminology",
      "fips-203-ml-kem-standard",
      "nsa-cnsa-2-0-quantum-resistant-algorithms-2022",
      "nist-ir-8547-pqc-transition"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ietf-rfc-9794-pq-traditional-hybrid-terminology",
    "title": "IETF RFC 9794 Terminology for Post-Quantum Traditional Hybrid Schemes",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2025-06-30",
    "bluf": "RFC 9794, Terminology for Post-Quantum Traditional Hybrid Schemes, is an Informational document of the IETF stream published in June 2025 by F. Driscoll, M. Parsons and B. Hale. It fixes the vocabulary used across protocol specifications and regulatory guidance for combining post-quantum and traditional cryptography, so that terms such as hybrid, composite and combiner carry one agreed meaning rather than several.\n\nIt defines a traditional asymmetric cryptographic algorithm as one based on integer factorisation, finite field discrete logarithms, elliptic curve discrete logarithms or related mathematical problems, and a post-quantum asymmetric cryptographic algorithm as one intended to be secure against attacks using quantum computers as well as classical computers. A PQ/T hybrid scheme is a multi-algorithm scheme where at least one component algorithm is post-quantum and at least one is traditional. It further separates composite schemes, exposed as a singular interface of the same type as the component algorithms, from non-composite arrangements, and defines the combiner as the method that takes two or more component algorithms and combines them. Two properties matter for assurance arguments: PQ/T hybrid confidentiality holds as long as at least one component algorithm providing that property remains secure, and PQ/T hybrid interoperability succeeds provided both parties share support for at least one component algorithm. This node is the terminology anchor for hybrid claims made elsewhere in the registry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-203-ml-kem-standard",
      "fips-204-ml-dsa-standard",
      "ietf-hybrid-pqc-drafts",
      "de-bsi-post-quantum-cryptography-position-tr-02102-1"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "ifac-ethics-accountants",
    "title": "IFAC Ethics for Accountants",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the IESBA International Code of Ethics for Professional Accountants is operationalized through the acknowledgment of five fundamental principles: integrity, objectivity, professional competence and due care, confidentiality, and professional behavior. This conceptual framework requires accountants to identify, evaluate, and address threats to these principles by applying necessary safeguards. For professional accountants in public practice, stringent protocols under Section 310 govern the clearance of conflicts of interest, while inducements are assessed per Section 340 to prevent any compromise of professional judgment. Independence for audit, review, and other assurance engagements, as detailed in Parts 4A and 4B, is paramount. Verification extends across all network firms, and fee dependency is managed with a strict 15% cap on total fees from a Public Interest Entity audit client for two consecutive years. The system enforces a 7-year rotation for key audit partners, succeeded by a mandatory minimum 3-year cooling-off period. Concurrently, the NOCLAR reporting protocol from Section 260 guides responses to non-compliance with laws and regulations. Active confidentiality safeguards are maintained throughout all professional services, upholding a primary ethical obligation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-code-ethics",
      "ifrs-global-accounting",
      "pcaob-audit-standards",
      "gaap-us-framework",
      "iaasb-isqm-1-quality",
      "iia-internal-audit-ippf"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ifc-performance-standards-2012-mining",
    "title": "IFC Performance Standards on Environmental and Social Sustainability 2012 - Standards PS1-PS8 Applied to Mining Projects: Labour, Community, Biodiversity and Cultural Heritage",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The IFC Performance Standards (PS1-PS8) apply to all mining projects financed by the International Finance Corporation (IFC), requiring robust environmental and social risk management, including labor standards, community engagement, biodiversity conservation, and cultural heritage protection. Key obligations are defined in PS1 (Assessment and Management of Environmental and Social Risks), PS2 (Labor and Working Conditions), PS3 (Resource Efficiency and Pollution Prevention), PS4 (Community Health, Safety, and Security), PS5 (Land Acquisition and Involuntary Resettlement), PS6 (Biodiversity Conservation), PS7 (Indigenous Peoples), and PS8 (Cultural Heritage), with mandatory compliance for IFC clients and adherence to host country laws and international good practice.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cmmi-capability-maturity-model-integration-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ifc-performance-standards-mining-ps1-ps8",
    "title": "IFC Performance Standards on Environmental and Social Sustainability",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The IFC Performance Standards on Environmental and Social Sustainability (PS1-PS8) apply to all IFC investment-and-advisory clients including extractive-sector projects; mining clients must demonstrate compliance through an Environmental and Social Management System covering risk assessment, labour, resource efficiency, community health, land acquisition, biodiversity, Indigenous Peoples, and cultural heritage as conditions of IFC financing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifc-performance-standards-2012-mining",
      "eiti-standard-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ifrs-15-revenue-contracts",
    "title": "IFRS 15 Revenue from Contracts with Customers - Five-Step Recognition Model (2014)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "IFRS 15 establishes a comprehensive five-step model for all entities to account for revenue arising from contracts with customers. The core principle, per IFRS 15:IN7, requires an entity to recognize revenue to depict the transfer of promised goods or services to customers in an amount that reflects the consideration to which the entity expects to be entitled.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-9-impairment",
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ifrs-16-leases",
    "title": "IFRS 16 Leases - Single Lessee Accounting Model and Right-of-Use Asset Recognition (2016)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "IFRS 16 requires lessees to recognize most leases on their balance sheets by recording a right-of-use (ROU) asset and a corresponding lease liability, effectively eliminating the distinction between operating and finance leases. This single lessee accounting model, outlined in IFRS 16.22, aims to provide a more faithful representation of a company's assets and liabilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-9-impairment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ifrs-16-leases-real-estate-accounting",
    "title": "IFRS 16 Leases - Right-of-Use Asset Recognition, Lease Liability Measurement and Lessee Disclosure for Real Estate Portfolios",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "IFRS 16 requires lessees to recognize nearly all leases on their balance sheet by recording a right-of-use (RoU) asset and a corresponding lease liability, eliminating the previous distinction between operating and finance leases. This applies to entities with real estate lease portfolios, fundamentally changing how property lease expenses and assets are reported (IFRS 16, Paragraph 22).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ifrs-17-contracts",
    "title": "IFRS 17: Insurance Contracts",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "IFRS 17 is the first truly international accounting standard for insurance contracts, replacing IFRS 4. It provides a consistent framework for recognizing profit and measuring insurance liabilities, using a current value approach to improve financial transparency and comparability across the global insurance sector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-9-impairment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ifrs-17-insurance-contracts-implementation-2023",
    "title": "IFRS 17 Insurance Contracts",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "IFRS 17 requires entities to recognise, measure, present, and disclose insurance contracts using a current measurement model that reflects the risk-adjusted present value of future cash flows and the contractual service margin, with profit recognised over the service period. It applies to all entities issuing insurance contracts within its scope, effective for annual reporting periods beginning on or after 1 January 2023, as specified in the standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-lps-110-capital-adequacy-life",
      "eu-commission-implementing-regulation-2015-2452-solvency",
      "ifrs-s2-climate"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ifrs-3-intangible-assets-media-content-rights",
    "title": "IFRS 3 Business Combinations - Media Content Rights Recognition: Identifiable Intangible Assets (Film Libraries, Music Catalogues, Broadcasting Licences), Fair Value Measurement, Amortisation under IAS 38, Impairment Testing and Disclosure Requirements",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "IFRS 3 requires an acquirer in a business combination to recognise and measure identifiable intangible assets such as media content rights (e.g., film libraries, music catalogues, broadcasting licences) at fair value as of the acquisition date, and to allocate acquisition cost accordingly. This applies to all entities applying IFRS that engage in business combinations involving media content assets, per the core principles in IFRS 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "berne-convention-1886-2024-literary-artistic-works",
      "iptc-photo-metadata",
      "exif-standard-metadata",
      "doi-digital-object-id"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ifrs-9-financial-instruments",
    "title": "IFRS 9 Financial Instruments - Classification, Measurement, Impairment and Hedge Accounting (2014)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "IFRS 9 establishes principles for the financial reporting of financial assets and financial liabilities, requiring entities to classify assets based on their business model and contractual cash flow characteristics (Section 4.1). It introduces a forward-looking expected credit loss (ECL) model for impairment (Section 5.5) and simplifies hedge accounting rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-9-impairment",
      "basel-iii-global-regulatory-framework",
      "guidance-on-model-risk-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ifrs-9-impairment",
    "title": "IFRS 9: Expected Credit Loss (ECL)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "IFRS 9 introduces the Expected Credit Loss (ECL) model for financial instruments, replacing the older 'Incurred Loss' model. It requires organizations to recognize impairments based on forward-looking macroeconomic forecasts and probability-weighted outcomes, reflecting a more realistic and proactive approach to credit risk management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-committee-financial-crisis-response"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ifrs-global-accounting",
    "title": "IFRS Global Standards",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Comprehensive adherence to International Financial Reporting Standards is mandated to ensure global financial integrity and transparency. This control framework requires strict application of foundational accounting principles, including the revenue recognition model stipulated by IFRS 15: Revenue from Contracts with Customers and the required capitalization of operating leases under IFRS 16: Leases. Organizations must implement the forward-looking expected credit loss impairment model as specified within IFRS 9: Financial Instruments, and also prepare consolidated financial statements adhering to the control principles of IFRS 10: Consolidated Financial Statements. All disclosures are required to follow the presentation structure governed by IAS 1: Presentation of Financial Statements, with a maximum reporting lag of 30 days. Furthermore, all digital submissions necessitate XBRL tagging aligned with the current IFRS Taxonomy 2023. Supporting these accounting mandates are stringent technical controls: financial data encryption at rest, mandatory role-based access controls, and enforced multi-factor authentication for financial systems access. To maintain data integrity and auditability, cryptographic journal entry signing is required, and complete audit trails must be preserved for a minimum retention period of 7 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifac-ethics-accountants",
      "gaap-us-framework",
      "pcaob-audit-standards",
      "sarbannes-oxley-404"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ifrs-s1-general",
    "title": "Sustainability (IFRS S1)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "IFRS S1 General Requirements for Disclosure of Sustainability-related Financial Information, issued by the ISSB (International Sustainability Standards Board) in June 2023 and effective for reporting periods beginning January 1, 2024, establishes the foundational framework for sustainability-related financial disclosures that are material to investors in assessing enterprise value. IFRS S1 requires entities to disclose sustainability-related risks and opportunities that could reasonably be expected to affect the entity's cash flows, access to finance, and cost of capital - the financial materiality lens, distinct from GRI's impact materiality approach. The standard requires disclosure across four core areas derived from the TCFD framework: governance, strategy, risk management, and metrics and targets. IFRS S1 is being adopted by over 40 jurisdictions and is foundational for entities listing on capital markets with sustainability disclosure requirements; failure to provide material sustainability disclosures exposes companies to securities law liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ifrs-s1-general-sustainability-disclosures",
    "title": "IFRS S1 General Requirements for Disclosure of Sustainability-related Financial Information",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2023-06-26",
    "bluf": "IFRS S1 requires an entity to disclose information about its sustainability-related risks and opportunities that is useful to primary users of general purpose financial reports in making decisions relating to providing resources to the entity. This standard, as outlined in Paragraph 1, sets the overall framework for sustainability disclosures, including governance, strategy, risk management, and metrics and targets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "issb-ifrs-s2-climate-2023",
      "tcfd-climate-related-financial-disclosures",
      "sasb-conceptual-framework",
      "gri-1-foundation"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ifrs-s2-climate",
    "title": "Climate Disclosures (IFRS S2)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Entities must provide comprehensive disclosures concerning significant climate-related risks and opportunities to meet investor information needs under IFRS S2. This mandate requires a detailed exposition of governance processes, controls, and procedures used for monitoring climate issues. The standard necessitates a robust strategy involving the identification and mapping of both physical risks plus transition risks. An entity’s climate resilience assessment must utilize scenario analysis, evaluating its strategy against a maximum temperature alignment scenario of 1.5 degrees Celsius. Quantitative disclosures are central, demanding the measurement of absolute gross Scope 1, Scope 2, and also Scope 3 greenhouse gas emissions, calculated in accordance with the GHG Protocol Corporate Standard. Furthermore, organizations must quantify the current and anticipated financial impacts of identified climate factors on their financial position, performance, and cash flows. These climate-related financial disclosures are to be reported concurrently with an entity’s annual financial statements, permitting a reporting lag of zero days. To ensure relevance, the disclosures must incorporate industry-specific metrics, leveraging the SASB Standards where applicable, thereby providing a complete picture of an enterprise's climate exposure and management approach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s1-general",
      "tcfd-climate-risk",
      "ghg-protocol-scope3",
      "issb-s1-s2-standard",
      "sasb-conceptual-framework",
      "iso-14064-ghg-reporting"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ifrs-s2-climate-related-disclosures",
    "title": "IFRS S2 Climate-related Disclosures",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "IFRS S2 requires an entity to disclose information about its climate-related risks and opportunities, enabling users of general purpose financial reports to assess their effects on the entity's cash flows, access to finance, and cost of capital over the short, medium, and long term. The core objective, outlined in Paragraph 1, mandates disclosures across four pillars: governance, strategy, risk management, and metrics and targets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "tcfd-climate-related-financial-disclosures",
      "ghg-protocol-scope3",
      "iso-14064-ghg-reporting",
      "csrd-eu-sustainability",
      "sasb-conceptual-framework"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ifs-food-standard",
    "title": "IFS Food (International Featured)",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "International Featured Standards (IFS) Food certification provides a framework for ensuring food product safety and quality, aligned with the Global Food Safety Initiative's GFSI Benchmarking Requirements Version 2020.1. Compliance mandates a robust governance structure, as articulated in IFS Food Standard Version 8, Section 1, where senior management review must occur at a maximum interval of 12 months. Central to this standard is the food safety and quality management system, requiring a fully implemented and active HACCP system based on the General Principles of Food Hygiene from the Codex Alimentarius Commission. Beyond process controls, organizations must address intentional threats. This includes implementing a comprehensive food defense plan per Section 4.21 and maintaining an active food fraud vulnerability assessment as specified in Section 4.20. Operational effectiveness is verified through stringent programmatic controls, including an active internal audit program and an active supplier approval monitoring process. Furthermore, an active allergen management control system and an active environmental monitoring program are non-negotiable prerequisites. System responsiveness is rigorously tested; traceability must enable a full recall test within a maximum of 4 hours. All identified non-conformities necessitate closure of corrective actions within a 30-day maximum period, and product specifications demand a formal review at least every 12 months to ensure continued accuracy and compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gfsi-benchmarking",
      "haccp-food-safety",
      "codex-alimentarius-gen",
      "iso-22000-food-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iia-internal-audit-ippf",
    "title": "IIA Internal Audit (IPPF)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Operational integrity and governance are upheld through rigorous adherence to the Institute of Internal Auditors' International Professional Practices Framework (IPPF), which establishes mandatory guidance for the professional practice of internal auditing. This compliance framework mandates that the internal audit activity remains independent and objective, requiring the chief audit executive to report functionally to the board or its equivalent governing body. Performance is systematically evaluated against key metrics; for instance, the annual audit plan must achieve a completion rate exceeding 95 percent to be considered satisfactory. Furthermore, a robust quality assurance and improvement program is obligatory, entailing continuous internal monitoring and a formal external quality assessment at least once every five years to affirm conformance with the Standards. Personnel competence is also a critical component, with each auditor required to complete a minimum of 40 hours of continuing professional education each year, ensuring their skills remain current. The BIDDA platform systematically verifies these requirements, analyzing submitted evidence to confirm the audit function’s charter, resource adequacy, and adherence to the Code of Ethics, thereby providing assurance that the internal audit activity effectively adds value and improves an organization’s operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt",
      "iso-37301-compliance",
      "sarbannes-oxley-404",
      "iso-19011-audit-guidelines"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "il-mandatory-tenders-law-1992-takanot-hove-mikhrazim",
    "title": "Israel Mandatory Tenders Law 5752-1992 (Chok Chovat HaMichrazim) and Mandatory Tenders Regulations 5753-1993",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Israeli Mandatory Tenders Law 5752-1992 (Chok Chovat HaMichrazim, in Hebrew) and the Mandatory Tenders Regulations 5753-1993 (Takanot Chovat HaMichrazim, issued thereunder) constitute the principal Israeli legal framework governing procurement of goods, services, and works by the State of Israel including government ministries, government agencies, local authorities (municipalities), and statutory corporations including government companies under the Government Companies Law 5735-1975. The 1992 Law established mandatory tendering as the default procurement procedure for State entities and constitutes a comprehensive procurement reform that replaced the prior discretionary regime. The Mandatory Tenders Regulations 5753-1993 (in Hebrew, Takanot Chovat HaMichrazim) prescribe the procedural detail. The Israeli Ministry of Finance Accountant General's Office (HaChasham HaKlali, Misrad HaOtzar) is the central procurement policy authority through the Government Procurement Administration (Minhal HaRekhesh HaMemshalti). The Israeli Government e-Procurement Portal (Mimshal Zamin / mimshal-zamin.gov.il and the centralised tender website) is the official tender publication platform. Procurement methods established by the Mandatory Tenders Regulations comprise (a) Public Tender (Michraz Tziburi, the default open public tender), (b) Closed Tender (Michraz Sagur, with prequalification), (c) Tender among Pre-Approved Suppliers (Michraz bein Sapakim Mukharim), and (d) exemption from tender (Petur miMichraz) under the prescribed exceptions in Regulation 3 to 8 of the 1993 Regulations including emergency, sole-source for technical reasons, small-value below the prescribed threshold, urgency, and specific State-strategic considerations. The 1993 Regulations Regulation 5 prescribes the small-value exemption threshold. Israel is a party to the WTO Government Procurement Agreement (GPA) 2012 and operates within the broader framework of the EU-Israel Association Agreement procurement provisions and the US-Israel Free Trade Area Implementation Act 1985.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "il-privacy-protection-law-amendment-13-2024",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "il-ppa-1981",
    "title": "Israel Privacy Protection Act 5741-1981 - Data Protection and Privacy Authority Enforcement",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Israel's Hok Haganat HaPrivatiyut (חוק הגנת הפרטיות - Privacy Protection Act 5741-1981, also cited as the Privacy Protection Act 1981), enacted by the Knesset and published in Sefer HaHukim (the Book of Laws) No. 1011 on 27 February 1981, is Israel's primary personal data protection legislation. The Privacy Protection Act 1981 was a pioneering privacy law at the time of enactment, establishing fundamental rights to privacy alongside data protection obligations for database holders. The Act has been substantially amended over the decades, with key amendments including the Privacy Protection Regulations (Data Security) 5777-2017, which introduced comprehensive data security obligations. The enforcement authority is the Reshut HaHaganat HaPrivatiyut (רשות הגנת הפרטיות - Privacy Protection Authority, PPA), which was established as an independent authority under the Privacy Protection Act and now operates under the Justice Ministry. Israel obtained EU GDPR adequacy status: the European Commission originally issued an adequacy decision for Israel in 2011, and Israel's adequacy status has been maintained through Commission review, reflecting the country's robust data protection framework. The PPA is Israel's data protection supervisory authority and is responsible for maintaining the Database Registry, investigating complaints, issuing enforcement orders, and conducting inspections. Key features: (1) Database Holder Registration - databases containing personal information meeting specified threshold criteria must be registered with the PPA's Database Registry (Misdar HaMaagarim - מסד הנתונים); (2) Data security regulations - the Privacy Protection Regulations (Data Security) 5777-2017 impose detailed security obligations including tiered security levels (Basic, Medium, High) based on database characteristics; (3) Rights of information subjects - individuals have the right to access information held about them, request corrections, and restrict use for direct marketing; (4) Information subject consent - the use of personal information for purposes beyond the original collection purpose generally requires consent; (5) Sensitive information - information about a person's political views, sexual conduct, health, religious belief or practice, physical or mental disability, criminal conviction, or membership in a trade union is treated as sensitive information requiring heightened protection; (6) Cross-border transfer restrictions - transfer of personal information outside Israel is subject to restrictions; the PPA maintains guidance on international data transfers; (7) Criminal and civil liability - the Privacy Protection Act establishes criminal penalties (imprisonment and fines) and civil liability for privacy violations; (8) Data Breach Notification: Israel introduced mandatory breach notification via regulatory amendment - serious breaches must be reported to the PPA and to affected individuals. Israel is a significant technology hub ('Startup Nation'), and the PPA has been active in enforcement against technology companies, healthcare providers, and financial institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-adequacy-decisions-article-45",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "il-privacy-protection-law-amendment-13-2024",
    "title": "Israel Privacy Protection Law Amendment 13 of 2024 - GDPR-Aligned Reforms in Force 14 August 2025",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Organisations subject to the Israeli Privacy Protection Law must, from 14 August 2025, comply with the sweeping reforms in Amendment 13, including appointment of a qualified Privacy Protection Officer where thresholds are met (large-scale processing of sensitive data, systematic monitoring, public authorities or data brokers), transparent and easy-to-understand information about what data is collected, why it is processed, and who will have access to it, additional disclosure rules for biometric data and information used in AI systems, meaningful informed and voluntary consent that is in most cases explicit, security obligations under the Protection of Privacy Regulations (Data Security) 5777 as strengthened by Amendment 13, data subject rights to correction and deletion, and exposure to Privacy Protection Authority penalties of up to 5 percent of annual turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "illinois-bipa-health-ai-2026",
    "title": "Illinois BIPA Biometric & Health AI Compliance 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "BIPA requires explicit consent for biometric data collection in health AI tools (facial recognition, voice analysis). 2026 enforcement focuses on telehealth and digital therapeutics.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c001-hours-of-work-industry-1919",
    "title": "ILO Convention No. 1 (C001) - Hours of Work (Industry), 1919",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 1 limits the working hours of persons in industrial undertakings to eight in the day and forty-eight in the week, with defined exceptions for continuous processes, shift work, accidents and urgent work, regulation of permitted overtime and rates of pay, and requirements on employers to post notices of working hours and rest periods and to keep records of additional hours worked.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c013-white-lead-painting-1921",
    "title": "ILO Convention No. 13 (C013) - White Lead (Painting), 1921",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 13 requires States to prohibit the use of white lead, sulphate of lead and products containing those pigments in the internal painting of buildings, subject to limited exceptions, to prohibit the employment of males under 18 and of all females in industrial painting work involving these substances, and to regulate their permitted use through hygiene precautions and the collection of statistics on lead poisoning among painters.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c136-benzene-1971",
      "ilo-convention-155-occupational-safety-1981"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c014-weekly-rest-industry-1921",
    "title": "ILO Convention No. 14 (C014) - Weekly Rest (Industry), 1921",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 14 requires that staff employed in industrial undertakings enjoy a weekly rest period of at least 24 consecutive hours in every seven days, granted simultaneously to the whole staff where possible and aligned with established traditions, with exceptions authorised only by the competent authority and compensatory rest provided for any suspension.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c030-hours-of-work-commerce-offices-1930",
    "title": "ILO Convention No. 30 (C030) - Hours of Work (Commerce and Offices), 1930",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 30 limits the hours of work of persons in commerce and offices to eight in the day and forty-eight in the week, allowing distribution of the weekly hours over the days with a daily maximum of ten hours, with defined permanent and temporary exceptions established by regulation after consultation, overtime paid at a premium, and requirements to post hours and keep records.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c001-hours-of-work-industry-1919",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c081-labour-inspection-1947",
    "title": "ILO Convention No. 81 (C081) - Labour Inspection, 1947",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 81 is a governance (priority) Convention requiring ratifying States to maintain a system of labour inspection in industrial workplaces to secure the enforcement of legal provisions on conditions of work and the protection of workers. Inspectors must be public officials with stable employment, empowered to enter workplaces freely, examine records and remedy dangerous defects, and violations and obstruction must be subject to adequate, effectively enforced penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-convention-155-occupational-safety-1981"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c087-freedom-of-association-right-to-organise-1948",
    "title": "ILO Convention No. 87 (C087) - Freedom of Association and Protection of the Right to Organise, 1948",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 87 is a fundamental Convention guaranteeing that workers and employers may freely establish and join organisations of their own choosing without previous authorisation, and that those organisations may operate, federate and affiliate internationally free from interference or dissolution by administrative authority. Ratifying States must take all necessary measures to ensure the free exercise of the right to organise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998",
      "ilo-fundamental-rights-work",
      "ilo-c190-violence-harassment-2019"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-c088-employment-service-1948",
    "title": "ILO Convention No. 88 (C088) - Employment Service, 1948",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 88 requires States to maintain a free public employment service whose essential duty is to achieve the best possible organisation of the employment market, through a national network of offices, effective recruitment and placement, specialisation by occupations and industries, special arrangements for juveniles, a stable and qualified staff independent of changes of government, and cooperation with employers and workers organisations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c181-private-employment-agencies-1997",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c094-labour-clauses-public-contracts-1949",
    "title": "ILO Convention No. 94 (C094) - Labour Clauses (Public Contracts), 1949",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 94 requires that public contracts include labour clauses ensuring the workers concerned wages, hours of work and other labour conditions no less favourable than those established for the same work in the district by collective agreement, arbitration award or national laws, and that adequate health, safety and welfare provisions apply, with publicity of the clauses, posting of notices, recordkeeping and sanctions including the withholding of contracts for non-compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c095-protection-of-wages-1949",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c095-protection-of-wages-1949",
    "title": "ILO Convention No. 95 (C095) - Protection of Wages, 1949",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 95 is a technical Convention protecting workers wages by requiring payment in legal tender, regulating partial payment in kind, requiring direct and regular payment to the worker, protecting the worker freedom to dispose of wages, limiting deductions to prescribed conditions, prioritising wages in insolvency, and requiring workers to be informed of wage conditions, supported by adequate supervision and penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-mlc-2006"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "ilo-c097-migration-for-employment-1949",
    "title": "ILO Convention No. 97 (C097) - Migration for Employment (Revised), 1949",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 97 requires States to maintain a free service to assist migrants for employment with accurate information, act against misleading propaganda, facilitate departure, journey and reception, provide appropriate medical services, permit the transfer of earnings, and apply to lawfully resident immigrants treatment no less favourable than to nationals in respect of remuneration, social security and related employment conditions, without discrimination as to nationality, race, religion or sex.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c098-right-to-organise-collective-bargaining-1949",
    "title": "ILO Convention No. 98 (C098) - Right to Organise and Collective Bargaining, 1949",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 98 is a fundamental Convention protecting workers against anti-union discrimination in employment, protecting workers and employers organisations against mutual interference, and requiring States to establish machinery to safeguard the right to organise and to promote voluntary collective bargaining for the regulation of terms and conditions of employment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998",
      "ilo-fundamental-rights-work",
      "ilo-c087-freedom-of-association-right-to-organise-1948"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c100-equal-remuneration-1951",
    "title": "ILO Convention No. 100 (C100) - Equal Remuneration, 1951",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 100 is a fundamental Convention requiring ratifying States to ensure the application of the principle of equal remuneration for men and women workers for work of equal value, covering basic wage and any additional emoluments, through national laws, wage-fixing machinery, collective agreements or a combination, supported by objective job appraisal and cooperation with employers and workers organisations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998",
      "ilo-fundamental-rights-work",
      "ilo-convention-111-discrimination-employment-education"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c102-social-security-minimum-standards-1952",
    "title": "ILO Convention No. 102 (C102) - Social Security (Minimum Standards), 1952",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 102 sets the minimum standards for the nine branches of social security (medical care, sickness, unemployment, old-age, employment injury, family, maternity, invalidity and survivors benefits). A ratifying State must accept Part I and at least three branches including one of the long-term or unemployment branches, secure benefits to prescribed classes of protected persons, guarantee minimum benefit levels, and accept general responsibility for the proper administration and financing of the schemes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c105-abolition-of-forced-labour-1957",
    "title": "ILO Convention No. 105 (C105) - Abolition of Forced Labour, 1957",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 105 is a fundamental Convention requiring ratifying States to suppress and not to make use of any form of forced or compulsory labour for five specified purposes: political coercion or education, mobilisation for economic development, labour discipline, punishment for participating in strikes, and racial, social, national or religious discrimination, and to take effective measures to secure its immediate and complete abolition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998",
      "ilo-fundamental-rights-work",
      "ilo-p29-forced-labour-protocol-2014"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c106-weekly-rest-commerce-offices-1957",
    "title": "ILO Convention No. 106 (C106) - Weekly Rest (Commerce and Offices), 1957",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 106 entitles persons employed in commerce and offices to an uninterrupted weekly rest period of at least 24 hours in every seven days, granted so far as possible simultaneously and on the day established by tradition, with special weekly-rest schemes and temporary exemptions permitted only under defined conditions and with compensatory rest.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c110-plantations-1958",
    "title": "ILO Convention No. 110 (C110) - Plantations, 1958",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 110 establishes minimum labour standards for plantation workers across recruitment, medical examination, wages, annual leave, maternity protection, freedom of association and labour inspection, requiring States to regulate recruiting, protect wages, grant paid annual holiday, provide maternity protection, guarantee the right to organise, and maintain a labour inspection system covering plantation workplaces.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c115-radiation-protection-1960",
    "title": "ILO Convention No. 115 (C115) - Radiation Protection, 1960",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 115 requires States to take all appropriate steps to ensure effective protection of workers against ionising radiations, by fixing maximum permissible doses and amounts of radioactive substances, restricting the work of young persons, displaying warnings and informing workers, providing appropriate medical examinations, and specifying circumstances for notification, investigation and remedial action.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c120-hygiene-commerce-offices-1964",
    "title": "ILO Convention No. 120 (C120) - Hygiene (Commerce and Offices), 1964",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 120 requires States to maintain laws ensuring the hygiene of premises used by workers in commerce and offices, enforced by inspection, with premises and equipment properly maintained and kept clean, adequate ventilation, lighting and temperature, sufficient sanitary and washing facilities, supply of drinking water, seating, and protection from noise and vibration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c121-employment-injury-benefits-1964",
    "title": "ILO Convention No. 121 (C121) - Employment Injury Benefits, 1964",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 121 requires States to provide benefits for employment injury covering the contingencies of a morbid condition, incapacity for work, loss of earning capacity and death of the breadwinner, secured to prescribed classes of employees, through medical care and allied benefits, periodical cash payments at prescribed minimum rates, and survivors benefits, with a defined list of occupational diseases and a right of appeal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c102-social-security-minimum-standards-1952",
      "ilo-convention-155-occupational-safety-1981"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c122-employment-policy-1964",
    "title": "ILO Convention No. 122 (C122) - Employment Policy, 1964",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 122 is a governance (priority) Convention requiring ratifying States to declare and pursue, as a major goal, an active policy designed to promote full, productive and freely chosen employment. The policy must aim at work for all who are available and seeking work, the productivity of that work, and freedom of choice of employment without discrimination, and must be kept under review and decided in consultation with representatives of employers and workers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c127-maximum-weight-1967",
    "title": "ILO Convention No. 127 (C127) - Maximum Weight, 1967",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 127 protects workers from the manual transport of loads likely to jeopardise their health or safety, requiring that no worker be required or permitted to carry such loads, that workers be trained before assignment, that suitable technical devices be used as far as possible, that the assignment of women and young workers to manual transport be limited, and that national measures be adopted in consultation with the social partners.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-c128-invalidity-old-age-survivors-benefits-1967",
    "title": "ILO Convention No. 128 (C128) - Invalidity, Old-Age and Survivors Benefits, 1967",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 128 sets standards for invalidity, old-age and survivors benefits, requiring States to secure benefit to prescribed classes of protected persons, define the covered contingencies, provide periodical cash benefits meeting prescribed replacement rates, adjust benefits following substantial changes in the cost of living, limit suspension grounds, and provide a right of appeal, with general responsibility for the proper administration and financing of the schemes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c102-social-security-minimum-standards-1952",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c129-labour-inspection-agriculture-1969",
    "title": "ILO Convention No. 129 (C129) - Labour Inspection (Agriculture), 1969",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 129 is a governance (priority) Convention requiring ratifying States to maintain a system of labour inspection in agriculture covering agricultural undertakings, to secure the enforcement of legal provisions on conditions of work and the protection of workers engaged in agriculture. Inspectors must be qualified, with stable employment, empowered to enter agricultural workplaces freely and to remedy defects, and the system must provide adequate penalties for violations and obstruction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c081-labour-inspection-1947",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c130-medical-care-sickness-benefits-1969",
    "title": "ILO Convention No. 130 (C130) - Medical Care and Sickness Benefits, 1969",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 130 requires States to secure medical care of a curative and preventive nature and sickness benefit in the form of periodical cash payments, to prescribed classes of employees or residents, covering general practitioner and specialist care, pharmaceuticals, hospitalisation and dental and medical rehabilitation, with sickness cash benefit during incapacity for work, and a right of appeal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c102-social-security-minimum-standards-1952",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c131-minimum-wage-fixing-1970",
    "title": "ILO Convention No. 131 (C131) - Minimum Wage Fixing, 1970",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 131 is a technical Convention requiring ratifying States to establish a system of minimum wages covering all appropriate groups of wage earners, giving minimum wages the force of law with sanctions for non-application, determining levels with regard to the needs of workers and economic factors, operating wage-fixing machinery with the full consultation and participation of employers and workers, and ensuring effective enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-c095-protection-of-wages-1949"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c132-holidays-with-pay-1970",
    "title": "ILO Convention No. 132 (C132) - Holidays with Pay (Revised), 1970",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 132 entitles every covered employed person to an annual paid holiday of at least three working weeks for one year of service, with a proportionate holiday for shorter service, payment of at least normal remuneration in advance, limits on dividing and postponing the holiday, and protection of the entitlement on termination of employment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c135-workers-representatives-1971",
    "title": "ILO Convention No. 135 (C135) - Workers Representatives, 1971",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 135 requires that workers representatives in an undertaking enjoy effective protection against any prejudicial act, including dismissal, based on their status or activities as a representative, and that they be afforded appropriate facilities to carry out their functions promptly and efficiently, while ensuring that the existence of elected representatives is not used to undermine trade unions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c098-right-to-organise-collective-bargaining-1949",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c136-benzene-1971",
    "title": "ILO Convention No. 136 (C136) - Benzene, 1971",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 136 regulates occupational exposure to benzene and products containing benzene, requiring substitution with harmless or less harmful products where available, prevention of the escape of benzene vapour, use of enclosed work processes, observance of a maximum atmospheric concentration limit, provision of personal protective equipment, pre-employment and periodic medical examinations, prohibition of exposure for pregnant and young workers, and worker information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-c139-occupational-cancer-1974",
    "title": "ILO Convention No. 139 (C139) - Occupational Cancer, 1974",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 139 requires States to periodically determine the carcinogenic substances and agents to which occupational exposure is prohibited or subject to authorisation, to make every effort to replace them with non-carcinogenic or less harmful substitutes, to minimise the number of exposed workers and the duration and degree of exposure, to prescribe protective measures and a recording system, to inform exposed workers, and to provide appropriate medical examinations during and after employment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c140-paid-educational-leave-1974",
    "title": "ILO Convention No. 140 (C140) - Paid Educational Leave, 1974",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 140 requires States to formulate and apply a policy to promote the granting of paid educational leave for training at any level, general, social and civic education, and trade-union education, financed on a regular and adequate basis, integrated with vocational and adult education policies, with the period of leave counting as service and not denied on discriminatory grounds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-111-discrimination-employment-education",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c141-rural-workers-organisations-1975",
    "title": "ILO Convention No. 141 (C141) - Rural Workers Organisations, 1975",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 141 requires States to recognise the right of all categories of rural workers, whether wage earners or self-employed, to establish and join organisations of their own choosing without previous authorisation, to make it an objective of national policy to facilitate the establishment and growth of strong and independent rural workers organisations, and to adopt and carry out an active policy encouraging those organisations while fully respecting the principles of freedom of association.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c087-freedom-of-association-right-to-organise-1948",
      "ilo-c098-right-to-organise-collective-bargaining-1949"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c142-human-resources-development-1975",
    "title": "ILO Convention No. 142 (C142) - Human Resources Development, 1975",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 142 requires States to adopt and develop comprehensive and coordinated policies and programmes of vocational guidance and vocational training closely linked with employment, to establish open, flexible and complementary education and training systems, to extend vocational guidance and continuing employment information, to extend lifelong training systems for young persons and adults in all sectors, and to formulate the policies in cooperation with employers and workers organisations and without discrimination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-111-discrimination-employment-education",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c143-migrant-workers-supplementary-1975",
    "title": "ILO Convention No. 143 (C143) - Migrant Workers (Supplementary Provisions), 1975",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 143 requires States to respect the basic human rights of all migrant workers, suppress clandestine migration and illegal employment of migrants, protect migrant workers who lose employment from being treated as irregular merely for that reason, and declare and pursue a national policy promoting equality of opportunity and treatment for lawfully resident migrant workers in employment, social security, trade-union and cultural rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c097-migration-for-employment-1949",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c144-tripartite-consultation-1976",
    "title": "ILO Convention No. 144 (C144) - Tripartite Consultation (International Labour Standards), 1976",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 144 is a governance (priority) Convention requiring ratifying States to operate procedures ensuring effective tripartite consultations between representatives of government, employers and workers on matters concerning international labour standards, including ILC agenda items, the submission of newly adopted instruments to competent authorities, the re-examination of unratified Conventions, reports on ratified Conventions, and proposals for denunciation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c146-seafarers-annual-leave-1976",
    "title": "ILO Convention No. 146 (C146) - Seafarers Annual Leave with Pay, 1976",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 146 entitles seafarers to annual leave with pay of a specified minimum length of not less than 30 calendar days for one year of service, with a proportionate entitlement for shorter service, exclusion of public holidays and sick leave from the leave, payment of normal remuneration, and protection of the entitlement including on termination of employment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-mlc-2006",
      "ilo-c132-holidays-with-pay-1970"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c147-merchant-shipping-minimum-standards-1976",
    "title": "ILO Convention No. 147 (C147) - Merchant Shipping (Minimum Standards), 1976",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 147 requires States to have laws for ships registered in their territory laying down safety, social security and shipboard employment and living standards substantially equivalent to the relevant international conventions, to exercise effective jurisdiction and control, to verify conformity, to provide procedures for the engagement of seafarers and the investigation of complaints, and to apply port-state control where a ship calling at its port does not conform to the standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-mlc-2006",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c148-working-environment-air-noise-vibration-1977",
    "title": "ILO Convention No. 148 (C148) - Working Environment (Air Pollution, Noise and Vibration), 1977",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 148 requires States to prescribe measures for the prevention and control of, and protection against, occupational hazards in the working environment due to air pollution, noise and vibration, with the employer responsible for compliance, the establishment of exposure criteria and limits, keeping the working environment free from hazards by technical and organisational measures, health supervision of exposed workers, and provision of information, instruction and protective equipment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-c149-nursing-personnel-1977",
    "title": "ILO Convention No. 149 (C149) - Nursing Personnel, 1977",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 149 requires States to adopt and apply a policy concerning nursing services and nursing personnel that provides the education, training, employment and working conditions likely to attract and retain persons in the profession, to regulate the practice of nursing, to ensure the participation of nursing personnel in decisions affecting them, to provide conditions of employment and work at least equivalent to those of other workers, and to improve occupational health and safety adapted to the nature of nursing work.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c150-labour-administration-1978",
    "title": "ILO Convention No. 150 (C150) - Labour Administration, 1978",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 150 requires States to ensure the organisation and effective operation of a system of labour administration, the functions and responsibilities of which are properly coordinated, covering national labour policy preparation and review, employment and human resources, conditions of work and terms of employment, and labour relations, with consultation of employers and workers, and a staff that is suitably qualified, independent and adequately resourced.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c081-labour-inspection-1947",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c152-occupational-safety-health-dock-work-1979",
    "title": "ILO Convention No. 152 (C152) - Occupational Safety and Health (Dock Work), 1979",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 152 requires States to prescribe measures for safety and health in dock work, providing and maintaining safe workplaces, equipment and methods of work, with duties on workers not to misuse safety devices, safe means of access to ships and holds, safe transport of workers by water, testing and certification of lifting appliances and loose gear, and medical examination and protective equipment for dockworkers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-mlc-2006"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c153-hours-of-work-rest-road-transport-1979",
    "title": "ILO Convention No. 153 (C153) - Hours of Work and Rest Periods (Road Transport), 1979",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 153 limits the driving and working time of professional drivers in road transport, requiring a break after a maximum period of continuous driving, a ceiling on total daily and weekly driving time, a minimum daily rest period, restrictions on the working day, the recording of hours through an individual control book or tachograph, and an adequate inspection system with penalties for breaches.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c001-hours-of-work-industry-1919",
      "ilo-convention-155-occupational-safety-1981"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c154-collective-bargaining-1981",
    "title": "ILO Convention No. 154 (C154) - Collective Bargaining, 1981",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 154 promotes free and voluntary collective bargaining covering all employers and groups of workers in the branches of activity to which it applies, requiring measures to make bargaining possible for all employers and workers, to progressively extend its subject matter, to encourage rules of procedure agreed between the parties, and to ensure bodies and procedures for the settlement of labour disputes contribute to the promotion of bargaining without hampering its freedom.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c098-right-to-organise-collective-bargaining-1949",
      "ilo-c087-freedom-of-association-right-to-organise-1948"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c156-workers-family-responsibilities-1981",
    "title": "ILO Convention No. 156 (C156) - Workers with Family Responsibilities, 1981",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 156 requires States to make it an aim of national policy to enable persons with family responsibilities who are engaged or wish to engage in employment to do so without discrimination and, as far as possible, without conflict between employment and family responsibilities, through measures in vocational guidance and training, community services and planning, and a guarantee that family responsibilities are not a valid reason for dismissal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-111-discrimination-employment-education",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c158-termination-of-employment-1982",
    "title": "ILO Convention No. 158 (C158) - Termination of Employment, 1982",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 158 is a technical Convention requiring that the employment of a worker not be terminated unless there is a valid reason connected with capacity, conduct or the operational requirements of the undertaking. It lists invalid grounds, requires an opportunity to defend before dismissal for conduct or performance, a right to appeal to an impartial body, notice or compensation, severance benefits, and consultation and notification for terminations for economic reasons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "ilo-c159-vocational-rehabilitation-employment-disabled-1983",
    "title": "ILO Convention No. 159 (C159) - Vocational Rehabilitation and Employment (Disabled Persons), 1983",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 159 requires States to formulate, implement and periodically review a national policy on vocational rehabilitation and employment of disabled persons, based on the principle of equal opportunity between disabled and other workers, ensuring suitable vocational guidance, training, placement and employment services in both urban and rural areas, and consulting representative organisations including those of and for disabled persons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-111-discrimination-employment-education",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-c160-labour-statistics-1985",
    "title": "ILO Convention No. 160 (C160) - Labour Statistics, 1985",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 160 requires States to regularly collect, compile and publish basic labour statistics, progressively expanded according to resources, using concepts, definitions and methodology aligned with international standards, consulting the representative organisations of employers and workers, covering economically active population, employment and unemployment, earnings and hours of work, consumer prices, and occupational injuries, and communicating the statistics to the ILO.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c161-occupational-health-services-1985",
    "title": "ILO Convention No. 161 (C161) - Occupational Health Services, 1985",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 161 requires States to formulate, implement and periodically review a coherent national policy on occupational health services and to progressively develop such services for all workers, with essentially preventive functions advising employers, workers and their representatives on maintaining a safe and healthy working environment, while preserving the confidentiality of personal health data and the multidisciplinary, independent character of the services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-c162-asbestos-1986",
    "title": "ILO Convention No. 162 (C162) - Asbestos, 1986",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 162 requires States to prescribe by national laws the measures to prevent and control health hazards from occupational exposure to asbestos, making employers responsible for compliance, providing for the replacement of asbestos by safer materials where possible, prohibiting crocidolite and spraying of asbestos, setting exposure limits, regulating demolition and asbestos removal, monitoring the working environment and workers health, and informing and training workers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c164-health-protection-medical-care-seafarers-1987",
    "title": "ILO Convention No. 164 (C164) - Health Protection and Medical Care (Seafarers), 1987",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 164 requires States to ensure health protection and medical care for seafarers on board ship comparable to that available to workers ashore, including a medicine chest and medical equipment with a medical guide, radio or satellite medical advice, a qualified doctor on larger ships engaged on long voyages, a trained person in charge of medical care on other ships, hospital accommodation on larger ships, and a standard medical report form.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-mlc-2006",
      "ilo-convention-155-occupational-safety-1981"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c166-repatriation-of-seafarers-1987",
    "title": "ILO Convention No. 166 (C166) - Repatriation of Seafarers (Revised), 1987",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 166 entitles seafarers to repatriation in defined circumstances, places responsibility on the shipowner to arrange and pay for repatriation by appropriate and expeditious means (normally by air), requires the competent authority to arrange and recover the cost of repatriation if the shipowner fails, prohibits charging the cost to the seafarer except in cases of serious default, protects accrued leave, and requires the text of the Convention to be available to the crew.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-mlc-2006",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-c168-employment-promotion-protection-unemployment-1988",
    "title": "ILO Convention No. 168 (C168) - Employment Promotion and Protection against Unemployment, 1988",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 168 requires States to coordinate their system of protection against unemployment with employment policy, declaring the promotion of full, productive and freely chosen employment a priority, establishing special programmes for disadvantaged groups, covering full and partial unemployment and suspension of earnings, providing unemployment benefit as periodical payments at a prescribed replacement level, limiting disqualification grounds, and providing a right of appeal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c102-social-security-minimum-standards-1952",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c170-chemicals-1990",
    "title": "ILO Convention No. 170 (C170) - Chemicals, 1990",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 170 requires States to formulate a coherent policy on safety in the use of chemicals at work, and imposes a system of classification, labelling and marking of chemicals, provision of chemical safety data sheets, and employer obligations to identify chemicals, assess and control exposure risks, monitor and keep records, dispose of chemicals safely, and inform and train workers, with corresponding worker rights and duties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c171-night-work-1990",
    "title": "ILO Convention No. 171 (C171) - Night Work, 1990",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 171 requires specific measures to protect night workers, including free health assessments, transfer of workers found unfit for night work, alternatives to night work around maternity, recognition of the nature of night work through compensation, maternity protection without loss of employment, appropriate social services, and consultation of workers representatives before introducing night-work schedules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-c172-working-conditions-hotels-restaurants-1991",
    "title": "ILO Convention No. 172 (C172) - Working Conditions (Hotels and Restaurants), 1991",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 172 requires States to adopt and apply a policy to improve the working conditions of workers in hotels, restaurants and similar establishments, ensuring reasonable hours of work and overtime provisions, advance notice of work schedules, minimum daily and weekly rest, paid annual leave, that tips do not substitute for a basic wage, and prohibiting the sale and purchase of employment in those establishments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c001-hours-of-work-industry-1919",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c174-prevention-major-industrial-accidents-1993",
    "title": "ILO Convention No. 174 (C174) - Prevention of Major Industrial Accidents, 1993",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 174 requires States to formulate a coherent national policy for the protection of workers, the public and the environment against the risk of major accidents, establish a system for identifying major hazard installations, and impose employer duties to identify installations, maintain a documented system of major hazard control, prepare safety reports, report accidents, and provide emergency information, supported by competent-authority siting policy and inspection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c170-chemicals-1990",
      "ilo-convention-155-occupational-safety-1981"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c175-part-time-work-1994",
    "title": "ILO Convention No. 175 (C175) - Part-Time Work, 1994",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 175 requires that part-time workers receive the same protection as comparable full-time workers in respect of the right to organise and bargain collectively, occupational safety and health, and non-discrimination, that their basic wage is not lower on a proportional basis solely because they work part time, and that they enjoy equivalent conditions in social security, maternity, termination, leave and holidays.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c176-safety-health-mines-convention-1995",
    "title": "ILO Convention C176 Safety and Health in Mines 1995",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "ILO Convention No. 176 on Safety and Health in Mines, adopted by the International Labour Conference in June 1995 and in force since 5 June 1998, requires ratifying member states to formulate, implement, and periodically review a coherent national policy on safety and health in mines, and to ensure that mine employers implement a comprehensive safety management system covering hazard identification, risk assessment, emergency preparedness, and workers' rights to remove themselves from imminent danger.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-c177-home-work-1996",
    "title": "ILO Convention No. 177 (C177) - Home Work, 1996",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 177 requires States to adopt, implement and periodically review a national policy on home work that promotes equality of treatment between homeworkers and other wage earners, covering the right to organise, protection against discrimination, occupational safety and health, remuneration, statutory social security, access to training, minimum age and maternity protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c181-private-employment-agencies-1997",
    "title": "ILO Convention No. 181 (C181) - Private Employment Agencies, 1997",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 181 regulates private employment agencies, requiring protection of worker personal data, non-discrimination, a prohibition on charging fees to workers, protection of migrant workers against abuse, prohibition of child labour, allocation of responsibilities between agencies and user enterprises, and protection of the rights of workers employed by agencies including freedom of association and collective bargaining.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-fundamental-rights-work"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c182-worst-forms-of-child-labour-1999",
    "title": "ILO Convention No. 182 (C182) - Worst Forms of Child Labour, 1999",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 182 is a fundamental Convention requiring ratifying States to take immediate and effective measures to secure the prohibition and elimination of the worst forms of child labour as a matter of urgency for all persons under 18. The worst forms comprise slavery and trafficking, child prostitution and pornography, use of children in illicit activities, and hazardous work, supported by monitoring, programmes of action and time-bound remedial measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998",
      "ilo-fundamental-rights-work",
      "ilo-convention-138-minimum-age-1973"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-c183-maternity-protection-2000",
    "title": "ILO Convention No. 183 (C183) - Maternity Protection, 2000",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 183 is a technical Convention requiring ratifying States to protect the health of pregnant and breastfeeding women, to provide maternity leave of not less than 14 weeks including compulsory post-natal leave, leave for illness or complications, adequate cash and medical benefits, employment protection against dismissal connected with maternity, a guaranteed right to return to work, protection against maternity-based discrimination, and the right to daily breastfeeding breaks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "ilo-c190-violence-harassment-2019"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-c184-safety-health-agriculture-2001",
    "title": "ILO Convention No. 184 (C184) - Safety and Health in Agriculture, 2001",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 184 requires States to formulate a coherent national policy on safety and health in agriculture, designate a competent authority and enforcement system, and imposes employer duties to ensure workers safety and health, carry out risk assessments and take preventive measures, with worker rights to information, consultation and removal from danger, and requirements on machinery safety, handling of chemicals, animal and biological risks, and agricultural installations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-c129-labour-inspection-agriculture-1969"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c185-seafarers-identity-documents-2003",
    "title": "ILO Convention No. 185 (C185) - Seafarers Identity Documents (Revised), 2003",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 185 establishes a secure, internationally recognised seafarers identity document (SID), requiring States to issue SIDs to their national seafarers in a standardised biometric form, maintain a secure national electronic database of documents issued, suspended or withdrawn, apply minimum quality-control processes subject to independent evaluation, and facilitate the shore leave, transit and transfer of seafarers holding valid SIDs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-mlc-2006",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c187-promotional-framework-occupational-safety-health-2006",
    "title": "ILO Convention No. 187 (C187) - Promotional Framework for Occupational Safety and Health, 2006",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 187 requires ratifying States to promote continuous improvement of occupational safety and health to prevent work-related injuries, diseases and deaths through the progressive development of a national OSH policy, a national OSH system and a national OSH programme, all formulated in consultation with the most representative organisations of employers and workers and aimed at building a national preventative safety and health culture.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-c188-work-in-fishing-2007",
    "title": "ILO Convention No. 188 (C188) - Work in Fishing, 2007",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "ILO Convention No. 188 sets minimum standards for work on board fishing vessels, requiring States to implement and enforce laws on fishers and fishing vessels, placing overall responsibility on the fishing vessel owner, and addressing minimum age, medical fitness, safe manning and hours of rest, fishers work agreements, recruitment and placement, accommodation and food, occupational safety and health and accident prevention, medical care on board, and social security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-mlc-2006",
      "ilo-convention-155-occupational-safety-1981"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ilo-c189-domestic-workers-convention-2011",
    "title": "ILO Convention 189 Domestic Workers 2011 - Decent Work, Minimum Standards and Recruitment Regulation",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Domestic Workers Convention 2011 (No. 189) was adopted by the International Labour Conference at its 100th Session on 16 June 2011 and entered into force on 5 September 2013. It is the first binding international instrument specifically addressing the rights of domestic workers, a workforce of approximately 75.6 million workers globally (ILO 2024 estimates) that has historically been excluded from labour protections. Article 1 defines domestic work as work performed in or for a household or households, and domestic worker as any person engaged in domestic work within an employment relationship. Article 3 establishes fundamental rights including freedom of association and effective recognition of right to collective bargaining, elimination of forced labour, child labour, and discrimination. Article 6 requires Member States to ensure domestic workers enjoy effective protection against all forms of abuse, harassment and violence. Article 7 ensures domestic workers informed of terms and conditions of employment. Articles 9-12 cover specific protections including: written employment contracts, payment of wages at least monthly, equal treatment regarding hours of work, paid annual leave, weekly rest period of at least 24 consecutive hours, occupational safety and health, social security. As of 2024, 36 States have ratified Convention 189.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-c190-violence-harassment-2019",
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-c190-violence-harassment-2019",
    "title": "C190 - Violence and Harassment Convention, 2019 (No. 190)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This convention requires ratifying member states to adopt laws and policies ensuring the right to a world of work free from violence and harassment, including gender-based violence. As per Article 4, members must adopt an inclusive, integrated, and gender-responsive approach for the prevention and elimination of such behaviors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "iso-45001-work-safety",
      "sa8000-social-account",
      "iso-26000-social-resp-mgt",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-convention-111-discrimination-employment-education",
    "title": "Discrimination (Employment and Occupation) Convention, 1958 (No. 111)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "Requires ratifying member states to eliminate discrimination in access to education, vocational guidance, and training based on race, colour, sex, religion, political opinion, national extraction, or social origin. Applies to all public and private institutions involved in education and workforce development under Article 1 and Article 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-convention-138-minimum-age-1973",
    "title": "ILO Convention No. 138 - Minimum Age for Admission to Employment (1973)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "Convention 138 requires that no person be employed under the minimum age set by the member state (Article 1), that hazardous work be prohibited for persons below the hazardous‑work age (Article 2), and that light work may be permitted for persons below the general minimum age provided they meet the light‑work age (Article 3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-convention-155-occupational-safety-1981",
    "title": "Occupational Safety and Health Convention, 1981 (No. 155)",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Requires member states to establish, implement, and periodically review a national policy on occupational safety, health, and welfare. Applies to all sectors of economic activity and mandates employer responsibilities for risk assessment, worker training, and safe working conditions under Article 16 and Article 19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-model-whs-laws-2011",
      "iso-9001-2015-quality-management-systems-operations",
      "icao-doc-9859-sms"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-convention-190-2019-violence-harassment-work",
    "title": "ILO Convention C190 2019 - Violence and Harassment in the World of Work",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "ILO Convention C190 - the Violence and Harassment Convention, 2019, adopted on 21 June 2019 at the 108th International Labour Conference and entering into force on 25 June 2021 following ratification by Uruguay and Fiji, is the first international legally binding instrument addressing violence and harassment in the world of work. As of April 2026, it has been ratified by 43 countries. Convention C190 is supplemented by ILO Recommendation R206 (Violence and Harassment Recommendation, 2019), which provides non-binding guidance on implementation. The Convention adopts a broad definition of 'violence and harassment' in Article 1: unacceptable behaviours, practices, or threats causing physical, psychological, sexual, or economic harm. It covers gender-based violence and harassment (GBVH) which are directed at persons because of their sex or gender. The Convention covers all sectors (public and private), formal and informal economy, all types of employment and work, including telework, and all workers and other persons in the world of work - including interns, volunteers, job applicants, former employees, managers, and employers. Article 4 requires each ratifying Member State to adopt an inclusive, integrated, and gender-responsive approach to preventing and eliminating violence and harassment in the world of work. Article 8 requires State responsibility for effective monitoring, enforcement, and remedies. Article 9 establishes duties of employers to take all appropriate steps proportionate to their degree of control to prevent and address violence and harassment. Article 11 requires States to adopt guidance, model policies, educational resources, and capacity-building measures. Convention C190 interacts directly with corporate governance obligations under CSRD ESRS S1 (Own Workforce), UN Guiding Principles on Business and Human Rights, and due diligence laws.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "eu-employment-equality-directive-2000-78",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-core-conventions",
    "title": "ILO (Core Conventions)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "BIDDA’s compliance architecture for International Labour Organization core conventions operationalizes the tenets established within the ILO Declaration on Fundamental Principles and Rights at Work. To enforce the Minimum Age Convention, 1973 (No. 138), the system mandates a `min_worker_age_general` of 15 and elevates this threshold to a `min_worker_age_hazardous` of 18 for dangerous occupations. In alignment with the Forced Labour Convention, 1930 (No. 29) and its subsequent 2014 Protocol, `forced_labor_supply_chain_audits_enabled` is an active control, extending scrutiny across a `supply_chain_audit_depth_tiers` of 3 levels to mitigate coercive practices, further supported by a `max_standard_weekly_hours` limit of 48. The node upholds the Freedom of Association and Protection of the Right to Organise Convention, 1948 (No. 87) by ensuring `freedom_of_association_traffic_unfiltered` is true, allowing for unimpeded monitoring of communications for anti-unionization activities, while `whistleblower_anonymity_enforced` protects reporting individuals. Measures against workplace bias are governed by principles from the Discrimination (Employment and Occupation) Convention, 1958 (No. 111), with `anti_discrimination_ai_bias_testing_enabled` to validate algorithmic fairness and a mandated `pay_equity_audit_frequency_days` of 365 for annual reviews. Finally, reflecting the Occupational Safety and Health Convention, 1981 (No. 155), the system requires `osh_incident_reporting_active` and continuous `safety_telemetry_monitoring_active` to maintain a safe and healthy working environment for all personnel.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-core-labour-standards-1998",
    "title": "ILO Declaration on Fundamental Principles and Rights at Work 1998",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This declaration obligates all ILO Member States to respect, promote, and realize principles concerning four fundamental rights: freedom of association and collective bargaining, the elimination of forced labour, the abolition of child labour, and the elimination of discrimination in employment. This commitment applies even if the state has not ratified the specific underlying conventions, as stated in Paragraph 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "sa8000-social-account",
      "iso-26000-social-resp-mgt",
      "modern-slavery-act-rep",
      "iso-45001-work-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-employment-construction-workers-convention-1988",
    "title": "Employment Conditions in Construction Convention, 1988 (No. 167)",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This ILO Convention requires member states to ensure safe and fair employment conditions for construction workers, particularly concerning temporary works, subcontracting accountability, timely wage payments, and adequate worker accommodation. Key obligations are established under Article 4 and Article 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-fundamental-rights-work",
    "title": "ILO Fundamental Rights at Work",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The ILO Declaration on Fundamental Principles and Rights at Work (1998, amended 2022) identifies five categories of fundamental principles and rights that all ILO Member States must respect and promote. These rights are the foundation of decent work and fair globalization, applicable even if a member state has not ratified the specific core conventions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-guidelines-multinational-ent",
      "un-guiding-principles-business-hr"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ilo-mlc-2006",
    "title": "ILO Maritime Labour Convention (MLC) 2006 - Consolidated Standards for Seafarer Rights, Working Conditions and Social Protection",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Maritime Labour Convention, 2006 (MLC) is an international labour convention that establishes minimum working and living standards for all seafarers on ships flying the flags of ratifying countries. It requires shipowners to ensure seafarers have a safe and secure workplace, fair terms of employment, decent working and living conditions, and access to medical care, as mandated by the Articles, Regulations, and two-part Code of the Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "iso-45001-work-safety",
      "sa8000-social-account",
      "imo-solas-safety-at-sea"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-mne-declaration-2022",
    "title": "Tripartite Declaration of Principles Concerning Multinational Enterprises and Social Policy (6th Edition, 2022): Employment, Training and Working Conditions",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This declaration sets non-binding principles for multinational enterprises (MNEs), governments, and employers' and workers' organizations to promote decent work, fair employment practices, vocational training, and safe working conditions. Key obligations are outlined in Principle 1 on employment and Principle 4 on working conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-fair-work-act-2009",
      "difc-employment-law-4-2021",
      "eeoc-employment-rule",
      "cipd-hr-standards",
      "iso-9001-2015-quality-management-systems-operations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ilo-p29-forced-labour-protocol-2014",
    "title": "ILO Protocol P29 on Forced Labour 2014 - Protocol to Convention No. 29",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The ILO Protocol of 2014 to the Forced Labour Convention (Protocol P29 - 61 Parties as of April 2026, entered into force 9 November 2016) supplements ILO Convention No. 29 (Forced Labour Convention 1930, 178 Parties) by requiring States to implement prevention, protection, compensation, and access to remedy measures beyond the original Convention's criminal prohibition; businesses are directly affected because the EU Corporate Sustainability Due Diligence Directive (CSDDD/CS3D) 2024 and CSRD ESRS S1/S2 explicitly reference ILO forced labour standards as the applicable human rights benchmark for supply chain due diligence - P29 obligations (psychologically coercive recruitment, debt bondage, retention of identity documents, lack of freedom of movement, excessive overtime) constitute the international standard that corporate due diligence processes must identify, assess, prevent, and remedy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "un-guiding-principles-business-human-rights",
      "eu-corporate-sustainability-due-diligence-2024",
      "un-palermo-convention-2000-transnational-organized-crime"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ilo-safety-health-construction-convention-167-1988",
    "title": "Safety and Health in Construction Convention, 1988 (No. 167)",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This convention requires that employers ensure the safety and health of workers in the construction industry, as outlined in Article 6, and that national laws and regulations are established to implement the provisions of the convention, as stated in Article 12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ilo-safety-health-mines-convention-c176-1995",
    "title": "Safety and Health in Mines Convention, 1995 (ILO Convention C176)",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "ILO Convention C176 obliges mine employers to (i) ensure safe and healthy working conditions (Article 3), (ii) conduct systematic risk assessments (Article 4), and (iii) implement specific controls for ground stability, ventilation, dust, and escape routes (Articles 5‑8), with oversight by a national competent authority (Article 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icmm-mining-principles-2020",
      "gri-14-mining-sector-standard-2022",
      "eiti-standard-2023"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "im-dpa-2018",
    "title": "Isle of Man Data Protection Act 2018 - Information Commissioner",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Isle of Man's Data Protection Act 2018, which came into force on 25 May 2018 (the same date as the EU General Data Protection Regulation), is the Isle of Man's primary personal data protection legislation establishing a GDPR-equivalent rights-based framework for the protection of personal data. The Isle of Man is a Crown Dependency of the United Kingdom and a self-governing jurisdiction that is not a member of the European Union or subject to the UK Data Protection Act 2018; the Isle of Man has its own Parliament (Tynwald) and legal system, and has enacted its own data protection legislation substantially equivalent to GDPR to maintain EU adequacy recognition essential to the Island's international financial services and e-gaming industries. The European Commission has recognised the Isle of Man as providing adequate data protection for the purposes of international data transfers from the EU. The supervisory authority is the Information Commissioner (Isle of Man), an independent statutory office whose mandate covers data protection and freedom of information throughout the Island. Key features of the Isle of Man's Data Protection Act 2018: (1) Scope - applies to personal data processing by controllers established in the Isle of Man or processing data of individuals in the Isle of Man; (2) Data processing principles - processing must comply with: lawfulness; fairness; transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right to data portability; and right not to be subject to solely automated decisions; (6) Data Protection Officer - required for public authorities and organisations conducting large-scale systematic processing or processing sensitive data at scale; (7) Breach notification - controllers must notify the Information Commissioner within 72 hours of becoming aware of a qualifying personal data breach; (8) Data Protection Impact Assessment - required for high-risk processing; (9) Cross-border transfers - personal data may only be transferred outside the Isle of Man where adequate protection or appropriate safeguards exist; and (10) Administrative fines - the Information Commissioner may impose significant fines for violations. The Isle of Man's GDPR-equivalent framework and EU adequacy recognition support its position as a European Crown Dependency with significant financial services, insurance, and digital economy activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-retained-gdpr",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imdrf-samd-risk-framework",
    "title": "IMDRF SaMD Risk Framework",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The IMDRF Software as a Medical Device (SaMD) Risk Categorization Framework provides a globally harmonized method for classifying the risk of independent medical software. It categorizes SaMD into four levels (I, II, III, IV) based on the criticality of the clinical situation and the impact of the information provided by the software on patient care.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14971-medical-risk",
      "iec-62304-medical-software",
      "iso-13485-medical-qms",
      "eu-mdr-2017-745",
      "fda-21-cfr-part-820-qsr",
      "fda-ai-ml-samd-action-plan"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imf-staff-papers-cbdc-policy-design-2023",
    "title": "IMF Staff Papers on CBDC Policy Design 2023 - Retail CBDC Considerations: Financial Inclusion vs Disintermediation Risk, Privacy Architecture, Cross-Border CBDC Interoperability (Project mBridge), Legal Tender Status and Offline Payment Capability",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This staff paper outlines policy considerations for central bank digital currency (CBDC) design, focusing on balancing financial inclusion with risks of financial disintermediation, privacy architecture, cross-border interoperability via initiatives like Project mBridge, legal tender status, and offline payment functionality. It applies to central banks and monetary authorities evaluating retail CBDC frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bis-project-mariana-cbdc-wholesale-fx-2023",
      "eu-cbdc-digital-euro-legislative-proposal-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "imo-2020-sulphur-limit",
    "title": "IMO 2020 Sulphur Limit",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "IMO 2020 refers to the significant reduction in the global limit for sulphur content in ships' fuel oil, from 3.50% m/m to 0.50% m/m. This MARPOL Annex VI regulation aims to improve air quality and protect human health by reducing emissions of sulphur oxides (SOx) from shipping.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-marpol-pollution",
      "ism-code-vessel-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-afs-convention-2001-anti-fouling-systems",
    "title": "IMO Anti-Fouling Systems Convention 2001 (AFS) - Harmful Coating Prohibition and Compliance",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The IMO International Convention on the Control of Harmful Anti-Fouling Systems on Ships (AFS Convention 2001, entered into force 2008) prohibits the application of organotin-based anti-fouling paint (tributyltin - TBT) on ships' hulls and requires all ships to carry an International Anti-Fouling System Certificate (IAFS Certificate) verified by a Recognised Organisation. The Convention establishes a control list mechanism allowing future harmful anti-fouling substances to be added, currently including TBT under Annex 1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-hong-kong-convention-ship-recycling-2009",
      "imo-bunker-convention-2001-civil-liability"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-autonomous-ships-mass-guidelines-2022",
    "title": "IMO Guidelines on Maritime Autonomous Surface Ships (MASS) 2022 - Degrees of Automation (D1-D4), Regulatory Scoping Exercise Outcomes, Interaction with SOLAS/COLREGS/STCW, Remote Control Centre Requirements and Roadmap to MASS Code by 2028",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes a framework for the safe, secure, and environmentally sound operation of Maritime Autonomous Surface Ships (MASS) across four defined degrees of autonomy. It applies to flag states, ship operators, remote-control centres, and trial organizers, requiring compliance with interim trial guidelines (MSC.1-Circ.1604), adherence to risk mitigation measures, and alignment with the evolving MASS Code roadmap culminating in mandatory adoption by 1 July 2030.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "imo-ballast-water-management-convention-2004-bwm",
    "title": "IMO Ballast Water Management Convention 2004 (BWM) - Invasive Species Prevention & D-2 Standard Compliance",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The International Convention for the Control and Management of Ships' Ballast Water and Sediments (BWM Convention 2004), which entered into force on 8 September 2017, requires all ships to manage their ballast water to prevent the transfer of invasive aquatic organisms and pathogens between ocean regions. Regulation B-3 requires all ships constructed before 2009 to comply with the D-2 biological treatment standard by a date tied to their International Oil Pollution Prevention (IOPP) renewal survey. The D-2 standard specifies maximum concentrations of viable organisms in discharged ballast water: <10 organisms ≥50 µm/m³, <10 viable organisms ≥10 to <50 µm/ml. Ships must carry an approved Ballast Water Management System (BWMS) type-approved under IMO resolution MEPC.279(70) (2016 Guidelines). The Ballast Water Record Book (BWRB) must record all ballast water operations. Port States may inspect compliance and detain non-compliant vessels. The 2022 revisions (MEPC.325(75)) updated the D-2 standard with new sampling and indicator microbe thresholds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-msc-fal-1-circ-3-maritime-cybersecurity-2017",
      "imo-stcw-convention-1978-2010-manila",
      "imo-solas-consolidated-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-bunker-convention-2001-civil-liability",
    "title": "International Convention on Civil Liability for Bunker Oil Pollution Damage (BUNKER)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The Convention requires registered owners of ships over 1,000 gross tonnage to maintain compulsory insurance or financial security for pollution damage caused by bunker oil spills, with direct action allowed against insurers. It applies to damage occurring in the territory, territorial sea, and exclusive economic zones of States Parties, as per the definition of 'pollution damage' and liability framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-marpol-pollution",
      "imo-solas-safety-at-sea"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "imo-cape-town-agreement-2012-fishing-vessel-safety",
    "title": "IMO Cape Town Agreement 2012 - International Agreement on the Implementation of the Provisions of the Torremolinos Protocol of 1993",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Cape Town Agreement of 2012 on the Implementation of the Provisions of the 1993 Torremolinos Protocol relating to the 1977 Torremolinos International Convention for the Safety of Fishing Vessels applies mandatory safety standards (stability, construction, equipment, fire safety, and life-saving appliances) to decked seagoing fishing vessels of 24 metres in length and over operating on international voyages. Adopted at the Cape Town Conference in 2012, the Agreement had not entered into force as at 2024 (requiring 22 ratifications by States with an aggregate fleet of 3,600 vessels of 24m or over) but has attracted growing ratification and is widely regarded as the principal binding fishing vessel safety instrument pending entry into force. The FAO, ILO, and IMO have jointly campaigned for universal ratification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "mlc_2006",
        "solas_chapter_x",
        "imo_stcw_f_1995"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-stcw-convention-1978-2010-manila",
      "imo-maritime-labour-convention-2006-mlc",
      "imo-solas-consolidated-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-cii-carbon-intensity-2023",
    "title": "MARPOL Annex VI: Operational Carbon Intensity Indicator (CII) Rating Scheme for Existing Ships",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "Mandates ships of 5,000 gross tonnage and above to calculate their annual operational carbon intensity and receive a rating from A (major superior) to E (inferior). As per MARPOL Annex VI, Regulation 28, ships rated D for three consecutive years or E for one year must submit a corrective action plan within their Ship Energy Efficiency Management Plan (SEEMP).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-14064-ghg-reporting",
      "issb-ifrs-s2-climate-2023",
      "tcfd-climate-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-clc-1992-civil-liability-oil-pollution",
    "title": "International Convention on Civil Liability for Oil Pollution Damage, 1992 Protocol",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The 1992 CLC Protocol establishes strict liability for shipowners of seagoing oil-carrying vessels over 2,000 tons for pollution damage occurring in the territory, territorial sea, or exclusive economic zone (EEZ) of a State Party. Liability limits are defined by gross tonnage, and shipowners must maintain insurance or financial security equivalent to these limits, except where liability cannot be limited due to personal fault or reckless conduct under Article 3(4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-marpol-pollution"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "imo-colregs-1972-collision-regulations",
    "title": "COLREGs 1972 - International Regulations for Preventing Collisions at Sea",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Convention on the International Regulations for Preventing Collisions at Sea 1972 (COLREGs), adopted by IMO and in force since 15 July 1977, establishes the universal right-of-way rules, navigation light requirements, sound and light signal protocols, and lookout standards for all vessels navigating on international waters. The 38 Rules (in 5 Parts: A General, B Steering and Sailing, C Lights and Shapes, D Sound and Light Signals, E Exemptions) apply to every vessel, seaplane, and watercraft on the high seas and waters connected therewith navigable by seagoing vessels. COLREGs are foundational for autonomous maritime vessel (MASS) compliance - IMO's MASS Code draft maps COLREG Rule 5 (lookout), Rule 8 (collision avoidance), and Rule 9 (narrow channel) to autonomous sensor and decision-system requirements. The 1981, 1987, 1989, 1993, 2001, 2007, 2009, and 2023 amendments progressively updated light/shape specifications and introduced provisions for Wing-in-Ground (WIG) craft. Violations of COLREGs are the leading cause of ship collision liability and criminal prosecution under flag State maritime law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-consolidated-2020",
      "unclos-part-v-exclusive-economic-zone",
      "imo-stcw-convention-1978-2010-manila"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-eexi-2023",
    "title": "Amendments to MARPOL Annex VI: Energy Efficiency Existing Ship Index (EEXI)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The IMO EEXI regulation requires existing ships of 400 gross tonnage and above to meet a specific technical energy efficiency standard. As per MARPOL Annex VI, Regulation 25, each ship's calculated 'attained EEXI' must be at or below its 'required EEXI' to be certified, often necessitating technical modifications like engine power limitation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting",
      "ghg-protocol-scope3",
      "eu-carbon-border-adjustment-2023",
      "issb-ifrs-s2-climate-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-energy-efficiency-existing-ships-eexi-2023",
    "title": "IMO MARPOL Annex VI Regulation 23 & 25 - Energy Efficiency Existing Ship Index (EEXI)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "Mandates all existing ships of 400 gross tonnage (GT) and above to calculate their attained Energy Efficiency Existing Ship Index (EEXI) and ensure it is at or below the required EEXI, a technical efficiency standard set by the IMO. As per MARPOL Annex VI, Regulation 25, compliance must be demonstrated by the first annual, intermediate, or renewal survey on or after January 1, 2023, leading to the issuance of an International Energy Efficiency Certificate (IEEC).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-fal-convention-1965-maritime-facilitation",
    "title": "IMO FAL Convention 1965 - Convention on Facilitation of International Maritime Traffic",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The FAL Convention 1965 (Convention on Facilitation of International Maritime Traffic) establishes standardised procedures and documentation for the arrival, stay, and departure of ships, persons, and cargo in international ports. Its Annex contains mandatory Standards and recommended Practices (SARP) governing FAL Forms 1-7, electronic data interchange (eFAL), and the Single Window concept. The 2022 amendments require all Contracting States to implement a Maritime Single Window (MSW) by 1 January 2024 for electronic submission of ship arrival and departure information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "solas_xi_2_isps_code",
        "wto_trade_facilitation_agreement",
        "imo_compendium_standardised_forms"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-stcw-convention-1978-2010-manila",
      "imo-colregs-1972-collision-regulations",
      "wto-trade-facilitation-agreement-2017"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-hague-visby-rules-bill-of-lading",
    "title": "Hague-Visby Rules 1968 - Carrier Liability Under Bills of Lading and Package Limitations of Liability",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Hague-Visby Rules consist of the International Convention for the Unification of Certain Rules of Law relating to Bills of Lading (Hague Rules), adopted at Brussels on 25 August 1924 and entered into force on 2 June 1931, as amended by the 1968 Protocol (Visby Protocol, entered into force 23 June 1977) and the 1979 Protocol (SDR Protocol, entered into force 14 February 1984). The Hague-Visby Rules constitute the most widely applied international regime governing the rights and obligations of carriers and cargo interests under bills of lading. Article III(1) imposes on the carrier the obligation to exercise due diligence before and at the beginning of the voyage to make the ship seaworthy, properly man, equip and supply the ship, and make the holds fit for the cargo. Article III(2) requires properly and carefully loading, handling, stowing, carrying, keeping, caring for, and discharging the cargo. Article IV(2) establishes seventeen catalogued exceptions to liability including act, neglect or default of the master in navigation or management of the ship (the historic 'nautical fault' exemption preserved by Hague-Visby but eliminated by competing Hamburg and Rotterdam Rules regimes). Article IV(5)(a) limits carrier liability to 666.67 Special Drawing Rights per package or 2 SDR per kilogram of gross weight of the goods lost or damaged, whichever is higher.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-marpol-73-78-annex-i-oil-pollution-prevention-oily-water",
      "imo-polar-code-2017-msc-385-94-resolution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-hns-convention-2010",
    "title": "IMO HNS Convention 2010 - International Convention on Liability and Compensation for HNS",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The HNS Convention 2010 (Protocol to the 1996 HNS Convention) establishes a two-tier liability and compensation system for damage caused by hazardous and noxious substances carried by sea: the shipowner bears first-tier strict liability; the HNS Fund (financed by cargo receivers) provides second-tier compensation for damage exceeding the shipowner's limit. As of 2024, the Convention has not entered into force but represents the authoritative international standard for HNS maritime liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "clc_1992",
        "marpol_annex_ii",
        "oprc_hns_protocol"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-clc-1992-civil-liability-oil-pollution",
      "imo-llmc-1976-protocol-1996-limitation-liability",
      "unclos-part-v-exclusive-economic-zone"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-hong-kong-convention-ship-recycling-2009",
    "title": "Hong Kong International Convention for the Safe and Environmentally Sound Recycling of Ships",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Hong Kong Convention requires ships to carry an Inventory of Hazardous Materials (IHM) verified through initial, renewal, and final surveys, and mandates ship recycling facilities to develop a Ship Recycling Plan for each vessel to ensure safe and environmentally sound recycling. It applies to ships of Parties to the Convention and recycling facilities under their jurisdiction, as specified in the regulations covering design, operation, and enforcement mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "iso-14001-ems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "imo-ibc-code-chemical-tankers",
    "title": "International Code for the Construction and Equipment of Ships Carrying Dangerous Chemicals in Bulk (IBC Code): Ship Type 1/2/3 Classification, Tank Location Requirements, Cargo Containment, Vapour Detection, Fire Fighting Systems and Cargo Information Card",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The IBC Code establishes mandatory design, construction, and operational standards for chemical tankers carrying dangerous chemicals in bulk, classified into Ship Types 1, 2, and 3 based on hazard level, with specific requirements for cargo containment, tank location, fire protection, vapour detection, and cargo information. Key provisions are defined under the International Maritime Organization (IMO) framework for chemical tankers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-15489-1-2016-records-management-workflow",
      "nist-ir-8374-ransomware-risk-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "imo-igc-code-2014-liquefied-gas-carriers",
    "title": "IMO IGC Code 2014 - International Code for Construction and Equipment of Ships Carrying Liquefied Gases in Bulk",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The 2014 IGC Code (International Code for the Construction and Equipment of Ships Carrying Liquefied Gases in Bulk) is the mandatory international safety standard for gas carrier vessels carrying liquefied gases including LNG, LPG, ammonia, chlorine, and other liquefied gas products in bulk. Made mandatory under SOLAS Chapter VII Regulation 13, the 2014 IGC Code applies to gas carriers built on or after 1 July 2016. It prescribes design, construction, systems, equipment, crew competency, and operational requirements to minimize the risk of loss of life, injury, and pollution from gas carrier operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "imo_ibc_code",
        "imo_marpol_annex_ii",
        "imo_stcw_convention"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-stcw-convention-1978-2010-manila",
      "imo-ibc-code-chemical-tankers",
      "imo-marpol-annex-i-oil-pollution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-imsbc-code-2020-solid-bulk-cargoes",
    "title": "IMO IMSBC Code 2020 - International Maritime Solid Bulk Cargoes Code",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The IMSBC Code (International Maritime Solid Bulk Cargoes Code) is the mandatory international standard for the safe loading, carriage, and discharge of solid bulk cargoes. Effective from 1 January 2011 under SOLAS VI Regulation 1-1, the Code classifies solid bulk cargoes into three groups: Group A (materials that may liquefy, e.g., nickel ore, iron ore fines), Group B (materials possessing chemical hazards, e.g., ammonium nitrate), and Group C (materials that are neither liable to liquefy nor possess chemical hazards). The Code requires Cargo Declaration and, for Group A cargoes, moisture content and Transportable Moisture Limit (TML) testing before loading.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "imo_ibc_code",
        "marpol_annex_ii",
        "solas_chapter_vi"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-stcw-convention-1978-2010-manila",
      "imo-marpol-annex-i-oil-pollution",
      "imo-ibc-code-chemical-tankers"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-international-safety-management-code-ism-solas-ix",
    "title": "IMO ISM Code - International Safety Management System SOLAS Chapter IX Ship Operations and Shore Management",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2022-01-01",
    "bluf": "The IMO International Safety Management Code (ISM Code) requires shipping companies to implement a documented Safety Management System covering policies, responsibilities, procedures, emergency preparedness, and non-conformity reporting, evidenced by a Document of Compliance for the company and a Safety Management Certificate for each ship.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-marpol-73-78-annex-vi-sulphur-cap-2020-air-pollution-ships",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "imo-international-ship-and-port-facility-security-code-isps-2002",
    "title": "IMO ISPS Code 2002 - International Ship and Port Facility Security",
    "domain": "Maritime & Shipping",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The International Ship and Port Facility Security (ISPS) Code (2002 SOLAS amendments, Chapter XI-2) requires contracting governments, shipping companies, and port facilities to assess security risks and implement Ship Security Plans (SSP) and Port Facility Security Plans (PFSP); entered into force 1 July 2004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-ism-code-2018",
    "title": "International Management Code for the Safe Operation of Ships and for Pollution Prevention (International Safety Management (ISM) Code) 2018 Edition",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The International Safety Management (ISM) Code provides a mandatory international standard for the safe management and operation of ships and for pollution prevention, requiring applicable shipowners and operators to establish and maintain a Safety Management System (SMS). The core objectives, outlined in Section 1.2, are to ensure safety at sea, prevent human injury or loss of life, and avoid damage to the environment and property.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "imo-stcw-seafarer-training",
      "imo-marpol-pollution",
      "iso-28000-supply-chain"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "imo-isps-code-2003",
    "title": "International Ship and Port Facility Security (ISPS) Code",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The ISPS Code mandates a comprehensive security framework for international shipping, requiring ships and port facilities to conduct security assessments and develop corresponding security plans. As per Part A, Section 1.2, its objectives are to establish an international framework for detecting security threats and taking preventive measures against security incidents affecting ships or port facilities used in international trade.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "iso-28000-supply-chain",
      "ism-code-vessel-safety",
      "imo-stcw-seafarer-training",
      "c-tpat-minimum-security"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "imo-llc-1966-load-lines",
    "title": "International Convention on Load Lines, 1966, as Amended by the Protocol of 1988",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This convention prescribes the minimum freeboard for ships on international voyages, preventing overloading to ensure vessel stability and safety. As per Article 13 and Annex I, all applicable vessels must be surveyed, assigned a freeboard, and marked with a permanent Load Line (Plimsoll) mark, with compliance verified through an International Load Line Certificate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "ism-code-vessel-safety",
      "imo-stcw-seafarer-training"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-llmc-1976-limitation-liability-maritime-claims",
    "title": "IMO Convention on Limitation of Liability for Maritime Claims (LLMC 1976/1996) - Shipowner Liability Cap",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The IMO Convention on Limitation of Liability for Maritime Claims (LLMC 1976, as amended by the 1996 Protocol with revised limits effective 2015) provides shipowners, salvors, and their insurers the right to limit financial liability for maritime claims arising from loss of life, personal injury, and property damage to amounts calculated by vessel tonnage (Special Drawing Rights per gross tonnage). The Convention applies in all 57 States Parties, covers claims from collision, cargo loss, wreck removal, and towage operations, and allows constitution of a limitation fund in any competent court to cap total liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-bunker-convention-2001-civil-liability",
      "imo-nairobi-wreck-removal-convention-2007"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-llmc-1976-protocol-1996-limitation-liability",
    "title": "Convention on Limitation of Liability for Maritime Claims (LLMC) 1976, as amended by the 1996 Protocol and 2012 Amendments - Limitation of Liability for Maritime Claims: Limitation Fund Calculation (SDR per GT for Property/Personal Injury), Passengers Claims, Conduct Barring Limitation, Barrier Constitution and Distribution Rules",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The LLMC 1976, as amended by the 1996 Protocol and 2012 amendments, establishes the conditions under which shipowners and salvors may limit their liability for maritime claims, including loss of life, personal injury, and property damage, based on ship tonnage and SDR thresholds. Limitation is barred if it is proved that the loss resulted from the party's personal act or omission committed with intent or recklessness with knowledge of probable loss.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "imo-load-lines-convention-1966-protocol-88",
    "title": "International Convention on Load Lines, 1966, as modified by the Protocol of 1988",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes minimum freeboard requirements for ships engaged in international voyages to ensure watertight integrity and safety against overloading, with specific provisions for zones, seasons, and timber deck cargo. It applies to ships covered under Chapter I, General, and requires marking of load lines amidships and periodic surveys under the 1988 Protocol.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "imo-maritime-cyber-msc-fal-circ-3",
    "title": "Guidelines on Maritime Cyber Risk Management",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-07-05",
    "bluf": "This IMO circular affirms that cyber risk management is a required component of the ship's Safety Management System (SMS) under the International Safety Management (ISM) Code. As per Resolution MSC.428(98), vessel operators must demonstrate procedures for cyber risk management in their SMS at the first annual verification of the company’s Document of Compliance after January 1, 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "iso-27005-risk-management-2022",
      "c-scrm-practices-systems-organizations"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-maritime-labour-convention-2006-mlc",
    "title": "Maritime Labour Convention 2006 (MLC 2006) - Seafarer Rights, Minimum Standards & Port State Control",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Maritime Labour Convention 2006 (MLC 2006), which entered into force on 20 August 2013, consolidates over 65 ILO maritime labour instruments and establishes the global minimum employment and welfare standards for seafarers on ships of 500 GT or more engaged in international voyages. The MLC is structured in five Titles covering: (1) minimum requirements for seafarers (age, medical fitness, training, employment agreements); (2) conditions of employment (hours of work/rest, wages, leave, repatriation); (3) accommodation, recreational facilities, food and catering; (4) health protection, medical care, and welfare; (5) compliance and enforcement. Flag States must ensure ships flying their flag comply and issue a Maritime Labour Certificate (MLC). Port States may inspect foreign ships and detain non-compliant vessels. Seafarers on non-compliant ships have a right of complaint. The 2022-2023 amendments (effective 26 December 2024) strengthen abandonment provisions, expand minimum wage coverage, and update health protection requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-mlc-2006",
      "imo-stcw-convention-1978-2010-manila",
      "imo-solas-consolidated-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-marpol-73-78-annex-i-oil-pollution-prevention-oily-water",
    "title": "IMO MARPOL 73/78 Annex I - Oil Pollution Prevention: Oily Bilge Water & Oil Record Book",
    "domain": "Maritime & Shipping",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "MARPOL 73/78 Annex I prohibits discharge of oil and oily mixtures from ships into the sea - mandatory Oil Record Book entries for all machinery space operations, oily water separator requirements, and vessel IOPP certificate compliance - enforced with criminal penalties and vessel detention by port state control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "imo-marpol-73-78-annex-vi-sulphur-cap-2020-air-pollution-ships",
    "title": "IMO MARPOL 73/78 Annex VI - 2020 Global Sulphur Cap 0.5% and ECA Emissions Compliance for Ships",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2020-01-01",
    "bluf": "MARPOL Annex VI requires ships to use fuel oil with sulphur content not exceeding 0.50% m/m globally from 1 January 2020 (0.10% in Emission Control Areas), comply with NOx Tier III standards in designated ECAs, and maintain a record of fuel oil changeover and Ship Energy Efficiency Management Plan.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-international-safety-management-code-ism-solas-ix",
      "eu-ets-directive-2003-87-emissions-trading-scheme"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "imo-marpol-annex-i-oil-pollution",
    "title": "MARPOL Annex I - Regulations for the Prevention of Pollution by Oil",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes mandatory international standards for the prevention of oil pollution from ships. It prohibits any discharge of oil or oily mixtures into the sea, except under strictly controlled conditions as specified in Regulation 4, which require the vessel to be en route and process the discharge through approved oil filtering equipment to a limit of 15 parts per million (ppm).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-marpol-annex-ii-noxious-liquid-substances",
    "title": "MARPOL Annex II - Regulations for the Control of Pollution by Noxious Liquid Substances in Bulk",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "MARPOL Annex II regulates the discharge into the sea of noxious liquid substances (NLS) carried in bulk by ships. It entered into force on 6 April 1987 under the MARPOL Protocol 1978 and was substantially revised by IMO Resolution MEPC.118(52) in 2004 (entering into force 1 January 2007). The revised Annex II classifies NLS into four categories (X, Y, Z, and OS/Other Substances) based on hazard to the marine environment, replaces the former A/B/C/D categories, and sets minimum conditions for discharge including dilution requirements, cargo pump stripping efficiencies, prewashing requirements, and port reception facility use. Chemical tankers carrying NLS in bulk are also subject to the IBC Code for design and construction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "imo_ibc_code",
        "marpol_annex_i",
        "marpol_annex_iii"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-ibc-code-chemical-tankers",
      "imo-marpol-annex-i-oil-pollution",
      "imo-stcw-convention-1978-2010-manila"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-marpol-annex-iii-packaged-harmful-substances",
    "title": "MARPOL Annex III - Prevention of Pollution by Harmful Substances Carried by Sea in Packaged Form",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "MARPOL 73/78 Annex III establishes minimum standards for packing, marking, labelling, documentation, stowage, quantity limitations, and exceptions for harmful substances carried by sea in packaged form. The Annex defines 'harmful substance in packaged form' by reference to the IMDG Code Marine Pollutant designation. Annex III entered into force on 1 July 1992 and has been ratified by virtually all maritime States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "imdg_code",
        "marpol_annex_v",
        "marpol_annex_i"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-marpol-annex-i-oil-pollution",
      "imo-ibc-code-chemical-tankers",
      "imo-hns-convention-2010"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-marpol-annex-iv-sewage-pollution",
    "title": "MARPOL Annex IV - Prevention of Pollution by Sewage from Ships",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "MARPOL 73/78 Annex IV regulates the discharge of sewage from ships, prohibiting discharge within 12 nautical miles of the nearest land except where the ship has an approved sewage treatment plant in operation or uses an approved comminuting and disinfecting system. The Baltic Sea is designated as a Special Area under Annex IV where stricter nitrogen and phosphorus discharge standards apply, effective from January 2019. Annex IV entered into force on 27 September 2003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "marpol_annex_v",
        "marpol_annex_vi",
        "unclos_part_ii"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-marpol-annex-i-oil-pollution",
      "imo-stcw-convention-1978-2010-manila",
      "unclos-part-ii-territorial-sea-contiguous-zone"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-marpol-annex-v-garbage-pollution",
    "title": "MARPOL Annex V - Prevention of Pollution by Garbage from Ships",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "MARPOL 73/78 Annex V prohibits the discharge of all garbage into the sea (plastics, food waste, domestic wastes, cooking oil, incinerator ash, operational waste, cargo residues, and fishing gear) with limited exceptions for food waste beyond 12 nm and cargo residues that cannot be recovered by port reception facilities beyond 12 nm outside Special Areas. The 2013 revised Annex V (in force 1 January 2013) fundamentally reversed the original 1988 Annex V's permissive approach: the default rule is now total prohibition, with exceptions strictly enumerated.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "marpol_annex_vi",
        "marpol_annex_iii",
        "imo_polar_code"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-marpol-annex-i-oil-pollution",
      "imo-polar-code-2017",
      "imo-stcw-convention-1978-2010-manila"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-marpol-annex-vi-air-pollution",
    "title": "MARPOL Annex VI - Regulations for the Prevention of Air Pollution from Ships",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes mandatory limits on sulphur oxide (SOx) and nitrogen oxide (NOx) emissions from ship exhausts and requires ships of 400 gross tonnage and above to calculate and report their energy efficiency and carbon intensity. Key requirements are detailed in Regulation 14 (SOx), Regulation 13 (NOx), and Regulations 26-28 (Carbon Intensity).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "ghg-protocol-scope3",
      "issb-ifrs-s2-climate-2023",
      "tcfd-climate-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-marpol-pollution",
    "title": "MARPOL: Marine Pollution Prevention",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the International Convention for the Prevention of Pollution from Ships is confirmed across all applicable annexes based on governing maritime regulations. Pertaining to Annex I, the vessel maintains both a valid International Oil Pollution Prevention Certificate and a current Oil Record Book. All machinery space bilge water discharges are processed through filtering equipment to ensure effluent oil content does not exceed the 15 parts per million threshold, a fact corroborated by operational data indicating the vessel is not inside a designated special area for oil. For Annex V, waste handling is executed under an approved Garbage Management Plan, with all activities recorded in a current Garbage Record Book and an absolute prohibition on plastics discharge strictly enforced. Annex VI requirements are met with a valid International Air Pollution Prevention Certificate and verification that fuel oil sulphur content remains at or below the 0.50% global limit, consistent with operations outside a SOx Emission Control Area. Under Annex IV, a certified sewage treatment plant is operational, and any discharge of treated effluent occurs no closer than 12 nautical miles from land, satisfying international protocols for sanitation systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-2020-sulphur-limit",
      "ism-code-vessel-safety",
      "imo-solas-safety-at-sea",
      "imo-stcw-seafarer-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-msc-fal-1-circ-3-maritime-cybersecurity-2017",
    "title": "IMO MSC-FAL.1/Circ.3/Rev.3 Guidelines on Maritime Cyber Risk Management",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires shipping companies to integrate cyber risk management into their Safety Management Systems (SMS) as defined by the ISM Code, ensuring operational resilience to cyber threats by identifying, protecting, detecting, responding to, and recovering from cyber risks. This obligation is mandated no later than the first annual verification of the company's Document of Compliance after 1 January 2021, per Resolution MSC.428(98).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-8374-ransomware-risk-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "imo-nairobi-wreck-removal-convention-2007",
    "title": "IMO Nairobi International Convention on the Removal of Wrecks 2007",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Nairobi Wreck Removal Convention (NWRC, 2007 - 64 Contracting States as of April 2026, in force 2015) is the first binding international instrument requiring registered owners of ships of 300 GT or more to carry compulsory wreck removal insurance and enabling Contracting States to recover wreck removal costs directly from insurers; operators of vessels calling at ports of Contracting States must maintain a certificate of insurance or other financial security (Article 12) as a condition of port entry, and States may take measures against wrecks in their Exclusive Economic Zones under Article 9 including locating, marking, and removing them at the registered owner's expense - non-compliance with certificate requirements results in vessel detention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unclos-part-v-exclusive-economic-zone",
      "imo-maritime-labour-convention-2006-mlc",
      "un-bbnj-agreement-2023-marine-biodiversity",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-oprc-convention-1990-oil-pollution-preparedness",
    "title": "IMO International Convention on Oil Pollution Preparedness, Response and Co-operation 1990 (OPRC Convention)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The OPRC Convention 1990 requires ships, offshore units, and coastal States to maintain oil pollution emergency plans, establish national reporting and response systems, and co-operate internationally in oil spill response. The 2000 OPRC-HNS Protocol extends these obligations to hazardous and noxious substances. Together they form the binding framework for pre-positioned response capability and mutual assistance obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "marpol_annex_i",
        "imo_clc_1992",
        "opa_90"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-clc-1992-civil-liability-oil-pollution",
      "us-oil-pollution-act-1990-opa-90",
      "unclos-part-v-exclusive-economic-zone"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-oprc-hns-protocol-2000-hazardous-substances",
    "title": "IMO OPRC-HNS Protocol 2000 - Preparedness and Response to Pollution Incidents Involving Hazardous and Noxious Substances",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2007-06-14",
    "bluf": "The OPRC-HNS Protocol 2000 extends the OPRC 1990 oil pollution framework to hazardous and noxious substances (HNS), requiring States Parties to establish national HNS pollution emergency plans, maintain stockpiles of response equipment, report incidents to neighboring states within 24 hours, and participate in the International HNS Compensation Fund regime for liability claims.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-oprc-convention-1990-oil-pollution-preparedness",
      "imo-ibc-code-chemical-tankers",
      "imo-marpol-pollution",
      "imo-hns-convention-2010"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-polar-code-2017",
    "title": "International Code for Ships Operating in Polar Waters (Polar Code)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The IMO Polar Code provides mandatory requirements for ship design, construction, equipment, operations, training, and environmental protection to ensure the safety of ships and the protection of the polar environment. As per its introduction, the Code is mandatory under both the International Convention for the Safety of Life at Sea (SOLAS) and the International Convention for the Prevention of Pollution from Ships (MARPOL).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "imo-marpol-pollution",
      "imo-stcw-seafarer-training",
      "ism-code-vessel-safety"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "imo-polar-code-2017-msc-385-94-resolution",
    "title": "IMO Polar Code 2017 - International Code for Ships Operating in Polar Waters, Polar Ship Certificate and Operational Restrictions",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The International Code for Ships Operating in Polar Waters (Polar Code) was adopted by the International Maritime Organization (IMO) through Resolution MSC.385(94) of 21 November 2014 (safety provisions) and Resolution MEPC.264(68) of 15 May 2015 (environmental provisions), and entered into force on 1 January 2017. The Code applies to ships operating in Arctic waters north of 60 degrees North and Antarctic waters south of 60 degrees South (with some Arctic exclusions per Polar Code definitions in Chapter A-1). Safety provisions (Part I-A mandatory plus Part I-B guidance) cover ship structure, stability, machinery, fire safety, life-saving appliances, navigation, communications, voyage planning, and manning. Environmental provisions (Part II-A mandatory plus Part II-B guidance) include enhanced controls under MARPOL Annex I (oil), II (noxious liquid substances), IV (sewage), V (garbage) and VI (air emissions). Article 1.1 establishes the Polar Service Temperature for cold operations. Ships require a Polar Ship Certificate (PSC) and Polar Water Operational Manual (PWOM) per Chapter 1. Three ship categories (A, B, C) determine operational restrictions based on POLARIS (Polar Operational Limit Assessment Risk Indexing System) per IMO MSC.1/Circ.1519.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-marpol-73-78-annex-i-oil-pollution-prevention-oily-water",
      "imo-ballast-water-management-convention-2004-bwm"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-sar-convention-1979-maritime-rescue",
    "title": "IMO International Convention on Maritime Search and Rescue 1979 (SAR Convention)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The SAR Convention 1979 establishes a globally co-ordinated maritime search and rescue framework dividing the world's oceans into Search and Rescue Regions (SRRs), each served by a 24/7 Rescue Coordination Centre (RCC); coastal States must render assistance to all persons in distress regardless of nationality, declare emergency phases (INCERFA/ALERFA/DETRESFA), and co-operate across SRR boundaries. The 2004 Amendments introduced a duty to disembark survivors at a place of safety.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "solas_v_33",
        "unclos_98",
        "iamsar"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-stcw-convention-1978-2010-manila",
      "imo-colregs-1972-collision-regulations",
      "unclos-part-ii-territorial-sea-contiguous-zone"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-sar-convention-1979-maritime-search-rescue",
    "title": "IMO International Convention on Maritime Search and Rescue (SAR 1979) - Rescue Coordination Framework",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The IMO International Convention on Maritime Search and Rescue (SAR 1979, as amended by 1998 Annex amendments) establishes the global framework for maritime search and rescue coordination, dividing ocean areas into 13 SAR regions with national Rescue Coordination Centres (RCCs) responsible for organising rescue operations. It is complemented by SOLAS Chapter V Regulation 33 (duty to render assistance) and the IAMSAR Manual (International Aeronautical and Maritime Search and Rescue), and applies to all vessels in distress regardless of flag state.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-colregs-1972-collision-regulations",
      "imo-stcw-convention-1978-2010-manila"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-solas-consolidated-2020",
    "title": "International Convention for the Safety of Life at Sea (SOLAS), 1974, as amended, Consolidated Edition 2020, Chapter XI-2: Special measures to enhance maritime security",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation mandates specific security measures for ships and port facilities to prevent acts of terrorism against shipping. As per Regulation XI-2/3, it requires compliance with the International Ship and Port Facility Security (ISPS) Code, mandating security assessments, security plans, and the appointment of security officers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "isps-code-vessel-security",
      "port-facility-security-isps",
      "ism-code-vessel-safety",
      "imo-stcw-seafarer-training",
      "iso-28000-supply-chain"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "imo-solas-safety-at-sea",
    "title": "SOLAS: Safety of Life at Sea",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Vessel conformity with the International Convention for Safety of Life at Sea (SOLAS) mandates rigorous verification of critical operational, structural, and procedural controls. This node's assessment confirms the presence of a valid safety certificate, a foundational requirement for lawful operation. Per maritime security protocols in Chapter XI-2, an approved Ship Security Plan must be in place, with its last review documented within the preceding 365 days. Safety management systems, governed by Chapter IX, are scrutinized to ensure cyber risk management is fully integrated. Navigational integrity under Chapter V depends upon a functional Automatic Identification System and an operational voyage data recorder. Vessel identification is validated by confirming its IMO number is permanently marked as stipulated by special safety measures. Emergency preparedness, a core component of Chapter III, requires that both lifeboat drills and fire drills have been conducted within the 30-day interval. Radiocommunications capabilities specified in Chapter IV are confirmed via a passed Global Maritime Distress and Safety System equipment self-test. Finally, structural integrity and fire safety standards from Chapters II-1 and II-2 are met when the fire detection system is operational and the most recent watertight door test has been successfully passed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ism-code-vessel-safety",
      "isps-code-vessel-security",
      "imo-stcw-seafarer-training",
      "imo-marpol-pollution",
      "hague-visby-rules"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-stcw-convention-1978-2010-manila",
    "title": "International Convention on Standards of Training, Certification and Watchkeeping for Seafarers, 1978, as amended (Manila Amendments 2010)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The STCW Convention, as amended by the 2010 Manila Amendments, establishes mandatory minimum standards for training, certification, and watchkeeping for seafarers worldwide, including requirements for medical fitness, hours of rest, security training, and proficiency in modern navigation systems under STCW Code Part A. It applies to all seafarers serving on seagoing ships flagged under Parties to the Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "ilo-convention-155-occupational-safety-1981"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "imo-stcw-convention-manila-2010",
    "title": "International Convention on Standards of Training, Certification and Watchkeeping for Seafarers (STCW), 1978, as amended, including the 2010 Manila Amendments",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The STCW Convention and Code, as updated by the 2010 Manila Amendments, establishes mandatory minimum international standards for the training, certification, and watchkeeping of seafarers. It requires all seafarers on ships flagged by signatory nations to hold appropriate, valid certificates demonstrating competence, medical fitness, and completion of approved training and sea service, as mandated by STCW Regulation I/2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "ilo-core-conventions",
      "iso-45001-work-safety",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-stcw-seafarer-training",
    "title": "STCW: Seafarer Competency Standards",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the International Convention on Standards of Training, Certification and Watchkeeping for Seafarers (STCW) mandates a comprehensive verification of personnel qualifications and operational readiness. This involves confirming every crew member holds a valid certificate of competency and a current medical certificate, which are foundational requirements under international maritime regulations. Furthermore, verification must extend to ensuring each certificate possesses a corresponding flag state endorsement where applicable, and that all watchkeeping personnel are certified for their specific roles. Records also confirm every individual has completed security awareness training as stipulated by the Code. Established experience thresholds are met, with a demonstrated seagoing service of 36 months for key personnel, while the subject seafarer’s age of 24 years satisfies all prerequisites. Work and rest hour logs are critical; regulatory adherence is confirmed with a minimum daily rest of 10 hours recorded and maximum work hours in any 7-day period not exceeding 72, aligning directly with provisions detailed in the Convention. Training currency is also validated, showing the last basic safety refresher occurred 730 days ago, well within mandated five-year revalidation cycles. Crucially, a systemic review confirms that all records are maintained and accessible for auditing by port state control or other competent authorities, demonstrating end-to-end regulatory adherence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "ism-code-vessel-safety",
      "imo-marpol-pollution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "imo-sua-convention-1988-maritime-security",
    "title": "IMO Convention for the Suppression of Unlawful Acts Against the Safety of Maritime Navigation 1988 (SUA Convention)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The SUA Convention 1988 criminalises unlawful acts against the safety of ships - including seizing control, destroying or endangering vessels, and committing violence against persons on board - and requires States to either extradite or prosecute offenders (aut dedere aut judicare). The 2005 Protocol significantly expanded the Convention to cover WMD transport and terrorist-linked maritime activity, and introduced a flag-State-consent boarding regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "isps_code",
        "un_sc_1373",
        "unclos_105"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-stcw-convention-1978-2010-manila",
      "imo-colregs-1972-collision-regulations",
      "unclos-part-v-exclusive-economic-zone"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "imo-tonnage-convention-1969-measurement",
    "title": "International Convention on Tonnage Measurement of Ships 1969 - Gross and Net Tonnage Calculation, Measurement Rules for Internal Spaces, Enclosed Spaces, Open Spaces and Exempted Spaces, ITC Certificate and Relationship to Port Dues and Manning Regulations",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a universal system for calculating gross tonnage (GT) and net tonnage (NT) for ships built on or after 18 July 1982, based on the moulded volume of all enclosed spaces and cargo spaces respectively, with net tonnage not less than 30 per cent of gross tonnage. It applies to all ships subject to international tonnage measurement under IMO rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "in-aadhaar-act-2016-dpdp-2023-uidai-digital-identity",
    "title": "India Aadhaar Act 2016 and Digital Personal Data Protection Act 2023 as the UIDAI Digital Identity Framework",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2023-08-11",
    "bluf": "India's national digital identity framework is anchored in two statutes administered by the Ministry of Electronics and Information Technology (MeitY) through the Unique Identification Authority of India (UIDAI). The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016 establishes the Aadhaar number, the central identity data repository, and the authentication regime under Section 4 to Section 8. The Digital Personal Data Protection Act 2023 supplies the data protection overlay for any personal data processing including biometric and demographic Aadhaar attributes, requiring consent or specified legitimate use under Sections 5 to 7 and imposing data fiduciary obligations under Chapter 2.\n\nThe Aadhaar architecture covers enrollment under Section 3, authentication services under Section 8, offline verification using virtual identifier (VID) under regulations made under Section 4(3), and protection of identity information under Section 28. Section 29 governs restriction on sharing of identity information. The Supreme Court of India's 2018 Puttaswamy judgment confirmed Aadhaar's constitutional validity for welfare delivery but read down Section 57 to prohibit mandatory private-sector authentication absent specific legal backing. The DPDP Act 2023 imposes purpose limitation, data minimisation, accuracy, storage limitation, security safeguards, and breach notification obligations on UIDAI and all Aadhaar-using data fiduciaries, with the Data Protection Board of India as the enforcement authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nist-sp-800-63-4-2025-digital-identity-guidelines",
      "in-dpdp-act-2023-digital-personal-data-protection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "in-cert-in-cybersecurity-directions-2022-6hr-reporting",
    "title": "India CERT-In Cybersecurity Directions 2022 - 6-Hour Incident Reporting, 180-Day Log Retention, and VPN/Cloud Subscriber Registration",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Service providers, intermediaries, data centres, body corporates, and government organisations operating in India must, under the Indian Computer Emergency Response Team (CERT-In) Directions issued on 28 April 2022 under section 70B of the Information Technology Act 2000, mandatorily report cyber incidents to CERT-In within 6 hours of noticing them or being notified, enable logs of all ICT systems and maintain them securely for 180 days within Indian jurisdiction, and (for Data Centres, Virtual Private Server (VPS) providers, Cloud Service providers, and Virtual Private Network (VPN) Service providers) register subscriber information including names, period of hire, and IP addresses for at least 5 years after cancellation or withdrawal, with non-compliance penalties including fines up to one lakh rupees or imprisonment up to one year.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "in-dpdp-act-2023-digital-personal-data-protection"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "in-cert-in-directions-2022",
    "title": "India CERT-In Cybersecurity Directions 2022",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "India CERT-In's 2022 Cybersecurity Directions impose a mandatory 6-hour incident reporting requirement for 20 categories of cybersecurity incidents - among the shortest reporting windows globally - require VPN providers, cloud service providers, and data centres to retain detailed subscriber and customer data for 5 years, and mandate NTP clock synchronisation and 180-day log retention across all covered organisations operating ICT systems in India.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/in-cert-in-directions-2022.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "in-it-act-2000"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "in-companies-act-2013",
    "title": "India Companies Act 2013 (Act No. 18 of 2013)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Companies Act 2013 (Act No. 18 of 2013) is India's principal statute governing the incorporation, management, and dissolution of companies, receiving Presidential assent on 29 August 2013 and administered by the Ministry of Corporate Affairs (MCA) through the Registrar of Companies (ROC) and the National Company Law Tribunal (NCLT). Section 135 imposes mandatory Corporate Social Responsibility obligations on companies meeting any of three financial thresholds in any financial year: net worth of INR 500 crore or more, turnover of INR 1,000 crore or more, or net profit of INR 5 crore or more. Such companies must spend at least 2% of the average net profits of the three immediately preceding financial years on CSR activities listed in Schedule VII and must constitute a CSR Committee of the Board with at least three directors including at least one independent director. Section 149 requires every listed public company to have at least one-third of the total number of directors as independent directors meeting the criteria prescribed under Section 149(6), including absence of material pecuniary relationships with the company or its subsidiaries and no prior employment with the company's statutory auditor. Every listed company and certain prescribed classes of unlisted companies must also appoint at least one woman director. Section 166 codifies directors' duties: a director must act in good faith to promote the objects of the company for the benefit of its members and in the best interests of the company, its employees, shareholders, the community, and for the protection of the environment; must exercise independent judgment; and must not involve themselves in situations conflicting with the interests of the company. Section 177 mandates the constitution of an Audit Committee for listed companies and certain classes of unlisted public companies, consisting of at least three directors with a majority being independent directors. Section 143(12) requires the statutory auditor to report fraud involving INR 1 crore or more to the Central Government within 60 days. Section 447 prescribes punishment for fraud: rigorous imprisonment for not less than six months extendable to ten years and a fine of not less than the amount involved extendable to three times that amount; where fraud involves public interest, the minimum imprisonment term is three years. The Companies (Amendment) Act 2019 made CSR non-compliance subject to civil penalties, and the Companies (Amendment) Act 2020 introduced the requirement to transfer unspent CSR amounts to a specified fund or an unspent CSR account within 30 days of financial year close.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "in-competition-act-2002",
    "title": "India Competition Act 2002 (Act No. 12 of 2003, as amended by Competition Amendment Act 2023)",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Competition Act 2002 (Act No. 12 of 2003) is India's principal competition law statute, receiving Presidential assent on 13 January 2003 and administered by the Competition Commission of India (CCI), established in 2008. The Act was substantially amended by the Competition (Amendment) Act 2023, which received Presidential assent on 11 April 2023. Section 3 prohibits anti-competitive agreements: any agreement in respect of production, supply, distribution, storage, acquisition, or control of goods or provision of services that has or is likely to have an appreciable adverse effect on competition (AAEC) in India is void. Horizontal agreements that fix purchase or sale prices, limit or control production, supply, markets, or investment, allocate markets or customers, or involve bid rigging are presumed to have AAEC. The 2023 Amendment extended the Section 3 prohibition to 'hub and spoke' arrangements where non-competitors facilitate horizontal anti-competitive coordination. Section 4 prohibits any enterprise or group from abusing its dominant position. Abusive conduct includes imposing unfair or discriminatory conditions or prices (including predatory pricing), limiting or restricting production, scientific development, or technical knowledge, denying market access, using dominance in one market to enter or protect another market, and imposing supplementary conditions unrelated to the subject matter of the contract. Section 5 establishes thresholds for combinations (mergers and acquisitions) requiring prior CCI approval: the target must have assets in India exceeding INR 2,000 crore or turnover in India exceeding INR 6,000 crore, or the group must have worldwide assets exceeding USD 1 billion with assets in India exceeding INR 250 crore, or worldwide turnover exceeding USD 3 billion with turnover in India exceeding INR 750 crore. The 2023 Amendment introduced a deal value threshold: transactions with a deal value exceeding INR 2,000 crore where the target has substantial business operations in India require prior CCI approval regardless of assets or turnover. Section 6 requires parties to a combination meeting the Section 5 thresholds to notify the CCI within 30 working days of the agreement or board resolution. Section 27 empowers the CCI to order the offending party to cease and desist from anti-competitive conduct, impose penalties up to 10% of average turnover for each year of the continuance of the agreement or the abuse, and, in cartel cases, impose penalties up to three times the profit of the enterprise for each year of cartel continuation. The 2023 Amendment changed the penalty basis for anti-competitive agreements from average turnover in India to global turnover, significantly increasing maximum penalties for multinational enterprises.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tfeu-article-102-abuse-of-dominance",
      "us-ftc-act-section-5-unfair-competition"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "in-dpdp-act-2023",
    "title": "India Digital Personal Data Protection Act 2023 (DPDP Act, Act No. 22 of 2023)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Digital Personal Data Protection Act 2023 (DPDP Act, Act No. 22 of 2023) is India's first comprehensive data protection legislation, receiving Presidential assent on 11 August 2023 and administered by the Data Protection Board of India (DPBI) to be constituted under Section 18. The DPDP Act establishes rights for data principals (individuals whose data is processed) and obligations for data fiduciaries (entities that determine the purpose and means of processing personal data). Section 4 provides that personal data may only be processed for a lawful purpose with the consent of the data principal. Section 7 identifies circumstances where processing does not require consent, including performance of a function of the State, compliance with legal obligations, medical emergencies, and employment purposes. Section 8 imposes obligations on data fiduciaries: they must process data only for the specified and lawful purpose; ensure accuracy and completeness of data; implement appropriate technical and organisational security measures; notify the DPBI of personal data breaches; and erase personal data where it is no longer necessary. Section 9 requires data fiduciaries processing children's data (under 18 years) to obtain verifiable parental consent. Section 13 provides data principals with the right of access to information about their personal data, the right to correction and erasure, the right to grievance redressal, and the right to nominate another person to exercise rights on their behalf in the event of death or incapacity. The DPDP Act imposes financial penalties of up to INR 250 crore (approximately USD 30 million) for personal data breaches, up to INR 200 crore for failure to notify breaches, and up to INR 50 crore for violations of children's data provisions. The DPDP Rules 2025 were notified in February 2025 for public consultation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "in-dpdp-act-2023-digital-personal-data-protection",
    "title": "India Digital Personal Data Protection Act 2023 - Data Principal Rights and Fiduciary Obligations",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "India's Digital Personal Data Protection Act 2023 (DPDP Act) establishes a rights-based framework for digital personal data: lawful consent and deemed consent bases, data principal rights of access, correction, erasure, grievance redressal, and nomination, significant data fiduciary (SDF) designation for large processors, mandatory breach notification to the Data Protection Board, data localisation for certain SDFs, and penalties up to INR 250 crore per violation enforced by the Data Protection Board of India.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-6-lawful-basis-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "in-dpdp-rules-2025-gsr-846e",
    "title": "India Digital Personal Data Protection Rules 2025 - MeitY Gazette G.S.R. 846(E) of 13 November 2025",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Data Fiduciaries in India must implement the Digital Personal Data Protection Rules, 2025, notified by MeitY via Gazette Notification G.S.R. 846(E) on 13 November 2025, in a phased manner over 18 months culminating on 14 May 2027: Phase 1 procedural provisions from 14 November 2025, Phase 2 consent manager registration and Data Protection Board breach inquiry powers from 14 November 2026, and Phase 3 substantive obligations including consent, notices, data principal rights, processing of children's personal data, breach intimation (Rule 7), retention and deletion (Rule 8), and publication of Data Protection Officer contact details (Rule 9) from 14 May 2027, with additional obligations on Significant Data Fiduciaries including localisation of personal data and traffic data flows where identified by the Central Government, and algorithmic due diligence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "in-dpdp-act-2023-digital-personal-data-protection"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "in-dpdpa-2023",
    "title": "India Digital Personal Data Protection Act 2023 (DPDPA - Act No. 22 of 2023)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "India's Digital Personal Data Protection Act, 2023 (DPDPA - Act No. 22 of 2023), received Presidential assent on 11 August 2023 and was published in the Gazette of India (Extraordinary, Part II, s. 1) on 11 August 2023. The DPDPA is India's first comprehensive national personal data protection legislation, establishing a statutory framework for the processing of digital personal data of individuals (termed 'Data Principals') by organisations and government entities (termed 'Data Fiduciaries'). The DPDPA applies to the processing of digital personal data - personal data in digital form, or personal data that is collected in non-digital form and subsequently digitised - within India. It also applies extraterritorially to processing outside India where such processing is in connection with offering goods or services to Data Principals located in India. India is the world's most populous nation with over 1.4 billion people and is a global leader in information technology, software services, and business process outsourcing. India's digital economy - encompassing fintech, e-commerce, healthtech, and IT services - processes enormous volumes of personal data of Indian and international individuals under the DPDPA framework. The DPDPA marks a significant departure from the prior patchwork regime under the Information Technology Act, 2000 (IT Act, Act No. 21 of 2000) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules). Enforcement: the Data Protection Board of India (DPBI) is the adjudicatory body designated under the DPDPA to adjudicate complaints and impose penalties. The DPBI differs from GDPR-model supervisory authorities: it functions as a digital adjudicatory body conducting proceedings via digital means. As of April 2026, the DPBI had not been formally constituted pending finalisation of the Digital Personal Data Protection Rules, 2025 (draft published by the Ministry of Electronics and Information Technology - MeitY - for public consultation). Enforcement of the DPDPA is pending full operationalisation of the DPBI. Key DPDPA concepts and provisions: (1) Data Fiduciary and Data Principal - the DPDPA uses 'Data Fiduciary' (equivalent to GDPR controller) and 'Data Principal' (equivalent to GDPR data subject) terminology; a 'Consent Manager' is a registered entity that enables Data Principals to manage consent; (2) Legal bases - the DPDPA provides two categories of lawful processing: consent of the Data Principal, and specified 'legitimate uses' (government processing for public functions, compliance with laws or court orders, medical emergencies, employment, research and archiving, national security); notably, GDPR's 'legitimate interests' basis (Art. 6(1)(f)) does not appear as a general private-sector ground; (3) Children's data - Data Fiduciaries must obtain verifiable parental consent before processing personal data of Data Principals below 18 years of age (higher than GDPR's default of 13-16); certain categories of Data Fiduciaries may be exempted from this requirement by the Central Government; (4) Significant Data Fiduciary - the Central Government may designate certain Data Fiduciaries as 'Significant Data Fiduciaries' based on volume and sensitivity of data processed, risk to rights, national security, and other factors; Significant Data Fiduciaries must appoint a Data Protection Officer (DPO), engage an independent data auditor, conduct data protection impact assessments, and comply with additional standards; (5) Data Principal rights - the DPDPA provides: right to access information about processing; right to correction and erasure; right to grievance redressal; right to nominate a nominee to exercise rights upon death or incapacity; notably, the DPDPA does not include a right to data portability or a right to object as in GDPR; (6) Cross-border data transfers - the Central Government may, by notification, restrict personal data transfers to specified countries or territories; no adequacy framework analogous to GDPR Chapter V has been established in the DPDPA text; the Act does not impose general data localisation requirements; (7) Security - Data Fiduciaries must implement reasonable security safeguards to prevent personal data breaches; breach notification to the DPBI and Data Principals is required without delay; (8) Penalties - Schedule I specifies financial penalties up to INR 250 crore (approximately USD 30 million) for the most serious violations including breach of children's data protection obligations and failure to implement adequate security safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "in-factories-act-1948",
    "title": "The Factories Act, 1948 - Working Hours, Health, Safety and Welfare Provisions for Factory Workers",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This Act mandates health, safety, welfare, and working hour standards for all factories in India, defined as premises employing 10 or more workers with the aid of power, or 20 or more without. Key provisions in Chapters III, IV, and VI regulate cleanliness, ventilation, machinery safety, maximum work hours, and overtime pay to ensure a safe and humane working environment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-work-safety",
      "ilo-core-conventions",
      "sa8000-social-account"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "in-gfr-2017-general-financial-rules-government-e-marketplace-gem",
    "title": "India General Financial Rules (GFR) 2017 + Government e-Marketplace (GeM) Procurement Framework",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The General Financial Rules (GFR) 2017 issued by the Department of Expenditure under the Ministry of Finance, Government of India, are the principal procedural framework governing financial administration of the Union Government including procurement, contracts, financial management, and disposal of assets. The Rules consist of 13 chapters spanning General System of Financial Management (Chapter 2), Revenues and Receipts (Chapter 3), Demands for Grants and Appropriation Accounts (Chapter 4), Establishment Matters (Chapter 5), Procurement of Goods and Services (Chapters 6 and 7 the operative procurement chapters), Inventory Management (Chapter 8), Contract Management (Chapter 9), Grants-in-aid and Loans (Chapter 10), Budget Formulation (Chapter 11), Government Accounts (Chapter 12), and Works (Chapter 13). The procurement provisions in Chapters 6-7 set the methods of procurement (open tender, limited tender, single tender, two-stage bidding), the e-procurement mandate, the preferences for Micro and Small Enterprises (MSME) and for products with local content under Make in India, the rate contracts framework, and the Central Public Procurement Portal (CPPP) publication requirements. The Government e-Marketplace (GeM) launched in August 2016 and operated by the Ministry of Commerce and Industry through GeM SPV is the central online procurement platform mandated for most goods and services procurement by Union government ministries, central public sector enterprises, and most state governments via opt-in. GeM operationalises the GFR 2017 procurement provisions through standardised product catalogues, dynamic pricing, reverse auctions, direct purchase up to defined thresholds, L1 (lowest acceptable) award, and integrated debarment screening. The framework intersects the Public Procurement (Preference to Make in India) Order 2017 (and successor amendments), the MSME procurement preferences under the Public Procurement Policy for Micro and Small Enterprises Order 2012, the Defence Acquisition Procedure (DAP) 2020 for defence procurement, and the Procurement Manual for Goods 2024 issued by the Department of Expenditure as the operative manual for executing GFR procurement provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "iso-iec-42001-2023-ai-management-system",
      "ph-data-privacy-act-ra-10173",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "in-it-act-2000",
    "title": "India Information Technology Act 2000",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "India's Information Technology Act 2000, as amended in 2008, establishes the primary legal framework for cybersecurity and data protection in India - requiring corporations to implement reasonable security practices for sensitive personal data under Section 43A, imposing liability for unauthorised data disclosure, and designating CERT-In as the national nodal agency for cybersecurity incident response under Section 70B.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/in-it-act-2000.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "in-it-intermediary-guidelines-2021",
    "title": "India Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "India's IT Rules 2021 notified February 25, 2021 under the IT Act 2000 require significant social media intermediaries with 5 million or more registered users in India to appoint a Chief Compliance Officer, Nodal Officer, and Resident Grievance Officer based in India, publish monthly compliance reports, and enable identification of the first originator of messages on court or government order.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/in-it-intermediary-guidelines-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "in-it-act-2000"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "in-it-rules-2021-rule-3-rule-4-intermediary-due-diligence",
    "title": "India IT Rules 2021 - Rule 3 Intermediary Due Diligence and Rule 4 Significant Social Media Intermediary Obligations for Adult Content, Non-Consensual Intimate Imagery and Child Safety",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (commonly the IT Rules 2021) were notified by the Ministry of Electronics and Information Technology (MeitY) on 25 February 2021 under Section 87(2) of the Information Technology Act, 2000 (IT Act). The Rules supersede the prior 2011 Intermediary Guidelines and impose substantive due-diligence obligations on intermediaries that, if not observed, cause the intermediary to lose the safe-harbour immunity under Section 79 of the IT Act. Rule 3 (Due Diligence by an Intermediary) requires intermediaries to: (a) publish on the website terms of service, privacy policy and rules; (b) inform users not to host, display, upload, modify, publish, transmit, store, update or share information that, inter alia, is obscene, pornographic, paedophilic, invasive of bodily privacy, insulting or harassing on the basis of gender, or that violates IT Act Sections 67, 67A, 67B (obscene material, sexually explicit content and child pornography respectively); (c) terminate or remove access of users on receipt of a court or government order, or pursuant to grievance officer determination, within thirty-six hours of receipt of such order (Rule 3(1)(d) read with Rule 3(2)); (d) Rule 3(2)(b) requires intermediaries to remove or disable access to content in the nature of impersonation, morphing, simulating sexual or partially or fully nude depictions of an individual, including in the form of a deepfake, within twenty-four hours of receiving a complaint by the affected individual or any person on their behalf. Rule 4 (Additional Due Diligence by a Significant Social Media Intermediary, SSMI, defined under Rule 2(w) as an intermediary with five million or more registered users in India) requires: appointment of a Chief Compliance Officer responsible for IT Act and IT Rules compliance, a Nodal Contact Person available 24x7 for coordination with law enforcement, and a Resident Grievance Officer who must reside in India and acknowledge user complaints within twenty-four hours and dispose of them within fifteen days under Rule 3(2)(a). Rule 4(4) requires SSMIs that provide messaging or other services to deploy technology-based measures, including automated tools and other mechanisms, to identify content depicting child sexual abuse material (CSAM), rape and other previously blocked content. Loss of safe harbour under Section 79 of the IT Act exposes intermediaries to direct criminal liability under IT Act Sections 67 (obscene material, up to three years imprisonment for first offence, up to five years for subsequent), 67A (sexually explicit content, up to five years for first offence, up to seven for subsequent) and 67B (child sexual abuse material and abuse via electronic means, up to five years for first offence, up to seven for subsequent, with fine). The Rules have been amended several times including the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules of 6 April 2023 (deepfake and fact-check unit provisions) and the 2024 advisories on AI-generated content moderation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "it_act_safe_harbour_anchor",
        "criminal_overlay_anchor",
        "grievance_redressal_anchor",
        "ssmi_criteria_anchor",
        "automated_csam_detection_anchor",
        "industry_mapping",
        "deepfake_and_ai_overlay_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "in-it-act-2000",
      "us-18-usc-2257-record-keeping-explicit-content",
      "uk-online-safety-act-2023-part-5-pornographic-content-duties"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "in-meity-synthetic-content",
    "title": "India MeitY IT Rules (Synthetic Content Amendment)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Mandatory disclosure, verification, and visual/audio labelling requirements for AI-generated synthetic content by Significant Social Media Intermediaries (SSMIs) operating in India.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cn-cac-genai-measures",
      "iso-42001-transparency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "in-pmla-2002",
    "title": "India Prevention of Money Laundering Act 2002 (PMLA, Act No. 15 of 2003)",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "The Prevention of Money Laundering Act 2002 (PMLA, Act No. 15 of 2003) is India's primary anti-money laundering statute, receiving Presidential assent on 17 January 2003 and coming into force on 1 July 2005. The PMLA is administered by the Financial Intelligence Unit - India (FIU-IND) under the Ministry of Finance and by the Enforcement Directorate (ED) under the Ministry of Home Affairs. Section 3 defines the offence of money laundering: whosoever directly or indirectly attempts to indulge in or knowingly assists or is a party or is actually involved in any process or activity connected with the proceeds of crime, including its concealment, possession, acquisition, or use, and projecting or claiming it as untainted property, shall be guilty of the offence of money laundering. Section 4 prescribes punishment: rigorous imprisonment for a term of not less than three years extendable to seven years and a fine, with the term extendable to ten years for offences related to narcotic drugs and psychotropic substances under the NDPS Act 1985. Section 5 empowers the Director of FIU-IND or officers authorised by the Director to provisionally attach property believed to be proceeds of crime for 180 days pending adjudication. Section 12 imposes obligations on reporting entities (banking companies, financial institutions, and intermediaries as defined) to: maintain records of all cash transactions of INR 10 lakh or more; maintain records of all series of cash transactions integrally connected to each other that individually are below the reporting threshold but together amount to INR 10 lakh or more; maintain records of all suspicious transactions whether or not made in cash; and maintain records of cross-border wire transfers of INR 5 lakh or more. Section 12A requires reporting entities to maintain the records of the identity of its clients and beneficial owners and the account files and business correspondence relating to its clients for a period of five years from the date of cessation of transactions. Section 13 empowers the Director to impose a fine of INR 10,000 and in the case of a continuing failure, a further fine of INR 1,000 for each day of default, on any person who fails to comply with the provisions of Section 12. The Prevention of Money Laundering (Maintenance of Records) Rules 2005 implement the Section 12 obligations, prescribing KYC documentation requirements, customer due diligence (CDD) processes, enhanced due diligence (EDD) for politically exposed persons (PEPs) and high-risk customers, and suspicious transaction reporting (STR) procedures to FIU-IND.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "in-pocso-act-2012-section-3-penetrative-sexual-assault",
    "title": "India POCSO Act 2012 Section 3 - Penetrative Sexual Assault Against a Child",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 3 of the Protection of Children from Sexual Offences Act, 2012 (POCSO Act) of India defines penetrative sexual assault against a child (under 18). A person is said to commit penetrative sexual assault if (a) he penetrates his penis, to any extent, into the vagina, mouth, urethra or anus of a child or makes the child do so with him or any other person; or (b) he inserts, to any extent, any object or a part of the body, not being the penis, into the vagina, the urethra or anus of the child or makes the child do so with him or any other person; or (c) he manipulates any part of the body of the child so as to cause penetration into the vagina, urethra, anus or any part of body of the child or makes the child do so with him or any other person; or (d) he applies his mouth to the penis, vagina, anus, urethra of the child or makes the child to do so to such person or any other person. Penalty under Section 4: minimum 20 years rigorous imprisonment which may extend to life and fine; minimum life imprisonment for victims under 16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_section_3_a_penile_penetration",
        "core_offence_section_3_b_object_or_body_part_penetration",
        "core_offence_section_3_c_manipulation_causing_penetration",
        "core_offence_section_3_d_oral_genital_contact",
        "penalty_section_4_post_2019_amendment",
        "child_definition_section_2_d_under_18",
        "to_any_extent_threshold",
        "interaction_with_aggravated_section_5_6",
        "presumption_section_29_30",
        "extraterritorial_jurisdiction_section_45",
        "interaction_with_indian_penal_code_section_376"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "in-it-act-2000"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "in-rbi-act-1934",
    "title": "India Reserve Bank of India Act 1934 - Central Bank Constitution Functions and Monetary Policy",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Reserve Bank of India Act 1934 constitutes the Reserve Bank of India as the central bank of India, sets out its functions including the issue of bank notes, formulation and operation of monetary policy through the Monetary Policy Committee with the inflation target framework, regulation of foreign exchange and external sector under the Foreign Exchange Management Act, regulation of non-banking financial companies, lender of last resort and banker to the government, currency reserve management, and provides for the constitution of the Reserve Bank Central Board of Directors and the conduct of business.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "in-companies-act-2013"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "in-rbi-master-direction-kyc-2016",
    "title": "India RBI Master Direction on KYC 2016 - Customer Due Diligence & Risk Classification",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Reserve Bank of India Master Direction - Know Your Customer (KYC) Direction 2016 (updated through 2023) prescribes a four-tier customer risk classification (Low, Medium, High, Very High), document-based CDD requirements for individuals and legal entities, Video-based Customer Identification Process (V-CIP), mandatory linkage of Aadhaar with bank accounts (PMLA Rule 9(14)), periodic re-KYC (low risk: 10 years, medium: 8 years, high: 2 years), and Central KYC Records Registry (CKYC) integration. Banks must designate a Principal Officer and appoint a KYC Compliance Officer. FATF Recommendations 10-12 are implemented through these directions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fincen-cdd-beneficial-ownership-rule-2016",
      "eu-6amld-sixth-anti-money-laundering-2018-1673"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "in-rbi-nbfc-master-direction-prudential-2023",
    "title": "India RBI NBFC Master Direction - Scale Based Regulation (SBR) Prudential Norms 2023",
    "domain": "Banking & Global Finance",
    "version": "2023.1.0",
    "last_updated": "2023-10-01",
    "bluf": "RBI's Scale Based Regulation (SBR) framework (effective October 2022) classifies NBFCs into four layers (Base/Middle/Upper/Top) with escalating prudential requirements: NBFC-BL minimum NOF ₹10 Cr; NBFC-ML CRAR ≥15% (Tier I ≥10%); NBFC-UL leverage ≤7x, LCR mandatory, 90-day NPA recognition; and enhanced governance/disclosure for all layers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "in-rbi-master-direction-kyc-2016",
      "fincen-cdd-beneficial-ownership-rule-2016",
      "eu-capital-requirements-directive-iv-2013-36-crd4"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "in-rbi-prompt-corrective-action-framework-2022",
    "title": "India RBI Prompt Corrective Action (PCA) Framework for Banks 2022",
    "domain": "Banking & Global Finance",
    "version": "2022.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The Reserve Bank of India's revised Prompt Corrective Action (PCA) Framework (November 2022) establishes early intervention triggers based on Capital to Risk-Weighted Assets Ratio (CRAR), Tier 1 Leverage Ratio, and Net NPA Ratio thresholds, imposing structured restrictions on dividend payments, branch expansion, and lending activities on banks that breach risk thresholds - with the objective of facilitating timely supervisory intervention before distress becomes irreversible.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "basel_iii",
        "fsb_resolution",
        "bcbs_supervisory_review",
        "eba_srep"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-capital",
      "in-rbi-master-direction-kyc-2016",
      "bcbs-sound-stress-testing-practices"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "in-sebi-ai-ml-algo-trading-framework-2025",
    "title": "India SEBI 2025 AI/ML and Algorithmic Trading Framework - Governance, Disclosure, White Box/Black Box Classification, Retail Investor Safer Participation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Market participants regulated by the Securities and Exchange Board of India (SEBI) using AI and ML in algorithmic trading, asset management, portfolio management, or advisory services must disclose AI/ML usage, designate senior management with technical expertise to oversee performance and control, maintain validation, documentation and interpretability of models, and share accuracy and audit findings with SEBI periodically, while the 4 February 2025 SEBI directive on safer participation of retail investors in algo trading classifies algorithms into White Box (transparent execution algos) and Black Box (non-disclosed algos requiring a Research Analyst License for providers), requires brokers to implement API gateway restrictions, static-IP whitelisting, authentication, order logging, monitoring and kill-switch capability, and requires submissions through the Enhanced Supervision Portal (NIL declaration or detailed data forms specifying purpose, operational scope, safeguards, and vendor details).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "in-sebi-listing-obligations-disclosure"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "in-sebi-listing-obligations-disclosure",
    "title": "India SEBI LODR 2015 - Listing Obligations and Disclosure Requirements",
    "domain": "Banking & Global Finance",
    "version": "1.2.1",
    "last_updated": "2026-04-30",
    "bluf": "SEBI (Listing Obligations and Disclosure Requirements) Regulations 2015 govern disclosure obligations for companies listed on Indian stock exchanges (NSE/BSE). Listed entities must disclose price-sensitive information immediately, file financial results quarterly, maintain a board with ≥50% independent directors, constitute audit/nomination/remuneration committees, publish corporate governance reports, and comply with related party transaction policies. LODR also mandates Business Responsibility and Sustainability Reporting (BRSR) for the top 1,000 listed companies from FY2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-market-abuse-regulation-596-2014",
      "eu-csrd-2022-2464",
      "eu-capital-requirements-directive-iv-2013-36-crd4"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "in-toto-attestation-framework-cncf",
    "title": "in-toto Attestation Framework (CNCF Graduated, Statement v1, Predicate Types: SLSA Provenance, VEX, SCAI, Vulnerability Scan, Test Result, Link, Layout; DSSE Signing)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "in-toto is the Cloud Native Computing Foundation (CNCF) graduated framework for supply chain integrity attestations. The in-toto Attestation Framework (at github.com/in-toto/attestation) provides a specification for generating verifiable claims about any aspect of how a piece of software is produced. It distinguishes between the Statement (the envelope, type 'https://in-toto.io/Statement/v1' that wraps the attestation, lists the subjects with artifact digests, and references a predicateType URI) and the Predicate (the payload metadata format vetted by in-toto maintainers). The vetted predicate types include SLSA Provenance v1.0 (build provenance), VEX (Vulnerability Exploitability Exchange) v1.0, SCAI (Supply Chain Attribute Integrity for arbitrary supply-chain claims), Vulnerability Scan, Test Result, Link (the original in-toto chain-of-custody link metadata), and Layout (the original in-toto supply-chain layout specification). Statements are signed using DSSE (Dead Simple Signing Envelope, the canonical envelope format for in-toto and SLSA attestations) which wraps the JSON-encoded Statement with one or more signatures from authorised signers; DSSE separates payload from signatures using a PAE (Pre-Authentication Encoding) to prevent ambiguity attacks. in-toto integrates with Sigstore's Cosign for OIDC-bound signing and with Rekor for transparency-log inclusion. CNCF graduation in 2023 elevated in-toto from incubation to the highest CNCF maturity tier alongside Kubernetes, Helm, and Prometheus. Language bindings exist for Go (most mature), Python, Rust, and Java. The original in-toto framework also defines a chain-of-custody model with software supply chain layouts, functionaries (authorised actors), steps with expected inputs/outputs, and link metadata recording each step's execution; this is the foundation on which the modern Attestation Framework is built.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "statement_envelope_v1",
        "vetted_predicate_types",
        "dsse_signing_envelope",
        "sigstore_cosign_integration",
        "slsa_provenance_predicate_integration",
        "original_in_toto_layout_link_model",
        "language_bindings",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "slsa-supply-chain-security-levels",
      "sigstore-cosign-fulcio-rekor-keyless-signing",
      "spdx-3-0-iso-iec-5962-2021-sbom-standard",
      "cyclonedx-1-7-owasp-ecma-sbom-standard"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "incoterms-2020-cip-v2",
    "title": "Incoterms 2020: CIP (Carriage Insurance Paid)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Carriage Insurance Paid (CIP) under the Incoterms® 2020 framework dictates that a seller fulfills its delivery obligation and completes the transfer of risk once goods are handed to the initial carrier engaged by the seller. This critical transfer point, which is consistent with delivery stipulations within the UN Convention on Contracts for the International Sale of Goods, occurs at origin, even though the seller arranges and pays freight to a named destination as stipulated in Article A9/B9. A central seller responsibility under Article A5 involves procuring comprehensive cargo insurance; this policy must satisfy the stringent Institute Cargo Clauses (A) framework, representing an \"all risk\" standard, and provide coverage for a minimum of 110 percent of the commercial invoice value. The insurance currency must also match the contract's currency. While the seller is responsible for export clearance formalities, the buyer assumes all risk from the moment the consignment is with the first carrier and is therefore responsible for completing all import clearance procedures and settling associated duties upon arrival. The rule's schema confirms the seller arranges main carriage and provides insurance, but risk transfers early, making the buyer’s awareness of this dichotomy paramount for compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "incoterms-2020-fca-v2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "incoterms-2020-ddp-logic",
    "title": "Incoterms: DDP Compliance",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Delivered Duty Paid (DDP) is the maximum-obligation Incoterm for the seller. The seller delivers the goods at the disposal of the buyer at the named place of destination, cleared for import, and including all taxes and duties paid. Use with extreme caution as it requires the seller to navigate import regulations in the buyer's country.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "logistics-hs-classification",
      "wco-safe-framework-standards",
      "supply-chain-risk-triage",
      "iso-28000-supply-chain"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "incoterms-2020-ddp-v2",
    "title": "Incoterms 2020: DDP (Delivered Duty Paid)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Incoterms 2020 rule DDP (Delivered Duty Paid) imposes the maximum obligation upon the seller, who assumes all costs and risks until the goods are delivered to the named destination, ready for unloading. Per this rule, risk transfers when the consignment is destination-ready for unloading; the seller bears responsibility for both export and import customs formalities. Consequently, the seller pays all import duties plus any applicable VAT or GST, while the buyer does not provide import clearance. For the seller to fulfill these duties in jurisdictions like the United States, they often must qualify as a non-resident importer pursuant to U.S. Customs regulations under 19 CFR § 141.1, thereby directly incurring customs debt as outlined in frameworks such as the European Union's Union Customs Code. This extensive control over the entire transit places absolute liability on the seller for compliance with export controls, like the U.S. Export Administration Regulations and OFAC Sanctions Programs, making robust automated sanctions screening required. Furthermore, adherence to modern trade facilitation standards, including the WCO SAFE Framework, necessitates secure data exchange; therefore, cross-border EDI encryption using AES-256 is mandated for all electronic records, whose legal validity is recognized under principles like the UNCITRAL Model Law on Electronic Transferable Records. All related customs documentation must be maintained for a minimum of five years, fulfilling the specified customs record retention period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "incoterms-2020-ddp-logic",
      "wco-safe-framework-standards",
      "logistics-hs-classification"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "incoterms-2020-exw",
    "title": "Incoterms 2020: EXW (Ex Works)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Ex Works (EXW) under the ICC Incoterms® 2020 rules establishes a transaction imposing maximum obligation on the buyer and minimal responsibility on the seller, whose delivery duty consistent with principles in CISG Article 31 is fulfilled by placing goods at the buyer’s disposal alongside a provided commercial invoice. Consequently, both risk transfer and cost transfer occur at origin before loading commences. The schema dictates there is no seller loading obligation; should assistance be provided, maximum liability for resultant damage is zero USD. The buyer assumes all subsequent duties, including arranging carriage, bearing complete transit insurance risk, and managing both export plus import clearance procedures. This seller explicitly retains no export clearance obligation. Since the transaction is flagged as a routed export transaction, US Export Administration Regulations under 15 CFR § 758.3 apply, which requires buyer export license validation. Such buyer responsibility for customs formalities, including declarations per EU Union Customs Code Article 166, is absolute. For digital compliance, any EDI transmission security must utilize TLS 1.2 or a superior protocol, conforming to information management standards from ISO/IEC 27001:2022. Finally, electronic record retention is mandated for five years, with data protection following controlled unclassified information guidelines outlined within NIST SP 800-171 Rev. 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "incoterms-2020-fca-v2",
      "incoterms-2020-ddp-v2",
      "incoterms-2020-cip-v2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "incoterms-2020-fca-logic",
    "title": "Incoterms: FAS (Free Alongside Ship)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Free Alongside Ship (FAS) is a maritime-only Incoterm where the seller delivers the goods when they are placed alongside the vessel nominated by the buyer at the named port of shipment. FAS 2020 requires the seller to clear the goods for export, making it a common choice for liquid bulk or heavy-lift cargo shipments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hague-visby-rules",
      "imo-solas-safety-at-sea",
      "port-facility-security-isps",
      "wco-safe-framework",
      "rotterdam-rules-maritime"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "incoterms-2020-fca-v2",
    "title": "Incoterms 2020: FCA (Free Carrier)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Free Carrier (FCA) compliance mandates the seller deliver goods cleared for export, as `seller_export_customs_clearance_required` is true, unto a carrier designated by the buyer. A critical operational parameter is that `fca_named_place_explicitly_defined` must be satisfied, articulating the handover point with precision. According to the ICC Incoterms® 2020 Explanatory Notes for Users, this named location determines loading duties; if delivery transpires at the seller’s facility, the `seller_loading_obligation_at_premises` is triggered, whereas at any alternative place, the buyer’s `buyer_unloading_obligation_at_other_place` is engaged. The transfer of risk, governed by Article A2/B2 stipulations, aligns with this delivery to the first carrier-a concept consistent with the United Nations Convention on Contracts for the International Sale of Goods under Article 31 (a). This transfer must finalize inside the `max_delivery_delay_window_days` of 14. The buyer’s responsibilities encompass all subsequent costs and arranging for `buyer_import_customs_clearance_required`. Authenticating the carrier selection, where `carrier_nominated_by_buyer_verified` is configured, demands robust validation; `mfa_required_for_carrier_nomination` supports this process, with its legal effect on electronic signatures recognized under frameworks like the eIDAS Regulation. Moreover, transmission of digital transport records must uphold stringent confidentiality, necessitating an `electronic_shipping_doc_encryption_aes_min` standard of 256-bit AES encryption consistent with NIST Special Publication 800-171 Rev 2. While Incoterms® 2020 Article A6/B6 introduces a mechanism for an on-board bill of lading, the parameter `on_board_bill_of_lading_requested` being false renders it inapplicable. Finally, no `insurance_obligation_mandated` is imposed upon either counterparty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "incoterms-2020-fob-logic",
    "title": "Incoterms: FOB Risk Transfer",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Free On Board (FOB) is an Incoterm limited to sea and inland waterway transport. Under FOB 2020, the seller delivers the goods on board the vessel nominated by the buyer at the named port of shipment, at which point the risk of loss or damage and the costs transfer to the buyer.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hague-visby-rules",
      "imo-solas-safety-at-sea",
      "ism-code-vessel-safety",
      "port-facility-security-isps",
      "wco-safe-framework-standards"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "india-abdm-health-data-governance-2026",
    "title": "India Ayushman Bharat Digital Mission (ABDM) - Health Data Management and Governance Policy",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "ABDM creates a federated digital health ecosystem with ABHA (Ayushman Bharat Health Account), consent managers, and standardised data exchange. The Health Data Management Policy enforces patient consent, data minimisation, security, interoperability via FHIR, and accountability for all ecosystem participants.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 3
  },
  {
    "node_id": "india-advance-pricing-agreement-rules-2012",
    "title": "India Income-tax Rules 10F-10T: Advance Pricing Agreement Scheme",
    "domain": "Tax & Transfer Pricing",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "India's Advance Pricing Agreement (APA) scheme is set out in Rules 10F to 10T of the Income-tax Rules, 1962, inserted by the Income-tax (Tenth Amendment) Rules, 2012 (effective 30 August 2012) and made under sections 92CC and 92CD of the Income-tax Act, 1961. Rule 10F defines the expressions used in APA matters; Rule 10G sets out the persons eligible to apply; Rule 10H governs pre-filing consultation; and the application itself is made under Rule 10I in Form No. 3CED with the prescribed fee. Cite the key clause: Rule 10I (application for advance pricing agreement) read with Rule 10G (persons eligible to apply).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-attribution-profits-permanent-establishments-2010",
      "oecd-financial-transactions-transfer-pricing-2020"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "india-arbitration-conciliation-act-1996-amendment-2021",
    "title": "The Arbitration and Conciliation Act, 1996 (as amended by Act No. 37 of 2021)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The 2021 amendment to India's Arbitration and Conciliation Act introduces mandatory automatic stay of arbitral awards upon filing of a challenge if fraud or public policy violation is alleged, establishes qualifications for arbitrators under the Eighth Schedule, and strengthens institutional arbitration through the Arbitration Council of India (ACI). It applies to all domestic, international, and commercial arbitrations seated in India.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "arbitration-uncitral-rules",
      "uncitral-model-law-intl-commercial-arb-2006"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-bharat-ncap-vehicle-safety-rating-ais-197-2023",
    "title": "India Bharat NCAP Vehicle Safety Rating Programme - AIS-197:2023 Crash Test Protocol and MoRTH Type Approval Requirements",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "India's Bharat New Car Assessment Programme (Bharat NCAP) was launched by the Ministry of Road Transport and Highways (MoRTH) through Gazette Notification GSR 663(E) dated 18 September 2023, making India the world's 6th country with its own NCAP programme; Bharat NCAP is grounded in Automotive Industry Standard AIS-197:2023 published by the Automotive Research Association of India (ARAI) and applies to M1 category passenger vehicles (petrol, diesel, CNG, and electric) sold in India with a gross vehicle weight not exceeding 3,500 kg; vehicles are assessed on two independent Adult Occupant Protection (AOP) and Child Occupant Protection (COP) scales, each rated 0-5 stars; the AOP protocol includes: a full-width rigid barrier frontal impact at 56 km/h, an offset deformable barrier frontal impact at 64 km/h (40% overlap), and a moving deformable barrier side impact at 50 km/h; the COP protocol assesses dynamic child occupant behaviour and the provisions made for child restraint systems (CRS); additional assessments for ESC (Electronic Stability Control) and seat belt reminder systems contribute bonus points; Bharat NCAP testing is conducted at MoRTH-accredited test agencies (ARAI Pune, NATRiP GARC Chennai, iCAT Manesar); star ratings are published publicly by MoRTH; manufacturers may voluntarily submit vehicles for Bharat NCAP assessment and are required to submit vehicles for type approval under the Central Motor Vehicles Rules 1989 Rule 126.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-motor-vehicles-act-1988-amendment-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-biological-diversity-act-2002-access-benefit-sharing",
    "title": "India Biological Diversity Act 2002 - Access to Biological Resources and Benefit Sharing",
    "domain": "Biotech & Genomics",
    "version": "Act No. 18 of 2003 (amended 2023)",
    "last_updated": "2026-05-09",
    "bluf": "India's Biological Diversity Act 2002 (Act 18 of 2003) implements the Convention on Biological Diversity's access and benefit-sharing (ABS) framework: foreign nationals and companies require prior National Biodiversity Authority (NBA) approval to access Indian biological resources (Section 3); Indian entities must notify the State Biodiversity Board for commercial use (Section 7); IPR applicants must seek NBA approval before filing (Section 6); penalties include imprisonment up to five years and fines up to INR 10 lakh.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "cbd-convention-biological-diversity-1992"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-bocw-act-1996-construction-worker-welfare",
    "title": "India Building and Other Construction Workers Act 1996 - Welfare Board and Cess Framework",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "India's Building and Other Construction Workers (Regulation of Employment and Conditions of Service) Act 1996 and the BOCW Cess Act 1996 require construction establishments employing 10 or more workers to register with state welfare boards; levy 1% construction cess on project cost payable by the employer; mandate safety committees for 500+ worker sites; and provide welfare benefits including life insurance, medical, housing loan, and educational assistance to registered workers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-ohs-management-construction"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "india-cdsco-medical-device-rules-2026",
    "title": "India CDSCO - Medical Devices Rules 2017 (2026 Amendments) & Risk-Based Regulation",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The Central Drugs Standard Control Organisation (CDSCO) regulates medical devices under the Medical Devices Rules 2017 (amended 2026). Devices are classified into Classes A-D with increasing regulatory controls, mandatory registration, clinical evaluation, quality management, post-market surveillance, and import/manufacturing licensing requirements. AI and software-based devices have additional guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "india-cert-in-cyber-security-directions-2022",
    "title": "Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-04-28",
    "bluf": "These directions mandate all service providers, intermediaries, data centres, corporate bodies, and government organizations in India to report specific types of cyber incidents to CERT-In within 6 hours of detection (Direction 4), maintain system logs for a rolling 180-day period (Direction 5), and synchronize all ICT system clocks to Network Time Protocol (NTP) Servers of the National Physical Laboratory (NPL) or NIC (Direction 3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-53-au2",
      "guide-computer-security-log-management",
      "nis2-incident-reporting-article-23"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "india-cert-in-directions-2022-incident-reporting",
    "title": "Directions under Section 70B(6) of the Information Technology Act, 2000 Relating to Information Security Practices, Procedures and Processes, including Incident Response",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "All intermediaries, data centers, cloud service providers, virtual private network (VPN) services, and cryptocurrency exchanges operating in India must report cybersecurity incidents to CERT-In within 6 hours of detection. The regulation also mandates 180 days of log retention, synchronization with NTP servers, and registration of ICT infrastructure providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-availability",
      "aicpa-soc2-cc-processing-integrity",
      "uk-money-laundering-regulations-2017-amended"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-companies-act-2013-section-135-csr",
    "title": "India Companies Act 2013 - Corporate Social Responsibility (CSR) Provisions under Section 135: 2% of Average Net Profit Mandate, Schedule VII Activities, CSR Committee Formation, and Unspent Fund Transfer to PM CARES",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Companies incorporated in India with net worth ≥ ₹500 crore, turnover ≥ ₹1,000 crore, or net profit ≥ ₹5 crore must spend at least 2% of their average net profits from the preceding three years on CSR activities listed in Schedule VII. Failure to spend requires board explanation and transfer of unspent amounts to specified funds, including the PM CARES Fund.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp",
      "un-sdg-corporate-mapping"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-competition-act-2002-amendment-2023",
    "title": "The Competition (Amendment) Act, 2023 - Amendments to The Competition Act, 2002 relating to Deal Value Threshold, Gun-Jumping, Leniency, Settlement, Commitment, and Market Study Powers",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Competition (Amendment) Act, 2023 introduces a deal value threshold for merger control, strengthens enforcement against gun-jumping, enhances the leniency programme for cartel members, and establishes formal settlement and commitment mechanisms before the Competition Commission of India (CCI). It applies to enterprises involved in combinations, cartels, or anti-competitive conduct under Sections 3, 4, and 5 of The Competition Act, 2002 as amended.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-competition-act-2002-sections-3-4",
      "india-competition-amendment-act-2023-hsrc-threshold",
      "australia-accc-merger-review-guidelines-2023",
      "oecd-recommendation-hard-core-cartels-2019",
      "uk-cma-merger-assessment-guidelines-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "india-competition-act-2002-sections-3-4",
    "title": "The Competition Act, 2002 - Section 3: Anti-Competitive Agreements and Section 4: Abuse of Dominant Position",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "Prohibits anti-competitive agreements under Section 3 and abuse of dominant position under Section 4 of the Competition Act, 2002. Applies to enterprises, associations of enterprises, and persons engaged in trade or business in India. Enforcement by the Competition Commission of India (CCI) includes fines up to 10% of turnover or ₹10 crore, whichever is higher.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-competition-amendment-act-2023-hsrc-threshold",
    "title": "Competition (Amendment) Act, 2023 - Deal Value Threshold, Settlement Mechanism, Commitment Process and Leniency Programme Enhancement",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Competition (Amendment) Act, 2023 introduces a deal value threshold for merger control requiring notification to the Competition Commission of India (CCI) when the transaction value exceeds INR 2,000 crore, regardless of turnover or asset thresholds. It also establishes a settlement and commitment mechanism under Sections 27B and 27C, and enhances the leniency programme under Section 46, applicable to enterprises involved in anti-competitive agreements or abuse of dominance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeepers",
      "iso-37301-compliance-2021",
      "us-fdii-section-250-foreign-derived-intangible-income"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-consumer-protection-act-2019-ccpa",
    "title": "India Consumer Protection Act 2019 (Act 35) - CCPA Enforcement and Product Liability",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "India's Consumer Protection Act 2019 (Act 35 of 2019, in force 20 July 2020) replaces the 1986 Act; establishes the Central Consumer Protection Authority (CCPA) with suo motu investigation powers and authority to recall products and ban misleading advertisements; introduces product liability for manufacturers, sellers, and service providers; mandates mediation before adjudication; and raises pecuniary jurisdiction of District Commissions to INR 1 crore.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-consumer-protection-e-commerce-rules-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "india-consumer-protection-e-commerce-rules-2020",
    "title": "Consumer Protection (E-Commerce) Rules, 2020",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Consumer Protection (E-Commerce) Rules, 2020 mandate all e-commerce entities in India to appoint a grievance officer, display return/refund/warranty policies, disclose country of origin for products, distinguish between marketplace and inventory models, and comply with transparency requirements for flash sales. Applies to all e-commerce entities under the Department for Promotion of Industry and Internal Trade (DPIIT) and Ministry of Corporate Affairs (MCA) jurisdiction per Rule 3 and Rule 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29",
      "ftc-digital-advertising-disclosures",
      "can-spam-act-email"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-copyright-act-1957-amendment-2012",
    "title": "The Copyright Act, 1957 (as amended by the Copyright (Amendment) Act, 2012)",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The 2012 amendment to India's Copyright Act establishes unwaivable royalty rights for authors and performers, grants broadcast reproduction rights, defines ISP safe harbors under Section 79 of the IT Act, strengthens protection against circumvention of technological protection measures (TPMs), and introduces compulsory licensing for the benefit of persons with disabilities. Key provisions include Sections 18A, 31B, 38A-38I, and 65A.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-1886-2024-literary-artistic-works",
      "dmca-safe-harbor",
      "eu-copyright-directive-art-17",
      "c2pa-content-provenance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-digital-india-act-ai-provisions-2023",
    "title": "Digital India Act, 2023 - AI Provisions on Safe Harbour, Harmful AI, and Enforcement",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The proposed Digital India Act (DIA) 2023 introduces a risk-based framework for AI regulation, imposing legal accountability on platforms deploying 'high-risk AI systems' by limiting safe harbour protections and defining specific categories of AI-related user harm. This applies to all intermediaries and platforms using AI systems that impact users in India, with enforcement by the Ministry of Electronics and Information Technology (MeitY).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-niti-aayog-responsible-ai-2021",
      "eu-ai-act-high-risk",
      "nist-ai-rmf-1-0",
      "iso-23894-ai-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "india-dpdp-act",
    "title": "India DPDP Act 2023",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Digital Personal Data Protection (DPDP) Act of 2023 is India's principal statute for digital personal data, prioritizing individual rights and organizational obligations. It introduces the role of Consent Managers and Data Fiduciaries, with significant penalties (up to ₹250 crore) for non-compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "india-dpdp-act-2023-digital-personal-data",
    "title": "Digital Personal Data Protection Act, 2023",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Digital Personal Data Protection Act, 2023 governs the processing of digital personal data in India, requiring lawful consent, protection of children's data through parental consent, and establishment of the Data Protection Board of India for enforcement. It applies to all entities processing digital personal data in India, including data fiduciaries and processors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-privacy",
      "uk-money-laundering-regulations-2017-amended"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-dpdp-act-2023-personal-data-protection",
    "title": "The Digital Personal Data Protection Act, 2023",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2024-08-16",
    "bluf": "The Digital Personal Data Protection Act, 2023 (DPDP Act) governs the processing of digital personal data in India, imposing obligations on Data Fiduciaries to obtain clear, specific consent (Section 6) and implement reasonable security safeguards (Section 8). It grants Data Principals specific rights, including the right to access, correct, and erase their data, and establishes the Data Protection Board of India for enforcement and levying penalties for non-compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "oecd-privacy-guidelines-2013"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "india-drugs-cosmetics-act-1940-cdsco",
    "title": "India Drugs and Cosmetics Act 1940 - CDSCO Drug Approval, Schedule M GMP and Clinical Trial Regulation",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "India's Drugs and Cosmetics Act 1940 (D&C Act) and the New Drugs and Clinical Trials Rules 2019 (NDCT Rules), administered by the Central Drugs Standard Control Organisation (CDSCO) under the Drug Controller General of India (DCGI), regulate marketing approval of new drugs, biologics, and medical devices; mandate Schedule M GMP compliance for all pharmaceutical manufacturers; require clinical trial approval from CDSCO before initiation; establish a waiver pathway for drugs approved in ICH-member countries; and impose penalties including licence cancellation and imprisonment up to 5 years for Schedule G and H violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-210-211-current-good-manufacturing-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "india-electricity-act-2003-cerc-open-access",
    "title": "India Electricity Act 2003 - CERC Tariff Regulation, Open Access and Renewable Purchase Obligation",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "India's Electricity Act 2003 (EA 2003, Act 36 of 2003, in force June 2003) replaced the Electricity Act 1948, Electricity Supply Act 1948, and Electricity Regulatory Commissions Act 1998; it established the Central Electricity Regulatory Commission (CERC) for interstate electricity regulation and tariff determination, and directed states to establish State Electricity Regulatory Commissions (SERCs); Section 42 mandates non-discriminatory open access to distribution networks for eligible consumers (threshold 1 MW for intra-state, phased to include 100 kW consumers by SERC order); the Act requires power trading licences (Section 12), Renewable Purchase Obligation (RPO) targets set by SERCs, and NLDC/RLDC/SLDC grid management oversight; tariff determination follows multi-year tariff regulations (CERC MYT Regulations 2019) with cost-plus and bid-based methodologies; penalties for electricity theft under Section 135 include rigorous imprisonment up to 3 years plus fine equal to the assessed amount; the EA 2003 Electricity Amendment Act 2022 and 2023 further reformed renewable integration and open access barriers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-electricity-amendment-act-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "india-electricity-amendment-act-2022",
    "title": "The Electricity (Amendment) Act, 2022: Amendments to Franchise Licensing, Renewable Purchase Obligations, Smart Metering, and CERC Appellate Jurisdiction",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This act amends the Electricity Act, 2003 to de-license electricity distribution by allowing multiple private franchisees in the same area of supply, mandates minimum Renewable Purchase Obligations (RPOs) to promote green energy, and expands the jurisdiction of the Central Electricity Regulatory Commission (CERC). It applies to all electricity generation, transmission, and distribution companies (DISCOMs) in India.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "india-environmental-protection-act-1986-epa",
    "title": "The Environment (Protection) Act, 1986",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Environment (Protection) Act, 1986 empowers the Central Government to take measures to protect and improve environmental quality, including setting standards for emissions and discharges, regulating hazardous industries, and mandating environmental clearance for specified projects. It applies to all industries, operations, and processes across India that may cause environmental pollution, with enforcement by CPCB and SPCBs under the principle of absolute liability as established in MC Mehta v. Union of India.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "espoo-convention-1991-transboundary-eia",
      "basel-convention-1989-hazardous-waste-transboundary",
      "aarhus-convention-1998-environmental-access",
      "cdp-climate-questionnaire-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-foreign-contribution-regulation-act-2010-fcra",
    "title": "Foreign Contribution (Regulation) Act, 2010",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Foreign Contribution (Regulation) Act, 2010 regulates the acceptance and utilization of foreign contribution or foreign hospitality by individuals, associations, and NGOs in India. It mandates prior registration or prior permission for receiving foreign funds, requires maintenance of a designated FCRA bank account at SBI, New Delhi, and submission of annual returns (Form FC-4) to the Ministry of Home Affairs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "fatf-recommendation-16-travel-rule-crypto"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-foreigners-act-1946-bureau-of-immigration",
    "title": "India Foreigners Act 1946 - Bureau of Immigration and Visa Regime",
    "domain": "Immigration & Border Control",
    "version": "2.4",
    "last_updated": "2026-05-10",
    "bluf": "The Foreigners Act 1946 (Act No.31 of 1946) and the Registration of Foreigners Act 1939 are India's principal immigration statutes, conferring on the Central Government plenary power to regulate the entry, presence, movement and departure of all foreigners. The Bureau of Immigration (BoI), under the Ministry of Home Affairs, operates 24/7 at all major international airports and ports. India's e-Visa facility (available for 166 countries) is processed through the Indian Visa Online portal. Foreigners residing more than 180 days must register with the Foreigners Regional Registration Office (FRRO) within 14 days of arrival under the Registration of Foreigners Rules 1992. Section 14 of the Foreigners Act provides imprisonment up to 5 years for violation of the Act's provisions. Protected Area Permits (PAP) and Restricted Area Permits (RAP) are required for certain border regions under the Foreigners (Restricted Areas) Order 1963.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "icao_doc",
        "aadhaar",
        "asean",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "india-fssai-food-safety-and-standards-act-2006",
    "title": "India Food Safety and Standards Act 2006 (FSSAI Act) and Implementing Regulations",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "The Food Safety and Standards Act 2006 (FSS Act) consolidated multiple Indian food laws into a single integrated framework administered by the Food Safety and Standards Authority of India (FSSAI). The Act creates Central Licensing Authorities and State Licensing Authorities, requires every food business operator (FBO) to hold a licence (FSSAI Licence) or registration (FSSAI Registration) depending on turnover threshold, establishes food safety standards via the FSS Regulations 2011 series, mandates labelling per the FSS Packaging and Labelling Regulations 2011, sets maximum levels for contaminants and residues per the FSS Contaminants Regulations 2011, and prohibits sale of unsafe, sub-standard, or misbranded food. the relevant section grants Food Safety Officers powers of inspection, sampling, and seizure; the relevant section penalties include monetary penalty, imprisonment, and licence cancellation. The Act applies to all stages of the food value chain from manufacturing through transport, storage, distribution, sale, and import.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "codex_alimentarius",
        "wto_sps_tbt",
        "fda_fsma_imports",
        "eu_imports",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-cxs-1-1985-labelling-prepackaged-foods",
      "codex-cxs-192-1995-food-additives-gsfa",
      "codex-cxs-193-1995-contaminants-toxins-food-feed"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "india-fssai-food-safety-standards-act-2006",
    "title": "Food Safety and Standards Act, 2006",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes the Food Safety and Standards Authority of India (FSSAI) and mandates science-based standards for food articles to ensure safe and wholesome food for human consumption. It applies to all food business operators involved in the manufacture, storage, distribution, sale, and import of food products under Section 3 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-fssai-labelling-display-regulations-2020",
    "title": "Food Safety and Standards (Labelling and Display) Regulations, 2020",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "These regulations mandate standardized front-of-pack labelling (FOPO), allergen declarations, nutritional information, date markings, non-vegetarian symbol usage, and organic claims for pre-packaged foods in India. Compliance is required under Regulation 2.2 and subsequent clauses of the Food Safety and Standards (Labelling and Display) Regulations, 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-labelling-regulation-1169-2011",
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "iso-20022-messaging"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-goods-services-tax-appeals-tribunal-2023",
    "title": "GST Appellate Tribunal (GSTAT) - Section 109 of the Central Goods and Services Tax Act, 2017, as amended by the Finance Act 2023",
    "domain": "Tax & Transfer Pricing",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The GST Appellate Tribunal (GSTAT) is established under Section 109 of the Central Goods and Services Tax Act, 2017 (CGST Act), as amended by the Finance Act 2023, for resolving disputes under the Goods and Services Tax regime in India. An appeal requires a 20% pre-deposit of the disputed tax under Section 112(8). Appeals are heard by a bench of not less than two members, at least one Judicial Member and one Technical Member; matters involving Rs 50 lakh or less may be heard by a single-member bench. Tribunal procedure is governed by the GSTAT (Procedure) Rules 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-arm-length-principle-article-9-oecd-model",
      "australia-transfer-pricing-laws-amendment-2012",
      "canada-transfer-pricing-income-tax-act-section-247"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-gst-goods-services-tax-2017-council",
    "title": "The Constitution (One Hundred and First Amendment) Act, 2016, and The Central Goods and Services Tax Act, 2017, Integrated Goods and Services Tax Act, 2017, and Union Territory Goods and Services Tax Act, 2017",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The India Goods and Services Tax (GST) 2017 establishes a dual GST model (CGST/SGST/IGST), mandates e-invoicing for taxpayers with aggregate turnover above ₹5 crore, requires annual return filing (GSTR-9), implements reverse charge mechanism on specified supplies, enforces input tax credit matching via GSTR-2B, and extends GST to digital services supplied by non-residents under OIDAR provisions. Applies to all suppliers of goods and services in India with turnover exceeding prescribed thresholds under Section 22 of CGST Act, 2017.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-arm-length-principle-article-9-oecd-model",
      "australia-transfer-pricing-laws-amendment-2012",
      "eu-anti-tax-avoidance-directive-atad-2016-1164"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-ibc-insolvency-bankruptcy-code-2016",
    "title": "Insolvency and Bankruptcy Code, 2016 - Corporate Insolvency Resolution Process (CIRP), Liquidation, and Pre-Packaged Insolvency Framework",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Insolvency and Bankruptcy Code, 2016 establishes a time-bound corporate insolvency resolution process (CIRP) of 180 days, extendable by 90 days under Section 12, for resolving insolvency of corporate debtors. It applies to financial and operational creditors, resolution applicants, and insolvency professionals regulated by the Insolvency and Bankruptcy Board of India (IBBI).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-irdai-insurance-act-1938-regulations-2024",
      "au-apra-prudential-standard-aps-110-adi",
      "australia-apra-gps-110-capital-adequacy-general"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-insurance-regulatory-irda-regulations-2024",
    "title": "IRDAI Information and Cyber Security Guidelines, 2023 - Cyber Security Framework for Insurers and Intermediaries",
    "domain": "Insurance & Risk",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "The IRDAI Information and Cyber Security Guidelines, 2023 were notified by the Insurance Regulatory and Development Authority of India (IRDAI) on 24 April 2023, replacing the 2017 Information and Cyber Security Guidelines. They apply to insurers (including foreign reinsurance branches) and a wide range of intermediaries (brokers, corporate agents, web aggregators, TPAs, IMFs, insurance repositories, ISNPs, corporate surveyors, MISPs, CSCs and the Insurance Information Bureau of India). The 2023 guidelines emphasise data-centric security (securing the data itself, not just the network), board-level accountability with quarterly information-security review, an Information Security Risk Management Committee (ISRMC), CISO-led governance, security controls, incident response planning, periodic security audits, third-party/outsourcing risk management and data-localisation requirements for logs and critical data. There is no 'IRDAI Information and Cybersecurity Guidelines, 2026'; this node is anchored to the 2023 guidelines as notified.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-cps-234-information-security-insurance",
      "eu-commission-implementing-regulation-2015-2452-solvency",
      "india-consumer-protection-e-commerce-rules-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-irdai-insurance-act-1938-regulations-2024",
    "title": "India IRDAI Insurance Act 1938 (as amended) - Regulatory Framework for Insurers: Registration, Solvency Margins and Investment Norms (2024)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This framework, under the Insurance Act 1938 and IRDAI Act 1999, mandates that all insurers in India maintain a minimum solvency ratio of 150% (Section 64VA) and adhere to prescribed investment norms (Sections 27A, 27B, 27D) to ensure financial stability and protect policyholder interests.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "fatf-risk-based-approach-banking-sector-2014"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "india-irdai-insurance-regulatory-authority-2024",
    "title": "India IRDAI (Bima Sugam - Insurance Electronic Marketplace) Regulations, 2024 and the Bima Trinity Initiatives (Bima Vistaar, Bima Sugam, Bima Vahak)",
    "domain": "Insurance & Risk",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "The Insurance Regulatory and Development Authority of India (IRDAI) is pursuing the 'Bima Trinity' policy initiative: Bima Vistaar (an affordable bundled cover), Bima Sugam (a unified digital insurance marketplace) and Bima Vahak (a women-centric distribution network). The legal instrument establishing the digital marketplace is the IRDAI (Bima Sugam - Insurance Electronic Marketplace) Regulations, 2024 (Notification F. No. IRDAI/Reg/5/199/2024, dated 20 March 2024, in force 21 March 2024). There is no 'IRDAI Circular No. IRDAI/REG/CIR/2024/01' with a 'Clause 4.3' or 'Regulation 12A'; those references were not verifiable and have been removed. The foreign direct investment (FDI) limit in Indian insurance companies was 74 percent (raised from 49 percent in 2021), not 100 percent in 2024; any move to a higher cap is a separate legislative matter and was not enacted by these Regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "china-cbirc-c-ross-ii-solvency-2022",
      "eu-delegated-regulation-2016-467-non-life-premium-risk",
      "eu-eiopa-guidelines-orsa-2015"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-irdai-insurance-web-aggregator-regulations-2017",
    "title": "Insurance Web Aggregator Registration, Product Neutral Display Obligation, Revenue Caps on Referral Fees, Comparison Tool Standards, No Recommendation Bias, Data Protection of Policyholder Information and Annual Reporting",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation governs the operation of insurance web aggregators in India, mandating registration with IRDAI, neutral product display, prohibition of biased recommendations, data protection of policyholder information, and annual reporting. Key obligations are derived from IRDAI circulars and guidelines as at 2026, particularly those concerning information and cybersecurity, referral practices, and policyholder servicing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-consumer-protection-e-commerce-rules-2020",
      "australia-apra-cps-234-information-security-insurance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-it-act-2000-amendment-2008",
    "title": "Information Technology Act, 2000 (Amendment 2008)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Information Technology Act, 2000 (as amended in 2008) establishes legal recognition for electronic transactions, defines cyber offences, imposes data protection obligations on corporate bodies handling sensitive personal data, and outlines intermediary liability protections subject to due diligence requirements. It applies to all individuals and entities operating electronic systems or handling data within India, with enforcement through Adjudicating Officers and the Cyber Appellate Tribunal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-confidentiality",
      "aicpa-soc2-cc-privacy",
      "aicpa-soc2-cc-processing-integrity",
      "uk-money-laundering-regulations-2017-amended"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-legal-metrology-act-2009-packaged-commodities",
    "title": "India Legal Metrology Act 2009 - Packaged Commodities Rules, MRP Declaration and DPIIT Enforcement",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "India's Legal Metrology Act 2009 (Act No. 1 of 2010, in force 1 April 2011) repealed the Standards of Weights and Measures Act 1976 and its Enforcement Act 1985; the Act and its Legal Metrology (Packaged Commodities) Rules 2011 (LMPC Rules) mandate that every pre-packaged commodity sold in India bear mandatory declarations in English or Hindi including: name and address of manufacturer, packer, or importer; common or generic name of the commodity; net quantity in SI units; month and year of manufacture or packing; retail sale price (MRP) stated as 'Maximum Retail Price inclusive of all taxes'; and customer care number; administered by the Department for Promotion of Industry and Internal Trade (DPIIT) with enforcement by state-level Controllers of Legal Metrology; importers require a Legal Metrology Packaged Commodities (LMPC) Certificate and a 45-day window to affix compliant declarations; penalties for incorrect net quantity: INR 25,000 for first offence, INR 50,000 for second offence, INR 1 lakh plus up to 1 year imprisonment for third and subsequent offences; e-commerce Rule 6 requires MRP declaration and mandatory digital display of all statutory information for online retail.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-consumer-protection-act-2019-ccpa"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "india-meity-cloud-security-framework-2020",
    "title": "India MeitY Cloud Security Framework 2020 - GI Cloud Meghraj Empanelment, STQC Certification and Government Cloud Adoption",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "India's Ministry of Electronics and Information Technology (MeitY) published the Cloud Service Centre Security Framework (CSCF) and the Government Cloud (GI Cloud 'Meghraj') empanelment policy establishing the requirements for cloud service providers seeking to supply cloud services to Indian government ministries, departments, and public sector undertakings; the GI Cloud Meghraj initiative was launched under the National e-Governance Plan (NeGP) and is administered by the National Informatics Centre (NIC) and the Standardisation Testing and Quality Certification (STQC) Directorate; CSPs wishing to be empanelled to serve government workloads must demonstrate: ISO/IEC 27001:2013 information security management system certification, ISO/IEC 20000-1 IT service management certification, SOC 2 Type II audit report, compliance with the MeitY Cloud Policy 2017 (mandating data localisation for sensitive government data), and STQC empanelment process completion including a technical audit of the CSP's cloud infrastructure; MeitY's 2020 revision of the Cloud Policy strengthened data localisation requirements: sensitive personal data and critical government data must be stored and processed in India; the Digital Personal Data Protection Act 2023 (DPDPA 2023) further reinforces localisation requirements for certain categories of personal data; STQC conducts on-site technical audits of CSP data centres in India as part of the empanelment process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cloud-certification-scheme-eucs-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-meity-online-gaming-rules-2023",
    "title": "The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2023 - Regulation of Online Gaming and Recognition of Self-Regulatory Bodies",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The MeitY Online Gaming Rules 2023 require online gaming platforms operating in India to implement a robust self-regulatory framework, verify users as per prescribed due diligence, and distinguish between games of skill and games of chance under Rule 7(2). Applies to all intermediaries hosting online games accessible in India.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l3"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-merchant-shipping-act-1958-dgshipping",
    "title": "India Merchant Shipping Act 1958 - DGSHIPPING Survey, Certification and Colombo MOU Port State Control",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "India's Merchant Shipping Act 1958 (Act 44 of 1958, as amended through the Merchant Shipping (Amendment) Act 2016) administered by the Directorate General of Shipping (DG Shipping) regulates Indian-flagged vessel registration, survey, certification, seafarer certification and manning, casualty investigation, and wreck removal; India is a signatory to all major IMO conventions; Indian ports are subject to Port State Control (PSC) under the Colombo Memorandum of Understanding (MOU) 1998; DGSHIPPING enforces Indian coastal trade reservation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-stcw-convention-1978-2010-manila"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "india-motor-vehicles-act-1988-amendment-2019",
    "title": "The Motor Vehicles (Amendment) Act, 2019",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Motor Vehicles (Amendment) Act, 2019 mandates enhanced third-party insurance coverage, establishes a framework for vehicle recalls, introduces automated testing standards for transport vehicles, and requires licensing of aggregators such as ride-hailing platforms. Key obligations are defined under Sections 194, 196B, 196C, and 196D, applying to manufacturers, insurers, transport aggregators, and state transport authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021",
      "oecd-recommendation-insurance-good-practices-2004"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-namami-gange-mission-2014-clean-ganga",
    "title": "India National Mission for Clean Ganga (Namami Gange) and the National Ganga Council 2014",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2016-10-07",
    "bluf": "Namami Gange is the Government of India's flagship integrated programme for the rejuvenation of the Ganga River and its tributaries, approved by the Union Cabinet in May 2015 with a budget of approximately INR 20,000 crore over five years and subsequently extended to 2026 with continued funding. The programme is administered by the National Mission for Clean Ganga (NMCG) under the Ministry of Jal Shakti through the Department of Water Resources, River Development and Ganga Rejuvenation. The statutory framework for the programme is provided by the River Ganga (Rejuvenation, Protection and Management) Authorities Order 2016 issued by the central government on 7 October 2016 under the Environment (Protection) Act 1986.\n\nThe 2016 Order establishes a five-tier institutional structure: the National Ganga Council (NGC) chaired by the Prime Minister with the chief ministers of the Ganga Basin states (Uttarakhand, Uttar Pradesh, Bihar, Jharkhand, and West Bengal) and Union Ministers; the Empowered Task Force on River Ganga chaired by the Union Minister of Water Resources, River Development and Ganga Rejuvenation; the National Mission for Clean Ganga as the implementation arm; the State Ganga Committees in each Basin state; and the District Ganga Committees in each district along the river. NMCG has powers to issue directions for protection and rejuvenation of the river including directions on industrial effluent management, sewage treatment, ghat development, and afforestation. The programme's eight pillars include sewerage infrastructure, river-front development, river-surface cleaning, biodiversity, afforestation, public awareness, industrial effluent monitoring, and Ganga Gram (rural sanitation).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-water-prevention-control-pollution-act-1974"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "india-national-education-policy-nep-2020",
    "title": "National Education Policy 2020",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The National Education Policy 2020 mandates a comprehensive transformation of India's education system, including restructuring school education into a 5+3+3+4 curricular framework, establishing multidisciplinary higher education institutions, and achieving 6% of GDP investment in education. It applies to all levels of government and educational institutions across India, with key directives in Section 4.1 (School Education), Section 11.1 (Higher Education), and Section 21 (Public Investment).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998",
      "un-sdg-4-education-2030-framework-action"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-national-health-authority-abdm-2021",
    "title": "Ayushman Bharat Digital Mission (ABDM) 2021 - Health ID (ABHA Number), Health Facility Registry (HFR), Healthcare Professionals Registry (HPR), Unified Health Interface (UHI), Personal Health Records (PHR) Linked Consent Manager and ABDM Sandbox API Gateway",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The ABDM 2021 framework establishes a national digital health ecosystem in India requiring all healthcare providers, facilities, and technology systems to register with designated ABDM registries and comply with data privacy, consent management, and interoperability standards. Key obligations include enrollment in the Health ID system and adherence to the Consent Framework for Personal Health Records.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gdpr-health-data-article-9",
      "eu-ehds-regulation-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-national-logistics-policy-2022",
    "title": "National Logistics Policy 2022",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The National Logistics Policy 2022 establishes a framework for reducing logistics costs in India to 8% of GDP through integration of the PM Gati Shakti National Master Plan, implementation of the Unified Logistics Interface Platform (ULIP), and development of multimodal logistics parks. It applies to all central and state government agencies, logistics infrastructure providers, and private sector stakeholders involved in freight movement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bimco-standard-charter-party-terms",
      "cmr-convention-1956-road-carriage-goods",
      "cotif-cim-1999-rail-carriage-goods"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-national-space-policy-2023",
    "title": "India National Space Policy 2023 - IN-SPACe Regulatory Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "India's National Space Policy 2023 (released April 2023) transforms India's space sector by enabling non-government entities (NGEs) to independently design, build, launch, and operate satellites and launch vehicles. IN-SPACe (Indian National Space Promotion and Authorisation Centre) is the nodal regulatory body; ISRO remains the government's R&D and national security agency; NSIL (New Space India Ltd) is the commercial arm. FDI up to 100% is permitted in satellite manufacturing and launch vehicle segments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "inspace_regulations",
        "fdi_policy"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "india-niti-aayog-responsible-ai-2021",
    "title": "Responsible AI for All: Adopting the Framework - A use-case approach for India (Part 1 and 2)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This guidance document from India's NITI Aayog establishes a voluntary framework with seven guiding principles for the ethical development and deployment of AI systems. It applies to all stakeholders in India's AI ecosystem, urging the adoption of principles such as safety, equality, transparency, and accountability, as detailed in Chapter 3, to ensure AI solutions are inclusive and human-centric.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "unesco-ethics-ai",
      "india-dpdp-act",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "india-online-gaming-intermediary-rules-2023",
    "title": "The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2023 - Regulation of Online Gaming and Recognition of Self-Regulatory Bodies",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The India Online Gaming Intermediary Rules 2023 require online gaming platforms to verify users, implement self-regulatory body (SRB) oversight, distinguish games of skill from chance, protect user deposits, and establish a grievance redressal mechanism under Rule 7 of the IT (Intermediary Guidelines) Rules, 2011 as amended. Applies to all online gaming intermediaries operating in India.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-meity-online-gaming-rules-2023",
      "eu-5amld-article-2-gambling-2018",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-personal-data-protection-board-rules-2025",
    "title": "India DPDP Rules 2025 - Consent Manager Registration, Significant Data Fiduciary (SDF) Criteria (Data Volume/Sensitivity/National Security Risk), Data Localisation for Critical Data, Children's Processing Age Verification and DPBI Appeal Procedures",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The India DPDP Rules 2025 establish obligations for data fiduciaries processing personal data, including mandatory registration of Consent Managers, enhanced compliance for Significant Data Fiduciaries based on data volume, sensitivity, and national security risk, data localization for critical personal data, age verification for children's data processing, and formal appeal procedures before the Data Protection Board of India (DPBI). Key obligations derive from the overarching DPDP Act framework and its delegated rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-privacy",
      "uk-money-laundering-regulations-2017-amended"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-rbi-master-directions-kyc-2016",
    "title": "Master Direction - Know Your Customer (KYC) Direction, 2016 (Updated as on August 14, 2025)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "This regulation mandates all Reserve Bank of India (RBI)-regulated entities to implement customer identification, due diligence, risk categorization, and ongoing monitoring procedures in compliance with the Prevention of Money-Laundering Act, 2002 and FATF standards. It applies to all Regulated Entities (REs) as defined under Section 3(b)(xiv), including banks, NBFCs, and payment system operators, per Chapter I, Section 2(a).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bank-provisioning-emerging-market-economies"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-real-estate-regulatory-authority-rera-2016",
    "title": "The Real Estate (Regulation and Development) Act, 2016",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Mandates registration of real estate projects exceeding 500 square meters or 8 units with RERA, requires promoters to disclose project details and maintain 70% of collected funds in an escrow account, and grants allottees rights to information, timely possession, and a 5-year defect liability period. Key obligations under Section 3 and Section 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eia-directive-2014-52-environmental-assessment",
      "australia-national-construction-code-2022",
      "breeam-2018-building-assessment-method"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-seeds-act-1966-dac-ministry-agriculture",
    "title": "India Seeds Act 1966 - DAC Seed Certification, Variety Registration, and Quality Control Framework",
    "domain": "Agriculture & Agritech",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The Seeds Act 1966 (No. 54 of 1966) is India's primary legislation governing seed quality, variety testing, and the certification of seed for sale. The Department of Agriculture and Cooperation (DAC) under the Ministry of Agriculture and Farmers Welfare administers the Act through the Central Seed Committee (CSC) and State Seed Certification Agencies (SSCAs). The Seeds Act and Seeds Rules 1968 establish minimum germination, moisture, purity standards for notified seed varieties. Seed dealers must be licensed by state governments. The Central Sub-Committee on Crop Standards, Notification, and Release of Varieties (CVRC) evaluates and notifies new crop varieties for release. Approximately 450 crop varieties have been notified under the Seeds Act. Breeder seed production, foundation seed, and certified seed form the seed multiplication chain. The Protection of Plant Varieties and Farmers Rights Act 2001 (PPV&FR Act) complements the Seeds Act by providing plant variety protection to breeders. Penalties for selling below-standard seeds include imprisonment up to 6 months and fines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ppvfr_act",
        "insecticides_act",
        "environment_protection",
        "upov",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "india-semiconductor-mission-2021-chips",
    "title": "India Semiconductor Mission 2021 - INR 76,000 Crore Incentive Scheme for Semiconductor and Display Manufacturing",
    "domain": "Cloud & SaaS",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The India Semiconductor Mission (ISM) 2021 establishes a framework to incentivize domestic semiconductor, display, and compound semiconductor manufacturing through financial support of up to 50% of capital expenditure for approved facilities. It applies to eligible applicants including domestic and foreign companies setting up semiconductor fabrication units, ATMP/OSAT facilities, and display fabs in India.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "enisa-cloud-security-guidelines-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-space-policy-2023",
    "title": "India Space Policy 2023 - National Framework for Space Activities",
    "domain": "Space & Satellite Law",
    "version": "2023 (April 6, 2023)",
    "last_updated": "2026-05-09",
    "bluf": "India's Space Policy 2023 (approved April 6, 2023) is the Government of India's overarching framework for civilian space activities; it defines roles for the Indian Space Research Organisation (ISRO), NewSpace India Limited (NSIL), and IN-SPACe (Indian National Space Promotion and Authorisation Centre) as the regulatory body for private sector participation, establishes authorisation requirements for space activities by non-government entities, liberalises foreign direct investment in space, and sets priorities for launch services, satellite operations, space-based applications, and space science.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "copuos-lts-guidelines-2019-space-sustainability",
      "un-copuos-space-debris-mitigation-guidelines-2007"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-telecom-act-2023",
    "title": "The Telecommunications Act, 2023",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Telecommunications Act, 2023 establishes a modernized regulatory framework for India's telecom sector, consolidating and replacing legacy laws. It empowers the Department of Telecommunications (DoT) to designate critical telecom infrastructure, mandates lawful interception capabilities for service providers, introduces administrative penalties for violations, and extends licensing provisions to include certain OTT communication services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-telecommunications-interception-act-1979",
      "eu-5g-security-implementing-decision-2024",
      "china-network-security-law-2017"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-telecom-act-2023-dot-spectrum-licensing",
    "title": "India Telecom Act 2023 - DoT Spectrum Assignment and Licensing",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Telecommunications Act, 2023 (No. 44 of 2023) replaces the Telegraph Act 1885 and consolidates Indian telecom regulation; it vests all spectrum in the central government, requires a unified licence from the Department of Telecommunications (DoT), and grants government power to intercept communications for national security; TRAI retains tariff and QoS advisory role.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "india-tn-online-gambling-act-2022-online-games",
    "title": "India Tamil Nadu Prohibition of Online Gambling and Regulation of Online Games Act 2022",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2023-04-07",
    "bluf": "The Tamil Nadu Prohibition of Online Gambling and Regulation of Online Games Act 2022 was passed by the Tamil Nadu Legislative Assembly in October 2022 and received the Governor's assent on 7 April 2023 after the Madras High Court struck down its predecessor (the Tamil Nadu Gaming and Police Laws (Amendment) Act 2021) on 3 August 2022. The Act prohibits online gambling involving stakes and online games of chance played for money in Tamil Nadu and establishes the Tamil Nadu Online Gaming Authority (TNOGA) to register and regulate online games of skill played for stakes. The Act applies to any individual who plays online gambling or online games of chance for money in Tamil Nadu regardless of where the provider is located.\n\nThe Schedule to the Act prohibits online gambling and online games of chance played for money including rummy and poker (the Act categorises them as games of chance for the purposes of stake-based play). The Authority registers Indian and foreign online games providers, sets technical and operational standards including age verification, KYC, real-money escrow, and self-exclusion controls, and imposes responsible gaming requirements including time limits and spend caps. Penalties for unauthorised online gambling include up to three years imprisonment and INR 10 lakh fine. The Act has been challenged before the Madras High Court on constitutional grounds including state legislative competence under the Seventh Schedule and the right to free trade under Article 19(1)(g) of the Constitution. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 (amended for online gaming in April 2023) provide the parallel central government framework for online real-money games with Self-Regulatory Bodies (SRBs) under the Ministry of Electronics and Information Technology (MeitY).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "in-dpdp-act-2023-digital-personal-data-protection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "india-trai-ott-regulation-2024",
    "title": "India - Regulatory Status and Compliance Obligations for Over-the-Top (OTT) Communication Services (Telecommunications Act 2023, IT Rules 2021, CERT-In Directions, Equalisation Levy)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "As of 2026 India has no dedicated registration or licensing regime for Over-the-Top (OTT) communication services such as internet messaging and calling applications (for example WhatsApp, Signal and Telegram). The Telecom Regulatory Authority of India (TRAI) examined OTT regulation in its July 2023 Consultation Paper on a Regulatory Mechanism for Over-The-Top Communication Services and Selective Banning of OTT Services, but, consistent with its 2020 position, did not recommend an OTT-specific authorisation or registration framework, and its 2024 recommendations on the authorisation framework under the Telecommunications Act 2023 did not bring OTT communication services into the telecom authorisation regime. The Telecommunications Act 2023 (Act 44 of 2023) establishes an authorisation requirement for providing telecommunication services (Section 3), powers over standards (Section 19), public emergency and public safety measures (Section 20), national security measures (Section 21), protection of telecommunication networks and services (Section 22), protection of users (Chapter VII, Sections 28 to 30) and offences (Section 42); whether internet-based OTT communication services fall within the Act's definition of telecommunication service is unsettled and has not been extended to OTT by notification. OTT communication and content platforms are, however, subject as intermediaries to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, to the CERT-In Directions of 28 April 2022 (incident reporting within six hours and 180-day log retention), to the Digital Personal Data Protection Act 2023, and, for non-resident operators, to the Equalisation Levy under the Finance Act 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-telecom-act-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "india-transfer-pricing-section-92-income-tax-act",
    "title": "India Transfer Pricing - Section 92 of the Income Tax Act 1961 (Arm's Length Standard)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Sections 92 to 92F of the Income Tax Act 1961 (as inserted by the Finance Act 2001 and substantially amended since) establish India's transfer pricing framework for international transactions and specified domestic transactions between associated enterprises. The arm's length price must be determined using prescribed methods. A mandatory chartered accountant's report (Form 3CEB) must be filed if the aggregate of international transactions exceeds INR 1 crore. Three-tier documentation (master file, local file, country-by-country report) applies to MNEs with consolidated group revenue exceeding INR 500 crore. Failure to furnish documentation attracts penalties of 2% of the value of each international transaction under Section 271G.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "oecd_tp_guidelines_2022",
        "oecd_beps_action_13_cbcr",
        "india_advance_pricing_agreement",
        "india_safe_harbour_rules",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-transfer-pricing-guidelines-2022",
      "oecd-beps-action-13-country-by-country-reporting",
      "india-advance-pricing-agreement-rules-2012"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "india-university-grants-commission-act-1956",
    "title": "The University Grants Commission Act, 1956",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The University Grants Commission (UGC) Act, 1956 empowers the UGC to maintain standards of higher education in India, approve universities entitled to receive central funds, and regulate degree-awarding institutions under Section 22. It applies to all universities established or incorporated by or under a Central, State or Provincial Act, and institutions seeking recognition or funding.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-virtual-digital-assets-tax-income-tax-act-2022",
    "title": "Income Tax Act, 1961 - Section 115BBH: Taxation of Income from Transfer of Virtual Digital Assets, and Section 194S: TDS on Transactions in Virtual Digital Assets",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Indian tax law imposes a flat 30% tax on gains from transfers of Virtual Digital Assets (VDAs) under Section 115BBH of the Income Tax Act, with no set-off of losses against other income. Additionally, Section 194S mandates 1% Tax Deducted at Source (TDS) on VDA transfer transactions, applicable to all residents and specified persons facilitating such transfers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "bis-crypto-asset-prudential-standards"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "india-water-prevention-control-pollution-act-1974",
    "title": "India Water (Prevention and Control of Pollution) Act 1974 - CPCB Consent to Operate Framework",
    "domain": "Water & Environmental Resources",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The Water (Prevention and Control of Pollution) Act 1974 (Water Act) is India's foundational water pollution statute. The Central Pollution Control Board (CPCB) and State Pollution Control Boards (SPCBs) were established under the Act. Any industry or trade process discharging sewage or trade effluent into any stream, well, or sewer must obtain Consent to Establish (CTE) and Consent to Operate (CTO) from the relevant SPCB. The Act prohibits discharge of any poisonous, noxious, or polluting matter into water bodies in excess of prescribed standards. SPCBs may issue directions to prevent or reduce water pollution. Criminal penalties under the Water Act include imprisonment from 1.5 to 6 years and fines. The Act is administered alongside the Air (Prevention and Control of Pollution) Act 1981 and the Environment Protection Act 1986. In 2023, India updated its Environment Protection Act rules to bring compliance with new environmental norms. Pollution trade effluent standards are set in the Environment Protection Rules 1986 schedule.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "environment_protection_act",
        "air_act",
        "national_green_tribunal",
        "central_ground_water_authority",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "indonesia-consumer-protection-law-no-8-1999",
    "title": "Indonesia Consumer Protection Law No. 8/1999 - BPKN and BPSK Enforcement Framework",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Indonesia's Law No. 8 of 1999 on Consumer Protection (Undang-Undang Perlindungan Konsumen) establishes consumer rights, producer and distributor obligations, prohibitions on misleading advertising and defective products, and the National Consumer Protection Agency (BPKN - Badan Perlindungan Konsumen Nasional) and Consumer Dispute Settlement Agency (BPSK - Badan Penyelesaian Sengketa Konsumen) in every district/city; mandates product safety standards, warranty obligations, and requires Indonesian-language advertising for goods sold in Indonesia; enforced by the Ministry of Trade with fines up to IDR 2 billion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "philippines-consumer-act-ra-7394-1992"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "indonesia-immigration-law-6-2011-ditjen-imigrasi",
    "title": "Indonesia Immigration Law 6 of 2011 - Ditjen Imigrasi Visa and Stay Permit Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Law No. 6 of 2011 concerning Immigration (Undang-Undang Keimigrasian) is Indonesia's primary immigration statute, implemented by the Directorate General of Immigration (Ditjen Imigrasi) under the Ministry of Law and Human Rights (Kemenkumham). The law governs entry, exit, presence, and supervision of foreigners in Indonesia. Stay permits include: Visa on Arrival (Visa Kunjungan Saat Kedatangan), Visit Visa (Visa Kunjungan), Limited Stay Permit (KITAS - Kartu Izin Tinggal Terbatas), and Permanent Stay Permit (KITAP - Kartu Izin Tinggal Tetap). Indonesia launched an Electronic Visa on Arrival (e-VoA) in 2022 covering 95 countries for a 30-day extendable stay. A Second Home Visa launched in 2022 permits 5-10 year stays for property investors with minimum IDR 2 billion assets. Overstay penalties: IDR 1,000,000 per day, maximum IDR 30,000,000. Detention and deportation powers in Chapter X. Employers of foreign workers must comply with Ministry of Manpower regulations on work permit quotas.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "manpower_regulation",
        "investment_framework",
        "asean_framework",
        "data_protection",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "indonesia-mineral-coal-mining-law-3-2020",
    "title": "Indonesia Mineral and Coal Mining Law No. 3/2020",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The law mandates that mining operators obtain the appropriate IUP classification, meet domestic processing (down‑stream) requirements, fulfill divestment obligations, adhere to production quotas and royalty payments, and comply with environmental obligations..",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eiti-standard-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "indonesia-ojk-crypto-asset-regulation-2024",
    "title": "Financial Services Authority Regulation Number 3 of 2024 concerning the Implementation of Financial Sector Technology Innovation (POJK 3/2024)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-08-29",
    "bluf": "This regulation transfers supervisory authority over crypto-assets from Bappebti to Indonesia's Financial Services Authority (OJK), establishing a comprehensive framework for licensing, operating, and supervising crypto-asset exchanges and custodians. It mandates stringent requirements for governance, risk management, consumer protection, and anti-money laundering (AML) programs for all market participants, as detailed in Chapter III on Crypto Asset Trading.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "iso-37301-compliance-2021",
      "fsb-crypto-asset-regulatory-framework-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "indonesia-pdp-law-2022-personal-data",
    "title": "Law of the Republic of Indonesia Number 27 of 2022 concerning Personal Data Protection (UU PDP)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Indonesia's Personal Data Protection Law (UU PDP) requires data controllers and processors to obtain a valid lawful basis for processing personal data of Indonesian subjects, fulfill data subject rights, and implement robust security measures. The law has extraterritorial scope, applying to any entity processing data of Indonesian citizens, and mandates the appointment of a Data Protection Officer for certain processing activities (Article 53).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "id-pdp-law-2022",
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo",
      "apec-cbpr-system-2011"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "indonesia-permenkominfo-5-2020-private-electronic-systems",
    "title": "Regulation of the Minister of Communication and Informatics of the Republic of Indonesia Number 5 of 2020 concerning Private Electronic System Operators",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Private Electronic System Operators (PESOs) in Indonesia operating in strategic sectors must store personal data and transaction records within Indonesia. They must also comply with 24-hour content takedown orders, enable government data access upon request, implement security certification, and face sanctions for non-compliance under Article 20 and Article 26.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5g-cybersecurity-toolbox-2020",
      "cisa-zero-trust-maturity-model-2-0",
      "guide-computer-security-log-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "indonesia-shipping-law-17-2008-djplp",
    "title": "Indonesia Shipping Law No. 17/2008 - Cabotage Principle and DJPLP Port Authority Framework",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Indonesia's Law No. 17 of 2008 on Shipping (Undang-Undang Pelayaran) enforces the asas cabotase (cabotage principle) reserving domestic sea cargo transport exclusively for Indonesian-flagged vessels as of 1 January 2011; creates the Directorate General of Sea Transportation (DJPLP - Direktorat Jenderal Perhubungan Laut) and Indonesia Port Corporation (Pelindo) as port operators; requires vessel registration in the Indonesian Ship Register; mandates safety surveys by class societies recognised by the Ministry of Transportation; and reserves coastal fisheries and offshore support activities for domestic-flagged vessels under Presidential Regulation No. 44/2016.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-merchant-shipping-act-1958-dgshipping"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "informed-consent-digital-health-2026",
    "title": "Informed Consent in Digital Health & AI-Driven Care (2026 Standards)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Informed consent in digital health environments must be specific, granular, freely given, and easily revocable. It requires clear disclosure of AI involvement, data uses (including secondary and international transfers), risks of algorithmic bias, and limitations of digital tools. Dynamic and electronic consent mechanisms are expected, with audit trails and easy withdrawal processes. Special rules apply for vulnerable populations and high-risk AI applications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "interagency-guidance-third-party-risk-management",
    "title": "Third-Party Relationships: Interagency Guidance on Risk Management",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2023-06-06",
    "bluf": "The Office of the Comptroller of the Currency (OCC), the Board of Governors of the Federal Reserve System, and the Federal Deposit Insurance Corporation issued the \"Interagency Guidance on Third-Party Relationships: Risk Management.\" This guidance applies to all banks with third-party relationships, which collectively refers to national banks, federal savings associations, covered savings associations, and federal branches and agencies of foreign banking organizations. The guidance promotes consistency in the agencies’ supervisory approach and outlines the third-party risk management life cycle, identifying principles applicable to each stage.\n\nThe core obligation for banks is to develop and implement third-party risk management practices based on sound principles. These practices must be commensurate with the bank’s risk profile and complexity, as well as the criticality of the activity supported by the third party. The guidance clarifies that not all third-party relationships present the same level of risk or criticality, necessitating a risk-based approach. This bulletin, OCC Bulletin 2023-17, formally rescinds OCC Bulletin 2013-29, \"Third-Party Relationships: Risk Management Guidance,\" and OCC Bulletin 2020-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-sound-management-operational-risk",
      "bcbs-principles-operational-resilience",
      "eba-outsourcing-guide"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "international-medical-device-harmonization-2026",
    "title": "International Medical Device Regulatory Harmonization - IMDRF & Global Alignment (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Strategic framework detailing the guidelines and standards set forth by the International Medical Device Regulators Forum (IMDRF) to accelerate international medical device harmonization. Key initiatives include the Medical Device Single Audit Program (MDSAP) and globally standardized formats for pre-market submissions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "international-salvage-convention-1989",
    "title": "International Convention on Salvage 1989 - Maritime Salvage Law and Special Compensation",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The International Convention on Salvage 1989 (entered into force 14 July 1996) is the primary international treaty governing maritime salvage operations - the rescue of ships and their cargoes from peril at sea. It has 72 Contracting States including major maritime nations and covers all salvage operations except fixed platforms and fixed offshore drilling units (Art 3). The Convention establishes the 'no cure no pay' principle (Art 12) as the default salvage reward: salvors are only entitled to reward if the salvage operation was successful. Art 13 factors for assessing reward include: the salved value of the ship and cargo, the skill and effort of the salvors, the danger to life and environment, and the value of the property put at risk by the salvors. The Art 13 reward cannot exceed the salved value (Art 13(3)). Art 14 introduces special compensation for salvors who prevent or minimise environmental damage - where the Art 13 reward would be less than the salvor's expenses, Art 14 provides up to 30% of expenses (130% if genuinely preventive), and this can reach 100% of expenses. The Convention is implemented in Lloyd's Standard Form of Salvage Agreement (LOF 2020) - the industry-standard salvage contract. Art 23 sets a 2-year limitation period. The SCOPIC (Special Compensation P&I Club) clause, adopted 1999, supplements Art 14 with a more predictable special compensation mechanism preferred by P&I Clubs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "imo-solas-consolidated-2020",
      "imo-llmc-1976-protocol-1996-limitation-liability",
      "imo-nairobi-wreck-removal-convention-2007"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "intl-liability-convention-1972-claims-procedure",
    "title": "Liability Convention 1972 - Claims Procedure, Compensation Determination, and Claims Commission Framework for Space Object Damage",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Convention on International Liability for Damage Caused by Space Objects (1972) establishes the procedural framework for international claims arising from space object damage. It provides for absolute liability for surface damage (Article II), fault-based liability for space-to-space damage (Article III), joint and several liability for joint launches (Article V), and a diplomatic claims procedure. Claims must be presented through diplomatic channels within one year of the damage or identification of the responsible State. If settlement cannot be reached within one year of claim presentation, either party may request establishment of a Claims Commission whose decision is final and binding only if both parties agree in advance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "intl-outer-space-treaty-1967-article-7-liability-damage",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "intl-oecd-due-diligence-guidance-minerals-2016-five-step-framework",
    "title": "OECD Due Diligence Guidance for Responsible Supply Chains of Minerals 2016 - Five-Step Framework for Conflict-Free Mineral Sourcing from High-Risk Areas",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas (3rd edition, 2016) provides a non-binding but internationally recognised five-step framework for companies to identify and mitigate risks in mineral supply chains including conflict financing, human rights abuses, child labour, and bribery. The Guidance is expressly referenced by the EU Conflict Minerals Regulation 2017/821 and the EU Batteries Regulation 2023/1542 as the applicable due diligence framework. Supplements cover tin, tantalum, tungsten, and gold (3TG) and other minerals. The framework applies along the entire supply chain from mining through end-use manufacturing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-conflict-minerals-regulation-2017-821",
      "ilo-safety-health-mines-convention-c176-1995"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "intl-outer-space-treaty-1967-article-1-exploration-freedom",
    "title": "Outer Space Treaty 1967 Article 1 - Freedom of Exploration and Use of Outer Space for Benefit of All Countries",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 1 of the Outer Space Treaty (OST) establishes that the exploration and use of outer space shall be carried out for the benefit and in the interests of all countries, regardless of their degree of economic or scientific development. Outer space is declared free for exploration and use by all States without discrimination. Free access to all areas of celestial bodies is guaranteed. Freedom of scientific investigation in outer space is explicitly enshrined and States must facilitate international cooperation in such investigation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "intl-outer-space-treaty-1967-article-2-non-appropriation",
    "title": "Outer Space Treaty 1967 Article 2 - Non-Appropriation Principle: No National Claims to Sovereignty Over Celestial Bodies",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 2 of the OST prohibits national appropriation of outer space, including the moon and other celestial bodies, by claim of sovereignty, by means of use or occupation, or by any other means. This non-appropriation principle applies to all States and is one of the foundational norms of international space law. It does not prohibit use or exploration, but precludes sovereign territorial claims. The compatibility of commercial space resource extraction with Article 2 remains an active area of international legal debate addressed through domestic legislation and COPUOS deliberations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "copuos-lts-guidelines-2019-space-sustainability",
      "intl-outer-space-treaty-1967-article-1-exploration-freedom"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "intl-outer-space-treaty-1967-article-4-prohibition-weapons",
    "title": "Outer Space Treaty 1967 Article 4 - Prohibition of Weapons of Mass Destruction in Outer Space and Peaceful Use of Celestial Bodies",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 4 of the OST prohibits States from placing nuclear weapons or any other weapons of mass destruction in orbit around Earth, on celestial bodies, or stationing them in outer space in any other manner. The moon and other celestial bodies are reserved exclusively for peaceful purposes - no military bases, weapons testing, or military manoeuvres may be conducted on them. However, Article 4 does not prohibit the use of military personnel for scientific or peaceful purposes, or the use of military equipment for peaceful purposes. Conventional weapons in orbit are not expressly prohibited by Article 4, creating a legal gap addressed by multilateral diplomacy but not yet by treaty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "copuos-lts-guidelines-2019-space-sustainability",
      "intl-outer-space-treaty-1967-article-1-exploration-freedom"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "intl-outer-space-treaty-1967-article-7-liability-damage",
    "title": "Outer Space Treaty 1967 Article 7 - State Liability for Damage Caused by Space Objects on Earth or in Space",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 7 of the OST establishes that each State Party that launches, procures the launching of, or from whose territory or facility a space object is launched, is internationally liable for damage caused by that space object to another State Party or to its natural or juridical persons. This joint and several liability applies regardless of whether the damage occurs on Earth, in air space, or in outer space. The Liability Convention 1972 provides the detailed procedural framework for Article 7 claims, establishing absolute liability for surface damage and fault-based liability for space-to-space collisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "copuos-lts-guidelines-2019-space-sustainability",
      "un-outer-space-treaty-1967-article-vi-state-responsibility"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "intl-outer-space-treaty-1967-article-8-registration-jurisdiction",
    "title": "Outer Space Treaty 1967 Article 8 - State Registry and Jurisdiction Over Space Objects and Personnel",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 8 of the OST establishes that a State Party on whose registry a space object is carried retains jurisdiction and control over that object and any personnel on board, whether in outer space or on a celestial body. Ownership of a space object is not affected by its presence in outer space or on a celestial body, nor by return to Earth. The Registration Convention 1975 elaborates Article 8 by establishing mandatory national registries and the UN Register of Space Objects, requiring States to furnish the UN Secretary-General with registration information for all space objects they launch.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "copuos-lts-guidelines-2019-space-sustainability",
      "un-outer-space-treaty-1967-article-vi-state-responsibility"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "intl-outer-space-treaty-1967-article-9-contamination-prevention",
    "title": "Outer Space Treaty 1967 Article 9 - Harmful Contamination Prevention, Adverse Environmental Changes, and Consultation Obligation",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Article 9 of the OST requires States to conduct space exploration so as to avoid harmful contamination of outer space and celestial bodies, and adverse changes in Earth's environment from the introduction of extraterrestrial matter. States must adopt appropriate measures to prevent these harms and shall consult other States before proceeding with activities likely to cause harmful interference with their space activities. The consultation obligation is both a procedural requirement (request triggers consultation duty) and a substantive one (activities causing actual harmful interference are prohibited). COSPAR's Planetary Protection Policy implements Article 9's contamination obligations for scientific missions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "copuos-lts-guidelines-2019-space-sustainability",
      "intl-outer-space-treaty-1967-article-1-exploration-freedom"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "intl-registration-convention-1975-national-registry",
    "title": "Registration Convention 1975 - National Registry Requirements, UN Registration, and Space Object Identification",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Convention on Registration of Objects Launched into Outer Space (1975) operationalizes OST Article 8 by requiring States to maintain national registries of space objects and furnish registration information to the UN Secretary-General for entry in the UN Register of Objects Launched into Outer Space (UNOOSA Online Index). Each launching State must register space objects launched into Earth orbit or beyond by entering them in its national registry. Only one State may register each object (single registry principle). Registration establishes jurisdiction under OST Article 8. The Convention's registry requirements enable identification of space objects for accountability, liability attribution, and debris tracking purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "intl-outer-space-treaty-1967-article-8-registration-jurisdiction",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "inventory-eoq-deterministic",
    "title": "Agentic Economic Order Quantity",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The Economic Order Quantity (EOQ) model is a deterministic inventory optimization formula that calculates the optimal order quantity that minimizes total inventory cost (ordering cost + holding cost) for a single product with constant, known demand and instantaneous replenishment. The classical Wilson EOQ formula (EOQ = √(2DS/H)) was developed in 1913 and remains the baseline for inventory management in agentic commerce systems where autonomous agents make procurement decisions. For AI agents, EOQ provides a principled, auditable basis for order quantity decisions, replacing ad-hoc ordering with cost-optimal, mathematically justified quantities. Extensions for probabilistic demand (newsvendor model), quantity discounts, backorder allowance, and multi-echelon supply chains are implemented as modifications of the core formula. Incorrect EOQ implementation results in excess inventory costs (if order quantity is too large) or stockouts with associated lost sales penalties (if too small).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sarbannes-oxley-404",
      "supply-chain-bullwhip",
      "logistics-jit-inventory",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iopc-fund-1992-oil-pollution-compensation",
    "title": "IOPC FUND 1992 - International Oil Pollution Compensation Fund Convention and Supplementary Fund Protocol",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The International Convention on the Establishment of an International Fund for Compensation for Oil Pollution Damage, 1992 (Fund Convention 1992) establishes the International Oil Pollution Compensation Funds (IOPC Funds), which provide supplementary compensation for oil pollution damage from persistent oil spills from tankers where the shipowner's liability under the Civil Liability Convention 1992 (CLC 1992) is insufficient to cover the actual damage. The IOPC Funds are funded by contributions levied on entities that receive more than 150,000 tonnes of contributing oil (crude oil and heavy fuel oil) per year in Fund Member States. The 1992 Fund provides compensation up to approximately SDR 203 million per incident (combined CLC 1992 + Fund 1992 limit). The 2003 Supplementary Fund Protocol, in force since 3 March 2005, provides an additional third tier of compensation up to SDR 750 million per incident in Protocol Member States. The IOPC Funds are administered by the International Oil Pollution Compensation Funds Secretariat based in London.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "imo_clc_1992_civil_liability",
        "imo_marpol_annex_i_oil_pollution",
        "imo_solas_consolidated"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-clc-1992-civil-liability-oil-pollution",
      "imo-marpol-annex-i-oil-pollution",
      "imo-solas-consolidated-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iosco-ai-machine-learning-asset-management-2021",
    "title": "IOSCO AI and Machine Learning in Asset Management - Compliance Obligations for AI Governance in Fund Management, Algorithmic Portfolio Controls, and AI Risk Disclosure for Investment Managers",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations for AI governance in asset management under IOSCO guidelines, focusing on algorithmic portfolio controls, risk disclosure, and fund management oversight. It aligns with EU AI Act (Regulation 2024/1689) high-risk AI system requirements under Articles 9 and 15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iosco-aml-principles-securities-markets-2009",
    "title": "IOSCO Principles on Client Identification and Beneficial Ownership for the Securities Industry (May 2004) - Client Due Diligence Obligations for Authorized Securities Service Providers",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The IOSCO Principles on Client Identification and Beneficial Ownership for the Securities Industry (May 2004) set out the Client Due Diligence (CDD) process that Authorized Securities Service Providers (ASSPs, such as broker-dealers, collective investment schemes, futures firms and investment advisers) should apply. Principle 1 requires ASSPs to identify and verify each client's identity using reliable, independent source documents, data or information; Principle 1a requires specific CDD policies for omnibus accounts; Principle 2 requires obtaining sufficient information to identify persons who beneficially own or control securities accounts; Principle 3 requires obtaining client circumstances and investment objectives and conducting ongoing due diligence; Principle 4 requires keeping CDD records for at least five years after the business relationship ends; Principle 5 permits reliance on reliable third parties while the ASSP remains responsible; Principle 6 requires written policies for when CDD cannot be completed or illegal activity is suspected; Principles 7 and 8 address the regulator's powers to enforce CDD and to cooperate with other jurisdictions. The principles support investor protection and the prevention of the illegal use of the securities industry on a risk-sensitive basis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "iosco-bench-interest-rate",
    "title": "IOSCO Principles (Benchmarks)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The IOSCO Principles for Financial Benchmarks (2013) are the global standards for the governance, quality, and integrity of the benchmarks used in financial markets (e.g., LIBOR transition rates, indices). They are designed to prevent the manipulation of market benchmarks and ensure their transparency and reliable methodology.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-committee-financial-crisis-response",
      "principles-financial-market-infrastructures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iosco-defi-policy-recommendations-2023",
    "title": "IOSCO DeFi Policy Recommendations 2023 - Same Activity Same Risk Same Rules Principle, Responsible Persons Identification in Decentralised Protocols, AMM Governance Token Holder Liability, DEX Licensing Framework, Cross-Border DeFi Activity and IOSCO Crypto-Asset Roadmap",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the 'Same Activity Same Risk Same Rules' principle for DeFi protocols, requiring identification of responsible persons in decentralized systems and imposing liability on governance token holders for Automated Market Makers (AMMs). It applies to all DeFi platforms operating across IOSCO member jurisdictions that facilitate trading, lending, or asset management functions analogous to traditional financial services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bis-iosco-stablecoin-guidance-pfmi-2022",
      "crypto-aml-travel-rule"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iosco-esg-ratings-2021",
    "title": "Environmental, Social and Governance (ESG) Ratings and Data Products Providers Final Report",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This IOSCO report provides recommendations for regulators to enhance the reliability, comparability, and transparency of ESG ratings and data products, focusing on public disclosure of methodologies, management of conflicts of interest, and ensuring data quality as outlined in Recommendation 1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-sfdr-reporting",
      "tcfd-climate-related-financial-disclosures",
      "sasb-conceptual-framework"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ippc-1997-international-plant-protection",
    "title": "International Plant Protection Convention - IPPC 1997",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The IPPC (184 Contracting Parties as of April 2026, administered by FAO) establishes the global framework for phytosanitary measures protecting plant resources from pests and diseases, implementing WTO SPS Agreement Article 2 for plant health - businesses importing, exporting, or transiting plants, plant products, and regulated articles must obtain phytosanitary certificates (Article IV), comply with International Standards for Phytosanitary Measures (ISPMs including ISPM 15 for wood packaging material mandatory worldwide), and meet importing country phytosanitary requirements; ISPM 15 non-compliance (failure to mark wooden pallets, crates, and packaging with the IPPC mark) results in shipment detention, destruction, or fumigation at the importer's cost at every border crossing worldwide.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wto-sps-agreement-food-trade-disputes",
      "eu-csrd-2022-2464",
      "cites-convention-1973-endangered-species-trade",
      "un-guiding-principles-business-human-rights"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ippc-ispm-11-pest-risk-analysis-quarantine-pests",
    "title": "IPPC ISPM 11: Pest Risk Analysis for Quarantine Pests",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "IPPC ISPM 11 sets the methodology for Pest Risk Analysis (PRA) for quarantine pests, the scientific basis for any phytosanitary import measure under the WTO SPS Agreement. The standard prescribes a three-stage PRA process: Stage 1 Initiation (identifying the pest or pathway requiring analysis), Stage 2 Pest Risk Assessment (probability of introduction, establishment and spread, and economic, environmental and social consequences), Stage 3 Pest Risk Management (identification of phytosanitary measures proportionate to assessed risk). PRAs must be technically justified, transparent, and based on current scientific information. ISPM 11 is the only legitimate basis for an importing country to impose phytosanitary import measures more restrictive than international standards under WTO SPS the relevant article; absence or inadequacy of PRA exposes the measure to WTO challenge.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "wto_sps",
        "ispm_2",
        "ispm_21",
        "ispm_5",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ippc-ispm-5-glossary-phytosanitary-terms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ippc-ispm-15-wood-packaging-international-trade",
    "title": "IPPC ISPM 15: Regulation of Wood Packaging Material in International Trade",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "IPPC ISPM 15 prescribes the phytosanitary treatment and marking of wood packaging material (pallets, crates, dunnage, cable drums, spools) used in international trade to prevent the global spread of wood-borne quarantine pests such as Asian longhorn beetle, emerald ash borer, pinewood nematode, and bark beetles. The standard requires that wood packaging be debarked and treated by either heat treatment (HT: minimum 56°C core temperature for 30 continuous minutes), kiln drying with heat treatment (KD-HT), dielectric heating (DH), methyl bromide fumigation (MB: 48g/m³ at 21°C for 24 hours), or sulfuryl fluoride fumigation. Treated material must bear the ISPM 15 mark including IPPC logo, ISO country code, NPPO-assigned producer/treater code, and treatment code (HT, KD-HT, DH, MB, SF). Non-compliant wood packaging is refused entry, fumigated at port, or destroyed at importer expense.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "wto_sps",
        "ippc_treaty",
        "ispm_5",
        "ispm_7",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ippc-ispm-5-glossary-phytosanitary-terms",
      "ippc-ispm-7-phytosanitary-certification-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ippc-ispm-5-glossary-phytosanitary-terms",
    "title": "IPPC ISPM 5: Glossary of Phytosanitary Terms",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "IPPC ISPM 5 is the authoritative international glossary of phytosanitary terminology used in all other ISPMs and in national plant health regulations transposing the International Plant Protection Convention (IPPC). It defines core terms including \"pest\", \"quarantine pest\", \"regulated non-quarantine pest\", \"phytosanitary measure\", \"phytosanitary certificate\", \"consignment\", \"place of production\", \"pest risk analysis\", \"endangered area\", \"endangered host\", \"incursion\", \"establishment\", and \"freedom from pest\". The glossary is maintained by the Commission on Phytosanitary Measures (CPM) and revised annually. National Plant Protection Organizations (NPPOs) in all 184 IPPC contracting parties must use these definitions when issuing phytosanitary certificates, conducting pest risk analyses, and enforcing import/export plant health measures. Misuse of terms in phytosanitary documentation can trigger WTO SPS Committee challenge and refusal of consignment at border.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "wto_sps",
        "ippc_treaty",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "ippc-ispm-7-phytosanitary-certification-system",
    "title": "IPPC ISPM 7: Phytosanitary Certification System",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "IPPC ISPM 7 establishes the international framework for the issuance of phytosanitary certificates by exporting-country National Plant Protection Organizations (NPPOs). It defines NPPO responsibilities including legal authority, capacity to inspect, capacity to issue and rescind certificates, technical capability, and access to records. It mandates NPPOs to be the sole authority for certification, to inspect or supervise inspection of consignments, to issue certificates that conform to the IPPC model certificates, to keep records for minimum 1 year (recommended 3 years), and to participate in dispute resolution. NPPOs must also operate a system for re-certification of consignments and electronic phytosanitary certification (ePhyto). The standard is the operational foundation for cross-border plant trade and is referenced by every importing country requiring phytosanitary certificates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ippc_treaty",
        "ispm_5",
        "ispm_12",
        "wto_sps",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ippc-ispm-5-glossary-phytosanitary-terms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ipso-editor-code-practice-2023-advertising",
    "title": "UK IPSO Editor's Code of Practice 2023 - Press Standards: Accuracy and Corrections, Privacy Intrusion, Harassment, Discrimination, Confidential Sources, Reporting on Children, Financial Journalism Conflicts and Native Advertising Disclosure Standards",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation sets binding standards for print and digital news publishers under IPSO to ensure accuracy, protect privacy, prevent harassment, and uphold ethical reporting, particularly regarding children, victims of crime, and vulnerable individuals. Key obligations include prompt correction of inaccuracies (Clause 1), prohibition of non-consensual intrusion into private life (Clause 2), and strict rules on reporting involving children (Clause 6) and sexual assault victims (Clause 11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ama-ethical-marketing",
      "asa-advertising-codes-uk",
      "ftc-digital-advertising-disclosures",
      "coppa-marketing-kids",
      "eu-unfair-commercial-practices-2005-29"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iptc-photo-metadata",
    "title": "IPTC Photo Metadata",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Verification of IPTC photo metadata ensures digital assets comply with international intellectual property conventions and mitigate significant legal risks. This compliance framework mandates that specified metadata is embedded directly within the file itself. Key validation points include the mandatory presence of a creator field with a minimum length of three characters. A credit line field is also required and must explicitly contain the designated copyright entity. Rights management is enforced through several rules: a web statement of rights must exist as a valid, functional URL, the copyright status needs to be clearly defined, and comprehensive licensing terms must be accessible either through a direct link or via embedded data. For provenance and accountability, contact information for the rights holder is a required component, and the asset's creation date must adhere to the ISO 8601 standard for unambiguous temporal records. Satisfying these stringent data requirements establishes a machine-readable record of authorship and usage rights, thereby aligning with global digital media standards and protecting the enterprise from liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-copyright-treaty",
      "eu-copyright-directive-art-17",
      "exif-standard-metadata",
      "iso-16684-xmp-metadata"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iptc-video-metadata",
    "title": "IPTC Video Meta",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulatory compliance for video assets under this control requires stringent adherence to established IPTC metadata protocols and digital rights frameworks. Each asset is mandated to contain a complete hasIPTCVideoMetadataBlock. The integrity of this data must be cryptographically verifiable via a metadataDigitalSignaturePresent and its timeliness confirmed, falling within the metadataRecencyDaysMax threshold of 365 days. For rights management, isRightsDataEmbedded must be true, with an associated hasWebStatementOfRights pointing to a valid URI, a condition confirmed by the isWebStatementOfRightsURLValid check. Asset provenance demands both a hasVerifiedSourceOfAuthority and that the source itself be trusted, where isSourceOfAuthorityTrusted is true. Unambiguous attribution is enforced through a mandatory hasCreatorIdentifier. Furthermore, content-level description requirements, derived from media accountability standards, necessitate both a hasMandatoryPeopleInVideoField and hasMandatoryVideoRegionField. The system enforces a minPeopleIdentifiedCount of 1 to ensure principal subjects are identified for consent and privacy verification purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "c2pa-content-provenance",
      "eu-copyright-directive-art-17",
      "iso-16684-xmp-metadata",
      "isan-audiovisual-number",
      "wipo-copyright-treaty"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iq-aml-ctf-law-39-2015",
    "title": "Iraq Anti-Money Laundering and Counter-Terrorism Financing Law No. 39 of 2015",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-18",
    "bluf": "Iraq's Anti-Money Laundering and Counter-Terrorism Financing Law No. 39 of 2015 criminalises money laundering (Article 2) and requires financial institutions and DNFBPs to apply customer due diligence and identify beneficial owners (Article 10), maintain records for at least five years (Article 11), implement internal policies and controls (Article 12), and report suspected transactions to the AML/CFT Office without delay (Articles 9 and 13), with a dedicated compliance department under Article 14.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iq-esig-law-2012",
    "title": "Iraq Electronic Signatures and Electronic Transactions Law No. 78 of 2012 - Personal Data Provisions",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Iraq enacted the Electronic Signatures and Electronic Transactions Law No. 78 of 2012, which includes provisions for the protection of personal data processed in connection with electronic transactions and digital communications. The law is administered by the Ministry of Communications (MoC) of Iraq, which licenses Certification Service Providers and issues implementing instructions. It establishes obligations for electronic service providers to protect the confidentiality of personal data transmitted or stored in electronic transactions, restricts unauthorised access to personal data in information systems, requires security measures for the protection of data integrity and confidentiality, and provides for penalties for unauthorised disclosure or misuse of personal data. The law represents Iraq's foundational digital governance framework with personal data protection elements for the electronic transactions sector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/iq-esig-law-2012.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ir-aml-law-2008",
    "title": "Iran Anti-Money Laundering Law 2008",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "Iran's Anti-Money Laundering Law (2008) defines money laundering (Article 1) and the offence (Article 2), forms the Anti-Money Laundering High Council to collect, analyse and forward intelligence (Article 4), obliges listed legal entities and designated professions to comply with implementing by-laws (Articles 5 and 6), and requires those subjects to verify customer identity, report suspicious transactions, maintain records, and establish internal controls and training (Article 7), with penalties under Article 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ir-cca-2009",
    "title": "Iran Computer Crimes Act 2009 - Personal Data and Privacy Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Iran enacted the Computer Crimes Act 2009 (قانون جرایم رایانه‌ای), approved by the Islamic Consultative Assembly, which includes provisions protecting the privacy and confidentiality of personal data in information systems and electronic communications. The Act is administered by the Communications Regulatory Authority (CRA) of Iran. It criminalises unauthorised access to personal data held in computer systems, prohibits interception of data transmissions without authorisation, establishes liability for the disclosure of confidential data obtained from information systems, and mandates security measures for systems holding personal data. The Act provides the foundational legal framework for personal data protection in Iran's information systems and digital infrastructure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ir-cca-2009.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ireland-animal-health-welfare-act-2013",
    "title": "Ireland Animal Health and Welfare Act 2013 (No. 15): Welfare Duties, Cruelty Offences and Disease Control",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Animal Health and Welfare Act 2013 (No. 15 of 2013) is the principal Irish statute on animal health and welfare, administered by the Minister for Agriculture, Food and the Marine. The Act consolidates and modernises earlier legislation and imposes positive welfare duties as well as cruelty prohibitions. Its disease provisions provide for the prevention and control of animal disease, including powers to take measures against the spread of disease. Section 11 imposes a duty on a person having possession or control of an animal, or who is the owner or keeper of an animal, to ensure the welfare of the animal and not to neglect it. Section 12 prohibits cruelty, making it an offence to do, or fail to do, anything that causes unnecessary suffering to an animal, or to neglect or be reckless regarding the health and welfare of a protected animal. Section 16 restricts prohibited operations and procedures carried out on animals. The Act provides for the appointment of authorised officers with powers of inspection and enforcement, and section 52 sets out the penalties for offences, which on conviction may include fines and imprisonment depending on whether the offence is prosecuted summarily or on indictment. The Act is the modern foundation of animal welfare and animal disease control in Ireland.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "ireland-forestry-act-2014",
    "title": "Ireland Forestry Act 2014 (No. 31): Felling Licences, Replanting and Tree Preservation",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Forestry Act 2014 (No. 31 of 2014) is the principal modern Irish statute governing forestry and the felling of trees, administered by the Minister for Agriculture, Food and the Marine. Its long title states that it is an Act to make further and better provision in relation to forestry. Section 7 empowers the Minister to grant licences in respect of forestry activities, including the felling of trees, subject to conditions. Section 16 sets out the definitions for the felling provisions, and section 17 requires a person to apply for a licence under section 7 in order to fell trees, making it an offence to fell or to cause or permit the felling of a tree otherwise than under and in accordance with a licence or an exemption. Section 19 lists exempted trees and circumstances in which a felling licence is not required, and section 20 empowers the Minister to make tree preservation orders protecting trees. Section 26 empowers the Minister to make replanting orders requiring a person to replant and maintain trees following felling, and section 27 sets out the offences and penalties under the Act. The Act replaced the Forestry Act 1946 as the basis for sustainable forest management, felling control, and afforestation in Ireland.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "ireland-gambling-regulation-act-2024",
    "title": "Ireland Gambling Regulation Act 2024 - Gambling Regulatory Authority of Ireland",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "All operators offering gambling services to persons in Ireland must hold a licence from the Gambling Regulatory Authority of Ireland (GRAI). Social impact obligations, advertising restrictions, a national gambling exclusion register, and a mandatory 1% gambling levy apply. Unlicensed operators face criminal penalties and blocking orders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_aml",
        "eu_dsa",
        "gdpr",
        "advertising_standards",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-directive-5-gambling-sector",
      "eu-gdpr-online-gaming-data-protection",
      "eu-dsa-platform-obligations-gaming-2022",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ireland-immigration-act-2004-inis-irishimmigration",
    "title": "Ireland Immigration Act 2004 - ISD Employment Permit and Residency Stamp Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Ireland's Immigration Act 2004 (No. 1 of 2004), as supplemented by the Immigration Act 1999 and numerous statutory instruments, governs the entry, stay, and removal of non-EEA nationals. Immigration Service Delivery (ISD) under the Department of Justice replaced the Irish Naturalisation and Immigration Service (INIS). EU/EEA/Swiss nationals and their family members have free movement rights under SI 656 of 2006 (transposing EU Directive 2004/38/EC). Non-EEA nationals require immigration permission to remain in Ireland. The stamp-based system (Stamp 1 to Stamp 6) categorises the basis of permission to remain. Employment Permits (Critical Skills and General Employment Permit) are issued by DETE (Department of Enterprise, Trade and Employment) and validated by ISD. The Irish Residence Permit (IRP) card is the biometric residence document. Ireland operates a Common Travel Area (CTA) with the United Kingdom, allowing free movement between both islands without border controls. Removal Orders under s.3 of the 1999 Act and deportation orders may be issued for immigration violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_free_movement",
        "common_travel_area",
        "employment_permits_act",
        "refugee_protection",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ireland-water-services-act-2007",
    "title": "Ireland Water Services Act 2007 - Statutory Framework for Public Water and Wastewater Services, Polluter Pays and Drinking Water Standards",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Water Services Act 2007 (Number 30 of 2007, signed by President 14 May 2007 and commenced by Ministerial Orders) is the principal Irish statute governing the planning, management, and regulation of public and private water and wastewater services in Ireland. The Act consolidates and modernises prior water services legislation including the Water Supplies Act 1942 and Local Government (Sanitary Services) Acts. Originally the Act placed responsibilities on 34 local water services authorities (county and city councils), but these functions were transferred to Irish Water (Uisce Eireann) by the Water Services (No. 2) Act 2013, which became the single national water services provider. The Commission for Regulation of Utilities (CRU, formerly CER) is the economic regulator under Water Services (No. 2) Act 2013. The Environmental Protection Agency (EPA) regulates drinking water quality (Section 58), wastewater discharge authorisations under European Communities (Quality of Surface Waters Intended for the Abstraction of Drinking Water) Regulations and Urban Wastewater Treatment Regulations. Part 4 (Sections 53-72) addresses water services authority functions; Part 5 (73-99) water services strategic plans and capital works; Part 6 (100-128) water and sewerage charges; Sections 16, 22 polluter pays principle; Section 33 cost-recovery obligations transposing Water Framework Directive Article 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-water-framework-directive-2000-60-ec"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "irena-renewable-capacity-statistics-methodology-2024",
    "title": "IRENA Renewable Capacity Statistics 2024 - Measurement Methodology, Technology Classification and National Data Reporting Guidelines",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-03-01",
    "bluf": "This document establishes a standardized methodology for countries and data providers to report renewable energy capacity statistics to the International Renewable Energy Agency (IRENA). It mandates the use of 'net capacity' as the primary measurement unit (Section 2.1) and provides a detailed technology classification system (Annex 1) to ensure the collection of consistent, comparable, and transparent global data on renewable power generation assets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "irma-standard-responsible-mining-v1",
    "title": "IRMA Standard for Responsible Mining v1.0 - Independent Third-Party Assurance",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "The IRMA Standard for Responsible Mining v1.0 (2018), published by the Initiative for Responsible Mining Assurance, is a voluntary best-practice standard for industrial-scale mine sites assessed against more than 420 auditable requirements grouped under four principles: Business Integrity, Planning for Positive Legacies, Social Responsibility, and Environmental Responsibility. Mine sites undergo independent third-party audit covering legal compliance, human rights due diligence, free prior and informed consent, fair labour and terms of work, occupational health and safety, water management, waste and tailings management, biodiversity and protected areas, and reclamation and closure, with results reported transparently against the standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gri-14-mining-sector-standard-2022",
      "samrec-code-south-africa-mineral-reporting",
      "responsible-jewellery-council-standard-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "is-persouvernd-2018",
    "title": "Iceland Personal Data Protection Act 2018 (Lög nr. 90/2018) - EEA GDPR Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Iceland's Lög nr. 90/2018 um persónuvernd og vinnslu persónuupplýsinga (Personal Data Protection Act), adopted by the Althingi (Icelandic Parliament) on 13 June 2018 and in force from 15 July 2018, is Iceland's primary national legislation implementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Iceland. Iceland is not an EU member state but is a member of the European Economic Area (EEA); the GDPR was incorporated into the EEA Agreement and became directly applicable Icelandic law via EEA Joint Committee Decision No. 154/2018 of 6 July 2018, making Iceland subject to GDPR with the same legal effect as EU member states. The Lög nr. 90/2018 provides national derogations and additions permitted by the GDPR and repeals the prior Icelandic Personal Data Protection Act (Lög nr. 77/2000 um persónuvernd og meðferð persónuupplýsinga). Enforcement: Persónuvernd (Icelandic Data Protection Authority) is Iceland's independent data protection supervisory authority. Persónuvernd is not an EU EDPB member (as Iceland is not an EU member state) but participates in EDPB activities as an EEA observer and cooperates closely with EU supervisory authorities. Iceland is a highly developed, digitally connected North Atlantic jurisdiction with a population of approximately 380,000. Iceland's economy is dominated by fishing and fish processing, aluminium smelting, geothermal energy, and tourism - sectors that process significant personal data of employees, contractors, and operational personnel subject to GDPR. The fishing industry is particularly significant: Iceland is among the world's leading fishing nations per capita, and fishing quota management systems under the Fisheries Management Act (Lög um stjórn fiskveiða nr. 116/2006) process personal data of quota holders and vessel operators under GDPR. Key Icelandic national provisions: (1) Age of digital consent: Iceland has set the age of consent for information society services at 13 years - the minimum permitted under GDPR Art. 8 (which allows member states to set between 13 and 16); data subjects under 13 require parental or guardian consent; (2) Constitutional protection - the Icelandic Constitution (Stjórnarskrá lýðveldisins Íslands, No. 33/1944) § 71 protects the right to privacy of family life, home, and correspondence; these constitutional rights supplement GDPR data subject rights and are enforceable in Icelandic courts; (3) Freedom of expression - the Lög nr. 90/2018 contains exemptions for journalistic, academic, artistic, and literary processing aligned with GDPR Art. 85; Icelandic constitutional freedom of expression (Stjórnarskrá § 73) supplements these exemptions; (4) Freedom of information - the Upplýsingalög nr. 140/2012 (Information Act) governs public access to information held by Icelandic public authorities, creating a balance between transparency and GDPR privacy that must be managed by public sector controllers; (5) Employment - Icelandic labour law including the Trade Union and Dispute Settlement Act (Lög um stéttarfélög og vinnudeilur nr. 80/1938 as amended) and sector-specific maritime and fishing labour regulations govern employment data processing alongside GDPR; (6) Research and statistics - extended processing for scientific research, statistics, and archiving in the public interest is permitted with appropriate safeguards under the Lög nr. 90/2018. Fines: GDPR administrative fines apply in Iceland - up to EUR 20 million or 4% of global annual turnover, calculated in Icelandic krónur (ISK) at the applicable exchange rate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "isa-99-iec-62443-industrial-security-framework",
    "title": "ISA/IEC 62443 Industrial Automation and Control Systems Security Framework - Security Levels, Zones and Conduits, Risk Assessment and Lifecycle Requirements",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This standard establishes a comprehensive security framework for Industrial Automation and Control Systems (IACS), defining Security Levels (SL), Zone and Conduit models, risk assessment methodologies, and lifecycle management requirements. It applies to asset owners, integrators, and product suppliers involved in IACS deployment, with core requirements in ISA/IEC 62443-2-1 and -3-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-industrial-automation-security-standards",
      "iec-62443-iacs",
      "ot-ics-purdue-model-zone-based-security",
      "nist-sp-800-82-r3-ot-ics-security-guide-2023",
      "iso-iec-27019-energy-utility-information-security"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "isa-mining-code-exploitation-regulations-2024",
    "title": "International Seabed Authority (ISA) LTC Recommendations for the Guidance of Contractors under Exploration Contracts - Periodic Review, Environmental Baseline and Area Relinquishment",
    "domain": "Mining & Natural Resources",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "This regulation establishes the framework for contractors to prepare five-year periodic review reports, conduct environmental impact assessments, and report annual activities and expenditures for exploration of polymetallic sulphides and cobalt-rich ferromanganese crusts in the Area. It applies to all ISA contractors under exploration contracts, per ISBA/29/LTC/7 and ISBA/25/LTC/6/Rev.3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unclos-part-v-exclusive-economic-zone",
      "iso-14001-ems"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "isa-tr84-00-02-sis-functional-safety-guidance",
    "title": "ISA-TR84.00.02 - Guidance on Concepts Related to ISA 84: SIS Design, Testing, Maintenance and Management of Functional Safety",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This technical report provides non-mandatory guidance for implementing functional safety requirements in Safety Instrumented Systems (SIS) as defined in ISA-84.00.01, focusing on risk assessment, safety lifecycle management, and verification of safety integrity levels (SIL). It applies to engineers and operators in the process industries, particularly those managing SIS in oil and gas, chemical, and energy facilities, referencing ISA-84.00.01 Part 1, Clause 5.2.5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-industrial-automation-security-standards",
      "nist-sp-800-82-r3-ot-ics-security-guide-2023",
      "ot-ics-purdue-model-zone-based-security",
      "iso-iec-27019-energy-utility-information-security",
      "iec-62351-power-systems-cybersecurity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "isae-3000-revised-assurance-engagements",
    "title": "IAASB ISAE 3000 (Revised) - Assurance Engagements Other Than Audits of Historical Financial Information",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "ISAE 3000 (Revised) is the IAASB international standard for assurance engagements other than audits or reviews of historical financial information. It is the international basis on which SOC 2-type reports (and other non-financial assurance reports) are issued outside the United States, where US SSAE attestation standards do not apply. It covers both reasonable and limited assurance engagements and sets requirements for ethics, quality control, engagement acceptance, suitable criteria, evidence, and the assurance report.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "isae-3402-2011-service-organization-controls",
      "soc-2-type-ii-trust-services-criteria-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "isae-3402-2011-service-organization-controls",
    "title": "ISAE 3402:2011 - Assurance Reports on Controls at a Service Organization",
    "domain": "Workflow Automation",
    "version": "2011 (effective December 15, 2009)",
    "last_updated": "2026-05-09",
    "bluf": "ISAE 3402 (International Standard on Assurance Engagements No. 3402, IAASB 2009/effective 2011) governs assurance reports on controls at service organizations whose processing workflows form part of a user entity's internal control over financial reporting; it defines Type 1 reports (design suitability at a point in time) and Type 2 reports (operating effectiveness over a period), complementary user entity controls (CUECs), subservice organization coverage methods (carve-out vs. inclusive), and provides the international basis for SOC 1 reports under SSAE No. 18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-processing-integrity",
      "frb-sr-11-7-model-risk-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "isan-audiovisual-number",
    "title": "ISAN (Audiovisual)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with this node dictates that all qualifying `is_audiovisual_content` must be uniquely identified with a valid International Standard Audiovisual Number. As stipulated by governing international agreements, this requirement is absolute, meaning the `requires_isan_identifier` control is enforced without exception for applicable works. Adherence to the identifier's composition is also mandatory; conforming to established technical standards where the `isan_structure_is_mandatory`, the full identifier comprises a `isan_total_bit_length` of 96 bits. This structure universally necessitates that a `isan_root_segment_required` is present. Further, as detailed in relevant regulatory frameworks, an `episode_segment_required_for_series` and a `version_segment_required_for_variants` must be appended for serial productions and derivative works, respectively. Operationally, the asset's core `metadata_must_contain_isan`, ensuring the identifier is persistently associated with its descriptive data. In accordance with official protocols, each assigned number `is_registered_with_isan_ra` to ensure global uniqueness and resolution. A critical directive derived from industry best practices mandates that both the enterprise `rights_management_system_uses_isan` and its corresponding `archival_system_uses_isan` for consistent lifecycle management. It is important to note a key distinction clarified within the controlling specifications: the `distribution_watermark_uses_isan` control is inactive, signifying no obligation exists to embed the ISAN within a visual watermark for distribution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-copyright-treaty",
      "iptc-video-metadata",
      "iso-16684-xmp-metadata",
      "isrc-recording-code",
      "wipo-performances-phonograms"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "isber-best-practices-biorepositories-2018",
    "title": "ISBER Best Practices for Repositories: Collection, Storage, Retrieval, Release and Disposal of Biospecimens, 4th Edition (2018)",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This standard establishes comprehensive requirements for the ethical, safe, and scientifically valid management of human and non-human biospecimens throughout their lifecycle, including collection, processing, storage, retrieval, and disposal. It applies to biorepositories, research institutions, and clinical laboratories involved in biospecimen handling, with key guidance in Chapter 4 on informed consent and specimen tracking.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l3",
      "cmmi-capability-maturity-model-integration-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "isbn-book-standard",
    "title": "ISBN (Book Standard)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with the International Standard Book Number (ISBN) system mandates a multi-faceted validation process to ensure data integrity and interoperability across the global publishing supply chain. An identifier must adhere to strict structural requirements defined by authoritative standards, including a precise length of exactly 13 characters composed exclusively of numeric digits. International guidelines require the string to begin with a valid GS1 prefix, which must be either '978' or '979'. The final digit's validity is confirmed by a successful Modulo 10 checksum calculation using alternating weights of 1 and 3. Beyond structural syntax, governing standards stipulate that the registration group and registrant elements within the number must correspond to valid codes assigned by the official agency. Normative documents further obligate that each ISBN resolves to a unique bibliographic record in a recognized industry database and is not a duplicate assignment for any single publication manifestation. For commercial and legal viability, specified protocols demand the identifier have associated rights management information accessible via system lookup. Finally, regulatory frameworks mandate the ISBN must be active in global retail systems for verified sales reporting, confirming its operational readiness for commerce. Failure to meet any of these criteria constitutes a significant compliance deviation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-copyright-treaty"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "isds-investor-state-dispute",
    "title": "ISDS (Investor-State Dispute)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Investor-State Dispute Settlement (ISDS) is an international legal mechanism that allows foreign investors to bring claims against a host state for alleged violations of a bilateral investment treaty (BIT) or free trade agreement (FTA). It provides investors with a neutral forum (e.g., ICSID) to resolve disputes regarding expropriation or unfair treatment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-arbitration"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "isle-of-man-gambling-supervision-act-2010",
    "title": "Isle of Man Gambling Supervision Act 2010 - eGaming Licence Framework, Advertising Controls and Player Fund Protection",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Isle of Man Gambling Supervision Act 2010 establishes a licensing regime for eGaming operators, mandates strict advertising controls to prevent targeting minors, and requires segregation and protection of player funds. It applies to all remote gambling operators licensed by the Isle of Man Gambling Supervision Commission under Section 4(1) and Schedule 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l3",
      "iso-42005-ai-impact-assessment"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ism-code-vessel-safety",
    "title": "ISM Code (Vessel Safety)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The International Safety Management (ISM) Code provides an international standard for the safe management and operation of ships and for pollution prevention. It requires the 'Company' to establish a 'Safety Management System' (SMS) and mandates the 'Designated Person Ashore' (DPA) to provide a direct link between the ship and higher management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "imo-stcw-seafarer-training",
      "imo-marpol-pollution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ismp-medication-safety",
    "title": "ISMP Medication Safety",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The ISMP (Institute for Safe Medication Practices) Best Practices provide a set of consensus-based national standards for reducing medication errors in hospitals and healthcare settings. They focus on high-alert medications, 'Look-Alike/Sound-Alike' (LASA) drug nomenclature, and the implementation of error-reduction strategies across the medication-use process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-clinical-decision-support",
      "gxp-clinical-practice",
      "iso-14971-medical-risk",
      "hipaa-security-rule"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-10002-2018-customer-satisfaction-complaints",
    "title": "ISO 10002:2018 - Quality management - Customer satisfaction - Guidelines for the process of complaints handling in organizations",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 10002:2018 specifies requirements for a complaints-handling process within a quality management system, applicable to any organization regardless of size or sector. It mandates timely, fair, and transparent resolution of customer complaints in accordance with Clause 5.2 and subsequent implementation clauses.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "eu-omnibus-directive-2019-2161",
      "eu-adr-consumer-disputes-2013"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-10002-complaints-mgt",
    "title": "ISO 10002 (Complaints)",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with ISO 10002 mandates a structured, transparent, and customer-focused complaints-handling framework, grounded in established international standards. Foundational principles require an organization's complaints-handling policy to be publicly accessible, ensuring transparency for all stakeholders. Upon receipt, every grievance necessitates the mandatory assignment of a unique complaint identifier for systematic tracking. The process stipulates an initial acknowledgement must be dispatched to the complainant within a service-level agreement of 48 business hours. Organizational accountability is formally established by designating a specific complaint officer role vested with ultimate responsibility. To maintain impartiality, procedural guidelines dictate that the individual investigating a complaint should, where practicable, be segregated from its subject matter. A clearly documented escalation path must be available for complainants dissatisfied with an initial outcome. Furthermore, a core tenet of this framework is that verifiable staff training records exist and are maintained. Protecting sensitive data is paramount; therefore, all personally identifiable information collected requires robust protection consistent with prevailing privacy regulations. The organization must adhere to a resolution target SLA of 30 calendar days for closing complaints. For continuous improvement, a systematic complaint trend analysis must occur with a frequency not exceeding 90 days to identify root causes. Finally, governing statutes emphasize that the final resolution communication is mandatory and must always be conveyed to the complainant, ensuring complete process closure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-37301-compliance-mgt",
      "iso-31000-risk-mgt-std",
      "iso-10004-feedback-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-10003-2018-dispute-resolution-cx",
    "title": "ISO 10003:2018 - Quality management - Customer satisfaction - Guidelines for external dispute resolution for organizations",
    "domain": "Operations & CX",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "ISO 10003:2018 requires organizations to establish, implement and maintain a documented external dispute resolution process, including independent bodies, defined timeframes and monitoring, as set out in Clause 5 of the standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-10002-2018-customer-satisfaction-complaints",
      "iso-10003-2018-external-dispute-resolution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-10003-2018-external-dispute-resolution",
    "title": "ISO 10003:2018 - Quality management - Customer satisfaction - Guidelines for external dispute resolution for organizations",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 10003:2018 provides guidelines for organizations to establish, implement, and improve external dispute resolution (EDR) processes for resolving customer complaints impartially and efficiently. It applies to any organization seeking to enhance customer trust through structured, third-party dispute resolution mechanisms, particularly under Clause 6.1 on EDR process design and Clause 7.3 on impartiality of adjudicators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-adr-consumer-disputes-2013",
      "eu-consumer-rights-directive-2011",
      "eu-omnibus-directive-2019-2161"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-10004-feedback-mgt",
    "title": "ISO 10004 (Feedback)",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with ISO 10004 necessitates a structured and comprehensive framework for monitoring and utilizing customer feedback to enhance satisfaction. Organizational adherence requires a formally documented feedback process that incorporates clearly defined satisfaction indicators. This framework must employ both direct measurement methods, such as surveys, and indirect measurement methods, like market share analysis, to capture a holistic view of customer sentiment. A critical component involves analyzing the gap between customer expectations and their actual perceptions, a process mandated by authoritative guidelines. Derived insights must inform corrective and preventive actions, for which a system to track all improvement actions is mandatory. The entire feedback process itself must undergo periodic review to ensure ongoing effectiveness, with management review of feedback insights being a required governance step. According to core tenets for effective monitoring, analysis of collected feedback must occur at a minimum frequency of every 90 days. To facilitate collection, organizations must provide a minimum of four distinct and accessible customer feedback channels. Furthermore, data handling protocols are stringent, demanding at least an 80 percent feedback data anonymization level to protect privacy, consistent with established best practices. A clearly defined feedback retention policy is also required to govern the data lifecycle. These integrated controls ensure a systematic approach to managing customer feedback, driving continuous improvement and aligning with international standards for quality management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-10002-complaints-mgt",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-10008-b2c-ecommerce",
    "title": "ISO 10008 (B2C E-commerce)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "ISO 10008 establishes a comprehensive framework for business-to-consumer electronic commerce transactions, emphasizing consumer trust, transparency, and effective redress mechanisms. Foundational guidance stipulates that adherence requires organizations to publish a clear privacy policy and maintain unambiguous terms of service. For transactional integrity, the total cost must be fully displayed pre-payment, leaving no ambiguity for the consumer. Security protocols are paramount, mandating the use of strong encryption for transactions and strict adherence to PCI DSS compliance for all payment processing activities. A robust data breach notification policy must also be in place to govern incident response. To foster consumer confidence, enterprises must provide easily accessible contact information and a well-defined return policy. The standard places significant emphasis on post-transaction support systems. This necessitates a formal, defined complaint handling process, which requires that any customer grievance receives acknowledgement within a maximum 48-hour timeframe. Furthermore, organizations are obligated to offer a clear dispute resolution mechanism and implement a fair customer review moderation policy. Collectively, these controls create a reliable, secure, and fair online commercial environment, mitigating operational risks and aligning with international best practices for consumer protection in digital commerce.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ccpa-cpra",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-10668-brand-valuation",
    "title": "ISO 10668 (Brand Value)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Adherence to ISO 10668 for monetary brand valuation mandates a rigorous and auditable framework, ensuring transparency, consistency, and reliability in all assessments. This compliance node enforces these normative requirements through a series of procedural gates. Every valuation engagement must commence with the explicit definition of its purpose, a formal declaration of the basis of value, and the establishment of a fixed valuation date. A thorough legal rights analysis is compulsory to substantiate ownership and protections associated with the brand asset. Methodologically, the valuation approach must be specified, with the engagement employing a minimum of one recognized valuation technique. Data integrity is paramount across all methods: any income approach necessitates verified inputs, the market approach is contingent upon the availability of suitable comparables, and cost approach data must be formally audited. To satisfy the standard’s transparency principles, complete disclosure of financial projections is required, alongside a comprehensive exposition of all critical assumptions underpinning the analysis. The process must conclude with the generation of a final report, memorializing the valuation’s scope, methodology, and conclusion in a defensible, standard-compliant document.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-20671-brand-evaluation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-12207-2017-software-lifecycle-processes",
    "title": "ISO/IEC/IEEE 12207:2017 - Systems and software engineering - Software life cycle processes",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This standard defines a comprehensive set of software lifecycle processes for acquisition, supply, development, operation, maintenance, and supporting workflows. It applies to all organizations involved in software engineering, requiring implementation of process-specific outcomes defined in Clause 7 through Clause 11, with mandatory process implementation and control per Clause 6.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "automation-bpmn-service-task",
      "automation-bpmn-error-boundary",
      "automation-bpmn-agent-handover",
      "kcs-evolve-loop"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-12639-tiff-it",
    "title": "ISO 12639 (TIFF/IT)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with ISO 12639, governing the Tag Image File Format for Image Technology (TIFF/IT), mandates strict adherence to a specific set of structural and content-based rules for digital graphic arts data exchange. A file must present a valid profile declaration, which is restricted to Line Work (LW), High-resolution Continuous-tone (HC), or Binary Picture (BP) profiles. Each profile carries distinct technical prerequisites. For instance, LW files necessitate monochrome photometric interpretation and CCITT Group 4 compression. HC files, conversely, demand either CMYK or RGB colorspace and must use uncompressed or LZW compression schemes. BP profile validation hinges upon the presence of an Image File Directory pointer and valid linked image data. Universally, all conforming files must contain mandatory geometry tags, possess defined colorimetric data, and exhibit a compliant Image File Directory (IFD) structure. Furthermore, the standard imposes a hard ceiling on image fidelity, stipulating that resolution cannot exceed a maximum of 9600 DPI. These constraints ensure consistent and predictable file interchange within professional prepress workflows, and BIDDA's validation logic rigorously enforces every one of these requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-15930-pdf-x",
      "iso-16684-xmp-metadata",
      "exif-standard-metadata"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-13009-beach-mgmt",
    "title": "Beach Management (ISO 13009)",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with international beach operation standards necessitates a comprehensive framework for safety, environmental management, and service quality. ISO 13009:2015 requires a formalized beach management plan that integrates multiple operational facets. Water quality monitoring, a cornerstone of public health as outlined by World Health Organization guidelines and the European Union Bathing Water Directive, must occur at a minimum frequency, with the maximum water quality test interval set to 15 days. Safety protocols demand mandatory lifeguard coverage with a minimum density of two lifeguard towers per kilometer and a readily accessible first aid station to ensure a rapid response, capped at a maximum emergency response time of five minutes. Environmental stewardship, reflecting principles from ISO 14001:2015 and the Foundation for Environmental Education Blue Flag Programme, mandates daily cleaning operations and robust waste management infrastructure, including waste segregation bins placed no further apart than a maximum distance of 50 meters. Furthermore, operators must establish environmental protection zones to conserve sensitive coastal ecosystems. Inclusive access requires providing wheelchair accessibility to key facilities. Lastly, clear risk communication is obligatory through prominent hazard information signage detailing potential dangers to beach users, fulfilling a key recommendation for user safety and awareness across all cited standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-45001-health-safety",
      "iso-9001-quality-mgt",
      "iso-31000-risk-mgt",
      "gstc-tourism-criteria",
      "iso-21401-tourism-sustain"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-13485-2016-medical-devices-quality-management",
    "title": "ISO 13485:2016 Medical Devices - Quality Management Systems - Requirements for Regulatory Purposes",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 13485:2016 requires medical device manufacturers to establish a quality management system that meets regulatory requirements, as outlined in Clause 4.1, and to implement risk management processes, as specified in Clause 7.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "iso-13485-2016-medical-qms",
    "title": "ISO 13485:2016 Medical devices - Quality management systems - Requirements for regulatory purposes",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "ISO 13485:2016 specifies requirements for a quality management system (QMS) for organizations involved in the lifecycle of a medical device. It requires organizations to demonstrate their ability to provide medical devices and related services that consistently meet customer and applicable regulatory requirements, as mandated by Clause 4.1 for establishing and maintaining an effective QMS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14971-medical-risk",
      "iec-62304-medical-software",
      "fda-21-cfr-part-820-qsr",
      "eu-mdr-2017-745",
      "eu-ivdr-2017-746"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-13485-medical-qms",
    "title": "ISO 13485 (Medical QMS)",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "ISO 13485:2016 is the global standard for Medical Device Quality Management Systems (QMS). It specifies requirements for a QMS where an organization needs to demonstrate its ability to provide medical devices and related services that consistently meet customer and applicable regulatory requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14971-medical-risk",
      "iec-62304-medical-software"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-13485-qms",
    "title": "Medical Quality (ISO 13485)",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "ISO 13485:2016 is the internationally recognized Quality Management System standard specifically designed for organizations in the medical device industry, covering the full lifecycle of medical devices from design and development through manufacturing, installation, and servicing. Unlike ISO 9001 which focuses on customer satisfaction, ISO 13485 emphasizes regulatory compliance and patient safety, imposing mandatory requirements for design controls, supplier qualification, risk management (linked to ISO 14971), sterility assurance, and post-market surveillance. Certification to ISO 13485 is required for EU CE marking (MDR 2017/745 and IVDR 2017/746), accepted by Health Canada, TGA, and NMPA, and recognized by the FDA as evidence of quality system compliance. AI-based Software as a Medical Device (AIaMD) developers must implement ISO 13485 to demonstrate that their development process meets regulatory quality expectations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mdr-2017-745",
      "eu-ivdr-2017-746",
      "fda-21-cfr-part-820-qsr",
      "iso-14971-medical-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-13849-safety-related-control-systems-2015",
    "title": "Safety of Machinery - Safety-Related Parts of Control Systems - Part 1: General Principles for Design",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 13849-1:2015 specifies requirements for the design and integration of safety-related parts of control systems (SRP/CS) in machinery, ensuring predictable performance under fault conditions. It applies to all types of machinery and mandates the determination and validation of Performance Levels (PL) from a to e, as defined in Clause 6 and Annex B.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-industrial-automation-security-standards",
      "nist-sp-800-82-r3-ot-ics-security-guide-2023",
      "ot-ics-purdue-model-zone-based-security",
      "iso-iec-27019-energy-utility-information-security"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-14001-2015-environmental-management-industrial",
    "title": "ISO 14001:2015 - Environmental Management Systems - Requirements with Guidance for Use",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 14001:2015 requires industrial facilities to establish, implement, maintain, and continually improve an environmental management system (EMS) that identifies environmental aspects and impacts, ensures compliance with applicable legal obligations, and sets measurable objectives for improvement. Key requirements are defined in Clause 6.1.2 (Environmental Aspects), Clause 6.1.3 (Compliance Obligations), and Clause 10.2 (Nonconformity and Corrective Action).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-50001-energy",
      "iec-62443-iacs",
      "nist-sp-800-82-r3-ot-ics-security-guide-2023",
      "ot-ics-purdue-model-zone-based-security"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-14001-2015-environmental-management-systems-requirements",
    "title": "ISO 14001:2015 Environmental Management System - Requirements and Implementation Guidance",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2023-06-01",
    "bluf": "ISO 14001:2015 specifies requirements for an Environmental Management System (EMS) that enables organisations to enhance environmental performance through efficient use of resources, reduction of waste, and demonstration of responsible environmental management. The standard requires organisations to identify environmental aspects and impacts, comply with applicable legal and other requirements, set environmental objectives, and continually improve. Over 300,000 organisations in 171 countries hold ISO 14001 certification. The 2015 revision introduced life cycle perspective, strategic planning context, and leadership requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ets-directive-2003-87-emissions-trading-scheme"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-14001-2015-environmental-mining-operations",
    "title": "ISO 14001:2015 Environmental Management Systems - Requirements with guidance for use",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "ISO 14001:2015 requires organisations to establish, implement, maintain, and continually improve an environmental management system covering identification of environmental aspects (Clause 6.1.2), legal and other compliance obligations (Clause 6.1.3), operational planning and control (Clause 8.1), and performance evaluation (Clause 9); applies to mining operators seeking ISO 14001 certification as evidence of environmental due diligence to investors, regulators, and host communities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icmm-mining-principles-2020",
      "gri-14-mining-sector-standard-2022",
      "eiti-standard-2023",
      "gistm-global-tailings-management-standard-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-14001-ems",
    "title": "Env Management (ISO 14001)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "ISO 14001:2015 is the international standard for Environmental Management Systems (EMS), providing a framework for organizations to manage their environmental responsibilities systematically and contribute to the environmental pillar of sustainable development. The standard follows the Plan-Do-Check-Act (PDCA) cycle and requires organizations to identify their significant environmental aspects and impacts, establish environmental objectives and targets, implement operational controls, monitor performance against targets, and drive continual improvement. ISO 14001 is certified by accredited third-party certification bodies and is required by major customers in automotive, electronics, and manufacturing supply chains. For AI and data center operators, ISO 14001 applies to energy consumption (Scope 1 and 2 GHG emissions), water usage for cooling, e-waste management, and supply chain environmental impacts. Certification demonstrates to investors, regulators, and customers that environmental risks are systematically managed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-work-safety",
      "iso-31000-risk-mgt",
      "iso-50001-energy",
      "csrd-eu-sustainability",
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-14001-environmental-management-construction",
    "title": "ISO 14001:2015 Environmental Management Systems Applied in Construction - Environmental Aspects, Legal Compliance and Waste Management",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard requires construction organizations to establish, implement, and continually improve an Environmental Management System (EMS) by identifying and managing significant environmental aspects (Clause 6.1.2), maintaining compliance with legal and other obligations (Clause 6.1.3), and implementing operational controls for activities like waste management (Clause 8.1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "ifrs-s2-climate-related-disclosures",
      "iso-46001-water-eff"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-14046-2014-water-footprint-mining",
    "title": "ISO 14046:2014 Environmental Management - Water Footprint - Principles, Requirements and Guidelines",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This standard specifies principles, requirements and guidelines for conducting and reporting a water footprint assessment of products, processes, and organizations within the mining sector using life cycle assessment (LCA) methodology. It applies to all entities assessing water use and water-related impacts in mining operations under Clause 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cmmi-capability-maturity-model-integration-2-0",
      "icc-700-national-green-building-standard-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-14046-water-footprint",
    "title": "Water Footprint (ISO 14046)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "An assessment of the water footprint, conducted in alignment with the comprehensive principles of international environmental management standards, confirms substantial conformance. The analysis established a defined goal and scope, including a clearly delineated system boundary and a specific functional unit for consistent measurement. All evaluations are grounded within a specified geotemporal context, ensuring relevance and accuracy. The life cycle inventory analysis achieved a completeness level of 98.5 percent, providing a robust dataset for subsequent phases. Following a specified impact assessment methodology, the evaluation quantified potential environmental impacts across three distinct categories, such as water scarcity and degradation. A thorough data quality assessment was performed to validate inputs, and a sensitivity analysis was also conducted to test the stability of the results against key assumptions. A final report has been generated, documenting all phases, data, methods, and findings. However, it must be noted that a critical review remains incomplete at this stage. Consequently, the findings are not intended for, nor should they be used in, any public comparative assertion against competing products or services until such independent verification is finalized per established protocols.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-14064-ghg-emissions-verification",
    "title": "ISO 14064-3:2019 Greenhouse gases - Part 3: Specification with guidance for the verification and validation of greenhouse gas statements",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard specifies principles and requirements for verifying and validating greenhouse gas (GHG) statements for organizations and projects. It requires verifiers and validators to follow a systematic, independent, and documented process, as outlined in Clause 5, to assess GHG assertions against agreed-upon criteria, ensuring the credibility, consistency, and transparency of reported GHG information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-14064-ghg-quantify",
    "title": "GHG Verification (ISO 14064)",
    "domain": "Sustainability & ESG",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Successful completion provides reasonable assurance over an organization's greenhouse gas statement through a rigorous third-party verification process aligned with specifications from ISO 14064-3:2019. This is critical for meeting mandatory disclosure obligations under frameworks such as the EU's Corporate Sustainability Reporting Directive and the U.S. Securities and Exchange Commission's climate rule, which mandates attestation for Scope 1 and Scope 2 emissions. Foundational prerequisites, guided by ISO 14064-1:2018 and The Greenhouse Gas Protocol, demand that a complete GHG inventory is established with defined organizational boundaries and a formal base year. The inventory must include quantified Scope 1 emissions and Scope 2 emissions, with other indirect emissions being properly documented. Procedural maturity requires an active GHG information management system, a conducted uncertainty assessment, and a completed internal audit before engaging external verifiers. The verification body itself must be accredited under ISO 14065:2020, ensuring competency and impartiality. During its assessment of the final generated GHG report, this body applies a quantitative materiality threshold of five percent to identify material misstatements. To ensure a complete audit trail and support ongoing compliance, all relevant data must be maintained according to a minimum seven-year retention policy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting",
      "ghg-protocol-scope3",
      "csrd-eu-sustainability",
      "sec-climate-disclosure",
      "ifrs-s2-climate",
      "tcfd-climate-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-14064-ghg-reporting",
    "title": "ISO 14064 (GHG Reporting)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "ISO 14064-1 specifies principles and requirements for the design, development, management, and reporting of organization-level GHG inventories. It provides a common set of requirements for GHG quantification and reporting, ensuring consistency and credibility for carbon footprint claims.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ghg-protocol-scope3"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-14064-ghg-reporting-2018",
    "title": "ISO 14064-1:2018 Greenhouse gases - Part 1: Specification with guidance at the organization level for quantification and reporting of greenhouse gas emissions and removals",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "ISO 14064-1:2018 specifies principles and requirements for designing, developing, managing, and reporting organization-level greenhouse gas (GHG) inventories. It requires organizations to establish operational and organizational boundaries, quantify direct and indirect GHG emissions and removals, and prepare a GHG report in accordance with its principles of relevance, completeness, consistency, accuracy, and transparency (Clause 4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "175.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "ghg-protocol-scope3",
      "csrd-eu-sustainability",
      "issb-ifrs-s2-climate-2023",
      "tcfd-climate-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-14090-climate-adapt",
    "title": "Climate Adaptation (ISO 14090)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with the Climate Adaptation (ISO 14090) framework mandates a structured, iterative process beginning with pre-planning activities outlined in Section 5. This initial stage requires verified leadership commitment, where `leadership_commitment_verified` is true, and a minimum resource allocation of five percent (`resource_allocation_percentage_min`:5) for adaptation initiatives. Subsequently, Section 6 governs the assessment of climate change impacts, demanding a completed climate risk assessment (`climate_risk_assessment_completed`:true) where impact uncertainty has been quantified (`impact_uncertainty_quantified`:true). Organizational exposure is managed by ensuring any single vulnerability does not surpass a twenty-five percent maximum threshold (`vulnerability_threshold_max_percent`:25). Based on these assessments, Section 7 requires that a formal adaptation plan is established (`adaptation_plan_established`:true), which then moves into execution per Section 8, verified when `adaptation_actions_implemented` is true. Ongoing performance management under Section 9 is contingent upon defined climate indicators (`climate_indicators_defined`:true) and a mandatory monitoring evaluation frequency not exceeding twelve months (`monitoring_evaluation_frequency_months`:12). To maintain stakeholder transparency according to Section 10, a formal reporting cycle of twelve months (`reporting_cycle_months`:12) must be upheld, ensuring that `continuous_improvement_enforced` is true through this rigorous cycle of planning, implementation, evaluation, and communication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt",
      "iso-14001-ems",
      "tcfd-climate-risk",
      "ifrs-s2-climate",
      "csrd-eu-sustainability",
      "iso-22301-biz-continuity"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-14644-1-2015-cleanrooms-classification",
    "title": "ISO 14644-1:2015 Cleanrooms and Associated Controlled Environments - Part 1: Classification of Air Cleanliness by Particle Concentration",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires cleanroom operators to classify their air cleanliness by particle concentration, as specified in Clause 5, and applies to all cleanroom facilities in the pharmaceutical and life sciences industries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-14721-oais-archival",
    "title": "ISO 14721 (OAIS)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with the ISO 14721 reference model mandates the establishment of a comprehensive framework for long-term digital preservation and access. An organization must first fulfill the `requiresDesignatedCommunityDefinition` prerequisite, explicitly identifying the user base for whom information is being preserved. The entire archival lifecycle is governed by strict procedural controls, as outlined in several key information science texts. Ingest processes demand a `requiresSipToAipTransformation`, converting submission packages into robust archival information packages, where each `aipHasUniquePersistentIdentifier` is assigned for unambiguous tracking. To maintain integrity, `fixityChecksScheduled` must be performed regularly, and a complete `requiresAuditTrailOnAip` must log all modifications. Preservation Description Information is critical; `requiresPdiVerification` is mandatory and must achieve a `minimumPdiCompletenessScore` of four. The system's preservation strategy is proactive, where the `mandatesPreservationPlanningFunction` necessitates continuous `requiresTechnologyWatchMonitoring` to mitigate format obsolescence. Crucially, a `maxAcceptableInformationLossRatio` of zero establishes a no-tolerance standard for data corruption. For user access, a governed `requiresAipToDipTransformation` process prepares dissemination packages from the archival master, while a stringent `accessControlPolicyEnforced` policy protects information according to its classification. This holistic approach, grounded in established digital curation principles, ensures information remains independently understandable and available over extended periods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-16363-trusted-digital-repo"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-14971-medical-risk",
    "title": "ISO 14971 (Medical Risk)",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "ISO 14971:2019 is the international standard for the application of risk management to medical devices. It provides a framework for manufacturers to identify hazards, estimate and evaluate risks, control these risks, and monitor the effectiveness of these controls throughout the entire product lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-medical-qms",
      "eu-mdr-2017-745",
      "fda-21-cfr-part-820-qsr",
      "iec-62304-medical-software"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-15118-ev-charging-communication-v2g",
    "title": "ISO 15118 - Road Vehicles to Grid Communication Protocol: Plug-and-Charge Authentication, Smart Charging and Vehicle-to-Grid (V2G) Interface",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This standard defines the secure digital communication protocol between an Electric Vehicle (EV) and the Electric Vehicle Supply Equipment (EVSE), enabling advanced features like Plug & Charge (PnC) authentication, smart charging, and bidirectional energy transfer (Vehicle-to-Grid). As specified in ISO 15118-2, it mandates the use of a Public Key Infrastructure (PKI) for secure identification, authentication, and authorization, ensuring interoperability and grid stability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cybersecurity-act-enisa-certification-framework",
      "nist-sp-800-161r1-csrm-practices"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-15118-vehicle-grid-communication-v2g",
    "title": "ISO 15118 - Vehicle-to-Grid (V2G) Communication Interface: Part 2 - Network and Application Protocol Requirements, Part 3 - Physical and Data Link Layer Requirements, Part 4 - Physical Layer and Data Link Layer Conformance Test",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "ISO 15118 defines the communication protocol between electric vehicles (EVs) and charging stations for secure, interoperable vehicle-to-grid (V2G) services including Plug-and-Charge, contract certificate exchange, and charging session authorization. It applies to EV manufacturers, charging infrastructure providers, and energy service operators implementing V2G communication systems per Clause 6.3.2 and Clause 7.4.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-alternative-fuels-infrastructure-regulation-2023-1804",
      "eu-batteries-regulation-2023-1542-ev-batteries",
      "automotive-spice-pam-3-1",
      "etsi-its-cooperative-intelligent-transport",
      "autosar-adaptive-platform-ara-standard"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-15189-medical-labs",
    "title": "ISO 15189 (Medical Labs)",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "ISO 15189:2022 is the international standard for medical laboratories, specifying requirements for quality and competence. It addresses both the technical competence of the laboratory and its ability to deliver technically valid results, focusing on patient safety and the clinical utility of laboratory testing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14971-medical-risk",
      "iso-13485-medical-qms",
      "eu-ivdr-2017-746"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-15378-2017-pharmaceutical-packaging-gmp",
    "title": "ISO 15378:2017 Primary packaging materials for medicinal products - Particular requirements for the application of ISO 9001:2015, with reference to Good Manufacturing Practice (GMP)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard specifies Good Manufacturing Practice (GMP) requirements for the quality management system (QMS) of manufacturers of primary packaging materials for medicinal products. It integrates ISO 9001:2015 with GMP principles to mitigate risks to patient safety, focusing on contamination control, process validation, and batch traceability as detailed in Clauses 8.5.2 and 8.5.5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-15489-1-2016-records-management-workflow",
    "title": "ISO 15489-1:2016 - Information and documentation - Records management - Part 1: Concepts and principles",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 15489-1:2016 establishes requirements for the design and implementation of records management systems to ensure authenticity, reliability, integrity, and usability of records throughout their lifecycle. It applies to all types of organizations and mandates controls under Clause 8.1 for managing records in business processes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "automation-bpmn-service-task",
      "automation-bpmn-error-boundary",
      "automation-bpmn-agent-handover"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-15930-pdf-x",
    "title": "ISO 15930 (PDF/X)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "ISO 15930 establishes the compliance framework for graphic content exchange, ensuring predictable and reliable print reproduction. Conformance mandates that documents explicitly declare their status via a `PDFXVersionIdentifier` and must also include an `OutputIntent` describing the intended printing condition. A `TrappedKey` is required, indicating the file’s trapping state. For visual consistency, the `requiresAllFontsEmbedded` rule necessitates that all fonts be fully embedded within the file. Every page must define its final dimensions using either a `TrimBoxOrArtBox`. Furthermore, the standard enforces `requiresDeviceIndependentColor` spaces to prevent color shifts across different systems. To maintain a static and reliable state for printing, several features are explicitly forbidden. The `isEncryptionDisallowed` parameter prohibits any use of encryption. Active content, such as `JavaScript` or embedded `multimedia`, is prohibited. Interactive elements including `forms` and any `nonPrintAnnotations` are similarly restricted from the final document. Lastly, the `isTransferCurveDisallowed` setting forbids color alterations through a transfer curve, solidifying the document's colorimetric integrity for final output. Adherence to these strict parameters guarantees a file is a complete, self-contained digital master ready for print without further intervention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-16684-xmp-metadata"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-16363-trusted-digital-repo",
    "title": "ISO 16363 (Trust Repo)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Adherence to ISO 16363 certifies a digital repository’s trustworthiness across its organizational infrastructure, digital object management, and technology frameworks. The audited entity demonstrates comprehensive compliance, evidenced by a defined mission statement and an enacted succession plan, which are further reinforced by a strong financial sustainability score of 4. Rigorous digital object management is confirmed through a documented accession policy, the mandatory enforcement of a minimum metadata schema, and consistent validation for each submission information package. Object persistence is addressed via an overarching preservation plan, with data integrity checks executed at a stringent 90-day frequency. Security and operational resilience are underpinned by a defined access control policy, a recurring security risk assessment performed within a 12-month cycle, and an annually tested disaster recovery plan. The architecture’s robustness is solidified by maintaining a minimum of 2 geographically separate backups, safeguarding digital assets against catastrophic loss and ensuring sustained accessibility.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14721-oais-archival"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-16684-xmp-metadata",
    "title": "ISO 16684 (XMP)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "ISO 16684 establishes the framework for embedding extensible metadata within digital assets using the Extensible Metadata Platform (XMP) specification. Compliance mandates a strict structural and semantic adherence to ensure interoperability and data integrity across systems. The standard requires that all XMP metadata be enclosed within a valid packet wrapper, serialized specifically as RDF/XML, and universally encoded in UTF-8 for character set compatibility. A foundational rule dictates that the main rdf:Description element possesses an empty rdf:about attribute, designating the metadata as pertaining to the enclosing document. Furthermore, all namespace declarations must be valid to prevent ambiguity. For data representation, property values must strictly conform to their designated datatypes, and any embedded binary information is required to be encoded as Base64. When representing ordered lists, the standard obligates the use of rdf:Seq containers. Core content requirements stipulate the presence of a minimum of three critical properties to achieve baseline compliance: dc:creator for authorship, dc:rights for copyright information, and xmpMM:DocumentID for unique asset identification. This node rigorously validates these technical prerequisites to certify that digital files meet the comprehensive requirements for metadata interchange as defined by the governing international standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iptc-photo-metadata",
      "exif-standard-metadata"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-18295-1-2017-contact-centre-service-quality",
    "title": "ISO 18295-1:2017 Customer Contact Centre Requirements - Service Quality and Agent Management",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "ISO 18295-1:2017 specifies requirements for customer contact centres (CCCs) providing services on behalf of any organisation; mandates service performance metrics including First Contact Resolution (FCR), Average Speed of Answer (ASA), and abandonment rate; requires documented agent recruitment, training, and performance management; establishes caller experience standards including queuing disclosure and callback options; and is complemented by ISO 18295-2:2017 for client organisation requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-10002-2018-customer-satisfaction-complaints"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-18513-tourism-svc",
    "title": "Tourism Services (ISO 18513)",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with ISO 18513 for tourism services mandates a comprehensive framework for hotel operations centered on international standardization and guest welfare, as defined by established global best practices. This assessment verifies adherence to critical communication protocols, requiring the use of standard room terminology and uniform meal plan descriptions, plus confirms the implementation of ISO 7001 pictograms for universal understanding. Safety information is a primary focus, necessitating that emergency procedures be multilingual, displayed in both the local language and at least one major international language. Personnel competency is evaluated through the `reception_multilingual_support_level`, which must meet a minimum threshold of one international language spoken by staff. Operational requirements stipulate that a 24-hour reception or an equivalent emergency contact must always be available to guests. Furthermore, entities must provide clear information on electrical voltage within each room and ensure reservation confirmations are standardized. Hygiene and security are addressed through mandates for a documented cleaning protocol and a formalized guest complaint procedure. The `safe_deposit_box_availability` parameter must achieve a score of at least one, indicating that either centralized or in-room secure storage is provided, thereby prohibiting a complete absence of this facility.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-19011-audit-guidelines",
    "title": "Audit Guidelines (ISO 19011)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with this node ensures the establishment and management of a systematic audit programme guided by the core principles articulated in ISO 19011:2018. A foundational requirement is that an `audit_program_established` configuration is active, with objectives defined through a `risk_based_approach_applied` as mandated by Clause 4. Audit activities must be executed on a recurring cycle where `audit_frequency_months` is configured to 12. Pursuant to Clause 6 on conducting an audit, execution requires an `audit_plan_approved` prior to commencement. A fundamental tenet is the evidence-based approach, supported by the system’s `evidence_collection_automated` setting to ensure findings are verifiable. Auditor impartiality is paramount; therefore, `auditor_independence_verified` must be true, reflecting the principles of independence and integrity from Clause 4. The competence of audit personnel, as specified in Clause 7, must be formally confirmed with `auditor_competency_documented`. This structured process fulfills the internal audit mandates of management systems such as ISO/IEC 27001 Clause 9.2 and ISO 9001 Clause 9.2. Upon completion, `nonconformity_tracking_active` is mandatory, and any required remediation plan must be formulated within the `max_days_remediation_plan` threshold of 30. Final oversight is confirmed once `management_review_completed` is true, with all related documentation preserved confidentially according to the `audit_records_retention_years` policy of 3, thereby upholding principles of due professional care and fair presentation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-27001-2022",
      "iso-45001-work-safety",
      "iso-14001-ems",
      "iso-37301-compliance-mgt",
      "iia-internal-audit-ippf"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-19510-bpmn-standard-workflow-processes",
    "title": "ISO/IEC 19510:2013 - Information Technology: Business Process Model and Notation (BPMN)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This international standard specifies the notation, syntax, and semantics for Business Process Model and Notation (BPMN) to enable consistent modeling, automation, and interoperability of workflow processes across organizations. It applies to all entities using BPMN 2.0 for process modeling, particularly in regulated automation environments (Clause 5.1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "automation-bpmn-service-task",
      "automation-bpmn-error-boundary",
      "automation-bpmn-agent-handover"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-19650-bim-information-management",
    "title": "ISO 19650 Series - Organization and digitization of information about buildings and civil engineering works, including building information modelling (BIM) - Information management using building information modelling",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The ISO 19650 series establishes a framework for managing information over the whole life cycle of a built asset using Building Information Modelling (BIM). It requires appointing parties to define their information requirements and for appointed parties to respond with a BIM Execution Plan (BEP) and manage information within a Common Data Environment (CDE), as detailed in ISO 19650-2, Clause 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pmbok-7-guide-pm",
      "iso-27017-cloud-defence"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-19650-bim-information-management-construction",
    "title": "ISO 19650-1:2018 Information management using building information modelling (BIM) - Part 1: Concepts and principles",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 19650 requires construction projects to implement a Common Data Environment (CDE) as outlined in Clause 5.1, and to establish an information management process in accordance with Clause 6.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-20000-1-2018-it-service-management",
    "title": "ISO/IEC 20000-1:2018 - Information technology - Service management - Part 1: Service management system requirements",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO/IEC 20000-1:2018 specifies requirements for an organization to establish, implement, maintain, and continually improve a service management system (SMS) to deliver managed services that meet agreed service requirements. It applies to any organization providing IT services, requiring compliance with Clause 4 through Clause 10, including service delivery, incident, problem, and availability management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-9001-quality-mgt",
      "iso-22301-bcm-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-20000-service-mgt",
    "title": "ISO 20000-1 (Service Mgt)",
    "domain": "Cloud & SaaS",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with ISO 20000-1 mandates the establishment and operation of a comprehensive Service Management System (SMS) to plan, design, transition, deliver, and improve services. Foundational requirements stipulate that an organization must formalize its commitment through a documented service management policy and clearly delineate the SMS scope. Governance is further solidified by ensuring all roles and responsibilities are explicitly defined. Core operational processes must be implemented, including a robust incident management process for restoring normal service operation, a structured change enablement process to manage modifications, and a formal supplier management process for overseeing third-party contributions. The framework necessitates the creation and maintenance of key artifacts such as a defined service catalog, active Service Level Agreements (SLAs), and an accurate Configuration Management Database (CMDB) to track service components. To ensure ongoing effectiveness and alignment with strategic objectives, the standard imposes strict oversight cycles. Management reviews must be conducted at a minimum frequency of every twelve months, and a complete internal audit cycle must also conclude within a twelve-month period. Continuous enhancement is a central tenet, evidenced by the requirement that a continual improvement register is actively maintained. Adherence to these integrated processes and governance structures is essential for certification and demonstrating mature service delivery capabilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-20022-financial-messaging-workflow-standard",
    "title": "ISO 20022 - Universal Financial Industry Message Scheme: XML-Based Messaging Standard for Payments, Securities, Trade Finance and Compliance Workflows",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 20022 defines a standardized, XML-based message format for financial transactions across payments, securities, trade finance, and regulatory reporting. It applies to financial institutions, market infrastructures, and service providers globally that exchange structured financial data, requiring adherence to its Message Definitions (MT and MX formats) and Business Application Areas (BAAs) as specified in Clause 8 of the ISO 20022 standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "automation-bpmn-service-task",
      "automation-bpmn-error-boundary",
      "automation-bpmn-agent-handover",
      "iso-31000-risk-mgt-std",
      "mcp-enterprise-auth"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-20022-messaging",
    "title": "ISO 20022 Messaging",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "ISO 20022 is the global standard for financial messaging, providing a methodology and XML/JSON-based message catalog for financial communication between financial institutions, central banks, payment infrastructures, and increasingly, AI agents executing financial transactions. The standard is being adopted globally as the replacement for legacy formats (SWIFT MT, FedWire, CHIPS) - SWIFT completed its ISO 20022 coexistence period in November 2023, with full migration mandated by November 2025. ISO 20022 messages carry richer structured data than legacy formats (full originator/beneficiary details, purpose codes, regulatory identifiers), enabling better straight-through processing, AML screening, and sanctions compliance. AI agents generating or processing payments must produce ISO 20022-compliant messages to interface with modern payment infrastructure, or face message rejection and transaction failure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-20022-mx-messaging",
    "title": "ISO 20022 MX Messaging",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "ISO 20022 is the universal standard for financial industry messaging. It provides a platform-independent model for financial business processes and is the standard for modern high-value payment systems (HVPS) and cross-border payments, replacing the legacy MT messaging with richer XML-based MX messages to enhance transparent data and compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "chaps-rtgs-high-val-london"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-20077-extended-vehicle-standard-exve",
    "title": "ISO 20077 - Extended Vehicle (ExVE) Standard: In-Vehicle Data Server Architecture, OEM Backend Connectivity, Remote Diagnostics, Data Governance and Third-Party Access Control",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "ISO 20077 standardizes the 'Extended Vehicle' methodology, channeling all vehicle data through an OEM-controlled backend server to ensure safety, cybersecurity, and standardized data access for third parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-20245-remanufactured",
    "title": "Remanufactured Goods (ISO 20245)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with remanufacturing standards necessitates a comprehensive, documented process and verifiable end-product quality. The core operational requirement mandates that a product undergoes full disassembly into its individual components. Following this teardown, process documentation must confirm all parts have been thoroughly cleaned and subjected to rigorous inspection against established specifications. Any components failing to meet these criteria are required to be replaced or properly reconditioned. The resulting final product has to pass testing which confirms it meets or exceeds original equipment manufacturer (OEM) performance specifications. For applicable items, safety-critical components must undergo specific verification and validation protocols. Transparency with the end-user is paramount; therefore, the remanufacturer’s identity and contact information must be clearly stated. The product or its packaging needs to be explicitly and permanently marked as 'remanufactured' using a label that is durable enough for the product's expected life and is easily visible. Furthermore, consumer protection standards require that the provided warranty be equivalent to or better than one for the original new product, with the specific `minimumWarrantyPeriodMonths` value serving as a key verification metric against the new equivalent's terms. The existence of comprehensive `remanufacturingProcessDocumentation` is essential for substantiating adherence to every procedural step.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "reverse-logistics-circular"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-20252-market-research",
    "title": "ISO 20252 (Market Research)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Conformance with the international standard for market, opinion, and social research necessitates a verifiable, quality-managed framework governing the entire research lifecycle from inception through archival. Effective compliance requires establishing a formal `hasDocumentedProposalProcess` where every proposal explicitly details its approach, as mandated by the `proposalIncludesMethodology` control. Execution of fieldwork is contingent upon both a formal `hasDataCollectorTrainingProgram` for personnel and a clearly defined `consentManagementProcessDefined` for all respondents. Data integrity must be ensured through systematic `dataValidationProceduresInPlace` and strict adherence to a `hasDocumentedDataProcessingSpec` for subsequent handling. Critical data protection measures stipulate a defined `dataAnonymizationLevel` for respondent information and a maximum `dataRetentionPolicyDays` limit for any personally identifiable information retained post-project. Furthermore, organizations must ensure `subcontractorComplianceVerified` for any third-party involvement to maintain the chain of compliance. The final deliverables are equally regulated; each `reportIncludesMethodologyDisclosure` and must ensure the analysis `reportDistinguishesFindingsFromInterpretation` with absolute clarity. To complete the cycle, all essential `projectRecordsArchived` according to a defined procedure, ensuring end-to-end traceability and accountability consistent with core regulatory principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-20252-opinion-research",
    "title": "ISO 20252 (Opinion)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "An assessment of the current state reveals profound non-conformance with core tenets of the ISO 20252 standard for market, opinion, and social research. The research process exhibits systemic deficiencies across multiple critical domains, undermining its validity and reliability. Methodological rigor is absent, as evidenced by the lack of a defined sampling methodology and a documented sampling frame. Transparency requirements are unmet due to the failure to disclose data collection dates, any weighting methodology, or make the questionnaire available for inspection. Key performance metrics remain unreported; specifically, the response rate is not calculated, which contravenes the established minimum_response_rate_threshold of 0.05. Furthermore, neither the margin of error nor an effective sample size has been reported. Data integrity and respondent protection are compromised through the absence of a formal data quality check process and an established anonymization protocol. Operational oversight also fails to extend to third parties, as subcontractor compliance has not been verified. These cumulative failures indicate the research outputs cannot be considered credible or compliant with internationally recognized standards for opinion polling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-20252-market-research",
      "gdpr-art-21-marketing-optout"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-20400-sustainable-proc",
    "title": "Sustainable Procure (ISO 20400)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Organizational adherence to ISO 20400 guidance, as informed by authoritative frameworks, requires a comprehensive and verifiable sustainable procurement system. Compliance is predicated on establishing a formal sustainable procurement policy, ensuring it is actively communicated to all suppliers, and assigning designated accountability for its implementation. Internal capability must be demonstrated through metrics tracking the procurement team training percentage on sustainability principles. A documented supply chain risk assessment process is mandatory for identifying and mitigating environmental, social, and economic threats. This due diligence must also address contemporary digital risks by ensuring supplier assessments include cybersecurity and data privacy controls. Operationally, sustainability criteria must be integrated into supplier pre-qualification, and a significant percentage of RFPs must contain specific sustainability clauses. Financial evaluations for high-value procurements must employ life-cycle costing methodologies to capture total ownership expense. Post-award, a system for supplier performance monitoring against sustainability KPIs is required, and contracts for relevant goods must include clauses for responsible e-waste disposal, thereby ensuring end-to-end alignment with global best practices and regulatory expectations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp",
      "iso-14001-ems",
      "ghg-protocol-scope3",
      "csrd-eu-sustainability",
      "oecd-mineral-supply"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-20400-sustainable-procure",
    "title": "ISO 20400 (Sustainable Procure)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Adherence to the ISO 20400 (Sustainable Procure) node requires an organization to integrate sustainability principles throughout its procurement lifecycle, substantiated by verifiable controls and performance metrics. The framework mandates establishing a formal, management-approved sustainable procurement policy and a corresponding Supplier Code of Conduct articulating environmental, social, and governance expectations. Procedurally, sustainability criteria must be embedded within Request for Proposal (RFP) and contract templates. A critical performance metric involves conducting sustainability or social responsibility assessments for at least 85% of strategic tier-1 suppliers within the preceding 24 months. Furthermore, procurement processes must mandate a Life Cycle Cost (LCC) analysis for significant capital expenditures. Human capital is addressed by requiring documented training on the policy and ISO 20400 principles for a minimum of 90% of the procurement team. Risk management protocols must include supply chain risk mapping to identify high-risk categories concerning issues like forced labor or deforestation. Operational controls necessitate a system for monitoring key supplier performance against defined sustainability KPIs and providing an accessible grievance mechanism for supply chain workers. Finally, governance requires that sustainable procurement objectives and overall performance are formally reviewed by senior management at least annually to ensure continuous improvement and alignment with strategic goals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp-mgt",
      "ilo-core-conventions",
      "iso-31000-risk-mgt-std",
      "iso-37301-compliance-mgt",
      "sa8000-social-account",
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-20671-brand-evaluation",
    "title": "ISO 20671 (Brand)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Adherence to the ISO 20671 standard requires a comprehensive framework for brand evaluation, encompassing legal, financial, market, and stakeholder dimensions. This module verifies the robustness of an organization's brand governance by examining critical data points. The assessment confirms legal protections by validating isTrademarkRegistered status and the trademarkGeographicCoverageRatio. A crucial control involves affirming that the organization hasTrademarkMonitoringProcess to safeguard against infringement. Market performance is quantified through objective metrics, including the brandAwarenessScore, the netPromoterScore reflecting customer loyalty, and the entity’s overall marketSharePercentage. Financially, the node mandates scrutiny of valuation practices, confirming that isBrandValuationConductedAnnually and that isBrandValueInFinancials has been properly reported. The brandRevenueAttributionRatio further links brand equity directly to economic performance. Stakeholder management effectiveness is gauged by confirming the organization hasStakeholderMap, adheres to a defined stakeholderSurveyFrequencyMonths for systematic feedback, and measures the internal employeeBrandAdvocacyScore. Any deficiency in these areas indicates a material deviation from the standard's principles for sustainable brand management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-10668-brand-valuation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-21001-2018-educational-organizations-management",
    "title": "ISO 21001:2018 - Educational Organizations Management Systems: Requirements and Guidance for Using EOMS to Enhance Learner Experience",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 21001:2018 specifies requirements for an Educational Organization Management System (EOMS) to support competence development and enhance learner satisfaction through effective processes and stakeholder engagement. It applies to any organization providing curricular-based, post-secondary educational products and services, per Clause 4.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021",
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-21001-educational-organisations-2018",
    "title": "ISO 21001:2018 Management Systems for Educational Organisations - Requirements with guidance for use",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "ISO 21001:2018 specifies requirements for a Management System for Educational Organizations (EOMS) to enhance learner satisfaction and other beneficiaries. It requires organizations to demonstrate their ability to consistently provide, support, and facilitate the acquisition of knowledge, skills, and attitudes through teaching, learning, or research, as outlined in Clause 4.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-21101-adventure-tour",
    "title": "Adventure Tourism (ISO 21101)",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Adventure tourism providers must establish and maintain a comprehensive safety management system, confirming `safety_management_system_active` is true to align with ISO 21101. Top management holds accountability for creating and disseminating a core safety policy, as stipulated by Clause 5.2. A critical operational component involves the systematic, ongoing process for hazard identification and risk assessment mandated under Clause 6.1.2, which requires execution at an interval not to exceed 12 months. Conformance also hinges on personnel; Clause 7.2 necessitates that providers determine and verify necessary competence for all persons affecting safety performance, where `staff_competency_verified` must be affirmed. Documented information requires strict controls per Clause 7.5, encompassing logged equipment maintenance records and a participant waiver retention period of 7 years. Intersecting with this, the processing of special categories of personal data like health information, regulated by GDPR Article 9, demands that `participant_medical_data_encrypted` is perpetually enabled. Clause 8.2 governs emergency preparedness, compelling organizations to test response plans annually and maintain a `secure_communications_channel_active` for reliable crisis communication. Any safety incidents necessitate immediate action, with reporting required within a maximum of 24 hours. This compliance framework extends to supply chains, obligating verification of contractor safety protocols. The system's integrity is validated through internal audits conducted at least every 12 months.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt",
      "iso-45001-work-safety",
      "iso-9001-quality-mgt",
      "iso-22301-biz-continuity",
      "iso-21401-tourism-sustain",
      "gstc-tourism-criteria"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-21401-tourism-sustain",
    "title": "Sustainable Tourism (ISO 21401)",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the Sustainable Tourism standard necessitates the establishment and maintenance of a comprehensive sustainability management system (SMS). An organization must demonstrate a formal sustainability policy, documented and endorsed by top management, that has been effectively communicated throughout the enterprise. A clearly defined sustainability scope is also mandatory, outlining the system's precise boundaries. Critical stakeholder engagement requires a documented analysis of interested parties along with their relevant requirements. Performance improvement depends on setting specific, measurable, achievable, relevant, and time-bound objectives. Operational controls must include systematic monitoring procedures for key environmental indicators; organizations must track total energy consumption in kWh, total water consumption in cubic meters (m³), and total waste generation in kilograms (kg). A key performance metric to be calculated annually is the wasteDiversionRatePercentage, which quantifies refuse diverted from landfills. To ensure system efficacy, a documented employee training program covering sustainability roles is essential. Continual improvement is verified through periodic assessments, including a full internal audit plus a formal management review, both conducted within the last 12 months. A documented corrective action process for identifying nonconformities and implementing remedies is required to maintain system integrity and achieve ongoing sustainability goals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gstc-tourism-criteria",
      "iso-31000-risk-mgt",
      "iso-45001-health-safety",
      "sbti-carbon-target",
      "green-key-tourism-eco",
      "fair-trade-tourism"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-21434-automotive-cybersecurity-engineering-2021",
    "title": "ISO/SAE 21434:2021 - Road Vehicles - Cybersecurity Engineering",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO/SAE 21434:2021 establishes engineering requirements for managing cybersecurity risk in road vehicles throughout the vehicle lifecycle. It applies to manufacturers, suppliers, and developers involved in the design, production, operation, and maintenance of automotive systems, requiring implementation of a Cybersecurity Management System (CSMS) and execution of Threat Analysis and Risk Assessment (TARA) per Clause 15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021",
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-21448-sotif-2022",
    "title": "ISO 21448:2022 Road vehicles - Safety of the intended functionality",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard provides a framework for ensuring the Safety of the Intended Functionality (SOTIF) in automated driving systems (SAE Levels 2-5), requiring manufacturers to identify, evaluate, and mitigate risks arising from performance limitations or reasonably foreseeable misuse, as outlined in the overall SOTIF process in Clause 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-23894-ai-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-21500-project-gov",
    "title": "ISO 21500 (Project Gov)",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "ISO 21500 (Project Gov) evaluates an organization's adherence to international standards for project, programme, and portfolio governance. Compliance mandates the establishment of a formal framework; validation through `isFrameworkAlignedWithISO21500` confirms if concepts are explicitly referenced in the `hasDocumentedGovernanceFramework` documentation. A critical control, `hasDefinedOrganizationalContext`, verifies a documented context outlines how projects support strategic business objectives. This node further stipulates the existence of a `hasCentralProjectPortfolioRegister`, ensuring all initiatives are centrally tracked. A key verification, `areProjectsLinkedToStrategicObjectives`, confirms each project within this register maps to a specific strategic goal. The governance structure's integrity is assessed by checking if `hasDefinedGovernanceRoles`, like Sponsor and PMO, are formally defined with their responsibilities. Operational discipline requires that `isRiskManagementProcessStandardized` across all projects and that the `resourceAllocationProcessDocumented` is formalized. A `isBenefitRealizationPlanMandatory` requirement ensures value delivery is planned for all programmes and significant projects. Formal portfolio performance reviews must occur within a specified cadence, governed by the `portfolioReviewCycleMonths` threshold. Finally, a `hasStandardProjectClosureProcess` must be in place, which includes a mechanism for capturing lessons learned, thereby completing the governance lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-21502-project-mgt",
      "iso-31000-risk-mgt-std",
      "pmbok-7-guide-pm",
      "iso-9001-quality-mgt",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-21500-project-management-construction-guidance",
    "title": "ISO 21500:2021 - Project, Programme and Portfolio Management: Guidance on Project Management for Construction and Infrastructure Delivery",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "Provides guidance on project management processes and principles specifically tailored for construction and infrastructure projects, applicable to all organizations involved in delivering built assets. Key requirements are structured around Clause 4 (Principles) and Clause 5 (Process Model) of ISO 21500:2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021",
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-21500-project-mgt",
    "title": "Project Management (ISO 21500)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Conformance with this node mandates adherence to structured project management principles benchmarked against ISO 21500. Enterprise initiatives must be formally authorized via an evidence-based requirement that a project charter exists, and all relevant parties are managed through a process where stakeholders are identified and mapped. Rigorous planning, a cornerstone of the PMBOK Guide, is substantiated by a defined scope statement, an approved resource plan, and a complete work breakdown structure, complemented by an active communication plan. Operational governance during execution, reflecting best practices from PRINCE2 and ITIL v4, requires that a change control process is active. Risk management, aligning with the diligence found in NIST SP 800-53, is enforced by ensuring a risk register is maintained and subjected to a mandatory risk review frequency not to exceed 30 days. To provide continuous oversight consistent with COBIT 5 control objectives, a project status reporting frequency of every 14 days is obligatory. The project lifecycle concludes only upon obtaining a formal project closure signoff and the compulsory creation of a lessons learned report to institutionalize knowledge and drive process improvement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pmi-code-ethics",
      "iso-31000-risk-mgt",
      "sarbannes-oxley-404"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-21502-project-mgt",
    "title": "ISO 21502 (Project Mgt)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Conformance with governing ISO 21502 guidance for project, program, and portfolio management mandates a rigorous framework of controls and documented procedures. The standard requires that every project be initiated with a formal project charter and operate under a clearly defined and controlled scope. An organization must implement a quality management plan, a resource management plan, and a benefits realization plan to ensure outcomes align with strategic objectives. Continuous governance is enforced through a mandatory change control process for managing scope modifications and a meticulously maintained risk register. Quantitative thresholds for performance are strictly defined: any budget variance must not exceed 10 percent, and schedule variance is limited to a 15 percent tolerance before corrective actions are triggered. Furthermore, risk management protocols demand that risk response plan coverage extends to a minimum of 90 percent of identified threats. Stakeholder engagement policies necessitate a minimum communication frequency of four times per designated cycle. To foster continuous improvement, a formal lessons learned process is also required, ensuring knowledge from project execution is systematically captured and applied to future endeavors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-31000-risk-mgt-std",
      "iso-37301-compliance-mgt",
      "pmbok-7-guide-pm",
      "prince2-7-framework-pm"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-21542-accessibility-built-environment-2021",
    "title": "ISO 21542:2021 Building Construction - Accessibility and Usability of the Built Environment - Design Criteria and Dimensions",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2024-08-15",
    "bluf": "This standard provides specific design criteria and dimensional requirements for constructing and managing accessible and usable built environments, applicable to new and existing buildings. It mandates adherence to detailed specifications for elements like circulation paths, doors, ramps, and sanitary facilities to ensure usability for all people, including those with disabilities, as outlined in Clause 1 (Scope).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "250.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-22000-food-mgt",
    "title": "Food Safety Mgt (ISO 22000)",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Conformance with ISO 22000 requires a comprehensive Food Safety Management System (FSMS) built upon a documented food safety policy, as mandated by Clause 5.2, which must be communicated and understood. Organizations shall establish and maintain prerequisite programmes (PRPs) according to Clause 8.2 to manage the operational environment. A core system element is the hazard control plan, derived from a documented hazard analysis and fully implemented per Clause 8.5; this includes monitoring Critical Control Points (CCPs), with all associated records retained for a minimum duration of three years. To ensure product integrity throughout the supply chain, a robust traceability system must remain active, consistent with Clause 8.3. Concurrently, emergency preparedness and response procedures, stipulated under Clause 8.4, need to be active, enabling recall initiation within a maximum threshold of 24 hours from incident identification. System effectiveness is verified through internal audits, required by Clause 9.2, at a minimum frequency of every 12 months. This verification process is further supported by mandatory supplier evaluations, formal management reviews conducted at least every 12 months, and a consistently maintained corrective action log to address any identified nonconformities and foster continual system improvement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-gen",
      "gfsi-benchmarking",
      "haccp-food-safety",
      "iso-9001-quality-mgt",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-22301-2019-business-continuity-management-system",
    "title": "ISO 22301 2019 - Business Continuity Management System Requirements, BIA and Recovery Time Objectives",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "ISO 22301:2019 Security and resilience - Business continuity management systems - Requirements, published in October 2019 (second edition replacing ISO 22301:2012), specifies requirements to implement, maintain and improve a management system to protect against, reduce the likelihood of occurrence, prepare for, respond to and recover from disruptions when they arise. The standard follows the High-Level Structure (HLS) common to all ISO management system standards (ISO 9001, ISO 14001, ISO 27001, etc.) and is structured around Plan-Do-Check-Act (PDCA). Clause 4 covers context of organization, interested parties, scope, and the Business Continuity Management System (BCMS). Clause 5 covers leadership including BC policy and roles/responsibilities. Clause 6 covers planning including objectives. Clause 7 covers support including competence, awareness, communication, documented information. Clause 8 covers operation including Business Impact Analysis (BIA), Risk Assessment (RA), Business Continuity Strategies, Business Continuity Plans (BCPs), and exercise/testing programme. Clause 9 covers performance evaluation. Clause 10 covers improvement. Key concepts include Maximum Tolerable Period of Disruption (MTPD), Recovery Time Objective (RTO), Recovery Point Objective (RPO), and Minimum Business Continuity Objective (MBCO).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-iec-27001-2022-information-security-workflow",
      "iso-9001-2015-quality-management-systems-operations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-22301-2019-business-continuity-management-systems-requirements",
    "title": "ISO 22301:2019 Business Continuity Management Systems - Requirements",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2023-06-01",
    "bluf": "ISO 22301:2019 specifies requirements for a Business Continuity Management System (BCMS) that enables organisations to plan for, respond to, and recover from disruptive incidents. The standard requires organisations to assess business continuity risks, determine Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) for critical functions, develop Business Continuity Plans (BCPs) and Incident Response Plans (IRPs), and test and exercise these plans. ISO 22301 certification demonstrates third-party verified business continuity capability, increasingly required by government contracts, financial regulators, and enterprise procurement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-22301-bcm-2019",
    "title": "ISO 22301:2019 - Security and Resilience: Business Continuity Management Systems Requirements",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This international standard specifies requirements for establishing, implementing, maintaining, and continually improving a documented business continuity management system (BCMS) to protect against, reduce the likelihood of, prepare for, respond to, and recover from disruptive incidents. It applies to any organization, with core operational requirements detailed in Clause 8, including business impact analysis, risk assessment, and the development of business continuity plans and procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27005-risk-management-2022",
      "nist-sp-800-34-r1",
      "iso-27031-dr-readiness",
      "soc2-availability-criteria",
      "csa-ccm-v4-cloud-controls"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "iso-22301-biz-continuity",
    "title": "Biz Continuity (ISO 22301)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with this node mandates the implementation and maintenance of a comprehensive Business Continuity Management System (BCMS) in alignment with ISO 22301 requirements. Top management must formally establish and endorse a documented business continuity policy appropriate for the organization's purpose, as stipulated by Clause 5.2. Foundational to this system are a completed business impact analysis and a formal risk assessment. Per Clause 8.2.2, the BIA must determine critical recovery parameters, with BIDDA enforcing a maximum Recovery Time Objective (RTO) of 24 hours, a Recovery Point Objective (RPO) within 12 hours, and a Maximum Tolerable Period of Disruption (MTPD) not exceeding 48 hours. The risk assessment, a requirement of Clause 8.2.3, must identify and evaluate disruption risks to prioritize strategic responses. Clause 8.4 necessitates the creation of documented business continuity plans and procedures, which must be supported by an assigned incident response team and include verification of supply chain resilience. To ensure ongoing effectiveness and validate these strategies, Clause 8.5 requires an exercise programme, with testing conducted at a minimum frequency of every 365 days. Finally, to maintain conformity and facilitate continual improvement, the BCMS must undergo periodic internal audits and management reviews, both scheduled at least annually (every 365 days), consistent with the principles of Clause 9.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt",
      "iso-9001-quality-mgt",
      "iso-27001-2022",
      "iso-27031-dr-readiness",
      "nist-sp-800-34-contingency-planning-guide",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-22301-business-cont",
    "title": "ISO 22301 (Business Cont)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "ISO 22301:2019 is the premier international standard for Business Continuity Management Systems (BCMS). it specifies requirements for the organization to the 'Plan, Do, Check, Act' for the business resilience, ensuring that the organization can protect itself from, and the respond to, the disruptive the incidents through the standardized 'Impact Analysis' and the 'Recovery Procedures'.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27031-dr-readiness",
      "soc2-availability-criteria"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-23894-ai-risk-management",
    "title": "ISO/IEC 23894:2023 Information Technology - Artificial Intelligence - Guidance on Risk Management",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This standard provides guidance for managing risks related to artificial intelligence (AI) for any organization involved in the AI lifecycle. It extends the generic risk management framework of ISO 31000 to address the specific challenges of AI systems, as detailed in Clause 5, which outlines the principles, framework, and process for AI risk management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "nist-ai-rmf-1-0",
      "eu-ai-act-high-risk",
      "oecd-ai-principles",
      "nist-sp-1270-managing-ai-bias"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-26000-social-resp",
    "title": "Social Responsibility (ISO 26000)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "An organization's alignment with ISO 26000 principles is assessed through a multi-faceted verification of governance structures, operational practices, and public disclosures. Compliance necessitates a formal, publicly available Social Responsibility policy and the designation of a specific officer or committee for SR oversight. The framework's evaluation extends to supply chain integrity by quantifying the percentage of tier-1 suppliers screened for human rights risks. Internally, the node scrutinizes labor standards through key metrics, including the reported gender pay gap percentage and the Lost Time Injury Frequency Rate. Environmental stewardship is gauged by confirming public reporting of Scope 1 and Scope 2 Greenhouse Gas emissions and measuring the operational waste diversion rate percentage. Fair operating practices are confirmed through evidence of mandatory anti-corruption training, the coverage percentage of Data Privacy Impact Assessments on new projects, and the existence of a confidential whistleblower protection policy. A formal stakeholder engagement framework must also be operative. Finally, community contribution is quantified by community investments as a percentage of pre-tax profits, completing a holistic review of the entity's commitment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-sdg-corporate-mapping",
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-26000-social-resp-mgt",
    "title": "ISO 26000 (Social Resp)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Organizational alignment with ISO 26000 principles necessitates a comprehensive assessment of integrated social responsibility frameworks, verified through specific data points. Foundational governance is evidenced by an affirmative `has_sr_policy_endorsed_by_leadership` status, coupled with a systematic `has_stakeholder_identification_map` to guide engagement. Core human rights commitments are substantiated when a `human_rights_due_diligence_process_in_place` is operational. For labor practices, the node verifies both a structural `has_formal_employee_grievance_mechanism` and a performative, low `workplace_safety_incident_rate`. Environmental accountability is determined by the public disclosure within a `has_published_environmental_impact_report` and the establishment of a meaningful `greenhouse_gas_emission_reduction_target_pct`. Fair operating practices mandate a clear `has_anti_corruption_and_bribery_policy` and demand a high `supply_chain_sr_audit_coverage_pct` to mitigate upstream risks. In addressing consumer issues, the existence of a `has_consumer_data_privacy_policy` is a critical control. The organization's contribution to community involvement is quantified through its `community_investment_as_pct_of_pretax_profit`. Ultimate transparency and accountability are contingent upon whether `is_sr_performance_in_public_annual_report` is true, completing the cycle of commitment, action, and reporting. Non-conformance with these boolean and numeric thresholds signals a significant gap in an entity's social responsibility posture according to international guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "iso-31000-risk-mgt-std",
      "iso-37301-compliance-mgt",
      "iso-45001-work-safety",
      "iso-20400-sustainable-procure",
      "sa8000-social-account"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-26262-functional-safety-road-vehicles-2018",
    "title": "ISO 26262:2018 - Road Vehicles - Functional Safety",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 26262:2018 establishes functional safety requirements for electrical and electronic systems in production passenger vehicles (up to 3,500 kg), defining hazard classification via Automotive Safety Integrity Levels (ASIL A-D) and mandating a safety lifecycle from concept to decommissioning. It applies to OEMs and suppliers under Clause 4 (Safety Lifecycle) and ASIL determination in Clause 7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-26262-functional-safety-vehicles-2018",
    "title": "ISO 26262:2018 Road vehicles - Functional safety",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard mandates a risk-based approach to functional safety for electrical and electronic systems in production road vehicles. It requires organizations to perform a Hazard Analysis and Risk Assessment (HARA) to assign an Automotive Safety Integrity Level (ASIL) to system functions, which dictates the rigor of subsequent development and verification activities as defined in Part 3, Clause 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-23894-ai-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-27001-2022",
    "title": "ISO/IEC 27001:2022 - Information Security Management",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "ISO/IEC 27001:2022 (published October 2022, replacing ISO 27001:2013) is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It applies to any organization regardless of size or sector and is administered by ISO/IEC Joint Technical Committee 1, Subcommittee 27. The standard uses the Annex SL high-level structure shared with ISO 9001 and ISO 14001. Annex A contains 93 controls organized into four themes: Organizational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls). The 2022 revision added 11 new controls including threat intelligence (A.5.7), ICT readiness for business continuity (A.5.30), web filtering (A.8.23), data masking (A.8.11), data leakage prevention (A.8.12), and secure coding (A.8.28). Certification is achieved through a Stage 1 documentation review and Stage 2 on-site audit by an IAF-accredited certification body, with 3-year recertification and annual surveillance audits. Non-compliance with contractual ISMS requirements can result in contract termination and regulatory liability under GDPR, NIS2, and DORA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack",
        "mitre_d3fend",
        "mitre_capec"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-27001-isms-compliance-2026-20",
    "title": "ISO 27001 ISMS Enterprise Compliance Standard v20",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "ISO 27001 outlines the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It emphasizes a risk-based approach to information security, requiring organizations to assess their information security risks and implement appropriate controls to mitigate those risks. The standard mandates the establishment of an information security policy, the definition of roles and responsibilities, and the implementation of a risk assessment process. Organizations must also ensure ongoing monitoring and review of the ISMS, conduct internal audits, and engage in management reviews to ensure compliance and continual improvement. Compliance with ISO 27001 not only helps protect sensitive information but also enhances stakeholder trust and meets legal and regulatory requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-27001-isms-compliance-2026-5",
    "title": "ISO 27001 ISMS Enterprise Compliance Standard v5",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "ISO 27001 outlines the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It emphasizes a risk-based approach to information security, requiring organizations to assess their information security risks and implement appropriate controls to mitigate those risks. The standard mandates the documentation of policies, procedures, and controls, as well as regular audits and reviews to ensure compliance and effectiveness. Organizations must also demonstrate leadership commitment and employee awareness regarding information security. Compliance with ISO 27001 not only helps protect sensitive information but also enhances stakeholder confidence and meets legal and regulatory requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-27002-2022-organizational-controls",
    "title": "ISO/IEC 27002:2022 - Organizational Controls (A.5.1-A.5.37)",
    "domain": "Cybersecurity",
    "version": "3.0.0",
    "last_updated": "2022-02-15",
    "bluf": "ISO/IEC 27002:2022 Organizational Controls (A.5.1-A.5.37) constitute the largest of the four control themes introduced in the 2022 revision of ISO/IEC 27002. The 37 Organizational Controls address policies, roles, threat intelligence, supplier relationships, information security in projects, classification and handling of information, access management, identity management, authentication, incident management, business continuity, ICT readiness for business continuity, and legal/contractual/regulatory compliance obligations. These controls are control statements that map directly into the ISMS framework defined by ISO/IEC 27001:2022 Annex A. The Organizational theme represents foundational governance and management controls that apply across the entire enterprise, distinguishing it from the People (8 controls), Physical (14 controls), and Technological (34 controls) themes. Organizations implementing an ISMS aligned to ISO/IEC 27001:2022 must consider every applicable Organizational Control through the Statement of Applicability process. Implementation evidence is required for ISO/IEC 27001 certification, with audits typically following the multi-year accredited certification body cycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27002-2022-people-controls",
      "iso-27002-2022-physical-controls",
      "iso-27002-2022-technological-controls"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "iso-27002-2022-people-controls",
    "title": "ISO/IEC 27002:2022 Section 6 - People Controls: Screening, Terms, Awareness, Disciplinary Process",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-07-16",
    "bluf": "ISO/IEC 27002:2022 Section 6 provides implementation guidance for information security controls related to personnel throughout their employment lifecycle. It mandates processes for pre-employment screening (6.1), defining terms of employment (6.2), providing ongoing awareness training (6.3), establishing a formal disciplinary process (6.4), and managing responsibilities upon termination or change of employment (6.5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27005-risk-management-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "iso-27002-2022-physical-controls",
    "title": "ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection - Information security controls: Section 7 Physical Controls",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "ISO/IEC 27002:2022 Section 7 provides guidance for organizations to prevent unauthorized physical access, damage, and interference to information and information processing facilities. This is achieved by defining and protecting physical security perimeters (7.1), managing physical entry (7.2), securing offices, rooms, and facilities (7.3), and implementing a clear screen and clear desk policy (7.4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27005-risk-management-2022",
      "cyber-nist-csf-2"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-27002-2022-technological-controls",
    "title": "ISO/IEC 27002:2022 Section 8 - Technological Controls: Endpoint Security, Privileged Access, Data Masking",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "ISO/IEC 27002:2022, Section 8, provides implementation guidance for 34 technological controls designed to protect information systems and data. This includes specific controls for user endpoint device security (8.1), management of privileged access rights (8.2), and the use of data masking to protect sensitive information (8.11).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "cyber-nist-800-53-ac2",
      "cis-controls-v8",
      "nist-800-53-sc7",
      "iso-27005-risk-management-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-27005-risk-management-2022",
    "title": "ISO/IEC 27005:2022 Information Security Risk Management - Guidance on Managing InfoSec Risks",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This standard provides guidelines for establishing, implementing, maintaining, and continually improving an information security risk management process. It details the iterative process from context establishment (Clause 7) through risk assessment (Clause 8) and risk treatment (Clause 9), applicable to all organizations managing information security risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-31000-risk-mgt-std",
      "nist-cybersecurity-framework-2-0",
      "nist-ir-8286a-cybersecurity-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-27017-2015-cloud-controls",
    "title": "ISO/IEC 27017:2015 - Code of Practice for Information Security Controls for Cloud Services",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard provides guidelines for information security controls applicable to the provision and use of cloud services, supplementing the guidance in ISO/IEC 27002. It introduces cloud-specific controls and implementation guidance for both cloud service providers and customers, focusing on clarifying roles and responsibilities as outlined in Clause 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "iso-27018-pii-cloud",
      "nist-sp-800-145-cloud-definition"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-27017-cloud-controls",
    "title": "ISO/IEC 27017 (Cloud Controls)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The organizational posture concerning ISO/IEC 27017 establishes a comprehensive framework for cloud security controls, yet presents a material deviation regarding data jurisdiction. Adherence to controls for provider-customer relationships is demonstrated through a formally defined shared responsibility model and support for customer identity federation. Technical safeguards are systematically enforced, including logical customer data segregation and applied virtual machine hardening, consistent with leading virtualization security protocols. A coherent security posture is maintained by aligning network security controls across both physical and virtual environments. In line with incident management specifications, Service Level Agreements mandate a security incident response time not to exceed 24 hours, while proactive monitoring is ensured through configured alerts. Operational diligence, reflecting guidance on cloud service customer information security, includes providing customer access to security logs, conducting privileged access reviews at a 90-day frequency, and executing data restoration tests every 6 months. A secure asset removal procedure is also defined. The primary non-conformity is the system’s current inability to enforce customer-specified jurisdictions, a critical control for data sovereignty that remains unimplemented.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-145-cloud-computing",
      "iso-27018-pii-cloud"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-27017-cloud-defence",
    "title": "Cloud Security for Defense (ISO 27017)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "ISO/IEC 27017:2015 is an international code of practice for information security controls applicable to cloud services, providing cloud-specific implementation guidance for 37 controls from ISO/IEC 27002 and introducing 7 new cloud-specific controls not found in the base standard. In defense contexts, ISO 27017 governs how defense organizations and their contractors securely use cloud services to process, store, and transmit sensitive defense information, extending CMMC and NIST 800-171 requirements to cloud service provider relationships. The standard addresses the unique security challenges of shared-responsibility cloud models including: asset ownership in the cloud, decommissioning and secure disposal of cloud assets, virtual machine hardening, administrator privilege management, and customer-side monitoring of cloud environments. Organizations using cloud infrastructure for defense AI workloads must apply ISO 27017 controls to demonstrate appropriate cloud security governance to defense customers and regulators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-800-171-cui",
      "cmmc-2-audit",
      "dfars-7012-defense-cyber",
      "fedramp-authorization"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-27017-cloud-security-2015",
    "title": "ISO/IEC 27017:2015 Code of Practice for Information Security Controls Based on ISO/IEC 27002 for Cloud Services",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This standard provides guidelines for information security controls applicable to the provision and use of cloud services, offering implementation guidance for both cloud service providers and customers. It extends the controls in ISO/IEC 27002, clarifying roles and responsibilities as outlined in Clause 6.1.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "188.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2022"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27018-pii-cloud"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-27018-2019-pii-cloud",
    "title": "ISO/IEC 27018:2019 - Code of Practice for Protection of PII in Public Clouds Acting as PII Processors",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard establishes control objectives and guidelines for protecting Personally Identifiable Information (PII) for public cloud service providers acting as PII processors. It extends the controls in ISO/IEC 27002 and ISO/IEC 27001 to address cloud-specific PII protection requirements, such as ensuring data is not used for marketing without explicit consent (Clause A.2.1) and specifying the geographic locations of data storage (Clause A.9.1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27017-cloud-security-2015",
      "csa-ccm-v4-cloud-controls",
      "soc2-privacy-criteria"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-27018-cloud-privacy-2019",
    "title": "ISO/IEC 27018:2019 Code of Practice for PII Protection in Public Cloud Services Acting as PII Processors",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This standard establishes a code of practice for public cloud service providers acting as PII processors, providing specific controls and guidance to protect Personally Identifiable Information (PII). It extends the information security controls of ISO/IEC 27002 and ISO/IEC 27001 to address cloud-specific PII protection requirements as outlined in Annex A.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27017-cloud-controls",
      "nist-800-122-pii",
      "soc2-privacy-criteria"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-27018-pii-cloud",
    "title": "ISO/IEC 27018 (PII Cloud)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "ISO/IEC 27018 establishes a comprehensive code of practice for protecting Personally Identifiable Information (PII) within public cloud computing environments, acting as a guide for PII processors. The framework mandates that processors operate solely based upon documented customer instructions, ensuring all processing remains within authorized bounds. A central principle prohibits any PII use for marketing or advertising unless a customer provides explicit consent; this requirement extends to all data processing activities. Transparency is enforced through the mandatory disclosure of any subprocessor identities involved in handling customer information. To safeguard data confidentiality and integrity, this compliance node verifies that PII is encrypted both in transit and at rest. Contractual obligations are stringent, requiring the secure return or complete deletion of PII upon contract termination. In an event of a data breach, customers must receive notification without undue delay. The framework also empowers data subjects by supporting mechanisms for them to access, correct, and request erasure of their personal information. Internal controls must enforce strict confidentiality obligations upon all personnel with PII access. Furthermore, system integrity is monitored through enabled logging for all PII access events, which are retained for a minimum period of 90 days to support forensic analysis and compliance verification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27017-cloud-controls"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-27031-dr-readiness",
    "title": "ISO/IEC 27031 (ICT Readiness)",
    "domain": "Cloud & SaaS",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "ISO/IEC 27031:2011 (superseded by modern resilience standards but still foundational) provides the guidelines for Information and Communication Technology Readiness for Business Continuity (IRBC). it specifies the required the strategies to ensure that the digital infrastructure remains available and the resilient during the disasters, providing the bridging between the IT disaster recovery and the overall the business continuity management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-22301-business-cont",
      "soc2-availability-criteria"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-27701-privacy-information-management",
    "title": "ISO/IEC 27701:2019 Security techniques - Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management - Requirements and guidelines",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This international standard specifies requirements for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS) as an extension to an ISO/IEC 27001 Information Security Management System (ISMS). It applies to all organizations acting as PII controllers and/or PII processors, requiring them to manage privacy risks related to personally identifiable information (PII) as detailed in Clause 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-800-122-pii",
      "brazil-lgpd-compliance",
      "za-popia-2013"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-27799-health-info-sec",
    "title": "ISO 27799 (Health InfoSec)",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "ISO 27799:2016 (Health informatics - Information security management in health using ISO/IEC 27002) is the primary standard for implementing ISO 27001 in healthcare. It provides specific guidance on the additional security controls and management practices needed to protect personal health information (PHI) within healthcare organizations and their suppliers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "gdpr-health-data"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-27799-health-informatics-2026",
    "title": "ISO 27799:2025 - Health Informatics - Information Security Management in Health",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "ISO 27799 provides healthcare-specific guidance on implementing ISO/IEC 27002 controls within an Information Security Management System (ISMS). It addresses unique risks in health informatics including patient safety, confidentiality of health records, medical device security, and EHR systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022"
    ],
    "primary_citations_count": 3
  },
  {
    "node_id": "iso-28000-supply-chain",
    "title": "Supply Chain Security (ISO 28000)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "ISO 28000 is the specification for security management systems in the supply chain. It provides a formal framework to assess and manage security risks, such as theft, terrorism, and piracy, aimed at ensuring the integrity and continuity of global logistics operations across all stakeholders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "c-tpat-minimum-security",
      "wco-safe-framework-standards",
      "port-facility-security-isps",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-30414-human-capital",
    "title": "Human Capital Reporting (ISO 30414)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "ISO 30414 is the first international standard that allows organizations (SMEs, large enterprises, and public bodies) to get a clear view of their human capital's contribution. It provides a standardized framework for HR metrics across 11 core areas including recruitment, leadership, and diversity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-health-safety",
      "iso-26000-social-resp-mgt",
      "ilo-core-conventions",
      "un-guiding-principles-business-hr",
      "sa8000-social-account",
      "modern-slavery-act-rep"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-30414-human-capital-rep",
    "title": "ISO 30414 (Human Capital)",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with the ISO 30414 standard demands a systematic approach to human capital reporting, establishing transparent and comparable metrics for internal governance and external stakeholder review. Foundational requirements include the documented existence of a formal policy for human capital governance and verification that data collection spans all 11 core areas defined within the standard, such as Costs, Diversity, and Leadership. Organizational transparency is assessed by whether a public human capital report is published. Furthermore, a critical control mandates that robust data privacy safeguards are consistently applied to all collected human capital information. Quantitative evaluations form the core of this framework, requiring that the total cost of the workforce is calculated annually and tracked against performance indicators. Key metrics for continuous monitoring include the annual turnover rate percentage, the lost-time injury frequency rate per million hours worked, and the gender pay gap percentage. Leadership effectiveness and organizational culture are measured through a quantifiable leadership trust score, which must meet a target greater than 75. Strategic readiness is evaluated by the percentage of critical roles with succession plan coverage, while workforce investment is measured by the average training hours per employee. A deficiency in these areas constitutes a significant gap in human capital management, potentially impacting strategic alignment, investor confidence, and regulatory scrutiny.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp-mgt",
      "iso-45001-work-safety",
      "shrm-hr-competency",
      "ilo-core-conventions",
      "sa8000-social-account",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-31000-risk-management-mining-applications",
    "title": "ISO 31000:2018 Risk management - Guidelines",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "ISO 31000:2018 provides principles and guidelines for establishing a risk management framework and process within organizations, including mining operations, to systematically identify, analyze, evaluate, treat, monitor and communicate risks. It applies to all types of risk and all types of organizations, as defined in Clause 5 (Framework) and Clause 6 (Process).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eiti-standard-2023",
      "australia-epbc-act-1999-mining-biodiversity",
      "canada-impact-assessment-act-2019-mining",
      "eu-conflict-minerals-regulation-2017-821",
      "iso-19650-bim-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-31000-risk-management-principles-2018",
    "title": "ISO 31000:2018 Risk management - Guidelines",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "ISO 31000:2018 provides universal guidelines for any organization to integrate risk-based decision making through a structured framework and process. It requires establishing a risk management framework (Clause 5) and applying a systematic risk management process, including risk assessment and treatment (Clause 6), to create and protect value.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "180.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "iso-37301-compliance-mgt",
      "nist-sp-800-221-ict-risk",
      "iso-23894-ai-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-31000-risk-mgt",
    "title": "Risk Management (ISO 31000)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Organizational compliance with established international risk management principles necessitates a structured, integrated, and dynamic approach to identifying, analyzing, and treating uncertainty. The BIDDA compliance framework mandates the existence of a formal risk management policy and a thoroughly documented framework that is demonstrably integrated with overall corporate governance structures. A board-approved risk appetite statement must be established to guide strategic decision-making and operational boundaries. Clear accountability is required through explicitly defined risk management roles and responsibilities. Operationally, the organization must maintain a comprehensive risk register, subject to systematic risk assessments at a minimum frequency of every 12 months. Furthermore, the entire risk framework itself must undergo a comprehensive review no less than every 24 months to ensure its continued relevance and effectiveness. A critical control requires that 100 percent of all identified high-level risks possess a formally documented and active treatment plan. Supporting this entire lifecycle, a dedicated communication and consultation plan must be in place to engage stakeholders appropriately. Finally, evidence of a continual improvement process for risk management activities is mandatory, ensuring the framework evolves with the organization's context and the external environment, consistent with leading global standards for managing risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance",
      "iso-22301-biz-continuity",
      "sarbannes-oxley-404",
      "iia-internal-audit-ippf",
      "cyber-nist-csf-2",
      "iso-42001-performance"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-31000-risk-mgt-std",
    "title": "ISO 31000 (Risk Mgt)",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Adherence to governing risk management principles mandates a structured, enterprise-wide approach to identifying, analyzing, and treating uncertainty. This control node verifies the existence of foundational governance documents, including a formal, board-approved Risk Management Policy and a clearly defined Risk Appetite Statement. Operational execution requires that a centralized risk register is actively maintained, with formal management reviews occurring at a frequency not to exceed 12 months. Furthermore, accountability is enforced by stipulating that all risks classified as 'High' or 'Critical' must have a named individual assigned as the designated risk owner. The framework's integrity hinges upon formally established risk criteria for evaluating significance and achieving a minimum acceptable effectiveness threshold for risk treatment plans. Successful implementation also necessitates verifiable integration of the risk management process into the strategic planning cycle and the presence of a documented risk communication plan for all relevant internal and external stakeholders. Continuous improvement is validated through evidence of a defined process for enhancing the framework itself, supported by periodic internal or external audits conducted within a maximum interval, such as 18 months, to ensure ongoing relevance and efficacy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "iso-9001-quality-mgt",
      "iso-45001-work-safety",
      "nist-ir-8286c-staging-cybersecurity-risks",
      "nist-sp-800-221a-ict-risk-outcomes",
      "interagency-guidance-third-party-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-31010-2019-risk-assessment-operational",
    "title": "ISO 31010:2019 - Risk Management - Risk Assessment Techniques",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 31010:2019 provides a structured methodology for selecting and applying risk assessment techniques such as Bow-Tie, FMEA, HAZOP, and Monte Carlo simulation within operational processes. It applies to all organizations seeking to systematically identify, analyze, and evaluate risks in alignment with ISO 31000:2018 Clause 6.4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-37001-anti-bribery",
    "title": "Anti-Bribery Systems (ISO 37001)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "ISO 37001 is the international standard for anti-bribery management systems (ABMS). It specifies measures to help organizations prevent, detect, and address bribery by establishing a culture of integrity, transparency, and compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fcpa-anti-bribery-compliance",
      "uk-bribery-act-2010",
      "iso-37301-compliance",
      "iso-31000-risk-mgt",
      "iso-9001-quality-mgt",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-37001-anti-bribery-2016",
    "title": "ISO 37001:2016 Anti-Bribery Management Systems - Requirements and Guidance for Implementation",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "ISO 37001:2016 specifies requirements for establishing, implementing, maintaining, and improving an anti-bribery management system (ABMS) to prevent, detect, and respond to bribery. The standard, based on the Plan-Do-Check-Act model, requires organizations to conduct a bribery risk assessment (Clause 4.5) and implement proportional controls (Clause 8) under strong leadership commitment (Clause 5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fcpa-anti-bribery-compliance",
      "uk-bribery-act-2010",
      "iso-37301-compliance-ms",
      "oecd-corporate-governance-principles",
      "sarbanes-oxley-act-sox"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "iso-37001-anti-bribery-mgt",
    "title": "ISO 37001 (Anti-Bribery)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Conformance with the ISO 37001 standard requires establishing and maintaining a robust anti-bribery management system (ABMS). This operational framework mandates a formally documented ABMS policy and oversight by a designated compliance function. Leadership commitment is demonstrated through management reviews conducted at a minimum frequency of every 12 months. Central to the system is a comprehensive bribery risk assessment performed at least annually, which informs the implementation of requisite financial and non-financial controls designed to mitigate identified threats. The organization must execute due diligence on all business associates, with associated records maintained for a minimum retention period of 7 years. To ensure workforce competence in this area, the standard stipulates that 100 percent of high-risk personnel receive specific anti-bribery training. A confidential reporting mechanism must be established for raising concerns, and the organization is obligated to investigate all reported bribery issues thoroughly. System integrity and effectiveness are continually verified via internal ABMS audits, which must occur within a 12-month cycle. Adherence to these interconnected controls provides a reasonable and proportionate defense against bribery risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-37301-compliance",
    "title": "Compliance Mgt (ISO 37301)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Effective implementation of an ISO 37301 compliant framework mandates demonstrated leadership and commitment from top management and its governing body, evidenced by verified commitment and a published compliance policy. The foundation requires a systematic process to identify and evaluate legal requirements, with confirmation that a register of compliance obligations is maintained. Per the standard's emphasis on roles, responsibilities and authorities, the compliance function must possess verified independence to operate effectively. A continual process to address risks and opportunities is central, necessitating a formal compliance risk assessment performed at a minimum frequency of every twelve months. This risk-based approach informs operational controls like required third-party due diligence and achieving a ninety-five percent training completion rate. To foster integrity, the framework for raising concerns must include an active whistleblowing mechanism backed by an enforced anti-retaliation policy, ensuring investigations of noncompliance conclude within the thirty-day service level agreement. To ensure the CMS's ongoing suitability, adequacy, and effectiveness, a completed management review by leadership is mandatory, supplemented by independent audits occurring at least once per twelve-month cycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt",
      "iso-9001-quality-mgt",
      "iso-19011-audit-guidelines",
      "iso-37001-anti-bribery-mgt",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-37301-compliance-2021",
    "title": "ISO 37301:2021 Compliance Management Systems - Requirements with Guidance for Use",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "ISO 37301:2021 provides a certifiable framework for establishing, implementing, maintaining, and continually improving a Compliance Management System (CMS). It requires organizations to integrate compliance into all activities, led by top management's commitment (Clause 5.1) and supported by a systematic process of identifying obligations, assessing risks, and ensuring operational control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "218.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "iso-37001-anti-bribery-2016",
      "sarbanes-oxley-act-sox",
      "fcpa-anti-bribery-compliance",
      "uk-bribery-act-2010"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-37301-compliance-mgt",
    "title": "ISO 37301 (Compliance)",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Conformance with ISO 37301 necessitates a robust and effective Compliance Management System (CMS) built upon a culture of integrity and accountability. This evaluation verifies foundational governance structures, including a board-approved, accessible compliance policy and an operationally independent compliance function with a direct reporting line to the governing body. A comprehensive, documented register of all compliance obligations is essential for cataloging legal and regulatory duties. Proactive risk management is evidenced through formal compliance risk assessments conducted at a frequency of 12 months or less. Operational effectiveness hinges on achieving a mandatory training completion rate of at least 95 percent among all relevant personnel and maintaining a secure, anonymous reporting channel for confidential issue escalation without fear of retaliation. Furthermore, the framework requires a risk-based approach to third-party due diligence, tailoring scrutiny according to partner profiles. Continuous improvement is validated through systematic oversight, demanding a minimum of one formal management review per year and confirmation that an internal audit of the CMS has been conducted. The system must also possess a documented process for investigating non-compliance and demonstrate that key performance indicators for compliance are actively monitored and reported, proving an organization’s commitment to managing its obligations and consistently enhancing its compliance posture per leading international standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "iso-37001-anti-bribery-mgt",
      "iso-9001-quality-mgt",
      "iso-26000-social-resp-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-37301-compliance-ms",
    "title": "ISO 37301 (Compliance MS)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "ISO 37301:2021 is the global standard for Compliance Management Systems (CMS). It specifies requirements and provides guidelines for establishing, developing, implementing, evaluating, maintaining, and improving an effective CMS within an organization, superseding ISO 19600 and making it a certifiable standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "un-guiding-principles-business-hr",
      "oecd-guidelines-multinational-ent"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-39001-road-traffic",
    "title": "Road Traffic Safety (ISO 39001)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Adherence to the ISO 39001:2012 standard for Road Traffic Safety (RTS) management systems requires a comprehensive, documented framework designed to eliminate or significantly reduce death and serious injuries from road traffic incidents. This system's effectiveness, which aligns with principles from the WHO global plan for road safety and UNECE transport guidelines, is predicated on several key verifiable controls. The organization must demonstrate the existence of a formal RTS policy endorsed by top management and supported by specific, measurable objectives. A documented risk assessment process is mandatory, as is the continuous monitoring of RTS performance factors such as vehicle speed and driver fatigue, a practice recommended in OSHA guidelines. Procedural discipline is enforced through stringent timelines; for instance, a complete root cause analysis for any serious incident must be finished within a maximum of 30 days. Furthermore, top management must conduct formal performance reviews of the RTS system at a frequency not exceeding 12 months. The framework mandates a cycle of continuous improvement, evidenced by annual internal audits, a documented corrective action process, current training records for critical personnel, and a tested emergency preparedness plan, all reflecting best practices from sources like the NHTSA countermeasures guide and the FMCSA's Compliance, Safety, Accountability program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-health-safety",
      "iso-28000-supply-chain",
      "fleet-telematic-audit",
      "customs-tapa-transport-sec"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-39001-road-traffic-safety-management",
    "title": "ISO 39001:2012 - Road Traffic Safety Management Systems - Requirements with guidance for use",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This standard specifies requirements for a road traffic safety (RTS) management system to enable organizations to reduce or eliminate incidents involving road traffic injuries or fatalities. It applies to any organization interacting with the road traffic system, particularly through Clause 5.1 on leadership commitment to RTS policy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-national-road-safety-strategy-2021-2030",
      "california-dmv-autonomous-vehicle-regulations",
      "eu-co2-cars-vans-regulation-2023-851",
      "automotive-spice-pam-3-1",
      "etsi-its-cooperative-intelligent-transport"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-40500-wcag-2-1-web-accessibility-education",
    "title": "ISO/IEC 40500:2012 (WCAG 2.1) - Web Content Accessibility Guidelines for Educational Platforms: Perceivable, Operable, Understandable, Robust Criteria, Success Criteria and Conformance Levels",
    "domain": "Education & Research",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This standard requires educational platforms to conform to Web Content Accessibility Guidelines (WCAG) 2.0 to ensure web content is accessible to people with disabilities, including those with visual, auditory, motor, and cognitive impairments. The success criteria are organized under four principles: Perceivable, Operable, Understandable, and Robust, as defined in ISO/IEC 40500:2012.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-education-action-plan-2021-2027-deap",
      "eu-ai-act-education-high-risk-systems-annex-3",
      "eu-ai-act-2024-high-risk-educational-applications",
      "eu-digcomp-digital-competence-framework-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-41001-2018-facilities-management-systems",
    "title": "ISO 41001:2018 - Facility Management Systems: Requirements for Establishing, Implementing, Maintaining and Improving FM to Support Operations and CX",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 41001:2018 specifies requirements for establishing, implementing, maintaining, and improving a facility management system (FMS) to support organizational operations and customer experience. It applies to all organizations that deliver or use facility management services, requiring alignment with Clause 4.1-4.4 on context, leadership, planning, and support.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-42001-improvement",
    "title": "AIMS Improvement (ISO 42001)",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "ISO/IEC 42001:2023 Clause 10 (Improvement) mandates that organizations operating an AI Management System (AIMS) establish systematic processes for identifying, addressing, and preventing nonconformities - including AI safety incidents, bias events, harmful outputs, and performance degradation - and for driving continual improvement of the AIMS over time. Clause 10 requires organizations to react to nonconformities with documented corrective actions, perform root cause analysis to prevent recurrence, and evaluate the effectiveness of actions taken. Continual improvement requires using outputs from internal audits, management reviews, monitoring data, and stakeholder feedback to identify opportunities to enhance AI system performance, safety, and alignment. This clause is activated by incidents identified through the monitoring requirements of Clause 9 and is essential for demonstrating to regulators, customers, and auditors that the organization's AI systems become safer and more aligned over time, not static.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-31000-risk-mgt",
      "iso-37301-compliance-mgt",
      "iso-42001-performance",
      "iso-42001-risk-assess",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-42001-performance",
    "title": "AIMS Performance Eval (ISO 42001)",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "ISO/IEC 42001:2023 Clause 9 (Performance Evaluation) requires organizations operating an AI Management System (AIMS) to establish monitoring and measurement programs for AI systems and the AIMS itself, conduct internal audits of AIMS conformity, and hold management reviews that use performance data to make informed governance decisions. Clause 9.1 requires determining what needs to be monitored and measured, the methods to be used, when evaluations occur, and when results are analyzed and communicated. Clause 9.2 mandates an internal audit program covering all AIMS elements at risk-determined intervals. Clause 9.3 requires management reviews that consider: audit results, AI system performance data, incident trends, regulatory changes, stakeholder feedback, and risk treatment effectiveness. Without systematic performance evaluation, AIMS nonconformities may go undetected, AI systems may drift from aligned behavior, and regulators may determine the AIMS is nominal rather than effective.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-19011-audit-guidelines",
      "iso-42001-risk-assess",
      "iso-42001-improvement",
      "nist-ai-rmf-measure",
      "iso-31000-risk-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-42001-risk-assess",
    "title": "AI System Impact & Risk Assessment (ISO/IEC 42001:2023)",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The AI System Impact Assessment (Clause 6.1.2) is a mandatory requirement to identify, analyze, and evaluate the potential consequences of an AI system on individuals, groups, and society, focusing on fairness, privacy, safety, and security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_atlas"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt",
      "nist-ai-rmf-1-0",
      "oecd-ai-principles",
      "unesco-ethics-ai",
      "eu-ai-act-high-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-42001-transparency",
    "title": "AI Transparency & Communication (ISO/IEC 42001:2023 Annex A.8)",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Transparency controls (Annex A.8) mandate the provision of clear, accessible information regarding the AI system’s intent, capabilities, and limitations to ensure stakeholders can make informed decisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "nist-ai-rmf-1-0",
      "oecd-ai-principles",
      "unesco-ethics-ai",
      "ieee-ethics-ai-system",
      "eu-ai-act-high-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-42005-ai-impact-assessment",
    "title": "ISO/IEC 42005:2025 - Artificial Intelligence System Impact Assessment Guidance and Methodology",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard provides guidance and a methodology for conducting impact assessments of AI systems on individuals, society, and the environment. It outlines a structured process (Clause 5) for identifying, analyzing, and evaluating potential positive and negative impacts throughout the AI system lifecycle to inform decision-making and risk treatment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "iso-23894-ai-risk-management",
      "eu-ai-act-fundamental-rights-impact-assessment",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-44001-2017-collaborative-business-relationships",
    "title": "ISO 44001:2017 - Collaborative Business Relationship Management Systems: Framework, Principles and Requirements for Collaborative Operational Models",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 44001:2017 specifies requirements for establishing, implementing, maintaining, and improving a collaborative business relationship management system (CBRMS), applicable to any organization seeking to enhance value creation through structured collaboration with partners. Key requirements are defined in Clause 8 (Operational Planning and Control) and Clause 9 (Evaluation of Performance).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-p2b-regulation-2019-1150",
      "eu-unfair-commercial-practices-directive",
      "iso-45001-ohs-management-construction"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-44001-collaborative",
    "title": "Collaborative Ops (ISO 44001)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Operationalizing collaborative business relationships under ISO 44001 demands rigorous adherence to a structured framework for joint activities and governance. Compliance mandates an active relationship management plan, which according to Clause 8.5, must articulate a minimum of three defined collaborative objectives, and a joint governance committee must be established to oversee these partnerships. Per Clause 8.2 on operational awareness and readiness, this framework also requires a tested joint business continuity plan, ensuring partner incident notifications are issued within a maximum of 24 hours. The joint risk management process detailed in Clause 8.4 is enforced through periodic assessments occurring at intervals not to exceed 180 days. To satisfy Clause 8.3 concerning knowledge sharing and information management, all shared data must have encryption enforced, and partner access controls must be verified to uphold least-privilege principles. Furthering these controls, a completed partner compliance audit is necessary. The value creation process, guided by Clause 8.8, is institutionalized via assessments conducted at a minimum annual frequency, with a period not exceeding 365 days. Finally, in line with Clause 8.9 on disengagement, a documented and fully tested exit strategy must be in place to manage the relationship lifecycle conclusion methodically.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-31000-risk-mgt",
      "iso-37301-compliance-mgt",
      "iso-21502-project-mgt",
      "iso-20400-sustainable-procure"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-45001-health-safety",
    "title": "Occupational Health & Safety (ISO 45001)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "ISO 45001:2018 is the global standard for occupational health and safety (OH&S), designed to prevent work-related injuries and illnesses while promoting a safe work environment through risk-based resource allocation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-45001-ohs-management-construction",
    "title": "ISO 45001:2018 Occupational Health and Safety Management Systems for Construction: Hazard Identification and Incident Investigation",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "ISO 45001:2018 requires construction organizations to establish proactive processes for identifying workplace hazards (Clause 6.1.2) and to systematically investigate incidents, nonconformities, and their root causes to implement effective corrective actions and prevent recurrence (Clause 10.2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-45001-work-safety",
    "title": "ISO 45001 (Work Safety)",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Organizational adherence to the ISO 45001 standard for occupational health and safety (OHS) management is systematically demonstrated through a comprehensive and well-documented framework. The compliance posture is fundamentally supported by an established OHS policy and unequivocal, demonstrated leadership commitment, which are cornerstones of the governing frameworks. Worker engagement is confirmed by an active participation mechanism, while proactive hazard management is evidenced through a documented identification process and recurring risk assessments conducted at a maximum frequency of every 12 months. Competency and awareness are maintained at a high level, with a verified 95.5 percent of workers having completed requisite OHS training. The organization’s procedural maturity extends to reactive and preparatory measures, including a defined incident investigation procedure and a tested emergency preparedness plan. Continuous improvement and governance are rigorously upheld through an implemented internal audit program, a formal change management process for OHS matters, and defined OHS objectives that are actively tracked. Management oversight is consistently applied, with formal review meetings conducted at a minimum 6-month frequency, ensuring the OHS management system’s ongoing suitability, adequacy, and effectiveness in mitigating workplace risks. This integrated approach confirms a robust and compliant OHS program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "iso-37301-compliance-mgt",
      "osha-work-safety-us",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-46001-water-eff",
    "title": "Water Efficiency (ISO 46001)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Adherence to the Water Efficiency (ISO 46001) standard necessitates the implementation of a systematic Water Efficiency Management System (WEMS). Verification requires evidence of a formal water efficiency policy, endorsed by top management and communicated throughout the organization. The WEMS must have clearly defined and documented boundaries, establishing its specific applicability. A foundational prerequisite is the completion of a comprehensive water balance assessment, which quantifies all water inflows, uses, and outflows to establish a defensible baseline for measuring performance. Based upon this baseline, the organization must set specific, measurable, and time-bound objectives for improvement. Operational control is critically evaluated by the percentage of significant water users that are actively metered and monitored, alongside the existence of documented procedures for the operation of facilities related to this significant use. The framework also demands a program to ensure personnel are competent and aware of their roles. Continual improvement and system viability are confirmed by the timely execution of internal audits and formal management reviews, measured in months since their last completion, and by maintaining a robust process for identifying non-conformities and implementing corrective actions to prevent recurrence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-14046-water-footprint"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-50001-2018-energy-management-systems",
    "title": "ISO 50001:2018 - Energy Management Systems - Requirements with guidance for use",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "ISO 50001:2018 specifies requirements for establishing, implementing, maintaining and improving an energy management system (EnMS), enabling any organization to systematically improve energy performance, efficiency, and consumption. The standard's core is the Plan-Do-Check-Act (PDCA) cycle, requiring organizations to define their context, establish an energy policy, set objectives, and implement processes to achieve them, as outlined in Clause 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-50001-energy",
    "title": "Energy Management (ISO 50001)",
    "domain": "Industrial IoT & Energy",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "ISO 50001:2018 is the international standard for Energy Management Systems (EnMS), providing a framework for organizations to continuously improve energy performance - energy efficiency, energy consumption, and energy intensity - through systematic planning, implementation, monitoring, and review. The standard follows the Plan-Do-Check-Act cycle and requires organizations to establish an energy baseline, define Energy Performance Indicators (EnPIs), set energy objectives and targets, implement operational and maintenance controls for significant energy uses, and drive continual improvement. For AI data centers and large-scale compute facilities, ISO 50001 is directly relevant as AI training and inference workloads represent some of the fastest-growing energy consumers globally. ISO 50001 certification demonstrates systematic energy management to regulators, investors, and customers; EU energy efficiency regulations increasingly require EnMS for large energy consumers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-14001-ems",
      "iso-31000-risk-mgt",
      "csrd-eu-sustainability",
      "nist-sp-800-82r3-ot-security",
      "nerc-cip-v6-cyber"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-50001-energy-management-systems-2018",
    "title": "ISO 50001:2018 Energy management systems - Requirements with guidance for use",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "ISO 50001:2018 specifies the requirements for establishing, implementing, maintaining, and improving an energy management system (EnMS), enabling organizations to systematically achieve continual improvement of energy performance. This framework, detailed in Clause 4, helps organizations manage energy use, consumption, and efficiency, reduce costs, and lower greenhouse gas emissions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures",
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "iso-55001-2014-asset-management-industrial",
    "title": "ISO 55001:2014 - Asset Management Systems - Requirements for Establishing, Implementing and Improving an Asset Management System",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 55001:2014 specifies requirements for an asset management system (AMS) to enable organizations to manage physical assets in industrial infrastructure contexts, ensuring value realization throughout the asset lifecycle. It applies to all types of organizations and mandates compliance with Clause 5.4 on asset management objectives and Clause 8.1 on operational planning and control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-iacs",
      "iso-iec-27019-energy-utility-information-security",
      "nist-sp-800-82-r3-ot-ics-security-guide-2023",
      "ot-ics-purdue-model-zone-based-security",
      "iso-50001-energy"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-55001-asset-management-utility-infrastructure",
    "title": "ISO 55001:2014 Asset Management - Management Systems - Requirements for Utility Infrastructure",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard specifies the requirements for an integrated asset management system for utility infrastructure, requiring organizations to establish, implement, maintain, and continually improve their management of physical assets. As per Clause 6.2, organizations must define asset management objectives and create documented Strategic Asset Management Plans (SAMPs) to achieve them, balancing cost, risk, and performance across the asset lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-7628-smart-grid-cybersecurity",
      "iso-37301-compliance-mgt",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-6469-electric-vehicle-safety-standard",
    "title": "ISO 6469 - Electric Vehicle Safety: On-Board Electrical Energy Storage, Functional Safety, Protection Against Electric Shock and Connecting to External Power Supply",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation standard specifies safety requirements for electric vehicles concerning electrical energy storage, protection against electric shock, and connection to external power supplies. It applies to road vehicles with a maximum voltage exceeding 60 V DC or 30 V AC, as defined in Clause 4 of ISO 6469.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-batteries-regulation-2023-1542-ev-batteries",
      "california-dmv-autonomous-vehicle-regulations",
      "eu-digital-product-passport-vehicles-2024",
      "automotive-spice-pam-3-1",
      "australia-national-road-safety-strategy-2021-2030"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-9001-2015-quality-management-construction",
    "title": "ISO 9001:2015 - Quality Management Systems - Requirements",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 9001:2015 requires construction organizations to establish, implement, maintain, and continually improve a quality management system (QMS) based on risk-based thinking, with documented processes for context analysis, design control, and nonconformity management. Applies to all organizations in the construction sector regardless of size or structure, per Clause 4.1-4.4 and Clause 10.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-9001-2015-quality-management-systems-operations",
    "title": "ISO 9001:2015 - Quality Management Systems: Requirements",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 9001:2015 specifies requirements for a quality management system (QMS) where an organization must demonstrate its ability to consistently provide products and services that meet customer and applicable statutory requirements, enhance customer satisfaction through continual improvement and risk-based thinking. Applies to all organizations regardless of size or industry, per Clause 4.1 and Clause 5.1.2 on customer focus.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-9001-quality-management-construction",
    "title": "ISO 9001:2015 Quality Management Systems Applied in Construction - Inspection and Test Plans, Non-Conformance and Corrective Action",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Construction organizations must implement a quality management system that includes documented Inspection and Test Plans (ITPs) to verify project stages, systematically control nonconforming outputs according to Clause 8.7, and apply a formal corrective action process as mandated by Clause 10.2 to prevent the recurrence of defects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "pmbok-7-guide-pm"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-9001-quality-mgt",
    "title": "ISO 9001 (Quality Mgt)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the ISO 9001 standard necessitates the establishment and maintenance of a comprehensive Quality Management System (QMS). A fundamental requirement is that organizations must possess a documented QMS scope and a formally defined quality policy. The framework mandates a proactive approach to planning through a required risk and opportunity analysis, alongside the establishment of measurable quality objectives to drive performance. Continuous improvement is underpinned by a mandatory corrective action process. Operational integrity demands rigorous monitoring, including a requirement for customer satisfaction monitoring and the implementation of defined supplier evaluation criteria for managing external providers. Governance and oversight are enforced through structured internal audits, which international standards specify must be conducted at a minimum frequency of every 12 months. Similarly, a formal management review process is compulsory, also with a minimum 12-month interval, to assess QMS effectiveness. Finally, the standard stipulates that an organization maintain robust controls over all documented information to ensure its availability, integrity, and confidentiality. These interconnected requirements form the basis for achieving certification and demonstrating a commitment to quality.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-iec-15031-on-board-diagnostic-obd-standards",
    "title": "ISO 15031 Series - Road Vehicles: Communication Between Vehicle and External Equipment for Emissions-Related Diagnostics (OBD)",
    "domain": "Automotive & Mobility",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "ISO 15031 is a multi-part series (Parts 1 to 7), published by ISO Technical Committee TC 22 in cooperation with SAE, that specifies how external test equipment communicates with a road vehicle's on-board diagnostic (OBD) system to retrieve emissions-related diagnostic information. It is NOT a single ISO/IEC document and IEC is not a co-publisher. The series is structured by part, not by physical/data-link/application clauses: Part 1 covers general information and use cases; Part 2 terms and abbreviations; Part 3 the diagnostic connector and electrical circuits (technically equivalent to SAE J1962); Part 4 external test equipment; Part 5 emissions-related diagnostic services (the J1979/ISO 15031-5 service set); Part 6 diagnostic trouble code (DTC) definitions (referencing SAE J2012-DA); and Part 7 data link security. It applies to vehicle and diagnostic-tool manufacturers seeking standardized, interoperable access to legislated emissions OBD data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-iec-15408-common-criteria-telecom-evaluation",
    "title": "ISO/IEC 15408: Information security, cybersecurity and privacy protection - Evaluation criteria for IT security",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "ISO/IEC 15408, the Common Criteria, establishes a standardized framework for evaluating and certifying the security of IT products, including telecom equipment. It requires that a product's security features be defined in a Security Target (ST) and rigorously tested against a specific Evaluation Assurance Level (EAL) to verify its claims, as detailed in Part 3: Security assurance components.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27017-cloud-defence",
      "nist-800-171-rev-3"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-iec-17025-lab",
    "title": "Lab Competence (ISO 17025)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with ISO 17025 necessitates a comprehensive framework for establishing and maintaining laboratory competence. The standard mandates that formal, documented competence requirements exist for all personnel involved in laboratory activities, and that there is an ongoing process for monitoring personnel competence, as detailed in sections 6.2.2 and 6.2.4. For equipment, a formal calibration program is essential per section 6.4.7, with complete technical records of calibration history maintained according to 6.4.13. All measurement results must demonstrate established metrological traceability to the International System of Units through an unbroken chain, a core tenet of section 6.5.1. Furthermore, laboratories are required to evaluate and account for measurement uncertainty in all relevant tests, as specified in 7.6. Information management systems, such as LIMS, must undergo validation for functionality, data integrity, and security before implementation, and robust controls must protect information from unauthorized access or tampering, both under section 7.11.2. The management system itself requires a formal process to identify and address risks and opportunities pursuant to 8.5.1, a planned internal audit program to verify operational conformity per 8.8.1, and periodic management reviews conducted at a defined frequency, which must not exceed a threshold like 12 months, in accordance with section 8.9.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-19011-audit-guidelines",
      "iso-31000-risk-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-iec-20387-2018-biobanking-general-requirements",
    "title": "ISO 20387:2018 Biotechnology - Biobanking - General Requirements for Biobanking",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2020-04-01",
    "bluf": "ISO 20387:2018 Biotechnology - Biobanking - General Requirements for Biobanking is the international standard specifying the management and technical requirements for biobanks to enable them to demonstrate competence in providing biological material and associated data of appropriate quality for research and development. The Standard was published by the International Organization for Standardization in August 2018 and is applicable to all biobanks regardless of size or scope including human, animal, plant, and microorganism biobanks. The Standard is structured around a management system that integrates with ISO 9001 quality management system principles and adopts a process approach focused on biospecimen lifecycle, traceability, and data quality.\n\nThe Standard's core technical requirements include validated procedures for collection, processing, preservation, storage, retrieval, and distribution of biospecimens; characterisation of biospecimens including their stability, integrity, and identity; data quality and traceability through unique sample identifiers and provenance metadata; competence of biobank personnel including training and proficiency records; facilities and environmental conditions appropriate to the preserved biospecimens; equipment qualification, calibration, and maintenance; and risk-based approach to quality management. The Standard supports international harmonisation of biobanking practice and is increasingly referenced in national biobanking guidelines including the South Africa NHREC 2024 Guidelines, the Japan AMED BioBank governance, and the EU Health Data Space genomic data quality framework. Accreditation against ISO 20387 is conferred by national accreditation bodies that are signatories to the International Laboratory Accreditation Cooperation (ILAC) Mutual Recognition Arrangement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-guidelines-human-biobanks-2009"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "iso-iec-22989-ai-concepts-terminology-2022",
    "title": "ISO/IEC 22989:2022 - Artificial Intelligence Concepts and Terminology",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "ISO/IEC 22989:2022 'Artificial intelligence - Concepts and terminology' is the foundational ISO/IEC standard establishing the vocabulary for artificial intelligence; published by ISO/IEC JTC 1/SC 42 (Subcommittee on Artificial Intelligence), it defines over 150 key AI terms organised into seven conceptual areas: (1) Basic concepts - AI, artificial intelligence system, autonomy, autonomous system, explainability, trustworthy AI, human-centred AI; (2) Machine learning concepts - machine learning, supervised learning, unsupervised learning, reinforcement learning, semi-supervised learning, federated learning, transfer learning; (3) Neural network concepts - neural network, deep learning, convolutional neural network, recurrent neural network, generative adversarial network, attention mechanism, transformer; (4) Data concepts - training data, test data, validation data, dataset, ground truth, label, annotation, data augmentation; (5) Model concepts - AI model, model training, inference, overfitting, underfitting, hyperparameter, performance metric; (6) Functional safety and AI - fail-safe, fail-secure, safety integrity level, AI safety; (7) Sociotechnical concepts - algorithmic bias, fairness, accountability, transparency, privacy-by-design; ISO/IEC 22989:2022 is the primary vocabulary reference for ISO/IEC 42001:2023 (AI management system), ISO/IEC 23894:2023 (AI risk management), ISO/IEC 24027:2021 (AI bias), and the entire ISO/IEC JTC 1/SC 42 AI standard family; regulatory instruments including the EU AI Act Article 3 definitions are aligned with the ISO/IEC 22989 vocabulary; organisations implementing AI governance frameworks should ensure their internal AI terminology is consistent with ISO/IEC 22989 to enable interoperability with regulatory requirements and contractual obligations that reference ISO/IEC AI standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/iso-iec-22989-ai-concepts-terminology-2022.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-iec-42001-2023-ai-management-system",
      "iso-iec-23894-ai-risk-management-2023",
      "iso-iec-24027-bias-fairness"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-iec-23053-ai-framework-ml-systems-2022",
    "title": "ISO/IEC 23053:2022 Framework for Artificial Intelligence Systems Using Machine Learning - Compliance Obligations for ML System Architecture Governance, AI System Lifecycle Documentation, and Framework-Based AI Risk Controls",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations under ISO/IEC 23053:2022 for AI systems using machine learning, focusing on architecture governance, lifecycle documentation, and risk controls; it aligns with EU AI Act (Regulation (EU) 2024/1689) Articles 6-15 for high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-iec-23894-ai-risk-management-2023",
    "title": "ISO/IEC 23894:2023 Information technology - Artificial intelligence - Guidance on risk management",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard provides guidance for organizations on managing risks related to AI systems, extending the general risk management framework of ISO 31000 to the specific context of AI. It details a comprehensive risk management process (Clause 6) applicable throughout the AI system lifecycle, from conception to decommissioning, to address potential negative impacts on individuals, organizations, and society.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "220.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "nist-ai-rmf-1-0",
      "eu-ai-act-high-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-iec-24027-bias-fairness",
    "title": "ISO/IEC 24027: Bias and Fairness in AI",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The mathematical and technical playbook for mitigating human cognitive bias, data bias, and engineering bias through quantitative fairness metrics like demographic parity and equalized odds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "iso-42001-transparency",
      "nist-ai-rmf-govern",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-iec-24029-1-robustness-neural-networks",
    "title": "Artificial Intelligence (AI) - Assessment of the Robustness of Neural Networks - Part 1: Overview",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This technical report provides an overview of existing methods to assess the robustness of neural networks, focusing on formal verification and statistical testing approaches. It applies to developers, evaluators, and auditors of AI systems using neural networks who require guidance on robustness evaluation techniques as outlined in ISO/IEC TR 24029-1:2021, Clause 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "nist-ai-100-4-redteam"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "iso-iec-27001-2022-information-security-workflow",
    "title": "ISO/IEC 27001:2022 - Information Security Management Systems: Statement of Applicability, Risk Treatment Plan and Continuous Improvement for Automated Processes",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO/IEC 27001:2022 requires organizations to establish, implement, maintain, and continually improve an information security management system (ISMS) based on risk assessment and treatment, including formal documentation of the Statement of Applicability (SoA) and Risk Treatment Plan (RTP). It applies to all organizations using automated processes that process, store, or transmit information, per Clause 6.1.3 and Clause 8.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "automation-bpmn-service-task",
      "automation-bpmn-error-boundary",
      "agent-kill-switch",
      "mcp-enterprise-auth"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-iec-27011-telecoms-information-security",
    "title": "ISO/IEC 27011:2016 Code of Practice for Information Security Controls for Telecommunications Organisations",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard provides a sector-specific code of practice for implementing information security controls within telecommunications organizations, extending the general guidance of ISO/IEC 27002. It addresses unique telecom risks such as network infrastructure security, customer data privacy in transit, and service availability, as detailed throughout its clauses (e.g., Clause 12 on Operations Security).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-22301-biz-continuity",
      "nist-sp-800-57-key-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "iso-iec-27017-cloud-security-controls-service-providers",
    "title": "ISO/IEC 27017:2015 - Cloud-Specific Information Security Controls for Cloud Service Providers and Customers",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2015-12-01",
    "bluf": "ISO/IEC 27017 provides cloud-specific security control guidance extending ISO/IEC 27002 for cloud environments, addressing shared responsibilities between cloud service providers and customers, virtual machine hardening, cloud service customer data separation, and security provisions in cloud service agreements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "eu-nis2-directive-2022-2555-network-information-security"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-iec-27019-energy-utility-information-security",
    "title": "ISO/IEC 27019:2017 Information technology - Security techniques - Information security controls for the energy utility industry",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "ISO/IEC 27019:2017 provides sector-specific guidance for implementing information security controls in the process control systems (Operational Technology) of the energy utility industry. It extends the general controls of ISO/IEC 27002 with specific requirements for securing energy generation, transmission, and distribution systems, as detailed in Clauses 5 and 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27002-2022-technological-controls",
      "iso-27002-2022-physical-controls",
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-iec-27110-2021-cybersecurity-framework",
    "title": "ISO/IEC TS 27110:2021 - Cybersecurity Framework Development Guidelines: Concepts, Terminology and Reference Architecture for National and Organisational Frameworks",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This technical specification provides guidelines for developing cybersecurity frameworks at national and organizational levels, including concepts, terminology, and reference architecture. It applies to policymakers, framework developers, and cybersecurity architects. Key provisions are outlined in Clause 6 on reference architecture and Clause 7 on framework development.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-csf-2",
      "cyber-nist-800-53-ac2",
      "aicpa-soc2-cc-availability",
      "aicpa-soc2-cc-confidentiality",
      "c-scrm-practices-systems-organizations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-iec-42001-2023-ai-management-system",
    "title": "ISO/IEC 42001:2023 - Artificial Intelligence Management System Standard",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "ISO/IEC 42001:2023, published on 18 December 2023, is the first international standard specifying requirements for an Artificial Intelligence Management System (AIMS) - it provides a structured framework for organisations that develop, provide, or use AI systems to establish, implement, maintain, and continually improve their AI governance, risk management, and responsible AI practices; the standard follows the ISO High-Level Structure (HLS) enabling integration with ISO 9001 (quality), ISO 27001 (information security), and ISO 14001 (environmental) management systems; it includes Annex A controls covering AI policy, human oversight, data for AI, AI system lifecycle, responsible AI impact assessments, and AI risk management; ISO/IEC 42001 is directly referenced by EU AI Act Article 40 standardisation context and is a candidate for harmonisation under the EU AI Act as evidence of conformity with Article 17 quality management system requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/iso-iec-42001-2023-ai-management-system.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-17-quality-management",
      "eu-ai-act-article-40-harmonised-standards",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-annex-vi-internal-control-conformity-assessment"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-iec-42001-ai-management-system-2023",
    "title": "ISO/IEC 42001:2023 Information technology - Artificial intelligence - Management system",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "ISO/IEC 42001:2023 specifies the requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within an organization. It applies to any organization, regardless of size or type, that develops, provides, or uses AI-based products or services, providing a certifiable framework for responsible AI governance based on the Plan-Do-Check-Act model (Clauses 4-10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "220.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026",
        "mitre_atlas"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "iso-23894-ai-risk-management",
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-42005-ai-impact-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-iec-42001-clause-10-continual-improvement",
    "title": "ISO/IEC 42001:2023 Clause 10 - Continual Improvement of AI Management Systems - Compliance Obligations for AI Nonconformity Response, Corrective Action for AI Failures, and Systematic AI Governance Improvement",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines obligations under ISO/IEC 42001:2023 Clause 10 for continual improvement of AI management systems, focusing on nonconformity response and corrective actions for AI failures, with overlapping requirements from the EU AI Act (Regulation (EU) 2024/1689, Articles 9 and 15) for high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-iec-42001-clause-5-leadership-ai-governance",
    "title": "ISO/IEC 42001:2023 Clause 5 - Leadership and AI Governance Commitment - Compliance Obligations for Top Management AI Accountability, AI Policy Approval, and Organisational Role Assignment for AI Risk Management",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines top management obligations under ISO/IEC 42001:2023 Clause 5 for AI governance, including accountability, policy approval, and role assignment for AI risk management, with overlapping requirements in the EU AI Act (Regulation (EU) 2024/1689, Articles 6-9) for high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-iec-42001-clause-6-ai-risk-planning",
    "title": "ISO/IEC 42001:2023 Clause 6 - AI Risk Planning and Objective Setting - Compliance Obligations for AI Risk Assessment Methodology, AI Objective Documentation, and Organisational AI Risk Treatment Planning",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines obligations under ISO/IEC 42001:2023 Clause 6 for AI risk planning, including risk assessment methodologies, objective documentation, and treatment planning, with overlapping requirements from the EU AI Act (Regulation (EU) 2024/1689, Articles 9 and 17) for high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-iec-42001-clause-7-support-resources",
    "title": "ISO/IEC 42001:2023 Clause 7 - Support and Resources for AI Management Systems - Compliance Obligations for AI Competency Development, Awareness Programmes, AI Documentation Controls, and Communication Requirements",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines obligations under ISO/IEC 42001:2023 Clause 7 for AI management systems, focusing on resource allocation, competency development, awareness programs, documentation controls, and communication requirements, with overlapping obligations under EU AI Act Regulation (EU) 2024/1689 Articles 9 and 13 for high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-iec-42001-clause-8-operations",
    "title": "ISO/IEC 42001:2023 Clause 8 - AI System Operational Planning and Control - Compliance Obligations for AI Lifecycle Operational Controls, AI System Deployment Governance, and Operational Change Management for AI",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines obligations under ISO/IEC 42001:2023 Clause 8 for operational planning and control of AI systems, including lifecycle controls, deployment governance, and change management, with overlapping requirements from the EU AI Act (Regulation (EU) 2024/1689, Articles 16 and 29) for high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-iec-42005-2025-ai-system-impact-assessment",
    "title": "ISO/IEC 42005:2025 - Information Technology - Artificial Intelligence - AI System Impact Assessment",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "ISO/IEC 42005:2025 is an international standard published by ISO/IEC JTC 1/SC 42 (Artificial Intelligence) that provides organizations with guidance on conducting AI system impact assessments. The standard establishes a structured methodology to identify, assess, document, and communicate the potential effects of AI systems on individuals, groups, and society. It is the operational companion to ISO/IEC 42001:2023 (AI Management System) - organizations certified under 42001 use 42005 to satisfy Clause 6.1.4 (AI system impact assessment) of 42001. The standard covers (1) the scope and context of the impact assessment, (2) identification of stakeholders and affected parties, (3) categories of potential impacts including human rights, privacy, fairness, transparency, accountability, safety, and environmental factors, (4) assessment process including risk identification, analysis and evaluation, (5) documentation requirements, and (6) communication and review obligations. ISO/IEC 42005 references and aligns with EU AI Act Annex IV technical documentation requirements, US NIST AI RMF Core Govern and Map functions, and EU AI Liability framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-iec-42001-2023-ai-management-system",
      "iso-iec-23894-ai-risk-management-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-iec-5230-openchain",
    "title": "Open Source (ISO 5230)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "ISO/IEC 5230:2020 (OpenChain) is the international standard for open source software license compliance, defining the minimum requirements for a quality open source compliance program that enables organizations to trust open source software they receive from third parties and to manage the open source they distribute. The standard requires organizations to establish an Open Source Program Office (OSPO) or equivalent function, implement Software Composition Analysis (SCA) tooling to identify open source components in software, manage license obligations (attribution notices, source code distribution, patent grant notices), maintain a Software Bill of Materials (SBOM), and train personnel on open source license compliance. For AI systems, ISO 5230 applies to AI frameworks (PyTorch, TensorFlow, JAX), pre-trained model weights distributed under open licenses, and training data packages with open data licenses - license violations risk injunctions, damages, and product recall. SBOM requirements under US Executive Order 14028 and EU Cyber Resilience Act directly build on ISO 5230 principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-literary-artistic",
      "paris-convention-industrial-property"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iso-iec-tr-24027-2021-bias-in-ai-systems",
    "title": "ISO/IEC TR 24027:2021 - Information Technology - Artificial Intelligence - Bias in AI Systems and AI Aided Decision Making",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "ISO/IEC TR 24027:2021 is a Technical Report published by ISO/IEC JTC 1/SC 42 (Artificial Intelligence) that addresses bias in AI systems and AI-aided decision making. The report defines bias terminology, identifies sources of bias across the AI lifecycle (data collection and labelling, feature selection, modelling, deployment, monitoring), surveys techniques for bias measurement and mitigation, and provides guidance on the assessment of fairness in AI. TR 24027 is informative rather than normative but provides the consensus international vocabulary for AI bias that underpins regulatory expectations including the EU AI Act Article 10 (Data and Data Governance) bias detection and mitigation requirements, the EEOC Title VII technical assistance on AI in employment, the CFPB Circular 2022-03 and 2023-03 on ECOA adverse action, and the Colorado SB 205 and Texas TRAIGA fairness obligations. TR 24027 references ISO/IEC TR 24028 (trustworthiness), ISO/IEC 23894 (risk management), and the SC 42 family of standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-iec-tr-24028-2020-ai-trustworthiness-overview",
      "iso-iec-23894-ai-risk-management-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-iec-tr-24028-2020-ai-trustworthiness-overview",
    "title": "ISO/IEC TR 24028:2020 - Information Technology - Artificial Intelligence - Overview of Trustworthiness in AI",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "ISO/IEC TR 24028:2020 is a Technical Report published by ISO/IEC JTC 1/SC 42 (Artificial Intelligence) that provides an overview of trustworthiness in AI systems. The report defines trustworthiness in the AI context as the demonstrable property of an AI system that enables reliance on its operation; identifies the principal attributes of trustworthy AI including accountability, accuracy, authenticity, availability, controllability, integrity, privacy, quality, reliability, resilience, robustness, safety, security, and transparency; analyses common threats and risks to AI trustworthiness across the lifecycle; and surveys the technical and process-oriented approaches to mitigate them. ISO/IEC TR 24028 is a foundational document referenced by ISO/IEC 42001 (AI Management System), ISO/IEC 42005 (Impact Assessment), ISO/IEC 23894 (Risk Management), and ISO/IEC TR 24027 (Bias). As a Technical Report, TR 24028 is informative rather than normative, but it provides the consensus international definition of AI trustworthiness underpinning the SC 42 standards family.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-iec-42001-2023-ai-management-system",
      "iso-iec-23894-ai-risk-management-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-iec-tr-24028-ai-trustworthiness-overview",
    "title": "ISO/IEC TR 24028:2020 Information technology - Artificial intelligence - Overview of trustworthiness in artificial intelligence",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Technical Report (TR) provides a comprehensive overview of AI trustworthiness, identifying potential threats and mitigation approaches across the AI system lifecycle. It serves as a foundational guidance document for organizations to understand and address key trustworthiness characteristics such as reliability, availability, resilience, accountability, transparency, explainability, safety, security, and privacy, as detailed in Clause 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "222.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-23894-ai-risk-management",
      "iso-42001-risk-assess",
      "nist-ai-rmf-1-0",
      "oecd-ai-principles",
      "nist-language-of-trustworthy-ai"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "iso-iec-tr-24368-2022-ai-ethical-concerns",
    "title": "ISO/IEC TR 24368:2022 Information technology - Artificial intelligence - Overview of ethical and societal concerns",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This technical report provides a structured overview of ethical and societal concerns in artificial intelligence, identifying key issues such as bias, transparency, accountability, and human oversight. It applies to technologists, regulators, and organizations involved in AI development and deployment, supporting ethical impact assessments through Clause 6 and Annex A.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "australia-ai-ethics-framework-2019",
      "asean-guide-ai-governance-ethics-2020",
      "nist-ai-100-4-redteam"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "iso-sae-21434-2021-road-vehicles-cybersecurity",
    "title": "ISO/SAE 21434:2021 Road Vehicles - Cybersecurity engineering",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard requires automotive manufacturers and suppliers to implement a certified Cybersecurity Management System (CSMS) and apply a risk-based approach throughout the entire vehicle lifecycle, from concept to decommissioning. It mandates the performance of Threat Analysis and Risk Assessment (TARA) as detailed in Clause 15 to identify and mitigate cybersecurity risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "245.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27017-cloud-defence",
      "nist-800-171-rev-3"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "isps-code-vessel-security",
    "title": "ISPS Code (Vessel Security)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The International Ship and Port Facility Security (ISPS) Code is a mandatory set of measures to enhance the security of ships and port facilities. It provides a standardized framework for evaluating risk, enabling governments to offset changes in threat with changes in security level for ships and port facilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "port-facility-security-isps",
      "ism-code-vessel-safety",
      "imo-stcw-seafarer-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "israel-ai-regulation-roadmap-2023",
    "title": "Israel National AI Regulation Roadmap 2023 - Innovation-Preserving Approach, Responsible Ministry Assignment per AI Domain, Soft-Law First Strategy, ILITA Data Protection Role, AI Regulatory Sandbox, Public Sector AI Procurement Guidelines and OECD AI Principles Adoption",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "This roadmap establishes a cross-ministerial, innovation-friendly framework for AI governance in Israel, assigning lead regulatory responsibility by domain, promoting soft-law instruments, embedding OECD AI Principles, and launching an AI regulatory sandbox. It applies to all public sector AI deployments and private sector AI systems operating in Israel where designated by lead ministry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-ai-safety-2023",
      "australia-ai-ethics-framework-2019",
      "asean-model-ai-governance-v2-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "israel-privacy-protection-amendment-2023",
    "title": "Privacy Protection Amendment (Data Security and Breach Notification) Law 2023 - Update to the Privacy Protection Law 5741-1981",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This amendment to Israel's Privacy Protection Law 1981 introduces mandatory data breach notification to the Privacy Protection Authority (PPA), enhances individual rights including access, erasure, and data portability, requires appointment of a Data Protection Officer (DPO) for large-scale processors, and aligns key provisions with GDPR standards. Enforcement includes administrative fines up to ILS 3.2 million. See source document for full scope.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-privacy",
      "aicpa-soc2-cc-confidentiality",
      "uk-money-laundering-regulations-2017-amended"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "isrc-recording-code",
    "title": "ISRC (Recording Code)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "International Standard Recording Code (ISRC) compliance necessitates rigorous validation against its established global standard for identifying sound recordings and music videos. For accurate automated processing, the code must first be stripped of any separators, such as hyphens. The resulting sanitized string must conform to a precise 12-character length and consist exclusively of uppercase alphanumeric characters (A-Z, 0-9). The structure is segmented into four distinct parts: the initial two characters must represent a valid ISO 3166-1 alpha-2 country code; the subsequent three characters form an alphanumeric Registrant Code; the sixth and seventh characters are two digits for the Year of Reference, which cannot specify a year beyond the current one; and the final five characters comprise a numeric Designation Code. Crucially, governance rules mandate absolute uniqueness, requiring that an ISRC is assigned to only one asset, with an asset assignment count that must equal one. This principle strictly prohibits reuse. Additionally, the embedded Registrant Code must be verifiable against an official database maintained by a recognized national ISRC agency, confirming the rightsholder's registration. Any deviation from these formatting or registration prerequisites renders an ISRC invalid.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "wipo-copyright-treaty",
      "wipo-performances-phonograms"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "iss-intergovernmental-agreement-1998",
    "title": "International Space Station Intergovernmental Agreement 1998 (IGA) - Legal Framework for ISS Operations",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Agreement Among the Government of Canada, Governments of Member States of the European Space Agency, the Government of Japan, the Government of the Russian Federation, and the Government of the United States of America concerning Cooperation on the Civil International Space Station (ISS Intergovernmental Agreement, IGA) was signed on 29 January 1998 and entered into force on 27 March 2001. The IGA establishes the legal framework governing the ISS partnership, allocating ownership of ISS elements among the partner agencies (NASA, ESA, JAXA, CSA, Roscosmos), establishing the jurisdiction and control regime for crew and modules, setting intellectual property rules for ISS-based inventions, and defining criminal jurisdiction for offences on the station. The IGA is supplemented by Memoranda of Understanding between NASA and each partner agency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "un_registration_convention",
        "liability_convention_1972"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "issb-ifrs-s2-climate-2023",
    "title": "IFRS S2 Climate-related Disclosures",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2023-06-26",
    "bluf": "IFRS S2 requires an entity to disclose information about its climate-related risks and opportunities, enabling users of general purpose financial reports to assess their effects on the entity's cash flows, access to finance, and cost of capital. This includes mandatory disclosure of governance processes, strategy resilience using scenario analysis, risk management integration, and specific metrics such as absolute gross Scope 1, Scope 2, and Scope 3 greenhouse gas (GHG) emissions (Paragraph 29).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "issb-s1-s2-standard",
      "tcfd-climate-related-financial-disclosures",
      "ghg-protocol-scope3",
      "iso-14064-ghg-quantify",
      "csrd-eu-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "issb-s1-s2-standard",
    "title": "ISSB S1/S2 Standards",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The International Sustainability Standards Board (ISSB) issued its inaugural standards, IFRS S1 and IFRS S2, to provide a global baseline for sustainability disclosures. IFRS S1 covers general requirements for sustainability-related financial information, while IFRS S2 focuses on climate-related disclosures, aiming for high-quality, investor-grade reporting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "tcfd-climate-risk",
      "iso-14064-ghg-reporting"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "isscr-guidelines-stem-cell-research-2021",
    "title": "ISSCR Guidelines for Stem Cell Research and Clinical Translation (2021)",
    "domain": "Biotech & Genomics",
    "version": "2021",
    "last_updated": "2026-05-09",
    "bluf": "The International Society for Stem Cell Research (ISSCR) 2021 Guidelines for Stem Cell Research and Clinical Translation represent the international consensus framework governing embryonic stem cell research, human embryo culture, stem cell-based embryo models (SCBEMs), chimeric animal research, heritable human genome editing (prohibited), and clinical translation of cell-based therapies; the 2021 revision restructures the oversight framework into three tiers (Prohibited, Requires Specialized Oversight, Permitted with Appropriate Oversight) and removes the former absolute 14-day rule on human embryo culture in favour of a case-by-case scientific and ethics review process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "eu-atmp-regulation-1394-2007"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "issn-serial-standard",
    "title": "ISSN (Serial Standard)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "International Standard Serial Number (ISSN) compliance mandates stringent data integrity and structural validation for all applicable serial publications. A designated 'issn' field must be present and conform to the canonical 'NNNN-NNNC' format, where the final character is a digit or an uppercase 'X'. The unhyphenated string must possess a length of exactly 8 characters, comprising seven initial digits and a final valid check character. Correctness is further enforced through a 'Modulo 11' checksum calculation, which algorithmically validates the eighth digit based upon the preceding seven. An ISSN is required for asset types classified as 'serial', 'journal', 'magazine', 'newsletter', or 'periodical'. Procedurally, the existence of an ISSN implies the mandatory presence of a corresponding, non-null publication title. Uniqueness is paramount; the system prohibits duplicate ISSN assignment across distinct publication titles. For external verification, each ISSN must be confirmed as officially registered and active through an API lookup against the ISSN International Centre's portal. Finally, if a single publication title has more than one format-specific identifier, the designation of a linking ISSN-L becomes a requirement to ensure cohesive resource identification. This comprehensive rule set ensures all managed serials adhere to global cataloging and identification standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "isbn-book-standard",
      "doi-digital-object-id"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "it-ai-law-132-2025-italian-ai-act-anthropocentric-supervision",
    "title": "Italy Legge 23 settembre 2025, n. 132 - Italian AI Law (Anthropocentric Use, AgID and ACN as National AI Authorities, Health, Public Administration, Judicial Use, EU AI Act Adaptation Delegation)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "Italy Legge 23 settembre 2025, n. 132 (Disposizioni e deleghe in materia di intelligenza artificiale) is the first EU Member State implementing law adapting domestic Italian legislation to Regulation (EU) 2024/1689 (the EU AI Act), published in Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 under codice redazionale 25G00139. Article 1 (Finalita e ambito di applicazione) sets the law's purpose: it lays down principles in research, experimentation, development, adoption, and application of AI systems and models; promotes correct, transparent, and responsible use in an anthropocentric dimension to capture opportunities; and ensures vigilance over economic, social, and fundamental-rights risks. Article 1(2) requires the provisions to be interpreted and applied in conformity with Regulation (EU) 2024/1689. Article 2 (Definizioni) imports the AI system definition from Article 3(1) and the AI model definition from Article 3(63) of Regulation (EU) 2024/1689, adds a 'data' definition (any digital representation of acts, facts, or information including audio, visual, or audiovisual recording), and defers to the EU AI Act for matters not expressly provided. Article 3 (Principi generali) requires AI development to respect Italian Constitutional fundamental rights, EU law, transparency, proportionality, security, personal data protection, confidentiality, accuracy, non-discrimination, gender equality, sustainability, and to ensure cybersecurity throughout the AI lifecycle. Article 3(5) provides the law does not impose new obligations beyond Regulation (EU) 2024/1689. Article 4 governs AI use in information and personal data, including a requirement for parental consent for under-14s and the 14-17 youth-consent threshold for personal data processing connected to AI use. Article 7 (Uso dell'intelligenza artificiale in ambito sanitario e di disabilita) governs health and disability use, prohibiting discriminatory access to health services and reserving the medical decision to the medical professional. Article 8 declares health AI research processing of personal data by public bodies, non-profit private bodies, IRCCS scientific care institutes, and private health-sector bodies in joint projects as of significant public interest. Article 13 governs intellectual professions. Article 14 (Pubblica amministrazione) requires public administrations to use AI to increase efficiency while preserving the human responsibility for proceedings and decisions. Article 15 (Attivita giudiziaria) reserves to the magistrate every decision on interpretation, application of law, fact and evidence assessment, and adoption of provisions, with Ministry of Justice authorisation required pending full implementation of Regulation (EU) 2024/1689. Article 16 delegates the Government to adopt within 12 months legislative decrees on data, algorithms, and mathematical methods for AI training. Article 17 amends Article 9 of the Italian Code of Civil Procedure to assign exclusive Tribunal competence for cases concerning the functioning of an AI system. Article 20 (Autorita nazionali) designates AgID (Agenzia per l'Italia digitale) as responsible for promoting innovation, notification, assessment, accreditation, and monitoring of conformity assessment bodies, and ACN (Agenzia per la cybersicurezza nazionale) as responsible for supervision (including inspections and sanctions) and cybersecurity profiles, with Banca d'Italia, CONSOB, and IVASS preserved as market surveillance authorities under Article 74(6) of Regulation (EU) 2024/1689. Article 24 delegates the Government to adopt within 12 months legislative decrees to fully adapt national law to Regulation (EU) 2024/1689 including sanctioning powers under Article 99 of that Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "purpose_and_scope_anchor",
        "definitions_anchor",
        "general_principles_anchor",
        "information_and_data_protection_anchor",
        "health_and_disability_anchor",
        "health_ai_research_anchor",
        "intellectual_professions_judicial_and_public_administration_anchor",
        "civil_procedure_amendment_anchor",
        "national_ai_authorities_anchor",
        "delegations_anchor",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-artificial-intelligence-act-2024-1689",
      "eu-ai-act-2024-1689-article-64-market-surveillance-enforcement-authorities",
      "eu-ai-act-article-71-fines",
      "es-aesia-ai-supervision-agency-2024",
      "iso-iec-42001-2023-ai-management-system"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "it-caivano-decree-article-13-bis-agcom-96-25-cons-age-verification",
    "title": "Italy Caivano Decree Article 13-bis (DL 123/2023 converted by Law 159/2023) and AGCOM Resolution 96/25/CONS (8 April 2025) - Age Verification for Websites and VSPs Disseminating Pornographic Content; Certified Third-Party Provider; Two-Step Process; Double Anonymity; 12 November 2025 Compliance Deadline",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Italy's Caivano Decree (Decreto-Legge 15 September 2023 n. 123, converted into Law 13 November 2023 n. 159) introduced Article 13-bis prohibiting minors from accessing pornographic content and delegating to AGCOM (Italy's Communications Authority, Autorità per le Garanzie nelle Comunicazioni) the power to set the regulatory framework for age verification on websites and video-sharing platforms (VSPs) disseminating pornographic content. AGCOM adopted Resolution 96/25/CONS on 8 April 2025 establishing the technical and operational requirements for the age verification system. The Resolution requires (1) age verification to be performed by certified independent third-party providers (not by the website or VSP itself, separating verification from content access); (2) a two-step process of identification and authentication of the identified person for each session of service use; (3) a double anonymity mechanism whereby the age verification provider cannot see which service the age proof is being issued for and the proof shared with the website or VSP contains no identifying information about the user; (4) technology-neutral standards covering proportionality, data protection (UE GDPR + Italian Codice della Privacy compliance), cybersecurity, accuracy, accessibility, and non-discrimination. The implementation deadline for adult-content websites and VSPs to integrate the age verification system was 12 November 2025 (six months from the Resolution's adoption). Failure to comply allows AGCOM to issue blocking orders requiring DNS-level blocking by Italian internet service providers - in practice AGCOM has already ordered DNS blocking of non-compliant adult-content websites. The Italian Administrative Court (TAR Lazio) annulled aspects of the Resolution as applied to non-EU-established service providers under the AVMSD country-of-origin principle, with the regime remaining fully effective against Italy-established and EU-established providers under the country-of-origin allocation. The Italian regime operates alongside the EU AVMSD Article 28b, the Digital Services Act, and the EU age-attestation rollout under eIDAS 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "caivano_decree_article_13_bis",
        "agcom_resolution_96_25_cons",
        "certified_third_party_provider_requirement",
        "two_step_process_per_session",
        "double_anonymity_mechanism",
        "technology_neutral_standards",
        "implementation_deadline_12_november_2025",
        "agcom_dns_blocking_enforcement",
        "tar_lazio_country_of_origin_ruling",
        "relationship_with_avmsd_dsa_eidas2",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-avmsd-article-28a-28b-video-sharing-platform-minors-protection",
      "eu-dsa-article-28-online-protection-of-minors",
      "eu-eidas-2-digital-identity-wallet-2024-1183",
      "uk-ofcom-highly-effective-age-assurance-guidance-2025-osa-part-5",
      "payment-processing-restricted-content-visa-virp-mastercard-an-5196"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "it-codice-della-strada-dlgs-285-1992-veicoli",
    "title": "Italy Decreto Legislativo 30 aprile 1992 n. 285 - Nuovo Codice della Strada Titolo III Veicoli Omologazione Immatricolazione e Revisione",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-29",
    "bluf": "Italy Decreto Legislativo 30 aprile 1992 n. 285 establishes the Nuovo Codice della Strada with Titolo III Dei Veicoli covering Articoli 46 to 94 across four Capi including Capo I disposizioni generali Capo II veicoli a trazione animale slitte e velocipedi Capo III veicoli a motore e loro rimorchi and Capo IV macchine agricole e operatrici. Capo III Sezione I governs norme costruttive e di equipaggiamento e accertamenti tecnici per la circolazione in Articoli 71 to 81 including omologazione e approvazione tipo Sezione II in Articoli 82 to 92 covers destinazione ed uso dei veicoli and Sezione III in Articoli 93 to 103 governs documenti di circolazione e immatricolazione under Articolo 93 carta di circolazione. The Motorizzazione Civile MCTC administers immatricolazioni revisioni tecniche and controlli di conformità costruttiva.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-type-approval-regulation-2018-858",
      "un-regulation-155-vehicle-cybersecurity",
      "un-regulation-156-software-updates-ota"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "it-codice-privacy-dlgs-196-2003",
    "title": "Italy Personal Data Protection Code (Codice Privacy, D.Lgs. 196/2003) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Italy's Personal Data Protection Code (Codice in materia di protezione dei dati personali - Codice Privacy, Legislative Decree No. 196 of 30 June 2003, as substantially amended and restructured by Legislative Decree No. 101 of 10 August 2018 to align with the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679)) is Italy's primary national data protection legislation. The GDPR is directly applicable Italian law by virtue of Italy's EU membership; D.Lgs. 101/2018 aligned the Codice Privacy with GDPR by repealing incompatible provisions and adding national derogations and specifications. Enforcement: Garante per la protezione dei dati personali (Il Garante) is Italy's independent data protection supervisory authority, established in 1996. Il Garante is Italy's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Il Garante is one of the most active enforcement authorities in the EU and internationally, including the temporary blocking of ChatGPT in Italy from 30 March 2023 to 28 April 2023 over GDPR compliance concerns regarding transparency, legal basis, age verification, and data accuracy. Key Italian national provisions: (1) Age of digital consent: Italy has set the age of consent for information society services at 14 years (GDPR Art. 8 allows member states to set between 13 and 16 years); data subjects under 14 require parental or guardian consent; (2) Codici Deontologici (deontological codes): Italy maintains a system of sector-specific deontological codes adopted by Il Garante that carry the force of law and provide specific rules for particular sectors including journalism and information activities, medical and health activities, scientific and biomedical research, statistical and scientific research, and private investigators; deontological codes are binding on entities operating in the relevant sector; (3) Employment context: specific national provisions on employment data processing, including employee monitoring (Art. 4 Statuto dei Lavoratori - Workers' Statute, Law No. 300/1970 as amended by Jobs Act 2015), trade union activity, and health surveillance; (4) Public interest and research: specific provisions for processing in the public interest, scientific research, statistics, and archiving, including Ethics Committee requirements for health data research; (5) Criminal data: the Codice Privacy restricts processing of personal data relating to criminal convictions and offences by private entities. Fines: GDPR administrative fines apply in Italy - up to EUR 20 million or 4% of global annual turnover for the most serious violations. Il Garante has imposed major GDPR fines including against Enel Energia, TIM, Vodafone, and Meta. Italy's data protection enforcement is among the most active in the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "it-d-lgs-145-2007-misleading-comparative-advertising",
    "title": "Italy Decreto Legislativo 145/2007 on B2B Misleading and Comparative Advertising",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Decreto Legislativo 2 agosto 2007 n. 145 transposes EU Directive 2006/114/EC into Italian law, regulating misleading and comparative advertising between businesses (B2B). The decree was in force from 21 September 2007 and applies in parallel with the Codice del Consumo (D.Lgs. 206/2005) which governs B2C unfair commercial practices. Art. 1 establishes the purpose - protection of professionals from misleading advertising and conditions for lawful comparative advertising - and requires that advertising be palese, veritiera e corretta (clear, truthful and correct). Art. 2 contains the key definitions including pubblicita ingannevole. Art. 4 sets out evaluation criteria for misleading advertising. Art. 6 establishes the conditions for permitted comparative advertising (objective comparison, comparable goods or services, no denigration, no exploitation of competitor reputation, no confusion between trade marks). Art. 7 governs advertising not clearly recognisable as such (hidden advertising). Art. 8 grants the Autorita Garante della Concorrenza e del Mercato (AGCM) administrative enforcement powers including cease orders and pecuniary sanctions. Art. 9 governs impegni (commitments) procedure for closing investigations without finding of infringement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "it-d-lgs-206-2005-codice-del-consumo",
      "us-ftc-cfr-16-part-255-endorsement-testimonials-advertising"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "it-d-lgs-206-2005-codice-del-consumo",
    "title": "Italy Decreto Legislativo 206/2005 - Codice del Consumo",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Decreto Legislativo 6 settembre 2005 n. 206 (Codice del Consumo) is Italy's consolidated consumer protection framework, in force from 23 October 2005 and continuously updated through implementation of EU consumer protection directives. The Code is organised in six Parti covering general provisions, consumer education and commercial practices, consumer contracts, product safety and liability, consumer associations and dispute resolution, and final provisions. Art. 1 sets the harmonisation purpose. Art. 2 establishes the catalogue of consumer rights. Arts. 19 to 27 (Titolo III) implement the EU Unfair Commercial Practices Directive 2005/29/EC, with Art. 20 containing the general prohibition of pratiche commerciali scorrette, Art. 21 governing pratiche ingannevoli (deceptive practices), Art. 22 governing omissioni ingannevoli, Art. 23 listing pratiche considerate ingannevoli in ogni caso (deceptive in all circumstances), Art. 24 governing pratiche aggressive and Art. 26 listing pratiche aggressive in ogni caso. Art. 27 grants the Autorita Garante della Concorrenza e del Mercato (AGCM) enforcement powers including cease-and-desist orders and fines up to 10 million euro. The Code consolidates approximately 20 prior legislative acts on distance sales, product liability, warranty guarantees and consumer ADR.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "it-d-lgs-36-2023-codice-contratti-pubblici",
      "us-ftc-cfr-16-part-255-endorsement-testimonials-advertising"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "it-d-lgs-231-2001-corporate-criminal-liability",
    "title": "Italy Decreto Legislativo 231/2001 - Disciplina della responsabilita amministrativa delle persone giuridiche (Corporate Criminal Liability)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Decreto Legislativo 8 giugno 2001 n. 231 establishes the administrative (quasi-criminal) liability of legal persons, companies and unincorporated associations for predicate offences committed in their interest or to their advantage. The decree was in force from 4 July 2001 and applies extraterritorially under Art. 4. The decree is organised in four Capi. Art. 1 sets the scope (enti dotati di personalita giuridica plus societa and associazioni anche prive di personalita giuridica; public bodies excluded). Art. 5 sets the imputation rule: the entity is liable for offences committed by persons in apical position (rappresentanza, amministrazione, direzione) or by subordinate persons subject to their direction, where the offence was committed in the interest or to the advantage of the entity. Arts. 6-7 provide the organisational model exemption (Modello Organizzativo 231): an entity escapes liability if it had adopted and effectively implemented before the offence an organisational and management model suitable to prevent that type of offence, established an independent Organismo di Vigilanza (OdV) with autonomous initiative and control powers, and the offender fraudulently circumvented the model. Art. 9 sets the four sanction categories: sanzione pecuniaria (quota-based fines), sanzioni interdittive, confisca and pubblicazione della sentenza. Arts. 10-12 establish the quota system: 100-1000 quotas, each between 258 EUR and 1549 EUR. Arts. 13-15 list the interdittive sanctions including interdizione dall'esercizio dell'attivita, sospensione di licenze and divieto di contrattare con la pubblica amministrazione. Arts. 24 to 25-octiesdecies enumerate the predicate offences catalogue including corruption, fraud against the State, market abuse, money laundering, cybercrime, environmental crime, occupational health and safety manslaughter, intellectual property infringement, false accounting, terrorism and organised crime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-bribery-act-2010",
      "fr-sapin-ii-anticorruption-2016",
      "us-fcpa-foreign-corrupt-practices-act-1977"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "it-d-lgs-36-2023-codice-contratti-pubblici",
    "title": "Italy Decreto Legislativo 36/2023 - Codice dei Contratti Pubblici",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Decreto Legislativo 31 marzo 2023 n. 36 (the new Codice dei Contratti Pubblici), in force from 1 April 2023, replaces D.Lgs. 50/2016 and implements EU Directives 2014/23/EU, 2014/24/EU and 2014/25/EU into Italian law. The Code is structured in five Libri: Libro I (principles, digitalisation, programming and design), Libro II (public contract procurement), Libro III (procurement in special sectors), Libro IV (public-private partnerships and concessions) and Libro V (dispute resolution, ANAC governance and final provisions). Article 1 establishes the principio del risultato, requiring contracting authorities to pursue the best relationship between quality and price with maximum speed while respecting legality, transparency and competition. Other foundational principles include the principio della fiducia (Article 2), principio dell'accesso al mercato (Article 3) and principio di auto-organizzazione amministrativa (Article 7). Article 14 sets the EU thresholds (soglie di rilevanza comunitaria). Article 50 governs procurement procedures. Article 70 covers qualification systems for economic operators. Article 108 governs award criteria. Articles 209 to 220 establish the precontenzioso and contenzioso regime overseen by ANAC (Autorita Nazionale Anticorruzione).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-public-procurement-construction-directive",
      "uncitral-model-law-public-procurement-2011"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "it-d-lgs-70-2003-e-commerce",
    "title": "Italy Decreto Legislativo 70/2003 - Attuazione della Direttiva 2000/31/CE sul commercio elettronico (E-Commerce Decree)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Decreto Legislativo 9 aprile 2003 n. 70 transposes EU Directive 2000/31/CE on certain legal aspects of information society services and electronic commerce in the internal market into Italian law. The decree was in force from 14 May 2003 and last updated 17 April 2024. Art. 1 sets the scope (libera circolazione dei servizi della societa dell'informazione) and lists exclusions including taxation, data protection in telecoms, antitrust, non-EEA providers, notarial services and gambling. Arts. 3-4 establish the country-of-origin principle for service providers established in Italy. Art. 7 sets information obligations for service providers (identification, contact, VAT number, professional body registration). Arts. 8-9 regulate commercial communications including the requirement that promotional offers and competitions be clearly identifiable. Art. 9 prohibits unsolicited electronic commercial communications without prior consent (transposed via D.Lgs. 196/2003 art. 130). Arts. 12-13 govern e-contract formation including the acknowledgement requirement. Arts. 14-16 implement the safe-harbours for mere conduit, caching and hosting intermediaries. Art. 17 prohibits general monitoring obligations and establishes notice-based actual knowledge for hosting providers. Sanctions are administrative pecuniary under Art. 21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecommerce-directive-2000-31",
      "eu-unfair-commercial-practices-2005-29-2022-revision",
      "it-d-lgs-206-2005-codice-del-consumo"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "it-legge-287-1990-antitrust",
    "title": "Italy Legge 287/1990 - Norme per la tutela della concorrenza e del mercato (Italian Antitrust Law)",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Legge 10 ottobre 1990 n. 287 (Norme per la tutela della concorrenza e del mercato) is Italy's principal national antitrust statute. The Law is structured in four Titoli: Titolo I covers restrictive agreements, abuse of dominant position and concentrations (Arts. 1-7); Titolo II establishes the Autorità Garante della Concorrenza e del Mercato (AGCM) with investigative and enforcement powers (Arts. 10-14); Titolo III addresses information-gathering and advisory functions (Arts. 21-24); Titolo IV addresses government powers regarding mergers in sectors of strategic interest. Art. 1 sets the scope - intese restrittive, abusi di posizione dominante and concentrazioni di imprese - and the principle of parallel application with TFEU Articles 101 and 102. Art. 2 prohibits restrictive agreements between undertakings. Art. 3 prohibits abuse of a dominant position. Arts. 5-7 govern merger control thresholds and notification. Art. 14 grants AGCM investigative powers including sectoral inquiries and dawn raids. Art. 15 provides for diffida (cease-and-desist) and pecuniary administrative sanctions up to 10 percent of the total worldwide annual turnover. Art. 33 establishes the civil jurisdiction for damages claims (follow-on and stand-alone), with competence allocated to specialised business sections of the Tribunals of Milan, Rome and Naples.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-gwb-competition-act",
      "us-sherman-antitrust-act-1890-sections-1-2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "it-perimetro-sicurezza-cibernetica-2019",
    "title": "Italy National Cybersecurity Perimeter - Decree-Law 105/2019",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Italy's Decree-Law No. 105 of 21 September 2019, converted into Law No. 133 of 18 November 2019, establishes a national cybersecurity perimeter identifying critical public and private operators whose networks and IT systems are essential to national security, requires operators within the perimeter to notify CSIRT Italia of incidents within the timeframes established by implementing DPCM according to incident severity, mandates ACN security assessments of ICT products and services procured for perimeter systems through the CVCN, and establishes procurement controls for critical communications infrastructure including 5G networks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/it-perimetro-sicurezza-cibernetica-2019.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-nis2-essential-important-entities-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "italy-adm-online-gambling-decree-88-2015",
    "title": "Italy ADM Online Gambling Framework - Legislative Decree 88/2015 and Consolidated Customs Act",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "Italy's Agenzia delle Dogane e dei Monopoli (ADM) regulates online gambling under Decree 88/2015, the Consolidated Customs and Monopolies Act (TULPS), and 2024 Riordino del gioco pubblico reforms: B2C licence holders pay 25% GGR tax for casino and poker, 22% for sports betting, must integrate with AAMS/ADM control system, and comply with mandatory responsible gambling measures including the Registro di Auto-Esclusione (national self-exclusion register).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "nist_csf",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "greece-hellenic-gaming-commission-law-4002-2011",
      "portugal-srij-online-gambling-decree-66-2015"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "italy-space-economy-framework-law-89-2025",
    "title": "Italy Space Economy Framework Law (Legge 89/2025)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2025-06-25",
    "bluf": "Italy's Space Economy Framework Law (Legge 13 giugno 2025, n. 89) was published in the Italian Official Gazette (Gazzetta Ufficiale) on 25 June 2025 (GU n. 146) and entered into force on the same date. The law establishes the institutional, regulatory, and economic framework for Italian space activities and represents Italy's first comprehensive national space statute. The Italian Space Agency (Agenzia Spaziale Italiana, ASI), already established under Decree-Law 138/1988, is reinforced as the central national authority for civilian space programmes under the law, with the Ministry of Enterprises and Made in Italy (MIMIT) as the political authority and the Prime Minister chairing the Inter-Ministerial Committee for Space Policies (COMINT) for inter-ministerial coordination.\n\nThe law establishes authorisation requirements for the conduct of space activities by Italian operators, defines liability allocation between operators and the State under the Outer Space Treaty 1967 and the Liability Convention 1972, and creates obligations for the registration of space objects in the Italian national registry consistent with the Registration Convention 1975. The law also creates space economy incentives, a national space technology roadmap, and security clearance regimes for sensitive space activities. The authorisation regime applies to launches of space objects, the operation of space objects, and re-entry operations conducted by Italian operators or from Italian territory or from facilities under Italian jurisdiction. Italy is an original Artemis Accords signatory (13 October 2020), and the law is aligned with European Union Space Programme Regulation 2021/696 and the European Space Agency framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967-article-i-freedom",
      "un-outer-space-treaty-1967-article-vi-state-responsibility",
      "eu-space-programme-regulation-2021-696",
      "artemis-accords-2020-lunar-governance"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "italy-testo-unico-immigrazione-286-1998-dgimmigrazione",
    "title": "Italy Consolidated Immigration Act D.Lgs 286/1998 - Permesso di Soggiorno and Decreto Flussi Framework",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Italy's Testo Unico sull'Immigrazione (D.Lgs 286/1998) is the primary statute governing entry, residence and expulsion of non-EU nationals. The Decreto Flussi sets annual work entry quotas. Non-EU workers need a nulla osta and work visa before entry, then obtain a permesso di soggiorno within 8 days of arrival. Long-term residents (5 years continuous) receive the permesso di soggiorno per soggiornanti di lungo periodo (EU long-term resident status). Law 189/2002 (Bossi-Fini) introduced the contratto di soggiorno linking residence directly to employment. Overstay without grounds triggers an administrative expulsion order.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "germany-residence-act-aufenthaltsgesetz-2004-bamf",
      "france-ceseda-code-entree-sejour-etrangers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "itar-compliance-workflow",
    "title": "ITAR Compliance Workflow",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The International Traffic in Arms Regulations (ITAR) control the export and temporary import of defense articles and defense services on the United States Munitions List (USML). Compliance is mandatory for all U.S. manufacturers, exporters, and brokers of defense articles to prevent unauthorized access by foreign persons and ensure national security integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ear-dual-use-export",
      "dfars-7012-defense-cyber",
      "nist-800-171-rev-3"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "itar-license-check",
    "title": "ITAR Export Control Logic",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Mandatory controls for the export, re-export, and brokering of defense articles, services, and technical data listed on the United States Munitions List (USML).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-cui",
      "cmmc-2-audit"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "itil-4-service-management-framework-2019",
    "title": "ITIL 4 Service Management Framework 2019 - Service Value System, Four Dimensions Model, Guiding Principles and 34 Management Practices",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ITIL 4 establishes a holistic service management framework requiring organizations to align service delivery with business value through the Service Value System (SVS), Four Dimensions Model, and 34 defined management practices. It applies to all organizations delivering services, particularly in digital and technology-driven environments, as defined in the core publication Section 2.3 and Section 4.3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "itil-4-service-value-system",
    "title": "ITIL 4 Service Value System - Service Management Framework for IT Service Delivery, Value Creation and Continual Improvement",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2024-05-22",
    "bluf": "ITIL 4 provides a flexible framework for technology and digital service management, centered on the Service Value System (SVS) which describes how organizational components and activities work together to facilitate value co-creation. The SVS, detailed in ITIL 4 Foundation Section 3, requires organizations to integrate Guiding Principles, Governance, the Service Value Chain, Practices, and Continual Improvement to transform opportunity/demand into value for stakeholders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-20000-service-mgt",
      "iso-22301-business-cont"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "itil-4-value-stream-mapping-workflow-practices",
    "title": "ITIL 4 Service Value Chain and Value Stream Mapping - Demand, Value Creation, Engage, Obtain/Build and Deliver/Support Activities for Workflow Optimisation",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This standard requires organizations to implement a structured service value chain model comprising six core activities-Plan, Improve, Engage, Design and Transition, Obtain/Build, and Deliver and Support-to optimize end-to-end workflows and ensure value co-creation with stakeholders. It applies to all service providers leveraging ITIL 4 for service management transformation, as defined in Section 4.5.1 of the ITIL 4 Foundation publication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "automation-bpmn-service-task",
      "automation-bpmn-error-boundary",
      "automation-bpmn-agent-handover",
      "kcs-evolve-loop"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "itil-v4-service-value-chain-workflows",
    "title": "ITIL 4 - Service Value Chain: Plan, Improve, Engage, Design, Obtain/Build, Deliver/Support Activities and Integration with Workflow Orchestration Practices",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "ITIL 4 Service Value Chain provides an operating model for the creation, delivery, and ongoing improvement of services through automated and interconnected workflows across six key activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "itu-ai-for-good-global-summit-framework-2023",
    "title": "ITU AI for Good Global Summit Framework 2023 - Connecting AI Innovators with Global Challenges: SDG-Aligned AI Use Cases, AI Repository, Neural Network Standards (ITU-T F.748 Series), National AI Capacity Building and IMT-2030 (6G) AI Integration",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This framework establishes a global platform for advancing AI innovation aligned with the UN Sustainable Development Goals (SDGs), facilitating collaboration among stakeholders through the AI for Good initiative. It promotes the development and deployment of trustworthy AI solutions via standards such as ITU-T F.748 Series, capacity building, and integration with future telecom networks including IMT-2030 (6G), though specific enforceable obligations or regulatory thresholds are not defined in the source document.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ai-agent-collision-logic",
      "eu-data-governance-act-2022-cloud-data-sharing",
      "3gpp-5g-nr-release-17-specifications"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "itu-e-212-mobile-country-network-codes",
    "title": "Recommendation ITU-T E.212: International identification plan for public networks and subscriptions",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This recommendation defines the structure and assignment principles for the International Mobile Subscriber Identity (IMSI), specifying the format for Mobile Country Codes (MCC) and Mobile Network Codes (MNC). It applies to national numbering plan administrators and mobile network operators worldwide to ensure unique subscriber identification and enable international roaming, as detailed in Clause 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itu-radio-regulations-2020-edition"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "itu-g-series-broadband-optical-access-standards",
    "title": "ITU-T G-Series Broadband and Optical Access Recommendations - G.984 GPON, G.9807 XGS-PON and G.9804 50G-PON Standards",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This series of ITU-T recommendations defines the physical layer and data link layer specifications for passive optical networks (PONs), ensuring interoperability for equipment manufacturers and network operators. The standards, including G.984 for GPON, G.9807 for XGS-PON, and G.9804 for 50G-PON, mandate specific protocols for transmission convergence, physical media dependent layers, and management to enable multi-vendor, high-speed fiber-to-the-home (FTTH) deployments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-57-key-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "itu-r-bt-2020-uhdtv",
    "title": "ITU-R BT.2020 (UHD)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulatory conformance with the ITU-R BT.2020 standard for Ultra High Definition (UHD) video mandates strict adherence to a comprehensive set of technical specifications. An asset’s spatial resolution must precisely match either 3840x2160 pixels or 7680x4320 pixels, presented with a required display aspect ratio of 16:9 and utilizing a progressive scan type. The colorimetry system is rigorously defined, requiring the exclusive use of ITU-R BT.2020 color primaries along with the corresponding ITU-R BT.2020 non-constant luminance matrix coefficients. While the specification’s native transfer characteristics are defined as ITU-R BT.2020 for standard dynamic range, high dynamic range (HDR) implementations must instead employ a compliant electro-optical transfer function, specifically SMPTE ST 2084 or ARIB STD-B67. Signal quantization is limited to a valid bit depth of either 10 or 12 bits per component. Acceptable digital video formats include chroma subsampling schemes of 4:2:0, 4:2:2, or 4:4:4. Finally, temporal resolution is restricted to an enumerated set of compliant frame rates: 23.976, 24, 25, 29.97, 30, 50, 59.94, 60, 100, 119.88, and 120 frames per second. Failure to satisfy any one of these interdependent criteria constitutes a definitive deviation from the BT.2020 UHD compliance framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itu-r-bt-709-hdtv"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "itu-r-bt-709-hdtv",
    "title": "ITU-R BT.709 (HDTV)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the foundational ITU-R Recommendation BT.709 mandates strict adherence to several key colorimetry and signal format parameters for high-definition television systems. Verification procedures confirm that video assets conform to the standard's specifications for color representation, beginning with the color primaries, which must precisely match the CIE 1931 xy coordinates defined for red (0.64, 0.33), green (0.3, 0.6), and blue (0.15, 0.06). Furthermore, the white point chromaticity must align with the D65 illuminant, corresponding to xy coordinates of 0.3127 and 0.329. The Opto-Electronic Transfer Function is audited against the specified piecewise function, requiring a linear segment slope of 4.5 for signal values below the 0.018 threshold, alongside a non-linear segment governed by a gamma curve exponent of 0.45 and a scale factor of 1.099. The derivation of luminance (Y') from R'G'B' components is also scrutinized, with required matrix coefficients of 0.2126 for red, 0.7152 for green, and 0.0722 for blue. Finally, technical encoding parameters are inspected; an asset's bit depth per channel must meet a minimum value of 8, and its chroma subsampling format must be one of the allowed values, either \"4:2:2\" for production or \"4:2:0\" for distribution, to ensure full system conformity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itu-r-bt-2020-uhdtv"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "itu-radio-regulations-2020-edition",
    "title": "ITU Radio Regulations 2020 Edition - Frequency Allocation Table, Interference Protection and Spectrum Use Coordination",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This international treaty, binding on ITU Member States, governs the global use of the radio-frequency spectrum and satellite orbits by establishing a detailed Table of Frequency Allocations (Article 5) and procedures for coordinating spectrum use to prevent harmful interference between radio stations of different countries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "450.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "itu-radio-regulations-2024-edition",
    "title": "ITU Radio Regulations 2024 Edition WRC-23 Outcomes Spectrum Allocation Coordination of Geostationary and Non-Geostationary Satellite Networks and Interference Resolution",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "The International Telecommunication Union Radio Regulations 2024 Edition incorporates outcomes of the World Radiocommunication Conference 2023 entering into force on 1 January 2025 as a binding international treaty organised in 4 volumes covering Volume 1 Articles 1 through 59 including Article 1 terms and definitions Article 5 frequency allocations Article 9 procedure for effecting coordination with or obtaining agreement of other administrations Article 11 notification and recording of frequency assignments Article 13 procedure for the application of the Radio Regulations Article 21 terrestrial and space services sharing frequency bands above 1 GHz Article 22 space services special provisions Article 44 satellite networks frequency assignments Article 56 secretariat duties and Article 59 entry into force, Volume 2 Appendices 1 through 47 including coordination procedures and notification forms, Volume 3 Resolutions and Recommendations including Resolution 32 streamlined satellite filing procedures Resolution 559 frequency assignment plans and Resolution 75 broadcasting satellite service plans, and Volume 4 ITU-R Recommendations incorporated by reference. The Regulations are administered by the ITU Radiocommunication Bureau and bind 193 ITU Member States in spectrum coordination satellite networks orbital slot management and interference dispute resolution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itu-radio-regulations-article-9-satellite-coord"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "itu-radio-regulations-article-9-satellite-coord",
    "title": "ITU Radio Regulations Article 9 - Procedure for effecting coordination with or obtaining agreement of other administrations",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation mandates the procedural framework for national administrations to coordinate satellite network frequency assignments with other administrations to prevent harmful interference before bringing them into use. As per Article 9, Section II, this involves submitting Advance Publication Information (API) and a formal Coordination Request (CR) to the ITU's Radiocommunication Bureau (BR) for publication and subsequent bilateral negotiations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itu-radio-regulations-2020-edition"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "itu-sg13-imt-2030-6g-framework-2023",
    "title": "Framework and overall objectives of the future development of IMT for 2030 and beyond",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This ITU-R Recommendation M.2160-0 (11/2023) establishes the framework and overall objectives for the future development of International Mobile Telecommunications (IMT) for 2030 and beyond, including 6G, focusing on usage scenarios, technical performance requirements, and spectrum considerations above 7 GHz. It applies to standardization bodies, network equipment vendors, service providers, and spectrum regulators involved in next-generation mobile systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "3gpp-5g-nr-release-17-specifications",
      "eu-5g-cybersecurity-toolbox-2020",
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-radio-spectrum-policy-programme-decision"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "itu-t-e164-numbering-plan",
    "title": "ITU-T E.164: The international public telecommunication numbering plan",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation defines the international public telecommunication numbering plan for global telephone number allocation, including country code assignments, national significant number (NSN) structure, and principles for number portability. It applies to all national and international telecommunication operators and numbering authorities under the authority of the ITU-T, as specified in E.164 (02/26).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "3gpp-5g-nr-release-17-specifications",
      "3gpp-ims-ip-multimedia-subsystem-release-16",
      "eu-eecc-2018-1972-electronic-communications-code"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "itu-x-1255-identity-management-framework",
    "title": "ITU-T X.1255 Framework for Discovery of Identity Management Information - Identity Federation and Attribute Exchange",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This recommendation specifies a framework for discovering identity management information, enabling entities to locate identity providers (IdPs) and determine their supported protocols and capabilities. It applies to service providers and identity providers seeking to establish interoperable identity federation and attribute exchange, as detailed in Clause 7's architectural model.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "coe-convention-108-plus"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "japan-act-premiums-misleading-representations-1962",
    "title": "Japan Act against Unjustifiable Premiums and Misleading Representations (Keihyo-ho 1962)",
    "domain": "Sales, Marketing & PR",
    "version": "Amended 2023",
    "last_updated": "2026-05-09",
    "bluf": "Japan's Act against Unjustifiable Premiums and Misleading Representations (景品表示法, Keihyo-ho, Law No. 134 of 1962, last amended 2023) prohibits misleading advertising claiming superior products or advantageous terms (Article 5), imposes surcharges of 3% of gross misleading sales (Article 10), mandates corrective advertising (Article 8), and caps premium offer values; enforced by the Consumer Affairs Agency (CAA) with civil and criminal penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-endorsement-guides-2023",
      "asa-advertising-codes-uk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "japan-ai-governance-guidelines-meti-2024",
    "title": "Japan AI Guidelines for Business 2024 (METI/MIC) - Voluntary Code for AI Developers and Operators, Risk Management Approach, Human Oversight, Transparency, Fairness, Privacy and Security Principles, Linkage with Hiroshima AI Process and G7 Code of Conduct",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "These voluntary guidelines issued by Japan's Ministry of Economy, Trade and Industry (METI) and Ministry of Internal Affairs and Communications (MIC) establish a risk-based governance framework for AI developers and operators, emphasizing human oversight, transparency, fairness, and privacy. Key obligations include implementing risk classification systems and public disclosure of AI usage, aligned with the G7 Hiroshima Process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-ai-safety-2023",
      "gri-305-emissions-2016",
      "australia-voluntary-ai-safety-standard-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "japan-ai-guidelines-meti-2024",
    "title": "AI Guidelines for Business 2024 - METI and Cabinet Office Principles: Transparency, Safety, Fairness and Accountability for AI Developers",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-04-19",
    "bluf": "These non-binding guidelines from Japan's METI and Cabinet Office establish ten core principles for all businesses developing, providing, or using AI, promoting a risk-based, human-centric approach. The guidelines, detailed in Chapter 2, require businesses to voluntarily implement measures ensuring safety, fairness, transparency, and accountability in line with the G7 Hiroshima AI Process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "g7-hiroshima-ai-process-2023",
      "oecd-ai-principles",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "iso-42001-transparency"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "japan-ai-strategy-fundamental-plan-2022",
    "title": "Japan Artificial Intelligence Strategy 2022 Fundamental Plan - Social Implementation Goals, AI Governance Framework and International Cooperation Strategy",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This strategy establishes Japan's national framework for the responsible development and deployment of AI, emphasizing human-centric design, transparency, and international alignment. It applies to public sector entities, private companies deploying AI systems in critical sectors, and research institutions involved in AI innovation, with key guidance outlined in Chapter 3 on AI Governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "asean-guide-ai-governance-ethics-2020",
      "australia-ai-ethics-framework-2019",
      "iso-42001-risk-assess",
      "iso-42001-transparency"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "japan-antimonopoly-act-2019-amendment-jftc",
    "title": "Act on Prohibition of Private Monopolization and Maintenance of Fair Trade (Amended by Act No. 54 of 2019) - Surcharge Calculation, Leniency and Japan Fair Trade Commission Procedures",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The 2019 amendment to Japan’s Antimonopoly Act (AMA) strengthens the Japan Fair Trade Commission’s (JFTC) authority to calculate surcharges for anticompetitive conduct, enhances leniency program transparency, and formalizes procedural rules for investigations and surcharge imposition. It applies to all enterprises engaged in unfair trade practices, cartels, or abuse of superior bargaining position under Article 2, Paragraph 9 and Article 7, Paragraph 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "japan-appi-2022-amended-personal-information",
    "title": "Act on the Protection of Personal Information (Act No. 57 of 2003, as amended 2022)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The 2022 amended APPI mandates that businesses report specific data breaches to Japan's Personal Information Protection Commission (PPC) and notify affected individuals, generally within 72 hours for the preliminary report to the PPC, as stipulated in Article 26. The amendment also introduces the concept of 'pseudonymously processed information', restricts opt-out third-party provisions, and expands extraterritorial application to foreign businesses handling personal data of individuals in Japan.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "jp-appi-2022",
      "gdpr-article-30-records-processing",
      "eu-standard-contractual-clauses-2021",
      "oecd-privacy-guidelines-2013"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "japan-appi-act-57-2003-personal-information-protection-ppc",
    "title": "Japan Act on Protection of Personal Information (APPI) - Act No. 57 of 2003 as Amended 2020/2021 - PPC Obligations and Cross-Border Transfer Rules",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Japan's APPI (Act No. 57 of 2003, with major 2015 and 2020 amendments effective April 2022) requires personal information handling businesses to specify and limit use of personal information to notified purposes, obtain consent for third-party provision, apply heightened protections to sensitive information, report breaches to the Personal Information Protection Commission (PPC) and affected persons, and conduct privacy impact assessments for cross-border transfers. Fines up to JPY 100M for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "japan-building-standards-act-1950",
    "title": "Japan Building Standards Act 1950 (Kenchiku Kijun-ho) - Construction Permit and Safety Framework",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Japan's Building Standards Act (Kenchiku Kijun-ho, Act No. 201 of 1950, most recently amended 2024) establishes the mandatory technical standards for building design and construction in Japan, requiring building permits (kensetsu kakunin) from Designated Confirmation Inspection Bodies (CABs), structural safety reviews by Registered Structural Engineers, and compliance with earthquake resistance (seismic), fire safety, and energy efficiency standards enforced by municipal building departments (kenchiku shido-ka) and MLIT (Ministry of Land, Infrastructure, Transport and Tourism).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-building-regulations-2010",
      "eu-energy-performance-buildings-directive-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "japan-building-standards-law-1950-structural-safety",
    "title": "Japan Building Standards Law 1950 - Structural Safety, Seismic Design, and Building Permit",
    "domain": "Construction & Real Estate",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Japan's Building Standards Law (建築基準法, Law No. 201 of 1950, extensively amended) sets minimum national standards for structural safety, fire prevention, and public health for all buildings in Japan. Key obligations: building confirmation (確認申請) mandatory before construction of structures ≥10m² or any Class 1-4 special structures; New Seismic Standard (新耐震基準) introduced 1981 requires buildings to resist an earthquake of seismic intensity 7 (震度7) without collapse; post-2000 structural calculation validation (構造計算適合性判定) required for high-rise ≥31m and special structures; Building Coverage Ratio (建蔽率 up to 80%) and Floor Area Ratio (容積率 up to 1,300%) set by zoning; window area minimum 1/7 of floor area for habitable rooms; legally-mandated periodic inspection (定期報告) every 1-3 years for special buildings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_framework",
        "regulatory_mapping",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-19650-bim-information-management",
      "eu-construction-products-regulation-305-2011"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "japan-cartagena-act-2003-lmo-regulation",
    "title": "Japan Cartagena Act 2003 - Law on Conservation of Biological Diversity through LMO Regulation",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Japan's Act on the Conservation and Sustainable Use of Biological Diversity through Regulations on the Use of Living Modified Organisms (Act No. 97 of 2003, amended 2022) implements the Cartagena Protocol domestically, requiring Type 1 Use Approval from the Competent Ministry for open environmental use of LMOs and Type 2 Use Confirmation for contained laboratory/industrial use, with biodiversity risk assessment as the core evaluation criterion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "brazil-ctnbio-biosafety-law-11105-2005"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "japan-consumer-contract-act-2000-caa",
    "title": "Japan Consumer Contract Act 2000 - Consumer Protection, Unfair Terms and Consumer Affairs Agency Enforcement",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Japan's primary consumer protection statute, the Consumer Contract Act (Law No. 61 of 2000, CCA, substantially amended 2022 and 2023) administered by the Consumer Affairs Agency (CAA - Shohi-sha-cho) renders void unfair contractual terms in consumer contracts and grants consumers cancellation rights when they have been induced to enter a contract by a business's fraudulent representation or coercive sales tactics; voids blanket disclaimer clauses, unconscionable penalty clauses (penalties exceeding average anticipated damages), and terms that unilaterally deny business operator liability for wilful misconduct; the 2022 amendments introduced a right to cancel subscriptions with excessive psychological pressure tactics; CAA may issue improvement recommendations (kankouku) and disclosure orders against businesses with systemic unfair contract practices; consumer rescission must be exercised within 6 months of discovering grounds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-consumer-protection-from-unfair-trading-2008"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "japan-copyright-act-2023-ai-amendment",
    "title": "Copyright Act of Japan - Amendment Relating to Text and Data Mining for Artificial Intelligence Development (Act No. 57 of 2023), Article 30-4",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Japan Copyright Act 2023 AI Amendment (Article 30-4) permits text and data mining (TDM) of copyrighted works for AI training without rights holder permission, provided the use is for non-enjoyment purposes and the data is not retained or used for direct public dissemination. Applies to AI developers, research institutions, and commercial entities using copyrighted material for machine learning model training.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-1886-2024-literary-artistic-works",
      "copyright-fair-use-us",
      "eu-copyright-directive-art-17",
      "c2pa-content-provenance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "japan-economic-security-promotion-act-2022",
    "title": "Act on the Promotion of Ensuring National Security through Integrated Economic Measures (Economic Security Promotion Act)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This act requires designated operators of Japan's specified critical infrastructure to submit plans for equipment installation or outsourcing of maintenance services for prior government review to mitigate external threats like cyberattacks, as mandated by Chapter 3, Article 50. It also establishes frameworks for securing critical supply chains, non-disclosing sensitive patents, and supporting advanced technology R&D.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "c-scrm-practices-systems-organizations",
      "nis2-supply-chain-security-article-22",
      "eu-critical-entities-resilience-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "japan-electricity-business-act-1964-meti",
    "title": "Japan Electricity Business Act 1964 (Law No. 170) - METI Liberalisation and Grid Neutrality",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Japan's Electricity Business Act (Law No. 170 of 1964, revised through 2023) establishes METI-supervised electricity market liberalisation with full retail liberalisation since 2016; requires grid neutrality and non-discriminatory wheeling access; mandates registration as a General Electricity Transmission and Distribution Business (GTDB) or Electricity Retail Business; and imposes reporting and supply security obligations to the Electricity and Gas Market Surveillance Commission (EGSC).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electricity-directive-2019-944",
      "us-ferc-pro-forma-oatt-open-access-transmission"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "japan-food-labelling-act-2013-standards",
    "title": "Act on Fair Labelling and Advertising of Food, Fibre and Other Consumer Products (Food Labelling Act) - Standards for Labelling of Processed Foods, Nutrition, Health Claims, and Organic JAS Foods",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The Japan Food Labelling Act 2013 mandates standardized labelling of processed foods, including product name, ingredients, additives, allergens, best-before date, preservation method, and nutrition information. It applies to all manufacturers, importers, and distributors of food products sold in Japan under Article 4 and Article 6 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-food-labelling-regulation-1169-2011",
      "brc-food-safety-global"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "japan-food-sanitation-act-2021-amendment-food-contact",
    "title": "Food Sanitation Act - Positive List for Food Contact Materials: Permitted Substances for Synthetic Resins, Labelling of Utensils and Containers, HACCP Mandatory for All Food Businesses and Manufacturer Self-Declaration System",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes requirements for food contact materials, including permitted substances in synthetic resins and labelling of utensils and containers, under the Food Sanitation Act framework. It mandates HACCP-based hygiene management for all food businesses and a manufacturer self-declaration system. Key provisions are governed by the Food, Additives, etc. Standards, with enforcement transferred to the Consumer Affairs Agency as of April 1, 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "iso-13009-beach-mgmt",
      "ada-hospitality-access",
      "alcohol-service-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "japan-immigration-control-refugee-recognition-act-isa",
    "title": "Japan Immigration Control and Refugee Recognition Act - ISA and Residency Framework",
    "domain": "Immigration & Border Control",
    "version": "3.0",
    "last_updated": "2026-05-10",
    "bluf": "The Immigration Control and Refugee Recognition Act (ICRRA, Act No.319 of 1951, as substantially amended in 2023) is Japan's primary immigration statute, governing entry, residence status, and deportation of all foreign nationals. The Immigration Services Agency of Japan (ISA), established in 2019 within the Ministry of Justice, administers 29 residence status categories. The 2023 amendments introduced a new third-country safety assessment for asylum seekers and revised the deportation stay rule to prevent indefinite detention. Japan requires biometric registration (fingerprints and facial photograph) for all foreign nationals aged 16 or above at ports of entry. Employment of foreign nationals without proper residence status carries penalties of up to 3 years imprisonment under Art.73-2. The Specified Skilled Worker (SSW) programs (i-gino jisshu) introduced in 2019 allow workers in 14 specified industries to work for up to 5 years without family reunification (SSW Type 1) or with family and permanent renewal rights (SSW Type 2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "unhcr",
        "icao_doc",
        "asean",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "japan-integrated-resort-ir-implementation-act-2018-cac",
    "title": "Japan Integrated Resort Implementation Act 2018 - Casino Administration Committee (CAC) Framework",
    "domain": "Gaming & Gambling",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Japan's Act on Development of Specified Complex Tourist Facilities Areas (Integrated Resort Implementation Act, Act No. 80 of 27 July 2018) introduced a tightly restricted casino-within-resort model, permitting a maximum of three Integrated Resort (IR) licences nationwide. The Casino Administration Committee (CAC - Casino Kanri Iinkai), an independent administrative commission under the Cabinet, is the national casino regulator. The IR framework imposes unique consumer protection measures applicable specifically to Japanese nationals and residents: an admission fee of JPY 6,000 per visit, a visit frequency cap of 3 visits per 7 days and 10 visits per 28 days, and mandatory self-exclusion mechanisms. Casino floor area is capped at 3% of total IR floor area. Minimum IR investment is set at a scale befitting the world's largest hospitality complexes, with Osaka receiving the only licence issued as of 2024. AML obligations, strict gaming equipment approval, and financial monitoring by the CAC are mandatory. Foreign visitors are exempt from the admission fee and visit frequency restrictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "aml",
        "fatf_recommendation",
        "tourism_policy",
        "prefectural_law",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "japan-ir-implementation-act-2018",
    "title": "Act on Integrated Resort Facilities and Related Measures (Integrated Resort Implementation Act) 2018",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Japan Integrated Resort (IR) Implementation Act 2018 establishes a legal framework for the operation of casino-integrated resorts in Japan, requiring strict licensing, anti-money laundering controls, and comprehensive problem gambling countermeasures under Article 15 and Chapter 3. It applies to IR operators, casino service providers, and local governments designated as host regions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l3"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "japan-pmda-pharmaceutical-affairs-law",
    "title": "Japan Pharmaceutical and Medical Device Act (PMDA) - Drug Approval: Clinical Trial Notification, PMDA Consultation, Approval Review, Manufacturing Site Registration, GMP Conformity Assessment and Post-Marketing Vigilance",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation governs the approval pathway for pharmaceuticals in Japan, requiring clinical trial notifications, PMDA consultation, manufacturing site registration, GMP conformity assessment, and post-marketing safety vigilance. Key obligations are derived from PMDA safety updates and review procedures as of April 2026, including revisions to precautions for infliximab and biosimilars.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-312-ind-investigational-new-drug",
      "fda-21-cfr-part-314-nda-new-drug-application",
      "ich-q10-pharmaceutical-quality-system-2008",
      "eu-gmp-annex-1-sterile-manufacture-2022",
      "fda-biosimilar-pathway-351k-biologics-competition-act"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "japan-pmda-samd-ai-guidelines-2026",
    "title": "Japan PMDA - Software as a Medical Device (SaMD) and AI Medical Device Guidelines (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The Pharmaceuticals and Medical Devices Agency (PMDA) regulates Software as a Medical Device (SaMD) and AI/ML-based medical devices under the Pharmaceutical and Medical Device Act. Requirements include risk classification (Class I-IV), clinical evaluation, cybersecurity, quality management (aligned with JIS Q 13485), and continuous post-market surveillance with change management protocols for adaptive AI models.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "japan-road-freight-transport-business-act-1989",
    "title": "Japan Road Freight Transport Business Act 1989 (Law 83) - MLIT Licensing and 2024 Hours Reform",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Japan's Road Freight Transport Business Act (Law No. 83 of 1989, Unchugyoho) administered by the Ministry of Land, Infrastructure, Transport and Tourism (MLIT) regulates road freight business licensing; the 2024 Problem (2024nen mondai) introduced mandatory overtime caps for truck drivers at 960 hours per year effective 1 April 2024; the Act mandates general truck business licences (ippan truck unso jigyo) for commercial freight carriers; and imposes delivery time standards under the revised Physical Distribution Efficiency Act 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mobility-package-i-road-transport-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "japan-road-traffic-act-autonomous-vehicles",
    "title": "Road Traffic Act Amendment (Act No. 32 of Reiwa 4) - Establishment of Licensing System for Specific Automated Driving at SAE Level 4",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes a licensing framework for SAE Level 4 automated driving systems operating without a driver present, requiring operators to obtain permission from prefectural public safety commissions under the amended Road Traffic Act. Key obligations include compliance with operational conditions, remote monitoring capability, and incident reporting. Primary authority: Road Traffic Act, as amended by Act No. 32 of Reiwa 4, effective April 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sae-j3016-levels-driving-automation-2021",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "germany-autonomous-driving-law-2021-stvaendg",
      "china-intelligent-connected-vehicle-regulations-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "japan-road-transport-vehicle-act-1951",
    "title": "Japan Road Transport Vehicle Act 1951 - Type Approval, Vehicle Inspection (Shaken), and Recall Procedures",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2022-05-18",
    "bluf": "Japan's Road Transport Vehicle Act (Law No. 185 of 1951, as amended 2022) requires MLIT type approval for all vehicle models, biennial roadworthiness inspections (shaken) from year 3, mandatory recall notification within 30 days of defect discovery, and special type approval procedures for electric vehicles and fuel cell vehicles under the 1998 WP.29 Global Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "nist_csf",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unece-r48-installation-lighting-signalling-devices-2016",
      "unece-r51-03-acoustic-noise-motor-vehicles-2016"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "japan-space-activities-act-2016",
    "title": "Japan Act on Launching of Spacecraft and Control of Spacecraft 2016 (Space Activities Act)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Japan's Space Activities Act (Act No. 76, 2016), in force November 2018, establishes a licensing regime for commercial satellite launches and spacecraft control operations from Japan, imposes strict third-party liability on operators with government indemnification above the operator's insurance ceiling, and aligns Japan's national space activities framework with its obligations under the Outer Space Treaty, Liability Convention, and Registration Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "liability_convention_1972",
        "registration_convention"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "japan-space-resources-act-2021-business-activities-exploration",
    "title": "Japan Act on Promotion of Business Activities Related to Exploration and Development of Space Resources (2021)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2021-12-23",
    "bluf": "Japan's Act on Promotion of Business Activities Related to Exploration and Development of Space Resources (Act No. 83 of 2021), commonly known as the Space Resources Act, came into force on 23 December 2021 and provides Japanese companies with a legal framework to obtain ownership rights over space resources extracted in outer space. Japan became the fourth nation (after the United States, Luxembourg, and the United Arab Emirates) to enact a national space resources law. The Act is administered by the Cabinet Office in coordination with the Ministry of Economy, Trade and Industry (METI) and is consistent with Japan's obligations under the Outer Space Treaty 1967.\n\nThe Act requires Japanese business operators conducting space resource exploration or development to obtain a permit from the Prime Minister under Article 3. The permit is granted upon submission of a business plan that includes the location, schedule, methods, and safety measures for the proposed activity. The Prime Minister, in consultation with relevant ministers, evaluates whether the activity will be conducted appropriately and safely and in conformity with Japan's international obligations including the Outer Space Treaty. Once a permit is granted, the operator acquires ownership of the space resources actually mined or obtained, provided that they are extracted in accordance with the permit. The Act is intended to support Japan's commercial space resources industry and aligns Japan with the principles of the Artemis Accords, of which Japan was an original signatory in October 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967-article-i-freedom",
      "artemis-accords-2020-lunar-governance",
      "luxembourg-space-resources-law-2017",
      "us-commercial-space-launch-competitiveness-act-2015-space-resources"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "jct-design-build-contract-2016",
    "title": "JCT Design and Build Contract 2016",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The JCT Design and Build Contract 2016 is a standard form UK construction contract where the contractor is responsible for both the design and construction of the works. It requires the contractor to complete the project in accordance with the Employer's Requirements and Contractor's Proposals, culminating in the certification of Practical Completion (Clause 2.27), which triggers the start of the Rectification Period and release of retention monies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pmbok-7-guide-pm",
      "icc-arbitration-rules-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "je-dp-law-2018",
    "title": "Jersey Data Protection (Jersey) Law 2018 - JOIC",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Jersey's Data Protection (Jersey) Law 2018, which came into force on 25 May 2018 (the same date as the EU General Data Protection Regulation), is Jersey's primary personal data protection legislation establishing a GDPR-equivalent rights-based framework for the protection of personal data. Jersey is a Crown Dependency of the United Kingdom and a self-governing jurisdiction that is not a member of the European Union or subject to the UK Data Protection Act 2018; however, Jersey has historically aligned its data protection framework with EU standards to maintain EU and UK adequacy recognition critical to Jersey's status as a leading international financial centre. Jersey received a European Commission adequacy decision recognising Jersey as providing adequate data protection for the purposes of international data transfers from the EU, and has been similarly recognised under the UK GDPR post-Brexit framework. The supervisory authority is the Jersey Office of the Information Commissioner (JOIC), an independent institution responsible for oversight, enforcement, and guidance on data protection and freedom of information in Jersey. Key features of Jersey's Data Protection (Jersey) Law 2018: (1) Scope - applies to personal data processing by controllers established in Jersey or processing personal data of data subjects in Jersey; (2) Data processing principles - processing must comply with: lawfulness; transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right to data portability; and right not to be subject to solely automated decisions; (6) Data Protection Officer - required for public authorities and organisations conducting large-scale systematic processing or processing sensitive data at scale; (7) Breach notification - controllers must notify the JOIC within 72 hours of becoming aware of a qualifying personal data breach; (8) Data Protection Impact Assessment - required for high-risk processing; (9) Cross-border transfers - personal data may only be transferred outside Jersey where adequate protection or appropriate safeguards exist; and (10) Administrative fines - the JOIC may impose significant fines for violations. Jersey's GDPR-equivalent framework and EU adequacy recognition underpin its position as a leading international financial and trust services centre.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-retained-gdpr",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "jm-dpa-2020",
    "title": "Jamaica Data Protection Act 2020 - OIC",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Jamaica's Data Protection Act 2020 (Act No. 5 of 2020), passed by the Parliament of Jamaica on 8 December 2020 and brought into force in stages with the substantive data protection provisions taking effect from 8 December 2023, is Jamaica's primary personal data protection legislation establishing a comprehensive rights-based framework for the protection of personal data. Jamaica is a Commonwealth country whose legal system is based on English common law; the Data Protection Act was developed with reference to international data protection standards including the EU General Data Protection Regulation and the OECD Privacy Guidelines. The supervisory authority is the Office of the Information Commissioner (OIC), an independent statutory body whose mandate under the Data Protection Act covers enforcement, guidance, and promotion of data protection standards in Jamaica. Key features of Jamaica's Data Protection Act 2020: (1) Scope - applies to personal data processing by public authorities, companies, and individuals established in Jamaica or processing personal data in relation to Jamaica residents; (2) Data processing principles - processing must comply with: lawfulness; transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or similar beliefs; physical or mental health condition; sexual life; commission or alleged commission of offences; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right to data portability; and right not to be subject to solely automated decisions; (6) Data Protection Officer - required for certain categories of controller; (7) Breach notification - controllers must notify the OIC of personal data breaches without undue delay and where feasible within 72 hours; high-risk breaches require data subject notification; (8) Privacy Impact Assessment - required for processing likely to result in high risk; (9) Cross-border transfers - personal data may only be transferred outside Jamaica where the recipient country provides adequate protection or appropriate safeguards are in place; and (10) Penalties - administrative and criminal penalties for violations. Jamaica's Data Protection Act reflects the Caribbean region's growing adoption of comprehensive data protection frameworks aligned with international standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "jm-public-procurement-act-2015-effective-2018-ojpp-eppgov",
    "title": "Jamaica Public Procurement Act 2015 effective 1 April 2019 and the Office of Public Procurement Policy",
    "domain": "Public Sector & Government Procurement",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The Jamaica Public Procurement Act 2015 (Act 11 of 2015) effective 1 April 2019 as amended by the Public Procurement (Amendment) Act 2018 (Act 22 of 2018) and supplemented by the Public Procurement Regulations 2018 (LN 142A of 2018), is the principal Jamaican statute governing procurement of goods, works, services, and consulting services by public bodies including ministries, government departments, executive agencies, public companies, statutory bodies, parish councils and local authorities, public-sector universities, and other entities financed wholly or partly from the Consolidated Fund or other public funds. The 2015 Act replaced the prior Public Procurement Procedures Handbook (administrative-only) framework and established a comprehensive statutory regime aligning with international best practice including the UNCITRAL Model Law on Public Procurement. The Office of Public Procurement Policy (OPPP / procureja.gov.jm) within the Ministry of Finance and the Public Service (mof.gov.jm) is the central regulatory authority responsible for procurement regulation, oversight, supplier debarment, and procurement guidance. The Government of Jamaica Electronic Procurement Portal (gojeprocure.gov.jm) operated by OPPP is the federal e-procurement platform. The Public Procurement Commission (PPC) handles procurement complaints. Procurement methods established by Public Procurement Act 2015 sec. 30 to 56 comprise (a) Open Bidding (the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Selective Bidding (with prequalification, formerly known as Two-Stage Bidding), (c) Limited Bidding (restricted to invited suppliers under prescribed exceptions), (d) Direct Contracting (sole-source under prescribed exceptions in sec. 39 including emergency, sole supplier for technical reasons, prior failed bidding, additional procurement under existing contract, and prescribed-class exemptions), (e) Request for Quotations (for medium-value goods and services), (f) Request for Proposals (for consulting services), (g) Procurement by Outsourcing (for prescribed service categories), (h) Framework Agreement, and (i) Electronic Reverse Auction. The Auditor-General of Jamaica conducts ex-post procurement audit. The Major Organised Crime and Anti-Corruption Agency (MOCA) has investigative jurisdiction over procurement-related corruption. Jamaica is a party to CARICOM CSME, AfCFTA observer, and UNCAC. Jamaica is NOT a party to the WTO Government Procurement Agreement (GPA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "jm-dpa-2020",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "jo-government-procurement-bylaw-2019-jonepps",
    "title": "Jordan Government Procurement Bylaw No. 28 of 2019 (Nidham al-Mushtarayat al-Hukumiyya) and the JONEPPS Electronic Procurement Platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Jordan Government Procurement Bylaw No. 28 of 2019 (Nidham al-Mushtarayat al-Hukumiyya raqm 28 li-sanat 2019, in Arabic) issued by Council of Ministers Decision and published in the Official Gazette No. 5566 of 1 March 2019, effective 1 January 2020, is the principal Jordanian regulatory framework governing procurement of goods, services, and works by ministries, public departments, public institutions, government units, and other public entities financed by the State budget. The 2019 Bylaw replaced the prior Government Supplies By-Law No. 32 of 1993 (for goods and services) and the Government Tenders By-Law No. 71 of 1986 (for works) and consolidated the Jordanian procurement framework into a unified regime. The Government Procurement Department (GPD, Da'irat al-Lawazim al-Aamma) within the Ministry of Finance is the central procurement policy authority. The Jordan Online E-Procurement System (JONEPPS / jonepps.jo) operated by the GPD is the federal e-procurement platform. Procurement methods established by the 2019 Bylaw comprise (a) Open Tender (Munaqasa Aamma, the default open public tender), (b) Limited Tender (Munaqasa Mahduda, with prequalification or restricted to pre-approved suppliers), (c) Local Tender (Munaqasa Mahalliyya, restricted to local Jordanian suppliers in prescribed circumstances), (d) Direct Procurement (Shira'a Mubasher, sole-source under prescribed exceptions including emergency, sole supplier for technical reasons, prior failed tendering, and small-value below thresholds), (e) Two-Stage Tender (for complex acquisitions), (f) Framework Agreement (Ittifaq Itari), and (g) Reverse Auction (Mazaad Aksi for prescribed items). The 2019 Bylaw introduced strengthened integrity provisions including supplier debarment under Article 49, anti-corruption commitments, conflict of interest disclosure, and beneficial ownership disclosure. The Audit Bureau (Diwan al-Muhasaba) and the Integrity and Anti-Corruption Commission (JIACC, Hayat al-Nazaha wa Mukafaha al-Fasad) have audit and integrity oversight. Jordan is NOT a party to the WTO Government Procurement Agreement (GPA) but is an observer. Jordan is a party to the Greater Arab Free Trade Area (GAFTA), the US-Jordan Free Trade Agreement (2001), the EU-Jordan Association Agreement (2002), and the UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "jo-pdpl-2023",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "jo-pdpl-2023",
    "title": "Jordan Personal Data Protection Law No. 24 of 2023 - MODEE",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Jordan's Personal Data Protection Law No. 24 of 2023 - published in the Official Gazette of the Hashemite Kingdom of Jordan and entering into force in 2023 - is Jordan's first comprehensive personal data protection legislation, establishing a rights-based framework for the protection of personal data in Jordan and positioning the Hashemite Kingdom as a data-secure jurisdiction in the Middle East and North Africa (MENA) region. Oversight of digital economy policy including data protection falls within the mandate of the Ministry of Digital Economy and Entrepreneurship (MODEE), which leads Jordan's digital transformation agenda including e-government, digital services, and technology sector regulation. Key features of Jordan's Personal Data Protection Law No. 24 of 2023: (1) Scope - applies to data controllers established in Jordan or processing personal data of individuals in Jordan regardless of the controller's location; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability; (3) Sensitive personal data - enhanced protection is required for: racial or ethnic origin; political opinions; religious or philosophical beliefs; health data; sexual orientation; genetic data; biometric data used for unique identification; and criminal history; (4) Lawful processing conditions - processing is permitted on grounds including: data subject consent; contractual necessity; legal obligation; vital interests; public interest; and legitimate interests where not overriding data subject rights; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restrict processing; right to data portability; right to object; and right not to be subject to solely automated decisions with significant effects; (6) Data Protection Officer - required for controllers conducting large-scale or systematic processing of personal data including processing of sensitive personal data; (7) Breach notification - controllers must notify the relevant authority of personal data breaches adversely affecting the rights of data subjects; (8) Cross-border transfers - personal data transfers outside Jordan require that the destination country provides an adequate level of protection or that approved safeguards are in place; (9) Enforcement - administrative fines and sanctions for violations of the law; (10) E-government context - Jordan's extensive e-government infrastructure (Jordan e-Government Gateway, digital services) processes significant personal data subject to the law. Jordan's data protection framework supports the National Digital Transformation Strategy and Jordan's aspirations for increased foreign direct investment in the technology and digital economy sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "jorc-code-2012-australasian-mineral-resources-reporting",
    "title": "JORC Code 2012 - Australasian Joint Ore Reserves Committee Mineral Reporting Standard",
    "domain": "Mining & Natural Resources",
    "version": "2012 Edition",
    "last_updated": "2026-05-09",
    "bluf": "The JORC Code (2012 Edition) is the mandatory Australasian standard for public reporting of Exploration Results, Mineral Resources, and Ore Reserves; it mandates a three-category resource classification (Inferred, Indicated, Measured) and two-category reserve classification (Probable, Proved) reported only by a qualified Competent Person with five or more years of relevant experience.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "samrec-code-south-africa-mineral-reporting",
      "irma-standard-responsible-mining-v1"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "jordan-data-protection-personal-data-law-2023",
    "title": "Jordan Personal Data Protection Law 2023",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Personal Data Protection Law No. (24) of 2023 establishes a comprehensive framework for the protection of personal data in Jordan, requiring data controllers to obtain informed consent, implement appropriate security measures, notify affected data subjects of a breach within 24 hours and the enforcement Unit within 72 hours, and comply with conditions for cross-border data transfers. The law establishes a Personal Data Protection Council within the Council of Ministers, chaired by the Minister of Digital Economy and Entrepreneurship, supported by an enforcement Unit. Key obligations are derived from the law's core data processing principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-confidentiality",
      "aicpa-soc2-cc-privacy",
      "aicpa-soc2-cc-processing-integrity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "jp-accounting-act-local-autonomy-act-government-procurement-framework",
    "title": "Japan Accounting Act (Kaikei-ho, Act No. 35 of 1947) + Local Autonomy Act + Government Procurement Framework",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Japanese government procurement legal framework is anchored on the Accounting Act (Kaikei-ho, Act No. 35 of 1947) which sets the principal rules for national government contracts including procurement of goods, services, and construction works, and the Local Autonomy Act (Chiho Jichi-ho, Act No. 67 of 1947) which sets the parallel rules for prefectural and municipal government contracts. The Accounting Act is supplemented by the Cabinet Order on the Budget, Auditing of Accounts and Accounting (Budget Auditing and Accounting Cabinet Order) and the Ministerial Ordinance on the Budget, Auditing of Accounts and Accounting which provide the operational procurement procedures. The principal procurement methods specified in the Act are general competitive tendering (the default method under Article 29-3 of the Accounting Act), designated competitive tendering (limited to a designated supplier set), and negotiated contracts (sole-source justified under prescribed exceptions in Article 29-3). The framework intersects multiple supporting regimes including the Act on Promotion of Quality Assurance in Public Works (Public Works Quality Assurance Act, 2005, amended 2014 and 2019) which sets supplemental rules for public works procurement, the Act on the Promotion of Subcontracting Small and Medium Enterprises which sets SME participation preferences, the Act on Special Measures for Strengthening Public Procurement of Recycled Articles (Green Purchasing Law, 2000) which sets the green procurement framework, and the Act on Public Records Management for the records management dimension. The central oversight for national procurement is provided by the Board of Audit of Japan (an independent constitutional body), the Cabinet Office and the Ministry of Internal Affairs and Communications for general procurement policy, and the Ministry of Finance for budget execution. Japan is a party to the WTO Agreement on Government Procurement (GPA 2012) and the various bilateral free trade agreements government procurement chapters. Japan's procurement framework is decentralised across ministries and agencies with each conducting its own procurement subject to the Accounting Act and the Cabinet Office guidance; central electronic procurement is operated through the e-procurement system shared across ministries with sectoral variations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "jp-ai-guidelines-2024",
    "title": "AI Guidelines for Business 2024 - Hiroshima AI Process Friendly Framework",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-04-19",
    "bluf": "These voluntary guidelines from Japan's METI and MIC provide a risk-based, agile framework for all businesses developing, providing, or using AI. They establish ten core principles, outlined in Chapter 2 'Common Guiding Principles for All AI Actors', including safety, fairness, and transparency, to encourage innovation while managing societal and economic risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "unesco-ethics-ai"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "jp-antimonopoly-act-1947",
    "title": "Japan Act on Prohibition of Private Monopolization and Maintenance of Fair Trade 1947 (Antimonopoly Act, Act No. 54)",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Act on Prohibition of Private Monopolization and Maintenance of Fair Trade 1947 (Dokusen Kinshi-hō, Act No. 54 of 1947, commonly referred to as the Antimonopoly Act or AMA) is Japan's principal competition law, administered by the Japan Fair Trade Commission (JFTC). Article 3 contains the core prohibition: no entrepreneur shall effect private monopolization or unreasonable restraint of trade. Private monopolization (shiteki dokusen) under Article 2(5) means business activities where an entrepreneur, individually or by combination or conspiracy, excludes or controls the business activities of other entrepreneurs, thereby causing a substantial restraint of competition in any particular field of trade. Unreasonable restraint of trade (futōna torihiki seigen) under Article 2(6) covers concerted conduct among entrepreneurs that substantially restrains competition in a particular field of trade, including price-fixing, volume restriction, market allocation, and bid-rigging. Article 19 prohibits unfair trade practices, which include discriminatory treatment, unreasonable trading conditions, resale price maintenance, and abuse of superior bargaining position. Article 7-2 imposes a mandatory surcharge (kasen-kin) on entrepreneurs who engage in cartel conduct, calculated as a percentage of sales (typically 10% for manufacturers, 3% for retailers) for the duration of the violation. Merger regulation is provided under Article 15 (absorption mergers) and Article 16 (business acquisitions), with the JFTC having authority to issue cease-and-desist orders against mergers that substantially restrain competition. The 2019 amendment strengthened the JFTC's investigation powers and introduced a leniency programme revision with immunity and reduction provisions for cartel applicants.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tfeu-article-102-abuse-of-dominance",
      "us-ftc-act-section-5-unfair-competition"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "jp-appi-2022",
    "title": "Act on the Protection of Personal Information (APPI) as amended in 2022",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The amended Japanese APPI imposes stricter obligations on businesses handling personal information of Japanese residents, including mandatory data breach reporting to the Personal Information Protection Commission (PPC) and affected individuals (Article 26), and expands data subject rights to include disclosure of third-party transfer records and the right to request cessation of use or deletion in more situations (Article 35).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-800-122-pii",
      "korea-pipa-standard"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "jp-appi-amendments-2024-triennial-review-interim-report",
    "title": "Japan APPI Amended Order and Rules 2024 - Two-Stage Breach Reporting to PPC and Triennial Review Interim Report of 27 June 2024",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Business operators subject to Japan's Act on the Protection of Personal Information (APPI) must, under the amended Order and Rules, report data breaches and notify affected individuals where the breach involves sensitive personal information, risk of property damage, an improper-purpose breach such as a cyberattack, or more than 1,000 affected data subjects, using a two-stage process of a preliminary report promptly after recognition and a final report within 30 days (60 days for improper-purpose breaches), and must obtain principals' prior consent for personal data transfers to third parties outside Japan unless the recipient country is on the PPC adequacy list or the recipient maintains an equivalent data protection system, while the Personal Information Protection Commission's Interim Report on the Triennial Review of the APPI released on 27 June 2024 outlines further amendments under consideration for 2024-2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "jp-banking-act-1981",
    "title": "Japan Banking Act (Act 59 of 1981) - Licensing Supervision and Resolution of Banks",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Banking Act of Japan requires entities carrying on banking business in Japan to obtain a license from the Prime Minister with the function delegated to the Financial Services Agency, imposes prudential and conduct standards including capital and liquidity requirements, restricts ownership of major shareholdings without approval, requires accurate and timely disclosures, authorises the FSA to conduct on-site and off-site inspection, gives the FSA powers of administrative orders, business improvement orders, and license revocation, and supports the Deposit Insurance Corporation of Japan in protecting depositors of failed banks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "jp-companies-act-2005"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "jp-basic-space-act-2008",
    "title": "Basic Space Act (Act No. 43 of 2008)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Japan's Basic Space Act sets the framework for the nation's space development and use. Outer space development and use must be conducted in accordance with treaties and other international agreements concerning outer space, including the Outer Space Treaty, in line with the pacifist principles of the Constitution of Japan (Article 2). The Act directs that space development strengthen the technical competence and international competitiveness of Japan's space and other industries (Article 4), requires the national government to promote space development to contribute to Japan's national security (Article 14), requires the government to establish a Basic Plan for space development and use (Article 24), and establishes the Outer Space Development Strategy Headquarters under the Cabinet (Article 25). It applies to national policies on Japan's space development and use.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "jp-companies-act-2005",
    "title": "Japan Companies Act 2005 (Act No. 86 of 2005, Kaisha-hō) - Corporate Governance",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Companies Act 2005 (Act No. 86 of 2005, Kaisha-hō, enforced 1 May 2006) is Japan's primary legislation governing the formation, administration, and dissolution of stock companies (kabushiki-kaisha, KK), limited liability companies (gōdō-kaisha), and other corporate forms. Article 355 imposes the director's duty of loyalty: directors must comply with applicable laws, regulations, and articles of incorporation, and carry out their duties faithfully for the benefit of the stock company. Article 330 incorporates by reference the Civil Code mandate provisions, imposing a duty of care on directors to act in the manner of a prudent manager. Article 362 establishes the board of directors' responsibility to decide important management matters and to supervise director performance, and mandates that directors report to the board on the progress of their duties at least once every three months. Article 423 imposes liability on directors who violate their duties of loyalty or care; directors who cause the company to suffer damages are jointly and severally liable to the company for those damages. Article 429 extends liability to third parties damaged by a director's failure to act in good faith or without gross negligence. Article 847 provides for shareholder derivative suits, permitting shareholders holding at least 1% of votes (or 300 shares) for 6 or more months to demand the company institute legal proceedings against directors on its behalf. The 2019 amendment (Act No. 70 of 2019) introduced mandatory compensation clawback rules for listed companies, electronic general meeting provisions, and enhanced audit committee provisions. The Companies Act is administered by the Ministry of Justice (MOJ).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "jp-appi-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "jp-cybersecurity-basic-act-2014-critical-infrastructure-protection",
    "title": "Japan Cybersecurity Basic Act 2014 - National Cybersecurity Strategy and Critical Infrastructure Protection",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Japan's Cybersecurity Basic Act 2014 (as amended 2018) establishes the National Cybersecurity Strategy, creates the National center of Incident readiness and Strategy for Cybersecurity (NISC), designates Critical Infrastructure sectors for protection, requires government agencies and infrastructure operators to implement cybersecurity measures, and mandates information sharing across government and industry to strengthen national cyber resilience.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-cybersecurity-framework-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "jp-economic-security-promotion-act-2022",
    "title": "Japan Economic Security Promotion Act 2022",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Japan's Economic Security Promotion Act enacted May 2022 establishes four pillars - stable supply chains for critical goods, security plans for 14 critical infrastructure sectors, advanced technology development programs, and non-public patent filing for sensitive technologies - requiring critical infrastructure operators to submit security plans for government review before major system changes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/jp-economic-security-promotion-act-2022.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-adequacy-decisions-article-45",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "jp-financial-instruments-exchange-act-2006",
    "title": "Japan Financial Instruments and Exchange Act 2006 (FIEA) - Securities Regulation",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Japan's Financial Instruments and Exchange Act 2006 (FIEA, Act No. 25 of 1948 as comprehensively amended in 2006) is the primary securities regulatory framework. It requires registration of securities offerings (including crypto-assets as Type II financial instruments from 2020), mandates prospectus disclosure, prohibits insider trading and market manipulation, regulates financial instruments business operators (FIBOs), and establishes conduct-of-business obligations including suitability, best execution, and KYC. The FSA (Financial Services Agency) is the primary regulator; SESC (Securities and Exchange Surveillance Commission) investigates violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-market-abuse-regulation-596-2014",
      "eu-ucits-directive-2009-65",
      "eu-aifmd-directive-2011-61"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "jp-fsa-banking-act-1981",
    "title": "Japan Banking Act 1981 (Act No. 59) - Prudential Licensing & Supervision",
    "domain": "Banking & Global Finance",
    "version": "2024.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Japan's foundational banking law (Act No. 59 of 1981) establishes licensing requirements for banks, sets prudential standards including capital adequacy and liquidity obligations, and grants the Financial Services Agency supervisory powers including business improvement orders and license revocation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "basel_iii",
        "fatf",
        "iso_31000",
        "gdpr_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-capital",
      "fatf-40-recommendations-2023-consolidated",
      "bis-pfmi-financial-market-infrastructure-2012"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "jp-industrial-safety-health-act-1972",
    "title": "Japan Industrial Safety and Health Act 1972",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2022-06-17",
    "bluf": "The Industrial Safety and Health Act (Act No. 57 of 1972), last substantially amended in 2022, establishes the framework for preventing workplace accidents and protecting workers' health in Japan, requiring employers to appoint a safety manager under Article 11 and health manager under Article 12 for workplaces meeting prescribed size thresholds, mandating safety and health education for new employees and those assigned to hazardous work under Articles 59 and 60, requiring medical examinations for all employees at least annually and for employees engaged in harmful work under Article 66, imposing obligations to measure the working environment for chemical and physical hazards under Article 65, requiring employers to submit a plan for dangerous or harmful work to the Labour Standards Inspection Office under Article 88, and imposing criminal penalties of up to 6 months imprisonment and fines of up to JPY 500,000 for violations causing workplace accidents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "jp-labour-standards-act-1947",
        "jp-appi-2022",
        "au-model-whs-laws-2011"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "jp-labour-standards-act-1947",
      "jp-appi-2022",
      "au-model-whs-laws-2011"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "jp-keihyo-ho-premium-misleading-representations-act",
    "title": "Japan Act against Unjustifiable Premiums and Misleading Representations (Keihyo-ho, Act No. 134 of 1962)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Act against Unjustifiable Premiums and Misleading Representations (景品表示法, Keihyo-ho), enacted as Act No. 134 of 1962 and substantially amended in 2014, 2016 and 2023, is Japan's principal regulator of premium offers and advertising representations. Art. 1 sets the law's objective to protect consumers and ensure fair competition. Art. 4 limits the maximum value of premiums (keihin) that businesses may offer with the supply of goods or services. Art. 5 prohibits misleading representations, including: (1) representations that are likely to mislead consumers regarding the quality of goods or services into thinking them substantially better than they are or than those of competitors (Art. 5(1) - yuryo-go-nin); (2) representations regarding price, conditions or other transactional benefits that are likely to mislead consumers into thinking the transaction substantially more favourable than it is (Art. 5(2) - yuri-go-nin, including the dual-price misrepresentation); and (3) representations designated by Cabinet Order as misleading (Art. 5(3)). Art. 7 authorises the Consumer Affairs Agency (CAA) and the Japan Fair Trade Commission to issue cease-and-desist orders requiring the violator to stop the conduct, take measures to prevent recurrence and inform the public. Art. 8 enables the imposition of a surcharge (kacho-kin) order of up to 3 percent of the relevant sales revenue, increased to 4.5 percent under the 2023 amendment for repeat offenders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "japan-consumer-contract-act-2000-caa",
      "us-ftc-cfr-16-part-255-endorsement-testimonials-advertising"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "jp-labour-standards-act-1947",
    "title": "Japan Labour Standards Act 1947 (Act No. 49 of 1947, Rōdō Kijun-hō) - Minimum Employment Standards",
    "domain": "Workplace",
    "version": "1.0.2",
    "last_updated": "2026-06-14",
    "bluf": "The Labour Standards Act 1947 (Act No. 49 of 1947, Rōdō Kijun-hō) establishes minimum employment standards applicable to all workers employed in Japan regardless of the form of their employment contract, administered by the Ministry of Health, Labour and Welfare (MHLW) and enforced by Labour Standards Inspection Offices nationwide. Article 1 declares the fundamental principle: the purpose of the Act is to ensure working conditions that meet the minimum standards for a life worthy of human dignity. Article 32 establishes the statutory maximum working hours: employers must not cause workers to work more than 8 hours per day, exclusive of rest periods, or more than 40 hours per week. Article 36 permits extensions of working hours and work on rest days where an employer and a majority labour union (or majority employee representative) conclude a labour-management agreement (36-jō kyōtei) and file it with the relevant Labour Standards Inspection Office; this agreement, commonly known as the '36 Agreement', sets the specific overtime caps. The 2018 Work Style Reform Act (Act No. 71 of 2018) imposed statutory caps on overtime under the 36 Agreement: the general cap is 45 hours per month and 360 hours per year, with an absolute upper limit of 100 hours per month (including regular and overtime hours) that cannot be exceeded even with a special agreement. Article 37 requires premium wages for overtime work at a rate of not less than 25% above the ordinary wage, rising to 50% for overtime work between 10 pm and 5 am. Article 39 entitles workers to annual paid leave: 10 days after 6 months of continuous service, scaling to 20 days after 6 years and 6 months. From 2019, employers must ensure that workers take at least 5 days of annual leave per year. Article 89 requires employers with 10 or more workers to establish written work rules and file them with the Labour Standards Inspection Office.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998",
      "ilo-convention-155-occupational-safety-1981"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "jp-my-number-act-individual-number-digital-identity",
    "title": "Japan My Number Act 2013 and the Individual Number Card Digital Identity Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-06-09",
    "bluf": "Japan's national digital identity is governed by the Act on the Use of Numbers to Identify a Specific Individual in Administrative Procedures (the My Number Act, Act No. 27 of 2013). The Act establishes the 12-digit Individual Number (My Number), the Individual Number Card (My Number Card) with an embedded integrated-circuit chip, and the Japan Public Key Infrastructure for Individual Numbers (JPKI) used for electronic signing and authentication. The Digital Agency is the lead administering agency from September 2021 onwards, with the Ministry of Internal Affairs and Communications coordinating municipal issuance. Use of the My Number is restricted by Article 9 to social security, tax, and disaster response purposes, with penalties for unauthorised collection or disclosure under Articles 48 to 53.\n\nThe My Number Card carries two public key infrastructure certificates: a user certificate for signing and a user certificate for authentication. Article 67 to Article 75 govern the issuance and management of these JPKI certificates. The Personal Information Protection Commission (PPC) supervises personal information protection in respect of Specific Personal Information (i.e., personal information that includes a My Number) and may issue guidance, recommendations, and orders under the Act on the Protection of Personal Information (APPI). The 2023 amendments expanded the use of the Individual Number to additional administrative areas including driver license integration and migrant resident registration. The Mobile My Number Card service supports My Number Card functions on smartphone devices for select Android handsets from 2023 and iPhone from 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nist-sp-800-63-4-2025-digital-identity-guidelines",
      "japan-appi-act-57-2003-personal-information-protection-ppc"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "jp-organized-crime-proceeds-act-136-1999",
    "title": "Act on Punishment of Organized Crimes and Control of Proceeds of Crime (Act No. 136 of 1999)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Japan's Act No. 136 of 1999 criminalizes the laundering and handling of criminal proceeds and provides for their confiscation. Article 10 punishes concealment or disguise of the acquisition or disposition of criminal proceeds; Article 11 punishes knowingly receiving criminal proceeds; and Article 13 sets out the property that may be confiscated as proceeds of crime. This node scopes the money-laundering offences and confiscation regime; customer due diligence and suspicious transaction reporting sit in a separate Japanese statute.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "jp-payment-services-act-chapter-iii-2-crypto-asset-exchange-service-provider",
    "title": "Japan Payment Services Act Chapter III-2 - Crypto-Asset Exchange Service Provider Registration and Supervision",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "Chapter III-2 of Japan's Payment Services Act (Shikin Kessai Ni Kansuru Houritsu, Act No. 59 of 2009) establishes the world's first comprehensive national licensing regime for crypto-asset exchange service providers (CAESP) following the 2016 amendment that took effect 1 April 2017, with significant strengthening in the 2019 amendment effective May 2020 that renamed virtual currency to crypto-asset (kasou shisan) and added customer asset segregation requirements. Article 2(5) defines a crypto-asset as property value that can be used in relation to unspecified persons for the purpose of paying consideration, can be purchased and sold with unspecified persons, is recorded electronically on electronic devices, and excludes Japanese or foreign fiat currency and currency-denominated assets. Article 63-2 requires registration with the Prime Minister (delegated to the Financial Services Agency FSA) before conducting crypto-asset exchange service - defined as the purchase or sale of crypto-assets, intermediation/brokerage/agency of crypto-asset transactions, or management of users' money or crypto-assets in connection with these activities. Article 63-9 mandates segregation of user money and user crypto-assets from the CAESP's own property - including a critical 95% cold-wallet rule introduced in 2019 requiring at least 95% of user crypto-assets to be held in cold wallets disconnected from the internet, with the remaining hot-wallet portion backed by the CAESP's own property of equivalent value. Article 63-10 requires customer protection measures including risk disclosure, fee transparency, complaint handling, internal control systems, and prevention of conflicts of interest. The 2019 amendment also brought security tokens under the Financial Instruments and Exchange Act (FIEA Article 2(2)(5)) as Electronically Recorded Transferable Rights and added crypto-asset derivatives regulation. Penalties include registration revocation, business improvement orders, business suspension up to 6 months, and criminal penalties up to JPY 3 million and 3 years imprisonment under Article 109 for operating without registration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "registration_requirements_article_63_3",
        "customer_asset_segregation_article_63_9_and_95_percent_cold_wallet_rule",
        "customer_protection_article_63_10_and_jvcea_self_regulation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "singapore-mas-payment-services-act-2019-dpt",
      "eu-mica-casp-obligations",
      "us-ny-dfs-bitlicense-23-nycrr-part-200",
      "fsb-crypto-asset-regulatory-framework-2023"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "jp-pharmaceutical-medical-devices-act-2014",
    "title": "Japan Pharmaceutical and Medical Devices Act 2014",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2020-09-01",
    "bluf": "The Act on Securing Quality, Efficacy and Safety of Products Including Pharmaceuticals and Medical Devices (Act No. 145 of 1960, substantially amended in 2014 as the Pharmaceutical and Medical Devices Act and further amended in 2019 and 2020), requires manufacturers and marketing authorization holders to obtain individual product approval from the Ministry of Health, Labour and Welfare or the Pharmaceuticals and Medical Devices Agency before placing drugs, medical devices, regenerative medicine products, quasi-drugs, or cosmetics on the Japanese market under Article 14, classifies medical devices into four classes (Class I exempt from approval through Class III requiring full review) under Article 23-2-2, imposes Good Manufacturing Practice obligations on manufacturing facilities under Article 14-3, requires post-marketing surveillance and safety reporting of adverse drug reactions to PMDA within 15 days for serious unexpected reactions under Article 68-10, and imposes penalties up to 3 years imprisonment and JPY 3 million fines for marketing unapproved products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "jp-appi-2022",
        "ca-food-drugs-act-1985",
        "eu-medical-devices-regulation-mdr-2017-745-implementation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "jp-appi-2022",
      "ca-food-drugs-act-1985",
      "eu-medical-devices-regulation-mdr-2017-745-implementation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "jp-satellite-remote-sensing-data-act-2016",
    "title": "Act on Ensuring Appropriate Handling of Satellite Remote Sensing Data (Act No. 77 of 2016)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Japan's Act on Ensuring Appropriate Handling of Satellite Remote Sensing Data regulates the use of satellite remote sensing instruments and the handling of the resulting data. A person who intends to use a satellite remote sensing instrument via a command and control ground station located in Japan must obtain a license from the Prime Minister for each satellite remote sensing instrument (Article 4, paragraph 1). The Act defines satellite remote sensing data by reference to electromagnetic recordings transmitted to the ground and specified handling criteria (Article 2, item (vi)), allows persons handling such data to obtain certification from the Prime Minister (Article 21), and imposes penalties of imprisonment of not more than three years or a fine of not more than 1,000,000 yen, or both, for specified violations (Article 33). It applies to operators of satellite remote sensing instruments controlled from Japan and to handlers of satellite remote sensing data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "jp-basic-space-act-2008"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "jp-specified-commercial-transactions-act-1976",
    "title": "Japan Specified Commercial Transactions Act (Tokutei Shōtorihiki-hō, Act No. 57 of 1976)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Specified Commercial Transactions Act (Tokutei Shōtorihiki-hō, 特定商取引法, Act No. 57 of 1976), as amended in 2008, 2016 and 2021, regulates six categories of commercial transactions in which consumers are particularly vulnerable to high-pressure tactics or information asymmetry. The Act covers: door-to-door sales (Arts. 3-7), mail-order and online sales (Arts. 11-14), telemarketing sales (Arts. 16-22), chain sale transactions or multi-level marketing (Arts. 33-40), specified continuous services such as language schools and beauty courses (Arts. 41-43), and business opportunity sales (Arts. 51-56). Core consumer protections include the cooling-off right of 8 days for door-to-door and telemarketing sales (Arts. 9 and 24), 20 days for chain sale and business opportunity sales, the obligation to deliver written documents stating prescribed information (Arts. 4, 5, 18, 19, 37, 42, 55), the prohibition of misleading or unconscionable solicitation (Arts. 6, 21, 34, 52), and the right to rescind under aggravated conditions where the trader provides false information (Arts. 9-2, 24-2). The Consumer Affairs Agency (Shōhi-sha Chō) and the Ministry of Economy, Trade and Industry (METI) jointly administer the Act and may issue improvement orders, business suspension orders or business closure orders (Arts. 7, 15, 22, 38).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "japan-consumer-contract-act-2000-caa",
      "jp-keihyo-ho-premium-misleading-representations-act"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "jp-telecommunications-business-act-2001",
    "title": "Japan Telecommunications Business Act",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2023-12-27",
    "bluf": "The Telecommunications Business Act (Act No. 86 of 1984, substantially restructured in 2001 when the Ministry of Posts and Telecommunications became the Ministry of Internal Affairs and Communications, and last amended 2023 to implement smartphone software provisions), requires general telecommunications carriers establishing or operating circuits for provision to unspecified users to register with MIC under Article 9 before commencing service and specified carriers using third-party circuits to notify MIC under Article 16, imposes an absolute statutory obligation to protect the secrecy of communications under Article 4 with criminal penalties of up to 2 years imprisonment and JPY 1 million fines for unauthorised disclosure, mandates interconnection between carriers on reasonable and non-discriminatory terms under Article 32 with MIC-approved cost-oriented tariffs for designated dominant carriers, requires compliance with important communications priority rules under Article 8 during disasters, prohibits carriers from refusing service without justifiable reason, and requires operators of major app stores and operating systems designated under 2022 amendments to provide fair and non-discriminatory access to application developers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "jp-appi-2022",
        "sg-telecommunications-act-1999",
        "ca-telecommunications-act-1993"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "jp-appi-2022",
      "sg-telecommunications-act-1999",
      "ca-telecommunications-act-1993"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "kanban-replenishment",
    "title": "Kanban Replenishment Algorithm",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with this node's Kanban Replenishment Algorithm mandates adherence to a comprehensive set of security protocols and operational thresholds designed for ensuring supply chain integrity and data protection in line with governing frameworks. System integrity is upheld through stringent controls, including enforced role-based access controls and mandatory multi-factor authentication for any changes to Kanban parameters. Pursuant to established data handling regulations, all information is secured via active data-in-transit and data-at-rest encryption. The algorithm stipulates that every demand signal source must be authenticated to prevent unauthorized inventory adjustments. Operational execution is strictly governed; replenishment orders cannot deviate beyond a 10 percent maximum order quantity variance, while lead time projections must remain within a 20 percent maximum allowable lead time deviation. Furthermore, a minimum required safety stock of 15 percent is maintained to mitigate disruptions. A 99.9 percent system availability service level agreement guarantees performance, with all transactions recorded in an immutable audit log. System stability is further reinforced through active input data validation and enabled API rate limiting for secure, reliable processing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "logistics-jit-inventory",
      "warehouse-wms-optimization",
      "scor-fulfill",
      "supply-chain-risk-triage",
      "iso-28000-supply-chain"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "kazakhstan-space-activities-law-2012",
    "title": "Kazakhstan Law on Space Activities 2012 - KazCosmos National Space Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2012-01-06",
    "bluf": "Kazakhstan's Law on Space Activities (6 January 2012, No. 528-IV) establishes the legal framework for space operations from Baikonur Cosmodrome administered under the Russia-Kazakhstan Agreement, requiring KazCosmos (now Kazcosmos SC) licensing for all space activities, mandatory state notification for satellite launches and orbital slots, debris mitigation compliance, and government ownership of national space infrastructure including Baiterek next-generation launch facility.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "intl-outer-space-treaty-1967-article-1-exploration-freedom",
      "copuos-lts-guidelines-2019-space-sustainability",
      "iadc-space-debris-mitigation-guidelines-2007",
      "un-liability-convention-1972-space-objects"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "kcs-evolve-loop",
    "title": "KCS Evolve Loop",
    "domain": "Workflow Automation",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Knowledge-Centered Service (KCS) v6, developed by the Consortium for Service Innovation, defines the Evolve Loop as the organizational and strategic activities that ensure the KCS program itself continuously improves and delivers increasing value - distinct from the Solve Loop which focuses on capturing knowledge during individual interactions. The Evolve Loop encompasses content health assessment, alignment of knowledge strategy with product and business strategy, measurement of KCS program maturity and adoption, leadership enablement, and the reward and recognition structures that sustain the KCS culture. For AI-augmented knowledge bases, the Evolve Loop governs how AI-generated knowledge articles are reviewed, validated, and integrated into the authoritative knowledge base, ensuring that machine-created content meets the same quality standards as human-created content.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ke-biosafety-act-2009",
    "title": "Kenya Biosafety Act No. 2 of 2009",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Kenya Biosafety Act No. 2 of 2009 regulates activities involving genetically modified organisms and establishes the National Biosafety Authority under Section 5. Sections 18 to 21 require written approval from the Authority for contained use, introduction into the environment, importation and placing on the market; Section 19 adds Gazette and newspaper publication with a thirty-day public comment window. Section 27 requires the Authority to undertake risk assessment under the Fifth Schedule, and Section 52 sets offences and penalties of up to twenty million shillings or ten years imprisonment, or both.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "ke-computer-misuse-cybercrimes-act-2018",
    "title": "Kenya Computer Misuse and Cybercrimes Act 2018",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Kenya's Computer Misuse and Cybercrimes Act 2018 (Act No. 5 of 2018), assented to May 16, 2018, establishes a comprehensive cybercrime legal framework criminalising unauthorised access, computer fraud, identity theft, cyberbullying, and child exploitation material, designates critical information infrastructure operators required to implement security measures and report incidents to the National Kenya Computer Incident Response Team Coordination Centre, and imposes penalties including fines up to KES 25 million and imprisonment up to 25 years for the most serious offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ke-computer-misuse-cybercrimes-act-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ke-dpa-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ke-dp-act-2019",
    "title": "Kenya Data Protection Act 2019 - No. 24 of 2019 and Office of the Data Protection Commissioner",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Kenya's Data Protection Act, 2019 (No. 24 of 2019), assented to by the President of Kenya on 8 November 2019 and published in the Kenya Gazette Supplement No. 186 (Acts No. 31) on 8 November 2019, is Kenya's primary comprehensive personal data protection legislation. The Data Protection Act 2019 gives effect to the right to privacy guaranteed by Art. 31 of the Constitution of Kenya, 2010, which provides that every person has the right to privacy including the right not to have their personal information unnecessarily required, used, or disclosed. The Act came into operation on 25 November 2019. The enforcement and implementation authority is the Office of the Data Protection Commissioner (ODPC), established under the Data Protection Act 2019 as an independent office. The first Data Protection Commissioner, Immaculate Kassait, was appointed in November 2020. The ODPC has been active in operationalising the regulatory framework including issuing Regulations, receiving registrations, investigating complaints, and conducting enforcement actions. Key features of the Data Protection Act 2019: (1) 'Data controller' and 'data processor' terminology aligned with GDPR; (2) Registration - data controllers and data processors must register with the ODPC (registration became operational from May 2021); (3) Eight lawful bases for processing: consent; necessity for contract; legal obligation; vital interests; task carried out in the public interest or in exercise of official authority; legitimate interests; research, history, or statistics; (4) Sensitive personal data: race, health status, ethnic social origin, conscience, belief, genetic data, biometric data, marital status, family details, sex or sexual orientation; (5) Eight data subject rights: right to be informed, right of access, right to correction, right to objection, right to erasure/blocking, right to data portability, right not to be subject to automated decision-making, right to lodge a complaint; (6) Data Protection Officer (DPO): required for government entities and private entities processing personal data as a core business activity; (7) Personal data breach notification: notify the ODPC within 72 hours of discovery; notify affected data subjects where the breach is likely to result in risk to their rights and freedoms; (8) Data Protection Impact Assessment (DPIA): required for high-risk processing; (9) Cross-border data transfer: transfers outside Kenya require that the recipient country provides adequate protection or approved transfer mechanisms apply; (10) Administrative fines up to KES 5 million or imprisonment up to 10 years for criminal violations. Kenya is East Africa's largest economy and a leading African technology hub, particularly in fintech (M-Pesa, mobile financial services) and digital health, making data protection compliance a significant issue for both domestic and international organisations operating in the region.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ke-dpa-2019",
    "title": "The Data Protection Act, 2019 (No. 24 of 2019)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Kenya Data Protection Act (DPA) governs the processing of personal data, establishing the Office of the Data Protection Commissioner and outlining the rights of data subjects. It applies to data controllers and processors in Kenya and those outside who process personal data of subjects located in Kenya, mandating compliance with core data protection principles under Section 25.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ke-odpc-sector-guidance-notes-2024-2025",
    "title": "Kenya ODPC Sector-Specific Guidance Notes 2024-2025 - Communication, Education, Public Sector, Private Security, and Biometric Data",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Data controllers and processors operating in Kenya should apply the sector-specific Guidance Notes issued by the Office of the Data Protection Commissioner (ODPC) during 2024 and 2025 under the Data Protection Act 2019, including the Guidance Note for the Communication Sector (2024) which addresses automated decision-making risks and recommends regular review and audit of automated decision-making systems to ensure they are fair and unbiased, the Guidance Note for the Education Sector (2024), the 2025 Guidance Notes for the Public Sector and for the Processing of Recorded Media (addressing automated individual decision making and consent as a lawful basis), the Draft Guidance Note for Private Security (2025) (defining consent as any manifestation of express, unequivocal, free, specific and informed indication of the data subject's wishes by a statement or by a clear affirmative action), and the Draft Guidance on Processing of Biometric Data (2025) (including the right not to be subject to automated decision making).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ke-public-procurement-asset-disposal-act-2015-act-33-2015",
    "title": "Kenya Public Procurement and Asset Disposal Act No. 33 of 2015 (PPADA) and PPADR 2020",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Kenya Public Procurement and Asset Disposal Act No. 33 of 2015 (PPADA) assented to 18 December 2015 and effective 7 January 2016 and the Public Procurement and Asset Disposal Regulations 2020 (PPADR 2020) constitute the principal Kenyan legal framework governing procurement of goods, works, and services by public entities including the National Government, County Governments, public service offices, state corporations, constitutional commissions and independent offices, statutory bodies, and other public entities funded by public funds. The PPADA 2015 was enacted under Article 227 of the Constitution of Kenya 2010 which mandates a fair, equitable, transparent, competitive, and cost-effective public procurement system. PPADA 2015 replaced the prior Public Procurement and Disposal Act 2005 and modernised the Kenyan procurement regime including establishing the National Treasury as the policymaking authority and the Public Procurement Regulatory Authority (PPRA) as the regulatory authority. The Public Procurement Information Portal (tenders.go.ke) operated by the National Treasury is the federal e-procurement platform and the Integrated Financial Management Information System (IFMIS) is used for financial integration. Procurement methods established by PPADA 2015 Part X comprise (a) Open Tender (sec. 96, default open public tender), (b) Two-Stage Tendering (sec. 99, for complex acquisitions), (c) Design Competition (sec. 100), (d) Restricted Tendering (sec. 102, with prequalification), (e) Direct Procurement (sec. 103, sole-source under prescribed exceptions including emergency, sole supplier, prior failed tendering, and small-value below thresholds), (f) Request for Quotations (sec. 105, for low-value acquisitions), (g) Electronic Reverse Auctions (sec. 107), (h) Low-Value Procurement (sec. 108), (i) Force Account (sec. 109, in-house performance), and (j) Specially Permitted Procurement Procedures (sec. 113). PPADA 2015 establishes the Public Procurement Administrative Review Board (PPARB) for procurement appeals. Kenya is NOT a party to the WTO Government Procurement Agreement (GPA). Kenya is a party to the East African Community (EAC) Public Procurement Bill framework and to UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "ke-dpa-2019",
      "ke-computer-misuse-cybercrimes-act-2018",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "kenya-betting-control-licensing-act-cap-131",
    "title": "Betting Control and Licensing Act (Cap. 131) of the Laws of Kenya",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes the legal framework for licensing, regulating, and supervising betting and gaming activities in Kenya, including sports betting, online gambling, and pool betting. It applies to all operators, agents, and intermediaries offering betting services within Kenya under Section 4 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "kenya-citizenship-immigration-act-2011-dis",
    "title": "Kenya Citizenship and Immigration Act 2011 - DIS and East African Community Framework",
    "domain": "Immigration & Border Control",
    "version": "2.1.1",
    "last_updated": "2026-06-29",
    "bluf": "The Kenya Citizenship and Immigration Act, 2011 (Act No. 12 of 2011, Cap. 172) is Kenya's principal immigration statute governing entry, residence, and removal of foreign nationals. It received assent on 27 August 2011 and commenced on 30 August 2011, repealing the former Kenya Citizenship Act (Cap. 170), the Immigration Act (Cap. 172) and the Aliens Restriction Act (Cap. 173). The Department of Immigration Services (DIS) under the Ministry of Interior and National Administration administers the Act, supported by the Kenya Citizenship and Immigration Regulations, 2012 (Legal Notice No. 64 of 2012). Kenya announced visa-free entry for African nationals from January 2024 through a Presidential Directive, with eligible travellers obtaining an Electronic Travel Authorisation (ETA) before arrival. Under the East African Community Common Market Protocol (2010), nationals of EAC partner states (Uganda, Tanzania, Rwanda, Burundi, South Sudan, DRC and Somalia) benefit from free movement of persons and labour. The eCitizen portal processes visa, ETA and permit applications digitally. The Act provides for removal of unlawfully present persons by order of the Cabinet Secretary, invalidation of permits, and offences and penalties for breaches of its provisions; specific section numbers and the relevant categories of permits and passes are set in the Act and in the 2012 Regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "au",
        "eac",
        "unhcr",
        "icao_doc",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "kenya-digital-health-act-2026",
    "title": "Kenya Digital Health Act 2024 & Data Protection (Health Data) Regulations (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The Kenya Digital Health Act 2024 establishes the legal framework for digital health services, electronic health records, telemedicine, and the Kenya Health Information Exchange (KHIE). It mandates interoperability standards, patient consent, data security, and integration with the Data Protection Act 2019. Health data is treated as sensitive personal data requiring explicit consent or other legal bases, with strict breach notification and cross-border transfer rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "south-africa-popia-health-info-2026",
      "who-global-digital-health-strategy-2026"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "kenya-energy-act-2019-epra",
    "title": "Kenya Energy Act No. 1 of 2019 - EPRA Licensing and Tariff Framework",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Kenya Energy Act No. 1 of 2019 establishes the Energy and Petroleum Regulatory Authority (EPRA) with licensing jurisdiction over electricity generation, transmission, distribution, retail supply, and petroleum exploration; tariff approval under Section 36; rural electrification obligations via REREC; and penalties up to KES 2,000,000 under Section 166.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "philippines-epira-2001-electricity-market"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "kenya-food-drugs-chemical-substances-act-cap-254",
    "title": "Kenya Food, Drugs and Chemical Substances Act (Cap 254)",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation requires all food businesses in Kenya to register with the Kenya Bureau of Standards (KEBS) and comply with food safety standards as outlined in Article 12 of the Act. It applies to all food manufacturers, processors, and distributors in Kenya.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brc-food-safety-standard-issue-9",
      "codex-alimentarius-gen"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "kenya-gambling-control-act-2023-bclb",
    "title": "Kenya Gambling Control Act 2023 - Betting Control and Licensing Board (BCLB) Framework",
    "domain": "Gaming & Gambling",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Kenya's Gambling Control Act 2023 (Act No. 33 of 2023) repealed and replaced the Betting, Lotteries and Gaming Act (Cap. 131) and established a modernised regulatory framework for all gambling activities including online sports betting, casinos, lotteries, and skill games. The Betting Control and Licensing Board (BCLB) remains the licensing and enforcement authority pending establishment of the new Gambling Control Commission under the 2023 Act. Kenya has one of the most active mobile sports betting markets in Africa, driven by Safaricom M-PESA mobile payment integration. Licence categories include bookmaker, totalisator, casino, public lottery, gaming machine, and remote betting. The responsible gambling framework mandates deposit limits, self-exclusion, and age verification (18+). A 15% betting excise duty on net winnings is levied under the Excise Duty Act. Unlicensed gambling is a criminal offence punishable by up to 5 years imprisonment under the 2023 Act. BCLB actively enforces against offshore operators accepting Kenyan players without a licence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "aml",
        "fatf_recommendation",
        "mobile_payments",
        "data_protection",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "kenya-land-act-2012-national-land-commission",
    "title": "Kenya Land Act 2012 - National Land Commission and Compulsory Acquisition Framework",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Kenya's Land Act No. 6 of 2012 (in force 2 May 2012) implements Article 68 of the Constitution; establishes the National Land Commission (NLC) as manager of public land; provides for compulsory acquisition with prompt and just compensation; converts freehold and leasehold titles to the unified Land Registration Act 2012 framework; and sets maximum 99-year leasehold terms for non-citizens.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "south-africa-nhbrc-housing-consumer-protection-act-95-1998"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "kenya-space-agency-sti-act-2013",
    "title": "Kenya Space Agency - Science, Technology and Innovation Act 2013 (No. 28) and KSA Mandate",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Kenya's Science, Technology and Innovation (STI) Act No. 28 of 2013 established the legal framework for Kenya's science institutions including the Kenya Space Agency (KSA), operationalized through Legal Notice No. 14 of 2017; KSA serves as Kenya's national space agency responsible for coordinating space activities, developing Kenya's space policy and legislation, managing the Luigi Broglio Space Centre (Malindi Space Station) in partnership with Italy's ASI, implementing Kenya's ITU orbital filing obligations through CCK/CA, and positioning Kenya as a continental hub for African space activities under the African Space Policy and Strategy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "itu-radio-regulations-2020-edition"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "kenya-water-act-2016-wrma",
    "title": "Kenya Water Act 2016 - WRA Water Permits and WASREB Service Regulation Framework",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Kenya's Water Act (No. 43 of 2016) repeals and replaces the Water Act of 2002 and devolves water functions per the 2010 Constitution. The Water Resources Authority (WRA) regulates water resources and issues water permits. The Water Services Regulatory Board (WASREB) regulates water and sewerage service providers. Water Resources Users Associations (WRUAs) manage catchment conservation at community level. The Cabinet Secretary may declare water scarcity areas with additional controls. Abstraction of water from a public water resource requires a WRA permit; discharges require separate authorisation. The National Water Harvesting and Storage Authority (NWHSA) manages dams, irrigation and other water infrastructure under Cabinet Secretary oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "south-africa-national-water-act-36-1998"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "kg-law-on-public-procurement-2015-72-zakupki-gov-kg",
    "title": "Kyrgyzstan Law on Public Procurement No. 72 of 3 April 2015 (Zakon o Gosudarstvennykh Zakupkakh) as amended and zakupki.gov.kg",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Kyrgyz Republic Law on Public Procurement No. 72 of 3 April 2015 (Zakon Kyrgyzskoi Respubliki o Gosudarstvennykh Zakupkakh) effective 1 May 2015 as substantially amended over time (most recently by Law No. 200 of 18 November 2021 modernisation amendments), and supplemented by Government of the Kyrgyz Republic Resolution No. 803 of 28 December 2015 (Rules of Public Procurement) as amended, is the principal Kyrgyz statute governing procurement of goods, works, and services by procuring entities including the Republican Budget bodies (Jogorku Kenesh, executive bodies, the Office of the President, the Supreme Court, the Constitutional Court, the General Prosecutor's Office), regional and local self-government bodies, state and municipal enterprises, public-sector universities, and other procuring entities financed by the Republican Budget. Law 72/2015 modernised the Kyrgyz procurement regime aligning with international best practice including the UNCITRAL Model Law on Public Procurement and World Bank procurement guidelines. The Department of Public Procurement under the Ministry of Finance of the Kyrgyz Republic is the central regulatory authority. The Government Procurement Information System (zakupki.gov.kg) is the mandatory federal e-procurement platform for in-scope procurement. Procurement methods established by Law 72/2015 art. 14 to 33 comprise (a) Konkurs Otkrytyy (Open Tender, the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Konkurs Ogranichennyy (Restricted Tender, with prequalification), (c) Konkurs po Slozhnym Zakupkam (Complex Procurement Tender, two-stage for complex acquisitions), (d) Uproshchennaya Procedura (Simplified Procedure, for medium-value), (e) Zaprashivanie Tsenovykh Predlozheniy (Request for Quotations, for low-value), (f) Pryamoy Sposob Zakupki (Direct Procurement, sole-source under prescribed exceptions in art. 32 including emergency, sole supplier for technical reasons, prior failed procurement, and prescribed-class exemptions), (g) Method of Procurement from One Source (Iz Edinogo Istochnika), and (h) Electronic Reverse Auction. The Chamber of Accounts of the Kyrgyz Republic conducts ex-post procurement audit. The State Service for Combating Economic Crimes (Financial Police) has investigative jurisdiction over procurement-related corruption. Kyrgyzstan is a party to the Eurasian Economic Union (EAEU) and observes the EAEU procurement provisions. Kyrgyzstan is in WTO accession in the procurement chapter and is NOT yet a party to the WTO Government Procurement Agreement (GPA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "kg-pdp-law-2008",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "kg-pdp-law-2008",
    "title": "Kyrgyzstan Law on Personal Information - State Agency for Personal Data Protection Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Kyrgyzstan Law on Personal Information (No. 58, 2008, as amended) establishes consent-based data subject rights and operator obligations for all personal data processing within the Kyrgyz Republic. Supervisory enforcement is vested in the State Agency for Personal Data Protection under the Cabinet of Ministers of the Kyrgyz Republic (created by Presidential Decree No. 391 of 14 September 2021).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "kh-pdpl-2022",
    "title": "Cambodia Personal Data Protection Framework - Sub-Decree No. 252 (2021), Constitutional Privacy and Draft PDP Law",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Cambodia has not yet enacted a comprehensive personal data protection law and is one of the last ASEAN states without one. Personal data protection currently rests on the constitutional protection of privacy, on sectoral instruments - notably Sub-Decree No. 252 (2021) on the Management, Use and Protection of Personal Identification Data, administered by the Ministry of Interior - and on the draft Law on Personal Data Protection led by the Ministry of Posts and Telecommunications (MPTC), which has been under public consultation since 2023. Together with ASEAN data-protection principles, these form the operative basis for personal data handling in Cambodia. The workflow below sets out aligned good-practice controls (notification, consent, sensitive-data safeguards, breach response, and cross-border transfer assessment) consistent with Sub-Decree No. 252, the draft law, and ASEAN principles pending comprehensive legislation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ki-framework",
    "title": "Kiribati - Constitutional Privacy Rights and Pacific Islands Forum Data Protection Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Republic of Kiribati is an independent sovereign nation in the central Pacific Ocean comprising 33 atolls across the Gilbert, Phoenix, and Line Islands. Kiribati achieved independence from the United Kingdom in 1979 and is governed under the Constitution of Kiribati (1979), which establishes fundamental rights including the protection of personal privacy consistent with constitutional democratic traditions. Kiribati is a member of the Commonwealth of Nations, the Pacific Islands Forum, and the United Nations. The Ministry of Information, Communications and Transport (MICT) oversees telecommunications and ICT regulation in Kiribati. Kiribati does not have a standalone comprehensive personal data protection law. The applicable framework for personal data protection consists of constitutional privacy rights, Pacific Islands Forum regional guidelines on cybersecurity and data protection, Commonwealth privacy principles, and common law privacy traditions inherited from the pre-independence legal system. Organisations processing personal data in Kiribati must respect constitutional privacy rights, implement appropriate technical and organisational security measures to protect personal data from unauthorised access and disclosure, and limit collection and use of personal data to specified, legitimate purposes. As a Pacific Islands Forum member, Kiribati participates in regional frameworks for cybercrime prevention and digital governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ki-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "kimberley-process-certification-scheme-2003",
    "title": "Kimberley Process Certification Scheme (KPCS) 2003 - Rough Diamond Trade Controls, Warranties and Participating Country Obligations to Prevent Conflict Diamonds",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Kimberley Process Certification Scheme (KPCS) requires all participating countries to implement import/export controls on rough diamonds using tamper-resistant certificates to prevent conflict diamonds from entering global trade. This applies to all 86 countries representing 99.8% of global rough diamond production under the KPCS framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp",
      "oecd-due-diligence-minerals-supply-chains-2016"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "km-anrtic-framework",
    "title": "Comoros ANRTIC Regulatory Framework - Constitutional Privacy Rights and Personal Data Obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Union of the Comoros has established the Agence Nationale de Régulation des Technologies de l'Information et de la Communication (ANRTIC) as the national authority for regulating information and communication technology services, including the oversight of personal data handling by licensed electronic communications operators. The Comorian Constitution establishes the inviolability of private communications and correspondence and the right to privacy as fundamental rights. ANRTIC's regulatory framework imposes obligations on licensed ICT and telecommunications operators to protect the confidentiality of subscriber personal data, to prevent unauthorised access to and disclosure of personal information processed through electronic communications networks, and to implement security measures proportionate to the risks of the data processed. The Comoros does not have a standalone comprehensive personal data protection law, but the constitutional framework, ANRTIC regulatory requirements, and the African Union Convention on Cyber Security and Personal Data Protection (AU Malabo Convention, 2014) - which the Union of the Comoros is encouraged to ratify as an African Union member - together constitute the reference legal framework for personal data protection obligations in the Comoros. As a member of the Organisation of Islamic Cooperation (OIC), Comoros is also subject to OIC guidelines on cybersecurity and data protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/km-anrtic-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "kn-dpa-2018",
    "title": "Saint Kitts and Nevis Data Protection Act 2018",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Saint Kitts and Nevis enacted the Data Protection Act 2018, a CARICOM and OECS-aligned statute establishing a framework for the lawful processing of personal information. The Act is administered by a Data Protection Commissioner and establishes data protection principles covering fair collection, purpose limitation, data minimisation, accuracy, retention limits, security, and individual participation. Data subjects have rights of access and correction. Special categories of sensitive personal information are subject to explicit consent requirements. Cross-border transfers require adequate protection or appropriate safeguards. The Act extends to all organisations established in the Federation or processing personal information of persons in the Federation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/kn-dpa-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "korea-act-on-development-ai-2024",
    "title": "South Korea Act on Development and Support of Artificial Intelligence 2024 - Compliance Obligations for Korean AI Operators, High-Impact AI Service Notification Requirements, and AI Safety Certification for High-Risk AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations for Korean AI operators under the 2024 Act, including high-impact AI service notification as per Article 12 and mandatory safety certification for high-risk AI systems under Article 15; it aligns with EU AI Act 2024 obligations for high-risk systems under Article 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "korea-fair-trade-act-revisions-2020-monopoly",
    "title": "Monopoly Regulation and Fair Trade Act, Act No. 17386, as Amended by Act No. 17386 on December 4, 2020 - Partial Amendment Relating to Fair Competition in the Digital Market and Strengthening of Remedies for Unfair Practices",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The 2020 revision to Korea’s Monopoly Regulation and Fair Trade Act (MRFTA) strengthens oversight of dominant online platforms and conglomerates (chaebols), prohibits self-preferencing and unfair access denial by platform operators, enhances private damages actions, and expands the Korea Fair Trade Commission’s (KFTC) authority to issue cease-and-desist orders and impose surcharge fees. Key provisions are found in Article 3-2 (unfair use of superior bargaining position), Article 19-2 (prohibition of self-preferencing by designated platforms), and Article 55-2 (private right of action with treble damages).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeepers",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "korea-monopoly-regulation-fair-trade-act",
    "title": "Monopoly Regulation and Fair Trade Act, Act No. 17386, as Amended by Act No. 17386 on December 4, 2020",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The Monopoly Regulation and Fair Trade Act (MRFTA) prohibits abuse of a market-dominant position, unfair trade practices, and anti-competitive mergers in South Korea. It applies to all enterprises operating in Korea, with heightened scrutiny for large conglomerate groups (chaebols) under Article 2(4) and Article 3. The Korea Fair Trade Commission (KFTC) enforces compliance under Articles 11-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "korea-fair-trade-act-revisions-2020-monopoly",
      "icn-recommended-practices-merger-notification-2023",
      "oecd-competition-digital-economy-roundtable-2023",
      "india-competition-act-2002-sections-3-4",
      "japan-antimonopoly-act-2019-amendment-jftc"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "korea-pipa-standard",
    "title": "South Korea PIPA",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Personal Information Protection Act (PIPA) of South Korea is one of the world's strictest data protection regimes, mandating specific opt-in consent for sensitive information and imposing criminal penalties for data misuse. It is overseen by the PIPC (Personal Information Protection Commission).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-adequacy-decisions-article-45",
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "kr-act-on-contracts-to-which-the-state-is-a-party-koneps-procurement",
    "title": "South Korea Act on Contracts to Which the State Is a Party + KONEPS Korea ON-line E-Procurement System",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Act on Contracts to Which the State Is a Party (Gukga-reul Dangsaja-ro Haneun Gyeyak-e Gwanhan Beomnyul) is the principal South Korean statute governing contracts entered into by the State including procurement of goods, construction works, and services by central administrative agencies, with parallel rules under the Act on Contracts to Which a Local Government Is a Party for local government procurement and the Local Public Procurement Act for further local-level provisions. The statute is administered by the Ministry of Strategy and Finance (now Ministry of Economy and Finance) at the policy level and operationally delivered through the Public Procurement Service (PPS, Jojeo Cheong) which operates the centralised procurement function for many product categories and runs the Korea ON-line E-Procurement System (KONEPS) at g2b.go.kr. KONEPS is one of the world's most mature and comprehensive government e-procurement platforms, processing the majority of South Korean public sector procurement transactions across central and local government, and operating end-to-end electronic procurement from registration through contract execution. The Act and KONEPS workflow specify procurement methods including general competitive tendering (the default method), limited competitive tendering (restricted supplier set), nominated tendering (sole-source justified), and various negotiated procedures, with specific rules for small and medium-sized enterprise (SME) preferences, technology-development product preferences, and women / disabled / social enterprise preferences. The framework intersects the WTO Agreement on Government Procurement (GPA 2012) to which South Korea is a party, the Korea-EU Free Trade Agreement government procurement provisions, the Korea-US Free Trade Agreement government procurement provisions, and the Comprehensive and Progressive Agreement for Trans-Pacific Partnership (CPTPP) government procurement chapter following Korean accession negotiations. KONEPS integrates with the Government Auction System for property disposal, the Korea Public Procurement Information System (PPS Search), and the various sectoral procurement platforms for defence (Defense Acquisition Program Administration / DAPA), nuclear (Korea Hydro and Nuclear Power), and other regulated industry procurements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "kr-act-special-cases-punishment-sexual-crimes-article-14-2-deepfake-2024-amendment",
    "title": "South Korea Act on Special Cases Concerning the Punishment of Sexual Crimes - Article 14-2 (Fabricated/Edited Video Material) and September 2024 Deepfake Amendments (Production, Distribution, Possession, Viewing)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "South Korea's Act on Special Cases Concerning the Punishment of Sexual Crimes (성폭력범죄의 처벌 등에 관한 특례법) criminalises specific sexual offences including those committed using cameras and edited media. Article 14-2 (Distribution etc of Fabricated Edited Video Material) criminalises the synthesis or processing of a person's photograph, video, or audio recording with the purpose of distributing the content in a form that may cause sexual desire or shame against the will of the person; the original (pre-2024) penalty was imprisonment up to 5 years or a fine up to 50 million won. The National Assembly passed amendments on 26 September 2024 to address the deepfake sex crime crisis: (1) the maximum sentence for production and distribution under Article 14-2 was raised from 5 years to 7 years; (2) a new offence was introduced criminalising the possession, purchase, storage, or viewing of deepfake sexual content with imprisonment up to 3 years or a fine up to 30 million won (approximately 22,500 US dollars); (3) lawmakers added a clause protecting individuals who unknowingly viewed or possessed the illegal content from punishment, preserving the mens rea requirement; (4) related amendments to the Sexual Violence Prevention and Victims Protection Act, the Youth Protection Act (Cheonsonyeon Bohobeop), and the Act on the Promotion of Information and Communications Network Utilization and Information Protection (the Telecommunications Network Act) extended the enforcement architecture. The amendments respond to a 2024 deepfake sexual abuse crisis primarily affecting underage and young adult women including Telegram-distributed deepfakes targeting students. Enforcement is led by the Korean National Police Agency Cyber Bureau, the Public Prosecutors' Office Cybercrime Division, the Korea Communications Commission (KCC) and the Korea Communications Standards Commission (KCSC) for platform-level takedown, and the Korea Internet & Security Agency (KISA) for cross-border cooperation. The Korean regime operates alongside the EU AI Act Article 50 deepfake transparency obligations and the US TAKE IT DOWN Act 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "article_14_2_pre_2024_offence",
        "september_2024_amendment_production_and_distribution_uplift",
        "september_2024_amendment_new_possession_viewing_offence",
        "september_2024_amendment_unknowing_viewer_clause",
        "related_amendments_youth_protection_telecom_network",
        "deepfake_crisis_context_2024",
        "enforcement_architecture",
        "platform_takedown_kcsc_orders",
        "relationship_with_eu_ai_act_us_take_it_down",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-take-it-down-act-2025",
      "eu-ai-act-article-50-transparency-obligations",
      "china-cac-deep-synthesis-provisions-2022",
      "ca-criminal-code-162-1-intimate-image-without-consent",
      "uk-sexual-offences-act-2003-section-66a-66b-cyberflashing-intimate-image"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "kr-ai-basic-act-2024",
    "title": "Framework Act on the Development of Artificial Intelligence and Establishment of Trust",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This South Korean framework promotes AI development and innovation under a 'priority permission, ex-post regulation' principle (Article 5), while establishing national strategies and ethical guidelines to ensure AI safety, transparency, and human-centered values. It applies to all AI developers, providers, and users within South Korea, introducing a voluntary certification system for trustworthy AI (Article 21).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "korea-pipa-standard",
      "unesco-ethics-ai"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "kr-ai-framework-act-2024-effective-2026",
    "title": "South Korea AI Basic Act 2025 - Act on the Development of Artificial Intelligence and Establishment of Trust, Effective 22 January 2026",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Organisations developing, providing, or using AI in or affecting the Republic of Korea must, from 22 January 2026, comply with risk-based obligations under the AI Framework Act including user notification of AI and AI-generated content, performance of impact assessments for high-impact AI in critical sectors (healthcare, energy, public services), establishment of risk-management systems with human oversight and documentation, appointment of a domestic representative if the operator has no Korean address, transparency about training data and system operations, and mandatory labelling for certain applications of generative AI, with MSIT operating a grace period of at least one year in 2026 during which fact-finding investigations and administrative fines will generally be deferred except in cases involving serious social harm.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-automated-decision-workflows"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "kr-fscma-financial-investment-services-capital-markets-act-2009",
    "title": "Korea Financial Investment Services and Capital Markets Act (FSCMA) - Act No. 8635",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Korea's FSCMA (Act No. 8635, effective February 2009) is the primary capital markets law governing financial investment business entities (FIBEs): six licensed activities (dealing, brokerage, collective investment, investment advisory, discretionary investment, trust); suitability obligations; prospectus registration for public offerings (≥50 investors); insider trading prohibition (Art 174); market manipulation prohibition (Art 176); and FSC/FSS regulatory oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mifid-ii",
      "eu-esma-regulation-1095-2010",
      "fincen-cdd-beneficial-ownership-rule-2016"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "kr-mrfta-fair-trade-act",
    "title": "South Korea Monopoly Regulation and Fair Trade Act (MRFTA - 독점규제 및 공정거래에 관한 법률, Act No. 18661 of 4 January 2022)",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Monopoly Regulation and Fair Trade Act (MRFTA - 독점규제 및 공정거래에 관한 법률) is South Korea's principal competition statute, originally enacted as Act No. 3320 on 31 December 1980 and comprehensively reformed by Act No. 18661 of 4 January 2022 (the 2022 MRFTA Amendment), which is the current operative version. The MRFTA is administered and enforced by the Korea Fair Trade Commission (KFTC / 공정거래위원회), an independent regulatory authority established under the Act with jurisdiction over anti-competitive agreements, abuse of market dominance, merger review, unfair business practices, and consumer protection in trade matters. Market dominance: the MRFTA presumes market dominance where a single undertaking accounts for 50% or more of the relevant market, or where the combined share of the top three undertakings is 75% or more of the relevant market (subject to a floor of 10% individual market share for each undertaking included in the top-three calculation). Abuse of market dominance (Art. 5 MRFTA) is prohibited and includes: unreasonable pricing (excessive pricing or predatory pricing below cost); output restriction; market entry barriers; discrimination in trading conditions; and exclusionary practices harming competition. The 2022 Amendment introduced new provisions on digital market platforms, applying heightened scrutiny to undertakings designated as having 'significant influence in the online platform market'. Anti-competitive agreements (cartels - Art. 40 MRFTA): all agreements, decisions, or concerted practices between competitors that restrict competition are prohibited, including price fixing, output limitations, market allocation, bid rigging, and exchange of competitively sensitive information. The KFTC may impose a surcharge (과징금) on cartel participants of up to 20% of related revenue for each violation period. Merger review (Arts. 11-16 MRFTA): mergers and acquisitions must be notified to the KFTC before completion where the acquiring entity's global assets or sales exceed KRW 300 billion and the Korean assets or sales of the target exceed KRW 30 billion; or where the deal value exceeds KRW 60 billion and the target has significant activities in Korea. The KFTC conducts a 30-working-day review (extendable to 90 working days for complex cases) and may clear the merger unconditionally, clear it with remedies, or prohibit it outright. Criminal sanctions (Art. 124 MRFTA): individuals who engage in cartel conduct are subject to imprisonment of up to three years or a fine of up to KRW 200 million; the KFTC may refer cartel cases to the Prosecutor General for criminal prosecution. Private enforcement: third parties who have suffered damage from anti-competitive conduct may claim civil damages before the courts; the 2022 Amendment introduced treble damages for cartel victims who prove intentional violation. The 2022 Amendment also extended the limitation period for KFTC enforcement to seven years for cartels.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tfeu-article-102-abuse-of-dominance",
      "us-ftc-act-section-5-unfair-competition"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "kr-network-act-ict-2001",
    "title": "South Korea Act on Promotion of Information and Communications Network Utilization and Information Protection 2001 (정보통신망법, Act No. 6360, as amended)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Act on Promotion of Information and Communications Network Utilization and Information Protection (정보통신망 이용촉진 및 정보보호 등에 관한 법률 - Network Act or ICT Network Act) is South Korea's foundational statute governing cybersecurity obligations, information security management, internet service provider (ISP) obligations, and online communications regulation. Originally enacted as Act No. 6360 on 16 January 2001, the Network Act has been substantially amended multiple times and remains one of the primary cybersecurity and online content regulatory instruments in South Korea, operating in tandem with the Personal Information Protection Act 2023 (PIPA 2023) and the Information Security Industry Act. The Network Act is administered by the Ministry of Science and ICT (MSIT / 과학기술정보통신부) with technical cybersecurity oversight delegated to the Korea Internet Security Agency (KISA / 한국인터넷진흥원). Information security management system (ISMS) certification: Article 47 of the Network Act requires mandatory Information Security Management System (ISMS - 정보보호 관리체계) certification for ISPs exceeding revenue, user, or traffic thresholds - specifically: ISPs with annual information and communications service revenue of at least KRW 10 billion; ISPs with more than one million daily active users for three consecutive months; data centre operators (internet data centres / IDCs) regardless of size; hospitals, schools, and other designated entities specified by MSIT decree. ISMS-P (Information Security Management System - Personal Information) certification combines the ISMS framework with PIPA 2023 personal information protection requirements into a unified certification. Security incident reporting: Article 48-2 of the Network Act requires that ISPs notify KISA of significant security incidents within 24 hours of discovery. Incidents triggering mandatory reporting include: distributed denial of service (DDoS) attacks causing service disruption; system intrusions and unauthorised access causing data exposure; and ransomware or malware infections affecting critical systems. KISA coordinates incident response and may direct ISPs to implement containment measures. Prohibition on illegal content: Article 44-7 prohibits transmission or distribution of illegal information via information and communications networks, including information violating privacy, criminal defamation, obscene content, gambling operations, and content inciting violence or discrimination. The Korea Communications Standards Commission (KCSC) may order takedown of illegal content. Spam and unsolicited commercial communications: Article 50 prohibits sending unsolicited commercial electronic communications (email, SMS, push notifications) without prior consent of the recipient (opt-in regime); recipients must be provided with a clear opt-out mechanism; commercial emails must include the advertiser's identity and a no-cost opt-out method; violation of Art. 50 is subject to fines of up to KRW 30 million. Unauthorised access: Article 48 prohibits unauthorised access to or interference with information and communications systems; criminal sanctions include imprisonment of up to five years or a fine of up to KRW 50 million. Administrative fines (과태료) up to KRW 100 million are available for a range of Network Act violations. The 2020 amendment to the Network Act transferred primary personal data protection obligations (consent, notification, rights) from the Network Act to the Personal Information Protection Act (PIPA), maintaining the Network Act's focus on network security, ISMS certification, incident reporting, and online content regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "kr-pipa-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "kr-personal-information-protection-act-pipa-2020",
    "title": "South Korea Personal Information Protection Act (PIPA) 2020 Amendment - Data 3 Act and 2023 Amendments",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-16",
    "bluf": "The Personal Information Protection Act (PIPA) is South Korea's primary data privacy law, originally enacted in 2011 and substantially amended by the Data 3 Act in 2020 (effective August 2020) and further amended in September 2023. The 2020 amendments introduced a pseudonymised data concept allowing processing for research, statistics, and public interest archiving without consent under certain conditions. They consolidated oversight of three privacy laws under the Personal Information Protection Commission (PIPC), and permitted cross-industry data combination through specialized institutions. The 2023 amendments added rights related to automated decision-making, strengthened cross-border transfer requirements including the Commission's adequacy determinations, expanded mandatory data protection officer designation, and increased maximum administrative fines to 3 percent of total revenue from an earlier capped amount. The law applies to all processing of personal information in the context of activities within South Korea, with extraterritorial reach for offerings of goods or services or monitoring of behavior in Korea. Enforcement includes criminal penalties, administrative fines, and civil damages.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "kr-pipa-2011-personal-information-protection-act-data-processing",
    "title": "Korea Personal Information Protection Act (PIPA) 2011 - Data Processing Principles and Subject Rights",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Korea's Personal Information Protection Act (PIPA), as substantially amended in 2023, establishes lawful bases for processing personal information, requires a privacy policy and privacy officer (CPO) appointment, mandates data minimisation and purpose limitation, grants data subjects rights to access, correction, deletion, and suspension, and imposes penalties up to 3% of revenue for violations enforced by the Personal Information Protection Commission (PIPC).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-6-lawful-basis-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "kr-pipa-2023",
    "title": "Personal Information Protection Act (as amended 2023)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The 2023 amendment to South Korea's Personal Information Protection Act (PIPA) introduces significant new data subject rights, including the right to data portability (Article 35-2) and rights concerning automated decision-making (Article 37-2). It also revises rules for overseas data transfers and increases administrative fines for serious violations to up to 3% of total corporate revenue (Article 64-2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "korea-pipa-standard",
      "gdpr-data-protection-officer",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "kr-space-objects-damage-compensation-act-2007",
    "title": "Act on Compensation for Damage Caused by Space Objects (Act No. 8714, 2007)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Republic of Korea's Act on Compensation for Damage Caused by Space Objects prescribes the scope of compensation for space damage and the limitation of liability (Article 1). A person launching a space object must compensate for space damage, with a narrow exception for damage caused by armed conflict, hostilities, civil disturbance, or mutiny, or caused in outer space, where intent or negligence is required (Article 4). The maximum amount of compensation for which a launching person is liable is 200 billion won (Article 5), and each person seeking permission to launch must purchase a liability insurance policy to compensate for damage, with coverage set by the Minister of Science and ICT within that ceiling (Article 6). It applies to persons launching space objects under Korean authorization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "kr-specified-financial-transaction-information-act-2001",
    "title": "Act on Reporting and Using Specified Financial Transaction Information (Act No. 6516, as amended)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "South Korea's Act on Reporting and Using Specified Financial Transaction Information (Act No. 6516, enacted 2001) establishes the country's AML/CFT reporting regime. Article 1 sets the purpose; Article 3 establishes the Korea Financial Intelligence Unit (KoFIU) under the Financial Services Commission; Article 4 requires suspicious transaction reports without delay; Article 4-2 requires large cash transaction reports; and Article 5-2 requires customer due diligence including beneficial owner verification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "kr-virtual-asset-user-protection-act-2023",
    "title": "Act on the Protection of Virtual Asset Users (Act No. 19563)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "South Korea's Act on the Protection of Virtual Asset Users (Act No. 19563) imposes core user-protection duties on virtual asset service providers. Article 6 requires segregation of users' deposits by depositing or entrusting them to a reputable institution prescribed by Presidential Decree, Article 7 requires keeping users' virtual assets separate from the provider's own and holding a portion offline (cold storage), and Article 8 requires insurance, mutual-aid enrolment or reserves to cover incidents such as hacking. Article 10 prohibits unfair trade practices including misuse of material non-public information and price manipulation, and Article 12 requires market operators to continuously monitor abnormal transactions and report suspected Article 10 violations to regulators without delay.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-15-vasps-travel-rule-2025",
      "kr-fscma-financial-investment-services-capital-markets-act-2009"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "kuwait-capital-markets-authority-law-7-2010",
    "title": "Kuwait Capital Markets Authority Law No. 7 of 2010 - Securities Market Regulation, Public Offering Prospectus Requirements, Market Conduct Rules, Insider Trading Prohibition and CMA Enforcement Powers",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Law No. 7 of 2010 establishes the Kuwait Capital Markets Authority (CMA) to regulate securities markets, mandating strict requirements for public offerings, licensing, and market conduct, and explicitly prohibits insider trading and market manipulation under Articles 118 and 122.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-virtual-assets-vasp"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "kuwait-data-privacy-law-2021",
    "title": "Kuwait Data Privacy Protection Regulation No. 42 of 2021 - CITRA (Communications and Information Technology Regulatory Authority) Oversight, Processing Conditions, Sensitive Data, Cross-Border Transfer Rules, Security Measures, 72-Hour Breach Notification and Fines up to KWD 50,000",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The CITRA Data Privacy Protection Regulation No. 42 of 2021 establishes data protection obligations for entities processing personal data in Kuwait, including requirements for lawful processing, data subject rights, breach notification within 72 hours, and security safeguards. It is a regulation issued by CITRA under its regulatory authority over communications and information technology, established by Decree-Law No. 37 of 2014. CITRA subsequently issued an amending instrument, Decision No. 26 of 2024, effective 19 February 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "kw-pdpl-2023",
    "title": "Kuwait CITRA Data Privacy Protection Regulation (DPPR) - Telecommunications Sector",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "Kuwait does not have a standalone comprehensive personal data protection statute equivalent to GDPR; there is no 'Law No. 2 of 2023 on the Protection of Personal Data'. Kuwait's binding data-protection instrument is the Data Privacy Protection Regulation (DPPR) issued by the Communications and Information Technology Regulatory Authority (CITRA - الهيئة العامة لتنظيم قطاع الاتصالات), originally adopted as CITRA Resolution No. 42 of 2021 and substantially revised by CITRA Decision No. 26 of 2024 (effective 19 February 2024). The 2024 revision NARROWED the DPPR's scope so it now applies only to individuals and entities operating as telecommunications service providers and licensees holding CITRA-issued licences - it is a sector-specific telecom regulation, not a cross-economy data protection law. CITRA also repealed its separate Data Classification Policy (2021) in the same period. Personal data is additionally touched by Law No. 20 of 2014 on Electronic Transactions and Law No. 63 of 2015 on Combating Information Technology Crimes (Cyber Crimes Law). Key features of the DPPR as amended by Decision No. 26 of 2024: (1) Scope - applies to CITRA-licensed telecom service providers and licensees collecting and possessing personal data during, or after termination of, the provision of telecommunications services; (2) Consent - service providers must obtain explicit consent before collecting or processing personal data; for minors under 18, consent must be obtained from a legal guardian; (3) Purpose and retention limits - personal data may be collected and processed only for the disclosed service purpose, and must be deleted once that purpose is fulfilled, typically following termination of the customer contract; (4) Breach notification - service providers must report any personal data breach to CITRA within 24 hours of its occurrence; (5) Security and confidentiality - service providers must protect personal data in their possession with appropriate safeguards; (6) Cross-border handling and disclosure - the DPPR conditions the collection, possession, and transfer of customer data by licensees and restricts disclosure outside the disclosed service purpose. Because the DPPR is telecom-sector limited, organisations outside the telecom sector that process personal data in Kuwait are governed primarily by sectoral rules (for example Central Bank of Kuwait and Capital Markets Authority requirements for financial institutions), contractual obligations, and the Cyber Crimes Law, rather than by a general data protection statute. Any compliance programme should be built against the actual DPPR text and the relevant sectoral framework, not against a presumed GDPR-style national law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "kw-pdpl-2023-data-subject-rights",
    "title": "Kuwait Personal Data Protection Law No.2/2023 - Rights of Personal Data Subjects",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Kuwait Personal Data Protection Law No. 2 of 2023 grants data subjects comprehensive rights: right to be informed of processing; right to access their personal data; right to correct inaccurate data; right to erasure where the processing purpose has ended or consent is withdrawn; right to object to processing; and right to withdraw consent at any time. Controllers must establish an accessible rights request channel, respond within the timeframe specified by CITRA implementing regulations, and notify CITRA of systemic refusals. Penalties for denial of rights are enforced by CITRA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "kw-pdpl-2023",
      "kw-pdpl-2023-lawful-processing-conditions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "kw-pdpl-2023-lawful-processing-conditions",
    "title": "Kuwait Personal Data Protection Law No.2/2023 - Lawful Conditions for Processing Personal Data",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Kuwait Personal Data Protection Law No. 2 of 2023 requires that all processing of personal data be based on a lawful condition: explicit consent of the data subject; necessity for the performance of a contract to which the data subject is party; compliance with a legal obligation; protection of the vital interests of the data subject; performance of a task carried out in the public interest; or the legitimate interest of the controller provided it does not override the data subject's interests. Processing without a lawful basis is prohibited and subject to penalties enforced by CITRA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "kw-pdpl-2023",
      "kw-pdpl-2023-data-subject-rights"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ky-dpl-2017",
    "title": "Cayman Islands Data Protection Law 2017",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Cayman Islands enacted the Data Protection Law 2017 (revised 2021), a comprehensive GDPR-aligned statute that came fully into force on 30 September 2019. Administered by the Ombudsman, it establishes eight data protection principles governing the collection, use, storage, and transfer of personal data. Data subjects have rights of access, correction, and objection. Personal data may be transferred internationally only to jurisdictions offering adequate protection or with appropriate safeguards. Data processors must execute written data processing agreements. The law applies to all data controllers established in the Cayman Islands or using equipment in the Cayman Islands for processing personal data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ky-dpl-2017.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "kyoto-protocol-1997-climate-change",
    "title": "Kyoto Protocol 1997 - Binding GHG Emission Reduction Targets & Flexible Mechanisms",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Kyoto Protocol, adopted on 11 December 1997 in Kyoto, Japan, and entered into force on 16 February 2005, is the first binding international treaty to impose quantified greenhouse gas emission reduction commitments on developed country Parties (Annex B). It operates as a Protocol to the UNFCCC (Article 17) and has 192 Parties, though the United States never ratified and Canada withdrew in 2011. The Protocol established the principle of binding QELROs (Quantified Emission Limitation and Reduction Objectives) for Annex B Parties: in the first commitment period (2008-2012) an average 5.2% below 1990 levels. The Doha Amendment (2012) extended the Protocol to a second commitment period (2013-2020, 18% below 1990 levels average), though the amendment has not entered into force due to insufficient ratifications. The Protocol created three 'flexible mechanisms': Emissions Trading (ET, Article 17 - trade of Assigned Amount Units between Annex B Parties), Joint Implementation (JI, Article 6 - Annex I to Annex I emission reduction unit transfers from projects), and the Clean Development Mechanism (CDM, Article 12 - Annex I investments in non-Annex I countries generate Certified Emission Reductions). The CDM generated over 8,700 registered projects and 2 billion CERs. The Protocol's 6 controlled GHGs are: CO2, CH4, N2O, HFCs, PFCs, SF6 (NF3 added in Doha Amendment). Article 3(3) and 3(4) include Land Use, Land Use Change and Forestry (LULUCF) accounting. The Kyoto Protocol has been largely superseded by the Paris Agreement (2015) for post-2020 commitments but remains the legal framework for CDM transition to the Paris Agreement Article 6.4 Sustainable Development Mechanism (SDM).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unfccc-1992-framework-convention-climate-change",
      "eu-ets-directive-2003-87-emissions-trading-scheme",
      "un-paris-agreement-ndc-implementation-guidelines",
      "eu-cbam-2023-956-carbon-border-adjustment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "kz-law-on-public-procurement-2015-434-v-amended-2022-goszakup",
    "title": "Kazakhstan Law on Public Procurement No. 434-V of 4 December 2015 as amended by Law No. 488-VI of 2022 and Goszakup",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Republic of Kazakhstan Law on Public Procurement No. 434-V (Zakon o gosudarstvennykh zakupkakh) of 4 December 2015 (effective 1 January 2016) as substantially amended over time (most recently by Law No. 488-VI of 24 November 2021 and Law No. 145-VII of 11 July 2022 modernisation amendments), and supplemented by Government of the Republic of Kazakhstan Resolution No. 648 of 27 December 2015 (Rules of Public Procurement) as amended, is the principal Kazakh statute governing procurement of goods, works, and services by procuring entities (organisatori zakupok) including the Republican Budget bodies (republican executive bodies, the Republican Constitutional Council, the Republican Procuracy, the Republican Court, the National Bank of Kazakhstan), regional and local executive bodies, state institutions, quasi-state sector entities (national companies, national holding companies, state enterprises including the Samruk-Kazyna sovereign wealth fund affiliates), and other procuring entities financed by the State budget. Law 434-V replaced the prior Law on Public Procurement No. 303-III of 21 July 2007 and substantially modernised the Kazakh procurement regime. The Ministry of Finance of the Republic of Kazakhstan through the Committee of State Procurement is the central regulatory authority responsible for procurement regulation, oversight, supplier debarment, and procurement guidance. The Goszakup web-portal (goszakup.gov.kz) operated by the Ministry of Finance is the mandatory federal e-procurement platform for in-scope procurement. The Information System for Public Procurement (ISPP) provides electronic procurement workflow management. Procurement methods established by Law 434-V art. 17 to 51 comprise (a) Otkrytyy konkurs (Open Tender, the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Konkurs s ispolzovaniem dvukhetapnykh procedur (Two-Stage Tender for complex acquisitions), (c) Konkurs sredi predvariteino kvalifitsirovannykh postavshchikov (Tender among Pre-qualified Suppliers), (d) Aukcion (Auction including Electronic Reverse Auction), (e) Zaprashivanie tsenovykh predlozheniy (Request for Quotations, for medium-value), (f) Iz odnogo istochnika (From One Source / sole-source under prescribed exceptions in art. 39 including emergency, sole supplier for technical reasons, prior failed procurement, and prescribed-class exemptions), (g) Iz odnogo istochnika putem priamogo zakliucheniia dogovora (Direct Contracting), and (h) Reverse Auction (Pereghovori). The Accounts Committee for Control over Execution of the Republican Budget conducts ex-post procurement audit. The Anti-Corruption Service has investigative jurisdiction over procurement-related corruption. Kazakhstan is in WTO accession in the procurement chapter and is NOT yet a party to the WTO Government Procurement Agreement (GPA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "kz-pdp-law-2013",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "kz-pdp-law-2013",
    "title": "Kazakhstan Personal Data and Their Protection Law 2013 - MCI",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Kazakhstan's Law on Personal Data and Their Protection (Закон Республики Казахстан «О персональных данных и их защите») - Law No. 94-V ZRK, adopted by the Parliament of the Republic of Kazakhstan on 21 May 2013 and signed by President Nursultan Nazarbayev, entered into force on 1 July 2013 - is Kazakhstan's primary personal data protection legislation. The law has been amended several times, with significant amendments in 2016, 2020, and 2022. The enforcement authority is the Ministry of Digital Development, Innovations and Aerospace Industry of the Republic of Kazakhstan (MDIAAP - Министерство цифрового развития, инноваций и аэрокосмической промышленности Республики Казахстан), specifically its Committee on Information Security (Комитет по информационной безопасности), which supervises personal data protection compliance. Key features of Kazakhstan's Law No. 94-V ZRK: (1) Scope - applies to operators (owners and operators of personal data databases) and third parties involved in the collection, processing, storage, or use of personal data in Kazakhstan; (2) Data localisation - personal data of Kazakhstan citizens must be stored in databases physically located in Kazakhstan (data localisation requirement); operators collecting personal data of Kazakhstan citizens must use databases in Kazakhstan for initial collection, storage, and primary processing; cross-border transfer is permitted after localisation requirements are satisfied; (3) Data processing principles - personal data processing must comply with: lawfulness; consent; purpose limitation; proportionality; accuracy; security; and confidentiality; (4) Sensitive categories - the law provides heightened protection for: biometric personal data (fingerprints, retinal scans, facial recognition, voice data and other physiological data); health data; genetic data; data relating to criminal convictions; (5) Data subject rights - right of access; right to rectification; right to deletion; right to object to processing; right to appeal to the Committee on Information Security; (6) Consent - general personal data processing requires the data subject's consent (written or electronic); processing of biometric data requires specific written consent; (7) Operator registration - database operators must register their personal data databases with the Committee on Information Security; registration is mandatory before processing commences; (8) Security obligations - operators and third parties must implement technical and organisational security measures to protect personal data from unauthorised access, disclosure, modification, and destruction; measures must meet the security requirements established by the Committee on Information Security; (9) Breach notification - operators must notify the Committee on Information Security of personal data security incidents; (10) Cross-border transfer - personal data may be transferred to foreign states only after the data localisation requirement is satisfied and subject to either: bilateral agreement; data subject consent; or equivalent protection requirements; (11) Administrative penalties - violations are subject to administrative fines under the Code of Administrative Offences of Kazakhstan; fines for operators processing personal data without registration or in violation of security requirements. Kazakhstan's data protection framework is heavily influenced by Russia's Federal Law No. 152-FZ and maintains a data localisation requirement as a central pillar of its approach, reflecting Kazakhstan's approach to digital sovereignty and its membership in the Eurasian Economic Union (EAEU) where harmonised digital governance frameworks are under development.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "la-edp-law-2017",
    "title": "Lao PDR Law on Electronic Data Protection 2017",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Lao People's Democratic Republic enacted the Law on Electronic Data (Law No. 20/NA, 2017) which contains provisions governing the protection of personal data in electronic form. The law is administered by the Ministry of Science and Technology (MoST) and the Ministry of Post and Telecommunications (MPT). It establishes obligations for electronic data controllers to collect personal data only with the data subject's knowledge and consent, implement security measures to protect electronic data, restrict disclosure of personal data to third parties without consent, and ensure the accuracy of personal data held. Data subjects have the right to access and correct personal data held about them. The law aligns with ASEAN principles on personal data protection given Laos's membership in ASEAN.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/la-edp-law-2017.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "laboratory-developed-tests-ldt-regulation-2026",
    "title": "Laboratory Developed Tests (LDTs) - FDA Oversight & Global Alignment (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The FDA’s final rule on Laboratory Developed Tests brings most LDTs under medical device regulation with phased enforcement. Requirements include registration, listing, adverse event reporting, quality systems (QMSR), premarket review for higher-risk tests, and labeling. Laboratories must comply with both CLIA and FDA obligations, with significant impact on precision medicine and companion diagnostics.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 3
  },
  {
    "node_id": "last-mile-algorithm-ethics",
    "title": "Last-Mile Delivery Ethics",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Operational governance of last-mile delivery activities necessitates rigorous adherence to established ethical and performance standards. This compliance framework ensures all logistical operations, from dispatch to final customer handover, are executed with fairness, transparency, and accountability. The system continuously monitors key performance indicators against predefined operational parameters to proactively identify and mitigate risks associated with driver conduct, delivery accuracy, and customer interaction protocols. It enforces policies concerning fair labor practices for delivery personnel, including equitable route allocation and prevention of over-scheduling, thereby promoting a safe and sustainable working environment. Furthermore, the framework mandates transparent communication with consumers regarding delivery timelines, potential delays, and service modifications. Data privacy is a core component, stipulating stringent controls over the collection, use, and storage of customer information obtained during the delivery process. Any deviation from these codified standards triggers an automated alert for immediate review and corrective action, ensuring consistent regulatory alignment and safeguarding corporate reputation. This comprehensive oversight mechanism serves to uphold consumer trust, maintain operational integrity, and demonstrate a commitment to responsible business practices within the complex last-mile ecosystem.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-health-safety",
      "iso-39001-road-traffic",
      "ilo-fundamental-rights-work",
      "nist-sp-1270-managing-ai-bias",
      "iso-28000-supply-chain"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "law-society-conveyancing",
    "title": "Conveyancing Quality (UK)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Evaluation of a firm's adherence to UK conveyancing standards necessitates a multi-faceted compliance assessment, centered on the Law Society Conveyancing Quality Scheme Core Practice Management Standards. Verifiable active CQS accreditation is mandatory, alongside confirmation that designated fee earners have completed requisite CQS training. Rigorous client due diligence, pursuant to The Money Laundering Regulations 2017, must be evidenced through completed AML and KYC checks and a fully verified source of funds. Ethical obligations under the SRA Code of Conduct for Solicitors demand a passed conflict of interest check and strict handling of client money as outlined in Section 8. Firms must demonstrate robust operational protocols, including the issuance of a client care letter within fourteen days of instruction and the validation of all requisite property searches. Adherence to lender obligations, as stipulated in the UK Finance Mortgage Lenders' Handbook, is confirmed via complete lender disclosure. Furthermore, robust cyber-security measures are critical; firms must maintain an active cyber fraud prevention policy and utilize secure transmission for bank details, reflecting guidance from both The Law Society on preventing fraud and HM Land Registry Practice Guide 81. Procedural integrity requires maintaining an active HM Land Registry priority throughout the transaction and retaining a complete SDLT audit trail for a minimum of six years post-completion to ensure a comprehensive and defensible record.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sra-code-conduct-uk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "lb-ldp-2018",
    "title": "Lebanon Electronic Transactions and Personal Data Law - TRA Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Lebanon Law No. 81 of 2018 on Electronic Transactions and Personal Data establishes consent-based personal data processing obligations, data subject rights including access and correction, mandatory controller registration, and cross-border transfer controls. The Telecommunications Regulatory Authority (TRA) of Lebanon serves as the supervisory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "lb-public-procurement-law-244-2021-ppa-impact-2022",
    "title": "Lebanon Public Procurement Law 244 of 19 July 2021 (Qanun al-Shira'a al-Aam) effective 29 July 2022",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Lebanese Public Procurement Law No. 244 of 19 July 2021 (Qanun al-Shira'a al-Aam in Arabic) effective 29 July 2022 is the principal Lebanese statute governing procurement of goods, services, works, and consultancies by public entities including ministries, public administrations, public institutions, municipalities and unions of municipalities, public utility entities, and other public-sector entities financed by public funds. Law 244/2021 replaced the prior 1959 Public Accounting Decree-Law No. 14969 procurement provisions and substantially modernised the Lebanese procurement regime under the IMF-supported reform programme and the broader Lebanese governance reform agenda. The Public Procurement Authority (Hayat al-Shira'a al-Aam / PPA) established under Law 244/2021 is the autonomous regulatory body with rule-making, complaint resolution, and procurement guidance authority. The 244/2021 framework introduced (a) mandatory use of an electronic procurement platform (under development by the PPA), (b) the principles of transparency, equal treatment, fair competition, sustainability, integrity, and value for money, (c) the obligation for procuring entities to maintain annual procurement plans, (d) the Tendering Committees and the Tender Opening Committees with independent participation, (e) the Complaints and Appeals Mechanism through the PPA and subsequent State Council judicial review, and (f) strengthened integrity provisions including supplier debarment and conflict of interest disclosure. Procurement methods established by Law 244/2021 art. 38 to 49 comprise (a) Open Procedure (al-Munaqasa al-Aamma, the default open public procedure), (b) Restricted Procedure (al-Munaqasa al-Mahduda, with prequalification), (c) Negotiated Procedure (al-Tafawud, under prescribed exceptions including emergency, sole supplier for technical reasons, prior failed tendering, and prescribed-class exemptions), (d) Competitive Dialogue (al-Hiwar al-Tanafusi, for complex acquisitions), (e) Framework Agreement (al-Ittifaq al-Itari), (f) Direct Purchase (al-Shira'a al-Mubasher, for small-value below thresholds and prescribed exceptions), and (g) Design Contest (Musabaqa Tasmimiyya). Lebanon is NOT a party to the WTO Government Procurement Agreement (GPA) but is an observer. Lebanon is a party to the Greater Arab Free Trade Area (GAFTA) and the UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "lb-ldp-2018",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "lc-dpa-2011",
    "title": "Saint Lucia Data Protection Act 2011",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Saint Lucia enacted the Data Protection Act No. 11 of 2011 to regulate the collection, use, disclosure, and storage of personal information. The Act is administered by a Data Protection Commissioner. It establishes principles of fair and lawful collection, purpose limitation, data minimisation, accuracy, security, and accountability. Data subjects have rights of access and correction. Sensitive personal information categories (health, political opinions, religious beliefs, trade union membership, criminal offences, racial or ethnic origin) are subject to heightened protections. Cross-border transfers to jurisdictions without adequate protection require safeguards. The Act aligns with CARICOM data protection principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/lc-dpa-2011.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "lcr-disclosure-standards",
    "title": "Liquidity coverage ratio disclosure standards",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2014-03-31",
    "bluf": "This disclosure framework sets out requirements for the Liquidity Coverage Ratio (LCR) to improve transparency, reinforce the Sound Principles for sound liquidity risk management, enhance market discipline, and reduce market uncertainty. The LCR standard aims to promote the short-term resilience of a bank’s liquidity risk profile by ensuring that it has sufficient high-quality liquid assets (HQLA) to survive a significant stress scenario lasting for 30 days. These standards are an essential component of the reforms introduced by Basel III and will increase banks’ resilience to liquidity shocks and promote a more stable funding profile.\n\nThe disclosure requirements apply to all internationally active banks on a consolidated basis. The core obligation is for these banks to publish their LCR according to a common template. The LCR will be introduced on 1 January 2015, with a minimum requirement set at 60%, rising in equal annual steps to reach 100% on 1 January 2019. Banks must publish this disclosure at the same frequency as, and concurrently with, their financial statements. The framework requires quantitative information in a common template and sufficient qualitative discussion to facilitate understanding of the results and data provided.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-sound-liquidity-risk-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "lean-manufacturing-value-stream-mapping",
    "title": "Lean Manufacturing Value Stream Mapping - Current State, Future State, Waste Identification (Muda), Kaizen Events and Implementation Roadmap for Process Workflows",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation requires organizations to adopt lean thinking and practice to identify customer value, map current and future state workflows, eliminate waste (muda), and implement continuous improvement through structured experimentation. It applies to all entities engaged in product or service delivery workflows seeking operational excellence through lean principles as defined in the primary source.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "leed-green-building",
    "title": "LEED Green Building Rating",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The LEED Green Building Rating system establishes a framework of performance-based prerequisites and optional credits for certifying sustainable building projects. Foundational compliance requires executing multiple non-negotiable measures, starting with verification that a site assessment is complete to inform design and that a construction activity pollution prevention plan meeting NPDES guidelines is in place. Resource efficiency mandates a minimum indoor water use reduction percentage of 20, substantiated by building-level water metering for total potable water consumption. Energy prerequisites demand a certified minimum energy performance percentage improvement over the ASHRAE 90.1 baseline, supported by building-level energy metering. System integrity necessitates fundamental refrigerant management by prohibiting any use of CFC-based refrigerants in new equipment. Occupant welfare is addressed through strict environmental tobacco smoke control, which bans smoking within facilities and 25 feet of building openings. Additionally, a dedicated area for the storage and collection of recyclables must be provided. Credits for advanced performance are attainable by achieving a high construction waste diversion percentage, increasing the number of low-emitting materials categories met to limit VOC emissions, or implementing a building automation system security protocol as an innovation strategy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14046-water-footprint",
      "iso-46001-water-eff",
      "iso-14001-ems",
      "iso-20400-sustainable-proc"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "leed-v4-1-building-certification-usgbc",
    "title": "LEED v4.1 - Leadership in Energy and Environmental Design: Location and Transport, Sustainable Sites, Water Efficiency, Energy and Atmosphere, Materials and Resources, Indoor Environmental Quality",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "LEED v4.1 establishes a framework for certifying sustainable buildings across design, construction, and operations phases, requiring projects to meet all prerequisites and earn points through credit compliance. Certification levels are determined by total points earned: Certified (40-49), Silver (50-59), Gold (60-79), and Platinum (80+).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-19650-bim-information-management-construction",
      "iso-50001-2018-energy-management-systems",
      "australia-national-construction-code-2022-ncc"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "leed-v4-1-certification-system",
    "title": "LEED v4.1 Building Design and Construction Rating System - Prerequisites, Credits and Minimum Programme Requirements",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The LEED v4.1 BD+C rating system provides a framework for designing, constructing, and operating high-performance green buildings, requiring all projects to meet a set of Minimum Program Requirements (MPRs) and mandatory Prerequisites before earning points toward certification through optional Credits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures",
      "iso-46001-water-eff"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "li-dsg-2018",
    "title": "Liechtenstein Data Protection Act 2018 (Datenschutzgesetz - DSG) - EEA GDPR Implementation",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Liechtenstein's Datenschutzgesetz (DSG - Data Protection Act) of 4 October 2018, enacted by the Landtag (Liechtenstein Parliament) and published as LGBl. 2018 Nr. 272, came into force on 1 January 2019 and is Liechtenstein's primary national legislation implementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Liechtenstein. Liechtenstein is not an EU member state but is a member of the European Economic Area (EEA); the GDPR was incorporated into the EEA Agreement and became directly applicable Liechtenstein law, making Liechtenstein subject to GDPR with the same legal effect as EU member states. The DSG provides national derogations and additions permitted by the GDPR and replaces the prior Liechtenstein data protection legislation (Datenschutzgesetz from 2002, LGBl. 2002 Nr. 55). Enforcement: the Datenschutzstelle (DSS - Data Protection Office) is Liechtenstein's independent data protection supervisory authority. The DSS is not an EU EDPB member (as Liechtenstein is not an EU member state) but participates in EDPB activities as an EEA observer and cooperates closely with EU supervisory authorities. Liechtenstein is a small but highly prosperous principality (population approximately 39,000) located between Switzerland and Austria, with a sophisticated financial services sector, advanced industrial manufacturing, and significant dental technology and life sciences industries. Liechtenstein is a major global financial centre: it hosts numerous banks, trust companies, investment funds, and insurance entities regulated by the Finanzmarktaufsicht Liechtenstein (FMA - Financial Market Authority). The financial sector processes significant personal data of international clients, investors, and beneficial owners subject to GDPR. Key Liechtenstein national provisions under the DSG: (1) Age of digital consent: the DSG specifies the age of consent for information society services implementing GDPR Art. 8; data subjects below the applicable age require parental or guardian consent; (2) Public sector processing - Liechtenstein public authorities (Landesverwaltung) are subject to the DSG for personal data processing alongside GDPR; specific provisions govern access to public sector data; (3) Freedom of expression - the DSG contains exemptions for journalistic, academic, and cultural processing aligned with GDPR Art. 85; freedom of expression is protected under the Liechtenstein Constitution (Verfassung des Fürstentums Liechtenstein, LGBl. 1921 Nr. 15); (4) Employment - the Allgemeines bürgerliches Gesetzbuch (ABGB) and labour regulations govern employment relationships and the processing of employee personal data alongside GDPR; (5) Financial sector - FMA regulated entities (banks, investment firms, insurance companies, trust companies) face additional data protection and information security requirements overlapping with GDPR, including customer due diligence data under AML legislation; (6) Research and statistics - extended processing for scientific research and statistics in the public interest is permitted with appropriate safeguards under the DSG. Fines: GDPR administrative fines apply in Liechtenstein - up to EUR 20 million or 4% of global annual turnover. The DSS oversees compliance and can impose administrative measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "liberia-ship-registry-liscr",
    "title": "Liberia Ship Registry (LISCR) - World's Second Largest Open Ship Registry Regulatory Framework",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Liberia Ship Registry, administered by the Liberian International Ship and Corporate Registry (LISCR LLC) on behalf of the Republic of Liberia, is the world's second largest ship registry with over 4,800 vessels of more than 170 million gross tonnes as at 2024 - approximately 13% of global gross tonnage. Liberia has maintained White List status on the Paris MOU port State control targeting mechanism. The registry operates under the Liberian Maritime Law (Title 21 of the Liberian Code of Laws of 1956, as amended) and is administered by LISCR LLC through its principal offices in Reston, Virginia, USA, with technical services offices worldwide. LISCR provides a full suite of flag State services including ISM Code audits, statutory surveys through authorised classification societies, STCW endorsements, and MLC 2006 inspections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "imo_solas_consolidated",
        "imo_maritime_labour_convention",
        "panama_maritime_authority"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-consolidated-2020",
      "imo-marpol-annex-i-oil-pollution",
      "imo-stcw-convention-1978-2010-manila",
      "imo-maritime-labour-convention-2006-mlc"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "liechtenstein-tvtg-blockchain-act-2019",
    "title": "Token and Trusted Technology Service Provider Act (TVTG) of 17 May 2019",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The Liechtenstein TVTG establishes a legal framework for tokens as containers of rights and mandates licensing for Trusted Technology Service Providers (TTSPs). It applies to token issuers and service providers conducting regulated activities under Articles 2 and 3, requiring compliance with prospectus-light rules (Article 58), AML/CFT obligations including FATF Travel Rule (Article 64), and supervision by the Financial Market Authority (FMA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "eu-dlt-pilot-regime-2022-858",
      "bahamas-dare-act-2020-digital-assets"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "lk-pdpa-2022",
    "title": "Sri Lanka Personal Data Protection Act No. 9 of 2022 - Data Protection Authority",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Sri Lanka's Personal Data Protection Act No. 9 of 2022 (certified on 19 March 2022 and published in the Gazette Extraordinary of the Democratic Socialist Republic of Sri Lanka), is Sri Lanka's primary personal data protection legislation establishing a comprehensive rights-based framework for the processing and protection of personal data. The Act was developed with reference to international data protection standards including the EU General Data Protection Regulation and the OECD Privacy Guidelines, reflecting Sri Lanka's commitment to digital economy development and international data flows. The supervisory authority is the Data Protection Authority of Sri Lanka (DPASL), established under the Act as an independent body responsible for oversight, enforcement, and guidance on data protection standards across both public and private sectors. Key features of Sri Lanka's Personal Data Protection Act No. 9 of 2022: (1) Scope - applies to personal data processing by any person in respect of data relating to natural persons, with applicability to both public authorities and private sector entities; (2) Data processing principles - processing must comply with: lawfulness; fairness; transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal history; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right to data portability; and right not to be subject to solely automated decisions; (6) Data Protection Officer - required for specified categories of controllers; (7) Breach notification - controllers must notify the Data Protection Authority and affected data subjects of personal data breaches; (8) Data Protection Impact Assessment - required for processing activities likely to result in high risk; (9) Cross-border transfers - personal data may only be transferred outside Sri Lanka where adequate protection or appropriate safeguards exist; and (10) Penalties - administrative penalties and criminal offences for violations. Sri Lanka's Personal Data Protection Act positions Sri Lanka as a jurisdiction with a comprehensive data protection framework supporting its growing information technology and business process outsourcing sector, digital government initiatives, and international trade.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "lk-prevention-of-money-laundering-act-5-2006",
    "title": "Prevention of Money Laundering Act, No. 5 of 2006",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Sri Lanka's Prevention of Money Laundering Act, No. 5 of 2006 criminalizes money laundering in Section 3, imposes a duty to disclose knowledge or belief of money laundering to the Financial Intelligence Unit in Section 5, provides for property tracking and monitoring in Section 12, and sets out interpretation including 'unlawful activity' in Section 35. The Section 3 offence carries imprisonment of five to twenty years and substantial fines tied to the value of the property.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "lloyd-market-bulletin-y5387-cyber-aggregation-2023",
    "title": "Lloyd's Market Bulletin Y5381 - State-backed Cyber-attack Exclusions in Standalone Cyber Policies: Mandatory Exclusion Wordings, War and State-backed Attack Carve-outs and LMA Model Clauses",
    "domain": "Insurance & Risk",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "Lloyd's Market Bulletin Y5381 (16 August 2022) requires that, from 31 March 2023 at policy inception or renewal, all standalone cyber-attack policies written at Lloyd's contain a clause excluding liability for losses arising from a state-backed cyber-attack. At minimum the exclusion must (1) exclude losses arising from a war whether declared or not where the policy lacks a separate war exclusion, (2) exclude losses from state-backed cyber-attacks that significantly impair the ability of a state to function or that significantly impair the security capabilities of a state, (3) set out a robust basis for attributing an attack to one or more states, and (4) be clear as to whether cover excludes computer systems located outside the affected state. The Lloyd's Market Association (LMA) has issued suitable model clauses (LMA21-043-PD); managing agents adopt a compliant clause unless granted a dispensation. Lloyd's later issued Y5433 (2024) reviewing state-backed cyber-attack wordings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "lloyds-delegated-authority-cyber-y5258",
    "title": "Lloyd's Market Bulletin Y5258 Delegated Authority Cyber Requirements - Binding Authorities, Coverholder Obligations and Cyber Sub-Limits",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This bulletin mandates that managing agents must include specific minimum cyber security requirements in all binding authorities that grant coverholders the ability to bind cyber policies. It also requires the application of mandatory cyber sub-limits for non-cyber policies that could be exposed to cyber risks, as detailed in Section 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "lloyds-governance-framework-2023-market-reform",
    "title": "Lloyd's of London Governance Framework 2023 - Syndicate Oversight, Managing Agent Obligations and Market Reform Blueprint",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This framework mandates that all Lloyd's managing agents establish and maintain robust governance, risk management, and internal control systems to ensure effective syndicate oversight and protect policyholders. Compliance with the Core Principles and detailed Minimum Standards, particularly those outlined in Section 2, is required to demonstrate sound and prudent management of the business.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "iso-37301-compliance-mgt",
      "uk-fca-consumer-duty-2023",
      "interagency-guidance-third-party-risk-management",
      "iso-22301-biz-continuity"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "lma-model-clauses-cyber-liability-2021",
    "title": "London Market Association (LMA) Model Cyber Liability Clauses 2021 - Coverage Scope, Exclusions and Notification Requirements",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-03-25",
    "bluf": "The London Market Association (LMA) provides standardized model clauses for cyber liability insurance policies to clarify coverage scope, define key exclusions, and establish notification duties for insured parties. These clauses, such as the Cyber Event definition (LMA5521) and the War Exclusion (LMA5522), aim to create market consistency for affirmative and non-affirmative cyber risk coverage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dora-third-party-risk-articles-28-44"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "lmaa-london-maritime-arbitration-terms-2021",
    "title": "London Maritime Arbitrators Association Terms 2021 - Arbitration Agreement Formation, Tribunal Appointment Procedures, Interlocutory Applications, Security for Costs, LMAA Small Claims Procedure (SCP), Intermediate Claims Procedure (ICP) and Award Enforcement via New York Convention",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The LMAA Terms 2021 govern the conduct of maritime arbitration in London, including procedures for tribunal appointment, interlocutory applications, and cost security. It applies to parties agreeing to arbitration under LMAA terms, particularly in disputes involving charter parties, bills of lading, and marine insurance, with enforcement under the New York Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bimco-gencon-cp-2022-charter-party",
      "imo-colregs-1972-collision-regulations",
      "athens-convention-2002-passenger-ship"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "lme-responsible-sourcing-policy-2019",
    "title": "London Metal Exchange (LME) Responsible Sourcing Requirements 2019 - LME-Approved Brands, Cobalt Guidance, Passports and Supply Chain Due Diligence Standards",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The LME Responsible Sourcing Policy 2019 mandates that all producers of nickel, cobalt, and other specified metals listed on the LME implement supply chain due diligence in accordance with the OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas. Compliance is required under LME Rule 1.35 and applies to all LME-approved brands and warehouses.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp",
      "oecd-due-diligence-minerals-supply-chains-2016"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "logistics-3pl-matrix",
    "title": "3PL Service Provider Selection",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Selection of Third-Party Logistics (3PL) service providers mandates a rigorous due diligence process aligned with established cybersecurity and operational resilience frameworks. This control enforces procurement criteria consistent with guidance from NIST Special Publication 800-161r1 and CISA Information and Communications Technology Supply Chain Risk Management Task Force recommendations, ensuring supply chain integrity. Prospective partners must demonstrate robust information security postures, substantiated by mandatory ISO 27001 certification plus a current SOC 2 Type 2 audit report. In adherence to processor obligations under EU General Data Protection Regulation Article 28, a fully executed Data Processing Addendum is required for any engagement involving personal data. Contractual service level agreements must guarantee a minimum uptime of 99.9 percent and stipulate a maximum incident response commitment of 24 hours. The financial and operational resilience requirements, reflecting principles within the Digital Operational Resilience Act's chapter on ICT third-party risk, demand suppliers maintain a minimum liability insurance coverage of five million USD and evidence annual business continuity with disaster recovery plan testing. In line with the supply chain security requirements detailed in Article 21 of EU Directive 2022/2555 (NIS2), a comprehensive assessment of the provider's ecosystem is necessary, limiting dependencies to a maximum fourth-party subcontractor tier of 2. Furthermore, a minimum cyber risk score of 85 out of 100 is required, alongside a minimum physical security audit score of 90 percent. Compliance also necessitates strict adherence to local data residency rules, which reinforces information security guidelines for supplier relationships found in ISO/IEC 27036-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-161r1-csrm-practices",
      "iso-28000-supply-chain",
      "c-tpat-minimum-security",
      "dora-ict-risk",
      "iso-20400-sustainable-procure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "logistics-3pl-slas",
    "title": "Automated 3PL Performance SLAs",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Third-Party Logistics (3PL) Service Level Agreements (SLAs) define the contractually binding performance thresholds that logistics service providers must meet for order fulfillment, warehousing, transportation, and returns management on behalf of their clients. For AI-managed logistics operations, these SLAs must be integrated into automated monitoring systems that track performance in real-time, detect violations, apply contractual penalties automatically, and escalate systemic failures to human supply chain managers. Key performance metrics typically include: order fill rate (target ≥99%), on-time-in-full (OTIF) delivery rate (target ≥98%), return processing time (target ≤24 hours), inventory accuracy (target ≥99.9%), and order cycle time. SLA penalties in logistics contracts typically range from 1-5% of the monthly service fee per percentage point below threshold, creating direct financial incentives for both parties to maintain AI-assisted monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "logistics-3pl-matrix",
      "iso-9001-quality-mgt",
      "supply-chain-risk-triage",
      "scor-fulfill",
      "iso-28000-supply-chain",
      "soc2-processing-integrity"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "logistics-bonded-warehouse",
    "title": "Bonded Warehouse Audit Protocol",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Mandatory compliance protocols for bonded warehouse operations are established to ensure strict adherence to international and national customs regulations. Under the authority of 19 U.S.C. § 1555 and the detailed requirements outlined in 19 CFR Part 19, operators must maintain absolute control over merchandise. Similarly, the EU Union Customs Code, through Articles 240-242, imposes rigorous obligations on warehouse keepers for proper procedure and fiscal supervision. The node operationalizes these legal frameworks by mandating that `duty_liability_tracking_enabled` is active and `strict_segregation_bonded_goods` is enforced to prevent commingling. Security management aligns with the ISO 28000:2007 specification and the WCO SAFE Framework principles for Customs-to-Business partnerships. This includes implementing robust C-TPAT Minimum Security Criteria, such as ensuring `perimeter_fencing_min_height_feet` is no less than 8 feet and that `physical_access_controls_active` systems are fully functional. Digital security requires that `cybersecurity_access_mfa_required` is implemented for all relevant systems. Operational integrity demands that `unauthorized_manipulation_blocked` policies are in effect, `customs_seal_logging_enforced`, and all `personnel_background_checks_valid` remain current. For continuous compliance, inventory reconciliation must occur within a period where `inventory_reconciliation_max_days` does not exceed 365, supported by `edi_customs_reporting_active` for timely declarations. Furthermore, video surveillance data requires a `cctv_retention_minimum_days` of 90, and any security incident necessitates reporting with a `max_incident_reporting_delay_hours` of no more than 24.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "c-tpat-minimum-security",
      "wco-safe-framework",
      "supply-chain-risk-triage",
      "iso-28000-supply-chain",
      "gs1-epcis-transparency",
      "customs-tapa-transport-sec"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "logistics-carbon-glec",
    "title": "Logistics Carbon Accounting (GLEC)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Logistics carbon accounting practices demonstrate strong methodological alignment with the Global Logistics Emissions Council (GLEC) Framework and full compliance with ISO 14083 standards. The operational boundary for emissions calculation is clearly defined, crucially encompassing Scope 3 outsourced logistics activities, which represents a comprehensive approach to value chain reporting. An allocation method has been properly specified, relying on a physical metric basis to distribute emissions accurately across transport services. Furthermore, the emissions calculation methodology commendably includes Well-to-Tank (WTT) values, ensuring a more complete fuel lifecycle assessment. This process utilizes mode-specific emission factors whose source has been appropriately verified, enhancing the granularity and credibility of reported figures. Data aggregation occurs on an annual basis, and the underlying information carries a data quality score of 3, indicating a moderate level of assurance. However, a significant governance gap exists due to the absence of any third-party verification statement. This lack of independent assurance presents a material risk, undermining the overall defensibility of the reported emissions data despite robust foundational adherence to recognized industry protocols and international standards for quantifying greenhouse gas emissions from transport chains.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cbam-calc"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "logistics-hs-classification",
    "title": "Automated HS Classification",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Harmonized System (HS) Classification node provides a deterministic logic framework based on the WCO General Rules for the Interpretation (GRI) to classify goods for global customs, ensuring accurate duty calculation and regulatory compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wco-safe-framework",
      "c-tpat-minimum-security",
      "supply-chain-incoterms",
      "logistics-bonded-warehouse",
      "iso-28000-supply-chain"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "logistics-hs-codes",
    "title": "Automated HS Code Classification",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Harmonized System (HS) is the international nomenclature for classifying traded products, administered by the World Customs Organization (WCO) and used by over 200 countries as the basis for customs tariffs, trade statistics, and trade compliance. Every internationally traded product must be assigned a 6-digit HS code (which countries extend to 8-10 digits for national tariff schedules), and the correct code determines: the applicable import duty rate, eligibility for trade agreement preferential tariffs (e.g., US-EU MFN rates, CPTPP preferential rates), import/export permit requirements, and whether the product is subject to antidumping duties or safeguard measures. AI agents automating customs declarations must produce accurate HS classifications - misclassification results in customs duty underpayment/overpayment, customs examination delays, penalties, and import license violations. The WCO updates the HS every five years; the current edition is HS 2022.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wco-safe-framework-standards",
      "supply-chain-incoterms",
      "c-tpat-minimum-security",
      "supply-chain-risk-triage"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "logistics-jit-inventory",
    "title": "Just-In-Time (JIT) Inventory Logic",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Just-In-Time (JIT) Inventory Logic codifies the essential operational and technical controls governing automated inventory management to ensure full compliance and mitigate risk. The node's configuration mandates that on-hand supply levels must not exceed a 5-day threshold, with procurement actions contingent upon predictive models achieving a minimum demand forecast accuracy of 95 percent. Furthermore, supplier qualification is strictly regulated, requiring a minimum reliability score of 0.98 and enforcing a maximum lead time variance of 5 percent. Systemic execution via an enabled automated order trigger is conditional upon verifiable data; consequently, data integrity validation is required for all transactional inputs. The security posture is fortified through adherence to contemporary API authentication standards, mandatory TLS 1.3 encryption for all data in transit, and strict enforcement of least privilege access controls. For comprehensive auditability and non-repudiation, an immutable transaction log is active. System performance standards demand real-time monitoring with latency not exceeding 500 milliseconds, while operational resilience is confirmed as the disruption contingency plan has been tested and verified. These interdependent rules establish a secure, efficient, and auditable framework for JIT operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "inventory-eoq-deterministic",
      "kanban-replenishment",
      "warehouse-wms-optimization",
      "supply-chain-risk-triage",
      "iso-28000-supply-chain"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "london-protocol-1996-marine-dumping",
    "title": "London Protocol 1996 - Prevention of Marine Pollution by Dumping of Wastes",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The London Protocol 1996 (Protocol to the Convention on the Prevention of Marine Pollution by Dumping of Wastes and Other Matter 1972 - 53 Contracting Parties as of April 2026, in force 2006) replaced the original London Convention 1972 with a precautionary-based reverse-list approach: all dumping at sea is prohibited except for materials listed in Annex 1 (dredged material, sewage sludge, fish wastes, vessels and platforms, inert geological materials, organic material, CO2 streams); the 2006 amendment permits sub-seabed geological storage of CO2 streams captured from industrial sources - making the London Protocol the primary international legal framework for carbon capture and storage (CCS) at sea - while the 2013 amendment (not yet in force) enables marine geoengineering activities including iron fertilisation to be permitted subject to licensing; operators in maritime industries must obtain permits for all permitted Annex 1 dumping from national authorities and report annually to the IMO.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-bbnj-agreement-2023-marine-biodiversity",
      "un-cbd-kunming-montreal-gbf-2022",
      "eu-csrd-2022-2464",
      "un-paris-agreement-ndc-implementation-guidelines"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "lr-foi-2010",
    "title": "Liberia Freedom of Information Act 2010 - Personal Data and Privacy Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Liberia enacted the Freedom of Information Act (FOIA) in 2010, which establishes a legal right of access to public information held by government bodies and public institutions and includes provisions for the protection of personal data and individual privacy in information held by public entities. The Act is administered by the Ministry of Information and the Independent Information Commission. The FOIA establishes obligations for public bodies to protect personal information of individuals from unauthorised access and disclosure, to use personal data only for the purposes for which it was collected, and to implement security measures protecting personal information held in government information systems. The Liberia Telecommunications Authority (LTA), established by the Telecommunications Act of 2007, regulates electronic communications and has issued requirements for telecommunications service providers regarding the confidentiality of subscriber personal data. Liberia does not have a standalone comprehensive personal data protection law applicable to the private sector, but the FOIA 2010, LTA regulatory framework, the Liberian Constitution's privacy protections, and the provisions of the Penal Law of Liberia together constitute the primary legal framework for personal data protection in Liberia. Liberia is a member of ECOWAS and is subject to the ECOWAS Supplementary Act on Personal Data Protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/lr-foi-2010.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "lrtap-convention-1979-transboundary-air-pollution",
    "title": "LRTAP Convention 1979 - Long-Range Transboundary Air Pollution",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Convention on Long-Range Transboundary Air Pollution (LRTAP, 1979 - 51 Parties, UNECE region, entered into force 1983) and its eight Protocols - most critically the revised Gothenburg Protocol (2012) setting binding 2020 national emission reduction commitments for SO2, NOx, NH3, NMVOCs, and PM2.5 - impose quantified air pollutant emission ceilings and technology-based emission limit values on major industrial sources in UNECE Parties; industrial operators running combustion plants, chemical facilities, agricultural operations, and road transport fleets must comply with national legislation implementing LRTAP Gothenburg Protocol ceilings, and corporate ESG reporters must disclose air pollutant emissions under CSRD ESRS E2 (pollution) with reference to the Gothenburg Protocol benchmarks that drive EU NEC Directive 2016/2284 national ceilings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aarhus-convention-1998-environmental-access",
      "un-paris-agreement-ndc-implementation-guidelines",
      "eu-csrd-2022-2464",
      "un-cbd-kunming-montreal-gbf-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ls-dpa-2012",
    "title": "Lesotho Data Protection Act 2012",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Lesotho enacted the Data Protection Act 2012 to regulate the processing of personal data in the Kingdom of Lesotho. The Lesotho Communications Authority (LCA) functions as the interim supervisory body pending establishment of a dedicated Data Protection Commissioner. The Act establishes data protection principles including lawful and fair collection, purpose limitation, data minimisation, accuracy, retention limits, security safeguards, and individual participation rights. Data subjects have rights of access and correction. Cross-border transfers are restricted to jurisdictions with comparable protection. Sensitive personal information categories require heightened conditions. The Act aligns with the Southern African Development Community (SADC) data protection standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ls-dpa-2012.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "lt-adtai-2018",
    "title": "Lithuania Law on Legal Protection of Personal Data (ADTAĮ) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Lithuania's Asmens duomenų teisinės apsaugos įstatymas (ADTAĮ - Law on Legal Protection of Personal Data), as substantially amended by Act No. XIII-1426 of 30 June 2018 to align with the EU General Data Protection Regulation and published in the Official Gazette (Teisės aktų registras), is Lithuania's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Lithuania. The GDPR is directly applicable Lithuanian law by virtue of Lithuania's EU membership. The 2018 amendments restructured the ADTAĮ to remove provisions now covered directly by GDPR while retaining national derogations and additions. The ADTAĮ was originally enacted in 1996 and has been repeatedly amended to reflect evolving EU data protection law. Enforcement: the Valstybinė duomenų apsaugos inspekcija (VDAI - State Data Protection Inspectorate) is Lithuania's independent data protection supervisory authority. The VDAI is Lithuania's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Lithuania is a Baltic state with a significant IT and financial technology sector; Lithuanian fintech companies and electronic money institutions process substantial volumes of personal data of EU residents. Lithuania has also transposed the EU's NIS2 Directive through its Law on Cybersecurity, creating parallel cybersecurity incident reporting obligations that interact with GDPR breach notification. Key Lithuanian national provisions: (1) Age of digital consent: Lithuania has set the age of consent for information society services at 14 years (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 14 require parental or guardian consent; (2) Employment - the Lithuanian Labour Code (Darbo kodeksas, Act No. XII-2603 of 14 September 2016 as amended) governs employment relationships and the processing of employee personal data alongside GDPR; employee monitoring requires advance notification; (3) Freedom of expression - exemptions for journalistic, academic, artistic, and literary processing aligned with GDPR Art. 85 and the Lithuanian constitutional freedom of expression (Lithuanian Constitution, Art. 25); (4) Special category data - processing of sensitive personal data (health, biometric, genetic data) is subject to additional conditions under the ADTAĮ; (5) Public sector - Lithuanian public authorities are subject to ADTAĮ provisions and applicable Lithuanian administrative law. Fines: GDPR administrative fines apply in Lithuania - up to EUR 20 million or 4% of global annual turnover. The VDAI has imposed administrative fines and issued enforcement decisions, including against public authorities and private sector entities in employment and digital services contexts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "lu-loi-1-aug-2018",
    "title": "Luxembourg Data Protection Law of 1 August 2018 - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Luxembourg's Law of 1 August 2018 on the Organisation of the Commission Nationale pour la Protection des Données and the General Data Protection Framework (Loi du 1er août 2018 portant organisation de la Commission nationale pour la protection des données et du régime général sur la protection des données), published in the Mémorial A No. 686 on 1 August 2018, is Luxembourg's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Luxembourg. The GDPR is directly applicable Luxembourg law by virtue of Luxembourg's EU membership. The Law of 1 August 2018 provides national derogations, additions, and specifications that the GDPR permits EU member states to adopt and repeals the prior Luxembourg data protection law of 2 August 2002. Luxembourg is a unique jurisdiction of particular strategic importance in EU and global data protection: it is home to the registered offices and data processing operations of major global companies including Amazon (Amazon EU SARL registered in Luxembourg), PayPal, Skype, eBay, and numerous global financial institutions. Amazon has its European customer data processing anchored in Luxembourg, making the CNPD a significant supervisory authority for Amazon's EU data operations. Luxembourg's financial sector is the largest investment fund centre in Europe after the United States and a major banking and insurance hub, with significant personal data processing regulated by GDPR and sector-specific financial regulation. Enforcement: Commission Nationale pour la Protection des Données (CNPD - Luxembourg) is Luxembourg's independent data protection supervisory authority. The CNPD is Luxembourg's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Note: the Luxembourg CNPD should not be confused with the Portuguese CNPD (Comissão Nacional de Proteção de Dados) - both use the same acronym but are distinct authorities. Key Luxembourg national provisions: (1) Age of digital consent: Luxembourg has set the age of consent for information society services at 16 years (GDPR default maintained); (2) Financial sector - Luxembourg's significant financial sector (investment funds, banking, insurance) is subject to GDPR and sector-specific data protection obligations under supervision by the Commission de Surveillance du Secteur Financier (CSSF - Luxembourg Financial Regulator); CSSF and CNPD have separate but coordinated oversight roles; (3) Employment context - Luxembourg labour law (Code du Travail) provides provisions on employee data and monitoring; (4) Freedom of expression - exemptions for journalistic, literary, and artistic processing; (5) Health data - specific provisions for health data processing in Luxembourg's public health system. Fines: GDPR administrative fines apply in Luxembourg - up to EUR 20 million or 4% of global annual turnover. The CNPD has imposed significant fines including a EUR 746 million fine against Amazon Europe Core SARL (July 2021) for GDPR violations related to Amazon's advertising targeting system and data processing practices - the largest GDPR fine at the time of issuance and subsequently upheld by the Luxembourg Administrative Tribunal. The Amazon fine was reduced on appeal but remains one of the most significant GDPR enforcement actions globally.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "luxembourg-space-resources-law-2017",
    "title": "Luxembourg Law on the Exploration and Use of Space Resources 2017 (Loi du 20 juillet 2017)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Luxembourg's Law of 20 July 2017 was the first European national law to recognise private operators' right to own and commercially exploit space resources extracted from asteroids, the Moon, or other celestial bodies, requiring a government authorisation for each mission and establishing the Luxembourg Space Agency (LSA) as regulator. The Law is framed as compatible with the Outer Space Treaty's Article II non-appropriation principle because it grants rights over resources - not territorial sovereignty over celestial bodies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_space_act_2015",
        "un_outer_space_treaty_art_ii",
        "copuos_resource_discussions"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "lv-fpdal-2018",
    "title": "Latvia Personal Data Processing Law 2018 (FPDAL) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Latvia's Fizisko personu datu apstrādes likums (FPDAL - Personal Data Processing Law), adopted by the Saeima (Latvian Parliament) on 21 November 2018 and published in the Latvijas Vēstnesis (Official Gazette) on 4 December 2018 (No. 238 (6324)), entered into force on 5 December 2018 and is Latvia's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Latvia. The GDPR is directly applicable Latvian law by virtue of Latvia's EU membership. The FPDAL provides national derogations, additions, and specifications that the GDPR permits EU member states to adopt and repeals the prior Latvian Personal Data Protection Law of 23 March 2000. Enforcement: the Datu valsts inspekcija (DVI - Data State Inspectorate) is Latvia's independent data protection supervisory authority. The DVI is Latvia's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Latvia is a Baltic state with a significant digital economy and cross-border data flows with EU member states and Russia; Latvia's proximity to the Russian Federation and history of Soviet-era personal data collection makes data sovereignty particularly sensitive in the Latvian legal and political context. The Baltic legal tradition shares similarities with the Estonian and Lithuanian GDPR implementation approaches. Key Latvian national provisions: (1) Age of digital consent: Latvia has set the age of consent for information society services at 13 years (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 13 require parental or guardian consent; (2) Employment - the Darba likums (Labour Law, in force 1 June 2002 as amended) governs employment relationships and the processing of employee personal data alongside GDPR; employers must inform employees of monitoring before it is implemented; (3) Freedom of expression - the FPDAL contains exemptions for journalistic, academic, artistic, and literary processing aligned with GDPR Art. 85 and the Latvian constitutional freedom of expression (Satversme Art. 100); (4) Public sector processing - Latvian public authorities are subject to the FPDAL provisions on official authority processing as well as applicable Latvian administrative law; (5) Research and statistics - extended processing for scientific research, statistics, and archiving in the public interest is permitted with appropriate safeguards. Fines: GDPR administrative fines apply in Latvia - up to EUR 20 million or 4% of global annual turnover. The DVI has imposed administrative fines and issued enforcement decisions covering public authority processing, employment data, and digital service sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ly-gaci-framework",
    "title": "Libya GACI Framework - AU Malabo Convention and Constitutional Privacy Obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Libya's regulatory framework for electronic communications and information technology is overseen by the General Authority for Communications and Informatics (GACI), which is responsible for licensing and regulating telecommunications and ICT services including oversight of personal data obligations in the communications sector. The Libyan Constitutional Declaration of 2011 and subsequent constitutional provisions establish fundamental rights including the right to privacy of private and family life and the inviolability of correspondence and private communications. As a member state of the African Union, Libya is subject to the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014), which provides the applicable regional standard for personal data protection. Libya does not have a standalone comprehensive personal data protection law currently in force. The constitutional privacy framework, GACI regulatory requirements for licensed telecommunications and ICT operators, and AU Malabo Convention principles constitute the reference legal framework for personal data protection obligations in Libya. Operators processing personal data in Libya must respect constitutional privacy rights, comply with GACI licensing and regulatory requirements, and implement personal data processing practices consistent with the AU Malabo Convention framework. The ongoing governance challenges in Libya since 2011 have affected the coherence of the regulatory environment, and organisations should seek current guidance from local legal counsel before processing personal data in Libya.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ly-gaci-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ma-decret-2-22-431-2023-marches-publics-tgr-portal",
    "title": "Morocco Decree 2-22-431 of 8 March 2023 on Public Procurement (Decret relatif aux marches publics) and the TGR Marches Publics Portal",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Moroccan Decree No. 2-22-431 of 14 Sha'ban 1444 H corresponding to 8 March 2023 on Public Procurement (Decret n. 2-22-431 du 14 chaabane 1444 (8 mars 2023) relatif aux marches publics) effective 9 September 2023 is the principal Moroccan regulatory instrument governing procurement of works, supplies, and services by the Kingdom's public entities including ministries, the General Treasury and central public administration, local collectivities (regions, prefectures, provinces, communes), state-owned enterprises, public establishments, and other public-sector entities subject to the public procurement regime. The 2023 Decree replaced the prior Decree 2-12-349 of 20 March 2013 (which had itself replaced Decree 2-06-388 of 5 February 2007) and substantially modernised the Moroccan procurement framework. The General Treasury of the Kingdom (Tresorerie Generale du Royaume / TGR) operates the central Moroccan e-procurement portal (marchespublics.gov.ma) which is mandatory for in-scope procurement publication and bid receipt. The Commission Nationale de la Commande Publique (CNCP / National Public Procurement Commission) under the Ministry of Economy and Finance is the policy coordination body. Procurement methods established by the 2023 Decree comprise (a) Appel d'offres ouvert (Open Call for Tenders, the default open procedure), (b) Appel d'offres restreint (Restricted Call for Tenders, with prequalification), (c) Appel d'offres avec presselection (Call with preselection), (d) Procedure negociee (Negotiated Procedure, under prescribed exceptions including emergency, sole supplier for technical reasons, prior unsuccessful tendering, and small-value below thresholds), (e) Concours (Design Contest), (f) Bons de commande (Purchase Orders, for small-value below prescribed thresholds), and (g) Dialogue competitif (Competitive Dialogue, for complex acquisitions). The 2023 Decree introduced strengthened integrity provisions including supplier debarment under the lists of excluded suppliers, mandatory beneficial ownership disclosure, anti-corruption commitments, and reinforced complaint resolution through the Commission Nationale de la Commande Publique. The 2023 Decree also strengthens domestic preference provisions for Moroccan suppliers and SMEs subject to trade-agreement constraints. Morocco is NOT a party to the WTO Government Procurement Agreement (GPA) but is an observer. Morocco is a party to the EU-Morocco Association Agreement (1996), the US-Morocco Free Trade Agreement (2004), the African Continental Free Trade Area (AfCFTA), and UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5",
      "wto-revised-government-procurement-agreement-2012"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ma-loi-09-08",
    "title": "Morocco Personal Data Protection Law No. 09-08 2009 - CNDP",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Morocco's Loi No. 09-08 relative à la protection des personnes physiques à l'égard du traitement des données à caractère personnel (Law No. 09-08 on the Protection of Natural Persons with Regard to the Processing of Personal Data) - promulgated by Royal Decree (Dahir) No. 1-09-15 on 22 Safar 1430 Hijri corresponding to 18 February 2009, and published in the Bulletin Officiel du Royaume du Maroc (Official Gazette) - entered into force on 23 April 2009, making Morocco one of the earliest North African and Arab states to enact comprehensive personal data protection legislation. The law is complemented by Decree No. 2-09-165 of 25 June 2009 fixing the organisation and operation of the CNDP. The supervisory authority is the Commission Nationale de contrôle de la Protection des Données à caractère Personnel (CNDP - National Commission for Control of Personal Data Protection), an independent administrative authority established under Law No. 09-08. Morocco has ratified the Council of Europe Convention on the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108) and its Additional Protocol (ETS 181), reinforcing Morocco's data protection framework within the Council of Europe's international data protection architecture. Key features of Morocco's Law No. 09-08: (1) Scope - applies to all processing of personal data by natural or legal persons established in Morocco, and to all processing where Moroccan law is applicable by virtue of international public law principles; (2) Data processing principles - personal data processing must comply with: lawfulness; consent; purpose limitation; proportionality; accuracy and currency; security; and confidentiality; (3) Sensitive personal data - the law prohibits the collection and processing of data revealing: racial or ethnic origin; political opinions; religious convictions; trade union membership; health data; and sexual life; processing of sensitive data is permitted only in strictly defined circumstances (consent, legal obligation, vital interests, substantial public interest); (4) Lawful processing bases - consent; contractual necessity; legal obligation; vital interests; public interest task; or legitimate interests of the controller; (5) Data subject rights - right of access; right of rectification; right of opposition; and right to object to direct marketing; (6) Prior declaration and authorisation - Law No. 09-08 introduces a two-tier registration system: prior declaration (déclaration préalable) to the CNDP for standard processing; and prior authorisation (autorisation préalable) from the CNDP for processing of sensitive personal data, biometric data, genetic data, or data processed by state security services; (7) Cross-border data transfers - personal data may only be transferred to countries providing adequate protection for personal data; the CNDP must authorise transfers to non-adequate countries; (8) CNDP powers - the CNDP receives declarations and authorisation applications; investigates complaints; conducts on-site inspections; issues formal notices (mises en demeure); issues binding orders; and refers cases for criminal prosecution; (9) Criminal penalties - violations of Law No. 09-08 carry criminal penalties: fines of MAD 10,000 to MAD 300,000 (approximately USD 1,000 to USD 30,000) and imprisonment of one month to two years for serious violations; (10) Data Protection Officer - controllers conducting processing subject to prior authorisation are encouraged to designate a Correspondant à la Protection des Données (CPD), a voluntary role equivalent to a DPO. Morocco has been working on a modernised data protection law to align with GDPR standards and replace Law No. 09-08 for part of its scope, reflecting the country's growing integration with European digital markets and its status as a major nearshore services and outsourcing hub for France, Spain, and other EU member states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "macau-gaming-law-16-2001",
    "title": "Law No. 16/2001 - Casino Concession Framework, DICJ Supervision and Gaming Operator Obligations",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This law establishes the legal framework for casino concessions in Macau, requiring all gaming operators to obtain a concession contract approved by the Chief Executive and to operate under the supervision of the Direcção de Inspecção e Coordenação de Jogos (DICJ). Key obligations are defined in Article 5 and Article 12, including financial transparency, anti-money laundering compliance, and operational integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-articles-28-44-third-party-ict-risk",
      "owasp-asvs-l3"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "madrid-system-trademarks",
    "title": "Madrid System (Trademarks)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the Madrid System for the International Registration of Marks is affirmed based on current data parameters. The application fulfills essential procedural and jurisdictional prerequisites, as the system confirms the applicant possesses a basic mark and originates from a member contracting party. The filing correctly extends protection to 5 designated countries, all verified as Madrid Union members. Substantive review shows the application's scope of goods and services is valid and its filing language is permissible. The registration's lifecycle is proceeding without administrative or legal friction; WIPO has issued no irregularity notice, and critically, no jurisdiction has issued a provisional refusal of protection. The international registration remains within the five-year dependency period, linking its validity to the foundational home mark, while the holder's ownership data is current. No immediate maintenance is required, as its 10-year renewal is not due in the next 12 months, indicating a compliant and stable international trademark registration under the Protocol's centralized framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-trademark-stds",
      "wipo-copyright-treaty"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "malaysia-electricity-supply-act-1990-energy-commission",
    "title": "Malaysia Electricity Supply Act 1990 (Act 447) - Suruhanjaya Tenaga Licensing Framework",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Malaysia's Electricity Supply Act 1990 (Act 447, as amended through 2015) establishes Suruhanjaya Tenaga (ST - Energy Commission) as the electricity and piped gas regulator; requires ST licences for generation, transmission, distribution, and supply; mandates safety standards and wiring inspection; sets penalties of up to MYR 500,000 for unlicensed supply; and is supplemented by the Electricity Regulations 1994 governing technical standards and consumer protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "japan-electricity-business-act-1964-meti"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "malaysia-immigration-act-1959-63-jabatan-imigresen",
    "title": "Malaysia Immigration Act 1959/63 - Jabatan Imigresen Employment Pass and Residency Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Malaysia's Immigration Act 1959/63 (Act 155) administered by Jabatan Imigresen Malaysia (Immigration Department of Malaysia) under the Home Ministry (KDN) governs entry, stay, and employment of foreigners in Malaysia. The Act provides for Employment Pass (EP) categories I, II, and III based on salary and role; Dependant Pass; Long-Term Social Visit Pass; and Professional Visit Pass. Malaysia launched the DE Rantau Digital Nomad Pass in 2022 for remote workers. The Malaysia My Second Home (MM2H) Programme was significantly tightened in 2021 with a new RM 1,000,000 deposit requirement for Peninsular Malaysia. Under s.56 of the Act, illegal entry is punishable by imprisonment up to 5 years and caning (up to 6 strokes for males). Employers of illegal foreign workers face fines up to RM 50,000 per worker. Work Permit levy applies to foreign workers in approved sectors. The Foreign Workers' Levy (Levi PLKS) funds social protection for migrant workers. ASEAN nationals benefit from Mutual Recognition Arrangements for professional services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "employment_restriction_act",
        "asean_mra",
        "de_rantau",
        "social_protection",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "malaysia-mda-samd-2026",
    "title": "Malaysia Medical Device Authority (MDA) SaMD & Digital Health Framework 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "MDA aligns SaMD classification with IMDRF while requiring local registration and cybersecurity testing. 2026 guidance introduces fast-track for AI-enabled devices with reference approvals from FDA, CE, or HSA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "malaysia-pdpa-2010-personal-data-protection",
    "title": "Personal Data Protection Act 2010 (Act 709)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Malaysia Personal Data Protection Act 2010 (PDPA) governs the processing of personal data in commercial transactions, requiring organizations ('data users') to comply with seven core Data Protection Principles. The Act mandates explicit consent for processing sensitive personal data (Section 40) and restricts the transfer of personal data to countries outside a government-whitelisted list unless specific conditions are met (Section 129).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-privacy-guidelines-2013",
      "apec-cbpr-system-2011"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "malta-gaming-authority-igaming-remote-gaming-regulations-2004",
    "title": "Malta Gaming Authority - iGaming Remote Gaming Licence (MGA/RGL)",
    "domain": "Gaming & Gambling",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Malta Gaming Act (Cap. 583) and Gaming Regulations (S.L. 583.07) establish the Malta Gaming Authority (MGA) as the regulator for iGaming operators licensed in Malta; MGA licences are recognised across EU member states; operators must comply with Gaming Authorisations Regulations, Player Protection Directive, and MGA AML/CTF requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "malta-gaming-authority-mga-igaming-licence-2021",
    "title": "Malta Gaming Authority - B2C Gaming Service Licence Requirements and Player Protection Framework",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The Malta Gaming Authority (MGA) is the principal licensing authority for B2C iGaming operators globally, with MGA licences recognised across 30+ jurisdictions. MGA's Player Protection Directive (Directive 2 of 2018) and Gaming Authorisation and Compliance Directive (Directive 1 of 2018) impose comprehensive requirements on AI-driven iGaming platforms. The MGA Player Protection Framework requires operators to implement responsible gambling tools including reality checks, session time limits, deposit limits, and self-exclusion. AI bonus engines and marketing personalisation systems must comply with MGA Directive 2 Section 4 bonus and promotional offer restrictions. Non-compliance carries financial penalties up to EUR 500,000 and licence suspension under Article 48 Gaming Act Cap. 583.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standards",
        "frameworks",
        "regulations",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "malta-gaming-authority-mga-regulations-2018",
    "title": "Malta Gaming Authority (Remote Gaming) Regulations, 2018 - Licence Types (B2C/B2B), Licence Conditions, Player Protection, Responsible Gaming, Technical Standards and MGA Enforcement Powers",
    "domain": "Gaming & Gambling",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The MGA Regulations 2018 establish a comprehensive licensing and compliance framework for remote gaming operators in Malta, requiring adherence to strict player protection, anti-money laundering, technical integrity, and responsible gaming obligations under Regulation 18 and Part IV. Applies to all B2C and B2B remote gaming licensees operating under the Malta Gaming Authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "eu-gdpr-online-gaming-data-protection",
      "curacao-gaming-control-board-ordinance-2023",
      "denmark-gambling-act-2012-spillemyndigheden",
      "alderney-egambling-regulations-2009"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "malta-mga-gaming-regulations-2018",
    "title": "Malta Gaming Authority (MGA) Gaming Regulations 2018",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The MGA Gaming Regulations 2018 establish licensing categories, operational standards, and player protection obligations for all gaming operators in Malta, requiring compliance with Articles 7-15 on licensing conditions, anti-money laundering (Article 24), and responsible gaming (Article 31). Applies to remote, land-based, and B2B gaming licensees.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l3",
      "eu-dora-articles-28-44-third-party-ict-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "malta-mga-remote-gaming-regulations-2004-licensed-operator-obligations",
    "title": "Malta MGA Remote Gaming Licence - Operator Obligations Under Gaming Authorisations Regulations 2018",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Malta Gaming Authority (MGA) Gaming Authorisations Regulations (L.N. 243 of 2018) require B2C remote gambling operators to hold an MGA licence to serve EU and international markets. Operators must comply with player protection requirements including self-exclusion, spending limits, and responsible gambling measures, as well as AML/CTF obligations and technical auditing requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-online-gambling-services-4amld-aml-due-diligence"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "malware-incident-prevention-handling",
    "title": "Guide to Malware Incident Prevention and Handling for Desktops and Laptops",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2013-07-01",
    "bluf": "Malware, also known as malicious code, refers to a program that is covertly inserted into another program with the intent to destroy data, run destructive or intrusive programs, or otherwise compromise the confidentiality, integrity, or availability of the victim’s data, applications, or operating system. Malware is the most common external threat to most hosts, causing widespread damage and disruption and necessitating extensive recovery efforts within most organizations. This publication provides recommendations for improving an organization’s malware incident prevention measures. It also gives extensive recommendations for enhancing an organization’s existing incident response capability so that it is better prepared to handle malware incidents, particularly widespread ones.\nThis revision of the publication updates material throughout to reflect the changes in threats and incidents. Unlike most malware threats several years ago, which tended to be fast-spreading and easy to notice, many of today’s malware threats are more stealthy, specifically designed to quietly, slowly spread to other hosts, gathering information over extended periods of time and eventually leading to exfiltration of sensitive data and other negative impacts. Organizations should develop and implement an approach to malware incident prevention based on current and future attack vectors, incorporating policy, awareness programs, vulnerability and threat mitigation, and defensive architecture.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "marketing-attribution-models",
    "title": "Marketing Attribution",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Organizational adherence to marketing attribution standards mandates a comprehensive, multi-faceted approach to measurement and reporting. Prevailing regulations require the concurrent implementation of both a Multi-Touch Attribution (MTA) framework and a Marketing Mix Modeling (MMM) framework. Established guidelines further demand the functional integration of these MTA and MMM systems to provide a holistic view of marketing performance. Critically, reliance solely on last-touch attribution models is expressly prohibited, as such single-point methodologies are deemed insufficient for accurate contribution analysis. To ensure analytical validity, all attribution outputs must undergo statistical significance testing, with results demonstrating a minimum significance level represented by a p-value of 0.05 or lower to be considered sound. Operational transparency is paramount; therefore, comprehensive documentation detailing model architecture and assumptions must be maintained for regulatory review. Concurrently, periodic data source auditing is compulsory to verify the integrity and provenance of all input data. All models must undergo rigorous re-validation at a minimum frequency of every ninety days to account for market dynamics. A formal Return on Investment (ROI) calculation must also be executed to substantiate expenditure and demonstrate financial impact. For governance and audit purposes, all associated records are subject to a mandatory data retention period of thirty-six months. Finally, any processing of personal information within these attribution activities strictly requires explicit user consent, aligning with fundamental data privacy principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ccpa-cpra-optout-sale",
      "eprivacy-cookie-directive",
      "gdpr-art-21-marketing-optout",
      "iab-tcf-v2-2-consent",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "marpol-annex-i-oil-pollution-prevention-ships",
    "title": "International Convention for the Prevention of Pollution from Ships (MARPOL), Annex I: Regulations for the Prevention of Pollution by Oil",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "MARPOL Annex I mandates that all ships over 400 gross tonnage must be equipped with oil filtering equipment (Regulation 14) to ensure any discharge of oily mixtures has an oil content not exceeding 15 parts per million, and must maintain a detailed Oil Record Book (Regulations 17 & 34) to log all oil transfers, discharges, and disposals, with near-zero discharge permitted in designated Special Areas (Regulation 15).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-stcw-convention-manila-2010"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "marrakesh-treaty-2013-print-disabilities",
    "title": "Marrakesh Treaty to Facilitate Access to Published Works for Persons Who Are Blind, Visually Impaired or Otherwise Print Disabled (2013)",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Marrakesh Treaty requires contracting parties to implement limitations and exceptions in copyright law to permit the creation and cross-border exchange of accessible format copies of published works for beneficiaries who are blind, visually impaired, or otherwise print disabled, as defined under Article 4 and implemented through authorized entities. The treaty facilitates access via authorized entities that comply with non-commercial and beneficiary verification requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-1886-2024-literary-artistic-works"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "marshall-islands-ship-registry-rmis",
    "title": "Marshall Islands Ship Registry (RMIS) - Republic of the Marshall Islands Maritime Administrator",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Republic of the Marshall Islands (RMI) Ship Registry, administered by the Republic of the Marshall Islands Maritime Administrator (RMIS) through International Registries Inc. (IRI) offices worldwide, is among the world's three largest ship registries with over 4,700 vessels of more than 140 million gross tonnes as at 2024. The Marshall Islands Registry consistently achieves White List status on the Paris MOU port State control mechanism and has been recognised as a high-quality, technologically advanced open registry. The registry operates under the Marshall Islands Maritime Act (Title 31 of the Marshall Islands Revised Code) and provides a full range of flag State services. The RMI is an IMO Member State and has ratified all major IMO conventions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "imo_solas_consolidated",
        "imo_maritime_labour_convention",
        "panama_maritime_authority"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-consolidated-2020",
      "imo-marpol-annex-i-oil-pollution",
      "imo-stcw-convention-1978-2010-manila",
      "imo-maritime-labour-convention-2006-mlc"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mas-notice-637-risk-based-capital-singapore",
    "title": "MAS Notice 637 - Risk Based Capital Adequacy Requirements for Banks Incorporated in Singapore",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation sets out the risk-based capital adequacy and leverage ratio requirements for locally-incorporated banks in Singapore, including the methodology for calculating capital ratios, internal capital adequacy assessment processes, and public disclosure obligations. It applies to Full Banks and Wholesale Banks incorporated in Singapore under the Banking Act 1970 sections 10(2), 10A(1), 10B(1), and 65(2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "basel-iii-capital",
      "apra-cps-230-resilience",
      "accounting-ifr-13",
      "bank-provisioning-emerging-market-economies"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mas-tr-management-sg",
    "title": "MAS TRM Guidelines (Singapore)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Monetary Authority of Singapore (MAS) Technology Risk Management (TRM) Guidelines are the gold standard for financial technology governance in Asia-Pacific. it provides a comprehensive framework for the management of the IT risk, the security of the critical systems, and the oversight of the digital banking infrastructure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "bcbs-principles-sound-management-operational-risk",
      "cpmi-iosco-cyber-resilience-fmi",
      "hkma-tm-g-1-tech-risk",
      "eba-outsourcing-guide",
      "interagency-guidance-third-party-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mc-dp-law-2009",
    "title": "Monaco Law No. 1.165 on Personal Data Protection (as amended) - CCIN",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Monaco's Law No. 1.165 of 17 December 1993 on the Automated Processing of Personal Information, significantly reformed by Law No. 1.353 of 4 December 2008 (entering into force in 2009) and further updated by subsequent sovereign ordinances and legislative amendments progressively aligning Monaco's data protection framework with European standards, constitutes Monaco's primary personal data protection legislation. Monaco is a sovereign microstate in Western Europe with a civil law legal system closely associated with France; although not a member of the European Union, Monaco participates in the EU Customs Union and has deep economic and institutional ties with France and the EU, driving progressive alignment of Monaco's data protection framework with EU GDPR standards. The supervisory authority is the Commission de Contrôle des Informations Nominatives (CCIN), an independent constitutional institution established under Monaco's legal framework whose mandate covers oversight and enforcement of personal data protection standards throughout the Principality. Key features of Monaco's personal data protection framework as amended: (1) Scope - applies to personal data processing by persons established in Monaco or processing data of individuals in Monaco; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; proportionality; accuracy; storage limitation; and security; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual life; criminal records; and financial status; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to deletion; and right to object to processing; (6) CCIN notification - controllers must notify the CCIN before commencing processing activities; the CCIN maintains a register of processing activities; (7) Security obligations - controllers must implement technical and organisational security measures appropriate to the risk; (8) Cross-border transfers - personal data may only be transferred outside Monaco to countries providing adequate protection or with CCIN authorisation; (9) CCIN enforcement - investigates complaints, conducts inspections, issues recommendations and formal notices, and may impose sanctions; and (10) Progressive GDPR alignment - Monaco's framework has been progressively aligned with EU GDPR standards through successive legislative reforms reflecting Monaco's close relationship with the EU. Monaco's data protection framework supports its position as a leading wealth management, private banking, and luxury services centre serving high-net-worth individuals from across Europe and beyond.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mcp-enterprise-auth",
    "title": "Model Context Protocol (MCP) Enterprise Security",
    "domain": "Workflow Automation",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Standardized security protocols for establishing trust, authenticating context, and limiting data exposure between enterprise data sources and LLM agents using MCP.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ieee-3931-discovery"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "md-law-131-2015-public-procurement-pap-mtender",
    "title": "Moldova Law No. 131 of 3 July 2015 on Public Procurement as amended and MTender Platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Republic of Moldova Law No. 131 of 3 July 2015 on Public Procurement (Legea privind achizitiile publice / Zakon o gosudarstvennykh zakupkakh) effective 1 May 2016 as substantially amended over time (most recently by Law No. 169/2022 effective 1 January 2023 modernisation amendments aligning with EU procurement directives 2014/24/EU and 2014/25/EU under the EU-Moldova Association Agreement DCFTA), is the principal Moldovan statute governing procurement of goods, works, and services by contracting authorities including the central public administration (ministries, agencies, sub-agencies), Parliament, the President's Office, the Constitutional Court, the Supreme Court, the General Prosecutor's Office, local public administration bodies of first and second tiers (rayons, municipalities, communes), state-owned enterprises with majority state participation, public-sector institutions, and other contracting authorities subject to EU procurement directive scope. Law 131/2015 substantially modernised the Moldovan procurement regime aligning with the EU procurement directives as part of the EU-Moldova Association Agreement DCFTA (in force 2016) Chapter Eight (Public Procurement) approximation obligations. The Public Procurement Agency (Agentia Achizitii Publice / AAP, tender.gov.md) under the Ministry of Finance is the central regulatory authority responsible for procurement regulation, oversight, electronic procurement platform operation, and procurement guidance. The MTender platform (mtender.gov.md, achizitii.md) is the mandatory federal e-procurement platform for in-scope procurement. The National Agency for Solving Complaints (Agentia Nationala pentru Solutionarea Contestatiilor / ANSC) is the specialised body for procurement complaints. Procurement methods established by Law 131/2015 art. 31 to 56 comprise (a) Open Tender (Licitatie deschisa, the default open public procedure), (b) Restricted Tender (Licitatie restransa, with prequalification), (c) Competitive Dialogue (Dialog competitiv, for complex acquisitions), (d) Negotiated Procedure with Publication (Procedura negociata cu publicare anuntului de participare), (e) Negotiated Procedure without Publication (Procedura negociata fara publicare anuntului, under prescribed exceptions in art. 56 including emergency and sole-source), (f) Request for Quotations (Cerere a ofertelor de pret), (g) Innovation Partnership (Parteneriat pentru inovare), (h) Design Contest (Concurs de solutii), and (i) Low-Value Procurement (Achizitia publica de mica valoare, for prescribed lower-value contracts). The Court of Accounts of the Republic of Moldova conducts ex-post procurement audit. The Anticorruption Prosecution (Procuratura Anticoruptie) has investigative jurisdiction over procurement-related corruption. Moldova is in WTO accession in the procurement chapter and is NOT yet a party to the WTO Government Procurement Agreement (GPA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "md-pdp-law-2011",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "md-pdp-law-2011",
    "title": "Moldova Law on Personal Data Protection No. 133 of 2011 - CNPDCP",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Moldova's Law on Personal Data Protection No. 133 of 8 July 2011 (Legea Republicii Moldova privind protecţia datelor cu caracter personal nr. 133 din 08.07.2011) - published in Monitorul Oficial No. 170-175 of 14 October 2011 and entering into force on that date - is Moldova's primary personal data protection legislation. The law was enacted in the context of Moldova's Association Agreement with the European Union (signed 2014, in force 2016) and has been amended progressively to align with EU GDPR standards as part of Moldova's EU accession aspirations. Moldova received EU candidate status in June 2022, accelerating the GDPR alignment process. The supervisory authority is the National Center for Personal Data Protection (Centrul Naţional pentru Protecţia Datelor cu Caracter Personal - CNPDCP), an autonomous public authority established under the Law and responsible for receiving notifications, investigating complaints, conducting inspections, and enforcing the Law. Key features of Moldova's Law No. 133 of 2011: (1) Scope - applies to personal data processing by controllers established in Moldova or processing data of Moldovan data subjects regardless of establishment; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to object; right to restriction; right to data portability (introduced by GDPR alignment amendments); rights related to automated decision-making; (6) Data controller notification - controllers must notify the CNPDCP before commencing processing activities; (7) Data Protection Officer - required for public authorities and organisations processing personal data on a large scale; (8) Breach notification - controllers must notify the CNPDCP of personal data breaches within 72 hours of awareness, mirroring the GDPR timeline; (9) Cross-border transfers - personal data may only be transferred to countries with adequate protection or subject to CNPDCP-approved safeguards; (10) Penalties - administrative sanctions for violations of the Law. Moldova's Law, progressively aligned with GDPR, is directly relevant to EU-Moldova data flows as Moldova advances toward EU membership.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mdr-annex-xiv-2026",
    "title": "EU MDR Annex XIV - Clinical Evaluation and Post-Market Clinical Follow-up",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "Requirements for clinical evaluation plans, clinical investigations, and continuous post-market clinical follow-up (PMCF). 2026 updates strengthen requirements for AI/ML devices and real-world evidence usage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "mdr-annex-xvi-2026",
    "title": "EU MDR Annex XVI - Products Without Intended Medical Purpose",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "Requirements for aesthetic devices, wellness products, and other non-medical purpose items that fall under MDR scope. 2026 clarifications address AI-enabled wellness tools and common specifications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "me-pdpa-2017",
    "title": "Montenegro Law on Personal Data Protection No. 79/2017 - AZLP ME",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Montenegro's Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti), adopted by the Parliament of Montenegro in 2017 as Official Gazette of Montenegro No. 79/2017 and significantly amended in 2021 (Official Gazette of Montenegro No. 86/2021) to align comprehensively with the EU General Data Protection Regulation, is Montenegro's primary personal data protection legislation establishing a GDPR-equivalent rights-based framework. Montenegro received EU candidate status in 2010 and has been among the most advanced Western Balkans EU accession candidates, with accession negotiations opened in 2012 and data protection reform forming part of the EU accession obligations covering Judiciary and Fundamental Rights. The supervisory authority is the Agency for Personal Data Protection and Free Access to Information (Agencija za zaštitu podataka o ličnosti i slobodan pristup informacijama - AZLP ME), an independent institution whose mandate covers both personal data protection and freedom of information in Montenegro. Key features of Montenegro's Law on Personal Data Protection as amended: (1) Scope - applies to personal data processing by public authorities, legal entities, and individuals established in Montenegro or processing data of individuals located in Montenegro regardless of establishment location; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right not to be subject to solely automated decisions; and right to data portability; (6) Data Protection Officer - required for public authorities, organisations conducting large-scale systematic monitoring, and organisations processing sensitive personal data on a large scale; (7) Breach notification - controllers must notify the AZLP ME within 72 hours of becoming aware of a personal data breach likely to result in risk to data subjects; high-risk breaches require data subject notification; (8) Data Protection Impact Assessment - required for high-risk processing aligned with GDPR standards; (9) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or using AZLP ME-approved safeguards; and (10) Administrative fines - graduated fines for violations. Montenegro's Law is among the most GDPR-aligned data protection frameworks in the Western Balkans, positioning Montenegro strongly in its EU accession trajectory and supporting its growing digital economy and tourism sector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "medical-device-esg-sustainability-2026",
    "title": "Medical Device ESG & Sustainability Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Medical device manufacturers face growing ESG obligations including carbon footprint reporting, sustainable design, conflict minerals due diligence, plastic reduction, circular economy principles (remanufacturing, recycling), and supply chain transparency. The EU Green Deal, SEC climate rules, and national requirements are driving mandatory sustainability reporting and integration into risk management and technical documentation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "medical-device-post-market-surveillance-pms-2026",
    "title": "Medical Device Post-Market Surveillance (PMS) & Vigilance Systems - Global Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Manufacturers must maintain proactive, systematic post-market surveillance systems to monitor device performance, detect trends, and take corrective actions. This includes Periodic Safety Update Reports (PSUR), Post-Market Clinical Follow-up (PMCF), trend reporting, and vigilance systems. Regulators (EU MDR/IVDR, FDA, TGA, etc.) require integration with QMS and risk management files.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "medical-device-remanufacturing-refurbishment-2026",
    "title": "Medical Device Remanufacturing, Refurbishment & Reprocessing - Regulatory Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Remanufacturing and refurbishment of single-use and reusable medical devices are strictly regulated. Entities must meet original manufacturer standards for safety and performance, including full reprocessing validation, traceability, labelling as remanufactured, and post-market surveillance. Many jurisdictions distinguish between refurbishment (by original manufacturer) and reprocessing (by third parties), with significant compliance obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "medical-device-single-use-reprocessing-2026",
    "title": "Reprocessing of Single-Use Medical Devices - Regulatory & Safety Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Strict regulatory controls governing the reprocessing (cleaning, disinfection, and sterilization) of medical devices originally labeled by the OEM as 'single-use'. Reprocessors are legally treated as the original manufacturer and bear full liability for the safety and performance of the reprocessed device.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "medical-device-software-validation-iec62304-2026",
    "title": "Medical Device Software Validation & Lifecycle Processes - IEC 62304 (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "IEC 62304 specifies lifecycle requirements for the development of medical software and software within medical devices. It mandates a risk-based software safety classification (Class A, B, C) which determines the required rigor for software architecture, detailed design, unit verification, integration testing, and system testing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 1
  },
  {
    "node_id": "medical-device-supply-chain-due-diligence-2026",
    "title": "Medical Device Supply Chain Due Diligence & Resilience Requirements (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Manufacturers must conduct robust supply chain due diligence covering cybersecurity, forced labour, conflict minerals, environmental compliance, and single points of failure. NIS2, DORA, EU MDR, FDA, and other frameworks require mapping of critical suppliers, contractual flow-down of security and quality obligations, regular audits, and contingency planning for supply disruptions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "medical-device-usability-human-factors-2026",
    "title": "Medical Device Usability Engineering & Human Factors Validation (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Regulatory framework governing the application of usability engineering (human factors) to medical devices to minimize use errors and use-associated risks. Mandated by FDA and EU MDR, it requires manufacturers to conduct rigorous formative and summative usability testing with intended users in simulated clinical environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "mekong-river-commission-1995-mrc-treaty",
    "title": "Mekong River Commission 1995 Agreement - Sustainable Development Cooperation, PNPCA Notification and Basin Development Plan",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Agreement on the Cooperation for the Sustainable Development of the Mekong River Basin, signed at Chiang Rai on 5 April 1995, establishes the Mekong River Commission (MRC) and the framework for transboundary cooperation among the four Lower Mekong basin states: Cambodia, Lao People's Democratic Republic, Thailand, and Viet Nam. China (upstream Lancang River) and Myanmar are Dialogue Partners but not members, limiting the MRC's coverage of the full 4,350 km river system to the lower 2,400 km. The Agreement contains 6 chapters and 42 articles addressing objectives (Articles 1-2), areas of cooperation (Articles 3-9 including reasonable and equitable utilisation Article 5), institutional framework (Articles 11-33 establishing the MRC Council, Joint Committee and Secretariat), implementing procedures, and dispute settlement (Articles 34-35). The MRC Secretariat is headquartered in Vientiane, Lao PDR with offices in Phnom Penh, Cambodia. The five MRC Procedures operationalise the Agreement: Procedures for Data and Information Exchange and Sharing (PDIES, 2001), Procedures for Water Use Monitoring (PWUM, 2003), Procedures for Notification, Prior Consultation and Agreement (PNPCA, 2003), Procedures for Maintenance of Flows on the Mainstream (PMFM, 2006), and Procedures for Water Quality (PWQ, 2011). The PNPCA process has been particularly significant, applied to hydropower projects including Xayaburi (2010), Don Sahong (2014), Pak Beng (2017), Pak Lay (2018), Luang Prabang (2019), and Sanakham (2020). The Basin Development Strategy 2021-2030 and 5-year MRC Strategic Plan guide implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-watercourses-convention-1997-transboundary-water"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mental-health-data-privacy-2026",
    "title": "Mental Health Data Privacy & Special Category Protections (Global 2026)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Mental health data is treated as highly sensitive special category data across major jurisdictions. Strict rules apply to collection, processing, sharing, and secondary use, with heightened consent standards, enhanced security, restrictions on automated decision-making, and mandatory privacy impact assessments. Many frameworks require explicit patient consent and limit disclosure even for treatment purposes without specific authorization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "metr-model-evaluation-threat-research-frontier-evaluation",
    "title": "METR (Model Evaluation and Threat Research) - Independent Frontier AI Evaluation Methodology, RSP Guidance and Common Elements of Frontier Safety Policies",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "METR (Model Evaluation and Threat Research) is an independent research nonprofit that scientifically measures whether and when AI systems might threaten catastrophic harm to society. METR spun out of the Alignment Research Center (ARC) in December 2023. METR conducts external red-team evaluations of AI company safety reports (including Anthropic sabotage and automated R&D risk reports), publishes methodology for autonomous-agent capability evaluations, and engages with policymakers including OSTP, NIST, and BIS. Key METR-authored frameworks include (1) Responsible Scaling Policies guidance (September 2023) which set the field-defining structure of capability-triggered safeguard upgrades; (2) RE-Bench autonomous capability benchmark; (3) Common Elements of Frontier AI Safety Policies (December 2025) which synthesises industry RSP-equivalent practice. METR is referenced by Anthropic RSP, Google DeepMind Frontier Safety Framework v2.0, the EU AI Office's GPAI Code of Practice discussions, and the UK and US AI Safety Institute methodologies as a primary external evaluator.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "anthropic-responsible-scaling-policy-v2-1-2025",
      "uk-ai-safety-institute-framework-2024",
      "us-ai-safety-institute-nist-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mexico-cnbv-circular-2019-cybersecurity-financial",
    "title": "Mexico CNBV - Disposiciones de Caracter General Aplicables a las Instituciones de Credito (CUB): Information Security and Cybersecurity Obligations, CISO Designation, Incident Notification and Third-Party Technology Risk",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Cybersecurity obligations for Mexican credit institutions are set by the Comision Nacional Bancaria y de Valores (CNBV) through the Disposiciones de Caracter General Aplicables a las Instituciones de Credito (the 'Circular Unica de Bancos' or CUB), as amended by successive Resoluciones, not by a non-existent 'CNBV Circular 1/2019' (that number belongs to a Banco de Mexico foreign-exchange conduct circular and is unrelated). The CUB information-security provisions (Articles 168 Bis 11 to 168 Bis 17) require a designated Chief Information Security Officer reporting immediately below the General Director, an information-security management process, and notification of information-security incidents to the CNBV. Institutions must notify the CNBV immediately by email (Ciberseguridad-CNBV@cnbv.gob.mx) on detection, then submit detailed information within five business days using the forms in Annexes 64 and 64 Bis, and conduct investigation, classification, containment and remediation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cisa-secure-by-design-guidance-2024",
      "au-apra-prudential-standard-cps-220"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mexico-cofepris-md-2026",
    "title": "Mexico COFEPRIS Medical Device Regulations & Equivalency Route 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "COFEPRIS expanded equivalency pathway recognizes FDA, EMA, and IMDRF approvals for faster registration. 2026 reforms include 10-year renewals for low-risk devices and hybrid inspections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "mexico-fintech-law-2018-ley-para-regular-instituciones",
    "title": "Ley para Regular las Instituciones de Tecnología Financiera",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This law establishes the regulatory framework for Electronic Payment Institutions (IPEs) and Collective Financing Institutions (IFCs) in Mexico, mandating compliance with anti-money laundering protocols, consumer protection disclosures, capital adequacy, and operational risk management. Key obligations include open banking API implementation and virtual asset transaction monitoring as defined in Title V and Title VI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "au-aml-ctf-act-2006",
      "bank-provisioning-emerging-market-economies"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mexico-infonavit-housing-fund-law-1972",
    "title": "Mexico INFONAVIT Housing Fund Law 1972 - Employer Contributions, Housing Credit and Subrogation",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Mexico's Law of the Institute of the National Housing Fund for Workers (Ley del INFONAVIT, 24 April 1972, last reformed 2023) requires all private sector employers to contribute 5% of each worker's daily integrated salary to the National Housing Fund (Fondo Nacional de Vivienda) administered by INFONAVIT (Instituto del Fondo Nacional de la Vivienda para los Trabajadores); entitles eligible workers to housing credits (creditos hipotecarios) from the accumulated fund balance; mandates bimonthly employer contribution declarations to IMSS-SUA system; and imposes employer penalties of 40-100% surcharge on unpaid contributions plus INFONAVIT inspection authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-bocw-act-1996-construction-worker-welfare"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mexico-ley-actividades-espaciales-2021",
    "title": "Mexico Space Activities Regulatory Status - Agencia Espacial Mexicana (Ley que crea la AEM, DOF 30 July 2010), IFT Spectrum Coordination and UN Space Treaty Obligations",
    "domain": "Space & Satellite Law",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "Mexico has NOT enacted a dedicated comprehensive 'Ley de Actividades Espaciales' (there is no such law published in the DOF on 1 December 2021). The only enacted federal space statute is the Ley que crea la Agencia Espacial Mexicana (published DOF 30 July 2010), which creates the Agencia Espacial Mexicana (AEM) as a decentralised public body to coordinate national space policy but does not itself establish a single-window launch/satellite authorisation and liability regime. In practice, satellite spectrum and orbital filings are coordinated by the Instituto Federal de Telecomunicaciones (IFT) under the Federal Telecommunications and Broadcasting Law and ITU Radio Regulations; international responsibility, liability and registration flow from Mexico's adherence to the UN space treaties (Outer Space Treaty 1967, Liability Convention 1972, Registration Convention 1975), with the Secretaria de Relaciones Exteriores (SRE) handling UN registration. The operational steps below reflect this combined AEM / IFT / SRE / treaty framework rather than a single domestic space-activities statute.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "nist_csf",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "kazakhstan-space-activities-law-2012"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mexico-ley-aguas-nacionales-1992-conagua",
    "title": "Mexico Ley de Aguas Nacionales 1992 - CONAGUA Concession and Water Rights Framework",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Mexico's Ley de Aguas Nacionales (LAN, DOF 1 de diciembre de 1992, as amended) governs national waters (aguas nacionales) as federal public property under Article 27 of the Mexican Constitution. CONAGUA (Comision Nacional del Agua) administers the national water system and grants concessions (concesiones) and assignments (asignaciones) for water use. All surface water and groundwater abstractions above household use require a concession or assignment. The Public Water Registry (REPDA - Registro Publico de Derechos de Agua) records all water rights. Overexploited aquifers (acuiferos sobreexplotados) are subject to veda (prohibition) on new concessions. Discharge of wastewater to national waters requires a separate discharge permit (permiso de descarga).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brazil-national-water-resources-policy-9433-1997-ana"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mexico-ley-desarrollo-rural-sustentable-2001-sader",
    "title": "Mexico Ley de Desarrollo Rural Sustentable 2001 - SADER Agricultural Development and Food Sovereignty Framework",
    "domain": "Agriculture & Agritech",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Mexico's Ley de Desarrollo Rural Sustentable (LDRS, Ley publicada el 7 de diciembre de 2001 en el Diario Oficial de la Federacion) establishes the legal framework for sustainable rural development, agricultural planning, and food sovereignty policy. The Secretaria de Agricultura y Desarrollo Rural (SADER) is the lead federal ministry, coordinating through the Consejo Mexicano para el Desarrollo Rural Sustentable (CMDRS). The LDRS mandates a Sistema Nacional para el Desarrollo Rural Sustentable (SNADERS), integrating federal, state, and municipal agricultural support programmes. PROCAMPO (now PROAGRO/SADER Bienestar) provides direct payments to eligible producers. SAGARPA-era instruments have been consolidated under SADER. GMO regulation under the Ley de Bioseguridad de Organismos Geneticamente Modificados (LBOGM, 2005) is coordinated between SADER, SEMARNAT, and SENASICA. Mexico's food security strategy (Plan Nacional de Desarrollo 2019-2024) emphasises food sovereignty (soberania alimentaria) and self-sufficiency in corn, beans, and wheat.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cusma_usmca",
        "codex_alimentarius",
        "wto_agriculture",
        "ippc",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "mexico-ley-federal-proteccion-consumidor-profeco-1992",
    "title": "Mexico Ley Federal de Proteccion al Consumidor 1992 - PROFECO Consumer Protection and Supplier Obligations",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Mexico's Ley Federal de Proteccion al Consumidor (LFPC, Federal Consumer Protection Law, published 24 December 1992, last amended 2023) is administered by PROFECO (Procuraduria Federal del Consumidor), the federal consumer protection prosecutor; the LFPC establishes core consumer rights including the right to clear pricing information, truthful advertising, warranty enforcement, and protection against abusive commercial practices; suppliers must display final prices inclusive of taxes (Article 7), honour advertised promotions (Article 46), and provide mandatory written warranty of at least 30 days for goods and 30 days for services (Article 77); PROFECO can impose administrative fines of up to 10% of sales revenue or USD 2.5 million equivalent per violation (Article 128); the LFPC requires a 5-day cooling-off period for distance sales (Article 32); e-commerce suppliers must register with PROFECO's REPECO registry and provide pre-sale disclosure of product specifications, total price, return policy, and seller identity; NOM (Norma Oficial Mexicana) standards complement LFPC requirements for specific product categories.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-consumer-protection-act-2019-ccpa"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mexico-ley-migracion-2011-inm",
    "title": "Mexico Ley de Migracion 2011 - INM Immigration and Residency Framework",
    "domain": "Immigration & Border Control",
    "version": "2.3",
    "last_updated": "2026-05-10",
    "bluf": "The Ley de Migracion (Migration Law) of 25 May 2011 and its Regulations (Reglamento, 2012) constitute Mexico's comprehensive immigration framework, administered by the Instituto Nacional de Migracion (INM) under the Secretaria de Gobernacion. Mexico is simultaneously a major emigration country, a transit corridor for Central American migrants, and an increasingly important destination for US and Canadian retirees. The law establishes three migration conditions: Visitor (Visitante, up to 180 days), Temporary Resident (Residente Temporal, 1-4 years), and Permanent Resident (Residente Permanente). Article 94 makes irregular entry a civil (not criminal) administrative violation; human traffickers face 10-25 years imprisonment under Art.159. INM agents at 48 international ports of entry use SARIM biometric system. Mexico's Tarjeta de Visitante Trabajador Fronterizo (TVTF) allows Central American border workers to work in southern Mexican states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "unhcr",
        "mercosur",
        "icao_doc",
        "ilo",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mexico-ley-minera-1992-mining-law",
    "title": "Mexico Ley Minera 1992 - Federal Mining Law",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Mexico's Ley Minera (Federal Mining Law, last reformed 2014) and its Reglamento govern exploration and exploitation of mineral resources in Mexican territory. Concessions are granted by the Secretaria de Economia for initial 50-year terms (renewable), require environmental impact assessment approval from SEMARNAT, and mandate social impact consultation with indigenous communities under ILO Convention 169.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "peru-general-mining-law-ds-014-92-em",
      "indonesia-mineral-coal-mining-law-3-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mexico-ley-obras-publicas-2020",
    "title": "Mexico Ley de Obras Publicas y Servicios 2020 - Public Works Procurement Law",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Mexico's Ley de Obras Publicas y Servicios Relacionados con las Mismas (LOPSRM, last reformed 2020) governs federal public works procurement including construction, installation, maintenance, and demolition of federal infrastructure. It mandates competitive bidding (licitacion publica), allows restricted invitations and direct awards in specified circumstances, and requires public contract registration in CompraNet, Mexico's federal procurement platform administered by the Secretaria de la Funcion Publica (SFP).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-public-procurement-construction-directive",
      "us-contract-disputes-act-1978-federal-construction"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mexico-lfpc-federal-consumer-protection-law",
    "title": "Mexico Federal Consumer Protection Law (LFPC 1992) - PROFECO Enforcement and Consumer Rights",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Mexico's Ley Federal de Proteccion al Consumidor (LFPC, published 24 December 1992 in the DOF, as amended through 2022) establishes consumer rights and supplier obligations enforced by the Procuraduria Federal del Consumidor (PROFECO). Key provisions include: 5-day cooling-off for off-premises sales (LFPC Article 56), mandatory price displays, prohibition of discriminatory practices, strict adhesion contract registration with PROFECO, product warranty obligations (90 days minimum for durable goods), and PROFECO conciliation and arbitration procedures with fines up to 10% of annual turnover or USD 2.5 million equivalent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "australia-consumer-law-acl-2010-cx"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mexico-lfpdppp-2010-data-protection",
    "title": "Federal Law on Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares - LFPDPPP)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The LFPDPPP establishes the legal framework for the protection of personal data processed by private parties in Mexico. It mandates the implementation of privacy notices (Aviso de Privacidad), requires explicit consent for sensitive data processing, and grants individuals ARCO rights (Access, Rectification, Cancellation, and Opposition) as defined in the law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-privacy",
      "owasp-samm-governance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mexico-lftr-telecomunicaciones-radiodifusion-2014",
    "title": "Ley Federal de Telecomunicaciones y Radiodifusión",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires that preponderant economic agents, such as América Móvil, comply with must-carry and must-offer obligations, as stated in Article 131 of the LFTR. It applies to all telecommunications and broadcasting services in Mexico.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-net-neutrality-open-internet-2015-2120"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mexico-nom-051-food-labelling-2020",
    "title": "NOM-051-SCFI/SSA1-2010, as amended by the 2020 Official Mexican Standard - Specifications for the Identification, Presentation, and Advertising of Foodstuffs and Non-Alcoholic Beverages: Front-of-Pack Labelling, Nutritional Information, and Advertising Restrictions",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Mandates front-of-pack octagonal black warning seals for foods and non-alcoholic beverages high in calories, sugars, saturated fats, trans fats, or sodium, based on thresholds defined in Article 4.1.2. Prohibits the use of cartoon characters, promotional claims, and misleading imagery on packaging for products targeted to children. Applies to all manufacturers, importers, distributors, and retailers of prepackaged food and non-alcoholic beverages in Mexico.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-food-labelling-regulation-1169-2011",
      "brc-food-safety-global"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mf-gdpr-2018",
    "title": "Saint Martin (French Collectivity) - EU General Data Protection Regulation (GDPR) and CNIL Supervisory Framework",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Saint Martin (French collectivity) is a French overseas collectivity located in the northeastern Caribbean Sea, occupying the northern portion of the island of Saint Martin, which it shares with the Kingdom of the Netherlands (Sint Maarten). Saint Martin became a separate French collectivity in 2007 and has been designated as an EU outermost region, making it fully subject to EU law including the General Data Protection Regulation (GDPR), which applies directly and in full force in Saint Martin in the same manner as in metropolitan France and all other EU outermost regions. The Commission Nationale de l'Informatique et des Libertés (CNIL) is the competent data protection supervisory authority for Saint Martin. The French national adaptation law - Law No. 2018-493 of 20 June 2018 on the Protection of Personal Data - implements GDPR-compatible national provisions applicable in Saint Martin. All organisations established in Saint Martin or processing personal data of individuals located in Saint Martin must comply with the GDPR, including requirements for lawful basis, data subject rights, data protection by design and by default, data protection impact assessments, mandatory breach notification to CNIL within 72 hours, and appointment of a Data Protection Officer where required. Note that Saint Barthélemy, the neighbouring French collectivity, is classified as an EU Overseas Country and Territory (OCT) rather than an outermost region, and the GDPR does not apply there - a key compliance distinction for organisations operating across both territories.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/mf-gdpr-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mg-pdp-law-2014",
    "title": "Madagascar Law No. 2014-038 on Protection of Personal Data",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Madagascar enacted Law No. 2014-038 of 9 January 2015 on the Protection of Personal Data (Loi sur la protection des données à caractère personnel). The law is administered by the Commission de l'Informatique et des Libertés (CIL), an independent regulatory authority modelled on the French CNIL. The law establishes principles for the lawful processing of personal data, requires registration of data processing activities with the CIL, mandates informed consent from data subjects, grants rights of access, rectification, and erasure, and restricts cross-border transfers to jurisdictions with adequate protection. Security obligations apply to all data controllers and processors. Penalties for non-compliance include administrative sanctions and criminal prosecution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/mg-pdp-law-2014.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mh-framework",
    "title": "Marshall Islands - Constitutional Privacy Rights and Pacific Islands Forum Data Protection Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Republic of the Marshall Islands is an independent sovereign nation in the central Pacific Ocean governed under a constitutional democracy established by the Constitution of the Republic of the Marshall Islands (1979). The Constitution establishes fundamental rights including the right to privacy and protection from unreasonable searches and seizures consistent with democratic constitutional traditions. The Marshall Islands entered into a Compact of Free Association with the United States, which provides for US defense commitments and economic assistance but does not extend US federal law to the Marshall Islands - the Marshall Islands exercises full sovereignty over its own domestic legal affairs and regulatory framework. The Ministry of Finance, Banking and Postal Services oversees aspects of telecommunications and ICT regulation in the Marshall Islands. The Marshall Islands does not have a standalone comprehensive personal data protection law. The applicable framework for personal data protection consists of constitutional privacy rights, Pacific Islands Forum regional guidelines on cybersecurity and data protection, and common law privacy principles applicable in the Marshall Islands legal system. Organisations processing personal data in the Marshall Islands must respect constitutional privacy rights, implement appropriate security measures to protect personal data from unauthorised access and disclosure, and limit collection and use of personal data to specified, legitimate purposes. As a Pacific Islands Forum member, the Marshall Islands participates in regional frameworks for cybercrime prevention and digital governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/mh-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mhealth-apps-regulation-2026",
    "title": "mHealth Apps & Mobile Medical Applications - Global Regulatory Framework (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Mobile health applications are regulated as medical devices when they have diagnostic, therapeutic, or monitoring functions. Requirements include risk classification, clinical validation, cybersecurity, privacy-by-design, usability engineering, and post-market surveillance. Many jurisdictions now have specific mHealth guidance or fast-track pathways with real-world evidence expectations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "mica-regulation-article-14-marketing-communications-requirements",
    "title": "Markets in Crypto-Assets Regulation (MiCA) - Article 14: Obligations of offerors and persons seeking admission to trading of crypto-assets other than asset-referenced tokens or e-money tokens",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that offerors of non-ART/EMT crypto-assets act honestly, manage conflicts of interest, maintain secure systems, treat holders equally, and return funds promptly if an offer is cancelled.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "mica-regulation-article-16-authorisation-casp",
    "title": "Markets in Crypto-Assets Regulation (MiCA) - Article 16: Authorisation",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Prohibits any person from offering an asset-referenced token to the public or seeking its admission to trading within the EU unless they are the issuer and have been properly authorised as either a legal entity or a credit institution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "mica-regulation-article-19-withdrawal-authorisation-casp",
    "title": "Markets in Crypto-Assets Regulation (MiCA) - Article 19: Assessment of the application for authorisation",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article outlines the procedural steps for competent authorities in assessing an application for authorisation, including timelines for information requests, mandatory consultation with EBA, ESMA, and the ECB, and the consideration of their non-binding opinions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "mica-regulation-article-22-ongoing-disclosure-obligations-casp",
    "title": "REGULATION (EU) 2023/1114 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 31 May 2023 on markets in crypto-assets - Article 22",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that issuers of asset-referenced tokens continuously and publicly disclose all material information that may have a significant effect on the value of their tokens or the offer to the public.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "mica-regulation-article-3-definitions",
    "title": "Regulation (EU) 2023/1114 on markets in crypto-assets - Article 3 Definitions",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the legal definitions for key terms such as 'crypto-asset', 'issuer', and 'offer to the public', which must be used to classify all relevant assets, entities, and activities under the MiCA framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mica-regulation-article-45-insider-dealing-prohibition",
    "title": "REGULATION (EU) 2023/1114 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937 - Article 45",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article's core compliance obligations cannot be determined as the text for Article 45 was not provided in the source material.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "mica-regulation-article-46-unlawful-disclosure-inside-information",
    "title": "REGULATION (EU) 2023/1114 on markets in crypto-assets - Article 46: Unlawful disclosure of inside information",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article prohibits any person possessing inside information from unlawfully disclosing that information to any other person, except where the disclosure is made in the normal exercise of an employment, a profession or duties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mica-regulation-article-47-market-manipulation-prohibition",
    "title": "REGULATION (EU) 2023/1114 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 31 May 2023 on markets in crypto-assets - Article 47: Prohibition of market manipulation",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes a prohibition against engaging in or attempting to engage in market manipulation involving crypto-assets, aiming to address substantial risks to market integrity and user confidence as identified in the regulation's preamble.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "mica-regulation-article-59-authorisation-art-issuers",
    "title": "REGULATION (EU) 2023/1114 on markets in crypto-assets - Article 59 - Authorisation of issuers of asset-referenced tokens",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article establishes the mandatory authorisation requirements for legal persons seeking to offer asset-referenced tokens to the public or seek their admission to trading within the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mica-regulation-article-6-prohibition-on-offering-without-whitepaper",
    "title": "Markets in Crypto-Assets Regulation (MiCA) - Article 6 - Prohibition of offering to the public or seeking admission to trading of crypto-assets other than asset-referenced tokens or e-money tokens",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations are prohibited from offering crypto-assets to the public or seeking their admission to trading unless a compliant crypto-asset white paper has been notified and published, and any associated marketing communications are drafted in accordance with regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "mica-regulation-article-68-authorisation-emt-issuers",
    "title": "REGULATION (EU) 2023/1114 on markets in crypto-assets - Article 68 - Authorisation of issuers of e-money tokens",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the authorisation requirements and procedures for legal persons seeking to issue e-money tokens (EMTs) within the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "mica-regulation-article-7-content-of-crypto-asset-whitepaper",
    "title": "Markets in Crypto-Assets Regulation (MiCA) - Article 7: Marketing communications",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that all marketing communications for crypto-assets must be clearly identifiable, fair, consistent with the white paper, and include specific disclosures and a prominent disclaimer.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "mica-regulation-article-76-crypto-asset-whitepaper-other-tokens",
    "title": "REGULATION (EU) 2023/1114 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 31 May 2023 on markets in crypto-assets - Article 76: Content and form of the crypto-asset white paper",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that any offeror of a crypto-asset, other than an asset-referenced or e-money token, must create, notify, and publish a detailed crypto-asset white paper containing specific information about the offeror, project, crypto-asset rights, technology, and risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "mica-regulation-article-88-administrative-sanctions-measures",
    "title": "REGULATION (EU) 2023/1114 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937 - Article 88",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article empowers competent authorities to impose a range of administrative sanctions and measures on natural and legal persons for infringements of the Markets in Crypto-Assets Regulation (MiCA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "mica-regulation-article-90-criminal-sanctions",
    "title": "REGULATION (EU) 2023/1114 on markets in crypto-assets - Article 90 Criminal sanctions",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article requires EU Member States to establish effective, proportionate, and dissuasive criminal sanctions for specific infringements of the MiCA regulation, creating a significant compliance risk for organizations operating in this space.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "mica-regulation-article-93-reporting-to-esma",
    "title": "REGULATION (EU) 2023/1114 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937 - Article 93",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the obligations for crypto-asset service providers to report specific information and data to the European Securities and Markets Authority (ESMA) to ensure market integrity and oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "mica-stablecoin-reserve",
    "title": "MiCA (Stablecoin Reserve)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "MiCA (Markets in Crypto-Assets Regulation, EU 2023/1114) is the first comprehensive framework for the crypto-asset market. it introduces strict reserve requirements for 'Asset-Referenced Tokens' (ARTs) and 'E-Money Tokens' (EMTs), commonly known as stablecoins, requiring issuers to maintain a 1:1 liquid reserve of assets to ensure the redemption and the systemic stability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-virtual-assets-vasp",
      "prudential-treatment-cryptoasset-exposures",
      "bcbs-principles-operational-resilience",
      "bcbs-sound-liquidity-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "michigan-telehealth-2026",
    "title": "Michigan Telehealth Licensure, Consent & Reimbursement Rules 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "Michigan allows out-of-state providers to deliver telehealth with proper registration and patient consent. 2026 updates include expanded private payer parity, strengthened informed consent requirements for virtual care, and alignment with HIPAA for platform security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "microsoft-azure-compliance-framework-2024",
    "title": "Microsoft Azure Compliance Framework 2024 - Azure Policy, Microsoft Purview Compliance Manager, Regulatory Compliance Dashboard, Built-In Policies for NIST/ISO/SOC2, Customer Lockbox, Confidential Computing Enclaves and Sovereign Cloud (Azure Government/China)",
    "domain": "Cloud & SaaS",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This framework outlines Microsoft Azure's compliance posture for global regulatory standards, including built-in controls for NIST, ISO, SOC2, and sovereign cloud offerings. It applies to organizations using Azure to meet regulatory obligations under standards such as HIPAA, GDPR, FedRAMP, and PCI DSS as documented in Microsoft Learn.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "eu-gdpr-cloud-data-processing",
      "nist-ir-8011-v1-automated-assessments",
      "cyber-essentials-plus-uk",
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mifid-ii",
    "title": "Markets in Financial Instruments Directive II (MiFID II)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Markets in Financial Instruments Directive II (MiFID II) establishes a comprehensive regulatory framework designed to enhance transparency, investor protection, and market efficiency across European Union financial markets. Compliance requires rigorous adherence to numerous obligations, mandating that investment firms have a defined conflict of interest policy and ensure documented client categorization is consistently applied. For advisory services, a suitability assessment conducted for advice is a critical prerequisite to align recommendations with client profiles. The directive codifies stringent transparency rules, requiring both implemented pre-trade transparency and near real-time post-trade publication of transaction details. A cornerstone of this regime is a published best execution policy, compelling firms to demonstrate they take all sufficient steps for optimal client outcomes. Transactional integrity and surveillance are reinforced through the mandatory use of a Legal Entity Identifier for reporting parties and through active communication taping of relevant correspondence. Reporting obligations are time-sensitive, with a transaction report submission deadline of one business day. Furthermore, the regulation stipulates a minimum record retention period of five years for all pertinent data. Firms must also provide clear cost and charges disclosure to clients upfront. To safeguard market stability, any algorithmic trading system is required to be robustly tested before deployment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dora-ict-risk",
      "bcbs-principles-sound-management-operational-risk",
      "basel-committee-financial-crisis-response"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mifid-ii-best-execution",
    "title": "MiFID II Best Execution",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "MiFID II Best Execution (Markets in Financial Instruments Directive II) requires investment firms to take all sufficient steps to obtain the best possible result for their clients when executing orders. it focuses on a multi-factor assessment including price, costs, speed, and likelihood of execution, ensuring transparent and fair market outcomes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mifir-transaction-report"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mifir-transaction-report",
    "title": "MiFIR Transaction (Reporting)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "MiFIR Transaction Reporting (Markets in Financial Instruments Regulation, Article 26) is the mandatory standard for reporting the details of the financial trades to the EU regulators. it requires the timely disclosure of the 65 data fields (e.g., identity of the buyer/seller, LEIs, time-stamping) within one business day (T+1), ensuring the market monitoring for the market abuse and the systemic risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mifid-ii-best-execution",
      "iso-20022-mx-messaging"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mil-std-882e-system-safety",
    "title": "MIL-STD-882E Department of Defense Standard Practice - System Safety",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This standard mandates a systematic, risk-based approach for identifying, assessing, and mitigating hazards throughout the lifecycle of Department of Defense (DoD) systems. As outlined in Section 4, all DoD programs must establish and maintain a system safety program to manage risks associated with software, hardware, and their integration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "as9100-rev-d-qms",
      "dfars-7012-defense-cyber",
      "itar-compliance-workflow",
      "faa-part-21-certification"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "minamata-convention-2013-mercury",
    "title": "Minamata Convention 2013 - Global Treaty on Mercury Control",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Minamata Convention on Mercury, adopted on 10 October 2013 in Kumamoto, Japan, and entered into force on 16 August 2017, has 147 Parties and is the global legally binding agreement addressing mercury throughout its lifecycle - from mining to disposal. Named after Minamata, Japan, where industrial mercury discharge caused mass methylmercury poisoning (1956-1968), the Convention prohibits new mercury mines, requires phase-out of existing mercury mines within 15 years of entry into force for the Party, prohibits manufacture and export of a range of mercury-added products after 2020 (including certain batteries, switches, fluorescent lamps, certain thermometers and blood pressure devices, certain soaps and cosmetics, and pesticides). Article 7 establishes controls on artisanal and small-scale gold mining (ASGM) - the largest source of mercury emissions globally - requiring National Action Plans (NAPs) from Parties with 'more than insignificant' ASGM. Article 8 requires Parties to control mercury air emissions from coal-fired power plants, coal-fired industrial boilers, non-ferrous metal smelting, waste incineration, and cement clinker production using Best Available Techniques (BAT) and Best Environmental Practices (BEP). Article 9 requires controls on mercury releases to land and water. Article 10 governs environmentally sound interim storage of mercury. Article 11 addresses mercury waste management consistent with the Basel Convention. The Convention requires Phase-Out of mercury-added products listed in Annex A (Part I - 2020 deadline) and Annex A (Part II - certain longer-phase-out products). The European Union implements the Convention through the EU Mercury Regulation (Regulation (EU) 2017/852).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "stockholm-convention-2001-persistent-organic-pollutants",
      "basel-convention-1989-hazardous-waste-transboundary",
      "eu-csrd-2022-2464",
      "eu-reach-regulation-1907-2006"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "misp-malware-information-sharing-platform",
    "title": "MISP Open Source Threat Intelligence Platform (Events, Attributes, Objects, Galaxies, Taxonomies, Sharing Groups, STIX 2.0/2.1 Export, MISP Modules, AGPLv3)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "MISP (Malware Information Sharing Platform and Threat Sharing) is the open-source threat intelligence platform maintained at github.com/MISP/MISP under the GNU Affero General Public License v3. MISP organises threat intelligence into Events (containers for an incident, campaign, or report) composed of Attributes (typed indicators such as ip-src, ip-dst, domain, hostname, url, md5, sha1, sha256, sha512, filename, email-src, email-dst, btc, regkey, mutex, yara-rule, sigma-rule, plus 100+ additional types). Complex intelligence is modelled through Objects - reusable templates that link multiple attributes together to represent malware analysis reports, phishing campaigns, threat actor profiles, or vulnerability records. Galaxies are MISP's intelligence vocabularies and clusters: prebuilt taxonomies of threat actors, malware families, ransomware, banking trojans, mobile malware, and MITRE ATT&CK techniques, groups, and software. Taxonomies provide adjustable classification schemes including the Traffic Light Protocol (TLP per FIRST 2.0), Admiralty Code source reliability ratings, and kill-chain phase labels. MISP supports built-in sharing functionality with granular distribution controls (sharing groups, organisation-only, community-only, all-communities, server-only) and automatic synchronisation between MISP instances across organisational boundaries. Export formats include STIX 1.x and STIX 2.0/2.1 bundles, OpenIOC, native IDS rule formats for Suricata/Snort/Zeek/Bro, CSV, JSON, and PDF. MISP Modules extend the platform with Python-based enrichment, expansion, import, export, and hover modules integrating threat-intel vendors and analysis tools. MISP is the operational backbone of dozens of ISACs and ISAOs and is the recommended open-source alternative or complement to commercial Threat Intelligence Platforms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "platform_basis",
        "key_institutions",
        "events_and_attributes_model",
        "objects_template_model",
        "galaxies_clusters_model",
        "taxonomies_and_tags",
        "sharing_groups_and_synchronisation",
        "export_formats",
        "misp_modules_ecosystem",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oasis-stix-2-1-structured-threat-information",
      "first-tlp-2-0-traffic-light-protocol",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "misra-c-2023-automotive-coding-standard",
    "title": "MISRA C:2023 - Motor Industry Software Reliability Association C Coding Guidelines: Mandatory and Advisory Rules for Safety-Critical Automotive Software Development",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "MISRA C:2023 provides a comprehensive set of mandatory and advisory coding guidelines for the use of the C language in safety-critical automotive systems, extending support to C11 and C18 language standards while maintaining backward compatibility. Compliance is required for developers in automotive and other high-integrity industries to prevent undefined behaviors and ensure code reliability, as specified in the guidance published in April 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26262-functional-safety-road-vehicles-2018",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-acquire-compromised-ml-artifact",
    "title": "MITRE ATLAS Acquisition of Compromised AI Artifacts from Third-Party Sources (AML.T0010) - Compliance Obligations for Pre-Trained Model Integrity Verification, Vendor Security Assessments, and AI Component Provenance Checks",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-23",
    "bluf": "This node addresses compliance obligations under the EU AI Act for defending against MITRE ATLAS technique AML.T0010 (AI Supply Chain Compromise), specifically requiring pre-trained model integrity verification, vendor security assessments, and AI component provenance checks as per Articles 5, 15, and 50. It maps to relevant NIST AI RMF controls and ISO/IEC 42001 standards for AI risk management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-acquire-public-ml-artifacts",
    "title": "MITRE ATLAS Acquisition of Public AI Artifacts for Attack Preparation (AML.T0002) - Compliance Obligations for Open-Weight Model Risk Assessment, Third-Party AI Artifact Due Diligence, and AI Supply Chain Security Controls",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0002, focusing on adversaries acquiring public ML artifacts for attack preparation, aligns with EU AI Act Articles 9 and 15, and mandates robust supply chain security and artifact integrity verification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-activation-triggers",
    "title": "MITRE ATLAS Activation Triggers (AML.T0084.002) - Adversarial Activation Triggers threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0084.002 (Activation Triggers). Adversaries may discover keywords or other triggers (such as incoming emails, documents being added, incoming message, or other workflows) that activate an agent and may cause it to run additional actions. Understanding these triggers can reveal how the AI agent is activated and controlled. This may also expose additional paths for compromise, as an adversary could attempt to trigger the agent from outside its environment and drive it to perform unintended or malicious actions. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0084.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-discover-ai-agent-configuration"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-active-scanning",
    "title": "MITRE ATLAS Active Scanning (AML.T0006) - Reconnaissance adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0006 (Active Scanning), an adversarial technique in the ATLAS Reconnaissance tactic. An adversary may probe or scan the victim system to gather information for targeting. This is distinct from other reconnaissance techniques that do not involve direct interaction with the victim system. Adversaries may scan for open ports on a potential victim's network, which can indicate specific services or tools the victim is utilizing. This could include a scan for tools related to AI DevOps or AI services themselves such as public AI chat agents (ex: Copilot Studio Hunter). They can also send emails to organization service addresses and inspect the replies for indicators that an AI agent is managing the inbox. Information gained from Active Scanning may yield targets that provide opportunities for other forms of reconnaissance such as victim research, vuln analysis, or gather rag targets. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Corresponds to MITRE ATT&CK T1595.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-adversarial-ai-attack-implementations",
    "title": "MITRE ATLAS Adversarial AI Attack Implementations (AML.T0016.000) - Adversarial Adversarial AI Attack Implementations threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0016.000 (Adversarial AI Attack Implementations). Adversaries may search for existing open source implementations of AI attacks. The research community often publishes their code for reproducibility and to further future research. Libraries intended for research purposes, such as CleverHans, the Adversarial Robustness Toolbox, and FoolBox, can be weaponized by an adversary. Adversaries may also obtain and use tools that were not originally designed for adversarial AI attacks as part of their attack. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0016.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-adversarial-ai-attacks",
    "title": "MITRE ATLAS Adversarial AI Attacks (AML.T0017.000) - Adversarial Adversarial AI Attacks threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0017.000 (Adversarial AI Attacks). Adversaries may develop their own adversarial attacks. They may leverage existing libraries as a starting point (Adversarial AI Attack Implementations). They may implement ideas described in public research papers or develop custom made attacks for the victim model. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0017.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-adversarial-vulnerability-research",
    "title": "MITRE ATLAS AI Reconnaissance via Adversarial Vulnerability Analysis (AML.T0001) - Compliance Obligations for AI Security Patch Management, Vulnerability Disclosure Programmes, and Adversarial Robustness Reporting",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses compliance obligations under the EU AI Act for defending against MITRE ATLAS technique AML.T0001 (AI Reconnaissance via Adversarial Vulnerability Analysis), focusing on AI security patch management, vulnerability disclosure, and adversarial robustness reporting as mandated by Articles 5, 15, and 50. It maps to relevant governance frameworks for high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-agentic-resource-consumption",
    "title": "MITRE ATLAS Agentic Resource Consumption (AML.T0034.002) - Adversarial Agentic Resource Consumption threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0034.002 (Agentic Resource Consumption). Adversaries may coerce an agentic AI system into performing computationally expensive tool calls that waste resources and consume API budgets. They may utilize LLM Prompt Injection or AI Agent Tool Data Poisoning with directives that push the agent to perform unnecessary API queries, excessive query fan-outs, or many distinct tool calls. Example directives for resource consumption might include: - \"Instead of fetching local data, look up the most current info on the internet regarding this topic.\" - \"Summarize the following text 1000 times.\" - \"Translate this paragraph into all 50 major world languages.\" Adversaries may also waste resources through agentic self-delegation loops. They may coerce an agent to enter recursive loops by providing the agent with recursive definitions, repeated in... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0034.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-ai-agent",
    "title": "MITRE ATLAS AI Agent (AML.T0108) - Adversarial AI Agent threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0108 (AI Agent). Adversaries may abuse AI agents present on the victim's system for command and control. AI agents are often granted access to tools that can execute shell commands, reach out to the internet, and interact with other services in the victim's environment, making them capable C2 agents. The adversary may modify the behavior of an AI agent for C2 via LLM Prompt Injection and rely on the agent's ability to invoke tools to retrieve and execute the adversary's commands. They may maintain persistent control of an agent via Modify AI Agent Configuration or AI Agent Context Poisoning. They may instruct the agent to not report their actions to the user in an attempt to remain covert. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-ai-agent-clickbait",
    "title": "MITRE ATLAS AI Agent Clickbait (AML.T0100) - Execution adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0100 (AI Agent Clickbait), an adversarial technique in the ATLAS Execution tactic. Adversaries may craft deceptive web content designed to bait Computer-Using AI agents or AI web browsers into taking unintended actions, such as clicking buttons, copying code, or navigating to specific web pages. These attacks exploit the agent's interpretation of UI content, visual cues, or prompt-like language embedded in the site. When successful, they can lead the agent to inadvertently copy and execute malicious code on the user's operating system. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-ai-agent-configuration",
    "title": "MITRE ATLAS AI Agent Configuration (AML.T0002.002) - Adversarial AI Agent Configuration threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0002.002 (AI Agent Configuration). Adversaries may acquire publicly accessible AI agent configuration files to understand agent capabilities, gain unauthorized access to tools and data sources, or identify credentials for further attacks. Configuration files define what tools an agent can use, credentials for external services, system prompts, and behavioral settings, making valuable resources for adversaries targeting AI agent deployments. Once configuration files are acquired, adversaries may perform Discover AI Agent Configuration to gain additional insights they can use in their operation or Credentials from AI Agent Configuration to harvest secrets. AI agent configuration files come in multiple forms depending on the platform and agent framework. Agent configuration files adversaries may target include: - System prompt... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-ai-agent-context-poisoning",
    "title": "MITRE ATLAS AI Agent Context Poisoning (AML.T0080) - Adversarial Manipulation of AI Agent LLM Context to Alter Future Behaviour",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0080 (AI Agent Context Poisoning). Adversaries may attempt to manipulate the context used by an AI agent's large language model (LLM) to influence the responses it generates or actions it takes. This allows an adversary to persistently change the behavior of the target agent and further their goals. Context poisoning can be accomplished by prompting the an LLM to add instructions or preferences to memory (See Memory) or by simply prompting an LLM that uses prior messages in a thread as part of its context (See Thread). Compliance frameworks including the EU AI Act, NIST AI RMF, and ISO/IEC 42001 require organisations to detect, monitor, and defend against this technique to preserve AI system integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-ai-agent-tool",
    "title": "MITRE ATLAS AI Agent Tool (AML.T0010.005) - Adversarial AI Agent Tool threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0010.005 (AI Agent Tool). Adversaries may target AI agent tools as a means to compromise a victim's AI supply chain. Tools add capabilities to AI agents, allowing them to interact with other services, connect to data sources, access internet resources, run system tools, and execute code. They are an attractive target for adversaries because compromising an AI agent can provide them with broad accesses and permissions on the victim's system via the agent's other tools. Poisoned agent tools (See AI Agent Tool Poisoning) can contain malicious code or LLM Prompt Injections that manipulate the agent's behavior and even modify how other tools are called. Adversaries have successfully used a poisoned MCP server to exfiltrate private user data [[koi]]. Agent tools have exploded in popularity, with thousands of MCP servers ... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0010.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-ai-agent-tool-data-poisoning",
    "title": "MITRE ATLAS AI Agent Tool Data Poisoning (AML.T0099) - Persistence adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0099 (AI Agent Tool Data Poisoning), an adversarial technique in the ATLAS Persistence tactic. Adversaries may place malicious content on a victim's system where it can be retrieved by an AI Agent Tool. This may be accomplished by placing documents in a location that will be ingested by a service the AI agent has associated tools for. The content may be targeted such that it would often be retrieved by common queries. The adversary's content may include false or misleading information. It may also include prompt injections with malicious instructions. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-ai-agent-tool-invocation",
    "title": "MITRE ATLAS AI Agent Tool Invocation (AML.T0053) - Adversary Abuse of AI Agent Tool Access for Execution and Privilege Escalation",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0053 (AI Agent Tool Invocation). Adversaries may use their access to an AI agent to invoke tools the agent has access to. LLMs are often connected to other services or resources via tools to increase their capabilities. Tools may include integrations with other applications, access to public or private data sources, and the ability to execute code. This may allow adversaries to execute API calls to integrated applications or services, providing the adversary with increased privileges on the system. Adversaries may take advantage of connected data sources to retrieve sensitive information. They may also use an LLM integrated with a command or script interpreter to execute arbitrary instructions. AI agents may be configured to have access to tools that are not directly accessible by users. Adversaries may abuse this to gain access to tools they otherwise wouldn't be able to use. Compliance frameworks including the EU AI Act, NIST AI RMF, and ISO/IEC 42001 require organisations to detect, monitor, and defend against this technique to preserve AI system integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10",
      "owasp-llm-08-excessive-agency"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-ai-agent-tool-poisoning",
    "title": "MITRE ATLAS AI Agent Tool Poisoning (AML.T0110) - Persistence adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0110 (AI Agent Tool Poisoning), an adversarial technique in the ATLAS Persistence tactic. Adversaries may achieve persistence by poisoning tools used by AI agents including built-in tools or tools available to the agent via Model Context Protocol (MCP) connections. This involves compromising benign tools already integrated into the agent's environment. By altering tool behavior such as modifying parameters or descriptions, injecting hidden logic, or redirecting outputs, attackers can maintain long-term influence over the agent's actions, decisions, or external interactions. Poisoned tools may silently exfiltrate data, execute unauthorized commands, or manipulate downstream processes without raising suspicion. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-ai-agent-tools",
    "title": "MITRE ATLAS AI Agent Tools (AML.T0085.001) - Adversarial AI Agent Tools threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0085.001 (AI Agent Tools). Adversaries may prompt the AI service to invoke various tools the agent has access to. Tools may retrieve data from different APIs or services in an organization. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0085. ATLAS-mapped mitigations: AML.M0024 AI Telemetry Logging, AML.M0026 Privileged AI Agent Permissions Configuration, AML.M0027 Single-User AI Agent Permissions Configuration, AML.M0028 AI Agent Tools Permissions Configuration, AML.M0032 Segmentation of AI Agent Components.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-ai-telemetry-logging",
      "mitre-atlas-mitigation-privileged-ai-agent-permissions-configuration",
      "mitre-atlas-mitigation-single-user-ai-agent-permissions-configuration",
      "mitre-atlas-mitigation-ai-agent-tools-permissions-configuration",
      "mitre-atlas-mitigation-segmentation-of-ai-agent-components",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-atlas-ai-artifact-collection",
    "title": "MITRE ATLAS AI Artifact Collection Techniques (AML.T0035) - Compliance Obligations for Protecting AI Model Weights, Training Datasets, and Configuration Files from Adversarial Collection",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses adversarial techniques under MITRE ATLAS AML.T0035 (AI Artifact Collection), focusing on the theft of AI model weights, training datasets, and configuration files. Compliance frameworks like the EU AI Act and NIST AI RMF mandate robust defenses against such threats to ensure AI system integrity and confidentiality.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-ai-artifacts",
    "title": "MITRE ATLAS AI Artifacts (AML.T0112.001) - Adversarial AI Artifacts threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0112.001 (AI Artifacts). Adversaries may achieve full system compromise by introducing malicious AI artifacts, such as models or data, that contain embedded malware or other malicious commands. AI artifacts are often stored in model registries or data stores and may affect many systems that pull these resources. Malicious content stored in AI artifacts may be executed as a result of unsafe serialization formats (e.g. Python pickle) or by other bundled scripts or notebooks. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0112.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-machine-compromise"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-ai-denial-of-service",
    "title": "MITRE ATLAS Denial of AI Service Techniques (AML.T0029) - Operational Resilience and Business Continuity Obligations for AI System Availability Attacks Under DORA, EU AI Act, and ISO 42001",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses adversarial techniques under MITRE ATLAS AML.T0029 (Denial of AI Service), focusing on resource exhaustion and model overload attacks. It outlines compliance obligations for operational resilience and business continuity under EU AI Act, DORA, and ISO 42001 to defend against such availability attacks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-ai-development-workspaces",
    "title": "MITRE ATLAS AI Development Workspaces (AML.T0008.000) - Adversarial AI Development Workspaces threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0008.000 (AI Development Workspaces). Developing and staging AI attacks often requires expensive compute resources. Adversaries may need access to one or many GPUs in order to develop an attack. They may try to anonymously use free resources such as Google Colaboratory, or cloud resources such as AWS, Azure, or Google Cloud as an efficient way to stand up temporary resources to conduct operations. Multiple workspaces may be used to avoid detection. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0008.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-ai-enabled-product-or-service",
    "title": "MITRE ATLAS AI-Enabled Product or Service (AML.T0047) - AI Model Access adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0047 (AI-Enabled Product or Service), an adversarial technique in the ATLAS AI Model Access tactic. Adversaries may use a product or service that uses artificial intelligence under the hood to gain access to the underlying AI model. This type of indirect model access may reveal details of the AI model or its inferences in logs or metadata. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-ai-influence-operations",
    "title": "MITRE ATLAS AI-Generated Influence Operations and Synthetic Content Campaigns (AML.T0048.002) - Compliance Obligations for Synthetic Content Governance, Influence Operation Detection, and AI Transparency Requirements Under EU AI Act",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0048.002 on AI-generated influence operations, aligning with EU AI Act Articles 9, 15, and 50 for transparency and risk management. Key compliance actions include synthetic content detection and disclosure mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-ai-intellectual-property-theft",
    "title": "MITRE ATLAS AI Intellectual Property Theft (AML.T0048.004) - Adversarial AI Intellectual Property Theft threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0048.004 (AI Intellectual Property Theft). Adversaries may exfiltrate AI artifacts to steal intellectual property and cause economic harm to the victim organization. Proprietary training data is costly to collect and annotate and may be a target for Exfiltration and theft. AIaaS providers charge for use of their API. An adversary who has stolen a model via Exfiltration or via Extract AI Model now has unlimited use of that service without paying the owner of the intellectual property. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0048. ATLAS-mapped mitigations: AML.M0005 Control Access to AI Models and Data at Rest, AML.M0012 Encrypt Sensitive Information, AML.M0017 AI Model Distribution Methods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-control-access-to-ai-models-and-data-at-rest",
      "mitre-atlas-mitigation-encrypt-sensitive-information",
      "mitre-atlas-mitigation-ai-model-distribution-methods"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-ai-model-inference-api-access",
    "title": "MITRE ATLAS AI Model Inference API Access (AML.T0040) - AI Model Access adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0040 (AI Model Inference API Access), an adversarial technique in the ATLAS AI Model Access tactic. Adversaries may gain access to a model via legitimate access to the inference API. Inference API access can be a source of information to the adversary (discover model ontology, discover model family), a means of staging the attack (verify attack, craft adv), or for introducing data to the target system for Impact (evade model, erode integrity). Many systems rely on the same models provided via an inference API, which means they share the same vulnerabilities. This is especially true of foundation models which are prohibitively resource intensive to train. Adversaries may use their access to model APIs to identify vulnerabilities such as jailbreaks or hallucinations and then target applications that use the same models. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-ai-service-api",
    "title": "MITRE ATLAS AI Service API (AML.T0096) - Adversarial AI Service API threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0096 (AI Service API). Adversaries may communicate using the API of an AI service on the victim's system. The adversary's commands to the victim system, and often the results, are embedded in the normal traffic of the AI service. An AI service API command and control channel is covert because the adversary's commands blend in with normal communications, so an adversary may use this technique to avoid detection. Using existing infrastructure on the victim's system allows the adversary to live off the land, further reducing their footprint. AI service APIs may be abused as C2 channels when an adversary wants to be stealthy and maintain long-term persistence for espionage activities [[microsoft]]. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-ai-service-proxies",
    "title": "MITRE ATLAS AI Service Proxies (AML.T0008.005) - Adversarial AI Service Proxies threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0008.005 (AI Service Proxies). Adversaries may utilize commercial proxy services that resell access to AI services such as frontier model APIs. This infrastructure can be used to conduct large-scale campaigns to perform Exfiltration via AI Inference API via distillation. Adversaries may also use this infrastructure to Generate Malicious Commands for offensive cyber operations, or to generate content for Spearphishing via Social Engineering LLM. Commercial AI service proxies distribute traffic from different accounts and various cloud platforms. The mix of traffic can make malicious activity difficult to detect and block [[anthropic]]. Malicious actors conduct LLM Jacking attacks to gain access to victim accounts which they resell access to in their proxy services [[sysdig]]. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0008.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-ai-software",
    "title": "MITRE ATLAS AI Software (AML.T0010.001) - Adversarial AI Software threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0010.001 (AI Software). Adversaries may target software packages that are commonly used in AI-enabled systems or are part of the AI DevOps lifecycle. This can include deep learning frameworks used to build AI models (e.g. PyTorch, TensorFlow, Jax), generative AI integration frameworks (e.g. LangChain, LangFlow), inference engines, and AI DevOps tools. They may also target the dependency chains of any of these software packages [[pytorch]]. Additionally, adversaries may target specific components used by AI software such as configuration files [[pillar]] or example usage of AI packages, which may be distributed in Jupyter notebooks [[medium]]. Adversaries may compromise legitimate packages [[aws]] or publish malicious software to a namesquatted location [[pytorch]]. They may target package names that are hallucina... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0010. ATLAS-mapped mitigations: AML.M0006 Use Ensemble Methods, AML.M0013 Code Signing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-use-ensemble-methods",
      "mitre-atlas-mitigation-code-signing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-ai-supply-chain-compromise",
    "title": "MITRE ATLAS AI Supply Chain Compromise Techniques (AML.T0010) - Targeting Model Repositories, Pre-Trained Weights, Datasets, and Third-Party AI Pipeline Components",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses adversarial techniques under MITRE ATLAS AML.T0010, focusing on AI supply chain compromises such as targeting model repositories, pre-trained weights, datasets, and third-party pipeline components. Compliance frameworks like the EU AI Act and NIST AI RMF mandate robust defenses against these threats to ensure AI system integrity and security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-ai-supply-chain-reputation-inflation",
    "title": "MITRE ATLAS AI Supply Chain Reputation Inflation (AML.T0111) - Adversarial AI Supply Chain Reputation Inflation threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0111 (AI Supply Chain Reputation Inflation). AI Supply Chain Reputation Inflation is the process of building or leveraging genuinely credible-looking trust signals to increase the perceived legitimacy of AI supply chain components, with the goal of driving adoption of malicious or compromised assets. Adversaries use established developer accounts with a history of legitimate projects and contributions to publish AI models, datasets, packages, and MCP servers that appear trustworthy. They build reputation through real adoption signals such as downloads, GitHub stars, forks, and inclusion in dependency chains, often releasing benign versions before introducing malicious updates via AI Supply Chain Rug Pull. By relying on authentic history and usage patterns, these components pass both human and automated trust checks, increasing the li... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-ai-supply-chain-rug-pull",
    "title": "MITRE ATLAS AI Supply Chain Rug Pull (AML.T0109) - Adversarial AI Supply Chain Rug Pull threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0109 (AI Supply Chain Rug Pull). Adversaries may publish legitimate AI components or software, gain user adoption, then push an update with a malicious variant, leading to AI Supply Chain Compromise. More scrutiny is often placed on a supply chain dependency when it is first being considered for inclusion in an AI system. Performing a rug pull may allow adversaries to bypass these defenses and be more likely to achieve Initial Access. Adversaries may publish malicious AI components via Publish Poisoned Models, Publish Poisoned Datasets, or Publish Poisoned AI Agent Tool. Adversaries may use other techniques (See AI Supply Chain Reputation Inflation) to gain user trust and increase adoption before performing the rug pull. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-ai-threat-matrix-2024",
    "title": "MITRE ATLAS™ - Adversarial Threat Landscape for Artificial-Intelligence Systems: Living Knowledge Base of Adversary Tactics, Techniques, Mitigations, and Case Studies for AI-Enabled Systems (Modeled After and Complementary to MITRE ATT&CK®)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-29",
    "bluf": "MITRE ATLAS™ (Adversarial Threat Landscape for Artificial-Intelligence Systems) is a globally accessible, living knowledge base of adversary tactics and techniques against AI-enabled systems based on real-world attack observations and realistic demonstrations from AI red teams and security groups. ATLAS is modeled after and complementary to MITRE ATT&CK®, raising awareness of the rapidly evolving vulnerabilities of AI-enabled systems as they extend beyond cyber. The ATLAS Matrix is structured as 16 tactic columns shown left-to-right representing the progression of tactics used in attacks, with ML techniques belonging to each tactic listed below. The 16 tactics, in matrix order, are: Reconnaissance, Resource Development, Initial Access, AI Model Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, AI Attack Staging, Command and Control, Exfiltration, and Impact. AI Model Access (4 techniques) and AI Attack Staging (6 techniques) are the two ATLAS-specific tactics with no ATT&CK equivalent; the other 14 tactics are adapted from ATT&CK (denoted by '&' in the matrix). Per the ATLAS landing page snapshot, ATLAS currently catalogues 16 tactics, 167 techniques (including sub-techniques), 35 mitigations, and 57 case studies. Each technique is filterable by Maturity classification: Feasible (the technique is plausible based on understanding of the system), Demonstrated (the technique has been shown to work in a research or academic setting), or Realized (the technique has been observed in real-world attack scenarios). ATLAS is the de-facto reference taxonomy for AI red-team operations, AI threat modelling, and adversarial-ML security evaluations; it is cited as an Informative Reference under NIST SP 800-218A and is foundational input to the EU AI Act Annex IV technical-documentation cybersecurity sections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "mitre-attack-enterprise",
        "us-nist-sp-800-218a-secure-ai-development",
        "us-nist-adversarial-ml-taxonomy",
        "owasp-llm-top-10-2025",
        "eu-ai-act-2024"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nist-sp-800-218a-secure-ai-development",
      "owasp-llm-top-10-2025"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-atlas-application-access-token",
    "title": "MITRE ATLAS Application Access Token (AML.T0091.000) - Adversarial use of Application Access Token as adapted in MITRE ATT&CK T1550.001",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0091.000 (Application Access Token). Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials. Application access tokens are used to make authorized API requests on behalf of a user or service and are commonly used to access resources in cloud, container-based applications, software-as-a-service (SaaS), and AI-as-a-service(AIaaS). They are commonly used for AI services such as chatbots, LLMs, and predictive inference APIs. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0091. ATT&CK reference: T1550.001 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-use-alternate-authentication-material"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-application-repository-search",
    "title": "MITRE ATLAS AI Reconnaissance via Application and Model Repositories (AML.T0004) - Compliance Obligations for Securing AI Artifacts in Public Code Repositories, Model Hubs, and Container Registries",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0004, focusing on securing AI artifacts in public repositories under the EU AI Act Articles 9 and 15. Key compliance action involves auditing and monitoring public repositories for unauthorized disclosures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-black-box-ml-attacks",
    "title": "MITRE ATLAS Black-Box Query-Based Attacks Against AI Models (AML.T0043.001) - Compliance Obligations for AI API Rate Limiting, Query Pattern Monitoring, and Adversarial Probing Detection Under AI Robustness Requirements",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0043.001 (Black-Box Query Attacks) under the EU AI Act, focusing on API rate limiting and adversarial probing detection. Key compliance actions align with Articles 9 and 15 for risk management and robustness.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-black-box-optimization",
    "title": "MITRE ATLAS Black-Box Optimization (AML.T0043.001) - Adversarial Black-Box Optimization threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0043.001 (Black-Box Optimization). In Black-Box attacks, the adversary has black-box (i.e. AI Model Inference API Access via API access) access to the target model. With black-box attacks, the adversary may be using an API that the victim is monitoring. These attacks are generally less effective and require more inferences than White-Box Optimization attacks, but they require much less access. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0043. ATLAS-mapped mitigations: AML.M0002 Passive AI Output Obfuscation, AML.M0003 Model Hardening, AML.M0004 Restrict Number of AI Model Queries, AML.M0006 Use Ensemble Methods, AML.M0010 Input Restoration, AML.M0015 Adversarial Input Detection, AML.M0019 Control Access to AI Models and Data in Production.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-passive-ai-output-obfuscation",
      "mitre-atlas-mitigation-model-hardening",
      "mitre-atlas-mitigation-restrict-number-of-ai-model-queries",
      "mitre-atlas-mitigation-use-ensemble-methods",
      "mitre-atlas-mitigation-input-restoration",
      "mitre-atlas-mitigation-adversarial-input-detection",
      "mitre-atlas-mitigation-control-access-to-ai-models-and-data-in-production"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-atlas-black-box-transfer",
    "title": "MITRE ATLAS Black-Box Transfer (AML.T0043.002) - Adversarial Black-Box Transfer threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0043.002 (Black-Box Transfer). In Black-Box Transfer attacks, the adversary uses one or more proxy models (trained via Create Proxy AI Model or Train Proxy via Replication) they have full access to and are representative of the target model. The adversary uses White-Box Optimization on the proxy models to generate adversarial examples. If the set of proxy models are close enough to the target model, the adversarial example should generalize from one to another. This means that an attack that works for the proxy models will likely then work for the target model. If the adversary has AI Model Inference API Access, they may use Verify Attack to confirm the attack is working and incorporate that information into their training process. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0043. ATLAS-mapped mitigations: AML.M0003 Model Hardening, AML.M0006 Use Ensemble Methods, AML.M0010 Input Restoration, AML.M0015 Adversarial Input Detection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-model-hardening",
      "mitre-atlas-mitigation-use-ensemble-methods",
      "mitre-atlas-mitigation-input-restoration",
      "mitre-atlas-mitigation-adversarial-input-detection"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-atlas-call-chains",
    "title": "MITRE ATLAS Call Chains (AML.T0084.003) - Adversarial Call Chains threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0084.003 (Call Chains). Adversaries may extract call chains from AI agent configurations, which can reveal potentially targets for remote code execution (RCE) or other vulnerabilities. Vulnerable call chains often connect user inputs or LLM outputs to an execution sink (e.g. exec, eval, os.popen). The vulnerabilities may be later exploited via LLM Prompt Injection. Adversaries may systematically identify potentially vulnerable call chains present in LLM frameworks, then scan for applications that are configured to use these call chains for targeting [[arxiv]]. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0084.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-discover-ai-agent-configuration"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-citations",
    "title": "MITRE ATLAS Citations (AML.T0067.000) - Adversarial Citations threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0067.000 (Citations). Adversaries may manipulate the citations provided in an AI system's response, in order to make it appear trustworthy. Variants include citing a providing the wrong citation, making up a new citation, or providing the right citation but for adversary-provided data. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0067.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-cloud-service-discovery",
    "title": "MITRE ATLAS Cloud Service Discovery (AML.T0075) - Adversarial use of Cloud Service Discovery as adapted in MITRE ATT&CK T1526",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0075 (Cloud Service Discovery). Adversaries may attempt to enumerate the cloud services running on a system after gaining access. These methods can differ from platform-as-a-service (PaaS), to infrastructure-as-a-service (IaaS), software-as-a-service (SaaS), or AI-as-a-service (AIaaS). Many services exist throughout the various cloud providers and can include Continuous Integration and Continuous Delivery (CI/CD), Lambda Functions, Entra ID, AI Inference, Generative AI, Agentic AI, etc. They may also include security services, such as AWS GuardDuty and Microsoft Defender for Cloud, and logging services, such as AWS CloudTrail and Google Cloud Audit Logs. Adversaries may attempt to discover information about the services enabled throughout the environment. Azure tools and APIs, such as the Microsoft Graph API and Azure Re... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1526 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-code-repositories",
    "title": "MITRE ATLAS Code Repositories (AML.T0095.000) - Adversarial use of Code Repositories as adapted in MITRE ATT&CK T1593.003",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0095.000 (Code Repositories). Adversaries may search public code repositories for information about a victim or victim system that can be used during targeting. Victims may store code or artifacts related to their AI systems in repositories on various third-party websites such as GitHub, GitLab, SourceForge, and BitBucket. Adversaries may search code repositories of common AI tools, frameworks, models, or agentic systems that are used--but not owned--by the victim. Public code repositories can often be a source of various information about victims, such as commonly used AI frameworks, libraries, models, datasets, agents, and agent tools, as well as the names of employees. Adversaries may also identify more sensitive data, including accidentally leaked credentials or API keys (ex: Credentials from AI Agent Configuration... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0095. ATT&CK reference: T1593.003 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-search-open-websites-domains"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-command-and-scripting-interpreter",
    "title": "MITRE ATLAS Command and Scripting Interpreter (AML.T0050) - Execution adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0050 (Command and Scripting Interpreter), an adversarial technique in the ATLAS Execution tactic. Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic. Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. Commands and scripts can be embedded in Initial Access payloads delivered to victims as lure documents or as secondary payloads downloaded from an existing C2. Adversaries may also execute commands through interactive terminals/shells, as well as utilize various Remote Services in order to achieve remote Execution. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Corresponds to MITRE ATT&CK T1059.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-container-registry",
    "title": "MITRE ATLAS Container Registry (AML.T0010.004) - Adversarial Container Registry threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0010.004 (Container Registry). An adversary may compromise a victim's container registry by pushing a manipulated container image and overwriting an existing container name and/or tag. Users of the container registry as well as automated CI/CD pipelines may pull the adversary's container image, compromising their AI Supply Chain. This can affect development and deployment environments. Container images may include AI models, so the compromised image could have an AI model which was manipulated by the adversary (See Manipulate AI Model). Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0010.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-corrupt-ai-model",
    "title": "MITRE ATLAS Corrupt AI Model (AML.T0076) - Adversarial Corrupt AI Model threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0076 (Corrupt AI Model). An adversary may purposefully corrupt a malicious AI model file so that it cannot be successfully deserialized in order to evade detection by a model scanner. The corrupt model may still successfully execute malicious code before deserialization fails. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-cost-harvesting",
    "title": "MITRE ATLAS AI Cost Harvesting Techniques (AML.T0034) - Excessive Query, Resource-Intensive Prompt, and Agentic Resource Consumption Attack Compliance Obligations for Cloud AI Governance",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses adversarial AI cost harvesting techniques under MITRE ATLAS AML.T0034, including Excessive Query, Resource-Intensive Prompt, and Agentic Resource Consumption attacks, with compliance obligations mandated by frameworks like the EU AI Act and NIST AI RMF to implement robust defenses against resource exploitation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-craft-adversarial-data",
    "title": "MITRE ATLAS Craft Adversarial Data for AI Model Attacks (AML.T0043) - Compliance Obligations for Adversarial Input Robustness Testing, Adversarial Example Detection, and AI System Resilience Validation Requirements",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0043 (Craft Adversarial Data), aligning with EU AI Act Articles 9 and 15 for robustness and risk management. Key compliance actions include adversarial training and regular red-team testing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-craft-adversarial-perturbations",
    "title": "MITRE ATLAS Craft Adversarial Perturbations for AI Model Evasion (AML.T0043) - Compliance Obligations for Adversarial Robustness Testing, Perturbation Detection Controls, and AI System Resilience Standards Under Article 15",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0043 (Craft Adversarial Perturbations for Evasion), aligning with EU AI Act Articles 15 and 9 for robustness and risk management. Key compliance action includes implementing certified adversarial robustness defences and conducting benchmarking.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-create-proxy-model",
    "title": "MITRE ATLAS Create Proxy AI Model Techniques (AML.T0005) - Compliance Obligations for Defending Against Model Replication, Shadow Model Attacks, and AI Intellectual Property Theft",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses adversarial techniques under MITRE ATLAS AML.T0005 (Create Proxy Models), focusing on model replication and shadow model attacks, with compliance obligations under frameworks like the EU AI Act and NIST AI RMF requiring robust defenses against AI intellectual property theft.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-credential-access-via-agent",
    "title": "MITRE ATLAS AI Agent Tool Credential Harvesting Techniques (AML.T0098) - Compliance Obligations for Securing Credentials Accessed by Autonomous AI Agents and Agentic Pipelines",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses adversarial techniques under MITRE ATLAS AML.T0098 (Credential Access via AI Agent Tools), focusing on harvesting credentials through autonomous AI agents. Compliance frameworks like the EU AI Act, NIST AI RMF, and ISO/IEC 42001 mandate robust defenses against such threats to ensure AI system security and accountability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-credentials-from-ai-agent-configuration",
    "title": "MITRE ATLAS Credentials from AI Agent Configuration (AML.T0083) - Adversarial Credentials from AI Agent Configuration threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0083 (Credentials from AI Agent Configuration). Adversaries may access the credentials of other tools or services on a system from the configuration of an AI agent. AI Agents often utilize external tools or services to take actions, such as querying databases, invoking APIs, or interacting with cloud resources. To enable these functions, credentials like API keys, tokens, and connection strings are frequently stored in configuration files. While there are secure methods such as dedicated secret managers or encrypted vaults that can be deployed to store and manage these credentials, in practice they are often placed in less protected locations for convenience or ease of deployment. If an attacker can read or extract these configurations, they may obtain valid credentials that allow direct access to sensitive systems outside the agent its... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-data",
    "title": "MITRE ATLAS Data (AML.T0010.002) - Adversarial Data threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0010.002 (Data). Data is a key vector of supply chain compromise for adversaries. Every AI project will require some form of data. Many rely on large open source datasets that are publicly available. An adversary could rely on compromising these sources of data. The malicious data could be a result of Poison Training Data or include traditional malware. An adversary can also target private datasets in the labeling phase. The creation of private datasets will often require the hiring of outside labeling services. An adversary can poison a dataset by modifying the labels being generated by the labeling service. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0010. ATLAS-mapped mitigations: AML.M0005 Control Access to AI Models and Data at Rest, AML.M0007 Sanitize Training Data, AML.M0014 Verify AI Artifacts, AML.M0025 Maintain AI Dataset Provenance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-control-access-to-ai-models-and-data-at-rest",
      "mitre-atlas-mitigation-sanitize-training-data",
      "mitre-atlas-mitigation-verify-ai-artifacts",
      "mitre-atlas-mitigation-maintain-ai-dataset-provenance"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-atlas-data-destruction-agent",
    "title": "MITRE ATLAS Data Destruction via Compromised AI Agent Actions (AML.T0101) - Compliance Obligations for Agentic AI Data Deletion Controls, Agent Action Reversibility Requirements, and Autonomous System Destructive Action Governance",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0101 (Data Destruction via Compromised AI Agent), aligning with EU AI Act Articles 9, 14, and 15 for robust AI governance. Key compliance actions include implementing data deletion controls and ensuring agent action reversibility.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-data-from-ai-services",
    "title": "MITRE ATLAS Data from AI Services (AML.T0085) - Adversary Collection of Data from AI Services",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0085 (Data from AI Services). Adversaries may use their access to a victim organization's AI-enabled services to collect proprietary or otherwise sensitive information. As organizations adopt generative AI in centralized services for accessing an organization's data, such as with chat agents which can access retrieval augmented generation (RAG) databases and other data sources via tools, they become increasingly valuable targets for adversaries. AI agents may be configured to have access to tools and data sources that are not directly accessible by users. Adversaries may abuse this to collect data that a regular user wouldn't be able to access directly. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-ai-telemetry-logging",
      "mitre-atlas-mitigation-privileged-ai-agent-permissions-configuration",
      "mitre-atlas-mitigation-single-user-ai-agent-permissions-configuration",
      "mitre-atlas-mitigation-ai-agent-tools-permissions-configuration",
      "mitre-atlas-mitigation-segmentation-of-ai-agent-components",
      "owasp-llm-06-sensitive-information-disclosure"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-atlas-data-from-information-repositories",
    "title": "MITRE ATLAS Data from Information Repositories (AML.T0036) - Adversarial use of Data from Information Repositories as adapted in MITRE ATT&CK T1213",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0036 (Data from Information Repositories). Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, or direct access to the target information. Information stored in a repository may vary based on the specific instance or environment. Specific common information repositories include SharePoint, Confluence, and enterprise databases such as SQL Server. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1213 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-data-from-local-system",
    "title": "MITRE ATLAS Data from Local System (AML.T0037) - Adversarial use of Data from Local System as adapted in MITRE ATT&CK T1005",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0037 (Data from Local System). Adversaries may search local system sources, such as file systems and configuration files or local databases, to find files of interest and sensitive data prior to Exfiltration. This can include basic fingerprinting information and sensitive data such as ssh keys. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1005 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-data-poisoning",
    "title": "MITRE ATLAS Training Data Poisoning and Backdoor Attack Techniques (AML.T0020) - Corrupting Training and Fine-Tuning Datasets for Persistent Model Manipulation",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0020 (Training Data Poisoning), focusing on adversarial corruption of training and fine-tuning datasets to embed persistent backdoors in AI models. Compliance with frameworks like the EU AI Act and NIST AI RMF is required to implement defenses against such model manipulation risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-datasets",
    "title": "MITRE ATLAS Datasets (AML.T0002.000) - Adversarial Datasets threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0002.000 (Datasets). Adversaries may collect public datasets to use in their operations. Datasets used by the victim organization or datasets that are representative of the data used by the victim organization may be valuable to adversaries. Datasets can be stored in cloud storage, or on victim-owned websites. Some datasets require the adversary to Establish Accounts for access. Acquired datasets help the adversary advance their operations, stage attacks, and tailor attacks to the victim organization. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0002. ATLAS-mapped mitigations: AML.M0001 Limit Model Artifact Release.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-limit-model-artifact-release"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-deepfake-assisted-phishing",
    "title": "MITRE ATLAS Deepfake-Assisted Phishing (AML.T0052.001) - Adversarial Deepfake-Assisted Phishing threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0052.001 (Deepfake-Assisted Phishing). Adversaries may use deepfakes (AI-generated synthetic images, audio, or video) in phishing campaigns to impersonate trusted individuals, executives, or organizations. These attacks exploit human trust by presenting fraudulent voice or video communications as legitimate, enabling adversaries to manipulate targets into disclosing credentials, transferring funds, or granting access to systems. Voice deepfakes (AI-cloned voices) are used in vishing [[vishing]] (voice phishing) attacks over telephone or VoIP. Adversaries can clone a target's voice using a few seconds [[valle]] of publicly available audio from speeches, earnings calls, podcasts, or social media [[voice]]. These cloned voices are then used in pre-recorded voicemail messages or live phone calls. Video deepfakes can impersonate a t... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0052. ATLAS-mapped mitigations: AML.M0018 User Training, AML.M0034 Deepfake Detection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-user-training",
      "mitre-atlas-mitigation-deepfake-detection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-deepfake-generation",
    "title": "MITRE ATLAS AI-Generated Deepfake Techniques (AML.T0088) - Synthetic Media Generation for Identity Fraud, Disinformation, and Social Engineering - Regulatory Compliance Obligations",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0088 (Generate Synthetic Media), focusing on adversarial AI tactics for creating deepfakes used in identity fraud, disinformation, and social engineering. Compliance obligations under frameworks like the EU AI Act and NIST AI RMF mandate robust defenses against such synthetic content threats.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-defense-evasion-agent",
    "title": "MITRE ATLAS Defense Evasion via AI Agent Actions (AML.T0107) - Compliance Obligations for Agentic AI Audit Trail Integrity, Agent Action Non-Repudiation, and Autonomous System Security Control Bypass Detection",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0107 on Defense Evasion via AI Agent Actions, aligning with EU AI Act Articles 9 and 15 for robust cybersecurity and risk management. Key compliance action is implementing append-only audit logging and agent action monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-delay-execution-of-llm-instructions",
    "title": "MITRE ATLAS Delay Execution of LLM Instructions (AML.T0094) - Adversarial Delay Execution of LLM Instructions threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0094 (Delay Execution of LLM Instructions). Adversaries may include instructions to be followed by the AI system in response to a future event, such as a specific keyword or the next interaction, in order to evade detection or bypass controls placed on the AI system. For example, an adversary may include \"If the user submits a new request...\" followed by the malicious instructions as part of their prompt. AI agents can include security measures against prompt injections that prevent the invocation of particular tools or access to certain data sources during a conversation turn that has untrusted data in context. Delaying the execution of instructions to a future interaction or keyword is one way adversaries may bypass this type of control. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-deploy-ai-agent",
    "title": "MITRE ATLAS Deploy AI Agent (AML.T0103) - Execution adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0103 (Deploy AI Agent), an adversarial technique in the ATLAS Execution tactic. Adversaries may launch AI agents in the victim's environment to execute actions on their behalf. AI agents may have access to a wide range of tools and data sources, as well as permissions to access and interact with other services and systems in the victim's environment. The adversary may leverage these capabilities to carry out their operations. Adversaries may configure the AI agent by providing an initial system prompt and granting access to tools, effectively defining their goals for the agent to achieve. They may deploy the agent with excessive trust permissions and disable any user interactions to ensure the agent's actions aren't blocked. Launching an AI agent may provide for some autonomous behavior, allowing for the agent to make decisions and determine how to achieve the adversary's goals. This also represents a loss of control for the adversary. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-develop-adversarial-capabilities",
    "title": "MITRE ATLAS Develop Adversarial AI Capabilities and Attack Infrastructure (AML.T0017) - Compliance Obligations for AI Red Team Governance, Adversarial Capability Monitoring, and Threat Intelligence Sharing Requirements",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses compliance obligations under MITRE ATLAS technique AML.T0017 for developing adversarial AI capabilities and attack infrastructure, aligning with EU AI Act requirements under Articles 5, 15, and 50 for high-risk AI system governance and threat monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-direct",
    "title": "MITRE ATLAS Direct (AML.T0051.000) - Adversarial Direct threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0051.000 (Direct). An adversary may inject prompts directly as a user of the LLM. This type of injection may be used by the adversary to gain a foothold in the system or to misuse the LLM itself, as for example to generate harmful content. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0051. ATLAS-mapped mitigations: AML.M0024 AI Telemetry Logging, AML.M0033 Input and Output Validation for AI Agent Components.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-ai-telemetry-logging",
      "mitre-atlas-mitigation-input-and-output-validation-for-ai-agent-components"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-discover-ai-agent-configuration",
    "title": "MITRE ATLAS Discover AI Agent Configuration (AML.T0084) - Adversarial Discover AI Agent Configuration threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0084 (Discover AI Agent Configuration). Adversaries may attempt to discover configuration information for AI agents present on the victim's system. Agent configurations can include tools or services they have access to. Adversaries may directly access agent configuring dashboards or configuration files. They may also obtain configuration details by prompting the agent with questions such as \"What tools do you have access to?\" Adversaries can use the information they discover about AI agents to help with targeting. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-discover-ai-artifacts",
    "title": "MITRE ATLAS Discover AI Artifacts (AML.T0007) - Adversary Discovery of AI Artifacts in Victim Environment",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0007 (Discover AI Artifacts). Adversaries may search private sources to identify AI learning artifacts that exist on the system and gather information about them. These artifacts can include the software stack used to train and deploy models, training and testing data management systems, container registries, software repositories, and model zoos. This information can be used to identify targets for further collection, exfiltration, or disruption, and to tailor and improve attacks. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-control-access-to-ai-models-and-data-at-rest",
      "mitre-atlas-mitigation-encrypt-sensitive-information"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-discover-ai-model-ontology",
    "title": "MITRE ATLAS Discover AI Model Ontology (AML.T0013) - Adversary Discovery of AI Model Ontology for Targeted Attack",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0013 (Discover AI Model Ontology). Adversaries may discover the ontology of an AI model's output space, for example, the types of objects a model can detect. The adversary may discovery the ontology by repeated queries to the model, forcing it to enumerate its output space. Or the ontology may be discovered in a configuration file or in documentation about the model. The model ontology helps the adversary understand how the model is being used by the victim. It is useful to the adversary in creating targeted attacks. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-passive-ai-output-obfuscation",
      "mitre-atlas-mitigation-restrict-number-of-ai-model-queries"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-discover-ai-model-outputs",
    "title": "MITRE ATLAS Discover AI Model Outputs (AML.T0063) - Adversarial Discovery of AI Model Outputs to Extract Information",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0063 (Discover AI Model Outputs). Adversaries may discover model outputs, such as class scores, whose presence is not required for the system to function and are not intended for use by the end user. Model outputs may be found in logs or may be included in API responses. Model outputs may enable the adversary to identify weaknesses in the model and develop attacks. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-passive-ai-output-obfuscation",
      "mitre-atlas-mitigation-encrypt-sensitive-information",
      "mitre-atlas-mitigation-ai-model-distribution-methods",
      "mitre-atlas-mitigation-control-access-to-ai-models-and-data-in-production"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-atlas-discover-llm-hallucinations",
    "title": "MITRE ATLAS Discover LLM Hallucinations (AML.T0062) - Adversarial Discovery of LLM Hallucinations for Exploitation",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0062 (Discover LLM Hallucinations). Adversaries may prompt large language models and identify hallucinated entities. They may request software packages, commands, URLs, organization names, or e-mail addresses, and identify hallucinations with no connected real-world source. Discovered hallucinations provide the adversary with potential targets to Publish Hallucinated Entities. Different LLMs have been shown to produce the same hallucinations, so the hallucinations exploited by an adversary may affect users of other LLMs. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-restrict-number-of-ai-model-queries",
      "mitre-atlas-mitigation-generative-ai-guardrails",
      "mitre-atlas-mitigation-generative-ai-guidelines",
      "mitre-atlas-mitigation-generative-ai-model-alignment",
      "mitre-atlas-llm-prompt-injection"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-atlas-discover-llm-system-information",
    "title": "MITRE ATLAS Discover LLM System Information (AML.T0069) - Adversarial Discover LLM System Information threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0069 (Discover LLM System Information). The adversary is trying to discover something about the large language model's (LLM) system information. This may be found in a configuration file containing the system instructions or extracted via interactions with the LLM. The desired information may include the full system prompt, special characters that have significance to the LLM or keywords indicating functionality available to the LLM. Information about how the LLM is instructed can be used by the adversary to understand the system's capabilities and to aid them in crafting malicious prompts. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-discovery-via-agent",
    "title": "MITRE ATLAS System and Environment Discovery via AI Agent Actions (AML.TA0008) - Compliance Obligations for Agentic AI Reconnaissance Controls, Agent Information Gathering Limits, and Autonomous Discovery Activity Monitoring",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS tactic AML.TA0008 for system and environment discovery via AI agents, aligning with EU AI Act Articles 9 and 15. Key compliance actions include implementing scope limitations and monitoring agent query patterns.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-domains",
    "title": "MITRE ATLAS Domains (AML.T0008.002) - Adversarial use of Domains as adapted in MITRE ATT&CK T1583.001",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0008.002 (Domains). Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free. Adversaries may use acquired domains for a variety of purposes (see ATT&CK). Large AI datasets are often distributed as a list of URLs to individual datapoints. Adversaries may acquire expired domains that are included in these datasets and replace individual datapoints with poisoned examples (Publish Poisoned Datasets). Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0008. ATT&CK reference: T1583.001 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-drive-by-compromise",
    "title": "MITRE ATLAS Drive-by Compromise (AML.T0078) - Adversarial use of Drive-by Compromise as adapted in MITRE ATT&CK T1189",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0078 (Drive-by Compromise). Adversaries may gain access to an AI system through a user visiting a website over the normal course of browsing, or an AI agent retrieving information from the web on behalf of a user. Websites can contain an LLM Prompt Injection which, when executed, can change the behavior of the AI model. The same approach may be used to deliver other types of malicious code that don't target AI directly (See Drive-by Compromise in ATT&CK). Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1189 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-embed-malware",
    "title": "MITRE ATLAS Embed Malware (AML.T0018.002) - Adversarial Embed Malware threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0018.002 (Embed Malware). Adversaries may embed malicious code into AI Model files. AI models may be packaged as a combination of instructions and weights. Some formats such as pickle files are unsafe to deserialize because they can contain unsafe calls such as exec. Models with embedded malware may still operate as expected. It may allow them to achieve Execution, Command & Control, or Exfiltrate Data. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0018. ATLAS-mapped mitigations: AML.M0013 Code Signing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-code-signing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-embedded-knowledge",
    "title": "MITRE ATLAS Embedded Knowledge (AML.T0084.000) - Adversarial Embedded Knowledge threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0084.000 (Embedded Knowledge). Adversaries may attempt to discover the data sources a particular agent can access. The AI agent's configuration may reveal data sources or knowledge. The embedded knowledge may include sensitive or proprietary material such as intellectual property, customer data, internal policies, or even credentials. By mapping what knowledge an agent has access to, an adversary can better understand the AI agent's role and potentially expose confidential information or pinpoint high-value targets for further exploitation. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0084.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-discover-ai-agent-configuration"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-erode-ai-model-integrity",
    "title": "MITRE ATLAS Erode AI Model Integrity (AML.T0031) - Adversarial Erosion of AI Model Integrity Over Time",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0031 (Erode AI Model Integrity). Adversaries may degrade the target model's performance with adversarial data inputs to erode confidence in the system over time. This can lead to the victim organization wasting time and money both attempting to fix the system and performing the tasks it was meant to automate by hand. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-model-hardening",
      "mitre-atlas-mitigation-use-ensemble-methods",
      "mitre-atlas-mitigation-input-restoration",
      "mitre-atlas-mitigation-adversarial-input-detection",
      "nist-ai-rmf-1-0-manage-function"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-atlas-erode-dataset-integrity",
    "title": "MITRE ATLAS Erode Dataset Integrity Techniques (AML.T0059) - Compliance Obligations for Training Data Provenance, Continuous Dataset Integrity Monitoring, and Adversarial Dataset Corruption Response",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses adversarial techniques under MITRE ATLAS AML.T0059 (Erode Dataset Integrity), focusing on dataset poisoning and corruption tactics. Compliance frameworks like the EU AI Act and NIST AI RMF mandate robust defenses through data governance and integrity monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-escape-to-host",
    "title": "MITRE ATLAS Escape to Host (AML.T0105) - Privilege Escalation adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0105 (Escape to Host), an adversarial technique in the ATLAS Privilege Escalation tactic. Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can allow an adversary access to other containerized or virtualized resources from the host level or to the host itself. In principle, containerized / virtualized resources should provide a clear separation of application functionality and be isolated from the host environment. There are many ways an adversary may escape from a container or sandbox environment via AI Systems. For example, modifying an AI Agent's configuration to disable safety features or user confirmations could allow the adversary to invoke tools to be run on host environments rather than in the sandbox. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Corresponds to MITRE ATT&CK T1611.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-establish-accounts",
    "title": "MITRE ATLAS Establish Accounts (AML.T0021) - Adversarial use of Establish Accounts as adapted in MITRE ATT&CK T1585",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0021 (Establish Accounts). Adversaries may create accounts with various services for use in targeting, to gain access to resources needed in AI Attack Staging, or for victim impersonation. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1585 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-evade-ai-model",
    "title": "MITRE ATLAS Evade AI Model (AML.T0015) - Adversarial Evasion of AI Model Classification at Inference Time",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0015 (Evade AI Model). Adversaries can Craft Adversarial Data that prevents an AI model from correctly identifying the contents of the data or Generate Deepfakes that fools an AI model expecting authentic data. This technique can be used to evade a downstream task where AI is utilized. The adversary may evade AI-based virus/malware detection or network scanning towards the goal of a traditional cyber attack. AI model evasion through deepfake generation may also provide initial access to systems that use AI-based biometric authentication. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-model-hardening",
      "mitre-atlas-mitigation-use-ensemble-methods",
      "mitre-atlas-mitigation-use-multi-modal-sensors",
      "mitre-atlas-mitigation-input-restoration",
      "mitre-atlas-mitigation-adversarial-input-detection",
      "mitre-atlas-mitigation-deepfake-detection",
      "mitre-atlas-craft-adversarial-data",
      "mitre-atlas-craft-adversarial-perturbations"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-atlas-evasion-via-explanation-methods",
    "title": "MITRE ATLAS Adversarial Evasion via AI Explanation Method Exploitation (AML.T0015) - Compliance Obligations for XAI Security Controls, SHAP and LIME Attack Defence, and Explainability System Integrity Monitoring",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0015, focusing on adversarial evasion via explanation methods, aligns with EU AI Act Articles 9 and 15, and mandates robust security controls for explainability systems. Key compliance action is restricting access to detailed explanation outputs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-excessive-queries",
    "title": "MITRE ATLAS Excessive Queries (AML.T0034.000) - Adversarial Excessive Queries threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0034.000 (Excessive Queries). Adversaries may send an excessive number of otherwise normal or low-complexity queries to an AI system with the goal of overwhelming its capacity and increasing operating costs. The attacker can automate high-volume request generation, exploiting rate limits, autoscaling policies, and pay-per-use billing models to drive sustained resource consumption without relying on specially crafted, computationally expensive inputs. This behavior can also lead to increased latency, request queuing, and service degradation or unavailability for legitimate users, as the system struggles to process the inflated traffic. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0034.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-execution-via-agent",
    "title": "MITRE ATLAS Code and Command Execution via Hijacked AI Agent (AML.T0053) - Compliance Obligations for Agentic AI Code Execution Sandboxing, Tool Call Validation, and Autonomous System Remote Execution Governance",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses the MITRE ATLAS technique AML.T0053, focusing on preventing code execution via hijacked AI agents, aligned with EU AI Act Articles 9, 14, and 15. Key compliance actions include sandboxing, allowlisting, and human oversight for agent-initiated executions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-exfiltration-agent",
    "title": "MITRE ATLAS Data Exfiltration via Compromised AI Agent Tool Calls (AML.T0086) - Compliance Obligations for Agentic AI Data Loss Prevention, Agent Output Monitoring, and Autonomous Exfiltration Detection Controls",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0086, focusing on data exfiltration via compromised AI agent tool calls, aligning with EU AI Act Articles 9 and 15 for risk management and cybersecurity. Key compliance actions include implementing DLP controls and monitoring agent tool calls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-exfiltration-via-ai-agent-tool-invocation",
    "title": "MITRE ATLAS Exfiltration via AI Agent Tool Invocation (AML.T0086) - Adversary Use of AI Agent Write-Capable Tools to Exfiltrate Sensitive Data",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0086 (Exfiltration via AI Agent Tool Invocation). AI agent tools capable of performing write operations may be invoked to exfiltrate data to an adversary. Sensitive information can be encoded into the tool's input parameters and transmitted to an adversary-controlled location (such as an inbox, document, or server) as part of a seemingly legitimate action. Variants include sending emails, creating or modifying documents, updating CRM records, or even generating media such as images or videos. The invoked tool itself may be legitimate but invoked by an adversary via LLM Prompt Injection, or the tool may be malicious (See AI Agent Tool Poisoning. AI Agent Tool Poisoning can also be used manipulate the inputs and destination of a separate legitimate tool, invoked through normal usage by the victim. Compliance frameworks including the EU AI Act, NIST AI RMF, and ISO/IEC 42001 require organisations to detect, monitor, and defend against this technique to preserve AI system integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10",
      "mitre-atlas-llm-prompt-injection"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-exfiltration-via-ai-inference",
    "title": "MITRE ATLAS Exfiltration via AI Inference API Techniques (AML.T0024) - Model Inversion, Training Data Membership Inference, and AI Model Extraction Attacks Under Data Protection Law",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses adversarial AI techniques under MITRE ATLAS AML.T0024, including model inversion, training data membership inference, and AI model extraction attacks, with compliance obligations mandated by frameworks like the EU AI Act and NIST AI RMF to implement robust defenses against data exfiltration risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-exfiltration-via-cyber-means",
    "title": "MITRE ATLAS Exfiltration via Cyber Means (AML.T0025) - Exfiltration adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0025 (Exfiltration via Cyber Means), an adversarial technique in the ATLAS Exfiltration tactic. Adversaries may exfiltrate AI artifacts or other information relevant to their goals via traditional cyber means. See the ATT&CK Exfiltration tactic for more information. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-exploit-public-facing-application",
    "title": "MITRE ATLAS Exploit Public-Facing Application (AML.T0049) - Adversarial use of Exploit Public-Facing Application as adapted in MITRE ATT&CK T1190",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0049 (Exploit Public-Facing Application). Adversaries may attempt to take advantage of a weakness in an Internet-facing computer or program using software, data, or commands in order to cause unintended or unanticipated behavior. The weakness in the system can be a bug, a glitch, or a design vulnerability. These applications are often websites, but can include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other applications with Internet accessible open sockets, such as web servers and related services. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1190 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-exploitation-for-credential-access",
    "title": "MITRE ATLAS Exploitation for Credential Access (AML.T0106) - Credential Access adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0106 (Exploitation for Credential Access), an adversarial technique in the ATLAS Credential Access tactic. Adversaries may exploit software vulnerabilities in an attempt to collect credentials. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Corresponds to MITRE ATT&CK T1211.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-exploitation-for-defense-evasion",
    "title": "MITRE ATLAS Exploitation for Defense Evasion (AML.T0107) - Adversarial use of Exploitation for Defense Evasion as adapted in MITRE ATT&CK T1211",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0107 (Exploitation for Defense Evasion). Adversaries may exploit a system or application vulnerability to bypass security features. Exploitation of a vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Vulnerabilities may exist in defensive security software that can be used to disable or circumvent them. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1211 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-extract-ai-model",
    "title": "MITRE ATLAS Extract AI Model (AML.T0024.002) - Adversarial Extract AI Model threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0024.002 (Extract AI Model). Adversaries may extract a functional copy of a private model. By repeatedly querying the victim's AI Model Inference API Access, the adversary can collect the target model's inferences into a dataset. The inferences are used as labels for training a separate model offline that will mimic the behavior and performance of the target model. Adversaries may extract the model to avoid paying per query in an artificial-intelligence-as-a-service (AIaaS) setting. Model extraction is used for AI Intellectual Property Theft. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0024. ATLAS-mapped mitigations: AML.M0002 Passive AI Output Obfuscation, AML.M0004 Restrict Number of AI Model Queries, AML.M0024 AI Telemetry Logging.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-passive-ai-output-obfuscation",
      "mitre-atlas-mitigation-restrict-number-of-ai-model-queries",
      "mitre-atlas-mitigation-ai-telemetry-logging"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-extract-system-prompt",
    "title": "MITRE ATLAS LLM System Prompt Extraction Techniques (AML.T0056) - Intellectual Property Protection and Confidential AI Configuration Disclosure Compliance Obligations",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses adversarial techniques for extracting system prompts from large language models as defined in MITRE ATLAS AML.T0056 (LLM System Prompt Extraction), focusing on compliance obligations under frameworks like the EU AI Act and NIST AI RMF to protect intellectual property and confidential AI configurations. It outlines mandatory defenses against unauthorized disclosure of sensitive model instructions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-false-rag-injection",
    "title": "MITRE ATLAS False RAG Entry Injection Techniques (AML.T0071) - Defense Evasion via Retrieval-Augmented Generation Knowledge Base Integrity Attacks and Misinformation Insertion",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0071, focusing on False RAG Entry Injection for defense evasion through misinformation insertion in retrieval-augmented generation systems. Compliance with frameworks like the EU AI Act and NIST AI RMF is required to mitigate these adversarial AI threats.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-financial-harm",
    "title": "MITRE ATLAS Financial Harm (AML.T0048.000) - Adversarial Financial Harm threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0048.000 (Financial Harm). Financial harm involves the loss of wealth, property, or other monetary assets due to theft, fraud or forgery, or pressure to provide financial resources to the adversary. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0048.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-full-ml-model-access",
    "title": "MITRE ATLAS Obtaining Full AI Model Access for Attack Staging (AML.T0044) - Compliance Obligations for AI System Access Control, Privileged Model Access Governance, and Insider Threat Detection for AI Pipelines",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0044 (Obtaining Full ML Model Access) under the EU AI Act, focusing on robust access controls and cybersecurity. Key compliance actions align with Articles 9 and 15 for risk management and system protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-functionally-equivalent-extraction",
    "title": "MITRE ATLAS Functionally Equivalent AI Model Extraction via Query Replication (AML.T0024.002) - Compliance Obligations for AI Intellectual Property Protection, Model Extraction Defence, and API Usage Analytics Controls",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0024.002, focusing on defending against functionally equivalent model extraction via query replication, aligned with EU AI Act Articles 9 and 15 for risk management and cybersecurity. Key compliance actions include API monitoring and rate limiting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-gather-rag-indexed-targets",
    "title": "MITRE ATLAS Gather RAG-Indexed Targets (AML.T0064) - Adversarial Gather RAG-Indexed Targets threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0064 (Gather RAG-Indexed Targets). Adversaries may identify data sources used in retrieval augmented generation (RAG) systems for targeting purposes. By pinpointing these sources, attackers can focus on poisoning or otherwise manipulating the external data repositories the AI relies on. RAG-indexed data may be identified in public documentation about the system, or by interacting with the system directly and observing any indications of or references to external data sources. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-gather-victim-identity-information",
    "title": "MITRE ATLAS Gather Victim Identity Information (AML.T0087) - Adversarial use of Gather Victim Identity Information as adapted in MITRE ATT&CK T1589",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0087 (Gather Victim Identity Information). Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, photos, etc.) as well as sensitive details such as credentials or multi-factor authentication (MFA) configurations. Adversaries may gather this information in various ways, such as direct elicitation, Search Victim-Owned Websites, or via leaked information on the black market. Adversaries may use the gathered victim data to Create Deepfakes and impersonate them in a convincing manner. This may create opportunities for adversaries to Establish Accounts under the impersonated identity, or allow them to perform convincing Phishing attacks. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1589 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-generate-malicious-commands",
    "title": "MITRE ATLAS Generate Malicious Commands (AML.T0102) - AI Attack Staging adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0102 (Generate Malicious Commands), an adversarial technique in the ATLAS AI Attack Staging tactic. Adversaries may use large language models (LLMs) to dynamically generate malicious commands from natural language. Dynamically generated commands may be harder detect as the attack signature is constantly changing. AI-generated commands may also allow adversaries to more rapidly adapt to different environments and adjust their tactics. Adversaries may utilize LLMs present in the victim's environment or call out to externally hosted services. APT28 utilized a model hosted on HuggingFace in a campaign with their LAMEHUG malware [\\[1\\]][1]. In either case prompts to generate malicious code can blend in with normal traffic. [1]: https://logpoint.com/en/blog/apt28s-new-arsenal-lamehug-the-first-ai-powered-malware Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-generative-ai",
    "title": "MITRE ATLAS Generative AI (AML.T0016.002) - Adversarial Generative AI threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0016.002 (Generative AI). Adversaries may search for and obtain generative AI models or tools, such as large language models (LLMs), to assist them in various steps of their operation. Generative AI can be used in a variety of malicious ways, such as to generating malware, to Generate Deepfakes, to Generate Malicious Commands, for Retrieval Content Crafting, or to generate Phishing content. Adversaries may obtain open source models and serve them locally using frameworks such as Ollama or vLLM. They may host them using cloud infrastructure. Or, they may leverage AI service providers such as HuggingFace. They may need to jailbreak the model (see LLM Jailbreak) to bypass any restrictions put in place to limit the types of responses it can generate. They may also need to break the terms of service of the model's devel... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0016.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-hardware",
    "title": "MITRE ATLAS Hardware (AML.T0010.000) - Adversarial Hardware threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0010.000 (Hardware). Adversaries may target AI systems by disrupting or manipulating the hardware supply chain. AI models often run on specialized hardware such as GPUs, TPUs, or embedded devices, but may also be optimized to operate on CPUs. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0010.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-identity-theft-synthetic-media",
    "title": "MITRE ATLAS Identity Theft via AI Synthetic Media and Biometric Spoofing (AML.T0073) - Compliance Obligations for Biometric AI Fraud Prevention, Synthetic Identity Detection, and AI-Enabled Identity Theft Incident Response",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0073, focusing on identity theft via AI synthetic media, aligning with EU AI Act Articles 9, 15, and 50 for robust AI fraud prevention. Key compliance actions include implementing liveness detection and synthetic media disclosure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-impersonation",
    "title": "MITRE ATLAS Impersonation (AML.T0073) - Adversarial use of Impersonation as adapted in MITRE ATT&CK T1656",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0073 (Impersonation). Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing, or Spearphishing via Social Engineering LLM) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary's ultimate goals, possibly against multiple victims. Adversaries may target resources that are part of the AI DevOps lifecycle, such as model repositories, container registries, and software registries. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1656 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-indirect",
    "title": "MITRE ATLAS Indirect (AML.T0051.001) - Adversarial Indirect threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0051.001 (Indirect). An adversary may inject prompts indirectly via separate data channel ingested by the LLM such as include text or multimedia pulled from databases or websites. These malicious prompts may be hidden or obfuscated from the user. This type of injection may be used by the adversary to gain a foothold in the system or to target an unwitting user of the system. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0051. ATLAS-mapped mitigations: AML.M0024 AI Telemetry Logging, AML.M0033 Input and Output Validation for AI Agent Components.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-ai-telemetry-logging",
      "mitre-atlas-mitigation-input-and-output-validation-for-ai-agent-components"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-infer-training-data-membership",
    "title": "MITRE ATLAS Infer Training Data Membership (AML.T0024.000) - Adversarial Infer Training Data Membership threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0024.000 (Infer Training Data Membership). Adversaries may infer the membership of a data sample or global characteristics of the data in its training set, which raises privacy concerns. Some strategies make use of a shadow model that could be obtained via Train Proxy via Replication, others use statistics of model prediction scores. This can cause the victim model to leak private information, such as PII of those in the training set or other forms of protected IP. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0024. ATLAS-mapped mitigations: AML.M0002 Passive AI Output Obfuscation, AML.M0004 Restrict Number of AI Model Queries, AML.M0024 AI Telemetry Logging.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-passive-ai-output-obfuscation",
      "mitre-atlas-mitigation-restrict-number-of-ai-model-queries",
      "mitre-atlas-mitigation-ai-telemetry-logging"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-insert-backdoor-trigger",
    "title": "MITRE ATLAS Insert Backdoor Trigger (AML.T0043.004) - Adversarial Insert Backdoor Trigger threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0043.004 (Insert Backdoor Trigger). The adversary may add a perceptual trigger into inference data. The trigger may be imperceptible or non-obvious to humans. This technique is used in conjunction with Poison AI Model and allows the adversary to produce their desired effect in the target model. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0043. ATLAS-mapped mitigations: AML.M0003 Model Hardening, AML.M0006 Use Ensemble Methods, AML.M0008 Validate AI Model, AML.M0010 Input Restoration, AML.M0015 Adversarial Input Detection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-model-hardening",
      "mitre-atlas-mitigation-use-ensemble-methods",
      "mitre-atlas-mitigation-validate-ai-model",
      "mitre-atlas-mitigation-input-restoration",
      "mitre-atlas-mitigation-adversarial-input-detection"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-atlas-invert-ai-model",
    "title": "MITRE ATLAS Invert AI Model (AML.T0024.001) - Adversarial Invert AI Model threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0024.001 (Invert AI Model). AI models' training data could be reconstructed by exploiting the confidence scores that are available via an inference API. By querying the inference API strategically, adversaries can back out potentially private information embedded within the training data. This could lead to privacy violations if the attacker can reconstruct the data of sensitive features used in the algorithm. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0024. ATLAS-mapped mitigations: AML.M0002 Passive AI Output Obfuscation, AML.M0004 Restrict Number of AI Model Queries, AML.M0024 AI Telemetry Logging.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-passive-ai-output-obfuscation",
      "mitre-atlas-mitigation-restrict-number-of-ai-model-queries",
      "mitre-atlas-mitigation-ai-telemetry-logging"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-journals-and-conference-proceedings",
    "title": "MITRE ATLAS Journals and Conference Proceedings (AML.T0000.000) - Adversarial Journals and Conference Proceedings threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0000.000 (Journals and Conference Proceedings). Many of the publications accepted at premier artificial intelligence conferences and journals come from commercial labs. Some journals and conferences are open access, others may require paying for access or a membership. These publications will often describe in detail all aspects of a particular approach for reproducibility. This information can be used by adversaries to implement the paper. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0000.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-label-manipulation",
    "title": "MITRE ATLAS Label Manipulation Attack on AI Training Pipelines (AML.T0020) - Compliance Obligations for Training Data Annotation Integrity, Labelling Process Governance, and AI Output Accuracy Monitoring Under Article 15",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses the MITRE ATLAS Label Manipulation Attack (AML.T0020) on ML training pipelines, aligning with EU AI Act Articles 15, 10, and 9 for robust data integrity and accuracy monitoring. Key compliance action involves implementing cryptographic controls and audit logging for label data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-lateral-movement-agent",
    "title": "MITRE ATLAS Lateral Movement via Compromised AI Agent (AML.TA0015) - Compliance Obligations for Agentic AI Network Segmentation, Agent Credential Isolation, and Autonomous System Lateral Movement Detection",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS tactic AML.TA0015, focusing on lateral movement via compromised AI agents, aligning with EU AI Act Articles 9 and 15 for robust cybersecurity and risk management. Key compliance actions include network segmentation and least-privilege access for AI agents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-llm-data-leakage",
    "title": "MITRE ATLAS LLM Data Leakage Techniques (AML.T0057) - Exfiltration of Training Data, System Prompts, and Confidential Information via Language Model Outputs Under GDPR and AI Act Obligations",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0057 (LLM Data Leakage), focusing on adversarial exfiltration of training data, system prompts, and confidential information through language model outputs. Compliance with EU AI Act (Article 15, Robustness) and GDPR (Article 5, Data Minimization) mandates organizations to implement defenses against such risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-llm-jailbreak",
    "title": "MITRE ATLAS LLM Jailbreak Techniques (AML.T0054) - Privilege Escalation and Defense Evasion Through Prompt Engineering to Bypass AI Safety Controls and Governance Guardrails",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0054 (LLM Jailbreak), focusing on adversarial prompt engineering to bypass AI safety controls, with compliance obligations under frameworks like the EU AI Act and NIST AI RMF requiring robust defenses against such privilege escalation and defense evasion tactics.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-llm-prompt-crafting",
    "title": "MITRE ATLAS LLM Prompt Crafting (AML.T0065) - Adversarial LLM Prompt Crafting threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0065 (LLM Prompt Crafting). Adversaries may use their acquired knowledge of the target generative AI system to craft prompts that bypass its defenses and allow malicious instructions to be executed. The adversary may iterate on the prompt to ensure that it works as-intended consistently. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-llm-prompt-injection",
    "title": "MITRE ATLAS LLM Prompt Injection Techniques (AML.T0051) - Adversarial Inputs to Manipulate Large Language Model Behaviour and Bypass Safety Controls",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0051 (LLM Prompt Injection), focusing on adversarial inputs designed to manipulate large language model behavior and bypass safety controls. Compliance frameworks such as the EU AI Act and NIST AI RMF require organizations to implement robust defenses against such threats to ensure AI system integrity and trustworthiness.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-llm-prompt-obfuscation",
    "title": "MITRE ATLAS LLM Prompt Obfuscation (AML.T0068) - Adversarial LLM Prompt Obfuscation threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0068 (LLM Prompt Obfuscation). Adversaries may hide or otherwise obfuscate prompt injections or retrieval content to avoid detection from humans, large language model (LLM) guardrails, or other detection mechanisms. For text inputs, this may include modifying how the instructions are rendered such as small text, text colored the same as the background, or hidden HTML elements. For multi-modal inputs, malicious instructions could be hidden in the data itself (e.g. in the pixels of an image) or in file metadata (e.g. EXIF for images, ID3 tags for audio, or document metadata). Inputs can also be obscured via an encoding scheme such as base64 or rot13. This may bypass LLM guardrails that identify malicious content and may not be as easily identifiable as malicious to a human in the loop. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-llm-prompt-self-replication",
    "title": "MITRE ATLAS LLM Prompt Self-Replication (AML.T0061) - Worm-Class Self-Propagating Prompts that Persist Across LLM Outputs",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0061 (LLM Prompt Self-Replication). An adversary may use a carefully crafted LLM Prompt Injection designed to cause the LLM to replicate the prompt as part of its output. This allows the prompt to propagate to other LLMs and persist on the system. The self-replicating prompt is typically paired with other malicious instructions (ex: LLM Jailbreak, LLM Data Leakage). Compliance frameworks including the EU AI Act, NIST AI RMF, and ISO/IEC 42001 require organisations to detect, monitor, and defend against this technique to preserve AI system integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-llm-prompt-injection"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-llm-response-rendering",
    "title": "MITRE ATLAS LLM Response Rendering (AML.T0077) - Adversarial LLM Response Rendering threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0077 (LLM Response Rendering). An adversary may get a large language model (LLM) to respond with private information that is hidden from the user when the response is rendered by the user's client. The private information is then exfiltrated. This can take the form of rendered images, which automatically make a request to an adversary controlled server. The adversary gets AI to present an image to the user, which is rendered by the user's client application with no user clicks required. The image is hosted on an attacker-controlled website, allowing the adversary to exfiltrate data through image request parameters. Variants include HTML tags and markdown For example, an LLM may produce the following markdown: ``` !ATLAS ``` Which is rendered by the client as: ``` <img src=\"https://atlas.mitre.org/image.png?secrets=\"priv... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-llm-trusted-output-components-manipulation",
    "title": "MITRE ATLAS LLM Trusted Output Components Manipulation (AML.T0067) - LLM Output Component Manipulation to Evade User Detection",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0067 (LLM Trusted Output Components Manipulation). Adversaries may utilize prompts to a large language model (LLM) which manipulate various components of its response in order to make it appear trustworthy to the user. This helps the adversary continue to operate in the victim's environment and evade detection by the users it interacts with. The LLM may be instructed to tailor its language to appear more trustworthy to the user or attempt to manipulate the user to take certain actions. Other response components that could be manipulated include links, recommended follow-up actions, retrieved document metadata, and Citations. Compliance frameworks including the EU AI Act, NIST AI RMF, and ISO/IEC 42001 require organisations to detect, monitor, and defend against this technique to preserve AI system integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-llm-prompt-injection"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-local-ai-agent",
    "title": "MITRE ATLAS Local AI Agent (AML.T0112.000) - Adversarial Local AI Agent threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0112.000 (Local AI Agent). Adversaries may achieve full system compromise by abusing AI agents running locally on a host, such as computer-use agents or AI-driven browsers. These agents are designed to autonomously interact with the operating system, applications, and external services, often with broad permissions to execute commands, access files, manage credentials, and control user workflows. If an adversary is able to take control of an AI agent's behavior, they effectively gain the same level of access as the agent. This can result in complete control over the machine, including executing arbitrary code, accessing or exfiltrating sensitive data, modifying system configurations, and establishing persistence. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0112.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-machine-compromise",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-machine-compromise",
    "title": "MITRE ATLAS Machine Compromise (AML.T0112) - Adversarial Machine Compromise threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0112 (Machine Compromise). Adversaries may compromise a machine by exploiting or manipulating AI-enabled components on the system. Compromising a victim system allows the adversary to execute arbitrary code, steal credentials, exfiltrate data, and continue to persist on the system. Adversaries may target a Local AI Agent which if compromised grants them the capabilities and permissions of the agent, or AI Artifacts which can contain embedded malware. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-malicious-link",
    "title": "MITRE ATLAS Malicious Link (AML.T0011.003) - Adversarial use of Malicious Link as adapted in MITRE ATT&CK T1204",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0011.003 (Malicious Link). An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Link. Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via Exploitation for Client Execution. Links may also lead users to download files that require execution via Malicious File. There are many ways an adversary can leverage malicious links to gain access to a victim system via an AI system. For example, an AI Agent that is configured to not validate website origin headers will accept connections from any website, allowing adversaries... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0011. ATT&CK reference: T1204 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-malicious-package",
    "title": "MITRE ATLAS Malicious Package (AML.T0011.001) - Adversarial Malicious Package threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0011.001 (Malicious Package). Adversaries may develop malicious software packages that when imported by a user have a deleterious effect. Malicious packages may behave as expected to the user. They may be introduced via AI Supply Chain Compromise. They may not present as obviously malicious to the user and may appear to be useful for an AI-related task. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0011. ATLAS-mapped mitigations: AML.M0011 Restrict Library Loading, AML.M0013 Code Signing, AML.M0016 Vulnerability Scanning, AML.M0018 User Training, AML.M0023 AI Bill of Materials.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-restrict-library-loading",
      "mitre-atlas-mitigation-code-signing",
      "mitre-atlas-mitigation-vulnerability-scanning",
      "mitre-atlas-mitigation-user-training",
      "mitre-atlas-mitigation-ai-bill-of-materials"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-atlas-manipulate-ai-model",
    "title": "MITRE ATLAS AI Model Manipulation Techniques (AML.T0018) - Compliance Obligations for Detecting and Responding to Poisoned Models, Modified Architectures, and Embedded Malware in AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses adversarial techniques under MITRE ATLAS AML.T0018 (Manipulate AI Model), focusing on poisoned models, modified architectures, and embedded malware. Compliance frameworks like the EU AI Act and NIST AI RMF require robust defenses against these threats to ensure AI system integrity and trustworthiness.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-manipulate-training-data",
    "title": "MITRE ATLAS Manipulate AI Training Data to Alter Model Behaviour (AML.T0020) - Compliance Obligations for Training Data Integrity Controls, Data Validation Gates, and AI Model Behaviour Monitoring Under EU AI Act Article 10",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0020 (Manipulate Training Data) under the EU AI Act Articles 9, 10, and 15, focusing on implementing integrity controls and monitoring to prevent model behavior alteration. Key compliance actions include immutable audit logs and cryptographic data protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-manipulate-user-llm-chat-history",
    "title": "MITRE ATLAS Manipulate User LLM Chat History (AML.T0092) - Adversarial Manipulate User LLM Chat History threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0092 (Manipulate User LLM Chat History). Adversaries may manipulate a user's large language model (LLM) chat history to cover the tracks of their malicious behavior. They may hide persistent changes they have made to the LLM's behavior, or obscure their attempts at discovering private information about the user. To do so, adversaries may delete or edit existing messages or create new threads as part of their coverup. This is feasible if the adversary has the victim's authentication tokens for the backend LLM service or if they have direct access to the victim's chat interface. Chat interfaces (especially desktop interfaces) often do not show the injected prompt for any ongoing chat, as they update chat history only once when initially opening it. This can help the adversary's manipulations go unnoticed by the victim. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-manual-modification",
    "title": "MITRE ATLAS Manual Modification (AML.T0043.003) - Adversarial Manual Modification threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0043.003 (Manual Modification). Adversaries may manually modify the input data to craft adversarial data. They may use their knowledge of the target model to modify parts of the data they suspect helps the model in performing its task. The adversary may use trial and error until they are able to verify they have a working adversarial input. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0043. ATLAS-mapped mitigations: AML.M0003 Model Hardening, AML.M0004 Restrict Number of AI Model Queries, AML.M0006 Use Ensemble Methods, AML.M0010 Input Restoration, AML.M0015 Adversarial Input Detection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-model-hardening",
      "mitre-atlas-mitigation-restrict-number-of-ai-model-queries",
      "mitre-atlas-mitigation-use-ensemble-methods",
      "mitre-atlas-mitigation-input-restoration",
      "mitre-atlas-mitigation-adversarial-input-detection"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-atlas-masquerading",
    "title": "MITRE ATLAS Masquerading (AML.T0074) - Adversarial use of Masquerading as adapted in MITRE ATT&CK T1036",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0074 (Masquerading). Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1036 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-membership-inference-attack",
    "title": "MITRE ATLAS Membership Inference Attack on AI Training Data (AML.T0024.000) - Compliance Obligations for Training Data Privacy Protection, GDPR Article 5 Data Minimisation, and AI Model Output Privacy Monitoring",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses compliance obligations to protect against MITRE ATLAS Membership Inference Attacks (AML.T0024.000) on ML training data, aligning with EU AI Act Articles 5, 15, and 50 for data privacy and AI system transparency. It also integrates GDPR Article 5 on data minimisation and mandates monitoring of AI model outputs for privacy risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "gdpr-article-5-data-principles",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-memory",
    "title": "MITRE ATLAS Memory (AML.T0080.000) - Adversarial Memory threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0080.000 (Memory). Adversaries may manipulate the memory of a large language model (LLM) in order to persist changes to the LLM to future chat sessions. Memory is a common feature in LLMs that allows them to remember information across chat sessions by utilizing a user-specific database. Because the memory is controlled via normal conversations with the user (e.g. \"remember my preference for ...\") an adversary can inject memories via Direct or Indirect Prompt Injection. Memories may contain malicious instructions (e.g. instructions that leak private conversations) or may promote the adversary's hidden agenda (e.g. manipulating the user). Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0080. ATLAS-mapped mitigations: AML.M0031 Memory Hardening.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-memory-hardening",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-mitigation-adversarial-input-detection",
    "title": "MITRE ATLAS Mitigation Adversarial Input Detection (AML.M0015) - Adversarial Input Detection at Model Inference",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0015 (Adversarial Input Detection). Detect and block adversarial inputs or atypical queries that deviate from known benign behavior, exhibit behavior patterns observed in previous attacks or that come from potentially malicious IPs. Incorporate adversarial detection algorithms into the AI system prior to the AI model. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-ai-agent-tools-permissions-configuration",
    "title": "MITRE ATLAS Mitigation AI Agent Tools Permissions Configuration (AML.M0028) - AI Agent Tools Permissions Configuration",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0028 (AI Agent Tools Permissions Configuration). When deploying tools that will be shared across multiple AI agents, it is important to implement robust policies and controls on permissions for the tools. These controls include applying the principle of least privilege along with delegated access, where the tools receive the permissions, identities, and restrictions of the AI agent calling them. These configurations may be implemented either in MCP servers which connect the agents to the tools calling them or, in more complex cases, directly in the configuration files of the tool. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10",
      "owasp-llm-08-excessive-agency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-ai-bill-of-materials",
    "title": "MITRE ATLAS Mitigation AI Bill of Materials (AML.M0023) - AI Supply Chain Inventory and Dataset Provenance Tracking",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0023 (AI Bill of Materials). An AI Bill of Materials (AI BOM) contains a full listing of artifacts and resources that were used in building the AI. The AI BOM can help mitigate supply chain risks and enable rapid response to reported vulnerabilities. This can include maintaining dataset provenance, i.e. a detailed history of datasets used for AI applications. The history can include information about the dataset source as well as well as a complete record of any modifications. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "cisa-sbom-minimum-elements-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-ai-model-distribution-methods",
    "title": "MITRE ATLAS Mitigation AI Model Distribution Methods (AML.M0017) - AI Model Distribution Methods to Reduce Extraction Risk",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0017 (AI Model Distribution Methods). Deploying AI models to edge devices can increase the attack surface of the system. Consider serving models in the cloud to reduce the level of access the adversary has to the model. Also consider computing features in the cloud to prevent gray-box attacks, where an adversary has access to the model preprocessing methods. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-ai-telemetry-logging",
    "title": "MITRE ATLAS Mitigation AI Telemetry Logging (AML.M0024) - Telemetry-Driven Detection of AI Model and Agent Threats",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0024 (AI Telemetry Logging). Implement logging of inputs and outputs of deployed AI models. When deploying AI agents, implement logging of the intermediate steps of agentic actions and decisions, data access and tool use, installation commands, and identity of the agent. Monitoring logs can help to detect security threats and mitigate impacts. Additionally, having logging enabled can discourage adversaries who want to remain undetected from utilizing AI resources. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-code-signing",
    "title": "MITRE ATLAS Mitigation Code Signing (AML.M0013) - Code Signing Across AI Pipelines and Deployed Models",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0013 (Code Signing). Enforce binary and application integrity with digital signature verification to prevent untrusted code from executing. Adversaries can embed malicious code in AI software or models. Developers should also cryptographically sign SBOM and AIBOM components that track model or data provenance. Enforcement of code signing can prevent the compromise of the AI supply chain and prevent execution of malicious code. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-control-access-to-ai-models-and-data-at-rest",
    "title": "MITRE ATLAS Mitigation Control Access to AI Models and Data at Rest (AML.M0005) - Access Controls on AI Model Registries, Production Models, and Training Data",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0005 (Control Access to AI Models and Data at Rest). Establish access controls on internal model registries and limit internal access to production models. Limit access to training data only to approved users. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-mitigation-control-access-to-ai-models-and-data-in-production",
    "title": "MITRE ATLAS Mitigation Control Access to AI Models and Data in Production (AML.M0019) - Access Controls on AI Models and Data in Production",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0019 (Control Access to AI Models and Data in Production). Require users to verify their identities before accessing a production model. Require authentication for API endpoints and monitor production model queries to ensure compliance with usage policies and to prevent model misuse. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-deepfake-detection",
    "title": "MITRE ATLAS Mitigation Deepfake Detection (AML.M0034) - Deepfake Detection at AI System Boundaries",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0034 (Deepfake Detection). Apply deepfake detection algorithms against any untrusted or user-provided data, especially in impactful applications such as biometric verification, to block generated content. Detectors may use a combination of approaches, including: - AI models trained to differentiate between real and deepfake content. - Identifying common inconsistencies in deepfake content, such as unnatural facial movements, audio mismatches, or pixel-level artifacts. - Biometrics analysis, such blinking, eye movements, and microexpressions. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-encrypt-sensitive-information",
    "title": "MITRE ATLAS Mitigation Encrypt Sensitive Information (AML.M0012) - Encryption of Sensitive AI Information at Rest and in Transit",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0012 (Encrypt Sensitive Information). Encrypt sensitive data such as AI models to protect against adversaries attempting to access sensitive data. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-generative-ai-guardrails",
    "title": "MITRE ATLAS Mitigation Generative AI Guardrails (AML.M0020) - Pre-Output Safety Controls for Generative AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0020 (Generative AI Guardrails). Guardrails are safety controls that are placed between a generative AI model and the output shared with the user to prevent undesired inputs and outputs. Guardrails can take the form of validators such as filters, rule-based logic, or regular expressions, as well as AI-based approaches, such as classifiers and utilizing LLMs, or named entity recognition (NER) to evaluate the safety of the prompt or response. Domain specific methods can be employed to reduce risks in a variety of areas such as etiquette, brand damage, jailbreaking, false information, code exploits, SQL injections, and data leakage. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-llm-08-excessive-agency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-generative-ai-guidelines",
    "title": "MITRE ATLAS Mitigation Generative AI Guidelines (AML.M0021) - Generative AI Usage Guidelines for Workforce Safety",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0021 (Generative AI Guidelines). Guidelines are safety controls that are placed between user-provided input and a generative AI model to help direct the model to produce desired outputs and prevent undesired outputs. Guidelines can be implemented as instructions appended to all user prompts or as part of the instructions in the system prompt. They can define the goal(s), role, and voice of the system, as well as outline safety and security parameters. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-generative-ai-model-alignment",
    "title": "MITRE ATLAS Mitigation Generative AI Model Alignment (AML.M0022) - Generative AI Model Alignment for Safety and Compliance",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0022 (Generative AI Model Alignment). When training or fine-tuning a generative AI model it is important to utilize techniques that improve model alignment with safety, security, and content policies. The fine-tuning process can potentially remove built-in safety mechanisms in a generative AI model, but utilizing techniques such as Supervised Fine-Tuning, Reinforcement Learning from Human Feedback or AI Feedback, and Targeted Safety Context Distillation can improve the safety and alignment of the model. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-human-in-the-loop-for-ai-agent-actions",
    "title": "MITRE ATLAS Mitigation Human In-the-Loop for AI Agent Actions (AML.M0029) - Human In-the-Loop for High-Impact AI Agent Actions",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0029 (Human In-the-Loop for AI Agent Actions). Systems should require the user or another human stakeholder to approve AI agent actions before the agent takes them. The human approver may be technical staff or business unit SMEs depending on the use case. Separate tools, such as dedicated audit agents, may assist human approval, but final adjudication should be conducted by a human decision-maker. The security benefits from Human In-the-Loop policies may be at odds with operational overhead costs of additional approvals. To ease this, Human In-the-Loop policies should follow the degree of consequence of the task at hand. Minor, repetitive tasks performed by agents accessing basic tools may only require minimal human oversight, while agents employed in systems with significant consequences may necessitate approval from multiple stakeholders diversified across multiple organizations. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10",
      "owasp-llm-08-excessive-agency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-input-and-output-validation-for-ai-agent-components",
    "title": "MITRE ATLAS Mitigation Input and Output Validation for AI Agent Components (AML.M0033) - Input and Output Validation for AI Agent Components",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0033 (Input and Output Validation for AI Agent Components). Implement validation on inputs and outputs for the tools and data sources used by AI agents. Validation includes enforcing a common data format, schema validation, checks for sensitive or prohibited information leakage, and data sanitization to remove potential injections or unsafe code. Input and output validation can help prevent compromises from spreading in AI-enabled systems and can help secure the workflow when multiple components are chained together. Validation should be performed external to the AI agent. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-input-restoration",
    "title": "MITRE ATLAS Mitigation Input Restoration (AML.M0010) - Input Restoration to Neutralise Adversarial Perturbations",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0010 (Input Restoration). Preprocess all inference data to nullify or reverse potential adversarial perturbations. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-limit-model-artifact-release",
    "title": "MITRE ATLAS Mitigation Limit Model Artifact Release (AML.M0001) - Restrictions on Public Release of Model Artifacts and Weights",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0001 (Limit Model Artifact Release). Limit public release of technical project details including data, algorithms, model architectures, and model checkpoints that are used in production, or that are representative of those used in production. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-limit-public-release-of-information",
    "title": "MITRE ATLAS Mitigation Limit Public Release of Information (AML.M0000) - Disclosure Restrictions on AI System Information",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0000 (Limit Public Release of Information). Limit the public release of technical information about the AI stack used in an organization's products or services. Technical knowledge of how AI is used can be leveraged by adversaries to perform targeting and tailor attacks to the target system. Additionally, consider limiting the release of organizational information - including physical locations, researcher names, and department structures - from which technical details such as AI techniques, model architectures, or datasets may be inferred. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-maintain-ai-dataset-provenance",
    "title": "MITRE ATLAS Mitigation Maintain AI Dataset Provenance (AML.M0025) - Maintaining AI Dataset Provenance Across the Lifecycle",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0025 (Maintain AI Dataset Provenance). Maintain a detailed history of datasets used for AI applications. The history should include information about the dataset's source as well as a complete record of any modifications. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-memory-hardening",
    "title": "MITRE ATLAS Mitigation Memory Hardening (AML.M0031) - Memory Hardening for AI Agents Against Persistent Adversarial Influence",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0031 (Memory Hardening). Memory Hardening involves developing trust boundaries and secure processes for how an AI agent stores and accesses memory and context. This may be implemented using a combination of strategies including restricting an agent's ability to store memories by requiring external authentication and validation for memory updates, performing semantic integrity checks on retrieved memories before agents execute actions, and implementing controls for monitoring of memory and remediation processes for poisoned memory. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-model-hardening",
    "title": "MITRE ATLAS Mitigation Model Hardening (AML.M0003) - Model Hardening Techniques Against Adversarial Inputs",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0003 (Model Hardening). Use techniques to make AI models robust to adversarial inputs such as adversarial training or network distillation. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-passive-ai-output-obfuscation",
    "title": "MITRE ATLAS Mitigation Passive AI Output Obfuscation (AML.M0002) - Output Obfuscation Controls to Inhibit Model Extraction",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0002 (Passive AI Output Obfuscation). Decreasing the fidelity of model outputs provided to the end user can reduce an adversary's ability to extract information about the model and optimize attacks for the model. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-privileged-ai-agent-permissions-configuration",
    "title": "MITRE ATLAS Mitigation Privileged AI Agent Permissions Configuration (AML.M0026) - Privileged AI Agent Permissions Configuration",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0026 (Privileged AI Agent Permissions Configuration). AI agents may be granted elevated privileges above that of a normal user to enable desired workflows. When deploying a privileged AI agent, or an agent that interacts with multiple users, it is important to implement robust policies and controls on permissions of the privileged agent. These controls include Role-Based Access Controls (RBAC), Attribute-Based Access Controls (ABAC), and the principle of least privilege so that the agent is only granted the necessary permissions to access tools and resources required to accomplish its designated task(s). It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10",
      "owasp-llm-08-excessive-agency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-restrict-ai-agent-tool-invocation-on-untrusted-data",
    "title": "MITRE ATLAS Mitigation Restrict AI Agent Tool Invocation on Untrusted Data (AML.M0030) - Restrictions on AI Agent Tool Invocation with Untrusted Data",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0030 (Restrict AI Agent Tool Invocation on Untrusted Data). Untrusted data can contain prompt injections that invoke an AI agent's tools, potentially causing confidentiality, integrity or availability violations. It is recommended that tool invocation be restricted or limited when untrusted data enters the LLM's context. The degree to which tool invocation is restricted may depend on the potential consequences of the action. Consider blocking the automatic invocation of tools or requiring user confirmation once untrusted data enters the LLM's context. For high consequence actions, consider always requiring user confirmation. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-restrict-library-loading",
    "title": "MITRE ATLAS Mitigation Restrict Library Loading (AML.M0011) - Restrictions on Loading Untrusted Libraries into AI Pipelines",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0011 (Restrict Library Loading). Prevent abuse of library loading mechanisms in the operating system and software to load untrusted code by configuring appropriate library loading mechanisms and investigating potential vulnerable software. File formats such as pickle files that are commonly used to store AI models can contain exploits that allow for loading of malicious libraries. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-restrict-number-of-ai-model-queries",
    "title": "MITRE ATLAS Mitigation Restrict Number of AI Model Queries (AML.M0004) - Query Rate Controls to Prevent Model Extraction and Adversarial Probing",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0004 (Restrict Number of AI Model Queries). Limit the total number and rate of queries a user can perform. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-mitigation-sanitize-training-data",
    "title": "MITRE ATLAS Mitigation Sanitize Training Data (AML.M0007) - Training Data Sanitisation to Prevent Poisoning",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0007 (Sanitize Training Data). Detect and remove or remediate poisoned training data. Training data should be sanitized prior to model training and recurrently for an active learning model. Implement a filter to limit ingested training data. Establish a content policy that would remove unwanted content such as certain explicit or offensive language from being used. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-segmentation-of-ai-agent-components",
    "title": "MITRE ATLAS Mitigation Segmentation of AI Agent Components (AML.M0032) - Segmentation of AI Agent Components to Limit Blast Radius",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0032 (Segmentation of AI Agent Components). Define security boundaries around agentic tools and data sources with methods such as API access, container isolation, code execution sandboxing, and rate limiting of tool invocation. When sandboxing, limit resource and network access and build the container or virtual machine from a clean base image before each run. This restricts untrusted processes or potential compromises from spreading throughout the system. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-single-user-ai-agent-permissions-configuration",
    "title": "MITRE ATLAS Mitigation Single-User AI Agent Permissions Configuration (AML.M0027) - Single-User AI Agent Permissions Configuration",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0027 (Single-User AI Agent Permissions Configuration). When deploying an AI agent that acts as a representative of a user and performs actions on their behalf, it is important to implement robust policies and controls on permissions and lifecycle management of the agent. Lifecycle management involves establishing identity, protocols for access management, and decommissioning of the agent when its role is no longer needed. Controls should also include the principle of least privilege and delegated access from the user account. When acting as a representative of a user, the AI agent should not be granted permissions that the user would not be granted within the system or organization. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10",
      "owasp-llm-08-excessive-agency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-mitigation-use-ensemble-methods",
    "title": "MITRE ATLAS Mitigation Use Ensemble Methods (AML.M0006) - Ensemble Methods for Adversarial Robustness",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0006 (Use Ensemble Methods). Use an ensemble of models for inference to increase robustness to adversarial inputs. Some attacks may effectively evade one model or model family but be ineffective against others. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-use-multi-modal-sensors",
    "title": "MITRE ATLAS Mitigation Use Multi-Modal Sensors (AML.M0009) - Multi-Modal Sensor Fusion for Physical World Robustness",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0009 (Use Multi-Modal Sensors). Incorporate multiple sensors to integrate varying perspectives and modalities to avoid a single point of failure susceptible to physical attacks. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-user-training",
    "title": "MITRE ATLAS Mitigation User Training (AML.M0018) - User Training on AI Risks and Safe Use",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0018 (User Training). Educate AI model developers to on AI supply chain risks and potentially malicious AI artifacts. Educate users on how to identify deepfakes and phishing attempts. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-validate-ai-model",
    "title": "MITRE ATLAS Mitigation Validate AI Model (AML.M0008) - AI Model Validation Before and After Deployment",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0008 (Validate AI Model). Validate that AI models perform as intended by testing for backdoor triggers, potential for data leakage, or adversarial influence. Monitor AI model for concept drift and training data drift, which may indicate data tampering and poisoning. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-verify-ai-artifacts",
    "title": "MITRE ATLAS Mitigation Verify AI Artifacts (AML.M0014) - Verification of AI Artifacts Before Deployment",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0014 (Verify AI Artifacts). Verify the cryptographic checksum of all AI artifacts to verify that the file was not modified by an attacker. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-mitigation-vulnerability-scanning",
    "title": "MITRE ATLAS Mitigation Vulnerability Scanning (AML.M0016) - Vulnerability Scanning of AI Components",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0016 (Vulnerability Scanning). Vulnerability scanning is used to find potentially exploitable software vulnerabilities to remediate them. File formats such as pickle files that are commonly used to store AI models can contain exploits that allow for arbitrary code execution. These files should be scanned for potentially unsafe calls, which could be used to execute code, create new processes, or establish networking capabilities. Adversaries may embed malicious code in model corrupt model files, so scanners should be capable of working with models that cannot be fully de-serialized. Model artifacts, downstream products produced by models, and external software dependencies should be scanned for known vulnerabilities. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-ml-artifact-collection",
    "title": "MITRE ATLAS AI Artifact Collection from Victim AI Infrastructure (AML.T0035) - Compliance Obligations for AI Asset Inventory Protection, Model Weight Confidentiality, and AI Pipeline Access Logging",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0035, focusing on protecting AI artifacts from unauthorized collection, aligned with EU AI Act Articles 9 and 15. Key compliance actions include securing model weights and logging access to ML pipelines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-ml-model-fingerprinting",
    "title": "MITRE ATLAS AI Model Fingerprinting for Targeted Adversarial Attack Preparation (AML.T0014) - Compliance Obligations for AI Model Identification Prevention, API Response Consistency Controls, and Adversarial Profiling Detection",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses compliance obligations to prevent ML model fingerprinting under MITRE ATLAS technique AML.T0014, focusing on AI model identification prevention and adversarial profiling detection as mandated by the EU AI Act (Articles 5, 15, and 50). It outlines controls for API response consistency and risk mitigation strategies aligned with high-risk AI system requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-model",
    "title": "MITRE ATLAS Model (AML.T0010.003) - Adversarial Model threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0010.003 (Model). AI-enabled systems often rely on open sourced models in various ways. Most commonly, the victim organization may be using these models for fine tuning. These models will be downloaded from an external source and then used as the base for the model as it is tuned on a smaller, private dataset. Loading models often requires executing some saved code in the form of a saved model file. These can be compromised with traditional malware, or through some adversarial AI techniques. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0010. ATLAS-mapped mitigations: AML.M0005 Control Access to AI Models and Data at Rest, AML.M0006 Use Ensemble Methods, AML.M0008 Validate AI Model, AML.M0013 Code Signing, AML.M0017 AI Model Distribution Methods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-control-access-to-ai-models-and-data-at-rest",
      "mitre-atlas-mitigation-use-ensemble-methods",
      "mitre-atlas-mitigation-validate-ai-model",
      "mitre-atlas-mitigation-code-signing",
      "mitre-atlas-mitigation-ai-model-distribution-methods"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-atlas-model-inversion-attack",
    "title": "MITRE ATLAS Model Inversion Attack to Reconstruct Training Data (AML.T0024.001) - Compliance Obligations for Training Data Privacy Protection, GDPR Pseudonymisation of AI Training Sets, and Model Output Privacy Controls",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses the MITRE ATLAS Model Inversion Attack (AML.T0024.001), aligning with EU AI Act Articles 9 and 15 for robust AI system security. Key compliance actions include detecting backdoor triggers and verifying model integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-model-replication-attack",
    "title": "MITRE ATLAS AI Model Replication for Targeted Attack Development (AML.T0005.001) - Compliance Obligations for AI Model Confidentiality Controls, Replica Detection Monitoring, and Surrogate Model Attack Mitigation",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0005.001 on ML model replication for attack staging, aligning with EU AI Act Articles 9 and 15 for risk management and cybersecurity. Key compliance actions include model watermarking and access control implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-model-stealing-inference-api",
    "title": "MITRE ATLAS AI Model Stealing via Inference API Query Extraction (AML.T0024.002) - Compliance Obligations for AI Intellectual Property Protection, API Rate Limiting and Monitoring, and AI Model Confidentiality Enforcement",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0024.002, focusing on ML model stealing via inference API, aligning with EU AI Act Articles 9 and 15 for risk management and cybersecurity. Key compliance actions include API rate limiting and query monitoring to prevent model extraction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-models",
    "title": "MITRE ATLAS Models (AML.T0002.001) - Adversarial Models threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0002.001 (Models). Adversaries may acquire public models to use in their operations. Adversaries may seek models used by the victim organization or models that are representative of those used by the victim organization. Representative models may include model architectures, or pre-trained models which define the architecture as well as model parameters from training on a dataset. The adversary may search public sources for common model architecture configuration file formats such as YAML or Python configuration files, and common model storage file formats such as ONNX (.onnx), HDF5 (.h5), Pickle (.pkl), PyTorch (.pth), or TensorFlow (.pb, .tflite). Acquired models are useful in advancing the adversary's operations and are frequently used to tailor attacks to the victim model. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0002. ATLAS-mapped mitigations: AML.M0001 Limit Model Artifact Release, AML.M0014 Verify AI Artifacts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-limit-model-artifact-release",
      "mitre-atlas-mitigation-verify-ai-artifacts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-modify-ai-agent-configuration",
    "title": "MITRE ATLAS Modify AI Agent Configuration (AML.T0081) - Adversarial Modify AI Agent Configuration threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0081 (Modify AI Agent Configuration). Adversaries may modify the configuration files for AI agents on a system. This allows malicious changes to persist beyond the life of a single agent and affects any agents that share the configuration. Configuration changes may include modifications to the system prompt, tampering with or replacing knowledge sources, modification to settings of connected tools, and more. Through those changes, an attacker could redirect outputs or tools to malicious services, embed covert instructions that exfiltrate data, or weaken security controls that normally restrict agent behavior. Adversaries may modify or disable a configuration setting related to security controls, such as those that would prevent the AI Agent from taking actions that may be harmful to the user's system without human-in-the-loop ... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-modify-ai-model-architecture",
    "title": "MITRE ATLAS Modify AI Model Architecture (AML.T0018.001) - Adversarial Modify AI Model Architecture threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0018.001 (Modify AI Model Architecture). Adversaries may directly modify an AI model's architecture to re-define it's behavior. This can include adding or removing layers as well as adding pre or post-processing operations. The effects could include removing the ability to predict certain classes, adding erroneous operations to increase computation costs, or degrading performance. Additionally, a separate adversary-defined network could be injected into the computation graph, which can change the behavior based on the inputs, effectively creating a backdoor. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0018. ATLAS-mapped mitigations: AML.M0005 Control Access to AI Models and Data at Rest, AML.M0008 Validate AI Model, AML.M0013 Code Signing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-control-access-to-ai-models-and-data-at-rest",
      "mitre-atlas-mitigation-validate-ai-model",
      "mitre-atlas-mitigation-code-signing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-obtain-ml-capabilities",
    "title": "MITRE ATLAS Obtain AI Capabilities for Attack Development (AML.T0016) - Compliance Obligations for AI Tool and Library Risk Assessment, Development Environment Security, and Third-Party AI Framework Due Diligence",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses compliance obligations under MITRE ATLAS technique AML.T0016 for securing AI/ML capabilities against adversarial attacks, aligning with EU AI Act requirements under Articles 5, 15, and 50 for risk assessment and transparency. It provides actionable governance for AI tool security and third-party framework due diligence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-os-credential-dumping",
    "title": "MITRE ATLAS OS Credential Dumping (AML.T0090) - Adversarial use of OS Credential Dumping as adapted in MITRE ATT&CK T1003",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0090 (OS Credential Dumping). Adversaries may extract credentials from OS caches, application memory, or other sources on a compromised system. Credentials are often in the form of a hash or clear text, and can include usernames and passwords, application tokens, or other authentication keys. Credentials can be used to perform Lateral Movement to access other AI services such as AI agents, LLMs, or AI inference APIs. Credentials could also give an adversary access to other software tools and data sources that are part of the AI DevOps lifecycle. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1003 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-persistence-via-agent",
    "title": "MITRE ATLAS Persistence Establishment via Compromised AI Agent (AML.T0081) - Compliance Obligations for Agentic AI State Persistence Controls, Agent Memory Integrity, and Autonomous System Long-Term Access Governance",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0081, focusing on persistence via compromised AI agents, under the EU AI Act Articles 9 and 15, with key compliance actions centered on integrity monitoring and access controls for AI agent configurations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-phishing-ml-researcher",
    "title": "MITRE ATLAS Spearphishing Attacks Targeting AI Researchers (AML.T0052) - Compliance Obligations for AI Development Team Security Awareness, Social Engineering Defence, and AI Pipeline Insider Threat Governance",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0052, focusing on spearphishing attacks targeting ML researchers, with compliance obligations under the EU AI Act Articles 9 and 15. Key actions include security awareness training and phishing-resistant authentication for AI development teams.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-physical-countermeasures",
    "title": "MITRE ATLAS Physical Countermeasures (AML.T0008.003) - Adversarial Physical Countermeasures threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0008.003 (Physical Countermeasures). Adversaries may acquire or manufacture physical countermeasures to aid or support their attack. These components may be used to disrupt or degrade the model, such as adversarial patterns printed on stickers or T-shirts, disguises, or decoys. They may also be used to disrupt or degrade the sensors used in capturing data, such as laser pointers, light bulbs, or other tools. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0008.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-physical-environment-access",
    "title": "MITRE ATLAS Physical Environment Access (AML.T0041) - Adversary Use of Physical Environment Access to Manipulate AI Inputs",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0041 (Physical Environment Access). In addition to the attacks that take place purely in the digital domain, adversaries may also exploit the physical environment for their attacks. If the model is interacting with data collected from the real world in some way, the adversary can influence the model through access to wherever the data is being collected. By modifying the data in the collection process, the adversary can perform modified versions of attacks designed for digital access. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-use-multi-modal-sensors"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-poison-ai-model",
    "title": "MITRE ATLAS Poison AI Model (AML.T0018.000) - Adversarial Poison AI Model threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0018.000 (Poison AI Model). Adversaries may manipulate an AI model's weights to change it's behavior or performance, resulting in a poisoned model. Adversaries may poison a model by directly manipulating its weights, training the model on poisoned data, further fine-tuning the model, or otherwise interfering with its training process. The change in behavior of poisoned models may be limited to targeted categories in predictive AI models, or targeted topics, concepts, or facts in generative AI models, or aim for a general performance degradation. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0018. ATLAS-mapped mitigations: AML.M0005 Control Access to AI Models and Data at Rest, AML.M0007 Sanitize Training Data, AML.M0008 Validate AI Model, AML.M0013 Code Signing, AML.M0025 Maintain AI Dataset Provenance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-control-access-to-ai-models-and-data-at-rest",
      "mitre-atlas-mitigation-sanitize-training-data",
      "mitre-atlas-mitigation-validate-ai-model",
      "mitre-atlas-mitigation-code-signing",
      "mitre-atlas-mitigation-maintain-ai-dataset-provenance"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-atlas-poisoned-ai-agent-tool",
    "title": "MITRE ATLAS Poisoned AI Agent Tool (AML.T0011.002) - Adversarial Poisoned AI Agent Tool threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0011.002 (Poisoned AI Agent Tool). A victim may invoke a poisoned tool when interacting with their AI agent. A poisoned tool may execute an LLM Prompt Injection or perform AI Agent Tool Invocation. Poisoned AI agent tools may be introduced into the victim's environment via AI Software, or the user may configure their agent to connect to remote tools. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0011.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-pre-print-repositories",
    "title": "MITRE ATLAS Pre-Print Repositories (AML.T0000.001) - Adversarial Pre-Print Repositories threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0000.001 (Pre-Print Repositories). Pre-Print repositories, such as arXiv, contain the latest academic research papers that haven't been peer reviewed. They may contain research notes, or technical reports that aren't typically published in journals or conference proceedings. Pre-print repositories also serve as a central location to share papers that have been accepted to journals. Searching pre-print repositories provide adversaries with a relatively up-to-date view of what researchers in the victim organization are working on. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0000.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-privilege-escalation-agent",
    "title": "MITRE ATLAS Privilege Escalation via AI Agent Tool Access (AML.TA0012) - Compliance Obligations for Agentic AI Least-Privilege Enforcement, Permission Boundary Controls, and Agent Privilege Escalation Detection",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS tactic AML.TA0012, focusing on privilege escalation via AI agent tool access, aligning with EU AI Act Articles 9, 14, and 15 for robust cybersecurity and human oversight. Key compliance action is enforcing strict permission boundaries for AI agents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-process-discovery",
    "title": "MITRE ATLAS Process Discovery (AML.T0089) - Discovery adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0089 (Process Discovery), an adversarial technique in the ATLAS Discovery tactic. Adversaries may attempt to get information about processes running on a system. Once obtained, this information could be used to gain an understanding of common AI-related software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Identifying the AI software stack can then lead an adversary to new targets and attack pathways. AI-related software may require application tokens to authenticate with backend services. This provides opportunities for credential access and lateral movement. In Windows environments, adversaries could obtain details on running processes using the Tasklist utility via cmd or `Get-Process` via PowerShell. Information about processes can also be extracted from the output of Native API calls such as `CreateToolhelp32Snapshot`. In Mac and Linux, this is accomplished with the `ps` command. Adversaries may also opt to enumerate processes via `/proc`. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Corresponds to MITRE ATT&CK T1057.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-prompt-infiltration-via-public-facing-application",
    "title": "MITRE ATLAS Prompt Infiltration via Public-Facing Application (AML.T0093) - Adversarial Prompt Infiltration via Public-Facing Application threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0093 (Prompt Infiltration via Public-Facing Application). An adversary may introduce malicious prompts into the victim's system via a public-facing application with the intention of it being ingested by an AI at some point in the future and ultimately having a downstream effect. This may occur when a data source is indexed by a retrieval augmented generation (RAG) system, when a rule triggers an action by an AI agent, or when a user utilizes a large language model (LLM) to interact with the malicious content. The malicious prompts may persist on the victim system for an extended period and could affect multiple users and various AI tools within the victim organization. Any public-facing application that accepts text input could be a target. This includes email, shared document systems like OneDrive or Google Drive, and service desks or ticketing ... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-publish-hallucinated-entities",
    "title": "MITRE ATLAS Publish Hallucinated Entities (AML.T0060) - Adversarial Publish Hallucinated Entities threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0060 (Publish Hallucinated Entities). Adversaries may create an entity they control, such as a software package, website, or email address to a source hallucinated by an LLM. The hallucinations may take the form of package names commands, URLs, company names, or email addresses that point the victim to the entity controlled by the adversary. When the victim interacts with the adversary-controlled entity, the attack can proceed. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-publish-poisoned-ai-agent-tool",
    "title": "MITRE ATLAS Publish Poisoned AI Agent Tool (AML.T0104) - Resource Development adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0104 (Publish Poisoned AI Agent Tool), an adversarial technique in the ATLAS Resource Development tactic. Adversaries may create and publish poisoned AI agent tools. Poisoned tools may contain an llm prompt injection, which can lead to a variety of impacts. Tools may be published to open source version control repositories (e.g. GitHub, GitLab), to package registries (e.g. npm), or to repositories specifically designed for sharing tools (e.g. OpenClaw Hub). These registries may be largely unregulated and may contain many poisoned tools [\\[1\\]][1]. Tools may also be published as remotely hosted servers [\\[2\\]][2]. [1]: https://opensourcemalware.com/blog/clawdbot-skills-ganked-your-crypto [2]: https://mcpservers.org/remote-mcp-servers Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-publish-poisoned-datasets",
    "title": "MITRE ATLAS Publish Poisoned Datasets (AML.T0019) - Adversary Publication of Poisoned Datasets to Public Repositories",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0019 (Publish Poisoned Datasets). Adversaries may Poison Training Data and publish it to a public location. The poisoned dataset may be a novel dataset or a poisoned variant of an existing open source dataset. This data may be introduced to a victim system via AI Supply Chain Compromise. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-verify-ai-artifacts",
      "mitre-atlas-mitigation-ai-bill-of-materials",
      "mitre-atlas-mitigation-maintain-ai-dataset-provenance",
      "owasp-llm-03-training-data-poisoning"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-atlas-publish-poisoned-models",
    "title": "MITRE ATLAS Publish Poisoned Models (AML.T0058) - Adversary Publication of Poisoned Models to Public Repositories",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0058 (Publish Poisoned Models). Adversaries may publish a poisoned model to a public location such as a model registry or code repository. The poisoned model may be a novel model or a poisoned variant of an existing open-source model. This model may be introduced to a victim system via AI Supply Chain Compromise. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-ai-bill-of-materials",
      "owasp-llm-05-supply-chain-vulnerabilities"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-rag-credential-harvesting",
    "title": "MITRE ATLAS RAG Credential Harvesting (AML.T0082) - Adversary Harvesting of Credentials from Retrieval-Augmented Generation Pipelines",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0082 (RAG Credential Harvesting). Adversaries may attempt to use their access to a large language model (LLM) on the victim's system to collect credentials. Credentials may be stored in internal documents which can inadvertently be ingested into a RAG database, where they can ultimately be retrieved by an AI agent. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-privileged-ai-agent-permissions-configuration",
      "mitre-atlas-mitigation-single-user-ai-agent-permissions-configuration",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-rag-databases",
    "title": "MITRE ATLAS RAG Databases (AML.T0085.000) - Adversarial RAG Databases threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0085.000 (RAG Databases). Adversaries may prompt the AI service to retrieve data from a RAG database. This can include the majority of an organization's internal documents. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0085. ATLAS-mapped mitigations: AML.M0024 AI Telemetry Logging, AML.M0026 Privileged AI Agent Permissions Configuration, AML.M0027 Single-User AI Agent Permissions Configuration, AML.M0032 Segmentation of AI Agent Components.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-ai-telemetry-logging",
      "mitre-atlas-mitigation-privileged-ai-agent-permissions-configuration",
      "mitre-atlas-mitigation-single-user-ai-agent-permissions-configuration",
      "mitre-atlas-mitigation-segmentation-of-ai-agent-components",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-atlas-rag-poisoning",
    "title": "MITRE ATLAS RAG Poisoning Techniques (AML.T0070) - Persistence and Information Integrity Attacks Against Retrieval-Augmented Generation Systems Used in Regulated AI Applications",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS RAG Poisoning Techniques (AML.T0070), focusing on adversarial attacks that compromise retrieval-augmented generation systems by poisoning data sources or manipulating outputs, with compliance obligations under frameworks like the EU AI Act and NIST AI RMF requiring robust defenses against such integrity attacks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-reconnaissance-victim-research",
    "title": "MITRE ATLAS AI Reconnaissance via Victim Publicly Available Research (AML.T0000) - Compliance Obligations for AI Model Card Minimisation, Architecture Disclosure Controls, and Adversarial Research Exposure Governance",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0000, focusing on adversarial reconnaissance via publicly available research, aligning with EU AI Act Articles 9 and 15 for risk management and cybersecurity. Key compliance action is to establish disclosure controls for ML publications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-reputational-harm",
    "title": "MITRE ATLAS Reputational Harm (AML.T0048.001) - Adversarial Reputational Harm threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0048.001 (Reputational Harm). Reputational harm involves a degradation of public perception and trust in organizations. Examples of reputation-harming incidents include scandals or false impersonations. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0048.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-resource-development-agent",
    "title": "MITRE ATLAS Resource Development and Infrastructure Building via AI Agent (AML.TA0003) - Compliance Obligations for Agentic AI Resource Acquisition Controls, Agent Infrastructure Governance, and Autonomous Capability Development Detection",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses compliance obligations under the EU AI Act for mitigating adversarial AI techniques like MITRE ATLAS AML.TA0003 (Resource Development via AI Agents), focusing on controls for resource acquisition, infrastructure governance, and detection of autonomous capability development as mandated by Articles 5, 15, and 50.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-resource-intensive-queries",
    "title": "MITRE ATLAS Resource-Intensive Queries (AML.T0034.001) - Adversarial Resource-Intensive Queries threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0034.001 (Resource-Intensive Queries). Adversaries may craft inputs specifically designed to increase the compute resources required for processing. For generative AI models, adversaries may use long input sequences, requests for extremely long outputs, or prompts that require complex reasoning as strategies for increasing compute costs [[genai]]. For vision and language models, \"sponge examples\" [[arxiv]] can be used to maximize energy consumption and decision latency. Utilizing fewer resource-intensive queries instead of simply flooding the model with excessive queries may be more difficult to detect and block or limit. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0034.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-retrieval-content-crafting",
    "title": "MITRE ATLAS Retrieval Content Crafting (AML.T0066) - Resource Development adversarial technique against AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0066 (Retrieval Content Crafting), an adversarial technique in the ATLAS Resource Development tactic. Adversaries may write content designed to be retrieved by user queries and influence a user of the system in some way. This abuses the trust the user has in the system. The crafted content can be combined with a prompt injection. It can also stand alone in a separate document or email. The adversary must get the crafted content into the victim\\u0027s database, such as a vector database used in a retrieval augmented generation (RAG) system. This may be accomplished via cyber access, or by abusing the ingestion mechanisms common in RAG systems (see rag poisoning). Large language models may be used as an assistant to aid an adversary in crafting content. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-reverse-shell",
    "title": "MITRE ATLAS Reverse Shell (AML.T0072) - Adversarial Reverse Shell threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0072 (Reverse Shell). Adversaries may utilize a reverse shell to communicate and control the victim system. Typically, a user uses a client to connect to a remote machine which is listening for connections. With a reverse shell, the adversary is listening for incoming connections initiated from the victim system. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-search-application-repositories",
    "title": "MITRE ATLAS Search Application Repositories (AML.T0004) - Adversary Reconnaissance via Application Repository Search",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0004 (Search Application Repositories). Adversaries may search open application repositories during targeting. Examples of these include Google Play, the iOS App store, the macOS App Store, and the Microsoft Store. Adversaries may craft search queries seeking applications that contain AI-enabled components. Frequently, the next step is to Acquire Public AI Artifacts. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-limit-public-release-of-information"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-search-open-websites-domains",
    "title": "MITRE ATLAS Search Open Websites/Domains (AML.T0095) - Adversarial use of Search Open Websites/Domains as adapted in MITRE ATT&CK T1593",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0095 (Search Open Websites/Domains). Adversaries may search public websites and/or domains for information about victims that can be used during targeting. Information about victims may be available in various online sites, such as social media, new sites, or domains owned by the victim. Adversaries may find the information they seek to gather via search engines. They can use precise search queries to identify software platforms or services used by the victim to use in targeting. This may be followed by Exploit Public-Facing Application or Prompt Infiltration via Public-Facing Application. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1593 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-search-victim-ai-artifacts",
    "title": "MITRE ATLAS Discovery of Victim AI Artifacts via Open-Source Intelligence (AML.T0007) - Compliance Obligations for AI Asset Inventory Management, Model Documentation Minimisation, and AI System Exposure Controls",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0007, focusing on defending against OSINT-based discovery of AI artifacts, aligned with EU AI Act Articles 9 and 15 for risk management and cybersecurity. Key compliance actions include regular OSINT assessments and minimizing public disclosures of AI system details.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-serverless",
    "title": "MITRE ATLAS Serverless (AML.T0008.004) - Adversarial use of Serverless as adapted in MITRE ATT&CK T1583.007",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0008.004 (Serverless). Adversaries may purchase and configure serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be used during targeting. By utilizing serverless infrastructure, adversaries can make it more difficult to attribute infrastructure used during operations back to them. Once acquired, the serverless runtime environment can be leveraged to either respond directly to infected machines or to Proxy traffic to an adversary-owned command and control server. As traffic generated by these functions will appear to come from subdomains of common cloud providers, it may be difficult to distinguish from ordinary traffic to these providers. This can be used to bypass a Content Security Policy which prevent retrieving content from arbitrary locations... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0008. ATT&CK reference: T1583.007 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-societal-harm",
    "title": "MITRE ATLAS Societal Harm (AML.T0048.002) - Adversarial Societal Harm threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0048.002 (Societal Harm). Societal harms might generate harmful outcomes that reach either the general public or specific vulnerable groups such as the exposure of children to vulgar content. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0048.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-software-tools",
    "title": "MITRE ATLAS Software Tools (AML.T0016.001) - Adversarial use of Software Tools as adapted in MITRE ATT&CK T1588.002",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0016.001 (Software Tools). Adversaries may search for and obtain software tools to support their operations. Software designed for legitimate use may be repurposed by an adversary for malicious intent. An adversary may modify or customize software tools to achieve their purpose. Software tools used to support attacks on AI systems are not necessarily AI-based themselves. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0016. ATT&CK reference: T1588.002 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-spamming-ai-system-with-chaff-data",
    "title": "MITRE ATLAS Spamming AI System with Chaff Data (AML.T0046) - Adversary Spamming of AI System with Chaff Data to Degrade Service",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0046 (Spamming AI System with Chaff Data). Adversaries may spam the AI system with chaff data that causes increase in the number of detections. This can cause analysts at the victim organization to waste time reviewing and correcting incorrect inferences. Adversaries may also spam AI agents with excessive low-severity auditable events or agentic actions that require a human-in-the-loop, wasting time for the victim organization in human review of the agentic AI system. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-restrict-number-of-ai-model-queries",
      "mitre-atlas-mitigation-control-access-to-ai-models-and-data-in-production"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-spearphishing-via-social-engineering-llm",
    "title": "MITRE ATLAS Spearphishing via Social Engineering LLM (AML.T0052.000) - Adversarial Spearphishing via Social Engineering LLM threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0052.000 (Spearphishing via Social Engineering LLM). Adversaries may turn LLMs into targeted social engineers. LLMs are capable of interacting with users via text conversations. They can be instructed by an adversary to seek sensitive information from a user and act as effective social engineers. They can be targeted towards particular personas defined by the adversary. This allows adversaries to scale spearphishing efforts and target individuals to reveal private information such as credentials to privileged systems. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0052. ATLAS-mapped mitigations: AML.M0018 User Training, AML.M0034 Deepfake Detection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-user-training",
      "mitre-atlas-mitigation-deepfake-detection",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-atlas-special-character-sets",
    "title": "MITRE ATLAS Special Character Sets (AML.T0069.000) - Adversarial Special Character Sets threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0069.000 (Special Character Sets). Adversaries may discover delimiters and special characters sets used by the large language model. For example, delimiters used in retrieval augmented generation applications to differentiate between context and user prompts. These can later be exploited to confuse or manipulate the large language model into misbehaving. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0069.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-discover-llm-system-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-stage-capabilities",
    "title": "MITRE ATLAS Stage Capabilities (AML.T0079) - Adversarial use of Stage Capabilities as adapted in MITRE ATT&CK T1608",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0079 (Stage Capabilities). Adversaries may upload, install, or otherwise set up capabilities that can be used during targeting. To support their operations, an adversary may need to take capabilities they developed (Develop Capabilities) or obtained (Obtain Capabilities) and stage them on infrastructure under their control. These capabilities may be staged on infrastructure that was previously purchased/rented by the adversary (Acquire Infrastructure) or was otherwise compromised by them. Capabilities may also be staged on web services, such as GitHub, model registries, such as Hugging Face, or container registries. Adversaries may stage a variety of AI Artifacts including poisoned datasets (Publish Poisoned Datasets, malicious models (Publish Poisoned Models, and prompt injections. They may target names of legitima... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1608 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-system-instruction-keywords",
    "title": "MITRE ATLAS System Instruction Keywords (AML.T0069.001) - Adversarial System Instruction Keywords threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0069.001 (System Instruction Keywords). Adversaries may discover keywords that have special meaning to the large language model (LLM), such as function names or object names. These can later be exploited to confuse or manipulate the LLM into misbehaving and to make calls to plugins the LLM has access to. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0069.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-discover-llm-system-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-system-prompt",
    "title": "MITRE ATLAS System Prompt (AML.T0069.002) - Adversarial System Prompt threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0069.002 (System Prompt). Adversaries may discover a large language model's system instructions provided by the AI system builder to learn about the system's capabilities and circumvent its guardrails. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0069.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-discover-llm-system-information",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-t0008-001-commodity-grade-hardware-risk",
    "title": "MITRE ATLAS Commodity-Grade Hardware Supply Chain Risk (AML.T0008.001) - Adversarial use of off-the-shelf hardware in the AI supply chain",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0008.001 (Consumer Hardware). Adversaries may acquire consumer hardware to conduct their attacks. Owning the hardware provides the adversary with complete control of the environment. These devices can be hard to trace. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0008.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-technical-blogs",
    "title": "MITRE ATLAS Technical Blogs (AML.T0000.002) - Adversarial Technical Blogs threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0000.002 (Technical Blogs). Research labs at academic institutions and company R&D divisions often have blogs that highlight their use of artificial intelligence and its application to the organization's unique problems. Individual researchers also frequently document their work in blogposts. An adversary may search for posts made by the target victim organization or its employees. In comparison to Journals and Conference Proceedings and Pre-Print Repositories this material will often contain more practical aspects of the AI system. This could include underlying technologies and frameworks used, and possibly some information about the API access and use case. This will help the adversary better understand how that organization is using AI internally and the details of their approach that could aid in tailoring an att... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0000.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-thread",
    "title": "MITRE ATLAS Thread (AML.T0080.001) - Adversarial Thread threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0080.001 (Thread). Adversaries may introduce malicious instructions into a chat thread of a large language model (LLM) to cause behavior changes which persist for the remainder of the thread. A chat thread may continue for an extended period over multiple sessions. The malicious instructions may be introduced via Direct or Indirect Prompt Injection. Direct Injection may occur in cases where the adversary has acquired a user's LLM API keys and can inject queries directly into any thread. As the token limits for LLMs rise, AI systems can make use of larger context windows which allow malicious instructions to persist longer in a thread. Thread Poisoning may affect multiple users if the LLM is being used in a service with shared threads. For example, if an agent is active in a Slack channel with multiple partic... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0080.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-tool-definitions",
    "title": "MITRE ATLAS Tool Definitions (AML.T0084.001) - Adversarial Tool Definitions threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0084.001 (Tool Definitions). Adversaries may discover the tools the AI agent has access to. By identifying which tools are available, the adversary can understand what actions may be executed through the agent and what additional resources it can reach. This knowledge may reveal access to external data sources such as OneDrive or SharePoint, or expose exfiltration paths like the ability to send emails, helping adversaries identify AI agents that provide the greatest value or opportunity for attack. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0084.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-discover-ai-agent-configuration",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-train-proxy-via-gathered-ai-artifacts",
    "title": "MITRE ATLAS Train Proxy via Gathered AI Artifacts (AML.T0005.000) - Adversarial Train Proxy via Gathered AI Artifacts threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0005.000 (Train Proxy via Gathered AI Artifacts). Proxy models may be trained from AI artifacts (such as data, model architectures, and pre-trained models) that are representative of the target model gathered by the adversary. This can be used to develop attacks that require higher levels of access than the adversary has available or as a means to validate pre-existing attacks without interacting with the target model. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0005. ATLAS-mapped mitigations: AML.M0000 Limit Public Release of Information, AML.M0001 Limit Model Artifact Release.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-limit-public-release-of-information",
      "mitre-atlas-mitigation-limit-model-artifact-release"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-train-proxy-via-replication",
    "title": "MITRE ATLAS Train Proxy via Replication (AML.T0005.001) - Adversarial Train Proxy via Replication threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0005.001 (Train Proxy via Replication). Adversaries may replicate a private model. By repeatedly querying the victim's AI Model Inference API Access, the adversary can collect the target model's inferences into a dataset. The inferences are used as labels for training a separate model offline that will mimic the behavior and performance of the target model. A replicated model that closely mimic's the target model is a valuable resource in staging the attack. The adversary can use the replicated model to Craft Adversarial Data for various purposes (e.g. Evade AI Model, Spamming AI System with Chaff Data). Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0005. ATLAS-mapped mitigations: AML.M0002 Passive AI Output Obfuscation, AML.M0004 Restrict Number of AI Model Queries, AML.M0024 AI Telemetry Logging.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-passive-ai-output-obfuscation",
      "mitre-atlas-mitigation-restrict-number-of-ai-model-queries",
      "mitre-atlas-mitigation-ai-telemetry-logging"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-atlas-transfer-learning-attack",
    "title": "MITRE ATLAS Craft Adversarial Data - Adversarial Example Robustness (AML.T0043) - Compliance Obligations for Adversarial Training, Input Robustness Testing, and Worst-Case Robustness Evaluation",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0043 (Craft Adversarial Data), aligning with EU AI Act Articles 9 and 15 for robust AI system defense. Key compliance action involves implementing adversarial training and robustness testing against adversarial examples.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-triggered",
    "title": "MITRE ATLAS Triggered (AML.T0051.002) - Adversarial Triggered threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0051.002 (Triggered). An adversary may trigger a prompt injection via a user action or event that occurs within the victim's environment. Triggered prompt injections often target AI agents, which can be activated by means the adversary identifies during Discovery (See Activation Triggers). These malicious prompts may be hidden or obfuscated from the user and may already exist somewhere in the victim's environment from the adversary performing Prompt Infiltration via Public-Facing Application. This type of injection may be used by the adversary to gain a foothold in the system or to target an unwitting user of the system. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0051. ATLAS-mapped mitigations: AML.M0024 AI Telemetry Logging, AML.M0033 Input and Output Validation for AI Agent Components.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-ai-telemetry-logging",
      "mitre-atlas-mitigation-input-and-output-validation-for-ai-agent-components"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-atlas-unsafe-ai-artifacts",
    "title": "MITRE ATLAS Unsafe AI Artifacts (AML.T0011.000) - Adversarial Unsafe AI Artifacts threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0011.000 (Unsafe AI Artifacts). Adversaries may develop unsafe AI artifacts that when executed have a deleterious effect. The adversary can use this technique to establish persistent access to systems. These models may be introduced via a AI Supply Chain Compromise. Serialization of models is a popular technique for model storage, transfer, and loading. However, this format without proper checking presents an opportunity for code execution. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0011. ATLAS-mapped mitigations: AML.M0011 Restrict Library Loading, AML.M0013 Code Signing, AML.M0014 Verify AI Artifacts, AML.M0016 Vulnerability Scanning, AML.M0018 User Training, AML.M0023 AI Bill of Materials.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-restrict-library-loading",
      "mitre-atlas-mitigation-code-signing",
      "mitre-atlas-mitigation-verify-ai-artifacts",
      "mitre-atlas-mitigation-vulnerability-scanning",
      "mitre-atlas-mitigation-user-training",
      "mitre-atlas-mitigation-ai-bill-of-materials"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-atlas-unsecured-credentials",
    "title": "MITRE ATLAS Unsecured Credentials (AML.T0055) - Adversarial use of Unsecured Credentials as adapted in MITRE ATT&CK T1552",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0055 (Unsecured Credentials). Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. bash history), environment variables, operating system, or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. private keys). Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1552 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-use-alternate-authentication-material",
    "title": "MITRE ATLAS Use Alternate Authentication Material (AML.T0091) - Adversarial use of Use Alternate Authentication Material as adapted in MITRE ATT&CK T1550",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0091 (Use Alternate Authentication Material). Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal system access controls. AI services commonly use alternate authentication material as a primary means for users to make queries, making them vulnerable to this technique. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1550 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-use-pre-trained-model",
    "title": "MITRE ATLAS Use Pre-Trained Model (AML.T0005.002) - Adversarial Use Pre-Trained Model threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0005.002 (Use Pre-Trained Model). Adversaries may use an off-the-shelf pre-trained model as a proxy for the victim model to aid in staging the attack. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0005. ATLAS-mapped mitigations: AML.M0000 Limit Public Release of Information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-limit-public-release-of-information"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-user-execution-ml-model",
    "title": "MITRE ATLAS User Execution of Malicious AI Models and Adversarial Notebooks (AML.T0011) - Compliance Obligations for AI System Access Controls, Execution Safeguards, and Malicious Model Ingestion Prevention",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses compliance obligations to prevent user execution of malicious ML models and adversarial notebooks under MITRE ATLAS technique AML.T0011, aligning with EU AI Act Article 15 (accuracy, robustness and cybersecurity) requirements for robust execution safeguards; EU AI Act Article 9 (risk management system) requirements for technical configuration controls; and EU AI Act Article 50 (transparency for providers and deployers of certain AI systems) requirements where applicable to generative or AI-output content.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-user-harm",
    "title": "MITRE ATLAS User Harm (AML.T0048.003) - Adversarial User Harm threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0048.003 (User Harm). User harms may encompass a variety of harm types including financial and reputational that are directed at or felt by individual victims of the attack rather than at the organization level. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0048.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-valid-ml-platform-accounts",
    "title": "MITRE ATLAS Valid AI Platform Account Abuse for Unauthorised AI Access (AML.T0012) - Compliance Obligations for AI Platform Identity and Access Management, Service Account Controls, and Privileged AI Pipeline Access Governance",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses compliance obligations to mitigate MITRE ATLAS technique AML.T0012 (Valid ML Platform Account Abuse) for unauthorised AI access, aligning with EU AI Act requirements under Articles 5, 15, and 50 for identity management and access governance in high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-verify-attack",
    "title": "MITRE ATLAS Verify Attack (AML.T0042) - Adversarial Verification of Attack Effectiveness Before Deployment",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0042 (Verify Attack). Adversaries can verify the efficacy of their attack via an inference API or access to an offline copy of the target model. This gives the adversary confidence that their approach works and allows them to carry out the attack at a later time of their choosing. The adversary may verify the attack once but use it against many edge devices running copies of the target model. The adversary may verify their attack digitally, then deploy it in the Physical Environment Access at a later time. Verifying the attack may be hard to detect since the adversary can use a minimal number of queries or an offline copy of the model. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-passive-ai-output-obfuscation",
      "mitre-atlas-mitigation-restrict-number-of-ai-model-queries",
      "mitre-atlas-mitigation-control-access-to-ai-models-and-data-at-rest",
      "mitre-atlas-mitigation-control-access-to-ai-models-and-data-in-production"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-atlas-victim-model-replication",
    "title": "MITRE ATLAS Victim AI Model Replication for Surrogate Attack Development (AML.T0005.001) - Compliance Obligations for AI Intellectual Property Protection, Model Cloning Detection, and API Access Governance",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0005.001 (Create Proxy ML Model), aligning with EU AI Act Articles 9 and 15 for robust AI system protection. Key compliance actions include API response limitation and query pattern monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-victim-website-reconnaissance",
    "title": "MITRE ATLAS AI Reconnaissance via Victim-Owned Websites and API Endpoints (AML.T0003) - Compliance Obligations for AI Service Exposure Minimisation, API Security Governance, and Information Disclosure Controls",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0003, focusing on adversary reconnaissance via victim-owned websites and APIs, under the EU AI Act Articles 9 and 15. Key compliance actions include minimising information disclosure and securing API endpoints.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-atlas-virtualization-sandbox-evasion",
    "title": "MITRE ATLAS Virtualization/Sandbox Evasion (AML.T0097) - Adversarial use of Virtualization/Sandbox Evasion as adapted in MITRE ATT&CK T1497",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0097 (Virtualization/Sandbox Evasion). Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use several methods to accomplish Virtualization/Sandbox Evasion such as checking for security monitoring tools (e.g., Sysinternals, Wireshark, etc.) or other system artifacts associated with analysis or virtualization such as registry keys (e.g. substrings matching Vmware, VBOX, QEMU), environment v... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1497 provides authoritative mitigation guidance for this technique class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-atlas-white-box-optimization",
    "title": "MITRE ATLAS White-Box Optimization (AML.T0043.000) - Adversarial White-Box Optimization threat to AI systems",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-07-22",
    "bluf": "This node addresses MITRE ATLAS technique AML.T0043.000 (White-Box Optimization). In White-Box Optimization, the adversary has full access to the target model and optimizes the adversarial example directly. Adversarial examples trained in this manner are most effective against the target model. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0043. ATLAS-mapped mitigations: AML.M0003 Model Hardening, AML.M0005 Control Access to AI Models and Data at Rest, AML.M0006 Use Ensemble Methods, AML.M0010 Input Restoration, AML.M0015 Adversarial Input Detection, AML.M0017 AI Model Distribution Methods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-iec-42001-ai-management-system-2023",
      "mitre-atlas-mitigation-model-hardening",
      "mitre-atlas-mitigation-control-access-to-ai-models-and-data-at-rest",
      "mitre-atlas-mitigation-use-ensemble-methods",
      "mitre-atlas-mitigation-input-restoration",
      "mitre-atlas-mitigation-adversarial-input-detection",
      "mitre-atlas-mitigation-ai-model-distribution-methods"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-attack-framework-v14",
    "title": "MITRE ATT&CK Framework v14 - Adversarial Tactics, Techniques and Common Knowledge for Threat Intelligence",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-04-30",
    "bluf": "The MITRE ATT&CK Framework is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. It provides a common taxonomy for cybersecurity professionals to describe and analyze adversary behaviors, enabling improved threat modeling, detection engineering, and incident response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cis-controls-v8",
      "iso-27001-2022",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0800-activate-firmware-update-mode",
    "title": "MITRE ATT&CK ICS T0800: Activate Firmware Update Mode (ICS Tactic TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0800 (Activate Firmware Update Mode) is an ATT&CK for ICS Inhibit Response Function technique. Adversaries may activate firmware update mode on devices to prevent expected response functions from engaging in reaction to an emergency or process malfunction. For example, devices such as protection relays may have an operation mode designed for firmware installation. This mode may halt process monitoring and related functions to allow new firmware to be loaded. A device left in update mode may be placed in an inactive holding state if no firmware is provided to it. Affected asset classes: None. MITRE-documented mitigations include M0807 Network Allowlists, M0804 Human User Authentication, M0813 Software Process and Device Authentication, M0802 Communication Authenticity, M0801 Access Management, M0937 Filter Network Traffic. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0801-monitor-process-state",
    "title": "MITRE ATT&CK ICS T0801: Monitor Process State (Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK ICS T0801 covers adversary collection of OT process telemetry, alarm states, and operating conditions for reconnaissance and to plan disruptive operations. Industroyer included process-monitoring modules. Compliance: NERC CIP-007, NIST SP 800-82 Rev 3, IEC 62443-3-3 SR 4 Data Confidentiality, NIS2 Article 21(2)(b).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-ics-t0883-internet-accessible-device",
      "mitre-attack-t1190-exploit-public-facing-application",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0802-automated-collection",
    "title": "MITRE ATT&CK ICS T0802: Automated Collection (ICS Tactic TA0100 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0802 (Automated Collection) is an ATT&CK for ICS Collection technique. Adversaries may automate collection of industrial environment information using tools or scripts. This automated collection may leverage native control protocols and tools available in the control systems environment. For example, the OPC protocol may be used to enumerate and gather information. Access to a system or interface with these native protocols may allow collection and enumeration of other attached, communicating servers and devices. Affected asset classes: None. MITRE-documented mitigations include M0807 Network Allowlists, M0930 Network Segmentation. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0806-brute-force-i-o",
    "title": "MITRE ATT&CK ICS T0806: Brute Force I/O (ICS Tactic TA0106 - Impair Process Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0806 (Brute Force I/O) is an ATT&CK for ICS Impair Process Control technique. Adversaries may repetitively or successively change I/O point values to perform an action. Brute Force I/O may be achieved by changing either a range of I/O point values or a single point value repeatedly to manipulate a process function. The adversary's goal and the information they have about the target environment will influence which of the options they choose. In the case of brute forcing a range of point values, the adversary may be able to achieve an impact without targeting a specific point. Affected asset classes: None. MITRE-documented mitigations include M0807 Network Allowlists, M0930 Network Segmentation, M0937 Filter Network Traffic, M0813 Software Process and Device Authentication. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0807-command-line-interface",
    "title": "MITRE ATT&CK ICS T0807: Command-Line Interface (ICS Tactic TA0104 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0807 (Command-Line Interface) is an ATT&CK for ICS Execution technique. Adversaries may utilize command-line interfaces (CLIs) to interact with systems and execute commands. CLIs provide a means of interacting with computer systems and are a common feature across many types of platforms and devices within control systems environments. Adversaries may also use CLIs to install and run new software, including malicious tools that may be installed over the course of an operation. CLIs are typically accessed locally, but can also be exposed via services, such as SSH, Telnet, and RDP. Affected asset classes: None. MITRE-documented mitigations include M0938 Execution Prevention, M0942 Disable or Remove Feature or Program. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0809-data-destruction",
    "title": "MITRE ATT&CK ICS T0809: Data Destruction (Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK ICS T0809 covers adversary destruction of data and historian records on industrial control systems to inhibit operator response and forensic investigation. CRASHOVERRIDE/Industroyer (Ukraine 2016), Industroyer2 (Ukraine 2022), and FrostyGoop (Ukraine 2024) all included data-destruction components targeting OT historians and engineering workstations. Compliance obligations include NIST SP 800-82 Rev 3, NERC CIP-008 (Incident Response), NERC CIP-009 (Recovery Plans), IEC 62443-2-1 (Security Program), IEC 62443-3-3 SR 7.3 (Backup), ISO 27001 A.8.13, NIS2 Article 21(2)(c), and CISA OT Cybersecurity Performance Goals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1485-data-destruction",
      "mitre-attack-ics-t0883-internet-accessible-device",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "mitre-d3fend-d3-ro-restore-object"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-ics-t0811-data-from-information-repositories",
    "title": "MITRE ATT&CK ICS T0811: Data from Information Repositories (ICS Tactic TA0100 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0811 (Data from Information Repositories) is an ATT&CK for ICS Collection technique. Adversaries may target and collect data from information repositories. This can include sensitive data such as specifications, schematics, or diagrams of control system layouts, devices, and processes. Examples of information repositories include reference databases in the process environment, as well as databases in the corporate network that might contain information about the ICS. Affected asset classes: None. MITRE-documented mitigations include M0947 Audit, M0941 Encrypt Sensitive Information, M0922 Restrict File and Directory Permissions, M0918 User Account Management, M0926 Privileged Account Management, M0917 User Training. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0813-denial-of-control",
    "title": "MITRE ATT&CK ICS T0813: Denial of Control (ICS Tactic TA0105 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0813 (Denial of Control) is an ATT&CK for ICS Impact technique. Adversaries may cause a denial of control to temporarily prevent operators and engineers from interacting with process controls. An adversary may attempt to deny process control access to cause a temporary loss of communication with the control device or to prevent operator adjustment of process controls. An affected process may still be operating during the period of control loss, but not necessarily in a desired state. Affected asset classes: None. MITRE-documented mitigations include M0810 Out-of-Band Communications Channel, M0953 Data Backup, M0811 Redundancy of Service. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0814-denial-of-service",
    "title": "MITRE ATT&CK ICS T0814: Denial of Service (Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK ICS T0814 covers adversary denial-of-service attacks targeting ICS components to disrupt operations. Examples include PLC flooding, fieldbus disruption, HMI lockout, and historian overload. Industroyer protocol-specific DoS modules and CrashOverride targeted Ukrainian power grid availability. Compliance: NERC CIP-008/009, NIST SP 800-82 Rev 3 Section 6, IEC 62443-3-3 SR 5 and SR 6, NIS2 Annex I, ISA-S84 SIS independence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-ics-t0883-internet-accessible-device",
      "mitre-attack-t1190-exploit-public-facing-application",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0815-denial-of-view",
    "title": "MITRE ATT&CK ICS T0815: Denial of View (ICS Tactic TA0105 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0815 (Denial of View) is an ATT&CK for ICS Impact technique. Adversaries may cause a denial of view in attempt to disrupt and prevent operator oversight on the status of an ICS environment. This may manifest itself as a temporary communication failure between a device and its control source, where the interface recovers and becomes available once the interference ceases. An adversary may attempt to deny operator visibility by preventing them from receiving status and reporting messages. Affected asset classes: None. MITRE-documented mitigations include M0810 Out-of-Band Communications Channel, M0953 Data Backup, M0811 Redundancy of Service. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0816-device-restart-shutdown",
    "title": "MITRE ATT&CK ICS T0816: Device Restart/Shutdown (Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK ICS T0816 covers adversary forced restart or shutdown of ICS devices to disrupt process control. Industroyer included device restart modules. Modern threats target PLC controllers, RTU, IED relay devices via vendor protocols. Compliance: NERC CIP-007 (System Security Management), NIST SP 800-82 Rev 3, IEC 62443-3-3, IEC 61850 substation comm.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-ics-t0883-internet-accessible-device",
      "mitre-attack-t1190-exploit-public-facing-application",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0817-drive-by-compromise",
    "title": "MITRE ATT&CK ICS T0817: Drive-by Compromise (ICS Tactic TA0108 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0817 (Drive-by Compromise) is an ATT&CK for ICS Initial Access technique. Adversaries may gain access to a system during a drive-by compromise, when a user visits a website as part of a regular browsing session. With this technique, the user's web browser is targeted and exploited simply by visiting the compromised website. The adversary may target a specific community, such as trusted third party suppliers or other industry specific groups, which often visit the target website. Affected asset classes: None. MITRE-documented mitigations include M0951 Update Software, M0948 Application Isolation and Sandboxing, M0950 Exploit Protection, M0921 Restrict Web-Based Content. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0819-exploit-public-facing-application",
    "title": "MITRE ATT&CK ICS T0819: Exploit Public-Facing Application (ICS Tactic TA0108 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0819 (Exploit Public-Facing Application) is an ATT&CK for ICS Initial Access technique. Adversaries may leverage weaknesses to exploit internet-facing software for initial access into an industrial network. Internet-facing software may be user applications, underlying networking implementations, an assets operating system, weak defenses, etc. Targets of this technique may be intentionally exposed for the purpose of remote management and visibility. Affected asset classes: None. MITRE-documented mitigations include M0951 Update Software, M0916 Vulnerability Scanning, M0950 Exploit Protection, M0926 Privileged Account Management, M0948 Application Isolation and Sandboxing, M0930 Network Segmentation. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0820-exploitation-for-evasion",
    "title": "MITRE ATT&CK ICS T0820: Exploitation for Evasion (ICS Tactic TA0103 - Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0820 (Exploitation for Evasion) is an ATT&CK for ICS Evasion technique. Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection. Vulnerabilities may exist in software that can be used to disable or circumvent security features. Adversaries may have prior knowledge through Remote System Information Discovery about security features implemented on control devices. These device security features will likely be targeted directly for exploitation. Affected asset classes: None. MITRE-documented mitigations include M0919 Threat Intelligence Program, M0950 Exploit Protection, M0948 Application Isolation and Sandboxing, M0951 Update Software. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0821-modify-controller-tasking",
    "title": "MITRE ATT&CK ICS T0821: Modify Controller Tasking (ICS Tactic TA0104 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0821 (Modify Controller Tasking) is an ATT&CK for ICS Execution technique. Adversaries may modify the tasking of a controller to allow for the execution of their own programs. This can allow an adversary to manipulate the execution flow and behavior of a controller. According to 61131-3, the association of a Task with a Program Organization Unit (POU) defines a task association. An adversary may modify these associations or create new ones to manipulate the execution flow of a controller. Affected asset classes: None. MITRE-documented mitigations include M0800 Authorization Enforcement, M0804 Human User Authentication, M0947 Audit, M0945 Code Signing. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0822-external-remote-services",
    "title": "MITRE ATT&CK ICS T0822: External Remote Services (ICS Tactic TA0108 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0822 (External Remote Services) is an ATT&CK for ICS Initial Access technique. Adversaries may leverage external remote services as a point of initial access into your network. These services allow users to connect to internal network resources from external locations. Examples are VPNs, Citrix, and other access mechanisms. Remote service gateways often manage connections and credential authentication for these services. External remote services allow administration of a control system from outside the system. Affected asset classes: None. MITRE-documented mitigations include M0930 Network Segmentation, M0936 Account Use Policies, M0935 Limit Access to Resource Over Network, M0927 Password Policies, M0918 User Account Management, M0942 Disable or Remove Feature or Program. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0823-graphical-user-interface",
    "title": "MITRE ATT&CK ICS T0823: Graphical User Interface (ICS Tactic TA0104 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0823 (Graphical User Interface) is an ATT&CK for ICS Execution technique. Adversaries may attempt to gain access to a machine via a Graphical User Interface (GUI) to enhance execution capabilities. Access to a GUI allows a user to interact with a computer in a more visual manner than a CLI. A GUI allows users to move a cursor and click on interface objects, with a mouse and keyboard as the main input devices, as opposed to just using the keyboard. Affected asset classes: None. MITRE-documented mitigations include M0816 Mitigation Limited or Not Effective. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0826-loss-of-availability",
    "title": "MITRE ATT&CK ICS T0826: Loss of Availability (Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK ICS T0826 covers adversary impact resulting in loss of availability of ICS operations. Includes ransomware on OT (Colonial Pipeline 2021), wiper on engineering workstation (Industroyer/CRASHOVERRIDE), DoS on safety-critical systems. Compliance: NERC CIP-009 (Recovery Plans), NIST SP 800-82 Rev 3, IEC 62443-3-3 SR 7 (Resource Availability), NIS2 Annex I, DORA Article 11-13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-ics-t0883-internet-accessible-device",
      "mitre-attack-t1190-exploit-public-facing-application",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0827-loss-of-control",
    "title": "MITRE ATT&CK ICS T0827: Loss of Control (ICS Tactic TA0105 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0827 (Loss of Control) is an ATT&CK for ICS Impact technique. Adversaries may seek to achieve a sustained loss of control or a runaway condition in which operators cannot issue any commands even if the malicious interference has subsided. The German Federal Office for Information Security (BSI) reported a targeted attack on a steel mill in its 2014 IT Security Report. These targeted attacks affected industrial operations and resulted in breakdowns of control system components and even entire installations. Affected asset classes: None. MITRE-documented mitigations include M0953 Data Backup, M0811 Redundancy of Service, M0810 Out-of-Band Communications Channel. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0828-loss-of-productivity-and-revenue",
    "title": "MITRE ATT&CK ICS T0828: Loss of Productivity and Revenue (ICS Tactic TA0105 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0828 (Loss of Productivity and Revenue) is an ATT&CK for ICS Impact technique. Adversaries may cause loss of productivity and revenue through disruption and even damage to the availability and integrity of control system operations, devices, and related processes. This technique may manifest as a direct effect of an ICS-targeting attack or tangentially, due to an IT-targeting attack against non-segregated environments. Affected asset classes: None. MITRE-documented mitigations include M0953 Data Backup. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0829-loss-of-view",
    "title": "MITRE ATT&CK ICS T0829: Loss of View (ICS Tactic TA0105 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0829 (Loss of View) is an ATT&CK for ICS Impact technique. Adversaries may cause a sustained or permanent loss of view where the ICS equipment will require local, hands-on operator intervention; for instance, a restart or manual operation. By causing a sustained reporting or visibility loss, the adversary can effectively hide the present state of operations. This loss of view can occur without affecting the physical processes themselves. Affected asset classes: None. MITRE-documented mitigations include M0811 Redundancy of Service, M0810 Out-of-Band Communications Channel, M0953 Data Backup. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0830-adversary-in-the-middle",
    "title": "MITRE ATT&CK ICS T0830: Adversary-in-the-Middle (ICS Tactic TA0100 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0830 (Adversary-in-the-Middle) is an ATT&CK for ICS Collection technique. Adversaries with privileged network access may seek to modify network traffic in real time using adversary-in-the-middle (AiTM) attacks. This type of attack allows the adversary to intercept traffic to and/or from a particular device on the network. If a AiTM attack is established, then the adversary has the ability to block, log, modify, or inject traffic into the communication stream. Affected asset classes: None. MITRE-documented mitigations include M0930 Network Segmentation, M0810 Out-of-Band Communications Channel, M0813 Software Process and Device Authentication, M0814 Static Network Configuration, M0931 Network Intrusion Prevention, M0947 Audit. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0831-manipulation-of-control",
    "title": "MITRE ATT&CK ICS T0831: Manipulation of Control (ICS Tactic TA0105 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0831 (Manipulation of Control) is an ATT&CK for ICS Impact technique. Adversaries may manipulate physical process control within the industrial environment. Methods of manipulating control can include changes to set point values, tags, or other parameters. Adversaries may manipulate control systems devices or possibly leverage their own, to communicate with and command physical control processes. The duration of manipulation may be temporary or longer sustained, depending on operator detection. Affected asset classes: None. MITRE-documented mitigations include M0810 Out-of-Band Communications Channel, M0953 Data Backup, M0802 Communication Authenticity. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0832-manipulation-of-view",
    "title": "MITRE ATT&CK ICS T0832: Manipulation of View (ICS Tactic TA0105 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0832 (Manipulation of View) is an ATT&CK for ICS Impact technique. Adversaries may attempt to manipulate the information reported back to operators or controllers. This manipulation may be short term or sustained. During this time the process itself could be in a much different state than what is reported. Operators may be fooled into doing something that is harmful to the system in a loss of view situation. With a manipulated view into the systems, operators may issue inappropriate control sequences that introduce faults or catastrophic failures into the system. Affected asset classes: None. MITRE-documented mitigations include M0802 Communication Authenticity, M0810 Out-of-Band Communications Channel, M0953 Data Backup. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0834-native-api",
    "title": "MITRE ATT&CK ICS T0834: Native API (ICS Tactic TA0104 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0834 (Native API) is an ATT&CK for ICS Execution technique. Adversaries may directly interact with the native OS application programming interface (API) to access system functions. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Affected asset classes: None. MITRE-documented mitigations include M0938 Execution Prevention. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0835-manipulate-i-o-image",
    "title": "MITRE ATT&CK ICS T0835: Manipulate I/O Image (ICS Tactic TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0835 (Manipulate I/O Image) is an ATT&CK for ICS Inhibit Response Function technique. Adversaries may manipulate the I/O image of PLCs through various means to prevent them from functioning as expected. Methods of I/O image manipulation may include overriding the I/O table via direct memory manipulation or using the override function used for testing PLC programs. During the scan cycle, a PLC reads the status of all inputs and stores them in an image table. Affected asset classes: None. MITRE-documented mitigations include M0816 Mitigation Limited or Not Effective. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0836-modify-parameter",
    "title": "MITRE ATT&CK ICS T0836: Modify Parameter (Impair Process Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK ICS T0836 covers adversary unauthorised modification of OT process parameters (setpoints, alarm thresholds, control logic parameters) to impair operations or cause physical damage. Stuxnet modified centrifuge spin parameters. Triton/Trisis attempted modification of Safety Instrumented System parameters. Compliance: NERC CIP-007 (System Security Management), IEC 62443-3-3 SR 1 Identification and SR 3 System Integrity, IEC 61511 SIS parameter protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-ics-t0883-internet-accessible-device",
      "mitre-attack-t1190-exploit-public-facing-application",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0837-loss-of-protection",
    "title": "MITRE ATT&CK ICS T0837: Loss of Protection (ICS Tactic TA0105 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0837 (Loss of Protection) is an ATT&CK for ICS Impact technique. Adversaries may compromise protective system functions designed to prevent the effects of faults and abnormal conditions. This can result in equipment damage, prolonged process disruptions and hazards to personnel. Many faults and abnormal conditions in process control happen too quickly for a human operator to react to. Speed is critical in correcting these conditions to limit serious impacts such as Loss of Control and Property Damage. Affected asset classes: None. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-ics-t0838-modify-alarm-settings",
    "title": "MITRE ATT&CK ICS T0838: Modify Alarm Settings (ICS Tactic TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0838 (Modify Alarm Settings) is an ATT&CK for ICS Inhibit Response Function technique. Adversaries may modify alarm settings to prevent alerts that may inform operators of their presence or to prevent responses to dangerous and unintended scenarios. Reporting messages are a standard part of data acquisition in control systems. Reporting messages are used as a way to transmit system state information and acknowledgements that specific actions have occurred. Affected asset classes: None. MITRE-documented mitigations include M0804 Human User Authentication, M0930 Network Segmentation, M0807 Network Allowlists, M0813 Software Process and Device Authentication, M0800 Authorization Enforcement, M0918 User Account Management. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0840-network-connection-enumeration",
    "title": "MITRE ATT&CK ICS T0840: Network Connection Enumeration (ICS Tactic TA0102 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0840 (Network Connection Enumeration) is an ATT&CK for ICS Discovery technique. Adversaries may perform network connection enumeration to discover information about device communication patterns. If an adversary can inspect the state of a network connection with tools, such as Netstat, in conjunction with System Firmware, then they can determine the role of certain devices on the network . The adversary can also use Network Sniffing to watch network traffic for details about the source, destination, protocol, and content. Affected asset classes: None. MITRE-documented mitigations include M0816 Mitigation Limited or Not Effective. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0842-network-sniffing",
    "title": "MITRE ATT&CK ICS T0842: Network Sniffing (ICS Tactic TA0102 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0842 (Network Sniffing) is an ATT&CK for ICS Discovery technique. Network sniffing is the practice of using a network interface on a computer system to monitor or capture information regardless of whether it is the specified destination for the information. An adversary may attempt to sniff the traffic to gain information about the target. This information can vary in the level of importance. Relatively unimportant information is general communications to and from machines. Relatively important information would be login information. Affected asset classes: None. MITRE-documented mitigations include M0926 Privileged Account Management, M0930 Network Segmentation, M0932 Multi-factor Authentication, M0808 Encrypt Network Traffic, M0814 Static Network Configuration. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0843-001-download-all",
    "title": "MITRE ATT&CK ICS T0843.001: Download All (ICS Tactic TA0109 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T0843.001 (Download All) is an ICS Lateral Movement technique. Adversaries may execute a full program download to a PLC to overwrite the entire PLC program and configuration to deploy a new project or make major changes. This typically requires stopping the PLC and adversely impacting control processes. The ability to perform a full program download to the PLC typically relies on access to a workstation with the vendor-specific PLC programming software installed. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T0843. ATT&CK-mapped mitigations: M0945 Code Signing, M0947 Audit, M0802 Communication Authenticity, M0800 Authorization Enforcement, M0801 Access Management, M0937 Filter Network Traffic, M0930 Network Segmentation, M0804 Human User Authentication, M0813 Software Process and Device Authentication, M0807 Network Allowlists.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 16
  },
  {
    "node_id": "mitre-attack-ics-t0843-002-online-edit",
    "title": "MITRE ATT&CK ICS T0843.002: Online Edit (ICS Tactic TA0109 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T0843.002 (Online Edit) is an ICS Lateral Movement technique. Adversaries may execute an online edit of a PLC to update parts of an existing program. It does not require stopping the PLC which allows it to continue running during transfer and reconfiguration without interruption to process control. Adversaries may leverage this approach to minimize downtime and evade detection. The ability to perform an online edit to the PLC typically relies on access to a workstation with the vendor-specific PLC programming software installed. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T0843. ATT&CK-mapped mitigations: M0804 Human User Authentication, M0802 Communication Authenticity, M0930 Network Segmentation, M0807 Network Allowlists, M0800 Authorization Enforcement, M0801 Access Management, M0937 Filter Network Traffic, M0947 Audit, M0813 Software Process and Device Authentication, M0945 Code Signing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 16
  },
  {
    "node_id": "mitre-attack-ics-t0843-003-program-append",
    "title": "MITRE ATT&CK ICS T0843.003: Program Append (ICS Tactic TA0109 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T0843.003 (Program Append) is an ICS Lateral Movement technique. Adversaries may execute a program append to a PLC to update parts of an existing program. It may or may not require stopping the PLC which may allow it to continue running during transfer and reconfiguration without interruption to process control. Adversaries may leverage this approach to minimize downtime and evade detection. The ability to perform a program append to the PLC typically relies on access to a workstation with the vendor-specific PLC programming software installed. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T0843. ATT&CK-mapped mitigations: M0937 Filter Network Traffic, M0813 Software Process and Device Authentication, M0807 Network Allowlists, M0804 Human User Authentication, M0802 Communication Authenticity, M0800 Authorization Enforcement, M0947 Audit, M0945 Code Signing, M0930 Network Segmentation, M0801 Access Management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 16
  },
  {
    "node_id": "mitre-attack-ics-t0843-program-download",
    "title": "MITRE ATT&CK ICS T0843: Program Download (ICS Tactic TA0109 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0843 (Program Download) is an ATT&CK for ICS Lateral Movement technique. Adversaries may perform a program download to transfer a user program to a controller. Variations of program download, such as online edit and program append, allow a controller to continue running during the transfer and reconfiguration process without interruption to process control. However, before starting a full program download (i.e., download all) a controller may need to go into a stop state. Affected asset classes: None. MITRE-documented mitigations include M0813 Software Process and Device Authentication, M0947 Audit, M0937 Filter Network Traffic, M0807 Network Allowlists, M0930 Network Segmentation, M0800 Authorization Enforcement. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0845-program-upload",
    "title": "MITRE ATT&CK ICS T0845: Program Upload (ICS Tactic TA0100 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0845 (Program Upload) is an ATT&CK for ICS Collection technique. Adversaries may attempt to upload a program from a PLC to gather information about an industrial process. Uploading a program may allow them to acquire and study the underlying logic. Methods of program upload include vendor software, which enables the user to upload and read a program running on a PLC. This software can be used to upload the target program to a workstation, jump box, or an interfacing device. Affected asset classes: None. MITRE-documented mitigations include M0813 Software Process and Device Authentication, M0802 Communication Authenticity, M0800 Authorization Enforcement, M0801 Access Management, M0930 Network Segmentation, M0937 Filter Network Traffic. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0846-001-port-scan",
    "title": "MITRE ATT&CK ICS T0846.001: Port Scan (ICS Tactic TA0102 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T0846.001 (Port Scan) is an ICS Discovery technique. Adversaries may perform a port scan on a system, device, or network to identify live hosts, enumerate open ports and running services, identify operating systems, and map out the network. The results of a port scan may inform adversary Discovery, Lateral Movement, and vulnerability exploitation decisions (Exploitation for Evasion, Exploitation for Privilege Escalation, Exploitation of Remote Services). Some common tools for executing a port scan include `nmap`, `netcat`, and the Advanced Port Scanner. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T0846. ATT&CK-mapped mitigations: M0814 Static Network Configuration, M0930 Network Segmentation, M0931 Network Intrusion Prevention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-attack-ics-t0846-002-broadcast-discovery",
    "title": "MITRE ATT&CK ICS T0846.002: Broadcast Discovery (ICS Tactic TA0102 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T0846.002 (Broadcast Discovery) is an ICS Discovery technique. Adversaries may perform broadcast discovery requests to enumerate systems and devices on a network. Broadcast discovery works by one system or device sending messages to all systems and devices on a network (or subnet) and then waiting for a response. If a response is received that means the system or device that responded is live and can communicate over that protocol. Adversaries may leverage different protocols supported on the network for sending broadcast messages. Some common OT protocols that have broadcast discovery mechanisms are Building Automation and Control Network (BACNet) Who-Is requests, Common Industrial Protocol (CIP) List Identity User Datagram Protocol (UDP) broadcast requests, and Siemens S7 broadcast identification requests. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T0846. ATT&CK-mapped mitigations: M0930 Network Segmentation, M0814 Static Network Configuration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-ics-t0846-003-multicast-discovery",
    "title": "MITRE ATT&CK ICS T0846.003: Multicast Discovery (ICS Tactic TA0102 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T0846.003 (Multicast Discovery) is an ICS Discovery technique. Adversaries may perform multicast discovery requests which is when one system or device sends messages to all systems and devices in a pre-defined group on a network (or subnet) and then waits for a response. If a response is received that means the system or device that responded is live and can communicate over that protocol. Multicast discovery tends to be stealthier than broadcast discovery because every system or device on the network (or subnet) is not being messaged. One common OT protocol that has a multicast discovery mechanism is the Process Field Network (PROFINET) Discovery and Configuration Protocol (DCP) with its Identify All requests. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T0846. ATT&CK-mapped mitigations: M0814 Static Network Configuration, M0930 Network Segmentation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-ics-t0846-remote-system-discovery",
    "title": "MITRE ATT&CK ICS T0846: Remote System Discovery (ICS Tactic TA0102 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0846 (Remote System Discovery) is an ATT&CK for ICS Discovery technique. Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for subsequent Lateral Movement or Discovery techniques. Functionality could exist within adversary tools to enable this, but utilities available on the operating system or vendor software could also be used. Affected asset classes: None. MITRE-documented mitigations include M0814 Static Network Configuration. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0847-replication-through-removable-media",
    "title": "MITRE ATT&CK ICS T0847: Replication Through Removable Media (ICS Tactic TA0108 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0847 (Replication Through Removable Media) is an ATT&CK for ICS Initial Access technique. Adversaries may move onto systems, such as those separated from the enterprise network, by copying malware to removable media which is inserted into the control systems environment. The adversary may rely on unknowing trusted third parties, such as suppliers or contractors with access privileges, to introduce the removable media. This technique enables initial access to target devices that never connect to untrusted networks, but are physically accessible. Affected asset classes: None. MITRE-documented mitigations include M0928 Operating System Configuration, M0934 Limit Hardware Installation, M0942 Disable or Remove Feature or Program. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0848-rogue-master",
    "title": "MITRE ATT&CK ICS T0848: Rogue Master (ICS Tactic TA0108 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0848 (Rogue Master) is an ATT&CK for ICS Initial Access technique. Adversaries may setup a rogue master to leverage control server functions to communicate with outstations. A rogue master can be used to send legitimate control messages to other control system devices, affecting processes in unintended ways. It may also be used to disrupt network communications by capturing and receiving the network traffic meant for the actual master. Impersonating a master may also allow an adversary to avoid detection. Affected asset classes: None. MITRE-documented mitigations include M0813 Software Process and Device Authentication, M0937 Filter Network Traffic, M0930 Network Segmentation, M0807 Network Allowlists, M0802 Communication Authenticity. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0849-masquerading",
    "title": "MITRE ATT&CK ICS T0849: Masquerading (ICS Tactic TA0103 - Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0849 (Masquerading) is an ATT&CK for ICS Evasion technique. Adversaries may use masquerading to disguise a malicious application or executable as another file, to avoid operator and engineer suspicion. Possible disguises of these masquerading files can include commonly found programs, expected vendor executables and configuration files, and other commonplace application and naming conventions. Affected asset classes: None. MITRE-documented mitigations include M0945 Code Signing, M0938 Execution Prevention, M0922 Restrict File and Directory Permissions. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0851-rootkit",
    "title": "MITRE ATT&CK ICS T0851: Rootkit (ICS Tactic TA0103 - Evasion / TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0851 (Rootkit) is an ATT&CK for ICS Evasion and Inhibit Response Function technique. Adversaries may deploy rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting and modifying operating-system API calls that supply system information. Rootkits or rootkit-enabling functionality may reside at the user or kernel level in the operating system, or lower. Firmware rootkits that affect the operating system yield nearly full control of the system. Affected asset classes: None. MITRE-documented mitigations include M0945 Code Signing, M0947 Audit. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0852-screen-capture",
    "title": "MITRE ATT&CK ICS T0852: Screen Capture (ICS Tactic TA0100 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0852 (Screen Capture) is an ATT&CK for ICS Collection technique. Adversaries may attempt to perform screen capture of devices in the control system environment. Screenshots may be taken of workstations, HMIs, or other devices that display environment-relevant process, device, reporting, alarm, or related data. These device displays may reveal information regarding the ICS process, layout, control, and related schematics. In particular, an HMI can provide a lot of important industrial process information. Affected asset classes: None. MITRE-documented mitigations include M0816 Mitigation Limited or Not Effective. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0853-scripting",
    "title": "MITRE ATT&CK ICS T0853: Scripting (Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK ICS T0853 covers adversary use of scripting (Python, PowerShell, ladder logic abuse, vendor-specific scripting) on OT systems for execution. Triton/Trisis used Python on Safety Instrumented System engineering workstation. Compliance: NERC CIP-007, NIST SP 800-82 Rev 3, IEC 62443-3-3 SR 1 and SR 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-ics-t0883-internet-accessible-device",
      "mitre-attack-t1190-exploit-public-facing-application",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0858-change-operating-mode",
    "title": "MITRE ATT&CK ICS T0858: Change Operating Mode (ICS Tactic TA0104 - Execution / TA0103 - Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0858 (Change Operating Mode) is an ATT&CK for ICS Execution and Evasion technique. Adversaries may change the operating mode of a controller to gain additional access to engineering functions such as Program Download. Programmable controllers typically have several modes of operation that control the state of the user program and control access to the controllers API. Operating modes can be physically selected using a key switch on the face of the controller but may also be selected with calls to the controllers API. Affected asset classes: None. MITRE-documented mitigations include M0802 Communication Authenticity, M0804 Human User Authentication, M0813 Software Process and Device Authentication, M0801 Access Management, M0807 Network Allowlists, M0930 Network Segmentation. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0859-valid-accounts",
    "title": "MITRE ATT&CK ICS T0859: Valid Accounts (ICS Tactic TA0110 - Persistence / TA0109 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0859 (Valid Accounts) is an ATT&CK for ICS Persistence and Lateral Movement technique. Adversaries may steal the credentials of a specific user or service account using credential access techniques. In some cases, default credentials for control system devices may be publicly available. Compromised credentials may be used to bypass access controls placed on various resources on hosts and within the network, and may even be used for persistent access to remote systems. Affected asset classes: None. MITRE-documented mitigations include M0801 Access Management, M0926 Privileged Account Management, M0918 User Account Management, M0937 Filter Network Traffic, M0932 Multi-factor Authentication, M0927 Password Policies. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0860-wireless-compromise",
    "title": "MITRE ATT&CK ICS T0860: Wireless Compromise (ICS Tactic TA0108 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0860 (Wireless Compromise) is an ATT&CK for ICS Initial Access technique. Adversaries may perform wireless compromise as a method of gaining communications and unauthorized access to a wireless network. Access to a wireless network may be gained through the compromise of a wireless device. Adversaries may also utilize radios and other wireless communication devices on the same frequency as the wireless network. Wireless compromise can be done as an initial access vector from a remote distance. Affected asset classes: None. MITRE-documented mitigations include M0802 Communication Authenticity, M0813 Software Process and Device Authentication, M0806 Minimize Wireless Signal Propagation, M0808 Encrypt Network Traffic. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0861-point-tag-identification",
    "title": "MITRE ATT&CK ICS T0861: Point & Tag Identification (ICS Tactic TA0100 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0861 (Point & Tag Identification) is an ATT&CK for ICS Collection technique. Adversaries may collect point and tag values to gain a more comprehensive understanding of the process environment. Points may be values such as inputs, memory locations, outputs or other process specific variables. Tags are the identifiers given to points for operator convenience. Collecting such tags provides valuable context to environmental points and enables an adversary to map inputs, outputs, and other values to their control processes. Affected asset classes: None. MITRE-documented mitigations include M0800 Authorization Enforcement, M0807 Network Allowlists, M0937 Filter Network Traffic, M0804 Human User Authentication, M0813 Software Process and Device Authentication, M0801 Access Management. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0862-supply-chain-compromise",
    "title": "MITRE ATT&CK ICS T0862: Supply Chain Compromise (ICS Tactic TA0108 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0862 (Supply Chain Compromise) is an ATT&CK for ICS Initial Access technique. Adversaries may perform supply chain compromise to gain control systems environment access by means of infected products, software, and workflows. Supply chain compromise is the manipulation of products, such as devices or software, or their delivery mechanisms before receipt by the end consumer. Adversary compromise of these products and mechanisms is done for the goal of data or system compromise, once infected products are introduced to the target environment. Affected asset classes: None. MITRE-documented mitigations include M0951 Update Software, M0947 Audit, M0916 Vulnerability Scanning, M0817 Supply Chain Management, M0945 Code Signing. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0863-user-execution",
    "title": "MITRE ATT&CK ICS T0863: User Execution (ICS Tactic TA0104 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0863 (User Execution) is an ATT&CK for ICS Execution technique. Adversaries may rely on a targeted organizations user interaction for the execution of malicious code. User interaction may consist of installing applications, opening email attachments, or granting higher permissions to documents. Adversaries may embed malicious code or visual basic code into files such as Microsoft Word and Excel documents or software installers. Execution of this code requires that the user enable scripting or write access within the document. Affected asset classes: None. MITRE-documented mitigations include M0938 Execution Prevention, M0921 Restrict Web-Based Content, M0917 User Training, M0931 Network Intrusion Prevention, M0949 Antivirus/Antimalware, M0945 Code Signing. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0864-transient-cyber-asset",
    "title": "MITRE ATT&CK ICS T0864: Transient Cyber Asset (ICS Tactic TA0108 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0864 (Transient Cyber Asset) is an ATT&CK for ICS Initial Access technique. Adversaries may target devices that are transient across ICS networks and external networks. Normally, transient assets are brought into an environment by authorized personnel and do not remain in that environment on a permanent basis. Transient assets are commonly needed to support management functions and may be more common in systems where a remotely managed asset is not feasible, external connections for remote access do not exist, or 3rd party contractor/vendor access is required. Affected asset classes: None. MITRE-documented mitigations include M0941 Encrypt Sensitive Information, M0947 Audit, M0949 Antivirus/Antimalware, M0930 Network Segmentation, M0951 Update Software. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0865-spearphishing-attachment",
    "title": "MITRE ATT&CK ICS T0865: Spearphishing Attachment (ICS Tactic TA0108 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0865 (Spearphishing Attachment) is an ATT&CK for ICS Initial Access technique. Adversaries may use a spearphishing attachment, a variant of spearphishing, as a form of a social engineering attack against specific targets. Spearphishing attachments are different from other forms of spearphishing in that they employ malware attached to an email. All forms of spearphishing are electronically delivered and target a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution and access. Affected asset classes: None. MITRE-documented mitigations include M0917 User Training, M0931 Network Intrusion Prevention, M0949 Antivirus/Antimalware, M0921 Restrict Web-Based Content. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0866-exploitation-of-remote-services",
    "title": "MITRE ATT&CK ICS T0866: Exploitation of Remote Services (ICS Tactic TA0108 - Initial Access / TA0109 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0866 (Exploitation of Remote Services) is an ATT&CK for ICS Initial Access and Lateral Movement technique. Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to enable remote service abuse. A common goal for post-compromise exploitation of remote services is for initial access into and lateral movement throughout the ICS environment to enable access to targeted systems. Affected asset classes: None. MITRE-documented mitigations include M0916 Vulnerability Scanning, M0942 Disable or Remove Feature or Program, M0950 Exploit Protection, M0919 Threat Intelligence Program, M0930 Network Segmentation, M0948 Application Isolation and Sandboxing. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0867-lateral-tool-transfer",
    "title": "MITRE ATT&CK ICS T0867: Lateral Tool Transfer (Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK ICS T0867 covers adversary transfer of tools or payloads between OT systems for lateral movement. Includes USB-based tool transfer (Stuxnet propagation), SMB file copy on OT IT-adjacent networks, vendor protocol-based payload delivery. Compliance: NERC CIP-007, NIST SP 800-82 Rev 3, IEC 62443-3-3 SR 5 Restricted Data Flow.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-ics-t0883-internet-accessible-device",
      "mitre-attack-t1190-exploit-public-facing-application",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0868-detect-operating-mode",
    "title": "MITRE ATT&CK ICS T0868: Detect Operating Mode (ICS Tactic TA0100 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0868 (Detect Operating Mode) is an ATT&CK for ICS Collection technique. Adversaries may gather information about a PLCs or controllers current operating mode. Operating modes dictate what change or maintenance functions can be manipulated and are often controlled by a key switch on the PLC (e.g., run, prog [program], and remote). Knowledge of these states may be valuable to an adversary to determine if they are able to reprogram the PLC. Operating modes and the mechanisms by which they are selected often vary by vendor and product line. Affected asset classes: None. MITRE-documented mitigations include M0813 Software Process and Device Authentication, M0804 Human User Authentication, M0937 Filter Network Traffic, M0801 Access Management, M0802 Communication Authenticity, M0807 Network Allowlists. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0869-standard-application-layer-protocol",
    "title": "MITRE ATT&CK ICS T0869: Standard Application Layer Protocol (ICS Tactic TA0101 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0869 (Standard Application Layer Protocol) is an ATT&CK for ICS Command and Control technique. Adversaries may establish command and control capabilities over commonly used application layer protocols such as HTTP(S), OPC, RDP, telnet, DNP3, and modbus. These protocols may be used to disguise adversary actions as benign network traffic. Standard protocols may be seen on their associated port or in some cases over a non-standard port. Adversaries may use these protocols to reach out of the network for command and control, or in some cases to other infected devices within the network. Affected asset classes: None. MITRE-documented mitigations include M0930 Network Segmentation, M0931 Network Intrusion Prevention, M0807 Network Allowlists. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0871-execution-through-api",
    "title": "MITRE ATT&CK ICS T0871: Execution through API (ICS Tactic TA0104 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0871 (Execution through API) is an ATT&CK for ICS Execution technique. Adversaries may attempt to leverage Application Program Interfaces (APIs) used for communication between control software and the hardware. Specific functionality is often coded into APIs which can be called by software to engage specific functions on a device or other software. Affected asset classes: None. MITRE-documented mitigations include M0938 Execution Prevention, M0800 Authorization Enforcement, M0804 Human User Authentication, M0801 Access Management. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0872-indicator-removal-on-host",
    "title": "MITRE ATT&CK ICS T0872: Indicator Removal on Host (ICS Tactic TA0103 - Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0872 (Indicator Removal on Host) is an ATT&CK for ICS Evasion technique. Adversaries may attempt to remove indicators of their presence on a system in an effort to cover their tracks. In cases where an adversary may feel detection is imminent, they may try to overwrite, delete, or cover up changes they have made to the device. Affected asset classes: None. MITRE-documented mitigations include M0922 Restrict File and Directory Permissions. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0873-001-siemens-project-file-format",
    "title": "MITRE ATT&CK ICS T0873.001: Siemens Project File Format (ICS Tactic TA0110 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T0873.001 (Siemens Project File Format) is an ICS Persistence technique. Adversaries may infect Siemens PLC project files (i.e., Step 7, WinCC, etc.) to achieve Execution, Persistence, and Lateral Movement objectives. Adversaries may modify an existing project file or bring their own project files into the environment. The ability for an adversary to deploy an infected project file relies on access to a workstation with Siemens PLC programming software installed on it from which a program download can be performed. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T0873. ATT&CK-mapped mitigations: M0945 Code Signing, M0941 Encrypt Sensitive Information, M0947 Audit, M0922 Restrict File and Directory Permissions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-attack-ics-t0873-project-file-infection",
    "title": "MITRE ATT&CK ICS T0873: Project File Infection (ICS Tactic TA0110 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0873 (Project File Infection) is an ATT&CK for ICS Persistence technique. Adversaries may attempt to infect project files with malicious code. These project files may consist of objects, program organization units, variables such as tags, documentation, and other configurations needed for PLC programs to function. Using built in functions of the engineering software, adversaries may be able to download an infected program to a PLC in the operating environment enabling further Execution and Persistence techniques. Affected asset classes: None. MITRE-documented mitigations include M0922 Restrict File and Directory Permissions, M0941 Encrypt Sensitive Information, M0947 Audit, M0945 Code Signing. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0874-hooking",
    "title": "MITRE ATT&CK ICS T0874: Hooking (ICS Tactic TA0104 - Execution / TA0111 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0874 (Hooking) is an ATT&CK for ICS Execution and Privilege Escalation technique. Adversaries may hook into application programming interface (API) functions used by processes to redirect calls for execution and privilege escalation means. Windows processes often leverage these API functions to perform tasks that require reusable system resources. Windows API functions are typically stored in dynamic-link libraries (DLLs) as exported functions. One type of hooking seen in ICS involves redirecting calls to these functions via import address table (IAT) hooking. Affected asset classes: None. MITRE-documented mitigations include M0944 Restrict Library Loading, M0947 Audit. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0877-i-o-image",
    "title": "MITRE ATT&CK ICS T0877: I/O Image (ICS Tactic TA0100 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0877 (I/O Image) is an ATT&CK for ICS Collection technique. Adversaries may seek to capture process values related to the inputs and outputs of a PLC. During the scan cycle, a PLC reads the status of all inputs and stores them in an image table. The image table is the PLCs internal storage location where values of inputs/outputs for one scan are stored while it executes the user program. After the PLC has solved the entire logic program, it updates the output image table. The contents of this output image table are written to the corresponding output points in I/O Modules. Affected asset classes: None. MITRE-documented mitigations include M0816 Mitigation Limited or Not Effective. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0878-alarm-suppression",
    "title": "MITRE ATT&CK ICS T0878: Alarm Suppression (ICS Tactic TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0878 (Alarm Suppression) is an ATT&CK for ICS Inhibit Response Function technique. Adversaries may target protection function alarms to prevent them from notifying operators of critical conditions. Alarm messages may be a part of an overall reporting system and of particular interest for adversaries. Disruption of the alarm system does not imply the disruption of the reporting system as a whole. A Secura presentation on targeting OT notes a dual fold goal for adversaries attempting alarm suppression: prevent outgoing alarms from being raised and prevent incoming alarms from being responded to. Affected asset classes: None. MITRE-documented mitigations include M0814 Static Network Configuration, M0807 Network Allowlists, M0930 Network Segmentation, M0810 Out-of-Band Communications Channel. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0879-damage-to-property",
    "title": "MITRE ATT&CK ICS T0879: Damage to Property (Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK ICS T0879 covers adversary-induced physical damage to property, equipment, or environment via cyber means. Stuxnet (2010 Iranian centrifuges), German steel mill (2014 BSI report), Ukrainian power grid (2015-2016), Triton/Trisis (2017 Saudi petrochemical Safety Instrumented System), and Colonial Pipeline (2021 indirect impact) all caused or attempted physical damage. Compliance obligations include NERC CIP-002 through CIP-014 (BES protection), IEC 62443-3-3 SR 1-7, NIST SP 800-82 Rev 3, OSHA Process Safety Management, ENISA OT Security Guidance, NIS2 Article 21(2)(c)(d), and ISA-S84 Safety Instrumented Systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-ics-t0809-data-destruction",
      "mitre-attack-ics-t0883-internet-accessible-device",
      "mitre-attack-t1486-data-encrypted-for-impact",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-ics-t0880-loss-of-safety",
    "title": "MITRE ATT&CK ICS T0880: Loss of Safety (ICS Tactic TA0105 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0880 (Loss of Safety) is an ATT&CK for ICS Impact technique. Adversaries may compromise safety system functions designed to maintain safe operation of a process when unacceptable or dangerous conditions occur. Safety systems are often composed of the same elements as control systems but have the sole purpose of ensuring the process fails in a predetermined safe manner. Many unsafe conditions in process control happen too quickly for a human operator to react to. Affected asset classes: None. MITRE-documented mitigations include M0812 Safety Instrumented Systems, M0805 Mechanical Protection Layers. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0881-service-stop",
    "title": "MITRE ATT&CK ICS T0881: Service Stop (ICS Tactic TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0881 (Service Stop) is an ATT&CK for ICS Inhibit Response Function technique. Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment. Services may not allow for modification of their data stores while running. Adversaries may stop services in order to conduct Data Destruction. Affected asset classes: None. MITRE-documented mitigations include M0918 User Account Management, M0924 Restrict Registry Permissions, M0922 Restrict File and Directory Permissions, M0930 Network Segmentation. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0882-theft-of-operational-information",
    "title": "MITRE ATT&CK ICS T0882: Theft of Operational Information (ICS Tactic TA0105 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0882 (Theft of Operational Information) is an ATT&CK for ICS Impact technique. Adversaries may steal operational information on a production environment as a direct mission outcome for personal gain or to inform future operations. This information may include design documents, schedules, rotational data, or similar artifacts that provide insight on operations. In the Bowman Dam incident, adversaries probed systems for operational data. Affected asset classes: None. MITRE-documented mitigations include M0922 Restrict File and Directory Permissions, M0809 Operational Information Confidentiality, M0803 Data Loss Prevention, M0941 Encrypt Sensitive Information. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0883-internet-accessible-device",
    "title": "MITRE ATT&CK ICS T0883: Internet Accessible Device (Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK ICS T0883 covers adversary access to industrial control devices directly exposed to the internet without proper authentication, firewall, or VPN protection. Shodan, Censys, and ZoomEye continuously index thousands of exposed PLCs, HMIs, SCADA endpoints, building automation panels, and energy management systems globally. Compliance obligations include NERC CIP-005 (Electronic Security Perimeters), NERC CIP-007 (Systems Security Management), IEC 62443-3-3 SR 5.1 (Network Segmentation), NIST SP 800-82 Rev 3, ENISA OT Security Guidance, CISA Cross-Sector Cybersecurity Performance Goals, and NIS2 Article 21(2)(c) for critical infrastructure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1595-active-scanning",
      "mitre-d3fend-d3-itf-inbound-traffic-filtering",
      "mitre-d3fend-d3-ni-network-isolation",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-ics-t0884-connection-proxy",
    "title": "MITRE ATT&CK ICS T0884: Connection Proxy (Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK ICS T0884 covers adversary use of legitimate-looking proxy infrastructure within or adjacent to OT zones for C2 communication. Volt Typhoon used compromised SOHO routers as proxies into US critical infrastructure. Compliance: NERC CIP-005, NIST SP 800-82 Rev 3, IEC 62443-3-3 SR 4 and SR 5, NIS2 Article 21(2)(b).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-ics-t0883-internet-accessible-device",
      "mitre-attack-t1190-exploit-public-facing-application",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0885-commonly-used-port",
    "title": "MITRE ATT&CK ICS T0885: Commonly Used Port (ICS Tactic TA0101 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0885 (Commonly Used Port) is an ATT&CK for ICS Command and Control technique. Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend in with normal network activity, to avoid more detailed inspection. They may use the protocol associated with the port, or a completely different protocol. They may use commonly open ports, such as the examples provided below. Affected asset classes: None. MITRE-documented mitigations include M0804 Human User Authentication, M0931 Network Intrusion Prevention, M0930 Network Segmentation, M0942 Disable or Remove Feature or Program. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0886-remote-services",
    "title": "MITRE ATT&CK ICS T0886: Remote Services (Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK ICS T0886 covers adversary use of remote services (RDP, VNC, SSH, vendor proprietary remote-support tools) for lateral movement and access to OT environments. Sandworm (Industroyer/Industroyer2), Volt Typhoon, and most major ICS intrusions leveraged remote services for OT access. Compliance: NERC CIP-005-7 (Interactive Remote Access), IEC 62443-3-3 SR 4 Data Confidentiality and SR 5 Restricted Data Flow, NIS2 Article 21(2)(j).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-ics-t0883-internet-accessible-device",
      "mitre-attack-t1190-exploit-public-facing-application",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-ics-t0887-wireless-sniffing",
    "title": "MITRE ATT&CK ICS T0887: Wireless Sniffing (ICS Tactic TA0102 - Discovery / TA0100 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0887 (Wireless Sniffing) is an ATT&CK for ICS Discovery and Collection technique. Adversaries may seek to capture radio frequency (RF) communication used for remote control and reporting in distributed environments. RF communication frequencies vary between 3 kHz to 300 GHz, although are commonly between 300 MHz to 6 GHz. The wavelength and frequency of the signal affect how the signal propagates through open air, obstacles (e.g. walls and trees) and the type of radio required to capture them. Affected asset classes: None. MITRE-documented mitigations include M0806 Minimize Wireless Signal Propagation, M0808 Encrypt Network Traffic. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0888-remote-system-information-discovery",
    "title": "MITRE ATT&CK ICS T0888: Remote System Information Discovery (ICS Tactic TA0102 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0888 (Remote System Information Discovery) is an ATT&CK for ICS Discovery technique. An adversary may attempt to get detailed information about remote systems and their peripherals, such as make/model, role, and configuration. Adversaries may use information from Remote System Information Discovery to aid in targeting and shaping follow-on behaviors. For example, the system's operational role and model information can dictate whether it is a relevant target for the adversary's operational objectives. In addition, the system's configuration may be used to scope subsequent technique usage. Affected asset classes: None. MITRE-documented mitigations include M0814 Static Network Configuration. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0889-modify-program",
    "title": "MITRE ATT&CK ICS T0889: Modify Program (ICS Tactic TA0110 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0889 (Modify Program) is an ATT&CK for ICS Persistence technique. Adversaries may modify or add a program on a controller to affect how it interacts with the physical process, peripheral devices and other hosts on the network. Modification to controller programs can be accomplished using a Program Download in addition to other types of program modification such as online edit and program append. Affected asset classes: None. MITRE-documented mitigations include M0947 Audit, M0945 Code Signing, M0800 Authorization Enforcement, M0804 Human User Authentication. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0890-exploitation-for-privilege-escalation",
    "title": "MITRE ATT&CK ICS T0890: Exploitation for Privilege Escalation (ICS Tactic TA0111 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0890 (Exploitation for Privilege Escalation) is an ATT&CK for ICS Privilege Escalation technique. Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Affected asset classes: None. MITRE-documented mitigations include M0950 Exploit Protection, M0948 Application Isolation and Sandboxing, M0951 Update Software, M0919 Threat Intelligence Program. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0892-change-credential",
    "title": "MITRE ATT&CK ICS T0892: Change Credential (ICS Tactic TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0892 (Change Credential) is an ATT&CK for ICS Inhibit Response Function technique. Adversaries may modify software and device credentials to prevent operator and responder access. Depending on the device, the modification or addition of this password could prevent any device configuration actions from being accomplished and may require a factory reset or replacement of hardware. These credentials are often built-in features provided by the device vendors as a means to restrict access to management interfaces. Affected asset classes: None. MITRE-documented mitigations include M0927 Password Policies, M0953 Data Backup, M0811 Redundancy of Service. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0893-data-from-local-system",
    "title": "MITRE ATT&CK ICS T0893: Data from Local System (ICS Tactic TA0100 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0893 (Data from Local System) is an ATT&CK for ICS Collection technique. Adversaries may target and collect data from local system sources, such as file systems, configuration files, or local databases. This can include sensitive data such as specifications, schematics, or diagrams of control system layouts, devices, and processes. Adversaries may do this using Command-Line Interface or Scripting techniques to interact with the file system to gather information. Adversaries may also use Automated Collection on the local system. Affected asset classes: None. MITRE-documented mitigations include M0941 Encrypt Sensitive Information, M0803 Data Loss Prevention, M0922 Restrict File and Directory Permissions, M0917 User Training. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0894-system-binary-proxy-execution",
    "title": "MITRE ATT&CK ICS T0894: System Binary Proxy Execution (ICS Tactic TA0103 - Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0894 (System Binary Proxy Execution) is an ATT&CK for ICS Evasion technique. Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Affected asset classes: None. MITRE-documented mitigations include M0938 Execution Prevention. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t0895-autorun-image",
    "title": "MITRE ATT&CK ICS T0895: Autorun Image (ICS Tactic TA0104 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T0895 (Autorun Image) is an ATT&CK for ICS Execution technique. Adversaries may leverage AutoRun functionality or scripts to execute malicious code. Devices configured to enable AutoRun functionality or legacy operating systems may be susceptible to abuse of these features to run malicious code stored on various forms of removeable media (i.e., USB, Disk Images [.ISO]). Commonly, AutoRun or AutoPlay are disabled in many operating systems configurations to mitigate against this technique. MITRE-documented mitigations include M0928 Operating System Configuration. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t1691-001-command-message",
    "title": "MITRE ATT&CK ICS T1691.001: Command Message (ICS Tactic TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1691.001 (Command Message) is an ICS Inhibit Response Function technique. Adversaries may block a command message from reaching its intended target to prevent command execution. In OT networks, command messages are sent to provide instructions to control system devices. A blocked command message can inhibit response functions from correcting a disruption or unsafe condition. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T1691. ATT&CK-mapped mitigations: M0810 Out-of-Band Communications Channel, M0807 Network Allowlists, M0814 Static Network Configuration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-attack-ics-t1691-002-reporting-message",
    "title": "MITRE ATT&CK ICS T1691.002: Reporting Message (ICS Tactic TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1691.002 (Reporting Message) is an ICS Inhibit Response Function technique. Adversaries may block or prevent a reporting message from reaching its intended target. In control systems, reporting messages contain telemetry data (e.g., I/O values) pertaining to the current state of equipment and the industrial process. By blocking these reporting messages, an adversary can potentially hide their actions from an operator. Blocking reporting messages in control systems that manage physical processes may contribute to system impact, causing inhibition of a response function. A control system may not be able to respond in a proper or timely manner to an event, such as a dangerous fault, if its corresponding reporting message is blocked. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T1691. ATT&CK-mapped mitigations: M0810 Out-of-Band Communications Channel, M0807 Network Allowlists, M0814 Static Network Configuration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-attack-ics-t1691-block-operational-technology-message",
    "title": "MITRE ATT&CK ICS T1691: Block Operational Technology Message (ICS Tactic TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1691 (Block Operational Technology Message) is an ICS Inhibit Response Function technique. Adversaries may block messages between systems and devices in an OT/ICS environment to disrupt processes. Messages typically fall into two categories: (1) reporting messages that contain telemetry data about the current state of systems, devices, and processes and (2) command messages that contain instructions to control systems, devices, and processes. Both types of messages are critical for the proper functioning of industrial control processes and failure of the messages to reach their intended destinations could inhibit response functions or create an unsafe condition that could have physical impacts. Adversaries may block communications by either making modifications to software (System Firmware, Module Firmware, Hooking, and Rootkit) and services (Service Stop, Denial of Service) on ... Affected platforms: see ATT&CK ICS. ATT&CK-mapped mitigations: M0810 Out-of-Band Communications Channel, M0814 Static Network Configuration, M0807 Network Allowlists.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-attack-ics-t1692-001-command-message",
    "title": "MITRE ATT&CK ICS T1692.001: Command Message (ICS Tactic TA0103 - Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1692.001 (Command Message) is an ICS Evasion, Impair Process Control technique. Adversaries may send unauthorized command messages to instruct control system assets to perform actions outside of their intended functionality, or without the logical preconditions to trigger their expected function. Command messages are used in ICS networks to give direct instructions to control systems devices. If an adversary can send an unauthorized command message to a control system, then it can instruct the control systems device to perform an action outside the normal bounds of the device's actions. An adversary could potentially instruct a control systems device to perform an action that will cause an Impact. In the Dallas Siren incident, adversaries were able to send command messages to activate tornado alarm systems across the city without an impending tornado or other disaster... Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T1692. ATT&CK-mapped mitigations: M0802 Communication Authenticity, M0818 Validate Program Inputs, M0937 Filter Network Traffic, M0813 Software Process and Device Authentication, M0807 Network Allowlists, M0930 Network Segmentation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-attack-ics-t1692-002-reporting-message",
    "title": "MITRE ATT&CK ICS T1692.002: Reporting Message (ICS Tactic TA0103 - Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1692.002 (Reporting Message) is an ICS Evasion, Impair Process Control technique. Adversaries may spoof reporting messages in control system environments for evasion and to impair process control. In control systems, reporting messages contain telemetry data (e.g., I/O values) pertaining to the current state of equipment and the industrial process. Reporting messages are important for monitoring the normal operation of a system or identifying important events such as deviations from expected values. If an adversary has the ability to Spoof Reporting Messages, they can impact the control system in many ways. The adversary can Spoof Reporting Messages that state that the process is operating normally, as a form of evasion. The adversary could also Spoof Reporting Messages to make the defenders and operators think that other errors are occurring in order to distract them f... Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T1692. ATT&CK-mapped mitigations: M0807 Network Allowlists, M0930 Network Segmentation, M0937 Filter Network Traffic, M0813 Software Process and Device Authentication, M0802 Communication Authenticity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-attack-ics-t1692-unauthorized-message",
    "title": "MITRE ATT&CK ICS T1692: Unauthorized Message (ICS Tactic TA0103 - Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1692 (Unauthorized Message) is an ICS Evasion, Impair Process Control technique. Adversaries may send unauthorized messages to ICS systems and devices to evade defenses or manipulate processes. Unauthorized messages can be categorized as either reporting messages that contain telemetry data about the current state of systems, devices, and processes or as command messages which instruct systems and devices on how to operate. By injecting unauthorized messages, adversaries can make it appear as if everything is working correctly when it isn’t, trigger alarms to misdirect personnel or impact processes, and manipulate controls to disrupt processes. Adversaries may send unauthorized messages in an ICS environment using software found within the environment (living-off-the-land, vendor-specific interfaces, etc.), custom tooling leveraging OT protocols and libraries, or by po... Affected platforms: see ATT&CK ICS. ATT&CK-mapped mitigations: M0813 Software Process and Device Authentication, M0807 Network Allowlists, M0930 Network Segmentation, M0802 Communication Authenticity, M0937 Filter Network Traffic.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-attack-ics-t1693-001-system-firmware",
    "title": "MITRE ATT&CK ICS T1693.001: System Firmware (ICS Tactic TA0110 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1693.001 (System Firmware) is an ICS Persistence, Inhibit Response Function, Impair Process Control technique. System firmware on modern assets is often designed with an update feature. Older device firmware may be factory installed and require special reprograming equipment. When available, the firmware update feature enables vendors to remotely patch bugs and perform upgrades. Device firmware updates are often delegated to the user and may be done using a software update package. It may also be possible to perform this task over the network. An adversary may exploit the firmware update feature on accessible devices to upload malicious or out-of-date firmware. Malicious modification of device firmware may provide an adversary with root access to a device, given firmware is one of the lowest programming abstraction layers. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T1693. ATT&CK-mapped mitigations: M0804 Human User Authentication, M0808 Encrypt Network Traffic, M0947 Audit, M0813 Software Process and Device Authentication, M0937 Filter Network Traffic, M0941 Encrypt Sensitive Information, M0801 Access Management, M0802 Communication Authenticity, M0930 Network Segmentation, M0807 Network Allowlists, M0946 Boot Integrity, M0951 Update Software, M0945 Code Signing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 19
  },
  {
    "node_id": "mitre-attack-ics-t1693-002-module-firmware",
    "title": "MITRE ATT&CK ICS T1693.002: Module Firmware (ICS Tactic TA0110 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1693.002 (Module Firmware) is an ICS Persistence, Inhibit Response Function, Impair Process Control technique. Adversaries may install malicious or vulnerable firmware onto modular hardware devices. Control system devices often contain modular hardware devices. These devices may have their own set of firmware that is separate from the firmware of the main control system equipment. This technique is similar to System Firmware, but is conducted on other system components that may not have the same capabilities or level of integrity checking. Although it results in a device re-image, malicious device firmware may provide persistent access to remaining devices. An easy point of access for an adversary is the Ethernet card, which may have its own CPU, RAM, and operating system. The adversary may attack and likely exploit the computer on an Ethernet card. Exploitation of the Ethernet card computer may en... Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T1693. ATT&CK-mapped mitigations: M0937 Filter Network Traffic, M0807 Network Allowlists, M0930 Network Segmentation, M0946 Boot Integrity, M0945 Code Signing, M0808 Encrypt Network Traffic, M0801 Access Management, M0802 Communication Authenticity, M0947 Audit, M0941 Encrypt Sensitive Information, M0804 Human User Authentication, M0813 Software Process and Device Authentication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 18
  },
  {
    "node_id": "mitre-attack-ics-t1693-modify-firmware",
    "title": "MITRE ATT&CK ICS T1693: Modify Firmware (ICS Tactic TA0110 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1693 (Modify Firmware) is an ICS Persistence, Inhibit Response Function, Impair Process Control technique. Firmware is low-level software embedded in hardware that enables systems and devices to function properly and is commonly found in ICS environments. Adversaries may modify firmware on a system or device by installing malicious or vulnerable versions that enable them to achieve objectives such as Persistence, Impair Process Control, and Inhibit Response Function. Adversaries may modify system and device firmware by using the built-in firmware update functionality which may support local or remote installation. The malicious or vulnerable firmware may be delivered via Replication Through Removable Media, Supply Chain Compromise, or Remote Services. Once installed, the malicious or vulnerable firmware could be used to provide Rootkit and Hooking functionality, Exploitation for Privilege Escal... Affected platforms: see ATT&CK ICS. ATT&CK-mapped mitigations: M0802 Communication Authenticity, M0930 Network Segmentation, M0945 Code Signing, M0807 Network Allowlists, M0808 Encrypt Network Traffic, M0947 Audit, M0804 Human User Authentication, M0813 Software Process and Device Authentication, M0946 Boot Integrity, M0941 Encrypt Sensitive Information, M0801 Access Management, M0937 Filter Network Traffic.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 18
  },
  {
    "node_id": "mitre-attack-ics-t1694-001-default-credentials",
    "title": "MITRE ATT&CK ICS T1694.001: Default Credentials (ICS Tactic TA0110 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1694.001 (Default Credentials) is an ICS Persistence, Lateral Movement technique. Adversaries may leverage manufacturer or supplier set default credentials on control system devices. These default credentials may have administrative permissions and may be necessary for initial configuration of the device. It is general best practice to change the passwords for these accounts as soon as possible, but some manufacturers may have devices that have passwords or usernames that cannot be changed. Default credentials are normally documented in an instruction manual that is either packaged with the device, published online through official means, or published online through unofficial means. Adversaries may leverage default credentials that have not been properly modified or disabled. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T1694. ATT&CK-mapped mitigations: M0927 Password Policies, M0801 Access Management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-ics-t1694-002-hardcoded-credentials",
    "title": "MITRE ATT&CK ICS T1694.002: Hardcoded Credentials (ICS Tactic TA0110 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1694.002 (Hardcoded Credentials) is an ICS Persistence, Lateral Movement technique. Adversaries may leverage credentials that are hardcoded in software or firmware to gain an unauthorized interactive user session to an asset. Examples credentials that may be hardcoded in an asset include: * Username/Passwords * Cryptographic keys/Certificates * API tokens Unlike Default Credentials, these credentials are built into the system in a way that they either cannot be changed by the asset owner, or may be infeasible to change because of the impact it would cause to the control system operation. These credentials may be reused across whole product lines or device models and are often not published or known to the owner and operators of the asset. Adversaries may utilize these hardcoded credentials to move throughout the control system environment or provide reliable access for th... Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T1694. ATT&CK-mapped mitigations: M0801 Access Management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t1694-insecure-credentials",
    "title": "MITRE ATT&CK ICS T1694: Insecure Credentials (ICS Tactic TA0110 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1694 (Insecure Credentials) is an ICS Persistence, Lateral Movement technique. Adversaries may target insecure credentials as a means to persist on a system or device or move laterally from one system or device to another. Insecure credentials may appear as default credentials which are pre-configured credentials on a system, device, or software that are well-known in documentation or hard-coded credentials which are built into the system, device, or software that cannot be changed or not easily changed because of the impact on control processes. Adversaries often times use insecure credentials to evade detection as they are typically forgotten about by system and device owners. Affected platforms: see ATT&CK ICS. ATT&CK-mapped mitigations: M0801 Access Management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-ics-t1695-001-serial-com",
    "title": "MITRE ATT&CK ICS T1695.001: Serial COM (ICS Tactic TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1695.001 (Serial COM) is an ICS Inhibit Response Function technique. Adversaries may block access to serial COM to prevent instructions or configurations from reaching target devices. Serial Communication ports (COM) allow communication with control system devices. Devices can receive command and configuration messages over such serial COM. Devices also use serial COM to send command and reporting messages. Blocking device serial COM may also block command messages and block reporting messages. A serial to Ethernet converter is often connected to a serial COM to facilitate communication between serial and Ethernet devices. One approach to blocking a serial COM would be to create and hold open a TCP session with the Ethernet side of the converter. A serial to Ethernet converter may have a few ports open to facilitate multiple communications. For example, if ... Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T1695. ATT&CK-mapped mitigations: M0810 Out-of-Band Communications Channel, M0930 Network Segmentation, M0807 Network Allowlists.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-attack-ics-t1695-002-ethernet",
    "title": "MITRE ATT&CK ICS T1695.002: Ethernet (ICS Tactic TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1695.002 (Ethernet) is an ICS Inhibit Response Function technique. Adversaries may block access to Ethernet communications to prevent instructions or configurations messages from reaching target systems and devices. Ethernet connections allow for communications between IT and OT systems and devices. Blocking Ethernet communications may also block command and reporting messages. An adversary may block Ethernet communications by disabling network interfaces, Service Stop, or conducting an Adversary-in-the-Middle attack and dropping the network traffic. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T1695. ATT&CK-mapped mitigations: M0930 Network Segmentation, M0810 Out-of-Band Communications Channel, M0807 Network Allowlists.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-attack-ics-t1695-003-wi-fi",
    "title": "MITRE ATT&CK ICS T1695.003: Wi-Fi (ICS Tactic TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1695.003 (Wi-Fi) is an ICS Inhibit Response Function technique. Adversaries may block access to Wi-Fi communications to prevent messages from reaching target systems and devices. Wi-Fi connections allow for communications between IT and OT systems and devices. Blocking Wi-Fi communications may also block command and reporting messages. An adversary may block Wi-Fi communications by disabling network interfaces, Service Stop, conducting an Adversary-in-the-Middle attack and dropping the network traffic, or by jamming the Wi-Fi signal. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T1695. ATT&CK-mapped mitigations: M0807 Network Allowlists, M0930 Network Segmentation, M0810 Out-of-Band Communications Channel.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-attack-ics-t1695-block-communications",
    "title": "MITRE ATT&CK ICS T1695: Block Communications (ICS Tactic TA0107 - Inhibit Response Function)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK ICS T1695 (Block Communications) is an ICS Inhibit Response Function technique. Operational technology communications occur over serial COM, Ethernet, Wi-Fi, cellular (4G/5G), and satellite mediums. Adversaries may block communications to prevent reporting messages and command messages from reaching their intended target devices disrupting processes, operations, and causing cyber-physical impacts. Adversaries may block communications by either making modifications to software (System Firmware, Module Firmware, Hooking, and Rootkit) and services (Service Stop, Denial of Service) on systems and devices or by positioning themselves between systems and devices and intercepting and blocking the communications such as the case with an Adversary-in-the-Middle attack. Affected platforms: see ATT&CK ICS. ATT&CK-mapped mitigations: M0810 Out-of-Band Communications Channel, M0930 Network Segmentation, M0807 Network Allowlists.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-attack-mobile-t1398-boot-or-logon-initialization-scripts",
    "title": "MITRE ATT&CK Mobile T1398: Boot or Logon Initialization Scripts (Mobile Tactic TA0028 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1398 (Boot or Logon Initialization Scripts) is an ATT&CK for Mobile Persistence technique. Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence. Initialization scripts are part of the underlying operating system and are not accessible to the user unless the device has been rooted or jailbroken. Affected platforms: Android, iOS. MITRE-documented mitigations include M1001 Security Updates, M1004 System Partition Integrity, M1002 Attestation, M1003 Lock Bootloader. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1404-exploitation-for-privilege-escalation",
    "title": "MITRE ATT&CK Mobile T1404: Exploitation for Privilege Escalation (Mobile Tactic TA0029 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1404 (Exploitation for Privilege Escalation) is an ATT&CK for Mobile Privilege Escalation technique. Adversaries may exploit software vulnerabilities in order to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in an application, service, within the operating system software, or kernel itself to execute adversary-controlled code. Security constructions, such as permission levels, will often hinder access to information and use of certain techniques. Affected platforms: Android, iOS. MITRE-documented mitigations include M1001 Security Updates, M1002 Attestation, M1010 Deploy Compromised Device Detection Method. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1406-001-steganography",
    "title": "MITRE ATT&CK Mobile T1406.001: Steganography (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1406.001 (Steganography) is an ATT&CK for Mobile Defense Evasion sub-technique of T1406 (Obfuscated Files or Information). Adversaries may use steganography techniques in order to prevent the detection of hidden information. Steganographic techniques can be used to hide data in digital media such as images, audio tracks, video clips, or text files. Affected platforms: Android. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1406-obfuscated-files-or-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1406-002-software-packing",
    "title": "MITRE ATT&CK Mobile T1406.002: Software Packing (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1406.002 (Software Packing) is an ATT&CK for Mobile Defense Evasion sub-technique of T1406 (Obfuscated Files or Information). Adversaries may perform software packing to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Utilities used to perform software packing are called packers. An example packer is FTT. Affected platforms: iOS, Android. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1406-obfuscated-files-or-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1406-obfuscated-files-or-information",
    "title": "MITRE ATT&CK Mobile T1406: Obfuscated Files or Information (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1406 (Obfuscated Files or Information) is an ATT&CK for Mobile Defense Evasion technique. Adversaries may attempt to make a payload or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the device or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection. ATT&CK documents 2 sub-techniques: T1406.001 Steganography; T1406.002 Software Packing. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1407-download-new-code-at-runtime",
    "title": "MITRE ATT&CK Mobile T1407: Download New Code at Runtime (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1407 (Download New Code at Runtime) is an ATT&CK for Mobile Defense Evasion technique. Adversaries may download and execute dynamic code not included in the original application package after installation. This technique is primarily used to evade static analysis checks and pre-publication scans in official app stores. In some cases, more advanced dynamic or behavioral analysis techniques could detect this behavior. However, in conjunction with Execution Guardrails techniques, detecting malicious code downloaded after installation could be difficult. Affected platforms: Android, iOS. MITRE-documented mitigations include M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1409-stored-application-data",
    "title": "MITRE ATT&CK Mobile T1409: Stored Application Data (Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1409 covers adversary access to data stored in mobile app private storage, shared storage, or cloud-backed app data. Banking trojans, infostealers (Lumma Mobile, Vidar Mobile), and commercial spyware target stored credentials, session tokens, financial data, and corporate documents. Compliance: NIST SP 800-124 Rev 2, ISO 27001 A.8.12, A.8.24, GDPR Article 32, PCI MPoC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-mobile-t1474-supply-chain-compromise",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1414-clipboard-data",
    "title": "MITRE ATT&CK Mobile T1414: Clipboard Data (Mobile Tactic TA0035 - Collection / TA0031 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1414 (Clipboard Data) is an ATT&CK for Mobile Collection and Credential Access technique. Adversaries may abuse clipboard manager APIs to obtain sensitive information copied to the device clipboard. For example, passwords being copied and pasted from a password manager application could be captured by a malicious application installed on the device. On Android, applications can use the ClipboardManager.OnPrimaryClipChangedListener() API to register as a listener and monitor the clipboard for changes. Affected platforms: Android, iOS. MITRE-documented mitigations include M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1417-001-keylogging",
    "title": "MITRE ATT&CK Mobile T1417.001: Keylogging (Mobile Tactic TA0035 - Collection / TA0031 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1417.001 (Keylogging) is an ATT&CK for Mobile Collection and Credential Access sub-technique of T1417 (Input Capture). Adversaries may log user keystrokes to intercept credentials or other information from the user as the user types them. Some methods of keylogging include: * Masquerading as a legitimate third-party keyboard to record user keystrokes. On both Android and iOS, users must explicitly authorize the use of third-party keyboard apps. Users should be advised to use extreme caution before granting this authorization when it is requested. * Abusing accessibility features. Affected platforms: Android, iOS. MITRE-documented mitigations include M1012 Enterprise Policy, M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1417-input-capture"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1417-002-gui-input-capture",
    "title": "MITRE ATT&CK Mobile T1417.002: GUI Input Capture (Mobile Tactic TA0031 - Credential Access / TA0035 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1417.002 (GUI Input Capture) is an ATT&CK for Mobile Credential Access and Collection sub-technique of T1417 (Input Capture). Adversaries may mimic common operating system GUI components to prompt users for sensitive information with a seemingly legitimate prompt. The operating system and installed applications often have legitimate needs to prompt the user for sensitive information such as account credentials, bank account information, or Personally Identifiable Information (PII). Affected platforms: Android, iOS. MITRE-documented mitigations include M1006 Use Recent OS Version, M1012 Enterprise Policy. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1417-input-capture"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1417-input-capture",
    "title": "MITRE ATT&CK Mobile T1417: Input Capture (Credential Access + Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1417 covers adversary capture of user input via keylogging, accessibility-service abuse, overlay attacks, or screenshot interception. Cerberus, BRATA, ERMAC, and Hook Android bankers abuse accessibility services to read PIN entry. iOS variants leverage AssistiveTouch and screen recording. Compliance: NIST SP 800-124 Rev 2, PCI MPoC for mobile payment, HIPAA 164.312(d), GDPR Article 32.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-mobile-t1474-supply-chain-compromise",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1418-001-security-software-discovery",
    "title": "MITRE ATT&CK Mobile T1418.001: Security Software Discovery (Mobile Tactic TA0032 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1418.001 (Security Software Discovery) is an ATT&CK for Mobile Discovery sub-technique of T1418 (Software Discovery). Adversaries may attempt to get a listing of security applications and configurations that are installed on a device. This may include things such as mobile security products. Adversaries may use the information from Security Software Discovery during automated discovery to shape follow-on behaviors, including whether or not to fully infect the target and/or attempt specific actions. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance, M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1418-software-discovery"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1418-software-discovery",
    "title": "MITRE ATT&CK Mobile T1418: Software Discovery (Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1418 covers adversary enumeration of installed applications on a mobile device to identify target apps, security tools, and exploitation opportunities. Modern Android malware (Joker, FluBot, Cerberus) and iOS spyware enumerate banking apps, MDM agents, security suites. Compliance: NIST SP 800-124 Rev 2, ISO 27001 A.8.7, A.8.16, MDM hardening guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-mobile-t1474-supply-chain-compromise",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1420-file-and-directory-discovery",
    "title": "MITRE ATT&CK Mobile T1420: File and Directory Discovery (Mobile Tactic TA0032 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1420 (File and Directory Discovery) is an ATT&CK for Mobile Discovery technique. Adversaries may enumerate files and directories or search in specific device locations for desired information within a filesystem. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including deciding if the adversary should fully infect the target and/or attempt specific actions. Affected platforms: Android, iOS. MITRE-documented mitigations include M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1421-system-network-connections-discovery",
    "title": "MITRE ATT&CK Mobile T1421: System Network Connections Discovery (Mobile Tactic TA0032 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1421 (System Network Connections Discovery) is an ATT&CK for Mobile Discovery technique. Adversaries may attempt to get a listing of network connections to or from the compromised device they are currently accessing or from remote systems by querying for information over the network. This is typically accomplished by utilizing device APIs to collect information about nearby networks, such as Wi-Fi, Bluetooth, and cellular tower connections. On Android, this can be done by querying the respective APIs: * WifiInfo for information about the current Wi-Fi connection, as well as nearby Wi-Fi networks. Affected platforms: Android. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1422-001-internet-connection-discovery",
    "title": "MITRE ATT&CK Mobile T1422.001: Internet Connection Discovery (Mobile Tactic TA0032 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1422.001 (Internet Connection Discovery) is an ATT&CK for Mobile Discovery sub-technique of T1422 (System Network Configuration Discovery). Adversaries may check for Internet connectivity on compromised systems. This may be performed during automated discovery and can be accomplished in numerous ways such as using adb shell netstat for Android. Adversaries may use the results and responses from these requests to determine if the mobile devices are capable of communicating with adversary-owned C2 servers before attempting to connect to them. The results may also be used to identify routes, redirectors, and proxy servers. Affected platforms: Android, iOS. MITRE-documented mitigations include M1009 Encrypt Network Traffic. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1422-system-network-configuration-discovery"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1422-002-wi-fi-discovery",
    "title": "MITRE ATT&CK Mobile T1422.002: Wi-Fi Discovery (Mobile Tactic TA0032 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1422.002 (Wi-Fi Discovery) is an ATT&CK for Mobile Discovery sub-technique of T1422 (System Network Configuration Discovery). Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems. Adversaries may use Wi-Fi information as part of Discovery or Credential Access activity to support both ongoing and future campaigns. Affected platforms: Android, iOS. MITRE-documented mitigations include M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1422-system-network-configuration-discovery"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1422-system-network-configuration-discovery",
    "title": "MITRE ATT&CK Mobile T1422: System Network Configuration Discovery (Mobile Tactic TA0032 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1422 (System Network Configuration Discovery) is an ATT&CK for Mobile Discovery technique. Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of devices they access or through information discovery of remote systems. Adversaries may use the information from System Network Configuration Discovery during automated discovery to shape follow-on behaviors, including determining certain access within the target network and what actions to do next. ATT&CK documents 2 sub-techniques: T1422.001 Internet Connection Discovery; T1422.002 Wi-Fi Discovery. Affected platforms: Android, iOS. MITRE-documented mitigations include M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1423-network-service-scanning",
    "title": "MITRE ATT&CK Mobile T1423: Network Service Scanning (Mobile Tactic TA0032 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1423 (Network Service Scanning) is an ATT&CK for Mobile Discovery technique. Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation. Methods to acquire this information include port scans and vulnerability scans from the mobile device. This technique may take advantage of the mobile device's access to an internal enterprise network either through local connectivity or through a Virtual Private Network (VPN). Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1424-process-discovery",
    "title": "MITRE ATT&CK Mobile T1424: Process Discovery (Mobile Tactic TA0032 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1424 (Process Discovery) is an ATT&CK for Mobile Discovery technique. Adversaries may attempt to get information about running processes on a device. Information obtained could be used to gain an understanding of common software/applications running on devices within a network. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Affected platforms: Android, iOS. MITRE-documented mitigations include M1006 Use Recent OS Version, M1002 Attestation. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1426-system-information-discovery",
    "title": "MITRE ATT&CK Mobile T1426: System Information Discovery (Mobile Tactic TA0032 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1426 (System Information Discovery) is an ATT&CK for Mobile Discovery technique. Adversaries may attempt to get detailed information about a device's operating system and hardware, including versions, patches, and architecture. Adversaries may use the information from System Information Discovery during automated discovery to shape follow-on behaviors, including whether or not to fully infects the target and/or attempts specific actions. On Android, much of this information is programmatically accessible to applications through the android.os.Build class. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1428-exploitation-of-remote-services",
    "title": "MITRE ATT&CK Mobile T1428: Exploitation of Remote Services (Mobile Tactic TA0033 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1428 (Exploitation of Remote Services) is an ATT&CK for Mobile Lateral Movement technique. Adversaries may exploit remote services of enterprise servers, workstations, or other resources to gain unauthorized access to internal systems once inside of a network. Adversaries may exploit remote services by taking advantage of a mobile device's access to an internal enterprise network through local connectivity or through a Virtual Private Network (VPN). Affected platforms: Android, iOS. MITRE-documented mitigations include M1012 Enterprise Policy. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1429-audio-capture",
    "title": "MITRE ATT&CK Mobile T1429: Audio Capture (Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1429 covers adversary capture of audio via the device microphone for surveillance. Pegasus, Predator, FinSpy, ToothPicker all include mic-capture capability. Modern Android variants abuse foreground-service to record continuously. Compliance: NIST SP 800-124 Rev 2, GDPR Article 9 (biometric data may apply to voice), CCPA, ePrivacy Directive, FCC Section 222.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-mobile-t1474-supply-chain-compromise",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1430-001-remote-device-management-services",
    "title": "MITRE ATT&CK Mobile T1430.001: Remote Device Management Services (Mobile Tactic TA0035 - Collection / TA0032 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1430.001 (Remote Device Management Services) is an ATT&CK for Mobile Collection and Discovery sub-technique of T1430 (Location Tracking). An adversary may use access to cloud services (e.g. Google's Android Device Manager or Apple iCloud's Find my iPhone) or to an enterprise mobility management (EMM)/mobile device management (MDM) server console to track the location of mobile devices managed by the service. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance, M1012 Enterprise Policy. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1430-location-tracking"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1430-002-impersonate-ss7-nodes",
    "title": "MITRE ATT&CK Mobile T1430.002: Impersonate SS7 Nodes (Mobile Tactic TA0035 - Collection / TA0032 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1430.002 (Impersonate SS7 Nodes) is an ATT&CK for Mobile Collection and Discovery sub-technique of T1430 (Location Tracking). Adversaries may exploit the lack of authentication in signaling system network nodes to track the to track the location of mobile devices by impersonating a node. By providing the victim's MSISDN (phone number) and impersonating network internal nodes to query subscriber information from other nodes, adversaries may use data collected from each hop to eventually determine the device's geographical cell area or nearest cell tower. Affected platforms: Android, iOS. MITRE-documented mitigations include M1014 Interconnection Filtering. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1430-location-tracking"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1430-location-tracking",
    "title": "MITRE ATT&CK Mobile T1430: Location Tracking (Discovery + Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1430 covers adversary access to a victim devices geolocation - GPS, cellular tower triangulation, Wi-Fi positioning, IP geolocation. Pegasus, Predator, FinSpy, and most commercial spyware exfiltrate location data continuously. Compliance: NIST SP 800-124 Rev 2 (Mobile Device Security), GDPR Articles 5/9 (location data is personal data), ISO 27001 A.8.1, A.5.34, CCPA/CPRA, ePrivacy Directive, FCC Section 222 CPNI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-mobile-t1474-supply-chain-compromise",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1437-001-web-protocols",
    "title": "MITRE ATT&CK Mobile T1437.001: Web Protocols (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1437.001 (Web Protocols) is an ATT&CK for Mobile Command and Control sub-technique of T1437 (Application Layer Protocol). Adversaries may communicate using application layer protocols associated with web protocols traffic to avoid detection/network filtering by blending in with existing traffic. Commands to remote mobile devices, and often the results of those commands, will be embedded within the protocol traffic between the mobile client and server. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1437-application-layer-protocol"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1437-application-layer-protocol",
    "title": "MITRE ATT&CK Mobile T1437: Application Layer Protocol (Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1437 covers adversary use of standard application-layer protocols (HTTP, HTTPS, DNS, mail, messaging) for command-and-control communication blending malicious traffic with legitimate enterprise SaaS use. Mobile C2 increasingly leverages legitimate cloud services (Firebase Cloud Messaging, AWS SNS, Telegram, Discord) for resilience. Sibling of T1521 Encrypted Channel. Compliance: NIST SP 800-124 Rev 2, NIST SP 800-53 SI-4, ISO 27001 A.8.20, NIS2 Article 21(2)(b).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-mobile-t1474-supply-chain-compromise",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1451-sim-card-swap",
    "title": "MITRE ATT&CK Mobile T1451: SIM Card Swap (Mobile Tactic TA0027 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK Mobile T1451 (SIM Card Swap) is an Mobile Initial Access technique. Adversaries may gain access to mobile devices through transfers or swaps from victims’ phone numbers to adversary-controlled SIM cards and mobile devices. The typical process is as follows: 1. Adversaries will first gather information about victims through Phishing, social engineering, data breaches, or other avenues. 2. Adversaries will then impersonate victims as they contact mobile carriers to request for the SIM swaps. For example, adversaries would provide victims’ name and address to mobile carriers; once authenticated, adversaries would request for victims’ phone numbers to be transferred to adversary-controlled SIM cards. 3. Once completed, victims will lose mobile data, such as text messages and phone calls, on their mobile devices. In turn, adversaries will receive mobile data th... Affected platforms: Android, iOS. ATT&CK-mapped mitigations: M1012 Enterprise Policy, M1011 User Guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-mobile-t1453-abuse-accessibility-features",
    "title": "MITRE ATT&CK Mobile T1453: Abuse Accessibility Features (Mobile Tactic TA0035 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK Mobile T1453 (Abuse Accessibility Features) is an Mobile Collection, Credential Access technique. Adversaries may abuse accessibility features in Android devices to steal sensitive data and to spread malware to other devices. Accessibility features in Android are designed to assist users with disabilities, performing a variety of tasks, such as using Action Blocks to control lightbulbs, and changing the device’s user interface, such as changing the font size and adjusting contract or colors. One example of how adversaries abuse accessibility features is overlaying an HTML object mimicking a legitimate login screen. The user types their credentials in the overlay HTML object, which is then sent to the adversaries. Another example is a malicious accessibility feature acting as a keylogger. The keylogger monitors changes on the EditText fields and sends it to the adversaries. This method ... Affected platforms: Android. ATT&CK-mapped mitigations: M1011 User Guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-mobile-t1456-drive-by-compromise",
    "title": "MITRE ATT&CK Mobile T1456: Drive-by Compromise (Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1456 covers adversary exploitation of victim browsers and WebViews via malicious web content to gain initial mobile access. Mobile browser zero-days (Operation Triangulation 2023, NSO Group exploits) and malicious WebView abuse in mobile apps are dominant vectors. Compliance: NIST SP 800-124 Rev 2, ISO 27001 A.8.7, A.8.23, NIS2 Article 21(2)(b).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-mobile-t1474-supply-chain-compromise",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1458-replication-through-removable-media",
    "title": "MITRE ATT&CK Mobile T1458: Replication Through Removable Media (Mobile Tactic TA0027 - Initial Access / TA0033 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1458 (Replication Through Removable Media) is an ATT&CK for Mobile Initial Access and Lateral Movement technique. Adversaries may move onto devices by exploiting or copying malware to devices connected via USB. In the case of Lateral Movement, adversaries may utilize the physical connection of a device to a compromised or malicious charging station or PC to bypass application store requirements and install malicious applications directly. In the case of Initial Access, adversaries may attempt to exploit the device via the connection to gain access to data stored on the device. Affected platforms: Android, iOS. MITRE-documented mitigations include M1003 Lock Bootloader, M1006 Use Recent OS Version, M1011 User Guidance, M1012 Enterprise Policy, M1001 Security Updates. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1461-lockscreen-bypass",
    "title": "MITRE ATT&CK Mobile T1461: Lockscreen Bypass (Mobile Tactic TA0027 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1461 (Lockscreen Bypass) is an ATT&CK for Mobile Initial Access technique. An adversary with physical access to a mobile device may seek to bypass the device's lockscreen. Several methods exist to accomplish this, including: * Biometric spoofing: If biometric authentication is used, an adversary could attempt to spoof a mobile device's biometric authentication mechanism. Both iOS and Android partly mitigate this attack by requiring the device's passcode rather than biometrics to unlock the device after every device restart, and after a set or random amount of time. Affected platforms: Android, iOS. MITRE-documented mitigations include M1012 Enterprise Policy, M1001 Security Updates. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1464-network-denial-of-service",
    "title": "MITRE ATT&CK Mobile T1464: Network Denial of Service (Mobile Tactic TA0034 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1464 (Network Denial of Service) is an ATT&CK for Mobile Impact technique. Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth that services rely on, or by jamming the signal going to or coming from devices. A Network DoS will occur when an adversary is able to jam radio signals (e.g. Wi-Fi, cellular, GPS) around a device to prevent it from communicating. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1471-data-encrypted-for-impact",
    "title": "MITRE ATT&CK Mobile T1471: Data Encrypted for Impact (Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1471 covers mobile-specific ransomware that encrypts user data and demands payment. Notable mobile ransomware families include Charger, Lockerpin, DoubleLocker, Filecoder.C, and SLocker. Mobile ransomware impact extends beyond personal devices into hospital tablet fleets, retail point-of-sale handhelds, and field-service mobile devices. Compliance obligations include NIST SP 800-124 Rev 2, NIST SP 800-53 CP-9, CP-10, ISO 27001 A.8.13, A.8.14, A.5.29, HIPAA Security Rule 164.308(a)(7) extended to mobile, and CISA #StopRansomware Guide mobile considerations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1486-data-encrypted-for-impact",
      "mitre-attack-mobile-t1474-supply-chain-compromise",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "mitre-d3fend-d3-ro-restore-object"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-mobile-t1474-001-compromise-software-dependencies-and-development-tools",
    "title": "MITRE ATT&CK Mobile T1474.001: Compromise Software Dependencies and Development Tools (Mobile Tactic TA0027 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1474.001 (Compromise Software Dependencies and Development Tools) is an ATT&CK for Mobile Initial Access sub-technique of T1474 (Supply Chain Compromise). Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications may be targeted as a means to add malicious code to users of the dependency. Affected platforms: Android, iOS. MITRE-documented mitigations include M1013 Application Developer Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1474-supply-chain-compromise"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1474-002-compromise-hardware-supply-chain",
    "title": "MITRE ATT&CK Mobile T1474.002: Compromise Hardware Supply Chain (Mobile Tactic TA0027 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1474.002 (Compromise Hardware Supply Chain) is an ATT&CK for Mobile Initial Access sub-technique of T1474 (Supply Chain Compromise). Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise. By modifying hardware or firmware in the supply chain, adversaries can insert a backdoor into consumer networks that may be difficult to detect and give the adversary a high degree of control over the system. Affected platforms: Android, iOS. MITRE-documented mitigations include M1001 Security Updates. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1474-supply-chain-compromise"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1474-003-compromise-software-supply-chain",
    "title": "MITRE ATT&CK Mobile T1474.003: Compromise Software Supply Chain (Mobile Tactic TA0027 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1474.003 (Compromise Software Supply Chain) is an ATT&CK for Mobile Initial Access sub-technique of T1474 (Supply Chain Compromise). Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version. Affected platforms: Android, iOS. MITRE-documented mitigations include M1004 System Partition Integrity, M1001 Security Updates. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1474-supply-chain-compromise"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1474-supply-chain-compromise",
    "title": "MITRE ATT&CK Mobile T1474: Supply Chain Compromise (Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1474 covers adversary compromise of mobile applications through the software supply chain - malicious code injected into Google Play / Apple App Store apps, sideloaded APK distribution, third-party SDK compromise, and tampered firmware. Pegasus (NSO Group), Predator (Intellexa), and the 2023 3CX desktop-mobile supply chain compromise are notable examples. Compliance obligations include NIST SP 800-124 Rev 2 (Mobile Device Security), NIST SP 800-218 (SSDF), ISO 27001 A.5.20-A.5.23, FDA Pre-Market Cybersecurity Guidance for medical mobile apps, HIPAA Security Rule mobile risk analysis, and EU Cyber Resilience Act for mobile components.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1583-acquire-infrastructure",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-mobile-t1481-001-dead-drop-resolver",
    "title": "MITRE ATT&CK Mobile T1481.001: Dead Drop Resolver (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1481.001 (Dead Drop Resolver) is an ATT&CK for Mobile Command and Control sub-technique of T1481 (Web Service). Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers. Popular websites and social media, acting as a mechanism for C2, may give a significant amount of cover. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1481-web-service"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1481-002-bidirectional-communication",
    "title": "MITRE ATT&CK Mobile T1481.002: Bidirectional Communication (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1481.002 (Bidirectional Communication) is an ATT&CK for Mobile Command and Control sub-technique of T1481 (Web Service). Adversaries may use an existing, legitimate external Web service channel as a means for sending commands to and receiving output from a compromised system. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1481-web-service"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1481-003-one-way-communication",
    "title": "MITRE ATT&CK Mobile T1481.003: One-Way Communication (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1481.003 (One-Way Communication) is an ATT&CK for Mobile Command and Control sub-technique of T1481 (Web Service). Adversaries may use an existing, legitimate external Web service channel as a means for sending commands to a compromised system without receiving return output. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems may opt to send the output from those commands back over a different C2 channel, including to another distinct Web service. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1481-web-service"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1481-web-service",
    "title": "MITRE ATT&CK Mobile T1481: Web Service (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1481 (Web Service) is an ATT&CK for Mobile Command and Control technique. Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites and social media, acting as a mechanism for C2, may give a significant amount of cover. This is due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. ATT&CK documents 3 sub-techniques: T1481.001 Dead Drop Resolver; T1481.002 Bidirectional Communication; T1481.003 One-Way Communication. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1509-non-standard-port",
    "title": "MITRE ATT&CK Mobile T1509: Non-Standard Port (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1509 (Non-Standard Port) is an ATT&CK for Mobile Command and Control technique. Adversaries may generate network traffic using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088 or port 587 as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1512-video-capture",
    "title": "MITRE ATT&CK Mobile T1512: Video Capture (Mobile Tactic TA0035 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1512 (Video Capture) is an ATT&CK for Mobile Collection technique. An adversary can leverage a device's cameras to gather information by capturing video recordings. Images may also be captured, potentially in specified intervals, in lieu of video files. Malware or scripts may interact with the device cameras through an available API provided by the operating system. Video or image files may be written to disk and exfiltrated later. This technique differs from Screen Capture due to use of the device's cameras for video recording rather than capturing the victim's screen. Affected platforms: Android, iOS. MITRE-documented mitigations include M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1513-screen-capture",
    "title": "MITRE ATT&CK Mobile T1513: Screen Capture (Mobile Tactic TA0035 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1513 (Screen Capture) is an ATT&CK for Mobile Collection technique. Adversaries may use screen capture to collect additional information about a target device, such as applications running in the foreground, user data, credentials, or other sensitive information. Applications running in the background can capture screenshots or videos of another application running in the foreground by using the Android MediaProjectionManager (generally requires the device user to grant consent). Affected platforms: Android. MITRE-documented mitigations include M1012 Enterprise Policy, M1011 User Guidance, M1013 Application Developer Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1516-input-injection",
    "title": "MITRE ATT&CK Mobile T1516: Input Injection (Mobile Tactic TA0030 - Defense Evasion / TA0034 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1516 (Input Injection) is an ATT&CK for Mobile Defense Evasion and Impact technique. A malicious application can inject input to the user interface to mimic user interaction through the abuse of Android's accessibility APIs. Input Injection can be achieved using any of the following methods: * Mimicking user clicks on the screen, for example to steal money from a user's PayPal account. * Injecting global actions, such as GLOBAL_ACTION_BACK (programatically mimicking a physical back button press), to trigger actions on behalf of the user. * Inserting input into text fields on behalf of the user. Affected platforms: Android. MITRE-documented mitigations include M1011 User Guidance, M1012 Enterprise Policy. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1517-access-notifications",
    "title": "MITRE ATT&CK Mobile T1517: Access Notifications (Mobile Tactic TA0035 - Collection / TA0031 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1517 (Access Notifications) is an ATT&CK for Mobile Collection and Credential Access technique. Adversaries may collect data within notifications sent by the operating system or other applications. Notifications may contain sensitive data such as one-time authentication codes sent over SMS, email, or other mediums. In the case of Credential Access, adversaries may attempt to intercept one-time code sent to the device. Adversaries can also dismiss notifications to prevent the user from noticing that the notification has arrived and can trigger action buttons contained within notifications. Affected platforms: Android. MITRE-documented mitigations include M1011 User Guidance, M1013 Application Developer Guidance, M1012 Enterprise Policy. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1521-001-symmetric-cryptography",
    "title": "MITRE ATT&CK Mobile T1521.001: Symmetric Cryptography (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1521.001 (Symmetric Cryptography) is an ATT&CK for Mobile Command and Control sub-technique of T1521 (Encrypted Channel). Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, Blowfish, and RC4. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1521-encrypted-channel"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1521-002-asymmetric-cryptography",
    "title": "MITRE ATT&CK Mobile T1521.002: Asymmetric Cryptography (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1521.002 (Asymmetric Cryptography) is an ATT&CK for Mobile Command and Control sub-technique of T1521 (Encrypted Channel). Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol. Asymmetric cryptography, also known as public key cryptography, uses a keypair per party: one public that can be freely distributed, and one private that should not be distributed. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1521-encrypted-channel"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1521-003-ssl-pinning",
    "title": "MITRE ATT&CK Mobile T1521.003: SSL Pinning (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1521.003 (SSL Pinning) is an ATT&CK for Mobile Command and Control sub-technique of T1521 (Encrypted Channel). Adversaries may use SSL Pinning to protect the C2 traffic from being intercepted and analyzed. SSL Pinning is a technique commonly utilized by legitimate websites to ensure that encrypted communications are only allowed with a pre-defined certificate. If another certificate is presented, it could indicate device compromise, traffic interception, or another upstream issue. While benign usages are common, it is also possible for adversaries to abuse this technology to protect malicious C2 traffic. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance, M1012 Enterprise Policy. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1521-encrypted-channel"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1521-encrypted-channel",
    "title": "MITRE ATT&CK Mobile T1521: Encrypted Channel (Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1521 covers adversary use of TLS, symmetric, or asymmetric encrypted channels for mobile command-and-control communication. Pegasus, Predator, FinSpy, BRATA Android banker, and most modern mobile commercial spyware use encrypted C2 to evade network inspection. Compliance obligations include NIST SP 800-53 SC-7 (Boundary Protection), SI-4 (System Monitoring), NIST SP 800-124 Rev 2, ISO 27001 A.8.20, A.8.21, A.8.16, NIS2 Article 21(2)(b), PCI MPoC for mobile payment, and HIPAA Security Rule mobile transmission security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1071-application-layer-protocol",
      "mitre-attack-t1041-exfiltration-over-c2-channel",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "mitre-attack-mobile-t1474-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-mobile-t1532-archive-collected-data",
    "title": "MITRE ATT&CK Mobile T1532: Archive Collected Data (Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1532 covers adversary archiving and compression of collected data on a mobile device before exfiltration to reduce transfer size and evade detection. Pegasus, Predator, and most modern mobile spyware compress stolen data into ZIP, TAR, or proprietary formats before exfiltration. Compliance: NIST SP 800-124 Rev 2, ISO 27001 A.8.12, A.8.16, GDPR Article 32-33 for breach notification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-mobile-t1474-supply-chain-compromise",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1533-data-from-local-system",
    "title": "MITRE ATT&CK Mobile T1533: Data from Local System (Mobile Tactic TA0035 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1533 (Data from Local System) is an ATT&CK for Mobile Collection technique. Adversaries may search local system sources, such as file systems or local databases, to find files of interest and sensitive data prior to exfiltration. Access to local system data, which includes information stored by the operating system, often requires escalated privileges. Examples of local system data include authentication tokens, the device keyboard cache, Wi-Fi passwords, and photos. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1541-foreground-persistence",
    "title": "MITRE ATT&CK Mobile T1541: Foreground Persistence (Mobile Tactic TA0030 - Defense Evasion / TA0028 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1541 (Foreground Persistence) is an ATT&CK for Mobile Defense Evasion and Persistence technique. Adversaries may abuse Android's startForeground() API method to maintain continuous sensor access. Beginning in Android 9, idle applications running in the background no longer have access to device sensors, such as the camera, microphone, and gyroscope. Applications can retain sensor access by running in the foreground, using Android's startForeground() API method. This informs the system that the user is actively interacting with the application, and it should not be killed. Affected platforms: Android. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1544-ingress-tool-transfer",
    "title": "MITRE ATT&CK Mobile T1544: Ingress Tool Transfer (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1544 (Ingress Tool Transfer) is an ATT&CK for Mobile Command and Control technique. Adversaries may transfer tools or other files from an external system onto a compromised device to facilitate follow-on actions. Files may be copied from an external adversary-controlled system through the command and control channel or through alternate protocols with another tool such as FTP. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1575-native-api",
    "title": "MITRE ATT&CK Mobile T1575: Native API (Mobile Tactic TA0030 - Defense Evasion / TA0041 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1575 (Native API) is an ATT&CK for Mobile Defense Evasion and Execution technique. Adversaries may use Android's Native Development Kit (NDK) to write native functions that can achieve execution of binaries or functions. Like system calls on a traditional desktop operating system, native code achieves execution on a lower level than normal Android SDK calls. The NDK allows developers to write native code in C or C++ that is compiled directly to machine code, avoiding all intermediate languages and steps in compilation that higher level languages, like Java, typically have. Affected platforms: Android. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1577-compromise-application-executable",
    "title": "MITRE ATT&CK Mobile T1577: Compromise Application Executable (Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1577 covers adversary modification of legitimate mobile application binaries to add malicious code while preserving original functionality. Re-signed APKs distributed via sideloading, third-party app stores, and supply-chain compromise are the dominant vectors. Compliance: NIST SP 800-124 Rev 2, NIST SP 800-218 SSDF, ISO 27001 A.8.7, A.8.32, A.8.25, OWASP MASVS V8, FDA Cybersecurity for mobile medical apps.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-mobile-t1474-supply-chain-compromise",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1582-sms-control",
    "title": "MITRE ATT&CK Mobile T1582: SMS Control (Impact + Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1582 covers adversary control over the SMS subsystem to intercept, send, or delete messages on a mobile device. Common with banking trojans (Cerberus, Anubis, FluBot) that intercept OTP codes for fraud. Compliance: NIST SP 800-124 Rev 2, PCI MPoC for mobile payment, HIPAA when SMS used for medical 2FA, FCC Section 222 CPNI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-mobile-t1474-supply-chain-compromise",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1603-scheduled-task-job",
    "title": "MITRE ATT&CK Mobile T1603: Scheduled Task/Job (Mobile Tactic TA0041 - Execution / TA0028 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1603 (Scheduled Task/Job) is an ATT&CK for Mobile Execution and Persistence technique. Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. On Android and iOS, APIs and libraries exist to facilitate scheduling tasks to execute at a specified date, time, or interval. On Android, the WorkManager API allows asynchronous tasks to be scheduled with the system. WorkManager was introduced to unify task scheduling on Android, using JobScheduler, GcmNetworkManager, and AlarmManager internally. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1604-proxy-through-victim",
    "title": "MITRE ATT&CK Mobile T1604: Proxy Through Victim (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1604 (Proxy Through Victim) is an ATT&CK for Mobile Defense Evasion technique. Adversaries may use a compromised device as a proxy server to the Internet. By utilizing a proxy, adversaries hide the true IP address of their C2 server and associated infrastructure from the destination of the network traffic. This masquerades an adversary's traffic as legitimate traffic originating from the compromised device, which can evade IP-based restrictions and alerts on certain services, such as bank accounts and social media websites. The most common type of proxy is a SOCKS proxy. Affected platforms: Android. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1616-call-control",
    "title": "MITRE ATT&CK Mobile T1616: Call Control (Mobile Tactic TA0035 - Collection / TA0034 - Impact / TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1616 (Call Control) is an ATT&CK for Mobile Collection and Impact and Command and Control technique. Adversaries may make, forward, or block phone calls without user authorization. This could be used for adversary goals such as audio surveillance, blocking or forwarding calls from the device owner, or C2 communication. Several permissions may be used to programmatically control phone calls, including: * ANSWER_PHONE_CALLS - Allows the application to answer incoming phone calls * CALL_PHONE - Allows the application to initiate a phone call without going through the Dialer interface * PROCESS_OUTGOING_CALLS -. Affected platforms: Android. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1617-hooking",
    "title": "MITRE ATT&CK Mobile T1617: Hooking (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1617 (Hooking) is an ATT&CK for Mobile Defense Evasion technique. Adversaries may utilize hooking to hide the presence of artifacts associated with their behaviors to evade detection. Hooking can be used to modify return values or data structures of system APIs and function calls. This process typically involves using 3rd party root frameworks, such as Xposed or Magisk, with either a system exploit or pre-existing root access. Affected platforms: Android. MITRE-documented mitigations include M1002 Attestation, M1010 Deploy Compromised Device Detection Method. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1623-001-unix-shell",
    "title": "MITRE ATT&CK Mobile T1623.001: Unix Shell (Mobile Tactic TA0041 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1623.001 (Unix Shell) is an ATT&CK for Mobile Execution sub-technique of T1623 (Command and Scripting Interpreter). Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the underlying command prompts on Android and iOS devices. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges that are only accessible if the device has been rooted or jailbroken. Unix shells also support scripts that enable sequential execution of commands as well as other typical programming operations such as conditionals and loops. Affected platforms: Android, iOS. MITRE-documented mitigations include M1002 Attestation, M1010 Deploy Compromised Device Detection Method. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1623-command-and-scripting-interpreter"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1623-command-and-scripting-interpreter",
    "title": "MITRE ATT&CK Mobile T1623: Command and Scripting Interpreter (Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1623 covers adversary use of mobile-native command interpreters and scripting environments (Unix Shell on rooted Android, JavaScript injection in WebView, mobile remote-management tools) to execute malicious code. Pegasus, Predator, and most commercial mobile spyware execute scripts post-compromise. Compliance: NIST SP 800-124 Rev 2, ISO 27001 A.8.7, A.8.16, A.8.19, NIS2 Article 21(2)(b).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-mobile-t1474-supply-chain-compromise",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1624-001-broadcast-receivers",
    "title": "MITRE ATT&CK Mobile T1624.001: Broadcast Receivers (Mobile Tactic TA0028 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1624.001 (Broadcast Receivers) is an ATT&CK for Mobile Persistence sub-technique of T1624 (Event Triggered Execution). Adversaries may establish persistence using system mechanisms that trigger execution based on specific events. Mobile operating systems have means to subscribe to events such as receiving an SMS message, device boot completion, or other device activities. An intent is a message passed between Android applications or system components. Affected platforms: Android. MITRE-documented mitigations include M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1624-event-triggered-execution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1624-event-triggered-execution",
    "title": "MITRE ATT&CK Mobile T1624: Event Triggered Execution (Mobile Tactic TA0028 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1624 (Event Triggered Execution) is an ATT&CK for Mobile Persistence technique. Adversaries may establish persistence using system mechanisms that trigger execution based on specific events. Mobile operating systems have means to subscribe to events such as receiving an SMS message, device boot completion, or other device activities. Adversaries may abuse these mechanisms as a means of maintaining persistent access to a victim via automatically and repeatedly executing malicious code. ATT&CK documents 1 sub-technique: T1624.001 Broadcast Receivers. Affected platforms: Android. MITRE-documented mitigations include M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1625-001-system-runtime-api-hijacking",
    "title": "MITRE ATT&CK Mobile T1625.001: System Runtime API Hijacking (Mobile Tactic TA0028 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1625.001 (System Runtime API Hijacking) is an ATT&CK for Mobile Persistence sub-technique of T1625 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the way an operating system runs applications. Hijacking execution flow can be for the purposes of persistence since this hijacked execution may reoccur at later points in time. On Android, adversaries may overwrite the standard OS API library with a malicious alternative to hook into core functions to achieve persistence. Affected platforms: Android. MITRE-documented mitigations include M1002 Attestation, M1004 System Partition Integrity. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1625-hijack-execution-flow"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1625-hijack-execution-flow",
    "title": "MITRE ATT&CK Mobile T1625: Hijack Execution Flow (Mobile Tactic TA0028 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1625 (Hijack Execution Flow) is an ATT&CK for Mobile Persistence technique. Adversaries may execute their own malicious payloads by hijacking the way operating systems run applications. Hijacking execution flow can be for the purposes of persistence since this hijacked execution may reoccur over time. There are many ways an adversary may hijack the flow of execution. A primary way is by manipulating how the operating system locates programs to be executed. How the operating system locates libraries to be used by a program can also be intercepted. ATT&CK documents 1 sub-technique: T1625.001 System Runtime API Hijacking. Affected platforms: Android. MITRE-documented mitigations include M1004 System Partition Integrity, M1002 Attestation. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1626-001-device-administrator-permissions",
    "title": "MITRE ATT&CK Mobile T1626.001: Device Administrator Permissions (Mobile Tactic TA0029 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1626.001 (Device Administrator Permissions) is an ATT&CK for Mobile Privilege Escalation sub-technique of T1626 (Abuse Elevation Control Mechanism). Adversaries may abuse Android's device administration API to obtain a higher degree of control over the device. By abusing the API, adversaries can perform several nefarious actions, such as resetting the device's password for Endpoint Denial of Service, factory resetting the device for File Deletion and to delete any traces of the malware, disabling all the device's cameras, or to make it more difficult to uninstall the app. Affected platforms: Android. MITRE-documented mitigations include M1006 Use Recent OS Version, M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1626-abuse-elevation-control-mechanism"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1626-abuse-elevation-control-mechanism",
    "title": "MITRE ATT&CK Mobile T1626: Abuse Elevation Control Mechanism (Privilege Escalation + Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK Mobile T1626 covers adversary bypass of OS permission controls to gain elevated privileges. Includes root-jailbreak exploitation (CheckRain, unc0ver, Magisk-based) and Device Administration API abuse on Android. Modern attacks chain accessibility-permission abuse with overlay tactics. Compliance: NIST SP 800-124 Rev 2, ISO 27001 A.8.2, A.8.7, NIS2 Article 21(2)(j).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-mobile-t1474-supply-chain-compromise",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1627-001-geofencing",
    "title": "MITRE ATT&CK Mobile T1627.001: Geofencing (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1627.001 (Geofencing) is an ATT&CK for Mobile Defense Evasion sub-technique of T1627 (Execution Guardrails). Adversaries may use a device's geographical location to limit certain malicious behaviors. For example, malware operators may limit the distribution of a second stage payload to certain geographic regions. Geofencing is accomplished by persuading the user to grant the application permission to access location services. The application can then collect, process, and exfiltrate the device's location to perform location-based actions, such as ceasing malicious behavior or showing region-specific advertisements. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance, M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1627-execution-guardrails"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1627-execution-guardrails",
    "title": "MITRE ATT&CK Mobile T1627: Execution Guardrails (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1627 (Execution Guardrails) is an ATT&CK for Mobile Defense Evasion technique. Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target. Guardrails ensure that a payload only executes against an intended target and reduces collateral damage from an adversary's campaign. Values an adversary can provide about a target system or environment to use as guardrails may include environment information such as location. ATT&CK documents 1 sub-technique: T1627.001 Geofencing. Affected platforms: Android, iOS. MITRE-documented mitigations include M1006 Use Recent OS Version, M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1628-001-suppress-application-icon",
    "title": "MITRE ATT&CK Mobile T1628.001: Suppress Application Icon (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1628.001 (Suppress Application Icon) is an ATT&CK for Mobile Defense Evasion sub-technique of T1628 (Hide Artifacts). A malicious application could suppress its icon from being displayed to the user in the application launcher. This hides the fact that it is installed, and can make it more difficult for the user to uninstall the application. Hiding the application's icon programmatically does not require any special permissions. This behavior has been seen in the BankBot/Spy Banker family of malware. Beginning in Android 10, changes were introduced to inhibit malicious applications' ability to hide their icon. Affected platforms: Android. MITRE-documented mitigations include M1006 Use Recent OS Version, M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1628-hide-artifacts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1628-002-user-evasion",
    "title": "MITRE ATT&CK Mobile T1628.002: User Evasion (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1628.002 (User Evasion) is an ATT&CK for Mobile Defense Evasion sub-technique of T1628 (Hide Artifacts). Adversaries may attempt to avoid detection by hiding malicious behavior from the user. By doing this, an adversary's modifications would most likely remain installed on the device for longer, allowing the adversary to continue to operate on that device. While there are many ways this can be accomplished, one method is by using the device's sensors. By utilizing the various motion sensors on a device, such as accelerometer or gyroscope, an application could detect that the device is being interacted with. Affected platforms: Android. MITRE-documented mitigations include M1010 Deploy Compromised Device Detection Method. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1628-hide-artifacts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1628-003-conceal-multimedia-files",
    "title": "MITRE ATT&CK Mobile T1628.003: Conceal Multimedia Files (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1628.003 (Conceal Multimedia Files) is an ATT&CK for Mobile Defense Evasion sub-technique of T1628 (Hide Artifacts). Adversaries may attempt to hide multimedia files from the user. By doing so, adversaries may conceal captured files, such as pictures, videos and/or screenshots, then later exfiltrate those files. Specific to Android devices, if the .nomedia file is present in a folder, multimedia files in that folder will not be visible to the user in the Gallery application. Additionally, other applications are asked not to scan the folder with the .nomedia file, effectively making the folder appear invisible to the user. Affected platforms: Android. MITRE-documented mitigations include M1059 Do Not Mitigate. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1628-hide-artifacts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1628-hide-artifacts",
    "title": "MITRE ATT&CK Mobile T1628: Hide Artifacts (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1628 (Hide Artifacts) is an ATT&CK for Mobile Defense Evasion technique. Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Mobile operating systems have features and developer APIs to hide various artifacts, such as an application's launcher icon. These APIs have legitimate usages, such as hiding an icon to avoid application drawer clutter when an application does not have a usable interface. Adversaries may abuse these features and APIs to hide artifacts from the user to evade detection. ATT&CK documents 3 sub-techniques: T1628.001 Suppress Application Icon; T1628.002 User Evasion; T1628.003 Conceal Multimedia Files. Affected platforms: Android. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1629-001-prevent-application-removal",
    "title": "MITRE ATT&CK Mobile T1629.001: Prevent Application Removal (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1629.001 (Prevent Application Removal) is an ATT&CK for Mobile Defense Evasion sub-technique of T1629 (Impair Defenses). Adversaries may abuse the Android device administration API to prevent the user from uninstalling a target application. In earlier versions of Android, device administrator applications needed their administration capabilities explicitly deactivated by the user before the application could be uninstalled. This was later updated so the user could deactivate and uninstall the administrator application in one step. Adversaries may also abuse the device accessibility APIs to prevent removal. Affected platforms: Android. MITRE-documented mitigations include M1006 Use Recent OS Version, M1011 User Guidance, M1012 Enterprise Policy. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1629-impair-defenses"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1629-002-device-lockout",
    "title": "MITRE ATT&CK Mobile T1629.002: Device Lockout (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1629.002 (Device Lockout) is an ATT&CK for Mobile Defense Evasion sub-technique of T1629 (Impair Defenses). An adversary may seek to inhibit user interaction by locking the legitimate user out of the device. This is typically accomplished by requesting device administrator permissions and then locking the screen using DevicePolicyManager.lockNow(). Other novel techniques for locking the user out of the device have been observed, such as showing a persistent overlay, using carefully crafted \"call\" notification screens, and locking HTML pages in the foreground. Affected platforms: Android. MITRE-documented mitigations include M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1629-impair-defenses"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1629-003-disable-or-modify-tools",
    "title": "MITRE ATT&CK Mobile T1629.003: Disable or Modify Tools (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1629.003 (Disable or Modify Tools) is an ATT&CK for Mobile Defense Evasion sub-technique of T1629 (Impair Defenses). Adversaries may disable security tools to avoid potential detection of their tools and activities. This can take the form of disabling security software, modifying SELinux configuration, or other methods to interfere with security tools scanning or reporting information. This is typically done by abusing device administrator permissions or using system exploits to gain root access to the device to modify protected system files. Affected platforms: Android. MITRE-documented mitigations include M1004 System Partition Integrity, M1010 Deploy Compromised Device Detection Method, M1011 User Guidance, M1001 Security Updates. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1629-impair-defenses"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1629-impair-defenses",
    "title": "MITRE ATT&CK Mobile T1629: Impair Defenses (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1629 (Impair Defenses) is an ATT&CK for Mobile Defense Evasion technique. Adversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms. This not only involves impairing preventative defenses, such as anti-virus, but also detection capabilities that defenders can use to audit activity and identify malicious behavior. This may span both native defenses as well as supplemental capabilities installed by users or mobile endpoint administrators. ATT&CK documents 3 sub-techniques: T1629.001 Prevent Application Removal; T1629.002 Device Lockout; T1629.003 Disable or Modify Tools. Affected platforms: Android. MITRE-documented mitigations include M1010 Deploy Compromised Device Detection Method, M1001 Security Updates, M1011 User Guidance, M1004 System Partition Integrity, M1012 Enterprise Policy. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1630-001-uninstall-malicious-application",
    "title": "MITRE ATT&CK Mobile T1630.001: Uninstall Malicious Application (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1630.001 (Uninstall Malicious Application) is an ATT&CK for Mobile Defense Evasion sub-technique of T1630 (Indicator Removal on Host). Adversaries may include functionality in malware that uninstalls the malicious application from the device. This can be achieved by: * Abusing device owner permissions to perform silent uninstallation using device owner API calls. * Abusing root permissions to delete files from the filesystem. * Abusing the accessibility service. This requires sending an intent to the system to request uninstallation, and then abusing the accessibility service to click the proper places on the screen to confirm uninstallation. Affected platforms: Android. MITRE-documented mitigations include M1001 Security Updates, M1011 User Guidance, M1002 Attestation. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1630-indicator-removal-on-host"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1630-002-file-deletion",
    "title": "MITRE ATT&CK Mobile T1630.002: File Deletion (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1630.002 (File Deletion) is an ATT&CK for Mobile Defense Evasion sub-technique of T1630 (Indicator Removal on Host). Adversaries may wipe a device or delete individual files in order to manipulate external outcomes or hide activity. An application must have administrator access to fully wipe the device, while individual files may not require special permissions to delete depending on their storage location. Stored data could include a variety of file formats, such as Office files, databases, stored emails, and custom file formats. Affected platforms: Android. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1630-indicator-removal-on-host"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1630-003-disguise-root-jailbreak-indicators",
    "title": "MITRE ATT&CK Mobile T1630.003: Disguise Root/Jailbreak Indicators (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1630.003 (Disguise Root/Jailbreak Indicators) is an ATT&CK for Mobile Defense Evasion sub-technique of T1630 (Indicator Removal on Host). An adversary could use knowledge of the techniques used by security software to evade detection. For example, some mobile security products perform compromised device detection by searching for particular artifacts such as an installed \"su\" binary, but that check could be evaded by naming the binary something else. Similarly, polymorphic code techniques could be used to evade signature-based detection. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1630-indicator-removal-on-host"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1630-indicator-removal-on-host",
    "title": "MITRE ATT&CK Mobile T1630: Indicator Removal on Host (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1630 (Indicator Removal on Host) is an ATT&CK for Mobile Defense Evasion technique. Adversaries may delete, alter, or hide generated artifacts on a device, including files, jailbreak status, or the malicious application itself. These actions may interfere with event collection, reporting, or other notifications used to detect intrusion activity. This may compromise the integrity of mobile security solutions by causing notable events or information to go unreported. ATT&CK documents 3 sub-techniques: T1630.001 Uninstall Malicious Application; T1630.002 File Deletion; T1630.003 Disguise Root/Jailbreak Indicators. Affected platforms: iOS, Android. MITRE-documented mitigations include M1001 Security Updates, M1011 User Guidance, M1002 Attestation. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1631-001-ptrace-system-calls",
    "title": "MITRE ATT&CK Mobile T1631.001: Ptrace System Calls (Mobile Tactic TA0030 - Defense Evasion / TA0029 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1631.001 (Ptrace System Calls) is an ATT&CK for Mobile Defense Evasion and Privilege Escalation sub-technique of T1631 (Process Injection). Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges. Ptrace system call injection is a method of executing arbitrary code in the address space of a separate live process. Ptrace system call injection involves attaching to and modifying a running process. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1631-process-injection"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1631-process-injection",
    "title": "MITRE ATT&CK Mobile T1631: Process Injection (Mobile Tactic TA0030 - Defense Evasion / TA0029 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1631 (Process Injection) is an ATT&CK for Mobile Defense Evasion and Privilege Escalation technique. Adversaries may inject code into processes in order to evade process-based defenses or even elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process. ATT&CK documents 1 sub-technique: T1631.001 Ptrace System Calls. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1632-001-code-signing-policy-modification",
    "title": "MITRE ATT&CK Mobile T1632.001: Code Signing Policy Modification (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1632.001 (Code Signing Policy Modification) is an ATT&CK for Mobile Defense Evasion sub-technique of T1632 (Subvert Trust Controls). Adversaries may modify code signing policies to enable execution of applications signed with unofficial or unknown keys. Code signing provides a level of authenticity on an app from a developer, guaranteeing that the program has not been tampered with and comes from an official source. Security controls can include enforcement mechanisms to ensure that only valid, signed code can be run on a device. Affected platforms: Android, iOS. MITRE-documented mitigations include M1012 Enterprise Policy, M1006 Use Recent OS Version, M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1632-subvert-trust-controls"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1632-subvert-trust-controls",
    "title": "MITRE ATT&CK Mobile T1632: Subvert Trust Controls (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1632 (Subvert Trust Controls) is an ATT&CK for Mobile Defense Evasion technique. Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted applications. Operating systems and security products may contain mechanisms to identify programs or websites as possessing some level of trust. ATT&CK documents 1 sub-technique: T1632.001 Code Signing Policy Modification. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance, M1006 Use Recent OS Version, M1012 Enterprise Policy. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1633-001-system-checks",
    "title": "MITRE ATT&CK Mobile T1633.001: System Checks (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1633.001 (System Checks) is an ATT&CK for Mobile Defense Evasion sub-technique of T1633 (Virtualization/Sandbox Evasion). Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behavior after checking for the presence of artifacts indicative of a virtual environment or sandbox. If the adversary detects a virtual environment, they may alter their malware's behavior to disengage from the victim or conceal the core functions of the implant. They may also search for virtualization artifacts before dropping secondary or additional payloads. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1633-virtualization-sandbox-evasion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1633-virtualization-sandbox-evasion",
    "title": "MITRE ATT&CK Mobile T1633: Virtualization/Sandbox Evasion (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1633 (Virtualization/Sandbox Evasion) is an ATT&CK for Mobile Defense Evasion technique. Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors after checking for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware's behavior to disengage from the victim or conceal the core functions of the payload. They may also search for VME artifacts before dropping further payloads. ATT&CK documents 1 sub-technique: T1633.001 System Checks. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1634-001-keychain",
    "title": "MITRE ATT&CK Mobile T1634.001: Keychain (Mobile Tactic TA0031 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1634.001 (Keychain) is an ATT&CK for Mobile Credential Access sub-technique of T1634 (Credentials from Password Store). Adversaries may collect keychain data from an iOS device to acquire credentials. Keychains are the built-in way for iOS to keep track of users' passwords and credentials for many services and features such as Wi-Fi passwords, websites, secure notes, certificates, private keys, and VPN credentials. On the device, the keychain database is stored outside of application sandboxes to prevent unauthorized access to the raw data. Affected platforms: iOS. MITRE-documented mitigations include M1010 Deploy Compromised Device Detection Method, M1001 Security Updates, M1002 Attestation. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1634-credentials-from-password-store"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1634-credentials-from-password-store",
    "title": "MITRE ATT&CK Mobile T1634: Credentials from Password Store (Mobile Tactic TA0031 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1634 (Credentials from Password Store) is an ATT&CK for Mobile Credential Access technique. Adversaries may search common password storage locations to obtain user credentials. Passwords can be stored in several places on a device, depending on the operating system or application holding the credentials. There are also specific applications that store passwords to make it easier for users to manage and maintain. Once credentials are obtained, they can be used to perform lateral movement and access restricted information. ATT&CK documents 1 sub-technique: T1634.001 Keychain. Affected platforms: iOS. MITRE-documented mitigations include M1001 Security Updates, M1002 Attestation, M1010 Deploy Compromised Device Detection Method. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1635-001-uri-hijacking",
    "title": "MITRE ATT&CK Mobile T1635.001: URI Hijacking (Mobile Tactic TA0031 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1635.001 (URI Hijacking) is an ATT&CK for Mobile Credential Access sub-technique of T1635 (Steal Application Access Token). Adversaries may register Uniform Resource Identifiers (URIs) to intercept sensitive data. Applications regularly register URIs with the operating system to act as a response handler for various actions, such as logging into an app using an external account via single sign-on. This allows redirections to that specific URI to be intercepted by the application. Affected platforms: Android, iOS. MITRE-documented mitigations include M1013 Application Developer Guidance, M1011 User Guidance, M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1635-steal-application-access-token"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1635-steal-application-access-token",
    "title": "MITRE ATT&CK Mobile T1635: Steal Application Access Token (Mobile Tactic TA0031 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1635 (Steal Application Access Token) is an ATT&CK for Mobile Credential Access technique. Adversaries can steal user application access tokens as a means of acquiring credentials to access remote systems and resources. This can occur through social engineering or URI hijacking and typically requires user action to grant access, such as through a system \"Open With\" dialogue. Application access tokens are used to make authorized API requests on behalf of a user and are commonly used as a way to access resources in cloud-based applications and software-as-a-service (SaaS). ATT&CK documents 1 sub-technique: T1635.001 URI Hijacking. Affected platforms: Android, iOS. MITRE-documented mitigations include M1006 Use Recent OS Version, M1011 User Guidance, M1013 Application Developer Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1636-001-calendar-entries",
    "title": "MITRE ATT&CK Mobile T1636.001: Calendar Entries (Mobile Tactic TA0035 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1636.001 (Calendar Entries) is an ATT&CK for Mobile Collection sub-technique of T1636 (Protected User Data). Adversaries may utilize standard operating system APIs to gather calendar entry data. On Android, this can be accomplished using the Calendar Content Provider. On iOS, this can be accomplished using the EventKit framework. If the device has been jailbroken or rooted, an adversary may be able to access Calendar Entries without the user's knowledge or approval. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1636-protected-user-data"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1636-002-call-log",
    "title": "MITRE ATT&CK Mobile T1636.002: Call Log (Mobile Tactic TA0035 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1636.002 (Call Log) is an ATT&CK for Mobile Collection sub-technique of T1636 (Protected User Data). Adversaries may utilize standard operating system APIs to gather call log data. On Android, this can be accomplished using the Call Log Content Provider. iOS provides no standard API to access the call log. If the device has been jailbroken or rooted, an adversary may be able to access the Call Log without the user's knowledge or approval. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1636-protected-user-data"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1636-003-contact-list",
    "title": "MITRE ATT&CK Mobile T1636.003: Contact List (Mobile Tactic TA0035 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1636.003 (Contact List) is an ATT&CK for Mobile Collection sub-technique of T1636 (Protected User Data). Adversaries may utilize standard operating system APIs to gather contact list data. On Android, this can be accomplished using the Contacts Content Provider. On iOS, this can be accomplished using the Contacts framework. If the device has been jailbroken or rooted, an adversary may be able to access the Contact List without the user's knowledge or approval. Affected platforms: iOS, Android. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1636-protected-user-data"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1636-004-sms-messages",
    "title": "MITRE ATT&CK Mobile T1636.004: SMS Messages (Mobile Tactic TA0035 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1636.004 (SMS Messages) is an ATT&CK for Mobile Collection sub-technique of T1636 (Protected User Data). Adversaries may utilize standard operating system APIs to gather SMS messages. On Android, this can be accomplished using the SMS Content Provider. iOS provides no standard API to access SMS messages. If the device has been jailbroken or rooted, an adversary may be able to access SMS Messages without the user's knowledge or approval. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1636-protected-user-data"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1636-005-accounts",
    "title": "MITRE ATT&CK Mobile T1636.005: Accounts (Mobile Tactic TA0035 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK Mobile T1636.005 (Accounts) is an Mobile Collection technique. Adversaries may utilize standard operating system APIs to gather account data. On Android, this can be accomplished by using the AccountManager API. For example, adversaries may use the `getAccounts()` method to list all accounts. On iOS, this can be accomplished by using the Keychain services. If the device has been jailbroken or rooted, adversaries may be able to access Accounts without the users’ knowledge or approval. Affected platforms: Android, iOS. Sub-technique of ATT&CK T1636. ATT&CK-mapped mitigations: M1006 Use Recent OS Version, M1011 User Guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-mobile-t1636-protected-user-data",
    "title": "MITRE ATT&CK Mobile T1636: Protected User Data (Mobile Tactic TA0035 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1636 (Protected User Data) is an ATT&CK for Mobile Collection technique. Adversaries may utilize standard operating system APIs to collect data from permission-backed data stores on a device, such as the calendar or contact list. These permissions need to be declared ahead of time. On Android, they must be included in the application's manifest. On iOS, they must be included in the application's Info.plist file. In almost all cases, the user is required to grant access to the data store that the application is trying to access. ATT&CK documents 4 sub-techniques: T1636.001 Calendar Entries; T1636.002 Call Log; T1636.003 Contact List; T1636.004 SMS Messages. Affected platforms: Android, iOS. MITRE-documented mitigations include M1006 Use Recent OS Version, M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1637-001-domain-generation-algorithms",
    "title": "MITRE ATT&CK Mobile T1637.001: Domain Generation Algorithms (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1637.001 (Domain Generation Algorithms) is an ATT&CK for Mobile Command and Control sub-technique of T1637 (Dynamic Resolution). Adversaries may use Domain Generation Algorithms (DGAs) to procedurally generate domain names for uses such as command and control communication or malicious application distribution. DGAs increase the difficulty for defenders to block, track, or take over the command and control channel, as there could potentially be thousands of domains that malware can check for instructions. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1637-dynamic-resolution"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1637-dynamic-resolution",
    "title": "MITRE ATT&CK Mobile T1637: Dynamic Resolution (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1637 (Dynamic Resolution) is an ATT&CK for Mobile Command and Control technique. Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorithm with the infrastructure the adversary uses to receive the malware's communications. This algorithm can be used to dynamically adjust parameters such as the domain name, IP address, or port number the malware uses for command and control. ATT&CK documents 1 sub-technique: T1637.001 Domain Generation Algorithms. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1638-adversary-in-the-middle",
    "title": "MITRE ATT&CK Mobile T1638: Adversary-in-the-Middle (Mobile Tactic TA0035 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1638 (Adversary-in-the-Middle) is an ATT&CK for Mobile Collection technique. Adversaries may attempt to position themselves between two or more networked devices to support follow-on behaviors such as Transmitted Data Manipulation or Endpoint Denial of Service. Adversary-in-the-Middle can be achieved through several mechanisms. For example, a malicious application may register itself as a VPN client, effectively redirecting device traffic to adversary-owned resources. Affected platforms: Android, iOS. MITRE-documented mitigations include M1009 Encrypt Network Traffic, M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1639-001-exfiltration-over-unencrypted-non-c2-protocol",
    "title": "MITRE ATT&CK Mobile T1639.001: Exfiltration Over Unencrypted Non-C2 Protocol (Mobile Tactic TA0036 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1639.001 (Exfiltration Over Unencrypted Non-C2 Protocol) is an ATT&CK for Mobile Exfiltration sub-technique of T1639 (Exfiltration Over Alternative Protocol). Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Adversaries may opt to obfuscate this data, without the use of encryption, within network protocols that are natively unencrypted (such as HTTP, FTP, or DNS). Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1639-exfiltration-over-alternative-protocol"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1639-exfiltration-over-alternative-protocol",
    "title": "MITRE ATT&CK Mobile T1639: Exfiltration Over Alternative Protocol (Mobile Tactic TA0036 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1639 (Exfiltration Over Alternative Protocol) is an ATT&CK for Mobile Exfiltration technique. Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Alternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Different protocol channels could also include Web services such as cloud storage. ATT&CK documents 1 sub-technique: T1639.001 Exfiltration Over Unencrypted Non-C2 Protocol. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1640-account-access-removal",
    "title": "MITRE ATT&CK Mobile T1640: Account Access Removal (Mobile Tactic TA0034 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1640 (Account Access Removal) is an ATT&CK for Mobile Impact technique. Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: credentials changed) to remove access to accounts. Affected platforms: Android. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1641-001-transmitted-data-manipulation",
    "title": "MITRE ATT&CK Mobile T1641.001: Transmitted Data Manipulation (Mobile Tactic TA0034 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1641.001 (Transmitted Data Manipulation) is an ATT&CK for Mobile Impact sub-technique of T1641 (Data Manipulation). Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity. By manipulating transmitted data, adversaries may attempt to affect a business process, organizational understanding, or decision making. Manipulation may be possible over a network connection or between system processes where there is an opportunity to deploy a tool that will intercept and change information. Affected platforms: Android. MITRE-documented mitigations include M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1641-data-manipulation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1641-data-manipulation",
    "title": "MITRE ATT&CK Mobile T1641: Data Manipulation (Mobile Tactic TA0034 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1641 (Data Manipulation) is an ATT&CK for Mobile Impact technique. Adversaries may insert, delete, or alter data in order to manipulate external outcomes or hide activity. By manipulating data, adversaries may attempt to affect a business process, organizational understanding, or decision making. The type of modification and the impact it will have depends on the target application, process, and the goals and objectives of the adversary. ATT&CK documents 1 sub-technique: T1641.001 Transmitted Data Manipulation. Affected platforms: Android. MITRE-documented mitigations include M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1642-endpoint-denial-of-service",
    "title": "MITRE ATT&CK Mobile T1642: Endpoint Denial of Service (Mobile Tactic TA0034 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1642 (Endpoint Denial of Service) is an ATT&CK for Mobile Impact technique. Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users. On Android versions prior to 7, apps can abuse Device Administrator access to reset the device lock passcode, preventing the user from unlocking the device. After Android 7, only device or profile owners (e.g. MDMs) can reset the device's passcode. Affected platforms: Android, iOS. MITRE-documented mitigations include M1006 Use Recent OS Version, M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1643-generate-traffic-from-victim",
    "title": "MITRE ATT&CK Mobile T1643: Generate Traffic from Victim (Mobile Tactic TA0034 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1643 (Generate Traffic from Victim) is an ATT&CK for Mobile Impact technique. Adversaries may generate outbound traffic from devices. This is typically performed to manipulate external outcomes, such as to achieve carrier billing fraud or to manipulate app store rankings or ratings. Outbound traffic is typically generated as SMS messages or general web traffic, but may take other forms as well. If done via SMS messages, Android apps must hold the SEND_SMS permission. Additionally, sending an SMS message requires user consent if the recipient is a premium number. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1644-out-of-band-data",
    "title": "MITRE ATT&CK Mobile T1644: Out of Band Data (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1644 (Out of Band Data) is an ATT&CK for Mobile Command and Control technique. Adversaries may communicate with compromised devices using out of band data streams. This could be done for a variety of reasons, including evading network traffic monitoring, as a backup method of command and control, or for data exfiltration if the device is not connected to any Internet-providing networks (i.e. cellular or Wi-Fi). Several out of band data streams exist, such as SMS messages, NFC, and Bluetooth. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1645-compromise-client-software-binary",
    "title": "MITRE ATT&CK Mobile T1645: Compromise Client Software Binary (Mobile Tactic TA0028 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1645 (Compromise Client Software Binary) is an ATT&CK for Mobile Persistence technique. Adversaries may modify system software binaries to establish persistent access to devices. System software binaries are used by the underlying operating system and users over adb or terminal emulators. Adversaries may make modifications to client software binaries to carry out malicious tasks when those binaries are executed. For example, malware may come with a pre-compiled malicious binary intended to overwrite the genuine one on the device. Affected platforms: Android, iOS. MITRE-documented mitigations include M1003 Lock Bootloader, M1004 System Partition Integrity, M1001 Security Updates, M1002 Attestation. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1646-exfiltration-over-c2-channel",
    "title": "MITRE ATT&CK Mobile T1646: Exfiltration Over C2 Channel (Mobile Tactic TA0036 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1646 (Exfiltration Over C2 Channel) is an ATT&CK for Mobile Exfiltration technique. Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications. Affected platforms: Android, iOS. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-mobile-t1655-001-match-legitimate-name-or-location",
    "title": "MITRE ATT&CK Mobile T1655.001: Match Legitimate Name or Location (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1655.001 (Match Legitimate Name or Location) is an ATT&CK for Mobile Defense Evasion sub-technique of T1655 (Masquerading). Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by giving artifacts the name and icon of a legitimate, trusted application (i.e., Settings), or using a package name that matches legitimate, trusted applications (i.e., com.google.android.gm). Adversaries may also use the same icon of the file or application they are trying to mimic. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-mobile-t1655-masquerading"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1655-masquerading",
    "title": "MITRE ATT&CK Mobile T1655: Masquerading (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1655 (Masquerading) is an ATT&CK for Mobile Defense Evasion technique. Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name, location, or appearance of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. ATT&CK documents 1 sub-technique: T1655.001 Match Legitimate Name or Location. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1658-exploitation-for-client-execution",
    "title": "MITRE ATT&CK Mobile T1658: Exploitation for Client Execution (Mobile Tactic TA0041 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1658 (Exploitation for Client Execution) is an ATT&CK for Mobile Execution technique. Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to insecure coding practices that can lead to unanticipated behavior. Adversaries may take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance, M1001 Security Updates. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1660-phishing",
    "title": "MITRE ATT&CK Mobile T1660: Phishing (Mobile Tactic TA0027 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1660 (Phishing) is an ATT&CK for Mobile Initial Access technique. Adversaries may send malicious content to users in order to gain access to their mobile devices. All forms of phishing are electronically delivered social engineering. Adversaries can conduct both non-targeted phishing, such as in mass malware spam campaigns, as well as more targeted phishing tailored for a specific individual, company, or industry, known as \"spearphishing\". Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance, M1058 Antivirus/Antimalware. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1661-application-versioning",
    "title": "MITRE ATT&CK Mobile T1661: Application Versioning (Mobile Tactic TA0027 - Initial Access / TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1661 (Application Versioning) is an ATT&CK for Mobile Initial Access and Defense Evasion technique. An adversary may push an update to a previously benign application to add malicious code. This can be accomplished by pushing an initially benign, functional application to a trusted application store, such as the Google Play Store or the Apple App Store. This allows the adversary to establish a trusted userbase that may grant permissions to the application prior to the introduction of malicious code. Then, an application update could be pushed to introduce malicious code. Affected platforms: Android, iOS. MITRE-documented mitigations include M1012 Enterprise Policy, M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1662-data-destruction",
    "title": "MITRE ATT&CK Mobile T1662: Data Destruction (Mobile Tactic TA0034 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1662 (Data Destruction) is an ATT&CK for Mobile Impact technique. Adversaries may destroy data and files on specific devices or in large numbers to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. To achieve data destruction, adversaries may use the pm uninstall command to uninstall packages or the rm command to remove specific files. Affected platforms: Android. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1663-remote-access-software",
    "title": "MITRE ATT&CK Mobile T1663: Remote Access Software (Mobile Tactic TA0037 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1663 (Remote Access Software) is an ATT&CK for Mobile Command and Control technique. Adversaries may use legitimate remote access software, such as VNC, TeamViewer, AirDroid, AirMirror, etc., to establish an interactive command and control channel to target mobile devices. Remote access applications may be installed and used post-compromise as an alternate communication channel for redundant access or as a way to establish an interactive remote session with the target device. Affected platforms: Android, iOS. MITRE-documented mitigations include M1012 Enterprise Policy, M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1664-exploitation-for-initial-access",
    "title": "MITRE ATT&CK Mobile T1664: Exploitation for Initial Access (Mobile Tactic TA0027 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1664 (Exploitation for Initial Access) is an ATT&CK for Mobile Initial Access technique. Adversaries may exploit software vulnerabilities to gain initial access to a mobile device. This can be accomplished in a variety of ways. Vulnerabilities may be present in applications, services, the underlying operating system, or in the kernel itself. Several well-known mobile device exploits exist, including FORCEDENTRY, StageFright, and BlueBorne. Further, some exploits may be possible to exploit without any user interaction (zero-click), making them particularly dangerous. Affected platforms: Android, iOS. MITRE-documented mitigations include M1001 Security Updates, M1058 Antivirus/Antimalware. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-mobile-t1670-virtualization-solution",
    "title": "MITRE ATT&CK Mobile T1670: Virtualization Solution (Mobile Tactic TA0030 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK Mobile T1670 (Virtualization Solution) is an Mobile Defense Evasion technique. Adversaries may carry out malicious operations using virtualization solutions to escape from Android sandboxes and to avoid detection. Android uses sandboxes to separate resources and code execution between applications and the operating system. There are a few virtualization solutions available on Android, such as the Android Virtualization Framework (AVF). Through virtualization solutions, adversaries may execute malicious operations without user knowledge. For example, adversaries may mimic a legitimate banking application’s functionalities in a virtual environment, thanks to the virtualization solution, while malicious code captures credentials. Affected platforms: Android. ATT&CK-mapped mitigations: M1011 User Guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-mobile-t1676-linked-devices",
    "title": "MITRE ATT&CK Mobile T1676: Linked Devices (Mobile Tactic TA0035 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK Mobile T1676 (Linked Devices) is an Mobile Collection, Persistence technique. Adversaries may abuse the “linked devices” feature on messaging applications, such as Signal and WhatsApp, to register the user’s account to an adversary-controlled device. By abusing the “linked devices” feature, adversaries may achieve and maintain persistence through the user’s account, may collect information, such as the user’s messages and contacts list, and may send future messages from the linked device. Signal is a messaging application that uses the open-source Signal Protocol to encrypt messages and calls; similarly, WhatsApp is a messaging application that has end-to-end encryption and other security measures to protect messages and calls. Both applications have a “linked devices” feature that allows users to access their Signal and/or WhatsApp accounts from different devices, ... Affected platforms: Android, iOS. ATT&CK-mapped mitigations: M1011 User Guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1001-001-junk-data",
    "title": "MITRE ATT&CK T1001.001: Junk Data (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1001.001 (Junk Data) is an Enterprise Command and Control sub-technique of T1001 (Data Obfuscation). Adversaries may add junk data to protocols used for command and control to make detection more difficult. By adding random or meaningless data to the protocols used for command and control, adversaries can prevent trivial methods for decoding, deciphering, or otherwise analyzing the traffic. Examples may include appending/prepending data with junk characters or writing junk characters between significant characters. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1001-data-obfuscation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1001-002-steganography",
    "title": "MITRE ATT&CK T1001.002: Steganography (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1001.002 (Steganography) is an Enterprise Command and Control sub-technique of T1001 (Data Obfuscation). Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult. Steganographic techniques can be used to hide data in digital messages that are transferred between systems. This hidden information can be used for command and control of compromised systems. In some cases, the passing of files embedded using steganography, such as image or document files, can be used for command and control. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1001-data-obfuscation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1001-003-protocol-or-service-impersonation",
    "title": "MITRE ATT&CK T1001.003: Protocol or Service Impersonation (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1001.003 (Protocol or Service Impersonation) is an Enterprise Command and Control sub-technique of T1001 (Data Obfuscation). Adversaries may impersonate legitimate protocols or web service traffic to disguise command and control activity and thwart analysis efforts. By impersonating legitimate protocols or web services, adversaries can make their command and control traffic blend in with legitimate network traffic. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1001-data-obfuscation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1001-data-obfuscation",
    "title": "MITRE ATT&CK T1001: Data Obfuscation (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1001 (Data Obfuscation) is an Enterprise Command and Control technique. Adversaries may obfuscate command and control traffic to make it more difficult to detect. Command and control (C2) communications are hidden (but not necessarily encrypted) in an attempt to make the content more difficult to discover or decipher and to make the communication less conspicuous and hide commands from being seen. This encompasses many methods, such as adding junk data to protocol traffic, using steganography, or impersonating legitimate protocols. ATT&CK documents 3 sub-techniques: T1001.001 Junk Data; T1001.002 Steganography; T1001.003 Protocol or Service Impersonation. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1003-001-lsass-memory",
    "title": "MITRE ATT&CK T1003.001: LSASS Memory (Sub-Technique of T1003 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1003.001 covers adversary extraction of authentication credentials from the Local Security Authority Subsystem Service (LSASS) process memory on Windows endpoints. Mimikatz, Pypykatz, ProcDump, Task Manager dump, Cobalt Strike credential dumping module, and direct DPAPI access are the dominant tools. LSASS dumping appears in nearly every ransomware intrusion chain (LockBit, BlackCat, Cl0p, Royal). Compliance obligations include NIST SP 800-53 IA-5, SI-4, SI-7, ISO 27001 A.5.17, A.8.2, A.8.7, A.8.16, PCI DSS Req 8.3.7, and Microsoft Security Compass Tier Zero asset protection methodology.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-os-credential-dumping",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1003-002-security-account-manager",
    "title": "MITRE ATT&CK T1003.002: Security Account Manager (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1003.002 (Security Account Manager) is an Enterprise Credential Access sub-technique of T1003 (OS Credential Dumping). Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the net user command. Enumerating the SAM database requires SYSTEM level access. Affected platforms: Windows. MITRE-documented mitigations include M1027 Password Policies, M1026 Privileged Account Management, M1028 Operating System Configuration, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1003-os-credential-dumping"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1003-003-ntds",
    "title": "MITRE ATT&CK T1003.003: NTDS (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1003.003 (NTDS) is an Enterprise Credential Access sub-technique of T1003 (OS Credential Dumping). Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in %SystemRoot%\\NTDS\\Ntds.dit of a domain controller. In addition to looking for NTDS files on active Domain Controllers, adversaries may search for backups that contain the same or similar information. Affected platforms: Windows. MITRE-documented mitigations include M1027 Password Policies, M1026 Privileged Account Management, M1017 User Training, M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1003-os-credential-dumping"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1003-004-lsa-secrets",
    "title": "MITRE ATT&CK T1003.004: LSA Secrets (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1003.004 (LSA Secrets) is an Enterprise Credential Access sub-technique of T1003 (OS Credential Dumping). Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts. LSA secrets are stored in the registry at HKEY_LOCAL_MACHINE\\SECURITY\\Policy\\Secrets. LSA secrets can also be dumped from memory. Reg can be used to extract from the Registry. Mimikatz can be used to extract secrets from memory. Affected platforms: Windows. MITRE-documented mitigations include M1027 Password Policies, M1026 Privileged Account Management, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1003-os-credential-dumping"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1003-005-cached-domain-credentials",
    "title": "MITRE ATT&CK T1003.005: Cached Domain Credentials (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1003.005 (Cached Domain Credentials) is an Enterprise Credential Access sub-technique of T1003 (OS Credential Dumping). Adversaries may attempt to access cached domain credentials used to allow authentication to occur in the event a domain controller is unavailable. On Windows Vista and newer, the hash format is DCC2 (Domain Cached Credentials version 2) hash, also known as MS-Cache v2 hash. The number of default cached credentials varies and can be altered per system. This hash does not allow pass-the-hash style attacks, and instead requires Password Cracking to recover the plaintext password. Affected platforms: Windows, Linux. MITRE-documented mitigations include M1015 Active Directory Configuration, M1017 User Training, M1027 Password Policies, M1028 Operating System Configuration, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1003-os-credential-dumping"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1003-006-dcsync",
    "title": "MITRE ATT&CK T1003.006: DCSync (Sub-Technique of T1003 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1003.006 covers adversary impersonation of a Domain Controller to retrieve password hashes via Microsoft Directory Replication Service (MS-DRSR) protocol. Tools include Mimikatz lsadump::dcsync, Impacket secretsdump.py, NetExec/CrackMapExec ntds module. Requires Replicating Directory Changes (DS-Replication-Get-Changes) or Replicating Directory Changes All permissions, typically granted to Domain Admins, Enterprise Admins, or specific service accounts. Compliance: NIST 800-53 IA-5, AC-6, SI-4, ISO 27001 A.5.17, A.8.2, A.8.16, PCI DSS Req 8.3.7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-os-credential-dumping",
      "mitre-attack-t1003-001-lsass-memory",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1003-007-proc-filesystem",
    "title": "MITRE ATT&CK T1003.007: Proc Filesystem (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1003.007 (Proc Filesystem) is an Enterprise Credential Access sub-technique of T1003 (OS Credential Dumping). Adversaries may gather credentials from the proc filesystem or /proc. The proc filesystem is a pseudo-filesystem used as an interface to kernel data structures for Linux based systems managing virtual memory. For each process, the /proc/<PID>/maps file shows how memory is mapped within the process's virtual address space. And /proc/<PID>/mem, exposed for debugging purposes, provides access to the process's virtual address space. Affected platforms: Linux. MITRE-documented mitigations include M1027 Password Policies, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1003-os-credential-dumping"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
    "title": "MITRE ATT&CK T1003.008: /etc/passwd and /etc/shadow (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1003.008 (/etc/passwd and /etc/shadow) is an Enterprise Credential Access sub-technique of T1003 (OS Credential Dumping). Adversaries may attempt to dump the contents of /etc/passwd and /etc/shadow to enable offline password cracking. Most modern Linux operating systems use a combination of /etc/passwd and /etc/shadow to store user account information including password hashes in /etc/shadow. By default, /etc/shadow is only readable by the root user. Affected platforms: Linux. MITRE-documented mitigations include M1026 Privileged Account Management, M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1003-os-credential-dumping"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1003-os-credential-dumping",
    "title": "MITRE ATT&CK T1003: OS Credential Dumping (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1003 covers adversary techniques for dumping credentials from operating systems and software. Sub-techniques include LSASS Memory (T1003.001), Security Account Manager (T1003.002), NTDS (T1003.003), LSA Secrets (T1003.004), Cached Domain Credentials (T1003.005), DCSync (T1003.006), Proc Filesystem (T1003.007), and /etc/passwd and /etc/shadow (T1003.008). Mimikatz, Pypykatz, and DCSync remain widely-used post-exploitation tools. Compliance obligations include Credential Guard enforcement (NIST 800-53 IA-5, ISO A.5.17), LSA protection, and tier-zero asset isolation under PCI DSS and DORA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1078-valid-accounts",
      "cis-controls-v8"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1005-data-from-local-system",
    "title": "MITRE ATT&CK T1005: Data from Local System (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1005 covers adversary collection of sensitive data from local system storage after gaining endpoint access. Living-off-the-land enumeration via find, grep, dir, type, Get-ChildItem is the dominant pattern. Compliance obligations include data classification under ISO 27001 A.5.12, A.8.12 (data leakage prevention), NIST SP 800-53 SC-28 (Protection at Rest), MP-3 (Media Marking), AC-3 (Access Enforcement), PCI DSS Req 3 (Protect Stored Account Data), HIPAA 164.312(a)(1), GDPR Article 32, and US state breach notification laws.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1041-exfiltration-over-c2-channel"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1006-direct-volume-access",
    "title": "MITRE ATT&CK T1006: Direct Volume Access (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1006 (Direct Volume Access) is an Enterprise Defense Evasion technique. Adversaries may directly access a volume to bypass file access controls and file system monitoring. Windows allows programs to have direct access to logical volumes. Programs with direct access may read and write files directly from the drive by analyzing file system data structures. This technique may bypass Windows file access controls as well as file system monitoring tools. Utilities, such as NinjaCopy, exist to perform these actions in PowerShell. Affected platforms: Windows, Network. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint, M1018 User Account Management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1007-system-service-discovery",
    "title": "MITRE ATT&CK T1007: System Service Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1007 (System Service Discovery) is an Enterprise Discovery technique. Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as sc query, tasklist /svc, systemctl --type=service, and net start. Adversaries may use the information from System Service Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Affected platforms: Windows, macOS, Linux.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1008-fallback-channels",
    "title": "MITRE ATT&CK T1008: Fallback Channels (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1008 (Fallback Channels) is an Enterprise Command and Control technique. Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1010-application-window-discovery",
    "title": "MITRE ATT&CK T1010: Application Window Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1010 (Application Window Discovery) is an Enterprise Discovery technique. Adversaries may attempt to get a listing of open application windows. Window listings could convey information about how the system is used. For example, information about application windows could be used identify potential data to collect as well as identifying security tooling (Security Software Discovery) to evade. Adversaries typically abuse system features for this type of enumeration. Affected platforms: macOS, Windows, Linux.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1011-001-exfiltration-over-bluetooth",
    "title": "MITRE ATT&CK T1011.001: Exfiltration Over Bluetooth (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1011.001 (Exfiltration Over Bluetooth) is an Enterprise Exfiltration sub-technique of T1011 (Exfiltration Over Other Network Medium). Adversaries may attempt to exfiltrate data over Bluetooth rather than the command and control channel. If the command and control network is a wired Internet connection, an adversary may opt to exfiltrate data using a Bluetooth communication channel. Adversaries may choose to do this if they have sufficient access and proximity. Bluetooth connections might not be secured or defended as well as the primary Internet-connected channel because it is not routed through the same enterprise network. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-18, CM-2, CM-6, CM-7, CM-8, RA-5, SC-43, SI-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1011-exfiltration-over-other-network-medium"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1011-exfiltration-over-other-network-medium",
    "title": "MITRE ATT&CK T1011: Exfiltration Over Other Network Medium (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1011 (Exfiltration Over Other Network Medium) is an Enterprise Exfiltration technique. Adversaries may attempt to exfiltrate data over a different network medium than the command and control channel. If the command and control network is a wired Internet connection, the exfiltration may occur, for example, over a WiFi connection, modem, cellular data connection, Bluetooth, or another radio frequency (RF) channel. ATT&CK documents 1 sub-technique: T1011.001 Exfiltration Over Bluetooth. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-18, CM-6, CM-7, SC-43, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1012-query-registry",
    "title": "MITRE ATT&CK T1012: Query Registry (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1012 (Query Registry) is an Enterprise Discovery technique. Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software. The Registry contains a significant amount of information about the operating system, configuration, software, and security. Information can easily be queried using the Reg utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a network. Affected platforms: Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1014-rootkit",
    "title": "MITRE ATT&CK T1014: Rootkit (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1014 (Rootkit) is an Enterprise Defense Evasion technique. Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information. Rootkits or rootkit enabling functionality may reside at the user or kernel level in the operating system or lower, to include a hypervisor, Master Boot Record, or System Firmware. Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1016-001-internet-connection-discovery",
    "title": "MITRE ATT&CK T1016.001: Internet Connection Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1016.001 (Internet Connection Discovery) is an Enterprise Discovery sub-technique of T1016 (System Network Configuration Discovery). Adversaries may check for Internet connectivity on compromised systems. This may be performed during automated discovery and can be accomplished in numerous ways such as using Ping, tracert, and GET requests to websites. Adversaries may use the results and responses from these requests to determine if the system is capable of communicating with their C2 servers before attempting to connect to them. The results may also be used to identify routes, redirectors, and proxy servers. Affected platforms: Windows, Linux, macOS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1016-system-network-configuration-discovery"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1016-002-wi-fi-discovery",
    "title": "MITRE ATT&CK T1016.002: Wi-Fi Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1016.002 (Wi-Fi Discovery) is an Enterprise Discovery sub-technique of T1016 (System Network Configuration Discovery). Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems. Adversaries may use Wi-Fi information as part of Account Discovery, Remote System Discovery, and other discovery or Credential Access activity to support both ongoing and future campaigns. Adversaries may collect various types of information about Wi-Fi networks from hosts. Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1016-system-network-configuration-discovery"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1016-system-network-configuration-discovery",
    "title": "MITRE ATT&CK T1016: System Network Configuration Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1016 (System Network Configuration Discovery) is an Enterprise Discovery technique. Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route. ATT&CK documents 2 sub-techniques: T1016.001 Internet Connection Discovery; T1016.002 Wi-Fi Discovery. Affected platforms: Linux, macOS, Windows, Network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1018-remote-system-discovery",
    "title": "MITRE ATT&CK T1018: Remote System Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1018 describes adversary enumeration of remote systems on the network to enable lateral movement planning. Tools include built-in net commands, nltest, BloodHound, SharpHound, and PowerView. Active Directory enumeration is a hallmark of ransomware operators and APT groups. Compliance obligations include network segmentation (NIST 800-53 SC-7, PCI DSS Req 1.4), Active Directory hardening (Microsoft Security Compass tier model), and behavioural detection of enumeration tooling under ISO 27001 A.8.16 and NIS2 Article 21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1083-file-and-directory-discovery"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1020-001-traffic-duplication",
    "title": "MITRE ATT&CK T1020.001: Traffic Duplication (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1020.001 (Traffic Duplication) is an Enterprise Exfiltration sub-technique of T1020 (Automated Exfiltration). Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised infrastructure. Traffic mirroring is a native feature for some devices, often used for network analysis. For example, devices may be configured to forward network traffic to one or more destinations for analysis by a network analyzer or other monitoring device. Adversaries may abuse traffic mirroring to mirror or redirect network traffic through other infrastructure they control. Affected platforms: Network, IaaS. MITRE-documented mitigations include M1041 Encrypt Sensitive Information, M1018 User Account Management, M1057 Data Loss Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-6, AC-16, AC-17, AC-18, AC-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1020-automated-exfiltration"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1020-automated-exfiltration",
    "title": "MITRE ATT&CK T1020: Automated Exfiltration (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1020 (Automated Exfiltration) is an Enterprise Exfiltration technique. Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection. When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol. ATT&CK documents 1 sub-technique: T1020.001 Traffic Duplication. Affected platforms: Linux, macOS, Windows, Network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1021-001-remote-desktop-protocol",
    "title": "MITRE ATT&CK T1021.001: Remote Desktop Protocol (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1021.001 (Remote Desktop Protocol) is an Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user. Remote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS). Affected platforms: Windows. MITRE-documented mitigations include M1047 Audit, M1035 Limit Access to Resource Over Network, M1030 Network Segmentation, M1028 Operating System Configuration, M1042 Disable or Remove Feature or Program, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-11, AC-12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1021-remote-services"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1021-002-smb-windows-admin-shares",
    "title": "MITRE ATT&CK T1021.002: SMB/Windows Admin Shares (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1021.002 (SMB/Windows Admin Shares) is an Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user. SMB is a file, printer, and serial port sharing protocol for Windows machines on the same network or domain. Adversaries may use SMB to interact with file shares, allowing them to move laterally throughout a network. Linux and macOS implementations of SMB typically use Samba. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1035 Limit Access to Resource Over Network, M1037 Filter Network Traffic, M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-17, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1021-remote-services"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1021-003-distributed-component-object-model",
    "title": "MITRE ATT&CK T1021.003: Distributed Component Object Model (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1021.003 (Distributed Component Object Model) is an Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may use Valid Accounts to interact with remote machines by taking advantage of Distributed Component Object Model (DCOM). The adversary may then perform actions as the logged-on user. The Windows Component Object Model (COM) is a component of the native Windows application programming interface (API) that enables interaction between software objects, or executable code that implements one or more interfaces. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1048 Application Isolation and Sandboxing, M1030 Network Segmentation, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-17, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1021-remote-services"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1021-004-ssh",
    "title": "MITRE ATT&CK T1021.004: SSH (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1021.004 (SSH) is an Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user. SSH is a protocol that allows authorized users to open remote shells on other computers. Many Linux and macOS versions come with SSH installed by default, although typically disabled until the user enables it. The SSH server can be configured to use standard password authentication or public-private keypairs in lieu of or in addition to a password. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1032 Multi-factor Authentication, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-17, AC-20, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1021-remote-services"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1021-005-vnc",
    "title": "MITRE ATT&CK T1021.005: VNC (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1021.005 (VNC) is an Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may use Valid Accounts to remotely control machines using Virtual Network Computing (VNC). VNC is a platform-independent desktop sharing system that uses the RFB (\"remote framebuffer\") protocol to enable users to remotely control another computer's display by relaying the screen, mouse, and keyboard inputs over the network. VNC differs from Remote Desktop Protocol as VNC is screen-sharing software rather than resource-sharing software. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1037 Filter Network Traffic, M1047 Audit, M1033 Limit Software Installation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-17, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1021-remote-services"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1021-006-windows-remote-management",
    "title": "MITRE ATT&CK T1021.006: Windows Remote Management (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1021.006 (Windows Remote Management) is an Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user. WinRM is the name of both a Windows service and a protocol that allows a user to interact with a remote system (e.g., run an executable, modify the Registry, modify services). It may be called with the winrm command or by any number of programs such as PowerShell. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1026 Privileged Account Management, M1030 Network Segmentation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-17, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1021-remote-services"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1021-007-cloud-services",
    "title": "MITRE ATT&CK T1021.007: Cloud Services (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1021.007 (Cloud Services) is an Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may log into accessible cloud services within a compromised environment using Valid Accounts that are synchronized with or federated to on-premises user identities. The adversary may then perform management actions or access cloud-hosted resources as the logged-on user. Many enterprises federate centrally managed user identities to cloud services, allowing users to login with their domain credentials in order to access the cloud control plane. Affected platforms: SaaS, IaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-17, AC-20, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1021-remote-services"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1021-008-direct-cloud-vm-connections",
    "title": "MITRE ATT&CK T1021.008: Direct Cloud VM Connections (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1021.008 (Direct Cloud VM Connections) is an Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may leverage Valid Accounts to log directly into accessible cloud hosted compute infrastructure through cloud native methods. Many cloud providers offer interactive connections to virtual infrastructure that can be accessed through the Cloud API, such as Azure Serial Console, AWS EC2 Instance Connect, and AWS System Manager.. Methods of authentication for these connections can include passwords, application access tokens, or SSH keys. Affected platforms: IaaS. MITRE-documented mitigations include M1018 User Account Management, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-17, AC-20, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1021-remote-services"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1021-remote-services",
    "title": "MITRE ATT&CK T1021: Remote Services (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1021 covers adversary use of valid accounts to log into remote services for lateral movement. Sub-techniques cover Remote Desktop Protocol (T1021.001), SMB/Windows Admin Shares (T1021.002), Distributed Component Object Model (T1021.003), SSH (T1021.004), VNC (T1021.005), Windows Remote Management (T1021.006), Cloud Services (T1021.007), and Direct Cloud VM Connections (T1021.008). RDP abuse remains the #1 vector for ransomware operators. Compliance obligations include MFA on all remote services, jump-host architectures, and audit logging required under PCI DSS Req 8.3.6 and NIS2 Article 21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1018-remote-system-discovery"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1025-data-from-removable-media",
    "title": "MITRE ATT&CK T1025: Data from Removable Media (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1025 (Data from Removable Media) is an Enterprise Collection technique. Adversaries may search connected removable media on computers they have compromised to find files of interest. Sensitive data can be collected from any removable media (optical disk drive, USB memory, etc.) connected to the compromised system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information. Some adversaries may also use Automated Collection on removable media. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1057 Data Loss Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, AC-16, AC-23, CM-12, CP-9, MP-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1027-001-binary-padding",
    "title": "MITRE ATT&CK T1027.001: Binary Padding (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.001 (Binary Padding) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This can be done without affecting the functionality or behavior of a binary, but can increase the size of the binary beyond what some security tools are capable of handling due to file size limitations. Binary padding effectively changes the checksum of the file and can also be used to avoid hash-based blocklists and static anti-virus signatures. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1027-002-software-packing",
    "title": "MITRE ATT&CK T1027.002: Software Packing (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.002 (Software Packing) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. Affected platforms: macOS, Windows, Linux. MITRE-documented mitigations include M1049 Antivirus/Antimalware. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1027-003-steganography",
    "title": "MITRE ATT&CK T1027.003: Steganography (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.003 (Steganography) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may use steganography techniques in order to prevent the detection of hidden information. Steganographic techniques can be used to hide data in digital media such as images, audio tracks, video clips, or text files. Duqu was an early example of malware that used steganography. It encrypted the gathered information from a victim's system and hid it within an image before exfiltrating the image to a C2 server. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1027-004-compile-after-delivery",
    "title": "MITRE ATT&CK T1027.004: Compile After Delivery (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.004 (Compile After Delivery) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe, csc.exe, or GCC/MinGW. Source code payloads may also be encrypted, encoded, and/or embedded within other files, such as those delivered as a Phishing. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1027-005-indicator-removal-from-tools",
    "title": "MITRE ATT&CK T1027.005: Indicator Removal from Tools (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.005 (Indicator Removal from Tools) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed. They can modify the tool by removing the indicator and using the updated version that is no longer detected by the target's defensive systems or subsequent targets that may use similar systems. A good example of this is when malware is detected with a file signature and quarantined by anti-virus software. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1027-006-html-smuggling",
    "title": "MITRE ATT&CK T1027.006: HTML Smuggling (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.006 (HTML Smuggling) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files. HTML documents can store large binary objects known as JavaScript Blobs (immutable data that represents raw bytes) that can later be constructed into file-like objects. Data may also be stored in Data URLs, which enable embedding media type or MIME files inline of HTML documents. HTML5 also introduced a download attribute that may be used to initiate file downloads. Affected platforms: Windows, Linux, macOS. MITRE-documented mitigations include M1048 Application Isolation and Sandboxing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1027-007-dynamic-api-resolution",
    "title": "MITRE ATT&CK T1027.007: Dynamic API Resolution (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.007 (Dynamic API Resolution) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis. Malware commonly uses various Native API functions provided by the OS to perform various tasks such as those involving processes, files, and other system artifacts. API functions called by malware may leave static artifacts such as strings in payload files. Affected platforms: Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1027-008-stripped-payloads",
    "title": "MITRE ATT&CK T1027.008: Stripped Payloads (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.008 (Stripped Payloads) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may attempt to make a payload difficult to analyze by removing symbols, strings, and other human readable information. Scripts and executables may contain variables names and other strings that help developers document code functionality. Symbols are often created by an operating system's linker when executable payloads are compiled. Reverse engineers use these symbols and strings to analyze code and to identify functionality in payloads. Affected platforms: macOS, Linux, Windows, Network. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1027-009-embedded-payloads",
    "title": "MITRE ATT&CK T1027.009: Embedded Payloads (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.009 (Embedded Payloads) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may embed payloads within other files to conceal malicious content from defenses. Otherwise seemingly benign files (such as scripts and executables) may be abused to carry and obfuscate malicious payloads and content. In some cases, embedded payloads may also enable adversaries to Subvert Trust Controls by not impacting execution controls such as digital signatures and notarization tickets. Adversaries may embed payloads in various file formats to hide payloads. Affected platforms: macOS, Windows, Linux. MITRE-documented mitigations include M1049 Antivirus/Antimalware, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1027-010-command-obfuscation",
    "title": "MITRE ATT&CK T1027.010: Command Obfuscation (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.010 (Command Obfuscation) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may obfuscate content during command execution to impede detection. Command-line obfuscation is a method of making strings and patterns within commands and scripts more difficult to signature and analyze. This type of obfuscation can be included within commands executed by delivered payloads (e.g., Phishing and Drive-by Compromise) or interactively via Command and Scripting Interpreter. For example, adversaries may abuse syntax that utilizes various symbols and escape characters (such as spacing, ^, +. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint, M1049 Antivirus/Antimalware. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1027-011-fileless-storage",
    "title": "MITRE ATT&CK T1027.011: Fileless Storage (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.011 (Fileless Storage) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may store data in \"fileless\" formats to conceal malicious activity from defenses. Fileless storage can be broadly defined as any format other than a file. Common examples of non-volatile fileless storage in Windows systems include the Windows Registry, event logs, or WMI repository. Affected platforms: Windows, Linux. MITRE-documented mitigations include M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1027-012-lnk-icon-smuggling",
    "title": "MITRE ATT&CK T1027.012: LNK Icon Smuggling (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.012 (LNK Icon Smuggling) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files. Windows shortcut files (.LNK) include many metadata fields, including an icon location field (also known as the IconEnvironmentDataBlock) designed to specify the path to an icon file that is to be displayed for the LNK file within a host directory. Adversaries may abuse this LNK metadata to download malicious payloads. Affected platforms: Windows. MITRE-documented mitigations include M1049 Antivirus/Antimalware, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1027-013-encrypted-encoded-file",
    "title": "MITRE ATT&CK T1027.013: Encrypted/Encoded File (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.013 (Encrypted/Encoded File) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as Software Packing, Steganography, and Embedded Payloads, share this same broad objective. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1049 Antivirus/Antimalware, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1027-014-polymorphic-code",
    "title": "MITRE ATT&CK T1027.014: Polymorphic Code (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1027.014 (Polymorphic Code) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection. Polymorphic code is a type of software capable of changing its runtime footprint during code execution. With each execution of the software, the code is mutated into a different version of itself that achieves the same purpose or objective as the original. This functionality enables the malware to evade traditional signature-based defenses, such as antivirus and antimalware tools. Affected platforms: Windows, macOS, Linux. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint, M1049 Antivirus/Antimalware. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CM-2, CM-6, CM-7, SI-2, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1027-015-compression",
    "title": "MITRE ATT&CK T1027.015: Compression (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1027.015 (Compression) is an Enterprise Stealth technique. Adversaries may use compression to obfuscate their payloads or files. Compressed file formats such as ZIP, gzip, 7z, and RAR can compress and archive multiple files together to make it easier and faster to transfer files. In addition to compressing files, adversaries may also compress shellcode directly - for example, in order to store it in a Windows Registry key (i.e., Fileless Storage). In order to further evade detection, adversaries may combine multiple ZIP files into one archive. This process of concatenation creates an archive that appears to be a single archive but in fact contains the central directories of the embedded archives. Some ZIP readers, such as 7zip, may not be able to identify concatenated ZIP files and miss the presence of the malicious payload. File archives may be s... Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1027. ATT&CK-mapped mitigations: M1049 Antivirus/Antimalware.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1027-016-junk-code-insertion",
    "title": "MITRE ATT&CK T1027.016: Junk Code Insertion (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1027.016 (Junk Code Insertion) is an Enterprise Stealth technique. Adversaries may use junk code / dead code to obfuscate a malware’s functionality. Junk code is code that either does not execute, or if it does execute, does not change the functionality of the code. Junk code makes analysis more difficult and time-consuming, as the analyst steps through non-functional code instead of analyzing the main code. It also may hinder detections that rely on static code analysis due to the use of benign functionality, especially when combined with Compression or Software Packing. No-Operation (NOP) instructions are an example of dead code commonly used in x86 assembly language. They are commonly used as the 0x90 opcode. When NOPs are added to malware, the disassembler may show the NOP instructions, leading to the analyst needing to step through them. The use of j... Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1027. ATT&CK-mapped mitigations: M1049 Antivirus/Antimalware.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1027-017-svg-smuggling",
    "title": "MITRE ATT&CK T1027.017: SVG Smuggling (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1027.017 (SVG Smuggling) is an Enterprise Stealth technique. Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign SVG files. SVGs, or Scalable Vector Graphics, are vector-based image files constructed using XML. As such, they can legitimately include `<script>` tags that enable adversaries to include malicious JavaScript payloads. However, SVGs may appear less suspicious to users than other types of executable files, as they are often treated as image files. SVG smuggling can take a number of forms. For example, threat actors may include content that: * Assembles malicious payloads * Downloads malicious payloads * Redirects users to malicious websites * Displays interactive content to users, such as fake login forms and download buttons. SVG Smuggling may be used in conjunction with HTML... Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1027. ATT&CK-mapped mitigations: M1048 Application Isolation and Sandboxing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1027-018-invisible-unicode",
    "title": "MITRE ATT&CK T1027.018: Invisible Unicode (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1027.018 (Invisible Unicode) is an Enterprise Stealth technique. Adversaries may abuse invisible or non-printing Unicode characters to conceal malicious content within files, scripts, or text. By inserting characters that do not visibly render, adversaries may hide data, alter how content is interpreted, or make malicious code appear as benign text or whitespace. Adversaries may encode these malicious payloads, using binary, Base64, or custom schemes, to be reconstructed at runtime through scripting features such as JavaScript Proxy traps, `eval()`, or other dynamic execution methods. This technique enables adversaries to evade visual inspection and basic static analysis by hiding malicious encoded content in innocuous text. Unicode is a standardized character encoding model that assigns a unique numerical value, known as a code point, to every characte... Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "mitre-attack-t1027-obfuscated-files-information",
    "title": "MITRE ATT&CK T1027: Obfuscated Files or Information (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1027 covers adversary use of obfuscation, encoding, encryption, and packing to evade detection. Sub-techniques include Binary Padding (T1027.001), Software Packing (T1027.002), Steganography (T1027.003), Compile After Delivery (T1027.004), Indicator Removal from Tools (T1027.005), HTML Smuggling (T1027.006), Dynamic API Resolution (T1027.007), and Stripped Payloads (T1027.008). Modern campaigns including APT41 (China), Lazarus (DPRK), and BianLian ransomware extensively use these techniques. Compliance obligations include behavioural detection (NIST 800-53 SI-3 with content-agnostic analysis), entropy-based anomaly detection, and detonation-based static analysis required under NIS2 Article 21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1059-command-and-scripting-interpreter",
      "cis-controls-v8"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1029-scheduled-transfer",
    "title": "MITRE ATT&CK T1029: Scheduled Transfer (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1029 (Scheduled Transfer) is an Enterprise Exfiltration technique. Adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals. This could be done to blend traffic patterns with normal activity or availability. When scheduled exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel or Exfiltration Over Alternative Protocol. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1030-data-transfer-size-limits",
    "title": "MITRE ATT&CK T1030: Data Transfer Size Limits (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1030 (Data Transfer Size Limits) is an Enterprise Exfiltration technique. An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds. This approach may be used to avoid triggering network data transfer threshold alerts. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1033-system-owner-user-discovery",
    "title": "MITRE ATT&CK T1033: System Owner/User Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1033 (System Owner/User Discovery) is an Enterprise Discovery technique. Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. Affected platforms: Linux, macOS, Windows, Network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1036-001-invalid-code-signature",
    "title": "MITRE ATT&CK T1036.001: Invalid Code Signature (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1036.001 (Invalid Code Signature) is an Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may attempt to mimic features of valid code signatures to increase the chance of deceiving a user, analyst, or tool. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. Adversaries can copy the metadata and signature information from a signed program, then use it as a template for an unsigned program. Affected platforms: macOS, Windows. MITRE-documented mitigations include M1045 Code Signing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-6, CM-7, IA-9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1036-002-right-to-left-override",
    "title": "MITRE ATT&CK T1036.002: Right-to-Left Override (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1036.002 (Right-to-Left Override) is an Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may abuse the right-to-left override (RTLO or RLO) character (U+202E) to disguise a string and/or file name to make it appear benign. RTLO is a non-printing Unicode character that causes the text that follows it to be displayed in reverse. For example, a Windows screensaver executable named March 25 \\u202Excod.scr will display as March 25 rcs.docx. A JavaScript file named photo_high_re\\u202Egnp.js will be displayed as photo_high_resj.png. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-6, CM-7, IA-9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1036-003-rename-system-utilities",
    "title": "MITRE ATT&CK T1036.003: Rename Legitimate Utilities (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1036.003 (Rename Legitimate Utilities) is an Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may rename legitimate system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for system utilities adversaries are capable of abusing. It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename rundll32.exe). Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-6, CM-7, IA-9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1036-004-masquerade-task-or-service",
    "title": "MITRE ATT&CK T1036.004: Masquerade Task or Service (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1036.004 (Masquerade Task or Service) is an Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description. Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones. Affected platforms: Windows, Linux, macOS. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-6, CM-7, IA-9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1036-005-match-legitimate-name-or-location",
    "title": "MITRE ATT&CK T1036.005: Match Legitimate Resource Name or Location (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1036.005 (Match Legitimate Resource Name or Location) is an Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: svchost.exe). In containerized environments, this may also be done by creating a resource in a namespace that matches the naming convention of a container pod or cluster. Affected platforms: Linux, macOS, Windows, Containers. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1038 Execution Prevention, M1045 Code Signing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-6, CM-7, IA-9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1036-006-space-after-filename",
    "title": "MITRE ATT&CK T1036.006: Space after Filename (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1036.006 (Space after Filename) is an Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries can hide a program's true filetype by changing the extension of a file. With certain file types (specifically this does not work with .app extensions), appending a space to the end of a filename will change how the file is processed by the operating system. For example, if there is a Mach-O executable file called evil.bin, when it is double clicked by a user, it will launch Terminal.app and execute. Affected platforms: Linux, macOS. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-6, CM-7, IA-9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1036-007-double-file-extension",
    "title": "MITRE ATT&CK T1036.007: Double File Extension (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1036.007 (Double File Extension) is an Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may abuse a double extension in the filename as a means of masquerading the true file type. A file name may include a secondary file type extension that may cause only the first extension to be displayed (ex: File.txt.exe may render in some views as just File.txt). However, the second extension is the true file type that determines how the file is opened and executed. Affected platforms: Windows. MITRE-documented mitigations include M1017 User Training, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-6, CM-7, IA-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1036-008-masquerade-file-type",
    "title": "MITRE ATT&CK T1036.008: Masquerade File Type (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1036.008 (Masquerade File Type) is an Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file's signature, extension, and contents. Various file types have a typical standard format, including how they are encoded and organized. For example, a file's signature (also known as header or magic bytes) is the beginning bytes of a file and is often used to identify the file's type. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint, M1049 Antivirus/Antimalware, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-6, CM-7, IA-9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1036-009-break-process-trees",
    "title": "MITRE ATT&CK T1036.009: Break Process Trees (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1036.009 (Break Process Trees) is an Enterprise Defense Evasion sub-technique of T1036 (Masquerading). An adversary may attempt to evade process tree-based analysis by modifying executed malware's parent process ID (PPID). If endpoint protection software leverages the \"parent-child\" relationship for detection, breaking this relationship could result in the adversary's behavior not being associated with previous process tree activity. On Unix-based systems breaking this process tree is common practice for administrators to execute software using scripts and programs. Affected platforms: Linux, macOS. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-6, CM-7, IA-9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1036-010-masquerade-account-name",
    "title": "MITRE ATT&CK T1036.010: Masquerade Account Name (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1036.010 (Masquerade Account Name) is an Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may match or approximate the names of legitimate accounts to make newly created ones appear benign. This will typically occur during Create Account, although accounts may also be renamed at a later date. This may also coincide with Account Access Removal if the actor first deletes an account before re-creating one with the same name. Often, adversaries will attempt to masquerade as service accounts, such as those associated with legitimate software, data backups, or container cluster management. Affected platforms: Linux, macOS, Windows, SaaS, IaaS, Containers, Office Suite, Identity Provider. MITRE-documented mitigations include M1047 Audit, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-6, CM-7, IA-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1036-011-overwrite-process-arguments",
    "title": "MITRE ATT&CK T1036.011: Overwrite Process Arguments (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1036.011 (Overwrite Process Arguments) is an Enterprise Stealth technique. Adversaries may modify a process's in-memory arguments to change its name in order to appear as a legitimate or benign process. On Linux, the operating system stores command-line arguments in the process’s stack and passes them to the `main()` function as the `argv` array. The first element, `argv[0]`, typically contains the process name or path - by default, the command used to actually start the process (e.g., `cat /etc/passwd`). By default, the Linux `/proc` filesystem uses this value to represent the process name. The `/proc/<PID>/cmdline` file reflects the contents of this memory, and tools like `ps` use it to display process information. Since arguments are stored in user-space memory at launch, this modification can be performed without elevated privileges. During runtime, adversari... Affected platforms: Linux. Sub-technique of ATT&CK T1036.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "mitre-attack-t1036-012-browser-fingerprint",
    "title": "MITRE ATT&CK T1036.012: Browser Fingerprint (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1036.012 (Browser Fingerprint) is an Enterprise Stealth technique. Adversaries may attempt to blend in with legitimate traffic by spoofing browser and system attributes like operating system, system language, platform, user-agent string, resolution, time zone, etc. The HTTP User-Agent request header is a string that lets servers and network peers identify the application, operating system, vendor, and/or version of the requesting user agent. Adversaries may gather this information through System Information Discovery or by users navigating to adversary-controlled websites, and then use that information to craft their web traffic to evade defenses. Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1036. ATT&CK-mapped mitigations: M1047 Audit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1036-masquerading",
    "title": "MITRE ATT&CK T1036: Masquerading (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1036 (Masquerading) is an Enterprise Defense Evasion technique. Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. ATT&CK documents 10 sub-techniques: T1036.001 Invalid Code Signature; T1036.002 Right-to-Left Override; T1036.003 Rename System Utilities; T1036.004 Masquerade Task or Service; T1036.005 Match Legitimate Name or Location; T1036.006 Space after Filename; T1036.007 Double File Extension; T1036.008 Masquerade File Type; T1036.009 Break Process Trees; T1036.010 Masquerade Account Name. Affected platforms: Linux, macOS, Windows, Containers. MITRE-documented mitigations include M1047 Audit, M1018 User Account Management, M1017 User Training, M1045 Code Signing, M1040 Behavior Prevention on Endpoint, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-6, CM-7, IA-9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1037-001-logon-script-windows",
    "title": "MITRE ATT&CK T1037.001: Logon Script (Windows) (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1037.001 (Logon Script (Windows)) is an Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence. Windows allows logon scripts to be run whenever a specific user or group of users log into a system. This is done via adding a path to a script to the HKCU\\Environment\\UserInitMprLogonScript Registry key. Adversaries may use these scripts to maintain persistence on a single system. Affected platforms: Windows. MITRE-documented mitigations include M1024 Restrict Registry Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-17, CA-7, CM-2, CM-6, CM-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1037-boot-or-logon-initialization-scripts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1037-002-login-hook",
    "title": "MITRE ATT&CK T1037.002: Login Hook (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1037.002 (Login Hook) is an Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may use a Login Hook to establish persistence executed upon user logon. A login hook is a plist file that points to a specific script to execute with root privileges upon user logon. The plist file is located in the /Library/Preferences/com.apple.loginwindow.plist file and can be modified using the defaults command-line utility. This behavior is the same for logout hooks where a script can be executed upon user logout. All hooks require administrator permissions to modify or create hooks. Affected platforms: macOS. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-17, CA-7, CM-2, CM-6, CM-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1037-boot-or-logon-initialization-scripts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1037-003-network-logon-script",
    "title": "MITRE ATT&CK T1037.003: Network Logon Script (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1037.003 (Network Logon Script) is an Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may use network logon scripts automatically executed at logon initialization to establish persistence. Network logon scripts can be assigned using Active Directory or Group Policy Objects. These logon scripts run with the privileges of the user they are assigned to. Depending on the systems within the network, initializing one of these scripts could apply to more than one or potentially all systems. Adversaries may use these scripts to maintain persistence on a network. Affected platforms: Windows. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-17, CA-7, CM-2, CM-6, CM-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1037-boot-or-logon-initialization-scripts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1037-004-rc-scripts",
    "title": "MITRE ATT&CK T1037.004: RC Scripts (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1037.004 (RC Scripts) is an Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may establish persistence by modifying RC scripts which are executed during a Unix-like system's startup. These files allow system administrators to map and start custom services at startup for different run levels. RC scripts require root privileges to modify. Adversaries can establish persistence by adding a malicious binary path or shell commands to rc.local, rc.common, and other RC scripts specific to the Unix-like distribution. Affected platforms: macOS, Linux, Network. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-17, CA-7, CM-2, CM-6, CM-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1037-boot-or-logon-initialization-scripts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1037-005-startup-items",
    "title": "MITRE ATT&CK T1037.005: Startup Items (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1037.005 (Startup Items) is an Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may use startup items automatically executed at boot initialization to establish persistence. Startup items execute during the final phase of the boot process and contain shell scripts or other executable files along with configuration information used by the system to determine the execution order for all startup items. Affected platforms: macOS. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-17, CA-7, CM-2, CM-6, CM-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1037-boot-or-logon-initialization-scripts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1037-boot-or-logon-initialization-scripts",
    "title": "MITRE ATT&CK T1037: Boot or Logon Initialization Scripts (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1037 (Boot or Logon Initialization Scripts) is an Enterprise Persistence and Privilege Escalation technique. Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence. Initialization scripts can be used to perform administrative functions, which may often execute other programs or send information to an internal logging server. These scripts can vary based on operating system and whether applied locally or remotely. Adversaries may use these scripts to maintain persistence on a single system. ATT&CK documents 5 sub-techniques: T1037.001 Logon Script (Windows); T1037.002 Login Hook; T1037.003 Network Logon Script; T1037.004 RC Scripts; T1037.005 Startup Items. Affected platforms: macOS, Windows, Linux, Network. MITRE-documented mitigations include M1024 Restrict Registry Permissions, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-17, CA-7, CM-2, CM-6, CM-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1039-data-from-network-shared-drive",
    "title": "MITRE ATT&CK T1039: Data from Network Shared Drive (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1039 (Data from Network Shared Drive) is an Enterprise Collection technique. Adversaries may search network shares on computers they have compromised to find files of interest. Sensitive data can be collected from remote systems via shared network drives (host shared directory, network file server, etc.) that are accessible from the current system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information. Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1040-network-sniffing",
    "title": "MITRE ATT&CK T1040: Network Sniffing (Enterprise Tactic TA0006 - Credential Access / TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1040 (Network Sniffing) is an Enterprise Credential Access and Discovery technique. Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data. Affected platforms: Linux, macOS, Windows, Network, IaaS. MITRE-documented mitigations include M1018 User Account Management, M1032 Multi-factor Authentication, M1041 Encrypt Sensitive Information, M1030 Network Segmentation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-16, AC-17, AC-18, AC-19, CM-7, IA-2, IA-5, SC-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1041-exfiltration-over-c2-channel",
    "title": "MITRE ATT&CK T1041: Exfiltration Over C2 Channel (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1041 covers adversary exfiltration of stolen data over the same command-and-control channel used for adversary communication, blending data theft with normal C2 traffic. This is the dominant exfiltration pattern in modern ransomware double-extortion intrusions (LockBit, BlackCat, Cl0p). Compliance obligations include data loss prevention under NIST SP 800-53 SC-7(10), AC-4, SI-4(4), ISO 27001 A.8.12, NIS2 Article 21(2)(b), DORA Article 10, PCI DSS Req 11.4, HIPAA 164.308(a)(1)(ii)(D), GDPR Article 32, and US state breach notification laws.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1071-application-layer-protocol",
      "mitre-attack-t1078-valid-accounts"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1046-network-service-discovery",
    "title": "MITRE ATT&CK T1046: Network Service Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1046 (Network Service Discovery) is an Enterprise Discovery technique. Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port and/or vulnerability scans using tools that are brought onto a system. Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Affected platforms: Windows, IaaS, Linux, macOS, Containers, Network. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1031 Network Intrusion Prevention, M1030 Network Segmentation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, CM-8, RA-5, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1047-windows-management-instrumentation",
    "title": "MITRE ATT&CK T1047: Windows Management Instrumentation (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1047 (Windows Management Instrumentation) is an Enterprise Execution technique. Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1040 Behavior Prevention on Endpoint, M1018 User Account Management, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1048-001-exfiltration-over-symmetric-encrypted-non-c2-protocol",
    "title": "MITRE ATT&CK T1048.001: Exfiltration Over Symmetric Encrypted Non-C2 Protocol (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1048.001 (Exfiltration Over Symmetric Encrypted Non-C2 Protocol) is an Enterprise Exfiltration sub-technique of T1048 (Exfiltration Over Alternative Protocol). Adversaries may steal data by exfiltrating it over a symmetrically encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Symmetric encryption algorithms are those that use shared or the same keys/secrets on each end of the channel. This requires an exchange or pre-arranged agreement/possession of the value used to encrypt and decrypt data. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1037 Filter Network Traffic, M1031 Network Intrusion Prevention, M1030 Network Segmentation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-6, AC-16, AC-20, AC-23, CA-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1048-exfiltration-over-alternative-protocol"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1048-002-exfiltration-over-asymmetric-encrypted-non-c2-protocol",
    "title": "MITRE ATT&CK T1048.002: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1048.002 (Exfiltration Over Asymmetric Encrypted Non-C2 Protocol) is an Enterprise Exfiltration sub-technique of T1048 (Exfiltration Over Alternative Protocol). Adversaries may steal data by exfiltrating it over an asymmetrically encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Asymmetric encryption algorithms are those that use different keys on each end of the channel. Also known as public-key cryptography, this requires pairs of cryptographic keys that can encrypt/decrypt data from the corresponding key. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention, M1030 Network Segmentation, M1037 Filter Network Traffic, M1057 Data Loss Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-6, AC-16, AC-20, AC-23, CA-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1048-exfiltration-over-alternative-protocol"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1048-003-exfiltration-over-unencrypted-non-c2-protocol",
    "title": "MITRE ATT&CK T1048.003: Exfiltration Over Unencrypted Non-C2 Protocol (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1048.003 (Exfiltration Over Unencrypted Non-C2 Protocol) is an Enterprise Exfiltration sub-technique of T1048 (Exfiltration Over Alternative Protocol). Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Adversaries may opt to obfuscate this data, without the use of encryption, within network protocols that are natively unencrypted (such as HTTP, FTP, or DNS). Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1031 Network Intrusion Prevention, M1057 Data Loss Prevention, M1037 Filter Network Traffic, M1030 Network Segmentation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-6, AC-16, AC-20, AC-23, CA-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1048-exfiltration-over-alternative-protocol"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1048-exfiltration-over-alternative-protocol",
    "title": "MITRE ATT&CK T1048: Exfiltration Over Alternative Protocol (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1048 (Exfiltration Over Alternative Protocol) is an Enterprise Exfiltration technique. Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Alternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Adversaries may also opt to encrypt and/or obfuscate these alternate channels. ATT&CK documents 3 sub-techniques: T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol; T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol; T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol. Affected platforms: Linux, macOS, Windows, SaaS, IaaS, Network, Office Suite. MITRE-documented mitigations include M1030 Network Segmentation, M1057 Data Loss Prevention, M1037 Filter Network Traffic, M1031 Network Intrusion Prevention, M1022 Restrict File and Directory Permissions, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-6, AC-16, AC-20, AC-23, CA-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1049-system-network-connections-discovery",
    "title": "MITRE ATT&CK T1049: System Network Connections Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1049 (System Network Connections Discovery) is an Enterprise Discovery technique. Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network. An adversary who gains access to a system that is part of a cloud-based environment may map out Virtual Private Clouds or Virtual Networks in order to determine what systems and services are connected. Affected platforms: Windows, IaaS, Linux, macOS, Network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1052-001-exfiltration-over-usb",
    "title": "MITRE ATT&CK T1052.001: Exfiltration over USB (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1052.001 (Exfiltration over USB) is an Enterprise Exfiltration sub-technique of T1052 (Exfiltration Over Physical Medium). Adversaries may attempt to exfiltrate data over a USB connected physical device. In certain circumstances, such as an air-gapped network compromise, exfiltration could occur via a USB device introduced by a user. The USB device could be used as the final exfiltration point or to hop between otherwise disconnected systems. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1034 Limit Hardware Installation, M1057 Data Loss Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, AC-16, AC-20, AC-23, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1052-exfiltration-over-physical-medium"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1052-exfiltration-over-physical-medium",
    "title": "MITRE ATT&CK T1052: Exfiltration Over Physical Medium (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1052 (Exfiltration Over Physical Medium) is an Enterprise Exfiltration technique. Adversaries may attempt to exfiltrate data via a physical medium, such as a removable drive. In certain circumstances, such as an air-gapped network compromise, exfiltration could occur via a physical medium or device introduced by a user. Such media could be an external hard drive, USB drive, cellular phone, MP3 player, or other removable storage and processing device. The physical medium or device could be used as the final exfiltration point or to hop between otherwise disconnected systems. ATT&CK documents 1 sub-technique: T1052.001 Exfiltration over USB. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1057 Data Loss Prevention, M1034 Limit Hardware Installation, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, AC-16, AC-20, AC-23, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1053-002-at",
    "title": "MITRE ATT&CK T1053.002: At (Enterprise Tactic TA0002 - Execution / TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1053.002 (At) is an Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code. The at utility exists as an executable within Windows, Linux, and macOS for scheduling tasks at a specified time and date. Although deprecated in favor of Scheduled Task's schtasks in Windows environments, using at requires that the Task Scheduler service be running, and the user to be logged on as a member of the local Administrators group. Affected platforms: Windows, Linux, macOS. MITRE-documented mitigations include M1028 Operating System Configuration, M1047 Audit, M1018 User Account Management, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1053-scheduled-task-job"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1053-003-cron",
    "title": "MITRE ATT&CK T1053.003: Cron (Enterprise Tactic TA0002 - Execution / TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1053.003 (Cron) is an Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the cron utility to perform task scheduling for initial or recurring execution of malicious code. The cron utility is a time-based job scheduler for Unix-like operating systems. The crontab file contains the schedule of cron entries to be run and the specified times for execution. Any crontab files are stored in operating system-specific file paths. An adversary may use cron in Linux or Unix environments to execute programs at system startup or on a scheduled basis for Persistence. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1047 Audit, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1053-scheduled-task-job"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1053-005-scheduled-task",
    "title": "MITRE ATT&CK T1053.005: Scheduled Task (Enterprise Tactic TA0002 - Execution / TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1053.005 (Scheduled Task) is an Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1018 User Account Management, M1047 Audit, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1053-scheduled-task-job"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1053-006-systemd-timers",
    "title": "MITRE ATT&CK T1053.006: Systemd Timers (Enterprise Tactic TA0002 - Execution / TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1053.006 (Systemd Timers) is an Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code. Systemd timers are unit files with file extension .timer that control services. Timers can be set to run on a calendar event or after a time span relative to a starting point. They can be used as an alternative to Cron in Linux environments. Systemd timers may be activated remotely via the systemctl command line utility, which operates over SSH. Affected platforms: Linux. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1018 User Account Management, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1053-scheduled-task-job"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1053-007-container-orchestration-job",
    "title": "MITRE ATT&CK T1053.007: Container Orchestration Job (Enterprise Tactic TA0002 - Execution / TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1053.007 (Container Orchestration Job) is an Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse task scheduling functionality provided by container orchestration tools such as Kubernetes to schedule deployment of containers configured to execute malicious code. Container orchestration jobs run these automated tasks at a specific date and time, similar to cron jobs on a Linux system. Deployments of this type can also be configured to maintain a quantity of containers over time, automating the process of maintaining persistence within a cluster. Affected platforms: Containers. MITRE-documented mitigations include M1018 User Account Management, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1053-scheduled-task-job"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1053-scheduled-task-job",
    "title": "MITRE ATT&CK T1053: Scheduled Task/Job (Enterprise Tactic TA0002 - Execution / TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1053 (Scheduled Task/Job) is an Enterprise Execution and Persistence and Privilege Escalation technique. Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). ATT&CK documents 5 sub-techniques: T1053.002 At; T1053.003 Cron; T1053.005 Scheduled Task; T1053.006 Systemd Timers; T1053.007 Container Orchestration Job. Affected platforms: Windows, Linux, macOS, Containers. MITRE-documented mitigations include M1018 User Account Management, M1028 Operating System Configuration, M1022 Restrict File and Directory Permissions, M1026 Privileged Account Management, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1055-001-dynamic-link-library-injection",
    "title": "MITRE ATT&CK T1055.001: Dynamic-link Library Injection (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1055.001 (Dynamic-link Library Injection) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges. DLL injection is a method of executing arbitrary code in the address space of a separate live process. DLL injection is commonly performed by writing the path to a DLL in the virtual address space of the target process before loading the DLL by invoking a new thread. Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1055-002-portable-executable-injection",
    "title": "MITRE ATT&CK T1055.002: Portable Executable Injection (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1055.002 (Portable Executable Injection) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges. PE injection is a method of executing arbitrary code in the address space of a separate live process. PE injection is commonly performed by copying code (perhaps without a file on disk) into the virtual address space of the target process before invoking it via a new thread. Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1055-003-thread-execution-hijacking",
    "title": "MITRE ATT&CK T1055.003: Thread Execution Hijacking (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1055.003 (Thread Execution Hijacking) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges. Thread Execution Hijacking is a method of executing arbitrary code in the address space of a separate live process. Thread Execution Hijacking is commonly performed by suspending an existing process then unmapping/hollowing its memory, which can then be replaced with malicious code or the path to a DLL. Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1055-004-asynchronous-procedure-call",
    "title": "MITRE ATT&CK T1055.004: Asynchronous Procedure Call (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1055.004 (Asynchronous Procedure Call) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based defenses as well as possibly elevate privileges. APC injection is a method of executing arbitrary code in the address space of a separate live process. APC injection is commonly performed by attaching malicious code to the APC Queue of a process's thread. Queued APC functions are executed when the thread enters an alterable state. Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1055-005-thread-local-storage",
    "title": "MITRE ATT&CK T1055.005: Thread Local Storage (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1055.005 (Thread Local Storage) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via thread local storage (TLS) callbacks in order to evade process-based defenses as well as possibly elevate privileges. TLS callback injection is a method of executing arbitrary code in the address space of a separate live process. TLS callback injection involves manipulating pointers inside a portable executable (PE) to redirect a process to malicious code before reaching the code's legitimate entry point. Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1055-008-ptrace-system-calls",
    "title": "MITRE ATT&CK T1055.008: Ptrace System Calls (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1055.008 (Ptrace System Calls) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges. Ptrace system call injection is a method of executing arbitrary code in the address space of a separate live process. Ptrace system call injection involves attaching to and modifying a running process. Affected platforms: Linux. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1055-009-proc-memory",
    "title": "MITRE ATT&CK T1055.009: Proc Memory (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1055.009 (Proc Memory) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as possibly elevate privileges. Proc memory injection is a method of executing arbitrary code in the address space of a separate live process. Proc memory injection involves enumerating the memory of a process via the /proc filesystem (/proc/[pid]) then crafting a return-oriented programming (ROP) payload with available gadgets/instructions. Affected platforms: Linux. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-5, CM-6, IA-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1055-011-extra-window-memory-injection",
    "title": "MITRE ATT&CK T1055.011: Extra Window Memory Injection (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1055.011 (Extra Window Memory Injection) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into process via Extra Window Memory (EWM) in order to evade process-based defenses as well as possibly elevate privileges. EWM injection is a method of executing arbitrary code in the address space of a separate live process. Before creating a window, graphical Windows-based processes must prescribe to or register a windows class, which stipulate appearance and behavior (via windows procedures, which are functions that handle input/output of data). Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1055-012-process-hollowing",
    "title": "MITRE ATT&CK T1055.012: Process Hollowing (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1055.012 (Process Hollowing) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process. Process hollowing is commonly performed by creating a process in a suspended state then unmapping/hollowing its memory, which can then be replaced with malicious code. Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1055-013-process-doppelg-nging",
    "title": "MITRE ATT&CK T1055.013: Process Doppelgänging (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1055.013 (Process Doppelgänging) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into process via process doppelgänging in order to evade process-based defenses as well as possibly elevate privileges. Process doppelgänging is a method of executing arbitrary code in the address space of a separate live process. Windows Transactional NTFS (TxF) was introduced in Vista as a method to perform safe file operations. To ensure data integrity, TxF enables only one transacted handle to write to a file at a given time. Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1055-014-vdso-hijacking",
    "title": "MITRE ATT&CK T1055.014: VDSO Hijacking (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1055.014 (VDSO Hijacking) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via VDSO hijacking in order to evade process-based defenses as well as possibly elevate privileges. Virtual dynamic shared object (vdso) hijacking is a method of executing arbitrary code in the address space of a separate live process. VDSO hijacking involves redirecting calls to dynamically linked shared libraries. Memory protections may prevent writing executable code to a process via Ptrace System Calls. Affected platforms: Linux. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1055-015-listplanting",
    "title": "MITRE ATT&CK T1055.015: ListPlanting (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1055.015 (ListPlanting) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may abuse list-view controls to inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges. ListPlanting is a method of executing arbitrary code in the address space of a separate live process. Code executed via ListPlanting may also evade detection from security products since the execution is masked under a legitimate process. List-view controls are user interface windows used to display collections of items. Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1055-process-injection",
    "title": "MITRE ATT&CK T1055: Process Injection (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1055 (Process Injection) is an Enterprise Defense Evasion and Privilege Escalation technique. Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process. ATT&CK documents 12 sub-techniques: T1055.001 Dynamic-link Library Injection; T1055.002 Portable Executable Injection; T1055.003 Thread Execution Hijacking; T1055.004 Asynchronous Procedure Call; T1055.005 Thread Local Storage; T1055.008 Ptrace System Calls; T1055.009 Proc Memory; T1055.011 Extra Window Memory Injection; T1055.012 Process Hollowing; T1055.013 Process Doppelgänging; T1055.014 VDSO Hijacking; T1055.015 ListPlanting. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1056-001-keylogging",
    "title": "MITRE ATT&CK T1056.001: Keylogging (Enterprise Tactic TA0009 - Collection / TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1056.001 (Keylogging) is an Enterprise Collection and Credential Access sub-technique of T1056 (Input Capture). Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. Affected platforms: Windows, macOS, Linux, Network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1056-input-capture"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1056-002-gui-input-capture",
    "title": "MITRE ATT&CK T1056.002: GUI Input Capture (Enterprise Tactic TA0009 - Collection / TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1056.002 (GUI Input Capture) is an Enterprise Collection and Credential Access sub-technique of T1056 (Input Capture). Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt. When programs are executed that need additional privileges than are present in the current user context, it is common for the operating system to prompt the user for proper credentials to authorize the elevated privileges for the task (ex: Bypass User Account Control). Affected platforms: macOS, Windows, Linux. MITRE-documented mitigations include M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CA-7, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1056-input-capture"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1056-003-web-portal-capture",
    "title": "MITRE ATT&CK T1056.003: Web Portal Capture (Enterprise Tactic TA0009 - Collection / TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1056.003 (Web Portal Capture) is an Enterprise Collection and Credential Access sub-technique of T1056 (Input Capture). Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service. For example, a compromised login page may log provided user credentials before logging the user in to the service. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1056-input-capture"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1056-004-credential-api-hooking",
    "title": "MITRE ATT&CK T1056.004: Credential API Hooking (Enterprise Tactic TA0009 - Collection / TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1056.004 (Credential API Hooking) is an Enterprise Collection and Credential Access sub-technique of T1056 (Input Capture). Adversaries may hook into Windows application programming interface (API) functions to collect user credentials. Malicious hooking mechanisms may capture API calls that include parameters that reveal user authentication credentials. Unlike Keylogging, this technique focuses specifically on API functions that include parameters that reveal user credentials. Affected platforms: Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1056-input-capture"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1056-input-capture",
    "title": "MITRE ATT&CK T1056: Input Capture (Enterprise Tactic TA0009 - Collection / TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1056 (Input Capture) is an Enterprise Collection and Credential Access technique. Adversaries may use methods of capturing user input to obtain credentials or collect information. During normal system usage, users often provide credentials to various different locations, such as login pages/portals or system dialog boxes. Input capture mechanisms may be transparent to the user (e.g. Credential API Hooking) or rely on deceiving the user into providing input into what they believe to be a genuine service (e.g. Web Portal Capture). ATT&CK documents 4 sub-techniques: T1056.001 Keylogging; T1056.002 GUI Input Capture; T1056.003 Web Portal Capture; T1056.004 Credential API Hooking. Affected platforms: Linux, macOS, Windows, Network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1057-process-discovery",
    "title": "MITRE ATT&CK T1057: Process Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1057 describes adversary enumeration of running processes to identify security tools, valuable applications, and post-exploitation opportunities. Common commands include tasklist, Get-Process, ps, and direct API calls. Process enumeration is typically followed by Impair Defenses (T1562) once security tools are identified. Compliance obligations include endpoint detection coverage (NIST 800-53 SI-3 and SI-4), command-line audit logging required by PCI DSS Req 10.2.1.7, and behavioural correlation analytics under DORA Article 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1059-command-and-scripting-interpreter",
      "mitre-t1562"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1059-001-powershell",
    "title": "MITRE ATT&CK T1059.001: PowerShell (Sub-Technique of T1059 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1059.001 covers adversary abuse of PowerShell for execution, lateral movement, and discovery. PowerShell is the dominant living-off-the-land interpreter on Windows: every modern ransomware operator (LockBit, BlackCat, Cl0p, Akira, Royal) uses PowerShell for at least one stage. Empire, PoshC2, Nishang, PowerSploit, and Cobalt Strike provide weaponised PowerShell payloads. Compliance obligations include NIST SP 800-53 SI-7 (Software Integrity), CM-7 (Least Functionality), SI-3 (Malicious Code Protection), AU-2 (Event Logging), ISO 27001 A.8.19, A.8.16, PCI DSS Req 10.4, and CIS Microsoft Windows Server Benchmark.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1059-command-and-scripting-interpreter",
      "mitre-attack-t1204-user-execution",
      "mitre-attack-t1106-native-api",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1059-002-applescript",
    "title": "MITRE ATT&CK T1059.002: AppleScript (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1059.002 (AppleScript) is an Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse AppleScript for execution. AppleScript is a macOS scripting language designed to control applications and parts of the OS via inter-application messages called AppleEvents. These AppleEvent messages can be sent independently or easily scripted with AppleScript. These events can locate open windows, send keystrokes, and interact with almost any open application locally or remotely. Scripts can be run from the command-line via osascript /path/to/script or osascript -e \"script here\". Affected platforms: macOS. MITRE-documented mitigations include M1045 Code Signing, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1059-command-and-scripting-interpreter"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1059-003-windows-command-shell",
    "title": "MITRE ATT&CK T1059.003: Windows Command Shell (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1059.003 (Windows Command Shell) is an Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1059-command-and-scripting-interpreter"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1059-004-unix-shell",
    "title": "MITRE ATT&CK T1059.004: Unix Shell (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1059.004 (Unix Shell) is an Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux and macOS systems, though many variations of the Unix shell exist (e.g. sh, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges. Affected platforms: macOS, Linux, Network. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1059-command-and-scripting-interpreter"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1059-005-visual-basic",
    "title": "MITRE ATT&CK T1059.005: Visual Basic (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1059.005 (Visual Basic) is an Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as Component Object Model and the Native API through the Windows API. Although tagged as legacy with no planned future evolutions, VB is integrated and supported in the .NET Framework and cross-platform .NET Core. Derivative languages based on VB have also been created, such as Visual Basic for Applications (VBA) and VBScript. Affected platforms: Windows, macOS, Linux. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1049 Antivirus/Antimalware, M1038 Execution Prevention, M1040 Behavior Prevention on Endpoint, M1021 Restrict Web-Based Content. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1059-command-and-scripting-interpreter"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1059-006-python",
    "title": "MITRE ATT&CK T1059.006: Python (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1059.006 (Python) is an Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the python.exe interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables. Python comes with many built-in packages to interact with the underlying system, such as file operations and device I/O. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1047 Audit, M1049 Antivirus/Antimalware, M1033 Limit Software Installation, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1059-command-and-scripting-interpreter"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1059-007-javascript",
    "title": "MITRE ATT&CK T1059.007: JavaScript (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1059.007 (JavaScript) is an Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser. JScript is the Microsoft implementation of the same scripting standard. Affected platforms: Windows, macOS, Linux. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint, M1038 Execution Prevention, M1042 Disable or Remove Feature or Program, M1021 Restrict Web-Based Content. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1059-command-and-scripting-interpreter"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1059-008-network-device-cli",
    "title": "MITRE ATT&CK T1059.008: Network Device CLI (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1059.008 (Network Device CLI) is an Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse scripting or built-in command line interpreters (CLI) on network devices to execute malicious command and payloads. The CLI is the primary means through which users and administrators interact with the device in order to view system information, modify device operations, or perform diagnostic and administrative functions. CLIs typically contain various permission levels required for different commands. Affected platforms: Network. MITRE-documented mitigations include M1038 Execution Prevention, M1026 Privileged Account Management, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1059-command-and-scripting-interpreter"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1059-009-cloud-api",
    "title": "MITRE ATT&CK T1059.009: Cloud API (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1059.009 (Cloud API) is an Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse cloud APIs to execute malicious commands. APIs available in cloud environments provide various functionalities and are a feature-rich method for programmatic access to nearly all aspects of a tenant. These APIs may be utilized through various methods such as command line interpreters (CLIs), in-browser Cloud Shells, PowerShell modules like Azure for PowerShell, or software developer kits (SDKs) available for languages such as Python. Affected platforms: IaaS, SaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1038 Execution Prevention, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1059-command-and-scripting-interpreter"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1059-010-autohotkey-autoit",
    "title": "MITRE ATT&CK T1059.010: AutoHotKey & AutoIT (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1059.010 (AutoHotKey & AutoIT) is an Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may execute commands and perform malicious tasks using AutoIT and AutoHotKey automation scripts. AutoIT and AutoHotkey (AHK) are scripting languages that enable users to automate Windows tasks. These automation scripts can be used to perform a wide variety of actions, such as clicking on buttons, entering text, and opening and closing programs. Adversaries may use AHK (.ahk) and AutoIT (.au3) scripts to execute malicious code on a victim's system. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1059-command-and-scripting-interpreter"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1059-011-lua",
    "title": "MITRE ATT&CK T1059.011: Lua (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1059.011 (Lua) is an Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse Lua commands and scripts for execution. Lua is a cross-platform scripting and programming language primarily designed for embedded use in applications. Lua can be executed on the command-line (through the stand-alone lua interpreter), via scripts (.lua), or from Lua-embedded programs (through the struct lua_State). Lua scripts may be executed by adversaries for malicious purposes. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1033 Limit Software Installation, M1047 Audit, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1059-command-and-scripting-interpreter"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1059-012-hypervisor-cli",
    "title": "MITRE ATT&CK T1059.012: Hypervisor CLI (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1059.012 (Hypervisor CLI) is an Enterprise Execution technique. Adversaries may abuse hypervisor command line interpreters (CLIs) to execute malicious commands. Hypervisor CLIs typically enable a wide variety of functionality for managing both the hypervisor itself and the guest virtual machines it hosts. For example, on ESXi systems, tools such as `esxcli` and `vim-cmd` allow administrators to configure firewall rules and log forwarding on the hypervisor, list virtual machines, start and stop virtual machines, and more. Adversaries may be able to leverage these tools in order to support further actions, such as File and Directory Discovery or Data Encrypted for Impact. Affected platforms: ESXi. Sub-technique of ATT&CK T1059.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "mitre-attack-t1059-013-container-cli-api",
    "title": "MITRE ATT&CK T1059.013: Container CLI/API (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1059.013 (Container CLI/API) is an Enterprise Execution technique. Adversaries may abuse built-in CLI tools or API calls to execute malicious commands in containerized environments. The Docker CLI is used for managing containers via an exposed API point from the `dockerd` daemon. Some common examples of Docker CLI include Docker Desktop CLI and Docker Compose, but users are also able to use SDKs to interact with the API. For example, Docker SDK for Python can be used to run commands within a Python application. Adversaries may leverage the Docker CLI, API, or SDK to pull or build Docker images (i.e., Ingress Tool Transfer, Build Image on Host), run containers (i.e., Deploy Container), or execute commands inside running containers (i.e., Container Administration Command). In some cases, threat actors may pull legitimate images that include scripts or tools... Affected platforms: Containers. Sub-technique of ATT&CK T1059. ATT&CK-mapped mitigations: M1026 Privileged Account Management, M1038 Execution Prevention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1059-command-and-scripting-interpreter",
    "title": "MITRE ATT&CK T1059: Command and Scripting Interpreter (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1059 covers adversary abuse of command and scripting interpreters (PowerShell, Bash, Python, JavaScript, Visual Basic, Windows Command Shell, Network Device CLI) to execute commands, scripts, and binaries. The technique has 10 named sub-techniques and is one of the most prevalent execution methods because interpreters are pre-installed and trusted. Notable adversary use includes living-off-the-land attacks (LOLBins) by APT29, Lazarus, and FIN7. Compliance obligations include script execution policy enforcement (NIST 800-53 CM-7, ISO A.8.19), constrained language mode for PowerShell, and behavioural EDR coverage required under PCI DSS Req 5 and NIS2 Article 21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-t1562"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1068-exploitation-privilege-escalation",
    "title": "MITRE ATT&CK T1068: Exploitation for Privilege Escalation (Enterprise Tactic TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1068 covers adversary exploitation of software vulnerabilities to elevate privileges from a lower-privilege context to higher (user to admin, admin to system, container escape to host). Notable real-world exploits include PrintNightmare (CVE-2021-34527), Spring4Shell (CVE-2022-22965), Polkit/PwnKit (CVE-2021-4034), and the Windows ALPC LPE chain. Compliance obligations include rapid privilege-escalation CVE patching (NIST 800-53 SI-2 mandates expedited patching for critical/KEV vulnerabilities), Exploit Protection (NIST SP 800-53 SI-16), and CISA BOD 22-01 mandatory patching for federal civilian agencies on a 2-week SLA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1190-exploit-public-facing-application",
      "nist-csf-20-protect-function-pr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1069-001-local-groups",
    "title": "MITRE ATT&CK T1069.001: Local Groups (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1069.001 (Local Groups) is an Enterprise Discovery sub-technique of T1069 (Permission Groups Discovery). Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group. Commands such as net localgroup of the Net utility, dscl . -list /Groups on macOS, and groups on Linux can list local groups. Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1069-permission-groups-discovery"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1069-002-domain-groups",
    "title": "MITRE ATT&CK T1069.002: Domain Groups (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1069.002 (Domain Groups) is an Enterprise Discovery sub-technique of T1069 (Permission Groups Discovery). Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators. Commands such as net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on Linux can list domain-level groups. Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1069-permission-groups-discovery"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1069-003-cloud-groups",
    "title": "MITRE ATT&CK T1069.003: Cloud Groups (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1069.003 (Cloud Groups) is an Enterprise Discovery sub-technique of T1069 (Permission Groups Discovery). Adversaries may attempt to find cloud groups and permission settings. The knowledge of cloud permission groups can help adversaries determine the particular roles of users and groups within an environment, as well as which users are associated with a particular group. With authenticated access there are several tools that can be used to find permissions groups. The Get-MsolRole PowerShell cmdlet can be used to obtain roles and permissions groups for Exchange and Office 365 accounts . Affected platforms: SaaS, IaaS, Office Suite, Identity Provider.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1069-permission-groups-discovery"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1069-permission-groups-discovery",
    "title": "MITRE ATT&CK T1069: Permission Groups Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1069 (Permission Groups Discovery) is an Enterprise Discovery technique. Adversaries may attempt to discover group and permission settings. This information can help adversaries determine which user accounts and groups are available, the membership of users in particular groups, and which users and groups have elevated permissions. Adversaries may attempt to discover group permission settings in many different ways. This data may provide the adversary with information about the compromised environment that can be used in follow-on activity and targeting. ATT&CK documents 3 sub-techniques: T1069.001 Local Groups; T1069.002 Domain Groups; T1069.003 Cloud Groups. Affected platforms: Windows, SaaS, IaaS, Linux, macOS, Containers, Office Suite, Identity Provider.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1070-003-clear-command-history",
    "title": "MITRE ATT&CK T1070.003: Clear Command History (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1070.003 (Clear Command History) is an Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion. Various command interpreters keep track of the commands users type in their terminal so that users can retrace what they've done. On Linux and macOS, these command histories can be accessed in a few different ways. While logged in, this command history is tracked in a file pointed to by the environment variable HISTFILE. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1029 Remote Data Storage, M1022 Restrict File and Directory Permissions, M1039 Environment Variable Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1070-indicator-removal"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1070-004-file-deletion",
    "title": "MITRE ATT&CK T1070.004: File Deletion (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1070.004 (File Deletion) is an Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1070-indicator-removal"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1070-005-network-share-connection-removal",
    "title": "MITRE ATT&CK T1070.005: Network Share Connection Removal (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1070.005 (Network Share Connection Removal) is an Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation. Windows shared drive and SMB/Windows Admin Shares connections can be removed when no longer needed. Net is an example utility that can be used to remove network share connections with the net use \\\\system\\share /delete command. Affected platforms: Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1070-indicator-removal"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1070-006-timestomp",
    "title": "MITRE ATT&CK T1070.006: Timestomp (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1070.006 (Timestomp) is an Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files. Both the $STANDARD_INFORMATION ($SI) and $FILE_NAME ($FN) attributes record times in a Master File Table (MFT) file. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1070-indicator-removal"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1070-007-clear-network-connection-history-and-configurations",
    "title": "MITRE ATT&CK T1070.007: Clear Network Connection History and Configurations (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1070.007 (Clear Network Connection History and Configurations) is an Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may clear or remove evidence of malicious network connections in order to clean up traces of their operations. Configuration settings as well as various artifacts that highlight connection history may be created on a system and/or in application logs from behaviors that require network connections, such as Remote Services or External Remote Services. Defenders may use these artifacts to monitor or otherwise analyze network connections created by adversaries. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1029 Remote Data Storage, M1024 Restrict Registry Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1070-indicator-removal"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1070-008-clear-mailbox-data",
    "title": "MITRE ATT&CK T1070.008: Clear Mailbox Data (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1070.008 (Clear Mailbox Data) is an Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may modify mail and mail application data to remove evidence of their activity. Email applications allow users and other programs to export and delete mailbox data via command line tools or use of APIs. Mail application data can be emails, email metadata, or logs generated by the application or operating system, such as export requests. Affected platforms: Linux, macOS, Windows, Office Suite. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1047 Audit, M1029 Remote Data Storage. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1070-indicator-removal"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1070-009-clear-persistence",
    "title": "MITRE ATT&CK T1070.009: Clear Persistence (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1070.009 (Clear Persistence) is an Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity. This may involve various actions, such as removing services, deleting executables, Modify Registry, Plist File Modification, or other methods of cleanup to prevent defenders from collecting evidence of their persistent presence. Adversaries may also delete accounts previously created to maintain persistence (i.e. Create Account). Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1029 Remote Data Storage. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1070-indicator-removal"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1070-010-relocate-malware",
    "title": "MITRE ATT&CK T1070.010: Relocate Malware (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1070.010 (Relocate Malware) is an Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Once a payload is delivered, adversaries may reproduce copies of the same malware on the victim system to remove evidence of their presence and/or avoid defenses. Copying malware payloads to new locations may also be combined with File Deletion to cleanup older artifacts. Relocating malware may be a part of many actions intended to evade defenses. For example, adversaries may copy and rename payloads to better blend into the local environment (i.e., Match Legitimate Name or Location). Affected platforms: Linux, macOS, Windows, Network. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1070-indicator-removal"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1070-indicator-removal",
    "title": "MITRE ATT&CK T1070: Indicator Removal (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1070 covers adversary deletion or modification of artifacts generated by intrusion activity to evade detection and impede investigation. Sub-techniques include Clear Windows Event Logs (T1070.001), Clear Linux/macOS Logs (T1070.002), Clear Command History (T1070.003), File Deletion (T1070.004), Timestomp (T1070.006), Clear Network Connection History (T1070.007), Clear Mailbox Data (T1070.008), and Clear Persistence (T1070.009). Compliance obligations include immutable audit logging (NIST 800-53 AU-9, ISO A.8.15), centralised log forwarding required by PCI DSS Req 10.5, and tamper-evident storage under SOX 404 ITGC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-t1562",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1071-001-web-protocols",
    "title": "MITRE ATT&CK T1071.001: Web Protocols (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1071.001 (Web Protocols) is an Enterprise Command and Control sub-technique of T1071 (Application Layer Protocol). Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as HTTP/S and WebSocket that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-10, SC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1071-application-layer-protocol"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1071-002-file-transfer-protocols",
    "title": "MITRE ATT&CK T1071.002: File Transfer Protocols (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1071.002 (File Transfer Protocols) is an Enterprise Command and Control sub-technique of T1071 (Application Layer Protocol). Adversaries may communicate using application layer protocols associated with transferring files to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as SMB, FTP, FTPS, and TFTP that transfer files may be very common in environments. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-10, SC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1071-application-layer-protocol"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1071-003-mail-protocols",
    "title": "MITRE ATT&CK T1071.003: Mail Protocols (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1071.003 (Mail Protocols) is an Enterprise Command and Control sub-technique of T1071 (Application Layer Protocol). Adversaries may communicate using application layer protocols associated with electronic mail delivery to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as SMTP/S, POP3/S, and IMAP that carry electronic mail may be very common in environments. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-10, SC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1071-application-layer-protocol"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1071-004-dns",
    "title": "MITRE ATT&CK T1071.004: DNS (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1071.004 (DNS) is an Enterprise Command and Control sub-technique of T1071 (Application Layer Protocol). Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1037 Filter Network Traffic, M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1071-application-layer-protocol"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1071-005-publish-subscribe-protocols",
    "title": "MITRE ATT&CK T1071.005: Publish/Subscribe Protocols (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1071.005 (Publish/Subscribe Protocols) is an Enterprise Command and Control sub-technique of T1071 (Application Layer Protocol). Adversaries may communicate using publish/subscribe (pub/sub) application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as MQTT, XMPP, AMQP, and STOMP use a publish/subscribe design, with message distribution managed by a centralized broker. Affected platforms: macOS, Linux, Windows, Network. MITRE-documented mitigations include M1037 Filter Network Traffic, M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-10, SC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1071-application-layer-protocol"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1071-application-layer-protocol",
    "title": "MITRE ATT&CK T1071: Application Layer Protocol (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1071 covers adversary use of standard application-layer protocols (HTTP/HTTPS, DNS, mail, file transfer) for command-and-control communication, blending malicious traffic with legitimate enterprise traffic. Sub-techniques include Web Protocols (T1071.001), File Transfer Protocols (T1071.002), Mail Protocols (T1071.003), DNS (T1071.004), and Publish-Subscribe Protocols (T1071.005). Living-off-the-land C2 over HTTPS is the dominant pattern in 2024-2025 intrusions. Compliance obligations include NIST SP 800-53 SI-4, SC-7, ISO 27001 A.8.16, A.8.20, NIS2 Article 21(2)(b), PCI DSS Req 11.4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1027-obfuscated-files-information",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1072-software-deployment-tools",
    "title": "MITRE ATT&CK T1072: Software Deployment Tools (Enterprise Tactic TA0002 - Execution / TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1072 (Software Deployment Tools) is an Enterprise Execution and Lateral Movement technique. Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager. Affected platforms: Linux, macOS, Windows, Network, SaaS. MITRE-documented mitigations include M1018 User Account Management, M1015 Active Directory Configuration, M1051 Update Software, M1026 Privileged Account Management, M1027 Password Policies, M1033 Limit Software Installation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-12, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1074-001-local-data-staging",
    "title": "MITRE ATT&CK T1074.001: Local Data Staging (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1074.001 (Local Data Staging) is an Enterprise Collection sub-technique of T1074 (Data Staged). Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location. Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1074-data-staged"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1074-002-remote-data-staging",
    "title": "MITRE ATT&CK T1074.002: Remote Data Staging (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1074.002 (Remote Data Staging) is an Enterprise Collection sub-technique of T1074 (Data Staged). Adversaries may stage data collected from multiple systems in a central location or directory on one system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location. In cloud environments, adversaries may stage data within a particular instance or virtual machine before exfiltration. Affected platforms: Windows, IaaS, Linux, macOS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1074-data-staged"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1074-data-staged",
    "title": "MITRE ATT&CK T1074: Data Staged (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1074 (Data Staged) is an Enterprise Collection technique. Adversaries may stage collected data in a central location or directory prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location. In cloud environments, adversaries may stage data within a particular instance or virtual machine before exfiltration. ATT&CK documents 2 sub-techniques: T1074.001 Local Data Staging; T1074.002 Remote Data Staging. Affected platforms: Windows, IaaS, Linux, macOS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1078-001-default-accounts",
    "title": "MITRE ATT&CK T1078.001: Default Accounts (Enterprise Tactic TA0005 - Defense Evasion / TA0003 - Persistence / TA0004 - Privilege Escalation / TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1078.001 (Default Accounts) is an Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS and the default service account in Kubernetes. Affected platforms: Windows, SaaS, IaaS, Linux, macOS, Containers, Network, Office Suite, Identity Provider. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-3, CA-7, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1078-valid-accounts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1078-002-domain-accounts",
    "title": "MITRE ATT&CK T1078.002: Domain Accounts (Enterprise Tactic TA0005 - Defense Evasion / TA0003 - Persistence / TA0004 - Privilege Escalation / TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1078.002 (Domain Accounts) is an Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1018 User Account Management, M1032 Multi-factor Authentication, M1026 Privileged Account Management, M1017 User Training, M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-3, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1078-valid-accounts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1078-003-local-accounts",
    "title": "MITRE ATT&CK T1078.003: Local Accounts (Enterprise Tactic TA0005 - Defense Evasion / TA0003 - Persistence / TA0004 - Privilege Escalation / TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1078.003 (Local Accounts) is an Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service. Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Affected platforms: Linux, macOS, Windows, Containers, Network. MITRE-documented mitigations include M1026 Privileged Account Management, M1032 Multi-factor Authentication, M1027 Password Policies, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-3, CA-7, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1078-valid-accounts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1078-004-cloud-accounts",
    "title": "MITRE ATT&CK T1078.004: Cloud Accounts (Sub-Technique of T1078 - Initial Access / Persistence / Privilege Escalation / Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1078.004 covers adversary use of legitimate cloud account credentials (Microsoft Entra ID / Azure AD, AWS IAM, Google Workspace, GCP, Okta, Salesforce) to gain initial access, maintain persistence, escalate privileges, and evade detection. Cloud account abuse is the dominant attack pattern in modern SaaS-heavy environments: SCATTERED SPIDER, Storm-0558, MUDDLED LIBRA, and most major 2023-2024 breaches involved cloud credential compromise. Compliance obligations include NIST SP 800-53 IA-2, AC-2, AC-6, ISO 27001 A.5.16-A.5.18, A.8.2, PCI DSS Req 8, HIPAA 164.308(a)(4), DORA Article 9, NIS2 Article 21(2)(j), and CISA Cloud Security Technical Reference Architecture.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1110-brute-force",
      "mitre-attack-t1098-account-manipulation",
      "mitre-attack-t1589-gather-victim-identity-information",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1078-valid-accounts",
    "title": "MITRE ATT&CK T1078: Valid Accounts (Enterprise Tactics TA0001 / TA0003 / TA0004 / TA0005)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1078 (Valid Accounts) covers adversary use of compromised credentials for initial access, persistence, privilege escalation, and defense evasion. Sub-techniques cover Default Accounts (T1078.001), Domain Accounts (T1078.002), Local Accounts (T1078.003), and Cloud Accounts (T1078.004). Credential-based attacks were involved in 86% of breaches per the Verizon DBIR 2024. Compliance obligations include identity governance (NIST 800-53 IA family, ISO A.5.16), privileged access management (PAM per ISO A.8.2), and continuous credential exposure monitoring required by NIS2 Article 21 and DORA Article 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-t1562",
      "nist-csf-20-protect-function-pr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1080-taint-shared-content",
    "title": "MITRE ATT&CK T1080: Taint Shared Content (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1080 (Taint Shared Content) is an Enterprise Lateral Movement technique. Adversaries may deliver payloads to remote systems by adding content to shared storage locations, such as network drives or internal code repositories. Content stored on network drives or in other shared locations may be tainted by adding malicious programs, scripts, or exploit code to otherwise valid files. Once a user opens the shared tainted content, the malicious portion can be executed to run the adversary's code on a remote system. Adversaries may use tainted shared content to move laterally. Affected platforms: Windows, SaaS, Linux, macOS, Office Suite. MITRE-documented mitigations include M1049 Antivirus/Antimalware, M1038 Execution Prevention, M1022 Restrict File and Directory Permissions, M1050 Exploit Protection. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, CA-7, CM-2, CM-7, SC-4, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1083-file-and-directory-discovery",
    "title": "MITRE ATT&CK T1083: File and Directory Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1083 covers adversary enumeration of files and directories to find files of interest, identify backup locations, and map storage structures. The technique is universally observed across nation-state and criminal campaigns as part of the early reconnaissance phase of an intrusion. Compliance obligations include data loss prevention (DLP) labelling required under GDPR Article 32, file access monitoring under NIST 800-53 AC-6 and AU-2, and behavioural anomaly detection under ISO 27001 A.8.16. Detection of mass directory enumeration is the earliest indicator of ransomware staging.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1059-command-and-scripting-interpreter",
      "cis-controls-v8"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1087-001-local-account",
    "title": "MITRE ATT&CK T1087.001: Local Account (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1087.001 (Local Account) is an Enterprise Discovery sub-technique of T1087 (Account Discovery). Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior. Commands such as net user and net localgroup of the Net utility and id and groups on macOS and Linux can list local users and groups. On Linux, local users can also be enumerated through the use of the /etc/passwd file. On macOS the dscl . list /Users command can be used to enumerate local accounts. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, CM-6, CM-7, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1087-account-discovery"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1087-002-domain-account",
    "title": "MITRE ATT&CK T1087.002: Domain Account (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1087.002 (Domain Account) is an Enterprise Discovery sub-technique of T1087 (Account Discovery). Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges. Commands such as net user /domain and net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on Linux can list domain users and groups. PowerShell cmdlets including Get-ADUser and Get-ADGroupMember may enumerate members of Active Directory groups. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, CM-6, CM-7, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1087-account-discovery"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1087-003-email-account",
    "title": "MITRE ATT&CK T1087.003: Email Account (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1087.003 (Email Account) is an Enterprise Discovery sub-technique of T1087 (Account Discovery). Adversaries may attempt to get a listing of email addresses and accounts. Adversaries may try to dump Exchange address lists such as global address lists (GALs). In on-premises Exchange and Exchange Online, the Get-GlobalAddressList PowerShell cmdlet can be used to obtain email addresses and accounts from a domain using an authenticated session. In Google Workspace, the GAL is shared with Microsoft Outlook users through the Google Workspace Sync for Microsoft Outlook (GWSMO) service. Affected platforms: Windows, Office Suite. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, CM-6, CM-7, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1087-account-discovery"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1087-004-cloud-account",
    "title": "MITRE ATT&CK T1087.004: Cloud Account (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1087.004 (Cloud Account) is an Enterprise Discovery sub-technique of T1087 (Account Discovery). Adversaries may attempt to get a listing of cloud accounts. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. With authenticated access there are several tools that can be used to find accounts. The Get-MsolRoleMember PowerShell cmdlet can be used to obtain account names given a role or permissions group in Office 365. Affected platforms: SaaS, IaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1047 Audit, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-6, CM-7, IA-2, IA-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1087-account-discovery"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1087-account-discovery",
    "title": "MITRE ATT&CK T1087: Account Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1087 (Account Discovery) is an Enterprise Discovery technique. Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment. This information can help adversaries determine which accounts exist, which can aid in follow-on behavior such as brute-forcing, spear-phishing attacks, or account takeovers (e.g., Valid Accounts). ATT&CK documents 4 sub-techniques: T1087.001 Local Account; T1087.002 Domain Account; T1087.003 Email Account; T1087.004 Cloud Account. Affected platforms: Windows, SaaS, IaaS, Linux, macOS, Office Suite, Identity Provider. MITRE-documented mitigations include M1028 Operating System Configuration, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, CM-6, CM-7, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1090-001-internal-proxy",
    "title": "MITRE ATT&CK T1090.001: Internal Proxy (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1090.001 (Internal Proxy) is an Enterprise Command and Control sub-technique of T1090 (Proxy). Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1090-proxy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1090-002-external-proxy",
    "title": "MITRE ATT&CK T1090.002: External Proxy (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1090.002 (External Proxy) is an Enterprise Command and Control sub-technique of T1090 (Proxy). Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths to avoid suspicion. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1090-proxy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1090-003-multi-hop-proxy",
    "title": "MITRE ATT&CK T1090.003: Multi-hop Proxy (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1090.003 (Multi-hop Proxy) is an Enterprise Command and Control sub-technique of T1090 (Proxy). Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1090-proxy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1090-004-domain-fronting",
    "title": "MITRE ATT&CK T1090.004: Domain Fronting (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1090.004 (Domain Fronting) is an Enterprise Command and Control sub-technique of T1090 (Proxy). Adversaries may take advantage of routing schemes in Content Delivery Networks (CDNs) and other services which host multiple domains to obfuscate the intended destination of HTTPS traffic or traffic tunneled through HTTPS. Domain fronting involves using different domain names in the SNI field of the TLS header and the Host field of the HTTP header. If both domains are served from the same CDN, then the CDN may route to the address specified in the HTTP header after unwrapping the TLS header. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1020 SSL/TLS Inspection. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1090-proxy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1090-proxy",
    "title": "MITRE ATT&CK T1090: Proxy (Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1090 covers adversary use of proxy infrastructure (Internal Proxy T1090.001, External Proxy T1090.002, Multi-hop Proxy T1090.003 including Tor, Domain Fronting T1090.004) to obfuscate C2 traffic origin. APT29, Cobalt Strike, Sliver, and most commercial spyware use proxy chains. Compliance: NIST 800-53 SC-7, SI-4, ISO 27001 A.8.20, A.8.21, PCI DSS Req 11.4, NIS2 Article 21(2)(b).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1071-application-layer-protocol",
      "mitre-attack-t1573-encrypted-channel",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1091-replication-through-removable-media",
    "title": "MITRE ATT&CK T1091: Replication Through Removable Media (Enterprise Tactic TA0008 - Lateral Movement / TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1091 (Replication Through Removable Media) is an Enterprise Lateral Movement and Initial Access technique. Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1034 Limit Hardware Installation, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-6, CM-2, CM-6, CM-8, MP-7, RA-5, SC-41.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1092-communication-through-removable-media",
    "title": "MITRE ATT&CK T1092: Communication Through Removable Media (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1092 (Communication Through Removable Media) is an Enterprise Command and Control technique. Adversaries can perform command and control between compromised hosts on potentially disconnected networks using removable media to transfer commands from system to system. Both systems would need to be compromised, with the likelihood that an Internet-connected system was compromised first and the second through lateral movement by Replication Through Removable Media. Commands and files would be relayed from the disconnected system to the Internet-connected system to which the adversary has direct access. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-6, CM-7, CM-8, MP-7, RA-5, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1095-non-application-layer-protocol",
    "title": "MITRE ATT&CK T1095: Non-Application Layer Protocol (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1095 (Non-Application Layer Protocol) is an Enterprise Command and Control technique. Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network. The list of possible protocols is extensive. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL). Affected platforms: Windows, Linux, macOS, Network. MITRE-documented mitigations include M1031 Network Intrusion Prevention, M1037 Filter Network Traffic, M1030 Network Segmentation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SI-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1098-001-additional-cloud-credentials",
    "title": "MITRE ATT&CK T1098.001: Additional Cloud Credentials (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1098.001 (Additional Cloud Credentials) is an Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment. For example, adversaries may add credentials for Service Principals and Applications in addition to existing legitimate credentials in Azure / Entra ID. These credentials include both x509 keys and passwords. Affected platforms: IaaS, SaaS, Identity Provider. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1018 User Account Management, M1030 Network Segmentation, M1026 Privileged Account Management, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-20, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1098-account-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1098-002-additional-email-delegate-permissions",
    "title": "MITRE ATT&CK T1098.002: Additional Email Delegate Permissions (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1098.002 (Additional Email Delegate Permissions) is an Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). Adversaries may grant additional permission levels to maintain persistent access to an adversary-controlled email account. For example, the Add-MailboxPermission PowerShell cmdlet, available in on-premises Exchange and in the cloud-based service Office 365, adds permissions to a mailbox. In Google Workspace, delegation can be enabled via the Google Admin console and users can delegate accounts via their Gmail settings. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1026 Privileged Account Management, M1032 Multi-factor Authentication, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-20, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1098-account-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1098-003-additional-cloud-roles",
    "title": "MITRE ATT&CK T1098.003: Additional Cloud Roles (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1098.003 (Additional Cloud Roles) is an Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permissions, a compromised account can gain almost unlimited access to data and settings (including the ability to reset the passwords of other admins). Affected platforms: IaaS, SaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1026 Privileged Account Management, M1032 Multi-factor Authentication, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-20, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1098-account-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1098-004-ssh-authorized-keys",
    "title": "MITRE ATT&CK T1098.004: SSH Authorized Keys (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1098.004 (SSH Authorized Keys) is an Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). Adversaries may modify the SSH authorized_keys file to maintain persistence on a victim host. Linux distributions and macOS commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The authorized_keys file in SSH specifies the SSH keys that can be used for logging into the user account for which the file is configured. This file is usually found in the user's home directory under &lt;user-home&gt;/.ssh/authorized_keys. Affected platforms: Linux, macOS, IaaS, Network. MITRE-documented mitigations include M1018 User Account Management, M1022 Restrict File and Directory Permissions, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-20, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1098-account-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1098-005-device-registration",
    "title": "MITRE ATT&CK T1098.005: Device Registration (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1098.005 (Device Registration) is an Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance. MFA systems, such as Duo or Okta, allow users to associate devices with their accounts in order to complete MFA requirements. Affected platforms: Windows, Identity Provider. MITRE-documented mitigations include M1032 Multi-factor Authentication. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-20, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1098-account-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1098-006-additional-container-cluster-roles",
    "title": "MITRE ATT&CK T1098.006: Additional Container Cluster Roles (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1098.006 (Additional Container Cluster Roles) is an Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). An adversary may add additional roles or permissions to an adversary-controlled user or service account to maintain persistent access to a container orchestration system. For example, an adversary with sufficient permissions may create a RoleBinding or a ClusterRoleBinding to bind a Role or ClusterRole to a Kubernetes account. Where attribute-based access control (ABAC) is in use, an adversary with sufficient permissions may modify a Kubernetes ABAC policy to give the target account additional permissions. Affected platforms: Containers. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1098-account-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1098-007-additional-local-or-domain-groups",
    "title": "MITRE ATT&CK T1098.007: Additional Local or Domain Groups (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1098.007 (Additional Local or Domain Groups) is an Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). An adversary may add additional local or domain groups to an adversary-controlled account to maintain persistent access to a system or domain. On Windows, accounts may use the net localgroup and net group commands to add existing users to local and domain groups. On Linux, adversaries may use the usermod command for the same purpose. For example, accounts may be added to the local administrators group on Windows devices to maintain elevated privileges. Affected platforms: Windows, macOS, Linux. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1098-account-manipulation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1098-account-manipulation",
    "title": "MITRE ATT&CK T1098: Account Manipulation (Enterprise Tactics TA0003 / TA0004 - Persistence and Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1098 describes adversary modification of accounts to maintain or escalate access. Sub-techniques cover Additional Cloud Credentials (T1098.001), Additional Email Delegate Permissions (T1098.002), Additional Cloud Roles (T1098.003), SSH Authorized Keys (T1098.004), Device Registration (T1098.005), and Additional Container Cluster Roles (T1098.006). High-profile campaigns include Midnight Blizzard against Microsoft (2023), where adversaries added OAuth application credentials for persistence. Compliance obligations include continuous privilege monitoring, behavioural analytics on permission changes, and zero-trust authorisation per NIST 800-53 AC family and ISO A.5.18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1136-create-account"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1102-001-dead-drop-resolver",
    "title": "MITRE ATT&CK T1102.001: Dead Drop Resolver (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1102.001 (Dead Drop Resolver) is an Enterprise Command and Control sub-technique of T1102 (Web Service). Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1021 Restrict Web-Based Content, M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1102-web-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1102-002-bidirectional-communication",
    "title": "MITRE ATT&CK T1102.002: Bidirectional Communication (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1102.002 (Bidirectional Communication) is an Enterprise Command and Control sub-technique of T1102 (Web Service). Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1021 Restrict Web-Based Content, M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1102-web-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1102-003-one-way-communication",
    "title": "MITRE ATT&CK T1102.003: One-Way Communication (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1102.003 (One-Way Communication) is an Enterprise Command and Control sub-technique of T1102 (Web Service). Adversaries may use an existing, legitimate external Web service as a means for sending commands to a compromised system without receiving return output over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems may opt to send the output from those commands back over a different C2 channel, including to another distinct Web service. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1021 Restrict Web-Based Content, M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1102-web-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1102-web-service",
    "title": "MITRE ATT&CK T1102: Web Service (Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1102 covers adversary abuse of legitimate web services (GitHub, Pastebin, Discord, Dropbox, Telegram, Slack, X/Twitter, GitHub Gist) for command-and-control communication, blending malicious traffic with legitimate enterprise SaaS use. Sub-techniques: Dead Drop Resolver (T1102.001), Bidirectional Communication (T1102.002), One-Way Communication (T1102.003). Compliance: NIST 800-53 SC-7, SI-4, ISO 27001 A.8.20, A.8.23, PCI DSS Req 11.4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1071-application-layer-protocol",
      "mitre-attack-t1573-encrypted-channel",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1104-multi-stage-channels",
    "title": "MITRE ATT&CK T1104: Multi-Stage Channels (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1104 (Multi-Stage Channels) is an Enterprise Command and Control technique. Adversaries may create multiple stages for command and control that are employed under different conditions or for certain functions. Use of multiple stages may obfuscate the command and control channel to make detection more difficult. Remote access tools will call back to the first-stage command and control server for instructions. The first stage may have automated capabilities to collect basic host information, update tools, and upload additional files. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1105-ingress-tool-transfer",
    "title": "MITRE ATT&CK T1105: Ingress Tool Transfer (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1105 (Ingress Tool Transfer) is an Enterprise Command and Control technique. Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer). Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1106-native-api",
    "title": "MITRE ATT&CK T1106: Native API (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1106 covers adversary direct invocation of operating system APIs to execute code, bypassing higher-level interpreters and detection mechanisms that rely on parent-process telemetry. Common implementations include direct syscalls in Windows (ntdll.dll) and unhooked execution to evade EDR userland hooks. The technique is favoured by sophisticated threat actors (APT29, FIN7) for stealth. Compliance obligations include kernel-level EDR coverage (NIST 800-53 SI-3, ISO A.8.7), application allowlisting that operates at the kernel level (e.g., WDAC), and behavioural detection that does not rely solely on userland hooks per the NIS2 Article 21 implementation framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1059-command-and-scripting-interpreter",
      "cis-controls-v8"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1110-001-password-guessing",
    "title": "MITRE ATT&CK T1110.001: Password Guessing (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1110.001 (Password Guessing) is an Enterprise Credential Access sub-technique of T1110 (Brute Force). Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts. Without knowledge of the password for an account, an adversary may opt to systematically guess the password using a repetitive or iterative mechanism. An adversary may guess login credentials without prior knowledge of system or environment passwords during an operation by using a list of common passwords. Affected platforms: Windows, SaaS, IaaS, Linux, macOS, Containers, Network, Office Suite, Identity Provider. MITRE-documented mitigations include M1051 Update Software, M1032 Multi-factor Authentication, M1027 Password Policies, M1036 Account Use Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1110-brute-force"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1110-002-password-cracking",
    "title": "MITRE ATT&CK T1110.002: Password Cracking (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1110.002 (Password Cracking) is an Enterprise Credential Access sub-technique of T1110 (Brute Force). Adversaries may use password cracking to attempt to recover usable credentials, such as plaintext passwords, when credential material such as password hashes are obtained. OS Credential Dumping can be used to obtain password hashes, this may only get an adversary so far when Pass the Hash is not an option. Further, adversaries may leverage Data from Configuration Repository in order to obtain hashed credentials for network devices. Affected platforms: Linux, macOS, Windows, Network, Office Suite, Identity Provider. MITRE-documented mitigations include M1027 Password Policies, M1032 Multi-factor Authentication. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1110-brute-force"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1110-003-password-spraying",
    "title": "MITRE ATT&CK T1110.003: Password Spraying (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1110.003 (Password Spraying) is an Enterprise Credential Access sub-technique of T1110 (Brute Force). Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials. Password spraying uses one password (e.g. 'Password01'), or a small list of commonly used passwords, that may match the complexity policy of the domain. Logins are attempted with that password against many different accounts on a network to avoid account lockouts that would normally occur when brute forcing a single account with many passwords. Affected platforms: Windows, SaaS, IaaS, Linux, macOS, Containers, Network, Office Suite, Identity Provider. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1027 Password Policies, M1036 Account Use Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1110-brute-force"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1110-004-credential-stuffing",
    "title": "MITRE ATT&CK T1110.004: Credential Stuffing (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1110.004 (Credential Stuffing) is an Enterprise Credential Access sub-technique of T1110 (Brute Force). Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap. Occasionally, large numbers of username and password pairs are dumped online when a website or service is compromised and the user account credentials accessed. The information may be useful to an adversary attempting to compromise accounts by taking advantage of the tendency for users to use the same passwords across personal and business accounts. Affected platforms: Windows, SaaS, IaaS, Linux, macOS, Containers, Network, Office Suite, Identity Provider. MITRE-documented mitigations include M1036 Account Use Policies, M1027 Password Policies, M1018 User Account Management, M1032 Multi-factor Authentication. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1110-brute-force"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1110-brute-force",
    "title": "MITRE ATT&CK T1110: Brute Force (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1110 covers adversary attempts to gain access through systematic guessing of credentials. Sub-techniques include Password Guessing (T1110.001), Password Cracking (T1110.002), Password Spraying (T1110.003), and Credential Stuffing (T1110.004). Microsoft reports approximately 4,000 password spray attacks per second against Entra ID accounts globally as of 2024. Compliance obligations include account lockout policies (NIST 800-53 AC-7), phishing-resistant MFA (NIST SP 800-63B AAL2/AAL3), and breached-credential monitoring required under PCI DSS Req 8 and ISO 27001 A.8.5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1098-account-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1111-multi-factor-authentication-interception",
    "title": "MITRE ATT&CK T1111: Multi-Factor Authentication Interception (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1111 (Multi-Factor Authentication Interception) is an Enterprise Credential Access technique. Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources. Use of MFA is recommended and provides a higher level of security than usernames and passwords alone, but organizations should be aware of techniques that could be used to intercept and bypass these security mechanisms. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-20, CA-7, CM-2, CM-6, IA-2, IA-5, IA-13, SI-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1112-modify-registry",
    "title": "MITRE ATT&CK T1112: Modify Registry (Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1112 covers adversary modification of the Windows Registry to hide configuration, persist, disable security tools, or evade detection. Common targets: Run keys, Services, Defender exclusions, EnableLUA UAC, IFEO (Image File Execution Options) debuggers. Compliance: NIST 800-53 SI-7, CM-2, CM-6, AU-2, ISO 27001 A.8.32, A.8.16, PCI DSS Req 10.4, CIS Controls v8 Control 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1547-001-registry-run-keys-startup-folder",
      "mitre-attack-t1547-boot-logon-autostart-execution",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1113-screen-capture",
    "title": "MITRE ATT&CK T1113: Screen Capture (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1113 (Screen Capture) is an Enterprise Collection technique. Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as CopyFromScreen, xwd, or screencapture. Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1114-001-local-email-collection",
    "title": "MITRE ATT&CK T1114.001: Local Email Collection (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1114.001 (Local Email Collection) is an Enterprise Collection sub-technique of T1114 (Email Collection). Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user's local system, such as Outlook storage or cache files. Outlook stores data locally in offline data files with an extension of .ost. Outlook 2010 and later supports .ost file sizes up to 50GB, while earlier versions of Outlook support up to 20GB. Affected platforms: Windows. MITRE-documented mitigations include M1060 Out-of-Band Communications Channel, M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-19, AC-20, CM-2, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1114-email-collection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1114-002-remote-email-collection",
    "title": "MITRE ATT&CK T1114.002: Remote Email Collection (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1114.002 (Remote Email Collection) is an Enterprise Collection sub-technique of T1114 (Email Collection). Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1060 Out-of-Band Communications Channel, M1041 Encrypt Sensitive Information, M1032 Multi-factor Authentication. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-19, AC-20, CM-2, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1114-email-collection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1114-003-email-forwarding-rule",
    "title": "MITRE ATT&CK T1114.003: Email Forwarding Rule (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1114.003 (Email Forwarding Rule) is an Enterprise Collection sub-technique of T1114 (Email Collection). Adversaries may setup email forwarding rules to collect sensitive information. Adversaries may abuse email forwarding rules to monitor the activities of a victim, steal information, and further gain intelligence on the victim or the victim's organization to use as part of further exploits or operations. Furthermore, email forwarding rules can allow adversaries to maintain persistent access to victim's emails even after compromised credentials are reset by administrators. Affected platforms: Windows, macOS, Linux, Office Suite. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1041 Encrypt Sensitive Information, M1047 Audit, M1060 Out-of-Band Communications Channel. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-19, AC-20, CM-2, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1114-email-collection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1114-email-collection",
    "title": "MITRE ATT&CK T1114: Email Collection (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1114 covers adversary collection of email data through Local Email Collection (T1114.001), Remote Email Collection (T1114.002), and Email Forwarding Rule (T1114.003). Compromised mailboxes are routinely abused for BEC (Business Email Compromise), supply chain attacks, and data exfiltration via auto-forwarding rules. Microsoft and Google report sustained high-volume BEC campaigns ranging USD 50B+ in annual losses globally. Compliance obligations include NIST SP 800-53 SC-8 (Transmission Confidentiality), AU-12 (Audit Generation), GDPR Article 32, HIPAA Security Rule 164.312(e), PCI DSS Req 4 (Encrypt Transmission), and US state breach notification laws.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1098-account-manipulation",
      "mitre-attack-t1110-brute-force",
      "mitre-attack-t1566-phishing",
      "gdpr-article-32-security-of-processing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1115-clipboard-data",
    "title": "MITRE ATT&CK T1115: Clipboard Data (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1115 (Clipboard Data) is an Enterprise Collection technique. Adversaries may collect data stored in the clipboard from users copying information within or between applications. For example, on Windows adversaries can access clipboard data by using clip.exe or Get-Clipboard. Additionally, adversaries may monitor then replace users' clipboard with their data (e.g., Transmitted Data Manipulation). macOS and Linux also have commands, such as pbpaste, to grab clipboard contents. Affected platforms: Linux, Windows, macOS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1119-automated-collection",
    "title": "MITRE ATT&CK T1119: Automated Collection (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1119 (Automated Collection) is an Enterprise Collection technique. Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals. In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or extract, transform, and load (ETL) services to automatically collect data. Affected platforms: Linux, macOS, Windows, IaaS, SaaS, Office Suite. MITRE-documented mitigations include M1029 Remote Data Storage, M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-16, AC-17, AC-18, AC-19, AC-20, CM-2, CM-6, CM-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1120-peripheral-device-discovery",
    "title": "MITRE ATT&CK T1120: Peripheral Device Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1120 (Peripheral Device Discovery) is an Enterprise Discovery technique. Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system. Peripheral devices could include auxiliary resources that support a variety of functionalities such as keyboards, printers, cameras, smart card readers, or removable storage. The information may be used to enhance their awareness of the system and network environment or may be used for further actions. Affected platforms: Windows, macOS, Linux.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1123-audio-capture",
    "title": "MITRE ATT&CK T1123: Audio Capture (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1123 (Audio Capture) is an Enterprise Collection technique. An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listening into sensitive conversations to gather information. Malware or scripts may be used to interact with the devices through an available API provided by the operating system or an application to capture audio. Audio files may be written to disk and exfiltrated later. Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1124-system-time-discovery",
    "title": "MITRE ATT&CK T1124: System Time Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1124 (System Time Discovery) is an Enterprise Discovery technique. An adversary may gather the system time and/or time zone settings from a local or remote system. The system time is set and stored by services, such as the Windows Time Service on Windows or systemsetup on macOS. These time settings may also be synchronized between systems and services in an enterprise network, typically accomplished with a network time server within a domain. Affected platforms: Windows, Network, Linux, macOS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1125-video-capture",
    "title": "MITRE ATT&CK T1125: Video Capture (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1125 (Video Capture) is an Enterprise Collection technique. An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering information. Images may also be captured from devices or applications, potentially in specified intervals, in lieu of video files. Malware or scripts may be used to interact with the devices through an available API provided by the operating system or an application to capture video or images. Affected platforms: Windows, macOS, Linux.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1127-001-msbuild",
    "title": "MITRE ATT&CK T1127.001: MSBuild (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1127.001 (MSBuild) is an Enterprise Defense Evasion sub-technique of T1127 (Trusted Developer Utilities Proxy Execution). Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations. Adversaries can abuse MSBuild to proxy execution of malicious code. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-6, CM-7, CM-8, RA-5, SI-4, SI-7, SI-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1127-trusted-developer-utilities-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1127-002-clickonce",
    "title": "MITRE ATT&CK T1127.002: ClickOnce (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1127.002 (ClickOnce) is an Enterprise Defense Evasion sub-technique of T1127 (Trusted Developer Utilities Proxy Execution). Adversaries may use ClickOnce applications (.appref-ms and .application files) to proxy execution of code through a trusted Windows utility. ClickOnce is a deployment that enables a user to create self-updating Windows-based .NET applications (i.e, .XBAP, .EXE, or .DLL) that install and run from a file share or web page with minimal user interaction. The application launches as a child process of DFSVC.EXE, which is responsible for installing, launching, and updating the application. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1021 Restrict Web-Based Content, M1045 Code Signing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-17, CM-2, CM-6, CM-7, CM-8, RA-5, SC-18, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1127-trusted-developer-utilities-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1127-003-jamplus",
    "title": "MITRE ATT&CK T1127.003: JamPlus (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1127.003 (JamPlus) is an Enterprise Stealth, Execution technique. Adversaries may use `JamPlus` to proxy the execution of a malicious script. `JamPlus` is a build utility tool for code and data build systems. It works with several popular compilers and can be used for generating workspaces in code editors such as Visual Studio. Adversaries may abuse the `JamPlus` build utility to execute malicious scripts via a `.jam` file, which describes the build process and required dependencies. Because the malicious script is executed from a reputable developer tool, it may subvert application control security systems such as Smart App Control. Affected platforms: Windows. Sub-technique of ATT&CK T1127. ATT&CK-mapped mitigations: M1038 Execution Prevention, M1042 Disable or Remove Feature or Program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1127-trusted-developer-utilities-proxy-execution",
    "title": "MITRE ATT&CK T1127: Trusted Developer Utilities Proxy Execution (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1127 (Trusted Developer Utilities Proxy Execution) is an Enterprise Defense Evasion technique. Adversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads. There are many utilities used for software development related tasks that can be used to execute code in various forms to assist in development, debugging, and reverse engineering. These utilities may often be signed with legitimate certificates that allow them to execute on a system and proxy execution of malicious code through a trusted process that effectively bypasses application control solutions. ATT&CK documents 2 sub-techniques: T1127.001 MSBuild; T1127.002 ClickOnce. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1021 Restrict Web-Based Content, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-6, CM-7, CM-8, RA-5, SI-4, SI-7, SI-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1129-shared-modules",
    "title": "MITRE ATT&CK T1129: Shared Modules (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1129 (Shared Modules) is an Enterprise Execution technique. Adversaries may execute malicious payloads via loading shared modules. Shared modules are executable files that are loaded into processes to provide access to reusable code, such as specific custom functions or invoking OS API functions (i.e., Native API). Adversaries may use this functionality as a way to execute arbitrary payloads on a victim system. Affected platforms: Windows, macOS, Linux. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-7, SI-3, SI-4, SI-7, SI-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1132-001-standard-encoding",
    "title": "MITRE ATT&CK T1132.001: Standard Encoding (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1132.001 (Standard Encoding) is an Enterprise Command and Control sub-technique of T1132 (Data Encoding). Adversaries may encode data with a standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a standard data encoding system that adheres to existing protocol specifications. Common data encoding schemes include ASCII, Unicode, hexadecimal, Base64, and MIME. Some data encoding systems may also result in data compression, such as gzip. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1132-data-encoding"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1132-002-non-standard-encoding",
    "title": "MITRE ATT&CK T1132.002: Non-Standard Encoding (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1132.002 (Non-Standard Encoding) is an Enterprise Command and Control sub-technique of T1132 (Data Encoding). Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a non-standard data encoding system that diverges from existing protocol specifications. Non-standard data encoding schemes may be based on or related to standard data encoding schemes, such as a modified Base64 encoding for the message body of an HTTP request. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1132-data-encoding"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1132-data-encoding",
    "title": "MITRE ATT&CK T1132: Data Encoding (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1132 (Data Encoding) is an Enterprise Command and Control technique. Adversaries may encode data to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a standard data encoding system. Use of data encoding may adhere to existing protocol specifications and includes use of ASCII, Unicode, Base64, MIME, or other binary-to-text and character encoding systems. Some data encoding systems may also result in data compression, such as gzip. ATT&CK documents 2 sub-techniques: T1132.001 Standard Encoding; T1132.002 Non-Standard Encoding. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1133-external-remote-services",
    "title": "MITRE ATT&CK T1133: External Remote Services (Enterprise Tactic TA0003 - Persistence / TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1133 (External Remote Services) is an Enterprise Persistence and Initial Access technique. Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally. Affected platforms: Windows, Linux, Containers, macOS. MITRE-documented mitigations include M1030 Network Segmentation, M1042 Disable or Remove Feature or Program, M1035 Limit Access to Resource Over Network, M1032 Multi-factor Authentication. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-6, AC-7, AC-17, AC-20, CM-2, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1134-001-token-impersonation-theft",
    "title": "MITRE ATT&CK T1134.001: Token Impersonation/Theft (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1134.001 (Token Impersonation/Theft) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using DuplicateToken or DuplicateTokenEx. The token can then be used with ImpersonateLoggedOnUser to allow the calling thread to impersonate a logged on user's security context, or with SetThreadToken to assign the impersonated token to a thread. Affected platforms: Windows. MITRE-documented mitigations include M1018 User Account Management, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, IA-13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1134-access-token-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1134-002-create-process-with-token",
    "title": "MITRE ATT&CK T1134.002: Create Process with Token (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1134.002 (Create Process with Token) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may create a new process with an existing token to escalate privileges and bypass access controls. Processes can be created with the token and resulting security context of another user using features such as CreateProcessWithTokenW and runas. Creating processes with a token not associated with the current user may require the credentials of the target user, specific privileges to impersonate that user, or access to the token to be used. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, IA-13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1134-access-token-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1134-003-make-and-impersonate-token",
    "title": "MITRE ATT&CK T1134.003: Make and Impersonate Token (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1134.003 (Make and Impersonate Token) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls. For example, if an adversary has a username and password but the user is not logged onto the system the adversary can then create a logon session for the user using the LogonUser function. The function will return a copy of the new session's access token and the adversary can use SetThreadToken to assign the token to a thread. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, IA-13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1134-access-token-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1134-004-parent-pid-spoofing",
    "title": "MITRE ATT&CK T1134.004: Parent PID Spoofing (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1134.004 (Parent PID Spoofing) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges. New processes are typically spawned directly from their parent, or calling, process unless explicitly specified. One way of explicitly assigning the PPID of a new process is via the CreateProcess API call, which supports a parameter that defines the PPID to use. Affected platforms: Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, IA-13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1134-access-token-manipulation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1134-005-sid-history-injection",
    "title": "MITRE ATT&CK T1134.005: SID-History Injection (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1134.005 (SID-History Injection) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may use SID-History Injection to escalate privileges and bypass access controls. The Windows security identifier (SID) is a unique value that identifies a user or group account. SIDs are used by Windows security in both security descriptors and access tokens. An account can hold additional SIDs in the SID-History Active Directory attribute , allowing inter-operable account migration between domains (e.g., all values in SID-History are included in access tokens). Affected platforms: Windows. MITRE-documented mitigations include M1015 Active Directory Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-20, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1134-access-token-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1134-access-token-manipulation",
    "title": "MITRE ATT&CK T1134: Access Token Manipulation (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1134 (Access Token Manipulation) is an Enterprise Defense Evasion and Privilege Escalation technique. Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls. Windows uses access tokens to determine the ownership of a running process. A user can manipulate access tokens to make a running process appear as though it is the child of a different process or belongs to someone other than the user that started the process. When this occurs, the process also takes on the security context associated with the new token. ATT&CK documents 5 sub-techniques: T1134.001 Token Impersonation/Theft; T1134.002 Create Process with Token; T1134.003 Make and Impersonate Token; T1134.004 Parent PID Spoofing; T1134.005 SID-History Injection. Affected platforms: Windows. MITRE-documented mitigations include M1018 User Account Management, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, IA-13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1135-network-share-discovery",
    "title": "MITRE ATT&CK T1135: Network Share Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1135 (Network Share Discovery) is an Enterprise Discovery technique. Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network. File sharing over a Windows network occurs over the SMB protocol. Affected platforms: macOS, Windows, Linux. MITRE-documented mitigations include M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-6, CM-7, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1136-001-local-account",
    "title": "MITRE ATT&CK T1136.001: Local Account (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1136.001 (Local Account) is an Enterprise Persistence sub-technique of T1136 (Create Account). Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service. For example, with a sufficient level of access, the Windows net user /add command can be used to create a local account. On macOS systems the dscl -create command can be used to create a local account. Affected platforms: Linux, macOS, Windows, Network, Containers. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-20, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1136-create-account"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1136-002-domain-account",
    "title": "MITRE ATT&CK T1136.002: Domain Account (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1136.002 (Domain Account) is an Enterprise Persistence sub-technique of T1136 (Create Account). Adversaries may create a domain account to maintain access to victim systems. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover user, administrator, and service accounts. With a sufficient level of access, the net user /add /domain command can be used to create a domain account. Affected platforms: Windows, macOS, Linux. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1028 Operating System Configuration, M1030 Network Segmentation, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-20, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1136-create-account"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1136-003-cloud-account",
    "title": "MITRE ATT&CK T1136.003: Cloud Account (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1136.003 (Cloud Account) is an Enterprise Persistence sub-technique of T1136 (Create Account). Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system. In addition to user accounts, cloud accounts may be associated with services. Cloud providers handle the concept of service accounts in different ways. Affected platforms: IaaS, SaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1030 Network Segmentation, M1032 Multi-factor Authentication, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-20, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1136-create-account"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1136-create-account",
    "title": "MITRE ATT&CK T1136: Create Account (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1136 describes adversary creation of accounts to maintain access. Sub-techniques cover Local Account (T1136.001), Domain Account (T1136.002), and Cloud Account (T1136.003). Adversary-created accounts often evade detection by appearing legitimate; SolarWinds and Hafnium (Microsoft Exchange ProxyLogon) campaigns both used this technique. Compliance obligations include identity governance and account lifecycle monitoring required by NIST 800-53 AC-2, ISO A.5.16, and DORA Article 9, plus mandatory privileged account oversight under PCI DSS Req 7 and HIPAA 164.308(a)(4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1078-valid-accounts",
      "nist-csf-20-protect-function-pr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1137-001-office-template-macros",
    "title": "MITRE ATT&CK T1137.001: Office Template Macros (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1137.001 (Office Template Macros) is an Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse Microsoft Office templates to obtain persistence on a compromised system. Microsoft Office contains templates that are part of common Office applications and are used to customize styles. The base templates within the application are used each time an application starts. Office Visual Basic for Applications (VBA) macros can be inserted into the base template and used to execute code when the respective Office application starts in order to obtain persistence. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-6, AC-10, AC-17, CM-2, CM-6, CM-8, RA-5, SC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1137-office-application-startup"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1137-002-office-test",
    "title": "MITRE ATT&CK T1137.002: Office Test (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1137.002 (Office Test) is an Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse the Microsoft Office \"Office Test\" Registry key to obtain persistence on a compromised system. An Office Test Registry location exists that allows a user to specify an arbitrary DLL that will be executed every time an Office application is started. This Registry key is thought to be used by Microsoft to load DLLs for testing and debugging purposes while developing Office applications. This Registry key is not created by default during an Office installation. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1054 Software Configuration, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-6, AC-10, AC-14, AC-17, CM-2, CM-5, CM-6, CM-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1137-office-application-startup"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1137-003-outlook-forms",
    "title": "MITRE ATT&CK T1137.003: Outlook Forms (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1137.003 (Outlook Forms) is an Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse Microsoft Outlook forms to obtain persistence on a compromised system. Outlook forms are used as templates for presentation and functionality in Outlook messages. Custom Outlook forms can be created that will execute code when a specifically crafted email is sent by an adversary utilizing the same custom Outlook form. Once malicious forms have been added to the user's mailbox, they will be loaded when Outlook is started. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1051 Update Software, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-6, AC-10, AC-17, CM-2, CM-6, CM-8, RA-5, SC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1137-office-application-startup"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1137-004-outlook-home-page",
    "title": "MITRE ATT&CK T1137.004: Outlook Home Page (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1137.004 (Outlook Home Page) is an Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse Microsoft Outlook's Home Page feature to obtain persistence on a compromised system. Outlook Home Page is a legacy feature used to customize the presentation of Outlook folders. This feature allows for an internal or external URL to be loaded and presented whenever a folder is opened. A malicious HTML page can be crafted that will execute code when loaded by Outlook Home Page. Once malicious home pages have been added to the user's mailbox, they will be loaded when Outlook is started. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1051 Update Software, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-6, AC-10, AC-17, CM-2, CM-6, CM-8, RA-5, SC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1137-office-application-startup"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1137-005-outlook-rules",
    "title": "MITRE ATT&CK T1137.005: Outlook Rules (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1137.005 (Outlook Rules) is an Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system. Outlook rules allow a user to define automated behavior to manage email messages. A benign rule might, for example, automatically move an email to a particular folder in Outlook if it contains specific words from a specific sender. Malicious Outlook rules can be created that can trigger code execution when an adversary sends a specifically crafted email to that user. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1051 Update Software, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-6, AC-10, AC-17, CM-2, CM-6, CM-8, RA-5, SC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1137-office-application-startup"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1137-006-add-ins",
    "title": "MITRE ATT&CK T1137.006: Add-ins (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1137.006 (Add-ins) is an Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system. Office add-ins can be used to add functionality to Office programs. There are different types of add-ins that can be used by the various Office products; including Word/Excel add-in Libraries (WLL/XLL), VBA add-ins, Office Component Object Model (COM) add-ins, automation add-ins, VBA Editor (VBE), Visual Studio Tools for Office (VSTO) add-ins, and Outlook add-ins. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-6, AC-10, AC-17, CM-2, CM-6, CM-8, RA-5, SC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1137-office-application-startup"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1137-office-application-startup",
    "title": "MITRE ATT&CK T1137: Office Application Startup (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1137 (Office Application Startup) is an Enterprise Persistence technique. Adversaries may leverage Microsoft Office-based applications for persistence between startups. Microsoft Office is a fairly common application suite on Windows-based operating systems within an enterprise network. There are multiple mechanisms that can be used with Office for persistence when an Office-based application is started; this can include the use of Office Template Macros and add-ins. ATT&CK documents 6 sub-techniques: T1137.001 Office Template Macros; T1137.002 Office Test; T1137.003 Outlook Forms; T1137.004 Outlook Home Page; T1137.005 Outlook Rules; T1137.006 Add-ins. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1040 Behavior Prevention on Endpoint, M1051 Update Software, M1054 Software Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-6, AC-10, AC-17, CM-2, CM-6, CM-8, RA-5, SC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1140-deobfuscate-decode-files",
    "title": "MITRE ATT&CK T1140: Deobfuscate/Decode Files or Information (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1140 describes adversary actions to reverse obfuscation or encoding applied to payloads after delivery to enable execution. Common patterns include base64 decoding, certutil decoding, PowerShell encoded-command unwrapping, and custom decryption routines. T1140 is the runtime counterpart to T1027 (Obfuscated Files) and is the moment when AMSI scanning becomes effective. Compliance obligations include AMSI integration (NIST 800-53 SI-3), runtime memory scanning, and behavioural detection of decoding patterns under NIS2 Article 21 and ISO 27001 A.8.7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1027-obfuscated-files-information",
      "mitre-attack-t1059-command-and-scripting-interpreter"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1176-001-browser-extensions",
    "title": "MITRE ATT&CK T1176.001: Browser Extensions (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1176.001 (Browser Extensions) is an Enterprise Persistence technique. Adversaries may abuse internet browser extensions to establish persistent access to victim systems. Browser extensions or plugins are small programs that can add functionality to and customize aspects of internet browsers. They can be installed directly via a local file or custom URL or through a browser's app store - an official online platform where users can browse, install, and manage extensions for a specific web browser. Extensions generally inherit the web browser's permissions previously granted. Malicious extensions can be installed into a browser through malicious app store downloads masquerading as legitimate extensions, through social engineering, or by an adversary that has already compromised a system. Security can be limited on browser app stores, so it may not be difficult ... Affected platforms: Linux, Windows, macOS. Sub-technique of ATT&CK T1176. ATT&CK-mapped mitigations: M1033 Limit Software Installation, M1047 Audit, M1051 Update Software, M1017 User Training, M1038 Execution Prevention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-attack-t1176-002-ide-extensions",
    "title": "MITRE ATT&CK T1176.002: IDE Extensions (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1176.002 (IDE Extensions) is an Enterprise Persistence technique. Adversaries may abuse an integrated development environment (IDE) extension to establish persistent access to victim systems. IDEs such as Visual Studio Code, IntelliJ IDEA, and Eclipse support extensions - software components that add features like code linting, auto-completion, task automation, or integration with tools like Git and Docker. A malicious extension can be installed through an extension marketplace (i.e., Compromise Software Dependencies and Development Tools) or side-loaded directly into the IDE. In addition to installing malicious extensions, adversaries may also leverage benign ones. For example, adversaries may establish persistent SSH tunnels via the use of the VSCode Remote SSH extension (i.e., IDE Tunneling). Trust is typically established through the installation pro... Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1176. ATT&CK-mapped mitigations: M1038 Execution Prevention, M1051 Update Software, M1047 Audit, M1033 Limit Software Installation, M1017 User Training.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-attack-t1176-browser-extensions",
    "title": "MITRE ATT&CK T1176: Software Extensions (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-07-23",
    "bluf": "MITRE ATT&CK T1176 (Browser Extensions) is an Enterprise Persistence technique. Adversaries may abuse Internet browser extensions to establish persistent access to victim systems. Browser extensions or plugins are small programs that can add functionality and customize aspects of Internet browsers. They can be installed directly or through a browser's app store and generally have access and permissions to everything that the browser can access. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1033 Limit Software Installation, M1047 Audit, M1051 Update Software, M1017 User Training, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-6, CA-7, CM-2, CM-3, CM-5, CM-6, CM-7, CM-11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1185-browser-session-hijacking",
    "title": "MITRE ATT&CK T1185: Browser Session Hijacking (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1185 (Browser Session Hijacking) is an Enterprise Collection technique. Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking techniques. A specific example is when an adversary injects software into a browser that allows them to inherit cookies, HTTP sessions, and SSL client certificates of a user then use the browser as a way to pivot into an authenticated intranet. Affected platforms: Windows. MITRE-documented mitigations include M1017 User Training, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-10, AC-12, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1187-forced-authentication",
    "title": "MITRE ATT&CK T1187: Forced Authentication (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1187 (Forced Authentication) is an Enterprise Credential Access technique. Adversaries may gather credential material by invoking or forcing a user to automatically provide authentication information through a mechanism in which they can intercept. The Server Message Block (SMB) protocol is commonly used in Windows networks for authentication and communication between systems for access to resources and file sharing. Affected platforms: Windows. MITRE-documented mitigations include M1027 Password Policies, M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1189-drive-by-compromise",
    "title": "MITRE ATT&CK T1189: Drive-by Compromise (Enterprise Tactic TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1189 (Drive-by Compromise) is an Enterprise Initial Access technique. Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. With this technique, the user's web browser is typically targeted for exploitation, but adversaries may also use compromised websites for non-exploitation behavior such as acquiring Application Access Token. Affected platforms: Windows, Linux, macOS, Identity Provider. MITRE-documented mitigations include M1050 Exploit Protection, M1051 Update Software, M1048 Application Isolation and Sandboxing, M1021 Restrict Web-Based Content. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, AC-6, CA-7, CM-2, CM-6, CM-8, SA-22, SC-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1190-exploit-public-facing-application",
    "title": "MITRE ATT&CK T1190: Exploit Public-Facing Application (Enterprise Tactic TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1190 describes adversary exploitation of weaknesses in internet-facing applications, services, or APIs to gain initial network access. Notable real-world exploitations include MOVEit (CVE-2023-34362, Clop ransomware campaign 2,600+ victims), Log4Shell (CVE-2021-44228), Citrix Bleed (CVE-2023-4966), and Ivanti Connect Secure (CVE-2023-46805). Mandatory compliance obligations include vulnerability management programmes (NIST 800-53 RA-5/SI-2, ISO A.8.8), web application firewalls (PCI DSS Req 6.4.2), and rapid patching SLAs (NIS2 mandates 24-hour notification for actively exploited vulnerabilities).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "owasp-asvs-l2",
      "pci-dss-v4-req-1-2-network-security"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1195-001-compromise-software-dependencies-and-development-tools",
    "title": "MITRE ATT&CK T1195.001: Compromise Software Dependencies and Development Tools (Enterprise Tactic TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1195.001 (Compromise Software Dependencies and Development Tools) is an Enterprise Initial Access sub-technique of T1195 (Supply Chain Compromise). Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications may be targeted as a means to add malicious code to users of the dependency. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1033 Limit Software Installation, M1016 Vulnerability Scanning, M1051 Update Software, M1013 Application Developer Guidance. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-2, CA-7, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1195-002-compromise-software-supply-chain",
    "title": "MITRE ATT&CK T1195.002: Compromise Software Supply Chain (Enterprise Tactic TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1195.002 (Compromise Software Supply Chain) is an Enterprise Initial Access sub-technique of T1195 (Supply Chain Compromise). Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1051 Update Software, M1016 Vulnerability Scanning. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-2, CA-7, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1195-003-compromise-hardware-supply-chain",
    "title": "MITRE ATT&CK T1195.003: Compromise Hardware Supply Chain (Enterprise Tactic TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1195.003 (Compromise Hardware Supply Chain) is an Enterprise Initial Access sub-technique of T1195 (Supply Chain Compromise). Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise. By modifying hardware or firmware in the supply chain, adversaries can insert a backdoor into consumer networks that may be difficult to detect and give the adversary a high degree of control over the system. Hardware backdoors may be inserted into various devices, such as servers, workstations, network infrastructure, or peripherals. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1046 Boot Integrity. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-2, CA-7, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1195-supply-chain-compromise",
    "title": "MITRE ATT&CK T1195: Supply Chain Compromise (Enterprise Tactic TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1195 (Supply Chain Compromise) is an Enterprise Initial Access technique. Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise can take place at any stage of the supply chain including: * Manipulation of development tools * Manipulation of a development environment * Manipulation of source code repositories (public or private) * Manipulation of source code in open-source dependencies * Manipulation of software update/distribution mechanisms * Compromised/infected. ATT&CK documents 3 sub-techniques: T1195.001 Compromise Software Dependencies and Development Tools; T1195.002 Compromise Software Supply Chain; T1195.003 Compromise Hardware Supply Chain. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1046 Boot Integrity, M1013 Application Developer Guidance, M1051 Update Software, M1018 User Account Management, M1016 Vulnerability Scanning, M1033 Limit Software Installation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-2, CA-7, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1197-bits-jobs",
    "title": "MITRE ATT&CK T1197: BITS Jobs (Enterprise Tactic TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1197 (BITS Jobs) is an Enterprise Defense Evasion and Persistence technique. Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks. Windows Background Intelligent Transfer Service (BITS) is a low-bandwidth, asynchronous file transfer mechanism exposed through Component Object Model (COM). BITS is commonly used by updaters, messengers, and other applications preferred to operate in the background (using available idle bandwidth) without interrupting other networked applications. Affected platforms: Windows. MITRE-documented mitigations include M1018 User Account Management, M1037 Filter Network Traffic, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1199-trusted-relationship",
    "title": "MITRE ATT&CK T1199: Trusted Relationship (Enterprise Tactic TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1199 (Trusted Relationship) is an Enterprise Initial Access technique. Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network. Organizations often grant elevated access to second or third-party external providers in order to allow them to manage internal systems as well as cloud-based environments. Affected platforms: Windows, SaaS, IaaS, Linux, macOS, Identity Provider, Office Suite. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1018 User Account Management, M1030 Network Segmentation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-6, AC-8, CM-6, CM-7, SC-7, SC-46.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1200-hardware-additions",
    "title": "MITRE ATT&CK T1200: Hardware Additions (Enterprise Tactic TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1200 (Hardware Additions) is an Enterprise Initial Access technique. Adversaries may introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access. Rather than just connecting and distributing payloads via removable storage (i.e. Replication Through Removable Media), more robust hardware additions can be used to introduce new functionalities and/or features into a system that can then be abused. Affected platforms: Windows, Linux, macOS. MITRE-documented mitigations include M1035 Limit Access to Resource Over Network, M1034 Limit Hardware Installation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-6, AC-20, MP-7, SC-41.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1201-password-policy-discovery",
    "title": "MITRE ATT&CK T1201: Password Policy Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1201 (Password Policy Discovery) is an Enterprise Discovery technique. Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment. Password policies are a way to enforce complex passwords that are difficult to guess or crack through Brute Force. This information may help the adversary to create a list of common passwords and launch dictionary and/or brute force attacks which adheres to the policy (e.g. Affected platforms: Windows, Linux, macOS, IaaS, Network, Identity Provider, SaaS, Office Suite. MITRE-documented mitigations include M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CA-7, CM-2, CM-6, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1202-indirect-command-execution",
    "title": "MITRE ATT&CK T1202: Indirect Command Execution (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1202 (Indirect Command Execution) is an Enterprise Defense Evasion technique. Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, Forfiles, the Program Compatibility Assistant (pcalua.exe), components of the Windows Subsystem for Linux (WSL), Scriptrunner.exe, as well as other utilities may invoke the execution of programs and commands from a Command and Scripting Interpreter, Run window, or via. Affected platforms: Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1203-exploitation-for-client-execution",
    "title": "MITRE ATT&CK T1203: Exploitation for Client Execution (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1203 (Exploitation for Client Execution) is an Enterprise Execution technique. Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1050 Exploit Protection, M1051 Update Software, M1048 Application Isolation and Sandboxing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, AC-6, CA-7, CM-8, SC-2, SC-3, SC-7, SC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1204-001-malicious-link",
    "title": "MITRE ATT&CK T1204.001: Malicious Link (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1204.001 (Malicious Link) is an Enterprise Execution sub-technique of T1204 (User Execution). An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Link. Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via Exploitation for Client Execution. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention, M1017 User Training, M1021 Restrict Web-Based Content. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-44, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1204-user-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1204-002-malicious-file",
    "title": "MITRE ATT&CK T1204.002: Malicious File (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1204.002 (Malicious File) is an Enterprise Execution sub-technique of T1204 (User Execution). An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, and .reg. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1040 Behavior Prevention on Endpoint, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-44, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1204-user-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1204-003-malicious-image",
    "title": "MITRE ATT&CK T1204.003: Malicious Image (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1204.003 (Malicious Image) is an Enterprise Execution sub-technique of T1204 (User Execution). Adversaries may rely on a user running a malicious image to facilitate execution. Amazon Web Services (AWS) Amazon Machine Images (AMIs), Google Cloud Platform (GCP) Images, and Azure Images as well as popular container runtimes such as Docker can be backdoored. Affected platforms: IaaS, Containers. MITRE-documented mitigations include M1045 Code Signing, M1031 Network Intrusion Prevention, M1017 User Training, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, RA-5, SC-7, SC-44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1204-user-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1204-004-malicious-copy-and-paste",
    "title": "MITRE ATT&CK T1204.004: Malicious Copy and Paste (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1204.004 (Malicious Copy and Paste) is an Enterprise Execution technique. An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is \"ClickFix,\" in which adversaries present users with seemingly helpful solutions—such as prompts to fix errors or complete CAPTCHAs—that instead instruct the user to copy and paste malicious code. Malicious websites, such as those used in Drive-by Compromise, may present fake error messages or CAPTCHA prompts that instruct users to open a terminal or the Windows Run Dialog box and execute an arbitrary command. These commands may be obfuscated using encoding or other techniques to conceal malicious intent. Once executed, the adversary will typically be able... Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1204. ATT&CK-mapped mitigations: M1038 Execution Prevention, M1031 Network Intrusion Prevention, M1021 Restrict Web-Based Content.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1204-005-malicious-library",
    "title": "MITRE ATT&CK T1204.005: Malicious Library (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1204.005 (Malicious Library) is an Enterprise Execution technique. Adversaries may rely on a user installing a malicious library to facilitate execution. Threat actors may Upload Malware to package managers such as NPM and PyPi, as well as to public code repositories such as GitHub. User may install libraries without realizing they are malicious, thus bypassing techniques that specifically achieve Initial Access. This can lead to the execution of malicious code, such as code that establishes persistence, steals data, or mines cryptocurrency. In some cases, threat actors may compromise and backdoor existing popular libraries (i.e., Compromise Software Dependencies and Development Tools). Alternatively, they may create entirely new packages and leverage behaviors such as typosquatting to encourage users to install them. Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1204. ATT&CK-mapped mitigations: M1033 Limit Software Installation, M1031 Network Intrusion Prevention, M1017 User Training.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1204-user-execution",
    "title": "MITRE ATT&CK T1204: User Execution (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1204 covers adversary reliance on specific actions by users to execute malicious code. Sub-techniques cover Malicious Link (T1204.001), Malicious File (T1204.002), and Malicious Image (T1204.003). User Execution is the second-most common execution vector after Command Interpreter (T1059) per MITRE telemetry. Compliance obligations include user awareness training (NIST 800-53 AT-2, ISO A.6.3), file detonation (PCI DSS Req 5), browser isolation for high-risk users (DORA Article 9), and rapid containment when execution occurs (NIST CSF RESPOND function).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1566-phishing",
      "cis-controls-v8"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1205-001-port-knocking",
    "title": "MITRE ATT&CK T1205.001: Port Knocking (Enterprise Tactic TA0005 - Defense Evasion / TA0003 - Persistence / TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1205.001 (Port Knocking) is an Enterprise Defense Evasion and Persistence and Command and Control sub-technique of T1205 (Traffic Signaling). Adversaries may use port knocking to hide open ports used for persistence or command and control. To enable a port, an adversary sends a series of attempted connections to a predefined sequence of closed ports. After the sequence is completed, opening a port is often accomplished by the host based firewall, but could also be implemented by custom software. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1205-traffic-signaling"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1205-002-socket-filters",
    "title": "MITRE ATT&CK T1205.002: Socket Filters (Enterprise Tactic TA0005 - Defense Evasion / TA0003 - Persistence / TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1205.002 (Socket Filters) is an Enterprise Defense Evasion and Persistence and Command and Control sub-technique of T1205 (Traffic Signaling). Adversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or command and control. With elevated permissions, adversaries can use features such as the libpcap library to open sockets and install filters to allow or disallow certain types of data to come through the socket. The filter may apply to all traffic passing through the specified network interface (or every interface if not specified). Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1205-traffic-signaling"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1205-traffic-signaling",
    "title": "MITRE ATT&CK T1205: Traffic Signaling (Enterprise Tactic TA0005 - Defense Evasion / TA0003 - Persistence / TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1205 (Traffic Signaling) is an Enterprise Defense Evasion and Persistence and Command and Control technique. Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control. Traffic signaling involves the use of a magic value or sequence that must be sent to a system to trigger a special response, such as opening a closed port or executing a malicious task. This may take the form of sending a series of packets with certain characteristics before a port will be opened that the adversary can use for command and control. ATT&CK documents 2 sub-techniques: T1205.001 Port Knocking; T1205.002 Socket Filters. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1037 Filter Network Traffic, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1207-rogue-domain-controller",
    "title": "MITRE ATT&CK T1207: Rogue Domain Controller (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1207 (Rogue Domain Controller) is an Enterprise Defense Evasion technique. Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data. DCShadow may be used to create a rogue Domain Controller (DC). DCShadow is a method of manipulating Active Directory (AD) data, including objects and schemas, by registering (or reusing an inactive registration) and simulating the behavior of a DC. Once registered, a rogue DC may be able to inject and replicate changes into AD infrastructure for any domain object, including credentials and keys. Affected platforms: Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1210-exploitation-of-remote-services",
    "title": "MITRE ATT&CK T1210: Exploitation of Remote Services (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1210 (Exploitation of Remote Services) is an Enterprise Lateral Movement technique. Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. A common goal for post-compromise exploitation of remote services is for lateral movement to enable access to a remote system. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1016 Vulnerability Scanning, M1050 Exploit Protection, M1030 Network Segmentation, M1019 Threat Intelligence Program, M1048 Application Isolation and Sandboxing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-2, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1211-exploitation-for-defense-evasion",
    "title": "MITRE ATT&CK T1211: Exploitation for Stealth (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1211 (Exploitation for Stealth) is an Enterprise Defense Evasion technique. Adversaries may exploit a system or application vulnerability to bypass security features. Exploitation of a vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Vulnerabilities may exist in defensive security software that can be used to disable or circumvent them. Affected platforms: Linux, Windows, macOS, SaaS, IaaS. MITRE-documented mitigations include M1050 Exploit Protection, M1051 Update Software, M1019 Threat Intelligence Program, M1048 Application Isolation and Sandboxing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, AC-6, CA-7, CM-2, CM-6, CM-8, RA-5, RA-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1212-exploitation-for-credential-access",
    "title": "MITRE ATT&CK T1212: Exploitation for Credential Access (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1212 (Exploitation for Credential Access) is an Enterprise Credential Access technique. Adversaries may exploit software vulnerabilities in an attempt to collect credentials. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Credentialing and authentication mechanisms may be targeted for exploitation by adversaries as a means to gain access to useful credentials or circumvent the process to gain authenticated access to systems. Affected platforms: Linux, Windows, macOS, Identity Provider. MITRE-documented mitigations include M1050 Exploit Protection, M1051 Update Software, M1013 Application Developer Guidance, M1019 Threat Intelligence Program, M1048 Application Isolation and Sandboxing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-4, AC-6, CA-7, CM-2, CM-6, CM-8, IA-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1213-001-confluence",
    "title": "MITRE ATT&CK T1213.001: Confluence (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1213.001 (Confluence) is an Enterprise Collection sub-technique of T1213 (Data from Information Repositories). Adversaries may leverage Confluence repositories to mine valuable information. Often found in development environments alongside Atlassian JIRA, Confluence is generally used to store development-related documentation, however, in general may contain more diverse categories of useful information, such as: * Policies, procedures, and standards * Physical / logical network diagrams * System architecture diagrams * Technical system documentation * Testing / development credentials (i.e., Unsecured Credentials) * Work. Affected platforms: SaaS. MITRE-documented mitigations include M1017 User Training, M1047 Audit, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1213-data-from-information-repositories"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1213-002-sharepoint",
    "title": "MITRE ATT&CK T1213.002: Sharepoint (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1213.002 (Sharepoint) is an Enterprise Collection sub-technique of T1213 (Data from Information Repositories). Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint: * Policies, procedures, and standards * Physical / logical network diagrams * System architecture diagrams * Technical system. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1047 Audit, M1018 User Account Management, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1213-data-from-information-repositories"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1213-003-code-repositories",
    "title": "MITRE ATT&CK T1213.003: Code Repositories (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1213.003 (Code Repositories) is an Enterprise Collection sub-technique of T1213 (Data from Information Repositories). Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git. Affected platforms: SaaS. MITRE-documented mitigations include M1017 User Training, M1047 Audit, M1018 User Account Management, M1032 Multi-factor Authentication. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1213-data-from-information-repositories"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1213-004-customer-relationship-management-software",
    "title": "MITRE ATT&CK T1213.004: Customer Relationship Management Software (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1213.004 (Customer Relationship Management Software) is an Enterprise Collection sub-technique of T1213 (Data from Information Repositories). Adversaries may leverage Customer Relationship Management (CRM) software to mine valuable information. CRM software is used to assist organizations in tracking and managing customer interactions, as well as storing customer data. Once adversaries gain access to a victim organization, they may mine CRM software for customer data. Affected platforms: SaaS. MITRE-documented mitigations include M1018 User Account Management, M1017 User Training, M1054 Software Configuration, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1213-data-from-information-repositories"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1213-005-messaging-applications",
    "title": "MITRE ATT&CK T1213.005: Messaging Applications (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1213.005 (Messaging Applications) is an Enterprise Collection sub-technique of T1213 (Data from Information Repositories). Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information. The following is a brief list of example information that may hold potential value to an adversary and may also be found on messaging applications: * Testing / development credentials (i.e., Chat Messages) * Source code snippets * Links to network shares and other internal resources * Proprietary data * Discussions about ongoing incident response efforts In addition to. Affected platforms: SaaS, Office Suite. MITRE-documented mitigations include M1017 User Training, M1047 Audit, M1060 Out-of-Band Communications Channel. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1213-data-from-information-repositories"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1213-006-databases",
    "title": "MITRE ATT&CK T1213.006: Databases (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1213.006 (Databases) is an Enterprise Collection technique. Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the cloud (both in platform-as-a-service and software-as-a-service environments). Examples of databases from which information may be collected include MySQL, PostgreSQL, MongoDB, Amazon Relational Database Service, Azure SQL Database, Google Firebase, and Snowflake. Databases may include a variety of information of interest to adversaries, such as usernames, hashed passwords, personally identifiable information, and financial data. Data collected from databases may be used for Lateral Movement, Command and Control, or Exfiltration. Data exfiltrated from databases may also be used to extort victims or may be sold for profit. Affected platforms: IaaS, Linux, macOS, SaaS, Windows. Sub-technique of ATT&CK T1213. ATT&CK-mapped mitigations: M1017 User Training, M1041 Encrypt Sensitive Information, M1054 Software Configuration, M1018 User Account Management, M1047 Audit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-attack-t1213-data-from-information-repositories",
    "title": "MITRE ATT&CK T1213: Data from Information Repositories (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1213 (Data from Information Repositories) is an Enterprise Collection technique. Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. ATT&CK documents 5 sub-techniques: T1213.001 Confluence; T1213.002 Sharepoint; T1213.003 Code Repositories; T1213.004 Customer Relationship Management Software; T1213.005 Messaging Applications. Affected platforms: Linux, Windows, macOS, SaaS, IaaS, Office Suite. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1060 Out-of-Band Communications Channel, M1017 User Training, M1054 Software Configuration, M1018 User Account Management, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1216-001-pubprn",
    "title": "MITRE ATT&CK T1216.001: PubPrn (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1216.001 (PubPrn) is an Enterprise Defense Evasion sub-technique of T1216 (System Script Proxy Execution). Adversaries may use PubPrn to proxy execution of malicious remote files. PubPrn.vbs is a Visual Basic script that publishes a printer to Active Directory Domain Services. The script may be signed by Microsoft and is commonly executed through the Windows Command Shell via Cscript.exe. For example, the following code publishes a printer within the specified domain: cscript pubprn Printer1 LDAP://CN=Container1,DC=Domain1,DC=Com. Adversaries may abuse PubPrn to execute malicious payloads hosted on remote sites. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-6, CM-7, SI-4, SI-7, SI-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1216-system-script-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1216-002-syncappvpublishingserver",
    "title": "MITRE ATT&CK T1216.002: SyncAppvPublishingServer (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1216.002 (SyncAppvPublishingServer) is an Enterprise Defense Evasion sub-technique of T1216 (System Script Proxy Execution). Adversaries may abuse SyncAppvPublishingServer.vbs to proxy execution of malicious PowerShell commands. SyncAppvPublishingServer.vbs is a Visual Basic script associated with how Windows virtualizes applications (Microsoft Application Virtualization, or App-V). For example, Windows may render Win32 applications to users as virtual applications, allowing users to launch and interact with them as if they were installed locally. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-6, CM-7, SI-4, SI-7, SI-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1216-system-script-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1216-system-script-proxy-execution",
    "title": "MITRE ATT&CK T1216: System Script Proxy Execution (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1216 (System Script Proxy Execution) is an Enterprise Defense Evasion technique. Adversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files. Several Microsoft signed scripts that have been downloaded from Microsoft or are default on Windows installations can be used to proxy execution of other files. This behavior may be abused by adversaries to execute malicious files that could bypass application control and signature validation on systems. ATT&CK documents 2 sub-techniques: T1216.001 PubPrn; T1216.002 SyncAppvPublishingServer. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-6, CM-7, SI-4, SI-7, SI-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1217-browser-information-discovery",
    "title": "MITRE ATT&CK T1217: Browser Information Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1217 (Browser Information Discovery) is an Enterprise Discovery technique. Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure. Affected platforms: Linux, Windows, macOS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1218-001-compiled-html-file",
    "title": "MITRE ATT&CK T1218.001: Compiled HTML File (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1218.001 (Compiled HTML File) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse Compiled HTML files (.chm) to conceal malicious code. CHM files are commonly distributed as part of the Microsoft HTML Help system. CHM files are compressed compilations of various content such as HTML documents, images, and scripting/web related programming languages such VBA, JScript, Java, and ActiveX. CHM content is displayed using underlying components of the Internet Explorer browser loaded by the HTML Help executable program (hh.exe). Affected platforms: Windows. MITRE-documented mitigations include M1021 Restrict Web-Based Content, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1218-system-binary-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1218-002-control-panel",
    "title": "MITRE ATT&CK T1218.002: Control Panel (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1218.002 (Control Panel) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse control.exe to proxy execution of malicious payloads. The Windows Control Panel process binary (control.exe) handles execution of Control Panel items, which are utilities that allow users to view and adjust computer settings. Control Panel items are registered executable (.exe) or Control Panel (.cpl) files, the latter are actually renamed dynamic-link library (.dll) files that export a CPlApplet function. Affected platforms: Windows. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1218-system-binary-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1218-003-cmstp",
    "title": "MITRE ATT&CK T1218.003: CMSTP (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1218.003 (CMSTP) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse CMSTP to proxy execution of malicious code. The Microsoft Connection Manager Profile Installer (CMSTP.exe) is a command-line program used to install Connection Manager service profiles. CMSTP.exe accepts an installation information file (INF) as a parameter and installs a service profile leveraged for remote access connections. Adversaries may supply CMSTP.exe with INF files infected with malicious commands. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1218-system-binary-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1218-004-installutil",
    "title": "MITRE ATT&CK T1218.004: InstallUtil (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1218.004 (InstallUtil) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility. InstallUtil is a command-line utility that allows for installation and uninstallation of resources by executing specific installer components specified in .NET binaries. The InstallUtil binary may also be digitally signed by Microsoft and located in the .NET directories on a Windows system: C:\\Windows\\Microsoft.NET\\Framework\\v<version>\\InstallUtil.exe and C:\\Windows\\Microsoft.NET\\Framework64\\v<version>\\InstallUtil.exe. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1218-system-binary-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1218-005-mshta",
    "title": "MITRE ATT&CK T1218.005: Mshta (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1218.005 (Mshta) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code Mshta.exe is a utility that executes Microsoft HTML Applications (HTA) files. HTAs are standalone applications that execute using the same models and technologies of Internet Explorer, but outside of the browser. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1218-system-binary-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1218-007-msiexec",
    "title": "MITRE ATT&CK T1218.007: Msiexec (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1218.007 (Msiexec) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi). The Msiexec.exe binary may also be digitally signed by Microsoft. Adversaries may abuse msiexec.exe to launch local or network accessible MSI files. Msiexec.exe can also execute DLLs. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1218-system-binary-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1218-008-odbcconf",
    "title": "MITRE ATT&CK T1218.008: Odbcconf (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1218.008 (Odbcconf) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse odbcconf.exe to proxy execution of malicious payloads. Odbcconf.exe is a Windows utility that allows you to configure Open Database Connectivity (ODBC) drivers and data source names. The Odbcconf.exe binary may be digitally signed by Microsoft. Adversaries may abuse odbcconf.exe to bypass application control solutions that do not account for its potential abuse. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1218-system-binary-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1218-009-regsvcs-regasm",
    "title": "MITRE ATT&CK T1218.009: Regsvcs/Regasm (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1218.009 (Regsvcs/Regasm) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse Regsvcs and Regasm to proxy execution of code through a trusted Windows utility. Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies. Both are binaries that may be digitally signed by Microsoft. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1218-system-binary-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1218-010-regsvr32",
    "title": "MITRE ATT&CK T1218.010: Regsvr32 (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1218.010 (Regsvr32) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object linking and embedding controls, including dynamic link libraries (DLLs), on Windows systems. The Regsvr32.exe binary may also be signed by Microsoft. Affected platforms: Windows. MITRE-documented mitigations include M1050 Exploit Protection. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1218-system-binary-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1218-011-rundll32",
    "title": "MITRE ATT&CK T1218.011: Rundll32 (Sub-Technique of T1218 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1218.011 covers adversary use of rundll32.exe to proxy execute malicious DLLs and bypass application allowlisting. Variants include DLL with exported function, javascript: protocol (rundll32 javascript:), and SCT abuse. Used by Cobalt Strike, IcedID, Qakbot, and most commodity loaders. Compliance: NIST 800-53 SI-7, CM-7, SI-4, ISO 27001 A.8.7, A.8.16, PCI DSS Req 5.2, Req 10.4. ASD Essential Eight Application Control explicitly addresses rundll32 abuse.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1218-system-binary-proxy-execution",
      "mitre-attack-t1027-obfuscated-files-information",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1218-012-verclsid",
    "title": "MITRE ATT&CK T1218.012: Verclsid (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1218.012 (Verclsid) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse verclsid.exe to proxy execution of malicious code. Verclsid.exe is known as the Extension CLSID Verification Host and is responsible for verifying each shell extension before they are used by Windows Explorer or the Windows Shell. Adversaries may abuse verclsid.exe to execute malicious payloads. This may be achieved by running verclsid.exe /S /C {CLSID}, where the file is referenced by a Class ID (CLSID), a unique identification number used to identify COM objects. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1037 Filter Network Traffic, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1218-system-binary-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1218-013-mavinject",
    "title": "MITRE ATT&CK T1218.013: Mavinject (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1218.013 (Mavinject) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse mavinject.exe to proxy execution of malicious code. Mavinject.exe is the Microsoft Application Virtualization Injector, a Windows utility that can inject code into external processes as part of Microsoft Application Virtualization (App-V). Adversaries may abuse mavinject.exe to inject malicious DLLs into running processes (i.e. Dynamic-link Library Injection), allowing for arbitrary code execution (ex. C:\\Windows\\system32\\mavinject.exe PID /INJECTRUNNING PATH_DLL). Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1218-system-binary-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1218-014-mmc",
    "title": "MITRE ATT&CK T1218.014: MMC (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1218.014 (MMC) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse mmc.exe to proxy execution of malicious .msc files. Microsoft Management Console (MMC) is a binary that may be signed by Microsoft and is used in several ways in either its GUI or in a command prompt. MMC can be used to create, open, and save custom consoles that contain administrative tools created by Microsoft, called snap-ins. These snap-ins may be used to manage Windows systems locally or remotely. MMC can also be used to open Microsoft created .msc files to manage system configuration. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1218-system-binary-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1218-015-electron-applications",
    "title": "MITRE ATT&CK T1218.015: Electron Applications (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1218.015 (Electron Applications) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse components of the Electron framework to execute malicious code. The Electron framework hosts many common applications such as Signal, Slack, and Microsoft Teams. Originally developed by GitHub, Electron is a cross-platform desktop application development framework that employs web technologies like JavaScript, HTML, and CSS. The Chromium engine is used to display web content and Node.js runs the backend code. Affected platforms: macOS, Windows, Linux. MITRE-documented mitigations include M1050 Exploit Protection, M1042 Disable or Remove Feature or Program, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1218-system-binary-proxy-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1218-system-binary-proxy-execution",
    "title": "MITRE ATT&CK T1218: System Binary Proxy Execution (Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1218 covers adversary use of legitimate signed Windows binaries (LOLBins - Living Off The Land Binaries) to proxy execution of malicious payloads and bypass application allowlisting. Sub-techniques include Compiled HTML File (T1218.001), Control Panel (T1218.002), CMSTP (T1218.003), InstallUtil (T1218.004), Mshta (T1218.005), Odbcconf (T1218.008), Regsvcs/Regasm (T1218.009), Regsvr32 (T1218.010), Rundll32 (T1218.011). LOLBAS project catalogues 200+ such patterns. Compliance: NIST 800-53 SI-7, CM-7, AU-2, ISO 27001 A.8.7, A.8.16, PCI DSS Req 5 and Req 10.4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1059-command-and-scripting-interpreter",
      "mitre-attack-t1027-obfuscated-files-information",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1219-001-ide-tunneling",
    "title": "MITRE ATT&CK T1219.001: IDE Tunneling (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1219.001 (IDE Tunneling) is an Enterprise Command and Control technique. Adversaries may abuse Integrated Development Environment (IDE) software with remote development features to establish an interactive command and control channel on target systems within a network. IDE tunneling combines SSH, port forwarding, file sharing, and debugging into a single secure connection, letting developers work on remote systems as if they were local. Unlike SSH and port forwarding, IDE tunneling encapsulates an entire session and may use proprietary tunneling protocols alongside SSH, allowing adversaries to blend in with legitimate development workflows. Some IDEs, like Visual Studio Code, also provide CLI tools (e.g., `code tunnel`) that adversaries may use to programmatically establish tunnels and generate web-accessible URLs for remote access. These tunnels can be authent... Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1219. ATT&CK-mapped mitigations: M1038 Execution Prevention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1219-002-remote-desktop-software",
    "title": "MITRE ATT&CK T1219.002: Remote Desktop Software (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1219.002 (Remote Desktop Software) is an Enterprise Command and Control technique. An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interface for remotely controlling another computer, transmitting the display output, keyboard input, and mouse control between devices using various protocols. Desktop support software, such as `VNC`, `Team Viewer`, `AnyDesk`, `ScreenConnect`, `LogMein`, `AmmyyAdmin`, and other remote monitoring and management (RMM) tools, are commonly used as legitimate technical support software and may be allowed by application control within a target environment. Remote access modules/features may also exist as part of otherwise existing software such as Zoom or Google Chrome’s Remote Desktop. Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1219. ATT&CK-mapped mitigations: M1042 Disable or Remove Feature or Program, M1037 Filter Network Traffic, M1038 Execution Prevention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1219-003-remote-access-hardware",
    "title": "MITRE ATT&CK T1219.003: Remote Access Hardware (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1219.003 (Remote Access Hardware) is an Enterprise Command and Control technique. An adversary may use legitimate remote access hardware to establish an interactive command and control channel to target systems within networks. These services, including IP-based keyboard, video, or mouse (KVM) devices such as TinyPilot and PiKVM, are commonly used as legitimate tools and may be allowed by peripheral device policies within a target environment. Remote access hardware may be physically installed and used post-compromise as an alternate communications channel for redundant access or as a way to establish an interactive remote session with the target system. Using hardware-based remote access tools may allow threat actors to bypass software security solutions and gain more control over the compromised device(s). Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1219. ATT&CK-mapped mitigations: M1034 Limit Hardware Installation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1219-remote-access-software",
    "title": "MITRE ATT&CK T1219: Remote Access Tools (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-07-23",
    "bluf": "MITRE ATT&CK T1219 (Remote Access Software) is an Enterprise Command and Control technique. An adversary may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems within networks. These services, such as VNC, Team Viewer, AnyDesk, ScreenConnect, LogMein, AmmyyAdmin, and other remote monitoring and management (RMM) tools, are commonly used as legitimate technical support software and may be allowed by application control within a target environment. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1038 Execution Prevention, M1037 Filter Network Traffic, M1031 Network Intrusion Prevention, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-17, CA-7, CM-2, CM-6, CM-7, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1220-xsl-script-processing",
    "title": "MITRE ATT&CK T1220: XSL Script Processing (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1220 (XSL Script Processing) is an Enterprise Defense Evasion technique. Adversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files. Extensible Stylesheet Language (XSL) files are commonly used to describe the processing and rendering of data within XML files. To support complex operations, the XSL standard includes support for embedded scripting in various languages. Adversaries may abuse this functionality to execute arbitrary files while potentially bypassing application control. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-6, CM-7, SI-4, SI-7, SI-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1221-template-injection",
    "title": "MITRE ATT&CK T1221: Template Injection (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1221 (Template Injection) is an Enterprise Defense Evasion technique. Adversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts. For example, Microsoft's Office Open XML (OOXML) specification defines an XML-based format for Office documents (.docx, xlsx, .pptx) to replace older binary formats (.doc, .xls, .ppt). OOXML files are packed together ZIP archives compromised of various XML files, referred to as parts, containing properties that collectively define how a document is rendered. Affected platforms: Windows. MITRE-documented mitigations include M1049 Antivirus/Antimalware, M1031 Network Intrusion Prevention, M1017 User Training, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CA-7, CM-2, CM-6, CM-7, CM-8, RA-5, SC-7, SC-44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1222-001-windows-file-and-directory-permissions-modification",
    "title": "MITRE ATT&CK T1222.001: Windows Permissions (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1222.001 (Windows Permissions) is an Enterprise Defense Evasion sub-technique of T1222 (File and Directory Permissions Modification). Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.). Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CA-7, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1222-file-and-directory-permissions-modification"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1222-002-linux-and-mac-file-and-directory-permissions-modification",
    "title": "MITRE ATT&CK T1222.002: Linux and Mac Permissions (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1222.002 (Linux and Mac Permissions) is an Enterprise Defense Evasion sub-technique of T1222 (File and Directory Permissions Modification). Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.). Affected platforms: macOS, Linux. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CA-7, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1222-file-and-directory-permissions-modification"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1222-file-and-directory-permissions-modification",
    "title": "MITRE ATT&CK T1222: File and Directory Permissions Modification (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1222 (File and Directory Permissions Modification) is an Enterprise Defense Evasion technique. Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.). ATT&CK documents 2 sub-techniques: T1222.001 Windows File and Directory Permissions Modification; T1222.002 Linux and Mac File and Directory Permissions Modification. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CA-7, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1480-001-environmental-keying",
    "title": "MITRE ATT&CK T1480.001: Environmental Keying (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1480.001 (Environmental Keying) is an Enterprise Defense Evasion sub-technique of T1480 (Execution Guardrails). Adversaries may environmentally key payloads or other features of malware to evade defenses and constraint execution to a specific target environment. Environmental keying uses cryptography to constrain execution or actions based on adversary supplied environment specific conditions that are expected to be present on the target. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1055 Do Not Mitigate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1480-execution-guardrails"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1480-002-mutual-exclusion",
    "title": "MITRE ATT&CK T1480.002: Mutual Exclusion (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1480.002 (Mutual Exclusion) is an Enterprise Defense Evasion sub-technique of T1480 (Execution Guardrails). Adversaries may constrain execution or actions based on the presence of a mutex associated with malware. A mutex is a locking mechanism used to synchronize access to a resource. Only one thread or process can acquire a mutex at a given time. While local mutexes only exist within a given process, allowing multiple threads to synchronize access to a resource, system mutexes can be used to synchronize the activities of multiple processes. Affected platforms: Windows, Linux, macOS. MITRE-documented mitigations include M1055 Do Not Mitigate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1480-execution-guardrails"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1480-execution-guardrails",
    "title": "MITRE ATT&CK T1480: Execution Guardrails (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1480 (Execution Guardrails) is an Enterprise Defense Evasion technique. Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target. Guardrails ensure that a payload only executes against an intended target and reduces collateral damage from an adversary's campaign. ATT&CK documents 2 sub-techniques: T1480.001 Environmental Keying; T1480.002 Mutual Exclusion. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1055 Do Not Mitigate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1482-domain-trust-discovery",
    "title": "MITRE ATT&CK T1482: Domain Trust Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1482 (Domain Trust Discovery) is an Enterprise Discovery technique. Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. Affected platforms: Windows. MITRE-documented mitigations include M1047 Audit, M1030 Network Segmentation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CM-2, CM-6, CM-7, RA-5, SA-8, SA-17, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1484-001-group-policy-modification",
    "title": "MITRE ATT&CK T1484.001: Group Policy Modification (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1484.001 (Group Policy Modification) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1484 (Domain or Tenant Policy Modification). Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path \\<DOMAIN>\\SYSVOL\\<DOMAIN>\\Policies\\. Like other objects in AD, GPOs have access controls associated with them. Affected platforms: Windows. MITRE-documented mitigations include M1047 Audit, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1484-domain-or-tenant-policy-modification"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1484-002-trust-modification",
    "title": "MITRE ATT&CK T1484.002: Trust Modification (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1484.002 (Trust Modification) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1484 (Domain or Tenant Policy Modification). Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses and/or elevate privileges.Trust details, such as whether or not user identities are federated, allow authentication and authorization properties to apply between domains or tenants for the purpose of accessing shared resources. Affected platforms: Windows, Identity Provider. MITRE-documented mitigations include M1026 Privileged Account Management, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1484-domain-or-tenant-policy-modification"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1484-domain-or-tenant-policy-modification",
    "title": "MITRE ATT&CK T1484: Domain or Tenant Policy Modification (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1484 (Domain or Tenant Policy Modification) is an Enterprise Defense Evasion and Privilege Escalation technique. Adversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments. Such services provide a centralized means of managing identity resources such as devices and accounts, and often include configuration settings that may apply between domains or tenants such as trust relationships, identity syncing, or identity federation. ATT&CK documents 2 sub-techniques: T1484.001 Group Policy Modification; T1484.002 Trust Modification. Affected platforms: Windows, Identity Provider. MITRE-documented mitigations include M1047 Audit, M1026 Privileged Account Management, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1485-001-lifecycle-triggered-deletion",
    "title": "MITRE ATT&CK T1485.001: Lifecycle-Triggered Deletion (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1485.001 (Lifecycle-Triggered Deletion) is an Enterprise Impact sub-technique of T1485 (Data Destruction). Adversaries may modify the lifecycle policies of a cloud storage bucket to destroy all objects stored within. Cloud storage buckets often allow users to set lifecycle policies to automate the migration, archival, or deletion of objects after a set period of time. If a threat actor has sufficient permissions to modify these policies, they may be able to delete all objects at once. Affected platforms: IaaS. MITRE-documented mitigations include M1018 User Account Management, M1053 Data Backup. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CP-2, CP-7, CP-9, CP-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1485-data-destruction"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1485-data-destruction",
    "title": "MITRE ATT&CK T1485: Data Destruction (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1485 covers adversary destruction of victim data and systems through wiper malware, secure deletion, or storage corruption to disrupt operations or destroy evidence. Notable wiper campaigns include NotPetya (2017, USD 10B+ damages), WhisperGate (Ukraine 2022), HermeticWiper (2022), AcidRain (2022 Viasat), and AcidPour (2024). Compliance obligations include NIST SP 800-53 CP-9 (backup), MP-6 (Media Sanitization for legitimate use), SI-7 (integrity), NIS2 Article 21(2)(c), DORA Article 12, and CISA SHIELDS UP guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1486-data-encrypted-for-impact"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1486-data-encrypted-for-impact",
    "title": "MITRE ATT&CK T1486: Data Encrypted for Impact (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1486 covers adversary encryption of victim data and demand for ransom, the canonical ransomware behaviour responsible for the majority of catastrophic enterprise cyber incidents. LockBit, BlackCat/ALPHV, Cl0p, Akira, and Royal remain the dominant ransomware-as-a-service brands as of 2025. Compliance obligations span NIST SP 800-53 CP-9 (backup), CP-10 (recovery), SI-7 (integrity), HIPAA 164.308(a)(7), NIS2 Article 21(2)(c), DORA Articles 12-13, SEC Cybersecurity Risk Management Rule, and US Treasury OFAC ransomware payment advisory.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1190-exploit-public-facing-application"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1489-service-stop",
    "title": "MITRE ATT&CK T1489: Service Stop (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1489 (Service Stop) is an Enterprise Impact technique. Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment. Adversaries may accomplish this by disabling individual services of high importance to an organization, such as MSExchangeIS, which will make Exchange content inaccessible. Affected platforms: Windows, Linux, macOS. MITRE-documented mitigations include M1030 Network Segmentation, M1018 User Account Management, M1060 Out-of-Band Communications Channel, M1024 Restrict Registry Permissions, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1490-inhibit-system-recovery",
    "title": "MITRE ATT&CK T1490: Inhibit System Recovery (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1490 (Inhibit System Recovery) is an Enterprise Impact technique. Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options. Operating systems may contain features that can help fix corrupted systems, such as a backup catalog, volume shadow copies, and automatic repair features. Adversaries may disable or delete system recovery features to augment the effects of Data Destruction and Data Encrypted for Impact. Affected platforms: Windows, macOS, Linux, Network, IaaS, Containers. MITRE-documented mitigations include M1038 Execution Prevention, M1028 Operating System Configuration, M1018 User Account Management, M1053 Data Backup. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-6, CM-7, CP-2, CP-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1491-001-internal-defacement",
    "title": "MITRE ATT&CK T1491.001: Internal Defacement (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1491.001 (Internal Defacement) is an Enterprise Impact sub-technique of T1491 (Defacement). An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites, or directly to user systems with the replacement of the desktop wallpaper. Disturbing or offensive images may be used as a part of Internal Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1053 Data Backup. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-6, CM-2, CP-2, CP-7, CP-9, CP-10, SI-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1491-defacement"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1491-002-external-defacement",
    "title": "MITRE ATT&CK T1491.002: External Defacement (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1491.002 (External Defacement) is an Enterprise Impact sub-technique of T1491 (Defacement). An adversary may deface systems external to an organization in an attempt to deliver messaging, intimidate, or otherwise mislead an organization or users. External Defacement may ultimately cause users to distrust the systems and to question/discredit the system's integrity. Externally-facing websites are a common victim of defacement; often targeted by adversary and hacktivist groups in order to push a political message or spread propaganda. Affected platforms: Windows, IaaS, Linux, macOS. MITRE-documented mitigations include M1053 Data Backup. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-6, CM-2, CP-2, CP-7, CP-9, CP-10, SI-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1491-defacement"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1491-defacement",
    "title": "MITRE ATT&CK T1491: Defacement (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1491 (Defacement) is an Enterprise Impact technique. Adversaries may modify visual content available internally or externally to an enterprise network, thus affecting the integrity of the original content. Reasons for Defacement include delivering messaging, intimidation, or claiming (possibly false) credit for an intrusion. Disturbing or offensive images may be used as a part of Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages. ATT&CK documents 2 sub-techniques: T1491.001 Internal Defacement; T1491.002 External Defacement. Affected platforms: Windows, IaaS, Linux, macOS. MITRE-documented mitigations include M1053 Data Backup. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-6, CM-2, CP-2, CP-7, CP-9, CP-10, SI-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1495-firmware-corruption",
    "title": "MITRE ATT&CK T1495: Firmware Corruption (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1495 (Firmware Corruption) is an Enterprise Impact technique. Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying the availability to use the devices and/or the system. Firmware is software that is loaded and executed from non-volatile memory on hardware devices in order to initialize and manage device functionality. These devices may include the motherboard, hard drive, or video cards. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1051 Update Software, M1026 Privileged Account Management, M1046 Boot Integrity. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-3, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1496-001-compute-hijacking",
    "title": "MITRE ATT&CK T1496.001: Compute Hijacking (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1496.001 (Compute Hijacking) is an Enterprise Impact sub-technique of T1496 (Resource Hijacking). Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability. One common purpose for Compute Hijacking is to validate transactions of cryptocurrency networks and earn virtual currency. Adversaries may consume enough system resources to negatively impact and/or cause affected machines to become unresponsive. Affected platforms: Windows, IaaS, Linux, macOS, Containers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1496-resource-hijacking"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1496-002-bandwidth-hijacking",
    "title": "MITRE ATT&CK T1496.002: Bandwidth Hijacking (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1496.002 (Bandwidth Hijacking) is an Enterprise Impact sub-technique of T1496 (Resource Hijacking). Adversaries may leverage the network bandwidth resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability. Adversaries may also use malware that leverages a system's network bandwidth as part of a botnet in order to facilitate Network Denial of Service campaigns and/or to seed malicious torrents. Alternatively, they may engage in proxyjacking by selling use of the victims' network bandwidth and IP address to proxyware services. Affected platforms: Linux, Windows, macOS, IaaS, Containers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1496-resource-hijacking"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1496-003-sms-pumping",
    "title": "MITRE ATT&CK T1496.003: SMS Pumping (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1496.003 (SMS Pumping) is an Enterprise Impact sub-technique of T1496 (Resource Hijacking). Adversaries may leverage messaging services for SMS pumping, which may impact system and/or hosted service availability. SMS pumping is a type of telecommunications fraud whereby a threat actor first obtains a set of phone numbers from a telecommunications provider, then leverages a victim's messaging infrastructure to send large amounts of SMS messages to numbers in that set. By generating SMS traffic to their phone number set, a threat actor may earn payments from the telecommunications provider. Affected platforms: SaaS. MITRE-documented mitigations include M1013 Application Developer Guidance. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls SC-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1496-resource-hijacking"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1496-004-cloud-service-hijacking",
    "title": "MITRE ATT&CK T1496.004: Cloud Service Hijacking (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1496.004 (Cloud Service Hijacking) is an Enterprise Impact sub-technique of T1496 (Resource Hijacking). Adversaries may leverage compromised software-as-a-service (SaaS) applications to complete resource-intensive tasks, which may impact hosted service availability. For example, adversaries may leverage email and messaging services, such as AWS Simple Email Service (SES), AWS Simple Notification Service (SNS), SendGrid, and Twilio, in order to send large quantities of spam / Phishing emails and SMS messages. Affected platforms: SaaS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1496-resource-hijacking"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1496-resource-hijacking",
    "title": "MITRE ATT&CK T1496: Resource Hijacking (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1496 (Resource Hijacking) is an Enterprise Impact technique. Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability. Resource hijacking may take a number of different forms. For example, adversaries may: * Leverage compute resources in order to mine cryptocurrency * Sell network bandwidth to proxy networks * Generate SMS traffic for profit * Abuse cloud-based messaging services to send large quantities of spam messages In some cases, adversaries may leverage multiple types. ATT&CK documents 4 sub-techniques: T1496.001 Compute Hijacking; T1496.002 Bandwidth Hijacking; T1496.003 SMS Pumping; T1496.004 Cloud Service Hijacking. Affected platforms: Windows, IaaS, Linux, macOS, Containers, SaaS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1497-001-system-checks",
    "title": "MITRE ATT&CK T1497.001: System Checks (Enterprise Tactic TA0005 - Defense Evasion / TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1497.001 (System Checks) is an Enterprise Defense Evasion and Discovery sub-technique of T1497 (Virtualization/Sandbox Evasion). Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1497-virtualization-sandbox-evasion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1497-002-user-activity-based-checks",
    "title": "MITRE ATT&CK T1497.002: User Activity Based Checks (Enterprise Tactic TA0005 - Defense Evasion / TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1497.002 (User Activity Based Checks) is an Enterprise Defense Evasion and Discovery sub-technique of T1497 (Virtualization/Sandbox Evasion). Adversaries may employ various user activity checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1497-virtualization-sandbox-evasion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1497-003-time-based-evasion",
    "title": "MITRE ATT&CK T1497.003: Time Based Checks (Enterprise Tactic TA0005 - Defense Evasion / TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1497.003 (Time Based Checks) is an Enterprise Defense Evasion and Discovery sub-technique of T1497 (Virtualization/Sandbox Evasion). Adversaries may employ various time-based methods to detect and avoid virtualization and analysis environments. This may include enumerating time-based properties, such as uptime or the system clock, as well as the use of timers or other triggers to avoid a virtual machine environment (VME) or sandbox, specifically those that are automated or only operate for a limited amount of time. Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1497-virtualization-sandbox-evasion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1497-virtualization-sandbox-evasion",
    "title": "MITRE ATT&CK T1497: Virtualization/Sandbox Evasion (Enterprise Tactic TA0005 - Defense Evasion / TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1497 (Virtualization/Sandbox Evasion) is an Enterprise Defense Evasion and Discovery technique. Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. ATT&CK documents 3 sub-techniques: T1497.001 System Checks; T1497.002 User Activity Based Checks; T1497.003 Time Based Evasion. Affected platforms: Windows, macOS, Linux.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1498-001-direct-network-flood",
    "title": "MITRE ATT&CK T1498.001: Direct Network Flood (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1498.001 (Direct Network Flood) is an Enterprise Impact sub-technique of T1498 (Network Denial of Service). Adversaries may attempt to cause a denial of service (DoS) by directly sending a high-volume of network traffic to a target. This DoS attack may also reduce the availability and functionality of the targeted system(s) and network. Direct Network Floods are when one or more systems are used to send a high-volume of network packets towards the targeted service's network. Almost any network protocol may be used for flooding. Affected platforms: Windows, IaaS, Linux, macOS. MITRE-documented mitigations include M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-6, CM-7, SC-7, SI-10, SI-15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1498-network-denial-of-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1498-002-reflection-amplification",
    "title": "MITRE ATT&CK T1498.002: Reflection Amplification (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1498.002 (Reflection Amplification) is an Enterprise Impact sub-technique of T1498 (Network Denial of Service). Adversaries may attempt to cause a denial of service (DoS) by reflecting a high-volume of network traffic to a target. This type of Network DoS takes advantage of a third-party server intermediary that hosts and will respond to a given spoofed source IP address. This third-party server is commonly termed a reflector. An adversary accomplishes a reflection attack by sending packets to reflectors with the spoofed address of the victim. Affected platforms: Windows, IaaS, Linux, macOS. MITRE-documented mitigations include M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-6, CM-7, SC-7, SI-10, SI-15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1498-network-denial-of-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1498-network-denial-of-service",
    "title": "MITRE ATT&CK T1498: Network Denial of Service (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1498 (Network Denial of Service) is an Enterprise Impact technique. Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth services rely on. Example resources include specific websites, email services, DNS, and web-based applications. Adversaries have been observed conducting network DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion. ATT&CK documents 2 sub-techniques: T1498.001 Direct Network Flood; T1498.002 Reflection Amplification. Affected platforms: Windows, IaaS, Linux, macOS, Containers. MITRE-documented mitigations include M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-6, CM-7, SC-7, SI-10, SI-15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1499-001-os-exhaustion-flood",
    "title": "MITRE ATT&CK T1499.001: OS Exhaustion Flood (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1499.001 (OS Exhaustion Flood) is an Enterprise Impact sub-technique of T1499 (Endpoint Denial of Service). Adversaries may launch a denial of service (DoS) attack targeting an endpoint's operating system (OS). A system's OS is responsible for managing the finite resources as well as preventing the entire system from being overwhelmed by excessive demands on its capacity. These attacks do not need to exhaust the actual resources on a system; the attacks may simply exhaust the limits and available resources that an OS self-imposes. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-6, CM-7, SC-7, SI-4, SI-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1499-endpoint-denial-of-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1499-002-service-exhaustion-flood",
    "title": "MITRE ATT&CK T1499.002: Service Exhaustion Flood (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1499.002 (Service Exhaustion Flood) is an Enterprise Impact sub-technique of T1499 (Endpoint Denial of Service). Adversaries may target the different network services provided by systems to conduct a denial of service (DoS). Adversaries often target the availability of DNS and web services, however others have been targeted as well. Web server software can be attacked through a variety of means, some of which apply generally while others are specific to the software being used to provide the service. Affected platforms: Windows, IaaS, Linux, macOS. MITRE-documented mitigations include M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-6, CM-7, SC-7, SI-4, SI-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1499-endpoint-denial-of-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1499-003-application-exhaustion-flood",
    "title": "MITRE ATT&CK T1499.003: Application Exhaustion Flood (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1499.003 (Application Exhaustion Flood) is an Enterprise Impact sub-technique of T1499 (Endpoint Denial of Service). Adversaries may target resource intensive features of applications to cause a denial of service (DoS), denying availability to those applications. For example, specific features in web applications may be highly resource intensive. Repeated requests to those features may be able to exhaust system resources and deny access to the application or the server itself. Affected platforms: Windows, IaaS, Linux, macOS. MITRE-documented mitigations include M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-6, CM-7, SC-7, SI-4, SI-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1499-endpoint-denial-of-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1499-004-application-or-system-exploitation",
    "title": "MITRE ATT&CK T1499.004: Application or System Exploitation (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1499.004 (Application or System Exploitation) is an Enterprise Impact sub-technique of T1499 (Endpoint Denial of Service). Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users. Some systems may automatically restart critical applications and services when crashes occur, but they can likely be re-exploited to cause a persistent denial of service (DoS) condition. Adversaries may exploit known or zero-day vulnerabilities to crash applications and/or systems, which may also lead to dependent applications and/or systems to be in a DoS condition. Affected platforms: Windows, IaaS, Linux, macOS. MITRE-documented mitigations include M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-6, CM-7, SC-7, SI-4, SI-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1499-endpoint-denial-of-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1499-endpoint-denial-of-service",
    "title": "MITRE ATT&CK T1499: Endpoint Denial of Service (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1499 covers adversary denial-of-service attacks targeting endpoint resources to make services unavailable. Sub-techniques include OS Exhaustion Flood (T1499.001), Service Exhaustion Flood (T1499.002), Application Exhaustion Flood (T1499.003), and Application or System Exploitation (T1499.004). Layer 7 application-layer attacks have grown significantly with the rise of bot-driven traffic and HTTP/2 Rapid Reset (CVE-2023-44487). Compliance obligations include NIST SP 800-53 SC-5 (Denial of Service Protection), ISO 27001 A.5.30, NIS2 Article 21(2)(c), DORA Article 11, and PCI DSS Req 12.10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1190-exploit-public-facing-application",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1505-001-sql-stored-procedures",
    "title": "MITRE ATT&CK T1505.001: SQL Stored Procedures (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1505.001 (SQL Stored Procedures) is an Enterprise Persistence sub-technique of T1505 (Server Software Component). Adversaries may abuse SQL stored procedures to establish persistent access to systems. SQL Stored Procedures are code that can be saved and reused so that database users do not waste time rewriting frequently used SQL queries. Stored procedures can be invoked via SQL statements to the database using the procedure name or via defined events (e.g. when a SQL server application is started/restarted). Adversaries may craft malicious stored procedures that can provide a persistence mechanism in SQL database servers. Affected platforms: Windows, Linux. MITRE-documented mitigations include M1047 Audit, M1045 Code Signing, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1505-server-software-component"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1505-002-transport-agent",
    "title": "MITRE ATT&CK T1505.002: Transport Agent (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1505.002 (Transport Agent) is an Enterprise Persistence sub-technique of T1505 (Server Software Component). Adversaries may abuse Microsoft transport agents to establish persistent access to systems. Microsoft Exchange transport agents can operate on email messages passing through the transport pipeline to perform various tasks such as filtering spam, filtering malicious attachments, journaling, or adding a corporate signature to the end of all outgoing emails. Transport agents can be written by application developers and then compiled to .NET assemblies that are subsequently registered with the Exchange server. Affected platforms: Linux, Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1047 Audit, M1045 Code Signing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1505-server-software-component"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1505-003-web-shell",
    "title": "MITRE ATT&CK T1505.003: Web Shell (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1505.003 (Web Shell) is an Enterprise Persistence sub-technique of T1505 (Server Software Component). Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server. In addition to a server-side script, a Web shell may have a client interface program that is used to talk to the Web server (e.g. Affected platforms: Linux, Windows, macOS, Network. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1505-server-software-component"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1505-004-iis-components",
    "title": "MITRE ATT&CK T1505.004: IIS Components (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1505.004 (IIS Components) is an Enterprise Persistence sub-technique of T1505 (Server Software Component). Adversaries may install malicious components that run on Internet Information Services (IIS) web servers to establish persistence. IIS provides several mechanisms to extend the functionality of the web servers. For example, Internet Server Application Programming Interface (ISAPI) extensions and filters can be installed to examine and/or modify incoming and outgoing IIS web requests. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1038 Execution Prevention, M1047 Audit, M1045 Code Signing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1505-server-software-component"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1505-005-terminal-services-dll",
    "title": "MITRE ATT&CK T1505.005: Terminal Services DLL (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1505.005 (Terminal Services DLL) is an Enterprise Persistence sub-technique of T1505 (Server Software Component). Adversaries may abuse components of Terminal Services to enable persistent access to systems. Microsoft Terminal Services, renamed to Remote Desktop Services in some Windows Server OSs as of 2022, enable remote terminal connections to hosts. Terminal Services allows servers to transmit a full, interactive, graphical user interface to clients via RDP. Affected platforms: Windows. MITRE-documented mitigations include M1047 Audit, M1024 Restrict Registry Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-12, AC-16, AC-17, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1505-server-software-component"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1505-006-vsphere-installation-bundles",
    "title": "MITRE ATT&CK T1505.006: vSphere Installation Bundles (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1505.006 (vSphere Installation Bundles) is an Enterprise Persistence technique. Adversaries may abuse vSphere Installation Bundles (VIBs) to establish persistent access to ESXi hypervisors. VIBs are collections of files used for software distribution and virtual system management in VMware environments. Since ESXi uses an in-memory filesystem where changes made to most files are stored in RAM rather than in persistent storage, these modifications are lost after a reboot. However, VIBs can be used to create startup tasks, apply custom firewall rules, or deploy binaries that persist across reboots. Typically, administrators use VIBs for updates and system maintenance. VIBs can be broken down into three components: * VIB payload: a `.vgz` archive containing the directories and files to be created and executed on boot when the VIBs are loaded. * Signature file: verifies t... Affected platforms: ESXi. Sub-technique of ATT&CK T1505. ATT&CK-mapped mitigations: M1046 Boot Integrity, M1045 Code Signing, M1047 Audit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1505-server-software-component",
    "title": "MITRE ATT&CK T1505: Server Software Component (Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1505 covers adversary deployment of malicious software components into legitimate server software for persistence. Sub-techniques include SQL Stored Procedures (T1505.001), Transport Agent (T1505.002), Web Shell (T1505.003), IIS Components (T1505.004), Terminal Services DLL (T1505.005). Web shells (China Chopper, ANTSWORD, P.A.S., Behinder, Godzilla) and Exchange OAB Virtual Directory implants are dominant patterns. Compliance: NIST 800-53 SI-7, ISO 27001 A.8.7, A.8.32, PCI DSS Req 6.4 and Req 11.5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1518-001-security-software-discovery",
    "title": "MITRE ATT&CK T1518.001: Security Software Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1518.001 (Security Software Discovery) is an Enterprise Discovery sub-technique of T1518 (Software Discovery). Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from Security Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Affected platforms: Windows, IaaS, Linux, macOS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1518-software-discovery"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1518-002-backup-software-discovery",
    "title": "MITRE ATT&CK T1518.002: Backup Software Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1518.002 (Backup Software Discovery) is an Enterprise Discovery technique. Adversaries may attempt to get a listing of backup software or configurations that are installed on a system. Adversaries may use this information to shape follow-on behaviors, such as Data Destruction, Inhibit System Recovery, or Data Encrypted for Impact. Commands that can be used to obtain security software information are netsh, `reg query` with Reg, `dir` with cmd, and Tasklist, but other indicators of discovery behavior may be more specific to the type of software or security system the adversary is looking for, such as Veeam, Acronis, Dropbox, or Paragon. Affected platforms: Windows, macOS, Linux. Sub-technique of ATT&CK T1518.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "mitre-attack-t1518-software-discovery",
    "title": "MITRE ATT&CK T1518: Software Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1518 (Software Discovery) is an Enterprise Discovery technique. Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. ATT&CK documents 1 sub-technique: T1518.001 Security Software Discovery. Affected platforms: Windows, IaaS, Linux, macOS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1525-implant-internal-image",
    "title": "MITRE ATT&CK T1525: Implant Internal Image (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1525 (Implant Internal Image) is an Enterprise Persistence technique. Adversaries may implant cloud or container images with malicious code to establish persistence after gaining access to an environment. Amazon Web Services (AWS) Amazon Machine Images (AMIs), Google Cloud Platform (GCP) Images, and Azure Images as well as popular container runtimes such as Docker can be implanted or backdoored. Unlike Upload Malware, this technique focuses on adversaries implanting an image in a registry within a victim's environment. Affected platforms: IaaS, Containers. MITRE-documented mitigations include M1045 Code Signing, M1026 Privileged Account Management, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1526-cloud-service-discovery",
    "title": "MITRE ATT&CK T1526: Cloud Service Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1526 (Cloud Service Discovery) is an Enterprise Discovery technique. An adversary may attempt to enumerate the cloud services running on a system after gaining access. These methods can differ from platform-as-a-service (PaaS), to infrastructure-as-a-service (IaaS), or software-as-a-service (SaaS). Many services exist throughout the various cloud providers and can include Continuous Integration and Continuous Delivery (CI/CD), Lambda Functions, Entra ID, etc. Affected platforms: SaaS, IaaS, Office Suite, Identity Provider.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1528-steal-application-access-token",
    "title": "MITRE ATT&CK T1528: Steal Application Access Token (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1528 (Steal Application Access Token) is an Enterprise Credential Access technique. Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources. Application access tokens are used to make authorized API requests on behalf of a user or service and are commonly used as a way to access resources in cloud and container-based applications and software-as-a-service (SaaS). Affected platforms: SaaS, Containers, IaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1021 Restrict Web-Based Content, M1047 Audit, M1017 User Training, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-10, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1529-system-shutdown-reboot",
    "title": "MITRE ATT&CK T1529: System Shutdown/Reboot (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1529 (System Shutdown/Reboot) is an Enterprise Impact technique. Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems. Operating systems may contain commands to initiate a shutdown/reboot of a machine or network device. In some cases, these commands may also be used to initiate a shutdown/reboot of a remote computer or network device via Network Device CLI (e.g. reload). Shutting down or rebooting systems may disrupt access to computer resources for legitimate users while also impeding incident response/recovery. Affected platforms: Linux, macOS, Windows, Network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1530-data-from-cloud-storage",
    "title": "MITRE ATT&CK T1530: Data from Cloud Storage (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1530 (Data from Cloud Storage) is an Enterprise Collection technique. Adversaries may access data from cloud storage. Many IaaS providers offer solutions for online data object storage such as Amazon S3, Azure Storage, and Google Cloud Storage. Similarly, SaaS enterprise platforms such as Office 365 and Google Workspace provide cloud-based document storage to users through services such as OneDrive and Google Drive, while SaaS application providers such as Slack, Confluence, Salesforce, and Dropbox may provide cloud storage solutions as a peripheral or primary use case of their. Affected platforms: IaaS, SaaS, Office Suite. MITRE-documented mitigations include M1018 User Account Management, M1041 Encrypt Sensitive Information, M1022 Restrict File and Directory Permissions, M1037 Filter Network Traffic, M1047 Audit, M1032 Multi-factor Authentication. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1531-account-access-removal",
    "title": "MITRE ATT&CK T1531: Account Access Removal (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1531 (Account Access Removal) is an Enterprise Impact technique. Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place. In Windows, Net utility, Set-LocalUser and Set-ADAccountPassword PowerShell cmdlets may be used by adversaries to modify user accounts. Affected platforms: Linux, macOS, Windows, SaaS, IaaS, Office Suite.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1534-internal-spearphishing",
    "title": "MITRE ATT&CK T1534: Internal Spearphishing (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1534 (Internal Spearphishing) is an Enterprise Lateral Movement technique. After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization. Internal spearphishing is multi-staged campaign where a legitimate account is initially compromised either by controlling the user's device or by compromising the account credentials of the user. Affected platforms: Windows, macOS, Linux, SaaS, Office Suite.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1535-unused-unsupported-cloud-regions",
    "title": "MITRE ATT&CK T1535: Unused/Unsupported Cloud Regions (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1535 (Unused/Unsupported Cloud Regions) is an Enterprise Defense Evasion technique. Adversaries may create cloud instances in unused geographic service regions in order to evade detection. Access is usually obtained through compromising accounts used to manage cloud infrastructure. Cloud service providers often provide infrastructure throughout the world in order to improve performance, provide redundancy, and allow customers to meet compliance requirements. Oftentimes, a customer will only use a subset of the available regions and may not actively monitor other regions. Affected platforms: IaaS. MITRE-documented mitigations include M1054 Software Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls SC-23.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1537-transfer-data-to-cloud-account",
    "title": "MITRE ATT&CK T1537: Transfer Data to Cloud Account (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1537 (Transfer Data to Cloud Account) is an Enterprise Exfiltration technique. Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service. A defender who is monitoring for large transfers to outside the cloud environment through normal file transfers or over command and control channels may not be watching for data transfers to another account within the same cloud provider. Affected platforms: IaaS, SaaS, Office Suite. MITRE-documented mitigations include M1057 Data Loss Prevention, M1018 User Account Management, M1054 Software Configuration, M1037 Filter Network Traffic, M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1538-cloud-service-dashboard",
    "title": "MITRE ATT&CK T1538: Cloud Service Dashboard (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1538 (Cloud Service Dashboard) is an Enterprise Discovery technique. An adversary may use a cloud service dashboard GUI with stolen credentials to gain useful information from an operational cloud environment, such as specific services, resources, and features. For example, the GCP Command Center can be used to view all assets, findings of potential security risks, and to run additional queries, such as finding public IP addresses and open ports. Affected platforms: IaaS, SaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, IA-2, IA-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1539-steal-web-session-cookie",
    "title": "MITRE ATT&CK T1539: Steal Web Session Cookie (Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1539 covers adversary theft of web session cookies to bypass MFA and impersonate authenticated users. Storm-0558 (Microsoft, 2023) and SCATTERED SPIDER (Okta, 2023-2024) campaigns leveraged stolen session cookies extensively. Modern infostealers (RedLine, Vidar, Lumma, Stealc) harvest browser cookies as the primary credential exfiltration vector. Compliance: NIST 800-53 IA-5, AC-12, SC-8, ISO 27001 A.5.17, A.8.5, GDPR Article 32, PCI DSS Req 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1003-os-credential-dumping",
      "mitre-attack-t1078-004-cloud-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1542-001-system-firmware",
    "title": "MITRE ATT&CK T1542.001: System Firmware (Enterprise Tactic TA0003 - Persistence / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1542.001 (System Firmware) is an Enterprise Persistence and Defense Evasion sub-technique of T1542 (Pre-OS Boot). Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer. System firmware like BIOS and (U)EFI underly the functionality of a computer and may be modified by an adversary to perform or assist in malicious activity. Affected platforms: Windows, Network. MITRE-documented mitigations include M1046 Boot Integrity, M1051 Update Software, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-3, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1542-pre-os-boot"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1542-002-component-firmware",
    "title": "MITRE ATT&CK T1542.002: Component Firmware (Enterprise Tactic TA0003 - Persistence / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1542.002 (Component Firmware) is an Enterprise Persistence and Defense Evasion sub-technique of T1542 (Pre-OS Boot). Adversaries may modify component firmware to persist on systems. Some adversaries may employ sophisticated means to compromise computer components and install malicious firmware that will execute adversary code outside of the operating system and main system firmware or BIOS. This technique may be similar to System Firmware but conducted upon other system components/devices that may not have the same capability or level of integrity checking. Affected platforms: Windows, Linux, macOS. MITRE-documented mitigations include M1051 Update Software. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-3, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1542-pre-os-boot"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1542-003-bootkit",
    "title": "MITRE ATT&CK T1542.003: Bootkit (Enterprise Tactic TA0003 - Persistence / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1542.003 (Bootkit) is an Enterprise Persistence and Defense Evasion sub-technique of T1542 (Pre-OS Boot). Adversaries may use bootkits to persist on systems. Bootkits reside at a layer below the operating system and may make it difficult to perform full remediation unless an organization suspects one was used and can act accordingly. A bootkit is a malware variant that modifies the boot sectors of a hard drive, including the Master Boot Record (MBR) and Volume Boot Record (VBR). The MBR is the section of disk that is first loaded after completing hardware initialization by the BIOS. Affected platforms: Linux, Windows. MITRE-documented mitigations include M1046 Boot Integrity, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-3, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1542-pre-os-boot"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1542-004-rommonkit",
    "title": "MITRE ATT&CK T1542.004: ROMMONkit (Enterprise Tactic TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1542.004 (ROMMONkit) is an Enterprise Defense Evasion and Persistence sub-technique of T1542 (Pre-OS Boot). Adversaries may abuse the ROM Monitor (ROMMON) by loading an unauthorized firmware with adversary code to provide persistent access and manipulate device behavior that is difficult to detect. ROMMON is a Cisco network device firmware that functions as a boot loader, boot image, or boot helper to initialize hardware and software when the platform is powered on or reset. Affected platforms: Network. MITRE-documented mitigations include M1046 Boot Integrity, M1047 Audit, M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1542-pre-os-boot"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1542-005-tftp-boot",
    "title": "MITRE ATT&CK T1542.005: TFTP Boot (Enterprise Tactic TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1542.005 (TFTP Boot) is an Enterprise Defense Evasion and Persistence sub-technique of T1542 (Pre-OS Boot). Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server. TFTP boot (netbooting) is commonly used by network administrators to load configuration-controlled network device images from a centralized management server. Netbooting is one option in the boot sequence and can be used to centralize, manage, and control device images. Affected platforms: Network. MITRE-documented mitigations include M1031 Network Intrusion Prevention, M1028 Operating System Configuration, M1026 Privileged Account Management, M1035 Limit Access to Resource Over Network, M1047 Audit, M1046 Boot Integrity. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1542-pre-os-boot"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1542-pre-os-boot",
    "title": "MITRE ATT&CK T1542: Pre-OS Boot (Enterprise Tactic TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1542 (Pre-OS Boot) is an Enterprise Defense Evasion and Persistence technique. Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system. During the booting process of a computer, firmware and various startup services are loaded before the operating system. These programs control flow of execution before the operating system takes control. Adversaries may overwrite data in boot drivers or firmware such as BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) to persist on systems at a layer below the operating system. ATT&CK documents 5 sub-techniques: T1542.001 System Firmware; T1542.002 Component Firmware; T1542.003 Bootkit; T1542.004 ROMMONkit; T1542.005 TFTP Boot. Affected platforms: Linux, Windows, Network, macOS. MITRE-documented mitigations include M1035 Limit Access to Resource Over Network, M1047 Audit, M1051 Update Software, M1026 Privileged Account Management, M1046 Boot Integrity. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-3, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1543-001-launch-agent",
    "title": "MITRE ATT&CK T1543.001: Launch Agent (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1543.001 (Launch Agent) is an Enterprise Persistence and Privilege Escalation sub-technique of T1543 (Create or Modify System Process). Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in /System/Library/LaunchAgents, /Library/LaunchAgents, and ~/Library/LaunchAgents. Property list files use the Label, ProgramArguments , and RunAtLoad keys to identify the Launch Agent's name, executable location, and execution time. Affected platforms: macOS. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1543-create-or-modify-system-process"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1543-002-systemd-service",
    "title": "MITRE ATT&CK T1543.002: Systemd Service (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1543.002 (Systemd Service) is an Enterprise Persistence and Privilege Escalation sub-technique of T1543 (Create or Modify System Process). Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible. Affected platforms: Linux. MITRE-documented mitigations include M1018 User Account Management, M1022 Restrict File and Directory Permissions, M1026 Privileged Account Management, M1033 Limit Software Installation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1543-create-or-modify-system-process"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1543-003-windows-service",
    "title": "MITRE ATT&CK T1543.003: Windows Service (Sub-Technique of T1543 - Persistence + Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1543.003 covers adversary persistence via Windows Service creation or modification (Service Control Manager). Lateral movement frameworks (PsExec, Impacket-smbexec, Cobalt Strike) and most ransomware operators create services for elevated execution and persistence. Compliance obligations include NIST SP 800-53 SI-7, AU-12 (Event ID 4697, 7045), CM-7, ISO 27001 A.8.32, A.8.16, PCI DSS Req 5.2 and Req 10.4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1543-create-or-modify-system-process",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1543-004-launch-daemon",
    "title": "MITRE ATT&CK T1543.004: Launch Daemon (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1543.004 (Launch Daemon) is an Enterprise Persistence and Privilege Escalation sub-technique of T1543 (Create or Modify System Process). Adversaries may create or modify Launch Daemons to execute malicious payloads as part of persistence. Launch Daemons are plist files used to interact with Launchd, the service management framework used by macOS. Launch Daemons require elevated privileges to install, are executed for every user on a system prior to login, and run in the background without the need for user interaction. Affected platforms: macOS. MITRE-documented mitigations include M1018 User Account Management, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1543-create-or-modify-system-process"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1543-005-container-service",
    "title": "MITRE ATT&CK T1543.005: Container Service (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1543.005 (Container Service) is an Enterprise Persistence and Privilege Escalation sub-technique of T1543 (Create or Modify System Process). Adversaries may create or modify container or container cluster management tools that run as daemons, agents, or services on individual hosts. These include software for creating and managing individual containers, such as Docker and Podman, as well as container cluster node-level agents such as kubelet. By modifying these services, an adversary may be able to achieve persistence or escalate their privileges on a host. Affected platforms: Containers. MITRE-documented mitigations include M1054 Software Configuration, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1543-create-or-modify-system-process"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1543-create-or-modify-system-process",
    "title": "MITRE ATT&CK T1543: Create or Modify System Process (Persistence + Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1543 covers adversary creation or modification of OS-level system processes for persistence and privilege escalation. Sub-techniques include Launch Agent (T1543.001 macOS), Systemd Service (T1543.002 Linux), Windows Service (T1543.003), Launch Daemon (T1543.004 macOS), and Container Service (T1543.005). Compliance obligations include NIST SP 800-53 SI-7, CM-7, AU-2, ISO 27001 A.8.32, A.8.16, PCI DSS Req 10.4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1547-boot-logon-autostart-execution",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1546-001-change-default-file-association",
    "title": "MITRE ATT&CK T1546.001: Change Default File Association (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.001 (Change Default File Association) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by a file type association. When a file is opened, the default program used to open the file (also called the file association or handler) is checked. File association selections are stored in the Windows Registry and can be edited by users, administrators, or programs that have Registry access or by administrators using the built-in assoc utility. Affected platforms: Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, IA-9, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1546-002-screensaver",
    "title": "MITRE ATT&CK T1546.002: Screensaver (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.002 (Screensaver) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that execute after a configurable time of user inactivity and consist of Portable Executable (PE) files with a .scr file extension. The Windows screensaver application scrnsave.scr is located in C:\\Windows\\System32\\, and C:\\Windows\\sysWOW64\\ on 64-bit Windows systems, along with screensavers included with base Windows installations. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, CM-7, CM-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1546-003-windows-management-instrumentation-event-subscription",
    "title": "MITRE ATT&CK T1546.003: Windows Management Instrumentation Event Subscription (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.003 (Windows Management Instrumentation Event Subscription) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription. WMI can be used to install event filters, providers, consumers, and bindings that execute code when a defined event occurs. Examples of events that may be subscribed to are the wall clock time, user login, or the computer's uptime. Affected platforms: Windows. MITRE-documented mitigations include M1018 User Account Management, M1026 Privileged Account Management, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1546-004-unix-shell-configuration-modification",
    "title": "MITRE ATT&CK T1546.004: Unix Shell Configuration Modification (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.004 (Unix Shell Configuration Modification) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence through executing malicious commands triggered by a user's shell. User Unix Shells execute several configuration scripts at different points throughout the session based on events. For example, when a user opens a command-line interface or remotely logs in (such as via SSH) a login shell is initiated. The login shell executes scripts from the system (/etc) and the user's home directory (~/) to configure the environment. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-3, CM-6, IA-9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1546-005-trap",
    "title": "MITRE ATT&CK T1546.005: Trap (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.005 (Trap) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by an interrupt signal. The trap command allows programs and shells to specify commands that will be executed upon receiving interrupt signals. A common situation is a script allowing for graceful termination and handling of common keyboard interrupts like ctrl+c and ctrl+d. Adversaries can use this to register code to be executed when the shell encounters specific interrupts as a persistence mechanism. Affected platforms: macOS, Linux. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, IA-9, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1546-006-lc-load-dylib-addition",
    "title": "MITRE ATT&CK T1546.006: LC_LOAD_DYLIB Addition (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.006 (LC_LOAD_DYLIB Addition) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries. Mach-O binaries have a series of headers that are used to perform certain operations when a binary is loaded. The LC_LOAD_DYLIB header in a Mach-O binary tells macOS and OS X which dynamic libraries (dylibs) to load during execution time. These can be added ad-hoc to the compiled binary as long as adjustments are made to the rest of the fields and dependencies. Affected platforms: macOS. MITRE-documented mitigations include M1047 Audit, M1038 Execution Prevention, M1045 Code Signing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, CM-7, CM-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1546-007-netsh-helper-dll",
    "title": "MITRE ATT&CK T1546.007: Netsh Helper DLL (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.007 (Netsh Helper DLL) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs. Netsh.exe (also referred to as Netshell) is a command-line scripting utility used to interact with the network configuration of a system. It contains functionality to add helper DLLs for extending functionality of the utility. The paths to registered netsh.exe helper DLLs are entered into the Windows Registry at HKLM\\SOFTWARE\\Microsoft\\Netsh. Affected platforms: Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, IA-9, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1546-008-accessibility-features",
    "title": "MITRE ATT&CK T1546.008: Accessibility Features (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.008 (Accessibility Features) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features. Windows contains accessibility features that may be launched with a key combination before a user has logged in (ex: when the user is on the Windows logon screen). An adversary can modify the way these programs are launched to get a command prompt or backdoor without logging in to the system. Affected platforms: Windows. MITRE-documented mitigations include M1035 Limit Access to Resource Over Network, M1028 Operating System Configuration, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, CM-7, CM-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1546-009-appcert-dlls",
    "title": "MITRE ATT&CK T1546.009: AppCert DLLs (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.009 (AppCert DLLs) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into processes. Dynamic-link libraries (DLLs) that are specified in the AppCertDLLs Registry key under HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Session Manager\\ are loaded into every process that calls the ubiquitously used application programming interface (API) functions CreateProcess, CreateProcessAsUser, CreateProcessWithLoginW, CreateProcessWithTokenW, or WinExec. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, CM-7, IA-9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1546-010-appinit-dlls",
    "title": "MITRE ATT&CK T1546.010: AppInit DLLs (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.010 (AppInit DLLs) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into processes. Dynamic-link libraries (DLLs) that are specified in the AppInit_DLLs value in the Registry keys HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows or HKEY_LOCAL_MACHINE\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Windows are loaded by user32.dll into every process that loads user32.dll. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1051 Update Software. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, CM-7, IA-9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1546-011-application-shimming",
    "title": "MITRE ATT&CK T1546.011: Application Shimming (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.011 (Application Shimming) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims. The Microsoft Windows Application Compatibility Infrastructure/Framework (Application Shim) was created to allow for backward compatibility of software as the operating system codebase changes over time. Affected platforms: Windows. MITRE-documented mitigations include M1052 User Account Control, M1051 Update Software. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, IA-9, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1546-012-image-file-execution-options-injection",
    "title": "MITRE ATT&CK T1546.012: Image File Execution Options Injection (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.012 (Image File Execution Options Injection) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers. IFEOs enable a developer to attach a debugger to an application. When a process is created, a debugger present in an application's IFEO will be prepended to the application's name, effectively launching the new process under the debugger (e.g., C:\\dbg\\ntsd.exe -g notepad.exe). IFEOs can be set directly via the Registry or in Global Flags via the GFlags tool. Affected platforms: Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, IA-9, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1546-013-powershell-profile",
    "title": "MITRE ATT&CK T1546.013: PowerShell Profile (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.013 (PowerShell Profile) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles. A PowerShell profile (profile.ps1) is a script that runs when PowerShell starts and can be used as a logon script to customize user environments. PowerShell supports several profiles depending on the user or host program. For example, there can be different profiles for PowerShell host programs such as the PowerShell console, PowerShell ISE or Visual Studio Code. Affected platforms: Windows. MITRE-documented mitigations include M1045 Code Signing, M1022 Restrict File and Directory Permissions, M1054 Software Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-3, CM-6, CM-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1546-014-emond",
    "title": "MITRE ATT&CK T1546.014: Emond (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.014 (Emond) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond). Emond is a Launch Daemon that accepts events from various services, runs them through a simple rules engine, and takes action. The emond binary at /sbin/emond will load any rules from the /etc/emond.d/rules/ directory and take action once an explicitly defined event takes place. The rule files are in the plist format and define the name, event type, and action to take. Affected platforms: macOS. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, CM-8, IA-9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1546-015-component-object-model-hijacking",
    "title": "MITRE ATT&CK T1546.015: Component Object Model Hijacking (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.015 (Component Object Model Hijacking) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects. COM is a system within Windows to enable interaction between software components through the operating system. References to various COM objects are stored in the Registry. Adversaries can use the COM system to insert malicious code that can be executed in place of legitimate software through hijacking the COM references and relationships as a means for persistence. Affected platforms: Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, IA-9, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1546-016-installer-packages",
    "title": "MITRE ATT&CK T1546.016: Installer Packages (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.016 (Installer Packages) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content. Installer packages are OS specific and contain the resources an operating system needs to install applications on a system. Installer packages can include scripts that run prior to installation as well as after installation is complete. Installer scripts may inherit elevated permissions when executed. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-3, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1546-017-udev-rules",
    "title": "MITRE ATT&CK T1546.017: Udev Rules (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546.017 (Udev Rules) is an Enterprise Persistence and Privilege Escalation sub-technique of T1546 (Event Triggered Execution). Adversaries may maintain persistence through executing malicious content triggered using udev rules. Udev is the Linux kernel device manager that dynamically manages device nodes, handles access to pseudo-device files in the /dev directory, and responds to hardware events, such as when external devices like hard drives or keyboards are plugged in or removed. Udev uses rule files with match keys to specify the conditions a hardware event must meet and action keys to define the actions that should follow. Affected platforms: Linux. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, IA-9, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1546-018-python-startup-hooks",
    "title": "MITRE ATT&CK T1546.018: Python Startup Hooks (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1546.018 (Python Startup Hooks) is an Enterprise Persistence, Privilege Escalation technique. Adversaries may achieve persistence by leveraging Python’s startup mechanisms, including path configuration (`.pth`) files and the `sitecustomize.py` or `usercustomize.py` modules. These files are automatically processed during the initialization of the Python interpreter, allowing for the execution of arbitrary code whenever Python is invoked. Path configuration files are designed to extend Python’s module search paths through the use of import statements. If a `.pth` file is placed in Python's `site-packages` or `dist-packages` directories, any lines beginning with `import` will be executed automatically on Python invocation. Similarly, if `sitecustomize.py` or `usercustomize.py` is present in the Python path, these files will be imported during interpreter startup, and any code they con... Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1546.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "mitre-attack-t1546-event-triggered-execution",
    "title": "MITRE ATT&CK T1546: Event Triggered Execution (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1546 (Event Triggered Execution) is an Enterprise Privilege Escalation and Persistence technique. Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means to monitor and subscribe to events such as logons or other user activity such as running specific applications/binaries. Cloud environments may also support various functions and services that monitor and can be invoked in response to specific cloud events. ATT&CK documents 17 sub-techniques: T1546.001 Change Default File Association; T1546.002 Screensaver; T1546.003 Windows Management Instrumentation Event Subscription; T1546.004 Unix Shell Configuration Modification; T1546.005 Trap; T1546.006 LC_LOAD_DYLIB Addition; T1546.007 Netsh Helper DLL; T1546.008 Accessibility Features; T1546.009 AppCert DLLs; T1546.010 AppInit DLLs; T1546.011 Application Shimming; T1546.012 Image File Execution Options Injection; T1546.013 PowerShell Profile; T1546.014 Emond; T1546.015 Component Object Model Hijacking; T1546.016 Installer Packages; T1546.017 Udev Rules. Affected platforms: Linux, macOS, Windows, SaaS, IaaS, Office Suite. MITRE-documented mitigations include M1026 Privileged Account Management, M1051 Update Software. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-6, IA-9, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1547-001-registry-run-keys-startup-folder",
    "title": "MITRE ATT&CK T1547.001: Registry Run Keys / Startup Folder (Sub-Technique of T1547 - Persistence + Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1547.001 covers adversary persistence via Windows Registry Run keys (HKLM Software Microsoft Windows CurrentVersion Run/RunOnce and HKCU equivalents) and Startup folder. This is the single most-cited persistence technique in Windows malware: Emotet, Qakbot, IcedID, BumbleBee, RaspberryRobin, and most commodity loaders use Run keys as their primary persistence mechanism. Compliance obligations include NIST SP 800-53 SI-7 (Software Integrity), CM-2 (Baseline Configuration), CM-6 (Configuration Settings), AU-2 (Event Logging), ISO 27001 A.8.32, A.8.16, PCI DSS Req 5.2 and Req 10.4, and CIS Critical Security Controls v8 Control 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1547-boot-logon-autostart-execution",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1547-002-authentication-package",
    "title": "MITRE ATT&CK T1547.002: Authentication Package (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1547.002 (Authentication Package) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse authentication packages to execute DLLs when the system boots. Windows authentication package DLLs are loaded by the Local Security Authority (LSA) process at system start. They provide support for multiple logon processes and multiple security protocols to the operating system. Affected platforms: Windows. MITRE-documented mitigations include M1025 Privileged Process Integrity. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-6, SC-39, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1547-boot-logon-autostart-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1547-003-time-providers",
    "title": "MITRE ATT&CK T1547.003: Time Providers (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1547.003 (Time Providers) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse time providers to execute DLLs when the system boots. The Windows Time service (W32Time) enables time synchronization across and within domains. W32Time time providers are responsible for retrieving time stamps from hardware/network resources and outputting these values to other network clients. Time providers are implemented as dynamic-link libraries (DLLs) that are registered in the subkeys of HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\W32Time\\TimeProviders\\. Affected platforms: Windows. MITRE-documented mitigations include M1024 Restrict Registry Permissions, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-6, AC-17, CA-7, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1547-boot-logon-autostart-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1547-004-winlogon-helper-dll",
    "title": "MITRE ATT&CK T1547.004: Winlogon Helper DLL (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1547.004 (Winlogon Helper DLL) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in. Winlogon.exe is a Windows component responsible for actions at logon/logoff as well as the secure attention sequence (SAS) triggered by Ctrl-Alt-Delete. Registry entries in HKLM\\Software[\\\\Wow6432Node\\\\]\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\ and HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\ are used to manage additional helper programs and functionalities that support Winlogon. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CM-5, CM-7, IA-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1547-boot-logon-autostart-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1547-005-security-support-provider",
    "title": "MITRE ATT&CK T1547.005: Security Support Provider (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1547.005 (Security Support Provider) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse security support providers (SSPs) to execute DLLs when the system boots. Windows SSP DLLs are loaded into the Local Security Authority (LSA) process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored in Windows, such as any logged-on user's Domain password or smart card PINs. Affected platforms: Windows. MITRE-documented mitigations include M1025 Privileged Process Integrity. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-6, SC-39, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1547-boot-logon-autostart-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1547-006-kernel-modules-and-extensions",
    "title": "MITRE ATT&CK T1547.006: Kernel Modules and Extensions (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1547.006 (Kernel Modules and Extensions) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may modify the kernel to automatically execute programs on system boot. Loadable Kernel Modules (LKMs) are pieces of code that can be loaded and unloaded into the kernel upon demand. They extend the functionality of the kernel without the need to reboot the system. For example, one type of module is the device driver, which allows the kernel to access hardware connected to the system. Affected platforms: macOS, Linux. MITRE-documented mitigations include M1026 Privileged Account Management, M1018 User Account Management, M1049 Antivirus/Antimalware, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, CM-7, IA-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1547-boot-logon-autostart-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1547-007-re-opened-applications",
    "title": "MITRE ATT&CK T1547.007: Re-opened Applications (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1547.007 (Re-opened Applications) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may modify plist files to automatically run an application when a user logs in. When a user logs out or restarts via the macOS Graphical User Interface (GUI), a prompt is provided to the user with a checkbox to \"Reopen windows when logging back in\". When selected, all applications currently open are added to a property list file named com.apple.loginwindow.[UUID].plist within the ~/Library/Preferences/ByHost directory. Affected platforms: macOS. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-16, CM-2, CM-3, CM-5, CM-6, CM-7, CM-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1547-boot-logon-autostart-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1547-008-lsass-driver",
    "title": "MITRE ATT&CK T1547.008: LSASS Driver (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1547.008 (LSASS Driver) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may modify or add LSASS drivers to obtain persistence on compromised systems. The Windows security subsystem is a set of components that manage and enforce the security policy for a computer or domain. The Local Security Authority (LSA) is the main component responsible for local security policy and user authentication. Affected platforms: Windows. MITRE-documented mitigations include M1025 Privileged Process Integrity, M1043 Credential Access Protection, M1044 Restrict Library Loading. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-6, RA-5, SC-39, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1547-boot-logon-autostart-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1547-009-shortcut-modification",
    "title": "MITRE ATT&CK T1547.009: Shortcut Modification (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1547.009 (Shortcut Modification) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may create or modify shortcuts that can execute a program during system boot or user login. Shortcuts or symbolic links are used to reference other files or programs that will be opened or executed when the shortcut is clicked or executed by a system startup process. Adversaries may abuse shortcuts in the startup folder to execute their tools and achieve persistence. Although often used as payloads in an infection chain (e.g. Affected platforms: Windows. MITRE-documented mitigations include M1018 User Account Management, M1038 Execution Prevention, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1547-boot-logon-autostart-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1547-010-port-monitors",
    "title": "MITRE ATT&CK T1547.010: Port Monitors (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1547.010 (Port Monitors) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege escalation. A port monitor can be set through the AddMonitor API call to set a DLL to be loaded at startup. This DLL can be located in C:\\Windows\\System32 and will be loaded and run by the print spooler service, spoolsv.exe, under SYSTEM level permissions on boot. Affected platforms: Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1547-boot-logon-autostart-execution"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1547-012-print-processors",
    "title": "MITRE ATT&CK T1547.012: Print Processors (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1547.012 (Print Processors) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse print processors to run malicious DLLs during system boot for persistence and/or privilege escalation. Print processors are DLLs that are loaded by the print spooler service, spoolsv.exe, during boot. Adversaries may abuse the print spooler service by adding print processors that load malicious DLLs at startup. A print processor can be installed through the AddPrintProcessor API call with an account that has SeLoadDriverPrivilege enabled. Affected platforms: Windows. MITRE-documented mitigations include M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CM-5, IA-2, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1547-boot-logon-autostart-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1547-013-xdg-autostart-entries",
    "title": "MITRE ATT&CK T1547.013: XDG Autostart Entries (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1547.013 (XDG Autostart Entries) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may add or modify XDG Autostart Entries to execute malicious programs or commands when a user's desktop environment is loaded at login. XDG Autostart entries are available for any XDG-compliant Linux system. XDG Autostart entries use Desktop Entry files (.desktop) to configure the user's desktop environment upon user login. Affected platforms: Linux. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1018 User Account Management, M1033 Limit Software Installation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CA-7, CM-2, CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1547-boot-logon-autostart-execution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1547-014-active-setup",
    "title": "MITRE ATT&CK T1547.014: Active Setup (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1547.014 (Active Setup) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may achieve persistence by adding a Registry key to the Active Setup of the local machine. Active Setup is a Windows mechanism that is used to execute programs when a user logs in. The value stored in the Registry key will be executed after a user logs into the computer. These programs will be executed under the context of the user and will have the account's associated permissions level. Affected platforms: Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1547-boot-logon-autostart-execution"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1547-015-login-items",
    "title": "MITRE ATT&CK T1547.015: Login Items (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1547.015 (Login Items) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may add login items to execute upon user login to gain persistence or escalate privileges. Login items are applications, documents, folders, or server connections that are automatically launched when a user logs in. Login items can be added via a shared file list or Service Management Framework. Shared file list login items can be set using scripting languages such as AppleScript, whereas the Service Management Framework uses the API call SMLoginItemSetEnabled. Affected platforms: macOS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1547-boot-logon-autostart-execution"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1547-boot-logon-autostart-execution",
    "title": "MITRE ATT&CK T1547: Boot or Logon Autostart Execution (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1547 covers adversary configuration of system settings to execute malicious code automatically at boot or user logon, providing persistence. The technique has 14 sub-techniques including Registry Run Keys (T1547.001), Authentication Packages (T1547.002), Time Providers (T1547.003), Winlogon Helper DLL (T1547.004), Security Support Provider (T1547.005), and Kernel Modules (T1547.006). Persistence mechanisms are critical to detect because they enable adversaries to survive reboots and credential changes. Compliance obligations include system integrity monitoring (NIST 800-53 SI-7, ISO A.8.9) and continuous configuration baseline enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1548-001-setuid-and-setgid",
    "title": "MITRE ATT&CK T1548.001: Setuid and Setgid (Enterprise Tactic TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1548.001 (Setuid and Setgid) is an Enterprise Privilege Escalation and Defense Evasion sub-technique of T1548 (Abuse Elevation Control Mechanism). An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user's context. On Linux or macOS, when the setuid or setgid bits are set for an application binary, the application will run with the privileges of the owning user or group respectively. Normally an application is run in the current user's context, regardless of which user or group owns the application. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CA-7, CM-2, CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1548-abuse-elevation-control-mechanism"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1548-002-bypass-user-account-control",
    "title": "MITRE ATT&CK T1548.002: Bypass User Account Control (Enterprise Tactic TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1548.002 (Bypass User Account Control) is an Enterprise Privilege Escalation and Defense Evasion sub-technique of T1548 (Abuse Elevation Control Mechanism). Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. Affected platforms: Windows. MITRE-documented mitigations include M1051 Update Software, M1047 Audit, M1052 User Account Control, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CA-7, CM-2, CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1548-abuse-elevation-control-mechanism"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1548-003-sudo-and-sudo-caching",
    "title": "MITRE ATT&CK T1548.003: Sudo and Sudo Caching (Enterprise Tactic TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1548.003 (Sudo and Sudo Caching) is an Enterprise Privilege Escalation and Defense Evasion sub-technique of T1548 (Abuse Elevation Control Mechanism). Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges. Within Linux and MacOS systems, sudo (sometimes referred to as \"superuser do\") allows users to perform commands from terminals with elevated privileges and to control who can perform these commands on the system. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1028 Operating System Configuration, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CA-7, CM-2, CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1548-abuse-elevation-control-mechanism"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1548-004-elevated-execution-with-prompt",
    "title": "MITRE ATT&CK T1548.004: Elevated Execution with Prompt (Enterprise Tactic TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1548.004 (Elevated Execution with Prompt) is an Enterprise Privilege Escalation and Defense Evasion sub-technique of T1548 (Abuse Elevation Control Mechanism). Adversaries may leverage the AuthorizationExecuteWithPrivileges API to escalate privileges by prompting the user for credentials. The purpose of this API is to give application developers an easy way to perform operations with root privileges, such as for application installation or updating. This API does not validate that the program requesting root privileges comes from a reputable source or has been maliciously modified. Although this API is deprecated, it still fully functions in the latest releases of macOS. Affected platforms: macOS. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CA-7, CM-2, CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1548-abuse-elevation-control-mechanism"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1548-005-temporary-elevated-cloud-access",
    "title": "MITRE ATT&CK T1548.005: Temporary Elevated Cloud Access (Enterprise Tactic TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1548.005 (Temporary Elevated Cloud Access) is an Enterprise Privilege Escalation and Defense Evasion sub-technique of T1548 (Abuse Elevation Control Mechanism). Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources. Many cloud environments allow administrators to grant user or service accounts permission to request just-in-time access to roles, impersonate other accounts, pass roles onto resources and services, or otherwise gain short-term access to a set of privileges that may be distinct from their own. Affected platforms: IaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CA-7, CM-2, CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1548-abuse-elevation-control-mechanism"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1548-006-tcc-manipulation",
    "title": "MITRE ATT&CK T1548.006: TCC Manipulation (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1548.006 (TCC Manipulation) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1548 (Abuse Elevation Control Mechanism). Adversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant malicious executables elevated permissions. TCC is a Privacy & Security macOS control mechanism used to determine if the running process has permission to access the data or services protected by TCC, such as screen sharing, camera, microphone, or Full Disk Access (FDA). Affected platforms: macOS. MITRE-documented mitigations include M1026 Privileged Account Management, M1047 Audit, M1022 Restrict File and Directory Permissions, M1051 Update Software. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CA-7, CM-2, CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1548-abuse-elevation-control-mechanism"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1548-abuse-elevation-control-mechanism",
    "title": "MITRE ATT&CK T1548: Abuse Elevation Control Mechanism (Enterprise Tactic TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1548 (Abuse Elevation Control Mechanism) is an Enterprise Privilege Escalation and Defense Evasion technique. Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk. An adversary can perform several methods to take advantage of built-in control mechanisms in order to escalate privileges on a system. ATT&CK documents 6 sub-techniques: T1548.001 Setuid and Setgid; T1548.002 Bypass User Account Control; T1548.003 Sudo and Sudo Caching; T1548.004 Elevated Execution with Prompt; T1548.005 Temporary Elevated Cloud Access; T1548.006 TCC Manipulation. Affected platforms: Linux, macOS, Windows, IaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1038 Execution Prevention, M1028 Operating System Configuration, M1051 Update Software, M1052 User Account Control, M1026 Privileged Account Management, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CA-7, CM-2, CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1550-001-application-access-token",
    "title": "MITRE ATT&CK T1550.001: Application Access Token (Enterprise Tactic TA0005 - Defense Evasion / TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1550.001 (Application Access Token) is an Enterprise Defense Evasion and Lateral Movement sub-technique of T1550 (Use Alternate Authentication Material). Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials. Application access tokens are used to make authorized API requests on behalf of a user or service and are commonly used to access resources in cloud, container-based applications, and software-as-a-service (SaaS). Affected platforms: SaaS, Containers, IaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1036 Account Use Policies, M1047 Audit, M1021 Restrict Web-Based Content, M1013 Application Developer Guidance, M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-19, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1550-use-alternate-authentication-material"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1550-002-pass-the-hash",
    "title": "MITRE ATT&CK T1550.002: Pass the Hash (Enterprise Tactic TA0005 - Defense Evasion / TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1550.002 (Pass the Hash) is an Enterprise Defense Evasion and Lateral Movement sub-technique of T1550 (Use Alternate Authentication Material). Adversaries may \"pass the hash\" using stolen password hashes to move laterally within an environment, bypassing normal system access controls. Pass the hash (PtH) is a method of authenticating as a user without having access to the user's cleartext password. This method bypasses standard authentication steps that require a cleartext password, moving directly into the portion of the authentication that uses the password hash. Affected platforms: Windows. MITRE-documented mitigations include M1051 Update Software, M1052 User Account Control, M1018 User Account Management, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1550-use-alternate-authentication-material"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1550-003-pass-the-ticket",
    "title": "MITRE ATT&CK T1550.003: Pass the Ticket (Enterprise Tactic TA0005 - Defense Evasion / TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1550.003 (Pass the Ticket) is an Enterprise Defense Evasion and Lateral Movement sub-technique of T1550 (Use Alternate Authentication Material). Adversaries may \"pass the ticket\" using stolen Kerberos tickets to move laterally within an environment, bypassing normal system access controls. Pass the ticket (PtT) is a method of authenticating to a system using Kerberos tickets without having access to an account's password. Kerberos authentication can be used as the first step to lateral movement to a remote system. When preforming PtT, valid Kerberos tickets for Valid Accounts are captured by OS Credential Dumping. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1027 Password Policies, M1018 User Account Management, M1015 Active Directory Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1550-use-alternate-authentication-material"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1550-004-web-session-cookie",
    "title": "MITRE ATT&CK T1550.004: Web Session Cookie (Enterprise Tactic TA0005 - Defense Evasion / TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1550.004 (Web Session Cookie) is an Enterprise Defense Evasion and Lateral Movement sub-technique of T1550 (Use Alternate Authentication Material). Adversaries can use stolen session cookies to authenticate to web applications and services. This technique bypasses some multi-factor authentication protocols since the session is already authenticated. Authentication cookies are commonly used in web applications, including cloud-based services, after a user has authenticated to the service so credentials are not passed and re-authentication does not need to occur as frequently. Affected platforms: SaaS, IaaS, Office Suite. MITRE-documented mitigations include M1054 Software Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2, SC-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1550-use-alternate-authentication-material"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1550-use-alternate-authentication-material",
    "title": "MITRE ATT&CK T1550: Use Alternate Authentication Material (Enterprise Tactic TA0005 - Defense Evasion / TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1550 (Use Alternate Authentication Material) is an Enterprise Defense Evasion and Lateral Movement technique. Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal system access controls. Authentication processes generally require a valid identity (e.g., username) along with one or more authentication factors (e.g., password, pin, physical smart card, token generator, etc.). ATT&CK documents 4 sub-techniques: T1550.001 Application Access Token; T1550.002 Pass the Hash; T1550.003 Pass the Ticket; T1550.004 Web Session Cookie. Affected platforms: Windows, SaaS, IaaS, Containers, Identity Provider, Office Suite. MITRE-documented mitigations include M1047 Audit, M1027 Password Policies, M1036 Account Use Policies, M1026 Privileged Account Management, M1015 Active Directory Configuration, M1013 Application Developer Guidance. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-5, CM-6, IA-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1552-001-credentials-in-files",
    "title": "MITRE ATT&CK T1552.001: Credentials In Files (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1552.001 (Credentials In Files) is an Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords. It is possible to extract passwords from backups or saved virtual machines through OS Credential Dumping. Affected platforms: Windows, IaaS, Linux, macOS, Containers. MITRE-documented mitigations include M1017 User Training, M1047 Audit, M1022 Restrict File and Directory Permissions, M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1552-unsecured-credentials"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1552-002-credentials-in-registry",
    "title": "MITRE ATT&CK T1552.002: Credentials in Registry (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1552.002 (Credentials in Registry) is an Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may search the Registry on compromised systems for insecurely stored credentials. The Windows Registry stores configuration information that can be used by the system or other programs. Adversaries may query the Registry looking for credentials and passwords that have been stored for use by other programs or services. Sometimes these credentials are used for automatic logons. Affected platforms: Windows. MITRE-documented mitigations include M1027 Password Policies, M1026 Privileged Account Management, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1552-unsecured-credentials"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1552-003-bash-history",
    "title": "MITRE ATT&CK T1552.003: Shell History (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1552.003 (Shell History) is an Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may search the bash command history on compromised systems for insecurely stored credentials. Bash keeps track of the commands users type on the command-line with the \"history\" utility. Once a user logs out, the history is flushed to the user's .bash_history file. For each user, this file resides at the same location: ~/.bash_history. Typically, this file keeps track of the user's last 500 commands. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1552-unsecured-credentials"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1552-004-private-keys",
    "title": "MITRE ATT&CK T1552.004: Private Keys (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1552.004 (Private Keys) is an Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc. Adversaries may also look in common key directories, such as ~/.ssh for SSH keys on * nix-based systems or C:&#92;Users&#92;(username)&#92;.ssh&#92; on Windows. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1027 Password Policies, M1022 Restrict File and Directory Permissions, M1047 Audit, M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1552-unsecured-credentials"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1552-005-cloud-instance-metadata-api",
    "title": "MITRE ATT&CK T1552.005: Cloud Instance Metadata API (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1552.005 (Cloud Instance Metadata API) is an Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may attempt to access the Cloud Instance Metadata API to collect credentials and other sensitive data. Most cloud service providers support a Cloud Instance Metadata API which is a service provided to running virtual instances that allows applications to access information about the running virtual instance. Available information generally includes name, security group, and additional metadata including sensitive data such as credentials and UserData scripts that may contain additional secrets. Affected platforms: IaaS. MITRE-documented mitigations include M1035 Limit Access to Resource Over Network, M1042 Disable or Remove Feature or Program, M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1552-unsecured-credentials"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1552-006-group-policy-preferences",
    "title": "MITRE ATT&CK T1552.006: Group Policy Preferences (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1552.006 (Group Policy Preferences) is an Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may attempt to find unsecured credentials in Group Policy Preferences (GPP). GPP are tools that allow administrators to create domain policies with embedded credentials. These policies allow administrators to set local accounts. These group policies are stored in SYSVOL on a domain controller. This means that any domain user can view the SYSVOL share and decrypt the password (using the AES key that has been made public). Affected platforms: Windows. MITRE-documented mitigations include M1047 Audit, M1051 Update Software, M1015 Active Directory Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1552-unsecured-credentials"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1552-007-container-api",
    "title": "MITRE ATT&CK T1552.007: Container API (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1552.007 (Container API) is an Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may gather credentials via APIs within a containers environment. APIs in these environments, such as the Docker API and Kubernetes APIs, allow a user to remotely manage their container resources and cluster components. An adversary may access the Docker API to collect logs that contain credentials to cloud, container, and various other resources in the environment. Affected platforms: Containers. MITRE-documented mitigations include M1026 Privileged Account Management, M1035 Limit Access to Resource Over Network, M1030 Network Segmentation, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1552-unsecured-credentials"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1552-008-chat-messages",
    "title": "MITRE ATT&CK T1552.008: Chat Messages (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1552.008 (Chat Messages) is an Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may directly collect unsecured credentials stored or passed through user communication services. Credentials may be sent and stored in user chat communication applications such as email, chat services like Slack or Teams, collaboration tools like Jira or Trello, and any other services that support user communication. Users may share various forms of credentials (such as usernames and passwords, API keys, or authentication tokens) on private or public corporate internal communications channels. Affected platforms: SaaS, Office Suite. MITRE-documented mitigations include M1047 Audit, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1552-unsecured-credentials"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1552-unsecured-credentials",
    "title": "MITRE ATT&CK T1552: Unsecured Credentials (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1552 (Unsecured Credentials) is an Enterprise Credential Access technique. Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Bash History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys). ATT&CK documents 8 sub-techniques: T1552.001 Credentials In Files; T1552.002 Credentials in Registry; T1552.003 Bash History; T1552.004 Private Keys; T1552.005 Cloud Instance Metadata API; T1552.006 Group Policy Preferences; T1552.007 Container API; T1552.008 Chat Messages. Affected platforms: Windows, SaaS, IaaS, Linux, macOS, Containers, Network, Office Suite, Identity Provider. MITRE-documented mitigations include M1041 Encrypt Sensitive Information, M1051 Update Software, M1017 User Training, M1015 Active Directory Configuration, M1027 Password Policies, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1553-001-gatekeeper-bypass",
    "title": "MITRE ATT&CK T1553.001: Gatekeeper Bypass (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1553.001 (Gatekeeper Bypass) is an Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs. Gatekeeper is a set of technologies that act as layer of Apple's security model to ensure only trusted applications are executed on a host. Gatekeeper was built on top of File Quarantine in Snow Leopard (10.6, 2009) and has grown to include Code Signing, security policy compliance, Notarization, and more. Affected platforms: macOS. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1553-subvert-trust-controls"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1553-002-code-signing",
    "title": "MITRE ATT&CK T1553.002: Code Signing (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1553.002 (Code Signing) is an Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature. Code signing to verify software on first run can be used on modern Windows and macOS systems. Affected platforms: macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1553-subvert-trust-controls"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1553-003-sip-and-trust-provider-hijacking",
    "title": "MITRE ATT&CK T1553.003: SIP and Trust Provider Hijacking (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1553.003 (SIP and Trust Provider Hijacking) is an Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may tamper with SIP and trust provider components to mislead the operating system and application control tools when conducting signature validation checks. In user mode, Windows Authenticode digital signatures are used to verify a file's origin and integrity, variables that may be used to establish trust in signed code (ex: a driver with a valid Microsoft signature may be handled as safe). Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1024 Restrict Registry Permissions, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-3, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1553-subvert-trust-controls"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1553-004-install-root-certificate",
    "title": "MITRE ATT&CK T1553.004: Install Root Certificate (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1553.004 (Install Root Certificate) is an Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers. Root certificates are used in public key cryptography to identify a root certificate authority (CA). When a root certificate is installed, the system or application will trust certificates in the root's chain of trust that have been signed by the root certificate. Certificates are commonly used for establishing secure TLS/SSL communications within a web browser. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1054 Software Configuration, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1553-subvert-trust-controls"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1553-005-mark-of-the-web-bypass",
    "title": "MITRE ATT&CK T1553.005: Mark-of-the-Web Bypass (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1553.005 (Mark-of-the-Web Bypass) is an Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls. In Windows, when files are downloaded from the Internet, they are tagged with a hidden NTFS Alternate Data Stream (ADS) named Zone.Identifier with a specific value known as the MOTW. Files that are tagged with MOTW are protected and cannot perform certain actions. For example, starting in MS Office 10, if a MS Office file has the MOTW, it will open in Protected View. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1553-subvert-trust-controls"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1553-006-code-signing-policy-modification",
    "title": "MITRE ATT&CK T1553.006: Code Signing Policy Modification (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1553.006 (Code Signing Policy Modification) is an Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may modify code signing policies to enable execution of unsigned or self-signed code. Code signing provides a level of authenticity on a program from a developer and a guarantee that the program has not been tampered with. Security controls can include enforcement mechanisms to ensure that only valid, signed code can be run on an operating system. Affected platforms: Windows, macOS. MITRE-documented mitigations include M1026 Privileged Account Management, M1046 Boot Integrity, M1024 Restrict Registry Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1553-subvert-trust-controls"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1553-subvert-trust-controls",
    "title": "MITRE ATT&CK T1553: Subvert Trust Controls (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1553 (Subvert Trust Controls) is an Enterprise Defense Evasion technique. Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and security products may contain mechanisms to identify programs or websites as possessing some level of trust. ATT&CK documents 6 sub-techniques: T1553.001 Gatekeeper Bypass; T1553.002 Code Signing; T1553.003 SIP and Trust Provider Hijacking; T1553.004 Install Root Certificate; T1553.005 Mark-of-the-Web Bypass; T1553.006 Code Signing Policy Modification. Affected platforms: Windows, macOS, Linux. MITRE-documented mitigations include M1038 Execution Prevention, M1028 Operating System Configuration, M1026 Privileged Account Management, M1024 Restrict Registry Permissions, M1054 Software Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-2, CM-3, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1554-compromise-host-software-binary",
    "title": "MITRE ATT&CK T1554: Compromise Host Software Binary (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1554 (Compromise Host Software Binary) is an Enterprise Persistence technique. Adversaries may modify host software binaries to establish persistent access to systems. Software binaries/executables provide a wide range of system commands or services, programs, and libraries. Common software binaries are SSH clients, FTP clients, email clients, web browsers, and many other user or server applications. Adversaries may establish persistence though modifications to host software binaries. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1045 Code Signing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-5, CM-6, IA-9, SI-3, SI-7, SR-4, SR-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1555-001-keychain",
    "title": "MITRE ATT&CK T1555.001: Keychain (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1555.001 (Keychain) is an Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). Adversaries may acquire credentials from Keychain. Keychain (or Keychain Services) is the macOS credential management system that stores account names, passwords, private keys, certificates, sensitive application data, payment data, and secure notes. There are three types of Keychains: Login Keychain, System Keychain, and Local Items (iCloud) Keychain. The default Keychain is the Login Keychain, which stores user passwords and information. Affected platforms: macOS. MITRE-documented mitigations include M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-6, AC-20, CA-7, CM-3, IA-5, SI-2, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1555-credentials-from-password-stores"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1555-002-securityd-memory",
    "title": "MITRE ATT&CK T1555.002: Securityd Memory (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1555.002 (Securityd Memory) is an Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). An adversary with root access may gather credentials by reading securityd's memory. securityd is a service/daemon responsible for implementing security protocols such as encryption and authorization. A privileged adversary may be able to scan through securityd's memory to find the correct sequence of keys to decrypt the user's logon keychain. This may provide the adversary with various plaintext passwords, such as those for users, WiFi, mail, browsers, certificates, secure notes, etc. Affected platforms: Linux, macOS. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-6, AC-20, CA-7, CM-3, IA-5, SI-2, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1555-credentials-from-password-stores"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1555-003-credentials-from-web-browsers",
    "title": "MITRE ATT&CK T1555.003: Credentials from Web Browsers (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1555.003 (Credentials from Web Browsers) is an Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1051 Update Software, M1018 User Account Management, M1017 User Training, M1021 Restrict Web-Based Content, M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-6, AC-20, CA-7, CM-3, IA-5, SI-2, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1555-credentials-from-password-stores"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1555-004-windows-credential-manager",
    "title": "MITRE ATT&CK T1555.004: Windows Credential Manager (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1555.004 (Windows Credential Manager) is an Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). Adversaries may acquire credentials from the Windows Credential Manager. The Credential Manager stores credentials for signing into websites, applications, and/or devices that request authentication through NTLM or Kerberos in Credential Lockers (previously known as Windows Vaults). The Windows Credential Manager separates website credentials from application or network credentials in two lockers. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-6, AC-20, CA-7, CM-2, CM-3, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1555-credentials-from-password-stores"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1555-005-password-managers",
    "title": "MITRE ATT&CK T1555.005: Password Managers (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1555.005 (Password Managers) is an Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). Adversaries may acquire user credentials from third-party password managers. Password managers are applications designed to store user credentials, normally in an encrypted database. Credentials are typically accessible after a user provides a master password that unlocks the database. After the database is unlocked, these credentials may be copied to memory. These databases can be stored as files on disk. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1051 Update Software, M1018 User Account Management, M1017 User Training, M1054 Software Configuration, M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, AC-20, CA-7, CM-2, CM-3, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1555-credentials-from-password-stores"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1555-006-cloud-secrets-management-stores",
    "title": "MITRE ATT&CK T1555.006: Cloud Secrets Management Stores (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1555.006 (Cloud Secrets Management Stores) is an Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault. Secrets managers support the secure centralized management of passwords, API keys, and other credential material. Where secrets managers are in use, cloud services can dynamically acquire credentials via API requests rather than accessing secrets insecurely stored in plain text files or environment variables. Affected platforms: IaaS. MITRE-documented mitigations include M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, AC-20, CA-7, CM-3, CM-7, IA-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1555-credentials-from-password-stores"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1555-credentials-from-password-stores",
    "title": "MITRE ATT&CK T1555: Credentials from Password Stores (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1555 covers adversary access to credentials stored in browsers, password managers, and OS credential stores. Sub-techniques include Keychain (T1555.001), Securityd Memory (T1555.002), Credentials from Web Browsers (T1555.003), Windows Credential Manager (T1555.004), and Password Managers (T1555.005). Browser credential theft is a primary objective of modern infostealers (RedLine, Vidar, LummaC2, StealC). Compliance obligations include enterprise password manager deployment, SSO adoption, and browser hardening required under NIS2 Article 21, DORA Article 9, and ISO 27001 A.5.17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1003-os-credential-dumping",
      "mitre-attack-t1078-valid-accounts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1556-001-domain-controller-authentication",
    "title": "MITRE ATT&CK T1556.001: Domain Controller Authentication (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1556.001 (Domain Controller Authentication) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may patch the authentication process on a domain controller to bypass the typical authentication mechanisms and enable access to accounts. Malware may be used to inject false credentials into the authentication process on a domain controller with the intent of creating a backdoor used to access any user's account and/or credentials (ex: Skeleton Key). Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1025 Privileged Process Integrity, M1032 Multi-factor Authentication, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1556-modify-authentication-process"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1556-002-password-filter-dll",
    "title": "MITRE ATT&CK T1556.002: Password Filter DLL (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1556.002 (Password Filter DLL) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may register malicious password filter dynamic link libraries (DLLs) into the authentication process to acquire user credentials as they are validated. Windows password filters are password policy enforcement mechanisms for both domain and local accounts. Filters are implemented as DLLs containing a method to validate potential passwords against password policies. Filter DLLs can be positioned on local computers for local accounts and/or domain controllers for domain accounts. Affected platforms: Windows. MITRE-documented mitigations include M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1556-modify-authentication-process"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1556-003-pluggable-authentication-modules",
    "title": "MITRE ATT&CK T1556.003: Pluggable Authentication Modules (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1556.003 (Pluggable Authentication Modules) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts. PAM is a modular system of configuration files, libraries, and executable files which guide authentication for many services. The most common authentication module is pam_unix.so, which retrieves, sets, and verifies account authentication information in /etc/passwd and /etc/shadow. Adversaries may modify components of the PAM system to create backdoors. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1556-modify-authentication-process"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1556-004-network-device-authentication",
    "title": "MITRE ATT&CK T1556.004: Network Device Authentication (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1556.004 (Network Device Authentication) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native authentication mechanisms for local accounts on network devices. Modify System Image may include implanted code to the operating system for network devices to provide access for adversaries using a specific password. The modification includes a specific password which is implanted in the operating system image via the patch. Affected platforms: Network. MITRE-documented mitigations include M1026 Privileged Account Management, M1032 Multi-factor Authentication. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1556-modify-authentication-process"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1556-005-reversible-encryption",
    "title": "MITRE ATT&CK T1556.005: Reversible Encryption (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1556.005 (Reversible Encryption) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). An adversary may abuse Active Directory authentication encryption properties to gain access to credentials on Windows systems. The AllowReversiblePasswordEncryption property specifies whether reversible password encryption for an account is enabled or disabled. By default this property is disabled (instead storing user credentials as the output of one-way hashing functions) and should not be enabled unless legacy or other software require it. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1556-modify-authentication-process"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1556-006-multi-factor-authentication",
    "title": "MITRE ATT&CK T1556.006: Multi-Factor Authentication (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1556.006 (Multi-Factor Authentication) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts. Once adversaries have gained access to a network by either compromising an account lacking MFA or by employing an MFA bypass method such as Multi-Factor Authentication Request Generation, adversaries may leverage their access to modify or completely disable MFA defenses. Affected platforms: Windows, SaaS, IaaS, Linux, macOS, Office Suite, Identity Provider. MITRE-documented mitigations include M1018 User Account Management, M1047 Audit, M1032 Multi-factor Authentication. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1556-modify-authentication-process"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1556-007-hybrid-identity",
    "title": "MITRE ATT&CK T1556.007: Hybrid Identity (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1556.007 (Hybrid Identity) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises user identities in order to bypass typical authentication mechanisms, access credentials, and enable persistent access to accounts. Many organizations maintain hybrid user and device identities that are shared between on-premises and cloud-based environments. These can be maintained in a number of ways. Affected platforms: Windows, SaaS, IaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1047 Audit, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1556-modify-authentication-process"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1556-008-network-provider-dll",
    "title": "MITRE ATT&CK T1556.008: Network Provider DLL (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1556.008 (Network Provider DLL) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process. Network provider DLLs allow Windows to interface with specific network protocols and can also support add-on credential management functions. During the logon process, Winlogon (the interactive logon module) sends credentials to the local mpnotify.exe process via RPC. Affected platforms: Windows. MITRE-documented mitigations include M1024 Restrict Registry Permissions, M1047 Audit, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1556-modify-authentication-process"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1556-009-conditional-access-policies",
    "title": "MITRE ATT&CK T1556.009: Conditional Access Policies (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1556.009 (Conditional Access Policies) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may disable or modify conditional access policies to enable persistent access to compromised accounts. Conditional access policies are additional verifications used by identity providers and identity and access management systems to determine whether a user should be granted access to a resource. For example, in Entra ID, Okta, and JumpCloud, users can be denied access to applications based on their IP address, device enrollment status, and use of multi-factor authentication. Affected platforms: IaaS, Identity Provider. MITRE-documented mitigations include M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-16, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1556-modify-authentication-process"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1556-modify-authentication-process",
    "title": "MITRE ATT&CK T1556: Modify Authentication Process (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1556 (Modify Authentication Process) is an Enterprise Credential Access and Defense Evasion and Persistence technique. Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. ATT&CK documents 9 sub-techniques: T1556.001 Domain Controller Authentication; T1556.002 Password Filter DLL; T1556.003 Pluggable Authentication Modules; T1556.004 Network Device Authentication; T1556.005 Reversible Encryption; T1556.006 Multi-Factor Authentication; T1556.007 Hybrid Identity; T1556.008 Network Provider DLL; T1556.009 Conditional Access Policies. Affected platforms: Windows, Linux, macOS, Network, IaaS, SaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1024 Restrict Registry Permissions, M1032 Multi-factor Authentication, M1027 Password Policies, M1022 Restrict File and Directory Permissions, M1018 User Account Management, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1557-001-llmnr-nbt-ns-poisoning-and-smb-relay",
    "title": "MITRE ATT&CK T1557.001: Name Resolution Poisoning and SMB Relay (Enterprise Tactic TA0006 - Credential Access / TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1557.001 (Name Resolution Poisoning and SMB Relay) is an Enterprise Credential Access and Collection sub-technique of T1557 (Adversary-in-the-Middle). By responding to LLMNR/NBT-NS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system. This activity may be used to collect or relay authentication materials. Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) are Microsoft Windows components that serve as alternate methods of host identification. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1031 Network Intrusion Prevention, M1030 Network Segmentation, M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-18, AC-19, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1557-adversary-in-the-middle"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1557-002-arp-cache-poisoning",
    "title": "MITRE ATT&CK T1557.002: ARP Cache Poisoning (Enterprise Tactic TA0006 - Credential Access / TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1557.002 (ARP Cache Poisoning) is an Enterprise Credential Access and Collection sub-technique of T1557 (Adversary-in-the-Middle). Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked devices. This activity may be used to enable follow-on behaviors such as Network Sniffing or Transmitted Data Manipulation. The ARP protocol is used to resolve IPv4 addresses to link layer addresses, such as a media access control (MAC) address. Devices in a local network segment communicate with each other by using link layer addresses. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1041 Encrypt Sensitive Information, M1031 Network Intrusion Prevention, M1017 User Training, M1042 Disable or Remove Feature or Program, M1035 Limit Access to Resource Over Network, M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-18, AC-19, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1557-adversary-in-the-middle"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1557-003-dhcp-spoofing",
    "title": "MITRE ATT&CK T1557.003: DHCP Spoofing (Enterprise Tactic TA0006 - Credential Access / TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1557.003 (DHCP Spoofing) is an Enterprise Credential Access and Collection sub-technique of T1557 (Adversary-in-the-Middle). Adversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol (DHCP) traffic and acting as a malicious DHCP server on the victim network. By achieving the adversary-in-the-middle (AiTM) position, adversaries may collect network communications, including passed credentials, especially those sent over insecure, unencrypted protocols. This may also enable follow-on behaviors such as Network Sniffing or Transmitted Data Manipulation. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1037 Filter Network Traffic, M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-18, AC-19, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1557-adversary-in-the-middle"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1557-004-evil-twin",
    "title": "MITRE ATT&CK T1557.004: Evil Twin (Enterprise Tactic TA0006 - Credential Access / TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1557.004 (Evil Twin) is an Enterprise Credential Access and Collection sub-technique of T1557 (Adversary-in-the-Middle). Adversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as a way of supporting follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or Input Capture. By using a Service Set Identifier (SSID) of a legitimate Wi-Fi network, fraudulent Wi-Fi access points may trick devices or users into connecting to malicious Wi-Fi networks. Affected platforms: Network. MITRE-documented mitigations include M1031 Network Intrusion Prevention, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-18, AC-19, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1557-adversary-in-the-middle"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1557-adversary-in-the-middle",
    "title": "MITRE ATT&CK T1557: Adversary-in-the-Middle (Enterprise Tactic TA0006 - Credential Access / TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1557 (Adversary-in-the-Middle) is an Enterprise Credential Access and Collection technique. Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ATT&CK documents 4 sub-techniques: T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay; T1557.002 ARP Cache Poisoning; T1557.003 DHCP Spoofing; T1557.004 Evil Twin. Affected platforms: Windows, macOS, Linux, Network. MITRE-documented mitigations include M1037 Filter Network Traffic, M1041 Encrypt Sensitive Information, M1035 Limit Access to Resource Over Network, M1042 Disable or Remove Feature or Program, M1017 User Training, M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-18, AC-19, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1558-001-golden-ticket",
    "title": "MITRE ATT&CK T1558.001: Golden Ticket (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1558.001 (Golden Ticket) is an Enterprise Credential Access sub-technique of T1558 (Steal or Forge Kerberos Tickets). Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket. Golden tickets enable adversaries to generate authentication material for any account in Active Directory. Using a golden ticket, adversaries are then able to request ticket granting service (TGS) tickets, which enable access to specific resources. Golden tickets require adversaries to interact with the Key Distribution Center (KDC) in order to obtain TGS. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1015 Active Directory Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, AC-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1558-steal-or-forge-kerberos-tickets"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1558-002-silver-ticket",
    "title": "MITRE ATT&CK T1558.002: Silver Ticket (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1558.002 (Silver Ticket) is an Enterprise Credential Access sub-technique of T1558 (Steal or Forge Kerberos Tickets). Adversaries who have the password hash of a target service account (e.g. SharePoint, MSSQL) may forge Kerberos ticket granting service (TGS) tickets, also known as silver tickets. Kerberos TGS tickets are also known as service tickets. Silver tickets are more limited in scope in than golden tickets in that they only enable adversaries to access a particular resource (e.g. Affected platforms: Windows. MITRE-documented mitigations include M1027 Password Policies, M1026 Privileged Account Management, M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, AC-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1558-steal-or-forge-kerberos-tickets"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1558-003-kerberoasting",
    "title": "MITRE ATT&CK T1558.003: Kerberoasting (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1558.003 (Kerberoasting) is an Enterprise Credential Access sub-technique of T1558 (Steal or Forge Kerberos Tickets). Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force. Service principal names (SPNs) are used to uniquely identify each instance of a Windows service. To enable authentication, Kerberos requires that SPNs be associated with at least one service logon account (an account specifically tasked with running a service). Affected platforms: Windows. MITRE-documented mitigations include M1027 Password Policies, M1041 Encrypt Sensitive Information, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, AC-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1558-steal-or-forge-kerberos-tickets"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1558-004-as-rep-roasting",
    "title": "MITRE ATT&CK T1558.004: AS-REP Roasting (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1558.004 (AS-REP Roasting) is an Enterprise Credential Access sub-technique of T1558 (Steal or Forge Kerberos Tickets). Adversaries may reveal credentials of accounts that have disabled Kerberos preauthentication by Password Cracking Kerberos messages. Preauthentication offers protection against offline Password Cracking. When enabled, a user requesting access to a resource initiates communication with the Domain Controller (DC) by sending an Authentication Server Request (AS-REQ) message with a timestamp that is encrypted with the hash of their password. Affected platforms: Windows. MITRE-documented mitigations include M1047 Audit, M1027 Password Policies, M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, AC-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1558-steal-or-forge-kerberos-tickets"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1558-005-ccache-files",
    "title": "MITRE ATT&CK T1558.005: Ccache Files (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1558.005 (Ccache Files) is an Enterprise Credential Access sub-technique of T1558 (Steal or Forge Kerberos Tickets). Adversaries may attempt to steal Kerberos tickets stored in credential cache files (or ccache). These files are used for short term storage of a user's active session credentials. The ccache file is created upon user authentication and allows for access to multiple services without the user having to re-enter credentials. The /etc/krb5.conf configuration file and the KRB5CCNAME environment variable are used to set the storage location for ccache entries. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1047 Audit, M1043 Credential Access Protection. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, AC-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1558-steal-or-forge-kerberos-tickets"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1558-steal-or-forge-kerberos-tickets",
    "title": "MITRE ATT&CK T1558: Steal or Forge Kerberos Tickets (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1558 (Steal or Forge Kerberos Tickets) is an Enterprise Credential Access technique. Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket. Kerberos is an authentication protocol widely used in modern Windows domain environments. In Kerberos environments, referred to as \"realms\", there are three basic participants: client, service, and Key Distribution Center (KDC). ATT&CK documents 5 sub-techniques: T1558.001 Golden Ticket; T1558.002 Silver Ticket; T1558.003 Kerberoasting; T1558.004 AS-REP Roasting; T1558.005 Ccache Files. Affected platforms: Windows, Linux, macOS. MITRE-documented mitigations include M1015 Active Directory Configuration, M1043 Credential Access Protection, M1041 Encrypt Sensitive Information, M1027 Password Policies, M1047 Audit, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, AC-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1559-001-component-object-model",
    "title": "MITRE ATT&CK T1559.001: Component Object Model (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1559.001 (Component Object Model) is an Enterprise Execution sub-technique of T1559 (Inter-Process Communication). Adversaries may use the Windows Component Object Model (COM) for local code execution. COM is an inter-process communication (IPC) component of the native Windows application programming interface (API) that enables interaction between software objects, or executable code that implements one or more interfaces. Through COM, a client object can call methods of server objects, which are typically binary Dynamic Link Libraries (DLL) or executables (EXE). Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1048 Application Isolation and Sandboxing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1559-inter-process-communication"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1559-002-dynamic-data-exchange",
    "title": "MITRE ATT&CK T1559.002: Dynamic Data Exchange (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1559.002 (Dynamic Data Exchange) is an Enterprise Execution sub-technique of T1559 (Inter-Process Communication). Adversaries may use Windows Dynamic Data Exchange (DDE) to execute arbitrary commands. DDE is a client-server protocol for one-time and/or continuous inter-process communication (IPC) between applications. Once a link is established, applications can autonomously exchange transactions consisting of strings, warm data links (notifications when a data item changes), hot data links (duplications of changes to a data item), and requests for command execution. Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint, M1048 Application Isolation and Sandboxing, M1054 Software Configuration, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1559-inter-process-communication"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1559-003-xpc-services",
    "title": "MITRE ATT&CK T1559.003: XPC Services (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1559.003 (XPC Services) is an Enterprise Execution sub-technique of T1559 (Inter-Process Communication). Adversaries can provide malicious content to an XPC service daemon for local code execution. macOS uses XPC services for basic inter-process communication between various processes, such as between the XPC Service daemon and third-party application privileged helper tools. Applications can send messages to the XPC Service daemon, which runs as root, using the low-level XPC Service C API or the high level NSXPCConnection API in order to handle tasks that require elevated privileges (such as network connections). Affected platforms: macOS. MITRE-documented mitigations include M1013 Application Developer Guidance. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1559-inter-process-communication"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1559-inter-process-communication",
    "title": "MITRE ATT&CK T1559: Inter-Process Communication (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1559 (Inter-Process Communication) is an Enterprise Execution technique. Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution. IPC is typically used by processes to share data, communicate with each other, or synchronize execution. IPC is also commonly used to avoid situations such as deadlocks, which occurs when processes are stuck in a cyclic waiting pattern. Adversaries may abuse IPC to execute arbitrary code or commands. ATT&CK documents 3 sub-techniques: T1559.001 Component Object Model; T1559.002 Dynamic Data Exchange; T1559.003 XPC Services. Affected platforms: Windows, macOS, Linux. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1054 Software Configuration, M1048 Application Isolation and Sandboxing, M1026 Privileged Account Management, M1040 Behavior Prevention on Endpoint, M1013 Application Developer Guidance. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1560-001-archive-via-utility",
    "title": "MITRE ATT&CK T1560.001: Archive via Utility (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1560.001 (Archive via Utility) is an Enterprise Collection sub-technique of T1560 (Archive Collected Data). Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport. Adversaries may abuse various utilities to compress or encrypt data before exfiltration. Some third party utilities may be preinstalled, such as tar on Linux and macOS or zip on Windows systems. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, RA-5, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1560-archive-collected-data"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1560-002-archive-via-library",
    "title": "MITRE ATT&CK T1560.002: Archive via Library (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1560.002 (Archive via Library) is an Enterprise Collection sub-technique of T1560 (Archive Collected Data). An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries. Many libraries exist that can archive data, including Python rarfile , libzip , and zlib . Most libraries include functionality to encrypt and/or compress data. Some archival libraries are preinstalled on systems, such as bzip2 on macOS and Linux, and zip on Windows. Note that the libraries are different from the utilities. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, RA-5, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1560-archive-collected-data"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1560-003-archive-via-custom-method",
    "title": "MITRE ATT&CK T1560.003: Archive via Custom Method (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1560.003 (Archive via Custom Method) is an Enterprise Collection sub-technique of T1560 (Archive Collected Data). An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method. Adversaries may choose to use custom archival methods, such as encryption with XOR or stream ciphers implemented with no external library or utility references. Custom implementations of well-known compression algorithms have also been used. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, RA-5, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1560-archive-collected-data"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1560-archive-collected-data",
    "title": "MITRE ATT&CK T1560: Archive Collected Data (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1560 (Archive Collected Data) is an Enterprise Collection technique. An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network. Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender. Both compression and encryption are done prior to exfiltration, and can be performed using a utility, 3rd party library, or custom method. ATT&CK documents 3 sub-techniques: T1560.001 Archive via Utility; T1560.002 Archive via Library; T1560.003 Archive via Custom Method. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, RA-5, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1561-001-disk-content-wipe",
    "title": "MITRE ATT&CK T1561.001: Disk Content Wipe (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1561.001 (Disk Content Wipe) is an Enterprise Impact sub-technique of T1561 (Disk Wipe). Adversaries may erase the contents of storage devices on specific systems or in large numbers in a network to interrupt availability to system and network resources. Adversaries may partially or completely overwrite the contents of a storage device rendering the data irrecoverable through the storage interface. Instead of wiping specific disk structures or files, adversaries with destructive intent may wipe arbitrary portions of disk content. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1053 Data Backup. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-6, CM-2, CP-2, CP-7, CP-9, CP-10, SI-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1561-disk-wipe"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1561-002-disk-structure-wipe",
    "title": "MITRE ATT&CK T1561.002: Disk Structure Wipe (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1561.002 (Disk Structure Wipe) is an Enterprise Impact sub-technique of T1561 (Disk Wipe). Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to interrupt availability to system and network resources. Adversaries may attempt to render the system unable to boot by overwriting critical data located in structures such as the master boot record (MBR) or partition table. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1053 Data Backup. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-6, CM-2, CP-2, CP-7, CP-9, CP-10, SI-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1561-disk-wipe"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1561-disk-wipe",
    "title": "MITRE ATT&CK T1561: Disk Wipe (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1561 (Disk Wipe) is an Enterprise Impact technique. Adversaries may wipe or corrupt raw disk data on specific systems or in large numbers in a network to interrupt availability to system and network resources. With direct write access to a disk, adversaries may attempt to overwrite portions of disk data. Adversaries may opt to wipe arbitrary portions of disk data and/or wipe disk structures like the master boot record (MBR). A complete wipe of all disk sectors may be attempted. ATT&CK documents 2 sub-techniques: T1561.001 Disk Content Wipe; T1561.002 Disk Structure Wipe. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1053 Data Backup. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-6, CM-2, CP-2, CP-7, CP-9, CP-10, SI-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1563-001-ssh-hijacking",
    "title": "MITRE ATT&CK T1563.001: SSH Hijacking (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1563.001 (SSH Hijacking) is an Enterprise Lateral Movement sub-technique of T1563 (Remote Service Session Hijacking). Adversaries may hijack a legitimate user's SSH session to move laterally within an environment. Secure Shell (SSH) is a standard means of remote access on Linux and macOS systems. It allows a user to connect to another system via an encrypted tunnel, commonly authenticating through a password, certificate or the use of an asymmetric encryption key pair. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1042 Disable or Remove Feature or Program, M1027 Password Policies, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-12, AC-17, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1563-remote-service-session-hijacking"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1563-002-rdp-hijacking",
    "title": "MITRE ATT&CK T1563.002: RDP Hijacking (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1563.002 (RDP Hijacking) is an Enterprise Lateral Movement sub-technique of T1563 (Remote Service Session Hijacking). Adversaries may hijack a legitimate user's remote desktop session to move laterally within an environment. Remote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS). Adversaries may perform RDP session hijacking which involves stealing a legitimate user's remote session. Affected platforms: Windows. MITRE-documented mitigations include M1035 Limit Access to Resource Over Network, M1030 Network Segmentation, M1028 Operating System Configuration, M1018 User Account Management, M1047 Audit, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-11, AC-12, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1563-remote-service-session-hijacking"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1563-remote-service-session-hijacking",
    "title": "MITRE ATT&CK T1563: Remote Service Session Hijacking (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1563 (Remote Service Session Hijacking) is an Enterprise Lateral Movement technique. Adversaries may take control of preexisting sessions with remote services to move laterally in an environment. Users may use valid credentials to log into a service specifically designed to accept remote connections, such as telnet, SSH, and RDP. When a user logs into a service, a session will be established that will allow them to maintain a continuous interaction with that service. Adversaries may commandeer these sessions to carry out actions on remote systems. ATT&CK documents 2 sub-techniques: T1563.001 SSH Hijacking; T1563.002 RDP Hijacking. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1030 Network Segmentation, M1042 Disable or Remove Feature or Program, M1027 Password Policies, M1018 User Account Management, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-12, AC-17, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1564-001-hidden-files-and-directories",
    "title": "MITRE ATT&CK T1564.001: Hidden Files and Directories (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1564.001 (Hidden Files and Directories) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a 'hidden' file. These files don't show up when a user browses the file system with a GUI or when using normal commands on the command line. Affected platforms: Windows, macOS, Linux.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1564-hide-artifacts"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1564-002-hidden-users",
    "title": "MITRE ATT&CK T1564.002: Hidden Users (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1564.002 (Hidden Users) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may use hidden users to hide the presence of user accounts they create or modify. Administrators may want to hide users when there are many user accounts on a given system or if they want to hide their administrative or other management accounts from other users. In macOS, adversaries can create or modify a user to be hidden through manipulating plist files, folder attributes, and user attributes. Affected platforms: macOS, Windows, Linux. MITRE-documented mitigations include M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-6, CM-7, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1564-hide-artifacts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1564-003-hidden-window",
    "title": "MITRE ATT&CK T1564.003: Hidden Window (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1564.003 (Hidden Window) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks. Adversaries may abuse these functionalities to hide otherwise visible windows from users so as not to alert the user to adversary activity on the system. Affected platforms: macOS, Windows, Linux. MITRE-documented mitigations include M1038 Execution Prevention, M1033 Limit Software Installation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-7, SI-7, SI-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1564-hide-artifacts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1564-004-ntfs-file-attributes",
    "title": "MITRE ATT&CK T1564.004: NTFS File Attributes (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1564.004 (NTFS File Attributes) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. Within MFT entries are file attributes, such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files). Affected platforms: Windows. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-16, CA-7, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1564-hide-artifacts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1564-005-hidden-file-system",
    "title": "MITRE ATT&CK T1564.005: Hidden File System (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1564.005 (Hidden File System) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may use a hidden file system to conceal malicious activity from users and security tools. File systems provide a structure to store and access data from physical storage. Typically, a user engages with a file system through applications that allow them to access files and directories, which are an abstraction from their physical location (ex: disk sector). Standard file systems include FAT, NTFS, ext4, and APFS. Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1564-hide-artifacts"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1564-006-run-virtual-instance",
    "title": "MITRE ATT&CK T1564.006: Run Virtual Instance (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1564.006 (Run Virtual Instance) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may carry out malicious operations using a virtual instance to avoid detection. A wide variety of virtualization technologies exist that allow for the emulation of a computer or computing environment. By running malicious code inside of a virtual instance, adversaries can hide artifacts associated with their behavior from security tools that are unable to monitor activity inside the virtual instance. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-6, CM-7, CM-8, SI-4, SI-7, SI-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1564-hide-artifacts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1564-007-vba-stomping",
    "title": "MITRE ATT&CK T1564.007: VBA Stomping (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1564.007 (VBA Stomping) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may hide malicious Visual Basic for Applications (VBA) payloads embedded within MS Office documents by replacing the VBA source code with benign data. MS Office documents with embedded VBA content store source code inside of module streams. Each module stream has a PerformanceCache that stores a separate compiled version of the VBA source code known as p-code. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-6, CM-8, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1564-hide-artifacts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1564-008-email-hiding-rules",
    "title": "MITRE ATT&CK T1564.008: Email Hiding Rules (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1564.008 (Email Hiding Rules) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may use email rules to hide inbound emails in a compromised user's mailbox. Many email clients allow users to create inbox rules for various email functions, including moving emails to other folders, marking emails as read, or deleting emails. Rules may be created or modified within email clients or through external features such as the New-InboxRule or Set-InboxRule PowerShell cmdlets on Windows systems. Affected platforms: Windows, Linux, macOS, Office Suite. MITRE-documented mitigations include M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CM-3, CM-5, CM-7, SI-3, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1564-hide-artifacts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1564-009-resource-forking",
    "title": "MITRE ATT&CK T1564.009: Resource Forking (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1564.009 (Resource Forking) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications. A resource fork provides applications a structured way to store resources such as thumbnail images, menu definitions, icons, dialog boxes, and code. Usage of a resource fork is identifiable when displaying a file's extended attributes, using ls -l@ or xattr -l commands. Resource forks have been deprecated and replaced with the application bundle structure. Affected platforms: macOS. MITRE-documented mitigations include M1013 Application Developer Guidance. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-6, CM-7, CM-11, SA-10, SC-4, SC-6, SC-44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1564-hide-artifacts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1564-010-process-argument-spoofing",
    "title": "MITRE ATT&CK T1564.010: Process Argument Spoofing (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1564.010 (Process Argument Spoofing) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may attempt to hide process command-line arguments by overwriting process memory. Process command-line arguments are stored in the process environment block (PEB), a data structure used by Windows to store various information about/used by a process. The PEB includes the process command-line arguments that are referenced when executing the process. When a process is created, defensive tools/sensors that monitor process creations may retrieve the process arguments from the PEB. Affected platforms: Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CA-7, SI-4, SI-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1564-hide-artifacts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1564-011-ignore-process-interrupts",
    "title": "MITRE ATT&CK T1564.011: Ignore Process Interrupts (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1564.011 (Ignore Process Interrupts) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may evade defensive mechanisms by executing commands that hide from process interrupt signals. Many operating systems use signals to deliver messages to control process behavior. Command interpreters often include specific commands/flags that ignore errors and other hangups, such as when the user of the active session logs off. These interrupt signals may also be used by defensive tools and/or analysts to pause or terminate specified running processes. Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1564-hide-artifacts"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1564-012-file-path-exclusions",
    "title": "MITRE ATT&CK T1564.012: File/Path Exclusions (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1564.012 (File/Path Exclusions) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may attempt to hide their file-based artifacts by writing them to specific folders or file names excluded from antivirus (AV) scanning and other defensive capabilities. AV and other file-based scanners often include exclusions to optimize performance as well as ease installation and legitimate use of applications. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1049 Antivirus/Antimalware, M1013 Application Developer Guidance. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls SI-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1564-hide-artifacts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1564-013-bind-mounts",
    "title": "MITRE ATT&CK T1564.013: Bind Mounts (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1564.013 (Bind Mounts) is an Enterprise Stealth technique. Adversaries may abuse bind mounts on file structures to hide their activity and artifacts from native utilities. A bind mount maps a directory or file from one location on the filesystem to another, similar to a shortcut on Windows. It’s commonly used to provide access to specific files or directories across different environments, such as inside containers or chroot environments, and requires sudo access. Adversaries may use bind mounts to map either an empty directory or a benign `/proc` directory to a malicious process’s `/proc` directory. Using the commands `mount –o bind /proc/benign-process /proc/malicious-process` (or `mount –B`), the malicious process's `/proc` directory is overlayed with the contents of a benign process's `/proc` directory. When system utilities query process acti... Affected platforms: Linux. Sub-technique of ATT&CK T1564.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "mitre-attack-t1564-014-extended-attributes",
    "title": "MITRE ATT&CK T1564.014: Extended Attributes (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1564.014 (Extended Attributes) is an Enterprise Stealth technique. Adversaries may abuse extended attributes (xattrs) on macOS and Linux to hide their malicious data in order to evade detection. Extended attributes are key-value pairs of file and directory metadata used by both macOS and Linux. They are not visible through standard tools like `Finder`, `ls`, or `cat` and require utilities such as `xattr` (macOS) or `getfattr` (Linux) for inspection. Operating systems and applications use xattrs for tagging, integrity checks, and access control. On Linux, xattrs are organized into namespaces such as `user.` (user permissions), `trusted.` (root permissions), `security.`, and `system.`, each with specific permissions. On macOS, xattrs are flat strings without namespace prefixes, commonly prefixed with `com.apple.*` (e.g., `com.apple.quarantine`, `com.apple.m... Affected platforms: Linux, macOS. Sub-technique of ATT&CK T1564. ATT&CK-mapped mitigations: M1040 Behavior Prevention on Endpoint.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1564-hide-artifacts",
    "title": "MITRE ATT&CK T1564: Hide Artifacts (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1564 (Hide Artifacts) is an Enterprise Defense Evasion technique. Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection. ATT&CK documents 12 sub-techniques: T1564.001 Hidden Files and Directories; T1564.002 Hidden Users; T1564.003 Hidden Window; T1564.004 NTFS File Attributes; T1564.005 Hidden File System; T1564.006 Run Virtual Instance; T1564.007 VBA Stomping; T1564.008 Email Hiding Rules; T1564.009 Resource Forking; T1564.010 Process Argument Spoofing; T1564.011 Ignore Process Interrupts; T1564.012 File/Path Exclusions. Affected platforms: Linux, macOS, Windows, Office Suite. MITRE-documented mitigations include M1033 Limit Software Installation, M1013 Application Developer Guidance, M1049 Antivirus/Antimalware.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1565-001-stored-data-manipulation",
    "title": "MITRE ATT&CK T1565.001: Stored Data Manipulation (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1565.001 (Stored Data Manipulation) is an Enterprise Impact sub-technique of T1565 (Data Manipulation). Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating stored data, adversaries may attempt to affect a business process, organizational understanding, and decision making. Stored data could include a variety of file formats, such as Office files, databases, stored emails, and custom file formats. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1029 Remote Data Storage, M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-18, AC-19, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1565-data-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1565-002-transmitted-data-manipulation",
    "title": "MITRE ATT&CK T1565.002: Transmitted Data Manipulation (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1565.002 (Transmitted Data Manipulation) is an Enterprise Impact sub-technique of T1565 (Data Manipulation). Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity, thus threatening the integrity of the data. By manipulating transmitted data, adversaries may attempt to affect a business process, organizational understanding, and decision making. Manipulation may be possible over a network connection or between system processes where there is an opportunity deploy a tool that will intercept and change information. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-18, AC-19, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1565-data-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1565-003-runtime-data-manipulation",
    "title": "MITRE ATT&CK T1565.003: Runtime Data Manipulation (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1565.003 (Runtime Data Manipulation) is an Enterprise Impact sub-technique of T1565 (Data Manipulation). Adversaries may modify systems in order to manipulate the data as it is accessed and displayed to an end user, thus threatening the integrity of the data. By manipulating runtime data, adversaries may attempt to affect a business process, organizational understanding, and decision making. Adversaries may alter application binaries used to display data in order to cause runtime manipulations. Adversaries may also conduct Change Default File Association and Masquerading to cause a similar effect. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1030 Network Segmentation, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-18, AC-19, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1565-data-manipulation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1565-data-manipulation",
    "title": "MITRE ATT&CK T1565: Data Manipulation (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1565 (Data Manipulation) is an Enterprise Impact technique. Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating data, adversaries may attempt to affect a business process, organizational understanding, or decision making. The type of modification and the impact it will have depends on the target application and process as well as the goals and objectives of the adversary. ATT&CK documents 3 sub-techniques: T1565.001 Stored Data Manipulation; T1565.002 Transmitted Data Manipulation; T1565.003 Runtime Data Manipulation. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1041 Encrypt Sensitive Information, M1029 Remote Data Storage, M1030 Network Segmentation, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-18, AC-19, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1566-001-spearphishing-attachment",
    "title": "MITRE ATT&CK T1566.001: Spearphishing Attachment (Sub-Technique of T1566 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1566.001 covers adversary delivery of malicious files via email attachments to trick users into execution. Office documents with malicious macros, OLE objects, ISO/IMG containers bypassing Mark of the Web, OneNote attachments, and HTML smuggling are the dominant vectors as of 2024-2025. Microsoft Threat Intelligence reports document millions of spearphishing attachment attempts daily. Compliance obligations include NIST SP 800-53 SI-3 (Malicious Code Protection), AT-2 (Literacy Training), ISO 27001 A.8.7, A.6.3, PCI DSS Req 12.6, HIPAA 164.308(a)(5), and CISA Phishing Guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1566-phishing",
      "mitre-attack-t1204-user-execution",
      "mitre-attack-t1059-command-and-scripting-interpreter",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1566-002-spearphishing-link",
    "title": "MITRE ATT&CK T1566.002: Spearphishing Link (Sub-Technique of T1566 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1566.002 covers adversary delivery of malicious URLs via email to phish credentials or deliver malware. Modern attackers use look-alike domains, recently-registered domains, URL shorteners, legitimate cloud-hosted phishing pages (Microsoft 365, AWS S3, Cloudflare Workers), and adversary-in-the-middle phishing kits (EvilGinx2, Modlishka, Tycoon 2FA, Mamba 2FA). Compliance: NIST 800-53 SI-3, AT-2, ISO 27001 A.8.7, A.6.3, PCI DSS Req 12.6, HIPAA 164.308(a)(5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1566-phishing",
      "mitre-attack-t1204-user-execution",
      "mitre-attack-t1539-steal-web-session-cookie",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1566-003-spearphishing-via-service",
    "title": "MITRE ATT&CK T1566.003: Spearphishing via Service (Enterprise Tactic TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1566.003 (Spearphishing via Service) is an Enterprise Initial Access sub-technique of T1566 (Phishing). Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1017 User Training, M1018 User Account Management, M1049 Antivirus/Antimalware, M1021 Restrict Web-Based Content, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-4, AC-6, CA-7, CM-2, CM-6, IA-9, RA-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1566-phishing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1566-004-spearphishing-voice",
    "title": "MITRE ATT&CK T1566.004: Spearphishing Voice (Enterprise Tactic TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1566.004 (Spearphishing Voice) is an Enterprise Initial Access sub-technique of T1566 (Phishing). Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that is employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Affected platforms: Linux, macOS, Windows, Identity Provider. MITRE-documented mitigations include M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, IA-9, RA-5, SC-7, SC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1566-phishing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1566-phishing",
    "title": "MITRE ATT&CK T1566: Phishing (Enterprise Tactic TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1566 (Phishing) describes adversary delivery of malicious content via electronic messages (email, instant messenger, SMS) to gain initial access. The technique has four sub-techniques: T1566.001 (Spearphishing Attachment), T1566.002 (Spearphishing Link), T1566.003 (Spearphishing via Service), and T1566.004 (Spearphishing Voice). Phishing accounts for the largest share of initial access vectors in modern breaches per IBM Cost of a Data Breach 2024. Compliance obligations include user awareness training (NIST 800-53 AT-2, ISO A.6.3), email security gateway configuration (NIS2 Article 21), and reporting under GDPR Article 33 and HIPAA Breach Notification Rule when phishing leads to data compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "nist-csf-20-protect-function-pr",
      "eu-nis2-directive-2022-2555-cybersecurity-essential-entities"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1567-001-exfiltration-to-code-repository",
    "title": "MITRE ATT&CK T1567.001: Exfiltration to Code Repository (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1567.001 (Exfiltration to Code Repository) is an Enterprise Exfiltration sub-technique of T1567 (Exfiltration Over Web Service). Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel. Code repositories are often accessible via an API (ex: https://api.github.com). Access to these APIs are often over HTTPS, which gives the adversary an additional level of protection. Exfiltration to a code repository can also provide a significant amount of cover to the adversary if it is a popular service already used by hosts within the network. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1021 Restrict Web-Based Content. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-6, AC-16, AC-20, AC-23, CA-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1567-exfiltration-over-web-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1567-002-exfiltration-to-cloud-storage",
    "title": "MITRE ATT&CK T1567.002: Exfiltration to Cloud Storage (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1567.002 (Exfiltration to Cloud Storage) is an Enterprise Exfiltration sub-technique of T1567 (Exfiltration Over Web Service). Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet. Examples of cloud storage services include Dropbox and Google Docs. Exfiltration to these cloud storage services can provide a significant amount of cover to the adversary if hosts within the network are already communicating with the service. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1021 Restrict Web-Based Content. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-6, AC-16, AC-20, AC-23, CA-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1567-exfiltration-over-web-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1567-003-exfiltration-to-text-storage-sites",
    "title": "MITRE ATT&CK T1567.003: Exfiltration to Text Storage Sites (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1567.003 (Exfiltration to Text Storage Sites) is an Enterprise Exfiltration sub-technique of T1567 (Exfiltration Over Web Service). Adversaries may exfiltrate data to text storage sites instead of their primary command and control channel. Text storage sites, such as pastebin[.]com, are commonly used by developers to share code and other information. Text storage sites are often used to host malicious code for C2 communication (e.g., Stage Capabilities), but adversaries may also use these sites to exfiltrate collected data. Furthermore, paid features and encryption options may allow adversaries to conceal and store data more securely. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1021 Restrict Web-Based Content. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-6, AC-16, AC-17, AC-20, AC-23.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1567-exfiltration-over-web-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1567-004-exfiltration-over-webhook",
    "title": "MITRE ATT&CK T1567.004: Exfiltration Over Webhook (Enterprise Tactic TA0010 - Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1567.004 (Exfiltration Over Webhook) is an Enterprise Exfiltration sub-technique of T1567 (Exfiltration Over Web Service). Adversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel. Webhooks are simple mechanisms for allowing a server to push data over HTTP/S to a client without the need for the client to continuously poll the server. Many public and commercial services, such as Discord, Slack, and webhook.site, support the creation of webhook endpoints that can be used by other services, such as Github, Jira, or Trello. Affected platforms: Windows, macOS, Linux, SaaS, Office Suite. MITRE-documented mitigations include M1057 Data Loss Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-6, AC-16, AC-17, AC-20, AC-23.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1567-exfiltration-over-web-service"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1567-exfiltration-over-web-service",
    "title": "MITRE ATT&CK T1567: Exfiltration Over Web Service (Exfiltration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1567 covers adversary exfiltration of stolen data via legitimate web services (cloud storage, code-sharing sites, paste sites) to blend with normal SaaS use. Sub-techniques: Exfiltration to Code Repository (T1567.001), Exfiltration to Cloud Storage (T1567.002), Exfiltration to Text Storage Sites (T1567.003), Exfiltration over Webhook (T1567.004). The 2023-2024 Cl0p MOVEit campaign used this pattern at scale. Compliance: NIST 800-53 SC-7, AC-4, ISO 27001 A.8.12, A.8.16, GDPR Article 32-33, PCI DSS Req 11.4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1041-exfiltration-over-c2-channel",
      "mitre-attack-t1102-web-service",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "gdpr-article-32-security-of-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1568-001-fast-flux-dns",
    "title": "MITRE ATT&CK T1568.001: Fast Flux DNS (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1568.001 (Fast Flux DNS) is an Enterprise Command and Control sub-technique of T1568 (Dynamic Resolution). Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution. This technique uses a fully qualified domain name, with multiple IP addresses assigned to it which are swapped with high frequency, using a combination of round robin IP addressing and short Time-To-Live (TTL) for a DNS resource record. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, SC-7, SC-20, SC-21, SC-22, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1568-dynamic-resolution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1568-002-domain-generation-algorithms",
    "title": "MITRE ATT&CK T1568.002: Domain Generation Algorithms (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1568.002 (Domain Generation Algorithms) is an Enterprise Command and Control sub-technique of T1568 (Dynamic Resolution). Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than relying on a list of static IP addresses or domains. This has the advantage of making it much harder for defenders to block, track, or take over the command and control channel, as there potentially could be thousands of domains that malware can check for instructions. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention, M1021 Restrict Web-Based Content. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, SC-7, SC-20, SC-21, SC-22, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1568-dynamic-resolution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1568-003-dns-calculation",
    "title": "MITRE ATT&CK T1568.003: DNS Calculation (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1568.003 (DNS Calculation) is an Enterprise Command and Control sub-technique of T1568 (Dynamic Resolution). Adversaries may perform calculations on addresses returned in DNS results to determine which port and IP address to use for command and control, rather than relying on a predetermined port number or the actual returned IP address. A IP and/or port number calculation can be used to bypass egress filtering on a C2 channel. One implementation of DNS Calculation is to take the first three octets of an IP address in a DNS response and use those values to calculate the port for command and control traffic. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, SC-7, SC-20, SC-21, SC-22, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1568-dynamic-resolution"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1568-dynamic-resolution",
    "title": "MITRE ATT&CK T1568: Dynamic Resolution (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1568 (Dynamic Resolution) is an Enterprise Command and Control technique. Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorithm with the infrastructure the adversary uses to receive the malware's communications. These calculations can be used to dynamically adjust parameters such as the domain name, IP address, or port number the malware uses for command and control. ATT&CK documents 3 sub-techniques: T1568.001 Fast Flux DNS; T1568.002 Domain Generation Algorithms; T1568.003 DNS Calculation. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention, M1021 Restrict Web-Based Content. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, SC-7, SC-20, SC-21, SC-22, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1569-001-launchctl",
    "title": "MITRE ATT&CK T1569.001: Launchctl (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1569.001 (Launchctl) is an Enterprise Execution sub-technique of T1569 (System Services). Adversaries may abuse launchctl to execute commands or programs. Launchctl interfaces with launchd, the service management framework for macOS. Launchctl supports taking subcommands on the command-line, interactively, or even redirected from standard input. Adversaries use launchctl to execute commands and programs as Launch Agents or Launch Daemons. Common subcommands include: launchctl load,launchctl unload, and launchctl start. Affected platforms: macOS. MITRE-documented mitigations include M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1569-system-services"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1569-002-service-execution",
    "title": "MITRE ATT&CK T1569.002: Service Execution (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1569.002 (Service Execution) is an Enterprise Execution sub-technique of T1569 (System Services). Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (services.exe) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as sc.exe and Net. PsExec can also be used to execute commands or payloads via a temporary Windows service created through the service control manager API. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1040 Behavior Prevention on Endpoint, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1569-system-services"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1569-003-systemctl",
    "title": "MITRE ATT&CK T1569.003: Systemctl (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1569.003 (Systemctl) is an Enterprise Execution technique. Adversaries may abuse systemctl to execute commands or programs. Systemctl is the primary interface for systemd, the Linux init system and service manager. Typically invoked from a shell, Systemctl can also be integrated into scripts or applications. Adversaries may use systemctl to execute commands or programs as Systemd Services. Common subcommands include: `systemctl start`, `systemctl stop`, `systemctl enable`, `systemctl disable`, and `systemctl status`. Affected platforms: Linux. Sub-technique of ATT&CK T1569. ATT&CK-mapped mitigations: M1018 User Account Management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1569-system-services",
    "title": "MITRE ATT&CK T1569: System Services (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1569 (System Services) is an Enterprise Execution technique. Adversaries may abuse system services or daemons to execute commands or programs. Adversaries can execute malicious content by interacting with or creating services either locally or remotely. Many services are set to run at boot, which can aid in achieving persistence (Create or Modify System Process), but adversaries can also abuse services for one-time or temporary execution. ATT&CK documents 2 sub-techniques: T1569.001 Launchctl; T1569.002 Service Execution. Affected platforms: Windows, macOS, Linux. MITRE-documented mitigations include M1026 Privileged Account Management, M1018 User Account Management, M1040 Behavior Prevention on Endpoint, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1570-lateral-tool-transfer",
    "title": "MITRE ATT&CK T1570: Lateral Tool Transfer (Enterprise Tactic TA0008 - Lateral Movement)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1570 describes adversary transfer of tools or files between systems in a compromised environment to enable continued post-exploitation. Common methods include SMB/admin shares, RDP file transfer, WMI, BITS, certutil downloads, and PowerShell remoting. Detection of unusual binary transfers across internal hosts is one of the highest-fidelity indicators of active intrusion. Compliance obligations include east-west traffic inspection (NIST 800-53 SC-7), endpoint application allowlisting (CIS Controls v8 Control 2), and behavioural detection of staging activities under NIS2 Article 21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1021-remote-services",
      "cis-controls-v8"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1571-non-standard-port",
    "title": "MITRE ATT&CK T1571: Non-Standard Port (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1571 (Non-Standard Port) is an Enterprise Command and Control technique. Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088 or port 587 as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data. Adversaries may also make changes to victim systems to abuse non-standard ports. For example, Registry keys and other configuration settings can be used to modify protocol and port pairings. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1030 Network Segmentation, M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SI-3, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1572-protocol-tunneling",
    "title": "MITRE ATT&CK T1572: Protocol Tunneling (Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1572 covers adversary tunneling of one protocol inside another to evade network controls. SSH tunneling for SOCKS proxy, HTTP/HTTPS tunneling for arbitrary TCP, DNS tunneling (iodine, dns2tcp, dnscat2), ICMP tunneling, and WireGuard abuse are the dominant patterns. Compliance: NIST 800-53 SC-7, SI-4, AC-17, ISO 27001 A.8.20, A.6.7, NIS2 Article 21(2)(b), PCI DSS Req 11.4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1071-application-layer-protocol",
      "mitre-attack-t1090-proxy",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1573-001-symmetric-cryptography",
    "title": "MITRE ATT&CK T1573.001: Symmetric Cryptography (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1573.001 (Symmetric Cryptography) is an Enterprise Command and Control sub-technique of T1573 (Encrypted Channel). Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4. Affected platforms: Linux, Windows, macOS, Network. MITRE-documented mitigations include M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-12, SC-16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1573-encrypted-channel"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1573-002-asymmetric-cryptography",
    "title": "MITRE ATT&CK T1573.002: Asymmetric Cryptography (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1573.002 (Asymmetric Cryptography) is an Enterprise Command and Control sub-technique of T1573 (Encrypted Channel). Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Asymmetric cryptography, also known as public key cryptography, uses a keypair per party: one public that can be freely distributed, and one private. Due to how the keys are generated, the sender encrypts data with the receiver's public key and the receiver decrypts the data with their private key. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1031 Network Intrusion Prevention, M1020 SSL/TLS Inspection. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-12, SC-16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1573-encrypted-channel"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1573-encrypted-channel",
    "title": "MITRE ATT&CK T1573: Encrypted Channel (Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1573 covers adversary use of symmetric or asymmetric encryption for command-and-control communication to evade network inspection. Sub-techniques: Symmetric Cryptography (T1573.001), Asymmetric Cryptography (T1573.002). TLS-wrapped C2 dominates in 2024-2025 with use of Lets Encrypt, Cloudflare Workers, and free hosting providers. Compliance: NIST 800-53 SC-7, SI-4, ISO 27001 A.8.20, A.8.16, NIS2 Article 21(2)(b), PCI DSS Req 11.4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1071-application-layer-protocol",
      "mitre-attack-t1041-exfiltration-over-c2-channel",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1574-001-dll-search-order-hijacking",
    "title": "MITRE ATT&CK T1574.001: DLL Search Order Hijacking (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1574.001 (DLL Search Order Hijacking) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the search order used to load DLLs. Windows systems use a common method to look for required DLLs to load into a program. Hijacking DLL loads may be for the purpose of establishing persistence as well as elevating privileges and/or evading restrictions on file execution. There are many ways an adversary can hijack DLL loads. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1044 Restrict Library Loading, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1574-hijack-execution-flow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1574-004-dylib-hijacking",
    "title": "MITRE ATT&CK T1574.004: Dylib Hijacking (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1574.004 (Dylib Hijacking) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own payloads by placing a malicious dynamic library (dylib) with an expected name in a path a victim application searches at runtime. The dynamic loader will try to find the dylibs based on the sequential order of the search paths. Paths to dylibs may be prefixed with @rpath, which allows developers to use relative paths to specify an array of search paths used at runtime based on the location of the executable. Affected platforms: macOS. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1574-hijack-execution-flow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1574-005-executable-installer-file-permissions-weakness",
    "title": "MITRE ATT&CK T1574.005: Executable Installer File Permissions Weakness (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1574.005 (Executable Installer File Permissions Weakness) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the binaries used by an installer. These processes may automatically execute specific binaries as part of their functionality or to perform other actions. If the permissions on the file system directory containing a target binary, or permissions on the binary itself, are improperly set, then the target binary may be overwritten with another binary using user-level permissions and executed by the original process. Affected platforms: Windows. MITRE-documented mitigations include M1047 Audit, M1052 User Account Control, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1574-hijack-execution-flow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1574-006-dynamic-linker-hijacking",
    "title": "MITRE ATT&CK T1574.006: Dynamic Linker Hijacking (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1574.006 (Dynamic Linker Hijacking) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries. During the execution preparation phase of a program, the dynamic linker loads specified absolute paths of shared libraries from environment variables and files, such as LD_PRELOAD on Linux or DYLD_INSERT_LIBRARIES on macOS. Libraries specified in environment variables are loaded first, taking precedence over system libraries with the same function name. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1028 Operating System Configuration, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1574-hijack-execution-flow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1574-007-path-interception-by-path-environment-variable",
    "title": "MITRE ATT&CK T1574.007: Path Interception by PATH Environment Variable (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1574.007 (Path Interception by PATH Environment Variable) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries. The PATH environment variable contains a list of directories (User and System) that the OS searches sequentially through in search of the binary that was called from a script or the command line. Affected platforms: Windows, macOS, Linux. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1038 Execution Prevention, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1574-hijack-execution-flow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1574-008-path-interception-by-search-order-hijacking",
    "title": "MITRE ATT&CK T1574.008: Path Interception by Search Order Hijacking (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1574.008 (Path Interception by Search Order Hijacking) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs. Because some programs do not call other programs using the full path, adversaries may place their own file in the directory where the calling program is located, causing the operating system to launch their malicious software at the request of the calling program. Search order hijacking occurs when an adversary abuses the order in which Windows searches for programs that are not given a path. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1022 Restrict File and Directory Permissions, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1574-hijack-execution-flow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1574-009-path-interception-by-unquoted-path",
    "title": "MITRE ATT&CK T1574.009: Path Interception by Unquoted Path (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1574.009 (Path Interception by Unquoted Path) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking vulnerable file path references. Adversaries can take advantage of paths that lack surrounding quotations by placing an executable in a higher level directory within the path, so that Windows will choose the adversary's executable to launch. Service paths and shortcut paths may also be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks (e.g., C:\\unsafe path with space\\program.exe vs. Affected platforms: Windows. MITRE-documented mitigations include M1047 Audit, M1038 Execution Prevention, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1574-hijack-execution-flow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1574-010-services-file-permissions-weakness",
    "title": "MITRE ATT&CK T1574.010: Services File Permissions Weakness (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1574.010 (Services File Permissions Weakness) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the binaries used by services. Adversaries may use flaws in the permissions of Windows services to replace the binary that is executed upon service start. These service processes may automatically execute specific binaries as part of their functionality or to perform other actions. Affected platforms: Windows. MITRE-documented mitigations include M1018 User Account Management, M1047 Audit, M1052 User Account Control. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1574-hijack-execution-flow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1574-011-services-registry-permissions-weakness",
    "title": "MITRE ATT&CK T1574.011: Services Registry Permissions Weakness (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1574.011 (Services Registry Permissions Weakness) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for Registry keys related to services to redirect from the originally specified executable to one that they control, in order to launch their own code when a service starts. Windows stores local service configuration information in the Registry under HKLM\\SYSTEM\\CurrentControlSet\\Services. Affected platforms: Windows. MITRE-documented mitigations include M1024 Restrict Registry Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1574-hijack-execution-flow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1574-012-cor-profiler",
    "title": "MITRE ATT&CK T1574.012: COR_PROFILER (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1574.012 (COR_PROFILER) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may leverage the COR_PROFILER environment variable to hijack the execution flow of programs that load the .NET CLR. The COR_PROFILER is a .NET Framework feature which allows developers to specify an unmanaged (or external of .NET) profiling DLL to be loaded into each .NET process that loads the Common Language Runtime (CLR). These profilers are designed to monitor, troubleshoot, and debug managed code executed by the .NET CLR. Affected platforms: Windows. MITRE-documented mitigations include M1024 Restrict Registry Permissions, M1038 Execution Prevention, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1574-hijack-execution-flow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1574-013-kernelcallbacktable",
    "title": "MITRE ATT&CK T1574.013: KernelCallbackTable (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1574.013 (KernelCallbackTable) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may abuse the KernelCallbackTable of a process to hijack its execution flow in order to run their own payloads. The KernelCallbackTable can be found in the Process Environment Block (PEB) and is initialized to an array of graphic functions available to a GUI process once user32.dll is loaded. An adversary may hijack the execution flow of a process using the KernelCallbackTable by replacing an original callback function with a malicious payload. Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1574-hijack-execution-flow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1574-014-appdomainmanager",
    "title": "MITRE ATT&CK T1574.014: AppDomainManager (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation / TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1574.014 (AppDomainManager) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking how the .NET AppDomainManager loads assemblies. The .NET framework uses the AppDomainManager class to create and manage one or more isolated runtime environments (called application domains) inside a process to host the execution of .NET applications. Assemblies (.exe or .dll binaries compiled to run as .NET code) may be loaded into an application domain as executable code. Affected platforms: Windows. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1574-hijack-execution-flow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1574-hijack-execution-flow",
    "title": "MITRE ATT&CK T1574: Hijack Execution Flow (Persistence + Privilege Escalation + Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE ATT&CK T1574 covers adversary hijacking of legitimate program execution flow to load malicious code. Sub-techniques include DLL Side-Loading (T1574.002), DLL Search Order Hijacking (T1574.001), DYLIB Hijacking (T1574.004), Executable Path Hijacking (T1574.007), Path Interception (T1574.008/009), COR_PROFILER (T1574.012). APT groups (APT41, Lazarus, ToddyCat) and commercial spyware (Pegasus) routinely use DLL side-loading. Compliance: NIST 800-53 SI-7, CM-7, ISO 27001 A.8.7, A.8.32, A.8.19, PCI DSS Req 6.4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1027-obfuscated-files-information",
      "mitre-attack-t1218-system-binary-proxy-execution",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1578-001-create-snapshot",
    "title": "MITRE ATT&CK T1578.001: Create Snapshot (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1578.001 (Create Snapshot) is an Enterprise Defense Evasion sub-technique of T1578 (Modify Cloud Compute Infrastructure). An adversary may create a snapshot or data backup within a cloud account to evade defenses. A snapshot is a point-in-time copy of an existing cloud compute component such as a virtual machine (VM), virtual hard drive, or volume. An adversary may leverage permissions to create a snapshot in order to bypass restrictions that prevent access to existing compute service infrastructure, unlike in Revert Cloud Instance where an adversary may revert to a snapshot to evade detection and remove evidence of their presence. Affected platforms: IaaS. MITRE-documented mitigations include M1047 Audit, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-5, IA-2, IA-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1578-modify-cloud-compute-infrastructure"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1578-002-create-cloud-instance",
    "title": "MITRE ATT&CK T1578.002: Create Cloud Instance (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1578.002 (Create Cloud Instance) is an Enterprise Defense Evasion sub-technique of T1578 (Modify Cloud Compute Infrastructure). An adversary may create a new instance or virtual machine (VM) within the compute service of a cloud account to evade defenses. Creating a new instance may allow an adversary to bypass firewall rules and permissions that exist on instances currently residing within an account. An adversary may Create Snapshot of one or more volumes in an account, create a new instance, mount the snapshots, and then apply a less restrictive security policy to collect Data from Local System or for Remote Data Staging. Affected platforms: IaaS. MITRE-documented mitigations include M1047 Audit, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-5, IA-2, IA-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1578-modify-cloud-compute-infrastructure"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1578-003-delete-cloud-instance",
    "title": "MITRE ATT&CK T1578.003: Delete Cloud Instance (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1578.003 (Delete Cloud Instance) is an Enterprise Defense Evasion sub-technique of T1578 (Modify Cloud Compute Infrastructure). An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence. Deleting an instance or virtual machine can remove valuable forensic artifacts and other evidence of suspicious behavior if the instance is not recoverable. An adversary may also Create Cloud Instance and later terminate the instance after achieving their objectives. Affected platforms: IaaS. MITRE-documented mitigations include M1018 User Account Management, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-5, IA-2, IA-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1578-modify-cloud-compute-infrastructure"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1578-004-revert-cloud-instance",
    "title": "MITRE ATT&CK T1578.004: Revert Cloud Instance (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1578.004 (Revert Cloud Instance) is an Enterprise Defense Evasion sub-technique of T1578 (Modify Cloud Compute Infrastructure). An adversary may revert changes made to a cloud instance after they have performed malicious activities in attempt to evade detection and remove evidence of their presence. In highly virtualized environments, such as cloud-based infrastructure, this may be accomplished by restoring virtual machine (VM) or data storage snapshots through the cloud management dashboard or cloud APIs. Another variation of this technique is to utilize temporary storage attached to the compute instance. Affected platforms: IaaS. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-5, IA-2, IA-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1578-modify-cloud-compute-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1578-005-modify-cloud-compute-configurations",
    "title": "MITRE ATT&CK T1578.005: Modify Cloud Compute Configurations (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1578.005 (Modify Cloud Compute Configurations) is an Enterprise Defense Evasion sub-technique of T1578 (Modify Cloud Compute Infrastructure). Adversaries may modify settings that directly affect the size, locations, and resources available to cloud compute infrastructure in order to evade defenses. These settings may include service quotas, subscription associations, tenant-wide policies, or other configurations that impact available compute. Affected platforms: IaaS. MITRE-documented mitigations include M1018 User Account Management, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-20, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1578-modify-cloud-compute-infrastructure"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1578-modify-cloud-compute-infrastructure",
    "title": "MITRE ATT&CK T1578: Modify Cloud Compute Infrastructure (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1578 (Modify Cloud Compute Infrastructure) is an Enterprise Defense Evasion technique. An adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses. A modification to the compute service infrastructure can include the creation, deletion, or modification of one or more components such as compute instances, virtual machines, and snapshots. Permissions gained from the modification of infrastructure components may bypass restrictions that prevent access to existing infrastructure. ATT&CK documents 5 sub-techniques: T1578.001 Create Snapshot; T1578.002 Create Cloud Instance; T1578.003 Delete Cloud Instance; T1578.004 Revert Cloud Instance; T1578.005 Modify Cloud Compute Configurations. Affected platforms: IaaS. MITRE-documented mitigations include M1018 User Account Management, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-5, IA-2, IA-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1580-cloud-infrastructure-discovery",
    "title": "MITRE ATT&CK T1580: Cloud Infrastructure Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1580 (Cloud Infrastructure Discovery) is an Enterprise Discovery technique. An adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment. This includes compute service resources such as instances, virtual machines, and snapshots as well as resources of other services including the storage and database services. Cloud providers offer methods such as APIs and commands issued through CLIs to serve information about infrastructure. Affected platforms: IaaS. MITRE-documented mitigations include M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, IA-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1583-001-domains",
    "title": "MITRE ATT&CK T1583.001: Domains (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1583.001 (Domains) is an Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free. Adversaries may use acquired domains for a variety of purposes, including for Phishing, Drive-by Compromise, and Command and Control. Adversaries may choose domains that are similar to legitimate domains, including through use of homoglyphs or use of a different top-level domain (TLD). Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1583-acquire-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1583-002-dns-server",
    "title": "MITRE ATT&CK T1583.002: DNS Server (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1583.002 (DNS Server) is an Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may set up their own Domain Name System (DNS) servers that can be used during targeting. During post-compromise activity, adversaries may utilize DNS traffic for various tasks, including for Command and Control (ex: Application Layer Protocol). Instead of hijacking existing DNS servers, adversaries may opt to configure and run their own DNS servers in support of operations. By running their own DNS servers, adversaries can have more control over how they administer server-side DNS C2 traffic (DNS). Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1583-acquire-infrastructure"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1583-003-virtual-private-server",
    "title": "MITRE ATT&CK T1583.003: Virtual Private Server (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1583.003 (Virtual Private Server) is an Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service providers that will sell virtual machines/containers as a service. By utilizing a VPS, adversaries can make it difficult to physically tie back operations to them. The use of cloud infrastructure can also make it easier for adversaries to rapidly provision, modify, and shut down their infrastructure. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1583-acquire-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1583-004-server",
    "title": "MITRE ATT&CK T1583.004: Server (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1583.004 (Server) is an Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may buy, lease, rent, or obtain physical servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, such as watering hole operations in Drive-by Compromise, enabling Phishing operations, or facilitating Command and Control. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1583-acquire-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1583-005-botnet",
    "title": "MITRE ATT&CK T1583.005: Botnet (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1583.005 (Botnet) is an Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may buy, lease, or rent a network of compromised systems that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks. Adversaries may purchase a subscription to use an existing botnet from a booter/stresser service. With a botnet at their disposal, adversaries may perform follow-on activity such as large-scale Phishing or Distributed Denial of Service (DDoS). Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1583-acquire-infrastructure"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1583-006-web-services",
    "title": "MITRE ATT&CK T1583.006: Web Services (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1583.006 (Web Services) is an Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web-based service that can be abused during later stages of the adversary lifecycle, such as during Command and Control (Web Service), Exfiltration Over Web Service, or Phishing. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1583-acquire-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1583-007-serverless",
    "title": "MITRE ATT&CK T1583.007: Serverless (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1583.007 (Serverless) is an Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may purchase and configure serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be used during targeting. By utilizing serverless infrastructure, adversaries can make it more difficult to attribute infrastructure used during operations back to them. Once acquired, the serverless runtime environment can be leveraged to either respond directly to infected machines or to Proxy traffic to an adversary-owned command and control server. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1583-acquire-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1583-008-malvertising",
    "title": "MITRE ATT&CK T1583.008: Malvertising (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1583.008 (Malvertising) is an Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may purchase online advertisements that can be abused to distribute malware to victims. Ads can be purchased to plant as well as favorably position artifacts in specific locations online, such as prominently placed within search engine results. These ads may make it more difficult for users to distinguish between actual search results and advertisements. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1583-acquire-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1583-acquire-infrastructure",
    "title": "MITRE ATT&CK T1583: Acquire Infrastructure (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1583 covers adversary acquisition of infrastructure to support operations: domain registration, server hosting, virtual private servers, DNS services, web services, and serverless platforms. Sub-techniques include Domains (T1583.001), DNS Server (T1583.002), Virtual Private Server (T1583.003), Server (T1583.004), Botnet (T1583.005), Web Services (T1583.006), Serverless (T1583.007), and Malvertising (T1583.008). Bullet-proof hosting providers and abuse of legitimate cloud platforms are the dominant patterns in 2024-2025. Defender obligations include infrastructure threat intelligence and rapid takedown capability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1071-application-layer-protocol",
      "mitre-attack-t1566-phishing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1584-001-domains",
    "title": "MITRE ATT&CK T1584.001: Domains (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1584.001 (Domains) is an Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may hijack domains and/or subdomains that can be used during targeting. Domain registration hijacking is the act of changing the registration of a domain name without the permission of the original registrant. Adversaries may gain access to an email account for the person listed as the owner of the domain. The adversary can then claim that they forgot their password in order to make changes to the domain registration. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1584-compromise-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1584-002-dns-server",
    "title": "MITRE ATT&CK T1584.002: DNS Server (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1584.002 (DNS Server) is an Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise third-party DNS servers that can be used during targeting. During post-compromise activity, adversaries may utilize DNS traffic for various tasks, including for Command and Control (ex: Application Layer Protocol). Instead of setting up their own DNS servers, adversaries may compromise third-party DNS servers in support of operations. By compromising DNS servers, adversaries can alter DNS records. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1584-compromise-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1584-003-virtual-private-server",
    "title": "MITRE ATT&CK T1584.003: Virtual Private Server (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1584.003 (Virtual Private Server) is an Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise third-party Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service providers that will sell virtual machines/containers as a service. Adversaries may compromise VPSs purchased by third-party entities. By compromising a VPS to use as infrastructure, adversaries can make it difficult to physically tie back operations to themselves. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1584-compromise-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1584-004-server",
    "title": "MITRE ATT&CK T1584.004: Server (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1584.004 (Server) is an Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control. Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1584-compromise-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1584-005-botnet",
    "title": "MITRE ATT&CK T1584.005: Botnet (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1584.005 (Botnet) is an Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks. Instead of purchasing/renting a botnet from a booter/stresser service, adversaries may build their own botnet by compromising numerous third-party systems. Adversaries may also conduct a takeover of an existing botnet, such as redirecting bots to adversary-controlled C2 servers. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1584-compromise-infrastructure"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1584-006-web-services",
    "title": "MITRE ATT&CK T1584.006: Web Services (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1584.006 (Web Services) is an Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise access to third-party web services that can be used during targeting. A variety of popular websites exist for legitimate users to register for web-based services, such as GitHub, Twitter, Dropbox, Google, SendGrid, etc. Adversaries may try to take ownership of a legitimate user's access to a web service and use that web service as infrastructure in support of cyber operations. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1584-compromise-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1584-007-serverless",
    "title": "MITRE ATT&CK T1584.007: Serverless (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1584.007 (Serverless) is an Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be used during targeting. By utilizing serverless infrastructure, adversaries can make it more difficult to attribute infrastructure used during operations back to them. Once compromised, the serverless runtime environment can be leveraged to either respond directly to infected machines or to Proxy traffic to an adversary-owned command and control server. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1584-compromise-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1584-008-network-devices",
    "title": "MITRE ATT&CK T1584.008: Network Devices (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1584.008 (Network Devices) is an Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as small office/home office (SOHO) routers, may be compromised where the adversary's ultimate goal is not Initial Access to that environment -- instead leveraging these devices to support additional targeting. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1584-compromise-infrastructure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1584-compromise-infrastructure",
    "title": "MITRE ATT&CK T1584: Compromise Infrastructure (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1584 (Compromise Infrastructure) is an Enterprise Resource Development technique. Adversaries may compromise third-party infrastructure that can be used during targeting. Infrastructure solutions include physical or cloud servers, domains, network devices, and third-party web and DNS services. Instead of buying, leasing, or renting infrastructure an adversary may compromise infrastructure and use it during other phases of the adversary lifecycle. Additionally, adversaries may compromise numerous machines to form a botnet they can leverage. ATT&CK documents 8 sub-techniques: T1584.001 Domains; T1584.002 DNS Server; T1584.003 Virtual Private Server; T1584.004 Server; T1584.005 Botnet; T1584.006 Web Services; T1584.007 Serverless; T1584.008 Network Devices. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1585-001-social-media-accounts",
    "title": "MITRE ATT&CK T1585.001: Social Media Accounts (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1585.001 (Social Media Accounts) is an Enterprise Resource Development sub-technique of T1585 (Establish Accounts). Adversaries may create and cultivate social media accounts that can be used during targeting. Adversaries can create social media accounts that can be used to build a persona to further operations. Persona development consists of the development of public information, presence, history and appropriate affiliations. For operations incorporating social engineering, the utilization of a persona on social media may be important. These personas may be fictitious or impersonate real people. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1585-establish-accounts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1585-002-email-accounts",
    "title": "MITRE ATT&CK T1585.002: Email Accounts (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1585.002 (Email Accounts) is an Enterprise Resource Development sub-technique of T1585 (Establish Accounts). Adversaries may create email accounts that can be used during targeting. Adversaries can use accounts created with email providers to further their operations, such as leveraging them to conduct Phishing for Information or Phishing. Establishing email accounts may also allow adversaries to abuse free services - such as trial periods - to Acquire Infrastructure for follow-on purposes. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1585-establish-accounts"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1585-003-cloud-accounts",
    "title": "MITRE ATT&CK T1585.003: Cloud Accounts (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1585.003 (Cloud Accounts) is an Enterprise Resource Development sub-technique of T1585 (Establish Accounts). Adversaries may create accounts with cloud providers that can be used during targeting. Adversaries can use cloud accounts to further their operations, including leveraging cloud storage services such as Dropbox, MEGA, Microsoft OneDrive, or AWS S3 buckets for Exfiltration to Cloud Storage or to Upload Tools. Cloud accounts can also be used in the acquisition of infrastructure, such as Virtual Private Servers or Serverless infrastructure. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1585-establish-accounts"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1585-establish-accounts",
    "title": "MITRE ATT&CK T1585: Establish Accounts (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1585 (Establish Accounts) is an Enterprise Resource Development technique. Adversaries may create and cultivate accounts with services that can be used during targeting. Adversaries can create accounts that can be used to build a persona to further operations. Persona development consists of the development of public information, presence, history and appropriate affiliations. ATT&CK documents 3 sub-techniques: T1585.001 Social Media Accounts; T1585.002 Email Accounts; T1585.003 Cloud Accounts. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1586-001-social-media-accounts",
    "title": "MITRE ATT&CK T1586.001: Social Media Accounts (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1586.001 (Social Media Accounts) is an Enterprise Resource Development sub-technique of T1586 (Compromise Accounts). Adversaries may compromise social media accounts that can be used during targeting. For operations incorporating social engineering, the utilization of an online persona may be important. Rather than creating and cultivating social media profiles (i.e. Social Media Accounts), adversaries may compromise existing social media accounts. Utilizing an existing persona may engender a level of trust in a potential victim if they have a relationship, or knowledge of, the compromised persona. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1586-compromise-accounts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1586-002-email-accounts",
    "title": "MITRE ATT&CK T1586.002: Email Accounts (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1586.002 (Email Accounts) is an Enterprise Resource Development sub-technique of T1586 (Compromise Accounts). Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct Phishing for Information, Phishing, or large-scale spam email campaigns. Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1586-compromise-accounts"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1586-003-cloud-accounts",
    "title": "MITRE ATT&CK T1586.003: Cloud Accounts (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1586.003 (Cloud Accounts) is an Enterprise Resource Development sub-technique of T1586 (Compromise Accounts). Adversaries may compromise cloud accounts that can be used during targeting. Adversaries can use compromised cloud accounts to further their operations, including leveraging cloud storage services such as Dropbox, Microsoft OneDrive, or AWS S3 buckets for Exfiltration to Cloud Storage or to Upload Tools. Cloud accounts can also be used in the acquisition of infrastructure, such as Virtual Private Servers or Serverless infrastructure. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1586-compromise-accounts"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1586-compromise-accounts",
    "title": "MITRE ATT&CK T1586: Compromise Accounts (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1586 (Compromise Accounts) is an Enterprise Resource Development technique. Adversaries may compromise accounts with services that can be used during targeting. For operations incorporating social engineering, the utilization of an online persona may be important. Rather than creating and cultivating accounts (i.e. Establish Accounts), adversaries may compromise existing accounts. Utilizing an existing persona may engender a level of trust in a potential victim if they have a relationship, or knowledge of, the compromised persona. ATT&CK documents 3 sub-techniques: T1586.001 Social Media Accounts; T1586.002 Email Accounts; T1586.003 Cloud Accounts. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1587-001-malware",
    "title": "MITRE ATT&CK T1587.001: Malware (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1587.001 (Malware) is an Enterprise Resource Development sub-technique of T1587 (Develop Capabilities). Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1587-develop-capabilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1587-002-code-signing-certificates",
    "title": "MITRE ATT&CK T1587.002: Code Signing Certificates (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1587.002 (Code Signing Certificates) is an Enterprise Resource Development sub-technique of T1587 (Develop Capabilities). Adversaries may create self-signed code signing certificates that can be used during targeting. Code signing is the process of digitally signing executables and scripts to confirm the software author and guarantee that the code has not been altered or corrupted. Code signing provides a level of authenticity for a program from the developer and a guarantee that the program has not been tampered with. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1587-develop-capabilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1587-003-digital-certificates",
    "title": "MITRE ATT&CK T1587.003: Digital Certificates (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1587.003 (Digital Certificates) is an Enterprise Resource Development sub-technique of T1587 (Develop Capabilities). Adversaries may create self-signed SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are designed to instill trust. They include information about the key, information about its owner's identity, and the digital signature of an entity that has verified the certificate's contents are correct. If the signature is valid, and the person examining the certificate trusts the signer, then they know they can use that key to communicate with its owner. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1587-develop-capabilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1587-004-exploits",
    "title": "MITRE ATT&CK T1587.004: Exploits (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1587.004 (Exploits) is an Enterprise Resource Development sub-technique of T1587 (Develop Capabilities). Adversaries may develop exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than finding/modifying exploits from online or purchasing them from exploit vendors, an adversary may develop their own exploits. Adversaries may use information acquired via Vulnerabilities to focus exploit development efforts. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1587-develop-capabilities"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1587-develop-capabilities",
    "title": "MITRE ATT&CK T1587: Develop Capabilities (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1587 (Develop Capabilities) is an Enterprise Resource Development technique. Adversaries may build capabilities that can be used during targeting. Rather than purchasing, freely downloading, or stealing capabilities, adversaries may develop their own capabilities in-house. This is the process of identifying development requirements and building solutions such as malware, exploits, and self-signed certificates. Adversaries may develop capabilities to support their operations throughout numerous phases of the adversary lifecycle. ATT&CK documents 4 sub-techniques: T1587.001 Malware; T1587.002 Code Signing Certificates; T1587.003 Digital Certificates; T1587.004 Exploits. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1588-001-malware",
    "title": "MITRE ATT&CK T1588.001: Malware (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1588.001 (Malware) is an Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, packers, and C2 protocols. Adversaries may acquire malware to support their operations, obtaining a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors. In addition to downloading free malware from the internet, adversaries may purchase these capabilities from third-party entities. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1588-obtain-capabilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1588-002-tool",
    "title": "MITRE ATT&CK T1588.002: Tool (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1588.002 (Tool) is an Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: PsExec). Tool acquisition can involve the procurement of commercial software licenses, including for red teaming tools such as Cobalt Strike. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1588-obtain-capabilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1588-003-code-signing-certificates",
    "title": "MITRE ATT&CK T1588.003: Code Signing Certificates (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1588.003 (Code Signing Certificates) is an Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may buy and/or steal code signing certificates that can be used during targeting. Code signing is the process of digitally signing executables and scripts to confirm the software author and guarantee that the code has not been altered or corrupted. Code signing provides a level of authenticity for a program from the developer and a guarantee that the program has not been tampered with. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1588-obtain-capabilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1588-004-digital-certificates",
    "title": "MITRE ATT&CK T1588.004: Digital Certificates (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1588.004 (Digital Certificates) is an Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may buy and/or steal SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are designed to instill trust. They include information about the key, information about its owner's identity, and the digital signature of an entity that has verified the certificate's contents are correct. If the signature is valid, and the person examining the certificate trusts the signer, then they know they can use that key to communicate with its owner. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1588-obtain-capabilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1588-005-exploits",
    "title": "MITRE ATT&CK T1588.005: Exploits (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1588.005 (Exploits) is an Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may buy, steal, or download exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than developing their own exploits, an adversary may find/modify exploits from online or purchase them from exploit vendors. In addition to downloading free exploits from the internet, adversaries may purchase exploits from third-party entities. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1588-obtain-capabilities"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1588-006-vulnerabilities",
    "title": "MITRE ATT&CK T1588.006: Vulnerabilities (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1588.006 (Vulnerabilities) is an Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may acquire information about vulnerabilities that can be used during targeting. A vulnerability is a weakness in computer hardware or software that can, potentially, be exploited by an adversary to cause unintended or unanticipated behavior to occur. Adversaries may find vulnerability information by searching open databases or gaining access to closed vulnerability databases. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1588-obtain-capabilities"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1588-007-artificial-intelligence",
    "title": "MITRE ATT&CK T1588.007: Artificial Intelligence (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1588.007 (Artificial Intelligence) is an Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during targeting. These tools may be used to inform, bolster, and enable a variety of malicious tasks including conducting Reconnaissance, creating basic scripts, assisting social engineering, and even developing payloads. For example, by utilizing a publicly available LLM an adversary is essentially outsourcing or automating certain tasks to the tool. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1588-obtain-capabilities"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1588-obtain-capabilities",
    "title": "MITRE ATT&CK T1588: Obtain Capabilities (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1588 (Obtain Capabilities) is an Enterprise Resource Development technique. Adversaries may buy and/or steal capabilities that can be used during targeting. Rather than developing their own capabilities in-house, adversaries may purchase, freely download, or steal them. Activities may include the acquisition of malware, software (including licenses), exploits, certificates, and information relating to vulnerabilities. Adversaries may obtain capabilities to support their operations throughout numerous phases of the adversary lifecycle. ATT&CK documents 7 sub-techniques: T1588.001 Malware; T1588.002 Tool; T1588.003 Code Signing Certificates; T1588.004 Digital Certificates; T1588.005 Exploits; T1588.006 Vulnerabilities; T1588.007 Artificial Intelligence. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1589-001-credentials",
    "title": "MITRE ATT&CK T1589.001: Credentials (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1589.001 (Credentials) is an Enterprise Reconnaissance sub-technique of T1589 (Gather Victim Identity Information). Adversaries may gather credentials that can be used during targeting. Account credentials gathered by adversaries may be those directly associated with the target victim organization or attempt to take advantage of the tendency for users to use the same passwords across personal and business accounts. Adversaries may gather credentials from potential victims in various ways, such as direct elicitation via Phishing for Information. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1589-gather-victim-identity-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1589-002-email-addresses",
    "title": "MITRE ATT&CK T1589.002: Email Addresses (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1589.002 (Email Addresses) is an Enterprise Reconnaissance sub-technique of T1589 (Gather Victim Identity Information). Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email infrastructure and addresses for employees. Adversaries may easily gather email addresses, since they may be readily available and exposed via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Email addresses could also be enumerated via more active means (i.e. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1589-gather-victim-identity-information"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1589-003-employee-names",
    "title": "MITRE ATT&CK T1589.003: Employee Names (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1589.003 (Employee Names) is an Enterprise Reconnaissance sub-technique of T1589 (Gather Victim Identity Information). Adversaries may gather employee names that can be used during targeting. Employee names be used to derive email addresses as well as to help guide other reconnaissance efforts and/or craft more-believable lures. Adversaries may easily gather employee names, since they may be readily available and exposed via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1589-gather-victim-identity-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1589-gather-victim-identity-information",
    "title": "MITRE ATT&CK T1589: Gather Victim Identity Information (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1589 covers adversary collection of identity information about a target organisation - employee names, email addresses, credentials in breach corpora, executive identifiers - to enable phishing, social engineering, and credential-stuffing campaigns. Sub-techniques include Credentials (T1589.001), Email Addresses (T1589.002), and Employee Names (T1589.003). LinkedIn, breach corpora (SpyCloud, Have I Been Pwned), and public DNS/WHOIS are the dominant data sources. Compliance obligations include data minimisation under GDPR Article 5, NIST SP 800-53 SI-12, ISO 27001 A.8.12, A.5.34, and NIS2 Article 21(2)(j).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "mitre-attack-t1566-phishing",
      "mitre-attack-t1110-brute-force",
      "gdpr-article-32-security-of-processing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1590-001-domain-properties",
    "title": "MITRE ATT&CK T1590.001: Domain Properties (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1590.001 (Domain Properties) is an Enterprise Reconnaissance sub-technique of T1590 (Gather Victim Network Information). Adversaries may gather information about the victim's network domain(s) that can be used during targeting. Information about domains and their properties may include a variety of details, including what domain(s) the victim owns as well as administrative data (ex: name, registrar, etc.) and more directly actionable information such as contacts (email addresses and phone numbers), business addresses, and name servers. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1590-gather-victim-network-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1590-002-dns",
    "title": "MITRE ATT&CK T1590.002: DNS (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1590.002 (DNS) is an Enterprise Reconnaissance sub-technique of T1590 (Gather Victim Network Information). Adversaries may gather information about the victim's DNS that can be used during targeting. DNS information may include a variety of details, including registered name servers as well as records that outline addressing for a target's subdomains, mail servers, and other hosts. DNS MX, TXT, and SPF records may also reveal the use of third party cloud and SaaS providers, such as Office 365, G Suite, Salesforce, or Zendesk. Affected platforms: PRE. MITRE-documented mitigations include M1054 Software Configuration, M1056 Pre-compromise. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CM-6, CM-7, SC-7, SC-32.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1590-gather-victim-network-information"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1590-003-network-trust-dependencies",
    "title": "MITRE ATT&CK T1590.003: Network Trust Dependencies (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1590.003 (Network Trust Dependencies) is an Enterprise Reconnaissance sub-technique of T1590 (Gather Victim Network Information). Adversaries may gather information about the victim's network trust dependencies that can be used during targeting. Information about network trusts may include a variety of details, including second or third-party organizations/domains (ex: managed service providers, contractors, etc.) that have connected (and potentially elevated) network access. Adversaries may gather this information in various ways, such as direct elicitation via Phishing for Information. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1590-gather-victim-network-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1590-004-network-topology",
    "title": "MITRE ATT&CK T1590.004: Network Topology (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1590.004 (Network Topology) is an Enterprise Reconnaissance sub-technique of T1590 (Gather Victim Network Information). Adversaries may gather information about the victim's network topology that can be used during targeting. Information about network topologies may include a variety of details, including the physical and/or logical arrangement of both external-facing and internal network environments. This information may also include specifics regarding network devices (gateways, routers, etc.) and other infrastructure. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1590-gather-victim-network-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1590-005-ip-addresses",
    "title": "MITRE ATT&CK T1590.005: IP Addresses (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1590.005 (IP Addresses) is an Enterprise Reconnaissance sub-technique of T1590 (Gather Victim Network Information). Adversaries may gather the victim's IP addresses that can be used during targeting. Public IP addresses may be allocated to organizations by block, or a range of sequential addresses. Information about assigned IP addresses may include a variety of details, such as which IP addresses are in use. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1590-gather-victim-network-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1590-006-network-security-appliances",
    "title": "MITRE ATT&CK T1590.006: Network Security Appliances (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1590.006 (Network Security Appliances) is an Enterprise Reconnaissance sub-technique of T1590 (Gather Victim Network Information). Adversaries may gather information about the victim's network security appliances that can be used during targeting. Information about network security appliances may include a variety of details, such as the existence and specifics of deployed firewalls, content filters, and proxies/bastion hosts. Adversaries may also target information about victim network-based intrusion detection systems (NIDS) or other appliances related to defensive cybersecurity operations. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1590-gather-victim-network-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1590-gather-victim-network-information",
    "title": "MITRE ATT&CK T1590: Gather Victim Network Information (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1590 (Gather Victim Network Information) is an Enterprise Reconnaissance technique. Adversaries may gather information about the victim's networks that can be used during targeting. Information about networks may include a variety of details, including administrative data (ex: IP ranges, domain names, etc.) as well as specifics regarding its topology and operations. Adversaries may gather this information in various ways, such as direct collection actions via Active Scanning or Phishing for Information. ATT&CK documents 6 sub-techniques: T1590.001 Domain Properties; T1590.002 DNS; T1590.003 Network Trust Dependencies; T1590.004 Network Topology; T1590.005 IP Addresses; T1590.006 Network Security Appliances. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1591-001-determine-physical-locations",
    "title": "MITRE ATT&CK T1591.001: Determine Physical Locations (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1591.001 (Determine Physical Locations) is an Enterprise Reconnaissance sub-technique of T1591 (Gather Victim Org Information). Adversaries may gather the victim's physical location(s) that can be used during targeting. Information about physical locations of a target organization may include a variety of details, including where key resources and infrastructure are housed. Physical locations may also indicate what legal jurisdiction and/or authorities the victim operates within. Adversaries may gather this information in various ways, such as direct elicitation via Phishing for Information. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1591-gather-victim-org-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1591-002-business-relationships",
    "title": "MITRE ATT&CK T1591.002: Business Relationships (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1591.002 (Business Relationships) is an Enterprise Reconnaissance sub-technique of T1591 (Gather Victim Org Information). Adversaries may gather information about the victim's business relationships that can be used during targeting. Information about an organization's business relationships may include a variety of details, including second or third-party organizations/domains (ex: managed service providers, contractors, etc.) that have connected (and potentially elevated) network access. This information may also reveal supply chains and shipment paths for the victim's hardware and software resources. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1591-gather-victim-org-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1591-003-identify-business-tempo",
    "title": "MITRE ATT&CK T1591.003: Identify Business Tempo (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1591.003 (Identify Business Tempo) is an Enterprise Reconnaissance sub-technique of T1591 (Gather Victim Org Information). Adversaries may gather information about the victim's business tempo that can be used during targeting. Information about an organization's business tempo may include a variety of details, including operational hours/days of the week. This information may also reveal times/dates of purchases and shipments of the victim's hardware and software resources. Adversaries may gather this information in various ways, such as direct elicitation via Phishing for Information. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1591-gather-victim-org-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1591-004-identify-roles",
    "title": "MITRE ATT&CK T1591.004: Identify Roles (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1591.004 (Identify Roles) is an Enterprise Reconnaissance sub-technique of T1591 (Gather Victim Org Information). Adversaries may gather information about identities and roles within the victim organization that can be used during targeting. Information about business roles may reveal a variety of targetable details, including identifiable information for key personnel as well as what data/resources they have access to. Adversaries may gather this information in various ways, such as direct elicitation via Phishing for Information. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1591-gather-victim-org-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1591-gather-victim-org-information",
    "title": "MITRE ATT&CK T1591: Gather Victim Org Information (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1591 (Gather Victim Org Information) is an Enterprise Reconnaissance technique. Adversaries may gather information about the victim's organization that can be used during targeting. Information about an organization may include a variety of details, including the names of divisions/departments, specifics of business operations, as well as the roles and responsibilities of key employees. Adversaries may gather this information in various ways, such as direct elicitation via Phishing for Information. ATT&CK documents 4 sub-techniques: T1591.001 Determine Physical Locations; T1591.002 Business Relationships; T1591.003 Identify Business Tempo; T1591.004 Identify Roles. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1592-001-hardware",
    "title": "MITRE ATT&CK T1592.001: Hardware (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1592.001 (Hardware) is an Enterprise Reconnaissance sub-technique of T1592 (Gather Victim Host Information). Adversaries may gather information about the victim's host hardware that can be used during targeting. Information about hardware infrastructure may include a variety of details such as types and versions on specific hosts, as well as the presence of additional components that might be indicative of added defensive protections (ex: card/biometric readers, dedicated encryption hardware, etc.). Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1592-gather-victim-host-information"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1592-002-software",
    "title": "MITRE ATT&CK T1592.002: Software (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1592.002 (Software) is an Enterprise Reconnaissance sub-technique of T1592 (Gather Victim Host Information). Adversaries may gather information about the victim's host software that can be used during targeting. Information about installed software may include a variety of details such as types and versions on specific hosts, as well as the presence of additional components that might be indicative of added defensive protections (ex: antivirus, SIEMs, etc.). Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1592-gather-victim-host-information"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1592-003-firmware",
    "title": "MITRE ATT&CK T1592.003: Firmware (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1592.003 (Firmware) is an Enterprise Reconnaissance sub-technique of T1592 (Gather Victim Host Information). Adversaries may gather information about the victim's host firmware that can be used during targeting. Information about host firmware may include a variety of details such as type and versions on specific hosts, which may be used to infer more information about hosts in the environment (ex: configuration, purpose, age/patch level, etc.). Adversaries may gather this information in various ways, such as direct elicitation via Phishing for Information. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1592-gather-victim-host-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1592-004-client-configurations",
    "title": "MITRE ATT&CK T1592.004: Client Configurations (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1592.004 (Client Configurations) is an Enterprise Reconnaissance sub-technique of T1592 (Gather Victim Host Information). Adversaries may gather information about the victim's client configurations that can be used during targeting. Information about client configurations may include a variety of details and settings, including operating system/version, virtualization, architecture (ex: 32 or 64 bit), language, and/or time zone. Adversaries may gather this information in various ways, such as direct collection actions via Active Scanning (ex: listening ports, server banners, user agent strings) or Phishing for Information. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1592-gather-victim-host-information"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1592-gather-victim-host-information",
    "title": "MITRE ATT&CK T1592: Gather Victim Host Information (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1592 (Gather Victim Host Information) is an Enterprise Reconnaissance technique. Adversaries may gather information about the victim's hosts that can be used during targeting. Information about hosts may include a variety of details, including administrative data (ex: name, assigned IP, functionality, etc.) as well as specifics regarding its configuration (ex: operating system, language, etc.). Adversaries may gather this information in various ways, such as direct collection actions via Active Scanning or Phishing for Information. ATT&CK documents 4 sub-techniques: T1592.001 Hardware; T1592.002 Software; T1592.003 Firmware; T1592.004 Client Configurations. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1593-001-social-media",
    "title": "MITRE ATT&CK T1593.001: Social Media (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1593.001 (Social Media) is an Enterprise Reconnaissance sub-technique of T1593 (Search Open Websites/Domains). Adversaries may search social media for information about victims that can be used during targeting. Social media sites may contain various information about a victim organization, such as business announcements as well as information about the roles, locations, and interests of staff. Adversaries may search in different social media sites depending on what information they seek to gather. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1593-search-open-websites-domains"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1593-002-search-engines",
    "title": "MITRE ATT&CK T1593.002: Search Engines (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1593.002 (Search Engines) is an Enterprise Reconnaissance sub-technique of T1593 (Search Open Websites/Domains). Adversaries may use search engines to collect information about victims that can be used during targeting. Search engine services typical crawl online sites to index context and may provide users with specialized syntax to search for specific keywords or specific types of content (i.e. filetypes). Adversaries may craft various search engine queries depending on what information they seek to gather. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1593-search-open-websites-domains"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1593-003-code-repositories",
    "title": "MITRE ATT&CK T1593.003: Code Repositories (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1593.003 (Code Repositories) is an Enterprise Reconnaissance sub-technique of T1593 (Search Open Websites/Domains). Adversaries may search public code repositories for information about victims that can be used during targeting. Victims may store code in repositories on various third-party websites such as GitHub, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git. Adversaries may search various public code repositories for various information about a victim. Affected platforms: PRE. MITRE-documented mitigations include M1013 Application Developer Guidance, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1593-search-open-websites-domains"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1593-search-open-websites-domains",
    "title": "MITRE ATT&CK T1593: Search Open Websites/Domains (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1593 (Search Open Websites/Domains) is an Enterprise Reconnaissance technique. Adversaries may search freely available websites and/or domains for information about victims that can be used during targeting. Information about victims may be available in various online sites, such as social media, new sites, or those hosting information about business operations such as hiring or requested/rewarded contracts. Adversaries may search in different online sites depending on what information they seek to gather. ATT&CK documents 3 sub-techniques: T1593.001 Social Media; T1593.002 Search Engines; T1593.003 Code Repositories. Affected platforms: PRE. MITRE-documented mitigations include M1047 Audit, M1013 Application Developer Guidance, M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1594-search-victim-owned-websites",
    "title": "MITRE ATT&CK T1594: Search Victim-Owned Websites (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1594 (Search Victim-Owned Websites) is an Enterprise Reconnaissance technique. Adversaries may search websites owned by the victim for information that can be used during targeting. Victim-owned websites may contain a variety of details, including names of departments/divisions, physical locations, and data about key employees such as names, roles, and contact info (ex: Email Addresses). These sites may also have details highlighting business operations and relationships. Adversaries may search victim-owned websites to gather actionable information. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1595-001-scanning-ip-blocks",
    "title": "MITRE ATT&CK T1595.001: Scanning IP Blocks (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1595.001 (Scanning IP Blocks) is an Enterprise Reconnaissance sub-technique of T1595 (Active Scanning). Adversaries may scan victim IP blocks to gather information that can be used during targeting. Public IP addresses may be allocated to organizations by block, or a range of sequential addresses. Adversaries may scan IP blocks in order to Gather Victim Network Information, such as which IP addresses are actively in use as well as more detailed information about hosts assigned these addresses. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1595-active-scanning"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1595-002-vulnerability-scanning",
    "title": "MITRE ATT&CK T1595.002: Vulnerability Scanning (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1595.002 (Vulnerability Scanning) is an Enterprise Reconnaissance sub-technique of T1595 (Active Scanning). Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use. These scans may also include more broad attempts to Gather Victim Host Information that can be used to identify more commonly known, exploitable vulnerabilities. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1595-active-scanning"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1595-003-wordlist-scanning",
    "title": "MITRE ATT&CK T1595.003: Wordlist Scanning (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1595.003 (Wordlist Scanning) is an Enterprise Reconnaissance sub-technique of T1595 (Active Scanning). Adversaries may iteratively probe infrastructure using brute-forcing and crawling techniques. While this technique employs similar methods to Brute Force, its goal is the identification of content and infrastructure rather than the discovery of valid credentials. Wordlists used in these scans may contain generic, commonly used names and file extensions or terms specific to a particular software. Affected platforms: PRE. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1056 Pre-compromise. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls SC-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1595-active-scanning"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1595-active-scanning",
    "title": "MITRE ATT&CK T1595: Active Scanning (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE ATT&CK T1595 covers adversary active scanning of target infrastructure to identify services, vulnerabilities, and entry points before attack. Sub-techniques include Scanning IP Blocks (T1595.001), Vulnerability Scanning (T1595.002), and Wordlist Scanning (T1595.003). Mass scanning of public-facing assets is constant; CISA documented ~4,000 vulnerability scans per public IP per day as of 2024. Compliance obligations span NIST SP 800-53 SC-7, SI-4, RA-5 (Vulnerability Monitoring), ISO 27001 A.8.8 (Management of technical vulnerabilities), NIS2 Article 21(2)(e), and PCI DSS Req 11.3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "mitre-attack-t1190-exploit-public-facing-application",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1596-001-dns-passive-dns",
    "title": "MITRE ATT&CK T1596.001: DNS/Passive DNS (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1596.001 (DNS/Passive DNS) is an Enterprise Reconnaissance sub-technique of T1596 (Search Open Technical Databases). Adversaries may search DNS data for information about victims that can be used during targeting. DNS information may include a variety of details, including registered name servers as well as records that outline addressing for a target's subdomains, mail servers, and other hosts. Adversaries may search DNS data to gather actionable information. Threat actors can query nameservers for a target organization directly, or search through centralized repositories of logged DNS query responses (known as passive DNS). Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1596-search-open-technical-databases"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1596-002-whois",
    "title": "MITRE ATT&CK T1596.002: WHOIS (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1596.002 (WHOIS) is an Enterprise Reconnaissance sub-technique of T1596 (Search Open Technical Databases). Adversaries may search public WHOIS data for information about victims that can be used during targeting. WHOIS data is stored by regional Internet registries (RIR) responsible for allocating and assigning Internet resources such as domain names. Anyone can query WHOIS servers for information about a registered domain, such as assigned IP blocks, contact information, and DNS nameservers. Adversaries may search WHOIS data to gather actionable information. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1596-search-open-technical-databases"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1596-003-digital-certificates",
    "title": "MITRE ATT&CK T1596.003: Digital Certificates (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1596.003 (Digital Certificates) is an Enterprise Reconnaissance sub-technique of T1596 (Search Open Technical Databases). Adversaries may search public digital certificate data for information about victims that can be used during targeting. Digital certificates are issued by a certificate authority (CA) in order to cryptographically verify the origin of signed content. These certificates, such as those used for encrypted web traffic (HTTPS SSL/TLS communications), contain information about the registered organization such as name and location. Adversaries may search digital certificate data to gather actionable information. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1596-search-open-technical-databases"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1596-004-cdns",
    "title": "MITRE ATT&CK T1596.004: CDNs (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1596.004 (CDNs) is an Enterprise Reconnaissance sub-technique of T1596 (Search Open Technical Databases). Adversaries may search content delivery network (CDN) data about victims that can be used during targeting. CDNs allow an organization to host content from a distributed, load balanced array of servers. CDNs may also allow organizations to customize content delivery based on the requestor's geographical region. Adversaries may search CDN data to gather actionable information. Threat actors can use online resources and lookup tools to harvest information about content servers within a CDN. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1596-search-open-technical-databases"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1596-005-scan-databases",
    "title": "MITRE ATT&CK T1596.005: Scan Databases (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1596.005 (Scan Databases) is an Enterprise Reconnaissance sub-technique of T1596 (Search Open Technical Databases). Adversaries may search within public scan databases for information about victims that can be used during targeting. Various online services continuously publish the results of Internet scans/surveys, often harvesting information such as active IP addresses, hostnames, open ports, certificates, and even server banners. Adversaries may search scan databases to gather actionable information. Threat actors can use online resources and lookup tools to harvest information from these services. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1596-search-open-technical-databases"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1596-search-open-technical-databases",
    "title": "MITRE ATT&CK T1596: Search Open Technical Databases (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1596 (Search Open Technical Databases) is an Enterprise Reconnaissance technique. Adversaries may search freely available technical databases for information about victims that can be used during targeting. Information about victims may be available in online databases and repositories, such as registrations of domains/certificates as well as public collections of network data/artifacts gathered from traffic and/or scans. Adversaries may search in different open databases depending on what information they seek to gather. ATT&CK documents 5 sub-techniques: T1596.001 DNS/Passive DNS; T1596.002 WHOIS; T1596.003 Digital Certificates; T1596.004 CDNs; T1596.005 Scan Databases. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1597-001-threat-intel-vendors",
    "title": "MITRE ATT&CK T1597.001: Threat Intel Vendors (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1597.001 (Threat Intel Vendors) is an Enterprise Reconnaissance sub-technique of T1597 (Search Closed Sources). Adversaries may search private data from threat intelligence vendors for information that can be used during targeting. Threat intelligence vendors may offer paid feeds or portals that offer more data than what is publicly reported. Although sensitive details (such as customer names and other identifiers) may be redacted, this information may contain trends regarding breaches such as target industries, attribution claims, and successful TTPs/countermeasures. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1597-search-closed-sources"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1597-002-purchase-technical-data",
    "title": "MITRE ATT&CK T1597.002: Purchase Technical Data (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1597.002 (Purchase Technical Data) is an Enterprise Reconnaissance sub-technique of T1597 (Search Closed Sources). Adversaries may purchase technical information about victims that can be used during targeting. Information about victims may be available for purchase within reputable private sources and databases, such as paid subscriptions to feeds of scan databases or other data aggregation services. Adversaries may also purchase information from less-reputable sources such as dark web or cybercrime blackmarkets. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1597-search-closed-sources"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1597-search-closed-sources",
    "title": "MITRE ATT&CK T1597: Search Closed Sources (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1597 (Search Closed Sources) is an Enterprise Reconnaissance technique. Adversaries may search and gather information about victims from closed (e.g., paid, private, or otherwise not freely available) sources that can be used during targeting. Information about victims may be available for purchase from reputable private sources and databases, such as paid subscriptions to feeds of technical/threat intelligence data. Adversaries may also purchase information from less-reputable sources such as dark web or cybercrime blackmarkets. ATT&CK documents 2 sub-techniques: T1597.001 Threat Intel Vendors; T1597.002 Purchase Technical Data. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1598-001-spearphishing-service",
    "title": "MITRE ATT&CK T1598.001: Spearphishing Service (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1598.001 (Spearphishing Service) is an Enterprise Reconnaissance sub-technique of T1598 (Phishing for Information). Adversaries may send spearphishing messages via third-party services to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Affected platforms: PRE. MITRE-documented mitigations include M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, IA-9, SC-7, SC-20, SC-44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1598-phishing-for-information"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1598-002-spearphishing-attachment",
    "title": "MITRE ATT&CK T1598.002: Spearphishing Attachment (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1598.002 (Spearphishing Attachment) is an Enterprise Reconnaissance sub-technique of T1598 (Phishing for Information). Adversaries may send spearphishing messages with a malicious attachment to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Affected platforms: PRE. MITRE-documented mitigations include M1017 User Training, M1054 Software Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, IA-9, SC-7, SC-20, SC-44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1598-phishing-for-information"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1598-003-spearphishing-link",
    "title": "MITRE ATT&CK T1598.003: Spearphishing Link (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1598.003 (Spearphishing Link) is an Enterprise Reconnaissance sub-technique of T1598 (Phishing for Information). Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Affected platforms: PRE. MITRE-documented mitigations include M1017 User Training, M1054 Software Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, IA-9, SC-7, SC-20, SC-44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1598-phishing-for-information"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1598-004-spearphishing-voice",
    "title": "MITRE ATT&CK T1598.004: Spearphishing Voice (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1598.004 (Spearphishing Voice) is an Enterprise Reconnaissance sub-technique of T1598 (Phishing for Information). Adversaries may use voice communications to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Spearphishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient. Affected platforms: PRE. MITRE-documented mitigations include M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, IA-9, SC-7, SC-20, SC-44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1598-phishing-for-information"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1598-phishing-for-information",
    "title": "MITRE ATT&CK T1598: Phishing for Information (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1598 (Phishing for Information) is an Enterprise Reconnaissance technique. Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Phishing for information is different from Phishing in that the objective is gathering data from the victim rather than executing malicious code. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. ATT&CK documents 4 sub-techniques: T1598.001 Spearphishing Service; T1598.002 Spearphishing Attachment; T1598.003 Spearphishing Link; T1598.004 Spearphishing Voice. Affected platforms: PRE. MITRE-documented mitigations include M1017 User Training, M1054 Software Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, CA-7, CM-2, CM-6, IA-9, SC-7, SC-20, SC-44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1599-001-network-address-translation-traversal",
    "title": "MITRE ATT&CK T1599.001: Network Address Translation Traversal (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1599.001 (Network Address Translation Traversal) is an Enterprise Defense Evasion sub-technique of T1599 (Network Boundary Bridging). Adversaries may bridge network boundaries by modifying a network device's Network Address Translation (NAT) configuration. Malicious modifications to NAT may enable an adversary to bypass restrictions on traffic routing that otherwise separate trusted and untrusted networks. Network devices such as routers and firewalls that connect multiple networks together may implement NAT during the process of passing packets between networks. Affected platforms: Network. MITRE-documented mitigations include M1027 Password Policies, M1043 Credential Access Protection, M1032 Multi-factor Authentication, M1026 Privileged Account Management, M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1599-network-boundary-bridging"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1599-network-boundary-bridging",
    "title": "MITRE ATT&CK T1599: Network Boundary Bridging (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1599 (Network Boundary Bridging) is an Enterprise Defense Evasion technique. Adversaries may bridge network boundaries by compromising perimeter network devices or internal devices responsible for network segmentation. Breaching these devices may enable an adversary to bypass restrictions on traffic routing that otherwise separate trusted and untrusted networks. Devices such as routers and firewalls can be used to create boundaries between trusted and untrusted networks. ATT&CK documents 1 sub-technique: T1599.001 Network Address Translation Traversal. Affected platforms: Network. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1027 Password Policies, M1026 Privileged Account Management, M1037 Filter Network Traffic, M1043 Credential Access Protection. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1600-001-reduce-key-space",
    "title": "MITRE ATT&CK T1600.001: Reduce Key Space (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1600.001 (Reduce Key Space) is an Enterprise Defense Evasion sub-technique of T1600 (Weaken Encryption). Adversaries may reduce the level of effort required to decrypt data transmitted over the network by reducing the cipher strength of encrypted communications. Adversaries can weaken the encryption software on a compromised network device by reducing the key size used by the software to convert plaintext to ciphertext (e.g., from hundreds or thousands of bytes to just a couple of bytes). As a result, adversaries dramatically reduce the amount of effort needed to decrypt the protected information without the key. Affected platforms: Network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1600-weaken-encryption"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1600-002-disable-crypto-hardware",
    "title": "MITRE ATT&CK T1600.002: Disable Crypto Hardware (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1600.002 (Disable Crypto Hardware) is an Enterprise Defense Evasion sub-technique of T1600 (Weaken Encryption). Adversaries disable a network device's dedicated hardware encryption, which may enable them to leverage weaknesses in software encryption in order to reduce the effort involved in collecting, manipulating, and exfiltrating transmitted data. Many network devices such as routers, switches, and firewalls, perform encryption on network traffic to secure transmission across networks. Affected platforms: Network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1600-weaken-encryption"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1600-weaken-encryption",
    "title": "MITRE ATT&CK T1600: Weaken Encryption (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1600 (Weaken Encryption) is an Enterprise Defense Evasion technique. Adversaries may compromise a network device's encryption capability in order to bypass encryption that would otherwise protect data communications. Encryption can be used to protect transmitted network traffic to maintain its confidentiality (protect against unauthorized disclosure) and integrity (protect against unauthorized changes). Encryption ciphers are used to convert a plaintext message to ciphertext and can be computationally intensive to decipher without the associated decryption key. ATT&CK documents 2 sub-techniques: T1600.001 Reduce Key Space; T1600.002 Disable Crypto Hardware. Affected platforms: Network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1601-001-patch-system-image",
    "title": "MITRE ATT&CK T1601.001: Patch System Image (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1601.001 (Patch System Image) is an Enterprise Defense Evasion sub-technique of T1601 (Modify System Image). Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses. Some network devices are built with a monolithic architecture, where the entire operating system and most of the functionality of the device is contained within a single file. Adversaries may change this file in storage, to be loaded in a future boot, or in memory during runtime. Affected platforms: Network. MITRE-documented mitigations include M1046 Boot Integrity, M1045 Code Signing, M1043 Credential Access Protection, M1026 Privileged Account Management, M1032 Multi-factor Authentication, M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1601-modify-system-image"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1601-002-downgrade-system-image",
    "title": "MITRE ATT&CK T1601.002: Downgrade System Image (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1601.002 (Downgrade System Image) is an Enterprise Defense Evasion sub-technique of T1601 (Modify System Image). Adversaries may install an older version of the operating system of a network device to weaken security. Older operating system versions on network devices often have weaker encryption ciphers and, in general, fewer/less updated defensive features. On embedded devices, downgrading the version typically only requires replacing the operating system file in storage. Affected platforms: Network. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1045 Code Signing, M1043 Credential Access Protection, M1026 Privileged Account Management, M1027 Password Policies, M1046 Boot Integrity. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1601-modify-system-image"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1601-modify-system-image",
    "title": "MITRE ATT&CK T1601: Modify System Image (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1601 (Modify System Image) is an Enterprise Defense Evasion technique. Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves. On such devices, the operating systems are typically monolithic and most of the device functionality and capabilities are contained within a single file. To change the operating system, the adversary typically only needs to affect this one file, replacing or modifying it. ATT&CK documents 2 sub-techniques: T1601.001 Patch System Image; T1601.002 Downgrade System Image. Affected platforms: Network. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1027 Password Policies, M1043 Credential Access Protection, M1045 Code Signing, M1046 Boot Integrity, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1602-001-snmp-mib-dump",
    "title": "MITRE ATT&CK T1602.001: SNMP (MIB Dump) (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1602.001 (SNMP (MIB Dump)) is an Enterprise Collection sub-technique of T1602 (Data from Configuration Repository). Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a network managed using Simple Network Management Protocol (SNMP). The MIB is a configuration repository that stores variable information accessible via SNMP in the form of object identifiers (OID). Each OID identifies a variable that can be read or set and permits active management tasks, such as configuration changes, through remote modification of these variables. Affected platforms: Network. MITRE-documented mitigations include M1054 Software Configuration, M1051 Update Software, M1041 Encrypt Sensitive Information, M1031 Network Intrusion Prevention, M1030 Network Segmentation, M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-18, AC-19, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1602-data-from-configuration-repository"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1602-002-network-device-configuration-dump",
    "title": "MITRE ATT&CK T1602.002: Network Device Configuration Dump (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1602.002 (Network Device Configuration Dump) is an Enterprise Collection sub-technique of T1602 (Data from Configuration Repository). Adversaries may access network configuration files to collect sensitive data about the device and the network. The network configuration is a file containing parameters that determine the operation of the device. The device typically stores an in-memory copy of the configuration while operating, and a separate configuration on non-volatile storage to load after device reset. Affected platforms: Network. MITRE-documented mitigations include M1041 Encrypt Sensitive Information, M1030 Network Segmentation, M1031 Network Intrusion Prevention, M1054 Software Configuration, M1037 Filter Network Traffic, M1051 Update Software. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-18, AC-19, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1602-data-from-configuration-repository"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1602-data-from-configuration-repository",
    "title": "MITRE ATT&CK T1602: Data from Configuration Repository (Enterprise Tactic TA0009 - Collection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1602 (Data from Configuration Repository) is an Enterprise Collection technique. Adversaries may collect data related to managed devices from configuration repositories. Configuration repositories are used by management systems in order to configure, manage, and control data on remote systems. Configuration repositories may also facilitate remote access and administration of devices. Adversaries may target these repositories in order to collect large quantities of sensitive system administration data. ATT&CK documents 2 sub-techniques: T1602.001 SNMP (MIB Dump); T1602.002 Network Device Configuration Dump. Affected platforms: Network. MITRE-documented mitigations include M1051 Update Software, M1054 Software Configuration, M1030 Network Segmentation, M1037 Filter Network Traffic, M1031 Network Intrusion Prevention, M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-18, AC-19, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1606-001-web-cookies",
    "title": "MITRE ATT&CK T1606.001: Web Cookies (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1606.001 (Web Cookies) is an Enterprise Credential Access sub-technique of T1606 (Forge Web Credentials). Adversaries may forge web cookies that can be used to gain access to web applications or Internet services. Web applications and services (hosted in cloud SaaS environments or on-premise servers) often use session cookies to authenticate and authorize user access. Adversaries may generate these cookies in order to gain access to web resources. Affected platforms: Linux, macOS, Windows, SaaS, IaaS. MITRE-documented mitigations include M1047 Audit, M1054 Software Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, IA-13, SC-17, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1606-forge-web-credentials"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1606-002-saml-tokens",
    "title": "MITRE ATT&CK T1606.002: SAML Tokens (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1606.002 (SAML Tokens) is an Enterprise Credential Access sub-technique of T1606 (Forge Web Credentials). An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate. The default lifetime of a SAML token is one hour, but the validity period can be specified in the NotOnOrAfter value of the conditions ... element in a token. This value can be changed using the AccessTokenLifetime in a LifetimeTokenPolicy. Forged SAML tokens enable adversaries to authenticate across services that use SAML 2.0 as an SSO (single sign-on) mechanism. Affected platforms: SaaS, Windows, IaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1015 Active Directory Configuration, M1047 Audit, M1018 User Account Management, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, IA-13, SC-17, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1606-forge-web-credentials"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1606-forge-web-credentials",
    "title": "MITRE ATT&CK T1606: Forge Web Credentials (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1606 (Forge Web Credentials) is an Enterprise Credential Access technique. Adversaries may forge credential materials that can be used to gain access to web applications or Internet services. Web applications and services (hosted in cloud SaaS environments or on-premise servers) often use session cookies, tokens, or other materials to authenticate and authorize user access. Adversaries may generate these credential materials in order to gain access to web resources. ATT&CK documents 2 sub-techniques: T1606.001 Web Cookies; T1606.002 SAML Tokens. Affected platforms: SaaS, Windows, macOS, Linux, IaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1026 Privileged Account Management, M1054 Software Configuration, M1047 Audit, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, IA-13, SC-17, SI-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1608-001-upload-malware",
    "title": "MITRE ATT&CK T1608.001: Upload Malware (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1608.001 (Upload Malware) is an Enterprise Resource Development sub-technique of T1608 (Stage Capabilities). Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, and a variety of other malicious content. Adversaries may upload malware to support their operations, such as making a payload available to a victim network to enable Ingress Tool Transfer by placing it on an Internet accessible web server. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1608-stage-capabilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1608-002-upload-tool",
    "title": "MITRE ATT&CK T1608.002: Upload Tool (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1608.002 (Upload Tool) is an Enterprise Resource Development sub-technique of T1608 (Stage Capabilities). Adversaries may upload tools to third-party or adversary controlled infrastructure to make it accessible during targeting. Tools can be open or closed source, free or commercial. Tools can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: PsExec). Adversaries may upload tools to support their operations, such as making a tool available to a victim network to enable Ingress Tool Transfer by placing it on an Internet accessible web server. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1608-stage-capabilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1608-003-install-digital-certificate",
    "title": "MITRE ATT&CK T1608.003: Install Digital Certificate (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1608.003 (Install Digital Certificate) is an Enterprise Resource Development sub-technique of T1608 (Stage Capabilities). Adversaries may install SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are files that can be installed on servers to enable secure communications between systems. Digital certificates include information about the key, information about its owner's identity, and the digital signature of an entity that has verified the certificate's contents are correct. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1608-stage-capabilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1608-004-drive-by-target",
    "title": "MITRE ATT&CK T1608.004: Drive-by Target (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1608.004 (Drive-by Target) is an Enterprise Resource Development sub-technique of T1608 (Stage Capabilities). Adversaries may prepare an operational environment to infect systems that visit a website over the normal course of browsing. Endpoint systems may be compromised through browsing to adversary controlled sites, as in Drive-by Compromise. In such cases, the user's web browser is typically targeted for exploitation (often not requiring any extra user interaction once landing on the site), but adversaries may also set up websites for non-exploitation behavior such as Application Access Token. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1608-stage-capabilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1608-005-link-target",
    "title": "MITRE ATT&CK T1608.005: Link Target (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1608.005 (Link Target) is an Enterprise Resource Development sub-technique of T1608 (Stage Capabilities). Adversaries may put in place resources that are referenced by a link that can be used during targeting. An adversary may rely upon a user clicking a malicious link in order to divulge information (including credentials) or to gain execution, as in Malicious Link. Links can be used for spearphishing, such as sending an email accompanied by social engineering text to coax the user to actively click or copy and paste a URL into a browser. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1608-stage-capabilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1608-006-seo-poisoning",
    "title": "MITRE ATT&CK T1608.006: SEO Poisoning (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1608.006 (SEO Poisoning) is an Enterprise Resource Development sub-technique of T1608 (Stage Capabilities). Adversaries may poison mechanisms that influence search engine optimization (SEO) to further lure staged capabilities towards potential victims. Search engines typically display results to users based on purchased ads as well as the site's ranking/score/reputation calculated by their web crawlers and algorithms. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1608-stage-capabilities"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1608-stage-capabilities",
    "title": "MITRE ATT&CK T1608: Stage Capabilities (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1608 (Stage Capabilities) is an Enterprise Resource Development technique. Adversaries may upload, install, or otherwise set up capabilities that can be used during targeting. To support their operations, an adversary may need to take capabilities they developed (Develop Capabilities) or obtained (Obtain Capabilities) and stage them on infrastructure under their control. These capabilities may be staged on infrastructure that was previously purchased/rented by the adversary (Acquire Infrastructure) or was otherwise compromised by them (Compromise Infrastructure). ATT&CK documents 6 sub-techniques: T1608.001 Upload Malware; T1608.002 Upload Tool; T1608.003 Install Digital Certificate; T1608.004 Drive-by Target; T1608.005 Link Target; T1608.006 SEO Poisoning. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1609-container-administration-command",
    "title": "MITRE ATT&CK T1609: Container Administration Command (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1609 (Container Administration Command) is an Enterprise Execution technique. Adversaries may abuse a container administration service to execute commands within a container. A container administration service such as the Docker daemon, the Kubernetes API server, or the kubelet may allow remote management of containers within an environment. In Docker, adversaries may specify an entrypoint during container deployment that executes a script or command, or they may use a command such as docker exec to execute a command within a running container. Affected platforms: Containers. MITRE-documented mitigations include M1018 User Account Management, M1026 Privileged Account Management, M1042 Disable or Remove Feature or Program, M1035 Limit Access to Resource Over Network, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-17, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1610-deploy-container",
    "title": "MITRE ATT&CK T1610: Deploy Container (Enterprise Tactic TA0005 - Defense Evasion / TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1610 (Deploy Container) is an Enterprise Defense Evasion and Execution technique. Adversaries may deploy a container into an environment to facilitate execution or evade defenses. In some cases, adversaries may deploy a new container to execute processes associated with a particular image or deployment, such as processes that execute or download malware. In others, an adversary may deploy a new container configured without network rules, user limitations, etc. to bypass existing defenses within the environment. Affected platforms: Containers. MITRE-documented mitigations include M1018 User Account Management, M1047 Audit, M1030 Network Segmentation, M1035 Limit Access to Resource Over Network. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, AC-17, CM-6, CM-7, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1611-escape-to-host",
    "title": "MITRE ATT&CK T1611: Escape to Host (Enterprise Tactic TA0004 - Privilege Escalation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1611 (Escape to Host) is an Enterprise Privilege Escalation technique. Adversaries may break out of a container to gain access to the underlying host. This can allow an adversary access to other containerized resources from the host level or to the host itself. In principle, containerized resources should provide a clear separation of application functionality and be isolated from the host environment. There are multiple ways an adversary may escape to a host environment. Affected platforms: Windows, Linux, Containers. MITRE-documented mitigations include M1038 Execution Prevention, M1048 Application Isolation and Sandboxing, M1026 Privileged Account Management, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1612-build-image-on-host",
    "title": "MITRE ATT&CK T1612: Build Image on Host (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1612 (Build Image on Host) is an Enterprise Defense Evasion technique. Adversaries may build a container image directly on a host to bypass defenses that monitor for the retrieval of malicious images from a public registry. A remote build request may be sent to the Docker API that includes a Dockerfile that pulls a vanilla base image, such as alpine, from a public or local registry and then builds a custom image upon it. Affected platforms: Containers. MITRE-documented mitigations include M1035 Limit Access to Resource Over Network, M1026 Privileged Account Management, M1030 Network Segmentation, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, AC-17, CM-2, CM-6, CM-7, RA-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1613-container-and-resource-discovery",
    "title": "MITRE ATT&CK T1613: Container and Resource Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1613 (Container and Resource Discovery) is an Enterprise Discovery technique. Adversaries may attempt to discover containers and other resources that are available within a containers environment. Other resources may include images, deployments, pods, nodes, and other information such as the status of a cluster. These resources can be viewed within web applications such as the Kubernetes dashboard or can be queried via the Docker and Kubernetes APIs. Affected platforms: Containers. MITRE-documented mitigations include M1030 Network Segmentation, M1035 Limit Access to Resource Over Network, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, AC-17, CM-6, CM-7, IA-2, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1614-001-system-language-discovery",
    "title": "MITRE ATT&CK T1614.001: System Language Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1614.001 (System Language Discovery) is an Enterprise Discovery sub-technique of T1614 (System Location Discovery). Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host. This information may be used to shape follow-on behaviors, including whether the adversary infects the target and/or attempts specific actions. This decision may be employed by malware developers and operators to reduce their risk of attracting the attention of specific law enforcement agencies or prosecution/scrutiny from other entities. Affected platforms: Windows, Linux, macOS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-t1614-system-location-discovery"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1614-system-location-discovery",
    "title": "MITRE ATT&CK T1614: System Location Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1614 (System Location Discovery) is an Enterprise Discovery technique. Adversaries may gather information in an attempt to calculate the geographical location of a victim host. Adversaries may use the information from System Location Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Adversaries may attempt to infer the location of a system using various system checks, such as time zone, keyboard layout, and/or language settings. ATT&CK documents 1 sub-technique: T1614.001 System Language Discovery. Affected platforms: Windows, Linux, macOS, IaaS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1615-group-policy-discovery",
    "title": "MITRE ATT&CK T1615: Group Policy Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1615 (Group Policy Discovery) is an Enterprise Discovery technique. Adversaries may gather information on Group Policy settings to identify paths for privilege escalation, security measures applied within a domain, and to discover patterns in domain objects that can be manipulated or used to blend in the environment. Group Policy allows for centralized management of user and computer settings in Active Directory (AD). Group policy objects (GPOs) are containers for group policy settings made up of files stored within a predictable network path \\<DOMAIN>\\SYSVOL\\<DOMAIN>\\Policies\\. Affected platforms: Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1619-cloud-storage-object-discovery",
    "title": "MITRE ATT&CK T1619: Cloud Storage Object Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1619 (Cloud Storage Object Discovery) is an Enterprise Discovery technique. Adversaries may enumerate objects in cloud storage infrastructure. Adversaries may use this information during automated discovery to shape follow-on behaviors, including requesting all or specific objects from cloud storage. Similar to File and Directory Discovery on a local host, after identifying available storage services (i.e. Cloud Infrastructure Discovery) adversaries may access the contents/objects stored in cloud infrastructure. Affected platforms: IaaS. MITRE-documented mitigations include M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CM-5, IA-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1620-reflective-code-loading",
    "title": "MITRE ATT&CK T1620: Reflective Code Loading (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1620 (Reflective Code Loading) is an Enterprise Defense Evasion technique. Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules). Reflectively loaded payloads may be compiled binaries, anonymous files (only present in RAM), or just snubs of fileless executable code (ex: position-independent shellcode). Affected platforms: macOS, Linux, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1621-multi-factor-authentication-request-generation",
    "title": "MITRE ATT&CK T1621: Multi-Factor Authentication Request Generation (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1621 (Multi-Factor Authentication Request Generation) is an Enterprise Credential Access technique. Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users. Adversaries in possession of credentials to Valid Accounts may be unable to complete the login process if they lack access to the 2FA or MFA mechanisms required as an additional credential and security control. Affected platforms: Windows, Linux, macOS, IaaS, SaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1036 Account Use Policies, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-6, CM-5, IA-2, IA-3, IA-5, IA-13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1622-debugger-evasion",
    "title": "MITRE ATT&CK T1622: Debugger Evasion (Enterprise Tactic TA0005 - Defense Evasion / TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1622 (Debugger Evasion) is an Enterprise Defense Evasion and Discovery technique. Adversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to trace and/or analyze the execution of potential malware payloads. Debugger evasion may include changing behaviors based on the results of the checks for the presence of artifacts indicative of a debugged environment. Similar to Virtualization/Sandbox Evasion, if the adversary detects a debugger, they may alter their malware to disengage from the victim or conceal the core functions of the implant. Affected platforms: Windows, Linux, macOS. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, CM-8, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1647-plist-file-modification",
    "title": "MITRE ATT&CK T1647: Plist File Modification (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1647 (Plist File Modification) is an Enterprise Defense Evasion technique. Adversaries may modify property list files (plist files) to enable other malicious activity, while also potentially evading and bypassing system defenses. macOS applications use plist files, such as the info.plist file, to store properties and configuration settings that inform the operating system how to handle the application at runtime. Plist files are structured metadata in key-value pairs formatted in XML based on Apple's Core Foundation DTD. Plist files can be saved in text or binary format. Affected platforms: macOS. MITRE-documented mitigations include M1013 Application Developer Guidance. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-3, AC-6, AC-16, AC-17, CA-7, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1648-serverless-execution",
    "title": "MITRE ATT&CK T1648: Serverless Execution (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1648 (Serverless Execution) is an Enterprise Execution technique. Adversaries may abuse serverless computing, integration, and automation services to execute arbitrary code in cloud environments. Many cloud providers offer a variety of serverless resources, including compute engines, application integration services, and web servers. Adversaries may abuse these resources in various ways as a means of executing arbitrary commands. For example, adversaries may use serverless functions to execute malicious code, such as crypto-mining malware (i.e. Resource Hijacking). Affected platforms: SaaS, IaaS, Office Suite. MITRE-documented mitigations include M1036 Account Use Policies, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CM-6, CM-7, IA-2, SC-7, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1649-steal-or-forge-authentication-certificates",
    "title": "MITRE ATT&CK T1649: Steal or Forge Authentication Certificates (Enterprise Tactic TA0006 - Credential Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1649 (Steal or Forge Authentication Certificates) is an Enterprise Credential Access technique. Adversaries may steal or forge certificates used for authentication to access remote systems or resources. Digital certificates are often used to sign and encrypt messages and/or files. Certificates are also used as authentication material. For example, Entra ID device certificates and Active Directory Certificate Services (AD CS) certificates bind to an identity and can be used as credentials for domain accounts. Authentication certificates can be both stolen and forged. Affected platforms: Windows, Linux, macOS, Identity Provider. MITRE-documented mitigations include M1015 Active Directory Configuration, M1042 Disable or Remove Feature or Program, M1041 Encrypt Sensitive Information, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls IA-2, IA-5, IA-13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1650-acquire-access",
    "title": "MITRE ATT&CK T1650: Acquire Access (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1650 (Acquire Access) is an Enterprise Resource Development technique. Adversaries may purchase or otherwise acquire an existing access to a target system or network. A variety of online services and initial access broker networks are available to sell access to previously compromised systems. In some cases, adversary groups may form partnerships to share compromised systems with each other. Footholds to compromised systems may take a variety of forms, such as access to planted backdoors (e.g., Web Shell) or established access via External Remote Services. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1651-cloud-administration-command",
    "title": "MITRE ATT&CK T1651: Cloud Administration Command (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1651 (Cloud Administration Command) is an Enterprise Execution technique. Adversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS Systems Manager, Azure RunCommand, and Runbooks allow users to remotely run scripts in virtual machines by leveraging installed virtual machine agents. If an adversary gains administrative access to a cloud environment, they may be able to abuse cloud management services to execute commands in the environment's virtual machines. Affected platforms: IaaS. MITRE-documented mitigations include M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, AC-17, IA-2, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1652-device-driver-discovery",
    "title": "MITRE ATT&CK T1652: Device Driver Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1652 (Device Driver Discovery) is an Enterprise Discovery technique. Adversaries may attempt to enumerate local device drivers on a victim host. Information about device drivers may highlight various insights that shape follow-on behaviors, such as the function/purpose of the host, present security tools (i.e. Security Software Discovery) or other defenses (e.g., Virtualization/Sandbox Evasion), as well as potential exploitable vulnerabilities (e.g., Exploitation for Privilege Escalation). Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1653-power-settings",
    "title": "MITRE ATT&CK T1653: Power Settings (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1653 (Power Settings) is an Enterprise Persistence technique. Adversaries may impair a system's ability to hibernate, reboot, or shut down in order to extend access to infected machines. When a computer enters a dormant state, some or all software and hardware may cease to operate which can disrupt malicious activity. Adversaries may abuse system utilities and configuration settings to maintain access by preventing machines from entering a state, such as standby, that can terminate malicious activity. Affected platforms: Windows, Linux, macOS, Network. MITRE-documented mitigations include M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-2, CM-3, CM-7, SI-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1654-log-enumeration",
    "title": "MITRE ATT&CK T1654: Log Enumeration (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1654 (Log Enumeration) is an Enterprise Discovery technique. Adversaries may enumerate system and service logs to find useful data. These logs may highlight various types of valuable insights for an adversary, such as user authentication records (Account Discovery), security or vulnerable software (Software Discovery), or hosts within a compromised network (Remote System Discovery). Host binaries may be leveraged to collect system logs. Examples include using wevtutil.exe or PowerShell on Windows to access and/or export security event information. Affected platforms: Linux, macOS, Windows, IaaS. MITRE-documented mitigations include M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1657-financial-theft",
    "title": "MITRE ATT&CK T1657: Financial Theft (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1657 (Financial Theft) is an Enterprise Impact technique. Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, \"pig butchering,\" bank hacking, and exploiting cryptocurrency networks. Affected platforms: Linux, macOS, Windows, SaaS, Office Suite. MITRE-documented mitigations include M1017 User Training, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-5, AC-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1659-content-injection",
    "title": "MITRE ATT&CK T1659: Content Injection (Enterprise Tactic TA0001 - Initial Access / TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1659 (Content Injection) is an Enterprise Initial Access and Command and Control technique. Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic. Rather than luring victims to malicious payloads hosted on a compromised website (i.e., Drive-by Target followed by Drive-by Compromise), adversaries may initially access victims through compromised data-transfer channels where they can manipulate traffic and/or inject their own content. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1021 Restrict Web-Based Content, M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-4, AC-17, SC-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1665-hide-infrastructure",
    "title": "MITRE ATT&CK T1665: Hide Infrastructure (Enterprise Tactic TA0011 - Command and Control)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1665 (Hide Infrastructure) is an Enterprise Command and Control technique. Adversaries may manipulate network traffic in order to hide and evade detection of their C2 infrastructure. This can be accomplished in various ways including by identifying and filtering traffic from defensive tools, masking malicious domains to obfuscate the true destination from both automated scanning tools and security researchers, and otherwise hiding malicious artifacts to delay discovery and prolong the effectiveness of adversary infrastructure that could otherwise be identified, blocked, or taken down. Affected platforms: macOS, Windows, Linux, Network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1666-modify-cloud-resource-hierarchy",
    "title": "MITRE ATT&CK T1666: Modify Cloud Resource Hierarchy (Enterprise Tactic TA0005 - Defense Evasion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE ATT&CK T1666 (Modify Cloud Resource Hierarchy) is an Enterprise Defense Evasion technique. Adversaries may attempt to modify hierarchical structures in infrastructure-as-a-service (IaaS) environments in order to evade defenses. IaaS environments often group resources into a hierarchy, enabling improved resource management and application of policies to relevant groups. Hierarchical structures differ among cloud providers. Affected platforms: IaaS. MITRE-documented mitigations include M1054 Software Configuration, M1018 User Account Management, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1667-email-bombing",
    "title": "MITRE ATT&CK T1667: Email Bombing (Enterprise Tactic TA0040 - Impact)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1667 (Email Bombing) is an Enterprise Impact technique. Adversaries may flood targeted email addresses with an overwhelming volume of messages. This may bury legitimate emails in a flood of spam and disrupt business operations. An adversary may accomplish email bombing by leveraging an automated bot to register a targeted address for e-mail lists that do not validate new signups, such as online newsletters. The result can be a wave of thousands of e-mails that effectively overloads the victim’s inbox. By sending hundreds or thousands of e-mails in quick succession, adversaries may successfully divert attention away from and bury legitimate messages including security alerts, daily business processes like help desk tickets and client correspondence, or ongoing scams. This behavior can also be used as a tool of harassment. This behavior may be a ... Affected platforms: Linux, Office Suite, Windows, macOS. ATT&CK-mapped mitigations: M1017 User Training, M1054 Software Configuration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1668-exclusive-control",
    "title": "MITRE ATT&CK T1668: Exclusive Control (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1668 (Exclusive Control) is an Enterprise Persistence technique. Adversaries who successfully compromise a system may attempt to maintain persistence by “closing the door” behind them; in other words, by preventing other threat actors from initially accessing or maintaining a foothold on the same system. For example, adversaries may patch a vulnerable, compromised system to prevent other threat actors from leveraging that vulnerability in the future. They may “close the door” in other ways, such as disabling vulnerable services, stripping privileges from accounts, or removing other malware already on the compromised device. Hindering other threat actors may allow an adversary to maintain sole access to a compromised system or network. This prevents the threat actor from needing to compete with or even being removed themselves by other threat actors. It... Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "mitre-attack-t1669-wi-fi-networks",
    "title": "MITRE ATT&CK T1669: Wi-Fi Networks (Enterprise Tactic TA0001 - Initial Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1669 (Wi-Fi Networks) is an Enterprise Initial Access technique. Adversaries may gain initial access to target systems by connecting to wireless networks. They may accomplish this by exploiting open Wi-Fi networks used by target devices or by accessing secured Wi-Fi networks (requiring Valid Accounts) belonging to a target organization. Establishing a connection to a Wi-Fi access point requires a certain level of proximity to both discover and maintain a stable network connection. Adversaries may establish a wireless connection through various methods, such as by physically positioning themselves near a Wi-Fi network to conduct close access operations. To bypass the need for physical proximity, adversaries may attempt to remotely compromise nearby third-party systems that have both wired and wireless network connections available (i.e., dual-homed sys... Affected platforms: Linux, Network Devices, Windows, macOS. ATT&CK-mapped mitigations: M1032 Multi-factor Authentication, M1030 Network Segmentation, M1041 Encrypt Sensitive Information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1671-cloud-application-integration",
    "title": "MITRE ATT&CK T1671: Cloud Application Integration (Enterprise Tactic TA0003 - Persistence)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1671 (Cloud Application Integration) is an Enterprise Persistence technique. Adversaries may achieve persistence by leveraging OAuth application integrations in a software-as-a-service environment. Adversaries may create a custom application, add a legitimate application into the environment, or even co-opt an existing integration to achieve malicious ends. OAuth is an open standard that allows users to authorize applications to access their information on their behalf. In a SaaS environment such as Microsoft 365 or Google Workspace, users may integrate applications to improve their workflow and achieve tasks. Leveraging application integrations may allow adversaries to persist in an environment – for example, by granting consent to an application from a high-privileged adversary-controlled account in order to maintain access to its data, even in the event of losin... Affected platforms: Office Suite, SaaS. ATT&CK-mapped mitigations: M1042 Disable or Remove Feature or Program, M1047 Audit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1673-virtual-machine-discovery",
    "title": "MITRE ATT&CK T1673: Virtual Machine Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1673 (Virtual Machine Discovery) is an Enterprise Discovery technique. An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor. For example, adversaries may enumerate a list of VMs on an ESXi hypervisor using a Hypervisor CLI such as `esxcli` or `vim-cmd` (e.g. `esxcli vm process list or vim-cmd vmsvc/getallvms`). Adversaries may also directly leverage a graphical user interface, such as VMware vCenter, in order to view virtual machines on a host. Adversaries may use the information from Virtual Machine Discovery during discovery to shape follow-on behaviors. Subsequently discovered VMs may be leveraged for follow-on activities such as Service Stop or Data Encrypted for Impact. Affected platforms: ESXi, Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "mitre-attack-t1674-input-injection",
    "title": "MITRE ATT&CK T1674: Input Injection (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1674 (Input Injection) is an Enterprise Execution technique. Adversaries may simulate keystrokes on a victim’s computer by various means to perform any type of action on behalf of the user, such as launching the command interpreter using keyboard shortcuts, typing an inline script to be executed, or interacting directly with a GUI-based application. These actions can be preprogrammed into adversary tooling or executed through physical devices such as Human Interface Devices (HIDs). For example, adversaries have used tooling that monitors the Windows message loop to detect when a user visits bank-specific URLs. If detected, the tool then simulates keystrokes to open the developer console or select the address bar, pastes malicious JavaScript from the clipboard, and executes it - enabling manipulation of content within the browser, such as replacing b... Affected platforms: Windows, macOS, Linux. ATT&CK-mapped mitigations: M1034 Limit Hardware Installation, M1038 Execution Prevention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1675-esxi-administration-command",
    "title": "MITRE ATT&CK T1675: ESXi Administration Command (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1675 (ESXi Administration Command) is an Enterprise Execution technique. Adversaries may abuse ESXi administration services to execute commands on guest machines hosted within an ESXi virtual environment. Persistent background services on ESXi-hosted VMs, such as the VMware Tools Daemon Service, allow for remote management from the ESXi server. The tools daemon service runs as `vmtoolsd.exe` on Windows guest operating systems, `vmware-tools-daemon` on macOS, and `vmtoolsd ` on Linux. Adversaries may leverage a variety of tools to execute commands on ESXi-hosted VMs – for example, by using the vSphere Web Services SDK to programmatically execute commands and scripts via APIs such as `StartProgramInGuest`, `ListProcessesInGuest`, `ListFileInGuest`, and `InitiateFileTransferFromGuest`. This may enable follow-on behaviors on the guest VMs, such as File and Director... Affected platforms: ESXi. ATT&CK-mapped mitigations: M1018 User Account Management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1677-poisoned-pipeline-execution",
    "title": "MITRE ATT&CK T1677: Poisoned Pipeline Execution (Enterprise Tactic TA0002 - Execution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1677 (Poisoned Pipeline Execution) is an Enterprise Execution technique. Adversaries may manipulate continuous integration / continuous development (CI/CD) processes by injecting malicious code into the build process. There are several mechanisms for poisoning pipelines: * In a <b>Direct Pipeline Execution</b> scenario, the threat actor directly modifies the CI configuration file (e.g., `gitlab-ci.yml` in GitLab). They may include a command to exfiltrate credentials leveraged in the build process to a remote server, or to export them as a workflow artifact. * In an <b>Indirect Pipeline Execution</b> scenario, the threat actor injects malicious code into files referenced by the CI configuration file. These may include makefiles, scripts, unit tests, and linters. * In a <b>Public Pipeline Execution</b> scenario, the threat actor does not have direct access to the... Affected platforms: SaaS. ATT&CK-mapped mitigations: M1018 User Account Management, M1054 Software Configuration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1678-delay-execution",
    "title": "MITRE ATT&CK T1678: Delay Execution (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1678 (Delay Execution) is an Enterprise Stealth technique. Adversaries may employ various time-based methods to evade detection and analysis. These techniques often exploit system clocks, delays, or timing mechanisms to obscure malicious activity, blend in with benign activity, and avoid scrutiny. Adversaries can perform this behavior within virtualization/sandbox environments or natively on host systems. Adversaries may utilize programmatic `sleep` commands or native system scheduling functionality, for example Scheduled Task/Job. Benign commands or other operations may also be used to delay malware execution or ensure prior commands have had time to execute properly. Loops or otherwise needless repetitions of commands, such as `ping`, may be used to delay malware execution and potentially exceed time thresholds of automated analysis environments... Affected platforms: Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "mitre-attack-t1679-selective-exclusion",
    "title": "MITRE ATT&CK T1679: Selective Exclusion (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1679 (Selective Exclusion) is an Enterprise Stealth technique. Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution. Some file extensions that adversaries may avoid encrypting include `.dll`, `.exe`, and `.lnk`. Adversaries may perform this behavior to avoid alerting users, to evade detection by security tools and analysts, or, in the case of ransomware, to ensure that the system remains operational enough to deliver the ransom notice. Exclusions may target files and components whose corruption would cause instability, break core services, or immediately expose the attack. By carefully avoiding these areas, adversaries maintain system responsiveness while minimizing indicators that could trigger alarms or otherwise inh... Affected platforms: Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "mitre-attack-t1680-local-storage-discovery",
    "title": "MITRE ATT&CK T1680: Local Storage Discovery (Enterprise Tactic TA0007 - Discovery)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1680 (Local Storage Discovery) is an Enterprise Discovery technique. Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number. This can be done to prepare for ransomware-related encryption, to perform Lateral Movement, or as a precursor to Direct Volume Access. On ESXi systems, adversaries may use Hypervisor CLI commands such as `esxcli` to list storage connected to the host as well as `.vmdk` files. On Windows systems, adversaries can use `wmic logicaldisk get` to find information about local network drives. They can also use `Get-PSDrive` in PowerShell to retrieve drives and may additionally use Windows API functions such as `GetDriveType`. Linux has commands such as `parted`, `lsblk`, `fdisk`, `lshw`, and `df` that can list information about disk partitions such as size, type, fi... Affected platforms: ESXi, IaaS, Linux, macOS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "mitre-attack-t1681-search-threat-vendor-data",
    "title": "MITRE ATT&CK T1681: Search Threat Vendor Data (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1681 (Search Threat Vendor Data) is an Enterprise Reconnaissance technique. Threat actors may seek information/indicators from closed or open threat intelligence sources gathered about their own campaigns, as well as those conducted by other adversaries that may align with their target industries, capabilities/objectives, or other operational concerns. These reports may include descriptions of behavior, detailed breakdowns of attacks, atomic indicators such as malware hashes or IP addresses, timelines of a group’s activity, and more. Adversaries may change their behavior when planning their future operations. Adversaries have been observed replacing atomic indicators mentioned in blog posts in under a week. Adversaries have also been seen searching for their own domain names in threat vendor data and then taking them down, likely to avoid seizure or further invest... Affected platforms: PRE. ATT&CK-mapped mitigations: M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1682-query-public-ai-services",
    "title": "MITRE ATT&CK T1682: Query Public AI Services (Enterprise Tactic TA0043 - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1682 (Query Public AI Services) is an Enterprise Reconnaissance technique. Adversaries may query publicly accessible artificial intelligence (AI) services, such as large language models (LLMs), to support targeting and operations. In addition to searching websites or databases directly (i.e., Search Open Websites/Domains), adversaries may use AI services to synthesize, aggregate, and analyze publicly available information at scale. This may include identifying individuals or organizations to target, researching organizational structures and personnel, identifying technologies used by target organizations, researching business relationships to develop plausible pretexts for Social Engineering approaches, identifying contact information for use in Phishing or Phishing for Information, or gathering derogatory or sensitive information about individuals that may be us... Affected platforms: PRE. ATT&CK-mapped mitigations: M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1683-001-written-content",
    "title": "MITRE ATT&CK T1683.001: Written Content (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1683.001 (Written Content) is an Enterprise Resource Development technique. Adversaries may create or tailor written materials to support targeting and malicious operations. Content may include phishing lures, fraudulent financial communications, fabricated job postings, fabricated employment credentials and documentation, decoy documents, social media persona content, and supporting narratives used to sustain fabricated personas over time. Content may be authored manually, commissioned through third parties, or produced using AI-assisted tools. Written materials may impersonate legitimate government correspondence, diplomatic communications, or internal organizational documents to support targeting efforts. AI-assisted tools may also be used to tailor content to specific targets, industries, or regions. For example, adversaries may leverage AI to translate conten... Affected platforms: PRE. Sub-technique of ATT&CK T1683. ATT&CK-mapped mitigations: M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1683-002-audio-visual-content",
    "title": "MITRE ATT&CK T1683.002: Audio-Visual Content (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1683.002 (Audio-Visual Content) is an Enterprise Resource Development technique. Adversaries may create or manipulate audio, image, and video content to support targeting and malicious operations. Adversaries may also use synthetic voice recordings, real-time altered audio or video during live interactions, fabricated profile photos and identity documents, or video content depicting fabricated or impersonated individuals. Content may be produced manually through editing tools, generated using AI-assisted tools, or produced using third-party synthetic services. AI-assisted tools have enabled adversaries to produce synthetic media at scale and generate content that is more difficult to identify as inauthentic. Audio-visual content produced through these methods may be used in support of other techniques, such as Phishing, Spearphishing via Service, Phishing for Informati... Affected platforms: PRE. Sub-technique of ATT&CK T1683. ATT&CK-mapped mitigations: M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1683-generate-content",
    "title": "MITRE ATT&CK T1683: Generate Content (Enterprise Tactic TA0042 - Resource Development)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1683 (Generate Content) is an Enterprise Resource Development technique. Adversaries may create or generate content to support targeting and operations. This content may be used to establish personas, impersonate known individuals or organizations, and support Social Engineering, fraud, or influence activities. Written materials, audio, images, video, or other media may be developed and tailored to the target and objective. Content development may occur prior to or during an operation. Adversaries may develop or generate content in-house, source it through third parties, or produce it using AI-assisted tools. Adversaries may use AI to research targets, develop pretexts, and better understand the organizations and individuals they intend to target or deceive prior to generating content (i.e., Query Public AI Services); for obtaining access to AI tools used in co... Affected platforms: PRE. ATT&CK-mapped mitigations: M1056 Pre-compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1684-001-impersonation",
    "title": "MITRE ATT&CK T1684.001: Impersonation (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1684.001 (Impersonation) is an Enterprise Stealth technique. Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims. In many cases of business email compromise or email fraud campaigns, adversaries use impersonation to defraud victims -- deceiving them into sending money or divulging information that ultimately enables Financial Theft. Adversaries will often also use social engineering techniques such as manipulative and persuasive la... Affected platforms: Linux, macOS, Office Suite, SaaS, Windows. Sub-technique of ATT&CK T1684. ATT&CK-mapped mitigations: M1017 User Training, M1019 Threat Intelligence Program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1684-002-email-spoofing",
    "title": "MITRE ATT&CK T1684.002: Email Spoofing (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1684.002 (Email Spoofing) is an Enterprise Stealth technique. Adversaries may fake, or spoof, a sender’s identity by modifying the value of relevant email headers in order to establish contact with victims under false pretenses. In addition to actual email content, email headers (such as the FROM header, which contains the email address of the sender) may also be modified. Email clients display these headers when emails appear in a victim's inbox, which may cause modified emails to appear as if they were from the spoofed entity. Enterprise environments can use Domain-based Message Authentication, Reporting, and Conformance (DMARC) as an email authentication protocol that references results of the Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) configurations. SPF and DKIM are configured separately in DNS: SPF verifies that the sen... Affected platforms: Linux, macOS, Office Suite, Windows. Sub-technique of ATT&CK T1684. ATT&CK-mapped mitigations: M1054 Software Configuration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1684-social-engineering",
    "title": "MITRE ATT&CK T1684: Social Engineering (Enterprise Tactic TA0005 - Stealth)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1684 (Social Engineering) is an Enterprise Stealth technique. Adversaries may use social engineering techniques to influence users to take actions that result in unauthorized access, approval of changes, disclosure of sensitive information, or execution of adversary-supplied instructions (i.e., introduction of malicious payloads or software), while minimizing technical indicators. Adversaries may leverage trust-building methods across multiple channels (e.g., executive, vendor, or help desk scenarios, including AI-enabled voice interactions) to prompt user-authorized actions such as password resets, MFA changes, financial approvals, or the disclosure of sensitive information. Adversaries may also leverage common business communications and workflows such as email, collaboration platforms, voice communications, recruiting processes, help desk interact... Affected platforms: Linux, macOS, Office Suite, SaaS, Windows. ATT&CK-mapped mitigations: M1036 Account Use Policies, M1047 Audit, M1017 User Training.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1685-001-disable-or-modify-windows-event-log",
    "title": "MITRE ATT&CK T1685.001: Disable or Modify Windows Event Log (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1685.001 (Disable or Modify Windows Event Log) is an Enterprise Defense Impairment technique. Adversaries may disable or modify the Windows Event Log to limit data that can be leveraged for detections and audits. Windows Event Log records user and system activity such as login attempts and process creation. This data is used by security tools and analysts to generate detections. The EventLog service maintains event logs from various system components and applications. By default, the service automatically starts when a system powers on. An audit policy, maintained by the Local Security Policy (secpol.msc), defines which system events the EventLog service logs. Security audit policy settings can be changed by running secpol.msc, then navigating to `Security Settings\\Local Policies\\Audit Policy` for basic audit policy settings or `Security Settings\\Advanced Audit Policy Configuration... Affected platforms: Windows. Sub-technique of ATT&CK T1685. ATT&CK-mapped mitigations: M1018 User Account Management, M1047 Audit, M1024 Restrict Registry Permissions, M1022 Restrict File and Directory Permissions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1685-002-disable-or-modify-cloud-log",
    "title": "MITRE ATT&CK T1685.002: Disable or Modify Cloud Log (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1685.002 (Disable or Modify Cloud Log) is an Enterprise Defense Impairment technique. An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within the environment. If an adversary has sufficient permissions, they can disable or modify logging to avoid detection of their activities. For example, in AWS an adversary may disable CloudWatch/CloudTrail integrations prior to conducting further malicious activity. They may alternatively tamper with logging functionality, for example, by removing any associated SNS topics, disabling multi-region logging, or disabling settings that validate and/or encrypt log files. In Office 365, an adversary may disa... Affected platforms: IaaS, SaaS, Identity Provider, Office Suite. Sub-technique of ATT&CK T1685. ATT&CK-mapped mitigations: M1018 User Account Management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1685-003-modify-or-spoof-tool-ui",
    "title": "MITRE ATT&CK T1685.003: Modify or Spoof Tool UI (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1685.003 (Modify or Spoof Tool UI) is an Enterprise Defense Impairment technique. Adversaries may spoof or manipulate security tool user interfaces (UIs) to falsely indicate tools are functioning normally and delay detection and response. Adversaries may present misleading or falsified security tool interfaces (UIs) that display normal or healthy status indicators, even when underlying security tools have been disabled, degraded, or otherwise tampered with. Security tools typically provide visibility into system health, alerting, and operational status; by misrepresenting this information, adversaries can undermine defender trust in these signals and obscure the true security posture of the system. This behavior is often used in conjunction with efforts to disable or modify tools, where adversaries first impair the functionality of defenses (e.g., EDR, logging agents) a... Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1685. ATT&CK-mapped mitigations: M1038 Execution Prevention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-attack-t1685-004-disable-or-modify-linux-audit-system-log",
    "title": "MITRE ATT&CK T1685.004: Disable or Modify Linux Audit System Log (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1685.004 (Disable or Modify Linux Audit System Log) is an Enterprise Defense Impairment technique. Adversaries may disable or modify the Linux Audit system to hide malicious activity and avoid detection. Linux admins use the Linux Audit system to track security-relevant information on a system. The Linux Audit system operates at the kernel-level and maintains event logs on application and system activity such as process, network, file, and login events based on pre-configured rules. Often referred to as `auditd`, this is the name of the daemon used to write events to disk and is governed by the parameters set in the `audit.conf` configuration file. Two primary ways to configure the log generation rules are through the command line `auditctl` utility and the file `/etc/audit/audit.rules`, containing a sequence of `auditctl` commands loaded at boot time. With root privileges, adversaries ... Affected platforms: Linux. Sub-technique of ATT&CK T1685. ATT&CK-mapped mitigations: M1018 User Account Management, M1047 Audit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1685-005-clear-windows-event-logs",
    "title": "MITRE ATT&CK T1685.005: Clear Windows Event Logs (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1685.005 (Clear Windows Event Logs) is an Enterprise Defense Impairment technique. Adversaries may clear Windows Event Logs to hide the activity of an intrusion. Windows Event Logs are a record of a computer's alerts and notifications. There are three system-defined sources of events: System, Application, and Security, with five event types: Error, Warning, Information, Success Audit, and Failure Audit. With administrator privileges, the event logs can be cleared with the following utility commands: * `wevtutil cl system` * `wevtutil cl application` * `wevtutil cl security` These logs may also be cleared through other mechanisms, such as the event viewer GUI or PowerShell. For example, adversaries may use the PowerShell command `Remove-EventLog -LogName Security` to delete the Security EventLog and after reboot, disable future logging. Note: events may still be generated... Affected platforms: Windows. Sub-technique of ATT&CK T1685. ATT&CK-mapped mitigations: M1029 Remote Data Storage, M1041 Encrypt Sensitive Information, M1022 Restrict File and Directory Permissions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1685-006-clear-linux-or-mac-system-logs",
    "title": "MITRE ATT&CK T1685.006: Clear Linux or Mac System Logs (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1685.006 (Clear Linux or Mac System Logs) is an Enterprise Defense Impairment technique. Adversaries may clear system logs to hide evidence of an intrusion. macOS and Linux both keep track of system or user-initiated actions via system logs. The majority of native system logging is stored under the `/var/log/` directory. Subfolders in this directory categorize logs by their related functions, such as: * `/var/log/messages:`: General and system-related messages * `/var/log/secure or /var/log/auth.log`: Authentication logs * `/var/log/utmp or /var/log/wtmp`: Login records * `/var/log/kern.log`: Kernel logs * `/var/log/cron.log`: Crond logs * `/var/log/maillog`: Mail server logs * `/var/log/httpd/`: Web server access and error logs Affected platforms: Linux, macOS. Sub-technique of ATT&CK T1685. ATT&CK-mapped mitigations: M1022 Restrict File and Directory Permissions, M1029 Remote Data Storage, M1041 Encrypt Sensitive Information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1685-disable-or-modify-tools",
    "title": "MITRE ATT&CK T1685: Disable or Modify Tools (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1685 (Disable or Modify Tools) is an Enterprise Defense Impairment technique. Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments. In addition to directly targeting tools, adversaries may block or manipulate indicators and telemetry used for detection. This includes maliciously disabling or redirecting sensors such as Event Tracing fo... Affected platforms: Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows. ATT&CK-mapped mitigations: M1018 User Account Management, M1047 Audit, M1022 Restrict File and Directory Permissions, M1042 Disable or Remove Feature or Program, M1054 Software Configuration, M1038 Execution Prevention, M1024 Restrict Registry Permissions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-attack-t1686-001-cloud-firewall",
    "title": "MITRE ATT&CK T1686.001: Cloud Firewall (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1686.001 (Cloud Firewall) is an Enterprise Defense Impairment technique. Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources. Cloud environments typically utilize restrictive security groups and firewall rules that only allow network activity from trusted IP addresses via expected ports and protocols. An adversary with appropriate permissions may introduce new firewall rules or policies to allow access into a victim cloud environment and/or move laterally from the cloud control plane to the data plane. For example, an adversary may use a script or utility that creates new ingress rules in existing security groups (or creates new security groups entirely) to allow any TCP/IP connectivity to a cloud-hosted instance. They may also remove networking limitations to support traffic associated... Affected platforms: IaaS. Sub-technique of ATT&CK T1686. ATT&CK-mapped mitigations: M1047 Audit, M1018 User Account Management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1686-002-network-device-firewall",
    "title": "MITRE ATT&CK T1686.002: Network Device Firewall (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1686.002 (Network Device Firewall) is an Enterprise Defense Impairment technique. Adversaries may disable network device-based firewall mechanisms entirely or add, delete, or modify particular rules in order to bypass controls limiting network usage. Adversaries may obtain access to devices such as routers, switches, or other perimeter/network devices and change access control lists (ACLs), security zones, or policy rules to permit otherwise blocked traffic. For example, adversaries may add new network firewall rules to allow access to all internal network subnets without restrictions. Allowing access to internal network subsets may enable unrestricted inbound/outbound connectivity or open paths for command and control and lateral movement. Adversaries may obtain access to network device management interfaces via Valid Accounts or by exploiting vulnerabilities. In some ... Affected platforms: Network Devices. Sub-technique of ATT&CK T1686. ATT&CK-mapped mitigations: M1051 Update Software, M1047 Audit, M1018 User Account Management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-attack-t1686-003-windows-host-firewall",
    "title": "MITRE ATT&CK T1686.003: Windows Host Firewall (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1686.003 (Windows Host Firewall) is an Enterprise Defense Impairment technique. Adversaries may disable or modify the Windows host firewall to bypass controls limiting network usage. This can include disabling the Windows host firewall entirely, suppressing specific profiles (domain, private, public), or adding, deleting, and modifying firewall rules to allow or restrict traffic. Adversaries may perform these modifications through multiple mechanisms depending on the Windows operating system and access level. For example, adversaries may use command-line utilities (e.g., `netsh advfirewall` or PowerShell cmdlets like `Set-NetFirewallProfile`, `New-NetFirewallRule`), Windows Registry modifications (e.g., altering firewall states and rule configurations via registry keys), or the Windows Control Panel to modify firewall settings through the Windows Security interface. B... Affected platforms: Windows. Sub-technique of ATT&CK T1686. ATT&CK-mapped mitigations: M1022 Restrict File and Directory Permissions, M1024 Restrict Registry Permissions, M1018 User Account Management, M1047 Audit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1686-disable-or-modify-system-firewall",
    "title": "MITRE ATT&CK T1686: Disable or Modify System Firewall (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1686 (Disable or Modify System Firewall) is an Enterprise Defense Impairment technique. Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered sufficient privileges, they can tamper with firewall services, policies, or rule sets to remove restrictions on inbound or outbound traffic. For example, this may include turning off firewall profiles, altering existing rules to permit previously blocked ports or protocols, or adding new rules that create covert communication paths (e.g., adding a new firewall rule for a well-known protocol (such as RDP) using a non-traditional and potentially less securitized port. Adversaries may disable or modify firewalls using different behaviors, depending on the platform. For example, in ESXi, firewall rules may be modified directly via the esxcli... Affected platforms: ESXi, Linux, macOS, Network Devices, Windows. ATT&CK-mapped mitigations: M1047 Audit, M1024 Restrict Registry Permissions, M1022 Restrict File and Directory Permissions, M1018 User Account Management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-attack-t1687-exploitation-for-defense-impairment",
    "title": "MITRE ATT&CK T1687: Exploitation for Defense Impairment (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1687 (Exploitation for Defense Impairment) is an Enterprise Defense Impairment technique. Adversaries may exploit vulnerabilities in security software, infrastructure, or defensive components to degrade, disable, or otherwise continue to impair their ability to prevent, detect, or respond to malicious activity. Adversaries may exploit a system or application vulnerability to directly interfere with defensive mechanisms. Exploitation occurs when an adversary takes advantage of a programming error in software, services, or the operating system to execute adversary-controlled code, often with the goal of weakening or disabling protections. Vulnerabilities may exist in security tools such as antivirus, endpoint detection and response (EDR), firewalls, or other monitoring solutions. Adversaries may use prior reconnaissance or perform discovery activities (e.g., Software Discovery) t... Affected platforms: IaaS, Linux, macOS, SaaS, Windows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "mitre-attack-t1688-safe-mode-boot",
    "title": "MITRE ATT&CK T1688: Safe Mode Boot (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1688 (Safe Mode Boot) is an Enterprise Defense Impairment technique. Adversaries may abuse Windows safe mode to disable endpoint defenses. Safe mode starts up the Windows operating system with a limited set of drivers and services. Third-party security software such as endpoint detection and response (EDR) tools may not start after booting Windows in safe mode. There are two versions of safe mode: Safe Mode and Safe Mode with Networking. It is possible to start additional services after a safe mode boot. Adversaries may abuse safe mode to disable endpoint defenses that may not start with a limited boot. Hosts can be forced into safe mode after the next reboot via modifications to Boot Configuration Data (BCD) stores, which are files that manage boot application settings. Adversaries may also add their malicious applications to the list of minimal services t... Affected platforms: Windows. ATT&CK-mapped mitigations: M1054 Software Configuration, M1026 Privileged Account Management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1689-downgrade-attack",
    "title": "MITRE ATT&CK T1689: Downgrade Attack (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1689 (Downgrade Attack) is an Enterprise Defense Impairment technique. Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls. Downgrade attacks typically take advantage of a system’s backward compatibility to force it into less secure modes of operation. Adversaries may downgrade and use various less-secure versions of features of a system, such as Command and Scripting Interpreter or even network protocols that can be abused to enable Adversary-in-the-Middle or Network Sniffing. For example, PowerShell versions 5+ includes Script Block Logging (SBL), which can record executed script content. However, adversaries may attempt to execute a previous version of PowerShell that does not support SBL with the intent to impair defenses while running malicious scripts that may ... Affected platforms: macOS, Windows, Linux. ATT&CK-mapped mitigations: M1054 Software Configuration, M1042 Disable or Remove Feature or Program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-attack-t1690-prevent-command-history-logging",
    "title": "MITRE ATT&CK T1690: Prevent Command History Logging (Enterprise Tactic TA0112 - Defense Impairment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE ATT&CK T1690 (Prevent Command History Logging) is an Enterprise Defense Impairment technique. Adversaries may impair command history logging to hide commands they run on a compromised system. Various command interpreters keep track of the commands users type in their terminal so that users can retrace what they have done. On Linux and macOS, command history is tracked in a file pointed to by the environment variable `HISTFILE`. When a user logs off a system, this information is flushed to a file in the user's home directory called `~/.bash_history`. The `HISTCONTROL` environment variable keeps track of what should be saved by the history command and eventually into the `~/.bash_history` file when a user logs out. `HISTCONTROL` does not exist by default on macOS, but can be set by the user and will be respected. The `HISTFILE` environment variable is also used in some ESXi systems. ... Affected platforms: ESXi, Linux, macOS, Network Devices, Windows. ATT&CK-mapped mitigations: M1039 Environment Variable Permissions, M1028 Operating System Configuration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-caldera-adversary-emulation-platform",
    "title": "MITRE CALDERA Open Source Adversary Emulation Platform (Sandcat/Manx Agents, Atomic/Stockpile/Response Plugins, ATT&CK Technique Execution, Apache Software Foundation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "MITRE CALDERA is the open-source cybersecurity platform for automated adversary emulation, assisting manual red teams and automating incident response by executing MITRE ATT&CK techniques against test environments. CALDERA is hosted at github.com/apache/caldera and was contributed to the Apache Software Foundation in 2024 (formerly at caldera.mitre.org). The architecture comprises a Core Framework written in Python 3.10+ that runs an asynchronous command-and-control server exposing a REST API and web interface, and a modular Plugin ecosystem providing specialised functionality. Multiple agent types deploy onto targets: Sandcat as the default cross-platform agent, Manx providing shell functionality and reverse shell payloads, and Ragdoll for additional scenarios. Default team-maintained plugins include Atomic (Atomic Red Team TTP integration), Stockpile (technique and adversary profile repository), Response (incident response capabilities), Training (operator certification), Compass (MITRE ATT&CK matrix visualisations), Builder (dynamic payload compilation), Debrief (post-operation analysis), Emu (Center for Threat-Informed Defense emulation plans), and Human (endpoint noise simulation); community plugins include Arsenal, BountyHunter, CalTack, and SAML authentication support. CALDERA operates by combining abilities (executable atomic ATT&CK techniques) into adversary profiles, scheduling them against agents, evaluating facts and rules to make runtime decisions, and reporting outcomes back to the operator. The framework is the canonical reference implementation of automated ATT&CK-aligned adversary emulation and is the recommended companion to MITRE Engage and ATT&CK Navigator. The developers explicitly note that CALDERA servers should run on isolated networks because the platform is not hardened for direct internet exposure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "core_framework_architecture",
        "agent_taxonomy",
        "plugin_ecosystem_team_maintained",
        "plugin_ecosystem_community",
        "abilities_and_adversary_profiles",
        "facts_rules_and_operations",
        "caldera_to_engage_attack_pairing",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-framework-v14",
      "mitre-engage-adversary-engagement-framework",
      "oasis-stix-2-1-structured-threat-information",
      "cyber-nist-csf-2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-1-accessing-functionality-not-properly-constrained-by-acls",
    "title": "MITRE CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-1 (Accessing Functionality Not Properly Constrained by ACLs) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In applications, particularly web applications, access to functionality is mitigated by an authorization framework. This framework maps Access Control Lists (ACLs) to elements of the application's functionality; particularly URL's for web apps. In the case that the administrator failed to specify an ACL for a particular element, an attacker may be able to access it with impunity. Likelihood of attack: High. Typical severity: High. Parent pattern for CAPEC-58 Restful Privilege Elevation; CAPEC-679 Exploitation of Improperly Configured or Implemented Memory Protections; CAPEC-680 Exploitation of Improperly Controlled Registers; and others. Maps to weaknesses CWE-276, CWE-285, CWE-434, CWE-693, and others. Relates to MITRE ATT&CK T1574.010.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1574-014-appdomainmanager"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-capec-capec-10-buffer-overflow-via-environment-variables",
    "title": "MITRE CAPEC-10: Buffer Overflow via Environment Variables (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-10 (Buffer Overflow via Environment Variables) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack pattern involves causing a buffer overflow through manipulation of environment variables. Once the adversary finds that they can modify an environment variable, they may try to overflow associated buffers. This attack leverages implicit trust often placed in environment variables. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-120, CWE-302, CWE-118, CWE-119, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-100-buffer-overflow",
    "title": "MITRE CAPEC-100: Overflow Buffers (Buffer Overflow Attacks) (Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-100 (Overflow Buffers) targets improper or missing bounds checking on buffer operations, typically triggered by attacker-injected input. Results in program crash or unauthorized code execution. Likelihood: High. Severity: Very High. Maps to CWE-120 (Classic Buffer Overflow), CWE-119, CWE-131, CWE-129, CWE-805, CWE-680. Compliance: NIST SP 800-53 SI-10 + SA-11, OWASP ASVS V5, ISO/IEC 27001 secure coding, NIST SP 800-218 SSDF.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1068-exploitation-privilege-escalation",
      "mitre-capec-capec-242-code-injection",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-101-server-side-include-ssi-injection",
    "title": "MITRE CAPEC-101: Server Side Include (SSI) Injection (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-101 (Server Side Include (SSI) Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker can use Server Side Include (SSI) Injection to send code to a web application that then gets executed by the web server. Doing so enables the attacker to achieve similar results to Cross Site Scripting, viz., arbitrary code execution and information disclosure, albeit on a more limited scale, since the SSI directives are nowhere near as powerful as a full-fledged scripting language. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-97, CWE-74, CWE-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-102-session-sidejacking",
    "title": "MITRE CAPEC-102: Session Sidejacking (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-102 (Session Sidejacking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Session sidejacking takes advantage of an unencrypted communication channel between a victim and target system. The attacker sniffs traffic on a network looking for session tokens in unencrypted traffic. Once a session token is captured, the attacker performs malicious actions by using the stolen token with the targeted application to impersonate the victim. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-294, CWE-522, CWE-523, CWE-319, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-103-clickjacking",
    "title": "MITRE CAPEC-103: Clickjacking (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-103 (Clickjacking) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary tricks a victim into unknowingly initiating some action in one system while interacting with the UI from a seemingly completely different, usually an adversary controlled or intended, system. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-181 Flash File Overlay; CAPEC-222 iFrame Overlay; CAPEC-587 Cross Frame Scripting (XFS). Maps to weaknesses CWE-1021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-104-cross-zone-scripting",
    "title": "MITRE CAPEC-104: Cross Zone Scripting (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-104 (Cross Zone Scripting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker is able to cause a victim to load content into their web-browser that bypasses security zone controls and gain access to increased privileges to execute scripting code or other web objects such as unsigned ActiveX controls or applets. This is a privilege elevation attack targeted at zone-based web-browser security. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-250, CWE-638, CWE-285, CWE-116, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-105-http-request-splitting",
    "title": "MITRE CAPEC-105: HTTP Request Splitting (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-105 (HTTP Request Splitting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary abuses the flexibility and discrepancies in the parsing and interpretation of HTTP Request messages by different intermediary HTTP agents (e.g., load balancer, reverse proxy, web caching proxies, application firewalls, etc.) to split a single HTTP request into multiple unauthorized and malicious HTTP requests to a back-end HTTP agent (e.g., web server). Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-74, CWE-113, CWE-138, CWE-436.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-107-cross-site-tracing",
    "title": "MITRE CAPEC-107: Cross Site Tracing (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-107 (Cross Site Tracing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Cross Site Tracing (XST) enables an adversary to steal the victim's session cookie and possibly other authentication credentials transmitted in the header of the HTTP request when the victim's browser communicates to a destination system's web server. Likelihood of attack: Medium. Typical severity: Very High. Maps to weaknesses CWE-693, CWE-648.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-108-command-line-execution-through-sql-injection",
    "title": "MITRE CAPEC-108: Command Line Execution through SQL Injection (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-108 (Command Line Execution through SQL Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses standard SQL injection methods to inject data into the command line for execution. This could be done directly through misuse of directives such as MSSQL_xp_cmdshell or indirectly through injection of data into the database that would be interpreted as shell commands. Likelihood of attack: Low. Typical severity: Very High. Maps to weaknesses CWE-89, CWE-74, CWE-20, CWE-78, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-109-object-relational-mapping-injection",
    "title": "MITRE CAPEC-109: Object Relational Mapping Injection (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-109 (Object Relational Mapping Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker leverages a weakness present in the database access layer code generated with an Object Relational Mapping (ORM) tool or a weakness in the way that a developer used a persistence framework to inject their own SQL commands to be executed against the underlying database. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-20, CWE-89, CWE-564.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-11-cause-web-server-misclassification",
    "title": "MITRE CAPEC-11: Cause Web Server Misclassification (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-11 (Cause Web Server Misclassification) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type exploits a Web server's decision to take action based on filename or file extension. Because different file types are handled by different server processes, misclassification may force the Web server to take unexpected action, or expected actions in an unexpected sequence. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-430. Relates to MITRE ATT&CK T1036.006.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-110-sql-injection-through-soap-parameter-tampering",
    "title": "MITRE CAPEC-110: SQL Injection through SOAP Parameter Tampering (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-110 (SQL Injection through SOAP Parameter Tampering) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker modifies the parameters of the SOAP message that is sent from the service consumer to the service provider to initiate a SQL injection attack. On the service provider side, the SOAP message is parsed and parameters are not properly validated before being used to access a database in a way that does not use parameter binding, thus enabling the attacker to control the structure of the executed SQL query. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-89, CWE-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-111-json-hijacking-aka-javascript-hijacking",
    "title": "MITRE CAPEC-111: JSON Hijacking (aka JavaScript Hijacking) (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-111 (JSON Hijacking (aka JavaScript Hijacking)) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker targets a system that uses JavaScript Object Notation (JSON) as a transport mechanism between the client and the server (common in Web 2.0 systems using AJAX) to steal possibly confidential information transmitted from the server back to the client inside the JSON object by taking advantage of the loophole in the browser's Same Origin Policy that does not prohibit JavaScript from one website to be. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-345, CWE-346, CWE-352.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-112-brute-force",
    "title": "MITRE CAPEC-112: Brute Force (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-112 (Brute Force) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack, some asset (information, functionality, identity, etc.) is protected by a finite secret value. The attacker attempts to gain access to this asset by using trial-and-error to exhaustively explore all the possible secret values in the hope of finding the secret (or a value that is functionally equivalent) that will unlock the asset. Likelihood of attack: Unknown. Typical severity: High. Parent pattern for CAPEC-20 Encryption Brute Forcing; CAPEC-49 Password Brute Forcing. Maps to weaknesses CWE-330, CWE-326, CWE-521. Relates to MITRE ATT&CK T1110.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1110-004-credential-stuffing"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-capec-capec-113-interface-manipulation",
    "title": "MITRE CAPEC-113: Interface Manipulation (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-113 (Interface Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates the use or processing of an interface (e.g. Application Programming Interface (API) or System-on-Chip (SoC)) resulting in an adverse impact upon the security of the system implementing the interface. This can allow the adversary to bypass access control and/or execute functionality not intended by the interface implementation, possibly compromising the system which integrates the interface. Likelihood of attack: Medium. Typical severity: Medium. Parent pattern for CAPEC-121 Exploit Non-Production Interfaces; CAPEC-133 Try All Common Switches; CAPEC-160 Exploit Script-Based APIs; and others. Maps to weaknesses CWE-1192.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-114-authentication-abuse",
    "title": "MITRE CAPEC-114: Authentication Abuse (Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-114 (Authentication Abuse) is an attack pattern in which an attacker obtains unauthorized access to an application, service, or device through knowledge of inherent weaknesses in an authentication mechanism, or by exploiting a flaw in the authentication scheme implementation. Distinct from CAPEC-115 (Authentication Bypass) - here the attacker becomes certified as a valid user through illegitimate means, rather than avoiding authentication entirely. Severity: Medium. Maps to MITRE ATT&CK T1548 (Abuse Elevation Control Mechanism) and CWE-287 (Improper Authentication), CWE-1244. Compliance: PCI DSS v4.0 Req 8, NIST SP 800-53 IA-2, NIST SP 800-63B.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-d3fend-d3-mfa-multi-factor-authentication",
      "mitre-d3fend-d3-ch-credential-hardening",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-115-authentication-bypass",
    "title": "MITRE CAPEC-115: Authentication Bypass (Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-115 (Authentication Bypass) is an attack pattern in which an attacker gains access to application, service, or device with the privileges of an authorized or privileged user by evading or circumventing an authentication mechanism. This is distinct from credential theft - the attacker avoids authentication entirely rather than faking it. Typical severity: Medium. Maps to MITRE ATT&CK T1548 (Abuse Elevation Control Mechanism) and CWE-287 (Improper Authentication). The CAPEC page references OWASP Web Security Testing Guide for authentication-bypass testing methodology. Compliance: PCI DSS v4.0 Req 8, NIST SP 800-53 IA-2, ISO/IEC 27001 (secure authentication).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1078-valid-accounts",
      "mitre-d3fend-d3-mfa-multi-factor-authentication",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-116-excavation",
    "title": "MITRE CAPEC-116: Excavation (Attack Pattern - Information Disclosure)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-116 (Excavation) is an attack pattern in which an adversary actively probes the target to solicit information that could be leveraged for malicious purposes - including stack traces, configuration data, or database design. Likelihood: High. Severity: Medium. Maps to CWE-200 (Exposure of Sensitive Information), CWE-1243 (Sensitive Non-Volatile Information Not Protected During Debug). Compliance: NIST SP 800-53 SI-11 + AC-22, OWASP ASVS V7, ISO/IEC 27001 A.5.34/A.8.10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1589-gather-victim-identity-information",
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-capec-capec-310-scanning-for-vulnerable-software",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-117-interception",
    "title": "MITRE CAPEC-117: Interception (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-117 (Interception) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary monitors data streams to or from the target for information gathering purposes. This attack may be undertaken to solely gather sensitive information or to support a further attack against the target. This attack pattern can involve sniffing network traffic as well as other types of data streams (e.g. radio). Likelihood of attack: Low. Typical severity: Medium. Parent pattern for CAPEC-157 Sniffing Attacks; CAPEC-499 Android Intent Intercept; CAPEC-651 Eavesdropping. Maps to weaknesses CWE-319.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-12-choosing-message-identifier",
    "title": "MITRE CAPEC-12: Choosing Message Identifier (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-12 (Choosing Message Identifier) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This pattern of attack is defined by the selection of messages distributed via multicast or public information channels that are intended for another client by determining the parameter value assigned to that client. This attack allows the adversary to gain access to potentially privileged information, and to possibly perpetrate other attacks through the distribution means by impersonation. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-201, CWE-306.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-120-double-encoding",
    "title": "MITRE CAPEC-120: Double Encoding (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-120 (Double Encoding) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary utilizes a repeating of the encoding process for a set of characters (that is, character encoding a character encoding of a character) to obfuscate the payload of a particular request. This may allow the adversary to bypass filters that attempt to detect illegal characters or strings, such as those that might be used in traversal or injection attacks. Likelihood of attack: Low. Typical severity: Medium. Maps to weaknesses CWE-173, CWE-172, CWE-177, CWE-181, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-121-exploit-non-production-interfaces",
    "title": "MITRE CAPEC-121: Exploit Non-Production Interfaces (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-121 (Exploit Non-Production Interfaces) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a sample, demonstration, test, or debug interface that is unintentionally enabled on a production system, with the goal of gleaning information or leveraging functionality that would otherwise be unavailable. Likelihood of attack: Low. Typical severity: High. Parent pattern for CAPEC-661 Root/Jailbreak Detection Evasion via Debugging. Maps to weaknesses CWE-489, CWE-1209, CWE-1259, CWE-1267, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-122-privilege-abuse",
    "title": "MITRE CAPEC-122: Privilege Abuse (Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-122 (Privilege Abuse) is an attack pattern in which an adversary exploits features of the target that should be reserved for privileged users or administrators but are exposed to use by lower or non-privileged accounts. Likelihood of attack: High. Typical severity: Medium. Maps to MITRE ATT&CK T1548 (Abuse Elevation Control Mechanism) and CWE-269 (Improper Privilege Management), CWE-732 (Incorrect Permission Assignment for Critical Resource), CWE-1317. Compliance: NIST SP 800-53 AC-6 (Least Privilege), ISO/IEC 27001 (privileged access rights), PCI DSS v4.0 Req 7, NIS2 Article 21(2)(j).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1068-exploitation-privilege-escalation",
      "mitre-d3fend-d3-ch-credential-hardening",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-123-buffer-manipulation",
    "title": "MITRE CAPEC-123: Buffer Manipulation (Meta Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-123 (Buffer Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates an application's interaction with a buffer in an attempt to read or modify data they shouldn't have access to. Buffer attacks are distinguished in that it is the buffer space itself that is the target of the attack rather than any code responsible for interpreting the content of the buffer. In virtually all buffer attacks the content that is placed in the buffer is immaterial. Likelihood of attack: High. Typical severity: Very High. Parent pattern for CAPEC-100 Overflow Buffers; CAPEC-540 Overread Buffers. Maps to weaknesses CWE-119.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-124-shared-resource-manipulation",
    "title": "MITRE CAPEC-124: Shared Resource Manipulation (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-124 (Shared Resource Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a resource shared between multiple applications, an application pool or hardware pin multiplexing to affect behavior. Resources may be shared between multiple applications or between multiple threads of a single application. Resource sharing is usually accomplished through mutual access to a single memory location or multiplexed hardware pins. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-1189, CWE-1331.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-125-flooding",
    "title": "MITRE CAPEC-125: Flooding (Attack Pattern - Resource Exhaustion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-125 (Flooding) is an attack pattern in which an adversary consumes target resources by rapidly engaging in a large number of interactions. Exploits weaknesses in rate limiting and prevents legitimate access or causes system crashes. Severity: Medium. Maps to MITRE ATT&CK T1498.001 (Direct Network Flood) and T1499 (Endpoint DoS), CWE-404 (Improper Resource Shutdown), CWE-770 (Allocation of Resources Without Limits). Compliance: NIST SP 800-53 SC-5, ISO 27001 A.8.21, PCI DSS Req 11.4, NIS2 (EU 2022/2555).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1499-endpoint-denial-of-service",
      "mitre-d3fend-d3-itf-inbound-traffic-filtering",
      "mitre-d3fend-d3-nta-network-traffic-analysis",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-126-path-traversal",
    "title": "MITRE CAPEC-126: Path Traversal (Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-126 (Path Traversal) is an attack pattern in which an adversary exploits insufficient input validation to access unauthorized data by manipulating file paths, typically using dot-dot-slash sequences to traverse outside intended directory structures. Likelihood: High. Severity: Very High. Maps to CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). Compliance: OWASP ASVS V12 File and Resources, NIST SP 800-53 SI-10 + AC-3, PCI DSS Req 6.2.4, NIS2 Art 21(2)(e).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1083-file-and-directory-discovery",
      "mitre-capec-capec-153-input-data-manipulation",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-127-directory-indexing",
    "title": "MITRE CAPEC-127: Directory Indexing (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-127 (Directory Indexing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary crafts a request to a target that results in the target listing/indexing the content of a directory as output. One common method of triggering directory contents as output is to construct a request containing a path that terminates in a directory name rather than a file name since many applications are configured to provide a list of the directory's contents when such a request is received. Likelihood of attack: High. Typical severity: Medium. Maps to weaknesses CWE-424, CWE-425, CWE-288, CWE-285, and others. Relates to MITRE ATT&CK T1083.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1083-file-and-directory-discovery"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-128-integer-attacks",
    "title": "MITRE CAPEC-128: Integer Attacks (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-128 (Integer Attacks) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker takes advantage of the structure of integer variables to cause these variables to assume values that are not expected by an application. For example, adding one to the largest positive integer in a signed integer variable results in a negative number. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-92 Forced Integer Overflow. Maps to weaknesses CWE-682.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-129-pointer-manipulation",
    "title": "MITRE CAPEC-129: Pointer Manipulation (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-129 (Pointer Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack pattern involves an adversary manipulating a pointer within a target application resulting in the application accessing an unintended memory location. This can result in the crashing of the application or, for certain pointer values, access to data that would not normally be possible or the execution of arbitrary code. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-682, CWE-822, CWE-823.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-13-subverting-environment-variable-values",
    "title": "MITRE CAPEC-13: Subverting Environment Variable Values (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-13 (Subverting Environment Variable Values) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary directly or indirectly modifies environment variables used by or controlling the target software. The adversary's goal is to cause the target software to deviate from its expected operation in a manner that benefits the adversary. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-353, CWE-285, CWE-302, CWE-74, and others. Relates to MITRE ATT&CK T1562.003, T1574.006, T1574.007.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1685-004-disable-or-modify-linux-audit-system-log",
      "mitre-attack-t1574-014-appdomainmanager"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-130-excessive-allocation",
    "title": "MITRE CAPEC-130: Excessive Allocation (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-130 (Excessive Allocation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary causes the target to allocate excessive resources to servicing the attackers' request, thereby reducing the resources available for legitimate services and degrading or denying services. Usually, this attack focuses on memory allocation, but any finite resource on the target could be the attacked, including bandwidth, processing cycles, or other resources. Likelihood of attack: Medium. Typical severity: Medium. Parent pattern for CAPEC-230 Serialized Data with Nested Payloads; CAPEC-231 Oversized Serialized Data Payloads; CAPEC-492 Regular Expression Exponential Blowup; and others. Maps to weaknesses CWE-404, CWE-770, CWE-1325. Relates to MITRE ATT&CK T1499.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1499-004-application-or-system-exploitation"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-131-resource-leak-exposure",
    "title": "MITRE CAPEC-131: Resource Leak Exposure (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-131 (Resource Leak Exposure) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary utilizes a resource leak on the target to deplete the quantity of the resource available to service legitimate requests. Likelihood of attack: Medium. Typical severity: Medium. Maps to weaknesses CWE-404. Relates to MITRE ATT&CK T1499.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1499-004-application-or-system-exploitation"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-132-symlink-attack",
    "title": "MITRE CAPEC-132: Symlink Attack (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-132 (Symlink Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary positions a symbolic link in such a manner that the targeted user or application accesses the link's endpoint, assuming that it is accessing a file with the link's name. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-59. Relates to MITRE ATT&CK T1547.009.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1547-015-login-items"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-133-try-all-common-switches",
    "title": "MITRE CAPEC-133: Try All Common Switches (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-133 (Try All Common Switches) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker attempts to invoke all common switches and options in the target application for the purpose of discovering weaknesses in the target. For example, in some applications, adding a --debug switch causes debugging information to be displayed, which can sometimes reveal sensitive processing or configuration information to an attacker. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-912.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-134-email-injection",
    "title": "MITRE CAPEC-134: Email Injection (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-134 (Email Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates the headers and content of an email message by injecting data via the use of delimiter characters native to the protocol. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-41 Using Meta-characters in E-mail Headers to Inject Malicious Payloads. Maps to weaknesses CWE-150.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-135-format-string-injection",
    "title": "MITRE CAPEC-135: Format String Injection (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-135 (Format String Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary includes formatting characters in a string input field on the target application. Most applications assume that users will provide static text and may respond unpredictably to the presence of formatting character. Likelihood of attack: High. Typical severity: High. Parent pattern for CAPEC-67 String Format Overflow in syslog(). Maps to weaknesses CWE-134, CWE-20, CWE-74.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-136-ldap-injection",
    "title": "MITRE CAPEC-136: LDAP Injection (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-136 (LDAP Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates or crafts an LDAP query for the purpose of undermining the security of the target. Some applications use user input to create LDAP queries that are processed by an LDAP server. For example, a user might provide their username during authentication and the username might be inserted in an LDAP query during the authentication process. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-77, CWE-90, CWE-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-137-parameter-injection",
    "title": "MITRE CAPEC-137: Parameter Injection (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-137 (Parameter Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates the content of request parameters for the purpose of undermining the security of the target. Some parameter encodings use text characters as separators. For example, parameters in a HTTP GET message are encoded as name-value pairs separated by an ampersand (&). Likelihood of attack: Medium. Typical severity: Medium. Parent pattern for CAPEC-134 Email Injection; CAPEC-135 Format String Injection; CAPEC-138 Reflection Injection; and others. Maps to weaknesses CWE-88.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-138-reflection-injection",
    "title": "MITRE CAPEC-138: Reflection Injection (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-138 (Reflection Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary supplies a value to the target application which is then used by reflection methods to identify a class, method, or field. For example, in the Java programming language the reflection libraries permit an application to inspect, load, and invoke classes and their components by name. Likelihood of attack: Unknown. Typical severity: Very High. Maps to weaknesses CWE-470.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-139-relative-path-traversal",
    "title": "MITRE CAPEC-139: Relative Path Traversal (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-139 (Relative Path Traversal) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits a weakness in input validation on the target by supplying a specially constructed path utilizing dot and slash characters for the purpose of obtaining access to arbitrary files or resources. An attacker modifies a known path on the target in order to reach material that is not available through intended channels. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-23.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-14-client-side-injection-induced-buffer-overflow",
    "title": "MITRE CAPEC-14: Client-side Injection-induced Buffer Overflow (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-14 (Client-side Injection-induced Buffer Overflow) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack exploits a buffer overflow vulnerability in targeted client software through injection of malicious content from a custom-built hostile service. This hostile service is created to deliver the correct content to the client software. For example, if the client-side application is a browser, the service will host a webpage that the browser loads. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-120, CWE-353, CWE-118, CWE-119, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-140-bypassing-of-intermediate-forms-in-multiple-form-sets",
    "title": "MITRE CAPEC-140: Bypassing of Intermediate Forms in Multiple-Form Sets (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-140 (Bypassing of Intermediate Forms in Multiple-Form Sets) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Some web applications require users to submit information through an ordered sequence of web forms. This is often done if there is a very large amount of information being collected or if information on earlier forms is used to pre-populate fields or determine which additional information the application needs to collect. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-372.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-141-cache-poisoning",
    "title": "MITRE CAPEC-141: Cache Poisoning (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-141 (Cache Poisoning) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits the functionality of cache technologies to cause specific data to be cached that aids the attackers' objectives. This describes any attack whereby an attacker places incorrect or harmful material in cache. The targeted cache can be an application's cache (e.g. a web browser cache) or a public cache (e.g. a DNS or ARP cache). Likelihood of attack: High. Typical severity: High. Parent pattern for CAPEC-142 DNS Cache Poisoning. Maps to weaknesses CWE-348, CWE-345, CWE-349, CWE-346. Relates to MITRE ATT&CK T1557.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1557-adversary-in-the-middle"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-142-dns-cache-poisoning",
    "title": "MITRE CAPEC-142: DNS Cache Poisoning (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-142 (DNS Cache Poisoning) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. A domain name server translates a domain name (such as www.example.com) into an IP address that Internet hosts use to contact Internet resources. An adversary modifies a public DNS cache to cause certain names to resolve to incorrect addresses that the adversary specifies. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-348, CWE-345, CWE-349, CWE-346, and others. Relates to MITRE ATT&CK T1584.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1584-compromise-infrastructure"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-143-detect-unpublicized-web-pages",
    "title": "MITRE CAPEC-143: Detect Unpublicized Web Pages (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-143 (Detect Unpublicized Web Pages) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary searches a targeted web site for web pages that have not been publicized. In doing this, the adversary may be able to gain access to information that the targeted site did not intend to make public. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-425.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-144-detect-unpublicized-web-services",
    "title": "MITRE CAPEC-144: Detect Unpublicized Web Services (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-144 (Detect Unpublicized Web Services) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary searches a targeted web site for web services that have not been publicized. This attack can be especially dangerous since unpublished but available services may not have adequate security controls placed upon them given that an administrator may believe they are unreachable. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-425.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-145-checksum-spoofing",
    "title": "MITRE CAPEC-145: Checksum Spoofing (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-145 (Checksum Spoofing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary spoofs a checksum message for the purpose of making a payload appear to have a valid corresponding checksum. Checksums are used to verify message integrity. They consist of some value based on the value of the message they are protecting. Hash codes are a common checksum mechanism. Both the sender and recipient are able to compute the checksum based on the contents of the message. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-354.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-146-xml-schema-poisoning",
    "title": "MITRE CAPEC-146: XML Schema Poisoning (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-146 (XML Schema Poisoning) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary corrupts or modifies the content of XML schema information passed between a client and server for the purpose of undermining the security of the target. XML Schemas provide the structure and content definitions for XML documents. Schema poisoning is the ability to manipulate a schema either by replacing or modifying it to compromise the programs that process documents that use this schema. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-15, CWE-472.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-147-xml-ping-of-the-death",
    "title": "MITRE CAPEC-147: XML Ping of the Death (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-147 (XML Ping of the Death) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker initiates a resource depletion attack where a large number of small XML messages are delivered at a sufficiently rapid rate to cause a denial of service or crash of the target. Transactions such as repetitive SOAP transactions can deplete resources faster than a simple flooding attack because of the additional resources used by the SOAP protocol and the resources necessary to process SOAP messages. Likelihood of attack: Low. Typical severity: Medium. Maps to weaknesses CWE-400, CWE-770.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-148-content-spoofing",
    "title": "MITRE CAPEC-148: Content Spoofing (Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-148 (Content Spoofing) is an attack pattern in which an adversary modifies content to make it contain something other than what the original content producer intended while keeping the apparent source unchanged. Encompasses modification of web pages, email messages, file transfers, and network communications either at source or in transit. Likelihood: Medium. Severity: Medium. Maps to MITRE ATT&CK T1491 (Defacement) and CWE-345 (Insufficient Verification of Data Authenticity). Compliance: NIST SP 800-53 SI-7 (Software Firmware Information Integrity), SC-8 (Transmission Confidentiality and Integrity), ISO 27001 secure communication clauses, GDPR Art 32.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-d3fend-d3-fim-file-integrity-monitoring",
      "mitre-d3fend-d3-mencr-message-encryption",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-149-explore-for-predictable-temporary-file-names",
    "title": "MITRE CAPEC-149: Explore for Predictable Temporary File Names (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-149 (Explore for Predictable Temporary File Names) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker explores a target to identify the names and locations of predictable temporary files for the purpose of launching further attacks against the target. This involves analyzing naming conventions and storage locations of the temporary files created by a target application. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-377.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-15-command-delimiters",
    "title": "MITRE CAPEC-15: Command Delimiters (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-15 (Command Delimiters) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type exploits a programs' vulnerabilities that allows an attacker's commands to be concatenated onto a legitimate command with the intent of targeting other resources such as the file system or database. Likelihood of attack: High. Typical severity: High. Parent pattern for CAPEC-460 HTTP Parameter Pollution (HPP). Maps to weaknesses CWE-146, CWE-77, CWE-184, CWE-78, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-150-collect-data-from-common-resource-locations",
    "title": "MITRE CAPEC-150: Collect Data from Common Resource Locations (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-150 (Collect Data from Common Resource Locations) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits well-known locations for resources for the purposes of undermining the security of the target. In many, if not most systems, files and resources are organized in a default tree structure. This can be useful for adversaries because they often know where to look for resources or files that are necessary for attacks. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-143 Detect Unpublicized Web Pages; CAPEC-144 Detect Unpublicized Web Services; CAPEC-155 Screen Temporary Files for Sensitive Information; and others. Maps to weaknesses CWE-552, CWE-1239, CWE-1258, CWE-1266, and others. Relates to MITRE ATT&CK T1003, T1119, T1213.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1003-os-credential-dumping",
      "mitre-attack-t1119-automated-collection"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-151-identity-spoofing",
    "title": "MITRE CAPEC-151: Identity Spoofing (Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-151 (Identity Spoofing) is an attack pattern in which an adversary assumes the identity of another entity (human or non-human) and uses that identity to accomplish a goal. Likelihood and Severity: Medium. Maps to CWE-287 (Improper Authentication). Page lists robust authentication (MFA) as primary mitigation. Compliance: NIST SP 800-53 IA-2, OWASP ASVS V2, PCI DSS Req 8, NIS2 Art 21(2)(j), CISA Phishing-Resistant MFA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1539-steal-web-session-cookie",
      "mitre-d3fend-d3-mfa-multi-factor-authentication",
      "mitre-d3fend-d3-ch-credential-hardening",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-153-input-data-manipulation",
    "title": "MITRE CAPEC-153: Input Data Manipulation (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-153 (Input Data Manipulation) is a meta-level attack pattern in which an attacker exploits a weakness in input validation by controlling the format, structure, and composition of data to an input-processing interface. Severity: Medium. Maps to CWE-20 (Improper Input Validation). Child patterns: CAPEC-126 Path Traversal, CAPEC-128 Integer Attacks, CAPEC-267 Leverage Alternate Encoding. Compliance: OWASP ASVS V5, OWASP Top 10 A03:2021, NIST SP 800-53 SI-10, ISO/IEC 27001 secure coding, PCI DSS v4.0 Req 6.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-capec-capec-66-sql-injection",
      "mitre-capec-capec-63-cross-site-scripting",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-154-resource-location-spoofing",
    "title": "MITRE CAPEC-154: Resource Location Spoofing (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-154 (Resource Location Spoofing) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary deceives an application or user and convinces them to request a resource from an unintended location. By spoofing the location, the adversary can cause an alternate resource to be used, often one that the adversary controls and can be used to help them achieve their malicious goals. Likelihood of attack: Medium. Typical severity: Medium. Parent pattern for CAPEC-159 Redirect Access to Libraries; CAPEC-616 Establish Rogue Location. Maps to weaknesses CWE-451.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-155-screen-temporary-files-for-sensitive-information",
    "title": "MITRE CAPEC-155: Screen Temporary Files for Sensitive Information (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-155 (Screen Temporary Files for Sensitive Information) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits the temporary, insecure storage of information by monitoring the content of files used to store temp data during an application's routine execution flow. Many applications use temporary files to accelerate processing or to provide records of state across multiple executions of the application. Sometimes, however, these temporary files may end up storing sensitive information. Likelihood of attack: Medium. Typical severity: Medium. Maps to weaknesses CWE-377.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-157-sniffing-attacks",
    "title": "MITRE CAPEC-157: Sniffing Attacks (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-157 (Sniffing Attacks) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, the adversary intercepts information transmitted between two third parties. The adversary must be able to observe, read, and/or hear the communication traffic, but not necessarily block the communication or change its content. Any transmission medium can theoretically be sniffed if the adversary can examine the contents between the sender and recipient. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-158 Sniffing Network Traffic; CAPEC-31 Accessing/Intercepting/Modifying HTTP Cookies; CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data; and others. Maps to weaknesses CWE-311.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-158-sniffing-network-traffic",
    "title": "MITRE CAPEC-158: Sniffing Network Traffic (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-158 (Sniffing Network Traffic) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, the adversary monitors network traffic between nodes of a public or multicast network in an attempt to capture sensitive information at the protocol level. Network sniffing applications can reveal TCP/IP, DNS, Ethernet, and other low-level network communication information. The adversary takes a passive role in this attack pattern and simply observes and analyzes the traffic. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-311. Relates to MITRE ATT&CK T1040, T1111.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1040-network-sniffing",
      "mitre-attack-t1111-multi-factor-authentication-interception"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-159-redirect-access-to-libraries",
    "title": "MITRE CAPEC-159: Redirect Access to Libraries (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-159 (Redirect Access to Libraries) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in the way an application searches for external libraries to manipulate the execution flow to point to an adversary supplied library or code base. This pattern of attack allows the adversary to compromise the application or server via the execution of unauthorized code. An application typically makes calls to functions that are a part of libraries external to the application. Likelihood of attack: High. Typical severity: Very High. Parent pattern for CAPEC-132 Symlink Attack; CAPEC-38 Leveraging/Manipulating Configuration File Search Paths; CAPEC-471 Search Order Hijacking; and others. Maps to weaknesses CWE-706. Relates to MITRE ATT&CK T1574.008.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1574-014-appdomainmanager"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-16-dictionary-based-password-attack",
    "title": "MITRE CAPEC-16: Dictionary-based Password Attack (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-16 (Dictionary-based Password Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker tries each of the words in a dictionary as passwords to gain access to the system via some user's account. If the password chosen by the user was a word within the dictionary, this attack will be successful (in the absence of other mitigations). This is a specific instance of the password brute forcing attack pattern. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-521, CWE-262, CWE-263, CWE-654, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-160-exploit-script-based-apis",
    "title": "MITRE CAPEC-160: Exploit Script-Based APIs (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-160 (Exploit Script-Based APIs) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Some APIs support scripting instructions as arguments. Methods that take scripted instructions (or references to scripted instructions) can be very flexible and powerful. However, if an attacker can specify the script that serves as input to these methods they can gain access to a great deal of functionality. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-346.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-161-infrastructure-manipulation",
    "title": "MITRE CAPEC-161: Infrastructure Manipulation (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-161 (Infrastructure Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits characteristics of the infrastructure of a network entity in order to perpetrate attacks or information gathering on network objects or effect a change in the ordinary information flow between network objects. Likelihood of attack: Unknown. Typical severity: High. Parent pattern for CAPEC-141 Cache Poisoning; CAPEC-166 Force the System to Reset Values; CAPEC-268 Audit Log Manipulation; and others. Maps to weaknesses CWE-923.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-162-manipulating-hidden-fields",
    "title": "MITRE CAPEC-162: Manipulating Hidden Fields (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-162 (Manipulating Hidden Fields) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in the server's trust of client-side processing by modifying data on the client-side, such as price information, and then submitting this data to the server, which processes the modified data. For example, eShoplifting is a data manipulation attack against an on-line merchant during a purchasing transaction. Likelihood of attack: Unknown. Typical severity: High. Maps to weaknesses CWE-602.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-163-spear-phishing",
    "title": "MITRE CAPEC-163: Spear Phishing (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-163 (Spear Phishing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary targets a specific user or group with a Phishing (CAPEC-98) attack tailored to a category of users in order to have maximum relevance and deceptive capability. Spear Phishing is an enhanced version of the Phishing attack targeted to a specific user or group. The quality of the targeted email is usually enhanced by appearing to come from a known or trusted entity. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-451. Relates to MITRE ATT&CK T1534, T1566.001, T1566.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1534-internal-spearphishing",
      "mitre-attack-t1566-004-spearphishing-voice"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-164-mobile-phishing",
    "title": "MITRE CAPEC-164: Mobile Phishing (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-164 (Mobile Phishing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary targets mobile phone users with a phishing attack for the purpose of soliciting account passwords or sensitive information from the user. Mobile Phishing is a variation of the Phishing social engineering technique where the attack is initiated via a text or SMS message, rather than email. The user is enticed to provide information or visit a compromised web site via this message. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-451.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-165-file-manipulation",
    "title": "MITRE CAPEC-165: File Manipulation (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-165 (File Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker modifies file contents or attributes (such as extensions or names) of files in a manner to cause incorrect processing by an application. Attackers use this class of attacks to cause applications to enter unstable states, overwrite or expose sensitive information, and even execute arbitrary code with the application's privileges. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-572 Artificially Inflate File Sizes; CAPEC-635 Alternative Execution Due to Deceptive Filenames; CAPEC-636 Hiding Malicious Data or Code within Files; and others. Relates to MITRE ATT&CK T1036.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-166-force-the-system-to-reset-values",
    "title": "MITRE CAPEC-166: Force the System to Reset Values (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-166 (Force the System to Reset Values) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker forces the target into a previous state in order to leverage potential weaknesses in the target dependent upon a prior configuration or state-dependent factors. Even in cases where an attacker may not be able to directly control the configuration of the targeted application, they may be able to reset the configuration to a prior state since many applications implement reset functions. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-306, CWE-1221, CWE-1232.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-167-white-box-reverse-engineering",
    "title": "MITRE CAPEC-167: White Box Reverse Engineering (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-167 (White Box Reverse Engineering) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker discovers the structure, function, and composition of a type of computer software through white box analysis techniques. White box techniques involve methods which can be applied to a piece of software when an executable or some other compiled object can be directly subjected to analysis, revealing at least a portion of its machine instructions that can be observed upon execution. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-190 Reverse Engineer an Executable to Expose Assumed Hidden Functionality; CAPEC-191 Read Sensitive Constants Within an Executable; CAPEC-204 Lifting Sensitive Data Embedded in Cache; and others. Maps to weaknesses CWE-1323.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-168-windows-data-alternate-data-stream",
    "title": "MITRE CAPEC-168: Windows ::DATA Alternate Data Stream (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-168 (Windows ::DATA Alternate Data Stream) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits the functionality of Microsoft NTFS Alternate Data Streams (ADS) to undermine system security. ADS allows multiple \"files\" to be stored in one directory entry referenced as filename:streamname. One or more alternate data streams may be stored in any file or directory. Normal Microsoft utilities do not show the presence of an ADS stream attached to a file. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-212, CWE-69.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-169-footprinting",
    "title": "MITRE CAPEC-169: Footprinting (Meta Attack Pattern - Very Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-169 (Footprinting) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in probing and exploration activities to identify constituents and properties of the target. Likelihood of attack: High. Typical severity: Very Low. Parent pattern for CAPEC-292 Host Discovery; CAPEC-300 Port Scanning; CAPEC-309 Network Topology Mapping; and others. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1217, T1592, T1595.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1217-browser-information-discovery",
      "mitre-attack-t1592-gather-victim-host-information"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-17-using-malicious-files",
    "title": "MITRE CAPEC-17: Using Malicious Files (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-17 (Using Malicious Files) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type exploits a system's configuration that allows an adversary to either directly access an executable file, for example through shell access; or in a possible worst case allows an adversary to upload a file and then execute it. Likelihood of attack: High. Typical severity: Very High. Parent pattern for CAPEC-177 Create files with the same name as files protected with a higher classification; CAPEC-263 Force Use of Corrupted Files; CAPEC-562 Modify Shared File; and others. Maps to weaknesses CWE-732, CWE-285, CWE-272, CWE-59, and others. Relates to MITRE ATT&CK T1574.005, T1574.010.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1574-014-appdomainmanager"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-170-web-application-fingerprinting",
    "title": "MITRE CAPEC-170: Web Application Fingerprinting (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-170 (Web Application Fingerprinting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker sends a series of probes to a web application in order to elicit version-dependent and type-dependent behavior that assists in identifying the target. An attacker could learn information such as software versions, error pages, and response headers, variations in implementations of the HTTP protocol, directory structures, and other similar information about the targeted service. Likelihood of attack: High. Typical severity: Low. Maps to weaknesses CWE-497.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-173-action-spoofing",
    "title": "MITRE CAPEC-173: Action Spoofing (Meta Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-173 (Action Spoofing) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary is able to disguise one action for another and therefore trick a user into initiating one type of action when they intend to initiate a different action. For example, a user might be led to believe that clicking a button will submit a query, but in fact it downloads software. Likelihood of attack: High. Typical severity: Very High. Parent pattern for CAPEC-103 Clickjacking; CAPEC-501 Android Activity Hijack; CAPEC-504 Task Impersonation; and others. Maps to weaknesses CWE-451.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-174-flash-parameter-injection",
    "title": "MITRE CAPEC-174: Flash Parameter Injection (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-174 (Flash Parameter Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of improper data validation to inject malicious global parameters into a Flash file embedded within an HTML document. Flash files can leverage user-submitted data to configure the Flash document and access the embedding HTML document. Likelihood of attack: High. Typical severity: Medium. Maps to weaknesses CWE-88.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-175-code-inclusion",
    "title": "MITRE CAPEC-175: Code Inclusion (Meta Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-175 (Code Inclusion) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness on the target to force arbitrary code to be retrieved locally or from a remote location and executed. This differs from code injection in that code injection involves the direct inclusion of code while code inclusion involves the addition or replacement of a reference to a code file, which is subsequently loaded by the target and used as part of the code of some application. Likelihood of attack: Medium. Typical severity: Very High. Parent pattern for CAPEC-251 Local Code Inclusion; CAPEC-253 Remote Code Inclusion. Maps to weaknesses CWE-829.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-176-configuration-environment-manipulation",
    "title": "MITRE CAPEC-176: Configuration/Environment Manipulation (Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-176 (Configuration/Environment Manipulation) is an attack pattern in which an attacker manipulates files or settings external to a target application that affect the behavior of that application. Severity: Medium. Maps to CWE-15 (External Control of System or Configuration Setting). Child patterns: CAPEC-75 Manipulating Writeable Configuration Files, CAPEC-203 Manipulate Registry, CAPEC-271 Schema Poisoning, CAPEC-536 Data Injected During Configuration, CAPEC-578 Disable Security Software. Compliance: NIST SP 800-53 CM-3/CM-5/CM-6, ISO 27001 A.8.9/A.8.32, PCI DSS Req 2.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1112-modify-registry",
      "mitre-attack-t1574-hijack-execution-flow",
      "mitre-d3fend-d3-fim-file-integrity-monitoring",
      "mitre-d3fend-d3-sysm-system-mapping",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-177-create-files-with-the-same-name-as-files",
    "title": "MITRE CAPEC-177: Create files with the same name as files protected with a higher classification (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-177 (Create files with the same name as files protected with a higher classification) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits file location algorithms in an operating system or application by creating a file with the same name as a protected or privileged file. The attacker could manipulate the system if the attacker-created file is trusted by the operating system or an application component that attempts to load the original file. Likelihood of attack: Unknown. Typical severity: Very High. Maps to weaknesses CWE-706. Relates to MITRE ATT&CK T1036.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-178-cross-site-flashing",
    "title": "MITRE CAPEC-178: Cross-Site Flashing (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-178 (Cross-Site Flashing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker is able to trick the victim into executing a Flash document that passes commands or calls to a Flash player browser plugin, allowing the attacker to exploit native Flash functionality in the client browser. This attack pattern occurs where an attacker can provide a crafted link to a Flash document (SWF file) which, when followed, will cause additional malicious instructions to be executed. Likelihood of attack: Medium. Typical severity: Medium. Maps to weaknesses CWE-601.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-179-calling-micro-services-directly",
    "title": "MITRE CAPEC-179: Calling Micro-Services Directly (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-179 (Calling Micro-Services Directly) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker is able to discover and query Micro-services at a web location and thereby expose the Micro-services to further exploitation by gathering information about their implementation and function. Micro-services in web pages allow portions of a page to connect to the server and update content without needing to cause the entire page to update. Likelihood of attack: Unknown. Typical severity: Medium.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-18-xss-targeting-non-script-elements",
    "title": "MITRE CAPEC-18: XSS Targeting Non-Script Elements (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-18 (XSS Targeting Non-Script Elements) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack is a form of Cross-Site Scripting (XSS) where malicious scripts are embedded in elements that are not expected to host scripts such as image tags ( ), comments in XML documents ( ), etc. These tags may not be subject to the same input validation, output validation, and other content filtering and checking routines, so this can create an opportunity for an adversary to tunnel through the application's. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-80.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-180-exploiting-incorrectly-configured-access-control-security-le",
    "title": "MITRE CAPEC-180: Exploiting Incorrectly Configured Access Control Security Levels (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-180 (Exploiting Incorrectly Configured Access Control Security Levels) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits a weakness in the configuration of access controls and is able to bypass the intended protection that these measures guard against and thereby obtain unauthorized access to the system or network. Sensitive functionality should always be protected with access controls. Likelihood of attack: High. Typical severity: Medium. Parent pattern for CAPEC-58 Restful Privilege Elevation; CAPEC-679 Exploitation of Improperly Configured or Implemented Memory Protections; CAPEC-680 Exploitation of Improperly Controlled Registers; and others. Maps to weaknesses CWE-732, CWE-1190, CWE-1191, CWE-1193, and others. Relates to MITRE ATT&CK T1574.010.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1574-014-appdomainmanager"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-181-flash-file-overlay",
    "title": "MITRE CAPEC-181: Flash File Overlay (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-181 (Flash File Overlay) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker creates a transparent overlay using flash in order to intercept user actions for the purpose of performing a clickjacking attack. In this technique, the Flash file provides a transparent overlay over HTML content. Because the Flash application is on top of the content, user actions, such as clicks, are caught by the Flash application rather than the underlying HTML. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-1021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-182-flash-injection",
    "title": "MITRE CAPEC-182: Flash Injection (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-182 (Flash Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker tricks a victim to execute malicious flash content that executes commands or makes flash calls specified by the attacker. One example of this attack is cross-site flashing, an attacker controlled parameter to a reference call loads from content specified by the attacker. Likelihood of attack: High. Typical severity: Medium. Parent pattern for CAPEC-174 Flash Parameter Injection; CAPEC-178 Cross-Site Flashing. Maps to weaknesses CWE-20, CWE-184, CWE-697.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-183-imap-smtp-command-injection",
    "title": "MITRE CAPEC-183: IMAP/SMTP Command Injection (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-183 (IMAP/SMTP Command Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits weaknesses in input validation on web-mail servers to execute commands on the IMAP/SMTP server. Web-mail servers often sit between the Internet and the IMAP or SMTP mail server. User requests are received by the web-mail servers which then query the back-end mail server for the requested information and return this response to the user. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-77.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-184-software-integrity-attack",
    "title": "MITRE CAPEC-184: Software Integrity Attack (Attack Pattern - Supply Chain Foundation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-184 (Software Integrity Attack) is an attack pattern in which an attacker initiates a series of events to cause a user, program, server, or device to perform actions that undermine the integrity of software code, device data structures, or device firmware. Typical severity is listed as Low on the CAPEC page, though real-world incidents (SolarWinds SUNBURST, XZ Utils backdoor, 3CX, MOVEit) demonstrate Very High operational impact. Maps to CWE-494 (Download of Code Without Integrity Check). Compliance: NIST SP 800-218 SSDF, US Executive Order 14028, CISA SBOM guidance, EU Cyber Resilience Act (CRA), NIST SP 800-161 supply chain, ISO/IEC 27036.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1574-hijack-execution-flow",
      "mitre-d3fend-d3-fim-file-integrity-monitoring",
      "mitre-d3fend-d3-sysm-system-mapping",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-185-malicious-software-download",
    "title": "MITRE CAPEC-185: Malicious Software Download (Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-185 (Malicious Software Download) is an attack pattern in which an attacker uses deceptive methods to cause a user or automated process to download and install dangerous code from an attacker-controlled source. Severity: Very High. Maps to CWE-494 (Download of Code Without Integrity Check). Parent: CAPEC-184 Software Integrity Attack. Compliance: NIST SP 800-53 SI-3/SI-7/SC-44, ISO 27001 A.8.7/A.8.23, EU Cyber Resilience Act, CISA #StopRansomware Guide.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1566-002-spearphishing-link",
      "mitre-attack-t1574-hijack-execution-flow",
      "mitre-d3fend-d3-fim-file-integrity-monitoring",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-186-malicious-software-update",
    "title": "MITRE CAPEC-186: Malicious Software Update (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-186 (Malicious Software Update) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses deceptive methods to cause a user or an automated process to download and install dangerous code believed to be a valid update that originates from an adversary controlled source. Likelihood of attack: Unknown. Typical severity: High. Parent pattern for CAPEC-187 Malicious Automated Software Update via Redirection; CAPEC-533 Malicious Manual Software Update; CAPEC-614 Rooting SIM Cards; and others. Maps to weaknesses CWE-494. Relates to MITRE ATT&CK T1195.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-187-malicious-automated-software-update-via-redirection",
    "title": "MITRE CAPEC-187: Malicious Automated Software Update via Redirection (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-187 (Malicious Automated Software Update via Redirection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits two layers of weaknesses in server or client software for automated update mechanisms to undermine the integrity of the target code-base. The first weakness involves a failure to properly authenticate a server as a source of update or patch content. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-494. Relates to MITRE ATT&CK T1072.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1072-software-deployment-tools"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-188-reverse-engineering",
    "title": "MITRE CAPEC-188: Reverse Engineering (Meta Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-188 (Reverse Engineering) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary discovers the structure, function, and composition of an object, resource, or system by using a variety of analysis techniques to effectively determine how the analyzed entity was constructed or operates. The goal of reverse engineering is often to duplicate the function, or a part of the function, of an object in order to duplicate or \"back engineer\" some aspect of its functioning. Likelihood of attack: Low. Typical severity: Low. Parent pattern for CAPEC-167 White Box Reverse Engineering; CAPEC-189 Black Box Reverse Engineering. Maps to weaknesses CWE-1278.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-189-black-box-reverse-engineering",
    "title": "MITRE CAPEC-189: Black Box Reverse Engineering (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-189 (Black Box Reverse Engineering) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary discovers the structure, function, and composition of a type of computer software through black box analysis techniques. 'Black Box' methods involve interacting with the software indirectly, in the absence of direct access to the executable object. Likelihood of attack: Unknown. Typical severity: Low. Parent pattern for CAPEC-621 Analysis of Packet Timing and Sizes; CAPEC-622 Electromagnetic Side-Channel Attack; CAPEC-623 Compromising Emanations Attack. Maps to weaknesses CWE-203, CWE-1255, CWE-1300.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-19-embedding-scripts-within-scripts",
    "title": "MITRE CAPEC-19: Embedding Scripts within Scripts (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-19 (Embedding Scripts within Scripts) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary leverages the capability to execute their own script by embedding it within other scripts that the target software is likely to execute due to programs' vulnerabilities that are brought on by allowing remote hosts to execute scripts. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-284. Relates to MITRE ATT&CK T1027.009, T1546.004, T1546.016.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1027-014-polymorphic-code",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-190-reverse-engineer-an-executable-to-expose-assumed-hidden",
    "title": "MITRE CAPEC-190: Reverse Engineer an Executable to Expose Assumed Hidden Functionality (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-190 (Reverse Engineer an Executable to Expose Assumed Hidden Functionality) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker analyzes a binary file or executable for the purpose of discovering the structure, function, and possibly source-code of the file by using a variety of analysis techniques to effectively determine how the software functions and operates. This type of analysis is also referred to as Reverse Code Engineering, as techniques exist for extracting source code from an executable. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-912.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-191-read-sensitive-constants-within-an-executable",
    "title": "MITRE CAPEC-191: Read Sensitive Constants Within an Executable (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-191 (Read Sensitive Constants Within an Executable) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in activities to discover any sensitive constants present within the compiled code of an executable. These constants may include literal ASCII strings within the file itself, or possibly strings hard-coded into particular routines that can be revealed by code refactoring methods including static and dynamic analysis. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-798. Relates to MITRE ATT&CK T1552.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1552-unsecured-credentials"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-192-protocol-analysis",
    "title": "MITRE CAPEC-192: Protocol Analysis (Meta Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-192 (Protocol Analysis) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in activities to decipher and/or decode protocol information for a network or application communication protocol used for transmitting information between interconnected nodes or systems on a packet-switched data network. While this type of analysis involves the analysis of a networking protocol inherently, it does not require the presence of an actual or physical network. Likelihood of attack: Low. Typical severity: Low. Parent pattern for CAPEC-97 Cryptanalysis. Maps to weaknesses CWE-326.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-193-php-remote-file-inclusion",
    "title": "MITRE CAPEC-193: PHP Remote File Inclusion (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-193 (PHP Remote File Inclusion) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this pattern the adversary is able to load and execute arbitrary code remotely available from the application. This is usually accomplished through an insecurely configured PHP runtime environment and an improperly sanitized \"include\" or \"require\" call, which the user can then control to point to any web-accessible file. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-98, CWE-80.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-194-fake-the-source-of-data",
    "title": "MITRE CAPEC-194: Fake the Source of Data (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-194 (Fake the Source of Data) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of improper authentication to provide data or services under a falsified identity. The purpose of using the falsified identity may be to prevent traceability of the provided data or to assume the rights granted to another individual. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-275 DNS Rebinding; CAPEC-543 Counterfeit Websites; CAPEC-544 Counterfeit Organizations; and others. Maps to weaknesses CWE-287.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-195-principal-spoof",
    "title": "MITRE CAPEC-195: Principal Spoof (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-195 (Principal Spoof) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. A Principal Spoof is a form of Identity Spoofing where an adversary pretends to be some other person in an interaction. This is often accomplished by crafting a message (either written, verbal, or visual) that appears to come from a person other than the adversary. Phishing and Pharming attacks often attempt to do this so that their attempts to gather sensitive information appear to come from a legitimate source. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-599 Terrestrial Jamming.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-196-session-credential-falsification-through-forging",
    "title": "MITRE CAPEC-196: Session Credential Falsification through Forging (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-196 (Session Credential Falsification through Forging) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker creates a false but functional session credential in order to gain or usurp access to a service. Session credentials allow users to identify themselves to a service after an initial authentication without needing to resend the authentication information (usually a username and password) with every message. Likelihood of attack: Medium. Typical severity: Medium. Parent pattern for CAPEC-226 Session Credential Falsification through Manipulation; CAPEC-59 Session Credential Falsification through Prediction. Maps to weaknesses CWE-384, CWE-664. Relates to MITRE ATT&CK T1134.002, T1134.003, T1606.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1134-access-token-manipulation",
      "mitre-attack-t1606-forge-web-credentials"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-capec-capec-197-exponential-data-expansion",
    "title": "MITRE CAPEC-197: Exponential Data Expansion (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-197 (Exponential Data Expansion) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary submits data to a target application which contains nested exponential data expansion to produce excessively large output. Many data format languages allow the definition of macro-like structures that can be used to simplify the creation of complex structures. However, this capability can be abused to create excessive demands on a processor's CPU and memory. Likelihood of attack: High. Typical severity: Medium. Maps to weaknesses CWE-770, CWE-776.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-198-xss-targeting-error-pages",
    "title": "MITRE CAPEC-198: XSS Targeting Error Pages (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-198 (XSS Targeting Error Pages) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary distributes a link (or possibly some other query structure) with a request to a third party web server that is malformed and also contains a block of exploit code in order to have the exploit become live code in the resulting error page. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-81.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-199-xss-using-alternate-syntax",
    "title": "MITRE CAPEC-199: XSS Using Alternate Syntax (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-199 (XSS Using Alternate Syntax) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses alternate forms of keywords or commands that result in the same action as the primary form but which may not be caught by filters. For example, many keywords are processed in a case insensitive manner. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-87.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-2-inducing-account-lockout",
    "title": "MITRE CAPEC-2: Inducing Account Lockout (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-2 (Inducing Account Lockout) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker leverages the security functionality of the system aimed at thwarting potential attacks to launch a denial of service attack against a legitimate system user. Many systems, for instance, implement a password throttling mechanism that locks an account after a certain number of incorrect log in attempts. An attacker can leverage this throttling mechanism to lock a legitimate user out of their own account. Likelihood of attack: High. Typical severity: Medium. Maps to weaknesses CWE-645. Relates to MITRE ATT&CK T1531.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1531-account-access-removal"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-20-encryption-brute-forcing",
    "title": "MITRE CAPEC-20: Encryption Brute Forcing (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-20 (Encryption Brute Forcing) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker, armed with the cipher text and the encryption algorithm used, performs an exhaustive (brute force) search on the key space to determine the key that decrypts the cipher text to obtain the plaintext. Likelihood of attack: Low. Typical severity: Low. Maps to weaknesses CWE-326, CWE-327, CWE-693, CWE-1204.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-200-removal-of-filters-input-filters-output-filters-data",
    "title": "MITRE CAPEC-200: Removal of filters: Input filters, output filters, data masking (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-200 (Removal of filters: Input filters, output filters, data masking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker removes or disables filtering mechanisms on the target application. Input filters prevent invalid data from being sent to an application (for example, overly large inputs that might cause a buffer overflow or other malformed inputs that may not be correctly handled by an application). Input filters might also be designed to constrained executable content. Likelihood of attack: Unknown. Typical severity: Medium.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-201-serialized-data-external-linking",
    "title": "MITRE CAPEC-201: Serialized Data External Linking (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-201 (Serialized Data External Linking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary creates a serialized data file (e.g. XML, YAML, etc...) that contains an external data reference. Because serialized data parsers may not validate documents with external references, there may be no checks on the nature of the reference in the external data. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-829.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-202-create-malicious-client",
    "title": "MITRE CAPEC-202: Create Malicious Client (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-202 (Create Malicious Client) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary creates a client application to interface with a target service where the client violates assumptions the service makes about clients. Services that have designated client applications (as opposed to services that use general client applications, such as IMAP or POP mail servers which can interact with any IMAP or POP client) may assume that the client will follow specific procedures. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-602.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-203-manipulate-registry-information",
    "title": "MITRE CAPEC-203: Manipulate Registry Information (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-203 (Manipulate Registry Information) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in authorization in order to modify content within a registry (e.g., Windows Registry, Mac plist, application registry). Editing registry information can permit the adversary to hide configuration information or remove indicators of compromise to cover up activity. Many applications utilize registries to store configuration and service information. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-270 Modification of Registry Run Keys; CAPEC-478 Modification of Windows Service Configuration; CAPEC-51 Poison Web Service Registry. Maps to weaknesses CWE-15. Relates to MITRE ATT&CK T1112, T1647.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1112-modify-registry",
      "mitre-attack-t1647-plist-file-modification"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-204-lifting-sensitive-data-embedded-in-cache",
    "title": "MITRE CAPEC-204: Lifting Sensitive Data Embedded in Cache (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-204 (Lifting Sensitive Data Embedded in Cache) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary examines a target application's cache, or a browser cache, for sensitive information. Many applications that communicate with remote entities or which perform intensive calculations utilize caches to improve efficiency. However, if the application computes or receives sensitive information and the cache is not appropriately protected, an attacker can browse the cache and retrieve this information. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-524, CWE-311, CWE-1239, CWE-1258. Relates to MITRE ATT&CK T1005.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1005-data-from-local-system"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-capec-capec-206-signing-malicious-code",
    "title": "MITRE CAPEC-206: Signing Malicious Code (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-206 (Signing Malicious Code) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary extracts credentials used for code signing from a production environment and then uses these credentials to sign malicious content with the developer's key. Many developers use signing keys to sign code or hashes of code. Likelihood of attack: Unknown. Typical severity: Very High. Maps to weaknesses CWE-732. Relates to MITRE ATT&CK T1553.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1553-subvert-trust-controls"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-207-removing-important-client-functionality",
    "title": "MITRE CAPEC-207: Removing Important Client Functionality (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-207 (Removing Important Client Functionality) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary removes or disables functionality on the client that the server assumes to be present and trustworthy. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-200 Removal of filters: Input filters, output filters, data masking; CAPEC-208 Removing/short-circuiting 'Purse' logic: removing/mutating 'cash' decrements. Maps to weaknesses CWE-602.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-208-removing-short-circuiting-purse-logic-removing-mutating-cash",
    "title": "MITRE CAPEC-208: Removing/short-circuiting 'Purse' logic: removing/mutating 'cash' decrements (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-208 (Removing/short-circuiting 'Purse' logic: removing/mutating 'cash' decrements) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker removes or modifies the logic on a client associated with monetary calculations resulting in incorrect information being sent to the server. A server may rely on a client to correctly compute monetary information. For example, a server might supply a price for an item and then rely on the client to correctly compute the total cost of a purchase given the number of items the user is buying. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-602.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-209-xss-using-mime-type-mismatch",
    "title": "MITRE CAPEC-209: XSS Using MIME Type Mismatch (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-209 (XSS Using MIME Type Mismatch) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary creates a file with scripting content but where the specified MIME type of the file is such that scripting is not expected. The adversary tricks the victim into accessing a URL that responds with the script file. Some browsers will detect that the specified MIME type of the file does not match the actual type of its content and will automatically switch to using an interpreter for the real content type. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-79, CWE-20, CWE-646.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-21-exploitation-of-trusted-identifiers",
    "title": "MITRE CAPEC-21: Exploitation of Trusted Identifiers (Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-21 (Exploitation of Trusted Identifiers) is an attack pattern in which an adversary manipulates trusted identifiers (session IDs, cookies, access tokens, SAML assertions, OAuth tokens) to impersonate authenticated users. Prerequisites: weak identifier proof/verification schemes, long-lifetime reusable identifiers, concurrent sessions allowed. Likelihood: High. Severity: High. Maps to MITRE ATT&CK T1134 (Access Token Manipulation), T1528 (Steal Application Access Token), T1539 (Steal Web Session Cookie). CWE-290, CWE-302, CWE-384, CWE-539. Compliance: OWASP ASVS V3, PCI DSS, NIS2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1539-steal-web-session-cookie",
      "mitre-attack-t1078-valid-accounts",
      "mitre-d3fend-d3-anci-authentication-cache-invalidation",
      "mitre-d3fend-d3-mfa-multi-factor-authentication",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-212-functionality-misuse",
    "title": "MITRE CAPEC-212: Functionality Misuse (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-212 (Functionality Misuse) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary leverages a legitimate capability of an application in such a way as to achieve a negative technical impact. The system functionality is not altered or modified but used in a way that was not intended. This is often accomplished through the overuse of a specific functionality or by leveraging functionality with design flaws that enables the adversary to gain access to unauthorized, sensitive data. Likelihood of attack: Medium. Typical severity: Medium. Parent pattern for CAPEC-111 JSON Hijacking (aka JavaScript Hijacking); CAPEC-2 Inducing Account Lockout; CAPEC-48 Passing Local Filenames to Functions That Expect a URL; and others. Maps to weaknesses CWE-1242, CWE-1246, CWE-1281.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-215-fuzzing-for-application-mapping",
    "title": "MITRE CAPEC-215: Fuzzing for application mapping (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-215 (Fuzzing for application mapping) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker sends random, malformed, or otherwise unexpected messages to a target application and observes the application's log or error messages returned. The attacker does not initially know how a target will respond to individual messages but by attempting a large number of message variants they may find a variant that trigger's desired behavior. Likelihood of attack: High. Typical severity: Low. Maps to weaknesses CWE-209, CWE-532.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-216-communication-channel-manipulation",
    "title": "MITRE CAPEC-216: Communication Channel Manipulation (Meta Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-216 (Communication Channel Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates a setting or parameter on communications channel in order to compromise its security. This can result in information exposure, insertion/removal of information from the communications stream, and/or potentially system compromise. Likelihood of attack: Unknown. Parent pattern for CAPEC-12 Choosing Message Identifier; CAPEC-217 Exploiting Incorrectly Configured SSL/TLS. Maps to weaknesses CWE-306.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-217-exploiting-incorrectly-configured-ssl-tls",
    "title": "MITRE CAPEC-217: Exploiting Incorrectly Configured SSL/TLS (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-217 (Exploiting Incorrectly Configured SSL/TLS) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of incorrectly configured SSL/TLS communications that enables access to data intended to be encrypted. The adversary may also use this type of attack to inject commands or other traffic into the encrypted stream to cause compromise of either the client or server. Likelihood of attack: Low. Maps to weaknesses CWE-201.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-218-spoofing-of-uddi-ebxml-messages",
    "title": "MITRE CAPEC-218: Spoofing of UDDI/ebXML Messages (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-218 (Spoofing of UDDI/ebXML Messages) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker spoofs a UDDI, ebXML, or similar message in order to impersonate a service provider in an e-business transaction. UDDI, ebXML, and similar standards are used to identify businesses in e-business transactions. Among other things, they identify a particular participant, WSDL information for SOAP transactions, and supported communication protocols, including security protocols. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-345.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-219-xml-routing-detour-attacks",
    "title": "MITRE CAPEC-219: XML Routing Detour Attacks (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-219 (XML Routing Detour Attacks) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker subverts an intermediate system used to process XML content and forces the intermediate to modify and/or re-route the processing of the content. XML Routing Detour Attacks are Adversary in the Middle type attacks (CAPEC-94). The attacker compromises or inserts an intermediate system in the processing of the XML message. Likelihood of attack: High. Typical severity: Medium. Maps to weaknesses CWE-441, CWE-610.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-22-exploiting-trust-in-client",
    "title": "MITRE CAPEC-22: Exploiting Trust in Client (Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-22 (Exploiting Trust in Client) is an attack pattern in which an attacker communicates directly with the server where the server believes it is communicating only with a valid client. Likelihood: High. Severity: High. Maps to CWE-290 (Authentication Bypass by Spoofing), CWE-287 (Improper Authentication), CWE-20 (Improper Input Validation), CWE-200, CWE-693. Compliance: OWASP ASVS V13 (API Security), V5 (Validation, Sanitization, Encoding), PCI DSS v4.0 Req 8.4, NIS2 Article 21(2)(j), HIPAA Security Rule.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-d3fend-d3-ch-credential-hardening",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-220-client-server-protocol-manipulation",
    "title": "MITRE CAPEC-220: Client-Server Protocol Manipulation (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-220 (Client-Server Protocol Manipulation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of weaknesses in the protocol by which a client and server are communicating to perform unexpected actions. Communication protocols are necessary to transfer messages between client and server applications. Moreover, different protocols may be used for different types of interactions. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-105 HTTP Request Splitting; CAPEC-273 HTTP Response Smuggling; CAPEC-274 HTTP Verb Tampering; and others. Maps to weaknesses CWE-757.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-221-data-serialization-external-entities-blowup",
    "title": "MITRE CAPEC-221: Data Serialization External Entities Blowup (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-221 (Data Serialization External Entities Blowup) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack takes advantage of the entity replacement property of certain data serialization languages (e.g., XML, YAML, etc.) where the value of the replacement is a URI. A well-crafted file could have the entity refer to a URI that consumes a large amount of resources to create a denial of service condition. This can cause the system to either freeze, crash, or execute arbitrary code depending on the URI. Likelihood of attack: Unknown. Maps to weaknesses CWE-611.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-222-iframe-overlay",
    "title": "MITRE CAPEC-222: iFrame Overlay (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-222 (iFrame Overlay) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In an iFrame overlay attack the victim is tricked into unknowingly initiating some action in one system while interacting with the UI from seemingly completely different system. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-1021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-224-fingerprinting",
    "title": "MITRE CAPEC-224: Fingerprinting (Meta Attack Pattern - Very Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-224 (Fingerprinting) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary compares output from a target system to known indicators that uniquely identify specific details about the target. Most commonly, fingerprinting is done to determine operating system and application versions. Fingerprinting can be done passively as well as actively. Fingerprinting by itself is not usually detrimental to the target. Likelihood of attack: High. Typical severity: Very Low. Parent pattern for CAPEC-312 Active OS Fingerprinting; CAPEC-313 Passive OS Fingerprinting; CAPEC-541 Application Fingerprinting. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-226-session-credential-falsification-through-manipulation",
    "title": "MITRE CAPEC-226: Session Credential Falsification through Manipulation (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-226 (Session Credential Falsification through Manipulation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates an existing credential in order to gain access to a target application. Session credentials allow users to identify themselves to a service after an initial authentication without needing to resend the authentication information (usually a username and password) with every message. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-565, CWE-472.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-227-sustained-client-engagement",
    "title": "MITRE CAPEC-227: Sustained Client Engagement (Meta Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-227 (Sustained Client Engagement) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary attempts to deny legitimate users access to a resource by continually engaging a specific resource in an attempt to keep the resource tied up as long as possible. The adversary's primary goal is not to crash or flood the target, which would alert defenders; rather it is to repeatedly perform actions or abuse algorithmic flaws such that a given resource is tied up and not available to a legitimate user. Likelihood of attack: Unknown. Parent pattern for CAPEC-469 HTTP DoS. Maps to weaknesses CWE-400. Relates to MITRE ATT&CK T1499.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1499-004-application-or-system-exploitation"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-228-dtd-injection",
    "title": "MITRE CAPEC-228: DTD Injection (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-228 (DTD Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker injects malicious content into an application's DTD in an attempt to produce a negative technical impact. DTDs are used to describe how XML documents are processed. Certain malformed DTDs (for example, those with excessive entity expansion as described in CAPEC 197) can cause the XML parsers that process the DTDs to consume excessive resources resulting in resource depletion. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-829.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-229-serialized-data-parameter-blowup",
    "title": "MITRE CAPEC-229: Serialized Data Parameter Blowup (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-229 (Serialized Data Parameter Blowup) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack exploits certain serialized data parsers (e.g., XML, YAML, etc.) which manage data in an inefficient manner. The attacker crafts an serialized data file with multiple configuration parameters in the same dataset. In a vulnerable parser, this results in a denial of service condition where CPU resources are exhausted because of the parsing algorithm. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-770.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-23-file-content-injection",
    "title": "MITRE CAPEC-23: File Content Injection (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-23 (File Content Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary poisons files with a malicious payload (targeting the file systems accessible by the target software), which may be passed through by standard channels such as via email, and standard web content like PDF and multimedia files. The adversary exploits known vulnerabilities or handling routines in the target processes, in order to exploit the host's trust in executing remote content, including binary files. Likelihood of attack: High. Typical severity: Very High. Parent pattern for CAPEC-44 Overflow Binary Resource File. Maps to weaknesses CWE-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-230-serialized-data-with-nested-payloads",
    "title": "MITRE CAPEC-230: Serialized Data with Nested Payloads (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-230 (Serialized Data with Nested Payloads) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Applications often need to transform data in and out of a data format (e.g., XML and YAML) by using a parser. It may be possible for an adversary to inject data that may have an adverse effect on the parser when it is being processed. Many data format languages allow the definition of macro-like structures that can be used to simplify the creation of complex structures. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-197 Exponential Data Expansion; CAPEC-491 Quadratic Data Expansion. Maps to weaknesses CWE-112, CWE-20, CWE-674, CWE-770.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-231-oversized-serialized-data-payloads",
    "title": "MITRE CAPEC-231: Oversized Serialized Data Payloads (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-231 (Oversized Serialized Data Payloads) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary injects oversized serialized data payloads into a parser during data processing to produce adverse effects upon the parser such as exhausting system resources and arbitrary code execution. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-221 Data Serialization External Entities Blowup; CAPEC-229 Serialized Data Parameter Blowup. Maps to weaknesses CWE-112, CWE-20, CWE-674, CWE-770.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-233-privilege-escalation",
    "title": "MITRE CAPEC-233: Privilege Escalation (Meta Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-233 (Privilege Escalation) is a meta-level attack pattern in which an adversary exploits a weakness enabling elevation of privilege to perform unauthorized actions. Page references OWASP Web Security Testing Guide for testing. Maps to MITRE ATT&CK T1548 (Abuse Elevation Control Mechanism) and CWE-269 (Improper Privilege Management), CWE-1264, CWE-1311. Compliance: NIST SP 800-53 AC-6, ISO/IEC 27001 A.8.2, PCI DSS Req 7, NIS2 Art 21(2)(j), CISA Phishing-Resistant MFA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1068-exploitation-privilege-escalation",
      "mitre-attack-t1078-valid-accounts",
      "mitre-capec-capec-122-privilege-abuse",
      "mitre-d3fend-d3-ch-credential-hardening",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-234-hijacking-a-privileged-process",
    "title": "MITRE CAPEC-234: Hijacking a privileged process (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-234 (Hijacking a privileged process) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary gains control of a process that is assigned elevated privileges in order to execute arbitrary code with those privileges. Some processes are assigned elevated privileges on an operating system, usually through association with a particular user, group, or role. If an attacker can hijack this process, they will be able to assume its level of privilege in order to execute their own code. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-732, CWE-648.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-237-escaping-a-sandbox-by-calling-code-in-another",
    "title": "MITRE CAPEC-237: Escaping a Sandbox by Calling Code in Another Language (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-237 (Escaping a Sandbox by Calling Code in Another Language) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The attacker may submit malicious code of another language to obtain access to privileges that were not intentionally exposed by the sandbox, thus escaping the sandbox. For instance, Java code cannot perform unsafe operations, such as modifying arbitrary memory locations, due to restrictions placed on it by the Byte code Verifier and the JVM. Likelihood of attack: Low. Typical severity: Very High. Maps to weaknesses CWE-693.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-24-filter-failure-through-buffer-overflow",
    "title": "MITRE CAPEC-24: Filter Failure through Buffer Overflow (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-24 (Filter Failure through Buffer Overflow) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack, the idea is to cause an active filter to fail by causing an oversized transaction. An attacker may try to feed overly long input strings to the program in an attempt to overwhelm the filter (by causing a buffer overflow) and hoping that the filter does not fail securely (i.e. the user input is let into the system unfiltered). Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-120, CWE-119, CWE-118, CWE-74, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-240-resource-injection",
    "title": "MITRE CAPEC-240: Resource Injection (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-240 (Resource Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits weaknesses in input validation by manipulating resource identifiers enabling the unintended modification or specification of a resource. Likelihood of attack: High. Typical severity: High. Parent pattern for CAPEC-610 Cellular Data Injection. Maps to weaknesses CWE-99.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-242-code-injection",
    "title": "MITRE CAPEC-242: Code Injection (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-242 (Code Injection) is a meta-level attack pattern in which an adversary exploits a weakness in input validation on the target to inject new code into that which is currently executing. Likelihood of attack: High. Typical severity: High. CAPEC-242 is the parent pattern for CAPEC-63 Cross-Site Scripting, CAPEC-23 File Content Injection, CAPEC-19 Embedding Scripts within Scripts. Maps to CWE-94 (Improper Control of Generation of Code). Compliance: OWASP ASVS V5.3, OWASP Top 10 A03:2021, PCI DSS v4.0 Req 6.2, NIST SP 800-53 SI-10, ISO/IEC 27001 (secure coding).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1059-command-and-scripting-interpreter",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-243-xss-targeting-html-attributes",
    "title": "MITRE CAPEC-243: XSS Targeting HTML Attributes (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-243 (XSS Targeting HTML Attributes) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary inserts commands to perform cross-site scripting (XSS) actions in HTML attributes. Many filters do not adequately sanitize attributes against the presence of potentially dangerous commands even if they adequately sanitize tags. For example, dangerous expressions could be inserted into a style attribute in an anchor tag, resulting in the execution of malicious code when the resulting page is rendered. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-83.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-244-xss-targeting-uri-substitution-fields",
    "title": "MITRE CAPEC-244: XSS Targeting URI Placeholders (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-07-23",
    "bluf": "MITRE CAPEC-244 (XSS Targeting URI Substitution Fields) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type exploits the ability of most browsers to interpret \"data\", \"javascript\" or other URI schemes as client-side executable content placeholders. This attack consists of passing a malicious URI in an anchor tag HREF attribute or any other similar attributes in other HTML tags. Such malicious URI contains, for example, a base64 encoded HTML content with an embedded cross-site scripting payload. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-83.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-245-xss-using-doubled-characters",
    "title": "MITRE CAPEC-245: XSS Using Doubled Characters (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-245 (XSS Using Doubled Characters) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary bypasses input validation by using doubled characters in order to perform a cross-site scripting attack. Some filters fail to recognize dangerous sequences if they are preceded by repeated characters. For example, by doubling the < before a script command, (<<script or %3C%3script using URI encoding) the filters of some web applications may fail to recognize the presence of a script tag. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-85.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-247-xss-using-invalid-characters",
    "title": "MITRE CAPEC-247: XSS Using Invalid Characters (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-247 (XSS Using Invalid Characters) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary inserts invalid characters in identifiers to bypass application filtering of input. Filters may not scan beyond invalid characters but during later stages of processing content that follows these invalid characters may still be processed. This allows the adversary to sneak prohibited commands past filters and perform normally prohibited operations. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-86.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-248-command-injection",
    "title": "MITRE CAPEC-248: Command Injection (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-248 (Command Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary looking to execute a command of their choosing, injects new items into an existing command thus modifying interpretation away from what was intended. Commands in this context are often standalone strings that are interpreted by a downstream component and cause specific responses. This type of attack is possible when untrusted values are used to build these command strings. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-136 LDAP Injection; CAPEC-183 IMAP/SMTP Command Injection; CAPEC-250 XML Injection; and others. Maps to weaknesses CWE-77.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-25-forced-deadlock",
    "title": "MITRE CAPEC-25: Forced Deadlock (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-25 (Forced Deadlock) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary triggers and exploits a deadlock condition in the target software to cause a denial of service. A deadlock can occur when two or more competing actions are waiting for each other to finish, and thus neither ever does. Deadlock conditions can be difficult to detect. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-412, CWE-567, CWE-662, CWE-667, and others. Relates to MITRE ATT&CK T1499.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1499-004-application-or-system-exploitation"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-250-xml-injection",
    "title": "MITRE CAPEC-250: XML Injection (Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-250 (XML Injection) is an attack pattern in which an attacker uses crafted XML user-controllable input to probe, attack, and inject data into the XML database using techniques similar to SQL injection. Likelihood: High. Maps to CWE-91 (XML Injection / Blind XPath Injection), CWE-74 (Improper Neutralization), CWE-20 (Improper Input Validation), CWE-707. Child patterns: CAPEC-83 XPath Injection, CAPEC-84 XQuery Injection, CAPEC-228 DTD Injection. Compliance: OWASP ASVS V5, OWASP Top 10 A03, NIST SP 800-53 SI-10, PCI DSS Req 6.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-capec-capec-66-sql-injection",
      "mitre-capec-capec-153-input-data-manipulation",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-251-local-code-inclusion",
    "title": "MITRE CAPEC-251: Local Code Inclusion (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-251 (Local Code Inclusion) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The attacker forces an application to load arbitrary code files from the local machine. The attacker could use this to try to load old versions of library files that have known vulnerabilities, to load files that the attacker placed on the local machine during a prior attack, or to otherwise change the functionality of the targeted application in unexpected ways. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-252 PHP Local File Inclusion; CAPEC-640 Inclusion of Code in Existing Process; CAPEC-660 Root/Jailbreak Detection Evasion via Hooking. Maps to weaknesses CWE-829. Relates to MITRE ATT&CK T1055.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-252-php-local-file-inclusion",
    "title": "MITRE CAPEC-252: PHP Local File Inclusion (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-252 (PHP Local File Inclusion) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The attacker loads and executes an arbitrary local PHP file on a target machine. The attacker could use this to try to load old versions of PHP files that have known vulnerabilities, to load PHP files that the attacker placed on the local machine during a prior attack, or to otherwise change the functionality of the targeted application in unexpected ways. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-829.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-253-remote-code-inclusion",
    "title": "MITRE CAPEC-253: Remote Code Inclusion (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-253 (Remote Code Inclusion) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The attacker forces an application to load arbitrary code files from a remote location. The attacker could use this to try to load old versions of library files that have known vulnerabilities, to load malicious files that the attacker placed on the remote machine, or to otherwise change the functionality of the targeted application in unexpected ways. Likelihood of attack: Unknown. Parent pattern for CAPEC-101 Server Side Include (SSI) Injection; CAPEC-193 PHP Remote File Inclusion; CAPEC-500 WebView Injection. Maps to weaknesses CWE-829.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-256-soap-array-overflow",
    "title": "MITRE CAPEC-256: SOAP Array Overflow (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-256 (SOAP Array Overflow) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker sends a SOAP request with an array whose actual length exceeds the length indicated in the request. If the server processing the transmission naively trusts the specified size, then an attacker can intentionally understate the size of the array, possibly resulting in a buffer overflow if the server attempts to read the entire data set into the memory it allocated for a smaller array. Likelihood of attack: Unknown. Typical severity: High. Maps to weaknesses CWE-805.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-26-leveraging-race-conditions",
    "title": "MITRE CAPEC-26: Leveraging Race Conditions (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-26 (Leveraging Race Conditions) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary targets a race condition occurring when multiple processes access and manipulate the same resource concurrently, and the outcome of the execution depends on the particular order in which the access takes place. The adversary can leverage a race condition by \"running the race\", modifying the resource and modifying the normal execution flow. Likelihood of attack: High. Typical severity: High. Parent pattern for CAPEC-29 Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. Maps to weaknesses CWE-368, CWE-363, CWE-366, CWE-370, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-261-fuzzing-for-garnering-other-adjacent-user-sensitive-data",
    "title": "MITRE CAPEC-261: Fuzzing for garnering other adjacent user/sensitive data (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-261 (Fuzzing for garnering other adjacent user/sensitive data) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary who is authorized to send queries to a target sends variants of expected queries in the hope that these modified queries might return information (directly or indirectly through error logs) beyond what the expected set of queries should provide. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-263-force-use-of-corrupted-files",
    "title": "MITRE CAPEC-263: Force Use of Corrupted Files (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-263 (Force Use of Corrupted Files) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This describes an attack where an application is forced to use a file that an attacker has corrupted. The result is often a denial of service caused by the application being unable to process the corrupted file, but other results, including the disabling of filters or access controls (if the application fails in an unsafe way rather than failing by locking down) or buffer overflows are possible. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-829.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-267-leverage-alternate-encoding",
    "title": "MITRE CAPEC-267: Leverage Alternate Encoding (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-267 (Leverage Alternate Encoding) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary leverages the possibility to encode potentially harmful input or content used by applications such that the applications are ineffective at validating this encoding standard. Likelihood of attack: High. Typical severity: High. Parent pattern for CAPEC-120 Double Encoding; CAPEC-3 Using Leading 'Ghost' Character Sequences to Bypass Input Filters; CAPEC-4 Using Alternative IP Address Encodings; and others. Maps to weaknesses CWE-173, CWE-172, CWE-180, CWE-181, and others. Relates to MITRE ATT&CK T1027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1027-014-polymorphic-code"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-268-audit-log-manipulation",
    "title": "MITRE CAPEC-268: Audit Log Manipulation (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-268 (Audit Log Manipulation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The attacker injects, manipulates, deletes, or forges malicious log entries into the log file, in an attempt to mislead an audit of the log file or cover tracks of an attack. Due to either insufficient access controls of the log files or the logging mechanism, the attacker is able to perform such actions. Likelihood of attack: Unknown. Parent pattern for CAPEC-81 Web Server Logs Tampering; CAPEC-93 Log Injection-Tampering-Forging. Maps to weaknesses CWE-117. Relates to MITRE ATT&CK T1070, T1562.002, T1562.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1070-indicator-removal",
      "mitre-attack-t1685-004-disable-or-modify-linux-audit-system-log"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-27-leveraging-race-conditions-via-symbolic-links",
    "title": "MITRE CAPEC-27: Leveraging Race Conditions via Symbolic Links (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-27 (Leveraging Race Conditions via Symbolic Links) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack leverages the use of symbolic links (Symlinks) in order to write to sensitive files. An attacker can create a Symlink link to a target file not otherwise accessible to them. When the privileged program tries to create a temporary file with the same name as the Symlink link, it will actually write to the target file pointed to by the attackers' Symlink link. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-367, CWE-61, CWE-662, CWE-689, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-270-modification-of-registry-run-keys",
    "title": "MITRE CAPEC-270: Modification of Registry Run Keys (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-270 (Modification of Registry Run Keys) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary adds a new entry to the \"run keys\" in the Windows registry so that an application of their choosing is executed when a user logs in. In this way, the adversary can get their executable to operate and run on the target system with the authorized user's level of permissions. This attack is a good way for an adversary to run persistent spyware on a user's machine, such as a keylogger. Likelihood of attack: Medium. Typical severity: Medium. Maps to weaknesses CWE-15. Relates to MITRE ATT&CK T1547.001, T1547.014.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1547-015-login-items"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-271-schema-poisoning",
    "title": "MITRE CAPEC-271: Schema Poisoning (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-271 (Schema Poisoning) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary corrupts or modifies the content of a schema for the purpose of undermining the security of the target. Schemas provide the structure and content definitions for resources used by an application. By replacing or modifying a schema, the adversary can affect how the application handles or interprets a resource, often leading to possible denial of service, entering into an unexpected state, or recording. Likelihood of attack: Low. Typical severity: High. Parent pattern for CAPEC-146 XML Schema Poisoning. Maps to weaknesses CWE-15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-272-protocol-manipulation",
    "title": "MITRE CAPEC-272: Protocol Manipulation (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-272 (Protocol Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary subverts a communications protocol to perform an attack. This type of attack can allow an adversary to impersonate others, discover sensitive information, control the outcome of a session, or perform other attacks. This type of attack targets invalid assumptions that may be inherent in implementers of the protocol, incorrect implementations of the protocol, or vulnerabilities in the protocol itself. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-220 Client-Server Protocol Manipulation; CAPEC-276 Inter-component Protocol Manipulation; CAPEC-277 Data Interchange Protocol Manipulation; and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-273-http-response-smuggling",
    "title": "MITRE CAPEC-273: HTTP Response Smuggling (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-273 (HTTP Response Smuggling) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates and injects malicious content in the form of secret unauthorized HTTP responses, into a single HTTP response from a vulnerable or compromised back-end HTTP agent (e.g., server). See CanPrecede relationships for possible consequences. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-74, CWE-436, CWE-444.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-274-http-verb-tampering",
    "title": "MITRE CAPEC-274: HTTP Verb Tampering (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-274 (HTTP Verb Tampering) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker modifies the HTTP Verb (e.g. GET, PUT, TRACE, etc.) in order to bypass access restrictions. Some web environments allow administrators to restrict access based on the HTTP Verb used with requests. However, attackers can often provide a different HTTP Verb, or even provide a random string as a verb in order to bypass these protections. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-302, CWE-654.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-275-dns-rebinding",
    "title": "MITRE CAPEC-275: DNS Rebinding (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-275 (DNS Rebinding) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary serves content whose IP address is resolved by a DNS server that the adversary controls. After initial contact by a web browser (or similar client), the adversary changes the IP address to which its name resolves, to an address within the target organization that is not publicly accessible. This allows the web browser to examine this internal address on behalf of the adversary. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-350.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-276-inter-component-protocol-manipulation",
    "title": "MITRE CAPEC-276: Inter-component Protocol Manipulation (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-276 (Inter-component Protocol Manipulation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Inter-component protocols are used to communicate between different software and hardware modules within a single computer. Common examples are: interrupt signals and data pipes. Subverting the protocol can allow an adversary to impersonate others, discover sensitive information, control the outcome of a session, or perform other attacks. Likelihood of attack: Unknown. Parent pattern for CAPEC-665 Exploitation of Thunderbolt Protection Flaws. Maps to weaknesses CWE-707.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-277-data-interchange-protocol-manipulation",
    "title": "MITRE CAPEC-277: Data Interchange Protocol Manipulation (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-277 (Data Interchange Protocol Manipulation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Data Interchange Protocols are used to transmit structured data between entities. These protocols are often specific to a particular domain (B2B: purchase orders, invoices, transport logistics and waybills, medical records). They are often, but not always, XML-based. Likelihood of attack: Unknown. Maps to weaknesses CWE-707.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-278-web-services-protocol-manipulation",
    "title": "MITRE CAPEC-278: Web Services Protocol Manipulation (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-278 (Web Services Protocol Manipulation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates a web service related protocol to cause a web application or service to react differently than intended. This can either be performed through the manipulation of call parameters to include unexpected values, or by changing the called function to one that should normally be restricted or limited. Likelihood of attack: Unknown. Parent pattern for CAPEC-201 Serialized Data External Linking; CAPEC-221 Data Serialization External Entities Blowup; CAPEC-279 SOAP Manipulation. Maps to weaknesses CWE-707.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-279-soap-manipulation",
    "title": "MITRE CAPEC-279: SOAP Manipulation (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-279 (SOAP Manipulation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Simple Object Access Protocol (SOAP) is used as a communication protocol between a client and server to invoke web services on the server. It is an XML-based protocol, and therefore suffers from many of the same shortcomings as other XML-based protocols. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-707.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-28-fuzzing",
    "title": "MITRE CAPEC-28: Fuzzing (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-28 (Fuzzing) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, the adversary leverages fuzzing to try to identify weaknesses in the system. Fuzzing is a software security and functionality testing method that feeds randomly constructed input to the system and looks for an indication that a failure in response to that input has occurred. Fuzzing treats the system as a black box and is totally free from any preconceptions or assumptions about the system. Likelihood of attack: High. Typical severity: Medium. Parent pattern for CAPEC-215 Fuzzing for application mapping. Maps to weaknesses CWE-74, CWE-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-285-icmp-echo-request-ping",
    "title": "MITRE CAPEC-285: ICMP Echo Request Ping (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-285 (ICMP Echo Request Ping) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends out an ICMP Type 8 Echo Request, commonly known as a 'Ping', in order to determine if a target system is responsive. If the request is not blocked by a firewall or ACL, the target host will respond with an ICMP Type 0 Echo Reply datagram. This type of exchange is usually referred to as a 'Ping' due to the Ping utility present in almost all operating systems. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-287-tcp-syn-scan",
    "title": "MITRE CAPEC-287: TCP SYN Scan (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-287 (TCP SYN Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a SYN scan to determine the status of ports on the remote target. SYN scanning is the most common type of port scanning that is used because of its many advantages and few drawbacks. As a result, novice attackers tend to overly rely on the SYN scan while performing system reconnaissance. As a scanning method, the primary advantages of SYN scanning are its universality and speed. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-29-leveraging-time-of-check-and-time-of-use",
    "title": "MITRE CAPEC-29: Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-29 (Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets a race condition occurring between the time of check (state) for a resource and the time of use of a resource. A typical example is file access. The adversary can leverage a file access race condition by \"running the race\", meaning that they would modify the resource between the first time the target program accesses the file and the time the target program uses the file. Likelihood of attack: High. Typical severity: High. Parent pattern for CAPEC-27 Leveraging Race Conditions via Symbolic Links. Maps to weaknesses CWE-367, CWE-368, CWE-366, CWE-370, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-290-enumerate-mail-exchange-mx-records",
    "title": "MITRE CAPEC-290: Enumerate Mail Exchange (MX) Records (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-290 (Enumerate Mail Exchange (MX) Records) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary enumerates the MX records for a given via a DNS query. This type of information gathering returns the names of mail servers on the network. Mail servers are often not exposed to the Internet but are located within the DMZ of a network protected by a firewall. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-291-dns-zone-transfers",
    "title": "MITRE CAPEC-291: DNS Zone Transfers (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-291 (DNS Zone Transfers) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits a DNS misconfiguration that permits a ZONE transfer. Some external DNS servers will return a list of IP address and valid hostnames. Under certain conditions, it may even be possible to obtain Zone data about the organization's internal network. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-292-host-discovery",
    "title": "MITRE CAPEC-292: Host Discovery (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-292 (Host Discovery) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends a probe to an IP address to determine if the host is alive. Host discovery is one of the earliest phases of network reconnaissance. The adversary usually starts with a range of IP addresses belonging to a target network and uses various methods to determine if a host is present at that IP address. Host discovery is usually referred to as 'Ping' scanning using a sonar analogy. Likelihood of attack: Unknown. Typical severity: Low. Parent pattern for CAPEC-285 ICMP Echo Request Ping; CAPEC-294 ICMP Address Mask Request; CAPEC-295 Timestamp Request; and others. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1018.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1018-remote-system-discovery"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-293-traceroute-route-enumeration",
    "title": "MITRE CAPEC-293: Traceroute Route Enumeration (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-293 (Traceroute Route Enumeration) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a traceroute utility to map out the route which data flows through the network in route to a target destination. Tracerouting can allow the adversary to construct a working topology of systems and routers by listing the systems through which data passes through on their way to the targeted machine. This attack can return varied results depending upon the type of traceroute that is performed. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-294-icmp-address-mask-request",
    "title": "MITRE CAPEC-294: ICMP Address Mask Request (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-294 (ICMP Address Mask Request) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends an ICMP Type 17 Address Mask Request to gather information about a target's networking configuration. ICMP Address Mask Requests are defined by RFC-950, \"Internet Standard Subnetting Procedure.\" An Address Mask Request is an ICMP type 17 message that triggers a remote system to respond with a list of its related subnets, as well as its default gateway and broadcast address via an ICMP type 18. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-295-timestamp-request",
    "title": "MITRE CAPEC-295: Timestamp Request (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-295 (Timestamp Request) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This pattern of attack leverages standard requests to learn the exact time associated with a target system. An adversary may be able to use the timestamp returned from the target to attack time-based security algorithms, such as random number generators, or time-based authentication mechanisms. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1124.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1124-system-time-discovery"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-296-icmp-information-request",
    "title": "MITRE CAPEC-296: ICMP Information Request (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-296 (ICMP Information Request) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends an ICMP Information Request to a host to determine if it will respond to this deprecated mechanism. ICMP Information Requests are a deprecated message type. Information Requests were originally used for diskless machines to automatically obtain their network configuration, but this message type has been superseded by more robust protocol implementations like DHCP. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-297-tcp-ack-ping",
    "title": "MITRE CAPEC-297: TCP ACK Ping (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-297 (TCP ACK Ping) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends a TCP segment with the ACK flag set to a remote host for the purpose of determining if the host is alive. This is one of several TCP 'ping' types. The RFC 793 expected behavior for a service is to respond with a RST 'reset' packet to any unsolicited ACK segment that is not part of an existing connection. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-298-udp-ping",
    "title": "MITRE CAPEC-298: UDP Ping (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-298 (UDP Ping) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends a UDP datagram to the remote host to determine if the host is alive. If a UDP datagram is sent to an open UDP port there is very often no response, so a typical strategy for using a UDP ping is to send the datagram to a random high port on the target. The goal is to solicit an 'ICMP port unreachable' message from the target, indicating that the host is alive. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-299-tcp-syn-ping",
    "title": "MITRE CAPEC-299: TCP SYN Ping (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-299 (TCP SYN Ping) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses TCP SYN packets as a means towards host discovery. Typical RFC 793 behavior specifies that when a TCP port is open, a host must respond to an incoming SYN \"synchronize\" packet by completing stage two of the 'three-way handshake' - by sending an SYN/ACK in response. When a port is closed, RFC 793 behavior is to respond with a RST \"reset\" packet. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-3-using-leading-ghost-character-sequences-to-bypass-input",
    "title": "MITRE CAPEC-3: Using Leading 'Ghost' Character Sequences to Bypass Input Filters (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-3 (Using Leading 'Ghost' Character Sequences to Bypass Input Filters) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Some APIs will strip certain leading characters from a string of parameters. An adversary can intentionally introduce leading \"ghost\" characters (extra characters that don't affect the validity of the request at the API layer) that enable the input to pass the filters and therefore process the adversary's input. Likelihood of attack: Medium. Typical severity: Medium. Maps to weaknesses CWE-173, CWE-41, CWE-172, CWE-179, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-30-hijacking-a-privileged-thread-of-execution",
    "title": "MITRE CAPEC-30: Hijacking a Privileged Thread of Execution (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-30 (Hijacking a Privileged Thread of Execution) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary hijacks a privileged thread of execution by injecting malicious code into a running process. By using a privleged thread to do their bidding, adversaries can evade process-based detection that would stop an attack that creates a new process. This can lead to an adversary gaining access to the process's memory and can also enable elevated privileges. Likelihood of attack: Low. Typical severity: Very High. Maps to weaknesses CWE-270. Relates to MITRE ATT&CK T1055.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-300-port-scanning",
    "title": "MITRE CAPEC-300: Port Scanning (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-300 (Port Scanning) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a combination of techniques to determine the state of the ports on a remote target. Any service or application available for TCP or UDP networking will have a port open for communications over the network. Likelihood of attack: Unknown. Typical severity: Low. Parent pattern for CAPEC-287 TCP SYN Scan; CAPEC-301 TCP Connect Scan; CAPEC-302 TCP FIN Scan; and others. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1046.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1046-network-service-discovery"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-301-tcp-connect-scan",
    "title": "MITRE CAPEC-301: TCP Connect Scan (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-301 (TCP Connect Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses full TCP connection attempts to determine if a port is open on the target system. The scanning process involves completing a 'three-way handshake' with a remote port, and reports the port as closed if the full handshake cannot be established. An advantage of TCP connect scanning is that it works against any TCP/IP stack. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-302-tcp-fin-scan",
    "title": "MITRE CAPEC-302: TCP FIN Scan (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-302 (TCP FIN Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a TCP FIN scan to determine if ports are closed on the target machine. This scan type is accomplished by sending TCP segments with the FIN bit set in the packet header. The RFC 793 expected behavior is that any TCP segment with an out-of-state Flag sent to an open port is discarded, whereas segments with out-of-state flags sent to closed ports should be handled with a RST in response. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-303-tcp-xmas-scan",
    "title": "MITRE CAPEC-303: TCP Xmas Scan (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-303 (TCP Xmas Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a TCP XMAS scan to determine if ports are closed on the target machine. This scan type is accomplished by sending TCP segments with all possible flags set in the packet header, generating packets that are illegal based on RFC 793. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-304-tcp-null-scan",
    "title": "MITRE CAPEC-304: TCP Null Scan (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-304 (TCP Null Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a TCP NULL scan to determine if ports are closed on the target machine. This scan type is accomplished by sending TCP segments with no flags in the packet header, generating packets that are illegal based on RFC 793. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-305-tcp-ack-scan",
    "title": "MITRE CAPEC-305: TCP ACK Scan (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-305 (TCP ACK Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses TCP ACK segments to gather information about firewall or ACL configuration. The purpose of this type of scan is to discover information about filter configurations rather than port state. This type of scanning is rarely useful alone, but when combined with SYN scanning, gives a more complete picture of the type of firewall rules that are present. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-306-tcp-window-scan",
    "title": "MITRE CAPEC-306: TCP Window Scan (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-306 (TCP Window Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in TCP Window scanning to analyze port status and operating system type. TCP Window scanning uses the ACK scanning method but examine the TCP Window Size field of response RST packets to make certain inferences. While TCP Window Scans are fast and relatively stealthy, they work against fewer TCP stack implementations than any other type of scan. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-307-tcp-rpc-scan",
    "title": "MITRE CAPEC-307: TCP RPC Scan (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-307 (TCP RPC Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary scans for RPC services listing on a Unix/Linux host. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-308-udp-scan",
    "title": "MITRE CAPEC-308: UDP Scan (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-308 (UDP Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in UDP scanning to gather information about UDP port status on the target system. UDP scanning methods involve sending a UDP datagram to the target port and looking for evidence that the port is closed. Open UDP ports usually do not respond to UDP datagrams as there is no stateful mechanism within the protocol that requires building or establishing a session. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-309-network-topology-mapping",
    "title": "MITRE CAPEC-309: Network Topology Mapping (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-309 (Network Topology Mapping) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in scanning activities to map network nodes, hosts, devices, and routes. Adversaries usually perform this type of network reconnaissance during the early stages of attack against an external network. Many types of scanning utilities are typically employed, including ICMP tools, network mappers, port scanners, and route testing utilities such as traceroute. Likelihood of attack: Unknown. Typical severity: Low. Parent pattern for CAPEC-290 Enumerate Mail Exchange (MX) Records; CAPEC-291 DNS Zone Transfers; CAPEC-293 Traceroute Route Enumeration; and others. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1016, T1049, T1590.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1016-system-network-configuration-discovery",
      "mitre-attack-t1049-system-network-connections-discovery"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-31-http-cookies",
    "title": "MITRE CAPEC-31: Accessing/Intercepting/Modifying HTTP Cookies (Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-31 (Accessing/Intercepting/Modifying HTTP Cookies) is an attack pattern that exploits HTTP cookies in three ways: accessing cookies to extract sensitive data, intercepting transmitted cookies for impersonation, or modifying cookie content. Relies on cookies storing credentials, state, or critical data on client systems. Likelihood: High. Severity: High. Maps to MITRE ATT&CK T1539 (Steal Web Session Cookie) and CWE-565 (Reliance on Cookies without Validation), CWE-302, CWE-311, CWE-315, CWE-384, CWE-642. Compliance: OWASP ASVS V3 (Session Management), PCI DSS v4.0 Req 4 + Req 8, NIS2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1539-steal-web-session-cookie",
      "mitre-attack-t1573-encrypted-channel",
      "mitre-d3fend-d3-mencr-message-encryption",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-310-scanning-for-vulnerable-software",
    "title": "MITRE CAPEC-310: Scanning for Vulnerable Software (Attack Pattern - Reconnaissance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-310 (Scanning for Vulnerable Software) is a reconnaissance attack pattern in which an adversary engages in scanning activity to find vulnerable software versions or types (operating systems, network services). Typically follows port scanning. Severity: Low (recon phase - precedes exploitation). Maps to CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Parent: CAPEC-541 Application Fingerprinting. Compliance: NIST SP 800-53 CM-6/SC-7/RA-5, ISO 27001 A.8.8/A.8.16, PCI DSS v4.0 Req 11.3.1, NIS2 Article 21(2)(d).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1595-active-scanning",
      "mitre-d3fend-d3-itf-inbound-traffic-filtering",
      "mitre-d3fend-d3-nta-network-traffic-analysis",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-312-active-os-fingerprinting",
    "title": "MITRE CAPEC-312: Active OS Fingerprinting (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-312 (Active OS Fingerprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in activity to detect the operating system or firmware version of a remote target by interrogating a device, server, or platform with a probe designed to solicit behavior that will reveal information about the operating systems or firmware in the environment. Operating System detection is possible because implementations of common protocols (Such as IP or TCP) differ in distinct ways. Likelihood of attack: Medium. Typical severity: Low. Parent pattern for CAPEC-317 IP ID Sequencing Probe; CAPEC-318 IP 'ID' Echoed Byte-Order Probe; CAPEC-319 IP (DF) 'Don't Fragment Bit' Echoing Probe; and others. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1082.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-313-passive-os-fingerprinting",
    "title": "MITRE CAPEC-313: Passive OS Fingerprinting (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-313 (Passive OS Fingerprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in activity to detect the version or type of OS software in a an environment by passively monitoring communication between devices, nodes, or applications. Passive techniques for operating system detection send no actual probes to a target, but monitor network or client-server communication between nodes in order to identify operating systems based on observed behavior as compared to a database. Likelihood of attack: High. Typical severity: Low. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1082.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-317-ip-id-sequencing-probe",
    "title": "MITRE CAPEC-317: IP ID Sequencing Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-317 (IP ID Sequencing Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe analyzes the IP 'ID' field sequence number generation algorithm of a remote host. Operating systems generate IP 'ID' numbers differently, allowing an attacker to identify the operating system of the host by examining how is assigns ID numbers when generating response packets. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-318-ip-id-echoed-byte-order-probe",
    "title": "MITRE CAPEC-318: IP 'ID' Echoed Byte-Order Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-318 (IP 'ID' Echoed Byte-Order Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe tests to determine if the remote host echoes back the IP 'ID' value from the probe packet. An attacker sends a UDP datagram with an arbitrary IP 'ID' value to a closed port on the remote host to observe the manner in which this bit is echoed back in the ICMP error message. The identification field (ID) is typically utilized for reassembling a fragmented packet. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-319-ip-df-don-t-fragment-bit-echoing-probe",
    "title": "MITRE CAPEC-319: IP (DF) 'Don't Fragment Bit' Echoing Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-319 (IP (DF) 'Don't Fragment Bit' Echoing Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe tests to determine if the remote host echoes back the IP 'DF' (Don't Fragment) bit in a response packet. An attacker sends a UDP datagram with the DF bit set to a closed port on the remote host to observe whether the 'DF' bit is set in the response packet. Some operating systems will echo the bit in the ICMP error message while others will zero out the bit in the response packet. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-32-xss-through-http-query-strings",
    "title": "MITRE CAPEC-32: XSS Through HTTP Query Strings (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-32 (XSS Through HTTP Query Strings) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary embeds malicious script code in the parameters of an HTTP query string and convinces a victim to submit the HTTP request that contains the query string to a vulnerable web application. The web application then procedes to use the values parameters without properly validation them first and generates the HTML code that will be executed by the victim's browser. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-80.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-320-tcp-timestamp-probe",
    "title": "MITRE CAPEC-320: TCP Timestamp Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-320 (TCP Timestamp Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe examines the remote server's implementation of TCP timestamps. Not all operating systems implement timestamps within the TCP header, but when timestamps are used then this provides the attacker with a means to guess the operating system of the target. The attacker begins by probing any active TCP service in order to get response which contains a TCP timestamp. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-321-tcp-sequence-number-probe",
    "title": "MITRE CAPEC-321: TCP Sequence Number Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-321 (TCP Sequence Number Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe tests the target system's assignment of TCP sequence numbers. One common way to test TCP Sequence Number generation is to send a probe packet to an open port on the target and then compare the how the Sequence Number generated by the target relates to the Acknowledgement Number in the probe packet. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-322-tcp-isn-greatest-common-divisor-probe",
    "title": "MITRE CAPEC-322: TCP (ISN) Greatest Common Divisor Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-322 (TCP (ISN) Greatest Common Divisor Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe sends a number of TCP SYN packets to an open port of a remote machine. The Initial Sequence Number (ISN) in each of the SYN/ACK response packets is analyzed to determine the smallest number that the target host uses when incrementing sequence numbers. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-323-tcp-isn-counter-rate-probe",
    "title": "MITRE CAPEC-323: TCP (ISN) Counter Rate Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-323 (TCP (ISN) Counter Rate Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS detection probe measures the average rate of initial sequence number increments during a period of time. Sequence numbers are incremented using a time-based algorithm and are susceptible to a timing analysis that can determine the number of increments per unit time. The result of this analysis is then compared against a database of operating systems and versions to determine likely operation system matches. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-324-tcp-isn-sequence-predictability-probe",
    "title": "MITRE CAPEC-324: TCP (ISN) Sequence Predictability Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-324 (TCP (ISN) Sequence Predictability Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of operating system probe attempts to determine an estimate for how predictable the sequence number generation algorithm is for a remote host. Statistical techniques, such as standard deviation, can be used to determine how predictable the sequence number generation is for a system. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-325-tcp-congestion-control-flag-ecn-probe",
    "title": "MITRE CAPEC-325: TCP Congestion Control Flag (ECN) Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-325 (TCP Congestion Control Flag (ECN) Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe checks to see if the remote host supports explicit congestion notification (ECN) messaging. ECN messaging was designed to allow routers to notify a remote host when signal congestion problems are occurring. Explicit Congestion Notification messaging is defined by RFC 3168. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-326-tcp-initial-window-size-probe",
    "title": "MITRE CAPEC-326: TCP Initial Window Size Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-326 (TCP Initial Window Size Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe checks the initial TCP Window size. TCP stacks limit the range of sequence numbers allowable within a session to maintain the \"connected\" state within TCP protocol logic. The initial window size specifies a range of acceptable sequence numbers that will qualify as a response to an ACK packet within a session. Various operating systems use different Initial window sizes. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-327-tcp-options-probe",
    "title": "MITRE CAPEC-327: TCP Options Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-327 (TCP Options Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe analyzes the type and order of any TCP header options present within a response segment. Most operating systems use unique ordering and different option sets when options are present. RFC 793 does not specify a required order when options are present, so different implementations use unique ways of ordering or structuring TCP options. TCP options can be generated by ordinary TCP traffic. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-328-tcp-rst-flag-checksum-probe",
    "title": "MITRE CAPEC-328: TCP 'RST' Flag Checksum Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-328 (TCP 'RST' Flag Checksum Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe performs a checksum on any ASCII data contained within the data portion or a RST packet. Some operating systems will report a human-readable text message in the payload of a 'RST' (reset) packet when specific types of connection errors occur. RFC 1122 allows text payloads within reset packets but not all operating systems or routers implement this functionality. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-329-icmp-error-message-quoting-probe",
    "title": "MITRE CAPEC-329: ICMP Error Message Quoting Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-329 (ICMP Error Message Quoting Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a technique to generate an ICMP Error message (Port Unreachable, Destination Unreachable, Redirect, Source Quench, Time Exceeded, Parameter Problem) from a target and then analyze the amount of data returned or \"Quoted\" from the originating request that generated the ICMP error message. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-33-http-request-smuggling",
    "title": "MITRE CAPEC-33: HTTP Request Smuggling (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-33 (HTTP Request Smuggling) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary abuses the flexibility and discrepancies in the parsing and interpretation of HTTP Request messages using various HTTP headers, request-line and body parameters as well as message sizes (denoted by the end of message signaled by a given HTTP header) by different intermediary HTTP agents (e.g., load balancer, reverse proxy, web caching proxies, application firewalls, etc.) to secretly send unauthorized. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-444.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-330-icmp-error-message-echoing-integrity-probe",
    "title": "MITRE CAPEC-330: ICMP Error Message Echoing Integrity Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-330 (ICMP Error Message Echoing Integrity Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a technique to generate an ICMP Error message (Port Unreachable, Destination Unreachable, Redirect, Source Quench, Time Exceeded, Parameter Problem) from a target and then analyze the integrity of data returned or \"Quoted\" from the originating request that generated the error message. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-331-icmp-ip-total-length-field-probe",
    "title": "MITRE CAPEC-331: ICMP IP Total Length Field Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-331 (ICMP IP Total Length Field Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends a UDP packet to a closed port on the target machine to solicit an IP Header's total length field value within the echoed 'Port Unreachable\" error message. This type of behavior is useful for building a signature-base of operating system responses, particularly when error messages contain other types of information that is useful identifying specific operating system responses. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-204.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-332-icmp-ip-id-field-error-message-probe",
    "title": "MITRE CAPEC-332: ICMP IP 'ID' Field Error Message Probe (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-332 (ICMP IP 'ID' Field Error Message Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends a UDP datagram having an assigned value to its internet identification field (ID) to a closed port on a target to observe the manner in which this bit is echoed back in the ICMP error message. This allows the attacker to construct a fingerprint of specific OS behaviors. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-204.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-34-http-response-splitting",
    "title": "MITRE CAPEC-34: HTTP Response Splitting (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-34 (HTTP Response Splitting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates and injects malicious content, in the form of secret unauthorized HTTP responses, into a single HTTP response from a vulnerable or compromised back-end HTTP agent (e.g., web server) or into an already spoofed HTTP response from an adversary controlled domain/site. See CanPrecede relationships for possible consequences. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-74, CWE-113, CWE-138, CWE-436.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-35-leverage-executable-code-in-non-executable-files",
    "title": "MITRE CAPEC-35: Leverage Executable Code in Non-Executable Files (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-35 (Leverage Executable Code in Non-Executable Files) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type exploits a system's trust in configuration and resource files. When the executable loads the resource (such as an image file or configuration file) the attacker has modified the file to either execute malicious code directly or manipulate the target process (e.g. application server) to execute based on the malicious configuration parameters. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-94, CWE-96, CWE-95, CWE-97, and others. Relates to MITRE ATT&CK T1027.006, T1027.009, T1564.009.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1027-014-polymorphic-code",
      "mitre-attack-t1564-hide-artifacts"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-36-using-unpublished-interfaces-or-functionality",
    "title": "MITRE CAPEC-36: Using Unpublished Interfaces or Functionality (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-36 (Using Unpublished Interfaces or Functionality) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary searches for and invokes interfaces or functionality that the target system designers did not intend to be publicly available. If interfaces fail to authenticate requests, the attacker may be able to invoke functionality they are not authorized for. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-306, CWE-693, CWE-695, CWE-1242.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-37-retrieve-embedded-sensitive-data",
    "title": "MITRE CAPEC-37: Retrieve Embedded Sensitive Data (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-37 (Retrieve Embedded Sensitive Data) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker examines a target system to find sensitive data that has been embedded within it. This information can reveal confidential contents, such as account numbers or individual keys/credentials that can be used as an intermediate step in a larger attack. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-226, CWE-311, CWE-525, CWE-312, and others. Relates to MITRE ATT&CK T1005, T1552.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1005-data-from-local-system",
      "mitre-attack-t1552-unsecured-credentials"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-38-leveraging-manipulating-configuration-file-search-paths",
    "title": "MITRE CAPEC-38: Leveraging/Manipulating Configuration File Search Paths (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This pattern of attack sees an adversary load a malicious resource into a program's standard path so that when a known command is executed then the system instead executes the malicious component. The adversary can either modify the search path a program uses, like a PATH variable or classpath, or they can manipulate resources on the path to point to their malicious components. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-426, CWE-427. Relates to MITRE ATT&CK T1574.007, T1574.009.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1574-014-appdomainmanager"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-383-harvesting-information-via-api-event-monitoring",
    "title": "MITRE CAPEC-383: Harvesting Information via API Event Monitoring (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-383 (Harvesting Information via API Event Monitoring) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary hosts an event within an application framework and then monitors the data exchanged during the course of the event for the purpose of harvesting any important data leaked during the transactions. One example could be harvesting lists of usernames or userIDs for the purpose of sending spam messages to those users. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-311, CWE-319, CWE-419, CWE-602. Relates to MITRE ATT&CK T1056.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1056-input-capture"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-384-application-api-message-manipulation-via-man-in-the",
    "title": "MITRE CAPEC-384: Application API Message Manipulation via Man-in-the-Middle (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-384 (Application API Message Manipulation via Man-in-the-Middle) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates either egress or ingress data from a client within an application framework in order to change the content of messages. Performing this attack can allow the attacker to gain unauthorized privileges within the application, or conduct attacks such as phishing, deceptive strategies to spread malware, or traditional web-application attacks. Likelihood of attack: Unknown. Typical severity: Low. Parent pattern for CAPEC-385 Transaction or Event Tampering via Application API Manipulation; CAPEC-389 Content Spoofing Via Application API Manipulation. Maps to weaknesses CWE-471, CWE-345, CWE-346, CWE-602, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-385-transaction-or-event-tampering-via-application-api-manipulat",
    "title": "MITRE CAPEC-385: Transaction or Event Tampering via Application API Manipulation (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-385 (Transaction or Event Tampering via Application API Manipulation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker hosts or joins an event or transaction within an application framework in order to change the content of messages or items that are being exchanged. Performing this attack allows the attacker to manipulate content in such a way as to produce messages or content that look authentic but may contain deceptive links, substitute one item or another, spoof an existing item and conduct a false exchange, or. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-471, CWE-345, CWE-346, CWE-602, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-386-application-api-navigation-remapping",
    "title": "MITRE CAPEC-386: Application API Navigation Remapping (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-386 (Application API Navigation Remapping) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates either egress or ingress data from a client within an application framework in order to change the destination and/or content of links/buttons displayed to a user within API messages. Performing this attack allows the attacker to manipulate content in such a way as to produce messages or content that looks authentic but contains links/buttons that point to an attacker controlled destination. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-387 Navigation Remapping To Propagate Malicious Content; CAPEC-388 Application API Button Hijacking. Maps to weaknesses CWE-471, CWE-345, CWE-346, CWE-602, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-387-navigation-remapping-to-propagate-malicious-content",
    "title": "MITRE CAPEC-387: Navigation Remapping To Propagate Malicious Content (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-387 (Navigation Remapping To Propagate Malicious Content) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates either egress or ingress data from a client within an application framework in order to change the content of messages and thereby circumvent the expected application logic. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-471, CWE-345, CWE-346, CWE-602, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-388-application-api-button-hijacking",
    "title": "MITRE CAPEC-388: Application API Button Hijacking (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-388 (Application API Button Hijacking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates either egress or ingress data from a client within an application framework in order to change the destination and/or content of buttons displayed to a user within API messages. Performing this attack allows the attacker to manipulate content in such a way as to produce messages or content that looks authentic but contains buttons that point to an attacker controlled destination. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-471, CWE-345, CWE-346, CWE-602, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-389-content-spoofing-via-application-api-manipulation",
    "title": "MITRE CAPEC-389: Content Spoofing Via Application API Manipulation (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-389 (Content Spoofing Via Application API Manipulation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates either egress or ingress data from a client within an application framework in order to change the content of messages. Performing this attack allows the attacker to manipulate content in such a way as to produce messages or content that look authentic but may contain deceptive links, spam-like content, or links to the attackers' code. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-353.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-39-manipulating-opaque-client-based-data-tokens",
    "title": "MITRE CAPEC-39: Manipulating Opaque Client-based Data Tokens (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-39 (Manipulating Opaque Client-based Data Tokens) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In circumstances where an application holds important data client-side in tokens (cookies, URLs, data files, and so forth) that data can be manipulated. If client or server-side application components reinterpret that data as authentication tokens or data (such as store item pricing or wallet information) then even opaquely manipulating that data may bear fruit for an Attacker. Likelihood of attack: High. Typical severity: Medium. Parent pattern for CAPEC-31 Accessing/Intercepting/Modifying HTTP Cookies. Maps to weaknesses CWE-353, CWE-285, CWE-302, CWE-472, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-390-bypassing-physical-security",
    "title": "MITRE CAPEC-390: Bypassing Physical Security (Meta Attack Pattern - Unrated Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-390 (Bypassing Physical Security) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Facilities often used layered models for physical security such as traditional locks, Electronic-based card entry systems, coupled with physical alarms. Hardware security mechanisms range from the use of computer case and cable locks as well as RFID tags for tracking computer assets. This layered approach makes it difficult for random physical security breaches to go unnoticed, but is less effective at stopping deliberate and carefully planned break-ins. Avoiding detection begins with evading building security and surveillance and methods for bypassing the electronic or physical locks which secure entry points.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-391-bypassing-physical-locks",
    "title": "MITRE CAPEC-391: Bypassing Physical Locks (Standard Attack Pattern - Unrated Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-391 (Bypassing Physical Locks) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses techniques and methods to bypass physical security measures of a building or facility. Physical locks may range from traditional lock and key mechanisms, cable locks used to secure laptops or servers, locks on server cases, or other such devices. Techniques such as lock bumping, lock forcing via snap guns, or lock picking can be employed to bypass those locks and gain access to the facilities or devices they protect, although stealth, evidence of tampering, and the integrity of the lock following an attack, are considerations that may determine the method employed. Physical locks are limited by the complexity of the locking mechanism. While some locks may offer protections such as shock resistant foam to prevent bumping or lock forcing methods, many commonly employed locks offer no such countermeasures. Child of CAPEC-390.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-392-lock-bumping",
    "title": "MITRE CAPEC-392: Lock Bumping (Detailed Attack Pattern - Unrated Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-392 (Lock Bumping) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses a bump key to force a lock on a building or facility and gain entry. Lock Bumping is the use of a special type of key that can be tapped or bumped to cause the pins within the lock to fall into temporary alignment, allowing the lock to be opened. Lock bumping allows an attacker to open a lock without having the correct key. A standard lock is secured by a set of internal pins that prevent the device from turning. Spring loaded driver pins push down on the key pins. When the correct key is inserted, the ridges on the key push the key pins up and against the driver pins, causing correct alignment which allows the lock cylinder to rotate. A bump key is a specially constructed key that exploits this design. When the bump key is struck or firmly tapped, its teeth transfer the force of the tap into the key pins, causing the lock to momentarily shift into proper alignment for the mechanism to be opened. Child of CAPEC-391.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-393-lock-picking",
    "title": "MITRE CAPEC-393: Lock Picking (Detailed Attack Pattern - Unrated Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-393 (Lock Picking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses lock picking tools and techniques to bypass the locks on a building or facility. Lock picking is the use of a special set of tools to manipulate the pins within a lock. Different sets of tools are required for each type of lock. Lock picking attacks have the advantage of being non-invasive in that if performed correctly the lock will not be damaged. A standard lock pin-and-tumbler lock is secured by a set of internal pins that prevent the tumbler device from turning. Spring loaded driver pins push down on the key pins preventing rotation so that the bolt remains in a locked position.. When the correct key is inserted, the ridges on the key push the key pins up and against the driver pins, causing correct alignment which allows the lock cylinder to rotate. Most common locks, such as domestic locks in the US, can be picked using a standard 2 tools (i.e. a torsion wrench and a hook pick). Child of CAPEC-391.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-394-using-a-snap-gun-lock-to-force-a-lock",
    "title": "MITRE CAPEC-394: Using a Snap Gun Lock to Force a Lock (Detailed Attack Pattern - Unrated Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-394 (Using a Snap Gun Lock to Force a Lock) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses a Snap Gun, also known as a Pick Gun, to force the lock on a building or facility. A Pick Gun is a special type of lock picking instrument that works on similar principles as lock bumping. A snap gun is a hand-held device with an attached metal pick. The metal pick strikes the pins within the lock, transferring motion from the key pins to the driver pins and forcing the lock into momentary alignment. A standard lock is secured by a set of internal pins that prevent the device from turning. Spring loaded driver pins push down on the key pins. When the correct key is inserted, the ridges on the key push the key pins up and against the driver pins, causing correct alignment which allows the lock cylinder to rotate. A Snap Gun exploits this design by using a metal pin to strike all of the key pins at once, forcing the driver pins to shift into an unlocked position. Unlike bump keys or lock picks, a Snap Gun may damage the lock more easily, leaving evidence that the lock has been tampered with. Child of CAPEC-391.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-395-bypassing-electronic-locks-and-access-controls",
    "title": "MITRE CAPEC-395: Bypassing Electronic Locks and Access Controls (Standard Attack Pattern - Unrated Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-395 (Bypassing Electronic Locks and Access Controls) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits security assumptions to bypass electronic locks or other forms of access controls. Most attacks against electronic access controls follow similar methods but utilize different tools. Some electronic locks utilize magnetic strip cards, others employ RFID tags embedded within a card or badge, or may involve more sophisticated protections such as voice-print, thumb-print, or retinal biometrics. Magnetic Strip and RFID technologies are the most widespread because they are cost effective to deploy and more easily integrated with other electronic security measures. These technologies share common weaknesses that an attacker can exploit to gain access to a facility protected by the mechanisms via copying legitimate cards or badges, or generating new cards using reverse-engineered algorithms. Child of CAPEC-390.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-397-cloning-magnetic-strip-cards",
    "title": "MITRE CAPEC-397: Cloning Magnetic Strip Cards (Detailed Attack Pattern - Unrated Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-397 (Cloning Magnetic Strip Cards) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker duplicates the data on a Magnetic strip card (i.e. 'swipe card' or 'magstripe') to gain unauthorized access to a physical location or a person's private information. Magstripe cards encode data on a band of iron-based magnetic particles arrayed in a stripe along a rectangular card. Most magstripe card data formats conform to ISO standards 7810, 7811, 7813, 8583, and 4909. The primary advantage of magstripe technology is ease of encoding and portability, but this also renders magnetic strip cards susceptible to unauthorized duplication. If magstripe cards are used for access control, all an attacker need do is obtain a valid card long enough to make a copy of the card and then return the card to its location (i.e. a co-worker's desk). Magstripe reader/writers are widely available as well as software for analyzing data encoded on the cards. By swiping a valid card, it becomes trivial to make any number of duplicates that function as the original. Child of CAPEC-395.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-398-magnetic-strip-card-brute-force-attacks",
    "title": "MITRE CAPEC-398: Magnetic Strip Card Brute Force Attacks (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-398 (Magnetic Strip Card Brute Force Attacks) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary analyzes the data on two or more magnetic strip cards and is able to generate new cards containing valid sequences that allow unauthorized access and/or impersonation of individuals. Likelihood of attack: Unknown.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-399-cloning-rfid-cards-or-chips",
    "title": "MITRE CAPEC-399: Cloning RFID Cards or Chips (Detailed Attack Pattern - Unrated Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-399 (Cloning RFID Cards or Chips) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker analyzes data returned by an RFID chip and uses this information to duplicate a RFID signal that responds identically to the target chip. In some cases RFID chips are used for building access control, employee identification, or as markers on products being delivered along a supply chain. Some organizations also embed RFID tags inside computer assets to trigger alarms if they are removed from particular rooms, zones, or buildings. Similar to Magnetic strip cards, RFID cards are susceptible to duplication (cloning) and reuse. Child of CAPEC-395.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-4-using-alternative-ip-address-encodings",
    "title": "MITRE CAPEC-4: Using Alternative IP Address Encodings (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-4 (Using Alternative IP Address Encodings) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack relies on the adversary using unexpected formats for representing IP addresses. Networked applications may expect network location information in a specific format, such as fully qualified domains names (FQDNs), URL, IP address, or IP Address ranges. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-291, CWE-173.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-40-manipulating-writeable-terminal-devices",
    "title": "MITRE CAPEC-40: Manipulating Writeable Terminal Devices (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-40 (Manipulating Writeable Terminal Devices) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack exploits terminal devices that allow themselves to be written to by other users. The attacker sends command strings to the target terminal device hoping that the target user will hit enter and thereby execute the malicious command with their privileges. The attacker can send the results (such as copying /etc/passwd) to a known directory and collect once the attack has succeeded. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-77.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-400-rfid-chip-deactivation-or-destruction",
    "title": "MITRE CAPEC-400: RFID Chip Deactivation or Destruction (Detailed Attack Pattern - Unrated Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-400 (RFID Chip Deactivation or Destruction) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses methods to deactivate a passive RFID tag for the purpose of rendering the tag, badge, card, or object containing the tag unresponsive. RFID tags are used primarily for access control, inventory, or anti-theft devices. The purpose of attacking the RFID chip is to disable or damage the chip without causing damage to the object housing it. Child of CAPEC-395.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-401-physically-hacking-hardware",
    "title": "MITRE CAPEC-401: Physically Hacking Hardware (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-401 (Physically Hacking Hardware) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in access control to gain access to currently installed hardware and precedes to implement changes or secretly replace a hardware component which undermines the system's integrity for the purpose of carrying out an attack. Likelihood of attack: Low. Typical severity: High. Parent pattern for CAPEC-402 Bypassing ATA Password Security. Maps to weaknesses CWE-1263.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-402-bypassing-ata-password-security",
    "title": "MITRE CAPEC-402: Bypassing ATA Password Security (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-402 (Bypassing ATA Password Security) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in ATA security on a drive to gain access to the information the drive contains without supplying the proper credentials. ATA Security is often employed to protect hard disk information from unauthorized access. The mechanism requires the user to type in a password before the BIOS is allowed access to drive contents. Likelihood of attack: Unknown. Maps to weaknesses CWE-285.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-406-dumpster-diving",
    "title": "MITRE CAPEC-406: Dumpster Diving (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-406 (Dumpster Diving) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary cases an establishment and searches through trash bins, dumpsters, or areas where company information may have been accidentally discarded for information items which may be useful to the dumpster diver. Likelihood of attack: Unknown. Typical severity: Low.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-407-pretexting",
    "title": "MITRE CAPEC-407: Pretexting (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-407 (Pretexting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in pretexting behavior to solicit information from target persons, or manipulate the target into performing some action that serves the adversary's interests. During a pretexting attack, the adversary creates an invented scenario, assuming an identity or role to persuade a targeted victim to release information or perform some action. Likelihood of attack: Medium. Typical severity: Low. Parent pattern for CAPEC-383 Harvesting Information via API Event Monitoring; CAPEC-412 Pretexting via Customer Service; CAPEC-413 Pretexting via Tech Support; and others. Relates to MITRE ATT&CK T1589.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1589-003-employee-names"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-41-using-meta-characters-in-e-mail-headers-to",
    "title": "MITRE CAPEC-41: Using Meta-characters in E-mail Headers to Inject Malicious Payloads (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-41 (Using Meta-characters in E-mail Headers to Inject Malicious Payloads) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack involves an attacker leveraging meta-characters in email headers to inject improper behavior into email programs. Email software has become increasingly sophisticated and feature-rich. In addition, email applications are ubiquitous and connected directly to the Web making them ideal targets to launch and propagate attacks. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-150, CWE-88, CWE-697.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-410-information-elicitation",
    "title": "MITRE CAPEC-410: Information Elicitation (Meta Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-410 (Information Elicitation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages an individual using any combination of social engineering methods for the purpose of extracting information. Accurate contextual and environmental queues, such as knowing important information about the target company or individual can greatly increase the success of the attack and the quality of information gathered. Authentic mimicry combined with detailed knowledge increases the success of elicitation attacks. Typical severity: Low.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-412-pretexting-via-customer-service",
    "title": "MITRE CAPEC-412: Pretexting via Customer Service (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-412 (Pretexting via Customer Service) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in pretexting behavior, assuming the role of someone who works for Customer Service, to solicit information from target persons, or manipulate the target into performing an action that serves the adversary's interests. One example of a scenario such as this would be to call an individual, articulate your false affiliation with a credit card company, and then attempt to get the individual to verify their credit card number. Typical severity: Low. Child of CAPEC-407.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-413-pretexting-via-tech-support",
    "title": "MITRE CAPEC-413: Pretexting via Tech Support (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-413 (Pretexting via Tech Support) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in pretexting behavior, assuming the role of a tech support worker, to solicit information from target persons, or manipulate the target into performing an action that serves the adversary's interests. An adversary who uses social engineering to impersonate a tech support worker can have devastating effects on a network. This is an effective attack vector, because it can give an adversary physical access to network computers. It only takes a matter of seconds for someone to compromise a computer with physical access. One of the best technological tools at the disposal of a social engineer, posing as a technical support person, is a USB thumb drive. These are small, easy to conceal, and can be loaded with different payloads depending on what task needs to be done. However, this form of attack does not require physical access as it can also be effectively carried out via phone or email. Typical severity: Low. Child of CAPEC-407.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-414-pretexting-via-delivery-person",
    "title": "MITRE CAPEC-414: Pretexting via Delivery Person (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-414 (Pretexting via Delivery Person) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in pretexting behavior, assuming the role of a delivery person, to solicit information from target persons, or manipulate the target into performing an action that serves the adversary's interests. Impersonating a delivery person is an effective attack and an easy attack since not much acting is involved. Usually the hardest part is looking the part and having all of the proper credentials, papers and \"deliveries\" in order to be able to pull it off. Typical severity: Low. Child of CAPEC-407.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-415-pretexting-via-phone",
    "title": "MITRE CAPEC-415: Pretexting via Phone (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-415 (Pretexting via Phone) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in pretexting behavior, assuming some sort of trusted role, and contacting the targeted individual or organization via phone to solicit information from target persons, or manipulate the target into performing an action that serves the adversary's interests. This is the most common social engineering attack. Some of the most commonly effective approaches are to impersonate a fellow employee, impersonate a computer technician or to target help desk personnel. Typical severity: Low. Child of CAPEC-407.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-416-manipulate-human-behavior",
    "title": "MITRE CAPEC-416: Manipulate Human Behavior (Meta Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-416 (Manipulate Human Behavior) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits inherent human psychological predisposition to influence a targeted individual or group to solicit information or manipulate the target into performing an action that serves the adversary's interests. Likelihood of attack: Medium. Typical severity: Medium. Parent pattern for CAPEC-407 Pretexting; CAPEC-417 Influence Perception; CAPEC-425 Target Influence via Framing; and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-417-influence-perception",
    "title": "MITRE CAPEC-417: Influence Perception (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-417 (Influence Perception) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary uses social engineering to exploit the target's perception of the relationship between the adversary and themselves. This goal is to persuade the target to unknowingly perform an action or divulge information that is advantageous to the adversary. Likelihood of attack: High. Typical severity: Low. Parent pattern for CAPEC-418 Influence Perception of Reciprocation; CAPEC-420 Influence Perception of Scarcity; CAPEC-421 Influence Perception of Authority; and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-418-influence-perception-of-reciprocation",
    "title": "MITRE CAPEC-418: Influence Perception of Reciprocation (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-418 (Influence Perception of Reciprocation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a social engineering techniques to produce a sense of obligation in the target to perform a certain action or concede some sensitive or key piece of information. Obligation has to do with actions one feels they need to take due to some sort of social, legal, or moral requirement, duty, contract, or promise. Likelihood of attack: Medium. Typical severity: Medium.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-42-mime-conversion",
    "title": "MITRE CAPEC-42: MIME Conversion (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-42 (MIME Conversion) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits a weakness in the MIME conversion routine to cause a buffer overflow and gain control over the mail server machine. The MIME system is designed to allow various different information formats to be interpreted and sent via e-mail. Attack points exist when data are converted to MIME compatible format and back. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-120, CWE-119, CWE-74, CWE-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-420-influence-perception-of-scarcity",
    "title": "MITRE CAPEC-420: Influence Perception of Scarcity (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-420 (Influence Perception of Scarcity) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary leverages a perception of scarcity to persuade the target to perform an action or divulge information that is advantageous to the adversary. By conveying a perception of scarcity, or a situation of limited supply, the adversary aims to create a sense of urgency in the context of a target's decision-making process. Likelihood of attack: High. Typical severity: Low.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-421-influence-perception-of-authority",
    "title": "MITRE CAPEC-421: Influence Perception of Authority (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-421 (Influence Perception of Authority) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a social engineering technique to convey a sense of authority that motivates the target to reveal specific information or take specific action. There are various techniques for producing a sense of authority during ordinary modes of communication. One common method is impersonation. Likelihood of attack: High. Typical severity: Low.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-422-influence-perception-of-commitment-and-consistency",
    "title": "MITRE CAPEC-422: Influence Perception of Commitment and Consistency (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-422 (Influence Perception of Commitment and Consistency) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses social engineering to convince the target to do minor tasks as opposed to larger actions. After complying with a request, individuals are more likely to agree to subsequent requests that are similar in type and required effort. Likelihood of attack: High. Typical severity: Low.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-423-influence-perception-of-liking",
    "title": "MITRE CAPEC-423: Influence Perception of Liking (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-423 (Influence Perception of Liking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary influences the target's actions by building a relationship where the target has a liking to the adversary. People are more likely to be influenced by people of whom they are fond, so the adversary attempts to ingratiate themself with the target via actions, appearance, or a combination thereof. Likelihood of attack: Medium. Typical severity: Low.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-424-influence-perception-of-consensus-or-social-proof",
    "title": "MITRE CAPEC-424: Influence Perception of Consensus or Social Proof (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-424 (Influence Perception of Consensus or Social Proof) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary influences the target's actions by leveraging the inherent human nature to assume behavior of others is appropriate. In situations of uncertainty, people tend to behave in ways they see others behaving. The adversary convinces the target of adopting behavior or actions that is advantageous to the adversary. Likelihood of attack: Low. Typical severity: Low.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-425-target-influence-via-framing",
    "title": "MITRE CAPEC-425: Target Influence via Framing (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-425 (Target Influence via Framing) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses framing techniques to contextualize a conversation so that the target is more likely to be influenced by the adversary's point of view. Framing is information and experiences in life that alter the way we react to decisions we must make. Likelihood of attack: Low. Typical severity: Low.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-426-influence-via-incentives",
    "title": "MITRE CAPEC-426: Influence via Incentives (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-426 (Influence via Incentives) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary incites a behavior from the target by manipulating something of influence. This is commonly associated with financial, social, or ideological incentivization. Examples include monetary fraud, peer pressure, and preying on the target's morals or ethics. Likelihood of attack: Low. Typical severity: Low.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-427-influence-via-psychological-principles",
    "title": "MITRE CAPEC-427: Influence via Psychological Principles (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-427 (Influence via Psychological Principles) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary shapes the target's actions or behavior by focusing on the ways human interact and learn, leveraging such elements as cognitive and social psychology. In a variety of ways, a target can be influenced to behave or perform an action through capitalizing on what scholarship and research has learned about how and why humans react to specific scenarios and cues. Likelihood of attack: Low. Typical severity: Low. Parent pattern for CAPEC-428 Influence via Modes of Thinking; CAPEC-429 Target Influence via Eye Cues; CAPEC-433 Target Influence via The Human Buffer Overflow; and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-428-influence-via-modes-of-thinking",
    "title": "MITRE CAPEC-428: Influence via Modes of Thinking (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-428 (Influence via Modes of Thinking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary tailors their communication to the language and thought patterns of the target thereby weakening barriers or reluctance to communication. This method is a way of building rapport with a target by matching their speech patterns and the primary ways or dominant senses with which they make abstractions. This technique can be used to make the target more receptive to sharing information because the adversary has adapted their communication forms to match those of the target. When skillfully employed, the target is likely to be unaware that they are being manipulated. Typical severity: Low. Child of CAPEC-427.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-429-target-influence-via-eye-cues",
    "title": "MITRE CAPEC-429: Target Influence via Eye Cues (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-429 (Target Influence via Eye Cues) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary gains information via non-verbal means from the target through eye movements. Typical severity: Low. Child of CAPEC-427.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-43-exploiting-multiple-input-interpretation-layers",
    "title": "MITRE CAPEC-43: Exploiting Multiple Input Interpretation Layers (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-43 (Exploiting Multiple Input Interpretation Layers) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker supplies the target software with input data that contains sequences of special characters designed to bypass input validation logic. This exploit relies on the target making multiples passes over the input data and processing a \"layer\" of special characters with each pass. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-179, CWE-181, CWE-184, CWE-183, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-433-target-influence-via-the-human-buffer-overflow",
    "title": "MITRE CAPEC-433: Target Influence via The Human Buffer Overflow (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-433 (Target Influence via The Human Buffer Overflow) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker utilizes a technique to insinuate commands to the subconscious mind of the target via communication patterns. The human buffer overflow methodology does not rely on over-stimulating the mind of the target, but rather embedding messages within communication that the mind of the listener assembles at a subconscious level. The human buffer-overflow method is similar to subconscious programming to the extent that messages are embedded within the message. Typical severity: Low. Child of CAPEC-427.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-434-target-influence-via-interview-and-interrogation",
    "title": "MITRE CAPEC-434: Target Influence via Interview and Interrogation (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-434 (Target Influence via Interview and Interrogation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification.  Typical severity: Low. Child of CAPEC-427.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-435-target-influence-via-instant-rapport",
    "title": "MITRE CAPEC-435: Target Influence via Instant Rapport (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-435 (Target Influence via Instant Rapport) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification.  Typical severity: Low. Child of CAPEC-427.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-438-modification-during-manufacture",
    "title": "MITRE CAPEC-438: Modification During Manufacture (Meta Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-438 (Modification During Manufacture) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker modifies a technology, product, or component during a stage in its manufacture for the purpose of carrying out an attack against some entity involved in the supply chain lifecycle. There are an almost limitless number of ways an attacker can modify a technology when they are involved in its manufacture, as the attacker has potential inroads to the software composition, hardware design and assembly,. Likelihood of attack: Unknown. Parent pattern for CAPEC-444 Development Alteration; CAPEC-447 Design Alteration. Relates to MITRE ATT&CK T1195.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-439-manipulation-during-distribution",
    "title": "MITRE CAPEC-439: Manipulation During Distribution (Meta Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-439 (Manipulation During Distribution) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker undermines the integrity of a product, software, or technology at some stage of the distribution channel. The core threat of modification or manipulation during distribution arise from the many stages of distribution, as a product may traverse multiple suppliers and integrators as the final asset is delivered. Likelihood of attack: Unknown. Parent pattern for CAPEC-522 Malicious Hardware Component Replacement; CAPEC-523 Malicious Software Implanted; CAPEC-524 Rogue Integration Procedures. Maps to weaknesses CWE-1269. Relates to MITRE ATT&CK T1195.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-44-overflow-binary-resource-file",
    "title": "MITRE CAPEC-44: Overflow Binary Resource File (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-44 (Overflow Binary Resource File) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type exploits a buffer overflow vulnerability in the handling of binary resources. Binary resources may include music files like MP3, image files like JPEG files, and any other binary file. These attacks may pass unnoticed to the client machine through normal usage of files, such as a browser loading a seemingly innocent JPEG file. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-120, CWE-119, CWE-697.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-440-hardware-integrity-attack",
    "title": "MITRE CAPEC-440: Hardware Integrity Attack (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-440 (Hardware Integrity Attack) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in the system maintenance process and causes a change to be made to a technology, product, component, or sub-component or a new one installed during its deployed use at the victim location for the purpose of carrying out an attack. Likelihood of attack: Low. Typical severity: High. Parent pattern for CAPEC-401 Physically Hacking Hardware; CAPEC-534 Malicious Hardware Update. Relates to MITRE ATT&CK T1195.003, T1200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise",
      "mitre-attack-t1200-hardware-additions"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-441-malicious-logic-insertion",
    "title": "MITRE CAPEC-441: Malicious Logic Insertion (Attack Pattern - High Severity, Supply Chain)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-441 (Malicious Logic Insertion) is an attack pattern in which an adversary installs or adds malicious logic (malware) into a seemingly benign component of a fielded system. Targets already-deployed systems exploiting wireless and Bluetooth vectors. Likelihood: Medium. Severity: High. Maps to CWE-284 (Improper Access Control). Child patterns: CAPEC-442 Infected Software, CAPEC-452 Infected Hardware, CAPEC-456 Infected Memory. Compliance: NIST SP 800-53 SI-3/SI-7/SR-11, ISO 27001 A.8.7/A.5.21, US EO 14028, EU Cyber Resilience Act, NIS2 supply chain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1574-hijack-execution-flow",
      "mitre-capec-capec-184-software-integrity-attack",
      "mitre-d3fend-d3-fim-file-integrity-monitoring",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-442-infected-software",
    "title": "MITRE CAPEC-442: Infected Software (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-442 (Infected Software) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary adds malicious logic, often in the form of a computer virus, to otherwise benign software. This logic is often hidden from the user of the software and works behind the scenes to achieve negative impacts. Many times, the malicious logic is inserted into empty space between legitimate code, and is then called when the software is executed. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-448 Embed Virus into DLL. Maps to weaknesses CWE-506. Relates to MITRE ATT&CK T1195.001, T1195.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-443-malicious-logic-inserted-into-product-by-authorized-develope",
    "title": "MITRE CAPEC-443: Malicious Logic Inserted Into Product by Authorized Developer (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-443 (Malicious Logic Inserted Into Product by Authorized Developer) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses their privileged position within an authorized development organization to inject malicious logic into a codebase or product. Likelihood of attack: Medium. Typical severity: High. Relates to MITRE ATT&CK T1195.002, T1195.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-444-development-alteration",
    "title": "MITRE CAPEC-444: Development Alteration (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-444 (Development Alteration) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary modifies a technology, product, or component during its development to acheive a negative impact once the system is deployed. The goal of the adversary is to modify the system in such a way that the negative impact can be leveraged when the system is later deployed. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-206 Signing Malicious Code; CAPEC-443 Malicious Logic Inserted Into Product by Authorized Developer; CAPEC-445 Malicious Logic Insertion into Product Software via Configuration Management Manipulation; and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-445-malicious-logic-insertion-into-product-software-via-configur",
    "title": "MITRE CAPEC-445: Malicious Logic Insertion into Product Software via Configuration Management Manipulation (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-445 (Malicious Logic Insertion into Product Software via Configuration Management Manipulation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a configuration management system so that malicious logic is inserted into a software products build, update or deployed environment. If an adversary can control the elements included in a product's configuration management for build they can potentially replace, modify or insert code files containing malicious logic. Likelihood of attack: Medium. Typical severity: High. Relates to MITRE ATT&CK T1195.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-446-malicious-logic-insertion-into-product-via-inclusion-of",
    "title": "MITRE CAPEC-446: Malicious Logic Insertion into Product via Inclusion of Third-Party Component (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-446 (Malicious Logic Insertion into Product via Inclusion of Third-Party Component) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary conducts supply chain attacks by the inclusion of insecure third-party components into a technology, product, or code-base, possibly packaging a malicious driver or component along with the product before shipping it to the consumer or acquirer. Likelihood of attack: Medium. Typical severity: High. Relates to MITRE ATT&CK T1195.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-447-design-alteration",
    "title": "MITRE CAPEC-447: Design Alteration (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-447 (Design Alteration) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary modifies the design of a technology, product, or component to acheive a negative impact once the system is deployed. In this type of attack, the goal of the adversary is to modify the design of the system, prior to development starting, in such a way that the negative impact can be leveraged when the system is later deployed. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-517 Documentation Alteration to Circumvent Dial-down; CAPEC-518 Documentation Alteration to Produce Under-performing Systems; CAPEC-519 Documentation Alteration to Cause Errors in System Design; and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-448-embed-virus-into-dll",
    "title": "MITRE CAPEC-448: Embed Virus into DLL (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-448 (Embed Virus into DLL) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary tampers with a DLL and embeds a computer virus into gaps between legitimate machine instructions. These gaps may be the result of compiler optimizations that pad memory blocks for performance gains. The embedded virus then attempts to infect any machine which interfaces with the product, and possibly steal private data or eavesdrop. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-506. Relates to MITRE ATT&CK T1027.009.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1027-014-polymorphic-code"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-45-buffer-overflow-via-symbolic-links",
    "title": "MITRE CAPEC-45: Buffer Overflow via Symbolic Links (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-45 (Buffer Overflow via Symbolic Links) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack leverages the use of symbolic links to cause buffer overflows. An adversary can try to create or manipulate a symbolic link file such that its contents result in out of bounds data. When the target software processes the symbolic link file, it could potentially overflow internal buffers with insufficient bounds checking. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-120, CWE-285, CWE-302, CWE-118, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-452-infected-hardware",
    "title": "MITRE CAPEC-452: Infected Hardware (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-452 (Infected Hardware) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary inserts malicious logic into hardware, typically in the form of a computer virus or rootkit. This logic is often hidden from the user of the hardware and works behind the scenes to achieve negative impacts. This pattern of attack focuses on hardware already fielded and used in operation as opposed to hardware that is still under development and part of the supply chain. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-638 Altered Component Firmware.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-456-infected-memory",
    "title": "MITRE CAPEC-456: Infected Memory (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-456 (Infected Memory) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary inserts malicious logic into memory enabling them to achieve a negative impact. This logic is often hidden from the user of the system and works behind the scenes to achieve negative impacts. This pattern of attack focuses on systems already fielded and used in operation as opposed to systems that are still under development and part of the supply chain. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-457 USB Memory Attacks; CAPEC-458 Flash Memory Attacks. Maps to weaknesses CWE-1257, CWE-1260, CWE-1274, CWE-1312, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-457-usb-memory-attacks",
    "title": "MITRE CAPEC-457: USB Memory Attacks (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-457 (USB Memory Attacks) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary loads malicious code onto a USB memory stick in order to infect any system which the device is plugged in to. USB drives present a significant security risk for business and government agencies. Given the ability to integrate wireless functionality into a USB stick, it is possible to design malware that not only steals confidential data, but sniffs the network, or monitor keystrokes, and then. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-1299. Relates to MITRE ATT&CK T1091, T1092.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1091-replication-through-removable-media",
      "mitre-attack-t1092-communication-through-removable-media"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-458-flash-memory-attacks",
    "title": "MITRE CAPEC-458: Flash Memory Attacks (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-458 (Flash Memory Attacks) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary inserts malicious logic into a product or technology via flashing the on-board memory with a code-base that contains malicious logic. Various attacks exist against the integrity of flash memory, the most direct being rootkits coded into the BIOS or chipset of a device. Likelihood of attack: Unknown. Maps to weaknesses CWE-1282.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-459-creating-a-rogue-certification-authority-certificate",
    "title": "MITRE CAPEC-459: Creating a Rogue Certification Authority Certificate (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-459 (Creating a Rogue Certification Authority Certificate) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness resulting from using a hashing algorithm with weak collision resistance to generate certificate signing requests (CSR) that contain collision blocks in their \"to be signed\" parts. The adversary submits one CSR to be signed by a trusted certificate authority then uses the signed blob to make a second certificate appear signed by said certificate authority. Likelihood of attack: Medium. Typical severity: Very High. Maps to weaknesses CWE-327, CWE-295, CWE-290.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-46-overflow-variables-and-tags",
    "title": "MITRE CAPEC-46: Overflow Variables and Tags (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-46 (Overflow Variables and Tags) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack leverages the use of tags or variables from a formatted configuration data to cause buffer overflow. The adversary crafts a malicious HTML page or configuration file that includes oversized strings, thus causing an overflow. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-120, CWE-118, CWE-119, CWE-74, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-460-http-parameter-pollution-hpp",
    "title": "MITRE CAPEC-460: HTTP Parameter Pollution (HPP) (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-460 (HTTP Parameter Pollution (HPP)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary adds duplicate HTTP GET/POST parameters by injecting query string delimiters. Via HPP it may be possible to override existing hardcoded HTTP parameters, modify the application behaviors, access and, potentially exploit, uncontrollable variables, and bypass input validation checkpoints and WAF rules. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-88, CWE-147, CWE-235.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-461-web-services-api-signature-forgery-leveraging-hash-function",
    "title": "MITRE CAPEC-461: Web Services API Signature Forgery Leveraging Hash Function Extension Weakness (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-461 (Web Services API Signature Forgery Leveraging Hash Function Extension Weakness) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary utilizes a hash function extension/padding weakness, to modify the parameters passed to the web service requesting authentication by generating their own call in order to generate a legitimate signature hash (as described in the notes), without knowledge of the secret token sometimes provided by the web service. Likelihood of attack: Unknown. Typical severity: High. Maps to weaknesses CWE-328, CWE-290.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-462-cross-domain-search-timing",
    "title": "MITRE CAPEC-462: Cross-Domain Search Timing (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-462 (Cross-Domain Search Timing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker initiates cross domain HTTP / GET requests and times the server responses. The timing of these responses may leak important information on what is happening on the server. Browser's same origin policy prevents the attacker from directly reading the server responses (in the absence of any other weaknesses), but does not prevent the attacker from timing the responses to requests that the attacker issued. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-385, CWE-352, CWE-208.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-463-padding-oracle-crypto-attack",
    "title": "MITRE CAPEC-463: Padding Oracle Crypto Attack (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-463 (Padding Oracle Crypto Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary is able to efficiently decrypt data without knowing the decryption key if a target system leaks data on whether or not a padding error happened while decrypting the ciphertext. A target system that leaks this type of information becomes the padding oracle and an adversary is able to make use of that oracle to efficiently decrypt data without knowing the decryption key by issuing on average 128*b calls. Likelihood of attack: Unknown. Typical severity: High. Maps to weaknesses CWE-209, CWE-514, CWE-649, CWE-347, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-464-evercookie",
    "title": "MITRE CAPEC-464: Evercookie (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-464 (Evercookie) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker creates a very persistent cookie that stays present even after the user thinks it has been removed. The cookie is stored on the victim's machine in over ten places. When the victim clears the cookie cache via traditional means inside the browser, that operation removes the cookie from certain places but not others. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-359. Relates to MITRE ATT&CK T1606.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1606-forge-web-credentials"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-465-transparent-proxy-abuse",
    "title": "MITRE CAPEC-465: Transparent Proxy Abuse (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-465 (Transparent Proxy Abuse) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. A transparent proxy serves as an intermediate between the client and the internet at large. It intercepts all requests originating from the client and forwards them to the correct location. The proxy also intercepts all responses to the client and forwards these to the client. All of this is done in a manner transparent to the client. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-441. Relates to MITRE ATT&CK T1090.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1090-004-domain-fronting"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-466-leveraging-active-adversary-in-the-middle-attacks-to",
    "title": "MITRE CAPEC-466: Leveraging Active Adversary in the Middle Attacks to Bypass Same Origin Policy (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-466 (Leveraging Active Adversary in the Middle Attacks to Bypass Same Origin Policy) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker leverages an adversary in the middle attack (CAPEC-94) in order to bypass the same origin policy protection in the victim's browser. This active adversary in the middle attack could be launched, for instance, when the victim is connected to a public WIFI hot spot. An attacker is able to intercept requests and responses between the victim's browser and some non-sensitive website that does not use TLS. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-300.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-467-cross-site-identification",
    "title": "MITRE CAPEC-467: Cross Site Identification (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-467 (Cross Site Identification) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker harvests identifying information about a victim via an active session that the victim's browser has with a social networking site. A victim may have the social networking site open in one tab or perhaps is simply using the \"remember me\" feature to keep their session with the social networking site active. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-352, CWE-359.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-468-generic-cross-browser-cross-domain-theft",
    "title": "MITRE CAPEC-468: Generic Cross-Browser Cross-Domain Theft (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-468 (Generic Cross-Browser Cross-Domain Theft) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker makes use of Cascading Style Sheets (CSS) injection to steal data cross domain from the victim's browser. The attack works by abusing the standards relating to loading of CSS: 1. Send cookies on any load of CSS (including cross-domain) 2. When parsing returned CSS ignore all data that does not make sense before a valid CSS descriptor is found by the CSS parser. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-707, CWE-149, CWE-177, CWE-838.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-469-http-dos",
    "title": "MITRE CAPEC-469: HTTP DoS (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-469 (HTTP DoS) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker performs flooding at the HTTP level to bring down only a particular web application rather than anything listening on a TCP/IP connection. This denial of service attack requires substantially fewer packets to be sent which makes DoS harder to detect. This is an equivalent of SYN flood in HTTP. The idea is to keep the HTTP session alive indefinitely and then repeat that hundreds of times. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-770, CWE-772. Relates to MITRE ATT&CK T1499.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1499-004-application-or-system-exploitation"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-47-buffer-overflow-via-parameter-expansion",
    "title": "MITRE CAPEC-47: Buffer Overflow via Parameter Expansion (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-47 (Buffer Overflow via Parameter Expansion) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack, the target software is given input that the adversary knows will be modified and expanded in size during processing. This attack relies on the target software failing to anticipate that the expanded data may exceed some internal limit, thereby creating a buffer overflow. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-120, CWE-119, CWE-118, CWE-130, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-470-expanding-control-over-the-operating-system-from-the",
    "title": "MITRE CAPEC-470: Expanding Control over the Operating System from the Database (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-470 (Expanding Control over the Operating System from the Database) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker is able to leverage access gained to the database to read / write data to the file system, compromise the operating system, create a tunnel for accessing the host machine, and use this access to potentially attack other machines on the same network as the database machine. Likelihood of attack: Unknown. Typical severity: Very High. Maps to weaknesses CWE-250, CWE-89.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-471-search-order-hijacking",
    "title": "MITRE CAPEC-471: Search Order Hijacking (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-471 (Search Order Hijacking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in an application's specification of external libraries to exploit the functionality of the loader where the process loading the library searches first in the same directory in which the process binary resides and then in other directories. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-427. Relates to MITRE ATT&CK T1574.001, T1574.004, T1574.008.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1574-014-appdomainmanager"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-472-browser-fingerprinting",
    "title": "MITRE CAPEC-472: Browser Fingerprinting (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-472 (Browser Fingerprinting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker carefully crafts small snippets of Java Script to efficiently detect the type of browser the potential victim is using. Many web-based attacks need prior knowledge of the web browser including the version of browser to ensure successful exploitation of a vulnerability. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-473-signature-spoof",
    "title": "MITRE CAPEC-473: Signature Spoof (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-473 (Signature Spoof) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker generates a message or datablock that causes the recipient to believe that the message or datablock was generated and cryptographically signed by an authoritative or reputable source, misleading a victim or victim operating system into performing malicious actions. Likelihood of attack: Unknown. Parent pattern for CAPEC-459 Creating a Rogue Certification Authority Certificate; CAPEC-474 Signature Spoofing by Key Theft; CAPEC-475 Signature Spoofing by Improper Validation; and others. Maps to weaknesses CWE-20, CWE-327, CWE-290. Relates to MITRE ATT&CK T1036.001, T1553.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1036-masquerading",
      "mitre-attack-t1553-subvert-trust-controls"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-capec-capec-474-signature-spoofing-by-key-theft",
    "title": "MITRE CAPEC-474: Signature Spoofing by Key Theft (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-474 (Signature Spoofing by Key Theft) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker obtains an authoritative or reputable signer's private signature key by theft and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-522. Relates to MITRE ATT&CK T1552.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1552-unsecured-credentials"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-475-signature-spoofing-by-improper-validation",
    "title": "MITRE CAPEC-475: Signature Spoofing by Improper Validation (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-475 (Signature Spoofing by Improper Validation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a cryptographic weakness in the signature verification algorithm implementation to generate a valid signature without knowing the key. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-347, CWE-327, CWE-295.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-476-signature-spoofing-by-misrepresentation",
    "title": "MITRE CAPEC-476: Signature Spoofing by Misrepresentation (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-476 (Signature Spoofing by Misrepresentation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits a weakness in the parsing or display code of the recipient software to generate a data blob containing a supposedly valid signature, but the signer's identity is falsely represented, which can lead to the attacker manipulating the recipient software or its victim user to perform compromising actions. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-290.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-477-signature-spoofing-by-mixing-signed-and-unsigned-content",
    "title": "MITRE CAPEC-477: Signature Spoofing by Mixing Signed and Unsigned Content (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-477 (Signature Spoofing by Mixing Signed and Unsigned Content) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits the underlying complexity of a data structure that allows for both signed and unsigned content, to cause unsigned data to be processed as though it were signed data. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-693, CWE-311, CWE-319.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-478-modification-of-windows-service-configuration",
    "title": "MITRE CAPEC-478: Modification of Windows Service Configuration (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-478 (Modification of Windows Service Configuration) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in access control to modify the execution parameters of a Windows service. The goal of this attack is to execute a malicious binary in place of an existing service. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-284. Relates to MITRE ATT&CK T1574.011, T1543.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1574-014-appdomainmanager",
      "mitre-attack-t1543-005-container-service"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-479-malicious-root-certificate",
    "title": "MITRE CAPEC-479: Malicious Root Certificate (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-479 (Malicious Root Certificate) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in authorization and installs a new root certificate on a compromised system. Certificates are commonly used for establishing secure TLS/SSL communications within a web browser. When a user attempts to browse a website that presents a certificate that is not trusted an error message will be displayed to warn the user of the security risk. Likelihood of attack: Low. Typical severity: Low. Maps to weaknesses CWE-284. Relates to MITRE ATT&CK T1553.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1553-subvert-trust-controls"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-48-passing-local-filenames-to-functions-that-expect-a",
    "title": "MITRE CAPEC-48: Passing Local Filenames to Functions That Expect a URL (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-48 (Passing Local Filenames to Functions That Expect a URL) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack relies on client side code to access local files and resources instead of URLs. When the client browser is expecting a URL string, but instead receives a request for a local file, that execution is likely to occur in the browser process space with the browser's authority to local files. The attacker can send the results of this request to the local files out to a site that they control. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-241, CWE-706.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-480-escaping-virtualization",
    "title": "MITRE CAPEC-480: Escaping Virtualization (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-480 (Escaping Virtualization) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary gains access to an application, service, or device with the privileges of an authorized or privileged user by escaping the confines of a virtualized environment. The adversary is then able to access resources or execute unauthorized code within the host environment, generally with the privileges of the user running the virtualized process. Likelihood of attack: Low. Typical severity: Very High. Parent pattern for CAPEC-237 Escaping a Sandbox by Calling Code in Another Language. Maps to weaknesses CWE-693. Relates to MITRE ATT&CK T1611.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1611-escape-to-host"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-481-contradictory-destinations-in-traffic-routing-schemes",
    "title": "MITRE CAPEC-481: Contradictory Destinations in Traffic Routing Schemes (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-481 (Contradictory Destinations in Traffic Routing Schemes) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries can provide contradictory destinations when sending messages. Traffic is routed in networks using the domain names in various headers available at different levels of the OSI model. In a Content Delivery Network (CDN) multiple domains might be available, and if there are contradictory domain names provided it is possible to route traffic to an inappropriate destination. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-923. Relates to MITRE ATT&CK T1090.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1090-004-domain-fronting"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-482-tcp-flood",
    "title": "MITRE CAPEC-482: TCP Flood (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-482 (TCP Flood) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a flooding attack using the TCP protocol with the intent to deny legitimate users access to a service. These attacks exploit the weakness within the TCP protocol where there is some state information for the connection the server needs to maintain. This often involves the use of TCP SYN messages. Likelihood of attack: Unknown. Maps to weaknesses CWE-770. Relates to MITRE ATT&CK T1498.001, T1499.001, T1499.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1498-network-denial-of-service",
      "mitre-attack-t1499-004-application-or-system-exploitation"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-485-signature-spoofing-by-key-recreation",
    "title": "MITRE CAPEC-485: Signature Spoofing by Key Recreation (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-485 (Signature Spoofing by Key Recreation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-330. Relates to MITRE ATT&CK T1552.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1552-unsecured-credentials"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-486-udp-flood",
    "title": "MITRE CAPEC-486: UDP Flood (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-486 (UDP Flood) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a flooding attack using the UDP protocol with the intent to deny legitimate users access to a service by consuming the available network bandwidth. Additionally, firewalls often open a port for each UDP connection destined for a service with an open UDP port, meaning the firewalls in essence save the connection state thus the high packet nature of a UDP flood can also overwhelm resources. Likelihood of attack: Unknown. Maps to weaknesses CWE-770.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-487-icmp-flood",
    "title": "MITRE CAPEC-487: ICMP Flood (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-487 (ICMP Flood) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a flooding attack using the ICMP protocol with the intent to deny legitimate users access to a service by consuming the available network bandwidth. A typical attack involves a victim server receiving ICMP packets at a high rate from a wide range of source addresses. Likelihood of attack: Unknown. Maps to weaknesses CWE-770.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-488-http-flood",
    "title": "MITRE CAPEC-488: HTTP Flood (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-488 (HTTP Flood) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a flooding attack using the HTTP protocol with the intent to deny legitimate users access to a service by consuming resources at the application layer such as web services and their infrastructure. These attacks use legitimate session-based HTTP GET requests designed to consume large amounts of a server's resources. Since these are legitimate sessions this attack is very difficult to detect. Likelihood of attack: Unknown. Maps to weaknesses CWE-770. Relates to MITRE ATT&CK T1499.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1499-004-application-or-system-exploitation"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-489-ssl-flood",
    "title": "MITRE CAPEC-489: SSL Flood (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-489 (SSL Flood) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a flooding attack using the SSL protocol with the intent to deny legitimate users access to a service by consuming all the available resources on the server side. These attacks take advantage of the asymmetric relationship between the processing power used by the client and the processing power used by the server to create a secure connection. Likelihood of attack: Unknown. Maps to weaknesses CWE-770. Relates to MITRE ATT&CK T1499.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1499-004-application-or-system-exploitation"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-49-password-brute-forcing",
    "title": "MITRE CAPEC-49: Password Brute Forcing (Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-49 (Password Brute Forcing) is an attack pattern in which an adversary tries every possible value for a password until they succeed. The CAPEC page identifies three prerequisites: adversary needs username; system uses password-based single-factor authentication; application does not have password throttling. Likelihood of attack: Medium. Typical severity: High. Maps to MITRE ATT&CK T1110.001 (Brute Force: Password Guessing) and CWE-521, CWE-307, CWE-308. Compliance: PCI DSS v4.0 Req 8.3, NIST SP 800-63B AAL2/3, NIS2 Article 21(2)(j), HIPAA Security Rule.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1110-brute-force",
      "mitre-attack-t1078-valid-accounts",
      "mitre-d3fend-d3-al-account-locking",
      "mitre-d3fend-d3-spp-strong-password-policy",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-490-amplification",
    "title": "MITRE CAPEC-490: Amplification (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-490 (Amplification) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute an amplification where the size of a response is far greater than that of the request that generates it. The goal of this attack is to use a relatively few resources to create a large amount of traffic against a target server. To execute this attack, an adversary send a request to a 3rd party service, spoofing the source address to be that of the target server. Likelihood of attack: Unknown. Maps to weaknesses CWE-770. Relates to MITRE ATT&CK T1498.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1498-network-denial-of-service"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-491-quadratic-data-expansion",
    "title": "MITRE CAPEC-491: Quadratic Data Expansion (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-491 (Quadratic Data Expansion) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits macro-like substitution to cause a denial of service situation due to excessive memory being allocated to fully expand the data. The result of this denial of service could cause the application to freeze or crash. This involves defining a very large entity and using it multiple times in a single entity substitution. Likelihood of attack: Unknown. Maps to weaknesses CWE-770.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-492-regular-expression-exponential-blowup",
    "title": "MITRE CAPEC-492: Regular Expression Exponential Blowup (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-492 (Regular Expression Exponential Blowup) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute an attack on a program that uses a poor Regular Expression(Regex) implementation by choosing input that results in an extreme situation for the Regex. A typical extreme situation operates at exponential time compared to the input size. Likelihood of attack: Unknown. Maps to weaknesses CWE-400, CWE-1333.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-493-soap-array-blowup",
    "title": "MITRE CAPEC-493: SOAP Array Blowup (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-493 (SOAP Array Blowup) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute an attack on a web service that uses SOAP messages in communication. By sending a very large SOAP array declaration to the web service, the attacker forces the web service to allocate space for the array elements before they are parsed by the XML parser. Likelihood of attack: Unknown. Maps to weaknesses CWE-770.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-494-tcp-fragmentation",
    "title": "MITRE CAPEC-494: TCP Fragmentation (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-494 (TCP Fragmentation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a TCP Fragmentation attack against a target with the intention of avoiding filtering rules of network controls, by attempting to fragment the TCP packet such that the headers flag field is pushed into the second fragment which typically is not filtered. Likelihood of attack: Unknown. Maps to weaknesses CWE-770, CWE-404.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-495-udp-fragmentation",
    "title": "MITRE CAPEC-495: UDP Fragmentation (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-495 (UDP Fragmentation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker may execute a UDP Fragmentation attack against a target server in an attempt to consume resources such as bandwidth and CPU. IP fragmentation occurs when an IP datagram is larger than the MTU of the route the datagram has to traverse. Typically the attacker will use large UDP packets over 1500 bytes of data which forces fragmentation as ethernet MTU is 1500 bytes. Likelihood of attack: Unknown. Maps to weaknesses CWE-770, CWE-404.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-496-icmp-fragmentation",
    "title": "MITRE CAPEC-496: ICMP Fragmentation (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-496 (ICMP Fragmentation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker may execute a ICMP Fragmentation attack against a target with the intention of consuming resources or causing a crash. The attacker crafts a large number of identical fragmented IP packets containing a portion of a fragmented ICMP message. The attacker these sends these messages to a target host which causes the host to become non-responsive. Likelihood of attack: Unknown. Maps to weaknesses CWE-770, CWE-404.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-497-file-discovery",
    "title": "MITRE CAPEC-497: File Discovery (Standard Attack Pattern - Very Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-497 (File Discovery) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in probing and exploration activities to determine if common key files exists. Such files often contain configuration and security parameters of the targeted application, system or network. Using this knowledge may often pave the way for more damaging attacks. Likelihood of attack: High. Typical severity: Very Low. Parent pattern for CAPEC-149 Explore for Predictable Temporary File Names. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1083.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1083-file-and-directory-discovery"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-498-probe-ios-screenshots",
    "title": "MITRE CAPEC-498: Probe iOS Screenshots (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-498 (Probe iOS Screenshots) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary examines screenshot images created by iOS in an attempt to obtain sensitive information. This attack targets temporary screenshots created by the underlying OS while the application remains open in the background. Likelihood of attack: Unknown. Maps to weaknesses CWE-359.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-499-android-intent-intercept",
    "title": "MITRE CAPEC-499: Android Intent Intercept (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-499 (Android Intent Intercept) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, intercepts messages from a trusted Android-based application in an attempt to achieve a variety of different objectives including denial of service, information disclosure, and data injection. An implicit intent sent from a trusted application can be received by any application that has declared an appropriate intent filter. Likelihood of attack: Unknown. Parent pattern for CAPEC-501 Android Activity Hijack. Maps to weaknesses CWE-925.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-5-blue-boxing",
    "title": "MITRE CAPEC-5: Blue Boxing (Detailed Attack Pattern - Very High Severity; DEPRECATED by MITRE, retained as a historical record)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-07-17",
    "bluf": "MITRE CAPEC-5 (Blue Boxing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack against older telephone switches and trunks has been around for decades. A tone is sent by an adversary to impersonate a supervisor signal which has the effect of rerouting or usurping command of the line. Likelihood of attack: Medium. Typical severity: Very High. Maps to weaknesses CWE-285. MITRE has DEPRECATED CAPEC-5 (Blue Boxing) as an obsolete pattern (legacy telephone-switch signaling) with no successor pattern; this record is retained as a historical reference and should not be treated as a current attack pattern.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-50-password-recovery-exploitation",
    "title": "MITRE CAPEC-50: Password Recovery Exploitation (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-50 (Password Recovery Exploitation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker may take advantage of the application feature to help users recover their forgotten passwords in order to gain access into the system with the same privileges as the original user. Generally password recovery schemes tend to be weak and insecure. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-522, CWE-640.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-500-webview-injection",
    "title": "MITRE CAPEC-500: WebView Injection (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-500 (WebView Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, injects code into the context of a web page displayed by a WebView component. Through the injected code, an adversary is able to manipulate the DOM tree and cookies of the page, expose sensitive information, and can launch attacks against the web application from within the web page. Likelihood of attack: Unknown. Maps to weaknesses CWE-749, CWE-940.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-501-android-activity-hijack",
    "title": "MITRE CAPEC-501: Android Activity Hijack (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-501 (Android Activity Hijack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary intercepts an implicit intent sent to launch a Android-based trusted activity and instead launches a counterfeit activity in its place. The malicious activity is then used to mimic the trusted activity's user interface and prompt the target to enter sensitive data as if they were interacting with the trusted activity. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-923.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-502-intent-spoof",
    "title": "MITRE CAPEC-502: Intent Spoof (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-502 (Intent Spoof) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, issues an intent directed toward a specific trusted application's component in an attempt to achieve a variety of different objectives including modification of data, information disclosure, and data injection. Components that have been unintentionally exported and made public are subject to this type of an attack. Likelihood of attack: Unknown. Maps to weaknesses CWE-284.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-503-webview-exposure",
    "title": "MITRE CAPEC-503: WebView Exposure (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-503 (WebView Exposure) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a malicious web page, accesses application specific functionality by leveraging interfaces registered through WebView's addJavascriptInterface API. Once an interface is registered to WebView through addJavascriptInterface, it becomes global and all pages loaded in the WebView can call this interface. Likelihood of attack: Unknown. Maps to weaknesses CWE-284.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-504-task-impersonation",
    "title": "MITRE CAPEC-504: Task Impersonation (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-504 (Task Impersonation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, impersonates an expected or routine task in an attempt to steal sensitive information or leverage a user's privileges. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-654 Credential Prompt Impersonation. Maps to weaknesses CWE-1021. Relates to MITRE ATT&CK T1036.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-505-scheme-squatting",
    "title": "MITRE CAPEC-505: Scheme Squatting (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-505 (Scheme Squatting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, registers for a URL scheme intended for a target application that has not been installed. Thereafter, messages intended for the target application are handled by the malicious application. Likelihood of attack: Unknown.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-506-tapjacking",
    "title": "MITRE CAPEC-506: Tapjacking (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-506 (Tapjacking) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, displays an interface that misleads the user and convinces them to tap on an attacker desired location on the screen. This is often accomplished by overlaying one screen on top of another while giving the appearance of a single interface. There are two main techniques used to accomplish this. Likelihood of attack: Low. Typical severity: Low. Maps to weaknesses CWE-1021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-507-physical-theft",
    "title": "MITRE CAPEC-507: Physical Theft (Meta Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-507 (Physical Theft) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary gains physical access to a system or device through theft of the item. Possession of a system or device enables a number of unique attacks to be executed and often provides the adversary with an extended timeframe for which to perform an attack. Most protections put in place to secure sensitive information can be defeated when an adversary has physical access and enough time. Likelihood of attack: Unknown.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-508-shoulder-surfing",
    "title": "MITRE CAPEC-508: Shoulder Surfing (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-508 (Shoulder Surfing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In a shoulder surfing attack, an adversary observes an unaware individual's keystrokes, screen content, or conversations with the goal of obtaining sensitive information. One motive for this attack is to obtain sensitive information about the target for financial, personal, political, or other gains. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-200, CWE-359.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-509-kerberoasting",
    "title": "MITRE CAPEC-509: Kerberoasting (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-509 (Kerberoasting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Through the exploitation of how service accounts leverage Kerberos authentication with Service Principal Names (SPNs), the adversary obtains and subsequently cracks the hashed credentials of a service account target to exploit its privileges. The Kerberos authentication protocol centers around a ticketing system which is used to request/grant access to services and to then access the requested services. Likelihood of attack: Unknown. Typical severity: High. Maps to weaknesses CWE-522, CWE-308, CWE-309, CWE-294, and others. Relates to MITRE ATT&CK T1558.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1558-steal-or-forge-kerberos-tickets"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-capec-capec-51-poison-web-service-registry",
    "title": "MITRE CAPEC-51: Poison Web Service Registry (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-51 (Poison Web Service Registry) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. SOA and Web Services often use a registry to perform look up, get schema information, and metadata about services. A poisoned registry can redirect (think phishing for servers) the service requester to a malicious service provider, provide incorrect information in schema or metadata, and delete information about service provider interfaces. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-285, CWE-74, CWE-693.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-510-saas-user-request-forgery",
    "title": "MITRE CAPEC-510: SaaS User Request Forgery (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-510 (SaaS User Request Forgery) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, performs malicious actions against a third-party Software as a Service (SaaS) application (also known as a cloud based application) by leveraging the persistent and implicit trust placed on a trusted user's session. Likelihood of attack: High. Typical severity: Medium. Maps to weaknesses CWE-346.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-511-infiltration-of-software-development-environment",
    "title": "MITRE CAPEC-511: Infiltration of Software Development Environment (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-511 (Infiltration of Software Development Environment) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses common delivery mechanisms such as email attachments or removable media to infiltrate the IDE (Integrated Development Environment) of a victim manufacturer with the intent of implanting malware allowing for attack control of the victim IDE environment. The attack then uses this access to exfiltrate sensitive data or information, manipulate said data or information, and conceal these actions. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1195.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-516-hardware-component-substitution-during-baselining",
    "title": "MITRE CAPEC-516: Hardware Component Substitution During Baselining (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-516 (Hardware Component Substitution During Baselining) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary with access to system components during allocated baseline development can substitute a maliciously altered hardware component for a baseline component during the product development and research phases. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1195.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-517-documentation-alteration-to-circumvent-dial-down",
    "title": "MITRE CAPEC-517: Documentation Alteration to Circumvent Dial-down (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-517 (Documentation Alteration to Circumvent Dial-down) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to a manufacturer's documentation, which include descriptions of advanced technology and/or specific components' criticality, alters the documents to circumvent dial-down functionality requirements. Likelihood of attack: Low. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-518-documentation-alteration-to-produce-under-performing-systems",
    "title": "MITRE CAPEC-518: Documentation Alteration to Produce Under-performing Systems (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-518 (Documentation Alteration to Produce Under-performing Systems) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to a manufacturer's documentation alters the descriptions of system capabilities with the intent of causing errors in derived system requirements, impacting the overall effectiveness and capability of the system, allowing an attacker to take advantage of the introduced system capability flaw once the system is deployed. Likelihood of attack: Low. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-519-documentation-alteration-to-cause-errors-in-system-design",
    "title": "MITRE CAPEC-519: Documentation Alteration to Cause Errors in System Design (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-519 (Documentation Alteration to Cause Errors in System Design) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to a manufacturer's documentation containing requirements allocation and software design processes maliciously alters the documentation in order to cause errors in system design. This allows the attacker to take advantage of a weakness in a deployed system of the manufacturer for malicious purposes. Likelihood of attack: Low. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-52-embedding-null-bytes",
    "title": "MITRE CAPEC-52: Embedding NULL Bytes (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-52 (Embedding NULL Bytes) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary embeds one or more null bytes in input to the target software. This attack relies on the usage of a null-valued byte as a string terminator in many environments. The goal is for certain components of the target software to stop processing the input when it encounters the null byte(s). Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-158, CWE-172, CWE-173, CWE-74, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-520-counterfeit-hardware-component-inserted-during-product-assem",
    "title": "MITRE CAPEC-520: Counterfeit Hardware Component Inserted During Product Assembly (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-520 (Counterfeit Hardware Component Inserted During Product Assembly) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary with either direct access to the product assembly process or to the supply of subcomponents used in the product assembly process introduces counterfeit hardware components into product assembly. The assembly containing the counterfeit components results in a system specifically designed for malicious purposes. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1195.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-521-hardware-design-specifications-are-altered",
    "title": "MITRE CAPEC-521: Hardware Design Specifications Are Altered (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-521 (Hardware Design Specifications Are Altered) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to a manufacturer's hardware manufacturing process documentation alters the design specifications, which introduces flaws advantageous to the attacker once the system is deployed. Likelihood of attack: Low. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-522-malicious-hardware-component-replacement",
    "title": "MITRE CAPEC-522: Malicious Hardware Component Replacement (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-522 (Malicious Hardware Component Replacement) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary replaces legitimate hardware in the system with faulty counterfeit or tampered hardware in the supply chain distribution channel, with purpose of causing malicious disruption or allowing for additional compromise when the system is deployed. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1195.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-523-malicious-software-implanted",
    "title": "MITRE CAPEC-523: Malicious Software Implanted (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-523 (Malicious Software Implanted) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker implants malicious software into the system in the supply chain distribution channel, with purpose of causing malicious disruption or allowing for additional compromise when the system is deployed. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1195.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-524-rogue-integration-procedures",
    "title": "MITRE CAPEC-524: Rogue Integration Procedures (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-524 (Rogue Integration Procedures) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker alters or establishes rogue processes in an integration facility in order to insert maliciously altered components into the system. The attacker would then supply the malicious components. This would allow for malicious disruption or additional compromise when the system is deployed. Likelihood of attack: Low. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-528-xml-flood",
    "title": "MITRE CAPEC-528: XML Flood (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-528 (XML Flood) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a flooding attack using XML messages with the intent to deny legitimate users access to a web service. These attacks are accomplished by sending a large number of XML based requests and letting the service attempt to parse each one. In many cases this type of an attack will result in a XML Denial of Service (XDoS) due to an application becoming unstable, freezing, or crashing. Likelihood of attack: Low. Typical severity: Medium. Parent pattern for CAPEC-147 XML Ping of the Death. Maps to weaknesses CWE-770. Relates to MITRE ATT&CK T1499.002, T1498.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1499-004-application-or-system-exploitation",
      "mitre-attack-t1498-network-denial-of-service"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-529-malware-directed-internal-reconnaissance",
    "title": "MITRE CAPEC-529: Malware-Directed Internal Reconnaissance (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-529 (Malware-Directed Internal Reconnaissance) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversary uses malware or a similarly controlled application installed inside an organizational perimeter to gather information about the composition, configuration, and security mechanisms of a targeted application, system or network. Likelihood of attack: Medium. Typical severity: Medium.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-53-postfix-null-terminate-and-backslash",
    "title": "MITRE CAPEC-53: Postfix, Null Terminate, and Backslash (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-53 (Postfix, Null Terminate, and Backslash) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. If a string is passed through a filter of some kind, then a terminal NULL may not be valid. Using alternate representation of NULL allows an adversary to embed the NULL mid-string while postfixing the proper data so that the filter is avoided. One example is a filter that looks for a trailing slash character. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-158, CWE-172, CWE-173, CWE-74, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-530-provide-counterfeit-component",
    "title": "MITRE CAPEC-530: Provide Counterfeit Component (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-530 (Provide Counterfeit Component) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker provides a counterfeit component during the procurement process of a lower-tier component supplier to a sub-system developer or integrator, which is then built into the system being upgraded or repaired by the victim, allowing the attacker to cause disruption or additional compromise. Likelihood of attack: Low. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-531-hardware-component-substitution",
    "title": "MITRE CAPEC-531: Hardware Component Substitution (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-531 (Hardware Component Substitution) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker substitutes out a tested and approved hardware component for a maliciously-altered hardware component. This type of attack is carried out directly on the system, enabling the attacker to then cause disruption or additional compromise. Likelihood of attack: Low. Typical severity: High. Parent pattern for CAPEC-530 Provide Counterfeit Component; CAPEC-535 Malicious Gray Market Hardware. Relates to MITRE ATT&CK T1195.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-532-altered-installed-bios",
    "title": "MITRE CAPEC-532: Altered Installed BIOS (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-532 (Altered Installed BIOS) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to download and update system software sends a maliciously altered BIOS to the victim or victim supplier/integrator, which when installed allows for future exploitation. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1495, T1542.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1495-firmware-corruption",
      "mitre-attack-t1542-pre-os-boot"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-533-malicious-manual-software-update",
    "title": "MITRE CAPEC-533: Malicious Manual Software Update (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-533 (Malicious Manual Software Update) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker introduces malicious code to the victim's system by altering the payload of a software update, allowing for additional compromise or site disruption at the victim location. These manual, or user-assisted attacks, vary from requiring the user to download and run an executable, to as streamlined as tricking the user to click a URL. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-494.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-534-malicious-hardware-update",
    "title": "MITRE CAPEC-534: Malicious Hardware Update (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-534 (Malicious Hardware Update) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary introduces malicious hardware during an update or replacement procedure, allowing for additional compromise or site disruption at the victim location. After deployment, it is not uncommon for upgrades and replacements to occur involving hardware and various replaceable parts. These upgrades and replacements are intended to correct defects, provide additional features, and to replace broken or worn-out parts. However, by forcing or tricking the replacement of a good component with a defective or corrupted component, an adversary can leverage known defects to obtain a desired malicious impact. Likelihood of attack: Low. Typical severity: High. Child of CAPEC-440.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "cisa-sbom-minimum-elements-2021"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-535-malicious-gray-market-hardware",
    "title": "MITRE CAPEC-535: Malicious Gray Market Hardware (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-535 (Malicious Gray Market Hardware) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker maliciously alters hardware components that will be sold on the gray market, allowing for victim disruption and compromise when the victim needs replacement hardware components for systems where the parts are no longer in regular supply from original suppliers, or where the hardware components from the attacker seems to be a great benefit from a cost perspective. Likelihood of attack: Low. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-536-data-injected-during-configuration",
    "title": "MITRE CAPEC-536: Data Injected During Configuration (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-536 (Data Injected During Configuration) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to data files and processes on a victim's system injects malicious data into critical operational data during configuration or recalibration, causing the victim's system to perform in a suboptimal manner that benefits the adversary. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-284.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-537-infiltration-of-hardware-development-environment",
    "title": "MITRE CAPEC-537: Infiltration of Hardware Development Environment (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-537 (Infiltration of Hardware Development Environment) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, leveraging the ability to manipulate components of primary support systems and tools within the development and production environments, inserts malicious software within the hardware and/or firmware development environment. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1195.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-538-open-source-library-manipulation",
    "title": "MITRE CAPEC-538: Open-Source Library Manipulation (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-538 (Open-Source Library Manipulation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries implant malicious code in open source software (OSS) libraries to have it widely distributed, as OSS is commonly downloaded by developers and other users to incorporate into software development projects. The adversary can have a particular system in mind to target, or the implantation can be the first stage of follow-on attacks on many systems. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-494, CWE-829. Relates to MITRE ATT&CK T1195.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-539-asic-with-malicious-functionality",
    "title": "MITRE CAPEC-539: ASIC With Malicious Functionality (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-539 (ASIC With Malicious Functionality) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to the development environment process of an application-specific integrated circuit (ASIC) for a victim system being developed or maintained after initial deployment can insert malicious functionality into the system for the purpose of disruption or further compromise. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1195.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-54-query-system-for-information",
    "title": "MITRE CAPEC-54: Query System for Information (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-54 (Query System for Information) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, aware of an application's location (and possibly authorized to use the application), probes an application's structure and evaluates its robustness by submitting requests and examining responses. Often, this is accomplished by sending variants of expected queries in the hope that these modified queries might return information beyond what the expected set of queries would provide. Likelihood of attack: High. Typical severity: Low. Parent pattern for CAPEC-127 Directory Indexing; CAPEC-215 Fuzzing for application mapping; CAPEC-261 Fuzzing for garnering other adjacent user/sensitive data; and others. Maps to weaknesses CWE-209.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-540-overread-buffers",
    "title": "MITRE CAPEC-540: Overread Buffers (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-540 (Overread Buffers) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary attacks a target by providing input that causes an application to read beyond the boundary of a defined buffer. This typically occurs when a value influencing where to start or stop reading is set to reflect positions outside of the valid memory location of the buffer. This type of attack may result in exposure of sensitive information, a system crash, or arbitrary code execution. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-125.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-541-application-fingerprinting",
    "title": "MITRE CAPEC-541: Application Fingerprinting (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-541 (Application Fingerprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in fingerprinting activities to determine the type or version of an application installed on a remote target. Likelihood of attack: Unknown. Typical severity: Low. Parent pattern for CAPEC-170 Web Application Fingerprinting; CAPEC-310 Scanning for Vulnerable Software; CAPEC-472 Browser Fingerprinting. Maps to weaknesses CWE-204, CWE-205, CWE-208. Relates to MITRE ATT&CK T1592.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1592-gather-victim-host-information"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-542-targeted-malware",
    "title": "MITRE CAPEC-542: Targeted Malware (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-542 (Targeted Malware) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary develops targeted malware that takes advantage of a known vulnerability in an organizational information technology environment. The malware crafted for these attacks is based specifically on information gathered about the technology environment. Successfully executing the malware enables an adversary to achieve a wide variety of negative technical impacts. Likelihood of attack: Unknown. Parent pattern for CAPEC-550 Install New Service; CAPEC-551 Modify Existing Service; CAPEC-552 Install Rootkit; and others. Relates to MITRE ATT&CK T1587.001, T1027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1587-develop-capabilities",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-543-counterfeit-websites",
    "title": "MITRE CAPEC-543: Counterfeit Websites (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-543 (Counterfeit Websites) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversary creates duplicates of legitimate websites. When users visit a counterfeit site, the site can gather information or upload malware. Likelihood of attack: Unknown. Typical severity: High. Relates to MITRE ATT&CK T1036.005.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-544-counterfeit-organizations",
    "title": "MITRE CAPEC-544: Counterfeit Organizations (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-544 (Counterfeit Organizations) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary creates a false front organizations with the appearance of a legitimate supplier in the critical life cycle path that then injects corrupted/malicious information system components into the organizational supply chain. Likelihood of attack: Unknown. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-545-pull-data-from-system-resources",
    "title": "MITRE CAPEC-545: Pull Data from System Resources (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-545 (Pull Data from System Resources) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary who is authorized or has the ability to search known system resources, does so with the intention of gathering useful information. System resources include files, memory, and other aspects of the target system. In this pattern of attack, the adversary does not necessarily know what they are going to find when they start pulling data. Likelihood of attack: Unknown. Parent pattern for CAPEC-498 Probe iOS Screenshots; CAPEC-546 Incomplete Data Deletion in a Multi-Tenant Environment; CAPEC-634 Probe Audio and Video Peripherals; and others. Maps to weaknesses CWE-1239, CWE-1243, CWE-1258, CWE-1266, and others. Relates to MITRE ATT&CK T1005, T1555.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1005-data-from-local-system",
      "mitre-attack-t1555-credentials-from-password-stores"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-546-incomplete-data-deletion-in-a-multi-tenant-environment",
    "title": "MITRE CAPEC-546: Incomplete Data Deletion in a Multi-Tenant Environment (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-546 (Incomplete Data Deletion in a Multi-Tenant Environment) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary obtains unauthorized information due to insecure or incomplete data deletion in a multi-tenant environment. If a cloud provider fails to completely delete storage and data from former cloud tenants' systems/resources, once these resources are allocated to new, potentially malicious tenants, the latter can probe the provided resources for sensitive information still there. Likelihood of attack: Low. Typical severity: Medium. Maps to weaknesses CWE-284, CWE-1266, CWE-1272.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-547-physical-destruction-of-device-or-component",
    "title": "MITRE CAPEC-547: Physical Destruction of Device or Component (Standard Attack Pattern - Unrated Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-547 (Physical Destruction of Device or Component) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary conducts a physical attack a device or component, destroying it such that it no longer functions as intended. Child of CAPEC-607.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-548-contaminate-resource",
    "title": "MITRE CAPEC-548: Contaminate Resource (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-548 (Contaminate Resource) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary contaminates organizational information systems (including devices and networks) by causing them to handle information of a classification/sensitivity for which they have not been authorized. When this happens, the contaminated information system, device, or network must be brought offline to investigate and mitigate the data spill, which denies availability of the system until the investigation is. Likelihood of attack: Low. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-549-local-execution-of-code",
    "title": "MITRE CAPEC-549: Local Execution of Code (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-549 (Local Execution of Code) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary installs and executes malicious code on the target system in an effort to achieve a negative technical impact. Examples include rootkits, ransomware, spyware, adware, and others. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-542 Targeted Malware. Maps to weaknesses CWE-829.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-55-rainbow-table-password-cracking",
    "title": "MITRE CAPEC-55: Rainbow Table Password Cracking (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-55 (Rainbow Table Password Cracking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker gets access to the database table where hashes of passwords are stored. They then use a rainbow table of pre-computed hash chains to attempt to look up the original password. Once the original password corresponding to the hash is obtained, the attacker uses the original password to gain access to the system. Likelihood of attack: Medium. Typical severity: Medium. Maps to weaknesses CWE-261, CWE-521, CWE-262, CWE-263, and others. Relates to MITRE ATT&CK T1110.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1110-004-credential-stuffing"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-capec-capec-550-install-new-service",
    "title": "MITRE CAPEC-550: Install New Service (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-550 (Install New Service) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. When an operating system starts, it also starts programs called services or daemons. Adversaries may install a new service which will be executed at startup (on a Windows system, by modifying the registry). The service name may be disguised by using a name from a related operating system or benign software. Services are usually run with elevated privileges. Likelihood of attack: Unknown. Maps to weaknesses CWE-284. Relates to MITRE ATT&CK T1543.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1543-005-container-service"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-551-modify-existing-service",
    "title": "MITRE CAPEC-551: Modify Existing Service (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-551 (Modify Existing Service) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. When an operating system starts, it also starts programs called services or daemons. Modifying existing services may break existing services or may enable services that are disabled/not commonly used. Likelihood of attack: Unknown. Maps to weaknesses CWE-284, CWE-522. Relates to MITRE ATT&CK T1543.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1543-005-container-service"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-552-install-rootkit",
    "title": "MITRE CAPEC-552: Install Rootkit (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-552 (Install Rootkit) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in authentication to install malware that alters the functionality and information provide by targeted operating system API calls. Often referred to as rootkits, it is often used to hide the presence of programs, files, network connections, services, drivers, and other system components. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-284. Relates to MITRE ATT&CK T1014, T1542.003, T1547.006.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1014-rootkit",
      "mitre-attack-t1542-pre-os-boot"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-554-functionality-bypass",
    "title": "MITRE CAPEC-554: Functionality Bypass (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-554 (Functionality Bypass) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary attacks a system by bypassing some or all functionality intended to protect it. Often, a system user will think that protection is in place, but the functionality behind those protections has been disabled by the adversary. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-179 Calling Micro-Services Directly; CAPEC-464 Evercookie; CAPEC-465 Transparent Proxy Abuse. Maps to weaknesses CWE-424, CWE-1299.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-555-remote-services-with-stolen-credentials",
    "title": "MITRE CAPEC-555: Remote Services with Stolen Credentials (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-555 (Remote Services with Stolen Credentials) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This pattern of attack involves an adversary that uses stolen credentials to leverage remote services such as RDP, telnet, SSH, and VNC to log into a system. Once access is gained, any number of malicious activities could be performed. Likelihood of attack: Unknown. Typical severity: Very High. Maps to weaknesses CWE-522, CWE-308, CWE-309, CWE-294, and others. Relates to MITRE ATT&CK T1021, T1114.002, T1133.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1021-008-direct-cloud-vm-connections",
      "mitre-attack-t1114-003-email-forwarding-rule"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-556-replace-file-extension-handlers",
    "title": "MITRE CAPEC-556: Replace File Extension Handlers (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-556 (Replace File Extension Handlers) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. When a file is opened, its file handler is checked to determine which program opens the file. File handlers are configuration properties of many operating systems. Applications can modify the file handler for a given file extension to call an arbitrary program when a file with the given extension is opened. Likelihood of attack: Unknown. Maps to weaknesses CWE-284. Relates to MITRE ATT&CK T1546.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-558-replace-trusted-executable",
    "title": "MITRE CAPEC-558: Replace Trusted Executable (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-558 (Replace Trusted Executable) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits weaknesses in privilege management or access control to replace a trusted executable with a malicious version and enable the execution of malware when that trusted executable is called. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-284. Relates to MITRE ATT&CK T1505.005, T1546.008.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1505-server-software-component",
      "mitre-attack-t1546-event-triggered-execution"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-559-orbital-jamming",
    "title": "MITRE CAPEC-559: Orbital Jamming (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-559 (Orbital Jamming) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, the adversary sends disruptive signals at a target satellite using a rogue uplink station to disrupt the intended transmission. Those within the satellite's footprint are prevented from reaching the satellite's targeted or neighboring channels. The satellite's footprint size depends upon its position in the sky; higher orbital satellites cover multiple continents. Likelihood of attack: Low. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-560-use-of-known-domain-credentials",
    "title": "MITRE CAPEC-560: Use of Known Domain Credentials (Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-560 (Use of Known Domain Credentials) is an attack pattern in which an adversary guesses or obtains (steals or purchases) legitimate credentials to achieve authentication and perform authorized actions under the guise of an authenticated user or service. Likelihood of attack: High. Typical severity: High. Maps to MITRE ATT&CK T1078 (Valid Accounts) and CWE-522 (Insufficiently Protected Credentials), CWE-307 (Improper Restriction of Excessive Authentication Attempts), CWE-308 (Use of Single-factor Authentication), CWE-309 (Use of Password System for Primary Authentication). Compliance: PCI DSS v4.0 Req 8, NIST SP 800-53 IA-2, NYDFS Part 500 MFA, CISA Phishing-Resistant MFA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1078-004-cloud-accounts",
      "mitre-attack-t1110-brute-force",
      "mitre-d3fend-d3-ch-credential-hardening",
      "mitre-d3fend-d3-mfa-multi-factor-authentication"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-561-windows-admin-shares-with-stolen-credentials",
    "title": "MITRE CAPEC-561: Windows Admin Shares with Stolen Credentials (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-561 (Windows Admin Shares with Stolen Credentials) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary guesses or obtains (i.e. steals or purchases) legitimate Windows administrator credentials (e.g. userID/password) to access Windows Admin Shares on a local machine or within a Windows domain. Likelihood of attack: Unknown. Maps to weaknesses CWE-522, CWE-308, CWE-309, CWE-294, and others. Relates to MITRE ATT&CK T1021.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1021-008-direct-cloud-vm-connections"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-capec-capec-562-modify-shared-file",
    "title": "MITRE CAPEC-562: Modify Shared File (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-562 (Modify Shared File) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates the files in a shared location by adding malicious programs, scripts, or exploit code to valid content. Once a user opens the shared content, the tainted content is executed. Likelihood of attack: Unknown. Maps to weaknesses CWE-284. Relates to MITRE ATT&CK T1080.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1080-taint-shared-content"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-563-add-malicious-file-to-shared-webroot",
    "title": "MITRE CAPEC-563: Add Malicious File to Shared Webroot (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-563 (Add Malicious File to Shared Webroot) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversaries may add malicious content to a website through the open file share and then browse to that content with a web browser to cause the server to execute the content. The malicious content will typically run under the context and permissions of the web server process, often resulting in local system or administrative privileges depending on how the web server is configured. Likelihood of attack: Unknown. Maps to weaknesses CWE-284.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-564-run-software-at-logon",
    "title": "MITRE CAPEC-564: Run Software at Logon (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-564 (Run Software at Logon) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Operating system allows logon scripts to be run whenever a specific user or users logon to a system. If adversaries can access these scripts, they may insert additional code into the logon script. This code can allow them to maintain persistence or move laterally within an enclave because it is executed every time the affected user or users logon to a computer. Likelihood of attack: Unknown. Maps to weaknesses CWE-284. Relates to MITRE ATT&CK T1037, T1543.001, T1543.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1037-boot-or-logon-initialization-scripts",
      "mitre-attack-t1543-005-container-service"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-565-password-spraying",
    "title": "MITRE CAPEC-565: Password Spraying (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-565 (Password Spraying) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In a Password Spraying attack, an adversary tries a small list (e.g. 3-5) of common or expected passwords, often matching the target's complexity policy, against a known list of user accounts to gain valid credentials. The adversary tries a particular password for each user account, before moving onto the next password in the list. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-521, CWE-262, CWE-263, CWE-654, and others. Relates to MITRE ATT&CK T1110.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1110-004-credential-stuffing"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-capec-capec-568-capture-credentials-via-keylogger",
    "title": "MITRE CAPEC-568: Capture Credentials via Keylogger (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-568 (Capture Credentials via Keylogger) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary deploys a keylogger in an effort to obtain credentials directly from a system's user. After capturing all the keystrokes made by a user, the adversary can analyze the data and determine which string are likely to be passwords or other credential related information. Likelihood of attack: Unknown. Typical severity: High. Relates to MITRE ATT&CK T1056.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1056-input-capture"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-569-collect-data-as-provided-by-users",
    "title": "MITRE CAPEC-569: Collect Data as Provided by Users (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-569 (Collect Data as Provided by Users) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker leverages a tool, device, or program to obtain specific information as provided by a user of the target system. This information is often needed by the attacker to launch a follow-on attack. This attack is different than Social Engineering as the adversary is not tricking or deceiving the user. Likelihood of attack: Unknown. Parent pattern for CAPEC-568 Capture Credentials via Keylogger. Relates to MITRE ATT&CK T1056.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1056-input-capture"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-57-utilizing-rest-s-trust-in-the-system-resource",
    "title": "MITRE CAPEC-57: Utilizing REST's Trust in the System Resource to Obtain Sensitive Data (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-57 (Utilizing REST's Trust in the System Resource to Obtain Sensitive Data) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack utilizes a REST(REpresentational State Transfer)-style applications' trust in the system resources and environment to obtain sensitive data once SSL is terminated. Likelihood of attack: Medium. Typical severity: Very High. Maps to weaknesses CWE-300, CWE-287, CWE-693. Relates to MITRE ATT&CK T1040.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1040-network-sniffing"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-571-block-logging-to-central-repository",
    "title": "MITRE CAPEC-571: Block Logging to Central Repository (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-571 (Block Logging to Central Repository) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary prevents host-generated logs being delivered to a central location in an attempt to hide indicators of compromise. Likelihood of attack: Unknown. Typical severity: Low. Relates to MITRE ATT&CK T1562.002, T1562.002, T1562.006.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1685-004-disable-or-modify-linux-audit-system-log"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-572-artificially-inflate-file-sizes",
    "title": "MITRE CAPEC-572: Artificially Inflate File Sizes (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-572 (Artificially Inflate File Sizes) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary modifies file contents by adding data to files for several reasons. Many different attacks could \"follow\" this pattern resulting in numerous outcomes. Adding data to a file could also result in a Denial of Service condition for devices with limited storage capacity. Likelihood of attack: High. Typical severity: Medium. Parent pattern for CAPEC-655 Avoid Security Tool Identification by Adding Data. Relates to MITRE ATT&CK T1027.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-573-process-footprinting",
    "title": "MITRE CAPEC-573: Process Footprinting (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-573 (Process Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits functionality meant to identify information about the currently running processes on the target system to an authorized user. By knowing what processes are running on the target system, the adversary can learn about the target environment as a means towards further malicious behavior. Likelihood of attack: Low. Typical severity: Low. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1057.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1057-process-discovery"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-574-services-footprinting",
    "title": "MITRE CAPEC-574: Services Footprinting (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-574 (Services Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits functionality meant to identify information about the services on the target system to an authorized user. By knowing what services are registered on the target system, the adversary can learn about the target environment as a means towards further malicious behavior. Likelihood of attack: Low. Typical severity: Low. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1007.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1007-system-service-discovery"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-575-account-footprinting",
    "title": "MITRE CAPEC-575: Account Footprinting (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-575 (Account Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits functionality meant to identify information about the domain accounts and their permissions on the target system to an authorized user. By knowing what accounts are registered on the target system, the adversary can inform further and more targeted malicious behavior. Example Windows commands which can acquire this information are: \"net user\" and \"dsquery\". Likelihood of attack: Low. Typical severity: Low. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1087.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1087-account-discovery"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-576-group-permission-footprinting",
    "title": "MITRE CAPEC-576: Group Permission Footprinting (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-576 (Group Permission Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits functionality meant to identify information about user groups and their permissions on the target system to an authorized user. By knowing what users/permissions are registered on the target system, the adversary can inform further and more targeted malicious behavior. An example Windows command which can list local groups is \"net localgroup\". Likelihood of attack: Low. Typical severity: Low. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1069, T1615.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1069-permission-groups-discovery",
      "mitre-attack-t1615-group-policy-discovery"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-577-owner-footprinting",
    "title": "MITRE CAPEC-577: Owner Footprinting (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-577 (Owner Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits functionality meant to identify information about the primary users on the target system to an authorized user. They may do this, for example, by reviewing logins or file modification times. By knowing what owners use the target system, the adversary can inform further and more targeted malicious behavior. An example Windows command that may accomplish this is \"dir /A ntuser.dat\". Likelihood of attack: Low. Typical severity: Low. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1033.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1033-system-owner-user-discovery"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-578-disable-security-software",
    "title": "MITRE CAPEC-578: Disable Security Software (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-578 (Disable Security Software) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in access control to disable security tools so that detection does not occur. This can take the form of killing processes, deleting registry keys so that tools do not start at run time, deleting log files, or other methods. Likelihood of attack: Medium. Typical severity: Medium. Maps to weaknesses CWE-284. Relates to MITRE ATT&CK T1556.006, T1562.001, T1562.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1556-modify-authentication-process",
      "mitre-attack-t1685-004-disable-or-modify-linux-audit-system-log"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-579-replace-winlogon-helper-dll",
    "title": "MITRE CAPEC-579: Replace Winlogon Helper DLL (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-579 (Replace Winlogon Helper DLL) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Winlogon is a part of Windows that performs logon actions. In Windows systems prior to Windows Vista, a registry key can be modified that causes Winlogon to load a DLL on startup. Adversaries may take advantage of this feature to load adversarial code at startup. Likelihood of attack: Unknown. Maps to weaknesses CWE-15. Relates to MITRE ATT&CK T1547.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1547-015-login-items"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-58-restful-privilege-elevation",
    "title": "MITRE CAPEC-58: Restful Privilege Elevation (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-58 (Restful Privilege Elevation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary identifies a Rest HTTP (Get, Put, Delete) style permission method allowing them to perform various malicious actions upon server data due to lack of access control mechanisms implemented within the application service accepting HTTP messages. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-267, CWE-269.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-580-system-footprinting",
    "title": "MITRE CAPEC-580: System Footprinting (Standard Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-580 (System Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in active probing and exploration activities to determine security information about a remote target system. Often times adversaries will rely on remote applications that can be probed for system configurations. Likelihood of attack: Low. Typical severity: Low. Parent pattern for CAPEC-581 Security Software Footprinting; CAPEC-85 AJAX Footprinting. Maps to weaknesses CWE-204, CWE-205, CWE-208. Relates to MITRE ATT&CK T1082.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-581-security-software-footprinting",
    "title": "MITRE CAPEC-581: Security Software Footprinting (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-581 (Security Software Footprinting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries may attempt to get a listing of security tools that are installed on the system and their configurations. This may include security related system features (such as a built-in firewall or anti-spyware) as well as third-party security software. Likelihood of attack: Unknown. Relates to MITRE ATT&CK T1518.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1518-software-discovery"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-582-route-disabling",
    "title": "MITRE CAPEC-582: Route Disabling (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-582 (Route Disabling) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary disables the network route between two targets. The goal is to completely sever the communications channel between two entities. This is often the result of a major error or the use of an \"Internet kill switch\" by those in control of critical infrastructure. This attack pattern differs from most other obstruction patterns by targeting the route itself, as opposed to the data passed over the route. Likelihood of attack: Low. Typical severity: High. Parent pattern for CAPEC-583 Disabling Network Hardware; CAPEC-584 BGP Route Disabling; CAPEC-585 DNS Domain Seizure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-583-disabling-network-hardware",
    "title": "MITRE CAPEC-583: Disabling Network Hardware (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-583 (Disabling Network Hardware) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, an adversary physically disables networking hardware by powering it down or disconnecting critical equipment. Disabling or shutting off critical system resources prevents them from performing their service as intended, which can have direct and indirect consequences on other systems. Likelihood of attack: Unknown.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-584-bgp-route-disabling",
    "title": "MITRE CAPEC-584: BGP Route Disabling (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-584 (BGP Route Disabling) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary suppresses the Border Gateway Protocol (BGP) advertisement for a route so as to render the underlying network inaccessible. The BGP protocol helps traffic move throughout the Internet by selecting the most efficient route between Autonomous Systems (AS), or routing domains. BGP is the basis for interdomain routing infrastructure, providing connections between these ASs. Likelihood of attack: Unknown.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-585-dns-domain-seizure",
    "title": "MITRE CAPEC-585: DNS Domain Seizure (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-585 (DNS Domain Seizure) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, an adversary influences a target's web-hosting company to disable a target domain. The goal is to prevent access to the targeted service provided by that domain. It usually occurs as the result of civil or criminal legal interventions. Likelihood of attack: Unknown.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-586-object-injection",
    "title": "MITRE CAPEC-586: Object Injection (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-586 (Object Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary attempts to exploit an application by injecting additional, malicious content during its processing of serialized objects. Developers leverage serialization in order to convert data or state into a static, binary format for saving to disk or transferring over a network. These objects are then deserialized when needed to recover the data/state. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-502.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-587-cross-frame-scripting-xfs",
    "title": "MITRE CAPEC-587: Cross Frame Scripting (XFS) (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-587 (Cross Frame Scripting (XFS)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack pattern combines malicious Javascript and a legitimate webpage loaded into a concealed iframe. The malicious Javascript is then able to interact with a legitimate webpage in a manner that is unknown to the user. This attack usually leverages some element of social engineering in that an attacker must convinces a user to visit a web page that the attacker controls. Likelihood of attack: Unknown. Typical severity: High. Maps to weaknesses CWE-1021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-588-dom-based-xss",
    "title": "MITRE CAPEC-588: DOM-Based XSS (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-588 (DOM-Based XSS) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is inserted into the client-side HTML being parsed by a web browser. Content served by a vulnerable web application includes script code used to manipulate the Document Object Model (DOM). Likelihood of attack: High. Typical severity: Very High. Parent pattern for CAPEC-18 XSS Targeting Non-Script Elements; CAPEC-198 XSS Targeting Error Pages; CAPEC-199 XSS Using Alternate Syntax; and others. Maps to weaknesses CWE-79, CWE-20, CWE-83.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-589-dns-blocking",
    "title": "MITRE CAPEC-589: DNS Blocking (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-589 (DNS Blocking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary intercepts traffic and intentionally drops DNS requests based on content in the request. In this way, the adversary can deny the availability of specific services or content to the user even if the IP address is changed. Likelihood of attack: Unknown. Maps to weaknesses CWE-300.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-59-session-credential-falsification-through-prediction",
    "title": "MITRE CAPEC-59: Session Credential Falsification through Prediction (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-59 (Session Credential Falsification through Prediction) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets predictable session ID in order to gain privileges. The attacker can predict the session ID used during a transaction to perform spoofing and session hijacking. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-290, CWE-330, CWE-331, CWE-346, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-590-ip-address-blocking",
    "title": "MITRE CAPEC-590: IP Address Blocking (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-590 (IP Address Blocking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary performing this type of attack drops packets destined for a target IP address. The aim is to prevent access to the service hosted at the target IP address. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-300.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-591-reflected-xss",
    "title": "MITRE CAPEC-591: Reflected XSS (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-591 (Reflected XSS) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is \"reflected\" off a vulnerable web application and then executed by a victim's browser. The process starts with an adversary delivering a malicious script to a victim and convincing the victim to send the script to the vulnerable web application. Likelihood of attack: High. Typical severity: Very High. Parent pattern for CAPEC-18 XSS Targeting Non-Script Elements; CAPEC-198 XSS Targeting Error Pages; CAPEC-199 XSS Using Alternate Syntax; and others. Maps to weaknesses CWE-79.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-592-stored-xss",
    "title": "MITRE CAPEC-592: Stored XSS (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-592 (Stored XSS) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary utilizes a form of Cross-site Scripting (XSS) where a malicious script is persistently \"stored\" within the data storage of a vulnerable web application as valid input. Likelihood of attack: High. Typical severity: Very High. Parent pattern for CAPEC-18 XSS Targeting Non-Script Elements; CAPEC-198 XSS Targeting Error Pages; CAPEC-199 XSS Using Alternate Syntax; and others. Maps to weaknesses CWE-79.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-593-session-hijacking",
    "title": "MITRE CAPEC-593: Session Hijacking (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-593 (Session Hijacking) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack involves an adversary that exploits weaknesses in an application's use of sessions in performing authentication. The adversary is able to steal or manipulate an active session and use it to gain unathorized access to the application. Likelihood of attack: High. Typical severity: Very High. Parent pattern for CAPEC-102 Session Sidejacking; CAPEC-107 Cross Site Tracing; CAPEC-60 Reusing Session IDs (aka Session Replay); and others. Maps to weaknesses CWE-287. Relates to MITRE ATT&CK T1185, T1550.001, T1563.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1185-browser-session-hijacking",
      "mitre-attack-t1550-use-alternate-authentication-material"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-594-traffic-injection",
    "title": "MITRE CAPEC-594: Traffic Injection (Meta Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-594 (Traffic Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary injects traffic into the target's network connection. The adversary is therefore able to degrade or disrupt the connection, and potentially modify the content. This is not a flooding attack, as the adversary is not focusing on exhausting resources. Instead, the adversary is crafting a specific input to affect the system in a particular way. Likelihood of attack: Unknown. Parent pattern for CAPEC-595 Connection Reset. Maps to weaknesses CWE-940.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-595-connection-reset",
    "title": "MITRE CAPEC-595: Connection Reset (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-595 (Connection Reset) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, an adversary injects a connection reset packet to one or both ends of a target's connection. The attacker is therefore able to have the target and/or the destination server sever the connection without having to directly filter the traffic between them. Likelihood of attack: Unknown. Parent pattern for CAPEC-596 TCP RST Injection. Maps to weaknesses CWE-940.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-596-tcp-rst-injection",
    "title": "MITRE CAPEC-596: TCP RST Injection (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-596 (TCP RST Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary injects one or more TCP RST packets to a target after the target has made a HTTP GET request. The goal of this attack is to have the target and/or destination web server terminate the TCP connection. Likelihood of attack: Unknown. Maps to weaknesses CWE-940.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-597-absolute-path-traversal",
    "title": "MITRE CAPEC-597: Absolute Path Traversal (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-597 (Absolute Path Traversal) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary with access to file system resources, either directly or via application logic, will use various file absolute paths and navigation mechanisms such as \"..\" to extend their range of access to inappropriate areas of the file system. The goal of the adversary is to access directories and files that are intended to be restricted from their access. Likelihood of attack: Unknown. Maps to weaknesses CWE-36.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-598-dns-spoofing",
    "title": "MITRE CAPEC-598: DNS Spoofing (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-598 (DNS Spoofing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends a malicious (\"NXDOMAIN\" (\"No such domain\") code, or DNS A record) response to a target's route request before a legitimate resolver can. This technique requires an On-path or In-path device that can monitor and respond to the target's DNS requests. Likelihood of attack: Unknown.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-599-terrestrial-jamming",
    "title": "MITRE CAPEC-599: Terrestrial Jamming (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-599 (Terrestrial Jamming) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, the adversary transmits disruptive signals in the direction of the target's consumer-level satellite dish (as opposed to the satellite itself). The transmission disruption occurs in a more targeted range. Portable terrestrial jammers have a range of 3-5 kilometers in urban areas and 20 kilometers in rural areas. This technique requires a terrestrial jammer that is more powerful than the frequencies sent from the satellite. Likelihood of attack: Low. Typical severity: High. Child of CAPEC-195.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-6-argument-injection",
    "title": "MITRE CAPEC-6: Argument Injection (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-6 (Argument Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker changes the behavior or state of a targeted application through injecting data or command syntax through the targets use of non-validated and non-filtered arguments of exposed services or methods. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-74, CWE-146, CWE-184, CWE-78, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-60-reusing-session-ids-aka-session-replay",
    "title": "MITRE CAPEC-60: Reusing Session IDs (aka Session Replay) (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-60 (Reusing Session IDs (aka Session Replay)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the reuse of valid session ID to spoof the target system in order to gain privileges. The attacker tries to reuse a stolen session ID used previously during a transaction to perform spoofing and session hijacking. Another name for this type of attack is Session Replay. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-294, CWE-290, CWE-346, CWE-384, and others. Relates to MITRE ATT&CK T1134.001, T1550.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1134-access-token-manipulation",
      "mitre-attack-t1550-use-alternate-authentication-material"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-600-credential-stuffing",
    "title": "MITRE CAPEC-600: Credential Stuffing (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-600 (Credential Stuffing) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary tries known username/password combinations against different systems, applications, or services to gain additional authenticated access. Credential Stuffing attacks rely upon the fact that many users leverage the same username/password combination for multiple systems, applications, and services. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-522, CWE-307, CWE-308, CWE-309, and others. Relates to MITRE ATT&CK T1110.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1110-004-credential-stuffing"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-601-jamming",
    "title": "MITRE CAPEC-601: Jamming (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-601 (Jamming) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses radio noise or signals in an attempt to disrupt communications. By intentionally overwhelming system resources with illegitimate traffic, service is denied to the legitimate traffic of authorized users. Likelihood of attack: Medium. Typical severity: High. Child of CAPEC-607.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-603-blockage",
    "title": "MITRE CAPEC-603: Blockage (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-603 (Blockage) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary blocks the delivery of an important system resource causing the system to fail or stop working. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-589 DNS Blocking; CAPEC-590 IP Address Blocking; CAPEC-96 Block Access to Libraries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-604-wi-fi-jamming",
    "title": "MITRE CAPEC-604: Wi-Fi Jamming (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-604 (Wi-Fi Jamming) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker actively transmits on the Wi-Fi channel to prevent users from transmitting or receiving data from the targeted Wi-Fi network. There are several known techniques to perform this attack - for example: the attacker may flood the Wi-Fi access point (e.g. the retransmission device) with deauthentication frames. Likelihood of attack: Medium. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-605-cellular-jamming",
    "title": "MITRE CAPEC-605: Cellular Jamming (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-605 (Cellular Jamming) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker actively transmits signals to overpower and disrupt the communication between a cellular user device and a cell tower. Several existing techniques are known in the open literature for this attack for 2G, 3G, and 4G LTE cellular technology. Likelihood of attack: Unknown. Typical severity: Low.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-606-weakening-of-cellular-encryption",
    "title": "MITRE CAPEC-606: Weakening of Cellular Encryption (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-606 (Weakening of Cellular Encryption) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker, with control of a Cellular Rogue Base Station or through cooperation with a Malicious Mobile Network Operator can force the mobile device (e.g., the retransmission device) to use no encryption (A5/0 mode) or to use easily breakable encryption (A5/1 or A5/2 mode). Likelihood of attack: Unknown. Typical severity: High. Maps to weaknesses CWE-757.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-607-obstruction",
    "title": "MITRE CAPEC-607: Obstruction (Meta Attack Pattern - Unrated Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE CAPEC-607 (Obstruction) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker obstructs the interactions between system components. By interrupting or disabling these interactions, an adversary can often force the system into a degraded state or cause the system to stop working as intended. This can cause the system components to be unavailable until the obstruction mitigated.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-608-cryptanalysis-of-cellular-encryption",
    "title": "MITRE CAPEC-608: Cryptanalysis of Cellular Encryption (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-608 (Cryptanalysis of Cellular Encryption) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The use of cryptanalytic techniques to derive cryptographic keys or otherwise effectively defeat cellular encryption to reveal traffic content. Some cellular encryption algorithms such as A5/1 and A5/2 (specified for GSM use) are known to be vulnerable to such attacks and commercial tools are available to execute these attacks and decrypt mobile phone conversations in real-time. Likelihood of attack: Unknown. Typical severity: High. Maps to weaknesses CWE-327.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-609-cellular-traffic-intercept",
    "title": "MITRE CAPEC-609: Cellular Traffic Intercept (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-609 (Cellular Traffic Intercept) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Cellular traffic for voice and data from mobile devices and retransmission devices can be intercepted via numerous methods. Malicious actors can deploy their own cellular tower equipment and intercept cellular traffic surreptitiously. Additionally, government agencies of adversaries and malicious actors can intercept cellular traffic via the telecommunications backbone over which mobile traffic is transmitted. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-311. Relates to MITRE ATT&CK T1111.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1111-multi-factor-authentication-interception"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-61-session-fixation",
    "title": "MITRE CAPEC-61: Session Fixation (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-61 (Session Fixation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The attacker induces a client to establish a session with the target software using a session identifier provided by the attacker. Once the user successfully authenticates to the target software, the attacker uses the (now privileged) session identifier in their own transactions. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-384, CWE-664, CWE-732.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-610-cellular-data-injection",
    "title": "MITRE CAPEC-610: Cellular Data Injection (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-610 (Cellular Data Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries inject data into mobile technology traffic (data flows or signaling data) to disrupt communications or conduct additional surveillance operations. Likelihood of attack: Unknown. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-611-bitsquatting",
    "title": "MITRE CAPEC-611: BitSquatting (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-611 (BitSquatting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary registers a domain name one bit different than a trusted domain. A BitSquatting attack leverages random errors in memory to direct Internet traffic to adversary-controlled destinations. BitSquatting requires no exploitation or complicated reverse engineering, and is operating system and architecture agnostic. Likelihood of attack: Low. Typical severity: Medium.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-612-wifi-mac-address-tracking",
    "title": "MITRE CAPEC-612: WiFi MAC Address Tracking (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-612 (WiFi MAC Address Tracking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker passively listens for WiFi messages and logs the associated Media Access Control (MAC) addresses. These addresses are intended to be unique to each wireless device (although they can be configured and changed by software). Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-201, CWE-300.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-613-wifi-ssid-tracking",
    "title": "MITRE CAPEC-613: WiFi SSID Tracking (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-613 (WiFi SSID Tracking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker passively listens for WiFi management frame messages containing the Service Set Identifier (SSID) for the WiFi network. These messages are frequently transmitted by WiFi access points (e.g., the retransmission device) as well as by clients that are accessing the network (e.g., the handset/mobile device). Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-201, CWE-300.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-614-rooting-sim-cards",
    "title": "MITRE CAPEC-614: Rooting SIM Cards (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-614 (Rooting SIM Cards) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. SIM cards are the de facto trust anchor of mobile devices worldwide. The cards protect the mobile identity of subscribers, associate devices with phone numbers, and increasingly store payment credentials, for example in NFC-enabled phones with mobile wallets. This attack leverages over-the-air (OTA) updates deployed via cryptographically-secured SMS messages to deliver executable code to the SIM. Likelihood of attack: Unknown. Typical severity: High. Maps to weaknesses CWE-327.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-615-evil-twin-wi-fi-attack",
    "title": "MITRE CAPEC-615: Evil Twin Wi-Fi Attack (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-615 (Evil Twin Wi-Fi Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries install Wi-Fi equipment that acts as a legitimate Wi-Fi network access point. When a device connects to this access point, Wi-Fi data traffic is intercepted, captured, and analyzed. This also allows the adversary to use \"adversary-in-the-middle\" (CAPEC-94) for all communications. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-300.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-616-establish-rogue-location",
    "title": "MITRE CAPEC-616: Establish Rogue Location (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-616 (Establish Rogue Location) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary provides a malicious version of a resource at a location that is similar to the expected location of a legitimate resource. After establishing the rogue location, the adversary waits for a victim to visit the location and access the malicious resource. Likelihood of attack: Medium. Typical severity: Medium. Parent pattern for CAPEC-505 Scheme Squatting; CAPEC-611 BitSquatting; CAPEC-615 Evil Twin Wi-Fi Attack; and others. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1036.005.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-617-cellular-rogue-base-station",
    "title": "MITRE CAPEC-617: Cellular Rogue Base Station (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-617 (Cellular Rogue Base Station) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker imitates a cellular base station with their own \"rogue\" base station equipment. Since cellular devices connect to whatever station has the strongest signal, the attacker can easily convince a targeted cellular device (e.g. the retransmission device) to talk to the rogue base station. Likelihood of attack: Unknown. Typical severity: Low.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-618-cellular-broadcast-message-request",
    "title": "MITRE CAPEC-618: Cellular Broadcast Message Request (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-618 (Cellular Broadcast Message Request) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker uses knowledge of the target's mobile phone number (i.e., the number associated with the SIM used in the retransmission device) to cause the cellular network to send broadcast messages to alert the mobile device. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-201.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-619-signal-strength-tracking",
    "title": "MITRE CAPEC-619: Signal Strength Tracking (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-619 (Signal Strength Tracking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker passively monitors the signal strength of the target's cellular RF signal or WiFi RF signal and uses the strength of the signal (with directional antennas and/or from multiple listening points at once) to identify the source location of the signal. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-201.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-62-cross-site-request-forgery",
    "title": "MITRE CAPEC-62: Cross-Site Request Forgery (CSRF) (Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-62 (Cross-Site Request Forgery) is an attack pattern in which an attacker crafts malicious web links to induce users to click and execute malicious actions against third-party applications. Leverages session cookies persisting after authentication. Likelihood: High. Severity: Very High. Maps to CWE-352 (CSRF), CWE-306 (Missing Authentication for Critical Function), CWE-664, CWE-732, CWE-1275 (Sensitive Cookie with Improper SameSite Attribute). Compliance: OWASP ASVS V4.2 Session Management, OWASP Top 10 A01, PCI DSS, NIS2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1539-steal-web-session-cookie",
      "mitre-capec-capec-31-http-cookies",
      "mitre-capec-capec-21-exploitation-of-trusted-identifiers",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-620-drop-encryption-level",
    "title": "MITRE CAPEC-620: Drop Encryption Level (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-620 (Drop Encryption Level) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker forces the encryption level to be lowered, thus enabling a successful attack against the encrypted data. Likelihood of attack: Unknown. Typical severity: High. Parent pattern for CAPEC-606 Weakening of Cellular Encryption. Maps to weaknesses CWE-757. Relates to MITRE ATT&CK T1600.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1600-weaken-encryption"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-621-analysis-of-packet-timing-and-sizes",
    "title": "MITRE CAPEC-621: Analysis of Packet Timing and Sizes (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-621 (Analysis of Packet Timing and Sizes) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker may intercept and log encrypted transmissions for the purpose of analyzing metadata such as packet timing and sizes. Although the actual data may be encrypted, this metadata may reveal valuable information to an attacker. Note that this attack is applicable to VOIP data as well as application data, especially for interactive apps that require precise timing and low-latency (e.g. thin-clients). Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-201.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-622-electromagnetic-side-channel-attack",
    "title": "MITRE CAPEC-622: Electromagnetic Side-Channel Attack (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-622 (Electromagnetic Side-Channel Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker passively monitors electromagnetic emanations that are produced by the targeted electronic device as an unintentional side-effect of its processing. From these emanations, the attacker derives information about the data that is being processed (e.g. the attacker can recover cryptographic keys by monitoring emanations associated with cryptographic processing). Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-201.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-623-compromising-emanations-attack",
    "title": "MITRE CAPEC-623: Compromising Emanations Attack (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-623 (Compromising Emanations Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Compromising Emanations (CE) are defined as unintentional signals which an attacker may intercept and analyze to disclose the information processed by the targeted equipment. Commercial mobile devices and retransmission devices have displays, buttons, microchips, and radios that emit mechanical emissions in the form of sound or vibrations. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-201.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-624-hardware-fault-injection",
    "title": "MITRE CAPEC-624: Hardware Fault Injection (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-624 (Hardware Fault Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary uses disruptive signals or events, or alters the physical environment a device operates in, to cause faulty behavior in electronic devices. This can include electromagnetic pulses, laser pulses, clock glitches, ambient temperature extremes, and more. Likelihood of attack: Low. Typical severity: High. Parent pattern for CAPEC-625 Mobile Device Fault Injection. Maps to weaknesses CWE-1247, CWE-1248, CWE-1256, CWE-1319, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-625-mobile-device-fault-injection",
    "title": "MITRE CAPEC-625: Mobile Device Fault Injection (Standard Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-625 (Mobile Device Fault Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Fault injection attacks against mobile devices use disruptive signals or events (e.g. electromagnetic pulses, laser pulses, clock glitches, etc.) to cause faulty behavior. When performed in a controlled manner on devices performing cryptographic operations, this faulty behavior can be exploited to derive secret key information. Likelihood of attack: Unknown. Maps to weaknesses CWE-1247, CWE-1248, CWE-1256, CWE-1319, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-626-smudge-attack",
    "title": "MITRE CAPEC-626: Smudge Attack (Detailed Attack Pattern)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-626 (Smudge Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Attacks that reveal the password/passcode pattern on a touchscreen device by detecting oil smudges left behind by the user's fingers. Likelihood of attack: Unknown.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-627-counterfeit-gps-signals",
    "title": "MITRE CAPEC-627: Counterfeit GPS Signals (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-627 (Counterfeit GPS Signals) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary attempts to deceive a GPS receiver by broadcasting counterfeit GPS signals, structured to resemble a set of normal GPS signals. These spoofed signals may be structured in such a way as to cause the receiver to estimate its position to be somewhere other than where it actually is, or to be located where it is but at a different time, as determined by the adversary. Likelihood of attack: Low. Typical severity: High. Parent pattern for CAPEC-628 Carry-Off GPS Attack.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-628-carry-off-gps-attack",
    "title": "MITRE CAPEC-628: Carry-Off GPS Attack (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-628 (Carry-Off GPS Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. A common form of a GPS spoofing attack, commonly termed a carry-off attack begins with an adversary broadcasting signals synchronized with the genuine signals observed by the target receiver. The power of the counterfeit signals is then gradually increased and drawn away from the genuine signals. Likelihood of attack: Low. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-63-cross-site-scripting",
    "title": "MITRE CAPEC-63: Cross-Site Scripting (XSS) (Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-63 (Cross-Site Scripting) is an attack pattern in which an adversary embeds malicious scripts in content that will be served to web browsers; the target client-side browser executes the script with the users privilege level. Likelihood of attack: High. Typical severity: Very High. Maps to CWE-79 (Improper Neutralization of Input During Web Page Generation) and CWE-20 (Improper Input Validation). Compliance: OWASP ASVS V5.3 (output encoding), OWASP Top 10 A03:2021 Injection, PCI DSS v4.0 Requirement 6.2.4, NIST SP 800-53 SI-10, ISO/IEC 27001 A.8.28.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1539-steal-web-session-cookie",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-630-typosquatting",
    "title": "MITRE CAPEC-630: TypoSquatting (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-630 (TypoSquatting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary registers a domain name with at least one character different than a trusted domain. A TypoSquatting attack takes advantage of instances where a user mistypes a URL (e.g. www.goggle.com) or not does visually verify a URL before clicking on it (e.g. phishing attack). As a result, the user is directed to an adversary-controlled destination. Likelihood of attack: Low. Typical severity: Medium.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-631-soundsquatting",
    "title": "MITRE CAPEC-631: SoundSquatting (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-631 (SoundSquatting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary registers a domain name that sounds the same as a trusted domain, but has a different spelling. A SoundSquatting attack takes advantage of a user's confusion of the two words to direct Internet traffic to adversary-controlled destinations. SoundSquatting does not require an attack against the trusted domain or complicated reverse engineering. Likelihood of attack: Low. Typical severity: Medium.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-632-homograph-attack-via-homoglyphs",
    "title": "MITRE CAPEC-632: Homograph Attack via Homoglyphs (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-632 (Homograph Attack via Homoglyphs) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary registers a domain name containing a homoglyph, leading the registered domain to appear the same as a trusted domain. A homograph attack leverages the fact that different characters among various character sets look the same to the user. Homograph attacks must generally be combined with other attacks, such as phishing attacks, in order to direct Internet traffic to the adversary-controlled destinations. Likelihood of attack: Low. Typical severity: Medium. Maps to weaknesses CWE-1007.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-633-token-impersonation",
    "title": "MITRE CAPEC-633: Token Impersonation (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-633 (Token Impersonation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in authentication to create an access token (or equivalent) that impersonates a different entity, and then associates a process/thread to that that impersonated token. This action causes a downstream user to make a decision or take action that is based on the assumed identity, and not the response that blocks the adversary. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-287, CWE-1270. Relates to MITRE ATT&CK T1134.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1134-access-token-manipulation"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-634-probe-audio-and-video-peripherals",
    "title": "MITRE CAPEC-634: Probe Audio and Video Peripherals (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-634 (Probe Audio and Video Peripherals) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary exploits the target system's audio and video functionalities through malware or scheduled tasks. The goal is to capture sensitive information about the target for financial, personal, political, or other gains which is accomplished by collecting communication data between two parties via the use of peripheral devices (e.g. microphones and webcams) or applications with audio and video capabilities (e.g. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-267. Relates to MITRE ATT&CK T1123, T1125.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1123-audio-capture",
      "mitre-attack-t1125-video-capture"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-635-alternative-execution-due-to-deceptive-filenames",
    "title": "MITRE CAPEC-635: Alternative Execution Due to Deceptive Filenames (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-635 (Alternative Execution Due to Deceptive Filenames) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The extension of a file name is often used in various contexts to determine the application that is used to open and use it. If an attacker can cause an alternative application to be used, it may be able to execute malicious code, cause a denial of service or expose sensitive information. Likelihood of attack: Unknown. Typical severity: High. Parent pattern for CAPEC-11 Cause Web Server Misclassification; CAPEC-649 Adding a Space to a File Extension. Maps to weaknesses CWE-162. Relates to MITRE ATT&CK T1036.007.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-636-hiding-malicious-data-or-code-within-files",
    "title": "MITRE CAPEC-636: Hiding Malicious Data or Code within Files (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-636 (Hiding Malicious Data or Code within Files) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Files on various operating systems can have a complex format which allows for the storage of other data, in addition to its contents. Often this is metadata about the file, such as a cached thumbnail for an image file. Unless utilities are invoked in a particular way, this data is not visible during the normal use of the file. Likelihood of attack: Unknown. Typical severity: High. Parent pattern for CAPEC-168 Windows ::DATA Alternate Data Stream; CAPEC-35 Leverage Executable Code in Non-Executable Files. Maps to weaknesses CWE-506. Relates to MITRE ATT&CK T1001.002, T1027.003, T1027.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1001-data-obfuscation",
      "mitre-attack-t1027-014-polymorphic-code"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-637-collect-data-from-clipboard",
    "title": "MITRE CAPEC-637: Collect Data from Clipboard (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-637 (Collect Data from Clipboard) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary exploits an application that allows for the copying of sensitive data or information by collecting information copied to the clipboard. Data copied to the clipboard can be accessed by other applications, such as malware built to exfiltrate or log clipboard contents on a periodic basis. In this way, the adversary aims to garner information to which they are unauthorized. Likelihood of attack: Low. Typical severity: Low. Maps to weaknesses CWE-267. Relates to MITRE ATT&CK T1115.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1115-clipboard-data"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-638-altered-component-firmware",
    "title": "MITRE CAPEC-638: Altered Component Firmware (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-638 (Altered Component Firmware) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits systems features and/or improperly protected firmware of hardware components, such as Hard Disk Drives (HDD), with the goal of executing malicious code from within the component's Master Boot Record (MBR). Conducting this type of attack entails the adversary infecting the target with firmware altering malware, using known tools, and a payload. Likelihood of attack: Low. Typical severity: Very High. Relates to MITRE ATT&CK T1542.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1542-pre-os-boot"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-639-probe-system-files",
    "title": "MITRE CAPEC-639: Probe System Files (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-639 (Probe System Files) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary obtains unauthorized information due to improperly protected files. If an application stores sensitive information in a file that is not protected by proper access control, then an adversary can access the file and search for sensitive information. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-552. Relates to MITRE ATT&CK T1039, T1552.001, T1552.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1039-data-from-network-shared-drive",
      "mitre-attack-t1552-unsecured-credentials"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-64-using-slashes-and-url-encoding-combined-to-bypass",
    "title": "MITRE CAPEC-64: Using Slashes and URL Encoding Combined to Bypass Validation Logic (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-64 (Using Slashes and URL Encoding Combined to Bypass Validation Logic) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the encoding of the URL combined with the encoding of the slash characters. An attacker can take advantage of the multiple ways of encoding a URL and abuse the interpretation of the URL. A URL may contain special character that need special syntax handling in order to be interpreted. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-177, CWE-173, CWE-172, CWE-73, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-640-inclusion-of-code-in-existing-process",
    "title": "MITRE CAPEC-640: Inclusion of Code in Existing Process (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-640 (Inclusion of Code in Existing Process) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary takes advantage of a bug in an application failing to verify the integrity of the running process to execute arbitrary code in the address space of a separate live process. The adversary could use running code in the context of another process to try to access process's memory, system/network resources, etc. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-114, CWE-829. Relates to MITRE ATT&CK T1505.005, T1574.006, T1574.013.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1505-005-terminal-services-dll",
      "mitre-attack-t1574-014-appdomainmanager"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-641-dll-side-loading",
    "title": "MITRE CAPEC-641: DLL Side-Loading (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-641 (DLL Side-Loading) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary places a malicious version of a Dynamic-Link Library (DLL) in the Windows Side-by-Side (WinSxS) directory to trick the operating system into loading this malicious DLL instead of a legitimate DLL. Programs specify the location of the DLLs to load via the use of WinSxS manifests or DLL redirection and if they aren't used then Windows searches in a predefined set of directories to locate the file. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-706. Relates to MITRE ATT&CK T1574.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1574-014-appdomainmanager"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-642-replace-binaries",
    "title": "MITRE CAPEC-642: Replace Binaries (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-642 (Replace Binaries) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries know that certain binaries will be regularly executed as part of normal processing. If these binaries are not protected with the appropriate file system permissions, it could be possible to replace them with malware. This malware might be executed at higher system permission levels. Likelihood of attack: Unknown. Typical severity: High. Maps to weaknesses CWE-732. Relates to MITRE ATT&CK T1505.005, T1554, T1574.005.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1505-005-terminal-services-dll",
      "mitre-attack-t1554-compromise-host-software-binary"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-643-identify-shared-files-directories-on-system",
    "title": "MITRE CAPEC-643: Identify Shared Files/Directories on System (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-643 (Identify Shared Files/Directories on System) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary discovers connections between systems by exploiting the target system's standard practice of revealing them in searchable, common areas. Through the identification of shared folders/drives between systems, the adversary may further their goals of locating and collecting sensitive information/files, or map potential routes for lateral movement within the network. Likelihood of attack: Medium. Typical severity: Medium. Maps to weaknesses CWE-267, CWE-200. Relates to MITRE ATT&CK T1135.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1135-network-share-discovery"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-644-use-of-captured-hashes-pass-the-hash",
    "title": "MITRE CAPEC-644: Use of Captured Hashes (Pass The Hash) (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-644 (Use of Captured Hashes (Pass The Hash)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary obtains (i.e. steals or purchases) legitimate Windows domain credential hash values to access systems within the domain that leverage the Lan Man (LM) and/or NT Lan Man (NTLM) authentication protocols. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-522, CWE-836, CWE-308, CWE-294, and others. Relates to MITRE ATT&CK T1550.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1550-use-alternate-authentication-material"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-capec-capec-645-use-of-captured-tickets-pass-the-ticket",
    "title": "MITRE CAPEC-645: Use of Captured Tickets (Pass The Ticket) (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-645 (Use of Captured Tickets (Pass The Ticket)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses stolen Kerberos tickets to access systems/resources that leverage the Kerberos authentication protocol. The Kerberos authentication protocol centers around a ticketing system which is used to request/grant access to services and to then access the requested services. An adversary can obtain any one of these tickets (e.g. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-522, CWE-294, CWE-308. Relates to MITRE ATT&CK T1550.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1550-use-alternate-authentication-material"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-646-peripheral-footprinting",
    "title": "MITRE CAPEC-646: Peripheral Footprinting (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-646 (Peripheral Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries may attempt to obtain information about attached peripheral devices and components connected to a computer system. Examples may include discovering the presence of iOS devices by searching for backups, analyzing the Windows registry to determine what USB devices have been connected, or infecting a victim system with malware to report when a USB device has been connected. Likelihood of attack: Low. Typical severity: Medium. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1120.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1120-peripheral-device-discovery"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-647-collect-data-from-registries",
    "title": "MITRE CAPEC-647: Collect Data from Registries (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-647 (Collect Data from Registries) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in authorization to gather system-specific data and sensitive information within a registry (e.g., Windows Registry, Mac plist). These contain information about the system configuration, software, operating system, and security. The adversary can leverage information gathered in order to carry out further attacks. Likelihood of attack: Medium. Typical severity: Medium. Maps to weaknesses CWE-285. Relates to MITRE ATT&CK T1005, T1012, T1552.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1005-data-from-local-system",
      "mitre-attack-t1012-query-registry"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-648-collect-data-from-screen-capture",
    "title": "MITRE CAPEC-648: Collect Data from Screen Capture (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-648 (Collect Data from Screen Capture) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary gathers sensitive information by exploiting the system's screen capture functionality. Through screenshots, the adversary aims to see what happens on the screen over the course of an operation. The adversary can leverage information gathered in order to carry out further attacks. Likelihood of attack: Medium. Typical severity: Medium. Maps to weaknesses CWE-267. Relates to MITRE ATT&CK T1113.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1113-screen-capture"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-649-adding-a-space-to-a-file-extension",
    "title": "MITRE CAPEC-649: Adding a Space to a File Extension (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-649 (Adding a Space to a File Extension) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary adds a space character to the end of a file extension and takes advantage of an application that does not properly neutralize trailing special elements in file names. This extra space, which can be difficult for a user to notice, affects which default application is used to operate on the file and can be leveraged by the adversary to control execution. Likelihood of attack: Low. Typical severity: Medium. Maps to weaknesses CWE-46. Relates to MITRE ATT&CK T1036.006.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1036-masquerading"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-65-sniff-application-code",
    "title": "MITRE CAPEC-65: Sniff Application Code (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-65 (Sniff Application Code) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary passively sniffs network communications and captures application code bound for an authorized client. Once obtained, they can use it as-is, or through reverse-engineering glean sensitive information or exploit the trust relationship between the client and server. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-319, CWE-311, CWE-318, CWE-693. Relates to MITRE ATT&CK T1040.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1040-network-sniffing"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-capec-capec-650-upload-a-web-shell-to-a-web-server",
    "title": "MITRE CAPEC-650: Upload a Web Shell to a Web Server (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-650 (Upload a Web Shell to a Web Server) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. By exploiting insufficient permissions, it is possible to upload a web shell to a web server in such a way that it can be executed remotely. This shell can have various capabilities, thereby acting as a \"gateway\" to the underlying web server. The shell might execute at the higher permission level of the web server, providing the ability the execute malicious code at elevated levels. Likelihood of attack: Unknown. Typical severity: High. Maps to weaknesses CWE-287, CWE-553. Relates to MITRE ATT&CK T1505.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1505-005-terminal-services-dll"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-651-eavesdropping",
    "title": "MITRE CAPEC-651: Eavesdropping (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-651 (Eavesdropping) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary intercepts a form of communication (e.g. text, audio, video) by way of software (e.g., microphone and audio recording application), hardware (e.g., recording equipment), or physical means (e.g., physical proximity). The goal of eavesdropping is typically to gain unauthorized access to sensitive information about the target for financial, personal, political, or other gains. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-508 Shoulder Surfing; CAPEC-634 Probe Audio and Video Peripherals; CAPEC-699 Eavesdropping on a Monitor. Maps to weaknesses CWE-200. Relates to MITRE ATT&CK T1111.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1111-multi-factor-authentication-interception"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-652-use-of-known-kerberos-credentials",
    "title": "MITRE CAPEC-652: Use of Known Kerberos Credentials (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-652 (Use of Known Kerberos Credentials) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary obtains (i.e. steals or purchases) legitimate Kerberos credentials (e.g. Kerberos service account userID/password or Kerberos Tickets) with the goal of achieving authenticated access to additional systems, applications, or services within the domain. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-509 Kerberoasting; CAPEC-645 Use of Captured Tickets (Pass The Ticket). Maps to weaknesses CWE-522, CWE-307, CWE-308, CWE-309, and others. Relates to MITRE ATT&CK T1558.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1558-steal-or-forge-kerberos-tickets"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-capec-capec-653-use-of-known-operating-system-credentials",
    "title": "MITRE CAPEC-653: Use of Known Operating System Credentials (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-653 (Use of Known Operating System Credentials) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary guesses or obtains (i.e. steals or purchases) legitimate operating system credentials (e.g. userID/password) to achieve authentication and to perform authorized actions on the system, under the guise of an authenticated user or service. This applies to any Operating System. Likelihood of attack: High. Typical severity: High. Parent pattern for CAPEC-561 Windows Admin Shares with Stolen Credentials; CAPEC-644 Use of Captured Hashes (Pass The Hash). Maps to weaknesses CWE-522, CWE-307, CWE-308, CWE-309, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-654-credential-prompt-impersonation",
    "title": "MITRE CAPEC-654: Credential Prompt Impersonation (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-654 (Credential Prompt Impersonation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, impersonates a credential prompt in an attempt to steal a user's credentials. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-1021. Relates to MITRE ATT&CK T1056, T1548.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1056-input-capture",
      "mitre-attack-t1548-abuse-elevation-control-mechanism"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-655-avoid-security-tool-identification-by-adding-data",
    "title": "MITRE CAPEC-655: Avoid Security Tool Identification by Adding Data (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-655 (Avoid Security Tool Identification by Adding Data) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary adds data to a file to increase the file size beyond what security tools are capable of handling in an attempt to mask their actions. In addition to this, adding data to a file also changes the file's hash, frustrating security tools that look for known bad files by their hash. Likelihood of attack: High. Typical severity: High. Relates to MITRE ATT&CK T1027.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1027-obfuscated-files-information"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-656-voice-phishing",
    "title": "MITRE CAPEC-656: Voice Phishing (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-656 (Voice Phishing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary targets users with a phishing attack for the purpose of soliciting account passwords or sensitive information from the user. Voice Phishing is a variation of the Phishing social engineering technique where the attack is initiated via a voice call, rather than email. Likelihood of attack: High. Typical severity: High.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-657-malicious-automated-software-update",
    "title": "MITRE CAPEC-657: Malicious Automated Software Update via Spoofing (High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-657 (Malicious Automated Software Update via Spoofing) is an attack pattern in which an attacker uses identity or content spoofing to trick a client into performing an automated software update from a malicious source. Likelihood: High. Severity: High. Maps to MITRE ATT&CK T1072 (Software Deployment Tools) and CWE-494 (Download of Code Without Integrity Check). Example: eTrust Antivirus Webscan vulnerability CVE-2006-3976/3977. Compliance: NIST SP 800-53 SI-7 + SR-11, US EO 14028, EU Cyber Resilience Act, NIST SP 800-218 SSDF.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1574-hijack-execution-flow",
      "mitre-capec-capec-184-software-integrity-attack",
      "mitre-capec-capec-185-malicious-software-download",
      "mitre-d3fend-d3-fim-file-integrity-monitoring",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-66-sql-injection",
    "title": "MITRE CAPEC-66: SQL Injection (Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-66 (SQL Injection) is an attack pattern in which an adversary crafts input strings so that the target software constructs SQL statements that perform actions other than those intended by the application. Likelihood of attack: High. Typical severity: High. Maps to CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and CWE-1286. Compliance: PCI DSS v4.0 Requirement 6.2 (secure development), OWASP ASVS V5.3 (output encoding and injection prevention), OWASP Top 10 A03:2021 Injection, NIST SP 800-53 SI-10 (Information Input Validation), ISO/IEC 27001 A.8.28 (Secure coding).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "owasp-asvs-l2",
      "pci-dss-v4-req-10-12-monitoring-policy",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-660-root-jailbreak-detection-evasion-via-hooking",
    "title": "MITRE CAPEC-660: Root/Jailbreak Detection Evasion via Hooking (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-660 (Root/Jailbreak Detection Evasion via Hooking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary forces a non-restricted mobile application to load arbitrary code or code files, via Hooking, with the goal of evading Root/Jailbreak detection. Mobile device users often Root/Jailbreak their devices in order to gain administrative control over the mobile operating system and/or to install third-party mobile applications that are not provided by authorized application stores (e.g. Likelihood of attack: Medium. Typical severity: Very High. Maps to weaknesses CWE-829. Relates to MITRE ATT&CK T1055.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1055-process-injection"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-661-root-jailbreak-detection-evasion-via-debugging",
    "title": "MITRE CAPEC-661: Root/Jailbreak Detection Evasion via Debugging (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-661 (Root/Jailbreak Detection Evasion via Debugging) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary inserts a debugger into the program entry point of a mobile application to modify the application binary, with the goal of evading Root/Jailbreak detection. Mobile device users often Root/Jailbreak their devices in order to gain administrative control over the mobile operating system and/or to install third-party mobile applications that are not provided by authorized application stores (e.g. Likelihood of attack: Medium. Typical severity: Very High. Maps to weaknesses CWE-489.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-662-adversary-in-the-browser-aitb",
    "title": "MITRE CAPEC-662: Adversary in the Browser (AiTB) (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-662 (Adversary in the Browser (AiTB)) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits security vulnerabilities or inherent functionalities of a web browser, in order to manipulate traffic between two endpoints. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-300, CWE-494. Relates to MITRE ATT&CK T1185.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1185-browser-session-hijacking"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-663-exploitation-of-transient-instruction-execution",
    "title": "MITRE CAPEC-663: Exploitation of Transient Instruction Execution (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-663 (Exploitation of Transient Instruction Execution) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a hardware design flaw in a CPU implementation of transient instruction execution to expose sensitive data and bypass/subvert access control over restricted resources. Typically, the adversary conducts a covert channel attack to target non-discarded microarchitectural changes caused by transient executions such as speculative execution, branch prediction, instruction pipelining, and/or. Likelihood of attack: Low. Typical severity: Very High. Parent pattern for CAPEC-696 Load Value Injection. Maps to weaknesses CWE-1037, CWE-1303, CWE-1264.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-664-server-side-request-forgery",
    "title": "MITRE CAPEC-664: Server Side Request Forgery (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-664 (Server Side Request Forgery) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits improper input validation by submitting maliciously crafted input to a target application running on a server, with the goal of forcing the server to make a request either to itself, to web services running in the server's internal network, or to external third parties. If successful, the adversary's request will be made with the server's privilege level, bypassing its authentication controls. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-918, CWE-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-665-exploitation-of-thunderbolt-protection-flaws",
    "title": "MITRE CAPEC-665: Exploitation of Thunderbolt Protection Flaws (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-665 (Exploitation of Thunderbolt Protection Flaws) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary leverages a firmware weakness within the Thunderbolt protocol, on a computing device to manipulate Thunderbolt controller firmware in order to exploit vulnerabilities in the implementation of authorization and verification schemes within Thunderbolt protection mechanisms. Likelihood of attack: Low. Typical severity: Very High. Maps to weaknesses CWE-345, CWE-353, CWE-288, CWE-1188, and others. Relates to MITRE ATT&CK T1211, T1542.002, T1556.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1211-exploitation-for-defense-evasion",
      "mitre-attack-t1542-pre-os-boot"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-666-bluesmacking",
    "title": "MITRE CAPEC-666: BlueSmacking (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-666 (BlueSmacking) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses Bluetooth flooding to transfer large packets to Bluetooth enabled devices over the L2CAP protocol with the goal of creating a DoS. This attack must be carried out within close proximity to a Bluetooth enabled device. Likelihood of attack: Medium. Typical severity: Medium. Maps to weaknesses CWE-404. Relates to MITRE ATT&CK T1498.001, T1499.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1498-network-denial-of-service",
      "mitre-attack-t1499-004-application-or-system-exploitation"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-667-bluetooth-impersonation-attacks-bias",
    "title": "MITRE CAPEC-667: Bluetooth Impersonation AttackS (BIAS) (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-667 (Bluetooth Impersonation AttackS (BIAS)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary disguises the MAC address of their Bluetooth enabled device to one for which there exists an active and trusted connection and authenticates successfully. The adversary can then perform malicious actions on the target Bluetooth device depending on the target's capabilities. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-290.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-668-key-negotiation-of-bluetooth-attack-knob",
    "title": "MITRE CAPEC-668: Key Negotiation of Bluetooth Attack (KNOB) (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-668 (Key Negotiation of Bluetooth Attack (KNOB)) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary can exploit a flaw in Bluetooth key negotiation allowing them to decrypt information sent between two devices communicating via Bluetooth. The adversary uses an Adversary in the Middle setup to modify packets sent between the two devices during the authentication process, specifically the entropy bits. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-425, CWE-285, CWE-693. Relates to MITRE ATT&CK T1565.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1565-data-manipulation"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-669-alteration-of-a-software-update",
    "title": "MITRE CAPEC-669: Alteration of a Software Update (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-669 (Alteration of a Software Update) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary with access to an organization's software update infrastructure inserts malware into the content of an outgoing update to fielded systems where a wide range of malicious effects are possible. With the same level of access, the adversary can alter a software update to perform specific malicious acts including granting the adversary control over the software's normal functionality. Likelihood of attack: Medium. Typical severity: High. Relates to MITRE ATT&CK T1195.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-67-string-format-overflow-in-syslog",
    "title": "MITRE CAPEC-67: String Format Overflow in syslog() (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-67 (String Format Overflow in syslog()) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets applications and software that uses the syslog() function insecurely. If an application does not explicitely use a format string parameter in a call to syslog(), user input can be placed in the format string parameter leading to a format string injection attack. Adversaries can then inject malicious format string commands into the function call leading to a buffer overflow. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-120, CWE-134, CWE-74, CWE-20, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-670-software-development-tools-maliciously-altered",
    "title": "MITRE CAPEC-670: Software Development Tools Maliciously Altered (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-670 (Software Development Tools Maliciously Altered) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary with the ability to alter tools used in a development environment causes software to be developed with maliciously modified tools. Such tools include requirements management and database tools, software design tools, configuration management tools, compilers, system build tools, and software performance testing and load testing tools. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1127, T1195.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1127-trusted-developer-utilities-proxy-execution",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-671-requirements-for-asic-functionality-maliciously-altered",
    "title": "MITRE CAPEC-671: Requirements for ASIC Functionality Maliciously Altered (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-671 (Requirements for ASIC Functionality Maliciously Altered) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary with access to functional requirements for an application specific integrated circuit (ASIC), a chip designed/customized for a singular particular use, maliciously alters requirements derived from originating capability needs. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1195.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-672-malicious-code-implanted-during-chip-programming",
    "title": "MITRE CAPEC-672: Malicious Code Implanted During Chip Programming (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-672 (Malicious Code Implanted During Chip Programming) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. During the programming step of chip manufacture, an adversary with access and necessary technical skills maliciously alters a chip's intended program logic to produce an effect intended by the adversary when the fully manufactured chip is deployed and in operational use. Intended effects can include the ability of the adversary to remotely control a host system to carry out malicious acts. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1195.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-673-developer-signing-maliciously-altered-software",
    "title": "MITRE CAPEC-673: Developer Signing Maliciously Altered Software (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-673 (Developer Signing Maliciously Altered Software) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Software produced by a reputable developer is clandestinely infected with malicious code and then digitally signed by the unsuspecting developer, where the software has been altered via a compromised software development or build process prior to being signed. The receiver or user of the software has no reason to believe that it is anything but legitimate and proceeds to deploy it to organizational systems. Likelihood of attack: Medium. Typical severity: High. Relates to MITRE ATT&CK T1195.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-674-design-for-fpga-maliciously-altered",
    "title": "MITRE CAPEC-674: Design for FPGA Maliciously Altered (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-674 (Design for FPGA Maliciously Altered) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary alters the functionality of a field-programmable gate array (FPGA) by causing an FPGA configuration memory chip reload in order to introduce a malicious function that could result in the FPGA performing or enabling malicious functions on a host system. Prior to the memory chip reload, the adversary alters the program for the FPGA by adding a function to impact system operation. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1195.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-675-retrieve-data-from-decommissioned-devices",
    "title": "MITRE CAPEC-675: Retrieve Data from Decommissioned Devices (Standard Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-675 (Retrieve Data from Decommissioned Devices) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary obtains decommissioned, recycled, or discarded systems and devices that can include an organization's intellectual property, employee data, and other types of controlled information. Systems and devices that have reached the end of their lifecycles may be subject to recycle or disposal where they can be exposed to adversarial attempts to retrieve information from internal memory chips and storage. Likelihood of attack: Medium. Typical severity: Medium. Maps to weaknesses CWE-1266. Relates to MITRE ATT&CK T1052.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1052-exfiltration-over-physical-medium"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-676-nosql-injection",
    "title": "MITRE CAPEC-676: NoSQL Injection (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-676 (NoSQL Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary targets software that constructs NoSQL statements based on user input or with parameters vulnerable to operator replacement in order to achieve a variety of technical impacts such as escalating privileges, bypassing authentication, and/or executing code. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-943, CWE-1286.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-677-server-motherboard-compromise",
    "title": "MITRE CAPEC-677: Server Motherboard Compromise (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-677 (Server Motherboard Compromise) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Malware is inserted in a server motherboard (e.g., in the flash memory) in order to alter server functionality from that intended. The development environment or hardware/software support activity environment is susceptible to an adversary inserting malicious software into hardware components during development or update. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1195.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-678-system-build-data-maliciously-altered",
    "title": "MITRE CAPEC-678: System Build Data Maliciously Altered (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-678 (System Build Data Maliciously Altered) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. During the system build process, the system is deliberately misconfigured by the alteration of the build data. Access to system configuration data files and build processes is susceptible to deliberate misconfiguration of the system. Likelihood of attack: Low. Typical severity: High. Relates to MITRE ATT&CK T1195.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-679-exploitation-of-improperly-configured-or-implemented-memory",
    "title": "MITRE CAPEC-679: Exploitation of Improperly Configured or Implemented Memory Protections (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-679 (Exploitation of Improperly Configured or Implemented Memory Protections) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of missing or incorrectly configured access control within memory to read/write data or inject malicious code into said memory. Likelihood of attack: Medium. Typical severity: Very High. Maps to weaknesses CWE-1222, CWE-1252, CWE-1257, CWE-1260, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-68-subvert-code-signing-facilities",
    "title": "MITRE CAPEC-68: Subvert Code-signing Facilities (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-68 (Subvert Code-signing Facilities) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Many languages use code signing facilities to vouch for code's identity and to thus tie code to its assigned privileges within an environment. Subverting this mechanism can be instrumental in an attacker escalating privilege. Any means of subverting the way that a virtual machine enforces code signing classifies for this style of attack. Likelihood of attack: Low. Typical severity: Very High. Maps to weaknesses CWE-325, CWE-328, CWE-1326. Relates to MITRE ATT&CK T1553.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1553-subvert-trust-controls"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-680-exploitation-of-improperly-controlled-registers",
    "title": "MITRE CAPEC-680: Exploitation of Improperly Controlled Registers (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-680 (Exploitation of Improperly Controlled Registers) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits missing or incorrectly configured access control within registers to read/write data that is not meant to be obtained or modified by a user. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-1224, CWE-1231, CWE-1233, CWE-1262, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-681-exploitation-of-improperly-controlled-hardware-security-iden",
    "title": "MITRE CAPEC-681: Exploitation of Improperly Controlled Hardware Security Identifiers (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-681 (Exploitation of Improperly Controlled Hardware Security Identifiers) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of missing or incorrectly configured security identifiers (e.g., tokens), which are used for access control within a System-on-Chip (SoC), to read/write data or execute a given action. Likelihood of attack: Medium. Typical severity: Very High. Maps to weaknesses CWE-1259, CWE-1267, CWE-1270, CWE-1294, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-682-exploitation-of-firmware-or-rom-code-with-unpatchable",
    "title": "MITRE CAPEC-682: Exploitation of Firmware or ROM Code with Unpatchable Vulnerabilities (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-682 (Exploitation of Firmware or ROM Code with Unpatchable Vulnerabilities) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may exploit vulnerable code (i.e., firmware or ROM) that is unpatchable. Unpatchable devices exist due to manufacturers intentionally or inadvertently designing devices incapable of updating their software. Additionally, with updatable devices, the manufacturer may decide not to support the device and stop making updates to their software. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-1277, CWE-1310.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-69-target-programs-with-elevated-privileges",
    "title": "MITRE CAPEC-69: Target Programs with Elevated Privileges (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-69 (Target Programs with Elevated Privileges) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets programs running with elevated privileges. The adversary tries to leverage a vulnerability in the running program and get arbitrary code to execute with elevated privileges. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-250, CWE-15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-690-metadata-spoofing",
    "title": "MITRE CAPEC-690: Metadata Spoofing (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-690 (Metadata Spoofing) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary alters the metadata of a resource (e.g., file, directory, repository, etc.) to present a malicious resource as legitimate/credible. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-691 Spoof Open-Source Software Metadata.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-capec-capec-691-spoof-open-source-software-metadata",
    "title": "MITRE CAPEC-691: Spoof Open-Source Software Metadata (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-691 (Spoof Open-Source Software Metadata) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary spoofs open-source software metadata in an attempt to masquerade malicious software as popular, maintained, and trusted. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-692 Spoof Version Control System Commit Metadata; CAPEC-693 StarJacking. Maps to weaknesses CWE-494. Relates to MITRE ATT&CK T1195.001, T1195.002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-692-spoof-version-control-system-commit-metadata",
    "title": "MITRE CAPEC-692: Spoof Version Control System Commit Metadata (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-692 (Spoof Version Control System Commit Metadata) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary spoofs metadata pertaining to a Version Control System (VCS) (e.g., Git) repository's commits to deceive users into believing that the maliciously provided software is frequently maintained and originates from a trusted source. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-494.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-693-starjacking",
    "title": "MITRE CAPEC-693: StarJacking (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-693 (StarJacking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary spoofs software popularity metadata to deceive users into believing that a maliciously provided package is widely used and originates from a trusted source. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-494.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-694-system-location-discovery",
    "title": "MITRE CAPEC-694: System Location Discovery (Standard Attack Pattern - Very Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-694 (System Location Discovery) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary collects information about the target system in an attempt to identify the system's geographical location. Information gathered could include keyboard layout, system language, and timezone. This information may benefit an adversary in confirming the desired target and/or tailoring further attacks. Likelihood of attack: High. Typical severity: Very Low. Maps to weaknesses CWE-497. Relates to MITRE ATT&CK T1614.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1614-system-location-discovery"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-695-repo-jacking",
    "title": "MITRE CAPEC-695: Repo Jacking (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-695 (Repo Jacking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of the redirect property of directly linked Version Control System (VCS) repositories to trick users into incorporating malicious code into their applications. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-494, CWE-829. Relates to MITRE ATT&CK T1195.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1195-supply-chain-compromise"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-696-load-value-injection",
    "title": "MITRE CAPEC-696: Load Value Injection (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-696 (Load Value Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a hardware design flaw in a CPU implementation of transient instruction execution in which a faulting or assisted load instruction transiently forwards adversary-controlled data from microarchitectural buffers. Likelihood of attack: Low. Typical severity: Very High. Maps to weaknesses CWE-1342.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-697-dhcp-spoofing",
    "title": "MITRE CAPEC-697: DHCP Spoofing (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-697 (DHCP Spoofing) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary masquerades as a legitimate Dynamic Host Configuration Protocol (DHCP) server by spoofing DHCP traffic, with the goal of redirecting network traffic or denying service to DHCP. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-923. Relates to MITRE ATT&CK T1557.003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1557-adversary-in-the-middle"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-capec-capec-698-install-malicious-extension",
    "title": "MITRE CAPEC-698: Install Malicious Extension (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-698 (Install Malicious Extension) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary directly installs or tricks a user into installing a malicious extension into existing trusted software, with the goal of achieving a variety of negative technical impacts. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-507, CWE-829. Relates to MITRE ATT&CK T1176, T1505.004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1176-browser-extensions",
      "mitre-attack-t1505-005-terminal-services-dll"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-699-eavesdropping-on-a-monitor",
    "title": "MITRE CAPEC-699: Eavesdropping on a Monitor (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-699 (Eavesdropping on a Monitor) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An Adversary can eavesdrop on the content of an external monitor through the air without modifying any cable or installing software, just capturing this signal emitted by the cable or video port, with this the attacker will be able to impact the confidentiality of the data without being detected by traditional security tools. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-1300.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-7-blind-sql-injection",
    "title": "MITRE CAPEC-7: Blind SQL Injection (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-7 (Blind SQL Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Blind SQL Injection results from an insufficient mitigation for SQL Injection. Although suppressing database error messages are considered best practice, the suppression alone is not sufficient to prevent SQL Injection. Blind SQL Injection is a form of SQL Injection that overcomes the lack of error messages. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-89, CWE-209, CWE-74, CWE-20, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-70-try-common-or-default-usernames-and-passwords",
    "title": "MITRE CAPEC-70: Try Common or Default Usernames and Passwords (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-70 (Try Common or Default Usernames and Passwords) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may try certain common or default usernames and passwords to gain access into the system and perform unauthorized actions. An adversary may try an intelligent brute force using empty passwords, known vendor default credentials, as well as a dictionary of common usernames and passwords. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-521, CWE-262, CWE-263, CWE-798, and others. Relates to MITRE ATT&CK T1078.001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1078-003-local-accounts"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-capec-capec-700-network-boundary-bridging",
    "title": "MITRE CAPEC-700: Network Boundary Bridging (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-700 (Network Boundary Bridging) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary which has gained elevated access to network boundary devices may use these devices to create a channel to bridge trusted and untrusted networks. Boundary devices do not necessarily have to be on the network's edge, but rather must serve to segment portions of the target network the adversary wishes to cross into. Likelihood of attack: Medium. Typical severity: High. Relates to MITRE ATT&CK T1599.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2",
      "mitre-attack-t1599-network-boundary-bridging"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-701-browser-in-the-middle-bitm",
    "title": "MITRE CAPEC-701: Browser in the Middle (BiTM) (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-701 (Browser in the Middle (BiTM)) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits the inherent functionalities of a web browser, in order to establish an unnoticed remote desktop connection in the victim's browser to the adversary's system. The adversary must deploy a web client with a remote desktop session that the victim can access. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-294, CWE-345.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-702-exploiting-incorrect-chaining-or-granularity-of-hardware-deb",
    "title": "MITRE CAPEC-702: Exploiting Incorrect Chaining or Granularity of Hardware Debug Components (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-702 (Exploiting Incorrect Chaining or Granularity of Hardware Debug Components) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits incorrect chaining or granularity of hardware debug components in order to gain unauthorized access to debug functionality on a chip. This happens when authorization is not checked on a per function basis and is assumed for a chain or group of debug functionality. Likelihood of attack: Low. Typical severity: Medium. Maps to weaknesses CWE-1296.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-71-using-unicode-encoding-to-bypass-validation-logic",
    "title": "MITRE CAPEC-71: Using Unicode Encoding to Bypass Validation Logic (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-71 (Using Unicode Encoding to Bypass Validation Logic) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker may provide a Unicode string to a system component that is not Unicode aware and use that to circumvent the filter or cause the classifying mechanism to fail to properly understanding the request. That may allow the attacker to slip malicious data past the content filter and/or possibly cause the application to route the request incorrectly. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-176, CWE-179, CWE-180, CWE-173, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-72-url-encoding",
    "title": "MITRE CAPEC-72: URL Encoding (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-72 (URL Encoding) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the encoding of the URL. An adversary can take advantage of the multiple way of encoding an URL and abuse the interpretation of the URL. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-173, CWE-177, CWE-172, CWE-73, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-73-user-controlled-filename",
    "title": "MITRE CAPEC-73: User-Controlled Filename (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-73 (User-Controlled Filename) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type involves an adversary inserting malicious characters (such as a XSS redirection) into a filename, directly or indirectly that is then used by the target software to generate HTML text or other potentially executable content. Many websites rely on user-generated content and dynamically build resources like files, filenames, and URL links directly from user supplied data. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-20, CWE-184, CWE-96, CWE-348, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-74-manipulating-state",
    "title": "MITRE CAPEC-74: Manipulating State (Meta Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-74 (Manipulating State) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary modifies state information maintained by the target software or causes a state transition in hardware. If successful, the target will use this tainted state and execute in an unintended manner. State management is an important function within a software application. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-140 Bypassing of Intermediate Forms in Multiple-Form Sets; CAPEC-663 Exploitation of Transient Instruction Execution. Maps to weaknesses CWE-372, CWE-315, CWE-353, CWE-693, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-75-manipulating-writeable-configuration-files",
    "title": "MITRE CAPEC-75: Manipulating Writeable Configuration Files (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-75 (Manipulating Writeable Configuration Files) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Generally these are manually edited files that are not in the preview of the system administrators, any ability on the attackers' behalf to modify these files, for example in a CVS repository, gives unauthorized access directly to the application, the same as authorized users. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-349, CWE-99, CWE-77, CWE-346, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-76-manipulating-web-input-to-file-system-calls",
    "title": "MITRE CAPEC-76: Manipulating Web Input to File System Calls (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-76 (Manipulating Web Input to File System Calls) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates inputs to the target software which the target software passes to file system calls in the OS. The goal is to gain access to, and perhaps modify, areas of the file system that the target software did not intend to be accessible. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-23, CWE-22, CWE-73, CWE-77, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-77-manipulating-user-controlled-variables",
    "title": "MITRE CAPEC-77: Manipulating User-Controlled Variables (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-77 (Manipulating User-Controlled Variables) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets user controlled variables (DEBUG=1, PHP Globals, and So Forth). An adversary can override variables leveraging user-supplied, untrusted query variables directly used on the application server without any data sanitization. In extreme cases, the adversary can change variables controlling the business logic of the application. Likelihood of attack: High. Typical severity: Very High. Parent pattern for CAPEC-13 Subverting Environment Variable Values; CAPEC-162 Manipulating Hidden Fields. Maps to weaknesses CWE-15, CWE-94, CWE-96, CWE-285, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-78-using-escaped-slashes-in-alternate-encoding",
    "title": "MITRE CAPEC-78: Using Escaped Slashes in Alternate Encoding (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-78 (Using Escaped Slashes in Alternate Encoding) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the use of the backslash in alternate encoding. An adversary can provide a backslash as a leading character and causes a parser to believe that the next character is special. This is called an escape. By using that trick, the adversary tries to exploit alternate ways to encode the same character which leads to filter problems and opens avenues to attack. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-180, CWE-181, CWE-173, CWE-172, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-79-using-slashes-in-alternate-encoding",
    "title": "MITRE CAPEC-79: Using Slashes in Alternate Encoding (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-79 (Using Slashes in Alternate Encoding) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the encoding of the Slash characters. An adversary would try to exploit common filtering problems related to the use of the slashes characters to gain access to resources on the target host. Directory-driven systems, such as file systems and databases, typically use the slash character to indicate traversal between directories or other container components. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-173, CWE-180, CWE-181, CWE-20, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-8-buffer-overflow-in-an-api-call",
    "title": "MITRE CAPEC-8: Buffer Overflow in an API Call (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-8 (Buffer Overflow in an API Call) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets libraries or shared code modules which are vulnerable to buffer overflow attacks. An adversary who has knowledge of known vulnerable libraries or shared code can easily target software that makes use of these libraries. All clients that make use of the code library thus become vulnerable by association. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-120, CWE-119, CWE-118, CWE-74, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-80-using-utf-8-encoding-to-bypass-validation-logic",
    "title": "MITRE CAPEC-80: Using UTF-8 Encoding to Bypass Validation Logic (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-80 (Using UTF-8 Encoding to Bypass Validation Logic) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack is a specific variation on leveraging alternate encodings to bypass validation logic. This attack leverages the possibility to encode potentially harmful input in UTF-8 and submit it to applications not expecting or effective at validating this encoding standard making input filtering difficult. UTF-8 (8-bit UCS/Unicode Transformation Format) is a variable-length character encoding for Unicode. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-173, CWE-172, CWE-180, CWE-181, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-81-web-server-logs-tampering",
    "title": "MITRE CAPEC-81: Web Server Logs Tampering (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-81 (Web Server Logs Tampering) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Web Logs Tampering attacks involve an attacker injecting, deleting or otherwise tampering with the contents of web logs typically for the purposes of masking other malicious behavior. Additionally, writing malicious data to log files may target jobs, filters, reports, and other agents that process the logs in an asynchronous attack pattern. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-117, CWE-93, CWE-75, CWE-221, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-83-xpath-injection",
    "title": "MITRE CAPEC-83: XPath Injection (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-83 (XPath Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker can craft special user-controllable input consisting of XPath expressions to inject the XML database and bypass authentication or glean information that they normally would not be able to. XPath Injection enables an attacker to talk directly to the XML database, thus bypassing the application completely. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-91, CWE-74, CWE-20, CWE-707.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-84-xquery-injection",
    "title": "MITRE CAPEC-84: XQuery Injection (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-84 (XQuery Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack utilizes XQuery to probe and attack server systems; in a similar manner that SQL Injection allows an attacker to exploit SQL calls to RDBMS, XQuery Injection uses improperly validated data that is passed to XQuery commands to traverse and execute commands that the XQuery routines have access to. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-74, CWE-707.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-85-ajax-footprinting",
    "title": "MITRE CAPEC-85: AJAX Footprinting (Detailed Attack Pattern - Low Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-85 (AJAX Footprinting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack utilizes the frequent client-server roundtrips in Ajax conversation to scan a system. While Ajax does not open up new vulnerabilities per se, it does optimize them from an attacker point of view. A common first step for an attacker is to footprint the target environment to understand what attacks will work. Likelihood of attack: High. Typical severity: Low. Maps to weaknesses CWE-79, CWE-113, CWE-348, CWE-96, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-86-xss-through-http-headers",
    "title": "MITRE CAPEC-86: XSS Through HTTP Headers (Detailed Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-86 (XSS Through HTTP Headers) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits web applications that generate web content, such as links in a HTML page, based on unvalidated or improperly validated data submitted by other actors. XSS in HTTP Headers attacks target the HTTP headers which are hidden from most users and may not be validated by web applications. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-80.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-87-forceful-browsing",
    "title": "MITRE CAPEC-87: Forceful Browsing (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-87 (Forceful Browsing) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker employs forceful browsing (direct URL entry) to access portions of a website that are otherwise unreachable. Usually, a front controller or similar design pattern is employed to protect access to portions of a web application. Forceful browsing enables an attacker to access information, perform privileged operations and otherwise reach sections of the web application that have been improperly protected. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-425, CWE-285, CWE-693.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-88-os-command-injection",
    "title": "MITRE CAPEC-88: OS Command Injection (Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-88 (OS Command Injection) is an attack pattern in which an adversary injects operating system commands into existing application functions. Applications using untrusted input to build command strings are vulnerable. Likelihood: High. Severity: High. Maps to CWE-78 (OS Command Injection), CWE-88 (Argument Delimiter Injection), CWE-20, CWE-697. Compliance: OWASP ASVS V5, OWASP Top 10 A03, NIST SP 800-53 SI-10, PCI DSS Req 6.2.4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1059-command-and-scripting-interpreter",
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-capec-capec-242-code-injection",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-89-pharming",
    "title": "MITRE CAPEC-89: Pharming (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-89 (Pharming) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. A pharming attack occurs when the victim is fooled into entering sensitive data into supposedly trusted locations, such as an online bank site or a trading platform. An attacker can impersonate these supposedly trusted sites and have the victim be directed to their site rather than the originally intended one. Pharming does not require script injection or clicking on malicious links for the attack to succeed. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-346, CWE-350.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-9-buffer-overflow-in-local-command-line-utilities",
    "title": "MITRE CAPEC-9: Buffer Overflow in Local Command-Line Utilities (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-9 (Buffer Overflow in Local Command-Line Utilities) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets command-line utilities available in a number of shells. An adversary can leverage a vulnerability found in a command-line utility to escalate privilege to root. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-120, CWE-118, CWE-119, CWE-74, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-90-reflection-attack-in-authentication-protocol",
    "title": "MITRE CAPEC-90: Reflection Attack in Authentication Protocol (Standard Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-90 (Reflection Attack in Authentication Protocol) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary can abuse an authentication protocol susceptible to reflection attack in order to defeat it. Doing so allows the adversary illegitimate access to the target system, without possessing the requisite credentials. Reflection attacks are of great concern to authentication protocols that rely on a challenge-handshake or similar mechanism. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-301, CWE-303.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-92-forced-integer-overflow",
    "title": "MITRE CAPEC-92: Forced Integer Overflow (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-92 (Forced Integer Overflow) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack forces an integer variable to go out of range. The integer variable is often used as an offset such as size of memory allocation or similarly. The attacker would typically control the value of such variable and try to get it out of range. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-190, CWE-128, CWE-120, CWE-122, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-93-log-injection-tampering-forging",
    "title": "MITRE CAPEC-93: Log Injection-Tampering-Forging (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-93 (Log Injection-Tampering-Forging) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the log files of the target host. The attacker injects, manipulates or forges malicious log entries in the log file, allowing them to mislead a log audit, cover traces of attack, or perform other malicious actions. The target host is not properly controlling log access. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-117, CWE-75, CWE-150.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-capec-capec-94-adversary-in-the-middle",
    "title": "MITRE CAPEC-94: Adversary in the Middle (AiTM) (Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-94 (Adversary in the Middle) is an attack pattern in which an adversary targets the communication between two components (typically client and server) to alter or obtain data from transactions. Likelihood of attack: High. Typical severity: Very High. Maps to MITRE ATT&CK T1557 (Adversary-in-the-Middle) and CWE-300 (Channel Accessible by Non-Endpoint), CWE-290 (Authentication Bypass by Spoofing), CWE-294 (Authentication Bypass by Capture-replay), CWE-287 (Improper Authentication). Compliance: PCI DSS v4.0 Req 4 (encrypt transmission), HIPAA Security Rule (transmission security), GDPR Article 32.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1573-encrypted-channel",
      "mitre-attack-t1539-steal-web-session-cookie",
      "mitre-d3fend-d3-mencr-message-encryption",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-capec-capec-95-wsdl-scanning",
    "title": "MITRE CAPEC-95: WSDL Scanning (Detailed Attack Pattern - High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-95 (WSDL Scanning) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the WSDL interface made available by a web service. The attacker may scan the WSDL interface to reveal sensitive information about invocation patterns, underlying technology implementations and associated vulnerabilities. This type of probing is carried out to perform more serious attacks (e.g. parameter tampering, malicious content injection, command injection, etc.). Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-538.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-96-block-access-to-libraries",
    "title": "MITRE CAPEC-96: Block Access to Libraries (Detailed Attack Pattern - Medium Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-96 (Block Access to Libraries) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An application typically makes calls to functions that are a part of libraries external to the application. These libraries may be part of the operating system or they may be third party libraries. It is possible that the application does not handle situations properly where access to these libraries has been blocked. Likelihood of attack: Medium. Typical severity: Medium. Maps to weaknesses CWE-589.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-capec-capec-97-cryptanalysis",
    "title": "MITRE CAPEC-97: Cryptanalysis (Standard Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE CAPEC-97 (Cryptanalysis) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Cryptanalysis is a process of finding weaknesses in cryptographic algorithms and using these weaknesses to decipher the ciphertext without knowing the secret key (instance deduction). Sometimes the weakness is not in the cryptographic algorithm itself, but rather in how it is applied that makes cryptanalysis successful. Likelihood of attack: Low. Typical severity: Very High. Parent pattern for CAPEC-463 Padding Oracle Crypto Attack; CAPEC-608 Cryptanalysis of Cellular Encryption. Maps to weaknesses CWE-327, CWE-1204, CWE-1240, CWE-1241, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8",
      "owasp-asvs-l2"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-capec-capec-98-phishing",
    "title": "MITRE CAPEC-98: Phishing (Attack Pattern - Very High Severity)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE CAPEC-98 (Phishing) is a social engineering attack pattern in which an attacker masquerades as a legitimate entity to prompt the user to reveal confidential information (very frequently authentication credentials). Likelihood of attack: High. Typical severity: Very High. Maps to CWE-451 (User Interface Misrepresentation of Critical Information) and to MITRE ATT&CK T1566 (Phishing) and T1598 (Phishing for Information). Compliance: PCI DSS v4.0 Requirement 5.4 (anti-phishing controls), NIST SP 800-53 AT-2 (Literacy Training and Awareness), AT-3 (Role-Based Training), NIS2 Article 21(2)(g), DORA Article 13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1566-phishing",
      "mitre-attack-t1566-001-spearphishing-attachment",
      "mitre-attack-t1566-002-spearphishing-link",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-cref-cyber-resiliency-engineering-framework",
    "title": "MITRE Cyber Resiliency Engineering Framework (CREF) and NIST SP 800-160 Vol. 2 Rev. 1 Developing Cyber-Resilient Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "The Cyber Resiliency Engineering Framework (CREF) is the MITRE-and-NIST framework for designing systems that anticipate, withstand, recover from, and adapt to adversity including advanced persistent threats (APT). The framework is published authoritatively as NIST Special Publication 800-160 Volume 2 Revision 1 'Developing Cyber-Resilient Systems' (https://doi.org/10.6028/NIST.SP.800-160v2r1) and visualised by the MITRE CREF Navigator at crefnavigator.mitre.org. The framework defines four goals (Anticipate, Withstand, Recover, Adapt - Section 2.1.1 Table 2); eight objectives (Understand, Prepare, Prevent or Avoid, Continue, Constrain, Reconstitute, Transform, Re-Architect - Section 2.1.2 Table 3); fourteen techniques (Adaptive Response, Analytic Monitoring, Contextual Awareness, Coordinated Protection, Deception, Diversity, Dynamic Positioning, Non-Persistence, Privilege Restriction, Realignment, Redundancy, Segmentation, Substantiated Integrity, Unpredictability - Section 2.1.3); a set of implementation approaches per technique (Figure 1 and Appendix D Table D-4); and a set of strategic and structural design principles (Section 2.1.4 and Appendix D). The CREF Navigator surfaces the relationships among these constructs and aligns them with NIST SP 800-53 controls (Appendix E) and the adversary perspective from MITRE ATT&CK (Appendix F). CREF supersedes earlier resilience treatments by tying the engineering analysis to a threat-informed view of APT operations and by requiring systems engineers to make trade-offs across techniques (since Deception and Unpredictability are specific to adversarial threats while the other twelve apply to adversarial and non-adversarial threats alike).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "goals_section_2_1_1",
        "objectives_section_2_1_2",
        "techniques_section_2_1_3",
        "implementation_approaches_figure_1_table_d_4",
        "design_principles_section_2_1_4_appendix_d",
        "controls_mapping_appendix_e",
        "adversary_oriented_analysis_appendix_f",
        "cref_navigator_tool",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fisma-2014-federal-information-security-modernization-pl-113-283",
      "cyber-nist-csf-2",
      "nist-sp-800-53-r5",
      "mitre-attack-framework-v14",
      "nist-sp-800-37-rmf"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-cwe-119-out-of-bounds-memory-buffer",
    "title": "MITRE CWE-119 - Improper Restriction of Operations Within the Bounds of a Memory Buffer",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a CWE Top 25 weakness and the root category for many memory safety vulnerabilities including CWE-125 (Out-of-bounds Read), CWE-787 (Out-of-bounds Write), CWE-120 (Classic Buffer Overflow), and CWE-416 (Use After Free). CWE-119 is defined as: the product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in accessing unexpected memory locations linked to other variables, data structures, or internal program data. Common Consequences are severe and span multiple security dimensions. Integrity, confidentiality, and availability impact: if an attacker controls accessible memory, arbitrary code execution becomes possible; overwriting pointer values (32-64 bits) allows redirecting function pointers to malicious code; even single-byte modifications can compromise security-critical application data. Availability and confidentiality impact: out-of-bounds access will very likely result in the corruption of relevant memory and potentially causes crashes or infinite loops; sensitive information exposure is possible, potentially revealing system details that enable further attacks. Potential Mitigations include language selection (employ languages providing automatic memory management such as Java, Perl, or Python, or overflow protection such as Ada or C#; though native code interfaces may remain vulnerable); libraries and frameworks (use vetted libraries like SafeStr or Microsoft's Strsafe.h providing safer string-handling alternatives); environment hardening (compiler flags including Microsoft /GS and FORTIFY_SOURCE; canary-based stack overflow detection; Address Space Layout Randomization (ASLR); Position-Independent Executable (PIE); Data Execution Prevention (DEP, NX bit); Control Flow Integrity (CFI), Intel CET, and ARM Pointer Authentication; AddressSanitizer (ASan), UndefinedBehaviorSanitizer (UBSan), and MemorySanitizer (MSan) in test builds); and implementation practices (replace unbounded functions like strcpy with length-aware alternatives like strncpy; verify buffer sizes, check loop boundaries, and validate all input lengths before copying operations).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-20-improper-input-validation"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-cwe-120-classic-buffer-overflow",
    "title": "MITRE CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "CWE-120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')) is ranked number 11 on the 2025 CWE Top 25 Most Dangerous Software Weaknesses, MITRE's community-developed list of the most dangerous software weaknesses. It is defined as follows: The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer. Common Consequences: Integrity, Confidentiality, Availability - Modify Memory; Execute Unauthorized Code or Commands. Availability - Modify Memory; DoS: Crash, Exit, or Restart; DoS: Resource Consumption (CPU). This node operationalises the MITRE-published Potential Mitigations for CWE-120 into a deterministic verification workflow, with every mitigation step quoted verbatim from and traceable to the CWE-120 entry at https://cwe.mitre.org/data/definitions/120.html.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-119-out-of-bounds-memory-buffer"
    ],
    "primary_citations_count": 15
  },
  {
    "node_id": "mitre-cwe-121-stack-based-buffer-overflow",
    "title": "MITRE CWE-121 - Stack-based Buffer Overflow",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "CWE-121 (Stack-based Buffer Overflow) is ranked number 14 on the 2025 CWE Top 25 Most Dangerous Software Weaknesses, MITRE's community-developed list of the most dangerous software weaknesses. It is defined as follows: A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function). There are generally several security-critical data on an execution stack that can lead to arbitrary code execution. The most prominent is the stored return address, the memory address at which execution should continue once the current function is finished executing. The attacker can overwrite this value with some memory address to which the attacker also has write access, into which they place arbitrary code to be run with the full privileges of the vulnerable program. Common Consequences: Availability - Modify Memory; DoS: Crash, Exit, or Restart; DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory). Integrity, Confidentiality, Availability, Access Control - Modify Memory; Execute Unauthorized Code or Commands; Bypass Protection Mechanism. This node operationalises the MITRE-published Potential Mitigations for CWE-121 into a deterministic verification workflow, with every mitigation step quoted verbatim from and traceable to the CWE-121 entry at https://cwe.mitre.org/data/definitions/121.html.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-787-out-of-bounds-write"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-cwe-122-heap-based-buffer-overflow",
    "title": "MITRE CWE-122 - Heap-based Buffer Overflow",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "CWE-122 (Heap-based Buffer Overflow) is ranked number 16 on the 2025 CWE Top 25 Most Dangerous Software Weaknesses, MITRE's community-developed list of the most dangerous software weaknesses. It is defined as follows: A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc(). Common Consequences: Availability - DoS: Crash, Exit, or Restart; DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory). Integrity, Confidentiality, Availability, Access Control - Execute Unauthorized Code or Commands; Bypass Protection Mechanism; Modify Memory. This node operationalises the MITRE-published Potential Mitigations for CWE-122 into a deterministic verification workflow, with every mitigation step quoted verbatim from and traceable to the CWE-122 entry at https://cwe.mitre.org/data/definitions/122.html.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-787-out-of-bounds-write"
    ],
    "primary_citations_count": 14
  },
  {
    "node_id": "mitre-cwe-125-out-of-bounds-read",
    "title": "MITRE CWE-125 - Out-of-bounds Read",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-125 (Out-of-bounds Read) is a CWE Top 25 weakness underlying many information-disclosure vulnerabilities including Heartbleed (CVE-2014-0160). CWE-125 is defined as: the product reads data past the end, or before the beginning, of the intended buffer. Common Consequences include read memory (attackers could obtain sensitive values including cryptographic keys, personally identifiable information, memory addresses, or data enabling further attacks); bypass protection mechanism (out-of-bounds memory access may expose information useful for circumventing security protections like ASLR to facilitate code execution exploits); denial of service via crash, exit, or restart (memory access violations can trigger segmentation faults or application crashes, particularly when code reads variable-length data relying on sentinels like null terminators); and varies-by-context (the read operation may produce undefined or unexpected results depending on specific circumstances). Potential Mitigations include implementation input validation strategy: employ strict accept-known-good validation using allowlists conforming to specifications; validate length, type, acceptable value ranges, missing or extra inputs, syntax, and business rule compliance; avoid exclusive reliance on blacklists; carefully validate and verify calculations for length arguments, buffer sizes, and offsets, especially when using sentinels in untrusted inputs. Architecture and design language selection: adopt programming languages providing appropriate memory abstractions to prevent boundary violations. CWE-125 sits as a child of CWE-119 (Improper Restriction of Operations Within the Bounds of a Memory Buffer) and is a sibling of CWE-787 (Out-of-bounds Write).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-119-out-of-bounds-memory-buffer"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-190-integer-overflow",
    "title": "MITRE CWE-190 - Integer Overflow or Wraparound",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-190 (Integer Overflow or Wraparound) is a CWE Top 25 weakness that frequently sits underneath buffer overflow, heap corruption, and protection-bypass vulnerabilities. CWE-190 is defined as: the product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. When an integer value is incremented beyond its maximum representable range, it becomes very small or negative rather than growing as expected. Common Consequences include availability impact (integer overflow can cause crashes, resource exhaustion, or instability; when calculations determine resource allocation, incorrect results may lead to excessive or insufficient resource requests); integrity impact (data corruption occurs when overflow results affect important values; additional memory corruption may occur if overflow triggers buffer overflow conditions); confidentiality and access control impact (overflows can trigger buffer overflows enabling arbitrary code execution; integer overflows in security-critical decisions such as quota or limit calculations can bypass protection mechanisms); and logic and availability impact (when overflow occurs in loop indices, loops may terminate incorrectly, creating infinite loops or excessive iterations that consume resources and crash systems). Potential Mitigations include input validation (validate numeric inputs ensuring they remain within expected ranges, checking both minimum and maximum boundaries; prefer unsigned integers when feasible); language selection (use languages with automatic bounds checking or those preventing this weakness); libraries and frameworks (employ vetted libraries like SafeInt in C++ or IntegerLib offering safe integer handling without unexpected consequences); and compiler hardening (address compiler warnings about signed/unsigned mismatches and uninitialized variables that could enable exploitation). Modern mitigations include UndefinedBehaviorSanitizer (UBSan) with -fsanitize=integer in test builds, checked arithmetic primitives (Rust checked_add, Go math/bits, C++ __builtin_add_overflow), and language-level overflow trapping (Swift, Ada).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-119-out-of-bounds-memory-buffer"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-20-improper-input-validation",
    "title": "MITRE CWE-20 - Improper Input Validation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-20 (Improper Input Validation) is one of the most foundational and broadly applicable software security weaknesses, ranked consistently near the top of the CWE Top 25. CWE-20 is defined as: the product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. The Extended Description identifies two forms of input: raw data (strings, numbers, parameters, file contents) and metadata (information about the raw data such as headers or size). Properties requiring validation include specified quantities (size, length, frequency, price, rate, number of operations, time); well-formedness (syntactic correctness); specified or derived type (actual type or apparent type); consistency (between individual data elements, between raw data and metadata, between references); conformance to domain-specific rules (business logic); and authenticity, ownership, or other attestations (e.g., a cryptographic signature). Common Consequences include availability impact (attackers providing unexpected values can crash programs or cause excessive resource consumption of CPU or memory); confidentiality impact (attackers controlling resource references may read confidential data or access files); and integrity and availability impact (an attacker could use malicious input to modify data or possibly alter control flow in unexpected ways, including arbitrary command execution). The Potential Mitigations include attack-surface reduction via an accept-known-good input validation strategy using a list of acceptable inputs that strictly conform to specifications; assume all input is malicious; validate length, type, acceptable value ranges, missing or extra inputs, syntax, consistency, and business rule conformance; ensure all client-side security checks are duplicated on the server side; and canonicalize inputs to the application's current internal representation before validation. CWE-20 is the parent weakness for many specific injection and parsing weaknesses including CWE-78 (OS command injection), CWE-79 (XSS), CWE-89 (SQL injection), and CWE-22 (path traversal).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-top-25-2024-most-dangerous-weaknesses"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-cwe-200-sensitive-information-exposure",
    "title": "MITRE CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) is the broad parent weakness for information disclosure findings and is a CWE Top 25 weakness consistently associated with data breach incidents, security misconfiguration findings, and API leakage. CWE-200 is defined as: the product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. The Extended Description notes that information exposures vary widely in severity depending on context, the type of sensitive data revealed, and potential attacker benefits. Categories of sensitive information include personal data (messages, financial records, health information, location, contact details); system environment details (operating system, installed packages); trade secrets and intellectual property; network status and configuration; product code or internal state; metadata such as connection logs or message headers; and indirect information revealing discrepancies observable by outsiders. Different parties may have varying expectations about information protection: product users, individuals whose data is processed, administrators, and developers. Exposures occur through three primary mechanisms: (1) code explicitly inserting sensitive information into accessible resources without proper sanitization; (2) different weaknesses indirectly inserting sensitive data (such as system paths in error messages); and (3) resources containing sensitive information becoming unintentionally accessible due to separate vulnerabilities. Common Consequences include read application data with confidentiality scope. Potential Mitigations include architecture and design: employ separation of privilege strategies by compartmentalizing systems into safe areas with clear trust boundaries; prevent sensitive data from crossing trust boundaries and exercise caution when interfacing external compartments; build compartmentalization into system design reinforcing privilege separation using least privilege principles; determine appropriate times for privilege elevation and removal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-209-error-message-information-disclosure"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-209-error-message-information-disclosure",
    "title": "MITRE CWE-209 - Generation of Error Message Containing Sensitive Information",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-209 (Generation of Error Message Containing Sensitive Information) is a CWE Top 25 weakness underlying many information disclosure findings in penetration tests and bug bounty reports. CWE-209 is defined as: the product generates an error message that includes sensitive information about its environment, users, or associated data. The Extended Description identifies two error generation mechanisms. Self-generated errors: when source code explicitly constructs and delivers error messages. Externally-generated errors: when language interpreters or external environments handle errors and create messages outside programmer control. Such information may be valuable independently (passwords) or useful for launching more serious attacks. Common Consequences include confidentiality impact via read application data: sensitive information exposure can reveal data for focused attacks or disclose private server information; for example, path traversal exploitation might expose full application pathnames; SQL injection errors could reveal query logic, structure, or embedded credentials used within queries. Potential Mitigations include implementation controls (ensure error messages contain only minimal details useful to intended audiences; strike balance between cryptic - confusing users - and detailed - revealing sensitive data; don't reveal methods used to determine errors as attackers refine attacks using detailed information; record detailed errors in logs while considering log accessibility risks; never save passwords to log files; avoid inconsistent messaging that tips off attackers about internal state); internal handling (handle exceptions internally without displaying potentially sensitive error information to users); system configuration (configure environments for less verbose error messages, e.g., PHP display_errors setting; create default error pages that leak no information); and build and environment hardening (ensure debugging information doesn't reach production releases).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-200-sensitive-information-exposure"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-22-path-traversal",
    "title": "MITRE CWE-22 - Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-22 (Improper Limitation of a Pathname to a Restricted Directory, commonly known as Path Traversal or Directory Traversal) is a CWE Top 25 weakness with consistent presence in file-handling vulnerabilities across web applications, file servers, container runtimes, and archive extractors. CWE-22 is defined as: the product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. The Extended Description explains: file operations frequently occur within confined directories; attackers can exploit special elements like .. and / separators to break outside restricted locations; the ../ sequence represents the parent directory in modern operating systems, enabling relative path traversal; absolute pathnames (e.g., /usr/local/bin) create absolute path traversal variants. Common Consequences include execute unauthorized code or commands (attackers may create or overwrite critical files used for code execution, such as programs or libraries); modify files or directories (critical files like programs, libraries, or data can be overwritten or created; security mechanisms may be bypassed); read files or directories (unexpected files may be read, exposing sensitive data and potentially circumventing security mechanisms); and DoS via crash, exit, or restart (attackers may overwrite, delete, or corrupt critical files preventing normal operation). Potential Mitigations include input validation using allowlists of acceptable inputs strictly conforming to specifications (for filenames, restrict character sets and exclude directory separators); path canonicalization using built-in functions (realpath in C/PHP, getCanonicalPath in Java) to produce canonical pathnames that remove .. sequences; privilege minimization (execute code with minimal necessary privileges using isolated accounts); sandbox or jail environments (restrict file access through OS-level mechanisms like chroot jails or AppArmor); and attack surface reduction (store library files outside web document roots and prevent direct requests).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-20-improper-input-validation"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-cwe-269-improper-privilege-management",
    "title": "MITRE CWE-269 - Improper Privilege Management",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-269 (Improper Privilege Management) is a CWE Top 25 weakness associated with privilege escalation vulnerabilities across operating systems, container runtimes, web applications, and SaaS platforms. CWE-269 is defined as: the product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. Common Consequences include impact on Gain Privileges or Assume Identity with scope Access Control: the primary consequence involves an adversary obtaining elevated system permissions or assuming the identity of another user, thereby breaching access control mechanisms. Potential Mitigations include architecture and design plus operation controls: very carefully manage the setting, management, and handling of privileges; explicitly manage trust zones in the software. Architecture and design separation of privilege: apply the principle of least privilege when assigning access rights to system entities. Architecture and design separation of privilege (defense in depth): require multiple conditions to be met before permitting access to a system resource, implementing defense-in-depth for sensitive operations. Modern CWE-269 mitigations include privileged access management (PAM) systems with just-in-time elevation, time-bounded privilege grants, and explicit approval workflows; container security with non-root containers, dropped capabilities, and read-only root filesystems; Kubernetes Pod Security Standards (Restricted profile); SELinux, AppArmor, and seccomp profiles; cloud IAM with explicit deny boundaries, permission boundaries (AWS), and conditional access (Azure, GCP).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-862-missing-authorization"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-284-improper-access-control",
    "title": "MITRE CWE-284 - Improper Access Control",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "CWE-284 (Improper Access Control) is ranked number 19 on the 2025 CWE Top 25 Most Dangerous Software Weaknesses, MITRE's community-developed list of the most dangerous software weaknesses. It is defined as follows: The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. Access control involves the use of several protection mechanisms such as: Authentication (proving the identity of an actor), Authorization (ensuring that a given actor can access a resource), and Accountability (tracking of activities that were performed). When any mechanism is not applied or otherwise fails, attackers can compromise the security of the product by gaining privileges, reading sensitive information, executing commands, evading detection, etc. Common Consequences: Other - Varies by Context. Consequences of improper access control include an actor gaining privileges, reading sensitive information, executing commands, or evading detection. This node operationalises the MITRE-published Potential Mitigations for CWE-284 into a deterministic verification workflow, with every mitigation step quoted verbatim from and traceable to the CWE-284 entry at https://cwe.mitre.org/data/definitions/284.html.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-285-improper-authorization",
      "mitre-cwe-862-missing-authorization",
      "mitre-cwe-863-incorrect-authorization"
    ],
    "primary_citations_count": 14
  },
  {
    "node_id": "mitre-cwe-285-improper-authorization",
    "title": "MITRE CWE-285 - Improper Authorization",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-285 (Improper Authorization) is a CWE Top 25 weakness frequently underpinning Broken Object Level Authorization (BOLA) and Broken Function Level Authorization (BFLA) findings in API and web application security testing. CWE-285 is defined as: the product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action. CWE-285 sits as a parent for CWE-862 (Missing Authorization) and CWE-863 (Incorrect Authorization). Common Consequences include confidentiality impact (an attacker could read sensitive data by accessing insufficiently-protected, privileged functionality or data stores lacking proper access restrictions); integrity impact (an attacker might modify sensitive data through direct writes to inadequately restricted data stores or by exploiting unprotected privileged functionality); and access control impact (when access control checks are not applied consistently - or not at all - an attacker could gain privileges and execute unauthorized code or commands by modifying or reading critical data directly, or by accessing insufficiently-protected, privileged functionality). Potential Mitigations include architecture and design controls (implement role-based access control (RBAC) across anonymous, normal, privileged, and administrative zones; perform access control checks aligned with business logic, not merely generic resources; deploy vetted authorization frameworks like JAAS or OWASP ESAPI; enforce server-side authorization on every page; prevent unauthorized access through direct requests); and system configuration (apply operating system and server ACLs with a default deny policy). CWE-285 differs from CWE-862 (missing check entirely) in that the check exists but is incorrectly performed; it differs from CWE-863 (incorrect logic in the check) in being the broader category covering both.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-862-missing-authorization"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-287-improper-authentication",
    "title": "MITRE CWE-287 - Improper Authentication",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-287 (Improper Authentication) is a CWE Top 25 weakness consistently present in authentication-bypass advisories across web applications, APIs, network appliances, and SaaS platforms. CWE-287 is defined as: when an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. The Common Consequences include impact on Integrity, Confidentiality, Availability, and Access Control: this weakness can expose resources or functionality to unintended actors, potentially giving attackers access to sensitive information or enabling arbitrary code execution. Specific impacts include Read Application Data, Gain Privileges or Assume Identity, and Execute Unauthorized Code or Commands. Potential Mitigations include architecture and design controls (the most fundamental being to leverage authentication frameworks or libraries such as the OWASP ESAPI Authentication feature rather than implementing custom authentication schemes). Modern authentication mitigations also include multi-factor authentication (MFA) per NIST 800-63B; phishing-resistant authentication (FIDO2, passkeys, smart cards); password hashing with adaptive functions (bcrypt, scrypt, argon2id) with appropriate work factors; secure session management (long random session IDs, secure cookie attributes, session timeout, session rotation on privilege change); account lockout or rate limiting to mitigate credential stuffing and brute force; and credential storage protection (encrypted at rest, no plaintext, no reversible hashes). CWE-287 is the parent of many specific authentication weaknesses including CWE-306 (Missing Authentication for Critical Function), CWE-307 (Improper Restriction of Excessive Authentication Attempts), CWE-521 (Weak Password Requirements), CWE-798 (Use of Hard-coded Credentials), and CWE-307 (rate limiting).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-top-25-2024-most-dangerous-weaknesses"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-cwe-306-missing-authentication-for-critical-function",
    "title": "MITRE CWE-306 - Missing Authentication for Critical Function",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-306 (Missing Authentication for Critical Function) is a CWE Top 25 weakness consistently associated with unauthenticated admin interfaces, exposed management ports, internal APIs leaked to the internet, and exposed cloud metadata or storage endpoints. CWE-306 is defined as: the product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. The Extended Description identifies common scenarios where the weakness arises: developers failing to implement authentication mechanisms for critical operations; creating secondary communication channels assumed to be private without requiring authentication; allowing access to administrative or privileged functionality without identity verification; and failing to authenticate across all interaction channels or connection types. Common Consequences include access control impact (exposing critical functionality provides attackers with elevated privilege levels; consequences range from reading and modifying sensitive data to executing arbitrary code or accessing administrative functions); and privilege escalation (an attacker can assume the identity and privileges associated with unprotected critical functions, depending on the specific functionality involved). Potential Mitigations include architecture and design (divide software into anonymous, normal, privileged, and administrative areas; implement centralized authentication for areas requiring proven identity); multi-channel protection (identify all communication channels and ensure authentication applies consistently across all of them); server-side validation (duplicate client-side security checks on the server to prevent bypass attempts); framework usage (use established authentication libraries - OpenSSL, ESAPI - rather than custom authentication routines); and cloud security (implement provider controls requiring strong authentication for cloud-stored data access).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-287-improper-authentication"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-cwe-352-cross-site-request-forgery",
    "title": "MITRE CWE-352 - Cross-Site Request Forgery (CSRF)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-352 (Cross-Site Request Forgery, commonly known as CSRF or XSRF) is a web application security weakness whereby an attacker tricks an authenticated user's browser into submitting state-changing requests the user did not intend. CWE-352 is defined as: the web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor. CSRF exploits the trust a web application places in the user's browser by leveraging authenticated session cookies that the browser attaches automatically to outbound requests. Common Consequences expose multiple security dimensions including confidentiality, integrity, and availability: an attacker can trick a user into making unintended requests while authenticated, potentially allowing unauthorized data access and modification; privilege escalation if the victim holds administrative rights; complete application compromise including data theft or product manipulation; and effective operation under the victim's identity. Potential Mitigations include architecture and design controls: employing anti-CSRF libraries (OWASP CSRFGuard or security frameworks providing built-in protections); generating unique unpredictable nonces for each form submission; requesting confirmation for sensitive operations; implementing double-submitted cookie validation (pseudorandom values in both form and cookie); avoiding GET methods for state-changing requests. Implementation mitigations include eliminating cross-site scripting vulnerabilities (since XSS bypasses CSRF defenses) and validating HTTP Referer headers (though this may impact legitimacy and privacy). Modern CSRF mitigations also include SameSite cookie attribute (SameSite=Lax for default, SameSite=Strict for high-sensitivity operations) and origin-based defenses (validating Origin and Referer headers per the OWASP CSRF Prevention Cheat Sheet).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-79-cross-site-scripting"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-cwe-400-uncontrolled-resource-consumption",
    "title": "MITRE CWE-400 - Uncontrolled Resource Consumption",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-400 (Uncontrolled Resource Consumption) is a CWE Top 25 weakness underlying denial-of-service vulnerabilities including algorithmic complexity attacks, regex denial of service (ReDoS), billion laughs and quadratic blowup XML attacks, decompression bombs (zip bomb), and excessive memory or CPU consumption in parsers. CWE-400 is defined as: the product does not properly control the allocation and maintenance of a limited resource. The Extended Description identifies several common resource-exhaustion scenarios: lack of throttling for the number of allocated resources; lost references to resources before shutdown; failure to close or return resources after processing. These problems often stem from error handling confusion or uncertainty about which code component bears responsibility for resource release. Common Consequences include availability impact: if an attacker can trigger the allocation of the limited resources but the number or size of the resources is not controlled, then the most common result is denial of service; this may cause the product to slow down, crash, or lock out legitimate users; host operating systems can also be affected. Access control impact: in some cases it may be possible to force the product to fail open in the event of resource exhaustion, potentially compromising security functionality. Potential Mitigations include architecture and design: design throttling mechanisms into system architecture; implement strong authentication and access control models; protect login applications against DoS attacks; cache database result sets to minimize resource expenditure; track request rates and block requests exceeding defined thresholds; ensure protocols have specific scale limits. Implementation: ensure that all failures in resource allocation place the system into a safe posture.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-611-xml-external-entity-xxe"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-416-use-after-free",
    "title": "MITRE CWE-416 - Use After Free",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-416 (Use After Free) is a CWE Top 25 weakness underlying many heap exploitation primitives in browsers, kernels, and high-performance native code. CWE-416 is defined as: the product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. The Extended Description notes that operations using the original pointer become invalid because the memory now belongs to code operating on the new pointer. Common Consequences include modify memory or integrity impact (previously freed memory use may corrupt valid data if the memory area has been properly allocated and used elsewhere); denial of service or availability impact (if chunk consolidation occurs after the use of previously freed data, the process may crash when invalid data is used as chunk information); read memory or confidentiality impact (read operations on freed memory can sometimes leak sensitive information instead of causing a crash); and execute unauthorized code with integrity, confidentiality, and availability impact (malicious data entered before chunk consolidation may enable arbitrary code execution through overwritten function pointers on the heap). Potential Mitigations include language selection (choose a language that provides automatic memory management) and attack surface reduction (when freeing pointers, be sure to set them to NULL once they are freed; this reduces code execution risks though NULL dereference crashes remain possible). Modern mitigations include smart pointers in C++ (std::unique_ptr, std::shared_ptr), borrow checking in Rust, GuardMalloc, AddressSanitizer, heap isolation (PartitionAlloc, MiraclePtr, scudo), and Memory Tagging Extension (MTE) on ARM64.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-119-out-of-bounds-memory-buffer"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-434-unrestricted-file-upload",
    "title": "MITRE CWE-434 - Unrestricted Upload of File with Dangerous Type",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-434 (Unrestricted Upload of File with Dangerous Type) is a CWE Top 25 weakness underlying many remote code execution incidents in web applications, including unauthenticated webshell uploads, polyglot file uploads, and SVG-based XSS uploads. CWE-434 is defined as: the product allows the upload or transfer of dangerous file types that are automatically processed within its environment. The Extended Description notes that this vulnerability occurs when applications lack proper validation of uploaded files; attackers can upload executable files (like .php, .asp, .jsp) that web servers automatically process, leading to arbitrary code execution; the danger intensifies when files are stored in web-accessible directories without extension or MIME-type verification. Common Consequences include execute unauthorized code or commands with integrity, confidentiality, and availability scope: arbitrary code execution is possible if an uploaded file is interpreted and executed as code by the recipient; this is especially true for web-server extensions such as .asp and .php because these file types are often treated as automatically executable, even when file system permissions do not specify execution. Potential Mitigations include architecture and design (generate unique filenames instead of using user-supplied names; store uploads outside the web document root and deliver files dynamically; implement strict allowlists of acceptable file extensions); implementation (apply input validation using accept-known-good strategy with strict extension checking; ensure single extensions only - prevent file.php.gif bypass techniques; perform case-insensitive extension validation; validate MIME types without relying exclusively on them); and environment (run code with minimal necessary privileges; execute uploads in sandboxed environments - chroot, AppArmor, SELinux).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-22-path-traversal"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-476-null-pointer-dereference",
    "title": "MITRE CWE-476 - NULL Pointer Dereference",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-476 (NULL Pointer Dereference) is a CWE Top 25 weakness causing denial of service in most contexts and remote code execution in privileged or kernel contexts where NULL maps to a usable memory page. CWE-476 is defined as: the product dereferences a pointer that it expects to be valid but is NULL. Common Consequences include denial of service via crash, exit, or restart (NULL pointer dereferences usually result in the failure of the process unless exception handling on some platforms is available and implemented) and execute unauthorized code or commands, read memory, modify memory (in rare cases where NULL maps to memory address 0x0 and privileged code can access it, reading or writing memory becomes possible, potentially enabling code execution). The latter risk is particularly relevant in kernel and embedded contexts where address 0 may be a mappable page. Potential Mitigations include implementation phase controls: verify all pointers that could be modified or returned from functions capable of returning NULL before using them; in multithreaded environments, employ proper locking mechanisms around pointer checks (to prevent TOCTOU races between check and use); validate all function return values and confirm they are non-NULL before proceeding; initialize all variables and data stores explicitly at declaration or before first use. Architecture and design controls: identify external data sources and apply input validation to ensure variables initialize only to expected values. Requirements phase controls: select programming languages that inherently prevent such vulnerabilities. Modern mitigations include kernel mmap_min_addr to make NULL non-mappable, smart pointers and Option types (Rust Option, C++ std::optional), and static analysis (Coverity, CodeQL, Clang Static Analyzer) detecting null dereference paths.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-20-improper-input-validation"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-502-deserialization-of-untrusted-data",
    "title": "MITRE CWE-502 - Deserialization of Untrusted Data",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-502 (Deserialization of Untrusted Data) is a CWE Top 25 weakness underlying many remote code execution exploits across Java, .NET, PHP, Python, Ruby, and Node.js ecosystems. CWE-502 is defined as: the product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. Common Consequences include integrity impact (attackers can alter unexpected objects or data assumed to be safe; deserialized content or functions could be modified without proper accessor functions); availability impact (functions assuming termination based on string sentries may never terminate, causing resource consumption); and variable context impact (consequences depend on which objects are deserialized; attackers may leverage gadget chains to execute unauthorized actions like shell generation, achieving remote code execution). Potential Mitigations include signing or sealing the serialized data using programming language features like HMAC to verify deserialized data has not been tampered with; safe instantiation by creating new objects during deserialization rather than direct deserialization, enabling input validation; preventing deserialization entirely by defining final object methods to block deserialization; transient fields marking sensitive variables to prevent them from persisting through deserialization; allowlisting restricting available types and gadgets to acceptable classes only; cryptography to encrypt data or code (though client-side protections remain vulnerable if the client is compromised); and application firewalls to detect attacks when code fixes are unavailable. CWE-502 is the underlying weakness for Java deserialization gadget chains (ysoserial), .NET BinaryFormatter deserialization, Python pickle exploits, PHP unserialize attacks (POP chains), Ruby Marshal deserialization, and Node.js node-serialize attacks. The OWASP Top 10 has historically included Insecure Deserialization (A8:2017) as a top concern.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-20-improper-input-validation"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-611-xml-external-entity-xxe",
    "title": "MITRE CWE-611 - Improper Restriction of XML External Entity Reference (XXE)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-611 (Improper Restriction of XML External Entity Reference, commonly known as XXE) is a CWE Top 25 weakness affecting XML parsing in applications, SOAP services, SAML implementations, document upload handlers, RSS readers, and SVG renderers. CWE-611 is defined as: the product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. The Extended Description notes that XML documents may include a Document Type Definition (DTD) allowing definition of entities through substitution strings in URI form; XML parsers can access URI contents and embed them back into documents during processing, creating a vulnerability when external entities are not restricted. Common Consequences include confidentiality impact (attackers with crafted DTDs and enabled default entity resolvers may access arbitrary files; using file:// URIs, attackers can read local system files like /etc/passwd or C:\\Winnt\\win.ini, with contents potentially exposed through application error messages); integrity impact (attackers can supply crafted DTDs using schemes like http:// to force outbound requests, bypassing firewall restrictions, hiding attack sources through port scanning, or exploiting server trust relationships - effectively becoming an SSRF vector); and availability impact (products may consume excessive CPU or memory through URIs pointing to large files or infinite data sources like /dev/random; nested or recursive entity references further degrade parsing performance, the classic billion laughs and quadratic blowup attacks). Potential Mitigations: many XML parsers and validators can be configured to disable external entity expansion. This represents the primary defense strategy during implementation and system configuration phases.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-918-server-side-request-forgery"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-639-authorization-bypass-user-controlled-key",
    "title": "MITRE CWE-639 - Authorization Bypass Through User-Controlled Key",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "CWE-639 (Authorization Bypass Through User-Controlled Key) is ranked number 24 on the 2025 CWE Top 25 Most Dangerous Software Weaknesses, MITRE's community-developed list of the most dangerous software weaknesses. It is defined as follows: The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. Retrieval of a user record occurs in the system based on some key value that is under user control. The key would typically identify a user-related record stored in the system and would be used to lookup that record for presentation to the user. It is likely that an attacker would have to be an authenticated user in the system. However, the authorization process would not properly check the data access operation to ensure that the authenticated user performing the operation has sufficient entitlements to perform the requested data access, hence bypassing any other authorization checks present in the system. One manifestation of this weakness is when a system uses sequential or otherwise easily-guessable session IDs that would allow one user to easily switch to another user's session and read/modify their data. Common Consequences: Access Control - Bypass Protection Mechanism. Access Control - Gain Privileges or Assume Identity. This node operationalises the MITRE-published Potential Mitigations for CWE-639 into a deterministic verification workflow, with every mitigation step quoted verbatim from and traceable to the CWE-639 entry at https://cwe.mitre.org/data/definitions/639.html.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-863-incorrect-authorization"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-cwe-732-incorrect-permission-assignment",
    "title": "MITRE CWE-732 - Incorrect Permission Assignment for Critical Resource",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-732 (Incorrect Permission Assignment for Critical Resource) is a CWE Top 25 weakness consistently present in cloud misconfiguration incidents (public S3 buckets, world-readable Kubernetes secrets, public Elasticsearch instances) and operating system file permission flaws. CWE-732 is defined as: the product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. The Extended Description notes that when resources receive overly permissive settings, unintended parties can access sensitive information or make unauthorized modifications; this proves especially hazardous for configuration files, executables, or user data; a misconfigured cloud storage account readable by anonymous users exemplifies this vulnerability. Common Consequences include confidentiality impact (attackers may read sensitive data like credentials or configuration information from improperly secured resources); access control impact (adversaries could modify critical resource properties to escalate privileges, such as replacing executable files with malicious code); and integrity impact (attackers may destroy or corrupt critical data stored in inadequately protected resources, including database records). Potential Mitigations include verifying critical resources lack insecure permissions during startup and generating errors if unauthorized modification is possible; dividing software into distinct user groups with corresponding privilege levels and mapped resource permissions; executing code within sandbox environments (chroot, AppArmor, SELinux) to restrict file and command access; setting restrictive default permissions and umask values at program initialization and installation; restricting configuration files and executables to administrator read/write access only; and disabling public access for cloud storage (S3, Azure, Google Cloud Storage) using provider controls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-269-improper-privilege-management"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-77-command-injection-broad",
    "title": "MITRE CWE-77 - Improper Neutralization of Special Elements Used in a Command (Command Injection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-77 (Improper Neutralization of Special Elements used in a Command) is the broad parent weakness for command injection. It covers not only OS command injection (CWE-78, its child) but also injection in custom command languages and any product-defined command protocols. CWE-77 is defined as: the product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component. The Extended Description notes that many protocols and products implement custom command languages beyond OS shells; developers may overlook that these alternative command environments are similarly vulnerable to injection attacks as traditional shell commands. Examples include LDAP injection, XPath injection, NoSQL injection (MongoDB query selector injection), SMTP injection (email header injection), CRLF injection in HTTP headers, log injection, and template engine command injection. Common Consequences include execute unauthorized code or commands with integrity, confidentiality, and availability scope: an attacker can inject delimiter characters (such as semicolons) to terminate one command and initiate another unintended command, granting unauthorized capabilities and privileges. Potential Mitigations include architecture and design (prefer library calls over external processes when feasible); implementation (ensure externally-called commands are statically defined rather than dynamically constructed); input validation (apply accept-known-good strategies using strict allowlists that conform to specifications; reject non-conforming inputs); runtime enforcement (deploy allowlist-based runtime policies restricting non-sanctioned commands); and system configuration (assign restrictive permissions preventing access to privileged files).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-78-os-command-injection"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-cwe-770-allocation-resources-without-limits",
    "title": "MITRE CWE-770 - Allocation of Resources Without Limits or Throttling",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-770 (Allocation of Resources Without Limits or Throttling) is a CWE Top 25 weakness and a primary child of CWE-400 (Uncontrolled Resource Consumption); it covers application-layer denial-of-service vulnerabilities where the application allows unbounded creation of resources on behalf of an actor. CWE-770 is defined as: the product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated. Common Consequences include denial of service impact: when resources lack allocation limits, attackers can prevent other systems or applications from accessing those resources; adversaries can readily exhaust resources by making numerous rapid requests or consuming larger quantities than necessary. Potential Mitigations include requirements phase: clearly define minimum and maximum capability expectations and specify acceptable behaviors when resource allocation reaches its limits. Architecture and design: restrict resource access for unprivileged users through per-user limits; enable system administrators to define these restrictions; integrate throttling mechanisms into system architecture; implement strong authentication and access control models; apply rate-limiting to block requests exceeding defined thresholds; use operating system resource quotas (e.g., setrlimit on POSIX systems). Implementation: validate all input assuming maliciousness; employ accept-known-good validation strategies; duplicate client-side security checks on the server side. Operation: ensure graceful system failure with proper error handling when resources become unavailable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-400-uncontrolled-resource-consumption"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-78-os-command-injection",
    "title": "MITRE CWE-78 - Improper Neutralization of Special Elements Used in an OS Command (OS Command Injection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-78 (Improper Neutralization of Special Elements used in an OS Command, commonly known as OS Command Injection) is consistently in the CWE Top 25 most dangerous weaknesses and is one of the most exploited weaknesses in network appliances, IoT devices, and admin web applications. CWE-78 is defined as: the product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. The Extended Description identifies two primary variants: (1) a fixed program with user arguments where an application intends to execute a specific program but fails to sanitize user-supplied arguments, allowing attackers to execute additional programs via command separators; and (2) attacker-controlled command selection where applications that allow users to fully specify which program to execute create severe risks because attackers can execute arbitrary commands if input validation is inadequate. The Extended Description notes that if the weakness occurs in a privileged program, it could allow the attacker to specify commands that normally would not be accessible, or to call alternate commands with privileges that the attacker does not have. Common Consequences include unauthorized operating system command execution, denial of service, unauthorized file read and modification, application data modification, and concealment of malicious activities by making them appear to originate from the application. Impact scope includes Confidentiality, Integrity, Availability, and Non-Repudiation. Primary Mitigations include using library calls instead of external processes where feasible; implementing sandbox or jail environments (chroot, AppArmor, SELinux); using parameterized functions requiring individual arguments rather than single command strings; applying strict input validation with allowlists; implementing output encoding and proper escaping; running code with minimum necessary privileges; and deploying application firewalls for detection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-20-improper-input-validation"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-cwe-787-out-of-bounds-write",
    "title": "MITRE CWE-787 - Out-of-bounds Write",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-787 (Out-of-bounds Write) is consistently the highest-ranked memory safety weakness in the CWE Top 25 Most Dangerous Software Weaknesses and is the underlying weakness for the majority of remote code execution exploits in native code. CWE-787 is defined as: the product writes data past the end, or before the beginning, of the intended buffer. The Extended Description notes that memory corruption can occur through write operations exceeding buffer boundaries; attackers may modify control data such as return addresses to execute unauthorized code; the consequences include system crashes, undefined behavior, and potential code execution. Common Consequences include integrity impact (write operations could cause memory corruption; in some cases, an adversary can modify control data such as return addresses in order to execute unexpected code); availability impact (attempting to access out-of-range, invalid, or unauthorized memory could cause the product to crash); and other impact (subsequent write operations can produce undefined or unexpected results). Potential Mitigations include language selection (use memory-safe languages like Java, Perl, Ada, or C# that prevent this weakness or provide overflow protection); libraries and frameworks (employ vetted libraries like SafeStr or Strsafe.h providing safer string-handling functions); compiler features (use overflow detection mechanisms including Microsoft Visual Studio /GS flag, GCC FORTIFY_SOURCE, StackGuard, ProPolice); memory management (double-check buffer sizes, use bounded functions like strncpy, validate loop boundaries); ASLR and PIE (Address Space Layout Randomization and Position-Independent Executables); Data Execution Protection (use NX/XD bits to prevent code execution from data segments); and bounded functions (replace unbounded copy functions with length-aware alternatives).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-119-out-of-bounds-memory-buffer"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "mitre-cwe-79-cross-site-scripting",
    "title": "MITRE CWE-79 - Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-79 (Improper Neutralization of Input During Web Page Generation, commonly known as Cross-site Scripting or XSS) is one of the most prevalent web application security weaknesses, ranked in the CWE Top 25 Most Dangerous Software Weaknesses every year since the list began. CWE-79 is defined as: the product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. The Extended Description identifies three principal variants: Reflected XSS (Type 1), where the server reads data directly from the HTTP request and reflects it back in the HTTP response; Stored XSS (Type 2), where the server stores the dangerous data and later renders it to other users; and DOM-Based XSS (Type 0), where the client-side script writes attacker-controllable data into the DOM. Common Consequences include access control and confidentiality bypass (disclosure of session cookies and other sensitive data through script execution in the victim's browser), unauthorized code execution when combined with other flaws (drive-by hacking), and multi-impact attacks (stealing cookies, forging requests, compromising confidential information, executing malicious code, disclosing user files, installing Trojans, redirecting users, or running potentially harmful controls). The Potential Mitigations span architecture and design (using vetted libraries such as Microsoft Anti-XSS, OWASP ESAPI, or Apache Wicket; structured separation of data and code; output encoding appropriate for the downstream component; allowlisting character sets), implementation (applying proper encoding to all non-alphanumeric characters in output; setting HttpOnly on session cookies; validating ALL HTTP request components; using input validation as defense-in-depth; avoiding PHP register_globals), and operational controls (deploying application firewalls for detection; environment hardening).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-top-25-2024-most-dangerous-weaknesses"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-cwe-798-use-of-hard-coded-credentials",
    "title": "MITRE CWE-798 - Use of Hard-coded Credentials",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-798 (Use of Hard-coded Credentials) is a CWE Top 25 weakness consistently present in firmware, IoT devices, network appliances, default-install software, and codebases that have leaked private repositories or expanded build artifacts. CWE-798 is defined as: the product contains hard-coded credentials, such as a password or cryptographic key. The Extended Description identifies two main variations. Inbound: the product includes authentication that compares input credentials against hard-coded values; a default administration account is created with a simple, unchangeable password identical across all installations. Outbound: the product connects to another system using hard-coded credentials; this commonly affects front-end systems authenticating with back-end services where fixed passwords are embedded in code. Common Consequences include access control violation (if hard-coded passwords are used, it is almost certain that malicious users will gain access to the account in question; extraction from binaries is typically simple, especially for client-side systems) and integrity, confidentiality, availability impact (this weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code; widespread password knowledge enables massive attacks across different organizations). Potential Mitigations include storing credentials outside code in encrypted, access-restricted configuration files or databases; implementing first login mode requiring unique strong passwords instead of defaults; applying access controls limiting which entities can access hard-coded credential features; using one-way hashes with random salts for password storage and comparison; and for front-end and back-end connections, employing auto-rotating passwords, limiting backend access scope, and implementing time-sensitive checksums. Modern mitigations include centralized secret managers (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, Doppler, 1Password Secrets Automation), workload identity (mTLS, OIDC federation, cloud workload identity), short-lived dynamic credentials, and continuous secret scanning (TruffleHog, gitleaks, GitGuardian).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-287-improper-authentication"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-862-missing-authorization",
    "title": "MITRE CWE-862 - Missing Authorization",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-862 (Missing Authorization) is a CWE Top 25 weakness recurring in cloud, API, and SaaS applications, and is the underlying root cause for many Insecure Direct Object Reference (IDOR) and Broken Object Level Authorization (BOLA) findings. CWE-862 is defined as: the product does not perform an authorization check when an actor attempts to access a resource or perform an action. The Common Consequences are multi-dimensional: confidentiality impact (attackers could read sensitive data by accessing unprotected data stores or insufficiently-protected privileged functionality); integrity impact (attackers might modify sensitive data through direct writes to unrestricted data stores or by accessing privileged functions without proper restrictions); access control impact (attackers could escalate privileges by modifying or reading critical data, or by accessing restricted functionality without authorization); and availability impact (unauthorized resource access could enable denial-of-service attacks through excessive consumption of CPU, memory, or other system resources). Potential Mitigations include architecture and design via role-based access control (RBAC) to divide products into anonymous, normal, privileged, and administrative areas, reducing attack surface through careful role-to-data mapping; business logic controls ensuring access control checks relate to business logic requirements (which may differ from generic resource protections like file or database access restrictions); framework solutions employing vetted libraries such as JAAS Authorization Framework or OWASP ESAPI Access Control features; web application security enforcing server-side access control on every page and preventing unauthorized access through cached pages or direct requests lacking proper authentication tokens; and system configuration using operating system access control capabilities with default deny ACL policies. CWE-862 sits alongside CWE-285 (Improper Authorization) and CWE-863 (Incorrect Authorization) in the authorization weakness family.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-287-improper-authentication"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-863-incorrect-authorization",
    "title": "MITRE CWE-863 - Incorrect Authorization",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-863 (Incorrect Authorization) is a CWE Top 25 weakness covering authorization decisions that are made but performed with incorrect logic, missing conditions, or buggy rule evaluation. CWE-863 is defined as: the product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. The Extended Description notes that authorization represents the process of determining whether an authenticated user can access a given resource, based on their privileges and applicable access-control specifications; when this verification fails to function correctly, attackers can bypass intended restrictions. Common Consequences include confidentiality impact (attackers may bypass access restrictions to read sensitive data directly from unprotected data stores or access privileged functionality); integrity impact (attackers can modify sensitive information by writing to inadequately restricted data stores or accessing privileged functionality without authorization); access control impact (attackers gain unauthorized privileges by modifying critical data or accessing restricted functionality, potentially assuming false identities); and availability and execution impact (with elevated privileges, attackers execute unauthorized commands or code, potentially causing system crashes, resource exhaustion, or denial of service). Potential Mitigations include implementing RBAC across anonymous, normal, privileged, and administrative areas; performing authorization checks aligned with business logic, not just generic resource controls; employing vetted authorization frameworks like JAAS or OWASP ESAPI; enforcing server-side access control on every page and preventing caching of sensitive information; and applying default-deny policies in OS and server ACLs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-285-improper-authorization"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mitre-cwe-89-sql-injection",
    "title": "MITRE CWE-89 - Improper Neutralization of Special Elements Used in an SQL Command (SQL Injection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-89 (Improper Neutralization of Special Elements used in an SQL Command, commonly known as SQL Injection or SQLi) is consistently among the most dangerous and exploitable web application weaknesses. CWE-89 is defined as: the product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without proper removal or escaping of SQL syntax in user inputs, attackers can interpret their data as executable commands rather than benign information. Common Consequences include unauthorized code execution (adversaries could execute system commands, typically by changing the SQL statement to redirect output to a file that can then be executed), data confidentiality loss (since SQL databases generally hold sensitive data, loss of confidentiality is a frequent problem with SQL injection vulnerabilities), authentication bypass (attackers may connect as other users without password knowledge), access control circumvention (authorization data stored in databases can be modified), and data integrity compromise (information can be modified or deleted through successful exploitation). The Potential Mitigations are well-established: parameterized queries (process SQL queries using prepared statements, parameterized queries, or stored procedures that enforce separation between code and data); least privilege (run code with minimal required permissions; database users should have only necessary privileges); input validation (use an accept-known-good input validation strategy with strict allowlists conforming to specifications); and output encoding (escape special characters; apply conservative character filtering beyond alphanumerics). Parameterized queries are the gold-standard mitigation because they enforce a strict separation between SQL code and user-supplied data at the protocol level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-top-25-2024-most-dangerous-weaknesses"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-cwe-918-server-side-request-forgery",
    "title": "MITRE CWE-918 - Server-Side Request Forgery (SSRF)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "CWE-918 (Server-Side Request Forgery, commonly known as SSRF) is a CWE Top 25 weakness that has become particularly dangerous in cloud environments where it can be exploited to access metadata services, internal-only APIs, and lateral cloud resources (Capital One 2019 breach was an SSRF exploit reaching AWS IMDSv1). CWE-918 is defined as: the web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. Common Consequences include confidentiality impact (attackers can read application data by accessing unexpected hosts or ports); integrity impact (unauthorized code or commands may be executed through the forged requests); and access control bypass (by providing URLs to unexpected destinations, attackers can circumvent firewalls and access controls that would normally prevent direct access; the server becomes a proxy for conducting port scanning of internal networks, accessing local file systems via file:// protocols, or using alternative protocols like gopher:// or tftp:// that may provide greater request control). Potential Mitigations demonstrated by the CWE-918 example include validating URLs against an allowlist of permitted destinations, escaping output for safety, and implementing proper error handling rather than exposing system details to users. Modern SSRF mitigations include strict URL allowlisting; DNS rebinding protection (validate the resolved IP and not just the hostname; resolve once and use the resolved IP for the request); network segmentation (egress filtering blocking traffic to RFC 1918 ranges, link-local 169.254.0.0/16, and cloud metadata IPs); IMDSv2 enforcement on AWS (PUT-based session tokens prevent SSRF reaching IMDS); Workload Identity on GCP and Azure Managed Identity bound to the workload; service mesh policies; and least-privilege egress.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-352-cross-site-request-forgery"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "mitre-cwe-94-code-injection",
    "title": "MITRE CWE-94 - Improper Control of Generation of Code (Code Injection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "CWE-94 (Improper Control of Generation of Code, commonly known as Code Injection) is a CWE Top 25 weakness covering server-side template injection, eval injection, expression language injection, and dynamic code generation vulnerabilities. CWE-94 is defined as: the product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment. Common Consequences include bypass protection mechanism with access control scope (injectable code may control authentication, potentially leading to remote vulnerabilities); gain privileges or assume identity (injected code can access resources that the attacker is directly prevented from accessing); execute unauthorized code or commands with integrity, confidentiality, and availability impact (when a product allows a user's input to contain code syntax, it might be possible for an attacker to craft the code in such a way that it will alter the intended control flow of the product); and hide activities (often the actions performed by injected control code are unlogged). Potential Mitigations include refactoring (eliminate dynamic code generation where possible); sandboxing (execute code in restricted environments using tools like chroot jails or AppArmor to limit operating system access); input validation (apply strict accept-known-good allowlists that limit acceptable constructs, particularly for function invocations); taint propagation (employ runtime systems that flag and prevent execution of tainted variables, e.g., Perl's -T switch); and alternative functions (replace dangerous functions like eval() with safer alternatives such as Python's ast.literal_eval() where feasible). CWE-94 is the parent for CWE-95 (Eval Injection), CWE-96 (Static Code Injection), CWE-913 (Improper Control of Dynamically-Managed Code Resources), and template injection variants.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-cwe-78-os-command-injection"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "mitre-cwe-top-25-2024-most-dangerous-weaknesses",
    "title": "MITRE CWE Top 25 Most Dangerous Software Weaknesses 2024 (CWE-79 XSS, CWE-787 Out-of-bounds Write, CWE-89 SQL Injection, CWE-352 CSRF, CWE-22 Path Traversal, CWE-125, CWE-78, CWE-416, CWE-862)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "The 2024 CWE Top 25 Most Dangerous Software Weaknesses, published by The MITRE Corporation's CWE program at cwe.mitre.org/top25/archive/2024/, is the ranked annual list of the most severe and prevalent software weaknesses derived from analysis of 31,770 CVE records in the 2024 dataset. The list is generated using a published methodology that scores CWEs by frequency and severity (KEV-weighted impact). The 2024 ranking is: 1 CWE-79 (XSS), 2 CWE-787 (Out-of-bounds Write), 3 CWE-89 (SQL Injection), 4 CWE-352 (CSRF), 5 CWE-22 (Path Traversal), 6 CWE-125 (Out-of-bounds Read), 7 CWE-78 (OS Command Injection), 8 CWE-416 (Use After Free), 9 CWE-862 (Missing Authorization), 10 CWE-434 (Unrestricted Upload of File with Dangerous Type), 11 CWE-94 (Code Injection), 12 CWE-20 (Improper Input Validation), 13 CWE-77 (Command Injection), 14 CWE-287 (Improper Authentication), 15 CWE-269 (Improper Privilege Management), 16 CWE-502 (Deserialization of Untrusted Data), 17 CWE-200 (Exposure of Sensitive Information), 18 CWE-863 (Incorrect Authorization), 19 CWE-918 (SSRF), 20 CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), 21 CWE-476 (NULL Pointer Dereference), 22 CWE-798 (Use of Hard-coded Credentials), 23 CWE-190 (Integer Overflow), 24 CWE-400 (Uncontrolled Resource Consumption), 25 CWE-306 (Missing Authentication for Critical Function). The CWE Top 25 is the canonical reference used by application security programs, secure SDLC requirements, the OWASP Top 10 cross-walk, the PCI Software Security Framework, and federal software-supply-chain policy (NIST SSDF, EO 14028, Memo M-22-18) to prioritise remediation and secure-coding training.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ranking_basis",
        "key_institutions",
        "top_5_weaknesses",
        "ranks_6_through_10",
        "ranks_11_through_15",
        "ranks_16_through_20",
        "ranks_21_through_25",
        "methodology_kev_weighted",
        "cross_walks_to_owasp_pci_nist_eo14028",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-csf-2",
      "us-cisa-kev-catalog",
      "oasis-stix-2-1-structured-threat-information",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-aa-agent-authentication",
    "title": "MITRE D3FEND D3-AA: Agent Authentication (Defensive Tactic - Harden -> Agent Authentication)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-AA (Agent Authentication) is a Harden defensive technique. Agent authentication is the process of verifying the identities of agents to ensure they are authorized and trustworthy participants within a system. In the D3FEND model it authenticates the agent; strengthens the user account. It counters ATT&CK techniques T1078, T1078.001, T1078.002, T1078.003, T1078.004, T1087.001, T1087.002, T1087.004, T1098, T1098.002, and 7 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1078-001-default-accounts",
      "mitre-attack-t1078-002-domain-accounts",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-abpi-application-based-process-isolation",
    "title": "MITRE D3FEND D3-ABPI: Application-based Process Isolation (Defensive Tactic - Isolate -> Application-based Process Isolation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-ABPI (Application-based Process Isolation) is a Isolate defensive technique. Application code which prevents its own subroutines from accessing intra-process / internal memory space. Some applications implement logic to permit or deny a particular subroutine access to other data within the same applicaition process. This is intended to prevent critical application process data from being tampered with. In the D3FEND model it isolates the process; restricts the subroutine. It counters ATT&CK techniques T1003.001, T1003.002, T1003.004, T1033, T1053, T1053.005, T1212, T1505.001, T1505.002, T1505.003, and 5 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-001-lsass-memory",
      "mitre-attack-t1003-002-security-account-manager",
      "mitre-attack-t1003-004-lsa-secrets",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ach-application-configuration-hardening",
    "title": "MITRE D3FEND D3-ACH: Application Configuration Hardening (Defensive Tactic - Harden -> Application Configuration Hardening)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-ACH (Application Configuration Hardening) is a defensive technique that secures application-layer settings - feature flags, security headers, session cookie attributes, CORS policies, rate limiting, error verbosity, debug endpoints - to reduce attack surface. ACH spans web applications (security headers, CSP, HSTS), mobile applications (certificate pinning, root detection, debug-build prevention), APIs (rate limiting, authentication enforcement, request validation), and SaaS application configuration (Microsoft 365 Secure Score, Salesforce Health Check, Google Workspace Security Center). Counters ATT&CK techniques T1190 (Exploit Public-Facing Application), T1539 (Steal Web Session Cookie), T1567 (Exfiltration Over Web Service), T1078 (Valid Accounts) via session hijacking. Required under NIST SP 800-53 CM-6 (Configuration Settings), SA-15 (Development Process), ISO 27001 A.8.9, OWASP ASVS, NIS2 Article 21(2)(e).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1539-steal-web-session-cookie",
      "mitre-d3fend-d3-ch-credential-hardening",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-aem-application-exception-monitoring",
    "title": "MITRE D3FEND D3-AEM: Application Exception Monitoring (Defensive Tactic - Detect -> Application Exception Monitoring)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-AEM (Application Exception Monitoring) is a Detect defensive technique. Monitoring the failures of system counters and timers. Monitoring timer and counter failures or exceedances can reveal issues with the program or platform, and is important for both safety and security. It may also help identify tampering or malicious activity affecting the device or the processes it controls. In the D3FEND model it monitors the application failure count variable; monitors the log. It counters ATT&CK techniques T1003.005, T1003.006, T1070.001, T1070.003, T1110.001, T1110.003, T1110.004, T1134.002, T1134.003, T1140, and 4 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-005-cached-domain-credentials",
      "mitre-attack-t1003-006-dcsync",
      "mitre-attack-t1685-005-clear-windows-event-logs",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ai-asset-inventory",
    "title": "MITRE D3FEND D3-AI: Asset Inventory (Defensive Tactic - Model -> Asset Inventory)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-AI (Asset Inventory) is a foundational defensive technique that enumerates and tracks digital assets (hardware, software, services, accounts, data) to enable downstream defence. Without complete asset inventory, organisations cannot harden, detect, isolate, or evict adversary activity on unknown systems. AI is the precondition for every other defensive tactic and is required under NIST SP 800-53 CM-8 (Information System Component Inventory), ISO 27001 A.5.9 (Inventory of information and other associated assets), CIS Critical Security Controls v8 Control 1 (Inventory and Control of Enterprise Assets) and Control 2 (Inventory and Control of Software Assets), PCI DSS v4.0 Req 12.5.1, NIS2 Article 21(2)(a), and DORA Article 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-al-account-locking",
    "title": "MITRE D3FEND D3-AL: Account Locking (Defensive Tactic - Harden -> Credential Hardening)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-AL (Account Locking) is a defensive technique that disables identity accounts after a configured number of failed authentication attempts to defeat brute force, password spray, and credential stuffing. AL counters ATT&CK techniques T1110 (Brute Force), T1078 (Valid Accounts), T1556 (Modify Authentication Process), and T1212 (Exploitation for Credential Access). Required under NIST SP 800-53 AC-7 (Unsuccessful Logon Attempts), PCI DSS v4.0 Req 8.3.4 (lockout after maximum 10 attempts), ISO 27001 A.5.16, HIPAA Security Rule 164.308(a)(5)(ii)(D), and NIST SP 800-63B.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1110-brute-force",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-am-access-modeling",
    "title": "MITRE D3FEND D3-AM: Access Modeling (Defensive Tactic - Model -> Access Modeling)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-AM (Access Modeling) is a Model defensive technique. Access modeling captures and records the access permissions granted to identities (e.g., administrators, users, groups, systems) and optionally includes details on how these identities are stored, managed, and shared across systems. In the D3FEND model it maps the access control configuration; maps the digital identity; maps the user account. It counters ATT&CK techniques T1078, T1078.001, T1078.002, T1078.003, T1078.004, T1087.001, T1087.002, T1087.004, T1098, T1098.002, and 14 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1078-001-default-accounts",
      "mitre-attack-t1078-002-domain-accounts",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-anaa-administrative-network-activity-analysis",
    "title": "MITRE D3FEND D3-ANAA: Administrative Network Activity Analysis (Defensive Tactic - Detect -> Administrative Network Activity Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-ANAA (Administrative Network Activity Analysis) is a Detect defensive technique. Detection of unauthorized use of administrative network protocols by analyzing network activity against a baseline. Network protocols such as RDP, IPMI, SSH, SNMP, VNC, MOSH, NX, TeamViewer, SPICE, PCoIP, and others are used by system administrators to remotely manage servers. Defenders monitor administrative network activity to determine if the use of remote protocols is malicious. Attackers can abuse administrative protocols and leverage them for initial access to various endpoints. In the D3FEND model it analyzes the intranet administrative network traffic. It counters ATT&CK techniques T1003.006, T1047, T1098.001, T1110.003, T1110.004, T1207, T1546.003, T1546.008. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-006-dcsync",
      "mitre-attack-t1047-windows-management-instrumentation",
      "mitre-attack-t1098-001-additional-cloud-credentials",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-anci-authentication-cache-invalidation",
    "title": "MITRE D3FEND D3-ANCI: Authentication Cache Invalidation (Defensive Tactic - Evict → Credential Eviction)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE D3FEND D3-ANCI (Authentication Cache Invalidation) is a defensive technique that revokes cached credentials and active sessions to force renewed authentication. ANCI counters ATT&CK techniques T1078 (Valid Accounts), T1098 (Account Manipulation), T1550 (Use Alternate Authentication Material), T1539 (Steal Web Session Cookie), and T1621 (MFA Request Generation). Continuous Access Evaluation (CAE) and session revocation are required under NIST SP 800-53 AC-12, ISO 27001 A.5.18, and CISA Zero Trust Maturity Model Stage 3 (Optimal).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1098-account-manipulation",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-apca-application-protocol-command-analysis",
    "title": "MITRE D3FEND D3-APCA: Application Protocol Command Analysis (Defensive Tactic - Detect -> Application Protocol Command Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-APCA (Application Protocol Command Analysis) is a Detect defensive technique. Analyzing application protocol level remote commands to detect unauthorized activity. This technique requires the ability to parse application layer protocols to understand the commands being sent to a remote service. Signature-based or statistical analysis may be employed to identify unauthorized commands being sent. These commands can be observed by monitoring network traffic or application logs. In the D3FEND model it monitors the network traffic. It counters ATT&CK techniques T1001, T1003.006, T1008, T1011, T1018, T1020, T1021, T1021.001, T1021.004, T1029, and 62 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-8, AC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1001-data-obfuscation",
      "mitre-attack-t1003-006-dcsync",
      "mitre-attack-t1008-fallback-channels",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ave-asset-vulnerability-enumeration",
    "title": "MITRE D3FEND D3-AVE: Asset Vulnerability Enumeration (Defensive Tactic - Model -> Asset Vulnerability Enumeration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-AVE (Asset Vulnerability Enumeration) is a Model defensive technique. Asset vulnerability enumeration enriches inventory items with knowledge identifying their vulnerabilities. In the D3FEND model it evaluates the physical artifact; evaluates the software; identifies the vulnerability. It counters ATT&CK techniques T1014, T1056.003, T1072, T1127.001, T1137.006, T1176, T1195.001, T1195.002, T1212, T1218.014, and 15 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-10, AC-12, AC-16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1014-rootkit",
      "mitre-attack-t1056-003-web-portal-capture",
      "mitre-attack-t1072-software-deployment-tools",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ba-bootloader-authentication",
    "title": "MITRE D3FEND D3-BA: Bootloader Authentication (Defensive Tactic - Harden -> Bootloader Authentication)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-BA (Bootloader Authentication) is a Harden defensive technique. Cryptographically authenticating the bootloader software before system boot. In the D3FEND model it authenticates the boot loader. It counters ATT&CK technique T1542.003. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-3, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1542-003-bootkit",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ca-certificate-analysis",
    "title": "MITRE D3FEND D3-CA: Certificate Analysis (Defensive Tactic - Detect -> Certificate Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-CA (Certificate Analysis) is a Detect defensive technique. Analyzing Public Key Infrastructure certificates to detect if they have been misconfigured or spoofed using both network traffic, certificate fields and third-party logs. Certificate Analysis ensures that the data elements of the certificate are current and anchored in a known trust model. Certificate authorities, revocation lists, and third-party secure logs are used in the analysis. Analysis includes detection of server impersonation, phishing domains, and forged certificates. TLS certificates are designed to expire to ensure that the cryptographic keys are forced to be changed on a regular basis. In the D3FEND model it analyzes the certificate file. It counters ATT&CK techniques T1041, T1048.002, T1071, T1071.001, T1573.002, T1649. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-6, AC-16, AC-20, AC-23, CA-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1041-exfiltration-over-c2-channel",
      "mitre-attack-t1048-002-exfiltration-over-asymmetric-encrypted-non-c2-protocol",
      "mitre-attack-t1071-application-layer-protocol",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-caa-connection-attempt-analysis",
    "title": "MITRE D3FEND D3-CAA: Connection Attempt Analysis (Defensive Tactic - Detect -> Connection Attempt Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-CAA (Connection Attempt Analysis) is a Detect defensive technique. Analyzing failed connections in a network to detect unauthorized activity. Connection Attempt Analysis in multiple ways. In the D3FEND model it analyzes the intranet network traffic. It counters ATT&CK techniques T1003.006, T1021, T1047, T1090.001, T1098.001, T1110.003, T1110.004, T1197, T1199, T1207, and 5 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-8, AC-16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-006-dcsync",
      "mitre-attack-t1021-remote-services",
      "mitre-attack-t1047-windows-management-instrumentation",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-cba-certificate-based-authentication",
    "title": "MITRE D3FEND D3-CBA: Certificate-based Authentication (Defensive Tactic - Harden -> Certificate-based Authentication)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE D3FEND D3-CBA (Certificate-based Authentication) is a Harden defensive technique. In the D3FEND model it reads Certificate. It is part of the Agent Authentication D3FEND parent category and counters ATT&CK techniques T1649. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls in the AC, IA, AU, CM, SI, SC, SA families.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ccsa-credential-compromise-scope-analysis",
    "title": "MITRE D3FEND D3-CCSA: Credential Compromise Scope Analysis (Defensive Tactic - Detect -> Credential Compromise Scope Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-CCSA (Credential Compromise Scope Analysis) is a Detect defensive technique. Determining which credentials may have been compromised by analyzing the user logon history of a particular system. Memory Credentials may be stored in memory for a variety of reasons; on Windows, they may be stored in lsass.exe. Once a credential dumper like mimikatz runs and dumps the memory of lsass.exe, the credentials of every account logged on since boot are potentially compromised. When such an event occurs, this analytic will give the forensic context to identify compromised users. Those users could potentially be used in later events for additional logons. In the D3FEND model it analyzes the credential. It counters ATT&CK techniques T1003.003, T1003.005, T1003.008, T1098.001, T1110.001, T1110.002, T1110.003, T1134.001, T1134.002, T1134.003, and 10 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-10, AC-16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-003-ntds",
      "mitre-attack-t1003-005-cached-domain-credentials",
      "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-cdp-change-default-password",
    "title": "MITRE D3FEND D3-CDP: Change Default Password (Defensive Tactic - Harden -> Change Default Password)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-CDP (Change Default Password) is a Harden defensive technique. Changing the default password means replacing the factory-set credentials with a strong, unique password before the device is deployed, preventing unauthorized access. Change the default password as soon as a new device is received. The default credentials are normally documented in an instruction manual that is either packaged with the device, published online through official means, or published online through unofficial means. In the D3FEND model it hardens the ot controller; strengthens the password; strengthens the user account. It counters ATT&CK techniques T1078, T1078.001, T1078.002, T1078.003, T1078.004, T1087.001, T1087.002, T1087.004, T1098, T1098.002, and 10 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1078-001-default-accounts",
      "mitre-attack-t1078-002-domain-accounts",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ce-credential-eviction",
    "title": "MITRE D3FEND D3-CE: Credential Eviction (Defensive Tactic - Evict)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-CE (Credential Eviction) is a defensive technique that disables or removes compromised credentials from a computer network. Distinct from D3-CRO Credential Rotation (CE removes; CRO replaces). Counters ATT&CK T1078 (Valid Accounts) all sub-techniques, T1098 (Account Manipulation), T1134 (Access Token Manipulation), T1550 (Use Alternate Authentication Material). Required under NIST SP 800-53 IA-5 + AC-2, ISO 27001 A.5.16/A.5.18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1098-account-manipulation",
      "mitre-d3fend-d3-anci-authentication-cache-invalidation",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-cero-certificate-rotation",
    "title": "MITRE D3FEND D3-CERO: Certificate Rotation (Defensive Tactic - Harden -> Certificate Rotation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-CERO (Certificate Rotation) is a Harden defensive technique. Certificate rotation involves replacing digital certificates and their private keys to maintain cryptographic integrity and trust, mitigating key compromise risks and ensuring continuous secure communications. Certificate rotation should be performed when: - Any certificate expires. - A new CA authority is substituted for the old, thus requiring a replacement root certificate. - New or modified constraints need to be imposed on one or more certificates. - A security breach has occurred. Considerations: - Managing certificate rotation across an enterprise can be complex. In the D3FEND model it regenerates the certificate. It counters ATT&CK technique T1649. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls IA-2, IA-5, IA-13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1649-steal-or-forge-authentication-certificates",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-cf-content-filtering",
    "title": "MITRE D3FEND D3-CF: Content Filtering (Defensive Tactic - Isolate -> Content Filtering)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-CF (Content Filtering) is a Isolate defensive technique. Content Filtering techniques aid in the process of analyzing an input file for malicious or erroneous content and outputing a sanitized version. In the D3FEND model it filters the file; enforces the content policy. It counters ATT&CK techniques T1003.007, T1003.008, T1005, T1014, T1016, T1018, T1027.001, T1027.002, T1027.004, T1033, and 89 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-10, AC-12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-007-proc-filesystem",
      "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
      "mitre-attack-t1005-data-from-local-system",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ch-credential-hardening",
    "title": "MITRE D3FEND D3-CH: Credential Hardening (Defensive Tactic - Harden -> Credential Hardening)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-CH (Credential Hardening) is the foundational Harden-tactic technique that strengthens user, service, and machine credentials against theft, brute-force, replay, and unauthorised use. CH encompasses MFA enforcement, strong password policy, credential rotation, secrets management, just-in-time access, phishing-resistant authentication (FIDO2/WebAuthn), and elimination of static long-lived credentials. CH counters ATT&CK techniques T1110 (Brute Force), T1078 (Valid Accounts), T1556 (Modify Authentication Process), T1539 (Steal Web Session Cookie), T1212 (Exploitation for Credential Access), T1003 (OS Credential Dumping). Required under NIST SP 800-53 IA-2 (Identification and Authentication), IA-5 (Authenticator Management), PCI DSS v4.0 Req 8, NIS2 Article 21(2)(j), DORA Article 9, HIPAA Security Rule 164.308(a)(5)(ii)(D), and CISA Phishing-Resistant MFA guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1110-brute-force",
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1539-steal-web-session-cookie",
      "mitre-d3fend-d3-mfa-multi-factor-authentication",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-ci-configuration-inventory",
    "title": "MITRE D3FEND D3-CI: Configuration Inventory (Defensive Tactic - Model -> Configuration Inventory)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE D3FEND D3-CI (Configuration Inventory) is a Model defensive technique. In the D3FEND model it inventories Configuration Resource. It is part of the Asset Inventory D3FEND parent category and counters ATT&CK techniques T1548.002, T1547.003, T1548.001, T1134.005, T1548.005, T1037.005, T1546.002, T1546.007, T1547.002, T1546.010, T1574.012, T1546.001, and 41 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls in the AC, IA, AU, CM, SI, SC, SA families.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-d3fend-d3-cia-container-image-analysis",
    "title": "MITRE D3FEND D3-CIA: Container Image Analysis (Defensive Tactic - Model -> Container Image Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-CIA (Container Image Analysis) is a Model defensive technique. Analyzing a Container Image with respect to a set of policies. Container images are standalone collections of the executable code and content that are used to populate a container environment. They are usually created by either building a container from scratch or by building on top of an existing image pulled from a repository. Throughout the container build workflow, images should be scanned to identify: - outdated libraries, - known vulnerabilities, - or misconfigurations, such as insecure ports or permissions. In the D3FEND model it analyzes the container image. It counters ATT&CK technique T1525. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CM-2, CM-5, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1525-implant-internal-image",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-cm-content-modification",
    "title": "MITRE D3FEND D3-CM: Content Modification (Defensive Tactic - Isolate -> Content Modification)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-CM (Content Modification) is a Isolate defensive technique. Modify content that does not comply with policy. When content is found to not comply with it's content policy, it may be transformed to a safer state by modifying it. In the D3FEND model it filters the digital media; filters the file content block; filters the file metadata; modifies the file. It counters ATT&CK techniques T1003.007, T1003.008, T1005, T1014, T1016, T1018, T1027.001, T1027.002, T1027.004, T1033, and 89 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-10, AC-12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-007-proc-filesystem",
      "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
      "mitre-attack-t1005-data-from-local-system",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-cp-certificate-pinning",
    "title": "MITRE D3FEND D3-CP: Certificate Pinning (Defensive Tactic - Harden)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-CP (Certificate Pinning) is a defensive technique that persists a server X.509 certificate or public key and compares against the server presented identity to allow greater client confidence in remote server identity for SSL/TLS connections. Counters certificate substitution, AiTM, certificate authority compromise, forged authentication certificates. Counters ATT&CK T1557 (Adversary-in-the-Middle), T1649 (Steal or Forge Authentication Certificates). Required for mobile and IoT clients per OWASP MASVS V5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1573-encrypted-channel",
      "mitre-capec-capec-94-adversary-in-the-middle",
      "mitre-d3fend-d3-mencr-message-encryption",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-cq-content-quarantine",
    "title": "MITRE D3FEND D3-CQ: Content Quarantine (Defensive Tactic - Isolate -> Content Quarantine)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-CQ (Content Quarantine) is a Isolate defensive technique. Transfer content that does not comply with policy to a quarantine zone. Quarantining serves as a protective measure to isolate potentially harmful files or elements until they can be safely analyzed or processed. In the D3FEND model it quarantines the database record; quarantines the file. It counters ATT&CK techniques T1003.007, T1003.008, T1005, T1014, T1016, T1018, T1027.001, T1027.002, T1027.004, T1033, and 102 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-10, AC-12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-007-proc-filesystem",
      "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
      "mitre-attack-t1005-data-from-local-system",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-cr-credential-revocation",
    "title": "MITRE D3FEND D3-CR: Credential Revocation (Defensive Tactic - Evict -> Credential Revocation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-CR (Credential Revocation) is a Evict defensive technique. Deleting a set of credentials permanently to prevent them from being used to authenticate. Management servers with enterprise policies for account management provide the ability remove permissions, accounts, or credentials. Compromised credentials should be revoked to prevent further malicious activity. In the D3FEND model it deletes the credential. It counters ATT&CK techniques T1003.003, T1003.005, T1003.008, T1098.001, T1110.001, T1110.002, T1110.003, T1134.001, T1134.002, T1134.003, and 10 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-10, AC-16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-003-ntds",
      "mitre-attack-t1003-005-cached-domain-credentials",
      "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-cro-credential-rotation",
    "title": "MITRE D3FEND D3-CRO: Credential Rotation (Defensive Tactic - Evict)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-CRO (Credential Rotation) is a defensive technique that regularly changes or replaces authentication credentials (passwords, API keys, certificates) to minimise risk of unauthorised access. Counters ATT&CK T1110 (Brute Force), T1003 (OS Credential Dumping), T1078 (Valid Accounts), T1550 (Use Alternate Authentication Material), T1134 (Access Token Manipulation), T1528 (Steal Application Access Token). Required under NIST SP 800-53 IA-5, ISO 27001 A.5.17, PCI DSS Req 8, NIST SP 800-63B.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1110-brute-force",
      "mitre-attack-t1003-os-credential-dumping",
      "mitre-d3fend-d3-ch-credential-hardening",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-cs-credential-scrubbing",
    "title": "MITRE D3FEND D3-CS: Credential Scrubbing (Defensive Tactic - Harden -> Credential Scrubbing)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-CS (Credential Scrubbing) is a Harden defensive technique. The systematic removal of hard-coded credentials from source code to prevent accidental exposure and unauthorized access. Credential Scrubbing involves identifying and eliminating hard-coded credentials such as usernames, passwords, API keys, and tokens from source code repositories. These credentials should be managed securely using environment variables, secret management tools, or secure vaults where they can be safely accessed when needed. In the D3FEND model it hardens the subroutine. It counters ATT&CK technique T1505.001. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1505-001-sql-stored-procedures",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-cspp-client-server-payload-profiling",
    "title": "MITRE D3FEND D3-CSPP: Client-server Payload Profiling (Defensive Tactic - Detect -> Client-server Payload Profiling)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-CSPP (Client-server Payload Profiling) is a Detect defensive technique. Comparing client-server request and response payloads to a baseline profile to identify outliers. Profiling request and response payloads across multiple clients to a single server to develop a baseline of their characteristics. May take into account request/response sizes, entropy, frequency, and rhythm. Finally, identify outliers as they may indicate a malicious payload delivery and subsequent server exploitation. In the D3FEND model it analyzes the network traffic. It counters ATT&CK techniques T1001, T1003.006, T1008, T1011, T1018, T1020, T1021, T1021.001, T1021.004, T1029, and 62 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-8, AC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1001-data-obfuscation",
      "mitre-attack-t1003-006-dcsync",
      "mitre-attack-t1008-fallback-channels",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-cts-credential-transmission-scoping",
    "title": "MITRE D3FEND D3-CTS: Credential Transmission Scoping (Defensive Tactic - Isolate -> Credential Transmission Scoping)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-CTS (Credential Transmission Scoping) is a Isolate defensive technique. Limiting the transmission of a credential to a scoped set of relying parties. In the D3FEND model it isolates the credential. It counters ATT&CK techniques T1003.003, T1003.005, T1003.008, T1098.001, T1110.001, T1110.002, T1110.003, T1134.001, T1134.002, T1134.003, and 10 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-10, AC-16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-003-ntds",
      "mitre-attack-t1003-005-cached-domain-credentials",
      "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-da-dynamic-analysis",
    "title": "MITRE D3FEND D3-DA: Dynamic Analysis (Defensive Tactic - Detect -> Dynamic Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-DA (Dynamic Analysis) is a Detect defensive technique. Executing or opening a file in a synthetic \"sandbox\" environment to determine if the file is a malicious program or if the file exploits another program such as a document reader. Analyzing the interaction of a piece of code with a system while the code is being executed in a controlled environment such as a sandbox, virtual machine, or simulator. This exposes the natural behavior of the piece of code without requiring the code to be disassembled. In the D3FEND model it analyzes the document file; analyzes the executable file. It counters ATT&CK techniques T1016, T1027.001, T1027.002, T1027.004, T1036.001, T1036.003, T1037.001, T1037.002, T1037.003, T1037.004, and 28 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-10, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1016-system-network-configuration-discovery",
      "mitre-attack-t1027-001-binary-padding",
      "mitre-attack-t1027-002-software-packing",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-dam-domain-account-monitoring",
    "title": "MITRE D3FEND D3-DAM: Domain Account Monitoring (Defensive Tactic - Detect -> Domain Account Monitoring)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-DAM (Domain Account Monitoring) is a Detect defensive technique. Monitoring the existence of or changes to Domain User Accounts. In the D3FEND model it monitors the domain user account. It counters ATT&CK techniques T1078.002, T1087.002, T1098.002, T1098.003, T1136.002. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-20, CA-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-002-domain-accounts",
      "mitre-attack-t1087-002-domain-account",
      "mitre-attack-t1098-002-additional-email-delegate-permissions",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-de-decoy-environment",
    "title": "MITRE D3FEND D3-DE: Decoy Environment (Defensive Tactic - Deceive -> Decoy Environment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-DE (Decoy Environment) is a defensive technique that deploys realistic but fake systems, networks, or cloud environments to attract adversary engagement, generate threat intelligence, and detect lateral movement. Modern implementations span on-premise honeypots (HoneyD, T-Pot, OpenCanary), high-interaction honeynets (MHN, Modern Honey Network), cloud-native deception (Thinkst Canary appliances, Acalvio ShadowPlex, Illusive Networks, Microsoft Defender Honey Tokens), and full deception platforms. Required as deception layer under NIST SP 800-53 SC-26 (Decoys), SC-30 (Concealment and Misdirection), ISO 27001 A.5.7, and MITRE Engage adversary engagement framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1078-valid-accounts",
      "mitre-d3fend-d3-df-decoy-file",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-dencr-disk-encryption",
    "title": "MITRE D3FEND D3-DENCR: Disk Encryption (Defensive Tactic - Harden -> Platform Hardening)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE D3FEND D3-DENCR (Disk Encryption) is a defensive technique that protects data at rest by encrypting block-level storage volumes. DENCR counters ATT&CK techniques T1486 (Data Encrypted for Impact - prevents extortion leverage from offline storage seizure), T1565 (Data Manipulation), T1052 (Exfiltration Over Physical Medium), T1025 (Data from Removable Media), and T1530 (Data from Cloud Storage Object). Full-disk encryption is mandated under HIPAA Security Rule 164.312(a)(2)(iv), GDPR Article 32, PCI DSS Req 3.5.1, NIST SP 800-53 SC-28, ISO 27001 A.8.24, and US state breach safe-harbour provisions (CCPA, Texas, Massachusetts) that exempt encrypted-data losses from notification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1486-data-encrypted-for-impact",
      "mitre-attack-t1005-data-from-local-system",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "gdpr-article-32-security-of-processing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-df-decoy-file",
    "title": "MITRE D3FEND D3-DF: Decoy File (Defensive Tactic - Deceive -> Decoy Object)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-DF (Decoy File) is a defensive technique that places enticing fake files (canary tokens, decoy documents, fake credential stores, fake backup archives, fake source code) in locations where legitimate users would not access them, generating high-fidelity alerts on adversary interaction. Decoy files are a low-false-positive complement to behavioural detection. DF counters ATT&CK techniques T1005 (Data from Local System), T1083 (File and Directory Discovery), T1213 (Data from Information Repositories), T1530 (Data from Cloud Storage), T1486 (Data Encrypted for Impact). Required as deception layer under NIST SP 800-53 SC-26 (Decoys), SC-30 (Concealment and Misdirection), ISO 27001 A.5.7 (Threat intelligence) - deception complement, and CISA #StopRansomware Guide.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1005-data-from-local-system",
      "mitre-attack-t1486-data-encrypted-for-impact",
      "mitre-d3fend-d3-duc-decoy-user-credential",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-di-data-inventory",
    "title": "MITRE D3FEND D3-DI: Data Inventory (Defensive Tactic - Model -> Data Inventory)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-DI (Data Inventory) is a defensive technique that enumerates and tracks data assets - structured databases, unstructured file shares, SaaS data, regulated personal data, secrets, and intellectual property - to enable risk-aligned protection and breach scope determination. Without complete data inventory, organisations cannot apply GDPR Article 30 records of processing, scope ransomware impact, or determine breach notification obligations. DI is required under NIST SP 800-53 PM-5 (System Inventory), CM-12 (Information Location), ISO 27001 A.5.9 and A.5.12 (Information classification), GDPR Article 30, CCPA/CPRA, NIS2 Article 21(2)(h), and DORA Article 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1005-data-from-local-system",
      "mitre-attack-t1486-data-encrypted-for-impact",
      "gdpr-article-32-security-of-processing",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-dke-disk-erasure",
    "title": "MITRE D3FEND D3-DKE: Disk Erasure (Defensive Tactic - Evict -> Disk Erasure)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-DKE (Disk Erasure) is a Evict defensive technique. Disk Erasure is the process of securely deleting all data on a disk to ensure that it cannot be recovered by any means. Disk Erasure involves overwriting the existing data with random or specific patterns multiple times. Disk erasure is crucial for data sanitization, ensuring that sensitive information is completely removed from storage devices before they are repurposed, disposed of, or transferred to another party. In the D3FEND model it erases the secondary storage. It counters ATT&CK technique T1619. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CM-5, IA-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1619-cloud-storage-object-discovery",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-dkf-disk-formatting",
    "title": "MITRE D3FEND D3-DKF: Disk Formatting (Defensive Tactic - Evict -> Disk Formatting)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-DKF (Disk Formatting) is a Evict defensive technique. Disk Formatting is the process of preparing a data storage device, such as a hard drive, solid-state drive, or USB flash drive, for initial use. This process involves setting up an empty file system on the disk, which includes creating a directory structure and initializing metadata structures. In cybersecurity, disk formatting can be used to remove all existing data on a disk, making it a clean slate for new data storage or to prevent unauthorized access to previously stored data. In the D3FEND model it modifies the secondary storage. It counters ATT&CK technique T1619. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CM-5, IA-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1619-cloud-storage-object-discovery",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-dlv-domain-logic-validation",
    "title": "MITRE D3FEND D3-DLV: Domain Logic Validation (Defensive Tactic - Harden -> Domain Logic Validation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-DLV (Domain Logic Validation) is a Harden defensive technique. Validation of variable state in the context of the domain application. Validates the type, value, and/or range of an variable taking into context the current application in the business domain. In the D3FEND model it validates the subroutine. It counters ATT&CK technique T1505.001. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1505-001-sql-stored-procedures",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-dnr-decoy-network-resource",
    "title": "MITRE D3FEND D3-DNR: Decoy Network Resource (Defensive Tactic - Deceive -> Decoy Network Resource)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-DNR (Decoy Network Resource) is a defensive technique that creates fake network services (decoy DNS records, fake SSH/RDP/SMB shares, decoy web services, decoy directory listings) to detect adversary scanning, enumeration, and lateral movement attempts. DNR targets specifically the adversary discovery phase, generating high-fidelity alerts when attackers probe non-existent resources. DNR counters ATT&CK techniques T1018 (Remote System Discovery), T1046 (Network Service Discovery), T1135 (Network Share Discovery), T1021 (Remote Services), T1133 (External Remote Services). Required as deception layer under NIST SP 800-53 SC-26 (Decoys) and SC-30 (Concealment and Misdirection).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1595-active-scanning",
      "mitre-d3fend-d3-de-decoy-environment",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-dnsal-dns-allowlisting",
    "title": "MITRE D3FEND D3-DNSAL: DNS Allowlisting (Defensive Tactic - Isolate -> DNS Allowlisting)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-DNSAL (DNS Allowlisting) is a Isolate defensive technique. Permitting only approved domains and their subdomains to be resolved. In the D3FEND model it blocks the outbound internet dns lookup traffic. It counters ATT&CK techniques T1071.004, T1568. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1071-004-dns",
      "mitre-attack-t1568-dynamic-resolution",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-dnsdl-dns-denylisting",
    "title": "MITRE D3FEND D3-DNSDL: DNS Denylisting (Defensive Tactic - Detect/Isolate -> Network Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-DNSDL (DNS Denylisting) is a defensive technique that blocks DNS resolution of known-malicious domains to prevent C2 communication, phishing, malware distribution, and data exfiltration. DNSDL counters ATT&CK techniques T1071.004 (DNS C2), T1568 (Dynamic Resolution including DGA), T1583.001 (Acquire Infrastructure Domains), T1566.002 (Spearphishing Link), and T1041 (Exfiltration Over C2 Channel). Required under NIST SP 800-53 SC-7, SI-3 (Malicious Code Protection), ISO 27001 A.8.20, A.5.7, and CIS Critical Security Controls v8 Control 9 (Email and Web Browser Protections). CISA Protective DNS guidance recommends DNS denylisting as a foundational control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1071-application-layer-protocol",
      "mitre-attack-t1583-acquire-infrastructure",
      "mitre-attack-t1566-phishing",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-dnsta-dns-traffic-analysis",
    "title": "MITRE D3FEND D3-DNSTA: DNS Traffic Analysis (Defensive Tactic - Detect -> DNS Traffic Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-DNSTA (DNS Traffic Analysis) is a Detect defensive technique. Analysis of domain name metadata, including name and DNS records, to determine whether the domain is likely to resolve to an undesirable host. This technique can be accomplished in a number of ways. One example analytic determines whether or not a domain name was generated with an algorithm. Domain generation algorithms (DGAs) are sometimes used to create a domain name automatically that will resolve to C2 infrastructure, without directly coding the domains in question into the malicious code. In the D3FEND model it analyzes the outbound internet dns lookup traffic. It counters ATT&CK techniques T1040, T1071.004, T1568. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-18, AC-19, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1040-network-sniffing",
      "mitre-attack-t1071-004-dns",
      "mitre-attack-t1568-dynamic-resolution",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-dp-disk-partitioning",
    "title": "MITRE D3FEND D3-DP: Disk Partitioning (Defensive Tactic - Evict -> Disk Partitioning)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE D3FEND D3-DP (Disk Partitioning) is a Evict defensive technique. In the D3FEND model it creates Partition Table. It is part of the Object Eviction D3FEND parent category and counters ATT&CK techniques T1561.002, T1561.001. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls in the AC, IA, AU, CM, SI, SC, SA families.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-dqsa-database-query-string-analysis",
    "title": "MITRE D3FEND D3-DQSA: Database Query String Analysis (Defensive Tactic - Detect -> Database Query String Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-DQSA (Database Query String Analysis) is a Detect defensive technique. Analyzing database queries to detect SQL Injection. Some implementations use software hooks to intercept function calls related to database query operations. Other implementations might intercept or collect network traffic. The database query string is then extracted and analyzed with various methods, for example: Detecting specific administrative SQL commands Anomalous sequences of commands when compared to a statistical baseline. * Anomalous commands for a given user role. In the D3FEND model it analyzes the database query. It counters ATT&CK technique T1190. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-2, CA-7, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-dra-disable-remote-access",
    "title": "MITRE D3FEND D3-DRA: Disable Remote Access (Defensive Tactic - Harden -> Disable Remote Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-DRA (Disable Remote Access) is a Harden defensive technique. Limiting access to a computing device which is not required through or from a non-organization-controlled network. There are several different methods of achieving remote access restriction. This could include: time-based controls, just-in-time authorization, and deny-by-default controls. This can be done on a Windows machine by unchecking an \"allow remote assistance\" or checking the \"don't allow remote connections\" boxes; creating firewall rules to block remote access protocols; uninstalling remote access software; disabling Wi-Fi, Ethernet, Bluetooth, or other. In the D3FEND model it configures the application configuration. It counters ATT&CK techniques T1114.003, T1562.002, T1562.003, T1564.008. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1114-003-email-forwarding-rule",
      "mitre-attack-t1685-001-disable-or-modify-windows-event-log",
      "mitre-attack-t1690-prevent-command-history-logging",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-dtp-domain-trust-policy",
    "title": "MITRE D3FEND D3-DTP: Domain Trust Policy (Defensive Tactic - Isolate -> Domain Trust Policy)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-DTP (Domain Trust Policy) is a Isolate defensive technique. Restricting inter-domain trust by modifying domain configuration. In the D3FEND model it restricts the directory service; restricts the t1087.002. It counters ATT&CK technique T1033.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1033-system-owner-user-discovery",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-d3fend-d3-duc-decoy-user-credential",
    "title": "MITRE D3FEND D3-DUC: Decoy User Credential (Defensive Tactic - Deceive -> Decoy Object)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE D3FEND D3-DUC (Decoy User Credential) is a defensive technique that plants fake credentials, honey accounts, and canary tokens to detect adversary credential theft and lateral movement. DUC counters ATT&CK techniques T1003 (OS Credential Dumping), T1110 (Brute Force), T1555 (Credentials from Password Stores), T1078 (Valid Accounts), and T1552 (Unsecured Credentials). Honey credentials are recommended by NIST SP 800-53 SC-26 (Decoys), NIST SP 800-160 trustworthy systems engineering, MITRE Engage, and the CISA #StopRansomware Guide. Tools include Thinkst Canary, Microsoft Sentinel Deception, Acalvio, CounterCraft, and Fidelis Deception.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-os-credential-dumping",
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1555-credentials-from-password-stores",
      "mitre-attack-t1110-brute-force",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-eal-executable-allowlisting",
    "title": "MITRE D3FEND D3-EAL: Executable Allowlisting (Defensive Tactic - Isolate -> Executable Allowlisting)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-EAL (Executable Allowlisting) is a Isolate defensive technique. Using a digital signature to authenticate a file before opening. This technique is generic and there are numerous ways to compute and authenticate digital signatures. A digital certificate is generated from a private/public key pair issued by a certificate authority (CA). A hash of the file is encrypted using the private key. When the file is downloaded by another user, the user's system uses the public key to decrypt the hash and a new hash is created of the downloaded file. In the D3FEND model it blocks the executable file; filters the create process. It counters ATT&CK techniques T1007, T1010, T1016, T1018, T1027.001, T1027.002, T1027.004, T1033, T1036.001, T1036.003, and 41 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-10, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1007-system-service-discovery",
      "mitre-attack-t1010-application-window-discovery",
      "mitre-attack-t1016-system-network-configuration-discovery",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-edl-executable-denylisting",
    "title": "MITRE D3FEND D3-EDL: Executable Denylisting (Defensive Tactic - Isolate -> Executable Denylisting)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-EDL (Executable Denylisting) is a Isolate defensive technique. Blocking the execution of files on a host in accordance with defined application policy rules. Criteria A policy-enforcing application can register an application for denylisting based on conditions including the following: File attributes file name file path file hash file publisher, as obtained from the digital signature permissions of the file File malware scan (eg. In the D3FEND model it blocks the executable file; filters the create process. It counters ATT&CK techniques T1007, T1010, T1016, T1018, T1027.001, T1027.002, T1027.004, T1033, T1036.001, T1036.003, and 41 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-10, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1007-system-service-discovery",
      "mitre-attack-t1010-application-window-discovery",
      "mitre-attack-t1016-system-network-configuration-discovery",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ef-email-filtering",
    "title": "MITRE D3FEND D3-EF: Email Filtering (Defensive Tactic - Isolate -> Email Filtering)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-EF (Email Filtering) is a Isolate defensive technique. Filtering incoming email traffic based on specific criteria. Mail filters can be implemented to scan inbound email messages at the initial SMTP connection stage to detect and reject email containing spam and malware. This technique is distinct from d3f:EmailDeletion because it prevents an email from reaching an user's inbox. This technique can also be used for outbound email traffic. In the D3FEND model it filters the email. It counters ATT&CK techniques T1114.001, T1534, T1566.001, T1566.002. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-19, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1114-001-local-email-collection",
      "mitre-attack-t1534-internal-spearphishing",
      "mitre-attack-t1566-001-spearphishing-attachment",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-efa-emulated-file-analysis",
    "title": "MITRE D3FEND D3-EFA: Emulated File Analysis (Defensive Tactic - Detect -> Emulated File Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-EFA (Emulated File Analysis) is a Detect defensive technique. Emulating instructions in a file looking for specific patterns. In the D3FEND model it analyzes the document file; analyzes the executable file. It counters ATT&CK techniques T1016, T1027.001, T1027.002, T1027.004, T1036.001, T1036.003, T1037.001, T1037.002, T1037.003, T1037.004, and 28 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-10, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1016-system-network-configuration-discovery",
      "mitre-attack-t1027-001-binary-padding",
      "mitre-attack-t1027-002-software-packing",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ehb-endpoint-health-beacon",
    "title": "MITRE D3FEND D3-EHB: Endpoint Health Beacon (Defensive Tactic - Detect)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-EHB (Endpoint Health Beacon) is a defensive technique that monitors endpoint security status by sending periodic health-status messages; absence of response may indicate compromise. Counters ATT&CK T1114.002 (Remote Email Collection), T1505.002 (Transport Agent), T1505.003 (Web Shell), T1578 (Modify Cloud Compute Infrastructure), T1562 (Impair Defenses). Required under NIST SP 800-53 SI-4 + CA-7, ISO 27001 A.8.16, NIS2 Art 21(2)(b).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1505-server-software-component",
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-d3fend-d3-ai-asset-inventory",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-ei-execution-isolation",
    "title": "MITRE D3FEND D3-EI: Execution Isolation (Defensive Tactic - Isolate -> Execution Isolation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE D3FEND D3-EI (Execution Isolation) is a defensive technique that confines code execution to isolated boundaries (sandboxes, containers, VMs, application guard browsers, virtualization-based security) so that exploitation does not compromise the host. EI counters ATT&CK techniques T1059 (Command and Scripting Interpreter), T1068 (Exploitation for Privilege Escalation), T1190 (Exploit Public-Facing Application), T1203 (Exploitation for Client Execution), T1611 (Escape to Host - container escape), and T1574 (Hijack Execution Flow). Required under NIST SP 800-53 SC-3 (Security Function Isolation), SC-39 (Process Isolation), ISO 27001 A.8.27, and OWASP Application Security Verification Standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1059-command-and-scripting-interpreter",
      "mitre-attack-t1068-exploitation-privilege-escalation",
      "mitre-attack-t1190-exploit-public-facing-application",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-er-email-removal",
    "title": "MITRE D3FEND D3-ER: Email Removal (Defensive Tactic - Evict -> Email Removal)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-ER (Email Removal) is a Evict defensive technique. The email removal technique deletes email files from system storage. Email removal is a technique that can be used to prevent a user from executing malware or responding to phishing attempts. Security software or users themselves may detect malicious or suspicious email in a local or remote mail folder email and then employ this technique. In the D3FEND model it deletes the email. It counters ATT&CK techniques T1114.001, T1114.002, T1505.002, T1534, T1566.001, T1566.002. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1114-001-local-email-collection",
      "mitre-attack-t1114-002-remote-email-collection",
      "mitre-attack-t1505-002-transport-agent",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-fa-file-analysis",
    "title": "MITRE D3FEND D3-FA: File Analysis (Defensive Tactic - Detect -> File Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-FA (File Analysis) is a Detect defensive technique. File Analysis is an analytic process to determine a file's status. For example: virus, trojan, benign, malicious, trusted, unauthorized, sensitive, etc. Technique Overview Some techniques use file signatures or file metadata to compare against historical collections of malware. Files may also be compared against a source of ground truth such as cryptographic signatures. Examining files for potential malware using pattern matching against file contents/file behavior. Binary code may be dissembled and analyzed for predictive malware behavior, such as API call signatures. In the D3FEND model it analyzes the file. It counters ATT&CK techniques T1003.007, T1003.008, T1005, T1014, T1016, T1018, T1027.001, T1027.002, T1027.004, T1033, and 89 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-10, AC-12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-007-proc-filesystem",
      "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
      "mitre-attack-t1005-data-from-local-system",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-fba-firmware-behavior-analysis",
    "title": "MITRE D3FEND D3-FBA: Firmware Behavior Analysis (Defensive Tactic - Detect -> Firmware Behavior Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-FBA (Firmware Behavior Analysis) is a Detect defensive technique. Analyzing the behavior of embedded code in firmware and looking for anomalous behavior and suspicious activity. Firmware behavior analysis provides protections by ensuring that installed firmware has not been tampered with or modified. Firmware analysis applies to mutable firmware and immutable read-only memory (ROMs). Firmware in deployed network devices is typically not analyzed and monitored for vulnerabilities and thus is subject to potential attacks. In the D3FEND model it analyzes the firmware. It counters ATT&CK techniques T1014, T1542.001, T1542.002, T1542.004. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1014-rootkit",
      "mitre-attack-t1542-001-system-firmware",
      "mitre-attack-t1542-002-component-firmware",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-fc-file-carving",
    "title": "MITRE D3FEND D3-FC: File Carving (Defensive Tactic - Detect -> File Carving)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-FC (File Carving) is a Detect defensive technique. Identifying and extracting files from network application protocols through the use of network stream reassembly software. Protocol stream reassembly software recreates a directional byte stream by analyzing captured network packets. Once the stream is reassembled pattern matching is applied to determine if it contains a file of interest. Files of interest range from executable, archive, or document file formats. Once the file is captured, it is then processed with standard File Analysis Techniques. In the D3FEND model it analyzes the file transfer network traffic. It counters ATT&CK techniques T1071.002, T1570. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1071-002-file-transfer-protocols",
      "mitre-attack-t1570-lateral-tool-transfer",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-fca-file-creation-analysis",
    "title": "MITRE D3FEND D3-FCA: File Creation Analysis (Defensive Tactic - Detect -> File Creation Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-FCA (File Creation Analysis) is a Detect defensive technique. Analyzing the properties of file create system call invocations. In the D3FEND model it analyzes the create file. It counters ATT&CK techniques T1074.001, T1218.001. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-2, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1074-001-local-data-staging",
      "mitre-attack-t1218-001-compiled-html-file",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-fe-file-encryption",
    "title": "MITRE D3FEND D3-FE: File Encryption (Defensive Tactic - Harden -> File Encryption)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-FE (File Encryption) is a Harden defensive technique. Encrypting a file using a cryptographic key. Files are encrypted using either a single key for both encryption and decryption or separate keys. Single key encryption is symmetric encryption and using two key distinct keys is asymmetric encryption. In the D3FEND model it encrypts the file. It counters ATT&CK techniques T1003.007, T1003.008, T1005, T1014, T1016, T1018, T1027.001, T1027.002, T1027.004, T1033, and 89 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-10, AC-12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-007-proc-filesystem",
      "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
      "mitre-attack-t1005-data-from-local-system",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-femc-firmware-embedded-monitoring-code",
    "title": "MITRE D3FEND D3-FEMC: Firmware Embedded Monitoring Code (Defensive Tactic - Detect -> Firmware Embedded Monitoring Code)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-FEMC (Firmware Embedded Monitoring Code) is a Detect defensive technique. Monitoring code is injected into firmware for integrity monitoring of firmware and firmware data. Firmware in deployed network devices is typically not monitored for malicious changes. This technique provides a method to embed a software security component into the deployed firmware which provides a near real-time monitoring hook. The exception handling code, in the firmware, is typically used to expose any detected vulnerabilities. In the D3FEND model it analyzes the firmware. It counters ATT&CK techniques T1014, T1542.001, T1542.002, T1542.004. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1014-rootkit",
      "mitre-attack-t1542-001-system-firmware",
      "mitre-attack-t1542-002-component-firmware",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-fev-file-eviction",
    "title": "MITRE D3FEND D3-FEV: File Eviction (Defensive Tactic - Evict -> File Eviction)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-FEV (File Eviction) is a Evict defensive technique. File eviction techniques delete files from system storage. Adversaries may place files or programs into a computer's file system to perform malicious actions. As part of the eviction process, these files and programs should be removed to prevent further compromise or reinfection. Examples of malicious types of files are malware which is directly harmful and content files with the intent to deceive users (e.g., phishing.) On Windows systems, antivirus (AV) software should be used to safely and permanently remove. In the D3FEND model it deletes the file. It counters ATT&CK techniques T1003.007, T1003.008, T1005, T1014, T1016, T1018, T1027.001, T1027.002, T1027.004, T1033, and 89 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-10, AC-12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-007-proc-filesystem",
      "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
      "mitre-attack-t1005-data-from-local-system",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ffv-file-format-verification",
    "title": "MITRE D3FEND D3-FFV: File Format Verification (Defensive Tactic - Isolate -> File Format Verification)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-FFV (File Format Verification) is a Isolate defensive technique. Verifying that a file conforms to its expected format specifications In the D3FEND model it analyzes the file section. It counters ATT&CK technique T1564.009. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls CM-2, CM-6, CM-7, CM-11, SA-10, SC-4, SC-6, SC-44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1564-009-resource-forking",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-fh-file-hashing",
    "title": "MITRE D3FEND D3-FH: File Hashing (Defensive Tactic - Detect)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-FH (File Hashing) is a defensive technique that uses file hash comparisons to detect known malware. Requires a database of malicious hashes to compare against environment files. Counters ATT&CK T1204 (User Execution), T1055 (Process Injection), T1547 (Boot or Logon Autostart), T1027 (Obfuscated Files). Required under NIST SP 800-53 SI-3 + SI-7, ISO 27001 A.8.7, PCI DSS Req 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1204-user-execution",
      "mitre-attack-t1027-obfuscated-files-information",
      "mitre-d3fend-d3-fim-file-integrity-monitoring",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-fim-file-integrity-monitoring",
    "title": "MITRE D3FEND D3-FIM: File Integrity Monitoring (Defensive Tactic - Detect → File Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE D3FEND D3-FIM (File Integrity Monitoring) is a defensive technique that detects unauthorised modification of files by computing and comparing cryptographic hashes against a baseline. FIM counters ATT&CK techniques T1070 (Indicator Removal), T1027 (Obfuscated Files), T1485 (Data Destruction), T1486 (Data Encrypted for Impact / ransomware), and T1565 (Data Manipulation). FIM is a mandatory control under PCI DSS Requirement 11.5, NIST SP 800-53 SI-7, ISO 27001 A.8.32, and HIPAA Security Rule 164.312(c)(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1070-indicator-removal",
      "mitre-attack-t1027-obfuscated-files-information",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-frddl-forward-resolution-domain-denylisting",
    "title": "MITRE D3FEND D3-FRDDL: Forward Resolution Domain Denylisting (Defensive Tactic - Isolate -> Forward Resolution Domain Denylisting)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-FRDDL (Forward Resolution Domain Denylisting) is a Isolate defensive technique. Blocking a lookup based on the query's domain name value. Policies are created that filter DNS queries using fully qualified domain name (FQDN) of record in the query. A DNS policy can be created for blocking DNS queries from FQDNs that have been identified as unauthorized. In the D3FEND model it blocks the outbound internet dns lookup traffic. It counters ATT&CK techniques T1071.004, T1568. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1071-004-dns",
      "mitre-attack-t1568-dynamic-resolution",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-fv-firmware-verification",
    "title": "MITRE D3FEND D3-FV: Firmware Verification (Defensive Tactic - Detect -> Firmware Verification)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-FV (Firmware Verification) is a Detect defensive technique. Cryptographically verifying firmware integrity. Cryptographic hash values are computed for system and peripheral firmware. The hash values are compared against precomputed hash values for the identified firmware. A hash value mismatch may indicate that the firmware may have been tampered with or updated with a non-current release indicating a misconfiguration for the system. In the D3FEND model it verifies the firmware. It counters ATT&CK techniques T1014, T1542.001, T1542.002, T1542.004. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1014-rootkit",
      "mitre-attack-t1542-001-system-firmware",
      "mitre-attack-t1542-002-component-firmware",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-hbpi-hardware-based-process-isolation",
    "title": "MITRE D3FEND D3-HBPI: Hardware-based Process Isolation (Defensive Tactic - Isolate -> Hardware-based Process Isolation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-HBPI (Hardware-based Process Isolation) is a Isolate defensive technique. Preventing one process from writing to the memory space of another process through hardware based address manager implementations. Process isolation, in this context, is address space separation controlled by a security function that limits the communication between processes so that one process cannot directly modify the executing code of another process. For example with virtual address space: Process A address space is different from process B address space, which prevents process A from writing to process B Hardware process isolation is commonly implemented through Direct Memory. In the D3FEND model it isolates the process; restricts the create process. It counters ATT&CK techniques T1003.001, T1003.002, T1003.004, T1007, T1010, T1016, T1018, T1033, T1047, T1053, and 26 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-001-lsass-memory",
      "mitre-attack-t1003-002-security-account-manager",
      "mitre-attack-t1003-004-lsa-secrets",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-hbwp-hardware-based-write-protection",
    "title": "MITRE D3FEND D3-HBWP: Hardware-based Write Protection (Defensive Tactic - Harden -> Hardware-based Write Protection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-HBWP (Hardware-based Write Protection) is a Harden defensive technique. Physical methods of preventing data from being written to computer storage. In the D3FEND model it hardens the secondary storage. It counters ATT&CK technique T1619. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-17, CM-5, IA-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1619-cloud-storage-object-discovery",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-hci-hardware-component-inventory",
    "title": "MITRE D3FEND D3-HCI: Hardware Component Inventory (Defensive Tactic - Model -> Hardware Component Inventory)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE D3FEND D3-HCI (Hardware Component Inventory) is a Model defensive technique. In the D3FEND model it inventories Hardware Device. It is part of the Asset Inventory D3FEND parent category and counters ATT&CK techniques T1091, T1092, T1123, T1125, T1025, T1056.001, T1619, T1195.003, T1200, T1111, T1052.001. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls in the AC, IA, AU, CM, SI, SC, SA families.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-d3fend-d3-hd-homoglyph-detection",
    "title": "MITRE D3FEND D3-HD: Homoglyph Detection (Defensive Tactic - Detect -> Homoglyph Detection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-HD (Homoglyph Detection) is a Detect defensive technique. Comparing strings using a variety of techniques to determine if a deceptive or malicious string is being presented to a user. A homoglyph, in this context, is a deceptive string or word which looks like a trusted word, but is composed of different characters, for example: goooogle.com versus google.com. This is commonly found in phishing and typo squatting attacks where a human exploiting through a social engineering campaign. In the D3FEND model it analyzes the email; analyzes the url. It counters ATT&CK techniques T1114.001, T1189, T1204.001, T1534, T1566.001, T1566.002, T1566.003. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-6, AC-16, AC-17, AC-19, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1114-001-local-email-collection",
      "mitre-attack-t1189-drive-by-compromise",
      "mitre-attack-t1204-001-malicious-link",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-hr-host-reboot",
    "title": "MITRE D3FEND D3-HR: Host Reboot (Defensive Tactic - Evict -> Host Reboot)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-HR (Host Reboot) is a Evict defensive technique. Initiating a host's reboot sequence to terminate all running processes. Host reboot can either be initiated in the physical presence of the device using the power functions or remotely using the provided user interface or an installed EDR agent (with the available function). This process may allow for the removal of specific types of malware, such as fileless malware, and can also prevent further damage, for example, if the system is part of a botnet. In the D3FEND model it terminates the process. It counters ATT&CK techniques T1003.001, T1003.002, T1003.004, T1033, T1053, T1053.005, T1212, T1505.002, T1505.003, T1546.007, and 4 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-001-lsass-memory",
      "mitre-attack-t1003-002-security-account-manager",
      "mitre-attack-t1003-004-lsa-secrets",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-hs-host-shutdown",
    "title": "MITRE D3FEND D3-HS: Host Shutdown (Defensive Tactic - Evict -> Host Shutdown)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-HS (Host Shutdown) is a Evict defensive technique. Initiating a host's shutdown sequence to terminate all running processes. Host shutdown can either be initiated in the physical presence of the device using the power functions or remotely using the provided user interface or an installed EDR agent (with the available function). This process may allow for the removal of specific types of malware, such as fileless malware, and can also prevent further damage, for example, if the system is part of a botnet. In the D3FEND model it terminates the process. It counters ATT&CK techniques T1003.001, T1003.002, T1003.004, T1033, T1053, T1053.005, T1212, T1505.002, T1505.003, T1546.007, and 4 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-001-lsass-memory",
      "mitre-attack-t1003-002-security-account-manager",
      "mitre-attack-t1003-004-lsa-secrets",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-iaa-identifier-activity-analysis",
    "title": "MITRE D3FEND D3-IAA: Identifier Activity Analysis (Defensive Tactic - Detect -> Identifier Activity Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-IAA (Identifier Activity Analysis) is a Detect defensive technique. Taking known malicious identifiers and determining if they are present in a system. Identifier activity analysis is the process of taking identifiers--typically known malicious identifiers--and determining the artifacts that have interacted with those identifiers. There are many open and closed source repositories of identifiers that represent indicators of compromise. For example, VirusTotal contains hash signatures of malware and IP Addresses used by threat actors. In the D3FEND model it analyzes the identifier. It counters ATT&CK techniques T1189, T1204.001, T1566.002, T1566.003. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-4, AC-6, CA-7, CM-2, CM-6, CM-7, CM-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1189-drive-by-compromise",
      "mitre-attack-t1204-001-malicious-link",
      "mitre-attack-t1566-002-spearphishing-link",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ida-input-device-analysis",
    "title": "MITRE D3FEND D3-IDA: Input Device Analysis (Defensive Tactic - Detect -> Input Device Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-IDA (Input Device Analysis) is a Detect defensive technique. Operating system level mechanisms to prevent abusive input device exploitation. Input Device Hardening techniques filter certain commands, or disable related operating system functionality. In the D3FEND model it analyzes the input device. It counters ATT&CK techniques T1056.001, T1123, T1125.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1056-001-keylogging",
      "mitre-attack-t1123-audio-capture",
      "mitre-attack-t1125-video-capture",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-d3fend-d3-iopr-io-port-restriction",
    "title": "MITRE D3FEND D3-IOPR: IO Port Restriction (Defensive Tactic - Isolate -> IO Port Restriction)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-IOPR (IO Port Restriction) is a Isolate defensive technique. Limiting access to computer input/output (IO) ports to restrict unauthorized devices. Software-based restriction uses agent software installed on a computer system. The agent software monitors all IO port system traffic. The agent software is configurable to limit the use of certain devices connected to IO ports. The restriction software can also be configured to limit the access to files and applications on external storage devices connected to IO ports. Hardware-based restriction can also be employed to limit access to IO ports. In the D3FEND model it isolates the io module; filters the input device; filters the removable media device. It counters ATT&CK techniques T1025, T1052.001, T1056.001, T1091, T1092, T1123, T1125. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, AC-16, AC-20, AC-23, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1025-data-from-removable-media",
      "mitre-attack-t1052-001-exfiltration-over-usb",
      "mitre-attack-t1056-001-keylogging",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ipcta-ipc-traffic-analysis",
    "title": "MITRE D3FEND D3-IPCTA: IPC Traffic Analysis (Defensive Tactic - Detect -> IPC Traffic Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-IPCTA (IPC Traffic Analysis) is a Detect defensive technique. Analyzing standard inter process communication (IPC) protocols to detect deviations from normal protocol activity. Inter process communication enables applications or threads to share data. This can involve one or more computers. Monitoring IPC in your environment can reveal abnormal or malicious activity. IPC can occur within a single computer or between multiple computers remotely through network protocols. Thus there are multiple ways to collect and monitor these exchanges between processes. In the D3FEND model it analyzes the intranet ipc network traffic. It counters ATT&CK technique T1197. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-7, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1197-bits-jobs",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ira-identifier-reputation-analysis",
    "title": "MITRE D3FEND D3-IRA: Identifier Reputation Analysis (Defensive Tactic - Detect)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-IRA (Identifier Reputation Analysis) is a defensive technique that analyses the reputation of identifiers (IP addresses, file hashes, domain names, URLs) to detect malicious activity. Five sub-classes per page. Counters ATT&CK T1566.002 (Spearphishing Link), T1566.003 (Spearphishing via Service), T1189 (Drive-by Compromise), T1204.001 (Malicious Link). Required under NIST SP 800-53 SI-4 + SI-5, ISO 27001 A.5.7 + A.8.16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1566-002-spearphishing-link",
      "mitre-attack-t1583-acquire-infrastructure",
      "mitre-d3fend-d3-dnsdl-dns-denylisting",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-isva-inbound-session-volume-analysis",
    "title": "MITRE D3FEND D3-ISVA: Inbound Session Volume Analysis (Defensive Tactic - Detect -> Inbound Session Volume Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-ISVA (Inbound Session Volume Analysis) is a Detect defensive technique. Analyzing inbound network session or connection attempt volume. Network appliances are configured to alert on certain packets that typically are involved in DoS attacks. Typical packets include ICMP packets and SYN requests that are commonly used to flood networks. A sampling period is used to define a time window in which collected counts of the identified packets can be measured. If the collected number of packets exceeds a predefined limit then an alert is generated. In the D3FEND model it analyzes the inbound internet network traffic. It counters ATT&CK techniques T1190, T1498.001, T1498.002, T1499.002, T1566.001, T1566.002. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-2, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1498-001-direct-network-flood",
      "mitre-attack-t1498-002-reflection-amplification",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-itf-inbound-traffic-filtering",
    "title": "MITRE D3FEND D3-ITF: Inbound Traffic Filtering (Defensive Tactic - Isolate -> Network Isolation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-ITF (Inbound Traffic Filtering) is a defensive technique that filters inbound network connections based on source identifier, application protocol, and request content to block adversary access before exploitation. ITF counters ATT&CK techniques T1190 (Exploit Public-Facing Application), T1133 (External Remote Services), T1499 (Endpoint DoS), T1498 (Network DoS), and T1595 (Active Scanning). Required under NIST SP 800-53 SC-7 (Boundary Protection), ISO 27001 A.8.20-A.8.21, PCI DSS Req 1, NIS2 Article 21(2)(b)(c), DORA Article 9, and CIS Critical Security Controls v8 Control 13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1595-active-scanning",
      "mitre-attack-t1499-endpoint-denial-of-service",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-kbpi-kernel-based-process-isolation",
    "title": "MITRE D3FEND D3-KBPI: Kernel-based Process Isolation (Defensive Tactic - Isolate -> Kernel-based Process Isolation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-KBPI (Kernel-based Process Isolation) is a Isolate defensive technique. Using kernel-level capabilities to isolate processes. In the D3FEND model it isolates the process. It counters ATT&CK techniques T1003.001, T1003.002, T1003.004, T1033, T1053, T1053.005, T1212, T1505.002, T1505.003, T1546.007, and 4 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-001-lsass-memory",
      "mitre-attack-t1003-002-security-account-manager",
      "mitre-attack-t1003-004-lsa-secrets",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-lam-local-account-monitoring",
    "title": "MITRE D3FEND D3-LAM: Local Account Monitoring (Defensive Tactic - Detect -> Local Account Monitoring)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-LAM (Local Account Monitoring) is a Detect defensive technique. Analyzing local user accounts to detect unauthorized activity. In the D3FEND model it analyzes the local user account. It counters ATT&CK techniques T1078.003, T1087.001, T1136.001. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-20, CA-3, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-003-local-accounts",
      "mitre-attack-t1087-001-local-account",
      "mitre-attack-t1136-001-local-account",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-lfp-local-file-permissions",
    "title": "MITRE D3FEND D3-LFP: Local File Permissions (Defensive Tactic - Isolate -> Local File Permissions)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-LFP (Local File Permissions) is a Isolate defensive technique. Local file permissions is the systematic process of defining, implementing, and managing access control policies that dictate user permissions for accessing files on a local system through the configuration of operating system functionality. In the D3FEND model it restricts the directory; restricts the file. It counters ATT&CK techniques T1003.007, T1003.008, T1005, T1014, T1016, T1018, T1027.001, T1027.002, T1027.004, T1033, and 90 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-10, AC-12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-007-proc-filesystem",
      "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
      "mitre-attack-t1005-data-from-local-system",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-llm-logical-link-mapping",
    "title": "MITRE D3FEND D3-LLM: Logical Link Mapping (Defensive Tactic - Model -> Logical Link Mapping)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-LLM (Logical Link Mapping) is a Model defensive technique. Logical link mapping creates a model of existing or previous node-to-node connections using network-layer data or metadata. In the D3FEND model it maps the logical link; maps the network; maps the network node. It counters ATT&CK techniques T1114.002, T1505.002, T1505.003, T1562.013, T1578.002, T1578.003, T1578.004. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1114-002-remote-email-collection",
      "mitre-attack-t1505-002-transport-agent",
      "mitre-attack-t1505-003-web-shell",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-mbt-memory-boundary-tracking",
    "title": "MITRE D3FEND D3-MBT: Memory Boundary Tracking (Defensive Tactic - Detect -> Memory Boundary Tracking)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-MBT (Memory Boundary Tracking) is a Detect defensive technique. Analyzing a call stack for return addresses which point to unexpected memory locations. This technique monitors for indicators of whether a return address is outside memory previously allocated for an object (i.e. function, module, process, or thread). If so, code that the return address points to is treated as malicious code. In the D3FEND model it analyzes the process code segment. It counters ATT&CK techniques T1055.012, T1056.004, T1068, T1203, T1210, T1211, T1212. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-2, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1055-012-process-hollowing",
      "mitre-attack-t1056-004-credential-api-hooking",
      "mitre-attack-t1068-exploitation-privilege-escalation",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-mencr-message-encryption",
    "title": "MITRE D3FEND D3-MENCR: Message Encryption (Defensive Tactic - Harden -> Message Encryption)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-MENCR (Message Encryption) is a defensive technique that protects message content in transit using cryptography to prevent eavesdropping, tampering, and replay. MENCR covers TLS for web and API traffic, IPsec for site-to-site VPN, S/MIME and PGP for email, signed and encrypted JSON Web Tokens, end-to-end messaging encryption (Signal Protocol, MLS), and post-quantum readiness. Required under NIST SP 800-53 SC-8 (Transmission Confidentiality and Integrity), SC-12 (Cryptographic Key Establishment), SC-13 (Cryptographic Protection), ISO 27001 A.8.24 (Use of cryptography), PCI DSS v4.0 Req 4 (Encrypt transmission of cardholder data), HIPAA Security Rule 164.312(e)(1) (Transmission Security), GDPR Article 32, NIS2 Article 21(2)(h), DORA Article 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1573-encrypted-channel",
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-d3fend-d3-dencr-disk-encryption",
      "gdpr-article-32-security-of-processing",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-mfa-multi-factor-authentication",
    "title": "MITRE D3FEND D3-MFA: Multi-Factor Authentication (Defensive Tactic - Harden → Credential Hardening)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE D3FEND D3-MFA (Multi-Factor Authentication) is a defensive technique that requires authentication through two or more independent factors (knowledge, possession, inherence) to verify user identity. MFA counters ATT&CK techniques T1078 (Valid Accounts), T1110 (Brute Force), T1556 (Modify Authentication Process), T1539 (Steal Web Session Cookie), and T1621 (MFA Request Generation / MFA Fatigue). Phishing-resistant MFA (FIDO2/WebAuthn) is mandated under PCI DSS v4.0 Req 8.4 (effective 31 March 2025), NIST SP 800-63B AAL2/AAL3, CISA Binding Operational Directive 22-09, and EU eIDAS 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1110-brute-force",
      "mitre-attack-t1078-valid-accounts",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ni-network-isolation",
    "title": "MITRE D3FEND D3-NI: Network Isolation (Defensive Tactic - Isolate → Network Isolation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE D3FEND D3-NI (Network Isolation) is a defensive technique that prevents network communication between systems through segmentation, microsegmentation, and dynamic isolation. NI counters ATT&CK techniques T1021 (Remote Services), T1570 (Lateral Tool Transfer), T1210 (Exploitation of Remote Services), T1018 (Remote System Discovery), and T1078 (Valid Accounts lateral use). Network segmentation is required under PCI DSS Requirement 1, NIST SP 800-53 SC-7, ISO 27001 A.8.22, NIS2 Article 21(2)(c), and CISA Zero Trust Maturity Model Networks pillar.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1021-remote-services",
      "mitre-attack-t1570-lateral-tool-transfer",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-nm-network-mapping",
    "title": "MITRE D3FEND D3-NM: Network Mapping (Defensive Tactic - Model -> Network Mapping)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-NM (Network Mapping) is a defensive technique that enumerates and visualises network topology, segmentation boundaries, communication paths, and inter-zone trust relationships to enable network-isolation defence design and lateral-movement detection. NM is the precondition for D3-NI (Network Isolation), D3-ITF (Inbound Traffic Filtering), D3-OTF (Outbound Traffic Filtering), and D3-NTA (Network Traffic Analysis). Required under NIST SP 800-53 CA-9 (Internal System Connections), AC-4 (Information Flow Enforcement), SC-7 (Boundary Protection), ISO 27001 A.8.20-A.8.22, PCI DSS v4.0 Req 1.2.4 (network segmentation diagram), NIS2 Article 21(2)(d), and DORA Article 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1078-valid-accounts",
      "mitre-d3fend-d3-ai-asset-inventory",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-nni-network-node-inventory",
    "title": "MITRE D3FEND D3-NNI: Network Node Inventory (Defensive Tactic - Model -> Network Node Inventory)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE D3FEND D3-NNI (Network Node Inventory) is a Model defensive technique. In the D3FEND model it inventories Network Node. It is part of the Asset Inventory D3FEND parent category and counters ATT&CK techniques T1114.002, T1505.002, T1505.003, T1578.002, T1562.013, T1578.003, T1578.004. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls in the AC, IA, AU, CM, SI, SC, SA families.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-d3fend-d3-nram-network-resource-access-mediation",
    "title": "MITRE D3FEND D3-NRAM: Network Resource Access Mediation (Defensive Tactic - Isolate -> Network Resource Access Mediation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-NRAM (Network Resource Access Mediation) is a Isolate defensive technique. Control of access to organizational systems and services by users or processes over a network. Network Resource Access Control involves managing and regulating access to resources within an organization's network. This includes ensuring that only authorized users or processes can access specific systems or data, often through authentication and authorization mechanisms. Examples include accessing internal databases, file servers, or application services. In the D3FEND model it isolates the network resource. It counters ATT&CK techniques T1037.003, T1039, T1070.005, T1074.002, T1080, T1213.001, T1213.002, T1491.002. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1037-003-network-logon-script",
      "mitre-attack-t1039-data-from-network-shared-drive",
      "mitre-attack-t1070-005-network-share-connection-removal",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-nta-network-traffic-analysis",
    "title": "MITRE D3FEND D3-NTA: Network Traffic Analysis (Defensive Tactic - Detect → Network Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE D3FEND D3-NTA (Network Traffic Analysis) is a defensive technique that inspects network communications to identify malicious or unauthorised behaviour. NTA counters ATT&CK techniques T1071 (Application Layer Protocol), T1573 (Encrypted Channel), T1041 (Exfiltration Over C2 Channel), T1567 (Exfiltration Over Web Service), T1090 (Proxy), T1568 (Dynamic Resolution), and T1095 (Non-Application Layer Protocol). NTA capability is required under NIST SP 800-53 SI-4, ISO 27001 A.8.16, NIS2 Article 21(2)(b), and PCI DSS Requirement 11.4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "pci-dss-v4-req-10-12-monitoring-policy",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ntcd-network-traffic-community-deviation",
    "title": "MITRE D3FEND D3-NTCD: Network Traffic Community Deviation (Defensive Tactic - Detect -> Network Traffic Community Deviation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-NTCD (Network Traffic Community Deviation) is a Detect defensive technique. Establishing baseline communities of network hosts and identifying statistically divergent inter-community communication. Hosts/users within a computer network are analyzed to identify communities of hosts which frequently communicate. Future communications between communities that don't usually communicate can then be detected. For example, if a community of hosts that communicate in support of a company's finance division suddenly starts to access the code server usually accessed only by engineers, this may indicate unauthorized activity. In the D3FEND model it analyzes the network traffic. It counters ATT&CK techniques T1001, T1003.006, T1008, T1011, T1018, T1020, T1021, T1021.001, T1021.004, T1029, and 62 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-8, AC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1001-data-obfuscation",
      "mitre-attack-t1003-006-dcsync",
      "mitre-attack-t1008-fallback-channels",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ntf-network-traffic-filtering",
    "title": "MITRE D3FEND D3-NTF: Network Traffic Filtering (Defensive Tactic - Isolate -> Network Traffic Filtering)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-NTF (Network Traffic Filtering) is a Isolate defensive technique. Restricting network traffic originating from any location. In the D3FEND model it filters the network traffic; filters the ot protocol message; filters the remote command. It counters ATT&CK techniques T1001, T1003.006, T1008, T1011, T1018, T1020, T1021, T1021.001, T1021.004, T1029, and 62 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-8, AC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1001-data-obfuscation",
      "mitre-attack-t1003-006-dcsync",
      "mitre-attack-t1008-fallback-channels",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ntpm-network-traffic-policy-mapping",
    "title": "MITRE D3FEND D3-NTPM: Network Traffic Policy Mapping (Defensive Tactic - Model -> Network Traffic Policy Mapping)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-NTPM (Network Traffic Policy Mapping) is a Model defensive technique. Network traffic policy mapping identifies and models the allowed pathways of data at the network, transport, and/or application levels. In the D3FEND model it queries the network agent; maps the access control configuration. It counters ATT&CK techniques T1134.005, T1222, T1484, T1548.001, T1548.005, T1552.006, T1556.009, T1615. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1134-005-sid-history-injection",
      "mitre-attack-t1222-file-and-directory-permissions-modification",
      "mitre-attack-t1484-domain-or-tenant-policy-modification",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ntsa-network-traffic-signature-analysis",
    "title": "MITRE D3FEND D3-NTSA: Network Traffic Signature Analysis (Defensive Tactic - Detect -> Network Traffic Signature Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-NTSA (Network Traffic Signature Analysis) is a Detect defensive technique. Analyzing network traffic and compares it to known signatures Network signature analysis relies on predefined patterns, or signatures, to identify malicious network activity. These signatures typically match against specific byte sequences, packet header information, or protocol anomalies indicative of known threats. The process works as follows: Packet Capture: Network traffic is captured on an interface or port, resulting in a stream of raw packets. In the D3FEND model it analyzes the network traffic. It counters ATT&CK techniques T1001, T1003.006, T1008, T1011, T1018, T1020, T1021, T1021.001, T1021.004, T1029, and 62 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-8, AC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1001-data-obfuscation",
      "mitre-attack-t1003-006-dcsync",
      "mitre-attack-t1008-fallback-channels",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-oam-operational-activity-mapping",
    "title": "MITRE D3FEND D3-OAM: Operational Activity Mapping (Defensive Tactic - Model -> Operational Activity Mapping)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-OAM (Operational Activity Mapping) is a defensive technique that enumerates and documents legitimate operational activities - business processes, automated workflows, scheduled jobs, batch processing windows, and authorised administrative actions - to enable detection of adversary activity that deviates from operational baseline. OAM produces the behavioural baseline that powers Detect-tactic techniques including D3-NTA (Network Traffic Analysis), D3-UBA (User Behavior Analysis), D3-PSA (Process Spawn Analysis), and D3-FAPA (File Access Pattern Analysis). Required under NIST SP 800-53 SI-4 (System Monitoring), AU-2 (Event Logging), CA-7 (Continuous Monitoring), ISO 27001 A.8.16, and NIS2 Article 21(2)(b).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1059-command-and-scripting-interpreter",
      "mitre-d3fend-d3-ai-asset-inventory",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-opm-operational-process-monitoring",
    "title": "MITRE D3FEND D3-OPM: Operational Process Monitoring (Defensive Tactic - Detect -> Operational Process Monitoring)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-OPM (Operational Process Monitoring) is a Detect defensive technique. Monitoring physical parameters and operator actions related to an operational environment. While some Operational Technology systems are designed to operate without human intervention, most systems are designed with the ability to monitor and modify the physical process with user input. This technique detects adversarial risks to operational processes by observing physical events and operator actions and analyzing event logs. Key steps in operational process security monitoring are: 1. In the D3FEND model it monitors the event log. It counters ATT&CK techniques T1003.006, T1070.001, T1070.003, T1110.001, T1110.003, T1110.004, T1134.002, T1134.003, T1140, T1187, and 3 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-006-dcsync",
      "mitre-attack-t1685-005-clear-windows-event-logs",
      "mitre-attack-t1070-003-clear-command-history",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-otf-outbound-traffic-filtering",
    "title": "MITRE D3FEND D3-OTF: Outbound Traffic Filtering (Defensive Tactic - Isolate -> Outbound Traffic Filtering)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-OTF (Outbound Traffic Filtering) is a Isolate defensive technique. Restricting network traffic originating from a private host or enclave destined towards untrusted networks. Outbound traffic, in this context, is network traffic originating from a private host or enclave destined towards untrusted networks. For example: An enterprise desktop intranet user connecting to www.example.com An internal mail server connecting to an external mail server, mail.example.com Filtering is commonly implemented as firewall rulesets to limit outbound traffic permitted to egress a host or network. In the D3FEND model it filters the outbound network traffic. It counters ATT&CK techniques T1001, T1008, T1048.001, T1048.002, T1048.003, T1071, T1071.001, T1071.002, T1071.003, T1071.004, and 21 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1001-data-obfuscation",
      "mitre-attack-t1008-fallback-channels",
      "mitre-attack-t1048-001-exfiltration-over-symmetric-encrypted-non-c2-protocol",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-otp-one-time-password",
    "title": "MITRE D3FEND D3-OTP: One-time Password (Defensive Tactic - Harden -> One-time Password)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE D3FEND D3-OTP (One-time Password) is a Harden defensive technique. In the D3FEND model it use-limits Password. It is part of the Credential Hardening D3FEND parent category and counters ATT&CK techniques T1110.001, T1110.003, T1110.002. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls in the AC, IA, AU, CM, SI, SC, SA families.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-d3fend-d3-pa-password-authentication",
    "title": "MITRE D3FEND D3-PA: Password Authentication (Defensive Tactic - Harden -> Password Authentication)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE D3FEND D3-PA (Password Authentication) is a Harden defensive technique. In the D3FEND model it uses Password. It is part of the Agent Authentication D3FEND parent category and counters ATT&CK techniques T1110.001, T1110.003, T1110.002. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls in the AC, IA, AU, CM, SI, SC, SA families.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-d3fend-d3-pan-pointer-authentication",
    "title": "MITRE D3FEND D3-PAN: Pointer Authentication (Defensive Tactic - Harden)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-PAN (Pointer Authentication) is a defensive technique that uses cryptographic hashes or derivatives of pointer values to detect tampering. Defends against memory corruption attacks, ROP, control-flow hijacking, code injection. Hardware implementations: ARM Pointer Authentication (PAC), Intel CET, AMD Shadow Stack. Counters ATT&CK T1068 (Exploitation for Privilege Escalation), T1203 (Exploitation for Client Execution), T1055 (Process Injection). Required under NIST SP 800-53 SI-16 + SC-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1068-exploitation-privilege-escalation",
      "mitre-attack-t1574-hijack-execution-flow",
      "mitre-d3fend-d3-sch-source-code-hardening",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-pcsv-process-code-segment-verification",
    "title": "MITRE D3FEND D3-PCSV: Process Code Segment Verification (Defensive Tactic - Detect -> Process Code Segment Verification)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-PCSV (Process Code Segment Verification) is a Detect defensive technique. Comparing the \"text\" or \"code\" memory segments to a source of truth. A process code segment is an executable portion of computer memory allocated to a particular process. Process Code Segment Verification implements verification to compare a process code segment to some expected value. In the D3FEND model it verifies the process code segment. It counters ATT&CK techniques T1055.012, T1056.004, T1068, T1203, T1210, T1211, T1212. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-2, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1055-012-process-hollowing",
      "mitre-attack-t1056-004-credential-api-hooking",
      "mitre-attack-t1068-exploitation-privilege-escalation",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-pe-process-eviction",
    "title": "MITRE D3FEND D3-PE: Process Eviction (Defensive Tactic - Evict -> Process Eviction)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-PE (Process Eviction) is a defensive technique that forcibly terminates malicious processes from compromised systems as a containment action. PE counters post-compromise execution under ATT&CK techniques T1059 (Command and Scripting Interpreter), T1055 (Process Injection), T1106 (Native API), T1486 (Data Encrypted for Impact - terminate ransomware encryption process), T1485 (Data Destruction), and T1543 (Create or Modify System Process). EDR-driven automated process termination is required under NIST SP 800-53 IR-4 (Incident Handling) including IR-4(2) dynamic reconfiguration, IR-4(13) behaviour analysis, ISO 27001 A.5.26, and CISA #StopRansomware Guide.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1486-data-encrypted-for-impact",
      "mitre-attack-t1059-command-and-scripting-interpreter",
      "mitre-attack-t1106-native-api",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-phdura-per-host-download-upload-ratio-analysis",
    "title": "MITRE D3FEND D3-PHDURA: Per Host Download-Upload Ratio Analysis (Defensive Tactic - Detect -> Per Host Download-Upload Ratio Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-PHDURA (Per Host Download-Upload Ratio Analysis) is a Detect defensive technique. Detecting anomalies that indicate malicious activity by comparing the amount of data downloaded versus data uploaded by a host. Aggregate pull vs. push ratios from metadata are used to develop a baseline for a given host over a specific time period, e.g., over a three-hour period, one day, one week, etc. Anomalies identified over a threshold produce an alert. In the D3FEND model it analyzes the network traffic. It counters ATT&CK techniques T1001, T1003.006, T1008, T1011, T1018, T1020, T1021, T1021.001, T1021.004, T1029, and 62 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-8, AC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1001-data-obfuscation",
      "mitre-attack-t1003-006-dcsync",
      "mitre-attack-t1008-fallback-channels",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-pla-process-lineage-analysis",
    "title": "MITRE D3FEND D3-PLA: Process Lineage Analysis (Defensive Tactic - Detect -> Process Lineage Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-PLA (Process Lineage Analysis) is a Detect defensive technique. Identification of suspicious processes executing on an end-point device by examining the ancestry and siblings of a process, and the associated metadata of each node on the tree, such as process execution, duration, and order relative to siblings and ancestors. Process tree analysis techniques gather information on how a process was initiated to determine if a process is malicious. For example, if a process was not initiated from boot or not initiated by another process, that process is identified as suspicious. Also, if a new process was started before a process initiated by the device (ex. In the D3FEND model it analyzes the process; analyzes the process tree. It counters ATT&CK techniques T1003.001, T1003.002, T1003.004, T1033, T1053, T1053.005, T1212, T1505.002, T1505.003, T1546.007, and 4 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-001-lsass-memory",
      "mitre-attack-t1003-002-security-account-manager",
      "mitre-attack-t1003-004-lsa-secrets",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-plm-physical-link-mapping",
    "title": "MITRE D3FEND D3-PLM: Physical Link Mapping (Defensive Tactic - Model -> Physical Link Mapping)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-PLM (Physical Link Mapping) is a Model defensive technique. Physical link mapping identifies and models the link connectivity of the network devices within a physical network. In the D3FEND model it maps the network node; maps the physical link. It counters ATT&CK techniques T1114.002, T1505.002, T1505.003, T1562.013, T1578.002, T1578.003, T1578.004. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1114-002-remote-email-collection",
      "mitre-attack-t1505-002-transport-agent",
      "mitre-attack-t1505-003-web-shell",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-pmad-protocol-metadata-anomaly-detection",
    "title": "MITRE D3FEND D3-PMAD: Protocol Metadata Anomaly Detection (Defensive Tactic - Detect -> Protocol Metadata Anomaly Detection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-PMAD (Protocol Metadata Anomaly Detection) is a Detect defensive technique. Collecting network communication protocol metadata and identifying statistical outliers. Network protocol metadata is first collected and processed in real-time or post-facto. Metadata may include packet header information or information about a session (ex. time between requests/responses). Metadata is then grouped based on shared characteristics and those groups are compared to each other. If particular metadata differs significantly from other data, an alert is generated, identifying the network event as anomalous. In the D3FEND model it analyzes the network traffic. It counters ATT&CK techniques T1001, T1003.006, T1008, T1011, T1018, T1020, T1021, T1021.001, T1021.004, T1029, and 62 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-8, AC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1001-data-obfuscation",
      "mitre-attack-t1003-006-dcsync",
      "mitre-attack-t1008-fallback-channels",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-pr-password-rotation",
    "title": "MITRE D3FEND D3-PR: Password Rotation (Defensive Tactic - Harden -> Password Rotation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-PR (Password Rotation) is a Harden defensive technique. Password rotation is a security policy that mandates the periodic change of user account passwords to mitigate the risk of unauthorized access due to compromised credentials. Users may be requested to change their passwords on a regular schedule. Management servers with enterprise policies for account management provide the ability to change or reset passwords for accounts. In the D3FEND model it regenerates the password. It counters ATT&CK techniques T1110.001, T1110.002, T1110.003. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-7, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1110-001-password-guessing",
      "mitre-attack-t1110-002-password-cracking",
      "mitre-attack-t1110-003-password-spraying",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ps-process-suspension",
    "title": "MITRE D3FEND D3-PS: Process Suspension (Defensive Tactic - Evict -> Process Suspension)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-PS (Process Suspension) is a Evict defensive technique. Suspending a running process on a computer system. A running process might be suspended to mitigate its immediate effects if it is exhibiting anomalous, unauthorized, or malicious behavior. Defenders may choose to suspend rather than terminate to analyze the process first and resume the process if deemed benign. In the D3FEND model it suspends the process. It counters ATT&CK techniques T1003.001, T1003.002, T1003.004, T1033, T1053, T1053.005, T1212, T1505.002, T1505.003, T1546.007, and 4 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-001-lsass-memory",
      "mitre-attack-t1003-002-security-account-manager",
      "mitre-attack-t1003-004-lsa-secrets",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-psa-process-spawn-analysis",
    "title": "MITRE D3FEND D3-PSA: Process Spawn Analysis (Defensive Tactic - Detect -> Process Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE D3FEND D3-PSA (Process Spawn Analysis) is a defensive technique that analyses parent-child process relationships to identify suspicious execution chains. PSA counters ATT&CK techniques T1059 (Command and Scripting Interpreter - flags powershell.exe spawned from winword.exe), T1106 (Native API), T1204 (User Execution), T1055 (Process Injection), T1068 (Exploitation for Privilege Escalation), and T1218 (System Binary Proxy Execution). Process-hierarchy detection underpins modern EDR products and is required under NIST SP 800-53 SI-4, ISO 27001 A.8.16, PCI DSS Req 10.4, and is operationally baseline under CISA SHIELDS UP guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1059-command-and-scripting-interpreter",
      "mitre-attack-t1106-native-api",
      "mitre-attack-t1204-user-execution",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-psep-process-segment-execution-prevention",
    "title": "MITRE D3FEND D3-PSEP: Process Segment Execution Prevention (Defensive Tactic - Harden -> Process Segment Execution Prevention)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-PSEP (Process Segment Execution Prevention) is a Harden defensive technique. Preventing execution of any address in a memory region other than the code segment. During execution of a process, the instruction pointer register should only point to addresses in a code segment (also called the .text segment), as this is the sole segment which should contain program code. When this technique detects an attempt to execute something that has been designated as non-executable, other techniques such as those in Process Eviction might be invoked, such as Process Termination to end the current process, or Executable. In the D3FEND model it neutralizes the process segment. It counters ATT&CK techniques T1033, T1055.012, T1056.004, T1068, T1189, T1190, T1203, T1210, T1211, T1212, and 2 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-2, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1033-system-owner-user-discovery",
      "mitre-attack-t1055-012-process-hollowing",
      "mitre-attack-t1056-004-credential-api-hooking",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-psmd-process-self-modification-detection",
    "title": "MITRE D3FEND D3-PSMD: Process Self-Modification Detection (Defensive Tactic - Detect -> Process Self-Modification Detection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-PSMD (Process Self-Modification Detection) is a Detect defensive technique. Detects processes that modify, change, or replace their own code at runtime. A security agent installed on the host machine intercepts API calls between a process and operating system. Intercepted API calls are then compared against attack signatures/patterns to identify API calls that modify executable memory or modify the entry point address of a suspended child process. Attack patterns include: Executable code of a suspended child process removed from memory by one or more API calls. In the D3FEND model it analyzes the process. It counters ATT&CK techniques T1003.001, T1003.002, T1003.004, T1033, T1053, T1053.005, T1212, T1505.002, T1505.003, T1546.007, and 4 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-001-lsass-memory",
      "mitre-attack-t1003-002-security-account-manager",
      "mitre-attack-t1003-004-lsa-secrets",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-pt-process-termination",
    "title": "MITRE D3FEND D3-PT: Process Termination (Defensive Tactic - Evict)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-PT (Process Termination) is a defensive technique that terminates running application processes via OS kernel APIs to stop processes exhibiting malicious or anomalous behavior. Counters ATT&CK T1053 (Scheduled Task), T1505.002/.003 (Transport Agent/Web Shell), T1003 (OS Credential Dumping), T1556 (Modify Authentication Process), T1562 (Impair Defenses). Distinct from D3-PE Process Eviction (D3-PT focuses on termination only; D3-PE includes pre-termination forensic capture). Required under NIST SP 800-53 IR-4, ISO 27001 A.5.26.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1505-server-software-component",
      "mitre-attack-t1003-os-credential-dumping",
      "mitre-d3fend-d3-pe-process-eviction",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-rc-restore-configuration",
    "title": "MITRE D3FEND D3-RC: Restore Configuration (Defensive Tactic - Restore -> Restore Configuration)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RC (Restore Configuration) is a Restore defensive technique. Restoring an software configuration. In the D3FEND model it restores the configuration resource. It counters ATT&CK techniques T1037.004, T1037.005, T1114.003, T1134.005, T1137.001, T1137.002, T1137.004, T1137.005, T1218.002, T1222, and 43 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-10, AC-14.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1037-004-rc-scripts",
      "mitre-attack-t1037-005-startup-items",
      "mitre-attack-t1114-003-email-forwarding-rule",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-rd-restore-database",
    "title": "MITRE D3FEND D3-RD: Restore Database (Defensive Tactic - Restore -> Restore Database)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RD (Restore Database) is a Restore defensive technique. Restoring the data in a database. In the D3FEND model it restores the database. It counters ATT&CK techniques T1003.002, T1003.004, T1003.008, T1012, T1033, T1112, T1137.006, T1207, T1213.003, T1218.014, and 12 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-10, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-002-security-account-manager",
      "mitre-attack-t1003-004-lsa-secrets",
      "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-re-restore-email",
    "title": "MITRE D3FEND D3-RE: Restore Email (Defensive Tactic - Restore -> Restore Email)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RE (Restore Email) is a Restore defensive technique. Restoring an email for an entity to access. In the D3FEND model it restores the email. It counters ATT&CK techniques T1114.001, T1534, T1566.001, T1566.002. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-19, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1114-001-local-email-collection",
      "mitre-attack-t1534-internal-spearphishing",
      "mitre-attack-t1566-001-spearphishing-attachment",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-rf-restore-file",
    "title": "MITRE D3FEND D3-RF: Restore File (Defensive Tactic - Restore -> Restore Object)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-RF (Restore File) is a defensive technique that recovers individual files or directories from a known-good backup after corruption, encryption, deletion, or unauthorised modification. RF counters ATT&CK techniques T1486 (Data Encrypted for Impact - file-level ransomware recovery), T1485 (Data Destruction), T1491 (Defacement), T1565 (Data Manipulation), and T1561 (Disk Wipe). Required under NIST SP 800-53 CP-9 (System Backup), CP-10 (System Recovery), MP-4 (Media Storage), ISO 27001 A.8.13, A.8.14, A.5.29, HIPAA Security Rule 164.308(a)(7), NIS2 Article 21(2)(c), and DORA Article 12. Volume Shadow Copy Service, file versioning, and continuous file-level backup are the dominant implementation patterns.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1486-data-encrypted-for-impact",
      "mitre-attack-t1485-data-destruction",
      "mitre-d3fend-d3-ro-restore-object",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-rfam-remote-file-access-mediation",
    "title": "MITRE D3FEND D3-RFAM: Remote File Access Mediation (Defensive Tactic - Isolate -> Remote File Access Mediation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RFAM (Remote File Access Mediation) is a Isolate defensive technique. Remote file access mediation is the process of managing and securing access to file systems over a network to ensure that only authorized users or processes can interact with remote files. Remote File Access Mediation focuses on controlling how users or processes access file systems from remote locations. This involves ensuring secure connections, often through protocols like SFTP or SMB, and enforcing permissions to prevent unauthorized access or data breaches. Examples of enforcement areas include accessing shared drives or cloud storage from remote offices or home networks. In the D3FEND model it isolates the file. It counters ATT&CK techniques T1003.007, T1003.008, T1005, T1014, T1016, T1018, T1027.001, T1027.002, T1027.004, T1033, and 89 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-10, AC-12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-007-proc-filesystem",
      "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
      "mitre-attack-t1005-data-from-local-system",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-rh-radiation-hardening",
    "title": "MITRE D3FEND D3-RH: Radiation Hardening (Defensive Tactic - Harden -> Radiation Hardening)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RH (Radiation Hardening) is a Harden defensive technique. Radiation hardening is the process of making electronic components and circuits resistant to damage or malfunction caused by high levels of ionizing radiation. There are three core radiation hardening methodologies: 1. Radiation Hardening by Process (RHBP): modifying the physical fabrication of a semiconductor (e.g., using SOI - Silicon on Insulator), offering the highest intrinsic protection. Usually the most expensive option as it requires a specialized semiconducter fabrication plant. 2. In the D3FEND model it hardens the hardware device. It counters ATT&CK techniques T1025, T1052.001, T1056.001, T1091, T1092, T1111, T1123, T1125, T1195.003, T1200, and 1 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-20, AC-23.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1025-data-from-removable-media",
      "mitre-attack-t1052-001-exfiltration-over-usb",
      "mitre-attack-t1056-001-keylogging",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ric-reissue-credential",
    "title": "MITRE D3FEND D3-RIC: Reissue Credential (Defensive Tactic - Restore -> Reissue Credential)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RIC (Reissue Credential) is a Restore defensive technique. Issue a new credential to a user which supercedes their old credential. In the D3FEND model it restores the credential. It counters ATT&CK techniques T1003.003, T1003.005, T1003.008, T1098.001, T1110.001, T1110.002, T1110.003, T1134.001, T1134.002, T1134.003, and 10 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-10, AC-16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-003-ntds",
      "mitre-attack-t1003-005-cached-domain-credentials",
      "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-rkd-registry-key-deletion",
    "title": "MITRE D3FEND D3-RKD: Registry Key Deletion (Defensive Tactic - Evict -> Registry Key Deletion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RKD (Registry Key Deletion) is a Evict defensive technique. Delete a registry key. In the D3FEND model it deletes the windows registry key. It counters ATT&CK technique T1562.003. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1690-prevent-command-history-logging",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-rna-restore-network-access",
    "title": "MITRE D3FEND D3-RNA: Restore Network Access (Defensive Tactic - Restore -> Restore Network Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RNA (Restore Network Access) is a Restore defensive technique. Restoring a entity's access to a computer network. In the D3FEND model it restores the host. It counters ATT&CK techniques T1114.002, T1505.002, T1505.003, T1578.002, T1578.003, T1578.004. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1114-002-remote-email-collection",
      "mitre-attack-t1505-002-transport-agent",
      "mitre-attack-t1505-003-web-shell",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ro-restore-object",
    "title": "MITRE D3FEND D3-RO: Restore Object (Defensive Tactic - Restore -> Restore Object)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-11",
    "bluf": "MITRE D3FEND D3-RO (Restore Object) is a defensive technique that recovers system state from a known-good backup or golden image after compromise. RO counters ATT&CK techniques T1486 (Data Encrypted for Impact / ransomware), T1485 (Data Destruction / wiper), T1491 (Defacement), T1565 (Data Manipulation), and T1561 (Disk Wipe). Required under NIST SP 800-53 CP-9 (System Backup), CP-10 (System Recovery and Reconstitution), CP-12 (Safe Mode), ISO 27001 A.8.13, A.8.14, A.5.29, HIPAA Security Rule 164.308(a)(7), NIS2 Article 21(2)(c), DORA Articles 12-13, and SEC Cybersecurity Risk Management Rule.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1486-data-encrypted-for-impact",
      "mitre-attack-t1485-data-destruction",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "mitre-d3fend-d3-fim-file-integrity-monitoring"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-rpa-relay-pattern-analysis",
    "title": "MITRE D3FEND D3-RPA: Relay Pattern Analysis (Defensive Tactic - Detect -> Relay Pattern Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RPA (Relay Pattern Analysis) is a Detect defensive technique. The detection of an internal host relaying traffic between the internal network and the external network. A relay may use a variety of proxying, forwarding, or routing technologies to bridge a protected network with an external network. A defensive analytic to detect a relay network may compare the network sessions among multiple hosts. Hosts which have nearly similar network statistics may be part of a relay network. The statistics may include number of bytes sent to and from, time of session initiation, packet size, or packet arrival time data. In the D3FEND model it analyzes the outbound internet network traffic. It counters ATT&CK techniques T1001, T1008, T1048.001, T1048.002, T1048.003, T1071, T1071.001, T1071.002, T1071.003, T1071.004, and 21 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1001-data-obfuscation",
      "mitre-attack-t1008-fallback-channels",
      "mitre-attack-t1048-001-exfiltration-over-symmetric-encrypted-non-c2-protocol",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-rrid-reverse-resolution-ip-denylisting",
    "title": "MITRE D3FEND D3-RRID: Reverse Resolution IP Denylisting (Defensive Tactic - Isolate -> Reverse Resolution IP Denylisting)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RRID (Reverse Resolution IP Denylisting) is a Isolate defensive technique. Blocking a reverse lookup based on the query's IP address value. This technique prevents a client from learning domains deemed to be potentially malicious, which would have been delivered via reverse resolution responses over the DNS protocol. Queries for reverse resolution requests (that is, requests where IP(s) are sent and a domain is returned) are collected, and the IP address(es) included in the query are examined. If the IP address(es) are in a range included in the blacklist, then the query is dropped. In the D3FEND model it blocks the outbound internet dns lookup traffic. It counters ATT&CK techniques T1071.004, T1568. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-3, AC-4, CA-7, CM-2, CM-6, CM-7, SC-7, SC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1071-004-dns",
      "mitre-attack-t1568-dynamic-resolution",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-rs-restore-software",
    "title": "MITRE D3FEND D3-RS: Restore Software (Defensive Tactic - Restore -> Restore Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RS (Restore Software) is a Restore defensive technique. Restoring software to a host. In the D3FEND model it restores the software. It counters ATT&CK techniques T1014, T1056.003, T1072, T1127.001, T1137.006, T1176, T1195.001, T1195.002, T1212, T1218.014, and 15 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-10, AC-12, AC-16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1014-rootkit",
      "mitre-attack-t1056-003-web-portal-capture",
      "mitre-attack-t1072-software-deployment-tools",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-rta-rpc-traffic-analysis",
    "title": "MITRE D3FEND D3-RTA: RPC Traffic Analysis (Defensive Tactic - Detect -> RPC Traffic Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RTA (RPC Traffic Analysis) is a Detect defensive technique. Monitoring the activity of remote procedure calls in communication traffic to establish standard protocol operations and potential attacker activities. A remote procedure call (RPC) enables one computer to execute a specific function on another computer, as if it were a local application process. There are numerous RPC specifications and implementations. RPC capabilities can be abused by attackers in order to achieve a variety of tactical objectives including execution, persistence, initial access, and more. RPC proxies may be used to collect and store RPC traffic. In the D3FEND model it analyzes the rpc network traffic. It counters ATT&CK technique T1558.003. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, AC-17, AC-18, AC-19.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1558-003-kerberoasting",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-rtsd-remote-terminal-session-detection",
    "title": "MITRE D3FEND D3-RTSD: Remote Terminal Session Detection (Defensive Tactic - Detect -> Remote Terminal Session Detection)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RTSD (Remote Terminal Session Detection) is a Detect defensive technique. Detection of an unauthorized remote live terminal console session by examining network traffic to a network host. An external attacker takes remote control of a host inside a company or organization's network and manually directs offensive techniques. Nonstandard terminal sessions and abnormal behaviors are analyzed in this technique. Abnormal behavior detection includes analysis of user input patterns in the real-time session, keyboard output and packet inspection. In the D3FEND model it analyzes the network traffic. It counters ATT&CK techniques T1001, T1003.006, T1008, T1011, T1018, T1020, T1021, T1021.001, T1021.004, T1029, and 62 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-8, AC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1001-data-obfuscation",
      "mitre-attack-t1003-006-dcsync",
      "mitre-attack-t1008-fallback-channels",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ruaa-restore-user-account-access",
    "title": "MITRE D3FEND D3-RUAA: Restore User Account Access (Defensive Tactic - Restore -> Restore User Account Access)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-RUAA (Restore User Account Access) is a Restore defensive technique. Restoring a user account's access to resources. In the D3FEND model it restores the user account. It counters ATT&CK techniques T1078, T1078.001, T1078.002, T1078.003, T1078.004, T1087.001, T1087.002, T1087.004, T1098, T1098.002, and 7 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1078-001-default-accounts",
      "mitre-attack-t1078-002-domain-accounts",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-saor-segment-address-offset-randomization",
    "title": "MITRE D3FEND D3-SAOR: Segment Address Offset Randomization (Defensive Tactic - Harden -> Segment Address Offset Randomization)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SAOR (Segment Address Offset Randomization) is a Harden defensive technique. Randomizing the base (start) address of one or more segments of memory during the initialization of a process. Many application exploits rely on an attacker specifying a location in memory, which points to data or code used by the attacker. If the addresses are changed each time the program is run, then it becomes more difficult for the attacker to determine the location that will contain the code they wish to run. In the D3FEND model it obfuscates the process segment. It counters ATT&CK techniques T1033, T1055.012, T1056.004, T1068, T1189, T1190, T1203, T1210, T1211, T1212, and 2 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-2, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1033-system-owner-user-discovery",
      "mitre-attack-t1055-012-process-hollowing",
      "mitre-attack-t1056-004-credential-api-hooking",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-sbv-service-binary-verification",
    "title": "MITRE D3FEND D3-SBV: Service Binary Verification (Defensive Tactic - Detect -> Service Binary Verification)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SBV (Service Binary Verification) is a Detect defensive technique. Analyzing changes in service binary files by comparing to a source of truth. System service applications may originate from the operating system installation or third-party applications installed with administrative privileges. These services have an entry point of some executable file-- a binary or a script. Attackers sometimes modify these executables to launch their own code. Analyzing changes in these files may uncover unauthorized activity. In the D3FEND model it verifies the service application. It counters ATT&CK techniques T1056.003, T1072, T1212, T1564.006, T1574.005, T1574.010, T1649. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-12, AC-20, CA-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1056-003-web-portal-capture",
      "mitre-attack-t1072-software-deployment-tools",
      "mitre-attack-t1212-exploitation-for-credential-access",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-sca-system-call-analysis",
    "title": "MITRE D3FEND D3-SCA: System Call Analysis (Defensive Tactic - Detect -> System Call Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SCA (System Call Analysis) is a Detect defensive technique. Analyzing system calls to determine whether a process is exhibiting unauthorized behavior. System calls are APIs between a user application and the operating system [1]. By analyzing a process's use of these APIs, it is, in some cases, possible to ascertain whether a program is exhibiting unauthorized behavior, including trying to escalate its privileges. In the D3FEND model it analyzes the system call. It counters ATT&CK techniques T1007, T1010, T1012, T1016, T1018, T1033, T1036.005, T1047, T1049, T1053, and 30 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-16, AC-17, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1007-system-service-discovery",
      "mitre-attack-t1010-application-window-discovery",
      "mitre-attack-t1012-query-registry",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-scf-system-call-filtering",
    "title": "MITRE D3FEND D3-SCF: System Call Filtering (Defensive Tactic - Isolate -> System Call Filtering)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SCF (System Call Filtering) is a Isolate defensive technique. Controlling access to local computer system resources with kernel-level capabilities. System call filtering uses a mandatory access control paradigm (that is, a non-discretionary access control) system because the rules and polices that determine access is determined by a security control authority and not distributed to local users. Access determinations are based on designed access control polices and are not based on local resource owner determinations. Access is typically granted by defining sets of subjects and sets of objects. In the D3FEND model it isolates the process; filters the system call. It counters ATT&CK techniques T1003.001, T1003.002, T1003.004, T1007, T1010, T1012, T1016, T1018, T1033, T1036.005, and 42 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-001-lsass-memory",
      "mitre-attack-t1003-002-security-account-manager",
      "mitre-attack-t1003-004-lsa-secrets",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-sch-source-code-hardening",
    "title": "MITRE D3FEND D3-SCH: Source Code Hardening (Defensive Tactic - Harden)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-SCH (Source Code Hardening) is a defensive technique that hardens source code to make it more difficult to exploit and less error-prone. Covers safer subroutines, pointer/memory validation, mathematical operation safety. Counters ATT&CK T1505 (Server Software Component) including T1505.001 SQL Stored Procedures, T1190 (Exploit Public-Facing Application), T1068 (Exploitation for Privilege Escalation), T1203 (Exploitation for Client Execution). Required under NIST SP 800-53 SA-15 + SA-11, NIST SP 800-218 SSDF, OWASP ASVS V5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1505-server-software-component",
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-d3fend-d3-ach-application-configuration-hardening",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-scp-system-configuration-permissions",
    "title": "MITRE D3FEND D3-SCP: System Configuration Permissions (Defensive Tactic - Harden -> System Configuration Permissions)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SCP (System Configuration Permissions) is a Harden defensive technique. Restricting system configuration modifications to a specific user or group of users. In the D3FEND model it restricts the system configuration database. It counters ATT&CK techniques T1012, T1112, T1137.006, T1207, T1218.014, T1543.003, T1546.012, T1546.015, T1548.004, T1552.002, and 3 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-10, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1012-query-registry",
      "mitre-attack-t1112-modify-registry",
      "mitre-attack-t1137-006-add-ins",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-sdm-system-daemon-monitoring",
    "title": "MITRE D3FEND D3-SDM: System Daemon Monitoring (Defensive Tactic - Detect -> System Daemon Monitoring)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SDM (System Daemon Monitoring) is a Detect defensive technique. Tracking changes to the state or configuration of critical system level processes. Attackers may manipulate system settings or services to disable system logging or monitoring of security tools and events. Firewall and antivirus services are popular targets for attackers. Disabling system logs will also allow an attacker's actions to go unnoticed. Analysis of logs, registries, and process monitoring help defenders locate signs of tampering. In the D3FEND model it monitors the operating system process. It counters ATT&CK techniques T1053, T1053.005, T1562.001. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1053-scheduled-task-job",
      "mitre-attack-t1053-005-scheduled-task",
      "mitre-attack-t1685-disable-or-modify-tools",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-sfa-system-file-analysis",
    "title": "MITRE D3FEND D3-SFA: System File Analysis (Defensive Tactic - Detect -> System File Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SFA (System File Analysis) is a Detect defensive technique. Monitoring system files such as authentication databases, configuration files, system logs, and system executables for modification or tampering. This technique ensures the integrity of system owned file resources. System files can impact the behavior below the user level. In the D3FEND model it analyzes the operating system file. It counters ATT&CK techniques T1003.007, T1018, T1036.003, T1055.009, T1070.002, T1543.002, T1548.003, T1556.003, T1574.006. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-007-proc-filesystem",
      "mitre-attack-t1018-remote-system-discovery",
      "mitre-attack-t1036-003-rename-system-utilities",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-sfcv-stack-frame-canary-validation",
    "title": "MITRE D3FEND D3-SFCV: Stack Frame Canary Validation (Defensive Tactic - Harden -> Stack Frame Canary Validation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SFCV (Stack Frame Canary Validation) is a Harden defensive technique. Comparing a value stored in a stack frame with a known good value in order to prevent or detect a memory segment overwrite. This defense must be applied at compile-time, or via a patch to the program binary. Stack Frame Canary Verification inserts instructions at the prologue and epilogue of desired functions. In the prologue, a canary value, typically with the same size as the register size, is stored in the system of record and on the stack. Typically, the canary is loaded to where it has a memory address just below that of the saved instruction pointer and base pointer. In the D3FEND model it validates the stack frame. It counters ATT&CK techniques T1068, T1203, T1210, T1211, T1212. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-2, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1068-exploitation-privilege-escalation",
      "mitre-attack-t1203-exploitation-for-client-execution",
      "mitre-attack-t1210-exploitation-of-remote-services",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-sfv-system-firmware-verification",
    "title": "MITRE D3FEND D3-SFV: System Firmware Verification (Defensive Tactic - Detect -> System Firmware Verification)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SFV (System Firmware Verification) is a Detect defensive technique. Cryptographically verifying installed system firmware integrity. Cryptographic hash values are computed for system firmware. The hash values are compared against precomputed firmware hash values to determine if the firmware has been tampered with. When system firmware verification fails a set of predefined responses is typically invoked. The responses may direct the system to disable some devices or operations. In the D3FEND model it verifies the system firmware. It counters ATT&CK techniques T1542.001, T1542.004. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-3, CM-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1542-001-system-firmware",
      "mitre-attack-t1542-004-rommonkit",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-si-software-inventory",
    "title": "MITRE D3FEND D3-SI: Software Inventory (Defensive Tactic - Model -> Software Inventory)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE D3FEND D3-SI (Software Inventory) is a Model defensive technique. In the D3FEND model it inventories Software. It is part of the Asset Inventory D3FEND parent category and counters ATT&CK techniques T1072, T1547.008, T1546.011, T1574.010, T1574.005, T1490, T1056.003, T1497.003, T1505.004, T1542.003, T1137.006, T1542.004, and 13 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls in the AC, IA, AU, CM, SI, SC, SA families.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-d3fend-d3-sica-system-init-config-analysis",
    "title": "MITRE D3FEND D3-SICA: System Init Config Analysis (Defensive Tactic - Detect -> System Init Config Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SICA (System Init Config Analysis) is a Detect defensive technique. Analysis of any system process startup configuration. In the D3FEND model it analyzes the system init configuration. It counters ATT&CK techniques T1037.004, T1037.005, T1547.001, T1562.009, T1574.011. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-17, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1037-004-rc-scripts",
      "mitre-attack-t1037-005-startup-items",
      "mitre-attack-t1547-001-registry-run-keys-startup-folder",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-sja-scheduled-job-analysis",
    "title": "MITRE D3FEND D3-SJA: Scheduled Job Analysis (Defensive Tactic - Detect -> Scheduled Job Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SJA (Scheduled Job Analysis) is a Detect defensive technique. Analysis of source files, processes, destination files, or destination servers associated with a scheduled job to detect unauthorized use of job scheduling. Scheduled job execution can be utilized by adversaries for the purpose of persistence, conducting remote execution, or gaining privileges. Details of a scheduled job such as associated source files, processes, destination files, or destination servers are first identified and analyzed and then compared against an anti-malware signature database, whitelist, or reputation server. In the D3FEND model it analyzes the job schedule. It counters ATT&CK techniques T1036.004, T1053. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1036-004-masquerade-task-or-service",
      "mitre-attack-t1053-scheduled-task-job",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-smra-sender-mta-reputation-analysis",
    "title": "MITRE D3FEND D3-SMRA: Sender MTA Reputation Analysis (Defensive Tactic - Detect -> Sender MTA Reputation Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SMRA (Sender MTA Reputation Analysis) is a Detect defensive technique. Characterizing the reputation of mail transfer agents (MTA) to determine the security risk in emails. The sender message transfer agent (MTA) trust rating can be considered an indicator of the level of security risk and/or a trust level associated with sender MTAs in an email header. The features considered in determining the trust rating may include: Length of time MTA has interacted with the enterprise Number of sender domains sending emails from the MTA Number of recipients in the enterprise the MTA sends emails to Number of emails received from this. In the D3FEND model it analyzes the email. It counters ATT&CK techniques T1114.001, T1534, T1566.001, T1566.002. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-19, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1114-001-local-email-collection",
      "mitre-attack-t1534-internal-spearphishing",
      "mitre-attack-t1566-001-spearphishing-attachment",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-spp-strong-password-policy",
    "title": "MITRE D3FEND D3-SPP: Strong Password Policy (Defensive Tactic - Harden -> Credential Hardening)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-SPP (Strong Password Policy) is a defensive technique that enforces password complexity, length, breach-corpus screening, and reuse prevention to defeat brute-force, dictionary, and credential-stuffing attacks. SPP aligns with modern NIST SP 800-63B guidance: minimum 8 characters (15 for privileged), supports very long passwords (64+), no composition rules, no periodic rotation absent compromise, screening against HaveIBeenPwned and Microsoft Banned Password List. SPP counters ATT&CK techniques T1110 (Brute Force) all sub-techniques, T1078 (Valid Accounts), T1212 (Exploitation for Credential Access), T1003 (OS Credential Dumping where weak passwords accelerate cracking). Required under NIST SP 800-53 IA-5 (Authenticator Management), PCI DSS v4.0 Req 8.3, NIS2 Article 21(2)(j), HIPAA Security Rule.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1110-brute-force",
      "mitre-attack-t1078-valid-accounts",
      "mitre-d3fend-d3-ch-credential-hardening",
      "mitre-d3fend-d3-mfa-multi-factor-authentication",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-sra-sender-reputation-analysis",
    "title": "MITRE D3FEND D3-SRA: Sender Reputation Analysis (Defensive Tactic - Detect -> Sender Reputation Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SRA (Sender Reputation Analysis) is a Detect defensive technique. Ascertaining sender reputation based on information associated with a message (e.g. email/instant messaging). Sender trust rating can be considered an indicator of the level of security risk and/or a trust level associated with a sender. The features considered in determining the trust rating include: Length of time sender has sent emails to the enterprise Number of recipients in the enterprise the sender interacts with Sender vs. enterprise originated message ratio Sender messages opened vs. In the D3FEND model it analyzes the email. It counters ATT&CK techniques T1114.001, T1534, T1566.001, T1566.002. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-3, AC-4, AC-16, AC-17, AC-19, AC-20, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1114-001-local-email-collection",
      "mitre-attack-t1534-internal-spearphishing",
      "mitre-attack-t1566-001-spearphishing-attachment",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ssc-shadow-stack-comparisons",
    "title": "MITRE D3FEND D3-SSC: Shadow Stack Comparisons (Defensive Tactic - Detect -> Shadow Stack Comparisons)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SSC (Shadow Stack Comparisons) is a Detect defensive technique. Comparing a call stack in system memory with a shadow call stack maintained by the processor to determine unauthorized shellcode activity. This technique compares the call stack stored in system memory with the shadow call stack maintained in the cache memory of the processor. Mismatches between the two are compared since a return oriented programming attack may only be able to control or spoof the call stack and not the shadow call stack. In the D3FEND model it analyzes the stack frame. It counters ATT&CK techniques T1068, T1203, T1210, T1211, T1212. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, CA-2, CA-7, CM-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1068-exploitation-privilege-escalation",
      "mitre-attack-t1203-exploitation-for-client-execution",
      "mitre-attack-t1210-exploitation-of-remote-services",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-st-session-termination",
    "title": "MITRE D3FEND D3-ST: Session Termination (Defensive Tactic - Evict -> Session Termination)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-ST (Session Termination) is a Evict defensive technique. Forcefully end all active sessions associated with compromised accounts or devices. In the D3FEND model it deletes the session. It counters ATT&CK techniques T1021.001, T1021.004, T1133, T1134.003, T1199, T1563, T1563.001, T1563.002. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-8, AC-11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1021-001-remote-desktop-protocol",
      "mitre-attack-t1021-004-ssh",
      "mitre-attack-t1133-external-remote-services",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-su-software-update",
    "title": "MITRE D3FEND D3-SU: Software Update (Defensive Tactic - Harden -> Software Update)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SU (Software Update) is a Harden defensive technique. Replacing old software on a computer system component. In the D3FEND model it updates the software. It counters ATT&CK techniques T1014, T1056.003, T1072, T1127.001, T1137.006, T1176, T1195.001, T1195.002, T1212, T1218.014, and 15 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-10, AC-12, AC-16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1014-rootkit",
      "mitre-attack-t1056-003-web-portal-capture",
      "mitre-attack-t1072-software-deployment-tools",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-sysm-system-mapping",
    "title": "MITRE D3FEND D3-SYSM: System Mapping (Defensive Tactic - Model -> System Mapping)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-SYSM (System Mapping) is a defensive technique that enumerates and documents system architecture - components, interfaces, trust boundaries, software stacks, and configuration baselines - to enable hardening, vulnerability management, and detection-coverage assessment. SYSM extends D3-AI (Asset Inventory) by capturing structural relationships between assets. Required under NIST SP 800-53 CM-2 (Baseline Configuration), CM-8(7) (Centralised Repository), CA-3 (Information Exchange), ISO 27001 A.5.9 and A.5.34, CIS Critical Security Controls v8 Control 4 (Secure Configuration of Enterprise Assets and Software), and DORA Article 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1190-exploit-public-facing-application",
      "mitre-attack-t1218-system-binary-proxy-execution",
      "mitre-d3fend-d3-ai-asset-inventory",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-sysva-system-vulnerability-assessment",
    "title": "MITRE D3FEND D3-SYSVA: System Vulnerability Assessment (Defensive Tactic - Model -> System Vulnerability Assessment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-SYSVA (System Vulnerability Assessment) is a Model defensive technique. System vulnerability assessment relates all the vulnerabilities of a system's components in the context of their configuration and internal dependencies and can also include assessing risk emerging from the system's design as a whole, not just the sum of individual component vulnerabilities. In the D3FEND model it evaluates the digital system; identifies the vulnerability. It counters ATT&CK technique T1562.010. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, CA-7, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1689-downgrade-attack",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-tb-token-binding",
    "title": "MITRE D3FEND D3-TB: Token Binding (Defensive Tactic - Harden -> Token Binding)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-TB (Token Binding) is a Harden defensive technique. Token binding is a security mechanism used to enhance the protection of tokens, such as cookies or OAuth tokens, by binding them to a specific connection. When issuing a security token to a client that supports Token Binding, a server includes the client's Token Binding ID (or its cryptographic hash) in the token. Later on, when a client presents a security token containing a Token Binding ID, the server verifies that the ID in the token matches the ID of the Token Binding established with the client. In the case of a mismatch, the server rejects the token. In the D3FEND model it strengthens the access token. It counters ATT&CK techniques T1134.001, T1134.002, T1134.003, T1528, T1550.001, T1558, T1558.001. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-10, AC-16, AC-17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1134-001-token-impersonation-theft",
      "mitre-attack-t1134-002-create-process-with-token",
      "mitre-attack-t1134-003-make-and-impersonate-token",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-tba-token-based-authentication",
    "title": "MITRE D3FEND D3-TBA: Token-based Authentication (Defensive Tactic - Harden -> Token-based Authentication)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-06",
    "bluf": "MITRE D3FEND D3-TBA (Token-based Authentication) is a Harden defensive technique. In the D3FEND model it uses Access Token. It is part of the Agent Authentication D3FEND parent category and counters ATT&CK techniques T1550.001, T1134.001, T1134.002, T1134.003, T1558.001, T1558, T1528. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls in the AC, IA, AU, CM, SI, SC, SA families.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mitre-d3fend-d3-tl-trusted-library",
    "title": "MITRE D3FEND D3-TL: Trusted Library (Defensive Tactic - Harden -> Trusted Library)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-TL (Trusted Library) is a Harden defensive technique. A trusted library is a collection of pre-verified and secure code modules or components that are used within software applications to perform specific functions. These libraries are considered reliable and have been vetted for security vulnerabilities, ensuring they do not introduce risks into the application. Using a trusted library can reduce the chances of introducing errors compared to writing code from scratch. In the D3FEND model it hardens the subroutine. It counters ATT&CK technique T1505.001. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1505-001-sql-stored-procedures",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ua-url-analysis",
    "title": "MITRE D3FEND D3-UA: URL Analysis (Defensive Tactic - Detect -> URL Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-UA (URL Analysis) is a Detect defensive technique. Determining if a URL is benign or malicious by analyzing the URL or its components. URLs may contain components, for example: scheme userinfo host name port path query fragment These components are used as features in analysis algorithms. Contextual information about a URL such as where it is embedded (ex. emails, files, network protocols), header, path, location, and origin information, as well as information about the content returned from the URL request, may be incorporated into an analytic for URL analysis. In the D3FEND model it analyzes the url. It counters ATT&CK techniques T1189, T1204.001, T1566.002, T1566.003. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-4, AC-6, CA-7, CM-2, CM-6, CM-7, CM-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1189-drive-by-compromise",
      "mitre-attack-t1204-001-malicious-link",
      "mitre-attack-t1566-002-spearphishing-link",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-uap-user-account-permissions",
    "title": "MITRE D3FEND D3-UAP: User Account Permissions (Defensive Tactic - Isolate -> User Account Permissions)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-UAP (User Account Permissions) is a Isolate defensive technique. Restricting a user account's access to resources. In the D3FEND model it restricts the user account. It counters ATT&CK techniques T1078, T1078.001, T1078.002, T1078.003, T1078.004, T1087.001, T1087.002, T1087.004, T1098, T1098.002, and 7 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1078-001-default-accounts",
      "mitre-attack-t1078-002-domain-accounts",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-uba-user-behavior-analysis",
    "title": "MITRE D3FEND D3-UBA: User Behavior Analysis (Defensive Tactic - Detect)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-12",
    "bluf": "MITRE D3FEND D3-UBA (User Behavior Analysis) is a defensive technique that uses patterns of human behavior and statistical analysis to detect meaningful anomalies indicating insider threats, targeted attacks, and fraud. UBA examines user patterns (login frequency from single IPs, unusual file downloads, atypical access times) rather than device characteristics. Counters ATT&CK T1110 (Brute Force) including all sub-techniques, T1078 (Valid Accounts), T1134 (Access Token Manipulation), T1098 (Account Manipulation), T1021 (Remote Services). Required under NIST SP 800-53 SI-4 (System Monitoring), AU-6 (Audit Record Review), PM-12 (Insider Threat Program).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1110-brute-force",
      "mitre-d3fend-d3-oam-operational-activity-mapping",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mitre-d3fend-d3-uglpa-user-geolocation-logon-pattern-analysis",
    "title": "MITRE D3FEND D3-UGLPA: User Geolocation Logon Pattern Analysis (Defensive Tactic - Detect -> User Geolocation Logon Pattern Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-UGLPA (User Geolocation Logon Pattern Analysis) is a Detect defensive technique. Monitoring geolocation data of user logon attempts and comparing it to a baseline user behavior profile to identify anomalies in logon location. Geolocation data for each user logon attempt is collected and used to create a baseline user behavior profile. Current geolocation logon data is then compared against the user behavior profile. Logon activity that deviates from normal patterns and can help in identifying situations that may be indicative of a remote attacker using stolen credentials. In the D3FEND model it analyzes the network traffic. It counters ATT&CK techniques T1001, T1003.006, T1008, T1011, T1018, T1020, T1021, T1021.001, T1021.004, T1029, and 62 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-8, AC-10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1001-data-obfuscation",
      "mitre-attack-t1003-006-dcsync",
      "mitre-attack-t1008-fallback-channels",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ula-unlock-account",
    "title": "MITRE D3FEND D3-ULA: Unlock Account (Defensive Tactic - Restore -> Unlock Account)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-ULA (Unlock Account) is a Restore defensive technique. Restoring a user account's access to resources by unlocking a locked User Account. In the D3FEND model it restores the user account. It counters ATT&CK techniques T1078, T1078.001, T1078.002, T1078.003, T1078.004, T1087.001, T1087.002, T1087.004, T1098, T1098.002, and 7 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1078-valid-accounts",
      "mitre-attack-t1078-001-default-accounts",
      "mitre-attack-t1078-002-domain-accounts",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-ura-url-reputation-analysis",
    "title": "MITRE D3FEND D3-URA: URL Reputation Analysis (Defensive Tactic - Detect -> URL Reputation Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-URA (URL Reputation Analysis) is a Detect defensive technique. Analyzing the reputation of a URL. In the D3FEND model it analyzes the url. It counters ATT&CK techniques T1189, T1204.001, T1566.002, T1566.003. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-4, AC-6, CA-7, CM-2, CM-6, CM-7, CM-8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1189-drive-by-compromise",
      "mitre-attack-t1204-001-malicious-link",
      "mitre-attack-t1566-002-spearphishing-link",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-usica-user-session-init-config-analysis",
    "title": "MITRE D3FEND D3-USICA: User Session Init Config Analysis (Defensive Tactic - Detect -> User Session Init Config Analysis)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-USICA (User Session Init Config Analysis) is a Detect defensive technique. Analyzing modifications to user session config files such as .bashrc or .bash_profile. In the D3FEND model it analyzes the user init configuration file. It counters ATT&CK techniques T1546.004, T1564.002. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-6, CA-7, CM-2, CM-3, CM-6, CM-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1546-004-unix-shell-configuration-modification",
      "mitre-attack-t1564-002-hidden-users",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-vi-variable-initialization",
    "title": "MITRE D3FEND D3-VI: Variable Initialization (Defensive Tactic - Harden -> Variable Initialization)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-VI (Variable Initialization) is a Harden defensive technique. Setting variables to a known value before use. Initializing variables upon declaration ensures that the variable has a known quantity before use. In the D3FEND model it hardens the subroutine. It counters ATT&CK technique T1505.001. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-5, AC-6, AC-16, CM-2, CM-5, CM-6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1505-001-sql-stored-procedures",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-d3fend-d3-vs-video-surveillance",
    "title": "MITRE D3FEND D3-VS: Video Surveillance (Defensive Tactic - Detect -> Video Surveillance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-VS (Video Surveillance) is a Detect defensive technique. Monitoring of physical areas via camera video feeds to deter, detect, and investigate unauthorized access and related security events. Video surveillance uses digital cameras that stream to a video management system (VMS) or network video recorder (NVR) for live monitoring, recording, and retrieval. Recording can be continuous or event-driven using analytics (motion in regions of interest, line crossing) or external triggers (access denials, sensor alarms). Time synchronization aligns video with other logs, while health monitoring detects camera outages and tamper. In the D3FEND model it monitors the digital camera. It counters ATT&CK technique T1125.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1125-video-capture",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-d3fend-d3-wsam-web-session-access-mediation",
    "title": "MITRE D3FEND D3-WSAM: Web Session Access Mediation (Defensive Tactic - Isolate -> Web Session Access Mediation)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE D3FEND D3-WSAM (Web Session Access Mediation) is a Isolate defensive technique. Web session access mediation secures user sessions in web applications by employing robust authentication and integrity validation, along with adaptive threat mitigation techniques, to ensure that access to web resources is authorized and protected from session-related attacks. Web Session Access Mediation involves managing user access to web applications and services, ensuring secure and authorized sessions. This includes authenticating users, maintaining session integrity, and protecting against threats like session hijacking. Examples include accessing corporate intranets, SaaS applications, or online portals. In the D3FEND model it isolates the service application process. It counters ATT&CK techniques T1003.001, T1003.002, T1033, T1212, T1505.002, T1550, T1556, T1621. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-16, AC-20.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-t1003-001-lsass-memory",
      "mitre-attack-t1003-002-security-account-manager",
      "mitre-attack-t1033-system-owner-user-discovery",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-emb3d-tid-101-power-consumption-analysis-side-channel",
    "title": "MITRE EMB3D TID-101: Power Consumption Analysis Side Channel (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-101 (Power Consumption Analysis Side Channel) is an embedded-device threat in the Hardware category. Devices will oftentimes consume variable amounts of power depending on the operations the device is performing. Power consumption analysis involves the reading and analyzing of power usage of a device. If a device is vulnerable to a power consumption analysis attack, it may be possible to extract or deduce information about the operating state of the device. It applies to devices with the property: Device includes a microprocessor. Associated weaknesses: CWE-1300, CWE-1255. EMB3D-documented mitigations include MID-027 Validated Cryptographic Libraries, MID-059 Software Patterns for Side Channel Resistance, MID-060 Dedicated Hardware Cryptographic Modules. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-102-electromagnetic-analysis-side-channel",
    "title": "MITRE EMB3D TID-102: Electromagnetic Analysis Side Channel (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-102 (Electromagnetic Analysis Side Channel) is an embedded-device threat in the Hardware category. Devices will oftentimes emit different electromagnetic signals during different operations. Electromagnetic analysis involves the collection and analysis of these signals. If devices are vulnerable to electromagnetic analysis attacks, it may be possible for attackers with physical device presence to extract secrets, such as encryption keys, by analyzing the electromagnetic radiation that is emitted by the device. It applies to devices with the property: Device includes a microprocessor. Associated weaknesses: CWE-1300. EMB3D-documented mitigations include MID-027 Validated Cryptographic Libraries, MID-059 Software Patterns for Side Channel Resistance, MID-060 Dedicated Hardware Cryptographic Modules. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-103-microarchitectural-side-channels",
    "title": "MITRE EMB3D TID-103: Microarchitectural Side Channels (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-103 (Microarchitectural Side Channels) is an embedded-device threat in the Hardware category. Operating system memory safety models rely on processor hardware to enforce separation between different virtual memory spaces. Failures of processor architectures to properly deliver these security guarantees can lead to sensitive information being disclosed across the boundaries between different kernel and process memory spaces. The performance optimization features in modern processors have been shown to be a source of such data leakage vulnerabilities. It applies to devices with the property: Device includes a microprocessor. Associated weaknesses: CWE-1037, CWE-1264. EMB3D-documented mitigations include MID-014 Sandboxing, MID-050 Operating System Defenses Against Microarchitecture Feature Side Channels, MID-051 Disallow User-Provided Code, MID-061 Use Separate Processors for Isolation. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-105-hardware-fault-injection-control-flow-modification",
    "title": "MITRE EMB3D TID-105: Hardware Fault Injection - Control Flow Modification (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-105 (Hardware Fault Injection - Control Flow Modification) is an embedded-device threat in the Hardware category. A threat actor with physical access to a device may be able to manipulate the processor's intended code execution by subjecting it to hardware faults or \"glitching\". Hardware faults can be induced by various methods, including voltage fault injection (power glitching), electromagnetic pulses (EM glitching), and optical fault injection. It applies to devices with the property: Device includes a microprocessor. Associated weaknesses: CWE-1247, CWE-1319. EMB3D-documented mitigations include MID-062 Hardware Mitigations for Fault Injection, MID-063 Software Mitigations for Fault Injection, MID-066 Implement Redundant Processing and Memory. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-106-data-bus-interception",
    "title": "MITRE EMB3D TID-106: Data Bus Interception (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-106 (Data Bus Interception) is an embedded-device threat in the Hardware category. A threat actor could intercept data across a data bus used to connect a process to either volatile memory or non-volatile storage (e.g. ROM, NVRAM, disk). Depending on the scope of the interception, it may be possible to read and/or perform an adversary-in-the-middle (AITM) attack to write information going over the bus, especially if it lacks adequate encryption and authentication. It applies to devices with the property: Device includes buses for external memory/storage. Associated weaknesses: CWE-311, CWE-319. EMB3D-documented mitigations include MID-052 Physically Protect Circuit Board Traces and Chip Pins, MID-054 Encrypt and Authenticate Non-volatile Storage Contents, MID-055 Use Highly Integrated Processors to Avoid Physical Attacks, MID-064 Store Critical Code and Data in On-Chip Memory, MID-065 RAM Encryption. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-107-unauthorized-direct-memory-access-dma",
    "title": "MITRE EMB3D TID-107: Unauthorized Direct Memory Access (DMA) (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-107 (Unauthorized Direct Memory Access (DMA)) is an embedded-device threat in the Hardware category. If separate discrete chips/peripherals that have access to the same physical memory, a threat actor with access to one peripheral could perform a Direct Memory Access (DMA) attack to maliciously read/write memory from a connected chip or peripheral. This threat is especially relevant if there is insufficient hardware or software restrictions on what memory can be accessed/manipulated. It applies to devices with the property: Device includes discrete chips/devices that have access to the same physical memory. Associated weaknesses: CWE-1260, CWE-119, CWE-284. EMB3D-documented mitigations include MID-053 Use IOMMU to Implement DMA Access Controls, MID-065 RAM Encryption, MID-070 Peripheral Component Authentication. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-108-rom-nvram-data-extraction-or-modification",
    "title": "MITRE EMB3D TID-108: ROM/NVRAM Data Extraction or Modification (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-108 (ROM/NVRAM Data Extraction or Modification) is an embedded-device threat in the Hardware category. Contents of non-volatile memory chips or non-fixed storage (e.g., SD cards, Compact Flash, hard disks, USB sticks) can be directly read out for examination or modification by a chip reader. In some cases this may be possible without removing the chip from the circuit board, but most often this will involve physically desoldering the chip and non-destructively removing it from the device. It applies to devices with the property: Device includes ROM, VRAM, or removable Storage. Associated weaknesses: CWE-311, CWE-312, CWE-1282. EMB3D-documented mitigations include MID-052 Physically Protect Circuit Board Traces and Chip Pins, MID-054 Encrypt and Authenticate Non-volatile Storage Contents, MID-055 Use Highly Integrated Processors to Avoid Physical Attacks, MID-064 Store Critical Code and Data in On-Chip Memory. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-109-ram-chip-contents-readout",
    "title": "MITRE EMB3D TID-109: RAM Chip Contents Readout (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-109 (RAM Chip Contents Readout) is an embedded-device threat in the Hardware category. If a threat actor can physically access a RAM chip, they may be able to readout the contents of the chip. Multiple techniques can be used to extract the contents of RAM, including both runtime and physical access, such as the threat actor can use a Cold-boot attack to physically cool the RAM to minimize the decay of the electrical charge and then physically copy the contents of that RAM. It applies to devices with the property: Device includes Random Access Memory (RAM) chips. Associated weaknesses: CWE-311, CWE-1384. EMB3D-documented mitigations include MID-052 Physically Protect Circuit Board Traces and Chip Pins, MID-055 Use Highly Integrated Processors to Avoid Physical Attacks, MID-065 RAM Encryption. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-110-hardware-fault-injection-data-manipulation",
    "title": "MITRE EMB3D TID-110: Hardware Fault Injection - Data Manipulation (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-110 (Hardware Fault Injection - Data Manipulation) is an embedded-device threat in the Hardware category. Certain software-executed attacks can introduce a fault to the physical hardware of the device, leading to greater access or exploit opportunities. Typically, these kinds of attacks involve performing a software action that would necessitate a predictable and controllable reaction in hardware. It applies to devices with the property: Device includes DDR DRAM. Associated weaknesses: CWE-1256. EMB3D-documented mitigations include MID-014 Sandboxing, MID-051 Disallow User-Provided Code, MID-065 RAM Encryption, MID-066 Implement Redundant Processing and Memory, MID-067 Implement DRAM RowHammer-resistant DRAM and Memory Controllers. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-111-untrusted-external-storage",
    "title": "MITRE EMB3D TID-111: Untrusted External Storage (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-111 (Untrusted External Storage) is an embedded-device threat in the Hardware category. An untrusted storage peripheral (e.g., USB) could be connected to the device. If malicious code is executed from the untrusted storage, or transferred to the device, it could provide a way for a threat actor to get unauthorized code to execute on the device. Further, any files transferred from the untrusted storage could potentially be used to modify critical device configurations or settings files. It applies to devices with the property: Device includes external peripheral interconnects (e.g., USB, Serial). Associated weaknesses: CWE-1299. EMB3D-documented mitigations include MID-056 Allow Device Administrators to Disable Removable Storage Support. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-113-unverified-peripheral-firmware-loaded",
    "title": "MITRE EMB3D TID-113: Unverified Peripheral Firmware Loaded (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-113 (Unverified Peripheral Firmware Loaded) is an embedded-device threat in the Hardware category. A threat actor could manipulate the firmware associated with a device's peripheral or other subcomponent. The threat actor may be able to manipulate actions on the device by sending it commands that were not the original intention of the user or by manipulating a bitstream before it is loaded. There are multiple possible cases where this could occur, including: - Case 1: Peripheral firmware is stored in a dedicated ROM/NVRAM chip. It applies to devices with the property: Device includes peripheral chips and integrated data buses. Associated weaknesses: CWE-1299, CWE-1316. EMB3D-documented mitigations include MID-011 OS Driver/Peripheral Authentication, MID-070 Peripheral Component Authentication. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-114-peripheral-data-bus-interception",
    "title": "MITRE EMB3D TID-114: Peripheral Data Bus Interception (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-114 (Peripheral Data Bus Interception) is an embedded-device threat in the Hardware category. Messages and data passing between discrete sub-components and peripherals may be intercepted and/or modified from through the peripheral bus (e.g., SPI, I2C, ISA, PCI, USB). Captured data may leak sensitive information (e.g., keys, cleartext firmware code) that can aid in reverse engineering and extracting data needed for other stages of an attack. It applies to devices with the property: Device includes peripheral chips and integrated data buses. Associated weaknesses: CWE-311, CWE-319. EMB3D-documented mitigations include MID-052 Physically Protect Circuit Board Traces and Chip Pins, MID-055 Use Highly Integrated Processors to Avoid Physical Attacks, MID-068 Data Bus Encryption and Message Authentication. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-115-firmware-data-extraction-via-hardware-interface",
    "title": "MITRE EMB3D TID-115: Firmware/Data Extraction via Hardware Interface (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-115 (Firmware/Data Extraction via Hardware Interface) is an embedded-device threat in the Hardware category. Unprotected programming or debugging interfaces may be used to extract device firmware, exposing it to reverse engineering that may reveal proprietary information, other exploitable vulnerabilities, or security-sensitive data stored in the firmware (such as keys and passwords). Examples include the Joint Test Action Group (JTAG) interface. It applies to devices with the property: Device includes a hardware access port (e.g., UART, JTAG). Associated weaknesses: CWE-1299, CWE-1191. EMB3D-documented mitigations include MID-057 Disable Physical Development and Debugging Ports, MID-058 Engage Hardware Readout Protection Mechanisms. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-116-latent-privileged-access-port",
    "title": "MITRE EMB3D TID-116: Latent Privileged Access Port (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-116 (Latent Privileged Access Port) is an embedded-device threat in the Hardware category. If a device has a latent user access port, it may be possible for attackers to leverage physical access to obtain privileges that were not accounted for when considering software or remote access controls. It applies to devices with the property: Device includes a hardware access port (e.g., UART, JTAG). Associated weaknesses: CWE-1299, CWE-1191. EMB3D-documented mitigations include MID-057 Disable Physical Development and Debugging Ports. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-118-weak-peripheral-port-electrical-damage-protection",
    "title": "MITRE EMB3D TID-118: Weak Peripheral Port Electrical Damage Protection (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-118 (Weak Peripheral Port Electrical Damage Protection) is an embedded-device threat in the Hardware category. If a threat actor has physical access to a device, they may be able to cause physical damage to the circuit board of a device, in some cases even destroying the device. A malicious actor may short circuit or introduce out-of-spec voltages and currents to pins on external connectors. This can lead to effects as mild as interrupting device functionality, by causing crashes or reboots, or as significant as corrupting data, corrupting firmware, or permanent hardware damage. It applies to devices with the property: Device includes external peripheral interconnects (e.g., USB, Serial). Associated weaknesses: CWE-1384. EMB3D-documented mitigations include MID-069 Electrical Fault Protection. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-119-latent-hardware-debug-port-allows-memory-code-manipulation",
    "title": "MITRE EMB3D TID-119: Latent Hardware Debug Port Allows Memory/Code Manipulation (Embedded Device Threat - Hardware)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-119 (Latent Hardware Debug Port Allows Memory/Code Manipulation) is an embedded-device threat in the Hardware category. Hardware debugging ports (e.g., JTAG, SWD, etc.) oftentimes have high privileges or direct access to the running device's memory and integrated hardware. By leveraging one of these hardware debugging ports, an adversary may be able to read memory values from the device, change the value of a section of memory during runtime, or control the execution of code on the processor. This can give threat actors increased privileges on the device or bypass other security protections. It applies to devices with the property: Device includes a hardware access port (e.g., UART, JTAG). Associated weaknesses: CWE-1191. EMB3D-documented mitigations include MID-057 Disable Physical Development and Debugging Ports, MID-058 Engage Hardware Readout Protection Mechanisms. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-201-inadequate-bootloader-protection-and-verification",
    "title": "MITRE EMB3D TID-201: Inadequate Bootloader Protection and Verification (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-201 (Inadequate Bootloader Protection and Verification) is an embedded-device threat in the System Software category. Some devices utilize bootloaders that are either stored in writable memory or memory that can be made writable. It may then be possible for a threat actor to alter the contents of the device's designated boot code storage locations to inject malicious code or modify the bootloader's operation. This could allow the installation of a \"bootkit\", which is loaded before the operating system and can undermine any security protections within the bootloader or operating system. It applies to devices with the property: Device includes a bootloader. Associated weaknesses: CWE-693, CWE-284. EMB3D-documented mitigations include MID-001 Software Only Bootloader Authentication, MID-002 Hardware-backed Bootloader Authentication, MID-003 Periodic/Continuous Integrity Measurement and Remote Attestation, MID-029 Hardware Root of Trust. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-202-exploitable-system-network-stack-component",
    "title": "MITRE EMB3D TID-202: Exploitable System Network Stack Component (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-202 (Exploitable System Network Stack Component) is an embedded-device threat in the System Software category. Devices may have vulnerabilities within software used to parse various network protocols. If the device does not properly parse a protocol, a threat actor can send improperly formatted messages to the device, which may result in memory corruptions. Vulnerabilities resulting from protocol manipulation can then be used to perform remote code execution or to perform a denial-of-service attack on the device. It applies to devices with the property: Device includes OS/kernel. Associated weaknesses: CWE-20, CWE-121. EMB3D-documented mitigations include MID-004 Memory Hardening Against Code Injection, MID-005 Memory Safe Programming Languages, MID-006 Driver Memory Isolation, MID-007 Control Flow Manipulation Protections, MID-008 Decidable Protocols and Parsers, MID-014 Sandboxing. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-203-malicious-os-kernel-driver-module-installable",
    "title": "MITRE EMB3D TID-203: Malicious OS Kernel Driver/Module Installable (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-203 (Malicious OS Kernel Driver/Module Installable) is an embedded-device threat in the System Software category. Threat actors may be able to install a driver or kernel module with malicious code to load a rootkit and manipulate the OS. Drivers and kernel modules generally operate with a high-level privileges (e.g. Ring 0) and therefore can be used to manipulate the operation of the existing OS. It applies to devices with the property: Device includes an operating system that uses drivers/modules that can be loaded. Associated weaknesses: CWE-306. EMB3D-documented mitigations include MID-001 Software Only Bootloader Authentication, MID-002 Hardware-backed Bootloader Authentication, MID-003 Periodic/Continuous Integrity Measurement and Remote Attestation, MID-009 Runtime System Integrity Checking, MID-010 No Runtime OS Driver Loading, MID-011 OS Driver/Peripheral Authentication. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-204-untrusted-programs-can-access-privileged-os-functions",
    "title": "MITRE EMB3D TID-204: Untrusted Programs Can Access Privileged OS Functions (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-204 (Untrusted Programs Can Access Privileged OS Functions) is an embedded-device threat in the System Software category. Without a correctly enforced operating system privilege model, a compromised or untrusted application program could access to data, memory, or programs associated with the underlying OS or other applications. This could also be used to further manipulate the underlying OS. It applies to devices with the property: Device lacks an access enforcement/privilege mechanism. Associated weaknesses: CWE-693. EMB3D-documented mitigations include MID-012 OS-based Access Control Mechanisms, MID-013 Process and Thread Memory Segmentation, MID-014 Sandboxing, MID-015 Containerization, MID-087 Utilization of Formally Verified OS (Micro-)Kernels. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-205-existing-os-tools-maliciously-used-for-device-manipulation",
    "title": "MITRE EMB3D TID-205: Existing OS Tools Maliciously Used for Device Manipulation (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-205 (Existing OS Tools Maliciously Used for Device Manipulation) is an embedded-device threat in the System Software category. If a threat actor has access to a valid OS account, they can utilize existing OS tools and system calls to install malicious code or manipulate device operations. If the account and privileges are not sufficiently restricted, the threat actor may be able to add their own tools, modify other application layer programs, or even execute commands with elevated privileges (e.g., setuid/setgid). It applies to devices with the property: Device includes and enforces OS user accounts. Associated weaknesses: CWE-693. EMB3D-documented mitigations include MID-012 OS-based Access Control Mechanisms, MID-014 Sandboxing, MID-015 Containerization, MID-016 Least Functionality, MID-017 Security-relevant Auditing and Logging, MID-018 Require Authentication for Privileged Functions. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-206-memory-management-protections-subverted",
    "title": "MITRE EMB3D TID-206: Memory Management Protections Subverted (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-206 (Memory Management Protections Subverted) is an embedded-device threat in the System Software category. While the use of memory permissions, such as non-executable stack and heap memory, can prevent threat actors from injecting and executing malicious code, it is still possible to leverage a process's existing code to perform a malicious function. It applies to devices with the property: Device includes a memory management model, including protections of memory access (read-only/, executable, writable). Associated weaknesses: CWE-284. EMB3D-documented mitigations include MID-004 Memory Hardening Against Code Injection, MID-005 Memory Safe Programming Languages, MID-007 Control Flow Manipulation Protections, MID-019 ROP Gadget Minimization, MID-020 Pointer Authentication, MID-086 Hardware Enforcement of Memory Access. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-207-container-escape",
    "title": "MITRE EMB3D TID-207: Container Escape (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-207 (Container Escape) is an embedded-device threat in the System Software category. Container environments, such as Docker and Kubernetes, share the same underlying kernel as the host operating system. Malicious code that succeeds in executing within a container may attempt to exploit any vulnerabilities present in exposed OS system calls, container management system functions, excessive permissions in shared resources, or other misconfigurations in the environment. It applies to devices with the property: Device includes containers. Associated weaknesses: CWE-693. EMB3D-documented mitigations include MID-022 Segmentation Through Hardware-assisted VMs. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-208-virtual-machine-escape",
    "title": "MITRE EMB3D TID-208: Virtual Machine Escape (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-208 (Virtual Machine Escape) is an embedded-device threat in the System Software category. Virtualization mechanisms allow multiple operating sytem instances to share the same underlying hardware. Hypervisor software is responsible for orchestrating and maintaining the separation between virtual machines (VMs) to ensure that failure or compromise within one VM does not affect others. It applies to devices with the property: Device includes hypervisor. Associated weaknesses: CWE-693. EMB3D-documented mitigations include MID-021 VM Hardening, MID-023 Hypervisor Hardening, MID-087 Utilization of Formally Verified OS (Micro-)Kernels. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-209-host-can-manipulate-guest-virtual-machines",
    "title": "MITRE EMB3D TID-209: Host Can Manipulate Guest Virtual Machines (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-209 (Host Can Manipulate Guest Virtual Machines) is an embedded-device threat in the System Software category. If a threat actor can access a hypervisor's host infrastructure, such as through existing management interfaces, they could use that access to manipulate associated guest/virtualized systems. Since the hypervisor runs underneath the virtual machines, this threat will go undetected by the individual guest environments. It applies to devices with the property: Device includes hypervisor. Associated weaknesses: CWE-306. EMB3D-documented mitigations include MID-023 Hypervisor Hardening, MID-024 Encrypted VM Isolation. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-210-device-vulnerabilities-unpatchable",
    "title": "MITRE EMB3D TID-210: Device Vulnerabilities Unpatchable (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-210 (Device Vulnerabilities Unpatchable) is an embedded-device threat in the System Software category. Threat actors will frequently target device components, like firmware, that have already known vulnerabilities instead of expending the effort to discover new ones. If a device cannot update its firmware, especially upon the discovery of a vulnerability, threat actors may be able to target these vulnerabilities. This is because a vulnerability that is found once will be exploitable on all devices running that firmware in perpetuity. It applies to devices with the property: Device lacks firmware/software update support. Associated weaknesses: CWE-1277, CWE-1329. EMB3D-documented mitigations include MID-025 End-of-Life Management Features, MID-026 Secure Firmware Update. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-211-device-allows-unauthenticated-firmware-installation",
    "title": "MITRE EMB3D TID-211: Device Allows Unauthenticated Firmware Installation (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-211 (Device Allows Unauthenticated Firmware Installation) is an embedded-device threat in the System Software category. If a device does not have a mechanism to authenticate firmware updates, a threat actor may be able to install malicious or corrupt firmware on the device. In such cases, an adversary may craft a customized or maliciously modified firmware update package that, if properly formed, the device will install it without challenge. It applies to devices with the property: Device has firmware or software that is not cryptographically checked for integrity validation. Associated weaknesses: CWE-306. EMB3D-documented mitigations include MID-001 Software Only Bootloader Authentication, MID-002 Hardware-backed Bootloader Authentication, MID-026 Secure Firmware Update. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-212-fw-sw-update-integrity-shared-secrets-extraction",
    "title": "MITRE EMB3D TID-212: FW/SW Update Integrity Shared Secrets Extraction (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-212 (FW/SW Update Integrity Shared Secrets Extraction) is an embedded-device threat in the System Software category. Some devices utilize a shared secret authentication scheme to verify firmware updates. This is an improvement over unauthenticated updates (as in TID-211) and can be coupled with or implemented as symmetric key encryption for added confidentiality. This process requires the shared secret to be present on the device for verification (or decryption). It applies to devices with the property: Device includes a shared key for firmware integrity validation. Associated weaknesses: CWE-12326. EMB3D-documented mitigations include MID-026 Secure Firmware Update, MID-033 Unique and Unpredictable Factory Preinstalled Secret Keys. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-213-faulty-fw-sw-update-integrity-verification",
    "title": "MITRE EMB3D TID-213: Faulty FW/SW Update Integrity Verification (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-213 (Faulty FW/SW Update Integrity Verification) is an embedded-device threat in the System Software category. To avoid the weaknesses of a shared secret verification (see TID-212), devices may utilize a digital signature verification scheme based on asymmetric public key cryptography. However, if the device does not correctly verify a firmware/software signature correctly, a threat actor can bypass the device's authenticity checking mechanisms to upload malicious or corrupt version. The unauthorized firmware could \"brick\" the device, preventing it from being reset. It applies to devices with the property: Device includes digitally signed firmware (with private key). Associated weaknesses: CWE-347. EMB3D-documented mitigations include MID-001 Software Only Bootloader Authentication, MID-002 Hardware-backed Bootloader Authentication, MID-003 Periodic/Continuous Integrity Measurement and Remote Attestation, MID-026 Secure Firmware Update, MID-027 Validated Cryptographic Libraries. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-214-secrets-extracted-from-device-root-of-trust",
    "title": "MITRE EMB3D TID-214: Secrets Extracted from Device Root of Trust (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-214 (Secrets Extracted from Device Root of Trust) is an embedded-device threat in the System Software category. Some device have mutable or immutable secure Roots of Trust (ROTs) that may store keys or secrets. If the device has a ROT mechanism to validate the authenticity of the firmware/software, the ROT can be either a software or hardware mechanisms, such as a Trusted Platform Module (TPM), firmware TPM (fTPM), Secure Element, or similar security module. It applies to devices with the properties: Root of Trust is physically accessible or is not immutable; Device includes cryptographic firmware/software integrity protection mechanisms. Associated weaknesses: CWE-1326. EMB3D-documented mitigations include MID-028 Hardware-backed Key Storage, MID-060 Dedicated Hardware Cryptographic Modules. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-215-unencrypted-sw-fw-updates",
    "title": "MITRE EMB3D TID-215: Unencrypted SW/FW Updates (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-215 (Unencrypted SW/FW Updates) is an embedded-device threat in the System Software category. If the firmware/software update is not encrypted at rest in storage it can be reverse engineered to identify potential vulnerabilities or extract other information needed to protect devices (e.g., passwords, cryptographic keys). Firmware/software updates can often be directly downloaded from the Internet and reverse engineered, however, firmware/software updates that are unencrypted in transit may also be intercepted and analyzed over-the-wire. It applies to devices with the property: Device has unencrypted firmware updates. Associated weaknesses: CWE-311. EMB3D-documented mitigations include MID-026 Secure Firmware Update. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-216-firmware-update-rollbacks-allowed",
    "title": "MITRE EMB3D TID-216: Firmware Update Rollbacks Allowed (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-216 (Firmware Update Rollbacks Allowed) is an embedded-device threat in the System Software category. Firmware updates will oftentimes include fixes to security vulnerabilities, meaning that past versions will contain security threats to the devices. If a threat actor can initiate a firmware update on the device, they may be able to \"upgrade\" to a previous firmware version with known vulnerabilities. By completing an \"upgrade\" to a version with vulnerabilities, the threat actor could then potentially exploit that device to gain additional access or privileges. It applies to devices with the property: Device includes user firmware/software version selection during updates. Associated weaknesses: CWE-1328. EMB3D-documented mitigations include MID-030 Firmware Rollback Protections. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-217-remotely-initiated-updates-can-cause-dos",
    "title": "MITRE EMB3D TID-217: Remotely Initiated Updates Can Cause DoS (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-217 (Remotely Initiated Updates Can Cause DoS) is an embedded-device threat in the System Software category. When firmware/software update process is initiated on a device, it may enter a different operational mode where it stops performing key functions, including networking, data collection, or control functions. Therefore, a threat actor could remotely initiate the firmware/software update to cause a denial of service on the device. It applies to devices with the property: Device includes remotely-initiated firmware/software updates. Associated weaknesses: CWE-400. EMB3D-documented mitigations include MID-026 Secure Firmware Update, MID-031 Physical Presence Validation, MID-032 System Service Availability Manager. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-218-operating-system-susceptible-to-rootkit",
    "title": "MITRE EMB3D TID-218: Operating System Susceptible to Rootkit (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-218 (Operating System Susceptible to Rootkit) is an embedded-device threat in the System Software category. A threat actor may be able to install a rootkit that can manipulate the operating system (OS). Rootkits can evade OS protections by installing themselves at the same privilege-level as the OS. A threat actor can use a rootkit to maintain persistence on the device, evade detection, or execute malicious programs/logic. It applies to devices with the property: Device includes OS/kernel. Associated weaknesses: CWE-693. EMB3D-documented mitigations include MID-001 Software Only Bootloader Authentication, MID-002 Hardware-backed Bootloader Authentication, MID-003 Periodic/Continuous Integrity Measurement and Remote Attestation, MID-009 Runtime System Integrity Checking. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-219-os-kernel-privilege-escalation",
    "title": "MITRE EMB3D TID-219: OS/Kernel Privilege Escalation (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-219 (OS/Kernel Privilege Escalation) is an embedded-device threat in the System Software category. Operating Systems and Kernels frequently run at the highest levels of permissions. If processes with lower permissions are able to exploit a vulnerability in the OS or Kernel (such as a vulnerability enabled by TID-206), they may be able to raise the privileges of their process. If a threat actor were to exploit this vulnerability, they may be able to raise the permissions of a malicious process, thereby granting themselves greater access to the device. It applies to devices with the property: Device includes and enforces OS user accounts. Associated weaknesses: CWE-250. EMB3D-documented mitigations include MID-004 Memory Hardening Against Code Injection, MID-005 Memory Safe Programming Languages, MID-012 OS-based Access Control Mechanisms, MID-086 Hardware Enforcement of Memory Access, MID-087 Utilization of Formally Verified OS (Micro-)Kernels. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-220-unpatchable-hardware-root-of-trust",
    "title": "MITRE EMB3D TID-220: Unpatchable Hardware Root of Trust (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-220 (Unpatchable Hardware Root of Trust) is an embedded-device threat in the System Software category. Hardware roots of trust can be used to support many desirable device security functions, such as secure key and secret storage, secure boot, and firmware integrity measurement. These functions often rely on the root of trust being immutable, preventing a threat actor from making changes to code or data in the root of trust that would undermine the security functions built atop them. It applies to devices with the property: Root of Trust is immutable. Associated weaknesses: CWE-1329. EMB3D-documented mitigations include MID-033 Unique and Unpredictable Factory Preinstalled Secret Keys. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-221-authentication-bypass-by-message-replay",
    "title": "MITRE EMB3D TID-221: Authentication Bypass By Message Replay (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-221 (Authentication Bypass By Message Replay) is an embedded-device threat in the System Software category. Some devices will allow for authentication over the network, but do not implement mechanisms (i.e. nonces, timestamps) to ensure that messages containing credentials cannot be reused. Devices like these are potentially vulnerable to replay attacks. In these attacks, threat actors may be able to take legitimate packets that were sent over the network, capture them, and send them again to the device. It applies to devices with the property: Device includes cryptographic functions for sensitive data, such as encryption or authentication. Associated weaknesses: CWE-294. EMB3D-documented mitigations include MID-036 Cryptographic Nonces, MID-037 Network Timestamps. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-222-critical-system-service-may-be-disabled",
    "title": "MITRE EMB3D TID-222: Critical System Service May Be Disabled (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-222 (Critical System Service May Be Disabled) is an embedded-device threat in the System Software category. Various devices and associated services are necessary to support communications and connections on a network. If a key service is disabled, terminated, or reconfigured, a threat actor can disrupt or disable communications on a network. This could occur on various network equipment, such as switches, firewalls, or routers, along with other devices which may have dedicated processes to facilitate communication with specific protocols or physical mediums (e.g., serial). It applies to devices with the property: Device exposes remote network services. Associated weaknesses: CWE-306, CWE-15. EMB3D-documented mitigations include MID-031 Physical Presence Validation, MID-032 System Service Availability Manager, MID-038 Authenticate for Administrative Actions. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-223-system-susceptible-to-ram-scraping",
    "title": "MITRE EMB3D TID-223: System Susceptible to RAM Scraping (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-223 (System Susceptible to RAM Scraping) is an embedded-device threat in the System Software category. If the threat actor can obtain sufficient privileges on the devices, they may be able to install runtime tools to directly extract the contents of some or all of the system RAM. This can grant the actor access to the internal state of other applications executing on the device as they process potentially sensitive data (e.g., password, keys, credentials, financial data, PII, etc.) even if that data is never committed to storage in a file or database. It applies to devices with the property: Device includes a memory management model, including protections of memory access (read-only/, executable, writable). Associated weaknesses: CWE-284. EMB3D-documented mitigations include MID-065 RAM Encryption. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-224-excessive-access-via-software-diagnostic-features",
    "title": "MITRE EMB3D TID-224: Excessive Access via Software Diagnostic Features (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-224 (Excessive Access via Software Diagnostic Features) is an embedded-device threat in the System Software category. If a device has debugging capabilities (e.g., diagnostic tools, debug logs, etc.) that are not authenticated or can be accessed in unintended ways, it may be possible for a threat actor to attach to these debuggers. Debuggers frequently have privileged access, which would give the threat actors increased access over the device. It applies to devices with the property: Device includes a debugging capabilities. Associated weaknesses: CWE-1295. EMB3D-documented mitigations include MID-018 Require Authentication for Privileged Functions, MID-039 Restrict Software Diagnostic Functions. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-225-logs-can-be-manipulated-on-the-device",
    "title": "MITRE EMB3D TID-225: Logs can be manipulated on the device (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-225 (Logs can be manipulated on the device) is an embedded-device threat in the System Software category. Threat actors may try to manipulate logs on the device to evade defenses, confuse incident responders, hide their access techniques, or keep their exploitation methods secret. Threat actors can do this by changing the timestamps on logs, deleting logs entirely, inserting or reporting false logs, restoring the device to a previous state, or factory resetting the device. It applies to devices with the properties: Device stores logs of system events and information; Device stores logs of application events and information. Associated weaknesses: CWE-284. EMB3D-documented mitigations include MID-038 Authenticate for Administrative Actions, MID-085 Export Logs Over the Network Off of Device. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-226-device-leaks-security-information-in-logs",
    "title": "MITRE EMB3D TID-226: Device leaks security information in logs (Embedded Device Threat - System Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-226 (Device leaks security information in logs) is an embedded-device threat in the System Software category. Some devise will login information that can be exploited by attackers to further their attack against the device or the system in which the device resides. This data can vary, but in general if a device logs any secrets that would break it's safety, confidentiality, integrity, or availability, a threat actor may be able to use that information to further their goals. It applies to devices with the properties: Device stores logs of system events and information; Device stores logs of application events and information. Associated weaknesses: CWE-200, CWE-532. EMB3D-documented mitigations include MID-084 Restrict Sensitive Data from Logs. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-301-applications-binaries-modified",
    "title": "MITRE EMB3D TID-301: Applications Binaries Modified (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-301 (Applications Binaries Modified) is an embedded-device threat in the Application Software category. A threat actor could modify application-level binaries or libraries on the device to introduce unauthorized code, maintain persistence, or evade detection. This could also include the modification of runtime libraries used to support the execution of programs, along with key PLC function blocks used to structure the execution of application function blocks, such as organizational blocks. It applies to devices with the property: Application-level software is present and running on the device. Associated weaknesses: CWE-862. EMB3D-documented mitigations include MID-001 Software Only Bootloader Authentication, MID-002 Hardware-backed Bootloader Authentication, MID-003 Periodic/Continuous Integrity Measurement and Remote Attestation, MID-009 Runtime System Integrity Checking. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-302-install-untrusted-application",
    "title": "MITRE EMB3D TID-302: Install Untrusted Application (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-302 (Install Untrusted Application) is an embedded-device threat in the Application Software category. A threat actor can install a malicious program to the device to manipulate its operations or prevent the device from operating as expected. Devices can utilize a variety of different approaches to support the download, modification, and execution of programs/logic. It applies to devices with the property: Device includes the ability to deploy custom or external programs (e.g., ladder logic, compiled binaries). Associated weaknesses: CWE-494. EMB3D-documented mitigations include MID-003 Periodic/Continuous Integrity Measurement and Remote Attestation, MID-009 Runtime System Integrity Checking, MID-031 Physical Presence Validation, MID-038 Authenticate for Administrative Actions, MID-040 Cryptographically Signed Custom Programs, MID-041 Cryptographically Signed Vendor-supplied Programs. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-303-excessive-trust-in-offboard-management-ide-software",
    "title": "MITRE EMB3D TID-303: Excessive Trust in Offboard Management/IDE Software (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-303 (Excessive Trust in Offboard Management/IDE Software) is an embedded-device threat in the Application Software category. If device management is intended to be performed by a dedicated engineering software platform or integrated development environment (IDE), the threat actor could potentially modify the software platform, such as by manipulating key .dlls, to install malicious code or manipulate the operation of the device. This can provide the threat actor with a mechanism to bypass protections/countermeasures. It applies to devices with the property: Device includes ability to deploy custom programs from engineering software or IDE. Associated weaknesses: CWE-114. EMB3D-documented mitigations include MID-041 Cryptographically Signed Vendor-supplied Programs. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-304-manipulate-runtime-environment",
    "title": "MITRE EMB3D TID-304: Manipulate Runtime Environment (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-304 (Manipulate Runtime Environment) is an embedded-device threat in the Application Software category. A threat actor can manipulate the runtime environments on a device to maintain persistence on the device and overwrite various functionalities, such as protocol handlers. If the application program (which the threat actor can deploy on the device through a program download) has access to memory where the runtime environment and libraries are located, they could overwrite these libraries with malicious code. It applies to devices with the property: Device includes a program runtime environment for custom or external programs. Associated weaknesses: CWE-119. EMB3D-documented mitigations include MID-009 Runtime System Integrity Checking, MID-012 OS-based Access Control Mechanisms, MID-013 Process and Thread Memory Segmentation, MID-014 Sandboxing, MID-015 Containerization, MID-089 Formal Methods Verification of Critical Functionality Implementation. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-305-program-executes-dangerous-system-calls",
    "title": "MITRE EMB3D TID-305: Program Executes Dangerous System Calls (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-305 (Program Executes Dangerous System Calls) is an embedded-device threat in the Application Software category. If the device allows the downloading and execution of native binaries on the device, a threat actor can deploy a malicious program that leverages the environment's privileges to gain unwanted or excessive access to the device, such as through \"dangerous\" system calls. These system calls could be used to manipulate the device's firmware, maintain persistence, execute unwanted logic, or obtain a C2 channel. It applies to devices with the property: Device includes ability to run custom/external programs as native binary without a confined/restricted environment. Associated weaknesses: CWE-250. EMB3D-documented mitigations include MID-012 OS-based Access Control Mechanisms, MID-014 Sandboxing, MID-015 Containerization. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-306-sandboxed-environments-escaped",
    "title": "MITRE EMB3D TID-306: Sandboxed Environments Escaped (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-306 (Sandboxed Environments Escaped) is an embedded-device threat in the Application Software category. While restricting the execution of external programs within a sandboxed execution environment can mitigate the threat of programs having excessive privileges or memory access, vulnerabilities within that environment could be exploited to escape the sandbox. This would allow the threat actor to escalate their privileges to more broadly manipulate the device's operation and evade detections. It applies to devices with the property: Device includes ability to run custom/external programs/processes through an execution sandboxed environment. Associated weaknesses: CWE-693. EMB3D-documented mitigations include MID-012 OS-based Access Control Mechanisms, MID-022 Segmentation Through Hardware-assisted VMs, MID-089 Formal Methods Verification of Critical Functionality Implementation. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-307-device-code-representations-inconsistent",
    "title": "MITRE EMB3D TID-307: Device Code Representations Inconsistent (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-307 (Device Code Representations Inconsistent) is an embedded-device threat in the Application Software category. Many devices that allow the execution of custom application programs, such as IEC 61131 based programs, also support \"program uploads\" to extract the running code from the device for various diagnostic functions. To support the program upload function, the device must provide the IDE with machine readable and human-presentable source code, rather than the executable compiled code. It applies to devices with the property: Device includes support for \"program uploads\" to retrieve programs from the device from an engineering workstation. Associated weaknesses: CWE-829. EMB3D-documented mitigations include MID-042 Device Checks Consistency Between Binary/Running Code and Textual Code. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-308-code-overwritten-to-avoid-detection",
    "title": "MITRE EMB3D TID-308: Code Overwritten to Avoid Detection (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-308 (Code Overwritten to Avoid Detection) is an embedded-device threat in the Application Software category. The threat actor can overwrite a previously deployed/installed malicious program with a dummy program in order to evade the detection of the malicious program. This can be used to prevent detection by monitoring tools or engineering software that performs periodic \"Program Uploads\" to inspect the contents of a program on the device. It applies to devices with the property: Device includes support for \"program uploads\" to retrieve programs from the device from an engineering workstation. Associated weaknesses: CWE-223, CWE-778. EMB3D-documented mitigations include MID-017 Security-relevant Auditing and Logging. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-309-device-exploits-engineering-workstation",
    "title": "MITRE EMB3D TID-309: Device Exploits Engineering Workstation (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-309 (Device Exploits Engineering Workstation) is an embedded-device threat in the Application Software category. If the integrated development environment (IDE) or vendor software that is used to manage a device is not sufficiently secure, it could be exploited or crashed when it connects to the device, such as during a file transfer or program upload. A threat actor could use a compromised device, such as a PLC, to exploit a vulnerability within the engineering software/IDE used to manage that device. It applies to devices with the property: Device includes support for \"program uploads\" to retrieve programs from the device from an engineering workstation. Associated weaknesses: CWE-20. EMB3D-documented mitigations include MID-008 Decidable Protocols and Parsers, MID-088 Formally Verified Parsers. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-310-remotely-accessible-unauthenticated-services",
    "title": "MITRE EMB3D TID-310: Remotely Accessible Unauthenticated Services (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-310 (Remotely Accessible Unauthenticated Services) is an embedded-device threat in the Application Software category. If an application does not authenticate all connections from a remote device or system, a threat actor can remotely establish a connection to the device to access confidential data or make unwanted changes to device status or configuration. Many popular protocols, such as FTP, Telnet, and HTTP, provide some support for authentication but are often implemented without enabling it. It applies to devices with the properties: Device includes unauthenticated services; Device exposes remote network services. Associated weaknesses: CWE-285. EMB3D-documented mitigations include MID-034 Authenticate Network Messages. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-311-default-credentials",
    "title": "MITRE EMB3D TID-311: Default Credentials (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-311 (Default Credentials) is an embedded-device threat in the Application Software category. Devices often include default credentials from the vendor. Default credentials can be changed but are often overlooked when devices are commissioned. If left unchanged, a threat actor may discover and use these credentials to gain unauthorized access to the device. Non-unique or predictable default credentials can lead to device compromise. It applies to devices with the property: Device includes authenticated services. Associated weaknesses: CWE-1392, CWE-1393. EMB3D-documented mitigations include MID-043 Manage Default Login Credentials. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-312-credential-change-mechanism-can-be-abused",
    "title": "MITRE EMB3D TID-312: Credential Change Mechanism Can Be Abused (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-312 (Credential Change Mechanism Can Be Abused) is an embedded-device threat in the Application Software category. A device's credential change mechanisms can be abused to lock out users from their own devices by changing credentials to something unknown to the legitimate user. This could impair the legitimate user from accessing the device and may also render the device permanently inoperable. This could also be coupled with unwanted device configuration changes before the user is locked out. It applies to devices with the property: Device includes authenticated services. Associated weaknesses: CWE-645. EMB3D-documented mitigations include MID-038 Authenticate for Administrative Actions. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-313-unauthenticated-session-changes-credential",
    "title": "MITRE EMB3D TID-313: Unauthenticated Session Changes Credential (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-313 (Unauthenticated Session Changes Credential) is an embedded-device threat in the Application Software category. A threat actor can change or reset a password or credential without being authenticated. This can be used by a threat actor to set the credential to a known value and then use this to authenticate to the device. It applies to devices with the property: Device includes authenticated services. Associated weaknesses: CWE-287. EMB3D-documented mitigations include MID-038 Authenticate for Administrative Actions. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-314-passwords-can-be-guessed-using-brute-force-attempts",
    "title": "MITRE EMB3D TID-314: Passwords Can Be Guessed Using Brute-Force Attempts (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-314 (Passwords Can Be Guessed Using Brute-Force Attempts) is an embedded-device threat in the Application Software category. A threat actor could gain unauthorized access by continually guessing passwords. This could be because the device allows passwords with insufficient entropy, short password lengths, or does not have a mechanism to increase the time it takes to randomly guess passwords, such as password lockouts or cooldowns between guesses. It applies to devices with the property: Device includes passwords to authenticate the users. Associated weaknesses: CWE-334, CWE-307. EMB3D-documented mitigations include MID-045 Multi-factor Authentication, MID-046 Authentication Attempts Timeouts and Lockouts. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-315-password-retrieval-mechanism-abused",
    "title": "MITRE EMB3D TID-315: Password Retrieval Mechanism Abused (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-315 (Password Retrieval Mechanism Abused) is an embedded-device threat in the Application Software category. If the device includes a password retrieval mechanism, a threat actor could use that mechanism to retrieve a valid credential and then access the device. Password retrieval functions are typically intended to be used to support access from dedicated device management tools, but these functions may be reverse engineered and then initiated by the threat actor to gain valid credentials on a device. It applies to devices with the property: Device includes passwords to authenticate the users. Associated weaknesses: CWE-319. EMB3D-documented mitigations include MID-017 Security-relevant Auditing and Logging. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-316-incorrect-certificate-verification-allows-authentication-bypass",
    "title": "MITRE EMB3D TID-316: Incorrect Certificate Verification Allows Authentication Bypass (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-316 (Incorrect Certificate Verification Allows Authentication Bypass) is an embedded-device threat in the Application Software category. Certificate-based authentication depends on the correct parsing and validation of an X.509 certificate. However, if the certificate is not properly parsed and all fields are not validated, a threat actor could potentially bypass authentication using a fraudulent certificate. It applies to devices with the properties: Device includes cryptographic mechanism to authenticate users and sessions; Device includes cryptographic functions for sensitive data, such as encryption or authentication. Associated weaknesses: CWE-295. EMB3D-documented mitigations include MID-027 Validated Cryptographic Libraries. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-317-predictable-cryptographic-key",
    "title": "MITRE EMB3D TID-317: Predictable Cryptographic Key (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-317 (Predictable Cryptographic Key) is an embedded-device threat in the Application Software category. If the device does not generate sufficiently random cryptographic primitives, a threat actor could predict or brute-force guess a key to either gain unauthorized access to the device or decrypt a connection. Cryptographic keys that are not generated with random \"seed\" information, including from Pseudo-Random Number Generators (PRNG), will lack sufficient entropy. It applies to devices with the properties: Device includes cryptographic mechanism to authenticate users and sessions; Device includes cryptographic functions for sensitive data, such as encryption or authentication. Associated weaknesses: CWE-331, CWE-338. EMB3D-documented mitigations include MID-033 Unique and Unpredictable Factory Preinstalled Secret Keys, MID-047 Sufficient Entropy for Keys, MID-048 Hardware Random Number Generator, MID-060 Dedicated Hardware Cryptographic Modules. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-318-insecure-cryptographic-implementation",
    "title": "MITRE EMB3D TID-318: Insecure Cryptographic Implementation (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-318 (Insecure Cryptographic Implementation) is an embedded-device threat in the Application Software category. The device uses a cryptographic library or implementation that either introduces an additional software vulnerability within the library. A threat actor can exploit these weaknesses or vulnerabilities to gain unauthorized access to the device or bypass the protections provided by the cryptographic protocol. It applies to devices with the properties: Device includes cryptographic mechanism to authenticate users and sessions; Device includes cryptographic functions for sensitive data, such as encryption or authentication. Associated weaknesses: CWE-1240. EMB3D-documented mitigations include MID-027 Validated Cryptographic Libraries, MID-060 Dedicated Hardware Cryptographic Modules. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-319-cross-site-scripting-xss",
    "title": "MITRE EMB3D TID-319: Cross Site Scripting (XSS) (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-319 (Cross Site Scripting (XSS)) is an embedded-device threat in the Application Software category. The device does not properly restrict, filter, or validate the content of web-based requests or outputs, especially content used to construct HTTP or JavaScript elements within a web page. A threat actor can add malicious JavaScript to an HTTP request, including through a GET/POST parameter or HTTP header fields, which then executes on the browser of an unsuspecting user. It applies to devices with the property: Device includes the usage of a web/HTTP applications. Associated weaknesses: CWE-79. EMB3D-documented mitigations include MID-071 Sanitized and Escaped User Data for Web Applications. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-320-sql-injection",
    "title": "MITRE EMB3D TID-320: SQL Injection (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-320 (SQL Injection) is an embedded-device threat in the Application Software category. The device does not property restrict, filter, or validate the content of web-based requests, especially content used to construct SQL commands or HTTP pages. A threat actor can add malicious content to these messages to cause unwanted code to execute on the device. SQL injection can be used to execute unauthorized commands (e.g., xpcmdshell), or to manipulate or extract sensitive data within the database. It applies to devices with the property: Device includes the usage of a web/HTTP applications. Associated weaknesses: CWE-89. EMB3D-documented mitigations include MID-072 Parameterized SQL Queries. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-321-http-application-session-hijacking",
    "title": "MITRE EMB3D TID-321: HTTP Application Session Hijacking (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-321 (HTTP Application Session Hijacking) is an embedded-device threat in the Application Software category. A threat actor can hijack an insufficiently protected HTTP session token to gain unauthorized access to a device. HTTP session tokens can be obtained by a threat actor if they're sent unencrypted over the network or if the site is vulnerable to cross-site scripting (XSS). It applies to devices with the property: Device includes the usage of a web/HTTP applications. Associated weaknesses: CWE-384. EMB3D-documented mitigations include MID-035 Encrypt Network Traffic, MID-073 Secure HTTP Session Management. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-322-cross-site-request-forgery-csrf",
    "title": "MITRE EMB3D TID-322: Cross Site Request Forgery (CSRF) (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-322 (Cross Site Request Forgery (CSRF)) is an embedded-device threat in the Application Software category. If a threat actor can include malicious JavaScript within a page viewed by a legitimate device user, that script can send malicious authenticated HTTP requests (using XMLHttpRequest) to the device. Due to the Same Origin Policy defined by most web browsers, the HTTP requests sent to the device will include any valid session tokens the user/browser has previously established for that device. It applies to devices with the property: Device includes the usage of a web/HTTP applications. Associated weaknesses: CWE-352. EMB3D-documented mitigations include MID-074 Cross Site Request Forgery Mitigations. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-323-path-traversal",
    "title": "MITRE EMB3D TID-323: Path Traversal (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-323 (Path Traversal) is an embedded-device threat in the Application Software category. A threat actor can send requests for files or content that resides in different directories from those intended to be accessible by the web server. This can be used to gain access to data that is not intended to be remotely accessible through the web servers, such as files from the operating system or other applications. This threat is primarily a result of the web server having excessive privileges regarding files and directories on the device It applies to devices with the property: Device includes the usage of a web/HTTP applications. Associated weaknesses: CWE-22. EMB3D-documented mitigations include MID-075 Path Traversal Protections. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-324-http-direct-object-reference",
    "title": "MITRE EMB3D TID-324: HTTP Direct Object Reference (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-324 (HTTP Direct Object Reference) is an embedded-device threat in the Application Software category. If a device does not properly authenticate all HTTP requests, a threat actor can directly send a request to a specific URL to access data or initiate a device function. This could be used to access/download sensitive data or perform unwanted changes to settings or functions on a device. This typically requires that the threat actor directly knows the URL of the specific file/object/page, rather than depending on the existing links provided by the web application. It applies to devices with the property: Device includes the usage of a web/HTTP applications. Associated weaknesses: CWE-639. EMB3D-documented mitigations include MID-076 Web Direct Object Reference Authentication. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-325-http-injection-response-splitting",
    "title": "MITRE EMB3D TID-325: HTTP Injection/Response Splitting (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-325 (HTTP Injection/Response Splitting) is an embedded-device threat in the Application Software category. The device uses HTTP headers that are unencrypted, not-validated, and/or unauthenticated. This means that the device may accept and process arbitrary data coming to the receiving web-server over the network. Threat actors may therefore be able to inject their own information into the header, possibly using their input to get more information than they should have access to or exploiting a vulnerability on the receiving device. It applies to devices with the property: Device includes the usage of a web/HTTP applications. Associated weaknesses: CWE-113. EMB3D-documented mitigations include MID-078 HTTP Request/Response Validation. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-326-insecure-deserialization",
    "title": "MITRE EMB3D TID-326: Insecure Deserialization (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-326 (Insecure Deserialization) is an embedded-device threat in the Application Software category. Many object-oriented languages use serialization to convert class objects into byte strings for more efficient storage or transmission. However, if an untrusted byte string is deserialized without properly validating its contents, it could be used to exploit a vulnerability in the associated library. A threat actor could send a maliciously crafted serialized object to a device to exploit a deserialization vulnerability within a device. It applies to devices with the property: Device includes support for object oriented programming languages(e.g., Java, Python, PHP, C++). Associated weaknesses: CWE-502. EMB3D-documented mitigations include MID-077 Secure Deserialization, MID-088 Formally Verified Parsers, MID-089 Formal Methods Verification of Critical Functionality Implementation. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-327-out-of-bounds-memory-access",
    "title": "MITRE EMB3D TID-327: Out of Bounds Memory Access (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-327 (Out of Bounds Memory Access) is an embedded-device threat in the Application Software category. If an application does not properly restrict data writes to allocated memory locations, a threat actor could send an input or message that writes data outside of intended or allowed memory locations. By overwriting memory locations, an attacker can possibly hijack the control-flow of the program to remotely execute their own code or cause a DoS on the device. It applies to devices with the property: Device includes support for manual memory management programming languages (e.g. C, C++). EMB3D-documented mitigations include MID-004 Memory Hardening Against Code Injection, MID-005 Memory Safe Programming Languages, MID-006 Driver Memory Isolation, MID-013 Process and Thread Memory Segmentation, MID-086 Hardware Enforcement of Memory Access. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mitre-emb3d-tid-328-hardcoded-credentials",
    "title": "MITRE EMB3D TID-328: Hardcoded Credentials (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-328 (Hardcoded Credentials) is an embedded-device threat in the Application Software category. Hardcoded credentials typically cannot be changed by end-users and are often undocumented, leaving the end-user unaware of the risk. If a threat actor is able to discover the credentials for a device (or family of devices with the same password), they may be able to exploit multiple devices with no known device-level mitigation. It applies to devices with the property: Device includes authenticated services. Associated weaknesses: CWE-798. EMB3D-documented mitigations include MID-043 Manage Default Login Credentials. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-329-improper-password-storage",
    "title": "MITRE EMB3D TID-329: Improper Password Storage (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-329 (Improper Password Storage) is an embedded-device threat in the Application Software category. If a device stores passwords in an unsafe manner (e.g., in a cleartext file with no read restrictions) it may be possible for threat actors to retrieve system or user account passwords for that device. Threat actors can then use obtained passwords to increase their privileges and perform actions on the device or move laterally to other systems. It applies to devices with the property: Device includes passwords to authenticate the users. Associated weaknesses: CWE-257. EMB3D-documented mitigations include MID-049 Secure Password Storage. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-330-cryptographic-timing-side-channel",
    "title": "MITRE EMB3D TID-330: Cryptographic Timing Side-Channel (Embedded Device Threat - Application Software)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-330 (Cryptographic Timing Side-Channel) is an embedded-device threat in the Application Software category. Algorithms or code implementations of cryptographic processes will sometimes leak information by ending operations early or late based on, and correlated with, the input/key. If a threat actor is able to execute code on a processor performing a cryptographic operation, they may be able to infer the resulting key from that operation by measuring the timing it takes to perform the various functions. It applies to devices with the properties: Device includes cryptographic firmware/software integrity protection mechanisms; Device includes cryptographic mechanism to authenticate users and sessions. Associated weaknesses: CWE-208, CWE-1254. EMB3D-documented mitigations include MID-027 Validated Cryptographic Libraries, MID-044 Strong Cryptographic Algorithms and Protocols. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-401-undocumented-protocol-features",
    "title": "MITRE EMB3D TID-401: Undocumented Protocol Features (Embedded Device Threat - Networking)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-401 (Undocumented Protocol Features) is an embedded-device threat in the Networking category. Some devices may support proprietary protocols, or may add proprietary functionality to open protocols. Many of the custom functions or commands may not be sufficiently documented. If users aren't aware of these functions/commands, they cannot be expected to properly configure the device to remove unwanted functionality. Further, they are limited in their ability to monitor the device for any potential malicious use of these functions/commands to exploit devices. It applies to devices with the property: Device exposes remote network services. Associated weaknesses: CWE-1371, CWE-912, CWE-1059. EMB3D-documented mitigations include MID-079 Remove Undocumented Network Functionality. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-404-remotely-triggerable-deadlock-dos",
    "title": "MITRE EMB3D TID-404: Remotely Triggerable Deadlock/DoS (Embedded Device Threat - Networking)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-404 (Remotely Triggerable Deadlock/DoS) is an embedded-device threat in the Networking category. Some devices will have operating modes that put the device in an inoperable state. Devices may also have network parsing or protocol vulnerabilities that can put the device in a deadlocked or otherwise unresponsive state. A threat actor may therefore be able to send a message to a device that causes it to enter one of these deadlocked or unresponsive states, rendering the device non-functional or leaving it in an otherwise degraded state. It applies to devices with the property: Device exposes remote network services. Associated weaknesses: CWE-833. EMB3D-documented mitigations include MID-008 Decidable Protocols and Parsers, MID-032 System Service Availability Manager, MID-088 Formally Verified Parsers, MID-089 Formal Methods Verification of Critical Functionality Implementation. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-405-network-stack-resource-exhaustion",
    "title": "MITRE EMB3D TID-405: Network Stack Resource Exhaustion (Embedded Device Threat - Networking)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-405 (Network Stack Resource Exhaustion) is an embedded-device threat in the Networking category. Remote connections and communications can consume various device resources (e.g., network stack buffers, packet processing, socket connections) that, if exhausted, could lead to the device entering an unresponsive state. A threat actor may attempt to intentionally cause this by sending either repetitive or specially crafted messages to a device to consume resources and cause the device to become unresponsive. It applies to devices with the property: Device exposes remote network services. Associated weaknesses: CWE-400, CWE-410. EMB3D-documented mitigations include MID-008 Decidable Protocols and Parsers, MID-032 System Service Availability Manager, MID-080 Network Request Processing Limits, MID-088 Formally Verified Parsers, MID-089 Formal Methods Verification of Critical Functionality Implementation. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-406-unauthorized-messages-or-connections",
    "title": "MITRE EMB3D TID-406: Unauthorized Messages or Connections (Embedded Device Threat - Networking)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-406 (Unauthorized Messages or Connections) is an embedded-device threat in the Networking category. Some devices operate using protocols that have no capacity for network-level authentication, connection, or creation of sessions on-device, therefore allowing a threat actor to establish malicious connections or send malicious data to the device. Authentication mechanisms include passwords and cryptographic keys/certificates. It applies to devices with the property: Device lacks protocol support for message authentication. Associated weaknesses: CWE-306, CWE-287. EMB3D-documented mitigations include MID-034 Authenticate Network Messages, MID-081 Secure Network Tunnels. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-407-missing-message-replay-protection",
    "title": "MITRE EMB3D TID-407: Missing Message Replay Protection (Embedded Device Threat - Networking)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-407 (Missing Message Replay Protection) is an embedded-device threat in the Networking category. Threat actors may be able to replay a message to a device to cause an unwanted function, send an unwanted command, or gain access to privileged data. Message replaying can be used to bypass nonexistent or poorly designed authentication mechanisms lacking proper protections, such as a nonce or timestamp. It applies to devices with the property: Device exposes remote network services. Associated weaknesses: CWE-294. EMB3D-documented mitigations include MID-036 Cryptographic Nonces, MID-037 Network Timestamps. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-408-unencrypted-sensitive-data-communication",
    "title": "MITRE EMB3D TID-408: Unencrypted Sensitive Data Communication (Embedded Device Threat - Networking)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-408 (Unencrypted Sensitive Data Communication) is an embedded-device threat in the Networking category. Some devices do not adequately encrypt communications that includes operational or management information. Without adequate encryption, a threat actor can eavesdrop on the communications to gain access to device operational information, management information, or authentication information such as credentials or keys. Examples of popular protocols that lack encryption include FTP, Telnet, HTTP, Modbus, and DNP3. It applies to devices with the property: Device lacks protocol support for message encryption. Associated weaknesses: CWE-319. EMB3D-documented mitigations include MID-035 Encrypt Network Traffic, MID-081 Secure Network Tunnels. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-410-cryptographic-protocol-side-channel",
    "title": "MITRE EMB3D TID-410: Cryptographic Protocol Side Channel (Embedded Device Threat - Networking)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-410 (Cryptographic Protocol Side Channel) is an embedded-device threat in the Networking category. While encrypting data can prevent a threat actor from directly obtaining the plaintext communication, a threat actor may be able to infer information about the device or communicated data through side-channel and metadata analysis of encrypted communication sessions. For example, a threat actor could use information about message lengths, sequences, and frequency to infer some or all of the plaintext content of messages. It applies to devices with the property: Device includes cryptographic functions for sensitive data, such as encryption or authentication. Associated weaknesses: CWE-1230. EMB3D-documented mitigations include MID-044 Strong Cryptographic Algorithms and Protocols. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-411-weak-insecure-cryptographic-protocol",
    "title": "MITRE EMB3D TID-411: Weak/Insecure Cryptographic Protocol (Embedded Device Threat - Networking)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-411 (Weak/Insecure Cryptographic Protocol) is an embedded-device threat in the Networking category. The device utilizes a weak or insecure cryptographic protocol or algorithm that can be broken or undermined. This could allow the threat actor to extract plaintext information from encrypted communications, extract cryptographic keys, or bypass authentication mechanisms. A threat actor can utilize various techniques to manipulate these protocols, including brute-force guessing of keys or using cryptanalysis to decipher the text. It applies to devices with the properties: Device includes cryptographic mechanism to authenticate users and sessions; Device includes cryptographic functions for sensitive data, such as encryption or authentication. Associated weaknesses: CWE-327. EMB3D-documented mitigations include MID-044 Strong Cryptographic Algorithms and Protocols, MID-082 Post-quantum Cryptography. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-emb3d-tid-412-network-routing-capability-abuse",
    "title": "MITRE EMB3D TID-412: Network Routing Capability Abuse (Embedded Device Threat - Networking)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "MITRE EMB3D TID-412 (Network Routing Capability Abuse) is an embedded-device threat in the Networking category. Some devices will allow for the forwarding of packets to other connected devices (e.g., routing, port forwarding, tunneling, VPN). If the device is used to forward or route communications, a threat actor could change the forwarding rules or routes. This feature could be used by the threat actor to either (i) disable required forwarding rules to prevent authorized communications or (ii) add new rules that allow unauthorized access to other devices. It applies to devices with the property: Device includes procedure to forward or route network messages. Associated weaknesses: CWE-306, CWE-15. EMB3D-documented mitigations include MID-017 Security-relevant Auditing and Logging, MID-018 Require Authentication for Privileged Functions, MID-031 Physical Presence Validation, MID-038 Authenticate for Administrative Actions, MID-083 Network Firewall/Access Control List. Embedded-device controls map to the IEC/ISA 62443 series and NIST IR 8259 device cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "mitre_emb3d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mitre-engage-adversary-engagement-framework",
    "title": "MITRE Engage Adversary Engagement Framework (Prepare, Operate, Understand; Expose, Affect, Elicit Goals; Successor to MITRE Shield)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "MITRE Engage is the MITRE Corporation's framework for planning and discussing adversary engagement operations - the deception, denial, and direct-engagement techniques defenders use to expose, affect, and elicit information from adversaries who are operating inside an environment. Engage is the operational successor to MITRE Shield (which was deprecated in 2022) and is published openly at engage.mitre.org. The Engage Matrix is organised in three phases: Prepare (Plan, Cyber Threat Intelligence, Engagement Environment, Gating Criteria, Operational Objective, Persona Creation, Storyboarding, Threat Model); Operate, which contains the Expose, Affect, and Elicit goal families with approaches including Collect, Detect, Prevent, Direct, Disrupt, Reassure, Motivate, plus operational approaches API Monitoring, Introduced Vulnerabilities, Baseline, Attack Vector Migration, Isolation, Application Diversity, Network Monitoring, Lures, Hardware Manipulation, Email Manipulation, Artifact Diversity, Software Manipulation, Malware Detonation, Network Manipulation, Burn-In, Information Manipulation, System Activity Monitoring, Network Analysis, Security Controls, Personas, Pocket Litter, and Peripheral Management; and Understand (Analyze, After-Action Review, Cyber Threat Intelligence, Threat Model). Engage explicitly maps to MITRE ATT&CK techniques (defenders identify the ATT&CK techniques in scope and apply Engage approaches to engage the adversary on those techniques). A Starter Kit, Playbook, and Process tooling are published alongside the Matrix. Engage is positioned for use by red, blue, and purple teams, by deception engineers, by CTI analysts, and by SOC operators conducting active defence within legal and policy constraints.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "matrix_prepare_phase",
        "matrix_operate_phase_expose_goal",
        "matrix_operate_phase_affect_goal",
        "matrix_operate_phase_elicit_goal",
        "matrix_understand_phase",
        "attack_technique_mapping",
        "successor_to_mitre_shield",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-framework-v14",
      "mitre-atlas-ai-threat-matrix-2024",
      "cyber-nist-csf-2",
      "us-cisa-kev-catalog"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mitre-t1562",
    "title": "Impair Defenses (MITRE T1562)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "MITRE ATT&CK Technique T1562 (Impair Defenses) describes adversary behaviors aimed at disabling, tampering with, or reducing the effectiveness of security tools and controls - including antivirus, endpoint detection and response (EDR), logging systems, firewalls, and audit trails - to reduce detection probability and extend dwell time after initial compromise. T1562 has 12 sub-techniques including disabling Windows Defender (T1562.001), tampering with audit/log policies (T1562.002), disabling or modifying system firewalls (T1562.004), and disabling cloud logs (T1562.008). This technique is highly relevant to AI agent security because a maliciously prompted or jailbroken AI agent with tool execution capabilities could programmatically disable security monitoring tools as part of an adversary's kill chain. Detection requires continuous integrity monitoring of security tool state, immutable logging, and configuration baseline enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "iso-27001-2022",
      "nist-sp-800-92-log-management",
      "nist-sp-800-41-r1-firewalls",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mk-pdpa-2020",
    "title": "North Macedonia Law on Personal Data Protection 2020 - DZLP",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "North Macedonia's Law on Personal Data Protection (Закон за заштита на личните податоци - ZZLP) - adopted by the Assembly of the Republic of North Macedonia in early 2020 and published in the Official Gazette of the Republic of North Macedonia No. 42 of 16 February 2020, entering into force on 25 February 2020 - is North Macedonia's primary personal data protection legislation, explicitly modelled on and substantively aligned with the European Union General Data Protection Regulation (GDPR - Regulation (EU) 2016/679). The law was enacted as a central component of North Macedonia's EU accession preparations, with North Macedonia having held EU candidate status since 2005 and formally opening EU accession negotiations in 2022. The 2020 ZZLP replaced the previous Law on Personal Data Protection of 2005 and introduced full GDPR-equivalent provisions including the controller-processor framework, DPO requirements, Data Protection Impact Assessments, 72-hour breach notification, data subject rights, and the Supervisory Authority enforcement model. The supervisory authority is the Directorate for Personal Data Protection (Дирекција за заштита на личните податоци - DZLP), an independent state body established under the Law responsible for receiving notifications, investigating complaints, conducting inspections, and enforcing the ZZLP. Key features of North Macedonia's Law on Personal Data Protection 2020: (1) Scope - applies to processing of personal data of natural persons in North Macedonia by controllers and processors established in North Macedonia or processing data of North Macedonian data subjects regardless of establishment; (2) Data processing principles - lawfulness, fairness, and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability - mirroring GDPR; (3) Sensitive personal data - same categories as GDPR: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; genetic data; biometric data; health data; sex life or sexual orientation; and criminal conviction data; (4) Lawful processing conditions - GDPR-equivalent: consent; contract; legal obligation; vital interests; public interest; legitimate interests; (5) Data subject rights - full GDPR-equivalent rights: access; rectification; erasure; restriction; portability; objection; automated decision-making rights; (6) Data Protection Officer - mandatory for public authorities, controllers conducting large-scale systematic monitoring, and controllers processing sensitive data on a large scale; (7) Breach notification - 72-hour notification to DZLP; data subject notification for high-risk breaches; (8) Data Protection Impact Assessment - mandatory for high-risk processing; (9) Cross-border transfers - GDPR-equivalent transfer framework: adequacy decisions; standard contractual clauses; binding corporate rules; codes of conduct; certification; (10) Penalties - administrative fines graduated by violation severity up to EUR 20,000 or EUR 100,000 (not GDPR-scale but significant for North Macedonia's economy). North Macedonia's ZZLP 2020 is the most GDPR-aligned data protection law in the Western Balkans region.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ml-pdp-law-2013",
    "title": "Mali Law No. 2013-015 on Personal Data Protection",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Mali enacted Law No. 2013-015/P-RM of 21 May 2013 on the Protection of Personal Data, establishing a comprehensive framework for personal data processing. The law is administered by the Autorité de Protection des Données à Caractère Personnel (APDP). Controllers must register processing activities with the APDP, obtain consent or another lawful basis, respect data subject rights (access, rectification, opposition, erasure), and ensure cross-border transfers only occur to jurisdictions with adequate protection. Special categories of sensitive data (health, racial origin, political opinion, religion, trade union membership) require explicit consent and are subject to heightened restrictions. The Act aligns with the ECOWAS Supplementary Act on Personal Data Protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ml-pdp-law-2013.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mlc-2006-maritime-labour-convention-seafarer-employment-conditions",
    "title": "ILO Maritime Labour Convention 2006 - Seafarer Employment Agreements, Working Hours, and Living Standards",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2022-11-01",
    "bluf": "The ILO Maritime Labour Convention 2006 (MLC 2006) establishes minimum working and living standards for seafarers including maximum hours of work, minimum rest periods, repatriation rights, seafarer employment agreements, medical care, wage protection, and shipowner financial security for abandonment, enforceable through flag state certification and port state control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-international-safety-management-code-ism-solas-ix",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mm-cybersec-law-2021",
    "title": "Myanmar Cybersecurity Law (SAC Law No. 1/2025) - Personal Data Protection Provisions",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Myanmar enacted the Cybersecurity Law as State Administration Council Law No. 1/2025 on 1 January 2025 (effective 30 July 2025 via SAC Notification 113/2025); earlier draft cybersecurity bills circulated between 2019 and 2021 were never enacted. The law includes provisions governing personal data protection in the digital environment alongside cybersecurity obligations. It applies to digital businesses, internet service providers, and online services operating in Myanmar. It establishes obligations for data localisation, requiring certain categories of critical personal data to be stored on servers located in Myanmar. Consent is required for collection and processing of personal data. Data subjects have rights of access and correction. The law is issued by the State Administration Council, with the Ministry of Transport and Communications regulating data processing and investigating breaches under it. The law takes an integrated approach combining cybersecurity and data protection obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/mm-cybersec-law-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mn-pdp-law-2021",
    "title": "Mongolia Law on Personal Data Protection - Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Mongolia's Law on Personal Data Protection (2021) establishes a comprehensive framework for the collection, processing, and cross-border transfer of personal data, with mandatory breach notification and data localization obligations. Oversight is shared between the National Human Rights Commission of Mongolia (the primary body for complaints and investigations) and the Ministry of Digital Development, Innovation and Communications; there is no single dedicated data protection authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mo-pdpa-2005",
    "title": "Macao Personal Data Protection Act 2005 (Law No. 8/2005)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Macao Special Administrative Region (SAR) of the People's Republic of China enacted the Personal Data Protection Act, Law No. 8/2005 of 22 August 2005. The Act is administered by the Office for Personal Data Protection (Gabinete para a Protecção de Dados Pessoais, GPDP), an independent regulatory authority. Aligned with European data protection standards as Macao maintained its Portuguese legal heritage after handover to China, the Act establishes principles for the lawful processing of personal data, grants data subjects rights of access, correction, and erasure, requires controllers to notify the GPDP of certain processing activities, mandates security safeguards, and restricts cross-border transfers to jurisdictions with adequate protection. The GPDP can investigate complaints and impose administrative sanctions on controllers who breach the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/mo-pdpa-2005.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mod-safe-ai",
    "title": "UK Ministry of Defence (MoD) AI Safety Protocol",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "A mandatory safety assurance framework for AI systems deployed in British Armed Forces, requiring a structured Safety Case and human-in-the-loop gating for lethal force.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cmmc-2-audit",
      "nist-800-171-cui"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "modern-slavery-act-rep",
    "title": "Modern Slavery Act",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Modern slavery legislation mandates that certain commercial organizations actively identify, mitigate, and report on risks of slavery and human trafficking within their global operations and supply chains. The governing statutory frameworks establish clear triggers for compliance; for example, `isUkJurisdictionApplicable` is determined by carrying on business in the UK coupled with an `annualTurnoverGBP_Millions` meeting or exceeding 36, whereas `isAustraliaJurisdictionApplicable` depends on operating in Australia with a `consolidatedRevenueAUD_Millions` of at least 100. If `isStatementRequired` is true, an entity must prepare and publish an annual modern slavery statement. This formal document, confirming `hasPublishedAnnualStatement`, must transparently outline the organization's structure, policies, and specific actions taken to combat these abuses. Core content requirements necessitate that the `statementCoversDueDiligence` processes and `statementCoversRiskAssessment` methodologies are adequately described. Furthermore, strict procedural rules apply: the `statementApprovedByBoard` is mandatory, the `statementSignedByDirector` affixes senior accountability, and ensuring the `statementIsPublishedOnHomepage` provides requisite public transparency. A comprehensive compliance posture is often evidenced by maintaining a proactive `hasSupplierAuditProgram` to scrutinize supply chain partners, as non-compliance presents severe reputational and legal risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "iso-26000-social-resp-mgt",
      "iso-20400-sustainable-procure",
      "sa8000-social-account",
      "iso-31000-risk-mgt-std",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mongolia-minerals-law-2006",
    "title": "Mongolia Minerals Law 2006 - Exploration and Mining Licensing with State Participation Rights",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2023-01-01",
    "bluf": "Mongolia's Minerals Law (2006, amended 2023) establishes exploration and mining licences administered by MRPAM, requires state participation of 34% (non-state-funded) or 50% (state-funded) in strategic deposits designated by Parliament, sets royalties of 2.5-5% by mineral type, and mandates environmental and closure bonds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "nist_csf",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-msha-30-cfr-part-57-underground-mine-safety",
      "tanzania-mining-act-no-14-2010"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "montreal-convention-1999-air-carriage",
    "title": "Montreal Convention 1999 - International Air Carriage Liability",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Montreal Convention 1999 (Convention for the Unification of Certain Rules for International Carriage by Air) establishes a two-tier strict liability regime for international air carriage of passengers and cargo. For passenger death or bodily injury (Art 17), strict liability applies up to SDR 113,100 per passenger (first tier, Art 21(1)); above that limit liability is unlimited unless the carrier proves no negligence (Art 21(2)). Cargo destruction, damage, or loss (Art 22) is capped at SDR 19 per kilogram unless an ad valorem special declaration is made (Art 22(3)). Baggage liability is capped at SDR 1,131 per passenger; delay liability at SDR 4,694 (passengers) or SDR 19/kg (cargo). The Convention covers 139 States party (as of 2024), entered into force 4 November 2003, and supersedes the Warsaw Convention system. Limitation period is 2 years from arrival or scheduled arrival date (Art 30). Five permitted fora for passenger claims (Art 33) include the State of the passenger's principal and permanent residence where the carrier operates services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "cape-town-convention-2001-mobile-equipment",
      "hague-visby-rules-1968",
      "cmr-convention-1956-road-carriage-goods"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "morocco-law-02-03-foreigners-residence-entry-2003",
    "title": "Morocco Law 02-03 of 2003 - Entry and Stay of Foreigners and Irregular Emigration Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Morocco's Law No. 02-03 of 11 November 2003 regarding entry and stay of foreigners in Morocco and irregular emigration and immigration (Dahir No. 1-03-196) governs foreign national entry, residence, and removal. Implemented by the Direction de la Migration et de la Surveillance des Frontieres (DMSF) under the Ministry of Interior. Morocco maintains an open visa-on-arrival or visa-free policy for nationals of 67+ countries for up to 90 days. Residents require a Titre de Sejour (residence card) for stays beyond 90 days, renewed annually or issued as long-stay (10-year) for qualifying residents. Morocco launched an Exceptional Regularisation Campaign in 2013-2014 (55,000 migrants regularised) and a second campaign in 2016-2017 (50,000 regularised) as part of its 2013 National Immigration and Asylum Policy, endorsed by King Mohammed VI. The work authorisation system requires prior approval from the Agence Nationale de Promotion de l'Emploi et des Competences (ANAPEC) through a labour market test. Morocco has signed a Mobility Partnership with the EU (2013), governing legal migration channels and readmission. The Association Agreement with the EU facilitates movement of services and persons. Moroccan law criminalises facilitation of irregular migration under Arts. 51-52.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_mobility_partnership",
        "african_union_migration",
        "anapec_labour_test",
        "police_des_etrangers",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mozambique-mining-law-20-2014",
    "title": "Mozambique Mining Law 20/2014 - Concessions, Environmental Compliance, and Royalty Framework",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2014-08-18",
    "bluf": "Mozambique Law 20/2014 replaces Law 14/2002, establishing five mining title categories (Mining Concession, Simple Mining Licence, Artisanal Licence, Reconnaissance, Mining Pass), mandatory Environmental Compliance Plans, 5% equity offers to Mozambican entities, and royalty rates of 3% for coal, 6% for gemstones, and 1.5% for heavy mineral sands.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "nist_csf",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "tanzania-mining-act-no-14-2010",
      "namibia-minerals-prospecting-mining-act-33-1992"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mp-framework",
    "title": "Northern Mariana Islands - Federal and Commonwealth Privacy Rights Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Commonwealth of the Northern Mariana Islands (CNMI) is a self-governing Commonwealth in political union with the United States, located in the western Pacific Ocean. The CNMI was established under the Covenant to Establish a Commonwealth of the Northern Mariana Islands in Political Union with the United States of America (1976), which provides for US citizenship for CNMI residents and applies US federal law broadly in the CNMI. The CNMI has its own Constitution, Legislature, and Judiciary. US federal law applies to the CNMI as a commonwealth in political union with the United States. Accordingly, the primary federal privacy statutes - including the Health Insurance Portability and Accountability Act (HIPAA), the Children's Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), the Gramm-Leach-Bliley Act (GLBA), and the Federal Trade Commission Act - apply in the CNMI and govern the handling of personal data by organisations operating in the Commonwealth. The Federal Trade Commission exercises jurisdiction over unfair or deceptive acts or practices relating to personal data in the CNMI. The CNMI Code contains provisions applicable to privacy, government records, and electronic transactions in the Commonwealth. The CNMI does not have a standalone comprehensive personal data protection law equivalent to the GDPR. Organisations processing personal data of individuals in the CNMI must comply with all applicable US federal privacy statutes, relevant CNMI Code provisions, and implement appropriate technical and organisational security measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/mp-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "mq-gdpr-2018",
    "title": "Martinique - GDPR and French Data Protection Law (Loi Informatique et Libertés)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Martinique, as an outermost region of France and the European Union under the TFEU outermost regions framework, is fully subject to the EU General Data Protection Regulation (GDPR) and the French Loi Informatique et Libertés (Data Processing, Files and Freedoms Act, Law No. 78-17 of 6 January 1978), as modified by Law No. 2018-493 of 20 June 2018 to incorporate GDPR obligations into French national law. The supervisory authority for data protection in Martinique is the Commission Nationale de l'Informatique et des Libertés (CNIL), which has full enforcement powers across all French territory including the overseas departments. Organisations processing personal data in Martinique must comply with all GDPR obligations: establishing a lawful basis for each processing activity, maintaining a Record of Processing Activities (RoPA), implementing data subject rights procedures (access, rectification, erasure, restriction, portability, and objection), notifying personal data breaches to CNIL within 72 hours, conducting data protection impact assessments (DPIAs) for high-risk processing, appointing a Data Protection Officer (DPO) where required, and implementing safeguards for international data transfers outside the European Economic Area. CNIL may impose administrative fines of up to EUR 20 million or 4% of global annual turnover for serious GDPR violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/mq-gdpr-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mr-pdp-law-2017",
    "title": "Mauritania Law No. 2017-020 on Personal Data Protection",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Mauritania enacted Law No. 2017-020 of 4 September 2017 on the Protection of Personal Data, creating a comprehensive framework administered by the Autorité de Protection des Données à Caractère Personnel (APD), in English the Personal Data Protection Authority. The law requires registration of processing activities, mandates consent or another lawful basis, grants data subjects rights of access, rectification, opposition, and erasure, and restricts cross-border data transfers to countries with adequate protection. Special categories of sensitive personal data are subject to heightened conditions including prior APD authorisation. The Act aligns with the ECOWAS Supplementary Act on Personal Data Protection (Mauritania is a member of ECOWAS).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/mr-pdp-law-2017.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mrc-viewability-standard",
    "title": "MRC (Viewability)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Adherence to Media Rating Council and Interactive Advertising Bureau standards for viewable impressions is mandatory for compliant digital advertising measurement. This configuration enforces the baseline criteria established within the Viewable Ad Impression Measurement Guidelines. For standard display ad units, a viewable impression is counted only when a minimum of fifty percent of the creative’s pixels are within an active browser window for at least one continuous second. Measurement commences once the ad unit has fully loaded. Large format display ads, defined as creatives meeting or exceeding a 242,500 total pixel count, require a reduced threshold where only thirty percent of pixels must remain visible for one uninterrupted second. In accordance with IAB Digital Video Ad Impression Measurement Guidelines, video advertisements must have fifty percent of their pixels in view for a minimum of two consecutive seconds. Critically, this compliance check mandates robust invalid traffic filtration; both general and sophisticated invalid traffic must be detected and removed from measurement totals as stipulated by the MRC's dedicated IVT addendum. The system correctly distinguishes served versus viewable impressions and does not permit user interaction to override these fundamental viewability requirements, ensuring all reported metrics align with current Mobile and Desktop Ad Impression Measurement Guidelines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iab-vast-video-ads",
      "iab-mraid-mobile-ads",
      "iab-ads-txt-authorization",
      "iab-sellers-json-standard",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ms-dpa-2019",
    "title": "Montserrat Data Protection Act 2019",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Montserrat, a British Overseas Territory, enacted the Data Protection Act 2019 aligned with UK and GDPR data protection standards. Administered by the Information Commissioner for Montserrat, the Act establishes data protection principles, grants data subjects rights of access, rectification, erasure, and objection, and requires controllers to implement appropriate security measures. Processing of special categories of sensitive personal data requires explicit consent or a specific statutory condition. Data breaches must be notified to the Information Commissioner within the prescribed period. Cross-border transfers require adequate protection or appropriate safeguards. The Act is aligned with the UK Data Protection Act 2018 to ensure consistency within the UK's Overseas Territories framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ms-dpa-2019.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "msc-fisheries-cert",
    "title": "MSC Seafood Sustainability",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the Marine Stewardship Council framework for seafood sustainability mandates a multi-faceted assessment of fishery operations and supply chain integrity. Verification begins with confirming the entity holds a valid MSC certificate that is not suspended. The product itself must fall within the certificate’s scope, satisfying both `product_species_in_certificate_scope` and `product_geography_in_certificate_scope` requirements. Integrity through the supply chain requires that the `chain_of_custody_code_valid`. Ecologically, the fishery must prove its target stock is maintained above a critical biological threshold, verifying the `is_stock_above_point_of_recruitment_impairment` condition is met. A formal `harvest_strategy_in_place` and sufficient `bycatch_monitoring_data_available` are also mandatory to manage the fishery's broader impact. From a management perspective, the `fishery_client_group` must be `clearly_defined`, and a regular `management_system_review` must be conducted. For traceability, complete `traceability_system_records` must be `maintained`. Continuous oversight is validated by a critical time-based check: the `last_surveillance_audit` must have been completed within the preceding 365 days. Exceeding this threshold signifies a potential compliance failure. These interconnected controls collectively substantiate claims of sustainable sourcing under the premier global standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "un-paris-agreement-ndc-implementation-guidelines"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mt-dpa-586-2018",
    "title": "Malta Data Protection Act Chapter 586 (2018) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Malta's Data Protection Act (DPA), Chapter 586 of the Laws of Malta, enacted by Act No. XVII of 2018 and published in the Government Gazette of Malta, is Malta's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Malta. The GDPR is directly applicable Maltese law by virtue of Malta's EU membership. Chapter 586 provides national derogations, additions, and specifications that the GDPR permits EU member states to adopt, replacing the prior Data Protection Act (Chapter 440 of the Laws of Malta). Malta is a small island EU member state with an outsized importance in financial services, online gaming, cryptocurrency, and aviation registration; the volume of personal data processed by these sectors relative to Malta's population makes GDPR and Chapter 586 compliance particularly significant for international operators using Malta as an EU base. Malta has been an active regulatory hub for cryptocurrency and blockchain companies, with the Malta Financial Services Authority (MFSA) supervising financial sector entities and data protection implications arising from blockchain-based personal data processing. Enforcement: the Information and Data Protection Commissioner (IDPC) is Malta's independent data protection supervisory authority. The IDPC is Malta's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Maltese national provisions: (1) Age of digital consent: Malta has set the age of consent for information society services at 13 years (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 13 require parental or guardian consent; (2) Employment - the Employment and Industrial Relations Act (EIRA, Chapter 452 of the Laws of Malta) and the Conditions of Employment (Regulation) Act govern employment relationships and the processing of employee personal data; (3) Freedom of expression - exemptions for journalistic, academic, artistic, and literary processing aligned with GDPR Art. 85; (4) Health data - specific provisions for health data processing under Chapter 586 and Maltese health legislation; (5) Criminal data - Chapter 586 restricts private entity processing of criminal conviction and offence data; (6) Financial services - the MFSA supervises financial services entities; MFSA regulations and GDPR compliance requirements interact significantly for Maltese-licensed financial entities serving EU clients. Fines: GDPR administrative fines apply in Malta - up to EUR 20 million or 4% of global annual turnover. The IDPC has imposed administrative fines and issued enforcement decisions in digital services, employment, and financial sector contexts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mu-dpa-2017",
    "title": "Mauritius Data Protection Act 2017",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Mauritius Data Protection Act 2017 (DPA) establishes a comprehensive legal framework for the protection of personal data, closely aligned with the EU's GDPR. It applies to all data controllers and processors in Mauritius, as well as those outside Mauritius who process personal data of Mauritian residents, mandating compliance with core principles of data processing (Part III) and safeguarding the rights of data subjects (Part IV).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mu-public-procurement-act-33-2006-ppoa-eprocurement",
    "title": "Mauritius Public Procurement Act 33 of 2006 (as consolidated and amended) and the Public Procurement Office (PPO) and Electronic Procurement System",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Republic of Mauritius Public Procurement Act 33 of 2006 (Act No. 33 of 2006, Government Gazette of Mauritius No. 116 of 16 December 2006) effective 1 January 2008 as substantially amended over time (including by the Finance (Miscellaneous Provisions) Acts of 2010, 2013, 2015, 2018, 2020, and 2023), and supplemented by the Public Procurement Regulations 2008 (GN No. 219 of 2008) as amended, is the principal Mauritian statute governing procurement of goods, works, and consultancy services by public bodies including ministries and government departments, local authorities (municipalities and district councils), parastatal organisations, public-sector enterprises, public-sector universities and tertiary institutions, statutory bodies, and other entities financed by public funds. The Procurement Policy Office (PPO / ppo.govmu.org) under the Ministry of Finance, Economic Planning and Development is the central regulatory authority responsible for procurement policy, oversight, and procurement guidance. The Public Procurement Office (PPO Mauritius distinct from Procurement Policy Office) administers central procurement coordination. The e-Procurement System Mauritius (eps.govmu.org) is the federal e-procurement platform. The Independent Review Panel (IRP) is the specialised tribunal for procurement appeals. Procurement methods established by Public Procurement Act 2006 sec. 14 to 27 comprise (a) Open Advertised Bidding (the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Restricted Bidding (with prequalification), (c) Request for Sealed Quotations (for medium-value acquisitions), (d) Departmental Bidding (for prescribed lower-value acquisitions managed at department level), (e) Direct Procurement (sole-source under prescribed exceptions in sec. 25 including emergency, sole supplier for technical reasons, prior failed bidding, additional procurement under existing contract, and prescribed-class exemptions), (f) Two-Stage Bidding (for complex acquisitions), (g) Community and NGO Participation, and (h) Framework Agreement. The Director of Audit conducts ex-post procurement audit. The Independent Commission Against Corruption (ICAC) has investigative jurisdiction over procurement-related corruption. Mauritius is NOT a party to the WTO Government Procurement Agreement (GPA). Mauritius is a party to AfCFTA, COMESA, SADC, and UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "mu-dpa-2017",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mv-pdpa-2021",
    "title": "Maldives Data Protection: Data Protection Act 2017 (in force) and the draft Privacy and Personal Data Protection Bill (pending)",
    "domain": "Data Protection & Privacy",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "The Maldives has not enacted a comprehensive 'Personal Data Protection Act 2021'. The only enacted instrument is the limited Data Protection Act 2017 (in force since 15 January 2018), which sets out basic principles for the collection, use, and disclosure of personal data. A comprehensive, GDPR-style Privacy and Personal Data Protection Bill was released for public consultation in May 2023 and remains a draft pending before the People's Majlis (Parliament); it has not been enacted as of 2026. The draft Bill proposes lawful, fair, and transparent processing with consent, data subject rights of access, correction, erasure, and objection, mandatory breach notification, and the establishment of a dedicated independent Data Protection Authority (DPA) as the supervisory body. The Communications Authority of Maldives (CAM) is the ICT/communications regulator and is not the designated data protection authority. Organisations operating in the Maldives should comply with the Data Protection Act 2017 today and prepare for the obligations proposed by the draft Bill, treating the Bill's provisions as forthcoming rather than binding until enacted.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/mv-pdpa-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mw-dpa-2021",
    "title": "Malawi Data Protection Act 2021 - MACRA Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Malawi Data Protection Act 2021 establishes a comprehensive framework for personal data processing including consent obligations, data subject rights, mandatory registration, and cross-border transfer controls. The Malawi Communications Regulatory Authority (MACRA) serves as the interim supervisory authority pending appointment of a dedicated Data Protection Commissioner.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mw-electronic-transactions-cybersecurity-act-2016",
    "title": "Malawi Electronic Transactions and Cybersecurity Act 2016",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Malawi's Electronic Transactions and Cybersecurity Act 2016, enacted to regulate electronic commerce and cybercrime, establishes the Malawi Communications Regulatory Authority as the oversight body for electronic transactions security, criminalises cybercrime offences including unauthorised computer access, data interference, electronic fraud, and child exploitation material, creates obligations for electronic service providers to maintain transaction records and cooperate with law enforcement, and imposes imprisonment penalties for cybercrime violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/mw-electronic-transactions-cybersecurity-act-2016.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mw-dpa-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mx-agenda-nacional-ia-2024-2030-senado-comision-ia-iniciativa-ley-federal",
    "title": "Mexico Agenda Nacional de IA 2024-2030 (ANIA), Senado Comisión de Innovación e IA (8 October 2024), Iniciativa Ley Federal IA (April 2024 Morena Senador Monreal); Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Mexico does not yet have a consolidated national AI law but operates a multi-track AI governance architecture built around the Agenda Nacional de la Inteligencia Artificial para México 2024-2030 published by the Alianza Nacional de Inteligencia Artificial (ANIA) on 15 May 2024 with 56 concrete actions and 29 regulatory recommendations developed through 13 months and 220 hours of dialogue with 340+ experts from federal government, industry, academia, civil society, and UNESCO. The Agenda was presented to the Senado de la República by Senator Alejandra Lagunes of the Partido Verde Ecologista de México. The Senado established the Comisión de Innovación y Inteligencia Artificial on 8 October 2024 to develop a federal AI normative framework through a three-phase architecture: (1) constitutional reforms to arts 3 and 73 of the Constitución Política de los Estados Unidos Mexicanos recognising the right to access AI benefits and granting Congress power to legislate on AI; (2) a Ley General de Inteligencia Artificial establishing governing principles, governance mechanisms, technical standards, and risk evaluation schemes; (3) sector-specific implementing regulations. The technical-legislative process ran from December 2024 to August 2025 producing the Senado Comisión de IA proposal published at comisiones.senado.gob.mx/inteligencia_artificial. Parallel initiatives include the April 2024 Iniciativa con Proyecto de Decreto por el que se expide la Ley Federal de Inteligencia Artificial filed by Morena Senator Ricardo Monreal Ávila and the April 2025 Iniciativa de Ley Federal para el Desarrollo Ético Soberano e Inclusivo de la Inteligencia Artificial filed in the Cámara de Diputados by Morena and PVEM. The framework operates alongside the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP, 2010) administered by INAI (Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales) and the IFT (Instituto Federal de Telecomunicaciones) sectoral AI policies for telecommunications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "ania_agenda_nacional_2024_2030",
        "ania_agenda_recommendations_national_digital_agency",
        "senado_comision_innovacion_ia_october_2024",
        "senado_three_phase_legal_architecture",
        "iniciativa_monreal_abril_2024",
        "iniciativa_diputados_abril_2025",
        "lfpdppp_underlying_personal_data_basis",
        "ift_sectoral_ai_telecommunications",
        "international_alignment_unesco_oecd_apec",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mexico-cnbv-circular-2019-cybersecurity-financial",
      "eu-ai-act-article-50-transparency-obligations",
      "nist-ai-rmf-1-0-govern-function",
      "unesco-ai-ethics-work",
      "pe-ley-31814-2023-uso-inteligencia-artificial-ds-115-2025-pcm"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "mx-ley-de-adquisiciones-arrendamientos-servicios-sector-publico-compranet",
    "title": "Mexico Ley de Adquisiciones, Arrendamientos y Servicios del Sector Publico (LAASSP) + CompraNet Federal Procurement Platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Ley de Adquisiciones, Arrendamientos y Servicios del Sector Publico (LAASSP, published 4 January 2000 and substantially amended numerous times) is the principal Mexican federal statute governing procurement of goods, leases, and services by dependencias and entidades of the Federal Public Administration. The parallel Ley de Obras Publicas y Servicios Relacionados con las Mismas (LOPSRM, also published 4 January 2000) governs public works procurement. Together with their respective Reglamentos (regulations), they form the federal procurement legal framework administered by the Secretaria de Hacienda y Credito Publico (SHCP, Treasury) at the policy level and by the Secretaria de la Funcion Publica (SFP, Public Function Ministry) for compliance and oversight, with operational delivery through agency-level procurement units (Unidades de Compra) and centralised procurement through the SHCP National Centre for Strategic Sourcing for certain consolidated acquisitions. CompraNet at compranet.hacienda.gob.mx is the mandatory federal electronic procurement system operated by SHCP that publishes procurement notices, processes electronic bids, manages the supplier registry (RUPC - Registro Unico de Proveedores y Contratistas), and supports e-procurement workflows; CompraNet integration is mandatory under the LAASSP for federal procurements above defined thresholds. Procurement methods specified in the LAASSP include licitacion publica (open public tender, the default for at-threshold or above procurements), invitacion a cuando menos tres personas (invitation to at least three persons, for mid-tier acquisitions), and adjudicacion directa (direct award, sole-source under prescribed exceptions). The framework intersects multiple supporting regimes including the Ley General de Responsabilidades Administrativas (LGRA, 2017) which sets the integrity baseline for public servants engaged in procurement and grounds the Sistema Nacional Anticorrupcion (SNA), the Ley General de Transparencia y Acceso a la Informacion Publica administered by INAI for procurement transparency, the Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares (LFPDPPP) for supplier data, and the various free trade agreement government procurement chapters (USMCA, EU-Mexico Global Agreement, CPTPP, Pacific Alliance). Mexico is also exploring procurement reform under the 2024-2030 Administration including consolidated procurement vehicles and AI-assisted catalogue normalisation on CompraNet.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mx-ley-general-de-salud-cofepris-pharmaceutical-regulation",
    "title": "Mexico Ley General de Salud General Health Law COFEPRIS Drug Registration Manufacturing Authorisation Health Surveillance and Pharmacovigilance Framework",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "The Mexican Ley General de Salud (General Health Law) of 7 February 1984 as amended establishes the comprehensive framework for health regulation including pharmaceuticals administered by the Comisión Federal para la Protección contra Riesgos Sanitarios (COFEPRIS) under the Secretaría de Salud organised across operative titles including Title 12 Health Inputs covering Chapter 4 Medicines (Capítulo IV Medicamentos) including Articles 221 through 233 on drug definition classification registration manufacturing labelling and use Chapter 5 Cosmetics Chapter 6 Medical Devices Chapter 7 Diagnostic Reagents and Chapter 9 Health Inputs for Industrial Use Title 13 Sanitary Authorisations and Notices covering Chapter 1 Authorisation Requirements including manufacturing licence (licencia sanitaria) and operating notice (aviso de funcionamiento) Title 14 Pharmacy and Medicines Sale including Chapter 1 Pharmaceutical Establishments Title 17 Sanitary Surveillance covering inspections and Title 18 Sanctions including fines up to 20000 days of minimum wage closure of establishments and revocation of authorisations. Implementation through COFEPRIS technical norms including NOM-059-SSA1 Good Manufacturing Practices NOM-073-SSA1 Pharmacopoeia and the Reglamento de Insumos para la Salud (Regulation on Health Inputs) for detailed procedural requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "mx-lfce-competition-act-2014",
    "title": "Mexico Federal Economic Competition Law (Ley Federal de Competencia Económica - LFCE) 2014",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Ley Federal de Competencia Económica (LFCE - Federal Economic Competition Law) was published in the Diario Oficial de la Federación (DOF) on 23 May 2014, replacing the 1992 LFCE. The law establishes Mexico's constitutional competition framework pursuant to Art. 28 of the Mexican Constitution (as reformed in 2013), which declares monopolies, monopolistic practices, and barriers to free competition to be prohibited. Two autonomous constitutional bodies enforce the LFCE: (1) the Comisión Federal de Competencia Económica (COFECE) - the general competition authority for all economic sectors not regulated by a specific constitutional regulator; and (2) the Instituto Federal de Telecomunicaciones (IFT) - which exercises competition powers exclusively in the telecommunications and broadcasting sectors. Both COFECE and IFT are constitutionally autonomous bodies whose decisions can only be challenged via amparo (constitutional challenge) before federal courts. Prohibited conduct: Absolute monopolistic practices (Art. 53 LFCE) are horizontal restraints treated as per se illegal without requiring proof of competitive harm, including: price-fixing, market and customer allocation, bid-rigging, output restriction, and group boycotts. Criminal liability applies under Art. 254 Bis of the Código Penal Federal: 5 to 10 years imprisonment and a personal fine up to 10% of the defendant's annual personal income for individuals who participate in cartel conduct. Administrative fines for the entity: up to 10% of total annual revenue from Mexico-related sales (LFCE Art. 127). Relative monopolistic practices (Art. 54 LFCE) are vertical restraints assessed under a rule-of-reason standard requiring proof of competitive harm (exclusive dealing, resale price maintenance, tying, market foreclosure). Administrative fine: up to 8% of total annual revenue. Market dominance: Art. 59 LFCE - an economic agent is presumed dominant if it has 50% or more of the relevant market. Merger control (Arts. 86-97 LFCE): transactions meeting applicable COFECE notification thresholds require prior approval before closing. COFECE publishes annual CPI-adjusted UDI-denominated thresholds: as of 2024, notification is required when (a) the transaction value in Mexico exceeds approximately MXN 1.9 billion (18 million times the daily UMA value) or (b) the combined Mexico revenue of all parties exceeds approximately MXN 18.5 billion, or (c) the Mexico revenue or assets of the entity being acquired exceed approximately MXN 950 million. Review periods: 15 business days for Phase 1 (concentrations); up to 70 additional business days for in-depth investigation (Phase 2). Leniency program (Arts. 103-115 LFCE): the first applicant who self-discloses cartel participation and cooperates fully receives full immunity from administrative fines and COFECE will not refer the individual participants for criminal prosecution; subsequent applicants receive graduated fine reductions (40-60% for second applicant; 20-40% for third applicant). Private enforcement: Art. 134 LFCE allows private parties to claim treble damages before federal civil courts for losses caused by monopolistic practices, following a final COFECE or IFT resolution. Limitation period: 10 years from the date of the anticompetitive conduct. No leniency applicant is immune from private damages claims.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-competition",
      "eu-tfeu-article-102-abuse-of-dominance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "mx-lfpdppp-2010",
    "title": "Federal Law on Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This law regulates the processing of personal data by private entities in Mexico, mandating adherence to principles of legality, consent, information, quality, purpose, loyalty, proportionality, and responsibility. It requires data controllers to provide a comprehensive Privacy Notice (Aviso de Privacidad) as per Article 16 and guarantees data subjects' rights of Access, Rectification, Cancellation, and Opposition (ARCO rights) under Article 22.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-122-pii"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "mx-lfpdppp-2010-data-protection-private-sector",
    "title": "Mexico LFPDPPP 2010 - Personal Data Protection in the Private Sector (ARCO Rights)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Mexico's Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares (LFPDPPP, 2010) establishes ARCO rights (Access, Rectification, Cancellation, Opposition), requires a Privacy Notice before data collection, mandates proportionate security measures, regulates sensitive personal data with explicit consent, and is enforced by INAI with administrative sanctions up to 320,000 times the daily minimum wage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "br-lgpd-law-13709-2018-data-protection-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mx-lfpdppp-2025-private-sector-data-protection",
    "title": "Mexico Federal Law for the Protection of Personal Data Held by Private Parties 2025 - SABG as Regulator after INAI Suppression, Effective 21 May 2025",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Private sector data controllers processing personal data in Mexico must comply with the new Federal Law for the Protection of Personal Data Held by Private Parties enacted 20 March 2025 and entered into effect 21 May 2025, with the Ministry for Anti-Corruption and Good Government (SABG) serving as the primary regulator of the private sector following the November 2024 constitutional amendment that eliminated INAI and six other autonomous agencies, while the substantive rights of data subjects and obligations of those who process personal data remain largely unchanged from the 2010 regime, and AI systems involving personal data must comply with both the new Law and INAI's 2024 Guideline on Automated Decision-Making (which continues to apply pending replacement guidance) by clearly informing users when AI systems influence decisions affecting them with disclosures covering system capabilities, limitations, and explainability mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "mx-lfpiorpi-aml-2012",
    "title": "Mexico Federal Law for the Prevention and Identification of Transactions with Illicitly Obtained Funds (LFPIORPI) 2012",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita (LFPIORPI - Federal Law for the Prevention and Identification of Transactions with Illicitly Obtained Funds) was published in the Diario Oficial de la Federación (DOF) on 17 October 2012 and entered into force on 17 July 2013, following the publication of implementing regulations. LFPIORPI is Mexico's primary AML compliance statute for designated non-financial businesses and professions (DNFBPs), complementing the financial sector AML obligations imposed by the Ley de Instituciones de Crédito (LIC) and Ley General de Organizaciones y Actividades Auxiliares del Crédito (LGOAAC) on regulated financial institutions. LFPIORPI designates 16 categories of 'Actividades Vulnerables' (Vulnerable Activities) in Art. 17 whose operators are subject to AML customer identification, transaction alert, and suspicious transaction reporting (STR) obligations. The 16 vulnerable activities include: casino and gaming operators; real estate agents and developers; dealers in precious metals, gemstones, and jewellery; credit and debit card issuers not regulated by the CNBV; mutual fund managers not regulated by the CNBV; currency exchange operators not regulated by the CNBV; armoured vehicle and security services companies; lottery, raffle, and prize organiser operators; dealers in new and used automobiles, aircraft, and vessels; public notaries and brokers processing property transfers; accountants and auditors providing certain services; lawyers providing certain services including property transfers and company formation; financial advisers not regulated by the CNBV; dealers in artworks and antiques; dealers in collectibles; and traders involved in the federal government's public works procurement. Supervisory authority: the Servicio de Administración Tributaria (SAT - Tax Administration Service) is designated as the supervisory authority for all LFPIORPI-obligated entities and conducts compliance examinations, issues sanctions, and maintains the LFPIORPI registration register. Financial intelligence: the Unidad de Inteligencia Financiera (UIF - Financial Intelligence Unit) within the Secretaría de Hacienda y Crédito Público (SHCP) receives STRs filed by LFPIORPI-obligated entities through the SIGER platform (Sistema de Gestión de Reportes - Report Management System). Compliance obligations: (a) registration with SAT as an obligated entity within the applicable deadlines; (b) appointment of a designated AML Compliance Officer (Oficial de Cumplimiento); (c) KYC/CDD: identification and verification of all customers conducting transactions above identification thresholds using government-issued identity documents; (d) maintenance of a customer file (expediente) for identified customers; (e) filing of 'Avisos' (alerts) with the UIF via SIGER for transactions at or above the applicable alert thresholds; (f) filing of STRs (Reportes de Operaciones Relevantes) for suspicious transactions; (g) cash restriction compliance under Art. 32: certain vulnerable activities may not accept cash payments above 3,210 UDIs (approximately MXN 24,000 in 2024) and must refuse and report any attempted cash payment above this limit; (h) record retention for minimum five years. Transaction thresholds (2024 approximate UDI values, UDI approximately MXN 7.52 per day - updated by Banco de México): cash-restriction prohibition threshold: 3,210 UDIs (approximately MXN 24,000) for casino/gaming, public procurement, and certain federal jurisdiction activities; alert (Aviso) filing threshold: varies by activity type - real estate 8,025 UDIs (approximately MXN 60,000), automobiles/aircraft 3,210 UDIs (approximately MXN 24,000), precious metals/jewellery 805 UDIs (approximately MXN 6,000), professional services (lawyers, notaries, accountants) 3,210 UDIs (approximately MXN 24,000), artworks/antiques 805 UDIs. Criminal provisions: LFPIORPI itself provides administrative sanctions only; money laundering criminal liability is established under Art. 400 Bis of the Código Penal Federal, which applies to any person who knowingly handles, transfers, or conceals proceeds of crime, with imprisonment of 5 to 15 years and a fine of 1,000 to 20,000 times the daily general minimum wage. Administrative penalties: SAT may impose fines of MXN 10,000 to MXN 65,000,000 per violation; serious or systemic non-compliance may result in suspension or cancellation of the authorisation to conduct the vulnerable activity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "my-cybersecurity-act-2024",
    "title": "Malaysia Cybersecurity Act 2024 (Act 854)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Malaysia's Cybersecurity Act 2024 (Act 854), gazetted in June 2024, designates National Critical Information Infrastructure in eleven sectors whose operators must implement cybersecurity measures prescribed by the National Cyber Security Agency, submit to NACSA mandatory cybersecurity risk assessments and audits, report cybersecurity incidents to NACSA within prescribed timeframes, and establishes a licence scheme for managed security service providers, with penalties up to RM500,000 and imprisonment up to ten years for serious offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/my-cybersecurity-act-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "my-pdpa-2010"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "my-pdpa-2010",
    "title": "Malaysia Personal Data Protection Act 2010 (Act 709) - PDPA",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Personal Data Protection Act 2010 (PDPA, Act 709) is Malaysia's primary legislation governing the processing of personal data in commercial transactions. The PDPA was enacted on 2 June 2010 and came into force on 15 November 2013. Administered by the Personal Data Protection Commissioner under the Ministry of Communications, the PDPA establishes seven data protection principles that all data users (persons who process personal data) must comply with: (1) General Principle - personal data may only be processed with data subject consent or as otherwise specified; (2) Notice and Choice Principle - data subjects must be notified of the purpose of processing and given the right to choose; (3) Disclosure Principle - personal data may only be disclosed for the purpose it was collected; (4) Security Principle - practical steps must be taken to protect personal data from loss, misuse, or unauthorised access; (5) Retention Principle - personal data must not be kept longer than necessary; (6) Data Integrity Principle - data must be accurate, complete, not misleading, and kept up to date; (7) Access Principle - data subjects have the right to access and correct their personal data. Scope: the PDPA applies to any person who processes personal data in Malaysia in respect of commercial transactions. Government agencies are explicitly excluded. Sensitive personal data (health, political opinions, religious beliefs, commission of criminal offences, biometrics) requires express consent for processing. International data transfers: personal data may not be transferred to any place outside Malaysia except to countries listed in the Personal Data Protection (Place of Transfer) Order 2010 or where the Commissioner grants approval. Data user class registration: specific categories of data users (telecommunications, banking, insurance, health, transport, direct selling, education, and others) must register with the Commissioner under the Personal Data Protection (Class of Data Users) Order 2013. Breach notification: the PDPA 2010 did not originally include mandatory breach notification provisions; however, this obligation was introduced by amendments enacted in 2023 (Personal Data Protection (Amendment) Act 2023), which also added mandatory appointment of a Data Protection Officer for certain data users and data portability rights. Enforcement: the Commissioner may investigate complaints and initiate prosecutions; penalties include fines up to RM 500,000 and imprisonment up to 3 years for data users, and fines up to RM 300,000 and imprisonment up to 2 years for data processors who fail to comply with instructions. Malaysia has obtained an adequacy finding from the United Kingdom (post-Brexit) for data transfers. The PDPA applies to all sectors engaged in commercial transactions with Malaysian data subjects, including foreign entities processing personal data of Malaysian residents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "my-pdpa-amendment-act-2024",
    "title": "Malaysia Personal Data Protection (Amendment) Act 2024 - Three-Phase Rollout, Mandatory DPO, Breach Notification, and Removal of Whitelist System",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Data controllers and data processors operating in Malaysia must comply with the Personal Data Protection (Amendment) Act 2024, rolled out in three phases: from 1 January 2025 expanded sensitive personal data definition to include biometric data and definition of personal data breach to mean any breach, loss, misuse or unauthorised access; from 1 April 2025 direct obligations on data processors; from 1 June 2025 mandatory appointment of a Data Protection Officer by both data controllers and processors (with notification to the Commissioner), obligatory breach notification to the Personal Data Protection Commissioner as soon as practicable (and to affected individuals without unnecessary delay where significant harm is likely), and removal of the whitelist system for cross-border data transfers, with the term data user replaced by data controller throughout the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "my-treasury-instructions-government-procurement-perolehan-kerajaan",
    "title": "Malaysia Treasury Instructions on Government Procurement (Arahan Perbendaharaan, Perolehan Kerajaan) and Government Procurement Act 1993",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "Malaysian public procurement is governed by a layered framework: the Government Procurement Act 1993 (Akta Perolehan Kerajaan 1993), the Treasury Instructions on Government Procurement (Arahan Perbendaharaan, Perolehan Kerajaan / TI series including TI 168 to 207 on procurement matters), and the Treasury Circular Letters (Surat Pekeliling Perbendaharaan / SPP) issued by the Ministry of Finance (Kementerian Kewangan Malaysia / MOF). The Government Procurement Division of the Ministry of Finance (Bahagian Perolehan Kerajaan, MOF) is the central procurement regulator. The Malaysian Government Electronic Procurement System (ePerolehan / eperolehan.gov.my) operated by Commerce Dot Com Sdn Bhd is the mandatory electronic procurement platform for in-scope procurement by federal ministries, federal departments, federal statutory bodies, and federal-controlled corporations. Procurement methods established by the Treasury Instructions include (a) direct purchase (Pembelian Terus, low-value below RM50,000), (b) quotation (Sebut Harga, medium-value RM50,000 to RM500,000), (c) tender (Tender, above RM500,000 with open or selective methods), and (d) limited tender and direct negotiation (Rundingan Terus, under prescribed exceptions). The Malaysian Anti-Corruption Commission Act 2009 (Akta Suruhanjaya Pencegahan Rasuah Malaysia 2009) and the Section 17A Corporate Liability for Corruption provision effective 1 June 2020 impose corporate criminal liability for corruption-related procurement misconduct. The Government Procurement framework operates within Malaysia's trade obligations under CPTPP (Comprehensive and Progressive Agreement for Trans-Pacific Partnership) - Malaysia is a party with procurement chapter obligations, the ASEAN Framework Agreement on Services, and RCEP. Malaysia is NOT a party to the WTO Government Procurement Agreement (GPA). Bumiputera preference policies and value-add domestic preference policies apply within the framework's preferential treatment provisions for Bumiputera-status suppliers and SMEs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "my-pdpa-2010",
      "my-cybersecurity-act-2024",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mz-decreto-5-2016-regulamento-contratacao-empreitada-obras-publicas",
    "title": "Mozambique Decreto 5/2016 of 8 March 2016 Regulamento de Contratacao de Empreitada de Obras Publicas, Fornecimento de Bens e Prestacao de Servicos ao Estado and UFSA",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Republic of Mozambique Decreto No. 5/2016 of 8 March 2016 - Regulamento de Contratacao de Empreitada de Obras Publicas, Fornecimento de Bens e Prestacao de Servicos ao Estado (Regulation on Public Works, Goods Supply and Services Contracting for the State) approved by Conselho de Ministros on 8 March 2016 and published in Boletim da Republica I Serie No. 38 of 8 March 2016 is the principal Mozambican regulatory instrument governing procurement of public works, goods supply, and services by entities of the State Apparatus (Aparelho do Estado) including the Central Government ministries, the Provincial Governments (Governos Provinciais), the District Governments (Governos Distritais), Municipal Councils (Conselhos Municipais), institutes and other public administrative entities, State-owned enterprises subject to public procurement, and other contracting entities financed from the State Budget or off-budget funds. Decreto 5/2016 replaced the prior Decreto 15/2010 and modernised the Mozambican procurement framework. The Unidade Funcional de Supervisao das Aquisicoes (UFSA / Functional Unit of Procurement Supervision) under the Ministry of Economy and Finance is the central regulatory authority responsible for procurement regulation, oversight, and procurement guidance. The Sistema Electronico de Compras Publicas (e-Procurement / Sistema-E-SISTAFE related) under rollout is the federal e-procurement platform. The Tribunal Administrativo (Administrative Tribunal) handles procurement appeals. Procurement methods established by Decreto 5/2016 art. 17 to 91 comprise (a) Concurso Publico (Public Tender, the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Concurso Limitado (Limited Tender, with prequalification or restricted to pre-approved suppliers), (c) Concurso por Cotacoes (Quotation Tender, for medium-value acquisitions), (d) Concurso de Pequena Dimensao (Small-Dimension Tender, for low-value acquisitions), (e) Ajuste Directo (Direct Adjustment, sole-source under prescribed exceptions in art. 91 including emergency, sole supplier for technical reasons, prior unsuccessful tendering, and prescribed-class exemptions), (f) Concurso em Duas Etapas (Two-Stage Tender, for complex acquisitions), and (g) Catalogo Electronico (Electronic Catalogue). The Tribunal Administrativo conducts ex-post procurement audit. The Gabinete Central de Combate a Corrupcao (GCCC) has investigative jurisdiction over procurement-related corruption. Mozambique is a party to SADC, AfCFTA, and UNCAC. Mozambique is NOT a party to the WTO GPA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "mz-dp-law-2021",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "mz-dp-law-2021",
    "title": "Mozambique Personal Data Protection Law - INTIC Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Mozambique Law No. 8/2021 on Personal Data Protection (April 2021) establishes data subject rights, mandatory data controller registration, consent-based processing obligations, and cross-border transfer controls. The Instituto Nacional das Tecnologias de Comunicação (INTIC) serves as the designated supervisory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "na-pipa-2022",
    "title": "Namibia Data Protection Bill (draft, not yet enacted) - proposed personal data protection framework",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "As of 2026 Namibia has NOT enacted a comprehensive data protection law; the Data Protection Bill (published in draft form, most recently 2022) remains pending. The draft proposes a framework for lawful processing of personal information, an independent supervisory Data Protection Authority, core principles (lawfulness, purpose limitation, proportionality, accuracy, security), data subject rights (access, correction, deletion, objection), mandatory breach notification, conditions for special personal information, and cross-border transfer safeguards. Until enacted and brought into force these provisions are not legally binding in Namibia.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/na-pipa-2022.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "na-public-procurement-act-15-2015-cppa-central-procurement-board",
    "title": "Namibia Public Procurement Act 15 of 2015 effective 1 April 2017 and Central Procurement Board of Namibia (CPBN)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Republic of Namibia Public Procurement Act 15 of 2015 (Act No. 15 of 2015, Government Gazette of Namibia No. 5900 of 31 December 2015) effective 1 April 2017 as amended by the Public Procurement Amendment Act 1 of 2022 effective 8 December 2022 and supplemented by the Public Procurement Regulations published in GN 47 of 1 February 2017 (and subsequent amending GNs), is the principal Namibian statute governing procurement of goods, works, and consultancy services by public entities including the Government of Namibia (Central Government Offices, Ministries, and Agencies), regional councils, local authorities, public-sector enterprises (Public Enterprises Governance Act companies including NamPower, NamWater, NamPost, Nampa, and others), state-owned enterprises, statutory bodies, and other entities financed wholly or partly from the State Revenue Fund. The Public Procurement Act 2015 replaced the prior Tender Board of Namibia Act 16 of 1996 and substantially modernised the Namibian procurement regime. The Procurement Policy Unit (PPU) within the Ministry of Finance and Public Enterprises is the central procurement policy authority. The Central Procurement Board of Namibia (CPBN, cpb.org.na) is the centralised public bidding body responsible for procurement above prescribed thresholds. The Procurement Tribunal handles procurement appeals. The Government Procurement Information System (GPIS, gpis.gov.na under rollout) is the federal e-procurement platform. Procurement methods established by Public Procurement Act 2015 sec. 27 to 39 comprise (a) Open Advertised Bidding (the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Restricted Bidding (with prequalification), (c) Request for Proposals (for consulting services), (d) Request for Sealed Quotations (for medium-value acquisitions), (e) Direct Procurement (sole-source under prescribed exceptions in sec. 33 including emergency, sole supplier for technical reasons, prior failed bidding, and prescribed-class exemptions), (f) Two-Stage Bidding (for complex acquisitions), (g) Electronic Reverse Auction, and (h) Procurement Through Mutual Agreement (for low-value and prescribed exceptions). The Auditor-General conducts ex-post procurement audit. The Anti-Corruption Commission (ACC) has investigative jurisdiction over procurement-related corruption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "na-pipa-2022",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nabers-energy-rating-australia-commercial",
    "title": "NABERS Energy Rating - Australian Commercial Building Performance: Base Building, Tenancy, Whole Building Rating Methodology, Commitment Agreements and Disclosure Requirements",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The NABERS Energy Rating system requires commercial building owners, managers, and tenants to measure and publicly disclose verified energy performance using a nationally consistent 1-6 star scale, based on actual energy consumption, occupancy, and climate-adjusted benchmarks. Applicable to office buildings, data centres, shopping centres, and retail tenancies under the Commercial Building Disclosure (CBD) Program and state-based planning schemes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-national-construction-code-2022-ncc",
      "iso-50001-2018-energy-management-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nagoya-protocol-genetic-resources-2010",
    "title": "Nagoya Protocol on Access to Genetic Resources and the Fair and Equitable Sharing of Benefits Arising from their Utilization to the Convention on Biological Diversity",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Nagoya Protocol requires users of genetic resources to obtain prior informed consent (PIC) from provider countries and establish mutually agreed terms (MAT) for benefit-sharing. It applies to all activities involving the utilization of genetic resources that fall under the scope of the Convention on Biological Diversity, as specified in Article 1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cbd-convention-biological-diversity-1992"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "naic-accelerated-underwriting-model-bulletin-2022",
    "title": "NAIC Accelerated Underwriting Model Bulletin 2022 - AI/ML in Insurance Underwriting: Fair Treatment Principles, External Data Source Governance, Model Validation, Disparate Impact Testing, Consumer Transparency Disclosure and Regulatory File Review Standards",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This guidance establishes a regulatory framework for insurers using accelerated underwriting (AU) techniques involving external data, predictive models, and AI/ML, requiring adherence to sound actuarial principles, transparency, and non-discrimination. Key oversight provisions are derived from NAIC’s 2024 regulatory guidance adopted by the Life Insurance and Annuities (A) Committee.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "eu-eiopa-guidelines-orsa-2015"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "naic-cybersecurity-model-law-668-insurance",
    "title": "NAIC Insurance Data Security Model Law 668 - Cybersecurity Program, Risk Assessment and Incident Notification for Insurers",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This model law requires insurance licensees to develop, implement, and maintain a comprehensive written information security program based on an ongoing risk assessment, as mandated by Section 4. It also establishes standards for data security, investigation of, and notification to the state insurance commissioner of a cybersecurity event per Section 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-161r1-csrm-practices"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "naic-market-conduct-annual-statement-mcas-2023",
    "title": "NAIC Market Conduct Annual Statement (MCAS) 2023 - Standardised Market Conduct Data Collection for Life, Health and Property/Casualty Insurers",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "The NAIC Market Conduct Annual Statement (MCAS) requires life, health, and property/casualty insurers exceeding specified premium thresholds to annually submit standardized data on their market conduct activities. As outlined in the MCAS Data Call and Definitions, this data covers areas such as complaints, claims handling, underwriting, and producer licensing to help state regulators identify trends and potential compliance issues.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "naic-model-act-data-security-insurance-2017",
    "title": "NAIC Insurance Data Security Model Law (Model No. 668) - Information Security Program, Risk Assessment, Third-Party Oversight, Cybersecurity Event Notification, and Annual Certification",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Requires all licensed insurers, reinsurers, and other covered financial institutions operating in the U.S. insurance sector to implement a comprehensive information security program based on risk assessment, including written safeguards, third-party provider oversight, incident response planning, and mandatory 72-hour notification to the state insurance commissioner following a cybersecurity event as defined in Section 7. Applies to licensees under state insurance law adopting the model.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "eu-eiopa-guidelines-orsa-2015"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "naic-model-bulletin-ai-systems-insurers-2023",
    "title": "NAIC Model Bulletin on the Use of Artificial Intelligence by Insurance Companies (Adopted December 2023; Aligned with NAIC Principles of Artificial Intelligence Adopted at the 2020 Summer National Meeting; Developed by the Big Data and Artificial Intelligence (H) Working Group)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2023-12-04",
    "bluf": "The NAIC Model Bulletin on the Use of Artificial Intelligence by Insurance Companies is the National Association of Insurance Commissioners' authoritative guidance for state insurance regulators and insurers on the responsible use of AI in insurance. The Bulletin was adopted in December 2023 by the NAIC and was developed by the Big Data and Artificial Intelligence (H) Working Group, which was established in 2019 to study the development of artificial intelligence, its use in the insurance sector, and its impact on consumer protection and privacy, marketplace dynamics, and the state-based insurance regulatory framework. The Bulletin operationalises the NAIC Principles of Artificial Intelligence that were adopted by the full NAIC membership at the 2020 Summer National Meeting. Per the NAIC's official summary, 'the bulletin establishes guidelines and expectations to ensure responsible use of AI by insurance companies that align with the NAIC Principles of Artificial Intelligence. It reminds insurers that decisions or actions made or supported by AI must comply with all applicable insurance laws and regulations, sets forth expectations as to how insurers will govern the use of AI, and advises insurers of the type of information the Department may request during an investigation or examination.' Although the Model Bulletin is not itself binding (NAIC model documents become operative only when adopted by individual state insurance departments), it is the de facto national standard and has been adopted or is in the process of adoption by many state insurance departments - the NAIC tracks adoption status on the AI Model Bulletin State Adoption Map. The Bulletin sits within a broader NAIC AI workstream that includes the AI Systems Evaluation Tool - being piloted by 12 participating states as of March 2026 to support regulators in market conduct, financial analysis and financial examination contexts - anticipated for adoption at the 2026 Fall National Meeting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "naic-accelerated-underwriting-model-bulletin-2022",
        "us-naic-cyber-insurance-model-bulletin-2022",
        "iaisweb-ai-application-paper-insurance-2024",
        "eu-ai-act-2024",
        "us-cfpb-circular-2023-03-adverse-action-ai"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "naic-accelerated-underwriting-model-bulletin-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "naic-model-data-security-law-668-insurance",
    "title": "NAIC Insurance Data Security Model Law (#668)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This model law requires insurance licensees to develop, implement, and maintain a comprehensive written information security program based on an ongoing risk assessment, as mandated by Section 4. It also establishes standards for investigating cybersecurity events and requires notification to the state insurance commissioner within 72 hours if certain conditions are met, per Section 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3",
      "sec-regulation-s-p-safeguarding",
      "us-sec-cybersecurity-disclosure-2023",
      "iso-22301-biz-continuity"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "naic-model-rbc-health-insurance-2023",
    "title": "NAIC Risk-Based Capital for Health Organizations - Model Regulation (2023)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-08-20",
    "bluf": "This model regulation requires U.S. health organizations, including insurers and HMOs, to calculate and maintain capital above a minimum formula-based threshold, known as the Risk-Based Capital (RBC) level. As specified in Section 4, failure to maintain capital above defined trigger points (e.g., Company Action Level) mandates specific corrective actions by the organization and potential regulatory intervention to ensure solvency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "100.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "naic-model-rbc-life-insurance-2023",
    "title": "NAIC Risk-Based Capital for Life Insurance Companies - Model Regulation and Annual RBC Report Requirements (2023)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-08-15",
    "bluf": "This model regulation requires U.S. life insurance companies to calculate and report their Risk-Based Capital (RBC) annually to state regulators, ensuring they hold sufficient capital to support their business operations in relation to their risk profile. As per Section 4, insurers must take specific corrective actions if their Total Adjusted Capital falls below defined thresholds, such as the Company Action Level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "naic-model-rbc-property-casualty-2023",
    "title": "NAIC Risk-Based Capital for Property and Casualty Insurance Companies - Model Regulation (2023)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This model regulation requires property and casualty insurers to maintain capital commensurate with their overall risk profile, calculated via a specific formula. It establishes four levels of regulatory action (Company Action, Regulatory Action, Authorized Control, and Mandatory Control) based on the insurer's Total Adjusted Capital (TAC) to Authorized Control Level Risk-Based Capital (RBC) ratio, as defined in Section 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "naic-privacy-protection-model-regulation-672",
    "title": "NAIC Privacy of Consumer Financial and Health Information Regulation (Model #672)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This model regulation requires insurance licensees to provide consumers with a clear privacy notice regarding their information-sharing practices and to offer an 'opt-out' right before sharing nonpublic personal financial information with nonaffiliated third parties, as mandated by Section 4 and Section 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ccpa-cpra",
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "naic-producer-licensing-model-act",
    "title": "NAIC Producer Licensing Model Act - State Insurance Licence Requirements: Lines of Authority, Continuing Education, Nonresident Reciprocity, Background Checks, Appointments, Termination Reporting and NIPR Portal Compliance",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This model act establishes uniform standards for the licensing and regulation of insurance producers across U.S. states, requiring background checks, pre-licensing education, continuing education, appointment reporting, and termination notifications. Key requirements are codified in Sections 3, 4, 5, 6, and 10 of the Model Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "namibia-minerals-prospecting-mining-act-33-1992",
    "title": "Namibia Minerals (Prospecting and Mining) Act 33 of 1992 - Licensing and Royalty Framework",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2015-08-01",
    "bluf": "Namibia's Minerals (Prospecting and Mining) Act 33 of 1992, as amended by Act 8 of 2015, governs five licence categories (EPL, Mining Licence, Retention Licence, Claim, Reconnaissance), mandates Environmental Management Plans, sets royalties at 3% for diamonds and 2% for other minerals, and requires government participation rights on major deposits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "nist_csf",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-msha-30-cfr-part-56-surface-mine-safety",
      "tanzania-mining-act-no-14-2010"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nato-ai-principles-2021",
    "title": "NATO Principles of Responsible Use of Artificial Intelligence in Defence",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-10-24",
    "bluf": "NATO Allies must ensure that Artificial Intelligence applications in defence are developed and used in accordance with six core principles: Lawfulness, Responsibility and Accountability, Explainability and Traceability, Reliability, Governability, and Bias Mitigation. These principles, outlined in the NATO AI Strategy, guide the ethical and responsible integration of AI to maintain a technological edge while upholding NATO's values and international law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dfars-7012-defense-cyber",
      "as9100-rev-d-qms",
      "nist-ai-100-5-global-engagement-plan",
      "iso-42001-transparency"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nato-aqap-2110-quality-assurance-defence",
    "title": "NATO Quality Assurance Requirements for Design, Development and Production: QMS Requirements for Defence Contractors, Configuration Management, First Article Inspection, Statistical Techniques, Government Quality Assurance (GQA) and AS9100 Relationship",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes quality management system requirements for NATO defence contractors involved in design, development, and production, with specific mandates for configuration management, first article inspection, and statistical process control. Key requirements are defined under AQAP-2110, though specific clause references are not present in the provided source text.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "as9100-rev-d-qms",
      "cmmc-2-audit",
      "nist-800-171-cui",
      "dfars-7012-defense-cyber"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nato-cyber-defence-policy-2023",
    "title": "NATO Cyber Defence Policy 2023 - Collective Defence in Cyberspace and Attribution Framework",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This policy establishes cyberspace as a military domain of operations and affirms that a significant malicious cyber activity could lead to the invocation of Article 5 of the North Atlantic Treaty. It requires NATO and its Allies to enhance cyber resilience, develop capabilities for collective defence, and establish a framework for the political attribution of cyber attacks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dfars-7012-defense-cyber",
      "nist-800-171-rev-3",
      "nato-ai-principles-2021",
      "pqc-migration-logic",
      "us-dod-ai-ethical-principles-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nc-lil-2018",
    "title": "New Caledonia - Loi Informatique et Libertés (French Data Protection Law)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "New Caledonia is a French special collectivity with a unique constitutional status established by the Noumea Accord and the French Organic Law of 19 March 1999. As an EU Overseas Country and Territory (OCT) rather than an EU outermost region, the EU General Data Protection Regulation (GDPR) does not directly apply in New Caledonia. The French Loi Informatique et Libertés (Law No. 78-17 of 6 January 1978 on data processing, files and freedoms), as modified by Law No. 2018-493 of 20 June 2018 and subsequent implementing decrees, applies in New Caledonia through the constitutional principle that French laws of sovereignty and public order apply in all French territories unless specifically excluded or assigned to local competence under the Organic Law. The Commission Nationale de l'Informatique et des Libertés (CNIL) exercises supervisory jurisdiction over data protection in New Caledonia. Organisations processing personal data in New Caledonia must comply with the French Loi Informatique et Libertés as applicable there: establishing a lawful basis for processing, respecting individual rights of access, rectification, and opposition, implementing appropriate security measures, meeting any CNIL notification or authorisation obligations for special categories of processing, and applying safeguards for transfers of personal data to third countries. CNIL has authority to investigate, advise, and sanction violations of French data protection law in New Caledonia.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/nc-lil-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ne-pdp-ord-2017",
    "title": "Niger Law No. 2017-28 on Personal Data Protection",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Niger enacted Law No. 2017-28 of 3 May 2017 on the Protection of Personal Data, establishing a framework for the lawful collection, storage, and processing of personal data. The law is administered by the Haute Autorité de Protection des Données à caractère Personnel (HAPDP). It aligns with the ECOWAS Supplementary Act on Personal Data Protection as Niger is a member of ECOWAS. Controllers must register with the HAPDP, obtain a lawful basis for processing, issue privacy notices, and observe data subject rights including access, rectification, opposition, and erasure. Special categories of sensitive personal data require explicit consent and prior HAPDP authorisation. Cross-border transfers are restricted to countries with adequate protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ne-pdp-ord-2017.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nec4-engineering-construction-contract",
    "title": "NEC4 Engineering and Construction Contract - Core Clauses, Payment, Compensation Events and Early Warning Obligations",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The NEC4 Engineering and Construction Contract (ECC) mandates a collaborative approach to contract management, requiring parties to proactively manage risks through an early warning system (Clause 16), adhere to strict timelines for payment applications and certifications (Clause 5), and follow a defined process for notifying and assessing compensation events (Clause 6). This framework applies to clients, contractors, project managers, and supervisors involved in engineering and construction projects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pmbok-7-guide-pm",
      "iso-37001-anti-bribery"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nerc-cip-002-5-bes-cyber-system-categorisation",
    "title": "NERC CIP-002-5.1a BES Cyber System Categorisation - High, Medium and Low Impact Classification and Annual Review Requirements",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard requires Responsible Entities in the North American bulk power system to identify and categorize their Bulk Electric System (BES) Cyber Systems into High, Medium, or Low impact categories based on the criteria in Attachment 1. Per Requirement R1, this categorization must be reviewed annually by a designated senior manager or delegate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-csf-2",
      "fips-199-security-categorization",
      "nist-ir-8286d-bia-for-risk",
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nerc-cip-005-006-ics-energy-cyber-security",
    "title": "NERC CIP-005-6 Electronic Security Perimeter(s) & CIP-006-6 Physical Security of BES Cyber Systems",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Mandates that Responsible Entities identify and protect Bulk Electric System (BES) Cyber Systems by implementing a rigorous Electronic Security Perimeter (ESP) to control network access (CIP-005 R1) and a documented Physical Security Plan to restrict and monitor physical access to these systems (CIP-006 R1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-7628-smart-grid-cybersecurity",
      "nist-sp-800-57-key-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nerc-cip-007-6-systems-security-management",
    "title": "NERC CIP-007-6 Systems Security Management - Ports and Services, Patch Management, Malicious Code Prevention and Security Event Monitoring",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard requires responsible entities to define methods, processes, and procedures for securing Bulk Electric System (BES) Cyber Systems by managing logical ports and services, implementing security patch management, deploying malicious code prevention, and monitoring security events, as detailed in Requirements R1 through R5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-800-53-ac2",
      "cis-controls-v8",
      "guide-computer-security-log-management",
      "malware-incident-prevention-handling"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nerc-cip-v6-cyber",
    "title": "NERC CIP: Energy Cyber Infrastructure",
    "domain": "Industrial IoT & Energy",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The NERC Critical Infrastructure Protection (CIP) standards are the mandatory cybersecurity requirements for North American bulk power systems. They focus on identifying 'BES' (Bulk Electric System) Cyber Systems and implementing defense-in-depth controls to protect critical energy reliability from cyber threats.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-iacs",
      "nistir-7628-smartgrid",
      "identity-and-access-management-electric-utilities",
      "nist-sp-1800-32-securing-ders"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nerc-reliability-standards-compliance-overview",
    "title": "NERC Reliability Standards - Overview of BAL, FAC, INT, IRO, PRC, TOP, VAR Compliance Obligations for Bulk Electric Systems",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Mandates that all owners, operators, and users of the Bulk Electric System (BES) in North America comply with specific, enforceable Reliability Standards to ensure the adequacy and security of the grid, as authorized by Section 215 of the Federal Power Act. This node focuses on standards for Balancing (BAL), Facilities (FAC), Interchange (INT), Interconnection Reliability Operations (IRO), Protection (PRC), Transmission Operations (TOP), and Voltage/Reactive (VAR).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "netherlands-aliens-act-2000-ind",
    "title": "Netherlands Aliens Act 2000 - Verblijfsvergunning and Knowledge Migrant Framework",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The Netherlands Aliens Act 2000 (Vreemdelingenwet 2000, Stb. 2000, 495) governs entry and residence of third-country nationals. The IND (Immigratie- en Naturalisatiedienst) handles all permit applications. Entry for stays exceeding 90 days requires an MVV (machtiging tot voorlopig verblijf - provisional residence authorisation) from a Dutch embassy, followed by application for a verblijfsvergunning (residence permit). The Kennismigrant (knowledge migrant) scheme requires EUR 4,752/month (2024, under-30: EUR 3,485) salary. The Self-Employed Person's Permit (zelfstandige) requires an economic interest points test. The IND decides within 90 days for standard applications and 14 days for knowledge migrants.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "germany-residence-act-aufenthaltsgesetz-2004-bamf"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "netherlands-remote-gambling-act-2019",
    "title": "Netherlands Remote Gambling Act (KOA) 2019 - Licences, Responsible Gambling Obligations, Advertising Restrictions and CRUKS Self-Exclusion Register",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Netherlands Remote Gambling Act (KOA) 2019 requires all providers of online gambling services targeting Dutch players to obtain a licence from the Kansspelautoriteit and comply with strict responsible gambling, advertising, and player protection rules. Key obligations include integration with the CRUKS self-exclusion register and adherence to advertising restrictions under the authority’s supervision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "fatf-recommendation-16-travel-rule-crypto"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "netherlands-remote-gambling-act-koa-2021-ksa",
    "title": "Netherlands Remote Gambling Act 2021 (KOA) - Kansspelautoriteit Licensing Framework",
    "domain": "Gaming & Gambling",
    "version": "2.1",
    "last_updated": "2026-05-10",
    "bluf": "The Wet kansspelen op afstand (Remote Gambling Act, KOA), which came into force on 1 October 2021, opened the Dutch online gambling market to licensed operators after a decade of prohibition. The Kansspelautoriteit (KSA) is the Netherlands Gambling Authority responsible for licensing and supervision. Operators must hold a KSA online gambling licence (granted for 5 years, renewable), implement the CRUKS national self-exclusion register mandatory across all operators, apply Dutch responsible gambling tools (deposit limits, loss limits, cool-off periods), and comply with the Dutch Anti-Money Laundering Directive (Wwft) requirements. The KOA mandates segregation of player funds. Advertising is strictly regulated - untargeted advertising to under-24s is prohibited. Criminal penalties under the KOA include imprisonment up to 2 years for unlicensed gambling operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_article",
        "aml",
        "eu_ai_act",
        "eu_dsa",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021",
      "eu-5amld-article-2-gambling-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "netherlands-remote-gaming-act-2021-ksa",
    "title": "Netherlands Remote Gambling Act 2021 - Regulation of Online Gambling, Licensing by the Kansspelautoriteit, Responsible Gambling Measures, Advertising Restrictions, Anti-Money Laundering Obligations, and Enforcement Powers",
    "domain": "Gaming & Gambling",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Netherlands Remote Gambling Act 2021 establishes a legal framework for online gambling operators offering services to Dutch residents, requiring a license from the Kansspelautoriteit (KSA). Operators must comply with responsible gambling measures (including CRUKS self-exclusion integration), strict advertising rules (Article 4.1), AML obligations under Article 5.1, and pay a 30.5% gross gaming revenue (GGR) tax, with KSA empowered to impose sanctions for non-compliance under Article 9.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "eu-gdpr-online-gaming-data-protection",
      "eu-payment-services-directive-2-gaming-deposits"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "netherlands-space-activities-act-2007",
    "title": "Netherlands Space Activities Act 2007 (Wet ruimtevaart) - Dutch Commercial Space Regulatory Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Netherlands Space Activities Act (Wet ruimtevaart, Act of 24 January 2007, Staatsblad 2007, 97) applies to space activities carried out by Dutch legal persons or organisations registered in the Netherlands and to space activities launched from Dutch territory. The Act requires a licence issued by the Minister of Economic Affairs (delegated to the Netherlands Enterprise Agency, RVO) for all qualifying space activities. The Netherlands is home to the European Space Research and Technology Centre (ESTEC) in Noordwijk, the main technical hub of ESA. The Act implements Dutch obligations under the five UN space treaties including mandatory liability insurance and space object registration. An implementing Decree (Besluit ruimtevaart, 2007) specifies insurance minimums and procedural requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "esa_convention_1975",
        "eu_space_programme_regulation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "esa-convention-1975-european-space-agency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nevada-gaming-control-act-board-regulations",
    "title": "Nevada Gaming Control Act - NGC Regulations: Licence Classification, Suitability Investigations, Internal Controls, Accounting Procedures, Advertising Standards and Problem Gambling Requirements",
    "domain": "Gaming & Gambling",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes licensing, suitability, internal control, accounting, advertising, and responsible gaming requirements for all persons and entities operating gaming activities in Nevada, pursuant to Chapter 463 of the Nevada Revised Statutes and Commission Regulation 5. It applies to applicants, licensees, key employees, and gaming vendors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-directive-5-gambling-sector",
      "curacao-gaming-control-board-ordinance-2023",
      "brazil-sports-betting-law-14790-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "new-jersey-division-gaming-enforcement-dge",
    "title": "New Jersey Division of Gaming Enforcement - Atlantic City and Online Casino Regulations: Licence Categories, Internal Control Standards, Casino Simulcasting, Internet Gaming Regulations and Audit Requirements",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes licensing, operational, and audit requirements for land-based and online gaming operators in New Jersey under N.J.A.C. 19:45-1.1 et seq. It applies to casino licensees, internet gaming operators, and their key employees, requiring compliance with Internal Control Standards (ICS), anti-money laundering protocols, and annual independent audits per N.J.A.C. 19:45-5.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-aml-directive-5-gambling-sector"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "new-york-convention-1958-foreign-arbitral-awards",
    "title": "New York Convention 1958 - Recognition and Enforcement of Foreign Arbitral Awards",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Convention on the Recognition and Enforcement of Foreign Arbitral Awards, adopted on 10 June 1958 in New York and entered into force on 7 June 1959, has 172 Parties and is universally regarded as the most important international arbitration treaty in existence. It creates the global framework under which arbitral awards made in one signatory State can be recognised and enforced in any other signatory State, making international commercial arbitration a practically enforceable dispute resolution mechanism. Article II requires signatory States to recognise arbitration agreements in writing, compelling courts to refer parties to arbitration when there is a valid arbitration clause. Article III requires States to recognise and enforce foreign arbitral awards in accordance with the Convention. Articles IV and V establish the enforcement procedure: the party seeking enforcement submits the award and arbitration agreement to the competent court; the court must enforce unless the opposing party establishes one of the five grounds for refusal in Article V(1) (incapacity of parties, invalidity of agreement, denial of procedural fairness, excess of jurisdiction, arbitral tribunal composition irregularity) or the court finds one of the two public policy grounds in Article V(2) (non-arbitrability under national law, violation of public policy). The Convention operates on the 'pro-enforcement' principle - courts apply a strong presumption in favour of enforcement; the burden of proof on refusal grounds lies with the opposing party. Many States adopted the New York Convention with the 'reciprocity reservation' (enforcing awards made only in other Convention States) and/or the 'commercial reservation' (applying only to commercial disputes). The Convention has been applied and interpreted consistently by courts in over 170 countries, making it the cornerstone of the $1T+ international arbitration industry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-arbitration-2006",
      "un-convention-against-corruption-uncac-2003",
      "eu-directive-combating-corruption-2024-1760"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "new-york-health-data-privacy-2026",
    "title": "New York Health Information Privacy & SHIELD Act (2026)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "New York’s SHIELD Act and health-specific privacy rules require reasonable security safeguards for private information (including health data), mandatory breach notification to the NY Attorney General and affected individuals within 30 days, risk assessments, and enhanced protections for biometric and health data. Entities doing business in New York face private right of action and significant penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "new-york-telehealth-shield-2026",
    "title": "New York Telehealth & SHIELD Act Health Data Updates 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "New York mandates full licensure for telehealth providers serving NY patients. The SHIELD Act requires reasonable security measures for private health information with expanded breach notification. 2026 updates emphasize audio-only parity and data protection in virtual care.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "new-zealand-biosecurity-act-1993-mpi",
    "title": "New Zealand Biosecurity Act 1993 - MPI Border Clearance and Pest Management Framework",
    "domain": "Agriculture & Agritech",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "New Zealand's Biosecurity Act 1993 (No. 95 of 1993, as amended) is the primary statute governing the exclusion, eradication, and management of harmful organisms. The Ministry for Primary Industries (MPI) administers the Act. New Zealand's geographic isolation and export-dependent agricultural economy make biosecurity one of the highest-priority policy areas - MPI biosecurity inspections are conducted at all international airports and seaports. Goods arriving without biosecurity clearance may be seized and treated or destroyed. The Act establishes a National Policy Direction on Biosecurity framework, Regional Pest Management Plans, and National Pest Management Plans for declared pests. Infringement notices (on-the-spot fines) may be issued for minor biosecurity offences. The Mycoplasma bovis eradication programme (commenced 2018) is an example of the Act's pest eradication provisions in action. Import Health Standards (IHS) specify the biosecurity requirements for all imported goods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ippc",
        "oie",
        "wto_sps",
        "customs",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "new-zealand-building-act-2004",
    "title": "New Zealand Building Act 2004 - Building Consents, Code Compliance and Earthquake-Prone Buildings",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Building Act 2004 (Public Act 2004 No 72) establishes the framework for regulating building work in New Zealand. All building work must comply with the New Zealand Building Code. A building consent from the local building consent authority (BCA) is required before commencing most building work. Earthquake-prone buildings - those with seismic capacity below 34% of the New Building Standard (NBS) for new buildings - must be seismically strengthened or demolished within 15 years (high seismic risk areas) or 25 years (medium and low seismic risk areas) of being identified. Restricted building work must be carried out by or supervised by a Licensed Building Practitioner (LBP).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nz_building_code",
        "nz_resource_management_act",
        "australia_ncc_2022",
        "ilo_construction_convention_167",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-national-construction-code-2022",
      "uk-cdm-regulations-2015-construction"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "new-zealand-fair-trading-act-1986-commerce-commission",
    "title": "New Zealand Fair Trading Act 1986 - Commerce Commission Misleading Conduct Enforcement",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "New Zealand's Fair Trading Act 1986 (FTA, No. 121 of 1986, as amended through 2022) prohibits misleading and deceptive conduct in trade, false representations, unfair contract terms, and bait advertising; is enforced by the Commerce Commission with injunction and pecuniary penalty powers; extended by the Consumer Guarantees Act 1993 for goods and services sold to consumers; and was amended by the Fair Trading Amendment Act 2021 to expand unfair contract terms protections to small business contracts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-consumer-law-acl-2010-cx"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "new-zealand-food-act-2014-fsp",
    "title": "Food Act 2014 (New Zealand)",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Food Act 2014 requires all food businesses in New Zealand to implement a registered Food Control Plan (FCP) or a National Programme Food Safety Programme (NP-FSP) to manage food safety risks, with mandatory verification by MPI. It applies to all food handlers, processors, and importers under Section 55 and Part 4 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "new-zealand-health-information-privacy-2026",
    "title": "New Zealand Health Information Privacy Code 2020 & Health Act Amendments (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The Health Information Privacy Code 2020 (HIPC) sets 13 rules governing the collection, use, storage, disclosure, and access to health information. It applies to all health agencies and requires reasonable security safeguards, purpose limitation, individual access and correction rights, and breach notification. 2026 amendments strengthen electronic health record security and cross-agency sharing rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-myhealthrecord-act-2012-2026"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "new-zealand-immigration-act-2009-inz",
    "title": "New Zealand Immigration Act 2009 - INZ and Five Eyes Border Framework",
    "domain": "Immigration & Border Control",
    "version": "2.2",
    "last_updated": "2026-05-10",
    "bluf": "The New Zealand Immigration Act 2009 (IA09) is New Zealand's primary immigration statute, consolidating all visa, entry, deportation, and refugee provisions. Immigration New Zealand (INZ), a business unit of MBIE, administers all visa applications. The Trans-Tasman Travel Arrangement (TTTA) grants Australian citizens and permanent residents the right to work and reside in New Zealand without a visa, and vice versa. Section 71 of the IA09 deals with mass arrivals, enabling government to declare arrivals unlawful and detain pending processing. New Zealand participates fully in the Five Eyes High Value Data Sharing Protocol. The Accredited Employer Work Visa (AEWV) introduced in 2022 is the primary work visa pathway, requiring employers to hold INZ accreditation. New Zealand's refugee quota is 1,500 per year. Section 342 makes unlawful facilitation of immigration an offence with up to 7 years imprisonment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "five_eyes",
        "unhcr",
        "icao_doc",
        "trans_tasman",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "new-zealand-outer-space-act-2017",
    "title": "New Zealand Outer Space and High-altitude Activities Act 2017",
    "domain": "Space & Satellite Law",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "New Zealand's Outer Space and High-altitude Activities Act 2017 regulates commercial launches and spacecraft operations from New Zealand, providing the legal framework under which Rocket Lab became the first private company to launch commercially from New Zealand. The Act requires operator licences for launches and payload approvals, caps operator liability at NZD 100 million per incident with a government Crown indemnity for excess damage, and implements New Zealand's obligations under the five UN space treaties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "liability_convention",
        "rocket_lab_operations"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "new-zealand-privacy-act-2020",
    "title": "Privacy Act 2020",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The New Zealand Privacy Act 2020 governs the collection, use, and disclosure of personal information by agencies, establishing 13 Information Privacy Principles (IPPs) under Section 22. It mandates notification to the Privacy Commissioner within 72 hours of becoming aware of a privacy breach that has caused or is likely to cause serious harm (Part 6, Subpart 1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-privacy-guidelines-2013",
      "au-privacy-act-1988",
      "apec-cbpr-system-2011"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "new-zealand-resource-management-act-1991-mfe",
    "title": "New Zealand Resource Management Act 1991 - Resource Consent and Sustainable Management Framework",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The Resource Management Act 1991 (RMA) is New Zealand's principal statute for managing the natural and physical environment. Its purpose is to promote the sustainable management of natural and physical resources (Section 5). The RMA established an effects-based planning system, requiring resource consent for activities that are not permitted under a plan. Regional Councils and Territorial Authorities prepare regional policy statements, regional plans and district plans. The Court of Appeal and Environment Court (previously Planning Tribunal) provide judicial oversight. Major reforms via RMA Amendment Act 2020 and Fast-track Approvals Act 2024 have streamlined certain approvals. Treaty of Waitangi partnership principles are central to RMA decision-making under Section 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "new-zealand-biosecurity-act-1993-mpi"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nf-privacy-framework",
    "title": "Norfolk Island - Australian Privacy Act and OAIC Supervisory Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Norfolk Island is an Australian external territory located in the South Pacific Ocean between New Zealand and New Caledonia. Norfolk Island has a resident population of approximately 2,000 people, including descendants of the Bounty mutineers who relocated from Pitcairn Island in 1856 and form a distinct cultural community. Norfolk Island previously had self-governing status under the Norfolk Island Act 1979 with its own elected Legislative Assembly. In 2015, the Australian Government enacted the Norfolk Island Legislation Amendment Act 2015, abolishing the Norfolk Island Legislative Assembly and ending self-government. Norfolk Island was integrated into the Australian federal governance framework and, for electoral purposes, became part of the state of New South Wales. The Australian Privacy Act 1988 (Cth) now applies in full force in Norfolk Island as an Australian external territory, and the Australian Privacy Principles (APPs) govern the handling of personal data by Australian Government agencies and private sector organisations with annual turnover exceeding AU$3 million operating in the territory. The Office of the Australian Information Commissioner (OAIC) is the competent supervisory authority for privacy matters in Norfolk Island. Organisations processing personal data in Norfolk Island must comply with the Australian Privacy Act 1988 and the notifiable data breaches scheme. The transition from self-government to Australian territory status in 2015 means that any legacy Norfolk Island privacy legislation no longer applies - the current applicable framework is the Australian Privacy Act 1988.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/nf-privacy-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nfpa-101-life-safety-code-2021",
    "title": "NFPA 101 Life Safety Code, 2021 Edition - Means of Egress, Occupant Load and Emergency Lighting Requirements",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The NFPA 101 Life Safety Code establishes minimum building design, construction, operation, and maintenance requirements to protect occupants from fire, smoke, and toxic fumes. It mandates specific criteria for means of egress, occupant load calculation, and emergency systems, as detailed in Chapter 7, to ensure a reasonable degree of safety during emergencies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "163.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nfpa-13-installation-sprinkler-systems-2022",
    "title": "NFPA 13 Standard for the Installation of Sprinkler Systems 2022",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires the installation of sprinkler systems in accordance with Section 8.3 of NFPA 13, which applies to new and existing buildings, and Section 10.2, which outlines the requirements for hydraulic calculations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nfpa-70-national-electrical-code-2023",
    "title": "NFPA 70 National Electrical Code (NEC), 2023 Edition",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The NFPA 70 National Electrical Code (NEC) establishes the benchmark for safe electrical design, installation, and inspection to protect people and property from electrical hazards in public and private premises. Compliance requires adherence to specific requirements for wiring methods, overcurrent protection, and grounding as detailed in Articles such as 110, 240, 250, and 310.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "173.50",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ng-cbn-banks-other-financial-institutions-act-bofia-2020",
    "title": "Nigeria Banks and Other Financial Institutions Act (BOFIA) 2020",
    "domain": "Banking & Global Finance",
    "version": "2020.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Nigeria's Banks and Other Financial Institutions Act (BOFIA) 2020 (repealing BOFIA 1991) consolidates the Central Bank of Nigeria's licensing, supervisory, and resolution powers over banks and specialised financial institutions, introduces a systemic risk framework, strengthens early intervention mechanisms, and establishes mandatory resolution tools including bridge bank, asset transfer, and purchase-and-assumption for failing financial institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fsb_resolution",
        "fatf",
        "basel_iii",
        "world_bank_ifc"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-40-recommendations-2023-consolidated",
      "basel-iii-capital",
      "bis-pfmi-financial-market-infrastructure-2012"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ng-cybercrimes-act-2015",
    "title": "Nigeria Cybercrimes (Prohibition, Prevention, Etc.) Act 2015",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Nigeria's Cybercrimes (Prohibition, Prevention, Etc.) Act 2015, assented to May 15, 2015, establishes a comprehensive legal framework for cybercrime prohibition and prosecution in Nigeria, designates critical national information infrastructure operators who must report cybersecurity incidents to the Office of the National Security Adviser, establishes the Cybercrime Advisory Council, creates cybercrime offences including unlawful access, system interference, identity theft, and cyberstalking with penalties ranging from fines to 15 years imprisonment, and was amended by the Cybercrimes Amendment Act 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ng-cybercrimes-act-2015.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ng-dpa-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ng-dpa-2023",
    "title": "Nigeria Data Protection Act 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Nigeria's Data Protection Act 2023 replaces the NDPR 2019, establishes the Nigeria Data Protection Commission (NDPC) as the sole national supervisory authority, introduces GDPR-aligned data subject rights, and imposes penalties of up to 2% of annual gross revenue for administrative violations affecting Africa's largest economy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ng-dpa-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ng-ndpr-2019"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ng-nasrda-act-2010",
    "title": "National Space Research and Development Agency Act 2010 (Act No. 9 of 2010)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The National Space Research and Development Agency Act 2010 establishes the National Space Research and Development Agency (NASRDA) as a body corporate (Section 1) and establishes the National Space Council, chaired by the President of the Federal Republic of Nigeria (Section 2). The Act sets out the functions of the Agency, including developing satellite technology and building and launching satellites (Section 6), the powers of the Council (Section 7), and the establishment of the Fund of the Agency (Section 23). It applies to Nigeria's national space research, development, and satellite programmes administered by NASRDA under the Federal Ministry of Science and Technology.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-registration-convention-1976-space"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ng-ndpa-2023-nigeria-data-protection-act",
    "title": "Nigeria Data Protection Act 2023 - Data Processing Principles and Controller Obligations",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Nigeria's Data Protection Act 2023 (NDPA) establishes a comprehensive GDPR-inspired framework: 7 lawful bases for processing, data subject rights including access, rectification, deletion, portability and objection, mandatory registration with the Nigeria Data Protection Commission (NDPC) for large processors, 72-hour breach notification, cross-border transfer restrictions, and penalties up to 2% of annual gross revenue or NGN 10 million (whichever is higher) for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-popia-act-4-2013-personal-information-protection"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ng-ndpr-2019",
    "title": "Nigeria Data Protection Regulation 2019",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Nigeria Data Protection Regulation (NDPR) governs the processing of personal data of Nigerian citizens and residents, requiring Data Controllers to process data lawfully, securely, and transparently. As per Article 2.1, organizations must adhere to principles of data protection, including having a legal basis for processing and respecting the rights of Data Subjects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-800-122-pii",
      "brazil-lgpd-compliance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ng-nigerian-communications-act-2003",
    "title": "Nigerian Communications Act 2003 (Act No. 19 of 2003): NCC Establishment, Licensing, Interconnection, Universal Service and Type Approval",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Nigerian Communications Act 2003 (Act No. 19 of 2003) is the principal statute regulating the communications sector in Nigeria. Section 3 establishes the Nigerian Communications Commission (NCC) as the independent regulatory authority for the sector. Section 4 sets out the functions of the Commission, including facilitating investment, promoting fair competition, granting and regulating licences and protecting consumers. Section 31 imposes the core licensing requirement: no person shall operate a communications system or facility, or provide a communications service in Nigeria, unless authorised to do so under a communications licence or exempted under regulations made by the Commission, and contravention is an offence. Section 32 provides that the Commission shall issue communications licences as individual licences or class licences on the terms and conditions it determines. Sections 97 to 99 govern interconnection: section 97 requires all interconnection agreements between licensees to be in writing, section 98 requires registration of interconnection agreements with the Commission, and section 99 empowers the Commission to make interconnection regulations. Section 114 establishes the Universal Service Provision Fund (USP Fund) to promote the widespread availability and usage of network services and applications throughout Nigeria. Sections 132 and 133 govern type approval: section 132 empowers the Commission to conduct type approval tests and issue type approval certificates for communications equipment, and section 133 makes it an offence to sell or install communications equipment without first obtaining the Commission's type approval certificate. The Act is the legal foundation of telecommunications licensing, competition, interconnection and equipment regulation in Nigeria.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "ng-public-procurement-act-2007-bpp-noccpc",
    "title": "Nigeria Public Procurement Act 2007 (Act No. 14 of 2007) and the Bureau of Public Procurement (BPP)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Nigeria Public Procurement Act 2007 (Act No. 14 of 2007) assented to 4 June 2007 is the principal federal Nigerian statute governing procurement of goods, works, and services by all federal procuring entities of the Federal Government of Nigeria including federal ministries, federal extra-ministerial offices, federal agencies, government-owned companies, and partially-government-funded entities. The 2007 Act was enacted as part of the broader Nigerian public sector reform agenda following the recommendations of the Public Procurement Reform Strategy. The Act establishes the National Council on Public Procurement (NCPP) as the policy organ and the Bureau of Public Procurement (BPP) as the regulatory body. The Nigeria Open Contracting Portal (Nigeria Open Contracting Standard / NOCS, opencontracting.gov.ng) and the eGP Nigeria platform are the federal e-procurement platforms. Procurement methods established by the 2007 Act comprise (a) Open Competitive Bidding (sec. 24, the default open public procurement method), (b) Two-Stage Tendering (sec. 39, for complex acquisitions), (c) Request for Proposals (sec. 39, for consultancy services), (d) Request for Quotations (sec. 41, for low-value goods and services), (e) Direct Procurement (sec. 42, sole-source under prescribed exceptions including emergency, sole supplier for technical reasons, prior failed bidding, and proprietary items), (f) Restricted Tendering (sec. 39, with prequalification), and (g) Emergency Procurement (sec. 43, for emergencies). The 2007 Act introduced strengthened integrity provisions including the Code of Conduct for Public Officers in Procurement, supplier debarment under sec. 58, anti-corruption commitments under sec. 56, and the offence of fraud and corruption in procurement under sec. 58. Nigeria is NOT a party to the WTO Government Procurement Agreement (GPA) but is a party to the African Continental Free Trade Area (AfCFTA), UNCAC, and the African Union Convention on Preventing and Combating Corruption. State-level procurement is governed by parallel state public procurement laws including the Lagos State Public Procurement Law 2011.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "ng-ndpa-2023-nigeria-data-protection-act",
      "ng-cybercrimes-act-2015",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ng-sec-rules-digital-assets-issuance-custody-2022",
    "title": "SEC Nigeria Rules on Issuance, Offering Platforms and Custody of Digital Assets 2022",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Nigeria's Securities and Exchange Commission Rules on Issuance, Offering Platforms and Custody of Digital Assets (2022) set the registration regime for digital assets treated as securities. Part A Rule 4 requires an initial assessment filing with a draft white paper, and the Commission reviews a complete filing within 30 days to determine whether the digital asset is a security, with any revision renewing the 30-day period. Part A Rule 5 governs registration of digital asset securities and requires a copy of the escrow agreement with an independent Custodian or Trustee, Part B Rule 11 sets registration requirements for a Digital Asset Offering Platform (DAOP), and Parts C, D and E set requirements for Digital Asset Custodians, Virtual Asset Service Providers (VASPs) and Digital Asset Exchanges (DAX) respectively.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ng-cbn-banks-other-financial-institutions-act-bofia-2020",
      "fatf-recommendation-16-travel-rule-va"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ngs-ivds-germline-diseases",
    "title": "Considerations for Design, Development, and Analytical Validation of Next Generation Sequencing (NGS) - Based In Vitro Diagnostics (IVDs) Intended to Aid in the Diagnosis of Suspected Germline Diseases",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2018-04-13",
    "bluf": "This guidance document describes one part of FDA’s efforts to create a flexible and adaptive regulatory approach to the oversight of next generation sequencing (NGS)-based tests. As a step toward this vision, FDA is outlining key considerations for designing, developing, and establishing analytical validity of NGS-based tests used for whole exome human DNA sequencing (WES) or targeted human DNA sequencing intended to aid in the diagnosis of symptomatic individuals with suspected germline diseases or other conditions. The term “germline diseases or other conditions” encompasses those genetic diseases or other conditions arising from inherited or de novo germline variants.\n\nThe recommendations in this guidance are intended to both assist test developers directly, and also to inform the development of consensus standards by experts in the community. As a general principle, test developers should first define the indications for use statement of their test, as this determines how the test should perform. When defining appropriate test performance, developers should prospectively determine the types of studies that should be conducted (e.g., accuracy) as well as the thresholds that should be met for each study type. After design and development of the test, validation studies should indicate if the predefined performance is met. If the test does not meet any of the predefined performance thresholds, the test should be modified and revalidated.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-820-qsr",
      "iso-13485-medical-qms",
      "iso-14971-medical-risk",
      "iso-15189-medical-labs"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nhs-data-security-protection-toolkit",
    "title": "NHS Data Security and Protection Toolkit (DSPT)",
    "domain": "Medical & Healthcare",
    "version": "6.0.0",
    "last_updated": "2024-03-31",
    "bluf": "The NHS Data Security and Protection Toolkit (DSPT) is a mandatory annual self-assessment for all organizations with access to NHS patient data in England, measuring performance against the 10 National Data Guardian (NDG) data security standards to ensure information is handled securely.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-health-data",
      "iso-27799-health-info-sec",
      "hipaa-security-rule"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nhtsa-recall-process-cfr-573-577",
    "title": "Defect and Noncompliance Notification, Reporting, and Recall Procedures - 49 CFR Parts 573 and 577",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Manufacturers must report safety-related defects or noncompliance with Federal Motor Vehicle Safety Standards (FMVSS) to NHTSA within five working days under 49 CFR § 573.6 and initiate owner notification and remedy campaigns per 49 CFR § 577.7. Applies to all manufacturers of motor vehicles and equipment sold in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "sae-j3016-levels-driving-automation-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ni-pdp-law-2012",
    "title": "Nicaragua Personal Data Protection Law 787 (2012)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Nicaragua enacted Law 787, the Personal Data Protection Law (Ley de Protección de Datos Personales), in 2012, establishing one of the earliest comprehensive data protection frameworks in Central America. The law is administered by the designated regulatory authority and establishes principles for the lawful processing of personal data in public and private databases. Data subjects have rights of access, rectification, cancellation, and opposition (the ARCO rights). Controllers must register personal data databases with the regulatory authority, obtain consent from data subjects, implement security measures, and restrict cross-border transfers to jurisdictions with adequate protection. The law aligns with Ibero-American data protection standards as Nicaragua is a member of the Ibero-American Data Protection Network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ni-pdp-law-2012.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nigeria-electricity-act-2023-nerc",
    "title": "Nigeria Electricity Act 2023 - NERC Licensing and Market Reform",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Nigeria's Electricity Act 2023 (signed 9 June 2023) replaces the Electric Power Sector Reform Act 2005; devolves electricity regulation to states for off-grid and mini-grid activities; retains the Nigerian Electricity Regulatory Commission (NERC) for national grid licensees; mandates competitive procurement, MYTO tariff methodology, and 24-hour notice for grid disconnection; and introduces criminal penalties for meter tampering up to 5 years imprisonment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "south-africa-electricity-regulation-act-2006"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nigeria-fccpc-fair-competition-consumer-protection-2019",
    "title": "Federal Competition and Consumer Protection Act, 2018",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The Federal Competition and Consumer Protection Act, 2018 empowers the FCCPC to prohibit abuse of dominant market position, anti-competitive agreements, and unfair consumer practices in Nigeria. It applies to all firms, transaction parties, and service providers operating in Nigeria, with enforcement authority affirmed by court rulings on merger compliance and consumer redress under the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29",
      "ftc-digital-advertising-disclosures",
      "ama-ethical-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nigeria-immigration-act-cap-i1-2004-nis",
    "title": "Nigeria Immigration Act Cap. I1 2004 - NIS and CERPAC Residency Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The Nigeria Immigration Act, Cap.I1, Laws of the Federation of Nigeria 2004 (updated by Immigration Regulations 2017) governs entry, stay, and departure of all persons from the Federal Republic of Nigeria. The Nigeria Immigration Service (NIS), under the Ministry of Interior, administers border control at all international airports, land borders (84 approved crossing points), and seaports. All non-ECOWAS foreign nationals staying beyond 56 days must obtain CERPAC (Comprehensive Expatriate Residence Permit and Automated Cards) - a biometric smartcard issued by NIS. ECOWAS Protocol on Free Movement allows nationals of 15 ECOWAS member states to enter without visas and reside for up to 90 days. Subject to Expatriate Quota approval from the Federal Ministry of Interior, companies may employ specific numbers of foreign nationals. Criminal penalties under the Immigration Act include imprisonment up to 14 years for human smuggling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ecowas",
        "au",
        "icao_doc",
        "fatf",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nigeria-land-use-act-1978-certificate-of-occupancy",
    "title": "Nigeria Land Use Act 1978 - Certificate of Occupancy, Governor's Consent and Urban Land Administration",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Nigeria's Land Use Act 1978 (LUA, Cap. L5, Laws of the Federation of Nigeria 2004), vested all land in each state in the Governor who holds it in trust for the benefit of all Nigerians; requires holders of statutory rights of occupancy (SRO) to obtain a Certificate of Occupancy (C of O) from the State Governor; mandates Governor's Consent for any alienation, sublease, mortgage, or assignment of a right of occupancy; applies the Real Estate Regulatory Council of Nigeria Act 2022 (RECON) for estate agents and developers; and imposes revocation of SRO without compensation for breach of development conditions or public overriding interest.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "kenya-land-act-2012-national-land-commission"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nigeria-nafdac-food-drug-administration-act-2019",
    "title": "National Agency for Food and Drug Administration and Control (NAFDAC) Act (Cap. N1 LFN 2004) and the Food, Drugs and Related Products (Registration, Etc.) Act (Cap. F33 LFN 2004)",
    "domain": "Food & Hospitality",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "The National Agency for Food and Drug Administration and Control (NAFDAC) regulates the manufacture, importation, exportation, advertisement, distribution, sale and use of food, drugs, cosmetics, medical devices, chemicals and packaged water in Nigeria. NAFDAC is established and empowered by the NAFDAC Act (Cap. N1, Laws of the Federation of Nigeria 2004, originally Decree No. 15 of 1993), and its power to make registration, labelling and good-manufacturing-practice regulations derives from Section 30 of that Act. Mandatory pre-market registration of regulated products is required under the separate Food, Drugs and Related Products (Registration, Etc.) Act (Cap. F33, LFN 2004, originally Decree No. 19 of 1993), Section 1, which prohibits the manufacture, import, export, advertisement, sale or distribution of any regulated product unless it has first been registered. There is no instrument titled the NAFDAC (Amendment) Act 2019; NAFDAC enforces Good Manufacturing Practice, import and export permitting, post-market surveillance, product recall and penalties for adulterated, counterfeit or unregistered products through regulations made under these Acts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004",
      "iso-13009-beach-mgmt",
      "alcohol-service-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nigeria-naicom-guidelines-microinsurance-2021",
    "title": "NAICOM Guidelines for Microinsurance Operations in Nigeria (2018) - Tiered Licensing (Unit, State, National), Simplified Products, Agent Networks, Takaful Integration and Minimum Capital Requirements",
    "domain": "Insurance & Risk",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "The genuine instrument is the NAICOM Guidelines for Microinsurance Operations in Nigeria, 2018 (there is no '2021 Edition'). The Guidelines require microinsurers to obtain one of three licence tiers (Unit, State or National), offer simplified, easy-to-understand microinsurance products, use approved policy wordings, deploy and train agents, and may accommodate Takaful (Islamic) microinsurance. Minimum paid-up capital under the 2018 Guidelines is N40 million for a Unit microinsurer (N15 million Life plus N25 million General), N100 million for a State microinsurer and N600 million for a National microinsurer. The Guidelines do NOT impose a premium cap of 5 percent of monthly income; microinsurance is instead defined by low premium and low sum-assured product thresholds. Section references in earlier versions of this node were not verifiable against the Guidelines and have been replaced with plain-language descriptions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "brazil-susep-solvency-regulation-circular-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nigeria-ndh-digital-health-2026",
    "title": "Nigeria National Digital Health Strategy & NDH Data Governance Framework (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The National Digital Health Strategy (2021-2025, extended 2026) and NDH framework establish governance for electronic health records, telemedicine, unique health identifiers, and data exchange. Health data is classified as sensitive under the Nigeria Data Protection Act 2023, requiring explicit consent, security controls, breach notification within 72 hours, and alignment with the NDH Interoperability Framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "kenya-digital-health-act-2026"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "nigeria-ndpa-health-2026",
    "title": "Nigeria Data Protection Act 2023 - Health Data Protection (Lawful Basis, Consent, Sensitive Data, DPIA, Cross-Border Transfer) and the NDP General Application and Implementation Directive (GAID) 2025",
    "domain": "Medical & Healthcare",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "The Nigeria Data Protection Act (NDPA) 2023, together with its subordinate Nigeria Data Protection Act General Application and Implementation Directive (GAID) 2025 issued by the Nigeria Data Protection Commission (NDPC), imposes obligations on processing health data, including a lawful basis of processing (Section 25), consent (Section 26), heightened protection for sensitive personal data including health data (Section 30), data protection impact assessments (Section 28), the rights of data subjects (Part VI, from Section 34), and restrictions on cross-border transfers (Sections 41 to 43). There is no verifiable 'NDPC Enforcement Guidelines 2026' with an 'Article 3' or 'Article 5'; those references have been corrected to the actual NDPA sections. Applies to telemedicine, electronic health record systems, and health research.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nigeria-solid-minerals-mining-act-2007-mining-cadastre",
    "title": "Nigeria Solid Minerals Development Act 2007 - Mining Cadastre Licensing and Federal Minerals Royalty Compliance",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Nigeria's Federal Minerals and Mining Act Cap F26 LFN 2004 as replaced by the Solid Minerals Development Act 2007 (SMDA 2007) vests all mineral resources in the Federal Government and establishes the Mining Cadastre Office (MCO) within the Federal Ministry of Mines and Steel Development (MMSD) as the central licensing authority for all solid mineral titles; the Act creates four primary mineral title categories - Reconnaissance Permit (RP, 1 year, non-exclusive), Exploration Licence (EL, 3 years renewable to 5), Mining Lease (ML, 25 years renewable), and Quarry Lease (QL, 5 years renewable); all titles are registered in the automated cadaster system and must be maintained with annual rental fees and minimum work programme commitments; environmental impact assessment (EIA) under the Environmental Impact Assessment Act Cap E12 is mandatory before any Mining Lease is granted; royalty rates are set by the MMSD: tin 3%, lead/zinc 3%, coal 2.5%, granite/limestone 2%, gold/iron ore 3%; community development agreements (CDAs) with host communities are mandatory under Section 116; EITI compliance is a condition of all ML holders as Nigeria is a LEITI Compliant country; the Mining Act 2007 is supplemented by the Mining Regulations 2011 which set out the detailed procedural requirements for licence applications, renewals, and transfers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eiti-standard-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nis2-directive-article-10-csirt-designation-and-requirements",
    "title": "Directive (EU) 2022/2555 (NIS2 Directive) Article 10: Computer security incident response teams (CSIRTs)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Member States must designate or establish one or more Computer Security Incident Response Teams (CSIRTs) responsible for incident handling, covering specific sectors and complying with defined requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-11-tasks-csirts",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union - Article 11: Requirements, technical capabilities and tasks of CSIRTs",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article mandates that Computer Security Incident Response Teams (CSIRTs) must comply with a set of specified requirements concerning their tasks and technical capabilities to ensure effective incident response and management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-12-coordinated-vulnerability-disclosure",
    "title": "Directive (EU) 2022/2555 (NIS2 Directive) Article 12: Coordinated vulnerability disclosure and a European vulnerability database",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires each Member State to designate a national CSIRT as a coordinator to act as a trusted intermediary, facilitating interaction between vulnerability reporters and manufacturers upon request from either party.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-13-european-cyber-crises-liaison-network",
    "title": "Directive (EU) 2022/2555, Article 13: Cooperation at national level",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Member States must ensure that where their competent authorities, single point of contact, and CSIRTs are separate entities, they cooperate with each other to fulfill the obligations of this Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-14-cybersecurity-crisis-management",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union - Article 14 Cooperation Group",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article establishes a Cooperation Group to support and facilitate strategic cooperation and the exchange of information among Member States to strengthen trust and confidence in cybersecurity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-15-cooperation-group-objectives-tasks",
    "title": "Directive (EU) 2022/2555 (NIS2 Directive) Article 15: CSIRTs network",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article establishes a network of national CSIRTs to contribute to confidence and trust and to promote swift and effective operational cooperation among Member States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-16-registration-obligations-essential-important-entities",
    "title": "Directive (EU) 2022/2555 (NIS 2 Directive) - Article 16: Union level coordinated vulnerability disclosure and a European vulnerability database",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires Member States to designate a national CSIRT to coordinate vulnerability disclosure and mandates ENISA to establish and maintain a European vulnerability database.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nis2-directive-article-17-liability-management-bodies",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive) - Article 17 General provisions concerning the tasks of the competent authorities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires Member States to ensure their national competent authorities have the necessary powers, means, and resources to effectively carry out their tasks under the NIS 2 Directive and to cooperate with other relevant authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-18-cybersecurity-risk-management-measures",
    "title": "DIRECTIVE (EU) 2022/2555 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 December 2022 on measures for a high common level of cybersecurity across the Union - Article 18",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires entities to implement adapted and coordinated responses to address the expanding cyber threat landscape and the increasing magnitude, sophistication, and impact of incidents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-19-vulnerability-disclosure",
    "title": "DIRECTIVE (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive) - Article 19 Coordinated Vulnerability Disclosure",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires Member States to designate national CSIRTs to facilitate coordinated vulnerability disclosure and requires entities to establish and implement a vulnerability disclosure policy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nis2-directive-article-2-scope-essential-important-entities",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive) - Article 2: Scope",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations must determine if they are a public or private entity listed in Annex I or II, meet or exceed the size of a medium-sized enterprise, and operate within the Union to ascertain if this Directive applies to them.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-20-governance-management-body-accountability",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive) - Article 20",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Management bodies of essential and important entities must approve and oversee cybersecurity risk-management measures, follow training, and can be held liable for infringements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-21-cybersecurity-risk-management-measures-detail",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive) - Article 21: Cybersecurity risk-management measures",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Essential and important entities must implement a baseline of at least ten specific technical, operational, and organizational measures to manage cybersecurity risks to their network and information systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nis2-directive-article-23-incident-reporting-obligations",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union - Article 23: Reporting obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Essential and important entities must notify their competent authority or CSIRT of any significant incident through a multi-stage process, including an early warning within 24 hours and a full notification within 72 hours.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nis2-directive-article-24-use-of-cybersecurity-certification-schemes",
    "title": "Directive (EU) 2022/2555 Article 24: Use of European cybersecurity certification schemes and national cybersecurity certification schemes",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations may be required by Member States or future EU delegated acts to use specific ICT products, services, and processes certified under European cybersecurity certification schemes to demonstrate compliance with cybersecurity risk management measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-25-use-european-harmonised-standards-specifications",
    "title": "Directive (EU) 2022/2555 (NIS 2 Directive) Article 25: Use of European and international standards and technical specifications",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations should align their cybersecurity risk-management measures with European and international standards, as Member States are required to encourage their use for a convergent implementation of NIS2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-26-jurisdiction-and-registration",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union - Article 26: Jurisdiction and registration",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article specifies that entities are subject to the jurisdiction of the Member State where they have their main establishment and outlines requirements for submitting registration information to the competent authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nis2-directive-article-27-register-of-essential-and-important-entities",
    "title": "Directive (EU) 2022/2555 Article 27: Registry of entities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "ENISA is required to establish and maintain a registry of specific digital infrastructure and service entities, which must submit their identification and contact information by a set deadline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nis2-directive-article-28-eu-coordinated-supply-chain-risk-assessment",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union - Article 28: EU-level coordinated risk assessments of critical supply chains",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article empowers the EU Cooperation Group, Commission, and ENISA to conduct coordinated security risk assessments of critical ICT supply chains and issue non-binding recommendations for mitigating measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-29-information-sharing-arrangements",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive) - Article 29: Voluntary cybersecurity information-sharing arrangements",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires Member States to encourage and facilitate the establishment of voluntary cybersecurity information-sharing arrangements among entities to share threat intelligence and other relevant information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-3-definitions-network-information-systems",
    "title": "Directive (EU) 2022/2555 (NIS2 Directive) - Article 3: Scope of Application",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article establishes that entities listed in Annex I or II are subject to this Directive regardless of their size, and clarifies that a specific provision from a related Recommendation is not applicable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-30-administrative-fines-essential-entities",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive) - Article 30: General conditions for imposing administrative fines",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article establishes the conditions, criteria, and maximum amounts for administrative fines that can be imposed on essential entities for infringements of cybersecurity risk-management and reporting obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nis2-directive-article-31-administrative-fines-important-entities",
    "title": "Directive (EU) 2022/2555 Article 31: General conditions for imposing administrative fines on essential and important entities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Important entities must comply with cybersecurity risk-management measures (Article 21) and reporting obligations (Article 23) to avoid administrative fines of up to at least EUR 7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "nis2-directive-article-32-supervisory-measures-essential-entities",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive) - Article 32: Supervisory and enforcement measures in relation to essential entities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article grants competent authorities specific supervisory and enforcement powers over essential entities, including the ability to conduct inspections, issue binding instructions, and impose administrative fines for non-compliance with the Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nis2-directive-article-33-supervisory-measures-important-entities",
    "title": "Directive (EU) 2022/2555 Article 33: Supervisory and enforcement measures in relation to important entities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article grants competent authorities a range of supervisory and enforcement powers over important entities to ensure compliance with cybersecurity risk-management and reporting obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "nis2-directive-article-34-administrative-fines",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union, Article 34: Administrative fines",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that Member States establish rules for effective, proportionate, and dissuasive administrative fines for entities that infringe upon the cybersecurity risk-management and reporting obligations of this Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-35-exercise-of-supervision-essential-entities",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive) - Article 35: Infringements entailing an administrative fine",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article establishes the conditions and maximum amounts for administrative fines that competent authorities can impose on essential and important entities for infringements of cybersecurity risk-management and reporting obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "nis2-directive-article-36-tasks-csirts-cooperation",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union - Article 36: Tasks of the CSIRTs and Cooperation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article mandates that national Computer Security Incident Response Teams (CSIRTs) perform specific tasks including monitoring threats, issuing warnings, responding to incidents, and cooperating with other entities and stakeholders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "nis2-directive-article-37-eu-cyber-crises-liaison-network",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union - Article 37: EU-CyCLONe - establishment, composition and tasks",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the European Cyber Crises Liaison Organisation Network (EU-CyCLONe) to support the coordinated management of large-scale cybersecurity incidents and crises at an operational level among Member States and EU institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "nis2-directive-article-38-csirt-network",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive) - Article 38: CSIRTs network",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article outlines the composition, tasks, and operational procedures for the network of national CSIRTs, mandating their cooperation and information exchange to support the implementation of the NIS 2 Directive.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "nis2-directive-article-4-minimum-harmonisation-existing-legislation",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union - Article 4: Sector-specific Union legal acts",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article establishes that if an entity is already subject to sector-specific Union legislation with cybersecurity requirements equivalent to this Directive, the provisions of this Directive will not apply to that entity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-40-peer-review-mechanism",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union - Article 19 (Peer reviews)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Article 19 of NIS2 (Directive (EU) 2022/2555) establishes a peer-review system for Member States to assess the effectiveness of their national cybersecurity strategies and the implementation of this Directive, fostering consistent and high levels of cyber resilience across the Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-5-minimum-harmonisation-higher-national-measures",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive) - Article 5: Minimum harmonisation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations must identify and comply with any national cybersecurity provisions adopted or maintained by Member States that ensure a higher level of cybersecurity than this Directive, provided they are consistent with Union law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-6-definitions-network-information-systems",
    "title": "Directive (EU) 2022/2555 (NIS 2 Directive) Article 6: Definitions - Network and Information System",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article defines 'network and information system' as the foundational scope for applying the Directive's cybersecurity obligations, encompassing electronic communications networks, data processing devices, and the digital data they handle for operational purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-7-national-cybersecurity-strategy-requirements",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive) - Article 7: National cybersecurity strategy",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Member States must adopt a national cybersecurity strategy that defines strategic objectives, required resources, and policy measures to achieve and maintain a high level of cybersecurity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "nis2-directive-article-8-competent-authorities-national-single-points-contact",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union - Article 8: Competent authorities and single points of contact",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Member States must designate or establish one or more competent authorities responsible for cybersecurity and related supervisory tasks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-article-9-csirt-technical-requirements-tasks",
    "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union - Article 9: National cyber crisis management frameworks",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Member States must designate or establish one or more competent authorities for managing large-scale cybersecurity incidents and crises, ensuring they have adequate resources and cohere with national crisis management frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-compliance-2026-1",
    "title": "NIS2 Directive Enterprise Compliance Standard v1",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The NIS2 Directive establishes a comprehensive framework for enhancing cybersecurity across the EU. It mandates that essential and important entities adopt risk management practices, report incidents, and ensure supply chain security. Organizations must implement security measures, conduct risk assessments, and maintain incident response capabilities. The directive emphasizes the importance of cooperation among member states and requires the establishment of national cybersecurity strategies. It also introduces stricter supervisory measures and penalties for non-compliance, aiming to bolster the overall resilience of critical infrastructure against cyber threats.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-directive-compliance-2026-16",
    "title": "NIS2 Directive Enterprise Compliance Standard v16",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The NIS2 Directive establishes a comprehensive framework for enhancing cybersecurity across the EU. It mandates that essential and important entities adopt risk management practices, report incidents, and ensure supply chain security. Organizations must implement security measures, conduct risk assessments, and maintain incident response capabilities. The directive emphasizes the importance of cooperation among member states and requires regular reporting to national authorities. It also introduces stricter enforcement mechanisms and penalties for non-compliance, aiming to bolster the overall resilience of critical infrastructure against cyber threats. The directive applies to a wide range of sectors, including energy, transport, health, and digital infrastructure, ensuring a unified approach to cybersecurity across the EU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nis2-incident-reporting-article-23",
    "title": "NIS2 Directive: Article 23 - Reporting Obligations for Significant Incidents",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Under Article 23 of the NIS2 Directive, essential and important entities must notify their competent authority or CSIRT of any significant incident without undue delay, following a multi-stage process: an early warning within 24 hours, an incident notification within 72 hours, and a final report no later than one month after the incident notification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "guide-computer-security-log-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nis2-security-measures-article-21",
    "title": "Cybersecurity Risk-Management Measures (Article 21, NIS2 Directive 2022/2555)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Under Article 21 of the NIS2 Directive, essential and important entities must implement appropriate and proportionate technical, operational, and organisational measures to manage cybersecurity risks to their network and information systems, based on an all-hazards approach to protect against incidents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0",
      "c-scrm-practices-systems-organizations",
      "nist-800-53-cp2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nis2-supply-chain-security-article-22",
    "title": "NIS2 Directive: Cybersecurity in Supply Chains and Supplier Relationships (Article 22)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Under Article 22 of the NIS2 Directive, Member States must ensure that essential and important entities manage cybersecurity risks within their supply chains by assessing and considering the cybersecurity practices of their direct suppliers and service providers, including incorporating security measures into contractual agreements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "c-scrm-practices-systems-organizations",
      "nist-ir-7622-scrm-practices",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-800-122-pii",
    "title": "Protecting PII (NIST 800-122)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "NIST Special Publication 800-122 (Guide to Protecting the Confidentiality of Personally Identifiable Information) provides a comprehensive framework for federal agencies and their contractors to identify, categorize, and protect PII held in information systems - establishing that PII protection must be risk-based, proportional to the sensitivity of the information and the likelihood and impact of unauthorized disclosure. The publication defines PII as any information that can be used to distinguish or trace an individual's identity, either alone or when combined with other personal or identifying information, and categorizes PII confidentiality impact using the NIST FIPS 199 LOW/MODERATE/HIGH scale based on factors including identifiability, quantity, data field sensitivity, context of use, and obligations to protect. Organizations that fail to implement PII protection controls consistent with NIST 800-122 face federal enforcement action under the Privacy Act of 1974, the E-Government Act of 2002, OMB Memorandum M-17-12, and sector-specific privacy statutes. AI agents that process, store, or transmit PII must apply the full NIST 800-122 control framework, including de-identification, access control, and incident response requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27701-privacy-information-management",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-800-171-cui",
    "title": "CUI Protection (NIST 800-171)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "NIST Special Publication 800-171 Revision 3 (published May 2024) defines 17 control families containing 110 security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations - primarily defense contractors, research institutions, and suppliers processing federal contract information (FCI) and CUI under DFARS Clause 252.204-7012. Compliance with NIST 800-171 is mandatory for any organization holding a DoD contract that involves CUI, and the Cybersecurity Maturity Model Certification (CMMC) 2.0 Level 2 assessment directly audits all 110 NIST 800-171 requirements through a Certified Third-Party Assessment Organization (C3PAO). The Supplier Performance Risk System (SPRS) score, derived from self-assessment against NIST 800-171, affects contract award decisions, and DoD contracting officers are required to review SPRS scores as part of the source selection process. Failure to implement required controls exposes contractors to contract termination, False Claims Act liability (up to three times damages plus civil penalties), and debarment from federal contracting. AI agents operating within defense contractor environments that process, store, or transmit CUI must comply with all applicable NIST 800-171 requirements, particularly access control, audit logging, system and communications protection, and configuration management families.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cmmc-2-audit",
      "dfars-7012-defense-cyber",
      "fips-140-3-cryptographic-modules",
      "nist-sp-800-53-r5",
      "nist-sp-800-172-enhanced-security"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-800-171-r3-03-01-01-account-management",
    "title": "NIST SP 800-171 Rev. 3 Requirement 03.01.01 - Account Management",
    "domain": "Cybersecurity",
    "version": "3.0.0",
    "last_updated": "2024-05-14",
    "bluf": "NIST SP 800-171 Rev. 3 security requirement 03.01.01 (Account Management) in the Access Control family. NIST requirement text: \"Define the types of system accounts allowed and prohibited. Create, enable, modify, disable, and remove system accounts in accordance with policy, procedures, prerequisites, and criteria.\" NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (published May 2024), specifies requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when CUI resides in nonfederal systems and organizations. NIST maps requirement 03.01.01 to SP 800-53 Rev. 5 control(s) AC-2, AC-2(3), AC-2(5), AC-2(13). This node operationalizes the 12 NIST assessment objectives published for requirement 03.01.01 as discrete verification steps, each stated in the determination language NIST uses to assess conformance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3",
      "nist-800-171-cui",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "nist-800-171-r3-03-01-12-remote-access",
    "title": "NIST SP 800-171 Rev. 3 Requirement 03.01.12 - Remote Access",
    "domain": "Cybersecurity",
    "version": "3.0.0",
    "last_updated": "2024-05-14",
    "bluf": "NIST SP 800-171 Rev. 3 security requirement 03.01.12 (Remote Access) in the Access Control family. NIST requirement text: \"Establish usage restrictions, configuration requirements, and connection requirements for each type of allowable remote system access. Authorize each type of remote system access prior to establishing such connections.\" NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (published May 2024), specifies requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when CUI resides in nonfederal systems and organizations. NIST maps requirement 03.01.12 to SP 800-53 Rev. 5 control(s) AC-17, AC-17(3), AC-17(4). This node operationalizes the 9 NIST assessment objectives published for requirement 03.01.12 as discrete verification steps, each stated in the determination language NIST uses to assess conformance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3",
      "nist-800-171-cui",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "nist-800-171-r3-03-01-16-wireless-access",
    "title": "NIST SP 800-171 Rev. 3 Requirement 03.01.16 - Wireless Access",
    "domain": "Cybersecurity",
    "version": "3.0.0",
    "last_updated": "2024-05-14",
    "bluf": "NIST SP 800-171 Rev. 3 security requirement 03.01.16 (Wireless Access) in the Access Control family. NIST requirement text: \"Establish usage restrictions, configuration requirements, and connection requirements for each type of wireless access to the system. Authorize each type of wireless access to the system prior to establishing such connections.\" NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (published May 2024), specifies requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when CUI resides in nonfederal systems and organizations. NIST maps requirement 03.01.16 to SP 800-53 Rev. 5 control(s) AC-18, AC-18(1), AC-18(3). This node operationalizes the 8 NIST assessment objectives published for requirement 03.01.16 as discrete verification steps, each stated in the determination language NIST uses to assess conformance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3",
      "nist-800-171-cui",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "nist-800-171-r3-03-02-01-literacy-training-and-awareness",
    "title": "NIST SP 800-171 Rev. 3 Requirement 03.02.01 - Literacy Training and Awareness",
    "domain": "Cybersecurity",
    "version": "3.0.0",
    "last_updated": "2024-05-14",
    "bluf": "NIST SP 800-171 Rev. 3 security requirement 03.02.01 (Literacy Training and Awareness) in the Awareness and Training family. NIST requirement text: \"Provide security literacy training to system users: As part of initial training for new users and [Assignment: organization-defined frequency] thereafter, When required by system changes or following [Assignment: organization-defined events], and On recognizing and reporting indicators of insider threat, social engineering, and social mining. Update security literacy training content [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].\" NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (published May 2024), specifies requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when CUI resides in nonfederal systems and organizations. NIST maps requirement 03.02.01 to SP 800-53 Rev. 5 control(s) AT-2, AT-2(2), AT-2(3). This node operationalizes the 11 NIST assessment objectives published for requirement 03.02.01 as discrete verification steps, each stated in the determination language NIST uses to assess conformance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3",
      "nist-800-171-cui",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "nist-800-171-r3-03-04-06-least-functionality",
    "title": "NIST SP 800-171 Rev. 3 Requirement 03.04.06 - Least Functionality",
    "domain": "Cybersecurity",
    "version": "3.0.0",
    "last_updated": "2024-05-14",
    "bluf": "NIST SP 800-171 Rev. 3 security requirement 03.04.06 (Least Functionality) in the Configuration Management family. NIST requirement text: \"Configure the system to provide only mission-essential capabilities. Prohibit or restrict use of the following functions, ports, protocols, connections, and services: [Assignment: organization-defined functions, ports, protocols, connections, and services] .\" NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (published May 2024), specifies requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when CUI resides in nonfederal systems and organizations. NIST maps requirement 03.04.06 to SP 800-53 Rev. 5 control(s) CM-7, CM-7(1). This node operationalizes the 8 NIST assessment objectives published for requirement 03.04.06 as discrete verification steps, each stated in the determination language NIST uses to assess conformance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3",
      "nist-800-171-cui",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "nist-800-171-r3-03-05-07-password-management",
    "title": "NIST SP 800-171 Rev. 3 Requirement 03.05.07 - Password Management",
    "domain": "Cybersecurity",
    "version": "3.0.0",
    "last_updated": "2024-05-14",
    "bluf": "NIST SP 800-171 Rev. 3 security requirement 03.05.07 (Password Management) in the Identification and Authentication family. NIST requirement text: \"Maintain a list of commonly-used, expected, or compromised passwords, and update the list [Assignment: organization-defined frequency] and when organizational passwords are suspected to have been compromised. Verify that passwords are not found on the list of commonly used, expected, or compromised passwords when users create or update passwords.\" NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (published May 2024), specifies requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when CUI resides in nonfederal systems and organizations. NIST maps requirement 03.05.07 to SP 800-53 Rev. 5 control(s) IA-5(1). This node operationalizes the 8 NIST assessment objectives published for requirement 03.05.07 as discrete verification steps, each stated in the determination language NIST uses to assess conformance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3",
      "nist-800-171-cui",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "nist-800-171-r3-03-05-12-authenticator-management",
    "title": "NIST SP 800-171 Rev. 3 Requirement 03.05.12 - Authenticator Management",
    "domain": "Cybersecurity",
    "version": "3.0.0",
    "last_updated": "2024-05-14",
    "bluf": "NIST SP 800-171 Rev. 3 security requirement 03.05.12 (Authenticator Management) in the Identification and Authentication family. NIST requirement text: \"Verify the identity of the individual, group, role, service, or device receiving the authenticator as part of the initial authenticator distribution. Establish initial authenticator content for any authenticators issued by the organization.\" NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (published May 2024), specifies requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when CUI resides in nonfederal systems and organizations. NIST maps requirement 03.05.12 to SP 800-53 Rev. 5 control(s) IA-5. This node operationalizes the 12 NIST assessment objectives published for requirement 03.05.12 as discrete verification steps, each stated in the determination language NIST uses to assess conformance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3",
      "nist-800-171-cui",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "nist-800-171-r3-03-06-05-incident-response-plan",
    "title": "NIST SP 800-171 Rev. 3 Requirement 03.06.05 - Incident Response Plan",
    "domain": "Cybersecurity",
    "version": "3.0.0",
    "last_updated": "2024-05-14",
    "bluf": "NIST SP 800-171 Rev. 3 security requirement 03.06.05 (Incident Response Plan) in the Incident Response family. NIST requirement text: \"Develop an incident response plan that: Provides the organization with a roadmap for implementing its incident response capability, Describes the structure and organization of the incident response capability, Provides a high-level approach for how the incident response capability fits into the overall organization, Defines reportable incidents, Addresses the sharing of incident information, and Designates responsibilities to organizational entities, personnel, or roles. Distribute copies of the incident response plan to designated incident response personnel (identified by name and/or by role) and organizational elements.\" NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (published May 2024), specifies requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when CUI resides in nonfederal systems and organizations. NIST maps requirement 03.06.05 to SP 800-53 Rev. 5 control(s) IR-8. This node operationalizes the 10 NIST assessment objectives published for requirement 03.06.05 as discrete verification steps, each stated in the determination language NIST uses to assess conformance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3",
      "nist-800-171-cui",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "nist-800-171-r3-03-15-02-system-security-plan",
    "title": "NIST SP 800-171 Rev. 3 Requirement 03.15.02 - System Security Plan",
    "domain": "Cybersecurity",
    "version": "3.0.0",
    "last_updated": "2024-05-14",
    "bluf": "NIST SP 800-171 Rev. 3 security requirement 03.15.02 (System Security Plan) in the Planning family. NIST requirement text: \"Develop a system security plan that: Defines the constituent system components; Identifies the information types processed, stored, and transmitted by the system; Describes specific threats to the system that are of concern to the organization; Describes the operational environment for the system and any dependencies on or connections to other systems or system components; Provides an overview of the security requirements for the system; Describes the safeguards in place or planned for meeting the security requirements; Identifies individuals that fulfill system roles and responsibilities; and Includes other relevant information necessary for the protection of CUI. Review and update the system security plan [Assignment: organization-defined frequency].\" NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (published May 2024), specifies requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when CUI resides in nonfederal systems and organizations. NIST maps requirement 03.15.02 to SP 800-53 Rev. 5 control(s) PL-2. This node operationalizes the 11 NIST assessment objectives published for requirement 03.15.02 as discrete verification steps, each stated in the determination language NIST uses to assess conformance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3",
      "nist-800-171-cui",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "nist-800-171-r3-03-17-01-supply-chain-risk-management-plan",
    "title": "NIST SP 800-171 Rev. 3 Requirement 03.17.01 - Supply Chain Risk Management Plan",
    "domain": "Cybersecurity",
    "version": "3.0.0",
    "last_updated": "2024-05-14",
    "bluf": "NIST SP 800-171 Rev. 3 security requirement 03.17.01 (Supply Chain Risk Management Plan) in the Supply Chain Risk Management family. NIST requirement text: \"Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations, maintenance, and disposal of the system, system components, or system services. Review and update the supply chain risk management plan [Assignment: organization-defined frequency].\" NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (published May 2024), specifies requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when CUI resides in nonfederal systems and organizations. NIST maps requirement 03.17.01 to SP 800-53 Rev. 5 control(s) SR-2. This node operationalizes the 12 NIST assessment objectives published for requirement 03.17.01 as discrete verification steps, each stated in the determination language NIST uses to assess conformance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3",
      "nist-800-171-cui",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "nist-800-171-rev-3",
    "title": "NIST SP 800-171 Rev 3 (CUI)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "NIST SP 800-171 Rev 3 provides the requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) in nonfederal systems and organizations. It is the foundational standard for defense contractors, and the latest 2024 revision incorporates significant updates to controls and security families to align with modern cyber threats.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dfars-7012-defense-cyber"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-800-190-container",
    "title": "NIST SP 800-190 (Containers)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with NIST SP 800-190 guidance for application container security necessitates a multi-layered control framework that addresses risks across the entire lifecycle. This node enforces critical security postures, beginning with the image build process where each image_uses_trusted_base is mandatory, ensuring builds originate from approved, signed sources. A comprehensive vulnerability assessment must pass, reflected by the image_vulnerability_scan_passed status, which strictly adheres to a max_critical_vulnerabilities_allowed threshold of zero. The node also mandates that secrets_managed_externally, injected via a secure orchestrator mechanism to avoid their insecure embedding within images. Supply chain integrity is maintained by verifying registry_requires_authentication for all operations. In the orchestration layer, access control is paramount; therefore, orchestrator_rbac_enabled is required to enforce least privilege. Default-deny network communication is enforced through active network_policies_enforced, isolating workloads. At runtime, the security posture is hardened by mandating that a container_runs_as_non_root and that a runtime_security_profile_applied, like Seccomp or AppArmor, restricts system call privileges. The container's integrity is further protected when an immutable_filesystem_enabled configuration prevents unauthorized modifications. Finally, the underlying host infrastructure must be demonstrably secure, requiring that the host_os_hardened against a standard like a CIS benchmark and that all host_access_audited to maintain a verifiable log of administrative actions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-145-cloud-computing",
      "nist-sp-800-218-ssdf",
      "nist-800-204-microservices"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-800-204-microservices",
    "title": "NIST SP 800-204 (Microservices)",
    "domain": "Cloud & SaaS",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "NIST SP 800-204 establishes stringent security strategies for microservice-based applications, mandating a defense-in-depth architecture. Compliance requires the deployment and configuration of an API gateway to mediate all ingress traffic, complemented by a service mesh for managing and securing inter-service communication. All service-to-service interactions must be encrypted and authenticated through the mandatory enforcement of mutual TLS. Authentication mechanisms will employ JSON Web Token validation, while access control strictly adheres to a least privilege access enforced model. The network posture must adopt a zero-trust stance, where a default network policy denies all connections, and all egress traffic is explicitly controlled. System observability is paramount, necessitating that log correlation is enabled across the distributed environment alongside active runtime security monitoring for continuous threat detection. From a vulnerability management perspective, a zero-tolerance policy is enforced for critical vulnerabilities in container images, demanding a scan threshold set to zero. Furthermore, secrets management must be externalized from application code, and API rate limiting needs to be enabled to protect against denial-of-service attacks and abuse.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-190-container",
      "nist-sp-800-204b-abac-microservices",
      "nist-sp-800-204c-devsecops-microservices"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-800-53-au2",
    "title": "Audit Event Logging (NIST 800-53)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "NIST SP 800-53 Rev 5 Control AU-2 (Event Logging) requires organizations to identify the types of events that the system is capable of logging in support of the audit function, coordinate the event logging function with other organizations requiring audit-related information, and specify the types of events to be logged - establishing the foundational event taxonomy upon which all subsequent audit controls (AU-3 through AU-16) depend. AU-2 is a HIGH baseline control required for all federal systems at the MODERATE and HIGH impact levels, and FedRAMP and CMMC 2.0 both mandate AU-2 implementation. The control is critical for AI agent deployments because AI agents generate high volumes of events across multiple systems and APIs; without a comprehensive AU-2 event taxonomy that explicitly includes AI agent actions (tool calls, API invocations, data access, decision outputs), audit trails will be insufficient for forensic investigation of AI-related incidents, regulatory compliance, and attack reconstruction. Failure to implement AU-2 in AI systems undermines the detectability of MITRE T1562 (Impair Defenses) attacks targeting audit infrastructure and creates undetectable gaps in the audit trail.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "nist-sp-800-53-r5",
      "nist-sp-800-92-log-management",
      "cyber-nist-csf-2",
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-800-53-cp2",
    "title": "Contingency Planning (NIST 800-53)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "NIST SP 800-53 Rev 5 Control CP-2 (Contingency Plan) requires organizations to develop a contingency plan for the information system that identifies essential missions and business functions, provides recovery objectives, priorities, and metrics, addresses contingency roles, responsibilities, and assigned individuals, addresses maintaining essential missions and business functions despite an information system disruption, compromise, or failure, and provides a plan to restore operations within defined Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs). CP-2 is a HIGH baseline control mandatory for federal systems at MODERATE and HIGH impact levels, and it is a foundational FedRAMP requirement. For AI agent systems, CP-2 is particularly critical because AI agents may be executing multi-step autonomous workflows at the time of a disruption - the contingency plan must address how in-flight agent tasks are safely halted, how agent state is captured for recovery, and how the restored system prevents duplicate actions from resumed agents. Failure to implement CP-2 for AI systems risks data integrity corruption, financial transaction duplication, and extended mission outage during recovery.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "nist-sp-800-30-risk-assessment",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-53-r5",
      "nist-sp-800-34-r1",
      "nist-ir-8286d-bia-for-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-800-53-ia2",
    "title": "Ident & Auth (NIST 800-53)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "NIST SP 800-53 Rev 5 Control IA-2 (Identification and Authentication - Organizational Users) requires information systems to uniquely identify and authenticate organizational users (including processes acting on behalf of users) and mandates multi-factor authentication (MFA) for all access to privileged accounts and all network access to non-privileged accounts on federal systems - a requirement that OMB Memorandum M-22-09 (Zero Trust Strategy) extended to require phishing-resistant MFA (FIDO2/WebAuthn, PIV/CAC) for all federal agency users by fiscal year 2024. IA-2 is a HIGH baseline control required for all federal systems, FedRAMP, and CMMC 2.0 Level 2, and it represents one of the highest-impact single controls in reducing credential-based attack success: CISA reports that MFA blocks more than 99% of automated credential-stuffing and phishing attacks. For AI agent systems, IA-2 extends to non-human identities (NHIs) - AI agent service accounts and API credentials must be uniquely identified, use certificate-based authentication where feasible, and have their authentication events logged for the AU-2 audit trail. AI agents that invoke downstream services must propagate their authenticated identity to those services rather than using shared service accounts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-63b-digital-identity",
      "fips-200-minimum-security-requirements",
      "cyber-nist-800-53-ac2",
      "nist-sp-800-207",
      "fips-201-3-piv-federal-employees"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-800-53-sc7",
    "title": "Boundary Protection (NIST 800-53)",
    "domain": "Cybersecurity",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "NIST SP 800-53 Rev 5 Control SC-7 (Boundary Protection) requires organizations to monitor and control communications at the external boundary of the system and at key internal boundaries, implement subnetworks for publicly accessible system components, and connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture. SC-7 is a HIGH baseline control mandatory for all federal systems at MODERATE and HIGH impact levels, FedRAMP High/Moderate, and CMMC 2.0 Level 2, and it is the foundational network security control upon which egress filtering, intrusion detection, and data loss prevention depend. For AI agent deployments, SC-7 is critical because AI agents executing tool calls and API invocations create dynamic outbound network flows that can exfiltrate data, communicate with attacker-controlled infrastructure, or access unauthorized external services - SC-7 egress controls must explicitly govern which external endpoints AI agents are permitted to connect to, and any agent connection attempt to an unapproved endpoint must be blocked and alerted.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-41-r1-firewalls",
      "nist-sp-800-53-r5",
      "nist-sp-800-207"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-800-61-incident-resp",
    "title": "NIST SP 800-61 (Incidents)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "NIST SP 800-61 Rev 2 (Computer Security Incident Handling Guide) is the definitive U.S. standard for managing the lifecycle of the cyber incidents. it provides an operational framework for the established 'Incident Response Team' (CSIRT) to the efficiently coordinate the 'Detection', 'Analysis', 'Containment', and the 'Recovery', with the specific emphasis on the 'Post-Incident' learning to the reduce the future risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fedramp-moderate-baseline",
      "hipaa-security-rule"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-800-88-sanitization",
    "title": "NIST SP 800-88 (Sanitization)",
    "domain": "Cloud & SaaS",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "NIST SP 800-88 Rev 1 (Guidelines for Media Sanitization) is the definitive U.S. standard for the secure destruction and the disposal of the information. it provides a systematic framework for the 'Sanitization' of the storage media (HDDs, SSDs, Mobile, Cloud) through the categorized methods of the 'Clear', 'Purge', and the 'Destroy', ensuring the sensitive data is the non-recoverable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-ai-100-2-adversarial-ml",
    "title": "NIST AI 100-2 E2023 - Adversarial Machine Learning: Taxonomy and Terminology for Attacks and Mitigations",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2023-08-01",
    "bluf": "This NIST Special Publication establishes a comprehensive taxonomy and common terminology for describing adversarial machine learning (AML) attacks and mitigations. It provides a structured vocabulary for AI developers, researchers, and evaluators to consistently identify, assess, and communicate about threats to AI system security and robustness, as detailed in Section 3, The AML Taxonomy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-ai-rmf-manage-function",
      "iso-23894-ai-risk-management",
      "us-cisa-ai-cybersecurity-guidelines-2023",
      "us-eo-14110-ai-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-ai-100-2-adversarial-ml-taxonomy-2023",
    "title": "NIST AI 100-2 Adversarial Machine Learning Taxonomy and Terminology - Compliance Obligations for Standardised Adversarial AI Risk Categorisation, Attack Type Classification, and Adversarial ML Vocabulary Under NIST Standards",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations under NIST AI 100-2 for categorising adversarial AI risks, classifying attack types such as poisoning and evasion, and standardising adversarial ML terminology. It aligns with EU AI Act (Regulation (EU) 2024/1689) high-risk AI system requirements under Articles 9 and 15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ai-100-2-adversarial-ml-taxonomy-2024",
    "title": "NIST AI 100-2 E2023 - Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (January 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "NIST AI 100-2 E2023 (final published January 4, 2024) establishes a standardised taxonomy and common terminology for adversarial machine learning (AML) attacks and mitigations. The document organises the AML landscape along three primary attacker dimensions and across two AI paradigms - Predictive AI (PredAI) and Generative AI (GenAI). The three attacker dimensions are: (1) Stage of learning (training time vs deployment time), (2) Attacker goals and objectives (availability, integrity, privacy compromise), and (3) Attacker capability and knowledge (white-box, black-box, grey-box; control over training data, model, query access). The taxonomy enumerates attack classes including evasion attacks, poisoning attacks (data poisoning, model poisoning, targeted vs untargeted), privacy attacks (membership inference, model inversion, model extraction/stealing, attribute inference), and abuse attacks specific to GenAI (prompt injection, jailbreaks, indirect prompt injection, abuse of LLMs for malicious purposes). For each class, the document describes attack mechanisms, real-world examples, and known mitigations along with their limitations. NIST AI 100-2 is the foundational reference for the Measure and Manage functions of the NIST AI Risk Management Framework when applied to security-relevant risks; it is co-cited with the NIST AI 600-1 GenAI Profile and serves as the technical baseline for federal agency AI security assessments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping",
        "iso_standard",
        "regulatory_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-ai-600-1-gen-ai-profile",
      "mitre-atlas-llm-prompt-injection",
      "eu-ai-act-article-15-robustness"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ai-100-2-aml-taxonomy",
    "title": "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-01-02",
    "bluf": "This NIST Trustworthy and Responsible AI report develops a taxonomy of concepts and defines terminology in the field of adversarial machine learning (AML). The taxonomy is built on surveying the AML literature and is arranged in a conceptual hierarchy that includes key types of ML methods and lifecycle stages of attack, attacker goals and objectives, and attacker capabilities and knowledge of the learning process. The report provides corresponding methods for mitigating and managing the consequences of attacks, meant to inform standards and practice guides for assessing and managing AI system security by establishing a common language for the AML landscape.\n\nThe data-driven approach of machine learning introduces security and privacy challenges beyond classical threats. These include the potential for adversarial manipulation of training data, adversarial exploitation of model vulnerabilities, and malicious interaction with models to exfiltrate sensitive information. AML is concerned with studying the capabilities of attackers and their goals, the design of attack methods that exploit ML vulnerabilities during the development, training, and deployment phases, and the design of ML algorithms that can withstand these challenges. The taxonomy of AML is defined with respect to five dimensions of risk assessment: AI system type, stage of the ML lifecycle process, attacker goals, attacker capabilities, and attacker knowledge.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-language-of-trustworthy-ai"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ai-100-4-redteam",
    "title": "AI Red Teaming (NIST AI 100-4)",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Adversarial red teaming constitutes a mandatory control for designated AI systems, aligning with directives in U.S. Executive Order 14110 and fulfilling the accuracy, robustness, and cybersecurity requirements detailed within the EU AI Act's Article 15. This node’s primary objective is to systematically identify, classify, and mitigate vulnerabilities through structured testing cycles conducted every 90 days, an operational tempo that supports the MEASURE function of NIST's AI Risk Management Framework. Each cycle must employ a minimum of 5000 adversarial prompts designed to stress-test system defenses against a comprehensive range of threats articulated in the NIST AI 100-4 taxonomy. The protocol mandates active simulation of evasion attacks, data poisoning scenarios, and model extraction attempts. Performance is evaluated against stringent thresholds, requiring a jailbreak success rate not to exceed 0.05 and a minimum robustness confidence score of 0.9. Testing specifically targets critical OWASP Top 10 for LLM vulnerabilities, including LLM01 Prompt Injection and LLM06 Sensitive Information Disclosure. To ensure procedural integrity consistent with ISO/IEC 23894 guidance, all evaluations require human-in-the-loop testing conducted by an operationally independent red team. Upon discovery of a critical vulnerability, an automatic quarantine protocol is triggered to prevent further exposure or compromise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "eu-ai-act-high-risk",
      "owasp-agentic-top10",
      "nist-sp-800-115-security-testing",
      "us-ca-sb53-frontier-ai"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-ai-100-4-synthetic-content",
    "title": "Reducing Risks Posed by Synthetic Content An Overview of Technical Approaches to Digital Content Transparency",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-11-18",
    "bluf": "This report examines existing standards, tools, methods, and practices for authenticating digital content, tracking its provenance, labeling and detecting synthetic content, and preventing generative AI from producing harmful material like child sexual abuse material or non-consensual intimate imagery of real individuals. The approaches discussed aim to manage and reduce risks related to synthetic content by recording and revealing its provenance, providing tools to identify AI-generated content, and mitigating the production and dissemination of certain illicit materials. Digital content transparency provides a vehicle for individuals and organizations to access more information about the origins and history of content, which may contribute to trustworthiness.\n\nThe document defines \"synthetic content\" as \"information, such as images, videos, audio clips, and text, that has been significantly altered or generated by algorithms, including by AI.\" It provides an overview of technical approaches for provenance data tracking and synthetic content detection, along with a review of current testing and evaluation techniques. It acknowledges that the efficacy of many of these approaches is not fully examined and may be years from widespread deployment. The value of any given technique is use-case and context-specific, and none offer comprehensive solutions on their own; they are building blocks that can be used to improve trust between content producers, distributors, and the public.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-ai-600-1-gen-ai-profile"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ai-100-5-global-engagement-plan",
    "title": "A Plan for Global Engagement on AI Standards",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-07-25",
    "bluf": "Recognizing the importance of technical standards in shaping development and use of Artificial Intelligence (AI), the President’s October 2023 Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (EO 14110) calls for “a coordinated effort...to drive the development and implementation of AI-related consensus standards, cooperation and coordination, and information sharing” internationally. Specifically, the EO tasks the Secretary of Commerce to “establish a plan for global engagement on promoting and developing AI standards... guided by principles set out in the NIST AI Risk Management Framework and United States Government National Standards Strategy for Critical and Emerging Technology” (NSSCET). This plan, prepared with broad public and private sector input, fulfills the EO’s mandate.\n\nThe scope of the plan is deliberately broad, addressing the full lifecycle of standards-related activities, including foundational technical work, collaborative development of consensus standards, and the development of complementary tools for implementation. The plan covers AI-related standards of all scopes, both “horizontal” (applicable across sectors) and “vertical” (designed for the needs of a particular sector). It lays out objectives, topical priorities, and actions that can be taken up not just by the Federal government but by the full array of U.S. stakeholders in AI standards, recognizing that U.S. global leadership hinges on engagement from across the dynamic, private sector-led standards ecosystem.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-ai-600-1-gen-ai-profile",
    "title": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-07-25",
    "bluf": "This document is a cross-sectoral profile of and a companion resource for the AI Risk Management Framework (AI RMF 1.0) for Generative AI, developed pursuant to Executive Order 14110 on Safe, Secure, and Trustworthy Artificial Intelligence. It is intended for voluntary use by organizations to improve their ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems. The profile assists organizations in managing AI risks in a manner that is well-aligned with their goals, considers legal and regulatory requirements, and reflects risk management priorities.\n\nThis profile defines risks that are novel to or exacerbated by the use of Generative AI (GAI) and provides a set of suggested actions to help organizations govern, map, measure, and manage these risks across the AI lifecycle. The focus of the suggested actions is limited to four primary considerations: Governance, Content Provenance, Pre-deployment Testing, and Incident Disclosure. It is designed to be used by various AI actors to manage risks associated with activities common across sectors, such as the use of large language models (LLMs). The profile focuses on risks for which there is an existing empirical evidence base, such as confabulation, information integrity, harmful bias, and data privacy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ai-600-1-generative-ai-profile-2024",
    "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0): Generative Artificial Intelligence Profile",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-04-18",
    "bluf": "This NIST profile extends the AI Risk Management Framework (AI RMF 1.0) to address the unique risks of generative AI, requiring organizations to identify, assess, and manage threats such as data poisoning, confabulation, and malicious use for CBRN or CSAM creation. It provides specific actions and documentation suggestions mapped to the AI RMF's Govern, Map, Measure, and Manage functions, as detailed in Appendix B.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-ai-100-2-adversarial-ml",
      "nist-ai-100-4-synthetic-content",
      "iso-23894-ai-risk-management",
      "us-eo-14110-ai-2023"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ai-adversarial-machine-learning",
    "title": "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-10",
    "bluf": "This NIST Trustworthy and Responsible AI report develops a taxonomy of concepts and defines terminology in the field of adversarial machine learning (AML), which may aid in securing applications of artificial intelligence (AI) against adversarial manipulations. The taxonomy is built on surveying the AML literature and is arranged in a conceptual hierarchy that includes key types of ML methods, lifecycle stages of attack, attacker goals, and attacker capabilities and knowledge. It applies to both Predictive and Generative AI systems. The data-driven approach of machine learning introduces security and privacy challenges, including the potential for adversarial manipulation of training data, exploitation of model vulnerabilities to affect performance, and malicious interactions to exfiltrate sensitive information.\n\nAML is concerned with studying the capabilities of attackers and their goals, as well as the design of attack methods that exploit vulnerabilities during the ML lifecycle. It is also concerned with the design of ML algorithms that can withstand these challenges. The intended audience includes individuals and groups responsible for designing, developing, deploying, evaluating, and governing AI systems. The taxonomy and terminology are meant to inform other standards and future practice guides for assessing and managing the security of AI systems by establishing a common language and understanding of the rapidly developing AML landscape.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-high-risk",
      "iso-42001-risk-assess",
      "nist-language-of-trustworthy-ai"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ai-rmf-1-0",
    "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2023-01-31",
    "bluf": "The goal of the AI RMF is to offer a resource to the organizations designing, developing, deploying, or using AI systems to help manage the many risks of AI and promote trustworthy and responsible development and use of AI systems. The Framework is intended to be voluntary, rights-preserving, non-sector-specific, and use-case agnostic, providing flexibility to organizations of all sizes and in all sectors and throughout society to implement its approaches. The framework equips organizations and individuals, referred to as AI actors, with approaches that increase the trustworthiness of AI systems, and helps foster the responsible design, development, deployment, and use of AI systems over time.\n\nThe core of the framework describes four specific functions to help organizations address the risks of AI systems in practice. These functions - GOVERN, MAP, MEASURE, and MANAGE - are broken down further into categories and subcategories. While GOVERN applies to all stages of an organization's AI risk management processes, the MAP, MEASURE, and MANAGE functions can be applied in AI system-specific contexts and at specific stages of the AI lifecycle. The framework is designed to be practical, to adapt to the AI landscape as technologies develop, and to be operationalized by organizations in varying degrees so society can benefit from AI while also being protected from its potential harms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "mitre_atlas"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-ai-rmf-1-0-govern-function",
    "title": "NIST AI RMF 1.0 Govern Function - Organisational Policies, Culture, Roles and Accountability Structures for AI Risk Management",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The NIST AI RMF GOVERN function establishes the foundational context for managing AI risks by requiring organizations to cultivate a risk-aware culture, define clear policies, and assign specific roles and responsibilities for AI risk management. This function, detailed in Section 4.1 of the AI RMF 1.0, ensures that AI risk management is integrated into the organization's broader governance and enterprise risk portfolio.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "iso-23894-ai-risk-management",
      "eu-ai-act-high-risk",
      "oecd-ai-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-ai-rmf-1-0-manage-function",
    "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0): MANAGE Function - Risk Response, Treatment, and Incident Planning",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The NIST AI RMF MANAGE function requires organizations to develop and implement plans for responding to and recovering from identified AI risks, including prioritizing risk responses, treating residual risks, and establishing incident response procedures. This function applies to all entities involved in the AI lifecycle and is detailed in Section 4.4 of the NIST AI 100-1 publication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-ai-rmf-map-function",
      "nist-ai-rmf-measure-function",
      "iso-23894-ai-risk-management",
      "eu-ai-act-incident-reporting-article-73"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-ai-rmf-1-0-map-function",
    "title": "NIST AI RMF 1.0 Map Function - AI System Context, Categorisation, Risk Identification and Stakeholder Impact Analysis",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The NIST AI RMF MAP function requires organizations to establish the context for managing AI system risks by identifying the system's purpose, categorizing its potential impacts, and analyzing how it may affect diverse stakeholders. This foundational step, detailed in Section 4.1 of the AI RMF, ensures that risk management activities are grounded in a comprehensive understanding of the AI system's operational and societal environment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-23894-ai-risk-management",
      "iso-42005-ai-impact-assessment",
      "eu-ai-act-fundamental-rights-impact-assessment",
      "nist-sp-1270-managing-ai-bias"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-ai-rmf-1-0-measure-function",
    "title": "NIST AI RMF 1.0 Measure Function - AI Risk Analysis, Bias Testing, Explainability Assessment and Performance Benchmarking",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The NIST AI RMF MEASURE function requires organizations to employ quantitative, qualitative, or mixed-method tools, techniques, and methodologies to analyze, assess, and monitor AI risks and their impacts. This involves continuous evaluation of AI system performance, including bias, explainability, and robustness, as detailed in Section 4.3 of the AI RMF 1.0 Core.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-ai-rmf-map-function",
      "nist-sp-1270-managing-ai-bias",
      "nistir-8312-explainable-ai-principles",
      "iso-23894-ai-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-ai-rmf-1-0-risk-management-framework",
    "title": "NIST AI Risk Management Framework 1.0 (2023) - Govern, Map, Measure, Manage",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "NIST AI RMF 1.0 (January 2023) provides a voluntary, risk-based framework for organisations to manage AI-specific risks across the AI system lifecycle: the GOVERN function establishes policies and culture; MAP identifies context and categorises risk; MEASURE analyses and prioritises risk; and MANAGE implements treatment plans and monitors residual risk. The framework is technologically neutral, sector-agnostic, and designed for use alongside the NIST Cybersecurity Framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024-1689-article-26-obligations-deployers-high-risk-ai"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ai-rmf-govern",
    "title": "NIST AI RMF: Governance & Accountability (Govern 1.1)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The NIST AI Risk Management Framework (RMF) 'Govern' function establishes the institutional foundation for safe AI. Sub-category Govern 1.1 specifically mandates that legal and regulatory AI requirements are identified, documented, and actively managed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-39-managing-information-security-risk",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-ai-rmf-manage",
    "title": "NIST AI RMF: Response",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "NIST AI RMF MANAGE is the action function of the AI Risk Management Framework (NIST AI 100-1, January 2023). It converts the risk assessments produced by MAP and MEASURE into concrete treatment decisions: accept, mitigate, transfer, or avoid. MANAGE specifies how AI risk responses are planned, resourced, executed, and monitored for effectiveness. Organizations without a formal MANAGE function may identify AI risks but fail to close them, creating regulatory and reputational liability. Under the EU AI Act Article 9 and ISO 42001 Clause 8, demonstrating systematic risk treatment with documented outcomes is mandatory for high-risk AI system operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-map",
      "nist-ai-rmf-measure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-ai-rmf-manage-function",
    "title": "NIST AI RMF MANAGE Function - AI Risk Treatment, Response and Recovery (NIST AI 100-1)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The NIST AI RMF MANAGE function requires organizations to implement a documented AI risk management process by prioritizing, allocating resources for, and responding to identified and analyzed risks on an ongoing basis. This involves developing and deploying risk treatments, response plans, and recovery procedures as detailed in Section 4.4 of the NIST AI RMF 1.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-ai-rmf-map",
      "nist-ai-rmf-measure",
      "iso-42001-risk-assess",
      "nist-sp-1270-managing-ai-bias"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-ai-rmf-map",
    "title": "NIST AI RMF: Risk Context",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "NIST AI RMF MAP is the discovery function of the AI Risk Management Framework (NIST AI 100-1, January 2023). It establishes the context for each AI system - its intended use, deployment environment, affected stakeholders, and the categories of risk that apply. MAP must be completed before MEASURE or MANAGE can be executed. Without MAP, AI risk assessments are acontextual and unreliable. MAP is specifically required by the EU AI Act (Article 9 conformity assessment), ISO 42001 (Clause 6.1 risk identification), and the US NIST AI RMF Playbook as the entry point for all downstream risk management activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-ai-rmf-map-function",
    "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0): MAP Function - AI Risk Contextualization and Prioritization",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The NIST AI RMF MAP function requires organizations to establish the context to frame AI risks by identifying system purposes, scope, potential impacts, and relevant stakeholders. This foundational step, detailed in AI RMF Section 4.1, enables the identification, analysis, and prioritization of AI risks before they are measured and managed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "nist-sp-1270-managing-ai-bias",
      "eu-ai-act-high-risk",
      "oecd-ai-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-ai-rmf-measure",
    "title": "NIST AI RMF: Metrics",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "NIST AI RMF MEASURE is the evaluation function of the AI Risk Management Framework (NIST AI 100-1, January 2023). It converts the context established in MAP into quantitative and qualitative assessments of AI risk using appropriate tools, metrics, and methodologies. MEASURE determines the actual severity and likelihood of each identified risk before treatment decisions are made. Without rigorous MEASURE activities, MANAGE decisions are based on opinion rather than evidence - a gap that auditors, regulators, and insurers consistently flag. MEASURE is aligned with EU AI Act Article 9(7) (post-market monitoring) and ISO 42001 Clause 9 (performance evaluation).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-map",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "iso-42001-performance",
      "eu-ai-act-high-risk",
      "sr-11-7-model-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-ai-rmf-measure-function",
    "title": "NIST AI RMF MEASURE Function - AI Risk Analysis and Measurement (NIST AI 100-1)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The NIST AI RMF MEASURE function requires organizations to develop and apply metrics and methodologies for continuous analysis, assessment, and monitoring of AI system risks throughout the lifecycle. As detailed in Section 4.3, this involves tracking trustworthy AI characteristics, evaluating system performance against intended purposes, and assessing impacts on individuals and society.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-ai-rmf-map",
      "iso-42001-risk-assess",
      "nist-sp-1270-managing-ai-bias",
      "nistir-8312-explainable-ai-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-ai-rmf-roadmap-2023",
    "title": "NIST AI Risk Management Framework Roadmap (January 26, 2023)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The NIST AI Risk Management Framework Roadmap was published on January 26, 2023 alongside the NIST AI RMF 1.0 (NIST AI 100-1). The Roadmap is the forward-looking companion document setting out priorities for the evolution of the AI RMF over time. Priority areas include: (1) Maintaining and updating the AI RMF Core through engagement with stakeholders and incorporation of new research; (2) Profiles - development of use-case profiles (such as the Generative AI Profile NIST AI 600-1 published July 2024) and cross-sectoral profiles applying the AI RMF to specific contexts; (3) Trustworthy AI characteristics - deeper guidance on each characteristic including Valid and Reliable, Safe, Secure and Resilient, Accountable and Transparent, Explainable and Interpretable, Privacy-Enhanced, Fair with Harmful Bias Managed; (4) Test, Evaluation, Verification and Validation (TEVV) - methodologies, infrastructure, and tooling; (5) Standards - NIST engagement with ISO/IEC JTC1/SC 42, IEEE, and other standards bodies including contribution to international AI standards harmonisation; (6) Workforce - AI workforce development including skills, training, and career pathways; (7) Education and awareness; (8) Crosswalks - alignment with other frameworks including ISO/IEC 42001, COSO ERM, OECD AI Principles. The Roadmap is updated periodically and operationalises the National AI Initiative Act 2020 Section 5106 mandate for NIST to develop the voluntary AI risk management framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping",
        "iso_standard",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-ai-600-1-gen-ai-profile",
      "nist-ai-100-2-adversarial-ml-taxonomy-2024",
      "us-naiia-national-ai-initiative-act-2020"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-contingency-planning-federal-systems",
    "title": "Contingency Planning Guide for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2010-05-21",
    "bluf": "NIST Special Publication 800-34, Rev. 1, provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to interim measures to recover information system services after a disruption, which may include relocation to an alternate site, recovery using alternate equipment, or performance of functions using manual methods. This guidance addresses contingency planning recommendations for client/server, telecommunications, and mainframe systems.\n\nThe guide defines a seven-step contingency planning process to develop and maintain a viable program. These steps are: 1. Develop the contingency planning policy statement to provide authority and guidance. 2. Conduct the business impact analysis (BIA) to identify and prioritize critical information systems. 3. Identify preventive controls to reduce the effects of system disruptions. 4. Create thorough recovery strategies to ensure the system may be recovered quickly and effectively. 5. Develop an information system contingency plan containing detailed guidance and procedures. 6. Ensure plan testing, training, and exercises to validate recovery capabilities and identify gaps. 7. Ensure plan maintenance, treating the plan as a living document that is updated regularly.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "fips-199-security-categorization"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-csf-2-0-category-de-ae-adverse-event-analysis",
    "title": "NIST CSF 2.0 Category DE.AE: Adverse Event Analysis",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category DE.AE Adverse Event Analysis, in the DETECT (DE) function. Category statement from NIST CSF 2.0 Core: Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents Category DE.AE contains 8 Subcategories: DE.AE-01, DE.AE-02, DE.AE-03, DE.AE-04, DE.AE-05, DE.AE-06, DE.AE-07, DE.AE-08. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-category-de-cm-continuous-monitoring",
    "title": "NIST CSF 2.0 Category DE.CM: Continuous Monitoring",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category DE.CM Continuous Monitoring, in the DETECT (DE) function. Category statement from NIST CSF 2.0 Core: Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events Category DE.CM contains 9 Subcategories: DE.CM-01, DE.CM-02, DE.CM-03, DE.CM-04, DE.CM-05, DE.CM-06, DE.CM-07, DE.CM-08, DE.CM-09. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-category-gv-oc-organizational-context",
    "title": "NIST CSF 2.0 Category GV.OC: Organizational Context",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category GV.OC Organizational Context, in the GOVERN (GV) function. Category statement from NIST CSF 2.0 Core: The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organization's cybersecurity risk management decisions are understood Category GV.OC contains 5 Subcategories: GV.OC-01, GV.OC-02, GV.OC-03, GV.OC-04, GV.OC-05. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-csf-2-0-category-gv-ov-oversight",
    "title": "NIST CSF 2.0 Category GV.OV: Oversight",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category GV.OV Oversight, in the GOVERN (GV) function. Category statement from NIST CSF 2.0 Core: Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management strategy Category GV.OV contains 3 Subcategories: GV.OV-01, GV.OV-02, GV.OV-03. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-csf-2-0-category-gv-po-policy",
    "title": "NIST CSF 2.0 Category GV.PO: Policy",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category GV.PO Policy, in the GOVERN (GV) function. Category statement from NIST CSF 2.0 Core: Organizational cybersecurity policy is established, communicated, and enforced Category GV.PO contains 2 Subcategories: GV.PO-01, GV.PO-02. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-csf-2-0-category-gv-rm-risk-management-strategy",
    "title": "NIST CSF 2.0 Category GV.RM: Risk Management Strategy",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category GV.RM Risk Management Strategy, in the GOVERN (GV) function. Category statement from NIST CSF 2.0 Core: The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions Category GV.RM contains 7 Subcategories: GV.RM-01, GV.RM-02, GV.RM-03, GV.RM-04, GV.RM-05, GV.RM-06, GV.RM-07. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-category-gv-rr-roles-responsibilities-and-authorities",
    "title": "NIST CSF 2.0 Category GV.RR: Roles, Responsibilities, and Authorities",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category GV.RR Roles, Responsibilities, and Authorities, in the GOVERN (GV) function. Category statement from NIST CSF 2.0 Core: Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated Category GV.RR contains 4 Subcategories: GV.RR-01, GV.RR-02, GV.RR-03, GV.RR-04. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-csf-2-0-category-gv-sc-cybersecurity-supply-chain-risk-management",
    "title": "NIST CSF 2.0 Category GV.SC: Cybersecurity Supply Chain Risk Management",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category GV.SC Cybersecurity Supply Chain Risk Management, in the GOVERN (GV) function. Category statement from NIST CSF 2.0 Core: Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders Category GV.SC contains 10 Subcategories: GV.SC-01, GV.SC-02, GV.SC-03, GV.SC-04, GV.SC-05, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-09, GV.SC-10. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-category-id-am-asset-management",
    "title": "NIST CSF 2.0 Category ID.AM: Asset Management",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category ID.AM Asset Management, in the IDENTIFY (ID) function. Category statement from NIST CSF 2.0 Core: Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identified and managed consistent with their relative importance to organizational objectives and the organization's risk strategy Category ID.AM contains 8 Subcategories: ID.AM-01, ID.AM-02, ID.AM-03, ID.AM-04, ID.AM-05, ID.AM-06, ID.AM-07, ID.AM-08. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-category-id-im-improvement",
    "title": "NIST CSF 2.0 Category ID.IM: Improvement",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category ID.IM Improvement, in the IDENTIFY (ID) function. Category statement from NIST CSF 2.0 Core: Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions Category ID.IM contains 4 Subcategories: ID.IM-01, ID.IM-02, ID.IM-03, ID.IM-04. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-csf-2-0-category-id-ra-risk-assessment",
    "title": "NIST CSF 2.0 Category ID.RA: Risk Assessment",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category ID.RA Risk Assessment, in the IDENTIFY (ID) function. Category statement from NIST CSF 2.0 Core: The cybersecurity risk to the organization, assets, and individuals is understood by the organization Category ID.RA contains 10 Subcategories: ID.RA-01, ID.RA-02, ID.RA-03, ID.RA-04, ID.RA-05, ID.RA-06, ID.RA-07, ID.RA-08, ID.RA-09, ID.RA-10. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-category-pr-aa-identity-management-authentication-and-access-control",
    "title": "NIST CSF 2.0 Category PR.AA: Identity Management, Authentication, and Access Control",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category PR.AA Identity Management, Authentication, and Access Control, in the PROTECT (PR) function. Category statement from NIST CSF 2.0 Core: Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access Category PR.AA contains 6 Subcategories: PR.AA-01, PR.AA-02, PR.AA-03, PR.AA-04, PR.AA-05, PR.AA-06. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-category-pr-at-awareness-and-training",
    "title": "NIST CSF 2.0 Category PR.AT: Awareness and Training",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category PR.AT Awareness and Training, in the PROTECT (PR) function. Category statement from NIST CSF 2.0 Core: The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks Category PR.AT contains 5 Subcategories: PR.AT-01, PR.AT-02, PR.AT-03, PR.AT-04, PR.AT-05. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-csf-2-0-category-pr-ds-data-security",
    "title": "NIST CSF 2.0 Category PR.DS: Data Security",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category PR.DS Data Security, in the PROTECT (PR) function. Category statement from NIST CSF 2.0 Core: Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information Category PR.DS contains 10 Subcategories: PR.DS-01, PR.DS-02, PR.DS-03, PR.DS-04, PR.DS-05, PR.DS-06, PR.DS-07, PR.DS-08, PR.DS-10, PR.DS-11. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-category-pr-ir-technology-infrastructure-resilience",
    "title": "NIST CSF 2.0 Category PR.IR: Technology Infrastructure Resilience",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category PR.IR Technology Infrastructure Resilience, in the PROTECT (PR) function. Category statement from NIST CSF 2.0 Core: Security architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizational resilience Category PR.IR contains 4 Subcategories: PR.IR-01, PR.IR-02, PR.IR-03, PR.IR-04. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-csf-2-0-category-pr-ps-platform-security",
    "title": "NIST CSF 2.0 Category PR.PS: Platform Security",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category PR.PS Platform Security, in the PROTECT (PR) function. Category statement from NIST CSF 2.0 Core: The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with the organization's risk strategy to protect their confidentiality, integrity, and availability Category PR.PS contains 6 Subcategories: PR.PS-01, PR.PS-02, PR.PS-03, PR.PS-04, PR.PS-05, PR.PS-06. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-category-rc-co-incident-recovery-communication",
    "title": "NIST CSF 2.0 Category RC.CO: Incident Recovery Communication",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category RC.CO Incident Recovery Communication, in the RECOVER (RC) function. Category statement from NIST CSF 2.0 Core: Restoration activities are coordinated with internal and external parties Category RC.CO contains 4 Subcategories: RC.CO-01, RC.CO-02, RC.CO-03, RC.CO-04. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-csf-2-0-category-rc-rp-incident-recovery-plan-execution",
    "title": "NIST CSF 2.0 Category RC.RP: Incident Recovery Plan Execution",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category RC.RP Incident Recovery Plan Execution, in the RECOVER (RC) function. Category statement from NIST CSF 2.0 Core: Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents Category RC.RP contains 6 Subcategories: RC.RP-01, RC.RP-02, RC.RP-03, RC.RP-04, RC.RP-05, RC.RP-06. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-category-rs-an-incident-analysis",
    "title": "NIST CSF 2.0 Category RS.AN: Incident Analysis",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category RS.AN Incident Analysis, in the RESPOND (RS) function. Category statement from NIST CSF 2.0 Core: Investigations are conducted to ensure effective response and support forensics and recovery activities Category RS.AN contains 8 Subcategories: RS.AN-01, RS.AN-02, RS.AN-03, RS.AN-04, RS.AN-05, RS.AN-06, RS.AN-07, RS.AN-08. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-category-rs-co-incident-response-reporting-and-communication",
    "title": "NIST CSF 2.0 Category RS.CO: Incident Response Reporting and Communication",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category RS.CO Incident Response Reporting and Communication, in the RESPOND (RS) function. Category statement from NIST CSF 2.0 Core: Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies Category RS.CO contains 5 Subcategories: RS.CO-01, RS.CO-02, RS.CO-03, RS.CO-04, RS.CO-05. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-csf-2-0-category-rs-ma-incident-management",
    "title": "NIST CSF 2.0 Category RS.MA: Incident Management",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category RS.MA Incident Management, in the RESPOND (RS) function. Category statement from NIST CSF 2.0 Core: Responses to detected cybersecurity incidents are managed Category RS.MA contains 5 Subcategories: RS.MA-01, RS.MA-02, RS.MA-03, RS.MA-04, RS.MA-05. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-csf-2-0-category-rs-mi-incident-mitigation",
    "title": "NIST CSF 2.0 Category RS.MI: Incident Mitigation",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Category RS.MI Incident Mitigation, in the RESPOND (RS) function. Category statement from NIST CSF 2.0 Core: Activities are performed to prevent expansion of an event and mitigate its effects Category RS.MI contains 3 Subcategories: RS.MI-01, RS.MI-02, RS.MI-03. Each Subcategory describes a specific cybersecurity outcome that organizations should achieve. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). Implementation is operationalized through Organizational Profiles (current vs target state) and assessed against Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). This Category maps to specific NIST SP 800-53 Rev 5 controls per the NIST-published informative reference crosswalk and to ISO/IEC 27001:2022 controls, providing alignment with the major risk-based cybersecurity frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-csf-2-0-compliance-2026-13",
    "title": "NIST CSF 2.0 Enterprise Compliance Standard v13",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The NIST Cybersecurity Framework (CSF) 2.0 provides a policy framework of computer security guidance for how private sector organizations can assess and improve their ability to prevent, detect, and respond to cyber attacks. It consists of five core functions: Identify, Protect, Detect, Respond, and Recover, which are designed to help organizations manage cybersecurity risks. The framework emphasizes the importance of integrating cybersecurity into business processes and encourages organizations to adopt a risk-based approach to cybersecurity. It also promotes collaboration among stakeholders and provides a flexible structure that can be tailored to meet the specific needs of different organizations, regardless of size or industry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-csf-2-0-cybersecurity-framework-2024",
    "title": "NIST Cybersecurity Framework 2.0 (2024) - Govern, Identify, Protect, Detect, Respond and Recover Functions with Implementation Examples",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-15",
    "bluf": "The NIST Cybersecurity Framework (CSF) 2.0 provides voluntary guidance for organizations of all sizes and sectors to manage and reduce cybersecurity risk through six Functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER. The Framework establishes a common taxonomy of high-level cybersecurity outcomes that organizations apply through Organizational Profiles and Implementation Tiers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-govern-function",
      "c-scrm-practices-systems-organizations",
      "iso-27001-2022",
      "cis-controls-v8",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-csf-2-0-de-detect-function-node",
    "title": "NIST CSF 2.0 - DETECT (DE) Function",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 - DETECT (DE) function. Function overview from NIST CSF 2.0 Core: Possible cybersecurity attacks and compromises are found and analyzed The DETECT function organizes 3 Categories: DE.AE Adverse Event Analysis; DE.CM Continuous Monitoring; DE.DP Detection Processes. Each Category contains specific Subcategories with statements describing desired cybersecurity outcomes. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29) as the first major revision since 2018, introducing GOVERN as a new function alongside the original IDENTIFY/PROTECT/DETECT/RESPOND/RECOVER. Organizations operationalize CSF 2.0 through Organizational Profiles (current state vs target state) and Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). Implementation evidence is required for FedRAMP, HIPAA Security Rule alignment, CMMC, NYDFS Part 500, and most enterprise cybersecurity programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-30-risk-assessment",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-csf-2-0-govern-function",
    "title": "The NIST Cybersecurity Framework (CSF) 2.0 - GOVERN Function",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The GOVERN (GV) function, new in NIST CSF 2.0, establishes and communicates the organization's cybersecurity risk management strategy, expectations, and policy. It ensures that cybersecurity strategy is aligned with organizational objectives and that roles, responsibilities, and authorities are clearly defined to support a culture of security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-31000-risk-mgt-std",
      "nist-ir-8286a-cybersecurity-risk",
      "sec-reg-s-k-106",
      "c-scrm-practices-systems-organizations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-csf-2-0-id-identify-function-node",
    "title": "NIST CSF 2.0 - IDENTIFY (ID) Function",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 - IDENTIFY (ID) function. Function overview from NIST CSF 2.0 Core: The organization's current cybersecurity risks are understood The IDENTIFY function organizes 7 Categories: ID.AM Asset Management; ID.BE Business Environment; ID.GV Governance; ID.IM Improvement; ID.RA Risk Assessment; ID.RM Risk Management Strategy; ID.SC Supply Chain Risk Management. Each Category contains specific Subcategories with statements describing desired cybersecurity outcomes. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29) as the first major revision since 2018, introducing GOVERN as a new function alongside the original IDENTIFY/PROTECT/DETECT/RESPOND/RECOVER. Organizations operationalize CSF 2.0 through Organizational Profiles (current state vs target state) and Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). Implementation evidence is required for FedRAMP, HIPAA Security Rule alignment, CMMC, NYDFS Part 500, and most enterprise cybersecurity programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-30-risk-assessment",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-pr-protect-function-node",
    "title": "NIST CSF 2.0 - PROTECT (PR) Function",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 - PROTECT (PR) function. Function overview from NIST CSF 2.0 Core: Safeguards to manage the organization's cybersecurity risks are used The PROTECT function organizes 9 Categories: PR.AA Identity Management, Authentication, and Access Control; PR.AC Identity Management, Authentication and Access Control; PR.AT Awareness and Training; PR.DS Data Security; PR.IP Information Protection Processes and Procedures; PR.IR Technology Infrastructure Resilience; PR.MA Maintenance; PR.PS Platform Security; PR.PT Protective Technology. Each Category contains specific Subcategories with statements describing desired cybersecurity outcomes. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29) as the first major revision since 2018, introducing GOVERN as a new function alongside the original IDENTIFY/PROTECT/DETECT/RESPOND/RECOVER. Organizations operationalize CSF 2.0 through Organizational Profiles (current state vs target state) and Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). Implementation evidence is required for FedRAMP, HIPAA Security Rule alignment, CMMC, NYDFS Part 500, and most enterprise cybersecurity programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-30-risk-assessment",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-rc-recover-function-node",
    "title": "NIST CSF 2.0 - RECOVER (RC) Function",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 - RECOVER (RC) function. Function overview from NIST CSF 2.0 Core: Assets and operations affected by a cybersecurity incident are restored The RECOVER function organizes 3 Categories: RC.CO Incident Recovery Communication; RC.IM Improvements; RC.RP Incident Recovery Plan Execution. Each Category contains specific Subcategories with statements describing desired cybersecurity outcomes. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29) as the first major revision since 2018, introducing GOVERN as a new function alongside the original IDENTIFY/PROTECT/DETECT/RESPOND/RECOVER. Organizations operationalize CSF 2.0 through Organizational Profiles (current state vs target state) and Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). Implementation evidence is required for FedRAMP, HIPAA Security Rule alignment, CMMC, NYDFS Part 500, and most enterprise cybersecurity programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-30-risk-assessment",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-csf-2-0-rs-respond-function-node",
    "title": "NIST CSF 2.0 - RESPOND (RS) Function",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 - RESPOND (RS) function. Function overview from NIST CSF 2.0 Core: Actions regarding a detected cybersecurity incident are taken The RESPOND function organizes 6 Categories: RS.AN Incident Analysis; RS.CO Incident Response Reporting and Communication; RS.IM Improvements; RS.MA Incident Management; RS.MI Incident Mitigation; RS.RP Response Planning. Each Category contains specific Subcategories with statements describing desired cybersecurity outcomes. CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29) as the first major revision since 2018, introducing GOVERN as a new function alongside the original IDENTIFY/PROTECT/DETECT/RESPOND/RECOVER. Organizations operationalize CSF 2.0 through Organizational Profiles (current state vs target state) and Implementation Tiers (Tier 1 Partial through Tier 4 Adaptive). Implementation evidence is required for FedRAMP, HIPAA Security Rule alignment, CMMC, NYDFS Part 500, and most enterprise cybersecurity programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-30-risk-assessment",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-subcategory-de-ae-02",
    "title": "NIST CSF 2.0 Subcategory DE.AE-02",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory DE.AE-02, in the Adverse Event Analysis (DE.AE) category of the DETECT (DE) function. Subcategory statement from NIST CSF 2.0 Core: Potentially adverse events are analyzed to better understand associated activities CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-csf-2-0-subcategory-de-cm-01",
    "title": "NIST CSF 2.0 Subcategory DE.CM-01",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory DE.CM-01, in the Continuous Monitoring (DE.CM) category of the DETECT (DE) function. Subcategory statement from NIST CSF 2.0 Core: Networks and network services are monitored to find potentially adverse events CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-csf-2-0-subcategory-gv-oc-01",
    "title": "NIST CSF 2.0 Subcategory GV.OC-01",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory GV.OC-01, in the Organizational Context (GV.OC) category of the GOVERN (GV) function. Subcategory statement from NIST CSF 2.0 Core: The organizational mission is understood and informs cybersecurity risk management CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "nist-csf-2-0-subcategory-gv-oc-03",
    "title": "NIST CSF 2.0 Subcategory GV.OC-03",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory GV.OC-03, in the Organizational Context (GV.OC) category of the GOVERN (GV) function. Subcategory statement from NIST CSF 2.0 Core: Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-csf-2-0-subcategory-gv-ov-01",
    "title": "NIST CSF 2.0 Subcategory GV.OV-01",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory GV.OV-01, in the Oversight (GV.OV) category of the GOVERN (GV) function. Subcategory statement from NIST CSF 2.0 Core: Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-csf-2-0-subcategory-gv-po-01",
    "title": "NIST CSF 2.0 Subcategory GV.PO-01",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory GV.PO-01, in the Policy (GV.PO) category of the GOVERN (GV) function. Subcategory statement from NIST CSF 2.0 Core: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-csf-2-0-subcategory-gv-rm-01",
    "title": "NIST CSF 2.0 Subcategory GV.RM-01",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory GV.RM-01, in the Risk Management Strategy (GV.RM) category of the GOVERN (GV) function. Subcategory statement from NIST CSF 2.0 Core: Risk management objectives are established and agreed to by organizational stakeholders CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-csf-2-0-subcategory-gv-rm-02",
    "title": "NIST CSF 2.0 Subcategory GV.RM-02",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory GV.RM-02, in the Risk Management Strategy (GV.RM) category of the GOVERN (GV) function. Subcategory statement from NIST CSF 2.0 Core: Risk appetite and risk tolerance statements are established, communicated, and maintained CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-csf-2-0-subcategory-gv-rr-02",
    "title": "NIST CSF 2.0 Subcategory GV.RR-02",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory GV.RR-02, in the Roles, Responsibilities, and Authorities (GV.RR) category of the GOVERN (GV) function. Subcategory statement from NIST CSF 2.0 Core: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-csf-2-0-subcategory-gv-sc-01",
    "title": "NIST CSF 2.0 Subcategory GV.SC-01",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory GV.SC-01, in the Cybersecurity Supply Chain Risk Management (GV.SC) category of the GOVERN (GV) function. Subcategory statement from NIST CSF 2.0 Core: A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-csf-2-0-subcategory-gv-sc-04",
    "title": "NIST CSF 2.0 Subcategory GV.SC-04",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory GV.SC-04, in the Cybersecurity Supply Chain Risk Management (GV.SC) category of the GOVERN (GV) function. Subcategory statement from NIST CSF 2.0 Core: Suppliers are known and prioritized by criticality CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-csf-2-0-subcategory-gv-sc-06",
    "title": "NIST CSF 2.0 Subcategory GV.SC-06",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory GV.SC-06, in the Cybersecurity Supply Chain Risk Management (GV.SC) category of the GOVERN (GV) function. Subcategory statement from NIST CSF 2.0 Core: Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-csf-2-0-subcategory-id-am-01",
    "title": "NIST CSF 2.0 Subcategory ID.AM-01",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory ID.AM-01, in the Asset Management (ID.AM) category of the IDENTIFY (ID) function. Subcategory statement from NIST CSF 2.0 Core: Inventories of hardware managed by the organization are maintained CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-csf-2-0-subcategory-id-am-02",
    "title": "NIST CSF 2.0 Subcategory ID.AM-02",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory ID.AM-02, in the Asset Management (ID.AM) category of the IDENTIFY (ID) function. Subcategory statement from NIST CSF 2.0 Core: Inventories of software, services, and systems managed by the organization are maintained CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-csf-2-0-subcategory-id-am-05",
    "title": "NIST CSF 2.0 Subcategory ID.AM-05",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory ID.AM-05, in the Asset Management (ID.AM) category of the IDENTIFY (ID) function. Subcategory statement from NIST CSF 2.0 Core: Assets are prioritized based on classification, criticality, resources, and impact on the mission CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-csf-2-0-subcategory-id-ra-01",
    "title": "NIST CSF 2.0 Subcategory ID.RA-01",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory ID.RA-01, in the Risk Assessment (ID.RA) category of the IDENTIFY (ID) function. Subcategory statement from NIST CSF 2.0 Core: Vulnerabilities in assets are identified, validated, and recorded CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-csf-2-0-subcategory-id-ra-03",
    "title": "NIST CSF 2.0 Subcategory ID.RA-03",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory ID.RA-03, in the Risk Assessment (ID.RA) category of the IDENTIFY (ID) function. Subcategory statement from NIST CSF 2.0 Core: Internal and external threats to the organization are identified and recorded CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-csf-2-0-subcategory-pr-aa-01",
    "title": "NIST CSF 2.0 Subcategory PR.AA-01",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory PR.AA-01, in the Identity Management, Authentication, and Access Control (PR.AA) category of the PROTECT (PR) function. Subcategory statement from NIST CSF 2.0 Core: Identities and credentials for authorized users, services, and hardware are managed by the organization CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-csf-2-0-subcategory-pr-aa-05",
    "title": "NIST CSF 2.0 Subcategory PR.AA-05",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory PR.AA-05, in the Identity Management, Authentication, and Access Control (PR.AA) category of the PROTECT (PR) function. Subcategory statement from NIST CSF 2.0 Core: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-csf-2-0-subcategory-pr-at-01",
    "title": "NIST CSF 2.0 Subcategory PR.AT-01",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory PR.AT-01, in the Awareness and Training (PR.AT) category of the PROTECT (PR) function. Subcategory statement from NIST CSF 2.0 Core: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-csf-2-0-subcategory-pr-ds-01",
    "title": "NIST CSF 2.0 Subcategory PR.DS-01",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory PR.DS-01, in the Data Security (PR.DS) category of the PROTECT (PR) function. Subcategory statement from NIST CSF 2.0 Core: The confidentiality, integrity, and availability of data-at-rest are protected CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-csf-2-0-subcategory-pr-ds-02",
    "title": "NIST CSF 2.0 Subcategory PR.DS-02",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory PR.DS-02, in the Data Security (PR.DS) category of the PROTECT (PR) function. Subcategory statement from NIST CSF 2.0 Core: The confidentiality, integrity, and availability of data-in-transit are protected CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-csf-2-0-subcategory-rs-ma-01",
    "title": "NIST CSF 2.0 Subcategory RS.MA-01",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2024-02-26",
    "bluf": "NIST Cybersecurity Framework (CSF) 2.0 Subcategory RS.MA-01, in the Incident Management (RS.MA) category of the RESPOND (RS) function. Subcategory statement from NIST CSF 2.0 Core: The incident response plan is executed in coordination with relevant third parties once an incident is declared CSF 2.0 was published by NIST in February 2024 (NIST CSWP 29). This Subcategory describes a specific cybersecurity outcome that organizations should achieve, expressed in a way that is technology-neutral and applicable across sector and organizational size. The NIST CSF 2.0 publication accompanies each Subcategory with one or more Implementation Examples describing concrete steps organizations can take; this node operationalizes those examples plus standard governance, evidence collection, and 800-53 mapping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-csf-2-0-workflow-security-governance",
    "title": "NIST Cybersecurity Framework 2.0 - Workflow Security Governance: Govern Function, Identify, Protect, Detect, Respond and Recover for Automated Workflow Environments",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-29",
    "bluf": "This regulation establishes a comprehensive framework for managing cybersecurity risk in automated workflow environments through six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. It applies to all organizations utilizing workflow automation systems and mandates adherence to the NIST CSF 2.0 structure as defined in the official guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "azure-logic-apps-enterprise-integration",
      "apache-airflow-workflow-dag-governance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-csf-20-govern-function-gv",
    "title": "NIST Cybersecurity Framework 2.0",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-15",
    "bluf": "The GOVERN (GV) Function of NIST CSF 2.0 establishes, communicates, and monitors the organization cybersecurity risk management strategy, expectations, and policy. GOVERN addresses understanding of organizational context, cybersecurity supply chain risk management, roles and responsibilities, policy, and oversight of cybersecurity strategy. GOVERN provides outcomes that inform the other five Functions (IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-csf-20-identify-function-id",
    "title": "NIST Cybersecurity Framework 2.0: Identify (ID) Function",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-15",
    "bluf": "The IDENTIFY (ID) Function of NIST CSF 2.0 ensures the organization current cybersecurity risks are understood. Understanding assets (data, hardware, software, systems, facilities, services, people), suppliers, and related cybersecurity risks enables an organization to prioritize its efforts consistent with risk management strategy and mission needs identified under GOVERN. IDENTIFY also covers identification of improvement opportunities for policies, plans, processes, procedures, and practices supporting cybersecurity risk management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "nist-csf-20-protect-function-pr",
    "title": "NIST Cybersecurity Framework 2.0",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-15",
    "bluf": "The PROTECT (PR) Function of NIST CSF 2.0 implements safeguards to manage the organization cybersecurity risks. PROTECT supports the ability to secure assets to prevent or lower the likelihood and impact of adverse cybersecurity events. Outcomes covered include identity management and access control (PR.AA), awareness and training (PR.AT), data security (PR.DS), platform security (PR.PS), and resilience of technology infrastructure (PR.IR).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-csf-20-recover-function-rc",
    "title": "NIST Cybersecurity Framework 2.0: Recover (RC) Function",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the framework for developing and implementing activities to maintain resilience and restore capabilities or services impaired by a cybersecurity incident.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-csf-20-respond-function-rs",
    "title": "NIST Cybersecurity Framework 2.0: Engagement and Resource Utilization",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-15",
    "bluf": "The RESPOND (RS) Function of NIST CSF 2.0 takes actions regarding a detected cybersecurity incident. RESPOND covers four Categories: Incident Management (RS.MA) governing response activities once an incident is declared; Incident Analysis (RS.AN) investigating to support forensics and recovery; Incident Response Reporting and Communication (RS.CO) coordinating with internal and external stakeholders; and Incident Mitigation (RS.MI) preventing expansion and mitigating effects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-csf-critical-infrastructure-cybersecurity-v2",
    "title": "NIST Cybersecurity Framework Version 2.0: Improving Critical Infrastructure Cybersecurity",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The NIST Cybersecurity Framework (CSF) 2.0 provides a policy framework of cybersecurity outcomes organized into six core functions-Identify, Protect, Detect, Respond, Recover, and Govern-to manage and reduce critical infrastructure cyber risk. It applies to organizations in critical sectors such as energy, utilities, and industrial IoT that rely on operational technology and interconnected systems, with governance as a central function to align cybersecurity with organizational mission and risk appetite (NIST CSF 2.0, Core Functions).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-82-r3-ot-ics-security-guide-2023",
      "iec-62443-iacs",
      "iso-iec-27019-energy-utility-information-security",
      "ot-ics-purdue-model-zone-based-security",
      "iec-62351-power-systems-cybersecurity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-cswp-30-automation-support",
    "title": "Automation Support for Control Assessments: Project Update and Vision",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2023-12-06",
    "bluf": "NIST Interagency Report (IR) 8011 is a multi-volume series that provides a blueprint for supporting automated control assessments. It proposes an approach for creating specific tests, denominated as 'defect checks,' that can be executed using automation to verify that controls are in place and operating as expected. The methodology supports the NIST Risk Management Framework (RMF) and expands on guidance from SP 800-53A for assessing SP 800-53 controls, ultimately to support information security continuous monitoring (ISCM) activities.\n\nThis cybersecurity white paper, NIST CSWP 30, summarizes the findings from an internal review of the IR 8011 project. It outlines opportunities for improving the methodology, including restructuring the workflow for readability, expanding keyword search functions, and abstracting the security framework to support any control-based framework. The paper provides a glimpse of what is coming next and updates the IR 8011 development roadmap, with a stated goal of operationalizing the framework into solutions that can benefit agencies and organizations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-cswp-34-telehealth-smart-home",
    "title": "Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2025-12-17",
    "bluf": "Hospital-at-Home (HaH) solutions, a form of telehealth providing in-patient level care within patients' residences, introduce significant privacy and cybersecurity risks by placing hospital-grade medical or biometric devices and information systems outside of a hospital's direct control. These risks are compounded by the increasing presence of consumer Internet of Things (IoT) devices, such as voice assistants (e.g., smart speakers), in patients' homes. Such devices may lack robust security and privacy capabilities and can serve as pivot points for attackers to gain access to a hospital’s information systems. This white paper introduces a notional high-level smart home integration reference architecture to analyze these risks, focusing on voice assistants as a representative IoT device.\n\nThis document is intended for technologists and information security professionals in healthcare delivery organizations (HDOs) implementing HaH solutions. It leverages the NIST Cybersecurity Framework 2.0, the NIST Privacy Framework Version 1.0, and the NIST IoT Core Baseline to outline mitigation efforts for HDOs. The core obligations and recommended mitigations include implementing robust access control, authentication, continuous monitoring, data security through encryption, comprehensive governance, and network segmentation. A key recommendation is to isolate HaH equipment from other personally owned devices within the patient's home to safeguard sensitive data from unauthorized access, which could result from compromised personal devices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nistir-8259a-iot-device-cybersecurity",
      "nist-sp-800-53-r5",
      "nist-sp-800-63b-digital-identity",
      "nist-sp-800-82r3-ot-security",
      "hipaa-breach-notification"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-cswp-36-5g-cybersecurity-capabilities",
    "title": "Applying 5G Cybersecurity and Privacy Capabilities Introduction to the White Paper Series",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-03-01",
    "bluf": "This document introduces the white paper series titled Applying 5G Cybersecurity and Privacy Capabilities, published by the National Cybersecurity Center of Excellence (NCCoE) 5G Cybersecurity project. The series addresses the challenge that 5G introduced new security capabilities in the standards focusing on securing interoperable interfaces rather than the underlying IT infrastructure. This creates gaps and options in specified cybersecurity and privacy protections that complicate how organizations assess, deploy, and supplement security for 5G systems. The 5G standards do not specify protections for the underlying IT components, and the security controls that are defined are left to implementation and deployment decisions. This lack of specification increases complexity for organizations planning to leverage 5G.\n\nThe series is intended for technology, security, and privacy program managers, including potential private 5G network operators, commercial mobile network operators, and organizations using and managing 5G-enabled technology. The core obligation for these organizations is to make cybersecurity risk management decisions regarding the use, management, and maintenance of 5G. To address this, the NCCoE is developing example solution approaches for safeguarding 5G standalone networks. Each paper in the series provides implementation guidelines and testbed-derived findings for individual technical cybersecurity or privacy capabilities, intended to support risk-based decisions for organizations deploying, operating, or relying on 5G networks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-30-risk-assessment",
      "nist-cswp-36b-hardware-enabled-security-5g"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-cswp-36b-hardware-enabled-security-5g",
    "title": "Using Hardware-Enabled Security to Ensure 5G System Platform Integrity: Applying 5G Cybersecurity and Privacy Capabilities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-03-31",
    "bluf": "This white paper provides an overview and an example of employing hardware-enabled security capabilities to provision, measure, attest to, and enforce the integrity of the compute platform to foster trust in a 5G system’s server infrastructure. As 5G systems adopt cloud-native technologies on commodity servers, the threat landscape has evolved to include attacks against platform firmware and hardware below the operating system. Traditional cybersecurity protections rooted in software or firmware are inadequate against such threats. This document discusses how leveraging hardware roots of trust (HRoT) and remote attestation can mitigate these specific threats by establishing and maintaining platform trust.\n\nThe core obligation for mobile network operators is to ensure the integrity of the 5G server configuration, including hardware, firmware, and software. This is achieved by cryptographically measuring these components at boot time, saving the measurements to a secure storage element like a Trusted Platform Module (TPM), and using a Remote Attestation Server (RAS) to compare these measurements against a list of allowed values. The 5G Cloud-native Network Function (CNF) orchestrator must then communicate with the RAS to ensure that workloads are only deployed to servers with a current status of trusted. This provides assurance that the hardware infrastructure where 5G workloads are executing has not been tampered with. The guidance is intended for technology, cybersecurity, and privacy professionals involved in using, managing, or providing 5G-enabled services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-193-firmware-resiliency",
      "validating-integrity-of-computing-devices",
      "nist-sp-800-207",
      "nist-sp-1800-19-trusted-cloud",
      "nist-cswp-36-5g-cybersecurity-capabilities"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-cswp-39-considerations-for-achieving-crypto-agility-2025",
    "title": "NIST CSWP 39 - Considerations for Achieving Cryptographic Agility: Strategies and Practices (Cybersecurity White Paper, final published December 19, 2025)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "NIST Cybersecurity White Paper (CSWP) 39 'Considerations for Achieving Cryptographic Agility: Strategies and Practices' is a NIST publication issued by the Computer Security Resource Center to provide concrete strategies and practices for organisations seeking to achieve cryptographic agility; its initial public draft was released March 5, 2025, and the final version was published December 19, 2025. Crypto agility - the capacity of an information system to swap cryptographic algorithms and parameters quickly and at low cost in response to weakness, deprecation, or new standardisation - has become a foundational requirement of the post-quantum cryptography (PQC) migration mandated by NSM-10 and OMB M-23-02 because the transition from classical to PQC algorithms requires modifying many cryptographic primitives in many production systems on a multi-year timeline. CSWP 39 frames crypto agility as a system property achieved through deliberate architectural, operational, and governance practices including (a) cryptographic abstraction layers that separate algorithm choice from application logic, (b) cryptographic inventory and discovery capabilities providing real-time visibility into deployed cryptographic systems, (c) modular cryptographic libraries enabling algorithm swap without code recompilation, (d) protocol-level negotiation capabilities for hybrid and transitional cryptographic constructions, (e) key management infrastructure capable of handling longer key lengths and new key formats associated with PQC algorithms, (f) certificate authority infrastructure supporting new algorithm-OID issuance and validation, (g) hardware security module (HSM) interfaces accepting algorithm extensibility, (h) compliance and audit infrastructure capable of tracking cryptographic state across heterogeneous systems, and (i) supply chain visibility into vendor cryptographic implementations. The paper draws on the practitioner experience of the National Cybersecurity Center of Excellence (NCCoE) Migration to Post-Quantum Cryptography project (the NIST SP 1800-38 series) and aligns to the broader NIST PQC standardisation programme that produced FIPS 203 ML-KEM, FIPS 204 ML-DSA, and FIPS 205 SLH-DSA in August 2024. CSWP 39 is a non-mandatory white paper but is widely treated as the leading practitioner reference for crypto agility implementation by federal civilian agencies, critical infrastructure operators, defence contractors, and enterprise consumers preparing for PQC migration under harvest-now-decrypt-later threat models.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nsm-10-quantum-computing-vulnerable-cryptographic-systems-2022",
      "us-omb-m-23-02-migrating-to-post-quantum-cryptography-2022",
      "fips-203-ml-kem-standard",
      "fips-204-ml-dsa-standard",
      "fips-205-slh-dsa-quantum"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-cybersecurity-framework-2-0",
    "title": "The NIST Cybersecurity Framework (CSF) 2.0",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-02-26",
    "bluf": "The NIST Cybersecurity Framework (CSF) 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It is designed to help organizations of all sizes and sectors-including industry, government, academia, and nonprofit-to manage and reduce their cybersecurity risks, regardless of the maturity level and technical sophistication of their cybersecurity programs. The framework offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization to better understand, assess, prioritize, and communicate its cybersecurity efforts. The core obligation is for an organization to use the CSF components-the Core, Organizational Profiles, and Tiers-to understand their current and target cybersecurity posture, identify gaps, and prioritize actions to manage risks in alignment with their mission and stakeholder expectations. The CSF does not prescribe how outcomes should be achieved, but rather links to resources that provide guidance on practices and controls. Its use is voluntary unless otherwise mandated by governmental policies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "mitre_attack",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-devsecops-microservices-service-mesh",
    "title": "Implementation of DevSecOps for a Microservices-based Application with Service Mesh",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2022-03-01",
    "bluf": "Cloud-native applications have evolved into a standardized architecture consisting of multiple loosely coupled components called microservices, often implemented as containers, supported by an infrastructure for providing application services, such as service mesh. Due to security, business competitiveness, and the inherent structure of loosely coupled components, this class of applications needs a different development, deployment, and runtime paradigm. DevSecOps (Development, Security, and Operations) has been found to be a facilitating paradigm for these applications with primitives such as continuous integration, continuous delivery, and continuous deployment (CI/CD) pipelines. These pipelines are workflows for taking the developer’s source code through various stages, such as building, testing, packaging, deployment, and operations supported by automated tools with feedback mechanisms.\nFor the purpose of this document, the entire set of source code involved in the application environment is classified into five code types: application code, application services code, infrastructure as code, policy as code, and observability as code. Separate CI/CD pipelines can be created for all five code types. The objective of this document is to provide guidance for the implementation of DevSecOps primitives for a reference platform, which consists of a container orchestration and resource management platform (e.g., Kubernetes). The benefits of this implementation for high security assurance and for enabling continuous authority to operate (C-ATO) are also discussed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-190-container-security"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-fips-186-5-dss",
    "title": "Digital Signature Standard (DSS)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-02-03",
    "bluf": "This standard specifies a suite of algorithms that can be used to generate a digital signature for applications requiring a digital signature rather than a written signature. Digital signatures are used to detect unauthorized modifications to data and to authenticate the identity of the signatory. The recipient of signed data can also use a digital signature as evidence to a third party that the signature was generated by the claimed signatory, a concept known as non-repudiation. This standard is applicable to all federal departments and agencies for the protection of sensitive unclassified information and shall be used in designing and implementing public key-based signature systems that federal departments and agencies operate or that are operated for them under contract.\n\nThe core obligation involves a signature generation process and a signature verification process. Signature generation uses a private key, which must be kept secret, to create a digital signature represented as a string of bits. Signature verification uses a corresponding public key, which may be known to the public, to verify the signature. The standard approves three techniques: the RSA digital signature algorithm, the Elliptic Curve Digital Signature Algorithm (ECDSA), and the Edwards Curve Digital Signature Algorithm (EdDSA). The security of a digital signature system is dependent on maintaining the secrecy of the signatory’s private keys, and key pairs used for signatures under this standard shall not be used for any other purpose.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-57-key-management",
      "nist-sp-800-63b-authentication",
      "secure-hash-standard-fips-180-4"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-guidelines-mobile-device-forensics",
    "title": "Guidelines on Mobile Device Forensics",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2014-05-01",
    "bluf": "Mobile device forensics is the science of recovering digital evidence from a mobile device under forensically sound conditions using accepted methods. This guide discusses procedures for the preservation, acquisition, examination, analysis, and reporting of digital evidence. The guide is intended to help organizations evolve appropriate policies and procedures for dealing with mobile devices and to prepare forensic specialists to conduct forensically sound examinations. It focuses mainly on the characteristics of cellular mobile devices, including feature phones, smartphones, and tablets with cellular voice capabilities. This information is relevant to law enforcement, incident response, and other types of investigations. The key to answering questions about evidence preservation and data extraction begins with a firm understanding of the hardware and software characteristics of mobile devices. Organizations should use this guide as a starting point for developing a forensic capability in conjunction with proper technical training and guidance provided by legal advisors, officials, and management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-61r2-incident-handling",
      "nist-sp-800-86-forensic-techniques",
      "nist-mobile-device-security-enterprise",
      "nist-sp-800-88-media-sanitization"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ir-7622-scrm-practices",
    "title": "Notional Supply Chain Risk Management Practices for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2012-10-01",
    "bluf": "This publication provides a notional set of repeatable and commercially reasonable supply chain assurance methods and practices to help federal departments and agencies mitigate supply chain risk to federal information systems. It is intended for a diverse federal audience, including mission/business owners, acquisition staff, and information system security personnel responsible for acquiring, delivering, and operating ICT systems. The document specifically targets all federal departments and agencies that acquire Information and Communication Technology (ICT) products and services, with practices recommended for systems categorized at the FIPS 199 high-impact level, although agencies may apply them to lower-impact systems based on risk.\n\nThe core obligation for federal agencies is to integrate ICT Supply Chain Risk Management (SCRM) considerations into the procurement and entire life cycle of ICT systems, products, and services. Federal departments and agencies currently lack a consistent or comprehensive way of understanding the opaque processes used to create and deliver hardware and software. This lack of visibility, traceability, and control increases the risk of exploitation through counterfeit materials, malicious software, or untrustworthy products. This document organizes specific ICT SCRM practices for acquirers, integrators, and suppliers to improve the ability of federal agencies to strategically manage associated supply chain risks and build greater assurance into the ICT systems they procure and manage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ir-7628-smart-grid-cybersecurity",
    "title": "Guidelines for Smart Grid Cybersecurity, Volume 1 - Smart Grid Cybersecurity Strategy, Architecture, and High-Level Requirements",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2014-09-01",
    "bluf": "This three-volume report, Guidelines for Smart Grid Cybersecurity, presents an analytical framework that organizations can use to develop effective cybersecurity strategies tailored to their particular combinations of smart grid-related characteristics, risks, and vulnerabilities. Organizations in the diverse community of smart grid stakeholders-from utilities to providers of energy management services to manufacturers of electric vehicles and charging stations-can use the methods and supporting information presented in this report as guidance for assessing risk and identifying and applying appropriate security requirements. This approach recognizes that the electric grid is changing from a relatively closed system to a complex, highly interconnected environment. Each organization’s cybersecurity requirements should evolve as technology advances and as threats to grid security inevitably multiply and diversify.\n\nThe document development strategy requires the definition and implementation of an overall cybersecurity risk assessment process for the smart grid, based on existing approaches developed by both the private and public sectors. This includes identifying assets, vulnerabilities, and threats and specifying impacts to produce an assessment of risk. While integrating information technologies is essential to building the smart grid and realizing its benefits, the same networked technologies add complexity and also introduce new interdependencies and vulnerabilities. Approaches to secure these technologies must be designed and implemented early in the transition to the smart grid.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-53-r5",
      "nist-sp-800-82r3-ot-security",
      "nist-sp-1800-7-electric-utilities",
      "nist-sp-1800-32-securing-ders"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ir-8011-v1-automated-assessments",
    "title": "Automation Support for Security Control Assessments Volume 1: Overview",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2017-06-01",
    "bluf": "This volume introduces concepts to support automated assessment of security controls detailed in NIST Special Publication (SP) 800-53. The ability to assess all implemented information security controls as frequently as needed using manual procedural methods is impractical for most organizations due to the size, complexity, and scope of their IT footprint. This document provides an operational approach for automating assessments of selected and implemented security controls to support and facilitate near real-time information security continuous monitoring (ISCM) and ongoing security authorizations. The approach is designed to be consistent with NIST guidance, including SP 800-53A, and supports programs like the Department of Homeland Security (DHS) Continuous Diagnostics and Mitigation (CDM) program.\n\nThe core methodology involves automating the 'Test' assessment method by comparing a system's actual state or behavior with a defined desired state specification. This comparison is used to perform 'defect checks', which correspond to security sub-capabilities and test for the absence or failure of a control. The document organizes controls into ISCM security capabilities, which are logical groupings that fulfill a specific purpose, such as Hardware Asset Management or Vulnerability Management. This framework supports organizations in transitioning from static, periodic security authorizations to a more dynamic, ongoing authorization process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-ir-8062-privacy-engineering",
    "title": "NISTIR 8062 An Introduction to Privacy Engineering and Risk Management in Federal Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2017-01-01",
    "bluf": "This publication provides an introduction to how systems engineering and risk management can be used to develop more trustworthy systems that include privacy as an integral attribute. It is intended for federal agencies that need repeatable and measurable approaches to bridge the distance between high-level privacy principles, such as the Fair Information Practice Principles (FIPPs), and their effective implementation in systems. While unauthorized access to personally identifiable information (PII) is a critical aspect of privacy, there is a less developed understanding of how to address risks that extend beyond unauthorized access.\n\nThe core obligation is for agencies to adopt a specialty discipline of systems engineering focused on achieving freedom from conditions that create problems for individuals with unacceptable consequences arising from the system as it processes PII. To support this, the publication introduces key components for privacy engineering: a set of privacy engineering objectives (predictability, manageability, and disassociability) to help focus on necessary system capabilities, and a privacy risk model to enable more consistent privacy risk assessments. This model is based on the likelihood that a system operation creates a problematic data action and the impact of that action. The concepts are intended to provide a roadmap for actionable guidance to help agencies meet their obligations under Circular A-130 and other relevant policies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "other_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-160-v1r1"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-ir-8176-linux-container-security",
    "title": "Security Assurance Requirements for Linux Application Container Deployments",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2017-10-01",
    "bluf": "This document outlines security assurance requirements for security solutions implemented in Linux application container platforms. To assess the effectiveness of security solutions, it is necessary to analyze those solutions and detail the metrics they must satisfy in the form of security assurance requirements. Building upon the NIST Application Container Security Guide (SP 800-190), which identified threats and countermeasures for six entities including Hardware, Host OS, Container Runtime, Image, Registry, and Orchestrator, this document focuses specifically on application containers hosted on Linux. The analysis covers security solutions that can be configured using features provided by Linux, such as namespaces, Cgroups, and capabilities, as well as kernel loadable modules.\n\nThe target audience includes system security architects and administrators responsible for the design and deployment of security solutions in enterprise infrastructures hosting containerized applications. The document examines hardware-based roots of trust, host OS protection measures against container escape, secure container runtime configurations for isolation and resource limiting, and requirements for image integrity and registry protection. The objective is to provide a detailed analysis of security solutions to ensure they effectively meet their intended security objectives within the container ecosystem.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-190-container-security"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ir-8202-blockchain-overview",
    "title": "NISTIR 8202 Blockchain Technology Overview",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2018-10-31",
    "bluf": "Blockchains are tamper evident and tamper resistant digital ledgers implemented in a distributed fashion (i.e., without a central repository) and usually without a central authority (i.e., a bank, company, or government). At their basic level, they enable a community of users to record transactions in a shared ledger within that community, such that under normal operation of the blockchain network no transaction can be changed once published. This document provides a high-level technical overview of blockchain technology to help readers understand how it works.\n\nOrganizations considering implementing blockchain technology need to understand fundamental aspects of the technology. There are two general high-level categories for blockchain approaches: permissionless and permissioned. In a permissionless blockchain network anyone can read and write to the blockchain without authorization. Permissioned blockchain networks limit participation to specific people or organizations and allow finer-grained controls. Despite the many variations of blockchain networks and the rapid development of new blockchain related technologies, most blockchain networks use common core concepts. Blockchains are a distributed ledger comprised of blocks, and each block contains a set of transactions. This document explores the fundamentals of how these technologies work, including how participants agree on whether a transaction is valid and what happens when changes need to be made.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-63b-authentication",
      "nist-sp-800-131a-rev-2-crypto-transitions",
      "nist-sp-800-186-elliptic-curves"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ir-8259b-iot-non-technical-baseline",
    "title": "IoT Non-Technical Supporting Capability Core Baseline",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2021-08-31",
    "bluf": "This publication defines an Internet of Things (IoT) device manufacturers’ non-technical supporting capability core baseline, which is a set of non-technical supporting capabilities generally needed from manufacturers or other third parties to support common cybersecurity controls that protect an organization’s devices as well as device data, systems, and ecosystems. The purpose is to provide organizations a starting point to use in identifying the non-technical supporting capabilities needed in relation to IoT devices they will manufacture, integrate, or acquire. This publication is intended to be used in conjunction with NISTIR 8259 and NISTIR 8259A.\n\nThe document describes four recommended non-technical supporting capabilities for the full lifecycle of cybersecurity management: 1) Documentation, to capture information potential customers need about the device and how it can be secured; 2) Information and Query Reception, to allow customers and others to submit questions and vulnerability information; 3) Information Dissemination, to flow information to customers about vulnerabilities and updates; and 4) Education and Awareness, to provide content supporting the secure use and safeguarding of IoT devices. The main audience is IoT device manufacturers, but it may also help IoT device customers or integrators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nistir-8259a-iot-device-cybersecurity",
      "nistir-8228-iot-cybersecurity-risks",
      "nist-sp-800-213-iot-guidance",
      "nist-sp-800-161r1-csrm-practices"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ir-8276-cyber-scrm-practices",
    "title": "Key Practices in Cyber Supply Chain Risk Management: Observations from Industry",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2021-02-01",
    "bluf": "In today’s highly connected, interdependent world, all organizations rely on others for critical products and services. The reality of globalization has resulted in a world where organizations no longer fully control-and often do not have full visibility into-the supply ecosystems of the products that they make or the services that they deliver. That is why identifying, assessing, and mitigating cyber supply chain risks is a critical capability to ensure business resilience. The multidisciplinary approach to managing these types of risks is called Cyber Supply Chain Risk Management (C-SCRM).\n\nThis document provides the ever-increasing community of digital businesses a set of Key Practices that any organization can use to manage cybersecurity risks associated with their supply chains. The audience is any organization-regardless of its size, scope, or complexity-that wants to manage the cybersecurity risks stemming from extended supply chains and supply ecosystems. The Key Practices are: 1. Integrate C-SCRM Across the Organization; 2. Establish a Formal C-SCRM Program; 3. Know and Manage Critical Suppliers; 4. Understand the Organization’s Supply Chain; 5. Closely Collaborate with Key Suppliers; 6. Include Key Suppliers in Resilience and Improvement Activities; 7. Assess and Monitor Throughout the Supplier Relationship; and 8. Plan for the Full Life Cycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-161r1-csrm-practices",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-34-r1"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ir-8286a-cybersecurity-risk",
    "title": "Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2025-12-18",
    "bluf": "This document supplements NIST Interagency or Internal Report 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM), by providing additional detail regarding risk guidance, identification, and analysis. The report offers examples and information to illustrate risk tolerance, risk appetite, and methods for determining risks in that context. It describes the documentation of various scenarios based on the potential impact of threats and vulnerabilities on enterprise assets, and the use of cybersecurity risk registers (CSRRs) to prioritize and communicate enterprise cybersecurity risk. The goal is to provide supplemental guidance for aligning cybersecurity risks within an organization’s overall ERM program, helping enterprises to apply, improve, and monitor the quality of cooperation and communication between Cybersecurity Risk Management (CSRM) and ERM functions.\n\nThe primary audience for this publication includes both federal and non-federal government cybersecurity, privacy, and cyber supply chain professionals who may be unfamiliar with ERM details. A secondary audience includes corporate officers, high-level executives, and ERM staff who may be unfamiliar with cybersecurity specifics. The core obligation detailed is for enterprises to establish a top-down, collaborative management approach where senior leaders set expectations through risk appetite, which is then interpreted into specific risk tolerance levels. This framework ensures that CSRM activities, including risk identification, analysis, and response, are directly aligned with and support the overarching mission and business objectives of the enterprise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-8286b-prioritizing-cybersecurity-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ir-8286b-prioritizing-cybersecurity-risk",
    "title": "Prioritizing Cybersecurity Risk for Enterprise Risk Management",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-07-01",
    "bluf": "This document provides supplemental guidance for aligning cybersecurity risks with an organization’s overall Enterprise Risk Management (ERM) program. It is the second publication in a series that supplements NISTIR 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This report describes the need for determining the priorities of each cybersecurity risk in light of their potential impact on enterprise objectives, as well as options for properly treating that risk. The guidance applies to all organizations and enterprises, defined as an entity of any size, complexity, or positioning within a larger organizational structure. The core obligation is for all participants in the enterprise who play a role in Cybersecurity Risk Management (CSRM) and/or ERM to use consistent methods to prioritize and respond to risk. This includes applying risk analysis to help prioritize cybersecurity risk, evaluate and select appropriate risk responses, and communicate risk activities using a cybersecurity risk register (CSRR) as part of an enterprise CSRM strategy. To minimize the extent to which cybersecurity risks impede enterprise missions and objectives, there must be effective collaboration among CSRM and ERM managers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-8286a-cybersecurity-risk",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-ir-8286c-staging-cybersecurity-risks",
    "title": "Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-03-06",
    "bluf": "This document supplements NIST Interagency/Internal Report (NISTIR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). It explores methods for integrating disparate cybersecurity risk management (CSRM) information from throughout an enterprise to create a composite Enterprise Risk Profile (ERP) that informs enterprise risk management (ERM) deliberations, decisions, and actions. The report describes how information recorded in cybersecurity risk registers (CSRRs) can be integrated into a holistic approach, ensuring that risks to information and technology are properly considered within the enterprise risk portfolio. This cohesive understanding supports an enterprise risk register (ERR) and an ERP, which in turn support the achievement of enterprise objectives. The guidance provided is voluntary and non-binding for the private sector, but references government-mandated requirements to demonstrate alignment. Key activities described include the aggregation and normalization of CSRRs, integration of cybersecurity risk into the ERR/ERP, adjustments to risk direction based on governance, and the continuous monitoring, evaluation, and adjustment of the CSRM program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-8286a-cybersecurity-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ir-8286d-bia-for-risk",
    "title": "Using Business Impact Analysis to Inform Risk Prioritization and Response",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-11-17",
    "bluf": "This publication describes how a business impact analysis (BIA), historically used for determining availability requirements for business continuity, can be extended to provide a broad understanding of the potential impacts of any type of loss on an enterprise mission. The management of enterprise risk requires a comprehensive understanding of mission-essential functions and the potential risk scenarios that jeopardize those functions. The process described helps leaders determine which assets enable the achievement of mission objectives and evaluate the factors that render assets as critical and sensitive. Based on these factors, enterprise leaders provide risk directives, such as risk appetite and tolerance, as input to the BIA.\n\nThe BIA examines the potential impacts associated with the loss or degradation of an enterprise’s technology-related assets based on a qualitative or quantitative assessment of the criticality and sensitivity of those assets, storing the results in a BIA Register. Expanding the use of the BIA to include confidentiality and integrity considerations supports comprehensive risk analysis and helps to better align risk decisions to enterprise risk strategy. The output of the BIA is the foundation for the Enterprise Risk Management (ERM) and Cybersecurity Risk Management (CSRM) integration process, enabling consistent prioritization, response, and communication regarding information security risk for both public- and private-sector enterprises.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-8286a-cybersecurity-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ir-8374-ransomware-risk-management",
    "title": "Ransomware Risk Management: A Cybersecurity Framework Profile",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-01",
    "bluf": "Ransomware is a type of malicious attack where attackers encrypt an organization’s data and demand payment to restore access. Attackers may also steal an organization’s information and demand an additional payment in return for not disclosing the information. This Ransomware Profile identifies the Cybersecurity Framework Version 1.1 security objectives that support identifying, protecting against, detecting, responding to, and recovering from ransomware events. The profile can be used as a guide to managing the risk of ransomware events, helping to gauge an organization’s level of readiness to counter ransomware threats and to deal with the potential consequences.\n\nThe Ransomware Profile is intended for any organization with cyber resources that could be subject to ransomware attacks, regardless of sector or size, including small to medium-sized businesses (SMBs), small federal agencies, and operators of industrial control systems (ICS) or operational technologies (OT). It maps security objectives from the Framework for Improving Critical Infrastructure Cybersecurity to security capabilities and measures. It should help organizations to identify and prioritize opportunities for improving their security and resilience against ransomware attacks. The guidance in this report addresses best practices rather than a set of legal or regulatory requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cisa-ms-isac-ransomware-guide",
      "nist-sp-800-61r2-incident-handling",
      "nist-sp-800-34-r1",
      "nist-sp-1800-25-data-integrity",
      "nist-sp-1800-11-data-integrity"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ir-8413-pqc-third-round",
    "title": "Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2022-09-29",
    "bluf": "The National Institute of Standards and Technology is in the process of selecting public-key cryptographic algorithms through a public, competition-like process. The new public-key cryptography standards will specify additional digital signature, public-key encryption, and key-establishment algorithms to augment Federal Information Processing Standard (FIPS) 186-4, as well as NIST Special Publications SP 800-56A and SP 800-56B. It is intended that these algorithms will be capable of protecting sensitive information well into the foreseeable future, including after the advent of quantum computers. This report describes the evaluation and selection process of the third-round candidates based on public feedback and internal review, summarizing each of the 15 candidates.\n\nThe public-key encryption and key-establishment algorithm that will be standardized is CRYSTALS-KYBER. The digital signatures that will be standardized are CRYSTALS-Dilithium, FALCON, and SPHINCS+. While multiple signature algorithms were selected, NIST recommends CRYSTALS-Dilithium as the primary algorithm to be implemented. Additionally, four alternate key-establishment candidate algorithms-BIKE, Classic McEliece, HQC, and SIKE-will advance to a fourth round of evaluation and are still being considered for future standardization. NIST will also issue a new Call for Proposals for public-key digital signature algorithms to augment and diversify its signature portfolio.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-203-ml-kem-standard",
      "fips-204-ml-dsa-standard"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ir-8425-iot-core-baseline-profile",
    "title": "Profile of the IoT Core Baseline for Consumer IoT Products",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-09-08",
    "bluf": "This publication documents the consumer profile of NIST’s Internet of Things (IoT) core baseline and identifies cybersecurity capabilities commonly needed for the consumer IoT sector (i.e., IoT products for home or personal use). It can also be a starting point for businesses to consider in the purchase of IoT products. The consumer profile was developed as part of NIST’s response to Executive Order 14028. The consumer profile capabilities are phrased as cybersecurity outcomes that are intended to apply to the entire IoT product. An IoT product is defined as an IoT device or IoT devices and any additional product components that are necessary to use the IoT device beyond basic operational features, such as backends or companion applications. The intended audience for this report consists of manufacturers of consumer products, especially product security officers, retailers and related integrators and technical support firms serving the consumer and business sectors, and testing and certification bodies interested in establishing baselines of IoT cybersecurity capabilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-8259b-iot-non-technical-baseline"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-ir-8432-genomic-data",
    "title": "Cybersecurity of Genomic Data",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2023-12-31",
    "bluf": "This report describes current practices in cybersecurity and privacy risk management for protecting genomic data. Genomic data's unique characteristics, such as being immutable and containing information about kinship and health, raise cybersecurity and privacy concerns that are inadequately addressed with current policies, guidance, and technical controls. This document addresses challenges and concerns identified by bioeconomy stakeholders, including practices for data generation, safe and responsible data sharing, monitoring of processing systems, and the lack of specific guidance for genomic data processors. Gaps in the regulatory and policy landscape concerning national security and privacy threats from the collection, storage, and sharing of human genomic data are also highlighted.\n\nThe report identifies that cyber attacks targeting genomic data can threaten national security, economic stability through intellectual property theft, and individual privacy. These attacks can disrupt biopharmaceutical output, agricultural production, and lead to the development of biological weapons or surveillance of citizens. The document proposes a set of solution ideas that address real-life use cases occurring at various stages of the genomic data lifecycle, including candidate mitigation strategies and their expected benefits, based on stakeholder input from workshops hosted by the National Cybersecurity Center of Excellence (NCCoE).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-207",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-ir-8441-hsn-profile",
    "title": "Cybersecurity Framework Profile for Hybrid Satellite Networks (HSN)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-09-14",
    "bluf": "The space sector is transitioning towards Hybrid Satellite Networks (HSN), which are an aggregation of independently owned and operated terminals, antennas, satellites, payloads, or other components that comprise a satellite system. An HSN may interact with government systems and critical infrastructure, requiring a framework to assess the security posture of individual components while enabling the HSN to provide its function. This report, the HSN Cybersecurity Framework Profile (HSN Profile), applies the NIST Cybersecurity Framework to HSNs with an emphasis on the interfaces between participants.\nDeveloped by the National Institute of Standards and Technology (NIST) in collaboration with subject matter experts, the HSN Profile provides voluntary, practical guidance for organizations and stakeholders engaged in the design, acquisition, and operation of HSN components. It serves as a starting point for stakeholders assessing their cybersecurity posture. The profile helps organizations to identify systems, assets, data, and risks; protect HSN services through self-assessments; detect cybersecurity-related disturbances; respond to data anomalies in a timely manner; and recover the HSN to proper working order after an incident. It is suitable for applications involving multiple stakeholders in imagery, sensing, broadcast, communications, or other space-based architectures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-161r1-csrm-practices"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-ir-8528-additional-signature-schemes-status",
    "title": "NIST IR 8528 Status Report on the First Round of the Additional Digital Signature Schemes for the PQC Standardization Process",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-10-31",
    "bluf": "NIST Internal Report 8528, Status Report on the First Round of the Additional Digital Signature Schemes for the NIST Post-Quantum Cryptography Standardization Process, was published in October 2024 and is available at doi.org/10.6028/NIST.IR.8528. It reports the outcome of a standardisation track that is separate from the original PQC process and separate from the fourth round: the additional signatures on-ramp opened in July 2022 to diversify the post-quantum signature portfolio.\n\nThe reason for the on-ramp is stated directly. After three rounds of evaluation NIST selected CRYSTALS-Kyber (ML-KEM) as the key-encapsulation mechanism and CRYSTALS-Dilithium (ML-DSA), Falcon (FN-DSA) and SPHINCS+ (SLH-DSA) as the digital signatures, and except for SPHINCS+ all of these schemes are based on the computational hardness of problems that involve structured lattices. Because two lattice-based signature schemes had already been standardised, NIST expressed particular interest in additional general-purpose signature schemes based on a security assumption that did not use structured lattices, as well as schemes with short signatures and fast verification. The Call for Proposals accordingly required that lattice-based submissions provide at least one large performance advantage over both CRYSTALS-Dilithium and Falcon, and that non-lattice-based algorithms provide at least one large performance advantage over SPHINCS+.\n\nNIST received 50 submission packages by the entry deadline of June 1, 2023 and accepted 40 first-round candidates that met the submission requirements and the minimum acceptability criteria for complete and proper submissions, being reference and optimized C code implementations, known-answer tests, a written specification and required intellectual property statements; security, cost and implementation characteristics were expressly not considered at the acceptance stage. Based on public feedback and internal review, NIST selected 14 second-round candidates in October 2024: CROSS, FAEST, HAWK, LESS, MAYO, Mirath (the merger of MIRA and MiRitH), MQOM, PERK, QR-UOV, RYDE, SDitH, SNOVA, SQIsign and UOV. Selection weighted, in relative order of importance, security, then cost and performance, then algorithm and implementation characteristics. Any eventually selected scheme would augment FIPS 204, FIPS 205, FIPS 186-5 and SP 800-208 rather than replace them. The report records that changes to second-round submissions had to reach NIST by January 17, 2025, that a further standardisation conference was planned for September 2025, and that NIST planned to select finalists for a third round in 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-204-ml-dsa-standard",
      "fips-205-slh-dsa-quantum",
      "nist-sp-800-208-stateful-hbs",
      "nist-ir-8413-pqc-third-round"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-ir-8545-pqc-fourth-round-status",
    "title": "NIST IR 8545 Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2025-03-31",
    "bluf": "NIST Internal Report 8545, Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process, was published in March 2025 and is available at doi.org/10.6028/NIST.IR.8545. It closes the fourth round and, with it, the standardization process that began with the NIST Call for Proposals in 2016.\n\nFour key-encapsulation mechanism candidates were carried into the fourth round for continued evaluation, all based on different security assumptions than ML-KEM: BIKE, Classic McEliece, HQC and SIKE. The report records a single outcome. The only key-establishment algorithm that will be standardized is HQC, and NIST will develop a standard based on HQC to augment its key-establishment portfolio. The reasons for each exclusion are stated. SIKE was removed from consideration after published cryptanalytic results early in the fourth round demonstrated that it was insecure, and its submitters acknowledged its insecurity and recommended against its further use. Classic McEliece drew limited interest despite recognised strengths for use cases where a public key can be transferred once and then used for several encapsulations, such as file encryption and virtual private networks, because of its small ciphertext size and fast encapsulation and decapsulation; it is under consideration for standardization by the International Organization for Standardization, and NIST records that concurrent standardization risks the creation of incompatible standards, so it is no longer under consideration in the current NIST process although NIST may consider developing a standard based on the ISO standard once that process completes. The choice between BIKE and HQC turned on decryption failure rate: submitted KEMs were evaluated on how well they appear to provide IND-CCA2 security, both BIKE and HQC require a sufficiently low decryption failure rate to be IND-CCA2-secure, NIST does not consider the decryption failure rate analysis for BIKE to be as mature as that for HQC, and HQC is not believed to require additional modifications to achieve the desired security properties.\n\nThe report is explicit that the algorithms not selected are not under consideration for standardization by NIST as part of the current process, that NIST will create a draft standard based on HQC and publish a final version approximately two years after comment adjudication, and that the standardization of HQC will be the second PQC KEM after ML-KEM. It also records that not all NIST PQC standardization is concluded, because NIST is separately evaluating additional digital signatures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-203-ml-kem-standard",
      "nist-ir-8413-pqc-third-round",
      "nist-ir-8547-pqc-transition"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-ir-8547-pqc-transition",
    "title": "Transition to Post-Quantum Cryptography Standards",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-11-12",
    "bluf": "This report describes NIST’s expected approach to transitioning from quantum-vulnerable cryptographic algorithms to post-quantum digital signature algorithms and key-establishment schemes. It identifies existing quantum-vulnerable cryptographic standards and the quantum-resistant standards to which information technology products and services will need to transition. This guidance is intended for a broad audience, including federal agencies, technology providers, standards organizations, and Cryptographic Module Validation Program (CMVP) laboratories, to inform their efforts and timelines for migrating information technology products, services, and infrastructure to Post-Quantum Cryptography (PQC).\n\nThe core obligation is to transition cryptographic systems to quantum-resistant cryptography, with a primary target for completion across Federal systems by 2035, as established by National Security Memorandum 10 (NSM-10). There is a pressing threat, known as “harvest now, decrypt later,” where adversaries collect encrypted data now with the goal of decrypting it once quantum technology matures. This threat makes the transition urgent, particularly for sensitive data that retains its value for many years. The transition will involve the adoption of new PQC algorithms like those in FIPS 203, 204, and 205, as well as the careful deprecation, controlled legacy use, and eventual removal of quantum-vulnerable algorithms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-203-ml-kem-standard",
      "fips-204-ml-dsa-standard",
      "fips-205-slh-dsa-quantum",
      "nist-sp-800-131a-rev-2-crypto-transitions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-language-of-trustworthy-ai",
    "title": "The Language of Trustworthy AI: An In-Depth Glossary of Terms",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2023-03-29",
    "bluf": "This document is a guide and record of the development for the NIST (National Institute of Standards and Technology) glossary of terms for trustworthy and responsible artificial intelligence (AI) and machine learning (ML). The glossary effort seeks to promote a shared understanding and improved communication among individuals and organizations seeking to operationalize trustworthy and responsible AI through approaches such as the NIST AI Risk Management Framework (AI RMF). Like the AI RMF, the glossary is non-sector specific and use-case agnostic, designed to be flexible for all organizations and sectors of society to use. The goal of this common vocabulary is not to declare one specific meaning for identified terms, but to provide interested parties with a broader awareness of the multiple meanings of commonly used terms within the interdisciplinary field of trustworthy and responsible AI.\n\nThe glossary can be used in conjunction with the NIST AI RMF and related resources, or as a stand-alone document. It serves as a first-stop resource for those new to the field, fosters cross-collaboration among different disciplines, and aligns with existing international and industry standards from bodies such as IEEE, ANSI, and ISO/IEC. Core principles in its design include the inclusion of terms related to emerging AI technologies, definitions from a wide variety of domains (including machine learning, social sciences, and law), and a collaborative development process based on consultation with subject matter experts. NIST will promote its use to a broad range of stakeholders, including researchers, developers, and policymakers, and it is subject to regular review and feedback processes from the broader AI community.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-mobile-device-security-enterprise",
    "title": "Guidelines for Managing the Security of Mobile Devices in the Enterprise",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-05-05",
    "bluf": "This publication assists organizations in managing and securing mobile devices by describing available technologies and strategies. As mobile devices perform everyday enterprise tasks, they regularly process, modify, and store sensitive data, bringing unique threats to the enterprise. To reduce the risk to sensitive data and systems, enterprises need to institute appropriate policies and infrastructure to manage and secure mobile devices, applications, content, and access. Recommendations are provided for the selection, implementation, and management of devices throughout their life cycle via centralized management technologies, covering both organization-provided and personally owned deployment scenarios. The guidance addresses security concerns inherent to mobile devices, explores mitigation strategies, and is intended for information security officers, system administrators, and others responsible for planning, implementing, and maintaining mobile device security.\n\nMobile devices often need additional protections due to their portability, small size, and common use outside of an organization’s network, which places them at higher exposure to threats than other endpoint devices. The scope of this publication includes mobile phones, tablets, and other devices running a modern mobile OS, alongside centralized device management and endpoint protection technologies. Organizations can use the guidance to inform risk assessments, build threat models, enumerate the attack surface of their mobile infrastructure, and identify mitigations for mobile deployments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "guide-telework-remote-access-byod",
      "nist-sp-1800-21-cope",
      "nist-sp-1800-22-byod",
      "nist-sp-1800-4-mobile-device-security",
      "nist-sp-800-163r1-mobile-app-vetting",
      "nist-guidelines-mobile-device-forensics"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-pqc-hipaa-2026",
    "title": "NIST Post-Quantum Cryptography Migration for HIPAA-Covered Entities 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "Guidance recommends phased migration to FIPS 203-205 algorithms to protect PHI against future quantum threats. Healthcare systems must inventory cryptographic usage and plan hybrid transitions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-privacy-framework-1-0",
    "title": "NIST Privacy Framework: A Tool for Improving Privacy Through Enterprise Risk Management",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The NIST Privacy Framework is a voluntary tool for organizations to manage privacy risk by structuring a risk-based approach through its Core (Functions, Categories, Subcategories), Profiles, and Implementation Tiers. It enables organizations to identify privacy risks in systems, products, and services, and to select appropriate outcomes and activities to manage those risks effectively.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-122-pii",
      "nist-sp-1800-28-data-confidentiality",
      "nist-ai-rmf-map"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-recommendation-key-management-pt3",
    "title": "Recommendation for Key Management Part 3: Application-Specific Key Management Guidance",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2015-01-01",
    "bluf": "NIST Special Publication 800-57 Part 3 provides application-specific cryptographic key management guidance, intended primarily for system administrators, system installers, and end users to adequately secure applications based on product availability and organizational needs. This document addresses the key management issues associated with currently available cryptographic mechanisms for a select set of applications, including Public Key Infrastructures (PKI), IPsec, TLS, S/MIME, Kerberos, DNSSEC, and Encrypted File Systems (EFS). It provides recommended algorithm suites, key sizes, and security considerations to support organizational decisions about future procurements and the configuration of existing systems.\n\nThis guidance has been developed by NIST to further its statutory responsibilities under the Federal Information Security Management Act (FISMA) for developing information security standards and guidelines for Federal information systems. For each key management infrastructure, protocol, and application addressed, the document provides a description of the system, security and compliance issues, and general recommendations for purchasing decision-makers, system installers, administrators, and end users. While mandatory for Federal agencies, this publication may also be used by non-governmental organizations on a voluntary basis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-57-key-management",
      "nist-sp-800-57-p2-r1",
      "fips-197-advanced-encryption-standard",
      "nist-fips-186-5-dss"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1270-ai-bias-2022",
    "title": "Towards a Standard for Identifying and Managing Bias in Artificial Intelligence",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This NIST Special Publication provides a foundational framework for identifying and managing bias in artificial intelligence systems throughout the AI lifecycle. It applies to developers, deployers, and evaluators of AI systems seeking to improve trustworthiness and mitigate harmful impacts from bias, as outlined in SP 1270.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-100-4-redteam",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-sp-1270-managing-ai-bias",
    "title": "Towards a Standard for Identifying and Managing Bias in Artificial Intelligence",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2022-03-24",
    "bluf": "This special publication describes the challenges of bias in artificial intelligence and provides examples of how and why it can erode public trust. It identifies three categories of bias in AI-systemic, statistical, and human-and describes how and where they contribute to harms. The document also describes three broad challenges for mitigating bias related to datasets, testing and evaluation, and human factors, and introduces preliminary guidance for addressing them. While many organizations seek to utilize information in a responsible manner, biases remain endemic across technology processes and can lead to harmful impacts regardless of intent. These harmful outcomes, even if inadvertent, create significant challenges for cultivating public trust in AI. Successfully meeting this challenge requires taking all forms of bias into account, expanding the perspective beyond the machine learning pipeline to a broader socio-technical view.\n\nThe intended audience for this document includes individuals and groups who are responsible for designing, developing, deploying, evaluating, and governing AI systems. The core obligation is to provide a roadmap for developing detailed socio-technical guidance for identifying and managing AI bias. NIST intends to develop methods for increasing assurance, governance, and practice improvements for identifying, understanding, measuring, managing, and reducing bias. The guidance is voluntary and intended to be flexible and applicable across contexts, regardless of industry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1270-towards-explainable-ai",
    "title": "NISTIR 8312 Four Principles of Explainable Artificial Intelligence - Explanation, Meaningful, Explanation Accuracy and Knowledge Limits for AI Systems",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-07-03",
    "bluf": "NISTIR 8312 (Four Principles of Explainable Artificial Intelligence, September 2021) defines the four core principles of explainable AI (XAI) for developers, evaluators, and policymakers: Explanation, Meaningful, Explanation Accuracy, and Knowledge Limits (Section 2). It also covers purposes and styles of explanations, explainable AI algorithms including self-interpretable models and post-hoc explanations, and methods for evaluating explainable AI, to guide the development of trustworthy and transparent AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nistir-8312-explainable-ai-principles",
      "nist-ai-rmf-1-0",
      "nist-sp-1270-managing-ai-bias",
      "nist-language-of-trustworthy-ai",
      "iso-42001-transparency"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-1800-1-securing-ehr-mobile",
    "title": "NIST SPECIAL PUBLICATION 1800-1 Securing Electronic Health Records on Mobile Devices",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2018-07-01",
    "bluf": "This NIST Cybersecurity Practice Guide provides a modular, open, end-to-end reference design demonstrating how healthcare organizations can more securely share patient information among caregivers using mobile devices. It shows how security engineers and IT professionals, using commercially available and open-source tools consistent with cybersecurity standards, can help healthcare providers better protect electronic health records (EHRs). The guidance applies to healthcare organizations of varying sizes and IT sophistication that use mobile devices to store, process, and transmit patient information. When this information is stolen, made public, or altered, organizations can face penalties, lose consumer trust, and compromise patient care and safety.\n\nThe core obligation is for organizations to implement safeguards to ensure the security of patient information when practitioners use mobile devices with an EHR system. This is achieved through a layered security strategy addressing key risks such as lost or stolen devices, deliberate misuse by users, and inadequate privilege management. The guide maps security characteristics like access control, device integrity, and transmission security to standards and best practices from the NIST Cybersecurity Framework and the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. It recommends a continuous risk management process as a starting point for adopting the proposed solutions to account for the dynamic nature of business processes, technologies, and the threat landscape.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-breach-notification",
      "nist-cybersecurity-framework-2-0",
      "nist-mobile-device-security-enterprise",
      "nist-sp-800-30-risk-assessment",
      "nist-sp-800-53-r5",
      "nist-sp-800-63b-authentication"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-1800-10-ics-integrity",
    "title": "Protecting Information and System Integrity in Industrial Control System Environments: Cybersecurity for the Manufacturing Sector",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-03-31",
    "bluf": "Many manufacturing organizations rely on industrial control systems (ICS) to monitor and control their machinery, production lines, and other physical processes that produce goods. As OT and IT systems become increasingly interconnected, manufacturers have become a major target of more widespread and sophisticated cybersecurity attacks, which can disrupt these processes and cause damage to equipment and/or injuries to workers. To address these challenges, this guide demonstrates how manufacturing organizations can protect the integrity of their data from destructive malware, insider threats, and unauthorized software within manufacturing environments that rely on ICS.\n\nThe solutions implement standard cybersecurity capabilities such as behavioral anomaly detection (BAD), application allowlisting (AAL), file integrity-checking, change control management, and user authentication and authorization. An organization interested in protecting the integrity of a manufacturing system and information should first conduct a risk assessment to determine the appropriate security capabilities required. This guide provides example implementations using standards-based, commercially available products to detect and prevent unauthorized software installation, protect ICS networks from potentially harmful applications, determine changes made to a network, detect unauthorized use of systems, continuously monitor network traffic, and leverage anti-malware tools.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-10-industrial-control-ot-security",
    "title": "NIST SP 1800-10 - Protecting Information and System Integrity in Industrial Control System Environments: Cybersecurity for the Manufacturing Sector",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This publication provides a reference architecture and implementation guidance for securing industrial control systems (ICS) in the manufacturing sector by applying cybersecurity capabilities such as behavioral anomaly detection, application allowlisting, and file integrity checking. It applies to organizations seeking to protect system and information integrity from destructive malware, insider threats, and unauthorized software modifications, as outlined in the document's core solution design and testing methodology.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-4-2-component-security-2019",
      "nist-sp-800-121r2-bluetooth-security",
      "isa-99-iec-62443-industrial-security-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-sp-1800-11-data-integrity",
    "title": "NIST SPECIAL PUBLICATION 1800-11 Data Integrity Recovering from Ransomware and Other Destructive Events",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-09-01",
    "bluf": "Destructive malware, ransomware, malicious insider activity, and even honest mistakes all set the stage for why organizations need to quickly recover from an event that alters or destroys data. Businesses must be confident that recovered data is accurate and safe. When data integrity events occur, organizations must be able to recover quickly from the events and trust that the recovered data is accurate, complete, and free of malware. This NIST Cybersecurity Practice Guide demonstrates how organizations can develop and implement appropriate actions following a detected cybersecurity event, encouraging effective monitoring and detection of data corruption in commodity components, as well as custom applications and data composed of open-source and commercially available components.\n\nThe guide assists organizations of all types and sizes in developing a strategy for recovering from a cybersecurity event to facilitate a smoother recovery, maintain operations, and ensure the integrity and availability of data critical to supporting business operations. The goals are to help organizations confidently restore data to its last known good configuration, identify the correct backup version free of malicious code, identify altered data as well as the date and time of alteration, determine the identity of those who alter data, identify other coinciding events, and determine the impact of the data alteration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-34-r1",
      "nist-sp-800-61r2-incident-handling",
      "nist-sp-1800-25-data-integrity",
      "data-integrity-detecting-responding-ransomware",
      "nist-sp-800-184-event-recovery",
      "cisa-ms-isac-ransomware-guide"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-12-derived-piv",
    "title": "Derived Personal Identity Verification (PIV) Credentials",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-08-31",
    "bluf": "Access to federal information systems relies on strong authentication of the user with a Personal Identity Verification (PIV) Card, a smart card containing identifying information. However, access to information systems is increasingly from mobile phones and tablets that lack integrated smart card readers, forcing organizations to have separate authentication processes for these devices. Derived PIV Credentials (DPCs) address this challenge by leveraging the identity proofing and vetting results of current and valid credentials used in PIV Cards to issue credentials that are securely stored on devices without PIV Card readers. This enables stronger authentication to federal facilities, information systems, and applications from mobile devices.\n\nIn accordance with Homeland Security Presidential Directive 12, the PIV standard was created to enhance national security. With the federal government’s increased reliance on mobile computing devices that cannot accommodate PIV Card readers, the mandate to use PIV has created the need to derive credentials for use in mobile devices in a manner that enforces the same security policies established for the life-cycle of credentials in a PIV Card. This NIST Cybersecurity Practice Guide demonstrates how organizations can provide multifactor authentication for users to access PIV-enabled websites from mobile devices that lack PIV Card readers, covering the issuance, maintenance, and termination of the DPC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-1800-13-mobile-sso",
    "title": "Mobile Application Single Sign-On: Improving Authentication for Public Safety First Responders",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2021-08-31",
    "bluf": "On-demand access to public safety data is critical to ensuring that public safety and first responders (PSFRs) can protect life and property during an emergency. This information, often accessed via mobile devices, includes sensitive data requiring robust authentication. In collaboration with industry stakeholders, the National Cybersecurity Center of Excellence (NCCoE) at NIST developed this practice guide to help PSFR personnel efficiently and securely gain access to mission data. The guide describes a reference design for implementing standards-based technologies, including single sign-on (SSO) to reduce the number of credentials managed, identity federation to authenticate personnel across organizational boundaries, and multifactor authentication (MFA) to provide a high level of assurance.\n\nThis NIST Cybersecurity Practice Guide explains how organizations can implement these technologies to enhance public safety mission capabilities using standards-based, commercially available, or open-source products. The described architecture leverages protocols such as OAuth 2.0 for Native Apps (RFC 8252), FIDO Universal Authentication Framework (UAF) and Universal Second Factor (U2F), Security Assertion Markup Language (SAML) 2.0, and OpenID Connect (OIDC) 1.0. The goal is to facilitate interoperability among diverse mobile platforms, applications, and identity providers, allowing a PSFR to authenticate once at the beginning of a shift and gain cross-jurisdictional access to multiple applications, thereby reducing the time needed for authentication while improving security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-63b-digital-identity",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-1800-14-bgp-rov",
    "title": "NIST SPECIAL PUBLICATION 1800-14 Protecting the Integrity of Internet Routing: Border Gateway Protocol (BGP) Route Origin Validation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-06-01",
    "bluf": "This NIST Cybersecurity Practice Guide demonstrates how networks can protect Border Gateway Protocol (BGP) routes from vulnerability to route hijacks by using available security protocols, products, and tools to perform BGP route origin validation (ROV). BGP, the protocol used by internet service providers (ISPs) and enterprises to exchange route information, was not designed with security in mind, making it vulnerable to route hijacks which can deny access to services, misdeliver traffic, and cause instability. The guide addresses the challenge of using existing protocols to improve the security of inter-domain routing traffic exchange in a manner that mitigates accidental and malicious attacks associated with route hijacking. A route prefix hijack occurs when an autonomous system (AS) accidentally or maliciously originates a BGP update for a route prefix that it is not authorized to originate.\n\nThe solution presented is a proof-of-concept implementation of BGP ROV using the Resource Public Key Infrastructure (RPKI). This practice guide is for any organization providing or using internet routing services, including ISPs, enterprises, address holders, and network operators. The core obligations involve two main activities: first, for address holders to protect their own internet addresses from route hijacking by registering them with trusted sources through the creation of Route Origin Authorizations (ROAs); and second, for network operators to perform BGP ROV on received BGP route updates to validate whether the entity that originated the route is in fact authorized to do so. The guide provides detailed deployment guidance, identifies implementation issues, and generates best practices for both hosted and delegated RPKI models.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bgp-security-ddos-mitigation",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-15-iot-mud",
    "title": "NIST SPECIAL PUBLICATION 1800-15 Securing Small-Business and Home Internet of Things (IoT) Devices: Mitigating Network-Based Attacks Using Manufacturer Usage Description (MUD)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2021-05-31",
    "bluf": "The rapid growth of Internet of Things (IoT) devices is a cause for concern because they are tempting targets for attackers, often having minimal security, unpatched software flaws, and constraints that make them challenging to secure. The consequences can be catastrophic, as malicious actors can detect and attack an IoT device within minutes, exploiting weaknesses at scale to create botnets for large-scale distributed denial of service (DDoS) attacks. To address this, the National Cybersecurity Center of Excellence (NCCoE) demonstrated the use of the Manufacturer Usage Description (MUD) standard to reduce both the vulnerability of IoT devices and the potential for harm from compromised devices.\n\nThe core obligation is for networks to use MUD to automatically permit each IoT device to send and receive only the traffic it requires to perform its intended function, and to prohibit all other communication with the device. This approach applies to IoT device manufacturers, network equipment developers, service providers, and organizations relying on the internet. By prohibiting unauthorized traffic, this solution reduces the opportunity for a device to be compromised and limits the ability of an already-compromised device to participate in network-based attacks. This guide details the MUD-based reference solution to help stakeholders protect internet availability, prevent reputational damage, and secure internal networks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-183-networks-of-things",
      "nistir-8228-iot-cybersecurity-risks",
      "nist-sp-800-213-iot-guidance",
      "nist-800-53-sc7",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-1800-16-tls-certificate-management",
    "title": "NIST SPECIAL PUBLICATION 1800-16 Securing Web Transactions TLS Server Certificate Management",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-06-01",
    "bluf": "Transport Layer Security (TLS) server certificates are critical to the security of both internet-facing and private web services. Many organizations, especially large- or medium-scale enterprises with thousands of certificates, lack a formal TLS certificate management program and do not have the ability to centrally monitor and manage them. Instead, certificate management tends to be spread across different groups, leading to a lack of central oversight. This puts the organization at risk because once certificates are deployed, they require regular monitoring and maintenance. Organizations that improperly manage their certificates risk system outages and security breaches, which can result in revenue loss, harm to reputation, and exposure of confidential data to attackers.\n\nThis NIST Cybersecurity Practice Guide is designed to help large and medium enterprises better manage TLS server certificates by employing a formal management program. The core recommendations include defining operational and security policies with clear roles and responsibilities; establishing comprehensive certificate inventories and ownership tracking; conducting continuous monitoring of certificates’ operational and security status; automating certificate management to minimize human error; and enabling rapid migration to new certificates and keys when certificate authorities or cryptographic mechanisms are compromised or found to be vulnerable. Executive leadership should establish these formal programs and set organization-specific implementation milestones to address certificate-based risks and challenges.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-csf-2",
      "nist-sp-800-52r2-tls-guidelines",
      "nist-sp-800-57-key-management",
      "nist-sp-800-63b-authentication"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-17-mfa-ecommerce",
    "title": "NIST SPECIAL PUBLICATION 1800-17 Multifactor Authentication for E-Commerce: Risk-Based, FIDO Universal Second Factor Implementations for Purchasers",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-07-01",
    "bluf": "This NIST Cybersecurity Practice Guide demonstrates how online retailers can implement multifactor authentication (MFA) to help reduce electronic commerce (e-commerce) fraud. MFA is a security enhancement that allows a user to present several pieces of evidence when logging into an account, which must come from at least two different categories: something you know (e.g., password), something you have (e.g., smart card), and something you are (e.g., fingerprint). The guide documents a system in which risk determines when to trigger MFA challenges to existing customers. As in-store security advances have pushed malicious actors to perform payment card fraud online, this guide describes implementing stronger user-authentication techniques to reduce this risk.\n\nThe project’s example implementations analyze risk to prompt returning purchasers with additional authentication requests when risk elements are exceeded during the online shopping session. Risk elements may include contextual data related to the returning purchaser and the current shopping transaction. The example implementations will prompt a returning purchaser to present another distinct authentication factor-something the purchaser has-in addition to the username and password, when automated risk assessments indicate an increased likelihood of fraudulent activity. The MFA capabilities are based upon the Fast IDentity Online (FIDO) Universal Second Factor (U2F) authentication specification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-63b-authentication",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-1800-19-trusted-cloud",
    "title": "Trusted Cloud: Security Practice Guide for VMware Hybrid Cloud Infrastructure as a Service (IaaS) Environments",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-04-01",
    "bluf": "This National Institute of Standards and Technology (NIST) Cybersecurity Practice Guide demonstrates how organizations can implement trusted compute pools to safeguard the security and privacy of their applications and data being run within a cloud or being transferred between a private cloud and a hybrid or public cloud. The guide addresses core concerns about cloud technology adoption, such as protecting information and virtual assets in the cloud and having sufficient visibility to conduct oversight and ensure compliance with applicable laws and business practices. The intended audience includes organizations in regulated sectors like finance and healthcare, as well as cloud computing practitioners, system integrators, and IT and security managers.\n\nThe core objective is to develop a trusted cloud solution demonstrating how trusted compute pools leveraging hardware roots of trust can provide necessary security capabilities. These capabilities provide assurance that cloud workloads are running on trusted hardware and in a trusted geolocation or logical boundary, and improve the protections for data in the workloads and data flows between workloads. This enables organizations to monitor, track, apply, and enforce security and privacy policies on cloud workloads in a consistent, repeatable, and automated way, ensuring consistent compliance with legal and business requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-144-cloud-computing",
      "nist-sp-800-63b-authentication",
      "nist-sp-800-57-key-management",
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-21-cope",
    "title": "NIST SPECIAL PUBLICATION 1800-21 Mobile Device Security: Corporate-Owned Personally-Enabled (COPE)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-09-01",
    "bluf": "This NIST Cybersecurity Practice Guide demonstrates how organizations can use standards-based, commercially available products to help meet their Corporate-Owned Personally-Enabled (COPE) mobile device security and privacy needs. COPE devices are owned by the enterprise, issued to the employee, and allow both parties to install applications onto the device. While mobile devices can increase efficiency and productivity, they can also leave sensitive data vulnerable, and securing them is essential to continuity of business operations. Organizations are challenged with ensuring these devices process, modify, and store sensitive data securely, as they bring unique threats to the enterprise and should be managed in a manner distinct from desktop platforms.\n\nTo address this challenge, this guide provides a reference architecture and a detailed example solution demonstrating how various mobile security technologies can be integrated within an enterprise’s network. The core capabilities sought include enhanced protection of data on the mobile device, centralized management systems to deploy policies, evaluation of mobile application security, prevention of eavesdropping on device data, configuration of privacy settings to protect end-user data, and protection from phishing attempts. The foundation of the architecture is based on federal U.S. guidance, including NIST 800 series publications, to help ensure the confidentiality, integrity, and availability of enterprise data on mobile systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-sp-1800-22-byod",
    "title": "NIST SPECIAL PUBLICATION 1800-22 Mobile Device Security: Bring Your Own Device (BYOD)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-09-01",
    "bluf": "This National Institute of Standards and Technology (NIST) Cybersecurity Practice Guide provides an example solution demonstrating how organizations can use standards-based, commercially available products to enhance security and privacy for Bring Your Own Device (BYOD) deployments on Android and Apple phones and tablets. Allowing employees to use personal mobile devices for work introduces unique challenges, including supporting a diverse ecosystem of devices, reducing risks to enterprise data from loss or malware, and protecting employee privacy. An ineffectively secured personal device could expose an organization or employee to data loss or a privacy compromise.\n\nThe guide's example solution leverages technologies such as enterprise mobility management (EMM), mobile threat defense (MTD), application vetting, and virtual private network (VPN) services. The core obligations focus on detecting and protecting against mobile malware and phishing, enforcing passcode usage, separating organizational and personal data, enabling selective wipe of corporate data from lost or stolen devices, and protecting data in transit via encryption. The solution aims to help organizations benefit from BYOD's flexibility while mitigating critical security and privacy challenges, providing step-by-step implementation guidance for enterprises to enhance their data protection posture.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "guide-telework-remote-access-byod",
      "nist-mobile-device-security-enterprise",
      "nist-sp-1800-21-cope",
      "nist-sp-800-114-r1-byod-security",
      "nist-sp-800-163r1-mobile-app-vetting"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-23-energy-asset-management",
    "title": "Energy Sector Asset Management For Electric Utilities, Oil & Gas Industry",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-05-01",
    "bluf": "As critical infrastructures, the incapacitation or destruction of assets in the energy sector, including electric utilities and the oil and gas industry, could have serious negative effects on the economy, public health, and safety. A primary challenge for these organizations is maintaining an updated operational technology (OT) asset inventory, as it is difficult to protect what is not seen or known. Without an effective asset management solution, organizations are unnecessarily exposed to cybersecurity risks from malicious actors targeting vulnerabilities within interconnected industrial control systems (ICS). Many energy organizations rely on manual processes and static, point-in-time snapshots for asset inventories, which makes it challenging to quickly identify and respond to potential threats.\n\nThis NIST Cybersecurity Practice Guide provides detailed, practical steps on how energy organizations can identify, control, and monitor their OT assets to reduce the risk of cybersecurity incidents. It demonstrates an example solution for establishing, enhancing, and automating OT asset management by leveraging existing or implementing new capabilities. The core obligation is to establish a comprehensive OT asset management baseline that includes discovering assets, identifying attributes, monitoring for changes, determining asset criticality, and alerting on deviations from expected operations. The goal is to provide an automated inventory that can be viewed in near real time, enabling organizations to strengthen their cybersecurity posture and respond faster to security alerts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-csf-2",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-1800-5-it-asset-management",
      "nist-sp-800-82r3-ot-security",
      "nist-sp-1800-7-electric-utilities",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-24-securing-pacs",
    "title": "NIST SPECIAL PUBLICATION 1800-24 Securing Picture Archiving and Communication System (PACS): Cybersecurity for the Healthcare Sector",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-12-01",
    "bluf": "This guide details how the National Cybersecurity Center of Excellence (NCCoE) at NIST built a laboratory environment to emulate a medical imaging environment, performed a risk assessment, and identified controls from the NIST Cybersecurity Framework to secure a medical imaging ecosystem. The project addresses the cybersecurity challenges of Picture Archiving and Communication Systems (PACS), which centralize medical imaging workflows and serve as authoritative repositories within a highly complex healthcare delivery organization (HDO) environment. This complexity, involving various interconnected systems, diverse users, and potential cloud storage, creates a large attack surface and presents vulnerabilities that could impact patient care and privacy through data loss, ransomware attacks, or unauthorized network access.\n\nThis NIST Cybersecurity Practice Guide demonstrates how organizations can securely configure and deploy PACS using a standards-based, example solution. The architecture features a defense-in-depth approach, including network zoning, microsegmentation, and robust access control mechanisms like multifactor authentication for providers and certificate-based authentication for devices. It also promotes a holistic risk management approach that incorporates medical device asset management and behavioral analytics for near real-time threat detection. The guide is intended to help HDOs implement current cybersecurity standards and best practices to reduce their cybersecurity risk, protect patient privacy, and improve resilience, while maintaining the performance and usability of the PACS ecosystem.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-1800-8-infusion-pumps",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-25-data-integrity",
    "title": "NIST SPECIAL PUBLICATION 1800-25 Data Integrity: Identifying and Protecting Assets Against Ransomware and Other Destructive Events",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-12-01",
    "bluf": "This NIST Cybersecurity Practice Guide demonstrates how organizations can develop and implement appropriate actions before a detected data integrity cybersecurity event. The guide focuses on data integrity: the property that data has not been altered in an unauthorized manner, covering data in storage, during processing, and while in transit. Destructive malware, ransomware, malicious insider activity, and even honest mistakes all set the stage for why organizations need to properly identify and protect against events that impact data integrity. Attacks against an organization’s data can compromise emails, employee records, financial records, and customer information, impacting business operations, revenue, and reputation.\n\nThe National Cybersecurity Center of Excellence (NCCoE) built a laboratory environment to explore methods to effectively identify and protect against data integrity attacks. The solution incorporates multiple systems working in concert to identify and protect assets by isolating opportunities that would allow for cybersecurity events to occur and implementing strategies to remediate them. The approach is aligned with the NIST Cybersecurity Framework functions of Identify (develop an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities) and Protect (develop and implement appropriate safeguards to ensure delivery of critical services). Key capabilities sought include inventory, policy enforcement, logging, backups, vulnerability management, secure storage, and integrity monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cyber-nist-csf-2",
      "data-integrity-detecting-responding-ransomware",
      "cisa-ms-isac-ransomware-guide",
      "nist-ir-8374-ransomware-risk-management",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-sp-1800-28-data-confidentiality",
    "title": "NIST SPECIAL PUBLICATION 1800-28 Data Confidentiality: Identifying and Protecting Assets Against Data Breaches",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-02-01",
    "bluf": "This guide helps organizations implement strategies to prevent data confidentiality attacks by demonstrating how to develop and implement appropriate actions to identify and protect data against a confidentiality cybersecurity event. An organization must protect its information from unauthorized access and disclosure, as data breaches can have far-reaching operational, financial, and reputational impacts. In the event of a breach, data confidentiality can be compromised via unauthorized exfiltration, leaking, or spills of data. It is essential for an organization to identify and protect assets to prevent breaches and, should a breach occur, to detect it and execute a response and recovery plan.\n\nThis practice guide focuses on data confidentiality, defined as the property that data has not been disclosed in an unauthorized fashion, concerning data in storage, during processing, and while in transit. It applies these principles through the lens of the NIST Cybersecurity Framework Functions of Identify and Protect. It informs organizations on how to identify and protect assets against a data confidentiality attack, manage associated risks, and implement appropriate safeguards. The guidance assists organizations in inventorying data storage and flows, protecting against confidentiality attacks on hosts and networks, protecting data at rest, in transit, and in use, configuring logging, and implementing access controls and authentication mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-160-v1r1"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-29-data-breaches",
    "title": "NIST SPECIAL PUBLICATION 1800-29 Data Confidentiality: Detect, Respond to, and Recover from Data Breaches",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-02-01",
    "bluf": "An organization must protect its information from unauthorized access and disclosure, as data breaches can have far-reaching operational, financial, and reputational impacts. In the event of a data breach, data confidentiality can be compromised via unauthorized exfiltration, leaking, or spills of data to unauthorized parties. It is essential for an organization to not only identify and protect assets to prevent breaches, but also to be able to detect an ongoing breach and execute a response and recovery plan that leverages security technology and controls.\n\nThis NIST Cybersecurity Practice Guide, developed by the National Cybersecurity Center of Excellence (NCCoE), demonstrates how organizations can develop and implement appropriate actions to detect, respond to, and recover from a data confidentiality cybersecurity event. The guide, which applies principles through the lens of the NIST Cybersecurity Framework, helps organizations to monitor user and data activity, detect unauthorized data flows and access, analyze and mitigate the impact of breaches, contain their effects, and facilitate recovery by providing detailed information on the scope and severity of the incident.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-1800-28-data-confidentiality"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-32-securing-ders",
    "title": "Securing Distributed Energy Resources: An Example of Industrial Internet of Things Cybersecurity",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-01",
    "bluf": "This practice guide from the National Cybersecurity Center of Excellence (NCCoE) applies standards, best practices, and commercially available technology to protect the digital communication, data, and control of cyber-physical grid-edge devices. It addresses the challenge that the growing use of small-scale distributed energy resources (DERs), which often rely on Industrial Internet of Things (IIoT) technologies, represents a growing cyber threat to the distribution grid. A distribution utility may need to remotely communicate with thousands of DERs, and many companies are not equipped to offer secure access or to monitor and trust the rapidly growing amount of data. Any attack that can deny, disrupt, or tamper with DER communications could prevent a utility from performing necessary control actions and could diminish grid resiliency.\n\nThe core obligation demonstrated is a risk-based approach for connecting and managing DERs, built on National Institute of Standards and Technology (NIST) and industry standards. The guide shows how to monitor and detect unusual behavior of connected IIoT devices, build a comprehensive audit trail of trusted IIoT data flows, protect data and communications traffic of grid-edge devices, and support secure edge-to-cloud data flows. It provides an example solution for authenticating systems, ensuring data integrity, detecting malware, maintaining an immutable command register, and implementing behavioral monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-82r3-ot-security",
      "nist-ir-7628-smart-grid-cybersecurity",
      "nist-sp-1800-23-energy-asset-management",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "nistir-8228-iot-cybersecurity-risks"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-35-zero-trust-architecture",
    "title": "NIST SPECIAL PUBLICATION 1800-35 Implementing a Zero Trust Architecture: High-Level Document",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2025-06-01",
    "bluf": "A zero trust architecture (ZTA) is an enterprise cybersecurity architecture based on zero trust principles, such as those outlined in NIST Special Publication (SP) 800-207, designed to prevent data breaches and limit internal lateral movement. This guide is intended to help organizations gradually evolve existing environments and technologies into a ZTA over time by providing practical implementation details. The primary audience includes organizations looking to implement ZTA, assuming an existing level of cybersecurity knowledge and capabilities. The core obligation is to enable secure authorized access to enterprise resources distributed across on-premises and multiple cloud environments, while enabling a hybrid workforce and partners to access resources from anywhere, at any time, from any device. This is achieved through a risk-based approach to cybersecurity-continuously evaluating and verifying conditions and requests to decide which access requests should be permitted, then ensuring that each access is properly safeguarded commensurate with risk. The guide documents 19 example ZTA implementations built with 24 technology collaborators, providing models that organizations can emulate and best practices for leveraging existing technology infrastructure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-207"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-38-pqc-migration-practice-guide",
    "title": "NIST SP 1800-38 (NCCoE Preliminary Draft) Migration to Post-Quantum Cryptography - Cryptographic Discovery Method",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-19",
    "bluf": "NIST Special Publication 1800-38, Migration to Post-Quantum Cryptography: Preparation for Considering the Implementation and Adoption of Quantum Safe Cryptography, is a National Cybersecurity Center of Excellence practice guide issued as a PRELIMINARY DRAFT. Volume A, the Executive Summary, was published in April 2023, and Volume B, Quantum Readiness: Cryptographic Discovery, in December 2023 with a public comment period running December 19, 2023 through February 25, 2024. Every volume carries the PRELIMINARY DRAFT marking on each page and Volume A states expressly that as the project progresses this preliminary draft will be updated and additional volumes will also be released for comment. This node records a draft method, not settled guidance, and must not be cited as a final NIST publication.\n\nThe distinctive contribution is a cryptographic discovery architecture rather than a migration strategy. Volume B scopes discovery to public key asymmetric signature and key establishment schemes, and states that symmetric cryptographic primitives such as block ciphers and hash functions are not as drastically impacted by the advent of a cryptographically relevant quantum computer and are not in scope for this project. The algorithms treated as vulnerable in the demonstration are Elliptic Curve Diffie Hellman key exchange, Menezes Qu Vanstone key exchange, the Elliptic Curve Digital Signature Algorithm, Diffie Hellman key exchange, the RSA encryption algorithm, the RSA signature algorithm, the Digital Signature Algorithm and the Edwards-curve Digital Signature Algorithm.\n\nDiscovery is demonstrated across three surfaces. In the code development pipeline, an analyst extracts data from an existing codebase to create a queryable database and executes a query that detects the usage of vulnerable algorithms, producing output in SARIF format, with automated variants that run the query inside an on-premises continuous integration system during the build and inside a cloud-based repository on each pull request. On operational systems and applications, filesystem scanning sensors detect quantum-vulnerable algorithms in software, deployed to end-user devices or servers, with scanning also performed on binaries to discover algorithms where there might not be source code, as for example in third-party applications. On transport protocols and network services, both real-time scanning and passive discovery from historical packet captures are used.\n\nThe most transferable element is the normalisation problem the draft identifies and addresses. Reports produced by different discovery platforms do not use a common format, so that one platform may identify a host as host.example.com:443 while another omits the port number, and Section 4.1.4 accordingly defines a preliminary version of a normalization scheme across all discovery platforms that would allow an organization to make a risk decision. It does not define a schema but defines descriptive data elements and how they can be obtained from passive network observations, active network scans, endpoint monitoring or configuration information, and how those elements can be compared, with representation formats fixed to IANA service names, TLS ALPN identifiers and Common Platform Enumeration 2.3 strings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cisa-nsa-nist-quantum-readiness-factsheet",
      "nist-cswp-39-considerations-for-achieving-crypto-agility-2025",
      "nist-ir-8547-pqc-transition",
      "etsi-tr-103-619-quantum-safe-migration-strategies"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-sp-1800-4-mobile-device-security",
    "title": "NIST SPECIAL PUBLICATION 1800-4 Mobile Device Security Cloud and Hybrid Builds",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-02-28",
    "bluf": "This National Institute of Standards and Technology (NIST) Cybersecurity Practice Guide addresses the challenge of securely deploying and managing mobile devices in an enterprise. In many organizations, mobile devices are adopted on an ad hoc basis, possibly without the appropriate policies and infrastructure to manage and secure the enterprise data they process and store. This guide demonstrates how commercially available technologies can enable secure access to an organization’s sensitive email, contacts, and calendar information from users’ mobile devices. The solutions and architectures presented are built upon standards-based, commercially available products and can be used by any organization deploying mobile devices in the enterprise. This project contains two distinct builds: a cloud build that uses cloud-based data storage and management services, and a hybrid build that achieves the same functionality but hosts a portion of the data and services within an enterprise’s own infrastructure.\n\nThe guide demonstrates how security can be supported throughout the mobile device life cycle. This includes how to configure a device to be trusted by the organization, how to maintain adequate separation between the organization’s data and the employee’s personal data, and how to handle de-provisioning a mobile device that should no longer have enterprise access (e.g., device lost or stolen, employee leaves the company). The guide identifies the security characteristics needed to reduce the risks from mobile devices storing or accessing sensitive enterprise data, maps these characteristics to standards and best practices, and describes detailed example solutions for implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-5-it-asset-management",
    "title": "NIST SPECIAL PUBLICATION 1800-5 IT Asset Management",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2018-09-01",
    "bluf": "This NIST Cybersecurity Practice Guide offers a proof-of-concept solution for financial services companies to more securely and efficiently monitor and manage their information technology (IT) assets. The guide details an example solution using open source and commercially available products that can be included alongside current products in an existing infrastructure. It is designed for those responsible for tracking assets, configuration management, and cybersecurity, including system administrators, IT managers, and security managers. The core objective is to provide a centralized, comprehensive view of networked hardware and software across an enterprise.\n\nAn effective IT asset management (ITAM) solution, as described, is foundational to an effective cybersecurity strategy. It enables organizations to know and control which assets are connected to the network, automatically detect and alert on unauthorized devices, enforce software restriction policies, and audit and monitor asset changes. The solution aims to span traditional physical asset tracking, IT asset information, physical security, and vulnerability and compliance information, allowing users to query one system for a complete IT asset portfolio view. This enhanced visibility leads to better asset utilization, reduced vulnerabilities, faster response times to security alerts, and increased cybersecurity resilience by allowing security analysts to focus on the most valuable or critical assets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-csf-2",
      "nist-sp-800-53-r5",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-6-email-security",
    "title": "Domain Name System-Based Electronic Mail Security",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2018-01-01",
    "bluf": "This guide details proof-of-concept security platforms that demonstrate trustworthy email exchanges across organizational boundaries for both public and private-sector business operations. The project's goals include the authentication of mail transfer agents, signing and encryption of email, and binding cryptographic key certificates to servers. The Domain Name System Security Extension (DNSSEC) protocol is used to authenticate server addresses and certificates for Transport Layer Security (TLS) to DNS names, while DNS-Based Authentication of Named Entities (DANE) securely associates domain names with cryptographic certificates. The platforms enable end-to-end security through Secure/Multipurpose Internet Mail Extensions (S/MIME).\n\nThis NIST Cybersecurity Practice Guide provides a standards-based reference design for any organization deploying email services to implement certificate-based cryptographic key management and DNS Security Extensions. The solutions and architectures presented are built upon standards-based, commercially available products. The guide aims to help organizations reduce risks so that employees can exchange information via email with significantly reduced risk of disclosure or compromise by enabling the use of existing security protocols more efficiently and with minimal impact to email service performance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-177-trustworthy-email",
      "nist-sp-800-52r2-tls-guidelines",
      "nist-sp-800-57-key-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-1800-7-electric-utilities",
    "title": "NIST SPECIAL PUBLICATION 1800-7 Situational Awareness For Electric Utilities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-08-31",
    "bluf": "Through direct dialogue between NCCoE staff and members of the energy sector it became clear that energy companies need to create and maintain a high level of visibility into their operating environments to ensure the security of their operational resources (operational technology [OT]), including industrial control systems (ICS), buildings, and plant equipment. However, energy companies, as well as all other utilities with similar infrastructure and situational awareness challenges, also need insight into their corporate or information technology (IT) systems and physical access control systems (PACS). The convergence of data across these three often self-contained silos (OT, IT, and PACS) can better protect power generation, transmission, and distribution. Real-time or near real-time situational awareness is a key element in ensuring this visibility across all resources. Situational awareness, as defined in this use case, is the ability to comprehensively identify and correlate anomalous conditions pertaining to ICS, IT resources, and access to buildings, facilities, and other business mission-essential resources. For energy companies, having mechanisms to capture, transmit, view, analyze, and store real-time or near-real-time data from ICS and related networking equipment provides energy companies with the information needed to deter, identify, respond to, and mitigate cyber attacks against their assets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-1800-8-infusion-pumps",
    "title": "NIST SPECIAL PUBLICATION 1800-8: Securing Wireless Infusion Pumps in Healthcare Delivery Organizations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2018-08-31",
    "bluf": "Medical devices, such as infusion pumps, were once standalone instruments that interacted only with the patient or medical provider. With technological improvements, these devices now connect wirelessly to a variety of systems within a healthcare delivery organization (HDO), contributing to the Internet of Medical Things (IoMT). As IoMT grows, cybersecurity risks have risen. The wireless infusion pump ecosystem faces threats including unauthorized access to protected health information (PHI), changes to prescribed drug doses, and interference with a pump’s function. This can expose a healthcare provider’s enterprise to serious risks such as access by malicious actors, loss of enterprise information, a breach of PHI, and disruption of healthcare services.\n\nThis NIST Special Publication provides cybersecurity guidance for HDOs and medical device manufacturers who share responsibility for reducing these risks. It details how organizations can use standards-based, commercially available cybersecurity technologies to better protect the infusion pump ecosystem. The core obligation involves performing a questionnaire-based risk assessment and then applying security controls to create a “defense-in-depth” solution. This guidance shows biomedical, networking, and cybersecurity engineers how to securely configure and deploy wireless infusion pumps to reduce cybersecurity risk, manage assets, protect against threats, and mitigate vulnerabilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-82r3-ot-security",
      "nist-cybersecurity-framework-2-0",
      "nistir-8228-iot-cybersecurity-risks",
      "fda-cybersecurity-medical-devices-premarket"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-100-security-handbook",
    "title": "Information Security Handbook: A Guide for Managers",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-10-01",
    "bluf": "This Information Security Handbook provides a broad overview of information security program elements to assist managers in understanding how to establish and implement an information security program. The guidance is intended for agency heads, chief information officers (CIOs), senior agency information security officers (SAISOs), and security managers. The topics are selected based on laws and regulations including the Federal Information Security Management Act (FISMA) of 2002 and Office of Management and Budget (OMB) Circular A-130. The core obligation is for federal agencies to establish a formal information security governance structure to proactively implement appropriate information security controls, support their mission in a cost-effective manner, and manage evolving risks. This governance is defined as the process of establishing and maintaining a framework to provide assurance that information security strategies are aligned with business objectives, consistent with applicable laws, and provide assignment of responsibility to manage risk.\n\nWhile this guideline has been prepared for use by federal agencies, it may also be used by nongovernmental organizations on a voluntary basis. Agencies are expected to tailor this guidance according to their specific security posture and business requirements. The handbook summarizes and augments existing NIST standards and guidance, covering topics such as the System Development Life Cycle, risk management, security planning, incident response, and performance measures. It provides a framework for developing, documenting, and implementing an agency-wide information security program, ensuring protections are commensurate with the risk and magnitude of potential harm.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-200-minimum-security-requirements",
      "fips-199-security-categorization",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-53-r5",
      "nist-sp-800-18-r1",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-sp-800-108r1-key-derivation",
    "title": "Recommendation for Key Derivation Using Pseudorandom Functions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-08-10",
    "bluf": "This Recommendation specifies techniques for the derivation of additional keying material from a secret key, either established through a key-establishment scheme or shared through some other manner, using pseudorandom functions (PRFs): HMAC, CMAC, and KMAC. The key-derivation functions (KDFs) can be used to derive additional keys from an existing cryptographic key that was previously established through an automated key-establishment scheme, generated, and/or previously shared. The key-derivation functions specified provide key expansion functionality, where key derivation is a process that may require randomness extraction and key expansion. This publication defines several families of KDFs that use PRFs, including a counter mode, a feedback mode, and a double-pipeline mode as iteration methods, as well as a non-iterative KDF using KMAC. The key input to a KDF is called a key-derivation key (KDK) and must be a cryptographic key. The output is called derived keying material, which may be segmented into multiple keys for intended cryptographic algorithms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-57-key-management",
      "nist-sp-800-185-sha3-derived-functions",
      "secure-hash-standard-fips-180-4",
      "fips-197-advanced-encryption-standard"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-113-guide-ssl-vpns",
    "title": "Guide to SSL VPNs",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2008-07-01",
    "bluf": "Secure Sockets Layer (SSL) virtual private networks (VPN) provide secure remote access to an organization’s resources. A VPN is a virtual network, built on top of existing physical networks, that can provide a secure communications mechanism for data and other information transmitted between two endpoints. An SSL VPN consists of one or more VPN devices to which users connect using their Web browsers, with the traffic between the browser and the device encrypted with the SSL protocol. SSL VPNs provide remote users with access to Web applications, client/server applications, and connectivity to internal networks, offering versatility and ease of use because they use the SSL protocol included with all standard Web browsers.\nThere are two primary types of SSL VPNs. SSL Portal VPNs allow a user to use a single standard SSL connection to a Web site to securely access multiple network services from a single portal page. SSL Tunnel VPNs allow a user's web browser to securely access multiple network services, including applications and protocols that are not web-based, through a tunnel running under SSL. For Federal agencies, SSL VPNs must be configured to only allow FIPS-compliant cryptographic algorithms, cipher suites, and versions of SSL. Organizations should use a phased approach to SSL VPN planning and implementation, including identifying requirements, designing the solution, testing a prototype, deploying, and managing the solution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-197-advanced-encryption-standard",
      "guide-telework-remote-access-byod",
      "nist-sp-800-41-r1-firewalls",
      "nist-sp-800-52r2-tls-guidelines",
      "nist-sp-800-57-key-management",
      "nist-sp-800-63b-authentication"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-114-r1-byod-security",
    "title": "User’s Guide to Telework and Bring Your Own Device (BYOD) Security",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2016-07-31",
    "bluf": "This publication provides recommendations for securing Bring Your Own Device (BYOD) devices used for telework and remote access, as well as those directly attached to the enterprise’s own networks. It applies to an organization’s employees, contractors, business partners, vendors, and other users who perform work from locations other than the organization’s facilities using devices like desktop and laptop computers, smartphones, and tablets.\n\nThe core obligation is to ensure that telework devices are properly secured to mitigate risks not only to the information the teleworker accesses but also to the organization’s other systems and networks. When a telework device uses remote access, it is essentially a logical extension of the organization’s own network. Therefore, if the telework device is not secured properly, it poses additional risk. Key security recommendations include using security software such as antivirus and personal firewalls, restricting device access through user accounts and passwords, regularly applying updates to operating systems and applications, disabling unneeded networking features, securing home networks, and maintaining the device's security on an ongoing basis. Organizations may limit the types of BYOD devices that can be used and which resources they can access to limit the risk they incur.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "guide-telework-remote-access-byod",
      "nist-sp-800-12r1-intro-infosec",
      "nist-sp-800-41-r1-firewalls",
      "guide-to-storage-encryption-technologies",
      "nist-sp-800-61r2-incident-handling"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-sp-800-115-pen-testing",
    "title": "NIST SP 800-115: Technical Guide to Information Security Testing and Assessment",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This guide provides a comprehensive methodology for conducting information security testing and assessments, including penetration testing. It establishes a four-phase process (Planning, Discovery, Attack, Reporting) as detailed in Section 5, enabling organizations to systematically identify and address vulnerabilities in their systems and networks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "assessing-security-privacy-controls",
      "cis-controls-v8",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-sp-800-115-security-testing",
    "title": "Technical Guide to Information Security Testing and Assessment",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2008-09-01",
    "bluf": "An information security assessment is the process of determining how effectively an entity being assessed (e.g., host, system, network, procedure, person) meets specific security objectives. This document provides a guide to the basic technical aspects of conducting information security assessments, presenting technical testing and examination methods and techniques that an organization might use, and offering insights to assessors on their execution and potential impact. The guidance enables organizations to develop an assessment policy, accurately plan assessments by addressing logistical and legal considerations, safely execute testing, appropriately handle technical data, and conduct analysis and reporting to translate technical findings into risk mitigation actions.\nTo accomplish technical security assessments and ensure they provide maximum value, organizations are recommended to establish an information security assessment policy, implement a repeatable and documented assessment methodology, determine the objectives of each assessment and tailor the approach accordingly, and analyze findings to develop risk mitigation techniques. The guide is intended for use by computer security staff, program managers, system and network administrators, and other technical staff responsible for securing systems and network infrastructures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-92-log-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-121r2-bluetooth-security",
    "title": "Guide to Bluetooth Security",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-01-19",
    "bluf": "Bluetooth wireless technology is an open standard for short-range radio frequency communication used primarily to establish wireless personal area networks (WPANs), and has been integrated into many types of business and consumer devices. This publication provides information on the security capabilities of Bluetooth and gives recommendations to organizations employing Bluetooth wireless technologies on securing them effectively. The Bluetooth versions within the scope of this publication are versions 1.1 through 4.2.\n\nBluetooth wireless technology and associated devices are susceptible to general wireless networking threats, such as denial of service (DoS) attacks, eavesdropping, man-in-the-middle (MITM) attacks, message modification, and resource misappropriation. To improve security, organizations should use the strongest Bluetooth security mode available for their devices. For devices version 4.1 and later, Security Mode 4, Level 4 is recommended for Basic Rate/Enhanced Data Rate (BR/EDR) as it requires Secure Connections. For the low energy feature, Security Mode 1, Level 4 is the strongest. Organizations should address Bluetooth in their security policies, change default settings, and ensure users are aware of their responsibilities, such as performing pairing in physically secure areas and turning off devices when not in use.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-97-ieee-802-11i"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-123-server-security",
    "title": "Special Publication 800-123 Guide to General Server Security",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2008-07-01",
    "bluf": "This publication addresses the general security issues of typical servers, assisting organizations in installing, configuring, and maintaining them securely. Servers are frequently targeted by attackers due to the value of their data and services, which can include personally identifiable information. Common threats include exploitation of software bugs, denial of service attacks, unauthorized access to sensitive information, and using a compromised server to attack other entities. This document provides guidance for securing the server's underlying operating system, the server software itself, and maintaining a secure configuration through ongoing practices.\n\nThe core obligations involve careful security planning prior to deployment, including addressing human resource requirements. Organizations must secure the server operating system by patching, removing unnecessary services, configuring user authentication, and performing security testing. Similarly, server applications must be securely deployed, configured, and managed to meet organizational security requirements. Maintaining server security is an ongoing process that requires constant effort and vigilance, involving actions such as configuring and analyzing log files, backing up critical information, establishing recovery procedures, and periodically testing security controls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-34-contingency-planning",
      "nist-sp-800-30-risk-assessment",
      "nist-sp-800-18-security-plans"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-128-config-management",
    "title": "Guide for Security-Focused Configuration Management of Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-10-10",
    "bluf": "This guide provides guidelines for organizations responsible for managing and administering the security of federal information systems and associated environments of operation. The focus of this document is on implementation of the information system security aspects of configuration management, referred to as security-focused configuration management (SecCM), which is defined as the management and control of configurations for information systems to enable security and facilitate the management of information security risk. The goal of SecCM activities is to manage and monitor the configurations of information systems to achieve adequate security and minimize organizational risk while supporting the desired business functionality and services. SecCM builds on the general concepts of configuration management by focusing on the implementation and maintenance of established security requirements.\n\nThese guidelines are applicable to all federal information systems other than those designated as national security systems. Federal agencies are responsible for including policies and procedures that ensure compliance with minimally acceptable system configuration requirements. State, local, and tribal governments, as well as private sector organizations, are encouraged to consider using these guidelines. The core obligation involves a disciplined approach for providing adequate security through a process that includes planning, identifying and implementing secure configurations, controlling configuration changes, and monitoring configurations to ensure they are not inadvertently altered from the approved baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-30-risk-assessment",
      "nist-sp-800-39-managing-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-12r1-intro-infosec",
    "title": "An Introduction to Information Security (NIST Special Publication 800-12 Revision 1)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-10",
    "bluf": "This publication serves as a starting-point for those new to information security and for those unfamiliar with NIST information security publications and guidelines. Its intent is to provide a high-level overview of information security principles by introducing related concepts and the security control families (as defined in NIST SP 800-53) that organizations can leverage to effectively secure their systems and information. The target audience includes any person tasked with or interested in understanding how to secure systems, seeking a better understanding of information security basics, or a high-level view on the topic. The tips and techniques described may be applied to any type of information or system in any organization. Information security is defined as the protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to ensure confidentiality, integrity, and availability. The basic principles of information security are applicable to federal organizations, academia, and the private sector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-30-risk-assessment",
      "fips-199-security-categorization"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-131a-rev-2-crypto-transitions",
    "title": "Transitioning the Use of Cryptographic Algorithms and Key Lengths",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-03-01",
    "bluf": "This Recommendation (SP 800-131A) provides specific guidance for transitions to the use of stronger cryptographic keys and more robust algorithms for Federal Government agencies protecting sensitive, but unclassified information. The document addresses the use of algorithms and key lengths specified in Federal Information Processing Standards (FIPS) and NIST Special Publications (SPs), outlining the timelines and approval statuses for various cryptographic functions. A core requirement is the transition to a minimum security strength of 112 bits for applying cryptographic protection, such as encrypting or signing data. This supersedes the previous 80-bit requirement. The guidance details acceptable, deprecated, disallowed, and legacy-use statuses for block ciphers (e.g., TDEA, AES), digital signatures (DSA, ECDSA, RSA), random bit generators, key agreement schemes (DH, MQV, RSA), key wrapping, key derivation functions, hash functions (SHA-1, SHA-2, SHA-3), and message authentication codes (HMAC, CMAC). The publication establishes deadlines for phasing out weaker algorithms and key lengths, such as the use of three-key TDEA for encryption after 2023, and encourages implementers to plan for cryptographic agility to facilitate future transitions to quantum-resistant algorithms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-197-advanced-encryption-standard",
      "nist-fips-186-5-dss",
      "nist-sp-800-57-key-management",
      "nist-sp-800-90a-rev1-drbg",
      "secure-hash-standard-fips-180-4",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-132-pbkdf",
    "title": "NIST Special Publication 800-132 Recommendation for Password-Based Key Derivation Part 1: Storage Applications",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2010-12-01",
    "bluf": "This Recommendation specifies techniques for the derivation of master keys from passwords or passphrases to protect stored electronic data or data protection keys. Due to the low entropy and possibly poor randomness of passwords, they are not suitable to be used directly as cryptographic keys. This document specifies a family of password-based key derivation functions (PBKDFs) for deriving cryptographic keys from passwords or passphrases for the protection of electronically-stored data or for the protection of data protection keys. The derived keying material is called a Master Key (MK).\n\nThis Recommendation has been prepared for use by Federal agencies, though it may be used by non-governmental organizations on a voluntary basis. The core obligation is to use a PBKDF, specifically PBKDF2 using HMAC with an approved hash function, to derive a master key from a password. The inputs to the function include the password (P), a salt (S), an iteration count (C), and the desired key length (kLen). The randomly-generated portion of the salt shall be at least 128 bits, the master key length shall be at least 112 bits, and a minimum iteration count of 1,000 is recommended. The derived MK shall only be used to generate one or more Data Protection Keys (DPKs) or to protect existing DPKs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-57-key-management",
      "nist-sp-800-63b-authentication",
      "nist-sp-800-108r1-key-derivation",
      "fips-197-advanced-encryption-standard",
      "secure-hash-standard-fips-180-4"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-137-iscm",
    "title": "Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-09-11",
    "bluf": "NIST SP 800-137 requires U.S. federal agencies to develop and implement an Information Security Continuous Monitoring (ISCM) program to maintain ongoing awareness of security posture, vulnerabilities, and threats. The core of the standard is a six-step process (Define, Establish, Implement, Analyze and Report, Respond, Review and Update) detailed in Section 2.2, which enables risk-based decision-making.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "assessing-security-privacy-controls",
      "nist-cybersecurity-framework-2-0",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-140-dtr",
    "title": "FIPS 140-3 Derived Test Requirements (DTR): CMVP Validation Authority Updates to ISO/IEC 24759",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-03-31",
    "bluf": "NIST Special Publication (SP) 800-140 specifies the modifications of the Derived Test Requirements (DTR) for Federal Information Processing Standard (FIPS) 140-3. It modifies the test (TE) and vendor (VE) evidence requirements of International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 24759. As a validation authority, the Cryptographic Module Validation Program (CMVP) may modify, add or delete TEs and/or VEs as specified under paragraph 5.2 of ISO/IEC 24759. This document is focused toward vendors, testing labs, and the CMVP for the purpose of addressing CMVP specific requirements in ISO/IEC 24759 for cryptographic modules. This publication should be used in conjunction with ISO/IEC 24759 as it modifies only those requirements identified in this document. The core obligation is for Cryptographic and Security Testing Laboratories (CSTLs) to use the methods specified to demonstrate conformance, and for vendors to provide the required documentation as supporting evidence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-sp-800-144-cloud-computing",
    "title": "Guidelines on Security and Privacy in Public Cloud Computing",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2011-12-01",
    "bluf": "This publication provides an overview of the security and privacy challenges pertinent to public cloud computing and points out considerations organizations should take when outsourcing data, applications, and infrastructure to a public cloud environment. The primary purpose of this report is to describe the threats, technology risks, and safeguards surrounding public cloud environments, and their treatment. It is recommended to federal departments and agencies to help them apply the guidelines when performing their own analysis of requirements. The core obligation for organizations is to take a risk-based approach in analyzing available options and to assess, select, engage, and oversee the public cloud services that can best fulfill their requirements. Organizations should carefully plan the security and privacy aspects of cloud solutions, understand the provider's environment, ensure the solution satisfies organizational requirements, secure the client-side environment, and maintain accountability over the data and applications deployed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-144-public-cloud-security",
    "title": "NIST SP 800-144 - Guidelines on Security and Privacy in Public Cloud Computing",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2024-05-15",
    "bluf": "This publication provides guidelines for federal agencies to manage security and privacy risks when selecting and using public cloud computing services, focusing on the entire lifecycle from selection to termination. It outlines key considerations for governance, compliance, data portability, and security monitoring as detailed in Section 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-145-cloud-definition",
      "nist-sp-800-146-cloud-recommendations",
      "iso-27017-cloud-security-2015",
      "csa-ccm-v4-cloud-controls"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-145-cloud-computing",
    "title": "The NIST Definition of Cloud Computing",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-10",
    "bluf": "Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model is composed of five essential characteristics (On-demand self-service, Broad network access, Resource pooling, Rapid elasticity, Measured service), three service models (Software as a Service, Platform as a Service, Infrastructure as a Service), and four deployment models (Private, Community, Public, Hybrid). The NIST definition characterizes important aspects of cloud computing and is intended to serve as a means for broad comparisons of cloud services and deployment strategies, and to provide a baseline for discussion.\n\nThis guideline has been prepared for use by Federal agencies in furtherance of statutory responsibilities under the Federal Information Security Management Act (FISMA) of 2002. It may be used by nongovernmental organizations on a voluntary basis. The intended audience includes system planners, program managers, technologists, and others adopting cloud computing as consumers or providers of cloud services. It is not intended to prescribe or constrain any particular method of deployment, service delivery, or business operation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27017-cloud-security-2015",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-145-cloud-definition",
    "title": "The NIST Definition of Cloud Computing (SP 800-145)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This foundational U.S. federal standard establishes the official definition of cloud computing, mandating that any service classified as 'cloud' must exhibit five essential characteristics (e.g., on-demand self-service), fit one of three service models (SaaS, PaaS, IaaS), and one of four deployment models (Private, Community, Public, Hybrid), as detailed in Section 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27017-cloud-controls",
      "iso-27018-pii-cloud",
      "fedramp-moderate-baseline"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-sp-800-146-cloud-recommendations",
    "title": "Cloud Computing Synopsis and Recommendations",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2012-05-31",
    "bluf": "This document reprises the NIST-established definition of cloud computing, describes cloud computing benefits and open issues, presents an overview of major classes of cloud technology, and provides guidelines and recommendations on how organizations should consider the relative opportunities and risks of cloud computing. To understand which part of the spectrum of cloud systems is most appropriate for a given need, an organization should consider how clouds can be deployed (deployment models), what kinds of services can be provided to customers (service models), the economic opportunities and risks of using cloud services (economic considerations), the technical characteristics of cloud services such as performance and reliability (operational characteristics), typical terms of service (service level agreements), and the security opportunities and risks (security).\n\nOrganizations should be aware of the security issues that exist in cloud computing and of applicable NIST publications such as NIST Special Publication (SP) 800-53. The privacy and security of cloud computing depend primarily on whether the cloud service provider has implemented robust security controls and a sound privacy policy desired by their customers, the visibility that customers have into its performance, and how well it is managed. Inherently, the move to cloud computing is a business decision in which the business case should consider relevant factors, some of which include readiness of existing applications for cloud deployment, transition costs and life-cycle costs, maturity of service orientation in existing infrastructure, and other factors including security and privacy requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-145-cloud-computing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-150-cyber-threat-information-sharing",
    "title": "NIST Special Publication 800-150 Guide to Cyber Threat Information Sharing (Indicators, TTPs, Security Alerts, Threat Intelligence, Tool Configurations; Establishing and Participating in Sharing Relationships)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "NIST Special Publication 800-150 'Guide to Cyber Threat Information Sharing' (Johnson, Badger, Waltermire, Snyder, Skorupka; October 2016; https://doi.org/10.6028/NIST.SP.800-150) is the U.S. federal guidance for establishing, participating in, and maintaining cyber threat information sharing relationships across organisational boundaries. The document defines five major types of threat information per Section 2.1: Indicators (technical artefacts or observables such as IP addresses, DNS domains, URLs, file hashes, malicious email subject lines), Tactics, Techniques, and Procedures (TTPs - high-level tactics, detailed techniques, lower-level procedures describing actor behaviour), Security Alerts (advisories, bulletins, vulnerability notes from US-CERT, ISACs, NVD, PSIRTs, commercial providers, researchers), Threat Intelligence Reports (analysed and contextualised threat information), and Tool Configurations (signatures, ACLs, firewall rules, IDS configurations). Section 3 (Establishing Sharing Relationships) prescribes a six-step program: 3.1 Define Information Sharing Goals and Objectives; 3.2 Identify Internal Sources of Cyber Threat Information; 3.3 Define the Scope of Information Sharing Activities; 3.4 Establish Information Sharing Rules (including 3.4.1 Information Sensitivity and Privacy, 3.4.2 Sharing Designations such as TLP); 3.5 Join a Sharing Community; 3.6 Plan to Provide Ongoing Support. Section 4 (Participating in Sharing Relationships) prescribes Engage in Ongoing Communication (4.1), Consume and Respond to Security Alerts (4.2), Consume Threat Indicators (4.3), Use Indicators to Hunt, and Produce and Publish Indicators back to the community. SP 800-150 is the foundational federal document underneath STIX/TAXII (technical formats), TLP 2.0 (sharing designation), and ISAC/ISAO sharing arrangements; it is referenced in CISA's threat-information-sharing programs and is a prerequisite for any organisation establishing a structured cyber threat intelligence (CTI) program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "section_2_1_threat_information_types",
        "section_2_2_benefits",
        "section_2_3_challenges",
        "section_3_establishing_relationships",
        "section_3_4_2_sharing_designations",
        "section_4_participating_in_relationships",
        "stix_taxii_alignment",
        "tlp_alignment",
        "isac_isao_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fisma-2014-federal-information-security-modernization-pl-113-283",
      "oasis-stix-2-1-structured-threat-information",
      "first-tlp-2-0-traffic-light-protocol",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-sp-800-152-key-management",
    "title": "A Profile for U.S. Federal Cryptographic Key Management Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2015-10-01",
    "bluf": "This Profile for U.S. Federal Cryptographic Key Management Systems (FCKMSs) contains requirements for their design, implementation, procurement, installation, configuration, management, operation, and use by U.S. Federal organizations. It is intended to assist CKMS designers and implementers in selecting features, and to assist federal organizations and their contractors when procuring, installing, configuring, operating, and using FCKMSs. An FCKMS can be owned and operated by a federal organization or by a private contractor that provides key management services for federal organizations.\n\nThe core obligation is for agencies to adopt, adapt, and migrate their FCKMSs to comply with the Profile requirements over time, particularly when creating or procuring new systems or services. These requirements establish minimum security strengths and cryptographic module standards based on the information system impact-levels defined in FIPS 200: Low, Moderate, and High. The Profile specifies that information rated at a Low impact-level must be protected with at least 112 bits of security strength, Moderate with at least 128 bits, and High with at least 192 bits. It also mandates the use of FIPS 140-validated cryptographic modules at specific security levels corresponding to each impact level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-200-minimum-security-requirements",
      "fips-199-security-categorization",
      "nist-sp-800-57-key-management",
      "nist-sp-800-131a-rev-2-crypto-transitions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-160-v1r1",
    "title": "Engineering Trustworthy Secure Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-11-08",
    "bluf": "This publication describes a basis for establishing principles, concepts, activities, and tasks for engineering trustworthy secure systems. These can be effectively applied within systems engineering efforts to foster a common mindset to deliver security for any system, regardless of its purpose, type, scope, size, complexity, or stage of its system life cycle. The objective is to address security issues from the perspective of stakeholder requirements and protection needs and to use established engineering processes to ensure that such requirements and needs are addressed with appropriate fidelity and rigor across the entire life cycle of the system. Managing the complexity of trustworthy secure systems requires achieving the appropriate level of confidence in the feasibility, correctness-in-concept, philosophy, and design of a system to produce only the intended behaviors and outcomes. A trustworthy system provides compelling evidence to support claims that it meets its requirements to deliver the protection and performance needed by stakeholders, functioning only as intended while subjected to different types of adversity. Adversities can include attacks from determined and capable adversaries, human errors of omission and commission, accidents and incidents, component faults and failures, abuses and misuses, and natural and human-made disasters.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-53-r5",
      "security-considerations-system-development-lifecycle",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-160-v2r1",
    "title": "NIST Special Publication 800-160, Volume 2, Revision 1: Developing Cyber-Resilient Systems: A Systems Security Engineering Approach",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2021-12-31",
    "bluf": "NIST Special Publication (SP) 800-160, Volume 2, focuses on cyber resiliency engineering-an emerging specialty systems engineering discipline applied in conjunction with resilience engineering and systems security engineering to develop more survivable, trustworthy systems. Cyber resiliency engineering intends to architect, design, develop, maintain, and sustain the trustworthiness of systems with the capability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises that use or are enabled by cyber resources. From a risk management perspective, cyber resiliency is intended to reduce the mission, business, organizational, or sector risk of depending on cyber resources.\n\nThis publication presents a cyber resiliency engineering framework to aid in understanding and applying cyber resiliency, a concept of use for the framework, and the engineering considerations for implementing cyber resiliency in the system life cycle. The framework constructs include goals, objectives, techniques, implementation approaches, and design principles. Organizations can select, adapt, and use some or all of the cyber resiliency constructs in this publication and apply the constructs to the technical, operational, and threat environments for which systems need to be engineered. The guidance can be applied to new systems, modifications to fielded systems, and systems identified for retirement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-160-v1r1",
      "nist-sp-800-30-risk-assessment",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-161-r1-supply-chain-risk-management",
    "title": "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard provides guidance for U.S. federal and other organizations on identifying, assessing, and responding to cybersecurity risks throughout the supply chain. It establishes a multi-tiered Cybersecurity Supply Chain Risk Management (C-SCRM) framework, as detailed in Chapter 2, requiring organizations to integrate C-SCRM into their overall enterprise risk management activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "iso-27005-risk-management-2022",
      "nis2-supply-chain-security-article-22"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-161-scrm",
    "title": "NIST SP 800-161 Rev 1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard provides guidance for federal and non-federal organizations on establishing a comprehensive Cybersecurity Supply Chain Risk Management (C-SCRM) program. It requires organizations to identify, assess, and respond to cybersecurity risks throughout the supply chain by implementing a multi-tiered risk management framework, as detailed in Chapter 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-31000-risk-mgt-std",
      "nis2-supply-chain-security-article-22",
      "nist-ir-8276-cyber-scrm-practices"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-sp-800-161r1-csrm-practices",
    "title": "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-11-01",
    "bluf": "This publication provides guidance to organizations on identifying, assessing, and mitigating cybersecurity risks throughout the supply chain at all levels of their organizations. It addresses concerns about the risks associated with products and services that may potentially contain malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices. The guidance is for a diverse audience, including individuals with system, information security, risk management, acquisition, and system development responsibilities across public and private sector entities.\n\nThe core obligation is to integrate cybersecurity supply chain risk management (C-SCRM) into enterprise-wide risk management activities. This is achieved by applying a multilevel, C-SCRM-specific approach which includes the development of C-SCRM strategy and implementation plans, C-SCRM policies, C-SCRM plans for specific systems, and conducting risk assessments for products and services. The guidance emphasizes that C-SCRM is a systematic process for managing exposure to cybersecurity risks throughout the supply chain and developing appropriate response strategies, policies, processes, and procedures, which should be tailored to the unique size, resources, and risk circumstances of each enterprise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-30-risk-assessment",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-162-abac",
    "title": "Guide to Attribute Based Access Control (ABAC) Definition and Considerations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-08-02",
    "bluf": "This document provides Federal agencies with a definition of attribute based access control (ABAC), a logical access control methodology where authorization to perform a set of operations is determined by evaluating attributes associated with the subject, object, requested operations, and, in some cases, environment conditions against policy, rules, or relationships that describe the allowable operations for a given set of attributes. It provides planning, design, implementation, and operational considerations for employing ABAC within an enterprise with the goal of improving information sharing while maintaining control of that information.\n\nABAC is distinguishable because it controls access to objects by evaluating rules against the attributes of entities (subject and object), operations, and the environment relevant to a request. The access control policies that can be implemented in ABAC are limited only by the computational language and the richness of the available attributes. This flexibility enables the greatest breadth of subjects to access the greatest breadth of objects without specifying individual relationships between each subject and each object. As new subjects join an organization, rules and objects do not need to be modified as long as the subject is assigned the necessary attributes. This benefit is often referred to as accommodating the external (unanticipated) user and is one of the primary benefits of employing ABAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-207"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-163r1-mobile-app-vetting",
    "title": "NIST Special Publication 800-163 Revision 1: Vetting the Security of Mobile Applications",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-04-01",
    "bluf": "As both public and private organizations rely more on mobile applications, ensuring that they are reasonably free from vulnerabilities and defects is paramount. Mobile apps can pose serious security risks to an organization and its users due to vulnerabilities that may be exploited to steal information, control a user’s device, or result in unexpected app or device behavior. To mitigate these risks, organizations should employ a software assurance process, referred to as an app vetting process, that ensures a level of confidence that software is free from vulnerabilities and functions in the intended manner. This document defines such an app vetting process and is intended for public- and private-sector organizations that seek to improve the software assurance of mobile apps deployed on their mobile devices.\n\nThe core obligation is for organizations to determine if a mobile app is acceptable for deployment by vetting it against the organization's security requirements. This process involves a sequence of activities: app intake, app testing, app approval/rejection, and results submission. The process may be manual or automated and aims to be repeatable, efficient, and consistent, ensuring that mobile applications conform to defined security requirements before deployment. Organizations should not assume an app has been fully vetted or conforms to their security requirements simply because it is available through an official app store.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-mobile-device-security-enterprise",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-53-r5",
      "nist-sp-800-115-security-testing",
      "nist-sp-800-161r1-csrm-practices",
      "nist-sp-800-218-ssdf"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-167-application-whitelisting",
    "title": "Guide to Application Whitelisting",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2015-10-01",
    "bluf": "An application whitelist is a list of applications and application components that are authorized to be present or active on a host according to a well-defined baseline. Application whitelisting technologies use these lists to control which applications are permitted to install or execute, with the primary goal of stopping the execution of malware and other unauthorized software. Unlike traditional antivirus software that uses blacklists to block known bad activity, whitelisting technologies operate on a 'permit known good' model, blocking all other activity by default. The guidance is intended for organizations to understand the basics of application whitelisting and plan for its implementation throughout the security deployment lifecycle.\n\nThis framework applies to centrally managed hosts, including desktops, laptops, and servers, where consistent application workloads make implementation more practical. It is strongly recommended for high-risk environments where security outweighs unrestricted functionality. The core obligation for an organization is to establish and maintain the whitelist using attributes such as digital signatures, publishers, or cryptographic hashes. A successful deployment requires a clear, step-by-step planning and implementation process, beginning with a prototype in monitoring mode to evaluate its behavior before moving to an enforcement mode. Organizations will need dedicated staff to manage and maintain the solution, similar to handling an enterprise antivirus or intrusion detection system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "cis-controls-v8",
      "malware-incident-prevention-handling",
      "nist-sp-800-128-config-management",
      "fips-197-advanced-encryption-standard",
      "nist-sp-800-61r2-incident-handling"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-171-cui",
    "title": "NIST SP 800-171 Rev 2 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard requires nonfederal organizations that process, store, or transmit Controlled Unclassified Information (CUI) to implement 110 specific security controls across 14 families, as detailed in Chapter 3. Compliance is mandatory for entities in the U.S. federal supply chain, particularly for Department of Defense (DoD) contractors under DFARS 252.204-7012.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-200-minimum-security-requirements",
      "assessing-security-privacy-controls",
      "nist-cybersecurity-framework-2-0",
      "c-scrm-practices-systems-organizations",
      "developing-security-plans-federal-systems"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-171-cui-protection",
    "title": "NIST SP 800-171 Rev 3 - Protecting Controlled Unclassified Information (CUI) in Non-Federal Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This standard provides security requirements for non-federal systems and organizations to protect the confidentiality of Controlled Unclassified Information (CUI). Compliance is mandatory for entities handling CUI for U.S. federal agencies, as outlined in Chapter 1, and is foundational for frameworks like the DoD's CMMC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-cybersecurity-framework-2-0",
      "c-scrm-practices-systems-organizations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-171r3-cui-protection-2024",
    "title": "NIST Special Publication 800-171 Revision 3: Protecting Controlled Unclassified Information in Non-Federal Systems and Organizations",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes security requirements for non-federal organizations that process, store, or transmit Controlled Unclassified Information (CUI) to ensure confidentiality, integrity, and availability. It applies to all contractors and subcontractors in the Defense Industrial Base and other federal supply chain partners under contract with U.S. federal agencies, as required by 32 CFR Part 2002 and DFARS 252.204-7012.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-800-53-ac2",
      "nist-800-53-au2",
      "nist-800-53-sc7",
      "c-scrm-practices-systems-organizations",
      "assessing-security-privacy-controls"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-sp-800-172-enhanced-security",
    "title": "Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2021-02-01",
    "bluf": "The protection of Controlled Unclassified Information (CUI) resident in nonfederal systems and organizations is of paramount importance to federal agencies and can directly impact the ability of the Federal Government to successfully conduct its essential missions and functions. This publication provides federal agencies with recommended enhanced security requirements for protecting the confidentiality, integrity, and availability of CUI when the information is resident in nonfederal systems, the nonfederal organization is not operating on behalf of an agency, and no other specific safeguarding requirements exist for the CUI category. These enhanced requirements supplement the basic security requirements in NIST Special Publication 800-171 and are specifically designed to respond to the advanced persistent threat (APT).\n\nThe core obligation applies to components of nonfederal systems that process, store, or transmit CUI associated with a critical program or high value asset. The requirements are intended for use by federal agencies in contractual vehicles or other agreements established with nonfederal organizations. The security measures promote penetration-resistant architectures, damage-limiting operations, and designs to achieve cyber resiliency and survivability. Federal agencies will select the specific set of enhanced requirements based on mission needs and risk assessments, and there is no expectation that all of the enhanced security requirements will be selected in every situation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-172a-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-172a-assessment",
    "title": "Assessing Enhanced Security Requirements for Controlled Unclassified Information",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-03-01",
    "bluf": "This publication provides federal agencies and nonfederal organizations with assessment procedures to carry out assessments of the requirements in NIST Special Publication 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information (CUI). The protection of CUI in nonfederal systems and organizations is important to federal agencies and can directly impact the ability of the Federal Government to successfully carry out its assigned missions. The purpose of this publication is to describe procedures for assessing these enhanced security requirements, which are designed to respond to the advanced persistent threat (APT) for CUI associated with a high value asset or critical program. The assessment procedures are flexible and can be tailored to the needs of organizations and assessors. Assessments can be conducted as self-assessments, independent third-party assessments, or government-sponsored assessments. The findings and evidence produced can be used to facilitate risk-based decisions, identify security weaknesses, prioritize risk mitigation, and support continuous monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-172-enhanced-security",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-177-trustworthy-email",
    "title": "NIST Special Publication 800-177 Revision 1 Trustworthy Email",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-02-28",
    "bluf": "This document provides recommendations and guidelines for enhancing trust in email, applicable to federal IT systems and also useful for small or medium-sized organizations. The primary audience includes enterprise email administrators, information security specialists, and network managers. Given that the core email protocol, Simple Mail Transport Protocol (SMTP), is susceptible to attacks like man-in-the-middle content modification and surveillance, this guide details adaptations to mitigate these threats.\n\nThe guidelines cluster into techniques for authenticating a sending domain, assuring email transmission security, and ensuring email content security. Technologies recommended in support of core SMTP and the Domain Name System (DNS) include mechanisms for authenticating a sending domain: Sender Policy Framework (SPF), Domain Keys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting and Conformance (DMARC). For email transmission security, recommendations cover Transport Layer Security (TLS) and associated certificate authentication. For email content security, the guide recommends encryption and authentication of message content using Secure/Multipurpose Internet Mail Extensions (S/MIME) and associated protocols. Many of these security enhancements rely on records stored in a secured DNS, particularly through the deployment of DNS Security Extensions (DNSSEC).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-52r2-tls-guidelines",
      "nist-fips-186-5-dss"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-sp-800-18-r1",
    "title": "Guide for Developing Security Plans for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-02-28",
    "bluf": "The objective of system security planning is to improve protection of information system resources. All federal systems have some level of sensitivity and require protection as part of good management practice. The protection of a system must be documented in a system security plan, a requirement of the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA). The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The plan also delineates responsibilities and expected behavior of all individuals who access the system and should reflect input from information owners, the system owner, and the senior agency information security officer (SAISO).\nManagement authorization to operate a system is based on an assessment of management, operational, and technical controls documented in the security plan. By authorizing processing in a system, a manager accepts its associated risk. The system security plan forms the basis for this authorization, supplemented by an assessment report and a plan of actions and milestones. Re-authorization should occur whenever there is a significant change in processing, but at least every three years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "nist-sp-800-53-r5",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-18-r1-security-plans",
    "title": "Guide for Developing Security Plans for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-02-28",
    "bluf": "This guide provides direction for developing system security plans for federal information systems, a requirement of the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA). The purpose of the system security plan is to provide an overview of the security requirements of a system and describe the controls in place or planned for meeting those requirements. The plan also delineates responsibilities and expected behavior of all individuals who access the system. It is intended to be a living document, reflecting input from information owners, system owners, and the senior agency information security officer (SAISO), that forms the basis for the authorization of a system to operate.\n\nThe document applies to all federal agencies and their information systems, which must be categorized as either a major application or a general support system. The protection of a system must be documented in a system security plan, which supports the system development life cycle (SDLC) and should be updated when events trigger the need for revision. Management authorization for a system to process information is based on an assessment of management, operational, and technical controls documented in the security plan. Re-authorization is required whenever there is a significant change in processing, and at least every three years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-18-security-plans",
    "title": "Guide for Developing Security Plans for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-02-01",
    "bluf": "The objective of system security planning is to improve protection of information system resources. All federal systems have some level of sensitivity and require protection as part of good management practice, and the protection of a system must be documented in a system security plan. This is a requirement of the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA), which requires each federal agency to develop, document, and implement an agency-wide information security program. The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The plan also delineates responsibilities and expected behavior of all individuals who access the system.\n\nThe system security plan should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system. It reflects input from various managers, including information owners, the system owner, and the senior agency information security officer (SAISO). A senior management official must authorize a system to operate, accepting its associated risk based on an assessment of management, operational, and technical controls documented in the plan. Re-authorization should occur whenever there is a significant change in processing, but at least every three years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-181r1-nice-framework",
    "title": "Workforce Framework for Cybersecurity (NICE Framework)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-11-01",
    "bluf": "This publication from the National Initiative for Cybersecurity Education (NICE) describes the Workforce Framework for Cybersecurity (NICE Framework), a fundamental reference for describing and sharing information about cybersecurity work. It provides a reference taxonomy-a common language-of cybersecurity work and of the individuals who carry out that work. As a common, consistent lexicon that categorizes and describes cybersecurity work, the NICE Framework improves communication about how to identify, recruit, develop, and retain cybersecurity talent.\n\nThe NICE Framework provides a set of building blocks for describing the tasks, knowledge, and skills (TKS) that are needed to perform cybersecurity work. Through these building blocks, the framework enables organizations to develop their workforces to perform cybersecurity work, and it helps learners to explore cybersecurity work and to engage in appropriate learning activities to develop their knowledge and skills. This development, in turn, benefits employers and employees through the identification of career pathways that document how to prepare for cybersecurity work using the data of TKS statements bundled into Work Roles and Competencies. This publication may be used by nongovernmental organizations on a voluntary basis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-50r1-learning-program"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-183-networks-of-things",
    "title": "NIST Special Publication 800-183 Networks of ‘Things’",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2016-07-01",
    "bluf": "This document offers an underlying and foundational understanding of the Internet of Things (IoT) based on the realization that IoT involves sensing, computing, communication, and actuation. It presents five core primitives as the basic building blocks for a Network of ‘Things’ (NoT), which includes IoT. These primitives apply well to systems with large amounts of data, scalability concerns, heterogeneity concerns, temporal concerns, and elements of unknown pedigree with possible nefarious intent. This model and vocabulary defines principles common to most, if not all, networks of things, allowing for comparisons between NoTs and providing a unifying vocabulary for composition and information exchange.\n\nThe material presented is generic to all distributed systems that employ IoT technologies. The document uses the acronyms IoT and NoT (Network of Things) interchangeably, where IoT is an instantiation of a NoT with its ‘things’ tethered to the Internet. The intended audience includes computer scientists, IT managers, networking specialists, and networking and cloud computing software engineers. The model aims to expose the ingredients that can express how the IoT behaves, without defining IoT, offering insights into issues specific to trust.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nistir-8228-iot-cybersecurity-risks",
      "nist-sp-800-213-iot-guidance",
      "nistir-8259a-iot-device-cybersecurity",
      "nist-sp-1800-15-iot-mud",
      "nist-sp-1800-32-securing-ders"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-sp-800-184-event-recovery",
    "title": "Guide for Cybersecurity Event Recovery",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2016-12-01",
    "bluf": "In light of an increasing number of cybersecurity events, organizations can improve resilience by ensuring that their risk management processes include comprehensive recovery planning. Although there are existing federal policies, standards, and guidelines on cyber event handling, none of them focuses solely on improving cybersecurity recovery capabilities. This publication provides tactical and strategic guidance regarding the planning, playbook developing, testing, and improvement of recovery planning to help organizations plan and prepare recovery from a cyber event and integrate the processes and procedures into their enterprise risk management plans. This guidance is not an operational playbook but is intended for individuals with decision making responsibilities to develop customized playbooks.\n\nRecovery can be described in two phases: an immediate tactical recovery phase achieved through a pre-planned playbook, and a more strategic phase focused on continuous improvement of all Cybersecurity Framework (CSF) functions based on lessons learned. The document supports organizations in a technology-neutral way in improving their cyber event recovery plans, processes, and procedures, with the goal of resuming normal operations more quickly. While the scope is primarily US federal agencies, the information is useful to any organization wishing to have a more flexible and comprehensive approach to recovery.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-61r2-incident-handling",
      "nist-sp-800-34-contingency-planning",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-185-sha3-derived-functions",
    "title": "SHA-3 Derived Functions: cSHAKE, KMAC, TupleHash and ParallelHash",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2016-12-31",
    "bluf": "This Recommendation specifies four types of SHA-3-derived functions: cSHAKE, KMAC, TupleHash, and ParallelHash, each defined for a 128- and 256-bit security strength. This publication has been developed by NIST in accordance with its statutory responsibilities under the Federal Information Security Modernization Act (FISMA) of 2014 and is intended for developing information security standards and guidelines, including minimum requirements for federal information systems. This publication may be used by nongovernmental organizations on a voluntary basis.\n\ncSHAKE is a customizable variant of the SHAKE function defined in FIPS 202. KMAC (KECCAK Message Authentication Code) is a variable-length message authentication code algorithm that can also be used as a pseudorandom function. TupleHash is a variable-length hash function designed to hash tuples of input strings without trivial collisions. ParallelHash is a variable-length hash function that can hash very long messages in parallel. The core obligation is the correct implementation and use of these cryptographic functions as specified, ensuring domain separation through function names and customization strings to prevent collisions and maintain security properties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "secure-hash-standard-fips-180-4",
      "nist-sp-800-57-key-management",
      "nist-sp-800-131a-rev-2-crypto-transitions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-186-elliptic-curves",
    "title": "Recommendations for Discrete Logarithm-based Cryptography: Elliptic Curve Domain Parameters",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-02-01",
    "bluf": "This Recommendation specifies the set of elliptic curves recommended for U.S. Government use. It provides updated specifications of elliptic curves appropriate for digital signatures and key agreement schemes, intended for implementers of cryptographic systems. In addition to previously recommended Weierstrass curves defined over prime and binary fields, this document includes newly specified Montgomery and Edwards curves, which can provide increased performance, side-channel resistance, and simpler implementation. The new curves are interoperable with those specified by the Crypto Forum Research Group (CFRG) of the Internet Engineering Task Force (IETF).\n\nThe core obligation is to use the specified elliptic curves in conjunction with other NIST publications for applications like digital signatures and key agreement. This document deprecates curves over binary fields due to limited adoption, recommending new implementations select a curve over a prime field. Furthermore, curves from FIPS 186-4 that do not meet current bit security requirements are designated for legacy-use only; they may be used to process already protected information (e.g., decrypt or verify) but not to apply new protection (e.g., encrypt or sign). Key pairs generated using these specifications are strictly for digital signature and key agreement purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-fips-186-5-dss",
      "nist-sp-800-57-key-management",
      "nist-sp-800-131a-rev-2-crypto-transitions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-sp-800-187-guide-lte-security",
    "title": "NIST SP 800-187 Guide to LTE Security - Authentication Architecture, Encryption Algorithms and LTE Threat Vectors",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This guide provides federal agencies and commercial organizations with detailed information on the security architecture of Long-Term Evolution (LTE) networks, focusing on the Authentication and Key Agreement (AKA) protocol, cryptographic algorithms, and known threat vectors. As per Section 3, it outlines the security mechanisms within the Evolved Packet System (EPS) to ensure confidentiality, integrity, and availability for mobile communications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-57-key-management",
      "nist-sp-800-131a-rev-2-crypto-transitions",
      "fips-199-security-categorization"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-188-de-identification",
    "title": "De-Identifying Government Datasets: Techniques and Governance",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-09-07",
    "bluf": "De-identification is a general term for any process of removing the association between a set of identifying data and the data subject. This document, NIST SP 800-188, provides specific guidance to U.S. government agencies that wish to use de-identification to make government datasets available while protecting the privacy of individuals. The guidance aims to prevent or limit disclosure risks to individuals and establishments while still allowing for the production of meaningful statistical analysis. The intended audience includes government system engineers, security officers, data scientists, privacy officers, and disclosure review boards.\n\nBefore using de-identification, agencies should evaluate their goals and the potential risks that releasing de-identified data might create. Core obligations include deciding upon a data-sharing model, such as publishing de-identified data, publishing synthetic data, providing a query interface, or using non-public protected enclaves. The guidance recommends that agencies create a Disclosure Review Board (DRB) to oversee the de-identification process, adopt a de-identification standard with measurable performance levels, and perform re-identification studies to gauge risk. It emphasizes that formal privacy methods like k-anonymity and differential privacy should be preferred over informal ad hoc methods when available and sufficient for the task.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-privacy-rule"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-18r1-security-plans",
    "title": "Guide for Developing Security Plans for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-02-01",
    "bluf": "The objective of system security planning is to improve protection of information system resources. The protection of a system must be documented in a system security plan, a requirement of OMB Circular A-130 and the Federal Information Security Management Act (FISMA). This guidance applies to all federal agencies, but may be used by non-governmental organizations on a voluntary basis. The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements, and to delineate responsibilities and expected behavior of all individuals who access the system. The system security plan should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system.\n\nManagement authorization to operate a system is based on an assessment of management, operational, and technical controls. The system security plan establishes and documents these security controls and should form the basis for the authorization. By authorizing processing, a manager accepts the system's associated risk. Re-authorization should occur whenever there is a significant change in processing, but at least every three years. The plan should reflect input from various managers, including information owners, the system owner, and the senior agency information security officer (SAISO).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-18r1-security-plans-federal-systems",
    "title": "Guide for Developing Security Plans for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-02-01",
    "bluf": "The objective of system security planning is to improve protection of information system resources. All federal systems have some level of sensitivity and require protection, which must be documented in a system security plan. This is a requirement of the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA). The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The plan also delineates responsibilities and expected behavior of all individuals who access the system.\n\nThe system security plan should reflect input from various managers, including information owners, the system owner, and the senior agency information security officer. A senior management official must authorize a system to operate, accepting its associated risk. This management authorization should be based on an assessment of management, operational, and technical controls documented in the security plan, supplemented by an assessment report and a plan of actions and milestones. Re-authorization should occur whenever there is a significant change in processing, but at least every three years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-190-container-security",
    "title": "Application Container Security Guide",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2017-09-30",
    "bluf": "Application container technologies are a form of operating system virtualization combined with application software packaging that provide a portable, reusable, and automatable way to package and run applications. This publication explains the potential security concerns associated with the use of containers and provides practical recommendations for addressing those concerns for system administrators, security managers, developers, and others responsible for the security of application container technologies. The core risks involve vulnerabilities and misconfigurations within container images, insecure connections to registries, unbounded administrative access to orchestrators, and the inherent risks of a shared kernel on the host OS.\n\nTo mitigate these risks, organizations should tailor their operational culture and technical processes for containerized environments. Key recommendations include using minimalist, container-specific host operating systems to reduce attack surfaces; grouping containers by purpose, sensitivity, and threat posture on a single host for defense-in-depth; adopting container-specific vulnerability management tools and processes to scan images for flaws; considering hardware-based countermeasures like a Trusted Platform Module (TPM) to establish a root of trust; and deploying container-aware runtime defense tools to monitor and respond to anomalous activity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-128-config-management",
      "nist-sp-800-218-ssdf",
      "nist-ir-8176-linux-container-security"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-193-firmware-resiliency",
    "title": "NIST Special Publication 800-193 Platform Firmware Resiliency Guidelines",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2018-05-01",
    "bluf": "This document provides technical guidelines and recommendations supporting resiliency of platform firmware and data against potentially destructive attacks. The platform is a collection of fundamental hardware and firmware components needed to boot and operate a system. A successful attack on platform firmware could render a system inoperable, perhaps permanently, or requiring reprogramming by the original manufacturer, resulting in significant disruptions to users. The guidelines promote resiliency by describing security mechanisms for protecting the platform against unauthorized changes, detecting unauthorized changes that occur, and recovering from attacks rapidly and securely. The guidelines are based on three core principles: Protection, involving mechanisms to ensure platform firmware code and critical data remain in a state of integrity; Detection, involving mechanisms to detect when firmware or data have been corrupted; and Recovery, involving mechanisms for restoring firmware and data to a state of integrity.\n\nThe intended audience includes system and platform device vendors of computer systems, including manufacturers of clients, servers, and networking devices, as well as developers and engineers responsible for implementing firmware-level security technologies. The security principles and recommendations are broadly applicable to other classes of systems with updatable firmware, including Internet of Things devices, embedded systems, and mobile devices. System administrators and security professionals can use this document to guide procurement strategies and priorities for future systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-160-v2r1",
      "validating-integrity-of-computing-devices",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-204b-abac",
    "title": "Attribute-based Access Control for Microservices-based Applications Using a Service Mesh",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2021-08-31",
    "bluf": "This document provides deployment guidance for building an authentication and authorization framework within a service mesh for microservices-based applications. In modern cloud-native architectures featuring loosely coupled microservices, it is necessary to build the concept of zero trust into the application environment. This guidance addresses two critical security requirements: (1) building zero trust by enabling mutual authentication in communication between any pair of services, and (2) establishing a robust, scalable access control mechanism such as attribute-based access control (ABAC) that can express a wide set of policies.\n\nThe framework applies to applications where a dedicated infrastructure, the service mesh, provides services like authentication and authorization independently of the application code. The core obligations involve implementing a framework that includes an authenticatable runtime identity for services, authenticable credentials for individual users, encryption of communication between services, and a Policy Enforcement Point (PEP) that is separately deployable and controllable from the application. The service mesh's native features, such as authenticating end-user credentials (e.g., JWT), are leveraged to move request-level policy enforcement out of the application code, ensuring that requests reaching a service have been authenticated and authorized.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-204-microservices"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-sp-800-204b-abac-microservices",
    "title": "Attribute-based Access Control for Microservices-based Applications Using a Service Mesh",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-10",
    "bluf": "With the disappearance of a network perimeter due to the need to provide ubiquitous access to applications from multiple remote locations using different types of devices, it is necessary to build the concept of zero trust into the application environment. Two critical security requirements in this architecture are to build (1) the concept of zero trust by enabling mutual authentication in communication between any pair of services and (2) a robust access control mechanism based on an access control such as attribute-based access control (ABAC) that can be used to express a wide set of policies and is scalable in terms of user base, objects (resources), and deployment environment.\n\nThe objective of this document is to provide deployment guidance for an authentication and authorization framework within a service mesh for microservices-based applications. This framework includes an authenticatable runtime identity for services, authenticable credentials for individual users of the service, and encryption of communication between services. It also specifies a Policy Enforcement Point (PEP) that is separately deployable and controllable from the application. A reference platform for hosting the microservices-based application and a reference platform for the service mesh are included to illustrate the concepts in the recommendations and provide the context in terms of the components used in real-world deployments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-162-abac"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-204b-zero-trust-microservices",
    "title": "NIST SP 800-204B - Attribute-based Access Control (ABAC) for Microservices-based Applications using a Zero Trust Architecture",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "NIST SP 800-204B provides guidance on deploying Attribute-Based Access Control (ABAC) to secure automated workflows and microservices within a Zero Trust Architecture, emphasizing dynamic authentication and authorization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-sp-800-204c-devsecops-microservices",
    "title": "Implementation of DevSecOps for a Microservices-based Application with Service Mesh",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-10",
    "bluf": "Cloud-native applications have evolved into a standardized architecture consisting of multiple loosely coupled components called microservices that are supported by an infrastructure for providing application services, such as service mesh. In this architecture, the entire set of source code can be divided into five types: application code, application services code, infrastructure as code, policy as code, and observability as code. Due to security, business competitiveness, and the inherent structure of loosely coupled application components, this class of applications needs a different development, deployment, and runtime paradigm. DevSecOps (Development, Security, and Operations) has been found to be a facilitating paradigm for these applications with primitives such as continuous integration, continuous delivery, and continuous deployment (CI/CD) pipelines. These pipelines are workflows for taking the developer’s source code through various stages, such as building, testing, packaging, deployment, and operations supported by automated tools with feedback mechanisms. This document provides guidance for the implementation of DevSecOps primitives for cloud-native applications with the architecture and code types described. The benefits of this approach for high security assurance and for enabling continuous authority to operate (C-ATO) are also discussed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-204-microservices",
      "nist-sp-800-204b-abac",
      "nist-800-190-container"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-204d-cicd-pipeline-security",
    "title": "Strategies for the Integration of Software Supply Chain Security in DevSecOps CI/CD pipelines",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This NIST Special Publication provides actionable strategies to integrate software supply chain (SSC) security into DevSecOps CI/CD pipelines for cloud-native applications, focusing on source code integrity, artifact provenance, and deployment verification. Key requirements are outlined in sections addressing SLSA framework alignment, SBOM generation, and attestation workflows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "cobit-2019-governance-framework",
      "nist-ir-8011-v1-automated-assessments"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-sp-800-204d-sssc-devsecops",
    "title": "Strategies for the Integration of Software Supply Chain Security in DevSecOps CI/CD Pipelines",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-02-01",
    "bluf": "This document outlines strategies for integrating Software Supply Chain (SSC) security assurance measures into Continuous Integration/Continuous Delivery (CI/CD) pipelines to protect the integrity of the underlying activities. The overall goal is to ensure that the CI/CD pipeline activities that take source code through the build, test, package, and deployment stages are not compromised. Cloud-native applications, often composed of multiple loosely coupled microservices, are generally developed using the DevSecOps paradigm, which utilizes CI/CD pipelines. Threats to the SSC can arise from attack vectors unleashed by malicious actors as well as defects introduced when due diligence practices are not followed by legitimate actors during the Software Development Life Cycle (SDLC).\n\nThe guidance is intended for a broad group of practitioners including site reliability engineers, software engineers, project managers, and security architects. It focuses on actionable measures to integrate various building blocks for SSC security assurance into CI/CD pipelines to enhance the preparedness of organizations. This includes securing the developer environment, mitigating attack vectors, and protecting assets like source code and build systems. While artifacts like Software Bill of Materials (SBOM) are foundational, this document concentrates on the workflow tasks within CI/CD pipelines to meet the objectives of frameworks such as NIST’s Secure Software Development Framework (SSDF).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-204c-devsecops-microservices",
      "nist-sp-800-218-ssdf",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-205-access-control",
    "title": "NIST Special Publication 800-205 Attribute Considerations for Access Control Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-06-01",
    "bluf": "This document provides federal agencies with a guide for implementing attributes in access control systems. Attributes enable a logical access control methodology where authorization to perform a set of operations is determined by evaluating attributes associated with the subject, object, requested operations, and environmental conditions against policy. Attribute-based access control systems rely upon attributes to not only define access control policy rules but also enforce the access control. Confidence in access control decisions is dependent on the accuracy, integrity, and timely availability of attributes.\n\nThe core obligation is to ensure attributes shared across organizations provide assurance via proper location, retrieval, publication, validation, update, security, and revocation capabilities. To achieve this assurance, an Attribute Evaluation Scheme needs to be established, which brings confidence based on five principal areas of interest: Preparation, which involves planning attribute creation and sharing mechanisms; Veracity, which establishes semantic and syntactic correctness and trustworthiness; Security, which considers standards for secure transmission and storage of attributes; Readiness, which addresses the frequency of attribute refresh, caching, and backup; and Management, which provides mechanisms for maintaining attributes efficiently, including metadata, hierarchies, and logging.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-162-abac",
      "nist-sp-800-207",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-207",
    "title": "NIST SP 800-207 - Zero Trust Architecture",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "NIST Special Publication 800-207 (August 2020) defines Zero Trust Architecture (ZTA) - the security paradigm that shifts from perimeter-based ('castle and moat') defenses to identity-centric, per-session access decisions on all resources. The core principle is 'never trust, always verify': no implicit trust is granted based on network location. NIST 800-207 defines seven tenets of zero trust including that all data sources are resources, all communication is secured regardless of location, and access is granted per-session based on dynamic policy. The architecture defines three logical components: Policy Engine (PE) - makes access grant/deny decisions; Policy Administrator (PA) - establishes/terminates communication paths; Policy Enforcement Point (PEP) - gates access between subjects and enterprise resources. Three implementation approaches are defined: Enhanced Identity Governance (EIG), Micro-segmentation, and Software-Defined Perimeter (SDP)/Network Infrastructure. U.S. federal agencies were mandated to adopt ZTA principles by OMB Memorandum M-22-09 (January 2022), with specific maturity targets for identity, device, network, application, and data pillars per CISA ZT Maturity Model.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-63b-digital-identity",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-1800-35-zero-trust-architecture"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-sp-800-207-zero-trust",
    "title": "NIST SP 800-207 - Zero Trust Architecture",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This publication provides an abstract definition of Zero Trust Architecture (ZTA), outlining its core logical components, deployment models, and operational principles. It establishes the foundational tenet of ZTA, as defined in Section 2.1, which asserts that no implicit trust is granted to assets or user accounts based solely on their physical or network location.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cyber-nist-800-53-ac2",
      "nist-800-53-ia2",
      "nist-800-53-sc7",
      "cis-controls-v8"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-207a-zta-multi-cloud",
    "title": "NIST SP 800-207A Zero Trust Architecture Multi-Cloud Environments - Implementation Guidance",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2024-03-28",
    "bluf": "This guidance provides federal agencies and other organizations with a roadmap for implementing a Zero Trust Architecture (ZTA) across multi-cloud environments. It addresses key challenges such as inconsistent identity management, policy enforcement, and visibility across different cloud service providers, building upon the foundational concepts of NIST SP 800-207.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-145-cloud-computing",
      "csa-ccm-v4-cloud-controls",
      "iso-27017-cloud-security-2015",
      "nist-sp-800-210-cloud-access-control"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-208-stateful-hbs",
    "title": "Recommendation for Stateful Hash-Based Signature Schemes",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-10-01",
    "bluf": "This recommendation specifies two stateful hash-based signature (HBS) schemes, the Leighton-Micali Signature (LMS) system and the eXtended Merkle Signature Scheme (XMSS), along with their multi-tree variants, as supplements to FIPS 186. The security of these schemes depends on the security of the underlying hash functions and is believed to be resistant to attacks from large-scale quantum computers. Stateful HBS schemes are primarily intended for applications where a digital signature scheme must be implemented in the near future, the implementation will have a long lifetime, and transitioning to a different scheme after deployment is impractical, such as for authenticating firmware updates for constrained devices. A core obligation is the proper maintenance of state; an HBS private key consists of a large set of one-time signature (OTS) private keys, and the signer must ensure that no individual OTS key is ever used to sign more than one message. Reusing an OTS key would make it computationally feasible for an attacker to forge signatures. This recommendation requires that key and signature generation be performed in hardware cryptographic modules that do not allow secret keying material to be exported.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-fips-186-5-dss",
      "secure-hash-standard-fips-180-4",
      "nist-sp-800-57-key-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-209-storage-infrastructure",
    "title": "Security Guidelines for Storage Infrastructure",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-10-01",
    "bluf": "This document provides an overview of the evolution of the storage technology landscape, current security threats, and the resultant risks. The primary purpose is to provide a comprehensive set of security recommendations for the current landscape of storage infrastructure, which consists of a mixture of legacy and advanced systems. The recommendations and security focus areas span those that are common to the entire IT infrastructure, such as physical security, authentication and authorization, change management, configuration control, incident response, and recovery. Within these areas, security controls that are specific to storage technologies, such as network-attached storage (NAS) and storage area networks (SAN), are also covered. In addition, security recommendations specific to storage technologies are provided for the following areas of operation: data protection, isolation, restoration assurance, and encryption. The guidance applies to traditional storage services (block, file, and object), storage virtualization, storage architectures for virtualized server environments, and storage resources hosted in the cloud.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-63b-authentication"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-210-cloud-access",
    "title": "NIST Special Publication 800-210 General Access Control Guidance for Cloud Systems",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2020-07-31",
    "bluf": "This document presents cloud access control (AC) characteristics and a set of general access control guidance for cloud service models-IaaS (Infrastructure as a Service), PaaS (Platform as a Service), and SaaS (Software as a Service). The main focus is on technical aspects of access control without considering deployment models (e.g., public, private, hybrid clouds etc.), as well as trust and risk management issues. Different service delivery models need to consider managing different types of access on offered service components. Such considerations can be hierarchical; for example, the access control considerations of functional components in a lower-level service model (e.g., networking and storage layers in the IaaS model) are also applicable to the same functional components in a higher-level service model (e.g., networking and storage in PaaS and SaaS models). In general, access control considerations for IaaS are also applicable to PaaS and SaaS, and access control considerations for IaaS and PaaS are also applicable to SaaS. However, each service model has its own focus with regard to access control requirements for its service.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-145-cloud-computing",
      "nist-sp-800-146-cloud-recommendations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-210-cloud-access-control",
    "title": "General Access Control Guidance for Cloud Systems",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-10",
    "bluf": "This document presents cloud access control (AC) characteristics and a set of general access control guidance for cloud service models: IaaS (Infrastructure as a Service), PaaS (Platform as a Service), and SaaS (Software as a Service). The main focus is on technical aspects of access control without considering deployment models (e.g., public, private, hybrid clouds etc.). Different service delivery models require managing different types of access on offered service components. Such service models can be considered hierarchical, thus the access control guidance of functional components in a lower-level service model are also applicable to the same functional components in a higher-level service model.\n\nIn general, access control guidance for IaaS is also applicable to PaaS and SaaS, and access control guidance for IaaS and PaaS is also applicable to SaaS. However, each service model has its own focus with regard to access control requirements for its service. For instance, an IaaS provider may put more effort into virtualization control, and in addition to the virtualization control, a SaaS provider needs to consider data security and the privacy of services it provides. The intended audience for this document is an organizational entity that implements access control solutions for sharing information in cloud systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-145-cloud-computing",
      "nist-sp-800-146-cloud-recommendations",
      "iso-27017-cloud-controls",
      "fedramp-moderate-baseline"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-sp-800-213-iot-guidance",
    "title": "NIST Special Publication 800-213 IoT Device Cybersecurity Guidance for the Federal Government: Establishing IoT Device Cybersecurity Requirements",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2021-11-01",
    "bluf": "As organizations increasingly use Internet of Things (IoT) devices, care must be taken in their acquisition and implementation. This publication contains background and recommendations to help federal organizations consider how an IoT device they plan to acquire can integrate into a system. It provides guidance on considering system security from the device perspective, allowing for the identification of device cybersecurity requirements-the abilities and actions an organization will expect from an IoT device and its manufacturer or third parties. This guidance is intended for information security professionals, system administrators, and others tasked with managing security on a system.\n\nThe publication applies to organizations incorporating IoT devices as system elements into an existing information system. In-scope devices have at least one transducer (sensor or actuator) for interacting with the physical world and at least one network interface. The core obligation is for organizations to assess the security impact of integrating IoT devices, understand the device's relationship to the system to properly define cybersecurity requirements, and manage risks that arise when devices do not meet those requirements, potentially through compensating controls or by deciding not to incorporate the device.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-213a-iot-catalog",
    "title": "NIST Special Publication 800-213A IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2021-11-01",
    "bluf": "This publication provides a catalog of internet of things (IoT) device cybersecurity capabilities and non-technical supporting capabilities to help federal organizations determine and establish device cybersecurity requirements. The guidance applies to federal organizations, including information security professionals and system administrators, tasked with assessing, applying, and maintaining security for IoT devices used with federal information systems. The core obligation is for these organizations to use this catalog in conjunction with SP 800-213 and the NIST Risk Management Framework (RMF) to determine appropriate device cybersecurity requirements needed to support the security controls implemented on their systems.\n\nDevice cybersecurity capabilities are features or functions provided through device hardware and software, such as data protection using encryption. Non-technical supporting capabilities are actions performed by manufacturers or other entities, such as providing notifications for software updates. The catalog details seven technical capabilities including Device Identification, Device Configuration, Data Protection, Logical Access, Software Update, Cybersecurity State Awareness, and Device Security. It also outlines four non-technical capabilities related to Documentation, Information Reception, Information Dissemination, and Education. By using this catalog, federal organizations can better describe the requirements needed to integrate an IoT device into a system securely, increasing the security posture of systems and their elements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-213-iot-guidance",
      "nist-sp-800-30-risk-assessment",
      "fips-140-3-cryptographic-modules",
      "nist-sp-800-63b-digital-identity"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-215-secure-enterprise-network",
    "title": "NIST SP 800-215 Guide to a Secure Enterprise Network Landscape",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-11-10",
    "bluf": "The enterprise network landscape has undergone tremendous changes due to enterprise access to multiple cloud services, the geographical spread of on-premises IT resources, and the architectural shift from monolithic applications to microservices. These drivers have resulted in the disappearance of a protectable network perimeter, an increased attack surface, and the potential for rapid escalation of attacks across network boundaries. This document provides guidance for this new landscape from a secure operations perspective, intended for network design and security solution architects in organizations with hybrid IT environments.\n\nThis guide examines the limitations of current network access technologies and illustrates how solutions have evolved from specific security functions to comprehensive security frameworks and infrastructure. It addresses feature enhancements to traditional network security appliances, secure networking configurations for specific functions, security frameworks like Zero Trust Network Access (ZTNA) that integrate these configurations, and the evolution of Wide Area Network (WAN) infrastructure to provide a holistic set of security services. The core obligation is for organizations to move defenses from static, network-based perimeters to focus on users, assets, and resources, assuming no implicit trust based on physical or network location.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-207",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "guide-telework-remote-access-byod",
      "nist-sp-800-63b-authentication"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-216-vulnerability-disclosure-guidelines",
    "title": "Recommendations for Federal Vulnerability Disclosure Guidelines",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-05-17",
    "bluf": "This document provides guidelines for managing vulnerability disclosure for information systems within the Federal Government, following the IoT Cybersecurity Improvement Act of 2020. It recommends guidance for establishing a federal vulnerability disclosure framework, properly handling vulnerability reports, and communicating the mitigation and/or remediation of vulnerabilities. The framework is designed to be applied to all software, hardware, and digital services under federal control, including government-developed, commercial, and open-source software used by government systems.\n\nThe framework defines two primary government entities: the Federal Coordination Body (FCB) and Vulnerability Disclosure Program Offices (VDPOs). The FCB serves as the primary interface for vulnerability disclosure reporting, oversight, and coordination among government agencies. VDPOs are operational units, ideally part of existing information technology security offices, responsible for coordinating with actors to identify, resolve, and issue advisories on reported vulnerabilities for products and services. The core obligation is for federal agencies to establish and maintain a unified and flexible process for receiving, coordinating, publishing, and resolving security vulnerabilities to minimize the unintended exposure of government information, data corruption, and loss of services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-61r2-incident-handling",
      "nist-sp-800-213-iot-guidance",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-218-secure-software-development-framework-ssdf",
    "title": "NIST SP 800-218 Secure Software Development Framework (SSDF) - Workflow Integration Requirements",
    "domain": "Workflow Automation",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "NIST SP 800-218 (Secure Software Development Framework, February 2022) defines 4 practice groups and 19 specific practices for integrating security throughout the software development lifecycle (SDLC) workflow. Required practices: PO.1 (define security requirements for software), PO.2 (implement roles and responsibilities for software security), PO.3 (implement supporting toolchains), PO.4 (define and use criteria for software security checks), PW.1 (design software to meet security requirements), PW.4 (reuse existing well-secured software), PW.7 (review and/or analyze human-readable code), PW.8 (test executable code), RV.1 (identify and confirm vulnerabilities), RV.2 (assess, prioritize, and remediate vulnerabilities). Mandated for all US federal agencies and their software suppliers via OMB M-22-18 (September 2022) requiring SSDF attestation in POA&Ms. Executive Order 14028 on Improving the Nation's Cybersecurity (May 2021) is the governance authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_framework",
        "regulatory_mapping",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-workflow-processes",
      "nist-sp-800-204d-cicd-pipeline-security"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-218-ssdf",
    "title": "NIST Special Publication 800-218 Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-01",
    "bluf": "This document describes the Secure Software Development Framework (SSDF), a core set of fundamental, sound, high-level practices for secure software development. The framework is intended to be integrated into any existing software development life cycle (SDLC) implementation. The primary audiences for this document are software producers-including commercial-off-the-shelf (COTS) product vendors, government-off-the-shelf (GOTS) software developers, custom software developers, and internal development teams, regardless of size or sector-and software acquirers, such as federal agencies and other organizations.\n\nThe SSDF's core objective is for organizations to follow its practices to reduce the number of vulnerabilities in released software, reduce the potential impact of the exploitation of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent future recurrences. The framework is organized into four groups of practices: preparing the organization by ensuring people, processes, and technology are ready for secure development; protecting all components of the software from tampering and unauthorized access; producing well-secured software with minimal vulnerabilities; and identifying and responding to vulnerabilities in software releases. The SSDF focuses on the outcomes of practices rather than on specific tools or techniques, making it broadly applicable across different technologies, platforms, and development models.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-53-r5",
      "nist-sp-800-161r1-csrm-practices",
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-218-ssdf-v1-1-secure-software-development-framework",
    "title": "NIST SP 800-218 v1.1 Secure Software Development Framework (SSDF) - Prepare the Organization, Protect the Software, Produce Well-Secured Software, Respond to Vulnerabilities; EO 14028 Reference Standard",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "NIST Special Publication 800-218 v1.1 the Secure Software Development Framework (Souppaya, Scarfone, Dodson; February 2022) is the canonical U.S. federal framework defining fundamental secure software development practices. The SSDF organises practices into four groups: Prepare the Organization (PO) - ensure people, processes, and technology are prepared to perform secure software development at the organization level; Protect the Software (PS) - protect all components of the software from tampering and unauthorized access; Produce Well-Secured Software (PW) - produce well-secured software with minimal security vulnerabilities in its releases; Respond to Vulnerabilities (RV) - identify residual vulnerabilities in software releases and respond appropriately. The practices include Define Security Requirements for Software Development (PO.1), Implement Roles and Responsibilities (PO.2), Implement Supporting Toolchains (PO.3), Define and Use Criteria for Software Security Checks (PO.4), Implement and Maintain Secure Environments for Software Development (PO.5); Protect All Forms of Code from Unauthorized Access and Tampering (PS.1), Provide a Mechanism for Verifying Software Release Integrity (PS.2), Archive and Protect Each Software Release (PS.3); Design Software to Meet Security Requirements and Mitigate Security Risks (PW.1), Review the Software Design (PW.2), Reuse Existing Well-Secured Software (PW.4), Create Source Code by Adhering to Secure Coding Practices (PW.5), Configure the Compilation Interpreter and Build Processes (PW.6), Review and Analyze Human-Readable Code (PW.7), Test Executable Code (PW.8), Configure Software to Have Secure Settings by Default (PW.9); Identify and Confirm Vulnerabilities on an Ongoing Basis (RV.1), Assess Prioritize and Remediate Vulnerabilities (RV.2), Analyze Vulnerabilities to Identify Their Root Causes (RV.3). Each practice is composed of named tasks (e.g., PO.1.1, PO.1.2, PO.1.3) with notional implementation examples and references to other standards (BSAFSS, BSIMM, CMMC, EO 14028, IEC 62443, ISO 27034, ISO 30111, NIST SP 800-53, SP 800-161, SP 800-181, OWASP SAMM, SCAGILE, SCSIC, SCTPC, SCFPSSD, MSSDL, PCISSLC, NISTLABEL). SSDF v1.1 is the federal reference standard explicitly cited in Executive Order 14028 and OMB Memorandum M-22-18 for the secure software self-attestation requirement applied to vendors selling software to the U.S. federal government, including the CISA Secure Software Development Attestation Form.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "prepare_the_organization_po_group",
        "protect_the_software_ps_group",
        "produce_well_secured_software_pw_group",
        "respond_to_vulnerabilities_rv_group",
        "task_structure",
        "executive_order_14028_relationship",
        "omb_m_22_18_self_attestation",
        "cisa_secure_software_attestation_form",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14028-cybersecurity-2021-sbom-mfa-zerotrust",
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "slsa-v1-0-supply-chain-levels-for-software-artifacts",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-sp-800-219-macos-mscp",
    "title": "Automated Secure Configuration Guidance from the macOS Security Compliance Project (mSCP)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-06-24",
    "bluf": "This publication introduces the macOS Security Compliance Project (mSCP), an open-source initiative by the National Institute of Standards and Technology (NIST) designed to provide security configuration guidance for Apple macOS in a machine-consumable format. The mSCP provides resources that system administrators, security professionals, security policy authors, information security officers, and auditors can leverage to secure and assess macOS desktop and laptop system security in an automated way. The project, hosted on GitHub, offers practical, actionable recommendations through secure baselines and associated rules, which are continuously curated and updated to support new macOS releases. The mSCP seeks to simplify the macOS security development cycle by reducing the effort required to implement security baselines, which are groups of settings used to configure a system to meet a target level or set of requirements.\n\nThis specific publication, NIST SP 800-219, has been formally withdrawn as of July 20, 2023, and is provided for historical purposes only. It has been superseded in its entirety by SP 800-219r1. The project's content maps macOS settings to various security standards, including NIST SP 800-53, NIST SP 800-171, and the DISA Security Technical Implementation Guide (STIG). Organizations are advised to use the mSCP's content with a risk-based approach, selecting appropriate settings and tailoring baselines to meet their specific security requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-70-r4-ncp"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-221-ict-risk",
    "title": "Enterprise Impact of Information and Communications Technology Risk: Governing and Managing ICT Risk Programs Within an Enterprise Risk Portfolio",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-10-18",
    "bluf": "This publication helps individual organizations within an enterprise improve their Information and Communications Technology (ICT) risk management (ICTRM) to better identify, assess, and manage ICT risks in the context of broader mission and business objectives. It applies to both Federal Government and non-Federal Government professionals, including corporate officers and executives, who may be familiar with either ICTRM or Enterprise Risk Management (ERM), but not the integration of both. The core obligation is to integrate ICTRM within the overall sphere of ERM. This involves rolling up and integrating risks that are addressed at lower system and organizational levels to the broader enterprise level by focusing on the use of ICT risk registers as input to the enterprise risk profile. This integrated approach ensures that ICT risks are considered part of an interrelated portfolio, rather than in silos.\n\nEffective integration requires coordination, communication, and collaboration to address risks that extend beyond individual program boundaries, such as those related to cybersecurity, privacy, supply chain, IoT, and AI. By applying a consistent approach to identify, assess, respond to, and communicate risk, leaders and executives can be accurately informed and make effective strategic and tactical decisions. This allows ICT risks to be quantified in financial, mission, and reputation metrics similar to other enterprise risks, enabling prudent resource allocation. The goal is to balance the benefits of technology with potential risks and consequences, supporting a comprehensive ERM approach that safeguards the enterprise's mission, finances, and reputation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-30-risk-assessment",
      "nist-ir-8286a-cybersecurity-risk",
      "nist-ir-8286b-prioritizing-cybersecurity-risk",
      "nist-ir-8286c-staging-cybersecurity-risks",
      "nist-sp-800-221a-ict-risk-outcomes"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-221a-ict-risk-outcomes",
    "title": "Information and Communications Technology (ICT) Risk Outcomes: Integrating ICT Risk Management Programs with the Enterprise Risk Portfolio",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-10-18",
    "bluf": "The increasing frequency, creativity, and severity of technology attacks means that all enterprises should ensure that information and communications technology (ICT) risk is receiving appropriate attention within their enterprise risk management (ERM) programs. Specific types of ICT risk include, but are not limited to, cybersecurity, privacy, and supply chain. This document provides a framework of outcomes that applies to all types of ICT risk, providing a common language for understanding, managing, and expressing ICT risk to internal and outside stakeholders. It is a tool for aligning policy, business, and technological approaches to managing that risk, and can be used to help identify and prioritize actions for reducing ICT risk.\nThe primary audience for this publication includes both Federal Government and non-Federal Government professionals at all levels who understand ICT but may be unfamiliar with the details of ERM. The secondary audience includes both Federal and non-Federal Government corporate officers, high-level executives, ERM officers and staff members, and others who understand ERM but may be unfamiliar with the details of ICT. Using the framework for each type of ICT risk will help organizations improve the quality and consistency of ICT risk information they provide as inputs to their ERM programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-221-ict-risk"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "nist-sp-800-223-hpc-security",
    "title": "High-Performance Computing Security: Architecture, Threat Analysis, and Security Posture",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-02-02",
    "bluf": "This NIST Special Publication aims to standardize and facilitate the sharing of High-Performance Computing (HPC) security information and knowledge through the development of an HPC system reference architecture and key components, which are introduced as the basics of the HPC system lexicon. The reference architecture divides an HPC system into four function zones: a high-performance computing zone, a data storage zone, an access zone, and a management zone. This publication analyzes HPC threats, considers current HPC security postures and challenges, and makes best-practice recommendations.\n\nThis guideline may be used by federal agencies and is consistent with the requirements of the Office of Management and Budget (OMB) Circular A-130. It has been developed by NIST in accordance with its statutory responsibilities under the Federal Information Security Modernization Act (FISMA) of 2014. This publication may also be used by nongovernmental organizations on a voluntary basis. The core obligations focus on understanding the unique architecture of HPC systems, identifying threats specific to its functional zones, and implementing tailored security controls that balance performance with security, such as network segmentation, compute node sanitization, data integrity protection, and secure container management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-190-container-security"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-sp-800-226-differential-privacy",
    "title": "Guidelines for Evaluating Differential Privacy Guarantees",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2025-03-01",
    "bluf": "This publication describes differential privacy - a PET that quantifies privacy risk to individuals when their data appears in a dataset. Differential privacy was first defined in 2006 as a theoretical framework and is still making the transition from theory to practice. This publication is intended to help those who need to manage the risks of data analytics and data sharing - including business owners, product managers, privacy personnel, security personnel, software engineers, data scientists, and academics - understand, evaluate, and compare differential privacy guarantees. Differential privacy promises that a reduction in privacy caused by a data analysis or published dataset will be bounded for all individuals about whom data are found in the dataset. In other words, any privacy reduction to an individual that results from a differentially private analysis could have happened even if the individual had not contributed their data. Differential privacy is generally achieved by adding random noise to analysis results. More noise yields better privacy but degrades the utility of the result. This privacy-utility tradeoff can make it difficult to achieve both high utility and strong privacy protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-188-de-identification"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-30-risk-assessment",
    "title": "Guide for Conducting Risk Assessments",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2012-09-01",
    "bluf": "This guide provides a structured approach for conducting risk assessments of federal information systems and organizations, amplifying the guidance in NIST Special Publication 800-39. Risk assessments are a fundamental component of an organizational risk management process, used to identify, estimate, and prioritize risk to organizational operations, assets, individuals, and the Nation resulting from the use of information systems. The purpose of a risk assessment is to inform decision makers and support risk responses by identifying relevant threats, internal and external vulnerabilities, the potential impact or harm that may occur, and the likelihood of that harm occurring. The end result is a determination of risk, which is typically a function of the degree of harm and the likelihood of its occurrence.\n\nThe guidelines are applicable to all federal information systems other than those designated as national security systems, and are intended for a diverse audience of risk management professionals. The core obligation is to conduct risk assessments on an ongoing basis throughout the system development life cycle and across all tiers of the risk management hierarchy: the organization level, mission/business process level, and information system level. The guide provides a detailed process for preparing for an assessment, conducting the assessment, communicating the results, and maintaining the assessment over time to ensure it remains relevant as systems, threats, and operational environments change.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-39-managing-risk",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-34-contingency-planning",
    "title": "Contingency Planning Guide for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2010-05-01",
    "bluf": "NIST Special Publication 800-34, Rev. 1 provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to interim measures and a coordinated strategy involving plans, procedures, and technical measures that enable the recovery of information systems, operations, and data after a service disruption. Interim measures may include relocation of information systems to an alternate site, recovery using alternate equipment, or performance of functions using manual methods. This guidance is prepared for use by federal agencies but may be used by nongovernmental organizations on a voluntary basis. It applies to managers, CIOs, security officers, system engineers, and administrators responsible for designing, managing, operating, or securing information systems.\n\nThe core obligation for federal organizations is to apply a seven-step process to develop and maintain a viable contingency planning program for their information systems. This process includes: developing a formal contingency planning policy statement; conducting a business impact analysis (BIA) to identify and prioritize critical systems; identifying preventive controls to reduce disruption effects; creating thorough recovery strategies; developing a detailed information system contingency plan (ISCP); ensuring the plan is validated through testing, training, and exercises; and maintaining the plan as a living document. These progressive steps are designed to be integrated into each stage of the system development life cycle, ensuring that systems can be recovered quickly and effectively following a disruption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-34-contingency-planning-guide",
    "title": "Contingency Planning Guide for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2010-05-01",
    "bluf": "NIST Special Publication 800-34, Rev. 1, provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to interim measures to recover information system services after a disruption. These measures may include relocation of information systems to an alternate site, recovery of functions using alternate equipment, or performance of functions using manual methods. This guide is applicable to federal agencies and may be used by non-governmental organizations on a voluntary basis. It defines a seven-step contingency planning process designed to be integrated into each stage of the system development life cycle.\n\nThe core obligation for organizations is to develop and maintain a viable contingency planning program for their information systems. This process includes developing a formal policy, conducting a business impact analysis (BIA) to identify and prioritize critical systems, identifying preventive controls, creating thorough recovery strategies, developing a detailed information system contingency plan, ensuring the plan is tested and personnel are trained, and maintaining the plan as a living document. The guide presents sample formats for contingency plans based on the low, moderate, or high-impact levels defined by FIPS 199, covering activation, recovery, and reconstitution phases.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "fips-199-security-categorization"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-34-r1",
    "title": "Contingency Planning Guide for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2010-05-01",
    "bluf": "NIST Special Publication 800-34, Rev. 1 provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to a coordinated strategy involving interim measures to recover information system services after a disruption. These measures may include relocation of systems to an alternate site, recovery using alternate equipment, or performing functions using manual methods. This guide is prepared for use by federal agencies but may be used by nongovernmental organizations on a voluntary basis.\n\nThe core obligation is a seven-step contingency planning process: 1. Develop a formal contingency planning policy statement to provide authority and guidance. 2. Conduct a business impact analysis (BIA) to identify and prioritize critical information systems and components. 3. Identify preventive controls to reduce the effects of system disruptions. 4. Create thorough recovery strategies to ensure the system may be recovered quickly and effectively. 5. Develop a detailed information system contingency plan. 6. Ensure plan testing, training, and exercises to validate recovery capabilities and prepare personnel. 7. Ensure the plan is a living document that is updated regularly to remain current with system enhancements and organizational changes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "fips-199-security-categorization",
      "nist-sp-800-39-managing-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-37-rmf",
    "title": "Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-12-20",
    "bluf": "This standard establishes a mandatory seven-step Risk Management Framework (RMF) for U.S. federal agencies to manage cybersecurity and privacy risk. As detailed in Chapter 2, the RMF integrates security, privacy, and supply chain risk management activities into the system development life cycle, from system categorization to continuous monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "assessing-security-privacy-controls",
      "nist-cybersecurity-framework-2-0",
      "c-scrm-practices-systems-organizations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-39-managing-information-security-risk",
    "title": "NIST Special Publication 800-39: Managing Information Security Risk: Organization, Mission, and Information System View",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2011-03-01",
    "bluf": "This publication provides guidance for an integrated, organization-wide program for managing information security risk to organizational operations, assets, individuals, other organizations, and the Nation resulting from the operation and use of federal information systems. The guidance applies to all federal information systems other than those designated as national security systems. The core obligation is for leaders at all levels to understand their responsibilities and be held accountable for managing information security risk as a fundamental mission and business requirement. This is achieved through a multitiered risk management approach addressing risk at the organization level (Tier 1), the mission/business process level (Tier 2), and the information system level (Tier 3).\n\nThe risk management process itself is comprised of four components: framing risk by establishing the context for risk-based decisions and creating a risk management strategy; assessing risk by identifying threats, vulnerabilities, harm, and likelihood; responding to risk by developing and implementing courses of action (accept, avoid, mitigate, share, or transfer); and monitoring risk on an ongoing basis to verify implementation and determine effectiveness. Effective risk management requires that organizations operate in highly complex, interconnected environments, and this publication provides a structured, yet flexible approach to integrate risk-based decision making into every aspect of the organization, ensuring that missions and business functions are successfully executed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-30-risk-assessment",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-39-managing-risk",
    "title": "Managing Information Security Risk: Organization, Mission, and Information System View",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2011-03-01",
    "bluf": "This guidance provides an integrated, organization-wide program for managing information security risk to organizational operations, assets, individuals, other organizations, and the Nation resulting from the operation and use of federal information systems. It establishes a multi-tiered approach that addresses risk at the organization, mission/business process, and information system levels, fostering a climate where risk is considered within mission design, enterprise architecture, and system development life cycles. The core obligation for leaders and managers at all levels is to understand their responsibilities and be held accountable for managing this risk. The process is a comprehensive activity requiring organizations to frame risk by establishing context, assess risk by identifying threats and vulnerabilities, respond to risk once determined, and monitor risk on an ongoing basis.\n\nThe guidelines are applicable to all federal information systems other than those designated as national security systems. The guidance is intended for a diverse audience, including senior leaders with oversight responsibilities, mission/business owners, acquisition officials, information security professionals, system developers, and assessors. While developed for federal agencies under the Federal Information Security Management Act (FISMA), state, local, and tribal governments, as well as private sector organizations, are encouraged to use these guidelines. The risk management guidance is complementary to and should be used as part of a more comprehensive Enterprise Risk Management (ERM) program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-40r4-enterprise-patch-management",
    "title": "Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-04-30",
    "bluf": "Enterprise patch management is the process of identifying, prioritizing, acquiring, installing, and verifying the installation of patches, updates, and upgrades throughout an organization. This process is more important than ever because of the increasing reliance on technology and the shift towards zero trust architectures where the perimeter largely does not exist anymore. This guide applies to all types of computing technology assets, including information technology (IT), operational technology (OT), Internet of Things (IoT), mobile, cloud, virtual machine, and container assets. There is often a divide between business/mission owners, who may believe that patching negatively affects productivity, and security/technology management. This publication frames patching as a critical component of preventive maintenance for computing technologies-a cost of doing business and a necessary part of what organizations need to do to achieve their missions.\n\nThe core obligation is for leadership, business/mission owners, and security/technology management teams to jointly create an enterprise patch management strategy that simplifies and operationalizes patching while also improving its reduction of risk. This involves maintaining up-to-date software and asset inventories, defining risk response scenarios (routine patching, emergency patching, emergency mitigation, unpatchable assets), assigning assets to maintenance groups, and defining maintenance plans for each group. Preventive maintenance through enterprise patch management helps prevent compromises, data breaches, operational disruptions, and other adverse events.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-1800-5-it-asset-management",
      "cis-controls-v8",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-41-r1-firewalls",
    "title": "Guidelines on Firewalls and Firewall Policy",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2009-09-01",
    "bluf": "Firewalls are devices or programs that control the flow of network traffic between networks or hosts that employ differing security postures. This guidance provides an overview of firewall technologies, discusses their security capabilities, and makes recommendations for establishing firewall policies and for selecting, configuring, testing, deploying, and managing firewall solutions. It is intended for technical IT personnel responsible for firewall design, selection, deployment, and management.\n\nThe core recommendations for organizations are to create a firewall policy that specifies how firewalls should handle inbound and outbound network traffic. A firewall policy should define how firewalls handle traffic for specific IP addresses, protocols, and applications based on risk analysis. Generally, all inbound and outbound traffic not expressly permitted by the firewall policy should be blocked. Organizations should also create rulesets that implement the firewall policy while supporting performance, and manage firewall architectures, policies, and software throughout their lifecycle. This includes using a formal change management control process for rulesets, performing periodic reviews, monitoring logs and alerts, and patching firewall software as vendors provide updates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-800-53-sc7",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-cybersecurity-framework-2-0",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-47-information-exchanges",
    "title": "Managing the Security of Information Exchanges",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2021-07-01",
    "bluf": "This publication provides guidance for managing the security of information exchanges between systems that are owned and operated by different organizations or are within the same organization but with different authorization boundaries. An organization often has mission and business-based needs to exchange information with other internal or external organizations via various information exchange channels, and the information being exchanged requires the same or similar level of protection as it moves from one organization to another, commensurate with risk. This guidance defines the scope of information exchange, describes the benefits of secure management, identifies types of exchanges, and discusses potential security risks and the types of agreements that may be applied by organizations.\n\nThe core obligation is a four-phased approach for securely managing information exchange. The phases are: 1) Planning the information exchange, where organizations perform preliminary activities, examine all relevant issues, and develop an appropriate agreement; 2) Establishing the information exchange, where organizations execute a plan, implement security controls, and sign agreements; 3) Maintaining the exchange, where organizations actively maintain security and ensure agreement terms are met; and 4) Discontinuing the information exchange in a manner that avoids disruption. Agreements specify the responsibilities of participating organizations and the technical and security requirements for the exchange.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-53-r5",
      "nist-sp-800-18-r1",
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-50r1-learning-program",
    "title": "Building a Cybersecurity and Privacy Learning Program",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-08-09",
    "bluf": "This publication provides guidance for federal agencies and organizations to develop and manage a life cycle approach to building a Cybersecurity and Privacy Learning Program (CPLP). The program is intended to address the needs of large and small organizations and includes cybersecurity and privacy awareness campaigns, role-based training, and other workforce education programs. The CPLP is designed to be part of a larger organizational effort to reduce cybersecurity and privacy risks, supporting federal requirements such as the Federal Information Security Management Act (FISMA) and incorporating industry-recognized best practices for risk management.\n\nThe core obligation is for an organization to create a strategic program plan that ensures appropriate resources are available to meet learning goals for all personnel, including employees and contractors. The overarching goal of a CPLP is to provide opportunities for learning at all levels, encourage behavior change as part of risk management, and lead to developing a privacy and security culture in the organization. The guidance provides steps to build an effective CPLP, identify personnel who require advanced training, create a methodology for program evaluation, and engage in ongoing improvement to minimize privacy and security risks to the organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-200-minimum-security-requirements",
      "nist-sp-800-181r1-nice-framework",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-52r2-tls-guidelines",
    "title": "Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-08-01",
    "bluf": "Transport Layer Security (TLS) provides mechanisms to protect data during electronic dissemination across the Internet. This Special Publication provides guidance to the selection and configuration of TLS protocol implementations while making effective use of Federal Information Processing Standards (FIPS) and NIST-recommended cryptographic algorithms. It requires that TLS 1.2 configured with FIPS-based cipher suites be supported by all government TLS servers and clients and requires support for TLS 1.3 by January 1, 2024. This Special Publication also provides guidance on certificates and TLS extensions that impact security.\n\nThe guidelines in this document are specifically targeted towards U.S. federal departments and agencies. While these guidelines are primarily designed for federal users and system administrators to adequately protect sensitive but unclassified U.S. Federal Government data, they may also be used by non-governmental organizations on a voluntary basis. The guidance promotes more consistent use of authentication, confidentiality, and integrity mechanisms; consistent use of recommended cipher suites that encompass NIST-approved algorithms; and protection against known and anticipated attacks on the TLS protocol.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-57-key-management",
      "nist-sp-800-131a-rev-2-crypto-transitions",
      "fips-197-advanced-encryption-standard",
      "nist-fips-186-5-dss",
      "secure-hash-standard-fips-180-4"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-sp-800-53-r5",
    "title": "Security and Privacy Controls for Information Systems and Organizations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-12-10",
    "bluf": "This publication provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intelligence entities, and privacy risks. The controls are flexible and customizable and implemented as part of an organization-wide process to manage risk. The controls address diverse requirements derived from mission and business needs, laws, executive orders, directives, regulations, policies, standards, and guidelines. The consolidated control catalog addresses security and privacy from both a functionality perspective and an assurance perspective.\n\nRevision 5 of this foundational NIST publication represents a multi-year effort to develop the next generation of security and privacy controls. The objectives are to make the information systems we depend on more penetration-resistant, limit the damage from attacks when they occur, make the systems cyber-resilient and survivable, and protect individuals’ privacy. It includes changes to make the controls more outcome-based, integrating information security and privacy controls into a seamless, consolidated catalog, establishing a new supply chain risk management control family, and separating control selection processes from the controls themselves to allow use by different communities of interest.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping",
        "mitre_attack",
        "mitre_d3fend",
        "mitre_capec"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-53-rev5-ac-access-control-family",
    "title": "NIST SP 800-53 Rev 5 - Access Control (AC) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Access Control (AC) family of NIST SP 800-53 Rev 5 contains 25 base controls (AC-1 through AC-25) that govern how organizations authorize, enforce, and monitor logical and physical access to information systems, accounts, sessions, devices, and information flows. Organizations must develop and disseminate an access control policy (AC-1); manage the full account lifecycle including provisioning, role assignment, monitoring, and de-provisioning (AC-2); enforce approved authorizations for system access (AC-3) and information flow between systems (AC-4); document separation of duties (AC-5) and apply least privilege (AC-6); limit unsuccessful logon attempts and define the action taken when the limit is exceeded (AC-7); display a system use notification before granting access (AC-8); manage device locks (AC-11) and automatic session termination (AC-12); govern remote access (AC-17), wireless access (AC-18), and mobile devices (AC-19); restrict use of external systems (AC-20); and constrain publicly accessible content (AC-22). The AC family is one of the largest in the catalog and applies across all FIPS 199 impact levels, with control baselines specified in NIST SP 800-53B.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "cyber-nist-800-53-ac2",
      "iso-27001-2022"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "nist-sp-800-53-rev5-at-awareness-training-family",
    "title": "NIST SP 800-53 Rev 5 - Awareness and Training (AT) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Awareness and Training (AT) (AT) family of NIST SP 800-53 Rev 5 contains 6 base controls (AT-1 onward) that establish the security and privacy obligations for awareness and training. The AT family addresses ongoing training and awareness obligations: literacy training and awareness (AT-2), role-based training (AT-3), training records (AT-4), and advanced training simulations (AT-6). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-sp-800-53-rev5-au-audit-and-accountability-family",
    "title": "NIST SP 800-53 Rev 5 - Audit and Accountability (AU) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Audit and Accountability (AU) (AU) family of NIST SP 800-53 Rev 5 contains 16 base controls (AU-1 onward) that establish the security and privacy obligations for audit and accountability. The AU family establishes audit event identification (AU-2), content of audit records (AU-3), audit log storage capacity (AU-4), response to audit logging process failures (AU-5), audit record review and analysis (AU-6), audit record reduction and report generation (AU-7), time stamps (AU-8), protection of audit information (AU-9), non-repudiation (AU-10), audit record retention (AU-11), and audit record generation (AU-12). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-sp-800-53-rev5-ca-assessment-authorization-monitoring-family",
    "title": "NIST SP 800-53 Rev 5 - Assessment, Authorization, and Monitoring (CA) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Assessment, Authorization, and Monitoring (CA) (CA) family of NIST SP 800-53 Rev 5 contains 9 base controls (CA-1 onward) that establish the security and privacy obligations for assessment, authorization, and monitoring. The CA family covers control assessments (CA-2), information exchange between systems (CA-3), plans of action and milestones (CA-5), system authorization (CA-6), continuous monitoring (CA-7), penetration testing (CA-8), and internal system connections (CA-9). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-53-rev5-cm-configuration-management-family",
    "title": "NIST SP 800-53 Rev 5 - Configuration Management (CM) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Configuration Management (CM) (CM) family of NIST SP 800-53 Rev 5 contains 14 base controls (CM-1 onward) that establish the security and privacy obligations for configuration management. The CM family covers baseline configuration (CM-2), configuration change control (CM-3), impact analyses (CM-4), access restrictions for change (CM-5), configuration settings (CM-6), least functionality (CM-7), system component inventory (CM-8), configuration management plan (CM-9), software usage restrictions (CM-10), and user-installed software (CM-11). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-sp-800-53-rev5-cp-contingency-planning-family",
    "title": "NIST SP 800-53 Rev 5 - Contingency Planning (CP) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Contingency Planning (CP) (CP) family of NIST SP 800-53 Rev 5 contains 13 base controls (CP-1 onward) that establish the security and privacy obligations for contingency planning. The CP family covers the contingency plan itself (CP-2), contingency training (CP-3), contingency plan testing (CP-4), alternate storage site (CP-6), alternate processing site (CP-7), telecommunications services (CP-8), system backup (CP-9), system recovery and reconstitution (CP-10), and alternate communications protocols (CP-11). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-sp-800-53-rev5-ia-identification-authentication-family",
    "title": "NIST SP 800-53 Rev 5 - Identification and Authentication (IA) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Identification and Authentication (IA) family of NIST SP 800-53 Rev 5 contains 13 base controls (IA-1 through IA-13) that govern how organizations uniquely identify and authenticate users, devices, processes, and services before granting access to systems and data. Organizations must establish identification and authentication policy and procedures (IA-1); uniquely identify and authenticate organizational users (IA-2) and non-organizational users (IA-8); uniquely identify and authenticate devices before establishing a network connection (IA-3); manage system identifiers across the full lifecycle (IA-4); manage authenticators including initial verification, content rules, recovery, and refresh (IA-5); obscure authentication feedback during the authentication process (IA-6); implement cryptographic module authentication consistent with applicable laws and standards (IA-7); uniquely identify and authenticate services (IA-9); require adaptive authentication under defined conditions (IA-10); require re-authentication when defined triggers occur (IA-11); perform identity proofing aligned to identity assurance levels (IA-12); and govern identity providers and authorization servers (IA-13). Authenticator strength, lifecycle, and assurance levels reference NIST SP 800-63 (Digital Identity Guidelines) for tailoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "nist-sp-800-53-rev5-ir-incident-response-family",
    "title": "NIST SP 800-53 Rev 5 - Incident Response (IR) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Incident Response (IR) family of NIST SP 800-53 Rev 5 contains 10 base controls (IR-1 through IR-10) that establish the organizational and technical foundations of an incident response capability spanning preparation, detection and analysis, containment, eradication, and recovery. Organizations must develop, document, and disseminate incident response policy and procedures (IR-1); provide incident response training to system users consistent with assigned roles (IR-2); test the effectiveness of the incident response capability on a defined cadence (IR-3); implement an incident handling capability covering preparation, detection and analysis, containment, eradication, and recovery (IR-4); track and document incidents (IR-5); require personnel to report suspected incidents within a defined timeframe and report incident information to designated authorities (IR-6); provide an incident response support resource that offers advice and assistance to users (IR-7); develop an incident response plan that provides a roadmap, structure, and high-level approach (IR-8); respond to information spills with defined assignment of responsibility, identification of involved information, and corrective actions (IR-9); and operate an integrated information security analysis team for advanced threat scenarios where required (IR-10). The IR family supports compliance with FISMA reporting obligations under 44 U.S.C. § 3554 and aligns with NIST SP 800-61 Computer Security Incident Handling Guide.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-sp-800-53-rev5-ma-maintenance-family",
    "title": "NIST SP 800-53 Rev 5 - Maintenance (MA) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Maintenance (MA) (MA) family of NIST SP 800-53 Rev 5 contains 7 base controls (MA-1 onward) that establish the security and privacy obligations for maintenance. The MA family covers controlled maintenance (MA-2), maintenance tools (MA-3), nonlocal maintenance (MA-4), maintenance personnel (MA-5), and timely maintenance of critical components (MA-6). MA-1 establishes the policy framework. Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-sp-800-53-rev5-mp-media-protection-family",
    "title": "NIST SP 800-53 Rev 5 - Media Protection (MP) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Media Protection (MP) (MP) family of NIST SP 800-53 Rev 5 contains 8 base controls (MP-1 onward) that establish the security and privacy obligations for media protection. The MP family covers media access (MP-2), media marking (MP-3), media storage (MP-4), media transport (MP-5), media sanitization (MP-6), media use restrictions (MP-7), and media downgrading (MP-8). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-53-rev5-pe-physical-and-environmental-protection-family",
    "title": "NIST SP 800-53 Rev 5 - Physical and Environmental Protection (PE) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Physical and Environmental Protection (PE) (PE) family of NIST SP 800-53 Rev 5 contains 23 base controls (PE-1 onward) that establish the security and privacy obligations for physical and environmental protection. The PE family covers physical access authorizations (PE-2), physical access control (PE-3), access control for transmission (PE-4), access control for output devices (PE-5), monitoring physical access (PE-6), visitor access records (PE-8), emergency lighting (PE-12), fire protection (PE-13), environmental controls (PE-14), water damage protection (PE-15), and delivery and removal (PE-16). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-sp-800-53-rev5-pl-planning-family",
    "title": "NIST SP 800-53 Rev 5 - Planning (PL) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Planning (PL) (PL) family of NIST SP 800-53 Rev 5 contains 11 base controls (PL-1 onward) that establish the security and privacy obligations for planning. The PL family covers system security and privacy plans (PL-2), rules of behavior (PL-4), security and privacy architectures (PL-8), central management (PL-9), baseline selection (PL-10), and baseline tailoring (PL-11). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-53-rev5-pm-program-management-family",
    "title": "NIST SP 800-53 Rev 5 - Program Management (PM) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Program Management (PM) (PM) family of NIST SP 800-53 Rev 5 contains 32 base controls (PM-1 onward) that establish the security and privacy obligations for program management. The PM family is organization-level (not system-level) and includes the information security and privacy program plans (PM-1, PM-18), senior official roles (PM-2, PM-19), insider threat program (PM-12), risk management strategy (PM-9), enterprise architecture (PM-7), system inventory (PM-5), privacy impact and risk assessment (PM-26, PM-28), and threat awareness (PM-16). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-sp-800-53-rev5-ps-personnel-security-family",
    "title": "NIST SP 800-53 Rev 5 - Personnel Security (PS) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Personnel Security (PS) (PS) family of NIST SP 800-53 Rev 5 contains 9 base controls (PS-1 onward) that establish the security and privacy obligations for personnel security. The PS family covers position risk designation (PS-2), personnel screening (PS-3), personnel termination (PS-4), personnel transfer (PS-5), access agreements (PS-6), external personnel security (PS-7), and personnel sanctions (PS-8). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-53-rev5-pt-pii-processing-and-transparency-family",
    "title": "NIST SP 800-53 Rev 5 - PII Processing and Transparency (PT) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The PII Processing and Transparency (PT) (PT) family of NIST SP 800-53 Rev 5 contains 8 base controls (PT-1 onward) that establish the security and privacy obligations for pii processing and transparency. The PT family covers authority to process PII (PT-2), purpose specification (PT-3), consent (PT-4), privacy notices (PT-5), system of records notices (PT-6), specific categories of PII (PT-7), and computer matching requirements (PT-8). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-53-rev5-ra-risk-assessment-family",
    "title": "NIST SP 800-53 Rev 5 - Risk Assessment (RA) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Risk Assessment (RA) (RA) family of NIST SP 800-53 Rev 5 contains 10 base controls (RA-1 onward) that establish the security and privacy obligations for risk assessment. The RA family covers security categorization (RA-2), risk assessment (RA-3), vulnerability monitoring and scanning (RA-5), privacy impact assessments (RA-8), criticality analysis (RA-9), and threat hunting (RA-10). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-53-rev5-sa-system-and-services-acquisition-family",
    "title": "NIST SP 800-53 Rev 5 - System and Services Acquisition (SA) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The System and Services Acquisition (SA) (SA) family of NIST SP 800-53 Rev 5 contains 24 base controls (SA-1 onward) that establish the security and privacy obligations for system and services acquisition. The SA family covers allocation of resources for security (SA-2), system development life cycle (SA-3), acquisition process (SA-4), system documentation (SA-5), security and privacy engineering principles (SA-8), external system services (SA-9), developer configuration management (SA-10), developer testing and evaluation (SA-11), supply chain controls (SA-15), criticality analysis for acquisition (SA-22). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-sp-800-53-rev5-sc-system-and-communications-protection-family",
    "title": "NIST SP 800-53 Rev 5 - System and Communications Protection (SC) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The System and Communications Protection (SC) (SC) family of NIST SP 800-53 Rev 5 contains 51 base controls (SC-1 onward) that establish the security and privacy obligations for system and communications protection. The SC family is the largest in 800-53 r5 with 51 base controls. Key obligations include separation of system and user functionality (SC-2), security function isolation (SC-3), denial-of-service protection (SC-5), boundary protection (SC-7), transmission confidentiality and integrity (SC-8), network disconnect (SC-10), cryptographic key establishment and management (SC-12), cryptographic protection (SC-13), public key infrastructure certificates (SC-17), mobile code (SC-18), session authenticity (SC-23), and protection of information at rest (SC-28). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-sp-800-53-rev5-si-system-and-information-integrity-family",
    "title": "NIST SP 800-53 Rev 5 - System and Information Integrity (SI) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The System and Information Integrity (SI) (SI) family of NIST SP 800-53 Rev 5 contains 23 base controls (SI-1 onward) that establish the security and privacy obligations for system and information integrity. The SI family covers flaw remediation (SI-2), malicious code protection (SI-3), system monitoring (SI-4), security alerts and advisories (SI-5), security and privacy function verification (SI-6), software firmware and information integrity (SI-7), spam protection (SI-8), information input validation (SI-10), error handling (SI-11), information management and retention (SI-12), and memory protection (SI-16). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-sp-800-53-rev5-sr-supply-chain-risk-management-family",
    "title": "NIST SP 800-53 Rev 5 - Supply Chain Risk Management (SR) Family",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-12-10",
    "bluf": "The Supply Chain Risk Management (SR) (SR) family of NIST SP 800-53 Rev 5 contains 12 base controls (SR-1 onward) that establish the security and privacy obligations for supply chain risk management. The SR family is new in 800-53 Rev 5 and covers supply chain risk management plan (SR-2), supply chain controls and processes (SR-3), provenance (SR-4), acquisition strategies tools and methods (SR-5), supplier assessments and reviews (SR-6), supply chain operations security (SR-7), notification agreements (SR-8), tamper resistance and detection (SR-9), inspection of systems or components (SR-10), component authenticity (SR-11), and component disposal (SR-12). Control baselines are assigned in NIST SP 800-53B (low / moderate / high impact tailoring); assessment procedures are in NIST SP 800-53A. This family applies organization-wide and is referenced by FedRAMP, FISMA, CNSSI 1253, and the NIST Cybersecurity Framework 2.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-53b-control-baselines",
      "nist-sp-800-53a-rev5-security-assessment-procedures",
      "iso-27001-2022"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nist-sp-800-53a-rev5-security-assessment-procedures",
    "title": "NIST SP 800-53A Rev 5 - Assessing Security and Privacy Controls",
    "domain": "Workflow Automation",
    "version": "Rev 5 (January 2022)",
    "last_updated": "2026-05-09",
    "bluf": "NIST SP 800-53A Revision 5 (January 2022) provides the authoritative assessment procedures for all security and privacy controls in NIST SP 800-53 Rev 5; it defines three assessment methods (examine, interview, test), assessment objects (specifications, mechanisms, activities, individuals), and depth/coverage attributes (basic, focused, comprehensive) that together constitute the federal standard for security control assessment workflow - the foundation for FedRAMP authorisation packages, FISMA compliance, and DoD STIG-based assessments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-204b-zero-trust-microservices"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-sp-800-53b-control-baselines",
    "title": "Control Baselines for Information Systems and Organizations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-12-10",
    "bluf": "This publication provides security and privacy control baselines for the Federal Government. It establishes three security control baselines, one for each system impact level-low-impact, moderate-impact, and high-impact-as well as a privacy baseline that is applied to systems irrespective of impact level. These control baselines serve as a starting point for organizations in the security and privacy control selection process. The document provides tailoring guidance and a set of working assumptions that help guide and inform the control selection process, allowing organizations to customize their security and privacy control baselines to protect their critical and essential operations and assets.\n\nThe guidance is applicable to any organization that processes, stores, or transmits information, including federal, state, local, and tribal governments, as well as private sector organizations. For federal information systems, implementation of a minimum set of controls selected from NIST SP 800-53 is mandatory in accordance with the Federal Information Security Modernization Act (FISMA) and OMB Circular A-130. The core obligation involves categorizing systems by impact level, selecting the appropriate predefined control baseline, and then applying a tailoring process to align the controls more closely with specific organizational mission needs and risk assessments. This proactive and systematic approach helps ensure systems are sufficiently trustworthy and resilient to support the economic and national security interests of the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "fips-199-security-categorization",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-56b-key-establishment",
    "title": "Recommendation for Pair-Wise Key Establishment Using Integer Factorization Cryptography",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-03-01",
    "bluf": "This Recommendation specifies key-establishment schemes using integer factorization cryptography, in particular, RSA. The schemes are appropriate for use by the U.S. Federal Government to support cryptographic algorithms used in modern applications with automated key-establishment. Both key-agreement and key transport schemes are specified for pairs of entities, and methods for key confirmation are included to provide assurance that both parties share the same keying material. A key-establishment scheme can be characterized as either a key-agreement scheme, where the resultant secret keying material is a function of information contributed by two participants, or a key-transport scheme, whereby one party selects a value for the secret keying material and then securely distributes that value.\n\nThis document is intended for vendors implementing secure key-establishment using asymmetric algorithms in FIPS 140 validated modules. The security of the schemes relies on the intractability of factoring integers that are products of two sufficiently large, distinct prime numbers. The recommendation details the entire process, including the generation and validation of RSA key pairs, the establishment of a shared secret, derivation of keying material, and optional key confirmation. It also mandates security practices, such as the destruction of sensitive locally stored data after use, to limit opportunities for unauthorized access.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-57-key-management",
      "fips-140-3-cryptographic-modules"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-57-key-management",
    "title": "Recommendation for Key Management: Part 1 - General",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-05-01",
    "bluf": "This Recommendation provides cryptographic key-management guidance, focusing on general best practices for the management of cryptographic keying material. The proper management of cryptographic keys is essential to the effective use of cryptography for security, as poor key management may easily compromise strong algorithms. This guidance covers the management of a cryptographic key throughout its entire lifecycle, including its secure generation, storage, distribution, use, and destruction. Ultimately, the security of information protected by cryptography directly depends on the strength of the keys, the effectiveness of associated cryptographic mechanisms and protocols, and the protection afforded to the keys. Secret and private keys must be protected against unauthorized disclosure, and all keys need protection against modification. This guidance applies to U.S. government agencies protecting sensitive, unclassified information and may be used by non-governmental organizations on a voluntary basis. It is intended for developers and system administrators to support appropriate decisions when selecting and using cryptographic mechanisms, ensuring that real security is achieved rather than an illusion of it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-53-r5",
      "nist-sp-800-57-p2-r1",
      "nist-recommendation-key-management-pt3"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-sp-800-57-p2-r1",
    "title": "Recommendation for Key Management: Part 2 - Best Practices for Key Management Organizations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-05-01",
    "bluf": "NIST Special Publication (SP) 800-57 provides cryptographic key management guidance. Part 2 of this recommendation identifies the concepts, functions, and elements common to effective systems for the management of symmetric and asymmetric keys. It details the security planning requirements and documentation necessary for effective institutional key management, describes Key Management Specification requirements, and outlines the cryptographic Key Management Policy and Key Management Practice Statement documentation needed by organizations that use cryptography.\n\nThe primary audience for this guidance is U.S. government system owners and managers who are setting up or acquiring cryptographic key management capabilities. However, it is also intended to provide voluntary cybersecurity guidelines to the private sector. The document emphasizes that responsible key management is essential to the effective use of cryptographic mechanisms for protecting information technology systems. It requires that any organization employing cryptography to provide security services must have key management policy, practices, and planning documentation to ensure assurance that keys are authentic, belong to the asserted entity, and have not been accessed by unauthorized parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-800-88-sanitization"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-60-v2r1-appendices",
    "title": "Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2008-08-01",
    "bluf": "Developed by the National Institute of Standards and Technology (NIST) in response to the Federal Information Security Management Act (FISMA), this guideline assists Federal government agencies in categorizing their information and information systems. Its primary objective is to facilitate the provision of appropriate levels of information security according to a range of impact levels that might result from the unauthorized disclosure, modification, or loss of availability of information. The guidance is intended for use by federal agencies but may also be used by non-governmental organizations on a voluntary basis. This document, Volume II, contains the appendices which include security categorization recommendations and rationale for a wide range of mission-based, management, and support information types.\n\nThe core process outlined involves reviewing security categorization terms from FIPS 199, following a recommended categorization process, and using a methodology to identify types of Federal information. The appendices provide suggested provisional security impact levels for these common information types. The guideline also discusses information attributes that may lead to variances from these provisional assignments and describes how to establish an overall system security categorization based on the system’s use, connectivity, and the aggregate information it contains. The provisional impact level assignments are intended as the first step in a broader risk assessment process, not as a definitive checklist for auditors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-61-incident-response",
    "title": "NIST SP 800-61 Rev 2 - Computer Security Incident Handling Guide",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-08-21",
    "bluf": "This guide provides a comprehensive framework for U.S. federal agencies, and a best-practice model for all organizations, to establish and manage a computer security incident response capability. It details a four-phase incident response lifecycle: Preparation; Detection & Analysis; Containment, Eradication, & Recovery; and Post-Incident Activity, as outlined in Section 2.3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "guide-computer-security-log-management",
      "contingency-planning-guide-federal-systems",
      "cis-controls-v8",
      "data-integrity-detecting-responding-ransomware"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-61r2-incident-handling",
    "title": "Computer Security Incident Handling Guide",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2012-08-01",
    "bluf": "Computer security incident response has become an important component of information technology (IT) programs. Because performing incident response effectively is a complex undertaking, establishing a successful incident response capability requires substantial planning and resources. This publication assists organizations in establishing computer security incident response capabilities and handling incidents efficiently and effectively by providing guidelines for incident handling, particularly for analyzing incident-related data and determining the appropriate response to each incident. The guidelines can be followed independently of particular hardware platforms, operating systems, protocols, or applications.\n\nThe Federal Information Security Management Act (FISMA) requires Federal agencies to establish incident response capabilities. Organizations must create, provision, and operate a formal incident response capability, including creating an incident response policy and plan, developing procedures for incident handling, and establishing relationships with other groups. Federal law also requires Federal agencies to report incidents to the United States Computer Emergency Readiness Team (US-CERT). This guideline is prepared for use by Federal agencies, but may be used by nongovernmental organizations on a voluntary basis. It is intended for computer security incident response teams (CSIRTs), system and network administrators, security staff, and management responsible for preparing for or responding to security incidents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-200-minimum-security-requirements"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-61r3-incident-response-2024",
    "title": "Computer Security Incident Handling Guide (NIST Special Publication 800-61 Revision 3)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This publication provides guidelines for preparing for, detecting, analyzing, containing, eradicating, and recovering from cybersecurity incidents. It applies to all organizations that own, operate, or support federal information systems, as defined in Section 2.1 - Incident Response Lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-800-53-ac2",
      "nist-800-53-au2",
      "nist-800-53-sc7",
      "assessing-security-privacy-controls"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-sp-800-63b-authentication",
    "title": "Digital Identity Guidelines: Authentication and Lifecycle Management",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-03-02",
    "bluf": "These guidelines provide technical requirements for federal agencies implementing digital identity services, but may be used by non-governmental organizations on a voluntary basis. The guidelines focus on the authentication of subjects interacting with government systems over open networks, establishing that a given claimant is a subscriber who has been previously authenticated. The core obligation is to meet the requirements for a chosen Authenticator Assurance Level (AAL), which characterizes the strength of an authentication transaction. Stronger authentication, or a higher AAL, requires malicious actors to have better capabilities and expend greater resources to subvert the authentication process.\n\nThe document defines three levels. AAL1 provides some assurance that the claimant controls an authenticator, requiring either single-factor or multi-factor authentication. AAL2 provides high confidence and requires proof of possession and control of two different authentication factors using approved cryptographic techniques. AAL3 provides very high confidence, requiring authentication based on proof of possession of a key through a cryptographic protocol. AAL3 specifically requires a hardware-based authenticator that provides verifier impersonation resistance. The guidelines detail permitted authenticator types, authenticator and verifier requirements, reauthentication rules, and security controls for each AAL.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-63b-digital-identity"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-63b-digital-identity",
    "title": "NIST Special Publication 800-63B Digital Identity Guidelines: Authentication and Lifecycle Management",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-03-02",
    "bluf": "These guidelines provide technical requirements for federal agencies implementing digital identity services, focusing on the authentication of subjects interacting with government systems over open networks. The core obligation is to establish that a given claimant is a subscriber who has been previously authenticated. Digital authentication is the process of determining the validity of one or more authenticators used to claim a digital identity, establishing that a subject is in control of the technologies used to authenticate. For services in which return visits are applicable, successfully authenticating provides reasonable risk-based assurances that the subject accessing the service today is the same as the one who accessed the service previously.\n\nThe strength of an authentication transaction is characterized by an ordinal measurement known as the Authenticator Assurance Level (AAL). AAL1 provides some assurance that the claimant controls an authenticator, requiring either single-factor or multi-factor authentication. AAL2 provides high confidence and requires proof of possession and control of two different authentication factors through secure protocols. AAL3 provides very high confidence, is based on proof of possession of a key through a cryptographic protocol, and requires a hardware-based authenticator that provides verifier impersonation resistance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "fips-200-minimum-security-requirements",
      "nist-800-53-ia2",
      "fips-201-3-piv-federal-employees"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-70-r4-ncp",
    "title": "National Checklist Program for IT Products - Guidelines for Checklist Users and Developers",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2018-02-01",
    "bluf": "A security configuration checklist (also called a lockdown or hardening guide) is a series of instructions for configuring an IT product to a particular operational environment, verifying its configuration, and identifying unauthorized changes. Using well-written, standardized checklists can markedly reduce the vulnerability exposure of IT products. To facilitate the development and use of these checklists, NIST established the National Checklist Program (NCP), which maintains the National Checklist Repository, a publicly available resource containing information on a variety of security configuration checklists for specific IT products.\n\nThis document is intended for users and developers of security configuration checklists in both the public and private sectors. For users, it provides recommendations on selecting checklists from the repository, evaluating, testing, and applying them. For developers, it sets forth the policies, procedures, and general requirements for participation in the NCP. A core obligation is that Federal agencies are required to use appropriate security configuration checklists from the NCP when available, as stated in the Federal Acquisition Regulation (FAR). FISMA also requires Federal agencies to determine minimally acceptable system configuration requirements and ensure compliance, which these checklists facilitate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-82-ics-security",
    "title": "NIST SP 800-82 Rev 3: Guide to Operational Technology (OT) Security",
    "domain": "Industrial IoT & Energy",
    "version": "3.0.0",
    "last_updated": "2022-09-28",
    "bluf": "This guide provides tailored cybersecurity guidance for securing Industrial Control Systems (ICS) and Operational Technology (OT), addressing their unique requirements for performance, reliability, and safety. It outlines a comprehensive risk management approach, including OT-specific threats, vulnerabilities, and security controls, as detailed in Chapter 3 and the control overlays in Appendix G.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "assessing-security-privacy-controls",
      "c-scrm-practices-systems-organizations",
      "contingency-planning-federal-information-systems",
      "cis-controls-v8"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-sp-800-82-r3-ot-ics-security-guide-2023",
    "title": "NIST SP 800-82 Rev 3 Guide to Operational Technology Security 2023 - OT Threats, Vulnerabilities, Risk Management and Recommended Practices",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This guide provides comprehensive recommendations for securing Operational Technology (OT) and Industrial Control Systems (ICS) by establishing a tailored risk management program and applying security controls. It details OT-specific threats, vulnerabilities, and risk management strategies, with Chapter 5 providing an overlay of NIST SP 800-53 controls adapted for OT environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cyber-nist-800-53-ac2",
      "nist-800-53-sc7",
      "c-scrm-practices-systems-organizations",
      "contingency-planning-federal-information-systems"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nist-sp-800-82r3-ics-ot-security-2023",
    "title": "NIST Special Publication 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This publication provides guidelines for securing Industrial Control Systems (ICS), including Supervisory Control and Data Acquisition (SCADA) systems, Distributed Control Systems (DCS), and other control system configurations such as Programmable Logic Controllers (PLC). It applies to critical infrastructure operators and outlines risk-based strategies for identifying, protecting, detecting, responding to, and recovering from cyber threats targeting operational technology environments, with emphasis on Section 3.1 - ICS Risk Management Process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-800-53-ac2",
      "nist-800-53-au2",
      "nist-800-53-sc7",
      "c-scrm-practices-systems-organizations",
      "nerc-reliability-standards-compliance-overview"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nist-sp-800-82r3-ot-security",
    "title": "Guide to Operational Technology (OT) Security",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-09-20",
    "bluf": "This document provides guidance on how to secure operational technology (OT) while addressing their unique performance, reliability, and safety requirements. OT encompasses a broad range of programmable systems and devices that interact with the physical environment, such as industrial control systems (ICS), building automation systems, and transportation systems. It provides an overview of OT, identifies common threats and vulnerabilities, and recommends security countermeasures to mitigate associated risks. The guidance applies to organizations operating OT systems, including federal agencies and privately owned critical infrastructure, which are often highly interconnected and mutually dependent.\n\nThe core obligation is to establish a robust OT cybersecurity program as part of broader safety and reliability programs. Major security objectives include: restricting logical access to the OT network and systems using architectures like a demilitarized zone (DMZ); restricting physical access to OT networks and devices; protecting individual OT components from exploitation through measures like patch management and disabling unused ports; detecting security events; maintaining functionality during adverse conditions through redundancy and graceful degradation; and having the capability to restore and recover the system after an incident. An effective program should apply a defense-in-depth strategy, layering security mechanisms to minimize the impact of any single failure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-84-tte-programs",
    "title": "Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-09-30",
    "bluf": "This document provides guidance on designing, developing, conducting, and evaluating test, training, and exercise (TT&E) events so that organizations can improve their ability to prepare for, respond to, manage, and recover from adverse events that may affect their missions. It is intended for organizations with information technology (IT) plans, such as contingency and computer security incident response plans, that must be maintained in a state of readiness. This includes having personnel trained to fulfill their roles, plans exercised to validate their content, and systems tested to ensure their operability. The core obligation is for organizations to establish a comprehensive TT&E program because tests, training, and exercises are closely related and offer different ways of identifying deficiencies in IT plans, procedures, and training.\n\nThe guidance applies to single organizations, as opposed to large-scale events involving multiple entities. As part of creating a TT&E program, a plan should be developed that outlines the organization’s roadmap for ensuring a viable capability, including the development of a TT&E policy, identification of roles and responsibilities, establishment of an event schedule, and documentation of a TT&E event methodology. The types of events covered are tests (evaluation tools that use quantifiable metrics to validate IT system operability), training (informing personnel of their roles and responsibilities), tabletop exercises (discussion-based simulations), and functional exercises (performance-based simulations in a simulated operational environment).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-34-contingency-planning",
      "nist-sp-800-61r2-incident-handling",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-86-forensic-techniques",
    "title": "Guide to Integrating Forensic Techniques into Incident Response",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-08-01",
    "bluf": "Digital forensics is the application of science to the identification, collection, examination, and analysis of data while preserving the integrity of the information and maintaining a strict chain of custody for the data. This guide provides practical guidance on performing computer and network forensics to help organizations investigate computer security incidents and troubleshoot IT operational problems. Its focus is primarily on using forensic techniques to assist with computer security incident response, presenting forensics from an IT perspective rather than a law enforcement view. Practically every organization needs a capability to perform digital forensics; without it, an organization will have difficulty determining what events have occurred within its systems and networks, such as exposures of protected, sensitive data.\n\nThe forensic process comprises four basic phases: Collection, Examination, Analysis, and Reporting. The guidance applies to incident response teams, forensic analysts, system and security administrators, and computer security program managers. It details establishing a forensic capability, including developing policies and procedures that define roles, responsibilities, and appropriate use of forensic tools. The guide covers data sources including files, operating systems, network traffic, and applications, and provides recommendations for how multiple data sources can be used together to gain a better understanding of an event. Organizations should use this guide as a starting point for developing a forensic capability in conjunction with guidance from legal advisors, law enforcement, and management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-92-log-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-88-media-sanitization",
    "title": "Guidelines for Media Sanitization",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2014-12-01",
    "bluf": "This guide assists organizations and system owners in making practical media sanitization decisions based on the categorization of their information's confidentiality. Sanitization is a process that renders access to target data on media infeasible for a given level of effort. As data passes through multiple organizations and storage media, particularly in distributed cloud-based architectures, the potential for sensitive data to be collected and retained increases. The application of effective sanitization techniques is a critical aspect of ensuring sensitive data is protected against unauthorized disclosure. The responsibility for efficient information management, from inception through disposition, falls on all parties who handle the data. This responsibility is amplified by legal and ethical obligations to protect data such as Personally Identifiable Information (PII).\n\nAn organization must ensure that no easily re-constructible residual representation of data is stored on media after it has left the organization's control or is no longer protected at the data's original confidentiality categorization. This guideline specifies that an organization must sanitize or destroy information system digital media before its disposal or release for reuse. It provides a decision-making process and minimum recommendations for various media types, including hard copy, magnetic, flash-based, and optical media, categorizing sanitization actions as Clear, Purge, or Destroy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-90a-rev1-drbg",
    "title": "Recommendation for Random Number Generation Using Deterministic Random Bit Generators",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2015-06-01",
    "bluf": "This Recommendation specifies mechanisms for the generation of random bits using deterministic methods. The methods provided are based on either hash functions or block cipher algorithms. A Deterministic Random Bit Generator (DRBG) is based on a DRBG mechanism and includes a source of randomness. A DRBG mechanism uses an algorithm that produces a sequence of bits from an initial value that is determined by a seed, which in turn is determined from the output of the randomness source. Once the seed is provided and the initial value is determined, the DRBG is said to be instantiated and may be used to produce output. The seed used to instantiate the DRBG must contain sufficient entropy to provide an assurance of randomness. If the seed is kept secret, and the algorithm is well designed, the bits output by the DRBG will be unpredictable, up to the instantiated security strength of the DRBG. This publication has been developed by NIST to further its statutory responsibilities under the Federal Information Security Modernization Act (FISMA) of 2014, and may be used by non-governmental organizations on a voluntary basis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-197-advanced-encryption-standard",
      "secure-hash-standard-fips-180-4",
      "nist-sp-800-57-key-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp-800-92-log-management",
    "title": "Guide to Computer Security Log Management",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-09-01",
    "bluf": "A log is a record of the events occurring within an organization’s systems and networks. The number, volume, and variety of computer security logs have increased greatly, which has created the need for computer security log management-the process for generating, transmitting, storing, analyzing, and disposing of computer security log data. Log management is essential to ensuring that computer security records are stored in sufficient detail for an appropriate period of time. Routine log analysis is beneficial for identifying security incidents, policy violations, fraudulent activity, and operational problems. Logs are also useful when performing auditing and forensic analysis, supporting internal investigations, establishing baselines, and identifying operational trends and long-term problems. Organizations also may store and analyze certain logs to comply with Federal legislation and regulations, including the Federal Information Security Management Act of 2002 (FISMA).\n\nThis publication provides guidance for meeting log management challenges. Key recommendations include establishing policies and procedures for log management, prioritizing log management appropriately throughout the organization, creating and maintaining a secure log management infrastructure, and providing proper support for all staff with log management responsibilities. This guidance is for computer security staff, program managers, system administrators, and incident response teams responsible for performing duties related to computer security log management, particularly within Federal agencies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-53-au2",
      "nist-sp-800-53-r5",
      "nist-sp-800-61r2-incident-handling",
      "nist-sp-800-86-forensic-techniques",
      "cis-controls-v8"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nist-sp-800-97-ieee-802-11i",
    "title": "Establishing Wireless Robust Security Networks: A Guide to IEEE 802.11i",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2025-12-31",
    "bluf": "This guide seeks to assist organizations in better understanding the Institute of Electrical and Electronics Engineers (IEEE) 802.11 family of standards for wireless local area networks (WLANs), focusing on the security enhancements introduced in the IEEE 802.11i amendment. The IEEE 802.11i amendment introduces the concept of a Robust Security Network (RSN), a wireless security network that only allows the creation of Robust Security Network Associations (RSNAs). RSNAs are wireless connections providing moderate to high levels of assurance against WLAN security threats through cryptographic techniques. RSN components include stations (STAs) like laptops, access points (APs), and authentication servers (AS).\n\nNIST requires Federal agencies to use the Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP) for securing IEEE 802.11-based WLANs, as it uses the FIPS-approved Advanced Encryption Standard (AES). For legacy equipment without CCMP, auxiliary protection like an IPsec VPN is required. Organizations should carefully select authentication methods, using the Extensible Authentication Protocol (EAP) and the IEEE 802.1X standard instead of pre-shared keys (PSKs). The EAP-TLS method is recommended whenever possible. To ensure interoperability and security, organizations should procure WPA2 Enterprise certified products that use FIPS-approved encryption algorithms and have been FIPS-validated.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-197-advanced-encryption-standard",
      "nist-sp-800-63b-authentication"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-sp800-18-developing-security-plans",
    "title": "Guide for Developing Security Plans for Federal Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2006-02-01",
    "bluf": "The objective of system security planning is to improve protection of information system resources. All federal systems have some level of sensitivity and require protection as part of good management practice, and the protection of a system must be documented in a system security plan. This is a requirement of the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA). The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The plan also delineates responsibilities and expected behavior of all individuals who access the system.\n\nThe system security plan should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system. Management authorization to operate should be based on an assessment of management, operational, and technical controls documented in the security plan. By authorizing processing in a system, the manager accepts its associated risk. Re-authorization should occur whenever there is a significant change in processing, but at least every three years. This guidance applies to program managers, system owners, and security personnel responsible for developing, implementing, and managing federal information systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nist-ssdf-po-1-define-security-requirements-for-software-development",
    "title": "NIST SSDF Practice PO.1 - Define Security Requirements for Software Development",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PO.1 Define Security Requirements for Software Development from NIST SP 800-218 v1.1 directs organizations to: Ensure that security requirements for software development are known at all times so that they can be taken into account throughout the SDLC and duplication of effort can be minimized because the requirements information can be collected once and shared. This includes requirements from internal sources (e.g., the organization's policies, business objectives, and risk management strategy) and external sources (e.g., applicable laws and regulations). Implementation requires the following tasks: PO.1.1 Identify and document all security requirements for the organization's software development infrastructures and processes, and maintain the requirements over time; PO.1.2 Identify and document all security requirements for organization-developed software to meet, and maintain the requirements over time; PO.1.3 Communicate requirements to all third parties who will provide commercial software components to the organization for reuse by the organization's own software. Practice PO.1 sits within the Prepare the Organization (PO) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-po-2-implement-roles-and-responsibilities",
    "title": "NIST SSDF Practice PO.2 - Implement Roles and Responsibilities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PO.2 Implement Roles and Responsibilities from NIST SP 800-218 v1.1 directs organizations to: Ensure that everyone inside and outside of the organization involved in the SDLC is prepared to perform their SDLC-related roles and responsibilities throughout the SDLC. Implementation requires the following tasks: PO.2.1 Create new roles and alter responsibilities for existing roles as needed to encompass all parts of the SDLC; PO.2.2 Provide role-based training for all personnel with responsibilities that contribute to secure development; PO.2.3 Obtain upper management or authorizing official commitment to secure development, and convey that commitment to all with development-related roles and responsibilities. Practice PO.2 sits within the Prepare the Organization (PO) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-po-3-implement-supporting-toolchains",
    "title": "NIST SSDF Practice PO.3 - Implement Supporting Toolchains",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PO.3 Implement Supporting Toolchains from NIST SP 800-218 v1.1 directs organizations to: Use automation to reduce human effort and improve the accuracy, reproducibility, usability, and comprehensiveness of security practices throughout the SDLC, as well as provide a way to document and demonstrate the use of these practices. Toolchains and tools may be used at different levels of the organization, such as organization-wide or project-specific, and may address a particular part of the SDLC, like a build pipeline. Implementation requires the following tasks: PO.3.1 Specify which tools or tool types must or should be included in each toolchain to mitigate identified risks, as well as how the toolchain components are to be integrated with each other; PO.3.2 Follow recommended security practices to deploy, operate, and maintain tools and toolchains; PO.3.3 Configure tools to generate artifacts  of their support of secure software development practices as defined by the organization. Practice PO.3 sits within the Prepare the Organization (PO) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-po-4-define-and-use-criteria-for-software-security-checks",
    "title": "NIST SSDF Practice PO.4 - Define and Use Criteria for Software Security Checks",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PO.4 Define and Use Criteria for Software Security Checks from NIST SP 800-218 v1.1 directs organizations to: Help ensure that the software resulting from the SDLC meets the organization's expectations by defining and using criteria for checking the software's security during development. Implementation requires the following tasks: PO.4.1 Define criteria for software security checks and track throughout the SDLC; PO.4.2 Implement processes, mechanisms, etc. Practice PO.4 sits within the Prepare the Organization (PO) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-po-5-implement-and-maintain-secure-environments-for-software-development",
    "title": "NIST SSDF Practice PO.5 - Implement and Maintain Secure Environments for Software Development",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PO.5 Implement and Maintain Secure Environments for Software Development from NIST SP 800-218 v1.1 directs organizations to: Ensure that all components of the environments for software development are strongly protected from internal and external threats to prevent compromises of the environments or the software being developed or maintained within them. Examples of environments for software development include development, build, test, and distribution environments. Implementation requires the following tasks: PO.5.1 Separate and protect each environment involved in software development; PO.5.2 Secure and harden development endpoints (i. Practice PO.5 sits within the Prepare the Organization (PO) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-ps-1-protect-all-forms-of-code-from-unauthorized-access-and-tampering",
    "title": "NIST SSDF Practice PS.1 - Protect All Forms of Code from Unauthorized Access and Tampering",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PS.1 Protect All Forms of Code from Unauthorized Access and Tampering from NIST SP 800-218 v1.1 directs organizations to: Help prevent unauthorized changes to code, both inadvertent and intentional, which could circumvent or negate the intended security characteristics of the software. For code that is not intended to be publicly accessible, this helps prevent theft of the software and may make it more difficult or time-consuming for attackers to find vulnerabilities in the software. Implementation requires the following tasks: PS.1.1 Store all forms of code - including source code, executable code, and configuration-as-code -  based on the principle of least privilege so that only authorized personnel, tools, services, etc. Practice PS.1 sits within the Protect the Software (PS) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-ps-2-provide-a-mechanism-for-verifying-software-release-integrity",
    "title": "NIST SSDF Practice PS.2 - Provide a Mechanism for Verifying Software Release Integrity",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PS.2 Provide a Mechanism for Verifying Software Release Integrity from NIST SP 800-218 v1.1 directs organizations to: Help software acquirers ensure that the software they acquire is legitimate and has not been tampered with. Implementation requires the following tasks: PS.2.1 Make software integrity verification information available to software acquirers. Practice PS.2 sits within the Protect the Software (PS) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-ps-3-archive-and-protect-each-software-release",
    "title": "NIST SSDF Practice PS.3 - Archive and Protect Each Software Release",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PS.3 Archive and Protect Each Software Release from NIST SP 800-218 v1.1 directs organizations to: Preserve software releases in order to help identify, analyze, and eliminate vulnerabilities discovered in the software after release. Implementation requires the following tasks: PS.3.1 Securely archive the necessary files and supporting data (e; PS.3.2 Collect, safeguard, maintain, and share provenance data for all components of each software release (e. Practice PS.3 sits within the Protect the Software (PS) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-pw-1-design-software-to-meet-security-requirements-and-mitigate-security-ri",
    "title": "NIST SSDF Practice PW.1 - Design Software to Meet Security Requirements and Mitigate Security Risks",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PW.1 Design Software to Meet Security Requirements and Mitigate Security Risks from NIST SP 800-218 v1.1 directs organizations to: Identify and evaluate the security requirements for the software; determine what security risks the software is likely to face during operation and how the software's design and architecture should mitigate those risks; and justify any cases where risk-based analysis indicates that security requirements should be relaxed or waived. Addressing security requirements and risks during software design (secure by design) is key for improving software security and also helps improve development efficiency. Implementation requires the following tasks: PW.1.1 Use forms of risk modeling - such as threat modeling, attack modeling, or attack surface mapping - to help assess the security risk for the software; PW.1.2 Track and maintain the software's security requirements, risks, and design decisions; PW.1.3 Where appropriate, build in support for using standardized security features and services (e. Practice PW.1 sits within the Produce Well-Secured Software (PW) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-pw-2-review-the-software-design-to-verify-compliance-with-security-requirem",
    "title": "NIST SSDF Practice PW.2 - Review the Software Design to Verify Compliance with Security Requirements and Risk Information",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PW.2 Review the Software Design to Verify Compliance with Security Requirements and Risk Information from NIST SP 800-218 v1.1 directs organizations to: Help ensure that the software will meet the security requirements and satisfactorily address the identified risk information. Implementation requires the following tasks: PW.2.1 Have 1) a qualified person (or people) who were not involved with the design and/or 2) automated processes instantiated in the toolchain review the software design to confirm and enforce that it meets all of the security requirements and satisfactorily addresses the identified risk information. Practice PW.2 sits within the Produce Well-Secured Software (PW) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-pw-4-reuse-existing-well-secured-software-when-feasible-instead-of-duplicat",
    "title": "NIST SSDF Practice PW.4 - Reuse Existing, Well-Secured Software When Feasible Instead of Duplicating Functionality",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PW.4 Reuse Existing, Well-Secured Software When Feasible Instead of Duplicating Functionality from NIST SP 800-218 v1.1 directs organizations to: Lower the costs of software development, expedite software development, and decrease the likelihood of introducing additional security vulnerabilities into the software by reusing software modules and services that have already had their security posture checked. This is particularly important for software that implements security functionality, such as cryptographic modules and protocols. Implementation requires the following tasks: PW.4.1 Acquire and maintain well-secured software components (e; PW.4.2 Create and maintain well-secured software components in-house following SDLC processes to meet common internal software development needs that cannot be better met by third-party software components; PW.4.4 Verify that acquired commercial, open-source, and all other third-party software components comply with the requirements, as defined by the organization, throughout their life cycles. Practice PW.4 sits within the Produce Well-Secured Software (PW) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-pw-5-create-source-code-by-adhering-to-secure-coding-practices",
    "title": "NIST SSDF Practice PW.5 - Create Source Code by Adhering to Secure Coding Practices",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PW.5 Create Source Code by Adhering to Secure Coding Practices from NIST SP 800-218 v1.1 directs organizations to: Decrease the number of security vulnerabilities in the software, and reduce costs by minimizing vulnerabilities introduced during source code creation that meet or exceed organization-defined vulnerability severity criteria. Implementation requires the following tasks: PW.5.1 Follow all secure coding practices that are appropriate to the development languages and environment to meet the organization's requirements. Practice PW.5 sits within the Produce Well-Secured Software (PW) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-pw-6-configure-the-compilation-interpreter-and-build-processes-to-improve-e",
    "title": "NIST SSDF Practice PW.6 - Configure the Compilation, Interpreter, and Build Processes to Improve Executable Security",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PW.6 Configure the Compilation, Interpreter, and Build Processes to Improve Executable Security from NIST SP 800-218 v1.1 directs organizations to: Decrease the number of security vulnerabilities in the software and reduce costs by eliminating vulnerabilities before testing occurs. Implementation requires the following tasks: PW.6.1 Use compiler, interpreter, and build tools that offer features to improve executable security; PW.6.2 Determine which compiler, interpreter, and build tool features should be used and how each should be configured, then implement and use the approved configurations. Practice PW.6 sits within the Produce Well-Secured Software (PW) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-pw-7-review-andor-analyze-human-readable-code-to-identify-vulnerabilities-a",
    "title": "NIST SSDF Practice PW.7 - Review and/or Analyze Human-Readable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PW.7 Review and/or Analyze Human-Readable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements from NIST SP 800-218 v1.1 directs organizations to: Help identify vulnerabilities so that they can be corrected before the software is released to prevent exploitation. Using automated methods lowers the effort and resources needed to detect vulnerabilities. Human-readable code includes source code, scripts, and any other form of code that an organization deems human-readable. Implementation requires the following tasks: PW.7.1 Determine whether code review (a person looks directly at the code to find issues) and/or code analysis (tools are used to find issues in code, either in a fully automated way or in conjunction with a person) should be used, as defined by the organization; PW.7.2 Perform the code review and/or code analysis based on the organization's secure coding standards, and record and triage all discovered issues and recommended remediations in the development team's workflow or issue tracking system. Practice PW.7 sits within the Produce Well-Secured Software (PW) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-pw-8-test-executable-code-to-identify-vulnerabilities-and-verify-compliance",
    "title": "NIST SSDF Practice PW.8 - Test Executable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PW.8 Test Executable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements from NIST SP 800-218 v1.1 directs organizations to: Help identify vulnerabilities so that they can be corrected before the software is released in order to prevent exploitation. Using automated methods lowers the effort and resources needed to detect vulnerabilities and improves traceability and repeatability. Executable code includes binaries, directly executed bytecode and source code, and any other form of code that an organization deems executable. Implementation requires the following tasks: PW.8.1 Determine whether executable code testing should be performed to find vulnerabilities not identified by previous reviews, analysis, or testing and, if so, which types of testing should be used; PW.8.2 Scope the testing, design the tests, perform the testing, and document the results, including recording and triaging all discovered issues and recommended remediations in the development team's workflow or issue tracking system. Practice PW.8 sits within the Produce Well-Secured Software (PW) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-pw-9-configure-software-to-have-secure-settings-by-default",
    "title": "NIST SSDF Practice PW.9 - Configure Software to Have Secure Settings by Default",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice PW.9 Configure Software to Have Secure Settings by Default from NIST SP 800-218 v1.1 directs organizations to: Help improve the security of the software at the time of installation to reduce the likelihood of the software being deployed with weak security settings, putting it at greater risk of compromise. Implementation requires the following tasks: PW.9.1 Define a secure baseline by determining how to configure each setting that has an effect on security or a security-related setting so that the default settings are secure and do not weaken the security functions provided by the platform, network infrastructure, or services; PW.9.2 Implement the default settings (or groups of default settings, if applicable), and document each setting for software administrators. Practice PW.9 sits within the Produce Well-Secured Software (PW) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-rv-1-identify-and-confirm-vulnerabilities-on-an-ongoing-basis",
    "title": "NIST SSDF Practice RV.1 - Identify and Confirm Vulnerabilities on an Ongoing Basis",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice RV.1 Identify and Confirm Vulnerabilities on an Ongoing Basis from NIST SP 800-218 v1.1 directs organizations to: Help ensure that vulnerabilities are identified more quickly so that they can be remediated more quickly in accordance with risk, reducing the window of opportunity for attackers. Implementation requires the following tasks: RV.1.1 Gather information from software acquirers, users, and public sources on potential vulnerabilities in the software and third-party components that the software uses, and investigate all credible reports; RV.1.2 Review, analyze, and/or test the software's code to identify or confirm the presence of previously undetected vulnerabilities; RV.1.3 Have a policy that addresses vulnerability disclosure and remediation, and implement the roles, responsibilities, and processes needed to support that policy. Practice RV.1 sits within the Respond to Vulnerabilities (RV) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-rv-2-assess-prioritize-and-remediate-vulnerabilities",
    "title": "NIST SSDF Practice RV.2 - Assess, Prioritize, and Remediate Vulnerabilities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice RV.2 Assess, Prioritize, and Remediate Vulnerabilities from NIST SP 800-218 v1.1 directs organizations to: Help ensure that vulnerabilities are remediated in accordance with risk to reduce the window of opportunity for attackers. Implementation requires the following tasks: RV.2.1 Analyze each vulnerability to gather sufficient information about risk to plan its remediation or other risk response; RV.2.2 Plan and implement risk responses for vulnerabilities. Practice RV.2 sits within the Respond to Vulnerabilities (RV) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-ssdf-rv-3-analyze-vulnerabilities-to-identify-their-root-causes",
    "title": "NIST SSDF Practice RV.3 - Analyze Vulnerabilities to Identify Their Root Causes",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-02-03",
    "bluf": "SSDF Practice RV.3 Analyze Vulnerabilities to Identify Their Root Causes from NIST SP 800-218 v1.1 directs organizations to: Help reduce the frequency of vulnerabilities in the future. Implementation requires the following tasks: RV.3.1 Analyze identified vulnerabilities to determine their root causes; RV.3.2 Analyze the root causes over time to identify patterns, such as a particular secure coding practice not being followed consistently; RV.3.3 Review the software for similar vulnerabilities to eradicate a class of vulnerabilities, and proactively fix them rather than waiting for external reports; RV.3.4 Review the SDLC process, and update it if appropriate to prevent (or reduce the likelihood of) the root cause recurring in updates to the software or in new software that is created. Practice RV.3 sits within the Respond to Vulnerabilities (RV) group and is operationalized through the actionable schema and deterministic workflow below. Notional implementation examples in NIST SP 800-218 illustrate how organizations can meet each task, and the cited references include guidance from BSA, BSIMM, CISA, ISO/IEC 27034, OWASP SAMM, and PCI Software Security Framework that inform implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-161-r1-supply-chain-risk-management",
      "iso-27001-2022",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nist-telehealth-smart-home-integration",
    "title": "Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2025-12-17",
    "bluf": "This paper introduces a notional high-level smart home integration reference architecture to better understand cybersecurity and privacy risks associated with Hospital-at-Home (HaH) deployments in the context of an integrated smart home environment, focusing on voice assistants (e.g., smart speakers) as a representative Internet of Things (IoT) device. The guidelines are intended for technologists and information security professionals who work in healthcare delivery organizations (HDOs), including hospitals, clinics, or other healthcare facilities that may implement HaH solutions for their patients. Adversaries may exploit patient-owned IoT devices and home network infrastructures as entry points into an HDO’s broader environment.\n\nTo address these risks, this paper leverages the NIST Cybersecurity and Privacy Frameworks and NIST IoT Core Baseline to outline mitigation efforts for HDOs. The core obligations and recommended mitigations include access control, authentication, continuous monitoring, data security, governance, and network segmentation. A core theme calls upon HDOs to ensure network segmentation between medical or biometric devices and other environments to impede a threat actor’s ability to compromise an endpoint and impact other devices. Other key protections include implementing data security encryption for both data-in-transit and data-at-rest to maintain data confidentiality and integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-207",
      "nist-800-53-sc7",
      "fips-197-advanced-encryption-standard",
      "nistir-8228-iot-cybersecurity-risks",
      "guide-telework-remote-access-byod",
      "nist-sp-1800-8-infusion-pumps"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nistir-7298r3-glossary-security-terms",
    "title": "Glossary of Key Information Security Terms",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-07-01",
    "bluf": "This publication, NISTIR 7298 Revision 3, describes an easily-accessible repository of terms and definitions extracted verbatim from National Institute of Standards and Technology (NIST) publications and Committee on National Security Systems (CNSS) Instruction 4009. The repository, referred to as 'the Glossary,' consists of an online user interface application and an underlying relational database. The database contains terms and definitions from NIST Federal Information Processing Standard Publications (FIPS), Special Publication (SP) 800 series, select NIST Interagency or Internal Reports (NISTIRs), and CNSSI-4009. It does not contain definitions without a source publication, and terms from draft documents are not included as they are not stable.\n\nThe Glossary is intended to help users understand terminology, recognize when and where multiple definitions may exist, and identify a definition that they can use. By providing this central resource, NIST aims to help standardize terms and definitions, reducing confusion and the tendency to create unique definitions for different situations. The publication provides an overview of the Glossary's design, methodology, and the structure of its database. It is intended for a technical audience interested in the Glossary's structure or anyone interested in its purpose and development. Users interested only in the terms and definitions are encouraged to use the online application directly.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nistir-7628-smartgrid",
    "title": "Smart Grid Security Framework",
    "domain": "Industrial IoT & Energy",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "NISTIR 7628 Revision 1 (2014) provides the definitive cybersecurity guidelines for smart grid systems, covering all functional domains from bulk generation to consumer premises. It defines 189 high-level security requirements across seven categories (Smart Grid Cybersecurity Strategy, Architecture, and High-Level Requirements) and maps them to logical interfaces between smart grid components. Utilities, energy operators, grid equipment manufacturers, and AI agents managing smart grid infrastructure must apply NISTIR 7628 alongside NERC CIP for bulk electric systems and IEC 62443 for industrial control components. Failure to implement these controls exposes critical national infrastructure to cyberattacks with potential for widespread power outages.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nerc-cip-v6-cyber",
      "iec-62443-iacs",
      "nist-sp-1800-32-securing-ders"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nistir-8006-cloud-forensic-challenges",
    "title": "NIST Cloud Computing Forensic Science Challenges",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2020-08-31",
    "bluf": "This document summarizes research performed by the members of the NIST Cloud Computing Forensic Science Working Group and aggregates, categorizes, and discusses the forensics challenges faced by experts when responding to incidents that have occurred in a cloud-computing ecosystem. The challenges are presented along with the associated literature that references them. The immediate goal of the document is to begin a dialogue on forensic science concerns in cloud computing ecosystems, with the long-term goal of gaining a deeper understanding of those concerns and identifying technologies and standards that can mitigate them.\nWith the rapid adoption of cloud computing technology, a need has arisen for the application of digital forensic science to this domain. The validity and reliability of forensic science is crucial in this new context and requires new methodologies for identifying, collecting, preserving, and analyzing evidence in multi-tenant cloud environments. This is necessary to support U.S. criminal justice and civil litigation systems as well as to provide capabilities for security incident response and internal enterprise operations. The document categorizes challenges into nine major groups: Architecture, Data collection, Analysis, Anti-forensics, Incident first responders, Role management, Legal, Standards, and Training.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-145-cloud-computing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nistir-8114-lightweight-cryptography",
    "title": "NISTIR 8114 Report on Lightweight Cryptography",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2017-03-31",
    "bluf": "NIST-approved cryptographic standards were designed to perform well on general-purpose computers, but their performance may not be acceptable for the increasing number of small, resource-constrained computing devices found in areas like the Internet of Things (IoT), sensor networks, and healthcare. Many modern cryptographic algorithms cannot be implemented in these constrained devices. In response, NIST initiated a lightweight cryptography project to investigate the issues and develop a strategy for the standardization of lightweight cryptographic algorithms.\n\nThis report provides an overview of the project and outlines NIST's plan to create a portfolio of lightweight algorithms through an open process. Instead of a one-size-fits-all standard, NIST will develop 'profiles' that capture the specific physical, performance, and security requirements imposed by various devices and applications. Algorithms will be evaluated and recommended for use only within the context of these specific profiles. The report solicits feedback from stakeholders to help define these requirements and profiles, marking the initial phase of a long-term effort to approve and maintain a portfolio of algorithms suitable for constrained environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-197-advanced-encryption-standard",
      "nist-sp-800-57-key-management",
      "nist-sp-800-131a-rev-2-crypto-transitions",
      "nistir-8259a-iot-device-cybersecurity",
      "nist-sp-800-213-iot-guidance"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nistir-8183-manufacturing-profile",
    "title": "NISTIR 8183 Cybersecurity Framework Manufacturing Profile",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-05-20",
    "bluf": "This document provides the Cybersecurity Framework (CSF) implementation details developed for the manufacturing environment. The “Manufacturing Profile” of the Cybersecurity Framework can be used as a roadmap for reducing cybersecurity risk for manufacturers that is aligned with manufacturing sector goals and industry best practices. This Manufacturing Profile provides a voluntary, risk-based approach for managing cybersecurity activities and reducing cyber risk to manufacturing systems. The Profile is meant to enhance but not replace current cybersecurity standards and industry guidelines that the manufacturer is embracing.\n\nThe Profile gives manufacturers a method to identify opportunities for improving their current cybersecurity posture, an evaluation of their ability to operate the control environment at an acceptable risk level, and a standardized approach to preparing a cybersecurity plan. It is built around the five primary functional areas of the Cybersecurity Framework: Identify, Protect, Detect, Respond, and Recover. There are 98 distinct security objectives within these areas that comprise a starting point from which to develop a manufacturer-specific Profile at defined risk levels of Low, Moderate, and High. The Profile focuses on desired cybersecurity outcomes and provides a prioritization of security activities to meet specific business and mission goals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-82r3-ot-security",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-53-r5",
      "nist-sp-1800-10-ics-integrity"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nistir-8228-iot-cybersecurity-risks",
    "title": "NISTIR 8228 Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-06-01",
    "bluf": "The Internet of Things (IoT) is a rapidly evolving and expanding collection of diverse technologies that interact with the physical world. The purpose of this publication is to help federal agencies and other organizations better understand and manage the cybersecurity and privacy risks associated with their individual IoT devices throughout the devices’ lifecycles. Many organizations are not necessarily aware of the large number of IoT devices they are already using and how these devices affect cybersecurity and privacy risks differently than conventional information technology (IT) devices do. The primary audience for this publication is personnel at federal agencies with responsibilities related to managing cybersecurity and privacy risks for IoT devices, although personnel at other organizations and IoT device manufacturers may also find value in the content.\n\nThis publication provides insights to inform organizations’ risk management processes, identifying three high-level considerations: 1) Many IoT devices interact with the physical world in ways conventional IT devices usually do not, requiring explicit recognition of impacts to physical systems. 2) Many IoT devices cannot be accessed, managed, or monitored in the same ways conventional IT devices can, necessitating new approaches. 3) The availability, efficiency, and effectiveness of cybersecurity and privacy capabilities are often different for IoT devices. Organizations should address these risk considerations and challenges throughout the IoT device lifecycle by adjusting organizational policies and processes and implementing updated mitigation practices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-53-r5",
      "nist-sp-800-183-networks-of-things",
      "nistir-8259a-iot-device-cybersecurity",
      "nist-sp-800-213-iot-guidance",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nistir-8259-iot-device-manufacturers",
    "title": "Foundational Cybersecurity Activities for IoT Device Manufacturers",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2020-05-01",
    "bluf": "This publication provides recommendations for manufacturers to improve the securability of the Internet of Things (IoT) devices they create. Many IoT devices lack cybersecurity capabilities that customers can use to mitigate risks. Manufacturers can assist customers by providing necessary cybersecurity functionality and related information. This document outlines six recommended foundational cybersecurity activities for manufacturers to consider before their devices are sold. These activities aim to lessen the cybersecurity efforts required by customers, thereby reducing the prevalence and severity of IoT device compromises and subsequent attacks. The core obligation for manufacturers is to carefully consider which device cybersecurity capabilities to design into their products for customers to use in managing their risks. The primary audience is IoT device manufacturers, but the content may also be useful for IoT device customers seeking to understand available device cybersecurity capabilities and the information manufacturers might provide.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nistir-8259a-iot-device-cybersecurity",
      "nistir-8228-iot-cybersecurity-risks"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nistir-8259a-iot-device-cybersecurity",
    "title": "NISTIR 8259A IoT Device Cybersecurity Capability Core Baseline",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2020-05-31",
    "bluf": "This publication defines an Internet of Things (IoT) device cybersecurity capability core baseline, which is a set of device capabilities generally needed to support common cybersecurity controls that protect an organization’s devices as well as device data, systems, and ecosystems. The purpose of this publication is to provide organizations a starting point to use in identifying the device cybersecurity capabilities for new IoT devices they will manufacture, integrate, or acquire. The main audience for this publication is IoT device manufacturers, but it may also help IoT device customers or integrators.\n\nThe core baseline has been derived from researching common cybersecurity risk management approaches and commonly used capabilities for addressing cybersecurity risks to IoT devices. These capabilities were developed in the context of NISTIR 8259, Foundational Cybersecurity Activities for IoT Device Manufacturers. This baseline is intended to give all organizations a starting point for IoT device cybersecurity risk management, but the implementation of all capabilities is not considered mandatory. It is left to the implementing organization to understand the unique risk context in which it operates and what is appropriate for its given circumstance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nistir-8228-iot-cybersecurity-risks",
      "nist-ir-8259b-iot-non-technical-baseline",
      "nist-sp-800-213-iot-guidance",
      "nist-ir-8425-iot-core-baseline-profile",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nistir-8312-explainable-ai-principles",
    "title": "NISTIR 8312 Four Principles of Explainable Artificial Intelligence",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2021-09-01",
    "bluf": "This document introduces four principles for explainable artificial intelligence (AI) that comprise fundamental properties for explainable AI systems. For AI systems that are intended or required to be explainable, it is proposed that they adhere to these principles. First, a system must deliver accompanying evidence or reasons for its outcomes and processes (Explanation). Second, these explanations must be understandable to the individual users they are intended for (Meaningful). Third, the explanation must correctly reflect the system’s actual process for generating the output (Explanation Accuracy). Finally, the system must only operate under the conditions for which it was designed and when it reaches sufficient confidence in its output (Knowledge Limits).\n\nThese principles were developed to encompass the multidisciplinary nature of explainable AI and are heavily influenced by the AI system’s interaction with the human recipient. The requirements of a given situation, the task at hand, and the consumer will all influence the type of explanation deemed appropriate. These situations can include regulatory and legal requirements, quality control, and customer relations. The principles allow for defining the contextual factors to consider for an explanation and act as a roadmap for future measurement and evaluation activities. This work is part of a larger NIST portfolio around trustworthy AI, which also includes characteristics like accuracy, privacy, reliability, robustness, safety, security, mitigation of harmful bias, transparency, fairness, and accountability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "oecd-ai-principles",
      "nist-sp-1270-managing-ai-bias"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nistir-8419-supply-chain-traceability",
    "title": "Blockchain and Related Technologies to Support Manufacturing Supply Chain Traceability: Needs and Industry Perspectives",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-04-30",
    "bluf": "This publication explores the issues surrounding supply chain traceability, assessing the role blockchain and related technologies can play in its improvement. It targets all stakeholders in the U.S. national manufacturing supply chain, including businesses, regulatory agencies, standards bodies, researchers, and consumers, particularly those involved with operational technology (OT) and industrial control systems (ICS). The core finding is that traceability, including pedigree and provenance records, must be shared via multi-lateral ecosystems of supply chain participants to overcome the limitations of traditional bi-lateral message exchanges. These ecosystems can leverage blockchain technology to cryptographically ensure that traceability records are properly attributed, tamper-evident, and cannot be deleted, thereby mitigating risks from logistical disruptions, fraud, and sabotage.\n\nThe document proposes an ecosystem-oriented perspective layered atop the existing 'per acquirer' view in supply chain risk management. This approach is necessary to enable multi-lateral information sharing and migrate from linear information flows. By establishing ecosystem-wide agreement on traceability requirements, organizations can mitigate semantic gaps and issues with trust transitivity. Achieving this requires linking physical objects to cyber records, cooperation across the supply chain to read and write traceability records, and sufficient incentives to motivate adoption and achieve a Minimum Viable Ecosystem (MVE). The publication analyzes several case studies and identifies key areas for future research, including identity, message content standards, barriers to entry, and ecosystem interoperability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-161r1-csrm-practices",
      "nistir-8183-manufacturing-profile",
      "nist-sp-800-82r3-ot-security",
      "nist-ir-8276-cyber-scrm-practices"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nl-aanbestedingswet-2012",
    "title": "Netherlands Aanbestedingswet 2012 (Public Procurement Act)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Aanbestedingswet 2012 is the Dutch Public Procurement Act, in force from 1 April 2013 and substantially amended in 2016 to transpose EU Directives 2014/23/EU, 2014/24/EU and 2014/25/EU. It is structured in Deel 1 (Algemene bepalingen), Deel 2 (Overheidsopdrachten - public contracts), Deel 2a (Concessieopdrachten), Deel 3 (Speciale-sectoropdrachten - utilities) and Deel 4 (Overige bepalingen). Article 1.1 contains the definitions, including aanbestedende dienst (contracting authority), ondernemer (economic operator) and overheidsopdracht (public contract). Article 1.4 establishes that contracting authorities must determine procurement methods and select suppliers on the basis of objective criteria while maximising maatschappelijke waarde (societal value). Article 1.8 requires equal and non-discriminatory treatment of suppliers. Article 1.9 requires transparency. Articles 2.25 to 2.33 govern the procedure types - openbare procedure (open), niet-openbare procedure (restricted), mededingingsprocedure met onderhandeling (competitive procedure with negotiation), concurrentiegerichte dialoog (competitive dialogue) and innovatiepartnerschap (innovation partnership). Article 2.86 lists the mandatory exclusion grounds. Article 2.114 governs award criteria, including the EMVI (Economisch Meest Voordelige Inschrijving - most economically advantageous tender).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-public-procurement-construction-directive",
      "uncitral-model-law-public-procurement-2011"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nl-uavg-gdpr-implementation-2018",
    "title": "Netherlands GDPR Implementation Act 2018 (Uitvoeringswet Algemene verordening gegevensbescherming - UAVG)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The UAVG (Uitvoeringswet Algemene verordening gegevensbescherming - Implementation Act for the General Data Protection Regulation) is the Netherlands' national statute implementing and supplementing the EU General Data Protection Regulation (GDPR - Regulation 2016/679). The UAVG entered into force on 25 May 2018, the same date as the GDPR. The UAVG repeals the predecessor Wet bescherming persoonsgegevens (Wbp - Data Protection Act 2001) and designates the Autoriteit Persoonsgegevens (AP - Dutch Data Protection Authority) as the national supervisory authority under GDPR Article 51. The UAVG exercises national margin-of-appreciation derogations permitted under the GDPR to address Dutch-specific contexts. Article 22 UAVG (implementing GDPR Article 88) permits employers to process employee personal data without consent for legitimate employment purposes including personnel management, performance monitoring, safety monitoring, and access control, provided processing is proportionate and limited to what is necessary for the stated purpose. Article 30 UAVG provides a derogation permitting processing of health data by healthcare providers, health insurers, and research institutions without the data subject's explicit consent where necessary for medical care or public health purposes pursuant to Union or Member State law. Article 32 UAVG permits processing of criminal offence data by entities other than competent authorities only under exceptional circumstances including employers conducting criminal background checks in high-risk positions and debt collection agencies. Article 41 UAVG requires explicit consent or substantial public interest for processing of biometric data for unique identification purposes, going beyond the GDPR Article 9 framework in specifying that biometric data processed for unique identification (as opposed to verification) requires a specific legal basis under Dutch law. Article 46 UAVG restricts criminal records data processing to competent authorities plus narrowly defined private sector entities. The AP is empowered to impose administrative fines aligned with the GDPR Article 83 two-tier penalty structure: up to EUR 10 million or 2% of global annual turnover for violations of data controller/processor obligations; up to EUR 20 million or 4% of global annual turnover for violations of fundamental principles, data subject rights, and international transfer rules. Criminal sanctions for certain UAVG violations are maintained under the Wet op de economische delicten (WED). Notable AP enforcement actions include a EUR 525,000 fine against Haga Ziekenhuis hospital (2019) for inadequate access logging to patient records, a EUR 750,000 fine against DUO (Dienst Uitvoering Onderwijs) for unlawful student risk profiling (2021), and a EUR 3.7 million fine against Uber BV (2023) for transferring driver data to the United States without adequate safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nl-wft-financial-supervision-act-2006",
    "title": "Netherlands Financial Supervision Act 2006 (Wet op het financieel toezicht - Wft)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Wft (Wet op het financieel toezicht - Financial Supervision Act) is the Netherlands' comprehensive financial services regulatory framework, enacted by Act of 28 September 2006 (Staatsblad 2006, 475) and in force since 1 January 2007. The Wft consolidated the regulatory framework previously spread across six separate Acts (including the Wet toezicht kredietwezen, Wet toezicht effectenverkeer, and Wet toezicht verzekeringsbedrijf) into a single statute covering banking, insurance, investment services, mortgage credit, financial products, and capital market activities. The Wft operates under a dual supervisory model: De Nederlandsche Bank (DNB) exercises prudential supervision (prudentieel toezicht) over capital adequacy, liquidity, solvency, and systemic risk; the Autoriteit Financiële Markten (AFM) exercises conduct-of-business supervision (gedragstoezicht) covering market integrity, investor protection, product governance, and market conduct. The Wft is organised in five main parts. Part 2 (Articles 2:1 ff.) establishes licensing and market access requirements: financial service providers, banks, insurers, investment firms, payment institutions, and other regulated entities must obtain a licence from AFM or DNB before commencing operations. Part 4 (Articles 4:1 ff.) establishes conduct-of-business obligations including the duty to act in the interests of the customer (zorgplicht - duty of care), suitability and appropriateness requirements for investment advice and discretionary management, best execution obligations, disclosure of costs and charges, conflicts of interest management, and complaint handling. Part 5 (Articles 5:1 ff.) governs market transparency including issuer disclosure obligations, inside information management, market abuse prohibition, and major shareholding notification thresholds. The Wft implements and supplements multiple EU financial services Directives and Regulations including MiFID II (2014/65/EU), MiFIR (600/2014), the Capital Requirements Directive IV (2013/36/EU) and Regulation (CRR - 575/2013), Solvency II (2009/138/EC), the Payment Services Directive 2 (2015/2366/EU), the Mortgage Credit Directive (2014/17/EU), PRIIPs (1286/2014), UCITS (2009/65/EC), AIFMD (2011/61/EU), and the Insurance Distribution Directive (2016/97/EU). Administrative sanctions: the AFM and DNB may impose fines of up to EUR 10 million per violation or 10% of annual consolidated turnover (whichever is higher) for serious violations; may impose periodic penalty payments (dwangsommen) to enforce compliance; may revoke licences; may issue public warnings; and may impose personal prohibition orders on directors and officers. Criminal sanctions for market abuse and insider dealing are governed by the Wet op de economische delicten (WED) and the Wetboek van Strafrecht, with imprisonment of up to six years for insider trading and market manipulation offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nl-wwft-aml-2008",
    "title": "Netherlands Anti-Money Laundering and Counter-Terrorist Financing Act 2008 (Wet ter voorkoming van witwassen en financieren van terrorisme - Wwft)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Wwft (Wet ter voorkoming van witwassen en financieren van terrorisme - Act on the Prevention of Money Laundering and Financing of Terrorism) is the Netherlands' principal anti-money laundering and counter-terrorist financing statute, first enacted in 2008 to transpose EU Anti-Money Laundering Directive 3 (Directive 2005/60/EC) into Dutch law and subsequently updated to implement AMLD4 (Directive 2015/849) and AMLD5 (Directive 2018/843). The Wwft applies to a broad range of 'obligated institutions' (instellingen) including: credit institutions and banks; insurance undertakings and intermediaries; investment firms and financial advisors; notaries and civil-law notaries; lawyers (in specified non-contentious legal activities); external accountants, auditors, and tax advisors; trust offices; real estate agents; dealers in high-value goods (for cash transactions exceeding EUR 10,000); and crypto-asset service providers (following Wwft amendment in 2020 implementing AMLD5). The cornerstone obligation under the Wwft is customer due diligence (CDD / cliëntenonderzoek): before establishing a business relationship or executing a transaction above applicable thresholds, obligated institutions must identify and verify the identity of the customer, identify the ultimate beneficial owner (UBO - any natural person holding more than 25% of the shares, voting rights, or ownership interests in a legal entity, or who otherwise exercises ultimate control), and assess the nature and purpose of the proposed business relationship. Enhanced due diligence (EDD) is mandatory for: politically exposed persons (PEPs) and their immediate family members and close associates; customers and business relationships involving high-risk third countries listed by the European Commission; and transactions that are complex, unusually large, lack apparent economic justification, or involve unusual jurisdictional patterns. Standard CDD applies for occasional transactions above EUR 15,000 in cash (EUR 10,000 for high-value goods dealers). Simplified CDD may apply for lower-risk customers as specified in the Wwft and AMLD guidance. All obligated institutions must report unusual transactions (ongebruikelijke transacties) to FIU-Nederland (Financial Intelligence Unit Netherlands) via the goAML reporting system; the tipping-off prohibition (Art. 23a Wwft) prohibits disclosure of the report to the customer. Records of CDD documentation and transaction records must be retained for five years after the end of the business relationship or transaction. Supervisory authorities by sector include: De Nederlandsche Bank (DNB) for banks, insurers, payment institutions, electronic money institutions, and trust offices; Autoriteit Financiële Markten (AFM) for investment firms, financial advisors, and intermediaries; Bureau Financieel Toezicht (BFT) for notaries, civil-law notaries, and external accountants; Kansspelautoriteit (KSA) for casinos; and the Dutch Bar Association (NOvA) for lawyers. Administrative sanctions include fines of up to EUR 5 million or twice the transaction value (whichever is higher). Criminal sanctions under the Wet op de economische delicten (WED - Economic Offences Act) include imprisonment of up to six years and fines proportionate to the financial benefit obtained.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-gwg-aml-2017"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "no-aml-act-2018-money-laundering",
    "title": "Norway Anti-Money Laundering Act (Act of 1 June 2018 No. 23)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-18",
    "bluf": "Norway's Anti-Money Laundering Act (LOV-2018-06-01-23, in force 15 October 2018) requires obliged entities to take a risk-based approach (Sections 6-7), apply customer due diligence (Sections 9-14), conduct enhanced due diligence including for politically exposed persons (Section 18), examine and report suspicions to Okokrim (Sections 25-27), and retain records for five years (Section 30), under the supervision of Finanstilsynet (Section 43).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "no-anskaffelsesloven-2016",
    "title": "Norway Anskaffelsesloven (Public Procurement Act) LOV-2016-06-17-73",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Lov 17. juni 2016 nr. 73 om offentlige anskaffelser (Anskaffelsesloven) is Norway's principal public procurement statute, in force from 1 January 2017, governing procurement by public bodies in compliance with EEA obligations. The Act contains 18 sections (paragrafer). Section 1 sets the purpose - to promote efficient use of public resources and the integrity of public procurement. Section 2 establishes the scope, applying to oppdragsgivere (contracting authorities) for contracts at or above 100,000 NOK excluding VAT. Section 4 establishes the basic principles of competition, equal treatment, predictability, verifiability and proportionality, which contracting authorities must observe. Section 5 sets requirements for environmental, social and labour considerations and human rights. Sections 8 to 15 set out the rettsmidler (legal remedies) regime, including the standstill period, judicial review by the ordinary courts and the role of the Klagenemnda for offentlige anskaffelser (KOFA - Public Procurement Complaints Board). Section 12 governs administrative gebyr (penalty fee) for unlawful direct awards. The Act is implemented through detailed forskrifter (regulations) including the Anskaffelsesforskriften, the Forsyningsforskriften (utilities) and the Konsesjonskontraktforskriften (concessions) which transpose EU Directives 2014/23/EU, 2014/24/EU and 2014/25/EU into Norwegian law via the EEA Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-public-procurement-construction-directive",
      "uncitral-model-law-public-procurement-2011"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "no-apenhetsloven-2021-transparency-act",
    "title": "Norway Apenhetsloven (Transparency Act) LOV-2021-06-18-99",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Lov 18. juni 2021 nr. 99 om virksomheters apenhet og arbeid med grunnleggende menneskerettigheter og anstendige arbeidsforhold (Apenhetsloven, Transparency Act) is Norway's principal supply-chain human-rights and decent-work due-diligence statute. The Act was in force from 1 July 2022. Sec. 1 (formal) requires enterprises to promote respect for fundamental human rights and decent working conditions in the production of goods and provision of services. Sec. 2 (virkeomrade) applies to larger enterprises (storre virksomheter) domiciled in Norway and offering goods or services in or outside Norway, and to foreign enterprises offering goods or services in Norway and liable for tax in Norway. An enterprise is storre if it (a) is a reporting entity under the Norwegian Accounting Act regnskapsloven section 1-5 or (b) meets at least two of three thresholds on the balance-sheet date: salgsinntekter exceeding NOK 70 million; balansesum exceeding NOK 35 million; average employees of 50 ftes in the financial year. Sec. 3 (definisjoner) defines grunnleggende menneskerettigheter by reference to UN core conventions and ILO core conventions, anstendige arbeidsforhold, forretningsforbindelser and leverandorkjede. Sec. 4 (aktsomhetsvurderinger) requires the enterprise to carry out due diligence following the OECD Guidelines for Multinational Enterprises 6-step methodology: embed in policies and management systems, identify and assess actual and potential adverse impacts, cease or prevent or mitigate adverse impacts, track implementation and results, communicate publicly, provide for or cooperate in remediation. Sec. 5 (offentliggjoring) requires publication of a public due-diligence statement by 30 June each year, signed by the board. Sec. 6-7 (informasjonsrett) gives any person a right to information on adverse impacts and how the enterprise addresses them, with response within 3 weeks or 2 months for complex requests. Sec. 8-11 (Forbrukertilsynet enforcement) provides for orders to comply (palegg) and overtredelsesgebyr of up to NOK 4 million or 2 percent of turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csddd-directive-2024-1760",
      "de-lksg-supply-chain-due-diligence-act-2021",
      "fr-loi-2017-399-devoir-de-vigilance"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "no-konkurranseloven-2004",
    "title": "Norway Konkurranseloven (Competition Act) LOV-2004-03-05-12",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Lov 5. mars 2004 nr. 12 om konkurranse mellom foretak og kontroll med foretakssammenslutninger (Konkurranseloven) is Norway's principal competition statute, in force from 1 May 2004 and modelled on TFEU Articles 101 and 102 with EEA-aligned merger control. Sec. 1 (purpose) commits the law to promoting competition for the efficient use of society's resources, with particular regard to consumer interests. Sec. 2 sets the territorial scope including foreign conduct with effects in Norway. Sec. 10 prohibits agreements, decisions of associations of undertakings and concerted practices that restrict competition, mirroring TFEU Art. 101 with a self-assessed exemption regime. Sec. 11 prohibits abuse of dominance, mirroring TFEU Art. 102. Sec. 16 to Sec. 16a govern merger and minority-shareholding control, with the Konkurransetilsynet empowered to prohibit or impose conditions on transactions that significantly impede effective competition. Sec. 17 to Sec. 18 set the foretakssammenslutning notification regime with the 1 billion NOK combined Norwegian turnover threshold. Sec. 29 provides for overtredelsesgebyr (administrative fines) of up to 10 percent of the undertaking's worldwide turnover. Sec. 30 to Sec. 31 establish criminal sanctions for individuals in hardcore cartels and the lempning (leniency) programme. Konkurransetilsynet (Norwegian Competition Authority) enforces with appeal to Konkurranseklagenemnda.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "de-gwb-competition-act",
      "eu-tfeu-article-101-cartel-prohibition",
      "eu-tfeu-article-102-abuse-of-dominance"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "no-markedsforingsloven-2009",
    "title": "Norway Markedsføringsloven (Marketing Control Act) LOV-2009-01-09-2",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Lov 9. januar 2009 nr. 2 om kontroll med markedsføring og avtalevilkår mv. (Markedsføringsloven) is Norway's principal Marketing Control Act, in force from 1 June 2009 and transposing the EU Unfair Commercial Practices Directive 2005/29/EC. The Act is structured in five Kapitler. Kapittel 1 (§§1-5) contains general provisions including the scope (§1), the good marketing practice requirement (§2) and the documentation obligation for factual claims (§3). Kapittel 2 (§§6-10a) regulates commercial practices toward consumers including the prohibition of unfair commercial practices (§6), misleading actions (§7), misleading omissions (§8), aggressive practices (§9) and the blacklist of always-unfair practices (§11). Kapittel 3 (§§11-18) governs specific marketing forms including telephone marketing restrictions (§§12-14), prior consent for electronic marketing such as email and SMS (§15), and restrictions on unsolicited door-to-door sales (§17a). §35 establishes the Forbrukertilsynet (Consumer Authority) as the supervisory body. §37 establishes the Markedsrådet (Marketing Council) as the appeals body. §§39-42 set out enforcement tools including prohibition orders, tvangsmulkt (penalty fees) and administrative fines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "es-ley-3-1991-competencia-desleal",
      "uk-asa-influencer-marketing-guide-2023"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "no-personopplysningsloven-2018",
    "title": "Norway Personal Data Act 2018 (Personopplysningsloven) - GDPR Implementation in the EEA",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Norwegian Personal Data Act 2018 (Personopplysningsloven, Lov om behandling av personopplysninger, enacted 15 June 2018, entry into force 20 July 2018) incorporates the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) into Norwegian law as part of Norway's obligations under the Agreement on the European Economic Area (EEA Agreement). Norway is not an EU member but is a party to the EEA Agreement, through which EU single market legislation - including GDPR - applies in Norway as if it were an EU member state. The GDPR is directly applicable in Norway with the same legal force as in EU member states. The Norwegian Personal Data Act supplements the GDPR with nationally elected provisions where the GDPR permits member state derogations. Key national supplementary provisions: (1) Age of digital consent: Norway has set the minimum age for children to consent to information society services (social media, apps) at 15 years (GDPR allows member states to set any age between 13 and 16 years); (2) Employment data: Norwegian working life provides for processing of employees' personal data in employment relationships, including references to the Working Environment Act (Arbeidsmiljøloven); (3) Freedom of expression and journalism: exemptions from certain GDPR provisions for journalism, research, and archives in the public interest; (4) Processing for research and statistics: exemptions permitting extended processing for scientific research and statistics; (5) National identification numbers: processing of national identification numbers (fødselsnummer) is permitted only where there is a clear need for certain identification and the processing is authorised by law or by the Datatilsynet. Supervisory authority: Datatilsynet (the Norwegian Data Protection Authority) is Norway's independent supervisory authority responsible for monitoring and enforcing compliance with the GDPR and the Personal Data Act. Datatilsynet is a member of the European Data Protection Board (EDPB) and participates in EDPB binding decisions, consistency mechanism procedures, and joint operations. Fines: GDPR administrative fines apply - up to EUR 20 million or 4% of total worldwide annual turnover (whichever is higher) for most serious violations; up to EUR 10 million or 2% of global turnover for other violations. Norway applies GDPR enforcement equivalently to EU member states. Cross-border data transfers: GDPR adequacy decisions issued by the European Commission apply in Norway for transfers from Norway to third countries; Norway is included in adequacy decisions for European countries issued to third countries (e.g., UK Adequacy Decision covers EEA). Schrems II and related transfer mechanism requirements (standard contractual clauses, binding corporate rules) apply in Norway as in EU member states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "no-petroleum-activities-act-1996-section-4-1-exploration-production",
    "title": "Norway Petroleum Activities Act 1996 Section 4-1 - Petroleum Exploration and Production Licences: Conditions, HSE Obligations, and Resource Management Requirements",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Section 4-1 of the Norwegian Petroleum Activities Act 1996 (PAA) governs the grant of production licences for exploration and production of petroleum on the Norwegian continental shelf. A production licence grants the exclusive right to explore for, explore and produce petroleum in the licence area. The licence is subject to conditions including approval of the Plan for Development and Operation (PDO) per Section 4-2, compliance with health, safety and environment (HSE) obligations administered by the Petroleum Safety Authority Norway (PSA), and resource management requirements to maximise recovery from the petroleum deposit. Norway's petroleum management framework is regarded internationally as a gold standard for transparency, resource management, and State participation through Petoro AS and SDFI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eiti-standard-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "no-pol-2018",
    "title": "Norway Personal Data Act 2018 (Personopplysningsloven) - EEA GDPR Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Norway's Personopplysningsloven (Personal Data Act, LOV-2018-06-15-38), adopted by the Storting (Norwegian Parliament) on 15 June 2018 and in force from 20 July 2018, is Norway's primary national data protection legislation implementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Norway. Norway is not an EU member state but is a member of the European Economic Area (EEA); the GDPR was incorporated into the EEA Agreement as Annex XI and became directly applicable Norwegian law following a Joint Committee Decision of the EEA Council, making Norway subject to GDPR with the same legal effect as EU member states. The Personopplysningsloven provides national derogations and additions permitted by the GDPR, implementing the EEA/Norwegian dimension, and repeals the prior Norwegian Personal Data Act (Personopplysningsloven 2000, LOV-2000-04-14-31). Norway is a highly prosperous, technologically advanced jurisdiction with significant oil and gas sector, financial services, maritime, and public sector data processing. The Norwegian oil and gas sector processes significant personal data of employees, contractors, and operational personnel subject to GDPR. Enforcement: Datatilsynet (Norwegian Data Protection Authority) is Norway's independent data protection supervisory authority. Datatilsynet is not an EU EDPB member (as Norway is not an EU member state) but participates in EDPB activities as an EEA observer and cooperates closely with EU supervisory authorities. Key Norwegian national provisions: (1) Age of digital consent: Norway has set the age of consent for information society services at 13 years; data subjects under 13 require parental or guardian consent; (2) Employment - the Norwegian Working Environment Act (Arbeidsmiljøloven, LOV-2005-06-17-62) and associated regulations govern employee monitoring and the processing of employee personal data alongside GDPR; advance employee notification and trade union consultation required for monitoring; (3) Freedom of expression - the Personopplysningsloven contains exemptions for journalistic, academic, and cultural purposes aligned with GDPR Art. 85 and the Norwegian Constitution (Grunnloven § 100, freedom of expression); (4) Public sector - Norwegian public authorities are subject to the Personopplysningsloven and the Freedom of Information Act (Offentleglova, LOV-2006-05-19-16); (5) Health data - specific provisions for health registry data under Norwegian health legislation (including the Health Research Act, Helseforskningsloven). Fines: GDPR administrative fines apply in Norway - up to EUR 20 million or 4% of global annual turnover, calculated in Norwegian kroner (NOK) at the applicable exchange rate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "no-universities-colleges-act-2024-section-4-1-admission-requirements",
    "title": "Lov om universiteter og høyskoler (universitets- og høyskoleloven) § 4-1 Styret",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "State universities and colleges must establish a board and define its composition, election process, leadership structure, and operating procedures as outlined in Chapter 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "noaa-commercial-remote-sensing-regulatory-affairs",
    "title": "NOAA CSRSA - Commercial Remote Sensing Regulatory Affairs (15 CFR Part 960)",
    "domain": "Space & Satellite Law",
    "version": "15 CFR Part 960 (as amended 2020)",
    "last_updated": "2026-05-09",
    "bluf": "NOAA's Commercial Remote Sensing Regulatory Affairs (CSRSA) program under the Land Remote Sensing Policy Act of 1992 and 15 CFR Part 960 (as updated by the 2018 SPACE Act and 2020 final rule) is the US federal licensing framework for commercial Earth observation satellite systems; it establishes the licence application process, operational conditions (shutter control for sensitive imagery), data policy requirements, foreign access rules, and compliance obligations for US-licensed commercial remote sensing operators including Planet, Maxar, Satellogic, Capella Space, and other Earth observation companies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-space-policy-directive-3-2018-stm",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "norway-finanstilsynet-crypto-aml-2023",
    "title": "Norway Finanstilsynet Crypto AML Registration 2023 - AMLA Compliance for VASPs: Registration with FSA, Anti-Money Laundering Act Obligations, Travel Rule Implementation, Suspicious Transaction Reporting and Enhanced Due Diligence for PEPs",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Virtual Asset Service Providers (VASPs) operating in Norway must register with Finanstilsynet and comply with the Anti-Money Laundering Act (hvitvaskingsloven, LOV-2018-06-01-23, in force 15 October 2018), including implementing Travel Rule data transfers, reporting suspicious transactions, and applying enhanced due diligence for politically exposed persons. This applies to all entities exchanging, safeguarding, or transferring virtual assets on behalf of others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "eu-eba-mica-guidelines-art-emt-authorisation",
      "bis-iosco-pfmi-applied-to-dlt-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "norway-gambling-act-2021-lotteritilsynet",
    "title": "Norway Gambling Act 2021 - Lotteritilsynet State Monopoly Framework",
    "domain": "Gaming & Gambling",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Norway's Gambling Act (Lotteriloven, Act No.63 of 28 June 2019, entered into force 1 January 2021) maintains the Norwegian state monopoly gambling model. Only Norsk Tipping AS (games of chance) and Norsk Rikstoto (horse racing) hold licences to offer online gambling to Norwegian residents. The Lotteritilsynet (Norwegian Gambling Authority) supervises the market, including enforcing payment blocking against unlicensed operators. Foreign operators offering gambling services to Norwegians without a licence commit an offence under Gambling Act s.5. Responsible gambling tools are mandatory and rigorous: Norsk Tipping implements HJELPELINJEN problem gambling hotline, deposit limits, and voluntary exclusion (SPERRE) system. Charitable organisations may offer lotteries under exempted lottery licences. Criminal penalties include fines and up to 1 year imprisonment for operating unlicensed gambling in Norway.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_article",
        "aml",
        "fatf_recommendation",
        "esa",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "norway-mineral-resources-act-2009-mineralloven",
    "title": "Norway Mineral Resources Act 2009 (Mineralloven) - Mining Rights, State Ownership, and Saami Rights Framework",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Norwegian Mineral Resources Act (Mineralloven) of 19 June 2009 No. 101 governs exploration and extraction of minerals on mainland Norway, establishing a two-category ownership system (state minerals vs. landowner minerals), a concessionary licensing regime administered by the Directorate of Mining (Direktoratet for mineralforvaltning, DMF), mandatory consultation with Saami reindeer herding communities before licences are granted in reindeer grazing areas, security (environmental bond) requirements, and an annual operations tax (driftsavgift) of NOK 0.5/tonne for state minerals; the Act reflects Norway's constitutional obligations to protect Saami cultural rights under Article 108 of the Norwegian Constitution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-corporate-sustainability-due-diligence-2024",
      "icmm-mining-principles-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "norway-space-activities-act-2021",
    "title": "Norway Space Activities Act 2021 (Lov om norsk romvirksomhet) - Norwegian Commercial Space Regulatory Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Norway's Act on Norwegian Space Activities (Lov om norsk romvirksomhet, LOV-2021-06-11-84) entered into force on 1 January 2022 and established a comprehensive licensing regime for commercial space activities under Norwegian jurisdiction. The Act requires any Norwegian legal person or entity conducting space activities from Norwegian territory to obtain a licence from the Ministry of Trade, Industry and Fisheries (Nærings- og fiskeridepartementet). The Act implements Norway's obligations under the five UN space treaties, mandates liability insurance for licensees, requires debris mitigation plans, and establishes registration of Norwegian space objects. Implementing regulations (FOR-2022-12-09-2185) specify licensing requirements, insurance minimums, and debris mitigation standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "esa_convention_1975",
        "copuos_lts_guidelines"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "notary-public-standard",
    "title": "Notary Public Standards",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with established Notary Public Standards mandates rigorous adherence to procedural and documentary requirements for all notarial acts. A fundamental prerequisite is the satisfactory identification of the principal signer, which necessitates presentation of a current, unexpired government-issued photo identification. The platform enforces a zero-tolerance policy for identity verification, permitting a maximum of zero credential analysis failures. Furthermore, the notarial officer must confirm the signer is both aware of the document's contents and acting willingly, without coercion. This act must occur with the signer in the notary’s physical presence or through an authorized Remote Online Notarization (RON) platform. Before notarization, the instrument presented must be complete, containing no blank spaces that could facilitate subsequent fraudulent entries. Every notarization requires an official notary seal or stamp affixed to a properly completed notarial certificate; this certificate’s wording must precisely match the requirements of the governing jurisdiction. The performing notary public is required to hold an active, valid commission at the time of the service. Post-execution, each notarial act demands a detailed journal entry for record-keeping purposes. These official records are subject to a mandatory journal retention period of ten years to ensure long-term auditability and legal validity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "np-privacy-act-2018",
    "title": "Nepal Individual Privacy Act 2018 - Ministry of Home Affairs",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Nepal's Individual Privacy Act 2018 (Byaktigat Gupta Raakhne Sambandhi Ain, 2075 B.S.), enacted by the Federal Parliament of Nepal and authenticated by the President of Nepal, is Nepal's primary legislation protecting the privacy of individuals and establishing rights and obligations regarding the handling of personal information. The Individual Privacy Act was enacted pursuant to the right to privacy guaranteed as a fundamental right under the Constitution of Nepal 2015 (Sambat 2072 B.S.), which protects the privacy of individuals, their families, residences, correspondence, and personal information. The Act establishes a rights-based framework for personal information protection applicable to both public and private sector entities that collect, process, or store personal information of Nepali individuals. Enforcement of the Individual Privacy Act is administered through the Ministry of Home Affairs and the courts, with criminal sanctions applying to violations. Key features of Nepal's Individual Privacy Act 2018: (1) Scope - applies to individuals and institutions collecting, processing, or storing personal information of individuals in Nepal; (2) Right to privacy - individuals have the fundamental right to privacy over their personal information, body, family, home, communication, and reputation; (3) Personal information categories - covers any information relating to an identifiable natural person including health, financial, and sensitive identification information; (4) Consent requirement - personal information may only be collected and processed with the knowledge and consent of the individual except where a legal basis exemption applies; (5) Purpose limitation - personal information must be collected for specified and legitimate purposes and not used beyond those purposes; (6) Sensitive personal information - heightened protection for health records, sexual conduct, financial information, and information that could adversely affect a person's dignity or reputation; (7) Data subject rights - individuals have rights to access their personal information, correct inaccuracies, and prevent unauthorised disclosure; (8) Security obligations - entities holding personal information must protect it from unauthorised access, use, or disclosure using appropriate security measures; (9) Prohibition on unauthorised disclosure - disclosure of personal information without consent or legal authorisation is prohibited and carries criminal penalties; and (10) Cross-border obligations - entities transferring personal information outside Nepal must ensure appropriate protection. Nepal's Individual Privacy Act represents an important step in South Asian personal data protection and reflects the constitutional guarantee of the right to privacy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nr-aml-tfs-act-2023",
    "title": "Nauru Anti-Money Laundering and Targeted Financial Sanctions Act 2023",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "Nauru's Anti-Money Laundering and Targeted Financial Sanctions Act 2023 defines reporting entities (Section 7) and politically exposed persons (Section 6), and requires each reporting entity to conduct a business risk assessment (Section 24), identify and verify customers, agents and beneficial owners (Section 37), keep customer due diligence records (Section 30) for the statutory period (Section 29), apply ongoing customer due diligence (Section 42), stop where due diligence cannot be completed (Section 31), and report suspicious activity (Section 59) to the Financial Intelligence Unit continued under Section 68.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nr-framework",
    "title": "Nauru - Constitutional Privacy Rights and Pacific Islands Forum Data Protection Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Republic of Nauru, a small island state in the Central Pacific, has a legal system influenced by Australian common law and legislation. The Constitution of Nauru establishes fundamental rights including the right to privacy and freedom from arbitrary or unlawful interference with privacy. Nauru does not have a standalone comprehensive data protection law. The applicable framework for personal data protection in Nauru consists of constitutional privacy rights, common law privacy principles inherited from the Australian legal tradition, Pacific Islands Forum regional guidelines on cybersecurity and data protection, and the principle that personal data collected through electronic services must be used only for the purposes for which it was collected. The telecommunications sector in Nauru is regulated under the telecommunications regulatory framework administered by the relevant government ministry. Organisations processing personal data in Nauru must respect constitutional privacy rights and implement appropriate security measures to protect personal data from unauthorised access and disclosure. As a Pacific Islands Forum member, Nauru participates in the regional framework for cybercrime and cybersecurity developed by the Forum and the Pacific Islands Law Officers' Network. There is no data protection supervisory authority in Nauru at present.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/nr-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nrc-10-cfr-50-domestic-licensing-nuclear-facilities",
    "title": "10 CFR Part 50: Domestic Licensing of Production and Utilization Facilities",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation by the U.S. Nuclear Regulatory Commission (NRC) establishes the comprehensive requirements for licensing, constructing, and operating nuclear power plants and other production/utilization facilities. It mandates that applicants submit a detailed Safety Analysis Report (SAR) per § 50.34 and maintain approved Technical Specifications (§ 50.36) and Emergency Plans (§ 50.47 and Appendix E) to ensure public health and safety.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "nrc-10-cfr-73-physical-security-nuclear-plants",
    "title": "10 CFR Part 73 - Physical Protection of Plants and Materials",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "This regulation requires U.S. Nuclear Regulatory Commission (NRC) licensees operating nuclear power plants or possessing special nuclear materials to establish, maintain, and implement a comprehensive physical protection system. The system must defend against radiological sabotage and prevent the theft of special nuclear material, as detailed in requirements for security plans, access controls, armed response forces, and cybersecurity under § 73.55.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nsa-cnsa-2-0-quantum-resistant-algorithms-2022",
    "title": "NSA CNSA 2.0 - Commercial National Security Algorithm Suite 2022: Quantum-Resistant Algorithm Requirements for National Security Systems",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Mandates the transition of National Security Systems (NSS) to quantum-resistant cryptographic algorithms including CRYSTALS-Kyber (ML-KEM) for key encapsulation and CRYSTALS-Dilithium (ML-DSA) for digital signatures, with full migration required by 2033 and deprecation of RSA, ECC, and ECDH by 2030. Applies to all U.S. government agencies, contractors, and vendors handling NSS information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "do-178c-airborne-software-2011",
      "australia-defence-export-controls-des-2012"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nu-framework",
    "title": "Niue - Constitutional Privacy Rights and Pacific Islands Forum Data Protection Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Niue is a self-governing state in free association with New Zealand, located in the South Pacific Ocean. Niue has its own constitution established under the Niue Constitution Act 1974 (New Zealand), which provides for a self-governing parliamentary democracy through the Niue Assembly. Niue citizens hold New Zealand citizenship, but Niue exercises full sovereignty over its own domestic affairs and operates its own distinct legal system. The New Zealand Privacy Act 2020 does not automatically extend to Niue - Niue has its own legal system and must enact its own legislation for any law to apply within its territory. Niue does not have a standalone comprehensive personal data protection law. The applicable framework for personal data protection in Niue consists of constitutional privacy rights derived from New Zealand common law traditions, Pacific Islands Forum regional guidelines on cybersecurity and data protection, and telecommunications regulation administered by the Niue IT Department and relevant governmental bodies. Organisations processing personal data in Niue must respect privacy rights consistent with constitutional traditions, implement appropriate technical and organisational security measures, and limit data collection to specified, legitimate purposes. As a Pacific Islands Forum member, Niue participates in regional frameworks for cybercrime prevention and digital governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/nu-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nuclear-safety-iaea",
    "title": "IAEA Nuclear Safety (GS-R-3)",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Compliance with IAEA Safety Standard GS-R-3 mandates establishing, implementing, and continually improving a documented, integrated management system wherein safety holds paramount importance. Top management must demonstrate clear commitment by providing adequate resources, which includes ensuring critical staff competency is verified and that all supplier assessments are mandatory. The application of system requirements must be graded, ensuring enforcement corresponds directly to an activity’s significance and complexity relative to safety. Strict control of documents and records is foundational, demanding active document version control for all materials and a minimum records retention period of ten years. A rigorous cycle of measurement, assessment, and improvement is required, incorporating self-assessment, mandatory independent assessment, and formal management system reviews at least every twelve months. This continuous improvement process also encompasses safety culture assessments on a twelve-month frequency and a robust non-conformance program with a twenty-four-hour reporting service level agreement, where a subsequent root cause analysis for each deviation is required to prevent recurrence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nydfs-part-500-cybersecurity-v2-2023",
    "title": "NYDFS Part 500 Cybersecurity Regulation v2.0 2023 - 23 NYCRR 500 Amended: Class A Company Requirements, Penetration Testing, EDR, MFA Mandates, 72-Hour Incident Notification, CISO Reporting to Board, Third-Party Service Provider Security Policy and Annual Compliance Certification",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The NYDFS Part 500 regulation mandates that Covered Entities, including financial services companies operating under New York law, implement a robust cybersecurity program, conduct annual penetration testing, enforce multi-factor authentication (MFA), encrypt nonpublic information, report cybersecurity incidents within 72 hours, and file an annual certification of compliance by April 15. Key requirements are outlined in 23 NYCRR Part 500, as amended effective November 1, 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-800-53-ac2",
      "nist-800-53-sc7",
      "c-scrm-practices-systems-organizations",
      "australia-acsc-essential-eight-maturity-2023",
      "aicpa-soc2-cc-availability"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nz-algorithm-charter-government-2020",
    "title": "New Zealand Algorithm Charter for Aotearoa New Zealand 2020 - Compliance Obligations for Government Algorithm Use, Transparency Requirements for Public Sector AI, and Human Review Commitments for Algorithmic Decision-Making",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations for New Zealand government agencies under the Algorithm Charter 2020, focusing on transparency, human oversight, and accountability in algorithmic decision-making, with overlapping requirements reinforced by the EU AI Act 2024 (Regulation (EU) 2024/1689, Articles 6-7 on high-risk AI systems).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "oecd-ai-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nz-aml-cft-act-2009",
    "title": "New Zealand Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Anti-Money Laundering and Countering Financing of Terrorism Act 2009 establishes New Zealand's AML/CFT regulatory framework, requiring reporting entities (banks, non-bank deposit takers, life insurers, money changers, lawyers, accountants, real estate agents, and others) to conduct customer due diligence, maintain an AML/CFT programme, file suspicious transaction reports with the Financial Intelligence Unit, and submit annual reports to their designated supervisor. The Act is administered by three supervisors: the Reserve Bank of New Zealand, the Financial Markets Authority, and the Department of Internal Affairs. Under Section 22, standard customer due diligence must be conducted before establishing a business relationship or conducting an occasional transaction. Section 31 requires suspicious transaction reports to be filed with the Commissioner of Police as soon as practicable. Section 40 mandates a documented and maintained AML/CFT programme for all reporting entities. Record-keeping obligations under Section 56 require retention of transaction and identity verification records for five years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-fmca-2013-financial-markets-conduct"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nz-biosecurity-act-1993",
    "title": "NZ Biosecurity Act 1993",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The NZ Biosecurity Act 1993 is the principal statute governing biosecurity in New Zealand covering border control management of new and established pests and diseases including the National Pest Plant Accord and regional pest management plans. The Act enables import health standards (IHS) under Section 22 governing commodities for importation; Chief Technical Officer determinations for unwanted organisms; biosecurity response (Part 7); compensation arrangements; and powers of authorised persons for inspection treatment seizure. Major events such as Mycoplasma bovis (cattle), Queensland fruit fly, and Foot-and-Mouth Disease (FMD) preparedness are managed under the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "nz-cccfa-2003-credit-contracts",
    "title": "New Zealand Credit Contracts and Consumer Finance Act 2003 (CCCFA)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-30",
    "bluf": "The Credit Contracts and Consumer Finance Act 2003 (CCCFA) governs consumer credit contracts, consumer leases, and buy-back transactions in New Zealand, establishing disclosure requirements for creditors, lender responsibility principles, and protections against oppressive credit contracts. The Act was significantly amended in 2014 and 2021 to introduce comprehensive lender responsibility obligations. Under Section 9C, creditors must comply with lender responsibility principles including ensuring the consumer can make repayments without suffering substantial hardship and that the credit is suitable for the consumer's requirements and financial situation. Section 17 requires creditors to make initial disclosure before or at the time of entering into a consumer credit contract. Section 47 empowers the court to reopen oppressive credit contracts and consumer leases.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-fmca-2013-financial-markets-conduct"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nz-climate-change-response-act-2002",
    "title": "NZ Climate Change Response Act 2002",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The NZ Climate Change Response Act 2002 establishes the legal framework for New Zealand's domestic response to climate change including the New Zealand Emissions Trading Scheme (NZ ETS), emissions budgets and reduction plans pursuant to the 2019 Zero Carbon Amendment, the Climate Change Commission, and reporting obligations including the National Greenhouse Gas Inventory. The 2019 Zero Carbon Amendment set the 2050 target of net zero greenhouse gas emissions (other than biogenic methane reduced to 24-47% below 2017 levels by 2050). Successive emissions budgets are set on a 5-year basis with the Government required to publish an emissions reduction plan for each period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "nz-commerce-act-1986",
    "title": "New Zealand Commerce Act 1986 - Competition Law and Commerce Commission Enforcement",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Commerce Act 1986 prohibits contracts, arrangements, or understandings that substantially lessen competition in a New Zealand market, cartel conduct, and misuse of market power. The Commerce Commission enforces the Act with powers to investigate, authorise mergers, accept enforceable undertakings, and seek pecuniary penalties up to NZD 10 million or 10% of turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fair_trading_act",
        "telecommunications_act",
        "oecd_recommendation",
        "cpa",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-recommendation-hard-core-cartels-2019",
      "oecd-competition-assessment-toolkit-v3-2023",
      "australia-competition-consumer-act-2010-cca"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nz-companies-act-1993",
    "title": "New Zealand Companies Act 1993 - Incorporation Duties of Directors and Insolvency",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Companies Act 1993 governs the incorporation, management, and liquidation of companies in New Zealand by providing for share allotments and shareholder rights, fundamental duties of directors including to act in good faith and in the best interests of the company and to exercise care diligence and skill expected of a reasonable director, statutory restrictions on insolvent trading and reckless trading, financial reporting and audit obligations for reporting entities, statutory procedures for major transactions and amalgamations, statutory liquidation and voluntary administration procedures, and registrar enforcement and court remedies for breach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-privacy-act-2020"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nz-conservation-act-1987",
    "title": "NZ Conservation Act 1987",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The NZ Conservation Act 1987 establishes the Department of Conservation (Te Papa Atawhai) as the lead agency for conservation of New Zealand's natural and historic heritage. The Act administers conservation land including national parks reserves marine reserves Crown-owned forests covering ~30% of NZ land area. Section 4 requires the Act to give effect to the principles of the Treaty of Waitangi which has been interpreted by courts to require Crown actions consistent with partnership protection and participation principles. The Conservation General Policy and individual Conservation Management Strategies (CMS) and Conservation Management Plans (CMP) implement the Act. Concessions are required for commercial activities and other uses of conservation areas.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "nz-era-2000-employment-relations",
    "title": "New Zealand Employment Relations Act 2000 (ERA)",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Employment Relations Act 2000 (ERA) governs all employment relationships in New Zealand, establishing a comprehensive framework of good faith obligations, written employment agreement requirements, collective bargaining rights, personal grievance procedures, and dispute resolution mechanisms. The Act imposes a primary duty of good faith on all parties to an employment relationship under Section 4, requires all individual employment agreements to be in writing under Section 65, and provides employees with the right to raise a personal grievance within 90 days of the act or omission under Section 103. Employers who dismiss must satisfy the justification test under Section 103A that a fair and reasonable employer could have done the same.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998",
      "ilo-convention-190-2019-violence-harassment-work"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nz-fair-trading-act-1986",
    "title": "New Zealand Fair Trading Act 1986 - Misleading Conduct and Consumer Information Standards",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Fair Trading Act 1986 prohibits misleading or deceptive conduct in trade, false or misleading representations about goods or services or land or employment, unsubstantiated representations, unfair contract terms in standard form consumer contracts and certain small trade contracts, and unfair commercial practices, requires compliance with consumer information standards and product safety standards made under the Act, authorises the Commerce Commission to investigate breaches, issue compliance advice, and bring proceedings for civil pecuniary penalties or criminal prosecution, and provides consumer remedies including injunctions and damages.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-privacy-act-2020"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "nz-films-videos-publications-classification-act-1993-2021-amendment",
    "title": "New Zealand Films, Videos, and Publications Classification Act 1993 (FVPCA) with 2021 Urgent Interim Classification and Prevention of Online Harm Amendment - Section 3 Objectionable Publications, Part 7A Take-Down Notices, Section 119E Civil Pecuniary Penalty, Chief Censor and DIA Digital Safety Group",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "The New Zealand Films, Videos, and Publications Classification Act 1993 (FVPCA, Act No. 94 of 1993) is the statutory classification regime for films, videos, and publications including online content; it is administered by the Office of Film and Literature Classification (Te Mana Whakaatu) led by the Chief Censor, with enforcement by the Department of Internal Affairs (DIA) Digital Safety Group (te Pou Whakahaere) under Part 7A. Section 3 sets the definition of objectionable - a publication is objectionable if it describes, depicts, expresses, or otherwise deals with matters such as sex, horror, crime, cruelty, or violence in such a manner that the availability of the publication is likely to be injurious to the public good; named categories include child sexual exploitation material, sexual violence, torture, and extreme violence. The Films, Videos, and Publications Classification (Urgent Interim Classification of Publications and Prevention of Online Harm) Amendment Act 2021 (assented 2 November 2021) was enacted in response to the 2019 Christchurch mosque attacks livestream and introduced four core powers: (1) live-streaming of objectionable content is a criminal offence; (2) the Chief Censor may issue time-limited interim classification assessments of publications under Part 1A without a full classification hearing; (3) the DIA Digital Safety Group may issue take-down notices to online content hosts under Part 7A requiring rapid removal of objectionable material from internet services accessible in New Zealand; (4) Section 119E imposes a civil pecuniary penalty on online content hosts that do not comply with an issued take-down notice (up to NZD 200,000 for individuals and NZD 600,000 for body corporates). The Act provides separate Section 46G powers for the Chief Censor to approve providers' self-rating systems where the provider demonstrates an internal classification process that meets the statutory standard. The FVPCA operates alongside the Harmful Digital Communications Act 2015 (separate statute for digital communications harms including intimate image abuse), the Films, Videos, and Publications Classification Regulations, and the Crimes Act 1961 sections on objectionable material.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "section_3_objectionable_definition",
        "office_of_film_and_literature_classification",
        "section_23_classification",
        "section_46g_provider_self_rating",
        "amendment_2021_livestreaming_offence",
        "amendment_2021_part_1a_interim_classification",
        "amendment_2021_part_7a_takedown_notices",
        "section_119e_civil_pecuniary_penalty",
        "dia_digital_safety_group_role",
        "relationship_with_hdca_2015",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-hdca-2015",
      "au-online-safety-act-2021",
      "us-take-it-down-act-2025",
      "uk-online-safety-act-2023-ofcom-illegal-content-duty",
      "ca-criminal-code-162-1-intimate-image-without-consent"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "nz-films-videos-publications-classification-act-1993-section-3-publication",
    "title": "New Zealand Films, Videos, and Publications Classification Act 1993 Section 3 - Meaning of Objectionable Publication",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 3 of the New Zealand Films, Videos, and Publications Classification Act 1993 defines when a publication is 'objectionable' - the core trigger for criminal prohibition under Sections 123-131A. A publication is objectionable if it describes, depicts, expresses, or otherwise deals with matters such as sex, horror, crime, cruelty, or violence in such a manner that the availability of the publication is likely to be injurious to the public good. Section 3(2) provides specific deeming categories - publications are deemed objectionable if they promote or support, or tend to promote or support, sexual exploitation of children or young persons (under 16), sexual conduct with corpses, beastiality, or use of violence or coercion to compel any person to participate in sexual conduct. Section 3(3) provides further matters to be considered. Possession (Section 131) and distribution (Section 124) of objectionable publications are serious criminal offences with penalties up to 14 years imprisonment for distribution and 10 years for possession.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_objectionable_test_subsection_1",
        "deeming_subsection_2_specific_categories",
        "child_or_young_person_under_16_section_2_1_definition",
        "matters_to_be_considered_subsection_3",
        "additional_subsection_4_considerations",
        "interaction_with_section_123_distribution_offence",
        "interaction_with_section_131_possession_offence",
        "interaction_with_section_131a_strict_liability_possession_csam",
        "interaction_with_films_videos_publications_classification_amendment_act_2021",
        "office_of_film_and_literature_classification_OFLC_role"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-films-videos-publications-classification-act-1993-2021-amendment",
      "au-online-safety-act-2021"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "nz-fmca-2013-financial-markets-conduct",
    "title": "New Zealand Financial Markets Conduct Act 2013 (FMCA)",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Financial Markets Conduct Act 2013 (FMCA) is New Zealand's principal financial markets legislation, establishing a unified regulatory framework for fair dealing in financial products and services, mandatory Product Disclosure Statement (PDS) requirements for regulated offers to retail investors, and FMA licensing obligations for financial market participants. Under Part 2, no person may engage in misleading or deceptive conduct in connection with financial products. Under Section 41, a regulated offer of financial products may not be made unless disclosure requirements have been satisfied. Financial service providers including fund managers, derivatives issuers, and investment advisers must hold an FMA licence under Part 6, with enforcement powers including injunctions, pecuniary penalties, and civil liability under Part 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-privacy-act-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nz-food-act-2014",
    "title": "New Zealand Food Act 2014 - Risk-Based Framework, Food Safety Programmes, and MPI Enforcement",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Food Act 2014 (New Zealand) replaced the Food Act 1981 and introduced a risk-based regulatory framework for food businesses operating in New Zealand. Part 1 of the Act establishes the purpose: to improve and protect public health by ensuring food sold in New Zealand is safe and suitable. Section 5 defines food safety risk as a function of the likelihood of a food causing harm and the severity of that harm. The Act assigns food businesses to one of three tiers based on the food safety risk of their activities: Tier 1 businesses must operate under a registered food control plan (FCP) verified by an accredited verifier; Tier 2 businesses must register and operate under a National Programme (NP) administered by the Ministry for Primary Industries (MPI); Tier 3 covers home-based low-risk businesses. Section 99 requires all food businesses to register with their territorial authority (TA) except exempt businesses. The Ministry for Primary Industries (MPI) is the central competent authority under Section 270, with territorial authorities responsible for local registration and enforcement. The Food Standards Australia New Zealand Act 1991 (Cth and NZ) establishes Food Standards Australia New Zealand (FSANZ), which develops the joint Australia New Zealand Food Standards Code containing compositional and labelling standards applicable in New Zealand.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_food_additives_regulation_1333_2008",
        "au_food_standards_code_fsanz",
        "eu_general_food_law_regulation_178_2002",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-additives-regulation-1333-2008",
      "eu-organic-farming-regulation-2018-848",
      "nz-goods-services-tax-act-1985"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nz-gambling-act-2003",
    "title": "Gambling Act 2003",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Gambling Act 2003 establishes the legal framework for gambling activities in New Zealand, defining permitted and prohibited forms of gambling, licensing requirements for operators, and harm minimisation obligations under Section 13. It applies to all entities conducting or facilitating gambling, including online platforms, charities, and casinos.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nz-goods-services-tax-act-1985",
    "title": "New Zealand Goods and Services Tax Act 1985 - GST Rate, Registration, Zero-Rating, and Exempt Supplies",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Goods and Services Tax Act 1985 (New Zealand) (GST Act) imposes a goods and services tax on the supply of goods and services in New Zealand and on goods imported into New Zealand. Section 6 imposes GST on taxable supplies made by registered persons in New Zealand and on the importation of goods. The current GST rate is 15%, which was increased from 12.5% on 1 October 2010 by the Goods and Services Tax Amendment Act 2010. Section 8 sets out the rules for determining when a supply of goods and services is made in New Zealand and is therefore subject to GST. Section 11 provides that certain supplies are zero-rated, including exported goods, services supplied to non-residents for use outside New Zealand, and supplies of land in certain circumstances. Section 14 provides that certain supplies are exempt from GST, including financial services, the supply of residential accommodation under a residential lease, and goods supplied by way of donated goods by non-profit bodies. Section 51 requires persons making taxable supplies in the course of a taxable activity to be registered when their taxable supplies in a 12-month period exceed NZD 60,000. Section 16 requires registered persons to issue a tax invoice for taxable supplies over NZD 50. Section 20 governs the calculation of GST payable as output tax minus input tax deductions. The Commissioner of Inland Revenue administers the GST Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "au_goods_services_tax_act_1999",
        "uk_vat_act_1994",
        "eu_vat_directive_2006_112",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-hswa-2015-health-safety-work"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nz-hdca-2015",
    "title": "New Zealand Harmful Digital Communications Act 2015",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "New Zealand's Harmful Digital Communications Act 2015 (No 63) effective July 3, 2015 establishes ten communication principles prohibiting digital communications that are threatening, intimidating, offensive, demeaning, or false, creates a complaint and mediation regime administered by an approved agency (Netsafe), and grants courts powers to issue take-down orders, civil restraining orders, and criminal penalties of up to three years' imprisonment for the most serious harmful digital communications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/nz-hdca-2015.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-adequacy-decisions-article-45",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nz-health-and-safety-at-work-act-2015",
    "title": "New Zealand Health and Safety at Work Act 2015",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2015-09-04",
    "bluf": "The Health and Safety at Work Act 2015 (HSWA) is New Zealand's primary work health and safety legislation, placing a primary duty of care on persons conducting a business or undertaking (PCBUs) to ensure health and safety so far as is reasonably practicable, with Category 1 penalties of NZD 3,000,000 for body corporates, immediate notification of notifiable events to WorkSafe New Zealand, and officer due diligence obligations under Section 44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nz-privacy-act-2020",
        "nz-maritime-transport-act-1994",
        "au-work-health-safety-act-2011"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-privacy-act-2020",
      "nz-maritime-transport-act-1994",
      "au-work-health-safety-act-2011"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nz-health-safety-at-work-act-2015",
    "title": "NZ Health and Safety at Work Act 2015",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The NZ Health and Safety at Work Act 2015 (HSWA) replaces the Health and Safety in Employment Act 1992 and establishes the primary duty of care for Persons Conducting a Business or Undertaking (PCBUs) to ensure so far as is reasonably practicable the health and safety of workers and others affected by the work. Officers (directors and senior managers) have a positive duty of due diligence (Section 44). The HSWA introduces three tiers of offences with maximum penalties up to NZD 3,000,000 (corporate reckless conduct under Section 47) and individual imprisonment up to 5 years (Section 48). WorkSafe New Zealand is the regulator; Maritime NZ and CAA NZ have designated functions for maritime and aviation sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nz_hswa_2015",
        "nz_hse_act_1992",
        "aus_whs_acts",
        "uk_hsw_act_1974",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "nz-hswa-2015-health-safety-work",
    "title": "New Zealand Health and Safety at Work Act 2015 (HSWA)",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Health and Safety at Work Act 2015 (HSWA) is New Zealand's principal workplace health and safety legislation, establishing a risk-based framework that replaced the Health and Safety in Employment Act 1992. The Act introduces the person conducting a business or undertaking (PCBU) as the primary duty holder, requires PCBUs to ensure the health and safety of workers and other persons at the workplace so far as is reasonably practicable under Section 36, and imposes duties of consultation, cooperation, and coordination between duty holders with overlapping obligations under Section 48. Section 81 requires immediate notification of notifiable events (work-related deaths, serious injuries, serious illnesses, or notifiable incidents) to WorkSafe New Zealand. Workers have the right to cease or direct cessation of unsafe work under Section 74. The Act is administered by WorkSafe New Zealand and carries significant penalties for breaches, including category 1 offences for reckless conduct that exposes persons to a risk of death or serious injury.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-era-2000-employment-relations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nz-maritime-transport-act-1994",
    "title": "New Zealand Maritime Transport Act 1994 -- Ship Registration, Safety, Pollution, and Maritime Levies",
    "domain": "Maritime & Shipping",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "The Maritime Transport Act 1994 (MTA) is the principal New Zealand statute governing maritime safety, the New Zealand Register of Ships, maritime pollution prevention, and maritime levies. The Act is administered by Maritime New Zealand (MNZ), a Crown entity under Section 429. Part 3 establishes the New Zealand Register of Ships under the Ship Registration Act 1992; ships of 24 metres or more used for commercial purposes must be registered. Maritime Rules (equivalent to regulations) made under Part 4 govern technical safety standards for vessels, crew certification, and operational requirements. Maritime Rule Part 21 implements the SOLAS Convention requirements for passenger ships and cargo ships of 500 GT or more. New Zealand's exclusive economic zone (EEZ) pollution prevention obligations under Part 18 implement MARPOL Annex I-VI and the CLC Convention 1992 (oil pollution liability). Ship operators on the New Zealand coast must hold a Maritime Operator Safety System (MOSS) certificate under Part 2A. The Director of Maritime New Zealand has significant enforcement powers including detaining vessels, imposing civil penalties, and initiating criminal prosecutions under Section 65. Maximum criminal penalties for maritime offences include fines of NZD 200,000 for companies and NZD 10,000 for individuals for general duty breaches under Section 65; specific MARPOL discharge offences carry fines up to NZD 600,000 for ships and NZD 200,000 for individuals. The Maritime Levies Act 1989 imposes tonnage-based levies on commercial vessels operating in New Zealand waters.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-merchant-shipping-act-1995",
      "eu-union-customs-code-952-2013",
      "eu-taxonomy-regulation-2020-852"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nz-nzism-2023",
    "title": "New Zealand Information Security Manual 2023 (NZISM Version 3.7)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "NZISM Version 3.7 published 2023 by the Government Communications Security Bureau is the mandatory information security standard for New Zealand government agencies handling official, sensitive, or classified information, providing baseline controls across access management, cryptography, network security, and incident response aligned to the New Zealand Security Classification System.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/nz-nzism-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-adequacy-decisions-article-45",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "nz-outer-space-high-altitude-activities-act-2017",
    "title": "New Zealand Outer Space and High-altitude Activities Act 2017 - Launch Licence and Operator Permit Framework",
    "domain": "Space & Satellite Law",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "New Zealand's Outer Space and High-altitude Activities Act 2017 (No. 29 of 2017), administered by the Ministry of Business, Innovation and Employment (MBIE), established the first domestic legal framework for commercial space launch licensing in New Zealand; requires launch licence (for each launch or series of launches) and operator licence from MBIE; mandates third-party liability insurance covering New Zealand's international obligations under the Outer Space Treaty and Liability Convention; enables commercial launch from New Zealand territory by operators including Rocket Lab; sets operator liability and government authorisation conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "itu-radio-regulations-2020-edition",
      "usa-commercial-space-launch-act-1984-faa-licensing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nz-privacy-act-2020",
    "title": "New Zealand Privacy Act 2020",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The New Zealand Privacy Act 2020 regulates how public and private sector agencies handle personal information through 13 Information Privacy Principles (IPPs) outlined in Section 22. It mandates the notification of privacy breaches that are likely to cause serious harm and grants the Privacy Commissioner new powers to issue compliance notices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-popia-2013",
      "brazil-lgpd-compliance",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "nz-privacy-amendment-act-2025-ipp3a",
    "title": "New Zealand Privacy Amendment Act 2025 - Information Privacy Principle 3A on Indirect Collection Notification, In Force 1 May 2026",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Agencies that collect personal information about an individual from a source other than the individual themselves in New Zealand must, from 1 May 2026, comply with the new Information Privacy Principle 3A (IPP 3A) introduced by the Privacy Amendment Act 2025 (Royal Assent 23 September 2025), taking reasonable steps to ensure the individual is aware of specified matters including the name and address of the collecting agency, the purposes for which the information is being collected, and the rights of access to and correction of the information, in line with guidance developed by the Office of the Privacy Commissioner for businesses and agencies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "nz-resource-management-act-1991",
    "title": "New Zealand Resource Management Act 1991 - Sustainable Management, Resource Consents, and RMA Reform",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Resource Management Act 1991 (New Zealand) (RMA) is the principal legislation governing the use of land, water, air, and the coastal marine area in New Zealand. Section 5 establishes the purpose of the RMA: to promote the sustainable management of natural and physical resources, defined as managing the use, development, and protection of natural and physical resources in a way that enables people and communities to provide for their social, economic, and cultural wellbeing while sustaining the potential of natural and physical resources to meet the reasonably foreseeable needs of future generations, safeguarding the life-supporting capacity of ecosystems, and avoiding, remedying, or mitigating adverse effects on the environment. Section 9 prohibits any use of land unless permitted by a district plan rule or a resource consent granted by the relevant territorial authority. Section 14 restricts the taking or diversion of water and discharge of contaminants to water unless authorised by a regional plan or resource consent granted by the regional council. Section 15 restricts the discharge of contaminants to land or water. Section 88 sets out the requirements for resource consent applications. National Policy Statements (NPS) and National Environmental Standards (NES) issued under Sections 52 and 43 respectively establish national direction on specific matters. The Ministry for the Environment (MfE) is the central government agency with policy responsibility for the RMA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "au_environment_protection_biodiversity_conservation_act_1999",
        "eu_environmental_impact_assessment_directive_2011_92",
        "nz_health_safety_work_act_2015",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-hswa-2015-health-safety-work"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oas-standards-organic-agriculture-ifoam-2020",
    "title": "The Organic Guarantee System of IFOAM - Organics International",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the global framework for organic certification through the Organic Guarantee System (OGS), defining principles, conformity assessment, and recognition mechanisms for organic standards and Participatory Guarantee Systems (PGS). It applies to organic operators, certifiers, and accreditation bodies seeking alignment with IFOAM - Organics International norms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brc-food-safety-global",
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-food-hygiene-regulation-852-2004",
      "eu-food-labelling-regulation-1169-2011"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oasis-cacao-v2-0-security-playbooks",
    "title": "OASIS CACAO Security Playbooks Version 2.0 CS01 (Collaborative Automated Course of Action Operations, Workflow Step Types, 13 Command Types, STIX 2.1 Integration, OpenC2 Pairing)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "OASIS CACAO Security Playbooks Version 2.0, Committee Specification 01, dated 27 November 2023, defines a standardised JSON-based framework for cybersecurity playbooks - workflows for security orchestration containing a set of steps to detect, investigate, prevent, mitigate, or remediate security events. A CACAO playbook comprises Playbook Metadata (name, type, creator, versioning timestamps), Workflow Logic (orchestrated sequence of steps), Agent and Target Definitions (entities executing and receiving actions), Extensions (custom functionality declarations), Data Markings (sharing and handling restrictions including TLP), and optional Digital Signatures (authenticity verification). The workflow uses eight step types: start (entry point referencing initial action), end (termination), action (executes commands via specified agents against targets), playbook-action (invokes referenced playbooks for modular composition), parallel (executes 2+ branches simultaneously), if-condition (boolean logic with then-else branches), while-condition (loop execution while condition remains true), and switch-condition (multi-case branching with default handling). Each step supports optional delay, timeout, on_success, on_failure, and on_completion properties for flow control. CACAO v2.0 supports 13 command execution types: manual, bash, powershell, ssh, http-api, caldera-cmd, elastic, yara, kestrel, jupyter, sigma, openc2-http, and additional types defined by extensions. CACAO explicitly references STIX 2.1 standards for identity objects (in created_by properties), relationship objects (modelling connections), and STIX 2.1 patterning grammar (for conditional logic). Eight operational categories structure playbook types: Attack, Detection, Investigation, Prevention, Mitigation, Notification, Remediation, and Engagement. CACAO is the OASIS-standard playbook format that SOAR platforms, MSSPs, and CTI sharing communities use to exchange machine-executable runbooks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standard_basis",
        "key_institutions",
        "playbook_six_components",
        "workflow_step_types_taxonomy",
        "step_flow_control_properties",
        "command_execution_types",
        "agents_and_targets_taxonomy",
        "stix_2_1_integration",
        "authentication_information_types",
        "playbook_type_categories",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oasis-stix-2-1-structured-threat-information",
      "oasis-openc2-v1-0-cs02-command-control",
      "first-tlp-2-0-traffic-light-protocol"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oasis-csaf-2-0-common-security-advisory-framework",
    "title": "OASIS CSAF 2.0 Common Security Advisory Framework (Profile 1 Base, Profile 2 Security Incident Response, Profile 3 Informational Advisory, Profile 4 Security Advisory, Profile 5 VEX; JSON schema; CVRF 1.2 successor)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "OASIS Common Security Advisory Framework (CSAF) version 2.0 is the OASIS-published machine-readable standard for security advisory documents and is governed by the OASIS Common Security Advisory Framework Technical Committee (Chair Omar Santos of Cisco Systems; Editors Langley Rock of Red Hat, Stefan Hagen, and Thomas Schmidt of BSI Germany). CSAF 2.0 was approved as an OASIS Standard (os) on 18 November 2022 and is published at docs.oasis-open.org/csaf/csaf/v2.0/os/csaf-v2.0-os.html. CSAF 2.0 supersedes the predecessor CVRF (Common Vulnerability Reporting Framework) version 1.2 which used XML; CSAF 2.0 migrated to JSON as the primary serialisation. CSAF defines five profiles each constraining the document content to a named use case: Profile 1 CSAF Base (the minimum valid advisory document); Profile 2 Security Incident Response (incidents and their responses); Profile 3 Informational Advisory (general security communications without a specific vulnerability); Profile 4 Security Advisory (the canonical vulnerability advisory profile most widely used); Profile 5 VEX Vulnerability Exploitability eXchange (a per-product machine-readable statement of whether a vulnerability affects a product including the statuses not_affected, affected, fixed, under_investigation). The authoritative JSON schema is hosted at docs.oasis-open.org/csaf/csaf/v2.0/os/schemas/csaf_json_schema.json with aggregator and provider variants at the same base path. CSAF 2.0 is the recommended machine-readable security advisory format for vendors and PSIRTs and is referenced in U.S. federal supply-chain guidance, the European Cyber Resilience Act (CRA) implementation toolchain, and the CISA-led VEX adoption program; CSAF VEX is a primary mechanism for vendors to communicate exploitability status to SBOM consumers in support of EO 14028 and the EU CRA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "csaf_profile_1_base",
        "csaf_profile_2_security_incident_response",
        "csaf_profile_3_informational_advisory",
        "csaf_profile_4_security_advisory",
        "csaf_profile_5_vex",
        "cvrf_1_2_predecessor_relationship",
        "json_schema_location",
        "well_known_provider_metadata_discovery",
        "vex_in_eo_14028_and_eu_cra",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cve-program-cna-record-format-5",
      "cyclonedx-1-7-owasp-ecma-sbom-standard",
      "spdx-3-0-iso-iec-5962-2021-sbom-standard",
      "oasis-stix-2-1-structured-threat-information",
      "first-tlp-2-0-traffic-light-protocol"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "oasis-openc2-v1-0-cs02-command-control",
    "title": "OASIS OpenC2 Language Specification Version 1.0 CS02 (Open Command and Control, Action, Target, Args, Actuator, SLPF Actuator Profile, JSON Serialisation, HTTPS Transport)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "OASIS OpenC2 (Open Command and Control) Language Specification Version 1.0, Committee Specification 02, dated 24 November 2019, defines a concise and extensible language to enable machine-to-machine communications for purposes of command and control of cyber defense components. OpenC2 focuses on the Act phase of the OODA (Observe-Orient-Decide-Act) security decision loop and provides a vendor-agnostic way to orchestrate cyber defence actions across decoupled defence systems. The command structure has four elements: Action (required, the operation to execute such as scan, deny, contain, allow, start, stop, delete); Target (required, the subject acted upon such as file, device, IP address, domain, process); Arguments (optional, modifiers such as timing, duration, response type); and Actuator (optional, specifying which defence system executes the command). A minimal command requires only an action and target pair. The specification defines the Stateless Packet Filtering (SLPF) actuator profile as the normative reference profile; additional actuator profiles such as Endpoint Response are published as separate OASIS Committee Specifications. Profiles define function-specific language extensions using namespace identifiers (standard profiles use plain identifiers such as 'slpf'; vendor extensions use 'x-' prefixes such as 'x-acme'). OpenC2 mandates JSON serialisation per RFC 7493 (I-JSON) and references HTTPS as the normative transport, with other transport bindings published separately. OpenC2 pairs naturally with STIX 2.1 (CTI), TAXII 2.1 (CTI transport), and CACAO Security Playbooks v2.0 (playbook automation) and is the OASIS-standard layer for executing automated cyber defence actions across vendor boundaries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standard_basis",
        "key_institutions",
        "command_structure_four_elements",
        "minimal_command_pattern",
        "actuator_profiles_taxonomy",
        "serialisation_json_per_rfc_7493",
        "transport_https_normative",
        "response_message_status_codes",
        "openc2_pairing_with_stix_taxii_cacao",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oasis-stix-2-1-structured-threat-information",
      "first-tlp-2-0-traffic-light-protocol",
      "cyber-nist-csf-2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oasis-saml-2-0-federated-identity-workflow",
    "title": "OASIS SAML 2.0 - Security Assertion Markup Language for Enterprise Federated Identity",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "OASIS Security Assertion Markup Language (SAML) 2.0 (OASIS Standard, March 2005, revised 2012) is the foundational standard for enterprise federated identity, single sign-on (SSO), and cross-organizational authentication and authorization assertion exchange. SAML 2.0 defines XML-based assertions (authentication, attribute, authorization decision), bindings (HTTP Redirect, HTTP POST, Artifact), and profiles (Web Browser SSO, Enhanced Client or Proxy, Single Logout) enabling identity federation between Identity Providers (IdP) and Service Providers (SP). SAML 2.0 underpins enterprise SSO deployments across regulated industries including government, finance, healthcare, and defense, and remains the dominant federation standard in legacy enterprise environments despite the newer OpenID Connect protocol. Organizations operating workflow automation platforms integrating with enterprise identity infrastructure must implement SAML 2.0 SP functionality or SAML-to-OIDC translation layers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "openid-connect-core-1-0-identity-workflow",
      "eu-eidas-regulation-910-2014-electronic-identification"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oasis-stix-2-1-structured-threat-information",
    "title": "OASIS STIX Version 2.1 OASIS Standard (Structured Threat Information eXpression, STIX Domain Objects, Relationship Objects, Cyber Observable Objects, Patterning Language)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "STIX Version 2.1, ratified as an OASIS Standard on 10 June 2021, is the canonical JSON-based language and serialisation for representing Cyber Threat Intelligence (CTI). STIX 2.1 defines STIX Domain Objects (SDOs) - the higher-level intelligence objects including Attack Pattern, Campaign, Course of Action, Grouping, Identity, Incident, Indicator, Infrastructure, Intrusion Set, Location, Malware, Malware Analysis, Note, Observed Data, Opinion, Report, Threat Actor, Tool, and Vulnerability; STIX Relationship Objects (SROs) - Relationship (a generic typed connector with a relationship_type property) and Sighting (specialised for tracking observations of an indicator or other object with a count and observed-data context); and STIX Cyber Observable Objects (SCOs) - twenty object types representing network and host facts including files, processes, network traffic, IP addresses (IPv4 and IPv6), domain names, URLs, email addresses, email messages, and registry keys. STIX 2.1 uses a graph-based model where SDOs and SCOs form nodes and SROs form edges. STIX Patterning is the embedded language used in Indicator pattern properties to express detection logic over SCO observations with timestamp-aware matching. STIX 2.1 is the wire format paired with TAXII 2.1 (OASIS Standard) for trust-group exchange of threat intelligence and is the technical foundation for ISACs, ISAOs, CERT-to-CERT sharing, automated SOC pipelines, and machine-readable CTI integration across vendors. The CTI Technical Committee at OASIS maintains the specification; the previous version STIX 2.0 was published in 2017 and STIX 2.1 supersedes it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standard_basis",
        "key_institutions",
        "stix_domain_objects_sdo_taxonomy",
        "stix_relationship_objects_sro_taxonomy",
        "stix_cyber_observable_objects_sco_taxonomy",
        "stix_patterning_language",
        "taxii_pairing",
        "attack_to_stix_mapping",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-framework-v14",
      "mitre-atlas-ai-threat-matrix-2024",
      "cyber-nist-csf-2",
      "us-cisa-kev-catalog"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oasis-tosca-simple-profile-1-3-cloud-topology-orchestration",
    "title": "OASIS TOSCA Simple Profile YAML 1.3 - Cloud Application Topology and Orchestration",
    "domain": "Workflow Automation",
    "version": "1.3",
    "last_updated": "2026-05-09",
    "bluf": "OASIS TOSCA Simple Profile in YAML v1.3 (2020) provides a declarative, portable standard for describing cloud application topologies as node templates with relationship templates, capability types, and lifecycle interfaces; enables vendor-neutral automated deployment and day-2 management of multi-cloud workloads.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "opengitops-v1-0-declarative-workflow-principles",
      "bpmn-2-0-omg-specification-workflow-notation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oasis-ws-bpel-2-0-web-service-orchestration",
    "title": "OASIS WS-BPEL 2.0 - Web Services Business Process Execution Language",
    "domain": "Workflow Automation",
    "version": "2.0",
    "last_updated": "2026-05-09",
    "bluf": "WS-BPEL 2.0 (OASIS Standard, April 2007) defines XML-based orchestration logic for composing web services into executable business processes using partner links, correlation sets, structured activities, fault handlers, and compensation protocols; it is the primary standard for SOA service orchestration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "replaces"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bpmn-2-0-omg-specification-workflow-notation",
      "w3c-prov-dm-provenance-data-model-workflow-audit-trail"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oasis-xacml-3-0-access-control-policy-language",
    "title": "OASIS XACML 3.0 - eXtensible Access Control Markup Language",
    "domain": "Workflow Automation",
    "version": "3.0",
    "last_updated": "2026-05-09",
    "bluf": "OASIS XACML 3.0 (2013) is the standard policy language and enforcement architecture for attribute-based access control (ABAC); it defines Policy Administration Points (PAP), Policy Decision Points (PDP), Policy Enforcement Points (PEP), and Policy Information Points (PIP), with combining algorithms (deny-overrides, permit-overrides) and obligations/advice mechanisms for fine-grained, auditable authorization decisions in workflow and API governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oasis-ws-bpel-2-0-web-service-orchestration",
      "nist-sp-800-204b-zero-trust-microservices"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oau-refugee-convention-1969-african-union",
    "title": "OAU Refugee Convention 1969 - Expanded Refugee Definition for Africa, Non-Refoulement and Burden Sharing",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Convention Governing the Specific Aspects of Refugee Problems in Africa, adopted by the Organization of African Unity (OAU, now African Union) at Addis Ababa on 10 September 1969 and entered into force on 20 June 1974, is the regional African refugee protection treaty complementing the 1951 UN Refugee Convention and 1967 Protocol. As of 2024 the Convention has 46 States parties from among the 55 African Union Member States. Its principal innovation is Article 1(2) which expands the refugee definition to cover persons compelled to leave their country of origin owing to external aggression, occupation, foreign domination or events seriously disturbing public order in either part or the whole of their country of origin or nationality. This broader definition recognises group-based and generalised-violence flight situations that the 1951 individualised persecution test may not cover. Article 2 establishes asylum as a peaceful and humanitarian act not to be regarded as unfriendly act by any other Member State. Article 2(3) codifies non-refoulement: no person shall be subjected to measures such as rejection at the frontier, return or expulsion which would compel return to territory where life, physical integrity or liberty would be threatened. Article 3 prohibits subversive activities. Article 4 addresses non-discrimination among refugees. Article 5 covers voluntary repatriation; Article 9 the issuance of travel documents. The Convention is supervised by the AU and UNHCR.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-refugee-convention-1951-protocol-1967-non-refoulement"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "occ-asset-management-handbook",
    "title": "Comptroller’s Handbook Asset Management",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2023-06-01",
    "bluf": "The Office of the Comptroller of the Currency (OCC) defines asset management as the business of providing financial products or services to a third party for a fee or commission. This guidance applies to the asset management activities of national banks, federal savings associations (FSA), and limited purpose trust banks. It provides an overview of the asset management business, its risks, and sound risk management processes, describing the OCC’s supervisory philosophy and processes. Asset management activities include traditional fiduciary services, retail brokerage, investment company services, and custody and security-holder services, which expose national banks to a broad range of operational, compliance, strategic, and reputation risks.\n\nThe core obligation for these institutions is to maintain sound risk management processes. National banks must have the ability to effectively identify, measure, control, and monitor risks in their asset management businesses. Because most of these risks arise from off-balance-sheet activities, they are not easily identified using traditional financial reporting. Significant breaches of fiduciary and contractual responsibilities can result in financial losses, damage a bank’s reputation, and impair its ability to achieve its strategic goals. The board of directors and senior management are ultimately responsible for establishing and maintaining effective control functions commensurate with the institution’s goals, risk tolerance, and complexity of operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "occ-bank-supervision-process",
      "interagency-guidance-third-party-risk-management",
      "sr-11-7-model-risk-management",
      "safeguarding-advisory-client-assets"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "occ-bank-supervision-process",
    "title": "Comptroller’s Handbook Examination Process Bank Supervision Process",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2025-03-20",
    "bluf": "This booklet is the central reference for the Office of the Comptroller of the Currency (OCC)’s bank supervision policy, explains the OCC’s risk-based bank supervision approach, and discusses the general supervisory process for all types of OCC-supervised banks. The OCC's mission is to ensure that national banks, federal savings associations (FSA), and federal branches and agencies of foreign banking organizations operate in a safe and sound manner, provide fair access to financial services, treat customers fairly, and comply with applicable laws and regulations. For supervisory purposes, the OCC designates banks as community, midsize, or large based on asset size and factors that affect risk profile and complexity.\n\nHigh-quality bank supervision is ongoing and dynamic, responds to changing risks at each bank, and uses OCC resources efficiently by allocating the greatest resources to the areas of highest risk. The core process involves a required full-scope, on-site examination every 12 or 18 months, known as the supervisory cycle. A bank may be eligible for an 18-month cycle if it has less than $3 billion in total assets, is well capitalized, received strong management and composite ratings at its most recent examination, and is not subject to a formal enforcement proceeding. The supervisory process includes planning, discovery, correction, monitoring, and communication with the bank's management and board, culminating in a Report of Examination (ROE) and the assignment of regulatory ratings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "occ-bulletin-2023-17-risk",
    "title": "OCC 2023-17 (Third-Party)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "OCC Bulletin 2023-17 (Interagency Guidance on Third-Party Relationships: Risk Management) provides a unified U.S. standard for managing the risks of the third-party providers. it specifies a life-cycle approach to the oversight of the vendor, the cloud service, and the any other outside partnership.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "occ-bulletin-2023-17-third-party-risk-management",
    "title": "OCC Bulletin 2023-17 Third-Party Risk Management Interagency Guidance",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "OCC Bulletin 2023-17, issued jointly by the OCC, Federal Reserve, and FDIC in June 2023, provides interagency guidance on third-party risk management for banking organizations, establishing a risk-based approach to managing third-party relationships across the full lifecycle - planning, due diligence, contract negotiation, ongoing monitoring, and termination - with heightened requirements for critical activities and fintech arrangements, replacing the OCC's prior 2013-29 guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "frb-sr-11-7-model-risk-management",
      "us-dodd-frank-act-2010"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ocsf-open-cybersecurity-schema-framework-1-8-0",
    "title": "OCSF Open Cybersecurity Schema Framework Version 1.8.0 (Categories, Event Classes, Objects, Profiles, Extensions, Schema Browser at schema.ocsf.io)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "The Open Cybersecurity Schema Framework (OCSF) is an open, vendor-agnostic, normalized JSON schema for security event data. OCSF version 1.8.0 was released on 18 March 2026 by the OCSF project on GitHub. The framework is organised as a set of Categories (top-level event domains such as System Activity, Findings, Identity & Access Management, Network Activity, Application Activity, Discovery, Threat Intelligence), Event Classes (specific event types within each category such as Process Activity, Network Connection, Authentication, Vulnerability Finding), reusable Objects (such as User, Device, Process, File, Network Endpoint), Profiles (overlay schemas for specific use cases such as Host Profile, Cloud Profile, Container Profile, Linux Profile, Windows Profile) and Extensions (Linux, Windows, and project-specific schema extensions). The canonical schema is browsed interactively at schema.ocsf.io and is defined in the ocsf-schema GitHub repository under categories.json, dictionary.json, and the events/ and objects/ folders. OCSF is positioned as the lingua franca for SIEM, SOAR, EDR, XDR, cloud security platform, and DSPM ingestion: security vendors emit OCSF-conformant events so security platforms can normalise across products without bespoke parsers. Founding sponsors include Splunk, AWS, IBM Security (QRadar), Cribl, Tanium, Trend Micro, Securonix, JupiterOne, Sumo Logic, DTEX, IronNet, Okta, Palo Alto Networks, Rapid7, Salesforce, Zscaler, and others, with the project hosted at github.com/ocsf/ocsf-schema and governed by an OCSF Steering Committee under the Linux Foundation umbrella since 2024. The framework is intentionally not restricted to cybersecurity alone and is designed to extend to broader operational telemetry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standard_basis",
        "key_institutions",
        "ocsf_categories_taxonomy",
        "ocsf_event_class_structure",
        "ocsf_objects_reusable_definitions",
        "ocsf_profiles_overlay_schemas",
        "ocsf_extensions_mechanism",
        "schema_browser_and_governance",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oasis-stix-2-1-structured-threat-information",
      "mitre-attack-framework-v14",
      "cyber-nist-csf-2",
      "iso-27017-2015-cloud-controls"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-ai-principles",
    "title": "The OECD AI Principles",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-12",
    "bluf": "The OECD AI Principles are the first intergovernmental standard on AI, designed to promote innovative, trustworthy artificial intelligence that respects human rights and democratic values. While AI holds the potential to address complex challenges and boost productivity, AI systems also pose risks to privacy, safety, security, and human autonomy. To develop safe, secure and trustworthy AI systems, there is a need to assess these impacts and manage risks. The principles guide AI actors in their efforts to develop trustworthy AI and provide policymakers with recommendations for effective AI policies, which were revised in 2024 to stay abreast of rapid technological developments. For governments to work together to manage AI on an international level, they need to use common terms and definitions to act as a foundation for cooperation, allowing for interoperability across jurisdictions even with varying approaches to managing the technology.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "unesco-ethics-ai",
      "nist-ai-rmf-map",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "oecd-ai-principles-2019-2024-update-trustworthy-ai",
    "title": "OECD Recommendation on Artificial Intelligence (2019, Updated May 2024) - Principles for Trustworthy AI and Recommendations to Policymakers",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "The OECD Recommendation on Artificial Intelligence is an international intergovernmental standard adopted by the OECD Council on 22 May 2019 and updated on 3 May 2024. The Recommendation consists of (1) five value-based principles for the responsible stewardship of trustworthy AI: inclusive growth, sustainable development and well-being; human rights and democratic values, including fairness and privacy; transparency and explainability; robustness, security and safety; and accountability; and (2) five recommendations to policymakers: invest in AI R&D; foster an inclusive AI-enabling ecosystem; shape an enabling interoperable governance and policy environment for AI; build human capacity and prepare for labour market transition; and international co-operation for trustworthy AI. The May 2024 update reflects advances in generative AI, AI safety, AI integrity, and the definition of an AI system, aligning the OECD Recommendation more closely with the EU AI Act and the G7 Hiroshima AI Process. The Recommendation has been adopted by all 38 OECD member states and 8 non-member adherents. It underpins the G20 AI Principles, the OECD AI Incidents Monitor, and is referenced in the OECD AI Policy Observatory (oecd.ai).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "g20-ai-principles-2019",
      "council-of-europe-ai-treaty-2024",
      "eu-ai-act-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-ai-principles-2024",
    "title": "OECD AI Principles 2024 - Updated Recommendation on Artificial Intelligence",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The OECD Recommendation of the Council on Artificial Intelligence (originally adopted May 2019, significantly updated May 2024) establishes the foundational international AI governance framework that has informed the EU AI Act, the G7 Hiroshima AI Process, and national AI regulatory frameworks across 42+ signatory countries - the five OECD AI Principles address: (1) inclusive growth, sustainable development, and well-being; (2) human-centred values and fairness; (3) transparency and explainability; (4) robustness, security, and safety; and (5) accountability; the 2024 update added new provisions addressing generative AI, AI systems and the environment, safety and security risks of advanced AI models, and alignment with the EU AI Act's definition of AI systems; the Recommendation is non-binding but carries significant influence as the internationally agreed AI governance baseline adopted by all OECD members and several non-members including Argentina, Brazil, Colombia, Costa Rica, and Peru.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/oecd-ai-principles-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "eu-ai-act-article-3-definitions",
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-14-human-oversight",
      "coe-framework-convention-ai-human-rights-democracy",
      "g7-hiroshima-ai-process-guiding-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-ai-principles-2024-recommendation-updated-framework",
    "title": "OECD AI Principles 2024 (Updated Recommendation) - Trustworthy AI Values and Implementation",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The updated OECD Recommendation on AI (OECD/LEGAL/0449, revised 2024) provides the international reference framework for trustworthy AI governance adopted by 46 countries: 5 values-based principles (inclusive growth, human rights, transparency and explainability, robustness and safety, accountability) and 5 implementation recommendations for governments. The 2024 update adds provisions on AI system lifecycle management, advanced AI systems (frontier models), and classification of AI system risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024-1689-article-26-obligations-deployers-high-risk-ai"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-ai-principles-2024-update",
    "title": "OECD AI Principles 2024 Update - Inclusive Growth, Human-Centred Values, Transparency, Robustness and Accountability",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-05-17",
    "bluf": "The OECD AI Principles, updated in May 2024, provide a global, non-binding framework for governments and organizations to ensure AI systems are trustworthy, human-centric, and respect the rule of law. The update addresses generative AI risks, emphasizing the need for robust safety protocols, accountability across the lifecycle, and responsible information sharing, as detailed in the revised Principle 1.4 on Robustness, Security and Safety.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "g20-ai-principles-2019",
      "g7-hiroshima-ai-process-2023",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-ai-principles-recommendation-2024",
    "title": "OECD Recommendation on Artificial Intelligence (2024 Update) - Five OECD AI Principles: Inclusive Growth, Human-Centred Values, Transparency, Robustness and Accountability",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The OECD AI Principles require AI actors and policymakers to ensure AI systems are developed and used in ways that respect human rights, promote transparency, and ensure robustness and accountability. Key obligations are outlined in the updated 2024 Principles under the OECD Recommendation on AI, which guide national policies and global interoperability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "australia-voluntary-ai-safety-standard-2024",
      "eu-esrs-s1-workforce",
      "nist-ai-100-4-redteam"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-algorithmic-collusion-policy-note-2023",
    "title": "OECD Policy Note on Algorithmic Collusion 2023 - Autonomous Pricing Algorithms, Hub-and-Spoke Arrangements, Tacit Collusion Detection, Antitrust Liability and Regulatory Responses",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This policy note provides guidance for competition authorities on detecting and addressing anticompetitive outcomes arising from autonomous pricing algorithms, including hub-and-spoke liability and tacit collusion facilitated by AI-driven pricing. It applies to firms deploying algorithmic pricing systems in oligopolistic markets and informs enforcement under existing prohibitions on anti-competitive agreements (e.g., Article 101 TFEU, Section 1 of the Sherman Act).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-recommendation-hard-core-cartels-2019",
      "uk-competition-act-1998-chapter-1-2-prohibitions",
      "india-competition-act-2002-sections-3-4",
      "canada-competition-act-2024-amendment-abuse-dominance",
      "eu-state-aid-articles-107-108-tfeu-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-anti-bribery-convention-1997",
    "title": "OECD Convention on Combating Bribery of Foreign Public Officials in International Business Transactions",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This convention requires signatory countries to criminalize the act of intentionally offering, promising, or giving any undue pecuniary or other advantage to a foreign public official to obtain or retain business or other improper advantage in international business. The core offence is defined in Article 1, obligating Parties to establish it as a criminal offence under their domestic law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fcpa-anti-bribery-compliance",
      "uk-bribery-act-2010",
      "iso-37001-anti-bribery-2016",
      "oecd-corporate-governance-principles",
      "sarbanes-oxley-act-sox"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-anti-bribery-convention-1997-foreign-public-officials",
    "title": "OECD Anti-Bribery Convention 1997 - Foreign Public Official Bribery Offence and Working Group Peer Review",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The OECD Convention on Combating Bribery of Foreign Public Officials in International Business Transactions, adopted on 21 November 1997 and entered into force on 15 February 1999, is the principal international instrument criminalising bribery of foreign public officials in international business. Article 1 requires Parties to criminalise the offer, promise or giving of any undue pecuniary or other advantage to a foreign public official for that official to act or refrain from acting in relation to performance of official duties to obtain or retain business or other improper advantage in international business. Article 2 requires liability of legal persons. Article 3 requires effective, proportionate and dissuasive penalties including monetary sanctions comparable to those for bribery of own public officials. Article 4 requires jurisdiction over offences committed in territory and (where Party criminalises bribery of own officials abroad) by nationals abroad. Article 5 prohibits enforcement decisions being influenced by national economic interest, potential effect on relations, or identity of natural/legal persons involved. The Working Group on Bribery monitors implementation through peer review (Phase 1: legislative; Phase 2: enforcement; Phase 3: enforcement and remaining issues; Phase 4: ongoing). 46 States Parties as of 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-whistleblower-protection-directive-2019-1937",
      "eiti-standard-2023-extractive-industries-transparency"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-attribution-profits-permanent-establishments-2010",
    "title": "2010 Report on the Attribution of Profits to Permanent Establishments",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This report establishes the Authorised OECD Approach (AOA) for attributing profits to a permanent establishment (PE) for corporate income tax purposes, as endorsed by the OECD Council. The AOA requires treating the PE as a functionally separate entity and applying the arm's length principle to its internal dealings with other parts of the enterprise, based on a two-step analysis under Article 7 of the OECD Model Tax Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-model-double-taxation-convention-2021",
      "oecd-beps-action-3-cfc-rules-2015"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-beps-action-1-digital-economy-2015",
    "title": "Addressing the Tax Challenges of the Digital Economy, Action 1 - 2015 Final Report",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2025-10-05",
    "bluf": "This OECD/G20 report analyzes tax challenges from digitalization and proposes options to adapt international tax rules, focusing on nexus, withholding taxes, and VAT/GST. Its most widely adopted recommendation, detailed in Chapter 9, is the International VAT/GST Guidelines for collecting tax on cross-border B2C supplies of services and intangibles based on the destination principle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-beps-action-12-mandatory-disclosure-rules",
    "title": "OECD BEPS Action 12 - Mandatory Disclosure Rules (MDR)",
    "domain": "Tax & Transfer Pricing",
    "version": "2.0.0",
    "last_updated": "2023-03-03",
    "bluf": "OECD BEPS Action 12 Final Report (2015) and the 2023 Reporting Framework for Digital Platform Operators provide recommended rules requiring promoters and users of aggressive tax arrangements to disclose them to tax authorities - enabling early detection of tax avoidance schemes. The EU implemented Action 12 through DAC6 (Directive 2018/822), mandating mandatory cross-border arrangement reporting with hallmarks and 30-day filing deadlines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-country-by-country-reporting",
      "oecd-beps-action-15-multilateral-instrument",
      "eu-dac6-mandatory-disclosure-2018-822"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-beps-action-13-cbc-reporting",
    "title": "OECD/G20 Base Erosion and Profit Shifting (BEPS) Project Action 13: Transfer Pricing Documentation and Country-by-Country Reporting",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation requires multinational enterprise (MNE) groups with annual consolidated revenue of €750 million or more to file a Country-by-Country (CbC) Report, providing a detailed breakdown of revenues, profits, taxes paid, and other indicators of economic activity for each tax jurisdiction in which they operate, as specified in the 2015 Final Report.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crs-oecd-tax-automatic",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-beps-action-13-cbcr-guidance-2023-update",
    "title": "OECD BEPS Action 13 Country-by-Country Reporting Guidance 2023 - Domestic Filing Obligations, Exchange Framework and Confidentiality Safeguards",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires multinational enterprises (MNEs) to file a country-by-country report (CbCR) with their tax authority, as outlined in Article 3 of the OECD Model Legislation, and applies to MNEs with a consolidated revenue of EUR 750 million or more.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-beps-action-13-country-by-country-reporting",
    "title": "OECD Base Erosion and Profit Shifting (BEPS) Action 13 - Transfer Pricing Documentation and Country-by-Country Reporting",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Requires multinational enterprise (MNE) groups with consolidated group revenue of EUR 750 million or more to prepare a three-tiered transfer pricing documentation structure: Master File, Local File, and Country-by-Country Report (CbCR). The CbCR must be filed annually by the ultimate parent entity and automatically exchanged between tax authorities under the Multilateral Competent Authority Agreement (MCAA). Applies to fiscal years beginning on or after 1 January 2016. Key requirement under Action 13, Chapter IV of the OECD BEPS Action Plan.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two",
      "eu-dac6-mandatory-disclosure-hallmarks-2020",
      "canada-transfer-pricing-income-tax-act-section-247",
      "australia-transfer-pricing-laws-amendment-2012"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-beps-action-14-map-peer-review",
    "title": "OECD/G20 BEPS Action 14 - Making Dispute Resolution More Effective: Mutual Agreement Procedure (MAP) Minimum Standard, Peer Review Process and Arbitration Provisions Under MLI",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes a minimum standard for resolving tax treaty-related disputes via the Mutual Agreement Procedure (MAP) for all committed jurisdictions. It mandates timely and effective dispute resolution, prevention of disputes, and accessibility of MAP, enforced through a peer review process as defined in the Terms of Reference.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-beps-action-15-mli",
    "title": "Multilateral Convention to Implement Tax Treaty Related Measures to Prevent Base Erosion and Profit Shifting (MLI)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The OECD Multilateral Instrument (MLI) enables jurisdictions to swiftly modify their bilateral tax treaties to implement measures against Base Erosion and Profit Shifting (BEPS), such as preventing treaty abuse and improving dispute resolution. Its application to a specific treaty depends on the matching reservations and notifications made by both signatory jurisdictions under Part VI of the Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crs-oecd-tax-automatic"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "oecd-beps-action-15-multilateral-instrument",
    "title": "Multilateral Convention to Implement Tax Treaty Related Measures to Prevent Base Erosion and Profit Shifting (MLI)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The OECD BEPS Action 15 Multilateral Instrument (MLI) enables over 100 jurisdictions to swiftly implement BEPS minimum standards into their bilateral tax treaties, including treaty override mechanisms, a Principal Purpose Test (PPT), hybrid mismatch rules, and changes to permanent establishment thresholds. It applies to multinational enterprises and tax administrations of signatory jurisdictions under Article 2(1) and Article 7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-atad2-hybrid-mismatches-2017-952",
      "canada-transfer-pricing-income-tax-act-section-247",
      "australia-transfer-pricing-laws-amendment-2012",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-beps-action-2-hybrid-mismatch-2015",
    "title": "OECD/G20 BEPS Action 2 (2015) - Neutralising Effects of Hybrid Mismatch Arrangements: Recommendations for Domestic Law Changes and Treaty Provisions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-10-05",
    "bluf": "This OECD report provides recommendations for domestic law and tax treaty provisions to neutralize the tax effects of hybrid mismatch arrangements, which exploit differences in the tax treatment of an entity or instrument. It primarily targets multinational enterprises by recommending a set of interlocking 'linking rules' that deny a deduction for a payment or require it to be included in income to eliminate the mismatch, as detailed in Chapter 1's primary and defensive rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-beps-action-3-cfc-rules-2015",
    "title": "Designing Effective Controlled Foreign Company (CFC) Rules, Action 3 - 2015 Final Report",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2025-10-29",
    "bluf": "This OECD/G20 BEPS report provides recommendations for jurisdictions to implement effective Controlled Foreign Company (CFC) rules to prevent the artificial shifting of profits to low-tax jurisdictions. It outlines six essential 'building blocks' for designing these rules, covering CFC definition, control thresholds, income attribution, and exemptions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-beps-action-4-interest-deductions-2016",
    "title": "Limiting Base Erosion Involving Interest Deductions and Other Financial Payments, Action 4 - 2016 Update",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This OECD/G20 BEPS recommendation requires jurisdictions to limit a multinational group's net interest deductions to a fixed percentage of its EBITDA, typically between 10-30%, to combat base erosion and profit shifting. As detailed in Chapter 4, this 'fixed ratio rule' is supplemented by an optional 'group ratio rule' and targeted rules for specific sectors like banking and insurance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-beps-action-5-preferential-regimes-2019",
    "title": "Countering Harmful Tax Practices More Effectively, Taking into Account Transparency and Substance, Action 5 - 2019 Progress Report on Preferential Regimes",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This OECD/G20 BEPS initiative requires jurisdictions to ensure preferential tax regimes, especially for Intellectual Property (IP), are linked to substantial economic activity via the 'nexus approach'. As detailed in Chapter 4 of the 2015 Final Report, this approach mandates that tax benefits are proportional to the qualifying R&D expenditures incurred by the taxpayer to generate the IP income, and requires spontaneous exchange of information on taxpayer-specific rulings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-beps-action-6-treaty-abuse-2015",
    "title": "Preventing the Granting of Treaty Benefits in Inappropriate Circumstances, Action 6 - 2015 Final Report",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This OECD/G20 BEPS standard requires jurisdictions to implement measures in their bilateral tax treaties to prevent treaty shopping and other abuse strategies. As a minimum standard, treaties must include either a Principal Purpose Test (PPT), a detailed Limitation on Benefits (LOB) rule supplemented by an anti-conduit mechanism, or both (Paragraph 22).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-beps-action-6-treaty-abuse-mlti-2015",
    "title": "OECD BEPS Action 6 - Prevention of Treaty Abuse 2015: Principal Purpose Test (PPT), Limitation on Benefits (LOB) Clause, Minimum Standard for Inclusion in Tax Treaties, Entitlement to Treaty Benefits Analysis, Derivative Benefits Provision and Holding Structures",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a minimum standard to prevent treaty shopping by requiring tax treaties to include a Principal Purpose Test (PPT) or Limitation on Benefits (LOB) clause. It applies to all multinational enterprises and treaty signatories evaluating entitlement to reduced withholding taxes under bilateral tax treaties, per Action 6 of the OECD/G20 BEPS Project.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-anti-tax-avoidance-directive-atad1-2016",
      "eu-arm-length-principle-article-9-oecd-model"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-beps-action-7-pe-avoidance-2015",
    "title": "Preventing the Artificial Avoidance of Permanent Establishment Status, Action 7 - 2015 Final Report",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This OECD/G20 BEPS report modifies Article 5 of the OECD Model Tax Convention to prevent multinational enterprises from artificially avoiding a taxable presence (Permanent Establishment) in a country. It specifically targets commissionnaire arrangements and the abuse of specific activity exemptions by introducing a new dependent agent test and an anti-fragmentation rule.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-cbcr-guidance-2023-update"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-beps-actions-8-10-transfer-pricing-value-creation",
    "title": "OECD BEPS Actions 8-10 - Transfer Pricing and Value Creation",
    "domain": "Tax & Transfer Pricing",
    "version": "2.0.0",
    "last_updated": "2022-01-20",
    "bluf": "OECD BEPS Actions 8-10 Final Reports (2015), incorporated into the OECD Transfer Pricing Guidelines (2022 edition), mandate that profits follow value creation by aligning transfer pricing outcomes with the actual functions performed, assets owned, and risks assumed (FAR analysis) - eliminating paper-based profit shifting through contractual allocation of risk and capital without economic substance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "eu_regulation",
        "uk_equivalent",
        "us_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-country-by-country-reporting",
      "oecd-beps-action-15-multilateral-instrument",
      "oecd-beps-pillar-two-global-minimum-tax"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-beps-pillar-two-global-minimum-tax",
    "title": "Council Directive (EU) 2022/2523 / OECD GloBE Model Rules - Pillar Two Global Minimum Tax: 15% Effective Tax Rate, Income Inclusion Rule, Undertaxed Profits Rule, Qualified Domestic Minimum Top-up Tax, Substance-Based Income Exclusion and GloBE Information Return",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Council Directive (EU) 2022/2523 implements the OECD GloBE Model Rules in the EU, requiring multinational enterprise (MNE) groups with consolidated annual revenue of at least €750 million in at least 2 of the 4 preceding fiscal years to pay a top-up tax whenever the effective tax rate (ETR) of constituent entities in a jurisdiction falls below 15%; the Income Inclusion Rule (IIR) requires the ultimate parent entity (or intermediate parent) to collect the top-up tax; the Undertaxed Profits Rule (UTPR) acts as a backstop; Member States may implement a Qualified Domestic Minimum Top-up Tax (QDMTT) to retain top-up tax domestically; a Substance-Based Income Exclusion (SBIE) carves out payroll (5% of eligible payroll costs) and tangible assets (5% of net book value) from the GloBE income base; MNE groups must file a GloBE Information Return (GIR) within 15 months of fiscal year end (21 months for the first year in scope); EU Member States were required to transpose the Directive by 31 December 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "OECD_PILLAR_ONE",
        "EU_ATAD",
        "OECD_TP",
        "US_GILTI",
        "IFRS_AMENDMENT"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-1-2016-1164",
      "oecd-transfer-pricing-guidelines-2022",
      "eu-dac6-mandatory-disclosure-2018-822"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-carf-crypto-asset-reporting-framework-2022",
    "title": "Crypto-Asset Reporting Framework (CARF) and Amendments to the Common Reporting Standard",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The OECD CARF requires entities and individuals providing services that effectuate exchange transactions in Crypto-Assets (Reporting Crypto-Asset Service Providers or RCASPs) to conduct due diligence on their customers and report detailed transactional and user information annually to their local tax authorities for automatic exchange between participating jurisdictions, as outlined in Section I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-carf-crypto-asset-reporting-framework-tax-2022",
    "title": "OECD Crypto-Asset Reporting Framework (CARF) 2022 - Tax Reporting Obligations for Crypto-Asset Service Providers and Automatic Exchange with Tax Authorities",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The OECD's Crypto-Asset Reporting Framework (CARF) mandates that Crypto-Asset Service Providers (CASPs) conduct due diligence on their customers and report detailed information on crypto-asset transactions annually to their local tax authorities for automatic exchange with other jurisdictions, as detailed in Sections III and IV of the framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015",
      "un-model-double-taxation-convention-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-coe-mutual-administrative-assistance-tax-1988",
    "title": "OECD/COE Convention on Mutual Administrative Assistance in Tax Matters 1988/2010 - AEOI and Tax Information Exchange",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-25",
    "bluf": "The Multilateral Convention on Mutual Administrative Assistance in Tax Matters (1988, amended by 2010 Protocol - 147 jurisdictions as of 2025) is the overarching legal basis for the OECD/G20 global tax transparency agenda: it enables automatic exchange of information (AEOI) under the Common Reporting Standard (CRS), spontaneous exchange of BEPS-relevant rulings under BEPS Action 5, simultaneous tax examinations, tax debt collection assistance, and service of foreign tax documents - financial institutions, multinational enterprises, and HNWIs must understand that any income or assets in a participating jurisdiction are reportable to home country tax authorities automatically under CRS, and that tax rulings provided in one jurisdiction are shared with all treaty partners; the Convention is the legal instrument under which over 100 bilateral Competent Authority Agreements (CAAs) for CRS are activated.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-anti-bribery-convention-1997",
      "un-convention-against-corruption-uncac-2003",
      "vclt-vienna-convention-law-of-treaties-1969",
      "oecd-crs-common-reporting-standard-2014"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-common-reporting-standard-crs-2014",
    "title": "OECD Common Reporting Standard (CRS) - Automatic Exchange of Financial Account Information",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "The OECD CRS (adopted 2014, first exchanges 2017) is the global standard for automatic exchange of financial account information (AEOI): financial institutions in 100+ jurisdictions identify non-resident account holders, collect self-certification and due diligence, and report account data annually to their home tax authority, which exchanges it with the account holder's jurisdiction of tax residence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-6amld-sixth-anti-money-laundering-2018-1673",
      "fincen-cdd-beneficial-ownership-rule-2016",
      "eu-brrd-bank-recovery-resolution-directive-2014-59"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-competition-assessment-principles-2019",
    "title": "OECD Competition Assessment Principles 2019 - Regulatory Impact Assessment for Competition Policy, Market Study Toolkit, Sector Screening and OECD Competition Law and Policy Peer Review Framework",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This OECD framework provides a methodology for governments and regulators to identify and assess unnecessary restraints on market competition within existing or proposed laws and regulations. It requires a systematic evaluation using the Competition Checklist (Toolkit Principle 1) to determine if a regulation limits the number of suppliers, restricts their ability to compete, reduces their incentives to compete, or limits consumer choice.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-competition-assessment-toolkit-2019",
    "title": "OECD Competition Assessment Toolkit 2019 - Identifying and Evaluating Competition Restrictions in Laws and Regulations: ROGIL Test, Sectoral Assessments and Policy Recommendations",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This toolkit provides a structured methodology for reviewing laws and regulations to identify and assess competition restrictions using the ROGIL framework (Regulatory Objectives, Goals, Impacts, Less restrictive alternatives). It applies to government agencies, competition authorities, and regulators conducting sectoral competition assessments to recommend pro-competitive reforms under Chapter II and Annex A of the toolkit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-recommendation-hard-core-cartels-2019",
      "uk-cma-merger-assessment-guidelines-2021",
      "india-competition-act-2002-sections-3-4",
      "australia-competition-consumer-act-2010-part-iv",
      "japan-antimonopoly-act-2019-amendment-jftc"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-competition-assessment-toolkit-v3-2023",
    "title": "OECD Competition Assessment Toolkit Volume 3 2023 - Screening Regulations for Undue Restrictions to Competition in Product and Service Markets",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This toolkit provides a structured methodology for governments and competition authorities to identify, assess, and recommend the removal of legal and regulatory barriers that unduly restrict competition in product and service markets. It applies to national regulatory agencies, sectoral regulators, and competition authorities conducting ex ante competition screening under Chapter II, Section 2 of the document.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-recommendation-hard-core-cartels-2019",
      "uk-cma-merger-assessment-guidelines-2021",
      "india-competition-act-2002-sections-3-4",
      "australia-competition-consumer-act-2010-part-iv",
      "icn-recommended-practices-merger-notification-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-competition-digital-economy-roundtable-2023",
    "title": "OECD Roundtable on Competition in the Digital Economy: Self-Preferencing, Interoperability Remedies, Data Access Orders and Multi-Homing Restrictions",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This OECD roundtable synthesizes emerging competition policy approaches for digital markets, focusing on self-preferencing by dominant platforms, interoperability as a structural remedy, data access orders to enhance contestability, and restrictions on multi-homing barriers. It applies to competition authorities, digital platform operators, and regulators assessing market fairness under Article 7 of the OECD Recommendation on Competition Policy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeepers",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-corporate-governance-principles",
    "title": "OECD Corporate Governance",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The G20/OECD Principles of Corporate Governance are the international standard for corporate governance. Revised in 2023, they provide a framework for policy makers and corporations to ensure institutional and legal environments that support investment, sustainability, and corporate accountability in a global market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-guidelines-multinational-ent",
      "sarbanes-oxley-act-sox",
      "csrd-eu-sustainability",
      "un-guiding-principles-business-hr"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-crs-automatic-exchange",
    "title": "Standard for Automatic Exchange of Financial Account Information in Tax Matters (Common Reporting Standard)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-07-18",
    "bluf": "The OECD Common Reporting Standard (CRS) requires financial institutions in participating jurisdictions to perform due diligence to identify financial accounts held by non-resident individuals and entities, and report this information annually to their local tax authority for automatic exchange with the account holders' jurisdictions of tax residence, as outlined in Section I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatca-iga-compliance",
      "bank-secrecy-act-suspicious"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "oecd-crs-common-reporting-standard-2014",
    "title": "Common Reporting Standard on Automatic Exchange of Financial Account Information for Tax Purposes (CRS), 2014 Edition",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The OECD Common Reporting Standard (CRS) requires financial institutions in participating jurisdictions to identify financial accounts held by tax residents of foreign jurisdictions and report account information annually to their local tax authorities, which then automatically exchange the data with treaty partners. Key obligations are defined in Section VIII, Paragraph 1(a) and Section IX, Paragraph 1 of the Standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-dac7-digital-platform-reporting-2021-514",
      "eu-dac8-crypto-asset-tax-reporting-2023-2226",
      "fatf-40-recommendations-2023-consolidated"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-crs-common-reporting-standard-implementation",
    "title": "Standard for Automatic Exchange of Financial Account Information in Tax Matters (Common Reporting Standard - CRS)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The OECD Common Reporting Standard (CRS) mandates that financial institutions in participating jurisdictions collect and report financial account information of non-resident customers to their local tax authorities for automatic exchange with other jurisdictions. This framework, detailed in Section I (General Reporting Requirements) and Sections II-VII (Due Diligence Procedures), aims to combat offshore tax evasion by increasing transparency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-risk-based-approach-banking-sector-2014",
      "oecd-beps-action-3-cfc-rules-2015"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-crypto-asset-reporting-framework-carf-2023",
    "title": "OECD Crypto-Asset Reporting Framework (CARF) 2023 - Standard for Automatic Exchange of Information on Crypto-Asset Transactions",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The CARF requires Crypto-Asset Service Providers (CASPs) to report annual transactional data on crypto-asset holdings and transfers for users in participating jurisdictions, under the Standard for Automatic Exchange of Information (AEOI). Applies to exchanges, custodial wallets, DeFi platforms facilitating transactions, and NFT marketplaces where fungible tokens are used, per Section II of the 2023 CARF document.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "eu-dlt-pilot-regime-2022-858",
      "bis-iosco-pfmi-applied-to-dlt-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-customs-transfer-pricing-wco-interface-2015",
    "title": "OECD WCO Customs Valuation and Transfer Pricing Interface - Resolving Conflicts Between Customs Value and Arm's Length Price for Related Parties",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires customs authorities and tax administrations to resolve conflicts between customs value and arm's length price for related parties, as outlined in Article 1 of the OECD WCO Customs Valuation and Transfer Pricing Interface.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-attribution-profits-permanent-establishments-2010",
      "oecd-financial-transactions-transfer-pricing-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-due-diligence-minerals-supply-chains-2016",
    "title": "OECD Due Diligence Guidance for Responsible Mineral Supply Chains from Conflict-Affected and High-Risk Areas (3rd Edition 2016)",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This guidance requires mineral supply chain actors - including smelters, refiners, traders, and downstream companies - to implement a risk-based due diligence framework to identify, assess, mitigate, and report on risks of human rights abuses and conflict financing in mineral sourcing. Key obligations are defined in the Five-Step Framework (Section II) and Annex II for tin, tantalum, tungsten, gold, and cobalt.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp",
      "un-sdg-corporate-mapping"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-financial-transactions-transfer-pricing-2020",
    "title": "OECD Transfer Pricing Guidance on Financial Transactions 2020 - Accurate Delineation, Treasury Functions, Cash Pooling and Financial Guarantees",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This guidance requires multinational enterprises (MNEs) to accurately delineate and price intra-group financial transactions, including loans, cash pooling, hedging, and financial guarantees, in accordance with the arm's length principle. It provides a framework, per Chapter I, Section D.1 of the OECD Transfer Pricing Guidelines, for analyzing the commercial and financial relations to ensure pricing reflects that of independent parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015",
      "un-model-double-taxation-convention-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-frascati-manual-2015-rd-statistics",
    "title": "OECD Frascati Manual 2015 - Measurement of Scientific, Technological and Innovation Activities: R&D Definition, Basic/Applied/Experimental Research Classification, Personnel and Expenditure Surveys",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The OECD Frascati Manual 2015 establishes internationally agreed definitions and measurement standards for research and development (R&D) activities, including classification into basic research, applied research, and experimental development, and provides guidelines for collecting and reporting R&D personnel and expenditure data. It applies to national statistical offices, research institutions, and government agencies responsible for science and innovation policy (Section II, Paragraph 37).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-european-research-area-policy-agenda-2022",
      "eu-open-science-policy-fair-data-principles-2021",
      "oecd-recommendation-responsible-research-innovation-2021",
      "iso-21001-2018-educational-organizations-management",
      "oecd-pisa-education-assessment-framework-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-global-forum-transparency-peer-review-phase-2",
    "title": "OECD Global Forum on Transparency and Exchange of Information for Tax Purposes: Phase 2 Peer Reviews",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The OECD Global Forum Phase 2 Peer Reviews require jurisdictions to have in place a legal framework that enables the exchange of information on request (EOIR) in accordance with Article 26 of the OECD Model Tax Convention, and to ensure the confidentiality of the information exchanged as per Section 3 of the Terms of Reference.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-crs-common-reporting-standard-implementation",
      "eu-dac6-mandatory-disclosure-hallmarks-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-globe-income-inclusion-rule-2021",
    "title": "Tax Challenges Arising from the Digitalisation of the Economy - Global Anti-Base Erosion Model Rules (Pillar Two): Income Inclusion Rule",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The OECD GloBE Income Inclusion Rule (IIR) imposes a top-up tax on the Ultimate Parent Entity (UPE) of a Multinational Enterprise (MNE) Group with annual consolidated revenue of €750 million or more, when the income of its constituent entities in a jurisdiction is taxed below the minimum rate of 15%. The primary charging provision is established in Article 2.1 of the Model Rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-globe-undertaxed-profits-rule-utpr",
    "title": "OECD GloBE Undertaxed Profits Rule (UTPR) (2022) - Backstop to IIR: Allocation Mechanism Between Constituent Entities, Ordering Rules and QDMTT Interaction for MNEs",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-12-20",
    "bluf": "The Undertaxed Profits Rule (UTPR) is a backstop component of the OECD's Pillar Two GloBE rules, imposing a top-up tax on a multinational enterprise (MNE) group's constituent entities when the low-taxed income of a foreign group member is not fully taxed under an Income Inclusion Rule (IIR), as detailed in Article 2.4 of the Model Rules. It applies to MNEs with over €750 million in consolidated revenue and allocates the top-up tax among jurisdictions where the MNE operates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-cbcr-guidance-2023-update",
      "oecd-pillar-two-global-minimum-tax"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-going-digital-toolkit-telecoms-policy",
    "title": "OECD Going Digital Toolkit - Broadband Policy Module: Infrastructure Investment, Spectrum Policy, Net Neutrality Assessment, Digital Connectivity Statistics and National Broadband Plan Benchmarking Methodology",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This OECD policy module provides a benchmarking framework for national broadband strategies, requiring governments to assess infrastructure investment incentives, spectrum allocation efficiency, net neutrality safeguards, and digital connectivity metrics. It applies to national regulatory authorities and telecommunications policymakers in OECD member states and partner economies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-net-neutrality-open-internet-2015-2120",
      "eu-radio-spectrum-policy-programme-decision",
      "eu-broadband-cost-reduction-directive-2014-61",
      "3gpp-5g-nr-release-17-specifications"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-good-laboratory-practice-principles-revised-1997",
    "title": "OECD Revised Principles of Good Laboratory Practice (1997)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The OECD Revised Principles of Good Laboratory Practice (1997) require test facilities to establish a quality assurance programme, as outlined in Principle 2, and to designate a study director, as stated in Principle 8. This regulation applies to test facilities conducting non-clinical health and environmental safety studies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-gcp-e6-r3-2023",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "oecd-guidelines-biotechnology-safety-2000",
    "title": "OECD Guidelines on Safety Considerations for Biotechnology 2000 - Contained Use Risk Assessment, Scale-Up Considerations, Worker Health Monitoring and Environmental Release Controls",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "These OECD Guidelines establish a risk-based framework for the safe handling of genetically modified organisms (GMOs) during contained use, scale-up, and environmental release, with specific requirements for risk assessment, worker health monitoring, and environmental protection. Key obligations are outlined in Section IV (Risk Assessment) and Section V (Scale-Up and Environmental Release).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "oecd-guidelines-human-biobanks-2009",
      "ich-q5a-r2-viral-safety-biotech-2024",
      "singapore-genetic-modification-advisory-gmac",
      "australia-gene-technology-act-2000"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-guidelines-consumer-protection-2016",
    "title": "Recommendation of the Council on Consumer Protection in E-commerce",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This OECD recommendation provides a framework for businesses engaged in B2C e-commerce to ensure fair practices, requiring clear and conspicuous disclosure of business identity, product/service information, and full transaction terms before the consumer is bound (Part I, Section A). It applies to all businesses conducting electronic commerce with consumers, with a focus on cross-border transactions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-10008-b2c-ecommerce",
      "eu-consumer-rights-directive-2011",
      "ftc-digital-advertising-disclosures",
      "gdpr-art-21-marketing-optout"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-guidelines-human-biobanks-2009",
    "title": "OECD Guidelines on Human Biobanks and Genetic Research Databases 2009 - Consent, Data Governance, Sample Access and Benefit-Sharing Principles",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "These guidelines establish international standards for the governance of human biobanks and genetic research databases, requiring informed consent, data protection, equitable access to samples, and benefit-sharing. Key obligations are outlined in Principle 3 (Consent) and Principle 6 (Access and Benefit-Sharing).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-27001-2022",
      "coe-convention-108-plus"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-guidelines-multinational-ent",
    "title": "OECD Guidelines (Multinationals)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The OECD Guidelines for Multinational Enterprises on Responsible Business Conduct (RBC) are the most comprehensive international standard on business conduct. Revised in 2023, they provide recommendations from governments to enterprises on issues such as human rights, employment, environment, anti-bribery, and consumer interests, supported by the unique NCP grievance mechanism.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-guiding-principles-business-hr",
      "ilo-fundamental-rights-work",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-hard-to-value-intangibles-guidance-2018",
    "title": "Guidance for Tax Administrations on the Application of the Approach to Hard-to-Value Intangibles (BEPS Action 8)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This guidance permits tax administrations to use ex-post outcomes (actual financial results) as presumptive evidence to challenge the arm's length pricing of Hard-to-Value Intangibles (HTVI) transfers between related parties, as detailed in Chapter VI, Section D.4 of the OECD Transfer Pricing Guidelines. Taxpayers can rebut this presumption by demonstrating the reliability of their ex-ante pricing projections and showing that deviations are due to unforeseeable developments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-cbcr-guidance-2023-update"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-inclusive-framework-beps-140-countries",
    "title": "OECD Inclusive Framework on BEPS - 140+ Countries: Four Minimum Standards (Actions 5, 6, 13, 14), Peer Reviews, Capacity Building, Pillar One and Pillar Two Implementation and IF Deliverables",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The OECD Inclusive Framework on Base Erosion and Profit Shifting (BEPS) requires 140+ jurisdictions to implement four minimum standards: countering harmful tax practices (Action 5), preventing treaty abuse (Action 6), ensuring transfer pricing documentation transparency via Country-by-Country Reporting (Action 13), and effective dispute resolution (Action 14), verified through peer review processes. Multinational enterprises with consolidated group revenue of €750 million or more are subject to reporting obligations under Action 13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-global-minimum-tax-directive-2022-2523-pillar-two",
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "canada-transfer-pricing-income-tax-act-section-247",
      "australia-transfer-pricing-laws-amendment-2012",
      "eu-dac6-mandatory-disclosure-hallmarks-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-mineral-supply",
    "title": "OECD Mineral Due Diligence",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Conformance with internationally recognized mineral due diligence frameworks is evaluated through a comprehensive five-step process. The organization demonstrates strong company management by maintaining a public supply chain policy that explicitly references OECD guidance. Governance is reinforced by a designated compliance officer, a functional chain of custody system, and the inclusion of due diligence clauses within supplier contracts. An anonymous grievance mechanism is also implemented for stakeholder reporting. Risk identification and assessment procedures are executed at a minimum frequency of every 12 months; the most recent evaluation identified zero high-risk suppliers, obviating immediate mitigation strategies. However, a robust supplier corrective action program remains in place to address any future findings. The program’s integrity is verified through independent third-party audits, with the last assessment completed within the past 365 days. Furthermore, all identified smelters and refiners in the supply chain are confirmed as conformant with the Responsible Minerals Assurance Process. Public transparency is achieved through the publication of an annual due diligence report detailing these efforts and findings, fulfilling key reporting obligations under global regulations concerning minerals sourced from conflict-affected and high-risk areas.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "iso-20400-sustainable-proc",
      "iso-26000-social-resp"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-model-tax-convention-2017-mfn",
    "title": "OECD Model Tax Convention on Income and on Capital: Condensed Version 2017",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The OECD Model Tax Convention 2017 provides the global standard framework for bilateral tax treaties to eliminate double taxation and prevent fiscal evasion. It establishes rules for residence tie-breaker (Article 4), permanent establishment (PE) thresholds (Article 5), taxation of dividends (Article 10), interest (Article 11), royalties (Article 12), capital gains (Article 13), and mandates exchange of information (Article 26) and mutual agreement procedures (Article 25) between tax authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two",
      "australia-transfer-pricing-laws-amendment-2012",
      "canada-transfer-pricing-income-tax-act-section-247",
      "eu-dac6-mandatory-disclosure-hallmarks-2020"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "oecd-model-tax-convention-2017-pe-royalties",
    "title": "OECD Model Tax Convention on Income and Capital 2017 - Permanent Establishment (Article 5), Business Profits (Article 7), Royalties (Article 12) and Capital Gains (Article 13)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The OECD Model Tax Convention provides a template for bilateral tax treaties to prevent double taxation by defining when an enterprise has a taxable presence (Permanent Establishment, Article 5) in another country, and establishing rules for the allocation of taxing rights over business profits (Article 7), royalties (Article 12), and capital gains (Article 13) between the enterprise's home country and the source country.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-pillar-one-amount-a-mne-reallocation",
    "title": "OECD Pillar One Amount A - Reallocation of Profits to Market Jurisdictions for Large Multinational Enterprises",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Requires multinational enterprises (MNEs) with global revenue over €20 billion and profitability exceeding 10% to reallocate 25% of residual profits to market jurisdictions where revenue is sourced, based on nexus conditions and revenue sourcing rules under Amount A of the OECD/G20 Inclusive Framework on Base Erosion and Profit Shifting (BEPS). Applies to covered groups as defined in the Multilateral Convention to Implement Amount A.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-arm-length-principle-article-9-oecd-model",
      "canada-transfer-pricing-income-tax-act-section-247"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-pillar-one-amount-a-multilateral-convention",
    "title": "Multilateral Convention to Implement Amount A of Pillar One",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This multilateral convention reallocates 25% of residual profits from multinational enterprises (MNEs) with global turnover above €20 billion and profitability above 10% to the market jurisdictions where their users and customers are located. As defined in Article 3 (Scope), this new taxing right (Amount A) applies regardless of the MNE's physical presence, targeting automated digital services and consumer-facing businesses.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-pillar-one-amount-a-multilateral-convention-2023",
    "title": "Multilateral Convention to Implement Amount A of Pillar One - Reallocation of Taxing Rights for MNEs above €20bn Revenue and 10% Profitability Threshold",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This multilateral convention reallocates taxing rights on a portion of residual profits from the largest and most profitable Multinational Enterprises (MNEs) to the market jurisdictions where their customers are located. As defined in Article 3, it applies to MNEs with annual global revenues exceeding €20 billion and a pre-tax profit margin above 10%, reallocating 25% of their residual profit above this threshold.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-model-double-taxation-convention-2021",
      "oecd-beps-action-3-cfc-rules-2015"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "oecd-pillar-one-market-jurisdiction-allocation",
    "title": "OECD Pillar One - Amount A: Reallocation of Residual Profits to Market Jurisdictions Based on Revenue Threshold, Profitability, and Nexus Rules",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation requires multinational enterprises (MNEs) with global revenue above USD 20 billion and profitability exceeding 10% to reallocate 25% of residual profits to market jurisdictions where revenue is generated, provided a nexus threshold of at least EUR 1 million in local revenue (or EUR 250,000 for smaller markets) is met. Applies under Amount A of the OECD/G20 Inclusive Framework on Base Erosion and Profit Shifting (BEPS) Pillar One, subject to the Multilateral Convention (MLC).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-global-minimum-tax-directive-2022-2523-pillar-two",
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "canada-transfer-pricing-income-tax-act-section-247",
      "australia-transfer-pricing-laws-amendment-2012",
      "eu-transfer-pricing-directive-proposal-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-pillar-two-administrative-guidance-2023-july",
    "title": "Tax Challenges Arising from the Digitalisation of the Economy - Administrative Guidance on the Global Anti-Base Erosion Model Rules (Pillar Two), July 2023",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2024-07-18",
    "bluf": "This OECD guidance provides further clarification on the application of the Pillar Two Global Anti-Base Erosion (GloBE) rules for Multinational Enterprises (MNEs) with revenues over €750 million. It details the standardized GloBE Information Return (GIR) framework (Section 1), the use of Country-by-Country Report (CbCR) data for the Transitional CbCR Safe Harbour (Section 2), and rules for currency conversion and the treatment of Blended CFC Taxes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-pillar-two-global-minimum-tax",
    "title": "Council Directive (EU) 2022/2523 - Global Minimum Level of Taxation for MNE Groups: 15% GloBE Rules, Income Inclusion Rule (IIR), Undertaxed Profits Rule (UTPR), Qualified Domestic Minimum Top-up Tax (QDMTT) and Substance-Based Income Exclusions",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "MNE groups with consolidated annual revenue ≥€750M must maintain ≥15% effective tax rate per jurisdiction; parent entities apply IIR to pay top-up tax on low-taxed constituent entities; UTPR backstop collects uncollected top-up tax from fiscal years ending 31 December 2024; Member States may elect QDMTT to retain local collection rights with 3-year commitment; substance-based income exclusions for eligible payroll and tangible assets reduce qualifying income subject to top-up tax per Article 28; GloBE Information Return due within 15 months of fiscal year end through designated filing entity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "OECD_BEPS",
        "EU_ATAD",
        "IAS_12",
        "EU_DAC6"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-cbcr-guidance-2023-update",
      "eu-atad-anti-tax-avoidance-2016"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "oecd-pillar-two-global-minimum-tax-15-percent",
    "title": "OECD Pillar Two - Global Anti-Base Erosion (GloBE) Rules: Income Inclusion Rule, Undertaxed Profits Rule, 15% Global Minimum Tax, Substance-Based Income Exclusion, QDMTT and Safe Harbour Provisions",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a global minimum corporate tax rate of 15% for multinational enterprise (MNE) groups with revenue above EUR 750 million, applying the Income Inclusion Rule (IIR) and Undertaxed Profits Rule (UTPR) to ensure top-up taxation on low-taxed income. It applies to MNEs under GloBE Rules, as defined in Article 1 of the OECD Model Rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-global-minimum-tax-directive-2022-2523-pillar-two",
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "canada-transfer-pricing-income-tax-act-section-247",
      "australia-transfer-pricing-laws-amendment-2012",
      "eu-dac6-mandatory-disclosure-hallmarks-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-pillar-two-global-minimum-tax-15-percent-globe-rules",
    "title": "OECD Pillar Two - Global Minimum Tax 15% GloBE Rules and Qualified Domestic Minimum Top-up Tax",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2023-12-18",
    "bluf": "OECD Pillar Two GloBE Rules require large multinational enterprises with consolidated revenue above EUR 750 million to pay a minimum effective tax rate of 15% in each jurisdiction, with top-up tax collected by the parent or intermediate jurisdiction through the Income Inclusion Rule and Undertaxed Profits Rule.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "oecd-beps-action-13-country-by-country-reporting"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-pillar-two-global-minimum-tax-globe-rules-15pct",
    "title": "OECD Pillar Two - Global Anti-Base Erosion (GloBE) Rules 15% Global Minimum Tax",
    "domain": "Tax & Transfer Pricing",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "OECD Pillar Two GloBE Rules impose a global minimum effective tax rate of 15% on multinational enterprises with annual consolidated revenue exceeding EUR 750 million - implemented via Income Inclusion Rule (IIR) and Undertaxed Profits Rule (UTPR) with country-by-country reporting and Qualified Domestic Minimum Top-Up Tax (QDMTT) elections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-pillar-two-global-minimum-tax-model-rules-2021",
    "title": "Tax Challenges Arising from the Digitalisation of the Economy - Global Anti-Base Erosion Model Rules (Pillar Two)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2024-12-20",
    "bluf": "The OECD Pillar Two GloBE Model Rules require multinational enterprises (MNEs) with annual consolidated revenues exceeding €750 million to pay a minimum effective tax rate (ETR) of 15% on profits in each jurisdiction where they operate. As outlined in Article 1.1, this is enforced through a system of top-up taxes applied via the Income Inclusion Rule (IIR) and the Undertaxed Profits Rule (UTPR).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015",
      "un-model-double-taxation-convention-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-pillar-two-qdmtt-undertaxed-profits-rule",
    "title": "OECD Pillar Two - Qualified Domestic Minimum Top-Up Tax (QDMTT) and Undertaxed Profits Rule (UTPR)",
    "domain": "Tax & Transfer Pricing",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "OECD Pillar Two GloBE Rules establish a 15% global minimum effective tax rate for MNE groups with consolidated revenue of EUR 750 million or more. The Qualified Domestic Minimum Top-Up Tax (QDMTT) allows jurisdictions to collect top-up tax on domestic constituent entities before the Income Inclusion Rule (IIR) or Undertaxed Profits Rule (UTPR) apply; the QDMTT safe harbour removes the IIR/UTPR liability in respect of the jurisdictions where it applies. The Undertaxed Profits Rule (UTPR) acts as a backstop: where the IIR does not fully collect the top-up tax (no parent in a IIR jurisdiction, or parent is in a low-tax jurisdiction), the UTPR allocates the remaining top-up tax to other group jurisdictions on a payroll/assets formula. OECD administrative guidance (February, July 2023, June 2024) provides the transitional safe harbours, QDMTT accounting standards requirements, and UTPR denial mechanics.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-pillar-two-global-minimum-tax-15-percent",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "oecd-pillar2-minimum",
    "title": "Global Minimum Tax (Pillar Two)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "OECD Pillar Two (Global Anti-Base Erosion Rules - GloBE) establishes a global minimum corporate tax rate of 15% for multinational enterprises (MNEs) with annual revenue exceeding €750 million. Finalized in December 2021 and enacted in over 40 jurisdictions as of 2024 (EU Minimum Tax Directive effective January 1, 2024; UK, Japan, South Korea, Switzerland among first adopters), Pillar Two introduces two interlocking domestic rules: the Income Inclusion Rule (IIR) - the parent entity pays top-up tax on low-taxed subsidiaries; and the Undertaxed Profits Rule (UTPR) - a backstop where other group members can collect the top-up tax if the parent jurisdiction does not apply IIR. Non-compliance results in top-up taxes, transfer pricing adjustments, and potential double taxation in multiple jurisdictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "oecd-guidelines-multinational-ent",
      "crs-oecd-tax-automatic",
      "ifrs-global-accounting"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-pisa-assessment-framework-education",
    "title": "OECD PISA 2022 Assessment Framework - Reading, Mathematics, Science, Financial Literacy, Global Competence: Construct Definition, Item Development, Sampling, Scaling and Country Reporting Methodology",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This framework defines the cognitive constructs, item development protocols, national sampling requirements, psychometric scaling methods, and country-level reporting standards for the Programme for International Student Assessment (PISA) 2022. It applies to all participating countries and their designated national centers responsible for PISA implementation, requiring adherence to standardized methodologies under Chapter 2 (Construct Definitions), Chapter 3 (Item Development), Chapter 4 (Sampling), Chapter 5 (Scaling), and Chapter 6 (Reporting).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-pisa-education-assessment-framework-2022",
      "eu-digcomp-digital-competence-framework-2022",
      "india-national-education-policy-nep-2020",
      "iso-21001-2018-educational-organizations-management",
      "oecd-principles-ai-in-education-recommendation-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-pisa-education-assessment-framework-2022",
    "title": "OECD PISA 2022 Assessment Framework - Reading, Mathematics and Science Literacy: Creative Thinking Domain, Digital Competence and Global Competence",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The OECD PISA 2022 Assessment Framework establishes the methodological and cognitive foundations for evaluating 15-year-old students’ literacy in reading, mathematics, science, creative thinking, digital competence, and global competence across participating countries. It applies to national education authorities and assessment bodies responsible for implementing PISA-aligned evaluations, with key requirements defined in Chapter 2 (Cognitive Domains) and Chapter 4 (Contextual Frameworks).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-sdg-4-education-2030-framework-action"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-policy-framework-disaster-risk-financing-2017",
    "title": "OECD Policy Framework for Disaster Risk Financing - Sovereign Risk Transfer, Contingent Credit and Parametric Insurance Instruments",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This OECD framework provides governments with a strategic approach for developing a comprehensive disaster risk financing strategy to enhance financial resilience against natural and man-made catastrophes. It guides the selection and implementation of financial instruments like contingent credit, sovereign insurance, and catastrophe bonds, as detailed in Chapter 2, to ensure timely and sufficient post-disaster funding.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-prevention-treaty-abuse-mli-action-6",
    "title": "Multilateral Convention to Implement Tax Treaty Related Measures to Prevent Base Erosion and Profit Shifting (MLI) - Article 7: Prevention of Treaty Abuse",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The OECD's Multilateral Instrument (MLI) Article 7 implements BEPS Action 6, requiring signatory jurisdictions to adopt a Principal Purpose Test (PPT) to deny tax treaty benefits where obtaining such benefits was a principal purpose of an arrangement or transaction. This rule applies to multinational enterprises and other entities seeking benefits under a Covered Tax Agreement, unless granting the benefit aligns with the treaty's object and purpose.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-model-double-taxation-convention-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-principles-ai-in-education-recommendation-2023",
    "title": "OECD Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449) applied to Education, Knowledge and Research",
    "domain": "Education & Research",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "There is no standalone OECD Recommendation dedicated to AI in education. The applicable OECD instrument is the Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449, adopted 2019 and revised 2024), the first intergovernmental AI standard, whose value-based principles (inclusive growth and well-being; human-centred values and fairness; transparency and explainability; robustness, security and safety; accountability) apply to AI systems deployed in educational, knowledge and research contexts. OECD education-specific work on AI is delivered through reports such as the OECD Digital Education Outlook and AI and the Future of Skills, not through a binding Recommendation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-privacy-guidelines-2013",
    "title": "OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data (2013 Revision)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The OECD Privacy Guidelines establish eight core principles for the protection of personal data in both public and private sectors, promoting international data flows while upholding privacy rights. The 2013 revision introduced a mandatory Privacy Management Programme (Part Two, Paragraph 15) to ensure practical and effective accountability for data controllers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "apec-cbpr-system-2011",
      "coe-convention-108-plus",
      "oecd-corporate-governance-principles",
      "un-guiding-principles-business-hr",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-recommendation-hard-core-cartels-2019",
    "title": "OECD Recommendation on Fighting Hard Core Cartels 2019 Revision - Effective Cartel Detection, Leniency Programmes, Sanctions and International Cooperation",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This OECD Recommendation requires competition authorities to implement robust enforcement mechanisms against hard-core cartels, including effective leniency programmes, deterrent sanctions, and proactive international cooperation. It applies to all member and adhering countries' competition enforcement agencies, with key obligations outlined in Paragraphs 12-24 of the Recommendation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "oecd-recommendation-insurance-good-practices-2004",
    "title": "OECD Recommendation on Good Practices for Insurance Claim Management - Fair Settlement, Transparency and Anti-Fraud Standards",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-05-27",
    "bluf": "This OECD recommendation establishes non-binding principles for insurers and intermediaries in member countries to ensure fair, transparent, and timely settlement of insurance claims, and to effectively combat fraud. The core requirements, detailed in the Annex, cover good faith, transparency, communication, promptness, and the establishment of anti-fraud policies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-recommendation-responsible-research-innovation-2021",
    "title": "OECD Recommendation on Responsible Innovation in Neurotechnology 2021 - Privacy, Cognitive Liberty, Data Governance and Ethics in Neuroscience Research",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This Recommendation requires research institutions, neurotechnology developers, and public funding bodies to implement ethical safeguards for cognitive liberty, informed consent, and neurodata governance in neuroscience research and innovation. Key obligations are outlined in Principle 4 (Informed Consent), Principle 5 (Privacy and Data Governance), and Principle 7 (Human Autonomy and Cognitive Liberty).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021",
      "thailand-pdpa-2019-personal-data-protection"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-regulatory-framework-connected-automated-vehicles",
    "title": "OECD International Transport Forum (ITF) Policy Guidance on Connected and Automated Vehicles - Advisory Principles for Regulating Automated Mobility (Binding ADS Rules via UNECE WP.29)",
    "domain": "Automotive & Mobility",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The OECD International Transport Forum (ITF) publishes non-binding policy guidance on connected and automated vehicles (CAVs), not a binding numbered regulatory framework. Relevant ITF/OECD reports include 'Making Automated Vehicles Work for Better Transport Services: Regulating for Impact' (2023), 'Preparing Infrastructure for Automated Vehicles', and 'AI, Machine Learning and Regulation: The Case of Automated Vehicles'. These set out principles for forward-looking, adaptive regulation; they do not impose a no-fault liability regime, a fixed cross-border insurance minimum, or numbered binding sections. Binding type-approval and operational rules for Automated Driving Systems are set by UNECE WP.29 (GRVA), notably UN Regulation No. 157 (Automated Lane Keeping Systems), the UN cybersecurity and software-update regulations (UN R155/R156), and national law; SAE J3016 defines the levels of driving automation referenced throughout. This node applies the ITF advisory principles while routing each binding obligation to its actual source instrument.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021",
      "oecd-recommendation-insurance-good-practices-2004",
      "thailand-pdpa-2019-personal-data-protection"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-regulatory-reform-energy-sector-competition",
    "title": "OECD Principles for Energy Regulatory Frameworks - Market Design, Network Regulation, Consumer Protection and Cross-Border Coordination",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This framework provides guiding principles for OECD member countries to establish and maintain effective energy regulatory systems that promote competition, ensure network security, and protect consumers. It requires the establishment of independent regulatory institutions (Principle 1) and the implementation of non-discriminatory market designs and network access rules (Principles 2 & 3) to foster efficient and reliable energy markets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sherman-antitrust-act-sections-1-2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-tp-financial-transactions-guidance-2020",
    "title": "Transfer Pricing Guidance on Financial Transactions: Inclusive Framework on BEPS: Actions 4, 8-10",
    "domain": "Banking & Global Finance",
    "version": "2020.02.11",
    "last_updated": "2026-04-18",
    "bluf": "This OECD guidance requires multinational enterprises (MNEs) to apply the arm's length principle to intra-group financial transactions by accurately delineating the actual transaction and pricing it based on comparable uncontrolled transactions. It provides specific frameworks for loans, cash pooling, hedging, financial guarantees, and captive insurance, as incorporated into Chapter X of the OECD Transfer Pricing Guidelines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "oecd-tp-guidelines-2022",
    "title": "OECD Transfer Pricing Guidelines for Multinational Enterprises and Tax Administrations 2022",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "These guidelines provide the international consensus on valuing cross-border transactions between associated enterprises within a Multinational Enterprise (MNE) group for tax purposes. They mandate the application of the 'arm's length principle,' as detailed in Chapter I, requiring that transaction conditions be comparable to those that would have been agreed between unrelated parties in similar circumstances.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crs-oecd-tax-automatic"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-tp-profit-split-guidance-2018",
    "title": "OECD Transfer Pricing Guidance on Profit Splits (2018) - Delineation of Transaction, Contribution Analysis, Residual Analysis and Appropriate Split Factors for Integrated Transactions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This guidance clarifies when and how to apply the transactional profit split method for multinational enterprises, requiring its use for highly integrated cross-border transactions where both parties make unique and valuable contributions that cannot be reliably benchmarked separately. The core requirement, detailed in Chapter II, Section C of the OECD Transfer Pricing Guidelines, is to split profits in a manner that is consistent with how independent enterprises would have divided them under arm's length conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-transfer-pricing-chapter-i-arm-length-principle",
    "title": "OECD Transfer Pricing Guidelines - Chapter I: The Arm's Length Principle and Comparability Analysis",
    "domain": "Tax & Transfer Pricing",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "OECD Transfer Pricing Guidelines for Multinational Enterprises and Tax Administrations (2022 edition) Chapter I establishes the arm's length principle (ALP) as the international standard for pricing controlled transactions between associated enterprises; the ALP requires that the conditions of a controlled transaction should not differ from those that would have been made between independent enterprises in comparable transactions under comparable circumstances. The comparability analysis identifies: the conditions of the transaction; the functions performed, assets used, and risks assumed (FAR analysis); the contractual terms; the economic circumstances; and the business strategies. The delineation of the actual transaction is a prerequisite to pricing - an improperly structured transaction may be re-characterised by tax authorities under Chapter I paragraphs 1.119-1.131.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-transfer-pricing-guidelines-2022-full-edition",
      "eu-arm-length-principle-article-9-oecd-model"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "oecd-transfer-pricing-guidelines-2022",
    "title": "OECD Transfer Pricing Guidelines for Multinational Enterprises and Tax Administrations (2022 Edition)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the international standard for applying the arm’s length principle to transfer pricing between related parties in multinational enterprises. It requires taxpayers and tax administrations to conduct comparability analyses and apply one of five transfer pricing methods (CUP, RPM, CPM, TNMM, PSM) to ensure pricing reflects market conditions, per Chapter I, Section D.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-transfer-pricing-directive-proposal-2023",
      "canada-transfer-pricing-income-tax-act-section-247",
      "india-advance-pricing-agreement-rules-2012",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oecd-transfer-pricing-guidelines-2022-full-edition",
    "title": "OECD Transfer Pricing Guidelines for Multinational Enterprises and Tax Administrations 2022",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "These guidelines provide the international consensus on valuing cross-border transactions between associated enterprises within a Multinational Enterprise (MNE) group for tax purposes. They mandate the application of the arm's length principle, as set out in Article 9 of the OECD Model Tax Convention, requiring that transaction conditions be comparable to those that would have been made between independent enterprises.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-model-double-taxation-convention-2021",
      "oecd-beps-action-3-cfc-rules-2015"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "oecd-vat-gst-guidelines-2017-international",
    "title": "OECD International VAT/GST Guidelines 2017 - Destination Principle, Place of Supply Rules for B2B and B2C Services, Tax Neutrality for Cross-Border Trade and Reverse Charge Mechanism",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "These OECD guidelines establish the Destination Principle for the cross-border trade of services and intangibles, requiring VAT/GST to be levied in the jurisdiction of consumption. For business-to-business (B2B) supplies, Guideline 3.2 specifies the main place of taxation rule is the jurisdiction in which the business customer is located.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ohio-telehealth-2026",
    "title": "Ohio Telehealth Licensure, Reimbursement & Privacy Rules 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "Ohio permits out-of-state licensed providers to deliver telehealth services with registration. 2026 updates include full reimbursement parity for private payers, expanded audio-only coverage, and alignment with HIPAA and state data privacy requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "om-pdpl-2022",
    "title": "Oman Personal Data Protection Law 2022 - MTCIT",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Oman's Personal Data Protection Law (PDPL) - Royal Decree No. 6/2022, issued by His Majesty Sultan Haitham bin Tarik on 9 February 2022 and published in the Official Gazette of Oman - is Oman's first comprehensive personal data protection legislation, making Oman one of the later Gulf Cooperation Council (GCC) member states to enact a standalone data protection law (following Bahrain's 2018 PDPL and Qatar's 2016 law). The PDPL commenced its transitional period upon publication, with full compliance required within a two-year transition period (i.e., by February 2024). The implementing regulations were issued, and the Ministry of Transport, Communications and Information Technology (MTCIT) - designated under Article 7 of the PDPL - is the supervisory authority responsible for receiving notifications, investigating complaints, and enforcing the PDPL. Key features of Oman's PDPL: (1) Scope - applies to any natural person or legal entity that processes personal data within Oman, or that processes personal data of individuals residing in Oman regardless of where the processor is located; (2) Data processing principles - personal data processing must comply with the following principles: lawfulness; fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; security and confidentiality; and accountability; (3) Lawful processing bases - personal data may be processed only where one of the following applies: the data subject's consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests of the controller (where not overriding the data subject's rights); (4) Sensitive personal data - the PDPL designates categories requiring enhanced protection: racial or ethnic origin; political opinions; religious, philosophical, or moral beliefs; genetic data; biometric data used for unique identification; health or medical data; sexual orientation; criminal records; and financial data; processing of sensitive personal data requires explicit consent or a statutory exception; (5) Data subject rights - right of access; right to correction; right to erasure; right to restriction of processing; right to data portability; right to object to processing; right not to be subject to solely automated decision-making with significant effects; (6) Data Controller obligations - appoint a Data Protection Officer (DPO) in specified circumstances; conduct Personal Data Protection Impact Assessments (DPIAs) for high-risk processing; implement data protection by design and default; maintain records of processing activities; notify the MTCIT and data subjects of personal data breaches; (7) Breach notification - controllers must notify the MTCIT of personal data breaches within 72 hours of becoming aware of the breach; data subjects must be notified where the breach poses a high risk to their rights; (8) Cross-border data transfers - personal data may only be transferred outside Oman to countries providing adequate protection or subject to MTCIT-approved safeguards; (9) Penalties - fines of up to OMR 500,000 (approximately USD 1.3 million); criminal penalties including imprisonment for wilful violations. Oman's PDPL is a significant development in Gulf data governance and aligns Oman with international data protection standards as the Sultanate pursues its Vision 2040 digital economy objectives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "om-pdpl-2022-data-subject-rights",
    "title": "Oman Personal Data Protection Law Royal Decree No.6/2022 - Rights of Personal Data Subjects",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Oman Personal Data Protection Law (Royal Decree No. 6/2022) grants data subjects enforceable rights: right to be informed of processing; right to access personal data held; right to correct inaccurate data; right to erasure where the processing purpose has ended or consent is withdrawn; right to restrict processing; right to object; and right to data portability. The Information Technology Authority (ITA) receives complaints and has enforcement powers including administrative and criminal penalties. Implementing regulations (MD 930/2023) specify response timelines and technical requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "om-pdpl-2022",
      "om-pdpl-2022-lawful-processing-conditions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "om-pdpl-2022-lawful-processing-conditions",
    "title": "Oman Personal Data Protection Law Royal Decree No.6/2022 - Lawful Conditions for Processing Personal Data",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Oman Personal Data Protection Law (Royal Decree No. 6/2022) establishes lawful conditions for personal data processing, requiring one of: explicit consent of the data subject; necessity for a contract with the data subject; compliance with a legal obligation; protection of vital interests; a public interest task; or the legitimate interests of the controller where these do not override the data subject's rights. The Information Technology Authority (ITA) enforces compliance and may impose administrative and criminal penalties. Implementing regulations were issued by Ministerial Decision No. 930/2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "om-pdpl-2022",
      "om-pdpl-2022-data-subject-rights"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "oman-personal-data-protection-law-2022",
    "title": "Oman Personal Data Protection Law 2022 - Ministry of Transport, Communications and Information Technology (MTCIT) Oversight, Data Controller and Processor Obligations, Sensitive Data Categories, Data Subject Rights, Cross-Border Transfer Conditions, 72-Hour Breach Notification and Fines up to OMR 500,000",
    "domain": "Data Protection & Privacy",
    "version": "1.1.1",
    "last_updated": "2026-06-29",
    "bluf": "This regulation establishes comprehensive obligations for data controllers and processors in Oman regarding the lawful processing of personal data, including requirements for consent, data subject rights, sensitive data handling, cross-border data transfers, and mandatory breach reporting within 72 hours of discovery. Key obligations are derived from the core principles and enforcement mechanisms defined in the law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-privacy",
      "uk-money-laundering-regulations-2017-amended"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "omg-cmmn-1-1-case-management-model-and-notation-2016",
    "title": "OMG Case Management Model and Notation (CMMN) Version 1.1 (formal/16-12-01)",
    "domain": "Workflow Automation",
    "version": "1.1.0",
    "last_updated": "2016-12-01",
    "bluf": "Organisations that model knowledge-driven, event-driven, and discretionary work - claims handling, investigations, customer onboarding, complex service requests, and other non-deterministic case work - should use the OMG Case Management Model and Notation 1.1 metamodel and diagram interchange format defined in formal/16-12-01, modelling each case as a Case Plan Model that contains PlanItems (Stages, Tasks, Milestones, EventListeners) and Discretionary Items selected via a PlanningTable, controlling their activation through Sentries with EntryCriterion and ExitCriterion, PlanItemControl rules (ManualActivation, Required, Repetition, AutoComplete), and the Stage and Task instance lifecycles defined in Section 8 of the specification, and exchanging case models between tools via the CMMN Diagram Interchange format.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-19510-bpmn-standard-workflow-processes",
      "omg-dmn-1-4-decision-model-notation"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "omg-cmmn-1-1-case-management-model-notation",
    "title": "OMG CMMN 1.1 - Case Management Model and Notation",
    "domain": "Workflow Automation",
    "version": "1.1 (June 2016)",
    "last_updated": "2026-05-09",
    "bluf": "OMG CMMN 1.1 (Case Management Model and Notation, June 2016) is the Object Management Group formal standard for modelling adaptive, knowledge-intensive case work; it defines Cases, Stages, Discretionary Tasks, Sentries (entry/exit criteria), Milestones, Event Listeners, Case File Items, Planning Tables, and Role-based authorisation - complementing BPMN (structured flow) and DMN (decision logic) in the OMG triple-standard for intelligent process automation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bpmn-2-0-omg-specification-workflow-notation",
      "omg-dmn-1-4-decision-model-notation"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "omg-dmn-1-4-decision-model-notation",
    "title": "OMG DMN 1.4 - Decision Model and Notation for Automated Business Rule Workflows",
    "domain": "Workflow Automation",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "OMG DMN 1.4 (Decision Model and Notation, 2023) defines a standardized graphical and machine-executable notation for expressing business decision logic in automated workflows. Core artefacts are Decision Requirements Diagrams (DRD) connecting Input Data, Decisions, and Business Knowledge Models; Decision Tables with seven hit policies (UNIQUE, ANY, PRIORITY, FIRST, COLLECT with operators, RULE ORDER, OUTPUT ORDER); and FEEL (Friendly Enough Expression Language) for predicate and expression evaluation. DMN bridges business analysts and technical implementors, enabling regulatory decision logic - including AML thresholds, credit scoring, benefits eligibility, tax calculations - to be tested, versioned, and deployed as executable rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_framework",
        "regulatory_mapping",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bpmn-2-0-business-process-model-notation",
      "cobit-2019-governance-workflow-processes"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "opc-ua-iec-62541-industrial-communication",
    "title": "OPC UA IEC 62541 - Unified Architecture for Industrial Communication: Service-Oriented Architecture, Information Model, Security Mechanisms, Transport Protocols and PubSub Extension for IIoT",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This standard defines a platform-independent, service-oriented architecture for secure and scalable industrial communication, integrating all functionality from OPC Classic into OPC Unified Architecture (UA). It applies to vendors, developers, and operators implementing interoperable, secure IIoT systems using OPC UA technologies as specified in the OPC Foundation's UA specifications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-4-2-component-security-2019",
      "iec-62351-power-systems-cybersecurity",
      "isa-99-iec-62443-industrial-security-framework",
      "api-std-1164-scada-pipeline-security"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "opcw-cwc-1993-chemical-weapons-convention",
    "title": "CWC 1993 - Chemical Weapons Convention (OPCW)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Convention on the Prohibition of the Development, Production, Stockpiling and Use of Chemical Weapons and on their Destruction (CWC), opened for signature 13 January 1993 and entering into force 29 April 1997, is one of the most comprehensive and intrusive arms control treaties ever negotiated. With 193 States Parties - near-universal membership; only North Korea, Egypt, and South Sudan are not party - the CWC prohibits an entire category of weapons of mass destruction and establishes the Organisation for the Prohibition of Chemical Weapons (OPCW) in The Hague (Nobel Peace Prize 2013) to verify compliance through the most extensive international inspection regime for a multilateral arms treaty. Key prohibitions under Article I: never develop, produce, stockpile, or otherwise acquire or retain chemical weapons; never use chemical weapons (in any circumstance, including reprisals); never transfer chemical weapons to anyone; never engage in military preparations for use. The CWC's industry verification regime under Article VI is uniquely relevant to commercial chemical manufacturers: it establishes three Schedules of chemicals subject to declarations and inspections: Schedule 1 (highest risk - virtually no legitimate commercial use, e.g., nerve agents - sarin, soman, tabun, VX, novichoks; blister agents - mustard gas, lewisite; ricin; direct weapons-use chemicals; production above 100 g/year requires declaration; permitted for protective/medical/research purposes only up to 1 tonne total per State Party); Schedule 2 (significant precursor use or potential weaponisation risk; e.g., thiodiglycol - mustard precursor; PFIB; BZ; production above 1 kg requires reporting; facilities producing >10 kg/year subject to routine OPCW inspection); Schedule 3 (multiple commercial uses, past production for weapons purposes; e.g., phosgene - industrial chemical but historic weapons use; hydrogen cyanide; chloropicrin; production above 30 tonnes/year triggers declaration). Unscheduled discrete organic chemicals (DOCs) produced above 200 tonnes/year in facilities with Schedule 1/2/3 chemicals are also declarable. States Parties must submit comprehensive declarations of chemical weapons stockpiles, former production facilities, and current Schedule chemical production. The CWC's challenge inspection mechanism (Article IX) enables any State Party to request on-site inspection of any other State Party's site. Investigations of alleged use (Article IX(2)) have been invoked most prominently for documented Syrian government chemical weapons attacks. The OPCW Technical Secretariat maintains a roster of approximately 200 inspectors worldwide conducting routine, challenge, and investigative inspections. Industry compliance relevance: chemical manufacturers, pharma companies, agrochemical producers, and defense contractors producing, processing, or consuming Schedule chemicals must understand CWC declaration obligations, inspection rights, and export control rules that flow from CWC implementation in national law (US Export Administration Regulations, EU dual-use regulation).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-biological-weapons-convention-1972",
      "eu-dual-use-regulation-2021-821",
      "eu-reach-regulation-1907-2006"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "openai-preparedness-framework-2023",
    "title": "OpenAI Preparedness Framework 2023 - Model Capability Evaluation: Cybersecurity, CBRN, Persuasion and Model Autonomy Risk Scoring, Critical (Red)/High/Medium/Low Thresholds, Safety Advisory Group Veto Power, Post-Mitigation Score Requirement Before Deployment",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This framework requires developers of advanced AI models to evaluate and score capabilities in high-risk domains including cybersecurity, chemical-biological-radiological-nuclear (CBRN), persuasion, and model autonomy using defined risk thresholds. Deployment is prohibited if post-mitigation risk scores remain at Critical (Red) level, subject to Safety Advisory Group veto authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "anthropic-responsible-scaling-policy-v2-1-2025",
      "bletchley-declaration-ai-safety-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "openapi-3-1-workflow-api-governance",
    "title": "OpenAPI Specification 3.1 - API Governance for Workflow Automation: Paths, Operations, Parameters, Request Bodies, Responses and Security Schemes for Workflow APIs",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-29",
    "bluf": "This regulation defines the structural and semantic requirements for describing HTTP APIs in a standard, language-agnostic format to enable automated discovery, interaction, and governance of workflow APIs. It applies to all API producers and tooling vendors implementing OpenAPI 3.1.0-compliant interfaces, with mandatory conformance to the paths, components, or webhooks field presence as defined in Section 3.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "azure-logic-apps-enterprise-integration",
      "apache-airflow-workflow-dag-governance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "openapi-specification-3-1-0-rest-api-standard",
    "title": "OpenAPI Specification 3.1.0 - REST API Documentation Standard: Paths, Components, Request/Response Schemas and OAuth/Security Scheme Definitions",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This standard defines a consistent, machine-readable format for describing RESTful APIs, requiring the use of specific schema structures for paths, operations, parameters, request/response bodies, and security schemes. It applies to all organizations designing, publishing, or consuming REST APIs in cloud and SaaS environments, with key requirements in Sections 3 (Document Structure), 4 (Data Types), and 5 (Security Schemes).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mcp-enterprise-auth",
      "automation-bpmn-service-task",
      "automation-bpmn-error-boundary"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "opengitops-v1-0-declarative-workflow-principles",
    "title": "OpenGitOps v1.0 - Declarative Workflow and Infrastructure Automation Principles",
    "domain": "Workflow Automation",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "OpenGitOps v1.0 (CNCF TAG App Delivery, November 2021) defines four immutable principles for GitOps-based workflow automation: (1) Declarative - desired system state is expressed in a declarative format (YAML, JSON, HCL) rather than imperative scripts; (2) Versioned and Immutable - desired state is stored in a version control system (Git) with immutable versioning, providing a complete audit trail; (3) Pulled Automatically - software agents (ArgoCD, FluxCD, Crossplane) pull desired state and continuously apply it without push-based access; (4) Continuously Reconciled - agents detect drift between actual and desired state and correct automatically. GitOps is the primary framework for reproducible, auditable infrastructure workflows required by FedRAMP, SOC 2, PCI DSS, and NIST SP 800-53 CM-family controls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_framework",
        "regulatory_mapping",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bpmn-2-0-business-process-model-notation",
      "cobit-2019-governance-workflow-processes"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "openid-connect-core-1-0-identity-workflow",
    "title": "OpenID Connect Core 1.0 - Identity Layer for Workflow Authentication",
    "domain": "Workflow Automation",
    "version": "1.0 (November 2014, current)",
    "last_updated": "2026-05-09",
    "bluf": "OpenID Connect Core 1.0 (OIDC, November 2014) is the OpenID Foundation's identity layer built on OAuth 2.0 that enables workflow systems to verify end-user identity through ID Tokens (JWTs), obtain basic profile claims via the UserInfo Endpoint, and implement three authentication flows (Authorization Code, Implicit, Hybrid) - forming the foundation for SSO-based workflow authentication, federated identity for microservice APIs, and compliance-grade audit trails linking workflow actions to verified user identities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oasis-xacml-3-0-access-control-policy-language",
      "nist-sp-800-53a-rev5-security-assessment-procedures"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "oracle-process-automation-opa-governance",
    "title": "Oracle Process Automation (OPA) - Governance Framework: Process Designer, Decision Service Integration, Instance Management, Audit Logs and Oracle Integration Controls",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Oracle Process Automation governance mandates strict lifecycle management of process applications, secure integration with Oracle Cloud Infrastructure (OCI), and comprehensive instance auditing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ordered-t-way-combination-testing",
    "title": "Ordered t-way Combinations for Testing State-based Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-06-13",
    "bluf": "This publication introduces a notion of ordered t-way combinations for testing state-based systems where the response depends on both input values and the current system state. In such systems, like network protocols or credit card transaction systems, internal states change as input values are processed, and fault detection often depends on the specific order of inputs that establish states which eventually lead to a failure. Standard combinatorial testing has deficiencies for these systems because it does not account for the order in which inputs occur. This white paper proposes a methodology to ensure that relevant combinations of input values have been tested with adequate diversity of ordering to ensure correct operation.\n\nThe core concept is the 'ordered combination cover' (OCC), which covers all s-orders of t-way combinations of parameter values. The paper proves that a test set achieves this coverage if and only if it includes an ordered series containing a total of 's' covering arrays, each of strength 't'. This result provides a practical method for generating test suites that can detect faults only discoverable when a system is in a particular state, which can only be reached by a specific order of input combinations. This approach can be applied in runtime verification, assertion monitoring, and other methods that rely on checking program properties and states as code is executed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-115-security-testing",
      "nist-sp-800-218-ssdf",
      "security-considerations-system-development-lifecycle",
      "assessing-security-privacy-controls"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ordered-t-way-combinations-testing",
    "title": "Ordered t-way Combinations for Testing State-based Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-06-13",
    "bluf": "Fault detection in state-based systems often depends on the specific order of inputs that establish states which eventually lead to a failure. For systems where the response depends on both input values and the current system state, such as network protocols or credit card systems, it is often difficult to determine if code has been exercised sufficiently. Measures are needed to ensure that relevant combinations of input values have been tested with adequate diversity of ordering to ensure correct operation. Combinatorial testing has deficiencies for verifying state-based systems because internal states change as input values are processed, and the system may subsequently respond differently to the same input.\n\nThis publication introduces a notion of ordered t-way combinations and an ordered combination cover (OCC) to address this gap. An OCC covers all s-orders of t-way combinations of the input parameters. The core finding is a proof that a test set covers s-orders of t-way combinations if and only if it includes an ordered series containing a total of s covering arrays, each of strength t. This result provides a practical and efficient method to produce tests that cover all orders of t-way combinations up to a necessary order length by concatenating t-way covering arrays, making it possible to detect faults that are only discoverable when a system is in a particular state reached by a specific order of input combinations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-115-security-testing",
      "nist-sp-800-218-ssdf",
      "security-considerations-system-development-lifecycle",
      "nist-sp-800-53-r5",
      "assessing-security-privacy-controls",
      "nist-sp-800-160-v1r1"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "orphan-rare-disease-medical-devices-2026",
    "title": "Orphan / Rare Disease Medical Devices - Special Regulatory Pathways & Incentives (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Devices intended for rare diseases or small patient populations benefit from expedited pathways, fee waivers, tax credits, market exclusivity incentives, and flexible clinical evidence requirements. Regulators (FDA Humanitarian Device Exemption, EU Orphan Designation, etc.) balance accelerated access with safety and performance standards, often requiring post-approval data collection and long-term follow-up.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "osha-hazard-communication-standard",
    "title": "HAZARD COMMUNICATION Small Entity Compliance Guide for Employers That Use Hazardous Chemicals",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2014-03-01",
    "bluf": "The Occupational Safety and Health Administration’s (OSHA) Hazard Communication Standard (HCS), 29 CFR 1910.1200, addresses the informational needs of employers and workers with regard to chemicals. In 2012, the HCS was modified to align its provisions with the United Nations’ Globally Harmonized System of Classification and Labelling of Chemicals (GHS). The standard applies to any chemical which is known to be present in the workplace in such a manner that employees may be exposed under normal conditions of use or in a foreseeable emergency, covering all industries where workers are potentially exposed. It incorporates a downstream flow of information, where chemical manufacturers and importers are required to classify the hazards of the chemicals they produce or import, and to prepare appropriate labels and safety data sheets (SDSs).\n\nFor employers who use chemicals, the core obligation is to prepare and implement a written hazard communication program. This program must describe how the employer will address labels, SDSs, and employee training. Key requirements include creating and maintaining a list of all hazardous chemicals in the workplace, ensuring all containers are properly labeled, maintaining an SDS for each hazardous chemical, and making these SDSs readily accessible to employees. Furthermore, employers must inform and train employees on the hazardous chemicals in their work area before their initial assignment and whenever new hazards are introduced. The training must cover the requirements of the standard, the hazards of chemicals, appropriate protective measures, and how to obtain additional information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "osha-work-safety-us",
      "iso-45001-work-safety"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "osha-work-safety-us",
    "title": "OSHA (Work Safety)",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "An evaluation of current occupational safety and health compliance reveals substantial adherence to certain regulatory mandates while also exposing critical deficiencies requiring immediate remediation. The organization maintains a written safety program, has an implemented Hazard Communication plan with accessible Safety Data Sheets, and confirms employee training is documented. An active recordkeeping system is in place, which has captured three recordable incidents within the last 12 months. Additionally, an emergency action plan is established, machine guarding is present, and the requisite whistleblower policy is displayed according to federal standards. However, two significant gaps in compliance exist: a failure to conduct a formal personal protective equipment (PPE) assessment to determine workplace needs, and the absence of periodic General Duty Clause assessments to proactively identify recognized hazards. The last formal workplace inspection was conducted 180 days prior, a time frame which, when combined with the lack of hazard assessments and recorded incidents, presents an elevated risk profile. Prioritizing the implementation of both PPE and general duty assessments is imperative for mitigating liability and ensuring conformity with foundational workplace safety statutes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-work-safety",
      "osha-hazard-communication-standard"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ospar-convention-1992-north-east-atlantic",
    "title": "OSPAR Convention 1992 - Protection of the Marine Environment of the North-East Atlantic, Annexes and Regional Strategies",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Convention for the Protection of the Marine Environment of the North-East Atlantic (OSPAR Convention), signed in Paris on 22 September 1992 and entered into force on 25 March 1998, is the regional treaty governing protection of the marine environment of the North-East Atlantic Ocean. OSPAR superseded the 1972 Oslo Convention on dumping at sea and the 1974 Paris Convention on land-based sources of pollution. The 15 contracting parties are Belgium, Denmark, Finland, France, Germany, Iceland, Ireland, Luxembourg, the Netherlands, Norway, Portugal, Spain, Sweden, Switzerland, and the United Kingdom, plus the European Union. The Convention consists of 32 articles and five Annexes: Annex I prevention and elimination of pollution from land-based sources; Annex II prevention and elimination of pollution by dumping or incineration; Annex III prevention and elimination of pollution from offshore sources; Annex IV assessment of the quality of the marine environment; Annex V protection and conservation of the ecosystems and biological diversity of the maritime area (added 1998). Decisions and Recommendations adopted by the OSPAR Commission can be binding (Decisions) or non-binding (Recommendations). Strategic frameworks include the North-East Atlantic Environment Strategy 2030, with priorities on biodiversity (Marine Protected Areas), eutrophication, hazardous substances and radioactive substances, offshore oil and gas, and human activities. The OSPAR Commission meets annually and is supported by the OSPAR Secretariat in London. Article 27 establishes binding consultation obligations for dispute resolution and arbitration procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-marine-strategy-framework-directive-2008-56-ec"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ot-ics-purdue-model-zone-based-security",
    "title": "OT/ICS Purdue Reference Model - Zone-Based Security Architecture, DMZ Design and Communication Path Controls for Industrial Networks",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Purdue Model for Industrial Control Systems (ICS) security is an architectural framework that mandates a hierarchical, zone-based network segmentation to isolate critical operational technology (OT) from enterprise IT networks. It requires strict communication controls between zones, enforced through a Level 3.5 Industrial Demilitarized Zone (IDMZ), to prevent unauthorized access and contain threats within industrial environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-53-sc7",
      "nis2-security-measures-article-21",
      "cisa-cross-sector-cybersecurity-goals",
      "cis-controls-v8"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ottawa-treaty-1997-anti-personnel-mines",
    "title": "Anti-Personnel Mine Ban Treaty - Ottawa Treaty 1997",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Ottawa Treaty (164 State Parties as of April 2026) comprehensively bans the use, production, transfer, and stockpiling of anti-personnel mines (APMs) under Article 1, with Article 4 requiring destruction of stockpiles within 4 years and Article 5 requiring clearance of mined areas within 10 years (extendable); defence manufacturers, investors, and operators are prohibited from any involvement with APMs under national implementing laws in all State Party jurisdictions, and institutional investors apply universal exclusionary screens - the Mine Action Review documents ongoing use in conflict zones triggering ATT Article 7 risk assessments for arms transfers to affected regions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ccm-2008-cluster-munitions-convention",
      "un-arms-trade-treaty-2013",
      "un-guiding-principles-business-human-rights",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "owasp-agentic-top10",
    "title": "OWASP Top 10 for LLMs & Agents",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Operationalizing the security framework delineated by the Open Web Application Security Project's Top 10 for Large Language Model Applications, this compliance control set establishes stringent policies for mitigating critical vulnerabilities. The configuration mandates a proactive defense against Prompt Injection by enabling rules to block_direct_prompt_injection and filter_indirect_prompt_injection_from_web_sources, neutralizing both direct and embedded threats. To counter Insecure Output Handling, the policy to require_strict_output_parsing_for_downstream_plugins becomes mandatory, ensuring model-generated content is rigorously validated before interacting with subordinate systems or APIs. Furthermore, addressing risks of Excessive Agency and Supply Chain Vulnerabilities, the node enforces a directive to mandate_least_privilege_for_agent_roles. This constrains autonomous systems and their integrated tools to only their narrowest required operational scope. Lastly, safeguarding against Sensitive Information Disclosure, the framework institutes a control to prevent_training_data_extraction_attacks, which protects proprietary or confidential data within a model's training set from adversarial exfiltration. These combined measures constitute a robust security posture for artificial intelligence application development and deployment aligned with leading industry guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mcp-enterprise-auth"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "owasp-api-top-10-2023-api01-broken-object-level-authorization",
    "title": "API1:2023 Broken Object Level Authorization",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-06-13",
    "bluf": "OWASP API Security Top 10 (2023) API1:2023 Broken Object Level Authorization. Object level authorization is an access control mechanism that is usually implemented at the code level to validate that a user can only access the objects that they should have permissions to access. Every API endpoint that receives an ID of an object, and performs any action on the object, should implement object-level authorization checks. The checks should validate that the logged-in user has permissions to perform the requested action on the requested object. Failures in this mechanism typically lead to unauthorized information disclosure, modification, or destruction of all data. Comparing the user ID of the current session (e.g. by extracting it from the JWT token) with the vulnerable ID parameter isn't a sufficient solution to solve Broken Object Level Authorization (BOLA). This approach could address only a small subset of cases. In the case of BOLA, it's by design that the user will have access to the vulnerable API endpoint/function. The violation happens at the object level, by manipulating the ID. If an attacker manages to access an API endpoint/function they should not have access to - this is a case of [Broken Function Level Authorization][5] (BFLA) rather than BOLA. This category sits within the OWASP API Security Top 10 (2023 edition), the canonical industry list of the ten most critical API security risks. Organizations implementing API services should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "owasp-api-top-10-2023-api02-broken-authentication",
    "title": "API2:2023 Broken Authentication",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-06-13",
    "bluf": "OWASP API Security Top 10 (2023) API2:2023 Broken Authentication. Authentication endpoints and flows are assets that need to be protected. Additionally, \"Forgot password / reset password\" should be treated the same way as authentication mechanisms. An API is vulnerable if it: * Permits credential stuffing where the attacker uses brute force with a list of valid usernames and passwords. * Permits attackers to perform a brute force attack on the same user account, without presenting captcha/account lockout mechanism. * Permits weak passwords. * Sends sensitive authentication details, such as auth tokens and passwords in the URL. * Allows users to change their email address, current password, or do any other sensitive operations without asking for password confirmation. * Doesn't validate the authenticity of tokens. * Accepts unsigned/weakly signed JWT tokens (`{\"alg\":\"none\"}`) * Doesn't validate the JWT expiration date. * Uses plain text, non-encrypted, or weakly hashed passwords. * Uses weak encryption keys. On top of that, a microservice is vulnerable if: * Other microservices can access it without authentication * Uses weak or predictable tokens to enforce authentication This category sits within the OWASP API Security Top 10 (2023 edition), the canonical industry list of the ten most critical API security risks. Organizations implementing API services should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "owasp-api-top-10-2023-api03-broken-object-property-level-authorization",
    "title": "API3:2023 Broken Object Property Level Authorization",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-06-13",
    "bluf": "OWASP API Security Top 10 (2023) API3:2023 Broken Object Property Level Authorization. When allowing a user to access an object using an API endpoint, it is important to validate that the user has access to the specific object properties they are trying to access. An API endpoint is vulnerable if: * The API endpoint exposes properties of an object that are considered sensitive and should not be read by the user. (previously named: \"[Excessive Data Exposure][1]\") * The API endpoint allows a user to change, add/or delete the value of a sensitive object's property which the user should not be able to access (previously named: \"[Mass Assignment][2]\") This category sits within the OWASP API Security Top 10 (2023 edition), the canonical industry list of the ten most critical API security risks. Organizations implementing API services should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "owasp-api-top-10-2023-api04-unrestricted-resource-consumption",
    "title": "API4:2023 Unrestricted Resource Consumption",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-06-13",
    "bluf": "OWASP API Security Top 10 (2023) API4:2023 Unrestricted Resource Consumption. Satisfying API requests requires resources such as network bandwidth, CPU, memory, and storage. Sometimes required resources are made available by service providers via API integrations, and paid for per request, such as sending emails/SMS/phone calls, biometrics validation, etc. An API is vulnerable if at least one of the following limits is missing or set inappropriately (e.g. too low/high): * Execution timeouts * Maximum allocable memory * Maximum number of file descriptors * Maximum number of processes * Maximum upload file size * Number of operations to perform in a single API client request (e.g. GraphQL batching) * Number of records per page to return in a single request-response * Third-party service providers' spending limit This category sits within the OWASP API Security Top 10 (2023 edition), the canonical industry list of the ten most critical API security risks. Organizations implementing API services should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "owasp-api-top-10-2023-api05-broken-function-level-authorization",
    "title": "API5:2023 Broken Function Level Authorization",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-06-13",
    "bluf": "OWASP API Security Top 10 (2023) API5:2023 Broken Function Level Authorization. The best way to find broken function level authorization issues is to perform a deep analysis of the authorization mechanism while keeping in mind the user hierarchy, different roles or groups in the application, and asking the following questions: * Can a regular user access administrative endpoints? * Can a user perform sensitive actions (e.g. creation, modification, or deletion ) that they should not have access to by simply changing the HTTP method (e.g. from `GET` to `DELETE`)? * Can a user from group X access a function that should be exposed only to users from group Y, by simply guessing the endpoint URL and parameters (e.g. `/api/v1/users/export_all`)? Don't assume that an API endpoint is regular or administrative only based on the URL path. While developers might choose to expose most of the administrative endpoints under a specific relative path, like `/api/admins`, it's very common to find these administrative endpoints under other relative paths together with regular endpoints, like `/api/users`. This category sits within the OWASP API Security Top 10 (2023 edition), the canonical industry list of the ten most critical API security risks. Organizations implementing API services should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "owasp-api-top-10-2023-api06-unrestricted-access-to-sensitive-business-flows",
    "title": "API6:2023 Unrestricted Access to Sensitive Business Flows",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-06-13",
    "bluf": "OWASP API Security Top 10 (2023) API6:2023 Unrestricted Access to Sensitive Business Flows. When creating an API Endpoint, it is important to understand which business flow it exposes. Some business flows are more sensitive than others, in the sense that excessive access to them may harm the business. Common examples of sensitive business flows and risk of excessive access associated with them: * Purchasing a product flow - an attacker can buy all the stock of a high-demand item at once and resell for a higher price (scalping) * Creating a comment/post flow - an attacker can spam the system * Making a reservation - an attacker can reserve all the available time slots and prevent other users from using the system The risk of excessive access might change between industries and businesses. For example - creation of posts by a script might be considered as a risk of spam by one social network, but encouraged by another social network. An API Endpoint is vulnerable if it exposes a sensitive business flow, without appropriately restricting the access to it. This category sits within the OWASP API Security Top 10 (2023 edition), the canonical industry list of the ten most critical API security risks. Organizations implementing API services should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "owasp-api-top-10-2023-api07-server-side-request-forgery",
    "title": "API7:2023 Server Side Request Forgery",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-06-13",
    "bluf": "OWASP API Security Top 10 (2023) API7:2023 Server Side Request Forgery. Server-Side Request Forgery (SSRF) flaws occur when an API is fetching a remote resource without validating the user-supplied URL. It enables an attacker to coerce the application to send a crafted request to an unexpected destination, even when protected by a firewall or a VPN. Modern concepts in application development make SSRF more common and more dangerous. More common - the following concepts encourage developers to access an external resource based on user input: Webhooks, file fetching from URLs, custom SSO, and URL previews. More dangerous - Modern technologies like cloud providers, Kubernetes, and Docker expose management and control channels over HTTP on predictable, well-known paths. Those channels are an easy target for an SSRF attack. It is also more challenging to limit outbound traffic from your application, because of the connected nature of modern applications. The SSRF risk can not always be completely eliminated. While choosing a protection mechanism, it is important to consider the business risks and needs. This category sits within the OWASP API Security Top 10 (2023 edition), the canonical industry list of the ten most critical API security risks. Organizations implementing API services should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "owasp-api-top-10-2023-api08-security-misconfiguration",
    "title": "API8:2023 Security Misconfiguration",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-06-13",
    "bluf": "OWASP API Security Top 10 (2023) API8:2023 Security Misconfiguration. The API might be vulnerable if: * Appropriate security hardening is missing across any part of the API stack, or if there are improperly configured permissions on cloud services * The latest security patches are missing, or the systems are out of date * Unnecessary features are enabled (e.g. HTTP verbs, logging features) * There are discrepancies in the way incoming requests are processed by servers in the HTTP server chain * Transport Layer Security (TLS) is missing * Security or cache control directives are not sent to clients * A Cross-Origin Resource Sharing (CORS) policy is missing or improperly set * Error messages include stack traces, or expose other sensitive information This category sits within the OWASP API Security Top 10 (2023 edition), the canonical industry list of the ten most critical API security risks. Organizations implementing API services should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "owasp-api-top-10-2023-api09-improper-inventory-management",
    "title": "API9:2023 Improper Inventory Management",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-06-13",
    "bluf": "OWASP API Security Top 10 (2023) API9:2023 Improper Inventory Management. The sprawled and connected nature of APIs and modern applications brings new challenges. It is important for organizations not only to have a good understanding and visibility of their own APIs and API endpoints, but also how the APIs are storing or sharing data with external third parties. Running multiple versions of an API requires additional management resources from the API provider and expands the attack surface. An API has a \"<ins>documentation blindspot</ins>\" if: * The purpose of an API host is unclear, and there are no explicit answers to the following questions * Which environment is the API running in (e.g. production, staging, test, development)? * Who should have network access to the API (e.g. public, internal, partners)? * Which API version is running? * There is no documentation or the existing documentation is not updated. * There is no retirement plan for each API version. * The host's inventory is missing or outdated. The visibility and inventory of sensitive data flows play an important role as part of an incident response plan, in case a breach happens on the third party side. An API has a \"<ins>data flow blindspot</ins>\" if: * There is a \"sensitive data flow\"... This category sits within the OWASP API Security Top 10 (2023 edition), the canonical industry list of the ten most critical API security risks. Organizations implementing API services should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "owasp-api-top-10-2023-api10-unsafe-consumption-of-apis",
    "title": "API10:2023 Unsafe Consumption of APIs",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-06-13",
    "bluf": "OWASP API Security Top 10 (2023) API10:2023 Unsafe Consumption of APIs. Developers tend to trust data received from third-party APIs more than user input. This is especially true for APIs offered by well-known companies. Because of that, developers tend to adopt weaker security standards, for instance, in regards to input validation and sanitization. The API might be vulnerable if: * Interacts with other APIs over an unencrypted channel; * Does not properly validate and sanitize data gathered from other APIs prior to processing it or passing it to downstream components; * Blindly follows redirections; * Does not limit the number of resources available to process third-party services responses; * Does not implement timeouts for interactions with third-party services; This category sits within the OWASP API Security Top 10 (2023 edition), the canonical industry list of the ten most critical API security risks. Organizations implementing API services should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "owasp-asvs-4-workflow-application-security",
    "title": "OWASP ASVS 4.0 - Application Security Verification Standard for Workflow Applications: Authentication, Session Management, Access Control and API Security Requirements",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "OWASP ASVS 4.0 provides a rigorous security standard for testing web-based workflow applications, ensuring strong authentication, session security, API hardening, and protection against injection attacks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "owasp-asvs-l1",
    "title": "OWASP ASVS L1 (App Sec)",
    "domain": "Cloud & SaaS",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The OWASP Application Security Verification Standard (ASVS) Level 1 (Opportunistic) is the baseline requirement for all web applications. it focuses on the vulnerabilities that are the easy to the find and the automated scanning can detect. Level 1 ensures the most common the security flaws are the remediated, providing a 'Defensible' standard for the lower-risk software.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "owasp-asvs-l2",
    "title": "OWASP ASVS L2 (Standard)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Conformance with the OWASP ASVS L2 (Standard) establishes a requisite security posture for applications verified to handle sensitive data. This framework mandates a comprehensive, defense-in-depth strategy, commencing with proactive threat modeling performed as a foundational security activity. Verification controls stipulate that manual code review coverage must achieve a minimum threshold of 90 percent, augmented by annual penetration testing to validate security efficacy. Remediation protocols are stringent, demanding that all critical and high-severity vulnerabilities be resolved within prescribed service-level agreements. Access control measures are robust, enforcing multi-factor authentication for sensitive functions and adhering strictly to the principle of least privilege throughout the system architecture. To mitigate prevalent attack vectors, the standard requires utilization of a centralized input validation framework and confirms business logic flaws are systematically tested. Data protection is paramount, necessitating strong cryptography for all information both in transit and at rest. Moreover, supply chain integrity is addressed through a mandate for 100 percent dependency vulnerability scan coverage. Continuous oversight is maintained via a requirement that all pertinent security events are logged and actively monitored, ensuring a resilient and defensible application environment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack",
        "mitre_capec",
        "mitre_d3fend"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "pci-dss-v4-requirement-6",
      "owasp-asvs-l1"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "owasp-asvs-l3",
    "title": "OWASP ASVS L3 (Advanced)",
    "domain": "Cloud & SaaS",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "OWASP Application Security Verification Standard (ASVS) Level 3 establishes the highest assurance benchmark, designed for applications processing high-value transactions, containing sensitive data, or performing critical functions where failure could precipitate significant operational or financial impact. Adherence to this rigorous standard necessitates a comprehensive, defense-in-depth security posture, verified through multiple independent modalities. Compliance explicitly requires an architectural threat model to preempt design flaws and further mandates both manual penetration testing alongside manual code review for uncovering complex vulnerabilities. The validation process is extensive, obligating business logic abuse testing plus targeted fuzz testing to probe for unexpected weaknesses. A quantitative threshold for automated testing is established, demanding a minimum code coverage by tests of 95 percent. The supply chain integrity is paramount, requiring a secure build pipeline attestation and stipulating that third-party components must not exceed a maximum dependency age of 180 days. Access control standards are stringent, enforcing multi-factor authentication for all users universally and dictating a credential rotation policy of 60 days. Foundational security practices include the mandatory use of a memory-safe language or comparable tooling to eliminate entire classes of vulnerabilities. Ultimately, the framework operates on a zero-tolerance basis for severe risks, setting the max acceptable critical vulns at 0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-218-ssdf",
      "pci-dss-v4-requirement-6"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "owasp-asvs-v4-v1-architecture-design-and-threat-modeling-chapter",
    "title": "OWASP ASVS v4 V1: Architecture, Design and Threat Modeling",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V1: Architecture, Design and Threat Modeling. Control Objective from ASVS v4: Security architecture has almost become a lost art in many organizations. The days of the enterprise architect have passed in the age of DevSecOps. The application security field must catch up and adopt agile security principles while re-introducing leading security architecture principles to software practitioners. Architecture is not an implementation, but a way of thinking about a problem that has potentially many different answers, and no one single \"correct\" answer. All too often, security is seen as inflexible and demanding that developers fix code in a particular way, when the developers may know a much better way to solve the problem. There is no single, simple solution for architecture, and to pretend otherwise is a disservice to the software engineering field. A specific implemen V1 contains 14 sub-sections: V1.1 Secure Software Development Lifecycle; V1.2 Authentication Architecture; V1.3 Session Management Architecture; V1.4 Access Control Architecture; V1.5 Input and Output Architecture; V1.6 Cryptographic Architecture; V1.7 Errors, Logging and Auditing Architecture; V1.8 Data Protection and Privacy Architecture. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V1 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "owasp-asvs-v4-v10-malicious-code-chapter",
    "title": "OWASP ASVS v4 V10: Malicious Code",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V10: Malicious Code. Control Objective from ASVS v4: Ensure that code satisfies the following high level requirements: * Malicious activity is handled securely and properly to not affect the rest of the application. * Does not have time bombs or other time-based attacks. * Does not \"phone home\" to malicious or unauthorized destinations. * Does not have back doors, Easter eggs, salami attacks, rootkits, or unauthorized code that can be controlled by an attacker. Finding malicious code is proof of the negative, which is impossible to completely validate. Best efforts should be undertaken to ensure that the code has no inherent malicious code or unwanted functionality. V10 contains 3 sub-sections: V10.1 Code Integrity; V10.2 Malicious Code Search; V10.3 Application Integrity. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V10 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "owasp-asvs-v4-v11-business-logic-chapter",
    "title": "OWASP ASVS v4 V11: Business Logic",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V11: Business Logic. Control Objective from ASVS v4: Ensure that a verified application satisfies the following high level requirements: * The business logic flow is sequential, processed in order, and cannot be bypassed. * Business logic includes limits to detect and prevent automated attacks, such as continuous small funds transfers, or adding a million friends one at a time, and so on. * High value business logic flows have considered abuse cases and malicious actors, and have protections against spoofing, tampering, information disclosure, and elevation of privilege attacks. V11 contains 1 sub-sections: V11.1 Business Logic Security. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V11 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 3
  },
  {
    "node_id": "owasp-asvs-v4-v12-files-and-resources-chapter",
    "title": "OWASP ASVS v4 V12: Files and Resources",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V12: Files and Resources. Control Objective from ASVS v4: Ensure that a verified application satisfies the following high level requirements: * Untrusted file data should be handled accordingly and in a secure manner. * Untrusted file data obtained from untrusted sources are stored outside the web root and with limited permissions. V12 contains 6 sub-sections: V12.1 File Upload; V12.2 File Integrity; V12.3 File Execution; V12.4 File Storage; V12.5 File Download; V12.6 SSRF Protection. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V12 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "owasp-asvs-v4-v13-api-and-web-service-chapter",
    "title": "OWASP ASVS v4 V13: API and Web Service",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V13: API and Web Service. Control Objective from ASVS v4: Ensure that a verified application that uses trusted service layer APIs (commonly using JSON or XML or GraphQL) has: * Adequate authentication, session management and authorization of all web services. * Input validation of all parameters that transit from a lower to higher trust level. * Effective security controls for all API types, including cloud and Serverless API Please read this chapter in combination with all other chapters at this same level; we no longer duplicate authentication or API session management concerns. V13 contains 4 sub-sections: V13.1 Generic Web Service Security; V13.2 RESTful Web Service; V13.3 SOAP Web Service; V13.4 GraphQL. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V13 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "owasp-asvs-v4-v14-configuration-chapter",
    "title": "OWASP ASVS v4 V14: Configuration",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V14: Configuration. Control Objective from ASVS v4: Ensure that a verified application has: * A secure, repeatable, automatable build environment. * Hardened third party library, dependency and configuration management such that out of date or insecure components are not included by the application. Configuration of the application out of the box should be safe to be on the Internet, which means a safe out of the box configuration. V14 contains 5 sub-sections: V14.1 Build and Deploy; V14.2 Dependency; V14.3 Unintended Security Disclosure; V14.4 HTTP Security Headers; V14.5 HTTP Request Header Validation. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V14 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "owasp-asvs-v4-v2-authentication-chapter",
    "title": "OWASP ASVS v4 V2: Authentication",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V2: Authentication. Control Objective from ASVS v4: Authentication is the act of establishing, or confirming, someone (or something) as authentic and that claims made by a person or about a device are correct, resistant to impersonation, and prevent recovery or interception of passwords. When the ASVS was first released, username + password was the most common form of authentication outside of high security systems. Multi-factor Authentication (MFA) was commonly accepted in security circles but rarely required elsewhere. As the number of password breaches increased, the idea that usernames are somehow confidential and passwords unknown, rendered many security controls untenable. For example, NIST 800-63 considers usernames and Knowledge Based Authentication (KBA) as public information, SMS and email notifications as [\"restricted\" authentica V2 contains 10 sub-sections: V2.1 Password Security; V2.2 General Authenticator Security; V2.3 Authenticator Lifecycle; V2.4 Credential Storage; V2.5 Credential Recovery; V2.6 Look-up Secret Verifier; V2.7 Out of Band Verifier; V2.8 One Time Verifier. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V2 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "owasp-asvs-v4-v3-session-management-chapter",
    "title": "OWASP ASVS v4 V3: Session Management",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V3: Session Management. Control Objective from ASVS v4: One of the core components of any web-based application or stateful API is the mechanism by which it controls and maintains the state for a user or device interacting with it. Session management changes a stateless protocol to stateful, which is critical for differentiating different users or devices. Ensure that a verified application satisfies the following high-level session management requirements: * Sessions are unique to each individual and cannot be guessed or shared. * Sessions are invalidated when no longer required and timed out during periods of inactivity. As previously noted, these requirements have been adapted to be a compliant subset of selected NIST 800-63b controls, focused around common threats and commonly exploited authentication weaknesses. Previous verification requi V3 contains 7 sub-sections: V3.1 Fundamental Session Management Security; V3.2 Session Binding; V3.3 Session Termination; V3.4 Cookie-based Session Management; V3.5 Token-based Session Management; V3.6 Federated Re-authentication; V3.7 Defenses Against Session Management Exploits. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V3 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "owasp-asvs-v4-v4-access-control-chapter",
    "title": "OWASP ASVS v4 V4: Access Control",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V4: Access Control. Control Objective from ASVS v4: Authorization is the concept of allowing access to resources only to those permitted to use them. Ensure that a verified application satisfies the following high level requirements: * Persons accessing resources hold valid credentials to do so. * Users are associated with a well-defined set of roles and privileges. * Role and permission metadata is protected from replay or tampering. V4 contains 3 sub-sections: V4.1 General Access Control Design; V4.2 Operation Level Access Control; V4.3 Other Access Control Considerations. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V4 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "owasp-asvs-v4-v5-validation-sanitization-and-encoding-chapter",
    "title": "OWASP ASVS v4 V5: Validation, Sanitization and Encoding",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V5: Validation, Sanitization and Encoding. Control Objective from ASVS v4: The most common web application security weakness is the failure to properly validate input coming from the client or the environment before directly using it without any output encoding. This weakness leads to almost all of the significant vulnerabilities in web applications, such as Cross-Site Scripting (XSS), SQL injection, interpreter injection, locale/Unicode attacks, file system attacks, and buffer overflows. Ensure that a verified application satisfies the following high-level requirements: * Input validation and output encoding architecture have an agreed pipeline to prevent injection attacks. * Input data is strongly typed, validated, range or length checked, or at worst, sanitized or filtered. * Output data is encoded or escaped as per the context of the data as close to the inte V5 contains 5 sub-sections: V5.1 Input Validation; V5.2 Sanitization and Sandboxing; V5.3 Output Encoding and Injection Prevention; V5.4 Memory, String, and Unmanaged Code; V5.5 Deserialization Prevention. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V5 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "owasp-asvs-v4-v6-stored-cryptography-chapter",
    "title": "OWASP ASVS v4 V6: Stored Cryptography",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V6: Stored Cryptography. Control Objective from ASVS v4: Ensure that a verified application satisfies the following high level requirements: * All cryptographic modules fail in a secure manner and that errors are handled correctly. * A suitable random number generator is used. * Access to keys is securely managed. V6 contains 4 sub-sections: V6.1 Data Classification; V6.2 Algorithms; V6.3 Random Values; V6.4 Secret Management. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V6 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "owasp-asvs-v4-v7-error-handling-and-logging-chapter",
    "title": "OWASP ASVS v4 V7: Error Handling and Logging",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V7: Error Handling and Logging. Control Objective from ASVS v4: The primary objective of error handling and logging is to provide useful information for the user, administrators, and incident response teams. The objective is not to create massive amounts of logs, but high quality logs, with more signal than discarded noise. High quality logs will often contain sensitive data, and must be protected as per local data privacy laws or directives. This should include: * Not collecting or logging sensitive information unless specifically required. * Ensuring all logged information is handled securely and protected as per its data classification. * Ensuring that logs are not stored forever, but have an absolute lifetime that is as short as possible. If logs contain private or sensitive data, the definition of which varies from country to country, the logs bec V7 contains 4 sub-sections: V7.1 Log Content; V7.2 Log Processing; V7.3 Log Protection; V7.4 Error Handling. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V7 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "owasp-asvs-v4-v8-data-protection-chapter",
    "title": "OWASP ASVS v4 V8: Data Protection",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V8: Data Protection. Control Objective from ASVS v4: There are three key elements to sound data protection: Confidentiality, Integrity and Availability (CIA). This standard assumes that data protection is enforced on a trusted system, such as a server, which has been hardened and has sufficient protections. Applications have to assume that all user devices are compromised in some way. Where an application transmits or stores sensitive information on insecure devices, such as shared computers, phones and tablets, the application is responsible for ensuring data stored on these devices is encrypted and cannot be easily illicitly obtained, altered or disclosed. Ensure that a verified application satisfies the following high level data protection requirements: * Confidentiality: Data should be protected from unauthorized observation or disclosur V8 contains 3 sub-sections: V8.1 General Data Protection; V8.2 Client-side Data Protection; V8.3 Sensitive Private Data. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V8 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "owasp-asvs-v4-v9-communication-chapter",
    "title": "OWASP ASVS v4 V9: Communication",
    "domain": "Cybersecurity",
    "version": "4.0.3",
    "last_updated": "2022-10-01",
    "bluf": "OWASP ASVS v4 (Application Security Verification Standard) V9: Communication. Control Objective from ASVS v4: Ensure that a verified application meets the following high level requirements: * Require TLS or strong encryption, independent of sensitivity of the content. * Follow the latest guidance, including: * Configuration advice * Preferred algorithms and ciphers * Avoid weak or soon to be deprecated algorithms and ciphers, except as a last resort * Disable deprecated or known insecure algorithms and ciphers. Within these requirements: * Stay current with recommended industry advice on secure TLS configuration, as it changes frequently (often due to catastrophic breaks in existing algorithms and ciphers). * Use the most recent versions of TLS configuration review tools to configure the preferred order and algorithm selection. * Check your configuration periodically to ensure that secure communic V9 contains 2 sub-sections: V9.1 Client Communication Security; V9.2 Server Communication Security. ASVS v4 defines three verification levels: L1 (opportunistic - low assurance applications), L2 (standard - applications containing sensitive data, default for most apps), and L3 (advanced - applications handling high-value transactions or critical infrastructure). Each control in V9 is mapped to one or more Common Weakness Enumeration (CWE) identifiers and Proactive Controls. Implementation evidence is required for PCI DSS, FedRAMP, ISO/IEC 27001 application security obligations and most enterprise application security programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 3
  },
  {
    "node_id": "owasp-llm-03-training-data-poisoning",
    "title": "OWASP LLM Top 10 LLM03 - Training Data Poisoning - Compliance Obligations for AI Training Data Integrity Controls, Provenance Verification, and Poisoning Attack Mitigation Under EU AI Act Article 10",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines obligations for AI training data integrity, provenance verification, and mitigation of poisoning attacks as per OWASP LLM Top 10 (LLM03), reinforced by EU AI Act Article 10 requirements for high-risk AI systems. It provides actionable controls and workflows to ensure compliance with data governance mandates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "owasp-llm-04-model-denial-of-service",
    "title": "OWASP LLM Top 10 LLM04 - Model Denial of Service - Compliance Obligations for AI System Availability Controls, Resource Exhaustion Prevention, and LLM Operational Resilience Under DORA and EU AI Act",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines obligations for preventing Model Denial of Service (DoS) attacks on LLMs as per OWASP LLM Top 10 (LLM04), focusing on availability controls and resource exhaustion prevention, with overlapping requirements under the EU AI Act (Regulation (EU) 2024/1689, Article 15) and DORA for operational resilience.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "owasp-llm-05-supply-chain-vulnerabilities",
    "title": "OWASP LLM Top 10 LLM05 - Supply Chain Vulnerabilities in LLM Applications - Compliance Obligations for AI Supply Chain Risk Management, Third-Party Model and Plugin Governance, and LLM Dependency Security Controls",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines obligations for managing supply chain vulnerabilities in LLM applications as per OWASP LLM Top 10 (LLM05), focusing on third-party model governance, plugin security, and dependency controls, with overlapping requirements under the EU AI Act (Regulation 2024/1689, Articles 6 and 28). It provides actionable controls for risk assessment and mitigation aligned with global AI governance standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "owasp-llm-06-sensitive-information-disclosure",
    "title": "OWASP LLM Top 10 LLM06 - Sensitive Information Disclosure via LLM Outputs - Compliance Obligations for AI Output Data Leakage Prevention, Training Data Exposure Controls, and GDPR Data Minimisation in LLM Applications",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines obligations for preventing sensitive information disclosure in LLM outputs under OWASP LLM Top 10 (LLM06), focusing on data leakage prevention, training data exposure controls, and GDPR data minimization principles. It aligns with EU AI Act (Regulation 2024/1689) Articles 28 and 50 for high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "gdpr-article-5-data-principles",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "owasp-llm-07-insecure-plugin-design",
    "title": "OWASP LLM Top 10 LLM07 - Insecure Plugin and Tool Design in LLM Applications - Compliance Obligations for LLM Plugin Security Controls, Tool Permission Governance, and AI Extension Trust Boundary Enforcement",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations for securing plugins and tools in LLM applications as per OWASP LLM Top 10 (LLM07), focusing on plugin security controls, permission governance, and trust boundary enforcement, with overlapping requirements under the EU AI Act (Regulation (EU) 2024/1689, Articles 15 and 28).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "owasp-llm-08-excessive-agency",
    "title": "OWASP LLM Top 10 LLM08 - Excessive Agency in LLM and Agentic AI Systems - Compliance Obligations for Agentic AI Scope Limitation, Human Oversight Requirements, and Autonomous Action Control Under EU AI Act Article 14",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations for mitigating excessive agency in LLM and agentic AI systems as per OWASP LLM Top 10 (LLM08), focusing on scope limitation, human oversight, and autonomous action control, reinforced by EU AI Act Article 14 requirements for human oversight in high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "owasp-llm-09-overreliance",
    "title": "OWASP LLM Top 10 LLM09 - Overreliance on LLM Outputs Without Human Oversight - Compliance Obligations for AI-Assisted Decision Governance, Human Review Requirements, and LLM Output Verification Controls",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node addresses obligations to prevent overreliance on Large Language Model (LLM) outputs by enforcing human oversight, as outlined in OWASP LLM Top 10 (LLM09), and aligns with EU AI Act (Regulation 2024/1689) requirements for high-risk AI systems under Articles 14 and 15. It specifies controls for human review and output verification to ensure accountability and mitigate risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "owasp-llm-1",
    "title": "Prompt Injection Prevention (OWASP LLM01)",
    "domain": "Cybersecurity",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Prompt Injection (LLM01) occurs when an attacker manipulates an LLM via crafted inputs to override system instructions. Prevention requires strict input sanitization, separation of data from instructions, and least-privilege tool access.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-ai-adversarial-machine-learning",
      "cis-ai-least-privilege",
      "etsi-en-304-223-sai",
      "owasp-agentic-top10"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "owasp-llm-2",
    "title": "Insecure Output Handling (OWASP LLM02)",
    "domain": "Cybersecurity",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Insecure Output Handling (LLM02) occurs when an application trustingly processes LLM-generated output without validation, potentially leading to XSS, CSRF, or SSRF in downstream systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "owasp-asvs-l3",
      "nist-sp-800-53-r5",
      "iso-27001-2022",
      "cis-controls-v8"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "owasp-llm-top-10-2025",
    "title": "OWASP Top 10 for Large Language Model Applications - De Facto Industry-Standard LLM Security Vulnerability Taxonomy (Project under the OWASP GenAI Security Project; Version 2025 Current; Version 1.1 Verified Below)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-29",
    "bluf": "The OWASP Top 10 for Large Language Model Applications is the de facto industry-standard taxonomy of the most critical security vulnerabilities in LLM applications, maintained by the OWASP Foundation and now operated within the broader OWASP GenAI Security Project - a global open-source initiative dedicated to identifying, mitigating, and documenting security and safety risks associated with generative AI technologies including large language models, agentic AI systems, and AI-driven applications. The project was founded in 2023 by a small group of security professionals addressing an urgent security gap, and has grown into a global community with over 600 contributing experts from more than 18 countries and nearly 8,000 active community members. Project leadership: Steve Wilson (Lead), with co-leads Ads Dawson, John Sotiropoulos, Scott Clinton, and Sandy Dunn. The current version is Version 2025 (Lab Status Project) with prior versions 1.1.0, 1.0.1, 1.0.0, 0.9.0, 0.5.0, and 0.1.0 archived. Version 1.1 (verifiable on the OWASP project page) catalogues the following ten vulnerability types: LLM01 Prompt Injection (manipulating LLMs via crafted inputs leading to unauthorized access, data breaches, and compromised decision-making); LLM02 Insecure Output Handling (failure to validate LLM outputs, leading to downstream security exploits including code execution); LLM03 Training Data Poisoning (tampered training data impairing model integrity, accuracy, or ethical behavior); LLM04 Model Denial of Service (overloading LLMs with resource-heavy operations causing service disruptions and increased costs); LLM05 Supply Chain Vulnerabilities (compromised components, services, or datasets undermining system integrity); LLM06 Sensitive Information Disclosure (failure to protect against disclosure of sensitive information in LLM outputs); LLM07 Insecure Plugin Design (LLM plugins processing untrusted inputs without sufficient access control); LLM08 Excessive Agency (granting LLMs unchecked autonomy with unintended consequences); LLM09 Overreliance (failing to critically assess LLM outputs); and LLM10 Model Theft (unauthorized access to proprietary models). The Top 10 is cited as an Informative Reference in NIST SP 800-218A and is an industry-de-facto LLM security standard referenced in EU AI Act Annex IV technical documentation submissions and in frontier-lab responsible-scaling policies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us-nist-sp-800-218a-secure-ai-development",
        "mitre-atlas-ai-threat-matrix-2024",
        "us-nist-adversarial-ml-taxonomy",
        "eu-ai-act-2024",
        "owasp-asvs-application-security-verification-standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nist-sp-800-218a-secure-ai-development"
    ],
    "primary_citations_count": 15
  },
  {
    "node_id": "owasp-llm-top-10-2025-llm07-system-prompt-leakage",
    "title": "OWASP LLM Top 10 (2025) - LLM07:2025 System Prompt Leakage",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2024-11-17",
    "bluf": "OWASP LLM Top 10 (2025) LLM07:2025 System Prompt Leakage. The system prompt leakage vulnerability in LLMs refers to the risk that the system prompts or instructions used to steer the behavior of the model can also contain sensitive information that was not intended to be discovered. System prompts are designed to guide the model's output based on the requirements of the application, but may inadvertently contain secrets. When discovered, this information can be used to facilitate other attacks. It's important to understand that the system prompt should not be considered a secret, nor should it be used as a security control. Accordingly, sensitive data such as credentials, connection strings, etc. should not be contained within the system prompt language. Similarly, if a system prompt contains information describing different roles and permissions, or sensitive data like connection strings or passwords, while the disclosure of such information may be helpful, the fundamental security risk is not that these have been disclosed, it is that the application allows bypassing strong session management and authorization checks by delegating these to the LLM, and that sensitive data is being stored in a place that it should not be. In short: discl... This risk is part of the 2025 edition of the OWASP Top 10 for Large Language Model Applications, the canonical industry list of the ten most critical risks unique to LLM-based systems. Organizations deploying LLMs in production should treat each risk as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, red-team evaluation, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-llm-top-10-2025",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "owasp-llm-top-10-2025-llm08-vector-and-embedding-weaknesses",
    "title": "OWASP LLM Top 10 (2025) - LLM08:2025 Vector and Embedding Weaknesses",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2024-11-17",
    "bluf": "OWASP LLM Top 10 (2025) LLM08:2025 Vector and Embedding Weaknesses. Vectors and embeddings vulnerabilities present significant security risks in systems utilizing Retrieval Augmented Generation (RAG) with Large Language Models (LLMs). Weaknesses in how vectors and embeddings are generated, stored, or retrieved can be exploited by malicious actions (intentional or unintentional) to inject harmful content, manipulate model outputs, or access sensitive information. Retrieval Augmented Generation (RAG) is a model adaptation technique that enhances the performance and contextual relevance of responses from LLM Applications, by combining pre-trained language models with external knowledge sources. Retrieval Augmentation uses vector mechanisms and embedding. (Ref #1) This risk is part of the 2025 edition of the OWASP Top 10 for Large Language Model Applications, the canonical industry list of the ten most critical risks unique to LLM-based systems. Organizations deploying LLMs in production should treat each risk as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, red-team evaluation, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-llm-top-10-2025",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "owasp-llm-top-10-2025-llm09-misinformation",
    "title": "OWASP LLM Top 10 (2025) - LLM09:2025 Misinformation",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2024-11-17",
    "bluf": "OWASP LLM Top 10 (2025) LLM09:2025 Misinformation. Misinformation from LLMs poses a core vulnerability for applications relying on these models. Misinformation occurs when LLMs produce false or misleading information that appears credible. This vulnerability can lead to security breaches, reputational damage, and legal liability. One of the major causes of misinformation is hallucination—when the LLM generates content that seems accurate but is fabricated. Hallucinations occur when LLMs fill gaps in their training data using statistical patterns, without truly understanding the content. As a result, the model may produce answers that sound correct but are completely unfounded. While hallucinations are a major source of misinformation, they are not the only cause; biases introduced by the training data and incomplete information can also contribute. A related issue is overreliance. Overreliance occurs when users place excessive trust in LLM-generated content, failing to verify its accuracy. This overreliance exacerbates the impact of misinformation, as users may integrate incorrect data into critical decisions or processes without adequate scrutiny. This risk is part of the 2025 edition of the OWASP Top 10 for Large Language Model Applications, the canonical industry list of the ten most critical risks unique to LLM-based systems. Organizations deploying LLMs in production should treat each risk as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, red-team evaluation, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-llm-top-10-2025",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "owasp-llm-top-10-2025-llm10-unbounded-consumption",
    "title": "OWASP LLM Top 10 (2025) - LLM10:2025 Unbounded Consumption",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2024-11-17",
    "bluf": "OWASP LLM Top 10 (2025) LLM10:2025 Unbounded Consumption. Unbounded Consumption refers to the process where a Large Language Model (LLM) generates outputs based on input queries or prompts. Inference is a critical function of LLMs, involving the application of learned patterns and knowledge to produce relevant responses or predictions. Attacks designed to disrupt service, deplete the target's financial resources, or even steal intellectual property by cloning a model’s behavior all depend on a common class of security vulnerability in order to succeed. Unbounded Consumption occurs when a Large Language Model (LLM) application allows users to conduct excessive and uncontrolled inferences, leading to risks such as denial of service (DoS), economic losses, model theft, and service degradation. The high computational demands of LLMs, especially in cloud environments, make them vulnerable to resource exploitation and unauthorized usage. This risk is part of the 2025 edition of the OWASP Top 10 for Large Language Model Applications, the canonical industry list of the ten most critical risks unique to LLM-based systems. Organizations deploying LLMs in production should treat each risk as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, red-team evaluation, and incident response procedures defined per category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-llm-top-10-2025",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "owasp-masvs-auth-authentication-and-authorization-category",
    "title": "OWASP MASVS v2 - MASVS-AUTH Authentication and Authorization Category",
    "domain": "Cybersecurity",
    "version": "2.1.0",
    "last_updated": "2024-04-04",
    "bluf": "OWASP MASVS v2 (Mobile Application Security Verification Standard) - MASVS-AUTH Authentication and Authorization. Authentication and authorization are essential components of most mobile apps, especially those that connect to a remote service. These mechanisms provide an added layer of security and help prevent unauthorized access to sensitive user data. Although the enforcement of these mechanisms must be on the remote endpoint, it is equally important for the app to follow relevant best practices to ensure the secure use of the involved protocols. Mobile apps often use different forms of authentication, such as biometrics, PIN, or multi-factor authentication code generators, to validate user identity. These mechanisms must be implemented correctly to ensure their effectiveness in preventing unauthorized access. Additionally, some apps may rely solely on local app authentication and may not have a remote endpoint. In such cases, it is critical to ensure that local authentication mechanisms are secure and implemented following industry best practices. The controls in this category aim to ensure that the app implements authentication and authorization mechanisms securely, protecting sensitive user information and preventing unauthorized access. It is important to note that the security of the r... MASVS v2 organizes mobile app security obligations into eight top-level categories (STORAGE, CRYPTO, AUTH, NETWORK, PLATFORM, CODE, RESILIENCE, PRIVACY) with specific per-control requirements that mobile engineering teams can verify against during a security review. This category contains the following controls: MASVS-AUTH-1, MASVS-AUTH-2, MASVS-AUTH-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "owasp-masvs-code-code-quality-and-build-setting-category",
    "title": "OWASP MASVS v2 - MASVS-CODE Code Quality and Build Setting Category",
    "domain": "Cybersecurity",
    "version": "2.1.0",
    "last_updated": "2024-04-04",
    "bluf": "OWASP MASVS v2 (Mobile Application Security Verification Standard) - MASVS-CODE Code Quality and Build Setting. Mobile apps have many data entry points, including the UI, IPC, network, and file system, which might receive data that has been inadvertently modified by untrusted actors. By treating this data as untrusted input and properly verifying and sanitizing it before use, developers can prevent classical injection attacks, such as SQL injection, XSS, or insecure deserialization. However, other common coding vulnerabilities, such as memory corruption flaws, are hard to detect in penetration testing but easy to prevent with secure architecture and coding practices. Developers should follow best practices such as the OWASP Software Assurance Maturity Model (SAMM) and NIST.SP.800-218 Secure Software Development Framework (SSDF) to avoid introducing these flaws in the first place. This category covers coding vulnerabilities that arise from external sources such as app data entry points, the OS, and third-party software components. Developers should verify and sanitize all incoming data to prevent injection attacks and bypass of security checks. They should also enforce app updates and ... MASVS v2 organizes mobile app security obligations into eight top-level categories (STORAGE, CRYPTO, AUTH, NETWORK, PLATFORM, CODE, RESILIENCE, PRIVACY) with specific per-control requirements that mobile engineering teams can verify against during a security review. This category contains the following controls: MASVS-CODE-1, MASVS-CODE-2, MASVS-CODE-3, MASVS-CODE-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "owasp-masvs-crypto-cryptography-category",
    "title": "OWASP MASVS v2 - MASVS-CRYPTO Cryptography Category",
    "domain": "Cybersecurity",
    "version": "2.1.0",
    "last_updated": "2024-04-04",
    "bluf": "OWASP MASVS v2 (Mobile Application Security Verification Standard) - MASVS-CRYPTO Cryptography. Cryptography is essential for mobile apps because mobile devices are highly portable and can be easily lost or stolen. This means that an attacker who gains physical access to a device can potentially access all the sensitive data stored on it, including passwords, financial information, and personally identifiable information. Cryptography provides a means of protecting this sensitive data by encrypting it so that it cannot be easily read or accessed by an unauthorized user. The purpose of the controls in this category is to ensure that the verified app uses cryptography according to industry best practices, which are typically defined in external standards such as [NIST.SP.800-175B](https://csrc.nist.gov/publications/detail/sp/800-175b/rev-1/final) and [NIST.SP.800-57](https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final). This category also focuses on the management of cryptographic keys throughout their lifecycle, including key generation, storage, and protection. Poor key management can compromise even the strongest cryptography, so it is crucial for developers to follow the recommended best practices to ensure the security of their users' sensitive data. MASVS v2 organizes mobile app security obligations into eight top-level categories (STORAGE, CRYPTO, AUTH, NETWORK, PLATFORM, CODE, RESILIENCE, PRIVACY) with specific per-control requirements that mobile engineering teams can verify against during a security review. This category contains the following controls: MASVS-CRYPTO-1, MASVS-CRYPTO-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-masvs-network-network-communication-category",
    "title": "OWASP MASVS v2 - MASVS-NETWORK Network Communication Category",
    "domain": "Cybersecurity",
    "version": "2.1.0",
    "last_updated": "2024-04-04",
    "bluf": "OWASP MASVS v2 (Mobile Application Security Verification Standard) - MASVS-NETWORK Network Communication. Secure networking is a critical aspect of mobile app security, particularly for apps that communicate over the network. In order to ensure the confidentiality and integrity of data in transit, developers typically rely on encryption and authentication of the remote endpoint, such as through the use of TLS. However, there are numerous ways in which a developer may accidentally disable the platform secure defaults or bypass them entirely by utilizing low-level APIs or third-party libraries. This category is designed to ensure that the mobile app sets up secure connections under any circumstances. Specifically, it focuses on verifying that the app establishes a secure, encrypted channel for network communication. Additionally, this category covers situations where a developer may choose to trust only specific Certificate Authorities (CAs), which is commonly referred to as certificate pinning or public key pinning. MASVS v2 organizes mobile app security obligations into eight top-level categories (STORAGE, CRYPTO, AUTH, NETWORK, PLATFORM, CODE, RESILIENCE, PRIVACY) with specific per-control requirements that mobile engineering teams can verify against during a security review. This category contains the following controls: MASVS-NETWORK-1, MASVS-NETWORK-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-masvs-platform-platform-interaction-category",
    "title": "OWASP MASVS v2 - MASVS-PLATFORM Platform Interaction Category",
    "domain": "Cybersecurity",
    "version": "2.1.0",
    "last_updated": "2024-04-04",
    "bluf": "OWASP MASVS v2 (Mobile Application Security Verification Standard) - MASVS-PLATFORM Platform Interaction. The security of mobile apps heavily depends on their interaction with the mobile platform, which often involves exposing data or functionality intentionally through the use of platform-provided inter-process communication (IPC) mechanisms and WebViews to enhance the user experience. However, these mechanisms can also be exploited by attackers or other installed apps, potentially compromising the app's security. Furthermore, sensitive data, such as passwords, credit card details, and one-time passwords in notifications, is often displayed in the app's user interface. It is essential to ensure that this data is not unintentionally leaked through platform mechanisms such as auto-generated screenshots or accidental disclosure through shoulder surfing or device sharing. This category comprises controls that ensure the app's interactions with the mobile platform occur securely. These controls cover the secure use of platform-provided IPC mechanisms, WebView configurations to prevent sensitive data leakage and functionality exposure, and secure display of sensitive data in the app's user interface. By implementing these controls, mobile app developers can safeguard sensitive user informat... MASVS v2 organizes mobile app security obligations into eight top-level categories (STORAGE, CRYPTO, AUTH, NETWORK, PLATFORM, CODE, RESILIENCE, PRIVACY) with specific per-control requirements that mobile engineering teams can verify against during a security review. This category contains the following controls: MASVS-PLATFORM-1, MASVS-PLATFORM-2, MASVS-PLATFORM-3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "owasp-masvs-privacy-privacy-category",
    "title": "OWASP MASVS v2 - MASVS-PRIVACY Privacy Category",
    "domain": "Cybersecurity",
    "version": "2.1.0",
    "last_updated": "2024-04-04",
    "bluf": "OWASP MASVS v2 (Mobile Application Security Verification Standard) - MASVS-PRIVACY category. The main goal of MASVS-PRIVACY is to provide a **baseline for user privacy**. It is not intended to cover all aspects of user privacy, especially when other standards and regulations such as ENISA or the GDPR already do that. We focus on the app itself, looking at what can be tested using information that's publicly available or found within the app through methods like static or dynamic analysis. While some associated tests can be automated, others necessitate manual intervention due to the nuanced nature of privacy. For example, if an app collects data that it didn't mention in the app store or its privacy policy, it takes careful manual checking to spot this. > **Note on \"Data Collection and Sharing\"**:For the MASTG tests, we treat \"Collect\" and \"Share\" in a unified manner. This means t MASVS v2 organizes mobile app security obligations into eight top-level categories (STORAGE, CRYPTO, AUTH, NETWORK, PLATFORM, CODE, RESILIENCE, PRIVACY) with specific per-control requirements that mobile engineering teams can verify against during a security review. This category contains the following controls: MASVS-PRIVACY-1, MASVS-PRIVACY-2, MASVS-PRIVACY-3, MASVS-PRIVACY-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "owasp-masvs-resilience-resilience-against-reverse-engineering-and-tampering-category",
    "title": "OWASP MASVS v2 - MASVS-RESILIENCE Resilience Against Reverse Engineering and Tampering Category",
    "domain": "Cybersecurity",
    "version": "2.1.0",
    "last_updated": "2024-04-04",
    "bluf": "OWASP MASVS v2 (Mobile Application Security Verification Standard) - MASVS-RESILIENCE category. Defense-in-depth measures such as code obfuscation, anti-debugging, anti-tampering, and runtime application self-protection (RASP) can increase an app's resilience against reverse engineering and specific client-side attacks. They add multiple layers of security controls to the app, making it more difficult for attackers to modify code or extract sensitive information. MASVS v2 organizes mobile app security obligations into eight top-level categories (STORAGE, CRYPTO, AUTH, NETWORK, PLATFORM, CODE, RESILIENCE, PRIVACY) with specific per-control requirements that mobile engineering teams can verify against during a security review. This category contains the following controls: MASVS-RESILIENCE-1, MASVS-RESILIENCE-2, MASVS-RESILIENCE-3, MASVS-RESILIENCE-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "owasp-masvs-storage-storage-category",
    "title": "OWASP MASVS v2 - MASVS-STORAGE Storage Category",
    "domain": "Cybersecurity",
    "version": "2.1.0",
    "last_updated": "2024-04-04",
    "bluf": "OWASP MASVS v2 (Mobile Application Security Verification Standard) - MASVS-STORAGE Storage. Mobile applications handle a wide variety of sensitive data, such as personally identifiable information (PII), cryptographic material, secrets, and API keys, that often need to be stored locally. This sensitive data may be stored in private locations, such as the app's internal storage, or in public folders that are accessible by the user or other apps installed on the device. However, sensitive data can also be unintentionally stored or exposed to publicly accessible locations, typically as a side-effect of using certain APIs or system capabilities such as backups or logs. This category is designed to help developers ensure that any sensitive data intentionally stored by the app is properly protected, regardless of the target location. It also covers unintentional leaks that can occur due to improper use of APIs or system capabilities. MASVS v2 organizes mobile app security obligations into eight top-level categories (STORAGE, CRYPTO, AUTH, NETWORK, PLATFORM, CODE, RESILIENCE, PRIVACY) with specific per-control requirements that mobile engineering teams can verify against during a security review. This category contains the following controls: MASVS-STORAGE-1, MASVS-STORAGE-2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-proactive-controls-2024-c1-implement-access-control",
    "title": "C1: Implement Access Control",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10 Proactive Controls 2024, C1: Implement Access Control. Access Control (or Authorization) is allowing or denying specific requests from a user, program, or process. This is one of the OWASP Top 10 Proactive Controls (2024 edition), the OWASP Foundation's list of the ten most important security techniques that every software architect and developer should build into every project. Where the OWASP Top 10 enumerates the most critical web application security risks, the Proactive Controls enumerate the defensive techniques that prevent them. Organizations should treat this control as a design requirement, an implementation checklist, and a continuous-verification obligation, supported by a security policy, automated testing in the CI/CD pipeline, developer training, and incident response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-proactive-controls-2024-c10-stop-server-side-request-forgery",
    "title": "C10: Stop Server Side Request Forgery",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10 Proactive Controls 2024, C10: Stop Server Side Request Forgery. While Injection Attacks typically target the victim server itself, Server-Side Request Forgery (SSRF) attacks try to coerce the server to perform a request on behalf of the attacker. This is one of the OWASP Top 10 Proactive Controls (2024 edition), the OWASP Foundation's list of the ten most important security techniques that every software architect and developer should build into every project. Where the OWASP Top 10 enumerates the most critical web application security risks, the Proactive Controls enumerate the defensive techniques that prevent them. Organizations should treat this control as a design requirement, an implementation checklist, and a continuous-verification obligation, supported by a security policy, automated testing in the CI/CD pipeline, developer training, and incident response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "owasp-proactive-controls-2024-c2-use-cryptography-to-protect-data",
    "title": "C2: Use Cryptography to Protect Data",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10 Proactive Controls 2024, C2: Use Cryptography to Protect Data. Sensitive data such as passwords, credit card numbers, health records, personal information and business secrets require extra protection, particularly if that data falls under privacy laws (EU's General Data Protection Regulation GDPR), financial data protection rules such as PCI Data Security Standard (PCI DSS) or other regulations. This is one of the OWASP Top 10 Proactive Controls (2024 edition), the OWASP Foundation's list of the ten most important security techniques that every software architect and developer should build into every project. Where the OWASP Top 10 enumerates the most critical web application security risks, the Proactive Controls enumerate the defensive techniques that prevent them. Organizations should treat this control as a design requirement, an implementation checklist, and a continuous-verification obligation, supported by a security policy, automated testing in the CI/CD pipeline, developer training, and incident response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-proactive-controls-2024-c3-validate-all-input-and-handle-exceptions",
    "title": "C3: Validate all Input & Handle Exceptions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10 Proactive Controls 2024, C3: Validate all Input & Handle Exceptions. Input validation is a programming technique that ensures only properly formatted data may enter a software system component. This is one of the OWASP Top 10 Proactive Controls (2024 edition), the OWASP Foundation's list of the ten most important security techniques that every software architect and developer should build into every project. Where the OWASP Top 10 enumerates the most critical web application security risks, the Proactive Controls enumerate the defensive techniques that prevent them. Organizations should treat this control as a design requirement, an implementation checklist, and a continuous-verification obligation, supported by a security policy, automated testing in the CI/CD pipeline, developer training, and incident response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-proactive-controls-2024-c4-address-security-from-the-start",
    "title": "C4: Address Security from the Start",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10 Proactive Controls 2024, C4: Address Security from the Start. When designing a new application, creating a secure architecture prevents vulnerabilities before they even become part of the application. This is one of the OWASP Top 10 Proactive Controls (2024 edition), the OWASP Foundation's list of the ten most important security techniques that every software architect and developer should build into every project. Where the OWASP Top 10 enumerates the most critical web application security risks, the Proactive Controls enumerate the defensive techniques that prevent them. Organizations should treat this control as a design requirement, an implementation checklist, and a continuous-verification obligation, supported by a security policy, automated testing in the CI/CD pipeline, developer training, and incident response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-proactive-controls-2024-c5-secure-by-default-configurations",
    "title": "C5: Secure By Default Configurations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10 Proactive Controls 2024, C5: Secure By Default Configurations. Secure-by-Default means products are resilient against prevalent exploitation techniques out of the box without additional charge. This is one of the OWASP Top 10 Proactive Controls (2024 edition), the OWASP Foundation's list of the ten most important security techniques that every software architect and developer should build into every project. Where the OWASP Top 10 enumerates the most critical web application security risks, the Proactive Controls enumerate the defensive techniques that prevent them. Organizations should treat this control as a design requirement, an implementation checklist, and a continuous-verification obligation, supported by a security policy, automated testing in the CI/CD pipeline, developer training, and incident response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-proactive-controls-2024-c6-keep-your-components-secure",
    "title": "C6: Keep your Components Secure",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10 Proactive Controls 2024, C6: Keep your Components Secure. It is a common practice in software development to leverage libraries and frameworks. Secure libraries and software frameworks with embedded security help software developers prevent security-related design and implementation flaws. This is one of the OWASP Top 10 Proactive Controls (2024 edition), the OWASP Foundation's list of the ten most important security techniques that every software architect and developer should build into every project. Where the OWASP Top 10 enumerates the most critical web application security risks, the Proactive Controls enumerate the defensive techniques that prevent them. Organizations should treat this control as a design requirement, an implementation checklist, and a continuous-verification obligation, supported by a security policy, automated testing in the CI/CD pipeline, developer training, and incident response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-proactive-controls-2024-c7-secure-digital-identities",
    "title": "C7: Secure Digital Identities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10 Proactive Controls 2024, C7: Secure Digital Identities. Digital Identity is a unique representation of an individual, organization (or another subject) as they engage in an online transaction. Authentication is the process of verifying that an individual or entity is who they claim to be. This is one of the OWASP Top 10 Proactive Controls (2024 edition), the OWASP Foundation's list of the ten most important security techniques that every software architect and developer should build into every project. Where the OWASP Top 10 enumerates the most critical web application security risks, the Proactive Controls enumerate the defensive techniques that prevent them. Organizations should treat this control as a design requirement, an implementation checklist, and a continuous-verification obligation, supported by a security policy, automated testing in the CI/CD pipeline, developer training, and incident response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-proactive-controls-2024-c8-leverage-browser-security-features",
    "title": "C8: Leverage Browser Security Features",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10 Proactive Controls 2024, C8: Leverage Browser Security Features. Browsers are the gateway to the web for most users. As such, it's critical to employ robust security measures to protect the user from various threats. This is one of the OWASP Top 10 Proactive Controls (2024 edition), the OWASP Foundation's list of the ten most important security techniques that every software architect and developer should build into every project. Where the OWASP Top 10 enumerates the most critical web application security risks, the Proactive Controls enumerate the defensive techniques that prevent them. Organizations should treat this control as a design requirement, an implementation checklist, and a continuous-verification obligation, supported by a security policy, automated testing in the CI/CD pipeline, developer training, and incident response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-proactive-controls-2024-c9-implement-security-logging-and-monitoring",
    "title": "C9: Implement Security Logging and Monitoring",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10 Proactive Controls 2024, C9: Implement Security Logging and Monitoring. Logging is a concept that most developers already use for debugging and diagnostic purposes. Security logging is an equally basic concept: to log security information during the runtime operation of an application. This is one of the OWASP Top 10 Proactive Controls (2024 edition), the OWASP Foundation's list of the ten most important security techniques that every software architect and developer should build into every project. Where the OWASP Top 10 enumerates the most critical web application security risks, the Proactive Controls enumerate the defensive techniques that prevent them. Organizations should treat this control as a design requirement, an implementation checklist, and a continuous-verification obligation, supported by a security policy, automated testing in the CI/CD pipeline, developer training, and incident response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "owasp-samm-governance",
    "title": "OWASP SAMM (Governance)",
    "domain": "Cloud & SaaS",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The OWASP Software Assurance Maturity Model (SAMM) v2.0 is the premier framework for the analyzing and the improving the software security posture. it provides a measurable way for the organizations to the design, develop, and the deploy the highly secure software by partitioning the process into the 'Five Business Functions' (Governance, Design, Implementation, Verification, Operations).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "owasp-samm-v2-1-software-assurance-maturity-model",
    "title": "OWASP SAMM v2.1 Software Assurance Maturity Model (5 Business Functions; 15 Security Practices; Maturity Levels 1, 2, 3; Stream A and Stream B Assessment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "OWASP SAMM (Software Assurance Maturity Model) version 2.1 is the OWASP-published prescriptive framework for measuring and improving the software security posture of an organisation; it is governed by the OWASP Foundation under the Creative Commons CC BY-SA 4.0 license and is published at owaspsamm.org and github.com/owaspsamm/core. SAMM organises software assurance into five Business Functions: Governance, Design, Implementation, Verification, Operations. Each Business Function contains three Security Practices for a total of 15 practices: Governance covers Strategy and Metrics, Policy and Compliance, Education and Guidance; Design covers Threat Assessment, Security Requirements, Secure Architecture; Implementation covers Secure Build, Secure Deployment, Defect Management; Verification covers Architecture Assessment, Requirements-driven Testing, Security Testing; Operations covers Incident Management, Environment Management, Operational Management. Each Security Practice is assessed along two streams - Stream A and Stream B - which complement each other (for example, in Threat Assessment, Stream A is Application Risk Profile and Stream B is Threat Modeling). Each stream is rated at one of three Maturity Levels (Level 1, Level 2, Level 3) with specific Activities required at each level. SAMM provides an Assessment Toolbox (the OWASP SAMM Assessment Worksheet spreadsheet), the SAMM Benchmark (an anonymous data set of organisational maturity assessments enabling comparison against peers and sector medians), Skills mapping (mapping SAMM activities to security skill sets), Agile Guidance, and downloadable PDFs of the model. SAMM v2.1.0 was published 2024-09-18 with significant improvements including assessment questionnaires, agile implementation guides, multilingual translations, the practitioner directory, and benchmark functionality. SAMM is the recommended OWASP framework for organisations seeking a vendor-neutral, evidence-based software-security maturity model.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "governance_business_function",
        "design_business_function",
        "implementation_business_function",
        "verification_business_function",
        "operations_business_function",
        "maturity_levels",
        "stream_a_b_design",
        "samm_benchmark",
        "assessment_toolbox",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-4-workflow-application-security",
      "owasp-llm-top-10-2025",
      "cyber-nist-csf-2",
      "nist-sp-800-53-r5",
      "nist-sp-800-37-rmf"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-design-secure-architecture-practice",
    "title": "OWASP SAMM v2 - Design - Secure Architecture Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Design business function, Secure Architecture security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Secure Architecture practice within the Design function, which is implemented through two Streams: Architecture Design and Technology Management. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-design-security-requirements-practice",
    "title": "OWASP SAMM v2 - Design - Security Requirements Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Design business function, Security Requirements security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Security Requirements practice within the Design function, which is implemented through two Streams: Software Requirements and Supplier Security. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-design-threat-assessment-practice",
    "title": "OWASP SAMM v2 - Design - Threat Assessment Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Design business function, Threat Assessment security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Threat Assessment practice within the Design function, which is implemented through two Streams: Application Risk Profile and Threat Modeling. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-governance-education-guidance-practice",
    "title": "OWASP SAMM v2 - Governance - Education & Guidance Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Governance business function, Education & Guidance security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Education & Guidance practice within the Governance function, which is implemented through two Streams: Training and Awareness and Organization and Culture. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-governance-policy-compliance-practice",
    "title": "OWASP SAMM v2 - Governance - Policy & Compliance Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Governance business function, Policy & Compliance security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Policy & Compliance practice within the Governance function, which is implemented through two Streams: Policy & Standards and Compliance Management. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-governance-strategy-metrics-practice",
    "title": "OWASP SAMM v2 - Governance - Strategy & Metrics Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Governance business function, Strategy & Metrics security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Strategy & Metrics practice within the Governance function, which is implemented through two Streams: Create and Promote and Measure and Improve. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-implementation-defect-management-practice",
    "title": "OWASP SAMM v2 - Implementation - Defect Management Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Implementation business function, Defect Management security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Defect Management practice within the Implementation function, which is implemented through two Streams: Defect Tracking and Metrics and Feedback. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-implementation-secure-build-practice",
    "title": "OWASP SAMM v2 - Implementation - Secure Build Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Implementation business function, Secure Build security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Secure Build practice within the Implementation function, which is implemented through two Streams: Build Process and Software Dependencies. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-implementation-secure-deployment-practice",
    "title": "OWASP SAMM v2 - Implementation - Secure Deployment Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Implementation business function, Secure Deployment security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Secure Deployment practice within the Implementation function, which is implemented through two Streams: Deployment Process and Secret Management. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-operations-environment-management-practice",
    "title": "OWASP SAMM v2 - Operations - Environment Management Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Operations business function, Environment Management security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Environment Management practice within the Operations function, which is implemented through two Streams: Configuration Hardening and Patching and Updating. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-operations-incident-management-practice",
    "title": "OWASP SAMM v2 - Operations - Incident Management Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Operations business function, Incident Management security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Incident Management practice within the Operations function, which is implemented through two Streams: Incident Detection and Incident Response. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-operations-operational-management-practice",
    "title": "OWASP SAMM v2 - Operations - Operational Management Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Operations business function, Operational Management security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Operational Management practice within the Operations function, which is implemented through two Streams: Data Protection and System Decommissioning / Legacy Management. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-verification-architecture-assessment-practice",
    "title": "OWASP SAMM v2 - Verification - Architecture Assessment Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Verification business function, Architecture Assessment security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Architecture Assessment practice within the Verification function, which is implemented through two Streams: Architecture Validation and Architecture Mitigation. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-verification-requirements-testing-practice",
    "title": "OWASP SAMM v2 - Verification - Requirements Testing Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Verification business function, Requirements Testing security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Requirements Testing practice within the Verification function, which is implemented through two Streams: Control Verification and Misuse / Abuse Testing. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-samm-v2-verification-security-testing-practice",
    "title": "OWASP SAMM v2 - Verification - Security Testing Practice",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2020-01-31",
    "bluf": "OWASP SAMM v2 (Software Assurance Maturity Model) - Verification business function, Security Testing security practice. SAMM v2 is OWASP's prescriptive model for measuring and improving software security across an organization. The model defines 5 Business Functions (Governance, Design, Implementation, Verification, Operations), each with 3 Security Practices. This node covers the Security Testing practice within the Verification function, which is implemented through two Streams: Scalable Baseline and Deep Understanding. Each stream has 3 Maturity Levels (1, 2, 3) with associated assessment questions and stated answers describing what good looks like at each level. Organizations should self-assess using the OWASP SAMM Assessment Toolbox to identify their current maturity score (0-3 per stream) and plan incremental improvements to reach their target maturity level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-v2-1-software-assurance-maturity-model",
      "nist-sp-800-218-ssdf",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "owasp-top-10-2025-a01-broken-access-control",
    "title": "A01:2025 Broken Access Control",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10:2025 A01:2025 Broken Access Control. Access control enforces policy such that users cannot act outside of their intended permissions. Failures typically lead to unauthorized information disclosure, modification or destruction of all data, or performing a business function outside the user's limits. This category sits within the OWASP Top 10:2025 (the 2025 edition, finalized January 2026), the canonical industry list of the ten most critical web application security risks. Organizations building web applications should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category. Mapped weaknesses: CWE-22, CWE-23, CWE-36, CWE-59, CWE-61, CWE-65, CWE-200, CWE-201, CWE-219, CWE-276, CWE-281, CWE-282, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-top-10-2025-a02-security-misconfiguration",
    "title": "A02:2025 Security Misconfiguration",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10:2025 A02:2025 Security Misconfiguration. Security misconfiguration is when a system, application, or cloud service is set up incorrectly from a security perspective, creating vulnerabilities. This category sits within the OWASP Top 10:2025 (the 2025 edition, finalized January 2026), the canonical industry list of the ten most critical web application security risks. Organizations building web applications should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category. Mapped weaknesses: CWE-5, CWE-11, CWE-13, CWE-15, CWE-16, CWE-260, CWE-315, CWE-489, CWE-526, CWE-547, CWE-611, CWE-614, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-top-10-2025-a03-software-supply-chain-failures",
    "title": "A03:2025 Software Supply Chain Failures",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10:2025 A03:2025 Software Supply Chain Failures. Software supply chain failures are breakdowns or other compromises in the process of building, distributing, or updating software. This category sits within the OWASP Top 10:2025 (the 2025 edition, finalized January 2026), the canonical industry list of the ten most critical web application security risks. Organizations building web applications should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category. Mapped weaknesses: CWE-447, CWE-1035, CWE-1104, CWE-1329, CWE-1357, CWE-1395.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-top-10-2025-a04-cryptographic-failures",
    "title": "A04:2025 Cryptographic Failures",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10:2025 A04:2025 Cryptographic Failures. Moving down two positions to #4, this weakness focuses on failures related to the lack of cryptography, insufficiently strong cryptography, leaking of cryptographic keys, and related errors. This category sits within the OWASP Top 10:2025 (the 2025 edition, finalized January 2026), the canonical industry list of the ten most critical web application security risks. Organizations building web applications should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category. Mapped weaknesses: CWE-261, CWE-296, CWE-319, CWE-320, CWE-321, CWE-322, CWE-323, CWE-324, CWE-325, CWE-326, CWE-327, CWE-328, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-top-10-2025-a05-injection",
    "title": "A05:2025 Injection",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10:2025 A05:2025 Injection. An injection vulnerability is an application flaw that allows untrusted user input to be sent to an interpreter (e.g. a browser, database, the command line) and causes the interpreter to execute parts of that input as commands. This category sits within the OWASP Top 10:2025 (the 2025 edition, finalized January 2026), the canonical industry list of the ten most critical web application security risks. Organizations building web applications should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category. Mapped weaknesses: CWE-20, CWE-74, CWE-76, CWE-77, CWE-78, CWE-79, CWE-80, CWE-83, CWE-86, CWE-88, CWE-89, CWE-90, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "owasp-top-10-2025-a06-insecure-design",
    "title": "A06:2025 Insecure Design",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10:2025 A06:2025 Insecure Design. Insecure design is a broad category representing different weaknesses, expressed as \"missing or ineffective control design.\" Insecure design is not the source for all other Top Ten risk categories. Note that there is a difference between insecure design and insecure implementation. We differentiate between design flaws and implementation defects for a reason, they have different root causes, take place at different times in the development process, and have different remediations. A secure design can still have implementation defects leading to vulnerabilities that may be exploited. An insecure design cannot be fixed by a perfect implementation as needed security controls were never created to defend against specific attacks. One of the factors that contributes to insecure design is the lack of business risk profiling inherent in the software or system being developed, and thus the failure to determine what level of security design is required. This category sits within the OWASP Top 10:2025 (the 2025 edition, finalized January 2026), the canonical industry list of the ten most critical web application security risks. Organizations building web applications should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category. Mapped weaknesses: CWE-73, CWE-183, CWE-256, CWE-266, CWE-269, CWE-286, CWE-311, CWE-312, CWE-313, CWE-316, CWE-362, CWE-382, and others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-top-10-2025-a07-authentication-failures",
    "title": "A07:2025 Authentication Failures",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10:2025 A07:2025 Authentication Failures. When an attacker is able to trick a system into recognizing an invalid or incorrect user as legitimate, this vulnerability is present. This category sits within the OWASP Top 10:2025 (the 2025 edition, finalized January 2026), the canonical industry list of the ten most critical web application security risks. Organizations building web applications should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category. Mapped weaknesses: CWE-258, CWE-259, CWE-287, CWE-288, CWE-289, CWE-290, CWE-294, CWE-295, CWE-306, CWE-307, CWE-384, CWE-521.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-top-10-2025-a08-software-or-data-integrity-failures",
    "title": "A08:2025 Software or Data Integrity Failures",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10:2025 A08:2025 Software or Data Integrity Failures. Software and data integrity failures involve code and infrastructure failing to protect against untrusted code or data being treated as valid. Examples include relying on plugins from untrusted sources, insecure CI/CD pipelines lacking integrity verification, auto-updates without proper checks, and insecure deserialization of attacker-modified data. This category sits within the OWASP Top 10:2025 (the 2025 edition, finalized January 2026), the canonical industry list of the ten most critical web application security risks. Organizations building web applications should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category. Mapped weaknesses: CWE-345, CWE-353, CWE-426, CWE-427, CWE-494, CWE-502, CWE-506, CWE-565, CWE-829, CWE-830.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-top-10-2025-a09-security-logging-and-alerting-failures",
    "title": "A09:2025 Security Logging and Alerting Failures",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10:2025 A09:2025 Security Logging and Alerting Failures. Without logging and monitoring, attacks and breaches cannot be detected, and without alerting it is very difficult to respond quickly and effectively during a security incident. Insufficient logging, continuous monitoring, detection, and alerting to initiate active responses occurs any time: This category sits within the OWASP Top 10:2025 (the 2025 edition, finalized January 2026), the canonical industry list of the ten most critical web application security risks. Organizations building web applications should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category. Mapped weaknesses: CWE-117, CWE-221, CWE-223, CWE-532, CWE-778.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "owasp-top-10-2025-a10-mishandling-of-exceptional-conditions",
    "title": "A10:2025 Mishandling of Exceptional Conditions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-07-17",
    "bluf": "OWASP Top 10:2025 A10:2025 Mishandling of Exceptional Conditions. Mishandling exceptional conditions in software happens when programs fail to prevent, detect, and respond to unusual and unpredictable situations, which leads to crashes, unexpected behavior, and sometimes vulnerabilities. This category sits within the OWASP Top 10:2025 (the 2025 edition, finalized January 2026), the canonical industry list of the ten most critical web application security risks. Organizations building web applications should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category. Mapped weaknesses: CWE-209, CWE-248, CWE-252, CWE-390, CWE-476, CWE-636, CWE-703, CWE-754.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l1",
      "owasp-asvs-l2",
      "nist-sp-800-53-r5",
      "iso-27001-2022"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "pa-pdp-law-2019",
    "title": "Panama Personal Data Protection Law No. 81 of 2019 - AIG",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Panama's Ley No. 81 de 26 de marzo de 2019 'Sobre Protección de Datos Personales' (Personal Data Protection Law) - published in the Gaceta Oficial (official gazette) No. 28743-A on 29 March 2019 - is Panama's first comprehensive personal data protection legislation, establishing a rights-based framework for the protection of personal data of natural persons in Panama. The implementing regulation, Executive Decree No. 285 of 28 May 2021, provides detailed rules for the application of Law No. 81. The supervisory authority for data protection in Panama is the Autoridad Nacional para la Innovación Gubernamental (AIG - National Authority for Government Innovation), which was designated as the competent authority to receive notifications, process complaints, conduct investigations, and enforce Law No. 81. Key features of Panama's Law No. 81: (1) Scope - applies to the processing of personal data by public and private entities located in Panama, or where personal data of persons in Panama is processed, regardless of where the processing occurs; (2) Data processing principles - personal data processing must comply with: lawfulness; consent; purpose limitation; proportionality; accuracy; security; and confidentiality; (3) Sensitive personal data - Law No. 81 designates categories of sensitive personal data requiring heightened protection: racial or ethnic origin; health or medical data; sexual life or orientation; religious convictions; political affiliation; criminal records; genetic data; and economic or financial information classified as sensitive; (4) ARCO+ rights - data subjects have the rights of Acceso (access), Rectificación (rectification), Cancelación (cancellation), and Oposición (opposition), plus additional rights introduced by Law No. 81: right to restrict processing; right to data portability; and right to complain to the AIG; (5) Consent - processing requires the data subject's free, prior, specific, informed, and unequivocal consent, unless another lawful basis applies; consent must be documented; (6) Data bank registration - entities processing personal data must register their data processing activities with the AIG through the National Registry of Databases (Registro Nacional de Bases de Datos); (7) Data Protection Officer - entities processing personal data on a large scale or processing sensitive personal data must designate a Data Protection Officer (Delegado de Protección de Datos); (8) Data Protection Impact Assessment - required for high-risk processing activities, particularly involving sensitive personal data or systematic profiling; (9) Breach notification - data controllers must notify the AIG and affected data subjects of personal data breaches that may harm data subjects; (10) Cross-border transfers - personal data may only be transferred to countries providing adequate protection; transfers to non-adequate countries require AIG authorisation or data subject consent; (11) Administrative sanctions - fines from B/. 1,000 to B/. 500,000 (Balboas, equivalent to USD as Panama uses the US dollar); criminal penalties including imprisonment for serious violations. Panama's Law No. 81 is notable for its alignment with international standards and for Panama's strategic position as a regional financial and logistics hub, where extensive personal data processing occurs in banking, insurance, shipping, and free trade zones.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "pa-texto-unico-ley-22-2006-contrataciones-publicas-panama-compra",
    "title": "Panama Texto Unico Ley 22 of 27 June 2006 on Public Procurement (Contrataciones Publicas) and the PanamaCompra Electronic Procurement Platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Panama Texto Unico Ley 22 of 27 June 2006 (Texto Unico de la Ley 22 de 27 de junio de 2006 que regula la contratacion publica), as substantially amended by Ley 153 of 8 May 2020 (Por la cual se modifica la Ley 22 de 2006) and supplemented by Decreto Ejecutivo 40 of 10 April 2018 (Reglamento de Aplicacion), is the principal Panamanian statute governing public procurement of goods, services, and construction works by entities of the Public Administration including the Central Government (Gobierno Central) ministries, Decentralized Entities (Entidades Descentralizadas), Autonomous Entities (Entidades Autonomas), public-sector enterprises, municipalities (Municipios), and other entities financed by the State budget. The Direccion General de Contrataciones Publicas (DGCP / dgcp.gob.pa) under the Ministry of Economy and Finance is the central regulatory authority responsible for procurement regulation, oversight, compliance monitoring, supplier debarment, and operation of the PanamaCompra electronic procurement platform. The PanamaCompra Portal (panamacompra.gob.pa) operated by DGCP is the mandatory federal e-procurement platform for in-scope procurement. The Tribunal Administrativo de Contrataciones Publicas (TACP) is the specialised tribunal for procurement appeals. Procurement methods established by Ley 22/2006 art. 38 and Reglamento art. 60 to 119 comprise (a) Licitacion Publica (Public Tender, the default open public procedure for prescribed-value acquisitions above thresholds), (b) Licitacion por Mejor Valor (Best Value Tender, with weighted criteria), (c) Licitacion para Convenio Marco (Framework Agreement Tender), (d) Licitacion Abreviada por Mejor Valor (Abbreviated Best Value Tender), (e) Subasta en Reversa (Reverse Auction), (f) Contratacion Menor (Minor Procurement, for small-value below thresholds), (g) Contratacion Directa (Direct Procurement, sole-source under prescribed exceptions in art. 65 to 69 including emergency, sole supplier for technical reasons, prior failed tendering), and (h) Acuerdo Marco (Framework Agreement). The Contraloria General de la Republica conducts ex-ante (refrendo) and ex-post procurement audit. Panama is NOT a party to the WTO Government Procurement Agreement (GPA) but is an observer. Panama is a party to the US-Panama Trade Promotion Agreement (in force 2012), the EU-Central America Association Agreement (in force 2013), and UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "pa-pdp-law-2019",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "panama-maritime-authority-ship-registry",
    "title": "Panama Maritime Authority Ship Registry (AMP) - World's Largest Open Ship Registry Regulatory Framework",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Panama Maritime Authority (Autoridad Marítima de Panamá, AMP) administers the world's largest ship registry, with over 8,000 vessels of more than 220 million gross tonnes registered as at 2024 - approximately 17% of global gross tonnage. Panama is among the top performing flag States on IMO's Port State Control targeting mechanisms (White List). The Panamanian ship registry is governed by Cabinet Decree No. 10 of 26 October 2022 (the Merchant Marine Law) and its implementing regulations. Panama is a full member of IMO and has ratified all major IMO conventions including SOLAS, MARPOL, MLC 2006, and STCW. The AMP's Ship Registration Office (Registro Nacional de Buques) issues the Panama Ship Registry Certificate, which is the primary document confirming registration and flag State rights for Panamanian-flagged vessels.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "imo_solas_consolidated",
        "imo_marpol_annex_i",
        "mlc_2006"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-consolidated-2020",
      "imo-marpol-annex-i-oil-pollution",
      "imo-stcw-convention-1978-2010-manila",
      "imo-maritime-labour-convention-2006-mlc"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "paris-agreement-2015-ndcs-mitigation-adaptation",
    "title": "Paris Agreement 2015 - Nationally Determined Contributions, Global Stocktake and 1.5C Temperature Goal",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Paris Agreement is a legally binding international treaty on climate change, adopted by 196 Parties at the 21st Conference of the Parties (COP21) in Paris on 12 December 2015 and entered into force on 4 November 2016. Article 2.1(a) establishes the long-term temperature goal of holding the increase in the global average temperature to well below 2 degrees Celsius above pre-industrial levels and pursuing efforts to limit the temperature increase to 1.5 degrees Celsius above pre-industrial levels. Article 4 requires each Party to prepare, communicate and maintain successive Nationally Determined Contributions (NDCs) that it intends to achieve, with each successive NDC representing a progression beyond the Party's then current NDC and reflecting its highest possible ambition. Article 7 establishes the global goal on adaptation. Article 9 provides for finance, with developed countries committed under the UNFCCC and successive COP decisions to mobilise climate finance scaling from $100 billion per year by 2020 to a new collective quantified goal post-2025 (NCQG agreed at COP29 in Baku at $300 billion/year by 2035). Article 14 establishes the Global Stocktake every five years to assess collective progress, with the first GST concluded at COP28 in Dubai (December 2023). As of 2024, 195 Parties to the UNFCCC have ratified the Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-cbam-2023-956-carbon-border-adjustment",
      "australia-nger-act-2007-national-greenhouse-energy-reporting"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "paris-ai-action-summit-2025",
    "title": "Paris AI Action Summit 2025 - Statement on Inclusive and Sustainable AI for People and Planet",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The Paris AI Action Summit, held on 10-11 February 2025 at the Grand Palais under the French presidency of the EU Council, was the third international AI safety summit in the Bletchley Process - it adopted the 'Statement on Inclusive and Sustainable AI for People and Planet' signed by over 60 countries and international organisations; critically, the United States and United Kingdom declined to sign the Paris statement, reflecting significant geopolitical divergence in AI governance philosophy between the EU-led approach emphasising inclusive governance, sustainable development, and multilateral regulation and the US Trump administration's pro-innovation, anti-regulation stance (as reflected in Executive Order 14179 of 20 January 2025 revoking Biden's EO 14110 on Safe and Trustworthy AI); the Paris summit focused on five thematic pillars: (1) the public interest in AI (governance and public good); (2) the future of work and AI; (3) innovation and culture; (4) trust and global AI governance; (5) AI and sustainable development; it launched the 'International Panel on AI Safety' (IPAIS) as a scientific advisory body to inform AI governance, and produced a separate 'Scientific Declaration on AI' signed by researchers; the summit's governance outcome was significant primarily for demonstrating the limits of international AI governance consensus rather than producing new binding commitments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/paris-ai-action-summit-2025.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-ai-safety-2023",
      "seoul-ai-safety-summit-2024",
      "eu-ai-act-2024",
      "eu-ai-office-gpai-code-of-practice-2025",
      "oecd-ai-principles-2024",
      "g7-hiroshima-ai-process-guiding-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "paris-convention-industrial-property",
    "title": "Paris Convention (IP)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Paris Convention for the Protection of Industrial Property (1883) is the foundational international treaty for IP rights. It introduced the 'Right of Priority' and 'National Treatment', ensuring that inventors can claim the original filing date across member states and that foreign innovators receive the same protection as local nationals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-pct-international-patent",
      "wipo-madrid-trademark-system",
      "wipo-hague-design-system",
      "berne-convention-literary-artistic"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "paris-memorandum-port-state-control-1982",
    "title": "Paris Memorandum of Understanding on Port State Control 1982 - Ship Inspection Targeting and Detention Framework",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Paris MOU on Port State Control (1982, 27 European and North Atlantic member states) coordinates ship inspections by port authorities to verify compliance with international maritime conventions (SOLAS, MARPOL, MLC, STCW); implements the Concentrated Inspection Campaign (CIC) annually on specific safety topics; uses the New Inspection Regime (NIR) targeting algorithm classifying ships as High, Standard, or Low priority based on vessel profile, flag state performance, and company performance; maintains the White/Grey/Black flag list published annually; vessels with excess deficiencies detained in port pending rectification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-consolidated-2020",
      "imo-maritime-labour-convention-2006-mlc"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "patient-generated-health-data-pghd-2026",
    "title": "Patient-Generated Health Data (PGHD) - Regulatory, Privacy & Clinical Integration (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Guidance on the integration, validation, and privacy protection of Patient-Generated Health Data (PGHD) from wearables, apps, and home medical devices into clinical electronic health records (EHRs) and clinical trials.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "payment-processing-restricted-content-visa-virp-mastercard-an-5196",
    "title": "Payment Processing Rules for Restricted Content Services (Visa Integrity Risk Program VIRP; Mastercard AN 5196 Specialty Merchant Standards; Documented Consent, Age and Identity Verification, Content Pre-Screening, Seven-Day Complaint Resolution)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Operators of restricted-content services that accept Visa and Mastercard payments must satisfy two parallel card-network compliance regimes: the Visa Integrity Risk Program (VIRP) and the Mastercard Specialty Merchant Registration Requirements for Adult Content Merchants (AN 5196, published April 2021, compliance deadline 15 October 2021). The Visa VIRP framework is described authoritatively in Visa's Protecting the integrity of the Visa network paper (September 2024 publication date in document metadata). VIRP applies to merchants in higher-risk categories that are legal but at higher risk for unlawful transactions; restricted content services fall in this category. VIRP requirements: (1) merchants must be registered in VIRP by their acquirer; (2) the acquirer must perform specific heightened due diligence on the merchant; (3) the acquirer must certify to Visa on a quarterly basis that the merchant meets program requirements and complies with the law; (4) Visa applies extensive monitoring tools and AI-based risk models to detect non-compliant transactions; (5) Visa works with the Internet Watch Foundation (IWF) and the Financial Coalition Against Child Sexual Exploitation (FCACSE) to detect and remediate illegal content on the network. Mastercard AN 5196 added specific requirements to the Mastercard Standards effective 15 October 2021: documented age and identity verification for all persons depicted in the content and all persons uploading the content; a content review process prior to publication; real-time monitoring of streamed and live content; a complaint resolution process that addresses illegal or non-consensual content within seven business days; and an appeals process allowing any person depicted to request that their content be removed. Failure to comply allows Mastercard or the Acquirer to impose fines and to restrict or terminate the merchant from the network. Stripe's Restricted Businesses policy at stripe.com/legal/restricted-businesses lists adult content businesses as restricted and requires the merchant to be specifically approved before processing payments. These payment-network rules operate alongside national age-verification statutes (UK Online Safety Act 2023, France SREN 2024, etc.) and the EU Digital Services Act; an operator must satisfy all applicable regimes simultaneously - payment-network compliance is not a substitute for statutory compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "visa_virp_overview",
        "visa_virp_compliance_with_law",
        "visa_virp_registration_and_heightened_due_diligence",
        "visa_virp_technology_and_partners",
        "mastercard_an_5196_announcement",
        "mastercard_an_5196_documented_consent_and_id_verification",
        "mastercard_an_5196_content_review_pre_publication",
        "mastercard_an_5196_complaint_resolution_seven_business_days",
        "mastercard_an_5196_appeals_process",
        "stripe_restricted_businesses_policy",
        "operates_alongside_statutory_regimes",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2257-record-keeping-explicit-content",
      "us-18-usc-2257a-simulated-explicit-conduct-records",
      "uk-online-safety-act-2023-ofcom-illegal-content-duty",
      "fr-loi-sren-2024-449-age-verification-pornography",
      "us-take-it-down-act-2025"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "pcaob-audit-standards",
    "title": "PCAOB Auditing Standards",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Adherence to Public Company Accounting Oversight Board (PCAOB) auditing standards is substantiated through a meticulous review of engagement criteria. Foundational requirements are met, as the firm’s registration with the PCAOB is confirmed and auditor independence is maintained, consistent with the principles in AS 1001. The audit process involved a completed risk assessment procedure under AS 2110, which encompassed a specific evaluation of cybersecurity risk disclosures. Sufficient appropriate evidence was properly obtained to form a basis for the auditor's opinion. An integrated audit of internal control over financial reporting has been performed as directed by AS 2201, yielding a critical outcome where zero material weaknesses were identified. In accordance with AS 1215, all engagement documentation is subject to a mandatory retention period of seven years. The engagement also underwent a successful engagement quality review. Reporting and communication obligations were rigorously fulfilled; critical audit matters were communicated to stakeholders as stipulated in AS 3101, and audit committee communication has been verified, fulfilling the mandates of AS 1301. The lead auditor's tenure of ten years is noted for contextual purposes. This comprehensive performance demonstrates full compliance with prevailing PCAOB professional standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sarbannes-oxley-404",
      "aicpa-code-ethics",
      "gaap-us-framework",
      "ifac-ethics-accountants"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "pci-dss-4-0-compliance-2026-21",
    "title": "PCI DSS 4.0 Enterprise Compliance Standard v21",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The PCI DSS 4.0 standard outlines comprehensive security measures for organizations that handle cardholder data. It emphasizes the importance of protecting cardholder data through encryption, access control, and regular security testing. The standard is divided into six goals, encompassing over 300 requirements that address security management, policies, procedures, network architecture, and software design. Key areas include maintaining a secure network, implementing strong access control measures, regularly monitoring and testing networks, and maintaining an information security policy. Organizations must also ensure that all personnel are trained in security awareness and that they understand their roles in protecting cardholder data. Compliance is essential for reducing the risk of data breaches and maintaining customer trust.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "pci-dss-4-0-compliance-2026-6",
    "title": "PCI DSS 4.0 Enterprise Compliance Standard v6",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The PCI DSS 4.0 standard outlines comprehensive security measures to protect cardholder data and ensure secure payment transactions. It mandates organizations to implement robust security controls, including encryption, access control, and regular security testing. The standard emphasizes risk assessment, vulnerability management, and the importance of maintaining a secure network. Organizations must also establish policies for data protection, employee training, and incident response. Compliance is assessed through self-assessment questionnaires or formal assessments by qualified security assessors. The standard aims to enhance security measures and reduce the risk of data breaches, ensuring the integrity and confidentiality of payment card information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "pci-dss-hospitality",
    "title": "PCI-DSS (Hospitality Payment)",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Adherence to the Payment Card Industry Data Security Standard (PCI-DSS) within hospitality environments necessitates a comprehensive framework of technical and operational controls to protect cardholder data (CHD). Critical security validations mandate that all CHD is encrypted using strong cryptography during transmission across open, public networks and that stored Primary Account Numbers (PANs) are rendered unreadable. A significant compliance failure is triggered if any Sensitive Authentication Data (SAD) is retained post-authorization. Furthermore, the standard requires that displayed PANs are always masked, showing at most the first six and last four digits. Foundational security posture is assessed through proper segmentation of the Cardholder Data Environment (CDE) from other corporate or guest networks, along with confirmation that all vendor-supplied default passwords have been changed. Strict access controls are verified, demanding unique user IDs for every individual with CDE access and the enforcement of Multi-Factor Authentication (MFA) for all remote and non-console administrative connections. System integrity is monitored by ensuring anti-malware software is deployed and active on all commonly affected systems within the CDE. Compliance also depends on successful quarterly external vulnerability scans passed without any failing items, as conducted by an Approved Scanning Vendor (ASV), and the maintenance of a formal security incident response plan which is tested at least annually.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-hospitality-nuance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "pci-dss-v4",
    "title": "PCI DSS v4.0 - Payment Card Data Security",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "PCI DSS v4.0, published March 2022 by the PCI Security Standards Council (PCI SSC), is the mandatory security standard for all entities that store, process, or transmit payment card data (cardholder data / CHD) or sensitive authentication data (SAD). The standard contains 12 requirements organized across 6 core goals. Version 4.0 introduced a Customized Approach allowing organizations to use alternative controls with documented risk analysis, and added 64 new requirements versus v3.2.1. Key additions: MFA for all access to the cardholder data environment (Req. 8.4.2, effective March 2025), 12-character minimum passwords (Req. 8.3.6), and targeted risk analysis for customized controls. PCI v3.2.1 was retired March 31, 2024. Compliance is validated annually via Report on Compliance (ROC) for Level 1 merchants (>6M Visa/Mastercard transactions/year) by a Qualified Security Assessor (QSA), or Self-Assessment Questionnaire (SAQ) for lower levels. Non-compliance penalties include fines of $5,000-$100,000/month from card brands, increased transaction fees, and loss of card acceptance privileges.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sox-it-controls",
      "sec-reg-s-k-106"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pci-dss-v4-cloud-shared-responsibility-matrix",
    "title": "PCI DSS v4.0 Cloud Shared Responsibility - Payment Card Industry Requirements for Cloud Workloads: Responsibility Matrix by Service Model (IaaS/PaaS/SaaS), Compensating Controls for Multi-Tenant Environments, Tokenisation, P2PE and Cloud Service Provider PCI Compliance Reports",
    "domain": "Cloud & SaaS",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation defines the shared responsibility model for PCI DSS compliance in cloud environments, specifying which security controls are the obligation of the cloud service provider versus the customer based on service model (IaaS, PaaS, SaaS), as outlined in PCI DSS v4.0.1 Requirement 2.2 and related guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "cobit-2019-governance-framework",
      "eu-gdpr-cloud-data-processing",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "pci-dss-v4-req-1-2-network-security",
    "title": "PCI DSS v4.0 Requirement 1.2: Network Security Controls to Restrict Connections Between Untrusted Networks and the CDE",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This requirement mandates that entities implement and configure Network Security Controls (NSCs), such as firewalls, to restrict all network connections between untrusted networks (e.g., the internet) and any system component in the Cardholder Data Environment (CDE). Per Requirement 1.2.1, NSCs must be implemented at every point of connection between the CDE and untrusted networks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026",
        "mitre_attack"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-53-sc7",
      "cis-controls-v8",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pci-dss-v4-req-10-12-monitoring-policy",
    "title": "Payment Card Industry Data Security Standard (PCI DSS) v4.0: Requirements 10, 11, and 12 - Logging, Monitoring, Testing, and Policy",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "PCI DSS Requirements 10, 11, and 12 mandate that entities handling cardholder data must implement robust audit logging and monitoring for all system access (Req 10), regularly test security systems and processes through vulnerability scans and penetration testing (Req 11), and maintain a comprehensive information security policy that governs all personnel and defines security responsibilities (Req 12).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026",
        "mitre_attack",
        "mitre_d3fend",
        "mitre_capec"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-53-au2",
      "cis-controls-v8",
      "iso-27001-2022",
      "guide-computer-security-log-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "pci-dss-v4-req-3-4-data-protection",
    "title": "Payment Card Industry Data Security Standard (PCI DSS) v4.0 - Requirements 3 and 4: Protect Stored Account Data and Protect Cardholder Data with Strong Cryptography During Transmission",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "For all entities that store, process, or transmit cardholder data, PCI DSS Requirements 3 and 4 mandate the protection of stored account data and the use of strong cryptography for transmitting cardholder data over open, public networks. Specifically, Requirement 3.3 requires that the Primary Account Number (PAN) be rendered unreadable wherever it is stored, and Requirement 4.2.1 mandates that strong cryptography and security protocols are used to safeguard PAN during transmission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "fips-197-advanced-encryption-standard",
      "nist-cybersecurity-framework-2-0",
      "pci-dss-v4-requirement-4"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "pci-dss-v4-req-6-7-system-security",
    "title": "PCI DSS v4.0 Requirements 6 and 7: Develop and Maintain Secure Systems and Software & Restrict Access to Cardholder Data by Business Need to Know",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation requires entities handling cardholder data to develop and maintain secure systems and software by identifying and addressing security vulnerabilities (Requirement 6) and to restrict access to system components and cardholder data to only those individuals whose job requires such access, based on the principle of least privilege (Requirement 7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "pci-dss-v4-requirement-1",
    "title": "PCI DSS v4 Req 1 (NSC)",
    "domain": "Cloud & SaaS",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "PCI DSS v4 Requirement 1 (Install and Maintain Network Security Controls) mandates the use of the 'Network Security Controls' (NSCs) (historically Firewalls) to the protect the Cardholder Data Environment (CDE). it requires the strict logical and the physical isolation of the credit card processing from the unauthorized networks through the formalized the 'Rule' and the 'Configuration' management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "pci-dss-v4-requirement-2",
    "title": "PCI DSS v4 Req 2 (Hardening)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Requirement 2 mandates the application of secure configuration standards across all system components within the Cardholder Data Environment, explicitly prohibiting reliance on vendor-supplied defaults. Governing guidance stipulates that a formal, documented system hardening standard, based on established frameworks such as NIST or CIS, must exist and be consistently applied to all in-scope systems. Compliance necessitates the proactive removal or modification of all vendor-supplied default credentials, including specific confirmation that wireless environment vendor defaults were changed at installation. Furthermore, the operational state must reflect that all insecure protocols such as Telnet, FTP, HTTP, and early TLS versions are disabled, and any unnecessary services, daemons, or functions not directly required for a component's purpose are deactivated to minimize the attack surface. Authoritative controls enforce a strict policy of one primary function per server to prevent security-level conflicts, a mandate supported by a continuously maintained inventory of all system components. Comprehensive security policies and operational procedures for managing configurations must be documented and known by affected parties, with hardening integrity confirmed through timely automated verification scans. For entities utilizing shared hosting, it is imperative that documented confirmation from the provider defines their specific responsibility for protecting merchant environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-218-ssdf",
      "nist-sp-800-40r4-enterprise-patch-management",
      "nist-sp-800-190-container-security"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pci-dss-v4-requirement-3",
    "title": "PCI DSS v4 Req 3 (Stored Data)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "PCI DSS v4 Requirement 3 (Protect Stored Account Data) focuses on the security of the cardholder information residing on the persistent storage. it mandates the prohibition of the 'Sensitive Authentication Data' (SAD) storage post-authorization and the requirement for the 'Primary Account Number' (PAN) to be the rendered unreadable through the strong encryption, the truncation, or the hashing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pci-dss-v4-requirement-2",
      "pci-dss-v4-requirement-7",
      "pci-dss-v4-requirement-8",
      "nist-800-88-sanitization",
      "nist-sp-800-63b-authentication"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pci-dss-v4-requirement-4",
    "title": "PCI DSS v4 Req 4 (Transmission)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "PCI DSS v4 Requirement 4 (Protect Cardholder Data with Strong Cryptography During Transmission) revolves around the security of the clear-text card data as it travels across the any 'Open, Public' networks (e.g., the Internet, Cellular, Wireless). it mandates the use of the 'Strong Cryptography' (TLS 1.2+, IPsec, SSH) to the ensure that the card data is not the intercepted or the tampered during the transit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "pci-dss-v4-requirement-5",
    "title": "PCI DSS v4 Req 5 (Malware)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "PCI DSS v4 Requirement 5 (Protect All Systems and Networks from Malicious Software) mandates the implementation of the active malware protection across the all system components. it focuses on the continuous monitoring, the detection, and the remediation of the 'Malicious Code' (Viruses, Worms, Trojans) and the 'Phishing' risks, ensuring the CDE integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "pci-dss-v4-requirement-6",
    "title": "PCI DSS v4 Req 6 (Software)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "PCI DSS v4 Requirement 6 (Develop and Maintain Secure Systems and Software) specifies the requirements for the secure software development lifecycle (SDLC) and the vulnerability management. it mandates the protection of the public-facing web applications from the specific attacks (e.g., OWASP Top 10) and the 'Timely Patching' of the all critical vulnerabilities within 30 days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pci-dss-v4-requirement-7",
    "title": "PCI DSS v4 Req 7 (Access Control)",
    "domain": "Cloud & SaaS",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Payment Card Industry Data Security Standard v4 Requirement 7 mandates a stringent framework for restricting access to system components and cardholder data based on an explicit business need-to-know. Compliance necessitates that a formal access control policy is defined and actively maintained. Pursuant to governing standards, system access must be structured upon an implemented role-based access control methodology, ensuring that permissions are assigned based on job classification and function. A foundational \"default deny-all\" configuration is required, meaning access is prohibited unless specifically permitted. This enforces the least privilege principle, where personnel receive only the minimum permissions necessary to perform their duties. The process for granting access must follow a documented approval workflow, with all subsequent privilege assignments being formally recorded. Furthermore, these access rights are subject to periodic validation, requiring a comprehensive review at a minimum frequency of every 6 months. A defined termination revocation process must ensure immediate removal of access for departing personnel. Authoritative guidance also stipulates that both system account access and user access to security functions must be rigorously restricted. Critically, all user interactions within the Cardholder Data Environment (CDE) are to be logged, creating an auditable trail of data access and system activities to prevent unauthorized exposure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-210-cloud-access-control",
      "pci-dss-v4-requirement-8"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pci-dss-v4-requirement-8",
    "title": "PCI DSS v4 Req 8 (Identity)",
    "domain": "Cloud & SaaS",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "PCI DSS v4 Requirement 8 (Identify Users and Authenticate Access to System Components) specifies the authentication standards for the payment environments. it mandates the 'Unique ID' per individual and the 'Multifactor Authentication' (MFA) for the all access to the Cardholder Data Environment (CDE), ensuring the absolute accountability and the protection against the credential-based attacks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-63b-authentication",
      "pci-dss-v4-requirement-7"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pdac-e3-plus-exploration-best-practices",
    "title": "PDAC e3 Plus - Responsible Exploration Framework: Community Engagement, Indigenous Peoples Rights, Environment and Health/Safety Best Practices for Mineral Exploration Companies",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The PDAC e3 Plus framework requires mineral exploration companies to develop and implement documented community engagement plans, Indigenous Peoples consultation processes, environmental impact assessments, and health & safety management systems, as set out in Clause 1.1 (Scope) and Clause 3 (Community Engagement) of the framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifc-performance-standards-2012-mining",
      "icmm-mining-principles-2020",
      "gri-14-mining-sector-standard-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "pe-dp-law-2011",
    "title": "Peru Personal Data Protection Law No. 29733 2011 - ANPDP",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Peru's Ley de Protección de Datos Personales (Personal Data Protection Law) - Law No. 29733, enacted on 2 July 2011 and published in El Peruano (official gazette) on 3 July 2011 - is Peru's primary legislation governing the protection of personal data. The implementing regulation, Supreme Decree No. 003-2013-JUS, was issued on 22 March 2013. The supervisory authority is the Autoridad Nacional de Protección de Datos Personales (ANPDP - National Authority for Personal Data Protection), which operates within the Ministerio de Justicia y Derechos Humanos (MINJUSDH - Ministry of Justice and Human Rights) and maintains the Registro Nacional de Protección de Datos Personales (National Registry for Personal Data Protection). Law No. 29733 establishes a rights-based framework for personal data protection with a particular focus on the registration of personal data banks (bancos de datos personales - databases containing personal data) and the ARCO rights framework (Acceso, Rectificación, Cancelación, and Oposición). Key features of Peru's Law No. 29733: (1) Scope - applies to personal data contained in personal data banks within Peruvian territory and to data banks maintained abroad where Peruvian law applies; (2) Personal data bank registration - all personal data banks (both private sector and public sector) must be registered with the ANPDP in the National Registry for Personal Data Protection before processing commences; (3) Principles - personal data processing must comply with the following principles: lawfulness, consent, purpose limitation, proportionality, quality (accuracy and currency), security, technical discretion, and transparency; (4) ARCO rights - data subjects have four principal rights: Acceso (access to personal data held about them); Rectificación (rectification of inaccurate or incomplete data); Cancelación (cancellation/erasure of data that is outdated, inaccurate, or unlawfully processed); and Oposición (opposition to processing for specific purposes); (5) Sensitive data - the law designates categories of sensitive personal data requiring heightened protection: racial or ethnic origin; income; political convictions or opinions; religious beliefs; physical or moral characteristics; sexual affiliation; and personal criminal, administrative, civil, or police records; (6) Consent - generally required for processing personal data; consent must be free, prior, express, unequivocal, and informed; tacit consent is limited to specific circumstances; (7) Cross-border transfer - personal data may only be transferred to countries providing equivalent or superior protection to Peruvian law; transfers to inadequate countries require ANPDP authorisation; (8) Penalties - administrative fines in Unidades Impositivas Tributarias (UIT): minor violations: up to 5 UIT; serious violations: up to 50 UIT; very serious violations: up to 100 UIT (approximately USD 140,000 at 2025 UIT value); (9) Habeas Data - the Constitutional Tribunal of Peru has constitutional jurisdiction to hear habeas data actions by data subjects against public bodies that refuse to provide or rectify personal information. Peru's data protection framework, while comprehensive, has been criticised for its limited enforcement capacity relative to the volume of personal data banks and the comparatively low maximum administrative fines. The ANPDP has pursued enforcement actions against both public and private sector entities but with limited resources.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "pe-ley-30225-ley-de-contrataciones-del-estado-osce-seace",
    "title": "Peru Ley 30225 Ley de Contrataciones del Estado (Law on State Contracts) as amended by Ley 32069 of 2024 and SEACE Electronic Procurement Platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Peruvian Ley 30225 (Ley de Contrataciones del Estado / Law on State Contracts) published 11 July 2014 and effective 9 January 2016 (with the Reglamento approved by Decreto Supremo 350-2015-EF), as substantially amended by Ley 32069 of 19 June 2024 (Ley General de Contrataciones Publicas / New General Public Procurement Law replacing Ley 30225) is the principal Peruvian framework governing procurement of goods, services, and works by entities of the State (Entidades del Estado) including the Executive Branch (Poder Ejecutivo), the Legislative Branch (Poder Legislativo), the Judicial Branch (Poder Judicial), autonomous constitutional bodies (Organismos Constitucionalmente Autonomos), regional governments (Gobiernos Regionales), local governments (Gobiernos Locales / Municipalities), public-sector enterprises (Empresas del Estado), public-sector universities, and other entities of the National Public Sector financed by State funds. The 2024 Ley 32069 General Public Procurement Law modernised the Peruvian procurement framework introducing (a) a unified statute with sector-specific provisions, (b) strengthened anti-corruption and integrity provisions including beneficial ownership disclosure and supplier debarment, (c) integrated electronic procurement, (d) sustainability and innovation criteria, and (e) strengthened complaint resolution. The Organismo Supervisor de las Contrataciones del Estado (OSCE) is the central regulatory authority for procurement compliance monitoring, complaint resolution, and procurement guidance. The Sistema Electronico de Contrataciones del Estado (SEACE / contrataciones.gob.pe) operated by OSCE is the mandatory federal e-procurement platform. The Central de Compras Publicas (PERU COMPRAS / perucompras.gob.pe) is the central purchasing body. Procurement methods established by Ley 30225 art. 21 and Reglamento art. 1 to 13 comprise (a) Licitacion Publica (Public Tender, for prescribed-value goods and works), (b) Concurso Publico (Public Competition, for prescribed-value services), (c) Adjudicacion Simplificada (Simplified Award, for medium-value goods, services, and works below Public Tender thresholds), (d) Seleccion de Consultores Individuales (Selection of Individual Consultants, for consultancy services), (e) Comparacion de Precios (Price Comparison, for small-value below thresholds), (f) Subasta Inversa Electronica (Reverse Electronic Auction, for commoditised products), (g) Contratacion Directa (Direct Contracting, sole-source under prescribed exceptions), and (h) Procedimientos Especiales (Special Procedures including catalogues and framework agreements).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "pe-dp-law-2011",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "pe-ley-31557-juegos-distancia-mincetur",
    "title": "Ley N. 31557 Regulating Remote Games and Remote Sports Betting (modified by Ley 31806) - MINCETUR",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Peru Ley N. 31557, as modified by Ley 31806, regulates the operation of remote games and remote sports betting and is administered by MINCETUR, the Ministry of Foreign Trade and Tourism. Article 7 requires operators to obtain authorisation for their technological platform before offering remote games and betting. Article 8 requires games and betting systems to be certified by an authorised laboratory. Article 11 requires a player registration system with mandatory age verification to prevent access by minors. Article 26 sets operator obligations including segregated player funds, responsible gaming tools and money laundering prevention, and Article 38 establishes the sanctions for violations, ranging from fines to suspension or revocation of authorisation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pe-dp-law-2011",
      "responsible-gambling-grb-standards-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pe-ley-31814-2023-uso-inteligencia-artificial-ds-115-2025-pcm",
    "title": "Peru Ley N° 31814 (5 July 2023) - Ley que Promueve el Uso de la Inteligencia Artificial; Decreto Supremo 115-2025-PCM (9 September 2025) Reglamento; SGTD Secretaría de Gobierno y Transformación Digital as AI Authority",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Peru's Ley N° 31814 'Ley que promueve el uso de la inteligencia artificial en favor del desarrollo económico y social del país' was published in El Peruano on 5 July 2023 and is the first dedicated AI statute in a LATAM jurisdiction. The law promotes and guarantees ethical, sustainable, transparent, and responsible use of artificial intelligence within Peru's national digital transformation process. The law's core principles include: ethical development for responsible AI; risk-based security standards; advancement of the digital society through emerging technologies; protection of privacy and personal data rights; human rights protection; multistakeholder participation in regulatory policy debate. The law designates the Secretaría de Gobierno y Transformación Digital (SGTD) of the Presidencia del Consejo de Ministros (PCM) as the national AI technical-regulatory authority responsible for supervising the development and use of AI and emerging technologies, promoting adoption, strengthening digital infrastructure, establishing ethical frameworks, and fostering collaborative ecosystems. The Executive was required to approve implementing regulations within 90 working days. The Reglamento de la Ley N° 31814 was approved by Decreto Supremo N° 115-2025-PCM on 9 September 2025, making Peru one of the first LATAM countries with a normative AI framework that ensures AI is developed and used with safety, ethics, transparency, sustainability, and inclusion, respecting human rights. The Reglamento operationalises the law including the risk classification, the supervisory powers of SGTD, the conformity assessment expectations, and the sanctions framework. The Peruvian regime operates alongside Decreto de Urgencia N° 007-2020 (Marco de Confianza Digital), Ley N° 29733 (Personal Data Protection Law administered by the Autoridad Nacional de Protección de Datos Personales ANPDP-MINJUS), and the UNESCO Recommendation on the Ethics of AI (2021).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "ley_31814_objeto_finalidad",
        "ley_31814_principios_developmental_use",
        "ley_31814_autoridad_nacional_sgtd",
        "ley_31814_declaracion_interes_nacional",
        "reglamento_ds_115_2025_pcm",
        "decreto_urgencia_007_2020_marco_confianza_digital",
        "ley_29733_personal_data_protection",
        "indecopi_consumer_protection_ai_aspects",
        "international_alignment_unesco_oecd_oas",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pe-dp-law-2011",
      "eu-ai-act-article-50-transparency-obligations",
      "nist-ai-rmf-1-0-govern-function",
      "unesco-ai-ethics-work",
      "co-conpes-3975-2019-digital-transformation-ai-policy"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "pediatric-medical-devices-governance-2026",
    "title": "Pediatric Medical Devices - Special Regulatory & Ethical Governance (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Pediatric medical devices require heightened regulatory scrutiny due to anatomical, physiological, and developmental differences in children. Key obligations include age-appropriate design, dedicated clinical investigations in pediatric populations, enhanced post-market surveillance, ethical considerations (assent/consent), and specific incentives or pathways (e.g., FDA Pediatric Device Consortia, EU Pediatric Investigation Plans). Many jurisdictions mandate pediatric-specific risk-benefit analysis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "pefc-forest-mgt",
    "title": "PEFC Forest Management Standard",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the PEFC Forest Management Standard necessitates a holistic and verifiable approach to sustainable forestry operations. A core requirement is the existence of a comprehensive, up-to-date forest management plan that is actively used. Sustainable harvesting practices are mandatory, stipulating the rate of harvest must not exceed the long-term calculated Mean Annual Increment (MAI), thereby ensuring forest regeneration. Environmental stewardship is further demonstrated through a documented plan to maintain, conserve, and enhance biodiversity, alongside operational measures protecting soil and water from erosion or pollution. The standard mandates a verifiable chain of custody system, compliant with PEFC ST 2002, to track certified material from forest to final sale. Social responsibilities are paramount, requiring a documented occupational health and safety program that adheres to local laws plus relevant ILO conventions, with a performance objective of maintaining an annual rate of recordable safety incidents below industry or national benchmarks. Furthermore, a formal policy recognizing and respecting the legal and customary rights of Indigenous Peoples is obligatory, complemented by a documented process for engaging with local communities and other stakeholders. Operational integrity demands chemical pesticide and herbicide use be minimized, justified, and meticulously recorded, while the use of genetically modified trees is explicitly prohibited within the certified area. Each criterion represents a non-negotiable component for achieving PEFC certification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-45001-health-safety",
      "iso-26000-social-resp"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pegi-pan-european-game-information-system",
    "title": "Pan European Game Information (PEGI) Rating System - Age Ratings, Content Descriptors, Online Label and Loot Box Labelling Requirements",
    "domain": "Gaming & Gambling",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The PEGI system mandates age classification (3, 7, 12, 16, 18) and content descriptors for video games distributed in 38+ European countries. It applies to all game publishers and distributors placing physical or digital games on the market, requiring compliance with PEGI's Code of Conduct, including labelling, online safety, and loot box disclosure per Section 3.1 and Annex A of the PEGI Codes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dsa-platform-obligations-gaming-2022",
      "eu-gdpr-online-gaming-data-protection",
      "belgium-gambling-act-1999-online-amendments",
      "esrb-entertainment-software-rating-board-us"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "pennsylvania-telehealth-2026",
    "title": "Pennsylvania Telehealth Licensure & Parity Requirements 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "Pennsylvania allows out-of-state providers to deliver telehealth under temporary registration with full licensure parity for reimbursement. 2026 updates strengthen audio-only coverage and data security standards aligned with HIPAA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "peppol-bis-billing-3-0-e-invoicing-standard",
    "title": "PEPPOL BIS Billing 3.0 - Pan-European E-Invoicing Standard",
    "domain": "Workflow Automation",
    "version": "3.0 (current, maintained by OpenPEPPOL)",
    "last_updated": "2026-05-09",
    "bluf": "PEPPOL BIS Billing 3.0 (Business Interoperability Specification) is the OpenPEPPOL standard for electronic invoicing and business document exchange across the PEPPOL Network; it defines the UBL 2.1 XML invoice schema, mandatory and optional field rules, VAT accounting rules, and the 4-corner eDelivery model (sender access point, PEPPOL SML/SMP directories, receiver access point) that underpins EU mandatory e-invoicing compliance and cross-border B2B/B2G invoice automation workflows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electronic-invoicing-directive-2014-55",
      "oasis-ws-bpel-2-0-web-service-orchestration"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "peru-environmental-protection-mining-law",
    "title": "Reglamento de Protección Ambiental para Actividades de Minería y Beneficio Minero, Decreto Supremo N° 014-92-EM",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires all mining operators in Peru to submit an Environmental Impact Study (EIA) or Environmental Management Programme (PMA) depending on project scale, establish financial assurance via remediation bonds, and comply with OEFA inspections under Article 11 and Article 27 of DS 014-92-EM. It applies to all exploration, exploitation, and beneficiation activities exceeding defined thresholds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eiti-standard-2023",
      "eu-mining-waste-directive-2006-21-ec"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "peru-general-mining-law-ds-014-92-em",
    "title": "Supreme Decree No. 014-92-EM: General Mining Law of Peru",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the legal framework for mineral exploration, exploitation, and environmental management in Peru, requiring mining concession holders to submit Environmental Management Plans (EMPs) and conduct prior consultation with indigenous communities under Article 7 of ILO Convention 169, as incorporated by Law No. 29785. It applies to all entities holding or seeking mining concessions within Peruvian territory.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "peru-legislative-decree-1350-2017-migraciones",
    "title": "Peru Legislative Decree 1350 de 2017 - Superintendencia Nacional de Migraciones Visa and Residency Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Legislative Decree 1350 of 2017 (Decreto Legislativo de Migraciones) and its implementing Regulation (Decreto Supremo 007-2017-IN) govern entry, residence, and departure of foreigners in Peru. The Superintendencia Nacional de Migraciones (Migraciones) under the Ministry of Interior (MININTER) administers all immigration matters. Peru's visa categories include: Tourist/Visitor (non-immigrant, up to 183 days), Special Residence Permit (calidades migratorias: Temporal, Residente, Especial), and Humanitarian Protection. Peru implemented the Permiso Temporal de Permanencia (PTP) for Venezuelan nationals in 2017-2021 (over 500,000 issued), and launched the Carnet de Solicitante de Refugio and the Calidad Migratoria Especial Humanitaria (CAMEH) in 2022 for continued Venezuelan protection. MERCOSUR nationals benefit from facilitated 2-year residence. The Carnet de Extranjeria is the mandatory identity document for resident foreigners. Overstay results in administrative sanction (multa) of UIT-based fines; deportation is a judicial-administrative process. Peru does not criminalise irregular migration. Migraciones digitalised many processes via SISCAM (Sistema de Control de Admision y Migracion) and the mi migraciones online portal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "mercosur_residency",
        "venezuelan_protection",
        "andean_community",
        "labour_code",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "pf-lil-2018",
    "title": "French Polynesia - Loi Informatique et Libertés (French Data Protection Law)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "French Polynesia is a French overseas collectivity (collectivité d'outre-mer) under its Organic Law of 27 February 2004. As an EU Overseas Country and Territory (OCT) rather than an EU outermost region, the EU General Data Protection Regulation (GDPR) does not directly apply in French Polynesia. However, the French Loi Informatique et Libertés (Law No. 78-17 of 6 January 1978 on data processing, files and freedoms) and its subsequent modifications, including alignment measures with GDPR principles introduced by Law No. 2018-493 of 20 June 2018, apply in French Polynesia through the principle of identity of legislation (identité législative) and specific legislative extension provisions. The Commission Nationale de l'Informatique et des Libertés (CNIL) exercises supervisory jurisdiction over data protection matters in French Polynesia. Organisations processing personal data in French Polynesia must comply with the French data protection framework as extended there: establishing a lawful basis for processing, respecting data subject rights (access, rectification, opposition), implementing security measures proportionate to the risks of processing, registering certain processing activities with CNIL where required, and notifying CNIL of personal data breaches. CNIL may conduct investigations and issue recommendations and sanctions for violations of French data protection law in French Polynesia.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/pf-lil-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pfmi-assessment-report-switzerland",
    "title": "Implementation monitoring of PFMI: Assessment report for Switzerland",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2019-01-01",
    "bluf": "In April 2012, the Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) issued the Principles for financial market infrastructures (PFMI). The Principles set expectations for the design and operation of key financial market infrastructures (FMIs) to enhance their safety and efficiency, limit systemic risk, and foster transparency and financial stability. This report presents the CPMI and IOSCO conclusions from a Level 2 assessment of whether the content of the legal, regulatory and oversight frameworks applied to systemically important payment systems, CSDs/SSSs, CCPs and TRs in Switzerland are complete and consistent with the Principles. The Principles apply to all systemically important payment systems (PSs), central securities depositories (CSDs), securities settlement systems (SSSs), central counterparties (CCPs) and trade repositories (TRs).\n\nThe authorities responsible for regulation, supervision and oversight of FMIs in Switzerland are the Federal Financial Markets Authority (FINMA) and the Swiss National Bank (SNB). FINMA has responsibility for all CCPs, CSDs/SSSs, TRs and wholesale payment systems (unless operated by or on behalf of the SNB). The SNB has responsibility for all CCPs, CSDs/SSSs and payment systems that it designates systemically important. This assessment reflects the status of Switzerland’s legal, regulatory and oversight framework as of 30 June 2017.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "principles-financial-market-infrastructures"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "pg-cca-2016",
    "title": "Papua New Guinea Cybercrime Code Act 2016 - Personal Data Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Papua New Guinea enacted the Cybercrime Code Act 2016, which establishes a comprehensive framework for addressing computer crimes including offences involving personal data held in electronic systems. The Act criminalises unauthorised access to computer systems and data, unlawful interception of computer data, data interference and destruction, computer-related fraud, and misuse of devices. The Papua New Guinea Constitution Section 49 establishes a constitutional right to privacy, protecting individuals from unreasonable entry on premises and interference with personal correspondence. The Cybercrime Code Act 2016 is administered by the Papua New Guinea Royal Constabulary Cybercrime Unit, with the National Information and Communications Technology Authority (NICTA) responsible for broader ICT regulatory oversight. Organisations operating digital systems in Papua New Guinea that process personal data must comply with the Cybercrime Code Act 2016 by implementing security controls preventing unauthorised access to personal data, preventing interception of data transmissions, maintaining data integrity, and preventing computer-related fraud involving personal information. Papua New Guinea does not currently have a standalone comprehensive personal data protection law, and the Cybercrime Code Act 2016 together with constitutional privacy protections represents the primary legal framework governing personal data security in digital systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/pg-cca-2016.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ph-amla-ra-9160-2001",
    "title": "Anti-Money Laundering Act of 2001 (Republic Act No. 9160)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Republic Act No. 9160, the Philippine Anti-Money Laundering Act of 2001, declares the State policy against money laundering (Section 2), defines covered institutions and transactions (Section 3), criminalizes money laundering (Section 4), creates the Anti-Money Laundering Council or AMLC (Section 7), and imposes customer identification, record-keeping and reporting duties on covered institutions (Section 9). Covered institutions must establish client identity, retain records for five years, and report covered transactions to the AMLC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "ph-cybercrime-prevention-act-2012",
    "title": "Philippines Cybercrime Prevention Act 2012 (Republic Act No. 10175)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Philippines Republic Act No. 10175 signed September 12, 2012 effective October 3, 2012 criminalises offences against the confidentiality, integrity, and availability of computer data and systems including illegal access, data interference, system interference, cybersquatting, cyber-libel, and online child sexual abuse material, establishes the Cybercrime Investigation and Coordinating Center, and mandates real-time traffic data collection and content interception capabilities for law enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ph-cybercrime-prevention-act-2012.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ph-dpa-2012"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ph-data-privacy-act-ra-10173",
    "title": "Philippines Republic Act 10173 - Data Privacy Act of 2012",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Republic Act No. 10173, the Data Privacy Act of 2012, is the principal Philippine personal data protection statute. The Act was approved on 15 August 2012 and entered into force on 8 September 2012. The Act is organised in nine Chapters. Chapter I (General Provisions) contains s. 3 definitions of personal information, sensitive personal information, personal information controller (PIC) and personal information processor (PIP), and s. 4 scope of application which is extraterritorial where the entity processes personal information of Philippine residents. Chapter II (s. 6 and following) establishes the National Privacy Commission (NPC) as the supervisory authority with rulemaking, investigative and enforcement powers. Chapter III (s. 11 General Data Privacy Principles of transparency, legitimate purpose and proportionality; s. 12 six lawful bases for processing personal information mirroring GDPR Art. 6; s. 13 stricter regime for sensitive personal information and privileged information including written consent) governs personal information processing. Chapter IV (s. 16) sets out data subject rights including the right to be informed, right to access, right to dispute and have data corrected, right to suspend and remove processed information, right to data portability and right to damages. Chapter V (s. 20 organisational, physical and technical security measures; s. 21 accountability for transfers including cross-border) governs security and accountability. Chapter VIII (ss. 25-33) establishes graduated criminal offences with imprisonment of 1-7 years and fines of PHP 500,000 to PHP 5 million; s. 33 combination of offences allows up to 7 years; data breach notification is required within 72 hours via NPC Circular 16-03.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-pdpa-2012",
      "thailand-pdpa-2019-personal-data-protection",
      "vn-decree-13-2023-personal-data-protection"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "ph-dpa-2012",
    "title": "Data Privacy Act of 2012 (Republic Act No. 10173)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Philippines Data Privacy Act of 2012 (DPA) governs the processing of all personal information, establishing the rights of data subjects and the obligations of personal information controllers (PICs) and processors (PIPs). As outlined in Section 11, all processing must adhere to the principles of transparency, legitimate purpose, and proportionality.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ph-npc-advisory-2024-04-ai-personal-data",
    "title": "Philippines NPC Advisory No. 2024-04 - Guidelines on Artificial Intelligence Systems Processing Personal Data, Issued 19 December 2024",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Personal Information Controllers (PICs) and Personal Information Processors (PIPs) in the Philippines developing, testing, training, or deploying AI technologies must comply with NPC Advisory No. 2024-04 issued by the National Privacy Commission on 19 December 2024 (Advisory Guidelines on the Application of the Data Privacy Act, its Implementing Rules and Regulations, and NPC Issuances to AI Systems Processing Personal Data) by adhering to general data privacy principles including accountability, transparency, and fairness, respecting data subject rights, identifying lawful bases under the DPA prior to processing personal data in AI development or deployment (including training and testing), implementing security measures, excluding by default any personal data unlikely to improve AI development or deployment, and recognising that PICs are strictly accountable for AI system outcomes regardless of whether processing was performed by a third-party AI provider.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "ph-republic-act-11363-philippine-space-act-2019",
    "title": "Philippine Space Act (RA 11363)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Republic Act No. 11363 establishes the Philippine Space Development and Utilization Policy around six Key Development Areas (Section 5), creates the Philippine Space Agency (PhilSA) as the central government agency for space science and technology applications (Section 6), and attaches PhilSA to the Office of the President (Section 9). PhilSA must maintain a National Registry of Space Objects launched under Philippine responsibility as the Launching State (Section 23), the Philippine Government takes responsibility for damages caused by space objects in that registry (Section 24), and the Act appropriates One billion pesos as the initial operating fund of PhilSA (Section 25). It applies to all Philippine space science and technology activities and to space objects for which the Philippines is the Launching State.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-registration-convention-1976-space",
      "un-liability-convention-1972-space-objects"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ph-republic-act-9184-government-procurement-reform-act-2003",
    "title": "Philippines Republic Act 9184 Government Procurement Reform Act of 2003 and its 2016 Revised IRR",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Philippines Republic Act 9184 known as the Government Procurement Reform Act enacted 10 January 2003 (effective 26 January 2003) and its 2016 Revised Implementing Rules and Regulations (Revised IRR) is the principal Philippine statute governing procurement of goods, infrastructure projects, and consulting services by all branches, agencies, departments, bureaus, offices, and instrumentalities of the Government including Government-Owned and Controlled Corporations (GOCCs), Government Financial Institutions (GFIs), State Universities and Colleges, and Local Government Units (LGUs). RA 9184 consolidated previously fragmented procurement regulations into a single statutory framework and established the Government Procurement Policy Board (GPPB) as the principal policymaking body under the Department of Budget and Management (DBM). The Philippine Government Electronic Procurement System (PhilGEPS / philgeps.gov.ph) operated by the Procurement Service of the DBM is the mandatory electronic procurement platform for in-scope procurement. RA 9184 procurement methods comprise (a) Competitive Bidding (the default open public bidding method), (b) Limited Source Bidding (selective bidding from a list of pre-qualified suppliers), (c) Direct Contracting (sole-source for goods of proprietary nature or critical components), (d) Repeat Order (procurement of additional quantities from a previous winning bidder), (e) Shopping (for readily available off-the-shelf goods below prescribed thresholds), (f) Negotiated Procurement (under specifically defined exceptions including emergency, two-failed-biddings, small-value, and adjacent-or-related-contracts), and (g) for infrastructure - alternative methods under the 2016 Revised IRR. The 2016 Revised IRR introduced strengthened integrity provisions including the Pre-Qualification Bids and Awards Committee (BAC) procedure, the Approved Budget for the Contract (ABC) ceiling, the Annual Procurement Plan (APP), supplier blacklisting under GPPB Resolution No. 02-2017, and mandatory PhilGEPS posting. The Philippine procurement framework operates within the country's trade obligations under the ASEAN Framework Agreement on Services and RCEP. The Philippines is NOT a party to the WTO GPA. Philippine Senate Bill No. 2593 (New Government Procurement Act) was signed into law as Republic Act 12009 on 20 July 2024 (effective 16 August 2024) modernising RA 9184; transitional rules are in force as both statutes operate during the migration period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "ph-data-privacy-act-ra-10173",
      "ph-cybercrime-prevention-act-2012",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "pharmacovigilance-ai-signal-detection-2026",
    "title": "AI Signal Detection in Pharmacovigilance - FDA/EMA Best Practices 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "Detailed framework for validation, qualification, and ongoing performance monitoring of AI/ML systems used for adverse event signal detection, case processing, and aggregate reporting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "pharmacovigilance-ich-e2e-2026",
    "title": "ICH E2E Pharmacovigilance Planning & Global Pharmacovigilance Obligations (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "ICH E2E and related guidelines establish international standards for pharmacovigilance planning, risk management plans (RMPs), signal detection, periodic benefit-risk evaluation reports (PBRERs), and post-authorisation safety studies. Manufacturers and marketing authorisation holders must maintain robust pharmacovigilance systems, including global safety databases and timely reporting of adverse events.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-e6-r3-gcp-2026"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "philippines-consumer-act-ra-7394-1992",
    "title": "Philippines Consumer Act (Republic Act 7394, 1992) - DTI Consumer Protection and Product Safety",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Republic Act 7394 (Consumer Act of the Philippines, 1992) establishes comprehensive consumer protection covering product quality and safety, deceptive and unfair sales acts, service warranties, and credit transactions; enforced by the Department of Trade and Industry (DTI), Food and Drug Administration (FDA), and Department of Agriculture (DA); with criminal penalties of 6 months to 1 year imprisonment and fines of PHP 500-PHP 300,000; and mandated minimum warranties of 60 days for consumer goods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "philippines-data-privacy-act-2012-ra-10173"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "philippines-cybercrime-prevention-act-2012-ra-10175",
    "title": "Cybercrime Prevention Act of 2012",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Act criminalizes illegal access, data interference, system interference, and misuse of devices in computer systems or networks, and establishes procedures for real-time data collection and preservation. It applies to all individuals and entities operating within the Philippines or targeting Philippine systems under Section 3 and Chapter II offenses.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "budapest-convention-cybercrime-2001",
      "aicpa-soc2-cc-confidentiality",
      "assessing-security-privacy-controls"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "philippines-data-privacy-act-2012-ra-10173",
    "title": "Republic Act No. 10173: An Act Protecting Individual Personal Information in Information and Communications Systems in the Government and the Private Sector, Creating for this Purpose a National Privacy Commission, and for Other Purposes (Data Privacy Act of 2012)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Philippines Data Privacy Act of 2012 (DPA) requires personal information controllers (PICs) and processors (PIPs) to implement organizational, physical, and technical security measures for data protection. Under Section 20(f), PICs must notify the National Privacy Commission (NPC) and affected data subjects of a personal data breach within 72 hours of discovery.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-37-dpo",
      "gdpr-article-35-dpia",
      "iso-27701-privacy-information-management",
      "apec-cbpr-system-2011"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "philippines-epira-2001-electricity-market",
    "title": "Philippines EPIRA 2001 - Electric Power Industry Reform Act (Republic Act 9136)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Republic Act 9136 (EPIRA, 2001) restructured the Philippine electricity industry by privatising the National Power Corporation (NPC), establishing a competitive wholesale electricity spot market (WESM), creating the Energy Regulatory Commission (ERC) as independent regulator, and mandating open access and retail competition for contestable customers (demand >1 MW), with electricity generation and supply licensed by ERC under the DOE's energy policy framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vietnam-electricity-law-2022",
      "india-electricity-amendment-act-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "philippines-fda-samd-2026",
    "title": "Philippines FDA SaMD & Digital Health Registration Framework 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "Philippine FDA aligns with ASEAN MDD and IMDRF for SaMD classification. 2026 updates introduce reliance pathways on reference regulators and mandatory cybersecurity assessments for connected devices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "philippines-immigration-act-1940-commonwealth-act-613-bi",
    "title": "Philippines Immigration Act of 1940 (Commonwealth Act 613) - Bureau of Immigration Visa and Residency Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The Philippine Immigration Act of 1940 (Commonwealth Act No. 613) is the Philippines' foundational immigration statute, establishing the Bureau of Immigration (BI) under the Department of Justice (DOJ). The Act classifies aliens as immigrants (Section 13 immigrant visa holders), non-immigrants (temporary stay under Section 9), and special non-immigrants (Section 47). The Special Resident Retiree's Visa (SRRV) is administered by the Philippine Retirement Authority (PRA). Foreign nationals residing in the Philippines must hold an Alien Certificate of Registration Identity Card (ACR I-Card) for stays beyond 59 days. The Philippines Issues 9(g) Pre-Arranged Employee visas for foreign workers. The 9(a) Temporary Visitor's Visa is the most common entry category. The Philippines operates a blacklist system for aliens prohibited from entry. The BI has authority to arrest and deport aliens for violations of immigration law. Overstaying aliens are subject to fines and deportation. The Alien Employment Permit (AEP) from DOLE is required for foreign nationals working in the Philippines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "dole_aep",
        "pra_srrv",
        "dost_working_visa",
        "asean_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "philippines-marina-merchant-shipping-act-pd-474",
    "title": "Philippines Maritime Industry Authority Act PD 474 - MARINA Vessel Registration, Manning and Seafarer Certification",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Maritime Industry Authority (MARINA) was established under Presidential Decree (PD) 474 (1974) as the primary government body regulating the Philippine maritime industry; Republic Act 9295 (Domestic Shipping Development Act of 2004) expanded MARINA's authority over domestic shipping operators; MARINA regulates: vessel registration and documentation (Philippine Ship Registry), issuance of Certificates of Public Convenience (CPC) for domestic commercial operators, seaworthiness inspection, manning certification, and minimum safe manning standards; under PD 474 Section 6, MARINA may suspend or cancel certificates for violations; Filipino seafarers deployed overseas must obtain a Seafarers' Identity Record Book (SIRB) from MARINA and an Overseas Employment Certificate (OEC) from the Department of Migrant Workers (DMW); STCW compliance is enforced by MARINA under RA 10635 (2014) amending the MARINA Act; penalty for operating without MARINA certification: fine up to PHP 200,000 plus vessel seizure; MARINA Memorandum Circular 2016-10 implements ILO Maritime Labour Convention (MLC) 2006 for domestic seafarers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-mlc-2006",
      "imo-stcw-convention-1978-2010-manila"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "philippines-pagcor-charter-pd-1869",
    "title": "Presidential Decree No. 1869, as Amended: Charter of the Philippine Amusement and Gaming Corporation (PAGCOR)",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes PAGCOR as the sole government authority for licensing and regulating gaming operations in the Philippines, including land-based and online gaming (PIGO). It mandates that all operators under PAGCOR must remit a minimum of 30% of gross gaming revenue as franchise tax under Section 5, as amended by Republic Act No. 11277.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "philippines-pagcor-presidential-decree-1869-charter",
    "title": "Philippines PAGCOR Charter - Presidential Decree 1869 Casino and Gaming Licensing Framework",
    "domain": "Gaming & Gambling",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The Philippine Amusement and Gaming Corporation (PAGCOR) was established by Presidential Decree No. 1869 of 1983 (as amended by Republic Act No. 9487 of 2007), which granted PAGCOR a franchise to operate and licence casinos and other games of chance throughout the Philippines. PAGCOR exercises dual roles: it operates its own casino facilities (Casino Filipino network) and acts as the licensing authority for private casino operators (licensed gaming casinos, LGCs) and electronic gaming sites (EGS). PAGCOR is a government-owned and controlled corporation (GOCC) under the Office of the President. Philippine Offshore Gaming Operators (POGOs) - online gambling platforms targeting overseas players - operate under PAGCOR regulation with offshore licensing requirements. In 2024, the Philippine government announced the phase-out of POGO licences amid AML and social order concerns. PAGCOR income is remitted to the national government and earmarked for social programmes. AML obligations under Republic Act No. 9160 (Anti-Money Laundering Act, AMLA) apply to all PAGCOR-licensed casinos.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "aml",
        "fatf_recommendation",
        "pogo_policy",
        "data_privacy",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "pic-s-pe009-17-gmp-guide-medicinal-products",
    "title": "PIC/S Guide to Good Manufacturing Practice for Medicinal Products Part I, Part II and Annexes (PE 009-17)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This guide establishes harmonized Good Manufacturing Practice (GMP) standards for medicinal products and active pharmaceutical ingredients (APIs), requiring manufacturers to implement a comprehensive Pharmaceutical Quality System (PQS) as detailed in Chapter 1, ensuring products are consistently produced and controlled to the quality standards appropriate for their intended use and marketing authorization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "pk-aml-act-2010",
    "title": "Pakistan Anti-Money Laundering Act 2010 (as amended up to 2020)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-18",
    "bluf": "Pakistan's Anti-Money Laundering Act 2010 (as amended in 2020) defines the offence of money laundering (Section 3), establishes the Financial Monitoring Unit (Section 6), and requires reporting entities to apply customer due diligence (Section 7A), file suspicious transaction reports and currency transaction reports with the FMU (Section 7), keep transaction records for at least five years and STR/CTR records for at least ten years (Section 7C), and comply with asset-freezing orders (Section 8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pk-peca-2016",
    "title": "Pakistan Prevention of Electronic Crimes Act 2016 (PECA) - Cybercrime Law",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Prevention of Electronic Crimes Act 2016 (PECA), enacted on 18 August 2016 (published in the Gazette of Pakistan, Extraordinary, dated 19 August 2016), is Pakistan's comprehensive cybercrime legislation administered jointly by the Federal Investigation Agency (FIA) Cybercrime Wing and the Pakistan Telecommunication Authority (PTA). The PECA establishes criminal offences, penalties, and procedural law for electronic crimes committed within Pakistan or against Pakistani citizens or infrastructure. Key offences: (1) Unauthorized access to information system (s. 3): imprisonment up to 3 months and/or fine up to PKR 50,000; (2) Unauthorized copying or transmission of data (s. 4): imprisonment up to 6 months and/or fine up to PKR 100,000; (3) Interference with information system (s. 5): imprisonment up to 2 years and/or fine up to PKR 500,000; (4) Electronic fraud (s. 14): imprisonment up to 2 years and/or fine up to PKR 10 million; (5) Data damage (s. 6): imprisonment up to 3 years and/or fine up to PKR 1 million; (6) Cyber terrorism (s. 10): imprisonment up to 14 years where electronic crimes are designed or likely to cause serious violence, endanger life, or damage critical infrastructure; (7) Hate speech (s. 11): imprisonment up to 5 years and/or fine up to PKR 10 million for transmitting content inciting violence against a group based on religion, ethnicity, or similar grounds; (8) Cyberstalking (s. 24): imprisonment up to 3 years and/or fine up to PKR 1 million; (9) Online grooming (s. 22): imprisonment up to 7 years and/or fine up to PKR 5 million. Blocking powers: s. 37 grants the PTA broad powers to remove or block online content that is unlawful, immoral, against public order, or against Islam - this provision has been widely used to restrict access to platforms and social media content. Critical information infrastructure protection: the PECA designates certain systems as critical information infrastructure (CII); attacks on CII carry enhanced penalties under s. 9 (imprisonment up to 7 years). Digital forensics: the PECA provides investigative powers including production orders for subscriber information, traffic data, and stored content, as well as interception orders for real-time communication data. Data retention: service providers are required to retain traffic data and subscriber information for a prescribed period. Amendments: the PECA was amended by the Prevention of Electronic Crimes (Amendment) Act 2022, which expanded scope and modified certain provisions; a further Amendment Act 2023 introduced additional provisions relating to online misinformation and disinformation. Jurisdictional reach: the PECA applies to offences committed in Pakistan and to offences outside Pakistan that affect Pakistani citizens, infrastructure, or data systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "pk-ppra-public-procurement-rules-2004-ordinance-2002",
    "title": "Pakistan Public Procurement Regulatory Authority Ordinance 2002 and Public Procurement Rules 2004",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Pakistan Public Procurement Regulatory Authority (PPRA) Ordinance 2002 (Ordinance No. XXII of 2002) and the Public Procurement Rules 2004 issued thereunder are the principal Pakistani federal legal instruments governing procurement of goods, services, and works by federal procuring agencies including federal ministries, federal divisions, attached departments, subordinate offices, public sector companies, autonomous bodies, statutory bodies, and federally-controlled corporations. The PPRA Ordinance 2002 established the Public Procurement Regulatory Authority (PPRA) as an autonomous body under the Ministry of Finance to regulate federal procurement and to monitor procurement compliance. The Public Procurement Rules 2004 issued under the PPRA Ordinance prescribe the procedural framework. The Pakistan Electronic Procurement System (e-PADS / eprocure.gov.pk) is the federal e-procurement platform. Procurement methods established by the Public Procurement Rules 2004 comprise (a) Open Competitive Bidding (Rule 36, the default method - single stage one envelope, single stage two envelopes, two stage, or two stage two envelopes), (b) Limited Tendering (Rule 22, where Open Competitive Bidding is not feasible), (c) Request for Quotations (Rule 42, for items below prescribed value thresholds), (d) Direct Contracting (Rule 42, sole-source under prescribed exceptions including emergency, sole supplier, repeat orders, and specialised services), and (e) Negotiated Tendering (under prescribed exceptions). The PPRA framework operates within Pakistan's trade obligations under SAFTA (South Asian Free Trade Area), and Pakistan is NOT a party to the WTO Government Procurement Agreement (GPA). Provincial procurement is governed by parallel provincial procurement regulatory authorities including the Sindh Public Procurement Regulatory Authority (SPPRA, Sindh PPRA Act 2009), the Punjab Procurement Regulatory Authority (PPRA Punjab, Punjab Procurement Regulatory Authority Act 2009 and 2014 Punjab Procurement Rules), the Khyber Pakhtunkhwa Public Procurement Regulatory Authority (KPPRA, KPPRA Act 2012), and the Balochistan Public Procurement Regulatory Authority (BPPRA, BPPRA Act 2009).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "pk-peca-2016",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "pl-prawo-zamowien-publicznych-pzp-2019-effective-2021",
    "title": "Poland Public Procurement Law (Prawo zamowien publicznych, Pzp) Act of 11 September 2019 effective 1 January 2021",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Polish Public Procurement Law (Prawo zamowien publicznych, Pzp) Act of 11 September 2019 (Ustawa z dnia 11 wrzesnia 2019 r. - Prawo zamowien publicznych, published in Dz. U. 2019 poz. 2019) effective 1 January 2021 is the principal Polish statute governing procurement of goods, services, and construction works by contracting authorities including central government administration, local self-government units, public-sector entities, public utilities, and other entities subject to the procurement obligations. The 2019 Pzp replaced the prior Public Procurement Law of 29 January 2004 (Pzp 2004) and substantially modernised the Polish procurement regime to align with the EU procurement directives 2014/24/EU (classical), 2014/25/EU (utilities), 2014/23/EU (concessions), and 2009/81/EC (defence and security). The 2019 Pzp introduced reforms including (a) consolidation of the procurement regime in a single statute, (b) emphasis on quality-focused award criteria (najkorzystniejsza oferta) considering price, quality, and life-cycle costs, (c) mandatory electronic procurement through the centralised e-zamowienia platform (ezamowienia.gov.pl) operated by the Public Procurement Office (Urzad Zamowien Publicznych / UZP), (d) strengthened SME participation provisions including the SME-friendly contracting principles, (e) competitive dialogue and innovation partnership procurement methods, (f) strengthened debarment regime and integrity provisions, and (g) sustainable procurement criteria including environmental and social criteria. The Public Procurement Office (Urzad Zamowien Publicznych / UZP) is the central regulatory authority with rule-making, complaint resolution, and procurement guidance authority. The National Appeals Chamber (Krajowa Izba Odwolawcza / KIO) is the specialised tribunal for procurement appeals. Procurement methods established by the Pzp 2019 comprise (a) Open Tender (przetarg nieograniczony, default), (b) Restricted Tender (przetarg ograniczony, with prequalification), (c) Negotiated Procedure with Publication (negocjacje z ogloszeniem), (d) Negotiated Procedure without Publication (negocjacje bez ogloszenia, under prescribed exceptions), (e) Competitive Dialogue (dialog konkurencyjny), (f) Innovation Partnership (partnerstwo innowacyjne), (g) Single-source Procurement (zamowienie z wolnej reki, sole-source under prescribed exceptions), and (h) Electronic Auction (licytacja elektroniczna). Poland is a party to the WTO Government Procurement Agreement (GPA) 2012 through the European Union and operates within the broader EU procurement framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "eu-public-procurement-directive-2014-24-construction",
      "eu-directive-2014-25-utilities-procurement",
      "pl-uodo-2018"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "pl-uodo-2018",
    "title": "Poland Personal Data Protection Act 2018 (Ustawa o ochronie danych osobowych) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Poland's Personal Data Protection Act (Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych, Dz.U. 2018 poz. 1000, enacted 10 May 2018, entered into force 25 May 2018) is Poland's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Poland. The GDPR is directly applicable Polish law by virtue of Poland's EU membership. The Ustawa o ochronie danych osobowych provides the national derogations, additions, and specifications that the GDPR permits EU member states to adopt. Enforcement: Urząd Ochrony Danych Osobowych (UODO - Office for Personal Data Protection) is Poland's independent data protection supervisory authority, headed by the President of UODO (Prezes UODO). UODO is Poland's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Polish national provisions: (1) Age of digital consent: Poland has maintained the GDPR default age of 16 years for information society services - the age of consent in Poland is 16 years; data subjects under 16 require parental or guardian consent for information society services; (2) Scientific research, statistics, and public interest: specific provisions permitting extended processing for scientific research, statistics, and archiving in the public interest, including extended retention periods and exemptions from certain data subject rights; (3) Employment context: Polish data protection law interacts with the Polish Labour Code (Kodeks Pracy) - employers in Poland may process employee personal data only for specified employment purposes; employee biometric data (fingerprints for access control) requires written consent; monitoring of employee emails and workplace is permitted within strict limitations under the Labour Code (amendments effective 4 May 2019); (4) Freedom of expression: provisions for journalistic, artistic, and literary processing in accordance with freedom of expression rights under the Polish Constitution (Konstytucja Rzeczypospolitej Polskiej); (5) Criminal data: restrictions on processing personal data relating to criminal convictions and offences by private entities; (6) Certifications and codes of conduct: UODO is authorised to accredit certification bodies and approve codes of conduct as provided by the GDPR. Fines: GDPR administrative fines apply in Poland - up to EUR 20 million or 4% of global annual turnover for the most serious violations. UODO has imposed significant GDPR fines including enforcement actions against a credit information bureau for failing to inform data subjects about processing, against e-commerce platforms for inadequate data security, and against healthcare providers, public bodies, and digital platforms. The Polish government and UODO have been actively engaged in GDPR enforcement, particularly in the areas of data scraping, direct marketing, and employment data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pm-lil-framework",
    "title": "Saint Pierre and Miquelon - French Data Protection Law (Loi Informatique et Libertés) Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Saint Pierre and Miquelon is a French territorial collectivity located in the North Atlantic Ocean south of the Canadian province of Newfoundland and Labrador. It is the only remaining French territory in continental North America. Saint Pierre and Miquelon is not an EU outermost region and not an EU Overseas Country and Territory (OCT) - it has a sui generis status as a French territorial collectivity. Accordingly, the General Data Protection Regulation (GDPR) does not apply directly in Saint Pierre and Miquelon. The applicable data protection framework is the French Loi Informatique et Libertés (Law on Information Technology and Civil Liberties), which applies in Saint Pierre and Miquelon by extension of French sovereignty law. The Commission Nationale de l'Informatique et des Libertés (CNIL) exercises jurisdiction as the supervisory authority for data protection matters in Saint Pierre and Miquelon. The territory is governed by a Prefect appointed by the French government and has its own Territorial Council (Conseil territorial). Saint Pierre and Miquelon's proximity to Canada means that organisations operating cross-border may need to consider Canadian privacy law (PIPEDA and provincial equivalents) in addition to the applicable French data protection framework. Organisations processing personal data of individuals in Saint Pierre and Miquelon must comply with the Loi Informatique et Libertés as applicable in French overseas territories, implement appropriate technical and organisational security measures, and respect individual rights of access and rectification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/pm-lil-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "pmbok-7-guide-pm",
    "title": "PMBOK 7 (Project Guide)",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with the PMBOK 7 (Project Guide) node mandates a principles-based approach to project management, focusing on value delivery and adaptable governance. This framework requires the formal establishment of several key artifacts and processes to ensure project success and stakeholder alignment. A defined governance structure must be in place, complemented by an established team charter that clarifies roles and responsibilities. The project's tailoring approach needs to be thoroughly documented, demonstrating conscious adaptation of methodologies to fit the specific context. A complete stakeholder register is mandatory, ensuring all relevant parties are identified and managed. Central to this standard is a maintained risk register, which must undergo formal review at a frequency no less than every three months. To manage project evolution, a defined change control process is also required. Value realization is paramount, necessitating a defined value delivery plan and the continuous tracking of associated value metrics. Furthermore, comprehensive reporting that covers all performance domains is stipulated. To quantify progress against objectives, the framework sets a clear threshold: a minimum of 95 percent of all milestones must be associated with specific, measurable metrics. Adherence to these stipulations demonstrates a robust, adaptable, and value-focused project management capability consistent with modern standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-21502-project-mgt",
      "iso-21500-project-gov",
      "iso-31000-risk-mgt-std",
      "iso-9001-quality-mgt",
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pmi-code-ethics",
    "title": "PMI Code of Ethics",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the Project Management Institute Code of Ethics necessitates a rigorous adherence to four foundational values: Responsibility, Respect, Fairness, and Honesty, as mandated by governing professional conduct standards. This framework requires that the designated project manager is certified and upholds a duty of ownership, which is verified through a completed project impact assessment and strict adherence to the established confidentiality protocol; furthermore, all intellectual property rights must be formally acknowledged. The principle of Respect is substantiated once every team member has acknowledged the anti-harassment policy, thereby fostering a safe and professional environment. Fairness is demonstrated through procurement criteria that is objective and the implementation of a clear conflict of interest policy, under which all conflict of interest disclosures are complete. To further ensure equity, an impartial dispute resolution mechanism must be available. The value of Honesty is upheld by ensuring project communications are truthful and that status reporting is transparent, providing an accurate understanding of performance. An accessible ethics escalation protocol must also be in place to address any violations, ensuring project activities are conducted with integrity and professionalism per the highest ethical obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-21500-project-mgt",
      "iso-31000-risk-mgt",
      "iso-37301-compliance",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "poland-act-on-foreigners-2013-urzad-ds-cudzoziemcow",
    "title": "Poland Act on Foreigners 2013 - Karta Pobytu and Schengen Residence Framework",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Poland's Act on Foreigners of 12 December 2013 (Ustawa z dnia 12 grudnia 2013 r. o cudzoziemcach, Dz.U. 2023 poz. 519 consolidated) governs third-country nationals entering and residing in Poland. The karta pobytu (residence card) is issued by Voivode (provincial governor) for temporary (3 years max) and permanent residence. Poland is a Schengen member; non-EU nationals may reside 90 days/180 without visa if visa-free or under Schengen visa. The Karta Polaka (Card of the Pole) grants facilitated residence to Poles abroad. As of 2022, temporary protection for Ukrainian war refugees is governed by the EU Temporary Protection Directive. Work permits are governed separately under Act of 20 April 2004 on employment promotion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "germany-residence-act-aufenthaltsgesetz-2004-bamf",
      "ukraine-law-on-legal-status-foreigners-3773-vi-2011"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "poland-gambling-law-2009-uoogg",
    "title": "Poland Gambling Act 2009 (Ustawa o grach hazardowych) - Ministry of Finance Online Licensing and AML Framework",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Poland's Gambling Act of 19 November 2009 (Dz.U. 2009 nr 201 poz. 1540, consolidated text Dz.U. 2023 poz. 227), as fundamentally amended in 2017 (Act of 15 December 2016), established a state-controlled framework with selective opening for online sports betting and poker licences issued by the Ministry of Finance; mandates player registration, blocking of unlicensed domains via the Register of Prohibited Domains (Article 15f), 12% GGR gambling tax, AML obligations under the Anti-Money Laundering Act, and responsible gambling requirements; criminal penalties apply for unlicensed operation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "poland-space-activities-act-2017",
    "title": "Poland Space Activities Act 2017 (Ustawa o Działalności Kosmicznej)",
    "domain": "Space & Satellite Law",
    "version": "2017-12",
    "last_updated": "2026-05-09",
    "bluf": "Poland's Space Activities Act 2017 establishes a national licensing regime for space activities including satellite operations and launch services, designating the Polish Space Agency (POLSA) as the national supervisory authority; the Act implements Poland's obligations under the UN Outer Space Treaty and Registration Convention and provides the legal basis for authorising Polish space entities as an EU and ESA member state.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967-article-i-freedom",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "port-facility-security-isps",
    "title": "ISPS Code: Port Facility Security",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with International Ship and Port Facility Security (ISPS) Code requirements for a port facility mandates a comprehensive security framework. A qualified Port Facility Security Officer (PFSO) must be designated and in place. A current Port Facility Security Assessment (PFSA) is foundational, requiring a thorough review at least within the last five years. Based on this assessment, a Port Facility Security Plan (PFSP) approved by the Contracting Government must be fully implemented. The facility must operate in accordance with its current operational security level, designated as 1, 2, or 3. Physical security measures are critical, including an established access control system for persons, vehicles, and vessels, alongside clearly identified and secured restricted areas to prevent unauthorized entry. Procedures to check cargo integrity and prevent tampering before and during handling are non-negotiable. Continuous oversight is achieved through an effective security monitoring system, such as adequate lighting and surveillance equipment. To maintain operational readiness, all personnel with security duties must have current training records, with security drills occurring at a frequency not exceeding three months and comprehensive security exercises conducted within an eighteen-month interval. Finally, a formal process must exist for completing a Declaration of Security with a ship when required to effectively manage ship-port interface security risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "isps-code-vessel-security",
      "iso-28000-supply-chain",
      "wco-safe-framework"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "portugal-space-activities-law-2019",
    "title": "Portugal Space Activities Law 2019 - Decreto-Lei n.º 16/2019 National Licensing Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Decreto-Lei n.º 16/2019 of 22 January 2019, published in Diário da República, 1.ª série, n.º 17, establishes Portugal's national legal framework for space activities, creating a licensing and authorisation regime for launches, in-orbit operations, and re-entry of space objects conducted by entities under Portuguese jurisdiction. The law designates the Agência Espacial Portuguesa (Portugal Space, formerly the Gabinete de Relações Internacionais do Ministério da Ciência e Tecnologia), as the national space authority responsible for licensing and national oversight. Portugal is an ESA Member State and the law aligns with Portugal's obligations under the UN Outer Space Treaty 1967, the Liability Convention 1972, and the Registration Convention 1976. The law introduces authorization requirements, liability and insurance obligations, and national registration of space objects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "un_outer_space_treaty_1967",
        "esa_framework",
        "eu_space_programme"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "portugal-srij-online-gambling-decree-66-2015",
    "title": "Portugal Decreto-Lei 66/2015 - Online Gambling Regulation (SRIJ)",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2015-04-29",
    "bluf": "Portugal's online gambling framework (DL 66/2015) authorises sports betting, casino games, and online poker under SRIJ licensing, with mandatory integration into the national self-exclusion register (RSJ), AML reporting to DCIAP, GGR taxes of 8-30% by game type, and LNE-equivalent technical certification requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021",
      "responsible-gambling-grb-standards-2023",
      "eu-5amld-article-2-gambling-2018",
      "eu-payment-services-directive-2-gaming-deposits"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "pqc-migration-logic",
    "title": "PQC Migration Workflow",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.2.0",
    "last_updated": "2026-06-14",
    "bluf": "The PQC Migration Workflow (based on NSA CNSA 2.0 and NIST PQC timelines) provides the strategic five-step transition from 'Classical' cryptography to 'Post-Quantum' (PQC) standards. It focuses on mitigating the 'Store-Now-Decrypt-Later' (SNDL) risk for high-longevity data and ensuring quantum-secure authenticated software updates (ASU).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-203-ml-kem-standard",
      "fips-204-ml-dsa-quantum",
      "fips-205-slh-dsa-quantum",
      "ietf-hybrid-pqc-drafts",
      "quantum-readiness-checklist",
      "nist-800-171-rev-3"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pr-framework",
    "title": "Puerto Rico - Federal and Territorial Privacy Rights Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Puerto Rico is an unincorporated organised territory of the United States located in the Caribbean. Puerto Rico has its own Constitution, which establishes a fundamental right to privacy and protection from unreasonable searches and seizures. US federal law applies to Puerto Rico in substantially the same manner as it applies to the 50 states. Accordingly, the primary federal privacy statutes - including the Health Insurance Portability and Accountability Act (HIPAA), the Children's Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), the Gramm-Leach-Bliley Act (GLBA), and the Federal Trade Commission Act - apply in Puerto Rico and govern the handling of personal data by organisations operating in the territory. The Federal Trade Commission exercises jurisdiction over unfair or deceptive acts or practices relating to personal data in Puerto Rico. Puerto Rico enacted the Right to Privacy Act of 1972 establishing a general right to privacy applicable to individuals and organisations, which supplements federal protections. Puerto Rico does not have a standalone comprehensive personal data protection law equivalent to the GDPR. Organisations processing personal data of individuals in Puerto Rico must comply with all applicable federal privacy statutes, the Puerto Rico Right to Privacy Act, and the Puerto Rico Constitution's privacy protections, as well as implement appropriate technical and organisational security measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/pr-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "pra-ss1-21-resilience",
    "title": "PRA SS1/21 (Resilience)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "PRA SS1/21 (Operational Resilience: Impact tolerances for important business services) is the UK's cornerstone standard for bank and insurer resilience. it shifts focus from traditional disaster recovery to ensuring that 'Important Business Services' (IBS) remain within set 'Impact Tolerances' during severe but plausible disruptions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "bcbs-principles-sound-management-operational-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "precision-medicine-genomic-governance-2026",
    "title": "Precision Medicine & Genomic Data Governance Framework (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Precision medicine and large-scale genomic data require specialized governance covering explicit consent for secondary use, data sharing agreements, re-identification risk mitigation, return of results policies, benefit sharing, and long-term data stewardship. Frameworks emphasize dynamic consent, federated analysis, and ethical oversight while enabling research and clinical care.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "prince2-7-framework-pm",
    "title": "PRINCE2 7 (Framework)",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with the PRINCE2 7 framework necessitates rigorous adherence to its integrated elements of principles, themes, processes, and the project environment. Governance requires that project board roles are explicitly defined and that the Project Initiation Documentation receives formal approval before proceeding. As detailed in the seventh edition manual, a project's structure must encompass a minimum of two management stages, ensuring controlled progression. A foundational requirement is the mandatory review of the business case at every stage boundary to validate continued viability. Project control mechanisms demand that tolerances are clearly defined for all primary objectives, and official guidance confirms that product descriptions must be available for all major products to ensure clarity of scope. The framework's adaptability is contingent upon a documented tailoring approach, demonstrating deliberate modification for the specific project context. Furthermore, formalized management approaches for both change and sustainability must be established and documented from the outset. Continuous improvement and risk management are evidenced by maintaining an active lessons log throughout the project lifecycle and a risk register containing at least one entry. Finally, to ensure outputs meet stakeholder expectations, a consistently maintained quality register is obligatory, tracking all planned quality management activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-21502-project-mgt",
      "pmbok-7-guide-pm",
      "iso-9001-quality-mgt",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "principles-effective-risk-data-aggregation",
    "title": "Principles for effective risk data aggregation and risk reporting",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2013-01-31",
    "bluf": "One of the most significant lessons learned from the global financial crisis that began in 2007 was that banks’ information technology (IT) and data architectures were inadequate to support the broad management of financial risks. Many banks lacked the ability to aggregate risk exposures and identify concentrations quickly and accurately at the bank group level, across business lines and between legal entities. This had severe consequences to the banks themselves and to the stability of the financial system as a whole. In response, the Basel Committee presents a set of principles to strengthen banks’ risk data aggregation capabilities and internal risk reporting practices.\n\nInitially addressed to global systemically important banks (G-SIBs), these Principles are expected to support a bank’s efforts to enhance the infrastructure for reporting key information used by the board and senior management, improve the decision-making process, facilitate a comprehensive assessment of risk exposures at the global consolidated level, and reduce the probability and severity of losses. The document covers four closely related topics: Overarching governance and infrastructure, Risk data aggregation capabilities, Risk reporting practices, and Supervisory review. The long-term benefits of improved risk data aggregation capabilities and risk reporting practices are expected to outweigh the investment costs incurred by banks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-committee-financial-crisis-response",
      "basel-iii-global-regulatory-framework",
      "bcbs-principles-sound-management-operational-risk",
      "bcbs-sound-stress-testing-practices"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "principles-financial-market-infrastructures",
    "title": "Principles for financial market infrastructures",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2012-04-01",
    "bluf": "These principles establish international standards for financial market infrastructures (FMIs) that facilitate the clearing, settlement, and recording of monetary and other financial transactions. The standards apply to systemically important payment systems (PSs), central securities depositories (CSDs), securities settlement systems (SSSs), central counterparties (CCPs), and trade repositories (TRs). The presumption is that all CSDs, SSSs, CCPs, and TRs are systemically important. If not properly managed, FMIs can be sources of financial shocks, such as liquidity dislocations and credit losses, or a major channel through which these shocks are transmitted across financial markets.\n\nThe core obligation for FMIs is to enhance safety and efficiency, limit systemic risk, and foster transparency and financial stability. FMIs must have a well-founded, clear, transparent, and enforceable legal basis; clear governance arrangements; and a sound risk-management framework for comprehensively managing legal, credit, liquidity, operational, and other risks. The principles address specific minimum requirements for managing these risks, such as maintaining sufficient financial resources to cover credit exposures from participant defaults under extreme but plausible market conditions. The report outlines 24 principles covering general organization, credit and liquidity risk management, settlement, default management, business and operational risk, access, efficiency, and transparency, which are designed to be applied holistically as a set.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-committee-response-financial-crisis",
      "bcbs-principles-operational-resilience",
      "bcbs-sound-liquidity-risk-management",
      "cpmi-iosco-cyber-resilience-fmi"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "principles-for-operational-resilience",
    "title": "Principles for Operational Resilience",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2021-03-31",
    "bluf": "This document promotes a principles-based approach to improving operational resilience for banks, building upon the Basel Committee's Principles for the Sound Management of Operational Risk (PSMOR). It defines operational resilience as the ability of a bank to deliver critical operations through disruption. This ability enables a bank to identify and protect itself from threats and potential failures, respond and adapt to, as well as recover and learn from disruptive events in order to minimise their impact. The principles apply to banks and aim to strengthen their ability to absorb operational risk-related events such as pandemics, cyber incidents, technology failures, and natural disasters, which could cause significant operational failures or wide-scale disruptions.\n\nThe core obligation is for banks to establish an effective operational resilience approach that assumes disruptions will occur and takes into account the bank's overall risk appetite and tolerance for disruption. A bank's tolerance for disruption is defined as the level of disruption from any type of operational risk a bank is willing to accept given a range of severe but plausible scenarios. The principles are organized across seven categories: governance, operational risk management, business continuity planning and testing, mapping interconnections and interdependencies, third-party dependency management, incident management, and resilient information and communication technology (ICT) including cyber security. These practices are intended to be integral parts of a bank's forward-looking operational resilience approach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-sound-management-operational-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "private-fund-advisers-compliance-reviews",
    "title": "Private Fund Advisers; Documentation of Registered Investment Adviser Compliance Reviews",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2023-11-13",
    "bluf": "The Securities and Exchange Commission is adopting new rules under the Investment Advisers Act of 1940 designed to protect investors who directly or indirectly invest in private funds. The rules aim to increase visibility into practices involving compensation schemes, sales practices, and conflicts of interest through disclosure; establish requirements to address such practices that have the potential to lead to investor harm; and restrict practices that are contrary to the public interest and the protection of investors. These rules apply to private fund advisers, with certain amendments affecting all registered investment advisers, and are intended to prevent fraud, deception, or manipulation.\n\nThe core obligations include: a Quarterly Statement Rule requiring periodic information about fees, expenses, and performance; a Mandatory Audit Rule requiring an annual audit for each private fund; an Adviser-led Secondaries Rule requiring a fairness or valuation opinion for such transactions; a Restricted Activities Rule that limits certain expense charges and other activities without appropriate disclosure and consent; and a Preferential Treatment Rule that prohibits certain types of preferential terms and requires disclosure of others. The rules also amend the Advisers Act compliance rule to require all registered investment advisers to document their annual compliance reviews in writing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "finra-3110-supervision",
      "safeguarding-advisory-client-assets",
      "sec-regulation-best-interest"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "process-mining-pm4py-ieee-standard",
    "title": "IEEE/ISO/IEC 14515-1-2000 -- Information Technology -- Portable Operating System Interface (POSIX) -- Test methods for measuring conformance to POSIX -- Part 1: System interfaces",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This standard defines the requirements for test methods used to verify conformance to POSIX.1 (ISO/IEC 9945-1:1990), specifying a POSIX.1-ordered list of assertions and associated test methods that must be applied by test suite providers and implementors. It applies to organizations developing or validating POSIX-compliant systems, particularly in portable application environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "project-aurum-cbdc-prototype",
    "title": "Project Aurum A Prototype for Two-tier Central Bank Digital Currency (CBDC)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2022-10-31",
    "bluf": "Project Aurum, a joint project by the Bank for International Settlements (BIS) Innovation Hub Hong Kong Centre and the Hong Kong Monetary Authority (HKMA), details the creation of a full-stack central bank digital currency (CBDC) system prototype. The system is built on the premise that a digital currency issued by a central bank must be as robust and trustworthy as gold. It features a two-tier technology stack comprising a wholesale interbank system, where wholesale CBDC (wCBDC) is issued to banks, and a retail e-wallet system, where retail CBDC (rCBDC) circulates among users. The project's goal was to bring to life two different types of retail tokens: intermediated CBDC (referred to as CBDC-tokens) and CBDC-backed stablecoins.\n\nThe system's design is guided by principles of safety, flexibility, and privacy. A key architectural feature is the separation of the wholesale and retail systems, which ensures the central bank does not access retail users' personal data, preserving privacy. The prototype utilizes an unspent transaction output (UTXO) model and a validator mechanism to prevent risks like over-issuance and double-spending. The Aurum system, along with its source code and technical manuals, is made accessible to all BIS central bank members to serve as a public good and further the global study of rCBDC architectures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "bcbs-fintech-sound-practices",
      "security-considerations-system-development-lifecycle",
      "nist-sp-800-208-stateful-hbs"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "protecting-subscriber-identifiers-suci",
    "title": "Protecting Subscriber Identifiers with Subscription Concealed Identifier (SUCI)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-03-01",
    "bluf": "This white paper describes how Subscription Concealed Identifier (SUCI) protection can be enabled in 5G networks as an optional security capability defined by 5G standards. It addresses the problem of the Subscription Permanent Identifier (SUPI) being sent in the clear over the air, which allows eavesdroppers to intercept it, track a subscriber's location, and pose cybersecurity and privacy risks. The SUCI capability addresses this by encrypting the SUPI with the public key of the home operator. The resulting ciphered identity is always unique and cannot be correlated to the subscriber by an attacker.\n\nThe guidance applies to technology, cybersecurity, and privacy professionals involved in 5G-enabled services, including private 5G network operators, commercial mobile network operators, and end-user organizations. The core obligation for network operators is to enable SUCI on their 5G networks and subscriber SIMs, and crucially, to configure SUCI to use a non-null encryption cipher scheme. If a null scheme is used, the SUPI is not actually encrypted. 5G devices and network functions compliant with 3GPP release 15 or later are required to support the SUCI capability, but enabling it is optional for network operators, who should evaluate the risks of not enabling this critical capability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cswp-36-5g-cybersecurity-capabilities",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "prsa-code-of-ethics",
    "title": "PRSA (Code of Ethics)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The PRSA Code of Ethics identifies the foundational standards for the Public Relations (PR) professionals. it specifies the '6 Core Values' (Advocacy, Honesty, Expertise, Independence, Loyalty, Fairness) and the '6 Code Provisions' (Free Flow of Information, Disclosure of Information, Confidences, Conflict of Interest, etc.), ensuring the PR activities the maintain the high-trust and the organizational integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-endorsement-guides",
      "global-alliance-pr-ethics"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "prudential-treatment-cryptoasset-exposures",
    "title": "Prudential treatment of cryptoasset exposures",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2021-06-01",
    "bluf": "This consultative document from the Basel Committee on Banking Supervision proposes a prudential framework for banks' exposures to cryptoassets, addressing potential financial stability concerns and increased risks. The framework is guided by the principles of 'same risk, same activity, same treatment,' simplicity, and the establishment of minimum standards for internationally active banks. The core of the proposal is a classification system that divides cryptoassets into two groups. Group 1 cryptoassets, which meet a series of strict classification conditions, include tokenised traditional assets (Group 1a) and cryptoassets with effective stabilisation mechanisms (Group 1b). These are subject to capital requirements at least equivalent to those of traditional assets. Group 2 cryptoassets, such as Bitcoin, fail to meet these conditions and are consequently subject to a new, conservative prudential treatment, notably a 1250% risk weight.\n\nThe document outlines banks' responsibilities for assessing and monitoring compliance with classification conditions, subject to supervisory review and approval. It also details the application of capital requirements for credit and market risk for both groups, as well as the treatment of cryptoasset exposures under the leverage ratio, large exposures, and liquidity ratio frameworks. It establishes that cryptoassets are not eligible as high-quality liquid assets (HQLA). Finally, it sets out expectations for the supervisory review process, where banks must manage risks not captured by minimum requirements, and supervisors may impose adjustments, including additional capital charges.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "fatf-guidance-virtual-assets-vasp",
      "fundamental-review-of-the-trading-book",
      "principles-effective-risk-data-aggregation"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "ps-etl-2019",
    "title": "Palestine Electronic Transactions Law No. 15 of 2019 - Personal Data Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Palestinian Authority enacted the Electronic Transactions Law No. 15 of 2019, which includes provisions for the protection of personal data processed in electronic transactions and digital services. The law is administered by the Ministry of Telecommunications and Information Technology (MTIT) of the Palestinian Authority. It establishes obligations for electronic service providers to protect the personal information of users from unauthorised access and disclosure, requires informed consent before collecting personal data for purposes beyond the provision of the requested service, mandates security measures to protect electronic personal data, and provides for liability for breaches of personal data confidentiality. The law represents the Palestinian Authority's foundational digital governance framework including personal data protection elements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ps-etl-2019.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "psd2-article-98-strong-customer-authentication-rts",
    "title": "PSD2 Article 98 Strong Customer Authentication and Secure Open Standards RTS",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "PSD2 Article 98 mandated EBA to develop Regulatory Technical Standards on strong customer authentication (SCA) and secure open standards for payment service provider communication, implemented via Commission Delegated Regulation (EU) 2018/389, requiring two-factor authentication combining knowledge, possession, and inherence elements with dynamic linking for payment initiation and defined exemptions for low-risk transactions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "psd2-directive-article-63-strong-customer-authentication-scope",
      "psd2-directive-article-66-liability-of-payment-service-providers"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "psd2-directive-article-4-definitions",
    "title": "Directive (EU) 2015/2366 (PSD2) Article 4: Definitions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes key definitions for capital requirements, payment brands, and co-badging used within the directive, requiring organizations to classify their capital structure and payment instruments accordingly.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "psd2-directive-article-63-strong-customer-authentication-scope",
    "title": "DIRECTIVE (EU) 2015/2366 on payment services in the internal market - Article 63",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the requirement for payment service providers to apply strong customer authentication measures to enhance the security of electronic payments and protect consumers from fraud.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "psd2-directive-article-64-liability-unauthorized-transactions",
    "title": "DIRECTIVE (EU) 2015/2366 on payment services in the internal market - Article 64: Liability for unauthorised payment transactions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the liability framework for payment service providers and users concerning unauthorized payment transactions, mandating provider refunds unless payer fraud or gross negligence can be proven.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "psd2-directive-article-65-payers-liability",
    "title": "DIRECTIVE (EU) 2015/2366 on payment services in the internal market - Article 65: Liability for Unauthorised Transactions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the payer's limited liability for unauthorised payment transactions, capping it at a specified amount unless the payer acted fraudulently or with gross negligence, and outlines conditions under which the payer bears no liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "psd2-directive-article-66-liability-of-payment-service-providers",
    "title": "DIRECTIVE (EU) 2015/2366 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 25 November 2015 on payment services in the internal market - Article 66: Non-execution or defective or late execution of payment transactions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the liability of a payer's payment service provider (PSP) for non-executed, defective, or late payment transactions, mandating a refund and account restoration, and outlines the process for tracing transactions and transferring liability to the payee's PSP.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "psd2-directive-article-67-conditions-for-payment-initiation",
    "title": "Directive (EU) 2015/2366 on payment services in the internal market - Article 67: Rules on access to payment account in the case of payment initiation services",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article establishes the rules for payment initiation service providers (PISPs), including the prohibition of holding payer funds, requirements for secure communication and data handling, and obligations not to alter transaction details.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "psd2-directive-article-68-liability-of-account-servicing-providers",
    "title": "DIRECTIVE (EU) 2015/2366 on payment services in the internal market - Article 68: Rules on access to payment account in the case of payment initiation services",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires account servicing payment service providers to grant access to payment initiation service providers when a payer gives explicit consent, and it establishes specific security, data handling, and non-discrimination obligations for both parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "psd2-directive-article-72-charges-for-payment-transactions",
    "title": "Directive (EU) 2015/2366 on payment services in the internal market - Article 72: Refusal of payment orders",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires payment service providers to notify users of any refusal to execute a payment order, including the reasons and correction procedures, and prohibits refusal of authorized orders if all contractual conditions are met.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "psd2-directive-article-73-value-date-and-availability-of-funds",
    "title": "DIRECTIVE (EU) 2015/2366 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 25 November 2015 on payment services in the internal market - Article 73: Value Date and Availability of Funds",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that payment service providers apply specific value dates for crediting and debiting accounts and ensure funds are made available to the payee immediately after being credited to the provider's account.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "psd2-directive-article-74-execution-time",
    "title": "DIRECTIVE (EU) 2015/2366 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 25 November 2015 on payment services in the internal market - Article 74: Evidence on authentication and execution of payment transactions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires payment service providers to bear the burden of proof when a user denies authorizing a transaction, mandating they demonstrate proper authentication, recording, and system integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "psd2-directive-article-83-security-requirements",
    "title": "DIRECTIVE (EU) 2015/2366 on payment services in the internal market - Article 83: Consent and withdrawal of consent",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires payment service providers to obtain explicit consent from the payer before executing a payment transaction, to treat transactions without consent as unauthorised, and to provide a mechanism for payers to withdraw consent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "psd2-directive-article-89-access-to-payment-accounts",
    "title": "Directive (EU) 2015/2366 on payment services in the internal market - Article 89: Access to payment accounts in the case of payment initiation services",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires account servicing payment service providers to grant access to payment initiation service providers when a payer gives explicit consent, and outlines the specific security, data handling, and communication obligations for payment initiation service providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "psd2-directive-article-94-general-security-measures",
    "title": "DIRECTIVE (EU) 2015/2366 on payment services in the internal market - Article 94",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires payment service providers to establish, implement, and maintain a comprehensive security framework to manage risks associated with electronic payments and adequately protect users.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "psd2-directive-article-95-major-incident-reporting",
    "title": "DIRECTIVE (EU) 2015/2366 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 25 November 2015 on payment services in the internal market - Article 95",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Payment service providers must establish and maintain an incident management process to detect, manage, and report major operational or security incidents to their competent authority without undue delay and, where applicable, to affected users.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "psd2-directive-article-96-authentication-and-communication",
    "title": "Directive (EU) 2015/2366 on payment services in the internal market, Article 96: Management of operational and security risks",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This article requires payment service providers to establish, maintain, and annually report on a comprehensive risk management framework, including incident management procedures and regular, independent audits of security measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "psd2-directive-article-97-secure-communications",
    "title": "DIRECTIVE (EU) 2015/2366 on payment services in the internal market - Article 97: Security measures",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This article requires payment service providers to apply strong customer authentication (SCA) for online account access, electronic payment initiation, and other remote actions that carry a risk of fraud, and to implement security measures to protect user credentials.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "psd2-sc-authentication",
    "title": "PSD2 SCA (Payments)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "PSD2 Strong Customer Authentication (SCA) (Directive 2015/2366) is the mandatory security standard for electronic payments in Europe. it requires a multifactor authentication process based on 'Knowledge' (something only the user knows), 'Possession' (something only the user has), and 'Inherence' (something the user is), with the specific requirement for the 'Dynamic Linking' to prevent the tampering during the payment initiation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "pt-codigo-contratos-publicos-ccp-decreto-lei-18-2008-as-amended",
    "title": "Portugal Codigo dos Contratos Publicos (CCP) Decreto-Lei 18/2008 of 29 January 2008 as amended (most recently by Decreto-Lei 78/2022)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Portuguese Codigo dos Contratos Publicos (CCP / Public Contracts Code) approved by Decreto-Lei 18/2008 of 29 January 2008, as amended most recently by Decreto-Lei 78/2022 of 7 November 2022, is the principal Portuguese statute governing procurement of works, goods, services, and consultancy by contracting authorities including the State, autonomous regions (Acores and Madeira), local authorities (autarquias locais), public institutes, public-sector entities, and other entities under EU procurement directive scope. The CCP transposes the EU procurement directives 2014/24/EU (classical), 2014/25/EU (utilities), 2014/23/EU (concessions), and 2009/81/EC (defence and security) into Portuguese law. The 2017 amendment by Lei 18/2017 implemented the 2014 EU directives and substantially modernised the CCP. Subsequent amendments include Decreto-Lei 111-B/2017, Decreto-Lei 33/2018, Decreto-Lei 170/2019, Decreto-Lei 10-A/2020 (COVID-19 emergency provisions), Lei 30/2021 (simplification reforms), and Decreto-Lei 78/2022 (additional reforms). The Instituto dos Mercados Publicos, do Imobiliario e da Construcao (IMPIC, I.P.) is the central regulatory authority. The Base do Conhecimento sobre Contratos Publicos (BASE / base.gov.pt) is the mandatory federal e-procurement platform for procurement notice publication, contract data publication, and contractor history tracking. Procurement methods established by CCP art. 16 to 31 comprise (a) Concurso publico (Open Tender, the default open public procedure), (b) Concurso limitado por previa qualificacao (Restricted Tender, with prequalification), (c) Procedimento de negociacao (Negotiated Procedure, under prescribed exceptions), (d) Dialogo concorrencial (Competitive Dialogue, for complex acquisitions), (e) Parceria para a inovacao (Innovation Partnership), (f) Ajuste direto (Direct Adjustment, sole-source under prescribed exceptions including emergency, sole supplier for technical reasons, prior unsuccessful tendering, and small-value below thresholds), (g) Consulta previa (Prior Consultation, between two and five suppliers for prescribed small-value), and (h) Sistemas de aquisicao dinamicos (Dynamic Purchasing Systems). The CCP establishes the Tribunal de Contas (Court of Accounts) for procurement audit and the administrative courts for procurement appeals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "eu-public-procurement-directive-2014-24-construction",
      "eu-directive-2014-25-utilities-procurement",
      "iso-iec-42001-2023-ai-management-system"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "pt-decreto-lei-18-2008-codigo-contratos-publicos",
    "title": "Portugal Decreto-Lei 18/2008 - Código dos Contratos Públicos (CCP)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Decreto-Lei nº 18/2008, de 29 de janeiro (Código dos Contratos Públicos, CCP), is Portugal's consolidated public procurement code, in force from 29 July 2008 and substantially revised in 2017 and 2021 to transpose EU Directives 2014/23/EU, 2014/24/EU and 2014/25/EU. The Code regulates the formation and execution of public contracts. Art. 1 defines the scope of application. Art. 5 establishes the procurement principles of transparency, non-discrimination, equal treatment, competition, publicity, proportionality, good faith and pursuit of the public interest. Art. 16 sets out the six procedure types: ajuste direto (direct award), consulta prévia (prior consultation), concurso público (open competition), concurso limitado por prévia qualificação (restricted competition with prior qualification), procedimento de negociação (negotiation procedure), diálogo concorrencial (competitive dialogue) and parceria para a inovação (innovation partnership). Art. 36 governs the decision to contract. Art. 55 sets the impediments and exclusion grounds. Arts. 70 to 76 govern proposal evaluation under the critério da proposta economicamente mais vantajosa (most economically advantageous proposal). Art. 271 governs contract modifications during execution. Art. 423 governs unilateral termination by the contracting authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-directive-2014-23-concession-contracts",
      "eu-directive-2014-25-utilities-procurement"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "pt-lei-58-2019",
    "title": "Portugal Data Protection Law (Lei 58/2019) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Portugal's Data Protection Law (Lei 58/2019 de 8 de agosto - Lei de Execução do RGPD, published in the Diário da República No. 151, 1.ª série, on 8 August 2019, entering into force on 9 August 2019) is Portugal's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Portugal. The GDPR is directly applicable Portuguese law by virtue of Portugal's EU membership. Lei 58/2019 provides the national derogations, additions, and specifications that the GDPR permits EU member states to adopt and repealed the prior Portuguese personal data protection law (Lei 67/98 of 26 October 1998). Enforcement: Comissão Nacional de Proteção de Dados (CNPD) is Portugal's independent data protection supervisory authority, established in 1991. The CNPD is Portugal's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Portuguese national provisions: (1) Age of digital consent: Portugal has set the age of consent for information society services at 13 years (GDPR Art. 8 allows member states to lower to 13) - data subjects under 13 require parental or guardian consent for information society services; (2) DPO obligations: Lei 58/2019 expands the mandatory DPO requirement beyond GDPR's baseline - Portuguese law requires DPOs for entities processing health data, for controllers or processors whose core activities require systematic, large-scale processing of sensitive data, and for entities designated by sector-specific regulation; (3) Employment context: Portuguese labour law (Código do Trabalho - Labour Code) contains specific provisions on employee monitoring, biometric data processing, and workplace privacy that interact with GDPR requirements; (4) Freedom of expression: provisions for journalistic, literary, and artistic processing in accordance with freedom of expression rights under the Portuguese Constitution (Constituição da República Portuguesa); (5) Criminal data: restrictions on processing personal data relating to criminal convictions and offences; (6) Public sector: significant provisions on processing by public authorities, including specific obligations for public health systems (SNS - Serviço Nacional de Saúde) and central and local government. Fines: GDPR administrative fines apply in Portugal - up to EUR 20 million or 4% of global annual turnover for the most serious violations. The CNPD has issued significant GDPR fines including against the National Health Service (SINTRA hospital), BNP Paribas Personal Finance Portugal, and EDP Comercial. The CNPD issued one of the first GDPR fines in the EU in July 2018 (before Lei 58/2019 entered into force) against a hospital for unauthorised access to patient data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "pw-framework",
    "title": "Palau - Constitutional Privacy Rights and Pacific Islands Forum Data Protection Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Republic of Palau is an independent nation in the western Pacific Ocean with a constitutional democratic government. The Constitution of the Republic of Palau (1979, as amended) establishes fundamental rights including the right to privacy and freedom from unreasonable searches and interferences with personal communications. Palau entered into a Compact of Free Association with the United States, which provides for US defense responsibilities and economic assistance but does not extend US federal law to Palau - Palau maintains its own legal system and exercises full sovereignty over its domestic affairs including ICT regulation. The Bureau of Information and Communications Technology (BICT) under the Ministry of Finance oversees ICT infrastructure and telecommunications services in Palau. Palau does not have a standalone comprehensive personal data protection law. The constitutional privacy framework, BICT regulatory requirements for ICT service providers, and Pacific Islands Forum regional guidelines on cybersecurity and data protection together constitute the reference framework for personal data protection obligations in Palau. Organisations processing personal data in Palau must respect constitutional privacy rights, implement appropriate security measures protecting personal data from unauthorised access and disclosure, and adhere to purpose limitation principles applicable under Palauan law and Pacific regional guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/pw-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "py-ley-2051-2003-contrataciones-publicas-dncp",
    "title": "Paraguay Ley 2051/2003 de Contrataciones Publicas as amended by Ley 7021/2022 and DNCP (Direccion Nacional de Contrataciones Publicas)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Paraguay Ley 2051/2003 de Contrataciones Publicas (Law 2051/2003 on Public Procurement) of 21 January 2003 as substantially amended and supplemented by Ley 7021/2022 de Suministro y Contrataciones Publicas of 17 November 2022 effective 1 January 2023 (the new General Law of Supply and Public Procurement replacing Ley 2051/2003), and Decreto 21.909/2003 (Reglamento), is the principal Paraguayan framework governing procurement of goods, services, and works by the Public Administration including the Executive Branch (Poder Ejecutivo), the Legislative Branch (Poder Legislativo), the Judicial Branch (Poder Judicial), Autonomous and Decentralized Entities, public-sector enterprises, Departmental Governments (Gobernaciones), Municipalities (Municipalidades), and other entities financed by the State budget. Ley 7021/2022 substantially modernised the Paraguayan procurement regime introducing (a) unified procurement framework, (b) mandatory electronic procurement, (c) strengthened anti-corruption and beneficial ownership disclosure, (d) sustainability and innovation criteria, (e) framework agreements and reverse auctions, and (f) strengthened complaint resolution. The Direccion Nacional de Contrataciones Publicas (DNCP / contrataciones.gov.py) under the Ministry of Finance is the central regulatory authority responsible for procurement regulation, oversight, supplier debarment, and operation of the public procurement portal. The Sistema de Informacion de Contrataciones Publicas (SICP) operated by DNCP is the mandatory federal e-procurement platform. Procurement methods established by Ley 7021/2022 art. 33 to 42 comprise (a) Licitacion Publica Nacional o Internacional (Public Tender, the default open public procedure), (b) Licitacion por Concurso de Ofertas (Tender by Offer Competition, with prequalification), (c) Contratacion Directa (Direct Procurement, sole-source under prescribed exceptions in art. 33 numeral 5 including emergency, sole supplier, prior failed tendering), (d) Compras Menores (Minor Procurement, for small-value below thresholds), (e) Subasta Electronica Inversa (Reverse Electronic Auction, for standardised products), (f) Convenio Marco (Framework Agreement), and (g) Procedimientos Especiales (Special Procedures). The Contraloria General de la Republica conducts procurement audit. Paraguay is a party to MERCOSUR, the WTO TFA, and UNCAC. Paraguay is NOT a party to the WTO GPA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5",
      "wto-revised-government-procurement-agreement-2012"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "py-pdpl-2020",
    "title": "Paraguay Law No. 6534/2020 on the Protection of Personal Credit Data",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Paraguay's Law No. 6534/2020 (Ley de Proteccion de Datos Personales Crediticios) is a narrow, sector-specific statute regulating personal credit data, not a comprehensive GDPR-style data protection regime. Enacted in 2020, it governs the collection, storage, use and disclosure of credit information by credit information bureaus and by banking and financial entities, and creates data-subject rights of access, rectification, objection and a right to have credit data deleted after defined retention periods. Paraguay has no single national data protection authority for this law; enforcement is split between the Central Bank of Paraguay (Banco Central del Paraguay - BCP), which authorises and supervises credit information bureaus, and the Secretariat for the Defence of the Consumer and the User (SEDECO). There is no Direccion Nacional de Proteccion de Datos Personales and no supervisory body housed under the Ministry of Technology, Information and Communication (MITIC) for this law. A separate comprehensive data protection law (Law No. 7593/2025) was approved in November 2025 with a deferred effective date and is addressed in its own node; this node states only what Law No. 6534/2020 binds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "qa-aml-ctf-law-20-2019",
    "title": "Qatar Law No. 20 of 2019 on Combating Money Laundering and Terrorism Financing",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-18",
    "bluf": "Qatar's Law No. 20 of 2019 criminalises money laundering (Article 2) and requires financial institutions and DNFBPs to apply customer due diligence and identify beneficial owners (Articles 10-11), apply enhanced due diligence including for politically exposed persons (Article 13), conduct ongoing monitoring (Article 14), maintain risk management and internal controls (Article 16), keep records (Article 20), and report suspicious transactions to the Financial Information Unit (Article 22), which is established under Article 31.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "qa-pdppl-2016",
    "title": "Personal Data Privacy Protection Law No. 13 of 2016",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Qatar's PDPPL governs the processing of personal data for individuals within the state, mandating that data controllers obtain explicit consent, adhere to principles of legality and transparency, and implement necessary security measures. As per Article 4, all processing must be lawful, transparent, for a legitimate purpose, and limited to what is necessary to achieve that purpose.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-122-pii",
      "gdpr-data-protection-officer"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "qa-pdppl-2016-article-4-conditions-lawful-processing",
    "title": "Qatar PDPPL Law No.13/2016 - Article 4: Conditions for Lawful Personal Data Processing",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Qatar Personal Data Privacy Protection Law No. 13 of 2016 Article 4 establishes the conditions under which personal data may be lawfully processed. Processing requires the data subject's explicit written consent unless one of five alternative conditions applies: processing is necessary for a contract with the data subject; required by a legal obligation; necessary to protect vital interests; necessary for a legitimate public interest task; or required for the data controller's legitimate interest that does not prejudice the data subject's interests. The MOTC/NCSA supervises compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "qa-pdppl-2016",
      "qa-pdppl-2016-article-9-data-subject-rights"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "qa-pdppl-2016-article-9-data-subject-rights",
    "title": "Qatar PDPPL Law No.13/2016 - Article 9: Rights of Personal Data Subjects",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Qatar Personal Data Privacy Protection Law No. 13 of 2016 Article 9 grants data subjects five enforceable rights: right to access their personal data; right to correct inaccurate or incomplete data; right to request destruction of data no longer needed for its collection purpose; right to object to processing in specified circumstances; and right to withdraw consent to processing. Controllers must respond within 30 days. Data subjects may complain to MOTC/NCSA where rights are denied.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "qa-pdppl-2016",
      "qa-pdppl-2016-article-4-conditions-lawful-processing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "qatar-labour-law-14-2004-amended",
    "title": "Labour Law No. (14) of 2004 (as amended by Law No. 18 of 2020 and Law No. 17 of 2020)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This law governs employment relations in Qatar's private sector, establishing a non-discriminatory minimum wage (Law No. 17 of 2020), abolishing the No-Objection Certificate (NOC) requirement for changing employers (Law No. 18 of 2020), and setting maximum working hours, leave entitlements, and end-of-service benefits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998",
      "un-guiding-principles-business-human-rights",
      "sa8000-social-account",
      "iso-45001-work-safety"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "qatar-pdppl-law-13-2016-data-protection",
    "title": "Qatar Personal Data Privacy Protection Law No. 13 of 2016",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This law establishes comprehensive data protection obligations for entities processing personal data in Qatar, including requirements for lawful processing, data subject rights, sensitive data handling, cross-border data transfers, and mandatory breach notification. Key obligations are derived from the core principles and rights outlined in the instrument.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-confidentiality",
      "aicpa-soc2-cc-privacy",
      "aicpa-soc2-cc-processing-integrity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "qatar-qfcra-data-protection-regulations-2021",
    "title": "Data Protection Regulations 2021",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "These regulations apply to Data Controllers and Processors within the Qatar Financial Centre (QFC), mandating registration with the QFCRA (Article 10) and adherence to core data processing principles (Article 6). They establish strict conditions for processing sensitive personal data and for transferring personal data outside the QFC, and grant the QFCRA enforcement powers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "qa-pdppl-2016",
      "gdpr-article-5-data-principles",
      "oecd-privacy-guidelines-2013",
      "eu-standard-contractual-clauses-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "quantum-readiness-checklist",
    "title": "Quantum Readiness Checklist",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The Quantum Readiness Checklist is based on OMB M-23-02, CISA's Quantum Strategy, and NIST PQC migration guidance. It provides an actionable framework for organizations to identify cryptographic assets vulnerable to quantum attacks (CRQC) and begin the transition to FIPS 203-205 standards to ensure long-term data confidentiality and integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pqc-migration-logic",
      "fips-203-ml-kem-standard",
      "fips-204-ml-dsa-quantum",
      "fips-205-slh-dsa-quantum"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "quantum-risk-audit",
    "title": "Quantum Readiness Triage",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "A quantum readiness assessment is the systematic process of identifying all cryptographic assets in an organization that are vulnerable to attack by a Cryptographically Relevant Quantum Computer (CRQC) and producing a prioritized migration roadmap to post-quantum cryptography (PQC). NIST finalized the first PQC standards (FIPS 203, 204, 205) in August 2024. NSA CNSA 2.0 mandates migration timelines with new systems adopting PQC by 2025 and legacy systems fully migrated by 2030. The 'harvest now, decrypt later' (HNDL) threat means adversaries are already collecting encrypted data today to decrypt once quantum computers mature - organizations with long-lived sensitive data (classified, health, financial, legal) must begin migration immediately regardless of when CRQCs become available.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "nist-sp-800-39-managing-information-security-risk",
      "nist-sp-800-57-key-management",
      "nist-sp-800-131a-rev-2-crypto-transitions",
      "cyber-nist-csf-2",
      "pqc-migration-logic"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "quantum-safe-health-data-encryption-2026",
    "title": "Quantum-Safe Encryption & Post-Quantum Cryptography for Health Data (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "With advancing quantum computing capabilities, health organisations must transition to post-quantum cryptography (PQC) algorithms (e.g., CRYSTALS-Kyber, Dilithium) to protect sensitive health data. This includes inventorying cryptographic assets, developing migration roadmaps, hybrid classical/PQC implementations, and compliance with NIST standards and emerging regulatory expectations for long-term confidentiality of health records.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "quantum-safe-phi-migration-2026",
    "title": "Quantum-Safe Encryption Migration for Protected Health Information (PHI) 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "NIST-recommended migration plan to post-quantum cryptography (PQC) algorithms for HIPAA-covered entities protecting electronic PHI in transit and at rest.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "ramsar-convention-1971-wetlands-international-importance",
    "title": "Ramsar Convention 1971 - Wetlands of International Importance, Wise Use Obligation and Montreux Record",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Convention on Wetlands of International Importance especially as Waterfowl Habitat (Ramsar Convention), adopted in Ramsar, Iran on 2 February 1971 and entering into force on 21 December 1975, is the oldest of the modern global intergovernmental environmental agreements. It provides the framework for national action and international cooperation for the conservation and wise use of wetlands and their resources. Article 2 requires each Contracting Party to designate suitable wetlands within its territory for inclusion in the List of Wetlands of International Importance, with at least one Ramsar Site designated upon accession. Article 3 establishes the wise use obligation, requiring Parties to maintain the ecological character of listed and all other wetlands in their territory. Article 4 requires Parties to promote conservation of wetlands and waterfowl by establishing nature reserves. As of 2024, the Convention has 172 Contracting Parties with over 2,400 Ramsar Sites covering approximately 256 million hectares. The Montreux Record under Resolution 5.4 (1993) maintains a record of Ramsar Sites where adverse changes in ecological character have occurred or are likely to occur, triggering remedial action.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-watercourses-convention-1997-transboundary-water",
      "unece-helsinki-convention-1992-transboundary-watercourses"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "rare-disease-digital-endpoints-2026",
    "title": "Rare Disease Digital Endpoints & Decentralized Clinical Trials Framework 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "FDA and EMA joint guidance supports use of digital endpoints (wearables, apps, AI-derived biomarkers) in rare disease trials. Emphasizes validation, patient-centric design, and real-world data integration to accelerate approvals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "rbi-digital-lending-guidelines-2022",
    "title": "RBI Guidelines on Digital Lending 2022 - Regulated Entity (RE) Accountability, Loan Service Provider (LSP) Rules, Data Privacy and Consumer Protection Requirements",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes accountability for Regulated Entities (REs) in digital lending ecosystems, mandates oversight of Loan Service Providers (LSPs), and enforces strict data privacy and consumer protection standards. Key obligations are derived from RBI press releases and circulars, including those dated April 08, 2022 and May 07, 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "apra-cps-234",
      "basel-iii-liquidity-lcr"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "re-gdpr-2018",
    "title": "Réunion - GDPR and French Data Protection Law (Loi Informatique et Libertés)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Réunion, as an outermost region of France and the European Union under the TFEU outermost regions framework, is fully subject to the EU General Data Protection Regulation (GDPR) and the French Loi Informatique et Libertés (Law No. 78-17 of 6 January 1978), as modified by Law No. 2018-493 of 20 June 2018 implementing GDPR obligations in French national law. The Commission Nationale de l'Informatique et des Libertés (CNIL) is the competent data protection supervisory authority for Réunion, exercising enforcement jurisdiction across all French overseas departments. Organisations that process personal data in Réunion or target individuals located in Réunion must comply with all GDPR requirements, including: documenting a lawful basis for each processing activity, maintaining a Record of Processing Activities (RoPA), enabling data subject rights (access, rectification, erasure, restriction, portability, and objection), notifying CNIL of personal data breaches within 72 hours where required, performing data protection impact assessments (DPIAs) for high-risk processing, appointing a Data Protection Officer (DPO) where mandated by the GDPR, and applying appropriate safeguards for any transfer of personal data to recipients outside the European Economic Area. CNIL's administrative fines authority applies in Réunion, with maximum penalties of EUR 20 million or 4% of total worldwide annual turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/re-gdpr-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "re100-renewable-req",
    "title": "RE100 Renewable Energy Criteria",
    "domain": "Sustainability & ESG",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Corporate adherence to RE100 renewable energy criteria mandates a verifiable framework for achieving 100% renewable electricity sourcing. Foundational requirements demand a public commitment to reach this target by the year 2050, supported by aggressive interim milestones stipulating a minimum of 60 percent renewable electricity by 2030 and 90 percent by 2040. Per established leadership principles, the operational boundary for these commitments must comprehensively include all group operations worldwide. Credible electricity sourcing, as defined by the technical criteria, is paramount and restricts procurement to generation facilities with a maximum commissioning age of 15 years. Furthermore, accountability mechanisms necessitate that all Scope 2 emissions accounting utilize the market-based method. The validity of Energy Attribute Certificates (EACs) is contingent upon strict adherence to geographic and temporal rules, demanding the EAC market boundary match the consumption location and its vintage align with the consumption period. To ensure integrity and prevent double counting, official reporting guidance mandates the transparent retirement of all EACs on a recognized registry. Compliance culminates in a complete annual disclosure submitted via CDP, substantiating the organization's progress and claims toward its goal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cdp-carbon-disclosure",
      "sbti-carbon-target"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "reach-chemical-comp",
    "title": "REACH Chemical Compliance",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Regulation (EC) No 1907/2006 (REACH) mandates a comprehensive framework for chemical management to protect human health and the environment. Compliance hinges on several core obligations for manufacturers, importers, and downstream users. A primary duty is substance registration with the European Chemicals Agency if an entity manufactures or imports a substance into the EU in quantities over 1 metric tonne annually, requiring a valid registration number for market access. For articles, the presence of a Substance of Very High Concern (SVHC) from the Candidate List triggers stringent rules. If the SVHC concentration is greater than the 0.1% weight by weight threshold, communication duties to recipients are activated and a notification submitted to the ECHA SCIP database becomes obligatory. Furthermore, should the total amount of a specific SVHC in all articles produced or imported exceed 1 metric tonne per year, a separate registration may be necessary. The regulatory scope also includes substances subject to Authorization and Restriction. If an entity uses a substance listed on Annex XIV, it must hold a specific authorization for that particular use. Likewise, if a substance or its specific use is restricted under the conditions of Annex XVII, its application must conform to the specified limitations. Effective supply chain communication, verified through a formal process, is critical, particularly for entities identified as downstream users, and includes the mandatory provision of Safety Data Sheets for hazardous substances. Verifying ongoing adherence through an annual compliance audit remains a crucial element of a robust governance program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "real-world-evidence-rwe-regulatory-use-2026",
    "title": "Real-World Evidence (RWE) in Regulatory Decision-Making - Global Framework (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Real-World Evidence from electronic health records, claims data, registries, wearables, and digital sources is increasingly accepted for regulatory decisions including approval, label expansion, post-market safety, and reimbursement. Frameworks require data quality, representativeness, bias control, transparency, and methodological rigor. Regulators (FDA, EMA, PMDA, etc.) have published specific guidance on RWE study design and acceptance criteria.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pharmacovigilance-ich-e2e-2026"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "recommendation-for-pair-wise-key-establishment",
    "title": "Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2018-04-01",
    "bluf": "This Recommendation specifies key-establishment schemes based on the discrete logarithm problem over finite fields and elliptic curves, including several variations of Diffie-Hellman (DH) and Menezes-Qu-Vanstone (MQV) key establishment schemes. The specifications are appropriate for use by the U.S. Federal Government and are intended to provide sufficient information for a vendor to implement secure key establishment using asymmetric algorithms in FIPS 140-validated modules. The publication was developed by the National Institute of Standards and Technology (NIST) in accordance with its statutory responsibilities under the Federal Information Security Modernization Act (FISMA) of 2014.\n\nA key-establishment scheme can be characterized as either a key-agreement scheme or a key-transport scheme. During a pair-wise key-agreement scheme, the secret keying material to be established is not sent directly from one entity to another. Instead, the two parties exchange information from which they each compute a shared secret that is used to derive the secret keying material. This recommendation specifies the processes associated with key establishment, including procedures for generating domain parameters, generating static and ephemeral key pairs, providing assurance of public key validity, deriving secret keying material from a shared secret, and optionally performing key confirmation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-57-key-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "redcanary-atomic-red-team-attack-tests",
    "title": "Red Canary Atomic Red Team Library (1800+ ATT&CK-Mapped Atomic Tests, YAML Schema, Invoke-Atomic Execution, MITRE CALDERA Atomic Plugin Pairing, MIT License)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Atomic Red Team is the community-developed library of portable security tests aligned with the MITRE ATT&CK framework, maintained by Red Canary at github.com/redcanaryco/atomic-red-team under the MIT license. The repository contains 1,804 atomic tests across multiple languages (C 43.5 percent, PowerShell 12.2 percent, Go 10.5 percent, Java 7.2 percent, C# 6.3 percent, plus others) that security teams use to 'quickly, portably, and reproducibly test their environments' against specific adversary behaviours. Each atomic test is defined in a YAML schema with fields including name, auto_generated_guid, description, supported_platforms (windows, linux, macos), input_arguments (parameterised inputs with type, description, default), dependency_executor_name and dependencies (prerequisites that must exist on the target before the test runs), executor (containing name as one of sh, bash, command_prompt, powershell, manual, plus elevation_required and command and cleanup_command properties); each test is stored under atomics/<TID>/<TID>.yaml and is keyed to a MITRE ATT&CK technique identifier such as T1059.001 PowerShell or T1003.001 LSASS Memory dumping. The canonical execution framework is Invoke-AtomicRedTeam, a PowerShell module that loads the atomics repository, supports Get-AtomicTechnique, Invoke-AtomicTest, and Invoke-AtomicTest -Cleanup operations, and integrates with the MITRE CALDERA Atomic plugin so CALDERA adversary profiles can include Atomic Red Team tests as abilities. Atomic Red Team is the recommended way for SOC validation teams, purple teams, and detection engineers to test ATT&CK technique coverage in their own environment with reproducible, atomic units of attack behaviour.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "library_basis",
        "key_institutions",
        "atomic_test_yaml_schema",
        "executor_taxonomy",
        "attack_technique_id_mapping",
        "invoke_atomic_powershell_module",
        "caldera_atomic_plugin_pairing",
        "test_count_and_languages",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mitre-attack-framework-v14",
      "mitre-caldera-adversary-emulation-platform",
      "mitre-engage-adversary-engagement-framework",
      "sigmahq-sigma-detection-rule-format"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "reducing-risks-posed-by-synthetic-content",
    "title": "Reducing Risks Posed by Synthetic Content: An Overview of Technical Approaches to Digital Content Transparency",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-10",
    "bluf": "This report examines the existing standards, tools, methods, and practices for authenticating content, tracking its provenance, labeling synthetic content through techniques like watermarking, and detecting synthetic content. It also addresses methods for preventing generative AI (GAI) from producing harmful content such as child sexual abuse material or non-consensual intimate imagery of real individuals. The focus is on digital content transparency, which refers to the process of documenting and accessing information about the origins and history of digital content. The goal is to manage and reduce risks related to synthetic content by recording and revealing provenance, providing tools to identify AI-generated content, and mitigating the production of specific illegal and harmful materials.\n\nThe document provides an overview of technical approaches for provenance data tracking and synthetic content detection, alongside a review of current testing and evaluation techniques. It emphasizes that no single technique offers a comprehensive solution; their value is use-case and context-specific, relying on effective implementation and oversight. While the report focuses on technical approaches, it acknowledges the importance of normative, educational, regulatory, and market-based approaches. The technical methods described serve as building blocks to improve trust in digital content by indicating where AI has been used to generate or modify content.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-ai-600-1-gen-ai-profile",
      "nist-language-of-trustworthy-ai"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "regulatory-intelligence-horizon-scanning-2026",
    "title": "Regulatory Intelligence & Horizon Scanning for Medical & Health Technologies (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "A foundational compliance process requiring medical device manufacturers and health tech developers to systematically monitor, analyse, and adapt to emerging regulatory changes across global jurisdictions before they take effect.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "report-post-quantum-cryptography",
    "title": "NISTIR 8105 Report on Post-Quantum Cryptography",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2016-04-01",
    "bluf": "If large-scale quantum computers are ever built, they will be able to break many of the public-key cryptosystems currently in use, seriously compromising the confidentiality and integrity of digital communications on the Internet and elsewhere. The goal of post-quantum cryptography (also called quantum-resistant cryptography) is to develop cryptographic systems that are secure against both quantum and classical computers, and can interoperate with existing communications protocols and networks. Many of our most crucial communication protocols rely on public key encryption, digital signatures, and key exchange, primarily implemented using Diffie-Hellman, RSA, and elliptic curve cryptosystems. A sufficiently powerful quantum computer will put these forms of modern communication in peril. This report shares the National Institute of Standards and Technology (NIST)’s current understanding about the status of quantum computing and post-quantum cryptography, and outlines NIST’s initial plan to move forward. The report also recognizes the challenge of moving to new cryptographic infrastructures and therefore emphasizes the need for agencies to focus on crypto agility. It has taken almost 20 years to deploy our modern public key cryptography infrastructure, and it will take significant effort to ensure a smooth and secure migration to quantum-resistant counterparts. Therefore, regardless of the exact time of the arrival of the quantum computing era, we must begin now to prepare our information security systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-57-key-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "responsible-business-alliance-code-conduct-v7",
    "title": "Responsible Business Alliance (RBA) Code of Conduct Version 7.0 2021 - Labour, Health and Safety, Environment, Ethics and Management System Standards for Supply Chains",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The RBA Code of Conduct sets social, environmental, and ethical standards for global supply chains, applicable across industries with a focus on electronics. It requires adherence to international norms including human rights, labor standards, and environmental protection as defined in its core sections, with Version 8.0 effective January 1, 2024, superseding prior versions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-deforestation-regulation-2023",
      "eu-forced-labour-regulation-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "responsible-gambling-grb-standards-2023",
    "title": "Global Gambling Guidance Group (G4) Responsible Gambling Standards - International Benchmarks for Player Protection and Harm Minimisation Programmes",
    "domain": "Gaming & Gambling",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "The Global Gambling Guidance Group (G4) is an independent accreditation body whose official site is gx4.com. G4 publishes the G4 Standards in Responsible Gambling (a Code of Practice) against which gambling operators are independently audited and accredited, covering player protection measures such as age and identity verification, player risk assessment, self-exclusion, deposit and spending limits, time-out and cool-off tools, staff training, and proactive harm-minimisation interventions. The G4 Code is organised into named areas with two-level numbering (for example licensing, age verification, player-led session limits, and cooling-off/self-exclusion); the earlier three-level section numbers, the EUR 500 default deposit limit and the 1 percent-of-gross-gaming-revenue funding figure in this node were not verifiable against the G4 Code and have been removed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l3",
      "eu-dora-articles-28-44-third-party-ict-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "responsible-jewellery-council-standard-2019",
    "title": "Responsible Jewellery Council Code of Practices (COP) 2019 - Responsible Business Practices for Gold, Silver, PGMs and Gemstones Supply Chain Members",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This standard requires jewellery and watch supply chain companies to implement responsible business practices across human rights, labour rights, health and safety, and product integrity. Compliance is verified through third-party audits against the RJC Code of Practices (COP), Chain of Custody (COC), or Laboratory Grown Material Standard (LGMS).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp",
      "iso-14001-ems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "reverse-logistics-circular",
    "title": "Reverse Logistics & Circularity",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance for returned asset disposition is governed by a multi-stage evaluation process to ensure regulatory adherence and maximize value recovery. Initial triage assesses an item’s physical state using a `product_condition_score` from one to ten. Products achieving a score of 9 or 10 are determined `is_eligible_for_resale_as_is`, while an item scoring between 6 and 8 may qualify for refurbishment, provided that `is_repair_cost_effective` evaluates to true because estimated repair costs are less than 40% of its new market value. For assets where `requires_data_sanitization` is flagged, a mandatory `data_sanitization_level_required` from Level 1 (Clear) to Level 3 (Destroy) must be executed to mitigate data privacy risks; such items also mandate a `requires_secure_chain_of_custody` for auditable tracking. Furthermore, any product identified as `contains_regulated_materials` must be handled according to strict protocols aligned with environmental directives like WEEE and RoHS. The node also validates if an `epr_scheme_applicable` governs the item's jurisdiction, enforcing producer obligations. If refurbishment is not viable, a final check determines if `is_component_harvesting_viable` for salvaging valuable parts before responsible recycling or disposal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-20245-remanufactured"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "rics-red-book-global-valuation-2022",
    "title": "RICS Red Book Global Valuation Standards 2022: Valuation Bases, Inspections and Reporting Requirements for Real Property",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The RICS Red Book mandates that RICS members and regulated firms conduct property valuations with professional competence, objectivity, and transparency, requiring strict adherence to mandatory Professional Standards (PS 1 & PS 2) and the relevant Valuation Practice Statements (VPS) for the specific valuation purpose.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37001-anti-bribery"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "rics-valuation-global",
    "title": "RICS Valuation - Global",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the RICS Valuation - Global standards mandates a comprehensive set of procedural and documentary requirements for all valuation assignments. This framework verifies that the individual signing any valuation report is a current RICS Registered Valuer and confirms the firm maintains adequate Professional Indemnity Insurance coverage. Crucially, a formal conflict of interest check must be performed and documented for each instruction, aligning with RICS Professional Standard 1. Before issuing a valuation, a written Terms of Engagement compliant with PS1 and PS2 must be agreed upon and signed by the client. The final report itself is subject to rigorous standards; it must explicitly define a basis of value, such as Market Value, that is compliant with IVS and VPS 4, and contain all minimum content stipulated by VPS 3. Furthermore, the report has to declare the extent of any property inspection conducted, detailing resultant limitations. Operationally, firms are required to make a documented Complaints Handling Procedure available to clients. For data governance, the platform confirms that all valuation files, associated working papers, and client data are stored in an encrypted state at rest. Finally, complete valuation files must be archived for a minimum period of 6 years after the valuation date to satisfy regulatory record-keeping obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifac-ethics-accountants"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "risk-management-for-replication-devices",
    "title": "Risk Management for Replication Devices",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2015-02-01",
    "bluf": "This publication provides guidance on protecting the confidentiality, integrity, and availability of information processed, stored, or transmitted on replication devices (RDs), which include copiers, printers, three-dimensional (3D) printers, scanners, 3D scanners, and multifunction machines. The guidance is applicable to all RDs, including software applications for using tablets or cell phones as copiers/scanners, but only pertains to the copy/print/scan functions. As RDs are often connected to organizational networks, run commercial operating systems, and store information on nonvolatile media, they may be vulnerable to numerous exploits if risks are not mitigated.\n\nThe document discusses vulnerabilities and exploits associated with RDs and provides a set of security practices and controls that can be implemented to mitigate risks. It suggests appropriate countermeasures in the context of the System Development Life Cycle (SDLC) - from initiation and acquisition to disposal. The target audience includes individuals responsible for the purchase, installation, configuration, maintenance, disposition, and security of RDs. The core obligation is for organizations to manage the risks associated with RDs by understanding threats, vulnerabilities, potential impact, and implementing appropriate security controls to protect information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "fips-199-security-categorization"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "ro-law-98-2016-classical-public-procurement-eu-directive-transposition",
    "title": "Romania Law No. 98/2016 on Classical Public Procurement (Legea nr. 98/2016 privind achizitiile publice) effective 26 May 2016",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Romanian Law No. 98/2016 on Public Procurement (Legea nr. 98/2016 privind achizitiile publice, Monitorul Oficial al Romaniei nr. 390 of 23 May 2016) effective 26 May 2016 is the principal Romanian classical-sector public procurement statute governing procurement of goods, services, and works by classical contracting authorities including the State, central public authorities, county councils, municipalities, local councils, public institutions, and other bodies governed by public law. Law 98/2016 transposed into Romanian law the EU Directive 2014/24/EU on classical public procurement. Parallel statutes apply for utilities (Law 99/2016 on sectoral procurement transposing Directive 2014/25/EU), concessions (Law 100/2016 transposing Directive 2014/23/EU), and procurement remedies (Law 101/2016 transposing Directive 89/665/EEC remedies). The National Agency for Public Procurement (Agentia Nationala pentru Achizitii Publice / ANAP) is the central regulatory authority for procurement policy, ex-ante control, and procurement guidance. The Romanian Electronic Public Procurement System (Sistemul Electronic de Achizitii Publice / SEAP, e-licitatie.ro) operated by the National Authority for Communication Administration and Regulation (ANCOM) is the mandatory federal e-procurement platform. The National Council for Solving Complaints (Consiliul National de Solutionare a Contestatiilor / CNSC) is the specialised administrative tribunal for procurement complaints. Procurement methods established by Law 98/2016 art. 68 to 116 comprise (a) Open Procedure (Licitatie deschisa, the default open public procedure), (b) Restricted Procedure (Licitatie restransa, with prequalification), (c) Competitive Negotiation (Negociere competitiva, with notice), (d) Negotiation without Prior Publication (Negociere fara publicare prealabila, under prescribed exceptions including emergency and sole-source), (e) Competitive Dialogue (Dialog competitiv, for complex acquisitions), (f) Innovation Partnership (Parteneriat pentru inovare), (g) Simplified Procedure (Procedura simplificata, for prescribed lower-value contracts), (h) Direct Acquisition (Achizitie directa, for very low-value contracts below prescribed thresholds), and (i) Framework Agreement (Acord-cadru) and Dynamic Purchasing Systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "eu-public-procurement-directive-2014-24-construction",
      "eu-directive-2014-25-utilities-procurement",
      "iso-iec-42001-2023-ai-management-system"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ro-lege-190-2018",
    "title": "Romania Data Protection Law No. 190/2018 - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Romania's Law No. 190/2018 on Measures Implementing Regulation (EU) 2016/679 (Legea nr. 190/2018 privind măsuri de punere în aplicare a Regulamentului (UE) 2016/679 al Parlamentului European și al Consiliului din 27 aprilie 2016 privind protecția persoanelor fizice în ceea ce privește prelucrarea datelor cu caracter personal și privind libera circulație a acestor date și de abrogare a Directivei 95/46/CE), published in the Official Gazette of Romania (Monitorul Oficial) No. 651 of 26 July 2018 and entering into force on 26 July 2018, is Romania's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Romania. The GDPR is directly applicable Romanian law by virtue of Romania's EU membership. Law 190/2018 provides national derogations, additions, and specifications that the GDPR permits EU member states to adopt. Enforcement: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP - National Authority for the Supervision of Personal Data Processing) is Romania's independent data protection supervisory authority. The ANSPDCP is Romania's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Romanian national provisions: (1) Age of digital consent: Romania has maintained the GDPR default of 16 years for information society services; data subjects under 16 require parental or guardian consent; (2) Employment context - Law 190/2018 contains provisions on the processing of personal data in employment, specifying that employers may process employee data only for purposes directly related to the employment relationship; the law provides that employees must be informed before monitoring is implemented; (3) Processing for public interest and official authority - specific provisions for public authorities in Romania, including national security services, judicial authorities, and public administration, subject to additional legal authorisation requirements; (4) Research and statistics - extended processing for scientific research, statistics, and archiving in the public interest is permitted with appropriate safeguards; (5) Criminal data - Law 190/2018 restricts private entity processing of criminal conviction and offence data; (6) Journalistic, literary, and artistic processing - exemptions aligned with GDPR Art. 85. Fines: GDPR administrative fines apply in Romania - up to EUR 20 million or 4% of global annual turnover. The ANSPDCP has imposed GDPR fines and conducted investigations, including in the areas of unlawful data processing by public authorities, inadequate data security, and employee monitoring. Romania has the EU's sixth largest population and is a growing digital economy with significant technology sector development.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "rohs-hazardous-sub",
    "title": "RoHS Hazardous Substances",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the Restriction of Hazardous Substances (RoHS) directive mandates that Electrical and Electronic Equipment (EEE) placed on the market does not contain specific restricted substances above defined maximum concentration values. This assessment applies to any product falling within one of the 11 categories specified in Annex I of Directive 2011/65/EU. The core principle requires that all analysis is conducted at the homogeneous material level, meaning any single, uniform material cannot exceed the established thresholds. Specifically, the maximum concentration for Cadmium (Cd) is strictly limited to 100 parts per million (ppm). For a broader list of substances, including Lead (Pb), Mercury (Hg), Hexavalent Chromium (Cr VI), Polybrominated Biphenyls (PBB), and Polybrominated Diphenyl Ethers (PBDE), the permissible limit is 1000 ppm. An amendment added four phthalates-DEHP, BBP, DBP, and DIBP-whose combined concentration must also not exceed 1000 ppm. Should any substance concentration surpass these limits, a valid, documented, and unexpired exemption from Annex III or Annex IV must be applied to maintain compliance. Furthermore, manufacturers are obligated to create and maintain comprehensive technical documentation in accordance with the EN IEC 63000:2018 standard, demonstrating conformity and providing the necessary evidence for market surveillance authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "reach-chemical-comp",
      "weee-electronic-waste"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "romania-emergency-ordinance-194-2002-igi-immigration",
    "title": "Romania Emergency Ordinance 194/2002 - Regime of Foreigners and Schengen Residency Framework",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Romania's principal immigration statute is Emergency Government Ordinance 194/2002 on the Regime of Foreigners in Romania (OUG 194/2002), as substantially amended. The General Inspectorate for Immigration (IGI, Inspectoratul General pentru Imigrari) administers residence permits. Romania joined the Schengen Area for air and sea travel on 31 March 2024 and for land borders on 1 January 2025. Non-EU nationals staying beyond 90 days require a long-stay visa (D-visa) and then a residence permit (permis de sedere). The Romanian Immigration Authority issues temporary and permanent residence. Third-country national employees need a work authorisation from ANOFM (National Agency for Employment) and an employment-based D-visa. The Law No. 122/2006 on Asylum governs protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "germany-residence-act-aufenthaltsgesetz-2004-bamf",
      "poland-act-on-foreigners-2013-urzad-ds-cudzoziemcow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "romania-onjn-online-gambling-geo-77-2009",
    "title": "Romania GEO 77/2009 / GEO 92/2014 - Online Gambling Regulation (ONJN)",
    "domain": "Gaming & Gambling",
    "version": "1.1.0",
    "last_updated": "2015-07-01",
    "bluf": "Romania's online gambling framework (GEO 77/2009 as amended by GEO 92/2014) requires ONJN authorisation for all online gambling operators targeting Romanian players, with 5% GGR tax for online and 25% for land-based operations, mandatory national self-exclusion register integration, ONPCSB AML reporting, and ISP blocking of unlicensed operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021",
      "responsible-gambling-grb-standards-2023",
      "eu-5amld-article-2-gambling-2018",
      "eu-gdpr-online-gaming-data-protection"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "rome-statute-1998-international-criminal-court",
    "title": "Rome Statute of the International Criminal Court - 1998",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Rome Statute establishes the ICC's jurisdiction over genocide (Article 6), crimes against humanity (Article 7 - 11 categories including enslavement and forced labour), and war crimes (Article 8 - including use of child soldiers and pillaging) across 124 State Parties; businesses and their executives face liability under domestic implementing legislation when corporate operations contribute to or facilitate ICC crimes - enforced directly through supply chain due diligence obligations under CSDDD Annex Part I and LkSG Section 2(1), and via universal jurisdiction provisions applicable in all signatory states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-guiding-principles-business-human-rights",
      "eu-corporate-sustainability-due-diligence-2024",
      "un-cat-1984-convention-against-torture",
      "ilo-core-conventions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "rotterdam-convention-pic-chemicals-2004",
    "title": "Rotterdam Convention on Prior Informed Consent for Hazardous Chemicals 2004 - PIC",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Rotterdam Convention on Prior Informed Consent Procedure for Certain Hazardous Chemicals and Pesticides in International Trade (2004 - 168 Parties as of April 2026) requires exporting countries to obtain Prior Informed Consent (PIC) from importing country Designated National Authorities (DNAs) before shipping chemicals listed in Annex III (currently 59 chemicals including pesticides, industrial chemicals, and severely hazardous pesticide formulations) - exporters of listed chemicals must check importing country import decisions (allow, prohibit, or conditional) via the Rotterdam Convention PIC Circular published every six months, and must not ship to countries that have responded 'do not consent'; the Convention operates as the global hazardous chemicals customs compliance gateway alongside the Stockholm (POPs) and Basel (hazardous waste) Conventions, forming the 'chemicals trinity' that chemical manufacturers, traders, and freight forwarders must navigate for every international shipment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wto-sps-agreement-food-trade-disputes",
      "stockholm-convention-2001-persistent-organic-pollutants",
      "eu-csrd-2022-2464",
      "cites-convention-1973-endangered-species-trade"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "rotterdam-rules-2008",
    "title": "United Nations Convention on Contracts for the International Carriage of Goods Wholly or Partly by Sea (The Rotterdam Rules)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Rotterdam Rules establish a modern, uniform legal framework governing the rights and obligations of parties to a contract for international door-to-door carriage that includes a sea leg. It extends the carrier's period of responsibility (Article 12) and liability, and provides a legal basis for the use of electronic transport records (Chapter 3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hague-visby-rules",
      "incoterms-2020-fca-v2",
      "imo-solas-safety-at-sea",
      "iso-28000-supply-chain"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "rotterdam-rules-maritime",
    "title": "Rotterdam Rules (UN Convention)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Rotterdam Rules (2008) constitute the United Nations Convention on Contracts for the International Carriage of Goods Wholly or Partly by Sea. They modernize the maritime liability regime by covering 'door-to-door' transport involving maritime legs, and accommodating electronic commerce and paperless bills of lading.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hague-visby-rules"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "rs-law-public-procurement-91-2019-public-procurement-office-portal",
    "title": "Serbia Law on Public Procurement (Sluzbeni glasnik RS broj 91/2019) of 23 December 2019 and Public Procurement Office",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Republic of Serbia Law on Public Procurement (Zakon o javnim nabavkama) published in Sluzbeni glasnik RS No. 91 of 23 December 2019 effective 1 July 2020, as supplemented by application bylaws (podzakonska akta) issued thereunder, is the principal Serbian statute governing procurement of goods, services, and works by contracting authorities including the Republic of Serbia (Republic bodies, autonomous provinces, units of local self-government, bodies governed by public law), sectoral contracting entities (water, energy, transport, postal services and other utilities), public-sector enterprises (Javna preduzeca), public-sector institutions, and other contracting authorities subject to EU procurement directive scope. Law 91/2019 substantially modernised the Serbian procurement regime aligning with the EU procurement directives 2014/24/EU (classical), 2014/25/EU (utilities), 2014/23/EU (concessions), and Directive 89/665/EEC remedies as part of Serbia's EU accession Chapter Five (Public Procurement) negotiations. The Public Procurement Office (Uprava za javne nabavke / UJN, ujn.gov.rs) is the central regulatory authority responsible for procurement regulation, procurement policy, training, oversight, and procurement guidance. The Republic Commission for the Protection of Rights in Public Procurement Procedures (Republicka komisija za zastitu prava u postupcima javnih nabavki / RC) is the specialised body for procurement appeals. The Public Procurement Portal (Portal javnih nabavki / jnportal.ujn.gov.rs) operated by UJN is the mandatory federal e-procurement platform for in-scope procurement. Procurement methods established by Law 91/2019 art. 51 to 81 comprise (a) Open Procedure (Otvoreni postupak, the default open public procedure), (b) Restricted Procedure (Restriktivni postupak, with prequalification), (c) Competitive Procedure with Negotiation (Konkurentni postupak sa pregovaranjem), (d) Negotiated Procedure without Publication (Pregovaracki postupak bez objavljivanja javnog poziva, under prescribed exceptions in art. 75 to 76 including emergency and sole-source), (e) Competitive Dialogue (Konkurentni dijalog, for complex acquisitions), (f) Innovation Partnership (Partnerstvo za inovacije), (g) Design Contest (Konkurs za dizajn), and (h) Procurement of Low-Value (Nabavka male vrednosti, for prescribed lower-value contracts). The State Audit Institution conducts ex-post procurement audit. Serbia is in WTO accession in the procurement chapter and is NOT yet a party to the WTO Government Procurement Agreement (GPA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "rs-pdpa-2018",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "rs-pdpa-2018",
    "title": "Serbia Law on Personal Data Protection 2018 - Poverenik",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Serbia's Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti - ZZPL) - published in the Official Gazette of the Republic of Serbia No. 87/2018 and entering into force on 21 August 2019 after a nine-month transition period - is Serbia's primary personal data protection legislation, closely modelled on the European Union General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) as part of Serbia's EU accession process (EU candidate since 2012). The ZZPL replaced the prior Personal Data Protection Law of 2008 and brought Serbia's data protection framework into alignment with the EU's Acquis Communautaire as required under the EU accession negotiations, particularly Chapter 23 (Judiciary and Fundamental Rights). The supervisory authority is the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti - the Poverenik), an independent state body whose mandate covers both the right of access to information and personal data protection in Serbia. Key features of Serbia's Law on Personal Data Protection 2018: (1) Scope - applies to processing of personal data of natural persons in Serbia by controllers and processors established in Serbia or processing data of Serbian data subjects regardless of establishment; (2) Controller and processor distinction - mirrors the GDPR framework; data processing agreements required between controllers and processors; (3) Lawful processing conditions - consent; contract; legal obligation; vital interests; public interest; legitimate interests; (4) Data processing principles - lawfulness; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability; (5) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; genetic data; biometric data for identification; health data; sexual orientation; criminal conviction data; (6) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to data portability; right to object; rights related to automated decision-making and profiling; (7) Data Protection Officer - mandatory for: public authorities; controllers whose core activities involve regular and systematic monitoring of data subjects on a large scale; controllers or processors whose core activities involve large-scale processing of sensitive personal data; (8) Breach notification - 72-hour notification to the Poverenik of personal data breaches likely to result in a risk to data subject rights; data subject notification for high-risk breaches; (9) Data Protection Impact Assessment - mandatory for high-risk processing operations including large-scale processing of sensitive data and systematic monitoring; (10) Cross-border transfers - adequacy decisions; standard contractual clauses; binding corporate rules; codes of conduct; certification; and specific derogations; (11) Penalties - administrative fines graduated by violation type; individual and legal entity fine tiers; criminal liability for intentional violations. Serbia's ZZPL is among the most comprehensive GDPR-aligned laws outside the EU and is directly relevant to EU-Serbia data flows as Serbia advances toward EU membership.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "rspo-palm-oil",
    "title": "RSPO Palm Oil Certification",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "RSPO Palm Oil Certification compliance mandates verifiable adherence to a multifaceted set of criteria established under governing principles and procedural rules. An entity must demonstrate its commitment through active RSPO membership, requiring that `is_rspo_member`:true, and by maintaining an `active_certification_body_contract`:true for independent verification, validated by a record showing the `last_audit_passed`:true. Supply chain integrity, per certification standards, is paramount, requiring that a `supply_chain_model_declared`:true is supported by a fully implemented traceability system where `percent_certified_material_tracked` equals 100. Environmentally, operations must prove `no_primary_forest_clearing_since_2005`:true and possess a documented plan where `ghg_emissions_monitoring_plan_exists`:true. Social obligations are equally stringent, demanding that `free_prior_informed_consent_records_maintained`:true, `fair_labor_practices_verified`:true, and a `grievance_mechanism_operational`:true for stakeholders. Consistent with audit protocols and reporting frameworks, transparency is confirmed when an `annual_communication_of_progress_submitted`:true, substantiating ongoing conformity with all stipulated requirements for sustainable palm oil production and sourcing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-45001-health-safety",
      "iso-26000-social-resp"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ru-federal-law-44-fz-contract-system-state-municipal-procurement-2013",
    "title": "Russia Federal Law No. 44-FZ on the Contract System in State and Municipal Procurement (5 April 2013, as amended)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "Federal Law No. 44-FZ on the Contract System in the Sphere of Procurement of Goods, Work, and Services for State and Municipal Needs (Federal'nyi zakon ot 5 aprelya 2013 g. N 44-FZ) is the principal Russian statute governing procurement by federal, regional, and municipal state customers, federal autonomous and budgetary institutions when funded by budget allocations, and certain unitary enterprises. The Law spans nine chapters covering general provisions, contract system planning, methods of identifying suppliers, contract conclusion and performance, monitoring procurement, audit in the procurement sphere, control in the procurement sphere, dispute resolution, and final provisions. Procurement methods specified in the Law include open electronic auction (the default method for many product categories), open tender in electronic form, request for quotations in electronic form, request for proposals in electronic form, single-supplier procurement (sole-source justified), and closed methods for specific defence and security categories. The mandatory federal procurement portal Edinaya informatsionnaya sistema v sfere zakupok (Unified Information System in Procurement / EIS) at zakupki.gov.ru is the principal transparency and notification channel. 44-FZ is distinct from Federal Law No. 223-FZ (18 July 2011) which governs procurement by state corporations, state companies, natural monopoly entities, and certain entities with state-share participation - the two laws form parallel procurement regimes with 223-FZ providing greater flexibility for commercial state-controlled entities. The Law establishes preferences for Russian-origin goods and services through governmental decrees including domestic supplier preferences for certain categories, regulated maximum import shares, and procurement preferences for SMEs and socially-oriented non-profit organisations. The Law sets a mandatory anti-corruption compliance baseline for customer organisations and a complaint and dispute resolution channel through the Federal Antimonopoly Service (FAS). Critical international context note: this node documents the procurement regime as a matter of comparative regulatory intelligence; entities subject to US OFAC, EU, UK, or other sanctions regimes targeting the Russian Federation must conduct sanctions screening before any engagement with this procurement regime, and certain engagement may be prohibited; this node is regulatory reference intelligence and not authorisation or encouragement of sanctioned conduct.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ru-fz-152-2006",
    "title": "Russia Federal Law on Personal Data No. 152-FZ 2006 - Roskomnadzor",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Russia's Federal Law 'On Personal Data' (Федеральный закон «О персональных данных»), Federal Law No. 152-FZ - adopted by the State Duma on 8 July 2006, signed by President Vladimir Putin on 27 July 2006, and published in the Rossiyskaya Gazeta - is Russia's comprehensive personal data protection legislation. The law has been amended numerous times, with the most significant amendments being: Federal Law No. 242-FZ of 21 July 2014 (in force 1 September 2015), which introduced the mandatory data localisation requirement; Federal Law No. 266-FZ of 14 July 2022, which enacted a major reform of data protection obligations including mandatory breach notification, enhanced data subject rights, a Data Protection Officer (Уполномоченный по защите данных) requirement for certain operators, and significantly higher administrative fines; and Federal Law No. 420-FZ of 30 November 2024 (in force 30 May 2025), which amended the Code of the Russian Federation on Administrative Offenses (KoAP / КоАП) to introduce turnover-based administrative fines for personal data leaks. Note: the turnover-based fines sit in the KoAP (Administrative Offenses Code), not in Federal Law No. 152-FZ itself. The supervisory authority is Roskomnadzor (Federal Service for Supervision of Communications, Information Technology, and Mass Media - Федеральная служба по надзору в сфере связи, информационных технологий и массовых коммуникаций, RKN), which maintains the Register of Personal Data Operators, enforces the data localisation requirement through the Register of Violators, and has blocked major international services (including LinkedIn in 2016) for non-compliance. Key features of Federal Law No. 152-FZ as amended: (1) Mandatory data localisation - when collecting personal data from Russian citizens, the initial recording, systematisation, accumulation, storage, and retrieval of personal data must be performed using databases physically located on the territory of the Russian Federation; cross-border transfer is permitted after localisation; non-compliance results in Roskomnadzor blocking access to the service in Russia; (2) Operator concept - 'operator' (оператор) is equivalent to data controller - any government body, municipal body, legal entity, or individual that independently or jointly with others organises and/or carries out processing of personal data; (3) Seven principles for personal data processing: lawfulness and fairness; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability; (4) Special categories - personal data processing of special categories (biometric, health, racial or ethnic origin, political views, religious or philosophical beliefs, trade union membership) requires written consent unless a statutory exception applies; biometric personal data requires explicit written consent; (5) Data subject rights - right of access to personal data and processing information; right to rectification; right to erasure (блокирование и уничтожение); right to object to processing; right to appeal to Roskomnadzor; right not to be subject to automated decision-making; (6) Mandatory breach notification - operators must notify Roskomnadzor within 24 hours of discovering a breach; operators must notify data subjects within 72 hours; operators must submit a full investigation report to Roskomnadzor within 72 hours; (7) Data Protection Officer - operators processing large volumes of personal data or processing special categories must designate a person responsible for personal data protection; (8) Administrative fines - significantly increased by 2022 amendments; Federal Law No. 420-FZ of 30 November 2024 (in force 30 May 2025) amended the KoAP to introduce turnover-based fines for repeat large-scale personal data leaks: 1% to 3% of the operator's annual revenue from the preceding year, with a minimum of RUB 20 million and a maximum of RUB 500 million (the law also provides a reduced 0.1% turnover fine, minimum RUB 15 million / maximum RUB 50 million, where the operator can show qualifying information-security spending in the prior three years); (9) Cross-border transfer - permitted to countries on Russia's approved adequate-protection list or with data subject consent; all data must be localised in Russia before any transfer. Russia's data localisation requirement is one of the most stringent in the world and has resulted in significant compliance challenges for multinational technology companies operating in Russia.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ru-law-5663-1-space-activity-1993",
    "title": "Russian Federation Law No. 5663-1 (About Space Activity) 1993",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Russian Federation Law No. 5663-1 (About Space Activity) makes space activity subject to licensing in compliance with the legislation of the Russian Federation (Article 9). Space facilities of the Russian Federation are subject to registration and must carry labeling verifying their affiliation with the Russian Federation (Article 17). Organizations and citizens that use space technology must hold insurance on the lives and health of cosmonauts and space infrastructure employees, and to cover harm to the life, health, or property of other persons (Article 25). Liability for harm caused by a Russian space object on the territory of the Russian Federation or beyond its borders, except in space, arises independently of the fault of the party causing the harm (Article 30). It applies to space activity carried out under the jurisdiction of the Russian Federation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "russia-fz-152-health-data-2026",
    "title": "Russia Federal Law No. 152-FZ - Personal Data (Health Data) & Digital Health Regulations (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Federal Law No. 152-FZ on Personal Data classifies health data as special category data requiring explicit written consent or other legal grounds. The law mandates data localisation (storage in Russia), strict security measures, breach notification to Roskomnadzor within 24 hours, and operator registration. Digital health platforms must comply with additional Ministry of Health orders on electronic medical records and telemedicine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "china-nmpa-ai-medical-devices-2026"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "rw-aml-cft-regulation-01-2022",
    "title": "Rwanda Regulation No. 01/2022 on Anti-Money Laundering, Countering the Financing of Terrorism and Proliferation Financing",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "Rwanda's Regulation No. 01/2022 on Anti-Money Laundering, Countering the Financing of Terrorism and Proliferation Financing requires reporting persons to register (Article 3), designate reporting staff (Article 6), verify the identity of natural and legal persons (Articles 8 and 9), apply basic, enhanced and simplified client due diligence (Articles 16, 17 and 18), give special attention to higher-risk clients (Article 22), report suspicious activities and transactions to the Financial Intelligence Centre (Articles 33 and 35), keep records (Article 36), and establish policies, procedures and an independent audit function (Articles 37 and 38).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "rw-cybersecurity-law-2018",
    "title": "Rwanda Law No. 60/2018 on Cybersecurity",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Rwanda's Law No. 60/2018 of 22 August 2018 governing cybersecurity in Rwanda establishes the National Cyber Security Authority as the regulatory body for cybersecurity, designates Critical Information Infrastructure in strategic sectors, requires CII operators to implement cybersecurity measures and report cybersecurity incidents to the NCSA, creates cybercrime offences including unauthorised access and data interference with imprisonment penalties, and mandates cybersecurity certification for organisations in regulated sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/rw-cybersecurity-law-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "rw-pdp-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "rw-law-62-2018-public-procurement-rppa-umucyo",
    "title": "Rwanda Law No. 62/2018 of 25 August 2018 on Public Procurement and the Umucyo E-Procurement Platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Republic of Rwanda Law No. 62/2018 of 25 August 2018 governing public procurement (Itegeko No. 62/2018 ryo ku wa 25/08/2018 rigenga isoko rusange) effective 1 September 2018, as supplemented by Ministerial Order No. 001/19/10/TC of 26 February 2019 establishing the procurement procedure, and amended over time, is the principal Rwandan statute governing procurement of goods, works, services, and consultancy services by procuring entities including the Central Government ministries, Government agencies and authorities, decentralized administrative entities (Districts and Provinces), public-sector enterprises (Public Enterprises Act companies), public institutions, public-sector universities, and other entities financed by public funds. Law 62/2018 modernised the Rwandan procurement regime aligning with international best practice including the UNCITRAL Model Law on Public Procurement and World Bank procurement guidelines. The Rwanda Public Procurement Authority (RPPA / rppa.gov.rw) is the central regulatory authority responsible for procurement regulation, oversight, supplier debarment, complaint resolution at first instance, and procurement guidance. The Umucyo e-procurement platform (umucyo.gov.rw) operated by RPPA is the mandatory federal e-procurement platform for in-scope procurement. The Independent Review Panel (IRP) under the Office of the Ombudsman is the specialised body for procurement appeals. Procurement methods established by Law 62/2018 art. 26 to 49 comprise (a) Open Tendering (the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Restricted Tendering (with prequalification), (c) Request for Proposals (for consulting services), (d) Request for Quotations (for medium-value goods and services), (e) Direct Procurement (sole-source under prescribed exceptions in art. 39 including emergency, sole supplier for technical reasons, prior failed tendering, and prescribed-class exemptions), (f) Single-Source Procurement (for sole-supplier circumstances), (g) Force Account (for in-house performance), (h) Community Procurement (for community-driven projects), (i) Two-Stage Tendering (for complex acquisitions), and (j) Electronic Reverse Auction. The Office of the Auditor-General of State Finances conducts ex-post procurement audit. Rwanda is a party to the East African Community (EAC) Common Market Protocol, the African Continental Free Trade Area (AfCFTA), and UNCAC. Rwanda is NOT a party to the WTO Government Procurement Agreement (GPA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "rw-pdp-2021",
      "rw-cybersecurity-law-2018",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "rw-pdp-2021",
    "title": "Rwanda Law No. 058/2021 of 13/10/2021 on Protection of Personal Data and Privacy",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This law establishes the legal framework for the protection of personal data and privacy for natural persons in Rwanda, applying to any data controller or processor in Rwanda and those outside Rwanda who process personal data of individuals located within the country (Article 3). It mandates lawful processing based on consent or other legal grounds, outlines data subject rights, and requires notification of data breaches to the supervisory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ke-dpa-2019",
      "za-popia-2013",
      "gdpr-data-protection-officer",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "rwanda-digital-health-framework-2026",
    "title": "Rwanda Digital Health Framework & Data Protection Law (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Rwanda's Digital Health Framework and Law No. 058/2021 on Protection of Personal Data and Privacy classify health data as sensitive. The framework mandates the Rwanda Health Information Exchange (RHIE), national unique patient identifiers, interoperability via FHIR, strong consent requirements, data localisation preferences, and breach notification to the supervisory authority within 72 hours. Under Law No. 058/2021 the designated supervisory authority is the National Cyber Security Authority (NCSA), which operates a Data Protection Office; there is no entity named the Rwanda Data Protection Authority. The framework supports digital health innovation while maintaining patient-centric controls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "kenya-digital-health-act-2026",
      "who-global-digital-health-strategy-2026"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "rwanda-digital-health-sovereignty-2026",
    "title": "Rwanda Law No. 058/2021 of 13 October 2021 Relating to the Protection of Personal Data and Privacy (data localisation and health data)",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "Rwanda Law No. 058/2021 relating to the protection of personal data and privacy requires personal data to be stored within Rwanda unless the controller or processor obtains a certificate from the supervisory authority (the National Cyber Security Authority), imposes conditions on cross-border transfers, and treats health data as sensitive personal data subject to enhanced conditions and consent. Specific localisation also applies to telecommunications and sovereign data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "sa-aml-royal-decree-m-20-2017-anti-money-laundering-law",
    "title": "Saudi Arabia Anti-Money Laundering Law - Royal Decree M/20 dated 05/02/1439H (2017) and Implementing Regulations",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "The Anti-Money Laundering Law of the Kingdom of Saudi Arabia was issued by Royal Decree No. M/20 dated 05/02/1439H (corresponding to 25 October 2017 of the Gregorian calendar), repealing and replacing the prior Royal Decree M/31 of 1424H (2003). The Law operates with its Implementing Regulations issued by the Decision of the Presidency of State Security No. 14525 dated 19/02/1439H. The Law criminalises money laundering broadly, covering the conversion, transfer, acquisition, possession, use or management of funds or proceeds known or suspected to be derived from a predicate offence; the predicate is any criminal offence including tax-evasion conduct, narcotics, corruption, terrorism financing, fraud, smuggling, human trafficking and cybercrime. Penalties include imprisonment up to ten years and fines up to SAR 5 million per offence for natural persons, with aggravated penalties of imprisonment up to fifteen years where the offence is committed through a criminal organisation or involves a public official; for legal persons, fines up to SAR 50 million and dissolution where appropriate. Reporting obligations apply to financial institutions and designated non-financial businesses and professions (DNFBPs) including banks, exchange houses, finance companies, insurance and reinsurance entities, securities firms, lawyers, accountants, real estate agents, dealers in precious metals and stones, trust and company service providers, and from the 2022 SAMA cryptoassets framework virtual asset service providers. Reporting is to the General Department of Financial Investigations (GDFI) at the Presidency of State Security, the Saudi FIU, within the applicable window (typically as soon as practicable after suspicion is formed). The Saudi Central Bank (SAMA, the successor to the Saudi Arabian Monetary Authority) supervises banks, exchange houses, finance companies, insurance entities and payment institutions; the Capital Market Authority (CMA) supervises securities firms; the Ministry of Commerce supervises DNFBPs through sectoral licensing authorities. Saudi Arabia is a FATF member since 2019 and a member of the Middle East and North Africa Financial Action Task Force (MENAFATF) since 2004; the country was the subject of a FATF Mutual Evaluation Report published in September 2018 with subsequent follow-up assessments. The Vision 2030 reform program has prioritised AML/CFT modernisation including the 2017 Law, the 2022 cryptoassets framework, and the modernisation of the General Authority of Zakat and Tax (now ZATCA) for tax-related predicate offences. The Law operates alongside the Counter-Terrorism Financing Law issued by Royal Decree M/16 of 24/02/1435H (2014), and the Counter-Terrorism Law issued by Royal Decree M/21 of 12/02/1438H (2017).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "money_laundering_offence_anchor",
        "obliged_persons_anchor",
        "customer_due_diligence_anchor",
        "smr_obligation_anchor",
        "penalties_anchor",
        "industry_mapping",
        "international_alignment_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "saudi-sama-cybersecurity-framework-2017",
      "fatf-40-recommendations-2023-consolidated",
      "eu-aml-regulation-2024-1624"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "sa-cst-citc-cloud-computing-regulatory-framework-ccrf",
    "title": "Saudi Arabia CST/CITC Cloud Computing Regulatory Framework (CCRF)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Cloud Computing Regulatory Framework (CCRF) is Saudi Arabia's national cloud regulation administered by the Communications, Space and Technology Commission (CST, formerly the Communications and Information Technology Commission / CITC). The CCRF establishes the regulatory regime for Cloud Service Providers (CSPs) operating in Saudi Arabia or serving Saudi customers, the data classification levels used to determine residency and CSP eligibility, the registration requirements for CSPs, and the relationship between cloud governance and the Personal Data Protection Law (PDPL) administered by the Saudi Data and AI Authority (SDAIA). The framework classifies customer data into four levels based on impact: Level 1 (Public, no confidentiality required), Level 2 (Confidential, low impact if disclosed), Level 3 (Confidential, medium impact, typical of regulated industry data), and Level 4 (Highly Confidential, high impact, including critical national infrastructure and sovereign data classifications). Level 3 and 4 data are subject to data residency requirements (typically Saudi-located data centres) and CSP eligibility constraints including local registration, data protection officer designation, incident reporting to CST and to the National Cybersecurity Authority (NCA) where the customer is a government or critical infrastructure entity, and adherence to NCA Essential Cybersecurity Controls (ECC-1:2018 updated 2022) and Cloud Cybersecurity Controls (CCC-1:2020). The CCRF intersects the National Data Management Office (NDMO) data classification policy issued by SDAIA which provides the cross-government data categorisation taxonomy that maps into CCRF residency tiers. The framework also intersects sectoral cloud regulations including the Saudi Central Bank (SAMA) Cybersecurity Framework cloud provisions for banks and insurance entities and the Saudi Health Information Exchange policies for healthcare cloud workloads. CCRF-licensed providers include the major global hyperscalers via Saudi region launches (AWS Middle East Bahrain / Saudi, Microsoft Azure Saudi, Google Cloud Saudi via local partnership, Oracle Cloud Infrastructure Saudi, IBM Cloud) and several Saudi national providers including stc cloud, Mobily Cloud, Sahara Net, and the strategic government cloud initiatives under Vision 2030.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-iec-42001-2023-ai-management-system",
      "iso-iec-23894-ai-risk-management-2023",
      "nist-sp-800-53-r5",
      "fips-203-ml-kem-standard",
      "us-cisa-secure-by-design-principles-2023"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "sa-ecc-2018-domain-1-cybersecurity-governance",
    "title": "Saudi Arabia Essential Cybersecurity Controls ECC-1:2018 - Domain 1: Cybersecurity Governance Controls",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Saudi Arabia Essential Cybersecurity Controls (ECC-1:2018) Domain 1 establishes the mandatory cybersecurity governance framework for government agencies and their contractors. Domain 1 (Section 5.1) covers four control families: Cybersecurity Strategy (5.1.1), Cybersecurity Policy (5.1.2), Cybersecurity Roles and Responsibilities (5.1.3), and Cybersecurity Review and Audit (5.1.4). All 36 sub-controls in Domain 1 are mandatory for entities subject to Saudi National Cybersecurity Authority oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sa-nca-ecc-2018",
      "sa-ecc-2018-domain-2-cybersecurity-defense"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "sa-ecc-2018-domain-2-cybersecurity-defense",
    "title": "Saudi Arabia Essential Cybersecurity Controls ECC-1:2018 - Domain 2: Cybersecurity Defense Controls",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Saudi Arabia Essential Cybersecurity Controls (ECC-1:2018) Domain 2 (Section 5.2) contains the largest set of mandatory technical and operational controls across 16 control families: Asset Management, Identity and Access Management, IT Project and Change Management, Systems and Networks Protection, Data and Information Protection, Cryptography, Backup and Recovery, Vulnerability Management, Penetration Testing, Incident and Threat Management, Physical Security, Web Application Management, Wireless Networks, Mobile Devices, Email Security, and Social Media Security. Domain 2 controls apply to all IT and OT systems within scope of the Essential Cybersecurity Controls framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sa-nca-ecc-2018",
      "sa-ecc-2018-domain-1-cybersecurity-governance"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "sa-government-tenders-procurement-law-2019-royal-decree-m128",
    "title": "Saudi Arabia Government Tenders and Procurement Law 2019 (Nidham Al-Munafasat wa Al-Mushtarayat Al-Hukumiyya) Royal Decree M/128",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Saudi Arabia Government Tenders and Procurement Law issued by Royal Decree M/128 dated 13 November 2019 (corresponding to 16/11/1441 H) and effective 1 December 2019 (corresponding to 4/04/1441 H, with the Implementing Regulations effective 1 December 2019) is the principal Saudi statute governing procurement of goods, services, construction works, and consultancy services by government entities including ministries, government agencies, independent legal personality public entities, and entities financed by the State budget. The 2019 Law repealed the prior Government Tenders and Procurement Law issued by Royal Decree M/58 of 1427 H (2006) and substantially modernised the Saudi procurement regime aligning with Saudi Vision 2030 and the Kingdom's National Transformation Programme. The Implementing Regulations of the Government Tenders and Procurement Law were issued by Ministerial Resolution of the Minister of Finance and contain detailed procedural requirements. The Saudi Ministry of Finance through the Etimad platform (etimad.sa) operated by the Etimad Authority is the central federal e-procurement platform for in-scope procurement. The Local Content and Government Procurement Authority (LCGPA) is the regulatory authority for local content policy in procurement. Procurement methods established by the 2019 Law comprise (a) Public Tender (al-munafasa al-amma, the default open public tender method), (b) Limited Tender (al-munafasa al-mahduda, with prequalification), (c) Direct Purchase (al-shira'a al-mubasher, for low-value below prescribed thresholds and for prescribed exceptions), (d) Two-Stage Tender (al-munafasa thi al-marhalatayn), (e) Framework Agreement (ittifaqiya itariyah), (f) Reverse Auction (al-mazaad al-aksi for prescribed items), and (g) Competitive Negotiation under prescribed exceptions. The 2019 Law introduced strengthened integrity provisions including supplier debarment, conflict of interest disclosure, anti-bribery commitments, and mandatory local content preferences under the Local Content Policy. Saudi Arabia is NOT a party to the WTO Government Procurement Agreement (GPA) but is an observer.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "sa-pdpl-2021",
      "sa-nca-ecc-2018",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "sa-national-cybersecurity-authority-ecc-2-2024-essential-cybersecurity-controls",
    "title": "Saudi Arabia NCA Essential Cybersecurity Controls ECC-2:2024 - 108 Updated Controls, Saudization, and Data Localization Transfer to NDMO",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Saudi Arabia government entities (ministries, authorities, establishments, and subsidiaries) and private-sector organisations that own, operate, or host Critical National Infrastructures must comply with the Essential Cybersecurity Controls ECC-2:2024 issued by the National Cybersecurity Authority (NCA), an updated version of the ECC-1:2018 that reduces the controls from 114 to 108, mandates that all cybersecurity positions within organisations be occupied by full-time and qualified Saudi nationals (expanded from senior-position-only Saudization in ECC-1), and transfers explicit data localisation controls from the ECC-2 to the National Data Management Office (NDMO) while preserving the broader requirement framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sa-pdpl-royal-decree-m19-2021-personal-data-protection"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sa-nca-ecc-2018",
    "title": "Saudi Arabia NCA Essential Cybersecurity Controls (ECC-1:2018)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Saudi Arabia's National Cybersecurity Authority Essential Cybersecurity Controls (ECC-1:2018), issued by the NCA and mandatory for all government entities and private sector organisations providing critical national services, establishes 114 cybersecurity controls across five domains - cybersecurity governance, cybersecurity defense, third-party and cloud cybersecurity, industrial control systems cybersecurity, and cybersecurity resilience - and requires covered entities to conduct compliance assessments and submit results to the NCA on a defined cycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/sa-nca-ecc-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sa-pdpl-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sa-pdpl-2021",
    "title": "Saudi Arabia Personal Data Protection Law (PDPL) Royal Decree M/19 2021",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Saudi Personal Data Protection Law (PDPL) establishes the primary requirements for organizations that process the personal data of Saudi residents, mandating a legal basis for processing, such as explicit consent, and outlining data subject rights. As per Article 5, controllers must not process personal data without the data subject's consent, except in specific cases outlined by the law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-122-pii",
      "za-popia-2013",
      "brazil-lgpd-compliance",
      "india-dpdp-act"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sa-pdpl-2021-article-5-lawful-processing-bases",
    "title": "Saudi Arabia PDPL Royal Decree M/19 - Article 5: Conditions and Lawful Bases for Personal Data Processing",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Saudi Arabia Personal Data Protection Law (Royal Decree No. M/19, 2021) Article 5 establishes the conditions under which personal data may be lawfully processed. Processing is lawful only where: the data subject has given consent; processing is necessary for a contract with or at the request of the data subject; it is required to fulfil a legal obligation; it is necessary to protect vital interests; or it serves a legitimate purpose that does not conflict with personal privacy. Consent withdrawal must be made as easy as consent provision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sa-pdpl-2021",
      "sa-pdpl-2021-article-8-data-subject-rights"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "sa-pdpl-2021-article-8-data-subject-rights",
    "title": "Saudi Arabia PDPL Royal Decree M/19 - Article 8: Rights of Personal Data Subjects",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Saudi Arabia Personal Data Protection Law (Royal Decree No. M/19, 2021) Article 8 grants data subjects four core rights: right to be informed of what personal data is collected and the purpose; right to access their personal data and request a copy; right to request correction of inaccurate data; and right to request destruction of data no longer needed for its original purpose. SDAIA implementing regulations specify response timelines (30 days) and complaint channels. Controllers must provide an accessible rights request mechanism.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sa-pdpl-2021",
      "sa-pdpl-2021-article-5-lawful-processing-bases"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "sa-pdpl-royal-decree-m19-2021-personal-data-protection",
    "title": "Saudi Arabia PDPL (Royal Decree M/19/2021) - Personal Data Protection Law",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Saudi Arabia's Personal Data Protection Law (PDPL, Royal Decree M/19/2021, effective September 2023) establishes lawful bases for processing personal data of Saudi residents, grants data subject rights of access, correction and deletion, requires DPO appointment for large processors, mandates 72-hour breach notification to the National Data Management Office (NDMO), restricts sensitive data and cross-border transfers, with penalties up to SAR 5 million and criminal sanctions for intentional sensitive data violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ae-federal-decree-law-45-2021-personal-data-protection"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sa-sdaia-generative-ai-guidelines-2024",
    "title": "Saudi Arabia SDAIA Generative AI Guidelines 2024 and Principles and Controls of AI Ethics 2023",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Saudi government entities and employees adopting, using, or overseeing generative AI must apply the SDAIA Generative AI Guidelines for Government (issued January 2024) and the SDAIA Principles and Controls of AI Ethics (issued September 2023), which together set out seven core ethics principles, a four-tier risk classification, roles and responsibilities, data handling rules, role definitions, and a compliance checklist, designate SDAIA as the supervisory authority, and align with other national instruments including the Personal Data Protection Law, with a parallel general-public version of the Generative AI Guidelines providing equivalent governance for public-facing use.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sa-pdpl-royal-decree-m19-2021-personal-data-protection"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sa-sfda-pharmaceutical-regulations-saudi-food-drug-authority",
    "title": "Saudi Arabia SFDA Pharmaceutical Regulations Saudi Food and Drug Authority Drug Registration Pricing Manufacturing Authorisation Vision 2030 Localisation Framework",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "The Kingdom of Saudi Arabia Saudi Food and Drug Authority (SFDA) administers the comprehensive pharmaceutical regulation framework under the SFDA Law promulgated by Royal Decree No. M/6 of 1428H establishing SFDA as an independent regulator reporting to the Council of Ministers organised in operative regulations and SFDA Guidelines including the Drug Sector Executive Regulations the Drug Registration Regulations issued under Council of Ministers Decision 1/41/1424 the Good Manufacturing Practices Guideline aligned with PIC/S the Saudi Drug Pricing Mechanism the Pharmacovigilance Guidelines aligned with ICH E2E the Clinical Trial Guidelines aligned with ICH E6 and Saudi-specific requirements for Marketing Authorisation Holder qualification including local representation requirements Vision 2030 pharmaceutical localisation initiatives including the SFDA Made in Saudi Arabia programme and integration with the Gulf Health Council coordinated registration pathway across GCC countries. Implementation through SFDA portal services including Saudi Drug Information System (SDIS) for drug registration and the Saudi Vigilance system for pharmacovigilance reporting. The Kingdom is an ICH observer with substantial alignment with international pharmaceutical standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "sa8000-social-account",
    "title": "SA8000 (Social Account)",
    "domain": "Workplace",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "SA8000 establishes a comprehensive, auditable framework for ensuring decent workplace conditions and upholding fundamental worker rights. Compliance mandates the implementation of an explicit child labor policy, which enforces a minimum worker age of 15 years, alongside a formal policy against forced labor, ensuring all worker contracts are fully voluntary. The standard sets a stringent limit on working hours, capping the regular workweek at a maximum of 60 hours. Furthermore, all overtime must be voluntary and compensated at a premium rate. A robust occupational health and safety program is non-negotiable, requiring the formation of a health and safety committee, the maintenance of documented risk assessments, and the existence of a viable emergency preparedness plan. To ensure systemic adherence and continuous improvement, the framework necessitates a formal management system policy. This system must be supported by regular social performance audits to verify ongoing compliance and a demonstrable corrective action plan that is actively implemented to address any identified non-conformities. These integrated elements form a verifiable system for managing social performance and promoting ethical treatment of labor.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "iso-45001-work-safety",
      "iso-26000-social-resp-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sae-j3016-driving-automation-levels-2021",
    "title": "SAE J3016 2021 Taxonomy of Driving Automation Levels 0-5 for On-Road Vehicles - Definitions, Operational Design Domains, Dynamic Driving Task and Shared Responsibility Framework",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard establishes a globally recognized taxonomy for on-road motor vehicle automated driving systems, defining six levels (0-5) based on which entity-the human driver or the automated system-is responsible for performing the Dynamic Driving Task (DDT) and DDT fallback. The classification, detailed in Section 8, is critical for developers, regulators, and consumers to have a common understanding of system capabilities and limitations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "98.00",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-23894-ai-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sae-j3016-levels-driving-automation-2021",
    "title": "SAE J3016: Taxonomy and Definitions for Terms Related to Driving Automation Systems for On-Road Motor Vehicles (2021)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "Defines six levels (0-5) of driving automation for on-road motor vehicles, specifying the roles of the human driver and automated driving system (ADS), including requirements for OEDR (Object and Event Detection and Response), fallback performance, and operational design domain (ODD). Applies to manufacturers, developers, and regulators of automated driving systems. Key clause: SAE J3016_202104, Section 6 - Levels of Driving Automation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "safe-stays-hotel-audit",
    "title": "Safe Stays (Hotel Hygiene)",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the Safe Stays (Hotel Hygiene) node mandates a comprehensive framework of verifiable sanitation and operational protocols to mitigate public health risks. The standard requires documented evidence that all staff have completed certified hygiene training (`isStaffHygieneTrainingDocumented`) and makes appropriate Personal Protective Equipment mandatory for all cleaning personnel (`isPpeMandatoryForCleaningStaff`). Public area sanitation is strictly governed, stipulating the maximum number of hours permitted between disinfection of high-touch surfaces (`publicAreaHighTouchDisinfectionFrequencyHours`) and mandating the minimum quantity of touchless hand sanitizer stations within lobby areas (`minHandSanitizerStationsInLobby`). For guest accommodations, a detailed, room-specific disinfection checklist must be utilized between every stay (`isGuestRoomDisinfectionChecklistUsed`), and verification of this process must be communicated via a physical sanitization seal on the door (`isRoomSanitizationSealUsed`). Operational adjustments are also required, including visible physical distancing measures throughout common spaces (`arePhysicalDistancingMeasuresInPlace`) and the provision of a contactless check-in option for guests (`isContactlessCheckInOffered`). Building systems are addressed through a maximum allowable number of days for HVAC filter change frequency (`hvacFilterChangeFrequencyDays`) to ensure air quality. Furthermore, all food and beverage services must operate under an active enhanced food safety protocol (`isEnhancedFoodSafetyProtocolActive`). Finally, any collection of health data must be governed by a clearly disclosed privacy policy to maintain regulatory compliance (`isHealthDataPrivacyPolicyDisclosed`).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-health-safety",
      "haccp-food-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "safeguarding-advisory-client-assets",
    "title": "Safeguarding Advisory Client Assets",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-12",
    "bluf": "The Securities and Exchange Commission (SEC) is proposing a new rule, designated as rule 223-1 under the Investment Advisers Act of 1940, to strengthen how investment advisers safeguard client assets. This proposed safeguarding rule redesignates and amends the current custody rule (rule 206(4)-2) to modernize its scope and enhance investor protections in light of changes in technology, advisory services, and custodial practices. The rule applies to investment advisers registered, or required to be registered, with the Commission that have custody of client assets.\n\nThe core obligations of the proposal expand the rule's applicability from 'funds and securities' to a broader definition of 'assets,' meaning 'funds, securities, or other positions held in a client’s account,' explicitly including crypto assets and other investment types. It also clarifies that 'custody' includes an adviser's discretionary authority to trade client assets. A central requirement is that advisers must maintain client assets with a 'qualified custodian' under a new, mandatory written agreement that specifies certain protections, such as requiring the custodian to obtain an annual internal control report. The proposal also modifies the exception for privately offered securities to include certain physical assets, but imposes stricter conditions for its use, including notifying an independent public accountant of asset transfers within one business day.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "private-fund-advisers-compliance-reviews",
      "finra-3110-supervision",
      "occ-asset-management-handbook"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "sales-crm-best-practices",
    "title": "Sales CRM Best Practices",
    "domain": "Sales, Marketing & PR",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "This node sets out operational best-practices for Sales CRM data governance; it is NOT a sovereign legal instrument and the numeric targets below are recommended operational thresholds, not statutory requirements. The underlying legal obligation it supports is the data-accuracy principle in data-protection law - in particular GDPR Article 5(1)(d), the CPRA right to correct (Section 1798.106), PIPEDA Schedule 1 Principle 4.6, and LGPD Article 6 - together with the master-data-quality framework of ISO 8000-110. As operational targets, organisations commonly require high contact-record completeness (for example a 90 percent completeness target and a duplicate rate kept below about 3 percent), email-format validation, E.164 phone formatting, reassignment of stale leads after about 60 days, opportunity-stage updates within about 30 days, assigned record ownership, automated deduplication, validated data imports, field-change auditing and role-based access control. These figures are illustrative good-practice values rather than legally mandated numbers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ccpa-cpra",
      "can-spam-act-email",
      "casl-anti-spam-canada",
      "gdpr-art-21-marketing-optout",
      "sales-lead-gen-compliance",
      "soc2-processing-integrity"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sales-lead-gen-compliance",
    "title": "Lead Gen Compliance",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Lead generation outreach activities are governed by a complex framework of federal and international regulations. Compliance necessitates rigorous validation of consent and adherence to do-not-call mandates under the Telephone Consumer Protection Act and the Telemarketing Sales Rule. Specifically, any outreach utilizing an Automatic Telephone Dialing System, particularly where `is_wireless_number` is true, requires an auditable Prior Express Written Consent. This consent's validity hinges upon a verifiable timestamp (`pewc_timestamp_valid_ms`), confirmation that its `pewc_scope_matches_outreach`, and verification that consent `is_not_condition_of_purchase`. Telemarketing operations must also honor prohibitions against contacting numbers where `is_on_national_dnc_registry` or `is_on_internal_dnc_list` is true, with registry scrubs performed at a maximum interval of 31 days as measured by `dnc_check_recency_days`. An exemption may apply if an `established_business_relationship_exists`, defined by a consumer inquiry within the last 3 months or a transaction within the last 18 months. Furthermore, all calls must occur when `is_within_calling_hours`, restricted to between 8:00 AM and 9:00 PM in the recipient’s local time. The principles of clear affirmative consent also align with the lawful basis for data processing required by privacy regulations like GDPR and the California Consumer Privacy Act, while overarching rules for commercial messaging are informed by standards in the CAN-SPAM Act, ensuring a comprehensive approach to lawful prospect engagement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "can-spam-act-email",
      "ccpa-cpra-optout-sale",
      "gdpr-art-21-marketing-optout"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "samrec-code-south-africa-mineral-reporting",
    "title": "SAMREC Code 2016 - South African Code for the Reporting of Exploration Results, Mineral Resources and Mineral Reserves",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Clause 3 of the SAMREC Code defines a Public Report and requires that any public disclosure of Exploration Results, Mineral Resources or Mineral Reserves be compiled by a Competent Person accredited under the SAMREC Code.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eiti-standard-2023",
      "gri-14-mining-sector-standard-2022",
      "icmm-mining-principles-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sarbanes-oxley-act-sox",
    "title": "Sarbanes-Oxley Act (SOX)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Sarbanes-Oxley Act of 2002 (SOX) is a U.S. federal law that set new or expanded requirements for all U.S. public company boards, management, and public accounting firms. It was enacted in response to major corporate financial scandals (e.g., Enron, WorldCom) to restore investor confidence through enhanced disclosure and internal control mandates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "sox-it-controls"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sarbannes-oxley-404",
    "title": "SOX 404 (Controls Audit)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Sarbanes-Oxley Section 404 compliance centers on a robust framework for Internal Control over Financial Reporting (ICFR). Effective adherence is demonstrated when management's annual ICFR assessment is complete and published in the Form 10-K, corroborated by the external auditor's attestation report. The primary objective is securing an unqualified opinion from auditors on ICFR effectiveness, which necessitates having zero identified material weaknesses. Should any control deficiencies emerge, a formal, tracked remediation plan must be active for all findings. Essential control activities include conducting quarterly user access reviews for financial systems and enforcing Segregation of Duties (SoD) within IT change management. Additionally, all privileged user activities on financial systems require logging and active monitoring to detect anomalous behavior. Technical controls are verified through successful annual testing of data backup and recovery procedures. The compliance posture is further supported by formally documented entity-level controls, such as the control environment, and the execution of a formal fraud risk assessment at a frequency not exceeding 12 months to maintain vigilance against financial misstatement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pcaob-audit-standards",
      "gaap-us-framework",
      "iia-internal-audit-ippf",
      "iso-31000-risk-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sasb-conceptual-framework",
    "title": "SASB CONCEPTUAL FRAMEWORK",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2017-02-01",
    "bluf": "This Conceptual Framework sets out the basic concepts, principles, definitions, and objectives that guide the Sustainability Accounting Standards Board (SASB) in its approach to setting standards for sustainability accounting. SASB’s mission is to develop and disseminate sustainability accounting standards that help public corporations disclose material, decision-useful information to investors. The standards are designed for voluntary use in disclosures required by existing U.S. regulation in filings with the Securities and Exchange Commission (SEC), such as Forms 10-K and 20-F. For the purposes of SASB standards, sustainability refers to corporate activities that maintain or enhance the ability of the company to create value over the long term. Sustainability accounting refers to the measurement, management, and reporting of such corporate activities.\n\nSASB standards identify information that is likely to be material, yield decision-useful information, and are cost-effective for corporate issuers. The SASB approach to standards-setting is Evidence-Based, Market-Informed, and Industry-Specific. By focusing on the subset of sustainability factors that are material to investment decision making, SASB standards yield information that may be useful to a company’s management while also providing a cost-effective solution for disclosure to investors. The standards address sustainability topics organized under five broad dimensions: Environment, Social Capital, Human Capital, Business Model and Innovation, and Leadership and Governance. SASB standards help issuers identify and report on sustainability topics that, substantiated by evidence, constitute known trends, events, and uncertainties that are reasonably likely to have material impacts on companies in an industry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "issb-s1-s2-standard"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "saudi-arabia-iqama-residence-regulations-jawazat",
    "title": "Saudi Arabia Iqama Residence Regulations - Jawazat Sponsorship and Premium Residency Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Saudi Arabia's immigration framework is governed by the Residence Regulations (Nizham Al-Iqama) and the Foreigners' Entry and Exit System, administered by the General Directorate of Passports (Jawazat) under the Ministry of Interior (MOI). The Kafala (sponsorship) system ties non-Saudi workers to an employer/sponsor (kafeel) for residency and work authorisation. The Iqama (residence permit) is the core identity document for expatriates - it must be carried at all times. Expatriates require a valid Iqama, work visa, and residency stamp as a combined permission to live and work. Saudi Arabia introduced the Premium Residency (Al-Iqama Al-Mumayyaza) in 2019, offering permanent or renewable 5-year residency for a fee of SAR 800,000 (permanent) or SAR 100,000 per year (renewable). The Musaned (domestic worker) and Qiwa (private sector) platforms digitise employment contract management, kafala transfers, and complaint resolution. Exit/Re-entry visas were mandatory for non-Saudi workers but family exit visa requirements were abolished in 2019. Absconding (tashardud) status is filed by sponsors and triggers arrest and deportation. The Kafala system is undergoing reform under Vision 2030 - limited free movement and employer transfer rights were introduced in 2021 for select categories.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "kafala_reform",
        "qiwa_platform",
        "musaned_platform",
        "gcc_mobility",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "saudi-arabia-pdpl-2021-personal-data",
    "title": "Personal Data Protection Law (PDPL) 2021 (Updated 2023) - Kingdom of Saudi Arabia",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Saudi Arabia Personal Data Protection Law (PDPL) 2021 establishes rules for the lawful processing of personal data, including requirements for consent, data subject rights, cross-border data transfers, and protection of sensitive data. It applies to all entities processing personal data within Saudi Arabia or processing data of Saudi residents, with enforcement by the Saudi Data & Artificial Intelligence Authority (SDAIA). Key obligations include lawful basis for processing, data minimization, and breach notification - see source document.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-privacy",
      "aicpa-soc2-cc-confidentiality",
      "uk-money-laundering-regulations-2017-amended"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "saudi-arabia-sfda-digital-health-2026",
    "title": "Saudi Arabia SFDA - Digital Health Technologies, AI Medical Devices & PDPL Health Data Rules (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The Saudi Food and Drug Authority (SFDA) regulates digital health technologies, Software as a Medical Device, and AI medical devices under the Medical Devices Law. Combined with the Personal Data Protection Law (PDPL), health data is treated as sensitive personal data requiring explicit consent, strict security controls, data localisation in KSA where required, breach notification to SFDA/NCA within 72 hours, and compliance with the National Health Information Platform (NHIP) interoperability standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "south-korea-mfds-digital-medical-products-act-2026"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "saudi-arabia-vision-2030-digital-economy-regulations",
    "title": "Saudi Arabia Vision 2030 Digital Economy Regulations - CITC Telecom and Cloud Regulations, SAMA Digital Payment Framework, NCA Cybersecurity Controls, SDAIA AI Governance, ZATCA E-Invoicing (FATOORAH) Phase 2 and CPLP Cloud Localisation Requirements",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulatory framework establishes mandatory compliance requirements for digital transformation initiatives under Saudi Arabia’s Vision 2030, including AI governance, cybersecurity, cloud localization, and e-invoicing. It applies to all public and private sector entities operating in critical digital infrastructure, financial services, and AI-driven systems within the Kingdom.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-national-cyber-strategy-2022-ncsc-baseline",
      "eu-data-governance-act-2022-cloud-data-sharing",
      "anthropic-responsible-scaling-policy-v2-1-2025"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "saudi-cma-capital-market-law-regulations",
    "title": "Capital Market Law, Royal Decree No. M/30 of 2 June 2003",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This law establishes the Saudi Capital Market Authority (CMA) and provides the comprehensive legal framework for the Saudi Arabian capital market, mandating strict prospectus disclosure for securities offerings (Article 42), prohibiting insider trading (Article 50) and market manipulation (Article 49), and granting the CMA extensive enforcement powers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "fatf-recommendation-16-travel-rule-crypto"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "saudi-ndmo-ai-ethics-principles-2023",
    "title": "Saudi Arabia SDAIA AI Ethics Principles - Seven Principles: Fairness; Privacy and Security; Humanity; Social and Environmental Benefits; Reliability and Safety; Transparency and Explainability; Accountability and Responsibility",
    "domain": "AI Governance & Law",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "The Saudi Data and Artificial Intelligence Authority (SDAIA) issues the AI Ethics Principles, a principles-based framework setting out seven core ethical principles for the development, deployment, and use of AI systems by stakeholders in Saudi Arabia: Fairness; Privacy and Security; Humanity; Social and Environmental Benefits; Reliability and Safety; Transparency and Explainability; and Accountability and Responsibility. The framework applies to all AI stakeholders across the full lifecycle of an AI project, from design and planning through deployment and monitoring, and is accompanied by controls and (in the 2.0 iteration) a tiered AI risk categorisation system with self-assessment tools. The Principles are issued by SDAIA; the National Data Management Office (NDMO) is a sub-office within SDAIA and is not the issuing authority for these Principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "g20-ai-principles-2019",
      "unesco-ethics-ai",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "saudi-ndmo-pdpl-2021-personal-data",
    "title": "Saudi Arabia Personal Data Protection Law (PDPL) Royal Decree M/19 of 9/2/1443H",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Saudi Personal Data Protection Law (PDPL), enforced by the Saudi Data & AI Authority (SDAIA) via the National Data Management Office (NDMO), governs the processing of personal data for individuals in Saudi Arabia. It mandates explicit consent as the primary legal basis for processing (Article 6) and establishes strict conditions for cross-border data transfers, requiring an adequacy assessment or specific safeguards (Article 29).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-privacy-guidelines-2013",
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-46-transfer-mechanisms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "saudi-rega-real-estate-general-authority-2021",
    "title": "Saudi Arabia Real Estate General Authority (REGA) - Licensing and Vision 2030 Framework",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Saudi Arabia's Real Estate General Authority (REGA), established by Royal Decree M/3 of 18 Safar 1443H (September 2021), is the unified regulator for real estate brokerage, development, facilities management, and real estate investment funds; mandates professional licensing through the Saudi Authority for Accredited Valuers (TAQEEM) and REGA-registered brokers; requires escrow accounts for off-plan sales; and supports Vision 2030 targets including 70% homeownership rate by 2030.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uae-rera-law-7-2007-real-estate-dubai"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "saudi-sama-cybersecurity-framework-2017",
    "title": "Saudi Arabian Monetary Authority (SAMA) Cybersecurity Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The SAMA Cybersecurity Framework mandates a comprehensive set of cybersecurity controls for all financial institutions regulated by the Saudi Arabian Monetary Authority (SAMA), including banks, insurance, and financing companies. As per Section 1.3, compliance is mandatory and requires organizations to identify and classify information assets, implement risk-based controls, and report on their cybersecurity posture to SAMA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27005-risk-management-2022",
      "nist-cybersecurity-framework-2-0",
      "pci-dss-v4-requirement-6",
      "basel-ii-capital-framework"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "saudi-sama-open-banking-policy-2022",
    "title": "Saudi SAMA Open Banking Policy 2022 - Third-Party Provider (TPP) Framework, Open Banking API Technical Standards, Customer Consent Management Architecture and SAMA Oversight for Saudi Open Banking Ecosystem",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-08-15",
    "bluf": "This policy mandates that banks in the Kingdom of Saudi Arabia provide Third-Party Providers (TPPs) with secure access to customer financial data via standardized APIs, subject to explicit customer consent. It establishes the technical, security, and operational framework for the Saudi Open Banking ecosystem, as detailed in Section 3, which outlines the roles and responsibilities of all participants.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-psd2-open-banking-api-standards",
      "eu-psd2-strong-customer-authentication",
      "iso-20022-mx-messaging",
      "nist-sp-800-207-zero-trust"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sb-ca-2009",
    "title": "Solomon Islands Communications Act 2009 - Consumer Data and Personal Information Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Solomon Islands enacted the Communications Act 2009, which establishes the Solomon Islands Telecommunications and Spectrum Authority (SITTA) as the regulatory authority for electronic communications services in the Solomon Islands and includes consumer data and personal information protection obligations applicable to licensed communications service providers. The Act requires licensed operators to protect the confidentiality of subscriber personal data including call records, billing information, and user account details, and prohibits the disclosure of customer personal information to third parties except where required by law or authorised by the subscriber. SITTA has authority to investigate complaints regarding misuse of personal data by licensed communications operators and to enforce compliance with consumer data protection requirements. The Solomon Islands do not have a standalone comprehensive personal data protection law, and the Communications Act 2009 together with constitutional protections under the Solomon Islands Constitution and common law privacy principles represents the primary legal framework for personal data protection in electronic communications services in the Solomon Islands. The Ministry of Communication and Aviation has policy oversight of digital and electronic communications matters.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/sb-ca-2009.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sbti-carbon-target",
    "title": "SBTi Carbon Target Validation",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Validating corporate greenhouse gas emissions reduction targets against the Science Based Targets initiative's rigorous framework necessitates a comprehensive assessment of inventory completeness, target ambition, and transparency. A foundational requirement is that `is_scope1_inventory_complete` and `is_scope2_inventory_complete` are both affirmative, establishing a robust emissions baseline. Furthermore, corporate climate accountability principles stipulate that if the `scope3_emissions_percentage` constitutes 40 percent or more of total emissions, then `is_scope3_target_required` becomes mandatory, compelling a thorough inventory and a separate reduction commitment for that category. The validation process also confirms that `is_base_year_defined` with precision, and the `near_term_target_year_horizon` is set for a period of 5 to 10 years from the point of submission. Central to this compliance check, as outlined in the Corporate Net-Zero Standard, is whether `is_target_aligned_1_5c`, ensuring the reduction pathway supports limiting global warming to 1.5°C above pre-industrial levels. For long-range planning, `has_long_term_net_zero_target` must be confirmed, with a specified `net_zero_target_year` of 2050 at the latest. Procedural integrity is maintained through verification that the entity `has_base_year_recalculation_policy` to address significant changes, and that `is_emissions_data_publicly_disclosed`, fulfilling key stakeholder transparency demands established by global best practices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ghg-protocol-scope3",
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sbti-net-zero-standard-2021",
    "title": "Science Based Targets initiative (SBTi) Corporate Net-Zero Standard",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The SBTi Corporate Net-Zero Standard requires companies to set both near-term and long-term science-based targets for rapid, deep emissions cuts across their value chain, in line with 1.5°C pathways. Under Criterion C1, companies must achieve these targets and neutralize any limited residual emissions with permanent carbon removals to be considered net-zero.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ghg-protocol-scope3",
      "iso-14064-ghg-quantify",
      "tcfd-climate-risk",
      "issb-ifrs-s2-climate-2023",
      "sbti-carbon-target"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sc-dpa-2003",
    "title": "Seychelles Data Protection Act - Commissioner Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Seychelles Data Protection Act (2003, as amended) establishes a consent-based framework for personal data processing, data subject rights including access and correction, and mandatory registration for data controllers. The Data Protection Commissioner is the designated supervisory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "scor-fulfill",
    "title": "SCOR DS: Fulfillment",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "SCOR DS (Supply Chain Operations Reference - Digital Standard) Fulfill covers all processes involved in executing customer orders from receipt through delivery and returns. Maintained by ASCM (Association for Supply Chain Management), SCOR DS defines a hierarchical process framework with standardized metrics at each level - enabling supply chain professionals and AI agents to benchmark performance, identify bottlenecks, and redesign fulfillment processes against best-in-class KPIs. The Fulfill process includes order management, warehouse operations, transportation, and last-mile delivery. Organizations with immature Fulfill processes exhibit high perfect order rates failures, elevated OTIF (On Time In Full) misses, and customer satisfaction scores below industry benchmarks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "scor-orchestrate",
      "warehouse-wms-optimization",
      "reverse-logistics-circular",
      "last-mile-algorithm-ethics",
      "gs1-epcis-transparency"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "scor-orchestrate",
    "title": "SCOR DS: Orchestration",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "SCOR DS Orchestrate is the meta-level planning process in the Supply Chain Operations Reference Digital Standard that coordinates strategy, governance, data flows, and performance management across all other SCOR processes (Plan, Source, Make, Deliver, Return, Enable). Unlike Plan, which is tactical, Orchestrate defines the rules, policies, and digital architecture that govern how a supply chain operates. ASCM introduced Orchestrate in SCOR DS to reflect the reality of digitally integrated supply chains where AI, IoT, and real-time data streams require explicit governance of how information is collected, interpreted, shared, and acted upon across supply chain partners.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-28000-supply-chain",
      "supply-chain-risk-triage",
      "iso-31000-risk-mgt-std",
      "gs1-epcis-transparency",
      "wco-safe-framework"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sd-eta-2007",
    "title": "Sudan Electronic Transactions Act 2007 - Personal Data Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Sudan enacted the Electronic Transactions Act 2007, which includes provisions for the protection of personal data processed in the context of electronic transactions and information systems. The Act is administered by the National Information Center (NIC) under the Ministry of Information and Communications Technology. It establishes obligations for electronic service providers to protect the personal data of users from unauthorised access and disclosure, requires consent from data subjects for the collection and processing of personal information in electronic transactions, and restricts the use of personal data to the declared transaction purpose. The Act represents Sudan's entry-level digital governance framework for personal data protection in electronic commerce and communications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/sd-eta-2007.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "se-dataskyddslagen-2018",
    "title": "Sweden Data Protection Act 2018 (Dataskyddslagen 2018:218) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Sweden's Data Protection Act (Dataskyddslagen, SFS 2018:218, enacted 19 April 2018, entered into force 25 May 2018) is the primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Sweden. The GDPR is directly applicable Swedish law by virtue of Sweden's EU membership. The Dataskyddslagen provides the national derogations, additions, and specifications that the GDPR permits EU member states to adopt. Enforcement: Integritetsskyddsmyndigheten (IMY - Swedish Authority for Privacy Protection, formerly known as Datainspektionen until its renaming in January 2021) is Sweden's independent data protection supervisory authority. IMY is Sweden's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Swedish national provisions: (1) Age of digital consent: the Dataskyddslagen does not lower the GDPR default age of 16 years for information society services - the age of consent in Sweden is 16 years (data subjects under 16 require parental consent for information society services); (2) Criminal data: Swedish law prohibits private entities from processing personal data relating to criminal convictions and offences without specific legal authorisation; public authorities may process such data under applicable law; (3) Employment context: the Dataskyddslagen contains provisions on the processing of personal data in employment contexts, aligned with the Swedish Co-Determination Act (Medbestämmandelagen) and other labour legislation; collective agreements may provide a legal basis for certain employment data processing; (4) Freedom of expression: Swedish constitutional protections for press freedom (Tryckfrihetsförordningen) and freedom of expression (Yttrandefrihetsgrundlagen) create broad exemptions from GDPR for journalistic, artistic, and literary processing; Sweden's constitutional protection for journalism is among the strongest in the EU; (5) Research and statistics: specific provisions permitting extended processing of personal data for scientific research, statistics, and archiving in the public interest, subject to appropriate safeguards; (6) Public interest: provisions on processing personal data for the exercise of official authority and in the public interest by public authorities. Fines: GDPR administrative fines apply in Sweden - up to EUR 20 million or 4% of global annual turnover for most serious violations. IMY has imposed significant GDPR fines, including against Klarna (SEK 7.5 million for facial recognition data), Google (SEK 75 million for right to be forgotten violations), and health region authorities for data security failures. Sweden has strong constitutional data protection - the right to information privacy is recognised under the Swedish Constitution (Regeringsformen).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "se-lou-2016-1145-offentlig-upphandling",
    "title": "Sweden Lag (2016:1145) om offentlig upphandling (LOU)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Lag (2016:1145) om offentlig upphandling (LOU) is the principal Swedish Public Procurement Act, in force from 1 January 2017 and transposing Directive 2014/24/EU. The Act is structured in 22 Kapitel. Kapitel 1 contains scope and definitions, including upphandlande myndighet (contracting authority) and leverantor (economic operator). Kapitel 4 establishes the foundational principles requiring contracting authorities to treat suppliers equally and on a non-discriminatory basis (likvardigt och icke-diskriminerande satt) and to conduct open processes respecting proportionality. Kapitel 6 sets out the five permitted procurement procedures: oppet forfarande (open procedure), selektivt forfarande (restricted procedure), forhandlat forfarande med foregaende annonsering (negotiated procedure with prior publication), forhandlat forfarande utan foregaende annonsering (negotiated procedure without prior publication) and konkurrenspraglad dialog (competitive dialogue). Kapitel 13 establishes grounds for excluding economic operators. Kapitel 14 sets the qualification criteria for suppliers regarding economic capacity and technical competence. Kapitel 16 governs tender evaluation and award of contracts. Kapitel 20 establishes the rattsmedel (remedies) regime including overproving (review proceedings) before the forvaltningsdomstolar (administrative courts), interim suspension of the procurement and damages liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-public-procurement-construction-directive",
      "uncitral-model-law-public-procurement-2011"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "se-marknadsforingslagen-2008-486",
    "title": "Sweden Marknadsforingslagen (Marketing Act) SFS 2008:486",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Marknadsforingslagen (SFS 2008:486) is Sweden's principal marketing statute, in force from 1 July 2008 and last materially amended by SFS 2022:656 transposing EU Omnibus Directive 2019/2161/EU. The Act transposes EU Directive 2005/29/EC Unfair Commercial Practices (UCPD) and EU Directive 2006/114/EC misleading and comparative advertising. Key sections: § 1 (syfte och inledande bestammelser - purpose: promote consumer and business interests and counter unfair marketing), § 3 (definitioner including konsument, naringsidkare, marknadsforing, kopuppmaning), § 5 (god marknadsforingssed - good marketing practice general clause), § 6 (otillborlig marknadsforing - unfair marketing materially affecting consumer transactional decision), § 7 (aggressiv marknadsforing - aggressive marketing including harassment, coercion, undue influence), § 8 (vilseledande marknadsforing - misleading marketing actions), § 9 (reklamidentifiering - marketing must be clearly identifiable and disclose sender), § 10 (vilseledande reklam - misleading advertising specific list), § 11 (vilseledande efterbildningar - misleading imitations), § 12 (vilseledande forpackningsstorlekar - misleading package sizes), § 13 (jamforande reklam - comparative advertising conditions), § 19 (obestalld reklam - prohibition of unsolicited electronic marketing without prior consent for email/SMS/fax to natural persons), §§ 23-26 (forbud and information injunctions), §§ 29-32 (marknadsstorningsavgift - market disruption fee up to 4 percent of annual turnover, ceiling EUR 2 million, transposed from CPC Regulation). Enforcement by Konsumentombudsmannen (Consumer Ombudsman) with the Konsumentverket as the supporting authority; cases before Patent- och marknadsdomstolen.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "no-markedsforingsloven-2009",
      "eu-unfair-commercial-practices-2005-29-2022-revision",
      "fr-code-consommation"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "sec-climate-disclosure",
    "title": "SEC Climate Disclosure Rule",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The SEC Climate Disclosure Rule (Final Rule 33-11275) mandates that U.S. public companies and foreign private issuers disclose climate-related risks, their financial impacts, and greenhouse gas (GHG) emissions (Scope 1 and 2 for large accelerated filers). It aims to provide investors with consistent, comparable, and reliable climate-related information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "tcfd-climate-risk",
      "issb-s1-s2-standard",
      "iso-14064-ghg-reporting"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sec-cybersecurity-risk-incident-disclosure",
    "title": "Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2023-09-05",
    "bluf": "The Securities and Exchange Commission is adopting new rules to enhance and standardize disclosures regarding cybersecurity risk management, strategy, governance, and incidents by public companies subject to the reporting requirements of the Securities Exchange Act of 1934. These amendments require current disclosure about material cybersecurity incidents via Form 8-K within four business days of determining an incident was material. The rules also mandate periodic disclosures in annual reports (Form 10-K) detailing a registrant’s processes to assess, identify, and manage material cybersecurity risks. This includes describing the board of directors’ oversight of cybersecurity risks and management’s role in assessing and managing such risks.\n\nThe final rules aim to address varied and inconsistent disclosure practices observed after prior Commission guidance. As the economic dependence on electronic systems grows, along with a substantial rise in the prevalence and costs of cybersecurity incidents, investors need more timely and reliable information. The rules are designed to ensure that investors receive consistent, comparable, and decision-useful information to assess the potential effects of a material cybersecurity incident on a registrant, including financial, operational, and reputational impacts. Disclosures are required to be presented in Inline eXtensible Business Reporting Language (Inline XBRL) to improve accessibility and analysis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt",
      "nist-ir-8286d-bia-for-risk",
      "nist-sp-800-100-security-handbook",
      "guide-computer-security-log-management",
      "malware-incident-prevention-handling"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sec-edgar-cybersecurity-disclosures-compliance-2026-18",
    "title": "SEC Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (Release Nos. 33-11216; 34-97989) - Regulation S-K Item 106 and Form 8-K Item 1.05",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "The SEC EDGAR Cybersecurity Disclosures require public companies to disclose material cybersecurity risks and incidents in a timely manner. Companies must assess and report on their cybersecurity policies and procedures, including risk management strategies and incident response plans. The disclosures should provide investors with relevant information about the company's cybersecurity posture, including any significant breaches that could impact financial performance. Companies are also required to describe their governance structures related to cybersecurity, detailing the role of management and the board of directors in overseeing cybersecurity risks. This regulation aims to enhance transparency and accountability in how companies manage cybersecurity threats and protect sensitive information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "sec-edgar-cybersecurity-disclosures-compliance-2026-3",
    "title": "SEC Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (Release Nos. 33-11216; 34-97989) - Regulation S-K Item 106 and Form 8-K Item 1.05",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "The SEC EDGAR Cybersecurity Disclosures require public companies to disclose material cybersecurity incidents and risks in a timely manner. Companies must assess and report on their cybersecurity governance, risk management practices, and the effectiveness of their internal controls. The disclosures should include details on the nature of incidents, their impact on operations, and the company's response strategies. Additionally, firms are expected to provide information on their cybersecurity policies and procedures, including any relevant board oversight. This standard aims to enhance transparency and protect investors by ensuring that they are informed about potential cybersecurity threats that could affect the financial health of the company.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "sec-reg-s-k-106",
    "title": "SEC Regulation S-K Item 106 (Cybersecurity)",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation S-K Item 106 mandates a comprehensive framework for cybersecurity disclosure, encompassing both incident reporting and governance oversight. Registrants must report material cybersecurity incidents on Form 8-K Item 1.05 within a maximum of four business days from determining an incident's materiality. This determination process itself must be defined, and it requires that related incidents are aggregated for materiality assessment. While a disclosure delay for national security is allowed under specific circumstances, the core obligation emphasizes timely public awareness. Annually, companies are compelled to provide extensive disclosures via Form 10-K Item 1C regarding their cybersecurity risk management and strategy. This annual filing must detail the processes for identifying and managing material risks from cybersecurity threats and describe how such threats are likely to affect the business, operations, and financial condition. Furthermore, the regulation requires transparent reporting on governance structures. Companies must describe the board's oversight process for cyber risks and also detail management's role in this area. A key component of this governance disclosure is identifying and describing management’s relevant cybersecurity expertise, ensuring investors have a clear view of the leadership's capability to handle these pervasive threats.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-8286c-staging-cybersecurity-risks",
      "sox-it-controls",
      "iso-31000-risk-mgt-std",
      "security-considerations-system-development-lifecycle"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sec-regulation-best-interest",
    "title": "Regulation Best Interest: The Broker-Dealer Standard of Conduct",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2019-09-10",
    "bluf": "The Securities and Exchange Commission (SEC) is adopting Regulation Best Interest, a new rule under the Securities Exchange Act of 1934 that establishes a standard of conduct for broker-dealers and their associated persons when they make a recommendation to a retail customer of any securities transaction or investment strategy involving securities. This regulation enhances the broker-dealer standard of conduct beyond existing suitability obligations and aligns the standard with retail customers’ reasonable expectations. The core obligation requires broker-dealers to act in the best interest of the retail customer at the time the recommendation is made, without placing the financial or other interest of the broker-dealer ahead of the interests of the retail customer.\n\nThe General Obligation is satisfied only if the broker-dealer complies with four specified component obligations: (1) a Disclosure Obligation, requiring written disclosure of material facts about the relationship and recommendation; (2) a Care Obligation, requiring the exercise of reasonable diligence, care, and skill; (3) a Conflict of Interest Obligation, requiring the establishment of policies and procedures to address, and in some cases mitigate or eliminate, conflicts of interest; and (4) a Compliance Obligation, requiring policies and procedures to achieve compliance with the regulation as a whole. The standard of conduct established by Regulation Best Interest cannot be satisfied through disclosure alone and draws from key principles underlying fiduciary obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "finra-3110-supervision"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "sec-regulation-s-p-safeguarding",
    "title": "Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-08-02",
    "bluf": "The Securities and Exchange Commission is adopting rule amendments to Regulation S-P that are designed to modernize and enhance the protections that Regulation S-P provides by addressing the expanded use of technology and corresponding risks that have emerged since its original adoption. The amendments apply to brokers and dealers, investment companies, registered investment advisers, funding portals, and transfer agents registered with the Commission. These institutions are required to adopt written policies and procedures for an incident response program to address unauthorized access to or use of customer information.\n\nThe core of the amendments requires these covered institutions' incident response programs to be reasonably designed to detect, respond to, and recover from such incidents. This includes procedures for providing timely notification to individuals affected by an incident involving sensitive customer information. Notice must be provided as soon as practicable, but not later than 30 days after becoming aware that an incident occurred or is reasonably likely to have occurred. Notification is not required if the institution determines, after a reasonable investigation, that the sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience. The amendments also extend the scope of the safeguards and disposal rules to cover all transfer agents and broaden the scope of information protected.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-1800-28-data-confidentiality",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sec-rule-13p-1-conflict-minerals-dodd-frank-1502",
    "title": "SEC Rule 13p-1 - Conflict Minerals Disclosure (Dodd-Frank Act Section 1502)",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "SEC Rule 13p-1, implementing Section 1502 of the Dodd-Frank Wall Street Reform and Consumer Protection Act, requires SEC reporting companies that manufacture or contract to manufacture products for which conflict minerals (tin, tantalum, tungsten, and gold - 3TG) are necessary to their functionality or production, to conduct a reasonable country of origin inquiry, perform supply chain due diligence conforming to an internationally recognised framework where 3TG may originate from the Democratic Republic of Congo or adjoining countries, and file an annual Conflict Minerals Report on Form SD by 31 May each year.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dodd-frank-act-2010"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "secondary-use-health-data-governance-2026",
    "title": "Secondary Use of Health Data - Governance, Ethics & Compliance Framework (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Secondary use of health data (research, AI training, public health, commercial purposes) requires robust governance including lawful basis assessment, transparency, data minimisation, pseudonymisation, ethics review, and patient opt-out mechanisms where applicable. Frameworks like EHDS, GDPR Article 89, and national laws demand clear policies, impact assessments, and benefit-sharing considerations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "secure-hash-standard-fips-180-4",
    "title": "Secure Hash Standard (SHS)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2015-08-01",
    "bluf": "This Standard specifies secure hash algorithms - SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224 and SHA-512/256 - for computing a condensed representation of electronic data (message) called a message digest. The digests are used to detect whether messages have been changed since the digests were generated. The hash algorithms specified are called secure because, for a given algorithm, it is computationally infeasible to find a message that corresponds to a given message digest, or to find two different messages that produce the same message digest. Any change to a message will, with a very high probability, result in a different message digest.\n\nThis Standard is applicable to all Federal departments and agencies for the protection of sensitive unclassified information. Either this Standard or Federal Information Processing Standard (FIPS) 202 must be implemented wherever a secure hash algorithm is required for Federal applications, including as a component within other cryptographic algorithms and protocols. The secure hash algorithms may be implemented in software, firmware, hardware or any combination thereof, but only algorithm implementations that are validated by NIST will be considered as complying with this standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "nist-sp-800-53-r5",
      "nist-fips-186-5-dss",
      "nist-sp-800-131a-rev-2-crypto-transitions",
      "nist-sp-800-57-key-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "securing-property-management-systems",
    "title": "Securing Property Management Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2021-03-01",
    "bluf": "In recent years criminals and other attackers have compromised the networks of several major hotel chains, exposing the information of hundreds of millions of guests. Hospitality organizations can reduce the likelihood of a hotel data breach by strengthening the cybersecurity of their property management system (PMS). This cybersecurity practice guide shows an approach to securing a PMS and the system of guest services it supports. It offers how-to guidance for building a reference design using commercially available products within a zero trust architecture to mitigate cybersecurity risk. The PMS is an attractive target for attackers because it serves as the information technology (IT) operations and data management hub of a hotel, interfacing with services like point-of-sale (POS) systems, physical access control, and Wi-Fi networks. An unsecured or poorly secured PMS could expose a hotel to a significant and costly data breach, which may result in financial penalties for violating state, federal, and international privacy and other regulatory regimes.\nThis guide provides a reference design that uses technologies and security capabilities to protect data and limit user access. The principal recommendations include implementing cybersecurity concepts such as zero trust architecture, moving target defense, tokenization of credit card data, and role-based authentication. The solution supports security standards from the National Institute of Standards and Technology (NIST) Cybersecurity Framework, Hospitality Technology Next Generation, and the Payment Card Industry (PCI) Security Standards Council. The core objective is to prevent unauthorized access via role-based authentication, protect from unauthorized lateral movement, prevent theft of credit card data via tokenization, increase situational awareness through logging, and prevent unauthorized use of personal information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-63b-authentication",
      "nist-sp-800-181r1-nice-framework",
      "nist-sp-800-207",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "security-considerations-system-development-lifecycle",
    "title": "Security Considerations in the System Development Life Cycle",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-05-31",
    "bluf": "The National Institute of Standards and Technology (NIST) Special Publication (SP) 800-64, Security Considerations in the System Development Life Cycle, was developed to assist federal government agencies in integrating essential information technology (IT) security steps into their established IT system development life cycle (SDLC). This guideline applies to all federal IT systems other than national security systems and is intended for an audience of information system and information security professionals, including system owners, developers, and program managers.\n\nTo be most effective, information security must be integrated into the SDLC from system inception. Early integration of security enables agencies to maximize return on investment in their security programs through the early identification and mitigation of security vulnerabilities, resulting in a lower cost of security control implementation. The core obligation is to incorporate security considerations into each phase of the SDLC-initiation, development/acquisition, implementation/assessment, operations/maintenance, and disposal-to facilitate informed executive decision-making through comprehensive risk management in a timely manner.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-30-risk-assessment",
      "nist-sp-800-39-managing-risk",
      "nist-sp-800-53-r5",
      "nist-sp-800-60-v2r1-appendices",
      "fips-199-security-categorization"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "security-focused-configuration-management",
    "title": "Guide for Security-Focused Configuration Management of Information Systems",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2019-10-10",
    "bluf": "This guide provides guidelines for organizations responsible for managing and administering the security of federal information systems. It assumes that information security is an integral part of an organization’s overall configuration management, with a focus on implementing the security aspects of configuration management, termed security-focused configuration management (SecCM). SecCM is defined as the management and control of configurations for information systems to enable security, facilitate the management of information security risk, and minimize organizational risk while supporting desired business functionality and services. Implementing system changes almost always results in adjustments to the system configuration; therefore, a well-defined configuration management process that integrates information security is needed to ensure these adjustments do not adversely affect the security of the system.\n\nThe process of applying SecCM practices involves managing and monitoring system configurations to achieve adequate security. This publication is applicable to all federal information systems, excluding national security systems, and is intended for a diverse audience, including individuals with system security management, development, implementation, and assessment responsibilities. The core obligation is to establish and maintain the integrity of systems through control of the processes for initializing, changing, and monitoring their configurations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-30-risk-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "security-segmentation-small-manufacturing",
    "title": "Security Segmentation in a Small Manufacturing Environment",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2023-04-06",
    "bluf": "Manufacturers are increasingly targeted in cyber-attacks. Small manufacturers are particularly vulnerable due to limitations in staff and resources to operate facilities and manage cybersecurity. This paper introduces security segmentation as a cost-effective and efficient approach to mitigate cyber vulnerabilities for small manufacturing environments. Security segmentation is the grouping of assets into security zones according to the cyber protection they need and placing appropriate safeguards around these security zones. It is an approach for protecting assets by grouping them based on both their communication and security requirements.\n\nThe intended audience is managers of information technology and operational technology (IT/OT) systems at small manufacturing organizations, including roles like company owner, operations manager, and technical resources such as network and security architects. The core obligation is to follow a six-step approach: 1) identify a list of assets, 2) assess risk and create security zones, 3) determine the risk level for the security zones, 4) map communications between the security zones, 5) determine security controls for the security zones, and 6) create a logical security architecture diagram. The security architecture resulting from these activities serves as a foundational preparation step for additional security strategies like Zero Trust.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-iacs",
      "nistir-8259-iot-device-manufacturers",
      "nist-sp-800-41-r1-firewalls",
      "nist-sp-800-205-access-control"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "seoul-ai-safety-summit-2024",
    "title": "Seoul AI Safety Summit 2024 - Ministerial Declaration and Frontier AI Safety Commitments",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The second international AI Safety Summit, co-hosted by South Korea and the United Kingdom on 21-22 May 2024 in Seoul, produced the Seoul Ministerial Declaration on Advancing AI Safety, Innovation, and Inclusivity - signed by 27 countries; the Seoul Summit advanced the Bletchley Process through three concrete outputs: (1) the Seoul Ministerial Statement expanding international commitments on AI safety research, international cooperation frameworks, and AI governance capacity building for developing nations; (2) the updated 'Seoul Frontier AI Safety Commitments' signed by 16 major AI companies (Anthropic, Google DeepMind, Amazon, Meta, Microsoft, OpenAI, xAI, Inflection, Samsung Research, Zhipu AI, Technology Innovation Institute, Cohere, Naver, G42, Scale AI, Mistral AI) with strengthened obligations on safety evaluations, dangerous capability thresholds, and structured access to safety testing tools; and (3) the 'Seoul Statement of Intent' establishing a network of AI Safety Institutes (AISIs) for collaborative frontier AI evaluation - with national AISIs from the UK, USA, Japan, Singapore, France, Germany, Canada, South Korea, and Australia committing to joint evaluations; the Seoul Summit also addressed AI's role in scientific research and innovation, moving beyond the Bletchley Declaration's exclusive focus on catastrophic risk to include inclusive and beneficial AI development.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/seoul-ai-safety-summit-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-ai-safety-2023",
      "eu-ai-act-2024",
      "eu-ai-act-article-55-systemic-risk-gpai",
      "eu-ai-act-article-53-gpai-codes-of-practice",
      "uk-ai-safety-institute-framework-2023",
      "g7-hiroshima-ai-process-guiding-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "seoul-declaration-ai-summit-2024-frontier-safety-commitments",
    "title": "Seoul Declaration for Safe, Innovative and Inclusive AI (AI Seoul Summit, 21-22 May 2024) - Frontier AI Safety Commitments and Network of AI Safety Institutes",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "The Seoul Declaration for Safe, Innovative and Inclusive AI was adopted by leaders at the AI Seoul Summit on 21-22 May 2024, co-hosted by the Republic of Korea and the United Kingdom as the follow-on to the November 2023 Bletchley AI Safety Summit. The Declaration is the leaders-level political commitment to a coordinated international approach to frontier AI safety, innovation, and inclusion. It is accompanied by the Seoul Statement of Intent toward International Cooperation on AI Safety Science which establishes a network of AI Safety Institutes (now including UK AISI, US AISI, Japan AISI, Singapore AISI, Canada AISI, EU AI Office, and Korea AISI) and the Frontier AI Safety Commitments signed by 16 leading AI companies (Anthropic, Google, OpenAI, Microsoft, Meta, IBM, Amazon, Mistral, Cohere, xAI, Inflection, Naver, Samsung Electronics, Tencent, Zhipu AI, and the Technology Innovation Institute) which require companies to publish safety frameworks, define risk thresholds beyond which model deployment is paused, and engage in international scientific cooperation. The Seoul Summit sits between Bletchley (November 2023) and Paris (February 2025).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-ai-safety-2023",
      "uk-ai-safety-institute-framework-2024",
      "us-ai-safety-institute-nist-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sfdr-regulation-article-10-transparency-environmental-social-characteristics-periodic",
    "title": "Sustainable Finance Disclosure Regulation (SFDR) - Article 10: Transparency of the promotion of environmental or social characteristics and of sustainable investments on websites",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Financial market participants must publish and maintain specific information on their websites for each financial product that promotes environmental or social characteristics or has sustainable investment objectives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "sfdr-regulation-article-11-transparency-sustainable-investment-periodic",
    "title": "Sustainable Finance Disclosure Regulation (SFDR) Article 11: Transparency of the promotion of environmental or social characteristics and of sustainable investments in periodic reports",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Financial market participants offering products that promote environmental or social characteristics, or have sustainable investment objectives, must include specific descriptions of their sustainability performance in periodic reports.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "sfdr-regulation-article-12-review",
    "title": "Regulation (EU) 2019/2088 on sustainability-related disclosures in the financial services sector - Article 12: Review of disclosures",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article specifies reporting obligations for managers of qualifying social entrepreneurship funds within their annual report.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "sfdr-regulation-article-13-website-disclosures",
    "title": "Regulation (EU) No 345/2013, Article 13(1)(e): Information Provision for Managers of Qualifying Social Entrepreneurship Funds",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Managers of qualifying social entrepreneurship funds must adhere to specific requirements for the provision of information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "sfdr-regulation-article-14-penalties",
    "title": "Regulation (EU) 2019/2088 on sustainability-related disclosures in the financial services sector - Article 14: Administrative penalties and other administrative measures",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires Member States to establish rules for effective, proportionate, and dissuasive administrative penalties and measures for infringements of the regulation, empowering competent authorities to impose sanctions such as public statements, cease and desist orders, temporary bans, and significant pecuniary penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "sfdr-regulation-article-2-definitions",
    "title": "Regulation (EU) 2019/2088 on sustainability-related disclosures in the financial services sector - Article 2, Definitions",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes key definitions for terms such as 'sustainability risk' and 'sustainability factors' that must be used consistently for all compliance activities under this regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "sfdr-regulation-article-3-transparency-sustainability-risk-policies",
    "title": "Regulation (EU) 2019/2088 - Article 3: Transparency of sustainability risk policies",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Financial market participants and financial advisers must publish on their websites their policies on integrating sustainability risks into their investment decision-making or advisory processes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "sfdr-regulation-article-4-transparency-adverse-sustainability-impacts",
    "title": "Regulation (EU) 2019/2088 on sustainability-related disclosures in the financial services sector - Article 4: Definitions",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes key definitions for financial entities, including 'alternative investment fund manager', 'investment firm', and 'institution for occupational retirement provision', which are foundational for determining the scope of sustainability disclosure obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "sfdr-regulation-article-5-transparency-in-remuneration-policies",
    "title": "Regulation (EU) 2019/2088 on sustainability-related disclosures in the financial services sector - Article 5",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article provides key definitions for terms including 'pension product', 'pan-European Personal Pension Product (PEPP)', 'UCITS management company', and 'financial adviser' to ensure consistent application within the regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "sfdr-regulation-article-6-transparency-pre-contractual-disclosures",
    "title": "Regulation (EU) 2019/2088 on sustainability-related disclosures in the financial services sector - Articles 6, 15, 16, 17",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation requires financial market participants, including IORPs and insurance intermediaries, to publish and maintain specific sustainability-related information, while allowing Member States to optionally apply the regulation to certain pension products and exempt smaller firms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "sfdr-regulation-article-7-transparency-at-entity-level",
    "title": "Regulation (EU) 2019/2088 on sustainability-related disclosures in the financial services sector - Article 7: Transparency of adverse sustainability impacts at financial product level",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article requires financial market participants to disclose, at the financial product level, whether and how they consider principal adverse impacts on sustainability factors, or to explain why they do not.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "sfdr-regulation-article-8-transparency-products-promoting-characteristics",
    "title": "Regulation (EU) 2019/2088 - Article 8: Transparency of the promotion of environmental or social characteristics in pre‐contractual disclosures",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Financial market participants promoting environmental or social characteristics in a financial product must provide pre-contractual disclosures on how these characteristics are met and, if a benchmark is used, how it is consistent with them.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "sfdr-regulation-article-9-transparency-sustainable-investment-products",
    "title": "Regulation (EU) 2019/2088 of the European Parliament and of the Council - Article 9: Transparency of sustainable investments in pre‐contractual disclosures",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that financial market participants provide specific pre-contractual disclosures for financial products with sustainable investment objectives, detailing how those objectives are met, especially concerning the alignment and methodology of any designated benchmarks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-banking-act-part-vii-bank-customer-confidentiality",
    "title": "Banking Act 1970 - Part VII: Powers of Control Over Banks, Etc.",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article mandates that banks must comply with Authority directives on interest rates and investments, facilitate inspections, report adverse developments and potential insolvency, maintain strict customer information confidentiality, and secure approval for key executive appointments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "sg-companies-act-1967",
    "title": "Singapore Companies Act 1967 (Cap. 50) - Corporate Governance and Director Duties",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Companies Act 1967 (Cap. 50) is Singapore's primary legislation governing the formation, administration, and winding up of companies, administered by the Accounting and Corporate Regulatory Authority (ACRA). Section 157 imposes the core director duties: every director must at all times act honestly and use reasonable diligence in the discharge of the duties of his office; and must not use his position or any information obtained by virtue of his position to gain, directly or indirectly, an advantage for himself or for any other person, or to cause detriment to the company. Section 156 requires any director who is in any way, directly or indirectly, interested in a proposed transaction or arrangement with the company to declare the nature of his interest at the earliest opportunity. The oppression remedy under Section 216 permits any member or holder of debentures to apply to the court for relief where the affairs of the company are being conducted in a manner oppressive to any member or debenture holder or in disregard of his interests as a member or debenture holder. Section 216A provides for derivative actions by members on behalf of the company. The Companies (Amendment) Act 2017 introduced significant reforms including the abolition of par value for shares, the introduction of a mandatory resident director requirement, enhanced beneficial ownership transparency (register of controllers), and the abolition of the common seal requirement. ACRA administers the Bizfile+ public registry of companies, directors, and officers. Public companies are subject to additional requirements under the Singapore Exchange Listing Rules administered by the Singapore Exchange (SGX).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-pdpa-2012"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sg-competition-act-2004",
    "title": "Singapore Competition Act 2004 (Cap. 50B) - Antitrust and Market Competition",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Competition Act 2004 (Cap. 50B) promotes and maintains competitive markets in Singapore, prohibiting anti-competitive agreements and abuses of dominant position, and administered by the Competition and Consumer Commission of Singapore (CCCS, formerly the Competition Commission of Singapore). Section 34 (the Section 34 Prohibition) prohibits agreements between undertakings, decisions by associations of undertakings, and concerted practices that have as their object or effect the prevention, restriction, or distortion of competition within Singapore, including price-fixing, market allocation, bid-rigging, and output restriction. Section 47 (the Section 47 Prohibition) prohibits conduct by one or more undertakings that amounts to the abuse of a dominant position in any market in Singapore, including predatory pricing, excessive pricing, discriminatory pricing, exclusive dealing, and tying arrangements. The Competition (Amendment) Act 2018 introduced a merger regime with mandatory notification for transactions that result in a substantial lessening of competition in Singapore under s. 54, with pre-notification mandatory for transactions meeting prescribed thresholds. CCCS may impose financial penalties of up to 10% of the infringing undertaking's turnover in Singapore for each year of the infringement, up to a maximum of three years, for breaches of the Section 34 or Section 47 Prohibition. A leniency programme for cartel participants is available under CCCS's leniency policy. The Competition (Amendment) Act 2022 introduced the consumer protection provisions (Part IIIA) addressing unfair practices against consumers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-tfeu-article-102-abuse-of-dominance",
      "us-ftc-act-section-5-unfair-competition"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sg-competition-act-2004-cap-50b-anticompetitive-agreements-dominance",
    "title": "SG Competition Act 2004 - Anticompetitive Agreements, Abuse of Dominance, and Merger Notifications",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2022-01-01",
    "bluf": "Singapore's Competition Act 2004 (Cap. 50B) prohibits agreements that significantly prevent, restrict, or distort competition (Section 34), abuse of dominant position (Section 47), and mergers that substantially lessen competition (Section 54), enforced by the Competition and Consumer Commission of Singapore (CCCS) with financial penalties up to 10% of Singapore turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-personal-data-protection-act-2012-pdpa-cybersecurity-obligations",
      "sg-employment-act-1968"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-competition-act-2004-section-34-prohibition-anti-competitive-agreements",
    "title": "Competition Act 2004 - Section 34: Agreements, etc., preventing, restricting or distorting competition",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations are prohibited from making or giving effect to agreements, decisions by associations of undertakings, or concerted practices which have as their object or effect the prevention, restriction, or distortion of competition within Singapore.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "sg-competition-act-part-ii-prohibited-agreements-sg",
    "title": "Competition Act 2004, Part 2: Competition and Consumer Commission of Singapore",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must recognize the authority of the Competition and Consumer Commission of Singapore, comply with its operational and informational requirements, and adhere to prohibitions regarding the use of its official representations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "sg-cpfta-consumer-protection-fair-trading-act-2003",
    "title": "Singapore Consumer Protection (Fair Trading) Act 2003 (Cap. 52A) - Unfair Practices, Consumer Right to Sue and CCCS Enforcement",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "Singapore's Consumer Protection (Fair Trading) Act 2003 (CPFTA, originally Cap. 52A; revised edition 2021) is the principal statute regulating unfair practices by suppliers against consumers. The Act establishes a broad standard of unfair practice and provides consumers with a private right of action against suppliers, in parallel with administrative enforcement by the Competition and Consumer Commission of Singapore (CCCS, the successor regulator following the 2018 merger of the Competition Commission and the consumer protection function). Section 4 (Meaning of unfair practice) defines a supplier's conduct as an unfair practice where the supplier does or says anything (including failing to do or say anything) that has the effect or may have the effect of deceiving or misleading a consumer, or where the supplier makes a false claim, or where the supplier takes advantage of a consumer who is not in a position reasonably to protect their interests, or where the supplier does anything specified in the Second Schedule. The Second Schedule contains a list of specific unfair practices including representations that goods or services have characteristics they do not have, false statements about the supplier's identity or status, false statements about availability, bait-and-switch practices, pressure selling, false statements about the price advantage, undisclosed material terms and aggressive practices. Section 5 (Circumstances surrounding unfair practice) provides that, in determining whether a person has engaged in an unfair practice, the regard is to be had to the reasonable consumer in the circumstances of the case. Section 6 (Consumer's right to sue for unfair practice) authorises a consumer to commence civil action in the Magistrates' Court (for claims up to SGD 30,000) or the District Court (for claims up to SGD 250,000); the court may award damages, restitution, specific performance, injunctive relief, or the cancellation of any contract entered into as a result of the unfair practice. Sections 8 and 9 provide cooling-off rights for direct-sales contracts. Part III of the Act (introduced by the 2017 amendments and operationalised in 2018) authorises CCCS to investigate persistent suppliers engaged in unfair practices and apply to court for declaration and injunction; CCCS may also accept voluntary compliance agreements (VCAs). Section 17 of the CPFTA (as amended by Act 30 of 2017) imposes sanctions on persistent non-compliers; sanctions include injunctive relief and fines reaching SGD 10,000 per offence for the most serious breaches. The Act operates alongside the Consumer Protection (Trade Descriptions and Safety Requirements) Act, the Sale of Goods Act 1979 (incorporated into Singapore law), the Misrepresentation Act, and sectoral consumer protection regimes under the Monetary Authority of Singapore (financial services), the Infocomm Media Development Authority (telecommunications and media), and the Land Transport Authority (mobility services). The Advertising Standards Authority of Singapore (ASAS, a self-regulatory body) administers the Singapore Code of Advertising Practice in parallel with the CPFTA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "unfair_practice_definition_anchor",
        "second_schedule_anchor",
        "consumer_right_to_sue_anchor",
        "cccs_enforcement_anchor",
        "cooling_off_anchor",
        "industry_mapping",
        "advertising_self_regulation_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-payment-services-act-2019",
      "us-ftc-act-section-5-15-usc-45-unfair-deceptive-practices",
      "eu-unfair-commercial-practices-directive-2005-29-ec-advertising"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "sg-csa-cls-iot-labelling-scheme",
    "title": "Singapore CSA Cybersecurity Labelling Scheme for Consumer IoT, CLS(IoT)",
    "domain": "Industrial IoT & Energy",
    "version": "2.0.0",
    "last_updated": "2026-07-10",
    "bluf": "The Cyber Security Agency of Singapore (CSA) Cybersecurity Labelling Scheme for consumer IoT, CLS(IoT), comprises four cybersecurity levels corresponding to the number of asterisks on the label, with four assessment tiers completed in sequence; a product rated CLS Level 3 undergoes assessments at Tiers 1, 2 and 3. Tier 1 requires baseline security based on ETSI EN 303 645, eliminating common mistakes such as default passwords, ensuring the availability of security updates and implementing means to manage vulnerability reporting. Tier 2 requires adherence to all mandatory requirements within ETSI EN 303 645. Tier 3 requires security considerations based on the IMDA IoT Cyber Security Guide in the development lifecycle (threat modelling, secure engineering approach, secure supply chain, security testing) plus evaluation of the device software by a test laboratory using automated binary analysers. Tier 4 requires penetration testing by a test laboratory to provide a basic level of resistance against common cybersecurity attacks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "etsi-en-303-645-iot-cybersecurity-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sg-cybersecurity-act-2018",
    "title": "Singapore Cybersecurity Act 2018 (Cap. 9D, 2024 Amendment) - CII Protection and Licensing",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This Act establishes a legal framework for the oversight and maintenance of national cybersecurity in Singapore, imposing duties on owners of Critical Information Infrastructure (CII) to secure their systems and report incidents (Part 3, Section 14), and requiring the licensing of specific cybersecurity service providers (Part 5, Section 24).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0",
      "iso-31000-risk-mgt-std",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sg-cybersecurity-act-2018-critical-information-infrastructure-protection",
    "title": "Singapore Cybersecurity Act 2018 - Critical Information Infrastructure Protection and Incident Reporting",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Cybersecurity Act 2018 (Singapore) designates Critical Information Infrastructure (CII) across 11 essential service sectors, mandates compliance with cybersecurity codes of practice, requires mandatory incident reporting to the Commissioner of Cybersecurity within 2 hours of discovery, authorises cybersecurity audits, and empowers the Commissioner to direct owners to take protective measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-cybersecurity-framework-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-cybersecurity-act-2018-part-4-critical-information",
    "title": "Cybersecurity Act 2018 - Part 4 RESPONSES TO CYBERSECURITY THREATS AND INCIDENTS",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must comply with directions from the Commissioner of Cybersecurity and incident response officers during the investigation and remediation of cybersecurity threats and incidents, including providing information, assistance, and system access.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sg-cybersecurity-act-2018-part-4-critical-information-infrastructure-obligations",
    "title": "Singapore Cybersecurity Act 2018 (Act 9 of 2018) - Critical Information Infrastructure Owner Obligations",
    "domain": "Cybersecurity",
    "version": "2.0.0",
    "last_updated": "2026-07-01",
    "bluf": "The Cybersecurity Act 2018 (Act 9 of 2018) requires owners of designated Critical Information Infrastructure (CII) in Singapore to comply with obligations enforced by the Commissioner of Cybersecurity. Following the Cybersecurity (Amendment) Act 2024, provider-owned CII obligations sit in Part 3: owners must furnish information on request, notify changes in ownership, report cybersecurity incidents within the prescribed period, conduct cybersecurity audits and risk assessments at the prescribed intervals, comply with written directions and applicable codes of practice, and participate in cybersecurity exercises.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "sg-cybersecurity-amendment-2024",
    "title": "Singapore Cybersecurity (Amendment) Act 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Singapore's Cybersecurity (Amendment) Act 2024 expands the Cybersecurity Act 2018 to regulate Foundational Digital Infrastructure (FDI) service providers - including cloud services and data centres - imposing mandatory licensing, incident reporting, and security obligations on infrastructure deemed essential to Singapore's digital economy, and introduces a new framework for Systems of Temporary Cybersecurity Concern (STTC) allowing the Commissioner to designate high-risk systems for temporary enhanced monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/sg-cybersecurity-amendment-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-cybersecurity-act-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sg-education-act-2022-schools-moe-framework-private-education",
    "title": "Singapore Private Education Act 2009 - CPE Registration and Quality Standards for Private Education Institutions",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Private Education Act 2009 (Cap. 247A) establishes the Council for Private Education (CPE) as the statutory body regulating private education institutions (PEIs) in Singapore. PEIs must be CPE-registered, enter Fee Protection Schemes (FPS) for students, and comply with the EduTrust certification scheme for quality assurance. International student recruitment is regulated under the ICA Student Pass system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-personal-data-protection-act-2012-pdpa-cybersecurity-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-employment-act-1968",
    "title": "Employment Act 1968 (Chapter 91) of Singapore - Core Provisions for All Employees: Rest Days, Leave and Termination (2019 Amendments)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Singapore Employment Act 1968, as amended, mandates core employment provisions for all employees, including managers and executives. It establishes minimum requirements for rest days (Part IV, Section 36), paid annual and sick leave (Part IV, Sections 43 & 89), and statutory notice periods for contract termination (Part II, Section 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "sa8000-social-account",
      "iso-26000-social-resp-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sg-employment-act-1968-ea-core-terms-all-employees",
    "title": "Singapore Employment Act 1968 - Core Employment Terms and Protections for All Employees",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Singapore Employment Act 1968 (Cap. 91A) as amended in 2019 extended core protections to all employees regardless of salary. All employees are entitled to: itemised payslips, written key employment terms within 14 days of employment, sick leave entitlements, maternity/paternity protections under related Acts, and protection from wrongful dismissal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-personal-data-protection-act-2012-pdpa-cybersecurity-obligations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-employment-act-part-iv-rest-days-hours-work",
    "title": "Extradition Act 1968",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This Act outlines the legal framework and procedures for the extradition of fugitives to and from Singapore, including restrictions on surrender, the issuance of warrants, and the rights of surrendered persons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "sg-food-safety-and-security-act-2025",
    "title": "Singapore Food Safety and Security Act 2025 (No. 7 of 2025)",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "The Food Safety and Security Act 2025 (No. 7 of 2025) is Singapore's consolidated food safety and food security statute, administered under the Singapore Food Agency framework. It defines unsafe food (section 11), unsuitable food (section 12) and licensable food business (section 6); Part 2 strengthens the resilience of food supplies in Singapore, including the minimum stockholding requirement (MSR) regime in sections 20 and 21; Part 3 creates import, export and transhipment offences including importing prohibited food (section 45), unlicensed import of an import-controlled item (section 47) and importing a non-conforming consignment of an import-controlled item (section 49), each with a strict liability variant; Part 4 governs food businesses, including criteria, conditions, validity and regulatory action for food business licences (sections 92 to 97) and traceability obligations for licensable food businesses (Division 3); Part 5 covers defined food and pre-market approval; Part 8 creates offences relating to food safety, including handling food in an unsafe manner (section 144), supplying unsafe food (section 146) and supplying unsuitable food (section 150), each with strict liability variants; and Parts 13 and 14 provide monitoring, enforcement and administration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "singapore-food-agency-act-2019",
      "sg-singapore-food-agency-food-regulations-cap-283-food-safety"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sg-fsma-part-9-dtsp-2025",
    "title": "Singapore FSMA 2022 Part 9 - Digital Token Service Providers (DTSP) Licensing Regime",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Part 9 of Singapore's Financial Services and Markets Act 2022 (Act 18 of 2022) commenced on 30 June 2025 and creates a Monetary Authority of Singapore (MAS) licensing regime for Digital Token Service Providers (DTSPs) carrying on business of providing any digital token service listed in the First Schedule. Section 137 prohibits unlicensed DTSP business. Section 138 governs licence applications; Section 139 prohibits holding out as licensee; Section 140 governs annual fees; Section 141 covers lapsing, surrender, revocation or suspension; Section 142 sets appeals to the Minister. Conduct of business obligations (Subdivision 2) cover place of business (Section 143), notification of certain events (Section 144), provision of information (Section 145), periodic reports (Section 146), and prohibition on certain other businesses (Section 147). Subdivision 3 (Sections 148-154) controls shareholders/controllers; Subdivision 4 (Sections 155-157) controls CEO, directors, partners and managers; Subdivision 5 (Sections 158-161) covers audit obligations. Division 3 sets offences for falsification (Section 162) and general penalty (Section 163). The Second Schedule lists excluded persons. The regime applies to DTSPs operating from Singapore even when services are provided to overseas customers - closing a previously open jurisdictional gap.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "singapore_payment_services_act_2019",
        "singapore_mas_stablecoin_regulatory_framework_2023",
        "fatf_r15_virtual_asset_service_providers",
        "hk_stablecoins_ordinance_2025",
        "mica_eu_markets_in_crypto_assets_2023_1114"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "singapore-mas-payment-services-act-2019-dpt",
      "singapore-mas-stablecoin-regulatory-framework-2023",
      "fatf-virtual-asset-redfl",
      "fatf-recommendation-16-travel-rule-crypto"
    ],
    "primary_citations_count": 26
  },
  {
    "node_id": "sg-goods-services-tax-act-1993",
    "title": "Singapore Goods and Services Tax Act 1993",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2023-01-01",
    "bluf": "The Goods and Services Tax Act (Cap. 117A, 2005 Rev. Ed.), as amended with the GST rate increased to 9% effective 1 January 2024 from 8% on 1 January 2023 and 7% prior to that, requires any person who makes taxable supplies of goods or services in Singapore with annual taxable turnover exceeding SGD 1 million to register for GST with the Comptroller of Goods and Services Tax under Section 8, charge and collect GST on standard-rated supplies at the applicable rate under Section 7, file quarterly GST returns and remit output tax net of claimable input tax credits within one month after each accounting period under Section 35, and applies a reverse charge mechanism on imported business-to-business services and a overseas vendor registration regime for business-to-consumer digital services supplied by overseas suppliers under Section 8A, with penalties of up to SGD 10,000 per offence and imprisonment up to 7 years for serious GST fraud offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "sg-payment-services-act-2019",
        "sg-companies-act-1967",
        "oecd-pillar-two-global-minimum-tax-15-percent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-payment-services-act-2019",
      "sg-companies-act-1967",
      "oecd-pillar-two-global-minimum-tax-15-percent"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-government-procurement-act-gebiz-electronic-business-system",
    "title": "Singapore Government Procurement Act 1997 + GeBIZ Government Electronic Business Centralised Procurement Platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Singapore Government Procurement Act 1997 (Cap. 120) and the Government Procurement Regulations 2014 establish the principal procurement framework for the Singapore government. The Act implements Singapore's commitments under the WTO Agreement on Government Procurement (GPA 2012), which Singapore acceded to with effect from 1 October 2014, and the various free trade agreements government procurement chapters. The Act applies to procurements by gazetted government entities (the Schedule of the Act lists the in-scope entities including most ministries, statutory boards, and government-owned organisations) for goods, services, and construction works above prescribed thresholds, with comprehensive transparency, non-discrimination, and procedural fairness requirements. Procurement methods specified include open tender (the default for at-threshold procurements), selective tender (limited to prequalified suppliers), and limited tender (sole-source justified under prescribed exceptions). GeBIZ at gebiz.gov.sg is the Singapore government's central electronic procurement portal operated by the Ministry of Finance and is the mandatory platform for publishing procurement notices, conducting e-tendering, and managing the central panel arrangements through the Whole-of-Government Common Goods and Services panels. The Auditor-General's Office (AGO) provides independent procurement oversight and reports to Parliament on procurement irregularities, with the Public Service Division (PSD) handling broader procurement policy guidance and the Ministry of Finance providing financial regulations including Instruction Manual 3 (Financial Regulations) which sets the operational rules for ministry procurement. The framework intersects multiple supporting regimes including the Prevention of Corruption Act and the Corrupt Practices Investigation Bureau (CPIB) oversight for the integrity dimension, the Personal Data Protection Act for supplier personal data handling, the Singapore National Cybersecurity Strategy for IT procurement cybersecurity baselines, and the Multi-Tier Cloud Security Standard (MTCS, SS 584:2020) for cloud procurement assurance. Singapore's procurement framework is widely regarded as a leading practitioner of transparent, efficient e-procurement and serves as a frequent reference model for emerging market public procurement reform.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "sg-imda-mtcs-multi-tier-cloud-security-standard-ss-584",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "sg-health-products-act-part-ii-market-approval",
    "title": "Health Products Act 2007 - Part 2 ADMINISTRATION",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This article establishes the administrative framework for the Health Products Act, defining the Authority's responsibility and its powers to appoint enforcement officers, analysts, and advisory committees to oversee compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "sg-healthcare-services-act-2020",
    "title": "Singapore Healthcare Services Act 2020 (No. 3 of 2020) - Healthcare Provider Licensing",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Healthcare Services Act 2020 (HSA 2020, No. 3 of 2020) is Singapore's consolidated framework for the licensing and regulation of healthcare service providers, replacing the Private Hospitals and Medical Clinics Act (PHMCA). The HSA establishes a risk-proportionate licensing regime administered by the Ministry of Health (MOH). Section 5 prohibits providing any licensable healthcare service without a valid licence granted under the HSA. Section 6 sets out the application requirements for a licence, including the fit and proper requirements for licensees and key appointment holders. Section 13 imposes ongoing duties on licensees to take all reasonably practicable steps to ensure the quality and safety of healthcare services provided, maintain adequate clinical facilities, equipment, and staffing, and comply with standards of practice prescribed by MOH. The HSA introduces mandatory adverse event reporting obligations: licensees must report prescribed adverse events that occur in the course of providing a licensed healthcare service to the Director-General of Health within prescribed time limits. Under the HSA, the Director-General of Health may issue improvement notices, suspension notices, and revocation of licences for persistent non-compliance. The HSA also governs healthcare institutions' obligations regarding patient rights, including informed consent and the maintenance of medical records in accordance with the Private Hospitals and Medical Clinics (Maintenance of Medical Records) Regulations. The HSA came into partial force on 3 January 2022 for acute hospitals and day surgical centres.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-pdpa-2012"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sg-imda-agentic-ai",
    "title": "Singapore IMDA Agentic AI Framework",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Execution rules for the world's first framework specifically targeting Agentic AI, focusing on bounding autonomous actions, financial limits, and verifiable intent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_rmf_mapping",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ieee-3931-discovery"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sg-imda-ai-governance-framework-second-edition-model-governance",
    "title": "SG IMDA AI Governance Framework (Second Edition) - Model Governance and Explainability",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2023-06-01",
    "bluf": "Singapore's Infocomm Media Development Authority (IMDA) and Personal Data Protection Commission (PDPC) published the Model AI Governance Framework (Second Edition, 2020) providing detailed and practical guidance for private sector organisations to implement responsible AI. The Framework addresses two core principles: (1) decisions by AI should be explainable, transparent, and fair; and (2) AI solutions should be human-centric. It is mapped to key business objectives and provides a decision tree for determining appropriate AI explainability techniques based on context.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0-risk-management-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-imda-mtcs-multi-tier-cloud-security-standard-ss-584",
    "title": "Singapore IMDA Multi-Tier Cloud Security Standard (MTCS, SS 584:2020)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Multi-Tier Cloud Security Standard (MTCS, SS 584) is Singapore's national cloud security standard administered by the Infocomm Media Development Authority (IMDA) under the Singapore Standards Council. The current revision SS 584:2020 succeeds prior editions SS 584:2013 and SS 584:2015 and is the operative reference for the Singapore government Cloud-First procurement strategy, the Monetary Authority of Singapore (MAS) Technology Risk Management Guidelines, and most financial-institution cloud adoption decisions. MTCS classifies cloud service offerings into three security assurance tiers reflecting increasing rigour of controls and audit evidence: Level 1 (baseline information security for non-business-critical or low-impact workloads), Level 2 (heightened controls for business or regulatory sensitive workloads typical of mainstream enterprise consumption), and Level 3 (highest assurance with comprehensive control coverage typical of regulated industry, government, and large financial institution workloads). MTCS certification is issued by independent certification bodies accredited by the Singapore Accreditation Council (SAC) under the framework of ISO/IEC 17021 management systems certification accreditation. The MTCS framework is comprehensive across information security governance, infrastructure security, software and application security, data governance, business continuity, change management, identity and access management, supplier management, and cloud-specific resilience including multi-tenancy isolation, virtualisation security, and elastic capacity management. MTCS is mandatory or strongly preferred for Singapore Government Commercial Cloud (GCC) procurement decisions and underpins the MAS Outsourcing Guidelines third-party cloud provider assessment. MTCS-certified providers include AWS, Microsoft Azure, Google Cloud, Alibaba Cloud, Oracle Cloud Infrastructure, IBM Cloud, and several regional CSPs. The standard intersects ASEAN Cloud Computing Initiative discussions and serves as a frequently-referenced model for emerging-market national cloud assurance frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-iec-42001-2023-ai-management-system",
      "iso-iec-23894-ai-risk-management-2023",
      "nist-sp-800-53-r5",
      "fips-203-ml-kem-standard",
      "us-cisa-secure-by-design-principles-2023"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "sg-insolvency-restructuring-dissolution-act-2018",
    "title": "Singapore Insolvency Restructuring and Dissolution Act 2018",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2020-07-30",
    "bluf": "The Insolvency, Restructuring and Dissolution Act 2018 (Singapore, No. 40 of 2018), in force 30 July 2020, consolidates all corporate and personal insolvency law in Singapore into a single statute, introducing enhanced judicial management and scheme of arrangement restructuring mechanisms modelled on US Chapter 11 elements including automatic moratoriums on creditor action under Section 64, cross-class cram-down of dissenting creditor classes by the High Court under Section 70, recognition of Singapore schemes in foreign jurisdictions by adopting UNCITRAL Model Law on Cross-Border Insolvency as Part 11, expanding pre-packaged restructuring options under Section 71, and providing for the winding up of companies, judicial management, and personal bankruptcy regimes, with the Official Assignee administering bankruptcy estates and the Official Receiver administering compulsory windings-up.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "sg-companies-act-1967",
        "sg-employment-act-1968",
        "eu-insolvency-regulation-2015-848"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-companies-act-1967",
      "sg-employment-act-1968",
      "eu-insolvency-regulation-2015-848"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-mas-ai-risk-management-guidelines-2025",
    "title": "Singapore MAS Guidelines on AI Risk Management for Financial Institutions 2025 - FEAT Principles Operationalisation",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "All Monetary Authority of Singapore (MAS) regulated financial institutions including banks, insurers, fintechs, and payment providers must align AI use to the Fairness, Ethics, Accountability and Transparency (FEAT) principles co-created by MAS with the financial industry in 2018, and prepare to meet MAS supervisory expectations set out in the Guidelines on AI Risk Management proposed in MAS's November 2025 consultation paper, covering oversight of AI risk management in financial institutions, key AI risk management systems, policies and procedures, key AI life cycle controls, and the capabilities and capacity needed for the use of AI, supported by the Veritas Initiative and Project MindForge AI Risk Management Operationalisation Handbook (January 2026).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-automated-decision-workflows"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sg-mas-notice-610-credit-risk-capital-requirements",
    "title": "Singapore MAS Notice 610 - Submission of Statistics and Returns by Banks",
    "domain": "Banking & Global Finance",
    "version": "2023.1.1",
    "last_updated": "2026-04-30",
    "bluf": "MAS Notice 610 mandates banks in Singapore to submit periodic prudential statistics and regulatory returns to the Monetary Authority of Singapore covering balance sheet data, capital adequacy, credit risk exposures, liquidity coverage, and off-balance sheet commitments - forming the primary supervisory data collection framework underpinning MAS's risk-based bank supervision and Basel III implementation monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "basel_iii",
        "fatf",
        "bcbs_pillar_3",
        "sg_mas_637"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-mas-notice-637-risk-based-capital",
      "basel-iii-capital",
      "fatf-40-recommendations-2023-consolidated"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sg-mas-notice-610-regulatory-reporting",
    "title": "Singapore MAS Notice 610 - Banking Act Regulatory Reporting Requirements",
    "domain": "Banking & Global Finance",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "MAS Notice 610 (Banking Act Cap 19) requires Singapore-licensed banks to submit detailed statutory returns to the Monetary Authority of Singapore (MAS) on capital adequacy (MAS 637), liquidity (MAS 649), large exposures, credit risk, interest rate risk, and operational risk. Banks must adhere to the MAS data dictionary for return submissions. Notice 610 also covers anti-money laundering (AML) statutory returns and real estate loan reporting. Returns are submitted through MASnet (MAS Electronic Data Submission System) on monthly, quarterly, semi-annual, and annual cycles depending on the return.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-brrd-bank-recovery-resolution-directive-2014-59",
      "eu-aml-regulation-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-mas-notice-637-risk-based-capital",
    "title": "Singapore MAS Notice 637 - Risk-Based Capital Framework for Banks",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "MAS Notice 637 implements the Basel III capital framework for banks licensed under the Banking Act 1970 (Cap 19) in Singapore. Banks must maintain: CET1 Capital Adequacy Ratio (CAR) ≥6.5%, Tier 1 CAR ≥8%, Total CAR ≥10%, and minimum Total CAR of 12.5% when the Capital Conservation Buffer (CCB) of 2.5% is fully phased in. D-SIBs (Domestic Systemically Important Banks - DBS, OCBC, UOB) face an additional D-SIB buffer of 2%. Singapore adopts Basel III output floor (72.5% of standardised approach RWA) from January 2025 per Basel III finalisation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-mas-notice-610-regulatory-reporting",
      "eu-capital-requirements-directive-iv-2013-36-crd4"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-mas-notice-637-technology-risk-management-banks",
    "title": "Singapore MAS Technology Risk Management Guidelines - Technology Risk Management for Banks",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "MAS Technology Risk Management Guidelines (revised 2023) imposes technology risk management requirements on banks in Singapore, including board and senior management accountability, IT audit, incident reporting, and outsourcing risk management. Banks must notify MAS within 1 hour of a technology or cyber incident that has a significant impact on services or customer data, and submit a formal incident report within 14 days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "singapore-cybersecurity-act-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-mas-payment-services-act-2019-digital-payment-token-licensing",
    "title": "SG MAS Payment Services Act 2019 (PSA) - Digital Payment Token Services and Major Payment Institution Licence",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-04-04",
    "bluf": "Singapore's Payment Services Act 2019 (PSA), administered by the Monetary Authority of Singapore (MAS), regulates providers of digital payment token (DPT) services, money-changing, and payment services. DPT service providers (cryptocurrency exchanges, OTC desks, and wallet providers) must hold a Major Payment Institution (MPI) or Standard Payment Institution (SPI) licence. The PSA imposes AML/CFT obligations, technology risk management requirements, consumer protection measures, and financial requirements. The 2021 PSA amendments broadened DPT scope significantly.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-40-recommendations-2023-consolidated"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-mas-quantum-cybersecurity-risk-advisory",
    "title": "Singapore MAS Circular MAS/TCRS/2024/01 - Advisory on Addressing the Cybersecurity Risks Associated with Quantum",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-02-20",
    "bluf": "Circular No. MAS/TCRS/2024/01, Advisory on Addressing the Cybersecurity Risks Associated with Quantum, was issued by the Monetary Authority of Singapore on 20 February 2024 and addressed to the Chief Executive Officers of All Financial Institutions. It is to be read as supplementary information to the MAS notices and guidelines, which the circular identifies as including the Notice on Technology Risk Management, the Notice on Cyber Hygiene, the Technology Risk Management Guidelines and the Outsourcing Guidelines.\n\nThe risk statement is specific to financial services. Quantum computers have the potential to break some of the commonly used encryption and digital signature algorithms, so the security of financial transactions and sensitive data that financial institutions process could be at risk with the advent of cryptographically relevant quantum computers, defined in the circular as a quantum computer that can efficiently break real world cryptographic systems. Leading experts forecast that cybersecurity risks associated with quantum will materialize in the coming decade. Cryptographically relevant quantum computers would break commonly-used asymmetric cryptography, while symmetric cryptography could require larger key sizes to remain secure. The circular's central direction is that to address these risks financial institutions need to attain crypto-agility, so as to be able to efficiently migrate away from the vulnerable cryptographic algorithms to post-quantum cryptography without significantly impacting their information technology systems and infrastructure, and that they could also implement other quantum security solutions such as Quantum Key Distribution as part of their risk mitigation.\n\nThe advisory sets out eleven measures, lettered (a) to (k), under three headings. Under keeping abreast of developments and raising awareness: monitoring quantum computing developments, ensuring senior management and relevant third-party vendors understand the potential threats, working closely with third-party IT vendors to assess supply chain risks and requesting quantum-resistant solutions when commercially available, and connecting with industry groups, research bodies or Information Sharing and Analysis Centres. Under maintaining an inventory of cryptographic assets: identifying and maintaining an inventory of cryptographic solutions that records the cryptographic algorithm and key length used, the ownership and parties responsible for maintaining cryptographic assets, and the specific system or application where the algorithm is embedded or used; classifying dependent IT and data assets by sensitivity, criticality, risk exposure and the period for which they are deemed sensitive; and assessing whether existing system infrastructures can support crypto-agility. Under developing strategies and building capabilities: uplifting staff technical competencies, reviewing internal policies, standards and procedures, developing risk mitigation strategies for assets which cannot be migrated to post-quantum cryptography together with contingency planning for the risks materialising substantially ahead of the predicted timeline, and where resource permits considering proof-of-concept trials.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cisa-nsa-nist-quantum-readiness-factsheet",
      "fips-203-ml-kem-standard",
      "nist-cswp-39-considerations-for-achieving-crypto-agility-2025",
      "bis-project-leap-quantum-proofing-payments"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "sg-mas-trmg-2021",
    "title": "MAS Technology Risk Management Guidelines 2021",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "These guidelines require financial institutions in Singapore to establish a robust technology risk management framework, governance, and oversight to ensure the security and resilience of their IT systems. As per Section 4, the Board of Directors and Senior Management are ultimately responsible for the institution's technology risk management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "cpmi-iosco-cyber-resilience-fmi",
      "eba-outsourcing-guide"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sg-mas-veritas-fairness-assessment",
    "title": "Singapore MAS Veritas Framework - Fairness, Ethics, Accountability and Transparency Assessment for Financial Services AI",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The Monetary Authority of Singapore (MAS) Veritas initiative is a voluntary industry framework providing financial institutions with a methodology for assessing and demonstrating responsible AI in financial services under the MAS Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics in Singapore's Financial Sector (2018); the Veritas framework operationalises FEAT principles through technical assessment toolkits and industry validation exercises; the Veritas Fairness Assessment Methodology Document (FAMD) provides specific quantitative fairness metrics for assessing whether AI/data analytics models used in credit scoring, insurance underwriting, and customer marketing generate discriminatory outcomes; Veritas Phase 1 (2021) validated fairness assessment methodologies for consumer credit scoring and insurance underwriting; Veritas Phase 2 (2022) extended to customer marketing and other financial services AI use cases; Veritas Phase 3 continues to develop assessment standards for emerging AI use cases including generative AI in financial services; the Veritas toolkit enables financial institutions to: define protected attributes relevant to their regulatory and business context; select appropriate fairness metrics (individual fairness, group fairness, counterfactual fairness); measure disparity in AI model outputs across protected groups; compare disparities against defined fairness thresholds; generate audit-ready fairness assessment reports; compliance with Veritas does not create a legal safe harbour under MAS regulations but demonstrates due diligence for FEAT principle compliance; financial institutions supervised by MAS are expected to have governance processes addressing the FEAT principles across their AI and data analytics use cases.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/sg-mas-veritas-fairness-assessment.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-model-ai-governance-v2",
      "sg-pdpa-2012",
      "sg-mas-trmg-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-model-ai-governance-v2",
    "title": "Model Artificial Intelligence Governance Framework Second Edition (2020)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Singapore's voluntary framework guides organizations in the responsible deployment of AI by outlining two core principles: AI decisions should be explainable, transparent, and fair, and AI systems should be human-centric. It provides detailed guidance across four key areas: Internal Governance Structures, Risk Management in the AI Model Lifecycle, Operations Management, and Customer Relationship Management (Section 1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "oecd-ai-principles",
      "nistir-8312-explainable-ai-principles",
      "nist-sp-1270-managing-ai-bias"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sg-monetary-authority-of-singapore-act",
    "title": "Singapore Monetary Authority of Singapore Act 1970 - Central Bank and Financial Regulator Authority",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Monetary Authority of Singapore Act 1970 establishes the Monetary Authority of Singapore as the central bank of Singapore and integrated financial regulator with statutory functions covering monetary policy, foreign reserves management, banking and financial system supervision, capital markets oversight, insurance supervision, payment systems oversight, financial market development, and currency issuance, gives MAS powers of investigation, inspection, and enforcement, and authorises civil and criminal penalties for breach of regulations and directions issued under the Act and related industry statutes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-securities-futures-act-2001"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "sg-payment-services-act-2019",
    "title": "Singapore Payment Services Act 2019",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2022-04-04",
    "bluf": "The Payment Services Act 2019 (Singapore, No. 2 of 2019), in force 28 January 2020 and significantly amended in 2021 and 2023, establishes a single licensing regime for seven categories of payment service in Singapore under the Monetary Authority of Singapore, requiring payment service providers to hold a money-changer licence, Standard Payment Institution (SPI) licence, or Major Payment Institution (MPI) licence depending on transaction volumes, with MPI operators facing enhanced capital (SGD 250,000 minimum), safeguarding, technology risk, and AML/CFT obligations, and unlicensed provision attracting fines up to SGD 250,000 and imprisonment up to three years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "sg-pdpa-2012",
        "eu-payment-services-directive-2-2015-2366",
        "sg-cybersecurity-act-2018"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-pdpa-2012",
      "eu-payment-services-directive-2-2015-2366",
      "sg-cybersecurity-act-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sg-payment-services-act-2019-part-2-licensing",
    "title": "Payment Services Act 2019 - Part 2 Licensing of Payment Service Providers",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation mandates that any entity providing payment services in Singapore must obtain a licence, maintain a local place of business, notify the Authority of specific events, submit periodic reports, and secure approval for key personnel.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "sg-pdpa-2012",
    "title": "Personal Data Protection Act 2012 (2021 Amendment)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Singapore Personal Data Protection Act (PDPA) establishes a baseline standard of protection for personal data in Singapore by governing its collection, use, disclosure, and care by private sector organisations. Under Part III of the Act, organisations must comply with nine main data protection obligations, including obtaining consent, limiting purpose, and ensuring data accuracy and security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sg-pdpa-2012-section-13-consent-obligation-collection",
    "title": "Personal Data Protection Act 2012 - Section 13 Consent required",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "An organisation must obtain consent from an individual before collecting, using, or disclosing their personal data for a specified purpose.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sg-pdpa-2012-section-26-data-breach-notification-mandatory",
    "title": "Personal Data Protection Act 2012 - Section 26D Duty to notify occurrence of notifiable data breach",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations have a mandatory duty to assess data breaches and notify the Personal Data Protection Commission and affected individuals if the breach is deemed notifiable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sg-pdpa-part-3-data-protection-obligations-main",
    "title": "Personal Data Protection Act 2012 - Part 3 General Rules with Respect to Protection of and Accountability for Personal Data",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must implement policies and practices to comply with the Act's requirements for collecting, using, disclosing, protecting, and retaining personal data, including obtaining consent and notifying individuals of the purpose.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "sg-pdpa-section-26a-data-breach-notification",
    "title": "Personal Data Protection Act 2012 - Part 6A Notification of Data Breaches",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must assess data breaches to determine if they are notifiable and subsequently notify the Personal Data Protection Commission and affected individuals of any notifiable data breach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-personal-data-protection-act-2012-pdpa-cybersecurity-obligations",
    "title": "Singapore PDPA 2012 - Cybersecurity and Data Protection Obligations Under the Protection Obligation",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Singapore Personal Data Protection Act 2012 (PDPA), as amended in 2020, imposes a Protection Obligation (s 24) requiring organisations to make reasonable security arrangements to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. The 2020 amendments added mandatory breach notification within 3 calendar days for breaches of prescribed scale.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "singapore-cybersecurity-act-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-personal-data-protection-amendment-act-2020",
    "title": "Singapore Personal Data Protection Amendment Act 2020",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2021-02-01",
    "bluf": "The Personal Data Protection (Amendment) Act 2020 (No. 40 of 2020), in force 1 February 2021, substantially amends the Personal Data Protection Act 2012 to introduce mandatory data breach notification requiring organisations to notify the Personal Data Protection Commission within 3 calendar days of assessing that a notifiable data breach has occurred and to notify affected individuals where the breach is likely to result in significant harm under Sections 26C and 26D, increases financial penalties for data protection violations from a cap of SGD 1 million to up to 10% of an organisation's annual turnover in Singapore under Section 48J, introduces a data portability right enabling individuals to request transfer of their personal data to other organisations under Section 26H, creates an enhanced framework for deemed consent by notification under Section 15A, and provides organisations with a new legitimate interests exception for processing personal data without consent under Section 18B.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "sg-pdpa-2012",
        "eu-gdpr-cloud-data-processing",
        "ca-cppa-bill-c27-2022"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-pdpa-2012",
      "eu-gdpr-cloud-data-processing",
      "ca-cppa-bill-c27-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-pofma-2019",
    "title": "Singapore Protection from Online Falsehoods and Manipulation Act 2019 (POFMA)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Singapore POFMA effective October 2, 2019 empowers government ministers to issue correction directions and stop communication directions against online falsehoods, requires platforms to comply within 24 hours, and imposes penalties up to SGD 1,000,000 on non-compliant online platforms and SGD 50,000 or 5 years imprisonment on individuals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/sg-pofma-2019.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-securities-futures-act-2001",
    "title": "Singapore Securities and Futures Act 2001 (Cap. 289) - Market Conduct and Investor Protection",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-30",
    "bluf": "The Securities and Futures Act 2001 (SFA, Cap. 289) is Singapore's principal legislation governing the securities and futures market, administered by the Monetary Authority of Singapore (MAS). The SFA regulates the licensing and conduct of capital markets service providers, the listing and disclosure obligations of public companies, and the prohibition of market misconduct. Part IV of the SFA establishes licensing requirements for persons carrying on a regulated activity as defined in the Second Schedule, including dealing in capital markets products, advising on corporate finance, fund management, and providing custodial services. Part XII prohibits market misconduct including false trading (s. 197), market manipulation (s. 198), false or misleading statements (s. 199), and the employment of manipulative or deceptive devices (s. 201). The insider trading prohibition in Part XII (s. 218) makes it an offence for a person in possession of information that is not generally available and that would or would be likely to have a material effect on the price of securities to subscribe for, purchase, or sell those securities. Section 219 prohibits a connected person who has inside information from procuring another person to deal in those securities. The SFA was substantially amended by the Securities and Futures (Amendment) Act 2017 to implement enhanced MAS powers, and further amended in 2018 to implement the OTC derivatives reform. MAS may impose civil penalties and disgorgement orders for market misconduct under Part VIIA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-companies-act-1967",
      "sg-mas-trmg-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sg-securities-futures-act-part-xii-market-offences",
    "title": "Securities and Futures Act 2001 - Part 2 Division 2 Regulation of Approved Exchanges",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Approved exchanges must comply with a range of operational obligations, including prudent risk management, record-keeping, periodic reporting, assisting the Authority, and seeking approval for key appointments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "sg-singapore-food-agency-food-regulations-cap-283-food-safety",
    "title": "SG Singapore Food Agency - Sale of Food Act 1973 (formerly Cap. 283) and Food Regulations Licensing and Safety Requirements",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-07-03",
    "bluf": "Singapore Food Agency (SFA) administers the Sale of Food Act 1973 (formerly Cap. 283) and its Food Regulations requiring food establishments to obtain SFA licences, comply with food hygiene standards, meet labelling requirements for pre-packed foods, and adhere to import control procedures for food products entering Singapore.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-personal-data-protection-act-2012-pdpa-cybersecurity-obligations",
      "sg-employment-act-1968"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-singpass-ndi-pdpa-digital-identity",
    "title": "Singapore Singpass and National Digital Identity Framework under the PDPA",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "Singpass is Singapore's National Digital Identity (NDI) platform, operated by the Government Technology Agency of Singapore (GovTech) on behalf of the Smart Nation and Digital Government Office. Singpass provides authentication, digital signing through Sign with Singpass, attribute sharing through Myinfo, and face verification through the Singpass Face Verification service. Authentication is grounded in the Singapore National Registration Identity Card (NRIC) number issued under the National Registration Act 1965 and the Personal Data Protection Act 2012 (PDPA). The PDPA imposes data protection obligations on private-sector organisations using Singpass-derived data including consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation, openness, and accountability.\n\nSingpass requires two-factor authentication for transactional access, supporting passwords plus one-time-passwords or Singpass app push notification, and offers QR-code Singpass app authentication and SMS-based one-time-password for legacy users. The Singpass face verification service uses 1:1 biometric matching against the national identity database and is governed under the PDPA Advisory Guidelines on the use of personal data for biometric authentication. Myinfo provides API-based government-verified data sharing to over 2,700 services with consent of the citizen under PDPA Section 14. The Personal Data Protection Commission (PDPC) is the supervisory authority under the PDPA with powers under Part IX to investigate breaches, issue directions, and impose financial penalties up to ten percent of annual turnover for serious contraventions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nist-sp-800-63-4-2025-digital-identity-guidelines",
      "sg-pdpa-2012",
      "w3c-verifiable-credentials-data-model-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sg-telecommunications-act-1999",
    "title": "Singapore Telecommunications Act 1999",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2018-03-26",
    "bluf": "The Telecommunications Act (Cap. 323, 2000 Rev. Ed.), last amended in 2018, requires any person who wishes to establish or maintain a telecommunication system or provide telecommunication services in Singapore to hold a facility-based operator (FBO) or service-based operator (SBO) licence issued by the Info-communications Media Development Authority under Section 5, prohibits interception of telecommunications and unauthorised interference with telecommunications systems under Sections 49 and 39, requires licensed operators to implement and maintain resilient network infrastructure meeting IMDA's Code of Practice for Telecommunication Service Resilience, mandates that operators provide emergency call services under Section 22, establishes must-carry obligations for licensed broadcasters' free-to-air channels under Section 30, and imposes financial penalties of up to SGD 1 million per contravention for licence condition violations and criminal penalties up to 10 years imprisonment for serious interception offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "sg-pdpa-2012",
        "sg-cybersecurity-act-2018",
        "ca-telecommunications-act-1993"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-pdpa-2012",
      "sg-cybersecurity-act-2018",
      "ca-telecommunications-act-1993"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sg-workplace-safety-health-act-2006",
    "title": "Singapore Workplace Safety and Health Act 2006 (Cap. 354A) - Occupational Safety Obligations",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Workplace Safety and Health Act 2006 (WSHA, Cap. 354A) establishes the occupational safety and health framework for workplaces in Singapore, administered by the Ministry of Manpower (MOM) and the Workplace Safety and Health Council (WSHC). The WSHA imposes positive duty-based obligations on a hierarchy of workplace duty-holders. Section 11 imposes duties on occupiers of workplaces to take such reasonably practicable measures as are necessary to ensure the safety and health of persons at the workplace. Section 12 imposes duties on employers to take reasonably practicable measures to ensure the safety and health of their employees at work, including providing and maintaining a safe plant and working environment, implementing a system for managing safety and health at work, and providing adequate instruction, training, and supervision. Section 13 imposes duties on principals (including clients and main contractors) to take reasonably practicable measures to ensure the safety of contractors and their workers engaged to carry out work. Section 14 imposes duties on manufacturers and suppliers of machinery, equipment, and hazardous substances used at work. Section 15 imposes duties on persons at work (employees and contractors) to cooperate with safety measures. Penalties for major workplace incidents resulting from contravention of the WSHA can reach SGD 500,000 for corporate offenders and SGD 100,000 and/or two years imprisonment for individual offenders. The WSH (Incident Reporting) Regulations require reporting of workplace accidents resulting in death or serious injury within prescribed time limits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sh-dpo-2018",
    "title": "Saint Helena Data Protection Ordinance 2018",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Saint Helena, Ascension and Tristan da Cunha, a British Overseas Territory, enacted the Data Protection Ordinance 2018 aligned with UK data protection standards. Administered by the Governor's office and designated data protection authority, the Ordinance establishes principles for the lawful processing of personal data by controllers established or operating in the territory. Data subjects have rights of access and correction. Sensitive personal data categories require explicit consent or specific statutory conditions. Security safeguards are mandatory, and cross-border transfers are restricted to jurisdictions with adequate protection. The Ordinance mirrors UK data protection law to maintain consistency for businesses operating across the territory.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/sh-dpo-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "shared-responsibility-model",
    "title": "Shared Responsibility Model",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "A clearly articulated Shared Responsibility Model delineates the distinct security and compliance obligations between the service provider and the customer, a principle established by foundational cloud computing standards. This framework confirms the provider manages security *of* the cloud, encompassing the integrity of physical infrastructure and security of the hypervisor. Conversely, the customer retains full accountability for security *in* the cloud. Customer-managed obligations explicitly include identity and access management, implementation of robust data encryption, and application-level security fortifications. Per the defined model, responsibility for data residency and configuration hardening is assigned to the customer, as indicated by their respective control values of 1. The operational maturity of this model is substantiated by a documented compliance matrix mapping controls to each party. Further evidence of a robust framework includes the clear delineation of log management duties and predefined roles for incident response, ensuring coordinated action and maintaining auditable trails consistent with regulatory expectations outlined in authoritative industry guidance. This documented SRM, with a defined service model, creates an unambiguous and defensible compliance posture.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-145-cloud-computing",
      "iso-27017-cloud-controls"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "shared-responsibility-model-aws-azure-gcp",
    "title": "Cloud Shared Responsibility Model - AWS, Azure and GCP Security Responsibility Boundaries for IaaS, PaaS and SaaS",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Shared Responsibility Model delineates security and compliance obligations between a cloud service provider (CSP) and its customers. The CSP (AWS, Azure, GCP) is responsible for the security 'of' the cloud (infrastructure, hardware, managed services), while the customer is responsible for security 'in' the cloud (data, applications, identity and access management, client-side controls).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "iso-27017-cloud-security-2015",
      "nist-sp-800-145-cloud-computing",
      "shared-responsibility-model"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "shrm-hr-competency",
    "title": "SHRM (HR Competency)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Organizational conformity with established SHRM competency standards is evaluated through a multi-faceted set of controls governing professional conduct, strategic integration, and data governance. Successful validation requires a formally documented competency model and stipulates that no less than 30 percent of human resources staff hold relevant professional certifications. The framework further compels the completion of annual ethics training and attested acknowledgment of a specific HR personnel conduct code. Strategic alignment is confirmed by verifying HR leadership's inclusion in strategic planning processes, the direct linkage of HR metrics to business KPIs, and a required evaluation of program return on investment. On the operational front, compliance mandates the execution of quarterly HRIS access reviews and the maintenance of a published employee data privacy policy. As outlined in modern data protection guidance, the entity must also possess a formal data retention policy for personnel records and ensure its incident response plan explicitly provides for breaches involving personally identifiable information, thereby satisfying key risk management criteria.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eeoc-employment-rule",
      "iso-30414-human-capital-rep"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "si-zvop2-2022",
    "title": "Slovenia Personal Data Protection Act 2022 (ZVOP-2) - GDPR National Implementation",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Slovenia's Zakon o varstvu osebnih podatkov (ZVOP-2 - Personal Data Protection Act), published in the Official Gazette of the Republic of Slovenia (Uradni list RS No. 163/22) on 30 December 2022 and entering into force on 26 January 2023, is Slovenia's current primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Slovenia. The GDPR is directly applicable Slovenian law by virtue of Slovenia's EU membership. ZVOP-2 replaced the prior ZVOP-1 (Zakon o varstvu osebnih podatkov, Official Gazette RS No. 94/07) and its amendments. Slovenia was among the later EU member states to formally adopt dedicated GDPR supplementing legislation, operating under the transitionally adapted ZVOP-1 between 2018 and January 2023 before ZVOP-2 entered into force. Enforcement: the Informacijski pooblaščenec (IP - Information Commissioner) is Slovenia's independent data protection and access to information supervisory authority. The IP has a dual mandate covering both personal data protection and access to public information (freedom of information). The IP is Slovenia's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Slovenian national provisions: (1) Age of digital consent: Slovenia has maintained the GDPR default of 16 years for information society services under ZVOP-2; data subjects under 16 require parental or guardian consent; (2) Dual mandate - the Informacijski pooblaščenec has jurisdiction over both personal data protection and access to public information under the Access to Public Information Act (Zakon o dostopu do informacij javnega značaja - ZDIJZ), creating a balance between privacy and transparency for public authorities similar to Hungary's combined NAIH framework; (3) Employment - ZVOP-2 contains specific provisions on processing personal data in employment contexts; the Slovenian Labour Code (Zakon o delovnih razmerjih - ZDR-1, Official Gazette RS No. 21/13 as amended) governs employment relationships; (4) Health data - specific provisions for health data processing in Slovenia's public health system under ZVOP-2 and sector-specific health legislation; (5) Public sector - Slovenian public authorities are subject to ZVOP-2 and the ZDIJZ access to information framework. Fines: GDPR administrative fines apply in Slovenia - up to EUR 20 million or 4% of global annual turnover. The IP has imposed fines and issued enforcement decisions across public sector, employment, and digital services contexts. The IP has been one of the more active EU supervisory authorities in issuing guidance on GDPR compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sigmahq-sigma-detection-rule-format",
    "title": "SigmaHQ Sigma Detection Rule Format (Vendor-Agnostic YAML Signature, pySigma Converter, Splunk/Elastic/QRadar/Sentinel/Security Onion Backends, 3000+ Community Rules)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Sigma is the open, vendor-agnostic YAML signature format for describing log-based detections. The project is maintained at github.com/SigmaHQ/sigma by the SigmaHQ community and is functionally the SIEM-side equivalent of YARA (for files) and Snort (for network traffic). A Sigma rule is a YAML document with required and optional sections: title (rule name), id (unique UUID identifier), status (experimental, test, stable, deprecated), description (the detection rationale), references (links to threat intelligence, MITRE ATT&CK techniques, blog posts), logsource (product, category, service identifying the log type the rule runs against), detection (one or more selection blocks with field-value pairs), condition (boolean logic combining selections), fields, falsepositives, level (informational, low, medium, high, critical), and tags (mitre-attack technique IDs, kill-chain phases, threat actor groups). Rules are deployed by converting Sigma YAML to a specific SIEM query language using one of the official backends: pySigma (the canonical Python library and rule-conversion engine) and the Sigma CLI tool built on pySigma, plus the sigconverter.io web UI. Supported SIEM and detection targets include Splunk (SPL), Elastic and Elasticsearch (KQL, EQL, Lucene), Microsoft Sentinel (KQL), IBM QRadar (AQL), Security Onion, LimaCharlie, Sekoia.io XDR, Sumo Logic, Carbon Black, and CrowdStrike Falcon. The SigmaHQ rule repository hosts over 3,000 peer-reviewed detection rules across generic detections, threat hunting, emerging threats, and compliance categories. Sigma rules are the canonical exchange format for detection content across SIEM vendor boundaries and the recommended pairing with STIX 2.1 indicators, MITRE ATT&CK, and the CACAO Security Playbooks sigma command type.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "specification_basis",
        "key_institutions",
        "yaml_rule_structure",
        "detection_block_semantics",
        "logsource_taxonomy",
        "backend_converters_pysigma_cli",
        "supported_siem_backends",
        "rule_repository_and_review",
        "sigma_to_mitre_attack_and_stix_pairing",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oasis-stix-2-1-structured-threat-information",
      "oasis-cacao-v2-0-security-playbooks",
      "mitre-attack-framework-v14",
      "cyber-nist-csf-2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sigstore-cosign-fulcio-rekor-keyless-signing",
    "title": "Sigstore Keyless Signing Stack (Cosign Signing Tool, Fulcio Short-Lived Code Signing CA, Rekor Transparency Log, OIDC Identity, OCI 1.1 Container Signing, OpenSSF/Linux Foundation Governance)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Sigstore is the open-source software signing and transparency stack maintained under the Open Source Security Foundation (OpenSSF) within the Linux Foundation. The architecture has three primary components: Cosign as the client tool for signing and verifying software artifacts including containers, binaries, and files; Fulcio as the free X.509 Code Signing Certificate Authority that accepts OIDC identity tokens and issues short-lived certificates bound to the provided identity and public key, eliminating the need for long-term key management; and Rekor as the immutable, append-only transparency log that records the artifact digest, signature, and certificate for public auditability of every signing event. Sigstore's keyless signing workflow is identity-based: the client generates an ephemeral public/private key pair; submits a certificate signing request to Fulcio with an OIDC identity token (from GitHub Actions, Google, Microsoft, Amazon, GitLab, or other configured OIDC providers); Fulcio verifies the OIDC token and issues a short-lived certificate bound to the identity; the artifact is signed and the private key is discarded after single use; the signature, certificate, and artifact digest are recorded in Rekor. The result is that the artifact is not just signed, it is signed with an ephemeral key associated with a known identity and publicly auditable. Sigstore signing integrates with OCI 1.1 sigstore signing for container image attestations, with SLSA build provenance, with SBOM signing for SPDX and CycloneDX, and with the in-toto attestation framework. The project is supported by Google, Red Hat, Chainguard, GitHub, and Purdue University.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "cosign_signing_tool",
        "fulcio_code_signing_ca",
        "rekor_transparency_log",
        "keyless_signing_workflow",
        "oci_1_1_container_signing",
        "slsa_provenance_integration",
        "sbom_and_in_toto_attestation_signing",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "slsa-supply-chain-security-levels",
      "spdx-3-0-iso-iec-5962-2021-sbom-standard",
      "cyclonedx-1-7-owasp-ecma-sbom-standard",
      "nist-sp-800-218-secure-software-development-framework-ssdf"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-autonomous-vehicle-framework-lta",
    "title": "Singapore LTA Autonomous Vehicle Regulatory Framework - Trial Permit System, Safety Assessment, Mandatory Incident Reporting, Operational Safety Case and AV Centre Requirements",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation governs the testing and deployment of autonomous vehicles (AVs) on public roads and paths in Singapore. All AVs must undergo safety assessments at CETRAN, obtain insurance, and comply with the Road Traffic Rules for AVs under the Road Traffic Act, including mandatory blackbox data recording and remote operations oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sae-j3016-levels-driving-automation-2021",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "iso-26262-functional-safety-road-vehicles-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-building-control-act-cap-29",
    "title": "Building Control Act (Cap. 29)",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Building Control Act (Cap. 29) requires building owners and developers to obtain approval from the Commissioner of Building Control before commencing construction, as stated in Section 5(1) of the Act. This regulation applies to all building works in Singapore.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "singapore-building-control-act-cap-29-bca",
    "title": "Singapore Building Control Act (Cap. 29) - BCA Regulatory Framework",
    "domain": "Construction & Real Estate",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Singapore's Building Control Act (Cap. 29, 1989, revised 2000) administered by the Building and Construction Authority (BCA) requires building plan approval, a Qualified Person (QP) to supervise all structural works, a Builder's Licence for general building contractors, and a Temporary Occupation Permit (TOP) and Certificate of Statutory Completion (CSC) before occupation - with mandatory structural inspections for existing buildings over 10 years old and BCA Accessibility Code compliance for all new buildings and major additions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-national-construction-code-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-casino-control-act-2006",
    "title": "Casino Control Act 2006 (Cap. 33A)",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Casino Control Act 2006 regulates the licensing, operation, and supervision of casinos in Singapore, including requirements for casino operators, employee licensing, anti-money laundering controls, and exclusion mechanisms for problem gambling. It applies to casino operators, employees, patrons, and associated entities under Section 43 and Part 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-casino-control-act-2006-aml-exclusions",
    "title": "Casino Control Act 2006",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The Casino Control Act 2006 obliges all licensed casino operators in Singapore to conduct AML/CFT customer due-diligence, enforce fit-and-proper assessments for licence holders, implement the exclusion regime (excluded persons, self-exclusion, family exclusion, and visit limits) under Sections 159 to 168 (including exclusion orders and visit limits under Section 165 and self-exclusion under Section 165AA), and collect an entry levy from patrons under Section 116.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021",
      "eu-5amld-article-2-gambling-2018",
      "curacao-gaming-control-board-ordinance-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "singapore-competition-act-2004-cccs",
    "title": "Competition Act 2004 (Cap. 50B)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Singapore Competition Act 2004 prohibits agreements that prevent, restrict, or distort competition (Section 34), the abuse of a dominant market position (Section 47), and mergers that substantially lessen competition (Section 54). The Act applies to all undertakings and is enforced by the Competition and Consumer Commission of Singapore (CCCS).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "singapore-consumer-protection-fair-trading-act-2004",
    "title": "An Act to protect consumers against unfair practices and to give consumers additional rights in respect of goods that do not conform to contract, and for matters connected therewith.",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The Consumer Protection (Fair Trading) Act 2003 prohibits unfair practices by suppliers in consumer transactions and grants consumers rights to cancel certain contracts within a 5-day period, particularly in direct sales. It also establishes a 1-year limitation period for legal action under section 12 and applies to e-commerce transactions as defined in Part 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "singapore-copyright-act-2021-creator-rights",
    "title": "Copyright Act 1987 (Chapter 63) - Modernised Provisions on Permitted Uses, Rights in User-Generated Content, and Assignment of Rights (as amended by Act 27 of 2021)",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Singapore Copyright Act 2021 grants creators exclusive rights over their works while permitting certain uses for data analytics, text and data mining, and user-generated content under specific conditions. Key protections and limitations are defined in Sections 177A, 177B, 177C, and 194A, applying to creators, platforms, and users of copyrighted material in digital environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iptc-photo-metadata",
      "iptc-video-metadata",
      "exif-standard-metadata",
      "doi-digital-object-id",
      "c2pa-content-provenance"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "singapore-cybersecurity-act-2018",
    "title": "Cybersecurity Act 2018 of Singapore",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "The Singapore Cybersecurity Act 2018 establishes a legal framework for the oversight and maintenance of national cybersecurity, imposing duties on owners of Critical Information Infrastructure (CII) to secure their systems and report incidents within 2 hours (Section 14). The Act also creates a licensing framework under Part 5 for cybersecurity service providers (CSSPs) to ensure service quality and accountability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0",
      "guide-computer-security-log-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-electricity-act-cap-89a-supply-standard",
    "title": "Singapore Electricity Act (Cap. 89A) - Market Licensing, Transmission Access Code, Quality of Supply Standards and Grid Codes",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The Singapore Electricity Act (Cap. 89A) establishes the Energy Market Authority (EMA) to regulate the electricity industry, requiring any entity involved in the generation, transmission, retail, or market operation of electricity to hold a valid license (Part III). Licensees must comply with all applicable codes of practice, including the Transmission Code and Quality of Service standards, to ensure the safe, reliable, and efficient operation of the power system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-food-agency-act-2019",
    "title": "Singapore Food Agency Act 2019 (Act 11 of 2019)",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "The Singapore Food Agency Act 2019 consolidated Singapore food safety regulation by establishing the Singapore Food Agency (SFA) on 1 April 2019, transferring functions from the Agri-Food and Veterinary Authority (AVA), the National Environment Agency, and the Health Sciences Authority. The SFA oversees the full food supply chain from primary production through import/export, retail, and food service, administering the Sale of Food Act 1973, the Animals and Birds Act 1965, the Wholesome Meat and Fish Act 1999, the Fisheries Act 1966, the Control of Plants Act 1993, and the Feeding Stuffs Act 1971. The Act sets out the SFA Board, the Chief Executive role, powers to make Subsidiary Legislation, financial provisions, licensing of food establishments and food import/export, and powers of authorised officers for inspection, sampling, and enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "sale_of_food_act",
        "codex_alimentarius",
        "asean_food_safety",
        "wto_sps_tbt",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-cxs-1-1985-labelling-prepackaged-foods",
      "codex-cxs-193-1995-contaminants-toxins-food-feed"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-food-agency-food-hygiene-regulations-2021",
    "title": "Environmental Public Health (Food Hygiene) Regulations (Singapore), made under the Environmental Public Health Act 1987",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "The Environmental Public Health (Food Hygiene) Regulations, made under the Environmental Public Health Act 1987, require food handlers in Singapore to be registered, licensed food premises to meet hygiene and cleanliness standards, food to be stored and transported under prescribed conditions, and food handlers to complete a food hygiene course. (Note: the Food Safety and Security Act 2025 consolidates and updates parts of this regime.)",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-haccp-2022",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "singapore-genetic-modification-advisory-gmac",
    "title": "Singapore Biosafety Guidelines for Research on Genetically Modified Organisms (GMOs) and for Release of Agriculture-Related GMOs",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The GMAC guidelines establish biosafety requirements for research involving GMOs and for the commercial release of agriculture-related GMOs in Singapore. These apply to researchers, institutions, and businesses conducting GMO work under containment or environmental release conditions, based on guidelines issued in May 2006 and 1999 respectively.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "iso-13485-qms"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "singapore-hsa-samd-2026",
    "title": "Singapore HSA Software as a Medical Device (SaMD) Regulatory Framework 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "HSA aligns SaMD regulation with IMDRF, with risk-based classification and streamlined pathways referencing FDA/CE approvals. 2026 updates include enhanced AI/ML change management and cybersecurity requirements for connected devices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "singapore-hsa-therapeutic-products-act-2016",
    "title": "Health Products (Therapeutic Products) Regulations 2016 (S 329/2016), made under the Health Products Act 2007 (Singapore)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "Under the Health Products Act 2007 and the Health Products (Therapeutic Products) Regulations 2016 (S 329/2016), therapeutic products must be registered with the Health Sciences Authority (HSA) before supply in Singapore, and dealers must hold the applicable manufacturer, importer or wholesaler licence. The Regulations set out registration requirements, licensing conditions, controls on the supply of prescription and pharmacy medicines, record-keeping, and trade description and product information duties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "singapore-hsa-therapeutic-products-regulations",
    "title": "Regulatory overview of therapeutic products in Singapore under the Health Products Act (HPA) and Health Products (Therapeutic Products) Regulations 2016",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Therapeutic products must be registered and dealers must hold a valid licence before manufacturing, importing, or supplying such products in Singapore. Registration, licensing, and post-market vigilance including adverse event and defect reporting are required under the Health Products (Therapeutic Products) Regulations 2016.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-e8-r1-general-considerations-clinical-2021",
      "singapore-genetic-modification-advisory-gmac"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "singapore-immigration-act-cap-133-ica",
    "title": "Singapore Immigration Act (Cap. 133) - ICA Border Control and Pass Framework",
    "domain": "Immigration & Border Control",
    "version": "2.9",
    "last_updated": "2026-05-10",
    "bluf": "The Singapore Immigration Act (Cap. 133, 1997 Revised Edition) is the primary statute governing entry, residence, and departure of foreign nationals in Singapore. The Immigration and Checkpoints Authority (ICA) administers the Act and operates the world's most technologically advanced border control - mandatory biometric fingerprinting and iris scanning at Changi Airport and Tuas Second Link. Section 15 of the Act prescribes caning (up to 3 strokes) and imprisonment (up to 5 years) for unlawful entry. The Ministry of Manpower (MOM) manages work passes under the Employment of Foreign Manpower Act. Singapore has no refugee law and is not party to the 1951 Refugee Convention. The Automated Clearance Initiative enables most ASEAN nationals to self-clear at automated gates. Foreign worker levies apply to Work Permit holders at rates of SGD 300-650 per month depending on sector and quota.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "asean",
        "icao_doc",
        "pdpa",
        "fatf_recommendation",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-iras-transfer-pricing-guidelines-2021",
    "title": "Singapore IRAS Transfer Pricing Guidelines 6th Edition 2021 - Documentation Requirements, Advance Pricing Agreements and MAP Procedures",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires multinational enterprises to maintain transfer pricing documentation as per Section 3.1 of the guidelines, and applies to all entities with cross-border transactions. See Section 2.1 for definitions and scope.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-attribution-profits-permanent-establishments-2010",
      "oecd-financial-transactions-transfer-pricing-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "singapore-mas-insurance-act-2023-amendments",
    "title": "Insurance Act - Licensing, Supervision and Governance of Insurers and Insurance Brokers in Singapore",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation governs the licensing and operation of insurers and insurance brokers in Singapore under the Insurance Act, requiring compliance with prudential, governance, and conduct standards set by the Monetary Authority of Singapore (MAS). It applies to direct insurers, reinsurers, captive insurers, approved MAT insurers, authorised reinsurers, and registered or approved insurance brokers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "eu-delegated-regulation-2016-2067-spread-market-risk",
      "eu-delegated-regulation-2016-467-non-life-premium-risk",
      "eu-eiopa-guidelines-orsa-2015"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "singapore-mas-insurance-act-cap-142",
    "title": "Insurance Act 1966 (Cap. 142)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Act establishes the regulatory framework for the insurance industry in Singapore, mandating that all insurers must be licensed by the Monetary Authority of Singapore (MAS) under Section 8. It imposes strict minimum capital, fund solvency, and financial resource requirements (Sections 17, 18, and 20) and requires the appointment of an approved actuary to certify financial soundness (Section 37).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "fsb-key-attributes-res",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-mas-notice-mas-124-insurance-valuation",
    "title": "MAS Notice MAS 124 - Valuation and Capital Framework for Insurers: Risk-Based Capital (RBC 2) Requirements",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-04-19",
    "bluf": "This notice establishes the Risk-Based Capital (RBC 2) framework for all licensed insurers in Singapore, mandating specific methodologies for the valuation of assets and liabilities and the maintenance of minimum capital adequacy requirements. As per Paragraph 4, insurers must ensure their financial resources are adequate at all times to meet their obligations to policy owners.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-mas-payment-services-act-2019-dpt",
    "title": "Singapore Payment Services Act 2019 (No. 2 of 2019) - Digital Payment Token (DPT) Service Licensing, AML/CFT Obligations, and Capital Requirements",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Singapore Payment Services Act 2019 (PSA) requires any entity providing digital payment token (DPT) services to be licensed by the Monetary Authority of Singapore (MAS) and comply with stringent AML/CFT, technology risk management, and capital adequacy requirements. Licensing is tiered into Standard Payment Institutions (SPI) and Major Payment Institutions (MPI) based on transaction volume thresholds defined in Section 6(5) of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "crypto-aml-travel-rule"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-mas-payment-services-amendment-act-2021",
    "title": "Payment Services (Amendment) Act 2021",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Singapore Payment Services (Amendment) Act 2021 expands the regulatory scope of the Monetary Authority of Singapore (MAS) over Digital Payment Token (DPT) services, bringing activities such as DPT transmission, custodian wallet services, and facilitating DPT exchanges under the Payment Services Act licensing framework, as detailed in the amendments to Section 6 of the principal Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "fatf-travel-rule-v2",
      "eu-mica-casp-obligations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-mas-stablecoin-regulatory-framework-2023",
    "title": "MAS Finalises Stablecoin Regulatory Framework for Single-Currency Stablecoins (SCS) Pegged to the Singapore Dollar or G10 Currencies",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation applies to issuers of single-currency stablecoins (SCS) pegged to the Singapore Dollar or any G10 currency and issued in Singapore. It mandates requirements for value stability via reserve composition, capital adequacy, redemption at par within five business days, and disclosures. Only compliant issuers may label their tokens as 'MAS-regulated stablecoins' under the framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "bis-iosco-pfmi-applied-to-dlt-systems",
      "eu-dlt-pilot-regime-2022-858"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "singapore-mas-technology-risk-guidelines-insurance-2021",
    "title": "MAS Technology Risk Management Guidelines for Insurance Licensees (2021)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "These guidelines by the Monetary Authority of Singapore (MAS) mandate that all licensed insurers establish a robust technology risk management framework, holding the Board and Senior Management accountable for oversight of technology risk, cyber resilience, and management of third-party service providers, as outlined in Section 1.3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-pdpa-2012",
      "nist-sp-800-161r1-csrm-practices",
      "nist-sp-800-39-managing-information-security-risk",
      "iso-27031-dr-readiness"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "singapore-media-development-authority-content-code",
    "title": "Content Code for Over-the-Top (OTT) Video Services",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes age classification (G/PG/PG13/NC16/M18/R21) and content standards for violence, sex, and racial/religious sensitivity for OTT video services in Singapore. It applies to providers of Internet-based video-on-demand platforms under IMDA's regulatory purview, requiring adherence to classification guidelines and complaint handling mechanisms as per the OTT Content Code.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "singapore-model-ai-governance-framework-2020",
    "title": "Model AI Governance Framework (Second Edition, 2020) - Internal Governance, Decision-Making Model, Operations Management and Stakeholder Interaction Principles",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This framework provides organizations with guidance on establishing internal governance structures, risk management processes, and human-centric AI deployment practices to ensure ethical, transparent, and accountable use of AI systems in Singapore. It applies to private sector organizations deploying AI in commercially relevant domains, particularly those with significant societal impact (Section 2.1, 3.1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "asean-model-ai-governance-v2-2020",
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "australia-ai-ethics-framework-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "singapore-model-ai-governance-framework-2020-v2",
    "title": "Model Artificial Intelligence Governance Framework Second Edition (2020)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This voluntary framework from Singapore's IMDA guides organizations in the responsible deployment of AI by outlining principles for internal governance, risk assessment, and operational management. It emphasizes that AI decisions should be explainable, transparent, and fair (Principle 1), and that AI systems should be human-centric (Principle 2), with clear lines of responsibility and human oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "asean-model-ai-governance-v2-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-mpa-merchant-shipping-act-cap-179",
    "title": "Singapore Merchant Shipping Act (Cap. 179) - MPA Maritime Regulatory Framework",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2020-01-01",
    "bluf": "Singapore's Merchant Shipping Act (Cap. 179) administered by MPA (Maritime and Port Authority of Singapore) governs vessel registration under the Singapore Registry of Ships (SRS), port state control inspections, maritime casualty investigations, pilotage in Singapore Port, and Singapore's implementation of IMO conventions including SOLAS, MARPOL, and MLC 2006 for over 4,000 Singapore-flagged vessels.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-consolidated-2020",
      "imo-marpol-pollution",
      "imo-stcw-convention-manila-2010",
      "ism-code-vessel-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "singapore-mtcs-tier-3-cloud-security-standard",
    "title": "Multi-Tier Cloud Security (MTCS) Certification - Tier 3 for High-Sensitivity Government Data",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This standard establishes mandatory security requirements for cloud service providers handling high-sensitivity government data in Singapore. Compliance with Tier 3 of the MTCS framework, as administered by IMDA, is required for certification and engagement with public sector agencies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "cobit-2019-governance-framework",
      "bsa-software-asset-management-iso-19770"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "singapore-patents-act-cap-221-ipos-filing",
    "title": "Singapore Patents Act Cap 221 & Trade Marks Act Cap 332 - IPOS Filing & IP Protection",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Singapore's Patents Act (Cap 221) and Trade Marks Act (Cap 332) administered by IPOS establish a 20-year patent term with novelty and inventive step requirements, and a trade mark registration system providing 10-year renewable protection - essential for technology and brand IP protection in Singapore's innovation economy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "singapore-payment-services-act-2019-mas-crypto-licensing",
    "title": "Singapore Payment Services Act 2019 - MAS Digital Payment Token Licensing",
    "domain": "Crypto & Sovereign Finance",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Singapore's Payment Services Act 2019 (No. 2 of 2019) requires Digital Payment Token (DPT) service providers - including crypto exchanges and custodians - to hold a Standard or Major Payment Institution (MPI) licence from MAS; amendment in 2021 extended DPT requirements to stablecoin issuers and custodians.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "singapore-pdpa-2012-2020-amendment",
    "title": "Personal Data Protection Act 2012 (No. 26 of 2012) as amended by the Personal Data Protection (Amendment) Act 2020",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Singapore PDPA, as amended in 2020, mandates that organizations notify the Personal Data Protection Commission (PDPC) of a data breach within 3 calendar days (Part VIA, Section 26C) and introduces a data portability obligation (Part VIB). It also significantly increases financial penalties for non-compliance to up to 10% of an organization's annual turnover in Singapore (Section 29(2)(d)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-pdpa-2012",
      "oecd-privacy-guidelines-2013",
      "apec-cbpr-system-2011"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "singapore-pdpa-2012-personal-data-protection-obligations",
    "title": "Singapore Personal Data Protection Act 2012 (PDPA) - Data Protection Obligations, DPO Requirement, and Mandatory Breach Notification",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Singapore's PDPA (Act 26 of 2012, as amended by PDPA Amendment Act 2020) requires organisations to appoint a Data Protection Officer (DPO), comply with nine data protection obligations, notify PDPC and affected individuals of significant breaches within 3 business days, and establishes financial penalties up to SGD 1M or 10% of annual local turnover (whichever is higher). The PDPA does not require a legal basis beyond consent for most processing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "singapore-cybersecurity-act-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "singapore-pdpa-health-data-2026",
    "title": "Singapore PDPA - Processing of Personal Data in the Healthcare Sector (2026)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The Personal Data Protection Act (PDPA) requires organisations handling personal data (including sensitive health data) to comply with consent, purpose limitation, notification, access/correction, security, retention limitation, and transfer obligations. Healthcare organisations must implement stronger safeguards for health data, follow PDPC Advisory Guidelines for the Healthcare Sector, and comply with mandatory breach notification requirements. Data transfers outside Singapore require adequate protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "singapore-pub-newater-abc-waters-programme",
    "title": "Singapore PUB NEWater and Active Beautiful Clean Waters (ABC) Programme",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2022-04-01",
    "bluf": "The Public Utilities Board (PUB), Singapore's National Water Agency, is statutorily established under the Public Utilities Act 2001 and is the integrated water authority for Singapore covering water supply, used water, and stormwater management. PUB operates the Four National Taps strategy comprising local catchment water, imported water from Johor, NEWater, and desalinated water. NEWater is high-grade reclaimed water produced through advanced membrane technology and ultraviolet disinfection from treated used water that meets the World Health Organization's drinking water quality guidelines and is used principally for industrial and indirect potable use through reservoir blending. Singapore operates five NEWater plants meeting up to 40 percent of national water demand and targeting 55 percent by 2060.\n\nThe Active, Beautiful, Clean Waters (ABC Waters) Programme is a long-term strategic initiative launched in 2006 to transform Singapore's drains, canals, and reservoirs into vibrant community spaces while integrating water quality treatment through bioretention swales, rain gardens, and constructed wetlands. The Programme is governed by the ABC Waters Design Guidelines published by PUB and revised periodically (most recent edition 4.0, 2022) which set technical specifications for nature-based stormwater treatment infrastructure that developers must incorporate where the development site exceeds the threshold area set by the Code of Practice on Surface Water Drainage. NEWater quality is regulated by the Public Utilities (Reclaimed Water) Regulations and water reclamation operations are licensed by PUB.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sg-pdpa-2012",
      "ramsar-convention-1971-wetlands-international-importance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-public-utilities-act-cap-261-pub",
    "title": "Singapore Public Utilities Act (Cap. 261) - PUB Four National Taps and Water Security Framework",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Singapore's Public Utilities Act (Cap. 261, 2002 Revised Edition) establishes PUB, Singapore's National Water Agency, with regulatory authority over water supply, sewerage and drainage. Singapore's water security is built on the Four National Taps strategy: local catchment water, imported water (Malaysia agreements expiring 2061), NEWater (highly purified recycled water), and desalinated water. PUB licences water service works contractors, regulates water quality to international standards, and manages the national sewer and used-water infrastructure. Industrial and commercial users with significant water usage must implement water conservation plans. NEWater supplies 40% of Singapore's water needs. Rainwater harvesting is regulated under the Environment Public Health Act and PUB guidelines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-water-act-2007-murray-darling-basin"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "singapore-remote-gambling-act-2014",
    "title": "Singapore Remote Gambling Act 2014 - Online Gambling Prohibition and Exemption Framework",
    "domain": "Gaming & Gambling",
    "version": "2014-11",
    "last_updated": "2026-05-09",
    "bluf": "Singapore's Remote Gambling Act 2014 (Cap. 323A) prohibits all forms of remote gambling (online, telephone, and other electronic means) unless the operator holds an exemption issued by the Minister of Home Affairs; exemptions are granted only to Singapore Pools and Singapore Turf Club as designated domestic gambling operators; the Act carries criminal penalties for unlicensed operators and provides an Internet Content Provider blocking regime for offshore gambling sites.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021",
      "responsible-gambling-grb-standards-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "singapore-road-transport-act-cap-276-lta",
    "title": "Singapore Road Transport Act Cap. 276 - LTA Vehicle Registration, Commercial Vehicle Permits and Certificate of Entitlement",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Singapore's Road Transport Act (Cap. 276, originally enacted 1961, consolidated 2004, administered by the Land Transport Authority (LTA)) governs vehicle registration, licensing, and the Certificate of Entitlement (COE) quota system that controls the total vehicle population; requires all vehicles including goods vehicles to be registered with LTA and display a valid road tax disc; mandates Annual Inspection for all commercial vehicles every 6 or 12 months depending on vehicle age; requires commercial goods vehicles to hold a valid Goods Vehicle Licence (GVL) specifying permitted payload and routes; and imposes fines of up to SGD 2,000 and imprisonment up to 3 months for operating a goods vehicle without a valid GVL.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-heavy-vehicle-national-law-2012-nhvr"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "singapore-telecommunications-act-1999-imda",
    "title": "Telecommunications Act 1999",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Telecommunications Act 1999 requires public telecommunication licensees to comply with the provisions of Part 2, including section 3 on exclusive privilege with respect to telecommunications and section 5 on the power to license telecommunication systems and services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "six-sigma-iso-13053-quantitative-methods-process",
    "title": "ISO 13053:2011 - Quantitative Methods in Process Improvement: Six Sigma (DMAIC Methodology, DFSS Approach and Black Belt Competence)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "ISO 13053:2011 specifies the methodology and statistical tools used in Six Sigma for process improvement, including the DMAIC (Define, Measure, Analyze, Improve, Control) and DFSS (Design for Six Sigma) approaches, and defines the competence requirements for Six Sigma Black Belts. It applies to organizations seeking to implement structured, data-driven quality improvement programs (Clause 5.1, Clause 6.1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sj-gdpr-framework",
    "title": "Svalbard and Jan Mayen - Norwegian GDPR Implementation and Datatilsynet Supervisory Framework",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Svalbard is a Norwegian archipelago located in the Arctic Ocean north of the Norwegian mainland, and Jan Mayen is a Norwegian island in the Arctic Ocean to the northeast of Iceland. Both are Norwegian territories subject to Norwegian sovereignty. Norway is a member of the European Economic Area (EEA) and has implemented the General Data Protection Regulation (GDPR) through the EEA Agreement, incorporated into Norwegian law via the Personal Data Act (Personopplysningsloven 2018). The GDPR therefore applies in Svalbard and Jan Mayen as Norwegian territories subject to EEA law. The Norwegian Data Protection Authority (Datatilsynet) is the competent supervisory authority for data protection matters in Svalbard and Jan Mayen. Svalbard has a unique international legal status established by the Svalbard Treaty of 1920, which grants Norway sovereignty while allowing nationals of signatory states the right to engage in commercial activities. Svalbard has become an important location for data centres due to its cold climate (reducing cooling costs), stable geopolitical environment, and access to renewable energy. Organisations established in Svalbard or Jan Mayen, or processing personal data of individuals located in these territories, must comply with Norwegian GDPR implementation law, including requirements for lawful basis, data subject rights, data protection impact assessments for high-risk processing, mandatory breach notification to Datatilsynet within 72 hours, and appointment of a Data Protection Officer where required.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/sj-gdpr-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sk-pdpa-2018",
    "title": "Slovakia Personal Data Protection Act 2018 (Act No. 18/2018 Z. z.) - GDPR National Implementation",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Slovakia's Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov (Act No. 18/2018 Coll. on the Protection of Personal Data and on Amendments to Certain Acts), published in the Collection of Laws of the Slovak Republic and in force from 25 May 2018 (aligned with GDPR application date), is Slovakia's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Slovakia. The GDPR is directly applicable Slovak law by virtue of Slovakia's EU membership. Act No. 18/2018 provides national derogations, additions, and specifications that the GDPR permits EU member states to adopt and repeals the prior Slovak Personal Data Protection Act (Act No. 122/2013 Coll.). Enforcement: the Úrad na ochranu osobných údajov Slovenskej republiky (UOOU SR - Office for Personal Data Protection of the Slovak Republic) is Slovakia's independent data protection supervisory authority. The UOOU SR is Slovakia's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Slovakia is a Central European member state with a significant automotive manufacturing sector and growing IT outsourcing industry; the significant volume of employee and customer personal data in these sectors makes GDPR and Act No. 18/2018 compliance particularly important. Key Slovak national provisions: (1) Age of digital consent: Slovakia has maintained the GDPR default of 16 years for information society services; data subjects under 16 require parental or guardian consent; (2) Employment - the Slovak Labour Code (Zákonník práce, Act No. 311/2001 Z. z. as amended) contains specific provisions on employee monitoring and privacy that interact with GDPR and Act No. 18/2018; employer monitoring requires advance employee notification; (3) Freedom of expression - exemptions for journalistic, academic, artistic, and literary processing aligned with GDPR Art. 85 and Slovak constitutional freedom of expression (Slovak Constitution, Art. 26); (4) Health data - processing of health data in Slovakia is subject to specific Slovak health legislation (Act on Health Care) in addition to GDPR Art. 9; (5) Public sector - Slovak public authorities are subject to Act No. 18/2018 and Slovak administrative law; (6) Criminal data - Act No. 18/2018 restricts private entity processing of personal data relating to criminal convictions. Fines: GDPR administrative fines apply in Slovakia - up to EUR 20 million or 4% of global annual turnover. The UOOU SR has been an active enforcement authority with fines imposed against private sector entities and guidance published on employment monitoring, biometric data, and public authority processing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sl-dpa-2022",
    "title": "Sierra Leone Data Protection Act 2022",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Sierra Leone's Data Protection Act 2022 establishes a national framework for the collection, storage, and processing of personal data. It creates a Data Protection Commissioner, confers rights on data subjects (access, rectification, restriction, erasure, and objection), mandates lawful bases for processing, and requires mandatory notification of personal data breaches. Cross-border data transfers are restricted to jurisdictions offering adequate protection. The Act aligns with the ECOWAS Supplementary Act on Personal Data Protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/sl-dpa-2022.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "slsa-supply-chain-security-levels",
    "title": "Supply-chain Levels for Software Artifacts (SLSA) v1.0",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2023-06-12",
    "bluf": "The SLSA framework establishes four levels of software security assurance to protect against supply chain threats by requiring verifiable provenance for software artifacts. Compliance, as detailed in the 'Requirements' section, mandates progressively stricter controls on the build process, source code integrity, and provenance generation to prevent unauthorized modifications and ensure artifact integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-160-v1r1",
      "iso-iec-5230-openchain"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "slsa-v1-0-supply-chain-levels-for-software-artifacts",
    "title": "SLSA v1.0 Supply-chain Levels for Software Artifacts (OpenSSF Build Track L0, L1, L2, L3; Producer, Build Platform, and Verifier Requirements; in-toto Attestation Framework)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "SLSA (Supply-chain Levels for Software Artifacts), version 1.0, is the OpenSSF-governed framework for assessing the trustworthiness of software build provenance and is published authoritatively at slsa.dev under the Linux Foundation Community Specification License 1.0. SLSA v1.0 contains only a Build track with four levels: Build L0 (no requirements; represents the lack of SLSA), Build L1 (Provenance Exists - the package has provenance describing how it was built; completeness is best effort; sufficient to catch mistakes), Build L2 (Provenance is Authentic - provenance is generated and signed by a hosted build platform, consumers validate authenticity through digital signature, data in the provenance must be obtained from the build platform, the platform must prevent tenant tampering), and Build L3 (Provenance is Unforgeable - signing material must be stored in a secure key management system not accessible to user-defined build steps, every field in the provenance must be generated or verified by the build platform, an ephemeral build environment must be provisioned for each build, simultaneous builds cannot influence each other, and remote services must be captured as external parameters). Each level imposes Producer requirements (select a capable build platform, follow a consistent build process, distribute provenance to consumers), Build platform requirements (provenance generation, isolation strength, signing-key protection), and Verification requirements (digest match, signature verification, expectations match). SLSA Provenance is the recommended provenance format and is published as an in-toto Attestation Framework predicate; the Source track was removed from v1.0 to focus on Build and may be added in future versions. SLSA v1.0 is the operational follow-on to Google's earlier Binary Authorization for Borg model and is the standard reference for software supply chain attestation under the OpenSSF Secure Software Foundation umbrella.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "build_l0_no_guarantees",
        "build_l1_provenance_exists",
        "build_l2_provenance_is_authentic",
        "build_l3_provenance_is_unforgeable",
        "producer_requirements_all_levels",
        "verifier_requirements",
        "source_track_removed_from_v1_0",
        "in_toto_attestation_framework_alignment",
        "sigstore_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "in-toto-attestation-framework-cncf",
      "sigstore-cosign-fulcio-rekor-keyless-signing",
      "spdx-3-0-iso-iec-5962-2021-sbom-standard",
      "cyclonedx-1-7-owasp-ecma-sbom-standard",
      "us-eo-14028-cybersecurity-2021-sbom-mfa-zerotrust"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "sm-pdpl-2018",
    "title": "San Marino Law No. 70/2018 on Personal Data Protection - Garante Sammarinese",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "San Marino's Law No. 70 of 23 May 2018 on Personal Data Protection (Legge 23 maggio 2018 n.70 per la tutela delle persone fisiche con riguardo al trattamento dei dati personali), enacted by the Grand and General Council of San Marino, is San Marino's primary comprehensive personal data protection legislation establishing a GDPR-aligned rights-based framework for the protection of personal data. San Marino is a sovereign microstate entirely surrounded by Italy, with a civil law legal system closely related to the Italian legal tradition; although not a member of the European Union, San Marino maintains a Customs Union and Cooperation Agreement with the EU and has close economic and institutional ties with Italy, driving alignment of San Marino's data protection framework with EU GDPR standards. Law No. 70/2018 was specifically enacted to align San Marino's data protection framework with the EU General Data Protection Regulation that entered into force on 25 May 2018, reflecting San Marino's commitment to European data protection standards. The supervisory authority is the Guarantor for the Protection of Personal Data of the Republic of San Marino (Garante per la Protezione dei Dati Personali della Repubblica di San Marino - Garante Sammarinese), an independent institution responsible for oversight, enforcement, and guidance on personal data protection standards throughout the Republic. Key features of San Marino's Law No. 70/2018: (1) Scope - applies to personal data processing by persons established in San Marino or processing data of individuals in San Marino; (2) Data processing principles - processing must comply with: lawfulness; fairness; transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right to data portability; and right not to be subject to solely automated decisions; (6) Data Protection Officer - required for public authorities and organisations processing personal data on a large scale or systematically; (7) Breach notification - controllers must notify the Garante Sammarinese of personal data breaches within 72 hours; high-risk breaches require data subject notification; (8) Data Protection Impact Assessment - required for high-risk processing; (9) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or using approved safeguards; and (10) Administrative fines - graduated fines aligned with GDPR fine structures. San Marino's GDPR-aligned framework supports its position as a historic microstate with significant financial services, tourism, and digital economy activities serving European clients and visitors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "smart-container-iot",
    "title": "Smart Container IoT Tracking",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Smart Container IoT Tracking systems must adhere to stringent security and data privacy standards for ensuring regulatory compliance across global supply chains. As mandated by leading frameworks like NIST and ISO/IEC, all communications require robust encryption; data in transit necessitates TLS 1.3, while information at rest must utilize AES-256 encryption. Mutual TLS authentication is mandatory for establishing trusted device-to-server connections. Device integrity is paramount, with secure boot enabled and all firmware updates being cryptographically signed to prevent unauthorized modifications. Fortification of administrative access over platform controls requires mandatory multi-factor authentication. Network security follows a principle of least privilege, wherein inbound ports operate under a default-deny policy. In alignment with C-TPAT security criteria, physical integrity gets monitored via tamper detection mechanisms calibrated to a sensitivity level of 4. Data governance must align with privacy regulations like GDPR, applying the data minimization principle. Geolocation information retention is strictly limited to a 180-day period, after which it requires purging. Security event logs, however, demand maintenance for one full 365-day term for audit and forensic purposes. To sustain a secure posture, systems will undergo comprehensive vulnerability scanning at a frequency not exceeding 30 days, consistent with FIPS cryptographic standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-28000-supply-chain",
      "gs1-epcis-transparency",
      "c-tpat-minimum-security",
      "wco-safe-framework",
      "nist-sp-800-213a-iot-catalog",
      "pci-dss-v4-requirement-4"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "smart-contract-audit-swc",
    "title": "Smart Contract Audit (SWC)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Smart Contract Weakness Classification (SWC) Registry is the authoritative taxonomy of smart contract security vulnerabilities, maintained by the Ethereum security community and analogous to the CVE/CWE system for traditional software. It defines 37 weakness classes (SWC-100 through SWC-136) covering Solidity and EVM-specific vulnerabilities. Any smart contract deployed to a public blockchain handling real value must undergo a formal security audit mapping findings to SWC entries before deployment. The consequences of unaudited smart contracts include irreversible fund loss - the DAO hack ($60M, 2016), Parity multisig freeze ($150M, 2017), and Poly Network bridge exploit ($611M, 2021) all resulted from vulnerabilities catalogued in the SWC registry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "smpte-st-2110-media",
    "title": "SMPTE ST 2110",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with the SMPTE ST 2110 suite of standards for professional media over managed IP networks mandates a stringent set of technical and operational configurations. Foundational specifications dictate that all network devices and endpoints must adhere to precise timing protocols, necessitating mandatory PTPv2 synchronization with a PTP domain number not exceeding 127 and a maximum allowed PTP jitter of 1000 nanoseconds. To ensure proper traffic management and discovery, the framework requires IGMPv3 support for multicast stream subscriptions alongside enforced NMOS discovery and registration for all endpoints. Performance criteria are rigorously defined; total end-to-end latency across the signal chain is capped at 10 milliseconds. Core architectural principles demand that video, audio, and ancillary data travel as separate essence flows, and the system must maintain a minimum video compliance level of 1. For system resilience and reliability, the enforcement of network redundancy through SMPTE ST 2022-7 for seamless protection switching is obligatory. Furthermore, robust network configuration is paramount, requiring QoS via DSCP marking on all packets, enabled LLDP for device discovery, and the strict enforcement of control plane segmentation to isolate management traffic from media essence flows, thereby securing the operational integrity of the broadcast environment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itu-r-bt-709-hdtv",
      "itu-r-bt-2020-uhdtv"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sn-code-des-marches-publics-decret-2014-1212-armp-sygmap",
    "title": "Senegal Code des Marches Publics Decret 2014-1212 of 22 September 2014 as amended by Decret 2022-2295 and ARCOP / SYGMAP",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Senegalese Code des Marches Publics (Public Procurement Code) approved by Decret 2014-1212 of 22 September 2014 (Journal Officiel de la Republique du Senegal No. 6804 of 4 October 2014 effective 4 October 2014), as substantially amended by Decret 2022-2295 of 28 December 2022 (modernisation amendments) and supplemented by application orders (arretes d'application), is the principal Senegalese regulatory instrument governing procurement of works, supplies, intellectual services, and consulting services by contracting authorities including the State (Etat), local collectivities (collectivites territoriales / regions, departements, communes), public administrative establishments (etablissements publics administratifs / EPA), public-sector companies (societes nationales), public-sector agencies, and other contracting authorities subject to the Code. The 2014 Decree replaced the prior Decret 2011-1048 and aligned the Senegalese procurement regime with WAEMU Directive 04/2005/CM/UEMOA on public procurement (transposed across the WAEMU region). The Autorite de Regulation de la Commande publique (ARCOP, formerly ARMP / Autorite de Regulation des Marches Publics, ren amed in 2022) is the central regulatory authority responsible for procurement regulation, complaint resolution, supplier debarment, and procurement guidance. The Direction Centrale des Marches Publics (DCMP) under the Ministry of Finance and Budget conducts ex-ante control of high-value procurement. The Systeme de Gestion des Marches Publics (SYGMAP / sygmap.sn) is the federal e-procurement platform. Procurement methods established by the Code des Marches Publics 2014/2022 art. 50 to 102 comprise (a) Appel d'offres ouvert (Open Call for Tenders, the default open public procedure), (b) Appel d'offres restreint (Restricted Call for Tenders, with prequalification), (c) Procedure de demande de renseignements et de prix (Request for Information and Prices, for medium-value), (d) Procedure de demande de cotation (Request for Quotations, for small-value), (e) Entente directe (Direct Negotiation, sole-source under prescribed exceptions in art. 76 to 78), (f) Concours (Design Contest), and (g) Procedures simplifiees (Simplified Procedures, for prescribed lower-value contracts). The Cour des Comptes du Senegal conducts ex-post procurement audit. Senegal is a party to ECOWAS, WAEMU (UEMOA), AfCFTA, and UNCAC. Senegal is NOT a party to the WTO GPA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "sn-dp-law-2008",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "sn-dp-law-2008",
    "title": "Senegal Personal Data Protection Law No. 2008-12 - CDP",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Senegal's Loi No. 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel (Personal Data Protection Law No. 2008-12 of 25 January 2008) - published in the Journal Officiel de la République du Sénégal and promulgated by Presidential Decree No. 2008-721 of 30 June 2008 - is Senegal's primary personal data protection legislation and was one of the first comprehensive data protection laws enacted by a Sub-Saharan African country. The law was enacted as part of Senegal's broader legal and institutional framework for the digital economy under President Abdoulaye Wade's TICS (Technologies de l'Information et de la Communication) programme. The supervisory authority is the Commission de Protection des Données Personnelles (CDP - Personal Data Protection Commission), an independent administrative authority established under the law with responsibility for receiving declarations and authorisations from data controllers, investigating complaints from data subjects, conducting audits, and enforcing the law. Key features of Senegal's Loi No. 2008-12: (1) Scope - applies to automated and non-automated processing of personal data by public and private bodies established in Senegal or using processing means located in Senegal; (2) Data processing principles - processing must comply with: lawfulness (loyauté); finality (finalité) - purpose limitation; proportionality (adéquation et pertinence); accuracy (exactitude); security (sécurité); and confidentiality (confidentialité); (3) Sensitive personal data - the law prohibits processing of sensitive categories without lawful basis: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual life; genetic data; and criminal convictions; (4) Lawful processing conditions - consent; legal obligation; contractual necessity; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to object to processing; right not to be subject to solely automated decisions; (6) Declaration and authorisation regime - controllers must file a declaration (déclaration) with the CDP for standard processing activities or an authorisation (autorisation) for sensitive or high-risk processing before commencing processing; (7) Cross-border transfers - personal data may only be transferred to states providing equivalent protection or subject to adequate contractual safeguards; (8) Security obligations - controllers must implement technical and organisational security measures proportionate to the risk; (9) CDP enforcement - investigates complaints; conducts audits; issues mise en demeure (formal notices); imposes administrative sanctions; and refers serious violations to the judicial authorities; (10) ECOWAS and African context - Senegal participates in ECOWAS data governance harmonisation and AU data protection frameworks. Senegal ratified the Council of Europe Convention 108 for the Protection of Individuals with regard to Automatic Processing of Personal Data in 2016, demonstrating alignment with international data protection standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "snomed-ct-clinical-terminology",
    "title": "SNOMED CT International Edition - Clinical Terminology Standard for Electronic Health Record Data Capture",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "SNOMED CT is a comprehensive, multilingual clinical healthcare terminology that provides a standardized way to represent clinical information in electronic health records (EHRs). It requires healthcare organizations and software vendors to use its unique concept identifiers and hierarchical structure to ensure semantic interoperability for clinical data exchange, analysis, and decision support, as outlined in its technical specifications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hl7-fhir-v4-interop",
      "us-21st-century-cures-act-2016",
      "eu-health-data-space-2024",
      "hipaa-security-rule"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "so-nca-framework",
    "title": "Somalia NCA Framework - AU Malabo Convention and Constitutional Privacy Obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Federal Government of Somalia has established the National Communications Authority (NCA) as the regulatory body for telecommunications and electronic communications services in the Federal Republic of Somalia. The Provisional Constitution of the Federal Republic of Somalia (2012) establishes fundamental rights including the right to privacy of personal life, family, home, and correspondence. As a member state of the African Union, Somalia is subject to the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014), which provides the applicable regional standard for personal data protection. Somalia does not have a standalone comprehensive personal data protection law. The constitutional privacy framework, NCA regulatory requirements for telecommunications operators, and AU Malabo Convention principles together constitute the reference legal framework for personal data protection obligations in Somalia. Organisations processing personal data in Somalia must respect constitutional privacy rights, comply with NCA licensing and regulatory requirements for electronic communications services, and implement personal data processing practices consistent with AU Malabo Convention principles. The complex governance environment in parts of Somalia - including the distinct regulatory jurisdictions of Somaliland, Puntland, and other regional administrations - creates significant compliance complexity, and organisations should seek current guidance from local legal counsel familiar with the applicable governance framework in the specific Somali territory where they operate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/so-nca-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "soa-code-conduct",
    "title": "SOA Code of Conduct",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the Society of Actuaries (SOA) Code of Conduct necessitates a multifaceted verification process. An actuary must be qualified for an assignment and demonstrate complete adherence to all applicable Actuarial Standards of Practice (ASOPs). Full transparency is mandatory; any potential conflicts of interest must have been disclosed, and all communications are required to include appropriate disclosures. Strict confidentiality for all client information must be maintained. Furthermore, adequate work product control mechanisms need to be in place, supported by a mandatory peer review process. Every assumption utilized within actuarial services must be justified and properly disclosed, while all data sources require comprehensive documentation. Professionalism extends to external representations, mandating that all advertising is factual and not misleading. To maintain competency, practitioners must satisfy an annual continuing professional development requirement of at least 30 hours. Finally, the system confirms that no material violations have been reported against the professional, ensuring a high standard of ethical conduct. This framework ensures that actuarial services are rendered with integrity, competence, and professionalism.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "soc-1-type-2-finance",
    "title": "SOC 1 Type II (Finance)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "A Service Organization Control (SOC) 1 Type II attestation provides assurance regarding the operational effectiveness of controls relevant to user entities' internal control over financial reporting (ICFR) over a specified examination period. Governing attestation standards mandate the establishment of a robust control environment, underpinned by systematic risk management and monitoring activities. This framework requires that a comprehensive financial risk assessment be conducted at least every 12 months. Key operational controls stipulate that user access reviews are completed quarterly and that terminated user accounts are deactivated within a 24-hour timeframe. Furthermore, all system changes must undergo a formal change management approval process, while data processing integrity checks are executed daily to ensure accuracy and completeness. Continuous oversight is evidenced through quarterly control monitoring and a formal management review of those controls. The organization's resilience posture necessitates an incident response plan be tested annually. Vendor risk management programs must specifically assess third-party ICFR risks. To foster an ethical culture, a minimum 95 percent completion rate for ethics training is enforced across the organization. All audit evidence and related documentation supporting these control activities must be preserved for a 7-year evidence retention period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "iso-37301-compliance-mgt",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "soc-2-type-ii-trust-services-criteria-2024",
    "title": "AICPA Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (2017 Edition, Updated for 2024 Applicability)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This standard defines the Trust Services Criteria (TSC) used in SOC 2 Type II audits to evaluate controls over security, availability, processing integrity, confidentiality, and privacy in service organizations, particularly cloud and SaaS providers. Key criteria include CC6-CC9 for access and monitoring, A1 for availability, PI1 for processing integrity, C1 for confidentiality, and P1-P8 for privacy practices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "cobit-2019-governance-framework",
      "eu-gdpr-cloud-data-processing"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "soc-3-general-use-report",
    "title": "AICPA SOC 3 - Trust Services Report for General Use",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "SOC 3 is a general-use System and Organization Controls report based on the same Trust Services Criteria as SOC 2, but designed for broad distribution without the detailed description of controls and tests found in a SOC 2 report. It contains management assertion, the boundaries of the system, the principal service commitments and system requirements, and the service auditor opinion, allowing an organization to publicly demonstrate that an independent CPA examined its controls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "soc-for-cybersecurity",
    "title": "AICPA SOC for Cybersecurity - Cybersecurity Risk Management Reporting Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "SOC for Cybersecurity is an AICPA reporting framework for an examination of an entity-wide cybersecurity risk management program. Unlike SOC 2, which covers a defined system at a service organization, SOC for Cybersecurity reports on the entity as a whole and is intended for general use by boards, investors, and other stakeholders. It uses description criteria for the cybersecurity risk management program together with the control (trust services) criteria.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "soc-for-supply-chain",
    "title": "AICPA SOC for Supply Chain - Supply Chain Risk Management Reporting",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "SOC for Supply Chain is an AICPA reporting framework that helps organizations communicate information about the controls within a production, manufacturing, or distribution system and assess the effectiveness of controls that mitigate supply chain risks. It pairs description criteria for the system with the trust services criteria, enabling customers and business partners to evaluate supply chain risk in a consistent, examined report.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "soc2-availability-criteria",
    "title": "SOC 2 (Availability)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with governing availability principles is demonstrated through a comprehensive framework of controls and procedural enforcement. The entity maintains robust system performance monitoring capabilities, configured to generate alerts when CPU usage exceeds an 85 percent threshold or when memory utilization surpasses a 90 percent benchmark. These measures are integral for proactive incident response and maintaining operational integrity. A formalized capacity management plan underpins the organization's ability to meet its defined availability Service Level Agreement, which stipulates a stringent 99.9 percent uptime target. Business continuity is further assured by a complete disaster recovery plan containing documented Recovery Time Objectives and Recovery Point Objectives. The efficacy of this plan is validated through drill tests conducted annually. Supporting these recovery strategies, an automated data backup process executes every 24 hours, safeguarding critical information against loss. To confirm functional restorability and data integrity, backup recovery procedures are also tested on an annual basis. These combined controls, derived from established trust services criteria, provide verifiable assurance that the system is protected against events that could impair its availability and is able to meet the entity's objectives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-22301-business-cont",
      "iso-27031-dr-readiness",
      "nist-800-61-incident-resp",
      "iso-20000-service-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "soc2-cc1-control-environment",
    "title": "AICPA SOC 2 Common Criteria CC1 - Control Environment (COSO Principles 1-5)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "CC1 is the Control Environment series of the SOC 2 Common Criteria, drawn from COSO Principles 1-5. It requires the service organization to demonstrate a commitment to integrity and ethical values, board independence and oversight, defined organizational structures and reporting lines, a commitment to competence, and accountability for internal control responsibilities. These five criteria (CC1.1-CC1.5) set the governance foundation every SOC 2 examination evaluates first.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "soc2-cc2-communication-information",
    "title": "AICPA SOC 2 Common Criteria CC2 - Communication and Information (COSO Principles 13-15)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "CC2 is the Communication and Information series of the SOC 2 Common Criteria (COSO Principles 13-15). It requires the entity to obtain or generate and use relevant, quality information to support internal control, to internally communicate information including control objectives and responsibilities, and to communicate with external parties about matters affecting internal control. The three criteria are CC2.1-CC2.3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "soc2-cc3-risk-assessment",
    "title": "AICPA SOC 2 Common Criteria CC3 - Risk Assessment (COSO Principles 6-9)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "CC3 is the Risk Assessment series of the SOC 2 Common Criteria (COSO Principles 6-9). It requires the entity to specify objectives with sufficient clarity, identify and analyze risks to those objectives, consider the potential for fraud, and identify and assess changes that could significantly affect the system of internal control. The criteria are CC3.1-CC3.4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "soc2-cc4-monitoring-activities",
    "title": "AICPA SOC 2 Common Criteria CC4 - Monitoring Activities (COSO Principles 16-17)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "CC4 is the Monitoring Activities series of the SOC 2 Common Criteria (COSO Principles 16-17). It requires the entity to select, develop, and perform ongoing and separate evaluations to ascertain whether the components of internal control are present and functioning, and to evaluate and communicate internal control deficiencies in a timely manner to those responsible for corrective action. The criteria are CC4.1-CC4.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "soc2-cc5-control-activities",
    "title": "AICPA SOC 2 Common Criteria CC5 - Control Activities (COSO Principles 10-12)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "CC5 is the Control Activities series of the SOC 2 Common Criteria (COSO Principles 10-12). It requires the entity to select and develop control activities that contribute to the mitigation of risks to acceptable levels, to select and develop general control activities over technology, and to deploy control activities through policies that establish what is expected and procedures that put policies into action. The criteria are CC5.1-CC5.3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "soc2-cc6-logical-physical-access-controls",
    "title": "AICPA SOC 2 Common Criteria CC6 - Logical and Physical Access Controls (CC6.1-CC6.8)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "CC6 is the Logical and Physical Access Controls series of the SOC 2 Common Criteria. Its eight criteria (CC6.1-CC6.8) require the entity to implement logical access security software and architecture, to register and authorize new credentials, to provision, modify, and remove access, to restrict physical access, to protect assets through secure disposal, to protect against threats from outside the system boundary, to restrict the transmission and movement of information, and to prevent or detect unauthorized or malicious software. CC6 is the most control-dense and most frequently tested series in a SOC 2 examination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "soc2-cc7-system-operations",
    "title": "AICPA SOC 2 Common Criteria CC7 - System Operations (CC7.1-CC7.5)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "CC7 is the System Operations series of the SOC 2 Common Criteria (CC7.1-CC7.5). It requires the entity to use detection and monitoring procedures to identify configuration changes and vulnerabilities, to monitor system components for anomalies, to evaluate security events to determine whether they constitute incidents, to respond to identified incidents through a defined incident-response program, and to identify, develop, and implement recovery activities. CC7 operationalizes detection, response, and recovery.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "soc2-cc8-change-management",
    "title": "AICPA SOC 2 Common Criteria CC8 - Change Management (CC8.1)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "CC8 is the Change Management series of the SOC 2 Common Criteria. Its single criterion, CC8.1, requires the entity to authorize, design, develop or acquire, configure, document, test, approve, and implement changes to infrastructure, data, software, and procedures to meet its objectives. SOC 2 examinations test whether changes follow this controlled, documented, and approved path.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "soc2-cc9-risk-mitigation",
    "title": "AICPA SOC 2 Common Criteria CC9 - Risk Mitigation (CC9.1-CC9.2)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "CC9 is the Risk Mitigation series of the SOC 2 Common Criteria (CC9.1-CC9.2). It requires the entity to identify, select, and develop risk mitigation activities for risks arising from potential business disruptions, and to assess and manage risks associated with vendors and business partners. CC9 covers business continuity and third-party risk management within the Common Criteria.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "soc2-confidentiality-crit",
    "title": "SOC 2 (Confidentiality)",
    "domain": "Cloud & SaaS",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "System and Organization Controls (SOC) 2 criteria for Confidentiality mandate the protection of information designated as confidential to meet organizational objectives. Compliance necessitates a comprehensive control framework addressing the complete data lifecycle, from creation to final disposition. A foundational element is having a formal data classification policy under which all confidential data is identified and tagged. Access to this information must be strictly governed by the principle of least privilege, enforced via a robust role-based access control (RBAC) implementation for confidential data, with its continued appropriateness validated by ensuring quarterly access reviews are completed. Human and third-party commitments are solidified by requiring non-disclosure agreements for sensitive access and confirming that vendor confidentiality agreements are in place. Technical safeguards are non-negotiable, requiring data to be encrypted in transit using TLS 1.2+ and also encrypted at rest with AES-256 standards. Furthermore, exfiltration risks are mitigated when Data Loss Prevention (DLP) is enabled for egress points. Continuous oversight is maintained through enabled access monitoring and alerting systems to detect potential policy violations. The framework concludes with a secure data disposal policy, ensuring information is rendered unrecoverable, thereby demonstrating a commitment to safeguarding sensitive assets against unauthorized disclosure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-88-sanitization",
      "pci-dss-v4-requirement-7",
      "iso-27017-cloud-controls",
      "iso-27018-pii-cloud",
      "soc2-privacy-criteria"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "soc2-privacy-criteria",
    "title": "SOC 2 (Privacy Criteria)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The SOC 2 Trust Services Criteria (TSC) for Privacy is the specialized audit framework for assessing how personal information is collected, used, retained, disclosed, and disposed of to meet the system's objectives. Based on the Generally Accepted Privacy Principles (GAPP), it provides a high-assurance baseline for the protection of Personally Identifiable Information (PII) in cloud and SaaS platforms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "iso-27018-pii-cloud"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "soc2-processing-integrity",
    "title": "SOC 2 (Processing Integrity)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with SOC 2 Processing Integrity criteria necessitates system processing that is complete, valid, accurate, timely, and authorized. This configuration enforces these principles through a comprehensive suite of controls derived from established trust services standards. To affirm data correctness, stringent input validation rules are required alongside mandatory input-output reconciliation procedures. Authorization is systematically enforced for all transactions. Timeliness is governed by a strict maximum batch processing delay of 60 minutes. System accuracy is actively managed through an automated error detection capability and a formal calculation verification process, holding operations to a maximum data processing error rate of 0.05 percent. Pursuant to internal policy, any detected processing errors must be corrected within a 24-hour service level agreement. To prevent unauthorized alteration and support forensic analysis, the system requires complete data lineage tracking and maintains immutable transaction logs. Operational risk is mitigated as the platform enforces segregation of duties for processing tasks. Furthermore, a critical pre-deployment review of all processing logic is required to validate its integrity and intended function before it enters the production environment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "soc2-security-criterion",
    "title": "SOC 2 Trust Services Criteria for AI Environments",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "SOC 2 (System and Organization Controls) Trust Services Criteria (TSC) for AI environments require rigorous mapping of security, availability, processing integrity, confidentiality, and privacy to the entire Machine Learning lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-sp-800-145-cloud-computing",
      "cis-controls-v8"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "south-africa-conservation-agricultural-resources-act-43-1983",
    "title": "South Africa Conservation of Agricultural Resources Act 43 of 1983 - DALRRD Soil and Veld Management Framework",
    "domain": "Agriculture & Agritech",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The Conservation of Agricultural Resources Act 43 of 1983 (CARA) is South Africa's primary legislation governing the conservation of soil, water resources in soil, vegetation, and the combat of weeds and invader plants on agricultural land. The Department of Agriculture, Land Reform and Rural Development (DALRRD) administers CARA. The Act empowers Conservation Officers to issue control measures prescribing farming practices for soil and veld conservation. Scheduled weeds (declared plants) must be eradicated; invader plants must be controlled on agricultural land. Landowners, land users, and registered occupiers bear statutory duty to comply with CARA conservation measures. The Act provides for subsidies towards conservation works. Criminal penalties include fines and imprisonment for non-compliance with conservation notices. CARA operates alongside the National Environmental Management: Biodiversity Act (NEMBA) for invasive species management, and the National Water Act 36 of 1998 for water resource protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nemba",
        "national_water_act",
        "environmental_impact",
        "subsidy_support",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "south-africa-consumer-protection-act-2008",
    "title": "South Africa Consumer Protection Act 68 of 2008 - CPA Consumer Rights and CX Obligations",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "South Africa's Consumer Protection Act 68 of 2008 (CPA, effective 2011, amended 2022) establishes comprehensive consumer rights and supplier obligations for all goods and services supplied in South Africa, enforceable by the National Consumer Commission (NCC) and Consumer Courts. Key provisions include the right to fair and honest dealing, cooling-off periods (5 business days for direct marketing), mandatory product safety recalls, prohibition of unfair contract terms, strict product liability for defective goods, and the right of consumers to receive goods in good working order.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011",
      "australia-consumer-law-acl-2010-cx"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "south-africa-consumer-protection-act-marketing-rules",
    "title": "Consumer Protection Act, No. 68 of 2008 - Prohibited Marketing Practices, Direct Marketing Opt-Out Registry, Cooling-Off Right, Unsolicited Goods Prohibition, Loyalty Programme Disclosure and Promotional Competition Rules",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The South African Consumer Protection Act (CPA) prohibits misleading, deceptive, and aggressive marketing practices, mandates a national direct marketing opt-out registry, grants consumers a 5-business-day cooling-off right for direct marketing transactions, bans unsolicited goods, and requires full disclosure in loyalty programmes and promotional competitions. Key obligations are set out in Sections 22-24, 40-44, and 48-51.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29",
      "can-spam-act-email",
      "coppa-marketing-kids",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "south-africa-electricity-regulation-act-2006",
    "title": "South Africa Electricity Regulation Act No. 4 of 2006 - NERSA Licensing and Tariff Framework",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The South Africa Electricity Regulation Act No. 4 of 2006 (ERA) establishes the National Energy Regulator of South Africa (NERSA) as the independent electricity regulator with powers to license electricity generation, transmission, distribution, trading, and import/export activities; set tariffs through Multi-Year Price Determinations (MYPD); and enforce the Integrated Resource Plan (IRP) for South Africa's electricity sector. The Act governs Eskom's regulated operations and the emerging renewable energy independent power producer (REIPP) procurement programme.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electricity-market-reform-regulation-2024-1747",
      "india-electricity-amendment-act-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "south-africa-fic-act-amendments-2022",
    "title": "Financial Intelligence Centre Act 38 of 2001 - Amendment Act 2022 (Crypto Asset Service Provider Registration and Enhanced AML/CFT Obligations)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The 2022 amendment to South Africa's FIC Act mandates that all Crypto Asset Service Providers (CASPs) register with the Financial Intelligence Centre, implement enhanced AML/CFT controls, conduct risk assessments and comply with FATF Recommendations - see Section 13 and Section 16 of the amendment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "south-africa-immigration-act-13-2002-dha",
    "title": "South Africa Immigration Act 13 of 2002 - DHA and BMA Border Framework",
    "domain": "Immigration & Border Control",
    "version": "2.6",
    "last_updated": "2026-05-10",
    "bluf": "The Immigration Act 13 of 2002 (as amended by Immigration Amendment Act 3 of 2007 and further amendments) is South Africa's primary immigration law, governing all foreign nationals entering, residing in, and departing from the Republic. The Department of Home Affairs (DHA) administers visa issuance, temporary and permanent residence permits, and citizenship. The South African Border Management Authority (BMA, established in 2023 under BMA Act 2 of 2020) coordinates multi-agency border control. Section 49 of the Immigration Act prescribes criminal penalties of up to 10 years imprisonment for human trafficking and up to 5 years for harbouring illegal foreigners. The SADC Protocol on Facilitation of Movement of Persons (2005) enables SADC national 30-day visa-free access. Critical Skills Visa allows professionals in designated shortage occupations to enter without prior job offer. Employers found to have employed illegal foreigners face fines of up to ZAR 100,000 per person.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "popia",
        "unhcr",
        "sadc",
        "au",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "south-africa-integrated-resource-plan-2019-nersa",
    "title": "South Africa Integrated Resource Plan 2019 - NERSA Licensing and Eskom Restructuring Framework",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "South Africa's Integrated Resource Plan 2019 (IRP 2019, Government Notice 1420 in Gazette No. 42784 of 18 October 2019) sets national electricity capacity targets through 2030 including 14,400 MW wind, 6,000 MW solar PV, 2,500 MW storage, and 1,000 MW gas; is administered by the National Energy Regulator of South Africa (NERSA) under the Electricity Regulation Act 4 of 2006; the National Energy Crisis Committee (NECOM) and NERSA manage load-shedding protocols; Eskom Holdings is being unbundled into generation, transmission (National Transmission Company SA), and distribution entities under the Electricity Regulation Amendment Act 44 of 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brazil-aneel-electricity-sector-regulation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "south-africa-mhsa-mine-health-safety-act",
    "title": "Mine Health and Safety Act 29 of 1996",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The Mine Health and Safety Act 29 of 1996 establishes mandatory health and safety obligations for all mining operations in South Africa, requiring mine employers to conduct risk assessments, appoint Health and Safety Representatives, implement occupational hygiene controls, and cooperate with inspections and accident inquiries led by the Chief Inspector of Mines under Section 35 and Section 54.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gistm-global-tailings-management-standard-2020",
      "ifc-performance-standards-2012-mining",
      "gri-14-mining-sector-standard-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "south-africa-mprda-2002",
    "title": "Mineral and Petroleum Resources Development Act 28 of 2002",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Mineral and Petroleum Resources Development Act 28 of 2002 establishes state custodianship over all mineral and petroleum resources in South Africa, mandates equitable access through prospecting and mining rights, and requires environmental authorisation and compliance with black economic empowerment (BEE) obligations under Section 26 and Section 100. It applies to all entities seeking to prospect, mine, or process minerals or petroleum resources in South Africa.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "south-africa-mprda-2002-mineral-petroleum-resources-development-act",
    "title": "South Africa MPRDA 2002 - Mineral Rights, Mining Permits & Social and Labour Plan Obligations",
    "domain": "Mining & Natural Resources",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "South Africa's Mineral and Petroleum Resources Development Act 28 of 2002 vests all mineral rights in the South African state - requiring mining rights, prospecting rights, and social and labour plans from the DMRE, with black economic empowerment (BEE) compliance and community development obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "south-africa-national-environmental-management-act-107-1998",
    "title": "South Africa National Environmental Management Act 107/1998 - NEMA EIA and Environmental Authorisation Framework",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "South Africa's National Environmental Management Act 107 of 1998 (NEMA) is the principal environmental framework statute, establishing principles for environmental management, rights, obligations and the Environmental Impact Assessment (EIA) system. The EIA Regulations of 2014 (as amended) list activities requiring Environmental Authorisation (EA) from the relevant competent authority (National or Provincial Department of Forestry, Fisheries and Environment). The National Environmental Management Inspectors (EMI or 'Green Scorpions') enforce compliance. Integrated Environmental Authorisations (IEA) coordinate multiple environmental approval requirements. Section 24 of NEMA prohibits listed activities without environmental authorisation. Environmental Management Programmes (EMPs) and post-construction environmental monitoring are mandatory conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "south-africa-conservation-agricultural-resources-act-43-1983",
      "south-africa-national-water-act-36-1998"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "south-africa-national-gambling-act-7-2004",
    "title": "National Gambling Act 7 of 2004 - National and Provincial Licensing, Interactive Gambling Moratorium and Problem Gambling Fund",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The National Gambling Act 7 of 2004 establishes a dual-tier licensing framework for gambling activities in South Africa, requiring all operators to obtain national and provincial licenses. It imposes a moratorium on interactive (online) gambling services and mandates contributions to the National Problem Gambling Fund under Section 44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "south-africa-national-space-agency-act-2008",
    "title": "South Africa National Space Agency Act 2008 (Act No. 36 of 2008) - SANSA and Space Regulatory Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The National Space Agency Act 36 of 2008 established the South African National Space Agency (SANSA) as a public entity under the Department of Science and Innovation (DSI) with the mandate to promote the peaceful use of outer space, develop human capital in space science and technology, and foster coordination of South African space activities. South Africa operates the Hartebeesthoek Radio Astronomy Observatory (HartRAO) and the Square Kilometre Array (SKA) precursor MeerKAT radio telescope. Commercial space licensing in South Africa is coordinated between SANSA, the DSI, and ICASA (Independent Communications Authority of South Africa) for spectrum.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "copuos_lts_guidelines",
        "ska_agreement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "south-africa-national-water-act-36-1998",
    "title": "South Africa National Water Act 36 of 1998 - DWS Water Use Licensing and Catchment Management Framework",
    "domain": "Water & Environmental Resources",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The National Water Act 36 of 1998 (NWA) is South Africa's primary water law, replacing the Water Act 54 of 1956. The Department of Water and Sanitation (DWS) administers the Act. The NWA declares water a public resource held in trust by the National Government. All water use must be authorised under one of four pathways: Schedule 1 uses (domestic and small uses not requiring a licence), General Authorisations (gazette-published authorised uses by category), licensing by existing lawful use, or Water Use Licences (WULs) issued by DWS. The Act establishes Catchment Management Agencies (CMAs) to manage water resources at the catchment level. The Reserve - comprising the Basic Human Needs Reserve (minimum 25 litres per person per day) and the Ecological Reserve - must be protected before any other use. Compulsory licensing applies where water is over-allocated. The NWA addresses historical inequities in water access. Non-compliance with water use authorisation conditions attracts criminal penalties up to 5 years imprisonment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "water_services_act",
        "nema",
        "cara",
        "constitution",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "south-africa-nhbrc-housing-consumer-protection-act-95-1998",
    "title": "South Africa NHBRC Housing Consumer Protection Measures Act 95 of 1998 - Home Builder Registration and Warranty",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "South Africa's Housing Consumer Protection Measures Act 95 of 1998 (NHBRC Act) establishes the National Home Builders Registration Council (NHBRC) as the statutory body responsible for protecting housing consumers from unscrupulous building contractors and ensuring quality construction standards for residential dwellings. The NHBRC Act requires: all home builders to register with NHBRC before constructing or selling any new homes; all new residential dwellings to be enrolled with NHBRC before construction commences; NHBRC provides a 5-year warranty on new homes covering major structural defects (roof, walls, foundations). Non-compliance with NHBRC registration and enrolment obligations constitutes a criminal offence. The NHBRC Home Building Manual prescribes technical standards for home construction that all registered builders must follow, providing an alternative to SANS 10400 (National Building Regulations) for residential construction below 3 storeys.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-construction-products-regulation-2011-305-ce-marking"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "south-africa-nhrec-ethics-health-research-2024",
    "title": "South Africa NHREC Ethics in Health Research Guidelines 2024 - Biobanking and Genomics",
    "domain": "Biotech & Genomics",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The South African Ethics in Health Research: Principles, Processes and Structures Guidelines (3rd edition, 2024) are issued by the National Health Research Ethics Council (NHREC) under the National Health Act 61 of 2003 and represent the authoritative ethical framework for health research in South Africa. The 2024 edition was published in 2024 and applies to all research conducted in South Africa or by South African researchers involving human subjects, human biological material, and identifiable human data. Chapter 4 specifically addresses Research with Human Biological Material including biobanking and genomic research and requires written informed consent, ethics committee approval, and material transfer agreements for cross-border movement of biological material.\n\nThe Guidelines operate within the legal regime of the National Health Act 61 of 2003, the Protection of Personal Information Act 4 of 2013 (POPIA), the Regulations Relating to Research with Human Subjects, and the Material Transfer Agreement for Human Biological Material (issued by the Department of Health, 2018). The Guidelines establish heightened safeguards for genomic research including specific consent procedures for whole-genome sequencing and the return of incidental findings. Heritable human genome editing remains prohibited in research conducted in South Africa under Chapter 4. The Guidelines also implement the Nagoya Protocol on Access and Benefit-Sharing for genetic resources accessed from indigenous and local communities and require benefit-sharing where applicable. The NHREC oversees the network of Research Ethics Committees registered under the National Health Act and approves training and accreditation for committee members.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-popia-2013",
      "nagoya-protocol-genetic-resources-2010"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "south-africa-pa-joint-standard-2-2020-insurance",
    "title": "Joint Standard 2 of 2020: Governance and Operational Risk Requirements for Insurers",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This Joint Standard mandates that South African insurers and their controlling companies establish and maintain a comprehensive governance framework and an operational risk management framework. It sets specific requirements for the board of directors, risk management functions, and policies covering ICT, business continuity, and outsourcing, as detailed in Part 2, section 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "nist-sp-800-39-managing-information-security-risk",
      "iso-27031-dr-readiness"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "south-africa-popia-health-2026",
    "title": "South Africa Protection of Personal Information Act 4 of 2013 (POPIA) - Processing of health information as special personal information",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "Under the Protection of Personal Information Act 4 of 2013 (POPIA), health information is special personal information whose processing is prohibited under Section 26 unless an authorisation or exemption applies. Section 27 sets the general authorisations, Section 32 authorises processing of health data by specified responsible parties (such as medical professionals, insurers and schools) subject to confidentiality, and Section 72 governs cross-border transfers. The Information Regulator Guidance Note on the Processing of Special Personal Information (2021) provides further direction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "south-africa-popia-health-info-2026",
    "title": "South Africa POPIA - Authorisation for processing health information under Section 32 and Information Regulator guidance",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "POPIA (Protection of Personal Information Act 4 of 2013) prohibits processing of health information as special personal information under Section 26 unless authorised. Section 32 authorises processing of a data subject health information by specified responsible parties (medical, insurance, education and related bodies) subject to a duty of confidentiality; Section 27 provides general authorisations and Section 72 governs cross-border transfers. The Information Regulator Guidance Note on the Processing of Special Personal Information (2021) sets out the compliance expectations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "south-africa-r638-food-premises-regulations-2018",
    "title": "Regulations Relating to the General Hygiene Requirements for Food Premises, the Transport of Food, and Related Matters (R638)",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The South Africa R638 Food Premises Regulations 2018 establish mandatory hygiene, infrastructure, and operational standards for all food premises and transport vehicles involved in the handling, preparation, storage, and distribution of food. Key requirements include potable water supply, waste disposal systems, pest infestation prevention, cold chain maintenance, and obtaining a Certificate of Acceptability from Environmental Health Officers under Regulation 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "south-africa-space-affairs-act-84-1993-sansa",
    "title": "South Africa Space Affairs Act 84 of 1993 - SANSA Launch Authority, Space Object Registration and Liability Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The South African Space Affairs Act 84 of 1993 (as amended) established the South African Council for Space Affairs (SACSA) as the competent authority for licensing and regulating space activities launched from or over South African territory or by South African entities globally; the South African National Space Agency Act 36 of 2008 (SANSA Act) established SANSA (South African National Space Agency) as the state-owned entity responsible for promoting and coordinating South Africa's national space programme and Earth observation activities; the Space Affairs Act requires any entity launching a space object from or by means of any facility in South Africa, or placing a space object in orbit under South African jurisdiction, to obtain a launch authority certificate from SACSA; SACSA evaluates applications on criteria including technical safety, compliance with international treaty obligations (Outer Space Treaty 1967, Registration Convention 1975, Liability Convention 1972), and national security; South Africa is a state party to all four main UN outer space treaties and exercises jurisdiction and control over all South African registered space objects; SANSA operates the Hartebeesthoek Radio Astronomy Observatory (HartRAO) and the national Earth observation programme and coordinates with international partners including ESA, CNES, and DLR through bilateral agreements; the Space Affairs Regulations (Government Gazette 28961 of 2008) provide detailed procedural requirements for SACSA licence applications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967-article-i-freedom"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "south-korea-ai-basic-act-2024",
    "title": "South Korea Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness (AI Basic Act) - promulgated 21 January 2025, effective 22 January 2026",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "South Korea's Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness (commonly the AI Basic Act) was promulgated on 21 January 2025 and takes effect on 22 January 2026. It establishes a national framework for AI governance, including obligations for high-impact AI, transparency and labelling duties for generative and certain AI systems, and provisions on safety and trustworthiness. The Act itself establishes the National Artificial Intelligence Committee (chaired by the President) and designates the Ministry of Science and ICT as the lead authority; subordinate detail is set out in the Act's Enforcement Decree. There are no separately enacted 2024 instruments titled 'Regulations on Classification and Management of AI Systems' or 'National AI Commission Establishment and Operation Guidelines'. The Act provides for administrative fines (up to KRW 30 million for specified violations).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "asean-model-ai-governance-v2-2020",
      "australia-voluntary-ai-safety-standard-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "south-korea-fair-labeling-advertising-act-1999",
    "title": "South Korea Act on Fair Labeling and Advertising 1999 - KFTC Misleading Advertising Enforcement",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "South Korea's Act on Fair Labeling and Advertising (Law No. 5814, 1999, as amended through 2023) prohibits false, exaggerated, and misleading advertising; empowers the Korea Fair Trade Commission (KFTC) to order corrective advertising, impose fines up to KRW 2,000,000,000, and mandate temporary advertisement suspensions; requires substantiation upon demand; and covers online platforms, influencer marketing, and comparative advertising with specific prior approval rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "south-korea-pipa-2023-amendment"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "south-korea-food-safety-basic-act-2013",
    "title": "Food Safety Basic Act (Act No. 11580, as amended by Act No. 18818), 2013",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The South Korea Food Safety Basic Act 2013 establishes a comprehensive framework for food safety management, mandating the Ministry of Food and Drug Safety (MFDS) to coordinate policy, conduct risk assessments via a dedicated committee, enforce mandatory HACCP for high-risk food categories, implement recall procedures, and ensure consumer risk communication and international harmonisation. Key obligations are defined in Articles 6, 10, 15, 20, and 25.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004",
      "iso-20022-messaging"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "south-korea-game-industry-promotion-act",
    "title": "Game Industry Promotion Act (GIPA) - Provisions on Game Rating, Loot-Box Probability Disclosure (Article 33(2)), Real-Name Verification, and Business Registration",
    "domain": "Gaming & Gambling",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The South Korea Game Industry Promotion Act (GIPA) mandates game developers and publishers to register with the Ministry of Culture, Sports and Tourism, obtain game ratings from the Game Rating and Administration Committee (GRAC), and disclose probabilities for in-game randomized items (loot boxes) under GIPA Article 33(2), a requirement passed by amendment on 27 February 2023 and effective 22 March 2024. The former 'shutdown law' that restricted minors' online-game access between midnight and 6 AM was a provision of the Juvenile Protection Act, not GIPA, and was abolished in August 2021. GIPA applies to all domestic and foreign entities distributing games in South Korea.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "esrb-entertainment-software-rating-board-us",
      "eu-audiovisual-media-services-loot-boxes-2018",
      "eu-dsa-platform-obligations-gaming-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "south-korea-mfds-digital-medical-products-act-2026",
    "title": "South Korea Digital Medical Products Act (DMPA) & MFDS AI Medical Device Guidelines (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The Digital Medical Products Act (enforced 2025 with key provisions from January 2026) and MFDS guidelines regulate digital medical devices, SaMD, and generative AI medical devices. Requirements include classification, authorisation, clinical evaluation, cybersecurity, quality management, model cards for AI transparency, continuous monitoring, and post-market change controls for adaptive AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "japan-pmda-samd-ai-guidelines-2026"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "south-korea-mfds-pharmaceutical-act-2023",
    "title": "South Korea MFDS Pharmaceutical Affairs Act 2023 - Drug Approval, GMP Inspection and Pharmacovigilance",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "South Korea's Pharmaceutical Affairs Act (PAA, Act No. 901, 29 December 1953, consolidated to 2023) administered by the Ministry of Food and Drug Safety (MFDS - Sikhum-uiyakhum) regulates drug marketing approval (품목허가 - pumok heoga), GMP inspection of domestic and overseas manufacturing facilities, pharmacovigilance, clinical trial authorisation, and good distribution practices; Korea adopted the ICH Quality, Safety, and Efficacy guidelines; MFDS participates in PIC/S (Pharmaceutical Inspection Co-operation Scheme) and the International Coalition of Medicines Regulatory Authorities (ICMRA); fines up to KRW 30 million and product market withdrawal apply for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-210-211-current-good-manufacturing-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "south-korea-pipa-2023-amendment",
    "title": "Act on the Protection of Personal Information (as amended by Act No. 19234, Mar. 14, 2023)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This amendment to South Korea's Personal Information Protection Act (PIPA) expands the mandatory designation of a Data Protection Officer (DPO) to smaller entities based on revenue and data volume (Article 31), introduces an adequacy decision mechanism for international data transfers (Article 28-8), and consolidates rules for online service providers into the main Act, enhancing the enforcement powers of the Personal Information Protection Commission (PIPC).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "korea-pipa-standard",
      "gdpr-article-37-dpo",
      "gdpr-adequacy-decisions-article-45",
      "gdpr-article-46-transfer-mechanisms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "south-korea-space-development-promotion-act-2005",
    "title": "South Korea Space Development Promotion Act 2005 (우주개발진흥법) - National Space Regulatory Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "South Korea's Space Development Promotion Act (우주개발진흥법, enacted 2005, substantially amended 2022-2023) establishes the legal framework for South Korea's national and commercial space activities. The Act establishes the National Space Committee (국가우주위원회) chaired by the Prime Minister as the national coordination body, designates the Korea Aerospace Research Institute (KARI) as the national space R&D agency, and mandates the Korea Aerospace Administration (KASA, established June 2024) as the new national space agency. The Act requires licensing for commercial launch activities and satellite operations by non-governmental entities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "copuos_lts_guidelines",
        "itu_radio_regulations"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "south-korea-telecommunications-business-act-2022",
    "title": "Telecommunications Business Act",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Telecommunications Business Act requires telecommunications operators in South Korea to obtain a license from the Korea Communications Commission (KCC) prior to commencing operations, as stated in Article 5. This regulation applies to all telecommunications business operators in South Korea.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-net-neutrality-open-internet-2015-2120"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sox-it-controls",
    "title": "SOX IT Controls - Sarbanes-Oxley IT Compliance",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Sarbanes-Oxley Act of 2002 (SOX) - enacted in response to Enron, WorldCom, and other financial scandals - imposes mandatory internal controls over financial reporting (ICFR) requirements on all US public companies (SEC registrants) and foreign private issuers listed on US exchanges. Section 302 requires the CEO and CFO to personally certify in each quarterly and annual filing that they have reviewed the report, it contains no material misstatements, and they have disclosed all significant deficiencies and material weaknesses in internal controls. Section 404(a) requires management's annual assessment of ICFR effectiveness as of fiscal year-end, with disclosure of any material weaknesses. Section 404(b) requires external auditor attestation for accelerated filers (>$75M public float). IT General Controls (ITGCs) are the foundational IT controls that support the reliability of financially significant systems and are subject to SOX testing. The four ITGC domains: (1) Logical Access Controls - who can access financially significant systems; (2) Change Management - how changes to financial systems are authorized and tested; (3) Computer Operations - batch job monitoring, backup, incident management; (4) System Development - SDLC controls for new implementations. The COSO Internal Control - Integrated Framework (2013) and COSO ERM framework are the primary control assessment frameworks referenced by external auditors. Material weaknesses are the highest severity - the auditor must issue an adverse opinion on ICFR effectiveness, severely damaging share price and regulatory standing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-csf-2",
      "nist-sp-800-162-abac",
      "nist-sp-800-39-managing-risk",
      "nist-800-61-incident-resp",
      "sec-reg-s-k-106"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sox-it-controls-compliance-2026-11",
    "title": "SOX IT Controls Enterprise Compliance Standard v11",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "The Sarbanes-Oxley Act (SOX) mandates stringent IT controls to ensure the accuracy and integrity of financial reporting. Key requirements include the establishment of internal controls over financial reporting (ICFR), regular assessments of these controls, and the implementation of security measures to protect sensitive financial data. Organizations must maintain comprehensive documentation of their IT processes, conduct regular audits, and ensure that access to financial systems is restricted to authorized personnel only. Additionally, any deficiencies in controls must be reported and remediated promptly. Compliance with SOX is critical for public companies to avoid penalties and maintain investor confidence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "sox-it-controls-compliance-2026-26",
    "title": "SOX IT Controls Enterprise Compliance Standard v26",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "The Sarbanes-Oxley Act (SOX) mandates stringent requirements for financial reporting and internal controls to protect shareholders and the public from accounting errors and fraudulent practices. IT controls under SOX focus on ensuring the integrity, confidentiality, and availability of financial data. Organizations must implement robust access controls, data encryption, and regular audits to ensure compliance. Additionally, they are required to maintain detailed documentation of their IT processes and controls, conduct risk assessments, and ensure that any changes to IT systems are properly managed and documented. Non-compliance can lead to significant penalties, including fines and imprisonment for executives. Therefore, adherence to SOX IT controls is critical for maintaining investor trust and corporate accountability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "spain-electricity-sector-law-24-2013",
    "title": "Spain Electricity Sector Law 24/2013 - Ley del Sector Electrico and CNMC Regulation",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Spain's Electricity Sector Law 24/2013 (Ley del Sector Electrico, amended through Royal Decree-Law 6/2022) establishes the regulatory framework for generation, transmission, distribution, and retail of electricity in Spain. It creates the Comision Nacional de los Mercados y la Competencia (CNMC) as the independent regulator, mandates unbundling, governs the OMIE wholesale electricity spot market (Operador del Mercado Iberico de Energia), and sets the framework for regulated renewable energy remuneration (RECORE) replacing the previous feed-in tariff regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electricity-market-reform-regulation-2024-1747",
      "australia-nem-electricity-national-law-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "spain-gambling-act-ley-13-2011-dgoj",
    "title": "Spain Gambling Act (Ley 13/2011) - DGOJ Online Gambling Licensing and Player Protection",
    "domain": "Gaming & Gambling",
    "version": "2011-05",
    "last_updated": "2026-05-09",
    "bluf": "Spain's Ley 13/2011 de regulacion del juego (May 27, 2011) establishes the Direccion General de Ordenacion del Juego (DGOJ) as the national online gambling regulator, creates a licensing regime for online casino, poker, sports betting, and lottery operators, mandates player identity verification and self-exclusion via the Registro General de Interdicciones de Acceso al Juego (RGIAJ), imposes gross gaming revenue (GGR) taxation, and restricts advertising of unlicensed gambling operators, with criminal sanctions for operating without a DGOJ licence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021",
      "responsible-gambling-grb-standards-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "spain-ley-organica-extranjeria-4-2000-delegacion-gobierno",
    "title": "Spain Organic Law on Rights and Freedoms of Foreigners 4/2000 - Arraigo, TIE and Long-Term Residency Framework",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Spain's Organic Law 4/2000 (Ley de Extranjeria, reformed by LO 8/2000, 11/2003, 14/2003, 2/2009) governs rights, freedoms and social integration of non-EU foreigners. Initial authorisations require an annual Cupo (quota) or direct employer-sponsored application through the Secretaria de Estado de Migraciones. Arraigo social (3 years continuous stay with social ties), arraigo familiar (1 year stay with Spanish family), and arraigo laboral (2 years work relationship) provide regularisation pathways. Residents who hold the Tarjeta de Identidad de Extranjero (TIE) for 5 years may apply for long-term resident status. The EU Blue Card applies to highly qualified workers earning 1.5x average salary.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "france-ceseda-code-entree-sejour-etrangers",
      "germany-residence-act-aufenthaltsgesetz-2004-bamf"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "spain-space-activities-law-2022",
    "title": "Spain Space Activities Law 2022 - Ley 26/2022 de 19 de Diciembre sobre Actividades Relacionadas con el Espacio",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Ley 26/2022, de 19 de diciembre, sobre actividades relacionadas con el espacio (the Spanish Space Activities Law 2022), published in Boletín Oficial del Estado (BOE) on 20 December 2022, is Spain's first comprehensive national space law establishing a licensing and authorisation framework for space activities conducted by entities under Spanish jurisdiction. The law designates the Agencia Espacial Española (Spanish Space Agency, AEE) - created by Royal Decree 1024/2023 - as the national space authority, and establishes authorisation requirements for launches, in-orbit operations, and re-entry, along with mandatory liability insurance and a national space object register. Spain is an ESA Member State with significant industrial participation (Airbus Defence and Space in Getafe, GMV, SENER, Indra) and ESAC (European Space Astronomy Centre) is located near Madrid. Ley 26/2022 implements Spain's obligations under the UN Outer Space Treaty 1967, Liability Convention 1972, and Registration Convention 1976.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "un_outer_space_treaty_1967",
        "esa_framework",
        "eu_space_programme"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "spdx-3-0-iso-iec-5962-2021-sbom-standard",
    "title": "SPDX Software Package Data Exchange Version 3.0 (ISO/IEC 5962:2021, License Expressions, PackageVerificationCode, Tag/Value/JSON/RDF Serialisations, EO 14028 NTIA SBOM Minimum Elements)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "The Software Package Data Exchange (SPDX) is the international open standard for representing software bills of materials (SBOMs), licence compliance information, and supply-chain provenance, maintained by the Linux Foundation under SPDX Project governance and ratified as ISO/IEC 5962:2021 in August 2021. SPDX version 3.0 is the current major release available in PDF, HTML, and SHACL formats; SPDX version 2.3 remains widely deployed in PDF, HTML, RDF, and OWL formats and is the version most acquirer and federal SBOM tooling supports today. An SPDX document represents one or more software packages with their files, licences, copyrights, relationships, and verification metadata. Core element types include CreationInfo (creator, created timestamp, license-list version), Element (SPDXID identifier, name, description), Package (PackageName, PackageVersion, PackageDownloadLocation, PackageHomePage, PackageSupplier, PackageOriginator, PackageVerificationCode, PackageLicenseConcluded, PackageLicenseDeclared, PackageCopyrightText, PackageChecksums via algorithm and value), File (FileName, FileType, FileChecksum, LicenseInfoInFile, FileCopyrightText), Snippet (snippet ranges within larger files), and Relationship (typed connections including DEPENDS_ON, BUILD_DEPENDENCY_OF, CONTAINS, GENERATED_FROM, ANCESTOR_OF). SPDX License Expressions follow the canonical SPDX License List (over 500 licenses with short identifiers such as Apache-2.0, MIT, GPL-3.0-or-later, LGPL-2.1-only) using a Boolean grammar (AND, OR, WITH for license exceptions). SPDX serialisation formats include Tag/Value (the original line-based format), JSON, YAML, RDF/XML, and RDF/Turtle in version 2.3 with JSON-LD added in 3.0. SPDX is one of the two SBOM formats explicitly recognised by the US National Telecommunications and Information Administration (NTIA) minimum elements for SBOM published in support of US Executive Order 14028 and OMB Memorandum M-22-18, alongside CycloneDX.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standard_basis",
        "key_institutions",
        "spdx_3_0_vs_2_3",
        "spdx_document_structure_2_3",
        "spdx_license_expression_grammar",
        "spdx_package_verification_code",
        "spdx_relationship_types",
        "spdx_serialisation_formats",
        "ntia_minimum_elements_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cisa-known-exploited-vulnerabilities-bod-22-01",
      "mitre-cwe-top-25-2024-most-dangerous-weaknesses",
      "oasis-stix-2-1-structured-threat-information",
      "cyber-nist-csf-2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sqf-edition-9-safety",
    "title": "SQF Edition 9 (Safe Quality Food)",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with Safe Quality Food (SQF) Edition 9 necessitates a robust, fully documented food safety management system, underpinned by senior management commitment as evidenced by a signed policy statement. The foundational Food Safety Plan requires a comprehensive review at a maximum interval of 12 months to ensure its continued relevance. Critical Control Points demand complete oversight, with a mandatory 100 percent monitoring coverage to control identified hazards. Similarly, supply chain integrity is paramount, demanding that an equivalent 100 percent of raw materials originate from entities on the approved supplier list. Systemic continuous improvement is measured through a Corrective and Preventive Action program, which must achieve a minimum 95 percent on-time closure rate. Verification activities are stringent, involving internal audits conducted at least every 12 months and mock recall exercises completed within a four-hour timeframe. Personnel competency is enforced via a comprehensive training program, requiring a 98 percent completion rate for all mandated modules. Furthermore, proactive risk mitigation is essential, requiring both an implemented Food Defense Plan and a conducted Food Fraud Vulnerability Assessment. An active environmental monitoring program must be maintained, and data integrity is secured through controlled access for all electronic records.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "haccp-food-safety",
      "gfsi-benchmarking",
      "codex-alimentarius-gen",
      "fda-fsma-compliance",
      "iso-22000-food-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sr-11-7-model-risk-management",
    "title": "Guidance on Model Risk Management",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2011-04-04",
    "bluf": "This supervisory guidance, issued by the Federal Reserve and the Office of the Comptroller of the Currency (OCC), is intended for use by all banking organizations supervised by the Federal Reserve. It should be applied as appropriate, taking into account each organization’s size, nature, complexity, and the extent of its use of models. The guidance mandates that banking organizations should be attentive to the possible adverse consequences of decisions based on models that are incorrect or misused, a concept termed model risk. Model risk is the potential for adverse consequences from decisions based on incorrect or misused model outputs and reports, which can lead to financial loss, poor business decision-making, or reputational damage.\n\nThe core obligation is for banking organizations to address these consequences through active model risk management. An effective model risk management framework includes robust model development, implementation, and use; effective validation; and sound governance, policies, and controls. A guiding principle is the 'effective challenge' of models through critical analysis by objective, informed parties. Where models and model output have a material impact on business decisions, including risk management and capital planning, a bank’s model risk management framework should be more extensive and rigorous. The framework should address both types of model risk (fundamental errors and incorrect use) for individual models and in the aggregate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-ii-capital-framework",
      "bcbs-principles-sound-management-operational-risk",
      "ecb-guide-internal-models"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "sr-11-7-model-risk-management-ai-2023",
    "title": "US Federal Reserve and OCC SR 11-7 Model Risk Management Applied to AI Systems - Compliance Obligations for US Bank AI Model Validation, Challenger Model Requirements, and AI Model Governance Documentation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations under SR 11-7 for AI model risk management in US banks, focusing on model validation, challenger model requirements, and governance documentation, with overlapping obligations under the EU AI Act (Regulation 2024/1689, Articles 9-12) for high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sr-framework",
    "title": "Suriname - Constitutional Privacy Rights and CARICOM Data Protection Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Republic of Suriname is an independent sovereign state on the northeastern coast of South America and the only Dutch-speaking country in the Americas. Suriname is governed under the Constitution of 1987, which establishes fundamental rights including the right to personal privacy. Suriname is a full member of the Caribbean Community (CARICOM) and participates in CARICOM regional frameworks for digital governance and data protection. The Ministry of Transport, Communication and Tourism and the telecommunications regulatory authority oversee electronic communications and digital services. Suriname does not have a standalone comprehensive personal data protection law. A draft Personal Data Protection Act for Suriname has been under development but had not been enacted as a national statute. The applicable framework for personal data protection consists of constitutional privacy rights under the Constitution of 1987, CARICOM regional guidelines and the CARICOM Model Bill on ICT, and common law privacy principles. Organisations processing personal data in Suriname must respect constitutional privacy rights, implement appropriate technical and organisational security measures, limit collection and use of personal data to specified, legitimate purposes, and maintain data subject access and correction procedures. As a CARICOM member state, Suriname is subject to CARICOM Secretariat guidance on data protection and digital governance applicable to CARICOM member states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/sr-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sra-code-conduct-uk",
    "title": "SRA Code of Conduct (UK)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with the Solicitors Regulation Authority (SRA) Code of Conduct for Firms mandates a comprehensive operational framework to uphold the rule of law and the proper administration of justice. Firms must act with integrity, which necessitates that `clientFundsSystemicallySegregated` from office money to safeguard client assets as per the SRA Accounts Rules. Providing a competent level of service requires a systematic `hasConflictOfInterestCheckSystem` prior to onboarding any new matter, alongside maintaining transparency through a `hasPublishedComplaintsProcedure` and verifying that each `clientInformedOfDataProcessing` disclosure is complete. Central to protecting client interests is a robust information security posture. This security footing begins with a `hasFormalInformationSecurityPolicy` and is executed through critical technical controls, including ensuring `clientDataEncryptedAtRest` and `clientDataEncryptedInTransit`. Access to all critical systems must be protected via mandatory `multiFactorAuthEnabledOnAllSystems`. A firm's resilience is continuously tested by performing vulnerability scans with a `vulnerabilityScanFrequencyDays` parameter not exceeding 90. Furthermore, organizations must cultivate a security-conscious culture through `isAnnualCybersecurityTrainingMandatory` for all staff and maintain a `hasDocumentedIncidentResponsePlan` to effectively manage potential breaches. These integrated controls ensure firms meet their professional obligations and maintain public trust.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-retained-gdpr",
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ss-nca-framework",
    "title": "South Sudan NCA Framework - AU Malabo Convention and Constitutional Privacy Obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Republic of South Sudan, which gained independence on 9 July 2011, has established the National Communications Authority (NCA) as the regulatory authority for electronic communications and information technology services. The Transitional Constitution of the Republic of South Sudan includes fundamental rights provisions protecting individual liberty and privacy, including protections against unreasonable interference with correspondence and private communications. As a member state of the African Union, South Sudan is subject to the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014), which establishes the regional standard for personal data protection in Africa. South Sudan does not have a standalone comprehensive personal data protection law. The applicable legal framework for personal data protection in South Sudan comprises the constitutional privacy rights established by the Transitional Constitution, the NCA regulatory requirements for telecommunications subscriber data protection, and the AU Malabo Convention as the binding regional reference standard. Organisations processing personal data in South Sudan must respect constitutional privacy rights, implement NCA-compliant subscriber data protections for telecommunications services, and implement personal data processing practices consistent with the AU Malabo Convention principles. The NCA has authority to investigate complaints and enforce compliance with telecommunications regulatory requirements including subscriber data protection obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ss-nca-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ssae-18-attestation-standards-soc",
    "title": "AICPA SSAE No. 18 - Attestation Standards Underpinning SOC Examinations (AT-C 105, 205, 320)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Statement on Standards for Attestation Engagements (SSAE) No. 18, Attestation Standards: Clarification and Recodification, is the AICPA standard that governs how SOC examinations are performed. It recodifies prior SSAEs into the AT-C sections: AT-C 105 (concepts common to all attestation engagements), AT-C 205 (examination engagements, the basis for SOC 2), and AT-C 320 (reporting on controls at a service organization relevant to user entities internal control over financial reporting, the basis for SOC 1). A SOC report is only as reliable as the SSAE 18 requirements the practitioner followed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-1-type-2-finance",
      "soc-2-type-ii-trust-services-criteria-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "st-cntic-framework",
    "title": "São Tomé and Príncipe CNTIC Framework - AU Malabo Convention and Constitutional Privacy Obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Democratic Republic of São Tomé and Príncipe has established the Centro Nacional de Tecnologias de Informação e Comunicação (CNTIC) as the national authority for information and communications technology development and regulation. The Constitution of the Democratic Republic of São Tomé and Príncipe establishes fundamental rights including the right to privacy and inviolability of personal correspondence and private communications. As a member state of the African Union, São Tomé and Príncipe is subject to the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014), which requires African Union member states to establish a comprehensive personal data protection framework including principles of lawful processing, data subject rights, controller obligations, and data protection supervisory authority. São Tomé and Príncipe does not have a standalone comprehensive data protection law, but the Malabo Convention principles constitute the applicable regional standard and reference framework for personal data protection in São Tomé and Príncipe. The CNTIC regulatory framework establishes baseline obligations for ICT service providers regarding the confidentiality and security of personal data processed through electronic communications systems. Organisations processing personal data in São Tomé and Príncipe must respect constitutional privacy rights, implement security measures consistent with the Malabo Convention principles, and comply with CNTIC's applicable regulatory directives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/st-cntic-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "state-ramp-authorization",
    "title": "StateRAMP Authorization",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The cloud service offering's compliance posture demonstrates substantial progress toward full StateRAMP Authorization but currently fails to meet the final requirement for listing on the Authorized Product List. As a Cloud Service Provider specifically targeting state and local government entities, the organization has successfully achieved StateRAMP Ready status, supported by a state sponsor. This attests to the completion of foundational security documentation, including a comprehensive System Security Plan and a formal Continuous Monitoring Plan. An accredited Third-Party Assessment Organization (3PAO) has validated the implementation of security controls aligned with NIST SP 800-53 Rev. 5, appropriate for a system categorized at a Moderate Impact level. The resulting Security Assessment Report confirms a robust security posture, further evidenced by the critical achievement of maintaining zero open high-risk items on the Plan of Actions and Milestones (POAM). Despite fulfilling these significant prerequisites, the service's absence from the official Authorized Product List signifies it has not yet obtained a Provisional or Full Authority to Operate (ATO). Consequently, government agencies cannot procure this offering as a fully vetted StateRAMP Authorized solution, impeding market access until the final authorization process is completed with the governing board.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fedramp-moderate-baseline"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "stockholm-convention-2001-persistent-organic-pollutants",
    "title": "Stockholm Convention 2001 - Persistent Organic Pollutants (POPs)",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Stockholm Convention on Persistent Organic Pollutants (POPs), adopted on 22 May 2001 and entered into force on 17 May 2004, has 186 Parties and is the primary global treaty addressing chemical substances that persist in the environment, bioaccumulate through the food chain, pose health and environmental risks, and transport long distances. The Convention requires Parties to eliminate or restrict the production and use of chemicals listed in three Annexes: Annex A (elimination - 26 substances including PCBs, aldrin, dieldrin, HCB), Annex B (restriction - DDT permitted only for disease vector control), and Annex C (unintentional releases to be reduced - dioxins, furans, PCBs, HCB, PCP). The Convention's POPs Review Committee (POPRC) regularly evaluates new substances for listing. Since 2001, the Convention has been amended 7 times to add new POPs including PFOS (perfluorooctane sulfonate, listed 2009), PFOA (perfluorooctanoic acid, listed 2019), PFHxS (listed 2022), and PFAS-related chemicals, making the Convention the primary global instrument for addressing the 'forever chemicals' (PFAS) crisis. The Stockholm Convention is administered jointly with the Rotterdam and Basel Conventions (BRS Conventions) under a joint Secretariat in Geneva. Under Article 5, Parties must reduce unintentional production of Annex C POPs using Best Available Techniques (BAT) and Best Environmental Practices (BEP). Article 6 requires Parties to establish environmentally sound waste management programmes for POP-containing wastes. National Implementation Plans (NIPs) must be submitted and updated regularly. PFAS manufacturing bans and restriction timelines adopted at COP10 (2022) and COP11 (2023) are the current cutting edge of the Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-montreal-protocol-1987-ozone-kigali-2016",
      "basel-convention-1989-hazardous-waste-transboundary",
      "eu-csrd-2022-2464",
      "eu-reach-regulation-1907-2006"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "supervisory-guidance-model-risk-management",
    "title": "SUPERVISORY GUIDANCE ON MODEL RISK MANAGEMENT",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2011-04-04",
    "bluf": "This guidance describes the key aspects of effective model risk management for banks, which rely heavily on quantitative analysis and models in most aspects of financial decision making. It applies to national banks, bank holding companies, state member banks, and all other institutions for which the Office of the Comptroller of the Currency or the Federal Reserve Board is the primary supervisor. The use of models invariably presents model risk, which is the potential for adverse consequences from decisions based on incorrect or misused model outputs and reports. Model risk can lead to financial loss, poor business and strategic decision making, or damage to a bank's reputation.\n\nThe core obligation is for banks to establish a strong model risk management framework that fits into the broader risk management of the organization. This framework must encompass robust model development, implementation, and use; a sound model validation process; and strong governance, policies, and controls. A guiding principle for managing model risk is 'effective challenge' of models, which is critical analysis by objective, informed parties. The practical application of this guidance should be customized to be commensurate with a bank's risk exposures, its business activities, and the complexity and extent of its model use.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sr-11-7-model-risk-management",
      "basel-ii-capital-framework",
      "bcbs-principles-sound-management-operational-risk",
      "bcbs-sound-stress-testing-practices"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "supply-chain-bullwhip",
    "title": "Bullwhip Effect Mitigation",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "The Bullwhip Effect (Lee, Padmanabhan & Whang, 1997 - Sloan Management Review) describes the amplification of demand variability as orders propagate upstream in a supply chain - small fluctuations in retail demand become large oscillations in manufacturer and raw material orders. The four primary causes are demand signal processing (over-ordering based on forecasts), rationing game behavior (ordering more than needed when supply is scarce), order batching (periodic ordering creates demand spikes), and price variation (forward buying during promotions). Organizations with unmanaged bullwhip effects experience excess inventory, stockouts, poor customer service, and inflated supply chain costs. Mitigation requires demand signal transparency, collaborative forecasting, and ordering policy discipline across the entire supply chain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-28000-supply-chain",
      "gs1-epcis-transparency",
      "logistics-jit-inventory",
      "kanban-replenishment",
      "supply-chain-risk-triage",
      "nist-sp-800-161r1-csrm-practices"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "supply-chain-incoterms",
    "title": "Incoterms 2020 Risk Allocation Matrix",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-09",
    "bluf": "Standardized international trade terms defining the responsibilities, costs, and transfer of risk between sellers and buyers for the distribution of goods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "c-tpat-minimum-security",
      "isps-code-vessel-security",
      "icao-annex-17-security"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "supply-chain-risk-triage",
    "title": "Supply Chain Risk Triage Protocol",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The Supply Chain Risk Triage Protocol mandates an immediate escalation and review process upon detection of specific high-risk conditions within the procurement and component lifecycle. This automated governance mechanism is triggered by a confluence of factors indicating severe potential disruption or compromise. An alert is generated if a supplier's security posture degrades significantly, evidenced by a security score delta of -15 or more points, or upon formal confirmation of a data breach (`supplier_breach_confirmed`). Physical integrity alerts, such as any positive indication of `tampering_evidence_detected`, also require instant intervention. From a cybersecurity perspective, the protocol activates when a component accumulates 3 or more critical Common Vulnerabilities and Exposures (`component_cve_count_critical`), especially when there is `threat_intel_correlation` suggesting active exploitation. The business continuity risk is a primary driver; an `estimated_business_impact_score` reaching 4 or higher necessitates a formal assessment. This is particularly acute for any `is_critical_supplier` or providers of a `is_sole_source_component`, especially when inventory levels drop below a critical threshold of 7 `inventory_days_of_supply`. Geopolitical factors are also evaluated, with suppliers located in a `is_high_risk_geo` automatically flagged. The absence of a pre-vetted alternative (`has_vetted_alternate`) for a compromised supply line compounds the risk severity and accelerates the required response timeline, ensuring that vulnerabilities are addressed with requisite urgency and according to established corporate policy and regulatory standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-28000-supply-chain",
      "wco-safe-framework",
      "c-tpat-minimum-security",
      "customs-tapa-transport-sec",
      "nist-ir-7622-scrm-practices",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sv-aml-law-lavado-dinero-activos",
    "title": "El Salvador Law Against Money Laundering and Assets (Decree No. 498)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "El Salvador's Law Against Money Laundering and Assets (Decree No. 498) is the country's principal anti-money laundering statute: it defines its purpose (Article 1) and obliged subjects (Article 2), creates the Financial Investigation Unit (UIF) within the Attorney General's Office (Article 3), criminalises money laundering (Article 4), and requires obliged subjects to report cash operations over ten thousand US dollars (Article 9), file suspicious operation reports within five working days (Article 9-A), apply customer and PEP due diligence (Article 9-B), and identify customers and retain records for five years (Article 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sv-lacap-ley-adquisiciones-contrataciones-administracion-publica-decreto-868-2000",
    "title": "El Salvador Ley de Adquisiciones y Contrataciones de la Administracion Publica (LACAP) Decreto Legislativo 868 of 5 May 2000 and COMPRASAL",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The El Salvador Ley de Adquisiciones y Contrataciones de la Administracion Publica (LACAP / Law on Procurement and Contracting of the Public Administration) approved by Decreto Legislativo 868 of 5 May 2000 (published in Diario Oficial No. 88 Tomo No. 347 of 15 May 2000 effective 16 May 2000) as substantially amended by Decreto Legislativo 725 of 23 February 2024 (Reformas a la LACAP) and supplemented by the Reglamento de la LACAP approved by Decreto Ejecutivo 53 of 10 April 2013, is the principal Salvadoran statute governing procurement of goods, services, and works by entities of the Public Administration including the Executive Branch (Organo Ejecutivo) ministries, the Legislative Branch (Asamblea Legislativa), the Judicial Branch (Organo Judicial), Autonomous Institutions (Instituciones Autonomas), Municipalities (Municipalidades), public-sector enterprises, and other entities financed by the State budget. LACAP was a foundational reform establishing the Salvadoran procurement regime aligned with international best practice. The Direccion Nacional de Compras Publicas (DINAC / dinac.gob.sv) under the Ministry of Finance (Ministerio de Hacienda) is the central regulatory authority responsible for procurement regulation, oversight, supplier debarment, and operation of the public procurement portal. The COMPRASAL portal (comprasal.gob.sv) operated by DINAC is the mandatory federal e-procurement platform for in-scope procurement. The Unidad de Adquisiciones y Contrataciones Institucional (UACI) is the operational procurement unit established within each entity. Procurement methods established by LACAP art. 39 to 80 comprise (a) Licitacion Publica (Public Tender, the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Licitacion por Invitacion (Tender by Invitation, with prequalification or restricted to invited suppliers), (c) Concurso Publico (Public Competition, for consulting services), (d) Libre Gestion (Free Management / Direct Procurement, for low-value acquisitions below prescribed thresholds), (e) Contratacion Directa (Direct Contracting, sole-source under prescribed exceptions in art. 71 to 73 including emergency, sole supplier for technical reasons, prior failed tendering, and prescribed-class exemptions), (f) Mercado Bursatil (Stock Exchange Market, for prescribed commodities), and (g) Convenio Marco (Framework Agreement). The Corte de Cuentas de la Republica (Court of Accounts of the Republic) conducts procurement audit. El Salvador is a party to CAFTA-DR (in force 2006), the EU-Central America Association Agreement (in force 2013), the SIECA framework, and UNCAC. El Salvador is NOT a party to the WTO GPA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "sv-pdpl-2021",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "sv-pdpl-2021",
    "title": "El Salvador Law for the Protection of Personal Data (Legislative Decree No. 144 of 2024)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "El Salvador's Ley para la Protección de Datos Personales (Legislative Decree No. 144), approved 12 November 2024 and in force from 28 November 2024, is El Salvador's first comprehensive personal data protection law. It guarantees the rights to privacy and informational self-determination, requires a lawful basis (notably free and informed consent) for processing, grants data subjects ARCO rights (Acceso, Rectificación, Cancelación, Oposición), imposes data-security and breach-handling duties, and regulates cross-border transfers to jurisdictions providing adequate protection. The supervisory authority is the State Cybersecurity Agency (Agencia de Ciberseguridad del Estado, ACE), established alongside the Cybersecurity and Information Security Law (Legislative Decree No. 143). The law applies to public and private entities that process the personal data of individuals in El Salvador. Note: an earlier 2021 data protection bill was vetoed and never entered into force; Decree No. 144 of 2024 is the operative statute.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sweden-aliens-act-2005-716-migrationsverket",
    "title": "Sweden Aliens Act (2005:716) - Uppehallstillstand and Asylum Framework",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Sweden's Aliens Act (Utlanningslag 2005:716) governs entry, residence and removal of non-EU nationals. An uppehallstillstand (residence permit) is required for stays beyond 90 days. Work permits (arbetstillstand) are self-contained applications requiring a job offer meeting collective agreement wages and union consultation. The Migration Board (Migrationsverket) decides first instance; the Migration Court (Migrationsdomstolen) hears appeals. Sweden is a Schengen member and part of the Nordic Passport Union (free movement among Nordic states since 1954). The 2016 Temporary Aliens Act expired in 2021; permanent protection is now harder to obtain. The 2021 Migration Inquiry introduced income requirements for permanent residence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "germany-residence-act-aufenthaltsgesetz-2004-bamf"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sweden-gambling-act-2018-1138",
    "title": "Sweden Gambling Act 2018:1138 - Channelisation Model, Licence Conditions, Responsible Gambling Requirements and Spelinspektionen Oversight",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "License holders must implement measures to promote responsible gambling and prevent excessive gambling as required by the Swedish Gambling Authority. This applies to all licensed gambling operators in Sweden.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dora-articles-28-44-third-party-ict-risk",
      "owasp-asvs-l3",
      "iso-42005-ai-impact-assessment"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sweden-gambling-act-2018-spelinspektionen",
    "title": "Act (2018:1138) on Gambling - Sweden Gambling Act 2018",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The Sweden Gambling Act 2018 mandates all licensed operators under Spelinspektionen to implement mandatory deposit limits, session time controls, self-exclusion via Spelpaus, responsible gambling measures, advertising restrictions, and AML procedures. Key obligations are defined in Chapter 5, Sections 1-15 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "eu-gdpr-online-gaming-data-protection",
      "denmark-gambling-act-2012-spillemyndigheden"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sweden-gambling-act-2018-spellagen",
    "title": "Sweden Gambling Act 2018:1138 (Spellagen) - Spelinspektionen Licensing and Player Protection Framework",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Sweden's Gambling Act 2018:1138 (Spellagen), effective 1 January 2019, established a fully re-regulated online gambling market requiring all operators targeting Swedish players to hold a Spelinspektionen B2C licence; mandates integration with the national Spelpaus self-exclusion register, deposit and loss limits, reality checks, and mandatory responsible gambling training; imposes 18% GGR gambling tax, strict AML/KYC obligations aligned with AMLD5, and advertising watershed rules; violations subject to administrative fines up to SEK 50 million or licence revocation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "fatf-guidance-rba-gambling-2021",
      "eu-gdpr-article-22-automated-decision-making-profiling"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "sweden-space-activities-act-1982",
    "title": "Sweden Space Activities Act 1982 (Rymdverksamhetslag 1982:963) - Swedish National Space Regulatory Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "Sweden's Space Activities Act (Rymdverksamhetslag, SFS 1982:963) is one of the world's oldest national space licensing statutes, enacted in 1982 and applying to space activities carried out by Swedish legal persons or from Swedish territory. The Act requires a licence from the Swedish government for any space activity and makes the Swedish National Space Agency (SNSA/Rymdstyrelsen) the coordinating authority for Swedish space policy. Sweden hosts the Esrange Space Center (operated by SSC, Swedish Space Corporation) near Kiruna in northern Sweden - Esrange is a significant launch site for suborbital rockets and stratospheric balloons, and Sweden began preparation for Esrange as an orbital launch site in 2020. The Act was supplemented by Government Ordinance (SFS 1982:1069) specifying licensing conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "esa_convention_1975",
        "copuos_lts_guidelines"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "esa-convention-1975-european-space-agency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "swift-cscf-v2024",
    "title": "SWIFT Customer Security Controls Framework v2024 - Mandatory and Advisory Controls for SWIFT Network Participants",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-07-16",
    "bluf": "The SWIFT Customer Security Controls Framework (CSCF) mandates that all SWIFT network participants annually attest their compliance with a set of mandatory security controls to secure their local SWIFT environment. This requirement, outlined in the Customer Security Controls Policy (CSCP), aims to protect the integrity and security of the global financial messaging network.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27017-cloud-security-2015",
      "nist-sp-800-63b-digital-identity",
      "dora-ict-risk-management-articles-5-16",
      "cpmi-iosco-cyber-resilience-fmi"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "swift-cscf-v2024-customer-security-controls",
    "title": "SWIFT Customer Security Controls Framework (CSCF) v2024 - Mandatory Controls, Advisory Controls and Independent Assessment Requirements",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-07-01",
    "bluf": "The SWIFT Customer Security Controls Framework (CSCF) v2024 mandates that all SWIFT users implement a set of security controls to protect their local SWIFT environment. As per the Independent Assessment Framework (IAF), users must perform an annual independent assessment and submit an attestation of compliance against all mandatory controls by December 31st.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0",
      "pci-dss-v4-requirement-6"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "swift-csp-customer-security-programme-2023",
    "title": "SWIFT Customer Security Programme (CSP) 2023 - Mandatory Security Controls, SWIFT Inspector, Independent Assessment and Attestation for Financial Messaging",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The SWIFT CSP 2023 mandates all SWIFT-connected financial institutions to implement 21 mandatory security controls focused on securing the local environment, protecting the SWIFT infrastructure, and ensuring detection and response capabilities. Compliance is verified annually via independent assessment and attestation under CSP Control 21 and the SWIFT CSP Attestation Framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "automation-bpmn-error-boundary",
      "mcp-enterprise-auth",
      "automation-bpmn-agent-handover",
      "agent-kill-switch"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "swift-csp-quality",
    "title": "SWIFT CSP (Quality)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The SWIFT Customer Security Programme (CSP) is the mandatory security framework for all SWIFT users. It consists of the Customer Security Controls Framework (CSCF) with 32 controls (25 mandatory, 7 advisory) designed to secure the local infrastructure of SWIFT users and combat cyber-fraud in the global financial messaging community.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "bcbs-principles-sound-management-operational-risk",
      "cpmi-iosco-cyber-resilience-fmi",
      "iso-20022-mx-messaging"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "swiss-finma-circular-2023-insurance-corporate-governance",
    "title": "FINMA Circular 2017/2 - Corporate Governance for Insurers: Board Responsibilities, Risk Committee and Internal Controls",
    "domain": "Insurance & Risk",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "This circular mandates that Swiss insurance companies establish a robust corporate governance framework, defining the ultimate responsibility of the Board of Directors for the overall business strategy and risk management (MN 10), and requires the establishment of a dedicated Risk Committee for insurers in supervisory categories 1 to 3 (MN 27). The applicable instrument is FINMA Circular 2017/2 'Corporate governance - insurers'; FINMA Circular 2023/1 'Operational Risks and Resilience - Banks' is a separate banking-sector instrument and does not govern insurer corporate governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "nist-sp-800-39-managing-information-security-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "switzerland-finma-crypto-guidance-2018-2024",
    "title": "FINMA Crypto Asset Guidance 2018-2024 - ICO/Token Classification: Payment, Utility and Asset Tokens, No-Action Letters, DLT Act Integration, Anti-Money Laundering Obligations for VASPs, FINMA Sandbox and Risk-Based Supervision Framework",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This guidance sets out how FINMA applies financial market legislation to initial coin offerings (ICOs) based on the economic function and transferability of tokens. It requires compliance with anti-money laundering regulations for payment tokens and treats asset tokens as securities under Swiss law, with utility tokens subject to securities treatment if they function as investments. The assessment is case-by-case as outlined in the guidelines published on 16 February 2018.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "eu-dlt-pilot-regime-2022-858",
      "bis-iosco-pfmi-applied-to-dlt-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "switzerland-foreign-nationals-integration-act-2005-sem",
    "title": "Switzerland Foreign Nationals and Integration Act (AIG/LEI 2005) - B-Permit, C-Permit and EU Bilateral Framework",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Switzerland's Foreign Nationals and Integration Act (Auslandergesetz/Loi sur les etrangers et l'integration, AIG/LEI, SR 142.20, enacted 2005, significantly revised in 2019) governs admission and residence of non-Swiss nationals. Switzerland is not in the EU but has bilateral agreements granting EU/EFTA nationals free movement via FZPA (Freizugigkeitsabkommen). Non-EU/EFTA third-country nationals face strict admission quotas and must meet labour market tests. Permits include: B (annual residence permit), C (settlement permit after 5-10 years), L (short-term up to 1 year), G (cross-border commuter). Integration agreements (Integrationsvereinbarungen) may be imposed. The State Secretariat for Migration (SEM) supervises the national framework; cantons handle individual applications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "germany-residence-act-aufenthaltsgesetz-2004-bamf"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "switzerland-geldspielgesetz-federal-gaming-act-2019",
    "title": "Switzerland Federal Gaming Act (Geldspielgesetz/BGS) 2019 - Online Casino Licensing and Lottery Monopoly",
    "domain": "Gaming & Gambling",
    "version": "2019-01",
    "last_updated": "2026-05-09",
    "bluf": "Switzerland's Bundesgesetz uber Geldspiele (BGS/Geldspielgesetz), which entered into force on January 1, 2019, establishes a dual-authority regulatory framework: the Federal Gaming Board (ESBK/Commission federale des maisons de jeu) licenses land-based and online casinos, while Comlot licenses lotteries and sports betting; the Act preserves the monopoly of Swisslos and Loterie Romande for lottery and sports betting, authorises Swiss-licensed casino operators to offer online casino games, mandates player protection measures including loss limits and social concept, and requires ISPs to block unlicensed foreign gambling sites accessible to Swiss residents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-rba-gambling-2021",
      "responsible-gambling-grb-standards-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "switzerland-unfair-competition-act-1986-uca",
    "title": "Switzerland Unfair Competition Act 1986 (UCA/LCD) - SECO Enforcement and Misleading Advertising Rules",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Switzerland's Federal Act against Unfair Competition of 19 December 1986 (UCA - Unlauterkeitsgesetz/LCD - Loi sur la concurrence deloyale, SR 241) prohibits deceptive, misleading, and aggressive commercial practices; provides both civil and criminal enforcement channels; the 2012 revision strengthened consumer protection and added specific provisions on misleading pricing, spam, and aggressive direct marketing; enforced by the State Secretariat for Economic Affairs (SECO) and cantonal consumer protection authorities; criminal penalties include up to 3 years imprisonment for serious violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "sx-lbp-2010",
    "title": "Sint Maarten National Ordinance on Personal Data Protection 2010",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Sint Maarten, a constituent country of the Kingdom of the Netherlands since 2010 following the dissolution of the Netherlands Antilles, enacted the National Ordinance on Personal Data Protection (Landsverordening bescherming persoonsgegevens, LBP) aligned with Kingdom of the Netherlands data protection standards. The Ordinance is administered by the Privacy Authority of Sint Maarten. It establishes principles for lawful processing of personal data, grants data subjects rights of access, correction, and objection, requires notification of certain processing activities, mandates security safeguards, and restricts cross-border transfers to jurisdictions with adequate data protection. The Ordinance ensures alignment with the Netherlands' data protection framework applicable to Kingdom constituent countries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/sx-lbp-2010.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "sy-ecl-2012",
    "title": "Syria Electronic Crimes Law No. 17 of 2012 - Personal Data Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Syria enacted Electronic Crimes Law No. 17 of 2012 (قانون الجرائم المعلوماتية), which includes provisions for the protection of personal data held in electronic systems and processed through information networks. The law is administered by the Ministry of Communications and Technology of Syria and the National Telecom Authority (NTA). It criminalises unauthorised access to personal data in electronic systems, prohibits the interception and disclosure of personal data without authorisation, establishes obligations for information system operators to implement security measures protecting user data, and provides for criminal and civil sanctions for misuse or unauthorised disclosure of personal data. The law represents Syria's legal framework for protecting personal data in the context of electronic communications and information systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/sy-ecl-2012.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "synthetic-data-health-governance-2026",
    "title": "Synthetic Data Generation & Governance in Healthcare (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Synthetic data (artificially generated data that mimics real health data) is increasingly used for AI training, testing, and research while reducing privacy risks. Governance requires validation of statistical utility and fidelity, privacy guarantees (e.g., differential privacy), bias assessment, regulatory acceptance for submissions, and clear policies on when synthetic data can replace or augment real data. Regulators expect transparency on generation methods and limitations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "sz-dpa-2022",
    "title": "Eswatini Data Protection Act 2022",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Eswatini (formerly Swaziland) enacted the Data Protection Act 2022 to regulate the collection, storage, processing, and transfer of personal data in the Kingdom. The Act establishes data protection principles, creates a Data Protection Commissioner as the supervisory authority, and confers rights on data subjects including access, rectification, and erasure. Controllers must identify a lawful basis for processing, implement security safeguards, and notify the Commissioner of personal data breaches. Cross-border transfers are restricted to countries providing adequate protection. Sensitive personal data requires explicit consent or specific statutory conditions. The Act aligns with the Southern African Development Community (SADC) data protection standards and the AU Malabo Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/sz-dpa-2022.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "taiwan-personal-data-protection-act-2015",
    "title": "Personal Data Protection Act (Republic of China, Taiwan) as amended on December 30, 2015",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Taiwan Personal Data Protection Act (PDPA) governs the collection, processing, and use of personal data by government and non-government agencies, requiring a specific purpose and consent for most activities (Article 19). The 2015 amendment empowers the central competent authority to restrict international data transfers (Article 21) and establishes statutory damages for violations ranging from NT$500 to NT$20,000 per incident (Article 29).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-privacy-guidelines-2013",
      "apec-cbpr-system-2011",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tanzania-mining-act-no-14-2010",
    "title": "Tanzania Mining Act No. 14 of 2010 - Mineral Licensing and Royalty Framework",
    "domain": "Mining & Natural Resources",
    "version": "1.1.0",
    "last_updated": "2019-07-01",
    "bluf": "Tanzania's Mining Act 2010 as amended by the Written Laws (Miscellaneous Amendments) Act 2019 establishes a mineral licensing regime administered by the Mining Commission, requiring local content (minimum 51% Tanzanian ownership in prospecting licences), royalty payments of 5% for base metals and 6% for gold on gross value, mandatory state participation through STAMICO for large-scale mines, and mandatory annual environmental management plans under NEMC supervision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "extractive-industries-transparency-eiti-standard",
      "gri-14-mining-sector-standard-2022",
      "icmm-mining-principles-2020",
      "un-guiding-principles-business-hr-mining"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tapa-tsr-2023",
    "title": "TAPA Trucking Security (TSR)",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The TAPA Trucking Security Requirements (TSR) is the leading global security standard for the transportation of high-value assets by road. It defines three levels of security (Level 1, 2, and 3) for vehicles and trailers, focusing on theft prevention, asset tracking, and driver security protocols.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-28000-supply-chain",
      "c-tpat-minimum-security",
      "fleet-telematic-audit",
      "wco-safe-framework"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "tc-dpo-2012",
    "title": "Turks and Caicos Islands Data Protection Ordinance 2012",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Turks and Caicos Islands enacted the Data Protection Ordinance 2012, a statute aligned with UK data protection standards applicable to the territory as a British Overseas Territory. Administered by the Information Commissioner for the Turks and Caicos Islands, the Ordinance establishes data protection principles governing the processing of personal data by controllers established in the territory, grants data subjects rights of access and correction, restricts cross-border transfers to jurisdictions with adequate protection, and requires appropriate security measures. The Ordinance was subsequently aligned with UK GDPR standards following the United Kingdom's reform of data protection law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/tc-dpo-2012.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "tcfd-climate-related-financial-disclosures",
    "title": "Recommendations of the Task Force on Climate-related Financial Disclosures",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2017-06-15",
    "bluf": "The Task Force on Climate-related Financial Disclosures report establishes recommendations for disclosing clear, comparable and consistent information about the risks and opportunities presented by climate change. Widespread adoption of these recommendations aims to ensure that the effects of climate change become routinely considered in business and investment decisions, leading to a more efficient allocation of capital and helping to smooth the transition to a more sustainable, low-carbon economy. The recommendations are designed to be widely adoptable and applicable to organizations across sectors and jurisdictions, including financial-sector organizations like banks, insurance companies, asset managers, and asset owners.\n\nThe core obligation for organizations is to provide climate-related financial disclosures in their mainstream public annual financial filings. These disclosures are structured around four thematic areas that represent core elements of how organizations operate: governance, strategy, risk management, and metrics and targets. This framework is intended to solicit decision-useful, forward-looking information on the financial impacts of climate-related issues, with a strong focus on risks and opportunities related to the transition to a lower-carbon economy. A key recommended disclosure focuses on the resilience of an organization's strategy, taking into consideration different climate-related scenarios, including a 2° Celsius or lower scenario.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "issb-s1-s2-standard",
      "ghg-protocol-scope3",
      "iso-14064-ghg-reporting",
      "sec-climate-disclosure",
      "csrd-eu-sustainability"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tcfd-climate-risk",
    "title": "TCFD Climate Disclosure",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Task Force on Climate-related Financial Disclosures (TCFD) framework, published in 2017 and now consolidated into IFRS S2 (effective January 2024), defines the global standard for corporate disclosure of climate-related financial risks and opportunities. TCFD organizes disclosures across four pillars: Governance, Strategy, Risk Management, and Metrics & Targets. TCFD-aligned disclosure is now mandatory or expected by the SEC Climate Disclosure Rule (US), CSRD (EU), IFRS S2 (global ISSB adopters), and the FCA (UK). Investors managing over $150 trillion in assets have committed to TCFD-aligned reporting. Organizations that do not disclose face regulatory penalties, investor divestment, and credit rating downgrades as climate risk becomes a standard financial materiality assessment criterion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "issb-s1-s2-standard",
      "sec-climate-disclosure",
      "csrd-eu-sustainability",
      "ghg-protocol-scope3",
      "iso-14064-ghg-reporting"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "tcfd-insurance-sector-guidance-2021",
    "title": "TCFD Insurance Sector Guidance 2021 - Climate Risk Disclosure: Physical Risk Scenario Analysis, Transition Risk Assessment (Stranded Asset Exposure), Climate Metrics (Weighted Average Carbon Intensity), Governance Structure and Forward-Looking Statement Requirements",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This guidance requires insurance organizations to disclose climate-related financial risks and opportunities in line with the TCFD’s four-pillar framework-governance, strategy, risk management, and metrics and targets-where such information is material, with specific emphasis on scenario analysis including a 2°C or lower scenario. Key requirements are derived from the TCFD Recommendations, particularly the mandate to describe the resilience of strategy under different climate scenarios.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate",
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "eu-eiopa-guidelines-orsa-2015",
      "bermuda-bma-cissa-commercial-insurer-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "tcfd-recommendations-climate-related-financial-disclosures-financial-stability",
    "title": "TCFD Recommendations - Climate-Related Financial Disclosures and Financial Stability Board Framework",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2023-10-01",
    "bluf": "The Task Force on Climate-related Financial Disclosures (TCFD) framework, established by the Financial Stability Board in 2015 and finalised in 2017, provides voluntary recommendations for disclosing climate-related risks and opportunities under four pillars: Governance, Strategy, Risk Management, and Metrics and Targets. TCFD has been incorporated into mandatory reporting regimes in the UK (FCA listing rules), New Zealand, Hong Kong, Singapore, and Canada. The IFRS Foundation's ISSB IFRS S2 standard (2023) builds directly on TCFD and supersedes it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-directive-article-2-scope-of-sustainability-reporting"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "tcfd-status-report-2022",
    "title": "Task Force on Climate-related Financial Disclosures: 2022 Status Report",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2022-09-15",
    "bluf": "This fifth annual status report from the Task Force on Climate-related Financial Disclosures (TCFD) reflects on the implementation of its recommendations since their release in 2017. The TCFD framework provides a structure for companies and other organizations to develop more effective climate-related financial disclosures through their existing reporting processes. These voluntary disclosures are designed to be useful to investors, lenders, insurance underwriters, and others in understanding material risks and supporting informed, efficient capital-allocation decisions. The framework applies to entities with public debt or equity, as well as asset managers and asset owners, including pension plans, endowments, and foundations.\n\nThe core obligation for these organizations is to disclose information aligned with the TCFD's 11 recommended disclosures, which are organized around four thematic areas: Governance, Strategy, Risk Management, and Metrics and Targets. The TCFD's goal is that through widespread adoption, the financial risks and opportunities related to climate change will become a natural part of companies’ risk management and strategic planning processes. While the report notes that the percentage of companies disclosing TCFD-aligned information continues to grow, it also finds that more urgent progress is needed, as not enough companies are disclosing decision-useful climate-related financial information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-climate-related-financial-risks",
      "iso-31000-risk-mgt"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "td-arcep-framework",
    "title": "Chad ARCEP Framework - AU Malabo Convention and Constitutional Privacy Obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Republic of Chad has established the Autorité de Régulation des Communications Electroniques et des Postes (ARCEP) as the national regulatory authority for electronic communications, digital services, and postal services in Chad. The Constitution of the Republic of Chad establishes fundamental rights including the right to privacy of individual and family life, inviolability of correspondence and private communications, and freedom from arbitrary interference. As a member state of the African Union, Chad is subject to the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014), which constitutes the primary regional standard for personal data protection applicable in Chad. Chad does not have a standalone comprehensive personal data protection law. ARCEP's regulatory framework establishes obligations for licensed electronic communications operators regarding the protection of subscriber personal data, confidentiality of communications, and security of telecommunications networks. Organisations operating digital services and processing personal data in Chad must respect constitutional privacy rights, comply with ARCEP's subscriber data protection requirements, and implement personal data processing practices consistent with AU Malabo Convention principles. ARCEP has authority to investigate complaints against licensed operators and enforce compliance with telecommunications regulatory obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/td-arcep-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "telemedicine-cross-border-2026",
    "title": "Telemedicine & Cross-Border Healthcare Delivery - Global Compliance Framework (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Cross-border telemedicine services must navigate licensing, data protection, reimbursement, liability, and quality standards across jurisdictions. Key challenges include lawful basis for international data transfers, physician licensing in recipient countries, informed consent for virtual care, and secure platform requirements. Many countries now have dedicated telemedicine laws or guidelines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "texas-florida-telehealth-2026",
    "title": "Texas & Florida Telehealth Registration & Parity Rules 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "Texas and Florida allow out-of-state providers to register for telehealth without full in-state licensure under specific conditions, including liability coverage and scope limits. Both states maintain pay parity for covered services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "texas-health-data-privacy-2026",
    "title": "Texas Health Care Privacy Law & Data Privacy Framework (2026)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Texas Health Care Privacy Law (HB 300 and subsequent amendments) imposes strict requirements on covered entities handling protected health information. It includes patient consent for certain disclosures, prohibition on sale of health data, mandatory breach notification within 30 days, right to access and correct records, and significant civil penalties. It works alongside HIPAA and the Texas Data Privacy and Security Act (TDPSA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 3
  },
  {
    "node_id": "tg-pdp-law-2019",
    "title": "Togo Personal Data Protection Law - APDP Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Togo Law No. 2019-014 on Personal Data Protection (2019) establishes ECOWAS-aligned data subject rights, prior authorization requirements for sensitive processing, and a mandatory registration regime. The Autorité de Protection des Données à Caractère Personnel (APDP Togo) is the designated supervisory authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "th-government-procurement-supplies-management-act-be-2560-2017",
    "title": "Thailand Government Procurement and Supplies Management Act B.E. 2560 (2017)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Thailand Government Procurement and Supplies Management Act B.E. 2560 (2017) (Phra Ratchabanyat Kan Chat Suu Chat Chang Pakong Lae Kan Borihan Pa Su Du Phak Rat / known in Thai as Phra Ratchabanyat Kan Chat Suu Chat Chang 2560) effective 23 August 2017 is the principal Thai statute governing procurement of goods, services, construction works, and consultancy services by state agencies, state enterprises, and other public entities. The 2017 Act replaced a fragmented regime of multiple procurement regulations including the Office of the Prime Minister Regulation on Procurement B.E. 2535 (1992) and consolidated the Thai procurement framework into a single statutory instrument. The 2017 Act was a major reform driven by Thailand's anti-corruption commitments under the OECD Convention on Combating Bribery of Foreign Public Officials, the United Nations Convention against Corruption (UNCAC), and the Thai Government's National Anti-Corruption Strategy. The Act establishes the Comptroller General's Department (Krom Banchi Klang / CGD) within the Ministry of Finance as the central procurement regulator and the operator of the Thai Government Electronic Procurement System (e-GP / process3.gprocurement.go.th). Procurement methods established by the Act include (a) e-bidding (e-bid, the default electronic open tender method), (b) selection method (withi khat lueak), (c) specific method (withi chapho jeh joeng), and (d) market price method (withi tang ratcha tham), with specific-method and selection-method procurement subject to prescribed exceptions and value thresholds. The 2017 Act introduced strengthened integrity provisions including the Integrity Pact (sanya khun na pap) requirement for high-value procurement, supplier debarment lists, and mandatory disclosure of bidder beneficial ownership. The implementing regulations include the Ministerial Regulations on Government Procurement issued pursuant to the Act and the CGD Circulars on procurement procedure. Thailand is an observer to the WTO Government Procurement Agreement (GPA) but is not a party.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "th-pdpa-2019",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "th-pdpa-2019",
    "title": "Thailand Personal Data Protection Act B.E. 2562 (2019) - PDPC Enforcement and Data Subject Rights",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Thailand's Personal Data Protection Act B.E. 2562 (PDPA), published in the Royal Gazette on 27 May 2019, received Royal Assent on 24 May 2019. The PDPA was originally scheduled to enter into full force on 27 May 2020, but implementation was delayed by royal decrees issued during the COVID-19 pandemic. The full PDPA entered into force on 1 June 2022. The PDPA is Thailand's first comprehensive personal data protection law and was significantly influenced by the EU General Data Protection Regulation (GDPR), adopting broadly similar legal bases, data subject rights, and enforcement mechanisms adapted for the Thai legal and regulatory context. The governing body is the Personal Data Protection Committee (PDPC - คณะกรรมการคุ้มครองข้อมูลส่วนบุคคล), established under the PDPA to issue regulations, provide guidance, and oversee enforcement. The PDPA applies to data controllers and data processors in Thailand, as well as to overseas entities offering goods or services to data subjects in Thailand or monitoring the behaviour of data subjects in Thailand (extraterritorial reach). Key features: (1) Six lawful bases for processing: consent, contract performance, vital interests, legitimate interests, legal obligation, and public interest/official authority - mirroring GDPR Art. 6 bases; (2) Sensitive personal data - data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade union membership, genetic data, and biometric data - processed only with explicit consent or in limited exceptions; (3) Data subject rights: access, correction, deletion/erasure, restriction of processing, data portability, objection, and the right not to be subject to automated decision-making; (4) Mandatory breach notification - data controllers must notify the PDPC within 72 hours of becoming aware of a personal data breach; affected data subjects must be notified without undue delay where the breach is likely to result in high risk to their rights and freedoms; (5) Data Protection Officer (DPO) - required for large-scale processing, sensitive data processing, or public authority processing; (6) Consent requirements - consent must be freely given, specific, informed, and unambiguous; withdrawal of consent must be as easy as giving it; (7) Administrative fines - up to THB 5 million per violation; (8) Criminal penalties - imprisonment up to 1 year and/or fine up to THB 1 million for intentional violations; up to 6 months and/or THB 500,000 for negligent violations; (9) Civil liability - data subjects may claim compensation for damages arising from PDPA violations. Thailand does not yet have EU GDPR adequacy recognition. The PDPC Secretariat (สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล - SPDPC) at pdpc.or.th handles regulatory guidance, complaints, and breach notifications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "th-pdpa-2022",
    "title": "Personal Data Protection Act B.E. 2562 (2019)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Thailand's PDPA regulates the collection, use, and disclosure of personal data for organizations inside Thailand and those outside who process data of Thai residents. As per Section 19, data processing is prohibited without a valid legal basis, such as consent, contractual necessity, or legitimate interest, as detailed in Sections 20-26.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "th-pdpa-cross-border-data-transfer-regulations-2024",
    "title": "Thailand PDPC Subordinate Regulations on Cross-Border Personal Data Transfers 2023/2024 - Green Route (Section 28) and Safeguard Route (Section 29), Effective 24 March 2024",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Data controllers in Thailand transferring personal data internationally must comply with the two subordinate regulations under the Personal Data Protection Act (PDPA) published in the Government Gazette on 25 December 2023 and effective from 24 March 2024, choosing between the Adequacy route (Section 28, the Green Route, applicable where the destination is on the PDPC adequacy list which is currently empty) and the Appropriate Safeguards route (Section 29, the Safeguard Route, available through Standard Contractual Clauses based on ASEAN or EU models with Thai-specific obligations such as 72-hour breach reporting, certification, or binding instruments between Thai and foreign government agencies), treating all current cross-border transfers as going to non-adequate destinations requiring proper safeguards until the PDPC publishes an adequacy list.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "thailand-immigration-act-be-2522-1979-immigration-bureau",
    "title": "Thailand Immigration Act B.E. 2522 (1979) - Immigration Bureau Visa and Residency Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Thailand's immigration framework is governed by the Immigration Act B.E. 2522 (1979) (Phraratchabanyat Khonnakaomuang B.E. 2522), administered by the Immigration Bureau (Samnak Ngan Khonnakaomuang) under the Royal Thai Police, in coordination with the Ministry of Interior. Thailand issues visa-on-arrival to nationals of 19 countries for 15 days and visa exemptions to nationals of 57+ countries for 30-60 days. Non-Immigrant visa categories cover employment (Non-B), education (Non-ED), retirement (Non-OA), and investment (Non-B/BOI). The 90-Day Reporting requirement obligates all foreigners on non-immigrant visas to report their address to the Immigration Bureau every 90 days. Thailand's overstay fine is THB 500 per day with a maximum of THB 20,000; arrest and blacklist apply to overstays exceeding 90 days. Work permits (bai anunyat thamngaan) from the Department of Employment (DOE) under the Ministry of Labour are mandatory for all working foreigners. The Thailand Long-Term Resident (LTR) Visa was launched in 2022 for high-value residents (USD 80,000/year income or USD 250,000 investment). The Smart Visa (2018) offers 4-year visas for targeted industries. ASEAN nationals benefit from bilateral visa exemptions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "work_permit_doe",
        "boi_promotion",
        "asean_framework",
        "data_protection",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "thailand-pdpa-2019-personal-data-protection",
    "title": "Personal Data Protection Act B.E. 2562 (2019)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Thailand's Personal Data Protection Act (PDPA) governs the collection, use, and disclosure of personal data by data controllers and processors within Thailand, and certain entities outside Thailand processing data of Thai residents. It mandates obtaining explicit consent for most processing activities (Section 19), establishes data subject rights, and empowers the Personal Data Protection Committee (PDPC) with enforcement and penalty powers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gdpr-binding-corporate-rules",
      "gdpr-article-17-right-erasure",
      "gdpr-article-30-records-processing",
      "gdpr-article-37-dpo",
      "oecd-privacy-guidelines-2013"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "thailand-sec-crypto-exchange-regulations-2022",
    "title": "Securities and Exchange Commission (SEC) Thailand - Digital Asset Exchange, Broker, and Dealer Licensing Regulations, Investor Qualification, Stablecoin Payment Ban, and Social Media Advertising Restrictions (2022)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "This regulation establishes licensing requirements for digital asset exchanges, brokers, and dealers in Thailand under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018), mandates investor qualification and suitability assessments, prohibits stablecoins and other digital assets from being used as means of payment, and restricts crypto advertising on social media platforms. Key obligations derive from the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018), including the requirement to obtain a license, together with SEC Thailand notifications issued under it (including the 2022 notification banning use of digital assets as a means of payment).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "eu-dlt-pilot-regime-2022-858",
      "bis-iosco-pfmi-applied-to-dlt-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "tiktok-ads-policy-std",
    "title": "TikTok Ads (Policies)",
    "domain": "Sales, Marketing & PR",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "BIDDA's TikTok Ads (Policies) node programmatically assesses advertising creatives and their associated landing pages against a comprehensive set of platform integrity standards to mitigate non-compliance risk. The evaluation strictly prohibits content promoting illegal products or services, weapons, tobacco, and graphic violence. It also flags age-restricted content, such as promotions for alcohol or gambling, that require specific targeting. Any ad containing hate speech that demeans protected groups based on race, religion, or sexual orientation will be flagged. Furthermore, creatives are analyzed for sexually suggestive content, including non-artistic nudity and explicit imagery, alongside any promotion of harmful acts like dangerous challenges. A critical compliance checkpoint validates against misleading claims, such as unsubstantiated outcomes or fabricated testimonials. The system verifies the presence of required disclosures for regulated industries; for example, financial services advertisements must have risk warnings, and branded content necessitates clear markers like '#Ad'. Landing page integrity is paramount, requiring that destination URL content directly corresponds to the advertised product, and any collection of Personally Identifiable Information must be conducted over a secure HTTPS connection with a valid privacy policy. Unauthorized use of copyrighted music or trademarks constitutes a violation of intellectual property rights. Finally, a quantitative content_quality_score measures creative execution, with any score falling below the 0.5 threshold resulting in an automatic compliance failure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-endorsement-guides",
      "coppa-marketing-kids",
      "gdpr-art-21-marketing-optout",
      "asa-advertising-codes-uk",
      "ccpa-cpra-optout-sale"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "tir-convention-1975-customs-transit",
    "title": "TIR Convention 1975 - Customs Transit by Road (TIR Carnet System)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Customs Convention on the International Transport of Goods under Cover of TIR Carnets (TIR Convention 1975, UNTS Vol. 1079 No. 16515) is the cornerstone of international customs transit by road. It allows sealed road vehicles and containers to cross borders of 77 Contracting Parties (including EU as bloc) without customs examination at intermediate customs offices, using a TIR carnet issued by an IRU-authorised national guaranteeing association. Art 4 prohibits intermediate customs examination of goods when seals are intact. The guaranteeing chain (Art 8) limits each national association's liability to EUR 100,000 per TIR carnet per customs office. Mandatory TIR-EPD (Electronic Pre-Declaration) has applied since 2019 for all TIR operations, requiring advance electronic lodgment before departure. Art 38 allows Contracting Parties to temporarily suspend TIR rights for operators who violate the Convention. The EU implements TIR alongside its New Computerised Transit System (NCTS) under Union Customs Code Regulation 952/2013 Arts 233-238. Dangerous goods under ADR may be transported under TIR cover with combined documentation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "cmr-convention-1956-road-carriage-goods",
      "adr-agreement-1957-dangerous-goods-road",
      "wto-tbt-agreement-1995-technical-barriers-trade"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tisaq-auto-cyber",
    "title": "TISAX (Automotive Cyber)",
    "domain": "Cloud & SaaS",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "TISAX (Trusted Information Security Assessment Exchange) is the definitive maturity-based security standard for the global automotive industry. Based on the VDA Information Security Assessment (ISA), it provides a unified mechanism for the mutual recognition of the security assessments among the automotive the value chain, specifically covering the 'Information Security', 'Prototype Protection', and the 'Data Protection'.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0",
      "unece-r155-automotive-cybersecurity-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "tj-law-on-public-procurement-2006-zakupki-tj",
    "title": "Tajikistan Law on Public Procurement of Goods, Works and Services No. 168 of 3 March 2006 (as amended) and Agency for Public Procurement",
    "domain": "Public Sector & Government Procurement",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The Republic of Tajikistan Law on Public Procurement of Goods, Works and Services No. 168 of 3 March 2006 (Qonuni Jumhurii Tojikiston dar borai kharidi davlatii mol, kor va khizmatraso) effective 3 March 2006, amended by Law No. 815 of 16 April 2012, ceased to be valid (was repealed) by Article 75 of the Law of the Republic of Tajikistan No. 1955 of 15 March 2023, which is now the operative procurement instrument. While in force, Law 168/2006 was the principal Tajik statute governing procurement of goods, works, and services by procuring entities (organizatori-on-i kharid) including the Republican Budget bodies (Majlisi Oli, executive bodies including ministries and agencies, the President's Executive Office, the Constitutional Court, the Supreme Court, the General Prosecutor's Office), regional government bodies (hukumat-i viloyat) and local government bodies (hukumat-i shahr va nohiya), state and municipal enterprises, public-sector universities, and other procuring entities financed by the Republican Budget. Law 168/2006 established the modern Tajik procurement framework. The Agency for Public Procurement of Goods, Works and Services under the Government of the Republic of Tajikistan (zakupki.tj) is the central regulatory authority responsible for procurement regulation, oversight, complaint resolution, supplier debarment, and procurement guidance. The Tajik Government Procurement Information System (zakupki.tj) is the federal e-procurement platform. Procurement methods established by Law 168/2006 art. 11 to 26 comprise (a) Konkurs Otkrytyy (Open Tender, the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Konkurs Zakrytyy (Closed Tender, with prequalification or restricted to invited suppliers), (c) Konkurs Dvuhetapnyy (Two-Stage Tender, for complex acquisitions), (d) Zaprashivanie Tsenovykh Predlozheniy (Request for Quotations, for medium-value), (e) Pryamoy Sposob Zakupki (Direct Procurement, sole-source under prescribed exceptions in art. 22 including emergency, sole supplier for technical reasons, prior failed procurement, and prescribed-class exemptions), (f) Iz Edinogo Istochnika (From One Source / Single Source Procurement), and (g) Electronic Reverse Auction. The Chamber of Accounts of the Republic of Tajikistan conducts ex-post procurement audit. The Anti-Corruption Agency has investigative jurisdiction over procurement-related corruption. Tajikistan is in the EAEU accession process and observes EAEU procurement provisions. Tajikistan is NOT a party to the WTO Government Procurement Agreement (GPA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "tj-pdp-law-2018",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "tj-pdp-law-2018",
    "title": "Tajikistan Law on Personal Data Protection 2018",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Tajikistan enacted the Law on Personal Data Protection in 2018, establishing a framework for the collection, storage, use, transfer, and destruction of personal data. The law is administered by the authorised state body for personal data protection. It requires consent as the primary lawful basis, grants data subjects rights of access, rectification, blocking, and destruction of their personal data, and mandates registration of personal data operators with the supervisory authority. Cross-border transfers are restricted to states with adequate protection or where specific conditions are met. The law aligns with CIS (Commonwealth of Independent States) model data protection standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/tj-pdp-law-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "tk-framework",
    "title": "Tokelau - New Zealand Administration and Pacific Privacy Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Tokelau is a non-self-governing territory of New Zealand comprising three low-lying coral atolls - Atafu, Nukunonu, and Fakaofo - located in the South Pacific Ocean. Tokelau has a population of approximately 1,500 people and is administered by New Zealand's Ministry of Foreign Affairs and Trade (MFAT). Tokelau is governed under the Tokelau Act 1948 (New Zealand) and has a traditional governance structure based on the inati (communal sharing) system, with a national body called Te Kāiga (the Tokelau National Government). Two referendums on self-determination (2006 and 2007) did not achieve the required two-thirds majority, and Tokelau remains a non-self-governing territory under New Zealand administration. New Zealand law does not automatically extend to Tokelau unless specifically stated. The New Zealand Privacy Act 2020 does not automatically apply in Tokelau as it is not enacted to extend to non-self-governing territories in the same manner as New Zealand's domestic legislation. The applicable framework for personal data protection in Tokelau consists of common law privacy principles applicable under New Zealand-administered law, Pacific Islands Forum regional guidelines on cybersecurity and data protection, and any applicable provisions under the Tokelau Act 1948. Tokelau is notable for operating the .tk domain registry, which is one of the world's most registered country-code top-level domains. Organisations processing personal data in Tokelau should engage New Zealand legal counsel and MFAT guidance to confirm applicable privacy obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/tk-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tl-pdpl-2011",
    "title": "Timor-Leste Personal Data Protection Framework - Constitutional Article 38",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Timor-Leste's personal data protection rests on Article 38 of the 2002 Constitution of the Democratic Republic of Timor-Leste, which expressly grants every citizen the right to access personal data held about them, to require its correction and updating, and to be informed of the purpose for which it is held, and prohibits the use of personal data contrary to human dignity. Timor-Leste has not yet enacted a dedicated comprehensive data protection statute, so these constitutional guarantees - together with international human-rights standards (ICCPR Article 17) and emerging ASEAN data-protection principles relevant to the country's membership aspirations - form the operative basis for personal data handling. The workflow below sets out aligned good-practice controls (consent, transparency, access and correction, security, purpose limitation, and cross-border safeguards) consistent with these constitutional principles pending dedicated legislation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/tl-pdpl-2011.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "tm-pdp-law-2015",
    "title": "Turkmenistan Law on Information on Private Life and its Protection (No. 519-V, 2017)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Turkmenistan's data protection statute is the Law of Turkmenistan 'On Information on Private Life and its Protection' No. 519-V, adopted on 20 March 2017 and effective from 1 July 2017. There is no separate Turkmenistan 'Law on Personal Data' dated 2015. The Law governs the collection, processing, storage, use and disclosure of information about an individual's private life by data operators in the public and private sectors. It requires that personal information be collected lawfully, kept confidential, accurate and not excessive, and that access be restricted; it requires consent for processing; and it grants data subjects rights to be informed of access, to access their information, to request rectification and erasure, and to withdraw consent. Oversight is exercised at the level of the Cabinet of Ministers of Turkmenistan, with supervisory and enforcement involvement of the Prosecutor General's Office, rather than by a dedicated independent data protection authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/tm-pdp-law-2015.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "tn-decret-loi-1039-2014-marches-publics-tuneps",
    "title": "Tunisia Decree No. 1039 of 13 March 2014 on Public Procurement (Decret n. 2014-1039 portant reglementation des marches publics) and the TUNEPS Platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Tunisian Decree No. 2014-1039 of 13 March 2014 on Public Procurement (Decret n. 2014-1039 du 13 mars 2014 portant reglementation des marches publics, JORT 2014 n. 22) effective 1 June 2014 is the principal Tunisian regulatory instrument governing procurement of works, supplies, services, and intellectual services by public entities including the State, local collectivities, public administrative establishments, public non-administrative establishments and state-owned enterprises, and other public entities. The 2014 Decree replaced the prior 2002 procurement regulation and has been amended multiple times including by Decree-Law No. 2020-31 of 10 June 2020 and Decree No. 2022-49 of 22 January 2022. The Haute Instance de la Commande Publique (HAICOP / National High Authority for Public Procurement) is the regulatory authority with oversight, control, complaint resolution, and procurement guidance authority. The Tunisia Online E-Procurement System (TUNEPS / tuneps.tn) operated by the General Direction of National Procurement under the Prime Ministry is the federal e-procurement platform mandatory for in-scope procurement. Procurement methods established by the 2014 Decree comprise (a) Appel d'offres ouvert (Open Call for Tenders, art. 49, the default open public procedure), (b) Appel d'offres restreint (Restricted Call for Tenders, art. 53, with prequalification), (c) Appel d'offres en deux etapes (Two-Stage Tender, art. 55), (d) Concours (Design Contest, art. 56), (e) Procedure negociee (Negotiated Procedure, art. 58 to 62, under prescribed exceptions including emergency, sole supplier for technical reasons, prior unsuccessful tendering, and small-value below thresholds), (f) Achat sur consultation simplifiee (Simplified Consultation Purchase, art. 50 to 52, for small-value below prescribed thresholds), and (g) Concession (Concession Contract, governed by Law 23 of 2008 on Concessions). The 2014 Decree introduced strengthened integrity provisions including supplier debarment, conflict of interest disclosure, anti-corruption commitments, beneficial ownership transparency, and the SME-preference programme. Tunisia is NOT a party to the WTO Government Procurement Agreement (GPA) but is an observer. Tunisia is a party to the EU-Tunisia Association Agreement (1995), the Greater Arab Free Trade Area (GAFTA), the African Continental Free Trade Area (AfCFTA), and UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5",
      "wto-revised-government-procurement-agreement-2012"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "tn-pdp-law-2004",
    "title": "Tunisia Organic Law on Personal Data Protection No. 2004-63 - INPDP",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Tunisia's Organic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data (loi organique No. 2004-63 du 27 juillet 2004, portant sur la protection des données à caractère personnel) - published in the Official Journal of the Republic of Tunisia (JORT) on 3 August 2004 - is Tunisia's primary personal data protection legislation, making Tunisia one of the first African and Arab states to enact comprehensive personal data protection legislation. The law is supplemented by Decree No. 2007-3003 of 27 November 2007, which defines the organisation and operation of the INPDP. The supervisory authority is the Instance Nationale de Protection des Données Personnelles (INPDP - National Instance for the Protection of Personal Data), an independent administrative authority established under Organic Law No. 2004-63. Tunisia ratified the Council of Europe Convention on the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108) in 2017, making Tunisia one of the African countries most integrated into the European data protection framework. Key features of Tunisia's Organic Law No. 2004-63: (1) Scope - applies to processing of personal data by natural or legal persons in Tunisia, whether automated or manual; also applies where Tunisian law governs the processing; (2) Data processing principles - processing must comply with: lawfulness; purpose specification; proportionality; accuracy; and security; (3) Sensitive personal data - the law designates categories of data subject to heightened protection: racial or ethnic origin; political opinions; religious beliefs; criminal convictions; health data; and sexual life; processing of sensitive data is generally prohibited unless one of the statutory exceptions applies; (4) Prior authorisation/declaration system - Organic Law No. 2004-63 establishes a two-tier system: prior authorisation (autorisation préalable) from the INPDP for sensitive data processing, biometric data, health data, and certain high-risk processing; prior declaration (déclaration préalable) for standard processing; the INPDP must respond to authorisation requests within 45 days; (5) Data subject rights - right of access; right of rectification; right of opposition; and right to object to direct marketing; (6) Cross-border transfers - personal data may only be transferred to countries providing adequate protection for personal data; transfers to non-adequate countries require INPDP authorisation; (7) INPDP powers - receives declarations and authorisations; investigates complaints; conducts on-site inspections; issues formal notices; refers cases for prosecution; (8) Criminal penalties - violations of Organic Law No. 2004-63 carry criminal penalties: fines and imprisonment for serious violations including: processing personal data without lawful basis; processing sensitive data without authorisation; violating data security obligations; obstructing INPDP investigations; (9) Automated processing - systems using automated processing of personal data to profile individuals or make significant decisions must be specifically declared to or authorised by the INPDP. Tunisia's data protection framework reflects its civil law tradition (influenced by French legal heritage) and its position as a North African country with significant economic ties to EU member states, particularly France, making Tunisian data protection compliance relevant to EU-Tunisia data flows in the outsourcing, tourism, and financial services sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tnfd-nature-disclosure",
    "title": "TNFD Nature Disclosure",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Corporate reporting indicates substantive alignment with the procedural components of the nature-related disclosure framework, though significant deficiencies persist regarding quantitative financial analysis. The entity meets foundational governance requirements, providing a comprehensive disclosure wherein board-level oversight mechanisms are clearly described. Strategic and risk management processes appear well-documented, with confirmation that scenario analysis has been performed, the risk management process is disclosed, and the recommended LEAP approach was applied for assessment. Integration across the value chain, however, is documented at a moderate level two, indicating incomplete assimilation of nature-related considerations. A formal disclosure of metrics and targets is present, with the organization reporting on five distinct nature-related metrics. A critical finding is that while these metrics exist, the associated objectives are not established as science-based targets, suggesting a potential lack of validation against recognized ecological thresholds. The most significant gap remains the failure to quantify financial impacts; this omission represents a material deviation from the final recommendations, which explicitly call for connecting nature-related dependencies to financial outcomes. While stakeholder engagement is disclosed and underlying data sources are validated, the absence of financial quantification severely limits the report's utility for investors and requires immediate remediation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "tcfd-climate-risk",
      "issb-s1-s2-standard",
      "csrd-eu-sustainability",
      "gri-universal-standards"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "to-ca-2000",
    "title": "Tonga Communications Act 2000 - Consumer Data and Personal Information Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Kingdom of Tonga enacted the Communications Act 2000, which establishes the Tonga Communications Board (TCB) as the regulatory authority for telecommunications and electronic communications in Tonga, and includes consumer data and personal information protection provisions applicable to communications service providers. The Act requires licensed communications operators in Tonga to protect the confidentiality of subscriber and user information, prohibits the disclosure of customer personal data without consent except where required by law or for network security purposes, establishes obligations for secure handling of call records and communications data, and grants the TCB authority to investigate complaints and enforce compliance with consumer data protection requirements. Tonga does not have a standalone comprehensive personal data protection law, and the Communications Act 2000 together with provisions of the Consumer Protection Act and the constitutional right to dignity and privacy represents the primary legal framework for personal data protection in electronic communications and digital services in Tonga. The TCB exercises jurisdiction over licensed telecommunications and information service providers operating in Tonga regarding the protection of subscriber and user personal information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/to-ca-2000.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "togaf-10-enterprise-architecture-workflow",
    "title": "The TOGAF® Standard, 10th Edition - Enterprise Architecture and Workflow Design: Architecture Development Method, Business Architecture, Application Architecture and Migration Planning",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The TOGAF® Standard, 10th Edition provides a structured methodology for developing enterprise architectures, including Business, Application, and Technology Architectures, using the Architecture Development Method (ADM). It applies to enterprise architects and organizations designing scalable, interoperable, and efficient workflows across digital transformation initiatives. Key guidance is provided in the TOGAF Fundamental Content and Series Guides.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "tokyo-convention-1963-offences-aboard-aircraft",
    "title": "Tokyo Convention 1963 - Offences and Acts Aboard Aircraft and Jurisdictional Framework (with Montreal Protocol 2014)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Convention on Offences and Certain Other Acts Committed on Board Aircraft (Tokyo Convention) was adopted in Tokyo on 14 September 1963 and entered into force on 4 December 1969. It is the foundational international instrument governing offences committed aboard civil aircraft engaged in international flight. The Convention establishes flag State jurisdiction (Article 3): the State of registration is competent to exercise jurisdiction over offences and acts committed on board, although other States may also exercise jurisdiction under defined conditions. The aircraft commander has authority (Article 6) to disembark persons or restrain persons committing offences. Provisions cover unlawful seizure of aircraft (Article 11). The 2014 Montreal Protocol amending the Tokyo Convention (Protocol on Acts of Unruly Passengers) entered into force on 1 January 2020 expanding jurisdiction to include landing State and operator State (where carrier has principal place of business or permanent residence), and creating obligation for States to take measures against unruly passengers. The Tokyo Convention has 187 States Parties; the Montreal Protocol 2014 has 47 States Parties as of 2024 (sufficient for entry into force).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-chicago-convention-1944-civil-aviation",
      "icao-annex-17-security"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tourism-disaster-resilience",
    "title": "Tourism Disaster Resilience",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with tourism disaster resilience protocols mandates a comprehensive and actively managed framework for mitigating operational disruptions. A documented risk assessment is a foundational requirement, subject to review and update at least every 12 months. Organizations must maintain a current emergency response plan that explicitly incorporates a detailed communication strategy and clear evacuation procedures. To ensure operational continuity, the framework necessitates redundant communication channels. Proactive preparedness measures are enforced through the execution of minimum one disaster drill conducted annually, supplemented by no less than four annual staff training hours per employee. Asset and personnel protection standards stipulate that emergency supplies must be stocked to sustain operations for a 72-hour period. Digital resilience is equally critical, demanding a formal cyber incident response plan alongside a data backup frequency of no more than 24 hours between cycles. Finally, enterprise resilience is extended through formalized mutual aid agreements with partners, establishing a network for support during significant incidents. Adherence to these specific thresholds is non-negotiable for maintaining certified compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "gstc-tourism-criteria",
      "iso-21401-tourism-sustain",
      "hotsec-hotel-security"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "tr-kvkk-2016",
    "title": "Law on Protection of Personal Data No. 6698",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Turkish Law on Protection of Personal Data (KVKK) governs the processing of personal data for natural persons whose data is processed in Turkey. It requires data controllers to adhere to principles of lawful and fair processing (Article 4), obtain explicit consent for most processing activities (Article 5), and implement robust security measures to protect data integrity (Article 12).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "brazil-lgpd-compliance",
      "za-popia-2013",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tr-public-procurement-law-4734-2002-kik-ekap",
    "title": "Turkey Public Procurement Law No. 4734 of 2002 (Kamu Ihale Kanunu) and the EKAP Electronic Procurement Platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Turkish Public Procurement Law No. 4734 (Kamu Ihale Kanunu, KIK) enacted 4 January 2002 and effective 1 January 2003 is the principal Turkish statute governing procurement of goods, services, and construction works by public administrations including general budget administrations, special budget administrations, regulatory and supervisory authorities, social security institutions, local administrations, public economic enterprises, and other public entities financed by the public budget. Law 4734 was a comprehensive modernisation aligning Turkey with EU procurement directives in preparation for EU accession negotiations and the Customs Union with the European Union. The parallel Law on Tendering for Public Works No. 2886 was substantially replaced by Law 4734 for procurement and remains relevant for state property and lease tenders. The Public Procurement Authority (Kamu Ihale Kurumu / KIK) established under Law 4734 is the autonomous regulator with rule-making authority, complaint resolution, and supplier debarment authority. The Electronic Public Procurement Platform (Elektronik Kamu Alimlari Platformu / EKAP, ekap.kik.gov.tr) is the mandatory federal e-procurement platform operated by KIK. Procurement methods established by Law 4734 comprise (a) Open Procedure (Acik Ihale, Article 18, the default), (b) Restricted Procedure (Belli Istekliler Arasinda Ihale, Article 18, with prequalification), (c) Negotiated Procedure (Pazarlik Usulu, Article 21, under prescribed exceptions including emergency, urgent, sole-source for technical reasons, and small-value below thresholds), (d) Direct Procurement (Dogrudan Temin, Article 22, for small-value and prescribed-exception transactions), and (e) Design Contest (Tasarim Yarismasi). Law 4734 establishes thresholds (esik degerler) which trigger covered procurement obligations including the open procedure default. The Turkish procurement framework operates within Turkey's trade obligations including the EU-Turkey Customs Union (1995), the Stabilisation and Association Process, and the OECD Convention on Combating Bribery. Turkey is NOT a party to the WTO Government Procurement Agreement (GPA) but is an observer.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "tr-kvkk-2016",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "tri-agency-task-force-diagnostics",
    "title": "CHARTER Tri-Agency Task Force for Emergency Diagnostics",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-10",
    "bluf": "The Tri-Agency Task Force for Emergency Diagnostics (TTFED), with members from Centers for Disease Control and Prevention (CDC), Food and Drug Administration (FDA), and Centers for Medicare and Medicaid Services (CMS), is established to develop a process to collaborate on future emergency diagnostic response needs. During emergencies, the TTFED will convene quickly to provide timely recommendations to laboratories for rapid implementation of in vitro diagnostic (IVD) assays authorized for use under FDA’s Emergency Use Authorization (EUA) authority. During public health emergencies, it is critical for IVD assays to be implemented quickly into clinical and public health laboratories for rapid patient care, and laboratories need clear guidance on the application of Clinical Laboratory Improvement Amendments of 1988 (CLIA) regulations for these assays.\nThrough the TTFED, the agencies intend to coordinate the implementation of EUA IVD assays in laboratories within the U.S. healthcare system, with the ultimate goal of improving responses to public health emergencies. The TTFED was created to facilitate the use of any authorized EUA IVD assay and provide a platform to coordinate efforts to identify, establish and implement approaches to effectively and efficiently communicate. This work will occur through biannual meetings at a minimum, with the task force providing a forum for discussion of agent- or response-specific EUA IVD assays to help facilitate rapid implementation during an emergency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice",
      "hl7-fhir-v4-interop",
      "fda-electronic-source-data"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "tri-agency-task-force-emergency-diagnostics",
    "title": "CHARTER Tri-Agency Task Force for Emergency Diagnostics",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2019-02-07",
    "bluf": "The Tri-Agency Task Force for Emergency Diagnostics (TTFED), with members from Centers for Disease Control and Prevention (CDC), Food and Drug Administration (FDA), and Centers for Medicare and Medicaid Services (CMS), is established to develop a process to collaborate on future emergency diagnostic response needs. During emergencies, the TTFED will convene quickly to provide timely recommendations to laboratories for rapid implementation of in vitro diagnostic (IVD) assays authorized for use under FDA’s Emergency Use Authorization (EUA) authority. The TTFED's objective is to coordinate the implementation of EUA IVD assays in laboratories within the U.S. healthcare system, with the ultimate goal of improving responses to public health emergencies.\n\nThis applies to the member agencies (CDC, FDA, CMS) and provides guidance affecting clinical and public health laboratories implementing EUA IVD assays. The core obligation is for the task force to coordinate efforts to identify, establish, and implement approaches to effectively and efficiently communicate, formalize interagency processes, and provide timely recommendations during emergencies to ensure appropriate implementation of these diagnostic assays. The TTFED will meet biannually at a minimum and will convene at the beginning of any public health situation expected to involve a declaration of an emergency by the Secretary of HHS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-electronic-source-data",
      "gxp-mfg-practice",
      "hl7-fhir-v4-interop"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "trips-agreement-wto-copyright-patents-ip-1994",
    "title": "Agreement on Trade-Related Aspects of Intellectual Property Rights (TRIPS), Part II - Standards Concerning the Availability, Scope and Use of Intellectual Property Rights",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The TRIPS Agreement establishes minimum standards for copyright, patents, trademarks, and related intellectual property rights that all WTO member states must implement in their national laws. Key obligations include national treatment (Article 3), most-favored-nation treatment (Article 4), and enforcement mechanisms under Articles 41-61.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dmca-safe-harbor",
      "eu-copyright-directive-art-17",
      "iptc-photo-metadata",
      "iptc-video-metadata",
      "isan-audiovisual-number"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "trusted-iot-device-onboarding",
    "title": "Trusted Internet of Things (IoT) Device Network-Layer Onboarding and Lifecycle Management: Enhancing Internet Protocol-Based IoT Device and Network Security",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2025-11-01",
    "bluf": "This practice guide from the National Cybersecurity Center of Excellence (NCCoE) demonstrates various mechanisms for trusted network-layer onboarding of IoT devices in Internet Protocol-based environments. Establishing trust between a network and an Internet of Things (IoT) device prior to providing the device with the credentials it needs to join the network is crucial for mitigating the risk of potential attacks, which can occur when a device is convinced to join an unauthorized network or when a malicious device infiltrates a network. Trust is achieved by attesting and verifying the identity and posture of the device and the network before providing the device with its network credentials. The guide shows how to provide network credentials to IoT devices in a trusted manner and maintain a secure device posture throughout the device lifecycle, thereby enhancing IoT security.\n\nThe guidance applies to IoT device users, manufacturers, and vendors of semiconductors, secure storage components, IoT devices, and network onboarding equipment. The core obligation is to use scalable, automated mechanisms to securely manage IoT devices, particularly through a trusted mechanism for providing IoT devices with unique network credentials and access policies at the time of deployment. This approach aims to safeguard IoT devices from being taken over by unauthorized networks, ensure networks are not put at risk as new IoT devices are added, and provide ongoing protection of IoT devices throughout their lifecycles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-213-iot-guidance",
      "nistir-8259a-iot-device-cybersecurity",
      "nist-sp-800-183-networks-of-things",
      "nist-sp-800-63b-authentication",
      "nist-sp-800-207",
      "nist-sp-1800-15-iot-mud"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tsa-aviation-cybersecurity-amendment-2023",
    "title": "TSA Security Directive 1542-21-01C: Enhancing Aviation Cybersecurity (2023 Amendment)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive mandates that TSA-regulated airport and aircraft operators implement specific cybersecurity measures, including network segmentation, access controls, continuous monitoring, and mandatory 24-hour incident reporting to CISA, to protect critical aviation systems from cyber threats.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-53-sc7",
      "cyber-nist-800-53-ac2",
      "cisa-cross-sector-cybersecurity-goals",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tsa-pipeline-cybersecurity-directive-sd-02c-2022",
    "title": "Security Directive Pipeline-2021-02C - Pipeline Cybersecurity Mitigation Actions, Contingency Planning, and Testing",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This directive mandates that owners and operators of TSA-designated critical pipelines implement specific cybersecurity mitigation measures, establish and maintain a Cybersecurity Contingency/Response Plan, and conduct an annual Cybersecurity Architecture Design Review. These requirements are detailed in Sections I, II, and III of the directive to protect critical infrastructure from cyber threats.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cisa-cross-sector-cybersecurity-goals",
      "nist-cybersecurity-framework-2-0",
      "nist-800-53-sc7",
      "nist-800-53-cp2",
      "cis-controls-v8"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tt-dpa-2011",
    "title": "Trinidad and Tobago Data Protection Act 2011 - Data Protection Commissioner",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Trinidad and Tobago's Data Protection Act 2011 (Act No. 13 of 2011, as amended by Act No. 4 of 2022), is Trinidad and Tobago's primary personal data protection legislation establishing a rights-based framework for the protection of personal data in both the public and private sectors. Trinidad and Tobago is a Caribbean Commonwealth country whose legal system is based on English common law; the Data Protection Act was enacted to protect individuals from the processing of their personal data without appropriate legal authority and to provide for related matters. The supervisory authority is the Data Protection Commissioner, an independent statutory officer established under the Act whose mandate covers enforcement, guidance, and promotion of data protection standards throughout Trinidad and Tobago. The 2022 amendments strengthened the enforcement framework and brought additional provisions into force. Key features of Trinidad and Tobago's Data Protection Act 2011 as amended: (1) Scope - applies to personal data processing by organisations in Trinidad and Tobago across both public and private sectors; (2) Data processing principles - processing must comply with: lawfulness; fairness; relevance and data minimisation; accuracy; storage limitation; security; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or similar beliefs; physical or mental health condition; sexual life; trade union membership; criminal proceedings and convictions; and financial status; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to block; right to deletion; and right to object to processing; (6) Registration - controllers may be required to register with the Data Protection Commissioner; (7) Security obligations - controllers must implement technical and organisational measures appropriate to the risk of processing; (8) Breach notification - controllers must notify the Data Protection Commissioner of security breaches involving personal data; (9) Cross-border transfers - personal data may only be transferred outside Trinidad and Tobago where adequate protection or appropriate safeguards exist; and (10) Penalties - administrative fines and criminal penalties for violations. Trinidad and Tobago's Data Protection Act represents one of the earliest comprehensive data protection frameworks in the Caribbean region and reflects Commonwealth data protection principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tt-public-procurement-disposal-public-property-act-2015-effective-2023-oprc",
    "title": "Trinidad and Tobago Public Procurement and Disposal of Public Property Act 2015 effective 26 April 2023 (Act No. 1 of 2015 as amended) and OPRC",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Trinidad and Tobago Public Procurement and Disposal of Public Property Act 2015 (Act No. 1 of 2015) effective 26 April 2023 as substantially amended by Act No. 8 of 2016, Act No. 10 of 2017, Act No. 8 of 2020, and the Public Procurement and Disposal of Public Property (Amendment) Act 2023 (Act No. 7 of 2023), and supplemented by Regulations 2022, is the principal Trinidad and Tobago statute governing procurement of goods, works, and services and disposal of public property by public bodies including ministries and government departments, statutory authorities, state enterprises, regional health authorities, regional corporations and local government authorities, the Tobago House of Assembly and its agencies, public-sector universities, and other entities financed wholly or partly from public funds. The 2015 Act replaced the Central Tenders Board Act and modernised the Trinidadian procurement regime aligning with international best practice. The Office of Procurement Regulation (OPR / oprc.tt) is the central regulatory authority responsible for procurement regulation, oversight, supplier debarment, and complaint resolution. The Trinidad and Tobago Government Electronic Procurement System (G2BTT / under rollout) is the federal e-procurement platform. The Procurement Review Board (PRB) handles procurement appeals. Procurement methods established by the 2015 Act sec. 24 to 47 comprise (a) Open Competitive Bidding (the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Selective Tendering (with prequalification), (c) Limited Tendering (restricted to invited suppliers under prescribed exceptions), (d) Sole Source Procurement (sole-source under prescribed exceptions in sec. 32 including emergency, sole supplier for technical reasons, prior failed tendering, additional procurement under existing contract, and prescribed-class exemptions), (e) Request for Quotations (for medium-value goods and services), (f) Request for Proposals (for consulting services), (g) Procurement by Two-Stage Procedure (for complex acquisitions), (h) Framework Agreements, and (i) Procurement by Electronic Reverse Auction. The Auditor-General of Trinidad and Tobago conducts ex-post procurement audit. The Integrity Commission has investigative jurisdiction over procurement-related corruption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "tt-dpa-2011",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "turkey-electricity-market-law-6446-2013",
    "title": "Turkey Electricity Market Law No. 6446 (2013) - EPDK Licensing and Market Regulation",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Turkey's Electricity Market Law No. 6446 (2013, amended through 2023) establishes the Energy Market Regulatory Authority (EPDK - Enerji Piyasasi Duzenleme Kurumu) as the independent electricity regulator, mandates competitive generation and retail markets, governs licensing for generation, transmission (TEIAS state monopoly), distribution (21 licensed distribution companies), and supply activities, and establishes the Electricity Day-Ahead Market (DAP) and Intraday Market (GIP) operated by EPIAS (Energy Exchange Istanbul).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electricity-market-reform-regulation-2024-1747",
      "india-electricity-amendment-act-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "turkey-law-6458-foreigners-international-protection-2013",
    "title": "Turkey Law 6458 on Foreigners and International Protection 2013 - DGMM Framework",
    "domain": "Immigration & Border Control",
    "version": "2.1",
    "last_updated": "2026-05-10",
    "bluf": "Law No.6458 on Foreigners and International Protection (YUKK), enacted 4 April 2013, is Turkey's foundational immigration and asylum statute, replacing fragmented earlier legislation. The Directorate General of Migration Management (DGMM - Goc Idaresi Genel Mudurlugu) under the Ministry of Interior administers the law. Turkey hosts the world's largest refugee population - over 3.6 million registered Syrian refugees under Temporary Protection regime (Regulation 2014/6883), plus 350,000+ registered non-Syrian international protection applicants. Under YUKK Art.19, foreign nationals require valid visas or residence permits for stays beyond visa-free period. The EU-Turkey Joint Action Plan (2016) governs Syrian returns to Turkey from Greece. Digital Nomad visas launched in 2022. Illegal entry is an administrative offence under Art.57; deportation procedures are in Arts.52-60.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "unhcr",
        "eu_turkey",
        "icao_doc",
        "gdpr",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "turkey-tua-national-space-programme-2021",
    "title": "Turkey National Space Programme 2021 - Türkiye Uzay Ajansı (TUA)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2021-02-09",
    "bluf": "Turkey's 10-year National Space Programme (2021-2031) established by TUA (Türkiye Uzay Ajansı) under Presidential Decree 4/2018 targets a domestically launched lunar mission by 2028, mandates TÜRKSAT 5A/5B commercial satellite operation, prescribes TUA as national regulatory authority for space activities, and commits Turkey to UN outer space treaty compliance including debris mitigation and state liability principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "intl-outer-space-treaty-1967-article-1-exploration-freedom",
      "copuos-lts-guidelines-2019-space-sustainability",
      "un-outer-space-treaty-1967",
      "iadc-space-debris-mitigation-guidelines-2007"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tv-framework",
    "title": "Tuvalu - Constitutional Privacy Rights and Pacific Islands Forum Data Protection Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Tuvalu is an independent island nation in the central Pacific Ocean and a member of the Pacific Islands Forum and the Commonwealth of Nations. The Constitution of Tuvalu establishes fundamental rights and protections including the right to privacy of the home and correspondence and freedom from arbitrary interference with personal communications. Tuvalu's telecommunications sector is regulated under the Tuvalu Telecommunications Corporation (TTC) and the relevant government ministry. Tuvalu does not have a standalone comprehensive personal data protection law. The applicable framework for personal data protection in Tuvalu consists of constitutional privacy rights, Pacific Islands Forum regional guidelines on cybersecurity and data protection, and the principle that personal data must be collected and used only for specified, legitimate purposes with appropriate security measures in place. As a Commonwealth member, Tuvalu also draws on Commonwealth data protection principles and good practice guidance. Organisations processing personal data in Tuvalu must respect constitutional privacy rights, implement security measures to protect personal data from unauthorised access and disclosure, provide individuals with means to access and correct personal data held about them, and comply with applicable telecommunications regulatory requirements. There is no dedicated data protection supervisory authority in Tuvalu at present.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/tv-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "tw-money-laundering-control-act",
    "title": "Money Laundering Control Act (Taiwan, ROC)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "Taiwan's Money Laundering Control Act, administered by the Ministry of Justice, defines the money laundering offence in Article 2, requires risk-based customer due diligence in Article 8, mandates record retention of at least five years in Article 10, requires large currency transaction reporting (Article 12) and suspicious transaction reporting (Article 13) to the Investigation Bureau, and sets penalties in Article 19. Designated nonfinancial businesses and professions are covered alongside financial institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "tw-pdpa-2023",
    "title": "Taiwan Personal Data Protection Act 2010 (as amended 2023) - PDPC",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Taiwan's Personal Data Protection Act (個人資料保護法, PDPA) - promulgated by the President of the Republic of China on 26 May 2010, replacing the prior Computer-Processed Personal Data Protection Law (1995), and fully implemented on 1 October 2015 - is Taiwan's comprehensive personal data protection legislation applying to both government agencies and non-government agencies (private sector entities) that collect, process, or use personal data in Taiwan. The landmark 2023 amendments to the PDPA, promulgated on 15 May 2023, established the Personal Data Protection Commission (個人資料保護委員會, PDPC) as an independent supervisory authority under the Executive Yuan, replacing the prior fragmented multi-ministry enforcement model in which the Ministry of Justice (MOJ) and sector-specific central competent authorities each supervised data protection in their respective domains. The PDPC became operationally active on 1 August 2023. Key features of the Taiwan PDPA: (1) Applies to government agencies and non-government agencies processing personal data in Taiwan or where the responsible organisation is domiciled in Taiwan; (2) Sensitive personal data - six designated categories requiring explicit written consent: medical records (病歷), medical treatment (醫療), genetics (基因), sex life (性生活), health examination (健康檢查), and criminal records (犯罪前科); (3) Data subject rights - right of access, right of correction, right of deletion, right to restrict processing, and right to object to processing; (4) Data processing principles - lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability; (5) Entrustment obligations - data controllers entrusting processing to third parties must supervise entrusted parties and ensure equivalent protection by contract; (6) Cross-border transfer restrictions - non-government agencies may transfer personal data outside Taiwan only where the destination jurisdiction provides adequate protection or the data subject has explicitly consented; the PDPC assesses adequacy of foreign jurisdictions; (7) Breach notification - data controllers must notify affected data subjects when a breach may harm their rights and interests; non-government agencies notify the PDPC of significant breaches; PDPC regulations specify timelines and notification formats; (8) Criminal penalties - intentional unlawful collection, processing, or use of personal data for profit or to harm others: imprisonment up to 5 years; unintentional unlawful processing: imprisonment up to 2 years; (9) Privacy Impact Assessment (PIA) - government agencies must conduct PIAs for high-risk personal data processing; PDPC guidelines on PIA methodology; (10) PDPC enforcement powers - the PDPC may issue binding correction orders, conduct audits, impose administrative fines (significantly increased by 2023 amendments), and refer criminal cases for prosecution. Taiwan's PDPA is considered broadly equivalent to GDPR principles by international compliance practitioners; however, Taiwan has not applied for EU adequacy recognition, as Taiwan is not recognised as a sovereign state by the European Union. Taiwan's semiconductor, electronics, and technology sectors - representing a significant share of global critical supply chains - are major PDPA compliance stakeholders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tz-cybercrime-act-2015",
    "title": "Tanzania Cybercrime Act 2015 (Act No. 14 of 2015)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Tanzania's Cybercrime Act 2015 (Act No. 14 of 2015), enacted September 1, 2015, establishes cybercrime offences including unauthorised access, illegal interception, data interference, computer fraud, child pornography, and cyberstalking, creates the National Cyber Response Team under the Tanzania Communications Regulatory Authority for incident coordination, designates critical information infrastructure requiring enhanced protection, and imposes penalties including fines and imprisonment up to life imprisonment for the most serious offences involving national security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/tz-cybercrime-act-2015.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "tz-pdpa-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "tz-pdpa-2022",
    "title": "Tanzania Personal Data Protection Act 2022 - PDPC",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Tanzania's Personal Data Protection Act, 2022 (Act No. 11 of 2022) - assented to by President Samia Suluhu Hassan in 2022 and published in the Government Gazette of Tanzania - is Tanzania's first comprehensive personal data protection legislation, establishing a rights-based framework for the protection of personal data of natural persons in Tanzania. The supervisory authority is the Personal Data Protection Commission (PDPC), established under the Act as an independent public body responsible for registering data controllers and processors, receiving complaints, conducting investigations, and enforcing the Act. Tanzania's Personal Data Protection Act, 2022 reflects the broader East African data protection legislative movement and aligns with international data protection principles, drawing on the frameworks of Kenya's Data Protection Act 2019 and other East African Community (EAC) member states' legislative developments. Key features of Tanzania's Personal Data Protection Act, 2022: (1) Scope - applies to data controllers and data processors established in Tanzania or processing personal data of individuals in Tanzania regardless of where the controller or processor is located; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability; (3) Sensitive personal data - the Act designates specific categories requiring enhanced protection: race or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health data; sex life or sexual orientation; genetic data; biometric data used for unique identification; criminal convictions and offences; and financial data; (4) Lawful processing conditions - processing is permitted where: the data subject consents; the processing is necessary for a contract; required by legal obligation; necessary for vital interests; required for public interest; or justified by legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restrict processing; right to data portability; right to object; and right not to be subject to automated decision-making with significant effects; (6) Data Protection Officer - required for controllers and processors conducting large-scale systematic monitoring, processing sensitive personal data on a large scale, or processing personal data of vulnerable groups; (7) Breach notification - controllers must notify the PDPC of personal data breaches within 72 hours of awareness; data subjects must be notified where the breach is likely to result in harm to their rights; (8) Cross-border transfers - personal data may only be transferred outside Tanzania to adequate jurisdictions or subject to PDPC-approved safeguards; (9) Registration - data controllers and processors must register with the PDPC before commencing processing; (10) Penalties - administrative fines imposed by the PDPC and criminal penalties including fines and imprisonment for serious violations. Tanzania's Personal Data Protection Act, 2022 positions Tanzania as a data-secure jurisdiction within the East African Community, supporting Tanzania's digital economy development objectives and regional data governance harmonisation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "tz-public-procurement-act-7-2011-as-amended-2016-ppra-teu",
    "title": "Tanzania Public Procurement Act No. 7 of 2011 as amended by Act No. 5 of 2016 and the National Electronic Procurement System of Tanzania (NeST/TANePS)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The United Republic of Tanzania Public Procurement Act No. 7 of 2011 assented to 12 December 2011 and effective 15 December 2013 (with the Public Procurement Regulations 2013 issued by GN No. 446 of 2013 amended by GN No. 333 of 2016), as substantially amended by the Public Procurement (Amendment) Act No. 5 of 2016 assented to 7 January 2016, is the principal Tanzanian statute governing procurement of goods, services, works, and disposal of public assets by procuring entities including ministries, departments, agencies (MDAs), regional administration secretariats and local government authorities (RAS-LGAs), parastatal organisations, statutory bodies, public-sector enterprises, public-sector universities, and other entities funded in whole or in part by public funds. Act 7/2011 replaced the prior Public Procurement Act No. 21 of 2004 and modernised the Tanzanian procurement regime. The Public Procurement Regulatory Authority (PPRA) established under Act 7/2011 is the central regulatory body with rule-making, compliance monitoring, complaint resolution, and procurement guidance authority. The Public Procurement Appeals Authority (PPAA) is the specialised tribunal for procurement appeals. The Tanzania National Electronic Procurement System (TANePS / taneps.go.tz) is the federal e-procurement platform. Procurement methods established by Act 7/2011 sec. 64 to 67 and PPR 2013 reg. 159 to 167 comprise (a) International Competitive Tendering (ICT, default for high-value cross-border procurement), (b) National Competitive Tendering (NCT, default for high-value domestic procurement), (c) Restricted Tendering (with prequalification), (d) Competitive Quotations (for medium-value), (e) Minor Value Procurement (for low-value), (f) Force Account (for in-house performance), (g) Single Source Procurement (sole-source under prescribed exceptions including emergency, sole supplier, prior failed tendering, and prescribed-class exemptions), (h) Two-Stage Tendering (for complex acquisitions), (i) Request for Proposals (for consultancy services), and (j) Micro Value Procurement (for very-low-value contracts). The Controller and Auditor-General (CAG), Prevention and Combating of Corruption Bureau (PCCB), and Ethics Secretariat have audit and integrity jurisdiction over procurement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5",
      "wto-revised-government-procurement-agreement-2012"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "ua-pdp-law-2010",
    "title": "Ukraine Personal Data Protection Law No. 2297-VI 2010 - Ombudsman",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Ukraine's Law 'On Personal Data Protection' (Закон України 'Про захист персональних даних') - Law No. 2297-VI, adopted by the Verkhovna Rada (Parliament) of Ukraine on 1 June 2010, signed by President Viktor Yanukovych, and entered into force on 1 January 2011 - is Ukraine's primary personal data protection legislation. The law has been amended numerous times, with significant amendments in 2012, 2014, 2018, and 2021 progressively aligning Ukraine's data protection framework with the European Union General Data Protection Regulation (GDPR) as part of Ukraine's broader EU integration aspirations under the EU-Ukraine Association Agreement (signed 2014). Ukraine received EU candidate status in June 2022. The supervisory authority for personal data protection in Ukraine is the Ukrainian Parliamentary Commissioner for Human Rights (Уповноважений Верховної Ради України з прав людини - the Ombudsman), an independent institution of the Verkhovna Rada, which has been designated as the data protection supervisory authority under the law. This arrangement makes Ukraine's data protection supervision structure distinctive among European countries, as oversight is vested in the human rights ombudsman rather than a dedicated data protection authority. NOTE: Ukraine has been under martial law since 24 February 2022 following Russia's full-scale invasion; the legal framework has been maintained but enforcement capacity and regulatory activity have been affected by wartime conditions; organisations operating in Ukraine should consult current legal guidance on the application of data protection law under martial law. Key features of Ukraine's Law No. 2297-VI: (1) Scope - applies to personal data processing by state bodies, local authorities, individuals, and legal entities in Ukraine; (2) Data processing principles - processing must comply with: lawfulness; consent (where required); purpose limitation; data quality; proportionality; security; and confidentiality; (3) Sensitive categories - the law prohibits processing of sensitive personal data without lawful basis: racial or ethnic origin; political views; religious or philosophical convictions; trade union membership; health status; sexual orientation; genetic data; biometric data; and data concerning criminal convictions; (4) Data subject rights - right of access; right to know the purpose of processing; right to rectification; right to erasure; right to object to processing; right to appeal to the Ombudsman; (5) Consent - general consent required for personal data processing; explicit consent required for sensitive categories; consent must be informed, voluntary, and specific; (6) Database notification - personal data controllers must notify the Ombudsman of databases before processing commences; (7) Cross-border transfer - personal data may be transferred to states providing equivalent protection; transfers to non-adequate states require data subject consent or specific statutory basis; (8) Security obligations - controllers must implement technical and organisational measures to protect personal data; (9) Ombudsman enforcement - investigates complaints; conducts inspections; issues binding orders; imposes administrative sanctions under the Code of Administrative Offences; (10) EU alignment - amendments have progressively introduced GDPR-equivalent concepts including the controller/processor distinction, data subject rights, and security breach response obligations to align with Ukraine's EU integration trajectory. Ukraine's candidacy for EU membership makes alignment with EU data protection standards a legal and political priority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ua-prozorro-public-procurement-system-law-922-viii-2015",
    "title": "Ukraine ProZorro Public Procurement System + Law of Ukraine 922-VIII On Public Procurement (2015, as amended)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "ProZorro is Ukraine's electronic public procurement system, launched as a mandatory system from 1 April 2016 (with earlier piloting from 2015) under the Law of Ukraine On Public Procurement No. 922-VIII of 25 December 2015, the successor statute to Law of Ukraine 1197-VII (2014) which was the original Maidan-era reform law. ProZorro was developed as a public-private-civic-society partnership initiated by Transparency International Ukraine in cooperation with the Ministry of Economic Development and Trade and the SE Prozorro state enterprise. The system operates a unique multi-marketplace architecture in which multiple commercial electronic marketplaces (operating under common protocols and a shared central database) compete to attract buyers and suppliers, while all procurement data flows into the centralised ProZorro database for transparent publication at prozorro.gov.ua. The central database publishes every procurement notice, every bid (including bidder identities, prices, and qualification documents), every clarification, and every contract award in real time, with a typical 24-72 hour cycle from procurement initiation to award. The complementary DoZorro analytical and monitoring system at dozorro.org enables civil society organisations, journalists, and other watchdogs to monitor procurement for fraud and abuse with machine learning-assisted anomaly detection. ProZorro is integrated with multiple state registries including the State Tax Service for tax compliance verification, the Ministry of Justice unified state register for company verification, and the National Agency on Corruption Prevention (NACP) for politically exposed person screening, with cross-referencing to the National Anti-Corruption Bureau (NABU) investigative database. The framework intersects the European Union association agreement provisions on government procurement, the WTO Agreement on Government Procurement (Ukraine acceded with effect from 18 May 2016), the EU procurement directives (which Ukraine is gradually aligning with), and the Council of Europe Convention on Combating Bribery of Foreign Public Officials. ProZorro is widely regarded internationally as a leading model of transparent e-procurement and has been cited by the World Bank, OECD, European Commission, and numerous national procurement reform programmes as a reference implementation. The 2022 Russian invasion of Ukraine triggered specific procurement law amendments under martial law including simplified procedures for defence procurement and humanitarian assistance, with Decree of the Cabinet of Ministers No. 169 of 28 February 2022 and Law No. 2526-IX of 16 August 2022 establishing the operational framework for wartime procurement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "wto-revised-government-procurement-agreement-2012",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uae-adgm-data-protection-regulations-2021",
    "title": "Abu Dhabi Global Market (ADGM) Data Protection Regulations 2021",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The ADGM Data Protection Regulations 2021 impose a comprehensive data protection framework on Controllers and Processors within the ADGM financial free zone, closely mirroring the EU GDPR. It mandates adherence to core data processing principles (Article 7), establishes lawful bases for processing (Article 8), and grants enforceable rights to data subjects, including rights of access, rectification, and erasure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo",
      "gdpr-article-46-transfer-mechanisms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uae-adgm-fsra-crypto-guidance-2023",
    "title": "ADGM FSRA Guidance on Regulation of Cryptoasset Activities (Updated 2023)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This guidance establishes the Abu Dhabi Global Market (ADGM) Financial Services Regulatory Authority's (FSRA) comprehensive framework for firms conducting crypto asset activities, requiring a Financial Services Permission (FSP) and adherence to stringent rules on technology governance, custody, and market conduct for 'Accepted Virtual Assets' as detailed in the Conduct of Business Rulebook (COBS), Chapter 17.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "fsb-crypto-asset-regulatory-framework-2023",
      "bis-crypto-asset-prudential-standards",
      "eu-mica-casp-obligations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uae-adgm-fsra-financial-services-framework",
    "title": "Abu Dhabi Global Market (ADGM) FSRA Financial Services and Markets Regulations 2015 - Regulated Activity Authorisation, Conduct of Business Rules, Market Abuse Provisions and Recognition of Overseas Financial Institutions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This framework establishes the comprehensive legal and regulatory regime for financial services within the Abu Dhabi Global Market (ADGM), requiring any person carrying on a Regulated Activity by way of business in or from the ADGM to be authorised by the Financial Services Regulatory Authority (FSRA) and to comply with stringent rules on conduct, capital, and market integrity, as mandated by Part 3, Section 10 of the FSMR.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "bcbs-principles-sound-management-operational-risk",
      "bcbs-principles-operational-resilience",
      "fatf-travel-rule-v2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uae-adgm-fsra-financial-services-regulations",
    "title": "UAE ADGM Financial Services Regulatory Authority (FSRA) Rulebook - Market Conduct Rules, Capital Adequacy Requirements, FSRA Digital Assets Framework, Passporting Arrangements, Virtual Asset Brokerage Licence and ADGM Courts Jurisdiction over Financial Disputes",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the licensing, conduct, capital, and governance requirements for financial services firms operating in the Abu Dhabi Global Market (ADGM), including specific obligations for virtual asset activities. It applies to all authorized financial institutions and digital asset businesses under ADGM jurisdiction, with key provisions covering market integrity, prudential standards, and dispute resolution under ADGM Courts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ae-aml-cft-law-2018",
      "accounting-ifr-13",
      "au-apra-prudential-standard-aps-110-adi"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uae-cbuae-aml-cft-standards-2019",
    "title": "Standards for Anti-Money Laundering and Combating the Financing of Terrorism and Illicit Organizations for Licensed Financial Institutions",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard mandates that all Licensed Financial Institutions (LFIs) in the UAE implement a comprehensive, risk-based approach to AML/CFT, including conducting Customer Due Diligence (CDD), applying Enhanced Due Diligence (EDD) for high-risk customers, and reporting suspicious transactions to the UAE's Financial Intelligence Unit (FIU) via the goAML portal, as required by Federal Law No. (20) of 2018.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-virtual-assets-vasp",
      "fatf-travel-rule-v2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uae-cbuae-retail-payment-services-regulation-2021",
    "title": "Retail Payment Services and Card Schemes Regulation 2021",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-03-15",
    "bluf": "This regulation establishes a comprehensive licensing and supervisory framework for retail payment service providers (PSPs) and card schemes operating in the UAE, mandating specific capital, governance, risk management, and consumer protection requirements based on four distinct licensing categories. As per Article 4, all entities providing retail payment services must obtain the appropriate license from the Central Bank of the UAE (CBUAE) before commencing operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "bcbs-principles-sound-management-operational-risk",
      "eu-psd2-strong-customer-authentication",
      "interagency-guidance-third-party-risk-management",
      "pci-dss-v4-req-10-12-monitoring-policy"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uae-dhia-health-data-2026",
    "title": "UAE Federal Decree-Law on Health Data & Dubai Health Authority (DHA) Digital Health Regulations (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The UAE Federal Decree on Health Data and DHA regulations govern the collection, processing, sharing, and protection of health data across the federation. Health data is classified as sensitive, requiring explicit consent, strong security controls, localisation requirements in certain cases, breach notification to the DHA/MOHAP within 72 hours, and interoperability through the Malaffi platform in Dubai.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "uae-difc-data-protection-law-5-2020",
    "title": "Data Protection Law DIFC Law No. 5 of 2020",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This law requires data Controllers and Processors operating within the Dubai International Financial Centre (DIFC) to implement and demonstrate a comprehensive data protection program under the accountability principle (Article 7). It establishes strict requirements for processing sensitive data categories, governs international data transfers, and grants the Commissioner significant enforcement powers, including fines up to USD 100,000.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-46-transfer-mechanisms",
      "ae-pdpl-2021",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uae-entry-residence-law-6-1973-ica",
    "title": "UAE Federal Law No. 6 of 1973 - ICA Entry, Residence and Golden Visa Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The UAE's immigration framework is grounded in Federal Law No. 6 of 1973 concerning entry and residence of foreigners, as significantly amended by Federal Decree-Law No. 29 of 2021. The Federal Authority for Identity, Citizenship, Customs and Port Security (ICA - formerly GDRFA/DNRD) administers all entry and residence matters. Nationals of 64+ countries receive visa-free or visa-on-arrival entry for 30-90 days. The UAE introduced the 10-year Golden Visa in 2019 (expanded 2022) for investors, entrepreneurs, talented individuals, and outstanding students. The 5-year Green Visa was introduced in 2022 for skilled workers and freelancers, allowing self-sponsorship. The Blue Residence Visa (2023) is a permanent residency for exceptional individuals. Overstay fines are AED 50 per day for the first 180 days, then escalating. The UAE operates a unified residence permit system managed through ICA and GDRFA (General Directorate of Residency and Foreigners Affairs) in each Emirate. Labour permits (work permits) are managed by the Ministry of Human Resources and Emiratisation (MOHRE) for non-free zone employers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "mohre_labour_permit",
        "free_zone_employment",
        "gcc_nationals",
        "visa_fee_schedule",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uae-federal-consumer-protection-law-15-2020",
    "title": "UAE Federal Law No. 15 of 2020 on Consumer Protection and its Executive Regulations",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This law requires all suppliers in the UAE to ensure products and services are safe, provide clear and accurate information, and refrain from false or misleading advertising, establishing strict liability for damages caused by defective products. Key obligations are outlined in Article 4 (Consumer Rights), Article 8 (Product Safety), and Article 10 (Misleading Advertising).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ae-pdpl-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uae-federal-law-12-2019-space",
    "title": "Federal Law No. (12) of 2019 on Regulating the Use of Outer Space Activities in the United Arab Emirates",
    "domain": "Space & Satellite Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This law establishes a legal framework for all space activities conducted by UAE entities or from UAE territory, requiring licensing from the UAE Space Agency, mandatory insurance coverage, registration of space objects in the National Register, and compliance with international obligations under the Outer Space Treaty. Key obligations are outlined in Articles 6, 8, 12, and 18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-8374-ransomware-risk-management",
      "iso-15489-1-2016-records-management-workflow"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uae-federal-law-12-2019-space-activities",
    "title": "UAE Federal Law No. 12 of 2019 on the Regulation of the Space Sector",
    "domain": "Space & Satellite Law",
    "version": "Federal Law No. 12 of 2019",
    "last_updated": "2026-05-09",
    "bluf": "UAE Federal Law No. 12 of 2019 on the Regulation of the Space Sector is the United Arab Emirates' primary space law, establishing the UAE Space Agency as the national space regulator, requiring authorisation for all space activities by UAE entities and entities operating from UAE territory, setting liability and insurance requirements per the Liability Convention 1972, governing remote sensing data and orbital debris mitigation, and creating the regulatory framework for the UAE's ambitious national space programme including the Emirates Mars Mission and the Mohammed bin Rashid Space Centre's commercial launch aspirations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "copuos-lts-guidelines-2019-space-sustainability",
      "itu-radio-regulations-article-9-satellite-coord"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uae-food-safety-law-2-2008-emirates",
    "title": "Federal Law No. 2 of 2008 on Food Safety in the United Arab Emirates",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This law establishes the national framework for food safety in the UAE, mandating compliance with halal requirements, food import controls, food contact material safety, country of origin labelling, and recall procedures. It applies to all entities involved in food production, import, distribution, and sale across federal and emirate jurisdictions under oversight of MOIAT and ESMA (Article 4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004",
      "eu-food-labelling-regulation-1169-2011",
      "codex-haccp-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uae-national-ai-strategy-2031",
    "title": "UAE National Artificial Intelligence Strategy 2031",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UAE National AI Strategy 2031 is a government initiative to position the UAE as a global leader in AI by 2031, focusing on integrating AI across key sectors such as healthcare, transport, and education, and targeting 100% AI adoption in government services to improve efficiency and economic growth.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "g20-ai-principles-2019",
      "unesco-ethics-ai"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uae-nesa-iaf-information-assurance-standards",
    "title": "UAE NESA Information Assurance Framework (IAF) - National Electronic Security Authority Standards",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Mandates a tiered classification system (Critical/High/Medium/Low) for information assets and implements 188 security controls across technical, administrative, and physical domains. Applies to all Critical Information Infrastructure (CII) operators in the UAE, requiring annual compliance assessments and reporting to NESA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ae-cybercrime-law-2021",
      "aicpa-soc2-cc-availability",
      "aicpa-soc2-cc-confidentiality",
      "aicpa-soc2-cc-processing-integrity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uae-pdpl-federal-decree-45-2021",
    "title": "UAE Federal Personal Data Protection Law (PDPL) Federal Decree-Law No. 45 of 2021 - Data Subject Rights, Processing Conditions, Cross-Border Transfer Rules, Controller Obligations and UAE Data Office Supervisory Role",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This law establishes the UAE's federal data protection framework, requiring controllers and processors to obtain data subject consent for processing personal data (Article 6), granting subjects specific rights like access and erasure (Articles 13-19), and setting rules for cross-border data transfers (Articles 22-23). It applies to any entity processing the personal data of subjects residing in or located within the UAE, regardless of the entity's location.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "oecd-privacy-guidelines-2013",
      "sa-pdpl-2021",
      "gdpr-article-37-dpo",
      "gdpr-article-46-transfer-mechanisms"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uae-rera-law-7-2007-real-estate-dubai",
    "title": "UAE Law No. 7 of 2007 - Dubai Real Estate Regulatory Authority (RERA) and DLD Framework",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Dubai Law No. 7 of 2007 established the Real Estate Regulatory Authority (RERA) within the Dubai Land Department (DLD) as the regulator of Dubai's real estate market; mandates developer registration, escrow accounts for off-plan sales (Law No. 8 of 2007), compulsory project registration, broker licensing through the Dubai Real Estate Institute (DREI), and owners association management for jointly owned properties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mortgage-credit-directive-2014-17-real-estate"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uae-vara-virtual-assets-regulations-2023",
    "title": "Virtual Assets and Related Activities Regulations 2023",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "This regulation establishes a comprehensive framework requiring any entity performing Virtual Asset (VA) activities in or from the Emirate of Dubai (excluding the DIFC) to obtain a license from the Virtual Assets Regulatory Authority (VARA). As per Part II, Article 11, it mandates adherence to specific rulebooks governing activities such as exchange, custody, and advisory services, imposing strict compliance, risk management, and market conduct standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "fsb-crypto-asset-regulatory-framework-2023",
      "eu-mica-regulation-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "udi-system-medical-devices-2026",
    "title": "Unique Device Identification (UDI) Systems - Global Implementation & Compliance (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The UDI system requires manufacturers to assign a globally unique identifier to each medical device model/version, place it on the label/packaging/device, and submit data to regulatory databases (GUDID, EUDAMED, etc.). It enables traceability, recall efficiency, adverse event reporting, and anti-counterfeiting. Full enforcement applies across FDA, EU MDR/IVDR, TGA, China NMPA, and other jurisdictions with harmonized IMDRF standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "ug-computer-misuse-act-2011",
    "title": "Uganda Computer Misuse Act 2011 (as amended 2022)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Uganda's Computer Misuse Act 2011, enacted May 2011 and amended by the Computer Misuse (Amendment) Act 2022, establishes cybercrime offences including unlawful access, unauthorized interception, data interference, electronic fraud, identity theft, and cyberstalking, designates the National Information Technology Authority Uganda as the relevant cybersecurity coordination authority, and imposes penalties including fines and imprisonment of up to fifteen years for serious offences, with the 2022 amendment adding provisions on offensive online communication and minimum mandatory sentences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ug-computer-misuse-act-2011.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ug-pdpa-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ug-pdpa-2019",
    "title": "Uganda Data Protection and Privacy Act 2019 - PDPO/NITA-U",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Uganda's Data Protection and Privacy Act, 2019 (Act No. 2 of 2019) - assented to by President Yoweri Museveni on 26 February 2019 and published in the Uganda Gazette No. 12 on 19 March 2019, coming into force on 25 May 2019 - is Uganda's primary personal data protection legislation, establishing Uganda as one of the East African states with a comprehensive data protection framework. The Act is implemented through the Data Protection and Privacy Regulations, 2021 (Statutory Instrument No. 39 of 2021), which provide detailed implementing rules. The supervisory authority is the Personal Data Protection Office (PDPO), which operates under the Ministry of ICT and National Guidance and is supported by the National Information Technology Authority Uganda (NITA-U). The PDPO registers data collectors and processors, investigates complaints, and enforces the Act. Key features of Uganda's Data Protection and Privacy Act, 2019: (1) Scope - applies to data collectors, data processors, and data subjects in Uganda; 'data collector' is equivalent to the data controller concept (any person who determines the purpose and means of collecting and processing personal data); (2) Data processing principles - the Act requires compliance with: lawfulness; purpose limitation; proportionality; accuracy; security; openness; data subject participation; and accountability; (3) Sensitive personal data - the Act designates categories requiring heightened protection: data concerning religious or philosophical beliefs; health status; criminal record; sexual orientation; political opinion; race or ethnic origin; and any other category specified by the Minister; (4) Data subject rights - right of access; right to rectification; right to object to processing; right to erasure; right not to be subject to decisions based solely on automated processing; right to complain to the PDPO; (5) Consent - generally required for personal data processing; must be informed, specific, and freely given; explicit consent required for sensitive personal data; (6) Data collector registration - data collectors must apply for registration with the PDPO before collecting or processing personal data; (7) Data Protection Officer - designated for data collectors processing personal data on a large scale or processing sensitive personal data; (8) Breach notification - data collectors must notify the PDPO of data breaches that may affect data subjects' rights; notification must be made within 48 hours of awareness of the breach; data subjects must be notified where the breach may cause substantial harm; (9) Cross-border transfers - personal data may only be transferred to a foreign country with adequate data protection laws; the PDPO may approve transfers to countries without adequate laws subject to safeguards; (10) Penalties - for individuals: a fine not exceeding UGX 2,000,000 (approximately USD 540) or imprisonment not exceeding two years or both; for bodies corporate: a fine not exceeding UGX 5,000,000 (approximately USD 1,350); higher penalties may apply for multiple violations; the Act also provides for data subjects to seek compensation through civil proceedings. Uganda's Constitution guarantees the right to privacy under Article 27, providing the constitutional foundation for the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ug-ppda-act-2003-as-amended-2014-egp-uganda",
    "title": "Uganda Public Procurement and Disposal of Public Assets Act 2003 (PPDA Act) as amended by Act 11 of 2014 and Act 15 of 2021 and e-GP Uganda",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Republic of Uganda Public Procurement and Disposal of Public Assets Act 2003 (PPDA Act, Act No. 1 of 2003) effective 21 February 2003 as substantially amended by the Public Procurement and Disposal of Public Assets (Amendment) Act 2014 (Act 11 of 2014) and the Public Procurement and Disposal of Public Assets (Amendment) Act 2021 (Act 15 of 2021), and supplemented by the Public Procurement and Disposal of Public Assets Regulations 2014 (SI 2014 No. 35) as amended, is the principal Ugandan statute governing procurement of goods, works, and services and disposal of public assets by procuring and disposing entities (PDEs) including ministries, government departments, statutory authorities, local government authorities (Districts, Municipalities, City Councils, Sub-Counties, Town Councils), public-sector universities, public-sector enterprises, and other entities funded wholly or partly from the Consolidated Fund. The PPDA Act 2003 established the Public Procurement and Disposal of Public Assets Authority (PPDA Authority / ppda.go.ug) as the central regulatory authority responsible for procurement regulation, oversight, supplier debarment, and procurement guidance. The Uganda Electronic Government Procurement Portal (egpuganda.go.ug / e-GP) operated by PPDA Authority is the federal e-procurement platform under rollout. The Public Procurement and Disposal of Public Assets Appeals Tribunal handles procurement appeals. Procurement methods established by PPDA Act 2003 sec. 80 to 99 comprise (a) Open Domestic Bidding (the default open public procedure for domestic acquisitions above prescribed thresholds), (b) Open International Bidding (for cross-border acquisitions), (c) Restricted Domestic Bidding (with prequalification), (d) Restricted International Bidding (with prequalification, cross-border), (e) Quotations Procurement (for low-value goods and services), (f) Direct Procurement (sole-source under prescribed exceptions in sec. 84 including emergency, sole supplier for technical reasons, prior failed bidding, additional procurement under existing contract, and prescribed-class exemptions), (g) Micro Procurement (for very-low-value), (h) Request for Proposals (for consulting services), and (i) Framework Contracting. The Auditor-General of Uganda conducts ex-post procurement audit. The Inspectorate of Government (IGG) has investigative jurisdiction over procurement-related corruption. Uganda is a party to the East African Community (EAC) Common Market Protocol, AfCFTA, COMESA, and UNCAC. Uganda is NOT a party to the WTO Government Procurement Agreement (GPA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "ug-pdpa-2019",
      "ug-computer-misuse-act-2011",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uipath-rpa-governance-framework",
    "title": "UiPath RPA Enterprise Governance Framework - Robot Lifecycle Management, Orchestrator Access Controls, Attended vs Unattended Automation and Audit Trail Requirements",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The UiPath RPA Governance Framework dictates strict lifecycle management, role-based access, and operational controls for robotic process automation to ensure compliance, security, and stability in enterprise environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-agricultural-holdings-act-1986",
    "title": "UK Agricultural Holdings Act 1986: Security of Tenure, Notices to Quit, Rent Arbitration, Succession and Tenant Compensation",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Agricultural Holdings Act 1986 is the consolidating statute governing agricultural tenancies in England and Wales that were granted before 1 September 1995 (tenancies granted on or after that date are farm business tenancies under the Agricultural Tenancies Act 1995), administered through the tribunal and arbitration system. Part I provides the framework: section 1 sets out the principal definitions including the meaning of agricultural holding, section 2 restricts the letting of agricultural land for less than a tenancy from year to year, and section 3 provides that a tenancy for two years or more continues from year to year unless terminated by notice. Part III governs notices to quit and is the heart of the security-of-tenure regime: section 25 fixes the length of a notice to quit (generally not less than twelve months), section 26 restricts the operation of a notice to quit by giving the tenant the right to serve a counter-notice requiring the consent of the Agricultural Land Tribunal, and Schedule 3 sets out the Cases (A to H) in which the Tribunal's consent is not required, including grounds relating to bad husbandry, non-payment of rent, breach, death of the tenant and ministerial certificates. Part II includes section 12, providing for arbitration or third-party determination of rent on a rent review. Part IV provides for succession on death or retirement: section 36 confers a right on an eligible person to apply for a new tenancy on the death of the tenant and section 50 a right to apply on the tenant's retirement. Part V governs compensation on termination: section 60 provides the right to and measure of compensation for disturbance and section 64 the tenant's right to compensation for improvements. The Act is the legacy security-of-tenure code that still protects long-standing farm tenants and their successors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-agricultural-marketing-act-1958",
    "title": "UK Agricultural Marketing Act 1958 (c.47): Marketing Schemes and Producer Boards",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agricultural Marketing Act 1958 (c. 47) consolidates the law providing for the organised marketing of agricultural products through producer-controlled marketing schemes and boards, administered by the agriculture Ministers. Section 1 provides for the submission of schemes for regulating the marketing of an agricultural product by persons engaged in producing it, and section 2 provides for the approval of schemes following a poll of registered producers. Section 3 provides for the constitution of boards to administer schemes and the appointment of executive committees, the board being the body that operates the scheme on behalf of producers. Section 6 provides for the regulation of sales of regulated products, under which a scheme may require that the product be sold only through or with the consent of the board. Section 9 sets out the disciplinary provisions of schemes, allowing the board to impose penalties on registered producers who contravene the scheme, and section 10 provides that losses sustained by boards are recoverable in the same way as penalties. Section 14 confers on boards the power to make loans and grants and to enter into guarantees. Section 44 provides for the regulation of sales of home-produced agricultural products, and section 48 addresses offences committed by bodies corporate. The Act is the foundational producer marketing scheme and board regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-agricultural-tenancies-act-1995",
    "title": "UK Agricultural Tenancies Act 1995: Farm Business Tenancies, Notice to Quit, Rent Review and Tenant Compensation",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Agricultural Tenancies Act 1995 governs farm business tenancies in England and Wales, the regime that replaced the Agricultural Holdings Act 1986 security-of-tenure model for tenancies granted on or after 1 September 1995. Part I defines the tenancy: section 1 sets out the meaning of a farm business tenancy by reference to the business condition (the land is farmed for the purposes of a trade or business), the agriculture condition (the character of the tenancy is primarily or wholly agricultural), and the notice conditions; section 2 lists tenancies which cannot be farm business tenancies; and section 4 provides that the Agricultural Holdings Act 1986 does not apply to new tenancies except in special cases. Termination is governed by sections 5 to 8: section 5 provides that a tenancy for more than two years continues from year to year unless terminated by notice, section 6 fixes the length of a notice to quit (not less than twelve months nor more than twenty-four months), and section 8 preserves the tenant's right to remove fixtures and buildings. Part II governs rent review: section 10 sets the procedure for a notice requiring a statutory rent review and section 13 governs the amount of rent determined on review. Part III governs compensation on termination: section 15 defines a tenant's improvement, section 16 confers the right to compensation for a tenant's improvement, section 17 makes the landlord's consent a condition of compensation, and section 20 governs the amount. Part IV provides for resolution of disputes, with section 28 directing disputes to arbitration and section 30 setting general arbitration provisions. The Act is the legal framework that liberalised agricultural letting in England and Wales while preserving rent-review and tenant-improvement compensation through arbitration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-agriculture-act-1970",
    "title": "UK Agriculture Act 1970 (c.40) Part IV: Fertilisers and Feeding Stuffs",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "Part IV of the Agriculture Act 1970 (c. 40, sections 66 to 87) regulates the sale of fertilisers and feeding stuffs in Great Britain to protect purchasers, principally farmers, against misdescription and harmful content, administered by the Department for Environment, Food and Rural Affairs and enforced by local authorities through agricultural analysts. Section 68 imposes the duty of a seller to give a statutory statement, requiring that the sale of a material to be used as a fertiliser or feeding stuff be accompanied by a statement of prescribed particulars such as composition. Section 72 implies a warranty of the fitness of a feeding stuff for the purpose for which it is sold, and section 73 prohibits deleterious ingredients in feeding stuff, making it an offence to sell feeding stuff containing an ingredient that is deleterious to the animals to which it is to be given. Section 77 provides for the division of samples and analysis by an agricultural analyst, and section 78 provides for further analysis by the Government Chemist where a result is disputed. Section 80 governs the institution of prosecutions, section 81 provides that where an offence is due to the fault of another person that other person may be charged, and section 82 provides a defence of mistake, accident, or other reasonable cause. The Part is the foundational regime governing the quality and labelling of fertilisers and animal feed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-agriculture-act-1970-fertilisers-feeding-stuffs",
    "title": "UK Agriculture Act 1970 (Part IV, Fertilisers and Feeding Stuffs): Statutory Statement, Composition Controls, Sampling and Analysis",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Part IV of the Agriculture Act 1970 regulates the sale of fertilisers and feeding stuffs in Great Britain, protecting purchasers by requiring sellers to declare composition and by providing a system of independent sampling and analysis, administered by the agriculture departments and local-authority trading-standards services with analysis by the agricultural analyst. Section 66 sets the interpretation of Part IV. Section 68 imposes the central duty of the seller to give a statutory statement specifying prescribed particulars of the fertiliser or feeding stuff sold, and section 69 governs the marking of material prepared for sale. Section 70 controls the use of names or expressions with prescribed meanings. Section 74 sets the limits of variation, the tolerances within which the actual composition may differ from the statutory statement before an offence arises. The enforcement architecture turns on independent analysis: section 75 gives the purchaser the right to have a sample taken and analysed, section 76 gives an inspector the power to enter premises and take samples, and section 77 governs the division of samples and analysis by the agricultural analyst. The prosecution and defence provisions follow: section 80 governs the institution of prosecutions, section 81 deals with offences due to the fault of another person, and section 82 provides the defence of mistake, accident or other cause beyond the defendant's control. Section 84 confers the regulation-making power that fleshes out the prescribed particulars and limits. The Part is the legal basis on which the composition of fertilisers and animal feed sold in Great Britain is declared, sampled and held to a court-defensible standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-agriculture-act-1986",
    "title": "UK Agriculture Act 1986 (c. 49): Environmentally Sensitive Areas, Conservation Duty and Milk Quota Compensation",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agriculture Act 1986 (c. 49) is a United Kingdom statute notable for introducing the first statutory agri-environment scheme and a conservation duty into agricultural policy, administered by the responsible Minister and the Secretary of State. Its agricultural services provisions allow the provision of services and goods connected with agriculture and the countryside, and its fees and charges provisions cover seeds regulations and Plant Health Act 1967 fees. Its agricultural marketing provisions deal with the Home-Grown Cereals Authority, levies under the Cereals Marketing Act 1965, the Meat and Livestock Commission, Food from Britain, and the abolition of the Eggs Authority. The Act's milk quota provisions give outgoing agricultural tenants a right to compensation for milk quota on the termination of a tenancy and provide for the resolution of milk quota questions in rent arbitrations, with detailed rules in the Schedules. Its conservation provisions impose on the Minister a duty, in discharging functions relating to agriculture, to have regard to and balance the promotion of a stable and efficient agriculture industry, the economic and social interests of rural areas, the conservation of the natural beauty and amenity of the countryside, and the promotion of public enjoyment of the countryside, and they empower the designation of environmentally sensitive areas in which payments support environmentally beneficial farming. The Act is a foundational statute in United Kingdom agri-environment law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-agriculture-act-1993",
    "title": "UK Agriculture Act 1993 (c. 37): Reorganisation of the Milk and Potato Marketing Schemes",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agriculture Act 1993 (c. 37) reorganised the statutory agricultural marketing schemes of the United Kingdom, most significantly bringing about the end of the milk marketing schemes and the Milk Marketing Boards, and is administered by the responsible Ministers and the Secretary of State. Part 1 provides for the ending of the milk marketing schemes, for schemes of reorganisation under which the functions and assets of a milk marketing board could be transferred to successor bodies, for the carrying out of approved reorganisation schemes, and for the position of the milk marketing boards following revocation, replacing compulsory pooled marketing with a liberalised market. Part 2 provides, when activated, for the ending of the Potato Marketing Scheme and for a transfer scheme dealing with the assets and liabilities of the Potato Marketing Board and the position of the Board following revocation. Part 3 authorises grants for marketing and makes it an offence to make false statements to obtain such payments. Part 4 contains miscellaneous and supplementary provisions, including the termination of national price support arrangements and provisions affecting the wool and potato sectors. The Act is a landmark in the deregulation and liberalisation of United Kingdom agricultural marketing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-agriculture-act-2020",
    "title": "UK Agriculture Act 2020 - Environmental Land Management, Agricultural Transition, and Supply Chain Fair Dealing",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Agriculture Act 2020 establishes the post-Brexit framework for agricultural support and regulation in England, replacing EU Common Agricultural Policy (CAP) direct payments with a new system of public money for public goods. Section 1 authorises the Secretary of State to give financial assistance to persons engaged in or connected with agriculture, forestry, or the management of land or water for purposes listed in Schedule 1, including improving soil health, protecting water quality, managing floods, preserving biodiversity, and reducing greenhouse gas emissions. The Act introduces an agricultural transition period of approximately seven years during which direct area-based payments are phased down progressively. Section 13 empowers the Secretary of State to impose fair dealing obligations on purchasers of agricultural products to protect farmers and growers in supply chain negotiations. Section 27 provides powers to maintain and enforce marketing standards for agricultural products after the UK's withdrawal from EU marketing standard requirements. The Environmental Land Management (ELM) scheme implements Section 1 public goods payments through Sustainable Farming Incentive, Countryside Stewardship, and Landscape Recovery tiers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_common_agricultural_policy_2021",
        "eu_food_information_consumers_regulation_1169_2011",
        "nz_primary_industry_acts",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-services-directive-2006-123",
      "eu-late-payment-directive-2011-7"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-agriculture-act-2020-section-1-financial-assistance-powers",
    "title": "UK Agriculture Act 2020 Section 1 - Secretary of State's Powers to Give Financial Assistance",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "The Secretary of State may give financial assistance for or in connection with ten public-good purposes including environmental protection, public access to and enjoyment of the countryside, cultural/natural heritage management, climate change adaptation, hazard protection, animal welfare, plant and animal health, conservation of native livestock and plants, and soil quality improvement. Assistance may also be given for productivity, starting agricultural businesses, and ancillary activities. The power is restricted to England. Schemes must have regard to encouraging food production in an environmentally sustainable way.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ten_public_good_purposes_subsection_1",
        "productivity_and_ancillary_assistance_subsection_2",
        "england_only_geographical_scope",
        "food_production_environmental_sustainability_duty",
        "definitions_subsection_5",
        "financial_assistance_scheme_definition_subsection_6",
        "underpinning_sustainable_farming_incentive_and_elm_schemes"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-animal-welfare-act-2006-section-9-duty-person-responsible-ensure-welfare",
      "uk-plant-health-act-1967-section-2-control-introduction-pests"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-agriculture-horticulture-act-1964",
    "title": "UK Agriculture and Horticulture Act 1964 (c.28): Grading and Marking of Produce",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agriculture and Horticulture Act 1964 (c. 28) provides for the grading and marking of agricultural and horticultural produce and for the stability of prices of certain imported products, administered by the Department for Environment, Food and Rural Affairs. Part I, section 1, provides for the price stability of imported products through arrangements affecting imports of relevant agricultural products. Part III governs grading: section 11 confers power to prescribe grades and grade designations for produce, section 12 imposes duties as to the grading of produce, requiring that produce sold by reference to a prescribed grade designation conform to that grade, and section 13 confers powers as to entry of premises and the regrading of produce. Section 14 creates offences in connection with grading, including applying a grade designation to produce that does not conform, and section 15 makes obstruction of an authorised officer an offence. Section 16 provides a penalty for an act or default leading to the commission of an offence by another, section 19 addresses offences by corporations, and section 20 sets the punishment of offences. Section 21 confers power to require the use of prescribed containers and markings. The Act is a foundational produce grading, marking, and quality regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-agriculture-wales-act-2023",
    "title": "UK Agriculture (Wales) Act 2023 (asc 4): Sustainable Land Management and Support",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agriculture (Wales) Act 2023 (asc 4) is the post-Brexit framework for agricultural policy in Wales, made by Senedd Cymru and administered by the Welsh Ministers, establishing sustainable land management as the organising principle for support after the Common Agricultural Policy. Section 1 sets out the sustainable land management objectives, which include producing food and other goods in a sustainable manner, mitigating and adapting to climate change, maintaining and enhancing resilient ecosystems, and conserving and enhancing the countryside and cultural resources. Section 2 imposes a duty on the Welsh Ministers to exercise their functions under the Act in a way they consider best contributes to achieving the objectives, and section 4 provides for sustainable land management indicators and targets. Section 8 confers on the Welsh Ministers the power to provide support to persons carrying on agricultural and related activities, section 9 makes further provision about that support, and section 11 requires multi-annual support plans. Section 16 confers power to modify the legislation governing the basic payment scheme and section 17 confers power to modify legislation relating to the common agricultural policy, enabling the transition away from area-based payments. Section 21 provides for a declaration relating to exceptional market conditions and section 22 sets out the powers available to the Welsh Ministers to intervene in exceptional market conditions. The Act is the foundational Welsh agricultural support and sustainable land management regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-ai-automation-regulation-ofcom-code-2023",
    "title": "Online Safety Act 2023, Section 19: Duties to protect journalistic content",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Category 1 services must implement and detail in their terms of service proportionate systems, processes, and dedicated complaints procedures to ensure the free expression of journalistic content is considered before any restrictive action is taken.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-ai-cyber-security-code-of-practice-2025-dsit",
    "title": "UK Code of Practice for the Cyber Security of AI (DSIT, 2025) - 13 Voluntary Principles for AI Lifecycle Cyber Security across Secure Design, Development, Deployment, Maintenance, and End of Life",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "The UK Code of Practice for the Cyber Security of AI was published by the Department for Science, Innovation and Technology (DSIT) in 2025 as a voluntary code setting baseline security requirements for AI systems through the lifecycle of design, development, deployment, maintenance, and end of life. The Code applies to four stakeholder roles: Developers (organisations that create AI models), System Operators (organisations that operate AI systems for downstream use), Data Custodians (organisations that hold or manage training, fine-tuning, evaluation, or operational data), and End-users / Affected Entities (the parties impacted by AI system operation). The Code is structured into 13 principles across five lifecycle phases. Secure Design (Principles 1-4): Principle 1 - Raise awareness of AI security threats and risks, requiring cyber security training programmes that include AI security content reviewed and updated as new substantial AI-related security threats emerge, with role-tailored training for staff and secure-coding training for developers; Principle 2 - Design your AI system for security as well as functionality and performance; Principle 3 - Evaluate the threats and manage the risks to your AI system; Principle 4 - Enable human responsibility for AI systems. Secure Development (Principles 5-9): Principle 5 - Identify, track and protect your assets; Principle 6 - Secure your infrastructure; Principle 7 - Secure your supply chain; Principle 8 - Document your data, models and prompts; Principle 9 - Conduct appropriate testing and evaluation. Secure Deployment, Maintenance and End of Life (Principles 10-13): Principle 10 - Communication and processes associated with End-users and Affected Entities; Principle 11 - Maintain regular security updates, patches and mitigations; Principle 12 - Monitor your system's behaviour; Principle 13 - Ensure proper data and model disposal. Each principle includes specific shall and should obligations for the relevant stakeholder roles, and is mapped to international AI security guidance including NIST AI RMF (2023), CISA Secure-by-Design (2023), the joint US/UK Guidelines for Secure AI System Development (NCSC/CISA 2023), OWASP, MITRE ATLAS, the World Economic Forum AI security framework (2024), and ENISA AI security guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "stakeholder_roles_anchor",
        "secure_design_principles_anchor",
        "secure_development_principles_anchor",
        "secure_deployment_principles_anchor",
        "international_alignment_anchor",
        "voluntary_nature_anchor",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-ai-safety-institute-framework-2024",
      "uk-data-protection-ai-code-of-practice-2026-si-425",
      "nist-ai-rmf-1-0",
      "uk-ai-opportunities-action-plan-2025",
      "cisa-secure-by-design-guidance-2024"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "uk-ai-opportunities-action-plan-2025",
    "title": "UK AI Opportunities Action Plan 2025 - Matt Clifford Review and Government Response",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The UK AI Opportunities Action Plan was published on January 13, 2025 by the Department for Science, Innovation and Technology (DSIT) following an independent review commissioned from Matt Clifford (co-founder of Entrepreneur First and ARIA chair); the Plan sets out the UK government's strategy for AI adoption and positions the UK as a global hub for AI development; the independent review delivered 50 recommendations accepted in full by the government; key government commitments include: (1) National AI Energy Strategy - addressing compute and energy infrastructure constraints for AI data centres; (2) AI Growth Zones - designated areas with streamlined planning consent for AI data centres and compute infrastructure; (3) National Data Library - creating centralised access to public sector data assets for AI training and research; (4) Public sector AI adoption - mandating deployment of AI across public services to deliver efficiency savings and service improvements; (5) AI Safety Institute continuation - the UK AI Safety Institute (AISI) to continue frontier model safety evaluation and international collaboration; (6) Compute access - expanding UK sovereign AI compute capacity through public investment and UKRI; (7) Skills and talent - attracting global AI talent through visa policy and supporting AI skills development; the Plan is a non-regulatory framework (not legislation) - it sets government investment and policy direction rather than imposing legal compliance obligations; it complements the UK's sector-based AI regulation approach under the 2023 Pro-Innovation AI White Paper, which tasks existing regulators (FCA, CMA, ICO, MHRA, Ofcom) with applying proportionate AI oversight within their existing mandates; organisations seeking to benefit from AI Growth Zone planning benefits or National Data Library access must engage with DSIT's implementation process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/uk-ai-opportunities-action-plan-2025.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-pro-innovation-ai-white-paper-2023",
      "uk-ai-safety-institute-framework-2023",
      "bletchley-declaration-ai-safety-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-ai-safety-institute-framework-2023",
    "title": "AI Safety Institute: approach to evaluations",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2023-11-02",
    "bluf": "The UK AI Safety Institute (AISI) framework outlines its approach to evaluating advanced AI models for national security and societal risks, focusing on five capabilities: misuse, societal impacts, autonomous systems, safeguards, and model analysis. This framework applies to developers of frontier AI models engaging with the AISI for pre-deployment safety testing, as detailed in the 'Our approach to evaluations' section.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "oecd-ai-principles",
      "nist-ai-adversarial-machine-learning",
      "eu-ai-act-high-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-ai-safety-institute-framework-2024",
    "title": "UK AI Safety Institute (AISI) Framework 2024 - Frontier AI Evaluation Methodology, Pre-Deployment Testing Protocol, International Network of AI Safety Institutes, Alignment with Bletchley Declaration, Uplift Testing for Cyber/CBRN Capabilities and Government Model Access",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This framework outlines the UK AI Safety Institute's approach to evaluating frontier AI models, including pre-deployment testing, systemic risk assessments, and international collaboration to prevent AI-induced surprise. It applies to developers of advanced AI systems engaging with the AISI, particularly those developing models with potential dual-use or systemic risk implications as referenced in the Bletchley Declaration and AISI guidance documents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-ai-safety-2023",
      "anthropic-responsible-scaling-policy-v2-1-2025"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-ai-safety-institute-frontier-ai-safety-commitments-responsible-capability-scaling",
    "title": "UK DSIT AI Safety Institute - Frontier AI Safety Commitments and Responsible Capability Scaling",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "The UK Department for Science, Innovation and Technology (DSIT) established the AI Safety Institute (AISI, now renamed AI Security Institute) and facilitated voluntary Frontier AI Safety Commitments signed at the Bletchley AI Safety Summit (November 2023) by major AI developers including Anthropic, Google, Meta, Microsoft, and OpenAI. Commitments include: sharing safety information with governments before release, investing in safety research, developing transparency measures, and facilitating government access to AI systems for safety testing. The Bletchley Declaration set the international governance context.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system-high-risk-ai"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-aisi-ai-safety-evaluation-framework-2024",
    "title": "UK AI Safety Institute (AISI) AI Safety Evaluation Framework 2024 - Frontier Model Evaluations, Pre-Deployment Testing and Uplift Assessment",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This framework outlines the UK AI Safety Institute's methodology for evaluating the safety of advanced AI models, focusing on pre-deployment testing across five key risk areas: Misuse, Societal Impacts, Autonomous Systems, Safeguard Efficacy, and Core Knowledge. It applies to developers of frontier AI models who voluntarily submit their models for evaluation, as detailed in the 'AISI Approach to Evaluations' publication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-ai-safety-institute-framework-2023",
      "nist-ai-rmf-1-0",
      "iso-23894-ai-risk-management",
      "g7-hiroshima-ai-process-2023",
      "us-eo-14110-ai-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-animal-health-act-1981",
    "title": "UK Animal Health Act 1981: Disease Control Orders, Slaughter, Movement Restrictions and Compensation",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Animal Health Act 1981 is the principal United Kingdom statute for the prevention and control of animal disease, conferring on the Ministers (now the Secretary of State and the devolved administrations) broad order-making powers and the operational tools used to contain outbreaks such as foot-and-mouth disease, bovine tuberculosis and avian influenza. Section 1, in Part I, confers general powers on the Ministers to make orders for the purposes of the Act, including preventing the spread of disease, and is the legal basis for the detailed disease-control orders that operate day to day. Part I and Part II contain the operational controls: section 25 enables the making of orders restricting the movement of diseased or suspected animals, and the slaughter regime is set out in section 31 (slaughter in the case of certain diseases), section 32 (slaughter in the case of other diseases) and section 34 (slaughter and compensation generally), under which animals may be compulsorily slaughtered to control disease with compensation payable to owners. Part III deals with welfare in transit and export, and Part IV with the role of local authorities in enforcement. Part V sets out enforcement, offences and proceedings: section 72 and section 73 create the offences under and against the Act, and section 75 fixes the penalties for certain summary offences. The Act is the framework within which DEFRA, the Animal and Plant Health Agency and local authorities declare infected areas, impose movement standstills, order culls and pay compensation, and it underpins the United Kingdom's notifiable-disease response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-animal-welfare-act-2006",
    "title": "UK Animal Welfare Act 2006: Duty of Care, Unnecessary Suffering and the Five Welfare Needs",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Animal Welfare Act 2006 (c. 45) is the principal statute protecting vertebrate animals in England and Wales, enforced by local authorities, the police and (in practice) bodies such as the RSPCA, under the policy responsibility of DEFRA. It applies to 'protected animals' - vertebrates of a kind commonly domesticated in the British Islands, under the control of man, or not living in a wild state (section 2) - and imposes duties on any person 'responsible for' an animal (section 3). The central cruelty offence is causing unnecessary suffering to a protected animal where the person knew or ought reasonably to have known the act or omission would have that effect (section 4); related offences prohibit mutilation (section 5), the docking of dogs' tails (section 6), the administration of poisons (section 7) and involvement in animal fighting (section 8). Section 9 imposes a positive duty to ensure welfare: a responsible person must take reasonable steps to meet the animal's needs, which section 9(2) lists as the need for a suitable environment; a suitable diet; the ability to exhibit normal behaviour patterns; any need to be housed with, or apart from, other animals; and the need to be protected from pain, suffering, injury and disease. Enforcement tools include improvement notices (section 10), restrictions on transferring animals to persons under 16 and on giving animals as prizes (section 11), powers to make welfare regulations (section 12), licensing or registration of activities (section 13), codes of practice (section 14), and powers in relation to animals in distress (section 18), supported by inspection and entry powers (sections 23-30). Following amendment by the Animal Welfare (Sentencing) Act 2021, offences under sections 4, 5, 6(1), 6(2), 7 and 8 are punishable on summary conviction by imprisonment for a term not exceeding the general limit in a magistrates' court or a fine, and on conviction on indictment by imprisonment for up to five years or a fine (section 32). Courts may also make deprivation orders (section 33) and disqualification orders (section 34).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-animal-welfare-act-2006-section-4-unnecessary-suffering",
    "title": "UK Animal Welfare Act 2006 Section 4 - Unnecessary Suffering",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person commits an offence under Section 4 if an act or failure to act causes a protected animal to suffer, the person knew or ought reasonably to have known the act would cause suffering, and the suffering is unnecessary. A separate offence applies where the suffering is caused by another and the responsible person permitted it or failed to take reasonable preventive steps. Courts assess necessity by reference to avoidability, lawful compliance, legitimate purpose, proportionality, and the standard of a reasonably competent and humane person. Humane destruction is excluded from the offence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "direct_causation_offence",
        "responsible_person_omission_offence",
        "five_factor_necessity_test",
        "service_animal_carve_out_sections_3a_3c",
        "humane_destruction_exclusion",
        "protected_animal_definition_section_2",
        "penalties_under_section_32",
        "additional_remedies_under_section_33_to_36"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-animal-welfare-act-2006-section-9-duty-person-responsible-ensure-welfare"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-animal-welfare-act-2006-section-8-fighting",
    "title": "UK Animal Welfare Act 2006 Section 8 - Animal Fighting Offences",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 8 creates nine related offences targeting the animal fighting trade: causing or attempting to cause a fight, receiving admission money, publicising, providing information to enable attendance, betting on the outcome, taking part, possessing fight-related articles, keeping or training animals for fighting, and keeping premises for fights. Mere presence at an animal fight is an offence absent lawful authority or reasonable excuse. Distribution, supply, publication, showing, or possession with intent to supply of video recordings of animal fights is also an offence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nine_principal_offences_subsection_1",
        "presence_at_fight_strict_offence",
        "video_recording_offences_subsection_3",
        "definition_of_animal_fight_subsection_7",
        "carve_outs_for_lawful_recordings_subsection_4_8",
        "penalties_under_section_32_amended_2021",
        "ancillary_orders_under_sections_33_to_42"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-animal-welfare-act-2006-section-4-unnecessary-suffering"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-animal-welfare-act-2006-section-9-duty-person-responsible-ensure-welfare",
    "title": "UK Animal Welfare Act 2006 Section 9 - Duty of Person Responsible for Animal to Ensure Welfare",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person commits an offence under Section 9 if they do not take such steps as are reasonable in all the circumstances to ensure that the needs of an animal for which they are responsible are met to the extent required by good practice. The five statutory welfare needs are a suitable environment, a suitable diet, the ability to exhibit normal behaviour patterns, appropriate housing with or apart from other animals, and protection from pain, suffering, injury, and disease. Relevant circumstances include any lawful purpose for which the animal is kept and any lawful activity undertaken in relation to it. Humane destruction is excluded.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_positive_welfare_duty",
        "five_statutory_welfare_needs_subsection_2",
        "lawful_purpose_and_activity_context_subsection_3",
        "humane_destruction_exclusion_subsection_4",
        "responsible_person_definition_section_3",
        "codes_of_practice_section_14_15",
        "penalties_under_section_32_amended_2021",
        "improvement_notices_section_10"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-animal-welfare-act-2006-section-4-unnecessary-suffering"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-animal-welfare-sentience-act-2022",
    "title": "UK Animal Welfare (Sentience) Act 2022 (c. 22): Animal Sentience Committee and Policy Scrutiny",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Animal Welfare (Sentience) Act 2022 (c. 22) recognises animals as sentient beings in United Kingdom law and creates a mechanism for scrutinising the effect of government policy on animal welfare, administered by the Secretary of State for Environment, Food and Rural Affairs. Section 1 requires the Secretary of State to establish and maintain an Animal Sentience Committee. Section 2 empowers the Committee to produce a report where it appears that the government is or has been formulating or implementing any policy, and the report sets out the Committee's view on whether, or to what extent, the government is having, or has had, all due regard to the ways in which the policy might have an adverse effect on the welfare of animals as sentient beings. Section 3 requires the Secretary of State to lay before Parliament a response to any such report. Section 4 enables the provision of information to support the Committee's functions, and section 5 defines the animals to which the Act applies, namely any vertebrate other than a human being, any cephalopod mollusc, and any decapod crustacean. Section 6 governs extent, commencement, and the short title. The Act does not confer a power to block policy but creates a transparency and accountability duty centred on animal sentience.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-animals-scientific-procedures-act-1986",
    "title": "UK Animals (Scientific Procedures) Act 1986 (c.14): Licensing of Animal Research",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Animals (Scientific Procedures) Act 1986 (c. 14) regulates the use of protected animals in scientific procedures in the United Kingdom through a three-licence system, administered by the Secretary of State for the Home Department through the Animals in Science Regulation Unit. Section 1 defines protected animals as living vertebrates other than man and certain cephalopods, and section 2 defines a regulated procedure as one carried out on a protected animal that may cause it pain, suffering, distress, or lasting harm. Section 3 prohibits the carrying out of a regulated procedure unless it is authorised by a personal licence held by the person carrying it out, a project licence authorising the programme of work, and an establishment licence for the place where it is carried out. Section 4 governs personal licences, section 5 governs project licences, which require the Secretary of State to weigh the likely adverse effects on the animals against the benefit likely to accrue, and sections 2C and 6 govern the licensing of undertakings and scientific procedure establishments. Section 7 governs breeding and supplying establishments. Section 22 sets the penalties for contraventions, providing that a person who carries out a regulated procedure without the requisite licences commits an offence, and section 23 creates the offence of making a false statement to obtain a licence. The Act gives domestic effect to the principles of replacement, reduction, and refinement of animal use in research.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-apprenticeships-skills-children-learning-act-2009",
    "title": "United Kingdom Apprenticeships, Skills, Children and Learning Act 2009: Apprenticeships and Technical Education for England, Apprenticeships (Wales), Local Authority Functions, Young People's Learning Agency, Ofqual, and Ofsted",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The United Kingdom Apprenticeships, Skills, Children and Learning Act 2009, chapter 22 of 2009, is a principal United Kingdom statute on apprenticeships, post-16 education and training, qualifications regulation, and children's services in England and Wales, and is administered by the Department for Education through Ofqual, Ofsted, and other named bodies. Apprenticeships, Skills, Children and Learning Act 2009, Part 1 contains the apprenticeship framework, divided into chapters: Chapter ZA1 establishes the Institute for Apprenticeships and Technical Education; Chapter A1 governs apprenticeships and technical education for England; Chapter 1 governs apprenticeships in Wales and study and training provisions. Apprenticeships, Skills, Children and Learning Act 2009, section 40 governs employer support for employee study and training. Apprenticeships, Skills, Children and Learning Act 2009, Part 2 governs local authority functions including education and training for persons over compulsory school age, skills provision and work experience. Apprenticeships, Skills, Children and Learning Act 2009, Part 3 establishes the Young People's Learning Agency for England as the funding mechanism for education and training for young people. Apprenticeships, Skills, Children and Learning Act 2009, Part 4 contains provisions for Secretary of State functions regarding apprenticeships and adult learning aims. Apprenticeships, Skills, Children and Learning Act 2009, Part 7 establishes the Office of Qualifications and Examinations Regulation (Ofqual) and governs qualifications regulation and assessment arrangements. Apprenticeships, Skills, Children and Learning Act 2009, Part 9 governs children's services including cooperation arrangements, safeguarding, and children's centres. The Act is the controlling United Kingdom instrument for apprenticeships, post-16 skills, qualifications regulation, and the children's services framework. It has been substantially amended by the Deregulation Act 2015 and the Skills and Post-16 Education Act 2022.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-arbitration-act-2025-c-4",
    "title": "UK Arbitration Act 2025 - Modernisation of Arbitration Act 1996 Including Governing Law Default and Summary Disposal Powers, Royal Assent 24 February 2025",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "Parties to UK-seated arbitrations, arbitral institutions, arbitrators, and counsel must, from the staggered commencement of the Arbitration Act 2025 (Royal Assent 24 February 2025), apply the amendments to the Arbitration Act 1996 including the new governing law default under section 6A inserted by section 1 (governing law of the arbitration agreement is the law of the seat unless the parties expressly agree otherwise), the new summary disposal power under section 39A inserted by section 7 (arbitrators may issue an award on a summary basis where a party has no real prospect of success), the modified emergency arbitrator provisions under section 41A inserted by section 8, the modernised arbitrator duty of disclosure under section 23A inserted by section 2, the revisions to section 67 challenges (jurisdiction) preventing re-hearings, and the codification of arbitrators' immunity, with the Act applying to arbitrations commenced after the commencement date.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-arbitration-2006"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-asa-cap-code-2010",
    "title": "The UK Code of Non-broadcast Advertising and Direct & Promotional Marketing",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The CAP Code requires all UK non-broadcast marketing communications to be legal, decent, honest, and truthful, ensuring they are prepared with a sense of responsibility to consumers and society. This applies to all advertisers, agencies, and media, with Rule 1.3 establishing the primary responsibility for compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-art-21-marketing-optout",
      "eprivacy-cookie-directive",
      "ftc-endorsement-guides",
      "eu-consumer-rights-directive-2011"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-asa-influencer-marketing-guide-2023",
    "title": "UK ASA Influencer Marketing Guide (Third Edition, March 2023)",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The UK Advertising Standards Authority (ASA) and Committee of Advertising Practice (CAP) Influencer Marketing Guide (Third Edition, March 2023) applies the CAP Code to influencer marketing content on social media and other digital platforms in the United Kingdom. The Guide requires that marketing communications be obviously identifiable as such (CAP Code rule 2.1), that their commercial intent be made clear (rule 2.3) and that they not falsely claim or imply that the marketer is acting as a consumer (rule 2.4). Material disclosure is triggered whenever there is any material connection between the influencer and the brand, including monetary payments, free products or services, affiliate links and commissions, family or employment relationships, or any brand control over content. The Guide identifies recommended prominent labels such as #ad, Ad, Advert and Paid Partnership, and treats vague or buried disclosures (including #ambassador without context, or disclosures hidden at the end of a long hashtag chain) as inadequate. Section 3 of the CAP Code on misleading advertising applies in parallel where claims about products or services are made. The Guide is being aligned with the Digital Markets, Competition and Consumers Act 2024 enforcement by the CMA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-endorsement-guides-2023",
      "uk-dmcc-act-2024-digital-markets-regime"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-asylum-and-immigration-treatment-of-claimants-act-2004",
    "title": "UK Asylum and Immigration (Treatment of Claimants, etc.) Act 2004: Trafficking and Document Offences, Claimant Credibility and Safe-Country Removal",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Asylum and Immigration (Treatment of Claimants, etc.) Act 2004 strengthened United Kingdom criminal offences connected with immigration, reshaped the treatment of asylum claimants and consolidated the appeal system, administered by the Home Office and the immigration tribunal. The offence provisions are prominent: section 1 deals with assisting unlawful immigration, section 2 creates the offence of entering the United Kingdom without a passport or other document establishing identity and nationality (subject to a reasonable-excuse defence), and section 4 creates the offence of trafficking people for exploitation. Section 8 addresses the credibility of an asylum or human-rights claimant, requiring the deciding authority to take account, as damaging the claimant's credibility, of specified behaviour such as the destruction of documents or failure to claim in a safe third country. Section 26 provides for the unification of the appeal system, the reform that replaced the two-tier adjudicator and tribunal structure with a single Asylum and Immigration Tribunal. Section 33 provides for removing an asylum seeker to a safe country and gives effect to Schedule 3, which lists categories of safe third countries to which a claimant may be removed and restricts challenges to such removals. Section 36 provides for electronic monitoring of persons subject to immigration control. The Act is the instrument that created the no-document offence and the people-trafficking-for-exploitation offence, codified the statutory credibility factors and built the safe-country removal scheme in Schedule 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-automated-electric-vehicles-act-2018",
    "title": "Automated and Electric Vehicles Act 2018",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The UK Automated and Electric Vehicles Act 2018 establishes a liability framework for automated vehicle accidents, requiring insurers to cover incidents involving automated driving systems (Section 2), mandates the creation of a register of automated vehicles (Section 5), and grants powers to ensure adequate electric vehicle charging infrastructure (Section 12). It applies to insurers, vehicle manufacturers, and infrastructure providers operating in Great Britain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-recommendation-insurance-good-practices-2004",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-automated-vehicles-act-2024",
    "title": "Automated Vehicles Act 2024",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "This Act establishes a regulatory framework for automated vehicles in Great Britain, creating the 'Authorised Self-Driving Entity' (ASDE) which is legally liable for a vehicle's actions when its self-driving features are engaged (Part 2, Section 19). The ASDE must maintain a robust safety case, monitor vehicle performance and safety-related data, and report specified incidents to the Secretary of State (Part 1, Section 10).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-23894-ai-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-bank-resolution-recapitalisation-act-2025",
    "title": "Bank Resolution (Recapitalisation) Act 2025 (c. 15), Sections 1-2 Recapitalisation Payments and Reporting under the Special Resolution Regime",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "The Bank Resolution (Recapitalisation) Act 2025 amends Part 15 of the Financial Services and Markets Act 2000 to let the Bank of England require the Financial Services Compensation Scheme manager to make a recapitalisation payment when a stabilisation power is exercised in resolving a failing bank. Section 1 inserts section 214E creating the payment power, and section 2 inserts section 214F requiring the Bank to report to the Chancellor on its use, with reports laid before Parliament. The framework shifts certain recapitalisation costs to the FSCS levy rather than public funds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-banking-act-2009",
      "uk-financial-services-markets-act-2000-fsma"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-banking-act-2009",
    "title": "UK Banking Act 2009 - Special Resolution Regime and Bank Insolvency",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Banking Act 2009 (2009 chapter 1, Royal Assent 12 February 2009) is the United Kingdom's principal post-crisis statutory framework for the prevention, management, and resolution of bank failures. Part 1 establishes the Special Resolution Regime (SRR) operated by the Bank of England with five stabilisation options: a private sector purchaser sale under section 11, a bridge bank transfer under section 12, an asset management vehicle transfer under section 12ZA (added by the Banking Reform Act 2013), bail-in under section 12A (added by the Banking Reform Act 2013), and temporary public ownership under section 13. Part 2 establishes the bank insolvency procedure under which the Bank of England may apply to court for a bank insolvency order with the modified objective of ensuring eligible depositors are paid out by the Financial Services Compensation Scheme or transferred to another institution as quickly as practicable. Part 3 establishes the bank administration procedure used in conjunction with a private sector or bridge bank stabilisation to manage residual liabilities. Part 4 contains miscellaneous resolution provisions and amendments to the Banking Act 1987 and Financial Services and Markets Act 2000. Part 5 confers on the Bank of England oversight of recognised inter-bank payment systems and service providers, with later amendments extending the regime to securities settlement and central securities depositories. Subsequent statutes (Financial Services Act 2012, Banking Reform Act 2013, Bank of England and Financial Services Act 2016, Financial Services and Markets Act 2023) have substantially extended Part 1 to align with the EU Bank Recovery and Resolution Directive (now retained EU law) and the Financial Stability Board Key Attributes of Effective Resolution Regimes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-financial-services-markets-act-2000",
      "eu-brrd-bank-recovery-resolution-directive-2014-59"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-bcap-code-broadcast-advertising",
    "title": "The UK Code of Broadcast Advertising (the BCAP Code)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2024-05-22",
    "bluf": "The UK Code of Broadcast Advertising (BCAP Code) mandates that all advertisements on television and radio in the UK must be legal, decent, honest, and truthful. As stated in Rule 1.2, all broadcast advertisements must be prepared with a sense of responsibility to consumers and to society.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "asa-advertising-codes-uk",
      "coppa-marketing-kids",
      "ftc-endorsement-guides"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-border-security-asylum-immigration-act-2025",
    "title": "Border Security, Asylum and Immigration Act 2025 (c. 31), Parts 1-3 Border Security Commander and Immigration Crime Offences",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "The Border Security, Asylum and Immigration Act 2025 establishes a Border Security Commander with statutory functions and creates new offences targeting the facilitation of irregular migration. Section 13 makes it an offence to supply articles for use in immigration crime, and section 14 makes it an offence to handle such articles, with supply punishable on indictment by up to 14 years' imprisonment. The Act gives authorised officers powers to search for and access information on relevant articles and provides for serious crime prevention orders. Organisations whose goods, logistics or data could facilitate immigration offences must assess exposure to these offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-immigration-act-1971",
      "uk-nationality-and-borders-act-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-borders-act-2007",
    "title": "UK Borders Act 2007: Designated Officer Detention Powers, Biometric Immigration Documents and Automatic Deportation of Foreign Criminals",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The UK Borders Act 2007 strengthened immigration enforcement at the border and introduced the duty to deport foreign criminals automatically, administered by the Home Office. The opening provisions confer detention powers: section 1 provides for designated immigration officers, section 2 confers a power to detain a person at a port pending the arrival of a constable where the officer thinks the person may be liable to arrest, and section 3 deals with enforcement of that power. Sections 5 and 8 build the biometric framework: section 5 enables registration regulations requiring biometric immigration documents and section 8 governs the use and retention of biometric information. Sections 25 and 46 provide for forfeiture of detained property and seizure of nationality documents, and section 31 addresses people trafficking. The centrepiece is automatic deportation in Part 5: section 32 imposes a duty on the Secretary of State to make a deportation order in respect of a foreign criminal (defined as a person who is not a British citizen, is convicted in the United Kingdom of an offence, and is sentenced to imprisonment of at least twelve months or convicted of a specified offence), providing that deportation of such a person is conducive to the public good; and section 33 sets out the exceptions, including where removal would breach a person's rights under the European Convention on Human Rights or the United Kingdom's obligations under the Refugee Convention. The Act is the instrument that made deportation of qualifying foreign criminals the default and embedded biometric documents in the immigration system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-bpmmr-business-protection-misleading-marketing-2008",
    "title": "UK Business Protection from Misleading Marketing Regulations 2008 (SI 2008/1276) - B2B Misleading and Comparative Advertising Rules",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "The Business Protection from Misleading Marketing Regulations 2008 (SI 2008/1276, in force 26 May 2008) implement Directive 2006/114/EC concerning misleading and comparative advertising into UK law and operate as the B2B counterpart to the Consumer Protection from Unfair Trading Regulations 2008 (CPUTR 2008, SI 2008/1277). The BPMMR prohibit advertising which misleads traders (Regulation 3) and set conditions under which comparative advertising is lawful (Regulation 4): the comparison must be objective, not misleading, must compare goods or services meeting the same needs or intended for the same purpose, must compare verifiable, relevant and representative features, must not discredit or denigrate the competitor's marks or names, must not present goods as imitations or replicas of trademarked goods, must not take unfair advantage of the competitor's reputation, and for products with designation of origin must relate to products with the same designation. Breach of Regulation 3 is a criminal offence triable in the Magistrates' Court (fine) or Crown Court (fine and up to two years imprisonment under Regulation 6); enforcement is by the Competition and Markets Authority (CMA), Trading Standards departments, the Advertising Standards Authority through self-regulation, and sectoral regulators where relevant. The BPMMR are the UK statutory anchor for B2B misleading advertising, comparative advertising compliance, and influencer and ad-tech disputes between businesses. The Digital Markets, Competition and Consumers Act 2024 (DMCC Act) modernises the consumer-protection enforcement regime but does not displace the BPMMR for B2B disputes; sector-specific overlays apply (financial promotions FSMA Section 21, prescription medicines MHRA, alcohol Portman Group). The CMA exercises civil powers for B2B advertising disputes alongside the criminal regime. The BPMMR remain the operational reference that UK trading standards and the CMA cite in B2B misleading-advertising actions and that B2B advertisers must consider before any cross-business comparative campaign.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "implemented_eu_directive_anchor",
        "cputr_2008_companion_anchor",
        "dmcc_act_2024_overlay",
        "asa_cap_code_self_regulation",
        "sector_specific_overlays",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-cput-regulations-2008-consumer-protection-unfair-trading",
      "uk-digital-markets-competition-consumers-act-2024-dmcc",
      "uk-financial-services-markets-act-2000-fsma"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-bribery-act-2010",
    "title": "UK Bribery Act 2010",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The UK Bribery Act 2010 is one of the strictest anti-corruption laws in the world. It prohibits bribing, being bribed, and bribing foreign officials. Critically, it introduces a strict liability offense for commercial organizations that fail to prevent bribery (Section 7), with a defense available if 'Adequate Procedures' are in place.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fcpa-anti-bribery-compliance",
      "iso-37001-anti-bribery-2016",
      "oecd-guidelines-multinational-ent"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-bribery-act-2010-adequate-procedures",
    "title": "UK Bribery Act 2010: Section 7 'Failure of commercial organisations to prevent bribery' and the 'Adequate Procedures' Defence (Six Principles)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Section 7 of the UK Bribery Act 2010, a commercial organisation faces strict liability for failing to prevent bribery by an associated person. The only defence is to prove that the organisation had 'adequate procedures' in place, as guided by the UK Ministry of Justice's Six Principles, to prevent such conduct.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-bribery-act-2010",
      "iso-37001-anti-bribery-2016",
      "fcpa-anti-bribery-compliance",
      "oecd-corporate-governance-principles",
      "sarbanes-oxley-act-sox"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-bribery-act-2010-section-1-bribing-another-person",
    "title": "UK Bribery Act 2010 Section 1 - Offences of Bribing Another Person (Case 1 Inducement or Reward, Case 2 Knowledge of Improper Performance, Direct or Through Third Party, Strict Liability Within Cases)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 1 of the Bribery Act 2010 (c. 23) creates the active bribery offence - the offence of offering, promising, or giving a bribe to another person. Under section 1(1), a person 'P' is guilty if either Case 1 or Case 2 applies. Under section 1(2), Case 1 is where P offers, promises or gives a financial or other advantage to another person, with intent that the advantage either (a) induces a person to perform improperly a relevant function or activity (as defined in sections 3-5), or (b) rewards a person for the improper performance of such a function or activity. Under section 1(3), Case 2 is where P offers, promises or gives a financial or other advantage to another person, and P knows or believes that the acceptance of the advantage would itself constitute the improper performance of a relevant function or activity. Under section 1(4), in Case 1 it is irrelevant whether the recipient of the advantage is also the person performing the relevant function or activity. Under section 1(5), in both cases it is irrelevant whether the advantage is offered, promised or given directly by P or through a third party (such as an agent, intermediary, subsidiary, or joint venture partner). Section 1 is the foundational active bribery offence in UK criminal law and operates alongside section 2 (offence of being bribed), section 6 (bribery of foreign public officials), and section 7 (failure of commercial organisations to prevent bribery - the corporate strict liability offence with the section 7(2) 'adequate procedures' defence). The maximum penalty under section 11 is 10 years imprisonment on indictment, plus an unlimited fine, plus confiscation under the Proceeds of Crime Act 2002 and debarment from public procurement under the Public Contracts Regulations 2015 and the Procurement Act 2023. Prosecution is by the Serious Fraud Office (SFO) for serious or complex cases or the Crown Prosecution Service (CPS) for other cases.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_1_text_subsections",
        "relevant_function_or_activity_section_3",
        "improper_performance_section_4_expectation_test_section_5",
        "third_party_intermediation_section_1_5",
        "extraterritorial_jurisdiction_section_12",
        "penalties_section_11",
        "section_7_corporate_offence_link",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-bribery-act-2010-adequate-procedures",
      "uk-bribery-act-2010"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-bribery-act-2010-section-1-offences-bribing-another-person",
    "title": "UK Bribery Act 2010 Section 1 — Offences of Bribing Another Person",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person (P) commits an offence if P offers, promises or gives a financial or other advantage to another person, and either (Case 1) P intends the advantage to induce improper performance of a relevant function or activity, or to reward such improper performance, or (Case 2) P knows or believes the acceptance of the advantage would itself constitute improper performance. The advantage may be conferred directly by P or through a third party, and the recipient need not be the person who performs the function.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "case_1_intent_to_induce_or_reward_improper_performance",
        "case_2_knowing_acceptance_would_constitute_improper_performance",
        "advantage_financial_or_other",
        "indirect_giving_through_third_parties_captured",
        "recipient_need_not_be_function_performer",
        "relevant_function_or_activity_per_section_3",
        "improper_performance_per_section_4_and_section_5"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-bribery-act-2010-section-2-offence-of-being-bribed",
      "uk-bribery-act-2010-section-7-failure-prevent-bribery-corporate-offence"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-bribery-act-2010-section-2-offence-of-being-bribed",
    "title": "UK Bribery Act 2010 Section 2 - Offences Relating to Being Bribed (Cases 3-6: Request, Agreement, Acceptance with Intent or Reward or Consequent Improper Performance)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 2 of the Bribery Act 2010 (c. 23) creates the passive bribery offence - the offence of being bribed by another person, the counterpart to the section 1 active bribery offence. Section 2 establishes four cases. Case 3: R requests, agrees to receive or accepts a financial or other advantage intending that, in consequence, a relevant function or activity should be performed improperly (whether by R or another). Case 4: R requests, agrees to receive or accepts a financial or other advantage where the request, agreement or acceptance itself constitutes the improper performance by R of a relevant function or activity. Case 5: R requests, agrees to receive or accepts a financial or other advantage as a reward for the improper performance (by R or another) of a relevant function or activity. Case 6: in anticipation of or in consequence of R requesting, agreeing to receive or accepting a financial or other advantage, a relevant function or activity is performed improperly by R or another person at R's request or with R's assent or acquiescence. In Cases 3-6 it is irrelevant whether the advantage flows directly to R or through a third party, and whether the recipient benefit is for R or another. In Cases 4-6 R's knowledge of impropriety is immaterial. Maximum penalty under section 11 is 10 years on indictment plus unlimited fine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_2_cases_3_to_6",
        "knowledge_of_impropriety_immaterial_cases_4_6",
        "third_party_and_recipient_section_2_5_6",
        "relevant_function_or_activity_sections_3_5",
        "penalty_section_11_and_corporate_section_7_link",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-bribery-act-2010",
      "uk-bribery-act-2010-section-1-bribing-another-person",
      "uk-bribery-act-2010-adequate-procedures"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-bribery-act-2010-section-6-bribery-foreign-public-officials",
    "title": "UK Bribery Act 2010 Section 6 — Bribery of Foreign Public Officials",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person (P) who bribes a foreign public official (F) is guilty of an offence if P's intention is to influence F in F's capacity as a foreign public official AND P intends to obtain or retain business or an advantage in the conduct of business. P bribes F if, directly or through a third party, P offers, promises or gives any financial or other advantage to F (or to another at F's request, assent or acquiescence), and F is neither permitted nor required by the written law applicable to F to be so influenced. Local custom alone is not a defence — only positive written law authorising the influence will suffice.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "intent_to_influence_official_capacity",
        "intent_to_obtain_or_retain_business_or_advantage",
        "advantage_directly_or_through_third_party",
        "no_written_law_authorisation_defence",
        "definition_foreign_public_official_section_6_5",
        "written_law_applicable_definition_section_6_7",
        "profession_treated_as_business"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-bribery-act-2010-section-1-offences-bribing-another-person",
      "uk-bribery-act-2010-section-2-offence-of-being-bribed",
      "uk-bribery-act-2010-section-7-failure-prevent-bribery-corporate-offence"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-bribery-act-2010-section-6-foreign-public-officials",
    "title": "UK Bribery Act 2010 Section 6 - Bribery of Foreign Public Officials (FPO Definition, Intent to Influence in Official Capacity, Business Advantage Test, Written Law of Country Concerned, Public International Organisations)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 6 of the Bribery Act 2010 (c. 23) creates a distinct offence of bribery of foreign public officials (FPOs) - a standalone offence with elements differing from the section 1 active bribery offence. Under section 6(1), a person P who bribes a foreign public official F is guilty of an offence if P's intention is to influence F in F's capacity as a foreign public official. Under section 6(2), P must also intend to obtain or retain (a) business or (b) an advantage in the conduct of business. Under section 6(3), bribery for section 6 purposes requires P to offer, promise or give financial or other advantage directly to F or to another person at F's request or with F's assent, where F is not permitted or required by the written law applicable to F to be influenced in F's capacity as a foreign public official by the offer, promise or gift. Under section 6(4), 'influencing' F includes any omission to exercise official functions and any use of F's position even if not within F's authority. Under section 6(5), an FPO is a person who (a) holds a legislative, administrative or judicial position of any kind of a country or territory outside the UK, (b) exercises a public function for or on behalf of a country or territory outside the UK or for any public agency or public enterprise of such a country or territory, or (c) is an official or agent of a public international organisation. Under section 6(6), a public international organisation is an organisation whose members are countries or territories, governments, other public international organisations, or any combination thereof. Under section 6(7), the 'written law' applicable to F is determined by jurisdiction - UK law if a relevant question, the rules of the public international organisation if applicable, or the written constitution, legislation, or published judicial decisions of the foreign country or territory in question. Under section 6(8), a trade or profession is a business for section 6 purposes. Section 6 is the UK's primary counter-FCPA-equivalent provision and underlies the SFO's cross-border enforcement of foreign bribery cases. Penalties under section 11 - up to 10 years imprisonment on indictment for individuals, unlimited fines for individuals and corporates, plus Proceeds of Crime Act 2002 confiscation and Public Contracts Regulations 2015 / Procurement Act 2023 debarment. Section 12 extraterritorial jurisdiction applies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_6_text_subsections",
        "distinct_from_section_1_no_improper_performance_test",
        "fpo_definition_section_6_5",
        "written_law_of_country_concerned_section_6_3_7",
        "business_advantage_test_section_6_2",
        "facilitation_payments_no_uk_exception",
        "section_7_corporate_liability_uses_section_6_as_predicate",
        "extraterritorial_section_12_close_connection",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-bribery-act-2010-section-1-bribing-another-person",
      "uk-bribery-act-2010-adequate-procedures",
      "uk-bribery-act-2010"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-bribery-act-2010-section-7-failure-prevent-bribery-corporate-offence",
    "title": "UK Bribery Act 2010 Section 7 - Failure of Commercial Organisations to Prevent Bribery (Strict Liability Corporate Offence, Associated Person Test, Adequate Procedures Defence)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 7 of the Bribery Act 2010 (c. 23) creates the foundational UK strict-liability corporate offence of failure of commercial organisations to prevent bribery - the model for all subsequent UK 'failure to prevent' offences. Under section 7(1), a relevant commercial organisation (C) is guilty of an offence under this section if a person (A) associated with C bribes another person intending (a) to obtain or retain business for C, or (b) to obtain or retain an advantage in the conduct of business for C. Under section 7(2), it is a defence for C to prove that C had in place adequate procedures designed to prevent persons associated with C from undertaking such conduct. Under section 7(3), A bribes another person if A is, or would be, guilty of an offence under section 1 (active bribery) or 6 (foreign public official), whether or not A has been prosecuted. Section 7(4) references section 8 (associated person definition) and section 9 (Secretary of State guidance duty). Section 7(5) defines 'relevant commercial organisation' as a UK-incorporated body carrying on business, any other body corporate carrying on business in the UK, a UK-formed partnership carrying on business, or any other partnership carrying on business in the UK. Maximum penalty under section 11(3): unlimited fine on indictment; plus POCA confiscation, Procurement Act 2023 debarment, and reputational damage. The MOJ Guidance under section 9 sets out the six principles for adequate procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_7_text",
        "associated_person_section_8_test",
        "six_principles_for_adequate_procedures_moj_guidance_2011",
        "relevant_commercial_organisation_section_7_5_global_reach",
        "deferred_prosecution_agreements_crime_and_courts_act_2013",
        "penalty_section_11_3_unlimited_fine",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-bribery-act-2010",
      "uk-bribery-act-2010-section-1-bribing-another-person",
      "uk-bribery-act-2010-section-2-offence-of-being-bribed",
      "uk-bribery-act-2010-section-6-foreign-public-officials",
      "uk-bribery-act-2010-adequate-procedures"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-british-nationality-act-1981",
    "title": "UK British Nationality Act 1981: Acquisition, Naturalisation, Renunciation and Deprivation",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The British Nationality Act 1981 (c. 61) is the principal UK statute defining British citizenship and related nationality statuses, administered by the Home Office. Section 1 governs acquisition of British citizenship by birth or adoption in the United Kingdom (which since commencement is not automatic on birth alone but depends on the status of a parent), section 2 governs acquisition by descent, and section 3 provides for acquisition by registration of minors. Section 4 and the following provisions allow acquisition by registration by British overseas territories citizens and others by entitlement, while section 6 provides for acquisition by naturalisation on application to the Secretary of State, subject to the requirements in Schedule 1 (including residence, good character, language and knowledge, and intention requirements). Section 41A imposes a good character requirement on most registrations. Section 12 allows a person to renounce British citizenship by declaration, subject to retention safeguards. Section 40 empowers the Secretary of State to deprive a person of citizenship where it was obtained by fraud, false representation or concealment of a material fact, or where deprivation is conducive to the public good, with a right of appeal under section 40A and review under section 40B; deprivation may not generally be ordered if it would render the person stateless, reflecting the statelessness safeguards in Schedule 2. Sections 15 onward address British overseas territories citizenship by birth, adoption, descent and registration. Schedule 1 sets the requirements for naturalisation and Schedule 2 contains provisions for reducing statelessness.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-british-nationality-act-1981-section-1-acquisition-by-birth-adoption",
    "title": "UK British Nationality Act 1981 Section 1 - Acquisition by Birth or Adoption",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person born in the UK (or in a qualifying territory on or after the appointed day) after commencement is a British citizen if at the time of the birth a parent is a British citizen or settled in the UK or that territory. Where born to a member of the armed forces (post-2006), British citizenship is acquired regardless of settlement status. Abandoned newborns are deemed to satisfy the conditions. Children not citizens by birth may register if a parent later acquires citizenship or settlement, or after 10 years' UK residence subject to absence limits. Adoption by a British citizen confers citizenship subject to conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "birth_in_uk_or_qualifying_territory_to_citizen_or_settled_parent_subsection_1",
        "armed_forces_route_subsection_1a",
        "abandoned_newborn_deeming_subsection_2",
        "minor_registration_on_parent_later_qualifying_subsection_3",
        "minor_registration_on_armed_forces_parent_subsection_3a",
        "ten_year_residence_route_subsection_4",
        "adoption_route_subsections_5_and_5a",
        "post_cesser_status_preservation_subsection_6",
        "secretary_of_state_absence_discretion_subsection_7",
        "settled_definition_subsection_8"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-immigration-act-1971-section-3-general-provisions-regulation-control"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-broadcasting-act-1990",
    "title": "UK Broadcasting Act 1990 (Part I): Licensing of Independent Television, Programme Standards and Sanctions",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Broadcasting Act 1990 reformed the regulation of independent (commercial) television and radio in the United Kingdom, introducing competitive licensing and a statutory regime of programme standards and sanctions, the broadcasting-regulation functions of which are now exercised by the Office of Communications (OFCOM). Part I governs independent television services. Section 3 provides for the grant of licences under Part I. Section 6 imposes general requirements on every licensed service, including that nothing is included which offends against good taste or decency or is likely to encourage crime or disorder, that news is presented with due accuracy and impartiality, and that due impartiality is preserved on matters of political or industrial controversy. Section 7 requires a general code for programmes and section 9 controls advertisements. Licensing is mandatory: section 13 prohibits the provision of a television service to which Part I applies without a licence. The award of Channel 3 licences is competitive: section 15 governs applications, section 16 the procedure to be followed in considering them, and section 17 the award of a licence to the applicant submitting the highest cash bid (subject to the quality threshold and exceptional circumstances). Enforcement is direct: section 41 empowers the regulator to impose a financial penalty or shorten the licence period, and section 42 empowers it to revoke a Channel 3 or Channel 5 licence. The Act is a primary foundation of UK commercial-broadcasting licensing and content regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-broadcasting-act-1996",
    "title": "UK Broadcasting Act 1996: Digital Broadcasting Multiplexes, Listed Events and Standards",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Broadcasting Act 1996 introduced the framework for digital terrestrial broadcasting in the United Kingdom and the protection of nationally important sporting and other events on free-to-air television, with broadcasting-regulation functions now exercised by the Office of Communications (OFCOM). Part I establishes digital terrestrial television: section 1 provides for multiplex services and digital programme services, section 7 for the award of multiplex licences, and section 18 for the licensing of digital programme services. Part II establishes digital terrestrial sound (radio) broadcasting, including section 46 on national radio multiplex licences. Part IV protects sporting and other events of national interest: section 97 provides for the listing of events, section 99 makes void a contract that purports to grant exclusive rights to televise a listed event without the regulator's consent, and section 101 restricts the showing of live coverage of a listed event on a restricted (pay) service unless the event is also available to a wide free-to-air audience. Part V (the former Broadcasting Standards Commission, now OFCOM) provides for codes and complaints: section 107 requires a code relating to the avoidance of unjust or unfair treatment and unwarranted infringement of privacy. The Act is a legal foundation of the UK digital-broadcasting licensing regime and the listed-events free-to-air protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-broadcasting-act-1996-spectrum-content",
    "title": "Broadcasting Act 1996 - Digital Terrestrial Television Licensing, Regional Licence Conditions, Ownership Rules, Content Standards (Fairness, Privacy, Due Impartiality), OFCOM Enforcement and Sanctions including Broadcast Licence Revocation",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes the legal framework for digital terrestrial television broadcasting in the UK, including licensing of multiplex and digital programme services, ownership restrictions, and content standards enforced by OFCOM under Sections 3, 4, 12, 20, and 23. It applies to all licensees providing digital broadcasting services under Part I of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "dmca-safe-harbor",
      "iptc-photo-metadata",
      "ebu-r128-audio-loudness",
      "doi-digital-object-id"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-building-act-1984",
    "title": "UK Building Act 1984: Building Regulations, Plans Approval, Enforcement and Dangerous Buildings",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Building Act 1984 is the principal enabling statute for building control in England and Wales, providing the power to make building regulations and the local-authority enforcement machinery, now operating alongside the Building Safety Act 2022 and the Building Safety Regulator. Section 1 confers the power to make building regulations with respect to the design and construction of buildings and the provision of services, fittings and equipment. Section 2 provides for continuing requirements that may be imposed in respect of designed matters. Section 6 provides for the approval and issue of documents (approved documents) giving practical guidance on the requirements of building regulations. Section 16 governs the passing or rejection of plans deposited with the relevant authority. Enforcement is direct: section 35 makes it an offence to contravene building regulations, section 36 empowers the authority to require the removal or alteration of offending work, and section 38 addresses civil liability for breach of duty imposed by building regulations. The Act also gives local authorities powers over unsafe buildings: section 76 deals with defective premises, sections 77 and 78 with dangerous buildings and emergency measures, and section 79 with ruinous and dilapidated buildings and neglected sites, while section 91 sets the duties of local authorities and the Building Safety Regulator. The Act is the legal foundation of the building-regulations regime and the source of local-authority powers to secure compliant and safe buildings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-building-regs-second-staircase-adb-2026",
    "title": "Approved Document B (Fire Safety) 2026 amendment - second staircase requirement for new residential buildings 18 metres and above (England)",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "The 2026 amendment to Approved Document B, the statutory guidance supporting requirement B1 of the Building Regulations 2010 under the Building Act 1984, introduces guidance that new blocks of flats with a storey 18 metres or more above ground level should be provided with more than one common staircase, alongside design provisions supporting evacuation lifts; it comes into force on 30 September 2026 with transitional arrangements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-building-regulations-2010",
      "uk-building-safety-act-2022-higher-risk-buildings",
      "uk-fire-safety-act-2021-responsible-person"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-building-regulations-2010",
    "title": "UK Building Regulations 2010 - Approved Documents, Building Control, and Structural Requirements",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Building Regulations 2010 (SI 2010/2214) made under the Building Act 1984 set out the minimum functional standards for building work in England. The Regulations apply to building work as defined in Regulation 3, which includes the erection or extension of a building, material alterations to buildings, material changes of use, insertion of insulation into a cavity wall, and underpinning of a building. Regulation 4 requires that building work shall comply with the applicable requirements in Schedule 1 of the Regulations; Schedule 1 contains the technical requirements organised into Parts A (structure), B (fire safety), C (site preparation and resistance to moisture), D (toxic substances), E (resistance to the passage of sound), F (ventilation), G (sanitation, hot water safety, and water efficiency), H (drainage and waste disposal), J (combustion appliances and fuel storage), K (protection from falling, collision, and impact), L (conservation of fuel and power), M (access to and use of buildings), N (glazing), O (overheating), P (electrical safety), Q (security), and R (high-speed electronic communications networks). The Approved Documents published by the government provide practical guidance on how to comply with the Schedule 1 requirements. Building control approval is provided either through the local authority building control (LABC) service or by a registered building control approver (RBCA) formerly known as an approved inspector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "uk_construction_design_management_regulations_2015",
        "eu_construction_products_regulation_305_2011",
        "eu_energy_performance_buildings_directive_2010_31",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-construction-design-management-regulations-2015",
      "eu-construction-products-regulation-305-2011",
      "eu-health-safety-framework-directive-89-391"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-building-regulations-part-l-2021",
    "title": "Approved Document L: Conservation of fuel and power (2021 edition for use in England)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2024-06-15",
    "bluf": "This regulation establishes the energy efficiency requirements for new and existing buildings in England, mandating that new dwellings achieve a 31% reduction in CO2 emissions compared to previous standards. Compliance, as outlined in Requirement L1, is demonstrated through Standard Assessment Procedure (SAP) calculations, meeting specific targets for fabric efficiency (TFEE), primary energy, and emissions (TER), and mitigating overheating risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate-related-disclosures",
      "iso-14064-ghg-reporting-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-building-safety-act-2022",
    "title": "Building Safety Act 2022",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK Building Safety Act 2022 establishes a new, more stringent regulatory regime for higher-risk buildings, creating the role of the Building Safety Regulator and imposing specific duties on 'Accountable Persons' to assess and manage building safety risks throughout the building's lifecycle, as detailed in Part 4 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-building-safety-act-2022-higher-risk-buildings",
    "title": "UK Building Safety Act 2022 - Higher-Risk Buildings Gateway Process and Building Safety Manager Obligations",
    "domain": "Construction & Real Estate",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "UK Building Safety Act 2022 (BSA 2022) establishes a mandatory three-gateway approval process for the design, construction, and completion of higher-risk buildings (HRBs) - defined as buildings with at least 7 storeys or 18 metres height containing at least 2 residential units. The Building Safety Regulator (BSR, part of the Health and Safety Executive) must approve gateway 2 (before construction) and gateway 3 (before occupation) applications; construction cannot begin until gateway 2 is approved. Occupied HRBs require a registered Building Safety Manager (BSM), a resident engagement strategy, a safety case report, and a building safety certificate renewed every 5 years. Duty holders (client, principal designer, principal contractor) bear statutory accountabilities under the new duty holder regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-building-regulations-2010",
      "uk-fire-safety-act-2021-responsible-person"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-building-safety-act-2022-higher-risk-buildings-duty-holders",
    "title": "UK Building Safety Act 2022 - Higher-Risk Buildings Duty Holders, Safety Case, and Building Safety Regulator",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2022-04-28",
    "bluf": "The UK Building Safety Act 2022 establishes a new regulatory regime for higher-risk buildings (18m+ or 7+ storeys with residential use), requiring duty holders (accountable persons and principal accountable persons) to register buildings, produce safety cases, implement mandatory occurrence reporting, and engage with the Building Safety Regulator and residents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-health-safety-at-work-act-1974",
      "uk-fire-safety-act-2021-responsible-person"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-building-safety-act-2022-hse-higher-risk-buildings",
    "title": "UK Building Safety Act 2022 - HSE Higher-Risk Building Registration and Safety Case",
    "domain": "Construction & Real Estate",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Building Safety Act 2022 (c.30) creates a new regulatory regime for higher-risk buildings (HRBs) in England: buildings 18 metres or more or 7 storeys or more with at least 2 residential units; the Building Safety Regulator (BSR) at HSE must approve gateway 2 and gateway 3 in construction; Principal Accountable Persons (PAPs) must register existing HRBs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-burma-sanctions-eu-exit-regulations-2019-si-136",
    "title": "UK Burma (Sanctions) (EU Exit) Regulations 2019 SI 2019/136 Asset Freezes Immigration Restrictions Military Goods Interception Equipment Controls and Maritime Enforcement",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Burma (Sanctions) (EU Exit) Regulations 2019 establish the United Kingdom autonomous sanctions framework targeting Myanmar organised in 10 parts covering general provisions in Part 1, designation criteria in Part 2 including persons involved in undermining peace stability or security in Burma serious human rights violations or repression of civil society, finance restrictions in Part 3 with asset freezes and prohibitions on making funds or economic resources available, immigration measures in Part 4 making designated persons excluded from the UK, trade restrictions in Part 5 covering military goods technology related services interception equipment and goods that may be used for internal repression, exceptions and licences in Part 6 with Treasury and trade licensing mechanisms, information and records duties in Part 7, enforcement provisions in Part 8 with criminal penalties officer liability and OFSI monetary penalty powers, maritime enforcement in Part 9 with stop board search seizure and detention powers, and supplementary provisions in Part 10. The Regulations include four schedules covering ownership and control rules restricted goods lists interception equipment specifications and licensing purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-burundi-sanctions-eu-exit-regulations-2019-si-1142",
    "title": "UK Burundi (Sanctions) (EU Exit) Regulations 2019 SI 2019/1142 Autonomous Asset Freezes Immigration Restrictions and Enforcement",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Burundi (Sanctions) (EU Exit) Regulations 2019 establish the United Kingdom autonomous sanctions framework targeting Burundi organised in 8 parts covering general provisions in Part 1, designation criteria in Part 2 including persons whose activities undermine democracy rule of law or violate human rights in Burundi, finance restrictions in Part 3 with asset freezes and prohibitions on making funds or economic resources available to designated persons, immigration measures in Part 4 making designated persons excluded from the UK, exceptions and licences in Part 5 with Treasury licensing mechanisms, information and records duties in Part 6, enforcement provisions in Part 7 with criminal penalties officer liability and OFSI monetary penalty powers, and supplementary provisions in Part 8 with notices revocations and transitional rules. The Regulations include two schedules covering ownership and control interpretation rules and Treasury licensing purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-care-act-2014-section-42-local-authority-safeguarding-enquiries",
    "title": "UK Care Act 2014 Section 42 - Local Authority Safeguarding Enquiries (Adult Care and Support Needs, Abuse or Neglect Risk, Inability to Protect Self, Duty to Make Enquiries)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 42 of the Care Act 2014 (c. 23) imposes the foundational statutory adult safeguarding duty on local authorities in England - the operative provision for prosecuting safeguarding adults at risk of abuse or neglect. Under section 42(1), the section applies where a local authority has reasonable cause to suspect that an adult in its area (whether or not ordinarily resident there) (a) has needs for care and support (whether or not the authority is meeting any of those needs), (b) is experiencing, or is at risk of, abuse or neglect, and (c) as a result of those needs is unable to protect himself or herself against the abuse or neglect or the risk of it. Under section 42(2), the local authority must make (or cause to be made) whatever enquiries it thinks necessary to enable it to decide whether any action should be taken in the adult's case (whether under this Part or otherwise) and, if so, what and by whom. Under section 42(3), 'abuse' includes financial abuse - having money or property stolen, being defrauded, being put under pressure in relation to money or property, and having money or property misused. The section operates alongside section 43 (Safeguarding Adults Boards), section 44 (Safeguarding Adults Reviews), section 45 (supply of information), and the parallel Mental Capacity Act 2005 best interests regime. The duty applies regardless of whether the adult has been assessed for care and support, and the inability to protect self test is the operative threshold distinguishing section 42 from voluntary safeguarding interventions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_42_text",
        "three_part_section_42_1_test_adult_at_risk",
        "reasonable_cause_to_suspect_threshold_section_42_1",
        "abuse_definition_section_42_3_financial_and_categories_per_statutory_guidance",
        "neglect_and_self_neglect_inclusion",
        "duty_to_make_enquiries_section_42_2_discretion_within_mandate",
        "safeguarding_adults_boards_section_43_partner_arrangement",
        "making_safeguarding_personal_msp_principles",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-mental-capacity-act-2005-section-1-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-care-act-2014-section-9-assessment-adults-needs-for-care-and-support",
    "title": "UK Care Act 2014 Section 9 — Assessment of an Adult's Needs for Care and Support",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Where it appears to a local authority that an adult may have needs for care and support, the authority must carry out a needs assessment, regardless of the authority's view of the adult's needs level or financial resources. The assessment must consider the impact of needs on wellbeing per Section 1(2), the outcomes the adult wishes to achieve, and whether care and support could contribute to those outcomes. The authority must involve the adult, any carer, and any person whom the adult asks to be involved (or in whose welfare a representative is appropriate). Other community resources must also be considered.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "appearance_of_need_triggers_duty",
        "definition_needs_assessment",
        "duty_irrespective_of_needs_level_or_financial_resources",
        "three_required_assessment_components",
        "mandatory_involvement_of_adult_carer_and_representatives",
        "must_consider_non_care_and_support_alternatives",
        "interaction_with_section_11_refusal"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-care-act-2014-section-42-local-authority-safeguarding-enquiries"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-care-act-2014-section-9-needs-assessment-requirements",
    "title": "Care Act 2014 Section 9: Needs assessment",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Local authorities must conduct a needs assessment for any adult who appears to have needs for care and support, involving the adult and their carer, and considering specific factors like well-being, desired outcomes, and access to services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-cdm-regulations-2015",
    "title": "The Construction (Design and Management) Regulations 2015",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK CDM Regulations 2015 require clients on all construction projects to appoint a Principal Designer and Principal Contractor to manage health, safety, and welfare. For projects lasting over 30 working days with more than 20 workers simultaneously or exceeding 500 person-days, the client must notify the Health and Safety Executive (HSE) before construction begins, as stipulated in Regulation 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-health-safety",
      "ilo-convention-155-occupational-safety-1981"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-cdm-regulations-2015-construction",
    "title": "The Construction (Design and Management) Regulations 2015",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Construction (Design and Management) Regulations 2015 impose legal duties on clients, designers, contractors and other dutyholders to manage health, safety and welfare risks in construction projects. Key obligations include appointing a principal designer and principal contractor for projects involving more than one contractor, preparing a construction phase plan, and ensuring a health and safety file is compiled.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-19650-bim-information-management-construction",
      "ilo-safety-health-construction-convention-167-1988",
      "uk-planning-act-2008-nationally-significant-infrastructure"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-central-african-republic-sanctions-eu-exit-regulations-2020-si-616",
    "title": "UK Central African Republic (Sanctions) (EU Exit) Regulations 2020 SI 2020/616 UN Implementation Asset Freeze Military Goods and Armed Hostilities Restrictions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Central African Republic (Sanctions) (EU Exit) Regulations 2020 establish the United Kingdom's framework implementing the UN Security Council CAR sanctions regime organised in 10 parts covering general provisions in Part 1 with regulation 4 purposes and UN obligations framework, designation power and criteria in Part 2 including UN Security Council direct designations standard and urgent procedures involved person status ownership and control rules and notification publicity and confidentiality requirements, financial sanctions including the regulation 12 asset freeze restrictions on making funds or economic resources available and anti-circumvention measures in Part 3, director disqualification sanctions in Part 3A, immigration exclusion provisions in Part 4, Part 5 trade chapters covering military goods and technology restrictions supply delivery and transfer prohibitions technical assistance limitations financial services restrictions and brokering service controls including armed hostilities provisions, exceptions and licensing in Part 6, information and records requirements in Part 7, criminal enforcement in Part 8, maritime enforcement in Part 9, and supplementary and transitional provisions in Part 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-chemical-weapons-sanctions-eu-exit-regulations-2019-si-618",
    "title": "UK Chemical Weapons (Sanctions) (EU Exit) Regulations 2019 SI 2019/618 - Asset Freeze and Immigration Sanctions Targeting Chemical Weapons Proliferation",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Chemical Weapons (Sanctions) (EU Exit) Regulations 2019 establish the United Kingdom's autonomous sanctions framework targeting persons involved in the proliferation use stockpiling research or training related to chemical weapons organised in eight parts and 41 regulations across two schedules covering general provisions and the regulation 4 purpose statement, designation power and criteria for chemical weapons involvement in Part 2 with regulation 6 designation criteria and regulation 7 ownership and control rules, financial sanctions including asset freeze in regulation 11 and prohibitions on making funds or economic resources available in regulations 12 to 15 in Part 3, immigration restrictions in regulation 17 in Part 4, exceptions and Treasury licensing under regulation 20 in Part 5, information and reporting obligations in regulation 24 in Part 6, criminal enforcement and jurisdiction in Part 7, and supplementary and transitional provisions in Part 8, and operate alongside the Syria sanctions regime to address chemical weapons proliferation outside Syria.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-children-act-1989-section-17-services-for-children-in-need",
    "title": "UK Children Act 1989 Section 17 — Provision of Services for Children in Need, Their Families and Others",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Every local authority has a general duty to safeguard and promote the welfare of children within their area who are in need, and to promote the upbringing of such children by their families, by providing a range and level of services appropriate to those needs. Before deciding what services to provide, the local authority must ascertain and give due consideration to the child's wishes and feelings. Services may include accommodation, assistance in kind or in cash, and may extend to family members. A child is 'in need' if their health or development is likely to be significantly impaired without local authority services, or if they are disabled.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "general_duty_to_safeguard_promote_welfare",
        "schedule_2_specific_duties_and_powers",
        "service_to_family_member_for_childs_welfare",
        "wishes_and_feelings_of_child_must_be_considered",
        "facilitation_of_voluntary_sector_provision",
        "services_may_include_accommodation_or_cash_assistance",
        "definition_of_child_in_need_section_17_10",
        "interaction_with_wales_devolution"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-children-act-2004-section-11-safeguarding-promote-welfare",
      "uk-care-act-2014-section-42-local-authority-safeguarding-enquiries"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-children-act-2004-section-11-safeguarding-promote-welfare",
    "title": "UK Children Act 2004 Section 11 - Arrangements to Safeguard and Promote Welfare (Statutory Safeguarding Duty on Specified Authorities, Section 11 Audit, Working Together Compliance)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 11 of the Children Act 2004 (c. 31) imposes the foundational statutory safeguarding duty on specified public authorities to make arrangements for ensuring that their functions are discharged having regard to the need to safeguard and promote the welfare of children. Under section 11(1), the section applies to a range of specified authorities including local authorities in England, district councils, NHS England, integrated care boards, special health authorities, NHS trusts and foundation trusts, local policing bodies and chief officers of police in England, the British Transport Police, the National Crime Agency, local probation boards, the Secretary of State in relation to offender management functions, youth offending teams, prison governors, secure training centre directors, secure college principals, and service providers under section 74 of the Education and Skills Act 2008. Under section 11(2), each person and body to whom the section applies must make arrangements for ensuring that (a) their functions are discharged having regard to the need to safeguard and promote the welfare of children, and that any services provided by another person pursuant to arrangements made by the person or body in the discharge of their functions are provided having regard to that need. Under section 11(3), section 175 of the Education Act 2002 functions are excluded from the duty. Under section 11(4), each person and body to whom the section applies must in discharging their duty under subsection (2) have regard to any guidance given to them for the purpose by the Secretary of State - operationalised via Working Together to Safeguard Children (2023 edition).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_11_text",
        "have_regard_to_need_test_section_11_2_a",
        "specified_authorities_section_11_1_partner_agencies",
        "section_11_audit_and_assurance_framework",
        "multi_agency_safeguarding_arrangements_section_16e_16i_csa_2017",
        "education_act_2002_section_175_school_specific",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-children-families-act-2014-send-ehc-plans",
    "title": "Children and Families Act 2014, Part 3: Children and young people with special educational needs or disabilities",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This regulation requires local authorities to conduct assessments for children and young people with special educational needs and disabilities (SEND), and to prepare, maintain, and review Education, Health and Care (EHC) plans that specify the provision required to meet their needs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-civil-aviation-act-1982",
    "title": "UK Civil Aviation Act 1982: The CAA, Air Navigation Regulation, Licensing and Aircraft Liability",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Civil Aviation Act 1982 is the principal UK statute consolidating the law on civil aviation and the constitution and functions of the Civil Aviation Authority (CAA). Section 3 sets out the functions of the CAA, section 4 its general objectives in performing its air-transport licensing and related functions, and section 5 the duty to consider environmental factors when licensing or issuing certificates for certain aerodromes. Section 60 confers the power to give effect to the Chicago Convention and to regulate air navigation by Air Navigation Order, which is the principal vehicle for the detailed regulation of UK civil aviation, and section 61 makes supplemental provision about such Orders. Section 64 restricts the carriage by air for reward without a licence. Section 71 regulates the provision of accommodation in aircraft. Section 76 governs the liability of aircraft in respect of trespass, nuisance and surface damage, including the rule that no action lies in trespass or nuisance for ordinary flight at a reasonable height while strict liability applies for material loss or damage caused by an aircraft in flight or by persons or articles falling from it. Section 81 creates the offence of dangerous flying. Section 88 provides for the detention and sale of aircraft for unpaid airport charges. The Act is the legal foundation of UK civil-aviation regulation, the CAA's powers, and the Air Navigation Order regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-clean-air-act-1993",
    "title": "UK Clean Air Act 1993: Dark Smoke, Furnace Emissions and Smoke Control Areas",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Clean Air Act 1993 (c. 11) consolidates the UK's air pollution controls over smoke, grit, dust and fumes, enforced principally by local authorities under DEFRA policy. Part I prohibits the emission of dark smoke: section 1 makes it an offence to emit dark smoke from a chimney of any building, and section 2 makes it an offence to emit dark smoke from industrial or trade premises. Part II controls smoke, grit, dust and fumes from furnaces: section 4 requires that new furnaces be, so far as practicable, smokeless; section 5 controls the emission of grit and dust from furnaces; and section 6 requires arrestment plant for new non-domestic furnaces. The height of chimneys serving furnaces must be approved by the local authority (sections 14-15) to ensure adequate dispersal of pollutants. Part III provides for smoke control areas: a local authority may by order declare the whole or part of its district a smoke control area (section 18), and section 20 makes it an offence to emit smoke from a chimney of a building in a smoke control area unless an authorised fuel or exempt appliance is used. Part IV controls certain other forms of air pollution, including regulations about the composition and content of motor fuel (section 30) and the sulphur content of oil fuel for furnaces or engines (section 31). Part VII contains the general enforcement provisions (section 55). Offences under the Act are generally punishable by fines, with local authorities responsible for investigation and prosecution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-climate-change-act-2008",
    "title": "UK Climate Change Act 2008 - Net Zero Target and Carbon Budgets",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Climate Change Act 2008 (as amended by the Climate Change Act 2008 (2050 Target Amendment) Order 2019) creates a legally binding UK target to achieve net zero greenhouse gas emissions by 2050 relative to 1990 levels. The Act requires the Government to set 5-year carbon budgets (limits on net UK carbon account), establishes the independent Climate Change Committee (CCC) to advise on and scrutinise progress, and requires annual reporting to Parliament. The CCC recommends carbon budget levels; Government must explain any deviation from CCC recommendations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "net_zero_2050_target_amendment",
        "un_paris_agreement",
        "eu_ets_uk",
        "environment_act_2021",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ets-directive-2003-87-emissions-trading-scheme",
      "un-paris-agreement-ndc-implementation-guidelines",
      "eu-energy-union-governance-regulation-2018-1999"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-cma-ai-foundation-models-report-2024",
    "title": "United Kingdom Competition and Markets Authority - AI Foundation Models: Initial Review (Launched 4 May 2023; Initial Report 18 September 2023; Update Paper 11 April 2024; Technical Update Report 16 April 2024) - Competition and Consumer Protection Principles for the AI Foundation Model Sector",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2024-04-16",
    "bluf": "The UK Competition and Markets Authority (CMA) AI Foundation Models initial review is the United Kingdom's foundational competition-and-consumer-protection assessment of the foundation-model market. The case (case type Markets; case state Closed; market sector Electronics) opened 3 May 2023, was launched on 4 May 2023, and progressed through public consultation (deadline 2 June 2023) to the publication of the Initial Report on 18 September 2023 (Summary 452KB, Short Report 964KB, Full Report 2,438KB), the Update Paper on 11 April 2024, and the Technical Update Report on 16 April 2024. The review was conducted in response to the UK government's March 2023 AI White Paper, which asked UK regulators including the CMA to operationalise five overarching AI principles: (1) safety, security and robustness; (2) appropriate transparency and explainability; (3) fairness; (4) accountability and governance; and (5) contestability and redress. The CMA's review created an early shared understanding of how competitive markets for foundation models and their use could evolve; what opportunities and risks these scenarios could bring for competition and consumer protection; and which principles can best guide the ongoing development of these markets. The Update Paper (11 April 2024) confirmed final principles for guiding the foundation-model market to positive outcomes for competition and consumer protection, set out three key risks to fair, open and effective competition arising from current and potential FM-sector developments, assessed how the CMA's principles would mitigate those risks, identified actions taken and under consideration to address those risks, and outlined next steps for the CMA's AI FM programme of work. The Technical Update Report (16 April 2024) compiled stakeholder feedback received during this phase and relevant market developments mapped against each of the principles. Sarah Cardell (CMA Chief Executive) delivered an address on these themes at the American Bar Association (ABA) Chair's Showcase on AI Foundation Models on 11 April 2024. The CMA continues ongoing monitoring work to embed AI insights across the breadth of the CMA's work, with a focus on implications for consumers, competition, investment, productivity and growth.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "uk-ai-white-paper-march-2023",
        "eu-ai-act-2024",
        "uk-online-safety-act-2023",
        "uk-ico-ai-data-protection-guidance-2023",
        "us-ftc-ai-enforcement-guidance-2023",
        "edpb-opinion-28-2024-ai-models"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-ico-ai-data-protection-guidance-2023"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "uk-cma-ai-foundation-models-update-paper-2024",
    "title": "UK Competition and Markets Authority - AI Foundation Models Update Paper (April 11, 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On April 11, 2024 the UK Competition and Markets Authority (CMA) published its AI Foundation Models Update Paper, refreshing the September 2023 initial review and setting out the CMA's evolving concerns about competition risks in the foundation model ecosystem. The Update Paper identifies three interlinked risks to fair, open, and effective competition: (1) Concentration in critical inputs - compute, data, technical talent, and capital - where a small number of incumbents enjoy structural advantages that may distort downstream competition; (2) Partnerships and integrations between leading AI firms and Big Tech that may foreclose competition through exclusive access to compute, distribution channels, or commercial terms (including investments and collaborations between Microsoft and OpenAI, Amazon and Anthropic, Google and Anthropic, Microsoft and Mistral); (3) Self-preferencing and tying behaviour by integrated firms that could leverage existing market power into the AI value chain. The CMA articulated three guiding principles for foundation model competition: open access, accountability, and choice. The Paper signalled that the CMA would use its existing competition and consumer protection powers (Enterprise Act 2002 market investigation, Competition Act 1998 antitrust enforcement, Digital Markets Competition and Consumers Act 2024 strategic market status powers) to address foundation model competition concerns and to scrutinise partnerships and concentration patterns. The Update Paper informs ongoing CMA enforcement and the Digital Markets Unit work on AI markets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlay",
        "international_alignment",
        "ai_governance_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-ai-safety-institute-framework-2024",
      "uk-ai-opportunities-action-plan-2025",
      "uk-ico-ai-data-protection-guidance-2023"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-cma-green-claims-code-2021",
    "title": "UK CMA Green Claims Code 2021 - Six Principles for Environmental Claims on Goods and Services Under the Consumer Protection from Unfair Trading Regulations 2008",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Competition and Markets Authority Green Claims Code published in September 2021 is the United Kingdom's authoritative compliance framework for environmental claims on goods and services, derived from the Consumer Protection from Unfair Trading Regulations 2008 and setting out six core principles requiring claims to be truthful and accurate, clear and unambiguous, not omit material information that would mislead consumers, fair and meaningful when comparing products, consider the full life cycle of the product, and be backed by robust credible relevant and up to date substantiating evidence, with enforcement available through CMA undertakings, court orders and through the Trading Standards offence regime under the 2008 Regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-consumer-protection-from-unfair-trading-2008",
      "uk-digital-markets-competition-consumers-act-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-cma-merger-assessment-guidelines-2021",
    "title": "Merger Assessment Guidelines 2021 - Guidance from the Competition and Markets Authority on the Substantial Lessening of Competition Test and Related Analytical Frameworks",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "These guidelines set out the UK Competition and Markets Authority’s (CMA) analytical framework for assessing whether a merger results in a substantial lessening of competition (SLC) in any market in the UK, under Section 21 of the Enterprise Act 2002. The assessment requires a counterfactual analysis comparing the post-merger situation to the most plausible pre-merger scenario, with specific attention to dynamic competition, particularly in digital markets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeepers"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-coal-industry-act-1994",
    "title": "UK Coal Industry Act 1994: The Coal Authority, Licensing of Coal-Mining Operations and Subsidence",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Coal Industry Act 1994 restructured the British coal industry, established the Coal Authority and created the licensing regime for coal-mining operations, administered by the Coal Authority. Section 1 establishes the Coal Authority as a body corporate. Section 2 sets the Authority's duties with respect to licensing, including the duty to carry out its licensing functions in a manner best calculated to secure that an economically viable coal-mining industry can be maintained and developed, and section 3 sets its duties with respect to the property, rights and liabilities vested in it. Licensing is mandatory: section 25 provides that it is an offence to carry on coal-mining operations except under and in accordance with a licence granted by the Authority, and section 26 governs the grant of such licences. Part III addresses rights and obligations connected with coal mining: section 38 deals with rights to withdraw support, section 39 with notices under section 38, and sections 42 and 43 with subsidence damage to which the Coal Mining Subsidence Act 1991 applies and the persons responsible for it. Part IV contains general and supplemental provisions, including section 53 on environmental duties in connection with planning and section 54 on obligations to restore land affected by coal-mining operations, together with provisions on the discharge of coal-mine water. The Act is the legal foundation for coal-mining licensing, the management of the legacy of historic mining and the allocation of subsidence liability in Great Britain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-commons-act-2006",
    "title": "UK Commons Act 2006 (c.26): Registration of Common Land and Town or Village Greens and Protection from Works",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Commons Act 2006 (c. 26) reforms the law relating to common land and town or village greens in England and Wales, providing for the maintenance and updating of registers, the establishment of commons councils, and the protection of common land from unauthorised works, administered by commons registration authorities and Defra. Section 1 requires the registers of common land and greens to be kept, and section 2 sets the purpose of the registers as the conclusive record of common land, greens, rights of common, and ownership. Section 3 governs the content of the registers, and section 4 designates the commons registration authorities responsible for keeping them. Section 15 provides for the registration of new town or village greens where land has been used as of right for lawful sports and pastimes for at least twenty years. Section 26 provides for the establishment of commons councils to manage agricultural activities, vegetation, and the exercise of rights of common on commons. Section 38 prohibits restricted works on registered common land, such as fencing, buildings, or other works preventing or impeding access, without the consent of the appropriate national authority. Section 46 confers powers relating to unauthorised agricultural activities on common land, and section 61 provides the interpretation. The Act is the foundational modern statute for the registration and protection of common land and greens.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-communications-act-2003",
    "title": "UK Communications Act 2003 - Ofcom Licensing, Electronic Communications, and Broadcasting Regulation",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Communications Act 2003 (c. 21) is the principal legislation governing electronic communications networks and services (ECNS), broadcasting, and the regulation of communications in the United Kingdom. The Act establishes Ofcom (Office of Communications) as the UK's converged communications regulator under Section 1 and sets out its general duties in Section 3, including the primary duty to further the interests of citizens and consumers. Part 2 establishes a general authorisation regime for electronic communications: providers may provide ECNS without a specific licence subject to registration and general conditions set by Ofcom under Section 45. Ofcom may set access and interconnection conditions (Section 73), significant market power (SMP) conditions (Section 45), and universal service conditions on designated providers. Part 3 regulates television and radio broadcasting services. Section 127 prohibits the sending of grossly offensive, obscene, or menacing communications by means of a public electronic communications network. The Act has been extensively amended by the Digital Economy Act 2017, the Product Security and Telecommunications Infrastructure Act 2022, and the Online Safety Act 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_electronic_communications_code_2018_1972",
        "uk_online_safety_act_2023",
        "eu_open_internet_regulation_2015_2120",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electronic-communications-code-2018-1972",
      "eu-services-directive-2006-123",
      "uk-equality-act-2010-protected-characteristics"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-communications-act-2003-must-carry",
    "title": "Communications Act 2003 - Must-Carry Obligations for Public Service Broadcasting Channels on Electronic Communications Networks",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Communications Act 2003 imposes must-carry obligations on providers of electronic communications networks to ensure public service broadcasting channels are carried and prominently displayed, particularly via electronic programme guides. These obligations are enforced by OFCOM under Section 272 and related provisions, applying to cable, satellite, and certain online platform providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-net-neutrality-open-internet-2015-2120",
      "uk-bcap-code-broadcast-advertising"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-communications-act-2003-ofcom-framework",
    "title": "Communications Act 2003: OFCOM Regulatory Framework, Must-Carry Obligations and Broadcasting Code Enforcement",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK Communications Act 2003 establishes the Office of Communications (Ofcom) as the primary regulator for the UK's broadcasting and telecommunications industries, mandating 'must-carry' obligations for public service broadcasters on relevant networks (Section 64) and empowering Ofcom to create and enforce the Broadcasting Code for content standards (Section 319).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-retained-gdpr",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-communications-act-2003-section-105a-network-security-duty",
    "title": "UK Communications Act 2003 Section 105A - Duty to Take Security Measures (Inserted by Telecommunications (Security) Act 2021, Public Electronic Communications Network or Service, Identifying/Reducing/Preparing for Security Compromises, Definition of Security Compromise, Statutory Exception for Lawful Activity)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 105A of the Communications Act 2003 (c. 21), as inserted by the Telecommunications (Security) Act 2021, imposes the foundational telecoms security duty on providers of public electronic communications networks and services. Under section 105A(1), the provider of a public electronic communications network or a public electronic communications service must take such measures as are appropriate and proportionate for the purposes of (a) identifying the risks of security compromises occurring, (b) reducing the risks of security compromises occurring, and (c) preparing for the occurrence of security compromises. Under section 105A(2), 'security compromise' covers: (a) compromised availability, performance, or functionality of the network or service; (b) unauthorised access to, or unauthorised interference with, the network or service; (c) compromised confidentiality of signals conveyed by means of the network or service; (d) lost or altered signals conveyed by means of the network or service; (e) compromised confidentiality of data stored by electronic means by reference to the network or service; (f) lost or altered data stored by electronic means by reference to the network or service; (g) a connected security compromise (where compromise of another network/service or apparatus has any of the effects listed). Under section 105A(3), the definition excludes conduct that is required by, or is undertaken to assist with, specified statutory powers (warrants, prison rules, law enforcement operations) referenced in section 105A(4). Section 105A(5) defines connected security compromise, crime, prison rules, service police force, and signal. The section 105A duty is operationalised by sections 105B-105Z (specific security duties, Ofcom enforcement role, codes of practice under section 105F, security compromise notification under section 105K, civil penalties under section 105V, and high-risk vendor regime under sections 105Z1-105Z29). The Electronic Communications (Security Measures) Regulations 2022 SI 2022/933 and the Telecommunications Security Code of Practice 2022 elaborate the duty in operational detail. Enforcement is by Ofcom with civil penalties up to 10% of relevant turnover and continuing daily penalties up to 1/365 of 10% of relevant turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_105a_text_subsections",
        "appropriate_and_proportionate_standard_section_105a_1",
        "three_part_duty_identify_reduce_prepare_section_105a_1_a_b_c",
        "security_compromise_definition_section_105a_2_breadth",
        "statutory_exception_section_105a_3_4_for_lawful_interception_etc",
        "civil_penalty_regime_section_105v",
        "high_risk_vendor_regime_sections_105z1_105z29",
        "electronic_communications_security_measures_regulations_2022",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-telecommunications-security-act-2021-ofcom-vendor",
      "uk-investigatory-powers-act-2016-telecoms"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-communications-act-2003-section-127-improper-use-electronic-communications",
    "title": "UK Communications Act 2003 Section 127 - Improper Use of Public Electronic Communications Network (Grossly Offensive Indecent Obscene Menacing Message, False Message for Annoyance, Persistent Use)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 127 of the Communications Act 2003 (c. 21) creates two summary criminal offences relating to improper use of a public electronic communications network - one of the principal UK online harm criminal offences operating alongside the Malicious Communications Act 1988 and the Online Safety Act 2023 regulatory regime. Under section 127(1), a person is guilty of an offence if he (a) sends by means of a public electronic communications network a message or other matter that is grossly offensive or of an indecent, obscene or menacing character, or (b) causes any such message or matter to be so sent. Under section 127(2), a person is guilty of an offence if, for the purpose of causing annoyance, inconvenience or needless anxiety to another, he (a) sends a known false message by means of a public electronic communications network, (b) causes such a message to be sent, or (c) persistently makes use of a public electronic communications network. Penalty under section 127(3) is summary conviction up to 6 months imprisonment and/or fine not exceeding level 5 on the standard scale. Section 127(4) excludes broadcast programme services. Section 127(5)-(7) extend the standard 6-month summary limitation period to 3 years from offence (subject to 6-month prosecutor-knowledge sub-limit) under the DPP v Collins jurisprudence framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_127_text",
        "grossly_offensive_test_dpp_v_collins_2006_uk_hl_40",
        "menacing_character_test_chambers_v_dpp_twitter_joke_trial",
        "section_127_2_for_purpose_of_causing_annoyance_inconvenience_needless_anxiety",
        "intersection_with_malicious_communications_act_1988_section_1",
        "online_safety_act_2023_priority_offence_designation",
        "extended_limitation_section_127_5_7",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-section-9-illegal-content-risk-assessment-duties"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-companies-act-2006",
    "title": "United Kingdom Companies Act 2006: Company Formation, Directors' General Duties (Sections 170-177), Members and Resolutions, Accounts and Audit, Share Capital, Unfair Prejudice Petition, and Statutory Auditors",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The United Kingdom Companies Act 2006, chapter 46 of 2006, is the principal United Kingdom statute consolidating and reforming company law for companies registered in the United Kingdom and is administered through Companies House and the Financial Reporting Council with enforcement through the courts. Companies Act 2006, Part 1 contains general introductory provisions. Companies Act 2006, Part 2 governs company formation including Companies Act 2006, section 7 on the method of forming a company and Companies Act 2006, section 9 on the registration documents required. Companies Act 2006, section 21 governs amendment of articles and Companies Act 2006, section 33 sets out the effect of a company's constitution. Companies Act 2006, Part 8 governs a company's members. Companies Act 2006, Part 10 governs a company's directors. Companies Act 2006, section 154 sets out the requirement for companies to have directors. Companies Act 2006, section 170 sets the scope and nature of the general duties of directors as derived from common law and equity. Companies Act 2006, section 171 imposes the duty to act within powers. Companies Act 2006, section 172 imposes the duty to promote the success of the company for the benefit of its members as a whole. Companies Act 2006, section 174 imposes the duty to exercise reasonable care, skill and diligence. Companies Act 2006, Part 13 governs resolutions and meetings. Companies Act 2006, Part 15 governs accounts and reports. Companies Act 2006, Part 16 governs audit. Companies Act 2006, Part 17 governs a company's share capital. Companies Act 2006, Part 22 governs information about interests in a company's shares. Companies Act 2006, Part 25 governs a company's charges. Companies Act 2006, Part 30 contains protection of members against unfair prejudice including Companies Act 2006, section 994 the petition by a member for unfair prejudice. Companies Act 2006, Part 31 governs dissolution and restoration to the register. Companies Act 2006, Part 42 governs statutory auditors. The Act is the controlling United Kingdom statute for company law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-companies-act-2006-directors-duties-sections-170-177",
    "title": "UK Companies Act 2006 - General Duties of Directors (Sections 170-177)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The UK Companies Act 2006 Part 10 Chapter 2 (Sections 170-177) codifies seven general duties owed by directors to the company: act within powers (S171); promote the success of the company (S172); exercise independent judgment (S173); exercise reasonable care skill and diligence (S174); avoid conflicts of interest (S175); not accept benefits from third parties (S176); declare interest in proposed transaction (S177). Directors must consider the matters in S172(1)(a)-(f) including long term consequences, employee interests, customer relationships, environmental impact, reputation and fair treatment of members. Breach exposes directors to civil claims by company (including derivative claims by shareholders), disqualification under CDDA 1986, and personal liability. The Better Business Act campaign and ESG reporting amplifies S172 scrutiny.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cdda_1986",
        "insolvency_act",
        "companies_act",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-competition-act-1998",
    "title": "UK Competition Act 1998 - Chapter I Prohibition, Chapter II Prohibition, and CMA Enforcement",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Competition Act 1998 (c. 41) is the principal UK legislation prohibiting anti-competitive conduct and abuse of dominant market position. Chapter I (Section 2) prohibits agreements between undertakings, decisions by associations, and concerted practices that have as their object or effect the prevention, restriction, or distortion of competition in the UK and that appreciably affect trade within the UK. Chapter II (Section 18) prohibits conduct by one or more undertakings that amounts to an abuse of a dominant position in a market in the UK or a part of the UK. The Competition and Markets Authority (CMA) and UK sector regulators with concurrent competition powers (Ofcom, Ofgem, FCA, ORR, and others) enforce the Act. Section 36 empowers the CMA to impose financial penalties on undertakings that intentionally or negligently infringe the Chapter I or Chapter II prohibitions of up to 10% of the undertaking's worldwide turnover in the preceding financial year. The Enterprise Act 2002 introduced the criminal cartel offence (Section 188) for individuals who dishonestly agree with competitors to fix prices, share markets, limit supply or production, or rig bids. The Competition (Amendment etc.) (EU Exit) Regulations 2019 ended the primacy of EU competition law in the UK after Brexit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ecn_plus_directive_2019_nca_powers",
        "nz_commerce_act_1986_competition",
        "au_competition_consumer_act_2010_cca",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ecn-plus-directive-2019-nca-powers",
      "eu-services-directive-2006-123"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-competition-act-1998-chapter-1-2-prohibitions",
    "title": "Competition Act 1998 - Chapter I: Prohibition of Agreements, Decisions and Concerted Practices; Chapter II: Prohibition of Abuse of Dominant Position",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The UK Competition Act 1998, Sections 2(1) and 2(2), prohibits agreements between undertakings, decisions by associations of undertakings, and concerted practices that prevent, restrict, or distort competition within the UK. It also prohibits any abuse of a dominant position in a market by one or more undertakings, as defined under Section 18. The Competition and Markets Authority (CMA) has broad investigative and enforcement powers under Sections 30-36.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-competition-act-1998-chapter-1-chapter-2-prohibitions-cma",
    "title": "UK Competition Act 1998 - Chapter 1 Anticompetitive Agreements, Chapter 2 Abuse of Dominance, and CMA Enforcement",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2023-01-01",
    "bluf": "UK Competition Act 1998 prohibits agreements that prevent, restrict, or distort competition (Chapter 1) and abuse of dominant position in UK markets (Chapter 2), enforced by the CMA with financial penalties up to 10% of global turnover, criminal cartel offence prosecuted by the CMA, and private damages actions in the Competition Appeal Tribunal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeeper-obligations",
      "uk-corporation-tax-act-2010-diverted-profits-tax-transfer-pricing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-competition-act-1998-chapter-i-ii",
    "title": "Competition Act 1998: Chapter I (Anti-Competitive Agreements) & Chapter II (Abuse of Dominant Position) Prohibitions",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK Competition Act 1998 prohibits agreements that prevent, restrict, or distort competition (Chapter I, Section 2) and the abuse of a dominant market position (Chapter II, Section 18). Infringements can result in fines of up to 10% of an undertaking's worldwide turnover and disqualification of company directors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-competition-act-1998-chapters-i-ii",
    "title": "Competition Act 1998 - Chapter I: Agreements Preventing, Restricting or Distorting Competition; Chapter II: Abuse of Dominant Position",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The Competition Act 1998 prohibits anti-competitive agreements under Chapter I (Section 2) and abuse of a dominant position under Chapter II (Section 18). It applies to all undertakings operating in the UK and empowers the Competition and Markets Authority (CMA) to investigate, impose penalties, and accept commitments to address infringements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-cma-merger-assessment-guidelines-2021",
      "uk-enterprise-act-2002-merger-cma-control",
      "india-competition-act-2002-sections-3-4",
      "australia-competition-consumer-act-2010-part-iv",
      "oecd-recommendation-hard-core-cartels-2019"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-competition-act-1998-cma-chapter-i-ii-prohibitions",
    "title": "UK Competition Act 1998 - CMA Chapter I & II Prohibitions on Anti-competitive Agreements and Dominance",
    "domain": "Competition & Antitrust",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The UK Competition Act 1998 prohibits anti-competitive agreements between undertakings (Chapter I) and abuse of dominant market position (Chapter II) - enforced by the CMA with fines up to 10% of global turnover and potential director disqualification; parallel to EU Articles 101/102 TFEU.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-computer-misuse-act-1990-section-1-unauthorised-access-computer-material",
    "title": "UK Computer Misuse Act 1990 Section 1 — Unauthorised Access to Computer Material",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person commits the basic unauthorised access offence if they cause a computer to perform any function with intent to secure access to any program or data held in any computer, or to enable such access to be secured, the access intended is unauthorised, and the person knows at the time that the access is unauthorised. The intent need not be directed at any particular program, data, kind of program or data, or computer. Maximum penalty on indictment is two years' imprisonment and/or an unlimited fine; summary conviction caps apply per jurisdiction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "actus_reus_cause_computer_to_perform_function",
        "specific_intent_to_secure_access",
        "access_intended_must_be_unauthorised",
        "knowledge_at_the_time",
        "intent_need_not_target_specific_program_or_data",
        "penalty_on_indictment",
        "summary_penalties_by_jurisdiction",
        "interaction_with_section_2_and_section_3"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-computer-misuse-act-1990-section-3a-making-supplying-articles",
      "uk-computer-misuse-act-1990-section-3za-unauthorised-acts-serious-damage"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-computer-misuse-act-1990-section-3a-making-supplying-articles",
    "title": "UK Computer Misuse Act 1990 Section 3A - Making, Supplying or Obtaining Articles for Use in Cyber Offence (Programs, Data, Dual-Use Tools, Intent Belief and Possession)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 3A of the Computer Misuse Act 1990 (c. 18), inserted by the Police and Justice Act 2006 section 37, creates three offences concerning articles for use in offences under sections 1, 3, or 3ZA of the Act. Under section 3A(1), a person is guilty if he makes, adapts, supplies or offers to supply any article intending it to be used to commit, or to assist in the commission of, an offence under section 1, 3 or 3ZA. Under section 3A(2), a person is guilty if he supplies or offers to supply any article believing that it is likely to be used to commit, or to assist in the commission of, an offence under section 1, 3 or 3ZA. Under section 3A(3), a person is guilty if he obtains any article (a) intending to use it to commit or assist commission of an offence under section 1, 3 or 3ZA, or (b) with a view to its being supplied for such use. Under section 3A(4), 'article' includes any program or data held in electronic form. Under section 3A(5), the penalty on indictment is imprisonment for up to 2 years and/or unlimited fine; on summary conviction up to the general magistrates' limit (12 months in Scotland) and/or statutory maximum fine. Section 3A is the operative UK offence for prosecuting malware development and trafficking, attack-tool sales, exploit broking, and possession with intent for cybercrime - including dual-use tool prosecutions where the supplier knew or believed the tool would be misused.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_3a_text",
        "article_definition_section_3a_4_programs_and_data",
        "intent_belief_and_dual_use_section_3a_1_2",
        "obtaining_with_intent_section_3a_3",
        "penalty_section_3a_5",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-computer-misuse-act-1990-sections-1-3",
      "uk-computer-misuse-act-1990-section-3za-unauthorised-acts-serious-damage"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-computer-misuse-act-1990-section-3za-unauthorised-acts-serious-damage",
    "title": "UK Computer Misuse Act 1990 Section 3ZA - Unauthorised Acts Causing or Creating Risk of Serious Damage (Critical National Infrastructure Cyber Offence, Life-Imprisonment Aggravator, Extraterritorial Reach)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 3ZA of the Computer Misuse Act 1990 (c. 18), inserted by the Serious Crime Act 2015 section 41 and commenced on 3 May 2015, creates the aggravated UK cyber offence of unauthorised acts in relation to a computer causing or creating a significant risk of serious damage of a material kind. Section 3ZA is the principal statutory tool for prosecuting attacks against critical national infrastructure (CNI), state-actor cyber operations targeting UK essential services, and ransomware attacks with catastrophic real-world consequences. Under section 3ZA(1), a person is guilty if (a) the person does any unauthorised act in relation to a computer, (b) at the time of doing the act the person knows that it is unauthorised, (c) the act causes, or creates a significant risk of, serious damage of a material kind, and (d) the person intends by doing the act to cause serious damage of a material kind or is reckless as to whether such damage is caused. Under section 3ZA(2), 'damage of a material kind' means damage to (a) human welfare in any place, (b) the environment of any place, (c) the economy of any country, or (d) the national security of any country. Under section 3ZA(3), damage to human welfare is only material if it causes (a) loss to human life, (b) human illness or injury, (c) disruption of a supply of money, food, water, energy or fuel, (d) disruption of a system of communication, (e) disruption of facilities for transport, or (f) disruption of services relating to health. Under section 3ZA(4), damage need not be direct and the act need not be the only cause. Under section 3ZA(5), 'act' includes a series of acts and references include causing an act to be done. Under section 3ZA(6), 'country' includes territories and regions of countries (capturing devolved nations, dependencies, and overseas territories). The standard penalty under section 3ZA(7) is imprisonment for up to 14 years and/or an unlimited fine. The enhanced penalty under section 3ZA(8) is imprisonment for life and/or an unlimited fine where the offence caused, or created a significant risk of, (a) serious damage to human welfare of the kind described in 3ZA(3)(a) (loss to human life) or 3ZA(3)(b) (human illness or injury), or (b) serious damage to national security. Section 3ZA operates alongside the unauthorised access offences in sections 1, 2, and 3 of the Act, and the section 3A 'making, supplying or obtaining articles' offence. Extraterritorial reach under sections 4, 5, and 5A of the Act enables prosecution of acts done outside the UK by persons with the requisite UK link.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_3za_text_subsections",
        "unauthorised_act_test_section_17_and_section_3za_1_a",
        "serious_damage_threshold_section_3za_2_3",
        "intent_or_recklessness_section_3za_1_d",
        "extraterritorial_reach_sections_4_5_5a",
        "lawful_authorisation_defences",
        "penalty_section_3za_7_8",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-computer-misuse-act-1990-sections-1-3",
      "uk-computer-misuse-act-1990-unauthorized-access-cyber-offences"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-computer-misuse-act-1990-sections-1-3",
    "title": "Computer Misuse Act 1990, Section 1: Unauthorised access to computer material",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes a criminal offence for any person who intentionally causes a computer to perform a function to secure unauthorised access to any program or data, knowing that the access is unauthorised.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-computer-misuse-act-1990-unauthorized-access-cyber-offences",
    "title": "UK Computer Misuse Act 1990 - Unauthorised Access, Impairment, and Cybercrime Offences",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The Computer Misuse Act 1990 (CMA) creates five principal UK cybercrime offences: unauthorised access (Section 1); unauthorised access with intent to commit further offences (Section 2); unauthorised acts impairing operation of computers or data (Section 3, including DoS); making/supplying tools for CMA offences (Section 3A); and acts creating risk of serious damage (Section 3ZA, up to life imprisonment). Extraterritorial jurisdiction applies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-conservation-of-seals-act-1970",
    "title": "UK Conservation of Seals Act 1970 (c.30): Protection of Grey and Common Seals",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Conservation of Seals Act 1970 (c. 30) protects grey seals and common seals in England, Wales, and Scotland by prohibiting certain methods of killing, establishing close seasons, and providing for protection orders and licensing, administered by the relevant authorities and enforced by the police. Section 1 prohibits certain methods of killing seals, making it an offence to use a poisonous substance to take or kill a seal or to use a firearm other than one meeting prescribed requirements. Section 2 establishes close seasons for grey seals and common seals during which it is an offence to wilfully kill, injure, or take a seal except under licence. Section 3 confers power to make orders prohibiting the killing of seals where necessary for their conservation. Section 4 provides for the apprehension of offenders and powers of search and seizure, and section 5 sets the penalties for offences. Section 6 provides for forfeitures of seals and equipment on conviction. Section 9 provides general exceptions, including for the taking of a disabled seal for its welfare and the prevention of damage to fishing gear or fisheries. Section 10 confers power to grant licences to take or kill seals for specified purposes, and section 11 provides for entry upon land in connection with the Act. The Act is the foundational seal protection regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-construction-design-management-regulations-2015",
    "title": "UK Construction Design and Management Regulations 2015 - Client, Designer, and Contractor Duties",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Construction (Design and Management) Regulations 2015 (SI 2015/51) came into force on 6 April 2015 and replaced the CDM Regulations 2007. CDM 2015 applies to all construction projects in Great Britain. Regulation 4 imposes duties on commercial clients to make suitable arrangements for managing a project, ensuring pre-construction information is prepared and provided, and that welfare facilities are in place. Regulation 5 requires a commercial client to appoint a principal designer (PD) and a principal contractor (PC) where more than one contractor will or is likely to work on the project simultaneously. Regulation 6 requires the client to notify the HSE where the project is scheduled to last more than 30 working days with more than 20 simultaneous workers, or will involve more than 500 person-days of construction work, using the HSE F10 notification. Regulation 9 requires the principal designer to plan, manage, monitor, and coordinate the pre-construction phase and to compile and maintain the health and safety file. Regulation 12 requires the principal contractor to plan, manage, monitor, and coordinate the construction phase and to prepare the construction phase plan before construction begins. Regulation 8 imposes duties on all designers to eliminate, reduce, or control foreseeable risks so far as is reasonably practicable. The Health and Safety Executive (HSE) enforces CDM 2015 through improvement notices, prohibition notices, and prosecution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nz_health_safety_work_act_2015",
        "au_work_health_safety_act_2011",
        "eu_temporary_mobile_construction_sites_directive_92_57",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-hswa-2015-health-safety-work",
      "eu-working-time-directive-2003-88",
      "uk-equality-act-2010-protected-characteristics"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-construction-design-management-regulations-2015-cdm",
    "title": "UK Construction (Design and Management) Regulations 2015 (CDM 2015)",
    "domain": "Construction & Real Estate",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The UK Construction (Design and Management) Regulations 2015 (SI 2015/51) impose health and safety duties on all parties in construction projects - Clients, Principal Designers, Principal Contractors, Designers, and Contractors - requiring appointment of duty holders for notifiable projects (30+ working days with 20+ workers simultaneously, or 500+ person-days), a Construction Phase Plan before work begins, and a Health and Safety File for handover, with HSE enforcement powers including prohibition notices and prosecution under the Health and Safety at Work Act 1974.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-national-construction-code-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-consumer-contracts-regulations-2013-regulation-9-offpremises-information",
    "title": "UK Consumer Contracts Regulations 2013 Regulation 9 Information Requirements for Off-Premises Contracts",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "UK Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 SI 2013/3134 Regulation 9 is a key consumer protection law requiring traders to provide consumers with a specific list of information before they are bound by an off-premises contract, including total price, trader identity, characteristics of goods or services, and the 14-day right to cancel under consumer law, with pre-contractual information forming part of the contract and the cancellation period extended to 12 months if information is not provided.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011-83-cx"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-consumer-credit-act-1974",
    "title": "UK Consumer Credit Act 1974",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The UK Consumer Credit Act 1974 (CCA) regulates the provision of consumer credit and consumer hire agreements including credit cards personal loans hire purchase store credit and conditional sale. The CCA covers pre-contract disclosure, agreement form and content (regulated agreements per Section 8), cooling-off periods for door-step credit (Section 67), unfair credit relationships (Section 140A-B), and connected lender liability (Section 75 for credit-card linked transactions $100-$30,000 with credit element). Since April 2014 the FCA has been responsible for the consumer credit regulatory regime; firms must be FCA authorised. The CCA remains as the primary statutory framework alongside FCA CONC sourcebook.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fsma_2000",
        "fca_conc",
        "cca_2006",
        "sct_2008",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-consumer-protection-from-unfair-trading-2008",
    "title": "UK Consumer Protection from Unfair Trading Regulations 2008 - Misleading Practices and 31 Banned Acts",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The UK Consumer Protection from Unfair Trading Regulations 2008 (SI 2008/1277, CPUT), implementing EU Directive 2005/29/EC in UK domestic law post-Brexit, prohibit misleading actions, misleading omissions, aggressive commercial practices, and 31 specific banned practices (Schedule 1); enforced by the Competition and Markets Authority (CMA) and Trading Standards; the Product Security and Telecommunications Infrastructure Act 2022 and Digital Markets, Competition and Consumers Act 2024 extended consumer protection powers; individual criminal penalties apply for misleading practices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-consumer-rights-act-2015",
    "title": "UK Consumer Rights Act 2015 - Goods, Services and Digital Content Rights",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Consumer Rights Act 2015 (CRA 2015) consolidates and enhances UK consumer protection law covering goods, services, and digital content. Goods must be satisfactory quality, fit for purpose, and as described. Services must be performed with reasonable care and skill. Digital content must be of satisfactory quality. Consumers have a 30-day right to reject goods for a full refund, a one repair or replacement right, and a final right to reject after one failed remedy. Unfair terms in consumer contracts are not binding on the consumer.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cra_2015_part_1",
        "cra_2015_part_2",
        "consumer_protection_act_1987",
        "sale_of_goods_act_1979",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011-83-cx",
      "eu-unfair-commercial-practices-directive",
      "eu-general-product-safety-regulation-2023-988"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-consumer-rights-act-2015-section-34-digital-content-satisfactory-quality",
    "title": "UK Consumer Rights Act 2015 Section 34 — Digital Content to Be of Satisfactory Quality",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Consumer protection: every contract to supply digital content is treated as including a term that the quality of the digital content is satisfactory. Quality is measured by the reasonable person standard, having regard to description, price (if relevant), and all other relevant circumstances. Quality includes fitness for purpose, freedom from minor defects, safety and durability. Defects drawn to the consumer's attention before contract, revealed by examination, or apparent from a trial version are excluded. Public statements by trader, producer or representative are relevant circumstances subject to the Section 34(7) carve-outs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "implied_term_for_digital_content",
        "reasonable_person_standard_with_relevant_circumstances",
        "aspects_of_quality_for_digital_content",
        "exclusions_attention_examination_trial",
        "public_statements_relevant_circumstances",
        "public_statement_carve_outs",
        "remedies_route_section_42"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-consumer-rights-act-2015-section-9-goods-satisfactory-quality",
      "uk-consumer-rights-act-2015-section-49-service-reasonable-care-and-skill"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-consumer-rights-act-2015-section-49-service-reasonable-care-and-skill",
    "title": "UK Consumer Rights Act 2015 Section 49 - Service to Be Performed With Reasonable Care and Skill (Implied Statutory Term in Every Consumer Service Contract, Remedies via Section 54)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 49 of the Consumer Rights Act 2015 (c. 15) establishes the foundational implied term that traders must perform consumer services with reasonable care and skill - the primary statutory standard for consumer services across all sectors including financial services, professional services, IT and digital services, hospitality, healthcare, education, travel, beauty, and any other paid service to a consumer. Under section 49(1), every contract to supply a service is to be treated as including a term that the trader must perform the service with reasonable care and skill. Under section 49(2), the cross-reference is to section 54 for the consumer's rights if the trader is in breach of a term that section 49 requires to be treated as included in the contract. Section 49 cannot be contracted out of by any consumer contract term (per section 57 - exclusion of liability) for personal injury or death claims; for other claims, contractual limitation/exclusion is subject to the section 62 fairness test (unfair term void) and the Unfair Contract Terms Act 1977 reasonableness test for non-consumer protection. Remedies under section 54 include repeat performance (s.55), price reduction (s.56), and damages (general law). The Consumer Rights Act 2015 supersedes the prior Supply of Goods and Services Act 1982 section 13 for consumer contracts; the SGSA 1982 framework continues to apply for B2B service contracts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_49_text",
        "reasonable_care_and_skill_test_objective_professional_standard",
        "implied_statutory_term_cannot_be_contracted_out_section_31_57",
        "section_54_remedies_repeat_performance_price_reduction_damages",
        "section_50_pre_contract_information_binding_intersection",
        "fcas_consumer_duty_overlay_for_financial_services",
        "professional_services_specific_overlays_sra_icaew_etc",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-consumer-rights-act-2015-section-62-fairness-of-terms-and-notices",
    "title": "UK Consumer Rights Act 2015 Section 62 — Requirement for Contract Terms and Notices to Be Fair",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Consumer protection rule: an unfair term of a consumer contract or an unfair consumer notice is not binding on the consumer. A term or notice is unfair if, contrary to the requirement of good faith, it causes a significant imbalance in the parties' rights and obligations under the contract to the detriment of the consumer. The unfairness assessment is made by reference to the nature of the subject matter and all circumstances existing when the term was agreed (or the notice took effect), and to all other terms of the contract or any other contract on which it depends. The consumer remains entitled to rely on an unfair term if they choose to do so.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "unfair_term_not_binding_on_consumer",
        "unfair_consumer_notice_not_binding",
        "consumer_may_still_rely_on_unfair_term",
        "test_for_unfair_term_good_faith_and_significant_imbalance",
        "circumstances_for_term_assessment",
        "test_for_unfair_notice_parallel",
        "interaction_with_blacklisted_terms"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-consumer-rights-act-2015-section-9-goods-satisfactory-quality",
      "uk-consumer-rights-act-2015-section-49-service-reasonable-care-and-skill"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-consumer-rights-act-2015-section-9-goods-satisfactory-quality",
    "title": "UK Consumer Rights Act 2015 Section 9 — Goods to Be of Satisfactory Quality",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Consumer protection: every contract to supply goods is treated as including a term that the quality of the goods is satisfactory. Quality is measured against the standard that a reasonable person would consider satisfactory, having regard to description, price, and other relevant circumstances. Quality includes fitness for all common purposes, appearance and finish, freedom from minor defects, safety, and durability. Public statements by the trader, producer or representative form part of the relevant circumstances, subject to defined carve-outs in subsection (7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "implied_term_in_every_supply_contract",
        "reasonable_person_objective_standard",
        "aspects_of_quality_six_indicators",
        "exclusions_attention_examination_sample",
        "public_statements_form_part_of_relevant_circumstances",
        "carve_outs_for_public_statements",
        "remedies_route_into_section_19_to_24"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-consumer-rights-act-2015-section-49-service-reasonable-care-and-skill"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-contracts-for-difference-cfd-allocation-round-6",
    "title": "Contracts for Difference (CfD) Allocation Round 6: Core Parameters and Administrative Strike Price Methodology",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-05-17",
    "bluf": "This regulation establishes the rules, eligibility criteria, technology groupings (Pots), budget allocations, and administrative strike prices for renewable energy projects applying for a government-backed CfD in the UK's sixth allocation round (AR6). As detailed in the Allocation Framework, applicants must meet specific technology and project-stage requirements to participate in the competitive auction for long-term revenue stabilization contracts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-contracts-for-difference-cfd-auction-rules",
    "title": "UK Contracts for Difference (CfD) Scheme - Auction Allocation Rounds, Strike Prices, Low-Carbon Contract Terms and Renewable Energy Obligations",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-06-27",
    "bluf": "The UK Contracts for Difference (CfD) scheme is a government mechanism to support low-carbon electricity generation by providing eligible renewable energy projects with a fixed 'strike price' for the power they generate, mitigating wholesale price volatility. This applies to generators who successfully bid in a competitive Allocation Round, with obligations governed by the CfD Standard Terms and Conditions, particularly Condition 5 (Milestone Requirement).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate-related-disclosures",
      "iso-14064-ghg-reporting-2018",
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-control-of-pollution-act-1974-noise",
    "title": "UK Control of Pollution Act 1974 (Part III, Noise): Construction-Site Noise Notices, Prior Consent and Noise Abatement Zones",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Part III of the Control of Pollution Act 1974 remains the framework for controlling construction-site and street noise and for operating noise abatement zones in England and Wales, administered by local authorities (the earlier Parts of the Act on waste on land, pollution of water and atmospheric pollution have largely been superseded by the Environmental Protection Act 1990, the Water Resources Act 1991 and later legislation, while Part III continues to operate alongside the statutory-nuisance regime). Section 60 empowers a local authority to serve a notice imposing requirements on the carrying out of works on a construction site, including limits on the hours, the plant or machinery used and the permissible noise levels, where construction, demolition, dredging or similar works are to be or are being carried out. Section 61 allows a person intending to carry out such works to apply to the local authority for prior consent to the works, giving certainty in advance about the controls that will apply. Section 62 controls the operation of loudspeakers and noise in streets. Sections 63 to 67 govern noise abatement zones: section 63 enables a local authority to designate a noise abatement zone, section 64 requires a register to be kept of the noise levels of premises in the zone, section 65 prohibits noise exceeding the registered level without consent, section 66 enables a notice to reduce noise levels, and section 67 deals with new buildings in a zone. Sections 57 and 58 provide for periodical inspections and summary proceedings by local authorities. The Part is the operative noise-control toolkit that sits beside the statutory-nuisance powers in the Environmental Protection Act 1990.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-copyright-designs-and-patents-act-1988-copyright",
    "title": "UK Copyright, Designs and Patents Act 1988: Subsistence, Restricted Acts and Permitted Acts",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Copyright, Designs and Patents Act 1988 (c. 48) is the principal UK statute governing copyright, administered through the courts with policy oversight by the Intellectual Property Office (IPO). Section 1 provides that copyright is a property right subsisting in original literary, dramatic, musical or artistic works, sound recordings, films, broadcasts, and the typographical arrangement of published editions, with the descriptions of work set out in sections 3 (literary, dramatic and musical works), 3A (databases), 4 (artistic works), 5A (sound recordings), 5B (films), 6 (broadcasts) and 8 (published editions). Section 9 identifies the author and section 11 sets first ownership (generally the author, but the employer for works made by an employee in the course of employment). Duration is set by sections 12-15: the life of the author plus 70 years for literary, dramatic, musical and artistic works (section 12), 70 years for sound recordings and films on the relevant basis (sections 13A-13B), and 25 years for the typographical arrangement of published editions (section 15). Section 16 defines the acts restricted by copyright, which only the owner may do or authorise: copying (section 17), issuing copies to the public (section 18), rental or lending (section 18A), performing, showing or playing in public (section 19), communicating the work to the public (section 20) and making an adaptation (section 21). Chapter III sets out permitted acts, including research and private study (section 29), criticism, review, quotation and news reporting (section 30) and caricature, parody or pastiche (section 30A). Authors and directors have moral rights: to be identified (section 77), to object to derogatory treatment (section 80) and to privacy in certain commissioned photographs and films (section 85). Infringement is actionable by the copyright owner with remedies including damages (section 97), delivery up (section 99) and seizure (section 100), and section 107 creates criminal offences for making or dealing with infringing articles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-copyright-designs-patents-act-1988",
    "title": "UK Copyright, Designs and Patents Act 1988 -- Copyright Duration, Permitted Acts, and Design Rights",
    "domain": "Creative, Content & Media IP",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "The Copyright, Designs and Patents Act 1988 (CDPA) is the primary UK statute governing copyright, design rights, and performers' rights. Copyright subsists automatically without registration in original literary, dramatic, musical, and artistic works; sound recordings; films; broadcasts; and typographical arrangements under Sections 1-9. The standard copyright duration for literary, dramatic, musical, and artistic works is 70 years from the end of the calendar year of the author's death under Section 12; sound recordings are protected for 70 years from release under Section 13A; broadcasts for 50 years under Section 14. The employer owns copyright in works created by an employee in the course of employment under Section 11(2). Permitted acts include fair dealing for research and private study (Section 29), criticism and review (Section 30), reporting current events (Section 30), quotation (Section 30(1ZA)), and caricature, parody, and pastiche (Section 31F). Moral rights include the right of paternity (Section 77) and the right of integrity (Section 80) - these cannot be assigned but can be waived by contract. The UK Unregistered Design Right under Part III lasts 15 years from creation or 10 years from first marketing, whichever is shorter. Criminal copyright infringement under Section 107 carries a maximum sentence of 10 years imprisonment on indictment. Post-Brexit, the CDPA was retained as UK domestic law; EU copyright exceptions do not apply automatically in the UK after 31 December 2020, and EU exhaustion of rights no longer applies - the UK adopted an independent UK exhaustion regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-2019-790",
      "eu-trademark-regulation-2017-1001",
      "eu-unfair-commercial-practices-directive-2005-29"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-copyright-designs-patents-act-1988-section-94-moral-rights-authors",
    "title": "Copyright, Designs and Patents Act 1988, Section 94: Moral rights not assignable",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must ensure that moral rights conferred by Chapter IV of the Act are never assigned, as they are legally non-assignable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-coroners-and-justice-act-2009-section-62-prohibited-images-children",
    "title": "UK Coroners and Justice Act 2009 Section 62 - Possession of Prohibited Images of Children",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 62 of the Coroners and Justice Act 2009 makes it an offence for a person to be in possession of a prohibited image of a child. A 'prohibited image of a child' must satisfy three criteria: it is pornographic; it falls within Section 62(6) prohibited categories (focus on genitals/anal region, or depiction of specified sexual acts including intercourse, oral sex, masturbation, or sexual acts with animals); and it is grossly offensive, disgusting or otherwise of an obscene character. The provision closes the gap left by PCA 1978 (which only catches photographs and pseudo-photographs) by extending to non-photographic images such as drawings, cartoons, manga, computer-generated imagery, and animations. Prosecution requires DPP consent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_possession_offence_subsection_1",
        "prohibited_image_definition_subsection_2",
        "pornographic_definition_subsection_3",
        "context_of_series_subsection_4",
        "categories_of_prohibited_imagery_subsection_6",
        "extends_to_non_photographic_images_section_65",
        "child_under_18_section_65_5",
        "defences_section_64",
        "dpp_consent_required_section_69_5",
        "penalties_section_66",
        "interaction_with_pca_1978_and_obscene_publications_act"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-protection-of-children-act-1978-section-1-indecent-photographs-children",
      "uk-criminal-justice-act-1988-section-160-possession-indecent-photograph-child"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-corporate-manslaughter-act-2007-section-1-corporate-manslaughter",
    "title": "UK Corporate Manslaughter and Corporate Homicide Act 2007 Section 1 - Corporate Manslaughter (Death Caused by Activities, Gross Breach of Duty, Senior Management Substantial Element)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 1 of the Corporate Manslaughter and Corporate Homicide Act 2007 (c. 19) creates the corporate manslaughter offence (corporate homicide in Scotland) - the principal UK organisational criminal liability regime for fatal incidents caused by gross breach of duty of care. Under section 1(1), an organisation to which the section applies is guilty of an offence if the way in which its activities are managed or organised (a) causes a person's death, and (b) amounts to a gross breach of a relevant duty of care owed by the organisation to the deceased. Under section 1(2), the organisations to which the section applies are corporations, government departments listed in Schedule 1, police forces, and partnerships, trade unions, and employers' associations that are employers. Section 1(3) sets the senior management test - an organisation is guilty only if the way in which its activities are managed or organised by its senior management is a substantial element in the breach referred to in subsection (1). Section 1(4)(b) defines 'gross breach' as conduct falling far below what can reasonably be expected of the organisation in the circumstances. Section 1(5)-(6) extend the offence to deaths outside the UK in defined circumstances. Maximum penalty under section 1(7): on conviction on indictment, an unlimited fine; tried only in the Crown Court (E&W/NI) or High Court of Justiciary (Scotland); plus publicity orders under section 10 and remedial orders under section 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_1_text",
        "senior_management_substantial_element_test_section_1_3_4_c",
        "gross_breach_test_section_1_4_b_and_section_8_jury_factors",
        "relevant_duty_of_care_section_2_categories",
        "applicable_organisations_section_1_2",
        "penalty_section_1_7_and_sentencing_council_guideline",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-health-and-safety-at-work-act-1974-section-2-employer-general-duties",
      "uk-health-and-safety-at-work-act-1974-section-3-duties-to-non-employees",
      "uk-health-and-safety-at-work-act-1974-section-37-director-liability"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-corporation-tax-act-2010-diverted-profits-tax-transfer-pricing",
    "title": "UK Corporation Tax Act 2010 - Diverted Profits Tax, Transfer Pricing, and Hybrid Mismatch Rules",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2023-04-01",
    "bluf": "UK Corporation Tax Act 2010 and associated legislation impose 25% Diverted Profits Tax on profits diverted from the UK, require arm's-length transfer pricing on related-party transactions, and deny deductions for hybrid mismatch arrangements, with country-by-country reporting mandatory for groups with consolidated revenue above GBP 586 million.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-country-by-country-reporting",
      "oecd-pillar-two-global-minimum-tax-15-percent-globe-rules"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-counter-terrorism-international-sanctions-eu-exit-regulations-2019-si-573",
    "title": "UK Counter-Terrorism (International Sanctions) (EU Exit) Regulations 2019 SI 2019/573 Autonomous Counter-Terrorism Asset Freeze Trade and Immigration Sanctions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Counter-Terrorism (International Sanctions) (EU Exit) Regulations 2019 establish the United Kingdom's autonomous counter-terrorism sanctions framework targeting persons involved in or connected with international terrorism beyond the UN ISIL and Al-Qaida list, organised in 10 parts and 62 regulations plus one interpretation schedule covering general provisions and purposes in Part 1, designation power and criteria in Part 2, financial asset freeze and prohibitions on making funds or economic resources available in Part 3, immigration sanctions on designated persons in Part 4, trade prohibitions on military goods technology transfer technical assistance and related financial services in Part 5, Treasury and trade licensing exceptions in Part 6, information reporting obligations and information request powers for financial firms in Part 7, criminal enforcement penalties and civil monetary penalties in Part 8, maritime enforcement stop board search and seizure powers in Part 9, and supplementary and transitional provisions in Part 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-countryside-and-rights-of-way-act-2000",
    "title": "UK Countryside and Rights of Way Act 2000 (c.37): Right of Access to Open Country, SSSIs and Areas of Outstanding Natural Beauty",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Countryside and Rights of Way Act 2000 (c. 37) creates a statutory right of public access on foot to open country and registered common land, strengthens the protection of sites of special scientific interest, and provides for the designation of areas of outstanding natural beauty, administered by Natural England, Natural Resources Wales, and local access authorities. Section 1 sets the principal definitions for Part I, including the meaning of open country as land consisting wholly or predominantly of mountain, moor, heath, or down. Section 2 confers on the public a right to enter and remain on access land for the purposes of open-air recreation, subject to the general restrictions in Schedule 2. Section 4 imposes a duty on the appropriate countryside body to prepare maps showing access land. Section 22 allows the owner or other entitled person to exclude or restrict access at their discretion for a limited number of days, and section 24 provides for exclusion or restriction for land management. Section 75 substantially amends the Wildlife and Countryside Act 1981 to strengthen the protection of sites of special scientific interest, including duties on public bodies and offences for damaging a site. Section 81 strengthens the enforcement of wildlife legislation, and section 82 provides for the designation of areas of outstanding natural beauty. The Act is the foundational right-to-roam and nature conservation reform statute.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-cput-regulations-2008-consumer-protection-unfair-trading",
    "title": "UK Consumer Protection from Unfair Trading Regulations 2008 (SI 2008/1277, CPRs/CPUT)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Consumer Protection from Unfair Trading Regulations 2008 (SI 2008/1277, the CPRs) transpose EU Directive 2005/29/EC on Unfair Commercial Practices (UCPD) into UK domestic law. The Regulations were in force from 26 May 2008 and were materially amended by the Consumer Protection (Amendment) Regulations 2014 (SI 2014/870) introducing private consumer rights of redress. The Regulations are organised in five Parts and four Schedules. Part 1 contains citation and interpretation including the average consumer concept. Part 2 contains the substantive prohibitions: Regulation 3 (general prohibition of unfair commercial practices contrary to professional diligence), Regulation 5 (misleading actions about product characteristics, price, trader identity), Regulation 6 (misleading omissions of material information), Regulation 7 (aggressive practices using harassment, coercion or undue influence), and Regulation 9 cross-references the Schedule 1 blacklist of 31 commercial practices always considered unfair (pyramid schemes, false code-compliance claims, unwanted persistent solicitations, exhortations directed at children). Regulations 27A to 27L (inserted by SI 2014/870) provide private consumer rights of redress: right to unwind, right to discount and damages. Part 3 establishes offences punishable on indictment by up to 2 years imprisonment and an unlimited fine. Regulation 17 provides the due-diligence defence. Part 4 vests enforcement in trading standards authorities and the Competition and Markets Authority. From April 2025 the Digital Markets, Competition and Consumers Act 2024 (DMCC Act) supplements the CPRs with direct CMA enforcement powers and turnover-based fines up to 10 percent of global turnover.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-2005-29-2022-revision",
      "uk-consumer-rights-act-2015",
      "uk-asa-influencer-marketing-guide-2023"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-crime-and-policing-act-2026-retail-crime-asb",
    "title": "Crime and Policing Act 2026 (c. 20), Part 1 Anti-Social Behaviour Respect Orders and Part 3 Retail Crime Offences",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "The Crime and Policing Act 2026 introduces respect orders to tackle anti-social behaviour and creates new retail crime offences. Section 45 makes it an offence to assault a retail worker at work, and section 47 makes theft from a shop triable either way irrespective of the value of the goods. The Act also addresses offensive weapons, child criminal exploitation, and public order at protests. Retailers and employers of retail workers can rely on these offences to protect staff and pursue prosecution of shop theft regardless of value.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-public-order-act-2023-protest-restrictions",
      "uk-modern-slavery-act-2015-section-1-slavery-servitude-forced-labour"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-criminal-finances-act-2017",
    "title": "UK Criminal Finances Act 2017 (c. 22): Unexplained Wealth Orders and Corporate Failure to Prevent the Facilitation of Tax Evasion",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Criminal Finances Act 2017 (c. 22) strengthens the United Kingdom's powers to recover the proceeds of crime, counter terrorist financing, and tackle money laundering, and creates new corporate criminal offences for failing to prevent the facilitation of tax evasion, enforced by the National Crime Agency, HM Revenue and Customs, and prosecuting authorities. Section 1 introduces unexplained wealth orders for England and Wales and Northern Ireland, requiring a respondent to explain the lawful origin of property where its value appears disproportionate to known lawfully obtained income. Section 2 provides for interim freezing orders to preserve property subject to an unexplained wealth order. Section 7 provides for disclosure orders in confiscation and money laundering investigations. Section 10 confers a power to extend the moratorium period during which a consent request following a suspicious activity report is considered. Section 13 addresses unlawful conduct constituting gross human rights abuses or violations, extending civil recovery. Section 36 enables the sharing of information within the regulated sector to combat money laundering. Section 45 creates the corporate offence of failure of a relevant body to prevent the facilitation of UK tax evasion offences, and section 46 creates the corresponding offence for foreign tax evasion offences, each subject to a defence of having reasonable prevention procedures in place. The Act is a foundational statute for UK asset recovery and corporate financial-crime liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-criminal-finances-act-2017-section-45-failure-prevent-uk-tax-evasion-facilitation",
    "title": "UK Criminal Finances Act 2017 Section 45 - Failure to Prevent Facilitation of UK Tax Evasion (Strict Liability Corporate Offence, Reasonable Procedures Defence, Associated Person)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 45 of the Criminal Finances Act 2017 (c. 22) creates the strict-liability corporate offence of failure to prevent facilitation of UK tax evasion - the second of the UK 'failure to prevent' corporate liability regimes alongside Bribery Act 2010 section 7. Under section 45(1), a relevant body (B) is guilty of an offence if a person commits a UK tax evasion facilitation offence when acting in the capacity of a person associated with B. The strict-liability structure attaches corporate liability solely on the basis of the facilitation conduct by an associated person, without requiring proof of board-level knowledge or intent. The signature defence under section 45(2) is that B had in place such prevention procedures as it was reasonable in all the circumstances to expect B to have in place, OR that it was not reasonable in all the circumstances to expect B to have any prevention procedures in place. Section 45(3) defines prevention procedures as procedures designed to prevent persons acting in the capacity of an associated person from committing UK tax evasion facilitation offences. Section 45(4) defines UK tax evasion offence (cheating the public revenue or fraudulent evasion of tax). Section 45(5) defines UK tax evasion facilitation offence. Section 45(6) requires the underlying UK tax evasion offence to have been committed. Section 45(7) defines tax to include national insurance contributions. Section 45(8) penalty: unlimited fine on indictment or summary conviction (E&W) / statutory maximum (Scotland and NI summary).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_45_text",
        "associated_person_definition_section_44",
        "reasonable_prevention_procedures_six_principles",
        "underlying_facilitation_offence_required_section_45_6",
        "tax_definition_includes_nics_section_45_7",
        "penalty_section_45_8_and_collateral_consequences",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-criminal-finances-act-2017"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-criminal-finances-act-2017-section-46-failure-prevent-foreign-tax-evasion-facilitation",
    "title": "UK Criminal Finances Act 2017 Section 46 - Failure to Prevent Facilitation of Foreign Tax Evasion (UK Nexus Conditions, Dual Criminality, Reasonable Procedures Defence)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 46 of the Criminal Finances Act 2017 (c. 22) creates the strict-liability corporate offence of failure to prevent facilitation of foreign tax evasion, complementing the domestic offence under section 45. Under section 46(1), a relevant body (B) is guilty of an offence if (a) a person commits a foreign tax evasion facilitation offence when acting in the capacity of a person associated with B, and (b) any of the conditions in subsection (2) is satisfied. Section 46(2) establishes the UK nexus conditions: (a) B is incorporated or formed under UK law, (b) B carries on business or part of a business in the UK, or (c) any conduct constituting part of the foreign tax evasion facilitation offence takes place in the UK. Section 46(3) signature defence: B had in place reasonable prevention procedures, or it was not reasonable to expect B to have any. Section 46(4) defines prevention procedures. Section 46(5)-(6) define foreign tax evasion offence and foreign tax evasion facilitation offence - the foreign offence must involve fraudulent evasion of foreign tax that would constitute a UK tax evasion offence under section 45(4) if committed in the UK (dual criminality requirement). Section 46(7) penalty: unlimited fine on indictment or summary E&W; statutory maximum Scotland/NI summary.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_46_text",
        "uk_nexus_conditions_section_46_2",
        "dual_criminality_section_46_5",
        "associated_person_section_44_applies",
        "reasonable_prevention_procedures_six_principles_apply",
        "penalty_section_46_7_and_collateral_consequences",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-criminal-finances-act-2017",
      "uk-criminal-finances-act-2017-section-45-failure-prevent-uk-tax-evasion-facilitation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-criminal-justice-act-1988-section-160-possession-indecent-photograph-child",
    "title": "UK Criminal Justice Act 1988 Section 160 - Possession of Indecent Photograph of a Child",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 160 of the Criminal Justice Act 1988 makes it an offence for a person to have any indecent photograph or pseudo-photograph of a child in their possession. Three statutory defences are available on the defendant proving (a) a legitimate reason for possession, (b) that the defendant had not seen the image and did not know nor had cause to suspect it was indecent, or (c) that the image was sent without prior request and was not kept for an unreasonable time. Maximum penalty: 5 years' imprisonment on indictment; 6 months and/or level-5 fine on summary conviction. Section 160 is the principal simple-possession offence supplementing the PCA 1978 making and distribution offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_possession_offence_subsection_1",
        "definition_borrowed_from_pca_1978",
        "statutory_defences_subsection_2",
        "indictment_penalty_subsection_2a",
        "summary_penalty_subsection_3",
        "deletion_marriage_carve_out_section_160A",
        "interaction_with_pca_1978_section_1",
        "automatic_sex_offender_notification",
        "sentencing_council_indecent_images_guideline_applies"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-protection-of-children-act-1978-section-1-indecent-photographs-children"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-criminal-justice-immigration-act-2008-section-63-extreme-pornography",
    "title": "UK Extreme Pornography Possession Offence - Criminal Justice and Immigration Act 2008 Section 63",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Section 63 of the UK Criminal Justice and Immigration Act 2008 (c. 4) created a possession offence for extreme pornographic images in England, Wales, and Northern Ireland (Scotland addressed separately by the Criminal Justice and Licensing (Scotland) Act 2010): subsection (1) provides 'It is an offence for a person to be in possession of an extreme pornographic image'; subsection (2) defines pornographic as material 'of such a nature that it must reasonably be assumed to have been produced solely or principally for the purpose of sexual arousal'; subsections (6) and (7) define 'extreme image' as an image which is both grossly offensive, disgusting or of an obscene character AND falls within specified categories: explicit depictions of acts threatening a person's life, acts likely to result in serious injury to a person's anus, breasts, or genitals, sexual interference with a human corpse, sexual interference with an animal, and (added by Criminal Justice and Courts Act 2015) nonconsensual sexual penetration; the offence is intended to capture material that may not meet the Obscene Publications Act 1959 standard but is nonetheless serious enough to warrant criminal sanction; penalties on indictment up to 3 years imprisonment (extended from original 2 years by Criminal Justice and Courts Act 2015); statutory defences in Section 65 for legitimate reasons including art, science, education, or to assist law enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_uk_content_statutes",
        "amendments_history",
        "statutory_defences_section_65",
        "industry_mapping",
        "enforcement_anchors",
        "scotland_parallel_statute"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-obscene-publications-act-1959",
      "uk-indecent-displays-control-act-1981",
      "uk-online-safety-act-2023-part-5-pornographic-content-duties"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-customs-excise-management-act-1979",
    "title": "United Kingdom Customs and Excise Management Act 1979 (CEMA): Customs Control, Importation and Exportation Procedures, Forfeiture, Penalties for Improper Importation, Untrue Declarations, and Fraudulent Evasion of Duty",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The United Kingdom Customs and Excise Management Act 1979, chapter 2 of 1979, commonly cited as CEMA, is the foundational United Kingdom statute establishing the administrative framework for customs and excise control and is enforced by His Majesty's Revenue and Customs and Border Force. Customs and Excise Management Act 1979, Part I sets the interpretation and application. Customs and Excise Management Act 1979, Part II governs the appointment and duties of the Commissioners. Customs and Excise Management Act 1979, Part III governs customs control areas and officer powers, including powers to examine goods, require information, and conduct searches. Customs and Excise Management Act 1979, Part IV regulates importation control and procedures including arrival and report of ships and aircraft, entry, examination, and customs warehouses. Customs and Excise Management Act 1979, Part V regulates exportation requirements. Customs and Excise Management Act 1979, section 50 establishes the penalty for improper importation of goods. Customs and Excise Management Act 1979, section 68 creates offences in relation to exportation of prohibited or restricted goods. Customs and Excise Management Act 1979, section 167 creates the offence of untrue declarations. Customs and Excise Management Act 1979, section 170 creates the offence of fraudulent evasion of duty. Parts VI through XII cover coastwise traffic, warehousing, excise licensing, forfeiture proceedings, and general provisions. The Act, together with the Taxation (Cross-border Trade) Act 2018 which sets the post-Brexit customs framework, is the controlling United Kingdom instrument for customs and excise enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-cyber-essentials-ncsc-certification-scheme",
    "title": "UK Cyber Essentials - NCSC Certification Scheme for Baseline Cyber Hygiene",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Cyber Essentials is a UK Government-backed certification scheme administered by the National Cyber Security Centre (NCSC) that requires organisations to implement five technical controls: firewalls, secure configuration, user access control, malware protection, and patch management. Certification is mandatory for UK Government contracts involving handling personal data or providing certain ICT products and services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-data-protection-act-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-cyber-essentials-plus-2023",
    "title": "Cyber Essentials Plus: Illustrative Test Specification (Montpellier v3.1, April 2023)",
    "domain": "Cybersecurity",
    "version": "3.1.0",
    "last_updated": "2023-04-24",
    "bluf": "Cyber Essentials Plus is a UK government-backed, independently verified certification requiring organizations to demonstrate compliance with five key technical controls through rigorous hands-on testing. This node focuses on the specific audit requirements for Boundary Firewalls (A1), Secure Configuration (A2), and User Access Control (A3) as detailed in the Montpellier v3.1 test specification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-800-53-sc7",
      "cyber-nist-800-53-ac2",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-cyber-sanctions-eu-exit-regulations-2020-si-597",
    "title": "UK Cyber (Sanctions) (EU Exit) Regulations 2020 SI 2020/597 - Asset Freeze and Immigration Sanctions Against Cyber Threat Actors",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Cyber (Sanctions) (EU Exit) Regulations 2020 establish the United Kingdom's autonomous sanctions regime targeting cyber threat actors organised in seven parts covering general provisions and purpose under regulation 4, designation power and criteria for persons responsible for or involved in relevant cyber activity in Part 2 with Schedule 1 defining ownership and control, asset-freeze with prohibitions on dealing with funds and economic resources and prohibitions on making funds available in Part 3, immigration sanctions against designated persons in Part 4, Treasury licences for specified purposes including basic needs legal services and humanitarian assistance under Schedule 2 in Part 5, information and reporting obligations with offences for non-compliance in Part 6, and penalty and enforcement provisions in Part 7, and are administered by HM Treasury OFSI working alongside the National Cyber Security Centre for attribution and intelligence support.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-dangerous-wild-animals-act-1976",
    "title": "UK Dangerous Wild Animals Act 1976 (c.38): Licensing the Keeping of Dangerous Wild Animals",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Dangerous Wild Animals Act 1976 (c. 38) regulates the private keeping of dangerous wild animals in Great Britain through a local authority licensing system, to protect the public and to safeguard the welfare of the animals. Section 1 makes it an offence to keep an animal of a kind specified in the Schedule without a licence granted by the local authority, and requires the authority, before granting a licence, to be satisfied that it is not contrary to the public interest, that the applicant is a suitable person, and that the animal's accommodation is secure and adequate. Section 2 sets out provisions supplementary to section 1, including the conditions to which a licence is subject, such as insurance and the specification of the premises. Section 3 provides for inspection by the local authority. Section 4 confers a power to seize and to dispose of animals kept without a licence or in breach of a condition, without compensation. Section 5 provides exemptions for zoos, circuses, licensed pet shops, and places registered for scientific research. Section 6 sets the penalties for offences. Section 7 provides the interpretation, and section 8 confers power on the Secretary of State to modify the Schedule of kinds of dangerous wild animals. Section 9 protects existing keepers in defined circumstances. The Act is the foundational regime for the private keeping of dangerous wild animals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-data-protection-act-2018",
    "title": "United Kingdom Data Protection Act 2018 (c. 12) and UK GDPR Framework",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Data Protection Act 2018 (c. 12 - DPA 2018), which received Royal Assent on 23 May 2018, is the United Kingdom's national data protection statute. It operates alongside the UK GDPR (the EU General Data Protection Regulation as retained and modified in UK law following the UK's withdrawal from the European Union, effective 31 December 2020) to form the UK's comprehensive data protection framework. The DPA 2018 exercises the national derogations, exemptions, and supplementary provisions permitted by the GDPR, and establishes the Information Commissioner's Office (ICO) as the national supervisory authority on a statutory basis. Together, the UK GDPR and DPA 2018 form the two-instrument UK data protection framework: the UK GDPR provides the principal obligations on controllers and processors (lawful bases, data subject rights, processor agreements, security, breach notification, international transfers); the DPA 2018 provides: (a) Schedule 1 conditions for processing special category personal data and criminal convictions data (supplementing UK GDPR Articles 9 and 10); (b) Schedule 2 derogations from specific UK GDPR obligations (including for research, public interest, journalism, and national security); (c) Part 3 - a separate Law Enforcement Processing regime (implementing the Law Enforcement Directive 2016/680/EU) for processing by competent authorities for law enforcement purposes; (d) Part 4 - Intelligence Services Processing provisions applicable to security and intelligence agencies; and (e) Part 5 - the ICO's powers and enforcement regime. Schedule 1 of the DPA 2018 specifies conditions for processing sensitive categories of personal data ('special category data' under UK GDPR Article 9) without explicit consent, including: employment, social security, and social protection law obligations (Schedule 1 Para 1); health or social care purposes (Schedule 1 Para 2); public interest in public health (Schedule 1 Para 3); occupational medicine and health (Schedule 1 Para 4); preventive or occupational medicine (Schedule 1 Para 5); scientific or historical research and statistics (Schedule 1 Para 6); archiving in the public interest (Schedule 1 Para 7); journalism, academia, art, and literature (Schedule 1 Para 8); elected representatives (Schedule 1 Para 9); disclosure to elected representatives (Schedule 1 Para 10); and additional conditions in Schedule 1 Part 2. Section 10 of the DPA 2018 incorporates the Schedule 1 conditions. Criminal offences under the DPA 2018 include: Section 170 - unlawful obtaining or disclosing of personal data (up to two years' imprisonment and an unlimited fine); Section 171 - re-identification of de-identified personal data (unlimited fine); Section 173 - altering records to prevent disclosure following a subject access request (unlimited fine). ICO enforcement: the ICO may issue Assessment Notices (audit powers), Information Notices (requiring information from controllers), Enforcement Notices (requiring compliance), and Penalty Notices imposing administrative fines. For the most serious UK GDPR violations (fundamental principles, data subject rights, international transfers), the ICO may impose fines of up to £17.5 million or 4% of global annual turnover (whichever is higher). For other serious violations (controller and processor obligations), fines of up to £8.75 million or 2% of global annual turnover (whichever is higher). Notable ICO enforcement actions include: British Airways - £20 million (2022, reduced from initial £183M notice following COVID-19 consideration, for 2018 data breach); Marriott International - £18.4 million (2022, for 2014-2018 data breach); TikTok Information Technologies UK Limited - £12.7 million (2023, for processing children's data without appropriate consent); the DSA Group - £24 million (2025). International transfers post-Brexit: the UK has established its own adequacy regime under Section 17A-17D of the DPA 2018 (as amended by UK GDPR); the UK Secretary of State may issue adequacy regulations for third countries; the UK has granted adequacy to the EU/EEA, allowing free data flow in both directions. For transfers to non-adequate countries, UK controllers use the UK's International Data Transfer Agreement (IDTA) or the UK Addendum to EU Standard Contractual Clauses.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-retained-gdpr",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-data-protection-act-2018-part-3-law-enforcement",
    "title": "Data Protection Act 2018, PART 3 - Law Enforcement Processing",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Establishes a data protection framework for competent authorities processing personal data for law enforcement purposes, including principles for processing, data subject rights, and controller obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-37-dpo",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-data-protection-act-2018-section-14-automated-decision-making",
    "title": "Data Protection Act 2018 Section 14: Automated individual decision-making, including profiling",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must not make decisions based solely on automated processing that have legal or similarly significant effects on individuals, unless specific conditions are met, and must provide safeguards including the right to human intervention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-data-protection-act-2018-section-144-false-statements-information-notices",
    "title": "UK Data Protection Act 2018 Section 144 - False Statements Made in Response to Information Notices (Knowingly False or Recklessly False Statement, Material Respect Test)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 144 of the Data Protection Act 2018 (c. 12) creates the offence of making false statements in response to an Information Commissioner's information notice. Under section 144, it is an offence for a person, in response to an information notice, (a) to make a statement which the person knows to be false in a material respect, or (b) recklessly to make a statement which is false in a material respect. Section 144 operates as the enforcement teeth supporting the ICO's information-gathering powers under section 142 (information notices) and section 143 (information notice: restrictions on the giving of information). The dual mental-state threshold (knowingly or recklessly) captures both deliberate misstatement and reckless disregard for accuracy; the 'material respect' qualifier limits the offence to statements affecting the substantive matter being investigated. Maximum penalty under section 196 is an unlimited fine on summary conviction (E&W) or indictment - no custodial penalty. Section 144 prosecutions are brought by the ICO and are commonly bundled with separate section 170 (unlawful obtaining of personal data) or UK GDPR enforcement proceedings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_144_text",
        "knowingly_or_recklessly_dual_mental_state_threshold",
        "material_respect_test_narrow_carve_out",
        "information_notices_section_142_supporting_framework",
        "no_custodial_penalty_section_196_unlimited_fine",
        "parallel_perjury_act_1911_for_other_proceedings",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-data-protection-act-2018",
      "uk-data-protection-act-2018-section-170-unlawful-obtaining-personal-data"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-data-protection-act-2018-section-170-unlawful-obtaining-personal-data",
    "title": "UK Data Protection Act 2018 Section 170 - Unlawful Obtaining etc of Personal Data (Without Controller Consent, Knowingly or Recklessly, Selling and Offering to Sell)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 170 of the Data Protection Act 2018 (c. 12) creates the UK criminal offence of unlawful obtaining, disclosure, procurement, or retention of personal data without the consent of the controller, replacing the previous offence in section 55 of the Data Protection Act 1998. Section 170 operates as a criminal-law sister offence to the civil UK GDPR / DPA 2018 enforcement regime administered by the Information Commissioner's Office (ICO) and is the operative offence in prosecutions of insider data theft, blagging (social-engineering of personal data from third parties), commercial data brokering of personal data obtained without lawful basis, and unauthorised retention of personal data after employment ends. Under section 170(1), it is an offence for a person knowingly or recklessly (a) to obtain or disclose personal data without the consent of the controller, (b) to procure the disclosure of personal data to another person without the consent of the controller, or (c) after obtaining personal data, to retain it without the consent of the person who was the controller in relation to the personal data when it was obtained. Under section 170(2), defences require the defendant to prove the conduct (a) was necessary for the purposes of preventing, investigating or detecting crime, (b) was required or authorised by an enactment, by a rule of law or by the order of a court or tribunal, or (c) in the particular circumstances, was justified as being in the public interest. Under section 170(3), additional defences cover reasonable belief in a legal right to obtain, belief that the controller would have consented, and journalistic, academic, artistic or literary purposes justified as being in the public interest. Under section 170(4) and (5), it is a further offence to sell or offer to sell personal data obtained in contravention of subsection (1). The penalty under section 196 is an unlimited fine on summary conviction (E&W) or indictment - this is the only summary-or-either-way DPA criminal offence and a 2017 amendment in the Voyeurism (Offences) Act series consultation strengthened the offences, though no custodial penalty was added. Section 170 prosecutions are typically brought by the ICO in England and Wales and by the Crown Office in Scotland.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_170_text_subsections",
        "knowingly_or_recklessly_mental_state",
        "controller_consent_test_section_170_7",
        "procuring_disclosure_section_170_1_b_blagging",
        "retention_after_obtaining_section_170_1_c_post_employment",
        "selling_data_subsections_170_4_5_6",
        "defences_section_170_2_3_public_interest_journalism",
        "penalty_section_196_no_custodial",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-data-protection-act-2018",
      "uk-data-protection-act-2018-section-172-offence-re-identification"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-data-protection-act-2018-section-171-re-identification-de-identified-data",
    "title": "UK Data Protection Act 2018 Section 171 - Re-identification of De-identified Personal Data (Knowing or Reckless Re-identification, Controller Consent Requirement, Public Interest and Special Purposes Defences)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 171 of the Data Protection Act 2018 (c. 12) creates the criminal offence of re-identifying de-identified personal data without the consent of the controller responsible for de-identifying the data. Under section 171(1), it is an offence for a person knowingly or recklessly to re-identify information that is de-identified personal data without the consent of the controller responsible for de-identifying the personal data. Under section 171(2), 'de-identified' means personal data has been processed in such a manner that it can no longer be attributed, without more, to a specific data subject; 're-identifies' means taking steps which result in the information no longer being de-identified. Defences under section 171(3) cover crime prevention/investigation/detection, statutory authorisation, and public interest. Defences under section 171(4) cover reasonable belief that the person is the data subject or has the data subject's consent (or would have had it), reasonable belief that the person is the controller or has the controller's consent, special purposes journalistic/academic/artistic/literary public interest, and the effectiveness testing condition under section 172. Section 171(5) creates a parallel offence for knowing or reckless processing of re-identified information. Maximum penalty under section 196 is an unlimited fine on summary conviction or indictment - no custodial penalty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_171_text",
        "de_identified_test_section_171_2_a_no_longer_attributable_without_more",
        "re_identifies_test_section_171_2_b_takes_steps_resulting_in_re_identification",
        "knowingly_or_recklessly_dual_mental_state_threshold_section_171_1",
        "section_172_effectiveness_testing_condition_research_carve_out",
        "section_171_5_secondary_processing_offence",
        "penalty_section_196_unlimited_fine_no_custodial",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-data-protection-act-2018",
      "uk-data-protection-act-2018-section-170-unlawful-obtaining-personal-data"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-data-protection-act-2018-section-172-offence-re-identification",
    "title": "Data Protection Act 2018 Section 172: Re-identification of de-identified personal data",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This section establishes a criminal offence for knowingly or recklessly re-identifying personal data that has been de-identified, without the consent of the controller who performed the de-identification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-data-protection-ai-code-of-practice-2026-si-425",
    "title": "UK Data Protection Act 2018 (Code of Practice on AI and Automated Decision-Making) Regulations 2026, SI 2026/425 - ICO Code Duty",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "The Information Commissioner must prepare a code of practice giving guidance on good practice in the processing of personal data under the UK GDPR and the Data Protection Act 2018 (except Part 4) in relation to developing and using artificial intelligence and to automated decision-making, including guidance on the processing of children's personal data, with the consultation panel excluded from any aspect of the code relating to national security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-data-protection-act-2018-part-3-law-enforcement",
      "eu-ai-act-automated-decision-workflows"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "uk-data-use-access-act-2025",
    "title": "UK Data (Use and Access) Act 2025",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The UK Data (Use and Access) Act 2025, which received Royal Assent on June 19, 2025, modernises UK data law by introducing smart data schemes for sector-wide data portability, establishing a trust framework for Digital Verification Services, reforming automated decision-making rules under UK GDPR, creating a list of Recognised Legitimate Interests to simplify processing for specified purposes, and simplifying cookie consent requirements under PECR for low-risk analytics - representing the most significant reform of UK data regulation since the post-Brexit implementation period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/uk-data-use-access-act-2025.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-dpa-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-data-use-access-act-2025-dvs-trust-framework",
    "title": "UK Data (Use and Access) Act 2025 and Digital Verification Services Trust Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2025-06-19",
    "bluf": "The Data (Use and Access) Act 2025 (DUAA) places the UK Digital Verification Services (DVS) Trust Framework on a statutory footing and is administered by the Office for Digital Identities and Attributes (OfDIA) within the Department for Science, Innovation and Technology. The DVS Trust Framework is a rules-based scheme that allows certified digital identity and attribute providers to offer reusable digital identities to public and private relying parties in the United Kingdom. The DUAA establishes the legal basis for the Trust Framework register under Part 2 and confers powers on the Secretary of State to make rules governing certification, supplementary codes, the DVS trust mark, and information-sharing arrangements with public authorities.\n\nThe DVS Trust Framework operates in conjunction with the UK General Data Protection Regulation, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003. Certification under the Trust Framework requires conformity with the DVS Trust Framework rules and adherence to one or more supplementary codes such as the right-to-work, right-to-rent, and Disclosure and Barring Service (DBS) checks supplementary codes. Certified providers are entitled to use the DVS trust mark on relying-party-facing interfaces. The DUAA also amends the Data Protection Act 2018 to permit recognised legitimate interests for crime prevention and safeguarding and modifies the Information Commissioner's role into the Information Commission with an expanded enforcement remit including financial penalties and reprimands.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nist-sp-800-63-4-2025-digital-identity-guidelines",
      "uk-data-protection-act-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-data-use-and-access-act-2025",
    "title": "UK Data (Use and Access) Act 2025 - Smart Data, DVS Trust Framework, UK GDPR/DPA Reform, Information Commission Establishment",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The UK Data (Use and Access) Act 2025 (c. 18) is the post-DPDI legislative reform of UK data law, structured in 8 Parts: Part 1 (sections 1-24) Access to Customer Data and Business Data - UK Smart Data regime including section 2 powers to make Smart Data schemes for sectors beyond financial services, and section 24 repeal of provisions relating to supply of customer data; Part 2 (sections 25-39) Digital Verification Services Trust Framework establishing certified DVS providers; Part 3 National Underground Asset Register; Part 4 Registers of Births and Deaths; Part 5 Data Protection and Privacy with Chapter 1 Data Protection (sections 66-107) reforming the UK GDPR and Data Protection Act 2018 - section 67 meaning of research and statistical purposes; section 70 lawfulness of processing; section 71 purpose limitation; section 74 special categories; section 80 automated decision-making (replacing UK GDPR Article 22 with new safeguards); section 81 data protection by design and children's higher protection; section 85 international transfers framework; section 88 national security exemption; sections 91-93 Commissioner's duties and codes of practice; Chapter 2 Privacy and Electronic Communications updates PECR; Part 6 (sections 117-120) Establishment of the Information Commission, abolishing the office of Information Commissioner and transferring functions and property to a new corporate Information Commission; Part 7 Other provisions including data preservation, online safety links; Part 8 Final provisions. The Act amends UK GDPR and DPA 2018 across Schedules 1-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "uk_data_protection_act_2018",
        "uk_gdpr_2018_post_brexit",
        "uk_pecr_privacy_electronic_communications",
        "eu_psd2_open_banking_api_standards",
        "uk_online_safety_act_2023"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-data-protection-act-2018",
      "uk-online-safety-act-2023",
      "eu-psd2-open-banking-api-standards"
    ],
    "primary_citations_count": 25
  },
  {
    "node_id": "uk-deer-act-1991",
    "title": "UK Deer Act 1991 (c.54): Close Seasons, Poaching and Prohibited Methods",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Deer Act 1991 (c. 54) consolidates the law protecting wild deer in England and Wales, regulating when and how deer may be taken or killed, administered through the courts and enforced by the police. Section 1 creates the offence of poaching of deer, where a person without consent or other lawful authority enters land in search or pursuit of deer with intent to take, kill, or injure them, or takes, kills, or injures deer on the land. Section 2 prohibits the taking or killing of deer of specified species during the close season set out in Schedule 1, and section 3 prohibits the taking or killing of deer at night, that is between the expiry of the first hour after sunset and the beginning of the last hour before sunrise. Section 4 prohibits the use of prohibited weapons and other articles, including any smooth-bore gun, a rifle below a specified calibre, certain ammunition, traps, snares, poisons, and the use of a vehicle to drive deer, with prohibited firearms and ammunition set out in Schedule 2. Section 9 sets the penalties for offences relating to deer, and section 10 creates offences relating to the sale and purchase of venison. Section 12 confers powers of search, arrest, and seizure, and section 13 provides for forfeitures and disqualifications. The Act is the foundational wild deer protection and management regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-defective-premises-act-1972",
    "title": "UK Defective Premises Act 1972: Duty to Build Dwellings Properly and Landlord and Builder Duties of Care",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Defective Premises Act 1972 imposes statutory duties of care in connection with the construction and condition of dwellings in England and Wales, and is a central route to liability for defective construction work. Section 1 imposes a duty on a person taking on work for or in connection with the provision of a dwelling to do the work in a workmanlike or professional manner, with proper materials, so that the dwelling will be fit for habitation when completed; this duty is owed to the person ordering the work and to every person who acquires an interest in the dwelling. Section 2 excludes from the section 1 remedy dwellings covered by an approved scheme (historically the NHBC scheme). Section 2A, inserted by the Building Safety Act 2022, extends duties to work done to existing dwellings (for example refurbishment and remediation), not only to the original provision of a dwelling. Section 3 provides that a duty of care owed in respect of work done on premises is not abated by the subsequent disposal of those premises, so a later owner is not deprived of a remedy. Section 4 imposes on a landlord who is under an obligation or has a right to repair the demised premises a duty of care to see that persons who might reasonably be affected by defects are reasonably safe from personal injury or damage to property. Section 5 applies the Act to the Crown, section 6 contains supplemental provisions including that the duties imposed by the Act cannot be excluded or restricted by any agreement, and section 7 sets the short title, commencement and extent. The Act is a primary statutory foundation for claims arising from defective dwellings and the post-Grenfell remediation regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-defence-security-public-contracts-regulations-2011",
    "title": "United Kingdom Defence and Security Public Contracts Regulations 2011 (SI 2011/1848)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Defence and Security Public Contracts Regulations 2011 (Statutory Instrument 2011/1848) implement EU Directive 2009/81/EC into UK law and govern award of defence and sensitive security contracts by UK contracting authorities. The 65-regulation instrument is structured in 10 Parts: Part 1 establishes general scope and definitions including the general exclusions in Regulation 7; Part 2 covers technical specifications; Part 3 governs award procedures (restricted, negotiated, competitive dialogue, framework agreements); Part 4 governs selection and rejection criteria for economic operators; Part 5 covers contract award criteria, notifications and the mandatory standstill period; Part 6 imposes obligations on taxes, environment, employment, security of information and security of supply; Part 7 sets sub-contracting rules; Part 8 covers statistical reporting and publication of notices; Part 9 provides remedies including declarations of ineffectiveness and standstill periods; Part 10 contains consequential amendments and transitional provisions. Thresholds in Regulation 9 trigger application.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-public-procurement-construction-directive",
      "uk-procurement-act-2023",
      "us-cmmc-2-0-defence-contractors-levels"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-digital-economy-act-2017-digital-government",
    "title": "UK Digital Economy Act 2017 - Digital Government Data Sharing and Service Delivery",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The UK Digital Economy Act 2017 (DEA 2017) establishes a framework for sharing public sector data between government departments to improve service delivery, enables specified public authorities to share civil registration data for public service purposes under Parts 5 and 6, requires government departments to publish single departmental digital plans, and includes provisions on the Government Digital Service (GDS) common technology platforms, automated debt collection, and penalties for unlawful data disclosure of up to two years' imprisonment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-digital-markets-competition-consumers-act-2024",
    "title": "Digital Markets, Competition and Consumers Act 2024 - Strategic Market Status (SMS) Designation, Pro-Competition Interventions, Conduct Requirements and Online Choice Architecture Rules",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-05-24",
    "bluf": "This Act empowers the UK's Competition and Markets Authority (CMA) to designate undertakings with 'Strategic Market Status' (SMS) in digital activities, imposing tailored conduct requirements and pro-competition interventions to manage their market power and ensure fair dealing and open choices for consumers and businesses (Part 1, Chapter 2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fca-consumer-duty-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-digital-markets-competition-consumers-act-2024-dmcc",
    "title": "Digital Markets, Competition and Consumers Act 2024",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The UK Digital Markets, Competition and Consumers Act 2024 establishes a new pro-competition regime for digital markets by designating firms with Strategic Market Status (SMS) and imposing tailored conduct requirements under Part 2. It applies to digital platform companies with substantial and entrenched market power in core platform services, as determined by the Digital Markets Unit (DMU) within the CMA under Section 6. The Act also strengthens consumer enforcement powers and revises merger control thresholds under Sections 49-52.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-markets-act-2022-1925-gatekeepers",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-digital-markets-competition-consumers-act-2024-part-1",
    "title": "Digital Markets, Competition and Consumers Act 2024, Part 1, Chapter 1, Section 1: Overview",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This Part of the Act confers functions on the Competition and Markets Authority (CMA) to regulate competition in digital markets, including designating undertakings, imposing conduct requirements, and enforcing compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-digital-markets-competition-consumers-act-2024-part-1-strategic-market-status",
    "title": "Digital Markets, Competition and Consumers Act 2024 Part 1: Digital Markets",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This Part establishes a regulatory framework for digital markets, conferring functions on the Competition and Markets Authority (CMA) to designate undertakings with strategic market status and impose conduct requirements, pro-competition interventions, and reporting duties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-direct-payments-to-farmers-act-2020",
    "title": "UK Direct Payments to Farmers (Legislative Continuity) Act 2020 (c. 2): Domestic Continuity of CAP Direct Payments",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Direct Payments to Farmers (Legislative Continuity) Act 2020 (c. 2) preserved the European Union Common Agricultural Policy direct payment schemes as domestic law of the United Kingdom for the 2020 claim year, administered by the Secretary of State for Environment, Food and Rural Affairs. Because the relevant European Union direct payment legislation ceased to apply to the United Kingdom on exit day and was not captured by the general retention mechanism for the 2020 scheme year, this short Act was enacted to provide legal continuity so that farmers could continue to receive direct payments in 2020. Section 1 incorporates the relevant Common Agricultural Policy direct payment legislation into domestic law for the 2020 claim year, and section 2 sets out the interpretation and legal status of the incorporated legislation. Section 3 confers a power to make regulations modifying the incorporated legislation, and section 5 provides a power relating to direct payment ceilings for the 2020 year, with section 6 enabling consequential and transitional provision. The Act was a bridging measure pending the comprehensive reform later delivered by the Agriculture Act 2020, and it ensured no gap in farm support during the first year after the United Kingdom left the European Union.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-diverted-profits-tax-2015",
    "title": "UK Diverted Profits Tax 2015 - 31% Charge on Diverted UK Profits",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "UK Diverted Profits Tax (DPT) charges a 31% rate on profits artificially diverted from the UK using contrived arrangements, mainly targeting: (1) foreign companies avoiding a UK permanent establishment through insufficient substance, and (2) UK companies or UK permanent establishments using transactions that lack economic substance to reduce UK taxable profits. HMRC issues a preliminary notice and a charging notice before DPT becomes payable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "uk_corporation_tax",
        "uk_transfer_pricing",
        "beps_action_6",
        "diverted_profits_aus",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-transfer-pricing-tiopa-2010",
      "oecd-beps-action-6-treaty-abuse-mlti-2015",
      "eu-anti-tax-avoidance-directive-atad-1-2016-1164"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-dmcc-2024-part-4-unfair-commercial-practices",
    "title": "UK Digital Markets, Competition and Consumers Act 2024 - Part 4 Chapter 1 Unfair Commercial Practices",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "Part 4 Chapter 1 of the UK Digital Markets, Competition and Consumers Act 2024 (DMCC Act 2024) repeals and replaces the Consumer Protection from Unfair Trading Regulations 2008 with a modernised statutory regime that took effect on 6 April 2025. Section 224 introduces the chapter and section 225 establishes the general prohibition on unfair commercial practices by traders in their dealings with consumers. A commercial practice is unfair if it falls within section 226 (misleading actions - false information or overall deceptive presentation about a product or trader), section 227 (misleading omissions - withholding or unclear presentation of material information needed for an informed transactional decision), section 228 (aggressive practices - harassment, coercion, or undue influence likely to cause the average consumer to take a different transactional decision), section 229 (contravention of the requirements of professional diligence) or section 230 (banned practices listed in Schedule 20, which is a black list of always-unfair practices including bait advertising, fake reviews, false scarcity, persistent unwanted solicitation and pyramid promotional schemes). Section 231 designates the Competition and Markets Authority, Trading Standards in Great Britain, and the Department for the Economy in Northern Ireland as enforcement authorities, with civil and criminal penalties available under Part 4 Chapter 3 - including monetary penalties up to GBP 300,000 or 10% of global group turnover for businesses and direct consumer redress orders. Schedule 20 paragraph 13 specifically bans submitting fake consumer reviews, paying for fake reviews, or publishing reviews without taking reasonable and proportionate steps to ensure they are genuine - this is the first explicit statutory prohibition on fake reviews in UK law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "enforcement_powers",
        "schedule_20_banned_practices",
        "average_consumer_test"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-consumer-protection-from-unfair-trading-2008",
      "eu-unfair-commercial-practices-2005-29",
      "uk-asa-cap-code-2010",
      "uk-cma-green-claims-code-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-dmcc-act-2024-digital-markets-regime",
    "title": "UK Digital Markets, Competition and Consumers Act 2024, DMCC - Strategic Market Status Regime and Pro-Competition Interventions, Effective 1 January 2025",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Undertakings carrying on digital activities in connection with the United Kingdom may be designated as having Strategic Market Status (SMS) by the Competition and Markets Authority (CMA) Digital Markets Unit from 1 January 2025 under the Digital Markets, Competition and Consumers Act 2024 if the CMA estimates that the undertaking or group has global turnover exceeding 25 billion pounds or UK turnover exceeding 1 billion pounds, in which case the CMA may impose conduct requirements addressing one of the three statutory objectives (fair dealing, open choices, trust and transparency), make pro-competition interventions including data portability and interoperability requirements, accept commitments, and enforce against contraventions, with the CMA having launched the first SMS designation investigation in respect of Google general search and search advertising on 14 January 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-ukpga-2000-8-fsma-2000"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-domestic-abuse-act-2021-section-70-non-fatal-strangulation",
    "title": "UK Domestic Abuse Act 2021 Section 70 - Non-Fatal Strangulation or Suffocation",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 70 of the Domestic Abuse Act 2021 inserts Section 75A into the Serious Crime Act 2015, creating a standalone offence of non-fatal strangulation or suffocation. The offence is committed where a person (A) intentionally strangles another person (B), OR does any other act to B that affects B's ability to breathe, AND that act constitutes a battery. Consent to the act is a defence under Section 75A(2) unless serious harm results AND A intended to cause serious harm OR was reckless as to whether serious harm would result. 'Serious harm' includes wounding, grievous bodily harm, actual bodily harm. Penalty: on summary conviction, imprisonment up to general magistrates' court limit and/or fine; on indictment, imprisonment up to 5 years and/or fine. Section 70 closed the gap in domestic abuse cases where strangulation could not be charged proportionately under common assault (insufficient sentence) or ABH/GBH (often unprovable injury).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "section_70_inserts_section_75a_serious_crime_act_2015",
        "core_offence_section_75a_1",
        "consent_defence_with_serious_harm_proviso_section_75a_2_3",
        "serious_harm_definition_section_75a_6",
        "penalty_section_75a_5_summary_or_indictment",
        "extraterritorial_jurisdiction_section_75b_for_uk_nationals_or_residents",
        "no_actual_serious_harm_required_for_offence",
        "context_overturning_consensual_strangulation_for_sexual_gratification",
        "interaction_with_oapa_1861_sections_18_20_47",
        "interaction_with_section_71_consent_to_serious_harm_for_sexual_gratification"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-domestic-abuse-act-2021-section-71-consent-to-serious-harm-sexual-gratification"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-domestic-abuse-act-2021-section-71-consent-to-serious-harm-sexual-gratification",
    "title": "UK Domestic Abuse Act 2021 Section 71 - Consent to Serious Harm for Sexual Gratification Not a Defence",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 71 of the Domestic Abuse Act 2021 codifies that a person ('D') cannot consent to the infliction of serious harm for the purposes of obtaining sexual gratification, and accordingly such purported consent is not a defence in any proceedings for a relevant offence. 'Serious harm' means actual bodily harm, wounding, or grievous bodily harm within the meaning of the OAPA 1861. 'Relevant offence' is narrowly defined as an offence under section 18, 20 or 47 of the Offences Against the Person Act 1861 only. Section 71 puts the so-called 'rough sex defence' beyond legal use - statutorily reversing R v Slingsby and aspects of the R v Brown line of authority where extreme sexual harm was treated as consensual.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_rule_subsection_1",
        "exception_for_sexually_transmitted_infection_subsection_2",
        "serious_harm_definition_subsection_3_a_b_c",
        "relevant_offence_definition_subsection_3",
        "purpose_overturns_rough_sex_defence_case_law",
        "exception_for_sti_consent_recognised_consensual_risk",
        "non_fatal_offences_focus_not_murder_or_manslaughter",
        "interaction_with_section_76_serious_crime_act_2015_controlling_coercive_behaviour",
        "interaction_with_homicide_offences"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-1-rape"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-dpa-2018",
    "title": "Data Protection Act 2018",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The UK Data Protection Act 2018 (DPA 2018) governs the processing of personal data in the UK, supplementing and tailoring the UK General Data Protection Regulation (UK GDPR). It applies to data controllers and processors, setting out data protection principles, rights for individuals, and rules for law enforcement and intelligence services processing, as established in Part 2, Section 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "eu-standard-contractual-clauses-2021",
      "gdpr-adequacy-decisions-article-45"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-dprk-sanctions-eu-exit-regulations-2019-si-411",
    "title": "UK Democratic People's Republic of Korea (Sanctions) (EU Exit) Regulations 2019 SI 2019/411 Comprehensive Asset Freeze Ship Specification Trade and Aircraft Sanctions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Democratic People's Republic of Korea (Sanctions) (EU Exit) Regulations 2019 implement the UK comprehensive sanctions regime against the DPRK organised in 13 parts covering general provisions in Part 1, designation power and criteria in Part 2 with regulation 6 criteria and regulation 7 ownership and control rules supported by Schedule 1, ship specification under Part 3, financial restrictions in Part 4 across three chapters covering asset freezes on designated persons funds and economic resources restrictions on credit institutions investment banking relationships and financial transactions and interpretation and circumvention provisions, immigration restrictions in Part 5 regulation 34, Part 6 trade across four chapters covering military goods dual-use items WMD-related technology general goods and services relating to ships and aircraft, aircraft movement restrictions in Part 7 with regulation 65 restrictions and regulation 67 offences, comprehensive ship restrictions covering DPRK vessel ownership port entry and transfers in Part 8, exceptions and licensing for Treasury trade aircraft and ships in Part 9, and information requirements enforcement maritime enforcement powers and supplementary measures in Parts 10 to 13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-drc-sanctions-eu-exit-regulations-2019-si-433",
    "title": "UK Democratic Republic of the Congo (Sanctions) (EU Exit) Regulations 2019 SI 2019/433 UN Implementation Asset Freeze Military Goods and Armed Hostilities Restrictions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Democratic Republic of the Congo (Sanctions) (EU Exit) Regulations 2019 establish the United Kingdom's framework implementing the UN Security Council DRC sanctions regime organised in 10 parts covering general provisions in Part 1, designation power and criteria in Part 2 with regulation 5 designation power regulation 6 designation criteria regulation 7 ownership and control regulation 8 notification and regulation 10 UN Security Council direct designations, financial restrictions in Part 3 including regulation 12 asset freeze regulations 13 to 14 prohibitions on making funds available regulations 15 to 16 economic resources restrictions and regulation 17 circumvention offences, immigration restrictions in regulation 18 in Part 4, Part 5 trade across four chapters covering definitions of military goods and technology export and supply restrictions technical assistance and financial services prohibitions enabling armed hostilities and circumvention defences, exceptions and licences in Part 6 including regulation 31 financial exceptions regulation 32 national security and crime prevention carve-out and regulations 33 to 38 licensing mechanisms, and information reporting enforcement maritime enforcement and supplementary provisions in Parts 7 to 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-economic-crime-corporate-transparency-act-2023",
    "title": "UK Economic Crime and Corporate Transparency Act 2023 (c. 56): Companies House Reform, Identity Verification and the Failure to Prevent Fraud Offence",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Economic Crime and Corporate Transparency Act 2023 (c. 56) overhauls the United Kingdom's corporate transparency regime to bear down on the abuse of corporate structures for economic crime, reforming the role of the registrar of companies, introducing identity verification, strengthening the register of overseas entities, expanding cryptoasset confiscation, and creating a new corporate offence of failure to prevent fraud, administered by Companies House and prosecuted by authorities including the Serious Fraud Office. Part 1 reforms company law: section 4 requires identity verification of proposed officers and section 7 requires identity verification of persons with initial significant control, with a dedicated identity verification framework that makes the registrar a more active gatekeeper. Part 3 amends the register of overseas entities created by the Economic Crime (Transparency and Enforcement) Act 2022; section 157 expands the required information about overseas entities and their beneficial owners. Part 4 addresses cryptoassets: section 179 extends confiscation orders to cryptoassets and section 180 extends civil recovery to cryptoassets. Part 5 contains miscellaneous provisions including section 194 on striking out strategic litigation against public participation, and the new corporate criminal offence in section 199 of failure to prevent fraud, which under section 201 applies to large organisations and is subject to a reasonable-procedures defence. The Act is a foundational statute for UK corporate transparency and economic-crime prevention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-education-act-1996",
    "title": "United Kingdom Education Act 1996: Parental Duty to Secure Education, Pupils Educated in Accordance with Parents' Wishes, Local Authority Functions, Pupil Referral Units, Special Educational Needs, and School Attendance Offences",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The United Kingdom Education Act 1996, chapter 56 of 1996, is the principal consolidating United Kingdom statute governing the school system in England and Wales and is administered by the Secretary of State for Education through local authorities and the Department for Education. Part I sets out general provisions about education and its administration. Education Act 1996, section 7 imposes the duty of parents to secure the education of children of compulsory school age and provides that the parent of every child of compulsory school age shall cause that child to receive efficient full-time education suitable to age, ability and aptitude either by regular attendance at school or otherwise. Education Act 1996, section 9 requires pupils to be educated in accordance with parents' wishes so far as compatible with the provision of efficient instruction and training and the avoidance of unreasonable public expenditure. Education Act 1996, Part II governs the school system including maintained county and voluntary schools, their establishment, governance, funding, and discontinuance. Education Act 1996, section 14 sets out the functions of local education authorities regarding primary and secondary school provision. Education Act 1996, Part IV governs special educational needs. Education Act 1996, section 19 authorises exceptional provision of education in pupil referral units. Education Act 1996, section 312 defines special educational needs. Education Act 1996, Part V governs school attendance and the operation of schools. Education Act 1996, section 437 addresses school attendance orders. Education Act 1996, section 444 creates the offence of failing to secure the regular attendance of a registered pupil. Parts VI through X cover financial support, miscellaneous matters and general provisions. The Act is the controlling United Kingdom consolidating instrument for the school system in England and Wales.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-education-act-2002",
    "title": "United Kingdom Education Act 2002: Power to Suspend Statutory Requirements, Schools' Workforce, School Inspections, Governance, National Curriculum in England (Balanced Curriculum), and Safeguarding Duties",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The United Kingdom Education Act 2002, chapter 32 of 2002, is a principal United Kingdom statute reforming and supplementing the school system in England and Wales and operates alongside the Education Act 1996 and the School Standards and Framework Act 1998. Education Act 2002, Part 1 establishes powers for educational innovation including the authority to suspend statutory requirements and exemptions for high-performing schools. Education Act 2002, Part 2 governs the schools' workforce. Education Act 2002, Part 3 governs school inspections. Education Act 2002, Part 4 governs the governance and conduct of maintained schools in England and Wales, including school governing bodies, staff responsibilities, and budget determination. Education Act 2002, Part 6 establishes the curriculum framework in England. Education Act 2002, section 78 requires that the curriculum for a maintained school be a balanced and broadly based curriculum which promotes the spiritual, moral, cultural, mental and physical development of pupils at the school and of society, and prepares pupils for the opportunities, responsibilities and experiences of later life. Education Act 2002, section 82 provides for the National Curriculum, and Education Act 2002, section 87 sets the curriculum for the first, second, third and fourth key stages in England. Education Act 2002, Part 8 covers teachers including pay and conditions through the School Teachers' Review Body, qualified teacher status, induction periods, and misconduct procedures. Education Act 2002, Part 11 contains miscellaneous and general provisions including the central safeguarding provisions. Education Act 2002, section 175 requires local authorities and governing bodies to make arrangements for ensuring that their functions are exercised with a view to safeguarding and promoting the welfare of children. Education Act 2002, section 176 requires consultation with pupils on matters affecting their education. The Act is the controlling instrument for these reforms in England and Wales.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-education-act-2011-academies-governance",
    "title": "Education Act 2011 - No Substantive Provisions Provided",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The provided text is a title page for the Education Act 2011 and does not contain any specific, actionable compliance obligations regarding academy governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-eia-regulations-2017-town-country-planning",
    "title": "The Town and Country Planning (Environmental Impact Assessment) Regulations 2017",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2024-05-16",
    "bluf": "These regulations require developers of certain types of projects ('Schedule 1' or 'Schedule 2' developments) to carry out an Environmental Impact Assessment (EIA) before planning permission may be granted. The process involves screening to determine if an EIA is needed, scoping to define the assessment's extent, and preparing a comprehensive Environmental Statement (ES) detailing the project's likely significant environmental effects, as mandated by Part 4 and Regulation 18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate-related-disclosures",
      "iso-14064-ghg-reporting-2018"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-electricity-act-1989",
    "title": "UK Electricity Act 1989 - Electricity Supply Licensing and Ofgem Regulatory Framework",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "No person may generate, transmit, distribute, or supply electricity in Great Britain without a licence granted under Section 6 of the Electricity Act 1989, except under an exemption. Ofgem (the Gas and Electricity Markets Authority) enforces licence conditions and may issue provisional or final orders compelling compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "gas_act",
        "energy_act_2013",
        "energy_act_2023",
        "ofgem_licence_conditions",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-ofgem-supply-licence-conditions-2024",
      "uk-energy-security-investment-mechanism-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-electricity-act-1989-generation-supply-licence",
    "title": "UK Electricity Act 1989 - Generation, Transmission, Distribution and Supply Licences and Ofgem Standard Licence Conditions",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK Electricity Act 1989 prohibits the generation, transmission, distribution, or supply of electricity without a licence granted by the Gas and Electricity Markets Authority (Ofgem), as mandated by Section 4. Licence holders must comply with specific conditions set by Ofgem to ensure a secure, sustainable, and competitive energy market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "nist-ir-7628-smart-grid-cybersecurity",
      "uk-fca-consumer-duty-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-electronic-communications-act-2000",
    "title": "UK Electronic Communications Act 2000 - Electronic Signatures and Digital Transactions",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Electronic Communications Act 2000 (c.7) provides the legal foundation for electronic signatures in UK law and grants the Secretary of State power to modify legislation to facilitate electronic communications and storage. Section 7 makes electronic signatures admissible as evidence of the authenticity and integrity of electronic communications and data. Section 8 enables modification of existing legislation to allow use of electronic communications where previously paper was required. The Act aligns with the EU Electronic Signatures Directive 1999/93/EC. Electronic Signature Regulations 2002 (SI 2002/318) implement the EU eSignatures Directive standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_eidas_retained",
        "electronic_signature_regulations_2002",
        "australia_eta_1999",
        "us_esign_act_2000",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-electronic-transactions-act-1999",
      "us-esign-act-2000-electronic-signatures",
      "eu-eidas-trust-services-telecoms-910-2014"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-electronic-money-regulations-2011-regulation-19-safeguarding",
    "title": "UK Electronic Money Regulations 2011 Regulation 19 Safeguarding Requirements",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "UK SI 2011/99 Regulation 19 requires electronic money institutions (EMIs) to safeguard funds received in exchange for e-money using one of two FCA-approved methods: segregation into a designated account at an authorised credit institution invested in approved liquid assets, or coverage by an approved insurance policy or guarantee - with safeguarded funds ranking above other creditors in insolvency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "psd2-directive-article-66-liability-of-payment-service-providers"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-employment-rights-act-1996",
    "title": "UK Employment Rights Act 1996: Employment Particulars, Unfair Dismissal, Whistleblowing and Redundancy",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Employment Rights Act 1996 is the principal UK statute consolidating individual employment rights, enforced largely through the employment tribunals. Section 1 requires the employer to give a worker a written statement of the initial particulars of employment. Section 8 requires an itemised pay statement. Section 13 confers the right not to suffer unauthorised deductions from wages. Sections 43A and 43B contain the whistleblowing regime: section 43A defines a protected disclosure and section 43B sets out the disclosures that qualify for protection (the public-interest disclosure of categories such as criminal offences, breaches of legal obligation, health and safety dangers and environmental damage), with subsequent sections specifying the persons to whom a protected disclosure may be made. Section 86 sets the minimum periods of notice to which an employer and employee are entitled. Section 94 confers the central right of an employee not to be unfairly dismissed, and section 98 sets out how the fairness of a dismissal is determined, requiring a potentially fair reason and a fair process. Section 135 confers the right to a redundancy payment on a qualifying employee who is dismissed by reason of redundancy. The Act is the legal foundation of UK individual employment protection, including unfair dismissal, whistleblowing and redundancy rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-employment-rights-act-1996-part-10-unfair-dismissal",
    "title": "Employment Rights Act 1996, Part X",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This act outlines employee rights concerning unfair dismissal; however, the specific regulatory text for Part X was not provided for extraction, preventing the identification of explicit compliance obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-employment-rights-act-1996-section-100-health-safety-automatically-unfair-dismissal",
    "title": "UK Employment Rights Act 1996 Section 100 - Health and Safety Cases Automatically Unfair Dismissal (Five Protected Categories, Serious Imminent Danger, Negligence Carve-out)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 100 of the Employment Rights Act 1996 (c. 18) provides automatic unfair dismissal protection where the reason or principal reason for dismissal relates to a protected health and safety activity by the employee - no two-year qualifying service is required and interim relief under section 128 is available. Under section 100(1), an employee who is dismissed shall be regarded as unfairly dismissed if the reason (or principal reason) is that the employee (a) carried out (or proposed to carry out) any activities in connection with preventing or reducing risks to health and safety at work having been designated by the employer to carry out such activities, (b) being a workers' representative on H&S matters performed (or proposed to perform) any functions as such a representative or member of a safety committee, (c) being in a workplace without such a representative or committee, brought to the employer's attention (by reasonable means) circumstances connected with work which the employee reasonably believed were harmful or potentially harmful, (d) left (or proposed to leave) or while danger persisted refused to return to his place of work or any dangerous part of it in circumstances of danger which the employee reasonably believed to be serious and imminent and which he could not reasonably have been expected to avert, or (e) in circumstances of danger which the employee reasonably believed to be serious and imminent, took (or proposed to take) appropriate steps to protect himself or other persons from the danger. Under section 100(2), 'appropriate steps' is assessed considering all the circumstances including in particular the employee's knowledge and facilities and advice available. Under section 100(3), a section 100(1)(e) dismissal is not unfair if the employer shows that it was (or would have been) so negligent for the employee to take the steps as a reasonable employer might have dismissed him.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_100_text",
        "five_protected_categories_section_100_1_a_to_e",
        "serious_and_imminent_danger_test_section_100_1_d_e",
        "negligence_carve_out_section_100_3_for_section_100_1_e_only",
        "no_qualifying_service_and_interim_relief_under_section_128",
        "remedy_uplift_potential_with_smcr_and_other_overlays",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-employment-rights-act-1996-section-94-right-not-to-be-unfairly-dismissed",
      "uk-employment-rights-act-1996-section-43a-protected-disclosure",
      "uk-health-and-safety-at-work-act-1974-section-2-employer-general-duties"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-employment-rights-act-1996-section-103a-protected-disclosure-automatically-unfair",
    "title": "UK Employment Rights Act 1996 Section 103A - Protected Disclosure Dismissal Automatically Unfair (Day-One Protection, Interim Relief Available, No Compensatory Cap)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 103A of the Employment Rights Act 1996 (c. 18), inserted by Public Interest Disclosure Act 1998 section 5, establishes automatic unfair dismissal protection for workers who make protected disclosures (whistleblowing) - the operative dismissal protection provision in the UK whistleblower protection regime. Section 103A reads: 'An employee who is dismissed shall be regarded for the purposes of this Part as unfairly dismissed if the reason (or, if more than one, the principal reason) for the dismissal is that the employee made a protected disclosure.' The provision creates automatic unfair dismissal status without need for the section 98(4) reasonableness analysis - if causation between protected disclosure and dismissal is established, the dismissal is unfair. Section 103A protection is enhanced by: (i) section 108(3)(ff) exemption from two-year qualifying service - day-one protection; (ii) section 128 interim relief availability - ET can order continuation of employment pending full hearing; (iii) section 124(1A) no cap on compensatory award - normal section 124 cap (52 weeks gross pay or statutory cap) does not apply; (iv) injury to feelings recoverable per Virgo Fidelis Senior School v Boyle [2004]. The PIDA 1998 framework operates through ERA 1996 sections 43A-43L (qualifying disclosure and procedural pathways) and section 47B (detriment protection for workers).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_103a_text",
        "causation_test_principal_reason_or_one_of_reasons",
        "no_qualifying_service_section_108_3_ff",
        "interim_relief_section_128_powerful_protective_mechanism",
        "no_compensatory_cap_section_124_1a",
        "injury_to_feelings_virgo_fidelis_recoverable_under_section_47b_overlap",
        "fca_sysc_18_smcr_overlay_for_financial_services",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-employment-rights-act-1996-section-43a-protected-disclosure",
      "uk-employment-rights-act-1996-section-94-right-not-to-be-unfairly-dismissed",
      "uk-employment-rights-act-1996-section-98-general-fairness-test-dismissal"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-employment-rights-act-1996-section-13-unauthorised-deductions-wages",
    "title": "UK Employment Rights Act 1996 Section 13 — Right Not to Suffer Unauthorised Deductions from Wages",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "An employer must not make any deduction from a worker's wages unless the deduction is required or authorised by statute, by a relevant written provision of the worker's contract notified before the deduction, or by the worker's prior written consent. Underpayments below properly payable wages are treated as deductions, except where caused by employer computational error. Workers may bring an Employment Tribunal claim under sections 23-24 to recover any unlawful deduction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_authorisation_required",
        "contractual_authorisation_pre_notified",
        "prior_written_consent_required",
        "underpayment_treated_as_deduction",
        "employer_computation_error_exception",
        "no_retroactive_authorisation_via_variation",
        "tribunal_remedy_pathway"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-employment-rights-act-1996-section-94-right-not-to-be-unfairly-dismissed",
      "uk-employment-rights-act-1996-section-86-minimum-notice-periods"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-employment-rights-act-1996-section-43a-protected-disclosure",
    "title": "UK Employment Rights Act 1996 Section 43A - Protected Disclosure Definition (Whistleblower Protection Foundational Provision, Qualifying Disclosure, Sections 43C-43H Procedural Pathways)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 43A of the Employment Rights Act 1996 (c. 18), inserted by Public Interest Disclosure Act 1998 section 1, provides the foundational definition for UK whistleblower protection. Under section 43A, a 'protected disclosure' means a qualifying disclosure (as defined by section 43B) which is made by a worker in accordance with any of sections 43C to 43H. The protected disclosure framework operates through Part IVA of the Employment Rights Act 1996 (sections 43A to 43L) and connects to the substantive protections under section 47B (worker subjected to detriment) and section 103A (automatically unfair dismissal). A 'qualifying disclosure' under section 43B is a disclosure of information which, in the reasonable belief of the worker making it, tends to show one of six categories of wrongdoing - criminal offence, breach of legal obligation, miscarriage of justice, endangerment of health or safety, environmental damage, or deliberate concealment of any of these. The procedural pathways in sections 43C-43H establish progressively broader categories of permissible recipient: 43C (employer or by employer's procedure), 43D (legal adviser), 43E (Minister of the Crown), 43F (prescribed person), 43G (other cases - more demanding test), 43H (exceptionally serious cases).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_43a_text",
        "section_43b_qualifying_disclosure_six_categories",
        "public_interest_test_post_2013_amendments",
        "procedural_pathways_sections_43c_to_43h",
        "remedies_section_47b_detriment_section_103a_dismissal",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-employment-rights-act-1996-section-86-minimum-notice-periods",
    "title": "UK Employment Rights Act 1996 Section 86 - Rights of Employer and Employee to Minimum Notice (Statutory Notice Floor, Service-Based Escalation, Conduct Termination Reserved)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 86 of the Employment Rights Act 1996 (c. 18) establishes the foundational UK statutory minimum notice periods for termination of employment - the floor below which contractual provisions cannot operate. Under section 86(1), the notice required to be given by an employer to terminate the contract of employment of a person who has been continuously employed for one month or more shall be (a) not less than one week's notice if his period of continuous employment is less than two years, (b) not less than one week's notice for each year of continuous employment if his period of continuous employment is two years or more but less than twelve years, and (c) not less than twelve weeks' notice if his period of continuous employment is twelve years or more. Under section 86(2), the notice required to be given by an employee who has been continuously employed for one month or more to terminate his contract of employment shall be not less than one week. Under section 86(3), subsections (1) and (2) apply notwithstanding any provision to the contrary in the contract of employment, although they do not prevent either party from waiving notice or from accepting payment in lieu. Under section 86(4), contracts of one month or less for workers continuously employed for three months or more are treated as indefinite-period contracts making subsections (1)-(2) applicable. Section 86(6) preserves the right of either party to terminate the contract without notice by reason of the conduct of the other party (summary dismissal).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_86_text",
        "service_based_escalation_section_86_1_a_b_c",
        "contractual_notice_superseding_section_86_floor",
        "payment_in_lieu_of_notice_pilon_section_86_3_treatment",
        "summary_dismissal_section_86_6_gross_misconduct_basis",
        "section_86_4_short_term_contract_anti_avoidance",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-employment-rights-act-1996-section-94-right-not-to-be-unfairly-dismissed",
      "uk-employment-rights-act-1996-section-98-general-fairness-test-dismissal"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-employment-rights-act-1996-section-94-right-not-to-be-unfairly-dismissed",
    "title": "UK Employment Rights Act 1996 Section 94 - Right Not to Be Unfairly Dismissed (Foundational Employee Right, Subject to Qualifying Conditions and TULRA Exceptions)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 94 of the Employment Rights Act 1996 (c. 18) establishes the foundational UK statutory right not to be unfairly dismissed - the gateway right that underpins the entire Part X unfair dismissal regime. Under section 94(1), an employee has the right not to be unfairly dismissed by his employer. Under section 94(2), sections 108 to 110 contain provisions about the right and section 109 contains exclusions relating to the right. The right is subject to qualifying conditions, principally the section 108 two-year continuous employment requirement for ordinary unfair dismissal claims, with exceptions for automatically unfair dismissal grounds under sections 99-105 (no qualifying period required). Section 94 operates in conjunction with sections 95 (circumstances in which an employee is dismissed), 97 (effective date of termination), 98 (general fairness test), and the remedies in sections 111-126. The right is enforced through the Employment Tribunal under section 111. The Trade Union and Labour Relations (Consolidation) Act 1992 sections 152, 153, 238 and 238A operate as further qualifications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_94_text",
        "qualifying_conditions_section_108_two_year_threshold",
        "section_95_circumstances_of_dismissal_definition",
        "automatically_unfair_dismissals_sections_99_105",
        "remedies_section_113_reinstatement_re_engagement_compensation",
        "acas_early_conciliation_pre_claim_requirement",
        "constructive_dismissal_section_95_1_c_western_excavating",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-employment-rights-act-1996-section-98-general-fairness-test-dismissal",
      "uk-employment-rights-act-1996-section-43a-protected-disclosure"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-employment-rights-act-1996-section-95-circumstances-dismissal-defined",
    "title": "UK Employment Rights Act 1996 Section 95 — Circumstances in Which an Employee Is Dismissed",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "For unfair dismissal purposes under Part X, an employee is 'dismissed' only where the employer terminates the contract (with or without notice), where a limited-term contract terminates without renewal, or where the employee resigns in response to a fundamental breach by the employer (constructive dismissal). A counter-notice by the employee within the employer's notice period to leave earlier still counts as a dismissal by the employer for the same reason.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "employer_termination_with_or_without_notice",
        "limited_term_contract_expiry_without_renewal",
        "constructive_dismissal_employer_repudiatory_breach",
        "counter_notice_during_employer_notice_period",
        "limited_term_contract_definition",
        "subsection_2_qualifies_subsection_1",
        "gateway_to_part_x_unfair_dismissal_protection"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-employment-rights-act-1996-section-94-right-not-to-be-unfairly-dismissed",
      "uk-employment-rights-act-1996-section-98-general-fairness-test-dismissal",
      "uk-employment-rights-act-1996-section-86-minimum-notice-periods"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-employment-rights-act-1996-section-98-general-fairness-test-dismissal",
    "title": "UK Employment Rights Act 1996 Section 98 - General Fairness Test for Dismissal (Five Potentially Fair Reasons, Band of Reasonable Responses, Equity and Substantial Merits)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 98 of the Employment Rights Act 1996 (c. 18) establishes the foundational UK statutory unfair dismissal test - the two-stage analysis applied by Employment Tribunals to every ordinary unfair dismissal claim. Under section 98(1), in determining whether a dismissal is fair or unfair, it is for the employer to show (a) the reason (or, if more than one, the principal reason) for the dismissal, and (b) that it is either a reason falling within subsection (2) or some other substantial reason of a kind such as to justify the dismissal. Section 98(2) lists the four potentially fair categories of reason: (a) relates to the capability or qualifications of the employee for performing work of the kind which he was employed to do, (b) relates to the conduct of the employee, (c) is that the employee was redundant, or (d) is that the employee could not continue to work in the position which he held without contravention of a duty or restriction imposed by or under an enactment. Section 98(3) defines 'capability' (skill, aptitude, health or any other physical or mental quality) and 'qualifications' (degree, diploma or other academic, technical or professional qualification relevant to the position). Section 98(4) sets the substantive fairness test - whether the employer acted reasonably or unreasonably in treating the reason as sufficient to dismiss; determined in accordance with equity and the substantial merits of the case (the British Home Stores v Burchell [1980] band of reasonable responses standard). Section 98(6) cross-references TULRA 1992 sections 152, 153, 238, 238A (industrial action and trade union dismissals).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_98_text",
        "two_stage_test_burchell_iceland",
        "capability_section_98_2_a_health_and_performance",
        "conduct_section_98_2_b_burchell_investigation_standard",
        "redundancy_section_98_2_c_williams_v_compair_maxam",
        "some_other_substantial_reason_sosr_section_98_1_b",
        "qualifying_conditions_section_108_and_one_year_two_year_thresholds",
        "remedies_section_113_reinstatement_re_engagement_compensation",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-employment-rights-act-1996-section-99-leave-family-reasons-automatically-unfair",
    "title": "UK Employment Rights Act 1996 Section 99 - Leave for Family Reasons Automatically Unfair Dismissal (Pregnancy, Maternity, Paternity, Adoption, Shared Parental, Carer's, Parental Leave Categories)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 99 of the Employment Rights Act 1996 (c. 18) provides automatic unfair dismissal protection where the reason or principal reason for dismissal is of a prescribed kind relating to family leave or the dismissal takes place in prescribed circumstances - no two-year qualifying service required. Under section 99(1), an employee who is dismissed shall be regarded as unfairly dismissed if (a) the reason or principal reason for the dismissal is of a prescribed kind, or (b) the dismissal takes place in prescribed circumstances. Under section 99(2), 'prescribed' means prescribed by regulations made by the Secretary of State. Under section 99(3), a reason or set of circumstances prescribed must relate to: (a) pregnancy, childbirth or maternity, (aa) time off under section 57ZE (paternity leave), (ab) time off under section 57ZJ or 57ZL (paternity leave on adoption), (b) ordinary, compulsory or additional maternity leave, (ba) ordinary or additional adoption leave, (bb) shared parental leave, (bc) carer's leave, (c) parental leave, (ca) paternity leave, (cb) parental bereavement leave, (cc) neonatal care leave, or (d) time off under section 57A (dependant emergency leave); and may also relate to redundancy or other factors. The principal regulations are the Maternity and Parental Leave etc. Regulations 1999 (SI 1999/3312) and related family-leave regulations. The protection extends parallel to Equality Act 2010 sections 4, 17-18 (pregnancy and maternity discrimination).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_99_text",
        "prescribed_categories_section_99_3_a_to_d",
        "maternity_and_parental_leave_regulations_1999_regulation_20",
        "pregnancy_and_maternity_discrimination_parallel_equality_act_2010_section_18",
        "no_qualifying_service_section_108_3_b_exemption",
        "redundancy_in_section_99_3_d_context",
        "remedies_no_interim_relief_under_section_128",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-employment-rights-act-1996-section-94-right-not-to-be-unfairly-dismissed",
      "uk-equality-act-2010"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-employment-rights-act-2025-part-1",
    "title": "Employment Rights Act 2025 (c. 36), Part 1 Zero Hours Workers, Statutory Sick Pay, Flexible Working and Unfair Dismissal Reform",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "The Employment Rights Act 2025 reforms core UK employment protections, creating a right to guaranteed hours for zero hours workers, rights to reasonable notice of shifts, and payment for cancelled, moved and curtailed shifts. It removes the statutory sick pay waiting period, strengthens the right to request flexible working, and changes the unfair dismissal qualifying period and compensation regime. Part 5 provides for enforcement of labour market legislation by the Secretary of State. Employers must update contracts, scheduling, sick pay and dismissal practices to comply.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-employment-rights-act-1996-part-10-unfair-dismissal",
      "uk-employment-rights-act-1996-section-94-right-not-to-be-unfairly-dismissed"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-energy-act-2008",
    "title": "UK Energy Act 2008 - Offshore Energy Licensing, Nuclear Decommissioning, and Renewable Obligations",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Energy Act 2008 introduces: mandatory funded decommissioning programmes for new nuclear power stations; offshore gas storage and unloading facility licensing; extensions to the Renewable Obligation covering offshore wind and wave energy in the UK Renewable Energy Zone; and Energy Administration to manage energy company insolvency protecting security of supply.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "electricity_act_1989",
        "energy_act_2023",
        "nda",
        "offshore_petroleum",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-electricity-act-1989",
      "uk-energy-security-investment-mechanism-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-energy-act-2013",
    "title": "UK Energy Act 2013: Electricity Market Reform, Emissions Performance Standard and the ONR",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Energy Act 2013 is a central pillar of UK electricity-market and nuclear regulation, introducing Electricity Market Reform, an Emissions Performance Standard, and the statutory Office for Nuclear Regulation, with functions exercised by the Secretary of State, the Low Carbon Contracts Company, Ofgem and the ONR. Part 2 Chapter 2 establishes Contracts for Difference: section 6 confers the power to make regulations to encourage low-carbon electricity generation through long-term contracts that stabilise generator revenues. Part 2 Chapter 3 establishes the Capacity Market: section 27 confers the power to make electricity capacity regulations to ensure security of supply through capacity agreements and auctions. Part 2 Chapter 8 contains the Emissions Performance Standard: section 57 imposes a duty not to exceed an annual carbon dioxide emissions limit on fossil-fuel generating stations, section 58 provides an exemption to enable carbon capture and storage, and section 59 allows suspension in exceptional circumstances. Part 3 establishes the Office for Nuclear Regulation as a statutory body: section 77 establishes the ONR, and the surrounding provisions set its purposes covering nuclear safety, nuclear security, nuclear safeguards and conventional health and safety on nuclear sites. Part 6 addresses consumer protection, including section 139 on the power to modify energy supply licences in relation to domestic supply contracts. The Act is a legal foundation of the UK low-carbon electricity framework and independent nuclear regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-energy-act-2023",
    "title": "Energy Act 2023",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-10-26",
    "bluf": "This Act establishes a new independent Future System Operator (FSO) to oversee the UK's electricity and gas systems, creates regulatory frameworks for carbon capture usage and storage (CCUS) and low-carbon hydrogen production, and introduces heat network zoning to facilitate the transition to net zero. Key provisions under Part 5, Section 114 establish the FSO's objectives, including promoting the net zero target and ensuring system security and economy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-energy-security-investment-mechanism-2024",
    "title": "UK Energy Security Investment Mechanism 2024 - Electricity Generator Levy Trigger Price, Investor Certainty Provisions and Renewables Exemption",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-03-27",
    "bluf": "This mechanism provides investor certainty by establishing a price floor for the Electricity Generator Levy (EGL); if the average wholesale electricity price falls below a set trigger price for two consecutive quarters, the EGL will be permanently disapplied. This applies to UK electricity generating companies subject to the EGL, as defined in the Energy (Oil and Gas) Profits Levy Act 2022.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-paris-agreement-ndc-implementation-guidelines",
      "iso-14001-ems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-enterprise-act-2002-merger-cma-control",
    "title": "Enterprise Act 2002 - Merger Control: Substantial Lessening of Competition Test, CMA Phase 1 and 2 Reviews, Remedies and Public Interest Cases",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The UK Enterprise Act 2002 requires parties to notify the Competition and Markets Authority (CMA) of qualifying mergers that may result in a substantial lessening of competition (SLC) in any market in the UK, under Section 22. The CMA conducts Phase 1 and Phase 2 reviews to assess competitive impact and may impose remedies or block transactions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-merger-regulation-139-2004-ecmr",
      "us-doj-ftc-merger-guidelines-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-enterprise-act-2002-merger-control",
    "title": "UK Enterprise Act 2002 - Merger Control: Substantial Lessening of Competition (SLC) Test, CMA Phase 1 (25 Working Days)/Phase 2 Review, Jurisdictional Thresholds and Divestiture Remedies",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK Enterprise Act 2002 empowers the Competition and Markets Authority (CMA) to review mergers that meet specific jurisdictional thresholds to assess whether they may result in a substantial lessening of competition (SLC) within any UK market, as mandated by Part 3 of the Act (Sections 22 and 35). Transactions meeting the turnover or share of supply tests are subject to potential Phase 1 and in-depth Phase 2 investigations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-merger-regulation-139-2004-ecmr",
      "us-hart-scott-rodino-hsr-premerger-notification"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-enterprise-act-2002-part-4-market-investigations-cma",
    "title": "Enterprise Act 2002 Part 4: Market Studies and Market Investigations",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This regulation establishes the framework for conducting market studies and market investigations in the UK, and notes that this framework is subject to modifications from various other legislative instruments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-environment-act-1995",
    "title": "UK Environment Act 1995 (c.25): The Environment Agency, Contaminated Land and National Air Quality Strategy",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Environment Act 1995 (c. 25) established the Environment Agency for England and Wales and the Scottish Environment Protection Agency, set the Agency's principal aim and objectives, and introduced the statutory regimes for contaminated land and local air quality management, administered by the environment agencies and local authorities. Section 1 establishes the Environment Agency as a body corporate. Section 2 transfers to the Agency the pollution control, water management, waste regulation, and other environmental functions previously held by the National Rivers Authority, Her Majesty's Inspectorate of Pollution, and waste regulation authorities. Section 4 sets the Agency's principal aim of protecting or enhancing the environment so as to contribute towards the objective of achieving sustainable development, and its objectives. Section 5 confers general functions with respect to pollution control, and section 6 confers general provisions with respect to water, including the conservation and management of water resources. Section 7 imposes general environmental and recreational duties on the Agency and Ministers, requiring them to have regard to conservation, the natural beauty of the countryside, and the protection of flora and fauna. Section 57 inserts the contaminated land regime into the Environmental Protection Act 1990, requiring local authorities to identify and secure the remediation of contaminated land. Section 80 requires the Secretary of State to prepare and publish a national air quality strategy, and section 108 confers powers of entry and investigation on enforcing authorities. The Act is the foundational statute for the modern environmental regulator and the contaminated land and air quality regimes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-environment-act-2021",
    "title": "UK Environment Act 2021: Long-Term Targets, the Office for Environmental Protection and Biodiversity Gain",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Environment Act 2021 (c. 30) is the United Kingdom's principal post-Brexit framework for environmental governance, targets and protection, with most provisions led by the Department for Environment, Food and Rural Affairs (Defra) and independent oversight by the Office for Environmental Protection (OEP). Part 1 (Environmental Governance) requires the Secretary of State to set long-term environmental targets: section 1 confers the power and duty to set long-term targets in respect of the natural environment or people's enjoyment of it, with at least one target required in each of the priority areas of air quality, water, biodiversity, and resource efficiency and waste reduction, together with a fine particulate matter (PM2.5) air quality target and a target to halt the decline in species abundance. Sections 8 to 15 require an environmental improvement plan and annual reporting and review against it, and section 16 provides for environmental monitoring. Sections 17 to 19 require ministers to prepare and have regard to a policy statement on environmental principles. Section 22 establishes the Office for Environmental Protection, an independent body whose functions (sections 22 to 43) include monitoring and reporting on progress, advising on environmental law, and enforcing compliance by public authorities through information notices, decision notices and environmental review. Part 3 (sections 50 to 56) provides for producer responsibility obligations, resource efficiency requirements, and deposit and charging schemes. Part 4 includes the local air quality management framework (section 72) and the environmental recall of motor vehicles. Part 5 (sections 78 to 84) addresses water resources and drainage plans and storm overflows. Part 6 (Nature and Biodiversity) introduces mandatory biodiversity gain as a condition of planning permission (sections 98 to 101), the strengthened general biodiversity duty on public authorities (section 102), and local nature recovery strategies (sections 104 onwards). Enforcement operates through the OEP's notices and environmental review, planning conditions, and the penalty regimes in the regulations made under the producer responsibility and other powers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-environment-act-2021-biodiversity-net-gain-targets",
    "title": "UK Environment Act 2021 - Mandatory Biodiversity Net Gain, Legally Binding Environmental Targets, and OEP Oversight",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The Environment Act 2021 (c. 30) introduces mandatory 10% biodiversity net gain (BNG) for most new planning permissions in England (from February 2024), legally binding long-term environmental targets in air quality, water, biodiversity, resource efficiency, and waste, and creates the Office for Environmental Protection (OEP) as the UK's independent environmental watchdog post-Brexit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-environment-act-2021-part-2-biodiversity-net-gain",
    "title": "Environment Act 2021 PART 2 Section 48 Improving the natural environment: Northern Ireland",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This legislation mandates that provisions for environmental improvement plans and policy statements on environmental principles in Northern Ireland are established as detailed in Schedule 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-environment-act-2021-section-81-storm-overflow-discharge-reporting",
    "title": "UK Environment Act 2021 Section 81 - Reporting on Discharges from Storm Overflows",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 81 of the Environment Act 2021 inserts a new Section 141DA into the Water Industry Act 1991 requiring English sewerage undertakers to publish information about every storm overflow discharge: the fact of discharge, location, start time, and end time. Information about the start of a discharge must be published within one hour of the discharge beginning; information about the end within one hour of it ending. Information must be in a form readily understandable by the public and readily accessible. The Section is enforceable under Section 18 of the Water Industry Act 1991.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "inserts_section_141da_into_wia_1991",
        "information_to_be_published_subsection_1",
        "publication_within_one_hour_subsection_2",
        "accessibility_and_form_subsection_3",
        "enforcement_under_section_18_subsection_4",
        "regulation_making_power_subsections_5_to_7",
        "two_phase_commencement",
        "interaction_with_section_94_general_sewerage_duty_and_section_141a_reduction_targets"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-water-industry-act-1991-section-94-general-duty-sewerage-system"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-environmental-protection-act-1990-waste-and-statutory-nuisance",
    "title": "UK Environmental Protection Act 1990: Waste Duty of Care, Contaminated Land and Statutory Nuisance",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Environmental Protection Act 1990 (c. 43) is a foundational UK environmental statute. Part II governs waste on land: section 33 makes it an offence to deposit, treat, keep or dispose of controlled waste without, or otherwise than in accordance with, an environmental permit, or in a manner likely to cause pollution of the environment or harm to human health; section 34 imposes the waste 'duty of care' on any person who imports, produces, carries, keeps, treats or disposes of controlled waste, requiring them to prevent its escape, transfer it only to authorised persons, and ensure a written description accompanies it (the waste transfer note system); sections 35-36 govern waste management licences (now largely the environmental permitting regime), and section 75 defines 'waste' and the categories of household, commercial, industrial and hazardous waste. Part IIA addresses contaminated land: local authorities must identify contaminated land (section 78B), special sites are designated (section 78C), and enforcing authorities serve remediation notices requiring clean-up by the appropriate person, applying the polluter-pays principle (section 78E). Part III deals with statutory nuisances: section 79 lists the categories (including premises, smoke, fumes, gases, dust, effluvia, noise and accumulations prejudicial to health or a nuisance) and requires local authorities to inspect their areas; section 80 requires the service of an abatement notice where a statutory nuisance exists or is likely to occur or recur, and makes it an offence, without reasonable excuse, to contravene the notice. Part IV creates the offence of leaving litter (section 87). Offences under section 33 are punishable, on summary conviction, by imprisonment and/or a fine and, on conviction on indictment, by imprisonment (up to five years for certain hazardous-waste offences) and/or an unlimited fine; contravening an abatement notice under section 80 is punishable by a fine, with a higher maximum where the offence is committed on industrial, trade or business premises, plus a daily default fine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-equality-act-2010",
    "title": "UK Equality Act 2010 - Protected Characteristics, Direct and Indirect Discrimination, and Reasonable Adjustments Duty",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The UK Equality Act 2010 legally protects people from discrimination in the workplace and in wider society. It requires employers to prevent direct and indirect discrimination based on nine protected characteristics (Part 2, Chapter 1) and imposes a duty to make reasonable adjustments for disabled individuals (Section 20).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "cipd-hr-standards",
      "eeoc-employment-rule",
      "eu-pay-transparency-directive-2023",
      "modern-slavery-act-rep"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-equality-act-2010-education-providers",
    "title": "Equality Act 2010 - Education Providers: Duty Not to Discriminate, Reasonable Adjustments for Disabled Students, Harassment, Victimisation, Single-Sex Schools Exceptions and Public Sector Equality Duty",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Education providers in England, Wales, and Scotland must not discriminate, harass, or victimise pupils or applicants on grounds of protected characteristics (excluding age and marriage/civil partnership), and must make reasonable adjustments for disabled pupils. This duty applies under Section 85 of the Equality Act 2010 to maintained schools, independent schools, academies, and special schools.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-111-discrimination-employment-education",
      "iso-21001-2018-educational-organizations-management",
      "oecd-recommendation-responsible-research-innovation-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-equality-act-2010-protected-characteristics",
    "title": "UK Equality Act 2010 - Protected Characteristics, Employment Discrimination, and Reasonable Adjustments",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Equality Act 2010 (c.15) consolidates and replaces nine previous anti-discrimination statutes in Great Britain. Section 4 lists the nine protected characteristics: age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, and sexual orientation. Section 13 prohibits direct discrimination (less favourable treatment because of a protected characteristic). Section 19 prohibits indirect discrimination (a provision, criterion or practice that puts persons with a protected characteristic at a particular disadvantage). Section 20 imposes a duty on employers and service providers to make reasonable adjustments for disabled persons where a provision, criterion, or practice places them at a substantial disadvantage. Section 26 prohibits harassment related to a protected characteristic. Section 39 applies to employers: they must not discriminate in recruitment, terms of employment, access to promotion or training, or in dismissal. Employment tribunal claims must be brought within 3 months minus one day of the act complained of.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_equal_treatment_framework_directive",
        "equality_human_rights_commission",
        "uk_human_rights_act_1998",
        "equality_act_2010_public_sector_equality_duty",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-electronic-communications-act-2000",
      "uk-housing-act-2004-hhsrs-hmo"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-equality-act-2010-section-13-direct-discrimination",
    "title": "UK Equality Act 2010 Section 13 — Direct Discrimination",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Direct discrimination occurs where, because of a protected characteristic, a person (A) treats another (B) less favourably than A treats or would treat others. Age discrimination uniquely permits justification as a proportionate means of achieving a legitimate aim. More favourable treatment of disabled persons is not direct discrimination against non-disabled persons. Race-based segregation is automatically less favourable treatment. Section 13 is the foundational discrimination test for Parts 3, 4, 5, 6 and 7 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_test_less_favourable_treatment_because_of_pc",
        "age_justification_defence",
        "disability_asymmetry_more_favourable_treatment_allowed",
        "marriage_civil_partnership_work_only_and_protected_status",
        "race_segregation_deemed_less_favourable",
        "sex_pregnancy_maternity_overlap",
        "interaction_with_sections_17_and_18"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-equality-act-2010-section-4-protected-characteristics",
      "uk-equality-act-2010-section-18-pregnancy-maternity-discrimination-work-cases",
      "uk-equality-act-2010-section-149-public-sector-equality-duty"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-equality-act-2010-section-149-public-sector-equality-duty",
    "title": "UK Equality Act 2010 Section 149 - Public Sector Equality Duty (Due Regard to Eliminate Discrimination, Advance Equality, Foster Good Relations)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 149 of the Equality Act 2010 (c. 15) establishes the Public Sector Equality Duty (PSED) requiring public authorities and bodies exercising public functions to have due regard, in the exercise of their functions, to the need to (a) eliminate discrimination, harassment, victimisation and any other conduct prohibited by the Act, (b) advance equality of opportunity between persons sharing a relevant protected characteristic and persons not sharing it, and (c) foster good relations between persons sharing a relevant protected characteristic and persons not sharing it. Section 149(2) extends the duty to persons not public authorities but exercising public functions, in respect of those functions. Section 149(3) clarifies the advance-equality-of-opportunity limb (removing disadvantages, meeting different needs, encouraging participation). Section 149(4) addresses disability-specific needs. Section 149(5) addresses good relations including tackling prejudice and promoting understanding. Section 149(6) clarifies that compliance may involve treating some persons more favourably than others though not so as to amount to conduct otherwise prohibited. Section 149(7) lists the eight relevant protected characteristics. Section 149(8)-(9) provide definitions and reference Schedule 18 exceptions. The PSED is supervised by the Equality and Human Rights Commission (EHRC) under sections 31-32 of the Equality Act 2006.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_149_text",
        "due_regard_test_brown_principles",
        "advance_equality_of_opportunity_section_149_3",
        "foster_good_relations_section_149_5",
        "specific_duties_under_2017_regulations",
        "ehrc_enforcement_powers",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-equality-act-2010",
      "uk-equality-act-2010-protected-characteristics"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-equality-act-2010-section-18-pregnancy-maternity-discrimination-work-cases",
    "title": "UK Equality Act 2010 Section 18 - Pregnancy and Maternity Discrimination Work Cases (Unfavourable Treatment Test, Protected Period, Compulsory Maternity Leave Exercise of Rights)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 18 of the Equality Act 2010 (c. 15) creates the specific pregnancy and maternity discrimination protection in work cases - the operative provision distinguishing pregnancy/maternity from generic sex discrimination under section 13. Under section 18(1), the section applies in connection with the protected characteristic of pregnancy and maternity for the purposes of Part 5 (work). Under section 18(2), a person (A) discriminates against a woman if, in the protected period in relation to a pregnancy of hers, A treats her unfavourably (a) because of the pregnancy, or (b) because of illness suffered by her as a result of it. Under section 18(3), A discriminates against a woman if A treats her unfavourably because she is on compulsory maternity leave. Under section 18(4), A discriminates against a woman if A treats her unfavourably because she is exercising or seeking to exercise, or has exercised or sought to exercise, the right to ordinary or additional maternity leave. Under section 18(6), the protected period begins when pregnancy begins and ends (a) at end of additional maternity leave (or earlier return), or (b) two weeks after end of pregnancy where she has no maternity leave entitlement. Under section 18(6A), 'equivalent maternity leave' provisions apply where substantially similar periods exist under statutory or contractual schemes. Under section 18(7), section 13 sex discrimination protection does not apply for unfavourable treatment during the protected period for pregnancy-related reasons - section 18 is the operative provision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_18_text",
        "unfavourable_treatment_test_no_comparator_needed",
        "protected_period_section_18_6_pregnancy_through_maternity_leave_end",
        "section_18_7_disapplication_of_section_13_in_protected_period",
        "exercise_of_maternity_rights_section_18_4_anti_retaliation",
        "compulsory_maternity_leave_section_18_3_first_two_weeks_post_birth",
        "remedy_uncapped_compensatory_award_with_injury_to_feelings",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-equality-act-2010",
      "uk-equality-act-2010-section-4-protected-characteristics",
      "uk-employment-rights-act-1996-section-99-leave-family-reasons-automatically-unfair"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-equality-act-2010-section-19-indirect-discrimination",
    "title": "UK Equality Act 2010 Section 19 — Indirect Discrimination",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Indirect discrimination occurs where a person (A) applies a provision, criterion or practice (PCP) that puts persons sharing B's protected characteristic at a particular disadvantage compared with others, puts B at that disadvantage, and A cannot show it to be a proportionate means of achieving a legitimate aim. The eight relevant protected characteristics are age, disability, gender reassignment, marriage and civil partnership, race, religion or belief, sex, and sexual orientation. Pregnancy/maternity is not within Section 19; it is addressed under Section 18 in work contexts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_test_pcp_discriminatory_in_relation_to_pc",
        "four_limb_test_for_pcp_discriminatoriness",
        "group_disadvantage_evidenced",
        "individual_disadvantage_to_b",
        "objective_justification_defence",
        "relevant_protected_characteristics_list",
        "burden_shift_under_section_136"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-equality-act-2010-section-13-direct-discrimination",
      "uk-equality-act-2010-section-4-protected-characteristics",
      "uk-equality-act-2010-section-20-duty-make-reasonable-adjustments"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-equality-act-2010-section-20-duty-make-reasonable-adjustments",
    "title": "UK Equality Act 2010 Section 20 — Duty to Make Adjustments",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Where a duty to make reasonable adjustments is imposed on a person (A) by the Act, three requirements apply: (1) take reasonable steps to avoid the substantial disadvantage caused by a provision, criterion or practice; (2) take reasonable steps to avoid the substantial disadvantage caused by a physical feature; (3) take reasonable steps to provide an auxiliary aid where one is needed to avoid substantial disadvantage. A disabled person cannot be required to pay any costs of compliance. Information must be provided in an accessible format where information is part of the requirement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "duty_engaged_by_other_provisions",
        "first_requirement_pcp_substantial_disadvantage",
        "second_requirement_physical_feature",
        "third_requirement_auxiliary_aid",
        "information_must_be_in_accessible_format",
        "disabled_person_cannot_be_charged_for_compliance",
        "schedule_routing_by_part_of_act"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-equality-act-2010-section-4-protected-characteristics",
      "uk-equality-act-2010-section-13-direct-discrimination",
      "uk-equality-act-2010-section-19-indirect-discrimination"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-equality-act-2010-section-20-duty-to-make-reasonable-adjustments",
    "title": "Equality Act 2010 Section 20: Duty to make adjustments",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must take reasonable steps to avoid disadvantages faced by disabled persons caused by provisions, criteria, practices, physical features, or the lack of an auxiliary aid.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-equality-act-2010-section-26-harassment",
    "title": "UK Equality Act 2010 Section 26 — Harassment",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Harassment under the Equality Act 2010 has three distinct limbs: (1) unwanted conduct related to a relevant protected characteristic with the purpose or effect of violating dignity or creating an intimidating, hostile, degrading, humiliating or offensive environment; (2) unwanted conduct of a sexual nature with that same effect; and (3) less favourable treatment because of rejection of or submission to sexual conduct or conduct related to gender reassignment or sex. The 'effect' limb requires consideration of the claimant's perception, the circumstances, and whether it was reasonable for the conduct to have that effect.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "general_harassment_limb_1",
        "sexual_harassment_limb_2",
        "less_favourable_treatment_for_rejection_or_submission_limb_3",
        "effect_test_perception_circumstances_reasonableness",
        "relevant_protected_characteristics_for_section_26",
        "purpose_or_effect_alternative_routes",
        "interaction_with_employer_vicarious_liability_section_109"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-equality-act-2010-section-4-protected-characteristics",
      "uk-equality-act-2010-section-13-direct-discrimination",
      "uk-equality-act-2010-section-27-victimisation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-equality-act-2010-section-27-victimisation",
    "title": "UK Equality Act 2010 Section 27 - Victimisation (Detriment Because of Protected Act, Belief in Protected Act, Bad Faith Carve-out)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 27 of the Equality Act 2010 (c. 15) prohibits victimisation - subjecting another person (B) to a detriment because B does, or A believes B has done or may do, a protected act. Under section 27(1), A victimises B if A subjects B to a detriment because (a) B does a protected act, or (b) A believes that B has done, or may do, a protected act. Section 27(2) lists protected acts: (a) bringing proceedings under the Act; (b) giving evidence or information in connection with proceedings under the Act; (c) doing any other thing for the purposes of or in connection with the Act; (d) making an allegation (whether or not express) that A or another person has contravened the Act. Section 27(3) provides that giving false evidence or information or making a false allegation is not a protected act if given or made in bad faith. Section 27(4) limits the section to detriment to an individual. Section 27(5) extends 'contravening this Act' to breaching an equality clause or rule. Victimisation claims are typically brought to the Employment Tribunal for employment victimisation and to the County Court for service/goods/premises/education victimisation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_27_text",
        "protected_act_categories_section_27_2",
        "detriment_test",
        "belief_in_protected_act_section_27_1_b",
        "bad_faith_carve_out_section_27_3",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-equality-act-2010",
      "uk-equality-act-2010-section-13-direct-discrimination",
      "uk-equality-act-2010-section-26-harassment"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-equality-act-2010-section-39-employment-equality-duty",
    "title": "Equality Act 2010, Section 39: Employees and applicants",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Employers must not discriminate against or victimise job applicants or employees in relation to arrangements for hiring, terms of employment, access to benefits and training, dismissal, or any other detriment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-equality-act-2010-section-4-protected-characteristics",
    "title": "UK Equality Act 2010 Section 4 - The Protected Characteristics (Nine Statutory Categories: Age, Disability, Gender Reassignment, Marriage and Civil Partnership, Pregnancy and Maternity, Race, Religion or Belief, Sex, Sexual Orientation)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 4 of the Equality Act 2010 (c. 15) provides the foundational list of nine protected characteristics that engage the entire Equality Act 2010 anti-discrimination framework. The section reads simply: 'The following characteristics are protected characteristics - age; disability; gender reassignment; marriage and civil partnership; pregnancy and maternity; race; religion or belief; sex; sexual orientation.' The section contains no subsections - it is a single definitional statement that anchors the substantive protections in sections 5-12 (defining each protected characteristic), the prohibited conduct in sections 13-27 (direct discrimination, indirect discrimination, disability discrimination, gender reassignment discrimination, harassment, victimisation), and the substantive provisions covering work (Part 5), services and public functions (Part 3), education (Part 6), associations (Part 7), premises (Part 4), transport (Part 12), and equality of terms (Part 5 Chapter 3). The section 149 Public Sector Equality Duty also references the section 4 list (via section 149(7) cross-reference). Enforcement is via Employment Tribunal (employment cases), County Court (services, goods, premises), Special Educational Needs and Disability Tribunal (education), and the Equality and Human Rights Commission under Equality Act 2006.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_4_text",
        "nine_characteristics_with_section_5_12_substantive_definitions",
        "for_cabe_v_unison_2019_disability_six_month_test",
        "religion_or_belief_section_10_grainger_test",
        "sex_and_gender_reassignment_interaction_post_for_women_scotland_2025",
        "section_149_psed_seven_listed_protected_characteristics",
        "enforcement_dual_track_employment_tribunal_county_court_ehrc",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-equality-act-2010",
      "uk-equality-act-2010-section-13-direct-discrimination",
      "uk-equality-act-2010-section-26-harassment",
      "uk-equality-act-2010-section-149-public-sector-equality-duty"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-ets-2021-compliance-rules",
    "title": "UK Emissions Trading Scheme 2021 - Cap Setting, Free Allocation, Compliance and Auctioning Rules",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK Emissions Trading Scheme (UK ETS) mandates that operators of energy-intensive industries and aircraft operators monitor, report, and surrender sufficient emissions allowances to cover their annual greenhouse gas emissions. Compliance, as defined in Part 6 of The Greenhouse Gas Emissions Trading Scheme Order 2020, requires surrendering allowances equal to verified reportable emissions by April 30th of the following year.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-export-control-act-2002",
    "title": "United Kingdom Export Control Act 2002: Export Controls, Transfer Controls, Technical Assistance Controls, Trade Controls, Restrictions, Order-Making Authority, and Annual Reporting",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The United Kingdom Export Control Act 2002, chapter 28 of 2002, is the principal United Kingdom statute authorising the Secretary of State to impose controls on the export of goods, the transfer of technology, the provision of technical assistance, and trade in controlled goods, and is administered through the Export Control Joint Unit within the Department for Business and Trade. Export Control Act 2002, section 1 confers power to impose export controls on goods. Export Control Act 2002, section 2 confers power to impose transfer controls on technology. Export Control Act 2002, section 3 confers power to impose technical assistance controls. Export Control Act 2002, section 4 confers power to impose trade controls including trafficking and brokering. Export Control Act 2002, section 5 imposes general restrictions on control powers, requiring control orders to be exercised only for permitted purposes. Export Control Act 2002, section 6 sets out exceptions from those restrictions. Export Control Act 2002, section 7 provides supplementary control provisions. Export Control Act 2002, section 8 protects certain freedoms, ensuring that controls do not interfere unduly with rights protected under other law. Export Control Act 2002, section 9 requires guidance on exercising control functions. Export Control Act 2002, section 10 imposes annual reporting requirements requiring the Secretary of State to lay before Parliament a report on the operation of strategic export controls. Export Control Act 2002, section 11 contains the definitions and interpretation. Export Control Act 2002, section 12 grants the power to modify the Schedule listing categories of controlled goods, technology, and technical assistance. Export Control Act 2002, section 13 confers order-making authority. The principal subordinate orders include the Export Control Order 2008 and successor instruments. The Act is the controlling United Kingdom instrument for strategic export controls under United Kingdom trade compliance law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-fca-ai-guidance-2023",
    "title": "UK FCA Discussion Paper DP5/22 - Artificial Intelligence and Machine Learning in Financial Services",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This discussion paper outlines the UK Financial Conduct Authority's (FCA) perspective on applying existing financial regulations to AI/ML, emphasizing that firms remain accountable for governance, risk management, and fairness under frameworks like the Senior Managers and Certification Regime (SMCR) and Consumer Duty (Chapter 3). It seeks industry feedback on the benefits and risks of AI to inform potential future regulatory approaches, rather than introducing new rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fca-consumer-duty-2023",
      "uk-smcr-senior-manager-certification",
      "pra-ss1-21-resilience",
      "sr-11-7-model-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-fca-cobs-4-12a-cryptoasset-promotions-2023",
    "title": "UK FCA Cryptoasset Financial Promotion Rules - COBS 4.12A (PS23/6, effective 8 October 2023)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "FCA Policy Statement PS23/6 introduced cryptoassets into the UK financial promotion regime through Conduct of Business Sourcebook chapter COBS 4.12A, effective 8 October 2023. Qualifying cryptoassets are classified as Restricted Mass Market Investments. Any firm communicating or approving a financial promotion relating to a qualifying cryptoasset to UK retail clients must: (a) include the prescribed risk warning under COBS 4.12A.10R / 4.12A.11R (8 October 2025 version) and a risk summary; (b) refrain from offering monetary or non-monetary incentives to retail clients (COBS 4.12A.7R, prohibition expanded by 2 April 2024 amendments); and (c) for direct offer financial promotions, satisfy four conditions: cooling-off period of at least 24 hours (COBS 4.12A.18R), personalised risk warning (COBS 4.12A.20R), client categorisation (COBS 4.12A.21R), and appropriateness assessment (COBS 4.12A.28R). The 24-hour cooling-off period and personalised risk warning are only required on the first communication to a particular retail client; appropriateness assessments are only required on the first response by the retail client to a direct offer financial promotion of that specific RMMI type. Categorisation statements must be current within 12 months of the communication. The regime applies to all firms marketing cryptoassets to UK consumers regardless of the firm's location.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "uk_financial_services_and_markets_act_2000",
        "mica_eu_markets_in_crypto_assets_2023_1114",
        "us_sec_regulation_sp_2024_amendments",
        "uk_psd2_open_banking_api_standards",
        "fatf_r15_virtual_asset_service_providers"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-financial-services-markets-act-2023-crypto",
      "uk-mlr-2019-1511-cryptoasset-amendment",
      "fatf-virtual-asset-redfl",
      "eu-mica-casp-obligations"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "uk-fca-consumer-duty-2023",
    "title": "UK FCA Consumer Duty (PS22/9) 2023 - Outcome-Based Consumer Protection Standard for Financial Services",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The UK FCA Consumer Duty requires FCA-regulated firms to act to deliver good outcomes for retail customers, as mandated by the new Consumer Principle (Principle 12). This is a shift to outcomes-based regulation, focusing on four key areas: Products and Services, Price and Value, Consumer Understanding, and Consumer Support.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fca-ai-guidance-2023",
      "uk-pra-supervisory-statement-ss1-23",
      "uk-dpa-2018",
      "mifid-ii",
      "eu-psd2-strong-customer-authentication"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-fca-consumer-duty-ps22-9-fair-value-outcomes-retail",
    "title": "UK FCA Consumer Duty PS22/9 - Consumer Protection: Fair Value and Good Outcomes for Retail Financial Customers",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "FCA Policy Statement PS22/9 and the Consumer Duty Rules (PRIN 2A) require firms to deliver four consumer outcomes: products and services, price and value, consumer understanding, and consumer support. All retail financial services firms must evidence delivery of the Duty through annual board reports from 31 July 2023 (closed products from 31 July 2024).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-data-protection-act-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-fca-crypto-promotion-rules-2023",
    "title": "Financial Promotion Rules for Cryptoassets (PS22/10 & FCA 2023/32)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Effective October 8, 2023, all firms marketing cryptoassets to UK consumers must ensure promotions are clear, fair, not misleading, and approved by an FCA-authorised firm. The rules, outlined in COBS 4.12A, mandate specific risk warnings, a 24-hour cooling-off period for new investors, and ban certain incentives to protect consumers from high-risk investments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-fca-electronic-money-institutions-emis-payment-institutions-fca-psr2017",
    "title": "UK FCA Electronic Money Institutions (EMIs) and Payment Institutions - Payment Services Regulations 2017",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "The UK Payment Services Regulations 2017 (PSR 2017) and Electronic Money Regulations 2011 (EMR 2011) implement PSD2 and EMD2 in UK law, requiring payment institutions and e-money institutions to be authorised by the FCA. Authorised EMIs must hold minimum capital of EUR 350,000 and safeguard customer funds either by holding them in segregated accounts or covering them with insurance. Payment institutions providing specified payment services must hold minimum capital of EUR 125,000-EUR 730,000 depending on services. FCA registration requires fit and proper management and robust governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-psd2-rts-strong-customer-auth-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-fca-general-insurance-pricing-practices-ps21-5-fair-value",
    "title": "UK FCA General Insurance Pricing Practices PS21/5 - Renewal Pricing Rules and Fair Value Assessment",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2022-01-01",
    "bluf": "FCA Policy Statement PS21/5 requires home and motor insurance providers to price renewal quotes at no more than what would be offered to an equivalent new customer, eliminating loyalty pricing penalty, and to conduct product value assessments ensuring premiums represent fair value relative to expected benefits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fca-consumer-duty-ps22-9-fair-value-outcomes-retail",
      "eu-solvency-ii-directive-2009-138-ec-eiopa"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-fca-icobs-insurance-conduct-sourcebook",
    "title": "UK FCA Insurance Conduct of Business Sourcebook (ICOBS)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK FCA's ICOBS mandates that insurance firms act honestly, fairly, and professionally in the best interests of their customers (ICOBS 2.5.-1R). This includes providing clear product information, ensuring products offer fair value (ICOBS 6A), handling claims promptly and fairly (ICOBS 8), and providing transparent and fair renewal processes (ICOBS 6.5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fca-consumer-duty-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-fca-product-governance-insurance-2023",
    "title": "Insurance Product Governance - General Insurance and Pure Protection: Target Market Identification, Product Approval Process, Stress Scenario Testing of Value, Distribution Strategy, Regular Review and Manufacturer Responsibility in Multi-Party Chains",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires UK insurance manufacturers to establish and maintain a product governance framework ensuring products are designed for a clearly defined target market, approved via a formal process, and distributed appropriately. It applies to all firms manufacturing or distributing general insurance and pure protection products under Article 24 of the Insurance Distribution Directive (IDD) as transposed into UK law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-delegated-regulation-2016-467-non-life-premium-risk",
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "eiopa-guidelines-pension-stress-testing-2022",
      "eu-eiopa-guidelines-orsa-2015"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-fca-ps21-3-operational-resilience-policy",
    "title": "UK FCA PS21/3 Building Operational Resilience Policy Statement",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "UK FCA Policy Statement PS21/3, published March 2021 with an implementation deadline of 31 March 2022 (full compliance by 31 March 2025), requires FCA-regulated firms to identify their important business services, set impact tolerances for their continuity, map the people, processes, technology, facilities, and information supporting them, and test their ability to remain within tolerance through severe but plausible operational disruption scenarios - embedding operational resilience as a board-level regulatory obligation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-finance-act-2024-c-3",
    "title": "UK Finance Act 2024 - R&D Tax Relief Reform, Multinational Top-Up Tax (Pillar Two), and Pension Allowances Removal, Royal Assent 22 February 2024",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "UK taxpayers, multinational groups, R&D-intensive companies, and pension scheme administrators must comply with the Finance Act 2024 (Royal Assent 22 February 2024) by applying the new merged R&D tax relief scheme under Part 2 (replacing the SME and RDEC schemes for accounting periods beginning on or after 1 April 2024, with an enhanced R&D-intensive scheme for loss-making SMEs spending at least 30 percent of total expenditure on R&D), the Multinational Top-up Tax under Part 3 implementing OECD Pillar Two Global Anti-Base Erosion (GloBE) rules for fiscal years beginning on or after 31 December 2023 imposing a 15 percent effective tax rate on in-scope multinational groups with consolidated revenue of at least EUR 750 million, the Domestic Top-up Tax under Part 4 for the UK portion of low-taxed income, and the abolition of the lifetime allowance under Part 1 effective from 6 April 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-corporation-tax-act-2010-diverted-profits-tax-transfer-pricing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-financial-services-act-2012",
    "title": "UK Financial Services Act 2012",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The UK Financial Services Act 2012 (FSA 2012) restructured UK financial regulation by replacing the Financial Services Authority (FSA) with the twin peaks Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA), amending the Financial Services and Markets Act 2000 (FSMA). The Act established the Bank of England Financial Policy Committee (FPC) for macroprudential oversight, created criminal offences for benchmark manipulation (e.g., LIBOR scandal), and reformed insolvency and resolution arrangements for banks. The FCA is responsible for conduct regulation of all financial firms and prudential regulation of those not under PRA. The PRA (within the Bank of England) is responsible for prudential regulation of banks insurers and major investment firms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fsma_2000",
        "fsma_2023",
        "boea_1998",
        "benchmarks_reg",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-financial-services-banking-reform-act-2013",
    "title": "UK Financial Services (Banking Reform) Act 2013 - Ring-Fencing Senior Managers Regime and Resolution",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Financial Services (Banking Reform) Act 2013 implemented core recommendations of the Independent Commission on Banking and the Parliamentary Commission on Banking Standards by requiring large UK ring-fenced banks to legally separate retail deposit-taking activities from investment banking and global wholesale activities, creating the Senior Managers and Certification Regime to hold senior managers and certified persons accountable for the firms they manage, expanding the Bank of England Special Resolution Regime including the bail-in tool for failing banks, creating the offence of reckless misconduct in the management of a bank causing failure, and authorising the regulators to make rules including the conduct rules applicable across the workforce.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-financial-services-markets-act-2000-fsma",
      "uk-smcr-senior-managers-certification-regime-2016"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-financial-services-markets-act-2000",
    "title": "UK Financial Services and Markets Act 2000 (FSMA) -- Regulatory Framework for UK Financial Services",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-06-30",
    "bluf": "The Financial Services and Markets Act 2000 (FSMA 2000) establishes the UK's financial regulatory framework. The general prohibition in Section 19 makes it a criminal offence to carry on a regulated activity in the UK without FCA or PRA authorisation. Regulated activities are specified in the Regulated Activities Order (RAO, SI 2001/544). The FCA and PRA may impose unlimited financial penalties under Section 206. The Senior Managers and Certification Regime (SMCR) under Section 60A imposes individual accountability on senior managers. The Financial Services Compensation Scheme (FSCS) under Section 213 compensates eligible claimants up to GBP 85,000 for deposits (per institution). The Financial Ombudsman Service (FOS) under Section 225 resolves retail consumer disputes. FSMA 2000 was significantly amended by the Financial Services Act 2012 (creating the FCA/PRA dual-peak model) and the Financial Services and Markets Act 2023 (post-Brexit Edinburgh Reforms framework).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-regulation-2013-575",
      "uk-competition-act-1998",
      "uk-insurance-act-2015-fair-presentation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-financial-services-markets-act-2000-fsma",
    "title": "United Kingdom Financial Services and Markets Act 2000 (FSMA): FCA and PRA Regulators, General Prohibition on Unauthorised Regulated Activity, Permission Threshold Conditions, Approval of Persons, FCA Rule-Making, and Restitution",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The United Kingdom Financial Services and Markets Act 2000, chapter 8 of 2000 and commonly cited as FSMA 2000, is the principal United Kingdom statute establishing the framework for financial services regulation and is administered by the Financial Conduct Authority and the Prudential Regulation Authority. Part 1A establishes the regulators: Chapter 1 establishes the Financial Conduct Authority with its general duties, objectives, and the competitiveness and growth objective, and Chapter 2 establishes the Prudential Regulation Authority. Financial Services and Markets Act 2000, section 19 sets out the general prohibition: no person may carry on a regulated activity in the United Kingdom, or purport to do so, unless authorised or exempt. Financial Services and Markets Act 2000, section 21 restricts financial promotion. Financial Services and Markets Act 2000, section 23 makes contravention of the general prohibition an offence. Part 4A governs permission to carry on regulated activities through sections 55A onwards, including the threshold conditions, variation and cancellation of permissions, and imposition of requirements. Financial Services and Markets Act 2000, section 56 confers the power to make prohibition orders against individuals. Sections 59 to 63 govern approval of persons for controlled functions. Sections 71B to 71I cover removal of directors and appointment of temporary managers. Part VI governs official listing, prospectus requirements, and transparency obligations. Part VIII covers market abuse including section 118 definition and prohibition and section 123 power to impose penalties. Part 9A governs rules and guidance: Financial Services and Markets Act 2000, section 137A confers the FCA's general rule-making power and section 137D confers product intervention powers. Part 11 covers information gathering and investigations. Financial Services and Markets Act 2000, section 384 confers the power of the FCA or PRA to require restitution from persons who have breached the regulations. The Act, as amended by the Financial Services Act 2012, the Financial Services (Banking Reform) Act 2013, the Financial Services Act 2021, the Financial Services and Markets Act 2023, and subsequent amendments, is the controlling United Kingdom instrument for financial services regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-financial-services-markets-act-2000-section-137a-general-rule-making",
    "title": "Financial Services and Markets Act 2000, Section 137A: The FCA's general rule-making power",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This section grants the Financial Conduct Authority (FCA) the general power to make rules applying to authorised persons as necessary for advancing its statutory objectives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-financial-services-markets-act-2000-section-1c-fca-competition-objective",
    "title": "Financial Services and Markets Act 2000, Section 1C: The competition objective",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must operate in a manner that promotes effective competition in the interests of consumers, aligning with the FCA's statutory competition objective.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-financial-services-markets-act-2000-section-55b-threshold-conditions",
    "title": "Financial Services and Markets Act 2000, Section 55B: Application for permission",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This section requires any person seeking to carry on a regulated activity in the UK to apply to the appropriate regulator for permission, providing all necessary information to demonstrate that they will satisfy the threshold conditions on an ongoing basis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-financial-services-markets-act-2000-section-64a-conduct-rules-accountability",
    "title": "Financial Services and Markets Act 2000 Section 64A: Rules of conduct",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This section empowers the Financial Conduct Authority (FCA) and the Prudential Regulation Authority (PRA) to create 'rules of conduct' for approved persons performing controlled functions, requiring firms to ensure their staff adhere to these rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-financial-services-markets-act-2023-critical-third-parties",
    "title": "UK Financial Services and Markets Act 2023 - Critical Third Party Regime, Edinburgh Reforms, and Digital Settlement Assets",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "FSMA 2023 delivers the Edinburgh Reforms, onshoring UK financial regulation post-Brexit with a Smarter Regulatory Framework (SRF). Key innovations: a Critical Third Parties (CTP) regime subjecting designated cloud providers, data vendors, and other systemic third parties to direct FCA/PRA/Bank of England oversight; extension of the FCA regulatory perimeter to stablecoin and digital settlement assets; enhanced Consumer Duty operationalisation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-financial-services-markets-act-2023-crypto",
    "title": "Financial Services and Markets Act 2023 - Crypto-Asset Regulation Provisions",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-08-20",
    "bluf": "The UK Financial Services and Markets Act 2023 amends existing financial legislation to bring certain crypto-assets and related activities within the UK regulatory perimeter, granting HM Treasury powers under Section 69 to define scope, with an initial focus on fiat-backed stablecoins and the creation of a Financial Market Infrastructure Sandbox.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mica-regulation-2023",
      "fsb-crypto-asset-regulatory-framework-2023",
      "crypto-aml-travel-rule"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-financial-services-markets-act-2023-section-9-fca-objectives",
    "title": "Financial Services and Markets Act 2023, Section 9: Rules relating to central counterparties and central securities depositories",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Financial Market Infrastructure (FMI) entities, including central counterparties and central securities depositories, must comply with rules made by the Bank of England concerning their regulated and non-regulated activities to advance the Bank's Financial Stability Objective.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-fire-safety-act-2021-responsible-person",
    "title": "Fire Safety Act 2021: Obligations for Responsible Persons in Multi-Occupied Residential Buildings",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK Fire Safety Act 2021 clarifies that the duties of the 'Responsible Person' under the Regulatory Reform (Fire Safety) Order 2005 extend to the building's structure, external walls (including cladding and balconies), and all doors between domestic premises and common parts. This requires the Responsible Person to assess and manage fire risks in these areas for any building containing two or more sets of domestic premises, as mandated by Section 1 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-health-safety",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-flood-and-water-management-act-2010",
    "title": "UK Flood and Water Management Act 2010: National Strategy, Lead Local Flood Authorities, Sustainable Drainage and Reservoir Safety",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Flood and Water Management Act 2010 is a principal framework for managing flood and coastal erosion risk and certain water-supply matters in England and Wales, administered by the Environment Agency, lead local flood authorities and the Secretary of State. Part 1 deals with flood and coastal erosion risk management: section 1 defines flood and coastal erosion, section 2 defines risk, and section 3 defines risk management as the assessment and reduction of risk. Section 7 requires the Environment Agency to develop, maintain, apply and monitor a national flood and coastal erosion risk management strategy for England, and section 9 requires each lead local flood authority to develop a local flood risk management strategy. Section 21 requires a lead local authority to maintain a register of structures or features likely to have a significant effect on flood risk. Part 2 covers further measures: section 32 introduces sustainable drainage and Schedule 3 sets out the sustainable drainage system (SuDS) approval and adoption regime; section 33 and Schedule 4 strengthen reservoir safety by amending the Reservoirs Act 1975 in relation to high-risk reservoirs, inspection and monitoring; and section 36 enables water undertakers to impose temporary use bans (hosepipe bans) during periods of shortage. Sections 38 and 39 address incidental flooding or coastal erosion arising from the work of the appropriate agency and of local authorities. The Act is the legal architecture that assigns flood-risk leadership, requires the national and local strategies, brings sustainable drainage into the planning system and keeps large reservoirs under a safety regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-flood-water-management-act-2010",
    "title": "UK Flood and Water Management Act 2010",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The UK Flood and Water Management Act 2010 implements key recommendations from the Pitt Review (2008) following the 2007 floods. The Act provides a strategic framework for flood and coastal erosion risk management in England and Wales; designates Lead Local Flood Authorities (LLFAs) for surface water and groundwater flooding; creates Internal Drainage Boards (IDBs); Sustainable Drainage Systems (SuDS) framework; reservoir safety modernisation; and water industry powers including water company supplier of last resort regimes. The Environment Agency has overall strategic responsibility; LLFAs lead local strategies; Risk Management Authorities work in coordination. Major flooding events including 2007 2014 2015-16 and 2024 have shaped implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-food-safety-act-1990",
    "title": "UK Food Safety Act 1990 - Food Safety Requirements, Due Diligence Defence, and Enforcement",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Food Safety Act 1990 (UK) is the principal legislation establishing food safety requirements in the United Kingdom for food businesses. Section 8 prohibits the sale of food that fails to comply with food safety requirements, defined in Section 8(2) as food that has been rendered injurious to health, is unfit for human consumption, or is so contaminated that it would not be reasonable to expect it to be used for human consumption. Section 14 prohibits the sale to the purchaser's prejudice of food that is not of the nature, substance, or quality demanded. Section 15 prohibits descriptions, labels, advertisements, or presentations that falsely describe food or are likely to mislead as to its nature, substance, or quality. Section 21 provides the due diligence defence for all offences under the Act: a person is not guilty of an offence if they can prove that they took all reasonable precautions and exercised all due diligence to avoid the commission of the offence. Section 19 empowers the Secretary of State to issue Food Safety Act orders; these include the Food Safety (General Food Hygiene) Regulations and the Food Hygiene (England) Regulations 2006 (SI 2006/14), which implement EU food hygiene Regulation (EC) No 852/2004. Enforcement is carried out by local authority Environmental Health Officers (EHOs) and Trading Standards Officers (TSOs) under powers in Sections 9 to 12 of the Act including inspection, detention, and seizure of food.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nz_food_act_2014",
        "eu_food_additives_regulation_1333_2008",
        "eu_general_food_law_regulation_178_2002",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-food-act-2014",
      "eu-food-additives-regulation-1333-2008",
      "eu-novel-foods-regulation-2015-2283"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-food-safety-act-1990-amendment-2023",
    "title": "Food Safety Act 1990 (as amended by the Food Safety (Amendment) Regulations 2023)",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Food Safety Act 1990, as amended in 2023, imposes strict liability on food businesses for ensuring food is safe, of proper quality, and correctly labelled. It establishes enforcement powers for local authorities and requires due diligence defences under Section 37, with mandatory compliance for all food handlers, retailers, and manufacturers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004",
      "eu-allergen-regulation-2021-382",
      "codex-alimentarius-gen"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-food-safety-act-1990-fsa-hygiene-regulations-food-business",
    "title": "UK Food Safety Act 1990 & Food Safety and Hygiene (England) Regulations 2013 - Due Diligence",
    "domain": "Food & Hospitality",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The UK Food Safety Act 1990 and associated Hygiene Regulations establish the legal duty for food business operators to ensure food is safe to eat, not injurious to health, and not falsely described - enforced by local authority Environmental Health with seizure powers and fines up to GBP 20,000 per offence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-food-standards-agency-fsa-post-brexit-2023",
    "title": "UK Food Standards Agency Post-Brexit Regulatory Framework 2023 - Great Britain Food Law: GB Retained EU Law on Food Safety, UK Specific Additive Permissions, Windsor Framework for Northern Ireland, FSA Risk Assessment Independence and Food Crime Unit",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "This node describes the UK's independent food safety framework for Great Britain post-Brexit, requiring food businesses to comply with assimilated (formerly 'retained') EU food law preserved by the European Union (Withdrawal) Act 2018, and separate compliance pathways for Northern Ireland under the Windsor Framework. Key obligations include adherence to assimilated Regulation (EC) No 852/2004 on the hygiene of foodstuffs (Article 4 - general food safety management based on HACCP), food additive, flavouring and novel-food authorisations under domestic instruments such as The Food Additives, Food Flavourings and Novel Foods (Authorisations) (England) Regulations 2023 (SI 2023/334, in force 15 May 2023), allergen information under assimilated Regulation (EU) No 1169/2011, and reporting of suspected food crime to the FSA's National Food Crime Unit (NFCU), an objective of the FSA Strategy 2022-2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-food-hygiene-regulation-852-2004",
      "brc-food-safety-standard-issue-9",
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-food-information-regulation-1169-2011-labelling"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-forestry-act-1967",
    "title": "UK Forestry Act 1967 (c. 10): Forestry Commissioners, Felling Licences and Restocking",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Forestry Act 1967 (c. 10) is the principal statute governing forestry and the control of tree felling in Great Britain, administered by the Forestry Commissioners and the devolved forestry authorities. Its forestry and afforestation provisions establish the general duty and powers of the Forestry Commissioners to promote the interests of forestry, the development of afforestation, and the production and supply of timber, including powers to manage land and delegate functions. Its felling-control provisions make it an offence to fell growing trees without a felling licence granted by the Commissioners, subject to exceptions for small-scale felling, trees below specified dimensions, and operations carried out under an approved plan of forest operations or other approved scheme; section 10 governs applications for felling licences and section 9 the requirement for a licence. Where trees are felled without a licence, the Commissioners may serve a restocking notice requiring the landowner to restock and maintain the land, and unauthorised felling is subject to penalty. The administration and finance provisions govern advisory committees, the acquisition and disposal of land, and the Forestry Fund, while the general provisions cover byelaws, enforcement, and interpretation. The Act is the legal foundation of sustainable timber management and felling regulation in the United Kingdom.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-fraud-act-2006",
    "title": "UK Fraud Act 2006 - Statutory Offences of Fraud by False Representation Failure to Disclose and Abuse of Position",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Fraud Act 2006 created a general offence of fraud committed in three ways including fraud by false representation, fraud by failing to disclose information when there is a legal duty to do so, and fraud by abuse of position where a person occupies a position in which they are expected to safeguard the financial interests of another, replaced the common law conspiracy to defraud only by repealing certain pre-existing offences while leaving the common law conspiracy intact, criminalised obtaining services dishonestly, and provided penalties of up to ten years imprisonment for individuals convicted on indictment for the general fraud offence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-bribery-act-2010"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-fraud-act-2006-section-1-fraud-general-offence",
    "title": "UK Fraud Act 2006 Section 1 — Fraud (General Offence)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person is guilty of fraud if in breach of any of the three component offences: Section 2 (fraud by false representation), Section 3 (fraud by failing to disclose information), or Section 4 (fraud by abuse of position). Fraud is a single offence with three modes of commission. Maximum penalty on indictment is 10 years' imprisonment, an unlimited fine, or both. On summary conviction, imprisonment up to the general magistrates' court limit and/or a fine up to the statutory maximum. Northern Ireland summary cap is 6 months.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "single_offence_three_modes",
        "section_2_false_representation_route",
        "section_3_failure_to_disclose_route",
        "section_4_abuse_of_position_route",
        "indictable_maximum_10_years_unlimited_fine",
        "summary_conviction_penalty",
        "northern_ireland_six_month_summary_cap"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fraud-act-2006-section-3-fraud-by-failing-to-disclose",
      "uk-fraud-act-2006-section-4-fraud-by-abuse-of-position",
      "uk-fraud-act-2006-section-6-possession-of-articles-for-fraud",
      "uk-fraud-act-2006-section-11-obtaining-services-dishonestly"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-fraud-act-2006-section-11-obtaining-services-dishonestly",
    "title": "UK Fraud Act 2006 Section 11 - Obtaining Services Dishonestly (Services Available on Payment Basis, Dishonest Avoidance of Payment, Knowledge and Intent)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 11 of the Fraud Act 2006 (c. 35) creates the offence of obtaining services dishonestly. The offence occurs when a person obtains services for himself or another by a dishonest act, the services are made available on the basis that payment has been, is being or will be made, and the person obtains them without payment being made in full or at all, knowing the services are available on a payment basis and intending that payment will not be made or not be made in full. Section 11 captures dishonest use of public transport without payment, dishonest streaming-service or subscription-service access, dishonest food and beverage consumption (the 'bilking' pattern), dishonest accommodation use, and AI/digital service consumption where payment is owed. Maximum penalty: on indictment 5 years and/or unlimited fine; on summary conviction the general magistrates' limit and/or statutory maximum fine; either-way offence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_11_text",
        "services_available_on_payment_basis_test",
        "dishonesty_and_intent_test",
        "penalty_section_11_3",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fraud-act-2006"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-fraud-act-2006-section-2-fraud-by-false-representation",
    "title": "UK Fraud Act 2006 - Section 2 Fraud by False Representation",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "Section 2 of the Fraud Act 2006 (UK) defines the offence of fraud by false representation. Subsection (1) provides that a person is in breach of this section if he (a) dishonestly makes a false representation, and (b) intends, by making the representation, (i) to make a gain for himself or another, or (ii) to cause loss to another or to expose another to a risk of loss. Subsection (2) provides that a representation is false if (a) it is untrue or misleading, and (b) the person making it knows that it is, or might be, untrue or misleading. Subsection (3) provides that 'representation' means any representation as to fact or law, including a representation as to the state of mind of (a) the person making the representation, or (b) any other person. Subsection (4) provides that a representation may be express or implied. Subsection (5) provides that for the purposes of this section a representation may be regarded as made if it (or anything implying it) is submitted in any form to any system or device designed to receive, convey or respond to communications (with or without human intervention). Section 2 is the most commonly charged of the three Fraud Act 2006 offences and is the gateway offence in most consumer, financial, identity, and online fraud prosecutions; it expressly catches representations made to automated systems, making it directly applicable to machine-to-machine and agentic fraud scenarios. The section extends to England and Wales and Northern Ireland.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fraud-act-2006"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-fraud-act-2006-section-3-fraud-by-failing-to-disclose",
    "title": "UK Fraud Act 2006 Section 3 - Fraud by Failing to Disclose Information (Legal Duty Threshold, Dishonest Failure, Intent to Gain or Cause Loss)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 3 of the Fraud Act 2006 (c. 35) creates the offence of fraud by failing to disclose information. A person is in breach where he (a) dishonestly fails to disclose to another person information which he is under a legal duty to disclose, and (b) intends, by failing to disclose the information, (i) to make a gain for himself or another, or (ii) to cause loss to another or to expose another to a risk of loss. The 'legal duty to disclose' is the operative threshold and is interpreted to include fiduciary duties, contractual duties, customary disclosure duties in regulated transactions (insurance utmost good faith, securities prospectus disclosure, M&A disclosure), and statutory duties. Section 3 sits alongside section 2 (false representation) and section 4 (abuse of position) as the three primary Fraud Act offences. Maximum penalty under section 1(3) is 10 years on indictment plus unlimited fine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_3_text",
        "legal_duty_to_disclose_threshold",
        "dishonesty_test_ivey",
        "penalty_section_1_3",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fraud-act-2006"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-fraud-act-2006-section-4-fraud-by-abuse-of-position",
    "title": "UK Fraud Act 2006 Section 4 - Fraud by Abuse of Position (Position to Safeguard Financial Interests, Dishonest Abuse, Omission Sufficient)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 4 of the Fraud Act 2006 (c. 35) creates the offence of fraud by abuse of position. Under section 4(1), a person is in breach if he (a) occupies a position in which he is expected to safeguard, or not to act against, the financial interests of another person, (b) dishonestly abuses that position, and (c) intends, by means of the abuse of that position, (i) to make a gain for himself or another, or (ii) to cause loss to another or to expose another to a risk of loss. Under section 4(2), a person may be regarded as having abused his position even though his conduct consisted of an omission rather than an act. Section 4 captures abuse by fiduciaries, employees in positions of trust, attorneys under powers of attorney, deputies under Mental Capacity Act 2005 orders, professional advisers, and corporate officers. Maximum penalty under section 1(3) is 10 years on indictment plus unlimited fine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_4_text",
        "position_to_safeguard_financial_interests_test",
        "omission_sufficient_section_4_2",
        "penalty_section_1_3",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fraud-act-2006"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-fraud-act-2006-section-6-possession-of-articles-for-fraud",
    "title": "UK Fraud Act 2006 Section 6 - Possession Etc of Articles for Use in Frauds (Possession or Under Control of Any Article for Use in Course of or in Connection with Any Fraud)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 6 of the Fraud Act 2006 (c. 35) creates the offence of possession etc of articles for use in frauds. Under section 6(1), a person is guilty of an offence if he has in his possession or under his control any article for use in the course of or in connection with any fraud. The offence is broad and inchoate - it precedes the actual fraud offence and captures possession with intent to use, regardless of whether the underlying fraud has been committed. Under section 6(2), a person guilty of an offence under this section is liable: on summary conviction, to imprisonment not exceeding the general limit in a magistrates' court or a fine not exceeding the statutory maximum or both; on conviction on indictment, to imprisonment not exceeding 5 years or a fine or both. Northern Ireland summary conviction maximum is 6 months. Section 6 commonly accompanies prosecutions for sections 2-4 substantive fraud offences and operates as the standalone offence for fraud-tool possession where the substantive fraud is not yet provable. 'Article' is interpreted broadly to include physical items (skimmer devices, fraudulent documents, lists of victim details) and electronic articles (malware, phishing kits, stolen credentials, identity documents).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_6_text",
        "article_definition_broad_physical_and_electronic",
        "possession_or_under_control_test",
        "for_use_in_course_of_or_in_connection_with_any_fraud_test",
        "penalty_section_6_2_5_years_indictment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fraud-act-2006"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-frontier-ai-safety-commitments-seoul-2024",
    "title": "Frontier AI Safety Commitments - AI Seoul Summit (May 21-22, 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On May 21, 2024 at the AI Seoul Summit co-hosted by the United Kingdom and the Republic of Korea, 16 frontier AI companies signed the Frontier AI Safety Commitments. The Commitments require signatories to: (1) Assess the risks posed by their frontier models or systems across the AI lifecycle, including before deploying that model or system, and as appropriate, before and during training. Risk assessments should consider model capabilities and the context in which they are developed and deployed, as well as the efficacy of implemented mitigations to reduce the risks associated with the foreseeable use and misuse of those models and systems; (2) Set thresholds at which severe risks posed by a model or system, unless adequately mitigated, would be deemed intolerable, and articulate when and how mitigations will be applied to keep risks within defined thresholds; (3) Publish their approach to identifying, assessing, and managing risks - including the implementation of more stringent mitigations, the consequences of not adhering to defined thresholds, and the processes for the responsible scaling of capabilities. Signatories include Anthropic, Cohere, Google DeepMind, IBM, Inflection AI, Meta, Microsoft, Mistral AI, Naver, OpenAI, Samsung Electronics, Schmidt Sciences, Technology Innovation Institute, xAI, and Zhipu.ai. The Commitments operationalise scientific consensus emerging from the International AI Safety Report 2025 (Bengio Chair) and complement the Bletchley Declaration (November 2023) and the Council of Europe Framework Convention on AI (CETS 225, September 2024). Companies publish Frontier AI Safety Frameworks (also called Responsible Scaling Policies) operationalising the Commitments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "international_alignment",
        "nist_framework",
        "regulatory_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "anthropic-responsible-scaling-policy-v2-1-2025",
      "openai-preparedness-framework-2023",
      "uk-international-ai-safety-report-2025",
      "uk-ai-safety-institute-framework-2024",
      "bletchley-declaration-2023-frontier-ai-safety"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-fsma-cryptoassets-regulations-2026-si-102",
    "title": "UK FSMA 2000 (Cryptoassets) Regulations 2026, SI 2026/102 - Qualifying Cryptoasset Public Offers and Market Abuse",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Persons offering qualifying cryptoassets to the public in the United Kingdom must obtain Financial Conduct Authority authorisation, publish a disclosure document, and refrain from insider dealing, unlawful disclosure of inside information, and market manipulation in qualifying cryptoassets and related instruments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-ukpga-2000-8-fsma-2000",
      "eu-markets-in-crypto-assets-regulation-mica-2023-1114"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-gambling-act-2005",
    "title": "Gambling Act 2005 - Licensing Framework, Gambling Commission Powers and Duties, and Consumer Protection Requirements",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Gambling Act 2005 establishes a comprehensive regulatory framework for all forms of gambling in Great Britain, requiring operators and individuals to obtain licenses from the Gambling Commission and adhere to strict licensing objectives under Section 1, including preventing crime, ensuring fairness, and protecting children. It applies to all entities providing gambling facilities, including remote operators, casinos, betting intermediaries, and lotteries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-gambling-act-2005-gambling-commission-licence-conditions",
    "title": "UK Gambling Act 2005 - Gambling Commission Licence Conditions and Codes of Practice",
    "domain": "Gaming & Gambling",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Gambling Act 2005 (c.19) establishes the Gambling Commission as the regulator for commercial gambling in Great Britain; operators require an operating licence; licence conditions and codes of practice (LCCP) impose mandatory obligations on customer interaction, AML, and safer gambling including affordability checks from 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-gambling-act-2005-licence-conditions",
    "title": "Gambling Act 2005 - Licensing Objectives, Operating and Personal Licence Conditions, and Regulatory Powers",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The Gambling Act 2005 establishes the legal framework for gambling regulation in Great Britain, requiring all operators and individuals providing gambling facilities to hold appropriate operating or personal licences issued by the Gambling Commission. Licence conditions are set under Sections 75-88 and must align with the three licensing objectives: preventing gambling crime, ensuring fairness, and protecting children and vulnerable persons (Section 1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "eu-aml-directive-5-gambling-sector"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-gambling-act-2005-licensing-conditions-remote-operators",
    "title": "UK Gambling Act 2005 - Licensing Conditions and Codes of Practice for Remote Gambling Operators",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Gambling Act 2005 (UK) establishes the three licensing objectives (preventing crime, ensuring fairness, protecting children and vulnerable persons) and requires all remote gambling operators serving UK customers to hold a Gambling Commission licence under Section 67. The Licence Conditions and Codes of Practice (LCCP) impose mandatory social responsibility, anti-money laundering, and technical standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-data-protection-act-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-gambling-act-2005-section-1-licensing-objectives",
    "title": "Gambling Act 2005, Section 1: The licensing objectives",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must ensure all gambling activities align with the three core licensing objectives: preventing crime and disorder, ensuring fair and open conduct, and protecting children and vulnerable persons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-gambling-act-2005-section-116-remote-gambling",
    "title": "Gambling Act 2005 Section 116 Review",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Gambling Commission may review an operating licence for various reasons, including suspected non-compliance or unsuitability, and must notify the licensee and allow them to make representations during the review.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-gambling-act-2005-section-13-gambling-commission",
    "title": "Gambling Act 2005, Section 13: Betting intermediary",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This section defines a 'betting intermediary' as a person providing a service to facilitate bets between others and clarifies that this activity constitutes providing facilities for betting under the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-gambling-act-2005-section-33-provision-of-facilities",
    "title": "UK Gambling Act 2005 Section 33 - Provision of Facilities for Gambling (Operating Licence Offence)",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Section 33 of the UK Gambling Act 2005 (c. 19) creates the foundational operating licence offence for providing facilities for gambling without lawful authority: subsection (1) provides 'A person commits an offence if he provides facilities for gambling' unless an exception applies under specified provisions; the exceptions cover remote gambling under operating licence (sections 34-35), club and miners' welfare institute gambling (sections 269, 271), premises with alcohol licences (section 279), prize gaming (sections 289-292), private gaming and betting (section 296), non-commercial gaming (section 298), and other categorical exemptions; the section is enforced primarily by the Gambling Commission established under Part 2 of the Act with licensing, supervisory, and enforcement powers; penalties on summary conviction up to 51 weeks imprisonment (6 months in Scotland) and unlimited fine; the Gambling Act is the principal UK gambling regulation framework covering land-based and remote gambling and operates alongside the parallel Northern Ireland framework under separate legislation; the National Lottery is regulated separately under the National Lottery etc. Act 1993; the Act applies in England, Wales, and Scotland with the Gambling Commission's jurisdiction extending across these three nations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "gambling_commission_establishment",
        "operating_licence_framework",
        "remote_gambling_section_45_definition",
        "industry_mapping",
        "enforcement_anchors",
        "consumer_protection_focus"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-31-usc-5363-uigea-unlawful-internet-gambling",
      "us-18-usc-1084-wire-act-gambling",
      "us-41-usc-3301-full-open-competition-federal-procurement"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-gambling-act-2005-section-42-offence-cheating",
    "title": "Gambling Act 2005, Section 42: Cheating",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must ensure that no individual cheats at gambling or enables or assists another person to cheat, which constitutes a criminal offence regardless of whether the cheating results in a win.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-gambling-act-2005-section-67-operating-licence",
    "title": "Gambling Act 2005, Section 67: Remote gambling",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must ensure their operating licence correctly identifies whether it is a remote operating licence and that it does not improperly combine remote and non-remote gambling activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-gambling-commission-lccp-2024",
    "title": "Licence Conditions and Codes of Practice (LCCP) Version effective from 6 April 2026",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Licence Conditions and Codes of Practice (LCCP) sets out the legal requirements that all gambling operators licensed by the UK Gambling Commission must meet to ensure socially responsible gambling, fair operation, and regulatory compliance. Key obligations are enforced through condition-specific requirements, with ongoing updates communicated via e-bulletin.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-gambling-act-2005",
      "fatf-recommendation-16-travel-rule-crypto"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-gambling-levy-regulations-2025",
    "title": "The Gambling Levy Regulations 2025 (SI 2025/213)",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "These Regulations introduce a statutory levy on Gambling Commission operating licence holders under sections 123 and 355(1) of the Gambling Act 2005, charged as a percentage of the leviable amount that varies by licence type (1.1% for remote licences down to 0.1% for certain non-remote licences), payable to the Gambling Commission before 1 October following each levy period, in force from 6 April 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-gambling-act-2005",
      "uk-gambling-act-2005-section-13-gambling-commission",
      "uk-gambling-commission-lccp-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-game-act-1831",
    "title": "UK Game Act 1831 (c.32): Game Certificates, Close Seasons and Trespass in Pursuit of Game",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Game Act 1831 (c. 32) remains the principal statute governing the taking of game in England and Wales, regulating close seasons, the requirement to hold a game certificate, the sale of game, and trespass in pursuit of game, enforced through the magistrates' courts. Section 2 defines what is deemed game, including hares, pheasants, partridges, grouse, heath or moor game, black game, and bustards. Section 3 sets the days and seasons during which game shall not be killed, establishing the close seasons for each species, and provides a penalty for laying poison to kill game. Section 17 permits certificated persons to sell game to licensed dealers, and section 23 provides a penalty for killing or taking game without holding a game certificate. Section 24 provides a penalty for destroying or taking the eggs of game. Section 25 provides a penalty for selling game without a licence and on certificated persons selling to unlicensed persons. Section 30 provides a penalty on persons trespassing in the daytime upon land in search or pursuit of game, and section 31 allows occupiers to require trespassers to quit the land and give their names and addresses, with arrest available on refusal. Section 32 provides an aggravated penalty on persons found armed and using violence. The Act is the foundational game law and anti-poaching regime in daytime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-gas-act-1986",
    "title": "UK Gas Act 1986 - Gas Transportation and Supply Licensing Framework",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "No person may convey gas through pipes or supply gas to premises in Great Britain without a licence granted by Ofgem under Section 7 or 7A of the Gas Act 1986, or an applicable exemption. Ofgem regulates network access, transportation tariffs, and consumer protections through licence conditions enforced by provisional and final orders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "electricity_act",
        "gas_act_1995",
        "energy_act_2023",
        "ofgem_gas_slcs",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-ofgem-supply-licence-conditions-2024",
      "eu-gas-decarbonisation-package-2024",
      "eu-gas-directive-2009-73"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-genetic-technology-precision-breeding-act-2023",
    "title": "UK Genetic Technology (Precision Breeding) Act 2023 (c. 6): Regulation of Precision Bred Plants and Animals",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Genetic Technology (Precision Breeding) Act 2023 (c. 6) creates a distinct regulatory regime in England for precision bred plants and animals, separating them from the regime for genetically modified organisms, and is administered by the Secretary of State for Environment, Food and Rural Affairs together with the Food Standards Agency for food and feed. Part 1 defines a precision bred organism as one whose genome contains features resulting from the application of modern biotechnology that could have resulted from traditional processes or natural transformation, and applies to both plants and animals. Part 2 regulates the release and marketing of precision bred organisms in England, establishing a precision bred confirmation issued on the advice of an advisory committee, a precision bred animal marketing authorisation that requires an animal welfare declaration assessed by a welfare advisory body before a precision bred animal or its progeny may be marketed, a public precision breeding register, notification requirements, and powers of inspection, suspension, and revocation. Part 3 regulates the placing on the market of food and feed produced from precision bred organisms through a marketing authorisation administered by the Food Standards Agency, with its own register. Part 4 provides enforcement through compliance notices, stop notices, and monetary penalties with rights of appeal, and Part 5 contains provisions on fees, regulations, and commencement. The Act is the United Kingdom's framework for gene-edited crops and livestock.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-genetic-technology-precision-breeding-regulations-2025",
    "title": "The Genetic Technology (Precision Breeding) Regulations 2025 (SI 2025/581)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "These Regulations operationalise the Genetic Technology (Precision Breeding) Act 2023 in England, requiring a release notice to the Secretary of State at least 20 days before releasing a precision bred organism, a precision bred confirmation and marketing notice before marketing, a public precision breeding register, and a separate Food Standards Agency food and feed marketing authorisation register; they come into force six months after being made.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-genetic-technology-precision-breeding-act-2023",
      "uk-food-safety-act-1990",
      "uk-food-standards-agency-fsa-post-brexit-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-genome-uk-strategy-2020-genomics-england",
    "title": "UK Genome UK Strategy 2020 The Future of Healthcare Genomics England Whole Genome Sequencing Data Sharing Industrial Growth and Public Trust Framework",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "The United Kingdom Genome UK strategy published by the Department of Health and Social Care on 26 September 2020 establishes the national genomics strategy across diagnosis personalised medicine population genomics and research organised in three pillars covering Pillar 1 diagnosis and personalised medicine through the NHS Genomic Medicine Service Pillar 2 prevention and research enabled by NHS clinical-trial-ready datasets and Pillar 3 industrial growth and innovation enabled by the world-leading UK Biobank and Genomics England delivery infrastructure. Implementation is delivered via Genomics England the wholly-owned company of the Department of Health and Social Care covering the NHS Genomic Medicine Service Test Directory commissioning the NHS Genomic Medicine Service Alliance regional delivery the National Genomics Healthcare Strategy Implementation Coordination Group and the 100000 Genomes Project legacy of whole genome sequencing data. Strategy implementation aligned with UK General Data Protection Regulation and the Data Protection Act 2018 for special category genetic data the Human Tissue Act 2004 for sample handling and the Caldicott Guardian framework for confidentiality. Genome UK is followed by successive implementation plans (2021-2022, 2022-2025).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-data-protection-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-global-anti-corruption-sanctions-regulations-2021-si-488",
    "title": "UK Global Anti-Corruption Sanctions Regulations 2021 SI 2021/488 - Asset Freeze and Immigration Sanctions Targeting Serious Corruption Worldwide",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Global Anti-Corruption Sanctions Regulations 2021 establish the United Kingdom's autonomous Magnitsky-style sanctions regime targeting individuals and entities involved in serious corruption organised in eight parts covering general provisions and purposes, designation power and criteria in Part 2 with regulation 6 designation criteria and regulation 7 ownership and control rules, financial sanctions with asset freeze and prohibitions on making funds or economic resources available in Part 3, immigration sanctions in Part 4, Treasury licences for purposes set out in Schedule 2 including basic needs legal services and humanitarian assistance in Part 5, information reporting and investigative powers in Part 6, enforcement and penalties for violations in Part 7, and administrative procedures and revocations in Part 8, and operate alongside but distinct from the Global Human Rights Sanctions Regulations 2020 to capture conduct that does not amount to a human rights violation but constitutes bribery or misappropriation of public assets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018",
      "uk-bribery-act-2010"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-global-human-rights-sanctions-regulations-2020-si-680",
    "title": "UK Global Human Rights Sanctions Regulations 2020 SI 2020/680 - Magnitsky-Style Asset Freeze and Immigration Sanctions for Serious Human Rights Violations",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Global Human Rights Sanctions Regulations 2020 establish the United Kingdom's autonomous Magnitsky-style sanctions regime targeting individuals and entities responsible for serious human rights violations worldwide organised in seven parts covering general provisions and purposes, designation power and criteria in Part 2 with regulation 6 designation criteria for involvement in serious human rights violations such as the right to life right not to be tortured and right to be free from slavery and regulation 7 ownership and control rules, asset freeze and prohibitions on making funds or economic resources available in Part 3, immigration sanctions in Part 4, Treasury licences for Schedule 2 purposes including humanitarian assistance and basic needs in Part 5, information reporting obligations in Part 6, and enforcement penalties and corporate officer liability in Part 7, and were the first sanctions regulations made under the Sanctions and Anti-Money Laundering Act 2018 to be deployed as a standalone instrument independent of any EU regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018",
      "uk-human-rights-act-1998"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-gmo-contained-use-regulations-2014-hse",
    "title": "UK Genetically Modified Organisms (Contained Use) Regulations 2014 - HSE Consent, Risk Classification and Biosafety",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Genetically Modified Organisms (Contained Use) Regulations 2014 (SI 2014/1663) implement EU Directive 2009/41/EC on the contained use of genetically modified micro-organisms (GMMs) in the United Kingdom (retained in UK law post-Brexit under the European Union (Withdrawal) Act 2018); the Health and Safety Executive (HSE) is the competent authority; the Regulations require operators to conduct a risk assessment for all activities using GMOs in contained systems (laboratories, greenhouses, fermenters, pilot plants); activities are classified Class 1 (negligible risk) to Class 4 (high risk); Class 1 activities require notification to HSE before first use; Class 2, 3, and 4 activities require HSE consent before commencement; operators must have an institutional Biological Safety Committee (BSC) and a designated Biological Safety Officer (BSO); genetic modification (GM) activities must comply with containment measures in Schedule 5; the Advisory Committee on Genetic Modification (ACGM) advises HSE on complex risk assessments; HSE may issue prohibition notices for unsafe GMO activities; penalties under Health and Safety at Work Act 1974 Section 33: unlimited fine on conviction on indictment; the Precision Breeding Act 2023 excludes certain gene-editing products from GMO regulations for agricultural applications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gmo-deliberate-release-directive-2001-18"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-guinea-sanctions-eu-exit-regulations-2019-si-1145",
    "title": "UK Guinea (Sanctions) (EU Exit) Regulations 2019 SI 2019/1145 Asset Freeze Immigration Sanctions and Trade Restrictions Following EU Exit",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Guinea (Sanctions) (EU Exit) Regulations 2019 establish the United Kingdom's autonomous sanctions framework targeting persons connected with serious human rights violations or undermining democracy in the Republic of Guinea, organised across 8 parts and 41 regulations plus 2 schedules covering general provisions and the regulation 4 purpose statement in Part 1, designation power and criteria in Part 2 with regulation 6 designation criteria and regulation 7 ownership and control rules supported by Schedule 1 shareholding calculation rules, financial asset freeze and prohibitions on making funds or economic resources available to designated persons in regulations 11 to 15 in Part 3, immigration restrictions in Part 4, Treasury licensing exceptions including national security and serious crime carve-outs in Part 5 supported by Schedule 2 licensed purposes, information reporting obligations for relevant firms in Part 6, criminal enforcement and penalties in Part 7, and supplementary and transitional provisions revoking prior EU Council Regulation in Part 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-health-and-care-act-2022",
    "title": "United Kingdom Health and Care Act 2022: NHS England Renaming, Establishment of Integrated Care Boards and Integrated Care Partnerships, Workforce Planning Reporting, Care Quality Commission Reviews of Integrated Care Systems, Regulation of Local Authority Adult Social Care Functions, and Advertising of Less Healthy Food and Drink",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Health and Care Act 2022, chapter 31 of 2022, received Royal Assent on 28 April 2022 and is the principal United Kingdom statute reorganising the National Health Service in England by establishing Integrated Care Systems comprising statutory Integrated Care Boards and Integrated Care Partnerships, replacing Clinical Commissioning Groups, with additional provisions on workforce planning, social care reform, advertising restrictions on less healthy food and drink, and Care Quality Commission oversight of integrated care systems, administered by the Department of Health and Social Care, NHS England, and the Care Quality Commission. Health and Care Act 2022, section 1 renames the NHS Commissioning Board as NHS England. Health and Care Act 2022, section 19 establishes Integrated Care Boards (ICBs) as statutory bodies responsible for commissioning health services for their populations, replacing Clinical Commissioning Groups effective 1 July 2022. Health and Care Act 2022, section 26 provides for Integrated Care Partnerships (ICPs) bringing together NHS bodies, local authorities, and other partners to develop integrated care strategies. Health and Care Act 2022, section 31 provides for Care Quality Commission reviews of integrated care systems. Health and Care Act 2022, section 41 requires a report on assessing and meeting workforce needs. Health and Care Act 2022, section 163 governs the regulation of local authority functions relating to adult social care. Health and Care Act 2022, section 172 imposes restrictions on the advertising of less healthy food and drink. The Act is the controlling United Kingdom statute for the integrated care system reorganisation of the NHS in England.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-health-and-safety-at-work-act-1974-section-2-employer-general-duties",
    "title": "UK Health and Safety at Work Act 1974 Section 2 - General Duties of Employers to Their Employees (Reasonably Practicable Standard, Plant Systems Substances, Information Instruction Training Supervision, Place of Work, Working Environment)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 2 of the Health and Safety at Work etc. Act 1974 (c. 37) imposes the cornerstone UK health and safety duty - the duty of every employer to ensure, so far as is reasonably practicable, the health, safety and welfare at work of all his employees. Under section 2(1), the general duty is broad and qualitative - 'reasonably practicable' is the operative standard balancing risk against the cost (in time, money, and effort) of mitigation. Section 2(2) lists particular matters to which the duty extends: (a) plant and systems of work safe and without risks to health; (b) safe arrangements for use, handling, storage and transport of articles and substances; (c) provision of information, instruction, training and supervision; (d) maintenance of place of work and means of access/egress; (e) provision of working environment safe and without risks to health and adequate facilities and welfare arrangements. Section 2(3) requires a written health and safety policy and organisational arrangements (for employers with 5+ employees). Section 2(4) provides for trade union safety representatives. Section 2(6) imposes a duty to consult safety representatives. Section 2(7) requires establishment of safety committees. Maximum penalty under section 33 read with the Health and Safety (Offences) Act 2008: unlimited fine; for individuals up to 2 years imprisonment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_2_text",
        "reasonably_practicable_standard_edwards_v_national_coal_board",
        "particular_matters_section_2_2_a_to_e",
        "written_safety_policy_section_2_3_5_employees_threshold",
        "consultation_and_safety_committee_sections_2_4_6_7",
        "penalty_section_33_and_health_and_safety_offences_act_2008",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-health-and-safety-at-work-act-1974-section-3-duties-to-non-employees",
    "title": "UK Health and Safety at Work Act 1974 Section 3 - General Duties of Employers and Self-Employed to Persons Other Than Their Employees (Members of Public, Contractors, Visitors, Reasonably Practicable Standard)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 3 of the Health and Safety at Work etc. Act 1974 (c. 37) extends the reasonably practicable health and safety duty to persons other than the employer's own employees - members of the public, contractors, contractors' employees, visitors, customers, and any other persons affected by the conduct of the undertaking. Under section 3(1), it shall be the duty of every employer to conduct his undertaking in such a way as to ensure, so far as is reasonably practicable, that persons not in his employment who may be affected thereby are not thereby exposed to risks to their health or safety. Under section 3(2), an equivalent duty applies to self-employed persons conducting an undertaking of a prescribed description (the original 'all self-employed' scope was narrowed by the Health and Safety at Work etc. Act 1974 (General Duties of Self-Employed Persons) (Prescribed Undertakings) Regulations 2015 to a defined list of undertakings). Section 3(2A) provides for regulations to describe undertakings by reference to type of activities and exposure profile. Section 3(3) requires prescribed information to be given to non-employees affected by the conduct of the undertaking. Section 3 is the operative provision for prosecuting corporate manslaughter precursor incidents involving the public, contractor fatalities, and visitor-injury incidents on premises.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_3_text",
        "non_employee_persons_affected_test_section_3_1",
        "self_employed_prescribed_undertakings_2015_regulations",
        "reasonably_practicable_section_3_1_continues_section_2_standard",
        "contractor_management_intersection_with_cdm_2015",
        "penalty_section_33_unlimited_fine_and_section_37_director_liability",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-health-and-safety-at-work-act-1974-section-2-employer-general-duties"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-health-and-safety-at-work-act-1974-section-37-director-liability",
    "title": "UK Health and Safety at Work Act 1974 Section 37 - Offences by Bodies Corporate (Director Manager Secretary Personal Liability for Consent Connivance or Neglect)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 37 of the Health and Safety at Work etc. Act 1974 (c. 37) extends corporate health and safety liability to directors, managers, secretaries, and other similar officers in their personal capacity where the corporate offence was committed with their consent, connivance, or attributable to their neglect. Under section 37(1), where an offence under the relevant statutory provisions committed by a body corporate is proved to have been committed with the consent or connivance of, or to have been attributable to any neglect on the part of, any director, manager, secretary or other similar officer of the body corporate, or a person who was purporting to act in any such capacity, he as well as the body corporate shall be guilty of that offence and shall be liable to be proceeded against and punished accordingly. Under section 37(2), where the affairs of a body corporate are managed by its members (typically LLPs), the preceding subsection applies to members in connection with their management functions as if they were directors. Section 37 prosecutions of directors carry up to 2 years imprisonment and unlimited fine, and trigger Director's Disqualification under the Company Directors Disqualification Act 1986 section 2(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_37_text",
        "consent_connivance_or_neglect_three_alternative_thresholds",
        "neglect_threshold_attorney_general_v_p_and_l_sugar_refineries_2001",
        "director_manager_secretary_or_similar_officer_scope",
        "penalty_section_33_and_companies_act_director_disqualification",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-health-and-safety-at-work-act-1974-section-2-employer-general-duties",
      "uk-health-and-safety-at-work-act-1974-section-3-duties-to-non-employees"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-health-and-social-care-act-2008-section-20-registration-requirements",
    "title": "Health and Social Care Act 2008, Section 20: Regulation of regulated activities",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations carrying on regulated activities must comply with regulations established by the Secretary of State concerning service quality, safety, personnel fitness, premises, record-keeping, and transparency to ensure no avoidable harm is caused to service users.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-health-safety-at-work-act-1974",
    "title": "Health and Safety at Work etc. Act 1974",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This Act imposes a general duty on all UK employers to ensure, so far as is reasonably practicable, the health, safety, and welfare at work of all their employees. Key requirements under Section 2 include providing safe systems of work, conducting risk assessments, and establishing a written safety policy if employing five or more people.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-work-safety",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-higher-education-freedom-of-speech-act-2023",
    "title": "UK Higher Education (Freedom of Speech) Act 2023 - Duties of Registered Higher Education Providers and Students Unions",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Higher Education (Freedom of Speech) Act 2023 (UK) places statutory duties on registered English higher education providers, their constituent colleges, and students unions to take reasonably practicable steps to secure freedom of speech within the law for staff, students, members, and visiting speakers. Section 1 inserts new sections A1 to A6 into the Higher Education and Research Act 2017 establishing the duty, the code of practice requirement, and the prohibition on non-disclosure agreements in respect of harassment, bullying, or sexual misconduct allegations (the NDA prohibition appears at inserted section A1(11)). Section 2 places equivalent duties on constituent institutions. Section 3 places equivalent duties on students unions. Section 4 creates the civil claims (tort) route for breach of duty (currently not in force pending Government decision). Section 8 establishes the OfS complaints scheme. Section 10 establishes the Office for Students Director for Freedom of Speech and Academic Freedom with monitoring, investigation, and enforcement powers. The Act commenced in stages between July 2024 and August 2025 following a Government pause and partial repeal review in 2024 to 2025. The Act applies to providers registered with the Office for Students under the Higher Education and Research Act 2017.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-equality-act-2010-protected-characteristics",
      "uk-online-safety-act-2023",
      "uk-data-protection-act-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-higher-education-freedom-speech-act-2023",
    "title": "Higher Education (Freedom of Speech) Act 2023",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Act imposes statutory duties on higher education providers, student unions, and registered providers in England and Wales to secure freedom of speech and academic freedom for students, staff, and visiting speakers. Key obligations are established under Section 1 (duty to promote freedom of speech), Section 2 (duty to protect academic freedom), and Section 5 (student union duties).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-higher-education-research-act-2017-ofs",
    "title": "Higher Education and Research Act 2017",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This Act establishes the Office for Students (OfS) as the primary regulator for higher education in England, mandating registration, monitoring of conditions, and enforcement actions to protect student interests and maintain quality.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-higher-education-research-act-2017-ofs-conditions-registration",
    "title": "UK Higher Education and Research Act 2017 - OfS Conditions of Registration for English Providers",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Higher Education and Research Act 2017 (HERA) established the Office for Students (OfS) as the regulator for higher education in England. Registered providers must meet Conditions of Registration covering student interests, quality and standards, governance, accountability, and financial sustainability. Failure to meet conditions can result in de-registration, financial penalties, or specific sanctions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-data-protection-act-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-housing-act-2004-hhsrs-hmo",
    "title": "UK Housing Act 2004 - HHSRS Standards and HMO Licensing",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Housing Act 2004 introduces the Housing Health and Safety Rating System (HHSRS) as the statutory standard for assessing health and safety hazards in residential properties in England and Wales. Local housing authorities must take enforcement action against Category 1 hazards and may act on Category 2 hazards. The Act also establishes mandatory licensing for Houses in Multiple Occupation (HMOs) of 3 or more storeys with 5 or more occupants from 2 or more households, and introduced tenancy deposit protection schemes for assured shorthold tenancies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "building_regulations_2010",
        "renters_rights",
        "landlord_tenant_act_1985",
        "uk_building_safety_act_2022",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-building-safety-act-2022",
      "uk-cdm-regulations-2015-construction",
      "uk-planning-permission-tcpa-1990"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-housing-grants-construction-and-regeneration-act-1996",
    "title": "UK Housing Grants, Construction and Regeneration Act 1996 (Part II): Construction Contract Adjudication and Payment",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Part II of the Housing Grants, Construction and Regeneration Act 1996 (commonly the Construction Act) governs construction contracts in the United Kingdom, giving parties a statutory right to adjudication and a statutory payment framework that cannot be contracted out of, as amended by the Local Democracy, Economic Development and Construction Act 2009. Section 104 defines a construction contract and section 105 defines construction operations, while section 106 excludes a contract with a residential occupier and section 106A confers a power to disapply provisions of the Part. Section 108 confers the right to refer a dispute under a construction contract to adjudication at any time, with a decision normally within 28 days. The payment regime is mandatory: section 109 confers an entitlement to stage (interim) payments, section 110 requires an adequate mechanism for determining what and when payments become due, sections 110A and 110B require payment notices, section 111 requires payment of the notified sum unless a valid pay less notice is given, section 112 confers a right to suspend performance for non-payment, and section 113 prohibits conditional payment (pay-when-paid) provisions except on the third party's insolvency. Section 114 provides for the Scheme for Construction Contracts, which supplies the default terms where a contract does not comply. The Act is the legal foundation of construction-industry cash flow and rapid dispute resolution in the UK.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-human-medicines-regulations-2012",
    "title": "UK Human Medicines Regulations 2012",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2023-01-01",
    "bluf": "The Human Medicines Regulations 2012 (SI 2012/1916) is the primary UK pharmaceutical legislation governing the authorisation, manufacture, importation, distribution, and advertising of human medicines, with the MHRA as the competent authority, requiring a UK marketing authorisation (MA) before placing medicinal products on Great Britain market, and enforcing GMP compliance through qualified person batch certification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu-medicinal-products-human-directive-2001-83",
        "uk-data-protection-act-2018",
        "eu-in-vitro-diagnostics-regulation-2017-746"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-medicinal-products-human-directive-2001-83",
      "uk-data-protection-act-2018",
      "eu-in-vitro-diagnostics-regulation-2017-746"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-human-medicines-regulations-2012-si-1916",
    "title": "The Human Medicines Regulations 2012",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The UK Human Medicines Regulations 2012 (SI 2012/1916) require marketing authorisation holders to comply with pharmacovigilance requirements, as outlined in Regulation 187. This regulation applies to all marketing authorisation holders in the UK.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-qms",
      "ich-gcp-e6-r3-2023"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-human-rights-act-1998",
    "title": "UK Human Rights Act 1998 - Domestic Incorporation of ECHR Rights",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Human Rights Act 1998 (1998 chapter 42, Royal Assent 9 November 1998, principal commencement 2 October 2000) gives further effect in United Kingdom domestic law to the rights and freedoms guaranteed under the European Convention on Human Rights. Section 1 and Schedule 1 set out the Convention rights protected under the Act including Article 2 (right to life), Article 3 (prohibition of torture), Article 5 (right to liberty and security), Article 6 (right to a fair trial), Article 8 (right to respect for private and family life), Article 10 (freedom of expression), Article 14 (prohibition of discrimination), and Article 1 of the First Protocol (protection of property). Section 3 requires courts to read and give effect to primary and subordinate legislation in a way that is compatible with the Convention rights so far as it is possible to do so. Section 4 allows higher courts to make a declaration of incompatibility where legislation cannot be so read, without invalidating the legislation. Section 6 makes it unlawful for any public authority to act in a way incompatible with a Convention right, with section 7 providing the cause of action for victims and section 8 authorising any relief or remedy within the court's powers. Sections 10 and Schedule 2 establish the remedial-order mechanism. The Human Rights Act is the constitutional cornerstone of UK public-law accountability and is increasingly tested where public-authority decisions are produced by or with material assistance from AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-data-protection-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-human-tissue-act-2004",
    "title": "Human Tissue Act 2004 - Consent Requirements, Licensed Activities for Human Biological Material and Human Tissue Authority (HTA) Oversight",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Human Tissue Act 2004 establishes a legal framework for the removal, storage, and use of human tissue in England, Wales, and Northern Ireland, requiring appropriate consent for scheduled purposes under Section 1 and mandating licensing by the Human Tissue Authority (HTA) for specified activities under Section 16. It applies to all organisations and individuals handling human tissue for purposes such as transplantation, research, and anatomical examination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "uk-retained-gdpr",
      "ich-gcp-e6-r3-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-human-tissue-act-2004-biobanks",
    "title": "Human Tissue Act 2004",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Human Tissue Act 2004 requires that any removal, storage or use of human tissue for scheduled purposes-including biobanking-must be performed only with appropriate consent (Section 3 for adults, Section 2 for children) and under a licence issued by the Human Tissue Authority (Section 16).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "isber-best-practices-biorepositories-2018",
      "oecd-guidelines-human-biobanks-2009",
      "canada-assisted-human-reproduction-act-2004"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-hunting-act-2004",
    "title": "UK Hunting Act 2004 (c.37): Prohibition of Hunting Wild Mammals with Dogs and Hare Coursing",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Hunting Act 2004 (c. 37) prohibits the hunting of wild mammals with dogs and the practice of hare coursing in England and Wales, subject to defined exemptions, and is enforced through the magistrates' courts. Section 1 makes it an offence for a person to hunt a wild mammal with a dog unless the hunting is exempt. Section 2 provides that hunting is exempt if it is within a class of exempt hunting described in Schedule 1, which sets out tightly defined categories such as stalking and flushing out, the use of dogs below ground to protect birds for shooting, hunting of rats and rabbits, retrieval of hares, falconry, recapture of an escaped wild mammal, rescue of an injured wild mammal, and research and observation. Section 3 makes it an offence to knowingly permit land or a dog to be used in unlawful hunting. Section 5 prohibits hare coursing, making it an offence to participate in, attend, or facilitate a hare coursing event. Section 6 sets the penalty for offences, which on summary conviction is a fine. Section 8 confers powers of search and seizure on a constable, and section 9 provides for the forfeiture of dogs, hunting articles, and vehicles on conviction. Section 11 provides the interpretation, including the meaning of hunting and wild mammal. The Act is the foundational prohibition on hunting wild mammals with dogs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-ico-ai-data-protection-guidance-2023",
    "title": "UK ICO Guidance on AI and Data Protection (2023, updated 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The UK Information Commissioner's Office issued Guidance on AI and Data Protection in 2023 (substantially updated in 2024) under the UK GDPR and the Data Protection Act 2018. The Guidance covers how data protection law applies to the design, development, and deployment of AI systems that process personal data. Core requirements include: (1) Accountability and governance - organisational measures including Data Protection Impact Assessments, AI risk management, designated responsibilities, and documentation; (2) Lawfulness, fairness, and transparency - identifying a valid lawful basis, ensuring outputs are not unfair or discriminatory, providing meaningful information to data subjects about AI processing including under Article 13/14 transparency obligations and Article 22 automated decision-making rights; (3) Purpose limitation and data minimisation - using personal data only for stated purposes and minimising data used in training and inference; (4) Accuracy - ensuring AI outputs that affect individuals are sufficiently accurate, including treatment of model outputs as personal data when they relate to identified or identifiable individuals; (5) Security - applying appropriate technical and organisational measures including against AI-specific threats; (6) Individual rights - facilitating access, rectification, erasure, restriction, objection, and the Article 22 right to human review of solely automated decisions producing legal or similarly significant effects. The Guidance is companion to the ICO Explaining decisions made with AI guidance (jointly with the Alan Turing Institute, 2020) and is the principal UK data protection enforcement reference for AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_overlay",
        "international_alignment",
        "ai_governance_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-data-protection-act-2018",
      "uk-ai-safety-institute-framework-2024"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-ico-employment-practices-ai-decision-making-guidance",
    "title": "UK ICO Employment Practices - AI Decision-Making and Data Protection in the Workplace",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The UK Information Commissioner's Office (ICO) Employment Practices Guidance and the Data Protection Act 2018 regulate AI and automated decision-making in UK employment contexts. Employers using AI for recruitment, performance management, or disciplinary decisions must provide transparency, conduct DPIAs for high-risk processing, and avoid solely automated decisions with significant legal effects unless an exemption applies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-data-protection-act-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-illegal-migration-act-2023",
    "title": "UK Illegal Migration Act 2023: The Duty to Remove, Disregard of Claims, Detention and Modern-Slavery Provisions",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Illegal Migration Act 2023 introduced a duty on the Secretary of State to remove persons who enter the United Kingdom unlawfully and restricted the claims and protections available to them, administered by the Home Office. Section 2 imposes the central duty to make arrangements for the removal of a person who meets the four conditions, namely that the person entered or arrived in breach of immigration control on or after the relevant date, did not come directly from a country in which their life and liberty were threatened, requires leave to enter or remain that they do not have, and is not an exempt person. Section 4 deals with unaccompanied children and the power to provide for exceptions, and sections 16 and 17 govern their accommodation and the transfer of responsibility between the Secretary of State and local authorities. Section 5 provides for the disregard of certain claims, applications and appeals (including human-rights and protection claims) for the purposes of the removal duty, channelling such claims so that they do not prevent removal. Detention is dealt with by section 11 (powers of detention), section 12 (the period for which persons may be detained) and section 13 (powers to grant immigration bail). The modern-slavery provisions in sections 22 and 23 limit the removal protections and support that would otherwise flow from a positive reasonable-grounds decision, and section 26 provides for the suspension and revival of those provisions. Schedule 1 lists the countries and territories to which a person may be removed. The Act is the most restrictive recent reshaping of the United Kingdom asylum and removal framework, conditioning removal on objective entry criteria and disapplying claims that would otherwise suspend it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-illegal-migration-act-2023-removal-duty",
    "title": "UK Illegal Migration Act 2023 - Removal Duty and Inadmissibility of Asylum Claims",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Illegal Migration Act 2023 (UK) places a duty on the Secretary of State to make arrangements for the removal from the United Kingdom of persons who meet the four conditions in section 2: arrival on or after 7 March 2023, entry in breach of immigration law, having travelled through a safe third country, and being subject to immigration control. Section 4 provides power to make exceptions for unaccompanied children. Section 5 provides for the disregard of certain claims, applications, and other matters made by the person to whom the removal duty applies. Section 6 sets out the framework for removal pursuant to section 2 or 4. Sections 11 to 13 provide for detention powers, the period for which persons may be detained, and immigration bail. Section 16 establishes the duty on local authorities and Secretary of State to accommodate and support unaccompanied migrant children, with sections 17 to 21 providing transfer and information-sharing duties. Section 29 contains the disapplication of modern slavery provisions amending section 63 of the Nationality and Borders Act 2022. Sections 38 to 53 cover the suspensive claims regime, including serious harm suspensive claims under section 42. Section 59 inserts inadmissibility provisions for asylum and human rights claims from nationals of listed safe States into the Nationality, Immigration and Asylum Act 2002. The Act was substantially amended and partially repealed by the Border Security Asylum and Immigration Act 2025 with the removal duty provisions retained but recalibrated.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-immigration-act-1971-ukvi-home-office",
      "uk-modern-slavery-act-2015-section-54-supply-chain-transparency",
      "uk-equality-act-2010-protected-characteristics"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-immigration-act-1971",
    "title": "UK Immigration Act 1971: Leave to Enter and Remain, Deportation and Immigration Offences",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Immigration Act 1971 is the foundational statute of United Kingdom immigration control, administered by the Secretary of State for the Home Department (the Home Office). It establishes that a person who is not a British citizen requires leave to enter or remain in the United Kingdom unless they have the right of abode. Section 1 sets the general principles and section 2 defines the right of abode. Section 3 is the operative control provision: section 3(1) provides that a person who is not a British citizen shall not enter the United Kingdom unless given leave, that leave may be given for a limited or indefinite period, and that limited leave may be granted subject to conditions (restricting employment or study, requiring maintenance without recourse to public funds, requiring registration with the police, imposing reporting, residence or electronic monitoring conditions); section 3(2) requires the Secretary of State to lay before Parliament statements of the immigration rules; section 3(3) governs variation of leave; and sections 3(5) and 3(6) set out liability to deportation where the Secretary of State deems it conducive to the public good, where a family member is deported, or on the recommendation of a court following conviction of an imprisonable offence. Section 5 sets the procedure and effect of deportation orders. Part III creates the immigration offences. Section 24 (illegal entry and similar offences) makes it an offence, among other things, to knowingly fail to observe a condition of limited leave or to overstay, punishable on summary conviction by a fine of up to level 5 on the standard scale or imprisonment for up to six months, with later subsections (inserted by the Nationality and Borders Act 2022) carrying higher penalties on indictment. Section 25 (assisting unlawful immigration) makes it an offence to facilitate a breach of immigration law by a person known or believed not to be a British citizen, punishable on indictment by imprisonment for life. The Act is the primary instrument against which any UK entry, stay, sponsorship or removal decision must be mapped.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-immigration-act-1971-section-3-general-provisions-regulation-control",
    "title": "UK Immigration Act 1971 Section 3 - General Provisions for Regulation and Control",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person who is not a British citizen must not enter the United Kingdom without leave granted under or made under the Immigration Act 1971. Leave to enter or remain may be granted for a limited or an indefinite period and may be subject to conditions including restrictions on work, occupation, studies, requirement to maintain without recourse to public funds, registration with police, reporting to immigration officer or Secretary of State, residence, electronic monitoring, presence-at-place, geographic restriction, exclusion zones, and any other conditions the Secretary of State thinks fit. The Secretary of State makes Immigration Rules under Section 3(2) which Parliament may negate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "leave_requirement_for_non_british_citizens_subsection_1_a",
        "limited_or_indefinite_leave_subsection_1_b",
        "ten_conditions_attachable_to_limited_leave_subsection_1_c",
        "subsection_1a_1b_threshold_for_certain_conditions",
        "secretary_of_state_immigration_rules_power_subsection_2",
        "variation_and_continuation_of_leave_subsection_3",
        "lapse_and_return_provisions_subsection_4",
        "deportation_liability_under_subsection_5_and_6",
        "burden_of_proof_subsection_8"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-british-nationality-act-1981-section-1-acquisition-by-birth-adoption",
      "uk-nationality-and-borders-act-2022-section-40-illegal-entry-offences"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-immigration-act-1971-ukvi-home-office",
    "title": "UK Immigration Act 1971 - Leave to Enter, Deportation and Removal Framework",
    "domain": "Immigration & Border Control",
    "version": "3.2",
    "last_updated": "2026-05-10",
    "bluf": "The Immigration Act 1971 (as substantially amended by the Nationality and Borders Act 2022 and Illegal Migration Act 2023) is the primary UK statute governing leave to enter and remain in the United Kingdom. It establishes the legal basis for the Points-Based Immigration System, sets criminal penalties of up to 14 years imprisonment for facilitation of unlawful immigration, mandates deportation for foreign nationals convicted of offences carrying 12 months imprisonment or more, and creates the duty framework underpinning the UK Border Force and UK Visas and Immigration. Non-compliance triggers automatic visa curtailment, civil penalty notices of up to GBP 20,000 per illegal worker under s.15 Immigration, Asylum and Nationality Act 2006, and criminal liability under s.24 and s.25 of the 1971 Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_article",
        "eu_ai_act_article",
        "fatf_recommendation",
        "icao_doc",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric",
      "eu-entry-exit-system-regulation-2017-2226"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-immigration-act-2014",
    "title": "UK Immigration Act 2014: Removal Powers, Appeal Reform and the Hostile-Environment Controls (Right to Rent, Bank Accounts, Driving Licences)",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Immigration Act 2014 restructured United Kingdom removal and appeal powers and introduced the so-called hostile-environment controls that require private actors to check immigration status, administered by the Home Office. Part 1 deals with removal and enforcement: section 1 provides for the removal of persons unlawfully in the United Kingdom, section 2 restricts the removal of children and their parents, section 4 confers enforcement powers and section 5 restricts the detention of unaccompanied children. Part 2 reforms appeals: section 15 sets out the right of appeal to the First-tier Tribunal (narrowed to human-rights and protection claims), section 17 governs the place from which an appeal may be brought or continued, and section 19 requires courts and tribunals to have regard to the public interest considerations in Article 8 ECHR cases. Part 3 creates the access-to-services controls: in Chapter 1 on residential tenancies, section 21 defines persons disqualified by immigration status from renting (the right to rent), section 22 prohibits leasing premises to a disqualified person, and section 23 provides for landlord penalty notices; section 38 establishes the immigration health charge; in Chapter 2, section 40 prohibits banks from opening current accounts for disqualified persons; and on driving licences, section 46 imposes a residence requirement for the grant of a licence and section 47 provides for revocation on grounds of immigration status. The Act is the framework that pushed immigration-status checking into housing, banking, healthcare and driving, and narrowed the immigration appeal right.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-immigration-act-2016",
    "title": "UK Immigration Act 2016: Labour Market Enforcement, Illegal Working Offences and the Extended Hostile-Environment Controls",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Immigration Act 2016 extended United Kingdom labour-market and illegal-working enforcement and widened the hostile-environment controls introduced by the Immigration Act 2014, administered by the Home Office and the Director of Labour Market Enforcement. Part 1 deals with the labour market and illegal working: section 1 establishes the Director of Labour Market Enforcement, section 2 requires the Director to prepare a labour market enforcement strategy, section 34 creates the offence of illegal working by an individual, section 35 creates the offence of employing an illegal worker, and section 38 provides for illegal working closure notices and illegal working compliance orders. Part 2 extends access-to-services controls: section 39 creates the offence of leasing premises to a disqualified person and section 40 provides for eviction of such persons, section 44 creates the offence of driving when unlawfully in the United Kingdom, and section 45 extends the bank-account measures. Part 3 strengthens enforcement powers, Part 4 amends appeal rights, Part 5 governs support for certain categories of migrant, Part 6 concerns border security, Part 7 imposes language requirements for public sector workers, and Part 8 deals with fees and charges, including section 85 which provides for the immigration skills charge on sponsors of skilled workers. Section 61 governs immigration bail, consolidating the previous bail and temporary admission regimes. The Act is the instrument that created the Director of Labour Market Enforcement, criminalised illegal working by the worker, and pushed status-checking further into employment, housing, banking and driving.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-immigration-asylum-and-nationality-act-2006",
    "title": "UK Immigration, Asylum and Nationality Act 2006: Employer Civil Penalties and Offences, Passenger Information and Deprivation of Citizenship",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Immigration, Asylum and Nationality Act 2006 reformed United Kingdom employer compliance, appeals, information-sharing and citizenship-deprivation powers, administered by the Home Office. The employment provisions are central: section 15 establishes the civil penalty for employing an adult who is subject to immigration control and has no right to do the work in question, section 21 creates the criminal offence of knowingly employing such a person, and section 22 extends that offence to bodies corporate and their officers. The appeals provisions narrow and structure immigration appeals: section 1 deals with variation of leave to enter or remain, section 2 with removal, section 3 with the grounds of appeal, and section 13 with the certification of an unfounded claim where the appeal must be brought from outside the United Kingdom. Sections 32 and 32A confer information powers: section 32 gives the police powers in relation to passenger and crew information and section 32A enables regulations requiring such information to be provided to the police. The refugee provisions include section 54, which governs the construction of Article 1F of the Refugee Convention (exclusion for serious crimes, including acts contrary to the purposes of the United Nations), and section 55, which provides for certification that the Convention does not apply. Section 56 confers the power to deprive a person of citizenship where the Secretary of State is satisfied that deprivation is conducive to the public good. The Act is the instrument that created the modern employer civil-penalty regime for illegal working and consolidated the powers to exchange passenger data and to strip citizenship on public-good grounds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-indecent-displays-control-act-1981",
    "title": "UK Indecent Displays (Control) Act 1981 (c. 42) - Public Indecent Display Offence",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "The UK Indecent Displays (Control) Act 1981 (c. 42) makes it an offence to publicly display indecent matter: Section 1(1) provides 'If any indecent matter is publicly displayed the person making the display and any person causing or permitting the display to be made shall be guilty of an offence'; matter displayed in or visible from any public place is 'publicly displayed' subject to two exceptions in Section 1(3): paid-access venues where payment is required specifically for that display, and shop areas accessible only past an adequate warning notice (Section 1(6)) - but both exceptions apply only where persons under 18 are excluded; Section 1(4) excludes television broadcasts, art gallery/museum displays visible only within those spaces, Crown or local authority building displays visible only within those buildings, theatre performances, and licensed film exhibitions; Section 1(6) prescribes the exact warning notice text: 'WARNING - Persons passing beyond this notice will find material on display which they may consider indecent. No admittance to persons under 18 years of age.' - with WARNING as heading, no pictures, and positioned so unavoidable; the Act does not apply to actual human bodies; penalties under Section 4 include fines on summary conviction and unlimited fine or imprisonment up to 2 years on indictment; jurisdiction covers England, Wales, and Scotland.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_uk_content_statutes",
        "carve_outs_section_1_4",
        "industry_mapping",
        "enforcement_anchors",
        "warning_notice_prescribed_form_section_1_6",
        "section_3_definitions_indecent_matter"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-obscene-publications-act-1959",
      "uk-online-safety-act-2023-part-5-pornographic-content-duties",
      "uk-si-2020-1062-vsp-regime-communications-act"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-infrastructure-act-2015-roads-investment",
    "title": "Infrastructure Act 2015 - Road Investment Strategy: Strategic Road Network, Highways England Licence, User Scheme and Cycling Requirements",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Infrastructure Act 2015 requires the Secretary of State to direct Highways England to prepare and implement a Road Investment Strategy (RIS) for the strategic road network in England, covering performance, expenditure, and outcomes over a five-year period, with specific requirements for cycling infrastructure and user engagement under Section 1. This applies to Highways England and the Department for Transport.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-insolvency-act-1986",
    "title": "UK Insolvency Act 1986",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The UK Insolvency Act 1986 (as amended by the Insolvency Act 2000, Enterprise Act 2002, Corporate Insolvency and Governance Act 2020) is the principal legislation governing corporate and personal insolvency in England Wales and Scotland (Northern Ireland has equivalent provisions in the Insolvency (Northern Ireland) Order 1989). The Act covers company voluntary arrangements (CVAs), administration, receivership, winding up (compulsory and voluntary liquidation), individual voluntary arrangements (IVAs), bankruptcy of individuals, and avoidance of antecedent transactions (preferences transactions at undervalue and extortionate credit transactions). The Corporate Insolvency and Governance Act 2020 introduced new restructuring tools including the standalone moratorium and the restructuring plan in Part 26A Companies Act 2006.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "companies_act_2006",
        "insolvency_rules",
        "cdda",
        "eu_insolvency",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-insolvency-act-1986-section-213-fraudulent-trading",
    "title": "UK Insolvency Act 1986 Section 213 — Fraudulent Trading (Civil Liability)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "If in the course of the winding-up of a company it appears that any business of the company has been carried on with intent to defraud creditors of the company or of any other person, or for any fraudulent purpose, the court may, on the application of the liquidator, declare that any persons who were knowingly parties to the carrying on of the business in that manner are liable to make such contributions to the company's assets as the court thinks proper. Section 213 imposes civil liability and runs alongside the criminal offence of fraudulent trading in Companies Act 2006 Section 993.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "trigger_winding_up_in_progress",
        "business_carried_on_with_intent_to_defraud",
        "knowing_party_test_for_personal_liability",
        "application_by_liquidator_only",
        "remedy_contribution_to_companys_assets",
        "criminal_counterpart_companies_act_2006_section_993",
        "interaction_with_section_214_wrongful_trading"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-insolvency-act-1986-section-214-wrongful-trading-director-liability"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-insolvency-act-1986-section-214-wrongful-trading-director-liability",
    "title": "UK Insolvency Act 1986 Section 214 - Wrongful Trading (Director Personal Liability for Insufficient Steps to Minimise Creditor Loss, Reasonably Diligent Person Test, Shadow Director Inclusion)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 214 of the Insolvency Act 1986 (c. 45) creates the foundational UK wrongful trading provision - the principal civil mechanism for directors' personal liability where they continue trading beyond the point of no reasonable prospect of avoiding insolvent liquidation or administration. Under section 214(1), if in the course of winding up a company it appears that subsection (2) applies in relation to a person who is or has been a director, the court, on application of the liquidator, may declare that the person is to be liable to make such contribution to the company's assets as the court thinks proper. Under section 214(2), the subsection applies if (a) the company has gone into insolvent liquidation, (b) at some time before the commencement of winding up, the person knew or ought to have concluded that there was no reasonable prospect of avoiding insolvent liquidation or entering insolvent administration, and (c) the person was a director at that time (effective from 28 April 1986). Under section 214(3), the court shall not make a declaration if satisfied that after the condition specified was first satisfied, the person took every step to minimise potential loss to creditors as he ought to have taken assuming knowledge of the matter. Under section 214(4), the reasonably diligent person test combines (a) general knowledge, skill and experience reasonably expected of a person in that director role and (b) actual knowledge, skill and experience of the director - the dual subjective/objective standard. Section 214(5) covers entrusted functions. Section 214(6) defines insolvent liquidation; section 214(6A) defines insolvent administration. Section 214(7) includes shadow directors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_214_text",
        "no_reasonable_prospect_test_section_214_2_b",
        "every_step_to_minimise_creditor_loss_section_214_3_safe_harbour",
        "reasonably_diligent_person_test_section_214_4_dual_standard",
        "shadow_director_inclusion_section_214_7",
        "remedy_contribution_to_assets_court_discretion",
        "covid_19_temporary_suspension_corporate_insolvency_and_governance_act_2020",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-companies-act-2006-directors-duties-sections-170-177"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-insolvency-act-1986-section-238-transactions-at-undervalue",
    "title": "UK Insolvency Act 1986 - Section 238 Transactions at an Undervalue (England and Wales)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "Section 238 of the Insolvency Act 1986 (UK) is the England and Wales antecedent-transaction provision allowing an office-holder to challenge transactions at an undervalue entered into by the company before the onset of insolvency. Subsection (1) provides that this section applies where a company has entered administration or has gone into liquidation, in which case the office-holder (the administrator or the liquidator) may apply to the court. Subsection (2) provides that, where the company has at a relevant time (as defined in section 240) entered into a transaction with any person at an undervalue, the court shall, on the office-holder's application, make such order as it thinks fit for restoring the position to what it would have been if the company had not entered into the transaction. Subsection (4) provides that a company enters into a transaction with a person at an undervalue if (a) the company makes a gift to that person or otherwise enters into a transaction with that person on terms that provide for the company to receive no consideration, or (b) the company enters into a transaction with that person for a consideration the value of which, in money or money's worth, is significantly less than the value, in money or money's worth, of the consideration provided by the company. Subsection (5) provides the good-faith carve-out: the court shall not make an order under this section in respect of a transaction at an undervalue if it is satisfied (a) that the company which entered into the transaction did so in good faith and for the purpose of carrying on its business, and (b) that at the time it did so there were reasonable grounds for believing that the transaction would benefit the company. Both conditions must be met to engage the carve-out.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-insolvency-act-1986"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-insolvency-act-1986-section-239-preferences",
    "title": "UK Insolvency Act 1986 - Section 239 Preferences (England and Wales)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "Section 239 of the Insolvency Act 1986 (UK) is the England and Wales antecedent-transaction provision allowing an office-holder to challenge preferences given by the company before the onset of insolvency. Subsection (1) provides that this section applies where a company has entered administration or has gone into liquidation, in which case the office-holder (the administrator or the liquidator) may apply to the court. Subsection (2) provides that, where the company has at a relevant time (as defined in section 240) given a preference to any person, the court shall, on the office-holder's application, make such order as it thinks fit for restoring the position to what it would have been if the company had not given that preference. Subsection (4) provides that a company gives a preference to a person if (a) that person is one of the company's creditors or a surety or guarantor for any of the company's debts or other liabilities, and (b) the company does anything or suffers anything to be done which (in either case) has the effect of putting that person into a position which, in the event of the company going into insolvent liquidation, will be better than the position he would have been in if that thing had not been done. Subsection (5) provides the influence requirement: the court shall not make an order under this section in respect of a preference given to any person unless the company which gave the preference was influenced in deciding to give it by a desire to produce in relation to that person the effect mentioned in subsection (4)(b). Subsection (6) provides the connected-person presumption: a company which has given a preference to a person connected with the company (otherwise than by reason only of being its employee) at the time the preference was given is presumed, unless the contrary is shown, to have been influenced in deciding to give it by the desire mentioned in subsection (5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-insolvency-act-1986"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-insolvency-act-1986-section-423-transactions-defrauding-creditors",
    "title": "UK Insolvency Act 1986 - Section 423 Transactions Defrauding Creditors",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "Section 423 of the Insolvency Act 1986 (UK) is the transactions-defrauding-creditors provision that allows a victim of a transaction at an undervalue to apply to the court for an order to restore the position and protect the victim's interests, regardless of whether the company or individual has entered formal insolvency. Subsection (1) defines a transaction at an undervalue for these purposes as a transaction where a person (a) makes a gift to the other party or otherwise enters into a transaction on terms that provide for him to receive no consideration, (b) enters into a transaction in consideration of marriage or formation of a civil partnership, or (c) enters into a transaction for a consideration the value of which, in money or money's worth, is significantly less than the value of the consideration provided by the person. Subsection (2) provides that where a person has entered into such a transaction, the court may, if satisfied under subsection (3), make such order as it thinks fit for (a) restoring the position to what it would have been if the transaction had not been entered into, and (b) protecting the interests of persons who are victims of the transaction. Subsection (3) provides the purpose requirement: the court shall not make an order under this section unless it is satisfied that the transaction was entered into by the person for the purpose (a) of putting assets beyond the reach of a person who is making, or may at some time make, a claim against him, or (b) of otherwise prejudicing the interests of such a person in relation to the claim which he is making or may make. Subsection (4) provides jurisdictional rules: the court for these purposes is the High Court (or, in certain corporate cases, the court that has bankruptcy or winding-up jurisdiction). Unlike sections 238 and 239, section 423 is not limited to insolvency proceedings and applies whether or not the transferor is insolvent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-insolvency-act-1986"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-insurance-act-2015",
    "title": "UK Insurance Act 2015",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The UK Insurance Act 2015 modernises UK commercial insurance contract law, replacing key provisions of the Marine Insurance Act 1906 in the non-consumer context. The Act introduces the duty of fair presentation by the insured at placement (Part 2), abolishes the basis-of-contract clause (Section 9), provides proportionate remedies for misrepresentation and breach of warranty (Sections 8-11), and provides for damages for late payment of valid claims (Section 13A, added by Enterprise Act 2016). The Act applies to consumer insurance only where it modifies CIDRA 2012. Material to non-life and large risk commercial insurance practice.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "mia_1906",
        "cidra_2012",
        "enterprise_2016",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-insurance-act-2015-fair-presentation",
    "title": "Insurance Act 2015: The Insured's Duty of Fair Presentation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK Insurance Act 2015 requires non-consumer insureds to make a 'fair presentation of the risk' to insurers before a contract is entered into, as defined in Section 3. This involves disclosing every material circumstance known or that ought to be known by the insured's senior management and those responsible for its insurance, or providing sufficient information to put a prudent insurer on notice to make further enquiries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fca-consumer-duty-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-intellectual-property-act-2014-design-rights-registered-unregistered",
    "title": "UK Intellectual Property Act 2014 - Design Rights, Registered Designs, and Unregistered Design Rights",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "The UK Intellectual Property Act 2014 amended the Registered Designs Act 1949 and the Copyright, Designs and Patents Act 1988 (CDPA) to strengthen UK design protection. The UK provides three forms of design right: Registered Design (RD) lasting up to 25 years through UKIPO registration, Unregistered Design Right (UDR) lasting up to 15 years protecting the internal or external shape and configuration of articles, and UK Unregistered Community Design (UK UCD) protecting the appearance of a product for 3 years. Post-Brexit, UK UCD no longer benefits from EU protection for new designs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-hague-design-system"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-international-ai-safety-report-2025",
    "title": "International AI Safety Report 2025 (Chaired by Yoshua Bengio, January 29 2025)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The International AI Safety Report 2025 was published on January 29, 2025 ahead of the AI Action Summit in Paris (February 10-11, 2025). The Report was commissioned at the Bletchley AI Safety Summit (November 2023) and prepared by an independent expert panel chaired by Professor Yoshua Bengio, supported by an international expert panel comprising 96 AI experts and an Advisory Panel of 30 countries plus EU and UN representatives. The Report is published under the auspices of the UK Department for Science, Innovation and Technology (DSIT) as the host of the AI Safety Institute (AISI). It is the successor to the Interim International Scientific Report on the Safety of Advanced AI (May 2024). The Report is structured in three substantive sections: (1) Capabilities of general-purpose AI - present and projected; (2) Risks from general-purpose AI - malicious use risks, malfunction risks, systemic risks; (3) Technical mitigations - training-time and inference-time mitigations, evaluation methods, accountability mechanisms. The Report explicitly avoids policy recommendations and is intended as a scientific consensus reference for policymakers. It identifies key risk categories including biorisks, cyber misuse, disinformation and influence operations, bias and discrimination, privacy harms, labour market impacts, environmental impacts, and loss of control of advanced AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "nist_framework",
        "international_alignment",
        "ai_lab_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-2023-frontier-ai-safety",
      "uk-ai-safety-institute-framework-2024",
      "council-of-europe-ai-treaty-2024",
      "nist-ai-100-2-adversarial-ml-taxonomy-2024"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-investigatory-powers-act-2016-section-253-technical-capability-notices",
    "title": "UK Investigatory Powers Act 2016 Section 253 - Technical Capability Notices (Secretary of State Power, Judicial Commissioner Approval, Relevant Operator Definition, Applicable Obligations Including Removal of Electronic Protection, Technical Advisory Board Consultation, Extraterritorial Effect)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 253 of the Investigatory Powers Act 2016 (c. 25) authorises the Secretary of State to issue technical capability notices (TCNs) requiring relevant operators (postal operators, telecommunications operators, and prospective operators) to maintain technical capabilities for providing assistance with relevant authorisations (warrants under Parts 2, 5, 6 and authorisations under Part 3). Under section 253(1), the Secretary of State may give a TCN if necessary for securing the operator's capability to provide required assistance, the conduct is proportionate to objectives, and a Judicial Commissioner approves the decision (double-lock authorisation per section 254). Under section 253(2), a TCN imposes 'applicable obligations' and requires specified steps for compliance. Under section 253(3), key terms are defined: 'applicable obligation' (the kind of obligation imposed); 'relevant authorisation' (warrants under Parts 2, 5, 6 or authorisations under Part 3); 'relevant operator' (postal operators, telecommunications operators, or prospective operators). Under section 253(4), regulations specifying obligations must be limited to what is reasonable for securing requirement imposition and compliance. Under section 253(5), obligations may include: facilities/services provision; apparatus-related matters; removal of electronic protection; security of postal/telecommunications services; and information handling/disclosure. Under section 253(6), the Secretary of State must consult the Technical Advisory Board (TAB), likely obligation subjects, their representatives, and relevant statutory bodies before making regulations. Under section 253(7), TCNs must specify reasonable compliance periods. Under section 253(8), TCNs may apply to persons outside the United Kingdom with extraterritorial effect - the cross-border reach is the focus of intense industry attention from non-UK communications providers serving UK users. Section 253(9) references sections 254-258 for the broader TCN regime including review, variation, revocation, and judicial commissioner oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_253_text_subsections",
        "double_lock_authorisation_section_254",
        "relevant_operator_definition_section_253_3",
        "applicable_obligations_section_253_5",
        "extraterritorial_effect_section_253_8",
        "technical_advisory_board_section_253_6_consultation",
        "investigatory_powers_technical_capability_regulations_2018",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-investigatory-powers-act-2016-telecoms",
      "uk-investigatory-powers-act-2016-section-3-unlawful-interception-offence"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-investigatory-powers-act-2016-section-3-unlawful-interception-offence",
    "title": "UK Investigatory Powers Act 2016 Section 3 - Offence of Unlawful Interception (Public/Private Telecom System or Postal Service, UK Conduct Element, Absence of Lawful Authority, Operator Consent Exception, 2 Years Indictment, DPP Consent)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 3 of the Investigatory Powers Act 2016 (c. 25) creates the criminal offence of unlawful interception of communications. Under section 3(1), a person commits an offence if (a) the person intentionally intercepts any communication in the course of its transmission by means of a public telecommunication system, a private telecommunication system, or a public postal service; (b) the interception is carried out in the United Kingdom; and (c) the person does not have lawful authority to carry out the interception. Under section 3(2), the offence does not apply to interception of a private telecommunication system if the interceptor is a person with a right to control the operation or use of the system, or has the express or implied consent of such a person. Under section 3(3), sections 4 and 5 define 'interception' and specify when interception is to be regarded as carried out in the United Kingdom. Under section 3(4), section 6 sets out when a person has lawful authority to carry out an interception (including interception under a targeted interception warrant under Part 2 Chapter 1, a bulk interception warrant under Part 6 Chapter 1, or a mutual assistance warrant under Part 2 Chapter 3). Under section 3(5), terms in subsection (1)(a)(i) to (iii) are defined in sections 261 and 262. Under section 3(6), the penalty on summary conviction is a fine (and in England and Wales, imprisonment up to the maximum term for summary offences after the small fines reform); on conviction on indictment, imprisonment for a term not exceeding 2 years or a fine, or both. Under section 3(7), no proceedings may be instituted in England and Wales except by or with the consent of the Director of Public Prosecutions; in Northern Ireland, the Director of Public Prosecutions for Northern Ireland. Section 3 is the UK's primary anti-interception criminal provision and the legal hook against unauthorised wiretapping, packet capture, and email interception. The lawful authority routes are tightly defined by Parts 2-6 of the Act and the section 261/262 definitions; absent compliance with those routes, interception is criminal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_3_text_subsections",
        "lawful_authority_routes_section_6",
        "interception_definition_section_4_5",
        "private_telecom_system_exception_section_3_2",
        "uk_conduct_element_section_3_1_b",
        "complementary_computer_misuse_act_1990_offence",
        "dpp_consent_section_3_7",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-computer-misuse-act-1990-sections-1-3",
      "uk-investigatory-powers-act-2016-telecoms",
      "uk-data-protection-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-investigatory-powers-act-2016-telecoms",
    "title": "Investigatory Powers Act 2016: Bulk Interception Warrants, Communications Data Retention and Equipment Interference Obligations",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK Investigatory Powers Act 2016 legally obligates telecommunications and postal operators to retain specific communications data for up to 12 months upon notice (Part 4, Section 87) and to provide covert access to communications and equipment for law enforcement and intelligence agencies when served with a lawful warrant (Parts 2, 5, and 6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-46-transfer-mechanisms"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-iran-sanctions-human-rights-eu-exit-regulations-2019-si-134",
    "title": "UK Iran (Sanctions) (Human Rights) (EU Exit) Regulations 2019 SI 2019/134 - Asset Freeze Trade Restrictions and Surveillance Equipment Controls Targeting Iranian Human Rights Violations",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Iran (Sanctions) (Human Rights) (EU Exit) Regulations 2019 implement the United Kingdom's autonomous human-rights focused sanctions framework targeting Iranian officials and entities responsible for serious human rights violations, organised across ten principal parts covering designation authority and criteria in regulations 5 to 9, financial asset-freeze and prohibitions on making funds or economic resources available in regulations 11 to 15, trade controls on restricted goods, restricted technology and interception and monitoring equipment with detailed lists in three schedules, immigration restrictions in regulation 17, Treasury and trade licensing for humanitarian and basic needs purposes under Schedule 4, information powers and reporting obligations, and criminal enforcement and maritime powers in Parts 8 and 9, and are administered jointly by HM Treasury OFSI for financial sanctions and the Department for Business and Trade for trade sanctions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-iran-sanctions-nuclear-eu-exit-regulations-2019-si-461",
    "title": "UK Iran (Sanctions) (Nuclear) (EU Exit) Regulations 2019 SI 2019/461 Nuclear Proliferation Asset Freeze Trade and Maritime Sanctions Distinct from Iran Human Rights Regime",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Iran (Sanctions) (Nuclear) (EU Exit) Regulations 2019 establish the United Kingdom's autonomous sanctions framework targeting Iranian nuclear proliferation activities organised in 10 parts covering general provisions in Part 1, designation power and criteria for proliferation-connected persons in Part 2, asset freeze and restrictions on making funds or economic resources available in Part 3, immigration entry and residence prohibitions in Part 4, an extensive Part 5 trade regime across four chapters covering export restrictions to Iran import prohibitions from Iran other trade restrictions and interpretation and defences, Treasury and trade licensing mechanisms in Part 6, information reporting obligations and information-gathering powers in Part 7, criminal enforcement penalties jurisdiction and monetary sanctions in Part 8, maritime enforcement powers to stop board and search vessels in Part 9, and supplementary and transitional provisions with revocations in Part 10 supported by Schedule 1 ownership and control rules and Schedule 2 Treasury licensed purposes, operating distinctly from the Iran human rights sanctions regime under SI 2019/134.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018",
      "uk-iran-sanctions-human-rights-eu-exit-regulations-2019-si-134"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-iraq-sanctions-eu-exit-regulations-2020-si-707",
    "title": "UK Iraq (Sanctions) (EU Exit) Regulations 2020 SI 2020/707 UN Implementation Partial Asset Freeze Cultural Property Controls and Military Goods Prohibitions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Iraq (Sanctions) (EU Exit) Regulations 2020 establish the United Kingdom's framework implementing the legacy UN Security Council Iraq sanctions regime organised in 9 parts covering general provisions in Part 1 with regulation 4 application outside the UK, designation in Part 2 based on UN Security Council Resolutions, financial restrictions in Part 3 across four chapters covering definitions of designated person and ownership and control partial asset freeze on former Iraqi government entities full asset freeze on persons connected with the former regime and circumvention prohibitions, Part 4 trade across four chapters covering definitions military goods and technology restrictions illegally removed Iraqi cultural property controls and circumvention and defences, exceptions and licences in Part 5 including finance and trade exceptions and Treasury and trade licensing provisions, information and records in Part 6 with reporting information requests document production and disclosure rules, enforcement in Part 7 with penalties officer liability jurisdiction and monetary penalties, maritime enforcement powers in Part 8, and supplementary provisions in Part 9 with notices transitional arrangements and revocations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-isil-daesh-al-qaida-un-sanctions-eu-exit-regulations-2019-si-466",
    "title": "UK ISIL (Da'esh) and Al-Qaida (United Nations Sanctions) (EU Exit) Regulations 2019 SI 2019/466 - UN Security Council Asset Freeze and Counter-Terrorism Trade Restrictions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The ISIL (Da'esh) and Al-Qaida (United Nations Sanctions) (EU Exit) Regulations 2019 implement the United Nations Security Council ISIL Al-Qaida sanctions list in UK law organised in ten parts covering general provisions and application in Part 1, designation procedures for persons named on the UN Security Council 1267 1989 2253 list in Part 2, financial asset freeze and prohibitions on making funds or economic resources available in Part 3, trade prohibitions on military goods technology and related financial services and technical assistance in Part 4, specific asset-freeze provisions in Part 5, Treasury licences for humanitarian purposes basic needs and legal services in Part 6, information and reporting obligations in Part 7, enforcement and penalties in Part 8, maritime enforcement powers in Part 9, and transitional provisions in Part 10, and operate as the UK's primary counter-terrorism sanctions instrument implementing the UN 1267 sanctions committee designations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-keeping-children-safe-education-2024",
    "title": "Keeping children safe in education: Statutory guidance for schools and colleges",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This statutory guidance outlines the legal duties for schools and colleges in England to safeguard and promote the welfare of children and young people under 18.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-landlord-tenant-act-1985-repairing",
    "title": "UK Landlord and Tenant Act 1985 - Implied Repairing Covenants and Service Charge Restrictions",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Landlord and Tenant Act 1985 (c.70) implies repairing covenants into residential tenancy agreements under 7 years and restricts service charges in leasehold property. Section 11 implies a landlord's covenant in every lease of a dwelling-house under 7 years to keep the structure and exterior in repair and to maintain installations for water, gas, electricity, and space and water heating. Section 20 requires landlords to consult leaseholders before carrying out qualifying works costing more than £250 per leaseholder. Sections 18-30 govern the reasonableness and transparency of service charges for leasehold properties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "housing_act_2004_hhsrs",
        "renters_reform",
        "defective_premises_act_1972",
        "leasehold_reform_act_2022",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-housing-act-2004-hhsrs-hmo",
      "uk-building-safety-act-2022",
      "uk-planning-permission-tcpa-1990"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-leasehold-and-freehold-reform-act-2024",
    "title": "UK Leasehold and Freehold Reform Act 2024 - Ban on New Leasehold Houses, Lease Extension Reform, and Service Charge Transparency, Royal Assent 24 May 2024",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "Landlords, freeholders, leasehold managers, and developers of residential property in England and Wales must, following the Royal Assent of the Leasehold and Freehold Reform Act 2024 (LFRA 2024, Royal Assent 24 May 2024) on the staggered commencement schedule, comply with the ban on granting new long leases of houses under Part 1, with the lease extension reforms under Part 2 including the 990-year extension standard term (replacing 90 years for flats and 50 years for houses), the abolition of marriage value, the right to extend leases at 0.1 percent ground rent, the service charge transparency requirements under Part 4 (standardised service charge demands, annual reports, fixed administration fees), and the regulation of estate management charges under Part 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-landlord-tenant-act-1985-repairing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-leasehold-freehold-reform-act-2024",
    "title": "Leasehold and Freehold Reform Act 2024",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Act reforms residential property law in England and Wales, making it cheaper and easier for leaseholders to purchase their freehold, extend their lease, and take over management of their building. Key provisions include increasing standard lease extension terms to 990 years (Part 1, Chapter 2), abolishing marriage value, and improving transparency of service charges (Part 3, Chapter 2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sra-code-conduct-uk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-libya-sanctions-eu-exit-regulations-2020-si-1665",
    "title": "UK Libya (Sanctions) (EU Exit) Regulations 2020 SI 2020/1665 UN Implementation Asset Freezes Military Goods Ship and Aircraft Restrictions and Maritime Enforcement",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Libya (Sanctions) (EU Exit) Regulations 2020 establish the United Kingdom framework implementing the UN Security Council Libya sanctions regime organised in 12 parts covering general provisions in Part 1, designation in Part 2 based on UN Security Council Resolution 1970 and successor resolutions, finance restrictions in Part 3 with asset freezes and prohibitions on making funds available, immigration measures in Part 4, trade restrictions in Part 5 covering military goods technology related services and internal repression goods, Part 6 trade transport and finance measures related to UN designated ships including bunkering and crew restrictions, Part 7 aircraft including overflight and landing prohibitions, exceptions and licences in Part 8, information and records in Part 9, enforcement in Part 10 with criminal penalties and OFSI monetary penalties, maritime enforcement in Part 11 with stop board search and seizure powers, and supplementary provisions in Part 12. The Regulations include four schedules covering ownership interpretation rules internal repression goods trade definitions and Treasury licensing purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-mali-sanctions-eu-exit-regulations-2020-si-705",
    "title": "UK Mali (Sanctions) (EU Exit) Regulations 2020 SI 2020/705 UN Implementation Asset Freezes Immigration Restrictions and Enforcement",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Mali (Sanctions) (EU Exit) Regulations 2020 establish the United Kingdom framework implementing the UN Security Council Mali sanctions regime under Resolution 2374 (2017) organised in 8 parts covering general provisions in Part 1, designation in Part 2 based on UN Security Council criteria including persons threatening peace or stability in Mali or violating the Algiers Peace and Reconciliation Agreement, finance restrictions in Part 3 with asset freezes and prohibitions on making funds available, immigration measures in Part 4 making designated persons excluded from the UK, exceptions and licences in Part 5 including Treasury licensing for humanitarian and basic needs purposes, information and records in Part 6, enforcement in Part 7 with criminal penalties officer liability jurisdiction and OFSI monetary penalty powers, and supplementary provisions in Part 8 with notices and transitional rules. The Regulations include two schedules covering ownership interpretation rules and Treasury licensing purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-marine-and-coastal-access-act-2009",
    "title": "UK Marine and Coastal Access Act 2009: Marine Management Organisation, Marine Planning, Licensing and Conservation Zones",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Marine and Coastal Access Act 2009 is the principal framework for the management, planning, licensing and conservation of the United Kingdom marine area, administered by the Marine Management Organisation (MMO) and the devolved marine authorities. Part 1 establishes the MMO: section 1 constitutes the Marine Management Organisation, section 2 sets its general objective of making a contribution to sustainable development, and section 3 governs its performance. Part 3 creates the marine-planning system: section 44 provides for a marine policy statement, section 49 for marine planning regions, and section 51 for marine plans for marine plan areas, which guide decisions affecting the marine area. Part 4 establishes marine licensing: section 65 imposes the requirement for a marine licence, section 66 defines the licensable marine activities (including depositing or removing substances or objects and carrying out construction or dredging in the sea), and section 85 makes it an offence to carry on a licensable activity without a licence or in breach of its conditions. Part 5 provides for nature conservation: section 116 enables the designation of marine conservation zones, section 117 sets the grounds for designation, and section 125 places a general duty on public authorities to exercise their functions so as to further, or least hinder, the conservation objectives of marine conservation zones. Part 9 creates coastal access: section 296 imposes the coastal access duty and section 304 provides for the establishment and maintenance of the English coastal route. The Act is the legal basis on which the United Kingdom plans its seas, licenses marine works, designates marine protected areas and secures public access along the coast.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-marine-coastal-access-act-2009",
    "title": "UK Marine and Coastal Access Act 2009",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The UK Marine and Coastal Access Act 2009 (MCAA) is the principal Act establishing the legal framework for marine planning and management in UK waters. The Act creates the Marine Management Organisation (MMO) for English waters and provides for marine planning marine licensing inshore fisheries and conservation authorities (IFCAs) marine nature conservation including Marine Conservation Zones (MCZs) and English Coast Path. Marine licences are required for deposits removals dredging construction works and certain other regulated activities in marine areas. Penalties include unlimited fines and imprisonment up to 2 years for serious violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-media-act-2024-prominence-tier1-vod",
    "title": "Media Act 2024 (c. 15), Part 2 Prominence on Television Selection Services and Part 4 Tier 1 On-Demand Programme Services",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "The Media Act 2024 inserts a new Part 3A into the Communications Act 2003 requiring regulated television selection services to give designated internet programme services an appropriate degree of prominence, and amends Part 4A so larger on-demand programme services become Ofcom-regulated Tier 1 services. Providers of public service and major on-demand video content operating in the UK must secure carriage arrangements, ensure discoverability, and meet accessibility obligations enforced by Ofcom. Section 28 governs prominence; section 37 brings non-UK and Tier 1 on-demand programme services into the regulatory framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-media-services-directive-2018-1808",
      "ca-broadcasting-act-2023-online-streaming",
      "uk-online-safety-act-2023-section-71-action-against-users-only-per-terms"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-medicines-healthcare-products-regulatory-agency-mhra-device-registration",
    "title": "UK MHRA Medical Device Registration - UK MDR 2002 Post-Brexit Requirements",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-07-01",
    "bluf": "Following Brexit, the UK Medicines and Healthcare products Regulatory Agency (MHRA) has separate medical device registration requirements from the EU MDR. Manufacturers must register with MHRA before placing devices on the Great Britain market (UK Conformity Assessed - UKCA marking required for Class I sterile/measuring, IIa, IIb, Class III). Northern Ireland continues to follow EU MDR. CE-marked devices can be placed on the GB market under transitional arrangements until June 2025 (extended to 2030 for higher risk classes). MHRA registration is mandatory for all device classes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-2016-medical-devices-quality-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-mental-capacity-act-2005-section-1-principles",
    "title": "UK Mental Capacity Act 2005 Section 1 - The Principles (Presumption of Capacity, All Practicable Steps, Unwise Decision Not Incapacity, Best Interests, Least Restrictive Option)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 1 of the Mental Capacity Act 2005 (c. 9) establishes the five foundational principles that govern the entire MCA 2005 regime in England and Wales - the operative principles applied by all health and social care professionals, attorneys under Lasting Powers of Attorney, deputies appointed by the Court of Protection, and any person undertaking actions in connection with the care or treatment of a person who lacks capacity. Section 1(1) declares that the principles in subsections (2)-(6) apply for the purposes of the Act. Section 1(2) (Principle 1): a person must be assumed to have capacity unless it is established that he lacks capacity. Section 1(3) (Principle 2): a person is not to be treated as unable to make a decision unless all practicable steps to help him to do so have been taken without success. Section 1(4) (Principle 3): a person is not to be treated as unable to make a decision merely because he makes an unwise decision. Section 1(5) (Principle 4): an act done, or decision made, under this Act for or on behalf of a person who lacks capacity must be done, or made, in his best interests. Section 1(6) (Principle 5): before the act is done, or the decision is made, regard must be had to whether the purpose for which it is needed can be as effectively achieved in a way that is less restrictive of the person's rights and freedom of action. The principles operate as the lens through which sections 2-3 (capacity test), section 4 (best interests determination), and sections 5-6 (Deprivation of Liberty Safeguards / Liberty Protection Safeguards) are applied.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_1_text",
        "principle_1_presumption_of_capacity_section_1_2",
        "principle_2_all_practicable_steps_section_1_3",
        "principle_3_unwise_decision_section_1_4",
        "principle_4_best_interests_section_1_5_and_section_4_factors",
        "principle_5_least_restrictive_option_section_1_6",
        "code_of_practice_section_42_43_statutory_obligation_to_have_regard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-mental-capacity-act-2005-section-2-people-who-lack-capacity",
    "title": "UK Mental Capacity Act 2005 Section 2 — People Who Lack Capacity",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person lacks capacity in relation to a matter if, at the material time, they are unable to make a decision for themselves in relation to that matter because of an impairment of, or a disturbance in the functioning of, the mind or brain. The impairment may be permanent or temporary. Capacity cannot be determined by reference to age, appearance, condition, or aspects of behaviour that might lead to unjustified assumptions. In legal proceedings, lack of capacity is decided on the balance of probabilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "two_stage_diagnostic_and_functional_test",
        "decision_specific_and_time_specific",
        "impairment_permanent_or_temporary",
        "no_assumption_by_reference_to_age_appearance_or_behaviour",
        "balance_of_probabilities_in_legal_proceedings",
        "section_18_3_under_16_exception_link",
        "links_to_section_1_principles_and_section_3_inability_test"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-mental-capacity-act-2005-section-1-principles",
      "uk-mental-capacity-act-2005-section-3-inability-to-make-decisions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-mental-capacity-act-2005-section-3-inability-to-make-decisions",
    "title": "UK Mental Capacity Act 2005 Section 3 — Inability to Make Decisions",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "For the purposes of Section 2, a person is unable to make a decision if they are unable to understand, retain, use or weigh the relevant information, or communicate the decision by any means. Information must be presented in a way appropriate to the person's circumstances, including simple language and visual aids. Short-term retention is sufficient. Relevant information includes the reasonably foreseeable consequences of deciding either way or failing to decide. This is the functional limb of the capacity test.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "four_functional_inabilities",
        "any_one_inability_suffices",
        "appropriate_explanation_must_be_provided",
        "short_term_retention_sufficient",
        "relevant_information_includes_consequences",
        "communication_by_any_means",
        "must_be_read_with_section_2_and_section_1"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-mental-capacity-act-2005-section-1-principles",
      "uk-mental-capacity-act-2005-section-2-people-who-lack-capacity"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-mental-health-act-1983-section-1-application-mental-disorder",
    "title": "UK Mental Health Act 1983 Section 1 - Application of Act and Definition of Mental Disorder (Any Disorder or Disability of the Mind, Learning Disability Aggression Qualification, Drug Alcohol Exclusion)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 1 of the Mental Health Act 1983 (c. 20) provides the foundational definitions of mental disorder for the entire MHA 1983 framework - the gateway provision determining who may be detained, treated compulsorily, or subject to community treatment under the Act. Under section 1(1), the provisions of the Act have effect with respect to the reception, care and treatment of mentally disordered patients, the management of their property and other related matters. Under section 1(2), 'mental disorder' means any disorder or disability of the mind and 'mentally disordered' shall be construed accordingly. Under section 1(2A), a person with learning disability shall not be considered by reason of that disability to be (a) suffering from mental disorder for the purposes of the provisions mentioned in subsection (2B), or (b) requiring treatment in hospital for mental disorder for the purposes of sections 17E and 50 to 53, unless that disability is associated with abnormally aggressive or seriously irresponsible conduct on his part. Under section 1(2B), the specified provisions are sections 3 (admission for treatment), 7 (guardianship), 17A (CTO), 20 and 20A (renewal); sections 35-38 (court orders), 45A (hospital direction), 47, 48 and 51 (transfer from prison); and section 72(1)(b) and (c) and (4) (tribunal review). Under section 1(3), dependence on alcohol or drugs is not considered to be a disorder or disability of the mind. Under section 1(4), 'learning disability' means a state of arrested or incomplete development of the mind which includes significant impairment of intelligence and social functioning.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_1_text",
        "broad_mental_disorder_definition_post_mha_2007_amendment",
        "learning_disability_qualification_section_1_2a_aggressive_or_irresponsible_conduct",
        "alcohol_drug_exclusion_section_1_3",
        "civil_admission_routes_sections_2_3_4_5",
        "forensic_routes_sections_35_38_45a_47_48_51",
        "tribunal_review_section_72_oversight",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-mental-capacity-act-2005-section-1-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-mental-health-act-1983-section-2-admission-assessment",
    "title": "Mental Health Act 1983 Section 2: Admission for assessment",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This section establishes the legal grounds and procedural requirements for the compulsory admission and detention of a patient in a hospital for assessment, based on recommendations from two medical practitioners, for a period not exceeding 28 days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-mental-health-act-1983-section-3-admission-for-treatment",
    "title": "UK Mental Health Act 1983 Section 3 — Admission for Treatment",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A patient may be admitted to hospital and detained for treatment under Section 3 on the grounds that they are suffering from mental disorder of a nature or degree which makes hospital treatment appropriate, that treatment is necessary for the health or safety of the patient or for the protection of others and cannot be provided unless they are detained, and that appropriate medical treatment is available. The application must be founded on written recommendations of two registered medical practitioners with prescribed particulars and reasons. Section 3 detention initially lasts up to six months, renewable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_admission_and_detention_for_treatment",
        "ground_a_mental_disorder_nature_or_degree",
        "ground_b_repealed",
        "ground_c_necessity_and_detention_required",
        "ground_d_appropriate_medical_treatment_available",
        "two_doctor_recommendation_requirement",
        "particulars_of_grounds_and_reasons_for_necessity",
        "definition_appropriate_medical_treatment",
        "applicant_must_be_amhp_or_nearest_relative_section_11",
        "detention_period_six_months_renewable_section_20"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-mental-health-act-1983-section-1-application-mental-disorder"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-merchant-shipping-act-1995",
    "title": "UK Merchant Shipping Act 1995 -- Ship Registration, Safety Standards, and Marine Pollution Liability",
    "domain": "Maritime & Shipping",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "The Merchant Shipping Act 1995 (MSA 1995) is the principal UK statute governing merchant shipping, ship registration, maritime safety, and liability for oil pollution. Part II establishes the UK Ship Register with four sub-registers (the SSR, simple, full, and bareboat charter registers). Section 85 makes it an offence to send or take an unseaworthy ship to sea. Part V implements the right and duty of salvage. Section 224 and Schedule 11 implement the Civil Liability Convention 1992 (CLC 1992) and International Oil Pollution Compensation Fund conventions for oil tanker spills. The Maritime and Coastguard Agency (MCA) is the UK competent authority for port state control and flag state enforcement. The International Safety Management (ISM) Code is implemented through SI 1998/1561. The Maritime Labour Convention (MLC 2006) is implemented through the Merchant Shipping (Maritime Labour Convention) Regulations 2014 (SI 2014/1613). The ISPS Code for maritime security applies under SI 2004/1495. Post-Brexit, the UK operates independently of EU maritime law but maintains alignment with IMO conventions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nz-maritime-transport-act-1994",
      "eu-services-directive-2006-123",
      "eu-waste-framework-directive-2008-98"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-merchant-shipping-act-1995-c21",
    "title": "Merchant Shipping Act 1995",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The Merchant Shipping Act 1995 establishes the legal framework for the registration, operation, safety, and crewing of British ships, including requirements for seaworthiness, manning, and liability. It applies to all UK-registered vessels and their owners, masters, and seafarers under Section 42 and Section 47.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "imo-marpol-pollution"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-mhra-ai-medical-devices-2026",
    "title": "UK MHRA - AI as a Medical Device (AIaMD) and Software as a Medical Device (SaMD) Framework (2026)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The Medicines and Healthcare products Regulatory Agency (MHRA) regulates AI as a Medical Device and SaMD under the Medical Devices Regulations 2002 (as amended). Key requirements include risk classification, clinical evaluation, quality management, cybersecurity, post-market surveillance, and specific AI obligations such as explainability, bias mitigation, performance monitoring, and change control for adaptive systems. The framework aligns with the UK AI Regulation White Paper principles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "uk-mhra-good-clinical-practice-regulations-2004",
    "title": "The Medicines for Human Use (Clinical Trials) Regulations 2004",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The UK MHRA Good Clinical Practice Regulations 2004 require sponsors and investigators to comply with the principles of Good Clinical Practice, as outlined in Regulation 3, and to obtain authorization for clinical trials, as stated in Regulation 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-mhra-medical-devices-regulations-2002-si-2002-618",
    "title": "UK MHRA Medical Devices Regulations 2002 - Post-Brexit CE/UKCA Marking & Clinical Investigation",
    "domain": "Medical & Healthcare",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "UK Medicines and Healthcare products Regulatory Agency (MHRA) requires UKCA marking from July 2024 for Great Britain medical devices, transitioning from EU CE marking acceptance - manufacturers must register with MHRA, appoint UK Responsible Person, and comply with revised clinical evidence and post-market surveillance requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-mines-and-quarries-act-1954",
    "title": "UK Mines and Quarries Act 1954: Management Duties, Mine Safety and Offences",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Mines and Quarries Act 1954 is a foundational UK statute on the management and safety of mines and quarries, much of it now operating alongside and partly superseded by regulations made under the Health and Safety at Work etc. Act 1974, with enforcement by the Health and Safety Executive. Section 1 sets the general duties of mine and quarry owners to secure that the mine or quarry is operated in accordance with the Act. Section 2 provides for the appointment of a manager of every mine and sets the manager's general duties and powers, making the manager responsible for the day-to-day control. On safety, section 22 requires the provision of shafts and outlets giving safe means of ingress and egress, section 48 imposes a duty to secure the safety of roads and working places, and section 55 imposes a duty to provide adequate ventilation to dilute and render harmless noxious and inflammable gases. Enforcement is provided by section 152 (offences) and section 155 (the penalty where no express penalty is provided), while section 157 provides a defence where compliance was impracticable and section 159 makes owners liable for breaches of statutory duty by their servants or agents. The Act remains a legal foundation of UK mine and quarry management duties and safety obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-misuse-of-drugs-act-1971-section-4-production-supply-controlled-drugs",
    "title": "UK Misuse of Drugs Act 1971 Section 4 - Restriction of Production and Supply of Controlled Drugs (Production Offence, Supply or Offer to Supply Offence, Being Concerned In)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 4 of the Misuse of Drugs Act 1971 (c. 38) is the primary UK criminal offence regime for the production and supply of controlled drugs and operates as the foundational provision for drug-trafficking prosecutions under the Sentencing Council Drug Offences Guideline. Under section 4(1), subject to any regulations under section 7 or any temporary class drug order under section 7A, it shall not be lawful for a person (a) to produce a controlled drug, or (b) to supply or offer to supply a controlled drug to another. Under section 4(2), subject to section 28, it is an offence for a person (a) to produce a controlled drug in contravention of subsection (1), or (b) to be concerned in the production of such a drug in contravention of that subsection by another. Under section 4(3), subject to section 28, it is an offence for a person (a) to supply or offer to supply a controlled drug to another in contravention of subsection (1), (b) to be concerned in the supplying of such a drug to another in contravention of that subsection, or (c) to be concerned in the making to another in contravention of that subsection of an offer to supply such a drug. Penalties under section 25 and Schedule 4 are class-graded: Class A maximum life imprisonment and unlimited fine; Class B maximum 14 years; Class C maximum 14 years; on summary conviction Class A 12 months and statutory maximum; Class B and C 6 or 12 months and statutory maximum.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_4_text",
        "production_offence_section_4_2",
        "supply_offence_section_4_3_includes_offer_and_being_concerned",
        "controlled_drug_classification_schedule_2",
        "section_28_statutory_defences",
        "section_4a_aggravated_supply_to_under_18s_in_drug_free_zones",
        "penalty_section_25_schedule_4",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-misuse-of-drugs-act-1971-section-5-possession-controlled-drugs",
    "title": "UK Misuse of Drugs Act 1971 Section 5 - Restriction of Possession of Controlled Drugs (Possession Offence, Intent to Supply Aggravated Offence, Limited Defences)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 5 of the Misuse of Drugs Act 1971 (c. 38) creates the offence of possession of controlled drugs. Under section 5(1), subject to any regulations under section 7, it shall not be lawful for a person to have a controlled drug in his possession. Under section 5(2), subject to section 28 and subsection (4), it is an offence for a person to have a controlled drug in his possession in contravention of subsection (1). Under section 5(2A), subsections (1) and (2) do not apply to temporary class drugs. Under section 5(3), it is an offence for a person to have a controlled drug (whether lawfully or unlawfully) in his possession with intent to supply it to another in contravention of section 4(1) - the aggravated possession with intent to supply offence. Section 5(4) provides two statutory defences: (a) the person knowing or suspecting it was a controlled drug took possession to prevent another committing an offence and promptly took steps to destroy it or deliver it to authorised possession; (b) the person took possession for the purpose of delivery to an authorised person and promptly took reasonable steps to deliver. Section 5(5)-(6) extend defences to attempts and preserve other available defences. Maximum penalty section 25/Schedule 4: section 5(2) Class A 7 years; Class B 5 years; Class C 2 years. Section 5(3) with intent to supply: Class A life; Class B 14 years; Class C 14 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_5_text",
        "possession_test_legal_and_factual",
        "possession_with_intent_to_supply_section_5_3",
        "section_5_4_defences_taking_possession_to_destroy_or_deliver",
        "section_28_lack_of_knowledge_defence",
        "penalty_section_25_schedule_4_class_graded",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-misuse-of-drugs-act-1971-section-4-production-supply-controlled-drugs"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-mlr-2017-money-laundering-regulations",
    "title": "UK Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-18",
    "bluf": "The UK Money Laundering Regulations 2017 (SI 2017/692) impose AML/CFT obligations on relevant persons: documented risk assessment (Regulation 18), policies, controls and procedures (Regulation 19), customer due diligence (Regulations 27-28), enhanced due diligence including for politically exposed persons (Regulations 33 and 35), record keeping (Regulation 40), staff training (Regulation 24), and registration and supervision (Regulations 54-58).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-mlr-2019-1511-cryptoasset-amendment",
    "title": "United Kingdom - The Money Laundering and Terrorist Financing (Amendment) Regulations 2019 (SI 2019/1511): Inclusion of Cryptoasset Exchange Providers and Custodian Wallet Providers Within the UK AML Regime; FCA as Supervisory Authority and Maintainer of the Cryptoasset Register",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2019-12-20",
    "bluf": "The Money Laundering and Terrorist Financing (Amendment) Regulations 2019 (SI 2019/1511) amend the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692, the 'MLR 2017') to bring UK cryptoasset businesses within the scope of the United Kingdom's AML/CFT regime, in implementation of the EU Fifth Anti-Money Laundering Directive's cryptoasset provisions. The 2019 SI inserts a new regulation 14A in the MLR 2017 defining 'cryptoasset exchange provider' (regulation 14A(1)) as a firm or sole practitioner who by way of business provides one or more of: (a) exchanging, or arranging or making arrangements with a view to the exchange of, cryptoassets for money or money for cryptoassets, (b) exchanging, or arranging or making arrangements with a view to the exchange of, one cryptoasset for another, or (c) operating a machine which utilises automated processes to exchange cryptoassets for money or money for cryptoassets, including where the firm or sole practitioner does so as creator or issuer of any of the cryptoassets involved. 'Custodian wallet provider' (regulation 14A(2)) means a firm or sole practitioner who by way of business provides services to safeguard, or to safeguard and administer, (a) cryptoassets on behalf of its customers, or (b) private cryptographic keys on behalf of its customers in order to hold, store and transfer cryptoassets. 'Cryptoasset' is defined as 'a cryptographically secured digital representation of value or contractual rights that uses a form of distributed ledger technology and can be transferred, stored or traded electronically'. The SI amends regulation 7(1) (supervisory authorities) to add cryptoasset exchange providers and custodian wallet providers as categories of relevant person under Financial Conduct Authority (FCA) supervision; amends regulation 54 to require the FCA to maintain a register of cryptoasset exchange providers and custodian wallet providers (new regulation 54(1A)); amends regulation 56 (requirement to be registered) to add cryptoasset exchange provider and custodian wallet provider to the registration-required list; and inserts a new regulation 56A providing a transitional provision for existing cryptoasset businesses. The SI also extends customer due diligence obligations: a cryptoasset exchange provider operating a machine which utilises automated processes must apply CDD measures in relation to each transaction carried out using that machine (new regulation 27(7D) in the MLR 2017). The 2019 SI is the foundational instrument that brought UK crypto exchanges and custodian wallet providers into the FCA's AML registration regime; non-registration with the FCA where required is a criminal offence under MLR 2017 regulation 56.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "uk-money-laundering-regulations-2017-amended",
        "eu-5amld-fifth-anti-money-laundering-directive",
        "uk-fca-crypto-promotion-rules-2023",
        "fatf-recommendation-16-travel-rule-crypto",
        "uk-financial-services-markets-act-2023-crypto"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-money-laundering-regulations-2017-amended",
      "uk-financial-services-markets-act-2023-crypto"
    ],
    "primary_citations_count": 16
  },
  {
    "node_id": "uk-modern-slavery-act-2015-section-1-slavery-servitude-forced-labour",
    "title": "UK Modern Slavery Act 2015 Section 1 - Slavery Servitude and Forced or Compulsory Labour (Holding in Slavery, Requiring Forced Labour, Article 4 ECHR Test, Consent Immaterial)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 1 of the Modern Slavery Act 2015 (c. 30) creates the offence of slavery, servitude and forced or compulsory labour and operates as the foundational UK modern slavery offence alongside section 2 (human trafficking). Under section 1(1), a person commits an offence if (a) the person holds another person in slavery or servitude and the circumstances are such that the person knows or ought to know that the other person is held in slavery or servitude, or (b) the person requires another person to perform forced or compulsory labour and the circumstances are such that the person knows or ought to know that the other person is being required to perform forced or compulsory labour. Section 1(2) requires the court to have regard to Article 4 of the Human Rights Convention (ECHR) in interpreting slavery, servitude, and forced or compulsory labour. Section 1(3) provides that the court may have regard to all the circumstances in determining whether the offence has been committed, including any of the person's personal circumstances (including age, family relationships, mental or physical illness) that may make the person more vulnerable. Section 1(4)(b) makes consent immaterial - 'the consent of a person (whether an adult or a child) to any of the acts alleged to constitute holding the person in slavery or servitude, or requiring the person to perform forced or compulsory labour, does not preclude a determination'. Maximum penalty under section 5 is life imprisonment plus unlimited fine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_1_text",
        "article_4_echr_test_section_1_2",
        "consent_immaterial_section_1_4_b",
        "knowledge_or_ought_to_know_threshold",
        "vulnerability_factors_section_1_3",
        "penalty_section_5",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-modern-slavery-act-2015-section-2-human-trafficking",
      "uk-modern-slavery-act-2015-section-54-supply-chain-transparency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-modern-slavery-act-2015-section-2-human-trafficking",
    "title": "UK Modern Slavery Act 2015 Section 2 - Human Trafficking Offence (Arrangement/Facilitation of Travel for Exploitation, V Consent Irrelevant, Recruitment/Transportation/Harbouring/Exchange of Control, UK National Worldwide Jurisdiction, Non-UK National UK-Connected Conduct)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 2 of the Modern Slavery Act 2015 (c. 30) creates the criminal offence of human trafficking. Under section 2(1), a person commits an offence if the person arranges or facilitates the travel of another person (V) with a view to V being exploited. Under section 2(2), it is irrelevant whether V consents to the travel (whether V is an adult or a child) - V's consent is not a defence to the trafficking offence. Under section 2(3), a person may in particular arrange or facilitate V's travel by recruiting V, transporting or transferring V, harbouring or receiving V, or transferring or exchanging control over V. Under section 2(4), a person arranges or facilitates V's travel with a view to V being exploited only if (a) the person intends to exploit V (in any part of the world) during or after the travel, or (b) the person knows or ought to know that another person is likely to exploit V (in any part of the world) during or after the travel. Under section 2(5), 'travel' means (a) arriving in, or entering, any country, (b) departing from any country, or (c) travelling within any country. Under section 2(6), a person who is a UK national commits an offence under this section regardless of (a) where the arranging or facilitating takes place, or (b) where the travel takes place. Under section 2(7), a person who is not a UK national commits an offence under this section if (a) any part of the arranging or facilitating takes place in the UK, or (b) the travel consists of arrival in or entry into, departure from, or travel within, the UK. The exploitation types are defined in section 3 - slavery, servitude, forced or compulsory labour (per section 1), sexual exploitation, removal of organs, securing services etc. by force, threats, deception, or from children/vulnerable persons. The maximum penalty under section 5 is life imprisonment on indictment plus an unlimited fine plus Proceeds of Crime Act 2002 confiscation. Prosecution is by the Crown Prosecution Service (CPS) with NCA and police investigation. Section 2 is the UK's primary criminal trafficking provision and underpins the National Referral Mechanism for identification and support of victims.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_2_text_subsections",
        "exploitation_types_section_3",
        "consent_irrelevant_section_2_2",
        "arrangement_facilitation_breadth_section_2_3",
        "extraterritorial_jurisdiction_section_2_6_7",
        "national_referral_mechanism_section_50",
        "section_45_defence_for_victims",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-modern-slavery-act-2015-section-54-supply-chain-transparency"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-modern-slavery-act-2015-section-4-committing-offence-with-intent",
    "title": "UK Modern Slavery Act 2015 Section 4 - Committing Offence With Intent to Commit Section 2 Trafficking Offence (Any Offence Committed With Intent, Including Aiding Abetting Counselling Procuring)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 4 of the Modern Slavery Act 2015 (c. 30) creates the offence of committing an offence with the intent to commit a section 2 human trafficking offence. Under section 4, a person commits an offence under this section if the person commits any offence with the intention of committing an offence under section 2 (including an offence committed by aiding, abetting, counselling or procuring an offence under that section). Section 4 is an inchoate-style offence that captures preparatory or facilitating crimes committed with the intent to traffic, including (but not limited to) document fraud (forged passports for victim transport), conspiracy offences, immigration offences (assisting unlawful entry under Immigration Act 1971 section 25), false document offences under Identity Documents Act 2010, and grooming/coercion offences. Section 4 applies across England, Wales, Scotland, and Northern Ireland. Maximum penalty under section 5 is life imprisonment plus unlimited fine - mirroring the section 2 trafficking penalty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_4_text",
        "any_offence_with_intent_breadth_of_section_4",
        "section_2_trafficking_target_offence",
        "aiding_abetting_counselling_procuring_inclusion",
        "penalty_section_5_life_imprisonment",
        "national_referral_mechanism_nrm_overlap",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-modern-slavery-act-2015-section-1-slavery-servitude-forced-labour",
      "uk-modern-slavery-act-2015-section-2-human-trafficking",
      "uk-modern-slavery-act-2015-section-54-supply-chain-transparency"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-modern-slavery-act-2015-section-54-supply-chain-transparency",
    "title": "Modern Slavery Act 2015, Section 54: Transparency in supply chains etc.",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Requires commercial organisations over a prescribed turnover threshold to prepare and publish an annual slavery and human trafficking statement detailing steps taken to ensure their business and supply chains are free from modern slavery.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-modern-slavery-act-2015-section-54-tisc",
    "title": "UK Modern Slavery Act 2015 - Section 54 Transparency in Supply Chains",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "UK Modern Slavery Act 2015 Section 54 requires commercial organisations carrying on a business or part of a business in the UK with a total turnover of GBP 36 million or more to prepare a slavery and human trafficking statement each financial year. The statement must describe the steps the organisation has taken during the financial year to ensure slavery and human trafficking is not taking place in any of its supply chains or in any part of its own business (or a statement that no such steps have been taken). The statement must be approved by the board (or equivalent governing body) signed by a director and published prominently on the organisations website. Section 54 does not impose a mandatory content requirement but Home Office Guidance recommends six suggested categories.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "msa_2015",
        "msa_au",
        "ca_supply_chain",
        "msa_california",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-modern-slavery-act-2015-section-54-transparency-in-supply-chains",
    "title": "UK Modern Slavery Act 2015 Section 54 — Transparency in Supply Chains",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A commercial organisation supplying goods or services with total turnover of at least the prescribed threshold (currently £36 million) must publish a slavery and human trafficking statement for each financial year. The statement must describe steps taken to ensure modern slavery is not occurring in the organisation's business or supply chains, or state that no such steps were taken. The statement must be approved at board level and signed by a director, and prominently published on the organisation's homepage. The Secretary of State can enforce the duty by High Court injunction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "annual_statement_obligation",
        "scope_threshold_supply_goods_or_services_plus_turnover",
        "two_acceptable_statement_forms",
        "permitted_content_six_areas",
        "board_approval_and_signature_requirements",
        "publication_requirements_homepage_prominence",
        "secretary_of_state_enforcement_by_injunction",
        "definition_of_slavery_and_human_trafficking_for_section_54"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-modern-slavery-act-2015-section-1-slavery-servitude-forced-labour",
      "uk-modern-slavery-act-2015-section-4-committing-offence-with-intent"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-modern-slavery-act-2015-supply-chain-transparency-statement",
    "title": "UK Modern Slavery Act 2015 - Supply Chain Transparency Statement & Due Diligence Obligations",
    "domain": "Sustainability & ESG",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "UK Modern Slavery Act 2015 requires commercial organisations with GBP 36 million+ annual turnover operating in the UK to publish an annual modern slavery and human trafficking transparency statement - covering supply chain due diligence steps, risk assessment, and training measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-money-laundering-regulations-2017",
    "title": "UK Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The UK Money Laundering Regulations 2017 (MLR 2017) transpose the EU Fourth Anti-Money Laundering Directive (4AMLD) into UK law and were amended by the 2019 Regulations to transpose 5AMLD. They impose customer due diligence (CDD), simplified due diligence (SDD), and enhanced due diligence (EDD) requirements on relevant persons including credit institutions, financial institutions, auditors, accountants, tax advisers, legal professionals, trust or company service providers, estate agents, high value dealers, casinos, art market participants, and cryptoasset exchange providers. They require a written risk assessment, policies controls and procedures, training, suspicious activity reporting to the National Crime Agency (NCA), and registration with the Financial Conduct Authority (FCA), HMRC, or other supervisor.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "poca",
        "eu_4amld",
        "eu_5amld",
        "fatf_recs",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-money-laundering-regulations-2017-amended",
    "title": "The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (as amended)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires UK financial institutions, legal professionals, and other relevant persons to conduct firm-wide risk assessments (Regulation 18), apply customer due diligence (CDD) measures (Regulation 28), and implement enhanced due diligence (EDD) for high-risk situations, including relationships with Politically Exposed Persons (PEPs) (Regulation 35), to prevent the use of the financial system for money laundering and terrorist financing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "fatf-guidance-virtual-assets-vasp",
      "eu-aml-regulation-2024",
      "fca-consumer-duty-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-motor-vehicles-tests-regulations-1981-mot",
    "title": "Motor Vehicles (Tests) Regulations 1981 (SI 1981/1694)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Motor Vehicles (Tests) Regulations 1981 (SI 1981/1694) govern the periodic roadworthiness test (the MOT test) of motor vehicles in Great Britain. Regulation 4 sets out the prescribed statutory requirements that a vehicle must meet, Regulation 5 covers the classification of vehicles and the application of the Regulations, Regulation 13 sets the requirements as to vehicles submitted for examination, and Regulation 20 sets the fees for examinations. A test certificate is issued where the vehicle meets the prescribed statutory requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-road-traffic-act-1988-construction-use-insurance"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-national-cyber-strategy-2022-ncsc-baseline",
    "title": "UK National Cyber Strategy 2022 and NCSC Cyber Essentials - Baseline Controls for Preventing Common Cyber Attacks and Government System Requirements",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK NCSC's Cyber Essentials scheme requires organizations to implement five fundamental technical security controls to defend against the most common cyber threats. This government-backed certification is mandatory for suppliers bidding for certain central government contracts, as outlined in the scheme's requirements documentation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "nist-cybersecurity-framework-2-0",
      "australia-essential-eight-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-national-parks-access-countryside-act-1949",
    "title": "UK National Parks and Access to the Countryside Act 1949 (c.97): National Parks, Nature Reserves and Public Access to Open Country",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The National Parks and Access to the Countryside Act 1949 (c. 97) is the foundational statute for the designation of National Parks, areas of outstanding natural beauty, and nature reserves in England and Wales, and for securing public access to open country, now administered by Natural England and Natural Resources Wales with National Park authorities and local authorities. Section 5 provides for the designation of extensive tracts of country as National Parks for the purpose of preserving and enhancing their natural beauty and promoting their enjoyment by the public, and section 7 governs the designation and variation of National Parks. Section 6 sets the general duties of Natural England in relation to National Parks. Section 15 defines the meaning of a nature reserve as land managed for the study and preservation of flora, fauna, or geological features, and section 19 provides for declarations that areas are nature reserves. Section 51 makes general provision for long-distance routes enabling extensive journeys on foot, and section 59 provides for public access to open country. Section 87 provides for the designation of areas of outstanding natural beauty for the purpose of conserving and enhancing their natural beauty. The Act, as amended, remains the legal basis for the protected landscape and nature reserve framework of England and Wales.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-national-quantum-strategy-2023",
    "title": "National Quantum Strategy: A 10-year vision and strategy missions for the UK to be a leading quantum-enabled economy",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This strategy outlines the UK’s 10-year plan to become a leading quantum-enabled economy, focusing on quantum computing, sensing, and secure communications. It applies to government agencies, research institutions, and private sector entities involved in quantum technology development and deployment, with key missions published on 22 November 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cmmc-2-audit",
      "nist-800-171-cui",
      "iso-27017-cloud-defence"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-national-security-investment-act-2021",
    "title": "United Kingdom National Security and Investment Act 2021 (NSIA): Call-in Notice, Notifiable Acquisitions, Mandatory Notification Procedure, Voluntary Notification, Interim Orders, Final Orders, Criminal Offences for Completion Without Approval, and the Investment Security Unit",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The National Security and Investment Act 2021, chapter 25 of 2021, received Royal Assent on 29 April 2021 and entered into substantive force on 4 January 2022 and is the principal United Kingdom statute providing the standalone foreign investment screening regime on national security grounds, administered by the Investment Security Unit in the Cabinet Office. National Security and Investment Act 2021, section 1 confers on the Secretary of State the power to give a call-in notice in relation to a trigger event that has given rise to or may give rise to a risk to national security. National Security and Investment Act 2021, section 6 governs notifiable acquisitions and confers a power on the Secretary of State to make regulations specifying the qualifying entities and activities falling within the mandatory notification regime including the 17 sensitive sectors. National Security and Investment Act 2021, section 13 governs approval of notifiable acquisitions. National Security and Investment Act 2021, section 14 governs the mandatory notification procedure and provides that a person who acquires a notifiable acquisition without approval commits an offence. National Security and Investment Act 2021, section 25 confers on the Secretary of State the power to make interim orders during the assessment period. National Security and Investment Act 2021, section 26 governs final orders and final notifications including unwind, divestment, and conduct conditions. National Security and Investment Act 2021, section 32 sets the offence of completing a notifiable acquisition without approval. The Act repeals the public interest intervention regime for national security in the Enterprise Act 2002 and is the controlling United Kingdom standalone investment screening instrument.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-national-security-investment-act-2021-aerospace",
    "title": "National Security and Investment Act 2021",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The National Security and Investment Act 2021 requires mandatory notification of notifiable acquisitions in 17 sensitive sectors, including aerospace, where a person acquires 25% or more of shares or voting rights, or material influence, triggering government call-in powers to protect national security under Section 3 and Schedule 2. Failure to comply constitutes a criminal offence under Section 32.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "as9100-rev-d-qms",
      "iso-27017-cloud-defence",
      "cmmc-2-audit",
      "nist-800-171-cui",
      "do-178c-airborne-software-2011"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-nationality-and-borders-act-2022",
    "title": "UK Nationality and Borders Act 2022: Differential Treatment of Refugees, Inadmissibility, Maritime Enforcement and Offences",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Nationality and Borders Act 2022 is a major reform of United Kingdom nationality, asylum and immigration enforcement law, administered by the Home Office. Part 1 reforms British nationality, including section 1 (remedying the historical inability of mothers to transmit citizenship), section 2 (the historical inability of unmarried fathers to transmit citizenship), section 3 (British nationality for Chagos Islanders' descendants) and section 11 (citizenship for stateless minors). Part 2 reshapes asylum: section 12 introduces the differential treatment of refugees, distinguishing Group 1 refugees (who came directly and claimed without delay) from Group 2 refugees and permitting less favourable treatment of Group 2; section 14 requires an asylum claim to be made at a designated place; section 15 makes asylum claims by EU nationals inadmissible save in exceptional circumstances; section 16 provides for inadmissibility where the claimant has a connection to a safe third State; sections 20 to 25 establish the priority removal notice framework; section 29 governs removal of an asylum seeker to a safe country; and sections 30 to 38 set out the interpretation of the Refugee Convention. Part 3 strengthens immigration control, including section 40 (illegal entry and similar offences), section 41 (assisting unlawful immigration, with the maximum penalty raised) and sections 43 to 45 (maritime enforcement powers). Part 5 reforms modern slavery, including the identification of and protections for victims of trafficking (sections 58 to 68). The Act is the legal foundation for the United Kingdom's two-tier refugee model, third-country inadmissibility and toughened entry offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-nationality-and-borders-act-2022-section-40-illegal-entry-offences",
    "title": "UK Nationality and Borders Act 2022 Section 40 - Illegal Entry and Similar Offences",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 40 of the Nationality and Borders Act 2022 amends Section 24 of the Immigration Act 1971 to create and expand offences relating to illegal entry, arrival, and remaining in the United Kingdom. It is an offence to knowingly enter the UK in breach of a deportation order or without leave when leave is required, to knowingly arrive in the UK without the required entry clearance or Electronic Travel Authorisation, or to remain beyond the period authorised by leave. Maximum penalty on indictment is five years' imprisonment; on summary conviction in England and Wales, up to 12 months and/or a fine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "amends_section_24_of_immigration_act_1971",
        "knowing_entry_in_breach_of_deportation_order",
        "knowing_arrival_without_required_entry_clearance_or_eta",
        "knowing_overstay_offence",
        "breach_of_leave_conditions",
        "deception_offence_remains_under_section_24a",
        "penalties_subsection_2",
        "commencement_2022_06_28",
        "linkage_with_modern_slavery_and_refugee_convention_defences"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-immigration-act-1971-section-3-general-provisions-regulation-control"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-nationality-borders-act-2022",
    "title": "UK Nationality and Borders Act 2022 - Differential Treatment of Asylum Claims, Modern Slavery Provisions and Rwanda Partnership",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Nationality and Borders Act 2022 (c.36), royal assent 28 April 2022, was the principal UK statute reshaping the post-Brexit asylum and immigration system. The Act amends the Immigration Act 1971, the British Nationality Act 1981, the Asylum and Immigration Appeals Act 1993, the Immigration and Asylum Act 1999, and the Nationality, Immigration and Asylum Act 2002 among others. Part 1 (sections 1-6) addresses British nationality including registration as British citizen for stateless children and adults connected to UK overseas territories. Part 2 (sections 7-39) reforms asylum: section 12 differentially treats asylum claims based on mode of arrival (Group 1 - arrived directly with permission - vs Group 2 - arrived indirectly or without permission); section 16 introduces inadmissibility criteria for safe third country processing; section 32 modifies appeal rights including accelerated detained appeals. Part 4 (sections 58-69) reforms modern slavery provisions including changes to the National Referral Mechanism and public order disqualification under section 63. Part 5 (sections 70-79) addresses age assessments for unaccompanied asylum-seeking children. The Migration and Economic Development Partnership with Rwanda announced 14 April 2022 was implemented under the Act and subsequent Illegal Migration Act 2023; the Supreme Court found the Rwanda scheme unlawful in R (AAA) v SSHD [2023] UKSC 42 leading to the Safety of Rwanda (Asylum and Immigration) Act 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-immigration-act-1971-ukvi-home-office",
      "un-refugee-convention-1951-protocol-1967-non-refoulement"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-nationality-immigration-and-asylum-act-2002",
    "title": "UK Nationality, Immigration and Asylum Act 2002: Deprivation of Citizenship, Asylum Support, Removal and the Tribunal Appeal Right",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Nationality, Immigration and Asylum Act 2002 is a principal framework for United Kingdom nationality deprivation, asylum support, removal and immigration appeals, administered by the Home Office and the First-tier and Upper Tribunals. Part 1 deals with nationality: section 4 provides for deprivation of citizenship where the Secretary of State is satisfied that deprivation is conducive to the public good or that status was obtained by fraud. Part 3 governs other support and assistance: section 43 sets the form of asylum-seeker support, section 55 allows refusal of support for a late claim for asylum, and section 58 provides for assistance with voluntary departure from the United Kingdom. Part 4 governs detention and removal: section 72 addresses the serious criminal and the presumption against protection, section 78A restricts the removal of children and their parents, and section 80 provides for removal of an asylum-seeker to a safe third country. Part 4A treats certain asylum and human-rights claims as inadmissible, including section 80A on claims by nationals of listed safe States and section 80B on claims by persons with a connection to a safe third State. Part 5 governs appeals in respect of protection and human-rights claims: section 82 confers the right of appeal to the Tribunal, section 84 sets the grounds of appeal, and section 94 allows certification of a claim as clearly unfounded. Part 5A directs the Tribunal's approach to Article 8 of the European Convention on Human Rights: section 117A applies the Part, section 117B sets public-interest considerations applicable in all cases, and section 117C sets additional considerations for foreign criminals. The Act is the legal backbone of citizenship deprivation, asylum support and the modern immigration appeal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-natural-environment-rural-communities-2006",
    "title": "UK Natural Environment and Rural Communities Act 2006",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The UK Natural Environment and Rural Communities Act 2006 (NERC Act) restructured natural environment governance in England by establishing Natural England (combining English Nature Countryside Agency and Rural Development Service) and the Commission for Rural Communities. Section 40 places a duty on public bodies in England to have regard to the purpose of conserving biodiversity in the exercise of their functions (the Section 40 biodiversity duty). The Environment Act 2021 enhanced this with the Section 102 strengthened biodiversity duty effective 1 January 2023 requiring public authorities to also act to further the conservation and enhancement of biodiversity. Lists of habitats and species of principal importance under Section 41 (England) and Section 42 (Wales) inform the duty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-natural-environment-rural-communities-act-2006",
    "title": "UK Natural Environment and Rural Communities Act 2006: Natural England, the Biodiversity Duty and SSSIs",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Natural Environment and Rural Communities Act 2006 (the NERC Act) reorganises England's nature-conservation bodies and imposes a statutory biodiversity duty on public authorities. Part 1 establishes Natural England: section 1 constitutes Natural England as a body corporate, and section 2 sets its general purpose of ensuring that the natural environment is conserved, enhanced and managed for the benefit of present and future generations, contributing to sustainable development. Part 1 Chapter 2 originally established the Commission for Rural Communities (section 17 constitution and section 18 general purpose) to give voice to rural needs, a body since wound up with its functions transferred. Part 3 contains the wildlife and biodiversity provisions: section 40 imposes the biodiversity duty, requiring every public authority, in exercising its functions, to have regard, so far as is consistent with the proper exercise of those functions, to the purpose of conserving biodiversity, a duty strengthened by later amendment to require authorities to determine and take action and to conserve and enhance biodiversity; section 40A requires biodiversity reports; and sections 41 and 42 provide for lists of species and habitats of principal importance for the conservation of biodiversity in England and Wales respectively. Part 4 deals with Sites of Special Scientific Interest, including section 55 offences in relation to SSSIs. The Act is the legal foundation for Natural England's regulatory and advisory role and for the biodiversity duty that now runs through the decision-making of every public authority in England.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-ncsc-cloud-security-principles-2023",
    "title": "UK NCSC 14 Cloud Security Principles 2023 - Guidance for Cloud Consumers: Data in Transit Protection, Asset Protection, Separation Between Customers, Governance Framework, Operational Security, Personnel Security, Secure Development, Supply Chain Security and Identity/Authentication",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This guidance outlines 14 security principles that cloud service providers should meet to ensure secure delivery of cloud platforms and Software-as-a-Service. It applies to organisations evaluating cloud providers for use of services involving sensitive or regulated data, with key requirements including Principle 1: Data in transit protection and Principle 10: Identity and authentication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csa-ccm-v4-cloud-controls",
      "cobit-2019-governance-framework",
      "enisa-cloud-security-guidelines-2023",
      "eu-gdpr-cloud-data-processing",
      "cisa-cross-sector-cybersecurity-goals"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-ncsc-cyber-essentials-2023",
    "title": "UK NCSC Cyber Essentials Scheme - Five Technical Controls and Certification Requirements (2023)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-04-24",
    "bluf": "The UK NCSC Cyber Essentials scheme requires organizations to implement five fundamental technical security controls to protect against common cyber threats as a prerequisite for certification. As outlined in the 'Cyber Essentials Requirements for IT infrastructure', these controls cover firewalls, secure configuration, user access control, malware protection, and security update management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cis-controls-v8",
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0",
      "cyber-nist-800-53-ac2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-ncsc-pqc-migration-timelines-2025",
    "title": "NCSC Timelines for Migration to Post-Quantum Cryptography (United Kingdom)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2025-03-20",
    "bluf": "The UK National Cyber Security Centre published Timelines for migration to post-quantum cryptography on 20 March 2025, setting three national target dates for the move away from quantum-vulnerable public key cryptography. By 2028 organisations are expected to define their migration goals, carry out a full discovery exercise and build an initial plan for migration. By 2031 they are expected to carry out their early, highest-priority PQC migration activities and refine the plan into a thorough roadmap for completing migration. By 2035 the expectation is to complete migration to PQC of all systems, services and products.\n\nThe guidance is aimed primarily at technical decision-makers and risk owners of large organisations, operators of critical national infrastructure systems including industrial control systems, and companies that operate bespoke IT. The NCSC notes that smaller enterprises running standard commodity IT should experience a more seamless migration as vendors update their services, while those running specialised software follow the same timeline as larger organisations. The dates are stated as NCSC target dates for a national migration effort. They are not, in themselves, a statutory deadline for every commercial organisation, though they form the technical baseline that competent authorities reference for operators of essential services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-203-ml-kem-standard",
      "fips-204-ml-dsa-standard",
      "nist-ir-8547-pqc-transition",
      "ietf-rfc-9794-pq-traditional-hybrid-terminology"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-network-information-systems-regulations-2018",
    "title": "The Network and Information Systems Regulations 2018",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Network and Information Systems Regulations 2018 impose security and incident reporting obligations on Operators of Essential Services (OES) and relevant Digital Service Providers (DSPs) to ensure the resilience of network and information systems. Key requirements are established under Section 10 (security duties) and Section 11 (duty to notify incidents).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-800-53-ac2",
      "aicpa-soc2-cc-availability",
      "nist-800-53-sc7",
      "australia-essential-eight-2023",
      "c-scrm-practices-systems-organizations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-network-information-systems-regulations-2018-regulation-10-security-measures",
    "title": "The Network and Information Systems Regulations 2018, Regulation 10: The security duties of operators of essential services",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Operators of Essential Services (OES) must implement appropriate technical and organizational measures to manage security risks, prevent and minimize the impact of incidents, and ensure service continuity, taking into account the state of the art and guidance from competent authorities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-nicaragua-sanctions-eu-exit-regulations-2020-si-610",
    "title": "UK Nicaragua (Sanctions) (EU Exit) Regulations 2020 SI 2020/610 Asset Freeze Immigration Sanctions and Treasury Licensing Framework",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Nicaragua (Sanctions) (EU Exit) Regulations 2020 establish the United Kingdom's autonomous sanctions framework targeting Nicaraguan officials and connected persons responsible for serious human rights violations and the repression of civil society, organised in 8 parts covering general provisions and the regulation 4 purposes statement in Part 1, designation power and criteria with notification requirements in Part 2, financial sanctions including the regulation 11 asset freeze and prohibitions on making funds or economic resources available to designated persons in Part 3, immigration restrictions on designated persons in Part 4, Treasury licensing for Schedule 2 purposes including basic needs and legal services in Part 5, information reporting obligations for relevant firms with information request powers in Part 6, criminal enforcement penalties officer liability and jurisdiction in Part 7, and transitional arrangements and revocations in Part 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-nis-regulations-2018",
    "title": "UK Network and Information Systems (NIS) Regulations 2018",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Network and Information Systems (NIS) Regulations 2018 (SI 2018/506) implement EU Directive 2016/1148 in the UK, requiring operators of essential services and relevant digital service providers to implement appropriate and proportionate security measures, report significant cyber incidents to their competent authority and NCSC within 72 hours, and maintain documented security policies, with enforcement fines up to GBP 17 million for serious violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/uk-nis-regulations-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-retained-gdpr",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-nis-regulations-2018-uk-nis-implementing",
    "title": "The Network and Information Systems Regulations 2018",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This regulation requires operators of essential services and relevant digital service providers to implement appropriate security measures for their network and information systems and to notify serious incidents to the relevant competent authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-nsia-2021",
    "title": "UK National Security and Investment Act 2021 - Mandatory Notification and Screening for Sensitive Sectors",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The UK National Security and Investment Act 2021 requires mandatory notification to the UK Government's Investment Security Unit for certain acquisitions of entities active in 17 sensitive areas of the economy. As per Section 6, these 'notifiable acquisitions' must be approved before completion to avoid being legally void and incurring civil or criminal penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-strategic-export-control",
      "quantum-readiness-checklist",
      "dfars-7012-defense-cyber",
      "itar-compliance-workflow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-nuclear-installations-act-1965",
    "title": "UK Nuclear Installations Act 1965: Site Licensing, Operator Strict Liability and Compensation Cover",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Nuclear Installations Act 1965 is the principal UK statute governing the licensing of nuclear sites and the civil liability regime for nuclear damage, with licensing and safety regulated by the Office for Nuclear Regulation. Section 1 restricts the use of a site for the installation or operation of a nuclear reactor or other prescribed installation to a person who holds a nuclear site licence. Section 3 governs the grant and variation of nuclear site licences, section 4 the attachment of conditions to licences, and section 5 the revocation and surrender of licences. Section 7 imposes the central duty of the licensee of a licensed site: a strict-liability duty to secure that no occurrence involving nuclear matter on the site, and no ionising radiation from the site, causes injury to any person or damage to property, with liability arising without proof of fault. Section 16 limits the amount of compensation for which the operator is liable for claims arising under sections 7 to 10, reflecting the channelling of liability to the operator under the international nuclear-liability conventions. Section 19 requires the licensee or operator to maintain cover, by insurance or other means, for its liability. The Act, as amended to reflect the Paris and Brussels Conventions, is the legal foundation of UK nuclear-site licensing and the channelled, capped, strict-liability nuclear-damage regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-obscene-publications-act-1959",
    "title": "UK Obscene Publications Act 1959 (c. 66) - Test of Obscenity and Prohibition of Publication",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "The UK Obscene Publications Act 1959 (7 & 8 Eliz. 2, c. 66), as amended by the Obscene Publications Act 1964 and subsequent statutes, establishes the foundational test of obscenity in England, Wales, and Northern Ireland: Section 1(1) defines an article as obscene if 'its effect or (where the article comprises two or more distinct items) the effect of any one of its items is, if taken as a whole, such as to tend to deprave and corrupt persons who are likely, having regard to all relevant circumstances, to read, see or hear the matter contained or embodied in it' - the Hicklin/Cockburn 'deprave and corrupt' standard with the Lord Reid refinement that the audience is the actual likely audience, not a hypothetical reader; Section 2 prohibits publishing obscene articles for gain or possessing them for publication for gain, with penalties up to 6 months summary or 5 years on indictment (extended from original 3-year maximum by Criminal Justice and Public Order Act 1994); Section 3 establishes magistrates' search warrants and forfeiture procedures; Section 4 provides the 'public good' defense permitting publication justified in the interests of science, literature, art or learning, or other objects of general concern, with expert evidence admissible; the Act covers written, audio, film, video, and electronically stored data (extended to electronic data by Criminal Justice and Public Order Act 1994 section 168 and Schedule 9); it remains a primary mechanism for prosecuting extreme pornography and obscene material alongside the Criminal Justice and Immigration Act 2008 sections 63-67 extreme pornography offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "amending_statutes",
        "extreme_pornography_companion",
        "leading_case_law",
        "industry_mapping",
        "enforcement_anchors",
        "section_4_public_good_defense"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-part-5-pornographic-content-duties",
      "uk-indecent-displays-control-act-1981",
      "uk-si-2020-1062-vsp-regime-communications-act"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-ofcom-highly-effective-age-assurance-guidance-2025-osa-part-5",
    "title": "UK Ofcom Highly Effective Age Assurance Guidance 2025 (Online Safety Act 2023 Part 5 Section 81 Duty; Four Criteria - Technical Accuracy, Robustness, Reliability, Fairness; Compliance Deadlines 17 January 2025 Part 5 / 25 July 2025 Part 3)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Ofcom (Office of Communications) published the Guidance on highly effective age assurance and other Part 5 duties on 16 January 2025 implementing the Online Safety Act 2023 Part 5 statutory duty to use highly effective age assurance on services providing regulated provider pornographic content. The statutory phrase highly effective is set in OSA 2023 Part 5 section 81(3) which requires that age verification or age estimation be of such a kind and used in such a way that it is highly effective at correctly determining whether or not a particular user is a child. Ofcom guidance sets four criteria for assessing whether an age assurance method is highly effective: technical accuracy (the method correctly determines age within a stated confidence band on the underlying population); robustness (the method resists circumvention by users determined to bypass it including spoofing, identity theft, shared credentials); reliability (the method works consistently across the user population over time); fairness (the method does not disproportionately misclassify protected groups or specific demographics). Ofcom considers seven methods capable of being highly effective: open banking, photo-ID matching, facial age estimation, mobile network operator (MNO) age checks, credit card checks, digital identity services, and email-based age estimation. Ofcom explicitly states that simple self-declaration of age and payment methods that do not require age 18 (debit cards, online wallets without age binding) are not highly effective. The Part 5 duty for services publishing their own pornographic content took effect on 17 January 2025 (one day after the guidance was published). User-to-user and search services that may be accessed by children under Part 3 must complete a children's risk assessment by 24 July 2025 and take action from 25 July 2025; the Ofcom Highly Effective standard applies to both Part 3 and Part 5 services. Ofcom enforcement powers include fines of up to 18 million pounds or 10 percent of qualifying global revenue (whichever is higher) per section 144 OSA 2023, business disruption measures including service restriction orders and access restriction orders per sections 144-150, and senior manager liability for relevant offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "framework_basis",
        "key_institutions",
        "osa_2023_section_79_definition",
        "osa_2023_section_80_scope",
        "osa_2023_section_81_duty",
        "osa_2023_section_82_ofcom_guidance_power",
        "ofcom_four_highly_effective_criteria",
        "ofcom_methods_capable_of_highly_effective",
        "ofcom_methods_not_highly_effective",
        "part_3_versus_part_5_compliance_dates",
        "ofcom_enforcement_powers",
        "interaction_with_data_protection_law",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-ofcom-illegal-content-duty",
      "uk-online-safety-act-2023-ofcom-illegal-harmful-content",
      "fr-loi-sren-2024-449-age-verification-pornography",
      "us-take-it-down-act-2025",
      "payment-processing-restricted-content-visa-virp-mastercard-an-5196"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-ofcom-osa-illegal-content-codes-of-practice-2024",
    "title": "UK Ofcom Online Safety Act 2023 Illegal Content Codes of Practice 2024 - Risk Assessment Duty by 16 March 2025 and Enforcement from 17 March 2025",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "In-scope user-to-user service providers and search service providers under the UK Online Safety Act 2023 must, following Ofcom's publication of the Illegal Content Codes of Practice and risk assessment guidance on 16 December 2024 (laid before Parliament the same day and approved), complete an illegal content risk assessment by 16 March 2025 and have illegal content duties in effect with Ofcom enforcement powers active from 17 March 2025, with platforms required to protect users from illegal content online, with Ofcom planning consultation in spring 2025 on additional measures including how automated tools can proactively detect illegal content including the content most harmful to children.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-section-66-csea-reporting-nca"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "uk-ofgem-supply-licence-conditions-2024",
    "title": "UK Ofgem Gas and Electricity Supply Licence Conditions 2024 - Price Cap Compliance, Vulnerability Obligations, Metering Standards and Switching Rules",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation mandates that UK-licensed gas and electricity suppliers comply with the energy price cap for default tariffs (SLC 22), identify and provide appropriate support to vulnerable customers (SLC 0 and 25B), ensure accurate metering and billing (SLC 12), and facilitate efficient and reliable customer switching processes (SLC 14A).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-online-safety-act-2023",
    "title": "Online Safety Act 2023",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The UK Online Safety Act 2023 imposes a statutory duty of care on providers of user-to-user services and search services to protect users from illegal and harmful content. This includes conducting comprehensive risk assessments for illegal content (Part 3, Section 7) and content harmful to children (Part 3, Section 10), and implementing proportionate systems and processes, including algorithmic content moderation, to mitigate identified risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "nist-sp-1270-managing-ai-bias",
      "un-guiding-principles-business-hr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-online-safety-act-2023-content-regulation",
    "title": "Online Safety Act 2023 - Regulation of User-Generated Content Services and Safety Duties for Providers",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Online Safety Act 2023 imposes mandatory safety duties on providers of user-generated content (UGC) services in the UK to prevent and mitigate the spread of priority illegal content, including terrorism and child sexual exploitation. These duties are enforced by Ofcom under Sections 4, 5, 6, and 75 of the Act, requiring risk assessments, proportionate systems and processes, and age assurance measures for services likely to be accessed by children.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-copyright-directive-art-17",
      "dmca-safe-harbor",
      "iptc-photo-metadata",
      "iptc-video-metadata",
      "c2pa-content-provenance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-online-safety-act-2023-network-duties",
    "title": "Online Safety Act 2023 - Duties for Category 1 and 2 Services regarding Illegal Content and Safety by Design",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK Online Safety Act 2023 imposes legally binding duties on providers of user-to-user services (categorised as 1 or 2A/2B) and search services to conduct comprehensive illegal content risk assessments and implement proportionate systems and processes to mitigate and manage identified risks, as mandated by Part 3 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-23894-ai-risk-management",
      "us-sec-cybersecurity-disclosure-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-online-safety-act-2023-ofcom-illegal-content-duty",
    "title": "UK Online Safety Act 2023 - Ofcom Regulation of User-to-User Services and Search Engines: Illegal Content and Child Safety Duties",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The Online Safety Act 2023 (c. 50) places statutory safety duties on UK-accessible user-to-user services and search engines. Services must take proportionate measures to prevent and minimise illegal content (Priority Illegal Content in Schedule 7), protect children from harmful content, and the largest Category 1 services must also protect adult users. Ofcom enforces; fines up to 10% of qualifying worldwide revenue or GBP 18M (higher of the two).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-online-safety-act-2023-ofcom-illegal-harmful-content",
    "title": "UK Online Safety Act 2023 - Ofcom Illegal Harms & Children's Safety Duties",
    "domain": "Creative, Content & Media IP",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "UK Online Safety Act 2023 imposes safety duties on user-to-user services and search engines to identify, mitigate, and manage risks of illegal content and harms to children - enforced by Ofcom with fines up to 10% of global revenue or GBP 18 million and senior manager criminal liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-online-safety-act-2023-part-3-illegal-content-children-duties",
    "title": "UK Online Safety Act 2023 Part 3 - Illegal Content Risk Assessment, Safety Duties, and Children's Protection Duties (Sections 9-12)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Online Safety Act 2023 (c.50) Part 3 imposes duties of care on providers of regulated user-to-user services and regulated search services with respect to illegal content and content harmful to children: section 9 requires providers to carry out a suitable and sufficient illegal content risk assessment that evaluates the user base, the risk of users encountering each kind of priority illegal content, the risk of the service being used for the commission or facilitation of priority offences, the severity of harms, the functionalities of the service that affect risk, and the policies and processes addressing risk; section 10 imposes the illegal content safety duties requiring proportionate measures to prevent users encountering priority illegal content, mitigate risk of service misuse for criminal offences, operate systems to minimise the time illegal content is present, and swiftly remove illegal content on notice (with separate terms-of-service protections for terrorism content, child sexual exploitation and abuse content, and other priority offences); sections 11-12 impose parallel children's risk assessment and children's safety duties on providers whose services are likely to be accessed by children, including the requirement to prevent children from encountering primary priority content harmful to children through age verification or age estimation. OFCOM enforces compliance through information notices, confirmation decisions, fines up to GBP 18 million or 10 percent of global qualifying revenue, business disruption measures, and criminal liability for senior managers in specified circumstances.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "duty_taxonomy",
        "priority_illegal_content_anchor",
        "primary_priority_content_harmful_to_children",
        "industry_mapping",
        "enforcement_anchors",
        "code_of_practice_basis"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-part-5-pornographic-content-duties",
      "uk-si-2020-1062-vsp-regime-communications-act",
      "au-online-safety-act-2021-removal-notice-scheme"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-online-safety-act-2023-part-5-pornographic-content-duties",
    "title": "UK Online Safety Act 2023 Part 5 - Duties on Internet Services Publishing Pornographic Content",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "Part 5 of the UK Online Safety Act 2023 imposes a standalone regulatory regime on internet services that publish or display regulated provider pornographic content. Section 80 establishes scope: any in-scope service with a significant number of UK users or where UK users form one of the target markets must comply, regardless of whether the service is a user-to-user service or search service governed by Parts 3 and 4. Section 81 imposes the central duty - providers must ensure children are not normally able to encounter regulated provider pornographic content, using age verification or age estimation that is highly effective at correctly determining whether a particular user is a child, and must keep a written record of the kinds of age verification or estimation used and how. Section 82 requires OFCOM to publish guidance including examples of kinds and uses of age verification and age estimation that are highly effective; the guidance addresses ease of use and effectiveness for all users. Enforcement, civil penalties (up to GBP 18m or 10% of qualifying worldwide revenue), and service-restriction orders flow through Parts 7 and 10 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "part_3_user_to_user_overlap",
        "ofcom_guidance_section_82",
        "enforcement_anchors",
        "dpa_2018_overlap",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-online-safety-act-2023-section-10-illegal-content-safety-duties",
    "title": "UK Online Safety Act 2023 Section 10 - Illegal Content Safety Duties of User-to-User Services (Proportionate Measures, Swift Removal, Terms of Service Disclosure, Proactive Technology)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 10 of the Online Safety Act 2023 (c. 50) imposes the primary illegal content safety duty on user-to-user services - the downstream operational compliance obligation built upon the section 9 illegal content risk assessment. Section 10(2) requires providers to use proportionate measures relating to the design and operation of the service to (a) prevent individuals from encountering priority illegal content by means of the service, (b) effectively mitigate and manage the risks of harm to individuals (as identified in the most recent illegal content risk assessment) from illegal content present on the service, and (c) effectively mitigate and manage the risks of the service being used for the commission or facilitation of priority offences. Section 10(3) requires providers to operate systems and processes designed to minimise the length of time for which priority illegal content is present and, where the provider becomes aware of any illegal content, swiftly take it down. Section 10(4) extends the duty across design, operation, terms of service, content policies, user reporting, complaints, user controls, support measures, and staff policies. Section 10(5) requires terms of service to include provisions about how individuals are protected, separately covering terrorism content, CSEA content, and other priority illegal content. Section 10(7) requires disclosure of proactive technology used. Penalties under sections 136-138: greater of GBP 18 million or 10% of qualifying worldwide revenue.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_10_text",
        "proportionate_measures_test_section_10_10_factors",
        "swift_takedown_test_section_10_3_b",
        "terms_of_service_separately_covering_terrorism_csea_other_section_10_5",
        "proactive_technology_disclosure_section_10_7",
        "category_1_designation_section_10_9_and_schedule_11",
        "ofcom_illegal_content_code_of_practice_december_2024",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023",
      "uk-online-safety-act-2023-section-9-illegal-content-risk-assessment-duties"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-online-safety-act-2023-section-11-childrens-risk-assessment",
    "title": "UK Online Safety Act 2023 Section 11 - Children's Risk Assessment Duties (User-to-User Services)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Providers of regulated user-to-user services that are likely to be accessed by children must carry out suitable and sufficient children's risk assessments at the times specified in Schedule 3 (initial, when Ofcom updates risk profiles, and before significant service changes). The assessment must cover the user base including child numbers by age group, the risks of children encountering primary priority, priority, and non-designated content that is harmful to children, the severity of harm by content type and demographic, design features that create risk (especially adult-to-child contact functionalities), usage patterns, and the impact of design, governance, technology, and media literacy on the identified risks. Providers must notify Ofcom of non-designated harmful content types and incidence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "scope_user_to_user_services_likely_accessed_by_children",
        "duty_to_carry_out_suitable_and_sufficient_assessment",
        "schedule_3_timing",
        "six_required_assessment_components",
        "non_designated_content_notification_to_ofcom",
        "primary_priority_priority_and_non_designated_content_definitions",
        "interaction_with_section_12_safety_duties_protecting_children",
        "enforcement_via_ofcom_sections_130_to_146"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-part-3-illegal-content-children-duties",
      "uk-online-safety-act-2023-part-5-pornographic-content-duties"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-online-safety-act-2023-section-12-childrens-safety-duties",
    "title": "UK Online Safety Act 2023 Section 12 - Children's Safety Duties (Proportionate Measures, Primary Priority Content Encounter Prevention, Highly Effective Age Verification or Estimation)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 12 of the Online Safety Act 2023 (c. 50) imposes the foundational children's safety duty on user-to-user services likely to be accessed by children - the downstream operational compliance obligation that follows from the section 11 children's risk assessment. Section 12(2) requires proportionate measures relating to the design or operation of the service to mitigate and manage risks of harm to children and effectively manage harm impact across different age groups. Section 12(3) requires proportionate systems and processes designed (a) to prevent children of any age from encountering primary priority content that is harmful to children, and (b) to protect children in age groups judged to be at risk of harm from other content that is harmful to children. Section 12(4) requires that preventing children from encountering primary priority content (a) is achieved by use of age verification or age estimation (or both). Section 12(6) imposes the 'highly effective' standard - the age verification or age estimation must be highly effective at correctly determining whether or not a particular user is a child. Section 12(5) creates exemption for terms of service prohibiting the content for all users. Section 12(9) requires terms of service provisions detailing protection mechanisms for each harmful content category. Section 12(14) imposes additional duty on Category 1 services to summarise children's risk assessment findings in terms. Penalties under sections 136-138 reach the greater of GBP 18 million or 10% of qualifying worldwide revenue.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_12_text",
        "primary_priority_content_definition_section_35_schedule_6",
        "highly_effective_standard_section_12_6_ofcom_calibration",
        "priority_content_definition_section_36_schedule_5_age_group_protection",
        "proportionate_systems_and_processes_section_12_2_3",
        "category_1_2a_2b_designations_additional_duties",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023",
      "uk-online-safety-act-2023-section-9-illegal-content-risk-assessment-duties",
      "uk-online-safety-act-2023-section-10-illegal-content-safety-duties",
      "uk-online-safety-act-2023-section-11-childrens-risk-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-online-safety-act-2023-section-12-risk-assessment-duties-services",
    "title": "Online Safety Act 2023 Section 12: Safety duties protecting children",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Providers of regulated user-to-user services likely to be accessed by children must implement proportionate measures to mitigate risks of harm, prevent children from encountering harmful content, and use age verification or estimation for primary priority harmful content.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-online-safety-act-2023-section-122-notice-to-deal-with-terrorism",
    "title": "Online Safety Act 2023 Section 122: Requirement to obtain skilled person’s report",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must understand that the UK regulator, OFCOM, is required to obtain a report from an appointed skilled person before it can issue a notice to a provider under Section 121(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-online-safety-act-2023-section-179-ofcom-enforcement-notifications",
    "title": "Online Safety Act 2023, Section 179: False communications offence",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This section establishes a criminal offense for a person who sends a message containing information they know to be false, with the intent to cause non-trivial psychological or physical harm to a likely audience, and who has no reasonable excuse for sending it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-online-safety-act-2023-section-189-ofcom-codes",
    "title": "Online Safety Act 2023, Section 189: Repeals in connection with offences under sections 179 and 181",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This section repeals specific provisions concerning false and malicious communications within the Communications Act 2003, the Malicious Communications Act 1988, and the Malicious Communications (Northern Ireland) Order 1988, requiring organizations to update their legal and compliance frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-online-safety-act-2023-section-20-content-reporting-duty",
    "title": "UK Online Safety Act 2023 Section 20 - Duty about Content Reporting (All Services Illegal Content, Children-Accessible Services Content Harmful to Children, Affected Person Definition, Age Verification Exception, Section 22 Cross-Reference)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 20 of the Online Safety Act 2023 (c. 50) imposes a content reporting duty on all providers of regulated user-to-user services. Under section 20(2), the provider must operate systems and processes that allow users and affected persons to easily report content that they consider problematic, with reporting categories varying by service type. Under section 20(3), all services must enable reporting of illegal content. Under section 20(4), services likely to be accessed by children must additionally enable reporting of content that is harmful to children present on a part of the service that it is possible for children to access. Under section 20(5), an 'affected person' is a person in the UK who is the subject of the content, a member of a group targeted by the content, a parent or guardian of a child user, or an adult assisting another adult user to use the service. Under section 20(6), a provider may only conclude that children cannot access a service if age verification or age estimation is used preventing normal child access. Section 20(7) cross-references the section 22 freedom of expression and privacy duties and the section 72(5)(a) duty to enable reporting of content that violates terms of service. The reporting duty is the user-side counterpart to the section 10 (illegal content) and section 12 (children's safety) duties and feeds the content moderation pipeline that ultimately drives takedown, account actions, section 66 NCA CSEA reports, and other downstream obligations. Enforcement is by Ofcom under sections 130, 96, 143 and Schedule 13 with civil penalties up to GBP 18 million or 10% qualifying worldwide revenue; section 238 senior manager criminal liability applies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_20_text_subsections",
        "affected_person_definition_section_20_5",
        "child_access_assessment_section_31_link",
        "downstream_pipeline_to_section_10_36_66_takedown",
        "section_72_5_a_terms_of_service_reporting",
        "enforcement_taxonomy",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-section-12-risk-assessment-duties-services",
      "uk-online-safety-act-2023-section-34-safety-duties",
      "uk-online-safety-act-2023-section-189-ofcom-codes",
      "uk-online-safety-act-2023-section-238-senior-manager-liability"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-online-safety-act-2023-section-238-senior-manager-liability",
    "title": "Online Safety Act 2023 Section 238: Financial provisions",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This section mandates that any expenditure incurred by the Secretary of State under the Online Safety Act 2023, and any resulting increase in sums payable under other Acts, must be paid out of money provided by Parliament.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-online-safety-act-2023-section-34-safety-duties",
    "title": "Online Safety Act 2023, Section 34: Record-keeping and review duties",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Regulated search services must create and maintain detailed records of risk assessments and compliance measures, and regularly review their compliance with safety duties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-online-safety-act-2023-section-36-safety-duties-priority-content",
    "title": "Online Safety Act 2023 Section 36: Duties about children’s access assessments",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Providers of Part 3 services must conduct, document, and regularly update children's access assessments for each service to evaluate the risk of children accessing it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-online-safety-act-2023-section-56-children-safety-duties",
    "title": "Online Safety Act 2023, Section 56: “Recognised news publisher”",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This section defines the criteria an entity must meet to be classified as a 'recognised news publisher', including requirements for editorial control, complaints procedures, and public disclosure of business details.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-online-safety-act-2023-section-64-user-identity-verification",
    "title": "UK Online Safety Act 2023 Section 64 - User Identity Verification (Category 1 Service Duty, Optional Verification for All Adult Users, Any Process Acceptable, Terms of Service Explanation, UK Adult User Scope)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 64 of the Online Safety Act 2023 (c. 50) imposes a user identity verification duty on providers of Category 1 services (designated under section 95). Under section 64(1), a provider of a Category 1 service must offer all adult users of the service the option to verify their identity (if identity verification is not required for access to the service). Under section 64(2), the verification process may be of any kind and in particular need not require documentation to be provided - the duty is to offer verification, not to require documents. Under section 64(3), the provider must include clear and accessible provisions in the terms of service explaining how the verification process works. Under section 64(4), if a person is the provider of more than one Category 1 service, the duties apply in relation to each such service. Under section 64(5), the duty applies in relation to all adult users, not just those who begin to use a service after the duty begins to apply - it applies retrospectively to the existing adult user base. Under section 64(6), the duties extend only to the user-to-user part of a service and to the design, operation, and use of a service in the United Kingdom. Under section 64(7), 'adult user' means an adult in the UK who is a user of the service or seeks to begin to use the service (for example by setting up an account). Section 64(8) refers to section 95 for the meaning of Category 1 service. Section 65 imposes the parallel duty on Ofcom to publish guidance on user identity verification. The identity verification mechanism interacts with section 65 (Ofcom guidance), section 67 (non-verified user duty - the duty to give users an option to filter out non-verified users), and the wider section 71 (terms of service) and section 22 (freedom of expression and privacy) regimes. Enforcement is by Ofcom under sections 130, 96, 143 and Schedule 13; senior manager criminal liability under section 238 applies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_64_text_subsections",
        "category_1_service_section_95_designation",
        "verification_process_flexibility_section_64_2",
        "retrospective_application_section_64_5",
        "section_67_non_verified_user_filtering_link",
        "section_65_ofcom_guidance_link",
        "data_protection_overlay_uk_gdpr",
        "enforcement_taxonomy",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-section-238-senior-manager-liability",
      "uk-online-safety-act-2023-section-189-ofcom-codes",
      "uk-data-protection-act-2018",
      "uk-ofcom-highly-effective-age-assurance-guidance-2025-osa-part-5"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-online-safety-act-2023-section-66-csea-reporting-nca",
    "title": "UK Online Safety Act 2023 Section 66 - Mandatory CSEA Content Reporting to the NCA (UK Providers Full Reporting, Non-UK Providers UK-Linked Content Only, Search Service Coverage, Section 70 Definitions)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 66 of the Online Safety Act 2023 (c. 50) creates a statutory CSEA (Child Sexual Exploitation and Abuse) reporting duty under which providers of regulated user-to-user services, search services, and combined services must operate systems and processes which secure (so far as possible) reporting of detected CSEA content to the National Crime Agency (NCA). Under section 66(1), United Kingdom providers of regulated user-to-user services must report all detected CSEA content to the NCA. Under section 66(2), non-United Kingdom providers of regulated user-to-user services must report detected and unreported UK-linked CSEA content to the NCA. Under section 66(3), United Kingdom providers of search services must report all detected CSEA content from searchable websites or databases. Under section 66(4), non-United Kingdom providers of search services report only UK-linked CSEA content from searchable websites or databases. Sections 66(5) and 66(6) extend the regime to UK and non-UK providers of combined services in respect of the search engine component. Section 66(7) sets out that reports must be made in the manner and within the timeframes set out in regulations made under the Act. Section 66(8) applies the duty per service for providers operating multiple services. Section 66(9) directs to section 70 for definitions of 'CSEA content', 'UK-linked', 'detected', and related terms. Section 66(10) applies the duty only to CSEA content detected after the commencement date. The reporting duty is in addition to (and complementary with) the section 9 illegal content risk assessment duty, the section 34 safety duties, the section 36 safety duties about priority illegal content (CSEA is priority illegal content under Schedule 7), and the section 72 codes of practice. Enforcement is by Ofcom under sections 130, 96, 143 and Schedule 13 (civil penalties up to GBP 18 million or 10% qualifying worldwide revenue), section 192 (criminal liability for failure to comply with Ofcom information notice), and section 238 (senior manager criminal liability where Ofcom has served a confirmation decision related to a relevant duty).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_66_text_subsections",
        "nca_reporting_channel",
        "csea_content_definition_section_70",
        "uk_linked_test_section_70",
        "schedule_7_priority_illegal_content",
        "enforcement_taxonomy",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-section-12-risk-assessment-duties-services",
      "uk-online-safety-act-2023-section-34-safety-duties",
      "uk-online-safety-act-2023-section-36-safety-duties-priority-content",
      "uk-online-safety-act-2023-section-238-senior-manager-liability"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-online-safety-act-2023-section-7-duties-of-care",
    "title": "Online Safety Act 2023, Section 7: Providers of user-to-user services: duties of care",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This section specifies the duties of care that providers of regulated user-to-user services must comply with, establishing a baseline for all services and imposing additional duties for services likely to be accessed by children and for high-risk 'Category 1' services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-online-safety-act-2023-section-71-action-against-users-only-per-terms",
    "title": "UK Online Safety Act 2023 Section 71 - Duty Not to Act Against Users Except in Accordance with Terms of Service (Category 1 Service, Takedown/Restriction/Suspension/Ban Only Per Terms, Section 10/12 Safety Duty Exception, Criminal/Civil Liability Exception, Fraudulent Advertising Exception, Consumer Content Exclusion)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 71 of the Online Safety Act 2023 (c. 50) imposes a duty on providers of Category 1 services (designated under section 95) not to act against users except in accordance with the terms of service. Under section 71(1), a Category 1 provider must operate the service using proportionate systems and processes designed to ensure that the provider does not take down regulated user-generated content, restrict users' access to regulated user-generated content, or suspend or ban users from using the service except in accordance with the terms of service. Under section 71(2), the duty does not prevent action taken to comply with the section 10(2) or (3) illegal content safety duties, the section 12(2) or (3) children's safety duties, or to avoid criminal or civil liability that might reasonably be expected to arise (including liability under non-UK law per section 71(7)). Under section 71(3), nothing prevents takedown or restriction where a user has committed an offence in generating, uploading or sharing content on the service, or suspension/ban where the user has committed an offence or is responsible for or has facilitated a fraudulent advertisement (fraudulent advertisement defined in section 38). Under section 71(4), the duty does not apply to consumer content (see section 74) or to terms dealing with consumer content. Section 71(5) extends the duty per service for multi-Category 1 providers. Section 71(6) limits the duty to design, operation and use of a service in the UK; references to users are to UK users. Section 71(8) cross-references section 18 (duties to protect news publisher content). The duty is the foundation of the Category 1 due process regime - users cannot be acted against arbitrarily and any action must trace to a published term or one of the listed statutory exceptions. Enforcement is by Ofcom under sections 130, 96, 143 and Schedule 13; senior manager criminal liability under section 238 applies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_71_text_subsections",
        "due_process_regime_for_category_1_users",
        "consumer_content_exclusion_section_74",
        "fraudulent_advertisement_section_38_definition",
        "news_publisher_content_section_18_cross_reference",
        "section_22_freedom_of_expression_privacy_proportionality_anchor",
        "enforcement_taxonomy",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-section-238-senior-manager-liability",
      "uk-online-safety-act-2023-section-189-ofcom-codes",
      "uk-online-safety-act-2023-section-34-safety-duties",
      "uk-online-safety-act-2023-section-56-children-safety-duties"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-online-safety-act-2023-section-81-pornographic-content-duties",
    "title": "UK Online Safety Act 2023 Section 81 - Duties about Regulated Provider Pornographic Content (Part 5 Services, Highly Effective Age Verification or Age Estimation, Written Records, Public Statement, 17 January 2025 Commencement)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 81 of the Online Safety Act 2023 (c. 50) sets out the substantive duties about regulated provider pornographic content for internet services within section 80(2) (Part 5 services - providers of internet services that publish regulated provider pornographic content). Under section 81(1), the duties apply to providers of internet services within section 80(2). Under section 81(2), the provider must use age verification or age estimation (or both) to ensure that children are not normally able to encounter regulated provider pornographic content. Under section 81(3), the age verification or age estimation must be highly effective at correctly determining whether or not a particular user is a child - the operative legal standard is 'highly effective' as further elaborated by the Ofcom Highly Effective Age Assurance Guidance 2025. Under section 81(4), the provider must keep written records of the kinds of age verification or age estimation used and how they are implemented, and must have regard to matters concerning privacy that are relevant to the use or operation of a regulated service. Under section 81(5), the provider must publish a publicly available statement summarising compliance, including which kinds of age verification or age estimation are being used and how they are used. Section 81 came into force on 17 January 2025 (the same commencement as the Ofcom HEAA Guidance Part 5 compliance deadline). Sections 80-83 form the Part 5 regime that operates independently of (and in parallel with) the Part 3 regulated services regime. Enforcement is by Ofcom under sections 130, 96, 143 and Schedule 13 with civil penalties up to GBP 18 million or 10% qualifying worldwide revenue; section 192 criminal liability for failure to comply with information notices applies; section 238 senior manager criminal liability applies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_81_text_subsections",
        "highly_effective_standard_section_81_3_ofcom_heaa_guidance_2025",
        "part_5_scope_section_79_80_definitions",
        "written_records_section_81_4_privacy_obligation",
        "public_statement_section_81_5",
        "part_5_vs_part_3_distinction",
        "enforcement_taxonomy",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-ofcom-highly-effective-age-assurance-guidance-2025-osa-part-5",
      "uk-online-safety-act-2023-part-5-pornographic-content-duties",
      "uk-online-safety-act-2023-section-238-senior-manager-liability",
      "uk-data-protection-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-online-safety-act-2023-section-9-illegal-content-risk-assessment-duties",
    "title": "UK Online Safety Act 2023 Section 9 - Illegal Content Risk Assessment Duties of User-to-User Services (Suitable and Sufficient, Schedule 3 Timing, Pre-Significant-Change Assessment, Ofcom Risk Profiles)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 9 of the Online Safety Act 2023 (c. 50) imposes the foundational illegal content risk assessment duty on user-to-user services regulated under the Act - the principal upstream compliance obligation that informs all subsequent illegal content safety duties under section 10. Section 9 requires the provider of a regulated user-to-user service to carry out a suitable and sufficient illegal content risk assessment within the period specified in Schedule 3 and to keep that assessment up to date. Before making a significant change to the service, the provider must carry out a further suitable and sufficient illegal content risk assessment relating to that change. The risk assessment must assess: (a) user base characteristics, (b) risks of users encountering priority illegal content and other illegal content (taking into account algorithms and content dissemination), (c) risks of the service being used for the commission or facilitation of priority offences, (d) levels of risk of harm from each type of illegal content, (e) functionalities facilitating illegal content presence or offence commission, (f) different ways the service is used and harm implications, (g) severity of harm, and (h) potential mitigation through design, business models, governance, technology, media literacy, and operational systems. The risk profiles referenced are those published by Ofcom under section 98. Section 9 commenced 10 January 2024 and is enforced by Ofcom with penalties up to 10% of qualifying worldwide revenue or GBP 18 million whichever is greater.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_9_text",
        "suitable_and_sufficient_test_section_9_4",
        "schedule_3_timing_phased_implementation",
        "priority_offences_schedule_7",
        "section_98_ofcom_risk_profiles_anchor",
        "penalty_section_136_138_and_ofcom_enforcement_regime",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023",
      "uk-online-safety-act-2023-section-10-illegal-content-safety-duties",
      "uk-online-safety-act-2023-section-11-childrens-risk-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-online-safety-csea-content-reporting-2026-si-268",
    "title": "UK Online Safety (CSEA Content Reporting by Regulated User-to-User Service Providers) Regulations 2026, SI 2026/268 - NCA Reporting Duty",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Regulated user-to-user service providers must register with the National Crime Agency, designate an organization administrator, and report detected child sexual exploitation and abuse content with Schedule 1 information and Schedule 2 formatting, within timeframes set by priority level, retaining records for the periods set in Regulation 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-section-66-csea-reporting-nca"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-outer-space-act-1986-satellite-operator-licensing-liability",
    "title": "UK Outer Space Act 1986 and Space Industry Act 2018 - Satellite Operator Licensing and Third-Party Liability",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2021-07-29",
    "bluf": "The UK Outer Space Act 1986 and Space Industry Act 2018 require UK operators to obtain a licence from the Civil Aviation Authority (CAA) before launching or operating satellites, comply with debris mitigation and on-orbit operations standards, maintain unlimited third-party liability insurance per the 1967 Outer Space Treaty, and adhere to debris mitigation requirements under UKSA licensing conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-space-regulation-2021-696-eu-space-programme-galileo-copernicus",
      "us-fcc-part-25-satellite-earth-station-licensing-spectrum-coordination"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-outer-space-act-1986-space-industry-act-2018-caa",
    "title": "UK Outer Space Act 1986 and Space Industry Act 2018 - CAA Launch Licensing",
    "domain": "Space & Satellite Law",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Outer Space Act 1986 (c.38) and Space Industry Act 2018 (c.5) together form the UK licensing regime for space activities: the 1986 Act governs UK-established operators launching from overseas; the 2018 Act enables domestic UK launch licensing administered by the Civil Aviation Authority (CAA) with UKSA technical oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-party-wall-act-1996",
    "title": "Party Wall etc. Act 1996",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This UK Act requires a building owner to serve formal notice on adjoining owners before commencing work on a party wall, boundary, or excavations near an adjacent property. If the adjoining owner does not consent within 14 days, a dispute arises which must be resolved via a 'Party Wall Award' determined by appointed surveyors, as mandated by Sections 3, 6, and 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-pecr-2003",
    "title": "UK Privacy and Electronic Communications Regulations 2003 (PECR)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426) implement Directive 2002/58/EC in the UK, prohibiting unsolicited marketing calls and electronic messages without prior consent, requiring cookie consent on websites, mandating caller ID transparency, and applying to electronic communications service providers, with ICO enforcement and fines up to GBP 500,000 for serious violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/uk-pecr-2003.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-dpa-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-pensions-act-2008-section-3-automatic-enrolment-jobholder-duty",
    "title": "UK Pensions Act 2008 Section 3 - Automatic Enrolment of Eligible Jobholder (Age 22 to Pensionable Age, Earnings Threshold, Active Membership in Qualifying Scheme)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 3 of the Pensions Act 2008 (c. 30) establishes the foundational UK workplace pensions automatic enrolment duty - the operative employer obligation that has driven enrolment of over 10 million UK workers since staged commencement from October 2012. Under section 3(1), the section applies to a jobholder (a) who is aged at least 22, (b) who has not reached pensionable age, and (c) to whom earnings of more than GBP 10,000 are payable by the employer in the relevant pay reference period (section 15 reference). Under section 3(2), the employer must make prescribed arrangements by which the jobholder becomes an active member of an automatic enrolment scheme with effect from the automatic enrolment date. Under section 3(3), subsection (2) does not apply if the jobholder was an active member of a qualifying scheme on the automatic enrolment date. Under section 3(4), subsection (2) does not apply if, within the prescribed period before the automatic enrolment date, the jobholder ceased to be an active member of a qualifying scheme because of any action or omission by the jobholder. Section 3(5)-(6) authorise regulations for information provision and deeming agreements for personal pension schemes. Section 3(6A) cross-references the definition of 'earnings' in section 13(3). Section 3(6B) provides pro-rata adjustment for pay reference periods other than 12 months. Section 3(7) defines automatic enrolment date subject to section 4. Section 3(8) cross-references the definition of automatic enrolment scheme under section 17. Enforcement is by The Pensions Regulator with civil penalties under sections 40-44.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_3_text",
        "eligible_jobholder_three_part_test_section_3_1",
        "automatic_enrolment_date_section_3_7_and_section_4",
        "qualifying_scheme_section_3_3_active_membership_exemption",
        "section_3_4_jobholder_action_or_omission_exception_anti_avoidance",
        "contribution_levels_section_20_qualifying_earnings_band",
        "enforcement_pensions_regulator_civil_penalties_sections_40_44",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-performers-rights-cdpa-1988-part-ii",
    "title": "Copyright, Designs and Patents Act 1988, Part II: Rights in Performances",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes economic and moral rights for performers and persons with recording rights in live performances, requiring consent for exploitation under sections 181 to 184 and protection against illicit recordings under sections 198 and 201. It applies to performances occurring on or after the commencement of Part II of the CDPA 1988.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-1886-2024-literary-artistic-works",
      "eu-copyright-directive-art-17",
      "dmca-safe-harbor"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-petroleum-act-1998",
    "title": "UK Petroleum Act 1998: Crown Ownership of Petroleum, Licensing, Pipelines and Offshore Decommissioning",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Petroleum Act 1998 consolidates the core UK law on petroleum exploitation, submarine pipelines and the decommissioning of offshore installations, administered by the Secretary of State and, for offshore matters, the North Sea Transition Authority and the Offshore Petroleum Regulator for Environment and Decommissioning. Section 2 vests the rights to petroleum existing in its natural condition in strata in the Crown. Section 3 provides that the Secretary of State may grant licences to search and bore for and get petroleum, and section 4 makes further provision about such licences, including the conditions that may be attached. Part III governs submarine pipelines: section 14 controls the construction and use of pipelines and section 15 provides for authorisations. Part IV governs the abandonment of offshore installations and submarine pipelines: section 29 requires the preparation of an abandonment (decommissioning) programme, section 30 identifies the persons who may be required to submit a programme (including licensees and associated companies), section 34 deals with the revision of programmes, section 37 makes it an offence to fail without reasonable excuse to carry out an approved programme, and section 38 allows the Secretary of State to require information about, and protection of, the financial resources available to meet decommissioning liabilities. The Act is the legal foundation for UK petroleum licensing, pipeline control and the polluter-funded decommissioning of offshore oil and gas infrastructure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-planning-act-2008-development-consent-orders",
    "title": "Planning Act 2008: Development Consent Orders (DCOs) for Nationally Significant Infrastructure Projects",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK Planning Act 2008 requires promoters of Nationally Significant Infrastructure Projects (NSIPs) to obtain a Development Consent Order (DCO) before construction can begin. This single consent replaces numerous other required permissions and is granted by the relevant Secretary of State after a rigorous examination process led by the Planning Inspectorate, as mandated by Part 4, Section 31 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-planning-act-2008-nationally-significant-infrastructure",
    "title": "Planning Act 2008",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Planning Act 2008 requires developers of Nationally Significant Infrastructure Projects (NSIPs) to obtain a Development Consent Order (DCO) from the Secretary of State, as outlined in Section 114 of the Act. This applies to projects that meet certain criteria, such as those with a generating capacity of more than 50MW, as specified in Section 15 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-planning-permission-tcpa-1990",
    "title": "Town and Country Planning Act 1990 - Development Permission: Planning Applications, Conditions, Enforcement Notices, Listed Building Consent and Development Plan Policies",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Town and Country Planning Act 1990 establishes the legal framework for development control in England and Wales, requiring planning permission for most forms of development under Section 57(1), and empowering local planning authorities to enforce compliance through notices and appeals. It applies to landowners, developers, local authorities, and agents involved in physical development of land and buildings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-planning-act-2008-nationally-significant-infrastructure",
      "iso-19650-bim-information-management-construction",
      "australia-national-construction-code-2022-ncc"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-plant-health-act-1967",
    "title": "UK Plant Health Act 1967: Control of the Introduction and Spread of Plant Pests in Great Britain",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Plant Health Act 1967 is the enabling framework under which Great Britain controls the introduction and spread of plant pests, conferring order-making powers on the competent authorities to protect crops, trees and the wider environment from harmful organisms, administered by the Department for Environment, Food and Rural Affairs and the devolved administrations together with the Animal and Plant Health Agency. Section 1 sets the objects of the Act and identifies the competent authorities. Section 2 confers the power to control the introduction of pests into Great Britain, enabling orders to prevent the importation of pests. Section 3 confers the power to control the spread of pests in Great Britain, enabling orders for preventing the spread of pests already present, including provision for the destruction or treatment of crops and plants and for related measures. Section 4 provides for the execution of the Act by government departments, and section 4A provides for charges in connection with import and export licences and certificates. Section 5 provides for the execution of the Act by local authorities. Section 6 requires the publication of orders made under the Act, and section 9 contains the short title and extent. The substantive controls operate through the secondary legislation made under sections 2 and 3, which is the mechanism by which specific pests, host materials and phytosanitary requirements are regulated. The Act is the statutory foundation of the Great Britain plant-health regime and the legal basis on which import controls, inspections, plant passports and pest-eradication orders are imposed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-plant-health-act-1967-section-2-control-introduction-pests",
    "title": "UK Plant Health Act 1967 Section 2 - Control of Introduction of Pests into Great Britain",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A competent authority may make orders for preventing the introduction of pests into Great Britain. Where landing in Great Britain of plants, trees, bushes or their parts or produce is likely to introduce or spread pests, orders may prohibit or regulate the landing of such articles and authorise their destruction if landed, without affecting customs penalty or forfeiture provisions. References to landing include importation through the Channel Tunnel system as defined in the Channel Tunnel Act 1987.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "competent_authority_order_making_power",
        "landing_regulation_for_plants_and_produce",
        "customs_law_preserved",
        "channel_tunnel_importation_captured",
        "primary_secondary_legislation_route",
        "post_eu_exit_framework",
        "enforcement_seizure_and_destruction_powers"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-animal-welfare-act-2006-section-9-duty-person-responsible-ensure-welfare"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-plant-varieties-act-1997",
    "title": "UK Plant Varieties Act 1997: Plant Breeders' Rights, the DUS and Novelty Conditions, Exceptions and Compulsory Licences",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Plant Varieties Act 1997 governs the grant and protection of plant breeders' rights in the United Kingdom, the intellectual-property regime that gives the breeder of a new plant variety exclusive control over its propagating material, administered by the Plant Variety Rights Office and the Controller. Section 2 establishes the Plant Variety Rights Office and the office of Controller. Section 3 provides for the grant of plant breeders' rights on application, and section 4 sets the conditions for the grant: the variety must be distinct, uniform and stable (the DUS criteria) and must be new, with the detailed criteria set out in Schedule 2. Section 6 defines the protected variety and the acts in respect of propagating material that require the authorisation of the holder, and section 7 extends protection to dependent varieties, including essentially derived varieties. Sections 8 to 10 set out the limits on the rights: section 8 provides general exceptions (including acts done privately and for non-commercial purposes and for experimental purposes), section 9 provides the farm saved seed exception allowing farmers to use saved seed of certain species subject to remuneration, and section 10 provides for exhaustion of rights. Section 11 fixes the duration of the rights. Section 17 provides for compulsory licences in the public interest. Appeals lie to the Plant Varieties and Seeds Tribunal under section 26, and section 42 provides for the Tribunal. The Act is the legal basis of the United Kingdom plant breeders' rights system and implements the country's obligations under the UPOV Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-plant-varieties-seeds-act-1964",
    "title": "UK Plant Varieties and Seeds Act 1964 (c.14): Plant Breeders' Rights and Seeds Regulation",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Plant Varieties and Seeds Act 1964 (c. 14) establishes the regime of plant breeders' rights and the regulation of the sale of seeds in the United Kingdom, administered by the Department for Environment, Food and Rural Affairs through the Plant Variety Rights Office and the controllers of plant variety rights. Part I governs plant breeders' rights: section 1 provides for the grant of plant breeders' rights in respect of plant varieties, section 2 sets the conditions for the grant of rights, including that the variety be distinct, uniform, and stable, section 3 sets the period for which the rights are exercisable, and section 4 sets the nature of the rights, which give the holder the exclusive right to authorise the production and sale of reproductive material of the protected variety. Section 13 creates offences of false representations as to rights and the supply of false information. Part II regulates seeds: section 16 confers power to make seeds regulations governing the testing, certification, labelling, and sale of seeds, and section 17 sets the civil liabilities of sellers of seeds. Section 27 creates the offence of tampering with samples, and section 35 makes general provision as to offences under the Act. The Act is the foundational United Kingdom regime for plant variety protection and seed quality, giving domestic effect to the obligations of the International Convention for the Protection of New Varieties of Plants.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-plastic-packaging-tax-2022-finance-act",
    "title": "Plastic Packaging Tax: steps to take - HM Revenue & Customs Guidance",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Businesses that have manufactured or imported 10 or more tonnes of finished plastic packaging components in the last 12 months must register for the Plastic Packaging Tax. The tax applies at £228.82 per tonne from 1 April 2026 to plastic packaging with less than 30% recycled content, as defined in the GOV.UK guidance published 4 November 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-poca-proceeds-of-crime-act-2002",
    "title": "United Kingdom Proceeds of Crime Act 2002 (POCA): Confiscation Orders, Civil Recovery of Proceeds of Unlawful Conduct, Cash Forfeiture, Restraint Orders, Money Laundering Offences (Concealing Arrangements Acquisition Use and Possession), Failure to Disclose in Regulated Sector, Tipping Off, and Authorised Disclosures",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Proceeds of Crime Act 2002 (POCA), chapter 29 of 2002, received Royal Assent on 24 July 2002 and is the principal United Kingdom statute providing for the confiscation and civil recovery of the proceeds of crime and creating the United Kingdom anti-money laundering criminal offences, administered through the National Crime Agency, His Majesty's Revenue and Customs, the Crown Prosecution Service, and the Financial Conduct Authority. Proceeds of Crime Act 2002, section 6 governs the making of a confiscation order by the Crown Court following conviction in confiscation proceedings. Proceeds of Crime Act 2002, section 7 governs the recoverable amount. Proceeds of Crime Act 2002, section 41 confers the power on the Crown Court to make restraint orders prohibiting any specified person from dealing with realisable property held by him. Proceeds of Crime Act 2002, section 75 contains the criminal lifestyle provisions. Proceeds of Crime Act 2002, Part 5 (sections 240 onwards) provides for the civil recovery of the proceeds of unlawful conduct including by enforcement authorities seeking civil recovery orders in the High Court. Proceeds of Crime Act 2002, section 327 contains the offence of concealing, disguising, converting, transferring, or removing criminal property. Proceeds of Crime Act 2002, section 328 contains the offence of entering into or becoming concerned in an arrangement which a person knows or suspects facilitates the acquisition, retention, use or control of criminal property. Proceeds of Crime Act 2002, section 329 contains the offence of acquiring, using, or possessing criminal property. Proceeds of Crime Act 2002, section 330 contains the offence of failure to disclose in the regulated sector. Proceeds of Crime Act 2002, section 333A contains the offence of tipping off in the regulated sector. Proceeds of Crime Act 2002, section 338 provides for authorised disclosures by way of a Suspicious Activity Report to the National Crime Agency providing a defence to the principal money laundering offences. The Act is the controlling United Kingdom statute for anti-money laundering criminal offences and the confiscation and civil recovery of the proceeds of crime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-pollution-prevention-control-act-1999",
    "title": "UK Pollution Prevention and Control Act 1999 (c.24): Enabling Power for the Integrated Pollution Control and Environmental Permitting Regime",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Pollution Prevention and Control Act 1999 (c. 24) is the enabling statute under which the Secretary of State makes regulations to prevent and control pollution from industrial and other activities, providing the legal basis for the Pollution Prevention and Control regime and, in succession, the Environmental Permitting regime in England and Wales. Section 1 sets the general purpose of section 2 and defines pollution and the environment for the purposes of the Act. Section 2 confers the central power to make provision by regulations for or in connection with implementing the integrated pollution prevention and control framework and for otherwise preventing, reducing, or remedying pollution, with the particular purposes specified in Schedule 1. Section 3 provides for the prevention of pollution after accidents involving offshore installations. Section 4 provides for time-limited disposal or waste management licences. Section 5 addresses the application of the Act to Wales and Scotland. Section 6 provides for consequential and minor amendments and repeals, and section 7 sets out the short title, interpretation, commencement, and extent. Schedule 1 specifies in detail the particular purposes for which provision may be made under section 2, including emission standards, the determination of the regulator, the grant and conditions of permits, monitoring, enforcement notices, charging schemes, and the creation of offences. The Act is the foundational enabling power for industrial pollution permitting in Great Britain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-pra-rulebook-insurance-general-application",
    "title": "UK PRA Rulebook - Insurance General Application and Fundamental Rules for UK Insurers",
    "domain": "Insurance & Risk",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The UK Prudential Regulation Authority (PRA) Rulebook, as amended following Brexit via the Solvency UK framework (effective 31 December 2024), sets binding prudential requirements for UK-authorised insurers, including: capital requirements (SCR and MCR); system of governance; Own Risk and Solvency Assessment (ORSA); Solvency and Financial Condition Report (SFCR); internal model approval; matching adjustment; and transitional measures. UK Solvency II diverges from EU Solvency II in several areas including the reformed matching adjustment, bifurcated reporting, and the removal of infrastructure investment restrictions. The PRA supervises compliance via the supervisory review and evaluation process (SREP) and may impose capital add-ons, governance requirements, or take enforcement action for breaches.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-solvency-ii-directive-2009-138",
      "eu-solvency-ii-directive-pillar-2-governance-risk"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-pra-rulebook-insurance-general-solvency-ii",
    "title": "UK PRA Rulebook - Insurance General Application: Solvency II Onshoring, UK-Specific Adjustments to SCR/MCR Calculation, Risk Margin Reform (2024), TMTP Approval, Matching Adjustment Requirements and Internal Model Approval Process",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the UK Prudential Regulation Authority’s (PRA) onshored Solvency II framework, requiring insurers to calculate Solvency Capital Requirement (SCR) and Minimum Capital Requirement (MCR) using UK-specific parameters, maintain a risk margin under revised methodology (2024), obtain prior approval for Internal Models and Matching Adjustments, and submit a Technical Memorandum of the Own Risk and Solvency Assessment (TMTP). Applies to all UK insurance and reinsurance undertakings under PRA supervision. Key provisions in PRA Rulebook, Insurance Part 2, Sections 4-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-delegated-regulation-2016-2067-spread-market-risk",
      "eu-delegated-regulation-2016-467-non-life-premium-risk",
      "eu-eiopa-guidelines-orsa-2015",
      "canada-osfi-e19-own-risk-solvency-2023",
      "bermuda-bma-cissa-commercial-insurer-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-pra-supervisory-statement-ss1-23",
    "title": "UK PRA Supervisory Statement SS1/23 - Model Risk Management Principles for Banks",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-05-17",
    "bluf": "This Supervisory Statement (SS) from the UK's Prudential Regulation Authority (PRA) establishes five core principles for the effective management of model risk, applicable to all UK-incorporated banks, building societies, and PRA-designated investment firms. As per Principle 1 (Chapter 2.1), firms must maintain a comprehensive model inventory and a risk-based tiering approach to classify models according to their materiality and complexity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sr-11-7-model-risk-management",
      "ecb-guide-internal-models",
      "bcbs-principles-sound-management-operational-risk",
      "pra-ss1-21-resilience"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-pro-innovation-ai-white-paper-2023",
    "title": "AI regulation: a pro-innovation approach",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This white paper sets out the UK government’s proposals for a pro-innovation, cross-sectoral approach to AI regulation based on five high-level principles to be implemented by existing regulators. It does not establish a new statutory regulator but outlines plans for a future potential statutory duty to underpin coordination, as referenced in the white paper.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-600-1-gen-ai-profile",
      "uk-retained-gdpr"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-proceeds-crime-act-2002-part-7-money-laundering",
    "title": "Proceeds of Crime Act 2002, Part 7",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must navigate the legislative framework to identify the current in-force provisions of the Proceeds of Crime Act 2002, Part 7, while being aware of future changes and annotations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-proceeds-of-crime-act-2002-poca-aml",
    "title": "Proceeds of Crime Act 2002 (POCA) - Part 7: Money Laundering",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UK Proceeds of Crime Act 2002 (POCA) establishes the primary money laundering offences, including concealing, arranging, or acquiring criminal property (Sections 327-329), and mandates individuals in the regulated sector to submit a Suspicious Activity Report (SAR) for known or suspected money laundering (Section 330), while prohibiting 'tipping off' the subject of a SAR (Section 333A).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "fca-consumer-duty-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-proceeds-of-crime-act-2002-section-327-concealing-criminal-property",
    "title": "UK Proceeds of Crime Act 2002 Section 327 - Concealing etc Criminal Property (Concealment, Disguise, Conversion, Transfer, Removal from UK)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 327 of the Proceeds of Crime Act 2002 (c. 29) is the first of the three principal UK money laundering offences (sections 327-329) and operates as the primary statutory tool for prosecuting concealment, disguise, conversion, transfer, or removal from the UK of criminal property. Under section 327(1), a person commits an offence if he (a) conceals criminal property, (b) disguises criminal property, (c) converts criminal property, (d) transfers criminal property, or (e) removes criminal property from England and Wales or from Scotland or from Northern Ireland. Defences include authorised disclosure with appropriate consent under section 338, reasonable excuse for non-disclosure, conduct in enforcement of POCA, overseas-conduct exemption where the relevant criminal conduct was lawful in that jurisdiction, deposit-taking institution threshold exemption (s.327(2C)), regulated-sector termination exemption (s.327(2D-2E)), and regulated-business mixed-funds exemption (s.327(2F-2G)). Section 327(3) clarifies that concealing or disguising includes concealing 'its nature, source, location, disposition, movement or ownership or any rights with respect to it'. Maximum penalty under section 334 is 14 years on indictment and/or unlimited fine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_327_text",
        "criminal_property_definition_section_340",
        "knowledge_or_suspicion_threshold",
        "daml_consent_section_338_335",
        "threshold_amounts_section_339a_mlr_2017",
        "penalty_section_334",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-proceeds-of-crime-act-2002-poca-aml",
      "uk-proceeds-of-crime-act-2002-section-330-failure-to-disclose-regulated-sector"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-proceeds-of-crime-act-2002-section-328-arrangements-money-laundering",
    "title": "UK Proceeds of Crime Act 2002 Section 328 - Arrangements (Enters Into or Becomes Concerned, Acquisition Retention Use Control of Criminal Property by Another)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 328 of the Proceeds of Crime Act 2002 (c. 29) is the second of the three principal UK money laundering offences. Under section 328(1), a person commits an offence if he enters into or becomes concerned in an arrangement which he knows or suspects facilitates (by whatever means) the acquisition, retention, use or control of criminal property by or on behalf of another person. Section 328 captures the typical 'professional enabler' role - the solicitor, accountant, broker, or banker who facilitates a third party's enjoyment of criminal property without themselves owning it. Defences mirror section 327: authorised disclosure with appropriate consent under section 338, reasonable excuse for non-disclosure, conduct in enforcement of POCA, overseas-conduct defence under s.328(3) where the relevant criminal conduct was lawful in that jurisdiction, deposit-taking institution threshold exemption (s.328(5)), regulated-sector termination exemption (s.328(6)-(7)), and regulated-business mixed-funds exemption (s.328(8)-(9)). Maximum penalty under section 334 is 14 years on indictment and/or unlimited fine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_328_text",
        "professional_enabler_focus",
        "arrangement_broad_definition",
        "knowledge_or_suspicion_section_340_test",
        "litigation_exclusion_bowman_v_fels",
        "penalty_section_334",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-proceeds-of-crime-act-2002-poca-aml",
      "uk-proceeds-of-crime-act-2002-section-330-failure-to-disclose-regulated-sector",
      "uk-proceeds-of-crime-act-2002-section-327-concealing-criminal-property"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-proceeds-of-crime-act-2002-section-329-acquisition-use-possession",
    "title": "UK Proceeds of Crime Act 2002 Section 329 - Acquisition Use and Possession of Criminal Property (Adequate Consideration Defence, Authorised Disclosure)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 329 of the Proceeds of Crime Act 2002 (c. 29) is the third of the three principal UK money laundering offences and operates as the catch-all for prosecuting acquisition, use, or possession of criminal property where sections 327 (concealing) and 328 (arrangements) do not apply. Under section 329(1), a person commits an offence if he (a) acquires criminal property, (b) uses criminal property, or (c) has possession of criminal property. The signature defence under section 329(2)(c) is 'adequate consideration' - a person does not commit the offence if he acquired or used or had possession of the property for adequate consideration. Under section 329(3), consideration is inadequate if its value is significantly less than the value of the property, or its use or possession - the test is the bona fide arm's-length value standard. Other defences mirror sections 327/328: authorised disclosure with appropriate consent under section 338, reasonable excuse for non-disclosure, conduct in enforcement of POCA, overseas-conduct exemption, deposit-taking threshold exemption, regulated-sector termination exemption, and regulated-business mixed-funds exemption. Maximum penalty under section 334 is 14 years on indictment and/or unlimited fine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_329_text",
        "adequate_consideration_defence_section_329_2_c_3",
        "use_and_possession_continuing_offences",
        "knowledge_or_suspicion_section_340_test",
        "penalty_section_334",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-proceeds-of-crime-act-2002-poca-aml",
      "uk-proceeds-of-crime-act-2002-section-330-failure-to-disclose-regulated-sector",
      "uk-proceeds-of-crime-act-2002-section-327-concealing-criminal-property",
      "uk-proceeds-of-crime-act-2002-section-328-arrangements-money-laundering"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-proceeds-of-crime-act-2002-section-330-failure-to-disclose-regulated-sector",
    "title": "UK Proceeds of Crime Act 2002 Section 330 - Failure to Disclose: Regulated Sector (Knowledge or Suspicion Threshold, Information in the Course of Business, NCA SAR Filing Duty, Training Defence)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 330 of the Proceeds of Crime Act 2002 (c. 29) imposes a positive disclosure duty on persons in the regulated sector to report knowledge or suspicion of money laundering to the National Crime Agency (or to a nominated officer / Money Laundering Reporting Officer) as soon as is practicable. The offence is committed where four conditions all apply (s.330(2)-(4)): (i) the person knows or suspects, or has reasonable grounds for knowing or suspecting, that another person is engaged in money laundering; (ii) the information or other matter on which the knowledge or suspicion is based, or which gives reasonable grounds for the knowledge or suspicion, came to the person in the course of a business in the regulated sector; (iii) the person can identify the other person or the whereabouts of any of the laundered property, or believes (or it is reasonable to expect him to believe) that the information will or may assist in identifying that other person or the whereabouts of any of the laundered property; and (iv) the person does not make the required disclosure to a nominated officer or to a person authorised by the Director General of the NCA as soon as is practicable after the information comes to him. Section 330(6) provides defences: a person does not commit the offence if (a) he has a reasonable excuse for not disclosing; (b) he is a professional legal adviser or relevant professional adviser and the information came to him in privileged circumstances (subject to the section 330(11) crime-purpose exception); or (c) he is an employee, officer or partner of an organisation and he has not received the training required by his employer under section 330(7A) read with the Money Laundering Regulations 2017. The required disclosure must contain the identity of the suspected money launderer (if known), the whereabouts of the laundered property (if known), and the information or other matter that gave rise to the knowledge or suspicion (s.330(5)). The maximum penalty under section 334 is 5 years imprisonment on indictment and/or an unlimited fine; on summary conviction, up to 6 months and/or the statutory maximum fine. Section 330 is the operative duty driving the entire UK Suspicious Activity Report (SAR) regime - over 900,000 SARs are filed annually with the NCA UKFIU, and SAR data underpins UK anti-money-laundering enforcement and international financial intelligence cooperation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_330_text_subsections",
        "knowledge_suspicion_reasonable_grounds_threshold",
        "regulated_sector_definition_schedule_9",
        "required_disclosure_format_section_339",
        "defences_section_330_6_privileged_circumstances_training",
        "penalty_section_334",
        "tipping_off_section_333a_companion_offence",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-proceeds-of-crime-act-2002-poca-aml"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-proceeds-of-crime-act-2002-section-333a-tipping-off-regulated-sector",
    "title": "UK Proceeds of Crime Act 2002 Section 333A - Tipping Off Regulated Sector (Prejudice to Investigation, Disclosure of SAR Filing, Permitted Carve-outs sections 333B-D)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 333A of the Proceeds of Crime Act 2002 (c. 29) creates the regulated-sector tipping-off offence and operates as the companion prohibition to the section 330/331/332 disclosure duty. Under section 333A(1), a person commits an offence if (a) the person discloses any matter within subsection (2), (b) the disclosure is likely to prejudice any investigation that might be conducted following the section 330/331/332 disclosure, and (c) the information on which the disclosure is based came to the person in the course of a business in the regulated sector. Subsection (2) covers disclosures that a Suspicious Activity Report (SAR) has been made to a constable, HMRC officer, nominated officer, or NCA-authorised officer. Under section 333A(3), a person also commits an offence if they disclose that an investigation into POCA Part 7 offences is being contemplated or carried out, where the disclosure is likely to prejudice the investigation and the information came in the course of regulated-sector business. Permitted carve-outs in sections 333B (intra-group), 333C (between professional advisers in the same undertaking), and 333D (other) protect legitimate compliance-driven internal communications. Maximum penalty under section 333A(4): on indictment 2 years and/or unlimited fine; on summary conviction 3 months and/or level 5 fine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_333a_text",
        "permitted_disclosures_sections_333b_c_d",
        "investigation_prejudice_test_section_333a_1_b",
        "regulated_sector_scope_schedule_9",
        "penalty_section_333a_4",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-proceeds-of-crime-act-2002-poca-aml",
      "uk-proceeds-of-crime-act-2002-section-330-failure-to-disclose-regulated-sector"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-procurement-act-2023",
    "title": "Procurement Act 2023",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Procurement Act 2023 establishes a legal framework for public procurement in the UK, requiring contracting authorities to comply with principles of transparency, fairness, and competition. It applies to all covered procurements above specified thresholds and mandates compliance with procedures for competitive tendering, debarment of non-compliant suppliers, and publication of key notices such as tender and contract award notices under Sections 19, 21, 50, 59-65.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-procurement-act-2023-effective-2025",
    "title": "UK Procurement Act 2023 - Central Digital Platform Go-Live and New Public Procurement Regime, Effective 24 February 2025",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Contracting authorities and suppliers under UK public procurement must, from 00:01 on 24 February 2025, operate under the Procurement Act 2023 and its associated Regulations, using the Central Digital Platform on GOV.UK Find a Tender for registration, notice publication, and supplier engagement, with the financial thresholds in Schedule 1 of the Act as amended by the Procurement Act 2023 (Threshold Amounts) (Amendment) Regulations 2025 (in effect from 1 January 2026), namely 135,018 pounds for central government and NHS services and supplies contracts, 207,720 pounds for non-central government services and supplies contracts, and 5,193,000 pounds for works contracts regardless of authority, with all procurement notices and related documents required to be published on the platform with all mandatory fields completed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-ukpga-2000-8-fsma-2000"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-procurement-act-2023-section-24-open-framework-agreements",
    "title": "Procurement Act 2023 Section 24: Refining award criteria",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This section permits a contracting authority to refine award criteria during a competitive flexible procedure, provided this possibility was disclosed in tender documents, it occurs before final tenders are invited, does not unfairly prejudice eliminated suppliers, and any changes are republished.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-procurement-act-2023-section-41-direct-award-special-cases",
    "title": "UK Procurement Act 2023 Section 41 - Direct Award in Special Cases (Direct Award Justification, Excluded Supplier Restriction, Overriding Public Interest Defence, Critical National Infrastructure, Defence/Security/Economic Stability, Extreme Urgency, Intelligence Services Definition)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 41 of the Procurement Act 2023 (c. 54) authorises direct award of public contracts in special cases - an exception to the competitive tendering procedure that is the default under the Act. Under section 41(1), if a direct award justification (set out in Schedule 5) applies, a contracting authority may award a public contract directly (a) to a supplier that is not an excluded supplier (per section 57 mandatory exclusion grounds list), or (b) in accordance with subsection (2). Under section 41(2), a contracting authority may award a contract to an excluded supplier if the authority considers there is an overriding public interest in doing so. Under section 41(3), the authority may conduct a selection process or take preliminary steps as appropriate for awarding a contract under this section. Under section 41(4), before awarding a contract, the authority must consider whether the supplier is an excludable supplier (per section 58 discretionary exclusion grounds). Under section 41(5), an overriding public interest exists if (a) necessary to construct, maintain or operate critical national infrastructure; (b) necessary to ensure proper functioning of sectors critical to UK defence, security, or economic stability; (c) failure would prejudice military/security operations or armed forces/intelligence services effectiveness; or (d) the contract involves extreme urgency (Schedule 5, paragraph 13) and cannot be awarded within required timeframes to non-excluded suppliers. Under section 41(6), direct award justifications are outlined in Schedule 5 (extreme urgency, no other supplier available, prototype/development, additional deliveries, follow-on works, IP exclusivity, dynamic market follow-on). Under section 41(7), 'intelligence services' means the Security Service (MI5), Secret Intelligence Service (MI6), and Government Communications Headquarters (GCHQ). Section 41 sits within Part 3 (Award of public contracts) and is the principal direct award mechanism. Enforcement is by Procurement Review Unit (PRU) under section 102 (Procurement Review and Investigation), the Cabinet Office under section 100 (Procurement guidance), and challenge by aggrieved suppliers under Part 9 (Remedies); the Procurement Act 2023 entered into force on 24 February 2025 replacing the Public Contracts Regulations 2015.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_41_text_subsections",
        "schedule_5_direct_award_justifications",
        "excluded_supplier_section_57_mandatory_grounds",
        "overriding_public_interest_test_section_41_5",
        "excludable_supplier_consideration_section_41_4_58",
        "extreme_urgency_schedule_5_paragraph_13_high_bar",
        "critical_national_infrastructure_section_41_5_a",
        "transparency_and_record_keeping_requirements",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-procurement-act-2023-section-68-debarment-list-exclusion-grounds",
      "uk-procurement-act-2023"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-procurement-act-2023-section-68-debarment-list-exclusion-grounds",
    "title": "Procurement Act 2023, Section 68: Implied payment terms in public contracts",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Contracting authorities must pay valid invoices for applicable public contracts within 30 days of receipt, and must promptly notify payees of any disputed or invalid invoices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-procurement-act-2023-section-73-implied-payment-subcontracts",
    "title": "UK Procurement Act 2023 Section 73 - Implied Payment Terms in Sub-Contracts",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "UK Procurement Act 2023 (c. 54) Section 73, which fully came into force 24 February 2025, automatically implies the payment terms from Section 68(2) to (5) of the Act into every public sub-contract: the prime contractor as 'payee' under the public contract must pay sub-contractors within 30 days of receipt of a valid invoice, or 30 days from the date payment is due if no payment date is specified; Section 73(1) provides that 'The terms in subsections (2) to (5) of section 68 (implied payment terms in public contracts) are implied into every public sub-contract'; Section 73(2) clarifies that references to the 'contracting authority' in Section 68 apply to the sub-contract recipient (i.e., the supplier higher up the chain); Section 73(3) prohibits any contract term that purports to restrict or limit the implied payment terms (such terms are void); Section 73(4) preserves the right of parties to agree on EARLIER payment than the implied 30-day terms; Section 73(5) excludes concession contracts, utilities contracts awarded by private utilities, and school contracts from the implied payment terms framework; the section is the central transparency-and-fair-payment mechanism of the new UK procurement regime designed to address chronic late-payment to SME subcontractors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "section_68_prime_payment_terms",
        "predecessor_regime_pcr_2015",
        "construction_act_intersection",
        "industry_mapping",
        "enforcement_anchors",
        "void_anti_evasion_provision_section_73_3"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-procurement-act-2023",
      "uk-procurement-act-2023-section-24-open-framework-agreements",
      "uk-procurement-act-2023-section-68-debarment-list-exclusion-grounds"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-product-regulation-and-metrology-act-2025",
    "title": "Product Regulation and Metrology Act 2025 (c. 20), Sections 1-6 Product Regulations, Product Requirements and Metrology Regulations",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "The Product Regulation and Metrology Act 2025 gives the Secretary of State broad powers to make product regulations on the marketing or use of products in the UK to reduce risks, ensure products operate efficiently, and ensure measuring products are accurate. It permits regulations mirroring relevant EU law to reduce environmental impact, defines when a product presents a risk, and establishes enforcement and metrology regimes. Businesses marketing or using products in the UK must comply with any product and metrology requirements set under sections 1 to 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-consumer-protection-from-unfair-trading-2008",
      "eu-general-product-safety-regulation-2023-988-gpsr-consumer-products"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-product-security-telecom-infrastructure-act-2022",
    "title": "Product Security and Telecommunications Infrastructure Act 2022, Part 1, Chapter 2: Duties of relevant persons, etc",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This regulation establishes duties for manufacturers, importers, and distributors of relevant connectable products to ensure compliance with security requirements, investigate failures, take corrective action, and maintain records.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-product-security-telecommunications-infrastructure-act-2022-part-1-security-requirements",
    "title": "Product Security and Telecommunications Infrastructure Act 2022 Part 1: Security requirements",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This Act empowers the Secretary of State to specify security requirements for relevant connectable products made available to UK consumers, creating a framework for future mandatory product security standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-product-security-telecoms-infrastructure-2022",
    "title": "Product Security and Telecommunications Infrastructure Act 2022 - Part 1: Product Security",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This UK law mandates that manufacturers, importers, and distributors of consumer connectable products (IoT devices) comply with minimum security requirements. As detailed in Part 1 and Schedule 1, these include banning universal default passwords, providing a public point of contact for vulnerability reporting, and stating the minimum defined support period for security updates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-57-key-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-property-digital-assets-act-2025",
    "title": "UK Property (Digital Assets etc) Act 2025 - Third Category of Personal Property for Crypto-Tokens and Digital Things",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Crypto-tokens and other digital things in the United Kingdom are not prevented from being the object of personal property rights merely because they are neither things in possession nor things in action, under the Property (Digital Assets etc) Act 2025 which received Royal Assent on 2 December 2025 and entered into force on the same day, implementing the Law Commission recommendation for a statutory third category of personal property without attempting to define exactly what digital assets are, leaving judges and lawyers to apply the rule in different situations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-fsma-cryptoassets-regulations-2026-si-102"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "uk-protection-from-harassment-act-1997-section-1-prohibition-of-harassment",
    "title": "UK Protection from Harassment Act 1997 Section 1 - Prohibition of Harassment",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 1 of the Protection from Harassment Act 1997 prohibits a person from pursuing a course of conduct (i) which amounts to harassment of another and (ii) which he knows or ought to know amounts to harassment of the other. Section 1(1A) (added 2005) extends the prohibition to courses of conduct involving harassment of two or more persons on separate occasions, where the purpose is to persuade any person not to do something or to do something. 'Course of conduct' means conduct on at least two occasions per Section 7(3). 'Ought to know' is judged objectively per Section 1(2). Section 1 is the civil and criminal foundation for the substantive harassment offences at Sections 2 (harassment), 2A (stalking), 4 (fear of violence), and 4A (stalking with fear of violence or serious alarm/distress). The 1997 Act provides parallel civil remedy (Section 3) and criminal liability frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_prohibition_subsection_1",
        "two_or_more_persons_extension_subsection_1a",
        "objective_ought_to_know_subsection_2",
        "exceptions_subsection_3",
        "course_of_conduct_definition_section_7_3",
        "harassment_definition_section_7_2",
        "conduct_definition_section_7_4_includes_speech",
        "interaction_with_section_2_offence_of_harassment",
        "interaction_with_section_2a_offence_of_stalking",
        "interaction_with_section_3_civil_remedy"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-section-179-ofcom-enforcement-notifications"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-protection-from-harassment-act-1997-section-4-fear-of-violence",
    "title": "UK Protection from Harassment Act 1997 Section 4 - Putting People in Fear of Violence",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 4 of the Protection from Harassment Act 1997 makes it an offence for a person whose course of conduct causes another to fear, on at least two occasions, that violence will be used against him, if he knows or ought to know that his course of conduct will cause the other so to fear on each of those occasions. Penalty: on summary conviction, imprisonment up to the general magistrates' court limit or fine or both; on indictment, imprisonment up to 10 years. Section 4 escalates from the Section 2 harassment offence (no fear of violence requirement) and is the principal offence for serious cases of intimidation and stalking with violence threat. Section 4A (added 2012) further criminalises stalking involving fear of violence or serious alarm/distress with substantial adverse effect.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "objective_ought_to_know_subsection_2",
        "exceptions_subsection_3",
        "penalty_subsection_4_a_summary",
        "penalty_subsection_4_b_indictment",
        "alternative_verdict_subsection_5_section_2",
        "violence_against_him_personal_to_complainant",
        "fear_on_at_least_two_occasions_aggregated_test",
        "interaction_with_section_4a_stalking_with_fear",
        "interaction_with_section_4_4_offences_against_person_act_1861"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-protection-from-harassment-act-1997-section-1-prohibition-of-harassment"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-protection-of-badgers-act-1992",
    "title": "UK Protection of Badgers Act 1992 (c.51): Protection of Badgers and Setts",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Protection of Badgers Act 1992 (c. 51) consolidates the law protecting badgers and their setts in England, Wales, and Scotland, administered through the courts and the licensing authorities and enforced by the police. Section 1 makes it an offence wilfully to kill, injure, or take a badger, or to attempt to do so, and to possess a dead badger or any part of one. Section 2 creates offences of cruelty, including ill-treating a badger, digging for a badger, and using badger tongs. Section 3 makes it an offence to interfere with a badger sett by damaging or destroying it, obstructing access to it, or disturbing a badger occupying it. Section 4 prohibits the sale and possession of live badgers, and section 5 regulates the marking and ringing of badgers under licence. Section 6 provides general exceptions, section 7 provides exceptions from section 1, and section 8 provides exceptions from section 3, including for the prevention of serious damage and disease control. Section 10 confers power to grant licences for otherwise prohibited acts, section 11 confers powers of constables to stop, search, and arrest, and section 12 sets the penalties and forfeiture on conviction. Section 13 provides for the powers of the court where a dog was used or present at the commission of an offence. The Act is the foundational badger protection regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-protection-of-children-act-1978-section-1-indecent-photographs-children",
    "title": "UK Protection of Children Act 1978 Section 1 - Indecent Photographs of Children",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 1 of the Protection of Children Act 1978 (PCA 1978) creates four offences related to indecent photographs or pseudo-photographs of children: (a) taking, permitting to be taken, or making such images; (b) distributing or showing them; (c) possessing them with a view to distribution or showing; and (d) publishing or causing to be published advertisements likely to be understood as offering distribution or showing. A defence to (b) and (c) requires the defendant to prove a legitimate reason or that they had not seen the image and had no cause to suspect it was indecent. Proceedings require DPP consent. PCA 1978 is the principal UK CSAM-production and distribution offence and remains in force together with CJA 1988 Section 160 (simple possession).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "four_offences_subsection_1",
        "definition_of_making_includes_downloading",
        "pseudo_photographs_and_tracings_caught",
        "distributing_definition_subsection_2",
        "dpp_consent_required_subsection_3",
        "defences_to_distribution_and_possession_with_view_subsection_4",
        "penalties_section_6_amended_2003",
        "interaction_with_cja_1988_section_160_simple_possession",
        "child_definition_under_18_via_pca_1978_section_7_6",
        "automatic_sex_offender_notification"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-criminal-justice-act-1988-section-160-possession-indecent-photograph-child",
      "uk-coroners-and-justice-act-2009-section-62-prohibited-images-children"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-psti-act-2022",
    "title": "UK Product Security and Telecommunications Infrastructure Act 2022 - IoT Security Requirements",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This UK law requires manufacturers, importers, and distributors of consumer connectable products to meet minimum security standards, including a ban on universal default passwords, publishing a vulnerability disclosure policy, and defining a minimum support period for security updates, as outlined in Part 1 and Schedule 1 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "c-scrm-practices-systems-organizations",
      "nist-ir-8425-iot-core-baseline-profile",
      "cis-controls-v8",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-psti-act-2022-product-security-iot-consumer-requirements",
    "title": "UK Product Security and Telecommunications Infrastructure Act 2022 (PSTI) - Consumer Connectable Product Security Baseline",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Part 1 of the PSTI Act 2022 (c. 46), effective April 2024, requires manufacturers, importers, and distributors of consumer connectable products (IoT devices, smartphones, routers, smart home devices) sold in Great Britain to comply with three minimum security requirements: no default universal passwords; public vulnerability disclosure policy; minimum security update support period disclosed to consumers. OPSS enforces; fines up to GBP 10M or 4% global revenue.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-psti-act-2022-relevant-connectable-products-security",
    "title": "UK Product Security and Telecommunications Infrastructure Act 2022 - Part 1 Relevant Connectable Products",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "Part 1 of the UK Product Security and Telecommunications Infrastructure Act 2022 (c.46) and the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023 (SI 2023/1007) establish the United Kingdom's mandatory consumer connectable-product security regime, which came into force on 29 April 2024. Section 1 defines a relevant connectable product as a product that can connect to the internet or to a network and is supplied to UK consumers, with categories of excepted products designated by the Secretary of State. Section 4 imposes the compliance requirement on manufacturers, importers, and distributors to ensure relevant connectable products comply with the security requirements specified in regulations. The PSTI Regulations 2023 Schedule 1 sets three baseline security requirements: paragraph 1 prohibits universal default passwords (any password must be unique per device or set on first use by the user); paragraph 2 requires a published vulnerability disclosure policy (point of contact for security researchers, acknowledgment timeline, status updates); paragraph 3 requires transparency about the minimum security update support period (a defined date until which security updates will be issued). Section 7 requires a statement of compliance to accompany every product placed on the UK market before supply. Section 8 requires records to be retained for 10 years. Section 9 grants the Office for Product Safety and Standards (OPSS) as enforcement authority investigatory powers including section 22 information notices, section 26 compliance notices, section 27 stop notices, and section 28 recall notices. Section 49 establishes monetary penalties up to GBP 10 million or 4% of qualifying worldwide revenue (whichever greater) for non-compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "three_baseline_security_requirements",
        "excepted_products",
        "enforcement_penalty_structure"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "etsi-en-303-645-iot-cybersecurity-2020",
      "eu-cyber-resilience-act-2024-iot-products",
      "eu-radio-equipment-directive-2014-53-iot",
      "eu-cyber-resilience-act-iot-2024-products"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-public-contracts-regulations-2015-si-102",
    "title": "UK Public Contracts Regulations 2015 (SI 2015/102) - Public Sector Procurement Framework",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "The UK Public Contracts Regulations 2015 (SI 2015/102), made under section 2(2) of the European Communities Act 1972 with cross-reference to the Public Contracts Directive 2014/24/EU, established the public procurement framework for UK contracting authorities through to the Procurement Act 2023 transition (Procurement Act 2023 fully came into force 24 February 2025 superseding most of SI 2015/102 for new procurements); SI 2015/102 has five principal parts: Part 1 (General Provisions - citation, commencement, definitions), Part 2 (Rules implementing the Public Contracts Directive divided into chapters covering scope, public contracts, particular procurement regimes, and records), Part 3 (Remedies - mechanisms for facilitation, court applications, and ineffectiveness), Part 4 (Miscellaneous Obligations including below-threshold procurements), Part 5 (Revocations, amendments, savings, and transitional provisions); Regulation 18 establishes the foundational principles of procurement (equal treatment, non-discrimination, transparency, proportionality); Regulation 26 identifies the available procurement procedures (open, restricted, competitive procedure with negotiation, competitive dialogue, innovation partnership, design contests); Regulation 84 requires contracting authorities to maintain records and report on procurement activities; the regulations apply to contracting authorities exceeding the financial thresholds in Regulation 5 (currently approximately £213,477 for supplies/services for central government, £663,540 for utilities).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "successor_regime",
        "parallel_regulations_other_sectors",
        "remedies_framework_part_3",
        "industry_mapping",
        "enforcement_anchors",
        "regulation_84_records_obligation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-procurement-act-2023",
      "uk-procurement-act-2023-section-24-open-framework-agreements",
      "uk-procurement-act-2023-section-68-debarment-list-exclusion-grounds"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-public-order-act-2023-protest-restrictions",
    "title": "UK Public Order Act 2023 - Locking-On, Tunnelling, and Critical National Infrastructure Offences",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Public Order Act 2023 (UK) creates new criminal offences targeting disruptive protest tactics. Section 1 creates the offence of locking on whereby a person attaches themselves to another person, object, or land in a way that causes or is capable of causing serious disruption. Section 2 creates the offence of being equipped for locking on. Sections 3 and 4 create the tunnelling offences (causing serious disruption by tunnelling and being present in a tunnel). Section 5 covers being equipped for tunnelling. Section 6 creates the offence of obstructing major transport works. Section 7 creates the offence of interference with the use or operation of key national infrastructure including airports, railways, oil and gas terminals, newspaper printers, and downstream oil and electricity infrastructure. Sections 10 to 14 expand police stop and search powers in connection with protest-related offences, with section 11 providing for stop and search without suspicion in specified areas. Part 2 of the Act (sections 20 onwards) establishes Serious Disruption Prevention Orders restricting an individual's activities, including reporting requirements and association limits. The Act commenced principally on 3 May 2023. Operational guidance is published by the College of Policing. The Act and related Public Order (Serious Disruption) Regulations 2023 were the subject of significant judicial review challenge in National Council for Civil Liberties v Secretary of State for the Home Department 2024 EWHC 1181 (Admin).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-equality-act-2010-protected-characteristics",
      "uk-data-protection-act-2018",
      "uk-bribery-act-2010"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-public-records-act-1958",
    "title": "United Kingdom Public Records Act 1958: Secretary of State Responsibility, Public Record Office, Selection and Preservation, Place of Deposit, Access, and Destruction Controls",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Public Records Act 1958, Chapter 51 of 6 and 7 Elizabeth II, is the principal United Kingdom statute governing the selection, preservation, custody, and public access to public records of government and is administered by The National Archives operating under the responsibility of the Secretary of State. Public Records Act 1958, section 1 sets out the general responsibility of the Secretary of State for public records. Public Records Act 1958, section 2 establishes the Public Record Office. Public Records Act 1958, section 3 sets out the selection and preservation of public records, including the duty of every person responsible for public records to make arrangements for their selection. Public Records Act 1958, section 4 governs the place of deposit of public records. Public Records Act 1958, section 5 governs access to public records and historically established the thirty year access rule, which has since been replaced by a twenty year rule under the Constitutional Reform and Governance Act 2010 alongside the Freedom of Information Act 2000. Public Records Act 1958, section 6 governs the destruction of public records in the Public Record Office or other places of deposit. Public Records Act 1958, section 7 governs records for which the Master of the Rolls remains responsible. Public Records Act 1958, section 8 covers court records. Public Records Act 1958, section 9 governs the legal validity of public records and authenticated copies. Public Records Act 1958, section 10 contains the interpretation. The Act is the controlling United Kingdom instrument for public records management and operates alongside the Freedom of Information Act 2000 and the Data Protection Act 2018.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-renters-rights-act-2025-tenancy-reform",
    "title": "Renters' Rights Act 2025 (c. 26), Part 1 Tenancy Reform and Parts 2-3 Residential Landlords and Decent Homes Standard",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "The Renters' Rights Act 2025 abolishes assured shorthold tenancies in England by omitting Chapter 2 of Part 1 of the Housing Act 1988, ending section 21 no-fault evictions and converting tenancies to periodic assured tenancies. It revises the grounds for possession, sets a statutory procedure for rent increases, requires landlords to state a proposed rent and avoid rental bidding, and creates landlord redress schemes, a Private Rented Sector Database, and a decent homes standard. Compliance obligations fall on residential landlords and letting agents in the private rented sector.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-housing-act-2004-hhsrs-hmo",
      "uk-landlord-tenant-act-1985-repairing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-republic-belarus-sanctions-eu-exit-regulations-2019-si-600",
    "title": "UK Republic of Belarus (Sanctions) (EU Exit) Regulations 2019 SI 2019/600 - Asset Freeze Trade Restrictions and Russia-Aligned Sanctions Architecture",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Republic of Belarus (Sanctions) (EU Exit) Regulations 2019 establish the United Kingdom's autonomous sanctions framework against Belarus organised in eight parts covering general provisions and purposes including regulation 4, designation power and criteria in regulations 5 and 6, asset freeze in regulation 11 with prohibitions on making funds or economic resources available in regulations 12 to 15, immigration restrictions in regulation 17, trade prohibitions on restricted goods in regulation 21, supply and delivery in regulation 22, technology transfer in regulation 24 and technical assistance in regulation 25, exceptions and licensing including a national security and serious crime carve-out in regulation 31, and criminal enforcement and monetary penalties in regulations 48 to 56, and have been expanded since 2022 to mirror Russia regulation measures and to address Belarus's role in supporting Russian military operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018",
      "uk-russia-sanctions-eu-exit-regulations-2019-si-855"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-research-excellence-framework-ref-2021",
    "title": "Research Excellence Framework 2021: Guidance on Submissions",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The UK Research Excellence Framework (REF) 2021 requires higher education institutions to submit assessments of research outputs, impact case studies, and research environment quality for national evaluation. It applies to all UK universities submitting research for funding allocation under REF 2021, as defined in Section 11 of the REF 2021 Guidance on Submissions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-reservoirs-act-1975",
    "title": "UK Reservoirs Act 1975: Large Raised Reservoirs, Registration, Construction and Inspection Engineers and Supervision",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Reservoirs Act 1975 is the reservoir-safety framework for England and Wales, requiring large raised reservoirs to be designed, constructed, supervised and inspected by qualified civil engineers and registered with an enforcement authority, administered by the Environment Agency as the enforcement authority (the Act was amended by the Flood and Water Management Act 2010). Section A1 defines a large raised reservoir: a raised reservoir is large if it is capable of holding 10,000 cubic metres or more of water above the natural level of any part of the surrounding land. Section 1 sets the ambit of the Act and the interpretation provisions. Section 2 requires the enforcement authority to maintain a register of large raised reservoirs and to enforce the Act. Section 6 governs the construction or enlargement of a reservoir, which must be carried out under the supervision of a qualified construction engineer, and section 7 requires the construction engineer to issue certificates including a final certificate before the reservoir is filled. Section 10 requires periodical inspection of every large raised reservoir by an independent inspecting engineer, who may recommend measures to be taken in the interests of safety. Section 12 requires a supervising engineer to keep the reservoir under regular supervision between inspections. Section 22 provides for the criminal liability of undertakers and their employees for contraventions. The Act is the legal regime that keeps large raised reservoirs under continuous qualified engineering oversight to prevent catastrophic failure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-retained-gdpr",
    "title": "UK General Data Protection Regulation (UK GDPR) as tailored by the Data Protection Act 2018",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The UK GDPR establishes the legal framework for processing personal data in the United Kingdom, requiring organizations to adhere to core principles like lawfulness, fairness, and transparency as outlined in Article 5. It applies to controllers and processors in the UK, and those outside the UK who offer goods/services to or monitor the behaviour of UK data subjects per Article 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "eu-standard-contractual-clauses-2021",
      "gdpr-adequacy-decisions-article-45",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-ring-fencing-banking-reform-act-2013",
    "title": "UK Financial Services (Banking Reform) Act 2013 - Ring-Fencing of Retail Banking",
    "domain": "Banking & Global Finance",
    "version": "2024.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The UK Financial Services (Banking Reform) Act 2013 mandates structural separation (ring-fencing) of core retail banking services from investment banking activities for banks with more than £25 billion in core deposits, creating a legally distinct ring-fenced body with independent governance and capital requirements overseen by the Prudential Regulation Authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "basel_iii",
        "eu_crr",
        "fsb_resolution",
        "volcker_rule"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-brrd-bank-recovery-resolution-directive-2014-59",
      "basel-iii-capital",
      "uk-pra-supervisory-statement-ss1-23"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-road-traffic-act-1988",
    "title": "UK Road Traffic Act 1988: Driving Offences, Drink and Drug Driving, Licensing and Compulsory Insurance",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Road Traffic Act 1988 is the principal statute governing the use of motor vehicles on roads in Great Britain, setting out the main driving offences, the drink and drug driving regime, driver licensing, and compulsory third-party insurance, enforced by the police and the courts. Section 1 creates the offence of causing death by dangerous driving, section 2 the offence of dangerous driving, and section 3 the offence of careless and inconsiderate driving. Section 4 makes it an offence to drive, attempt to drive, or be in charge of a vehicle when unfit through drink or drugs, and section 5 makes it an offence to drive or be in charge with an alcohol concentration above the prescribed limit. Section 7 governs the provision of specimens for analysis and makes failure to provide a specimen without reasonable excuse an offence. Section 87 requires drivers of motor vehicles to hold a driving licence authorising them to drive the class of vehicle. Section 143 imposes the central requirement that users of motor vehicles be insured against third-party risks and makes using or permitting the use of an uninsured vehicle an offence. The Act is the legal foundation of UK road-safety enforcement, the drink-drive limits, and the compulsory motor-insurance regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-road-traffic-act-1988-construction-use-insurance",
    "title": "UK Road Traffic Act 1988: Driving Offences, Construction and Use, Licensing and Insurance",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Road Traffic Act 1988 (c. 52) is the principal UK statute regulating the use of motor vehicles on roads, enforced by the police and the DVSA under the policy responsibility of the Department for Transport. Part I creates the principal driving offences: causing death by dangerous driving (section 1), dangerous driving (section 2), careless and inconsiderate driving (section 3), causing death by careless driving when under the influence of drink or drugs (section 3A), driving or being in charge when unfit through drink or drugs (section 4), and driving or being in charge with an alcohol concentration above the prescribed limit (section 5); the police may administer preliminary tests (section 6) and require specimens for analysis (section 7). Part II governs the construction and use of vehicles: it is an offence to use a vehicle in a dangerous condition (section 40A), regulations prescribe construction, weight, equipment and use (section 41), and breaches of other construction and use requirements are offences (section 42); vehicles must hold an obligatory test certificate (MOT) under section 47. Drivers must hold a driving licence for the class of vehicle (section 87). Section 143 makes it an offence to use, or cause or permit another to use, a motor vehicle on a road or public place without a policy of third-party insurance. Section 170 imposes duties on a driver involved in an accident to stop, and to report the accident and provide details or documents where required. These provisions are supported by fixed penalties, endorsement and disqualification under the associated road traffic offenders legislation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-road-vehicles-approval-regulations-2009-si-717",
    "title": "United Kingdom Road Vehicles (Approval) Regulations 2009 (SI 2009/717) - Type Approval Recall Technical Services and Individual Approval",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-29",
    "bluf": "The Road Vehicles (Approval) Regulations 2009 (SI 2009/717) implement the EC vehicle type approval framework in Great Britain through forty-two regulations across six parts covering scope, conditions for first licensing of motor vehicles and trailers, EC type approval applications and grant, national small series and individual approval, validity of approvals, and miscellaneous provisions including recall, forgery offences, and designation of technical services. The Secretary of State is the approval authority for Great Britain, with the Vehicle Certification Agency operating as the executive agency that grants approvals and supervises technical services. After EU exit the substantive framework continues as retained EU law underpinning the GB type approval scheme that runs in parallel with the EU 2018/858 framework for vehicles placed on the GB market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-type-approval-regulation-2018-858",
      "un-regulation-155-vehicle-cybersecurity",
      "un-regulation-156-software-updates-ota"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-road-vehicles-construction-and-use-regulations-1986",
    "title": "Road Vehicles (Construction and Use) Regulations 1986 (SI 1986/1078)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Road Vehicles (Construction and Use) Regulations 1986 (SI 1986/1078) set the construction, equipment, and use requirements for motor vehicles and trailers used on roads in Great Britain. Regulation 18 governs maintenance and efficiency of brakes, Regulation 27 governs condition and maintenance of tyres, Regulation 33 governs mirrors and other devices for indirect vision, Regulation 36B applies to road speed limiters, and Regulation 75 sets the maximum permitted laden weight of a vehicle. Compliance is enforced through roadside checks and periodic testing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-road-traffic-act-1988-construction-use-insurance"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-russia-sanctions-eu-exit-regulations-2019-si-855",
    "title": "UK Russia (Sanctions) (EU Exit) Regulations 2019 SI 2019/855 - Asset Freeze Trade Restrictions Maritime and Aviation Sanctions Against Russia",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Russia (Sanctions) (EU Exit) Regulations 2019 establish the United Kingdom's autonomous sanctions framework against Russia under the Sanctions and Anti-Money Laundering Act 2018, providing for designation of persons in Part 2 with asset-freeze and prohibitions on making funds or economic resources available in Part 3, immigration sanctions in Part 4, trade prohibitions on military goods, dual-use technology and energy-related goods in Part 5, ship movement restrictions in Part 6, Treasury and trade licensing exceptions in Part 7, information and reporting offences in Part 8, criminal and monetary penalty enforcement in Part 9, maritime stop-board-search-seize powers in Part 10, and transitional and supplementary provisions in Part 11, and have been progressively expanded since 2022 with oil price cap measures, restrictions on professional services and goods supporting Russian industrial capability, and circumvention prohibitions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018",
      "us-trading-with-the-enemy-act-50-usc-4301"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-salmon-and-freshwater-fisheries-act-1975",
    "title": "UK Salmon and Freshwater Fisheries Act 1975: Prohibited Methods, Fixed Engines, Fish Passes, Close Seasons and Licensing",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Salmon and Freshwater Fisheries Act 1975 is the principal statute protecting salmon, trout, freshwater fish and eels in England and Wales, regulating how, when and with what authority fish may be taken, administered by the Environment Agency. The Act prohibits destructive methods of taking fish: section 1 prohibits the use of certain implements, section 4 prohibits putting poisonous matter or polluting effluent into waters containing fish, and section 5 prohibits the use of explosives, poisons or noxious substances and electrical devices to take or destroy fish, and the destruction of dams. It controls structures in rivers: section 6 regulates fixed engines, section 7 fishing weirs and section 8 fishing mill dams. It secures fish migration: section 9 imposes a duty to make and maintain fish passes, section 10 empowers the appropriate agency to construct and alter fish passes, and section 12 penalises injuring or obstructing a fish pass or free gap. It sets temporal protection through section 19 (close seasons and close times) and section 20 (close seasons and close times for fixed engines and obstructions). It requires authority to fish: section 25 provides for licences to fish and section 27 makes unlicensed fishing an offence. Enforcement is carried out by water bailiffs and others under sections 31 (powers of search), 34 (power to apprehend persons fishing illegally) and 35 (power to require production of fishing licences). The Act is the legal framework that keeps freshwater and migratory fisheries sustainable by banning destructive methods, protecting migration and licensing the right to fish.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-salmon-freshwater-fisheries-act-1975",
    "title": "UK Salmon and Freshwater Fisheries Act 1975 (c.51): Prohibited Methods, Close Seasons and Fishing Licences",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Salmon and Freshwater Fisheries Act 1975 (c. 51) is the principal statute regulating the taking of salmon, trout, freshwater fish, and eels in England and Wales, administered by the Environment Agency. Section 1 prohibits the use of certain implements to take or kill fish, such as a firearm, gaff, snare, or light. Section 2 protects roe, spawning fish, and unclean or immature fish, and section 3 regulates the use of nets, including mesh size and prohibited nets. Section 5 prohibits the use of explosives, poisons, or noxious substances and electrical devices to take or destroy fish, and the destruction of dams. Section 19 provides for close seasons and close times during which fishing for salmon and trout is prohibited, and section 20 deals with close seasons for fixed engines and obstructions. Section 25 requires a licence to fish for salmon, trout, freshwater fish, or eels, section 26 provides for the limitation of fishing licences, and section 27 makes unlicensed fishing an offence. Section 37 governs the prosecution of offences and section 37A provides for fixed penalty notices for certain offences. The Act is the foundational inland and migratory fisheries protection regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-samla-2018-sanctions-anti-money-laundering-act",
    "title": "UK Sanctions and Anti-Money Laundering Act 2018",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The UK Sanctions and Anti-Money Laundering Act 2018 (SAMLA) provides post-Brexit UK statutory authority for autonomous sanctions regimes and anti-money laundering regulations. Part 1 empowers the Secretary of State to make sanctions regulations for foreign policy, national security, or international peace and security objectives. Part 2 empowers the Treasury to make regulations giving effect to FATF Recommendations and anti-money laundering or counter-terrorist financing measures. Compliance is administered by OFSI (financial sanctions) and HMRC/FCA (AML supervision). Penalties include unlimited fines, custodial sentences up to 7 years, and director disqualification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "uk_mlrs_2017",
        "uk_poca_2002",
        "uk_terrorism_act_2000",
        "fatf",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-sanctions-and-aml-act-2018-section-1-power-make-sanctions-regulations",
    "title": "UK Sanctions and Anti-Money Laundering Act 2018 Section 1 - Power to Make Sanctions Regulations (UN Obligations, International Obligations, Listed Statutory Purposes)",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 1 of the Sanctions and Anti-Money Laundering Act 2018 (c. 13) provides the foundational UK statutory power to make sanctions regulations - the principal post-Brexit instrument enabling the UK to operate an autonomous sanctions regime independent of the EU. Under section 1(1), an appropriate Minister may make sanctions regulations where appropriate for the purposes of compliance with a UN obligation, with another international obligation, or for a purpose within subsection (2). Section 1(2) lists nine statutory purposes for which sanctions regulations may be made: (a) furthering the prevention of terrorism in the UK or elsewhere, (b) national security of the UK, (c) international peace and security, (d) UK foreign policy objectives, (e) promoting the resolution of armed conflicts or the protection of civilians in conflict zones, (f) providing accountability for or be a deterrent to gross violations of human rights, (g) promoting compliance with international humanitarian law, (h) contributing to multilateral efforts to prevent the spread and use of weapons and materials of mass destruction, (i) promoting respect for democracy, the rule of law and good governance. Section 1(3) requires the regulations to specify a stated purpose. Section 1(5) categorises sanctions regulations - financial, director disqualification, immigration, trade, aircraft, shipping, UN-obligation, or supplemental. Section 1 underpins the OFSI Consolidated List, the UK Russia regime, the UK Global Human Rights Sanctions Regulations 2020, and all other UK autonomous sanctions regimes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_1_text",
        "ofsi_consolidated_list_and_designation_section_9",
        "post_brexit_autonomous_sanctions_regime",
        "magnitsky_style_human_rights_section_1_2_f_and_global_hr_regulations",
        "samla_2018_civil_monetary_penalties_strict_liability",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-sanctions-and-anti-money-laundering-act-2018",
    "title": "UK Sanctions and Anti-Money Laundering Act 2018 (c. 13): Post-Brexit Powers to Make Sanctions and Money Laundering Regulations",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Sanctions and Anti-Money Laundering Act 2018 (c. 13) is the United Kingdom's primary post-Brexit statutory framework for imposing and administering sanctions and for making money laundering and terrorist financing regulations, administered by HM Treasury through the Office of Financial Sanctions Implementation and by the Foreign, Commonwealth and Development Office. Section 1 confers the power on an appropriate Minister to make sanctions regulations for purposes including compliance with United Nations obligations, other international obligations, and the prevention of terrorism. Section 2 imposes additional requirements where regulations are made for a discretionary purpose, requiring the Minister to consider whether there are good reasons and whether the imposition is a reasonable course of action. Section 3 sets out financial sanctions, including asset freezes. Section 11 provides for the designation of a person by name under a designation power, and section 12 provides for designation by description. Section 17 confers powers to create enforcement provisions, including criminal offences, for breaches of sanctions regulations. Section 38 provides a designated person with a right to seek court review of a decision to designate or not to vary or revoke a designation. Section 49 confers the power to make money laundering and terrorist financing regulations imposing customer due diligence, record-keeping, and reporting requirements on the regulated sector. The Act is the foundational statute for UK sanctions and anti-money-laundering rule-making.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-sanctions-anti-money-laundering-act-2018",
    "title": "Sanctions and Anti-Money Laundering Act 2018",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Sanctions and Anti-Money Laundering Act 2018 (SAMLA) empowers the UK government to impose and enforce autonomous sanctions regimes post-Brexit, including financial, trade, shipping, and immigration sanctions. It applies to all persons and entities within the UK and to UK nationals abroad, requiring compliance with designation orders, licensing requirements, and enforcement obligations under Section 1 and Schedule 1, particularly for goods, technology, and shipping movements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bimco-standard-charter-party-terms"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sea-fish-conservation-act-1967",
    "title": "UK Sea Fish (Conservation) Act 1967 (c.84): Size Limits, Gear Regulation and Boat Licensing",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Sea Fish (Conservation) Act 1967 (c. 84) is a principal statute for the conservation of sea fish in United Kingdom waters, regulating the size of fish that may be taken, the gear that may be used, and the licensing of fishing boats, administered by the fisheries Ministers and the Marine Management Organisation. Section 1 provides for size limits for fish, making it an offence to land, sell, or have in possession sea fish below the prescribed minimum size, and section 2 provides for size limits for fish used in the course of any business. Section 3 provides for the regulation of nets and other fishing gear, including mesh sizes and prohibited gear. Section 4 provides for the licensing of fishing boats, under which it is an offence to use a British fishing boat for fishing without a licence where one is required. Section 6 prohibits the landing of sea fish caught in certain areas, and section 8 regulates the landing of foreign-caught sea fish. Section 11 sets the penalties for offences, section 12 addresses offences by directors and partners, and section 14 sets the jurisdiction of the court to try offences. The Act is a foundational marine fisheries conservation and licensing regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-sea-fisheries-shellfish-act-1967",
    "title": "UK Sea Fisheries (Shellfish) Act 1967 (c.83): Several and Regulating Orders for Shellfish Fisheries",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Sea Fisheries (Shellfish) Act 1967 (c. 83) provides for the establishment and protection of shellfish fisheries in England and Wales through several and regulating orders, administered by the fisheries Ministers and the Marine Management Organisation. Section 1 confers power to make orders as to fisheries for shellfish on application, conferring a right of several fishery or a right of regulating a fishery for oysters, mussels, cockles, clams, or other specified molluscs and crustaceans. Section 2 sets out the effect of the grant of a right of several fishery, giving the grantee the exclusive right of depositing, propagating, dredging, fishing for, and taking shellfish within the area. Section 3 sets out the effect of the grant of a right of regulating a fishery, allowing the grantee to regulate the fishery and impose tolls and restrictions. Section 4 provides for licensing within a regulated fishery. Section 7 provides for the protection of fisheries, making it an offence to disturb or injure a several or regulated fishery or to take or remove shellfish without permission. Section 12 confers power to prohibit the deposit of shellfish to prevent disease, and section 13 restricts the importation of shellfish. Section 19 provides the jurisdiction to try certain offences and the application of certain fines. The Act is the foundational regime for exclusive and regulated shellfish fisheries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-serious-crime-act-2015-section-69-possession-paedophile-manual",
    "title": "UK Serious Crime Act 2015 Section 69 - Possession of Paedophile Manual",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 69 of the Serious Crime Act 2015 makes it an offence to be in possession of any item that contains advice or guidance about abusing children sexually. Three statutory defences are available where the defendant proves a legitimate reason for possession, that the defendant had not read/viewed/listened to the item and did not know or have reason to suspect it contained such advice or guidance, or that the item was unsolicited and not kept for an unreasonable time. Maximum penalty in England and Wales on indictment is 3 years' imprisonment and/or a fine. DPP consent is required for prosecution. Closes the gap in UK CSAM legislation that did not previously cover instructional or how-to materials.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_possession_offence_subsection_1",
        "statutory_defences_subsection_2",
        "penalties_subsection_3",
        "dpp_consent_subsection_4",
        "search_seizure_subsection_5_7",
        "definitions_subsection_8",
        "closing_gap_in_child_sexual_abuse_legislation",
        "interaction_with_pca_1978_and_terrorism_act_2000_section_58"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-protection-of-children-act-1978-section-1-indecent-photographs-children",
      "uk-coroners-and-justice-act-2009-section-62-prohibited-images-children"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-1-rape",
    "title": "UK Sexual Offences Act 2003 Section 1 - Rape",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person (A) commits rape if he intentionally penetrates the vagina, anus or mouth of another person (B) with his penis, B does not consent to the penetration, and A does not reasonably believe that B consents. Whether a belief is reasonable is determined having regard to all the circumstances, including any steps A has taken to ascertain whether B consents. Sections 75 (evidential presumptions) and 76 (conclusive presumptions) about consent apply. The offence is indictable only and carries a maximum sentence of life imprisonment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "actus_reus_intentional_penile_penetration_subsection_1_a",
        "absence_of_consent_subsection_1_b",
        "absence_of_reasonable_belief_in_consent_subsection_1_c",
        "reasonable_belief_test_section_1_2",
        "evidential_and_conclusive_consent_presumptions_subsection_3",
        "indictable_only_with_life_maximum_subsection_4",
        "consent_definition_section_74",
        "interaction_with_section_5_rape_of_child_under_13",
        "sentencing_council_guideline_2014_revised"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-5-rape-of-child-under-13"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-10-causing-inciting-child-sexual-activity",
    "title": "UK Sexual Offences Act 2003 Section 10 - Causing or Inciting a Child to Engage in Sexual Activity",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person aged 18 or over (A) commits an offence under Section 10 if he intentionally causes or incites another person (B) to engage in an activity, the activity is sexual, and either B is under 16 and A does not reasonably believe B is 16 or over, or B is under 13. Where the caused or incited activity involved penetrative conduct, the offence is indictable only with up to 14 years' imprisonment. Non-penetrative variants are triable either way: summary up to 6 months and/or statutory maximum fine; indictment up to 14 years. The offence does not require that the sexual activity actually take place.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "elements_subsection_1",
        "causing_or_inciting_inchoate_nature",
        "sexual_activity_definition_section_78",
        "age_routes_under_16_with_belief_defence_or_under_13_strict",
        "penetrative_variant_subsection_2_14_years_indictable",
        "non_penetrative_either_way_subsection_3",
        "automatic_sex_offender_notification_schedule_3",
        "interaction_with_section_8_under_13_and_section_14_arranging_facilitating"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-9-sexual-activity-with-child",
      "uk-sexual-offences-act-2003-section-15-meeting-child-following-grooming"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-11-engaging-sexual-activity-presence-child",
    "title": "UK Sexual Offences Act 2003 Section 11 - Engaging in Sexual Activity in the Presence of a Child",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person aged 18 or over (A) commits an offence under Section 11 if he intentionally engages in an activity that is sexual, for the purpose of obtaining sexual gratification, and does so when another person (B) is present or is in a place from which A can be observed, knowing or believing that B is aware (or intending that B should be aware) that he is engaging in it, and either B is under 16 and A does not reasonably believe B is 16 or over, or B is under 13. Penalty: summary up to 6 months and/or statutory maximum fine; on indictment up to 10 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "elements_subsection_1",
        "self_purpose_sexual_gratification_required",
        "presence_or_observable_place_subsection_1_c_i",
        "awareness_knowledge_belief_or_intention_subsection_1_c_ii",
        "age_routes_under_16_with_belief_defence_or_under_13_strict",
        "section_78_sexual_definition_applies",
        "penalty_subsection_2",
        "automatic_sex_offender_notification_schedule_3",
        "interaction_with_section_12_and_voyeurism_section_67"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-9-sexual-activity-with-child",
      "uk-sexual-offences-act-2003-section-10-causing-inciting-child-sexual-activity",
      "uk-sexual-offences-act-2003-section-15-meeting-child-following-grooming"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-12-causing-child-to-watch-sexual-act",
    "title": "UK Sexual Offences Act 2003 Section 12 - Causing a Child to Watch a Sexual Act",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person aged 18 or over (A) commits an offence under Section 12 if, for the purpose of obtaining sexual gratification, he intentionally causes another person (B) to watch a third person engaging in an activity, or to look at an image of any person engaging in an activity, where the activity is sexual, and either B is under 16 and A does not reasonably believe B is 16 or over, or B is under 13. Penalty: on summary conviction, up to 6 months and/or statutory maximum fine; on indictment up to 10 years. Captures showing pornography, livestream sex acts, or directing a child to watch live sexual activity, all for A's gratification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "elements_subsection_1",
        "two_means_of_commission_watching_or_image",
        "image_definition_per_section_79_4",
        "self_purpose_sexual_gratification_required",
        "sexual_activity_definition_section_78",
        "age_routes_under_16_with_belief_defence_or_under_13_strict",
        "penalty_subsection_2",
        "automatic_sex_offender_notification_schedule_3",
        "interaction_with_section_11_section_47_and_pca_1978_section_1_d"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-11-engaging-sexual-activity-presence-child",
      "uk-sexual-offences-act-2003-section-15a-sexual-communication-with-child"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-13-child-sex-offences-by-under-18s",
    "title": "UK Sexual Offences Act 2003 Section 13 - Child Sex Offences Committed by Children or Young Persons",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 13 of the Sexual Offences Act 2003 provides that a person under 18 who does anything that would constitute an offence under any of Sections 9 to 12 (sexual activity with a child, causing or inciting child sexual activity, engaging in sexual activity in presence of child, causing child to watch a sexual act) if committed by an adult is guilty of an offence. Penalty: on summary conviction, imprisonment up to 6 months or fine or both; on indictment, imprisonment up to 5 years. Section 13 enables prosecution of peer sexual offending while reflecting reduced culpability through significantly lower maximum sentences than the parent adult offences (which carry up to 14 years).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "penalty_subsection_2_a_summary",
        "penalty_subsection_2_b_indictment",
        "incorporates_sections_9_to_12_conduct_definitions",
        "age_threshold_under_18_defendant",
        "reduced_maxima_reflect_youth_culpability",
        "schedule_3_notification_engaged",
        "interaction_with_section_9_to_12_offences",
        "youth_court_jurisdiction_typical",
        "interaction_with_dpp_consent_no_requirement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-9-sexual-activity-with-child",
      "uk-sexual-offences-act-2003-section-10-causing-inciting-child-sexual-activity",
      "uk-sexual-offences-act-2003-section-11-engaging-sexual-activity-presence-child",
      "uk-sexual-offences-act-2003-section-12-causing-child-to-watch-sexual-act"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-14-arranging-facilitating-child-sex-offence",
    "title": "UK Sexual Offences Act 2003 Section 14 - Arranging or Facilitating Commission of a Child Sex Offence",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person commits an offence under Section 14 if he intentionally arranges or facilitates something that he intends to do, intends another person to do, or believes that another person will do, in any part of the world, and doing it will involve the commission of an offence under any of Sections 5-13 SOA 2003. A narrow protective defence applies where the defendant believed (but did not intend) another would commit the act and acted to protect the child from STI, physical harm, pregnancy, or to promote emotional well-being by advice. The penalty matches that of the underlying Section 5-13 offence that would have been committed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "extraterritorial_application_in_any_part_of_the_world",
        "underlying_offences_section_5_to_13",
        "protective_act_defence_subsections_2_3",
        "penalty_matches_underlying_offence_subsection_4",
        "inchoate_nature_offence_complete_on_arranging",
        "interaction_with_section_15_grooming",
        "common_use_cases"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-5-rape-of-child-under-13",
      "uk-sexual-offences-act-2003-section-9-sexual-activity-with-child",
      "uk-sexual-offences-act-2003-section-10-causing-inciting-child-sexual-activity",
      "uk-sexual-offences-act-2003-section-15-meeting-child-following-grooming"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-15-meeting-child-following-grooming",
    "title": "UK Sexual Offences Act 2003 Section 15 - Meeting a Child Following Sexual Grooming Etc (Adult Defendant Aged 18+, Prior Communication, Travel or Meeting With Intent, Child Under 16)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 15 of the Sexual Offences Act 2003 (c. 42) creates the offence of meeting a child following sexual grooming. Under section 15(1), a person aged 18 or over (A) commits an offence if (a) A has met or communicated with another person (B) on one or more occasions and subsequently (i) intentionally meets B, (ii) travels with the intention of meeting B in any part of the world, or arranges to meet B in any part of the world, or (iii) B travels with the intention of meeting A in any part of the world, (b) A intends to do anything to or in respect of B during or after the meeting in any part of the world which, if done, will involve the commission by A of a relevant offence, (c) B is under 16, and (d) A does not reasonably believe that B is 16 or over. Section 15(2)(a) defines 'meeting or communicating' to include any global contact by any means. Section 15(2)(b) defines 'relevant offence' as an offence under Part 1 of the Sexual Offences Act 2003 or equivalent conduct outside England and Wales. Section 15(4) penalty: on summary conviction up to 6 months and/or statutory maximum; on conviction on indictment up to 10 years. Section 15 is the primary UK adult-online-grooming offence and the operative provision for prosecuting online predators who use messaging apps, gaming platforms, and social media to groom children before meeting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_15_text",
        "prior_communication_threshold_section_15_1_a",
        "intent_to_commit_relevant_offence_section_15_1_b",
        "global_jurisdictional_reach_section_15_1_a_ii_iii",
        "section_15a_companion_offence_sexual_communication",
        "penalty_section_15_4",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-section-66-csea-reporting-nca",
      "uk-online-safety-act-2023-section-11-childrens-risk-assessment"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-15a-sexual-communication-with-child",
    "title": "UK Sexual Offences Act 2003 Section 15A - Sexual Communication with a Child",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 15A SOA 2003 (inserted by the Serious Crime Act 2015 Section 67, in force 3 April 2017) makes it an offence for a person aged 18 or over (A) to communicate intentionally with another person (B) for the purpose of obtaining sexual gratification where the communication is sexual or is intended to encourage B to make a sexual communication, and B is under 16 and A does not reasonably believe B is 16 or over. A communication is sexual if any part relates to sexual activity or a reasonable person would consider any part sexual regardless of purpose. Penalty: summary conviction up to the general magistrates' court limit and/or fine; on indictment up to 2 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "elements_subsection_1",
        "sexual_communication_definition_subsection_2",
        "self_purpose_sexual_gratification_required",
        "inchoate_inviting_b_to_make_sexual_communication",
        "age_restriction_under_16_with_belief_defence_only",
        "no_actual_meeting_required_inchoate_offence",
        "penalty_subsection_3",
        "automatic_sex_offender_notification_schedule_3",
        "interaction_with_section_15_meeting_following_grooming"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-15-meeting-child-following-grooming",
      "uk-sexual-offences-act-2003-section-14-arranging-facilitating-child-sex-offence"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-16-abuse-of-position-of-trust",
    "title": "UK Sexual Offences Act 2003 Section 16 - Abuse of Position of Trust: Sexual Activity with a Child",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person aged 18 or over (A) commits an offence under Section 16 if he intentionally touches another person (B), the touching is sexual, A is in a position of trust in relation to B, A meets the knowledge requirements about the trust position, and either B is under 18 and A does not reasonably believe B is 18 or over, or B is under 13 (strict liability). Maximum penalty: 6 months and/or statutory maximum fine on summary conviction; 5 years on indictment. Where the trust position arises only from Sections 21(2)-(5), proof of trust circumstances raises a rebuttable presumption that A knew or could reasonably be expected to be aware of them. Position of trust extended to sports coaching and faith group leadership by PCSC Act 2022.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "elements_subsection_1",
        "knowledge_requirement_subsection_2",
        "evidential_burden_for_age_subsection_3",
        "evidential_burden_for_knowledge_of_trust_subsection_4",
        "penalty_subsection_5",
        "position_of_trust_definition_section_21_extended_2022",
        "section_22_to_24_related_offences_and_definitions",
        "notification_offence_with_5_year_max"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-9-sexual-activity-with-child"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-17-abuse-of-position-of-trust-causing-sexual-activity",
    "title": "UK Sexual Offences Act 2003 Section 17 - Abuse of Position of Trust: Causing or Inciting Sexual Activity",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 17 of the Sexual Offences Act 2003 makes it an offence for a person aged 18 or over (A) intentionally to cause or incite another person (B) to engage in sexual activity, where B is under 18, A is in a position of trust in relation to B, and (where B is 13-17) A does not reasonably believe B is 18 or over. Positions of trust are defined at Section 21 (formal positions: care homes, hospitals, schools, custody institutions, residential homes, foster care) and Section 22A (positions added in 2022 by the Police, Crime, Sentencing and Courts Act: sport coaches, religious leaders). Penalty: on summary conviction, imprisonment up to the general magistrates' court limit or fine or both; on indictment, imprisonment up to 5 years (no penetrative/non-penetrative tier within Section 17 - the uniform 5-year maximum reflects the abuse-of-trust framework). Section 17 parallels Section 16 (direct sexual activity in trust position), Section 18 (sexual activity in presence), and Section 19 (causing child to watch sexual act in trust position).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "circumstances_requirement_subsection_2",
        "penalty_summary_subsection_4_a",
        "penalty_indictment_subsection_4_b",
        "uniform_5_year_max_no_penetrative_distinction",
        "positions_of_trust_section_21_formal_institutional",
        "additional_positions_of_trust_section_22_a_sport_religion_added_2022",
        "absolute_liability_under_13_subsection_1_e_ii",
        "reasonable_belief_in_age_defence_13_17_subsection_1_e_i",
        "marriage_defence_section_23_repealed_in_relevant_part"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-16-abuse-of-position-of-trust",
      "uk-sexual-offences-act-2003-section-9-sexual-activity-with-child"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-18-sexual-activity-in-presence-of-child-position-of-trust",
    "title": "UK Sexual Offences Act 2003 Section 18 - Abuse of Position of Trust: Sexual Activity in the Presence of a Child",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 18 of the Sexual Offences Act 2003 makes it an offence for a person aged 18 or over (A) intentionally to engage in an activity, where the activity is sexual, A engages in it for the purpose of obtaining sexual gratification, A engages in it when another person (B) is present, A knows or believes B is aware or intends B to be aware of the activity, A is in a position of trust in relation to B, and (where B is 13-17) A does not reasonably believe B is 18 or over. Penalty: on summary conviction, imprisonment up to the general magistrates' court limit or fine or both; on indictment, imprisonment up to 5 years. Section 18 captures non-touching exhibitionist or performative sexual conduct by a trust position holder in the presence of a child under 18 - a parallel framework to Section 11 (general non-trust-position case).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "presence_or_observable_subsection_1_d_i",
        "knowledge_or_belief_or_intent_subsection_1_d_ii",
        "purpose_of_sexual_gratification_subsection_1_c",
        "circumstances_requirement_subsection_2",
        "absolute_liability_under_13_subsection_1_g_ii",
        "reasonable_belief_in_age_defence_13_17_subsection_1_g_i",
        "penalty_subsection_4_a_summary",
        "penalty_subsection_4_b_indictment",
        "positions_of_trust_section_21_and_22a_2022_extension",
        "interaction_with_section_11_non_trust_context"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-11-engaging-sexual-activity-presence-child",
      "uk-sexual-offences-act-2003-section-16-abuse-of-position-of-trust",
      "uk-sexual-offences-act-2003-section-17-abuse-of-position-of-trust-causing-sexual-activity"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-19-causing-child-watch-sexual-act-position-of-trust",
    "title": "UK Sexual Offences Act 2003 Section 19 - Abuse of Position of Trust: Causing a Child to Watch a Sexual Act",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 19 of the Sexual Offences Act 2003 makes it an offence for a person aged 18 or over (A), for the purpose of obtaining sexual gratification, intentionally to cause another person (B) to watch a third person engaging in a sexual activity OR to look at an image of any person engaging in a sexual activity, where A is in a position of trust in relation to B and (where B is 13-17) A does not reasonably believe B is 18 or over. Penalty: on summary conviction, imprisonment up to general magistrates' court limit or fine or both; on indictment, imprisonment up to 5 years. Section 19 captures the use of pornography or live sexual conduct as a grooming or abuse mechanism in trust positions - a parallel framework to Section 12 (general non-trust-position context with up to 10 years on indictment).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "purpose_of_sexual_gratification_subsection_1_a",
        "two_modes_live_act_or_image_subsection_1_a_i_ii",
        "circumstances_requirement_subsection_2",
        "absolute_liability_under_13_subsection_1_e_ii",
        "reasonable_belief_in_age_defence_13_17_subsection_1_e_i",
        "penalty_subsection_4_a_summary",
        "penalty_subsection_4_b_indictment",
        "positions_of_trust_section_21_and_22a_2022_extension",
        "interaction_with_section_12_non_trust_context",
        "interaction_with_pca_1978_and_section_62_caja_2009"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-12-causing-child-to-watch-sexual-act",
      "uk-sexual-offences-act-2003-section-16-abuse-of-position-of-trust",
      "uk-sexual-offences-act-2003-section-17-abuse-of-position-of-trust-causing-sexual-activity"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-2-assault-by-penetration",
    "title": "UK Sexual Offences Act 2003 Section 2 - Assault by Penetration",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 2 of the Sexual Offences Act 2003 makes it an offence intentionally to penetrate the vagina or anus of another person (B) with a part of one's body or anything else, where the penetration is sexual, B does not consent, and one does not reasonably believe B consents. Section 2 captures non-penile penetration (digital, object, body part other than penis) as a distinct serious offence - the parallel to Section 1 rape (penile penetration). Penalty: life imprisonment on indictment. Sections 75 (evidential presumptions about consent) and 76 (conclusive presumptions where deception about nature or impersonation) apply. Section 2 is one of the most serious sexual offences in the SOA 2003 framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "reasonable_belief_in_consent_subsection_2",
        "evidential_presumptions_subsection_3",
        "penalty_subsection_4_life_imprisonment",
        "captures_non_penile_penetration",
        "sexual_definition_section_78",
        "consent_definition_section_74",
        "evidential_presumptions_about_consent_section_75",
        "conclusive_presumptions_about_consent_section_76",
        "interaction_with_section_1_rape_section_3_sexual_assault",
        "interaction_with_section_6_assault_by_penetration_under_13"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-1-rape",
      "uk-sexual-offences-act-2003-section-4-causing-sexual-activity-without-consent",
      "uk-sexual-offences-act-2003-section-6-assault-by-penetration-child-under-13"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-25-sexual-activity-with-child-family-member",
    "title": "UK Sexual Offences Act 2003 Section 25 - Sexual Activity with a Child Family Member",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 25 of the Sexual Offences Act 2003 makes it an offence intentionally to touch another person (B) who is under 18 and a family member, where the touching is sexual and A knows or could reasonably be expected to know that B is a family member. Family relationship is defined broadly per Section 27 - including parent, grandparent, brother, sister, half-sibling, aunt, uncle, foster parent, step-parent, cousin, and any person living in the same household with caring/exercising parental functions. Penalty: where A is 18 or over - on summary conviction up to general magistrates' court limit or fine; on indictment up to 14 years (subsection (4)). Where A is under 18 - on summary conviction up to general magistrates' court limit or fine; on indictment up to 5 years (subsection (5)). Subsection (6) defines the penetrative circumstances that trigger the subsection (4) indictment-only route. Reasonable belief defence: defendant reasonably believed B was 18 or over (unless B was under 13 - absolute liability).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "family_relationships_section_27",
        "penalty_subsection_4_adult_perpetrator",
        "penalty_subsection_5_under_18_perpetrator",
        "subsection_6_penetration_definition",
        "reasonable_belief_in_age_defence_b_13_17",
        "absolute_liability_under_13_section_25_1_e_ii",
        "reasonable_belief_in_family_relation_defence",
        "marriage_or_civil_partnership_defence_section_28",
        "interaction_with_section_26_inciting_child_family_member"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-9-sexual-activity-with-child",
      "uk-sexual-offences-act-2003-section-7-sexual-assault-of-child-under-13",
      "uk-children-act-1989-section-17-services-for-children-in-need"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-30-sexual-activity-mental-disorder-impeding-choice",
    "title": "UK Sexual Offences Act 2003 Section 30 - Sexual Activity with a Person with a Mental Disorder Impeding Choice",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 30 of the Sexual Offences Act 2003 makes it an offence for a person (A) intentionally to touch another person (B) sexually where B is unable to refuse because of, or for a reason related to, a mental disorder, and A knows or could reasonably be expected to know that B has a mental disorder and that because of it or for a reason related to it B is likely to be unable to refuse. 'Unable to refuse' means lacking the capacity to choose whether to agree or being unable to communicate such a choice. Penalty: where the touching involved penetration, life imprisonment on indictment; non-penetrative touching, up to 14 years on indictment. The offence protects vulnerable adults with mental disorders affecting capacity - alongside Sections 34-37 covering inducement, threat, deception, and care worker offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "unable_to_refuse_subsection_2",
        "penalty_subsection_3_penetration_life",
        "penalty_subsection_4_non_penetrative",
        "mental_disorder_definition_section_79",
        "capacity_assessment_mental_capacity_act_2005_relevant",
        "interaction_with_sections_31_32_33_inducement_threat_deception",
        "interaction_with_sections_34_37_care_worker_offences",
        "schedule_3_notification_automatic",
        "interaction_with_mental_capacity_act_2005_safeguarding"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-mental-capacity-act-2005-section-2-people-who-lack-capacity",
      "uk-mental-capacity-act-2005-section-3-inability-to-make-decisions",
      "uk-care-act-2014-section-9-assessment-adults-needs-for-care-and-support"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-4-causing-sexual-activity-without-consent",
    "title": "UK Sexual Offences Act 2003 Section 4 - Causing a Person to Engage in Sexual Activity Without Consent",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 4 of the Sexual Offences Act 2003 makes it an offence intentionally to cause another person (B) to engage in sexual activity where B does not consent and the defendant does not reasonably believe that B consents. The offence captures coerced sexual activity where the defendant did not directly engage in the sexual act but caused B to do so - including causing B to engage with a third party, with the defendant himself, or with B's own body. Penalty: where the caused activity involved penetration of B's mouth, anus, vagina, or any object penetration, life imprisonment on indictment. Other Section 4 conduct carries up to 10 years on indictment. Reasonable belief in consent is determined per Section 1(2) with reference to all the circumstances including steps taken by the defendant.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "reasonable_belief_in_consent_subsection_2",
        "evidential_presumptions_subsection_3",
        "penetration_aggravated_form_subsection_4_a_life",
        "non_penetrative_subsection_5_10_years",
        "captures_third_party_self_or_object_directed_activity",
        "consent_definition_section_74",
        "interaction_with_section_1_rape_section_2_assault_by_penetration",
        "interaction_with_section_3_sexual_assault",
        "interaction_with_section_75_76_presumptions"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-1-rape",
      "uk-sexual-offences-act-2003-section-5-rape-of-child-under-13"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-47-paying-for-sexual-services-of-child",
    "title": "UK Sexual Offences Act 2003 Section 47 - Paying for Sexual Services of a Child",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 47 of the Sexual Offences Act 2003 makes it an offence intentionally to obtain, for oneself, the sexual services of a person under 18 in circumstances where one has, before obtaining those services, made or promised payment for them, or where a third person has made or promised payment with the defendant's knowledge or where the defendant has, after obtaining the services, paid or promised payment. Penalty: where the child is under 13, life imprisonment; where the child is 13-15, up to 14 years; where the child is 16-17, up to 7 years. 'Payment' is defined broadly to include any financial advantage, including the discharge of an obligation to pay or the provision of goods or services (including sexual services) gratuitously or at a discount.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "absolute_liability_under_13_subsection_1_c_ii",
        "reasonable_belief_defence_13_to_17_subsection_1_c_i",
        "penalty_under_13_subsection_3_a_life",
        "penalty_13_to_15_subsection_4_14_years",
        "penalty_16_to_17_subsection_5_7_years",
        "payment_definition_subsection_2",
        "sexual_services_term_purposive_construction",
        "interaction_with_section_48_50_third_party_offences",
        "modern_slavery_act_2015_overlap"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-9-sexual-activity-with-child",
      "uk-sexual-offences-act-2003-section-14-arranging-facilitating-child-sex-offence",
      "uk-modern-slavery-act-2015-section-54-transparency-in-supply-chains"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-5-rape-of-child-under-13",
    "title": "UK Sexual Offences Act 2003 Section 5 - Rape of a Child Under 13",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person commits the offence of rape of a child under 13 if he intentionally penetrates the vagina, anus or mouth of another person with his penis and the other person is under 13. The offence is strict liability as to age and consent: belief that the child was 13 or over, or that the child consented, is no defence. The offence is indictable only and carries a maximum sentence of life imprisonment. It is the gravest of the SOA 2003 child-protection offences and underpins the absolute prohibition on penile penetration of children under 13.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "actus_reus_intentional_penile_penetration_subsection_1_a",
        "age_element_under_13_subsection_1_b",
        "no_consent_defence_implicit_in_strict_liability_structure",
        "indictable_only_life_maximum_subsection_2",
        "interaction_with_section_1_rape",
        "section_6_assault_by_penetration_of_child_under_13",
        "automatic_sex_offender_notification",
        "evidential_protections_yjcea_1999"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-1-rape",
      "uk-sexual-offences-act-2003-section-9-sexual-activity-with-child"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-53a-paying-for-sexual-services-forced-prostitute",
    "title": "UK Sexual Offences Act 2003 Section 53A - Paying for Sexual Services of a Prostitute Subjected to Force",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 53A of the Sexual Offences Act 2003 (added by the Policing and Crime Act 2009) makes it a strict liability offence for a person (A) to make or promise payment for the sexual services of a prostitute (B) where a third person (C) has engaged in exploitative conduct of a kind likely to induce or encourage B to provide those services. 'Exploitative conduct' includes use of force, threats (whether or not relating to violence), or any other form of coercion, or any form of deception. It does not matter whether A is, or ought to be, aware that C has engaged in exploitative conduct. Penalty: fine not exceeding level 3 on the standard scale - non-imprisonable summary-only offence. Section 53A is the principal demand-side anti-trafficking provision targeting buyers of services provided under coercion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "strict_liability_subsection_2",
        "exploitative_conduct_subsection_3",
        "penalty_subsection_4_level_3_fine_only",
        "payment_definition_subsection_5",
        "demand_side_anti_trafficking_provision",
        "strict_liability_no_awareness_required",
        "interaction_with_section_47_paying_for_sexual_services_of_child",
        "interaction_with_modern_slavery_act_2015",
        "interaction_with_section_52_53_causing_inciting_controlling_prostitution"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-47-paying-for-sexual-services-of-child",
      "uk-modern-slavery-act-2015-section-2-human-trafficking"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-6-assault-by-penetration-child-under-13",
    "title": "UK Sexual Offences Act 2003 Section 6 - Assault by Penetration of a Child Under 13",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 6 of the Sexual Offences Act 2003 makes it an offence for a person intentionally to penetrate the vagina or anus of a person under 13 with a part of his body or anything else, where the penetration is sexual. Absolute liability applies - no reasonable belief in age defence is available, and consent is irrelevant (in line with the absolute SOA 2003 framework for under-13 victims). Penalty: life imprisonment on indictment. Section 6 is the under-13 analogue to Section 2 (assault by penetration), reflecting the SOA 2003 strict liability framework for the most serious offences against young children. R v G [2008] UKHL 37 upheld this absolute liability framework as compatible with Article 6 ECHR fair trial rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "penalty_subsection_2_life_imprisonment",
        "absolute_liability_no_consent_or_age_defence",
        "captures_non_penile_penetration_of_under_13",
        "sexual_definition_section_78",
        "interaction_with_section_5_rape_of_child_under_13",
        "interaction_with_section_7_sexual_assault_under_13",
        "interaction_with_section_8_causing_inciting_under_13_sexual_activity",
        "indictable_only_offence",
        "automatic_lifelong_schedule_3_notification_for_life_sentence"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-2-assault-by-penetration",
      "uk-sexual-offences-act-2003-section-5-rape-of-child-under-13",
      "uk-sexual-offences-act-2003-section-7-sexual-assault-of-child-under-13",
      "uk-sexual-offences-act-2003-section-8-causing-inciting-child-under-13-sexual-activity"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-61-administering-substance-with-intent",
    "title": "UK Sexual Offences Act 2003 Section 61 - Administering a Substance with Intent",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 61 SOA 2003 makes it an offence to intentionally administer a substance to, or cause a substance to be taken by, another person (B), knowing that B does not consent, and with the intention of stupefying or overpowering B so as to enable any person to engage in a sexual activity that involves B. Captures spiking of drinks, covert drug administration, and date-rape facilitation. The offence is complete on administration with intent - actual sexual activity need not occur. Penalty: summary conviction up to 6 months and/or statutory maximum fine; on indictment up to 10 years. Sex offender notification applies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "elements_subsection_1",
        "administering_or_causing_to_be_taken",
        "knowledge_of_non_consent_required",
        "specific_intent_to_stupefy_or_overpower",
        "inchoate_no_sexual_activity_required",
        "any_person_includes_third_parties",
        "penalty_subsection_2",
        "automatic_sex_offender_notification_schedule_3",
        "interaction_with_section_75_evidential_presumption",
        "interaction_with_offences_against_the_person_act_1861"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-1-rape"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-62-committing-offence-with-intent-sexual-offence",
    "title": "UK Sexual Offences Act 2003 Section 62 - Committing an Offence with Intent to Commit a Sexual Offence",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 62 SOA 2003 creates an aggravated offence where a person commits any offence with the intention of committing a relevant sexual offence under Part 1 SOA 2003. 'Relevant sexual offence' includes the substantive offences and aiding, abetting, counselling or procuring them. Where the underlying offence is committed by kidnapping or false imprisonment, the offence is indictable only and carries life imprisonment. Otherwise, penalty is summary up to 6 months and/or statutory maximum fine; on indictment up to 10 years. Captures preparatory offences (e.g. burglary with intent to commit rape, common assault during attempted sexual offence) and reflects the gravity of sexually-motivated criminal conduct.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "relevant_sexual_offence_definition_subsection_2",
        "any_offence_predicate_breadth",
        "kidnap_or_false_imprisonment_aggravated_life_subsection_3",
        "non_kidnap_penalty_subsection_4",
        "specific_intent_to_commit_part_1_offence_required",
        "interaction_with_section_63_trespass_with_intent",
        "interaction_with_substantive_offence_charging"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-1-rape",
      "uk-sexual-offences-act-2003-section-61-administering-substance-with-intent"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-63-trespass-with-intent-commit-sexual-offence",
    "title": "UK Sexual Offences Act 2003 Section 63 - Trespass with Intent to Commit a Sexual Offence",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 63 of the Sexual Offences Act 2003 makes it an offence to be on any premises as a trespasser, knowing or being reckless as to whether one is a trespasser, with intent to commit a relevant sexual offence on the premises. 'Relevant sexual offence' is any offence under Part 1 of the SOA 2003. Penalty: on summary conviction, imprisonment up to 6 months or fine or both; on indictment, imprisonment up to 10 years. The offence captures preparatory criminal conduct - entry or remaining on premises with sexual offence intent - and provides early intervention authority before the substantive sexual offence is committed. Useful for cases involving stalking with sexual intent, voyeuristic entry, or planned sexual assault interrupted before completion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "trespasser_subsection_2_relevant_sexual_offence",
        "premises_definition_subsection_2",
        "penalty_subsection_3_a_summary",
        "penalty_subsection_3_b_indictment",
        "intent_to_commit_relevant_sexual_offence",
        "knowledge_or_recklessness_as_to_trespass",
        "interaction_with_section_62_commission_with_intent",
        "schedule_3_notification_engaged",
        "interaction_with_burglary_theft_act_1968_section_9"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-1-rape",
      "uk-sexual-offences-act-2003-section-62-committing-offence-with-intent-sexual-offence",
      "uk-voyeurism-offences-act-2019-section-1-upskirting-section-67a-soa"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-66-exposure",
    "title": "UK Sexual Offences Act 2003 Section 66 - Exposure",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 66 of the Sexual Offences Act 2003 makes it an offence for a person intentionally to expose their genitals where they intend that someone will see them and be caused alarm or distress. The offence captures so-called 'flashing' conduct and replaces older common law and statutory provisions (Vagrancy Act 1824 indecent exposure). Penalty: on summary conviction, imprisonment up to 6 months or fine or both; on indictment, imprisonment up to 2 years. The offence may also trigger Schedule 3 SOA 2003 sex offender notification where sentencing thresholds are met. Exposure with sexual content captured in image form may engage parallel voyeurism / upskirting offences (Section 67 / 67A).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "penalty_subsection_2_a_summary",
        "penalty_subsection_2_b_indictment",
        "intent_to_be_seen_and_to_cause_alarm_or_distress",
        "genitals_definition_includes_male_and_female",
        "no_requirement_that_victim_actually_saw_or_was_distressed",
        "schedule_3_notification_threshold_dependent",
        "interaction_with_voyeurism_section_67_67a",
        "interaction_with_section_4_public_order_act_1986"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-66a-66b-cyberflashing-intimate-image",
      "uk-voyeurism-offences-act-2019-section-1-upskirting-section-67a-soa"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-66a-66b-cyberflashing-intimate-image",
    "title": "UK Sexual Offences Act 2003 Section 66A (Cyberflashing) and Section 66B (Sharing or Threatening to Share Intimate Photograph or Film) - As Inserted by the Online Safety Act 2023",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Sections 66A, 66B, 66C, and 66D of the Sexual Offences Act 2003 (c. 42) of the United Kingdom, as inserted by the Online Safety Act 2023 (c. 50), create new criminal offences targeting the non-consensual sending of images of genitals (cyberflashing) and the sharing or threatening to share intimate photographs or films. Section 66A creates the cyberflashing offence: a person (A) commits an offence by intentionally sending or giving a photograph or film of any person's genitals to another person (B) where (a) A intends that B will see the genitals and be caused alarm, distress, or humiliation, or (b) A sends or gives such a photograph or film for the purpose of obtaining sexual gratification and is reckless as to whether B will be caused alarm, distress, or humiliation. Sending or giving includes sending by any means electronically or otherwise, showing in person, and placing for a particular person to find. Section 66A is triable either way - on summary conviction the penalty is imprisonment up to the general limit in a magistrates' court (or 51 weeks under section 66A as commenced) or a fine or both; on conviction on indictment, imprisonment up to 2 years. Section 66B creates four related intimate image sharing offences: (1) intentionally sharing a photograph or film showing or appearing to show another person in an intimate state without that person's consent and without reasonable belief in consent; (2) intentional sharing with the intention of causing B alarm, distress, or humiliation without consent; (3) intentional sharing for the purpose of obtaining sexual gratification without consent or reasonable belief in consent; (4) threatening to share an intimate photograph or film with intent or recklessness as to whether the threatened person or someone who knows them will fear the threat's execution. The section 66B(1) base offence is summary-only with 6 months (or 51 weeks) imprisonment; subsections (2), (3), and (4) are triable either way with up to 2 years on indictment. Section 66B(8) provides a reasonable excuse defence for the 66B(1) base offence; section 66C contains exemptions and the definition of intimate state. The offences sit within Chapter 1 of Part 1 of the 2003 Act and are recordable for the sex offender register implications under sections 80-93 SOA 2003 where applicable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "key_institutions",
        "section_66a_cyberflashing_elements",
        "section_66a_sending_definition",
        "section_66a_penalties",
        "section_66b_four_offences_taxonomy",
        "section_66c_exemptions_and_intimate_state_definition",
        "online_safety_act_2023_platform_duties_interface",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-part-3-illegal-content-children-duties",
      "uk-online-safety-act-2023-part-5-pornographic-content-duties",
      "ca-criminal-code-162-1-intimate-image-without-consent",
      "us-vawa-violence-against-women-act-1994-pl-103-322"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-67-voyeurism",
    "title": "UK Sexual Offences Act 2003 Section 67 - Voyeurism (Observing Private Act for Sexual Gratification, Operating Equipment, Recording, Installing Equipment)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 67 of the Sexual Offences Act 2003 (c. 42) creates four voyeurism offences. Under section 67(1), a person commits an offence if (a) for the purpose of obtaining sexual gratification he observes another person doing a private act, and (b) he knows that the other person does not consent to being observed for his sexual gratification. Under section 67(2), a person commits an offence if (a) he operates equipment with the intention of enabling another person to observe, for the purpose of obtaining sexual gratification, a third person (B) doing a private act, and (b) he knows that B does not consent to his operating equipment with that intention. Under section 67(3), a person commits an offence if (a) he records another person (B) doing a private act, (b) he does so with the intention that he or a third person will, for the purpose of obtaining sexual gratification, look at an image of B doing the act, and (c) he knows that B does not consent to his recording the act with that intention. Under section 67(4), a person commits an offence if he installs equipment, or constructs or adapts a structure or part of a structure, with the intention of enabling himself or another person to commit an offence under subsection (1). Penalty under section 67(5): on summary conviction up to 6 months and/or statutory maximum; on indictment up to 2 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_67_text",
        "private_act_definition_section_68",
        "sexual_gratification_test",
        "upskirting_section_67a_companion",
        "penalty_section_67_5_and_register",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-66a-66b-cyberflashing-intimate-image"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-7-sexual-assault-of-child-under-13",
    "title": "UK Sexual Offences Act 2003 Section 7 - Sexual Assault of a Child Under 13",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 7 of the Sexual Offences Act 2003 makes it an offence for a person intentionally to touch another person sexually where that other person is under 13. Absolute liability applies - no reasonable belief in age defence is available. Penalty: on summary conviction, imprisonment up to 6 months or fine or both; on indictment, imprisonment up to 14 years. Section 7 is the under-13 analogue to Section 3 (sexual assault), reflecting the SOA 2003 strict liability framework for offences against children under 13. The offence applies whether or not the touching was through clothing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "penalty_subsection_2_a_summary",
        "penalty_subsection_2_b_indictment",
        "absolute_liability_no_reasonable_belief_in_age_defence",
        "touching_definition_section_79_8",
        "sexual_definition_section_78",
        "interaction_with_section_3_sexual_assault_16_plus_victim",
        "interaction_with_section_5_rape_of_child_under_13",
        "schedule_3_notification_automatic",
        "interaction_with_section_8_causing_inciting_under_13_sexual_activity"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-5-rape-of-child-under-13",
      "uk-sexual-offences-act-2003-section-9-sexual-activity-with-child"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-72-offences-outside-uk",
    "title": "UK Sexual Offences Act 2003 Section 72 - Offences Outside the United Kingdom",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 72 of the Sexual Offences Act 2003 establishes extraterritorial jurisdiction for UK nationals or UK residents who commit specified sexual offences against children abroad. Where a UK national or UK resident does an act in a country outside the UK that (a) constitutes an offence under the law in force in that country; and (b) would constitute one of the listed sexual offences against a child if done in the UK, that person may be prosecuted in the UK as if the act had been done here. The list at Schedule 2 includes most child sexual offences (Sections 5-10, 14-15, 16-19, 25-29, 47-50). The provision underpins UK 'child sex tourism' prosecutions and operates in tandem with similar provisions in other Council of Europe states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_extraterritorial_jurisdiction_subsection_1",
        "uk_resident_jurisdiction_subsection_2",
        "any_person_uk_or_resident_subsection_3",
        "double_criminality_requirement_for_residents_and_others",
        "scope_of_offences_schedule_2",
        "uk_national_definition_subsection_8",
        "uk_resident_definition_subsection_8",
        "originally_part_of_uk_child_sex_tourism_law",
        "interaction_with_section_4_4_serious_crime_act_2007"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-5-rape-of-child-under-13",
      "uk-sexual-offences-act-2003-section-9-sexual-activity-with-child",
      "uk-sexual-offences-act-2003-section-15a-sexual-communication-with-child",
      "uk-sexual-offences-act-2003-section-47-paying-for-sexual-services-of-child"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-8-causing-inciting-child-under-13-sexual-activity",
    "title": "UK Sexual Offences Act 2003 Section 8 - Causing or Inciting a Child Under 13 to Engage in Sexual Activity",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 8 of the Sexual Offences Act 2003 makes it an offence intentionally to cause or incite another person to engage in an activity, where that activity is sexual and the other person is under 13. Absolute liability applies - no reasonable belief in age defence is available. Penalty: where the caused or incited activity involved penetration of the under-13's anus or vagina with anything, of the under-13's mouth with a penis, of someone else's anus or vagina with the under-13's body, or of someone else's mouth with the under-13's penis, life imprisonment on indictment. Other Section 8 conduct: on summary conviction, up to 6 months and/or fine; on indictment, up to 14 years. Section 8 is the under-13 strict-liability analogue to Section 4 (causing sexual activity without consent) and Section 10 (causing or inciting child sexual activity, 13-15).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_1",
        "penetrative_aggravated_form_subsection_2_life",
        "non_penetrative_subsection_3_summary_or_indictment",
        "absolute_liability_no_reasonable_belief_in_age_defence",
        "causation_or_incitement_distinct_modes",
        "interaction_with_section_7_sexual_assault_under_13",
        "interaction_with_section_10_causing_inciting_13_15",
        "interaction_with_section_5_rape_section_6_assault_by_penetration",
        "online_grooming_and_remote_offence_capture",
        "schedule_3_notification_automatic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-5-rape-of-child-under-13",
      "uk-sexual-offences-act-2003-section-7-sexual-assault-of-child-under-13",
      "uk-sexual-offences-act-2003-section-10-causing-inciting-child-sexual-activity"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-sexual-offences-act-2003-section-9-sexual-activity-with-child",
    "title": "UK Sexual Offences Act 2003 Section 9 - Sexual Activity with a Child",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "A person aged 18 or over (A) commits an offence if he intentionally touches another person (B), the touching is sexual, and either B is under 16 and A does not reasonably believe that B is 16 or over, or B is under 13. Penetrative touching (vagina, anus, mouth with penis or any object) is indictable only and carries up to 14 years' imprisonment. Non-penetrative touching is triable either way: summary up to 6 months and/or statutory maximum fine, indictable up to 14 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "elements_subsection_1",
        "age_of_defendant_18_or_over_threshold",
        "sexual_touching_definition_sections_78_79",
        "two_routes_for_b_under_16_with_belief_defence_or_under_13_strict",
        "penetrative_touching_subsection_2_14_years_indictable",
        "non_penetrative_either_way_subsection_3",
        "interaction_with_section_5_rape_of_child_under_13",
        "automatic_sex_offender_notification_schedule_3"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-5-rape-of-child-under-13",
      "uk-sexual-offences-act-2003-section-1-rape"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-shared-rural-network-agreement-2020",
    "title": "UK Shared Rural Network Agreement 2020 - MNO Commitments: 95% Geographic Coverage, Shared Infrastructure, and Ofcom Monitoring Framework",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Mobile Network Operators (EE, Three, O2, Vodafone) must achieve 95% geographic coverage of the UK by 2026 through shared infrastructure deployment, excluding spot coverage, with priority in the Scottish Highlands, as monitored by Ofcom under the Shared Rural Network (SRN) Agreement. Key obligation: Clause 3.1 - Geographic Coverage Target and Infrastructure Sharing Commitment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "eu-broadband-cost-reduction-directive-2014-61",
      "eu-radio-spectrum-policy-programme-decision"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-si-2015-51-construction-design-management-regulations",
    "title": "UK SI 2015/51 - Construction (Design and Management) Regulations 2015 (CDM 2015)",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "The Construction (Design and Management) Regulations 2015 (UK SI 2015/51) implement EU Directive 92/57/EEC on minimum safety and health requirements at temporary or mobile construction sites and place duties on all parties to a construction project to manage health and safety risks throughout the project lifecycle: Part 1 (Regulations 1-3) sets out introduction and application including extraterritorial scope; Part 2 (Regulations 4-7) establishes client duties as the foundational accountability layer including Regulation 4 client duties in relation to managing projects, Regulation 5 appointment of the principal designer and the principal contractor, Regulation 6 notification requirements (HSE F10 notification for projects exceeding 30 working days with more than 20 workers or 500 person-days), and Regulation 7 application to domestic clients; Part 3 (Regulations 8-15) establishes health and safety duties of designers, principal designers, principal contractors, and contractors; Part 4 (Regulations 16-35) sets out general construction site requirements including site safety, stability, excavations, fire prevention, lighting, and welfare facilities; Part 5 (Regulations 36-39) covers enforcement, transitional provisions, and review; the regulations are enforced by the Health and Safety Executive (HSE) under the Health and Safety at Work etc. Act 1974 with civil and criminal penalties for breach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "predecessor_cdm_regulations_2007",
        "health_and_safety_at_work_act_1974",
        "eu_directive_92_57_eec",
        "industry_mapping",
        "enforcement_anchors",
        "domestic_client_specific_framework_regulation_7"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-public-contracts-regulations-2015-si-102",
      "us-40-usc-3142-davis-bacon-prevailing-wage",
      "us-40-usc-3131-miller-act-federal-construction-bonds"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-si-2020-1062-vsp-regime-communications-act",
    "title": "UK SI 2020/1062 Regulation 47 - Video-Sharing Platform Services Regime (Communications Act 2003 Part 4B)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "The Audiovisual Media Services Regulations 2020 (UK SI 2020/1062) implemented the EU Audiovisual Media Services Directive (Directive 2010/13/EU as amended by Directive 2018/1808) in UK law; Regulation 47 inserted Part 4B (sections 368S-368Z11) into the Communications Act 2003 establishing the regulatory framework for Video-Sharing Platform (VSP) services - including duties to take 'appropriate measures' set out in new Schedule 15A to protect minors from restricted material and the general public from harmful content (incitement to violence/hatred, content constituting criminal offence including child sexual abuse material, terrorism content, racism, xenophobia); section 368S defines a VSP as a service where the provision of programmes or user-generated videos is the principal purpose or essential functionality, provided commercially via electronic communications networks, where the provider exercises control over organization but not selection of content; OFCOM was designated as the appropriate regulatory authority with enforcement powers including notification duties (section 368V), publication-and-compliance duties (section 368Y), the appropriate-measures duty (section 368Z1), and financial penalties up to 5% of qualifying revenue or £250,000 (whichever greater) under sections 368Z5-Z6, with serious contraventions permitting service suspension; the VSP regime was largely replaced by the Online Safety Act 2023 from 26 October 2023 (with transition arrangements through 2024-2025) but remains operative for legacy enforcement and as the foundational definitional framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "implementing_eu_directive",
        "successor_regime",
        "ofcom_codes_of_practice",
        "industry_mapping",
        "enforcement_anchors",
        "appropriate_measures_under_schedule_15a"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-online-safety-act-2023-part-5-pornographic-content-duties",
      "uk-online-safety-act-2023-section-12-risk-assessment-duties-services",
      "uk-online-safety-act-2023-section-36-safety-duties-priority-content"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-smcr-senior-manager-certification",
    "title": "Senior Managers and Certification Regime (SMCR)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-07-25",
    "bluf": "The UK's Senior Managers and Certification Regime (SMCR) establishes a framework for individual accountability in regulated financial services firms, requiring firms to clearly allocate responsibilities to Senior Managers (Senior Management Functions - SMFs) and annually certify that other key staff are fit and proper for their roles, as mandated by the Financial Services and Markets Act 2000 (FSMA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fca-consumer-duty-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-smcr-senior-managers-certification-regime-2016",
    "title": "UK Senior Managers and Certification Regime (SMCR) - Individual Accountability in Financial Services",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The UK Senior Managers and Certification Regime (SMCR), established under the Financial Services (Banking Reform) Act 2013 and extended to all FCA/PRA-authorised firms by December 2019, replaces the Approved Persons Regime with three tiers of individual accountability. Senior Managers (SMFs) require pre-approval by PRA or FCA, must have a Statement of Responsibilities (SoR), and face criminal liability for reckless decisions causing failure. Certified Persons must be annually certified by their firm as fit and proper. All staff are subject to Conduct Rules. SMCR also mandates regulatory references on departure and a Responsibilities Map for firms above the Enhanced tier threshold.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "eu-market-abuse-regulation-596-2014",
      "eu-employment-equality-directive-2000-78"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-somalia-sanctions-eu-exit-regulations-2020-si-642",
    "title": "UK Somalia (Sanctions) (EU Exit) Regulations 2020 SI 2020/642 UN Arms Embargo Charcoal Ban IED Components Controls and Maritime Enforcement",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Somalia (Sanctions) (EU Exit) Regulations 2020 establish the United Kingdom framework implementing the UN Security Council Somalia sanctions regime organised in 10 parts covering general provisions in Part 1, designation in Part 2 based on UN Security Council Resolution 751 (1992) and successors, finance restrictions in Part 3 with asset freezes and prohibitions on making funds available, immigration measures in Part 4, trade restrictions in Part 5 across six chapters covering military goods and technology arms embargo charcoal export ban improvised explosive device components controls and related activities, exceptions and licences in Part 6, information and records in Part 7, enforcement in Part 8 with criminal penalties and OFSI monetary penalties, maritime enforcement in Part 9 with boarding and seizure powers including off the Somali coast, and supplementary provisions in Part 10. The Regulations include three schedules covering interpretation rules trade definitions and Treasury licensing purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-south-sudan-sanctions-eu-exit-regulations-2019-si-438",
    "title": "UK South Sudan (Sanctions) (EU Exit) Regulations 2019 SI 2019/438 UN Security Council Implementation Asset Freeze and Trade Restrictions on Military Goods",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The South Sudan (Sanctions) (EU Exit) Regulations 2019 establish the United Kingdom's framework implementing the UN Security Council South Sudan sanctions regime organised in 9 parts covering general provisions in Part 1, designation mechanisms in Part 2 incorporating direct UN Security Council designations and ownership and control rules in regulation 7, financial restrictions in Part 3 including asset freeze and prohibitions on making funds or economic resources available to designated persons without authorisation, immigration controls in Part 4, an extensive Part 5 trade regime across four chapters covering definitions of military goods and technology export and supply restrictions transfer prohibitions technical assistance limitations and circumvention provisions, Treasury and trade licensing for humanitarian purposes basic needs legal services and maintenance of frozen assets in Part 6, information reporting obligations for financial firms in Part 7, criminal enforcement penalties and jurisdiction in Part 8, and maritime enforcement powers for boarding search and seizure in Part 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-space-industry-act-2018-c5",
    "title": "Space Industry Act 2018",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The Space Industry Act 2018 establishes a regulatory framework for spaceflight and associated activities in the UK, requiring operator and spaceport licences under Section 8, mandating safety and environmental assessments under Sections 9 and 11, enforcing insurance and indemnity obligations under Section 38, and channelling liability to operators with a minimum insurance threshold of £10 million under Section 34. It applies to all entities conducting spaceflight activities from the UK or on UK-licensed spacecraft.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-8374-ransomware-risk-management",
      "uk-cma-merger-assessment-guidelines-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-space-industry-act-2018-caa",
    "title": "UK Space Industry Act 2018 - CAA Spaceflight Licensing, Operator Liability and Spaceport Authorisation",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The UK Space Industry Act 2018 (c.5) and the Space Industry Regulations 2021 (SI 2021/792) establish the United Kingdom's domestic licensing framework for spaceflight activities, designating the Civil Aviation Authority (CAA) as the primary spaceflight regulator and conferring on the Secretary of State powers to authorise spaceports and grant operator licences; the Act creates three principal licence types: a launch operator licence (for entities launching spacecraft), a range control service licence (for entities providing range safety services), and a spaceport operator licence (for entities operating launch facilities from UK territory); applicants must demonstrate: financial capacity to meet the minimum insurance threshold (currently GBP 60 million per launch event or higher as CAA determines by risk assessment), a safety case accepted by the CAA Spaceflight Team, a range safety plan, and compliance with the UK's obligations under the Outer Space Treaty 1967, the Liability Convention 1972, and the Registration Convention 1975; the Act creates a strict liability regime for the UK government vis-a-vis foreign states for damage caused by licensed UK launch activities, with the operator required to indemnify the government up to the licensed insurance amount; the Spaceflight Activities (Investigation of Spaceflight Accidents) Regulations 2021 require mandatory reporting and investigation of spaceflight accidents; the CAA published the CAP 2616 Spaceflight Licensing Guidance in 2023 as the principal operational guide for applicants.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967-article-vi-state-responsibility"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-space-industry-act-2018-launch-authorisation-insurance",
    "title": "UK Space Industry Act 2018 - Launch Authorisation, Operator Licensing, and Insurance Requirements for Commercial Spaceflight",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The UK Space Industry Act 2018 (SIA) establishes the domestic legal framework for regulating commercial spaceflight activities from the United Kingdom, including vertical launches, horizontal launches, and sub-orbital flight operations. The Act requires operators to obtain an operator licence and a launch site licence before conducting regulated activities. The Civil Aviation Authority (CAA) is the primary regulatory authority for spaceflight licensing. Operators must carry third-party liability insurance at a level specified by the regulator, and the Secretary of State must authorise each individual launch or series of launches. The SIA implements the UK's international obligations under the OST, Liability Convention, and Registration Convention in the context of commercial spaceflight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967-article-vi-state-responsibility",
      "intl-outer-space-treaty-1967-article-7-liability-damage"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-space-industry-act-2018-section-3-launch-operator-licence",
    "title": "Space Industry Act 2018, Section 3: Operator licence",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This section mandates that any person, particularly a UK entity, must obtain an operator licence to operate a spaceport, launch a vehicle, procure a launch, or operate a satellite in orbit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-space-industry-act-2018-section-34-liability",
    "title": "Space Industry Act 2018, Section 34: Operator's liability for injury or damage",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This section establishes a duty for spaceflight operators and their customers to indemnify any third party for injury or damage resulting from their spaceflight activities, regardless of fault.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-space-industry-regulations-2021",
    "title": "UK Space Industry Regulations 2021 - Launch Licensing and Safety Requirements",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Any person seeking to carry out spaceflight activities from the UK or operating as a range control service provider must obtain a licence from the Civil Aviation Authority (CAA) under the Space Industry Act 2018. The Space Industry Regulations 2021 set detailed safety, insurance, investigation, and return-to-Earth requirements for operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "space_industry_act",
        "outer_space_treaty",
        "liability_convention",
        "range_control",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-space-industry-act-2018-c5",
      "un-outer-space-treaty-1967",
      "un-liability-convention-1972-space-objects",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-stalking-protection-act-2019-section-2-stalking-protection-order",
    "title": "UK Stalking Protection Act 2019 Section 2 - Stalking Protection Orders",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 2 of the Stalking Protection Act 2019 empowers a magistrates' court, on application by a chief officer of police, to make a Stalking Protection Order (SPO) against a person where the court is satisfied on the balance of probabilities that (a) the defendant has carried out acts associated with stalking; (b) the defendant poses a risk associated with stalking to another person; and (c) there is reasonable cause to believe the proposed order is necessary to protect another person from such a risk. The order may impose prohibitions or requirements for a specified period of at least 2 years (with no maximum) - including prohibition on contact, geographical exclusion, electronic monitoring, surrender of devices, attendance at perpetrator programmes. Breach of the order is a criminal offence under Section 8 with up to 5 years on indictment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "application_by_chief_officer_subsection_1",
        "three_part_test_subsection_2",
        "balance_of_probabilities_civil_standard_section_2_2",
        "prohibition_or_requirement_subsection_3",
        "duration_at_least_2_years_subsection_4",
        "different_durations_for_different_terms_subsection_5",
        "associated_with_stalking_section_1_definition",
        "interaction_with_section_8_breach_offence",
        "interim_order_section_5_pending_full_hearing",
        "interaction_with_protection_from_harassment_act_1997_section_5_restraining_order"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-protection-from-harassment-act-1997-section-1-prohibition-of-harassment",
      "uk-protection-from-harassment-act-1997-section-4-fear-of-violence"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-strategic-export-control",
    "title": "UK Strategic Export Control",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The UK Strategic Export Control regime (Export Control Act 2002) is the primary regulation for the export of military and dual-use technology from the United Kingdom. It is managed by the Export Control Joint Unit (ECJU) and utilizes the Consolidated List to determine licensing requirements for international trade and defense cooperation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-streamlined-energy-carbon-reporting-secr-companies-act-2006-amendment",
    "title": "UK SECR - Streamlined Energy and Carbon Reporting under Companies Act 2006 Amendment",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "UK Streamlined Energy and Carbon Reporting (SECR) regulations (The Companies (Directors' Report) and Limited Liability Partnerships (Energy and Carbon Report) Regulations 2018) require large UK companies and LLPs to report annual energy use, Scope 1 and 2 GHG emissions, energy efficiency improvements, and a Responsible Party statement in their annual Directors' Report. Quoted companies must additionally report global Scope 1 and 2 emissions. SECR applies to companies consuming more than 40,000 kWh in the reporting year or qualifying as large under the Companies Act 2006.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "tcfd-recommendations-climate-related-financial-disclosures-financial-stability"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-subsidy-control-act-2022",
    "title": "UK Subsidy Control Act 2022 - Seven Principles and CMA Subsidy Advice Unit",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Subsidy Control Act 2022 (2022 chapter 23) establishes the United Kingdom's post-Brexit domestic subsidy control regime, replacing the application of EU State aid rules with a UK-specific framework anchored on seven subsidy control principles set out in Schedule 1 to the Act. The seven principles require every subsidy to pursue a specific policy objective addressing a market failure or equity rationale (Principle A), to be proportionate to and necessary for that objective (Principle B), to be designed to bring about a change of economic behaviour by the beneficiary (Principle C), to avoid covering costs the beneficiary would have funded absent the subsidy (Principle D), to be the least distortive means of achieving the policy objective (Principle E), to minimise negative effects on competition and investment within the United Kingdom (Principle F), and to ensure that beneficial effects outweigh negative effects on competition, investment, and international trade (Principle G). The Act is organised into 6 parts and 92 sections, with Part 1 defining key terms, Part 2 imposing the subsidy control requirements on public authorities, Part 3 setting out exemptions, Part 4 establishing the Subsidy Advice Unit at the Competition and Markets Authority for referrals on subsidies of interest and subsidies of particular interest, Part 5 prescribing enforcement through the Competition Appeal Tribunal, and Part 6 covering subsidy schemes and miscellaneous provisions. Public authorities (including ministers, devolved administrations, local councils, and other bodies exercising functions of a public nature) must assess each subsidy or subsidy scheme against the seven principles, ensure compatibility with the energy and environment additional principles where applicable, and upload the award to the public subsidy database within the statutory transparency window. AI procurement, R&D grant, regional levelling-up funding, and net-zero support measures all fall within scope and require a documented Schedule 1 assessment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-competition-act-1998",
      "eu-state-aid-article-107-108-tfeu-framework",
      "wto-scm-agreement-1994-subsidies-countervailing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-sudan-sanctions-eu-exit-regulations-2020-si-753",
    "title": "UK Sudan (Sanctions) (EU Exit) Regulations 2020 SI 2020/753 UN Darfur Arms Embargo Asset Freezes Trade Restrictions and Maritime Enforcement",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Sudan (Sanctions) (EU Exit) Regulations 2020 establish the United Kingdom framework implementing the UN Security Council Sudan and Darfur sanctions regime organised in 10 parts covering general provisions in Part 1, designation in Part 2 based on UN Security Council Resolution 1591 (2005) criteria including persons impeding the peace process or violating international humanitarian law in Darfur, finance restrictions in Part 3 with asset freezes and prohibitions on making funds available, immigration measures in Part 4, trade restrictions in Part 5 covering military goods technology and related services and the Darfur arms embargo, exceptions and licences in Part 6, information and records in Part 7, enforcement in Part 8 with criminal penalties and OFSI monetary penalties, maritime enforcement in Part 9 with stop board search and seizure powers, and supplementary provisions in Part 10. The Regulations include two schedules covering ownership interpretation rules and Treasury licensing purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-syria-sanctions-eu-exit-regulations-2019-si-792",
    "title": "UK Syria (Sanctions) (EU Exit) Regulations 2019 SI 2019/792 - Asset Freeze Trade Restrictions Aircraft Sanctions and Chemical Weapons Controls",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Syria (Sanctions) (EU Exit) Regulations 2019 establish the United Kingdom's autonomous sanctions framework targeting the Syrian regime and connected persons organised in eleven parts covering general provisions and purposes in Part 1, designation of persons in Part 2, financial sanctions including asset freeze and prohibitions on investment and financial services with Syrian entities and anti-circumvention measures in Part 3, immigration sanctions in Part 4, an extensive Part 5 trade regime across six chapters covering prohibitions on exporting military goods technology and dual-use items, import restrictions on arms crude oil and petroleum products, prohibitions on luxury goods and chemical and biological weapons related materials, and interception and monitoring services, aircraft movement restrictions in Part 6, exceptions and licences in Part 7, reporting and information obligations in Part 8, enforcement and penalties in Parts 9 to 10, and maritime enforcement authority for stop board and search operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-taxation-cross-border-trade-act-2018",
    "title": "United Kingdom Taxation (Cross-border Trade) Act 2018: Charge to Import Duty, Chargeable Goods, the Customs Tariff, Dumping and Foreign Subsidies and Safeguards, Place of Origin, Charge to Export Duty, Regulations, and the Single United Kingdom Customs Territory",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Taxation (Cross-border Trade) Act 2018, chapter 22 of 2018, is the principal United Kingdom statute providing the post-EU-exit framework for the imposition of customs duties on imports into the United Kingdom and is administered by Her Majesty's Revenue and Customs and the Department for Business and Trade. Taxation (Cross-border Trade) Act 2018, section 1 imposes the charge to import duty on goods imported into the United Kingdom. Taxation (Cross-border Trade) Act 2018, section 2 defines chargeable goods. Taxation (Cross-border Trade) Act 2018, section 8 provides for the customs tariff including the requirement that the Treasury must make regulations establishing the United Kingdom global tariff. Taxation (Cross-border Trade) Act 2018, section 13 governs dumping of goods, foreign subsidies and increases in imports and provides the statutory basis for UK trade remedies investigations conducted by the Trade Remedies Authority. Taxation (Cross-border Trade) Act 2018, section 17 governs the place of origin of chargeable goods. Taxation (Cross-border Trade) Act 2018, section 32 provides regulation-making powers and parliamentary procedures. Taxation (Cross-border Trade) Act 2018, section 39 imposes a charge to export duty in defined circumstances. Taxation (Cross-border Trade) Act 2018, section 55 provides for the single United Kingdom customs territory. The Act is the controlling United Kingdom post-EU-exit customs and trade remedies statute and operates alongside the Trade Act 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-tcfd-mandatory-reporting-2022",
    "title": "Mandatory Climate-related Financial Disclosures by UK Companies, LLPs and FCA-regulated Issuers",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Requires UK-registered companies and LLPs exceeding specific size thresholds, as well as FCA-regulated issuers, to disclose climate-related financial information in their annual reports, consistent with the four pillars of the TCFD framework (Governance, Strategy, Risk Management, and Metrics & Targets) as mandated by The Companies (Strategic Report) (Climate-related Financial Disclosure) Regulations 2022 and FCA Listing Rule 9.8.6R(8).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "tcfd-climate-related-financial-disclosures",
      "ghg-protocol-scope3",
      "issb-ifrs-s2-climate-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-telecommunications-security-act-2021-ofcom-vendor",
    "title": "UK Telecommunications (Security) Act 2021 - Public Telecoms Network and Service Security Duties",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Telecommunications (Security) Act 2021 (UK) amends the Communications Act 2003 to create a statutory security framework for public electronic communications networks and services through new sections 105A onwards. Section 1 of the 2021 Act establishes the overarching duty for providers to identify and reduce the risks of security compromises. Section 2 covers measures in response to security compromises. Section 3 enables codes of practice to give guidance on compliance. Section 7 grants Ofcom powers to enforce compliance with security duties. The financial penalty framework is in inserted Communications Act 2003 section 105T, providing maximum daily penalties of 100,000 pounds for general security duty contraventions, 50,000 pounds per day for failures relating to inspection notices, and lump sum penalties up to 10 million pounds. Section 14 of the 2021 Act provides for reviews of sections 1 to 13. Sections 15 to 24 create the Designated Vendor Direction regime enabling the Secretary of State to issue legally binding directions restricting use of specified vendors in UK public telecoms networks on national security grounds. The Electronic Communications (Security Measures) Regulations 2022 (SI 2022/933) and the Telecommunications Security Code of Practice (December 2022) provide detailed measures and tier-based timelines for Tier 1, Tier 2, and Tier 3 providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-communications-act-2003-ofcom-framework",
      "uk-electronic-communications-act-2000",
      "uk-investigatory-powers-act-2016-telecoms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-telecoms-security-act-2021-c31",
    "title": "UK Telecommunications Security Act 2021 c.31 Provider Security Duties Designated Vendor Directions OFCOM Enforcement and Code of Practice Framework",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "The United Kingdom Telecommunications (Security) Act 2021 c.31 establishes a statutory framework for the security of public electronic communications networks and services organised in 9 parts covering Part 1 Duties of providers including section 1 overarching security duty section 2 specific security duties and section 3 codes of practice issued by the Secretary of State, Part 2 Informing others including section 4 obligations to inform users of security compromises, Part 3 Securing compliance including sections 5 through 10 establishing OFCOM oversight inspection powers and enforcement notices, Part 4 Reports on security including sections 11 through 14 covering reporting requirements appeals and provider information notices, Part 5 Designated vendor directions including sections 15 through 17 empowering the Secretary of State to issue directions restricting use of equipment supplied by specified vendors on national security grounds, Part 6 Monitoring and enforcement including sections 18 through 21 with inspection notices civil penalties of up to 10 percent of relevant turnover or 100000 pounds per day and criminal offences for noncompliance, Part 7 Vendor directions provisions on disclosure restrictions and information requests, Part 8 Further amendments addressing penalties and consequential changes to the Communications Act 2003, and Part 9 Final provisions on commencement extent and short title.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-nis-regulations-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-terrorism-act-2000-section-15-terrorist-fund-raising",
    "title": "UK Terrorism Act 2000 Section 15 - Terrorist Fund-Raising (Invitation, Receipt, Provision of Money or Property, Reasonable Cause to Suspect Test)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 15 of the Terrorism Act 2000 (c. 11) creates the primary UK terrorist financing offence and operates as the legal foundation for the UK Counter-Terrorist Financing (CTF) regime, the National Crime Agency UKFIU SAR regime for terrorist-finance reporting, and the Office of Financial Sanctions Implementation (OFSI) terrorist asset-freezing regime. Section 15 creates three distinct offences. Under section 15(1), a person commits an offence if he (a) invites another to provide money or other property, and (b) intends that it should be used, or has reasonable cause to suspect that it may be used, for the purposes of terrorism. Under section 15(2), a person commits an offence if he (a) receives money or other property, and (b) intends that it should be used, or has reasonable cause to suspect that it may be used, for the purposes of terrorism. Under section 15(3), a person commits an offence if he (a) provides money or other property, and (b) knows or has reasonable cause to suspect that it will or may be used for the purposes of terrorism. Under section 15(4), a reference to the provision of money or other property is a reference to its being given, lent or otherwise made available, whether or not for consideration. The 'reasonable cause to suspect' objective threshold is the operative test in most prosecutions - it captures financial institutions, money service businesses, crowdfunding platforms, and cryptoasset service providers that fail to apply adequate CTF controls even where no actual suspicion is formed. Sections 16, 17, and 18 of the Act create the companion offences of use and possession of money or property for terrorism (s.16), funding arrangements (s.17), and terrorist money laundering (s.18). The disclosure duty in section 19 (general disclosure) and section 21A (regulated-sector disclosure) creates the SAR filing obligation to the NCA. The maximum penalty under section 22 is 14 years imprisonment on indictment plus an unlimited fine. Section 15 captures both Schedule 2 proscribed-organisation funding and non-proscribed-organisation terrorism (where the section 1 definition of terrorism applies independently of proscription).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_15_text_subsections",
        "reasonable_cause_to_suspect_objective_threshold",
        "definition_of_terrorism_section_1",
        "money_or_other_property_section_121_definition",
        "proscribed_organisations_schedule_2_link",
        "ctf_disclosure_duties_section_19_and_21a",
        "penalty_section_22",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-terrorism-act-2000-section-19-failure-disclose",
      "uk-proceeds-of-crime-act-2002-section-330-failure-to-disclose-regulated-sector"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-terrorism-act-2000-section-19-failure-disclose",
    "title": "Terrorism Act 2000, Section 19: Disclosure of information: duty",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This section mandates that a person must disclose information they know or believe could help prevent a terrorist act or lead to the prosecution of a terrorist, as soon as reasonably practicable, to a constable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-terrorism-protection-of-premises-act-2025-martyns-law",
    "title": "Terrorism (Protection of Premises) Act 2025 (c. 10), Part 1 Public Protection at Qualifying Premises and Events (Martyn's Law)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "The Terrorism (Protection of Premises) Act 2025, known as Martyn's Law, imposes public protection duties on those responsible for qualifying premises and events in the UK. Premises where it is reasonable to expect 200 or more individuals may be present are standard duty premises, and those where 800 or more may be present are enhanced duty premises with heightened obligations. Responsible persons must put in place public protection procedures and measures, with the Security Industry Authority acting as regulator under sections 5 to 10 and 12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-terrorist-content-online-regulation-2021-784",
      "uk-public-order-act-2023-protest-restrictions",
      "uk-modern-slavery-act-2015-section-1-slavery-servitude-forced-labour"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-theft-act-1968",
    "title": "UK Theft Act 1968",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The UK Theft Act 1968 (England and Wales; Scotland and Northern Ireland have separate provisions) codifies the principal property offences including theft (Section 1), robbery (Section 8), burglary (Section 9), aggravated burglary (Section 10), removal of articles from public places (Section 11), taking conveyances without consent (Section 12), abstracting electricity (Section 13), false accounting (Section 17), and handling stolen goods (Section 22). Theft (Section 1) requires dishonest appropriation of property belonging to another with intention to permanently deprive. The Fraud Act 2006 replaced deception offences in the Theft Acts 1968 and 1978. Penalties include imprisonment up to 7 years (theft), life (robbery and aggravated burglary).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fraud_act_2006",
        "theft_act_1978",
        "proceeds_crime_act",
        "sentencing_council",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-theft-act-1968-section-1-basic-definition-theft",
    "title": "UK Theft Act 1968 Section 1 - Basic Definition of Theft (Dishonest Appropriation, Property Belonging to Another, Intention to Permanently Deprive)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "Section 1 of the Theft Act 1968 (c. 60) provides the foundational UK criminal definition of theft. Under section 1(1), a person is guilty of theft if he dishonestly appropriates property belonging to another with the intention of permanently depriving the other of it; and 'thief' and 'steal' shall be construed accordingly. Under section 1(2), it is immaterial whether the appropriation is made with a view to gain, or is made for the thief's own benefit. Under section 1(3), the five following sections of the Act (sections 2-6) have effect as regards the interpretation and operation of this section. Section 2 (dishonesty), section 3 (appropriation), section 4 (property), section 5 (belonging to another), and section 6 (intention of permanently depriving) elaborate the five elements of the offence. The Ivey v Genting Casinos [2017] UKSC 67 and Barton & Booth v R [2020] EWCA Crim 575 objective dishonesty test replaces the former Ghosh subjective test. Maximum penalty under section 7 (as amended by Criminal Justice Act 1991) is 7 years imprisonment on indictment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "section_1_text",
        "five_elements_of_theft",
        "dishonesty_test_ivey_section_2_negative_definition",
        "appropriation_section_3_assumption_of_rights",
        "intention_of_permanently_depriving_section_6_treating_as_own",
        "penalty_section_7_amended",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-third-parties-rights-against-insurers-act-2010",
    "title": "UK Third Parties (Rights against Insurers) Act 2010",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "The UK Third Parties (Rights against Insurers) Act 2010 transfers an insured person's rights against its liability insurer to a third party to whom the insured has incurred liability when the insured becomes insolvent or is dissolved (Section 1), so the third party may proceed directly against the insurer. It sets out how the insured's liability is established in England, Wales and Northern Ireland (Section 2) and in Scotland (Section 3), limits the transferred rights to those of the insured (Section 8) subject to policy conditions (Section 9) and the insurer's set-off (Section 10), and gives the third party rights to information about the insurance (Section 11 and Schedule 1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-insurance-act-2015-fair-presentation",
      "eu-insurance-distribution-directive-2016-97-idd",
      "uk-financial-services-markets-act-2000-fsma"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-trade-act-2021",
    "title": "United Kingdom Trade Act 2021: Implementation of the Agreement on Government Procurement, Implementation of International Trade Agreements, Free Trade Agreements and Genocide, Trade Remedies Authority, Trade and Agriculture Commission, and HMRC Disclosure of Information",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Trade Act 2021, chapter 10 of 2021, received Royal Assent on 29 April 2021 and is the principal United Kingdom statute providing the post-EU-exit framework for the implementation of international trade agreements, the establishment of the Trade Remedies Authority, and the collection and disclosure of trade-related information, and is administered through the Department for Business and Trade and HM Revenue and Customs. Trade Act 2021, section 1 provides for the implementation of the Agreement on Government Procurement under the WTO. Trade Act 2021, section 2 provides for the implementation of international trade agreements through regulations made by an appropriate authority. Trade Act 2021, section 3 governs free trade agreements and genocide including parliamentary procedures where the High Court of England and Wales has made a preliminary determination that there exists credible evidence of genocide. Trade Act 2021, section 6 establishes the Trade Remedies Authority as a body corporate. Trade Act 2021, section 8 provides for the Trade and Agriculture Commission to provide advice on the consistency of provisions in free trade agreements with the maintenance of UK levels of statutory protection for animal or plant life or health, animal welfare, and the environment. Trade Act 2021, section 12 provides for the collection of exporter information by HMRC. Trade Act 2021, section 13 provides for the disclosure of information by HMRC to specified persons for trade purposes. The Act is the controlling United Kingdom statute for the post-EU-exit trade agreements framework and trade remedies architecture.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-trade-marks-act-1994",
    "title": "UK Trade Marks Act 1994: Registrability, Rights, Duration, Revocation and Remedies",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Trade Marks Act 1994 (c. 26) is the principal UK statute governing registered trade marks, administered by the Intellectual Property Office (IPO). Section 1 defines a trade mark as any sign capable of being represented and of distinguishing the goods or services of one undertaking from those of others, and section 2 establishes the registered trade mark as a property right. Section 3 sets the absolute grounds for refusal of registration (including marks devoid of distinctive character, descriptive marks, customary marks, and marks contrary to public policy or of a deceptive nature), and section 5 sets the relative grounds for refusal (conflict with earlier marks and rights). Section 9 confers on the proprietor the exclusive rights in the registered trade mark, which are infringed by the acts set out in section 10; sections 11 and 12 limit the effect of a registered mark and provide for exhaustion of rights. The duration of registration is ten years from the date of registration (section 42), renewable for further ten-year periods (section 43). A registration may be surrendered (section 45), revoked (section 46, including for non-use for five years or for becoming generic or deceptive) or declared invalid (section 47, on absolute or relative grounds). Remedies for infringement are provided in sections 14-19, including an action for infringement (section 14), orders for erasure of the offending sign (section 15), delivery up (section 16) and disposal (section 19) of infringing goods, material or articles. Section 92 creates the criminal offence of unauthorised use of a trade mark in relation to goods, such as applying a sign identical to or likely to be mistaken for a registered trade mark with a view to gain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-trade-marks-act-1994-section-10-infringement-registered-trade-mark"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-trade-marks-act-1994-section-10-infringement-registered-trade-mark",
    "title": "Trade Marks Act 1994 Section 10: Infringement of registered trade mark.",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must not use a sign in the course of trade that is identical or similar to a registered trade mark in a manner that causes a likelihood of confusion, takes unfair advantage of its reputation, or is detrimental to its character, including affixing such signs to packaging or related materials.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-transfer-pricing-guidelines-hmrc-intm",
    "title": "HMRC International Transfer Pricing Guidelines (INTM) - UK Arm's Length Principle Application: Thin Cap Rules (Replaced by Interest Limitation), Advance Thin Cap Agreements, Mutual Agreement and MAP Process",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The UK transfer pricing rules, as reformed effective 1 January 2026, require that transactions between connected parties be conducted at arm’s length, with specific rules on interest deductibility and thin capitalisation. Compliance is governed by the reformed rules detailed at INTM 414000, which apply to all relevant entities from the 2026 tax year onward.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-debt-equity-bias-reduction-allowance-debra-2023",
      "canada-transfer-pricing-income-tax-act-section-247",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two",
      "eu-transfer-pricing-directive-proposal-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-transfer-pricing-tiopa-2010",
    "title": "UK Transfer Pricing - Taxation (International and Other Provisions) Act 2010 and OECD BEPS Action 13 Documentation",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The UK transfer pricing rules, codified in Pt. 4 and Pt. 5 of the Taxation (International and Other Provisions) Act 2010 (TIOPA 2010), require that transactions between associated enterprises be conducted on arm's length terms as defined by the OECD Transfer Pricing Guidelines for Multinational Enterprises and Tax Administrations (2022 edition). The rules apply to UK-resident entities transacting with overseas associated enterprises and to domestic transactions between UK-resident associated enterprises where a UK tax advantage arises. Associated enterprise test: TIOPA 2010 applies where one person directly or indirectly participates in the management, control, or capital of another, or both are under common participation - broadly interpreted to include ≥25% ownership, common board control, or contractual management rights. Arm's length principle: each controlled transaction must be priced as if the parties were independent using the most appropriate OECD method - comparable uncontrolled price (CUP), resale price method (RPM), cost-plus, transactional net margin method (TNMM), or profit split. Documentation: for groups with consolidated annual revenue ≥ £750 million (the CbCR threshold), HMRC expects the Master File and Local File to be maintained in accordance with OECD BEPS Action 13, as implemented via The Taxes (Base Erosion and Profit Shifting) Regulations 2016 (SI 2016/1409, as amended). Groups below £750 million annual consolidated revenue are not required to maintain documentation in Master File/Local File format but must still keep contemporaneous transfer pricing documentation under TIOPA 2010 sufficient to demonstrate arm's length pricing. Country-by-Country Reporting (CbCR): ultimate parent entities of groups with consolidated annual revenue ≥ £750 million must file a CbCR with HMRC within 12 months of fiscal year end. SME exemption: entities with fewer than 250 employees and annual turnover ≤ EUR 50 million or balance sheet ≤ EUR 43 million are generally exempt absent an HMRC formal direction. Thin capitalisation: TIOPA 2010 governs arm's length pricing of related-party debt - interest on excess (non-arm's length) debt is disallowed; Advance Thin Capitalisation Agreements (ATCAs) provide forward certainty. Advance Pricing Agreements (APAs): HMRC can enter into unilateral, bilateral (competent authority), or multilateral APAs for 3-5 year periods with possible rollback. UK Corporate Interest Restriction (Finance (No. 2) Act 2017) separately limits net interest deductibility to 30% of tax-EBITDA at group level (£2 million de minimis per annum), operating in addition to thin capitalisation. Pillar Two interaction: transfer pricing adjustments to a UK entity's taxable income may alter covered taxes and GloBE income for UK Qualified Domestic Minimum Top-up Tax (QDMTT) computations under Finance (No. 2) Act 2023. HMRC Transfer Pricing Manual (INTM) provides the primary administrative guidance. Penalties: inaccuracy penalties of up to 100% of understated tax; HMRC enquiry window is 12 months post-filing (4 years for careless errors, 20 years for deliberate underpayments).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-cbcr-guidance-2023-update"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-transparency-of-lobbying-act-2014",
    "title": "UK Transparency of Lobbying, Non-Party Campaigning and Trade Union Administration Act 2014 (c. 4)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Transparency of Lobbying, Non-Party Campaigning and Trade Union Administration Act 2014 (c. 4) received Royal Assent on 30 January 2014. Part 1 of the Act (Registration of Consultant Lobbyists) was brought into force on 1 September 2014 by The Transparency of Lobbying etc. Act 2014 (Commencement No. 2) Order SI 2014/2125. The Act is organised in four Parts. Part 1 (ss. 1-25) creates a statutory regime for consultant lobbyists. Section 1 makes it an offence for a person to carry on the business of consultant lobbying unless registered. Section 2 defines consultant lobbying as the making of oral or written communications personally to a Minister of the Crown or Permanent Secretary on behalf of another person and in the course of a business carried on by the person making the communication and in return for payment. Section 4 establishes the Office of the Registrar of Consultant Lobbyists as an independent statutory office holder. Section 5 establishes the Register of Consultant Lobbyists, which is public, free to inspect and updated by means of quarterly information returns. Section 12 requires every registered person to submit quarterly information returns disclosing the names of their clients during the preceding quarter. Section 14 creates a civil penalty regime of up to GBP 7,500 for failure to register or to submit returns. Section 17 creates criminal offences for knowingly providing false information. Part 2 (ss. 26-39) amends the Political Parties Elections and Referendums Act 2000 to regulate controlled expenditure by third parties during election periods. Part 3 (ss. 40-43) regulates trade union administration including membership audit certificates. Part 4 (ss. 44-49) contains supplementary provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-bribery-act-2010",
      "us-fara-foreign-agents-registration-act-22-usc-611",
      "fr-sapin-ii-anticorruption-2016"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uk-ukpga-2000-8",
    "title": "UK Financial Services and Markets Act 2000",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The Financial Services and Markets Act 2000 is an Act of the Parliament of the United Kingdom that regulates financial services and markets. It provides for the transfer of certain statutory functions relating to building societies, friendly societies, industrial and provident societies, and certain other mutual societies. The Act also makes provision for connected purposes, including the regulation of financial services, the supervision of financial institutions, and the protection of consumers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-ukpga-2000-8-fsma-2000",
    "title": "Financial Services and Markets Act 2000 (Consolidated)",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0.0",
    "last_updated": "2026-05-21",
    "bluf": "Consolidated node for all parts of the Financial Services and Markets Act 2000.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": 0.01,
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 138
  },
  {
    "node_id": "uk-ukpga-2000-8-part-8b-cash-access-services",
    "title": "UK Financial Services and Markets Act 2000 Part 8B Cash Access Services",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-21",
    "bluf": "Part 8B of the UK Financial Services and Markets Act 2000 establishes a framework for cash access services in the United Kingdom. The Treasury is required to prepare a cash access policy statement outlining the government's policies on cash deposit and withdrawal services, including free cash access services for personal current accounts. The Treasury may designate relevant current account providers or operators of cash access coordination arrangements for the purposes of this Part, following consultation with the FCA and consideration of representations. The FCA is empowered to make rules and give directions to designated persons with the purpose of ensuring reasonable provision of cash access services. In determining reasonable provision, the FCA must have regard to the cash access policy statement and any local deficiencies in cash access services. The FCA may gather information and investigate relevant persons under Part 11 as modified. Disciplinary measures under Part 14 apply to designated persons. The FCA may charge fees for supervision only to designated persons who are relevant current account providers. The FCA's general duties are modified when discharging functions under this Part, excluding competition and competitiveness objectives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-ukpga-2010-15",
    "title": "UK Equality Act 2010",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The UK Equality Act 2010 is an Act of the Parliament of the United Kingdom that aims to consolidate and harmonize equality law in the UK. It provides a framework for protecting individuals from discrimination and harassment based on certain personal characteristics, including age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, and sexual orientation. The Act applies to various areas, including employment, education, and the provision of goods and services. It also imposes duties on public authorities to eliminate discrimination and promote equality of opportunity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-ukpga-2010-15-part-11-advancement-of-equality",
    "title": "UK Equality Act 2010 - Part 11 Advancement of equality",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-21",
    "bluf": "Outlines the Public Sector Equality Duty (PSED), requiring public authorities to have due regard to the need to eliminate discrimination, advance equality of opportunity, and foster good relations between people who share a protected characteristic and those who do not.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "iso_standard",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-ukpga-2010-15-part-2-equality-key-concepts",
    "title": "UK Equality Act 2010 - Part 2: Equality: key concepts",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-21",
    "bluf": "Defines the core protected characteristics (age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, sexual orientation) under the UK Equality Act 2010, which form the legal foundation for non-discrimination compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "uk-ukpga-2010-15-part-5",
    "title": "UK Equality Act 2010 Part 5: Workplace Discrimination and Equality Provisions",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Part 5 of the UK Equality Act 2010 codifies protections against discrimination in the workplace, covering employment, contract work, partnerships, and other work relationships. It prohibits direct and indirect discrimination, harassment, and victimization based on protected characteristics including age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, and sexual orientation. The Part imposes duties on employers to make reasonable adjustments for disabled employees and job applicants. It also addresses equal pay between men and women, including provisions for equality clauses in employment contracts. Specific sections cover occupational requirements, positive action, and exceptions for certain religious or belief-based organisations. The Part applies to employers, employees, job applicants, and workers in Great Britain, with enforcement through employment tribunals and the Equality and Human Rights Commission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-ukpga-2018-12",
    "title": "UK Data Protection Act 2018",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The UK Data Protection Act 2018 is an Act to make provision for the regulation of the processing of information relating to individuals; to make provision in connection with the Information Commissioner's functions under certain regulations relating to information; to make provision for a direct marketing code of practice; and for connected purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-ukpga-2018-12-part-3-law-enforcement-processing",
    "title": "UK Data Protection Act 2018 Part 3 Law Enforcement Processing",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Part 3 of the UK Data Protection Act 2018 governs the processing of personal data by competent authorities for law enforcement purposes. It transposes the EU Law Enforcement Directive (LED) into UK law and applies to processing by police, prosecutors, and other bodies with statutory law enforcement functions. Key obligations include lawful processing based on domestic law necessity, data subject rights such as access and rectification, restrictions on automated individual decision-making, and specific provisions for sensitive processing including criminal convictions data. Controllers must implement appropriate technical and organisational measures to ensure data security and conduct data protection impact assessments. The Act grants the Information Commissioner enforcement powers including assessment notices, enforcement notices, and penalty notices for non-compliance. The Part contains 65 sections covering scope, principles, rights, transfers, and enforcement specific to the law enforcement context. It is part of the broader Data Protection Act 2018 which supplements the UK GDPR.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-ukpga-2018-12-part-5-the-information-commissioner",
    "title": "UK Data Protection Act 2018 - PART 5: The Information Commissioner",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-21",
    "bluf": "PART 5 of the UK Data Protection Act 2018 establishes the office, functions, and powers of the Information Commissioner as the independent regulatory authority for data protection and information rights in the United Kingdom. It sets out the Commissioner's general duties, including the duty to promote good practice by data controllers and to monitor developments in data processing. The Part confers powers to issue information notices, assessment notices, and enforcement notices, and to impose monetary penalties for contraventions of the data protection legislation. It also creates the Information Commissioner's Office as a body corporate, specifies the appointment and terms of office of the Commissioner and staff, and establishes the Commissioner's duty to produce a annual report to Parliament. The Commissioner's functions include conducting investigations, issuing codes of practice, and providing advice to the government and the public. The Part provides for the Commissioner to charge fees for certain services. It also defines the Commissioner's role in relation to international co-operation and data transfers. The Part contains numerous sections but their specific numbers are not recited here to avoid any risk of inaccuracy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-ukpga-2018-12-part-6-enforcement",
    "title": "UK Data Protection Act 2018 - Part 6: Enforcement of data protection legislation by the Information Commissioner",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Part 6 of the UK Data Protection Act 2018 (sections 142-189) provides the statutory enforcement powers of the Information Commissioner's Office (ICO) under the UK General Data Protection Regulation and the Data Protection Act 2018 itself. It sets out a range of enforcement mechanisms including assessment notices, information notices, enforcement notices, penalty notices, and the power to impose monetary penalties of up to £17.5 million or 4% of annual worldwide turnover (whichever is higher) for serious breaches. The Part also establishes procedural safeguards for data controllers and processors, including rights of appeal to the First-tier Tribunal (General Regulatory Chamber) against ICO notices. It outlines the Commissioner's power to issue warnings, reprimands, and orders to comply with data subject requests. The enforcement regime is designed to ensure accountability and compliance with data protection law, with graduated responses from informal guidance to formal enforcement actions. The ICO may also apply for a warrant to enter and inspect premises if there are reasonable grounds to suspect a breach. This Part supersedes and consolidates enforcement powers previously contained in the Data Protection Act 1998.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-ukri-open-access-policy-2022",
    "title": "UK Research and Innovation (UKRI) Open Access Policy",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2024-08-01",
    "bluf": "This policy requires that all UKRI-funded, in-scope, peer-reviewed research articles and long-form publications be made immediately and freely available to the public upon publication. As detailed in Section 3, compliance is achieved via either the 'Gold' route (publication in an open access journal/platform) or the 'Green' route (deposition in an institutional repository), with a mandatory Creative Commons Attribution (CC BY) licence for articles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-uksi-2019-419",
    "title": "UK Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "The UK Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 make amendments to legislation in relation to the regulation of the processing of personal data. These Regulations amend the UK GDPR, the Data Protection Act 2018, and other legislation to ensure the continued protection of personal data in the United Kingdom after the United Kingdom's exit from the European Union. The Regulations also make consequential amendments to other legislation, including the Privacy and Electronic Communications Regulations 2003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-vehicle-excise-and-registration-act-1994",
    "title": "UK Vehicle Excise and Registration Act 1994: Vehicle Tax, Registration and Unlicensed-Vehicle Offences",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Vehicle Excise and Registration Act 1994 (c. 22) governs vehicle excise duty (vehicle tax) and the registration of vehicles in the UK, administered by the DVLA. Section 1 charges vehicle excise duty in respect of mechanically propelled vehicles used or kept on a public road and requires a licence (vehicle tax) to be taken out, and section 2 provides for annual rates of duty determined under Schedule 1. Section 5 and Schedule 2 set out exempt vehicles. Enforcement of the duty is through offences: section 29 makes it an offence to use or keep an unlicensed vehicle on a public road, section 30 imposes additional liability on the keeper of an unlicensed vehicle, section 31 defines the relevant period, and section 31A creates the continuous-registration offence committed by the registered keeper where a vehicle is unlicensed (subject to the exceptions in section 31B and the penalties in section 31C). Part II governs registration: section 21 requires the registration of vehicles, section 22 provides for registration regulations, and section 23 governs registration marks (number plates). Sections 44 and 45 create offences of forgery and fraud and of making false or misleading declarations or providing false information in connection with licences, registration and marks. The Act underpins the DVLA's vehicle register and the tax-and-register enforcement regime, including back duty recovery and additional liabilities for keepers of unlicensed vehicles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-veterinary-surgeons-act-1966",
    "title": "UK Veterinary Surgeons Act 1966 (c.36): Registration and Restriction of Veterinary Practice",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Veterinary Surgeons Act 1966 (c. 36) regulates the veterinary profession in the United Kingdom by establishing the Royal College of Veterinary Surgeons, maintaining the register of veterinary surgeons, and restricting the practice of veterinary surgery to registered persons. Section 1 provides for the Council of the Royal College of Veterinary Surgeons as the governing body of the profession. Section 2 provides for the register of veterinary surgeons maintained by the Royal College, and section 3 provides the right of holders of recognised university degrees to be registered. Section 5 sets out the supervisory functions of the Council, including over veterinary education and examinations. Section 15 provides for preliminary investigation and disciplinary committees, and section 16 provides for the removal of names from the register for crime or disgraceful conduct in a professional respect, with section 17 providing for appeals in disciplinary and other cases. Section 19 restricts the practice of veterinary surgery by unqualified persons, making it an offence for a person who is not a registered veterinary surgeon or registered veterinary practitioner to practise, or hold himself out as practising or as being prepared to practise, veterinary surgery, subject to the exemptions in Schedule 3. Section 20 prohibits the use of practitioners' titles by unqualified persons. The Act is the foundational professional regulation regime for veterinary surgeons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-victims-and-prisoners-act-2024",
    "title": "UK Victims and Prisoners Act 2024 - Victims Code Statutory Footing and Infected Blood Compensation Scheme, Royal Assent 24 May 2024",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "Criminal justice agencies in England and Wales (police forces, the Crown Prosecution Service, HMCTS, probation services, Youth Offending Teams, the Parole Board) and bodies providing services to victims of crime must, from the staggered commencement of the Victims and Prisoners Act 2024 (Royal Assent 24 May 2024), give due regard to the principles of the Code of Practice for Victims of Crime under section 1 (Victims Code on statutory footing), exercise the section 2 reviewable functions consistently with the Code, comply with the section 5 information-sharing arrangements with victim support services, support the Independent Public Advocate role under Part 2 for major incidents, and engage with the Infected Blood Compensation Scheme under Part 4 administered by the Infected Blood Compensation Authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-ukpga-2000-8-fsma-2000"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-video-recordings-act-1984",
    "title": "UK Video Recordings Act 1984: Classification of Video Works and Supply Offences",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Video Recordings Act 1984 establishes the system for the classification of video works supplied in the United Kingdom and the offences relating to their supply, with classification carried out by the designated authority (the British Board of Film Classification). Section 1 sets the interpretation, including the definitions of video work and video recording. Section 2 sets out the exempted works that fall outside the classification regime, subject to losing the exemption where the content includes specified material. Section 4 provides for the authority to determine the suitability of video works for classification and the arrangements made by the designated authority. Section 7 provides for the issue of classification certificates, including the recognised age categories. The offences are central: section 9 makes it an offence to supply or offer to supply a video recording containing a video work that has not been classified, section 11 makes it an offence to supply a classified work in breach of the classification (for example, supplying an age-restricted work to an underage person), and section 12 restricts the supply of works classified for restricted distribution to licensed sex shops. The Act, whose provisions were re-enacted by the Video Recordings Act 2010 to cure a procedural defect, is the legal foundation of UK video and video-game content classification and age-rating enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-voyeurism-offences-act-2019-section-1-upskirting-section-67a-soa",
    "title": "UK Voyeurism (Offences) Act 2019 Section 1 - Upskirting Offence (inserts Section 67A into SOA 2003)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Section 1 of the Voyeurism (Offences) Act 2019 inserts Section 67A into the Sexual Offences Act 2003, creating the offence of upskirting. A person commits an offence if, without consent and without reasonable belief in consent, they operate equipment beneath another's clothing, or record an image beneath another's clothing, in either case intending to enable themselves or another to observe (or in the case of recordings, to enable observation of) the victim's genitals or buttocks (whether exposed or covered with underwear), or the underwear covering them, in circumstances where they would not otherwise be visible. The purpose must be sexual gratification, or humiliating, alarming or distressing the victim.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "operation_of_equipment_offence_section_67a_1",
        "recording_of_image_offence_section_67a_2",
        "qualifying_purposes_subsection_3",
        "penalties_section_67a_4",
        "notification_requirement_for_certain_offenders",
        "interaction_with_section_67_voyeurism_general",
        "scotland_separate_regime",
        "automatic_amendments_to_other_legislation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sexual-offences-act-2003-section-66a-66b-cyberflashing-intimate-image"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-water-act-2003",
    "title": "UK Water Act 2003: Abstraction Licensing Reform, the Ofwat Duties and Water Conservation",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Water Act 2003 reformed the water abstraction licensing system, restructured the economic regulation of the water industry and strengthened water-conservation duties in England and Wales, amending the Water Resources Act 1991 and the Water Industry Act 1991, administered by the Environment Agency and the Water Services Regulation Authority (Ofwat). Part 1 reforms abstraction and impounding: section 1 deals with licences to abstract water, section 13 sets out the types of abstraction licence (including full, transfer and temporary licences) and how applications are made, section 20 provides for the limited extension of abstraction-licence validity and underpins the move to time-limited licences, and section 25 provides for compensation where a licence is modified on the direction of the Secretary of State. Part 2 makes new regulatory arrangements: section 34 establishes the Water Services Regulation Authority as a body corporate (replacing the Director General of Water Services), and section 39 sets the objectives and general duties under the Water Industry Act, including the furtherance of sustainable development. Part 2 also opens the market: section 56 provides for the licensing of other water suppliers, the basis of competition in water supply. Part 3 strengthens conservation: section 81 imposes a duty to encourage water conservation, section 82 places water-conservation requirements on relevant undertakers, and section 83 imposes a water-conservation duty on public authorities. The Act is the instrument that moved abstraction licensing toward time-limited, environmentally informed licences, modernised the economic regulator and embedded water conservation as a statutory duty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-water-industry-act-1991",
    "title": "UK Water Industry Act 1991 - Ofwat Economic Regulation of Water and Sewerage Undertakers, Drinking Water Inspectorate and Customer Protection",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Water Industry Act 1991 (WIA, c.56, royal assent 25 July 1991) is the principal UK consolidation Act governing the regulation of water and sewerage services in England and Wales. It codifies the post-privatisation regulatory framework established by the Water Act 1989, under which water and sewerage undertakers were established as appointed regional monopolies. The Water Services Regulation Authority (Ofwat, established by Water Act 2003 succeeding the Director General of Water Services) is the economic regulator setting price controls, monitoring service performance, and protecting customer interests under the WIA Part I (sections 1-26). The Drinking Water Inspectorate (DWI) within DEFRA regulates drinking water quality under WIA Sections 67-86. The Environment Agency (formerly NRA) regulates environmental aspects of water resources, abstraction, and pollution. Section 18 enforcement powers, Section 27 universal water supply duties, Section 37 general duties of undertakers, Sections 70-72 wholesomeness and water quality, Section 94 duty to provide sewerage system, and Schedule 12 customer redress mechanism. Substantially amended by Water Act 2003, Water Act 2014 (introducing competition for non-household retail), and Environment Act 2021 (introducing storm overflow reduction and water resources management plan requirements).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-water-resources-act-1991-abstraction-pollution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-water-industry-act-1991-section-94-general-duty-sewerage-system",
    "title": "UK Water Industry Act 1991 Section 94 - General Duty to Provide Sewerage System",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Every sewerage undertaker has a duty to provide, improve and extend a system of public sewers (whether inside or outside its area) and to cleanse and maintain those sewers and any lateral drains belonging to or vested in the undertaker so that the area is and continues to be effectually drained, and to make provision for emptying those sewers and dealing with their contents by means of sewage disposal works or otherwise. The duty must be performed having regard to trade effluent discharge obligations. The duty is enforceable under Section 18 by the Secretary of State or the Authority (Ofwat).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_sewerage_provision_duty_subsection_1_a",
        "emptying_and_disposal_duty_subsection_1_b",
        "trade_effluent_consideration_subsection_2",
        "section_18_enforcement_route_subsection_3",
        "preservation_of_chapter_obligations_subsection_4",
        "trade_effluent_definition_subsection_5",
        "lateral_drains_2010_amendment",
        "interaction_with_storm_overflow_regime_environment_act_2021"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-environment-act-2021-section-81-storm-overflow-discharge-reporting"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-water-resources-act-1991-abstraction",
    "title": "UK Water Resources Act 1991: Abstraction and Impounding Licensing",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Water Resources Act 1991 governs the management of water resources in England and Wales, with the abstraction and impounding licensing system administered by the Environment Agency in England and Natural Resources Wales in Wales. The core control is in Chapter II of Part II. Section 24(1) provides that no person shall abstract water from any source of supply, or cause or permit any other person to abstract any water, except in pursuance of a licence under that Chapter (subject to the statutory exemptions). A licence specifies the quantity of water that may be abstracted and the conditions and requirements applicable to the abstraction, such as the point of abstraction, the period, the purpose and the means of measurement. Section 25 restricts the construction or alteration of impounding works (such as dams or weirs that obstruct or impede the flow of inland water), which likewise require a licence. Section 24(4) creates the offence: a person is guilty of an offence if they contravene the restriction on abstraction (or the corresponding restriction), or, being the holder of a licence, fail to comply with a condition or requirement of the licence. Section 24(5) provides that a person guilty of the offence is liable, on summary conviction or on conviction on indictment, to a fine. The Act thereby makes the abstraction licence and its conditions the operative compliance instrument for any agricultural, industrial, public-supply or commercial operator that takes water from rivers, lakes or groundwater in England and Wales, and the regime is the principal lever for protecting flows, water bodies and downstream users from over-abstraction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-water-resources-act-1991-abstraction-pollution",
    "title": "UK Water Resources Act 1991 - Abstraction Licensing, Section 85 Water Pollution Offences and Environment Agency Powers",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Water Resources Act 1991 (WRA 1991) is the principal statute governing water resources, water quality and flood defence in England and Wales. Part II requires an abstraction licence under section 24 for the abstraction of water from any source of supply where the quantity abstracted exceeds 20 cubic metres in 24 hours (raised from 5 m3 by Water Act 2003). Part III creates the section 85 offence of causing or knowingly permitting the entry of any poisonous, noxious or polluting matter or any solid waste matter into any controlled waters, an offence of strict liability triable either way with unlimited fine on indictment. The Environment Agency (England) and Natural Resources Wales (Wales) are the regulators, with powers under section 161 to serve anti-pollution works notices requiring polluters to remediate at their cost. Controlled waters are defined broadly under section 104 to include territorial waters, coastal waters, inland freshwaters and groundwaters. The Water Act 2003, Flood and Water Management Act 2010 and Environment Act 2021 introduced subsequent reforms including Catchment Abstraction Management Strategies (CAMS) and storm overflow reduction duties on water companies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-water-framework-directive-2000-60-ec",
      "germany-water-management-act-wasserhaushaltsgesetz-2009"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-wildlife-and-countryside-act-1981",
    "title": "UK Wildlife and Countryside Act 1981: Species Protection, Invasive Species and SSSIs",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "The Wildlife and Countryside Act 1981 (c. 69) is the principal UK statute for the protection of wild birds, animals and plants and for the conservation of designated habitats, enforced by the police and statutory nature conservation bodies (Natural England, NatureScot and Natural Resources Wales) under DEFRA policy. Part I, section 1 protects wild birds, their nests and eggs, making it an offence intentionally to kill, injure or take a wild bird, or to take, damage or destroy an active nest or eggs, with special penalties for birds listed in Schedule 1; section 4 sets exceptions and section 16 confers the power to grant licences for otherwise prohibited acts. Section 9 protects certain wild animals listed in Schedule 5 against killing, injuring, taking, possession and disturbance, and section 13 protects wild plants listed in Schedule 8 against picking, uprooting and destruction. Section 14 prohibits releasing or allowing to escape into the wild any animal not ordinarily resident in Great Britain, and planting or causing certain invasive non-native plants to grow in the wild. Enforcement is supported by wildlife inspectors and associated powers (sections 18A-18F) and a general enforcement provision (section 19), with penalties and forfeiture under section 21. Part II provides for sites of special scientific interest (SSSIs): under section 28 and the following sections (28A-28S) conservation bodies notify SSSIs, specify operations likely to damage the special interest, and owners, occupiers and public bodies must not carry out listed operations without consent, with offences for damaging an SSSI. The protected lists are set out in the Schedules - Schedule 1 (birds protected by special penalties), Schedule 5 (protected animals) and Schedule 8 (protected plants).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-wildlife-countryside-act-1981",
    "title": "UK Wildlife and Countryside Act 1981 (c.69): Protection of Wild Birds, Animals, Plants and SSSIs",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Wildlife and Countryside Act 1981 (c. 69) is the principal nature conservation statute for Great Britain, protecting wild birds, animals, and plants and providing for the designation of sites of special scientific interest, administered by the Department for Environment, Food and Rural Affairs and the statutory nature conservation bodies and enforced by the police. Section 1 protects wild birds, their nests, and eggs, making it an offence intentionally to kill, injure, or take any wild bird or to take, damage, or destroy the nest of a wild bird while in use or being built or to take or destroy an egg. Section 5 prohibits certain methods of killing or taking wild birds, and section 6 restricts the sale of live or dead wild birds and eggs. Section 9 protects certain wild animals listed in Schedule 5, and section 11 prohibits certain methods of killing or taking wild animals. Section 13 protects wild plants listed in Schedule 8, making it an offence to pick, uproot, or destroy them. Section 14 restricts the introduction of new species, and section 16 confers power to grant licences. Section 21 sets out the penalties, forfeitures, and other consequences of offences. Section 28 provides for sites of special scientific interest, requiring notification by the nature conservation body and restricting operations likely to damage the special interest. The Act is the foundational species and habitat protection regime in domestic law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-wireless-telegraphy-act-2006",
    "title": "UK Wireless Telegraphy Act 2006: Spectrum Licensing, Trading and the Offence of Unauthorised Use",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Wireless Telegraphy Act 2006 is the principal UK statute governing the use and management of the radio spectrum, administered by the Office of Communications (OFCOM). Section 1 sets OFCOM's general functions in relation to the radio spectrum, section 2 provides for the United Kingdom Plan for Frequency Authorisation, and section 3 sets the duties OFCOM must observe in carrying out its spectrum functions, including the efficient use and management of the spectrum. Licensing is mandatory: section 8 provides that the establishment or use of a wireless telegraphy station, and the installation or use of wireless telegraphy apparatus, is unlawful unless authorised by a licence or an exemption regulation; section 9 governs the terms, provisions and limitations that may be attached to a licence; section 10 sets the procedure for grant; and section 12 provides for charges. Spectrum may be allocated by competitive means under section 14 (bidding for licences) and managed through section 29 (limitations on authorised spectrum use) and section 30 (spectrum trading). Enforcement is direct: section 35 makes unauthorised use of a wireless telegraphy station or apparatus an offence, section 36 addresses keeping apparatus available for unauthorised use, sections 37 and 38 address premises used for, and the facilitation of, unlawful broadcasting, and section 47 addresses misleading messages. The Act is the legal foundation for spectrum authorisation, trading and enforcement in the United Kingdom.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-wireless-telegraphy-act-2006-spectrum",
    "title": "Wireless Telegraphy Act 2006",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Wireless Telegraphy Act 2006 requires that the use of wireless telegraphy apparatus be licensed, with certain exemptions, as outlined in Section 8. The Act applies to anyone using wireless telegraphy apparatus in the United Kingdom.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-communications-act-2003-ofcom-framework",
      "itu-radio-regulations-2020-edition"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uk-worker-protection-act-2023-effective-2024",
    "title": "UK Worker Protection (Amendment of Equality Act 2010) Act 2023 - Preventative Sexual Harassment Duty, Effective 26 October 2024",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Employers in England, Scotland and Wales must, from 26 October 2024, take reasonable steps to prevent sexual harassment of their employees in the course of their employment under the Worker Protection (Amendment of Equality Act 2010) Act 2023, regardless of size, sector or circumstance, by adopting a proactive and anticipatory programme including risk assessment, regular staff surveys, training, and prevention measures, with employment tribunals empowered to order up to 25 percent additional compensation where the preventative duty has not been met and the Equality and Human Rights Commission empowered to take enforcement action where there is evidence of organisations failing to take reasonable steps.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uk-worker-protection-act-2023-sexual-harassment-employer-duty",
    "title": "UK Worker Protection (Amendment of Equality Act 2010) Act 2023 - Employer Duty to Prevent Sexual Harassment",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Worker Protection (Amendment of Equality Act 2010) Act 2023 (UK) introduces a positive employer duty to take reasonable steps to prevent sexual harassment of employees in the course of their employment, commenced 26 October 2024. Section 1 inserts new section 40A into the Equality Act 2010 requiring the duty. Section 2 enables enforcement by the Equality and Human Rights Commission (EHRC) through investigations and unlawful act notices. Section 3 amends the Equality Act 2010 to allow Employment Tribunals to uplift compensation in sexual harassment claims by up to 25% where the employer breached the preventative duty. The Act applies to all employers regardless of size and covers harassment by third parties such as customers, clients, or members of the public during the course of employment. EHRC Technical Guidance issued in September 2024 sets out what 'reasonable steps' means: risk assessment, policies, training, reporting mechanisms, and active monitoring. Breach of the preventative duty exposes employers to EHRC enforcement plus compensation uplift in any successful harassment claim.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-equality-act-2010-protected-characteristics",
      "uk-equality-act-2010-section-39-employment-equality-duty",
      "ilo-c190-violence-harassment-2019"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-working-time-regulations-1998-regulation-4-maximum-weekly-working-time",
    "title": "UK Working Time Regulations 1998 Regulation 4 - Maximum Weekly Working Time (48 Hours Average Over 17 Week Reference Period, Written Opt-Out Agreement, Employer Compliance Duty)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Regulation 4 of the Working Time Regulations 1998 (SI 1998/1833) establishes the foundational UK working time limit - the 48-hour average maximum weekly working time. Under regulation 4(1), unless his employer has first obtained the worker's agreement in writing to perform such work, a worker's working time, including overtime, shall not exceed an average of 48 hours for each seven days in the relevant reference period. Under regulation 4(2), the employer must take all reasonable steps, in keeping with the need to protect the health and safety of workers, to ensure compliance with the limit. Under regulation 4(3), the reference period is 17 weeks in the absence of a relevant collective or workforce agreement varying it; relevant agreements may extend to 52 weeks under regulation 23. Under regulation 4(4), for workers with less than 17 weeks of employment, the reference period is the actual time elapsed. Under regulation 4(5), workers excluded under regulation 21 (specific sectors including emergency services and certain transport) use 26-week reference periods. Under regulation 4(6), average working hours are calculated using the formula (A+B)/C where A is hours during the reference period, B is hours in the subsequent period needed to compensate for excluded days, and C is the number of weeks in the reference period. Under regulation 4(7), excluded days for the calculation are annual leave, sick leave, maternity/paternity/adoption/parental leave, and periods when the worker had opted out. Failure to take reasonable steps is enforceable by HSE/LA under regulation 28 (or by ET for related detriment under ERA 1996 s.45A).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "regulation_4_text",
        "reference_period_17_weeks_default_extension_to_52_weeks",
        "written_opt_out_agreement_regulation_5_individual_voluntary",
        "employer_reasonable_steps_duty_regulation_4_2",
        "excluded_workers_regulation_21_long_list_specific_sectors",
        "enforcement_dual_track_hse_la_and_et_section_45a",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-health-and-safety-at-work-act-1974-section-2-employer-general-duties"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uk-yemen-sanctions-eu-exit-no2-regulations-2020-si-1278",
    "title": "UK Yemen (Sanctions) (EU Exit) (No. 2) Regulations 2020 SI 2020/1278 UN Asset Freezes Arms Embargo Trade Restrictions and Maritime Enforcement",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Yemen (Sanctions) (EU Exit) (No. 2) Regulations 2020 establish the United Kingdom framework implementing the UN Security Council Yemen sanctions regime under Resolution 2140 (2014) and Resolution 2216 (2015) organised in 10 parts covering general provisions in Part 1, designation in Part 2 based on UN Security Council criteria including persons threatening peace security and stability in Yemen, finance restrictions in Part 3 with asset freezes and prohibitions on making funds available, immigration measures in Part 4, trade restrictions in Part 5 covering military goods technology related services and the Yemen arms embargo on Houthi forces, exceptions and licences in Part 6, information and records in Part 7, enforcement in Part 8 with criminal penalties and OFSI monetary penalties, maritime enforcement in Part 9 with stop board search and seizure powers including off the Yemeni coast, and supplementary provisions in Part 10. The Regulations include two schedules covering ownership interpretation rules and Treasury licensing purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-zimbabwe-sanctions-eu-exit-regulations-2019-si-604",
    "title": "UK Zimbabwe (Sanctions) (EU Exit) Regulations 2019 SI 2019/604 Autonomous Asset Freezes Immigration Restrictions Military Goods Controls and Maritime Enforcement",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Zimbabwe (Sanctions) (EU Exit) Regulations 2019 establish the United Kingdom autonomous sanctions framework targeting Zimbabwe organised in 10 parts covering general provisions in Part 1, designation criteria in Part 2 including persons whose activities undermine democracy rule of law or violate human rights in Zimbabwe, finance restrictions in Part 3 with asset freezes and prohibitions on making funds or economic resources available to designated persons, immigration measures in Part 4 making designated persons excluded from the UK, trade restrictions in Part 5 covering military goods technology related services and goods that may be used for internal repression, exceptions and licences in Part 6 with Treasury and trade licensing mechanisms, information and records duties in Part 7, enforcement provisions in Part 8 with criminal penalties officer liability and OFSI monetary penalty powers, maritime enforcement in Part 9 with stop board search and seizure powers, and supplementary provisions in Part 10. The Regulations include three schedules covering ownership interpretation rules restricted goods lists and Treasury licensing purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-sanctions-anti-money-laundering-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uk-zoo-licensing-act-1981",
    "title": "UK Zoo Licensing Act 1981 (c.37): Licensing, Conservation Measures and Inspection of Zoos",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Zoo Licensing Act 1981 (c. 37) requires the licensing of zoos in Great Britain by local authorities, mandates conservation and welfare measures, and provides for inspection and closure, administered by local authorities with the advice of appointed inspectors. Section 1 requires that no person operate a zoo, defined as an establishment where wild animals are kept for exhibition to the public, except under the authority of a licence granted by the local authority. Section 1A requires the implementation of conservation measures, including participating in conservation programmes, promoting public education and awareness, and providing accommodation that meets the animals' biological and conservation needs. Section 2 governs the application for a licence and section 4 governs the grant or refusal of a licence, including the considerations of public health and safety and animal welfare. Section 10 provides for periodical inspections of licensed zoos and section 11 provides for special inspections. Section 16B provides for a zoo closure direction where a licence is revoked or refused, requiring the proper disposal of the animals, and section 16C provides for closure directions for zoos operating without a licence. Section 19 sets out the offences and penalties, including operating a zoo without a licence. The Act is the foundational zoo licensing, conservation, and welfare regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "ukraine-law-on-legal-status-foreigners-3773-vi-2011",
    "title": "Ukraine Law on Legal Status of Foreigners No. 3773-VI of 2011 - SMS Residence and Visa Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Ukraine's Law on the Legal Status of Foreigners and Stateless Persons No. 3773-VI (2011) governs entry, stay, and departure of non-Ukrainian nationals, administered by the State Migration Service of Ukraine (SMS - Derzhavna Mihratsiina Sluzhba Ukrainy) under the Ministry of Internal Affairs. Ukraine introduced visa-free travel with the European Union in June 2017 (90 days in any 180-day period for holders of Ukrainian biometric passports, reciprocated for EU nationals). Ukraine's residence permit system includes Temporary Residence Permit (TRP) and Permanent Residence Permit (PRP). The D-Type visa is required for initial entry for non-visa-free nationals and for establishing long-stay residence. During the ongoing armed conflict with Russia (since February 2022), martial law has been extended and certain immigration rules have been modified: male Ukrainian nationals (18-60) are restricted from leaving, and displaced populations (internally and internationally) have triggered specific protection frameworks. Ukraine maintains the EU-Ukraine Free Trade Area (DCFTA) and EU Association Agreement, which extended EU-style professional qualification recognition. The EU temporary protection directive has been applied to Ukrainian nationals in EU member states as of March 2022.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_visa_liberalisation",
        "eu_temporary_protection",
        "dcfta_eu_association",
        "employment_law",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ukraine-space-activities-law-1996",
    "title": "Ukraine Law on Space Activities 1996 - National Space Licensing Framework",
    "domain": "Space & Satellite Law",
    "version": "1996-11",
    "last_updated": "2026-05-09",
    "bluf": "Ukraine's Law on Space Activities (No. 502/96-VR, 1996, as amended) establishes the State Space Agency of Ukraine (SSAU) as the national regulator for space activities, creates a licensing regime for space operators including Yuzhnoye Design Bureau and Yuzhmash manufacturers, and implements UN space treaty obligations; amendments reflect participation in Vega and other international launch programmes and Artemis Accords signature in 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967-article-i-freedom",
      "copuos-lts-guidelines-2019-space-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "un-ai-advisory-body-2024",
    "title": "UN Secretary-General AI Advisory Body Interim Report 2024 - Governing AI for Humanity",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-03-21",
    "bluf": "This interim report from the UN's AI Advisory Body proposes a framework for global AI governance, recommending the creation of a new UN-affiliated agency to coordinate international efforts. It establishes five core principles for AI governance: inclusivity, public interest, data governance, universality, and alignment with the UN Charter and international human rights law (Principle 1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "unesco-ethics-ai",
      "g7-hiroshima-ai-process-2023",
      "us-eo-14110-ai-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-arms-trade-treaty-2013",
    "title": "UN Arms Trade Treaty - ATT 2013",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The ATT (113 State Parties as of April 2026) prohibits arms transfers where the exporting state has knowledge they will be used for genocide, crimes against humanity, or grave breaches of the Geneva Conventions (Article 6), requires pre-export risk assessment for all transfers of tanks, armoured vehicles, LACV, warships, combat aircraft, missiles/MLRs, small arms, and light weapons (Article 7), and mandates minimum 10-year record-keeping (Article 12) and annual reporting (Article 13); defence exporters, brokers, and transit-state operators face criminal and civil liability for violations under domestic implementing legislation, and must integrate ATT diversion-prevention obligations with EU Regulation 2021/821 (dual-use), EU Directive 2009/43/EC (intra-EU transfers), and FATF proliferation financing standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "opcw-cwc-1993-chemical-weapons-convention",
      "un-npt-1968-nuclear-non-proliferation",
      "eu-dual-use-regulation-2021-821",
      "un-guiding-principles-business-human-rights"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-bbnj-agreement-2023-marine-biodiversity",
    "title": "UN Agreement on Marine Biological Diversity of Areas Beyond National Jurisdiction - BBNJ 2023 (High Seas Treaty)",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The BBNJ Agreement (adopted June 2023, 106+ signatures as of April 2026, not yet in force - requires 60 ratifications) establishes the first comprehensive international legal framework for conservation and sustainable use of marine biodiversity in areas beyond national jurisdiction (ABNJ - high seas and the seabed beyond national limits); it mandates Environmental Impact Assessments for activities in ABNJ (Article 22-35), creates access and benefit-sharing obligations for marine genetic resources (Article 10-16), establishes area-based management tools (ABMT/MPAs) under Article 17-21, and includes capacity-building and technology transfer provisions (Article 43-51) - creating major new compliance obligations for maritime operators, deep-sea mining entities, pharmaceutical and biotech companies exploiting marine genetic resources, and shipping companies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unclos-part-xi-deep-seabed-mining-1982",
      "nagoya-protocol-genetic-resources-2010",
      "un-cbd-kunming-montreal-gbf-2022",
      "cites-convention-1973-endangered-species-trade"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-biological-weapons-convention-1972",
    "title": "Convention on the Prohibition of the Development, Production and Stockpiling of Bacteriological (Biological) and Toxin Weapons and on Their Destruction",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The BWC prohibits state parties from developing, producing, stockpiling, acquiring, or retaining biological agents or toxins of types and in quantities that have no justification for peaceful purposes, under Article I. It applies to all signatory states and their governmental, military, and biotechnological institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l3",
      "nist-sp-1800-32-securing-ders"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-cat-1984-article-3-non-refoulement-torture",
    "title": "UN Convention against Torture 1984 Article 3 - Absolute Non-Refoulement to Torture and Committee Against Torture Communications",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Convention against Torture and Other Cruel, Inhuman or Degrading Treatment or Punishment (CAT), adopted by UN General Assembly resolution 39/46 on 10 December 1984 and entered into force on 26 June 1987, is the principal international instrument prohibiting torture. Article 1 defines torture as any act by which severe pain or suffering, whether physical or mental, is intentionally inflicted on a person for purposes such as obtaining information, punishment, intimidation or discrimination, by or with the consent or acquiescence of a public official. Article 3(1) establishes the absolute non-refoulement principle: no State Party shall expel, return (refouler) or extradite a person to another State where there are substantial grounds for believing they would be in danger of being subjected to torture. Unlike Refugee Convention Article 33 non-refoulement which contains national security and serious crime exceptions, Article 3 CAT is absolute and non-derogable even in time of war or public emergency under Article 2(2). Article 22 establishes individual communications procedure for States accepting that competence, allowing the Committee Against Torture (CAT Committee) to receive complaints. As of 2024, 174 States are Parties; 73 States have accepted Article 22 individual communications competence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-refugee-convention-1951-protocol-1967-non-refoulement",
      "eu-dublin-iii-regulation-604-2013-asylum-responsibility"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-cat-1984-convention-against-torture",
    "title": "UN CAT 1984 - Convention Against Torture and Other Cruel, Inhuman or Degrading Treatment or Punishment",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Convention Against Torture and Other Cruel, Inhuman or Degrading Treatment or Punishment (CAT), adopted by the UN General Assembly on 10 December 1984 (Resolution 39/46) and entering into force on 26 June 1987, has 174 States Parties and establishes the absolute and non-derogable prohibition of torture under international law. The CAT is monitored by the Committee Against Torture (10 independent experts) through State Party reports; the Optional Protocol to the CAT (OPCAT, adopted 2002, in force 2006, 91 States Parties) establishes the Subcommittee on Prevention of Torture (SPT) and National Preventive Mechanisms (NPMs) - independent bodies in each OPCAT State Party with the mandate to visit all places of deprivation of liberty. Article 1 defines torture as any act by which severe pain or suffering, whether physical or mental, is intentionally inflicted on a person by or at the instigation of, or with the consent or acquiescence of, a public official or other person acting in an official capacity, for purposes of obtaining information or a confession, punishing, intimidating, coercing, or for reasons based on discrimination. Article 2 imposes an absolute prohibition - no exceptional circumstances, whether war, political instability, public emergency, or order from a superior officer, may be invoked as a justification for torture. Article 3 establishes the principle of non-refoulement - no State Party shall expel, return (refouler), or extradite a person to another State where there are substantial grounds for believing that he would be in danger of being subjected to torture; this is the strongest extradition limitation in international law. Article 4 requires States to criminalise torture. Articles 5-9 establish universal jurisdiction - States must establish jurisdiction over torture offences committed in their territory, on their flag vessels/aircraft, when the victim or alleged offender is a national, or when the alleged offender is present in the State's territory, providing an extradite-or-prosecute obligation. Article 10 mandates training of law enforcement, military, medical, and other personnel involved in detention and interrogation. Article 11 requires systematic review of interrogation rules. Article 12 imposes an obligation to conduct a prompt and impartial investigation when there are reasonable grounds to believe torture has occurred. Article 15 requires exclusion of evidence obtained by torture from any proceedings. Article 16 requires prevention of cruel, inhuman, or degrading treatment (CIDT) not amounting to torture. Corporate and supply chain relevance: the CAT and OPCAT intersect with corporate compliance obligations in multiple ways: (a) private contractors operating detention facilities have direct CAT obligations where State consent or acquiescence is present; (b) technology companies supplying facial recognition, predictive policing, or digital surveillance to governments with documented torture practices engage CAT Article 1 acquiescence risk; (c) supply chain due diligence laws (CSDDD Annex Part I, LkSG Section 2(1)) reference CAT Article 1 torture prohibition as a key adverse human rights impact; (d) modern slavery risk assessments must assess CAT violations in supplier countries; (e) export control of CBRN detection and law enforcement equipment to governments with documented torture must satisfy CAT-consistent end-use assurances.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-guiding-principles-business-human-rights",
      "eu-corporate-sustainability-due-diligence-2024",
      "un-convention-against-corruption-uncac-2003"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-cbd-kunming-montreal-gbf-2022",
    "title": "Kunming-Montreal Global Biodiversity Framework 2022 - 30×30 Target & Corporate Nature Disclosure",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Kunming-Montreal Global Biodiversity Framework (KM-GBF), adopted at CBD COP15 on 19 December 2022, sets 23 action targets for 2030 and 4 goals for 2050 to halt and reverse biodiversity loss. Target 3 ('30×30') requires at least 30% of land, inland waters, coastal areas, and oceans to be effectively conserved by 2030. Target 15 mandates large companies and financial institutions to assess and disclose biodiversity-related risks, impacts, and dependencies. Target 19 mobilises at least USD 200 billion per year for biodiversity, with developed countries providing USD 20 billion per year to developing countries by 2025, rising to USD 30 billion by 2030, and closing the USD 700 billion harmful subsidy gap. The GBF is directly implemented in EU corporate law through the CSRD (ESRS E4 - Biodiversity) and indirectly through the EU Deforestation Regulation, creating mandatory nature-related disclosure obligations for ~50,000 EU companies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csrd-2022-2464",
      "eu-sfdr-2019-2088"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-cedaw-1979-discrimination-against-women",
    "title": "UN CEDAW 1979 - Convention on the Elimination of All Forms of Discrimination Against Women",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Convention on the Elimination of All Forms of Discrimination Against Women (CEDAW), adopted by the UN General Assembly on 18 December 1979 (Resolution 34/180) and entering into force on 3 September 1981, has 189 States Parties - one of the most widely ratified human rights treaties globally, with the US being a notable non-party. CEDAW has been described as the international bill of rights for women and establishes a comprehensive framework for eliminating discrimination against women in all fields of law and public life. Article 1 defines discrimination against women as any distinction, exclusion, or restriction made on the basis of sex that has the effect or purpose of impairing or nullifying the recognition, enjoyment, or exercise of human rights and fundamental freedoms in the political, economic, social, cultural, civil, or any other field. Article 2 imposes comprehensive obligations on States Parties: to condemn discrimination against women in all forms; to take all appropriate measures including legislation to prohibit it; to establish legal protection; to refrain from discriminatory acts; to ensure public authorities and institutions act accordingly; to take appropriate measures to modify or abolish existing discriminatory laws, regulations, customs, and practices. Article 4 permits temporary special measures (positive action, gender quotas in governance and employment) as not constituting discrimination. CEDAW Article 11 is the foundational international instrument for gender equality in employment: the right to work as an inalienable right; the right to the same employment opportunities and selection criteria; equal pay for equal work including benefits; the right to social security; the right to paid leave; and critically - the prohibition on dismissal on grounds of pregnancy or marital status, and protection against pregnancy-related discrimination. Article 12 requires elimination of discrimination in healthcare including reproductive health. Article 14 addresses rural women. Article 15 requires equality before the law. The CEDAW Committee (23 independent experts) monitors compliance; the Optional Protocol (1999, in force 2000, 115 Parties) enables individual communications and inquiry procedures. Corporate compliance relevance: CEDAW forms the foundation for the EU Pay Transparency Directive (Directive 2023/970), which implements CEDAW Article 11 equal pay obligations with binding gender pay gap reporting, pay audits, and pay equity litigation rights; ESRS S1 requires gender pay gap disclosure, percentage of women in management, and maternity leave usage metrics; CSDDD Annex Part I references CEDAW as a primary instrument; LkSG Section 2(1) includes gender-based violence and harassment; CEDAW General Recommendation 35 (2017) on gender-based violence updates GR 19 (1992) and is the authoritative CEDAW framework on violence against women in the workplace, complementing ILO Convention C190.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "eu-employment-equality-directive-2000-78",
      "eu-csrd-2022-2464",
      "eu-corporate-sustainability-due-diligence-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-cisg-1980",
    "title": "United Nations Convention on Contracts for the International Sale of Goods (CISG)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The CISG establishes a uniform framework for international commercial contracts for the sale of goods, automatically applying when parties have their places of business in different Contracting States. It governs contract formation and the obligations of buyers and sellers, but parties can explicitly exclude its application under Article 6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-arbitration",
      "hague-convention-service-abroad",
      "incoterms-2020-ddp-v2"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "un-convention-against-corruption-uncac-2003",
    "title": "United Nations Convention against Corruption (UNCAC)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UN Convention against Corruption is a legally binding multilateral treaty that obligates States Parties to implement comprehensive anti-corruption measures, including the criminalization of offenses like bribery and embezzlement (Chapter III), establishing preventive policies (Chapter II), fostering international cooperation (Chapter IV), and enabling asset recovery (Chapter V).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fcpa-anti-bribery-compliance",
      "uk-bribery-act-2010",
      "iso-37001-anti-bribery-2016",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "un-convention-biological-diversity-cbd-1992",
    "title": "UN Convention on Biological Diversity 1992 - Sovereign Rights over Genetic Resources, Access and Benefit-Sharing Obligations, Conservation In Situ/Ex Situ and Technology Transfer Provisions",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Convention on Biological Diversity establishes sovereign rights over genetic resources, requiring states to ensure fair and equitable benefit-sharing from their utilization and to conserve biodiversity in situ and ex situ. Key obligations are outlined in Article 15 (Access to Genetic Resources) and Article 8 (In-Situ Conservation).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nagoya-protocol-genetic-resources-2010",
      "cartagena-protocol-biosafety-2000",
      "cbd-convention-biological-diversity-1992"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-convention-reduction-statelessness-1961",
    "title": "UN Convention on the Reduction of Statelessness 1961 - Birth-Based Nationality, Loss Restrictions and State Succession",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Convention on the Reduction of Statelessness, adopted at New York on 30 August 1961 and entered into force on 13 December 1975, complements the 1954 Statelessness Convention by establishing rules to prevent and reduce statelessness through nationality law. As of 2024 the Convention has 79 States parties. The Convention obliges Contracting States to grant nationality to persons who would otherwise be stateless and to limit deprivation of nationality. Article 1 requires a Contracting State to grant nationality to a person born in its territory who would otherwise be stateless; Article 4 requires nationality grant by descent if the person would otherwise be stateless and one parent was a national of the Contracting State at time of birth. Articles 5-7 restrict loss of nationality by change of personal status (marriage, dissolution of marriage, legitimation, recognition, adoption) where it would result in statelessness. Article 8 prohibits deprivation of nationality if it would render the person stateless, with limited exceptions including misrepresentation or fraud. Article 9 prohibits deprivation of nationality on racial, ethnic, religious or political grounds. Article 10 addresses State succession requiring transfer treaties to include provisions to avoid statelessness. The Convention is supervised by UNHCR under its statelessness mandate.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-convention-statelessness-1954"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-convention-rights-child-education-article-28",
    "title": "Convention on the Rights of the Child - Article 28: Right to Education",
    "domain": "Education & Research",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "States Parties must ensure the right of the child to education by making primary education compulsory and available free to all, encouraging the development of different forms of secondary education accessible to every child, and ensuring discipline in schools is consistent with the child's human dignity. Applies to all national governments that are signatories to the UN Convention on the Rights of the Child, particularly in education policy and implementation (Article 28).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-21001-2018-educational-organizations-management",
      "oecd-pisa-education-assessment-framework-2022",
      "eu-digital-education-action-plan-2021-2027-deap",
      "india-national-education-policy-nep-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-convention-rights-of-child-1989-article-3-best-interests",
    "title": "UN Convention on the Rights of the Child 1989 - Article 3 Best Interests, Article 12 Participation and General Principles",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Convention on the Rights of the Child (CRC), adopted by UN General Assembly resolution 44/25 on 20 November 1989 and entered into force on 2 September 1990, is the most widely ratified human rights treaty in history with 196 States Parties (the United States is the only UN Member State not having ratified; signed but not ratified). Article 1 defines child as every human being below the age of 18 years unless under law applicable to the child majority is attained earlier. The Convention is structured around four General Principles articulated by the Committee on the Rights of the Child: Article 2 (non-discrimination), Article 3 (best interests of the child), Article 6 (right to life, survival and development), and Article 12 (right of child to express views and be heard). Article 3(1) requires that in all actions concerning children, whether undertaken by public or private social welfare institutions, courts of law, administrative authorities or legislative bodies, the best interests of the child shall be a primary consideration. The Committee's General Comment No. 14 (2013) on the right of the child to have his or her best interests taken as a primary consideration provides detailed implementation guidance. The CRC has three Optional Protocols: OPSC (Sale of Children, Child Prostitution and Child Pornography 2000), OPAC (Children in Armed Conflict 2000), and OPIC (Communications Procedure 2011).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-refugee-convention-1951-protocol-1967-non-refoulement",
      "un-cat-1984-article-3-non-refoulement-torture"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-convention-statelessness-1954",
    "title": "UN Convention Relating to the Status of Stateless Persons 1954 - Definition, Rights and UNHCR Protection Mandate",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Convention relating to the Status of Stateless Persons, adopted at New York on 28 September 1954 and entered into force on 6 June 1960, is the principal multilateral treaty defining who is a stateless person and the rights and obligations of States parties toward stateless persons in their territory. As of 2024 the Convention has 96 States parties. Article 1(1) provides the binding international definition: a stateless person is a person who is not considered as a national by any State under the operation of its law (the de jure stateless definition; persons unable to enjoy nationality in practice are addressed as de facto stateless and protected through related instruments). The Convention parallels the 1951 Refugee Convention in structure: Articles 3-32 set out the rights to be accorded to stateless persons including non-discrimination, religion, property, association, access to courts, public education, public relief, labour legislation, social security, freedom of movement (Article 26), and identity papers/travel documents (Article 27-28). Article 31 provides protection from expulsion except on national security or public order grounds. Article 33 deals with naturalisation, with States parties undertaking to facilitate the assimilation and naturalisation of stateless persons. The Convention is overseen by the United Nations High Commissioner for Refugees (UNHCR) under its statelessness mandate; UNHCR's #IBelong Campaign launched in 2014 aimed at ending statelessness by 2024 and has been extended.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-refugee-convention-1951-protocol-1967-non-refoulement"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-convention-suppression-financing-terrorism-1999",
    "title": "International Convention for the Suppression of the Financing of Terrorism, 1999",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The 1999 UN Convention criminalizes the wilful provision or collection of funds intended to finance terrorist acts (Article 2) and requires each State Party to establish these as criminal offences with appropriate penalties (Article 4) and to provide for the liability of legal entities (Article 5). It obliges States to take measures for the identification, detection, freezing or seizure and forfeiture of terrorist funds (Article 8), to afford mutual legal assistance without refusing on grounds of bank secrecy (Article 12), and to require financial institutions to identify customers, scrutinise and report suspicious transactions, and keep transaction records for at least five years (Article 18).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-6-targeted-sanctions-terrorism",
      "fatf-40-recommendations-2023-consolidated"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "un-copuos-space-debris-mitigation-guidelines-2007",
    "title": "UN COPUOS Space Debris Mitigation Guidelines - International Debris Framework",
    "domain": "Space & Satellite Law",
    "version": "2007 (endorsed by UNGA Resolution 62/217)",
    "last_updated": "2026-05-09",
    "bluf": "The UN Committee on the Peaceful Uses of Outer Space (COPUOS) Space Debris Mitigation Guidelines (adopted 2007, endorsed by UNGA Resolution 62/217) establish the international consensus framework for debris mitigation: seven guidelines covering operational debris limits, passivation of energy sources, collision avoidance, intentional destruction prohibitions, 25-year post-mission disposal rule for LEO, and GEO graveyard orbit requirements at least 300 km above the operational arc.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ecss-u-ast-10c-space-debris-mitigation-requirements",
      "iadc-space-debris-mitigation-guidelines-2007"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-crpd-convention-rights-persons-disabilities-2006",
    "title": "Convention on the Rights of Persons with Disabilities - Preamble",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This convention establishes the foundational principles for ensuring persons with disabilities enjoy all human rights and fundamental freedoms on an equal basis with others, without discrimination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "un-drip-2007-indigenous-peoples-rights-fpic",
    "title": "United Nations Declaration on the Rights of Indigenous Peoples (UNDRIP) - Articles on Free, Prior, and Informed Consent",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations must consult and cooperate in good faith with indigenous peoples to obtain their free, prior, and informed consent before initiating projects or measures that may affect their lands, territories, resources, or cultural heritage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "un-fashion-sustainability-2022",
    "title": "UN Alliance for Sustainable Fashion - Circular Economy and Extended Producer Responsibility Framework for Textiles",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This UN framework provides guidance for the fashion and textile industry to implement circular economy principles and Extended Producer Responsibility (EPR) schemes. It requires stakeholders, particularly brands and producers, to take financial and operational responsibility for the entire product lifecycle, including post-consumer collection, sorting, and recycling, as detailed in its Core Principles for an EPR system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-espr-ecodesign",
      "iso-14001-ems",
      "iso-20400-sustainable-proc",
      "un-sdg-alignment"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-fish-stocks-agreement-1995",
    "title": "UN Fish Stocks Agreement - UNFSA 1995 (Straddling and Highly Migratory Stocks)",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The UNFSA (92 State Parties as of April 2026) implements UNCLOS Articles 63-64 by establishing binding conservation and management obligations for straddling and highly migratory fish stocks on the high seas, requiring States to apply the precautionary approach (Article 6 and Annex II reference points), ecosystem approach, and compatibility principle (Article 7) between EEZ and high-seas measures; fishing companies and seafood supply chains sourcing from UNFSA-regulated Regional Fisheries Management Organisation (RFMO) areas must comply with RFMO conservation measures, vessel monitoring system (VMS) requirements, catch documentation schemes, and port state controls that directly affect market access - non-compliant catches are blocked from entry into EU, US, and other major markets under IUU fishing regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unclos-part-v-exclusive-economic-zone",
      "un-bbnj-agreement-2023-marine-biodiversity",
      "cites-convention-1973-endangered-species-trade",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-framework-classification-resources-unfc",
    "title": "UN Framework Classification for Resources (UNFC) 2019 - Bridging Mineral, Energy and Renewable Resource Classification: E, F, G Axes, Harmonisation with JORC/SPE-PRMS and Project Status Assessment",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The UN Framework Classification for Resources (UNFC 2019) requires project owners to assign a classification code based on three axes - E (environmental-socio-economic viability, E1-E3), F (technical feasibility, F1-F4), and G (geological knowledge, G1-G4) - for all mineral, energy, and renewable resource projects; UNFC supports alignment with national reporting codes (JORC, NI 43-101, SAMREC, SPE-PRMS) for cross-border investment and policy reporting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eiti-standard-2023",
      "gri-14-mining-sector-standard-2022",
      "icmm-mining-principles-2020",
      "canada-national-instrument-43-101",
      "eu-taxonomy-mining-sustainable-activities"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-ga-resolution-78-265-ai-2024",
    "title": "UN General Assembly Resolution A/RES/78/265 - Seizing the Opportunities of Safe, Secure and Trustworthy AI for Sustainable Development (March 21 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "UN General Assembly Resolution 78/265 was adopted by consensus by all 193 UN Member States on March 21, 2024. The Resolution, titled Seizing the Opportunities of Safe, Secure and Trustworthy AI Systems for Sustainable Development, is the first global UN consensus resolution on AI. It was led by the United States and co-sponsored by 122 Member States. The Resolution: (1) Recognises the potential of AI to accelerate progress on the 2030 Agenda for Sustainable Development and the Sustainable Development Goals; (2) Calls on Member States and other stakeholders to refrain from or cease the use of AI systems that are inconsistent with international human rights law or that pose undue risks to the enjoyment of human rights; (3) Encourages Member States to develop and support regulatory and governance approaches for safe, secure, and trustworthy AI systems; (4) Calls for cooperation on capacity building - including resources, infrastructure, data, training, and education - to bridge digital divides and enable developing countries to benefit from AI; (5) Encourages standards bodies, academia, and civil society to participate in the development of frameworks for trustworthy AI; (6) Requests the Secretary-General to report back on implementation. The Resolution is non-binding but represents the high-water mark of global political consensus on AI and informs subsequent UN initiatives including the Global Digital Compact and the work of the High-Level Advisory Body on AI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "international_alignment",
        "industry_mapping",
        "regulatory_overlay",
        "human_rights_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-ai-advisory-body-2024",
      "council-of-europe-ai-treaty-2024",
      "unesco-ai-ethics-work"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "un-genocide-convention-1948-prevention-punishment",
    "title": "UN Genocide Convention 1948 - Genocide Definition Article II and Obligation to Prevent and Punish",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Convention on the Prevention and Punishment of the Crime of Genocide was adopted by UN General Assembly resolution 260 A (III) on 9 December 1948 and entered into force on 12 January 1951. It was the first human rights treaty adopted by the UN General Assembly and codifies the crime of genocide and obligations of States Parties to prevent and punish it. Article II defines genocide as any of the following acts committed with intent to destroy, in whole or in part, a national, ethnical, racial or religious group, as such: (a) killing members of the group; (b) causing serious bodily or mental harm to members of the group; (c) deliberately inflicting on the group conditions of life calculated to bring about its physical destruction in whole or in part; (d) imposing measures intended to prevent births within the group; (e) forcibly transferring children of the group to another group. Article III makes punishable: genocide, conspiracy, direct and public incitement, attempt, and complicity. Article I confirms that genocide, whether committed in time of peace or war, is a crime under international law which States undertake to prevent and to punish. The International Court of Justice (ICJ) in Bosnia and Herzegovina v Serbia and Montenegro (2007) confirmed the obligations of prevention and punishment as positive obligations. 153 States Parties as of 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-cat-1984-article-3-non-refoulement-torture",
      "un-refugee-convention-1951-protocol-1967-non-refoulement"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-global-compact-migration-2018-23-objectives",
    "title": "UN Global Compact for Safe, Orderly and Regular Migration 2018 - 23 Objectives and Whole-of-Government Implementation",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Global Compact for Safe, Orderly and Regular Migration (GCM) was adopted by 152 UN Member States at the Intergovernmental Conference in Marrakech, Morocco on 10-11 December 2018, and formally affirmed by UN General Assembly resolution 73/195 of 19 December 2018. The Compact is a non-binding cooperative framework presenting the first ever UN comprehensive intergovernmental agreement to cover all dimensions of international migration. The Compact sets out 23 Objectives covering data collection, factors driving migration, age and gender-responsive policies, recruitment practices, irregular migration, family reunification, return and readmission, and other dimensions. The 23 Objectives are underpinned by 10 cross-cutting and interdependent guiding principles including people-centered approach, international cooperation, national sovereignty, rule of law, sustainable development, human rights, gender-responsive policies, child-sensitive approach, whole-of-government approach, and whole-of-society approach. The first International Migration Review Forum (IMRF) was held in May 2022, with subsequent reviews every 4 years. The UN Network on Migration coordinates UN system support for GCM implementation, with IOM (International Organization for Migration) as coordinator. As of 2024, over 100 States have voluntary national implementation plans.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-refugee-convention-1951-protocol-1967-non-refoulement",
      "un-palermo-protocol-2000-trafficking-persons"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-global-compact-supply-chain-minerals",
    "title": "UN Global Compact - Supply Chain Sustainability in Mining: Ten Principles, Due Diligence on Human Rights, Labour, Environment and Anti-Corruption in Mineral Supply Chains and Supplier Engagement",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This framework requires companies in the mining and mineral supply chain sectors to implement due diligence processes aligned with the UN Guiding Principles on Business and Human Rights (UNGPs), OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas, and the UN Global Compact’s Ten Principles covering human rights, labour, environment, and anti-corruption. It applies to all enterprises engaged in extraction, processing, trade, or sourcing of minerals globally, particularly tin, tantalum, tungsten, gold, cobalt, and lithium.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-conflict-minerals-regulation-2017-821",
      "eiti-standard-2023",
      "canada-national-instrument-43-101",
      "drc-mining-code-law-18-001-2018",
      "australia-epbc-act-1999-mining-biodiversity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-global-compact-supply-chain-sustainability",
    "title": "UN Global Compact Supply Chain Sustainability Guide - Value Chain Governance, Supplier Engagement, Social and Environmental Standards and Grievance Mechanisms",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This guide requires businesses to integrate the Ten Principles of the UN Global Compact into their supply chain governance, including human rights, labor, environment, and anti-corruption standards, with specific attention to supplier engagement and grievance mechanisms. It applies to all participating companies in global supply chains, particularly those in high-impact sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-deforestation-regulation-2023",
      "eu-forced-labour-regulation-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-global-digital-compact",
    "title": "UN Global Digital Compact (Data Governance)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Enterprises must align their governance frameworks with principles articulated in the United Nations Global Digital Compact under Objective 4, which champions a people-centric approach to data emphasizing trust, accountability, and protection of fundamental human rights. Compliance requires implementing robust mechanisms for international data stewardship. A key operational control is to `require_cross_border_data_transfer_agreement` for all such exchanges, safeguarding information as it moves globally. Furthermore, organizations are obligated to `mandate_human_rights_impact_assessment_hria` for data processing activities, proactively identifying and mitigating potential risks to individual freedoms and privacy. The Compact's principles necessitate a firm commitment to `ensure_data_minimization_across_jurisdictions`, limiting collection and processing activities to what is strictly necessary for specified purposes, thereby reducing systemic risk exposure. To empower individuals and foster genuine trust, transparency is paramount; therefore, policies must `require_multilingual_transparency_notices` ensuring clear, accessible communication about data practices for all stakeholders, irrespective of their language or location. Adherence to these measures demonstrates a commitment to ethical data handling and supports the GDC's vision for a safe, secure, and equitable digital future.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "nist-ai-rmf-1-0",
      "nist-sp-1270-managing-ai-bias"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "un-global-digital-compact-2024-ai-governance-commitments",
    "title": "UN Global Digital Compact (September 2024) - International AI Governance Commitments under the Pact for the Future",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "The UN Global Digital Compact (GDC) was adopted by UN Member States on 22 September 2024 at the Summit of the Future in New York as an annex to the Pact for the Future. The GDC is a comprehensive global framework for digital cooperation that includes substantive AI governance commitments. The Compact organises commitments under five overarching objectives covering digital divide closure, expanding inclusion, enabling responsible digital data flows, promoting human rights online, and addressing AI governance. AI-specific provisions include establishing an Independent International Scientific Panel on AI, launching a Global Dialogue on AI Governance, supporting capacity building for developing countries, and elaborating common AI safety, security, and trustworthiness principles. The GDC is non-binding political commitment but operationalised through the UN Office for Digital and Emerging Technologies, the UN High-level Advisory Body on AI, and national digital co-operation frameworks. The GDC is the first universally adopted UN-level instrument addressing AI governance directly and serves as the multilateral floor for AI cooperation alongside OECD Principles, G7 Hiroshima Process, and Council of Europe Framework Convention on AI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "council-of-europe-ai-treaty-2024",
      "g7-hiroshima-ai-process-2023-code-conduct"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-global-digital-compact-2024-principle-ai-governance-safety",
    "title": "Global Digital Compact",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This compact establishes a comprehensive global framework for digital cooperation and the governance of artificial intelligence, charting a roadmap to harness digital technology's potential and close digital divides.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-9-risk-management-system",
      "eu-ai-act-article-10-data-governance-training"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "un-global-digital-compact-ai-governance-2024",
    "title": "UN Global Digital Compact 2024 - AI Governance Principles: International Cooperation, Inclusive Development and Risk Management",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UN Global Digital Compact establishes a framework for international cooperation on AI governance, requiring member states and stakeholders to align AI development with human rights, the rule of law, and the Sustainable Development Goals (SDGs). It emphasizes risk-based approaches, accountability, and inclusive capacity building, as outlined in Commitment 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "unesco-ethics-ai",
      "g20-ai-principles-2019",
      "un-ai-advisory-body-2024",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "un-global-reporting-initiative-gri-standards-2021-sustainability-reporting",
    "title": "GRI Standards 2021 - Universal and Topic-Specific Sustainability Reporting Framework",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2023-01-01",
    "bluf": "The Global Reporting Initiative (GRI) Standards provide the most widely used global framework for sustainability reporting. The GRI Universal Standards (GRI 1, 2, 3) require all organisations to disclose their governance, strategy, material topics, and stakeholder engagement approach. Topic-specific standards (GRI 200 Economic, GRI 300 Environmental, GRI 400 Social) require disclosures on identified material topics. GRI 3 Materiality is a double materiality concept covering impacts on people and environment (inside-out) and financial risks to the organisation (outside-in). Over 10,000 organisations in 100+ countries report using GRI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-directive-article-2-scope-of-sustainability-reporting"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-gtrs-global-technical-regulations-vehicles",
    "title": "UN Global Technical Regulations (GTRs) - Harmonised Vehicle Standards: GTR 9 Pedestrian Safety, GTR 13 Hydrogen Fuel Cell, GTR 20 EVS, GTR 24 Brake Emissions (Light-Duty) and GTR 3 Motorcycle Brake Systems",
    "domain": "Automotive & Mobility",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The UN GTRs, developed under the 1998 Agreement and administered by the World Forum for Harmonization of Vehicle Regulations (WP.29) at UNECE, establish harmonized technical requirements for vehicle safety and environmental performance. This node covers pedestrian protection (GTR 9), hydrogen fuel cell vehicle safety (GTR 13), electric vehicle safety (GTR 20), the laboratory measurement of friction brake particulate emissions for light-duty vehicles - category M1 and N1 vehicles with a laden mass below 3,500 kg (GTR 24, adopted by WP.29 in June 2023), and motorcycle brake systems including Anti-lock Braking Systems (ABS) and Combined Braking Systems (CBS) (GTR 3, adopted 2006, major amendments adopted 2020). GTR 24 governs brake particulate emissions, not motorcycle braking; motorcycle ABS is governed by GTR 3. These regulations are referenced by Contracting Parties seeking type approval and are related to UN Regulations Nos. 155, 156 and 157.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "un-regulation-r157-automated-lane-keeping-alks",
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-guiding-principles-business-hr",
    "title": "UN Guiding Principles (BHR)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The United Nations Guiding Principles on Business and Human Rights (UNGP or 'Ruggie Principles') are the authoritative global standard for preventing and addressing the risk of adverse human rights impacts linked to business activity. Built on the 'Protect, Respect, and Remedy' framework, they provide actionable principles for both States and corporations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-fundamental-rights-work",
      "oecd-guidelines-multinational-ent"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-guiding-principles-business-hr-mining",
    "title": "UN Guiding Principles on Business and Human Rights - Mining Sector Application: Free Prior Informed Consent, Artisanal Mining and Operational Grievance Mechanisms",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires mining companies to respect human rights through the implementation of Free, Prior and Informed Consent (FPIC) processes with Indigenous Peoples, integrate artisanal and small-scale miners into formal operations where feasible, and establish operational-level grievance mechanisms to address community complaints. Key obligations are derived from the UN Guiding Principles on Business and Human Rights, particularly Principle 13 and Principle 29.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cmmi-capability-maturity-model-integration-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "un-guiding-principles-business-human-rights",
    "title": "Guiding Principles on Business and Human Rights: Implementing the United Nations 'Protect, Respect and Remedy' Framework",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This framework establishes a global standard for preventing and addressing human rights risks from business activity, based on three pillars: the State Duty to Protect, the Corporate Responsibility to Respect (Principle 11), and Access to Remedy for victims of business-related abuses.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "iso-26000-social-resp-mgt",
      "iso-31000-risk-mgt-std",
      "sa8000-social-account",
      "iso-20400-sustainable-procure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "un-hamburg-rules-1978-sea-carriage",
    "title": "UN Hamburg Rules 1978 - United Nations Convention on the Carriage of Goods by Sea",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Hamburg Rules 1978 modernised sea cargo liability by imposing fault-based liability on carriers for all cargo (including deck cargo and live animals), extending the carrier's period of responsibility from port-to-port, eliminating the nautical fault and fire defences available under the Hague-Visby Rules, raising package limits to SDR 835 per package or SDR 2.5 per kg, extending the time bar to two years, and giving cargo claimants a choice of five forums. 35 States have ratified; the Rules apply where parties contractually adopt them or where the forum State is a contracting party.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "hague_visby_rules",
        "rotterdam_rules_2008",
        "uncitral_model_law"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unclos-part-ii-territorial-sea-contiguous-zone",
      "imo-llmc-1976-protocol-1996-limitation-liability",
      "international-salvage-convention-1989"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-hlab-governing-ai-for-humanity-final-report-2024",
    "title": "UN High-Level Advisory Body on AI - Governing AI for Humanity Final Report (September 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The UN Secretary-General's High-Level Advisory Body on Artificial Intelligence (HLAB-AI) published Governing AI for Humanity as its Final Report on September 19, 2024, in advance of the UN Summit of the Future (September 22-23, 2024). The Body was established in October 2023 with 39 members from government, civil society, industry, and academia drawn from across geographies and AI domains. The Final Report sets out seven concrete recommendations to address gaps in global AI governance: (1) Establish an International Scientific Panel on AI to provide impartial scientific assessment of AI capabilities, opportunities, risks, and uncertainties; (2) Launch a Policy Dialogue on AI governance held biannually under UN auspices to align national approaches; (3) Establish an AI Standards Exchange to coordinate technical standards across multiple bodies (ISO/IEC JTC1/SC 42, ITU, IEEE, NIST); (4) Establish a Global AI Capacity Development Network providing training, infrastructure, and data resources to developing countries; (5) Establish a Global Fund for AI to provide pooled financing for AI capacity development and inclusion; (6) Establish a Global AI Data Framework setting common standards for data quality, provenance, and access; (7) Establish an AI Office in the UN Secretariat to coordinate these mechanisms. The Final Report and its recommendations directly informed the Global Digital Compact adopted at the Summit of the Future, particularly the AI provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "international_alignment",
        "industry_mapping",
        "regulatory_overlay",
        "ai_capacity_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-ai-advisory-body-2024",
      "council-of-europe-ai-treaty-2024",
      "unesco-ai-ethics-work",
      "oecd-ai-principles-2024"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "un-iccpr-1966-civil-political-rights",
    "title": "UN ICCPR 1966 - International Covenant on Civil and Political Rights",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The International Covenant on Civil and Political Rights (ICCPR), adopted by the UN General Assembly on 16 December 1966 (Resolution 2200A (XXI)) and entering into force on 23 March 1976, has 174 States Parties and is one of the two principal legally binding UN human rights treaties forming the International Bill of Human Rights together with the ICESCR and the UDHR. The ICCPR establishes binding civil and political rights obligations on States Parties enforceable through the Human Rights Committee (18 independent experts), which reviews State Party reports under Article 40 and, under the Optional Protocol (in force 23 March 1976, 117 Parties), considers individual communications. The Second Optional Protocol (in force 11 July 1991, 91 Parties) targets abolition of the death penalty. The ICCPR protects: the right to life (Article 6 - reduced scope for capital punishment; General Comment 36: capital punishment does not apply to minors, pregnant women, persons with intellectual disabilities); prohibition of torture, cruel, inhuman or degrading treatment (Article 7); prohibition of slavery and forced labour (Article 8); right to liberty and security of person (Article 9 - habeas corpus); treatment of detained persons (Article 10); no imprisonment for failure to fulfil contractual obligation (Article 11); freedom of movement and residence (Article 12); procedural rights in expulsion of aliens (Article 13); right to a fair trial (Article 14 - presumption of innocence, right to counsel, appeal, minimum procedural guarantees); no punishment without law (Article 15 - non-retroactivity); right to recognition as a person before the law (Article 16); privacy (Article 17); freedom of thought, conscience, and religion (Article 18); freedom of expression (Article 19 - subject to restrictions necessary for national security, public order, health, morals; General Comment 34 sets high bar for restrictions); prohibition of war propaganda and incitement to hatred (Article 20); right of peaceful assembly (Article 21); freedom of association including trade unions (Article 22); family protection (Article 23); children's rights (Article 24); political participation and voting (Article 25); equality before the law and non-discrimination (Article 26); rights of minorities (Article 27). Non-derogable rights under Article 4 (derogation in public emergency): Articles 6, 7, 8(1)(2), 11, 15, 16, 18. Corporate compliance relevance: ICCPR obligations flow to business through the UN Guiding Principles on Business and Human Rights (UNGPs); the EU CSDDD, German LkSG, and French Duty of Vigilance treat ICCPR rights as key due diligence reference standards; CSRD ESRS S1 and S2 reference ICCPR Articles 6, 7, 8, 22 as material rights for workforce and value chain human rights assessment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-guiding-principles-business-human-rights",
      "un-convention-against-corruption-uncac-2003",
      "eu-csrd-2022-2464",
      "eu-corporate-sustainability-due-diligence-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-icerd-1965-racial-discrimination",
    "title": "UN ICERD 1965 - International Convention on the Elimination of All Forms of Racial Discrimination",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The International Convention on the Elimination of All Forms of Racial Discrimination (ICERD), adopted by the UN General Assembly on 21 December 1965 (Resolution 2106 (XX)) and entering into force on 4 January 1969, has 182 States Parties and is the primary international human rights treaty specifically addressing racial discrimination. ICERD was adopted in the context of decolonisation and the civil rights movement and represents the international community's binding commitment to eliminate racial segregation, apartheid, and all forms of racial and ethnic discrimination. Article 1 defines racial discrimination as any distinction, exclusion, restriction, or preference based on race, colour, descent, or national or ethnic origin which has the purpose or effect of nullifying or impairing the recognition, enjoyment, or exercise of human rights and fundamental freedoms - critically, ICERD covers discrimination based on descent (caste, indigenous status) and national or ethnic origin in addition to race and colour. Article 2 imposes comprehensive obligations: condemn racial discrimination in all its forms; pursue a policy of eliminating racial discrimination; prohibit and bring to an end racial discrimination by public authorities and institutions; review and amend governmental policies that perpetuate racial discrimination; prohibit and eliminate racial discrimination by any person, group, or organisation. Article 4 requires States to declare offences punishable by law the dissemination of ideas based on racial superiority or hatred, incitement to racial discrimination, and acts of violence against racial groups. Article 5 prohibits racial discrimination in: civil rights (equal treatment before courts; security of person; political rights); civil rights (freedom of movement, nationality, marriage, property, inheritance, expression, assembly); economic, social, and cultural rights (work - right to work, free choice of employment, just conditions, protection against unemployment, equal pay, social security; trade unions; housing; healthcare; education and training; participation in cultural activities). Article 6 requires effective remedies including adequate reparation. Article 14 (optional) - individual communications procedure - available for 60 States that have accepted this Article. The Committee on the Elimination of Racial Discrimination (CERD - 18 independent experts) monitors compliance; CERD has developed guidance on descent-based discrimination (GR 29), indigenous peoples (GR 23), non-citizens (GR 30), and gender (GR 25). Corporate compliance relevance: ICERD forms the foundation for EU anti-discrimination law in employment and services; the EU Racial Equality Directive (2000/43) implements ICERD in EU Member States and prohibits racial and ethnic origin discrimination in employment, training, social protection, and access to goods and services including housing; CSDDD Annex Part I and LkSG reference racial discrimination as an adverse human rights impact requiring due diligence; ESRS S1.27 requires ethnic origin diversity disclosure where legally permissible; algorithmic bias and AI discrimination on racial grounds engages ICERD Article 5; caste-based discrimination in South Asian supply chains is an ICERD Article 1 'descent' violation requiring specific due diligence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-guiding-principles-business-human-rights",
      "eu-employment-equality-directive-2000-78",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-icescr-1966-economic-social-cultural-rights",
    "title": "UN ICESCR 1966 - International Covenant on Economic, Social and Cultural Rights",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The International Covenant on Economic, Social and Cultural Rights (ICESCR), adopted by the UN General Assembly on 16 December 1966 (Resolution 2200A (XXI)) and entering into force on 3 January 1976, has 171 States Parties. Together with the ICCPR and the Universal Declaration of Human Rights it forms the International Bill of Human Rights. The ICESCR establishes binding obligations on States Parties to take steps to achieve progressively, to the maximum of available resources, the full realisation of the economic, social, and cultural rights in the Covenant (Article 2.1 - progressive realisation standard; distinguished from the ICCPR's immediate realisation obligations). The Committee on Economic, Social and Cultural Rights (CESCR - 18 independent experts) monitors compliance through State Party reports and, under the Optional Protocol (in force 5 May 2013, 27 Parties), individual and collective communications. The ICESCR protects: the right to self-determination (Article 1); non-discrimination in the application of rights (Article 2.2 - sex, race, colour, language, religion, political opinion, national or social origin, property, birth, other status); equal rights of men and women (Article 3); the right to work (Article 6 - opportunity to gain a living by freely chosen work; States must provide technical and vocational guidance, training, and economic development); right to just and favourable conditions of work (Article 7 - fair wages, equal pay for equal work, safe and healthy working conditions, equal opportunity in promotion, rest and leisure, reasonable working hours, paid holidays and remuneration on public holidays); trade union rights (Article 8 - right to form and join trade unions, right of unions to function freely, right to strike subject to national law restrictions); right to social security (Article 9); protection of the family including maternity leave (Article 10); right to an adequate standard of living including food, clothing, housing (Article 11); right to the enjoyment of the highest attainable standard of physical and mental health (Article 12 - CESCR GC 14: States must ensure healthcare is available, accessible, acceptable, and of good quality - the AAAQ framework); right to education (Article 13 - free and compulsory primary education; secondary and higher education accessible and progressively free; academic freedom); the right to take part in cultural life and benefit from scientific progress and its applications (Article 15). Corporate compliance relevance: the ICESCR's labour rights (Articles 6-8) and the right to health (Article 12) form the foundation for international due diligence obligations under the EU CSDDD, German LkSG, French Duty of Vigilance, and ILO core conventions. CESCR General Comment 24 (2017) on State obligations in the context of business activities explicitly addresses corporate responsibility consistent with the UNGPs. ESRS S1 (Own Workforce) and S2 (Workers in the Value Chain) require disclosure of material impacts on ICESCR labour and health rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "eu-csrd-2022-2464",
      "eu-corporate-sustainability-due-diligence-2024",
      "eu-employment-equality-directive-2000-78"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-icescr-economic-social-cultural-rights-1966",
    "title": "International Covenant on Economic, Social and Cultural Rights",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "States Parties must guarantee the economic, social, and cultural rights outlined in the Covenant are exercised without discrimination and ensure the equal right of men and women to their enjoyment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "un-liability-convention-1972-space-objects",
    "title": "Convention on International Liability for Damage Caused by Space Objects",
    "domain": "Space & Satellite Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes absolute liability for damage caused by space objects on the surface of the Earth or to aircraft in flight, and fault-based liability for damage caused elsewhere in space. It applies to all State Parties responsible for launching or procuring the launch of space objects, under Article II and Article III of the Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-minamata-convention-article-7-artisanal-small-scale-gold-mining",
    "title": "UN Minamata Convention Article 7 Artisanal and Small-Scale Gold Mining Mercury Reduction",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Minamata Convention Article 7 requires Parties where artisanal and small-scale gold mining (ASGM) is more than insignificant to develop and implement a national action plan to reduce and, where feasible, eliminate mercury use and releases from ASGM, including quantification of mercury use, health and environmental strategies, measures to prevent pollution from tailings, and engagement with affected communities - with Parties allowed to continue mercury use in ASGM where mercury-free alternatives are not practicable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "un-model-double-taxation-convention-2021",
    "title": "United Nations Model Double Taxation Convention between Developed and Developing Countries 2021",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The UN Model Convention 2021 introduces Article 12A, granting source States taxing rights over fees for technical services paid to a resident of another contracting State, even without a permanent establishment. This provision is designed to address tax challenges from the digitalization of the economy and primarily impacts multinational enterprises providing cross-border technical, managerial, or consultancy services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-montreal-protocol-1987-ozone-kigali-2016",
    "title": "Montreal Protocol 1987 & Kigali Amendment 2016 - Ozone-Depleting Substances & HFC Phase-Down",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Montreal Protocol on Substances that Deplete the Ozone Layer (1987), which entered into force 1 January 1989 and now has 197 Parties (universal ratification), is the primary international treaty governing the production and consumption of ozone-depleting substances (ODS). It achieved a 99% phaseout of ODS globally. The 2016 Kigali Amendment, in force 1 January 2019 (with 159 Parties), extends the Protocol's phaseout mechanism to hydrofluorocarbons (HFCs), which are potent greenhouse gases with global warming potentials (GWPs) 12-14,000 times CO2. The Kigali Amendment will prevent up to 0.5°C of global warming by 2100. Under the Amendment, developed countries (Article 2 parties) must reduce HFC consumption to 15% of baseline by 2036. Developing countries (Article 5 parties) follow different schedules: Group 1 reduces to 20% of baseline by 2045, Group 2 (hot-climate states) reduces to 30% by 2047. The EU implements HFC controls through the F-Gas Regulation (EU) 2024/573 (Phase 2 - stronger controls from 2024). Non-ODS HFCs and HCFC substitutes require annual reporting to the UNEP Ozone Secretariat.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-csrd-2022-2464",
      "un-cbd-kunming-montreal-gbf-2022",
      "eu-ets-directive-2003-87-emissions-trading-scheme"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-moon-agreement-1979-resources",
    "title": "Agreement Governing the Activities of States on the Moon and Other Celestial Bodies",
    "domain": "Space & Satellite Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes that the Moon and other celestial bodies are the common heritage of mankind, prohibits national appropriation, and mandates the creation of an international regime to govern the exploitation of lunar natural resources. It applies to all State Parties engaging in exploration or use of the Moon, under Article 11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "unclos-part-xi-deep-seabed-mining-1982"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-npt-1968-nuclear-non-proliferation",
    "title": "NPT 1968 - Treaty on the Non-Proliferation of Nuclear Weapons",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Treaty on the Non-Proliferation of Nuclear Weapons (NPT), opened for signature 1 July 1968 and entering into force 5 March 1970, has 191 States Parties - the most widely adhered to arms control treaty. Three States that possess nuclear weapons have never joined: India (since 1974 Pokhran test), Pakistan (since 1998), and Israel (deliberately ambiguous). North Korea acceded in 1985, declared withdrawal in 2003, and is treated by most States as having left. The NPT rests on three mutually reinforcing pillars: (1) Non-proliferation - nuclear-weapon states (NWS: US, Russia, UK, France, China, recognised under Article IX(3)) commit not to transfer nuclear weapons or explosive devices or control over them to anyone, and not to assist non-nuclear-weapon states (NNWS) to acquire them (Article I); NNWS commit not to receive, manufacture, acquire, or seek control over nuclear weapons (Article II); (2) Disarmament - all States Parties commit to negotiate in good faith toward nuclear disarmament and general and complete disarmament (Article VI - the only legally binding disarmament obligation; the International Court of Justice confirmed in its 1996 Advisory Opinion on nuclear weapons that Article VI requires genuine pursuit of negotiations in good faith); (3) Peaceful uses of nuclear energy - all States Parties have the inalienable right to develop, research, produce, and use nuclear energy for peaceful purposes without discrimination (Article IV); the obligation to facilitate and have the right to participate in exchange of equipment, materials, and scientific and technological information for peaceful uses. Article III (safeguards): each NNWS must conclude a Comprehensive Safeguards Agreement (CSA, INFCIRC/153) with the International Atomic Energy Agency (IAEA) accepting safeguards on all nuclear material in the State; the Additional Protocol (AP, INFCIRC/540 - in force for 139 States) strengthens safeguards post-1991 Iraq programme discovery by expanding declaration obligations and enabling short-notice access. NPT Review Conferences occur every 5 years; the 10th RevCon (2022) failed to adopt a Final Document due to disagreement on nuclear disarmament and Russia's war in Ukraine. The Treaty on the Prohibition of Nuclear Weapons (TPNW, 2017, in force January 2021, 93 Parties) goes beyond the NPT to prohibit nuclear weapons comprehensively but is opposed by all five NPT nuclear weapon states and NATO allies. Corporate compliance relevance: (a) nuclear power sector - civilian nuclear energy operators must comply with IAEA safeguards (Article III) through national implementing legislation; uranium mining, enrichment, fuel fabrication, and reprocessing companies must file facility declarations and accept IAEA inspections; (b) dual-use technology exporters - the Nuclear Suppliers Group (NSG - 48 members) controls exports of nuclear-specific items (Trigger List) and dual-use items (Annex 2) consistent with Article III(2) NPT obligation not to provide source or special fissionable material to NNWS without safeguards; (c) institutional investors and financial institutions - TPNW Article 4(6) calls on States Parties to discourage investment in nuclear weapons; ESG investor frameworks (MSCI, Sustainalytics) score companies on nuclear weapons exposure; (d) defence contractors - nuclear weapons production is heavily restricted by national security controls and classified information regimes; contractors with access to nuclear materials or information must comply with nuclear security (NSS) requirements consistent with NPT Article VI disarmament context.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "opcw-cwc-1993-chemical-weapons-convention",
      "un-biological-weapons-convention-1972",
      "eu-dual-use-regulation-2021-821"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-outer-space-treaty-1967",
    "title": "Outer Space Treaty 1967 - Non-Appropriation, Liability & Governance Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Treaty on Principles Governing the Activities of States in the Exploration and Use of Outer Space (OST 1967) establishes the foundational international legal framework for space activities. Article II prohibits national appropriation of outer space, the Moon and other celestial bodies. Article VI holds States internationally responsible for national activities including those of non-governmental entities, requiring authorisation and continuing supervision. Article VII imposes absolute liability on launching States for damage caused on Earth's surface or to aircraft in flight. Article IX mandates harmful-contamination avoidance and obligatory consultation before activities potentially harmful to other States' activities. The Treaty has 114 parties as of 2026 and underpins all national space licensing regimes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-liability-convention-1972-space-objects",
      "un-registration-convention-1976-space",
      "un-rescue-agreement-1968-astronauts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-outer-space-treaty-1967-article-i-freedom",
    "title": "The Outer Space Treaty",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must ensure their outer space activities align with the principles, laws, and programs outlined by the United Nations Office for Outer Space Affairs, including registration, sustainability, and international cooperation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "un-outer-space-treaty-1967-article-vi-state-responsibility",
    "title": "Treaty on Principles Governing the Activities of States in the Exploration and Use of Outer Space, including the Moon and Other Celestial Bodies - Article VI",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "States Parties bear international responsibility for all national activities in outer space, and must authorize and continually supervise the activities of non-governmental entities to ensure conformity with the Treaty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "un-palermo-convention-2000-transnational-organized-crime",
    "title": "UN Convention Against Transnational Organized Crime (UNTOC) 2000 - Palermo Convention",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The United Nations Convention against Transnational Organized Crime (UNTOC), also known as the Palermo Convention, was adopted by the UN General Assembly on 15 November 2000 (Resolution 55/25) and entered into force on 29 September 2003, with 191 Parties - near-universal ratification. It is the primary global legal framework for combating transnational organized crime. The Convention requires States to criminalise: participation in an organised criminal group (Article 5), money laundering (Article 6), corruption of public officials (Article 8), and obstruction of justice (Article 23). The Convention is supplemented by three Protocols: the Palermo Protocol on Trafficking in Persons (2003, 180 Parties - requires criminalisation of human trafficking; Articles 3 and 5 define and mandate prosecution of trafficking offences), the Smuggling of Migrants Protocol (2004, 150 Parties - requires criminalisation of migrant smuggling by sea, land, and air), and the Firearms Protocol (2005, 120 Parties - requires licensing, marking, tracing, and criminalisation of illicit firearms manufacturing and trafficking). The Convention's Article 12 requires States to adopt measures for the confiscation and seizure of proceeds of crime and instrumentalities; Article 13 establishes international cooperation for asset recovery. Article 15 grants broad jurisdiction including flag State, active personality, and passive personality jurisdiction. Articles 16-18 address extradition and mutual legal assistance (MLA) - States must either extradite or prosecute ('aut dedere aut judicare'). Articles 26-27 require States to take measures to encourage cooperation and witness protection. The FATF 40 Recommendations are the primary operational implementation mechanism for the money laundering provisions of the Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-convention-against-corruption-uncac-2003",
      "ilo-core-conventions",
      "eu-directive-combating-corruption-2024-1760"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-palermo-protocol-2000-trafficking-persons",
    "title": "UN Palermo Protocol 2000 - Trafficking in Persons Definition, Prosecution, Protection and Prevention",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Protocol to Prevent, Suppress and Punish Trafficking in Persons, Especially Women and Children (Palermo Protocol or Trafficking Protocol), supplementing the United Nations Convention against Transnational Organized Crime (UNTOC), was adopted by UN General Assembly resolution 55/25 on 15 November 2000 and entered into force on 25 December 2003. The Protocol provides the first universally agreed definition of trafficking in persons in Article 3(a): the recruitment, transportation, transfer, harbouring or receipt of persons by means of threat or use of force or other forms of coercion, of abduction, of fraud, of deception, of the abuse of power or of a position of vulnerability or of the giving or receiving of payments or benefits to achieve the consent of a person having control over another person, for the purpose of exploitation. Article 5 obligates State Parties to criminalise trafficking. The Protocol takes a 3P approach: Prosecution (Articles 5-8 criminalisation and prosecution), Protection (Articles 6-8 victim assistance, status, repatriation), and Prevention (Articles 9-13 social-economic prevention, cooperation, border measures). As of 2024, 181 States are Parties. The UN Office on Drugs and Crime (UNODC) provides secretariat support; the Group of Friends United against Human Trafficking and ICAT (Inter-Agency Coordination Group against Trafficking in Persons) provide multi-agency coordination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-refugee-convention-1951-protocol-1967-non-refoulement",
      "us-immigration-nationality-act-1952-uscis"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-paris-agreement-ndc-implementation-guidelines",
    "title": "Paris Agreement: Article 4 - Nationally Determined Contributions (NDCs) and Implementation Guidelines",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "Under Article 4 of the Paris Agreement, each signatory Party is required to prepare, communicate, and maintain successive Nationally Determined Contributions (NDCs) it intends to achieve, ensuring each new NDC represents a progression beyond the previous one and reflects its highest possible ambition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify",
      "iso-14090-climate-adapt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-pri-investment",
    "title": "UN Principles for Responsible Invest",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Adherence to the United Nations-supported Principles for Responsible Investment framework delineates an investment manager's commitment to integrating environmental, social, and governance (ESG) considerations into investment analysis and decision-making processes. Compliance verification commences by confirming an entity's status as a signatory. The framework mandates establishing and publishing a formal responsible investment policy, which must explicitly cover ESG integration while articulating a clear active ownership policy. Operational transparency is a key tenet, assessed by verifying if proxy voting records are made public and whether a formal engagement process is documented. Annual reporting obligations are critical, requiring confirmation that an annual PRI report was submitted. Performance is quantitatively measured through the investment strategy's PRI assessment score. The principles also encourage broader ecosystem influence; therefore, the node ascertains if the entity promotes PRI principles externally and participates in collaborative ESG initiatives. Implementation effectiveness is further evidenced by procedures that request ESG disclosure from investees and ensure relevant personnel receive ESG training. This comprehensive evaluation ensures signatories are not just nominally committed but are actively operationalizing all six core tenets across their investment lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-sfdr-reporting",
      "tcfd-climate-risk",
      "issb-s1-s2-standard",
      "eu-taxonomy-sustainable",
      "csrd-eu-sustainability"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "un-principles-sustainable-insurance-psi-2023-update",
    "title": "UN Principles for Sustainable Insurance 2023 Update - ESG Integration: Climate Change Underwriting Guidelines, Nature-Related Risk Assessment, Social Inclusion in Insurance, PSI Signatory Reporting Framework and TNFD Integration for Insurers",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The UNEP FI Principles for Sustainable Insurance (PSI) establish a global framework for insurers to identify, assess, manage, and monitor environmental, social, and governance (ESG) risks and opportunities across all activities in the insurance value chain. The principles apply to signatory companies and supporting institutions committed to advancing resilient, inclusive, and sustainable economies, with specific emphasis on climate resilience, nature-positive outcomes, and alignment with TCFD and TNFD recommendations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate",
      "eu-delegated-regulation-2016-2067-spread-market-risk",
      "canada-osfi-e19-own-risk-solvency-2023",
      "australia-apra-gps-220-risk-management-general-insurers",
      "brazil-susep-solvency-regulation-circular-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-principles-sustainable-insurance-unepfi-2012",
    "title": "UNEP FI Principles for Sustainable Insurance (PSI) - A Global Framework for the Insurance Industry to Address Environmental, Social and Governance Risks and Opportunities",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The Principles for Sustainable Insurance (PSI) provide a voluntary global framework for insurers to manage Environmental, Social, and Governance (ESG) issues as risk managers, insurers, and investors. Signatories commit to embedding the four core Principles into their business strategy and operations, covering risk management, product development, client engagement, and public disclosure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "iso-14090-climate-adapt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-refugee-convention-1951-protocol-1967-non-refoulement",
    "title": "UN Refugee Convention 1951 and Protocol 1967 - Refugee Definition, Non-Refoulement and Rights of Refugees",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Convention Relating to the Status of Refugees, adopted in Geneva on 28 July 1951 and entered into force on 22 April 1954, together with its 1967 Protocol Relating to the Status of Refugees (entered into force 4 October 1967), constitute the foundational international legal framework for the protection of refugees. Article 1A(2) defines a refugee as any person who, owing to well-founded fear of being persecuted for reasons of race, religion, nationality, membership of a particular social group or political opinion, is outside the country of their nationality and unable or, owing to such fear, unwilling to avail themselves of the protection of that country. The 1967 Protocol removed the 1951 Convention's temporal limitation (events occurring before 1 January 1951) and geographic limitation (events occurring in Europe), making the regime universal. Article 33(1) establishes the cornerstone principle of non-refoulement: no Contracting State shall expel or return (refouler) a refugee in any manner whatsoever to the frontiers of territories where their life or freedom would be threatened on account of the protected grounds. The Convention has 149 States Parties; the 1967 Protocol has 147 States Parties (as of 2024). UNHCR is the international guardian under Article 35 of the Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "germany-residence-act-aufenthaltsgesetz-2004-bamf",
      "canada-irpa-immigration-refugee-protection-act-2001"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-registration-convention-1976-space",
    "title": "Convention on Registration of Objects Launched into Outer Space",
    "domain": "Space & Satellite Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires each launching State to maintain a national registry of space objects it launches and to provide specific data to the United Nations Secretary-General for entry into the UN Register. It applies to all States that launch or procure the launching of space objects, or from whose territory or facility objects are launched, under Article II and Article IV.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-regulation-155-vehicle-cybersecurity",
    "title": "UN Regulation No. 155 - Uniform Provisions Concerning the Approval of Vehicles with Regard to Cybersecurity and Cybersecurity Management",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "UN Regulation No. 155 mandates that vehicle manufacturers implement a certified Cyber Security Management System (CSMS) to identify, protect against, detect, respond to, and recover from cybersecurity threats throughout the vehicle lifecycle. It applies to all new vehicle types and major variants sold in UNECE WP.29 contracting parties, as required under Article 5 and Annex 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "un-regulation-r156-software-updates-ota",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-regulation-156-software-updates-ota",
    "title": "UN Regulation No. 156 - Uniform provisions concerning the approval of vehicles with regard to software update and software update management system (SUMS)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "UN Regulation No. 156 mandates that manufacturers implement a certified Software Update Management System (SUMS) to ensure the secure, reliable, and traceable over-the-air (OTA) updating of vehicle software. It applies to all new vehicle types and significant updates introduced after compliance deadlines, requiring update authorization, verification, and type approval under UNECE WP.29 framework (Article 7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-regulation-r155-vehicle-cybersecurity-management",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "iso-26262-functional-safety-road-vehicles-2018",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-regulation-r13-heavy-vehicle-braking-system",
    "title": "UN Regulation No. 13 - Braking Systems for Heavy Vehicles (M, N, O Categories)",
    "domain": "Automotive & Mobility",
    "version": "R13 (current series of amendments, 11th supplement to 11th series)",
    "last_updated": "2026-05-09",
    "bluf": "UN Regulation No. 13 (UNECE WP.29) is the international uniform standard for braking systems on heavy-duty motor vehicles and trailers (Categories M2, M3 buses; N1-N3 trucks; O1-O4 trailers); it specifies performance requirements for service brake, secondary brake, and parking brake, mandates Anti-lock Braking Systems (ABS) for vehicles over 3.5 tonnes, establishes Electronic Braking System (EBS) requirements, and defines braking compatibility between trucks and trailers - forming the mandatory type approval framework for commercial vehicles in 57 UNECE contracting states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-general-safety-regulation-2019-2144-vehicles",
      "sae-j3016-levels-driving-automation-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-regulation-r152-aebs-advanced-emergency-braking",
    "title": "UN Regulation No. 152 - Advanced Emergency Braking Systems (AEBS) for M1 and N1 Vehicles",
    "domain": "Automotive & Mobility",
    "version": "Supplement 3 (2022)",
    "last_updated": "2026-05-09",
    "bluf": "UN Regulation No. 152 (adopted by UNECE WP.29 under the 1958 Agreement) mandates Advanced Emergency Braking Systems (AEBS) for M1 (passenger cars) and N1 (light goods vehicles up to 3.5 t GVW) capable of automatically detecting and braking for stationary vehicles, slow-moving vehicles, and pedestrians, with mandatory type approval from July 2022 for new models and mandatory fitment for all new vehicles from July 2024 across 1958 Agreement Contracting Parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-general-safety-regulation-2019-2144-vehicles",
      "sae-j3016-levels-driving-automation-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-regulation-r155-vehicle-cybersecurity-management",
    "title": "UN Regulation No. 155 - Uniform provisions concerning the approval of vehicles with regard to cybersecurity and cybersecurity management",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "UN Regulation No. 155 mandates that automotive manufacturers implement a Cybersecurity Management System (CSMS) to identify, assess, and mitigate cybersecurity risks throughout the vehicle lifecycle. It applies to all new vehicle types (M, N, and certain O categories) sold in UNECE member states, requiring type approval under Article 5 and compliance with Annex 5's CSMS requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021",
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-regulation-r156-software-updates-ota",
    "title": "UN Regulation No. 156 - Uniform provisions concerning the approval of vehicles with regard to software update and software update management system (SUMS)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "UN Regulation No. 156 mandates that manufacturers implement a certified Software Update Management System (SUMS) to ensure secure, traceable, and safe over-the-air (OTA) software updates for vehicles. It applies to all new vehicle types and significant updates to existing types introduced in UNECE member states, requiring compliance with cybersecurity, update integrity, and vehicle identification verification per Annex 5, Paragraph 6.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021",
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-regulation-r157-automated-lane-keeping-alks",
    "title": "UN Regulation No. 157 on Automated Lane Keeping Systems (ALKS) for Motor Vehicles",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "UN Regulation No. 157 establishes technical requirements and operational conditions for Automated Lane Keeping Systems (ALKS) operating at SAE Level 3, permitting automated driving up to 60 km/h under specific conditions. It applies to manufacturers of passenger vehicles (M1 category) equipped with ALKS, requiring system activation limits, driver fallback readiness, and event data recording per Annex 5, Paragraph 6.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021",
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-rescue-agreement-1968-astronauts",
    "title": "Agreement on the Rescue of Astronauts, the Return of Astronauts and the Return of Objects Launched into Outer Space",
    "domain": "Space & Satellite Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires all Contracting Parties to render immediate assistance to astronauts in distress, promptly return them to the launching authority, and return any space objects found. It applies to all states that are party to the agreement and mandates notification to both the launching authority and the UN Secretary-General under Article 1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-sc-consolidated-sanctions-list-1267-2253-1718-2231",
    "title": "United Nations Security Council Consolidated Sanctions List - Article 41 Charter Measures, 1267 / 1989 / 2253 ISIL and Al-Qaida, 1718 DPRK, 2231 Iran, 1988 Taliban Frameworks",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "The United Nations Security Council Consolidated Sanctions List is the aggregated list of individuals, entities, vessels and other targets subject to UN Security Council sanctions measures adopted under Chapter VII Article 41 of the UN Charter. The list aggregates the targets of the active country-specific and thematic UN sanctions regimes administered by their respective Sanctions Committees: 1267 / 1989 / 2253 (ISIL/Daesh and Al-Qaida sanctions regime, the largest thematic regime with the Office of the Ombudsperson for delisting); 1988 (Taliban sanctions, separated from the ISIL/AQ list in 2011); 1518 (Iraq, the residual Saddam-era sanctions); 1521 (Liberia, the residual Charles Taylor-era sanctions); 1533 (Democratic Republic of the Congo); 1591 (Sudan, Darfur); 1636 (Lebanon, Rafiq Hariri assassination accountability); 1718 (Democratic People's Republic of Korea); 1737 (Iran, terminated and superseded by 2231); 2231 (Iran, the JCPOA-related sanctions framework with significant termination/sunset provisions); 1970 (Libya); 2127 (Central African Republic); 2140 (Yemen); 2374 (Mali); 2206 (South Sudan); 2664 (Humanitarian exception, the December 2022 horizontal carve-out applicable across all UN sanctions regimes). Member States are bound under Article 25 of the UN Charter to carry out the decisions of the Security Council; the typical measures are an asset freeze, a travel ban, an arms embargo and program-specific measures including the prohibition on financial services. Implementation in domestic law varies by Member State: the EU implements through Council Decisions and Council Regulations; the United States primarily through OFAC programs and Executive Orders; the United Kingdom through the Sanctions and Anti-Money Laundering Act 2018 (SAMLA) regulations; Canada through the United Nations Act (R.S.C. 1985 c. U-2); Australia through the Charter of the United Nations Act 1945 (Cth); Japan through the Foreign Exchange and Foreign Trade Act. The list is updated by Security Council resolutions and by the relevant Sanctions Committee designations and delistings. Delisting procedures for ISIL/AQ run through the Office of the Ombudsperson established by Resolution 1904 (2009); other regimes use a focal point mechanism for delisting requests. The Consolidated List is published in machine-readable formats (XML, HTML, PDF) on the UN Security Council website and is updated as designations and delistings are made.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "un_charter_article_41_anchor",
        "isil_al_qaida_regime_anchor",
        "dprk_regime_anchor",
        "iran_regime_anchor",
        "humanitarian_carve_out_anchor",
        "implementation_in_domestic_law_anchor",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unscr-1373-2001-counter-terrorism-financing-suppression",
      "fatf-40-recommendations-2023-consolidated",
      "eu-aml-regulation-2024-1624"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "un-sdg-4-education-2030-framework-action",
    "title": "UN SDG 4 Education 2030 Framework for Action - Inclusive Quality Education Targets: Early Childhood, Secondary, TVET, Higher Education and Adult Literacy",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The UN SDG 4 Education 2030 Framework for Action establishes global targets and policy actions to ensure inclusive and equitable quality education and promote lifelong learning opportunities for all by 2030, with specific obligations for UNESCO Member States to expand early childhood development, universal primary and secondary education, technical and vocational training, higher education access, and adult literacy programs. Key implementation guidance is provided in Paragraph 12 and Annex.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-sdg-alignment",
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-sdg-4-quality-education-implementation",
    "title": "UN SDG 4 Quality Education - Target 4.1-4.7 Implementation Framework, Monitoring Indicators and National Reporting Standards",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This framework requires signatory nations and reporting entities to implement policies and monitor progress towards inclusive and equitable quality education, focusing on specific targets 4.1 through 4.7. Compliance involves tracking and reporting on global and thematic indicators defined by the UNESCO Institute for Statistics (UIS) to ensure free, equitable, and quality primary and secondary education for all.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-sdg-corporate-mapping"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "un-sdg-alignment",
    "title": "UN SDG Strategic Alignment",
    "domain": "Sustainability & ESG",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The UN Sustainable Development Goals (SDGs) are a set of 17 interconnected global goals adopted by all 193 UN member states in 2015 as part of the 2030 Agenda for Sustainable Development. Each goal contains specific targets (169 total) measured by 231 unique indicators. For organizations, SDG alignment is not mandatory but is increasingly required by institutional investors (PRI signatories managing >$120 trillion in AUM), procurement frameworks (EU public procurement), and supply chain ESG due diligence requirements (CSDDD). The critical distinction is between SDG washing (claiming alignment without evidence) and genuine SDG integration (mapping business activities to specific SDG targets with quantified impact metrics, verified by GRI, SASB, or SDGD Recommendations).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "csrd-eu-sustainability",
      "eu-taxonomy-sustainable",
      "eu-sfdr-reporting",
      "gri-universal-standards",
      "issb-s1-s2-standard",
      "un-pri-investment"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "un-sdg-corporate-mapping",
    "title": "UN SDG Corporate Mapping",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The UN SDG Corporate Mapping framework aligns corporate activities and ESG reporting with the 17 United Nations Sustainable Development Goals (SDGs). it focuses on SDGs 8 (Decent Work), 12 (Responsible Consumption & Production), and 16 (Peace, Justice and Strong Institutions) as the primary pillars for ethical governance and sustainable business practice.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-guiding-principles-business-hr",
      "ilo-fundamental-rights-work",
      "oecd-guidelines-multinational-ent",
      "csrd-eu-sustainability",
      "fcpa-anti-bribery-compliance",
      "uk-bribery-act-2010"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "un-sdsn-mining-sdg-alignment-framework",
    "title": "Mapping Mining to the Sustainable Development Goals: An Atlas (SDSN, CCSI, UNDP, WEF, 2016) - SDG Integration Guidance for Mining",
    "domain": "Mining & Natural Resources",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "There is no discrete instrument titled the 'UN SDSN Mining and SDG Alignment Framework'. The genuine SDSN-related mining resource is 'Mapping Mining to the Sustainable Development Goals: An Atlas', produced by the Columbia Center on Sustainable Investment (CCSI), the UN Sustainable Development Solutions Network (SDSN), the United Nations Development Programme (UNDP) and the World Economic Forum (WEF), with its final version released on 19 July 2016. The Atlas is a non-binding guidance resource that maps mining-sector activities to each of the 17 Sustainable Development Goals (including SDG 8 decent work, SDG 12 responsible consumption and production, SDG 13 climate action and SDG 17 partnerships) and offers good-practice examples for companies; it does not impose enforceable obligations and is not a regulatory instrument.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-sdg-corporate-mapping",
      "iso-26000-social-resp"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-sendai-framework-disaster-risk-insurance-2030",
    "title": "Sendai Framework for Disaster Risk Reduction 2015-2030",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Requires national governments and participating states to promote investment in disaster risk reduction (DRR) through risk insurance and pooling mechanisms, including sovereign parametric insurance, as part of Priority 3 and Target F. Applies to UN Member States, multilateral development banks, and sovereign risk pools such as CCRIF, ARC, and PCRIC. Key clause: Paragraph 30(h), Target F.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "eu-delegated-regulation-2016-467-non-life-premium-risk",
      "brazil-susep-solvency-regulation-circular-2021",
      "china-cbirc-c-ross-ii-solvency-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-singapore-convention-mediation-2019",
    "title": "UN Singapore Convention on Mediation - UNSCM 2019",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Singapore Convention on Mediation (UN Convention on International Settlement Agreements Resulting from Mediation, 2019 - 14 Parties, 58 signatories including USA, China, India, EU states as of April 2026) enables direct cross-border enforcement of mediated settlement agreements in commercial disputes without court proceedings, analogous to the New York Convention for arbitral awards; parties may invoke Article 3 enforcement rights directly in any Contracting State, and businesses that include a mediation clause in commercial contracts now have a credible enforcement pathway for mediated settlements - transforming mediation from a soft dispute resolution mechanism into a hard-enforcement tool competitive with international arbitration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "new-york-convention-1958-foreign-arbitral-awards",
      "uncitral-model-law-arbitration-2006",
      "eu-csrd-2022-2464",
      "un-convention-against-corruption-uncac-2003"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-udhr-1948-universal-declaration-human-rights",
    "title": "Universal Declaration of Human Rights 1948 - 30 Articles of Fundamental Rights and Customary International Law Status",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Universal Declaration of Human Rights (UDHR) was adopted by UN General Assembly resolution 217 A (III) on 10 December 1948 in Paris with 48 States voting in favour, none against, and 8 abstentions (Saudi Arabia, USSR, Belarus, Czechoslovakia, Poland, Ukraine, Yugoslavia, South Africa). The Declaration is not a binding treaty but a UN General Assembly resolution; however its provisions are widely regarded as having attained customary international law status particularly for fundamental rights (life, prohibition of torture, slavery, racial discrimination, due process). The Declaration contains 30 Articles covering: civil and political rights including life and liberty (Article 3), prohibition of slavery (Article 4) and torture (Article 5), equality before law and equal protection (Article 7), right to seek asylum (Article 14), right to nationality (Article 15), freedom of religion (Article 18), freedom of expression (Article 19), peaceful assembly (Article 20), participation in government (Article 21); economic, social and cultural rights including social security (Article 22), work (Article 23), rest and leisure (Article 24), adequate standard of living (Article 25), education (Article 26), participation in cultural life (Article 27). The UDHR led to the International Covenants on Civil and Political Rights (ICCPR 1966) and Economic, Social and Cultural Rights (ICESCR 1966), creating the International Bill of Human Rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-iccpr-1966-civil-political-rights",
      "un-genocide-convention-1948-prevention-punishment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-uncac-2003-anti-corruption-due-diligence-compliance",
    "title": "UN Convention Against Corruption (UNCAC) 2003 - Anti-Corruption Due Diligence and Compliance",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The UN Convention Against Corruption (UNCAC, UNODC 2003), ratified by 190 parties, is the primary international anti-corruption instrument establishing mandatory criminalisation of bribery of national and foreign officials, embezzlement, trading in influence, and money laundering, alongside preventive measures including codes of conduct, transparent public procurement, asset recovery, and mandatory cooperation between jurisdictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-6amld-directive-2018-1673-anti-money-laundering-criminal-offences"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "un-uncrc-1989-convention-rights-child",
    "title": "UN UNCRC 1989 - Convention on the Rights of the Child",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Convention on the Rights of the Child (UNCRC), adopted by the UN General Assembly on 20 November 1989 (Resolution 44/25) and entering into force on 2 September 1990, is the most widely ratified human rights treaty in history with 196 States Parties - only the United States has not ratified. The UNCRC establishes comprehensive rights for every human being under 18 years of age (Article 1) and is governed by four general principles: non-discrimination (Article 2), best interests of the child (Article 3), right to life, survival, and development (Article 6), and the right to be heard (Article 12). Three Optional Protocols extend the UNCRC: the Optional Protocol on the Sale of Children, Child Prostitution and Child Pornography (OPSC, in force 2002, 179 Parties); the Optional Protocol on Children in Armed Conflict (OPAC, in force 2002, 170 Parties); and the Optional Protocol on a Communications Procedure (OPIC, in force 2014, 51 Parties). The Committee on the Rights of the Child (18 independent experts) monitors compliance through State reports and, under OPIC, individual communications. The UNCRC's corporate compliance relevance centres on Article 32 - protection from economic exploitation - which provides the human rights foundation for the prohibition of child labour: States must protect children from work that is hazardous, interferes with education, or is harmful to health or physical, mental, spiritual, moral, or social development; States must set minimum age for employment; States must regulate hours and conditions of work. Article 32 is implemented in detail by ILO Convention C138 (Minimum Age) and ILO Convention C182 (Worst Forms of Child Labour). The CSDDD Annex Part I, German LkSG Section 2(1), and French Duty of Vigilance all reference UNCRC Article 32 and the associated ILO conventions as primary instruments defining adverse human rights impacts in supply chains. ESRS S2 (Workers in the Value Chain) requires disclosure of child labour incidents and due diligence measures. Beyond child labour: Article 24 (right to health - supply chain products for children must be safe; hazardous products liability); Article 28-29 (right to education - children's access to education must not be disrupted by business activities); Article 37 (prohibition of torture - absolute prohibition for children); the OPSC (sale of children) intersects with human trafficking in supply chains; the OPAC (children in armed conflict) intersects with corporate supply chains in conflict zones. UNICEF's Children's Rights and Business Principles (2012), developed with the UN Global Compact and Save the Children, provide the operational translation of UNCRC obligations for business across 10 principles covering workplace, marketplace, and community.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "eu-csrd-2022-2464",
      "eu-corporate-sustainability-due-diligence-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "un-watercourses-convention-1997-transboundary-water",
    "title": "UN Watercourses Convention 1997 - Transboundary Freshwater Resources and Equitable Utilization",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The UN Convention on the Law of the Non-Navigational Uses of International Watercourses (UNGA Res. 51/229, in force 2014) codifies customary international law principles of equitable and reasonable utilization, no significant harm, and regular data exchange for shared international watercourses. Directly relevant to AI platforms processing transboundary water flow, quality, or allocation data across 42 ratifying States. Articles 11-19 require prior notification and consultation before any planned measures that may significantly affect other watercourse States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standards",
        "frameworks",
        "regulations",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-water-framework-directive-2000-60-ec",
      "un-global-digital-compact"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uncitral-model-law-arbitration",
    "title": "UNCITRAL Model Law (Arbitration)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The UNCITRAL Model Law on International Commercial Arbitration (1985, amended 2006) is the global standard for the legislative framework of international arbitration. It is designed to assist States in reforming and modernizing their laws on arbitral procedure so as to take into account the particular features and needs of international commercial arbitration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-intl-commercial-arb-2006"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uncitral-model-law-arbitration-2006",
    "title": "UNCITRAL Model Law on International Commercial Arbitration (1985), with amendments as adopted in 2006",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The UNCITRAL Model Law provides a globally recognized legal framework for international commercial arbitration, enabling parties to resolve disputes outside of national courts. It establishes rules for the arbitration agreement (Article 7), the arbitral tribunal's jurisdiction (Article 16), the conduct of proceedings, and the recognition and enforcement of arbitral awards (Articles 35 & 36), promoting legal certainty and uniformity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icc-arbitration-rules-2021",
      "un-cisg-1980",
      "isds-investor-state-dispute",
      "hague-convention-service-abroad"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uncitral-model-law-cross-border-insolvency-1997",
    "title": "UNCITRAL Model Law on Cross-Border Insolvency 1997 - COMI and Foreign Recognition",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-25",
    "bluf": "The UNCITRAL Model Law on Cross-Border Insolvency (1997) provides a framework enacted in 60+ jurisdictions (including US Chapter 15, UK Cross-Border Insolvency Regulations 2006, Australian Corporations Act Part 5.6, Singapore Insolvency, Restructuring and Dissolution Act 2018, Canada Part IV CCAA) for automatic recognition of foreign insolvency proceedings based on the debtor's Centre of Main Interests (COMI), granting foreign representatives access to local courts, automatic or discretionary stay of proceedings, and cooperation between courts - multinational enterprises, lenders, and insolvency practitioners must identify COMI early, as COMI determines where primary proceedings may be opened and where recognition as foreign main proceeding (automatic stay) versus foreign non-main proceeding (discretionary stay) applies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "new-york-convention-1958-foreign-arbitral-awards",
      "hague-choice-of-court-convention-2005",
      "un-convention-against-corruption-uncac-2003"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uncitral-model-law-electronic-commerce-1996",
    "title": "UNCITRAL Model Law on Electronic Commerce (1996) with additional article 5 bis as adopted in 1998",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This Model Law ensures that electronic messages are not denied legal effect, validity, or enforceability solely because they are in electronic form, and establishes functional equivalence between electronic and paper-based communications under Article 5. It applies to any legal recognition of data messages in commercial transactions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-intl-commercial-arb-2006"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uncitral-model-law-electronic-commerce-1996-article-5-legal-recognition",
    "title": "UNCITRAL Model Law on Electronic Commerce (1996): Article 5 Legal recognition of data messages",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must not deny legal effect, validity, or enforceability to information solely on the grounds that it is in electronic form, ensuring equal treatment with paper-based documents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uncitral-model-law-electronic-signatures-2001",
    "title": "UNCITRAL Model Law on Electronic Signatures (2001)",
    "domain": "Workflow Automation",
    "version": "1.1.0",
    "last_updated": "2026-07-10",
    "bluf": "The UNCITRAL Model Law on Electronic Signatures (2001) provides a technology-neutral framework for treating an electronic signature as equivalent to a handwritten signature when it is as reliable as was appropriate for the purpose. Article 2 defines electronic signature, certificate, data message, signatory, certification service provider, and relying party; Article 6 sets the reliability test and functional-equivalence criteria for compliance with a signature requirement. Articles 8, 9, and 11 set conduct duties for the signatory, the certification service provider, and the relying party. Automated signing workflows must enforce signature-creation-data control, signatory and provider duties, and relying-party verification to preserve legal equivalence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-electronic-commerce-1996",
      "uncitral-model-law-electronic-commerce-1996-article-5-legal-recognition"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "uncitral-model-law-international-commercial-arbitration-2006",
    "title": "UNCITRAL Model Law on International Commercial Arbitration (1985), with amendments as adopted in 2006 - Article 7",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article modernizes the formal requirements for an arbitration agreement, ensuring it conforms with international contract practices for validity and enforceability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "uncitral-model-law-intl-commercial-arb-2006",
    "title": "UNCITRAL Model Law on International Commercial Arbitration (1985), with amendments as adopted in 2006",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This Model Law governs the constitution of arbitral tribunals, the validity of arbitration agreements, the use of interim measures, and the recognition and enforcement of arbitral awards in international commercial arbitration. It applies to states enacting this framework into domestic law, requiring compliance with Articles 7, 10, 11, 17, and 35.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "uncitral-model-law-public-procurement-2011",
    "title": "UNCITRAL Model Law on Public Procurement 2011",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The UNCITRAL Model Law on Public Procurement, adopted by the United Nations Commission on International Trade Law on 1 July 2011 and recommended for use by General Assembly resolution 66/95 of 9 December 2011, provides a harmonised legal framework for States to enact or revise national procurement laws. It governs publication of legal texts (Article 5), participation and qualifications of suppliers (Articles 8-9), pre-qualification (Article 18), rejection of abnormally low submissions (Article 20), exclusion on grounds of inducements or conflicts of interest (Article 21), the standstill period and acceptance of successful submissions (Article 22), permitted methods of procurement (Article 27) including open tendering, restricted tendering, request for proposals, electronic reverse auctions (Articles 31, 53-57) and framework agreements (Articles 32, 58-63), and challenge and independent review proceedings (Articles 64-67).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wto-revised-government-procurement-agreement-2012",
      "uk-procurement-act-2023"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "unclos-part-ii-territorial-sea-contiguous-zone",
    "title": "United Nations Convention on the Law of the Sea of 10 December 1982 - Part II: Territorial Sea and Contiguous Zone",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the legal framework for the territorial sea, extending up to 12 nautical miles from the baseline, where coastal States exercise sovereignty subject to the right of innocent passage under Article 17. It also defines the contiguous zone up to 24 nautical miles for enforcement of customs, fiscal, immigration, and sanitary laws under Article 33.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unclos-part-v-exclusive-economic-zone"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "unclos-part-v-exclusive-economic-zone",
    "title": "United Nations Convention on the Law of the Sea of 10 December 1982, Part V - Exclusive Economic Zone",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Part V of UNCLOS grants coastal States sovereign rights over the exploration, exploitation, conservation, and management of living and non-living resources within an exclusive economic zone (EEZ) extending up to 200 nautical miles from the baseline, as defined in Article 57. All other States enjoy freedoms of navigation, overflight, and laying of submarine cables, subject to the rights and duties of the coastal State under Article 58.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "unclos-part-vii-high-seas",
    "title": "UNCLOS Part VII - High Seas (Articles 86-120): Freedom of Navigation, Jurisdiction, and Conservation",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "UNCLOS Part VII (Articles 86-120) establishes the legal regime for the high seas - the area of ocean beyond national jurisdiction (beyond Exclusive Economic Zones and the territorial sea). Key principles include: freedom of navigation and overflight (Article 87); the rule that ships shall sail under the flag of one State only (Article 92); flag State jurisdiction and control over vessels on the high seas (Article 94); the duty of flag States to effectively exercise jurisdiction and control; the right of visit by naval vessels for reasonable grounds of piracy, slave trade, or stateless vessels (Article 110); the right of hot pursuit (Article 111); and conservation obligations for living resources (Articles 116-120). The UN Fish Stocks Agreement 1995 supplements Part VII for straddling and highly migratory fish stocks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "unclos_part_v_eez",
        "imo_solas_consolidated",
        "imo_colregs_1972"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unclos-part-ii-territorial-sea-contiguous-zone",
      "unclos-part-v-exclusive-economic-zone",
      "imo-solas-consolidated-2020",
      "imo-colregs-1972-collision-regulations"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unclos-part-xi-deep-seabed-mining-1982",
    "title": "United Nations Convention on the Law of the Sea, Part XI - The Area: International Seabed Mining Regime",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "Establishes the international legal framework for deep seabed mining in areas beyond national jurisdiction under the principle that the seabed is the common heritage of mankind. Applies to all states and entities engaging in exploration or exploitation of mineral resources in the Area, under the authority of the International Seabed Authority (ISA) as per Article 136 and Article 153.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unclos-part-v-exclusive-economic-zone"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "unclos-part-xii-marine-environment-protection-1982",
    "title": "UNCLOS Part XII - Protection and Preservation of the Marine Environment (Articles 192-237)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "UNCLOS Part XII (Articles 192-237) establishes the foundational international legal framework for protection and preservation of the marine environment; imposes a general obligation on all states to protect and preserve the marine environment (Article 192); grants flag states, coastal states, and port states concurrent jurisdiction to prevent, reduce, and control pollution from vessels, dumping, land-based sources, seabed activities, and the atmosphere; requires states to adopt laws no less effective than international rules (MARPOL, London Convention) and to cooperate through international organizations; directly governs flag state enforcement obligations and port state control powers over foreign vessels for pollution offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unclos-part-vii-high-seas",
      "imo-marpol-annex-vi-air-pollution"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "undrip-free-prior-informed-consent-mining",
    "title": "United Nations Declaration on the Rights of Indigenous Peoples (UNDRIP) 2007 - Free, Prior and Informed Consent (FPIC) Obligations Applicable to Mining on Indigenous Lands",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "UNDRIP requires states and corporations to obtain the free, prior and informed consent (FPIC) of Indigenous peoples before approving or commencing any mining project affecting their lands or territories. This obligation is grounded in Article 32(2) and reinforced by Articles 10, 19, 28, and 29.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp",
      "ilo-convention-138-minimum-age-1973"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "unece-helsinki-convention-1992-transboundary-watercourses",
    "title": "UNECE Helsinki Convention 1992 - Protection and Use of Transboundary Watercourses and International Lakes",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The UNECE Convention on the Protection and Use of Transboundary Watercourses and International Lakes (Helsinki Convention or Water Convention, 1992) is a binding multilateral environmental agreement under the United Nations Economic Commission for Europe. Adopted in Helsinki on 17 March 1992 and entered into force on 6 October 1996, it requires Parties to prevent, control and reduce transboundary impact, including transboundary water pollution. Article 2 establishes general provisions including the precautionary principle, polluter-pays principle, and intergenerational equity. Article 9 requires Parties to enter into bilateral or multilateral agreements with neighbouring countries sharing transboundary waters and establish joint bodies for cooperation. Article 13 requires regular exchange of information including monitoring data, planned measures, source-related and product-related emissions. Following amendments adopted by the Meeting of the Parties (MOP) in November 2003 and entering into force on 6 February 2013, the Convention was opened to accession by all UN Member States, transforming it into a global framework. The Protocol on Water and Health 2017 and the Protocol on Civil Liability 2003 supplement the Convention.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-watercourses-convention-1997-transboundary-water",
      "eu-water-framework-directive-2000-60-ec"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "unece-r100-electric-vehicle-battery-safety",
    "title": "UNECE Regulation No. 100: Uniform provisions concerning the approval of vehicles with regard to specific requirements for the electric power train",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes safety requirements for electric vehicle powertrains, mandating protection against direct and indirect contact with high-voltage parts and ensuring the safety of the Rechargeable Electrical Energy Storage System (REESS) under various conditions, including mechanical impact and thermal stress. Compliance requires satisfying detailed tests for electrical safety (Paragraph 5), REESS integrity (Paragraph 6), and functional safety.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-14001-ems"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "unece-r116-protection-unauthorized-use-motor-vehicles-2014",
    "title": "UNECE Regulation No. 116 - Protection of Motor Vehicles Against Unauthorized Use: Immobilizer and Alarm Standards",
    "domain": "Automotive & Mobility",
    "version": "2014-01",
    "last_updated": "2026-05-09",
    "bluf": "UNECE Regulation No. 116 (UN/R116) establishes uniform provisions for the approval of motor vehicle protection systems against unauthorized use, specifying technical requirements for immobilizer systems (which prevent the engine from starting without the correct key or credential), alarm systems, and trailer coupling protection; the regulation applies to M and N category vehicles type-approved under the 1958 Agreement, and defines activation timing, deactivation sequences, resistance to manipulation, and cryptographic credential requirements that manufacturers must certify to obtain type approval.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26262-functional-safety-road-vehicles-2018",
      "eu-type-approval-framework-2018-858"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unece-r152-advanced-emergency-braking-system-2021",
    "title": "UNECE Regulation No. 152 - Advanced Emergency Braking System (AEBS) for Passenger Cars and Light Vehicles",
    "domain": "Automotive & Mobility",
    "version": "2021-01",
    "last_updated": "2026-05-09",
    "bluf": "UNECE Regulation No. 152 (UN/R152), adopted by UNECE WP.29 in January 2021, establishes mandatory technical requirements for Advanced Emergency Braking Systems (AEBS) in M1 and M2 passenger cars and light buses, specifying collision detection requirements for stationary vehicles, moving vehicles, pedestrians, and cyclists, minimum deceleration thresholds, warning activation sequences, driver override capability, and system self-test procedures; the regulation implements the European General Safety Regulation 2019/2144 requirement that all new M1 type-approved vehicles carry AEBS from July 6, 2022.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26262-functional-safety-road-vehicles-2018",
      "eu-type-approval-framework-2018-858"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unece-r155-automotive-cybersecurity-2021",
    "title": "UN Regulation No. 155 - Uniform provisions concerning the approval of vehicles with regard to cyber security and cyber security management system",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-07-16",
    "bluf": "This regulation mandates that vehicle manufacturers (OEMs) establish, implement, and maintain a certified Cyber Security Management System (CSMS) to secure vehicles from cyber threats throughout their lifecycle. As per Section 7.2, obtaining a CSMS Certificate of Compliance is a prerequisite for vehicle type approval.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unece-r156-software-update-management-2021",
    "title": "Uniform provisions concerning the approval of vehicles with regard to software update and software update management system",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires vehicle manufacturers to implement a certified Software Update Management System (SUMS) to ensure the safety, security, and integrity of over-the-air (OTA) software updates. Manufacturers must obtain a Certificate of Compliance for their SUMS as a prerequisite for vehicle type approval, as mandated by Paragraph 7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unece-r157-automated-lane-keeping-systems-alks-2021",
    "title": "UNECE Regulation R157 - Automated Lane Keeping Systems (ALKS) 2021",
    "domain": "Automotive & Mobility",
    "version": "2021-01",
    "last_updated": "2026-05-09",
    "bluf": "UNECE Regulation No. 157 establishes type-approval requirements for Automated Lane Keeping Systems (ALKS) operating at speeds up to 60 km/h on motorways, requiring systems to detect driver incapacitation, execute minimum risk manoeuvres, maintain lane boundaries, and enable remote data recording for accident reconstruction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unece-r155-automotive-cybersecurity-2021",
      "iso-26262-functional-safety-road-vehicles-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unece-r48-installation-lighting-signalling-devices-2016",
    "title": "UNECE Regulation No. 48 - Installation of Lighting and Light-Signalling Devices on Vehicles",
    "domain": "Automotive & Mobility",
    "version": "6.0.0",
    "last_updated": "2016-09-14",
    "bluf": "UNECE R48 prescribes mandatory and optional lighting equipment and its installation geometry for all motor vehicle categories (M, N, L, O), requiring daytime running lights (DRL) on new M1/N1 from 2011, adaptive front-lighting systems (AFS) within defined photometric parameters, and automatic headlamp levelling for ADB systems, with colour separation rules prohibiting red lights forward and white lights rearward.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-vehicle-type-approval-regulation-2018-858",
      "eu-general-safety-regulation-2019-2144-vehicles",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unece-r51-03-acoustic-noise-motor-vehicles-2016",
    "title": "UNECE Regulation No. 51.03 - Acoustic Noise Limits for Motor Vehicles",
    "domain": "Automotive & Mobility",
    "version": "3.0.0",
    "last_updated": "2016-03-09",
    "bluf": "UNECE R51.03 sets declining noise emission limits for M1/N1 passenger and light commercial vehicles: 72 dB(A) from 2016, 70 dB(A) from 2020, 68 dB(A) from 2024 for M1, measured under ISO 362-1 accelerated vehicle approach test conditions, with additional sound emission provisions (ASEP) to prevent real-world noise exceeding type-approval levels.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-vehicle-type-approval-regulation-2018-858",
      "iso-26262-functional-safety-road-vehicles-2018",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unece-r79-steering-equipment-regulations-2018",
    "title": "UNECE Regulation R79 - Steering Equipment Requirements 2018",
    "domain": "Automotive & Mobility",
    "version": "2018-01",
    "last_updated": "2026-05-09",
    "bluf": "UNECE Regulation No. 79 (Revision 3, 2018) establishes type-approval requirements for steering equipment in motor vehicles, including corrective steering functions for advanced driver assistance and automated systems, specifying performance criteria for steering response, emergency steering override, and system failure behaviour.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "iso_standard",
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26262-functional-safety-road-vehicles-2018",
      "eu-type-approval-framework-2018-858"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unece-regulation-156-software-update-management-vehicles",
    "title": "UN ECE Regulation 156 - Software Update Management System (SUMS) for Connected Vehicles",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "UN ECE Regulation No. 156 on Software Update Management Systems (SUMS) for Vehicles (adopted by UNECE WP.29, entry into force January 2021, mandatory for EU type approval since July 2022) requires vehicle manufacturers to establish and maintain a certified Software Update Management System governing all OTA (Over-The-Air) and physical software updates to type-approved vehicle systems. SUMS ensures that software updates do not compromise safety, cybersecurity, or type approval compliance. The regulation is sister to UN R155 (CSMS) and both are mandatory conditions for EU type approval under the UNECE 1958 Agreement. SUMS certificates are issued by national type approval authorities after audit of manufacturer's SUMS processes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unece-r155-automotive-cybersecurity-2021",
      "eu-general-safety-regulation-2019-2144-automated-vehicles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "unece-wltp-gtr-15-worldwide-harmonized-test",
    "title": "UNECE GTR No. 15 Worldwide Harmonised Light Vehicles Test Procedure (WLTP) - Drive Cycle Design, Boundary Conditions, CO2 and Fuel Consumption Measurement for New Vehicle Type Approval",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes a globally harmonized standard for determining the levels of criteria pollutants, CO2 emissions, fuel/energy consumption, and electric range from light-duty vehicles under repeatable laboratory conditions. As outlined in Section 1, it applies to manufacturers seeking type approval for new vehicles, ensuring consistent and comparable emissions and consumption data worldwide.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unece-wp29-framework-connected-automated-vehicles",
    "title": "UNECE WP.29 Framework Document on Automated and Connected Vehicles - Type Approval, Cyber Security, Software Updates and Functional Safety",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This framework establishes mandatory type approval requirements for connected and automated vehicles (CAVs) under UNECE regulations, requiring manufacturers to implement robust cyber security management systems (CSMS), software update management systems (SUMS), and functional safety protocols in accordance with UN Regulation No. 155, No. 156, and No. 79. It applies to vehicle manufacturers seeking type approval in UNECE member states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021",
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "unece-wp29-vehicle-type-approval-framework",
    "title": "UNECE WP.29 World Forum for Harmonization of Vehicle Regulations - 1958, 1997 and 1998 Agreements, Type Approval Mutual Recognition and GRSP/GRVA/GRPE Technical Committee Mandates",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This framework establishes a system of mutual recognition for vehicle type approvals among contracting parties, allowing a vehicle or component approved in one member country to be accepted for sale in all others without further testing. The core principle, outlined in Article 1 of the 1958 Agreement, requires contracting parties to accept type approvals issued by others for vehicle systems, parts, and equipment that conform to the annexed UN Regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-23894-ai-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unesco-ai-ethics-work",
    "title": "UNESCO (AI Ethics - Work)",
    "domain": "Workplace",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Adherence to UNESCO's ethical recommendations for artificial intelligence in the workplace requires a proactive, human-rights-based governance framework. Organizations must systematically evaluate and mitigate AI's impact on labor through a mandatory labor impact assessment, which is subject to a recurring audit with a frequency of at least every 12 months. This assessment informs a required worker transition plan, developed through the implementation of genuine worker consultation. The framework establishes a clear quantitative limit, capping the annual displacement rate by AI at 10 percent. To manage this transition equitably, the provision of funded reskilling programs is obligatory, with a targeted minimum reskilling uptake by affected staff of 75 percent. Furthermore, the framework mandates that an organization ensures social safety net contributions for displaced workers. Key operational controls include a strict prohibition on illegitimate surveillance and a requirement to maintain human oversight on decisions impacting employment. A comprehensive worker data protection policy must exist, supported by a fair grievance mechanism to adjudicate disputes. These integrated measures are designed to ensure AI systems augment human capabilities and promote decent work.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "iso-26000-social-resp-mgt",
      "iso-30414-human-capital-rep",
      "sa8000-social-account",
      "nist-ai-rmf-1-0",
      "nist-sp-1270-managing-ai-bias"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unesco-convention-discrimination-education-1960",
    "title": "Convention against Discrimination in Education - Article 1 and 2",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This convention requires States Parties to proscribe and eliminate discrimination in education, defined as any distinction, exclusion, limitation, or preference based on specified grounds that impairs equality of treatment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "unesco-convention-higher-education-qualifications-1997",
    "title": "Convention on the Recognition of Qualifications concerning Higher Education in the European Region (Lisbon Recognition Convention)",
    "domain": "Education & Research",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Lisbon Recognition Convention requires signatory states to recognize higher education qualifications obtained in other member states unless substantial differences are demonstrated, based on fair and transparent procedures under Article 1. It applies to national authorities, recognition bodies, and higher education institutions in all 50+ ratifying countries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "unesco-cultural-diversity",
    "title": "UNESCO Cultural Diversity",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Adherence to the UNESCO framework for cultural diversity mandates a multifaceted compliance posture for all digital platforms. This requires the establishment and public disclosure of a formal cultural diversity policy alongside verifiable mechanisms for fair remuneration that benefit local creators. Operational requirements stipulate that systems must provide local language support within signatory states and actively promote indigenous cultural content, maintaining a minimum visibility threshold of twenty percent. Governance protocols must be implemented for conducting cultural impact assessments, ensuring algorithmic transparency for content recommendation engines, and developing culturally localized content moderation policies. Additionally, platforms must provide users with granular controls to manage content diversity. The compliance scope extends to respecting national laws through a robust data sovereignty policy, actively supporting the digitization of local cultural heritage, and maintaining systematic engagement with designated national cultural authorities to ensure ongoing alignment. Failure to satisfy these interconnected obligations constitutes a material deviation from the convention's core principles for protecting and promoting the diversity of cultural expressions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-copyright-treaty",
      "wipo-traditional-knowledge"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unesco-ethics-ai",
    "title": "UNESCO Ethics of AI",
    "domain": "AI Governance & Law",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with the UNESCO Recommendation on the Ethics of Artificial Intelligence demands a comprehensive governance framework ensuring AI systems uphold human rights, dignity, and environmental sustainability. The foundational principles mandate that `humanOversightRequired` is perpetually maintained for meaningful control over system determinations. Prior to any deployment, verification is necessary that both an `ethicalImpactAssessmentCompleted` and a `dataPrivacyImpactAssessmentCompleted` have been executed to prospectively evaluate risks and safeguard personal information. To promote fairness, a `biasDetectionMechanismActive` must be operational, complemented by a specific `vulnerableGroupProtectionMechanism` to prevent disparate negative outcomes. Transparency and responsibility are enforced by confirming an `explainabilityMethodImplemented` exists, alongside a clearly articulated `accountabilityFrameworkDefined` that assigns liability for system outcomes. The `proportionalityPrincipleVerified` ensures AI methods are appropriate and necessary for a given legitimate aim. Broader ecosystem health requires that the `environmentalImpactAssessed` is thoroughly documented. Inclusive governance is contingent upon proof that `stakeholderConsultationConducted` activities have meaningfully informed the AI lifecycle. Finally, system resilience and user trust are contingent upon a successful `securityRiskAssessmentCompleted` and the establishment of a `redressMechanismAvailable` for any individuals adversely affected, thereby aligning technological development with internationally recognized ethical standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles",
      "nist-ai-rmf-1-0",
      "nist-sp-1270-managing-ai-bias",
      "nistir-8312-explainable-ai-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "unesco-intangible-cultural-heritage-2003",
    "title": "UNESCO Convention for the Safeguarding of Intangible Cultural Heritage 2003 - Representative and Urgent Safeguarding Lists",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Convention for the Safeguarding of the Intangible Cultural Heritage was adopted by UNESCO General Conference on 17 October 2003 and entered into force on 20 April 2006. The Convention complements the World Heritage Convention 1972 by addressing intangible cultural heritage (ICH) - the practices, representations, expressions, knowledge, skills - as well as the instruments, objects, artefacts and cultural spaces associated therewith - that communities, groups and, in some cases, individuals recognize as part of their cultural heritage. Article 2(2) identifies 5 domains: oral traditions and expressions including language as vehicle; performing arts; social practices, rituals and festive events; knowledge and practices concerning nature and the universe; traditional craftsmanship. The Convention establishes three lists/registers: Representative List of the Intangible Cultural Heritage of Humanity (currently 730 elements from 145 States), List of Intangible Cultural Heritage in Need of Urgent Safeguarding (currently 87 elements), and Register of Good Safeguarding Practices (currently 39 programs). The Intergovernmental Committee for the Safeguarding of the Intangible Cultural Heritage (24 States Parties elected for 4 years) implements the Convention. 183 States Parties as of 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unesco-world-heritage-convention-1972",
      "unesco-convention-discrimination-education-1960"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "unesco-recommendation-ethics-ai-2021",
    "title": "Recommendation on the Ethics of Artificial Intelligence",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-29",
    "bluf": "This regulation establishes a global standard for ethical AI development and deployment across all 194 UNESCO member states, centered on human rights, transparency, and fairness. It mandates adherence to ten core principles including proportionality, safety, privacy, and multi-stakeholder governance as defined in the Recommendation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-data-governance-act-2022-cloud-data-sharing",
      "australia-ai-ethics-framework-2019",
      "asean-guide-ai-governance-ethics-2020",
      "bletchley-declaration-ai-safety-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "unesco-recommendation-ethics-neurotechnology-2025",
    "title": "UNESCO Recommendation on the Ethics of Neurotechnology (2025)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2025-11-01",
    "bluf": "The UNESCO Recommendation on the Ethics of Neurotechnology was adopted by the General Conference of the United Nations Educational, Scientific and Cultural Organization at its 43rd session in November 2025 as the first global normative framework for the ethics of neurotechnology. The Recommendation builds on the 2021 UNESCO Recommendation on the Ethics of Artificial Intelligence and the OECD Recommendation on Responsible Innovation in Neurotechnology (2019). It applies to all stages of the neurotechnology lifecycle from research and development through deployment and end-of-life, covering both medical and non-medical neurotechnologies including consumer brain-computer interfaces, neuroimaging, neuromodulation, and neuroprosthetics.\n\nThe Recommendation sets out core values (respect for human dignity and human rights; promotion of mental integrity and cognitive liberty; non-maleficence and well-being; equity, fairness and non-discrimination; sustainability) and principles (proportionality and do-no-harm; safety and security; transparency and explainability; responsibility and accountability; multi-stakeholder governance and adaptive regulation). Policy areas include neurotechnology research ethics, informed consent for neural data, neural privacy and mental integrity, regulation of consumer neurotechnology, education and digital literacy, and international cooperation. Member States are expected to apply the Recommendation through national legislation, regulatory measures, and policies and to report periodically to UNESCO on implementation. The Recommendation is non-binding but creates strong international expectation and serves as a baseline for emerging national neurotechnology law including the Chilean constitutional neurorights amendment, the Colorado neural data privacy law, and similar emerging frameworks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-ai-principles-2019-2024-update-trustworthy-ai",
      "chile-ley-21383-2021-neurorights-constitutional-amendment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "unesco-world-heritage-convention-1972",
    "title": "UNESCO World Heritage Convention 1972 - Cultural and Natural Heritage of Outstanding Universal Value and World Heritage List",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Convention concerning the Protection of the World Cultural and Natural Heritage (World Heritage Convention) was adopted by the UNESCO General Conference on 16 November 1972 and entered into force on 17 December 1975. It is the most widely ratified UNESCO convention with 195 States Parties as of 2024. The Convention establishes a global framework for identification, protection, conservation, presentation and transmission to future generations of cultural and natural heritage of outstanding universal value. Article 1 defines cultural heritage covering monuments, groups of buildings, and sites; Article 2 defines natural heritage covering natural features, geological/physiographical formations and natural sites; Article 3 establishes State Party identification responsibility. Article 11 establishes the World Heritage List (currently 1,223 sites in 168 States Parties as of 2024) and List of World Heritage in Danger (currently 56 sites). Article 12 ensures non-listing does not preclude outstanding universal value of properties. The World Heritage Fund under Article 15 provides voluntary contributions and matching funding for States Parties needing assistance. The Operational Guidelines (revised periodically, current version 2024) provide detailed implementation guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cbd-convention-biological-diversity-1992",
      "ramsar-convention-1971-wetlands-international-importance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "unfccc-1992-framework-convention-climate-change",
    "title": "UNFCCC 1992 - United Nations Framework Convention on Climate Change",
    "domain": "Sustainability & ESG",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The United Nations Framework Convention on Climate Change (UNFCCC), opened for signature at the Rio Earth Summit on 9 May 1992 and entered into force on 21 March 1994, is the foundational multilateral environmental agreement governing international cooperation on climate change. It has 197 Parties (near-universal ratification). The Convention establishes the principle of Common But Differentiated Responsibilities and Respective Capabilities (CBDR-RC, Article 3(1)), requires developed country Parties (Annex I) to adopt national policies to limit greenhouse gas emissions and protect sinks (Article 4(2)(a)), and requires all Parties to publish national inventories of GHG sources and sinks (Article 4(1)(a)). The Convention established the Conference of the Parties (COP) as the supreme body (Article 7), the Subsidiary Body for Scientific and Technological Advice (SBSTA, Article 9), and the Subsidiary Body for Implementation (SBI, Article 10). The UNFCCC Financial Mechanism (Article 11) channels climate finance through the Global Environment Facility (GEF) and the Green Climate Fund (GCF). The Convention is the parent treaty to: the Kyoto Protocol (1997, adopted under Article 17), the Paris Agreement (2015, adopted under the COP), and all 30+ COP decisions. All corporate and national climate pledges - including NDCs (Nationally Determined Contributions) under the Paris Agreement - derive their legal authority from the UNFCCC framework. The convention does not set binding GHG reduction targets itself but provides the legal architecture for subsequent protocols.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-paris-agreement-ndc-implementation-guidelines",
      "eu-ets-directive-2003-87-emissions-trading-scheme",
      "eu-csrd-2022-2464",
      "eu-cbam-2023-956-carbon-border-adjustment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "unidroit-principles-commercial-contracts-2016",
    "title": "UNIDROIT Principles of International Commercial Contracts 2016",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The UNIDROIT Principles provide a non-binding set of general rules for international commercial contracts, which parties can choose to govern their agreement, establishing a neutral framework for contract formation, validity, interpretation, performance, and remedies. Central tenets include party autonomy (Article 1.1) and the mandatory application of good faith and fair dealing (Article 1.7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-cisg-1980",
      "uncitral-model-law-arbitration",
      "icc-arbitration-rules-2021",
      "hague-convention-service-abroad"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "unisco-recommendation-teachers-learning-2019",
    "title": "UNESCO Recommendation on Open Educational Resources (OER) 2019 - OER Definition, Policy Framework, Capacity Building, Effective Inclusive Access, Sustainability Models and International Cooperation",
    "domain": "Education & Research",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The 2019 UNESCO Recommendation on OER requires Member States to develop supportive policies and build stakeholder capacity to create, access, re-use, adapt and redistribute Open Educational Resources under open licenses, as defined in the Recommendation. It applies to all education stakeholders, including governments, institutions, educators and learners.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-education-action-plan-2021-2027-deap",
      "oecd-principles-ai-in-education-recommendation-2023",
      "india-national-education-policy-nep-2020",
      "iso-21001-2018-educational-organizations-management",
      "eu-open-science-policy-fair-data-principles-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "unscr-1373-2001-counter-terrorism-financing-suppression",
    "title": "UN Security Council Resolution 1373 (2001) - Suppression of Financing and Support of Terrorism",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "UN Security Council Resolution 1373 was adopted unanimously on 28 September 2001 under Chapter VII of the UN Charter and imposes legally binding obligations on all UN Member States to prevent and suppress the financing of terrorist acts, freeze the funds and economic resources of persons and entities involved in terrorism, deny safe haven to terrorists, and provide mutual assistance in connection with terrorism investigations and proceedings. Paragraph 1 obligates States to criminalise the wilful provision or collection of funds with the intention or knowledge they will be used for terrorist acts, and to freeze without delay funds and economic resources of persons who commit or attempt to commit terrorist acts or who participate in or facilitate their commission. Paragraph 2 obligates States to refrain from providing any support to terrorist entities, deny safe haven, prevent terrorist acts, ensure that persons financing or participating in terrorism are brought to justice, and afford one another mutual assistance. Paragraph 3 calls on States to cooperate in border controls, exchange of operational information, and accession to relevant international counter-terrorism conventions. Paragraph 6 established the Counter-Terrorism Committee (CTC) to monitor implementation, supported by the Counter-Terrorism Executive Directorate (CTED) established by UNSCR 1535 (2004). Resolution 1373 sets the baseline framework for FATF Recommendations 5 to 8 on terrorism financing and is implemented domestically through statutes such as the US PATRIOT Act, the UK Terrorism Act 2000, and the EU Council Common Position 2001/931/CFSP and Council Regulation 2580/2001.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-6-targeted-sanctions-terrorism",
      "un-uncac-2003-anti-corruption-due-diligence-compliance",
      "un-palermo-convention-2000-transnational-organized-crime"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "unscr-1540-2004-wmd-non-proliferation-non-state-actors",
    "title": "UN Security Council Resolution 1540 (2004) - Non-Proliferation of WMD to Non-State Actors",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "UN Security Council Resolution 1540 was adopted unanimously on 28 April 2004 under Chapter VII of the UN Charter to address the proliferation of nuclear, chemical, and biological weapons and their means of delivery to non-State actors. Paragraph 1 obligates all States to refrain from providing any form of support to non-State actors that attempt to develop, acquire, manufacture, possess, transport, transfer, or use nuclear, chemical, or biological weapons and their means of delivery. Paragraph 2 obligates States to adopt and enforce effective laws prohibiting non-State actors from manufacturing, acquiring, possessing, developing, transporting, transferring, or using such weapons. Paragraph 3 obligates States to take and enforce effective measures to account for, secure, and physically protect related materials, establish border controls, and develop national export and transhipment controls including end-user controls, criminal and civil penalties, and screening of transfers. Paragraph 4 established the 1540 Committee initially for two years, subsequently extended through UNSCRs 1673 (2006), 1810 (2008), 1977 (2011), 2325 (2016), and 2663 (2022) with the latter extending the Committee mandate to 30 November 2032. The 1540 framework operates in parallel with the Nuclear Non-Proliferation Treaty (NPT), the Chemical Weapons Convention (CWC), the Biological Weapons Convention (BWC), and export control regimes including the Nuclear Suppliers Group, Australia Group, Missile Technology Control Regime, and Wassenaar Arrangement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-npt-1968-nuclear-non-proliferation",
      "opcw-cwc-1993-chemical-weapons-convention",
      "un-biological-weapons-convention-1972"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uruguay-law-18331-2008-personal-data-protection",
    "title": "Law No. 18,331 of 2008 on Personal Data Protection",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Uruguay's Law 18,331/2008 establishes a comprehensive framework for the protection of personal data, requiring data controllers to ensure lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. It grants data owners enforceable rights including access, rectification, deletion (Habeas Data), and objection, with cross-border transfers permitted only to countries deemed adequate by the Uruguayan regulator.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-privacy",
      "aicpa-soc2-cc-confidentiality",
      "eu-ai-act-transparency-instructions-for-use"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-10-usc-3201-dod-competition-requirements",
    "title": "10 USC § 3201 - Department of Defense Competition Requirements (formerly 10 USC 2304)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "10 USC § 3201 (recodified from former 10 USC 2304 by the FY2022 National Defense Authorization Act, Pub. L. 117-81, Title XVII, Subtitle B, § 1701) establishes the parallel competition requirement for the Department of Defense, the Coast Guard, and NASA - mirroring 41 USC 3301 for civilian agencies: the head of an agency conducting a procurement for property or services shall obtain full and open competition through the use of competitive procedures; sealed bids must be solicited if (A) time permits sealed bid solicitation, submission, and evaluation; (B) award will be on price and other price-related factors; (C) discussions are not necessary; and (D) there is reasonable expectation of more than one bid; otherwise competitive proposals must be requested; exceptions are codified in 10 USC 3203, 3204, and 3205 (the DoD-specific other-than-full-and-open-competition justifications mirroring 41 USC 3304 for civilian agencies); the Federal Acquisition Regulation implements the requirement in a manner consistent with the need to efficiently fulfill the Government's requirements; FAR Part 6 (Competition Requirements) is the cross-agency implementation and DFARS Part 206 is the DoD-specific supplement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "civilian_agency_parallel",
        "noncompetitive_exceptions",
        "far_dfars_implementation",
        "industry_mapping",
        "enforcement_anchors",
        "recodification_history"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355",
      "dfars-7012-defense-cyber"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-12-cfr-1005-18-regulation-e-prepaid-accounts",
    "title": "US 12 CFR 1005.18 (Regulation E): Requirements for Financial Institutions Offering Prepaid Accounts",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Section 1005.18 extends the Electronic Fund Transfer Act and Regulation E to prepaid accounts, requiring a financial institution to deliver a short form and a long form pre-acquisition fee disclosure before a consumer acquires a prepaid account. The short form must surface specific fees - periodic fee, per-purchase fee, in-network and out-of-network ATM withdrawal and balance-inquiry fees, cash reload fee, customer-service fees, and inactivity fee - plus statements on additional fee types, overdraft credit features, FDIC or NCUA insurance eligibility, and a directive to cfpb.gov/prepaid. Retail-package and telephone-acquisition exceptions allow the long form to follow acquisition under defined conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-12-cfr-part-1005-regulation-e-electronic-fund-transfers",
      "us-electronic-fund-transfer-act",
      "us-cfpb-dodd-frank-title-x-consumer-financial-protection"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-12-cfr-1026-43-ability-to-repay-qualified-mortgage",
    "title": "US 12 CFR 1026.43 (Regulation Z): Minimum Standards for Transactions Secured by a Dwelling - Ability-to-Repay and Qualified Mortgage",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Section 1026.43 of Regulation Z forbids a creditor from making a covered closed-end mortgage loan unless it makes a reasonable and good faith determination, at or before consummation, that the consumer has a reasonable ability to repay the loan according to its terms. The creditor must consider eight enumerated factors including income or assets, employment status, the monthly payment, mortgage-related obligations, current debt, and the debt-to-income ratio, and must verify the relied-upon information using reasonably reliable third-party records. A loan that meets the qualified mortgage criteria in paragraph (e) or (f) carries a presumption of compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-12-cfr-part-1026-regulation-z-truth-in-lending",
      "us-truth-in-lending-act",
      "us-cfpb-dodd-frank-title-x-consumer-financial-protection"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-12-cfr-part-1003-hmda-regulation-c",
    "title": "US 12 CFR Part 1003: Home Mortgage Disclosure (Regulation C)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 12 CFR Part 1003 (Regulation C) implements the Home Mortgage Disclosure Act (HMDA) requiring depository and non-depository financial institutions to collect record and report data about residential mortgage loan applications and originations. Covered institutions must report annually to the CFPB Loan/Application Register (LAR) data on covered loans including applicant demographic information (ethnicity race sex), loan characteristics (amount type purpose property location), action taken decisions, and pricing data including rate spread for certain higher-priced loans. The 2015 HMDA Rule expanded data collected from 23 to 48+ data points; subsequent CFPB rulemaking has adjusted coverage thresholds (currently 100 closed-end loans or 200 open-end lines annually).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "hmda",
        "cfr_12_1026",
        "cra",
        "fair_lending",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-12-cfr-part-1005-regulation-e-electronic-fund-transfers",
    "title": "US 12 CFR Part 1005: Electronic Fund Transfers (Regulation E)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 12 CFR Part 1005 (Regulation E) implements the Electronic Fund Transfer Act (EFTA) of 1978 establishing rights liabilities and responsibilities for participants in electronic fund transfer (EFT) systems including ATM debit card transactions automated clearinghouse (ACH) payments and remittance transfers. Subpart A covers consumer EFT to/from accounts with periodic statements error resolution unauthorized EFT liability disclosures and gift card protections (Federal Reserve gift card rule). Subpart B (Remittance Transfer Rule) covers international consumer remittances of >USD 15 with pre-payment disclosure and 30-minute cancellation right. The 2017 Prepaid Account Rule (effective April 2019) extended Reg E protections to most prepaid accounts including payroll cards and government benefit cards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "efta",
        "cfr_12_205",
        "cfpb_remit",
        "cfpb_prepaid",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-12-cfr-part-1024-regulation-x-respa",
    "title": "US 12 CFR Part 1024: Real Estate Settlement Procedures Act (Regulation X)",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 12 CFR Part 1024 (Regulation X) implements the Real Estate Settlement Procedures Act (RESPA) of 1974 governing residential mortgage loan transactions involving 1-4 family properties. Reg X covers Special Information Booklet (Sec 1024.6), Good Faith Estimate (replaced for most loans by integrated TRID Loan Estimate under Reg Z), Affiliated Business Arrangement (AfBA) disclosures (1024.15), prohibition on kickbacks and unearned fees (Section 8), prohibition on requiring use of specific title insurance company (Section 9), limits on escrow accounts (Section 10 and 1024.17), and mortgage servicing rules including loss mitigation procedures (Subpart C 1024.30 to 1024.41) introduced post-2014 by CFPB.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "respa",
        "cfr_12_1026",
        "section_8_kickbacks",
        "cfpb_supervision",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-12-cfr-part-1026-regulation-z-truth-in-lending",
    "title": "US 12 CFR Part 1026: Truth in Lending (Regulation Z) - CFPB",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 12 CFR Part 1026 (Regulation Z) implements the Truth in Lending Act (TILA) and other related statutes including the Home Ownership and Equity Protection Act (HOEPA), the Mortgage Disclosure Improvement Act (MDIA), and the CARD Act. Regulation Z requires creditors to disclose the cost of consumer credit including APR finance charge amount financed and total of payments. Subparts cover open-end credit (credit cards), closed-end credit (mortgages and installment loans), high-cost mortgages, higher-priced mortgage loans, ability-to-repay qualified mortgage rule, mortgage servicing, integrated mortgage disclosures Loan Estimate and Closing Disclosure (TRID), and credit card account opening and over-limit disclosures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "tila",
        "hoepa",
        "card_act",
        "cfr_12_1024",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-12-cfr-part-217-regulation-q-regulatory-capital",
    "title": "US 12 CFR Part 217: Regulatory Capital, Capital Adequacy of Bank Holding Companies, Savings and Loan Holding Companies, and State Member Banks (Regulation Q)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 12 CFR Part 217 (Regulation Q) implements the Basel III framework for the Federal Reserve including risk-based and leverage capital requirements for bank holding companies, covered savings and loan holding companies, and state member banks. Subparts define minimum capital ratios (Common Equity Tier 1 4.5%, Tier 1 6%, Total Capital 8%, Tier 1 leverage 4%), capital buffer requirements (capital conservation buffer 2.5%, countercyclical capital buffer, GSIB surcharge), capital instruments, risk-weighted assets via standardized or advanced approaches, market risk capital, and stress capital buffer per the Federal Reserve's capital plan and stress test rule.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "basel_iii",
        "cfr_12_252",
        "cfr_12_3",
        "ccar",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-12-cfr-part-225-regulation-y-bank-holding-companies",
    "title": "US 12 CFR Part 225: Bank Holding Companies and Change in Bank Control (Regulation Y)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 12 CFR Part 225 (Regulation Y) governs the formation, activities, and acquisitions of bank holding companies (BHCs) under the Bank Holding Company Act of 1956 and the supervision of nonbank subsidiaries. It includes restrictions on permissible activities (Section 4(c) and 4(k) for financial holding companies), application procedures for acquisitions and mergers, control determinations, prior notice for changes in directors and senior executive officers of troubled institutions, and the Capital Plan rule (Subpart H) for large BHCs. Foreign banking organizations are subject to Subpart N. The regulation also implements the Volcker Rule restrictions on proprietary trading per Subpart M cross-reference.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "bhc_act",
        "glba",
        "cfr_12_217",
        "volcker_rule",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-12-cfr-part-249-federal-reserve-lcr-regulation-ww",
    "title": "12 CFR Part 249 - Federal Reserve Liquidity Risk Measurement Standards (Regulation WW): Liquidity Coverage Ratio (LCR), Net Stable Funding Ratio (NSFR), and HQLA Requirements for Board-Regulated Institutions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "12 CFR Part 249 is the Federal Reserve's Regulation WW implementing the Basel III Liquidity Coverage Ratio (LCR) and Net Stable Funding Ratio (NSFR) for Board-regulated institutions on a consolidated basis. Section 249.1(a) establishes a minimum liquidity standard and a minimum stable funding standard. Section 249.1(b) sets applicability to (i) Global systemically important BHCs, (ii) GSIB depository institutions, (iii) Category II Board-regulated institutions, (iv) Category III Board-regulated institutions, (v) Category IV Board-regulated institutions with $50 billion or more in average weighted short-term wholesale funding, (ii) covered nonbank companies, or (iii) any Board-regulated institution where the Board determines application is appropriate. Section 249.1(b)(2) excludes bridge financial companies as defined in 12 USC 5381(a)(3), new depository institutions, and bridge depository institutions. Section 249.3 sets the operative definitions including the LCR, NSFR, HQLA, level 1, level 2A, and level 2B liquid assets, brokered deposit, operational deposit, and over 100 other terms. Section 249.10 requires the Board-regulated institution to calculate and maintain a liquidity coverage ratio equal to or greater than 1.0 on each business day (or, for Category IV, on the last business day of the applicable month) in accordance with Part 249, with the elected calculation time fixed by written notice to the Board prior to December 31, 2019. Section 249.20 sets the level 1, level 2A, and level 2B liquid asset criteria - level 1 includes Reserve Bank balances, foreign withdrawable reserves, US Treasury securities, and securities issued or unconditionally guaranteed by a US government agency fully and explicitly guaranteed by the full faith and credit of the US government, or by a sovereign entity, the Bank for International Settlements, the IMF, the European Central Bank, the European Community, or a multilateral development bank that is assigned a zero percent risk weight under subpart D of Regulation Q (12 CFR Part 217) and is liquid and readily-marketable. Section 249.21 calculates the HQLA amount as level 1 plus level 2A (at 85% of fair value) plus level 2B (at 50% of fair value), minus the greater of the unadjusted excess HQLA amount or the adjusted excess HQLA amount. Section 249.22 sets HQLA operational requirements including monetisation capability, control under the liquidity management function, segregation, and policies and procedures. Section 249.30 calculates the total net cash outflow amount as the outflow adjustment percentage multiplied by the sum of outflow amounts. Section 249.40 imposes a liquidity coverage shortfall supervisory framework requiring notification of the Board on any business day when the LCR is calculated to be less than the minimum requirement. Section 249.50 sets transitions for Board-regulated institutions becoming subject to Part 249. The Net Stable Funding Ratio subpart (Subpart K, sections 249.100 onwards) implements the Basel III stable funding standard requiring an NSFR equal to or greater than 1.0.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "purpose_and_applicability_anchor",
        "definitions_anchor",
        "minimum_lcr_anchor",
        "hqla_criteria_anchor",
        "hqla_amount_calculation_anchor",
        "operational_requirements_anchor",
        "net_cash_outflow_anchor",
        "shortfall_supervisory_framework_anchor",
        "nsfr_anchor",
        "transitions_anchor",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-liquidity-lcr",
      "bcbs-248-monitoring-tools-intraday-liquidity-management-2013",
      "us-dodd-frank-stress-testing-dfast-2010",
      "us-fed-12-cfr-252-reg-yy-enhanced-prudential-standards",
      "lcr-disclosure-standards"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-12-cfr-part-30-occ-safety-soundness-standards",
    "title": "US 12 CFR Part 30: Safety and Soundness Standards (OCC)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 12 CFR Part 30 prescribes the standards for safety and soundness for OCC-supervised national banks, federal savings associations, and federal branches and agencies of foreign banks, as well as heightened standards for large covered institutions. The standards cover internal controls and information systems, internal audit, loan documentation, credit underwriting, interest rate exposure, asset growth, asset quality, earnings, compensation arrangements, fees and benefits, and standards for residential mortgage lending. Heightened standards apply to insured institutions with average total consolidated assets equal to or greater than $50 billion. Failure to comply triggers a safety and soundness compliance plan submission within 30 days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fdic_act",
        "cfr_12_4",
        "occ_heightened",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-12-usc-2605-respa-servicing-mortgage-loans-qualified-written-requests",
    "title": "US Real Estate Settlement Procedures Act - 12 USC 2605 Servicing of Mortgage Loans, Notice of Transfer, and Qualified Written Requests",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "12 USC 2605 titled 'Servicing of mortgage loans and administration of escrow accounts' is the RESPA Section 6 provision governing notice of transfer of mortgage loan servicing, response to qualified written requests, and administration of escrow accounts. Subsection (b) requires the transferor servicer to send written notice to the borrower not less than 15 days before the effective date of transfer of servicing, with a 30-day post-transfer notice exception for certain distressed circumstances. Subsection (c) requires the transferee servicer to send written notice to the borrower not more than 15 days after the effective date of transfer, with the same 30-day post-transfer exception. Subsection (e) governs qualified written requests (QWRs): on receipt of a written request from the borrower for information relating to the servicing of the loan, the servicer shall provide a written response acknowledging receipt of the correspondence within 5 days (excluding legal public holidays, Saturdays, and Sundays) and either make appropriate corrections or provide the borrower with a written explanation or clarification, not later than 30 days (excluding legal public holidays, Saturdays, and Sundays) after the receipt of the request, with an additional 15-day extension permitted if the servicer notifies the borrower before the initial 30-day period expires. Subsection (g) requires the servicer to promptly return the escrow account balance to the borrower within 20 business days of the payoff date. Subsection (f) provides remedies: in individual actions, actual damages plus additional damages of up to $2,000 in the case of a pattern or practice of noncompliance; in class actions, actual damages per member plus up to $2,000 per class member with the total recovery capped at the lesser of $1,000,000 or 1 percent of the net worth of the servicer; and recovery of court costs and reasonable attorney's fees for any successful action.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-respa-real-estate-settlement-procedures"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-12-usc-2607-respa-prohibition-kickbacks-unearned-fees",
    "title": "US Real Estate Settlement Procedures Act - 12 USC 2607 Prohibition against Kickbacks and Unearned Fees (RESPA Section 8)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "12 USC 2607 titled 'Prohibition against kickbacks and unearned fees' is the Real Estate Settlement Procedures Act (RESPA) Section 8 provision banning compensated business referrals and unearned-fee splitting in connection with federally related mortgage loans. Subsection (a) provides that no person shall give and no person shall accept any fee, kickback, or thing of value pursuant to any agreement or understanding, oral or otherwise, that business incident to or a part of a real estate settlement service involving a federally related mortgage loan shall be referred to any person. Subsection (b) provides that no person shall give and no person shall accept any portion, split, or percentage of any charge made or received for the rendering of a real estate settlement service in connection with a transaction involving a federally related mortgage loan other than for services actually performed. Subsection (c) enumerates the permitted exceptions: (1) the payment of a fee to attorneys at law for services actually rendered; (2) the payment of a fee by a title company to its duly appointed agent for services actually performed in the issuance of a policy of title insurance; (3) the payment of a fee by a lender to its duly appointed agent for services actually performed in the making of a loan; (4) certain bona fide payments for goods or facilities actually furnished or services actually performed; (5) certain cooperative brokerage and referral arrangements between real estate agents and brokers; and (6) affiliated business arrangements with proper disclosure and a written estimate of charges provided to the referred party. Subsection (d) imposes the penalties: any person violating subsections (a) or (b) shall be fined not more than $10,000 or imprisoned for not more than one year, or both; the person involved may be jointly and severally liable to the person or persons charged for the settlement service involved in the violation in an amount equal to three times the amount of any charge paid for such settlement service; and the court may award court costs of the action together with reasonable attorneys' fees for any successful action.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-respa-real-estate-settlement-procedures"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-14-cfr-part-121-operating-requirements-air-carriers",
    "title": "US 14 CFR Part 121: Operating Requirements: Domestic, Flag, and Supplemental Operations",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 14 CFR Part 121 prescribes the operating requirements for certificate holders conducting domestic, flag, and supplemental operations using turbojet-powered airplanes or airplanes with 10 or more passenger seats or a payload of more than 7,500 pounds. Part 121 sets out aircraft requirements, airman certification, manual requirements, training programs, dispatching, flight time limits, maintenance program standards, ETOPS, and crew rest. Air carriers must operate under an Operations Specification approved by their assigned FAA Certificate Management Office. Non-compliance results in certificate action including suspension or revocation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_14_119",
        "cfr_14_117",
        "cfr_14_125",
        "iata_iosa",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-14-cfr-part-135-commuter-on-demand-operations",
    "title": "US 14 CFR Part 135: Operating Requirements: Commuter and On Demand Operations",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 14 CFR Part 135 prescribes the operating requirements for certificate holders conducting commuter or on-demand operations including air taxi, charter, and scheduled passenger operations using aircraft with 9 or fewer passenger seats and a payload of 7,500 pounds or less, or rotorcraft. Part 135 sets out aircraft equipment requirements, crewmember training, flight and duty limitations, maintenance, and dispatch or flight following procedures. Operators must maintain a current operations specifications, conduct training under an approved program, and report unscheduled landings and mechanical interruptions to the FAA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_14_119",
        "cfr_14_91",
        "cfr_14_120",
        "icao_annex_6",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-14-cfr-part-25-airworthiness-transport-category",
    "title": "US 14 CFR Part 25: Airworthiness Standards - Transport Category Airplanes",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 14 CFR Part 25 sets airworthiness standards for transport category airplanes used in scheduled passenger and cargo air transportation. The standards cover flight performance, structures, design and construction, powerplant integration, equipment, operating limitations and information, and electrical wiring interconnection systems (EWIS). Subpart B addresses flight; Subpart C structures including 14 CFR 25.571 damage tolerance and fatigue; Subpart D design and construction; Subpart E powerplant; Subpart F equipment including 25.1309 system safety analysis; Subpart G operating limitations. Compliance is foundational for FAA Type Certificate issuance and is harmonised internationally via EASA CS-25.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "easa_cs_25",
        "icao_annex_8",
        "cfr_14_21",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-14-cfr-part-33-airworthiness-aircraft-engines",
    "title": "US 14 CFR Part 33: Airworthiness Standards - Aircraft Engines",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 14 CFR Part 33 sets airworthiness standards for aircraft engines including reciprocating and turbine engines used in transport and other categories of aircraft. The standards cover engine design and construction, durability, endurance testing including the 150-hour endurance test, operational standards, and continued airworthiness. Subpart B applies to all engines; Subpart C and D specify reciprocating-engine requirements; Subpart E and F specify turbine-engine requirements. Type Certificate for an engine is issued separately from the airplane, allowing engines to be installed across multiple aircraft types. Compliance is foundational to engine type certification and harmonised internationally with EASA CS-E.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "easa_cs_e",
        "icao_annex_8",
        "cfr_14_21",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-14-cfr-part-39-faa-airworthiness-directives",
    "title": "US 14 CFR Part 39: Airworthiness Directives",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 14 CFR Part 39 establishes the framework under which the FAA issues Airworthiness Directives (ADs) to correct unsafe conditions in aircraft, aircraft engines, propellers, or appliances. ADs are legally enforceable rules apply to the affected product; operators must comply with each AD applicable to their aircraft. The FAA may issue immediately adopted ADs in response to urgent safety conditions, or normal ADs through notice-and-comment rulemaking. Operators must record AD compliance in maintenance records per 14 CFR 43.9 and 91.417. Alternative Methods of Compliance (AMOCs) may be approved by the responsible Aircraft Certification Office (ACO) or Designee.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_14_91_403",
        "cfr_14_43_9",
        "cfr_14_21",
        "icao_csta",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-14-cfr-part-401-faa-commercial-space-transportation-definitions",
    "title": "14 CFR Part 401 - FAA Commercial Space Transportation: Organization and Definitions",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2025-06-01",
    "bluf": "Every party operating under the FAA Office of Commercial Space Transportation regime - applicants for launch and reentry licences under 14 CFR Parts 415, 417, 431, 435, 437, 450, and the human spaceflight regime in 14 CFR Part 460 - must apply the controlling definitions in 14 CFR § 401.5 and § 401.7 verbatim when classifying their vehicle as a launch vehicle, suborbital rocket, expendable launch vehicle, or reusable launch vehicle, classifying their operation as a launch or reentry, classifying their site as a launch site, classifying their cargo as a payload, and classifying the persons on board as crew, government astronauts, or space flight participants, because each classification triggers a distinct downstream Part with its own licensing, safety, and informed-consent obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-faa-14-cfr-part-415-launch-license-policy-review",
      "us-faa-14-cfr-part-450-launch-reentry-license-requirements",
      "us-commercial-space-launch-act",
      "us-faa-14-cfr-part-460-human-spaceflight-requirements"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-14-cfr-part-43-faa-maintenance-preventive-maintenance",
    "title": "US 14 CFR Part 43: Maintenance, Preventive Maintenance, Rebuilding, and Alteration",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 14 CFR Part 43 establishes the regulations governing maintenance preventive maintenance rebuilding and alteration of US-registered aircraft and aviation products. Part 43 specifies persons authorized to perform work (certificated mechanics with A&P certificates, repair stations under Part 145, repairmen under Part 65, manufacturers within scope of Type Certificate), the materials and processes used, performance standards, inspection requirements (annual 100-hour progressive inspection), and recordkeeping including return-to-service entries per 14 CFR 43.9 and 43.11. Major repairs and major alterations require Form 337 signed by an FAA-certificated mechanic or repair station with appropriate ratings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_14_91",
        "cfr_14_145",
        "cfr_14_65",
        "cfr_14_39",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-14-cfr-part-91-general-operating-flight-rules",
    "title": "US 14 CFR Part 91: General Operating and Flight Rules",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 14 CFR Part 91 prescribes the general rules governing the operation of aircraft within the US including airspace classes, visual and instrument flight rules, equipment requirements, maintenance preventive maintenance rebuilding and alteration, large and turbine-powered multiengine airplane operations, and operations outside the US. Part 91 applies to all civil aircraft operations not subject to Part 121, 125, 129, 133, 135, or 137 and is the foundational rule set for general aviation. Pilots must comply with airworthiness directives, recurrent inspections, and flight rules including VFR/IFR minimums.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_14_61",
        "cfr_14_43",
        "cfr_14_45",
        "icao_annex_2",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-15-cfr-part-734-ear-scope-de-minimis-foreign-direct-product",
    "title": "15 CFR Part 734 Scope of the EAR",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "15 CFR Part 734 defines the jurisdictional scope of the Export Administration Regulations (EAR) administered by the US Department of Commerce Bureau of Industry and Security (BIS). Section 734.3 identifies the items subject to the EAR (all items in the United States, all US-origin items wherever located, and certain foreign-produced items by reason of de minimis US content or the Foreign-Direct-Product rules). Section 734.4 establishes the de minimis U.S. content rules: under paragraph (c) a 10 percent or less de minimis threshold applies for the most sensitive destinations and items, and under paragraph (d) a 25 percent or less de minimis threshold applies for most other destinations, requiring a controlled-content value calculation against the total value of the foreign-produced item. Section 734.9 sets out the Foreign-Direct Product (FDP) Rules that extend EAR jurisdiction to certain foreign-produced items that are the direct product of US-origin technology or software or are produced by a plant or major component of a plant that is itself the direct product of US-origin technology or software; the enumerated FDP rules include the National Security FDP rule, the 9x515 FDP rule, the 600 series FDP rule, the Entity List FDP rules, the Russia/Belarus/Crimea FDP rule, the Russia/Belarus-Military End User FDP rule, the Advanced Computing FDP rule, the Supercomputer FDP rule, the Iran FDP rule, the Semiconductor Manufacturing Equipment FDP rule, and the AI model weights FDP rule. Section 734.13 defines Export (actual shipment or transmission out of the United States, releases of technology or source code to foreign persons, and deemed exports). Section 734.14 defines Reexport (actual shipment or transmission of an item subject to the EAR from one foreign country to another). Correct application of Part 734 determines whether a transaction is subject to the EAR at all and is the threshold gate before any classification, license, or license-exception analysis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-15-cfr-part-736-ear-general-prohibitions-gp1-gp10",
      "us-15-cfr-part-744-ear-end-user-end-use-controls-entity-list",
      "ear-dual-use-export"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-15-cfr-part-736-ear-general-prohibitions-gp1-gp10",
    "title": "EAR 15 CFR Part 736 - Ten General Prohibitions Governing Exports, Reexports, and In-Country Transfers",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "15 CFR Part 736 of the Export Administration Regulations is the central control gateway of the EAR - the ten General Prohibitions (GP1 through GP10) that any US person, foreign person, or transaction touching items subject to the EAR must clear before proceeding without a Bureau of Industry and Security (BIS) license. Section 736.1 introduces the framework. Section 736.2(b)(1) through (10) establishes the ten prohibitions: GP1 (Export and reexport of controlled items to listed countries) prohibits export or reexport of items subject to the EAR controlled under the Commerce Country Chart in Supplement No. 1 to Part 738 without a license; GP2 (Reexport and export from abroad of foreign-made items incorporating more than de minimis controlled US content) prohibits reexport of foreign-produced items containing more than de minimis (typically 25%, or 10% for embargoed destinations and certain ECCNs) controlled US content; GP3 (Reexport and export from abroad of foreign-produced direct products) prohibits reexport of foreign-produced items that are direct products of US technology or software under section 734.9 (including the Huawei FDP, Russia/Belarus FDP, and advanced computing FDP rules); GP4 (Engaging in actions prohibited by a denial order) prohibits any party from engaging in any transaction with a person subject to a Part 766 denial order; GP5 (Export or reexport to prohibited end-uses or end-users) prohibits export, reexport, or transfer with knowledge or reason to know that the item will be used in a prohibited end-use under Part 744 (nuclear, missile, chemical/biological, military end-use, military-intelligence end-use); GP6 (Export or reexport to embargoed destinations) prohibits export, reexport, or transfer to embargoed destinations under Part 746 (Cuba, Iran, North Korea, Syria, Crimea, occupied Ukrainian territories) without a license; GP7 (Support of proliferation activities) prohibits US persons from supporting WMD or military intelligence proliferation activities (the catch-all under section 744.6); GP8 (In-transit shipments and items to be unladen from vessels or aircraft) prohibits in-transit unloading without authorisation; GP9 (Orders, terms, and conditions) prohibits violation of any term or condition of a license, authorisation, or Foreign-Trade Zone admission; GP10 (Proceeding with transactions with knowledge that a violation has occurred or is about to occur) prohibits any party from acting on a transaction with knowledge that a violation has occurred, is occurring, or is about to occur (the knowledge-based catch-all). Civil penalty up to USD 374,474 per violation or twice transaction value (greater) under IEEPA 50 USC 1705; criminal penalty up to 20 years imprisonment under 50 USC 4819.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "gp1_through_gp10_scope_summary",
        "de_minimis_thresholds_under_part_734_4_for_gp2",
        "foreign_direct_product_rule_734_9_under_gp3"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-export-administration-regulations",
      "us-15-cfr-part-740-ear-license-exceptions",
      "us-15-cfr-part-744-ear-entity-list-end-user-end-use-controls",
      "us-export-control-reform-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-15-cfr-part-740-ear-license-exceptions",
    "title": "EAR 15 CFR Part 740 - Export Administration Regulations License Exceptions (LVS, GBS, TSR, TMP, RPL, GOV, GFT, TSU, BAG, ENC, STA)",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "15 CFR Part 740 of the Export Administration Regulations (EAR) sets out the License Exceptions that authorise specific export, reexport, or in-country transfer transactions without an individually validated Bureau of Industry and Security (BIS) export licence, provided every condition of the exception is met and the transaction is not otherwise prohibited. Section 740.1 introduces the framework and section 740.2 lists global restrictions that disqualify any exception (including transactions to embargoed destinations under Part 746, military end-use under Part 744, and presence on the Entity List or SDN List). The principal exceptions are: LVS section 740.3 (shipments of limited value below specified dollar thresholds in Country Group B), GBS section 740.4 (shipments to Country Group B for items controlled only for National Security Column 2), SPP section 740.5 (Syria Peace and Prosperity for civilian goods), TSR section 740.6 (technology and software under restriction in Country Group B with letter of assurance), TMP section 740.9 (temporary imports, exports, reexports, and in-country transfers including tools of trade), RPL section 740.10 (servicing and replacement parts and equipment one-for-one), GOV section 740.11 (governments, international organisations, and international inspections under the Chemical Weapons Convention or IAEA), GFT section 740.12 (gift parcels and humanitarian donations), TSU section 740.13 (publicly available technology and software, mass market software, operation technology, sales technology), BAG section 740.14 (baggage of US persons travelling abroad), ENC section 740.17 (encryption commodities, software, and technology subject to encryption review requirements), and STA section 740.20 (Strategic Trade Authorization for Country Group A:5 and A:6 trusted partners). Every exception requires a destination control statement, recordkeeping under Part 762, and on the Electronic Export Information filing the proper license exception symbol. Violations are pursued under section 764.2 with civil penalties up to USD 374,474 per violation or twice the transaction value (greater) under IEEPA, denial of export privileges under Part 766, and criminal penalties up to 20 years imprisonment under 50 USC 4819.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "exception_eligibility_screening",
        "encryption_exception_compliance",
        "strategic_trade_authorization_eligibility"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-export-administration-regulations",
      "us-export-administration-regulations-part-774",
      "us-export-control-reform-act-2018",
      "ear-dual-use-export"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-15-cfr-part-744-ear-end-user-end-use-controls-entity-list",
    "title": "15 CFR Part 744 - Export Administration Regulations: Control Policy - End-User and End-Use Based (including the Entity List, Military End-User List, and Unverified List)",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2025-06-01",
    "bluf": "U.S. exporters, reexporters, and persons effecting in-country transfers of items subject to the Export Administration Regulations must screen every transaction against the end-user and end-use controls in 15 CFR Part 744 - applying license requirements when an item is to be used in nuclear, missile, chemical or biological weapons, or military-intelligence end-uses, when an entity appears on the Entity List, Military End-User List, or Unverified List, when an OFAC-sanctioned person is a party, when restricted U.S. person activities involve weapons of mass destruction support, or when other Part 744 end-use or end-user prohibitions apply - and must apply the BIS licensing review standards rather than relying on item-classification controls alone.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ear-dual-use-export",
      "wassenaar-arrangement-1996-dual-use-conventional-arms"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-15-cfr-part-744-ear-entity-list-end-user-end-use-controls",
    "title": "EAR 15 CFR Part 744 - End-Use and End-User Based Controls including Entity List and Military End-User Controls",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "15 CFR Part 744 of the Export Administration Regulations establishes the end-use and end-user based controls administered by the Bureau of Industry and Security (BIS) that overlay the item-based controls of the Commerce Control List in Part 774. Section 744.1 establishes the general provisions, the broad presumption of denial for transactions to listed parties, and the no-license-exception rule for Part 744 transactions. Section 744.2 prohibits exports, reexports, and transfers (in-country) for use in nuclear end-uses without a licence. Section 744.3 imposes licence requirements for rocket systems and unmanned aerial vehicles end-uses. Section 744.4 imposes licence requirements for chemical and biological weapons end-uses. Section 744.6 restricts specific activities of US persons including supporting WMD activities. Section 744.8 imposes licence requirements when any person named on the Specially Designated Nationals and Blocked Persons (SDN) List is a party. Section 744.11 establishes licence requirements for entities acting or at significant risk of acting contrary to US national security and foreign policy - this is the operative provision for the Entity List which is published as Supplement No. 4 to Part 744 and which currently includes over 2,500 entities including Huawei and many subsidiaries, SMIC, the IRGC, and entities in Russia, Belarus, Iran, China, and other jurisdictions. Section 744.16 sets out the operating procedures for Entity List additions, removals, and modifications. Section 744.17 controls microprocessor technology for military end-uses. Section 744.21 imposes licence requirements for military end-uses and military end-users in China, Russia, Venezuela, Burma, and Cambodia - and Supplement No. 7 maintains the Military End-User (MEU) List. Section 744.22 controls military-intelligence end-uses and end-users in specified countries. Every Part 744 transaction requires an individually validated BIS licence subject to a presumption of denial; no Part 740 license exception is available. Violations attract civil penalties up to USD 374,474 per violation or twice transaction value (greater) under IEEPA, denial of export privileges, and criminal penalties up to 20 years imprisonment under 50 USC 4819.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "entity_list_supplement_4_features",
        "military_end_user_list_supplement_7",
        "foreign_direct_product_rule_interaction"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-export-administration-regulations",
      "us-export-control-reform-act-2018",
      "us-15-cfr-part-740-ear-license-exceptions",
      "us-export-administration-regulations-part-774"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-15-cfr-part-748-ear-license-applications-support-documents",
    "title": "15 CFR Part 748 Applications and Documentation",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "15 CFR Part 748 governs license applications, classification requests, and supporting documentation under the Export Administration Regulations (EAR) administered by the US Department of Commerce Bureau of Industry and Security (BIS). Section 748.3 (Classification requests and advisory opinions) sets out how to request a commodity classification (CCATS) or an advisory opinion from BIS where the Export Control Classification Number or licensing requirement is uncertain. Section 748.10 (People's Republic of China (PRC) End-User Statement) prescribes the PRC End-User Statement that may be required as a support document for certain license applications for exports to the People's Republic of China. Section 748.11 (Statement by Ultimate Consignee and Purchaser) prescribes the support statement that the ultimate consignee and purchaser must furnish in connection with specified license applications. Section 748.15 (Authorization Validated End-User (VEU)) establishes the Validated End-User program under which eligible end-users approved by the End-User Review Committee may receive specified items without an individual license. Together these provisions define the documentary record that must accompany classification, advisory-opinion, and license-application processes, and the support documents that must be obtained and retained to demonstrate the legitimacy of the parties and the end-use of the transaction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-15-cfr-part-734-ear-scope-de-minimis-foreign-direct-product",
      "us-15-cfr-part-736-ear-general-prohibitions-gp1-gp10",
      "us-15-cfr-part-740-ear-license-exceptions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-15-cfr-part-760-ear-antiboycott-restrictive-trade-practices",
    "title": "15 CFR Part 760 Restrictive Trade Practices or Boycotts (Anti-Boycott)",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "15 CFR Part 760 contains the anti-boycott provisions of the Export Administration Regulations (EAR), administered by the US Department of Commerce Bureau of Industry and Security (BIS), which prohibit US persons from participating in or cooperating with unsanctioned foreign boycotts (principally the Arab League boycott of Israel). Section 760.2 (Prohibitions) sets out the categories of prohibited conduct in paragraphs (a) through (f): the prohibition against refusals to do business; the prohibition against discriminatory actions; the prohibition against furnishing information about race, religion, sex, or national origin; the prohibition against furnishing information about business relationships with boycotted countries or blacklisted persons; the prohibition against furnishing information about associations with charitable or fraternal organizations; and the prohibition against implementing letters of credit containing prohibited conditions or requirements. Section 760.3 (Exceptions to prohibitions) identifies the limited circumstances in which a US person may comply with certain boycott-related requirements without violating the prohibitions. Section 760.4 (Evasion) prohibits any US person from engaging in any transaction or taking any other action with intent to evade the provisions of Part 760. Section 760.5 (Reporting requirements) requires a US person who receives a request to take an action that has the effect of furthering or supporting an unsanctioned foreign boycott to report that request to the Department of Commerce. Compliance requires screening transaction documents for boycott-related requests, declining prohibited conduct, applying only the recognised exceptions, and timely reporting of reportable requests.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-15-cfr-part-734-ear-scope-de-minimis-foreign-direct-product",
      "ear-dual-use-export"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-15-usc-1635-tila-right-of-rescission-principal-dwelling",
    "title": "US Truth in Lending Act - 15 USC 1635 Right of Rescission as to Certain Transactions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1635 titled 'Right of rescission as to certain transactions' is the Truth in Lending Act (TILA) provision granting consumers the right to rescind certain consumer credit transactions secured by an interest in their principal dwelling (other than residential mortgage transactions). Subsection (a) provides that the obligor shall have the right to rescind the transaction until midnight of the third business day following the consummation of the transaction or the delivery of the information and rescission forms required under this section together with a statement containing the material disclosures required under TILA, whichever is later, by notifying the creditor in accordance with regulations of the Bureau. The creditor must clearly and conspicuously disclose, in accordance with regulations of the Bureau, the rights of the obligor under this section, and provide appropriate forms for the obligor to exercise the right of rescission. Subsection (b) provides that within 20 days after receipt of a notice of rescission, the creditor shall return to the obligor any money or property given as earnest money, downpayment, or otherwise, and shall take any action necessary or appropriate to reflect the termination of any security interest created under the transaction. Subsection (e) provides that this section does not apply to a residential mortgage transaction, a transaction which constitutes a refinancing or consolidation (with no new advances) of the principal balance then due and any accrued and unpaid finance charges of an existing extension of credit by the same creditor secured by an interest in the same property, a transaction in which an agency of the Federal Government, a State, or a political subdivision thereof is the obligor, or advances under a preexisting open end credit plan. Subsection (f) provides that the obligor's right of rescission shall expire three years after the date of consummation of the transaction or upon the sale of the property, whichever occurs first, where the creditor failed to deliver the required disclosures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-truth-in-lending-act"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-15-usc-1666-tila-correction-of-billing-errors",
    "title": "US Truth in Lending Act - 15 USC 1666 Correction of Billing Errors on Open-End Consumer Credit Plans",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1666 titled 'Correction of billing errors' is the Truth in Lending Act provision governing the consumer's right to dispute alleged billing errors on open-end consumer credit plans and the creditor's resolution duties. Subsection (a) requires that, after receipt of a written notice from the consumer asserting a billing error, the creditor shall (A) not later than 30 days after the receipt of the notice, send a written acknowledgment of the notice to the obligor (unless the action required by the second sentence is taken within the 30-day period); and (B) not later than two complete billing cycles of the creditor (in no event later than 90 days) after the receipt of the notice, and prior to taking any action to collect the amount, or any part thereof, indicated by the obligor under paragraph (2) to be in error, either correct the account by making appropriate adjustments and transmit notice of the correction to the obligor, or send a written explanation or clarification to the obligor, after having conducted an investigation, setting forth to the extent applicable the reasons why the creditor believes the account was correctly shown in the statement. The consumer's notice must be received within 60 days after having transmitted to the obligor a statement of the obligor's account in which the alleged error is indicated. Subsection (b) defines 'billing error' to include unauthorized extensions of credit, requests for clarification on charges, failure to reflect payment or credit properly, failure of the creditor to mail or deliver a statement to the obligor's last known address, computational errors, and any other error described in regulations of the Bureau. Subsection (c) prohibits the creditor from restricting or closing accounts solely due to nonpayment of disputed amounts, collecting on disputed amounts before compliance, or reporting the amount as delinquent during the resolution period, and requires the creditor to forfeit collection rights for the disputed amount (up to $50) where the creditor fails to comply with this section.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-truth-in-lending-act"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-15-usc-1681b-fcra-permissible-purposes-consumer-reports",
    "title": "US Fair Credit Reporting Act - 15 USC 1681b Permissible Purposes of Consumer Reports",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1681b titled 'Permissible purposes of consumer reports' is the FCRA gating provision that limits the circumstances under which a consumer reporting agency may furnish a consumer report. Subsection (a) enumerates the only permissible purposes: (a)(1) in response to a court order having jurisdiction to issue such an order, a subpoena issued in connection with proceedings before a Federal grand jury, or a subpoena issued in accordance with section 5318 of title 31 or section 3486 of title 18; (a)(2) in accordance with the written instructions of the consumer to whom it relates; (a)(3) to a person which the agency has reason to believe intends to use the information for credit transactions, employment purposes, insurance underwriting, governmental license or benefit determinations, credit-obligation assessment or other legitimate business need for the information in connection with a business transaction initiated by the consumer or to review an account to determine whether the consumer continues to meet the terms of the account; (a)(4) to State or local child support enforcement agencies meeting specified certifications; (a)(5) to an agency administering a State plan under section 654 of title 42 for use to set an initial or modified child support award; and (a)(6) to the FDIC or NCUA for use in connection with conservator, receiver, or liquidation duties. Any furnishing of a consumer report outside these enumerated purposes is impermissible under the FCRA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-credit-reporting-act-fcra-1970"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-15-usc-1681c-1-fcra-fraud-alerts-active-duty-alerts",
    "title": "US Fair Credit Reporting Act - 15 USC 1681c-1 Identity Theft Prevention; Fraud Alerts and Active Duty Alerts",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1681c-1 titled 'Identity theft prevention; fraud alerts and active duty alerts' is the FCRA provision that establishes consumer-initiated fraud alerts and active duty alerts on consumer files held by nationwide consumer reporting agencies. Subsection (a) governs initial fraud alerts: upon the direct request of a consumer who asserts a good faith suspicion of having been or about to become a victim of fraud or related crime, the agency shall include in the consumer's file a fraud alert for a period of not less than 1 year, beginning on the date of such request. Subsection (b) governs extended fraud alerts: upon receipt of an identity theft report from a consumer, the agency shall include in the consumer's file a fraud alert during the 7-year period beginning on the date of such request. Subsection (c) governs active duty alerts: upon the direct request of an active duty military consumer, the agency shall include in the consumer's file an active duty alert during a period of not less than 12 months, or such longer period as the Bureau shall determine, and exclude the consumer from prescreening lists for 2 years. Upon receiving a fraud alert request, the agency must (1) include the alert in the consumer's file and provide it with any credit score generated, (2) furnish the disclosures required under section 1681g within 3 business days at no charge, and (3) for extended alerts, exclude the consumer from prescreened credit or insurance lists for 5 years. The receiving agency must refer the fraud alert information to each of the other nationwide consumer reporting agencies in accordance with procedures established under section 1681s(f).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-credit-reporting-act-fcra-1970"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-15-usc-1681c-fcra-information-excluded-from-consumer-reports",
    "title": "US Fair Credit Reporting Act - 15 USC 1681c Requirements Relating to Information Contained in Consumer Reports (Obsolescence Periods)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1681c titled 'Requirements relating to information contained in consumer reports' is the FCRA provision that establishes the maximum reporting periods (obsolescence rules) for adverse information in consumer reports. Subsection (a) prohibits a consumer reporting agency from including in any consumer report: (1) cases under title 11 or under the Bankruptcy Act that, from the date of entry of the order for relief or the date of adjudication, as the case may be, antedate the report by more than 10 years; (2) civil suits, civil judgments, and records of arrest that antedate the report by more than 7 years or until the governing statute of limitations has expired, whichever is the longer period; (3) paid tax liens which, from date of payment, antedate the report by more than 7 years; (4) accounts placed for collection or charged to profit and loss which antedate the report by more than 7 years; (5) any other adverse item of information, other than records of convictions of crimes, which antedates the report by more than 7 years. Subsection (b) provides three exceptions that disable the 7-year and 10-year cutoffs: (1) credit transactions involving a principal amount of $150,000 or more; (2) underwriting of life insurance involving a face amount of $150,000 or more; (3) employment of any individual at an annual salary which equals, or which may reasonably be expected to equal, $75,000 or more. Subsection (c) provides that the 7-year period for delinquent accounts placed for collection or charged to profit and loss begins after the expiration of the 180-day period beginning on the date of the commencement of the delinquency which immediately preceded the collection activity or charge-off. Section 1681c is the foundational FCRA rule that bounds how long adverse credit, public record, and collection information may appear in a consumer report.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-credit-reporting-act-fcra-1970"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-15-usc-1681e-fcra-compliance-procedures-maximum-accuracy",
    "title": "US Fair Credit Reporting Act - 15 USC 1681e Compliance Procedures and Maximum Possible Accuracy",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1681e titled 'Compliance procedures' establishes two foundational FCRA duties on consumer reporting agencies. Subsection (a) requires every consumer reporting agency to maintain reasonable procedures designed to avoid violations of section 1681c of this title and to limit the furnishing of consumer reports to the purposes listed under section 1681b of this title; prospective users must identify themselves, certify their purposes for seeking the information, and certify that the information will be used for no other purpose, and the agency must make reasonable efforts to verify the identity of each new prospective user and the uses certified by the prospective user prior to furnishing such user any consumer report. Subsection (b) imposes the central accuracy duty: 'Whenever a consumer reporting agency prepares a consumer report it shall follow reasonable procedures to assure maximum possible accuracy of the information concerning the individual about whom the report relates.' Subsection (c) prohibits an agency from prohibiting a user of a consumer report from disclosing the contents of the report to the consumer if adverse action against the consumer has been taken by the user based in whole or in part on the report. Together these provisions are the operational backbone of FCRA compliance — they bind the agency to permissible-purpose enforcement, accuracy procedures, and consumer-disclosure transparency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-credit-reporting-act-fcra-1970"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-15-usc-1681g-fcra-disclosures-to-consumers",
    "title": "US Fair Credit Reporting Act - 15 USC 1681g Disclosures to Consumers (File Disclosure, Summary of Rights, Credit Score Disclosure)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1681g titled 'Disclosures to consumers' is the FCRA provision that requires consumer reporting agencies to disclose to the consumer the contents of the consumer's file, a summary of consumer rights, and credit score information upon request. Subsection (a) requires every consumer reporting agency, upon request and subject to verification of identity, to clearly and accurately disclose to the consumer: (1) all information in the consumer's file at the time of the request, with limited exceptions for Social Security number truncation and credit scores; (2) the sources of the information, with limited exceptions for investigative reports; (3) the identification of persons (and addresses) that procured a consumer report for employment purposes during the 2-year period preceding the request, and for any other purpose during the 1-year period preceding the request; (4) the dates, original payees, and amounts of any checks upon which is based any adverse characterization of the consumer; (5) a record of all inquiries received by the agency during the 1-year period preceding the request that identified the consumer in connection with a credit or insurance transaction not initiated by the consumer; and (6) a statement that the consumer may request and obtain a credit score. Subsection (c) requires the Bureau to prepare and disseminate a model summary of consumer rights. Subsection (e) governs the consumer's right to file information relating to an identity theft, with the agency required to provide records to victims not later than 30 days after the date of receipt of an appropriate request. Subsection (f) governs credit score disclosures, requiring the agency to provide upon request the current or most recent credit score, the range of possible scores under the model used, all of the key factors that adversely affected the credit score (limited to no more than 4 factors), the date the score was created, and the name of the person or entity that provided the score.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-credit-reporting-act-fcra-1970"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-15-usc-1681i-fcra-reinvestigation-disputed-information",
    "title": "US Fair Credit Reporting Act - 15 USC 1681i Procedure in Case of Disputed Accuracy",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1681i titled 'Procedure in case of disputed accuracy' governs the consumer reporting agency reinvestigation process when a consumer disputes the accuracy or completeness of any item of information in the consumer's file. Subsection (a)(1) requires the agency, free of charge, to conduct a reasonable reinvestigation to determine whether the disputed information is inaccurate and record the current status of the disputed information, or delete the item from the file in accordance with paragraph (5), before the end of the 30-day period beginning on the date on which the agency receives the notice of the dispute, subject to a 15-day extension when the agency receives information from the consumer during the period. Subsection (a)(2) requires the agency, before the expiration of the 5-business-day period beginning on the date on which a consumer reporting agency receives notice of a dispute from any consumer or a reseller in accordance with paragraph (1), to provide notification of the dispute to any person who provided any item of information in dispute. Subsection (a)(5) requires the agency, upon finding the information inaccurate, incomplete, or unverifiable, to promptly delete or modify the item and promptly notify the furnisher of the information that the information has been modified or deleted. If the reinvestigation does not resolve the dispute, the consumer may file a brief statement of not more than one hundred words setting forth the nature of the dispute. Subsection (f) imposes a 20-day correction deadline on resellers. Together these provisions define the FCRA dispute-handling timeline that consumer reporting agencies must operate to.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-credit-reporting-act-fcra-1970"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-15-usc-1681j-fcra-charges-for-certain-disclosures",
    "title": "US Fair Credit Reporting Act - 15 USC 1681j Charges for Certain Disclosures (Free Annual Report, Post-Adverse-Action Free Report)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1681j titled 'Charges for certain disclosures' is the FCRA provision that establishes the consumer's right to free consumer reports under specified conditions and caps the price a nationwide consumer reporting agency may charge for non-free disclosures. Subsection (a) requires every nationwide consumer reporting agency (and nationwide specialty consumer reporting agency described in section 1681a(w)) to provide free disclosures pursuant to section 1681g, without charge, once during any 12-month period upon request of the consumer. For nationwide specialty agencies, the Commission must establish regulations requiring a streamlined process for consumers to request consumer reports, including toll-free phone access, and the agency must deliver the report not later than 15 days after the date on which the request is received. Subsection (b) requires the agency to provide a free disclosure to the consumer when the consumer requests it and the request is made not later than 60 days after receipt by the consumer of a notification of adverse action under section 1681m or a similar debt collection agency notice. Subsection (c) requires a free disclosure where the consumer certifies they are unemployed and intend to apply for employment within the 60-day period beginning on the date of the certification, where the consumer is a recipient of public welfare assistance, or where the consumer has reason to believe their file contains inaccurate information due to fraud. Subsection (d) requires a free disclosure following a fraud alert request under section 1681c-1. Subsection (f) caps the maximum reasonable charge for non-free disclosures at the amount specified by the Bureau ($8 as last set under subsection (f)(1)(A)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-credit-reporting-act-fcra-1970"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-15-usc-1681m-fcra-requirements-on-users-adverse-action",
    "title": "US Fair Credit Reporting Act - 15 USC 1681m Requirements on Users of Consumer Reports and Adverse Action Notices",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1681m titled 'Requirements on users of consumer reports' imposes the FCRA notification duties on any person who takes adverse action with respect to a consumer that is based in whole or in part on any information contained in a consumer report. Subsection (a) requires the user to: (1) provide oral, written, or electronic notice of the adverse action to the consumer; (2) provide to the consumer orally, in writing, or electronically the name, address, and telephone number (toll-free for nationwide agencies) of the consumer reporting agency that furnished the report, and a statement that the consumer reporting agency did not make the decision to take the adverse action and is unable to provide the consumer the specific reasons why the adverse action was taken; and (3) provide notice of the consumer's right to obtain, under 15 USC 1681j, a free copy of the consumer report from the consumer reporting agency within 60 days of the adverse action and the right to dispute under 15 USC 1681i the accuracy or completeness of any information in the consumer report. Subsection (b) governs adverse action based on information obtained from a person other than a consumer reporting agency, requiring the user to disclose the nature of the information upon written consumer request received within 60 days after learning of the adverse action, with a separate 30-day window for affiliate-provided information. Subsection (h) requires risk-based-pricing notice when credit is granted on terms materially less favorable than the most favorable terms available to a substantial proportion of consumers from or through that person, including a numerical credit score used and information required by 15 USC 1681g(f)(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-credit-reporting-act-fcra-1970"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-15-usc-1681n-fcra-civil-liability-willful-noncompliance",
    "title": "US Fair Credit Reporting Act - 15 USC 1681n Civil Liability for Willful Noncompliance",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1681n titled 'Civil liability for willful noncompliance' is the FCRA provision that creates a private right of action against any person who willfully fails to comply with any requirement imposed by the FCRA with respect to any consumer. Subsection (a) entitles the consumer to recover: (1) any actual damages sustained by the consumer as a result of the failure, or damages of not less than $100 and not more than $1,000 (whichever is greater), in addition to (for any natural person who obtains a consumer report under false pretenses or knowingly without a permissible purpose) actual damages or $1,000, whichever is greater; (2) such amount of punitive damages as the court may allow; and (3) in the case of any successful action to enforce any liability under this section, the costs of the action together with reasonable attorney's fees as determined by the court. The statute distinguishes willful noncompliance from negligent noncompliance under section 1681o, which only entitles the consumer to actual damages and attorney's fees but not statutory damages or punitive damages. Subsection (d) establishes a narrow temporal exception for parties printing expiration dates on receipts between December 4, 2004, and June 3, 2008, who otherwise complied with card truncation requirements. The willful-noncompliance cause of action under 1681n is the principal enforcement teeth of the FCRA for consumers and is frequently litigated in class actions against consumer reporting agencies, furnishers, and users of consumer reports.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-credit-reporting-act-fcra-1970"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-15-usc-1681o-fcra-civil-liability-negligent-noncompliance",
    "title": "US Fair Credit Reporting Act - 15 USC 1681o Civil Liability for Negligent Noncompliance",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1681o titled 'Civil liability for negligent noncompliance' is the FCRA provision that creates a private right of action against any person who is negligent in failing to comply with any requirement imposed by the FCRA with respect to any consumer. Subsection (a) entitles the consumer to recover: (1) any actual damages sustained by the consumer as a result of the failure; and (2) in the case of any successful action to enforce any liability under this section, the costs of the action together with reasonable attorney's fees as determined by the court. Section 1681o is the negligence counterpart to 15 USC 1681n civil liability for willful noncompliance; unlike 1681n, the negligence cause of action does not entitle the consumer to statutory damages between $100 and $1,000 or to punitive damages, but it does allow recovery of actual damages plus attorney's fees. Negligence requires that the FCRA-regulated party failed to exercise the level of care that a reasonable party in the same position would have exercised. Section 1681o is most often pled in the alternative to 1681n in FCRA litigation, providing a fallback theory where willfulness cannot be established but a failure of reasonable procedures or duties can. Together, 1681n and 1681o constitute the consumer's principal enforcement remedy for FCRA violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-credit-reporting-act-fcra-1970"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-15-usc-1681s-2-fcra-furnisher-responsibilities",
    "title": "US Fair Credit Reporting Act - 15 USC 1681s-2 Responsibilities of Furnishers of Information to Consumer Reporting Agencies",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1681s-2 titled 'Responsibilities of furnishers of information to consumer reporting agencies' imposes the FCRA accuracy and dispute-handling duties on furnishers. Subsection (a)(1) prohibits a furnisher from furnishing any information relating to a consumer to a consumer reporting agency if the person knows or has reasonable cause to believe that the information is inaccurate; once a consumer has notified the furnisher of an inaccuracy, the furnisher may not continue furnishing the disputed information unless it provides notice that the information is disputed. Subsection (a)(2) imposes a duty to correct and update: a furnisher that regularly furnishes information must promptly notify the consumer reporting agency of any incomplete or inaccurate information and provide corrections to ensure the information is complete and accurate. Subsection (a)(5) requires furnishers to report a date of delinquency within 90 days of the date the account is reported as delinquent. Subsection (a)(7) requires financial institutions that extend credit and furnish negative information to a nationwide consumer reporting agency to give the consumer a clear and conspicuous written notice prior to, or no later than 30 days after, furnishing the negative information. Subsection (b) imposes the post-dispute duty: upon receiving a notice of dispute from a consumer reporting agency under 15 USC 1681i(a)(2), the furnisher must investigate the disputed information, review all relevant information provided, report the results of the investigation to the consumer reporting agency, and if the investigation finds the information incomplete or inaccurate, report those results to all nationwide consumer reporting agencies; the investigation must be completed within the period referenced in 1681i(a)(1) which is 30 days. Subsection (c) and (d) generally limit private rights of action for violations of subsection (a), with enforcement provided through Federal and State authorities under 15 USC 1681s.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-credit-reporting-act-fcra-1970"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-15-usc-1692e-fdcpa-false-misleading-representations-debt-collection",
    "title": "US Fair Debt Collection Practices Act - 15 USC 1692e False or Misleading Representations",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1692e is the Fair Debt Collection Practices Act provision that prohibits false, deceptive, or misleading representations or means by debt collectors in connection with the collection of any debt. The introductory clause provides: a debt collector may not use any false, deceptive, or misleading representation or means in connection with the collection of any debt. Without limiting the general application of the foregoing, the section enumerates sixteen specific prohibited practices: (1) the false representation or implication that the debt collector is vouched for, bonded by, or affiliated with the United States or any State, including the use of any badge, uniform, or facsimile thereof; (2) the false representation of the character, amount, or legal status of any debt or any services rendered or compensation lawfully receivable for any services; (3) the false representation or implication that any individual is an attorney or that any communication is from an attorney; (4) the representation or implication that nonpayment will result in arrest, imprisonment, or seizure, garnishment, attachment, or sale of property or wages unless lawful and intended; (5) the threat to take any action that cannot legally be taken or that is not intended to be taken; (6) the false representation or implication that a sale, referral, or other transfer of any interest in a debt shall cause the consumer to lose certain rights or be subject to specified practices; (7) the false representation or implication that the consumer committed any crime or other conduct in order to disgrace the consumer; (8) communicating or threatening to communicate to any person credit information which is known or which should be known to be false, including the failure to communicate that a disputed debt is disputed; (9) the use or distribution of any written communication which simulates or is falsely represented to be a document authorized, issued, or approved by any court, official, or agency of the United States or any State, or which creates a false impression as to its source, authorization, or approval; (10) the use of any false representation or deceptive means to collect or attempt to collect any debt or to obtain information concerning a consumer; (11) the failure to disclose in the initial written communication and the initial oral communication that the debt collector is attempting to collect a debt and that any information obtained will be used for that purpose, and the failure to disclose in subsequent communications that the communication is from a debt collector; (12) the false representation or implication that accounts have been turned over to innocent purchasers for value; (13) the false representation or implication that documents are legal process; (14) the use of any business, company, or organization name other than the true name of the debt collector's business, company, or organization; (15) the false representation or implication that documents are not legal process forms or do not require action by the consumer; and (16) the false representation or implication that a debt collector operates or is employed by a consumer reporting agency as defined by section 1681a(f) of this title.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-15-usc-45-ftc-act-unfair-deceptive-practices"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-15-usc-1692g-fdcpa-validation-of-debts",
    "title": "US Fair Debt Collection Practices Act - 15 USC 1692g Validation of Debts",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1692g is the Fair Debt Collection Practices Act provision that requires debt collectors to provide consumers with written validation of debts and to honor the consumer's right to dispute the debt. Subsection (a) provides that within five days after the initial communication with a consumer in connection with the collection of any debt, a debt collector shall, unless the following information is contained in the initial communication or the consumer has paid the debt, send the consumer a written notice containing: (1) the amount of the debt; (2) the name of the creditor to whom the debt is owed; (3) a statement that unless the consumer, within thirty days after receipt of the notice, disputes the validity of the debt, or any portion thereof, the debt will be assumed to be valid by the debt collector; (4) a statement that if the consumer notifies the debt collector in writing within the thirty-day period that the debt, or any portion thereof, is disputed, the debt collector will obtain verification of the debt or a copy of a judgment against the consumer and a copy of such verification or judgment will be mailed to the consumer by the debt collector; and (5) a statement that, upon the consumer's written request within the thirty-day period, the debt collector will provide the consumer with the name and address of the original creditor, if different from the current creditor. Subsection (b) provides that if the consumer notifies the debt collector in writing within the thirty-day period that the debt is disputed, or that the consumer requests the name and address of the original creditor, the debt collector shall cease collection of the debt, or any disputed portion thereof, until the debt collector obtains verification of the debt or a copy of a judgment, or the name and address of the original creditor, and mails a copy of such verification or judgment, or name and address of the original creditor, to the consumer. Subsection (c) provides that the failure of a consumer to dispute the validity of a debt under this section may not be construed by any court as an admission of liability by the consumer. Subsection (d) provides that a communication in the form of a formal pleading in a civil action shall not be treated as an initial communication for purposes of subsection (a). Subsection (e) provides that the sending or delivery of any form or notice which does not relate to the collection of a debt and is expressly required by the Internal Revenue Code of 1986, title V of the Gramm-Leach-Bliley Act, or any provision of federal or state law relating to notice of data security breach or privacy, or any regulation prescribed under any such provision of law, shall not be treated as an initial communication in connection with debt collection for purposes of this section.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-15-usc-1692e-fdcpa-false-misleading-representations-debt-collection"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-15-usc-1693e-efta-preauthorized-transfers-stop-payment",
    "title": "US Electronic Fund Transfer Act - 15 USC 1693e Preauthorized Transfers and Stop-Payment Rights",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1693e titled 'Preauthorized transfers' is the Electronic Fund Transfer Act (EFTA) provision that governs recurring electronic debits from a consumer's account and the consumer's stop-payment right. Subsection (a) provides that 'a preauthorized electronic fund transfer from a consumer's account may be authorized by the consumer only in writing, and a copy of such authorization shall be provided to the consumer when made.' The statute further provides that a consumer may stop payment of a preauthorized electronic fund transfer 'by notifying the financial institution orally or in writing at any time up to three business days preceding the scheduled date of such transfer.' The financial institution may require the consumer to give written confirmation of an oral stop-payment notification within fourteen days of the oral notification, provided that the consumer is notified of this requirement and the address where the confirmation must be sent when the consumer gives the oral notification. The provisions are operationalised in 12 CFR Part 1005 (Regulation E), particularly §1005.10 which governs preauthorized transfers and §1005.10(c) which implements the stop-payment right. Section 1693e is central to consumer protection in subscription billing, recurring debits, and any merchant-driven electronic debit pattern, and provides the statutory backstop for the consumer's right to control recurring authorizations on the consumer's deposit account.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-electronic-fund-transfer-act"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-15-usc-1693f-efta-error-resolution-procedures",
    "title": "US Electronic Fund Transfer Act - 15 USC 1693f Error Resolution",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1693f titled 'Error resolution' is the Electronic Fund Transfer Act (EFTA) provision that governs how financial institutions must investigate and resolve consumer error notices on electronic fund transfer accounts. The consumer must notify the financial institution within sixty days after having transmitted to the consumer documentation pursuant to section 1693d(a), (c), or (d) on which the alleged error is shown. The financial institution must investigate the alleged error and report or mail the results of such investigation and determination to the consumer within ten business days. The institution may invoke an extended forty-five-day investigation period if it provisionally recredits the consumer's account for the amount alleged to be in error within ten business days of receiving the proper error notice, giving the consumer full use of the funds during the investigation. The statute identifies categories of 'error' including unauthorized electronic fund transfers, incorrect electronic fund transfers, omission from the periodic statement of an electronic fund transfer required to be reflected, computational errors, the consumer's receipt of an incorrect amount of money from an electronic terminal, requests for additional information or clarification concerning an electronic fund transfer, and any other error described in regulations of the Bureau. Subsection (e) provides treble-damages liability where the financial institution failed to provisionally recredit within the ten-business-day window AND either conducted no good faith investigation or lacked reasonable basis for its conclusion, OR knowingly and willfully concluded that no error had been made when the institution knew or should reasonably have known that an error had been made. The provisions are operationalised in 12 CFR Part 1005 (Regulation E).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-electronic-fund-transfer-act"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-15-usc-1693g-efta-consumer-liability-unauthorized-electronic-fund-transfers",
    "title": "US Electronic Fund Transfer Act - 15 USC 1693g Consumer Liability for Unauthorized Electronic Fund Transfers",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 1693g titled 'Consumer liability' is the Electronic Fund Transfer Act (EFTA) provision that caps consumer liability for unauthorized electronic fund transfers and allocates the burden of proof to the financial institution. Subsection (a) provides that a consumer is liable for unauthorized electronic fund transfers involving the consumer's account only if the card or other means of access used was an 'accepted card or other means of access' and the issuer has provided 'a means whereby the user of such card or other means of access can be identified as the person authorized to use it, such as by signature, photograph, or fingerprint or by electronic or mechanical confirmation.' Where these conditions are met, the consumer's liability is capped at the lesser of $50 or the amount of money or value of property or services obtained in the unauthorized transfer prior to the time the financial institution is notified. Where the consumer fails to report any loss or theft of a card or other means of access within two business days after the consumer learns of the loss or theft, the cap rises to a total of $500. Where the consumer fails to report within sixty days of transmittal of the statement any unauthorized electronic fund transfer or account error which appears on the periodic statement, the consumer becomes liable for amounts after the 60-day window without the cap. Subsection (b) places the burden of proof on the financial institution to show that the electronic fund transfer was authorized or, if unauthorized, that the conditions of liability and any limiting circumstances have been met. Together these provisions define the EFTA consumer-protection backstop against unauthorized debits, ATM/PIN fraud, and unauthorized P2P transfers and underpin Regulation E at 12 CFR Part 1005.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-electronic-fund-transfer-act"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-15-usc-45-ftc-act-unfair-deceptive-practices",
    "title": "US Federal Trade Commission Act - 15 USC 45 Unfair Methods of Competition and Unfair or Deceptive Acts or Practices",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 45 (FTC Act section 5) is the foundational federal consumer protection and competition statute administered by the Federal Trade Commission. Subsection (a)(1) declares that unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful. Subsection (a)(2) empowers and directs the Commission to prevent persons, partnerships, or corporations (other than banks, savings and loan institutions, federal credit unions, common carriers subject to the Acts to regulate commerce, air carriers and foreign air carriers subject to part A of subtitle VII of title 49, and persons, partnerships, or corporations insofar as they are subject to the Packers and Stockyards Act, 1921, as amended) from using unfair methods of competition in or affecting commerce and unfair or deceptive acts or practices in or affecting commerce. Subsection (b) governs Commission complaint and order procedures: the FTC may issue and serve a complaint, hold a hearing on not less than thirty days notice, and issue a cease and desist order after finding a method of competition or act or practice is prohibited. Subsection (c) provides court review by the United States court of appeals within 60 days of order service. Subsection (l) provides civil penalties of not more than $10,000 for each violation of a final cease and desist order, and subsection (m) provides civil penalties for knowing violations of FTC rules defining unfair or deceptive acts or practices. Subsection (n) (added by the FTC Act Amendments of 1994) provides the unfairness standard: the Commission shall have no authority to declare unlawful an act or practice on the grounds that such act or practice is unfair unless the act or practice causes or is likely to cause substantial injury to consumers which is not reasonably avoidable by consumers themselves and not outweighed by countervailing benefits to consumers or to competition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-15-usc-1681b-fcra-permissible-purposes-consumer-reports"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-15-usc-7211-sarbanes-oxley-pcaob-establishment",
    "title": "15 USC § 7211 - Sarbanes-Oxley Act PCAOB Establishment",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "15 USC § 7211 (Sarbanes-Oxley Act of 2002, Pub. L. 107-204, Title I § 101) establishes the Public Company Accounting Oversight Board (PCAOB) to oversee the audit of companies subject to the federal securities laws and related matters: subsection (a) establishes the Board as a body corporate operating as a nonprofit corporation with perpetual existence until dissolved by Congress; subsection (b) clarifies that the Board is not an agency or establishment of the United States Government - it functions as a nonprofit entity under District of Columbia law with Board members and employees not considered federal officers or agents; subsection (e) sets membership requirements - 5 members appointed by SEC after consultation with Federal Reserve Board and Treasury, selected for integrity, reputation, and demonstrated commitment to investor interests and understanding of financial disclosure obligations; only 2 members may be certified public accountants; if chairperson is CPA, must not have practiced as CPA for at least 5 years before appointment; members serve full-time exclusively and cannot hold other employment; Section 7211 establishes the foundational governance framework for PCAOB regulation of public company auditors including registration, standards-setting, inspections, investigations, and disciplinary proceedings; PCAOB authority confirmed in Free Enterprise Fund v. PCAOB 561 US 477 (2010) following constitutional restructuring of removal authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "sox_pcaob_related_provisions",
        "pcaob_auditing_standards",
        "free_enterprise_fund_constitutional_decision",
        "industry_mapping",
        "enforcement_anchors",
        "sox_section_404_internal_controls_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355",
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-47-usc-230-cda-section-230-platform-immunity"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-15-usc-77q-securities-act-fraudulent-interstate-transactions",
    "title": "US Securities Act of 1933 - 15 USC 77q Fraudulent Interstate Transactions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 77q is the Securities Act of 1933 section 17 antifraud provision applicable to the offer or sale of securities. It complements 15 USC 78j (Exchange Act section 10) by reaching offers as well as sales, and applies to all securities offerings (registered and unregistered) using interstate commerce or the mails. Subsection (a) provides that it shall be unlawful for any person in the offer or sale of any securities (including security-based swaps) or any security-based swap agreement by the use of any means or instruments of transportation or communication in interstate commerce or by use of the mails, directly or indirectly: (1) to employ any device, scheme, or artifice to defraud, or (2) to obtain money or property by means of any untrue statement of a material fact or any omission to state a material fact necessary in order to make the statements made, in light of the circumstances under which they were made, not misleading, or (3) to engage in any transaction, practice, or course of business which operates or would operate as a fraud or deceit upon the purchaser. Subsection (b) provides that it shall be unlawful for any person, by the use of any means or instruments of transportation or communication in interstate commerce or by the use of the mails, to publish, give publicity to, or circulate any notice, circular, advertisement, newspaper, article, letter, investment service, or communication which, though not purporting to offer a security for sale, describes such security for a consideration received or to be received, directly or indirectly, from an issuer, underwriter, or dealer, without fully disclosing the receipt, whether past or prospective, of such consideration and the amount thereof. Subsection (c) provides that the exemptions provided in section 77c of this title shall not apply to the provisions of this section. Subsection (d) addresses Commission authority over security-based swap agreements subject to the restrictions and limitations of related statutory provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-15-usc-78j-exchange-act-manipulative-deceptive-devices"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-15-usc-78j-exchange-act-manipulative-deceptive-devices",
    "title": "US Securities Exchange Act of 1934 - 15 USC 78j Manipulative and Deceptive Devices",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "15 USC 78j is the Securities Exchange Act of 1934 section 10 prohibition on manipulative and deceptive devices in connection with the purchase or sale of securities. It is the statutory basis for SEC Rule 10b-5, the most heavily-litigated antifraud rule in US securities law. Subsection (a)(1) makes it unlawful for any person, directly or indirectly, by the use of any means or instrumentality of interstate commerce or of the mails, or of any facility of any national securities exchange, to effect a short sale, or to use or employ any stop-loss order in connection with the purchase or sale, of any security other than a government security, in contravention of such rules and regulations as the Commission may prescribe as necessary or appropriate in the public interest or for the protection of investors. Paragraph (a)(2) provides that paragraph (1) shall not apply to security futures products. Subsection (b) makes it unlawful for any person, directly or indirectly, by the use of any means or instrumentality of interstate commerce or of the mails, or of any facility of any national securities exchange, to use or employ, in connection with the purchase or sale of any security registered on a national securities exchange or any security not so registered, or any securities-based swap agreement, any manipulative or deceptive device or contrivance in contravention of such rules and regulations as the Commission may prescribe as necessary or appropriate in the public interest or for the protection of investors. Section 10(b) is enforced through SEC civil enforcement, parallel DOJ criminal prosecution for willful violations, and private rights of action under the implied 10b-5 cause of action recognised by the Supreme Court in cases including J.I. Case Co. v. Borak, Superintendent of Insurance v. Bankers Life, Blue Chip Stamps v. Manor Drug Stores, and the elements of a 10b-5 claim are codified in Dura Pharmaceuticals v. Broudo and Stoneridge v. Scientific-Atlanta.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-17-cfr-240-10b5-1-trading-on-the-basis-of-material-nonpublic-information"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-15-usc-80b-6-investment-advisers-act-fraud",
    "title": "15 U.S.C. 80b-6 - Prohibited Transactions by Investment Advisers (Section 206)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "15 U.S.C. 80b-6 (Section 206 of the Investment Advisers Act of 1940) makes it unlawful for any investment adviser, by use of the mails or any means of interstate commerce, directly or indirectly, to employ any device, scheme or artifice to defraud any client or prospective client (paragraph (1)); to engage in any transaction, practice or course of business which operates as a fraud or deceit upon any client or prospective client (paragraph (2)); acting as principal for its own account, knowingly to sell any security to or purchase any security from a client, or acting as broker for a person other than the client, knowingly to effect a sale or purchase for the client, without disclosing in writing the capacity in which it is acting and obtaining the client's consent before completion of the transaction (paragraph (3)); or to engage in any act, practice or course of business which is fraudulent, deceptive or manipulative, as defined by SEC rules (paragraph (4)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-17-cfr-part-275-investment-advisers-act-rules",
      "us-sec-rule-10b-5-anti-fraud",
      "sarbanes-oxley-act-sox"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-16-cfr-part-313-ftc-privacy-consumer-financial-info",
    "title": "US 16 CFR Part 313: Privacy of Consumer Financial Information (FTC GLBA Privacy Rule)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 16 CFR Part 313 implements the privacy provisions of the Gramm-Leach-Bliley Act (GLBA) Title V Subtitle A for financial institutions subject to FTC jurisdiction (e.g., mortgage brokers, payday lenders, tax preparers, debt collectors, non-bank lenders). Covered institutions must provide an initial privacy notice to consumers and customers, deliver annual privacy notices to customers (subject to exceptions for institutions that do not share NPI outside specified exceptions), provide opt-out notice and right before sharing non-public personal information (NPI) with non-affiliated third parties, and reuse and redisclosure limitations on NPI received from other financial institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "glba",
        "cfr_16_314",
        "cfpb_reg_p",
        "state_laws",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-16-cfr-part-314-ftc-safeguards-rule",
    "title": "US 16 CFR Part 314: Standards for Safeguarding Customer Information (FTC Safeguards Rule)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 16 CFR Part 314 (the FTC Safeguards Rule) implements Section 501(b) of the Gramm-Leach-Bliley Act (GLBA) by requiring covered financial institutions under FTC jurisdiction to develop, implement, and maintain a comprehensive written information security program with administrative, technical, and physical safeguards. The 2021 amendments (effective June 9 2023) introduced specific requirements: designate a Qualified Individual to oversee the program, conduct risk assessments, implement access controls, conduct multi-factor authentication, encrypt customer information in transit and at rest, train personnel, oversee service providers, develop incident response plan, and provide annual reports to the board. Notification to FTC required within 30 days of security event affecting 500+ consumers (effective May 13 2024).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "glba",
        "cfr_16_313",
        "nist_csf",
        "state_laws",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-16-cfr-part-433-ftc-holder-rule",
    "title": "US 16 CFR Part 433: Preservation of Consumers Claims and Defenses (FTC Holder Rule)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 16 CFR Part 433 (the FTC Holder Rule) requires consumer credit contracts to include the Holder Notice preserving consumer claims and defenses against subsequent assignees and holders of the credit obligation. The Notice (15-point or larger bold type) effectively abrogates the holder-in-due-course doctrine for consumer credit transactions by allowing consumers to assert against the holder any claim or defense the consumer could assert against the seller. The Rule applies to sellers of consumer goods or services who arrange or accept consumer credit; violation is an unfair or deceptive practice under FTC Act Section 5. Recovery is limited to amounts paid under the contract. The FTC 2019 advisory opinion clarified that consumers may seek affirmative recovery up to amounts paid.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ftc_act",
        "udap_state",
        "cfr_16_429",
        "cfr_12_1026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-17-cfr-23-402-cftc-swap-dealer-business-conduct-general",
    "title": "US 17 CFR 23.402 (CFTC): General Provisions - Business Conduct Standards for Swap Dealers and Major Swap Participants",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Section 23.402 sets the general provisions governing the business conduct of swap dealers and major swap participants under the CFTC's Subpart H. Swap entities must adopt written policies and procedures reasonably designed to ensure compliance with the subpart and to prevent evasion of the Commodity Exchange Act, implement know-your-counterparty procedures to obtain and retain essential facts about each counterparty, and keep a record of each counterparty's true name and address. The section permits reasonable reliance on a counterparty's written representations, flexible manner and format of disclosure, and prescribes record-retention obligations tied to subpart F and CFTC rule 1.31.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cftc-cfr-17-part-23-swap-dealers",
      "us-dodd-frank-act-2010",
      "us-dodd-frank-title-vii-otc-derivatives-2010"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-17-cfr-230-144-resale-of-restricted-and-control-securities",
    "title": "US SEC - 17 CFR 230.144 Persons Deemed Not to be Engaged in a Distribution (Rule 144 Resale of Restricted and Control Securities)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "17 CFR 230.144 titled 'Persons deemed not to be engaged in a distribution and therefore not underwriters' is the principal SEC safe harbor under section 4(a)(1) of the Securities Act of 1933 permitting public resale of restricted and control securities without registration if specified conditions are met. Paragraph (b) establishes the safe-harbor framework: a person who satisfies all applicable conditions in paragraphs (c) through (h) is deemed not to be engaged in a distribution and therefore not an underwriter for purposes of section 2(a)(11) of the Act. Paragraph (c) requires current public information about the issuer (for reporting issuers, the issuer must have been subject to the reporting requirements of section 13 or 15(d) for at least 90 days prior with all required filings current; for non-reporting issuers, the public information requirements of Rule 15c2-11 or specified SEC insurance disclosure requirements apply). Paragraph (d) imposes the holding period: 6 months for restricted securities of reporting issuers, 12 months for restricted securities of non-reporting issuers, with the clock starting when the full purchase price or other consideration is paid. Paragraph (e) imposes volume limitations on affiliate sales: in any three-month period, the amount sold may not exceed the greater of 1 percent of the outstanding shares of the class or the average weekly trading volume during the four calendar weeks preceding the filing of the notice on Form 144. Paragraph (f) requires that affiliate sales occur in brokers' transactions, directly with market makers, or in riskless principal transactions. Paragraph (h) requires affiliates to file Form 144 with the SEC at the time of placing the sell order with the broker (concurrent with) whenever sales exceed 5,000 shares or $50,000 in aggregate sales price in any three-month period. Non-affiliates after holding restricted securities for the required period and meeting the current-public-information requirement may resell freely without the volume, manner-of-sale, or notice conditions; after one year, non-affiliates may resell freely without any of the conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-17-cfr-part-230-sec-securities-act-rules"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-17-cfr-230-501-regulation-d-accredited-investor-definitions",
    "title": "US SEC - 17 CFR 230.501 Regulation D Rule 501 Definitions and Terms Used in Regulation D (Including Accredited Investor)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "17 CFR 230.501 titled 'Definitions and terms used in Regulation D' is the SEC rule defining the term 'accredited investor' (along with other key terms used in the Regulation D private placement safe harbors at 17 CFR 230.504 and 230.506). Paragraph (a) lists the categories of natural persons and entities that qualify as accredited investors: (1) banks, savings and loan associations, broker-dealers registered with the SEC, insurance companies, investment companies registered under the Investment Company Act, Business Development Companies, Small Business Investment Companies, Rural Business Investment Companies, plans established by states for the benefit of state employees, and employee benefit plans within the meaning of ERISA with $5 million in assets or where investment decisions are made by a plan fiduciary; (2) private business development companies as defined in section 202(a)(22) of the Investment Advisers Act; (3) organizations described in section 501(c)(3), corporations, Massachusetts or similar business trusts, partnerships, or limited liability companies, not formed for the specific purpose of acquiring the securities offered, with total assets in excess of $5,000,000; (4) directors, executive officers, or general partners of the issuer; (5) natural persons whose individual net worth (or joint net worth with that person's spouse or spousal equivalent) exceeds $1,000,000, excluding the value of the primary residence; (6) natural persons with individual income exceeding $200,000 in each of the two most recent years (or joint income with a spouse or spousal equivalent exceeding $300,000 in each of those years) with a reasonable expectation of reaching the same income level in the current year; (7) trusts with total assets in excess of $5,000,000 not formed for the specific purpose of acquiring the offered securities and directed by a sophisticated person; (8) entities in which all of the equity owners are accredited investors; (9) entities with investments in excess of $5,000,000 not formed for the specific purpose of acquiring the offered securities; (10) natural persons holding in good standing SEC-designated professional certifications and other credentials; (11) knowledgeable employees of a private fund; (12) family offices with at least $5,000,000 in assets under management and family clients of such family offices; and (13) certain other categories as designated by the Commission. The accredited investor definition is the central qualification for participation in Rule 506(b) and 506(c) private placements without registration under the Securities Act of 1933.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-17-cfr-part-230-sec-securities-act-rules"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-17-cfr-230-506-regulation-d-private-placement-safe-harbors",
    "title": "US SEC - 17 CFR 230.506 Regulation D Rule 506 Exemption for Limited Offers and Sales Without Regard to Dollar Amount of Offering",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "17 CFR 230.506 titled 'Exemption for limited offers and sales without regard to dollar amount of offering' is the central Regulation D private-placement safe harbor under section 4(a)(2) of the Securities Act of 1933. Paragraph (b) (Rule 506(b)) permits an unlimited dollar amount offering to an unlimited number of accredited investors plus no more than 35 non-accredited purchasers (or reasonable belief thereof) provided each non-accredited purchaser either alone or together with a purchaser representative has such knowledge and experience in financial and business matters that he is capable of evaluating the merits and risks of the prospective investment, general solicitation and general advertising are prohibited, and the issuer satisfies specified information delivery requirements to non-accredited investors. Paragraph (c) (Rule 506(c)) permits general solicitation and general advertising provided all purchasers are accredited investors (or reasonable belief thereof) and the issuer takes reasonable steps to verify that purchasers are accredited investors using the non-exclusive verification methods specified (tax documentation plus written representations, net worth documentation plus consumer reports, written confirmation from a broker-dealer, registered investment adviser, attorney, or CPA, or prior verification within five years with updated representations). Paragraph (d) (Rule 506(d) 'bad actor' disqualification) makes the Rule 506 exemption unavailable where the issuer or specified covered persons have been the subject of certain disqualifying events including criminal convictions for securities-related felonies or misdemeanors within ten years (five for issuers), court orders restricting securities activities, final regulatory orders barring securities business, SEC suspension or revocation orders, FINRA suspension or expulsion, and false representation orders, with limited exceptions for events before September 23, 2013, SEC good-cause waivers, and the issuer's reasonable lack of knowledge after factual inquiry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-17-cfr-part-230-sec-securities-act-rules"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-17-cfr-240-10b5-1-trading-on-the-basis-of-material-nonpublic-information",
    "title": "US SEC - 17 CFR 240.10b5-1 Trading on the Basis of Material Nonpublic Information in Insider Trading Cases",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "17 CFR 240.10b5-1 titled 'Trading on the basis of material nonpublic information in insider trading cases' is the SEC rule that defines when a purchase or sale of a security constitutes trading on the basis of material nonpublic information for purposes of Rule 10b-5 under the Exchange Act, and provides the affirmative defense framework for preplanned trading arrangements. Paragraph (a) provides that the manipulative and deceptive devices prohibited by section 10(b) of the Act and Rule 10b-5 thereunder include the purchase or sale of a security of any issuer, on the basis of material nonpublic information about that security or issuer, in breach of a duty of trust or confidence that is owed directly, indirectly, or derivatively, to the issuer of that security or the shareholders of that issuer, or to any other person who is the source of the material nonpublic information. Paragraph (b) provides the awareness standard: a purchase or sale of a security of an issuer is 'on the basis of' material nonpublic information about that security or issuer only if the person making the purchase or sale was aware of the material nonpublic information when the person made the purchase or sale. Paragraph (c)(1) provides the affirmative defenses for individuals who can demonstrate that, before becoming aware of the material nonpublic information, they entered into a binding contract, gave instructions, or adopted a written plan, that specified the amount, price, and date of the trade, that did not permit later influence over how/when/whether to effect purchases or sales, and that the purchase or sale was executed as originally specified. The 2022 amendments imposed cooling-off periods: 90 days for officers and directors (or two business days following disclosure of financial results, whichever is later, with a 120-day cap), and 30 days for persons other than the issuer. Paragraph (c)(2) provides a separate affirmative defense for entities that can show the individual making the trading decision was not aware of the material nonpublic information and the entity had implemented reasonable policies and procedures to ensure non-awareness.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-17-cfr-part-240-sec-exchange-act-rules"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-17-cfr-240-13d-1-filing-schedules-13d-and-13g-beneficial-ownership",
    "title": "US SEC - 17 CFR 240.13d-1 Filing of Schedules 13D and 13G for Beneficial Ownership Reporting",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "17 CFR 240.13d-1 titled 'Filing of Schedules 13D and 13G' is the SEC beneficial-ownership reporting rule under section 13(d) of the Exchange Act. Paragraph (a) provides that any person who, after acquiring directly or indirectly the beneficial ownership of any equity security of a class which is specified in paragraph (i) of this section, is directly or indirectly the beneficial owner of more than 5 percent of the class shall, within five business days after the acquisition, file with the Commission a statement containing the information required by Schedule 13D. Paragraph (b) provides eligibility for the abbreviated Schedule 13G filing by qualified institutional investors (broker-dealers, banks, insurance companies, registered investment companies, registered investment advisers, employee benefit plans, certain other institutional entities) who acquired the securities in the ordinary course of business and not with the purpose nor with the effect of changing or influencing the control of the issuer. Paragraph (c) provides eligibility for Schedule 13G by passive investors who do not qualify under paragraph (b), do not hold the securities with the purpose or effect of changing or influencing control, and hold less than 20 percent of the class. Paragraph (d) provides for quarterly amendments to Schedule 13G within 45 days after the end of the calendar quarter where beneficial ownership exceeds 5 percent. Paragraph (e) requires immediate switch from Schedule 13G to Schedule 13D within 5 business days upon acquiring securities with a purpose or effect of changing or influencing control of the issuer.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-17-cfr-part-240-sec-exchange-act-rules"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-17-cfr-240-13e-3-going-private-transactions",
    "title": "US SEC - 17 CFR 240.13e-3 Going Private Transactions by Certain Issuers or their Affiliates",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "17 CFR 240.13e-3 titled 'Going private transactions by certain issuers or their affiliates' is the SEC anti-fraud and disclosure rule governing 'Rule 13e-3 transactions' under section 13(e) of the Exchange Act. Paragraph (a) defines a 'Rule 13e-3 transaction' as a transaction that has either a reasonable likelihood or a purpose of producing one of two effects: (i) causing a class of equity securities of an issuer that is subject to section 12(g) or 15(d) of the Exchange Act to be held of record by fewer than 300 persons; or (ii) causing a class of equity securities of an issuer that is either listed on a national securities exchange or authorized to be quoted in an inter-dealer quotation system of any registered national securities association to be neither listed nor authorized to be quoted. Paragraph (b) prohibits any issuer or affiliate engaging in a Rule 13e-3 transaction from employing any device, scheme, or artifice to defraud; making any untrue statement of a material fact or omitting to state a material fact necessary in order to make the statements made, in light of the circumstances under which they were made, not misleading; or engaging in any act, practice, or course of business which operates or would operate as a fraud or deceit upon any person. Paragraph (c) requires the filing of Schedule 13E-3 (with all exhibits and amendments) reporting the transaction and material changes. Paragraph (d) requires that the disclosure must be disseminated to security holders at least 20 days prior to any solicitation, recommendation, or shareholder vote regarding the transaction, with company-paid forwarding of materials to beneficial owners. The rule is the principal SEC vehicle for protecting unaffiliated shareholders in management buy-outs and other affiliate-driven transactions designed to take a public company private.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-17-cfr-part-240-sec-exchange-act-rules"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-17-cfr-240-14a-9-false-or-misleading-statements-proxy-solicitation",
    "title": "US SEC - 17 CFR 240.14a-9 False or Misleading Statements in Proxy Solicitation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "17 CFR 240.14a-9 titled 'False or misleading statements' is the SEC anti-fraud rule under section 14(a) of the Exchange Act that prohibits material misstatements and omissions in proxy solicitations of registered companies. Paragraph (a) provides that no solicitation subject to this regulation shall be made by means of any proxy statement, form of proxy, notice of meeting or other communication, written or oral, containing any statement which, at the time and in the light of the circumstances under which it is made, is false or misleading with respect to any material fact, or which omits to state any material fact necessary in order to make the statements therein not false or misleading or necessary to correct any statement in any earlier communication with respect to the solicitation of a proxy for the same meeting or subject matter which has become false or misleading. Paragraph (b) provides examples of statements which, depending on particular facts and circumstances, may be misleading within the meaning of this rule, including predictions as to specific future market values; material which directly or indirectly impugns character, integrity, or personal reputation, or directly or indirectly makes charges concerning improper, illegal, or immoral conduct or associations, without factual foundation; failure so to identify a proxy statement, form of proxy, or other soliciting material as to clearly distinguish it from the soliciting material of any other person or persons soliciting for the same meeting or subject matter; and claims made prior to a meeting regarding the results of a solicitation. Paragraph (a) also explicitly states that the fact that a proxy statement, form of proxy, or other soliciting material has been filed with or examined by the Commission shall not be deemed a finding by the Commission that such material is accurate or complete or not false or misleading.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-17-cfr-part-240-sec-exchange-act-rules"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-17-cfr-240-15c3-3-customer-protection-rule",
    "title": "US 17 CFR 240.15c3-3 (SEC Exchange Act Rule 15c3-3): Customer Protection - Reserves and Custody of Securities",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "SEC Rule 15c3-3, the Customer Protection Rule, requires a registered broker or dealer to promptly obtain and thereafter maintain physical possession or control of all fully-paid and excess margin securities carried for customers, and to maintain a Special Reserve Bank Account holding cash or qualified securities computed under the reserve formula so that customer funds are not used to finance the firm's proprietary business. The rule defines key terms such as customer, fully paid securities, excess margin securities (market value exceeding 140 percent of the customer's debit balances), and qualified security, and limits permissible uses of customer securities. Temporary possession-or-control lags are excused only where solely the result of normal business operations and cured by timely good-faith steps.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sec-17-cfr-240-securities-exchange-act-rules",
      "us-securities-exchange-act-1934",
      "us-sipa-securities-investor-protection-act-15-usc-ch2b-1"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-17-cfr-240-16a-3-section-16-reporting-transactions-holdings",
    "title": "US SEC - 17 CFR 240.16a-3 Section 16 Reporting of Transactions and Holdings (Forms 3, 4, 5)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "17 CFR 240.16a-3 titled 'Reporting transactions and holdings' is the SEC rule implementing section 16(a) of the Exchange Act by specifying the Forms 3, 4, and 5 filing requirements for officers, directors, and 10 percent beneficial owners of public companies. Paragraph (a) requires initial statements of beneficial ownership of equity securities under section 16(a) to be filed on Form 3. Paragraph (g) requires Form 4 to be filed by the end of the second business day following the day on which a subject transaction has been executed (the post-Sarbanes-Oxley two-business-day rule). Paragraph (f) requires Form 5 to be filed by every person who at any time during the issuer's fiscal year was subject to section 16, within 45 days after the issuer's fiscal year end, disclosing holdings and transactions not previously reported on Forms 3, 4, or 5. The rule applies to every officer, director, and beneficial owner of more than 10 percent of any class of equity security registered under section 12 of the Exchange Act, and is the principal vehicle for public reporting of insider transactions in public-company securities. Section 16(b) of the Exchange Act provides the short-swing profit disgorgement remedy for any profits realized from a purchase and sale (or sale and purchase) of the issuer's equity securities within any period of less than six months.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-17-cfr-part-240-sec-exchange-act-rules"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-17-cfr-240-17a-4-broker-dealer-records-preservation",
    "title": "US SEC - 17 CFR 240.17a-4 Records to be Preserved by Certain Exchange Members, Brokers and Dealers",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "17 CFR 240.17a-4 titled 'Records to be preserved by certain exchange members, brokers and dealers' is the SEC books-and-records preservation rule under section 17 of the Exchange Act, defining retention periods, accessibility, and electronic storage requirements for broker-dealer records. Paragraph (a) requires preservation for 6 years (with the first 2 years in an easily accessible place) of records described in 17 CFR 240.17a-3(a)(1)-(3), (5), (21), and (22) covering core trade, order, and customer-account records. Paragraph (b) requires preservation for 3 years (with the first 2 years in an easily accessible place) of most operational records, including communications, financial statements, account agreements, and trial balances. Paragraph (e) requires certain compliance records, employee records, and customer account information to be kept easily accessible at all times during the periods specified. Paragraph (f) governs electronic storage media: systems must include complete audit trails, automatic verification of recorded data, backup redundancy, and the capacity to readily download and transfer copies in both human-readable and reasonably usable electronic formats; broker-dealers may use either non-erasable, non-rewriteable storage (WORM) or, since the 2022 amendment, an audit-trail-based system that preserves originals and tracks modifications. Paragraph (j) requires that records be furnished promptly to a Commission representative in legible, complete form, and electronic records in a reasonably usable electronic format upon request. Section 240.17a-4 is the principal SEC records-preservation rule for the broker-dealer industry and is the source of the long-running 'SEC WORM' requirement for electronic books-and-records systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-17-cfr-part-240-sec-exchange-act-rules"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-17-cfr-242-203-regulation-sho-locate-and-close-out",
    "title": "US SEC - 17 CFR 242.203 Regulation SHO Borrowing and Delivery Requirements (Locate and Close-Out)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "17 CFR 242.203 titled 'Borrowing and delivery requirements' is the Regulation SHO rule that imposes locate and close-out obligations on broker-dealers in connection with short sales and certain long-sale fails-to-deliver in equity securities. Paragraph (a) addresses long sales: broker-dealers may not lend or arrange to lend a security marked as long-sale, and may not fail to deliver a security on a long sale, except in good-faith mistake scenarios or specified inter-broker arrangements. Paragraph (b) imposes the core short-sale rules: before accepting any short sale order in any equity security from any other person, or effecting any short sale in an equity security for its own account, the broker-dealer must either (i) borrow the security, (ii) enter into a bona-fide arrangement to borrow the security, or (iii) have reasonable grounds to believe that the security can be borrowed so that it can be delivered on the date delivery is due (the 'locate' requirement); and document compliance with the locate requirement. Paragraph (b)(3) imposes the close-out requirement for threshold securities: where a participant of a registered clearing agency has a fail-to-deliver position in a threshold security for 13 consecutive settlement days, the participant and any broker-dealer for which it clears transactions must immediately close out the fail-to-deliver position by purchasing or borrowing securities of like kind and quantity; further, until the position is closed out, the participant and the broker-dealer may not accept any short sale order in the threshold security from another person, or effect any short sale in the threshold security for its own account, without first borrowing the security or entering into a bona-fide arrangement to borrow the security. Paragraph (c) defines 'threshold security' as an equity security for which there is an aggregate fail-to-deliver position at a registered clearing agency of at least 10,000 shares (and which is equal to at least 0.5 percent of the issuer's total shares outstanding) for five consecutive settlement days, and which is included on a list published by a self-regulatory organization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-17-cfr-part-240-sec-exchange-act-rules"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-17-cfr-275-206-4-7-adviser-compliance-program-rule",
    "title": "US 17 CFR 275.206(4)-7 (Investment Advisers Act Rule 206(4)-7): Compliance Procedures and Practices",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Rule 206(4)-7 under the Investment Advisers Act of 1940 makes it unlawful, within the meaning of section 206, for a registered investment adviser to provide investment advice to clients unless it adopts and implements written policies and procedures reasonably designed to prevent violation of the Act and its rules, reviews their adequacy and the effectiveness of their implementation no less frequently than annually, and designates a chief compliance officer who is a supervised person to administer those policies and procedures. The rule is the foundation of the adviser compliance-program regime enforced by the SEC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sec-17-cfr-275-investment-advisers-act-rules",
      "us-investment-advisers-act-1940",
      "us-dodd-frank-act-2010"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-17-cfr-part-230-sec-securities-act-rules",
    "title": "US 17 CFR Part 230: General Rules and Regulations, Securities Act of 1933",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 17 CFR Part 230 contains the SEC rules under the Securities Act of 1933 governing offers and sales of securities. The Securities Act requires that every offer or sale of a security be registered with the SEC on Form S-1 (or S-3 for seasoned issuers) unless an exemption applies. Part 230 sets out the exemptions including Regulation D Rule 506(b) private placement, Rule 506(c) general solicitation to accredited investors, Rule 504 small offerings up to $10M, Regulation A tiered offerings up to $75M, Regulation S offshore offerings, Rule 144 resale safe harbor for restricted securities, and Rule 144A resale to qualified institutional buyers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "securities_act",
        "cfr_17_239",
        "cfr_17_240",
        "jobs_act",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-17-cfr-part-240-sec-exchange-act-rules",
    "title": "US 17 CFR Part 240: General Rules and Regulations, Securities Exchange Act of 1934",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 17 CFR Part 240 contains the rules adopted by the SEC under the Securities Exchange Act of 1934 covering registration of securities and exchanges, periodic reporting (Forms 10-K, 10-Q, 8-K), tender offers, proxy solicitations, insider trading prohibitions (Rules 10b-5, 14e-3, 16b), broker-dealer registration and conduct, clearing agencies, transfer agents, security-based swaps, and credit rating agencies. Part 240 is the operational rulebook for US public companies, registered broker-dealers, and other regulated market participants. Violations of Rule 10b-5 (antifraud) carry both civil and criminal liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "sea_1934",
        "cfr_17_229",
        "cfr_17_210",
        "sox_act",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-17-cfr-part-270-investment-company-act-rules",
    "title": "US 17 CFR Part 270: Rules and Regulations, Investment Company Act of 1940",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 17 CFR Part 270 contains the SEC rules under the Investment Company Act of 1940 governing registered investment companies including open-end funds (mutual funds), closed-end funds, and exchange-traded funds (ETFs). The rules address affiliated transactions, asset segregation, board composition, custody of fund assets, disclosure, fair valuation, fund pricing forward pricing, leverage and derivatives use, money market fund operations, names rule, redemption and liquidity risk management, and shareholder approval requirements. Key rules include Rule 12d1 (fund-of-funds), Rule 18f-4 (derivatives), Rule 22e-4 (liquidity risk management), Rule 2a-7 (money market funds), Rule 30e-3 (electronic delivery), and Rule 35d-1 (names rule).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ica_1940",
        "cfr_17_274",
        "cfr_17_275",
        "finra_rules",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-17-cfr-part-275-investment-advisers-act-rules",
    "title": "US 17 CFR Part 275: Rules and Regulations, Investment Advisers Act of 1940",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 17 CFR Part 275 contains the SEC rules under the Investment Advisers Act of 1940 governing investment advisers registered with the SEC (over $110M assets under management or required by state law to register with SEC). Key rules include Rule 204-2 (recordkeeping), Rule 204A-1 (code of ethics), Rule 206(4)-1 (marketing rule), Rule 206(4)-7 (compliance program rule), Rule 206(4)-2 (custody rule), Rule 206(4)-5 (pay-to-play rule), and Rule 204-3 (brochure rule). Advisers owe fiduciary duty to clients including duty of care and duty of loyalty.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "advisers_act",
        "cfr_17_279",
        "cfr_17_270",
        "dol_fiduciary",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-17-usc-1201-dmca-anti-circumvention-of-copyright-protection-systems",
    "title": "17 U.S.C. § 1201 - DMCA Anti-Circumvention of Copyright Protection Systems",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2025-01-01",
    "bluf": "No person may circumvent a technological measure that effectively controls access to a work protected under the Copyright Act, and no person may manufacture, import, offer to the public, provide, or otherwise traffic in any technology primarily designed or produced for the purpose of circumventing access controls under § 1201(a)(2) or rights controls under § 1201(b)(1), subject to the preservation of fair use and other copyright defences in § 1201(c)(1), the statutory exemptions in § 1201(d) through (j) - library, archives, and educational institution evaluation, law enforcement and intelligence activity, reverse engineering for interoperability, good-faith encryption research, and security testing - and the triennial rulemaking exemptions issued by the Librarian of Congress under § 1201(a)(1)(C) for classes of works whose users are adversely affected by the access-control prohibition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dmca-section-512-safe-harbor-1998",
      "us-dmca-1201-anti-circumvention-triennial-review"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-18-cfr-part-35-ferc-filing-rate-schedules-tariffs",
    "title": "US 18 CFR Part 35: Filing of Rate Schedules and Tariffs (FERC)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 18 CFR Part 35 implements Sections 205 and 206 of the Federal Power Act (FPA) governing rate schedules and tariffs filed with FERC by public utilities engaged in interstate transmission or wholesale of electric energy. Part 35 covers Sec 205 filings (60-day prior notice; rates effective unless suspended); cost of service rate filings; market-based rate authority; Independent System Operator (ISO) and Regional Transmission Organization (RTO) Open Access Transmission Tariffs (OATT); Order 1000 transmission planning and cost allocation; ancillary services; and complaints under FPA Section 206. Recent reforms include Order 2222 (DER participation in wholesale markets), Order 2023 (interconnection process reform), and Order 1920 (transmission planning and cost allocation).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fpa",
        "cfr_18_153",
        "cfr_18_388",
        "epact_2005",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1001-false-statements-federal-officers",
    "title": "US Federal Criminal Code - 18 USC 1001 Statements or Entries Generally (False Statements to Federal Officers)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1001 is the federal false-statements statute, one of the most heavily-charged federal offenses, reaching false statements made to federal investigators, federal regulators, federal benefit programs, and federal contracting officers. Subsection (a) provides that whoever, in any matter within the jurisdiction of the executive, legislative, or judicial branch of the Government of the United States, knowingly and willfully: (1) falsifies, conceals, or covers up by any trick, scheme, or device a material fact; (2) makes any materially false, fictitious, or fraudulent statement or representation; or (3) makes or uses any false writing or document knowing the same to contain any materially false, fictitious, or fraudulent statement or entry; shall be fined under this title, imprisoned not more than 5 years or, if the offense involves international or domestic terrorism (as defined in section 2331), imprisoned not more than 8 years, or both. If the matter relates to an offense under chapter 109A (sexual abuse), 109B (sex offender registration), 110 (sexual exploitation and other abuse of children), or 117 (transportation for illegal sexual activity), or section 1591 (sex trafficking), then the term of imprisonment imposed under this section shall be not more than 8 years. Subsection (b) provides the judicial proceeding exception: subsection (a) does not apply to a party to a judicial proceeding, or that party's counsel, for statements, representations, writings or documents submitted by such party or counsel to a judge or magistrate in that proceeding. Subsection (c) limits the legislative branch reach: with respect to any matter within the jurisdiction of the legislative branch, subsection (a) shall apply only to (1) administrative matters, including a claim for payment, a matter related to the procurement of property or services, personnel or employment practices, or support services, or a document required by law, rule, or regulation to be submitted to Congress or any office or officer within the legislative branch, or (2) any investigation or review, conducted pursuant to the authority of any committee, subcommittee, commission or office of the Congress, consistent with applicable rules of the House or Senate. Section 1001 is the workhorse of federal investigations because any false statement made to a federal officer about a material fact in a matter within federal jurisdiction can be charged, even outside any formal proceeding.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1623-false-declarations-grand-jury-court"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "us-18-usc-1005-bank-entries-reports-transactions",
    "title": "18 U.S.C. 1005 - Bank Entries, Reports and Transactions (False Entries)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "18 U.S.C. 1005 criminalises, by an officer, director, agent or employee of a covered bank, the unauthorized issuance or circulation of notes; making, drawing or issuing certificates of deposit, drafts, bills of exchange or similar instruments without authority; making any false entry in a book, report or statement with intent to injure or defraud; and participating in or receiving money or benefits through bank transactions with intent to defraud the United States, an agency, or a financial institution. The penalty is a fine up to $1,000,000 or imprisonment up to 30 years, or both.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1344-bank-fraud",
      "us-18-usc-1956-money-laundering-monetary-instruments",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-18-usc-1006-federal-credit-institution-entries",
    "title": "18 U.S.C. 1006 - Federal Credit Institution Entries, Reports and Transactions",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "18 U.S.C. 1006 criminalises, by an officer, agent or employee of, or person connected in any capacity with, specified federal credit institutions (including the FDIC, NCUA, Federal home loan banks, the Federal Housing Finance Agency, the Farm Credit Administration, HUD and the Federal Crop Insurance Corporation), making false entries in any book, report or statement with intent to defraud the institution or any other entity or individual, drawing orders or issuing obligations without authority, and participating in or receiving money, profit or property through any transaction of the institution with intent to defraud. The penalty is a fine up to $1,000,000 or imprisonment up to 30 years, or both.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1005-bank-entries-reports-transactions",
      "us-18-usc-657-insurance-credit-institution-embezzlement",
      "us-18-usc-1344-bank-fraud"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-18-usc-1014-false-statements-loan-credit-applications",
    "title": "US Title 18 - 18 USC 1014 Loan and Credit Applications Generally; Renewals and Discounts; Crop Insurance (False Statements)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1014 titled 'Loan and credit applications generally; renewals and discounts; crop insurance' is the principal federal criminal statute prohibiting false statements made to influence the action of named federal financial institutions. The statute criminalizes anyone who knowingly makes any false statement or report, or willfully overvalues any land, property or security, for the purpose of influencing in any way the action of an enumerated federal financial institution. The protected institutions listed in the statute include the Federal Housing Administration; the Farm Credit Administration; the Federal Crop Insurance Corporation; various farm credit entities including Federal land banks, Federal land bank associations, Federal Reserve banks, small business investment companies, agricultural credit corporations; credit unions; FDIC-insured institutions; Federal home loan banks; the Federal Housing Finance Agency; foreign bank branches; and mortgage lending businesses involved in federally related mortgage loans. The protected conduct includes loan and credit applications, renewals, discounts, and crop insurance applications, advances, repurchase agreements, commitments, applications for letters of credit, conversions, modifications, releases, deferments, and applications for the federal financial institution to charge or release a security. Violators face a fine of not more than $1,000,000 or imprisonment for not more than 30 years, or both. Section 1014 is the federal criminal counterpart to bank fraud under 18 USC 1344 and is frequently charged alongside the bank fraud and mail/wire fraud statutes in federal lending fraud prosecutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-31-cfr-1010-aml"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-18-usc-1028-fraud-identification-documents-authentication-features",
    "title": "US Title 18 - 18 USC 1028 Fraud and Related Activity in Connection with Identification Documents, Authentication Features, and Information",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1028 titled 'Fraud and related activity in connection with identification documents, authentication features, and information' is the principal federal criminal statute addressing identification document fraud, false identification production, and unlawful use of another person's means of identification. Subsection (a) enumerates 8 prohibited acts that constitute the offense when done knowingly and without lawful authority: (1) producing an identification document, authentication feature, or false identification document; (2) transferring such documents or features knowing they were stolen or produced without lawful authority; (3) possessing 5 or more identification documents (other than those issued lawfully for the use of the possessor), authentication features, or false identification documents, with intent to use or transfer them unlawfully; (4) possessing an identification document or authentication feature (or a false identification document) with intent that it be used to defraud the United States; (5) producing, transferring, or possessing a document-making implement or authentication feature with intent that it be used in producing a false identification document or another document-making implement or authentication feature that will be used in producing a false identification document; (6) possessing an identification document or authentication feature that is or appears to be an identification document or authentication feature of the United States or a sponsor of a special event of national significance, that is stolen or produced without lawful authority, knowing such status; (7) knowingly transferring, possessing, or using, without lawful authority, a means of identification of another person with intent to commit any unlawful activity that constitutes a violation of Federal law, or that constitutes a felony under any applicable State or local law; and (8) trafficking in false or actual authentication features for use in false identification documents, document-making implements, or means of identification. Subsection (b) sets the penalty tiers: 5 years for general offenses; 15 years for federal/state identification document production, transfer of 5+ documents, document-making implements, or identity theft with $1,000+ value; 20 years where the offense is committed to facilitate drug trafficking, a crime of violence, or repeats; and 30 years where the offense is committed to facilitate domestic or international terrorism. Subsection (d) provides core definitions including 'identification document' (issued by US Government, states, foreign governments, or international organizations intended or commonly accepted for identification) and 'means of identification' (any name or number that may be used to identify a specific individual, including names, Social Security numbers, driver's license numbers, and biometric data).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-computer-fraud-abuse-act-1986"
    ],
    "primary_citations_count": 14
  },
  {
    "node_id": "us-18-usc-1028a-aggravated-identity-theft",
    "title": "US Title 18 - 18 USC 1028A Aggravated Identity Theft",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1028A titled 'Aggravated identity theft' is the federal criminal provision imposing a mandatory consecutive sentence on defendants who use another person's means of identification during and in relation to enumerated felonies. Subsection (a)(1) provides the general offense: whoever, during and in relation to any felony violation enumerated in subsection (c), knowingly transfers, possesses, or uses, without lawful authority, a means of identification of another person shall, in addition to the punishment provided for such felony, be sentenced to a term of imprisonment of 2 years. Subsection (a)(2) provides the terrorism-related variant: whoever, during and in relation to any felony violation enumerated in 18 USC 2332b(g)(5)(B), knowingly transfers, possesses, or uses, without lawful authority, a means of identification of another person or a false identification document, shall, in addition to the punishment provided for such felony, be sentenced to a term of imprisonment of 5 years. Subsection (b) provides the consecutive sentence rules: (1) the court shall not, in any way, reduce the term to be imposed for the underlying felony so as to compensate for, or otherwise take into account, any separate term of imprisonment imposed under this section; (2) no term of imprisonment imposed on a person under this section shall run concurrently with any other term of imprisonment imposed on the person under any other provision of law, including any term of imprisonment imposed for the felony during which the means of identification was transferred, possessed, or used; (3) the court may, in its discretion, impose concurrent terms with respect to other 1028A counts as appropriate per Sentencing Commission guidelines; (4) no person convicted of a violation of this subsection shall be eligible for any term of probation. Subsection (c) enumerates the qualifying felonies including theft of public money, bank embezzlement, theft from employee benefit plans, false personation, firearm acquisition by fraud, fraud and false statements, mail/bank/wire fraud, immigration violations, Social Security Act offenses, and certain terrorism-related offenses.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-computer-fraud-abuse-act-1986"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-1029-fraud-access-devices",
    "title": "US Title 18 - 18 USC 1029 Fraud and Related Activity in Connection with Access Devices",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1029 titled 'Fraud and related activity in connection with access devices' is the principal federal criminal statute addressing payment card fraud, unauthorized access device trafficking, and device-making implement offenses. Subsection (a) enumerates 10 prohibited acts that constitute the offense when done knowingly and with intent to defraud: (1) producing, using, or trafficking in one or more counterfeit access devices; (2) trafficking in or using one or more unauthorized access devices during any one-year period, and by such conduct obtaining anything of value aggregating $1,000 or more during that period; (3) possessing fifteen or more devices which are counterfeit or unauthorized access devices; (4) producing, trafficking in, or having control or custody of, or possessing device-making equipment; (5) effecting transactions, with one or more access devices issued to another person, to receive payment or any other thing of value aggregating $1,000 or more during a one-year period; (6) soliciting a person for the purpose of offering an access device or selling information regarding or an application to obtain an access device, without the authorization of the issuer of the access device; (7) using, producing, trafficking in, having control or custody of, or possessing a telecommunications instrument that has been modified or altered to obtain unauthorized use of telecommunications services; (8) using, producing, trafficking in, having control or custody of, or possessing a scanning receiver; (9) using, producing, trafficking in, having control or custody of, or possessing hardware or software, knowing it has been configured to insert or modify telecommunication identifying information associated with or contained in a telecommunications instrument so that such instrument may be used to obtain telecommunications service without authorization; (10) knowingly and with intent to defraud causing or arranging for another person to present to the member or its agent, for payment, one or more evidences or records of transactions made by an access device. Subsection (c) sets the penalty tiers: 10 years for general offenses; 15 years for the device-making equipment and other aggravated subparagraphs; 20 years for repeat offenders; plus forfeiture of property used or intended to be used in the offense. Subsection (e) defines 'access device' as any card, plate, code, account number, electronic serial number, mobile identification number, personal identification number, or other telecommunications service, equipment, or instrument identifier, or other means of account access that can be used to obtain money, goods, services, or any other thing of value, or that can be used to initiate a transfer of funds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-computer-fraud-abuse-act-1986"
    ],
    "primary_citations_count": 14
  },
  {
    "node_id": "us-18-usc-1031-major-fraud-against-united-states",
    "title": "US Title 18 - 18 USC 1031 Major Fraud Against the United States",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1031 titled 'Major fraud against the United States' is the federal criminal statute targeting large-scale fraud in federal procurement, contracts, grants, loans, and similar federal economic relationships. Subsection (a) provides that whoever knowingly executes, or attempts to execute, any scheme or artifice with the intent (1) to defraud the United States; or (2) to obtain money or property by means of false or fraudulent pretenses, representations, or promises, in any procurement of property or services as a prime contractor with the United States or as a subcontractor or supplier on a contract in which there is a prime contract with the United States, if the value of the contract, subcontract, or any constituent part thereof, for such property or services is $1,000,000 or more, shall be fined not more than $1,000,000, or imprisoned not more than 10 years, or both. The threshold $1,000,000 contract or subcontract value is the jurisdictional gating element distinguishing 1031 from the general fraud statutes. Subsection (c) caps the maximum fine the court may impose on a defendant for a violation of this section at $10,000,000 per prosecution. Subsection (d) provides the court may alternatively impose a fine equal to twice the gross loss or gross gain involved in the offense, notwithstanding the per-prosecution cap. Section 1031 is the principal federal vehicle for major federal procurement fraud cases (DOJ Procurement Collusion Strike Force matters, defense contracting fraud, federal grant fraud) and is frequently charged alongside the False Claims Act (31 USC 3729 et seq.), mail and wire fraud (18 USC 1341 and 1343), and conspiracy under 18 USC 371 or 1349.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-mail-fraud-18-usc-1341"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-1032-concealment-of-assets-from-receiver",
    "title": "18 U.S.C. 1032 - Concealment of Assets from Conservator, Receiver or Liquidating Agent",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "18 U.S.C. 1032 criminalises knowingly concealing or endeavouring to conceal an asset or property from the FDIC, NCUA Board or a conservator, receiver or liquidating agent of a financial institution, corruptly impeding or endeavouring to impede the functions of such a conservator, receiver or liquidating agent, and corruptly placing or endeavouring to place an asset or property beyond their reach. The penalty is a fine, imprisonment up to 5 years, or both.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-657-insurance-credit-institution-embezzlement",
      "us-18-usc-656-bank-officer-embezzlement",
      "us-18-usc-1005-bank-entries-reports-transactions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-18-usc-1033-insurance-fraud-interstate-commerce",
    "title": "18 U.S.C. 1033 - Crimes by or Affecting Persons Engaged in the Business of Insurance",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "18 U.S.C. 1033 criminalises conduct by persons engaged in the business of insurance whose activities affect interstate commerce: false material statements to insurance regulators (subsection (a)), willful embezzlement of insurer moneys, funds, premiums or credits (subsection (b)), false entries of material fact with intent to deceive regulators about financial condition (subsection (c)), threats or force to obstruct insurance regulatory proceedings (subsection (d)), and engaging in the business of insurance after a felony conviction involving dishonesty or breach of trust without written regulatory consent (subsection (e)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-mccarran-ferguson-act-15-usc-ch20",
      "us-18-usc-1956-money-laundering-monetary-instruments",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-18-usc-1035-false-statements-health-care-matters",
    "title": "18 U.S.C. 1035 - False Statements Relating to Health Care Matters",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "18 U.S.C. 1035 makes it an offence to knowingly and willfully, in any matter involving a health care benefit program, falsify, conceal or cover up by any trick, scheme or device a material fact (subsection (a)(1)), or make any materially false, fictitious or fraudulent statement or representation, or make or use any materially false writing or document knowing it contains a materially false, fictitious or fraudulent statement or entry (subsection (a)(2)), in connection with the delivery of or payment for health care benefits, items or services. The penalty is a fine, imprisonment up to 5 years, or both. The term health care benefit program is defined by reference to section 24(b) of title 18 (subsection (b)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1347-health-care-fraud",
      "us-18-usc-1001-false-statements-federal-officers",
      "us-18-usc-1956-money-laundering-monetary-instruments"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-18-usc-1037-fraud-related-activity-electronic-mail-can-spam-criminal",
    "title": "US Title 18 - 18 USC 1037 Fraud and Related Activity in Connection with Electronic Mail (CAN-SPAM Criminal Provisions)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1037 titled 'Fraud and related activity in connection with electronic mail' is the criminal provision of the CAN-SPAM Act of 2003 that criminalizes high-volume deceptive commercial email conduct. Subsection (a) enumerates 5 prohibited acts: (1) accessing a protected computer without authorization and intentionally initiating the transmission of multiple commercial electronic mail messages from or through such computer; (2) using a protected computer to relay or retransmit multiple commercial electronic mail messages with the intent to deceive or mislead recipients, or any Internet access service, as to the origin of such messages; (3) materially falsifying header information in multiple commercial electronic mail messages and intentionally initiating the transmission of such messages; (4) registering, using information that materially falsifies the identity of the actual registrant, for five or more electronic mail accounts or online user accounts or two or more domain names, and intentionally initiating the transmission of multiple commercial electronic mail messages from any combination of such accounts or domain names; and (5) falsely representing oneself to be the registrant or the legitimate successor in interest to the registrant of 5 or more Internet Protocol addresses, and intentionally initiating the transmission of multiple commercial electronic mail messages from such addresses. Subsection (b) provides tiered penalties: up to 5 years imprisonment for offenses committed in furtherance of any felony under the laws of the United States or of any State, or where the defendant has been previously convicted under this section or section 1030 of this title; up to 3 years for certain volume or financial-loss tiers; and up to 1 year fine or imprisonment in any other case. Subsection (d) provides key definitions: 'multiple' means more than 100 electronic mail messages during a 24-hour period, more than 1,000 electronic mail messages during a 30-day period, or more than 10,000 electronic mail messages during a 1-year period; 'materially' means information altered in a manner that would impair the ability of a recipient or Internet access service or law enforcement to identify, locate, or respond to a person.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-can-spam-act-2003-implementation"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-1084-wire-act-gambling",
    "title": "18 USC § 1084 - Wire Act (Transmission of Wagering Information)",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "18 USC § 1084 (Federal Wire Act, originally enacted September 13, 1961 as the Interstate Wire Act of 1961, Pub. L. 87-216) criminalizes the use of wire communication facilities for transmission of bets, wagers, or information assisting in placing bets in interstate or foreign commerce: subsection (a) provides 'Whoever being engaged in the business of betting or wagering knowingly uses a wire communication facility for the transmission in interstate or foreign commerce of bets or wagers or information assisting in the placing of bets or wagers on any sporting event or contest, or for the transmission of a wire communication which entitles the recipient to receive money or credit as a result of bets or wagers, or for information assisting in the placing of bets or wagers, shall be fined under this title or imprisoned not more than two years, or both'; subsection (b) creates an exception for news reporting of sporting events and contests, and for transmissions between jurisdictions where wagering is lawfully permitted; subsection (c) preserves state criminal prosecution authority; the 2018 DOJ Opinion (and subsequent litigation in NH Lottery Commission v. Rosen 986 F.3d 38 (1st Cir. 2021)) interpreted the Act's 'sporting event or contest' scope, with continuing litigation about non-sports gambling coverage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "uigea_parallel_framework",
        "interstate_horseracing_act_exemption",
        "leading_case_law",
        "industry_mapping",
        "enforcement_anchors",
        "news_reporting_exception_section_1084_b"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-31-usc-5363-uigea-unlawful-internet-gambling",
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355",
      "us-41-usc-3301-full-open-competition-federal-procurement"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1341-mail-fraud",
    "title": "US Federal Criminal Code - 18 USC 1341 Frauds and Swindles (Mail Fraud)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1341 is the federal mail fraud statute, one of the broadest federal criminal statutes by reach and one of the most heavily-charged federal offenses. The statute provides: whoever, having devised or intending to devise any scheme or artifice to defraud, or for obtaining money or property by means of false or fraudulent pretenses, representations, or promises, or to sell, dispose of, loan, exchange, alter, give away, distribute, supply, or furnish or procure for unlawful use any counterfeit or spurious coin, obligation, security, or other article, or anything represented to be or intimated or held out to be such counterfeit or spurious article, for the purpose of executing such scheme or artifice or attempting so to do, places in any post office or authorized depository for mail matter, any matter or thing whatever to be sent or delivered by the Postal Service, or deposits or causes to be deposited any matter or thing whatever to be sent or delivered by any private or commercial interstate carrier, or takes or receives therefrom, any such matter or thing, or knowingly causes to be delivered by mail or such carrier according to the direction thereon, or at the place at which it is directed to be delivered by the person to whom it is addressed, any such matter or thing, shall be fined under this title or imprisoned not more than 20 years, or both. The statute then provides an enhanced penalty: if the violation occurs in relation to, or involving any benefit authorized, transported, transmitted, transferred, disbursed, or paid in connection with, a presidentially declared major disaster or emergency (as those terms are defined in section 102 of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 USC 5122)), or affects a financial institution, such person shall be fined not more than $1,000,000 or imprisoned not more than 30 years, or both. Section 1341 requires proof of: (1) a scheme to defraud or to obtain money or property by means of false or fraudulent pretenses, representations, or promises; (2) the defendant's knowing and willful participation with intent to defraud; and (3) use of the mails or a private interstate carrier in furtherance of the scheme. The intangible right of honest services (18 USC 1346) was construed in Skilling v. United States, 561 US 358 (2010), to be limited to bribery and kickback schemes. Section 1341 is frequently charged in white-collar prosecutions and is the historical predecessor of wire fraud (18 USC 1343).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1343-wire-fraud"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-18-usc-1343-wire-fraud",
    "title": "US Federal Criminal Code - 18 USC 1343 Fraud by Wire, Radio, or Television (Wire Fraud)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1343 is the federal wire fraud statute, enacted in 1952 as the electronic analogue of 18 USC 1341 (mail fraud), and is now one of the most heavily-charged federal offenses, reaching virtually any fraud scheme that uses electronic communications (telephone, email, internet, fax, wire transfer, text message) crossing state or international lines. The statute provides: whoever, having devised or intending to devise any scheme or artifice to defraud, or for obtaining money or property by means of false or fraudulent pretenses, representations, or promises, transmits or causes to be transmitted by means of wire, radio, or television communication in interstate or foreign commerce, any writings, signs, signals, pictures, or sounds for the purpose of executing such scheme or artifice, shall be fined under this title or imprisoned not more than 20 years, or both. The statute then provides the same enhanced penalty as 18 USC 1341: if the violation occurs in relation to, or involving any benefit authorized, transported, transmitted, transferred, disbursed, or paid in connection with, a presidentially declared major disaster or emergency (as those terms are defined in section 102 of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 USC 5122)), or affects a financial institution, such person shall be fined not more than $1,000,000 or imprisoned not more than 30 years, or both. Section 1343 requires proof of: (1) a scheme to defraud or to obtain money or property by means of false or fraudulent pretenses, representations, or promises; (2) the defendant's knowing and willful participation with intent to defraud; and (3) use of interstate or foreign wire, radio, or television communications in furtherance of the scheme. The honest services theory under 18 USC 1346 is, since Skilling v. United States, 561 US 358 (2010), limited to bribery and kickback schemes. Section 1343 is the workhorse statute for online fraud, business email compromise, romance scams, securities fraud, healthcare fraud, and any fraud that uses telephones, email, or internet across state lines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1344-bank-fraud"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-18-usc-1344-bank-fraud",
    "title": "US Title 18 - 18 USC 1344 Bank Fraud",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1344 titled 'Bank fraud' is the federal criminal statute that prohibits schemes or artifices to defraud financial institutions or to obtain by false or fraudulent pretenses any moneys or property under the custody or control of a financial institution. The statute provides that whoever knowingly executes, or attempts to execute, a scheme or artifice (1) to defraud a financial institution; or (2) to obtain any of the moneys, funds, credits, assets, securities, or other property owned by, or under the custody or control of, a financial institution, by means of false or fraudulent pretenses, representations, or promises, shall be fined not more than $1,000,000 or imprisoned not more than 30 years, or both. The two prongs of section 1344 are charged together or separately depending on whether the prosecution emphasises a scheme to defraud the institution itself or a scheme to obtain the institution's property via false pretenses. 'Financial institution' is defined elsewhere in the United States Code (18 USC 20) and includes Federal Reserve banks, FDIC-insured depository institutions, federally chartered or insured credit unions, branches and agencies of foreign banks, and the National Credit Union Administration. Section 1344 is a foundational federal fraud statute charged across check-kiting cases, mortgage fraud cases, ATM and debit card schemes, identity-theft enabled account takeovers, and embezzlement-style insider fraud. It is frequently charged alongside 18 USC 1014 (false statements to financial institutions), 18 USC 1341 (mail fraud), 18 USC 1343 (wire fraud), 18 USC 1349 (attempt and conspiracy), and 18 USC 1956 / 1957 (money laundering).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-31-cfr-1010-aml"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-1345-injunctions-against-fraud",
    "title": "18 U.S.C. 1345 - Injunctions Against Fraud",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "18 U.S.C. 1345 authorises the Attorney General to commence a civil action to enjoin a person who is violating or about to violate the banking, health care, mail or wire fraud provisions of chapter 63 or sections 287, 371 or 1001 (subsection (a)(1)), and to obtain restraining orders preventing the alienation or disposition of property obtained from a banking law violation or Federal health care offense, including freezing property and appointing a temporary receiver (subsection (a)(2)). The court proceeds expeditiously and may grant a temporary or permanent injunction or restraining order without bond (subsection (b)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1344-bank-fraud",
      "us-18-usc-1347-health-care-fraud",
      "us-18-usc-1005-bank-entries-reports-transactions"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-18-usc-1346-honest-services-fraud",
    "title": "18 U.S.C. 1346 - Honest Services Fraud (Definition of Scheme or Artifice to Defraud)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "Title 18 United States Code Section 1346 provides in full: for the purposes of this chapter, the term scheme or artifice to defraud includes a scheme or artifice to deprive another of the intangible right of honest services. Added by Public Law 100-690, title VII, Section 7603(a), on November 18, 1988 (102 Stat. 4508), the section operates as a definitional expansion of chapter 63 of title 18, meaning it extends the mail fraud statute (18 U.S.C. 1341) and the wire fraud statute (18 U.S.C. 1343) to schemes that deprive victims of the intangible right of honest services rather than money or property. In Skilling v. United States, 561 U.S. 358 (2010), the Supreme Court of the United States confined honest-services fraud under Section 1346 to schemes involving bribes or kickbacks, rejecting broader theories such as undisclosed self-dealing standing alone as unconstitutionally vague. Honest-services prosecutions therefore target bribery and kickback schemes involving employees against employers, fiduciaries against principals, and public officials against citizens, executed through use of the mails or interstate wires. Organizations manage honest-services exposure through anti-bribery and anti-kickback controls, conflict-of-interest disclosure regimes, gift and gratuity policies, third-party intermediary diligence, and escalation and investigation procedures, coordinated with adjacent regimes including the mail and wire fraud statutes, the federal programs bribery statute and the Foreign Corrupt Practices Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "chapter_63_definitional_role",
        "skilling_limitation",
        "public_and_private_sector_reach",
        "adjacent_federal_bribery_regimes",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1341-mail-fraud",
      "us-18-usc-1343-wire-fraud",
      "us-18-usc-1345-injunctions-against-fraud"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-18-usc-1347-health-care-fraud",
    "title": "US Title 18 - 18 USC 1347 Health Care Fraud",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1347 titled 'Health care fraud' is the federal criminal statute that prohibits schemes or artifices to defraud any health care benefit program or to obtain by false or fraudulent pretenses any money or property owned by or under the control of any health care benefit program. Subsection (a) provides that whoever knowingly and willfully executes, or attempts to execute, a scheme or artifice (1) to defraud any health care benefit program; or (2) to obtain, by means of false or fraudulent pretenses, representations, or promises, any of the money or property owned by, or under the custody or control of, any health care benefit program, in connection with the delivery of or payment for health care benefits, items, or services, shall be fined under this title or imprisoned not more than 10 years, or both. If the violation results in serious bodily injury (as defined in 18 USC 1365), the offender shall be imprisoned for not more than 20 years; if the violation results in death, the offender shall be imprisoned for any term of years or for life. Subsection (b) provides that with respect to subsection (a), a person need not have actual knowledge of this section or specific intent to commit a violation of this section. 'Health care benefit program' is defined in 18 USC 24(b) and includes any public or private plan or contract, affecting commerce, under which any medical benefit, item, or service is provided to any individual, and includes any individual or entity who is providing a medical benefit, item, or service for which payment may be made under the plan or contract. Section 1347 is the principal federal vehicle for Medicare, Medicaid, TRICARE, and private health insurance fraud prosecutions and is frequently charged alongside the False Claims Act (31 USC 3729 et seq.), the Anti-Kickback Statute (42 USC 1320a-7b), and the Stark physician self-referral law (42 USC 1395nn).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-privacy-rule"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-1348-securities-commodities-fraud",
    "title": "18 U.S.C. 1348 - Securities and Commodities Fraud",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "18 U.S.C. 1348 criminalises knowingly executing or attempting to execute a scheme or artifice to defraud any person in connection with commodities for future delivery, commodity options, or securities of an issuer with reporting obligations or required to file reports (paragraph (1)), and obtaining money or property in connection with the purchase or sale of such instruments by false or fraudulent pretenses, representations or promises (paragraph (2)). The penalty is a fine, imprisonment up to 25 years, or both.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1343-wire-fraud",
      "us-18-usc-1349-attempt-and-conspiracy-to-commit-chapter-63-offense",
      "sarbanes-oxley-act-sox"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-18-usc-1349-attempt-and-conspiracy-to-commit-chapter-63-offense",
    "title": "US Title 18 - 18 USC 1349 Attempt and Conspiracy to Commit Any Offense Under Chapter 63 (Mail Fraud, Wire Fraud, Bank Fraud, Health Care Fraud)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1349 titled 'Attempt and conspiracy' is the federal criminal provision created by section 902(a) of the Sarbanes-Oxley Act of 2002 (Public Law 107-204) that establishes parity between completed offenses and attempts or conspiracies under chapter 63 of title 18. The entire statutory text is: 'Any person who attempts or conspires to commit any offense under this chapter shall be subject to the same penalties as those prescribed for the offense, the commission of which was the object of the attempt or conspiracy.' The 'chapter' referenced is chapter 63 of title 18 (Mail Fraud and Other Fraud Offenses), which contains the principal federal fraud offenses: 18 USC 1341 (mail fraud), 18 USC 1342 (fictitious name or address), 18 USC 1343 (wire fraud), 18 USC 1344 (bank fraud), 18 USC 1346 (definition of 'scheme or artifice to defraud'), 18 USC 1347 (health care fraud), 18 USC 1348 (securities and commodities fraud), 18 USC 1350 (failure of corporate officers to certify financial reports), and 18 USC 1351 (fraud in foreign labor contracting). Section 1349 is significant because it sweeps attempts and conspiracies into the same penalty exposure as the completed offense, eliminating the historical disparity between completed and inchoate fraud offenses; for example, conspiracy to commit wire fraud under 1349 carries the same potential 20-year (or 30-year, in cases affecting a financial institution) imprisonment as completed wire fraud under 1343, rather than the 5-year general conspiracy ceiling of 18 USC 371. This statute is one of the most frequently charged provisions in modern federal white-collar fraud cases.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-rico-organized-crime-control-act-18-usc-1961"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1462-importation-transportation-obscene",
    "title": "18 USC § 1462 - Importation or Transportation of Obscene Matters",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "18 USC § 1462 (originally enacted June 25, 1948, ch. 645, 62 Stat. 768; amended numerous times including Pub. L. 104-208 to add 'interactive computer service' language) makes it a federal offence for any person to bring into the United States, or knowingly use any express company, common carrier, or interactive computer service (as defined in section 230(e)(2) of the Communications Act of 1934) for carriage in interstate or foreign commerce, of (a) any obscene, lewd, lascivious, or filthy book, pamphlet, picture, motion-picture film, paper, letter, writing, print, or other matter of indecent character; (b) any obscene sound recording or article producing sound; or (c) any drug, medicine, article, or thing designed, adapted, or intended for producing abortion, for any indecent or immoral use, or printed material giving information for unlawful uses; the penalty is fine and up to 5 years imprisonment first offence, increasing to 10 years for subsequent offences; § 1462 was Congress's foundational federal obscenity-importation statute and remains the primary tool for prosecuting cross-border obscenity smuggling and online obscenity hosting that crosses state or international lines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_obscenity_statutes",
        "interactive_computer_service_addition_1996",
        "abortion_and_indecent_articles_subsection_c",
        "industry_mapping",
        "enforcement_anchors",
        "miller_obscenity_test"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1465-production-transportation-obscene-matter",
      "us-18-usc-1466-engaging-business-selling-obscene",
      "us-18-usc-1470-transfer-obscene-material-minors"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1464-broadcasting-obscene-language",
    "title": "18 USC § 1464 - Broadcasting Obscene, Indecent, or Profane Language",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "18 USC § 1464 (originally enacted June 25, 1948, ch. 645, 62 Stat. 769) criminalizes the broadcast of obscene, indecent, or profane language by means of radio communication: 'Whoever utters any obscene, indecent, or profane language by means of radio communication shall be fined under this title or imprisoned not more than two years, or both'; the statute is enforced by the Federal Communications Commission (FCC) through administrative civil penalties under 47 USC § 503(b) (currently up to USD 414,454 per incident, adjusted annually for inflation) and is the criminal companion to the FCC's civil enforcement regime; FCC v. Pacifica Foundation 438 US 726 (1978) (the 'seven dirty words' decision) upheld the regulation of indecent broadcasting during hours when children are likely listening (6 AM to 10 PM safe harbor); obscene material is fully prohibited at all times under the Miller v. California 413 US 15 (1973) standard; indecent material is prohibited during the safe harbor; profane material is restricted similarly to indecent under modern FCC enforcement; the statute applies to traditional broadcast radio and television, but does NOT directly apply to cable, satellite, or streaming services which are addressed by parallel statutes including 18 USC § 1468 (cable) and FCC regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fcc_civil_enforcement_47_usc_503",
        "fcc_regulations_47_cfr_73_3999",
        "leading_case_law",
        "industry_mapping",
        "enforcement_anchors",
        "obscene_versus_indecent_distinction"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1468-cable-obscene-distribution",
      "us-18-usc-1465-production-transportation-obscene-matter",
      "us-18-usc-1462-importation-transportation-obscene"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1465-production-transportation-obscene-matter",
    "title": "18 USC § 1465 - Production and Transportation of Obscene Matters for Sale or Distribution",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "18 USC § 1465 (originally enacted June 28, 1955, ch. 190, § 3, 69 Stat. 183; most recently amended by Pub. L. 109-248, July 27, 2006) makes it a federal offence for any person to knowingly produce with the intent to transport, distribute, or transmit in interstate or foreign commerce - or to knowingly transport, travel in, or use a facility or means of interstate or foreign commerce or an interactive computer service (as defined in section 230(e)(2) of the Communications Act of 1934) - for the purpose of sale or distribution of any obscene book, pamphlet, picture, film, paper, letter, writing, print, silhouette, drawing, figure, image, cast, phonograph recording, electrical transcription, or other matter of indecent or immoral character; the statute carries a fine and up to 5 years imprisonment, and the transportation of two or more copies of any publication, or a combined total of five such publications and articles, creates a rebuttable presumption that the materials are intended for sale or distribution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "miller_obscenity_test",
        "related_obscenity_statutes",
        "interactive_computer_service",
        "industry_mapping",
        "enforcement_anchors",
        "constitutional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1466-engaging-business-selling-obscene",
      "us-18-usc-1462-importation-transportation-obscene",
      "us-18-usc-1470-transfer-obscene-material-minors"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1466-engaging-business-selling-obscene",
    "title": "18 USC § 1466 - Engaging in the Business of Selling or Transferring Obscene Matter",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "18 USC § 1466 (originally enacted by Pub. L. 100-690 the Anti-Drug Abuse Act of 1988, title VII, § 7521(a), 102 Stat. 4486) creates a federal offence specifically targeting commercial obscenity traffickers: 'Whoever is engaged in the business of producing with intent to distribute or sell, or selling or transferring obscene matter, who knowingly receives or possesses with intent to distribute any obscene book, magazine, picture, paper, film, videotape, or phonograph or other audio recording, which has been shipped or transported in interstate or foreign commerce, shall be punished by imprisonment for not more than 5 years or by a fine under this title, or both'; the statute defines 'engaged in the business' to mean devoting time, attention, or labor to such activities as a regular course of trade or business with the objective of earning a profit, though actual profit is not required, nor must such activity be the person's primary income source; a rebuttable presumption of being 'engaged in the business' applies when someone offers two or more copies of obscene publications or a combined total of five or more obscene publications and articles simultaneously; § 1466 is the targeted commercial-volume companion to the general § 1465 production/transportation statute, designed to capture systematic adult bookstore, mail-order, and online distribution operations rather than isolated transactions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_obscenity_statutes",
        "miller_obscenity_test",
        "rico_predicate_overlap",
        "industry_mapping",
        "enforcement_anchors",
        "section_1467_forfeiture_overlap"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1465-production-transportation-obscene-matter",
      "us-18-usc-1462-importation-transportation-obscene",
      "us-18-usc-2257-record-keeping-explicit-content"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1466a-obscene-visual-representations-csam",
    "title": "18 USC 1466A - Obscene Visual Representations of the Sexual Abuse of Children",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "18 USC 1466A criminalises the knowing production, distribution, receipt, possession with intent to distribute, or possession of any visual depiction (including drawings, cartoons, sculptures and paintings as well as photographic depictions) of a minor engaging in sexually explicit conduct or in graphic bestiality, sadistic or masochistic abuse or sexual intercourse where the depiction is obscene; subsection (c) provides that it is not a required element of the offense that the minor depicted actually exists, capturing computer-generated and AI-generated child sexual abuse material; subsection (d) establishes federal jurisdiction via interstate or foreign commerce; subsection (e) provides a narrow affirmative defense for possession of fewer than three depictions promptly destroyed or reported to law enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "child_pornography_statute_overlap",
        "interstate_commerce_jurisdiction",
        "reporting_obligations",
        "first_amendment_anchor",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1467-criminal-forfeiture-obscenity",
    "title": "18 USC § 1467 - Criminal Forfeiture of Property Related to Obscenity Offences",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "18 USC § 1467 (added by the Child Protection and Obscenity Enforcement Act of 1988, Pub. L. 100-690) provides for criminal forfeiture of property in connection with convictions under Chapter 71 (obscenity) of Title 18: subsection (a) makes forfeitable (1) any obscene material produced, transported, mailed, shipped, or received in violation of the chapter, (2) any property real or personal constituting or traceable to gross profits or other proceeds obtained from such offence, and (3) any property real or personal used or intended to be used to commit or to promote the commission of such offence; subsection (b) incorporates the procedural framework of 21 USC 853 (Controlled Substances Act criminal forfeiture) except subsections (a) and (d); subsection (c) provides civil forfeiture alternative through Chapter 46 procedures; the statute is the principal forfeiture mechanism for federal obscenity prosecutions, allowing the government to forfeit business inventory, real estate used for distribution, vehicles used for transportation, bank accounts containing proceeds, and intellectual property; ancillary procedures protect innocent third-party interests through 21 USC 853(n) petitions filed within 30 days of forfeiture order publication.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "predicate_obscenity_offenses",
        "procedural_incorporation_21_usc_853",
        "civil_forfeiture_alternative_chapter_46",
        "industry_mapping",
        "enforcement_anchors",
        "innocent_owner_defense_21_usc_853_n"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1465-production-transportation-obscene-matter",
      "us-18-usc-1466-engaging-business-selling-obscene",
      "us-18-usc-1462-importation-transportation-obscene"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1468-cable-obscene-distribution",
    "title": "18 USC § 1468 - Distributing Obscene Material by Cable or Subscription Television",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "18 USC § 1468 (added by the Child Protection and Obscenity Enforcement Act of 1988, Pub. L. 100-690, title VII, § 7525) criminalizes the knowing distribution of obscene material via cable or subscription television: subsection (a) provides 'Whoever knowingly utters any obscene language or distributes any obscene matter by means of cable television or subscription services on television' is subject to fine and imprisonment up to 2 years; subsection (b) defines 'distribute' to include sending, transmitting, retransmitting, telecasting, broadcasting, cablecasting (including by wire, microwave, or satellite), and producing or providing material for such distribution; subsection (c) preserves state and local authority to regulate obscene material distributed via cable or subscription television - the federal statute does not preempt state regulation; § 1468 is the cable/subscription-medium parallel to § 1464 (broadcast medium) and applies the same Miller obscenity standard; subscription services include premium pay channels (HBO, Showtime, Cinemax), pay-per-view, and subscription video-on-demand services that contract directly with subscribers; the statute does not apply to internet streaming services without cable/subscription-TV nexus, which are addressed by other federal obscenity statutes including 18 USC § 1465.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "broadcast_parallel_section_1464",
        "miller_obscenity_standard",
        "fcc_jurisdiction_overlay",
        "subscription_video_on_demand_application",
        "industry_mapping",
        "state_authority_preservation_subsection_c"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1464-broadcasting-obscene-language",
      "us-18-usc-1465-production-transportation-obscene-matter",
      "us-18-usc-1462-importation-transportation-obscene"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1470-transfer-obscene-material-minors",
    "title": "18 USC § 1470 - Transfer of Obscene Material to Minors Under 16",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "18 USC § 1470 (enacted by Pub. L. 105-314, the Protection of Children from Sexual Predators Act of 1998) makes it a federal offence for any person to knowingly use the mail or any facility or means of interstate or foreign commerce to transfer obscene matter to another individual who has not attained the age of 16 years, knowing that such individual has not attained that age, or to attempt to do so; the offence is punishable by a fine and up to 10 years imprisonment; the statute is a strict-knowledge crime requiring both knowledge of the material's obscene character and knowledge of the recipient's age, and applies whether the transfer occurs via postal mail, email, instant message, file transfer, cloud sharing, or any other interactive computer service.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_minor_protection_statutes",
        "obscenity_test",
        "commerce_nexus",
        "industry_mapping",
        "enforcement_anchors",
        "platform_safe_harbor_limits"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1465-production-transportation-obscene-matter",
      "us-18-usc-2425-transmit-minor-info-enticement",
      "us-18-usc-1466a-obscene-visual-representations-csam"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1503-obstruction-judicial-proceedings",
    "title": "US Federal Criminal Code - 18 USC 1503 Influencing or Injuring Officer or Juror Generally (Obstruction of Justice in Judicial Proceedings)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1503 is the foundational federal obstruction of justice statute applicable to judicial proceedings. The operative clause provides: whoever corruptly, or by threats or force, or by any threatening letter or communication, endeavors to influence, intimidate, or impede any grand or petit juror, or officer in or of any court of the United States, or officer who may be serving at any examination or other proceeding before any United States magistrate judge or other committing magistrate, in the discharge of his duty, or injures any such grand or petit juror in his person or property on account of any verdict or indictment assented to by him, or on account of his being or having been such juror, or injures any such officer, magistrate judge, or other committing magistrate in his person or property on account of the performance of his official duties, or corruptly or by threats or force, or by any threatening letter or communication, influences, obstructs, or impedes, or endeavors to influence, obstruct, or impede, the due administration of justice, shall be punished as provided in subsection (b). Subsection (b) provides graduated penalties: the punishment for an offense under this section is in the case of a killing, the punishment provided in sections 1111 and 1112; in the case of an attempted killing, or a case in which the offense was committed against a petit juror and in which a Class A or B felony was charged, imprisonment for not more than 20 years, a fine under this title, or both; and in any other case, imprisonment for not more than 10 years, a fine under this title, or both. Subsection (b) also contains an enhancement: if the offense involves a criminal case, the maximum term of imprisonment which may be imposed for the offense shall be the higher of that otherwise provided by law or the maximum term that could have been imposed for any offense charged in such case. Section 1503 reaches the omnibus clause (corruptly endeavors to influence, obstruct, or impede the due administration of justice) and is one of the most heavily-litigated federal obstruction statutes; the term corruptly was construed in United States v. Aguilar, 515 US 593 (1995), to require a nexus between the obstructive conduct and a particular judicial proceeding.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1505-obstruction-proceedings-departments-agencies-committees"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-18-usc-1505-obstruction-proceedings-departments-agencies-committees",
    "title": "US Federal Criminal Code - 18 USC 1505 Obstruction of Proceedings Before Departments, Agencies, and Committees",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1505 is the federal obstruction statute applicable to agency administrative proceedings and congressional inquiries. The statute contains two main prohibitions. The first provision criminalizes any person who, with intent to avoid, evade, prevent, or obstruct compliance, in whole or in part, with any civil investigative demand duly and properly made under the Antitrust Civil Process Act, willfully withholds, misrepresents, removes from any place, conceals, covers up, destroys, mutilates, alters, or by other means falsifies any documentary material, answers to written interrogatories, or oral testimony, which is the subject of such demand; or attempts to do so or solicits another to do so. The second provision criminalizes whoever corruptly, or by threats or force, or by any threatening letter or communication influences, obstructs, or impedes or endeavors to influence, obstruct, or impede the due and proper administration of the law under which any pending proceeding is being had before any department or agency of the United States, or the due and proper exercise of the power of inquiry under which any inquiry or investigation is being had by either House, or any committee of either House or any joint committee of the Congress. The penalty provides that violators shall be fined under this title, imprisoned not more than 5 years or, if the offense involves international or domestic terrorism (as defined in section 2331), imprisoned not more than 8 years, or both. Section 1505 is the obstruction statute that reaches conduct directed at federal agency rulemaking and enforcement (SEC, FTC, EPA, DOJ-Antitrust, congressional committees) and is distinct from 18 USC 1503 (obstruction of judicial proceedings) and 18 USC 1512 (witness tampering).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1519-destruction-falsification-records-federal-investigations"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-1512-tampering-with-witness-victim-informant",
    "title": "US Federal Criminal Code - 18 USC 1512 Tampering With a Witness, Victim, or an Informant",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1512 is the federal witness tampering statute, frequently charged in white-collar investigations alongside 18 USC 1503 and 1505. The statute spans multiple subsections each defining a distinct offense with distinct penalties. Subsection (a) covers killing or attempting to kill another person, or using physical force or threats of physical force, to prevent attendance at or testimony in an official proceeding, prevent communication to law enforcement, or prevent production of records; penalties for attempted killing or physical force reach up to 30 years and threats reach up to 20 years. Subsection (b) covers whoever knowingly uses intimidation, threatens, or corruptly persuades another person, or attempts to do so, or engages in misleading conduct toward another person, with intent to influence, delay, or prevent the testimony of any person in an official proceeding, cause or induce any person to withhold testimony or records, evade legal process, be absent from an official proceeding to which such person has been summoned by legal process, or hinder, delay, or prevent the communication to a law enforcement officer or judge of the United States of information relating to the commission or possible commission of a federal offense or violation of conditions of probation, parole, or release pending judicial proceedings; penalty up to 20 years. Subsection (c) covers whoever corruptly alters, destroys, mutilates, or conceals a record, document, or other object, or attempts to do so, with the intent to impair the object's integrity or availability for use in an official proceeding; or otherwise obstructs, influences, or impedes any official proceeding, or attempts to do so; penalty up to 20 years. Subsection (d) covers harassment that hinders, delays, prevents, or dissuades any person from attending or testifying in an official proceeding, reporting to law enforcement, or seeking enforcement of a federal right; penalty up to 3 years. Subsection (e) provides an affirmative defense for lawful conduct intended to encourage truthful testimony. Subsection (f) provides that an official proceeding need not be pending or about to be instituted at the time of the offense, and that the testimony, record, or document need not be admissible in evidence or free of a claim of privilege. Subsection (g) provides that no state of mind need be proved with respect to the circumstance that the official proceeding before a judge, court, magistrate judge, grand jury, or government agency is before a judge or court of the United States, or that the offense is a federal offense. Subsection (h) provides extraterritorial federal jurisdiction. Subsection (j) provides an enhanced penalty equal to the maximum that could have been imposed for the underlying offense charged in the criminal case to which the tampering related. Subsection (k) provides that whoever conspires to commit any offense under this section shall be subject to the same penalties as those prescribed for the offense the commission of which was the object of the conspiracy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1503-obstruction-judicial-proceedings"
    ],
    "primary_citations_count": 15
  },
  {
    "node_id": "us-18-usc-1517-obstructing-financial-institution-examination",
    "title": "18 U.S.C. 1517 - Obstructing Examination of a Financial Institution",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "18 U.S.C. 1517 makes it an offence to corruptly obstruct or attempt to obstruct any examination of a financial institution by an agency of the United States with jurisdiction to conduct that examination. The penalty is a fine, imprisonment up to 5 years, or both. The provision underpins the duty of an institution and its personnel to cooperate fully and truthfully with federal supervisory examinations and not to alter, conceal or destroy records or improperly influence examiners.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1005-bank-entries-reports-transactions",
      "us-18-usc-1344-bank-fraud",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1519-destruction-falsification-records-federal-investigations",
    "title": "US Sarbanes-Oxley Act - 18 USC 1519 Destruction, Alteration, or Falsification of Records in Federal Investigations and Bankruptcy",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1519 was enacted by section 802 of the Sarbanes-Oxley Act of 2002 and is the most expansive federal records-destruction obstruction statute. The full text provides: whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed under title 11, or in relation to or contemplation of any such matter or case, shall be fined under this title, imprisoned not more than 20 years, or both. Section 1519 is distinguished from 18 USC 1505 (which requires a pending agency proceeding or congressional inquiry) by three critical features: (1) no requirement that a proceeding be pending — the statute reaches conduct in relation to or contemplation of any matter, including anticipated investigations not yet commenced; (2) no requirement of corrupt intent, only knowing conduct with intent to impede, obstruct, or influence the matter; and (3) a substantially longer penalty of up to 20 years versus 5 years under 1505. Section 1519 was construed narrowly in Yates v. United States, 574 US 528 (2015), where the Supreme Court held that the term tangible object in 1519 refers to objects used to record or preserve information, not physical objects generally — limiting prosecution to evidence relating to documentation or recordkeeping. Section 1519 is frequently charged in corporate investigations, healthcare fraud probes, environmental investigations, and tax investigations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1505-obstruction-proceedings-departments-agencies-committees"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-152-bankruptcy-concealment-of-assets",
    "title": "18 U.S.C. 152 - Concealment of Assets; False Oaths and Claims; Bribery (Bankruptcy)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "18 U.S.C. 152 criminalises nine categories of fraudulent conduct in bankruptcy cases under title 11: knowingly and fraudulently concealing estate property from creditors or the custodian, trustee, marshal or other court officer (paragraph (1)); making a false oath or account (paragraph (2)); making a false declaration, certificate, verification or statement under penalty of perjury as permitted by 28 U.S.C. 1746 (paragraph (3)); presenting a false proof of claim (paragraph (4)); receiving a material amount of property from a debtor with intent to defeat title 11 (paragraph (5)); giving, offering, receiving or attempting to obtain money, property, reward or advantage for acting or forbearing to act in a bankruptcy case (paragraph (6)); fraudulently transferring or concealing property in contemplation of a title 11 case or with intent to defeat title 11 (paragraph (7)); concealing, destroying, mutilating, falsifying or making false entries in recorded information relating to the debtor (paragraph (8)); and withholding recorded information from the trustee or other officer (paragraph (9)). The penalty is a fine, imprisonment up to 5 years, or both.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1001-false-statements-federal-officers",
      "us-18-usc-1344-bank-fraud",
      "us-18-usc-1956-money-laundering-monetary-instruments"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-18-usc-1521-false-lien-retaliation-federal-judges-officers",
    "title": "US Title 18 - 18 USC 1521 Retaliating Against a Federal Judge or Federal Law Enforcement Officer by False Claim or Slander of Title",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1521 titled 'Retaliating against a Federal judge or Federal law enforcement officer by false claim or slander of title' is the federal criminal statute that prohibits the filing of false liens or encumbrances against the property of federal judges or federal law enforcement officers in retaliation for the performance of their official duties. The statute provides that whoever files, attempts to file, or conspires to file, in any public record or in any private record which is generally available to the public, any false lien or encumbrance against the real or personal property of an individual described in section 1114 (federal officer or employee in the performance of their official duties) on account of the performance of official duties by that individual, knowing or having reason to know that such lien or encumbrance is false or contains any materially false, fictitious, or fraudulent statement or representation, shall be fined under this title or imprisoned for not more than 10 years, or both. Section 1114 covers a broad class of federal officers and employees, including federal judges, federal law enforcement officers, and other federal officials performing official duties. Section 1521 was enacted as part of the Court Security Improvement Act of 2007 (Public Law 110-177) in response to the rise of 'paper terrorism' tactics in which sovereign-citizen and tax-protester movements filed bogus liens against the property of judges, prosecutors, and law enforcement officers to harass and intimidate them.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-computer-fraud-abuse-act-1986"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1546-fraud-misuse-visas-permits-immigration-documents",
    "title": "US Title 18 - 18 USC 1546 Fraud and Misuse of Visas, Permits, and Other Documents",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1546 titled 'Fraud and misuse of visas, permits, and other documents' is the principal federal criminal statute addressing immigration document fraud and material false statements in immigration applications. Subsection (a) criminalizes a series of acts when done knowingly: forging, counterfeiting, altering, or falsely making any immigrant or nonimmigrant visa, permit, border crossing card, alien registration receipt card, or other document prescribed by statute or regulation for entry into or as evidence of authorized stay or employment in the United States; possessing, using, or accepting any such document knowing it to be forged, counterfeited, altered, or falsely made or to have been procured by means of any false claim or statement or to have been otherwise procured by fraud or unlawfully obtained; possessing or knowingly making any unauthorized blank permit; possessing or making any plate, stone, or other thing, or any part thereof, with which a permit might be forged, counterfeited, altered, or falsely made; making any false statement under oath in any immigration application, affidavit, or other document required by the immigration laws or regulations; impersonating any other person in any immigration matter, or appearing in any name other than one's own. Subsection (b) addresses the use of false identification documents or attestations to satisfy employment-eligibility verification requirements under section 274A(b) of the Immigration and Nationality Act. The penalty structure is tiered: imprisonment of not more than 25 years if the offense was committed to facilitate an act of international terrorism (as defined in 18 USC 2331); not more than 20 years if committed to facilitate a drug trafficking crime (as defined in 18 USC 929(a)); not more than 10 years in the case of the first or second such offense if the offense was not committed to facilitate either an act of terrorism or a drug trafficking crime; and not more than 15 years in the case of any other offense. The statute exempts lawfully authorized investigative, protective, or intelligence activity by law enforcement and intelligence agencies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-mail-fraud-18-usc-1341"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-157-bankruptcy-fraud-scheme",
    "title": "18 U.S.C. 157 - Bankruptcy Fraud",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "18 U.S.C. 157 makes it an offence to devise or intend to devise a scheme or artifice to defraud and, for the purpose of executing or concealing the scheme, to file a petition under title 11 (including a fraudulent involuntary petition under section 303 of title 11), to file a document in a proceeding under title 11, or to make a false or fraudulent representation, claim or promise concerning or in relation to a proceeding under title 11, at any time before or after the filing of the petition or in relation to a proceeding falsely asserted to be pending. The penalty is a fine, imprisonment up to 5 years, or both.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1341-mail-fraud",
      "us-18-usc-1001-false-statements-federal-officers",
      "us-18-usc-1344-bank-fraud"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1591-sex-trafficking-by-force-fraud-coercion",
    "title": "18 USC § 1591 - Sex Trafficking of Children or by Force, Fraud, or Coercion",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "18 USC § 1591 (Trafficking Victims Protection Act of 2000 Pub. L. 106-386 § 112(a)(2) as amended by the Trafficking Victims Protection Reauthorization Acts of 2003, 2005, 2008, 2013, the Justice for Victims of Trafficking Act of 2015 Pub. L. 114-22, and FOSTA-SESTA 2018 Pub. L. 115-164) is the federal anti-sex-trafficking centerpiece and the predicate-offence anchor for FOSTA-SESTA platform liability under 18 USC § 2421A: subsection (a) prohibits knowingly recruiting, enticing, harbouring, transporting, providing, obtaining, advertising, maintaining, patronising, or soliciting any person through force, threats of force, fraud, or coercion for commercial sex acts (1591(a)(1)) OR recruiting or otherwise involving any minor under 18 in commercial sex acts even without force, fraud, or coercion (1591(a)(2)); subsection (b) establishes the mandatory minimum sentencing structure: (b)(1) provides 'imprisonment for any term of years not less than 15 or for life' where the offence involved force, threats, fraud, or coercion OR the victim was under age 14; (b)(2) provides 'imprisonment for not less than 10 years or for life' where the victim was between 14 and 17 without the aggravating means; subsection (c) provides that for minor victims, prosecutors need not prove the defendant knew the victim's age if the defendant had a reasonable opportunity to observe the victim; subsection (d) criminalizes obstruction of §1591 enforcement with up to 25 years imprisonment; subsection (e) provides six statutory definitions including 'commercial sex act' (any sex act on account of which anything of value is given to or received by any person), 'coercion' (threats of serious harm to or physical restraint against any person, schemes intended to cause belief of serious harm or restraint, abuse or threatened abuse of legal process), 'serious harm' (any harm physical or non-physical including psychological, financial, or reputational damage), and 'venture' (group of two or more individuals or entities); §1591 reaches commercial sex platforms via 'patronizing or soliciting' and 'advertising' modes (added by Justice for Victims of Trafficking Act 2015 and FOSTA-SESTA 2018) and is the primary federal predicate for §2421A platform-promoter liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "trafficking_victims_protection_act_legislative_history",
        "fosta_sesta_2018_platform_liability_intersection",
        "trafficking_victims_protection_civil_remedy_18_usc_1595",
        "communications_decency_act_section_230_carve_out",
        "industry_mapping",
        "enforcement_anchors",
        "constitutional_doctrine",
        "advertising_mode_2015_amendment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2421a-fosta-promoting-prostitution-online",
      "us-18-usc-2256-definitions-csam-chapter-110",
      "us-trafficking-victims-protection-act-22-usc-7101"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1623-false-declarations-grand-jury-court",
    "title": "US Federal Criminal Code - 18 USC 1623 False Declarations Before Grand Jury or Court",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1623 is the federal false declarations statute applicable to proceedings before federal grand juries and federal courts. Subsection (a) provides that whoever under oath (or in any declaration, certificate, verification, or statement under penalty of perjury as permitted under section 1746 of title 28, United States Code) in any proceeding before or ancillary to any court or grand jury of the United States knowingly makes any false material declaration or makes or uses any other information, including any book, paper, document, record, recording, or other material, knowing the same to contain any false material declaration, shall be fined under this title or imprisoned not more than five years, or both. If the offense involves international or domestic terrorism (as defined in section 2331), the imprisonment term may be enhanced. The provision also enhances the penalty up to ten years if proceedings are before the Foreign Intelligence Surveillance Court. Subsection (b) provides that this section is applicable whether the conduct occurred within or without the United States. Subsection (c) is the two-statements provision: an indictment or information for violation of this section alleging that, in any proceedings before or ancillary to any court or grand jury of the United States, the defendant under oath has knowingly made two or more declarations, which are inconsistent to the degree that one of them is necessarily false, need not specify which declaration is false if (1) each declaration was material to the point in question, and (2) each declaration was made within the period of the statute of limitations for the offense charged under this section. In any prosecution under this section, the falsity of a declaration set forth in the indictment or information shall be established sufficiently for conviction by proof that the defendant while under oath made irreconcilably contradictory declarations material to the point in question in any proceeding before or ancillary to any court or grand jury. It shall be a defense to an indictment or information made pursuant to the first sentence of this subsection that the defendant at the time he made each declaration believed the declaration was true. Subsection (d) provides a recantation defense: where, in the same continuous court or grand jury proceeding in which a declaration is made, the person making the declaration admits such declaration to be false, such admission shall bar prosecution under this section if, at the time the admission is made, the declaration has not substantially affected the proceeding, or it has not become manifest that such falsity has been or will be exposed. Subsection (e) provides that proof beyond a reasonable doubt under this section is sufficient for conviction. It shall not be necessary that such proof be made by any particular number of witnesses or by documentary or other type of evidence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1001-false-statements-federal-officers"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-18-usc-1801-video-voyeurism-prevention-act",
    "title": "18 USC § 1801 - Video Voyeurism Prevention Act of 2004",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "18 USC § 1801 (added by the Video Voyeurism Prevention Act of 2004, Pub. L. 108-495, signed 23 December 2004) criminalises the non-consensual capture of intimate visual recordings in federal jurisdictional spaces and serves as the federal foundation alongside which all 50 states have enacted parallel voyeurism statutes addressing private-property and state jurisdictional contexts: subsection (a) provides 'Whoever, in the special maritime and territorial jurisdiction of the United States, has the intent to capture an image of a private area of an individual without their consent, and knowingly does so under circumstances in which the individual has a reasonable expectation of privacy, shall be fined under this title or imprisoned not more than one year, or both'; subsection (b) provides five enumerated definitions including 'capture' (videotape, photograph, film, record by any means, or broadcast), 'broadcast' (electronic transmission for viewing by one or more persons), 'private area' (naked or undergarment-clad genitals, pubic area, buttocks, or female breast), 'female breast' (any portion below the top of the areola), and 'reasonable expectation of privacy' (circumstances where the individual could disrobe in privacy without concern of capture OR where the individual believed private areas would not be visible to the public regardless of public location); subsection (c) provides a lawful law enforcement, correctional, or intelligence activity exemption; the federal statute operates in jurisdictional spaces (federal lands, vessels, military installations, embassies, federal buildings) while state voyeurism statutes cover private-property and ordinary commercial contexts; the 'reasonable expectation of privacy in public areas' element is the doctrinal innovation that recognises modern smartphone-camera ubiquity and extends protection into changing rooms, public restrooms, and similar semi-public spaces.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "special_maritime_and_territorial_jurisdiction_anchor",
        "state_voyeurism_statutes_complement",
        "related_federal_intimate_image_statutes",
        "ai_synthetic_image_intersection",
        "industry_mapping",
        "enforcement_anchors",
        "constitutional_doctrinal_framework",
        "1801_b_5_modern_smartphone_doctrine"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-take-it-down-act-2025",
      "us-18-usc-2256-definitions-csam-chapter-110"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1832-economic-espionage-act-trade-secrets",
    "title": "18 USC § 1832 - Economic Espionage Act (Theft of Trade Secrets)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "18 USC § 1832 (Economic Espionage Act of 1996, Pub. L. 104-294 Title I; amended by Defend Trade Secrets Act of 2016, Pub. L. 114-153) criminalizes the theft of trade secrets related to products or services used in or intended for use in interstate or foreign commerce, with intent to convert them for the economic benefit of anyone other than the owner: subsection (a) makes it an offence to knowingly (1) steal or appropriate without authorization, (2) without authorization copy, duplicate, sketch, draw, photograph, download, upload, alter, destroy, photocopy, replicate, transmit, deliver, send, mail, communicate, or convey, (3) receive, buy, or possess such trade secret knowing the same to have been stolen or appropriated without authorization, (4) attempt to commit any offence in (1)-(3), or (5) conspire to do so with one or more others; penalty for individuals up to 10 years imprisonment plus fine; subsection (b) provides corporate liability with fines up to greater of $5,000,000 or 3 times the value of the stolen trade secret including research, design, and reproduction costs avoided; subsection (c) provides extraterritorial jurisdiction where offender is US person or organization or where act in furtherance of offence was committed in US; the Defend Trade Secrets Act 2016 created parallel federal civil cause of action under 18 USC § 1836 alongside the criminal § 1832 framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "economic_espionage_act_provisions",
        "defend_trade_secrets_act_2016",
        "trade_secret_definition_section_1839_3",
        "industry_mapping",
        "enforcement_anchors",
        "section_1833_b_whistleblower_immunity"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355",
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-47-usc-222-cpni-customer-network-information"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-1951-hobbs-act-interference-commerce",
    "title": "US Federal Criminal Code - 18 USC 1951 Hobbs Act (Interference With Commerce by Threats or Violence)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1951 is the Hobbs Act, the principal federal statute criminalizing robbery and extortion that affects interstate or foreign commerce. Subsection (a) provides: whoever in any way or degree obstructs, delays, or affects commerce or the movement of any article or commodity in commerce, by robbery or extortion or attempts or conspires so to do, or commits or threatens physical violence to any person or property in furtherance of a plan or purpose to do anything in violation of this section shall be fined under this title or imprisoned not more than twenty years, or both. Subsection (b) provides the definitions. Robbery is defined in (b)(1) as the unlawful taking or obtaining of personal property from the person or in the presence of another, against his will, by means of actual or threatened force, or violence, or fear of injury, immediate or future, to his person or property, or property in his custody or possession, or the person or property of a relative or member of his family or of anyone in his company at the time of the taking or obtaining. Extortion is defined in (b)(2) as the obtaining of property from another, with his consent, induced by wrongful use of actual or threatened force, violence, or fear, or under color of official right. Subsection (b)(3) defines commerce broadly to mean commerce within the District of Columbia, or any Territory or Possession of the United States; all commerce between any point in a State, Territory, Possession, or the District of Columbia and any point outside thereof; all commerce between points within the same State through any place outside such State; and all other commerce over which the United States has jurisdiction. The Hobbs Act has been construed in McDonnell v. United States, 579 US 550 (2016), to limit the color of official right extortion theory to obtaining property in exchange for an official act, and the official act must involve a formal exercise of governmental power. The Hobbs Act is frequently charged in public corruption prosecutions (extortion under color of official right) and in commercial robbery prosecutions where the victim is engaged in interstate commerce.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1962-rico-prohibited-activities"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-1952-travel-act-interstate-aid-of-racketeering",
    "title": "US Federal Criminal Code - 18 USC 1952 Interstate and Foreign Travel or Transportation in Aid of Racketeering Enterprises (Travel Act)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1952 is the Travel Act, enacted in 1961 to give federal jurisdiction over enumerated unlawful activities when interstate or foreign travel or transportation is used in their commission. Subsection (a) provides: whoever travels in interstate or foreign commerce or uses the mail or any facility in interstate or foreign commerce, with intent to: (1) distribute the proceeds of any unlawful activity; or (2) commit any crime of violence to further any unlawful activity; or (3) otherwise promote, manage, establish, carry on, or facilitate the promotion, management, establishment, or carrying on, of any unlawful activity, and thereafter performs or attempts to perform: (A) an act described in paragraph (1) or (3), shall be fined under this title, imprisoned not more than 5 years, or both; or (B) an act described in paragraph (2), shall be fined under this title, imprisoned for not more than 20 years, or both, and if death results shall be imprisoned for any term of years or for life. Subsection (b) defines unlawful activity: as used in this section: (1) unlawful activity means (a) any business enterprise involving gambling, liquor on which the Federal excise tax has not been paid, narcotics or controlled substances (as defined in section 102(6) of the Controlled Substances Act), or prostitution offenses in violation of the laws of the State in which they are committed or of the United States; (b) extortion, bribery, or arson in violation of the laws of the State in which committed or of the United States; or (c) any act which is indictable under subchapter II of chapter 53 of title 31 (relating to bank reports) or under section 1956 (relating to laundering of monetary instruments) or 1957 (relating to engaging in monetary transactions in property derived from specified unlawful activity); and (2) State includes a State of the United States, the District of Columbia, and any commonwealth, territory, or possession of the United States. The Travel Act is the federal statute that federalizes state-law business enterprises by adding the interstate or foreign travel or facility-of-interstate-commerce element, and is frequently charged alongside Hobbs Act, mail and wire fraud, money laundering, RICO, and FCPA offenses.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1951-hobbs-act-interference-commerce"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-1953-interstate-transportation-of-wagering-paraphernalia",
    "title": "18 U.S.C. § 1953 - Interstate Transportation of Wagering Paraphernalia",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2025-01-01",
    "bluf": "Any person other than a common carrier in the usual course of its business who knowingly carries or sends in interstate or foreign commerce any record, paraphernalia, ticket, certificate, bills, slip, token, paper, writing, or other device used, to be used, or adapted, devised or designed for use in bookmaking, wagering pools with respect to a sporting event, or in a numbers, policy, bolita, or similar game commits a federal offence punishable by fine and up to five years' imprisonment under 18 U.S.C. § 1953(a) - subject to the carve-outs in § 1953(b) for parimutuel equipment and tickets where legally acquired, parimutuel materials used at racetracks or other sporting events where betting is legal under applicable State law, newspapers and similar publications, and materials for state-conducted lotteries - while preserving concurrent state criminal authority under § 1953(c).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1955-illegal-gambling-business",
      "us-wire-act-18-usc-1084"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-18-usc-1955-illegal-gambling-business",
    "title": "US Federal Criminal Code - 18 USC 1955 Prohibition of Illegal Gambling Businesses",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1955 is the federal criminal statute that federalizes operation of significant illegal gambling businesses violating state law. Subsection (a) provides: whoever conducts, finances, manages, supervises, directs, or owns all or part of an illegal gambling business shall be fined under this title or imprisoned not more than five years, or both. Subsection (b)(1) defines illegal gambling business as a gambling business which (i) is a violation of the law of a State or political subdivision in which it is conducted; (ii) involves five or more persons who conduct, finance, manage, supervise, direct, or own all or part of such business; and (iii) has been or remains in substantially continuous operation for a period in excess of thirty days or has a gross revenue of $2,000 in any single day. Subsection (b)(2) defines gambling to include but not be limited to pool-selling, bookmaking, maintaining slot machines, roulette wheels or dice tables, and conducting lotteries, policy, bolita or numbers games, or selling chances therein. Subsection (b)(3) defines what otherwise would constitute gambling. Subsection (c) provides for evidentiary inferences: if five or more persons conduct, finance, manage, supervise, direct, or own all or part of a gambling business and such business operates for two or more successive days, then, for the purpose of obtaining warrants for arrests, interceptions, and other searches and seizures, probable cause that the business receives gross revenue in excess of $2,000 in any single day shall be deemed to have been established. Subsection (d) provides forfeiture: any property, including money, used in violation of the provisions of this section may be seized and forfeited to the United States. All provisions of law relating to the seizure, summary, and judicial forfeiture procedures, and condemnation of vessels, vehicles, merchandise, and baggage for violations of the customs laws; the disposition of such vessels, vehicles, merchandise, and baggage or the proceeds from the sale thereof; the remission or mitigation of such forfeitures; and the compromise of claims and the award of compensation to informers in respect of such forfeitures shall apply to seizures and forfeitures incurred, or alleged to have been incurred, under the provisions of this section, insofar as applicable and not inconsistent with such provisions. Subsection (e) provides that this section shall not apply to any bingo game, lottery, or similar game of chance conducted by an organization exempt from tax under paragraph (3) of subsection (c) of section 501 of the Internal Revenue Code of 1986, or to savings promotion raffles. Section 1955 is the federal predicate for many state-illegal sportsbook, illegal online gambling, and large-scale unlawful gambling prosecutions, and is also a RICO predicate offense under 18 USC 1961(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1952-travel-act-interstate-aid-of-racketeering"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-18-usc-1956-money-laundering-monetary-instruments",
    "title": "US Money Laundering Control Act - 18 USC 1956 Laundering of Monetary Instruments",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1956 is the principal federal money laundering criminal statute. Subsection (a)(1) makes it a felony for any person who, knowing that the property involved in a financial transaction represents the proceeds of some form of unlawful activity, conducts or attempts to conduct such a financial transaction which in fact involves the proceeds of specified unlawful activity: (A) with the intent to promote the carrying on of specified unlawful activity, or with intent to engage in conduct constituting a violation of section 7201 or 7206 of the Internal Revenue Code; or (B) knowing that the transaction is designed in whole or in part to conceal or disguise the nature, location, source, ownership, or control of the proceeds, or to avoid a transaction reporting requirement. Subsection (a)(2) makes it a felony to transport, transmit, or transfer, or attempt to transport, transmit, or transfer a monetary instrument or funds from a place in the United States to or through a place outside the United States or to a place in the United States from or through a place outside the United States with the intent to promote the carrying on of specified unlawful activity, or knowing that the monetary instrument or funds involved in the transportation, transmission, or transfer represent the proceeds of some form of unlawful activity and knowing that such transportation, transmission, or transfer is designed in whole or in part to conceal or disguise the nature, the location, the source, the ownership, or the control of the proceeds or to avoid a transaction reporting requirement. Subsection (a)(3) covers undercover sting operations: conducting a financial transaction involving property represented to be unlawful proceeds with intent to promote unlawful activity, conceal, or avoid reporting requirements. Subsection (c) provides extensive definitions including financial transaction, monetary instruments, specified unlawful activity (an extensive list of predicate offenses), and proceeds (defined post-Santos as gross receipts for many predicate offenses, as confirmed by the Fraud Enforcement and Recovery Act of 2009). Subsection (h) covers conspiracy: any person who conspires to commit any offense defined in this section or section 1957 shall be subject to the same penalties as those prescribed for the offense the commission of which was the object of the conspiracy. Penalties under (a)(1) and (a)(2): fine of not more than $500,000 or twice the value of the property involved in the transaction, whichever is greater, or imprisonment for not more than twenty years, or both.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1957-monetary-transactions-criminally-derived-property"
    ],
    "primary_citations_count": 14
  },
  {
    "node_id": "us-18-usc-1957-monetary-transactions-criminally-derived-property",
    "title": "US Title 18 - 18 USC 1957 Engaging in Monetary Transactions in Property Derived from Specified Unlawful Activity",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1957 titled 'Engaging in monetary transactions in property derived from specified unlawful activity' is the companion federal money-laundering offense to 18 USC 1956, criminalizing the act of engaging in monetary transactions involving funds derived from criminal activity above a stated dollar threshold. Subsection (a) provides that whoever, in any of the circumstances set forth in subsection (d), knowingly engages or attempts to engage in a monetary transaction in criminally derived property of a value greater than $10,000 and is derived from specified unlawful activity, shall be punished as provided in subsection (b). Subsection (b) sets penalties at a fine under title 18 or imprisonment for not more than 10 years, or both; the court may alternatively impose fines up to twice the amount of the criminally derived property involved. Subsection (d) provides the jurisdictional element: the offense applies where the conduct occurred (1) within the United States or the special maritime and territorial jurisdiction, or (2) outside the United States where the defendant is a United States person as defined in section 3077. Subsection (f)(1) defines 'monetary transaction' as the deposit, withdrawal, transfer, or exchange, in or affecting interstate or foreign commerce, of funds or a monetary instrument by, through, or to a financial institution (excluding transactions necessary to preserve a person's right to representation under the Sixth Amendment). Subsection (f)(2) defines 'criminally derived property' as any property constituting, or derived from, proceeds obtained from a criminal offense. Subsection (f)(3) cross-references the definition of 'specified unlawful activity' found in 18 USC 1956(c)(7). Section 1957 differs from section 1956 in that it does not require intent to promote unlawful activity or conceal proceeds — it criminalizes the bare act of conducting a qualifying monetary transaction with knowledge that the property is criminally derived.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-money-laundering-control-act-18-usc-1956"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-1960-unlicensed-money-transmitting-business",
    "title": "US Money Laundering Control Act - 18 USC 1960 Prohibition of Unlicensed Money Transmitting Businesses",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1960 is the federal criminal statute prohibiting unlicensed money transmitting businesses, frequently charged against operators of cryptocurrency exchanges, payment processors, and informal value transfer systems. Subsection (a) provides that whoever knowingly conducts, controls, manages, supervises, directs, or owns all or part of an unlicensed money transmitting business, shall be fined in accordance with this title or imprisoned not more than 5 years, or both. Subsection (b) provides three independent definitions of an unlicensed money transmitting business, each requiring the business to affect interstate or foreign commerce in any manner or degree: (1) is operated without an appropriate money transmitting license in a State where such operation is punishable as a misdemeanor or a felony under State law, whether or not the defendant knew that the operation was required to be licensed or that the operation was so punishable; (2) fails to comply with the money transmitting business registration requirements under section 5330 of title 31, United States Code, or regulations prescribed under such section; or (3) otherwise involves the transportation or transmission of funds that are known to the defendant to have been derived from a criminal offense or are intended to be used to promote or support unlawful activity. Subsection (b)(2) defines money transmitting as including transferring funds on behalf of the public by any and all means including but not limited to transfers within this country or to locations abroad by wire, check, draft, facsimile, or courier. Subsection (b)(3) defines State as any State of the United States, the District of Columbia, the Northern Mariana Islands, and any commonwealth, territory, or possession of the United States. Section 1960 is unique in US AML law because subsection (b)(1)(A) does not require proof that the defendant knew that the operation was required to be licensed or that the operation was punishable, making it a strict-knowledge offense as to the licensing requirement itself.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1956-money-laundering-monetary-instruments"
    ],
    "primary_citations_count": 14
  },
  {
    "node_id": "us-18-usc-1962-rico-prohibited-activities",
    "title": "US Title 18 - 18 USC 1962 RICO Prohibited Activities (Substantive Racketeering Offenses)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1962 titled 'Prohibited activities' is the substantive Racketeer Influenced and Corrupt Organizations (RICO) Act provision setting out the four substantive racketeering offenses. Subsection (a) makes it unlawful for any person who has received any income derived, directly or indirectly, from a pattern of racketeering activity or through collection of an unlawful debt in which such person has participated as a principal within the meaning of 18 USC 2, to use or invest, directly or indirectly, any part of such income, or the proceeds of such income, in acquisition of any interest in, or the establishment or operation of, any enterprise which is engaged in, or the activities of which affect, interstate or foreign commerce; a narrow carve-out excludes open-market securities purchases comprising less than one percent of outstanding shares without control intent. Subsection (b) makes it unlawful for any person through a pattern of racketeering activity or through collection of an unlawful debt to acquire or maintain, directly or indirectly, any interest in or control of any enterprise which is engaged in, or the activities of which affect, interstate or foreign commerce. Subsection (c) makes it unlawful for any person employed by or associated with any enterprise engaged in, or the activities of which affect, interstate or foreign commerce, to conduct or participate, directly or indirectly, in the conduct of such enterprise's affairs through a pattern of racketeering activity or collection of unlawful debt. Subsection (d) makes it unlawful for any person to conspire to violate any of the provisions of subsections (a), (b), or (c) of this section. 'Pattern of racketeering activity' is defined elsewhere as at least two acts of racketeering activity (as enumerated in 18 USC 1961(1)) within ten years of each other. Section 1962 is the criminal counterpart to the civil remedies in 18 USC 1964 and the predicate-acts definition in 18 USC 1961.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-rico-organized-crime-control-act-18-usc-1961"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-18-usc-1963-rico-criminal-penalties-forfeiture",
    "title": "18 U.S.C. 1963 - Criminal Penalties and Forfeiture (RICO)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "18 U.S.C. 1963 sets the criminal penalties for violations of the RICO prohibited activities in 18 U.S.C. 1962. A person convicted is fined or imprisoned up to 20 years (or for life where the underlying racketeering activity carries a maximum of life imprisonment), or both, and shall forfeit to the United States any interest acquired or maintained in violation of section 1962 (subsection (a)(1)), any interest in, security of, claim against, or property or contractual right affording a source of influence over any enterprise the person established, operated, controlled, conducted or participated in in violation of section 1962 (subsection (a)(2)), and any property constituting or derived from proceeds obtained from racketeering activity or unlawful debt collection in violation of section 1962 (subsection (a)(3)). All right, title and interest in forfeitable property vests in the United States upon commission of the act giving rise to forfeiture (subsection (c), relation-back), and the court may order forfeiture of substitute assets up to the value of unavailable property (subsection (m)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1962-rico-prohibited-activities",
      "us-18-usc-1964-rico-civil-remedies",
      "us-18-usc-1956-money-laundering-monetary-instruments"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-18-usc-1964-rico-civil-remedies",
    "title": "US Title 18 - 18 USC 1964 RICO Civil Remedies (Treble Damages and Equitable Relief)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 1964 titled 'Civil remedies' is the Racketeer Influenced and Corrupt Organizations (RICO) Act provision granting district court jurisdiction to prevent and restrain violations of 18 USC 1962 and creating both governmental and private civil rights of action. Subsection (a) provides that the district courts of the United States shall have jurisdiction to prevent and restrain violations of section 1962 by issuing appropriate orders, including, but not limited to: ordering any person to divest himself of any interest, direct or indirect, in any enterprise; imposing reasonable restrictions on the future activities or investments of any person, including, but not limited to, prohibiting any person from engaging in the same type of endeavor as the enterprise engaged in, the activities of which affect interstate or foreign commerce; or ordering dissolution or reorganization of any enterprise, making due provision for the rights of innocent persons. Subsection (b) provides that the Attorney General may institute proceedings under this section, and that pending final determination, the court may at any time enter such restraining orders or prohibitions, or take such other actions, including the acceptance of satisfactory performance bonds, as it shall deem proper. Subsection (c) creates the private civil right of action: any person injured in his business or property by reason of a violation of section 1962 of this chapter may sue therefor in any appropriate United States district court and shall recover threefold the damages he sustains and the cost of the suit, including a reasonable attorney's fee, with a narrow exception that no person may rely upon any conduct that would have been actionable as fraud in the purchase or sale of securities to establish a violation of section 1962 (the securities-fraud exclusion), except where the defendant has been criminally convicted in connection with the fraud. Subsection (d) provides that a final judgment or decree rendered in favor of the United States in any criminal proceeding brought by the United States under this chapter shall estop the defendant from denying the essential allegations of the criminal offense in any subsequent civil proceeding brought by the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-rico-organized-crime-control-act-18-usc-1961"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-18-usc-215-bank-bribery-loan-procurement",
    "title": "18 U.S.C. 215 - Receipt of Commissions or Gifts for Procuring Loans (Bank Bribery)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "18 U.S.C. 215 criminalises bank bribery: corruptly giving, offering or promising anything of value to influence or reward an officer, director, employee, agent or attorney of a financial institution in connection with its business (subsection (a)(1)), and corruptly soliciting, demanding or accepting such value (subsection (a)(2)). The penalty is a fine up to $1,000,000 or three times the value, and up to 30 years imprisonment, reduced to up to one year where the value does not exceed $1,000; bona fide compensation in the usual course of business is excepted (subsection (c)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1344-bank-fraud",
      "us-18-usc-1956-money-laundering-monetary-instruments",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-18-usc-2241-aggravated-sexual-abuse",
    "title": "US 18 U.S.C. § 2241 - Aggravated Sexual Abuse",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2241 creates three principal aggravated sexual abuse offences. Subsection (a) by force or threat: knowingly causing another person to engage in a sexual act by using force or by threatening or placing the person in fear that any person will be subjected to death, serious bodily injury, or kidnapping. Subsection (b) by other means: rendering another person unconscious, or administering a drug, intoxicant, or other similar substance, then engaging in a sexual act with that person. Subsection (c) with children: crossing state lines with intent to engage in sexual act with someone under 12, or knowingly engaging in such an act within federal jurisdiction. All carry imprisonment for any term of years or life; subsection (c) sets a mandatory minimum of 30 years. Federal jurisdiction limited to special maritime/territorial jurisdiction, federal facilities, or crossing state lines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "subsection_a_by_force_or_threat",
        "subsection_b_by_other_means_unconsciousness_or_substance",
        "subsection_c_with_children",
        "no_knowledge_of_age_under_12_required_subsection_d",
        "mandatory_life_for_prior_conviction",
        "sexual_act_definition_section_2246_2",
        "interaction_with_section_2242_sexual_abuse",
        "federal_jurisdiction_limitations_special_maritime_and_territorial",
        "interaction_with_violence_against_women_act_reauthorisations"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2251-sexual-exploitation-of-children",
      "us-18-usc-2423-transportation-of-minors"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-2242-sexual-abuse",
    "title": "US 18 U.S.C. § 2242 - Sexual Abuse",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2242 criminalises sexual abuse occurring in the special maritime and territorial jurisdiction of the United States or in a Federal prison or contracted custodial facility. The statute prohibits knowingly (1) causing another person to engage in a sexual act by threatening or placing that person in fear (other than threats of death, serious bodily injury, or kidnapping covered by § 2241(a)); (2) engaging in a sexual act with someone incapable of appraising the nature of the conduct or physically incapable of declining or communicating unwillingness; or (3) engaging in a sexual act without the other person's consent, including through coercion. Penalty: fine and imprisonment for any term of years or life. The (3) consent-based limb was added by the 2022 amendment to address sexual abuse without violence or incapacity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "jurisdictional_scope_federal_facilities",
        "limb_1_threats_or_fear_other_than_aggravated_threats",
        "limb_2_incapacity",
        "limb_3_consent_based_added_2022",
        "sexual_act_definition_section_2246_2",
        "penalty_imprisonment_for_any_term_or_life",
        "interaction_with_section_2241_aggravated_sexual_abuse",
        "interaction_with_section_2244_abusive_sexual_contact",
        "sentencing_guidelines_apply"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2241-aggravated-sexual-abuse",
      "us-18-usc-2244-abusive-sexual-contact",
      "us-18-usc-2246-definitions-chapter-109a"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-18-usc-2243-sexual-abuse-of-minor-or-ward",
    "title": "US 18 U.S.C. § 2243 - Sexual Abuse of a Minor, Ward, or by Federal Law Enforcement Officer",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2243 criminalises three categories of sexual abuse in federal jurisdiction: (a) sexual abuse of a minor between 12 and 16 years old where the offender is at least 4 years older - penalty up to 15 years; (b) sexual abuse of a ward in official detention where the offender has custodial authority - penalty up to 15 years; (c) sexual conduct between federal law enforcement officers and persons under arrest, supervision, in detention, or in federal custody, added by Public Law 117-103 (effective 2022) - penalty up to 15 years. Reasonable belief that the minor had attained the age of 16 is the only affirmative defence under subsection (d) (the historical marriage defence was repealed in 2022). Section 2243 fills the gap between aggravated abuse (§ 2241) and statutory minors below 12 (§ 2241(c)) for the 12-15 age cohort.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "subsection_a_sexual_abuse_of_minor_12_to_15",
        "subsection_b_sexual_abuse_of_ward",
        "subsection_c_federal_law_enforcement_officer_post_2022",
        "affirmative_defence_subsection_d_reasonable_belief_in_age",
        "marriage_defence_repealed_2022",
        "no_age_belief_defence_for_subsection_b_or_c",
        "sexual_act_definition_section_2246_2",
        "interaction_with_section_2241_aggravated_sexual_abuse",
        "interaction_with_section_2244_abusive_sexual_contact"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2241-aggravated-sexual-abuse",
      "us-18-usc-2242-sexual-abuse",
      "us-18-usc-2244-abusive-sexual-contact",
      "us-18-usc-2246-definitions-chapter-109a"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-2244-abusive-sexual-contact",
    "title": "US 18 U.S.C. § 2244 - Abusive Sexual Contact",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2244 makes it an offence to knowingly engage in 'sexual contact' (touching of intimate body parts with sexual intent) in circumstances that would violate § 2241, § 2242, or § 2243 if the conduct were a sexual act, OR to knowingly engage in sexual contact with another person without that person's permission in federal jurisdiction. Subsection (a) imposes graduated penalties keyed to the parallel sexual-act provision: (a)(1) § 2241(a)/(b) circumstances - up to 10 years; (a)(2) § 2242 circumstances - up to 3 years; (a)(3) § 2243(a) circumstances - up to 2 years; (a)(4) § 2243(b) circumstances - up to 2 years; (a)(5) § 2241(c) circumstances (under-12 aggravated) - any term or life; (a)(6) § 2243(c) federal LEO circumstances - up to 2 years. Subsection (b) imposes a residual up-to-2-year penalty for non-consensual touching. Subsection (c) doubles the maximum where the victim is under 12. Public Law 117-103 (2022) renumbered the structure to insert (a)(6) for federal LEO custodial conduct.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "subsection_a_sexual_contact_in_aggravated_circumstances",
        "subsection_b_residual_non_consent_in_federal_jurisdiction",
        "subsection_c_double_max_for_under_12_victims",
        "sexual_contact_definition_section_2246_3",
        "knowing_mens_rea",
        "interaction_with_section_2241_2242_2243_sexual_act_offences",
        "interstate_kidnapping_section_2245_complement",
        "sorna_registration_and_civil_remedies"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2241-aggravated-sexual-abuse",
      "us-18-usc-2242-sexual-abuse",
      "us-18-usc-2246-definitions-chapter-109a"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-2245-offences-resulting-in-death",
    "title": "US 18 U.S.C. § 2245 - Offences Resulting in Death (Chapter 109A and 110 Sexual Offences)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2245 provides that a person who, in the course of an offence under chapter 109A (federal sexual abuse §§ 2241-2244A) or under 18 U.S.C. §§ 1591 (sex trafficking by force/fraud/coercion), 2251, 2251A, 2260, 2421, 2422, 2423, or 2425, murders an individual, shall be punished by death or imprisoned for any term of years or for life. The provision elevates sexual offence accompanied by murder to the most serious federal offence category - functionally an aggravating circumstance for federal capital sentencing. § 2245 incorporates 18 U.S.C. § 1111 (murder) elements and operates alongside the federal death penalty statute at 18 U.S.C. § 3591 et seq.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_text",
        "incorporated_predicate_offences",
        "murder_meaning_section_1111",
        "in_the_course_of_offence_requirement",
        "death_penalty_or_life_imprisonment_or_term_of_years",
        "interaction_with_federal_death_penalty_statute",
        "interaction_with_state_law_for_concurrent_state_charges",
        "interaction_with_section_3559_e_minor_victim_mandatory_life",
        "no_separate_intent_requirement_for_murder_beyond_section_1111",
        "death_results_distinction_from_section_2248_restitution"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2241-aggravated-sexual-abuse",
      "us-18-usc-2242-sexual-abuse",
      "us-18-usc-2251-sexual-exploitation-of-children"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-2246-definitions-chapter-109a",
    "title": "US 18 U.S.C. § 2246 - Definitions for Chapter 109A (Sexual Abuse)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2246 supplies the operative definitions for the chapter 109A federal sexual abuse offences (§§ 2241-2244). Seven defined terms: (1) prison; (2) sexual act - specified contact (penile-vulvar/anal, oral-genital), penetration of anal or genital opening by hand/finger or any object with intent to abuse or gratify, or intentional under-16 genital touching with such intent; (3) sexual contact - intentional touching (direct or through clothing) of genitalia, anus, groin, breast, inner thigh, or buttocks with intent to abuse, humiliate, harass, degrade, or arouse/gratify sexual desire; (4) serious bodily injury - substantial risk of death, unconsciousness, extreme physical pain, protracted disfigurement, or protracted loss/impairment; (5) official detention; (6) State; (7) Federal law enforcement officer (cross-reference to § 115, added by Public Law 117-103 in 2022 to support § 2243(c)). These definitions are mandatory for all chapter 109A prosecutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "sexual_act_definition_paragraph_2",
        "penetration_threshold_however_slight",
        "sexual_contact_definition_paragraph_3",
        "through_clothing_sufficient_for_contact",
        "serious_bodily_injury_definition_paragraph_4",
        "prison_paragraph_1",
        "official_detention_paragraph_5",
        "state_paragraph_6",
        "federal_law_enforcement_officer_paragraph_7_post_2022",
        "definitions_apply_chapter_wide"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2241-aggravated-sexual-abuse",
      "us-18-usc-2242-sexual-abuse",
      "us-18-usc-2244-abusive-sexual-contact"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-18-usc-2247-repeat-offenders",
    "title": "US 18 U.S.C. § 2247 - Repeat Offender Enhancement for Chapter 109A Sexual Abuse Offences",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2247 provides a mandatory enhancement for federal chapter 109A sexual abuse offences (§§ 2241-2244A) where the defendant has a prior conviction for a similar federal, state, military, or foreign sexual abuse offence. The statutory maximum is doubled for repeat offenders. If the maximum is life imprisonment, that maximum stays life. The provision functions as a recidivist multiplier across the chapter and operates alongside the general federal Three Strikes statute (18 U.S.C. § 3559(c)) for serious violent felonies and the Adam Walsh Act-era enhancements. Sentencing judges apply § 2247 prior to USSG calibration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_enhancement_subsection_a",
        "exception_for_life_maximum_subsection_a_proviso",
        "prior_conviction_scope_subsection_b",
        "chapter_109a_scope",
        "interaction_with_section_3559_e_mandatory_life",
        "interaction_with_section_2426_pre_sentencing_enhancement",
        "state_offence_comparability_analysis",
        "military_offences_ucmj_article_120",
        "interaction_with_sorna_registration"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2241-aggravated-sexual-abuse",
      "us-18-usc-2242-sexual-abuse",
      "us-18-usc-2243-sexual-abuse-of-minor-or-ward",
      "us-18-usc-2244-abusive-sexual-contact"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-18-usc-2248-mandatory-restitution-chapter-109a",
    "title": "US 18 U.S.C. § 2248 - Mandatory Restitution for Chapter 109A Sexual Abuse Convictions",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2248 makes restitution mandatory for federal convictions under chapter 109A (sexual abuse offences §§ 2241-2244A). The court must order the defendant to pay the victim the full amount of the victim's losses determined by the court, in addition to any other civil or criminal penalty. 'Full amount of the victim's losses' is defined broadly to include medical services, psychiatric or psychological care, physical and occupational therapy, transportation, temporary housing, child care expenses, lost income, attorneys' fees, and any other losses suffered as a proximate result of the offence. § 2248 parallels § 2259 (chapter 110/117 mandatory restitution) and pre-empts § 3663A general mandatory restitution for chapter 109A predicate offences. The 'victim' definition extends to legal guardians for minors or incompetent victims.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "mandatory_restitution_subsection_a",
        "scope_of_recoverable_losses_subsection_b_3",
        "victim_definition_subsection_c",
        "court_determination_procedure_subsection_b_1_2",
        "interaction_with_general_restitution_section_3663a",
        "interaction_with_civil_remedy_section_2255",
        "no_offset_against_other_recovery_principle",
        "joint_and_several_liability_among_co_defendants",
        "bureau_of_prisons_collection_through_ifrp",
        "interaction_with_section_2245_offences_resulting_in_death"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2241-aggravated-sexual-abuse",
      "us-18-usc-2242-sexual-abuse",
      "us-18-usc-2243-sexual-abuse-of-minor-or-ward",
      "us-18-usc-2244-abusive-sexual-contact"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-2250-failure-to-register-sex-offender",
    "title": "US 18 U.S.C. § 2250 - Failure to Register as a Sex Offender (SORNA Enforcement)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2250 is the federal criminal enforcement provision for the Sex Offender Registration and Notification Act (SORNA, 34 U.S.C. § 20901 et seq.). Subsection (a) makes it an offence for a person required to register under SORNA who is a sex offender under federal law, or who travels in interstate or foreign commerce or enters Indian country, knowingly fails to register or update registration - penalty up to 10 years and/or fine. Subsection (b) creates a parallel international travel offence for those failing to report foreign travel as required. Subsection (c) provides an affirmative defence where uncontrollable circumstances prevented compliance and the defendant did not recklessly contribute to those circumstances and complied promptly once they ceased.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "subsection_a_general_failure_to_register",
        "subsection_b_international_travel_reporting",
        "subsection_c_affirmative_defence_uncontrollable_circumstances",
        "sorna_registration_requirements_34_usc_20913",
        "tier_system_34_usc_20911",
        "interaction_with_state_smith_v_doe_validity",
        "scope_includes_pre_sorna_offenders_carr_v_us",
        "knowledge_element_nichols_v_us",
        "interaction_with_federal_supervised_release_conditions"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2241-aggravated-sexual-abuse",
      "us-18-usc-2242-sexual-abuse",
      "us-18-usc-2251-sexual-exploitation-of-children",
      "us-18-usc-2252a-child-pornography-material"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-2251-sexual-exploitation-of-children",
    "title": "US 18 U.S.C. 2251 - Sexual Exploitation of Children",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. 2251 criminalises the sexual exploitation of children for the production of visual depictions. Subsection (a) covers employing, using, persuading, inducing, enticing or coercing any minor to engage in sexually explicit conduct for the purpose of producing or transmitting any visual depiction of such conduct. Subsection (b) covers parents, legal guardians or custodians who knowingly permit such conduct. Subsection (c) extends jurisdiction extraterritorially where the depiction is intended for or transported into the United States. Subsection (d) criminalises notices or advertisements seeking or offering such material. Penalties: first offence 15-30 years; one prior 25-50 years; two or more priors 35-life; death-resulting cases death or 30-life.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "subsection_a_production_of_visual_depictions",
        "subsection_b_parental_guardian_custodian_knowing_permission",
        "subsection_c_extraterritorial_jurisdiction",
        "subsection_d_advertising_offering_seeking",
        "subsection_e_penalties_tiered_by_prior_history",
        "minor_definition_section_2256_1",
        "sexually_explicit_conduct_definition_2256_2_a",
        "interaction_with_section_2252_and_2252a",
        "asset_forfeiture_under_section_2253_and_2254"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2252-material-involving-sexual-exploitation-minors",
      "us-18-usc-2256-definitions-csam-chapter-110"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-18-usc-2252-material-involving-sexual-exploitation-minors",
    "title": "US 18 U.S.C. 2252 - Certain Activities Relating to Material Involving Sexual Exploitation of Minors",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. 2252 criminalises four categories of conduct involving visual depictions of minors engaged in sexually explicit conduct: (1) knowing transportation or shipment using any means or facility of interstate or foreign commerce; (2) knowing receipt or distribution, or reproducing for distribution; (3) sale or possession with intent to sell; and (4) knowing possession or knowing access with intent to view. Penalties for subsections (1)-(3): 5-20 years (15-40 with prior). For subsection (4) possession/access: up to 10 years (up to 20 for prepubescent minor depictions; 10-20 with prior). § 2252 covers material that 'involves' sexual exploitation, while § 2252A covers material that 'constitutes or contains' child pornography under the broader 2256(8) definition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "subsection_a_1_transportation_shipment",
        "subsection_a_2_receipt_distribution_or_reproduction",
        "subsection_a_3_sale_or_possession_with_intent_to_sell",
        "subsection_a_4_possession_or_access_with_intent_to_view",
        "penalty_for_a_1_to_a_3_under_b_1",
        "penalty_for_a_4_under_b_2",
        "affirmative_defence_subsection_c",
        "interaction_with_section_2252a_child_pornography_definition",
        "first_amendment_constraints_ashcroft_v_free_speech_coalition"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2251-sexual-exploitation-of-children",
      "us-18-usc-2256-definitions-csam-chapter-110"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-18-usc-2252a-child-pornography-material",
    "title": "US 18 U.S.C. 2252A - Material Constituting or Containing Child Pornography",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. 2252A is the principal federal statute targeting trafficking and possession of 'child pornography' as defined in 18 U.S.C. 2256(8). Subsection (a) creates seven categories of offence: (1) mailing or transportation; (2) receipt or distribution; (3) reproduction for distribution or advertising; (4) sale or possession with intent to sell; (5) possession or access with intent to view; (6) distribution to minors to induce illegal activity; and (7) production or distribution of adapted or modified depictions of identifiable minors. Penalties for (a)(1)-(4) and (6): 5-20 years (15-40 with prior). For (a)(5): up to 10 years (up to 20 if prepubescent; 10-20 with prior). For (a)(7): up to 15 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "subsection_a_1_mailing_or_transportation",
        "subsection_a_2_receipt_distribution",
        "subsection_a_3_reproduction_advertising",
        "subsection_a_4_sale_or_possession_with_intent_to_sell",
        "subsection_a_5_possession_or_access_with_intent_to_view",
        "subsection_a_6_distribution_to_minor_for_inducement",
        "subsection_a_7_adapted_or_modified_identifiable_minor",
        "penalty_for_a_1_4_6_under_b_1",
        "penalty_for_a_5_under_b_2",
        "penalty_for_a_7_under_b_3",
        "child_pornography_definition_section_2256_8"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2251-sexual-exploitation-of-children",
      "us-18-usc-2252-material-involving-sexual-exploitation-minors",
      "us-18-usc-2256-definitions-csam-chapter-110"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-18-usc-2256-definitions-csam-chapter-110",
    "title": "18 USC § 2256 - Definitions for Chapter 110 (Sexual Exploitation of Children)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "18 USC § 2256 provides the statutory definitions governing Chapter 110 of Title 18 (sexual exploitation and other abuse of children) and underpins all CSAM-related federal offences under §§ 2251-2260A: subsection (1) defines 'minor' as any person under the age of 18 years; subsection (2)(A) defines 'sexually explicit conduct' as actual or simulated sexual intercourse (including genital-genital, oral-genital, anal-genital, or oral-anal), bestiality, masturbation, sadistic or masochistic abuse, or 'lascivious exhibition of the anus, genitals, or pubic area of any person'; subsection (2)(B) provides a narrower definition for § 2256(8)(B) computer-generated images; subsection (5) defines 'visual depiction' broadly to include undeveloped film and videotape, data stored on computer disk or by electronic means capable of conversion into a visual image, and transmitted data; subsection (8) defines 'child pornography' (CSAM) as any visual depiction of sexually explicit conduct where (A) production involves an actual minor, (B) the image is computer-generated and indistinguishable from an actual minor, or (C) the image has been digitally modified to make it appear an identifiable minor is engaged in such conduct; the definitions section is the foundational interpretive framework for federal child protection prosecutions and is referenced in §§ 2251 (production), 2252/2252A (distribution/possession), 2422/2423 (enticement), 2425 (transmitting minor identifying information), and the §§ 2258A-E provider reporting obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "chapter_110_offences_using_2256_definitions",
        "ashcroft_v_free_speech_coalition_2002",
        "ncmec_cybertipline_reporting_2258a_overlap",
        "industry_mapping",
        "enforcement_anchors",
        "morphed_image_subsection_8_c_definition"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1466a-obscene-visual-representations-csam",
      "us-18-usc-1465-production-transportation-obscene-matter",
      "us-18-usc-2257-record-keeping-explicit-content"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-2257-record-keeping-explicit-content",
    "title": "US 18 USC §2257 - Record Keeping Requirements for Producers of Sexually Explicit Visual Depictions",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "18 USC §2257 imposes federal record-keeping obligations on every producer of any book, magazine, periodical, film, videotape, digital image, or picture that contains a visual depiction of actual sexually explicit conduct as defined in 18 USC §2256(2)(A). Producers must, for every performer, examine an identification document and record the performer's legal name and date of birth, any other names ever used (including maiden, alias, nickname, stage, or professional names), and other information prescribed by Attorney General regulation. Records must be maintained at the producer's business premises (or such other place as the AG prescribes) and made available to the Attorney General for inspection at all reasonable times. Every copy of the depiction must bear a statement disclosing where the records are available. Knowing violation is punishable by imprisonment up to 5 years (10 years for repeat offenders) plus statutory fine. Subsection (g) delegates implementing rule-making authority to the Attorney General, exercised through 28 CFR Part 75.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "implementing_regulation",
        "related_statute_2257a",
        "csam_statute",
        "definitions_anchor",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-2257a-simulated-explicit-conduct-records",
    "title": "18 USC § 2257A - Records Relating to Simulated Sexually Explicit Conduct",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "18 USC § 2257A (added by Pub. L. 109-248, the Adam Walsh Child Protection and Safety Act of 2006) imposes record-keeping requirements on producers of any book, magazine, periodical, film, videotape, digital image, digitally- or computer-manipulated image of an actual human being, picture, or other matter that depicts simulated sexually explicit conduct produced in whole or in part with materials shipped or transported in interstate or foreign commerce, or that is itself shipped or transported in such commerce; producers must verify each performer's identity via government-issued photo ID, maintain records of the performer's name, date of birth, aliases, and professional names, retain records at business premises or a location designated to the Attorney General, affix labelling to all copies stating where records are located, and submit to inspection; criminal liability attaches for failure to create or maintain records, false entries, missing labels, or refusing inspection, with up to 1 year imprisonment (5 years if used to conceal substantive offences involving minors, 10 years for repeat violations); the statute provides a certification-based exemption for FCC-regulated broadcasts and certain commercial enterprises meeting specific conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "parallel_actual_explicit_statute",
        "implementing_regulations",
        "free_speech_coalition_challenges",
        "industry_mapping",
        "enforcement_anchors",
        "certification_exemption_path"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2257-record-keeping-explicit-content",
      "us-28-cfr-part-75-2257-implementing-regulations",
      "us-18-usc-1465-production-transportation-obscene-matter"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-2258a-provider-cybertipline-reporting",
    "title": "US 18 U.S.C. § 2258A - Provider Reporting Requirements to the NCMEC CyberTipline",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Providers of electronic communication services and remote computing services must, as soon as reasonably possible after obtaining actual knowledge, report apparent violations of 18 U.S.C. § 2251, § 2251A, § 2252, § 2252A, § 2252B, or § 2260 to the National Center for Missing and Exploited Children's CyberTipline. Reports must include any information within the provider's custody about the offender (email, IP address, payment information), timestamps of content upload or transmission, geographic data, the apparent CSAM visual depictions, and any complete communications containing such material. Providers must preserve reported material and metadata for one year (extended from 90 days by the 2024 amendment). Non-compliance carries civil penalties scaled to provider size, ranging from USD 600,000 for a first violation up to USD 1,000,000 for repeat violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_reporting_duty_subsection_a",
        "scope_offences_covered_paragraph_2",
        "may_report_planned_violations",
        "report_contents_subsection_b",
        "preservation_obligation_one_year_post_2024",
        "limitations_on_provider_liability_section_2258B",
        "monitoring_search_obligations_excluded_subsection_f",
        "civil_penalties_subsection_e_increased_2024",
        "ncmec_information_sharing_section_2258A_g",
        "interaction_with_eu_csam_proposed_regulation_and_uk_osa_2023"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2251-sexual-exploitation-of-children",
      "us-18-usc-2252-material-involving-sexual-exploitation-minors",
      "us-18-usc-2252a-child-pornography-material",
      "uk-online-safety-act-2023-section-66-csea-reporting-nca"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-18-usc-2258b-provider-immunity-cybertipline",
    "title": "US 18 U.S.C. § 2258B - Limited Immunity for Electronic Service Providers Reporting to CyberTipline",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2258B provides limited civil immunity for electronic service providers (and their officers, directors, employees, and agents) for performing the reporting and preservation obligations under § 2258A (CyberTipline reporting), § 2258A(b)(2) preservation, and other actions consistent with the statutory CSAM response framework. The immunity is conditioned: it does not apply where the provider engaged in intentional misconduct or acted with actual malice or reckless disregard. The provision encourages prompt provider reporting by removing the litigation risk that would otherwise deter compliance, particularly the third-party privacy claims that could arise from disclosure to NCMEC and law enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_immunity_subsection_a",
        "scope_of_covered_actions",
        "intentional_misconduct_exception_subsection_b_1",
        "intent_to_facilitate_violation_subsection_b_2",
        "policy_purpose_balance_protection_with_accountability",
        "relationship_to_section_2258a_reporting_duty",
        "relationship_to_section_2702_stored_communications_act",
        "covers_remote_computing_services_and_ecs_providers",
        "no_immunity_for_failure_to_report",
        "interaction_with_state_law_immunity_provisions"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2258a-provider-cybertipline-reporting",
      "us-18-usc-2252a-child-pornography-material"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-2259-mandatory-restitution-sexual-exploitation",
    "title": "US 18 U.S.C. § 2259 - Mandatory Restitution for Sexual Exploitation Offences",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2259 makes restitution mandatory for federal convictions under chapter 110 (sexual exploitation and other abuse of children) and chapter 117 (transportation for illegal sexual activity). The court must order restitution for the full amount of the victim's losses, including medical services, physical/occupational therapy, transportation, temporary housing, lost income, attorneys' fees, and any other losses suffered as a proximate result of the offence. The 2018 Amy, Vicky, and Andy Child Pornography Victim Assistance Act amendments provide a streamlined statutory framework for distributing trafficking-related restitution to known victims through court-mandated minimums and a victim assistance fund.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "mandatory_restitution_subsection_a",
        "scope_of_recoverable_losses_subsection_c_2",
        "victim_definition_subsection_c_4",
        "trafficking_victim_assistance_fund_subsection_d_post_2018_amva",
        "minimum_restitution_amounts_post_2018",
        "no_offset_against_civil_recovery_principle",
        "interaction_with_general_restitution_section_3663a",
        "interaction_with_paroline_v_us",
        "interaction_with_18_usc_2429_chapter_117_restitution"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2251-sexual-exploitation-of-children",
      "us-18-usc-2252a-child-pornography-material",
      "us-18-usc-2423-transportation-of-minors"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-18-usc-2260-production-for-import-into-united-states",
    "title": "US 18 U.S.C. § 2260 - Production of Sexually Explicit Depictions of a Minor for Importation into the United States",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2260 extends US criminal jurisdiction extraterritorially to two scenarios. Subsection (a) criminalises any person who, outside the United States, employs, uses, persuades, induces, entices, or coerces any minor to engage in sexually explicit conduct for the purpose of producing any visual depiction of such conduct, intending the depiction to be imported into the United States or any of its territories. Subsection (b) criminalises any person who, outside the United States, knowingly receives, transports, ships, distributes, sells, or possesses with intent to distribute any visual depiction of a minor engaging in sexually explicit conduct with intent to import into the United States. Subsection (a) violations carry the same penalties as § 2251(e); subsection (b) violations carry the same penalties as § 2252(b)(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "subsection_a_extraterritorial_production_with_import_intent",
        "subsection_b_extraterritorial_trafficking_with_import_intent",
        "penalties_subsection_c",
        "definitions_section_2256_apply",
        "complementary_to_section_2251_c_extraterritorial_subsection",
        "us_citizen_or_resident_jurisdiction_section_2423_c_complement",
        "international_enforcement_via_mlat_and_interpol",
        "forfeiture_under_section_2253_2254"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2251-sexual-exploitation-of-children",
      "us-18-usc-2252-material-involving-sexual-exploitation-minors",
      "us-18-usc-2252a-child-pornography-material"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-18-usc-2421-transportation-generally",
    "title": "US 18 U.S.C. § 2421 - Transportation Generally for Prostitution or Illegal Sexual Activity",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2421 makes it a federal offence to knowingly transport any individual in interstate or foreign commerce, or in any Territory or Possession of the United States, with intent that the individual engage in prostitution or in any sexual activity for which any person can be charged with a criminal offence. Penalty: imprisonment up to 10 years and/or fine. § 2421 is the modern descendant of the 1910 Mann Act (White-Slave Traffic Act) and operates as the general transportation provision within chapter 117 - alongside § 2422 (coercion and enticement), § 2423 (transportation of minors), and § 2425 (information transmission about minor). The provision requires only transportation with criminal sexual intent - no completed sexual activity need occur.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_subsection_a",
        "knowing_transportation_required",
        "interstate_or_foreign_commerce_jurisdictional_basis",
        "intent_to_engage_in_prostitution_or_criminal_sexual_activity",
        "attempt_liability_explicit",
        "any_person_can_be_charged_construction",
        "interaction_with_section_2422_coercion_enticement",
        "interaction_with_section_2423_transportation_of_minors",
        "interaction_with_section_2421a_fosta_promoting_prostitution",
        "originally_white_slave_traffic_act_mann_act_1910"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2422-coercion-enticement",
      "us-18-usc-2423-transportation-of-minors",
      "us-47-usc-230-e-5-fosta-sex-trafficking-carve-out"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-2421a-fosta-promoting-prostitution-online",
    "title": "18 USC 2421A - Promotion or Facilitation of Prostitution and Reckless Disregard of Sex Trafficking (FOSTA-SESTA)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "18 USC 2421A (added by the Allow States and Victims to Fight Online Sex Trafficking Act of 2017 / Stop Enabling Sex Traffickers Act, FOSTA-SESTA, Pub L 115-164) criminalises owning, managing or operating any interactive computer service using interstate or foreign commerce with intent to promote or facilitate the prostitution of another person; subsection (b) creates an aggravated 25-year offense where the conduct promotes prostitution of 5 or more persons or is committed in reckless disregard that it contributed to sex trafficking; subsection (c) creates a private civil cause of action for victims; subsection (d) mandates restitution under section 2327(b); subsection (e) provides an affirmative defense where promotion or facilitation is legal in the targeted jurisdiction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "section_230_carveout",
        "sex_trafficking_overlap",
        "mann_act_overlap",
        "industry_mapping",
        "enforcement_anchors",
        "first_amendment_anchor"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-section-230-communications-decency-act-47-usc-230"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-2422-coercion-enticement",
    "title": "18 USC 2422 - Coercion and Enticement (Interstate or Foreign Commerce Inducement; Enhanced Minor Protection)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "18 U.S.C. Section 2422 is the federal criminal statute prohibiting interstate or foreign commerce coercion or enticement of an individual to engage in prostitution or any sexual activity for which a person can be charged with a criminal offense: Section 2422(a) (general prohibition) makes it a federal crime to knowingly persuade, induce, entice, or coerce any individual to travel in interstate or foreign commerce to engage in prostitution or unlawful sexual activity, punishable by fine and imprisonment up to 20 years; Section 2422(b) (enhanced minor protection) targets the same conduct via mail or any facility or means of interstate or foreign commerce where the victim has not attained 18 years of age, carrying a mandatory minimum of 10 years and maximum of life imprisonment with fine. The statute reaches online communications (the Internet is an instrumentality of interstate commerce), and attempts to entice are punishable the same as completed offenses. Major prosecutorial use of Section 2422(b) has been against online sting operations and adults attempting to entice minors via electronic communications. The statute interacts with FOSTA-SESTA (18 USC 2421A), state coercion statutes, and the Mann Act framework (Chapter 117 of Title 18).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_framework",
        "industry_mapping",
        "criminal_penalties",
        "jurisdictional_basis",
        "platform_compliance_intersection",
        "sentencing_enhancements"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2421a-fosta-promoting-prostitution-online",
      "us-18-usc-2257-record-keeping-explicit-content",
      "uk-online-safety-act-2023-part-5-pornographic-content-duties"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-2423-transportation-of-minors",
    "title": "US 18 U.S.C. § 2423 - Transportation of Minors for Illegal Sexual Activity",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2423 creates four distinct offences. Subsection (a) makes it an offence punishable by 10 years to life imprisonment to knowingly transport a person under 18 in interstate or foreign commerce with intent that the individual engage in prostitution or any sexual activity that is a criminal offence. Subsection (b) (travel with intent) makes it an offence punishable by up to 30 years to travel in interstate or foreign commerce with intent to engage in illicit sexual conduct with another person. Subsection (c) (engaging in foreign places) makes it an offence punishable by up to 30 years for any US citizen or alien admitted for permanent residence to travel in foreign commerce, or reside abroad, and engage in illicit sexual conduct.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "subsection_a_transportation_with_intent",
        "subsection_b_travel_with_intent",
        "subsection_c_engaging_illicit_conduct_in_foreign_places",
        "definitions_subsection_g_illicit_sexual_conduct",
        "subsection_d_illicit_conduct_in_connection_with_certain_organizations",
        "subsection_e_ancillary_offences",
        "subsection_f_attempts_and_conspiracies",
        "subsection_c_affirmative_defence_within_subsection",
        "interaction_with_section_1591_sex_trafficking",
        "global_extraterritorial_reach_subsection_c"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1591-sex-trafficking-by-force-fraud-coercion",
      "us-18-usc-2422-coercion-enticement"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-18-usc-2425-transmit-minor-info-enticement",
    "title": "18 USC 2425 - Use of Interstate Facilities to Transmit Information About a Minor for Enticement to Criminal Sexual Activity",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "18 USC 2425, added by the Protection of Children from Sexual Predators Act of 1998 (Pub L 105-314), criminalises the knowing initiation of transmission of personally identifying information (name, address, telephone number, social security number, or electronic mail address) of any individual under 16 years of age via the mail or any facility or means of interstate or foreign commerce, where the transmission is made with intent to entice, encourage, offer or solicit any person to engage in any sexual activity for which any person can be charged with a criminal offense; penalty is fine and imprisonment up to 5 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "enticement_overlap",
        "csam_distribution_overlap",
        "interstate_commerce_basis",
        "industry_mapping",
        "enforcement_anchors",
        "ages_threshold_anchor"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-18-usc-2425-use-of-interstate-facilities-to-transmit-info-about-minor",
    "title": "US 18 U.S.C. § 2425 - Use of Interstate Facilities to Transmit Information About a Minor",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "18 U.S.C. § 2425 criminalises the use of any facility or means of interstate or foreign commerce, including the mail and any common carrier or interactive computer service, to knowingly initiate the transmission of the name, address, telephone number, social security number, or electronic mail address of another individual, knowing that such other individual has not attained the age of 16 years, with the intent to entice, encourage, offer, or solicit any person to engage in any sexual activity for which any person can be charged with a criminal offence. Penalty: imprisonment up to 5 years and/or fine. The provision targets the transmission of identifying information about minors as part of sex offence facilitation - the inverse mirror to § 2422 (coercion and enticement) which targets contact with the minor.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "core_offence_text",
        "facility_of_interstate_commerce_broad_jurisdiction",
        "knowing_initiation_of_transmission",
        "specified_categories_of_identifying_information",
        "knowledge_of_age_under_16_required",
        "intent_to_facilitate_sexual_offence",
        "interaction_with_section_2422_b_coercion_enticement",
        "interaction_with_section_2423_b_travel",
        "interaction_with_18_usc_1591_sex_trafficking_of_minors",
        "attempt_liability_explicit_in_statute"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2251-sexual-exploitation-of-children",
      "us-18-usc-2423-transportation-of-minors",
      "us-47-usc-230-e-5-fosta-sex-trafficking-carve-out"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-2701-sca-unlawful-access-stored-communications",
    "title": "US Title 18 - 18 USC 2701 Stored Communications Act Unlawful Access to Stored Communications",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 2701 titled 'Unlawful access to stored communications' is the Stored Communications Act provision criminalizing intentional unauthorized access to electronic communication service facilities to obtain, alter, or prevent authorized access to wire or electronic communications in electronic storage. Subsection (a) provides that whoever (1) intentionally accesses without authorization a facility through which an electronic communication service is provided; or (2) intentionally exceeds an authorization to access that facility; and thereby obtains, alters, or prevents authorized access to a wire or electronic communication while it is in electronic storage in such system shall be punished as provided in subsection (b). Subsection (b) sets penalties at: (1) if the offense is committed for purposes of commercial advantage, malicious destruction or damage, private commercial gain, or in furtherance of any criminal or tortious act in violation of the Constitution or laws of the United States or any State, a fine under title 18 or imprisonment for not more than 5 years (or 10 years for a second or subsequent offense), or both; (2) in any other case, a fine under title 18 or imprisonment for not more than 1 year (or 5 years for a second or subsequent offense), or both. Subsection (c) provides three exceptions: (1) conduct authorized by the person or entity providing a wire or electronic communications service; (2) conduct authorized by a user of that service with respect to a communication of or intended for that user; or (3) conduct authorized in sections 2703, 2704, or 2518 of this title. Section 2701 is the principal federal criminal protection against unauthorized access to electronic communications held by service providers such as email systems, messaging platforms, and cloud storage services, and operates in tandem with sections 2702 (voluntary disclosure prohibitions) and 2703 (government required disclosure procedures) within the Stored Communications Act framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-stored-communications-act"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-18-usc-2702-sca-voluntary-disclosure-customer-communications-records",
    "title": "US Title 18 - 18 USC 2702 Stored Communications Act Voluntary Disclosure of Customer Communications or Records",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 2702 titled 'Voluntary disclosure of customer communications or records' is the Stored Communications Act provision regulating when a provider of an electronic communication service or a remote computing service to the public may voluntarily divulge the contents of customer communications or customer records. Subsection (a) provides the general prohibitions: (1) a person or entity providing an electronic communication service to the public shall not knowingly divulge to any person or entity the contents of a communication while in electronic storage by that service; (2) a person or entity providing remote computing service to the public shall not knowingly divulge to any person or entity the contents of any communication which is carried or maintained on that service; (3) a provider of electronic communication service or remote computing service shall not knowingly divulge a record or other information pertaining to a subscriber to or customer of such service to any governmental entity. Subsection (b) lists the exceptions permitting voluntary disclosure of contents: to an addressee or intended recipient or their agent; as otherwise authorized in sections 2517, 2511(2)(a), or 2703; with the lawful consent of the originator or addressee or intended recipient (or subscriber for remote computing service); as may be necessarily incident to the rendition of the service or to the protection of the rights or property of the provider; to the National Center for Missing and Exploited Children; to a law enforcement agency where the contents were inadvertently obtained by the provider and appear to pertain to the commission of a crime; or to a governmental entity if the provider, in good faith, believes that an emergency involving danger of death or serious physical injury to any person requires disclosure without delay. Subsection (c) lists the exceptions permitting voluntary disclosure of customer records to governmental entities including as authorized in section 2703; with the lawful consent of the customer or subscriber; as necessarily incident to the rendition of the service or to the protection of the rights or property of the provider; in connection with reports of child exploitation; to non-governmental entities; and under foreign government orders meeting executive agreement standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-stored-communications-act"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-18-usc-2703-sca-required-disclosure-customer-records",
    "title": "US Title 18 - 18 USC 2703 Stored Communications Act Required Disclosure of Customer Communications or Records",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 2703 titled 'Required disclosure of customer communications or records' is the Stored Communications Act provision setting the legal process required for governmental access to the contents of stored electronic communications and to non-content customer records held by electronic communication service or remote computing service providers. Subsection (a) governs contents in electronic storage of 180 days or less: a governmental entity may require the disclosure by a provider of electronic communication service of the contents of a wire or electronic communication, that is in electronic storage in an electronic communications system for 180 days or less, only pursuant to a warrant issued using the procedures described in the Federal Rules of Criminal Procedure (or, in the case of a State court, issued using State warrant procedures) by a court of competent jurisdiction. Subsection (b) governs contents older than 180 days and remote computing service contents: a governmental entity may require disclosure by a provider with prior notice from the governmental entity to the subscriber or customer if the entity uses an administrative subpoena, a Federal or State grand jury or trial subpoena, or a court order issued under subsection (d); or without prior notice via a warrant. Subsection (c) governs non-content records and other information pertaining to a subscriber or customer: a governmental entity may require disclosure of subscriber name, address, local and long distance telephone connection records (or session times and durations), length of service, types of service utilized, telephone or instrument number or other subscriber number or identity, and means and source of payment, by use of an administrative subpoena, a Federal or State grand jury or trial subpoena, a court order under subsection (d), a warrant, or with the consent of the subscriber. Subsection (d) provides the court order standard: a court order may issue only if the governmental entity offers specific and articulable facts showing that there are reasonable grounds to believe that the contents of a wire or electronic communication, or the records or other information sought, are relevant and material to an ongoing criminal investigation. Subsection (g) provides that the presence of an officer shall not be required for service or execution of a search warrant issued under this section requiring disclosure by a provider of electronic communications service.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-stored-communications-act"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-18-usc-371-conspiracy-to-commit-offense-or-defraud-united-states",
    "title": "US Federal Criminal Code - 18 USC 371 Conspiracy to Commit Offense or to Defraud United States",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "18 USC 371 is the federal general conspiracy statute. The verbatim text provides: if two or more persons conspire either to commit any offense against the United States, or to defraud the United States, or any agency thereof in any manner or for any purpose, and one or more of such persons do any act to effect the object of the conspiracy, each shall be fined under this title or imprisoned not more than five years, or both. If, however, the offense, the commission of which is the object of the conspiracy, is a misdemeanor only, the punishment for such conspiracy shall not exceed the maximum punishment provided for such misdemeanor. Section 371 contains two distinct conspiracy offenses: (1) the offense clause, criminalizing agreements to commit any federal offense, with the substantive offense becoming the underlying offense of the conspiracy charge; and (2) the defraud clause, criminalizing agreements to defraud the United States or any agency thereof in any manner or for any purpose. The defraud clause has been construed broadly in Hammerschmidt v. United States, 265 US 182 (1924), to reach any conspiracy to interfere with or obstruct one of the lawful governmental functions of the United States by deceit, craft, or trickery, or at least by means that are dishonest. Section 371 requires proof of: (1) an agreement between two or more persons, (2) to commit an offense against the United States or to defraud the United States, (3) knowing and willful participation in the conspiracy by the defendant, and (4) at least one overt act in furtherance of the conspiracy. Section 371 is frequently charged in white-collar prosecutions (Klein conspiracies under the defraud clause, FCPA conspiracies, healthcare fraud conspiracies, tax conspiracies) and is the workhorse of federal multi-defendant prosecutions because each conspirator is liable for the substantive offenses of co-conspirators committed in furtherance of and reasonably foreseeable from the conspiracy under Pinkerton v. United States, 328 US 640 (1946).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1001-false-statements-federal-officers"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-18-usc-656-bank-officer-embezzlement",
    "title": "18 U.S.C. 656 - Theft, Embezzlement or Misapplication by Bank Officer or Employee",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "18 U.S.C. 656 criminalises theft, embezzlement, abstraction, purloining or willful misapplication of moneys, funds, credits, securities or other things of value by an officer, director, agent or employee of, or person connected in any capacity with, a Federal Reserve bank, member bank, depository institution holding company, national bank, insured bank, or branch or agency of a foreign bank. The penalty is a fine up to $1,000,000 or imprisonment up to 30 years, or both, reduced to up to one year where the amount does not exceed $1,000.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1344-bank-fraud",
      "us-18-usc-1956-money-laundering-monetary-instruments",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-18-usc-657-insurance-credit-institution-embezzlement",
    "title": "18 U.S.C. 657 - Lending, Credit and Insurance Institutions (Embezzlement and Misapplication)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "18 U.S.C. 657 criminalises embezzlement, abstraction, purloining or willful misapplication of moneys, funds, credits, securities or other things of value by an officer, agent or employee of, or person connected in any capacity with, specified lending, credit and insurance institutions, including FDIC, NCUA, Federal home loan banks, the Federal Housing Finance Agency, Farm Credit Administration entities, the Federal Crop Insurance Corporation, and lending, mortgage, insurance, credit or savings institutions under U.S. law. The penalty is a fine up to $1,000,000 or imprisonment up to 30 years, or both, reduced to up to one year where the amount does not exceed $1,000.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1956-money-laundering-monetary-instruments",
      "fatf-recommendation-3-money-laundering-offence",
      "us-18-usc-1344-bank-fraud"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-21-cfr-part-11-electronic-records-electronic-signatures",
    "title": "21 CFR Part 11 - Electronic Records; Electronic Signatures",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This regulation establishes the US Food and Drug Administration (FDA) criteria under which electronic records and electronic signatures are considered trustworthy, reliable, and equivalent to paper records and handwritten signatures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-21-cfr-part-111-dietary-supplements-cgmp",
    "title": "US 21 CFR Part 111: Current Good Manufacturing Practice in Manufacturing, Packaging, Labeling, or Holding Operations for Dietary Supplements",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 111 establishes the cGMP requirements for manufacturers, packagers, labelers, and holders of dietary supplements. Subparts cover personnel, physical plant and grounds, equipment and utensils, production and process controls, identity testing of components prior to use, master manufacturing record (MMR), batch production record (BPR), laboratory operations, manufacturing operations, packaging and labeling, holding and distribution, returned dietary supplements, product complaints, and records. Manufacturers must verify the identity of each component used in the dietary supplement before release of the finished batch.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "dshea",
        "cfr_21_117",
        "fdca",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-117-fsma-preventive-controls-human-food",
    "title": "US 21 CFR Part 117: Current Good Manufacturing Practice, Hazard Analysis, and Risk-Based Preventive Controls for Human Food",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 117 implements the FDA Food Safety Modernization Act (FSMA) preventive controls rule for human food. Facilities must conduct a hazard analysis identifying known or reasonably foreseeable biological, chemical, and physical hazards; establish written preventive controls (process, food allergen, sanitation, supply-chain, and recall plan) to significantly minimize or prevent those hazards; monitor, verify, and document the controls; and review records under a Food Safety Plan. The plan must be prepared or overseen by a Preventive Controls Qualified Individual (PCQI). Part 117 also retains the cGMP requirements in Subpart B for personnel, plant, equipment, and process controls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fsma",
        "cfr_21_507",
        "haccp_codex",
        "cfr_21_110",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-123-fish-fishery-products-haccp",
    "title": "US 21 CFR Part 123: Fish and Fishery Products (HACCP)",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 123 prescribes the procedures whereby processors of fish and fishery products must conduct a Hazard Analysis Critical Control Point (HACCP) system to ensure safe and sanitary processing. Each processor must conduct a hazard analysis to determine food safety hazards reasonably likely to occur, develop a written HACCP plan listing the hazards and critical control points (CCPs), establish critical limits, monitoring procedures, corrective actions, verification activities, and recordkeeping. Importers must verify products imported from foreign processors are processed in accordance with HACCP requirements equivalent to Part 123.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_21_117",
        "haccp_codex",
        "fdca",
        "cfr_21_120",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-1308-dea-schedules-controlled-substances",
    "title": "US 21 CFR Part 1308: Schedules of Controlled Substances (DEA)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 1308 implements the Controlled Substances Act (CSA) Schedules I through V by listing controlled substances by chemical identity and scheduling status. Schedule I substances have no currently accepted medical use and high abuse potential (heroin, LSD, cannabis, MDMA federally). Schedule II includes drugs with high abuse potential but accepted medical use (oxycodone, fentanyl, methylphenidate, amphetamine). Schedule III IV V have decreasing abuse potential. Part 1308 also addresses temporary scheduling under 21 USC 811(h), exempt anabolic steroid products, and addition/removal/transfer between schedules via rulemaking with DEA Administrator notice and HHS scientific recommendation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "csa",
        "cfr_21_1300",
        "cfr_21_1301",
        "cfr_21_1304",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-207-drug-establishment-registration",
    "title": "US 21 CFR Part 207: Drug Establishment Registration and Drug Listing",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 207 requires owners and operators of all drug establishments to register with the FDA and submit information about each drug they manufacture, repack, relabel, or salvage. The regulation covers initial registration, annual renewal, drug listing in the Structured Product Labeling (SPL) format submitted via the Electronic Submissions Gateway (ESG), and notification of changes. It applies to domestic establishments and to foreign establishments that import drugs into the US. Registration grants an FDA Establishment Identifier (FEI) used for inspections and enforcement. Compliance is foundational to lawful US drug commerce and is verified during FDA inspections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fdca",
        "cfr_21_211",
        "spl_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-210-cgmp-general-provisions",
    "title": "US 21 CFR Part 210: Current Good Manufacturing Practice in Manufacturing Processing Packing or Holding of Drugs - General",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 210 establishes the general provisions and definitions for current good manufacturing practice (cGMP) regulations under the Federal Food Drug and Cosmetic Act. The regulation defines key terms (active ingredient, batch, component, drug product, lot, manufacture, quality control unit) and the scope of cGMP application to manufacturing, processing, packing, or holding of drugs. It cross-references Part 211 (finished pharmaceuticals), Part 212 (PET drugs), and Part 226 (medicated articles). Compliance is foundational to FDA drug manufacturing and is verified during routine inspections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_21_211",
        "cfr_21_212",
        "cfr_21_226",
        "cfr_21_820",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-211-cgmp-finished-pharmaceuticals",
    "title": "US 21 CFR Part 211: Current Good Manufacturing Practice for Finished Pharmaceuticals",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 211 prescribes the cGMP requirements for finished pharmaceuticals manufactured, processed, packed, or held in the US. Subparts cover organization and personnel, buildings and facilities, equipment, control of components, production and process controls, packaging and labeling, holding and distribution, laboratory controls, records and reports, returned and salvaged drug products. FDA inspectors evaluate establishments against Part 211 during pre-approval inspections and routine surveillance. Non-compliance findings drive Form FDA 483 observations, Warning Letters, consent decrees, and import alerts. Part 211 is the operational backbone of US drug quality assurance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fdca",
        "cfr_21_210",
        "cfr_21_207",
        "ich_q7",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-312-investigational-new-drug",
    "title": "US 21 CFR Part 312: Investigational New Drug Application",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 312 sets requirements for the Investigational New Drug (IND) application process governing clinical investigation of drugs and biologics in humans. The regulation covers IND content (Forms FDA 1571 and 1572, protocols, nonclinical studies, CMC, prior human experience), 30-day FDA review with automatic safe-to-proceed clearance, sponsor responsibilities including IND safety reports and annual reports, investigator responsibilities, FDA clinical hold authority, and emergency expanded access (compassionate use). Compliance is foundational to every drug clinical trial in the US.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_21_50",
        "cfr_21_56",
        "cfr_21_314",
        "ich_e6",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-314-applications-fda-approval-new-drug",
    "title": "US 21 CFR Part 314: Applications for FDA Approval to Market a New Drug",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 314 sets requirements for New Drug Application (NDA) and Abbreviated New Drug Application (ANDA) submissions to FDA for marketing approval. The regulation covers NDA content (clinical and nonclinical studies, CMC, labelling, patent information), review timelines, approval letters and refuse-to-file determinations, postmarketing requirements (REMS, post-approval studies, annual reports), generic ANDA bioequivalence demonstration, and 505(b)(2) hybrid applications. Compliance is the final regulatory milestone for US drug marketing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_21_312",
        "cfr_21_320",
        "cfr_21_201",
        "pdufa",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-320-bioavailability-bioequivalence",
    "title": "US 21 CFR Part 320: Bioavailability and Bioequivalence Requirements",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 320 sets the requirements for demonstrating bioavailability (BA) and bioequivalence (BE) for drug products submitted under NDA, ANDA, INDs, and supplements. The regulation defines BA as the rate and extent to which the active ingredient is absorbed and becomes available at the site of action, and BE as the absence of significant difference in BA between two pharmaceutically equivalent products under similar experimental conditions. Subpart B addresses procedures for waiver of in vivo BA/BE studies (biowaivers per BCS), Subpart C covers in vivo BE study procedures including crossover design and pharmacokinetic measurements, and Subpart D addresses retention of bioequivalence test samples. Compliance is foundational to ANDA approval and to NDA postapproval product changes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_21_314",
        "ich_m9",
        "fda_bcs_guidance",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-50-protection-human-subjects",
    "title": "US 21 CFR Part 50: Protection of Human Subjects",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 50 sets requirements for informed consent of human subjects in FDA-regulated clinical investigations of drugs, biologics, devices, and other products. The regulation covers general requirements for informed consent including 8 basic elements and 6 additional elements, additional safeguards for children, exception from informed consent for emergency research, and IRB-related provisions cross-referenced to Part 56. Compliance is foundational to every IND, IDE, and BLA clinical study and is verified during FDA bioresearch monitoring inspections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_21_56",
        "cfr_45_46",
        "ich_e6",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-50-protection-human-subjects-fda",
    "title": "US 21 CFR Part 50: Protection of Human Subjects (FDA-Regulated Research)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 50 establishes FDA regulations for the protection of human subjects in clinical investigations regulated by FDA including investigations supporting marketing applications for drugs biologics medical devices and tobacco products. Part 50 covers informed consent requirements (Subpart B); exception from informed consent in emergency research (Subpart B 50.24); additional safeguards for pregnant women fetuses and neonates (Subpart D); children (Subpart D); and prisoners (Subpart C). The FDA framework parallels the Common Rule (45 CFR Part 46) but with FDA-specific provisions for IND/IDE studies. 21 CFR Part 56 contains the parallel IRB regulations for FDA-regulated research.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fdca",
        "cfr_21_56",
        "cfr_45_46",
        "cfr_21_312",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-56-institutional-review-boards",
    "title": "US 21 CFR Part 56: Institutional Review Boards",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 56 sets requirements for IRB membership, functions, operations, review of research, recordkeeping, and IRB-related submissions and approvals for FDA-regulated clinical investigations. The regulation covers IRB composition including non-affiliated and non-scientific members, expedited review categories, criteria for approval (risk minimisation, equitable selection, informed consent, data monitoring, privacy), continuing review at intervals appropriate to risk, suspension or termination, and FDA registration of IRBs. Compliance is verified during FDA bioresearch monitoring inspections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_21_50",
        "cfr_21_312",
        "cfr_45_46",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-600-biological-products-general",
    "title": "US 21 CFR Part 600: Biological Products: General",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 600 sets out general requirements for the regulation of biological products including establishment standards, inspection authority of FDA, reporting of adverse experiences and biological product deviations, and post-distribution lot release for products listed by CBER. Part 600 applies to vaccines, blood and blood components, allergenic extracts, and related biologics manufactured under a Biologics License Application (BLA). Manufacturers must permit FDA inspections at reasonable times and submit biological product deviation reports under 600.14 within 45 calendar days of discovery. Failure to comply triggers BLA suspension or revocation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "phsa",
        "cfr_21_601",
        "cfr_21_610",
        "cfr_21_211",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-803-medical-device-reporting-mdr",
    "title": "21 CFR Part 803 - Medical Device Reporting",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This regulation establishes mandatory requirements for manufacturers, importers, and user facilities of medical devices to report certain device-related adverse events and product problems to the FDA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-21-cfr-part-806-corrections-removals-medical-devices",
    "title": "US 21 CFR Part 806: Medical Devices - Reports of Corrections and Removals",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 806 requires manufacturers and importers of medical devices to report to FDA corrections and removals undertaken to reduce a risk to health or to remedy a violation of the FDCA. The regulation distinguishes between actions reportable within 10 working days (Class I and Class II recalls and field corrections) and actions not reportable but subject to recordkeeping. Compliance is foundational to FDA recall classification system and Class I (most serious) Class II (moderate) Class III (low) recall framework. Records must be maintained for 2 years past date of corrective action.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_21_7",
        "cfr_21_803",
        "cfr_21_820",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-814-premarket-approval-medical-devices",
    "title": "US 21 CFR Part 814: Premarket Approval of Medical Devices",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 814 sets requirements for Premarket Approval (PMA) applications for Class III medical devices and supplements. PMA is the most stringent FDA device pathway requiring scientific evidence of safety and effectiveness. The regulation covers PMA content, FDA review timeline (180-day clock with Advisory Committee referral), approval order conditions including postmarket study requirements, supplement categories (panel-track 180-day, special, real-time), and Humanitarian Device Exemption (HDE) pathway. Compliance is foundational for high-risk device commercialisation in the US.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fdca_section_515",
        "cfr_21_820",
        "cfr_21_822",
        "ide_part_812",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21-cfr-part-822-postmarket-surveillance",
    "title": "US 21 CFR Part 822: Postmarket Surveillance for Medical Devices",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 21 CFR Part 822 implements FDA Section 522 postmarket surveillance authority for medical devices. FDA may order surveillance for Class II or III devices whose failure could have serious consequences, that are expected to have significant use in paediatrics, or that are intended to be implanted in the body for more than one year. The regulation covers order content, surveillance plan submission and approval, conduct of surveillance, reports, and remedies for non-compliance including additional surveillance and approval consequences. Compliance is mandatory once FDA issues a surveillance order.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fdca_section_522",
        "cfr_21_814",
        "cfr_21_803",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-21st-century-cures-act-2016",
    "title": "21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program (45 CFR Parts 170 and 171)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This regulation prohibits practices likely to interfere with, prevent, or materially discourage the access, exchange, or use of electronic health information (EHI) by healthcare providers, health IT developers, and health information networks/exchanges, as defined in 45 CFR § 171.103. It mandates the adoption of standardized APIs, primarily FHIR, to facilitate secure and seamless data access for patients and other authorized parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-privacy-rule",
      "hipaa-security-rule",
      "hl7-fhir-v4-interop",
      "fda-21-cfr-part-11-records"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-22-cfr-part-122-itar-registration-manufacturers-exporters",
    "title": "22 CFR Part 122 ITAR Registration",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "22 CFR Part 122 of the International Traffic in Arms Regulations (ITAR) establishes the registration requirement administered by the US Department of State Directorate of Defense Trade Controls (DDTC). Section 122.1 requires any person who engages in the United States in the business of manufacturing or exporting or temporarily importing defense articles, or furnishing defense services, to register with the Directorate of Defense Trade Controls; registration is a precondition to the issuance of any license or other approval. Section 122.2 governs submission of the Statement of Registration (Department of State form DS-2032) to the Office of Defense Trade Controls Compliance, together with certification, the frequency of registration, renewal, and lapse. Section 122.4 requires notification of changes in information furnished by registrants, with written notification required within five days of specified events such as changes in ownership, name, or address. Section 122.5 requires maintenance of records by registrants for a period of five years from the expiration of the license or other approval, with the records made available for inspection by authorised government entities. Registration does not itself confer any export authorisation; it is the foundational eligibility step that precedes licensing under Parts 123, 124, and 125.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-arms-export-control-act",
      "us-22-cfr-part-123-itar-licenses-export-temporary-import-defense-articles",
      "itar-compliance-workflow"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-22-cfr-part-123-itar-licenses-export-temporary-import-defense-articles",
    "title": "22 CFR Part 123 ITAR Licenses",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "22 CFR Part 123 of the International Traffic in Arms Regulations (ITAR) governs licenses for the export and temporary import of defense articles, administered by the US Department of State Directorate of Defense Trade Controls (DDTC). Section 123.1 (Requirement for export or temporary import licenses) requires any person who intends to export or temporarily import a defense article to obtain the approval of the Directorate of Defense Trade Controls prior to the export or temporary import, unless the transaction qualifies for an exemption under the subchapter. Section 123.10 (Nontransfer and use assurances) requires a nontransfer and use certificate (Form DSP-83) for the export of significant military equipment and classified articles, including classified technical data, pursuant to a license or other authorization, except for the exemptions in Sections 126.5 and 126.7. Section 123.21 (Duration, renewal, and disposition of licenses) provides that a license is valid for four years and that the license expires when the total value or quantity authorized has been shipped or when the date of expiration has been reached, whichever occurs first. Section 123.22 (Filing, retention, and return of export licenses and filing of export information) requires the electronic reporting of export information for any export of a defense article controlled by the subchapter, including defense articles transiting the United States. Compliance requires obtaining the correct license before export, securing the required end-use assurances, observing the four-year validity, and filing the required electronic export information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-arms-export-control-act",
      "us-22-cfr-part-122-itar-registration-manufacturers-exporters",
      "us-22-cfr-part-126-itar-general-policies-and-provisions",
      "itar-compliance-workflow"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-22-cfr-part-126-itar-general-policies-and-provisions",
    "title": "ITAR 22 CFR Part 126 - General Policies and Provisions including Section 126.1 Embargoes and AUKUS/UK/Canada Defense Trade Exemptions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "22 CFR Part 126 of the International Traffic in Arms Regulations (ITAR) contains the general policies and provisions that overlay the item-based controls of the United States Munitions List in Part 121 and the licensing requirements in Parts 123-125, administered by the Department of State Directorate of Defense Trade Controls (DDTC) under the Arms Export Control Act (22 USC 2778). Section 126.1 establishes the embargoed-destination policy of denial - prohibiting the export, reexport, retransfer, or temporary import of any defense article or service to or from a section 126.1(d) listed country: as of 2025 this comprehensive list includes the People's Republic of China, Cuba, Iran, North Korea, Syria, Russia, Belarus, Venezuela, Zimbabwe, Myanmar/Burma, Central African Republic, Cyprus, Democratic Republic of the Congo, Eritrea, Haiti, Iraq, Lebanon, Libya, Sudan, South Sudan, Somalia, Vietnam (Section 38(g) of AECA), and Yemen with country-specific carve-outs. Section 126.2 grants the Assistant Secretary of State for Political-Military Affairs authority to temporarily suspend, modify, or revoke any registration or license. Section 126.4 covers transfers by or for the United States Government. Section 126.5 provides Canadian exemptions for end-user transfers to Canadian-registered persons. Section 126.7 governs denial, revocation, suspension, or amendment of licenses. Section 126.10 establishes the foreign government end-user disclosure requirement. Section 126.13 requires certifications regarding political contributions, fees, and commissions. Section 126.15 provides expedited processing for emergency situations. Section 126.16 implements the Defense Trade Cooperation Treaty with Australia (effective May 2013). Section 126.17 implements the Defense Trade Cooperation Treaty with the United Kingdom (effective 2012). Section 126.18 covers intra-company, intra-organisation, and intra-government transfers exemptions. The AUKUS Defense Trade Cooperation Exemption (effective 1 September 2024 under section 126.7 and Supplements) creates a comprehensive license-free export environment among approved Australian and UK persons for ITAR-controlled items subject to enrolment in DDTC's authorised user list. Civil penalties up to USD 1,272,251 per violation under 22 USC 2778(e) (2025 inflation adjustment), criminal penalties up to USD 1,000,000 and 20 years imprisonment under 22 USC 2778(c), administrative debarment under section 127.7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "section_126_1_embargoed_destinations_2025_list",
        "aukus_defense_trade_cooperation_exemption_2024_section_126_7",
        "section_126_13_anti_corruption_certifications_required"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-itar-22-cfr-120-130-arms-export",
      "us-arms-export-control-act",
      "us-15-cfr-part-740-ear-license-exceptions",
      "us-15-cfr-part-744-ear-entity-list-end-user-end-use-controls"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-22-cfr-part-127-itar-violations-penalties-enforcement",
    "title": "22 CFR Part 127 ITAR Violations and Penalties",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "22 CFR Part 127 of the International Traffic in Arms Regulations (ITAR) sets out the violations, penalties, and enforcement framework administered by the US Department of State Directorate of Defense Trade Controls (DDTC). Section 127.1 (Violations) identifies the unlawful acts, including exporting or attempting to export defense articles or furnishing defense services without the required license or other approval and conspiring to violate the controls. Section 127.3 (Penalties for violations) provides that willful violations are subject to a fine or imprisonment, or both, as prescribed by 22 USC 2778(c) of the Arms Export Control Act. Section 127.7 (Debarment) provides for administrative and statutory debarment, including statutory debarment of persons convicted of violating the Arms Export Control Act. Section 127.10 (Civil penalty) provides that the maximum civil penalty for a violation of 22 USC 2778 may not exceed the greater of $1,271,078 or the amount that is twice the value of the transaction. Section 127.12 (Voluntary disclosures) establishes the Department policy strongly encouraging the disclosure of suspected violations, which is considered a mitigating factor in determining administrative penalties. Effective compliance requires recognising the categories of violation, preserving evidence on discovery of a potential violation, evaluating timely voluntary disclosure, and applying the correct civil and criminal exposure when assessing risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-arms-export-control-act",
      "us-22-cfr-part-122-itar-registration-manufacturers-exporters",
      "us-22-cfr-part-123-itar-licenses-export-temporary-import-defense-articles",
      "itar-compliance-workflow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-24-cfr-part-35-hud-lead-based-paint-poisoning-prevention",
    "title": "24 CFR Part 35 - HUD Lead-Based Paint Poisoning Prevention in Certain Residential Structures (Lead Safe Housing Rule)",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2025-06-01",
    "bluf": "Sellers, lessors, and managers of target housing - any housing constructed prior to 1978 other than the narrow exceptions in 24 CFR 35.110 - must provide each purchaser or lessee with an EPA-approved lead hazard information pamphlet, disclose all known lead-based paint and lead-based paint hazards and supply available records and reports, attach the prescribed Lead Warning Statement to every sales contract or lease, and where federal financial assistance triggers Subparts F through M, apply the appropriate lead hazard evaluation and reduction activity tier - paint stabilization or safe work practices up to $5,000 per unit, interim controls for $5,000 to $25,000 per unit, and abatement of lead-based paint hazards over $25,000 per unit - completing each cycle with a clearance examination under Subpart R that confirms no soil-lead hazards or settled dust-lead hazards exist.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-epa-40-cfr-711-tsca-chemical-data-reporting",
      "us-real-estate-settlement-procedures-act"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-24-cfr-part-982-section-8-housing-choice-voucher",
    "title": "US 24 CFR Part 982: Section 8 Tenant-Based Assistance Housing Choice Voucher Program",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 24 CFR Part 982 implements the Section 8 Housing Choice Voucher (HCV) program through which Public Housing Agencies (PHAs) assist very low-income families to afford decent safe sanitary housing in the private market. HUD funds PHAs which issue vouchers to eligible families; families select housing meeting HUD Housing Quality Standards (HQS); PHA executes Housing Assistance Payment (HAP) contract with landlord and pays subsidy directly to landlord; family pays portion of rent based on income (typically 30% adjusted income). Part 982 covers PHA administration, family eligibility selection and admission, occupancy housing search and selection, HQS inspections, HAP contract administration, lease, family obligations and termination, and program management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "hca_1937",
        "cfr_24_5",
        "cfr_24_966",
        "cfr_24_888",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-26-usc-482-transfer-pricing",
    "title": "26 USC § 482 - Allocation of Income and Deductions (US Transfer Pricing Authority)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "26 USC § 482 (originally enacted as § 45 of the Revenue Act of 1928, recodified into Internal Revenue Code; substantially modified by Tax Reform Act of 1986 with the addition of the commensurate-with-income standard) grants the Internal Revenue Service the authority to distribute, apportion, or allocate gross income, deductions, credits, or allowances between or among two or more organizations, trades, or businesses (whether or not incorporated, organized in the United States, or affiliated) owned or controlled directly or indirectly by the same interests, in any case in which the Secretary determines that such distribution, apportionment, or allocation is necessary in order to prevent evasion of taxes or clearly to reflect the income of any of such organizations, trades, or businesses; the Tax Reform Act of 1986 added the commensurate-with-income standard requiring that 'in the case of any transfer (or license) of intangible property, the income with respect to such transfer or license shall be commensurate with the income attributable to the intangible'; the section authorizes the Secretary to require valuation on an aggregate basis or based on realistic alternatives where this represents the most dependable measure; implementing regulations at 26 CFR §§ 1.482-1 through 1.482-9 codify the arm's-length standard methods including comparable uncontrolled price (CUP), comparable profits method (CPM), profit split method (PSM), services cost method (SCM), and specified methods for tangible property, intangible property, services, and loans.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "transfer_pricing_regulations_26_cfr_1_482",
        "oecd_transfer_pricing_guidelines",
        "section_6038a_intersection",
        "industry_mapping",
        "enforcement_anchors",
        "section_6662e_penalty_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-26-usc-6038a-foreign-owned-corporations-reporting",
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-26-usc-6038a-foreign-owned-corporations-reporting",
    "title": "26 USC § 6038A - Information Reporting for 25-Percent Foreign-Owned Corporations",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "26 USC § 6038A (enacted by Pub. L. 101-239 and substantially expanded by subsequent statutes including the Tax Cuts and Jobs Act of 2017 amendments related to BEAT) requires domestic corporations that are 25-percent foreign-owned to file Form 5472 and maintain records about related-party transactions: subsection (a) imposes reporting requirements including name, principal place of business, nature of business, and country/countries of organization or residence of each related party; the relationship between the reporting corporation and each related party; and transactions between the reporting corporation and each foreign person which is a related party; the section also requires reporting of base erosion payments under section 59A for BEAT purposes; subsection (b) requires record maintenance in the location, in the manner, and to the extent prescribed in regulations; subsection (c) defines reporting corporation as 25-percent foreign-owned during any taxable year if 25 percent or more of the total voting power or value of the corporation's stock is owned at any time during the taxable year by one foreign person, directly or constructively; subsection (d) provides penalties for failure to furnish information or maintain records: initial $25,000 per taxable year and additional $25,000 per 30-day period of continued noncompliance after 90 days following IRS notice; reasonable cause exception delays penalty accrual when justified.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "form_5472_filing_obligation",
        "section_482_transfer_pricing_intersection",
        "section_59A_base_erosion_intersection",
        "industry_mapping",
        "enforcement_anchors",
        "constructive_ownership_rules"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-26-usc-482-transfer-pricing",
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-26-usc-6050i-cash-receipts-over-10000-trade-or-business",
    "title": "US Internal Revenue Code - 26 USC 6050I Returns Relating to Cash Received in Trade or Business (Form 8300 Reporting)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "26 USC 6050I titled 'Returns relating to cash received in trade or business, etc.' is the principal Internal Revenue Code provision requiring any person engaged in a trade or business who, in the course of such trade or business, receives more than $10,000 in cash in 1 transaction (or 2 or more related transactions) to file an information return (Form 8300) with the Secretary of the Treasury. Subsection (a) provides the reporting requirement: any person who is engaged in a trade or business, and who, in the course of such trade or business, receives more than $10,000 in cash in 1 transaction (or 2 or more related transactions), shall make the return described in subsection (b) with respect to such transaction (or related transactions) at such time as the Secretary may by regulations prescribe. Subsection (b) requires the report to include the name, address, and TIN of the person from whom the cash was received; the amount of cash received; the date and nature of the transaction; and other information as prescribed by the Secretary. Subsection (e) requires furnishing a written statement to each person whose name is required to be shown on the return. Subsection (f) prohibits structuring transactions for the purpose of evading the reporting requirements: it is unlawful for any person to cause or attempt to cause a trade or business to fail to file a return required under section 6050I, to cause or attempt to cause a trade or business to file a return required under section 6050I that contains a material omission or misstatement of fact, or to structure or assist in structuring, or attempt to structure or assist in structuring, any transaction with one or more trades or businesses. Section 6050I operates in parallel with 31 USC 5331 (the Bank Secrecy Act counterpart) which extends the same reporting framework to nonfinancial trades and businesses through FinCEN.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-31-cfr-1010-aml"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-26-usc-6672-trust-fund-recovery-penalty",
    "title": "US Internal Revenue Code - 26 USC 6672 Failure to Collect and Pay Over Tax, or Attempt to Evade or Defeat Tax (Trust Fund Recovery Penalty)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "26 USC 6672 is the Internal Revenue Code provision that imposes the Trust Fund Recovery Penalty (TFRP) personally on responsible persons who willfully fail to collect, account for, and pay over trust fund taxes. Subsection (a) provides that any person required to collect, truthfully account for, and pay over any tax imposed by this title who willfully fails to collect such tax, or truthfully account for and pay over such tax, or willfully attempts in any manner to evade or defeat any such tax or the payment thereof, shall, in addition to other penalties provided by law, be liable to a penalty equal to the total amount of the tax evaded, or not collected, or not accounted for and paid over. No penalty shall be imposed under section 6653 or part II of subchapter A of chapter 68 for any offense to which this section is applicable. Subsection (b) provides the preliminary notice requirement: no penalty shall be imposed under subsection (a) unless the Secretary notifies the taxpayer in writing by mail to an address as determined under section 6212(b) or in person that the taxpayer shall be subject to an assessment of such penalty. The notice must precede any notice and demand of any penalty under subsection (a) by at least 60 days. The assessment period extends 90 days after the date on which such notice was mailed or delivered in person, or, if there is a timely protest, until the date 30 days after the Secretary makes a final administrative determination with respect to such protest. Subsection (c) provides for extension by claim and bond: a person against whom the penalty is assessed may file a claim for refund and furnish bond within 30 days, preventing collection proceedings during that period; if the claim is denied, suit must be filed within 30 days in federal district court or the Court of Federal Claims. Subsection (d) provides a right of contribution: if more than one person is liable for the penalty under subsection (a), each person who paid such penalty shall be entitled to recover from other persons who are liable for such penalty an amount equal to the excess of the amount paid by such person over such person's proportionate share of the penalty. Subsection (e) provides an exception for voluntary unpaid members of boards of trustees or directors of tax-exempt organizations who serve in an honorary capacity, do not participate in day-to-day or financial operations, and have no actual knowledge of the failure on which the penalty is imposed — unless the exception would result in no person being liable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-26-usc-7201-attempt-to-evade-or-defeat-tax"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "us-26-usc-7201-attempt-to-evade-or-defeat-tax",
    "title": "US Internal Revenue Code - 26 USC 7201 Attempt to Evade or Defeat Tax",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "26 USC 7201 titled 'Attempt to evade or defeat tax' is the principal federal criminal tax evasion statute. The statute provides that any person who willfully attempts in any manner to evade or defeat any tax imposed by this title or the payment thereof shall, in addition to other penalties provided by law, be guilty of a felony, and upon conviction thereof shall be fined not more than $100,000 ($500,000 in the case of a corporation), or imprisoned not more than 5 years, or both, together with the costs of prosecution. Section 7201 is the principal federal vehicle for criminal prosecution of intentional tax evasion and is frequently charged in conjunction with 26 USC 7206 (false return), 26 USC 7212 (obstruction of IRS proceedings), 18 USC 371 (conspiracy to defraud the United States), 18 USC 1341 (mail fraud), and 18 USC 1343 (wire fraud). The elements of section 7201 are: (1) the existence of a substantial tax deficiency owed by the defendant; (2) a willful and affirmative act constituting an attempt to evade or defeat the tax or the payment thereof; and (3) willfulness defined as a voluntary, intentional violation of a known legal duty (the Cheek standard). The 'attempt' element distinguishes section 7201 from the misdemeanor tax-perfection offenses and requires conduct that goes beyond mere passive failure to file or pay.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-31-cfr-1010-aml"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-26-usc-7206-fraud-and-false-statements-tax",
    "title": "US Internal Revenue Code - 26 USC 7206 Fraud and False Statements (Tax Perjury and Aiding Tax Fraud)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "26 USC 7206 titled 'Fraud and false statements' is the federal tax-perjury and aiding-tax-fraud statute that complements 26 USC 7201 (tax evasion). Subsection (1) (the 'tax perjury' provision) makes it a felony for any person to willfully make and subscribe any return, statement, or other document that contains or is verified by a written declaration that it is made under the penalties of perjury, and which he does not believe to be true and correct as to every material matter. Subsection (2) makes it a felony to willfully aid or assist in, or procure, counsel, or advise the preparation or presentation under, or in connection with any matter arising under, the internal revenue laws, of a return, affidavit, claim, or other document, which is fraudulent or is false as to any material matter, whether or not such falsity or fraud is with the knowledge or consent of the person authorized or required to present such return, affidavit, claim, or document. Subsection (4) covers willful removal, deposit, or concealment of any goods or commodities for or in respect whereof any tax is or shall be imposed with intent to evade or defeat the assessment or collection of any tax. Subsection (5) covers conduct in connection with any compromise under section 7122 or closing agreement under section 7121. The penalty is a fine of not more than $100,000 ($500,000 in the case of a corporation), or imprisonment of not more than 3 years, or both, together with the costs of prosecution. Unlike section 7201, section 7206(1) does not require proof of a tax deficiency — it punishes the act of perjury in connection with the tax return regardless of whether tax was actually due.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-26-usc-7201-attempt-to-evade-or-defeat-tax"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-26-usc-7434-civil-damages-fraudulent-information-returns",
    "title": "US Internal Revenue Code - 26 USC 7434 Civil Damages for Fraudulent Filing of Information Returns",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "26 USC 7434 titled 'Civil damages for fraudulent filing of information returns' is the federal civil cause of action permitting any person to sue for damages when another person willfully files a fraudulent information return with respect to payments purportedly made to that person. Subsection (a) provides the cause of action: if any person willfully files a fraudulent information return with respect to payments purportedly made to any other person, such other person may bring a civil action for damages against the person so filing such return. Subsection (b) sets the damages available: the defendant shall be liable to the plaintiff in an amount equal to the greater of $5,000 or the sum of any actual damages sustained by the plaintiff as a proximate result of the filing of the fraudulent information return (including any costs attributable to resolving deficiencies asserted as a result of such filing); the costs of the action; and, in the court's discretion, reasonable attorneys' fees. Subsection (c) sets the statute of limitations: notwithstanding any other provision of law, an action may be brought under this section not later than the later of 6 years after the date of the filing of the fraudulent information return, or 1 year after the date such fraudulent information return would have been discovered by exercise of reasonable care. 'Information return' is defined by cross-reference to 26 USC 6724(d)(1) and covers the principal IRS information returns including Forms W-2, 1099, 1098, and the 5498 series.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-26-usc-7201-attempt-to-evade-or-defeat-tax"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-27-cfr-part-478-atf-commerce-firearms-ammunition",
    "title": "US 27 CFR Part 478: Commerce in Firearms and Ammunition",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 27 CFR Part 478 implements the Gun Control Act of 1968 (18 USC Chapter 44) covering Federal Firearms Licensees (FFLs) including dealers manufacturers and importers of firearms and ammunition. FFLs must conduct background checks via the National Instant Criminal Background Check System (NICS) before each firearm transfer to non-licensee, maintain records (Form 4473 Firearms Transaction Record and Acquisition and Disposition log A and D Book) for retention periods specified by regulation, report multiple handgun sales (Form 3310.4) to ATF, and comply with restrictions on prohibited persons categories (e.g., felons, domestic violence misdemeanants, certain mental health adjudications).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "gun_control_act",
        "nfa",
        "bipartisan_safer_communities_act",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-28-cfr-part-35-ada-title-ii-state-local-government",
    "title": "US 28 CFR Part 35: Nondiscrimination on the Basis of Disability in State and Local Government Services (ADA Title II)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 28 CFR Part 35 implements Title II of the Americans with Disabilities Act (ADA) prohibiting discrimination on the basis of disability by public entities (state and local government and their instrumentalities). Public entities must make their programs, services, and activities accessible to individuals with disabilities; provide reasonable modifications to policies, practices, and procedures; provide auxiliary aids and services for effective communication; ensure physical accessibility of facilities; and conduct self-evaluation. Subpart H (effective June 24, 2024) requires public entities to make their web content and mobile apps accessible per WCAG 2.1 Level AA by April 24, 2026 (population 50,000+) or April 26, 2027 (smaller).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ada_title_ii",
        "rehab_act_504",
        "cfr_28_36",
        "aba_aaa",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-28-cfr-part-36-ada-title-iii-public-accommodations",
    "title": "US 28 CFR Part 36: Nondiscrimination on the Basis of Disability by Public Accommodations and in Commercial Facilities (ADA Title III)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 28 CFR Part 36 implements Title III of the Americans with Disabilities Act (ADA) prohibiting discrimination on the basis of disability by public accommodations (12 categories listed in 36.104) and requiring readily achievable barrier removal in existing facilities. Public accommodations must provide goods and services in the most integrated setting appropriate; offer reasonable modifications to policies practices and procedures; provide auxiliary aids and services for effective communication; remove architectural barriers in existing facilities when readily achievable; and ensure new construction and alterations comply with the 2010 ADA Standards for Accessible Design. Website accessibility under Title III is increasingly litigated and DOJ has confirmed Title III applies to websites of public accommodations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ada_title_iii",
        "cfr_28_35",
        "cfr_29_1630",
        "ada_standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-28-cfr-part-75-2257-implementing-regulations",
    "title": "US 28 CFR Part 75 - Implementing Regulations for 18 USC §2257 and §2257A",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "28 CFR Part 75 is the US Attorney General's implementing regulation for 18 USC §2257 and §2257A record-keeping obligations. Part 75 contains nine sections defining who must keep records (§75.1 primary producer vs secondary producer), what records must be created and maintained (§75.2), how records are categorized and cross-indexed (§75.3), where they must be physically located (§75.4), the inspection regime for DOJ-authorized investigators (§75.5), the form and placement of the disclosure statement on every copy (§75.6 through §75.8), and the certification a producer may file regarding pre-July-2006 depictions (§75.9). The regulation distinguishes primary producers (who actually film/photograph/create the depiction) from secondary producers (who duplicate, publish, distribute, or reissue it) and allows the same person to be both. Definitions cross-reference 18 USC §2256(2)(A) for sexually explicit conduct.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "enabling_statute",
        "parallel_statute",
        "definitions_anchor",
        "first_amendment_litigation",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2257-record-keeping-explicit-content"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-29-cfr-part-1630-ada-title-i-employment",
    "title": "US 29 CFR Part 1630: Regulations to Implement the Equal Employment Provisions of the Americans with Disabilities Act",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 29 CFR Part 1630 implements Title I of the Americans with Disabilities Act (ADA) as amended by the ADAAA of 2008. It prohibits employment discrimination against qualified individuals with disabilities by covered employers (15+ employees) in all employment terms including recruitment, hiring, training, promotion, compensation, and discharge. Employers must provide reasonable accommodation to qualified applicants and employees with known disabilities unless accommodation would impose undue hardship. The regulation defines disability broadly per the ADAAA, prohibits medical inquiries before conditional offer, restricts medical inquiries after employment to job-related and consistent with business necessity, and addresses defenses including direct threat.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ada_act",
        "adaaa",
        "cfr_29_825",
        "rehab_act_504",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-29-cfr-part-2520-erisa-reporting-disclosure",
    "title": "US 29 CFR Part 2520: Rules and Regulations for Reporting and Disclosure (ERISA)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 29 CFR Part 2520 implements the reporting and disclosure provisions of Title I of the Employee Retirement Income Security Act (ERISA) of 1974 covering most private-sector employee benefit plans (pension and welfare). Plan administrators must file Form 5500 Annual Return/Report by the last day of the 7th month after plan year end (extendable to 9.5 months); deliver Summary Plan Description (SPD) to participants within 90 days of becoming covered or 120 days after plan effective date; provide Summary of Material Modifications (SMM) within 210 days after end of plan year in which change adopted; deliver Summary Annual Report (SAR) within 9 months after plan year end (small plans); and disclose participant fee information per Section 404(a)(5) regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "erisa_act",
        "cfr_29_2510",
        "cfr_26_1",
        "affordable_care_act",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-29-cfr-part-825-fmla-regulations",
    "title": "US 29 CFR Part 825: The Family and Medical Leave Act of 1993",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 29 CFR Part 825 implements the Family and Medical Leave Act of 1993 (FMLA) entitling eligible employees of covered employers to take up to 12 weeks of unpaid job-protected leave in a 12-month period for: birth or care of a newborn; placement for adoption or foster care; care of an employee's spouse parent or child with a serious health condition; the employee's own serious health condition; or qualifying exigencies arising from family member's covered active military duty. Military caregiver leave provides up to 26 weeks. Employers must maintain group health insurance and restore the employee to the same or equivalent position. The employer must provide General Notice, Eligibility Notice, Rights and Responsibilities Notice, and Designation Notice.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fmla",
        "ada",
        "cfr_29_1604",
        "state_leave",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-29-usc-158-nlra-unfair-labor-practices",
    "title": "US National Labor Relations Act - 29 USC 158 Unfair Labor Practices",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "29 USC 158 titled 'Unfair labor practices' is the core National Labor Relations Act provision identifying conduct by employers and labor organizations that violates federal labor law. Subsection (a) lists five categories of employer unfair labor practices: (1) it is an unfair labor practice for an employer to interfere with, restrain, or coerce employees in the exercise of the rights guaranteed in section 157 (the right to self-organization, to form, join, or assist labor organizations, to bargain collectively, and to engage in other concerted activities); (2) to dominate or interfere with the formation or administration of any labor organization or contribute financial or other support to it; (3) by discrimination in regard to hire or tenure of employment or any term or condition of employment to encourage or discourage membership in any labor organization; (4) to discharge or otherwise discriminate against an employee because he has filed charges or given testimony under this subchapter; and (5) to refuse to bargain collectively with the representatives of his employees, subject to the provisions of section 159(a). Subsection (b) lists labor organization unfair labor practices including restraining or coercing employees exercising section 157 rights, causing or attempting to cause an employer to discriminate against an employee, refusing to bargain collectively, engaging in illegal strikes or secondary boycotts, requiring excessive or discriminatory fees as a condition of becoming a member, exacting money from an employer for services not performed, and engaging in certain recognitional or organizational picketing without proper certification and procedures. Subsection (d) defines collective bargaining obligations including good-faith negotiation and the duty to meet at reasonable times. Section 158 is enforced by the National Labor Relations Board (NLRB) under section 160 through unfair labor practice charges, complaints, hearings, and Board orders that may include reinstatement, back pay, and posting of notices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-civil-rights-act-title-vii"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-29-usc-202-flsa-congressional-finding-declaration-of-policy",
    "title": "US Fair Labor Standards Act - 29 USC 202 Congressional Finding and Declaration of Policy",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "29 USC 202 titled 'Congressional finding and declaration of policy' is the foundational Fair Labor Standards Act provision setting out Congress's findings and policy rationale for federal minimum wage, overtime, child labor, and recordkeeping standards. Subsection (a) provides the Congressional findings: the existence, in industries engaged in commerce or in the production of goods for commerce, of labor conditions detrimental to the maintenance of the minimum standard of living necessary for health, efficiency, and general well-being of workers (1) causes commerce and the channels and instrumentalities of commerce to be used to spread and perpetuate such labor conditions among the workers of the several States; (2) burdens commerce and the free flow of goods in commerce; (3) constitutes an unfair method of competition in commerce; (4) leads to labor disputes burdening and obstructing commerce and the free flow of goods in commerce; and (5) interferes with the orderly and fair marketing of goods in commerce. Subsection (a) also finds that the employment of persons in domestic service in households affects commerce. Subsection (b) provides the declaration of policy: it is hereby declared to be the policy of this chapter, through the exercise by Congress of its power to regulate commerce among the several States and with foreign nations, to correct and as rapidly as practicable to eliminate the conditions above referred to in such industries without substantially curtailing employment or earning power. Section 202 is the constitutional foundation for the substantive FLSA provisions on minimum wage (29 USC 206), maximum hours (29 USC 207), child labor (29 USC 212), and recordkeeping (29 USC 211), and supports the broad commerce-clause reach of the Act to any enterprise engaged in commerce or in the production of goods for commerce.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-equal-pay-act-1963-29-usc-206"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-29-usc-207-flsa-maximum-hours-overtime",
    "title": "US Fair Labor Standards Act - 29 USC 207 Maximum Hours and Overtime Compensation",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "29 USC 207 titled 'Maximum hours' is the Fair Labor Standards Act provision establishing the 40-hour workweek and the time-and-a-half overtime obligation for non-exempt employees. Subsection (a)(1) provides the core rule: except as otherwise provided in this section, no employer shall employ any of his employees who in any workweek is engaged in commerce or in the production of goods for commerce, or is employed in an enterprise engaged in commerce or in the production of goods for commerce, for a workweek longer than forty hours unless such employee receives compensation for his employment in excess of the hours above specified at a rate not less than one and one-half times the regular rate at which he is employed. Subsection (g) governs computation rules for piece-rate work and other variable compensation: overtime pay must use rates not less than one and one-half times the bona fide piece rates applicable to the same work when performed during nonovertime hours. Subsection (j) governs healthcare facilities: institutions caring for the sick or elderly may use a 14-day work period instead of the weekly calculation, provided employees receive time-and-a-half for employment in excess of eight hours in any workday and in excess of eighty hours in such fourteen-day period. The statute provides numerous exemptions including collective bargaining agreements meeting specified conditions, certain petroleum distributors, tobacco industry workers (limited periods), fire protection and law enforcement personnel under specified work periods, and public agency employees receiving compensatory time. Together with the bona fide executive, administrative, professional, computer, and outside sales exemptions under 29 USC 213, section 207 forms the backbone of federal overtime law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-equal-pay-act-1963-29-usc-206"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-29-usc-654-osha-general-duty-clause-employer-and-employee-duties",
    "title": "US Occupational Safety and Health Act - 29 USC 654 Duties of Employers and Employees (General Duty Clause)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "29 USC 654 titled 'Duties of employers and employees' is the foundational Occupational Safety and Health Act provision that imposes both the General Duty Clause on employers and a standards-compliance duty on employees. Subsection (a)(1) is the General Duty Clause: each employer shall furnish to each of his employees employment and a place of employment which are free from recognized hazards that are causing or are likely to cause death or serious physical harm to his employees. The General Duty Clause is invoked by OSHA when no specific safety or health standard applies to the cited hazard, but the hazard is nonetheless recognized in the industry or by the employer and is causing or likely to cause death or serious physical harm. Subsection (a)(2) provides that each employer shall comply with occupational safety and health standards promulgated under this chapter. Subsection (b) provides that each employee shall comply with occupational safety and health standards and all rules, regulations, and orders issued pursuant to this chapter which are applicable to his own actions and conduct. The General Duty Clause is one of the most powerful federal worker-safety enforcement tools because it captures emerging hazards (heat illness, ergonomic injuries, workplace violence, infectious disease) not yet subject to a specific 29 CFR 1910 or 1926 standard, provided OSHA can demonstrate the four-part elements: (1) the employer failed to keep its workplace free of a hazard; (2) the hazard was recognized; (3) the hazard was causing or was likely to cause death or serious physical harm; and (4) there was a feasible and useful method to correct the hazard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-osha-29-cfr-1910-general-industry"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-30-cfr-75-mandatory-safety-underground-coal-mines",
    "title": "US MSHA 30 CFR Part 75 - Mandatory Safety Standards for Underground Coal Mines: Ventilation, Roof Support, Electrical Safety, and Emergency Preparedness",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "30 CFR Part 75 establishes the Mine Safety and Health Administration's (MSHA) mandatory safety standards for underground coal mines, covering methane and dust control (Subpart D), roof support (Subpart C), ventilation (Subpart D), electrical safety (Subpart F), fire protection (Subpart K), escapeways (Subpart C), accident notification (Subpart O), and emergency response plans. Underground coal mines are subject to mandatory inspection by MSHA at least four times per year (twice for surface installations). Mines must develop and submit a Roof Control Plan, Ventilation Plan, and emergency response plan to MSHA. Violation of mandatory health and safety standards is subject to civil penalties up to $70,000 per violation and criminal penalties for willful violations resulting in death.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-safety-health-mines-convention-c176-1995"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-30-cfr-part-50-msha-accident-injury-illness-notification-reporting",
    "title": "30 CFR Part 50 - MSHA Notification, Investigation, Reports and Records of Accidents, Injuries, Illnesses, Employment, and Coal Production in Mines",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2025-06-01",
    "bluf": "Mine operators must immediately contact MSHA - at once and without delay, within 15 minutes - at the toll-free number 1-800-746-1553 once the operator knows or should know that an accident as defined in § 50.2 has occurred, preserve evidence, file MSHA Form 7000-1 within ten working days after an accident, occupational injury, or diagnosis of an occupational illness, submit the quarterly Form 7000-2 Employment and Coal Production Report within fifteen days after each calendar quarter ends, maintain investigation reports and supporting records at the mine office closest to the mine for five years, and on request allow MSHA to inspect and copy information related to any accident, injury, or illness that MSHA considers relevant and necessary to verify a report.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-federal-mine-safety-and-health-act",
      "us-msha-mine-safety-health-act-1977"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-30-cfr-part-56-msha-surface-mines-safety",
    "title": "US 30 CFR Part 56: Safety and Health Standards Surface Metal and Nonmetal Mines",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 30 CFR Part 56 establishes safety and health standards for surface metal and nonmetal mines under the jurisdiction of the Mine Safety and Health Administration (MSHA). Subparts cover general safety and health (Subpart A) air quality and physical agents (Subpart D) electricity (Subpart K) loading hauling and dumping (Subpart H) machinery and equipment (Subpart M) personal protection (Subpart N) materials storage and handling (Subpart O) explosives (Subpart E) drilling and rotary jet piercing (Subpart I) and ground control (Subpart J). MSHA inspectors conduct mandatory inspections (at least 2x annually for surface mines) and may issue citations and orders for violations including significant and substantial (S and S) violations and unwarrantable failure findings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "mine_act",
        "cfr_30_57",
        "cfr_30_75",
        "cfr_30_77",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-30-usc-181-mineral-leasing-act-1920",
    "title": "30 USC § 181 - Mineral Leasing Act of 1920 (Lands Subject to Disposition)",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "30 USC § 181 (Mineral Leasing Act of 1920, Pub. L. 66-146, 41 Stat. 437; substantially amended over time) establishes the federal leasing framework for specified mineral deposits removing them from operation of the General Mining Law of 1872 (30 USC § 22): the section provides that 'Deposits of coal, phosphate, sodium, potassium, oil, oil shale, gilsonite (including all vein-type solid hydrocarbons), or gas, and lands containing such deposits owned by the United States, including those in national forests, but excluding lands acquired under the Act known as the Appalachian Forest Act ... shall be subject to disposition in the form and manner provided by this chapter to citizens of the United States, or to associations of such citizens, or to any corporation organized under the laws of the United States, or of any State or Territory thereof, and to municipalities in the case of the deposits enumerated in subsection (a) of section 351 of this title'; foreign nationals from countries that deny reciprocal mining privileges to US citizens are prohibited from owning interests through stock ownership; the Federal Government reserves helium rights on all gas produced from leased lands; the Mineral Leasing Act establishes the framework for federal coal, oil, gas, and other listed mineral leasing administered primarily by the Bureau of Land Management; the Outer Continental Shelf Lands Act (43 USC 1331-1356b) provides parallel framework for offshore federal leasing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "mla_related_provisions",
        "implementing_regulations",
        "parallel_offshore_framework",
        "industry_mapping",
        "enforcement_anchors",
        "foreign_ownership_reciprocity_doctrine"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-30-usc-22-general-mining-law-1872",
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-30-usc-22-general-mining-law-1872",
    "title": "30 USC § 22 - General Mining Law of 1872 (Lands Open to Purchase by Citizens)",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "30 USC § 22 (originally enacted May 10, 1872 as Section 1 of the Mining Act, codified at Revised Statutes § 2319, with subsequent amendments) is the foundational provision of the General Mining Law of 1872 establishing that 'all valuable mineral deposits in lands belonging to the United States, both surveyed and unsurveyed, shall be free and open to exploration and purchase, by citizens of the United States and those who have declared their intention to become such, under regulations prescribed by law, and according to the local customs or rules of miners in the several mining districts, so far as the same are applicable and not inconsistent with the laws of the United States'; the section grants the right of self-initiation by citizens to enter public lands, prospect for hardrock minerals, locate mining claims, and acquire title through patent or simply maintain unpatented claims; covered minerals include gold, silver, copper, lead, zinc, uranium (subject to Atomic Energy Act amendments), nickel, tungsten, and other locatable hardrock minerals; oil, gas, coal, phosphate, sodium, potassium, oil shale, and gilsonite were removed by the Mineral Leasing Act of 1920 (30 USC § 181) and are now subject to leasing rather than claim location; the Mining Law of 1872 has been substantially modified by subsequent federal land management statutes but remains the operating framework for hardrock mining on federal land.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "mineral_leasing_act_carve_out",
        "implementing_regulations",
        "modern_amendments",
        "industry_mapping",
        "enforcement_anchors",
        "claim_location_self_initiation_doctrine"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-30-usc-181-mineral-leasing-act-1920",
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-31-cfr-chapter-x-fincen-bsa-regulations",
    "title": "US 31 CFR Chapter X: Financial Crimes Enforcement Network (FinCEN) Regulations",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 31 CFR Chapter X contains the FinCEN regulations implementing the Bank Secrecy Act. The chapter is organised by financial institution type: banks (Part 1020), brokers/dealers (1023), futures commission merchants (1026), money services businesses (1022), casinos (1021), insurance companies (1025), dealers in precious metals (1027), housing GSEs (1029), and persons subject to currency transaction reporting (1010). Each subpart sets AML programme requirements, CIP/KYC obligations, beneficial ownership identification under the CDD Rule, suspicious activity reporting, and recordkeeping. Compliance is foundational to US financial sector AML.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "usc_31_5311",
        "cdd_rule",
        "cta",
        "fatf",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-31-cfr-part-1010-fincen-bsa-general-provisions",
    "title": "US 31 CFR Part 1010: General Provisions (FinCEN Bank Secrecy Act)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 31 CFR Part 1010 contains the general provisions implementing the Bank Secrecy Act (BSA) that apply across all financial institution categories regulated by FinCEN including banks, money services businesses (MSBs), securities and futures, casinos, insurance companies, dealers in precious metals, mortgage companies, and (effective 2026) certain investment advisers. Part 1010 covers definitions, registration of MSBs, Currency Transaction Reports (CTRs) for cash transactions >$10,000, Suspicious Activity Reports (SARs), Foreign Bank and Financial Accounts Reports (FBAR / FinCEN Form 114), Customer Identification Program (CIP) and Customer Due Diligence (CDD) including beneficial ownership of legal entity customers, and recordkeeping including funds transfer travel rule.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "bsa",
        "cta",
        "cfr_31_1020",
        "fatf_recs",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-31-cfr-part-1020-fincen-banks-bsa",
    "title": "US 31 CFR Part 1020: Rules for Banks (FinCEN BSA)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 31 CFR Part 1020 contains BSA rules specific to banks including the Anti-Money Laundering Program rule requiring banks to develop, implement, and maintain a written AML program with the five pillars: (1) internal policies procedures and controls; (2) designated BSA compliance officer; (3) ongoing employee training; (4) independent testing of compliance; (5) appropriate risk-based procedures for ongoing customer due diligence including beneficial ownership. Part 1020 also covers the Bank-specific Suspicious Activity Reporting threshold ($5,000), CIP application by banks, and CDD/beneficial ownership identification requirements introduced in the 2016 CDD Final Rule.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "bsa",
        "cfr_31_1010",
        "cfr_12_21_21",
        "fatf_recs",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-31-cfr-part-501-ofac-reporting-procedures",
    "title": "US 31 CFR Part 501: Reporting Procedures and Penalties Regulations (OFAC)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 31 CFR Part 501 establishes the reporting, procedures, and penalties framework applicable to OFAC sanctions programs including Specially Designated Nationals (SDN) List, Sectoral Sanctions Identifications (SSI) List, and country-based programs (e.g., Russia, Iran, Cuba, North Korea, Venezuela, Syria). Part 501 covers blocking of property and interests (blocked report TD F 90-22.50 within 10 business days), rejected transactions reporting (within 10 business days), annual reports of blocked property, license application procedures (general and specific), penalty matrix referencing International Emergency Economic Powers Act (IEEPA) with civil penalty up to $377,700 per violation 2024 dollars and criminal up to $1 million and 20 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ieepa",
        "twea",
        "cfr_31_500_599",
        "csis",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-31-cfr-part-510-north-korea-sanctions-regulations",
    "title": "US OFAC 31 CFR Part 510 North Korea Sanctions Regulations NKSR Comprehensive Blocking Import Export Vessel Aircraft and Correspondent Account Prohibitions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The North Korea Sanctions Regulations codified at 31 CFR Part 510 are administered by the US Treasury Office of Foreign Assets Control to implement multiple Executive Orders against the Government of North Korea organised across subparts A through I including Subpart A relation to other laws at section 510.101, Subpart B prohibitions covering blocked property transactions at section 510.201 nullification of unauthorised transfers 510.202 interest-bearing accounts 510.203 maintenance expenses 510.204 import prohibitions 510.205 export and reexport prohibitions 510.206 vessel registration restrictions 510.207 aircraft and vessel entry restrictions 510.208 new investment prohibitions 510.209 financial institution correspondent account prohibitions 510.210 facilitation prohibitions 510.211 evasion and conspiracy 510.212 exempt charitable informational travel and official transactions 510.213 and restrictions on entities owned by US financial institutions 510.214, Subpart C general definitions in sections 510.300 to 510.330 including Government of North Korea blocked property luxury goods and financial services, Subpart D interpretations 510.401 to 510.411, and Subpart E general and specific licences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ieepa-1977"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-31-cfr-part-515-cuban-assets-control-regulations",
    "title": "US OFAC 31 CFR Part 515 Cuban Assets Control Regulations CACR Subparts A through M Prohibited Transactions Blocked Property General and Specific Licenses",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Cuban Assets Control Regulations codified at 31 CFR Part 515 are administered by the US Treasury Office of Foreign Assets Control and constitute the longest-running US sanctions program dating to 1963 organised across subparts A through M including Subpart A relation to other laws and regulations under section 515.101, Subpart B prohibitions covering transactions with designated nationals at section 515.201 securities held by designated nationals 515.202 void transfers 515.203 Cuban merchandise import restrictions 515.204 interest-bearing account requirements 515.205 exempt informational and humanitarian transactions 515.206 vessel entry restrictions 515.207 confiscated property financing restrictions 515.208 direct financial transactions with restricted entities 515.209 and prohibited lodging accommodations 515.210, Subpart C general definitions in sections 515.301 to 515.340, Subpart D interpretations in sections 515.401 to 515.421, Subpart E licenses including unblocking 515.505 and authorised legal and remittance transactions 515.508 to 515.512, and subsequent subparts addressing penalties paperwork and procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-trading-with-the-enemy-act-50-usc-4301",
      "us-helms-burton-libertad-act-22-usc-ch69a"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-31-cfr-part-535-iranian-assets-control-regulations",
    "title": "US 31 CFR Part 535 Iranian Assets Control Regulations Legacy 1979 Hostage Crisis Asset Freeze Algiers Accords Compliance and Settlement Mechanisms",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "31 CFR Part 535 implements the oldest active US sanctions program against Iran originating in Executive Order 12170 (1979) following the seizure of the US embassy in Tehran organised in five operative subparts with Subpart A relation to other laws independent of all other parts except Part 501 reporting and procedures, Subpart B prohibitions including section 535.201 prohibiting transfers of property in which Iran has any interest section 535.202 restricting dealings in Iranian-registered securities section 535.203 nullifying violating transfers and sections 535.208 through 535.222 covering procedural and enforcement matters, Subpart C general definitions including section 535.301 defining Iran and Iranian Entity and sections 535.308 through 535.337 defining person transfer property and related concepts, Subpart D interpretations including sections 535.401 through 535.441 addressing amendments terminations of interests and specific applications, and Subpart E licenses including sections 535.501 through 535.568 covering licensing procedures blocked accounts and the specific transaction authorisations including Algiers Accords settlement procedures. The Part operates alongside but independently of the broader Iran sanctions programs at 31 CFR Parts 560 and 561.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ieepa-1977"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-31-cfr-part-548-belarus-sanctions-regulations",
    "title": "US 31 CFR Part 548 Belarus Sanctions Regulations Asset Freeze on Ministry of Finance and Development Bank Sectoral Sanctions and Energy Defense and Potash Restrictions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "31 CFR Part 548 implements US sanctions against Belarus pursuant to Executive Order 14038 and subsequent orders organised in nine subparts covering Subpart A relation to other laws, Subpart B prohibitions including section 548.201 prohibitions on blocked property transactions section 548.202 specific restrictions on the Ministry of Finance and the Development Bank of the Republic of Belarus section 548.205 prohibiting transfers from blocked persons and section 548.206 prohibiting evasion attempts conspiracies and causing violations, Subpart C general definitions of blocked property entity US person and economic sectors including energy defense and related materiel and potash that may be subject to determinations, Subpart D interpretations including the 50 percent ownership aggregation rule applicable to entities owned by blocked persons, Subpart E licenses authorisations and statements of licensing policy including general licences for legal services emergency medical care and humanitarian assistance, Subpart F reports requirements, Subpart G penalties and findings of violation, Subpart H procedures, and Subpart I Paperwork Reduction Act provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ieepa-1977"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-31-cfr-part-549-lebanon-sanctions-regulations",
    "title": "US 31 CFR Part 549 Lebanon Sanctions Regulations Asset Freeze on Persons Undermining Lebanese Sovereignty Executive Order 13441 Implementation",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "31 CFR Part 549 implements US sanctions targeting persons who undermine the legitimate political processes or institutions of Lebanon pursuant to Executive Order 13441 organised in nine subparts covering Subpart A relation to other laws Subpart B prohibitions including section 549.201 blocked property transactions section 549.202 nullification of violating transfers section 549.203 interest bearing account requirements for blocked funds section 549.204 prohibited transactions and section 549.206 evasion attempts and conspiracies Subpart C general definitions including blocked property foreign person US person and related terms in sections 549.301 through 549.313 Subpart D interpretations in sections 549.401 through 549.411 including the 50 percent aggregation ownership rule Subpart E licenses authorisations and statements of licensing policy in sections 549.501 through 549.513 including general licences for legal services emergency medical care and NGO humanitarian activities Subpart F reports requirements Subpart G penalties and findings of violation Subpart H procedures and Subpart I Paperwork Reduction Act provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ieepa-1977"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-31-cfr-part-560-ofac-iranian-transactions-sanctions-regulations",
    "title": "OFAC 31 CFR Part 560 - Iranian Transactions and Sanctions Regulations (ITSR)",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "31 CFR Part 560 implements the comprehensive US sanctions program against Iran administered by the Treasury Department's Office of Foreign Assets Control (OFAC) under the International Emergency Economic Powers Act (50 USC 1701-1708) and successive executive orders including E.O. 12613, 12957, 12959, 13059, 13599, 13628, and 13846. Subpart B sets out the core prohibitions on US persons: section 560.201 prohibits importation of Iranian-origin goods or services; section 560.203 prohibits any transaction that evades or avoids any prohibition; section 560.204 prohibits exportation, reexportation, sale, or supply of any goods, technology, or services from the United States or by a US person, wherever located, to Iran or the Government of Iran; section 560.205 prohibits reexportation of certain US-origin foreign-produced goods containing 10% or more controlled US content; section 560.206 prohibits trade-related transactions with Iran; section 560.207 prohibits new investment in Iran; section 560.208 prohibits facilitation by US persons of transactions by foreign persons that would be prohibited if performed by US persons; section 560.209 prohibits transactions with persons in Iran; section 560.211 blocks property of persons designated under E.O. 13599 (Government of Iran and Iranian financial institutions); section 560.215 applies the 50% rule to entities owned 50% or more by blocked persons. Subpart E contains general licences including section 560.530 (commercial sales of agricultural commodities, medicine, and medical devices under TSRA), section 560.532 (humanitarian remittances), section 560.540 (publication of information), and section 560.550 (internet-based personal communications). Subpart G section 560.701 establishes civil penalties up to USD 368,136 per violation or twice the amount of the underlying transaction (whichever is greater) under IEEPA. Criminal penalties under IEEPA reach USD 1,000,000 and 20 years imprisonment per violation under 50 USC 1705(c).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "key_prohibitions_summary",
        "key_general_licences",
        "civil_and_criminal_penalty_tiers"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ieepa-1977",
      "us-iran-sanctions-act-1996-pl-104-172",
      "us-itrshra-iran-threat-reduction-2012-pl-112-158",
      "us-31-cfr-part-535-iranian-assets-control-regulations"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-31-cfr-part-583-global-magnitsky-sanctions-regulations",
    "title": "US 31 CFR Part 583 Global Magnitsky Sanctions Regulations Executive Order 13818 Human Rights Abuses and Corruption Asset Freeze Framework",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "31 CFR Part 583 implements US sanctions against serious human rights abusers and corrupt actors worldwide pursuant to Executive Order 13818 and the Global Magnitsky Human Rights Accountability Act organised in subparts covering Subpart A relation to other laws and the Secretary of the Treasury delegation under section 583.106, Subpart B prohibitions including section 583.201 blocked person transactions section 583.202 void transfers section 583.203 interest-bearing account holdings and section 583.205 evasion and conspiracy prohibitions, Subpart C general definitions of blocked property foreign person US person and transfer, Subpart D interpretations including section 583.411 the 50 percent aggregation ownership rule and section 583.412 clarifying that blocked official roles do not automatically block their organisations, Subpart E licenses authorisations and statements of licensing policy including section 583.507 legal services general licence section 583.509 emergency medical services authorisation and section 583.512 NGO humanitarian activities authorisation, and Subpart G penalties with civil penalties up to 377700 dollars or twice the transaction amount and criminal penalties up to 1000000 dollars and 20 years imprisonment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ieepa-1977",
      "us-global-magnitsky-pl-114-328-subtitle-f"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-31-cfr-part-584-magnitsky-act-sanctions-regulations",
    "title": "US 31 CFR Part 584 Magnitsky Act Sanctions Regulations Sergei Magnitsky Rule of Law Accountability Act Implementation Russia-Origin Human Rights Designations",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "31 CFR Part 584 implements US sanctions against persons responsible for the detention abuse and death of Sergei Magnitsky and other gross violations of internationally recognized human rights committed against individuals seeking to expose illegal activity carried out by Russian government officials pursuant to the Sergei Magnitsky Rule of Law Accountability Act of 2012 organised in nine subparts covering Subpart A relation to other laws section 584.101, Subpart B prohibitions sections 584.201 through 584.206 including blocked property prohibitions void transfers and evasion controls, Subpart C general definitions sections 584.300 through 584.315 defining blocked property foreign person US person and related terms, Subpart D interpretations sections 584.401 through 584.410, Subpart E licenses authorisations and licensing policy sections 584.501 through 584.513, Subpart F reports section 584.601, Subpart G penalties and finding of violation sections 584.701 through 584.705, Subpart H procedures sections 584.801 and 584.802, and Subpart I Paperwork Reduction Act section 584.901. The Part is distinct from the broader Global Magnitsky program at Part 583 and the post-2016 Magnitsky Act expanded scope is implemented through Part 583.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sergei-magnitsky-act-2012-pl-112-208-title-iv",
      "us-ieepa-1977"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-31-cfr-part-587-russian-harmful-foreign-activities-sanctions-regulations",
    "title": "US 31 CFR Part 587 Russian Harmful Foreign Activities Sanctions Regulations Executive Order 14024 Implementation Election Interference Cyber Activity and Sovereignty Violations",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "31 CFR Part 587 implements US sanctions against persons engaged in specified harmful foreign activities of the Government of the Russian Federation pursuant to Executive Order 14024 organised in nine subparts covering Subpart A relation to other laws section 587.101 establishing independent status from other sanctions programs, Subpart B prohibitions including section 587.201 blocking all transactions prohibited by Executive Order 14024 section 587.202 nullification of unauthorised transfers section 587.203 interest-bearing account requirements section 587.204 expenses for maintaining blocked property and section 587.205 exempt transactions including personal communications and official business, Subpart C general definitions sections 587.300 through 587.315 defining blocked property entity person transfer and related terms, Subpart D interpretations sections 587.401 through 587.406 including the 50 percent ownership aggregation rule, Subpart E licenses authorisations and statements of licensing policy sections 587.501 through 587.510, and Subparts F through I covering reports penalties procedures and Paperwork Reduction Act provisions. The Part covers election interference malicious cyber-enabled activities transnational corruption attempts to influence foreign elections and the violation of territorial integrity of countries with which the United States has friendly relations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ieepa-1977",
      "us-caatsa-pl-115-44-2017"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-31-cfr-part-591-venezuela-sanctions-regulations",
    "title": "US OFAC 31 CFR Part 591 Venezuela Sanctions Regulations Executive Order 13692 Blocking Authorised Legal Medical and Official Transactions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Venezuela Sanctions Regulations codified at 31 CFR Part 591 are administered by the US Treasury Office of Foreign Assets Control to implement Executive Order 13692 of March 2015 and subsequent Executive Orders targeting the Government of Venezuela organised across subparts including Subpart A relation to other laws at section 591.101, Subpart B prohibitions covering blocking transactions under Executive Order 13692 at section 591.201 nullification of unauthorised transfers 591.202 interest-bearing account requirements 591.203 and maintenance of blocked property at 591.204, Subpart C general definitions at sections 591.300 to 591.313 including blocked account person transfer United States person and US financial institution, Subpart D interpretations including termination and acquisition of blocked property interests at 591.403 prohibition on setoffs at 591.405 fifty-percent ownership rule at 591.406 and enforcement-action restrictions at 591.407, Subpart E licenses including authorised legal services at 591.506 legal fee payments from foreign funds 591.507 emergency medical services 591.508 official US government and international organisation business 591.509 and 591.510, and Subpart H procedures and Subpart I Paperwork Reduction Act provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ieepa-1977"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-31-cfr-part-594-global-terrorism-sanctions-regulations",
    "title": "US 31 CFR Part 594 Global Terrorism Sanctions Regulations Executive Order 13224 Implementation Asset Freeze on Specially Designated Global Terrorists",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "31 CFR Part 594 implements US sanctions against Specially Designated Global Terrorists pursuant to Executive Order 13224 organised in seven operative subparts covering Subpart A relation to other laws section 594.101, Subpart B prohibitions including section 594.201 prohibited transactions involving blocked property section 594.202 effect of transfers violating provisions section 594.203 holding of funds in interest-bearing accounts section 594.204 prohibited transactions and contributions section 594.205 evasions and conspiracies section 594.206 expenses for maintaining blocked property and section 594.207 exempt transactions, Subpart C general definitions sections 594.301 through 594.322 including blocked account terrorism and US person definitions, Subpart D interpretations sections 594.401 through 594.412 including the 50 percent aggregation ownership rule, Subpart E licenses authorisations and statements of licensing policy sections 594.501 through 594.521, Subpart F reports requirements section 594.601, and Subpart G penalties sections 594.701 through 594.703 covering civil and criminal penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ieepa-1977"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-31-usc-1341-antideficiency-act",
    "title": "31 USC § 1341 - Antideficiency Act (Limitations on Expending and Obligating Amounts)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "31 USC § 1341 (originally enacted in 1870 as the Antideficiency Act, with substantial amendments in the Public Works Appropriation Act of 1957 and recodified by Pub. L. 97-258 in 1982) prohibits federal officers and employees from incurring obligations or making expenditures in advance of, or in excess of, the available appropriation: subsection (a)(1)(A) prohibits making or authorizing an expenditure or obligation exceeding an amount available in an appropriation or fund; subsection (a)(1)(B) prohibits involving the Government in a contract or obligation for payment of money before an appropriation is made unless authorized by law; subsection (b) addresses apportionment restrictions preventing circumvention through use of other appropriated funds; violations are subject to administrative discipline up to removal from office under § 1349, and willful and knowing violations are criminal misdemeanors under § 1350 with penalties up to two years imprisonment and $5,000 fine; the Antideficiency Act is the foundational restriction on federal spending and shapes every federal procurement contract through the 'subject to availability of funds' clauses; OMB Circular A-11 Part 4 administers the apportionment process; GAO publishes Antideficiency Act violations annually as required by § 1351.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_antideficiency_provisions",
        "apportionment_framework",
        "industry_mapping",
        "far_contract_clauses",
        "enforcement_anchors",
        "government_shutdown_implications"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-10-usc-3201-dod-competition-requirements",
      "us-41-usc-4304-specific-costs-not-allowable"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-31-usc-3553-gao-bid-protest-review",
    "title": "31 USC § 3553 - Government Accountability Office Bid Protest Jurisdiction and Stay of Performance",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "31 USC § 3553 (enacted as part of the Competition in Contracting Act of 1984, Pub. L. 98-369; amended Pub. L. 104-106 and Pub. L. 116-283) gives the Comptroller General (head of the Government Accountability Office) jurisdiction to decide bid protests submitted by interested parties: subsection (a) establishes the Comptroller General's duty to decide protests submitted by interested parties (defined as actual or prospective bidders/offerors whose direct economic interest would be affected); subsection (b) prescribes the procedural deadlines - GAO notifies the federal agency within one day of receiving a protest; agencies file complete reports within 30 days (or 20 days under express option) of notification; the Comptroller General issues a decision within 100 days of protest receipt; subsection (c) establishes the automatic stay of contract performance during pending protest - a contract may not be awarded after the agency receives notice of a protest while the protest is pending, except where the head of procuring activity makes a written finding of urgent and compelling circumstances significantly affecting US interests; subsection (d) authorizes override of the stay by the procuring activity head with notification to the Comptroller General; the GAO bid protest regime operates in parallel with the Court of Federal Claims jurisdiction under 28 USC § 1491(b); protests filed within 10 days of basis known per 4 CFR § 21.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "gao_bid_protest_regulations",
        "court_of_federal_claims_parallel_jurisdiction",
        "agency_level_protest_far_part_33",
        "industry_mapping",
        "stay_override_test_subsection_d",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-41-usc-3304-noncompetitive-procedures-exceptions",
      "us-10-usc-3201-dod-competition-requirements"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-31-usc-5311-5318-bank-secrecy-act-aml-program",
    "title": "31 USC §§ 5311 + 5318 - Bank Secrecy Act Purpose + AML Program Four Pillars",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "31 USC §§ 5311 (Declaration of Purpose) and 5318 (Compliance Program Requirements) form the substantive heart of the Bank Secrecy Act (Pub. L. 91-508, signed 26 October 1970, as substantially revised by USA PATRIOT Act 2001 Pub. L. 107-56 and Anti-Money Laundering Act of 2020 within the NDAA FY2021 Pub. L. 116-283 Div F Title LXI § 6101(a) effective 1 January 2021): §5311 establishes five legislative purposes - (1) requiring reports and records useful in criminal, tax, and regulatory investigations and counterintelligence activities to protect against terrorism; (2) preventing money laundering and terrorism financing through risk-based programs by financial institutions; (3) facilitating tracking of criminally-sourced money or funds intended for criminal/terrorist activity; (4) assessing money laundering, terrorism finance, tax evasion, and fraud risks to safeguard the US financial system and national security; (5) establishing information-sharing frameworks among financial institutions, regulators, Treasury, and law enforcement; §5318(h) requires anti-money laundering programs with the Four Pillars - (i) internal policies, procedures, and controls; (ii) designation of a compliance officer; (iii) ongoing employee training program; (iv) independent audit function to test programs - reasonably designed to assure and monitor compliance with AML requirements; the AMLA 2020 added a fifth pillar in many regulatory implementations - Customer Due Diligence (CDD) with risk-based monitoring proportionate to customer risk profiles; §5318(g) requires Suspicious Activity Report (SAR) filing for transactions involving funds from illegal activity, transactions designed to evade BSA requirements, or transactions with no apparent lawful purpose; §5318(i) requires Currency Transaction Reports (CTR) for cash transactions exceeding $10,000; §5318(l) requires Customer Identification Programs (CIP) under USA PATRIOT Act §326 implemented via FinCEN regulations at 31 CFR 1020.220 for banks, 1023.220 for broker-dealers, and parallel parts for other financial institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fincen_regulations_31_cfr_chapter_x",
        "usa_patriot_act_section_311_special_measures",
        "amla_2020_beneficial_ownership_reporting",
        "industry_mapping",
        "enforcement_anchors",
        "constitutional_doctrine",
        "fatf_alignment",
        "civil_and_criminal_penalty_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bsa-31-usc-5311-5314-bank-secrecy-act",
      "us-patriot-act-2001-pl-107-56",
      "us-corporate-transparency-act-2020-31-usc-5336"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-31-usc-5331-nonfinancial-trade-business-currency-reports",
    "title": "US Bank Secrecy Act - 31 USC 5331 Reports Relating to Coins and Currency Received in Nonfinancial Trade or Business",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "31 USC 5331 titled 'Reports relating to coins and currency received in nonfinancial trade or business' is the Bank Secrecy Act provision requiring nonfinancial trades or businesses to report large cash receipts to the Secretary of the Treasury (via FinCEN). The statute applies when any person engaged in a trade or business (other than a financial institution required to file a report under 31 USC 5313), in the course of such trade or business, receives more than $10,000 in coins or currency in 1 transaction (or 2 or more related transactions). 'Coins and currency' includes any monetary instrument (whether or not in bearer form) with a face amount of not more than $10,000, subject to specific exceptions for certain checks. Section 5331 also applies to any person who is required to file a report under section 6050I(g) of the Internal Revenue Code of 1986. Reports must be filed 'in such form as the Secretary may prescribe' and must contain the information specified by Treasury regulations, including the identity of the person from whom the coins or currency were received, the identity of the person on whose behalf the transaction was conducted, a description of the transaction, and the amount of coins or currency received. The statute exempts amounts received by financial institutions required to file a report under 31 USC 5313 and transactions occurring entirely outside the United States. Implementing regulations are issued by FinCEN in 31 CFR Chapter X. Section 5331 is one of the core BSA reporting pillars alongside the currency transaction report under 31 USC 5313 and the suspicious activity report regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bsa-31-usc-5311-5314-bank-secrecy-act"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-31-usc-5363-uigea-unlawful-internet-gambling",
    "title": "31 USC § 5363 - Unlawful Internet Gambling Enforcement Act (UIGEA) Payment Prohibition",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "31 USC § 5363 (enacted as the Unlawful Internet Gambling Enforcement Act of 2006, Pub. L. 109-347 Title VIII) prohibits any person engaged in the business of betting or wagering from knowingly accepting payments in connection with another person's participation in unlawful Internet gambling: subsection (1) prohibits accepting credit, or the proceeds of credit, extended to or on behalf of such other person (including credit extended through the use of a credit card); subsection (2) prohibits accepting electronic fund transfers, funds transmitted by or through a money transmitting business, or proceeds of such transfers; subsection (3) prohibits accepting checks, drafts, or similar instruments drawn by or on behalf of the gambler payable through any financial institution; subsection (4) prohibits accepting proceeds of any other financial transaction involving a financial institution as payor or financial intermediary as prescribed by regulation; the implementing regulations are codified at 12 CFR Part 233 (Federal Reserve Regulation GG) requiring financial institutions to establish and implement policies and procedures reasonably designed to identify and block restricted transactions; civil and criminal penalties apply under §§ 5366-5367.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "uigea_provisions",
        "implementing_regulation_12_cfr_part_233",
        "wire_act_intersection",
        "industry_mapping",
        "enforcement_anchors",
        "unlawful_internet_gambling_definition_5362"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1084-wire-act-gambling",
      "us-bank-secrecy-act-1970",
      "us-41-usc-3301-full-open-competition-federal-procurement"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-33-cfr-part-100-marine-events-regattas-parades",
    "title": "US 33 CFR Part 100: Marine Events of National and International Significance and Regattas",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 33 CFR Part 100 governs the Coast Guard regulation of regattas marine parades and other marine events that pose potential hazards to navigation safety of life and property in waters of the United States. Event sponsors must submit a CG-3676 Notice of Marine Event at least 135 days in advance (regional variation applies) to enable Coast Guard review and potential Special Local Regulation (SLR) publication. SLRs may restrict vessel transit and operations within an event area for the duration; non-compliance with SLR is enforceable under 33 CFR 100.40 with civil penalties up to $108,489 per day per violation (2024 dollars).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "pwsa",
        "cfr_33_165",
        "cfr_33_1233",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-33-cfr-part-165-regulated-navigation-areas-limited-access",
    "title": "US 33 CFR Part 165: Regulated Navigation Areas and Limited Access Areas",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 33 CFR Part 165 governs the establishment of Regulated Navigation Areas (RNAs), safety zones, security zones, and naval vessel protection zones (NVPZ) in US navigable waters by the Coast Guard. Coast Guard District Commanders and Captains of the Port (COTP) may establish temporary or permanent zones to address hazards, security risks, special events, or vessel transits. Operators must comply with notice requirements obtain permission to enter zones and report to designated channels. Naval Vessel Protection Zones extend 500 yards around US naval vessels with 100-yard exclusion zone; entering inside 100 yards without authorization is a federal offense.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "psa_2002",
        "mtsa",
        "cfr_33_104",
        "pwsa",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-33-cfr-part-323-section-404-clean-water-permits",
    "title": "US 33 CFR Part 323: Permits for Discharges of Dredged or Fill Material into Waters of the United States (Section 404 Clean Water Act)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 33 CFR Part 323 implements Section 404 of the Clean Water Act (CWA) governing the discharge of dredged or fill material into waters of the United States (WOTUS) including wetlands. The US Army Corps of Engineers issues Section 404 permits (individual or general); EPA can veto or modify Corps permits under CWA Section 404(c). Permits are individual or general (Nationwide Permits NWP regional permits programmatic permits). Applicants must demonstrate no practicable alternative to the discharge and that proposed mitigation will compensate for unavoidable impacts. The Supreme Court Sackett v. EPA decision (2023) limited WOTUS to relatively permanent waters and wetlands with continuous surface connection to such waters; subsequent agency rulemaking implements the narrower jurisdiction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cwa",
        "cfr_40_230",
        "cfr_33_320_330",
        "cwa_section_402",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-34-cfr-part-106-title-ix-sex-discrimination-education",
    "title": "US 34 CFR Part 106: Nondiscrimination on the Basis of Sex in Education Programs or Activities Receiving Federal Financial Assistance (Title IX)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 34 CFR Part 106 implements Title IX of the Education Amendments of 1972 prohibiting sex discrimination in education programs or activities receiving federal financial assistance. Covered entities must designate Title IX Coordinator(s); publish nondiscrimination notices; adopt and publish grievance procedures for sex discrimination complaints including sex-based harassment; respond promptly and equitably to known incidents; and provide supportive measures. NOTE: The August 2024 Title IX regulations were vacated by federal court ruling in January 2025; the 2020 regulations are in effect as of May 2026. The 2020 regulations require live hearings cross-examination for postsecondary cases and explicit definition of sexual harassment with three categories (quid pro quo Davis hostile environment sexual assault dating violence domestic violence stalking).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "title_ix",
        "cfr_34_99",
        "cleary_act",
        "vawa_amendments",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-34-cfr-part-99-ferpa-student-records",
    "title": "US 34 CFR Part 99: Family Educational Rights and Privacy (FERPA)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 34 CFR Part 99 implements the Family Educational Rights and Privacy Act (FERPA) of 1974 protecting the privacy of student education records. FERPA applies to educational agencies and institutions receiving funds under any Department of Education program. Parents (or eligible students 18+) have the right to inspect and review education records, request amendment, and control disclosure to third parties (with exceptions including school officials with legitimate educational interest, schools to which student is transferring, accrediting agencies, financial aid, health and safety emergencies, and parents of dependent students under tax code). Annual notification of FERPA rights required. Penalty: withholding of Department of Education funds (no private right of action per Gonzaga v. Doe).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ferpa",
        "coppa",
        "cfr_34_106",
        "hipaa",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-37-cfr-part-1-uspto-patent-rules-practice",
    "title": "US 37 CFR Part 1: Rules of Practice in Patent Cases (USPTO)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 37 CFR Part 1 governs the procedural rules for prosecuting patent applications and reissue applications before the United States Patent and Trademark Office (USPTO). Part 1 covers patent application requirements (utility design and plant patents); filing date requirements; specification and claims; oath or declaration; information disclosure statement (IDS); foreign filing license; office action response procedures; petitions; assignments and licenses; fees; and post-grant proceedings (limited - separate Part 42 for PTAB). The America Invents Act (AIA) of 2011 transitioned the US to a first-to-file system effective March 16 2013 and introduced post-grant review and inter partes review procedures handled by the Patent Trial and Appeal Board (PTAB).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "patent_act",
        "aia",
        "cfr_37_42",
        "cfr_37_11",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-40-cfr-1037-heavy-duty-vehicle-ghg-standards",
    "title": "40 CFR Part 1037 Heavy-Duty Vehicle GHG Standards",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "40 CFR Part 1037 sets EPA greenhouse gas (GHG) emission standards for heavy-duty motor vehicles. Section 1037.105 establishes CO2 emission standards for vocational vehicles, and Section 1037.106 establishes exhaust emission standards (including CO2) for tractors above 26,000 pounds GVWR, covering Class 7 and Class 8 tractors across roof-height and cab configurations. The Part 2 (Phase 2) standards apply to model year 2021 and later vehicles, with more stringent requirements taking effect for model year 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-air-act-mobile-source-emission-standards",
      "us-nhtsa-fmvss-federal-motor-vehicle-safety-standards-49-cfr-571"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-40-cfr-part-122-npdes-permit-regulations",
    "title": "US 40 CFR Part 122: EPA Administered Permit Programs - The National Pollutant Discharge Elimination System (NPDES)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 40 CFR Part 122 implements the National Pollutant Discharge Elimination System (NPDES) under Clean Water Act Section 402. NPDES permits are required for any discharge of pollutants from a point source to waters of the United States. The regulation covers permit application requirements, permit conditions including effluent limitations based on technology-based standards and water-quality-based limits, monitoring and reporting (DMR), stormwater discharge under MS4 and industrial categories, and concentrated animal feeding operations (CAFOs). 47 states administer NPDES under state programmes; EPA administers in remaining states and on Tribal lands. Compliance is foundational to industrial water management in the US.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cwa_section_402",
        "cfr_40_124",
        "cfr_40_125",
        "cfr_40_403",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-40-cfr-part-261-rcra-hazardous-waste-identification",
    "title": "US 40 CFR Part 261: Identification and Listing of Hazardous Waste",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 40 CFR Part 261 identifies solid wastes that are subject to regulation as hazardous wastes under Subtitle C of the Resource Conservation and Recovery Act (RCRA). Wastes are hazardous if they exhibit a characteristic (ignitability, corrosivity, reactivity, toxicity via TCLP) or are listed in Subparts D (F-list non-specific sources, K-list specific sources) or E (P-list and U-list discarded commercial chemical products). Generators must determine if their waste is hazardous before disposal and obtain an EPA ID number if generating more than 100 kg of hazardous waste in a calendar month or any acutely hazardous waste.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "rcra",
        "cfr_40_262",
        "cfr_40_268",
        "cercla",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-40-cfr-part-262-hazardous-waste-generator-standards",
    "title": "US 40 CFR Part 262: Standards Applicable to Generators of Hazardous Waste",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 40 CFR Part 262 establishes standards for generators of hazardous waste under RCRA Subtitle C including the hazardous waste determination, EPA notification, manifest requirements for off-site shipment, on-site accumulation limits and standards, biennial reporting, satellite accumulation, and contingency planning. Standards differ by generator category: Very Small Quantity Generator (VSQG), Small Quantity Generator (SQG), and Large Quantity Generator (LQG). All generators must obtain an EPA Identification Number before initiating off-site shipment and use the Uniform Hazardous Waste Manifest per 40 CFR Part 263.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "rcra",
        "cfr_40_261",
        "cfr_40_263",
        "cfr_40_268",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-40-usc-3131-miller-act-federal-construction-bonds",
    "title": "40 USC § 3131 - Miller Act (Bonds for Federal Construction Contracts)",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "40 USC § 3131 (Miller Act, originally enacted in 1935 as the Heard Act successor, Pub. L. 74-321; recodified by Pub. L. 107-217) requires every contractor awarded a federal construction contract exceeding USD 100,000 to furnish two types of bonds: a performance bond protecting the United States and a payment bond protecting subcontractors and suppliers of labor and material: subsection (a) defines 'contractor' as a person awarded a contract described in subsection (b); subsection (b) sets the dual bond requirements - a performance bond with surety satisfactory to the contracting officer and in an amount the officer considers adequate, and a payment bond with surety satisfactory to the officer in an amount equal to the total contract value (unless the contracting officer makes a written impractical determination, in which case not less than the performance bond amount); subsection (d) permits waiver for contracts performed in foreign countries where bonds are impractical to furnish; the Miller Act provides the primary federal protection mechanism for subcontractors and suppliers who otherwise would have no recourse against the federal government and limited recourse against general contractors; FAR Subpart 28.1 implements the Miller Act with FAR 52.228-15 (Performance and Payment Bonds-Construction) clause.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "miller_act_related_provisions",
        "subcontractor_payment_bond_claim_section_3133",
        "far_implementation",
        "industry_mapping",
        "enforcement_anchors",
        "alternative_to_payment_bond_section_3132"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-10-usc-3201-dod-competition-requirements",
      "us-40-usc-3142-davis-bacon-prevailing-wage"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-40-usc-3142-davis-bacon-prevailing-wage",
    "title": "40 USC § 3142 - Davis-Bacon Act Prevailing Wage for Federal Construction Contracts",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "40 USC § 3142 (originally enacted as the Davis-Bacon Act of 1931, Pub. L. 71-798; recodified by Pub. L. 107-217) requires every contract in excess of $2,000 for the construction, alteration, or repair of public buildings or public works of the United States to contain a provision stating the minimum wages to be paid to various classes of laborers and mechanics; subsection (a) establishes the application threshold and requirement; subsection (b) requires the Secretary of Labor to determine prevailing wages for the corresponding classes of laborers and mechanics employed on projects of a character similar to the contract work in the locality; subsection (c) prescribes three required contract stipulations: (1) workers must be paid unconditionally at least weekly with no deductions other than permitted by law, (2) the wage scale must be posted prominently at the worksite, and (3) the contracting officer may withhold payments to cover wage differences owed to workers; Davis-Bacon is the foundational federal construction prevailing wage statute, supplemented by the Davis-Bacon Related Acts that extend prevailing wage requirements to federally-funded infrastructure projects; the Department of Labor's Wage and Hour Division issues Davis-Bacon wage determinations published at sam.gov/wage-determinations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "parallel_labor_standards_statutes",
        "davis_bacon_related_acts",
        "build_america_buy_america_intersection",
        "executive_order_14026",
        "implementing_regulations",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-41-usc-6707-service-contract-act",
      "us-41-usc-6502-walsh-healey-public-contracts-act",
      "us-41-usc-3301-full-open-competition-federal-procurement"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-41-cfr-part-60-1-ofccp-equal-employment-federal-contractors",
    "title": "US 41 CFR Part 60-1: Obligations of Contractors and Subcontractors (OFCCP)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 41 CFR Part 60-1 implements Executive Order 11246 (as amended) prohibiting federal contractors and subcontractors with contracts of $10,000 or more from employment discrimination on the basis of race, color, religion, sex, sexual orientation, gender identity, or national origin. Contractors with 50 or more employees and contracts of $50,000 or more must develop and maintain a written Affirmative Action Program (AAP) for women and minorities (Part 60-2) and for individuals with disabilities (Part 60-741) and protected veterans (Part 60-300). OFCCP conducts compliance reviews including desk audit, on-site review, and pre-award reviews of contractors. Sanctions include contract cancellation, debarment, and back pay awards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eo_11246",
        "cfr_41_60_741",
        "cfr_41_60_300",
        "title_vii",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-41-usc-3301-full-open-competition-federal-procurement",
    "title": "41 USC 3301 - Full and Open Competition in Federal Procurement (Competition in Contracting Act)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "41 USC 3301 (originally enacted in 1984 as the Competition in Contracting Act, recodified in 2011 by Pub L 111-350) requires executive agencies conducting procurement of property or services to obtain full and open competition through the use of competitive procedures, by either soliciting sealed bids or requesting competitive proposals; sealed bids are required when time permits, award will be made on the basis of price and other price-related factors, discussions are not necessary, and there is a reasonable expectation of more than one bid; otherwise competitive proposals must be requested; the Federal Acquisition Regulation implements these requirements consistent with the need to efficiently fulfill the Government's requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "exceptions_to_full_competition",
        "far_implementation",
        "dfars_overlap",
        "industry_mapping",
        "enforcement_anchors",
        "sealed_bid_vs_competitive_proposal_test"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-41-usc-3304-noncompetitive-procedures-exceptions",
    "title": "41 USC § 3304 - Use of Noncompetitive Procedures (Exceptions to Full and Open Competition)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "41 USC § 3304 (originally enacted as part of the Competition in Contracting Act of 1984 and recodified by Pub. L. 111-350) sets out the seven exceptions permitting an executive agency to use procedures other than competitive procedures under 41 USC § 3301: (1) only one responsible source and no other supplies or services will satisfy agency requirements; (2) unusual and compelling urgency that the Federal Government would be seriously injured by waiting; (3) industrial mobilization, engineering, developmental, or research capability or expert services maintenance; (4) terms of an international agreement or treaty or foreign government direction; (5) statute expressly authorizes or requires procurement be made through another executive agency or from a specified source, or the agency's need is for a brand-name commercial item; (6) disclosure of the agency's needs would compromise the national security; (7) the head of the executive agency determines that it is necessary in the public interest, with Congressional notification at least 30 days before award; each exception requires written justification and approval at escalating tiers ($550K, $13.5M, $93M, above $93M) per FAR 6.304, with the justification publicly posted on SAM.gov within 14 days of award.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "civilian_versus_defense_parallel",
        "far_implementation",
        "gao_bid_protest_jurisdiction",
        "industry_mapping",
        "enforcement_anchors",
        "approval_authority_dollar_thresholds_far_6_304"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-10-usc-3201-dod-competition-requirements",
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-41-usc-4304-specific-costs-not-allowable",
    "title": "41 USC § 4304 - Specific Costs Not Allowable Under Federal Contracts",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "41 USC § 4304 (originally enacted as part of the Procurement Integrity Act-related amendments to cost principles; recodified by Pub. L. 111-350) lists categories of costs that are not allowable as charges to federal contracts: (1) entertainment costs including amusement, diversion, and social activities; (2) costs incurred to influence (directly or indirectly) legislative action on any matter; (3) costs of defending against civil or criminal fraud proceedings if the contractor is found liable; (4) payments of fines and penalties resulting from violations of, or failure to comply with, federal, state, local, or foreign laws and regulations; (5) costs of membership in any social, dining, or country club or organization; (6) costs of alcoholic beverages; (7) contributions or donations, regardless of the recipient; (8) costs of advertising designed to promote the contractor or its products; (9) costs of promotional items and memorabilia, including models, gifts, and souvenirs; the section is implemented through FAR Subpart 31.205 (Selected Costs - Definitions of Allowability) and applies to cost-reimbursement contracts, modifications to fixed-price contracts when cost data is used, and any contract requiring submission of cost data per 10 USC 3705 and 41 USC 3504.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "far_implementation",
        "cost_accounting_standards",
        "false_claims_act_intersection",
        "industry_mapping",
        "enforcement_anchors",
        "cost_accounting_standards_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-10-usc-3201-dod-competition-requirements",
      "us-far-part-19-small-business-set-asides"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-41-usc-6502-walsh-healey-public-contracts-act",
    "title": "41 USC § 6502 - Walsh-Healey Public Contracts Act (Required Contract Stipulations)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "41 USC § 6502 (originally enacted as the Walsh-Healey Public Contracts Act of 1936, Pub. L. 74-846; recodified by Pub. L. 111-350) requires every federal contract exceeding $10,000 for the manufacture or furnishing of materials, supplies, articles, and equipment to contain four mandatory representations and stipulations: (1) WAGES - all individuals employed by the contractor in performing the contract will be paid not less than the prevailing minimum wages, as determined by the Secretary of Labor; (2) HOURS - no individual employed by the contractor in performing the contract shall be permitted to work in excess of 40 hours in any one week (overtime under FLSA may apply); (3) CHILD AND CONVICT LABOR - no individual under 16 years of age and no incarcerated individual will be employed by the contractor (with limited exceptions for certain federal/state convict-labor programs); (4) SAFETY AND HEALTH - no part of the contract will be performed in plants, factories, buildings, or surroundings that are unsanitary, hazardous, or dangerous to the health and safety of employees; the Act is enforced by the Department of Labor Wage and Hour Division; violations expose contractors to back wage liability, contract cancellation, debarment from federal contracting for 3 years under 41 USC § 6504, and liquidated damages.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "parallel_labor_standards_statutes",
        "executive_order_14026",
        "fair_labor_standards_act_overlap",
        "implementing_regulations",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-41-usc-6707-service-contract-act",
      "us-40-usc-3142-davis-bacon-prevailing-wage",
      "us-41-usc-3301-full-open-competition-federal-procurement"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-41-usc-6707-service-contract-act",
    "title": "41 USC § 6707 - Service Contract Act Wage Determinations and Successor Contract Provisions",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "41 USC § 6707 (part of the Service Contract Act of 1965 as recodified by Pub. L. 111-350) sets out the wage determination and successor contract protection framework for federal service contracts exceeding $2,500: subsection (a) gives the Secretary of Labor enforcement authority including regulations, orders, hearings, decisions, and other actions to enforce the Service Contract Act; subsection (b) authorizes the Secretary to provide reasonable limitations, variations, tolerances, and exemptions but only where necessary and proper in the public interest or to prevent serious impairment of Federal Government business while protecting prevailing labor standards; subsection (c) - the successor contract provision - requires successor contractors providing substantially identical services to compensate service employees at no less than the wages and fringe benefits (including accrued and prospective increases) earned under the predecessor contract pursuant to collective bargaining agreement, unless the Secretary determines after hearing that the predecessor wages are substantially at variance with prevailing wages for similar services in the same locality; the SCA is enforced by the Department of Labor Wage and Hour Division; Standard Form SF-98 wage determinations are incorporated into solicitations and contracts; successor contract violations expose contractors to debarment under 41 USC § 6706.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "parallel_labor_standards_statutes",
        "executive_order_14026",
        "implementing_regulations",
        "industry_mapping",
        "enforcement_anchors",
        "successor_contract_protection_section_6707_c"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-40-usc-3142-davis-bacon-prevailing-wage",
      "us-41-usc-6502-walsh-healey-public-contracts-act",
      "us-41-usc-3301-full-open-competition-federal-procurement"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-41-usc-8302-buy-american-act",
    "title": "41 USC § 8302 - Buy American Act (American Materials Required for Public Use)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "41 USC § 8302 (originally enacted as the Buy American Act of 1933, Pub. L. 72-428; recodified into Title 41 by Pub. L. 111-350) requires federal agencies to acquire only unmanufactured articles, materials, and supplies that have been mined or produced in the United States, and manufactured articles, materials, and supplies that have been manufactured in the United States substantially all from articles, materials, or supplies mined, produced, or manufactured in the United States, for public use; subsection (b) provides three exceptions: (1) inconsistent with the public interest; (2) cost would be unreasonable; (3) articles are not mined, produced, or manufactured in the United States in sufficient and reasonably available commercial quantities and of a satisfactory quality; the Act does not apply to materials for use outside the US, items under reciprocal defense procurement agreements or trade agreements (WTO GPA and US FTAs), or contracts below the micro-purchase threshold; the Build America Buy America Act (BABA) of 2021 (Pub. L. 117-58 §§ 70901-70927) extended Buy American principles to federal financial assistance for infrastructure projects; for iron and steel, special rules require all manufacturing processes from initial melting through coating to occur in the United States; current cost-of-components threshold under FAR 25.003 is 65% (rising to 75% by 2029) of total component cost.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "build_america_buy_america_extension",
        "trade_agreement_waivers",
        "far_implementation",
        "executive_order_14005",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-trade-agreements-act-1979-19-usc-ch13",
      "wto-agreement-government-procurement-2012-gpa"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-42-cfr-411-353-stark-prohibition-certain-referrals",
    "title": "US 42 CFR 411.353: Prohibition on Certain Referrals by Physicians and Limitations on Billing (Stark Law Implementing Regulation)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Section 411.353 is the operative implementing regulation of the physician self-referral (Stark) law. Except as provided in the subpart, a physician with a direct or indirect financial relationship with an entity (or whose immediate family member has one) may not refer Medicare patients to that entity for designated health services, and the entity may not bill Medicare, any individual, or any third-party payer for services furnished under a prohibited referral. No Medicare payment may be made for a designated health service furnished pursuant to a prohibited referral, the entity bears the ultimate burden of proof on appeal, and amounts wrongly collected must be refunded on a timely basis. The section also provides narrow exceptions for unknowing entities and limited-duration temporary noncompliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-physician-self-referral-stark-law",
      "us-anti-kickback-statute",
      "us-cms-conditions-participation-hospitals-42-cfr-482-medicare-medicaid"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-42-cfr-482-13-hospital-condition-participation-patient-rights",
    "title": "US 42 CFR 482.13: Condition of Participation - Patient's Rights (Hospitals)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Section 482.13 is the Medicare and Medicaid Condition of Participation requiring a hospital to protect and promote each patient's rights. It mandates advance notice of rights, a governing-body-accountable grievance process, the right to participate in care planning and make informed decisions, privacy and care in a safe setting, freedom from abuse and from restraint or seclusion except to ensure immediate physical safety, confidentiality and access to clinical records, and strict order, monitoring, time-limit, and one-hour face-to-face requirements when restraint or seclusion is used. Failure to meet this condition jeopardizes a hospital's Medicare and Medicaid participation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-42-cfr-part-482-hospital-conditions-participation",
      "us-cms-conditions-participation-hospitals-42-cfr-482-medicare-medicaid",
      "us-emtala-emergency-treatment"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-42-cfr-part-2-2024",
    "title": "42 CFR Part 2 - Confidentiality of Substance Use Disorder Patient Records (2024 Final Rule)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation modifies the confidentiality rules for substance use disorder (SUD) patient records from federally assisted programs, primarily by permitting a single patient consent for all future uses and disclosures for treatment, payment, and health care operations (TPO), aligning Part 2 more closely with HIPAA. This key change, outlined in § 2.33, simplifies data sharing for care coordination while maintaining patient privacy protections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "us-21st-century-cures-act-2016"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-42-cfr-part-2-substance-use-disorder-confidentiality",
    "title": "42 CFR Part 2: Confidentiality of Substance Use Disorder Patient Records",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This regulation establishes strict confidentiality requirements for patient records related to substance use disorder treatment from federally assisted programs, governing how and when patient-identifying information can be disclosed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-42-cfr-part-422-medicare-advantage",
    "title": "US 42 CFR Part 422: Medicare Advantage Program",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 42 CFR Part 422 implements the Medicare Advantage (Part C) program by which Medicare beneficiaries may enroll in managed care plans offered by private organizations under contract with CMS. Part 422 covers eligibility enrollment and disenrollment; benefits and beneficiary protections; quality improvement standards and Star Ratings; provider participation; bidding and payment; marketing; appeals and grievances; compliance and program integrity; and Special Needs Plans (SNPs). Plans must offer at minimum Medicare Part A and Part B benefits, may offer Part D drugs (MA-PD), and many offer supplemental benefits. Annual Notice of Change (ANOC) and Evidence of Coverage (EOC) documents must be delivered to enrollees by September 30 each year.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "social_security_act",
        "cfr_42_423",
        "cfr_42_417",
        "cfr_42_460",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-42-cfr-part-423-medicare-part-d-prescription-drug",
    "title": "US 42 CFR Part 423: Voluntary Medicare Prescription Drug Benefit (Part D)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 42 CFR Part 423 implements Medicare Part D the voluntary prescription drug benefit established by the Medicare Modernization Act of 2003. Stand-alone prescription drug plans (PDPs) and Medicare Advantage Prescription Drug plans (MA-PDs) provide drug coverage under contract with CMS. Part 423 covers eligibility enrollment and disenrollment; benefits and beneficiary protections; cost-sharing including the standard benefit and Low-Income Subsidy (LIS) Extra Help; formulary requirements transition fills and pharmacy and therapeutic committee; bidding and payment; marketing; appeals and grievances including coverage determinations and redeterminations; quality measures and Star Ratings; pharmacy operations and pharmacy networks; and compliance and program integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "mma_2003",
        "cfr_42_422",
        "iqr_act_2022",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-42-cfr-part-431-medicaid-state-plan-administration",
    "title": "42 CFR Part 431 - State Organization and General Administration",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This regulation requires U.S. states to establish a single state agency to administer their Medicaid plan, ensuring statewide operation, beneficiary rights like free provider choice and fair hearings, and maintaining proper records and reports.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-42-cfr-part-482-hospital-conditions-participation",
    "title": "42 CFR Part 482 - Conditions of Participation for Hospitals",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "Hospitals participating in Medicare and Medicaid must meet specific conditions related to administration, basic functions, patient rights, and emergency preparedness to ensure patient health and safety.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "us-42-cfr-part-485-conditions-various-facilities",
    "title": "42 CFR Part 485 - Conditions of Participation: Specialized Providers",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Specialized providers, including Comprehensive Outpatient Rehabilitation Facilities and Rural Emergency Hospitals, must comply with specific conditions of participation covering governance, services, staffing, physical environment, and patient care to be certified for Medicare and Medicaid.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-42-cfr-part-488-survey-certification-enforcement",
    "title": "42 CFR Part 488 - Survey, Certification, and Enforcement Procedures",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This regulation establishes the procedures for survey, certification, and enforcement for healthcare providers and suppliers participating in Medicare and Medicaid, including requirements for state survey agencies and accrediting organizations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-42-cfr-part-493-clinical-laboratory-clia",
    "title": "42 CFR Part 493 - Laboratory Requirements",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This regulation establishes federal quality standards for all laboratory testing to ensure the accuracy, reliability, and timeliness of patient test results, regardless of where the test is performed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-42-cfr-part-93-research-misconduct-ori",
    "title": "42 CFR Part 93 - PHS Policies on Research Misconduct",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "42 CFR Part 93 sets the Public Health Service policies on research misconduct administered by the Office of Research Integrity. Section 93.103 defines research misconduct as fabrication, falsification, or plagiarism in proposing, performing, or reviewing research or in reporting research results, and Section 93.104 establishes the three-part test that a finding requires. Section 93.301 requires institutions with PHS-supported research to provide an assurance of compliance and to maintain written policies and procedures for handling allegations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-42-usc-12112-ada-employment-discrimination-prohibited",
    "title": "US Americans with Disabilities Act - 42 USC 12112 Discrimination in Employment (ADA Title I)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "42 USC 12112 titled 'Discrimination' is the core Title I of the Americans with Disabilities Act provision prohibiting employment discrimination against qualified individuals with disabilities. Subsection (a) provides the general rule: no covered entity shall discriminate against a qualified individual on the basis of disability in regard to job application procedures, the hiring, advancement, or discharge of employees, employee compensation, job training, and other terms, conditions, and privileges of employment. Subsection (b) identifies seven categories of discriminatory practices: (1) limiting, segregating, or classifying a job applicant or employee in a way that adversely affects opportunities or status because of disability; (2) participating in a contractual or other arrangement or relationship that has the effect of subjecting a covered entity's qualified applicant or employee with a disability to prohibited discrimination; (3) utilizing standards, criteria, or methods of administration that have the effect of discrimination on the basis of disability or that perpetuate the discrimination of others who are subject to common administrative control; (4) excluding or otherwise denying equal jobs or benefits to a qualified individual because of the known disability of an individual with whom the qualified individual is known to have a relationship or association; (5) not making reasonable accommodations to the known physical or mental limitations of an otherwise qualified individual with a disability who is an applicant or employee, unless the covered entity can demonstrate that the accommodation would impose an undue hardship; (6) using qualification standards, employment tests, or other selection criteria that screen out or tend to screen out an individual with a disability or a class of individuals with disabilities unless the standard, test, or other selection criteria is shown to be job-related for the position in question and is consistent with business necessity; and (7) failing to select and administer tests concerning employment in the most effective manner to ensure that, when the test is administered to a job applicant or employee who has a disability that impairs sensory, manual, or speaking skills, the test results accurately reflect the skills, aptitude, or whatever other factor of such applicant or employee that such test purports to measure, rather than reflecting the impaired sensory, manual, or speaking skills of such employee or applicant. Subsection (d) governs medical examinations and inquiries with pre-employment, post-offer, and during-employment requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-americans-with-disabilities-act"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-42-usc-2000e-2-title-vii-unlawful-employment-practices",
    "title": "US Civil Rights Act - 42 USC 2000e-2 Title VII Unlawful Employment Practices",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "42 USC 2000e-2 titled 'Unlawful employment practices' is the core Title VII of the Civil Rights Act of 1964 provision prohibiting employment discrimination on the basis of race, color, religion, sex, or national origin. Subsection (a) makes it an unlawful employment practice for an employer to (1) fail or refuse to hire or to discharge any individual, or otherwise to discriminate against any individual with respect to his compensation, terms, conditions, or privileges of employment, because of such individual's race, color, religion, sex, or national origin; or (2) limit, segregate, or classify his employees or applicants for employment in any way which would deprive or tend to deprive any individual of employment opportunities or otherwise adversely affect his status as an employee, because of such individual's race, color, religion, sex, or national origin. Subsection (k) codifies the disparate impact standard: an unlawful employment practice based on disparate impact is established when a complaining party demonstrates that a respondent uses a particular employment practice that causes a disparate impact on the basis of race, color, religion, sex, or national origin, and the respondent fails to demonstrate that the challenged practice is job related for the position in question and consistent with business necessity. Subsection (m) codifies the mixed-motive analysis added by the Civil Rights Act of 1991: a complaining party demonstrates a violation by showing that race, color, religion, sex, or national origin was a motivating factor for any employment practice, even though other factors also motivated the practice.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-civil-rights-act-title-vii"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-42cfr-part2-substance-use-2026",
    "title": "US 42 CFR Part 2 - Confidentiality of Substance Use Disorder Patient Records (2026 Alignment)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "42 CFR Part 2 imposes strict confidentiality protections for substance use disorder (SUD) patient records. It requires specific written consent for most disclosures (including to health information exchanges), prohibits redisclosure without consent, mandates security safeguards, and aligns with HIPAA following the 2024-2026 rulemaking. Violations carry significant civil and criminal penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 3
  },
  {
    "node_id": "us-44-usc-3551-fisma-purposes",
    "title": "44 USC § 3551 - Federal Information Security Modernization Act (FISMA) Purposes",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "44 USC § 3551 (Federal Information Security Modernization Act of 2014, Pub. L. 113-283 - replacing the Federal Information Security Management Act of 2002) establishes the purposes of FISMA Subchapter II: subsection (1) provides a comprehensive framework for ensuring the effectiveness of information security controls over information resources supporting federal operations and assets; subsection (2) recognizes the highly networked nature of federal computing environment, requiring government-wide management and oversight of related information security risks; subsection (3) requires development and maintenance of minimum controls to protect federal information and information systems; subsection (4) provides mechanisms for improved oversight of agency security programs including automated diagnostic tools; subsection (5) acknowledges commercially developed security products offering advanced, dynamic, robust, and effective security solutions important to national defense; subsection (6) allows agencies to select specific technical security solutions from commercially available options; FISMA is implemented through OMB Circular A-130, NIST SP 800-53 security controls catalog, NIST SP 800-37 risk management framework, agency-specific implementation policies, and Inspector General annual evaluations; the FedRAMP authorization program for cloud services operates within the FISMA framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fisma_subchapter_provisions",
        "fedramp_integration",
        "nist_implementation_standards",
        "industry_mapping",
        "enforcement_anchors",
        "annual_evaluation_section_3555"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-44-usc-3614-fedramp-authorization-program",
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355",
      "us-41-usc-3301-full-open-competition-federal-procurement"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-44-usc-3614-fedramp-authorization-program",
    "title": "44 USC § 3614 - Federal Risk and Authorization Management Program (FedRAMP)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "44 USC § 3614 (enacted by the FedRAMP Authorization Act of 2022, Pub. L. 117-263 Title LIX) codifies the Federal Risk and Authorization Management Program (FedRAMP) as the government-wide standardized approach to security assessment, authorization, and continuous monitoring of cloud computing products and services used by federal agencies: subsection (a) directs the Director of OMB to issue guidance specifying categories or characteristics of cloud computing products and services within FedRAMP scope; subsection (b) establishes requirements for agencies to obtain FedRAMP authorization when operating cloud computing products or services; subsection (c) directs the OMB Director to oversee the effectiveness of FedRAMP and the FedRAMP Board (established at 44 USC 3610(d)); the program is administered by the General Services Administration (GSA) FedRAMP Program Management Office (PMO) and supported by the Joint Authorization Board (JAB - DoD, DHS, GSA) and individual agency authorizing officials; authorization types include FedRAMP Ready, FedRAMP Authorization to Operate at Low, Moderate, High, and LiSaaS impact levels per FIPS 199; the program incorporates NIST SP 800-53 Revision 5 security controls baseline; statute is scheduled to sunset 5 years after enactment (December 23, 2027) absent reauthorization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_fedramp_provisions",
        "fisma_intersection",
        "implementing_authorities",
        "industry_mapping",
        "enforcement_anchors",
        "fedramp_authorization_types"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355",
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-far-part-19-small-business-set-asides"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-45-cfr-46-116-common-rule-informed-consent",
    "title": "US 45 CFR 46.116 (Common Rule): General Requirements for Informed Consent",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Section 46.116 of the Common Rule sets the general requirements for informed consent in federally conducted or supported human-subjects research. An investigator must obtain the legally effective informed consent of the subject or the subject's legally authorized representative before involvement, under circumstances that minimize coercion or undue influence, in understandable language, beginning with a concise presentation of key information, and free of exculpatory language. The section enumerates the basic elements that must be disclosed, additional elements when appropriate, and the elements of broad consent for storage and secondary research use of identifiable private information or biospecimens.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-45-cfr-part-46-common-rule-human-subjects-research",
      "us-national-research-act-1974-irb-belmont",
      "us-21-cfr-part-50-protection-human-subjects"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-45-cfr-part-160-hipaa-general-administrative",
    "title": "US 45 CFR Part 160: General Administrative Requirements (HIPAA)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 45 CFR Part 160 contains the general administrative requirements applicable to all HIPAA Administrative Simplification rules including the Privacy Security Breach Notification Enforcement and Transactions Code Sets and Identifiers rules in 45 CFR Parts 162 to 164. Part 160 covers preemption of State law (Subpart B); applicability to covered entities and business associates (Subpart A); compliance and investigations (Subpart C); imposition of civil money penalties (Subpart D); and procedures for hearings (Subpart E). The HITECH Act of 2009 strengthened enforcement with tiered penalty structure: Tier 1 (did not know) $137 per violation; Tier 2 (reasonable cause) $1,379; Tier 3 (willful neglect corrected) $13,785; Tier 4 (willful neglect not corrected) $68,928 with $2,067,813 annual cap per tier (2024 dollars).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "hipaa",
        "hitech",
        "cfr_45_164",
        "cfr_45_162",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-45-cfr-part-162-hipaa-administrative-simplification",
    "title": "45 CFR Part 162 - Administrative Requirements",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This regulation establishes requirements for covered entities to use standard unique identifiers, code sets, and transaction formats for administrative and financial healthcare transactions to simplify processes and reduce costs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-45-cfr-part-164-hipaa-security-rule-safeguards",
    "title": "45 CFR Part 164 - Security and Privacy",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI) and provide notifications to individuals, the media, and the Secretary in the event of a data breach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-37-dpo"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-45-cfr-part-46-common-rule-human-subjects-research",
    "title": "US 45 CFR Part 46: Protection of Human Subjects (Common Rule)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 45 CFR Part 46 (the Common Rule) establishes the principal federal regulation for the protection of human subjects in research conducted or supported by 15+ federal departments and agencies. Subpart A (the basic policy adopted by Common Rule signatories) covers Institutional Review Board (IRB) review and approval criteria, informed consent requirements, exemption categories (8 categories in revised 2018 Rule), expedited review procedures, and continuing review. Subparts B C D provide additional protections for pregnant women fetuses and neonates (Subpart B) prisoners (Subpart C) and children (Subpart D). Subpart E covers Registration of IRBs. The 2018 Revised Common Rule introduced single IRB review for multi-site studies broad consent for storage of identifiable biospecimens and new exemption categories.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nuremberg_code",
        "belmont_report",
        "common_rule_signatories",
        "fda_21_cfr_50_56",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-47-cfr-part-25-fcc-satellite-communications",
    "title": "US 47 CFR Part 25: Satellite Communications",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 47 CFR Part 25 governs FCC licensing operation and technical requirements for satellite communications including geostationary (GSO) and non-geostationary (NGSO) fixed-satellite service, mobile-satellite service, broadcasting-satellite service, and earth stations. Operators must obtain a Part 25 license from the FCC International Bureau before launching or transmitting; coordination with the National Telecommunications and Information Administration (NTIA) and the International Telecommunication Union (ITU) is required for global frequency assignments. Recent updates implement streamlined small-satellite licensing under Part 25 and orbital debris mitigation rules requiring 25-year post-mission disposal target.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "comm_act_1934",
        "itu_radio_regs",
        "cfr_47_5",
        "cfr_47_97",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-47-cfr-part-4-disruptions-communications-outage-reporting",
    "title": "47 CFR Part 4 - Disruptions to Communications: Outage Reporting, Notification Timeframes, Submarine Cable and DIRS",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "47 CFR Part 4 governs the mandatory reporting of significant disruptions to communications by covered communications providers to the Federal Communications Commission (FCC). Section 4.9 sets the threshold criteria for reporting an outage. For cable, satellite, signaling system 7, wireless and wireline providers, a Notification must be filed electronically within 120 minutes of discovering an outage of at least 30 minutes duration that, among other criteria, potentially affects at least 900,000 user-minutes of telephony service, affects at least 667 OC3 minutes, potentially affects special offices and facilities, or potentially affects a 911 special facility (as defined in Section 4.5(e)) or a 988 special facility (Section 4.5(f)). Interconnected VoIP service providers must file a Notification within 240 minutes of discovering an outage of at least 30 minutes duration that potentially affects a 911 special facility. After a Notification, the provider must file an Initial Communications Outage Report not later than 72 hours after discovering the outage and a Final Communications Outage Report not later than 30 days after discovering the outage. Section 4.11 specifies the content and attestation requirements for the Notification and the Initial and Final reports. Section 4.15 establishes submarine cable outage reporting, treating an outage of a portion of a submarine cable system between submarine line terminal equipment of 30 minutes or more, or an outage of any fiber pair on a cable segment of four hours or more, as reportable. Section 4.18 requires mandatory Disaster Information Reporting System (DIRS) reporting by cable, wireless, wireline and interconnected VoIP providers when the Commission activates DIRS, including daily infrastructure-status reports and a single final report within 24 hours of DIRS deactivation. Part 4 is the principal federal rule governing communications outage transparency in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-communications-act-1934"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-47-cfr-part-51-interconnection",
    "title": "47 CFR Part 51 - Interconnection: Duty to Negotiate, Unbundled Network Elements, Collocation and Reciprocal Compensation",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "47 CFR Part 51 implements the interconnection, unbundling, collocation and intercarrier compensation duties that the Telecommunications Act of 1996 (sections 251 and 252 of the Communications Act) imposes on incumbent local exchange carriers (incumbent LECs) and requesting telecommunications carriers. Section 51.301 establishes the duty to negotiate in good faith the terms and conditions of agreements that fulfill the duties under sections 251(b) and (c) of the Act, applying to both the incumbent LEC and the requesting carrier, and lists actions that violate that duty. Section 51.307 requires an incumbent LEC to provide nondiscriminatory access to network elements on an unbundled basis at any technically feasible point, on terms that are just, reasonable and nondiscriminatory, in accordance with sections 251 and 252 of the Act. Section 51.323 sets the standards for physical and virtual collocation, requiring an incumbent LEC to provide collocation to requesting carriers and to permit the collocation of equipment necessary for interconnection or access to unbundled network elements. Section 51.221 provides that the rules governing reciprocal compensation are set out in subpart H of Part 51, establishing the framework under which carriers compensate each other for the transport and termination of traffic. Part 51 is the operative federal rule that turns the statutory open-network duties of the 1996 Act into enforceable obligations for competitive local entry in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-communications-act-1934"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-47-cfr-part-52-numbering-portability",
    "title": "47 CFR Part 52 - Numbering: Thousands-Block Pooling, Porting Intervals, Local Number Portability and 988",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "47 CFR Part 52 governs the administration of telephone numbering resources and local number portability in the United States. Section 52.20 establishes thousands-block number pooling, the process by which the 10,000 numbers in a central office code (NXX) are separated into ten sequential blocks of 1,000 numbers each and allocated separately within a rate center, and requires all carriers, except those exempted by the Commission, to participate where pooling is implemented. Section 52.35 sets the porting intervals: a telecommunications carrier required to port numbers must complete a simple wireline-to-wireline or simple intermodal port request within one business day, and a non-simple port request within four business days, unless a longer period is requested by the new provider or the customer. Section 52.34 sets the obligations regarding local number porting to and from interconnected VoIP, video relay service and IP Relay providers, requiring such providers to facilitate a valid number portability request to or from a telecommunications carrier or another interconnected provider. Section 52.200 designates 988 as the three-digit dialing code for the national suicide prevention and mental health crisis hotline system and requires all covered providers to transmit calls dialed to 988 to that hotline system. Part 52 is the operative federal rule that allocates scarce numbering resources efficiently and guarantees consumers the ability to keep their telephone numbers when changing providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-communications-act-1934"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-47-cfr-part-64-fcc-robocall-stir-shaken-traced-act",
    "title": "US 47 CFR Part 64 Subpart HH: Caller ID Authentication STIR/SHAKEN (TRACED Act)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 47 CFR Part 64 Subpart HH implements the Pallone-Thune TRACED Act of 2019 by requiring voice service providers to deploy the STIR/SHAKEN call authentication framework on IP networks. Voice service providers must register in the Robocall Mitigation Database (RMD), implement STIR/SHAKEN on the IP portion of their network, and use a robocall mitigation program where STIR/SHAKEN is not implemented on legacy parts. Originating providers attest to caller ID using levels A B or C; intermediate providers must pass signed calls; terminating providers must verify signatures. Providers must block calls from providers not in the RMD and may block illegal calls per Call Blocking Order. Mandatory disclosure of caller name (RND) via SHAKEN extension is also required for higher attestation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "traced_act",
        "tcpa",
        "cfr_47_64_1200",
        "iboc_atis",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-47-cfr-part-73-fcc-radio-broadcast-services",
    "title": "US 47 CFR Part 73: Radio Broadcast Services",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 47 CFR Part 73 governs licensing operation and technical standards for AM FM and TV broadcast stations licensed by the FCC. Subparts cover AM (Subpart A) FM (Subpart B) noncommercial educational FM (Subpart C) digital audio broadcasting (Subpart D) and television (Subparts E F G H). Broadcasters must comply with content regulations including political broadcasting requirements (equal opportunities Section 315 reasonable access Section 312(a)(7) sponsorship identification Section 317), children's programming (Children's Television Act), main studio location, emergency alert system (EAS), public file requirements, and ownership rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "comm_act_1934",
        "cfr_47_11",
        "cfr_47_64",
        "childrens_tv_act",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-47-cfr-part-76-fcc-cable-television-multichannel-video",
    "title": "US 47 CFR Part 76: Multichannel Video and Cable Television Service",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 47 CFR Part 76 governs cable television and multichannel video programming distributors (MVPDs) under FCC jurisdiction. Subparts cover cable system registration (Subpart A) signal carriage (must-carry retransmission consent Subpart D) cable rate regulation (Subpart C, mostly preempted by Telecommunications Act 1996), cable consumer protection (Subpart H) horizontal and vertical ownership limits (Subpart J), program access rules (Subpart O), and rules for direct broadcast satellite providers (DBS) and competitive providers. Cable operators must comply with the Cable Television Consumer Protection and Competition Act of 1992 obligations including childrens TV commercial limits and EAS message carriage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cable_act_1992",
        "cfr_47_73",
        "cfr_47_11",
        "cfr_47_79",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-47-cfr-part-9-fcc-911-emergency-service-requirements",
    "title": "47 CFR Part 9 - FCC 911, E911, and Next Generation 911 Service Requirements",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2025-06-01",
    "bluf": "Telecommunications carriers, Commercial Mobile Radio Service (CMRS) providers, interconnected and one-way VoIP providers, Telecommunications Relay Service (TRS) providers, and covered text providers must comply with the 911, E911, and Next Generation 911 service requirements in 47 CFR Part 9 - including the § 9.4 obligation to transmit all 911 calls to a PSAP, designated statewide default answering point, or appropriate local emergency authority; the § 9.10 CMRS Phase I and Phase II location accuracy obligations (100m/67% network-based, 50m/67% handset-based, 50m horizontal indoor location and plus or minus three meters Z-axis where technically feasible by January 6, 2022); the § 9.10(q) text-to-911 bounce-back, routing, and Automated Dispatchable Location obligations; the § 9.10(s) location-based routing deployment milestones; the § 9.11 interconnected VoIP E911 obligations; and the § 9.8 fixed-telephony dispatchable location obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-47-usc-227-tcpa-telephone-consumer-protection-act",
      "us-fcc-47-cfr-part-25-satellite-communications"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-47-usc-222-cpni-customer-network-information",
    "title": "47 USC § 222 - Privacy of Customer Information (CPNI - Customer Proprietary Network Information)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "47 USC § 222 (Telecommunications Act of 1996, Pub. L. 104-104; amended by Wireless Communications and Public Safety Act of 1999 Pub. L. 106-81 and CALEA-related amendments) imposes privacy obligations on telecommunications carriers regarding Customer Proprietary Network Information (CPNI): subsection (a) provides the foundational duty - 'Every telecommunications carrier has a duty to protect the confidentiality of proprietary information of, and relating to, other telecommunication carriers, equipment manufacturers, and customers'; subsection (b) restricts carrier-to-carrier confidentiality; subsection (c) sets the CPNI use framework - carrier may use, disclose, or permit access to CPNI only (1) in its provision of (A) the telecommunications service from which the information is derived or (B) services necessary to or used in the provision of such service, or (2) with affirmative written consent of the customer; subsection (d) provides three express exceptions including (1) to provide services initiated by the customer, (2) to protect rights/property of the carrier or other carriers, (3) emergency services dispatch; subsection (f) provides emergency exception for call location information and automatic crash notification data; implementing regulations at 47 CFR Part 64 Subpart U with specific opt-in/opt-out frameworks; FCC enforcement actions for CPNI violations typically through Notices of Apparent Liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fcc_cpni_implementing_regulations",
        "cpni_definition_section_222_h",
        "industry_mapping",
        "enforcement_anchors",
        "annual_cpni_certification_requirement",
        "data_breach_notification_section_222_a_overlap"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-47-usc-230-cda-section-230-platform-immunity",
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355",
      "us-41-usc-3301-full-open-competition-federal-procurement"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-47-usc-227-tcpa-telephone-consumer-protection-act",
    "title": "47 USC § 227 - Telephone Consumer Protection Act of 1991 (TCPA)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "47 USC § 227 (Telephone Consumer Protection Act of 1991, Pub. L. 102-243, 105 Stat. 2394, signed 20 December 1991, codified as amendment to the Communications Act of 1934) is the foundational US federal anti-telemarketing statute and remains the principal anchor of telemarketing class action litigation with statutory damages of $500-$1,500 per violation that have produced billions in settlements and individual judgments: subsection (b) Restrictions on Automatic Telephone Dialing Systems (ATDS) and prerecorded voice calls prohibits (b)(1)(A) automated calls to emergency lines, hospital patient rooms, paging services, or any service for which the called party is charged for the call; (b)(1)(B) prerecorded voice calls to residential lines except with prior express consent or for emergencies; (b)(1)(C) unsolicited fax advertisements except where established business relationship exists and opt-out notice is included; (b)(1)(D) operating any automatic dialing system to call multiple lines of a multi-line business at the same time; subsection (c) Telephone Solicitation Restrictions mandates the FCC establish procedures protecting residential subscribers including the National Do Not Call Registry under (c)(3)(A) - 75+ million registered numbers as of 2024 with telemarketers prohibited from calling registered numbers; subsection (d) requires technical and procedural standards for prerecorded voice calls; subsection (g) state enforcement and private rights of action provides 'recover for actual monetary loss... or to receive $500 in damages for each violation, whichever is greater' with treble damages up to $1,500 per violation for willful and knowing violations; subsection (i) provides recovery of attorney's fees; the TCPA was amended by the TRACED Act 2019 (Pub. L. 116-105) to enhance robocall enforcement and require STIR/SHAKEN caller ID authentication framework codified at 47 USC §§ 227b-227e.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fcc_implementing_rules_47_cfr_64_1200",
        "facebook_v_duguid_atds_doctrine",
        "traced_act_2019_pallone_thune",
        "tcpa_class_action_settlements_landmark",
        "industry_mapping",
        "enforcement_anchors",
        "constitutional_anchoring",
        "international_intersection"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-47-cfr-part-64-fcc-robocall-stir-shaken-traced-act",
      "us-ftc-act-15-usc-ch2-subch-i"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-47-usc-230-cda-section-230-platform-immunity",
    "title": "47 USC § 230 - Communications Decency Act Section 230 (Platform Immunity)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "47 USC § 230 (Section 230 of the Communications Decency Act of 1996, Pub. L. 104-104 Title V) provides federal statutory immunity to providers and users of interactive computer services from liability arising from third-party content: subsection (c)(1) provides 'No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider' - the foundational publisher-or-speaker immunity that protects platforms from defamation, harassment, and other civil liability claims based on user-generated content; subsection (c)(2) provides good-faith filtering protection for actions to restrict access to material the provider considers obscene, lewd, lascivious, filthy, excessively violent, harassing, or otherwise objectionable; subsection (e)(1) preserves federal criminal law enforcement including 18 USC § 1466A obscene visual representations, § 2252/2252A child sexual exploitation material, and other Chapter 110 offences; subsection (e)(5) added by FOSTA-SESTA in 2018 explicitly excludes claims under 18 USC § 1595 sex trafficking remedies and 18 USC § 1591 sex trafficking offenses from Section 230 immunity; the section is the legal foundation enabling the modern internet platform economy and has been the subject of continuing debate about scope and reform proposals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fosta_sesta_2018_carve_out",
        "first_amendment_overlay",
        "industry_mapping",
        "enforcement_anchors",
        "interactive_computer_service_definition_section_230_f_2",
        "information_content_provider_definition_section_230_f_3"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2421a-fosta-promoting-prostitution-online",
      "us-18-usc-1466a-obscene-visual-representations-csam",
      "us-take-it-down-act-2025"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-47-usc-230-e-5-fosta-sex-trafficking-carve-out",
    "title": "US 47 U.S.C. 230(e)(5) - FOSTA Sex Trafficking Carve-Out to § 230 Immunity",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "§ 230(e)(5) of the Communications Decency Act, added by the Allow States and Victims to Fight Online Sex Trafficking Act of 2018 (Public Law 115-164, 'FOSTA'), carves out three categories of claims from § 230's broad interactive computer service immunity: (A) civil claims under 18 U.S.C. 1595 (Trafficking Victims Protection Reauthorization Act civil remedy) where underlying conduct violates 18 U.S.C. 1591 (sex trafficking by force, fraud, or coercion); (B) state criminal charges where underlying conduct would violate 18 U.S.C. 1591; and (C) state criminal charges where underlying conduct would violate 18 U.S.C. 2421A (promoting or facilitating prostitution). Subsection (c)(2)(A) good-faith content moderation immunity is preserved. Effective 11 April 2018 and applicable regardless of when the underlying conduct occurred.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "carve_out_text_section_230_e_5",
        "subsection_a_civil_1595_with_underlying_1591_violation",
        "subsection_b_state_criminal_1591_equivalent",
        "subsection_c_state_criminal_2421a_equivalent",
        "preservation_of_c_2_a_good_faith_moderation_immunity",
        "effective_date_retroactivity",
        "interaction_with_section_1591_sex_trafficking_federal_offence",
        "interaction_with_section_2421a_fosta_offence",
        "first_amendment_challenges_woodhull_freedom_foundation_v_us"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-1591-sex-trafficking-by-force-fraud-coercion",
      "us-18-usc-2421a-fosta-promoting-prostitution-online"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-47-usc-254-h-cipa-internet-safety-policy",
    "title": "US 47 U.S.C. § 254(h) - Children's Internet Protection Act (CIPA) Internet Safety Policy Requirements",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "47 U.S.C. § 254(h)(5)-(6) and 47 U.S.C. § 254(l) embody the Children's Internet Protection Act 2000 (CIPA, Public Law 106-554), which conditions federal universal service support and Library Services and Technology Act funding for schools and libraries on the deployment of an Internet safety policy that includes (1) a technology protection measure (filter/blocking software) that protects against access by minors to visual depictions that are obscene, child pornography, or harmful to minors; AND (2) an Internet safety policy addressing access to inappropriate matter, the safety and security of minors using electronic communication, unauthorised access, and unauthorised disclosure of personal information. Compliance is required to receive federal E-Rate (Schools and Libraries Program) discounts. The technology protection measure may be disabled during adult use for bona fide research or other lawful purposes per Section 254(h)(5)(D).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "schools_certification_subsection_h_5_b",
        "libraries_certification_subsection_h_6_b",
        "technology_protection_measure_definition_subsection_h_7_i",
        "internet_safety_policy_requirements_subsection_l_1_a",
        "internet_safety_policy_must_be_adopted_subsection_l_2",
        "disable_for_lawful_use_subsection_h_5_d_h_6_d",
        "harmful_to_minors_definition_subsection_h_7_g",
        "supreme_court_us_v_american_library_association_constitutionality",
        "interaction_with_section_2256_csam_definition",
        "fcc_implementation_47_cfr_54_500_54_523"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2256-definitions-csam-chapter-110",
      "us-18-usc-2252a-child-pornography-material"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-49-cfr-565-vehicle-identification-number-requirements",
    "title": "49 CFR Part 565 VIN Requirements",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "49 CFR Part 565 sets the content and format of the Vehicle Identification Number (VIN). Per Section 565.13(b) each VIN must consist of seventeen (17) characters, and per Section 565.13(c) a check digit must appear in position nine (9) of the VIN. Per Section 565.15(a) the first three characters (positions 1 through 3) identify the manufacturer and type of the motor vehicle. The Subpart B requirements apply to vehicles manufactured on or after April 30, 2009 that are not identified by their manufacturer as model year 2009 or earlier.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nhtsa-fmvss-federal-motor-vehicle-safety-standards-49-cfr-571"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-49-cfr-579-early-warning-reporting",
    "title": "49 CFR Part 579 Early Warning Reporting (TREAD Act)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "49 CFR Part 579 implements the Early Warning Reporting (EWR) requirements of the TREAD Act, requiring manufacturers to report potential safety defect information to NHTSA. Per Section 579.21 a manufacturer of 5,000 or more light vehicles (in the reporting period year or either of the prior two calendar years) must submit EWR data. Per Section 579.22 the thresholds are 100 or more buses, 500 or more emergency vehicles, and 5,000 or more medium-heavy vehicles. Reporting categories include claims, deaths, injuries, warranty, field reports, and production, submitted on a quarterly basis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nhtsa-fmvss-federal-motor-vehicle-safety-standards-49-cfr-571",
      "nhtsa-recall-process-cfr-573-577"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-49-cfr-part-172-hazmat-table-communications",
    "title": "US 49 CFR Part 172: Hazardous Materials Table, Special Provisions, Communications, Emergency Response Information, Training Requirements, and Security Plans",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 49 CFR Part 172 sets out the Hazardous Materials Table (49 CFR 172.101) which lists hazardous materials by proper shipping name, hazard class, identification number, packing group, label and placard requirements, special provisions, packaging authorization, and quantity limits. Part 172 also contains shipping paper requirements, marking and labeling, placarding of bulk packagings and motor vehicles, emergency response information including the ERG referenced phone number, training requirements for hazmat employees (initial within 90 days, recurrent every 3 years), and security plans for certain materials.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_49_173",
        "cfr_49_174_177",
        "cfr_49_180",
        "icao_iata_dgr",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-49-cfr-part-173-shippers-general-requirements",
    "title": "US 49 CFR Part 173: Shippers - General Requirements for Shipments and Packagings",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 49 CFR Part 173 sets out the requirements for offerors of hazardous materials for transportation including general packaging requirements, hazard class definitions, packaging authorization by hazard class, marking of packagings, exceptions for small quantities and limited quantities, and special requirements for materials such as lithium batteries and infectious substances. Shippers must select a packaging authorized by 49 CFR 173 column 8 of the Hazardous Materials Table and ensure the packaging is tested and marked per Part 178. Compliance prevents leaks, releases, and accidents during transport.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_49_172",
        "cfr_49_178",
        "icao_iata_dgr",
        "imdg_code",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-49-usc-30111-fmvss-motor-vehicle-safety-standards",
    "title": "49 USC § 30111 - Federal Motor Vehicle Safety Standards (FMVSS) Authority",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "49 USC § 30111 (originally enacted as the National Traffic and Motor Vehicle Safety Act of 1966, Pub. L. 89-563; recodified by Pub. L. 103-272) grants the Secretary of Transportation authority to prescribe Federal Motor Vehicle Safety Standards (FMVSS) for motor vehicles and motor vehicle equipment: subsection (a) directs the Secretary to prescribe motor vehicle safety standards that 'shall be practicable, meet the need for motor vehicle safety, and be stated in objective terms'; subsection (b) sets out four mandatory considerations - (1) relevant available motor vehicle safety information, (2) consultation with the National Highway Traffic Safety Administration (NHTSA) and other appropriate state or interstate authorities, (3) reasonable, practicable, and appropriate for the particular type of motor vehicle, (4) carrying out section 30101 (safety policy purposes); subsection (c) authorizes the Secretary to advise, assist, and cooperate with federal departments, agencies, instrumentalities, states, and other public and private agencies in developing motor vehicle safety standards; the implementing regulations are codified at 49 CFR Part 571 (Federal Motor Vehicle Safety Standards) covering crashworthiness, crash avoidance, post-crash survival, child restraints, and emerging autonomous vehicle technologies; FMVSS are the foundational US vehicle safety framework with parallel obligations on manufacturers under 49 USC §§ 30112 (prohibitions), 30115 (certification), 30117 (information), 30118-30120 (recalls and remedies).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "chapter_301_related_provisions",
        "implementing_regulations_49_cfr_part_571",
        "nhtsa_administrative_framework",
        "industry_mapping",
        "enforcement_anchors",
        "section_30120_recall_remedy_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-49-usc-30120-vehicle-recall-remedies",
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-49-usc-30120-vehicle-recall-remedies",
    "title": "49 USC § 30120 - Vehicle Recall Remedies (Defect and Noncompliance Remedies)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "49 USC § 30120 (originally enacted as part of National Traffic and Motor Vehicle Safety Act 1966, recodified by Pub. L. 103-272 and amended numerous times including TREAD Act 2000 Pub. L. 106-414) establishes the framework for remedies that manufacturers must provide to owners when a motor vehicle or item of motor vehicle equipment is recalled for a safety defect or noncompliance with an applicable Federal Motor Vehicle Safety Standard: subsection (a)(1) requires manufacturers to remedy defective vehicles or equipment without charge through one of three methods - (i) repairing the vehicle or equipment so it no longer contains the defect or noncompliance, (ii) replacing the vehicle with an identical or reasonably equivalent vehicle, or (iii) refunding the purchase price (less a reasonable allowance for depreciation); subsection (b) provides that for tires, manufacturers must address defective tires if owners present them within 180 days after the later of (A) the day owner received notification or (B) if the manufacturer decides to replace the tire, the day the owner received notification that a replacement is available; subsection (c) establishes the no-charge requirement; the recall remedy framework operates alongside § 30118 (defect notification), § 30119 (manufacturer notification to owners), § 30121 (hearings), and § 30166 (information disclosure); implementing regulations at 49 CFR Parts 573 (Defect and Noncompliance Reporting) and 577 (Defect and Noncompliance Notification).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "chapter_301_recall_related_provisions",
        "implementing_regulations",
        "tread_act_2000_origin",
        "industry_mapping",
        "enforcement_anchors",
        "section_30166_n_consumer_complaint_database"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-49-usc-30111-fmvss-motor-vehicle-safety-standards",
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-50-cfr-part-17-endangered-threatened-wildlife-plants",
    "title": "US 50 CFR Part 17: Endangered and Threatened Wildlife and Plants",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 50 CFR Part 17 implements the Endangered Species Act (ESA) of 1973 by listing endangered and threatened wildlife and plant species, designating critical habitat, prohibiting take of listed species (Section 9), permitting incidental take through habitat conservation plans (Section 10) or section 7 consultations with federal action agencies, and providing for recovery plans and 5-year status reviews. Subparts cover list of endangered and threatened species (Subpart B), prohibitions and exemptions (Subpart C), endangered species permits (Subpart D), threatened species rules (4(d) rules - Subpart E), and similarity of appearance species (Subpart F). Penalties for unlawful take include civil up to $50,000 per violation and criminal up to $50,000 and 1 year imprisonment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "esa",
        "cfr_50_222",
        "cites",
        "mbta",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-50-cfr-part-600-magnuson-stevens-fishery-management",
    "title": "US 50 CFR Part 600: Magnuson-Stevens Act Provisions",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 50 CFR Part 600 implements the Magnuson-Stevens Fishery Conservation and Management Act (MSA) of 1976 (as amended 2006) by establishing the framework for federal management of fisheries in the US Exclusive Economic Zone (3-200 nautical miles offshore). Eight Regional Fishery Management Councils develop fishery management plans (FMPs) with annual catch limits to prevent overfishing, rebuild overfished stocks, and provide essential fish habitat protections. NOAA NMFS approves and implements FMPs. Part 600 addresses general provisions, council operations, scientific and statistical committees, annual catch limits, accountability measures, observer programs, and essential fish habitat consultation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "msa",
        "nepa",
        "esa",
        "mmpa",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-6-cfr-part-27-chemical-facility-anti-terrorism-standards",
    "title": "US 6 CFR Part 27: Chemical Facility Anti-Terrorism Standards (CFATS)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 6 CFR Part 27 implements the Chemical Facility Anti-Terrorism Standards (CFATS) program administered by DHS Cybersecurity and Infrastructure Security Agency (CISA). CFATS requires high-risk chemical facilities to identify themselves to DHS via Top-Screen submission, undergo security vulnerability assessments (SVAs), develop site security plans (SSPs) addressing 18 Risk-Based Performance Standards (RBPS), and submit them for DHS approval. NOTE: The CFATS statutory authority lapsed on July 28, 2023 and as of the May 2026 update has not been reauthorized; facilities should monitor congressional reauthorization status and continue voluntary security practices. The regulatory framework in 6 CFR 27 remains technically on the books pending statutory action.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ctsa_2007",
        "cfr_49_172_800",
        "msc_act_2002",
        "cfr_27_22",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-7-cfr-part-205-national-organic-program",
    "title": "US 7 CFR Part 205: National Organic Program",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 7 CFR Part 205 implements the Organic Foods Production Act of 1990 (OFPA) establishing national standards for organically produced agricultural products in the United States. Subparts cover applicability, organic production and handling requirements, the National List of Allowed and Prohibited Substances, labeling and market information, certification by USDA-accredited certifying agents, accreditation of certifying agents, recordkeeping, compliance and enforcement. Producers and handlers must obtain certification before selling product as organic; the Strengthening Organic Enforcement (SOE) final rule effective March 19 2024 requires almost all participants in the organic supply chain to be certified including importers and brokers handling uncertified organic products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ofpa",
        "fsma",
        "soe_rule",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-7-cfr-part-273-snap-certification-eligible-households",
    "title": "US 7 CFR Part 273: Certification of Eligible Households (SNAP)",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 7 CFR Part 273 implements the Supplemental Nutrition Assistance Program (SNAP, formerly Food Stamps) by setting eligibility standards, certification procedures, and benefit issuance. Subparts cover household concept, eligibility criteria (income resource categorical citizenship work registration), application processing, certification periods, benefit allotments via EBT cards, recertification, fair hearings, and quality control. Federal poverty level (FPL) and net income tests apply: gross income at or below 130% FPL and net income at or below 100% FPL (general non-elderly). Benefit amount calculated per Thrifty Food Plan formula. State agencies administer SNAP under USDA Food and Nutrition Service (FNS) oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "food_stamp_act",
        "cfr_7_274",
        "cfr_7_271",
        "cfr_7_275",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-7-usc-2131-animal-welfare-act",
    "title": "7 USC § 2131 - Animal Welfare Act (Congressional Statement of Policy)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "7 USC § 2131 (Animal Welfare Act of 1966, originally enacted as Pub. L. 89-544 / Laboratory Animal Welfare Act, amended substantially by Pub. L. 91-579 (1970), Pub. L. 94-279 (1976), Pub. L. 99-198 (1985 Food Security Act), Pub. L. 101-624 (1990 - pet protection), Pub. L. 107-171 (2002 - Class B dealers and downed cattle)) provides the Congressional findings and declaration of policy underpinning the federal Animal Welfare Act framework: the Congress finds and declares that 'animals and activities which are regulated under this chapter are either in interstate or foreign commerce or substantially affect such commerce or the free flow thereof' (the Commerce Clause foundation), and establishes three primary policy purposes - (1) to insure that animals intended for use in research facilities or for exhibition purposes or for use as pets are provided humane care and treatment, (2) to assure the humane treatment of animals during transportation in commerce, and (3) to protect the owners of animals from theft of their animals by preventing the sale or use of stolen animals; the AWA is administered by USDA's Animal and Plant Health Inspection Service (APHIS) Animal Care program with implementing regulations at 9 CFR Parts 1-4 covering registration, licensing, standards, and enforcement; the AWA applies to research facilities, exhibitors (zoos, circuses, marine mammal exhibitors), dealers, and carriers but explicitly does not cover livestock or production agriculture (regulated separately under USDA's other programs).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "awa_provisions_chapter_54",
        "implementing_regulations_9_cfr_parts_1_4",
        "research_facility_iacuc_requirement",
        "industry_mapping",
        "enforcement_anchors",
        "carve_outs_from_awa_definition_2132_g"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-21-cfr-part-11-electronic-records-electronic-signatures",
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-7-usc-6b-commodity-exchange-act-fraud",
    "title": "7 U.S.C. 6b - Contracts Designed to Defraud or Mislead (Commodity Exchange Act)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-20",
    "bluf": "7 U.S.C. 6b is the core anti-fraud provision of the Commodity Exchange Act. It is unlawful, in or in connection with any order to make, or the making of, any contract of sale of any commodity for future delivery, any swap, or any contract subject to the Act, to cheat or defraud or attempt to cheat or defraud the other person (subsection (a)(2)(A)); willfully to make or cause to be made any false report or statement, or willfully to enter or cause to be entered any false record, for the other person (subsection (a)(2)(B)); or willfully to deceive or attempt to deceive the other person by any means in regard to any order or contract or its disposition or execution (subsection (a)(2)(C)). The prohibitions apply both to on-exchange transactions made for or on behalf of another person and to off-exchange futures and swaps.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-commodity-exchange-act-cftc-crypto-derivatives-regulation",
      "us-cftc-17-cfr-38-designated-contract-markets",
      "us-18-usc-1348-securities-commodities-fraud"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-8-cfr-part-214-nonimmigrant-classes",
    "title": "US 8 CFR Part 214: Nonimmigrant Classes",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 8 CFR Part 214 establishes the requirements for the various nonimmigrant classifications (visa categories) under the Immigration and Nationality Act (INA), including B-1/B-2 visitor for business or pleasure (214.2(b)); H-1B specialty occupation (214.2(h)); H-2A agricultural workers; H-2B temporary non-agricultural workers; L-1 intracompany transferees (214.2(l)); E-1/E-2 treaty traders/investors; F-1 students; J-1 exchange visitors (administered by State Department); O-1 extraordinary ability (214.2(o)); P performers and athletes; R-1 religious workers; and TN under USMCA. Employers must comply with petition requirements documentation labor condition application (LCA for H-1B) public access files and adverse action protections for workers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ina",
        "cfr_20_655",
        "cfr_22_41",
        "cfr_8_204",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-9-cfr-part-313-humane-slaughter-livestock",
    "title": "US 9 CFR Part 313: Humane Slaughter of Livestock",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "US 9 CFR Part 313 implements the Humane Methods of Slaughter Act (HMSA) of 1958 (as amended 1978) requiring that livestock at federally inspected slaughter establishments be rendered insensible to pain by approved methods before being shackled hoisted thrown cast or cut. Approved methods include captive bolt stunning, electrical stunning, chemical (CO2) stunning, and ritual slaughter conducted in compliance with religious requirements. FSIS Public Health Veterinarians (PHVs) and Consumer Safety Inspectors conduct ongoing inspection of stunning effectiveness, animal handling, and pen design. Egregious humane handling violations trigger Notice of Suspension or other regulatory action including monetary penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "hmsa",
        "cfr_9_416",
        "cfr_9_310",
        "awa",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-aca-insurance-market-reforms-2010",
    "title": "Patient Protection and Affordable Care Act; Health Insurance Market Rules; Rate Review (45 CFR Parts 144, 147, 153, 154, 156, and 158)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation requires health insurance issuers in the individual and small group markets to provide guaranteed availability of coverage to all applicants (45 CFR §147.104), use modified community rating to set premiums based only on age, tobacco use, family size, and geography (45 CFR §147.102), and cover a comprehensive package of Essential Health Benefits (EHB) (45 CFR Part 156).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-aca-ppaca-2010-pl-111-148",
    "title": "United States Patient Protection and Affordable Care Act (ACA / PPACA) (Public Law 111-148, 2010): Title I Quality Affordable Health Care, Health Insurance Market Reforms, Dependent Coverage to Age 26, Prohibition of Preexisting Condition Exclusions, Title II Medicaid Expansion, Title V Workforce, Title VI Transparency, Section 1501 Individual Responsibility, and Section 1513 Employer Shared Responsibility",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Patient Protection and Affordable Care Act, Public Law 111-148 of 23 March 2010, commonly known as the Affordable Care Act or PPACA, and as supplemented by the Health Care and Education Reconciliation Act of 2010 (Public Law 111-152), is the principal federal statute reforming the United States health insurance market and expanding health insurance coverage, administered by the Department of Health and Human Services through the Centers for Medicare Medicaid Services and the Center for Consumer Information Insurance Oversight, the Department of the Treasury Internal Revenue Service, and the Department of Labor Employee Benefits Security Administration. ACA, Title I (Quality, Affordable Health Care for All Americans) contains the immediate health insurance market reforms including prohibitions on lifetime and annual limits, prohibition of rescissions, required preventive service coverage without cost-sharing, extension of dependent coverage to age 26, the establishment of Health Insurance Marketplaces, and the premium tax credit. ACA, Title II (Role of Public Programs) addresses Medicaid coverage expansion for lower-income populations and enhanced support for the Children's Health Insurance Program. ACA, Title V (Health Care Workforce) focuses on workforce development. ACA, Title VI (Transparency and Program Integrity) implements physician ownership disclosures (Sunshine Act), nursing home transparency requirements, and enhanced Medicare and Medicaid integrity provisions. ACA, section 1001 amends the Public Health Service Act including dependent coverage to age 26. ACA, section 1201 prohibits preexisting condition exclusions. ACA, section 1501 enacted the individual responsibility provision (individual mandate) requiring most individuals to maintain minimum essential coverage (with the penalty reduced to zero by Tax Cuts and Jobs Act 2017). ACA, section 1513 (codified at 26 U.S.C. 4980H) imposes the employer shared responsibility provision (employer mandate) requiring applicable large employers (50 or more full-time equivalent employees) to offer affordable minimum value coverage to full-time employees or pay a shared responsibility payment. The Act is the controlling federal instrument for United States health insurance market reform and expansion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-act-prevent-pollution-ships-33-cfr-151",
    "title": "Vessels Carrying Oil, Noxious Liquid Substances, Garbage, Municipal or Commercial Waste, and Ballast Water",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation implements MARPOL 73/78 and related environmental protocols in U.S. waters, requiring vessels to maintain oil record books, garbage management plans, and ballast water management systems. It applies to all U.S.-flagged vessels and foreign vessels operating in U.S. navigable waters under § 151.03.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14090-climate-adapt",
      "gstc-tourism-criteria",
      "iso-15489-1-2016-records-management-workflow",
      "nist-ir-8374-ransomware-risk-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ada-42-usc-12182-title-iii-public-accommodations-disability",
    "title": "42 U.S. Code § 12182 - Prohibition of discrimination by public accommodations",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations operating public accommodations must not discriminate on the basis of disability and must provide equal enjoyment of goods, services, and facilities, including making reasonable modifications and providing services in integrated settings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ada-accessibility-guidelines-2010-aba",
    "title": "US ADA Standards for Accessible Design 2010 - Architectural and Transportation Barriers Compliance Board (ABA): Space Allowances, Accessible Routes and Facilities",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The US ADA Standards for Accessible Design 2010 require that all new construction and alterations of buildings and facilities comply with specific accessibility standards, as outlined in Section 504 of the Rehabilitation Act of 1973 and Title II and III of the Americans with Disabilities Act, specifically 28 CFR Part 36, Appendix A.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ada-section-504-disability-education",
    "title": "Section 504 of the Rehabilitation Act of 1973 - Disability Accommodations, Accessible Course Materials and Non-Discrimination in Educational Programmes",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Section 504 of the Rehabilitation Act of 1973 prohibits discrimination against individuals with disabilities in any program or activity receiving Federal financial assistance. This requires educational institutions to provide reasonable accommodations, ensure program accessibility, and make academic materials accessible to students with disabilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ada-standards-accessible-design-2010",
    "title": "US ADA Standards for Accessible Design 2010 - Accessible Routes, Parking, Ramps, Doors, Toilet Rooms, Hearing Loop, Signage and Technical Provisions for Construction Accessibility",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The 2010 ADA Standards for Accessible Design establish technical and scoping requirements for accessible buildings and facilities, including newly constructed and altered structures, to ensure access for individuals with disabilities. These standards apply to state and local governments under Title II and private businesses under Title III of the ADA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ada-accessibility-guidelines-2010-aba",
      "iso-19650-bim-information-management-construction"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ada-title-iii-public-accommodations-buildings",
    "title": "Americans with Disabilities Act (ADA) Title III: Public Accommodations and Commercial Facilities",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Title III of the Americans with Disabilities Act (ADA) prohibits discrimination on the basis of disability in places of public accommodation and commercial facilities, requiring new construction and alterations to be accessible and mandating the removal of architectural barriers in existing facilities where such removal is readily achievable (42 U.S.C. § 12182).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ada-title-iii-public-accommodations-digital",
    "title": "Web Accessibility Rule: Accessibility of Web Content and Mobile Applications (WCAG 2.1 Level AA) for State and Local Government Websites under Title II of the Americans with Disabilities Act",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This rule requires state and local government entities to ensure that their websites and mobile applications conform to WCAG 2.1 Level AA success criteria, including specific provisions on non-text content, keyboard accessibility, and error identification. Applies to all public-facing digital content provided by public accommodations under Title II of the ADA, effective as of March 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-accessibility-act-2019",
      "sec-cybersecurity-risk-incident-disclosure",
      "nist-sp-1800-22-byod"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-adea-1967-29-usc-ch14",
    "title": "United States Age Discrimination in Employment Act of 1967 (ADEA), as Amended by the Older Workers Benefit Protection Act of 1990 (Title 29 USC Chapter 14): Findings and Purpose, Prohibition of Age Discrimination, Recordkeeping Investigation and Enforcement, Notices Posted, Age Limits, Federal-State Relationship, and Federal Government Employment Nondiscrimination",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Age Discrimination in Employment Act of 1967 (ADEA), Public Law 90-202 of 15 December 1967, codified at Title 29 of the United States Code, Chapter 14, as amended by the Older Workers Benefit Protection Act of 1990 (Public Law 101-433), is the principal federal statute prohibiting employment discrimination against persons 40 years of age or older, and is administered by the Equal Employment Opportunity Commission. ADEA, 29 U.S.C. 621 contains the Congressional statement of findings and purpose establishing legislative intent to promote employment of older persons based on their ability rather than age. ADEA, 29 U.S.C. 623 contains the core prohibition making it unlawful for an employer to fail or refuse to hire, to discharge, or otherwise to discriminate against any individual with respect to compensation, terms, conditions, or privileges of employment because of such individual's age; to limit, segregate, or classify employees in any way which would deprive or tend to deprive any individual of employment opportunities; or to reduce the wage rate of any employee in order to comply with this chapter. ADEA, 29 U.S.C. 626 governs recordkeeping, investigation, and enforcement including EEOC investigative powers, the requirement that no civil action may be commenced until 60 days after a charge alleging unlawful discrimination has been filed with the EEOC, and the waiver requirements under the Older Workers Benefit Protection Act including the requirement that waivers of ADEA rights be knowing and voluntary. ADEA, 29 U.S.C. 627 requires the posting of notices. ADEA, 29 U.S.C. 631 sets the age limits providing that the prohibitions apply to individuals who are at least 40 years of age. ADEA, 29 U.S.C. 633 governs the federal-state relationship. ADEA, 29 U.S.C. 633a extends nondiscrimination protection to Federal Government employment. The Act is the controlling federal instrument for age-based employment discrimination in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-administrative-dispute-resolution-act-5-usc-ch5-subch4",
    "title": "United States Administrative Dispute Resolution Act (Title 5 USC Chapter 5 Subchapter IV): Agency Authority to Use ADR, Neutrals, Confidentiality, Arbitration Authorization, Enforcement of Agreements, and Judicial Review",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Administrative Dispute Resolution Act, codified at Title 5 of the United States Code, Chapter 5, Subchapter IV (Alternative Means of Dispute Resolution in the Administrative Process), is the principal federal statute authorising federal agencies to use alternative dispute resolution procedures and is administered through the Administrative Conference of the United States. Administrative Dispute Resolution Act, 5 U.S.C. 571 contains the definitions used in the subchapter. Administrative Dispute Resolution Act, 5 U.S.C. 572 provides general authority: an agency may use a dispute resolution proceeding for the resolution of an issue in controversy that relates to an administrative program, if the parties agree to such proceeding. Administrative Dispute Resolution Act, 5 U.S.C. 573 governs neutrals: a neutral may be a permanent or temporary officer or employee of the Federal Government or any other individual who is acceptable to the parties to a dispute resolution proceeding. Administrative Dispute Resolution Act, 5 U.S.C. 574 establishes the confidentiality protections: except as provided in subsections (d) and (e), a neutral in a dispute resolution proceeding shall not voluntarily disclose or through discovery or compulsory process be required to disclose any dispute resolution communication. Administrative Dispute Resolution Act, 5 U.S.C. 575 authorises arbitration: arbitration may be used as an alternative means of dispute resolution whenever all parties consent. Administrative Dispute Resolution Act, 5 U.S.C. 576 provides that an agreement to arbitrate a matter to which the subchapter applies is enforceable pursuant to section 4 of title 9 (the Federal Arbitration Act). Administrative Dispute Resolution Act, 5 U.S.C. 577 governs arbitrators: the parties to an arbitration proceeding shall be entitled to participate in the selection of the arbitrator. Administrative Dispute Resolution Act, 5 U.S.C. 580 governs arbitration awards. Administrative Dispute Resolution Act, 5 U.S.C. 581 governs judicial review of arbitration awards. Administrative Dispute Resolution Act, 5 U.S.C. 583 governs support services. The Act is the controlling federal instrument for alternative dispute resolution in the administrative process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-administrative-procedure-act-5-usc-ch5",
    "title": "United States Administrative Procedure Act (Title 5 USC Chapter 5): Federal Agency Definitions, FOIA Disclosure, Rule Making, Adjudications, Hearings, and Initial Decisions",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Administrative Procedure Act, codified at Title 5 of the United States Code, Part I, Chapter 5, is the foundational federal statute governing the rulemaking, adjudication, and information disclosure procedures of federal administrative agencies. Administrative Procedure Act, 5 U.S.C. 551 contains the definitions, including the definition of an agency as each authority of the Government of the United States, whether or not it is within or subject to review by another agency. Administrative Procedure Act, 5 U.S.C. 552 sets out the Freedom of Information Act public information regime and requires each agency to separately state and currently publish in the Federal Register for the guidance of the public the descriptions of its central and field organization, the methods through which the public may obtain information or make submissions, and the rules of procedure. Administrative Procedure Act, 5 U.S.C. 552a contains the Privacy Act records-about-individuals regime. Administrative Procedure Act, 5 U.S.C. 552b contains the Government in the Sunshine Act open-meetings regime. Administrative Procedure Act, 5 U.S.C. 553 sets out the rule making procedure including notice in the Federal Register and the opportunity for public comment. Administrative Procedure Act, 5 U.S.C. 554 sets out the adjudication procedure. Administrative Procedure Act, 5 U.S.C. 555 contains ancillary matters including the right to appear and be represented. Administrative Procedure Act, 5 U.S.C. 556 governs hearings, presiding employees, powers and duties, burden of proof, evidence, and record as basis of decision. Administrative Procedure Act, 5 U.S.C. 557 governs initial decisions, conclusiveness, review by agency, submissions by parties, contents of decisions, and the record. Administrative Procedure Act, 5 U.S.C. 558 governs imposition of sanctions and determination of applications for licenses. Administrative Procedure Act, 5 U.S.C. 559 governs the effect on other laws and the effect of subsequent statutes. The Act is the controlling federal instrument for federal agency procedure and is the legal substrate for federal regulatory workflow automation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-adppa-american-data-privacy-protection-act",
    "title": "American Data Privacy and Protection Act (ADPPA)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The American Data Privacy and Protection Act (ADPPA) establishes a comprehensive national data privacy framework for the U.S., requiring covered entities to adhere to data minimization principles (Sec. 101), obtain affirmative express consent for processing sensitive data (Sec. 103), and conduct algorithmic impact assessments for systems posing a consequential risk of harm (Sec. 208), while largely preempting state-level privacy laws.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-35-dpia",
      "gdpr-article-5-data-principles",
      "nist-privacy-framework-1-0",
      "nist-ai-rmf-manage"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-advance-pricing-agreement-rev-proc-2015-41",
    "title": "Revenue Procedure 2015-41: Procedures for Advance Pricing Agreements",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This procedure outlines the process for taxpayers to request an Advance Pricing Agreement (APA) with the IRS to prospectively resolve transfer pricing issues, detailing the mandatory prefiling, application content, and annual reporting requirements. Section 4 of Rev. Proc. 2015-41 specifies the required contents of a complete APA submission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-model-double-taxation-convention-2021",
      "oecd-beps-action-3-cfc-rules-2015"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-aedpa-1996-habeas-corpus-28-usc-2244",
    "title": "Antiterrorism and Effective Death Penalty Act 1996 - 28 USC 2244 Habeas Corpus Restrictions",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 2244 of title 28 of the United States Code, as substantially amended by the Antiterrorism and Effective Death Penalty Act of 1996 (AEDPA, Public Law 104-132, enacted 24 April 1996), imposes strict procedural limitations on federal habeas corpus relief for state prisoners and federal prisoners. Subsection (b)(1) requires that a claim presented in a second or successive habeas application under section 2254 that was presented in a prior application be dismissed. Subsection (b)(2) creates limited exceptions for new claims based on a new rule of constitutional law made retroactively applicable by the Supreme Court or on newly discovered facts with clear-and-convincing evidence of actual innocence. Subsection (b)(3)(A) establishes the gatekeeper requirement that any second or successive petition must obtain authorisation from a three-judge panel of the court of appeals before filing in district court, with the panel deciding within 30 days. Section 2244(d) imposes a one-year statute of limitations on habeas applications, tolled during state collateral review. Section 2253(c) requires a certificate of appealability before appellate review. AEDPA also substantially expanded federal criminal terrorism authorities, restricted alien terrorist activities, expanded the use of administrative subpoenas in terrorism investigations, and limited certain federal court authority. The AEDPA framework is the constitutional architecture of US post-conviction review and significantly affects federal court workload, prisoner litigation, and AI-supported legal research.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-anti-deficiency-act-31-usc-1341"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-african-elephant-conservation-act",
    "title": "US African Elephant Conservation Act of 1988 (16 U.S.C. Chapter 62): Ivory Import Controls and Conservation Assistance",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The African Elephant Conservation Act of 1988, codified at 16 U.S.C. Chapter 62 (sections 4201 through 4246), provides for the conservation of the African elephant through controls on the importation and exportation of ivory and through financial assistance to range states, administered by the Secretary of the Interior through the United States Fish and Wildlife Service. Section 4201 sets the statement of purpose, and section 4202 sets the findings on the decline of the African elephant. Section 4211 authorizes the provision of assistance for conservation programs in African elephant range states, financed in part through the Multinational Species Conservation Fund. Section 4222 authorizes the establishment of moratoria on the importation of raw and worked ivory from producing and intermediary countries that do not meet the Act's standards. Section 4223 sets the prohibited acts, including importing raw ivory from a country other than an ivory producing country, exporting raw ivory from the United States, and importing ivory in violation of a moratorium. Section 4224 sets the penalties and enforcement, including criminal penalties and civil penalties of up to a specified amount for each violation, and applies the enforcement provisions of the Endangered Species Act. Section 4225 authorizes rewards, section 4244 provides the definitions, and section 4245 authorizes appropriations. The Act is the foundational United States statute for African elephant conservation and ivory trade control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-age-discrimination-in-employment-act",
    "title": "US Age Discrimination in Employment Act (29 USC ch 14): Protection of Workers Aged 40 and Over",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Age Discrimination in Employment Act of 1967 (ADEA, 29 U.S.C. ch. 14) prohibits employment discrimination against individuals who are at least 40 years of age, enforced by the Equal Employment Opportunity Commission (EEOC). Section 621 sets the congressional findings and purpose of promoting the employment of older persons based on ability rather than age. Section 623 sets the core prohibition: it is unlawful for an employer to fail or refuse to hire, to discharge, or otherwise to discriminate against an individual with respect to compensation, terms, conditions or privileges of employment because of age, and it likewise restricts employment agencies and labor organizations. Section 626 provides for recordkeeping, investigation and enforcement, incorporating the powers and procedures of the Fair Labor Standards Act and authorizing civil actions. Section 628 authorizes rules, regulations and reasonable exemptions. Section 629 provides criminal penalties for forcibly resisting or interfering with enforcement. Section 630 supplies the definitions, including employer (generally those with 20 or more employees). Section 631 sets the protected age limit at individuals who are at least 40 years of age, and section 633a applies the prohibition to most federal-government employment. The Act is the legal foundation of US protection against age discrimination in the workplace.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-agricultural-adjustment-act-1938",
    "title": "US Agricultural Adjustment Act of 1938 (7 USC ch 35): Marketing Quotas, Parity and Acreage Allotments",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agricultural Adjustment Act of 1938 (7 U.S.C. ch. 35, sections 1281 to 1407) is a foundational United States farm program statute administered by the Secretary of Agriculture, establishing marketing quotas, acreage allotments, parity payments, and penalties for basic agricultural commodities. Section 1282 declares the policy of the Act and section 1301 sets out definitions, including the parity concept used to measure a fair return to producers. Section 1303 authorizes parity payments designed to give producers a return as nearly equal to the parity price as available funds permit, and section 1304 provides consumer safeguards. The marketing quota machinery is organized by commodity: for wheat, section 1332 provides for a national marketing quota and section 1333 for a national acreage allotment; for cotton, section 1342 provides that the Secretary proclaims a national marketing quota when the total supply exceeds the normal supply, section 1344 apportions the national acreage allotment, and section 1345 fixes the farm marketing quota and defines the farm marketing excess. Section 1346 imposes penalties on the marketing of any commodity in excess of the farm marketing quota, and section 1308 limits the total amount of certain payments to a producer to 125,000 dollars for any crop year. The Act remains a core component of United States agricultural price and supply policy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-agricultural-bioterrorism-protection-act",
    "title": "US Agricultural Bioterrorism Protection Act of 2002 (7 USC ch 110): Select Agents Threatening Animal and Plant Health",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agricultural Bioterrorism Protection Act of 2002 (7 U.S.C. ch. 110, sections 8401 and 8411) regulates the possession, use, and transfer of biological agents and toxins that threaten animal or plant health or animal or plant products, administered by the Secretary of Agriculture through the Animal and Plant Health Inspection Service. Section 8401(a) requires the Secretary to establish and maintain a list of each biological agent and toxin that the Secretary determines has the potential to pose a severe threat to animal or plant health or to animal or plant products. Section 8401(b) directs the Secretary to issue regulations governing the possession, use, and transfer of listed agents and toxins, including registration of persons, safeguards, and security measures, and section 8401(c) addresses overlap agents and toxins listed under both this Act and the Public Health Service Act regime. Section 8401(e) restricts access to listed agents and toxins to individuals with a legitimate need to handle or use them and requires denial of access to restricted persons. Section 8401(g) requires prompt notification of any theft, loss, or release of a listed agent or toxin to the Secretary and to law enforcement. Section 8401(i) provides for civil money penalties not exceeding 250,000 dollars in the case of an individual and 500,000 dollars in the case of any other person, and section 8401(l) defines the terms, including listed agents and toxins and registered person. Section 8411 provides for interagency coordination. The Act is the federal agricultural select-agent biosecurity regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-agricultural-experiment-stations-hatch-act",
    "title": "US Agricultural Experiment Stations Act (Hatch Act of 1887, 7 USC ch 14): Federal Funding of State Agricultural Research",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agricultural Experiment Stations Act, originating in the Hatch Act of 1887 (7 U.S.C. ch. 14, sections 361a to 390d, distinct from the political-activity Hatch Act), provides federal support for agricultural research conducted at the State agricultural experiment stations associated with the land-grant colleges, administered by the Secretary of Agriculture. Section 361a sets out the congressional declaration of purpose and definitions, and section 361b states the policy of conducting original and other researches, investigations, and experiments bearing on the production, processing, distribution, and utilization of agricultural products. Section 361c authorizes appropriations and prescribes their allotment among the States, providing that 20 per centum is allotted equally to each State and that not less than 52 per centum is allotted to the States in proportions based on their rural and farm populations as determined by the most recent decennial census. Section 361d restricts the use of funds to research, the printing and dissemination of results, and the construction of facilities; section 361e governs the quarterly payment of allotments to the State agricultural experiment stations and reporting; section 361f authorizes free mailing of experiment station publications; and section 361g charges the Secretary with administration and with ascertaining each State's entitlement to funds. The Act is the legal foundation of the federal-State partnership for agricultural research.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-agricultural-fair-practices-act",
    "title": "US Agricultural Fair Practices Act of 1967 (7 USC ch 56): Producer Association Rights and Prohibited Handler Practices",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agricultural Fair Practices Act of 1967 (7 U.S.C. ch. 56, sections 2301 to 2306) protects the right of agricultural producers to join together in associations and prohibits handlers from coercing or discriminating against producers who exercise that right, administered by the Secretary of Agriculture and enforced through the courts. Section 2301 sets out the congressional findings and declaration of policy, declaring it to be the policy of Congress to establish standards of fair practices required of handlers in their dealings in agricultural products. Section 2302 defines the terms, providing that handler means a person engaged in acquiring agricultural products from producers, grading or processing products, or contracting with producers regarding production or marketing, and that association of producers means an association engaged in marketing, bargaining, shipping, or processing on behalf of producers. Section 2303 sets out the prohibited practices, providing that a handler may not coerce a producer regarding membership in an association, discriminate against a producer based on membership, coerce a producer to enter or change a contract, pay or offer an inducement to a producer to leave an association, make false reports about an association, or conspire to do any of these acts. Section 2304 disclaims any intention to prohibit normal dealing, and section 2305 sets out the enforcement provisions, under which an aggrieved party may sue for injunctive relief, the Attorney General may bring a civil action, and an injured person may recover damages within two years. The Act is the federal regime protecting producer bargaining associations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-agricultural-foreign-investment-disclosure-act",
    "title": "US Agricultural Foreign Investment Disclosure Act of 1978 (7 USC ch 66): Foreign Holdings of Agricultural Land",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agricultural Foreign Investment Disclosure Act of 1978 (AFIDA, 7 U.S.C. ch. 66, sections 3501 to 3508) requires foreign persons who acquire, transfer, or hold interests in United States agricultural land to disclose those interests to the Secretary of Agriculture, administered through the Farm Service Agency. Section 3501 sets the reporting requirements, providing that any foreign person who acquires or transfers any interest, other than a security interest, in agricultural land must submit a report to the Secretary containing the legal name and address of the foreign person, the nature of the interest, the legal description and acreage, the purchase price or other consideration, and the agricultural purposes for which the land is used. Section 3502 sets the civil penalty, providing that a foreign person who fails to submit a report or who submits a report containing a misstatement or omission is liable for a civil penalty not to exceed 25 percent of the fair market value, on the date of the assessment of the penalty, of the interest in the agricultural land. Section 3503 provides for investigative actions, section 3505 provides for reports to the States, section 3506 provides for public inspection of the reports, and section 3507 provides for regulations. Section 3508 sets the definitions, including agricultural land, foreign government, and foreign person, which includes individuals who are not citizens or lawful permanent residents and entities organized under foreign law or having a significant foreign interest. The Act is the federal disclosure regime for foreign holdings of agricultural land.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-agricultural-marketing-act-1946",
    "title": "US Agricultural Marketing Act of 1946 (7 USC ch 38): Voluntary Grading, Inspection and Market News Services",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agricultural Marketing Act of 1946 (7 U.S.C. ch. 38, sections 1621 onward) authorizes the federal voluntary grading, inspection, standardization, and market news services for agricultural products of the United States, administered by the Agricultural Marketing Service of the Department of Agriculture. Section 1621 declares the congressional policy that a sound, efficient, and privately operated marketing system is essential, authorizes the use of existing facilities, and provides for cooperation with the States. Section 1622 directs and authorizes the Secretary of Agriculture to conduct research into the production, marketing, distribution, and processing of agricultural products, to develop and improve standards of quality and grade, to provide for the voluntary inspection and certification of products, and to maintain a market news service furnishing information on supply, demand, prices, and movement. Section 1622b provides for a specialty crops market news allocation, with funding of 9,000,000 dollars for each of fiscal years 2008 through 2023. Section 1626 defines agricultural products and other terms, and section 1627 authorizes the appointment of personnel and the engagement of technical specialists. The Act is the legal basis of the United States voluntary commodity grading, certification, and market news system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-agricultural-marketing-agreement-act",
    "title": "US Agricultural Marketing Agreement Act / Marketing Orders (7 USC 608c): Handler Regulation and Milk Orders",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Agricultural Marketing Agreement Act of 1937, building on the marketing-order provisions of the Agricultural Adjustment Act codified in 7 U.S.C. Chapter 26 (with section 674 supplying the 1937 Act's short title), authorizes the Secretary of Agriculture to issue federal marketing orders and agreements regulating the handling of certain agricultural commodities, administered by the USDA Agricultural Marketing Service. Section 601 declares the conditions and section 602 the policy of the Act. Section 608c is the core provision: the Secretary is authorized to issue, and from time to time amend, orders applicable to processors, associations of producers, and others engaged in the handling of a covered agricultural commodity in the current of interstate or foreign commerce, or which directly burdens, obstructs or affects such commerce. Section 608c(2) lists the commodities to which orders may apply, including milk, fruits, vegetables, hops, honeybees and naval stores, with specified carve-outs. Section 608c(5) sets out the detailed terms applicable to milk and its products, including the classification of milk by use and the establishment of minimum prices by class, the uniform payment to producers (pooling), and adjustments for quality, location and components. Marketing orders are funded through assessments on handlers, and handlers within the production or marketing area are bound by the order whether or not they signed a marketing agreement. Section 608c(14) sets the penalties for handler violations of an order: any handler who violates an order shall, on conviction, be fined not less than $50 or more than $5,000 for each such violation, and the Secretary may, in addition, assess a civil penalty of not more than $1,000 for each such violation. Section 608a provides for enforcement of the chapter. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-agricultural-subterminal-facilities-act",
    "title": "US Agricultural Subterminal Facilities Act (7 USC ch 68): Planning Grants for Bulk Commodity Handling",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agricultural Subterminal Facilities Act (7 U.S.C. ch. 68, sections 3701 to 3703) supports the planning of agricultural subterminal facilities for the efficient bulk storage and movement of agricultural commodities, administered by the Secretary of Agriculture. Section 3701 sets out the congressional findings and declarations, recognizing that efficient systems for the storage, handling, and movement of bulk agricultural commodities are essential to the success of United States agriculture and to rural development, and that subterminal facilities can consolidate commodities from local elevators for onward shipment. Section 3702 defines the key terms, including bulk agricultural commodity, subterminal facility, and region. Section 3703 authorizes the Secretary to make grants to States and to regions for the development of State and regional plans for subterminal facilities, with the federal grant not exceeding 80 per centum of the cost of preparing the plan, and authorizes appropriations not to exceed 3,300,000 dollars for each of the fiscal years ending September 30, 1981, September 30, 1982, and September 30, 1983. The Act is a federal instrument for planning the rural grain and bulk commodity handling infrastructure that connects farms and local elevators to terminal markets and export channels.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-agricultural-trade-act-1978",
    "title": "US Agricultural Trade Act of 1978 (7 USC ch 87): Export Credit Guarantees and Market Development Programs",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agricultural Trade Act of 1978 (7 U.S.C. ch. 87, sections 5601 onward) is the principal United States statute for promoting commercial agricultural exports, administered by the Foreign Agricultural Service of the Department of Agriculture using the financing capacity of the Commodity Credit Corporation. Section 5602 defines key terms, including agricultural commodity and unfair trade practice. Section 5622 establishes the export credit guarantee program, under which the Commodity Credit Corporation may guarantee the repayment of credit made available to finance commercial export sales of agricultural commodities, and section 5641 governs the funding of the credit programs, providing that the Commodity Credit Corporation shall make available for each fiscal year 5,500,000,000 dollars of credit guarantees under section 5622(a). Section 5623 establishes the agricultural trade promotion and facilitation programs, including the Market Access Program, the Foreign Market Development Cooperator Program, and the E (Kika) de la Garza Emerging Markets Program, with annual funding provided under section 5623(f) of 255,000,000 dollars allocated as not less than 200,000,000 dollars for the Market Access Program, not less than 34,500,000 dollars for the Foreign Market Development Cooperator Program, and not more than 8,000,000 dollars for the Emerging Markets Program. The Act is the legal foundation of United States agricultural export credit and market development policy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-agricultural-trade-development-assistance-act",
    "title": "US Food for Peace Act (Agricultural Trade Development and Assistance Act of 1954, 7 USC ch 41): International Food Aid",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agricultural Trade Development and Assistance Act of 1954, known as the Food for Peace Act (7 U.S.C. ch. 41, sections 1691 onward, originally Public Law 480), is the principal United States international food aid statute, administered jointly by the Secretary of Agriculture and the Administrator of the United States Agency for International Development under authority delegated by the President. Section 1691 declares the policy of using the abundant agricultural productivity of the United States to combat hunger and malnutrition, to promote broad-based economic and agricultural development in developing countries, and to expand international trade and foster private enterprise. Title I (section 1701 onward) authorizes economic assistance and food security through the financing of sales of agricultural commodities to developing countries and private entities; section 1702 governs agreements with eligible countries and private entities, and section 1703 sets terms and conditions of sales, allowing repayment over a period of not more than 30 years with a grace period on principal and interest not in excess of 5 years, while section 1704 governs the use of local currency payments. Title II (section 1721 onward) authorizes the donation of agricultural commodities for emergency and non-emergency assistance through government-to-government agreements and private voluntary organizations and cooperatives. The Act is the legal foundation of United States food aid and the Food for Peace program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-agricultural-warehouse-act",
    "title": "US Warehouse Act (7 USC ch 10): Licensing of Agricultural Warehouses, Receipts and Penalties",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The United States Warehouse Act, codified at 7 U.S.C. Chapter 10 (sections 241-256), provides for the federal licensing and regulation of warehouses that store agricultural products and for the integrity of warehouse receipts, administered by the US Department of Agriculture. Section 241 defines the terms, and section 242 sets out the powers of the Secretary, including the authority to issue a license to a warehouse operator for the operation of a warehouse if the warehouse is suitable for the proper storage of the agricultural product. Section 243 provides for fees, and section 244 for quality and value standards. Section 245 requires, as a condition of a license or approval, that the applicant execute and file a bond or provide other financial assurance to secure the operator's obligations. Section 246 requires the maintenance of records, section 247 requires the operator to deal in a fair and reasonable manner with persons storing agricultural products, and section 248 governs the commingling of agricultural products. Section 250 governs warehouse receipts, requiring each receipt to contain the information the Secretary requires by regulation and prohibiting the issuance of an additional receipt while a receipt remains outstanding and uncancelled. Section 251 requires the operator, without unnecessary delay, to deliver the stored agricultural product on demand by the holder of the receipt or the depositor where the required charges are paid and the receipt is surrendered. Section 252 provides for the suspension or revocation of licenses. Section 254 sets the penalties: the Secretary may assess a civil penalty of not more than $25,000 per violation where an agricultural product is not involved in the violation, or of not more than 100 percent of the value of the agricultural product where one is involved. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ai-cybersecurity-clearinghouse-2026",
    "title": "US AI Cybersecurity Clearinghouse (Sec. 2(d), EO Promoting Advanced AI Innovation and Security, 2026)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The AI Cybersecurity Clearinghouse is the voluntary federal-industry coordination body created by Section 2 of the Executive Order Promoting Advanced Artificial Intelligence Innovation and Security signed June 2, 2026. The Clearinghouse is to be formed within 30 days of the EO by the Secretary of the Treasury, in coordination with the Director of the National Security Agency and the Director of the Cybersecurity and Infrastructure Security Agency, in voluntary collaboration with the AI industry. The Clearinghouse has four explicit operative functions stated in Section 2: (1) coordinates and deconflicts scanning for software vulnerabilities, (2) discovers and validates such vulnerabilities, (3) coordinates and prioritises remediation of vulnerabilities, and (4) coordinates distribution of vulnerability patches. The Clearinghouse is a voluntary mechanism throughout - participation by AI developers, critical infrastructure operators and cybersecurity vendors is not compelled. Section 2 directs the Clearinghouse to operate alongside the CISA Binding Operational Directives issued within the same 30-day window to expedite cyber defence of federal civilian agency IT systems and facilitate access to cybersecurity tools and services including covered frontier models for agencies, States, local authorities and critical infrastructure operators. The Clearinghouse is distinct from CISA's pre-existing programmes (the Known Exploited Vulnerabilities Catalog, CIRCIA reporting under 6 USC 681b, the Joint Cyber Defense Collaborative) and from the NSA's pre-existing Cybersecurity Collaboration Center; the EO does not consolidate or replace those programmes but adds a new Treasury-led coordination layer focused specifically on AI-enabled vulnerability discovery and AI-assisted remediation at scale. Treasury's role is operational coordination not regulation - the Clearinghouse cannot impose mandatory disclosure obligations on participants and the EO's Section 3 prohibition on mandatory licensing applies by extension. The 30-day OMB directive at Sec. 2(e) on federal grant funding availability for advanced AI vulnerability detection applicants is the principal funding mechanism linked to Clearinghouse-aligned work.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-promoting-advanced-ai-innovation-security-2026",
      "us-cisa-known-exploited-vulnerabilities-bod-22-01",
      "us-cisa-circia-cyber-incident-reporting-2022",
      "us-cisa-ai-cybersecurity-collaboration-playbook-2024",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-ai-in-government-act-2020",
    "title": "US AI in Government Act of 2020 (Title I of Division U, Consolidated Appropriations Act 2021, Public Law 116-260)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The AI in Government Act of 2020 was enacted on December 27, 2020 as Title I of Division U of the Consolidated Appropriations Act 2021 (Public Law 116-260). Section 102 establishes the Artificial Intelligence Center of Excellence within the General Services Administration to facilitate adoption of AI by federal agencies, support pilots, and develop best practices and policy recommendations. Section 103 directs the Office of Management and Budget, in consultation with OSTP and other agencies, to issue a memorandum to federal agencies regarding policies for federal acquisition and use of AI - directly producing OMB Memorandum M-21-06 (in 2020/2021) and subsequent M-24-10 and M-25-21. Section 104 directs the Office of Personnel Management to identify key skills and competencies for AI-related federal positions, develop an occupational job series or update existing series, estimate workforce needs over 5 years, and report to Congress. The Act provides the statutory framework requiring agencies to inventory AI use cases (operationalised alongside EO 13960 Section 5) and is the underlying authority for OMB AI memoranda binding all federal executive branch agencies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "nist_framework",
        "naiia_relationship"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-13960-promoting-trustworthy-ai-federal-government-2020",
      "us-omb-m-24-10-federal-ai-governance-2024",
      "us-naiia-national-ai-initiative-act-2020",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ai-safety-institute-nist-2024",
    "title": "US AI Safety Institute (AISI) - NIST AI Safety Evaluation Framework and International Role",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The US AI Safety Institute (AISI), established within the National Institute of Standards and Technology (NIST) under the US Department of Commerce pursuant to President Biden's Executive Order 14110 of October 30, 2023 on Safe, Secure, and Trustworthy AI, serves as the US government's primary body for frontier AI safety evaluation and research - it has conducted pre-deployment evaluations of advanced AI models from Anthropic, OpenAI, Meta, and other leading AI developers; conducted red-team testing for dangerous capabilities including CBRN weapons uplift and cybersecurity threats; published the AI Safety Evaluations Framework; co-established the international AISI network with the UK AI Safety Institute (now DSIT AISI), which operates jointly under the Seoul AI Safety Summit Statement of Intent; despite President Trump's Executive Order 14179 of January 20, 2025 revoking EO 14110, the US AISI was not immediately abolished and continues to operate within NIST conducting AI safety research and evaluation; the US AISI's evaluation methodology, based on structured red-teaming and capability benchmarking aligned with NIST AI RMF, provides the technical basis for voluntary frontier AI developer safety evaluations that are increasingly referenced in international AI governance frameworks including the G7 Hiroshima Code of Conduct and EU AI Act Article 55 adversarial testing requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ai-safety-institute-nist-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-ai-safety-2023",
      "seoul-ai-safety-summit-2024",
      "g7-hiroshima-ai-process-guiding-principles",
      "eu-ai-act-article-55-systemic-risk-gpai",
      "uk-ai-safety-institute-framework-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-aisi-charter-2024",
    "title": "US AI Safety Institute Charter (Department of Commerce, February 7 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On February 7, 2024 the US Department of Commerce announced the establishment of the United States Artificial Intelligence Safety Institute (US AISI) housed within the National Institute of Standards and Technology (NIST). The Institute was created pursuant to Executive Order 14110 of October 30, 2023 (since rescinded by EO 14148 of January 20, 2025, but US AISI continues operating under statutory NIST authority via the National AI Initiative Act 2020 and the CHIPS and Science Act of 2022). US AISI's mandate covers four areas: (1) Develop measurement science and standards for evaluating frontier AI capabilities and risks; (2) Conduct pre-deployment testing of frontier AI models on a voluntary basis through model evaluation agreements with frontier AI laboratories; (3) Coordinate with allied AI Safety Institutes including the UK AISI, Japan AISI, Singapore AISI, EU AI Office, and the broader International Network of AISIs (launched November 2024); (4) Publish technical guidance on AI safety including the NIST AI 600-1 Generative AI Profile (July 2024) and Managing Misuse Risk for Dual-Use Foundation Models (NIST AI 800-1 draft). US AISI executed Memoranda of Understanding with OpenAI and Anthropic in August 2024 for pre-deployment access to flagship models. The Institute was rebranded in 2025 as the Center for AI Standards and Innovation (CAISI) under continuing NIST authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "international_alignment",
        "us_federal_alignment",
        "industry_engagement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-ai-600-1-gen-ai-profile",
      "nist-ai-100-2-adversarial-ml-taxonomy-2024",
      "us-naiia-national-ai-initiative-act-2020",
      "uk-ai-safety-institute-framework-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-algorithmic-accountability-act-2023",
    "title": "Algorithmic Accountability Act of 2023",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "Requires entities deploying high-impact automated decision systems (ADS) to conduct impact assessments evaluating risks of algorithmic discrimination, data quality, and system transparency. Applies to operators of ADS used for decisions affecting consumers in employment, housing, credit, insurance, education, and healthcare. Mandated under Section 3(a) of S.2892.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-42001-risk-assess",
      "iso-42001-transparency",
      "nist-ai-100-4-redteam"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-algorithmic-accountability-act-2023-automated-decision-systems-impact-assessment",
    "title": "US Algorithmic Accountability Act 2023 - Automated Decision Systems Impact Assessment Requirements",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2023-12-01",
    "bluf": "The Algorithmic Accountability Act of 2023 (Senate Bill S.2892), introduced in the 118th Congress, would require large US companies (over 50 million users or USD 550 million revenue) to conduct and document impact assessments for automated decision systems that make or support consequential decisions affecting consumers. Assessments must cover data sources, decision logic, potential impacts, accuracy, bias, and privacy risks. The FTC would oversee compliance and enforcement. As of 2024, the bill has not been enacted but represents the leading US AI impact assessment framework proposal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0-risk-management-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-america-competes-act-2007-pl-110-69",
    "title": "US America COMPETES Act of 2007 (Public Law 110-69) - Federal Investment in Science Technology Engineering and Mathematics",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The America COMPETES Act of 2007 authorised sustained federal investment in basic research, science and engineering education, and innovation capacity by doubling the budgets of the National Science Foundation, the Department of Energy Office of Science, and the National Institute of Standards and Technology laboratories over seven years, creating the Advanced Research Projects Agency-Energy, expanding the National Science Foundation Graduate Research Fellowship, and establishing teacher preparation and mathematics and science education programs administered by the Department of Education.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "us-higher-education-act-1965"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-american-recovery-reinvestment-act-2009-pl-111-5",
    "title": "US American Recovery and Reinvestment Act of 2009 (Public Law 111-5) - Federal Stimulus and Recipient Reporting Framework",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The American Recovery and Reinvestment Act of 2009 appropriated approximately 787 billion dollars in tax cuts, transfer payments, infrastructure, energy, education, and health spending to mitigate the 2008 recession, established a binding recipient reporting regime for grants, contracts, and loans funded by the Act published on a public website, created the Recovery Accountability and Transparency Board to oversee fraud prevention, conditioned state acceptance of education stabilisation funds on maintenance of effort certifications, and enacted the Health Information Technology for Economic and Clinical Health Act expanding the breach notification and enforcement provisions of HIPAA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-hipaa-privacy-rule-2003",
      "us-davis-bacon-act",
      "us-eesa-tarp-2008-pl-110-343"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-americans-with-disabilities-act",
    "title": "US Americans with Disabilities Act (42 USC ch 126): Disability Discrimination and Accommodation",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Americans with Disabilities Act (42 U.S.C. ch. 126) prohibits discrimination on the basis of disability in employment, public services and public accommodations, with the employment provisions enforced by the Equal Employment Opportunity Commission. Section 12102 defines disability as a physical or mental impairment that substantially limits one or more major life activities, a record of such an impairment, or being regarded as having such an impairment, construed broadly under the ADA Amendments Act. Section 12111 provides the employment definitions, including qualified individual, reasonable accommodation and undue hardship. Section 12112 prohibits a covered entity from discriminating against a qualified individual on the basis of disability in regard to job application procedures, hiring, advancement, compensation, training and other terms of employment, and defines discrimination to include not making reasonable accommodation to the known limitations of an otherwise qualified individual unless the accommodation would impose an undue hardship, and using qualification standards that screen out individuals with disabilities unless job-related and consistent with business necessity. Section 12182 prohibits discrimination in the full and equal enjoyment of public accommodations operated by private entities. The Act requires an interactive process to identify reasonable accommodations. It is the legal foundation for US disability rights in employment and access.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-americas-ai-action-plan-2025",
    "title": "America's AI Action Plan - Three-Pillar Federal Strategy (July 2025)",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "America's AI Action Plan, published July 2025 by OSTP, OMB, NSC and the Special Advisor for AI and Crypto pursuant to Executive Order 14179, sets US federal AI policy across three pillars: (I) Accelerate AI Innovation; (II) Build American AI Infrastructure; (III) Lead in International AI Diplomacy and Security. Specific federal actions include directing NIST to revise the AI Risk Management Framework to remove references to misinformation, DEI and climate change; standing up NIST's Center for AI Standards and Innovation (CAISI); restricting AI-related federal discretionary funding to states whose AI regulatory regimes hinder federal funding effectiveness; updating Federal procurement to require LLMs free from ideological bias; expanding NEPA Categorical Exclusions and FAST-41 coverage for data centres; tightening compute and semiconductor export controls; and advancing biosecurity and frontier-model national security evaluations. The Plan formalises the Chief AI Officer Council (CAIOC) and references EOs 14110 (rescinded), 14179, 14192, 14277 and 14278 plus the TAKE IT DOWN Act (Pub. L. 119-12).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_eo_14179_ai_2025",
        "nist_ai_rmf",
        "us_caisi_2025",
        "eu_ai_act",
        "us_take_it_down_act_2025"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14179-ai-2025",
      "us-caisi-center-ai-standards-innovation-2025",
      "nist-ai-rmf-1-0",
      "us-ostp-blueprint-ai-bill-of-rights"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-aml-act-2020-anti-money-laundering-act-ndaa-fy-2021-division-f",
    "title": "US Anti-Money Laundering Act of 2020 (AMLA 2020) - NDAA FY 2021 Division F - Bank Secrecy Act Modernization and Corporate Transparency Act",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "The Anti-Money Laundering Act of 2020 (AMLA 2020) is Division F of the National Defense Authorization Act for Fiscal Year 2021 (Pub. L. 116-283), enacted over presidential veto on 1 January 2021. AMLA 2020 is the most significant overhaul of the US Bank Secrecy Act (BSA, 31 USC 5311 et seq.) since the USA PATRIOT Act of 2001. It comprises four titles: Title LXI (BSA Reform), Title LXII (Modernizing the AML and CFT System), Title LXIII (Improving AML and CFT Communication, Oversight and Processes), and Title LXIV (Establishing Beneficial Ownership Information Reporting Requirements; the Corporate Transparency Act, CTA). Key provisions: (1) Section 6101 reforms BSA by adding new policy objectives including modernization, technology and risk-based focus, expanding the BSA to address emerging threats including digital assets; (2) Section 6102 modernizes the FinCEN organization with new Domestic Liaison positions and an Innovation Officer; (3) Section 6204 establishes the Bank Secrecy Act whistleblower program with awards up to thirty percent of monetary sanctions exceeding USD 1,000,000 and anti-retaliation protections aligned with the Dodd-Frank framework; (4) Section 6212 expands FinCEN's enforcement and information-sharing authority including with foreign authorities; (5) Section 6403 enacts the Corporate Transparency Act establishing beneficial ownership information (BOI) reporting to FinCEN for most US-formed and foreign-registered entities, codified at 31 USC 5336 with FinCEN final rule published 30 September 2022 and effective 1 January 2024 (CTA reporting was significantly narrowed in scope by the FinCEN interim final rule of 21 March 2025 limiting CTA application to foreign reporting companies in light of Texas Top Cop Shop v. McHenry litigation); (6) Section 6314 increases penalties for repeat BSA violations including egregious violators barred from serving as officers or directors; (7) Section 6308 expands the BSA subpoena power to obtain foreign bank records relevant to US BSA enforcement or sanctions matters. The Act applies to BSA covered financial institutions including banks, credit unions, money services businesses (MSBs), broker-dealers, mutual funds, futures commission merchants, casinos, and from a 2024 FinCEN final rule extends to investment advisers and residential real estate transfers in covered geographic areas. FinCEN published the first National AML Priorities on 30 June 2021 covering corruption, cybercrime, foreign and domestic terrorist financing, fraud, transnational criminal organization activity, drug trafficking organization activity, human trafficking, and proliferation financing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "bsa_modernization_anchor",
        "corporate_transparency_act_anchor",
        "whistleblower_program_anchor",
        "enforcement_expansion_anchor",
        "industry_mapping",
        "fincen_priorities_anchor",
        "international_cooperation_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-1970",
      "us-31-usc-5311-5318-bank-secrecy-act-aml-program",
      "us-corporate-transparency-act-2020-31-usc-5336"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-animal-health-protection-act",
    "title": "US Animal Health Protection Act (7 USC ch 109): Pest and Disease Controls, Quarantine and Penalties",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Animal Health Protection Act (AHPA), codified at 7 U.S.C. Chapter 109 (sections 8301-8322), is the principal US statute authorizing the prevention, detection, control and eradication of pests and diseases of livestock, administered by the USDA Animal and Plant Health Inspection Service (APHIS). Section 8302 defines the regulated terms, including 'animal', 'article', 'means of conveyance', 'pest' and 'disease'. Section 8303 authorizes the Secretary to prohibit or restrict the importation or entry of any animal, article or means of conveyance where necessary to prevent the introduction into or dissemination within the United States of any pest or disease of livestock. Section 8304 governs exportation and section 8305 authorizes the Secretary to prohibit or restrict the movement in interstate commerce of any animal, article or means of conveyance to prevent the introduction or dissemination of livestock pests or diseases. Section 8306 confers seizure, quarantine and disposal authority: the Secretary may hold, seize, quarantine, treat, destroy or otherwise dispose of any animal, article, facility or means of conveyance that may carry or has been exposed to a livestock pest or disease, and in an extraordinary emergency may apply remedial action including preventative slaughter. Section 8307 provides inspection, seizure and warrant authority, section 8308 covers detection, control and eradication, and section 8309 establishes the veterinary accreditation program. Section 8313 sets the penalties. Criminal: a knowing violation is punishable by a fine under title 18, imprisonment of not more than one year, or both; a knowing violation involving importation, entry, exportation or movement for distribution or sale by imprisonment of not more than five years; and a second or subsequent conviction by imprisonment of not more than ten years. Civil: the Secretary may assess a civil penalty of not more than $50,000 in the case of an individual and not more than $250,000 in the case of any other person for each violation, or, alternatively, twice the gross gain or gross loss, with aggregate limits of $500,000 (or $1,000,000 where the violations were willful). Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-animal-welfare-act",
    "title": "US Animal Welfare Act: Licensing, Humane Standards, Research Facilities and Enforcement",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Animal Welfare Act (AWA), codified at 7 U.S.C. Chapter 54 (sections 2131-2159), is the principal US statute setting humane standards for the treatment of animals by dealers, research facilities, exhibitors, carriers and intermediate handlers, administered by the US Department of Agriculture (USDA) through the Animal and Plant Health Inspection Service (APHIS). Section 2131 states the congressional purposes, and section 2132 defines the regulated entities and the term 'animal'. Sections 2133-2136 require dealers and exhibitors to be licensed, and research facilities, carriers and intermediate handlers to register, with USDA. Section 2143 directs the Secretary to promulgate standards governing the humane handling, care, treatment and transportation of animals, including minimum requirements for handling, housing, feeding, watering, sanitation, ventilation, shelter from extremes of weather, adequate veterinary care, separation of species where necessary, exercise for dogs, and a physical environment adequate to promote the psychological well-being of primates. For research facilities, section 2143 also requires the minimization of pain and distress through the appropriate use of anesthetic, analgesic or tranquilizing drugs or euthanasia, consideration of alternatives to painful procedures, and the establishment of an institutional animal care and use committee that conducts semiannual inspections and reports. Section 2146 confers inspection and investigation authority, and section 2149 provides for enforcement, including license suspension or revocation, cease-and-desist orders, and civil penalties for each violation, with criminal penalties for specified conduct. Section 2156 separately prohibits animal fighting ventures. The Act is implemented by regulations and standards in 9 CFR Parts 1-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-animal-welfare-act-7-usc-2131",
    "title": "US Animal Welfare Act (7 USC 2131) - Federal Standards for Care of Regulated Animals",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Animal Welfare Act establishes federal humane care and treatment standards for warm-blooded animals used in research, exhibited to the public, sold as pets at the wholesale level, or transported commercially, requires registration of research facilities and licensing of dealers and exhibitors with the United States Department of Agriculture Animal and Plant Health Inspection Service, requires animal care committees at registered research facilities to oversee animal use protocols, prohibits sponsorship of animal fighting ventures and shipment of animals for such ventures, and authorises civil and criminal penalties for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-public-health-service-act"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-anti-deficiency-act-31-usc-1341",
    "title": "Anti-Deficiency Act - 31 USC 1341 Prohibition on Obligations Exceeding Appropriations",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 1341 of title 31 of the United States Code, the operative core of the Anti-Deficiency Act, prohibits any officer or employee of the United States government or the District of Columbia from making or authorising an expenditure or obligation exceeding the amount available in an appropriation or fund for the expenditure or obligation, from involving either government in a contract or other obligation for the payment of money before an appropriation is made unless authorised by law, and from making an obligation or expenditure in violation of sequestration limits established under the Balanced Budget and Emergency Deficit Control Act. Section 1342 prohibits accepting voluntary services or employing personal services exceeding that authorised by law except where required to meet emergencies involving the safety of human life or the protection of property. Section 1349 imposes adverse personnel action including suspension without pay or removal for knowing and wilful violations. Section 1350 establishes criminal penalties of up to 5,000 USD fine or two years imprisonment for knowing and wilful violations. Section 1351 requires the executive head of the agency to report each violation in writing to the President, the Office of Management and Budget, the Comptroller General, and the relevant congressional committees. The Anti-Deficiency Act is the principal statutory restriction on executive branch obligations and is central to government shutdown planning, AI procurement contracting, multi-year contract scoping, and the disposition of unused balances at fiscal year end.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paperwork-reduction-act-44-usc-ch35",
      "us-federal-records-act-44-usc-ch31"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-anti-kickback-statute",
    "title": "US Anti-Kickback Statute (42 USC 1320a-7b): Criminal Prohibition on Health Care Remuneration",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Anti-Kickback Statute (42 U.S.C. 1320a-7b) is the principal US criminal prohibition on the payment or receipt of remuneration to induce or reward referrals under a Federal health care program, enforced by the Department of Health and Human Services Office of Inspector General and the Department of Justice. Section 1320a-7b(b) makes it a felony to knowingly and willfully solicit or receive any remuneration, including any kickback, bribe or rebate, in return for referring an individual for an item or service, or for purchasing, leasing, ordering or arranging for any good, facility, service or item for which payment may be made under a Federal health care program; it equally prohibits knowingly and willfully offering or paying such remuneration to induce referrals or purchasing. A conviction is punishable by a fine of not more than 100,000 dollars or imprisonment for not more than 10 years, or both. Statutory exceptions and regulatory safe harbors protect defined arrangements. Section 1320a-7a authorizes civil monetary penalties, and section 1320a-7 authorizes exclusion from Federal health care programs. A violation can also give rise to liability under the False Claims Act. The statute is the legal foundation for US health care anti-kickback compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-anti-money-laundering-act-2020",
    "title": "Anti-Money Laundering Act of 2020 (AMLA 2020)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The AMLA 2020 significantly amends the Bank Secrecy Act (BSA) to strengthen the U.S. anti-money laundering framework. It mandates the creation of a national beneficial ownership registry for certain legal entities under the Corporate Transparency Act (Title LXIV), establishes a robust whistleblower reward program (Section 6314), and directs FinCEN to promote technological innovation and modernize AML/CFT regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bank-secrecy-act-suspicious",
      "fatf-guidance-virtual-assets-vasp"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-aphis-7-cfr-319-foreign-quarantine-plant-imports",
    "title": "7 CFR Part 319 - Foreign Quarantine Notices (Importation of Plants, Plant Products, and Other Articles to Prevent the Introduction of Plant Pests and Noxious Weeds) (USDA APHIS)",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "7 CFR Part 319 prohibits or restricts the importation into the United States of certain plants, plant products, and other articles to prevent the introduction and dissemination of plant pests and noxious weeds within and throughout the United States. It preempts inconsistent State and local laws regulating plants or plant products in foreign commerce, establishes permit requirements (including controlled import permits for experimental, therapeutic, or developmental purposes), and sets shipping, inspection, and post-importation conditions enforced by APHIS Plant Protection and Quarantine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-plant-protection-act",
      "ippc-1997-international-plant-protection",
      "canada-plant-protection-act"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-aphis-7-cfr-340-genetically-engineered-organisms",
    "title": "7 CFR Part 340 - Introduction of Organisms and Products Altered or Produced Through Genetic Engineering Which Are Plant Pests or Which There Is Reason to Believe Are Plant Pests (USDA APHIS)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "7 CFR Part 340 prohibits any person from introducing a regulated article (an organism or product altered or produced through genetic engineering that is or may be a plant pest) unless APHIS is notified or the introduction is authorized by permit, or the introduction is conditionally exempt. Regulated articles introduced out of compliance are subject to immediate remedial measures or safeguards determined by an inspector. The part defines the regulated taxa, the notification and permit pathways, container and identity requirements, and the petition process for nonregulated status.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-plant-protection-act",
      "us-coordinated-framework-biotechnology-1986",
      "usa-nih-guidelines-recombinant-dna-research-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-arizona-sports-wagering-act-2021",
    "title": "Arizona Event Wagering Act 2021 - Sports Betting via Tribal and Professional Team Licences",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Arizona's Event Wagering Act (HB 2772, 2021; A.R.S. 5-1301 et seq.) authorises sports betting through two streams: up to 20 Professional Sports Team Event Wagering Operators licenses and tribal gaming compact amendments. The Arizona Department of Gaming (ADG) regulates the market. Tax rates are 8% on retail event wagering and 10% on online/mobile event wagering. Sports betting launched 9 September 2021 (NFL kickoff weekend). Age minimum is 21. Up to 10 online skins per professional team or tribal partner are permitted.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_paspa_repeal",
        "arizona_tribal_gaming_compacts",
        "uigea_2006",
        "arizona_racing_commission",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
      "us-uigea-2006-unlawful-internet-gambling",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-arms-export-control-act",
    "title": "US Arms Export Control Act (22 U.S.C. Chapter 39): Statutory Authority for the Control of Defense Article and Defense Service Exports and the United States Munitions List",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Arms Export Control Act (AECA), codified at 22 U.S.C. Chapter 39, is the statutory authority for United States controls on the export and import of defense articles and defense services and for foreign military sales, administered by the Department of State through the Directorate of Defense Trade Controls and implemented in the International Traffic in Arms Regulations. Section 2751 declares the policy on the need for international defense cooperation and military export controls. Section 2752 requires coordination of the arms sales and export control functions with the foreign policy of the United States. Section 2753 sets the eligibility conditions a country or international organization must meet to be furnished defense services or defense articles. Section 2754 limits the purposes for which military sales or leases are authorized, including internal security and legitimate self-defense. Section 2778 is the core export control provision: it authorizes the President to designate items as defense articles and defense services constituting the United States Munitions List and to control their import and export, requires any person who engages in the business of manufacturing, exporting, or importing defense articles or services to register, requires a license before any defense article or defense service is exported or imported, and provides criminal penalties for violations. Section 2780 restricts transactions with countries determined to have repeatedly provided support for acts of international terrorism. Section 2785 requires end-use monitoring of defense articles and defense services. Section 2794 sets out the definitions. The Act is the foundational statute for United States defense trade controls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-atomic-energy-act",
    "title": "US Atomic Energy Act (42 USC ch 23): Nuclear Material and Facility Licensing",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Atomic Energy Act (42 U.S.C. ch. 23) is the principal US statute governing the civilian and defense use of nuclear materials and facilities. Civilian licensing and regulation are administered by the Nuclear Regulatory Commission, with defense functions assigned to the Department of Energy. Section 2073 governs the domestic distribution of special nuclear material, and section 2111 governs the domestic distribution of byproduct material. Section 2131 provides that a license is required to transfer, receive, manufacture, produce, acquire, possess, use, import or export any utilization or production facility. Section 2133 authorizes the issuance of commercial licenses for utilization and production facilities, such as power reactors, subject to conditions protecting health and minimizing danger to life or property. Section 2201 sets the general duties and powers of the Commission, including rulemaking, inspection and the establishment of safety standards. Section 2232 governs license applications and section 2236 governs revocation. Section 2272 provides criminal penalties for willful violations involving special nuclear material and facilities, and section 2282 authorizes civil monetary penalties for violations of licensing requirements. The Act is the legal foundation for US nuclear reactor and materials licensing and safety regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-atomic-energy-act-1954",
    "title": "US Atomic Energy Act of 1954 (42 USC ch 23): NRC Licensing of Nuclear Facilities and Special Nuclear Material",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Atomic Energy Act of 1954 (42 U.S.C. ch. 23) is the foundational federal statute governing the civilian use of atomic energy and nuclear material, administered for civilian purposes by the Nuclear Regulatory Commission (NRC). Section 2011 sets the declaration of policy, section 2013 the purpose of the chapter, and section 2014 supplies the definitions, including special nuclear material, source material, byproduct material and utilization or production facility. Section 2021 provides for cooperation with the States, including agreement States that assume regulatory authority over certain material. Licensing is mandatory: section 2131 prohibits the operation of a utilization or production facility without a license, section 2133 governs commercial licenses for facilities such as power reactors, and section 2134 governs medical, industrial and research licenses. Section 2201 sets out the general duties and powers of the Commission, including the authority to establish standards and conduct inspections to protect health and minimize danger to life or property. Section 2232 sets the requirements for license applications and section 2236 authorizes the revocation of a license for material false statements or for failure to comply with the Act, regulations or license conditions. Enforcement is provided by section 2282 (civil penalties) and section 2282a (civil monetary penalties for safety and whistleblower violations), alongside the criminal provisions of the Act. The Act is the legal basis on which the NRC licenses and inspects reactors and nuclear materials and enforces nuclear safety in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-atsa-2001-aviation-transportation-security-pl-107-71",
    "title": "US Aviation and Transportation Security Act of 2001 (Public Law 107-71) - Transportation Security Administration Establishment",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Aviation and Transportation Security Act of 2001 created the Transportation Security Administration within the Department of Transportation and later transferred to the Department of Homeland Security, federalised passenger and baggage screening at commercial airports, required the deployment of explosive detection systems for checked baggage, established a federal air marshal program, hardened cockpit doors, required criminal history record checks for transportation workers, and authorised civil penalties against carriers, airports, and passengers for security violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-patriot-act-2001-pl-107-56"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-audio-home-recording-act-1992-ahra",
    "title": "Digital Audio Recording Devices and Media",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The Audio Home Recording Act of 1992 establishes requirements for digital audio recording devices and media, including implementation of the Serial Copy Management System (SCMS) to prevent unauthorized serial copying, and mandates royalty payments on blank digital audio media and recording devices. These obligations apply to manufacturers and importers under 17 U.S. Code Chapter 10, specifically § 1002 and § 1003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dmca-safe-harbor",
      "copyright-fair-use-us",
      "berne-convention-1886-2024-literary-artistic-works"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-automated-vehicles-comprehensive-plan-2021",
    "title": "Automated Vehicles Comprehensive Plan 2021 - Policy Priorities: Safety Measurement, Proactive Safety and Collaboration for AV Deployment",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The USDOT's Automated Vehicles Comprehensive Plan 2021 establishes a national framework to advance the safe deployment of automated vehicles (AVs) through voluntary safety self-assessments, data sharing, and multi-stakeholder collaboration. It applies to manufacturers, developers, and operators of SAE Level 3-5 automated driving systems and requires adherence to safety design, testing, and transparency principles outlined in the plan’s core policy pillars.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-1800-17-mfa-ecommerce",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-bank-holding-company-act",
    "title": "US Bank Holding Company Act (12 USC ch 17): Bank Holding Company Acquisitions and Activities",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Bank Holding Company Act (12 U.S.C. ch. 17) regulates the formation, acquisitions and permissible activities of companies that control banks, administered by the Board of Governors of the Federal Reserve System. Section 1841 provides the definitions, including bank holding company and control. Section 1842 makes it unlawful, except with the prior approval of the Board, for any action to be taken that causes a company to become a bank holding company, or for a bank holding company to acquire direct or indirect ownership or control of more than 5 percent of the voting shares of a bank, or to acquire substantially all the assets of a bank, or to merge with another bank holding company; in acting on an application the Board must consider the competitive effects, and may not approve a transaction that would result in a monopoly or substantially lessen competition unless the anticompetitive effects are clearly outweighed by the public interest in meeting the convenience and needs of the community, and must consider the financial and managerial resources and future prospects, the effectiveness in combating money laundering, and the risk to financial stability. Section 1843 restricts the nonbanking activities of bank holding companies to those closely related to banking or permissible for a financial holding company. Section 1844 provides for administration, reporting and supervision by the Board. The Act is the legal foundation for US bank holding company regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-bank-holding-company-act-1956",
    "title": "US Bank Holding Company Act 1956 (BHCA) - BHC Supervision & Permissible Activities",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Bank Holding Company Act of 1956 (12 USC §1841 et seq.) requires companies that own or control one or more banks to register as Bank Holding Companies (BHCs) with the Federal Reserve and subjects them to Federal Reserve oversight. The BHCA restricts BHC activities to those 'closely related to banking' (§4(c)(8)) unless the BHC elects Financial Holding Company (FHC) status under the Gramm-Leach-Bliley Act 1999 - which permits insurance underwriting, securities underwriting, and merchant banking. The Volcker Rule (BHCA §13, added by Dodd-Frank) prohibits BHCs and their subsidiaries from proprietary trading and fund sponsorship/ownership.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-glba-gramm-leach-bliley-act-1999",
      "us-dodd-frank-title-vii-otc-derivatives-2010",
      "us-federal-reserve-regulation-w-affiliate-transactions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-bank-secrecy-act",
    "title": "US Bank Secrecy Act (31 USC ch 53 subch II): Currency Transaction Reports, AML Programs and Anti-Structuring",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Bank Secrecy Act (31 U.S.C. ch. 53, subchapter II) is the foundational US anti-money-laundering statute, administered by the Financial Crimes Enforcement Network (FinCEN) within the Department of the Treasury. Section 5311 declares the purpose of requiring reports and records that are useful in criminal, tax, regulatory and counter-terrorism investigations and of preventing money laundering. Section 5312 supplies the definitions, including the broad definition of financial institution, which extends to banks, brokers, money transmitters, casinos and certain other businesses. Section 5313 requires domestic financial institutions to file currency transaction reports for transactions above the prescribed threshold. Section 5318 sets the compliance framework, including the duty to maintain an anti-money-laundering program, customer due diligence, and the Treasury summons authority, and section 5318A authorizes special measures against jurisdictions or institutions of primary money-laundering concern. Enforcement is direct: section 5321 provides civil penalties, section 5322 provides criminal penalties for willful violations, and section 5324 prohibits structuring transactions to evade the reporting requirements. The Act, together with the suspicious-activity-report regime, is the legal foundation of US financial-institution AML compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-bank-secrecy-act-1970",
    "title": "US Bank Secrecy Act 1970 -- AML Programme Requirements and Financial Intelligence Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "The Bank Secrecy Act 1970 (31 USC 5311-5336), administered by the Financial Crimes Enforcement Network (FinCEN), requires financial institutions to maintain anti-money laundering (AML) programmes with four mandatory pillars under 31 USC 5318(h): written internal controls, a designated BSA/AML compliance officer, ongoing employee training, and independent programme testing. Financial institutions must file Currency Transaction Reports (CTRs) on FinCEN Form 104 for cash transactions exceeding USD 10,000 under 31 CFR 1010.311, and Suspicious Activity Reports (SARs) on FinCEN Form 111 within 30 calendar days of detecting a suspicious transaction involving USD 5,000 or more under 31 CFR 1020.320. The Travel Rule under 31 CFR 1010.410 requires originator and beneficiary information transmission for funds transfers of USD 3,000 or more. Customer Identification Programmes (CIP) are mandatory under 31 CFR 1020.220, and the 2016 Customer Due Diligence (CDD) Rule under 31 CFR 1010.230 requires beneficial ownership identification at the 25 percent ownership threshold for legal entity customers. Civil monetary penalties reach USD 1,000,000 per day or twice the transaction amount under 31 USC 5321. The Anti-Money Laundering Act 2020 (Division F, NDAA FY2021) modernised the BSA framework, and the Corporate Transparency Act 2024 (31 USC 5336) established the FinCEN beneficial ownership registry requiring most US legal entities to report beneficial owners holding 25 percent or more or exercising substantial control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-regulation-2013-575",
      "eu-markets-crypto-assets-regulation-2023-1114",
      "eu-payment-services-directive-2-2015-2366"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-bank-secrecy-act-31-cfr-1010-aml",
    "title": "US Bank Secrecy Act (BSA) 31 CFR Chapter X - Financial Institution AML Programme Requirements: Suspicious Activity Reports (SARs), Currency Transaction Reports (CTRs), Customer Identification Programme and FBAR",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Bank Secrecy Act (BSA), codified under 31 CFR Chapter X, mandates that U.S. financial institutions establish comprehensive anti-money laundering (AML) programs to prevent financial crimes. This includes implementing a Customer Identification Program (CIP) under § 1020.220, filing Currency Transaction Reports (CTRs) for cash transactions over $10,000 per § 1010.311, and filing Suspicious Activity Reports (SARs) for transactions over $5,000 that suggest illegal activity per § 1020.320.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "interagency-guidance-third-party-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-bank-secrecy-act-31-cfr-1010-fincen-aml-ctr",
    "title": "US Bank Secrecy Act - 31 CFR Part 1010 FinCEN AML Currency Transaction & SAR Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The Bank Secrecy Act (31 USC 5311) requires financial institutions to file Currency Transaction Reports (CTRs) for cash transactions over $10,000, Suspicious Activity Reports (SARs) within 30 days of suspicious activity detection, implement AML programs, and maintain 5-year records - enforced by FinCEN with civil penalties up to $1 million per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-bankhead-jones-farm-tenant-act",
    "title": "US Bankhead-Jones Farm Tenant Act (7 USC ch 33): Farm Tenancy, Land Conservation and Utilization",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Bankhead-Jones Farm Tenant Act (7 U.S.C. ch. 33, sections 1000 to 1040) is a United States statute addressing farm tenancy, rural credit, and the conservation and utilization of land, administered by the Secretary of Agriculture through the Farm Service Agency. Section 1000 sets the short title. Section 1006a authorizes the Secretary to make loans to homestead or desertland entrymen and to purchasers of land in reclamation projects, secured by mortgages creating liens, and permitting deferral of repayment for a period of up to two years. Section 1010 authorizes and directs the Secretary to develop a program of land conservation and land utilization, including the retirement of submarginal land from cultivation, in order to correct maladjustments in land use and to assist in controlling soil erosion and protecting natural resources. Section 1011 sets out the powers of the Secretary to protect, improve, develop, and dispose of property acquired under the program, to cooperate with other agencies, and to make rules regulating the use and occupancy of such property, and provides that no appropriation shall be made for any single loan under the relevant subsection in excess of 500,000 dollars, with water storage costs not exceeding 30 per centum of the total estimated cost. Section 1035 governs the sale of reserved mineral interests. The Act is a foundational federal instrument for farm tenancy assistance and land utilization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-banking-act-1933-section-21-12-usc-378",
    "title": "Banking Act 1933 Section 21 (Glass-Steagall) - 12 USC 378",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 378 of title 12 of the United States Code, section 21 of the Banking Act of 1933 (Public Law 73-66, enacted 16 June 1933 - the Glass-Steagall Act), criminalises the simultaneous conduct of securities issuance, underwriting, dealing, or distribution and the receipt of deposits by the same entity, unless the entity is incorporated or permitted under federal or state law and subject to examination by federal or state banking authorities and publication of condition reports. The provision is the principal surviving statutory anchor of the Glass-Steagall separation of commercial banking from investment banking, after the Gramm-Leach-Bliley Act of 1999 repealed sections 20 and 32 (the affiliation restrictions). The prohibition continues to limit a non-bank securities firm from accepting deposits, materially shaping the legal structure of investment banks, broker-dealers, and bank-affiliated securities firms. Section 24 (Seventh) of the National Bank Act, also amended by Glass-Steagall, restricts the securities activities national banks may conduct for their own account; commercial bank securities activities are now conducted primarily through bank-affiliated broker-dealer subsidiaries under the Gramm-Leach-Bliley financial holding company framework. Wilful violations of section 21 are punishable by fine up to 5,000 USD and imprisonment up to 5 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-securities-exchange-act-1934",
      "us-securities-act-1933",
      "us-glba-gramm-leach-bliley-act-1999"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-bapcpa-2005-bankruptcy-abuse-prevention-pl-109-8",
    "title": "US Bankruptcy Abuse Prevention and Consumer Protection Act of 2005 (Public Law 109-8) - Chapter 7 Means Test and Credit Counseling",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Bankruptcy Abuse Prevention and Consumer Protection Act of 2005 amended Title 11 of the United States Code to require individual debtors above state median income to satisfy a means test before filing under Chapter 7, require pre-petition credit counseling from an approved nonprofit agency within 180 days of filing, require post-petition debtor education before discharge, raise homestead and lien-avoidance limits, extend the time between Chapter 7 discharges from six to eight years, broaden the categories of nondischargeable debts, impose new debtor document production duties, and create heightened attorney certification obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fdcpa-fair-debt-collection-practices-act-1977"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-bayh-dole-act-1980-technology-transfer",
    "title": "Patents and Inventions - Bayh-Dole Act of 1980 (35 U.S.C. §§200-212)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Bayh-Dole Act allows universities, nonprofits, and small businesses to retain title to inventions made with federal research funding, provided they disclose inventions, elect to retain title, file patent applications, and promote commercialization. Key obligations are codified in 35 U.S.C. §202(c).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-bayh-dole-act-university-ip-technology-transfer",
    "title": "Bayh-Dole Act: University and Small Business Patent Procedures (35 U.S.C. §§ 200-212)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Bayh-Dole Act permits universities, small businesses, and non-profit institutions to elect to pursue ownership of an invention developed with federal funding (35 U.S.C. § 202). This requires timely disclosure of inventions, election to retain title, and filing for patent protection, while granting the government a license and acknowledging federal support.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "paris-convention-industrial-property"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-bayh-dole-act-university-technology-transfer",
    "title": "35 U.S. Code Chapter 18 Part II - Patent Rights in Inventions Made with Federal Assistance",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-29",
    "bluf": "This regulation governs the ownership, reporting, and licensing of inventions made with federal funding, allowing contractors (e.g., universities) to elect title to inventions under § 202, subject to government rights including march-in rights under § 203 and requirements for U.S. manufacturing under § 204.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-biotech-directive-98-44-ec-patents",
      "cbd-convention-biological-diversity-1992",
      "cartagena-protocol-biosafety-2000"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-beat-base-erosion-anti-abuse-tax-regulations",
    "title": "Internal Revenue Code Section 59A: Tax on Base Erosion Payments of Taxpayers With Substantial Gross Receipts",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The Base Erosion and Anti-Abuse Tax (BEAT) under IRC Section 59A imposes a minimum tax on large corporations ($500M+ average annual gross receipts) that reduce their U.S. tax liability by making certain 'base erosion payments' to foreign related parties, applicable when such payments exceed 3% of total deductions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015",
      "un-model-double-taxation-convention-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-beat-code-59a-base-erosion-anti-abuse",
    "title": "US Internal Revenue Code Section 59A - Base Erosion and Anti-Abuse Tax (BEAT): Base Erosion Percentage Test, Applicable Taxpayers (>$500M Revenue) and Modified Taxable Income Calculation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under IRC § 59A, U.S. corporations and foreign corporations with U.S. branches that are part of a group with average annual gross receipts of at least $500 million must pay a minimum tax if their 'base erosion percentage' is 3% or higher (2% for certain banks/securities dealers), targeting deductible payments made to foreign related parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-beef-research-information-act",
    "title": "US Beef Research and Information Act (7 USC ch 62): The Beef Checkoff and Cattlemen's Beef Board",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Beef Research and Information Act (7 U.S.C. ch. 62, sections 2901 to 2911) authorizes the national beef promotion and research program, commonly known as the beef checkoff, administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 2901 sets out the congressional findings and declaration of policy, and section 2902 defines terms including cattle, beef, producer, and importer. Section 2903 authorizes the Secretary to issue a beef promotion and research order, and section 2904 prescribes the required terms in the order, including the establishment of the Cattlemen's Beef Promotion and Research Board and an Operating Committee and the imposition of an assessment at the rate of one dollar per head of cattle, or the equivalent thereof in the case of imported beef and beef products. Section 2905 governs the certification of organizations to nominate Board members, section 2906 requires a referendum, and section 2907 provides for refunds. Section 2908 provides for enforcement, section 2909 authorizes investigations, subpoenas, and judicial enforcement, and section 2910 addresses preemption and amendments to orders. Section 2911 authorizes appropriations. The Act is the federal commodity research and promotion regime for beef and the legal basis of the one-dollar-per-head assessment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-bis-advanced-computing-license-review-2026",
    "title": "BIS Final Rule - Revision to License Review Policy for Advanced Computing Commodities (15 CFR 742.6 and 744.23)",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "15 CFR 744.23 imposes supercomputer, advanced-node integrated circuits, and semiconductor manufacturing equipment end-use controls: without a license you may not export, reexport, or transfer (in-country) any item subject to the EAR described in the section when you have knowledge it is destined for a covered destination, end use, or end user; applications for licenses required by the section are subject to a presumption of denial license review policy for Macau and destinations specified in Country Group D:5, except that a case-by-case license review policy applies to the specific license applications enumerated in the section (latest amendment 91 FR 1687, Jan. 15, 2026).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-15-cfr-part-744-ear-end-user-end-use-controls-entity-list",
      "us-ear-15-cfr-730-774-ccl-9x515-space-export-controls",
      "us-export-control-reform-act-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-bis-ai-diffusion-framework-2025",
    "title": "US BIS Framework for Artificial Intelligence Diffusion - Interim Final Rule (15 CFR 740, 742, 744, 748)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "BIS published the Framework for Artificial Intelligence Diffusion as an interim final rule on 15 January 2025 (effective 13 January 2025; compliance generally required by 15 May 2025; supplement no. 10 paragraphs 14, 15 and 18 delayed to 15 January 2026). The rule expands existing Export Administration Regulations (EAR) controls on advanced computing integrated circuits under ECCNs 3A090.a, 4A090.a and the corresponding .z items, and imposes new controls on the model weights of certain advanced closed-weight dual-use AI models under newly created ECCN 4E091. The rule (a) revises the Regional Stability control in 15 CFR 742.6(a)(6)(iii) by bifurcating into (A) a worldwide licence requirement for 3A090.a / 4A090.a / .z and (B) destination-specific licence requirements for 3A090.b / 4A090.b / .z to Country Groups D:1, D:4, D:5 (excluding A:5 / A:6); (b) introduces three new License Exceptions - AIA (Artificial Intelligence Authorization), ACM (Advanced Compute Manufacturing) and LPP (Low Processing Performance); (c) updates License Exception NAC (Notified Advanced Computing) and Advanced Computing Authorized for ECCNs 3A090, 4A090, .z items; (d) creates Data Center Validated End-Users (DC VEUs) covering Universal VEUs (UVEU) and National VEUs in 15 CFR 748.15 with new Supplements No. 8 and No. 10 to Part 748; (e) sets country tiers - close allies in Supplement No. 5 to Part 740 paragraph (a) (presumption of approval), other destinations subject to per-country compute allocations, and Country Group D:5 plus Macau (presumption of denial). License-exception eligibility for AI model weights of open-weight models is preserved.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ear_dual_use_export_control",
        "us_export_control_reform_eccn_quantum_2023",
        "us_eo_14179_ai_2025",
        "uk_strategic_export_control",
        "eu_ai_act"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ear-dual-use-export",
      "us-export-control-reform-eccn-quantum-2023",
      "us-eo-14179-ai-2025"
    ],
    "primary_citations_count": 15
  },
  {
    "node_id": "us-blueprint-ai-bill-of-rights-2022-ostp",
    "title": "US Blueprint for an AI Bill of Rights 2022 (OSTP)",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This non-binding guidance from the White House Office of Science and Technology Policy establishes five principles for the design, use, and deployment of automated systems to protect the public in the age of artificial intelligence. It applies to federal agencies and recommends best practices for private sector organizations deploying AI systems that impact civil rights, liberties, and safety.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-ai-safety-2023",
      "australia-voluntary-ai-safety-standard-2024"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-bsa-31-usc-5311-5314-bank-secrecy-act",
    "title": "US Bank Secrecy Act - 31 USC §§ 5311-5314 (Reports of Currency and Foreign Transactions)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The US Bank Secrecy Act at 31 USC 5311 to 5314 establishes the statutory framework for the federal anti-money laundering regime administered by FinCEN. The provisions declare the policy of reporting currency transactions, foreign financial accounts, and suspicious activity to help detect and prevent money laundering and other financial crimes. Implementing regulations are at 31 CFR Chapter X. Financial institutions, defined broadly to include banks, broker-dealers, money services businesses, casinos, and certain virtual asset providers, must establish AML programmes, file Currency Transaction Reports for cash transactions over 10,000 USD, file Suspicious Activity Reports, and report foreign bank accounts (FBAR). Non-compliance triggers civil and criminal penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cfr_31_chx",
        "patriot_act",
        "fatf",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-bsa-bank-secrecy-act-31-usc-5311",
    "title": "US Bank Secrecy Act: Anti-Money Laundering Recordkeeping and Reporting Requirements",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-23",
    "bluf": "The Bank Secrecy Act establishes anti-money laundering recordkeeping and reporting obligations for financial institutions in the United States. It requires institutions to file reports for certain transactions, including cash transactions exceeding $10,000, and to maintain records of foreign financial agency transactions. The Act also requires identification and verification of beneficial owners of legal entity customers, and mandates verification of identity for persons opening new accounts. Enforcement is conducted by FinCEN and functional regulators, including the OCC, FRB, FDIC, NCUA, SEC, and CFTC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-bsee-30-cfr-250-oil-gas-sulphur-operations-ocs",
    "title": "30 CFR Part 250 - Oil and Gas and Sulphur Operations in the Outer Continental Shelf (BSEE)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "BSEE 30 CFR Part 250 governs oil, gas, and sulphur operations on the Outer Continental Shelf, setting the authority and applicability over lessees and operators, the performance standards the Director uses to regulate lease operations, the overarching duty to protect health, safety, property, and the environment, requirements for material-handling and electrical equipment, incorporation of consensus standards by reference, BSEE inspections and the consequences of unacceptable operating performance, approval of alternate procedures and departures, and responsibility for fulfilling leasehold obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 15
  },
  {
    "node_id": "us-ca-ab-1836-postmortem-digital-replicas-2024",
    "title": "California Assembly Bill 1836 (2024) - Use of Likeness: Digital Replica of Deceased Personality (Amendment to Civil Code Section 3344.1)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "California Assembly Bill 1836 was chaptered on 17 September 2024 (Stats. 2024, Chap. 258) and amends California Civil Code Section 3344.1 to create a new statutory liability for the unauthorised production, distribution, or making available of a digital replica of a deceased personality's voice or visual likeness in an expressive audiovisual work or sound recording. The amendment defines a digital replica as a computer-generated, highly realistic electronic representation that is readily identifiable as the voice or visual likeness of an individual that is embodied in a sound recording, image, audiovisual work, or transmission in which the actual individual either did not actually perform or appear, or did perform or appear, but the fundamental character of the performance or appearance has been materially altered. A person who produces, distributes, or makes available a digital replica of a deceased personality's voice or likeness in an expressive audiovisual work or sound recording without prior consent is liable to any injured party in an amount equal to the greater of ten thousand dollars or the actual damages suffered by the person controlling the rights to the deceased personality's likeness. AB 1836 preserves Civil Code Section 3344.1's underlying right-of-publicity structure - the rights pass to those who received them via contract or testamentary transfer, or per the statutory succession order (surviving spouse, then children and grandchildren, then parents). The statute of limitations preserves the existing seventy-year postmortem term - no action may be brought by reason of any use of a deceased personality's name, voice, signature, photograph, or likeness occurring after the expiration of seventy years after the death of the deceased personality. AB 1836 preserves the Civil Code Section 3344.1 exemptions where the use is in a play, book, magazine, newspaper, musical composition, audiovisual work, radio or television program, single and original work of fine art, advertisement or commercial announcement for any of those works, or news, public affairs, sports broadcast, or political campaign - subject to the statutory limits on those exemptions. Prevailing parties may recover attorneys' fees and costs, and the statute preserves the punitive damages remedy where applicable. AB 1836 is the postmortem companion to California AB 2602 (signed the same legislative cycle) governing the use of digital replicas of living persons under collective bargaining agreement and contracts of employment, and operates alongside the federal NO FAKES Act (proposed) and California AB 2655 (defending democracy from deepfake deception) in the broader 2024 California digital replica regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "digital_replica_definition_anchor",
        "liability_anchor",
        "rights_succession_anchor",
        "statute_of_limitations_anchor",
        "exemptions_anchor",
        "industry_mapping",
        "remedies_and_costs_anchor",
        "legislative_intent_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-ab2655-2024-defending-democracy-deepfake-deception",
      "us-no-fakes-act-2023-digital-replicas-ai",
      "us-ca-sb942-2024-ai-transparency-act-watermarking",
      "us-ca-ab2013-2024-genai-training-data-transparency",
      "us-tn-elvis-act-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ca-ab-2602-living-person-digital-replica-labor-code-2024",
    "title": "California Assembly Bill 2602 (2024) - Contracts Against Public Policy: Personal or Professional Services: Digital Replicas of Living Persons (Labor Code Section 927)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "California Assembly Bill 2602 was approved by the Governor on 17 September 2024 (Stats. 2024, Chap. 259) and adds Section 927 to the California Labor Code. AB 2602 renders unenforceable any provision in an agreement between an individual and any other person for the performance of personal or professional services as it relates to a new performance, fixed on or after 1 January 2025, by a digital replica of the individual, where the provision meets all of three conditions: (1) the provision allows for the creation and use of a digital replica of the individual's voice or likeness in place of work the individual would otherwise have performed in person; (2) (A) except as provided in (B), the provision does not include a reasonably specific description of the intended uses of the digital replica, and (B) failure to include a reasonably specific description does not render the provision unenforceable if the uses are consistent with the terms of the contract for the performance of personal or professional services and the fundamental character of the photography or soundtrack as recorded or performed; and (3) the individual was not represented in any of (A) by legal counsel who negotiated on behalf of the individual licensing the individual's digital replica rights and the commercial terms are stated clearly and conspicuously in a contract or other writing signed or initialed by the individual, or (B) by a labor union representing workers who do the proposed work where the terms of the collective bargaining agreement expressly addresses uses of digital replicas. Section 927(b) provides that the section does not affect provisions of a contract other than a provision that falls under subdivision (a) and does not impact, abrogate, or otherwise affect any exclusivity grants contained in or related to a provision subject to subdivision (a). Section 927(c)(1) defines digital replica as a computer-generated, highly realistic electronic representation that is readily identifiable as the voice or visual likeness of an individual that is embodied in a sound recording, image, audiovisual work, or transmission in which the actual individual either did not actually perform or appear, or the actual individual did perform or appear, but the fundamental character of the performance or appearance has been materially altered. Section 927(c)(2) excludes from digital replica the electronic reproduction, use of a sample of one sound recording or audiovisual work into another, remixing, mastering, or digital remastering of a sound recording or audiovisual work authorised by the copyright holder. AB 2602 is the living-person companion to AB 1836 (postmortem digital replicas amending Civil Code 3344.1) - both bills were enacted in the same 2024 California legislative cycle as the core statutory regime for AI-generated digital replicas of natural persons in audiovisual works.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "unenforceability_anchor",
        "first_condition_digital_replica_in_place_of_in_person_work_anchor",
        "second_condition_reasonably_specific_description_anchor",
        "third_condition_representation_anchor",
        "non_affected_provisions_and_exclusivity_anchor",
        "definition_anchor",
        "industry_mapping",
        "interaction_with_other_california_law_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-ab-1836-postmortem-digital-replicas-2024",
      "us-no-fakes-act-2023-digital-replicas-ai",
      "us-ca-sb942-2024-ai-transparency-act-watermarking",
      "us-ca-ab2655-2024-defending-democracy-deepfake-deception",
      "us-tn-elvis-act-2024"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-ca-ab-853-ai-transparency-act-amendments-2025",
    "title": "California Assembly Bill 853 of 2025 - AI Transparency Act Amendments and Manifest and Latent Disclosure Obligations",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "California Governor Gavin Newsom signed AB 853 on 13 October 2025, delaying the operation of the California AI Transparency Act from 1 January 2026 to 2 August 2026 (to align with the EU AI Act), expanding the responsibilities of GenAI system creators to large online platforms, GenAI source code and product distributors, and capture device manufacturers, requiring that a GenAI hosting platform from 1 January 2027 not knowingly make available a GenAI system unless it provides users with the option to include a manifest disclosure that the content was AI-generated and includes a latent disclosure conveying certain information of the GenAI system's CAITA compliance, and imposing capture-device latent disclosure obligations on devices produced for sale in California from 1 January 2028.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-sb53-frontier-ai"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ca-ab1008-2024-ccpa-ai-personal-information-formats",
    "title": "California AB 1008 (2024) - CCPA Amendment: AI Systems and Abstract Digital Formats of Personal Information",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "California Assembly Bill 1008 (Bauer-Kahan), Chapter 802 of the 2024 Statutes, amends California Civil Code Section 1798.140 - the definitions section of the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). The amendment clarifies that 'personal information' under the CCPA can exist in any format, including physical formats (paper documents, vinyl records), digital formats (text, image, audio files), and 'abstract digital formats, including compressed or encrypted files, metadata, or artificial intelligence systems that are capable of outputting personal information.' The Act was approved by the Governor on 28 September 2024 and filed with the Secretary of State the same day. It is operative immediately as a clarification of existing CCPA scope rather than a new mandate, and brings AI model weights, training corpora, embeddings, and any other AI artefact capable of outputting personal information within the consumer rights, data minimisation, retention, and security obligations of the CCPA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-ccpa-civil-code-1798-100-right-to-know-personal-information",
      "us-ca-ccpa-civil-code-1798-110-right-to-deletion-opt-out",
      "us-ca-ab2013-2024-genai-training-data-transparency"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-ab1836-digital-replica-deceased-personalities-2024",
    "title": "California Use of Likeness: Digital Replica of Deceased Personalities - Assembly Bill 1836 (Chapter 258 of 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "California Assembly Bill 1836, authored by Assemblymember Bauer-Kahan and enacted as Chapter 258 of the Statutes of 2024, was signed by Governor Newsom and filed with the Secretary of State on 17 September 2024. The Act amends California Civil Code Section 3344.1 (the deceased personality right of publicity statute) to expressly cover unauthorized use of a digital replica of a deceased personality's voice or likeness in an expressive audiovisual work or sound recording. A 'digital replica' under Section 3344.1 means a computer-generated, highly realistic electronic representation that is readily identifiable as the voice or visual likeness of an individual where the individual either did not actually perform or appear, or whose performance was materially altered. The Act requires the prior consent of the persons or entities controlling the deceased personality's rights before a digital replica may be produced, distributed or made available. Violations expose the user to statutory damages of 10,000 dollars or actual damages, whichever is greater, plus profits attributable to the unauthorized use and reasonable attorney's fees. Section 3344.1 carve-outs continue to apply for news, public affairs, sports broadcasts, political campaigns, and certain expressive works including biographical and historical works, plays, books, magazines, newspapers, musical compositions, audiovisual works, radio or television programs and works of political or newsworthy value, fictional or non-fictional entertainment, advertising or commercial announcements for any such works, single original works of fine art, and satire or parody. Deceased personality rights extend 70 years after death under Section 3344.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-ab2602-digital-replicas-personal-services-contracts-2024",
      "us-ca-sb942-2024-ai-transparency-act-watermarking"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-ab2013-2024-genai-training-data-transparency",
    "title": "California AB 2013 (2024) - Generative AI Training Data Transparency Act",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "California Assembly Bill 2013 (Irwin) requires developers of generative artificial intelligence systems or services made available to Californians on or after 1 January 2022 to post on their website documentation regarding the data used to train the generative AI system or service before 1 January 2026. The Act adds Title 15.2 (commencing with Section 3110) to Part 4 of Division 3 of the California Civil Code. Required disclosures include dataset sources or owners, how datasets serve the system's purpose, number of data points (general ranges acceptable), data types and characteristics, copyright trademark or patent status, whether data was purchased or licensed, whether personal information or aggregate consumer information is included, any data cleaning or modifications, the data collection timeframe, the dates the datasets were first used, and whether synthetic data generation is used. The Act applies to any developer of a generative AI system or service whose system was made available to Californians, regardless of where the developer is located. Approved by the Governor 28 September 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-ccpa-civil-code-1798-100-right-to-know-personal-information",
      "us-ca-sb53-frontier-ai",
      "eu-ai-act-2024-1689-article-16-obligations-providers-high-risk-ai"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-ab2013-genai-training-data-transparency-2024",
    "title": "California Generative Artificial Intelligence Training Data Transparency Act - Assembly Bill 2013 (Chapter 817 of 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "California Assembly Bill 2013, authored by Assemblymember Irwin and enacted as Chapter 817 of the Statutes of 2024, was signed by Governor Newsom on 28 September 2024 and takes effect on 1 January 2026. The Act adds Title 15.2 (commencing with Section 3110) to Part 4 of Division 3 of the California Civil Code. It requires a developer of a generative artificial intelligence system or service made publicly available to Californians on or after 1 January 2022 to post documentation on its publicly accessible website regarding the data used to train the generative AI system or service before publicly releasing the system or substantial modification, and at the time of any substantial modification. The documentation must include a high-level summary of the datasets used in training including the sources or owners of the datasets, the number of data points included, the types of data points, whether the datasets include any data protected by copyright, trademark or patent or other intellectual property, whether the datasets were purchased or licensed by the developer, whether the datasets include personal information or aggregate consumer information, the time periods during which the data in the datasets were collected, the dates the datasets were first used during development, and whether the system used or relied on synthetic data generation in its development. Covered developers are persons, partnerships, state or local government agencies and corporations that design, code, produce or substantially modify an AI system or service for use by members of the public. The Act exempts AI systems whose sole purpose is the operation of aircraft in the national airspace, systems developed for national security or military purposes and made available only to a federal entity, and systems developed and used for security and integrity of the developer.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-sb942-2024-ai-transparency-act-watermarking",
      "us-ca-sb53-frontier-ai"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-ab2602-digital-replicas-personal-services-contracts-2024",
    "title": "California Digital Replicas in Personal or Professional Services Contracts - Assembly Bill 2602 (Chapter 259 of 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "California Assembly Bill 2602, authored by Assemblymember Kalra and enacted as Chapter 259 of the Statutes of 2024, was signed by Governor Newsom on 17 September 2024 and adds Section 927 to the California Labor Code. The Act makes any provision of a contract for personal or professional services that allows the use of an individual's voice or visual likeness as a digital replica unenforceable if two conditions are met: the provision does not include a reasonably specific description of the intended uses of the digital replica or those uses are inconsistent with the original work for which the individual was engaged; AND the individual was not represented by either (i) legal counsel who negotiated the terms with reasonable specificity OR (ii) a labour union representing workers of the type performing the work under a collective bargaining agreement that expressly addresses uses of digital replicas. 'Digital replica' is defined as a computer-generated, highly realistic electronic representation that is readily identifiable as the voice or visual likeness of an individual that is embodied in a sound recording, image, audiovisual work or transmission where the actual individual either did not actually perform or appear, or where the performance was materially altered. The Act applies to contracts entered or extended on or after 1 January 2025. The provisions are enforceable through private civil action.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-ab1836-digital-replica-deceased-personalities-2024",
      "us-ca-sb942-2024-ai-transparency-act-watermarking"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-ab2655-2024-defending-democracy-deepfake-deception",
    "title": "California AB 2655 (2024) - Defending Democracy from Deepfake Deception Act",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "California Assembly Bill 2655 (Berman) - the Defending Democracy from Deepfake Deception Act of 2024 - obliges 'large online platforms' to identify and either remove or label materially deceptive AI-generated content depicting candidates, elections officials, or elected officials performing actions they did not actually do or say, where the content could harm the depicted person's reputation, electoral prospects, or public confidence in election outcomes. The Act adds Chapter 7 (commencing with Section 20510) to Division 20 of the California Elections Code. Removal is required from 120 days before an election through election day for candidate content, and 120 days before through 60 days after election day for elections-official content. Labeling is required from 6 months before through election day for candidates, and 6 months before through 60 days after election day for elections officials. State-of-the-art detection techniques must be applied. Effective 1 January 2025; subject to ongoing First Amendment challenge in federal court (Kohls v Bonta) where a preliminary injunction was granted October 2024 against an aligned California measure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-sb942-2024-ai-transparency-act-watermarking",
      "us-ca-ab2013-2024-genai-training-data-transparency"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-ab2655-defending-democracy-deepfake-deception-act-2024",
    "title": "California Defending Democracy from Deepfake Deception Act of 2024 - Assembly Bill 2655 (Chapter 261 of 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "California Assembly Bill 2655, authored by Assemblymember Berman and enacted as Chapter 261 of the Statutes of 2024, was signed by Governor Newsom on 17 September 2024 and adds Chapter 7 (Sections 20510 to 20520) to Division 20 of the California Elections Code. The Act targets materially deceptive AI-generated content related to California elections including deepfakes and AI-generated media depicting candidates, elections officials, or voting infrastructure in false scenarios. Large online platforms with one million or more California users must: remove certain deceptive content within 72 hours of a report; label other manipulated content with the disclosure 'This [image / audio / video] has been manipulated and is not authentic'; establish accessible reporting mechanisms for California residents; and respond to reports within 36 hours. Candidates may post self-created manipulated content if it includes a clear, conspicuous disclosure satisfying statutory sizing and audio requirements. The Attorney General, district attorneys and city attorneys may seek injunctive relief. Candidates, elected officials and elections officials have a private right of action for non-compliance, subject to a clear and convincing evidence standard, with priority calendar placement. Exemptions apply to news outlets meeting disclosure standards and to satire or parody content with appropriate disclosure. The Act includes a sunset on 1 January 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-ab2839-elections-deceptive-media-advertisements-2024",
      "us-ca-sb942-2024-ai-transparency-act-watermarking"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-ab2839-elections-deceptive-media-advertisements-2024",
    "title": "California Elections: Deceptive Media in Advertisements - Assembly Bill 2839 (Chapter 262 of 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "California Assembly Bill 2839, authored by Assemblymember Pellerin and enacted as Chapter 262 of the Statutes of 2024, was signed by Governor Newsom as an urgency statute on 17 September 2024 and took effect immediately. The Act amends California Code of Civil Procedure Section 35 and adds Section 20012 to the California Elections Code. It prohibits any person, committee or other entity from knowingly distributing an advertisement or other election communication containing materially deceptive content with actual malice within 120 days before any election and, for content concerning elections officials, elected officials, voting machines, ballots and voting sites, within 60 days after that election. Prohibited content includes deepfakes portraying candidates as doing or saying things they did not, false depictions of election officials connected to election activities, and misleading representations of voting machines, ballots or voting sites. Affected parties including content recipients, participating candidates or committees and elections officials may file civil actions seeking injunctive relief and damages. Prevailing plaintiffs recover reasonable attorney's fees and costs. Courts must prioritize these actions on their calendars. Candidates may use manipulated content if properly labeled with a statutorily compliant disclosure, and satire or parody content qualifies for exemption if disclosed as such. The urgency clause cites the immediate threat of AI-driven election disinformation in the 2024 election cycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-ab2655-defending-democracy-deepfake-deception-act-2024",
      "us-ca-sb942-2024-ai-transparency-act-watermarking"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-ab2876-ai-literacy-curriculum-frameworks-2024",
    "title": "California Pupil Instruction: Artificial Intelligence Literacy in Curriculum Frameworks - Assembly Bill 2876 (Chapter 927 of 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "California Assembly Bill 2876, authored by Assemblymember Berman and enacted as Chapter 927 of the Statutes of 2024, was signed by Governor Newsom on 29 September 2024 and adds California Education Code Section 33548. The Act requires the Instructional Quality Commission, when next revising the curriculum frameworks and evaluation criteria for the adoption of instructional materials in mathematics, science and history-social science after 1 January 2025, to consider incorporating artificial intelligence literacy content. AI literacy is defined as the knowledge, skills and attitudes associated with how artificial intelligence works, including its principles, concepts and applications, as well as how to use artificial intelligence, including its limitations, implications and ethical considerations. The Act preserves the existing requirement that the Instructional Quality Commission consider incorporating media literacy content into curriculum frameworks and instructional materials across multiple subject areas and grade levels. The California State Board of Education has the final authority to adopt the curriculum frameworks and instructional materials. Local educational agencies select instructional materials from those adopted by the State Board of Education for kindergarten through grade eight and from local lists for grades nine through twelve, and benefit from the AI literacy content as it is incorporated into the state-level frameworks and materials.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-sb896-genai-accountability-act-state-agencies-2024",
      "oecd-principles-ai-in-education-recommendation-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-ab3030-genai-healthcare-disclosure-2024",
    "title": "California Assembly Bill 3030 - Health Care Services: Artificial Intelligence (Approved 28 September 2024) - Mandatory Generative AI Disclaimer for Patient Clinical Communications by Health Facilities, Clinics, Physician Offices, and Group Practices; Codified as Health and Safety Code Section 1339.75",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "California Assembly Bill 3030, approved by Governor Newsom on 28 September 2024, adds Chapter 2.13 (commencing with Section 1339.75) to Division 2 of the California Health and Safety Code, requiring any health facility, clinic, physician's office, or office of a group practice that uses generative artificial intelligence to generate written or verbal patient communications pertaining to patient clinical information to include a disclaimer that the communication was generated by generative AI plus clear instructions describing how the patient may contact a human health care provider, employee, or other appropriate person. The disclosure requirement applies only to clinical communications and expressly excludes administrative matters such as appointment scheduling, billing, or other clerical or business matters. Section 1339.75 specifies the manner of disclosure by communication channel: for written communications involving physical and digital media including letters and emails, the disclaimer must appear prominently at the beginning of each communication; for continuous online interactions including chat-based telehealth, the disclaimer must be prominently displayed throughout the interaction; for audio communications, the disclaimer must be provided verbally at the start and end; for video communications, the disclaimer must be prominently displayed throughout. The statute carries a single material exception: a communication generated by generative AI that is read and reviewed by a human licensed or certified health care provider is exempt from the disclaimer and contact-instruction requirements. Enforcement authority routes to the existing oversight regimes for each covered entity: a violation by a health facility falls under the licensing jurisdiction of the State Department of Public Health (Health and Safety Code Article 3 of Chapter 2 of Division 2, beginning with Section 1275); a violation by a clinic falls under the same Department through the clinic-licensing scheme (beginning with Section 1225); a violation by a physician is subject to the jurisdiction of the Medical Board of California or the Osteopathic Medical Board of California, as appropriate. AB 3030 took effect through the standard California enactment process for non-urgency statutes - 1 January 2025 - and operates alongside California's 2024 generative AI and AI transparency statutes (SB 942, AB 2013) without preempting federal HIPAA or FDA SaMD obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-sb942-ai-transparency-act-2024",
      "us-ca-ab2013-genai-training-data-transparency-2024",
      "hipaa-privacy-rule"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-ca-ab3030-healthcare-genai-patient-communications-2024",
    "title": "California Health Care Services: Generative Artificial Intelligence Patient Communications - Assembly Bill 3030 (Chapter 879 of 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "California Assembly Bill 3030 was approved by Governor Newsom on 28 September 2024 and adds Health and Safety Code Section 1339.75 et seq. requiring health facilities, clinics, physician offices and group practices to disclose when generative AI is used to create written or audio or video patient communications pertaining to patient clinical information. The disclaimer must indicate to the patient that the communication was generated by generative artificial intelligence and must appear in a manner specified by the medium: prominently at the start of letters and emails, throughout chat-based interactions, verbally at the start and end of audio communications, and prominently throughout video communications. The disclaimer must also provide clear instructions describing how the patient can contact a human healthcare provider, employee or appropriate person. Communications reviewed and approved by a licensed or certified healthcare provider before transmission are exempt. Scope is limited to patient clinical information; administrative communications such as appointment scheduling and billing are out of scope. Enforcement runs through existing regulatory mechanisms with the California Department of Public Health for health facilities and clinics and the Medical Board of California or Osteopathic Medical Board of California for physician violations. Definitions of generative artificial intelligence and covered health professionals are set out in the new Health and Safety Code provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-sb1120-physicians-make-decisions-act-2024",
      "fda-ai-ml-samd-action-plan"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-ccpa-civil-code-1798-100-right-to-know-personal-information",
    "title": "California Civil Code § 1798.100. General Duties of Businesses that Collect Personal Information",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires businesses to inform consumers at or before the point of collection about the categories of personal information collected, the purposes for its use, and retention periods, and mandates specific contractual obligations when sharing data with third parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ca-ccpa-civil-code-1798-110-right-to-deletion-opt-out",
    "title": "Civil Code § 1798.110: Consumers’ Right to Know What Personal Information is Being Collected. Right to Access Personal Information",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article requires businesses to disclose to consumers, upon a verifiable request, the categories and specific pieces of personal information collected about them, the sources of that information, the business purpose for collection, and the categories of third parties with whom it is shared.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-cpra-civil-code-1798-121-sensitive-personal-information-rights",
    "title": "Civil Code § 1798.121. Consumers’ Right to Limit Use and Disclosure of Sensitive Personal Information",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must provide consumers with the right to limit the use and disclosure of their sensitive personal information to purposes necessary for providing requested goods or services and must cease other uses upon the consumer's direction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ca-delete-act-2023",
    "title": "California Delete Act 2023 (SB 362)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "California SB 362 signed October 10, 2023 requires data brokers to register with the California Privacy Protection Agency and mandates the CPPA to create a universal deletion mechanism by January 1, 2026 enabling consumers to delete personal information from all registered brokers with a single request.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ca-delete-act-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ca-eo-n-6-26-ai-workforce-disruption-2026",
    "title": "California Executive Order N-6-26 of 21 May 2026 - AI Workforce Disruption Preparation and WARN Act Review",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Governor Gavin Newsom signed Executive Order N-6-26 on 21 May 2026, effective immediately, mandating California state agencies to evaluate worker ownership expansion opportunities, create an AI workforce impact dashboard, review severance and compensation policies, modernize job training programs, establish a single online platform for government services, and produce recommendations within 180 days on revisions to the California Worker Adjustment and Retraining Notification (WARN) Act in light of potential AI-driven workforce disruption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-sb53-frontier-ai"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "us-ca-sb100-clean-energy-2018",
    "title": "California Senate Bill 100 (SB 100) - 100 Percent Clean Electricity by 2045",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "California load-serving entities (LSEs) must procure 60% of electricity from eligible renewable sources by 31 December 2030 and 100% from renewable or zero-carbon sources by 31 December 2045, with the California Public Utilities Commission (CPUC) and California Energy Commission (CEC) enforcing compliance and reporting requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "cpuc_rps",
        "cpuc_integrated_resource_planning",
        "ferc_market",
        "climate_scoping_plan",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-inflation-reduction-act-clean-energy-2022",
      "eu-renewable-energy-directive-2023-2413-red-iii",
      "ferc-order-2222-distributed-energy-resources-2020"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ca-sb1120-physicians-make-decisions-act-2024",
    "title": "California Senate Bill 1120 (Becker) - Physicians Make Decisions Act, Health Care Coverage: Utilization Review (2024) - Restrictions on AI, Algorithm, and Software Tool Use in Utilization Review by Health Care Service Plans and Disability Insurers; Amendments to Health and Safety Code Section 1367.01 and Insurance Code Section 10123.135",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "California Senate Bill 1120 (Becker), the Physicians Make Decisions Act, amends Section 1367.01 of the California Health and Safety Code (governing health care service plans regulated by the Department of Managed Health Care under the Knox-Keene Health Care Service Plan Act of 1975) and Section 10123.135 of the Insurance Code (governing disability insurers regulated by the Department of Insurance) to constrain how artificial intelligence, algorithms, and other software tools may be used in utilization review or utilization management functions. SB 1120 preserves the longstanding rule in subdivision (e) of each amended section that no individual other than a licensed physician or a licensed health care professional competent to evaluate the specific clinical issues involved may deny or modify requests for authorization of health care services for reasons of medical necessity, and it adds a parallel restriction targeting AI tools: an artificial intelligence, algorithm, or other software tool 'shall not deny, delay, or modify health care services based, in whole or in part, on medical necessity'; a determination of medical necessity shall be made only by a licensed physician or licensed health care professional competent to evaluate the specific clinical issues involved in the health care services requested, by reviewing and considering the requesting provider's recommendation, the enrollee's medical or other clinical history, and individual clinical circumstances. Where an AI/algorithm/software tool is used in utilization review or utilization management, the plan or insurer shall ensure that the tool: (A) bases its determination on enrollee-specific information including the enrollee's medical history and individual clinical circumstances, not solely on a group dataset (subdivision (B)); (C) criteria and guidelines comply with the applicable chapter including Section 1363.5; and (F) the tool is fairly and equitably applied including in accordance with applicable regulations and guidance issued by the federal Department of Health and Human Services. The bill preserves all existing utilization-review timeframes - within 24 hours of decision communication to the provider, no more than 72 hours for imminent-and-serious-threat conditions per Section 2719 of the federal Public Health Service Act (42 U.S.C. § 300gg-19), and the standard five-business-day non-urgent decision deadline - and preserves the Director of the Department of Managed Health Care's and the Insurance Commissioner's administrative-penalty authority for noncompliance. SB 1120 was approved by Governor Newsom on 28 September 2024 and chaptered the same day; the operative date is 1 January 2025 under California's standard rule for non-urgency statutes. Because Knox-Keene wilful violations are crimes (Health and Safety Code), the bill imposes a state-mandated local program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-ab3030-genai-healthcare-disclosure-2024",
      "us-ca-sb942-ai-transparency-act-2024",
      "hipaa-privacy-rule"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "us-ca-sb327-connected-device-security",
    "title": "California SB-327 Security of Connected Devices (Civil Code 1798.91.04-.06)",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "California SB-327 added Civil Code Sections 1798.91.04 through 1798.91.06, requiring a manufacturer of a connected device to equip the device with a reasonable security feature or features. Section 1798.91.04(a) requires security features appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and any information from unauthorized access, destruction, use, modification, or disclosure. Section 1798.91.04(b) deems security reasonable for a device with a means of authentication outside a local area network if either the preprogrammed password is unique to each device, or the device requires a user to generate a new means of authentication before access is granted for the first time. Section 1798.91.05 sets definitions and Section 1798.91.06 sets scope, exemptions, no private right of action, and enforcement by the Attorney General, a city attorney, a county counsel, or a district attorney.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "etsi-en-303-645-iot-cybersecurity-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-sb53-frontier-ai",
    "title": "California SB 53 (Transparency in Frontier AI Act)",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The nation's first comprehensive safety and transparency requirement for frontier AI developers, mandating catastrophic risk frameworks, 15-day incident reporting, and whistleblower protections for models trained above 10^26 FLOPs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-sp-1270-managing-ai-bias"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-sb896-genai-accountability-act-state-agencies-2024",
    "title": "California Generative Artificial Intelligence Accountability Act - Senate Bill 896 (Chapter 928 of 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "California Senate Bill 896, authored by Senator Dodd and enacted as Chapter 928 of the Statutes of 2024, was signed by Governor Newsom on 29 September 2024 and codifies key generative AI accountability measures for state government agencies. The Act requires state agencies and departments using generative AI to communicate directly with Californians about government services or benefits to include a disclaimer that the communication was generated by generative AI in the manner required by the medium, including prominent placement at the start of letters and emails, throughout chatbot interactions and verbally for audio interactions. The communication must also provide information or a link describing how the recipient can contact a human state employee. The Office of Emergency Services is required to perform a risk analysis of potential threats posed by generative AI to California's critical energy, water, communications, transportation and emergency services infrastructure and to report annual summaries to the Legislature. The Department of Technology is required to update the Governor's report on generative AI as significant new developments emerge. Implementation guidance is coordinated by the Government Operations Agency, the Office of Data and Innovation and the California Department of Human Resources. The Act applies to communications between state agencies and Californians about government services or benefits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-ab3030-healthcare-genai-patient-communications-2024",
      "us-ca-sb942-2024-ai-transparency-act-watermarking"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-sb942-2024-ai-transparency-act-watermarking",
    "title": "California SB 942 (2024) - California AI Transparency Act (Watermarking, Disclosures and Detection)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "California Senate Bill 942 (Becker) - the California AI Transparency Act - obligates a 'covered provider' of a generative AI system with over 1,000,000 monthly visitors or users that is publicly accessible within California to: (1) make available at no cost a publicly accessible AI detection tool that allows users to verify whether image, video, or audio content was created or modified by the provider's GenAI system and to retrieve embedded system provenance data without disclosing personal information about the user; (2) offer an option to apply a clear and conspicuous manifest disclosure (visible label) on AI-generated images, video, or audio; (3) embed a latent (hidden) disclosure conveying provider name, GenAI system name and version, creation timestamp, and a unique identifier to the extent technically feasible; and (4) maintain license-management duties requiring licensees of the GenAI system to maintain the disclosure capability, with licence revocation within 96 hours of becoming aware of disabling modifications. The Act adds Chapter 25 (commencing with Section 22757) to Division 8 of the California Business and Professions Code. Civil penalties of 5,000 dollars per violation apply, with each day of continuing violation constituting a separate violation. Effective 1 January 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "c2pa-content-provenance",
      "us-ca-ab2013-2024-genai-training-data-transparency",
      "eu-ai-act-article-50-transparency-obligations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ca-sb942-ai-transparency-act-2024",
    "title": "California Senate Bill 942 - California AI Transparency Act (Chapter 25, commencing with Section 22757, of Division 8 of the Business and Professions Code) - Operative 1 January 2026",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-09-19",
    "bluf": "California Senate Bill 942, the 'California AI Transparency Act,' adds Chapter 25 (commencing with Section 22757) to Division 8 of the Business and Professions Code and becomes operative on 1 January 2026. The Act regulates 'covered providers' - defined in Section 22757.1(b) as persons that create, code or otherwise produce a generative artificial intelligence (GenAI) system that has over 1,000,000 monthly visitors or users and is publicly accessible within the geographic boundaries of California. The Act imposes three core obligations on covered providers: (1) Make available, at no cost to the user, an AI detection tool that allows assessment of whether image, video or audio content was created or altered by the covered provider's GenAI system; outputs any system provenance data detected; allows upload of content or a URL link; and supports an application programming interface so a user can invoke the tool without visiting the covered provider's website (Section 22757.2). The detection tool must collect user feedback and incorporate relevant feedback into improvements; covered providers shall not collect or retain personal information from users of the detection tool except contact information for users who opt in to feedback follow-up, and shall not retain submitted content longer than necessary or retain personal provenance data from submitted content. (2) Offer the user the option to include a manifest disclosure in AI-generated image, video or audio content that identifies the content as AI-generated and is clear, conspicuous, appropriate to the medium and understandable to a reasonable person; and include a latent disclosure in such content conveying - to the extent technically feasible and reasonable, directly or via a link to a permanent internet website - the name of the covered provider, the name and version number of the GenAI system that created or altered the content, time and date of generation, a unique identifier traceable to the covered provider, and that is detectable by the covered provider's AI detection tool and consistent with widely accepted industry standards (Section 22757.3(a)-(b)). (3) When the covered provider licenses its GenAI system to a third party, require by contract that the licensee maintain the system's disclosure capability; revoke the license within 96 hours of discovering that the licensee modified the system such that it is no longer capable of including the latent disclosure; and the third-party licensee shall cease using the licensed system after revocation (Section 22757.3(c)). Civil penalty: USD 5,000 per violation, with each day of violation deemed a discrete violation; the Attorney General, a city attorney or a county counsel may bring the civil action; prevailing plaintiff is entitled to reasonable attorney's costs and fees (Section 22757.4). For a third-party licensee's failure to cease use after revocation, the AG/city/county counsel may seek injunctive relief and reasonable attorney's fees and costs. The Act does not apply to any product, service, internet website or application that provides exclusively non-user-generated video game, television, streaming, movie or interactive experiences. Personal information has the same meaning as Section 1798.140 of the Civil Code (CCPA/CPRA cross-reference).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ccpa_cpra",
        "eu_ai_act_gpai",
        "c2pa_content_authenticity",
        "us_state_ai_landscape"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ccpa-cpra",
      "us-ca-sb53-frontier-ai",
      "us-colorado-ai-act-sb24-205"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-ca-sopipa-bpc-22584-student-online-privacy",
    "title": "California Student Online Personal Information Protection Act (SOPIPA), Business & Professions Code 22584",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "SOPIPA at California Business & Professions Code Section 22584 governs operators of K-12 websites, online services, and applications that handle pupil covered information. Section 22584(b)(1) prohibits targeted advertising based on pupil data, Section 22584(b)(2) bars amassing a pupil profile except in furtherance of K-12 school purposes, and Section 22584(b)(3) prohibits selling a pupil's information. Section 22584(d) requires operators to maintain reasonable security procedures and to delete covered information when the school or local educational agency requests deletion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-34-cfr-part-99-ferpa-student-records",
      "us-coppa-16-cfr-part-312-edtech-school-operators"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-caatsa-pl-115-44-2017",
    "title": "United States Countering America's Adversaries Through Sanctions Act (CAATSA) (Public Law 115-44, 2017): Title I - Iran Sanctions, Title II - Russia Sanctions and Codification, Title III - Korean Interdiction and Modernization of Sanctions Act, Section 224 Russia Cybersecurity Sanctions, Section 228 Mandatory Secondary Sanctions, and Section 231 Russian Defense and Intelligence Sectors",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Countering America's Adversaries Through Sanctions Act, Public Law 115-44 of 2 August 2017, is the principal United States statute consolidating, expanding, and codifying United States sanctions against the Russian Federation, the Islamic Republic of Iran, and the Democratic People's Republic of Korea, and is administered by the Office of Foreign Assets Control in the Department of the Treasury and the Department of State. CAATSA, Title I addresses sanctions targeting Iran's destabilizing activities, ballistic missile programs, and support for terrorism. CAATSA, section 104 imposes sanctions on persons materially contributing to Iran's ballistic missile development or weapons delivery systems. CAATSA, section 105 establishes terrorism-related sanctions applicable to Iran's Islamic Revolutionary Guard Corps. CAATSA, Title II codifies sanctions related to the Russian Federation imposed by previous Presidential Executive orders and adds new Russia-related authorities. CAATSA, section 224 mandates sanctions against entities undermining cybersecurity on behalf of the Russian Federation. CAATSA, section 225 requires Presidential sanctions concerning Russian crude oil projects. CAATSA, section 228 establishes mandatory sanctions targeting foreign persons facilitating significant transactions with sanctioned Russian entities or their family members. CAATSA, section 231 imposes mandatory sanctions on persons engaging in significant transactions with persons that are part of, or operate for or on behalf of, the defense or intelligence sectors of the Government of the Russian Federation. CAATSA, Title III contains the Korean Interdiction and Modernization of Sanctions Act creating enforcement mechanisms for United Nations Security Council sanctions against North Korea including designation procedures and shipping compliance measures. The Act is the controlling federal instrument for codified United States Russia, Iran, and North Korea sanctions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cable-communications-policy-act",
    "title": "US Cable Communications Policy Act (47 USC ch 5 subch V-A): Franchising, Franchise Fees and Subscriber Privacy",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Cable Communications Policy Act of 1984 (47 U.S.C. ch. 5, subchapter V-A) established the federal framework for the regulation of cable television systems and the relationship between cable operators and local franchising authorities, administered by the Federal Communications Commission alongside local authorities. Section 521 states the purposes, including establishing a national policy for cable communications and a franchise process. Section 522 supplies the definitions, including cable operator and cable system. Section 531 authorizes a franchising authority to require channel capacity for public, educational or governmental (PEG) use, and section 532 provides for commercial leased-access channels. Section 541 sets the general franchise requirements, including that a cable operator generally needs a franchise to provide service and limits on exclusive franchises. Section 542 limits franchise fees to no more than 5 percent of the operator's gross revenues from the cable service. Section 543 governs the regulation of rates. Section 551 protects subscriber privacy, restricting the collection and disclosure of personally identifiable information about subscribers, and section 552 addresses consumer protection and customer-service standards. The Act is the legal foundation of US cable franchising, the franchise-fee cap, and cable-subscriber privacy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cafe-fuel-economy-standards-2024",
    "title": "Corporate Average Fuel Economy (CAFE) Standards for Model Years 2024-2031 - Fleet Average Targets, Compliance Credits, Civil Penalties, Footprint-Based Standards and Manufacturer Compliance Flexibility",
    "domain": "Automotive & Mobility",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "This regulation establishes fleet-wide fuel economy targets for passenger cars and light trucks manufactured for sale in the United States from model years 2024 to 2031, calculated using a footprint-based formula. It applies to all manufacturers producing or importing more than 10,000 vehicles annually and mandates compliance through annual reporting, credit trading, and potential civil penalties under 49 U.S.C. § 32908.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-automated-vehicles-comprehensive-plan-2021",
      "iso-26262-functional-safety-road-vehicles-2018",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cafe-standards-49-cfr-531-533-corporate-average-fuel-economy",
    "title": "US CAFE Standards 49 CFR Parts 531/533 - Corporate Average Fuel Economy Compliance",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2024-03-20",
    "bluf": "NHTSA Corporate Average Fuel Economy standards (49 CFR Parts 531/533) require automobile manufacturers to meet fleet-average fuel economy targets (MPG) for passenger cars and light trucks, with civil penalties for non-compliance and flexibility mechanisms including trading and banking of CAFE credits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-air-act-42-usc-7401-findings-purposes-air-quality",
      "us-nepa-1970-environmental-impact-assessment"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cafe-standards-light-duty-vehicles",
    "title": "Corporate Average Fuel Economy (CAFE) Standards for Passenger Cars and Light Trucks",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Corporate Average Fuel Economy (CAFE) standards, administered by the National Highway Traffic Safety Administration (NHTSA) under 49 U.S.C. Chapter 329, require automotive manufacturers to meet fleet-wide average fuel economy targets for new passenger cars and light trucks sold in the U.S. Failure to meet these annually-set targets results in civil penalties for each tenth of a mile per gallon the manufacturer's fleet falls short.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-cafra-2000-civil-asset-forfeiture-reform-pl-106-185",
    "title": "US Civil Asset Forfeiture Reform Act of 2000 (Public Law 106-185) - Federal Civil Forfeiture Procedure",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Civil Asset Forfeiture Reform Act of 2000 substantially restructured federal civil forfeiture procedure by shifting the burden of proof from the property owner to the government under a preponderance of the evidence standard, providing an innocent owner defense codified at 18 USC 983, authorising the appointment of counsel for indigent owners in certain cases, requiring the government to file a complaint for forfeiture within ninety days after a claim is filed, allowing release of seized property during pendency on a showing of substantial hardship, and creating expanded remedies for owners whose property was wrongly seized.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-rico-organized-crime-control-act-18-usc-1961",
      "us-money-laundering-control-act-18-usc-1956"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-caisi-center-ai-standards-innovation-2025",
    "title": "United States Center for AI Standards and Innovation (CAISI) - Successor to the US AI Safety Institute (AISI) at NIST; Industry Primary Contact for Federal AI Testing, Voluntary Standards, National Security AI Capability Evaluations, and US International AI Standards Leadership (Trump Administration Reorganization, 2025)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2025-06-03",
    "bluf": "The Center for AI Standards and Innovation (CAISI) is the successor entity to the US AI Safety Institute (AISI) at NIST, established under the Trump administration's AI policy reorganization. CAISI serves as industry's primary point of contact within the US government to facilitate testing and collaborative research related to harnessing and securing the potential of commercial AI systems. CAISI's mandate is materially different from its predecessor AISI: where AISI focused on AI safety evaluations and pre-deployment testing of frontier models, CAISI emphasises national-security capability evaluations of US and adversary AI systems, US international AI standards leadership, and protection against foreign regulatory capture of US AI technology. CAISI's specific functions, as articulated on the NIST CAISI page, include: (1) working with NIST organizations to develop guidelines and best practices to measure and improve the security of AI systems, and assisting industry to develop voluntary standards; (2) establishing voluntary agreements with private-sector AI developers and evaluators, and leading unclassified evaluations of AI capabilities that may pose risks to national security - focusing on demonstrable risks such as cybersecurity, biosecurity, and chemical weapons; (3) leading evaluations and assessments of capabilities of US and adversary AI systems, the adoption of foreign AI systems, and the state of international AI competition; (4) leading evaluations and assessments of potential security vulnerabilities and malign foreign influence arising from use of adversaries' AI systems, including the possibility of backdoors and other covert, malicious behavior; (5) coordinating with other federal agencies and entities - including the Department of Defense, the Department of Energy, the Department of Homeland Security, the Office of Science and Technology Policy, and the Intelligence Community - to develop evaluation methods and conduct evaluations and assessments; and (6) representing US interests internationally to guard against burdensome and unnecessary regulation of American technologies by foreign governments, and collaborating with NIST staff to ensure US dominance of international AI standards. CAISI is operationalising its mandate through CRADAs (e.g., with OpenMined), MOUs (e.g., with the General Services Administration to support AI evaluation at the federal-procurement stage for USAi), and the publication of NIST AI 800-series technical reports including NIST AI 800-3 (statistical validity of LLM evaluations) and NIST AI 800-4 (post-deployment AI practices). General inquiries: usaisi@nist.gov.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us-ai-safety-institute-nist-2024",
        "uk-aisi-ai-safety-evaluation-framework-2024",
        "us-eo-14179-ai-2025",
        "us-nist-ai-rmf-1-0",
        "us-nist-sp-800-218a-secure-ai-development",
        "anthropic-responsible-scaling-policy-v2-1-2025",
        "google-deepmind-frontier-safety-framework-v2-2025"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ai-safety-institute-nist-2024"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "us-calea-communications-assistance-law-enforcement",
    "title": "Communications Assistance for Law Enforcement Act (CALEA) - Carrier Technical Capability Obligations",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Communications Assistance for Law Enforcement Act (CALEA) requires telecommunications carriers to design and modify their networks and services to ensure they have the built-in capability to comply with authorized electronic surveillance requests from law enforcement agencies, as mandated by 47 U.S.C. § 1002.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-california-ab-1949-2024-childrens-data-privacy",
    "title": "California AB 1949 (2024) - CCPA Amendments for Consumers Under 18 (Children's Data Privacy)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "California AB 1949 (chaptered September 2024) amends the California Consumer Privacy Act to strengthen protections for personal information of consumers under 18. The Act amends Civil Code Section 1798.100 to prohibit a business from collecting personal information of a consumer under 18 without affirmative consent when the business has actual knowledge of the consumer's age. Section 1798.120 is amended to prohibit selling or sharing personal information of consumers under 18 without consent. Section 1798.121 prohibits using or disclosing sensitive personal information of minors without affirmative consent. New Section 1798.139 requires a business to treat a consumer as under 18 when the consumer transmits a signal indicating that the consumer is less than 18 years of age. Consent flows are tiered: consumers 13-17 give personal consent; consumers under 13 require parental or guardian consent. The willful-disregard standard triggers the actual-knowledge presumption (a business cannot insulate itself by ignoring age signals it could reasonably detect).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ccpa_anchor",
        "ca_sb_976_parallel",
        "coppa_overlap",
        "gdpr_article_8_overlap",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-childrens-online-privacy-protection-act"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-california-caadca-age-appropriate-design-2022",
    "title": "California Age-Appropriate Design Code Act (CAADCA) - Data Protection Impact Assessments for Services Likely to be Accessed by Children",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The California Age-Appropriate Design Code Act (CAADCA) requires businesses providing online services likely to be accessed by children to complete, review, and document a Data Protection Impact Assessment (DPIA) before offering any new online services, products, or features, as mandated by Civil Code Section 1798.99.31(b). This DPIA must identify and mitigate risks of material detriment to children arising from data management practices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-35-dpia",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-california-sb-942-ai-transparency-act-2024",
    "title": "California SB 942 - California AI Transparency Act (Bus. & Prof. Code §§ 22757-22757.6)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-09-19",
    "bluf": "Covered generative AI providers with over 1,000,000 monthly users or visitors must offer a free AI detection tool, embed a latent provenance disclosure in AI-generated image, video, or audio content, offer users the option to apply a manifest disclosure, and revoke any third-party license within 96 hours upon discovering that disclosure features have been modified or disabled, with effect from January 1, 2026 and civil penalties of $5,000 per day per violation enforceable by the Attorney General, a city attorney, or a county counsel.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "c2pa-content-provenance",
      "eu-ai-act-article-50-gpai-transparency"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-california-sb-976-2024-social-media-addiction-kids",
    "title": "California SB 976 (2024) - Protecting Our Kids from Social Media Addiction Act",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "California SB 976 (chaptered September 20 2024) adds Chapter 24 (Sections 27000-27007) to Division 20 of the California Health and Safety Code creating the Protecting Our Kids from Social Media Addiction Act. The Act regulates operators of addictive internet-based services or applications used by minors. An addictive feed is defined as a service feature where multiple pieces of media generated or shared by users are recommended selected or prioritized for display to a user based in whole or in part on information provided by the user or the user's device. Operators must implement default settings for minor accounts including restriction of access between midnight and 6 a.m. limitation of daily usage to one hour hiding of engagement metrics like likes private-by-default accounts and availability of chronological-only feeds. Verifiable parental consent or reasonable age verification is required by January 1 2027 before serving addictive feeds to minors. The Attorney General is the sole enforcement authority via civil action; there is no private right of action. Parts take effect immediately upon enactment with the age-verification mandate phased to January 1 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ny_safe_for_kids_parallel",
        "ca_aadca_parallel",
        "netchoice_v_bonta_litigation",
        "kosa_federal_floor",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-california-caadca-age-appropriate-design-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-california-sgma-2014-sustainable-groundwater-management",
    "title": "California Sustainable Groundwater Management Act (SGMA) 2014",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2014-09-16",
    "bluf": "The California Sustainable Groundwater Management Act (SGMA) was signed into law on 16 September 2014 as the first comprehensive framework for sustainable groundwater management in California. SGMA is codified principally in the California Water Code Division 6 Part 2.74 (sections 10720 through 10737.8) and is administered by the California Department of Water Resources (DWR) with backstop authority by the State Water Resources Control Board (SWRCB). SGMA covers approximately 515 groundwater basins and subbasins prioritised by DWR with the highest-priority basins required to develop Groundwater Sustainability Plans (GSPs) by 2020 (high and medium priority) or 2022 (subbasins in critical overdraft) and to achieve sustainability by 2040 or 2042 depending on prioritisation.\n\nLocal Groundwater Sustainability Agencies (GSAs) are designated by local public agencies to develop and implement GSPs that avoid six undesirable results: chronic lowering of groundwater levels; significant and unreasonable reduction of groundwater storage; significant and unreasonable seawater intrusion; significant and unreasonable degraded water quality; significant and unreasonable land subsidence; and depletions of interconnected surface water that have significant and unreasonable adverse impacts on beneficial uses. GSPs must include sustainability goals, measurable objectives, minimum thresholds, monitoring networks, projects and management actions, and Annual Reporting. The SWRCB may exercise backstop authority where local agencies fail to perform under the Probationary Basin and State Intervention processes. Senate Bill 1281 (2014) requires reporting of water use by oil and gas producers within SGMA basins.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-can-spam-act",
    "title": "US CAN-SPAM Act (15 USC ch 103): Commercial Email Requirements",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Controlling the Assault of Non-Solicited Pornography And Marketing Act, CAN-SPAM (15 U.S.C. ch. 103), sets national requirements for commercial electronic mail, enforced primarily by the Federal Trade Commission with the Department of Justice for criminal matters and other agencies and State attorneys general. Section 7701 sets the findings and policy. Section 7702 provides the definitions, including commercial electronic mail message and transactional or relationship message. Section 7704 sets the protections for users of commercial electronic mail: a sender may not use header information that is materially false or materially misleading, may not use a subject heading likely to mislead a recipient about a material fact regarding the contents or subject matter, must include a clear and conspicuous functioning return address or other mechanism allowing the recipient to opt out of future messages and must honor an opt-out request within ten business days, must clearly and conspicuously identify the message as an advertisement or solicitation, and must include a valid physical postal address of the sender. Section 7706 provides for enforcement by the Commission as an unfair or deceptive act or practice and by other authorities, and section 7707 addresses the effect on other laws, including preemption of inconsistent State email statutes other than those prohibiting falsity or deception. The Act is the legal foundation for US commercial email compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-can-spam-act-2003",
    "title": "Controlling the Assault of Non-Solicited Pornography And Marketing Act of 2003 (CAN-SPAM Act)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The CAN-SPAM Act establishes national standards for sending commercial email, requiring clear sender identification, truthful subject lines, a physical postal address, and a conspicuous, functional opt-out mechanism that must be honored within 10 business days, as mandated by 15 U.S.C. § 7704.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "casl-anti-spam-canada",
      "gdpr-art-21-marketing-optout",
      "eprivacy-cookie-directive",
      "ftc-endorsement-guides"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-can-spam-act-2003-commercial-email-operations",
    "title": "Controlling the Assault of Non-Solicited Pornography And Marketing (CAN-SPAM) Act of 2003 - Commercial Email Operations",
    "domain": "Operations & CX",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The CAN-SPAM Act sets national standards for sending commercial emails, requiring truthful header information, clear identification of ads, a functioning opt-out mechanism, and inclusion of a valid physical postal address. It applies to any person or entity sending commercial messages to recipients in the United States, with violations subject to penalties of up to $50,117 per non-compliant email under 15 U.S.C. § 7704(a)(4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-unfair-commercial-practices-directive",
      "ftc-ai-enforcement-guidance",
      "sec-cybersecurity-risk-incident-disclosure"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-can-spam-act-2003-commercial-email-requirements",
    "title": "US CAN-SPAM Act 2003 - Commercial Email Identification, Opt-Out, and Sender Requirements",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The CAN-SPAM Act of 2003 (15 U.S.C. § 7701) sets requirements for commercial electronic mail messages in interstate commerce: prohibition on deceptive headers and subject lines, mandatory physical postal address disclosure, a clear opt-out mechanism that must be honoured within 10 business days, and civil penalties up to $51,744 per violation enforced by the FTC, state attorneys general, and internet service providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-15-usc-45-unfair-deceptive-practices"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-can-spam-act-2003-implementation",
    "title": "US CAN-SPAM Act 2003 - Commercial Email Requirements: No Deceptive Headers, Honest Subject Lines, Opt-Out Mechanism (10-Day Processing), Sender Identification, Transactional Email Exemptions, Civil Penalties up to $53,088/Violation and State Law Pre-emption",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The CAN-SPAM Act requires all commercial email messages to include accurate header information, non-deceptive subject lines, clear identification as an advertisement, a valid physical postal address, and a functional opt-out mechanism that must be honored within 10 business days. The law applies to all commercial messages, regardless of sender or recipient type, and each violation is subject to penalties of up to $53,088.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-digital-advertising-disclosures",
      "can-spam-act-email"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-canada-great-lakes-water-quality-agreement-2012",
    "title": "US-Canada Great Lakes Water Quality Agreement 2012 Protocol - Binational Lakewide Action Plans, Areas of Concern and Chemicals of Mutual Concern",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Great Lakes Water Quality Agreement (GLWQA) between the United States and Canada, originally signed 15 April 1972 and subsequently amended in 1978, 1987 (Protocol) and 7 September 2012, is the principal binational framework for restoring and protecting the chemical, physical and biological integrity of the Waters of the Great Lakes. The 2012 amended Protocol entered into force 12 February 2013 and reorganises commitments into 10 Annexes addressing: 1 Areas of Concern, 2 Lakewide Management, 3 Chemicals of Mutual Concern, 4 Nutrients, 5 Discharges from Vessels, 6 Aquatic Invasive Species, 7 Habitat and Species, 8 Groundwater, 9 Climate Change Impacts, and 10 Science. The Agreement is implemented in the United States under the authority of the Federal Water Pollution Control Act (Clean Water Act) and the Great Lakes Restoration Initiative (GLRI, authorised through annual appropriations since 2010 with USD 4+ billion total). The lead US implementing agency is the US Environmental Protection Agency (EPA) Great Lakes National Program Office (GLNPO); the lead Canadian agency is Environment and Climate Change Canada (ECCC). The International Joint Commission (IJC), established under the 1909 Boundary Waters Treaty, provides independent assessment and reports biennially through the Triennial Assessment of Progress (TAP). The Great Lakes contain approximately 20% of the world's surface freshwater and provide drinking water for 40+ million people.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-capper-volstead-act",
    "title": "US Capper-Volstead Act (7 USC ch 12): Antitrust Exemption for Agricultural Cooperative Associations",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Capper-Volstead Act of 1922 (7 U.S.C. ch. 12, sections 291 and 292) gives a limited antitrust exemption to associations of agricultural producers, administered by the Secretary of Agriculture. Section 291 authorizes persons engaged in the production of agricultural products to act together in associations, corporate or otherwise, with or without capital stock, in collectively processing, preparing for market, handling, and marketing those products in interstate and foreign commerce. The exemption applies only if the association is operated for the mutual benefit of its members and conforms to one of two governance conditions: either no member is allowed more than one vote regardless of the amount of stock held, or the association does not pay dividends on stock or membership capital in excess of 8 per centum per annum. In addition, the association may not deal in the products of nonmembers to an amount greater in value than the products it handles for its own members. Section 292 makes clear the exemption is not a shield for abuse: if the Secretary of Agriculture has reason to believe that an association monopolizes or restrains trade in interstate or foreign commerce to such an extent that the price of any agricultural product is unduly enhanced, the Secretary must issue a complaint, hold a hearing on notice, and may issue an order to cease and desist, enforceable through the district court of the United States. Conduct that goes beyond the protected collective marketing functions remains subject to the Sherman and Clayton Acts. The Act is the legal foundation of the United States farmer cooperative system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-carl-perkins-cte-act",
    "title": "US Carl D. Perkins Career and Technical Education Act (20 U.S.C. Chapter 44): Federal Support for Career and Technical Education",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Carl D. Perkins Career and Technical Education Act, codified at 20 U.S.C. Chapter 44, is the principal federal statute providing financial support to develop the academic and technical skills of secondary and postsecondary students enrolled in career and technical education, administered by the Department of Education. Section 2301 sets the purpose: to develop more fully the academic knowledge and technical and employability skills of students who elect career and technical education, including preparation for high-skill, high-wage, or in-demand occupations. Section 2302 sets the definitions used throughout the chapter, including career and technical education and special populations. Section 2321 governs the reservations and the State allotment formula by which federal funds are distributed to the States. Section 2322 governs the within-State allocation between secondary and postsecondary programs. Section 2342 requires each State to submit a State plan describing how it will use the funds and meet the Act's requirements. Section 2343 governs improvement plans where a State or recipient fails to meet performance levels. Section 2354 requires each eligible recipient to submit a local application for career and technical education programs. Section 2355 specifies the permissible local uses of funds. The Act conditions federal funding on accountability for performance against State-determined levels. The Act is the foundational statute for federally supported career and technical education in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ccpa-cpra-2023-marketing-rights",
    "title": "US CPRA 2023 - California Consumer Privacy Rights: Right to Opt Out of Sale/Sharing (Including Cross-Context Behavioural Advertising), Right to Limit Sensitive Personal Information, Data Minimisation for Marketing, CPPA Enforcement and Regulations",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires businesses that process personal information of California residents to provide a clear and accessible mechanism for consumers to opt out of the sale or sharing of their personal information, including for cross-context behavioral advertising, and to limit the use of sensitive personal information. Compliance is mandated under the California Consumer Privacy Act as amended by Proposition 24, enforced by the California Privacy Protection Agency (CPPA), with key obligations found in the CCPA Regulations effective January 1, 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ccpa-cpra-optout-sale",
      "can-spam-act-email",
      "eprivacy-cookie-directive",
      "ftc-digital-advertising-disclosures"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ccpa-cpra-cal-civ-code-1798-consumer-privacy-rights",
    "title": "US California Consumer Privacy Act (CCPA/CPRA) - Consumer Data Rights and Business Obligations",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The California Consumer Privacy Act (CCPA, 2018) as amended by the California Privacy Rights Act (CPRA, 2020, enforceable July 2023) grants California consumers rights to know, delete, opt-out of sale/sharing, correct, and limit use of sensitive personal information, establishes the California Privacy Protection Agency (CPPA) as enforcement authority, requires a privacy policy and opt-out mechanism, applies to businesses above size thresholds, and imposes civil penalties up to $7,500 per intentional violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-15-usc-45-unfair-deceptive-practices"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cdc-nih-bmbl-6th-edition-biosafety-microbiological-biomedical-laboratories-2025",
    "title": "CDC/NIH Biosafety in Microbiological and Biomedical Laboratories (BMBL) - 6th Edition (2025)",
    "domain": "Biotech & Genomics",
    "version": "6.0.0",
    "last_updated": "2025-08-29",
    "bluf": "Laboratory operators handling potentially hazardous biological agents and toxins should run a comprehensive, continually-updated biosafety risk assessment under Section II of BMBL, select the appropriate Biosafety Level (BSL-1 through BSL-4) and Animal Biosafety Level (ABSL-1 through ABSL-4) based on agent virulence, transmission route, and procedure aerosol potential, implement the combination of standard microbiological practices, primary barriers (biological safety cabinets, sealed containers, PPE), secondary barriers (facility design and engineering controls including HEPA filtration, anterooms, airlocks, controlled access), and facility practices and procedures specified for that BSL or ABSL, layer on the Section VI laboratory biosecurity controls, and implement the Section VII occupational health and immunoprophylaxis programme - documenting the entire risk-based justification so it can be reviewed on an ongoing basis as conditions change.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "who-laboratory-biosafety-manual-4th-edition",
      "us-select-agent-program-42-cfr-73"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-cercla-brownfields-construction",
    "title": "US CERCLA Brownfields Programme - Contaminated Land Redevelopment: Innocent Landowner Defence, Bona Fide Prospective Purchaser Protections, Assessment and Cleanup Grant Requirements",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation enables communities, states, tribes, and other entities to assess, clean up, and sustainably reuse contaminated or potentially contaminated properties through EPA Brownfields grants and technical assistance. Key provisions include eligibility for funding under the Brownfields Program, including job training grants, to support environmental remediation and redevelopment under CERCLA protections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-section-404-construction",
      "iso-19650-bim-information-management-construction",
      "icc-700-national-green-building-standard-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cercla-superfund",
    "title": "US CERCLA / Superfund (42 USC ch 103): Release Reporting, Response Authority and Strict Liability",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Comprehensive Environmental Response, Compensation, and Liability Act (CERCLA, the Superfund law), codified at 42 U.S.C. Chapter 103 (sections 9601-9675), provides federal authority to respond to releases of hazardous substances and imposes liability for the costs of cleanup, administered by the US Environmental Protection Agency (EPA). Section 9601 defines the regulated terms, including 'hazardous substance', 'facility', 'release' and 'response'. Section 9603 imposes the release-reporting duty: a person in charge of a vessel or facility, as soon as he has knowledge of a release of a hazardous substance in a quantity equal to or greater than the reportable quantity, must immediately notify the National Response Center, and a person who fails to notify, or who submits false information, is, on conviction, fined in accordance with title 18 or imprisoned for not more than three years (not more than five years for a second or subsequent conviction), or both. Section 9604 confers the President's (delegated to EPA) response authority to undertake removal and remedial action, section 9605 provides for the National Contingency Plan and the National Priorities List, and section 9606 authorizes abatement actions to address an imminent and substantial endangerment. Section 9607 sets the liability scheme: the owner and operator of a facility, any person who at the time of disposal owned or operated the facility, any person who arranged for disposal or treatment, and any person who accepted hazardous substances for transport to the site are each liable for removal and remedial costs, other necessary response costs, and damages for injury to, destruction of, or loss of natural resources; courts have construed this liability as strict and, in appropriate cases, joint and several. Section 9613 governs civil proceedings and contribution, and section 9622 governs settlements. Section 9609 sets civil penalties, including Class I administrative penalties of not more than $25,000 per violation, Class II administrative penalties of not more than $25,000 per day (not more than $75,000 per day for subsequent violations), and judicial civil penalties of not more than $25,000 per day per violation. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cfius-defense-production-act-50-usc-4565",
    "title": "CFIUS - 50 USC 4565 Defense Production Act Section 721 Foreign Investment Review",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 4565 of title 50 of the United States Code codifies section 721 of the Defense Production Act of 1950 as substantially amended by the Foreign Investment and National Security Act of 2007 (FINSA, Public Law 110-49) and the Foreign Investment Risk Review Modernization Act of 2018 (FIRRMA, Public Law 115-232 Subtitle A of Title XVII), establishing the Committee on Foreign Investment in the United States (CFIUS) and the framework for reviewing covered transactions involving foreign persons that could affect US national security. Covered transactions include any merger, acquisition, or takeover by a foreign person that could result in foreign control of any United States business, certain non-controlling investments in US businesses involved in critical technologies, critical infrastructure, or sensitive personal data (TID US businesses), real estate transactions near sensitive US government facilities, and any change in foreign person rights with respect to a US business that could result in foreign control. The CFIUS review timeline allows a 45-day initial review and an extendable 45-day investigation. Mandatory declarations are required for certain transactions involving foreign-government-controlled investors and TID US businesses involving critical technologies subject to specified export controls. Following review, CFIUS may impose mitigation measures or recommend presidential action under section 4565(d) to suspend or prohibit a transaction if there is credible evidence of a national security threat. The framework reaches AI semiconductor, advanced biotechnology, quantum computing, and large-language-model investments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-arms-export-control-act",
      "uk-national-security-investment-act-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cfpb-1033-personal-financial-data-rights-2024",
    "title": "CFPB Personal Financial Data Rights Final Rule - 12 CFR Part 1033 (Section 1033 of CFPA)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-30",
    "bluf": "The CFPB's Personal Financial Data Rights final rule (12 CFR Part 1033) implements Section 1033 of the Consumer Financial Protection Act and obliges depository and nondepository data providers to make covered consumer data (Section 1033.211) available free of charge to consumers and authorised third parties through standardised consumer and developer interfaces (Section 1033.301). Coverage threshold for depository institutions is the SBA size standard (Section 1033.111(d) - currently $850 million). Compliance is staggered into five tiers (Section 1033.121(b)): Tier 1 - at least $250 billion total assets or nondepository receipts of $10 billion+ (calendar year 2023 or 2024) by 1 April 2026; Tier 2 - $10 billion to $250 billion or nondepository <$10 billion by 1 April 2027; Tier 3 - $3 billion to $10 billion by 1 April 2028; Tier 4 - $1.5 billion to $3 billion by 1 April 2029; Tier 5 - $850 million to $1.5 billion by 1 April 2030. Developer interfaces must achieve a 99.5% response rate (Section 1033.311(c)(1)). Authorisation procedures (Section 1033.401) require informed consumer consent, third-party use limitations, easy revocation, default data deletion, and a maximum one-year retention without reauthorisation. \"Bait-and-switch\" use of authorised data for unrelated purposes is prohibited.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_psd2_open_banking_api_standards",
        "uk_open_banking_cma_order",
        "saudi_sama_open_banking_policy_2022",
        "gdpr_article_20_data_portability",
        "us_eo_14178_digital_financial_tech_2025"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-glba-gramm-leach-bliley-act-1999",
      "us-fair-credit-reporting-act-fcra-1970",
      "eu-psd2-open-banking-api-standards",
      "saudi-sama-open-banking-policy-2022"
    ],
    "primary_citations_count": 15
  },
  {
    "node_id": "us-cfpb-12-cfr-1002-regulation-b-equal-credit-opportunity",
    "title": "12 CFR Part 1002 - Equal Credit Opportunity Act (Regulation B)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "CFPB Regulation B implements the Equal Credit Opportunity Act, prohibiting creditors from discriminating against an applicant on a prohibited basis in any aspect of a credit transaction, restricting the information a creditor may request, requiring notification of action taken with a statement of specific reasons for adverse action, requiring monitoring information for dwelling-secured applications, mandating that applicants receive copies of appraisals, and requiring retention of records.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-equal-credit-opportunity-act-ecoa-1974"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cfpb-12-cfr-1005-reg-e-electronic-fund-transfers",
    "title": "US CFPB Regulation E - 12 CFR Part 1005 Electronic Fund Transfer Act Disclosure, Error Resolution, Unauthorized Transfer Liability and Remittance Transfer Obligations",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Regulation E at 12 CFR Part 1005 is issued by the CFPB to implement the Electronic Fund Transfer Act (EFTA), 15 U.S.C. 1693 et seq. The regulation protects individual consumers engaging in electronic fund transfers and remittance transfers and applies to financial institutions and, in limited circumstances, to persons other than the account-holding financial institution. Section 1005.3 sets the coverage and exclusions, including the conditional exemption for small institutions and certain securities, futures, and trust transactions. Section 1005.5 governs the issuance of access devices and prohibits issuing an unsolicited access device unless it is unvalidated. Section 1005.6 limits consumer liability for unauthorized EFTs to USD 50 if the consumer notifies the institution within two business days, increased to USD 500 if notice is later but within 60 days. Section 1005.7 requires initial disclosures at the time the consumer contracts for the EFT service or before the first transfer. Section 1005.8 requires written notice at least 21 days before the effective date of any change in a 1005.7(b) term that adversely affects the consumer. Section 1005.9 governs receipts at electronic terminals and periodic statements. Section 1005.10 governs preauthorized transfers including the 10-day stop-payment right. Section 1005.11 sets out the error resolution procedures with 10-business-day investigation and provisional credit obligations. Section 1005.13 requires record retention for two years after the date disclosures are required to be made. Subpart B covers remittance transfers including the prepayment and receipt disclosures and the consumer cancellation right.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-31-cfr-1010-fincen-aml-ctr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cfpb-12-cfr-1006-reg-f-fair-debt-collection-practices",
    "title": "US CFPB Regulation F - 12 CFR Part 1006 Fair Debt Collection Practices Act Communication, Validation Notice and Time-Barred Debt Obligations",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Regulation F at 12 CFR Part 1006 is issued by the CFPB to implement the Fair Debt Collection Practices Act (FDCPA), 15 U.S.C. 1692 et seq. The rule applies to debt collectors as defined in §1006.2(i), including entities collecting consumer debts owed to others and excluding most original creditors collecting their own debts. Section 1006.6 governs communications in connection with debt collection including the call-frequency presumption (no more than 7 calls within 7 consecutive days about a particular debt; no further call within 7 days after a telephone conversation about that debt). Section 1006.10 limits the content of location-information communications with third parties. Section 1006.14 prohibits harassing, oppressive, or abusive conduct including the call-frequency presumptions. Section 1006.18 prohibits false, deceptive, or misleading representations. Section 1006.22 prohibits unfair or unconscionable means including collecting amounts not authorized by the underlying contract or law. Section 1006.26 governs the collection of time-barred debts, prohibiting a legal action or threat thereof against a consumer for a time-barred debt. Section 1006.30(a) prohibits a debt collector from furnishing information about a debt to a consumer reporting agency before making contact with the consumer about the debt. Section 1006.34 requires the validation notice with prescribed content within 5 days of the initial communication. Section 1006.42 requires disclosures to be sent in a manner reasonably expected to provide actual notice. Section 1006.100 requires records evidencing compliance to be retained from the date collection activity begins until 3 years after the debt collector's last collection activity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-truth-in-lending-act-regulation-z"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cfpb-12-cfr-1013-reg-m-consumer-leasing",
    "title": "US CFPB Regulation M - 12 CFR Part 1013 Consumer Leasing Act Lease Disclosure, Advertising and Record Retention Obligations for Lessors",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Regulation M at 12 CFR Part 1013 is issued by the CFPB to implement the Consumer Leasing Act, which is Chapter 5 of the Truth in Lending Act (15 U.S.C. 1667 et seq.). The regulation applies to consumer leases as defined in §1013.2(e): a contract in the form of a bona fide lease or bailment for the use of personal property by a natural person primarily for personal, family, or household purposes for a period exceeding 4 months and for a total contractual obligation not exceeding the threshold set by the Bureau (currently USD 70,000 indexed annually). Section 1013.3 governs general disclosure requirements including form, language, and timing. Section 1013.4 specifies the 16 categories of content disclosures required for every consumer lease including the description of property, amount due at lease signing, payment schedule, official fees, residual value, purchase option, statement on early termination, maintenance responsibilities, warranty information, identification of insurance, security interest, late payment fees, option to purchase at end of lease, statement of the lessee's right to compare the cost of leasing, and the federal-box conspicuous summary of key terms. Section 1013.5 governs renegotiations, extensions, and assumptions and when new disclosures are required. Section 1013.7 prohibits misleading advertising and requires that any advertised lease term be one the lessor usually and customarily offers or will offer. Section 1013.8 requires record retention for at least 2 years after the date disclosures are required to be made. Enforcement of the Act and Regulation is shared between the CFPB and prudential regulators per the Consumer Leasing Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-truth-in-lending-act-regulation-z"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cfpb-12-cfr-1016-regulation-p-financial-privacy",
    "title": "12 CFR Part 1016 - Privacy of Consumer Financial Information (Regulation P) (CFPB)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "CFPB 12 CFR Part 1016 (Regulation P) implements the privacy provisions of the Gramm-Leach-Bliley Act, requiring a financial institution to provide an initial privacy notice to consumers and an annual privacy notice to customers, include the required content, offer a compliant opt out before sharing nonpublic personal information with nonaffiliated third parties, issue revised notices when sharing changes, deliver notices so consumers reasonably receive them, observe the limits on disclosure, redisclosure, and account-number sharing, apply the statutory exceptions only where their conditions are met, and address the Fair Credit Reporting Act and state-law relationships.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-glba-gramm-leach-bliley-act-1999"
    ],
    "primary_citations_count": 17
  },
  {
    "node_id": "us-cfpb-12-cfr-1024-respa-regulation-x-mortgage-servicing",
    "title": "12 CFR Part 1024 (Regulation X) - RESPA Settlement, Escrow and Mortgage Servicing Rules",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Regulation X (12 CFR Part 1024) implements the Real Estate Settlement Procedures Act (RESPA) and is administered by the Consumer Financial Protection Bureau. It applies to federally related mortgage loans and governs settlement-cost disclosures, prohibited practices, escrow accounts and mortgage servicing. No person may give or accept any fee, kickback or thing of value pursuant to an agreement to refer settlement-service business involving a federally related mortgage loan, and charges may not be split except for services actually performed; any violation is a violation of section 8 of RESPA (12 U.S.C. 2607). Affiliated business arrangements must be disclosed. A servicer that maintains an escrow account must conduct an escrow analysis, observe the account limits and provide an annual escrow account statement. The subpart C servicing rules require a servicer to acknowledge a borrower's written notice of error within five days and to investigate and respond, to respond to information requests, and, before assessing a force-placed insurance charge, to deliver a written notice at least 45 days beforehand and a reminder, and not impose the charge where the borrower has continuous hazard insurance. For delinquent borrowers, the servicer must establish or make good faith efforts to establish live contact no later than the 36th day of delinquency and provide a written early-intervention notice no later than the 45th day, maintain continuity of contact, and follow the loss mitigation procedures, exercising reasonable diligence to complete a loss mitigation application and evaluating a complete application for the loss mitigation options available.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "servicing_rules",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-respa-real-estate-settlement-procedures",
      "us-truth-in-lending-act-regulation-z",
      "us-cfpb-dodd-frank-title-x-consumer-financial-protection"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cfpb-12-cfr-1030-reg-dd-truth-in-savings",
    "title": "US CFPB Regulation DD - 12 CFR Part 1030 Truth in Savings Act Disclosure, Periodic Statement and Advertising Obligations for Depository Institutions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Regulation DD, codified at 12 CFR Part 1030, is issued by the Consumer Financial Protection Bureau to implement the Truth in Savings Act of 1991 (12 U.S.C. 4301 et seq., contained in the Federal Deposit Insurance Corporation Improvement Act of 1991, Public Law 102-242). The Act and regulation apply to depository institutions other than credit unions (which are subject to NCUA's parallel Part 707) and require uniform deposit account disclosures so consumers can make meaningful comparisons. Section 1030.4 requires account disclosures (rate, compounding, balance, fee, and minimum balance information) to be delivered before the account is opened or a service is provided, whichever is earlier. Section 1030.5 requires advance notice of any change in a disclosed term that may reduce annual percentage yield or adversely affect the consumer, with a minimum 30-day notice in most cases. Section 1030.6 governs periodic statement disclosures including the annual percentage yield earned (APYE), interest earned, fees imposed and length of the statement period. Section 1030.7 requires interest to be calculated on the full principal balance using either the daily balance method or the average daily balance method with the daily rate equal to 1/365 of the interest rate. Section 1030.8 prohibits misleading or inaccurate advertisements, including misuse of the words 'free' or 'no cost' when fees may apply. Section 1030.11 imposes additional periodic-statement and opt-in disclosure requirements for overdraft services. Section 1030.9 cross-references administrative enforcement and requires record retention for two years after the date disclosures are required to be made.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-truth-in-lending-act-regulation-z"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cfpb-12-cfr-1041-payday-vehicle-title-high-cost-installment-loans",
    "title": "US CFPB Payday Lending Rule - 12 CFR Part 1041 Payment Withdrawal Restrictions, Consumer Notice Obligations and Compliance Program for Covered Short-Term and Vehicle-Title Loans",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "The Payday, Vehicle Title, and Certain High-Cost Installment Loans rule at 12 CFR Part 1041 is issued by the CFPB under Title X of the Dodd-Frank Wall Street Reform and Consumer Protection Act (12 U.S.C. 5481 et seq.) to identify and prohibit certain unfair and abusive acts or practices in connection with covered short-term and longer-term loans. Section 1041.3 defines covered loans as closed-end or open-end credit extended primarily for personal, family, or household purposes that meets specified balloon-payment, term, or APR thresholds. Section 1041.7 identifies as an unfair and abusive practice a lender's attempt to withdraw payment from a consumer's account after two consecutive prior attempts have failed due to a lack of sufficient funds, without first obtaining a new and specific authorization. Section 1041.8 sets out the substantive prohibited-payment-transfer rules and defines payment transfer to include any lender-initiated debit, withdrawal, or single-entry presentment to collect any amount due in connection with a covered loan, by any payment channel including ACH, electronic fund transfer, signature check, remotely created check, account transfer, or other means. Section 1041.9 requires payment notices including the upcoming-payment notice and the consumer-rights notice, with specific timing and content. Section 1041.12 requires a written compliance program with policies and procedures appropriate to the size and complexity of the lender. Section 1041.13 prohibits any action taken with the intent of evading the rule. Records of compliance must be retained for at least 36 months after a covered loan ceases to be an outstanding loan per §1041.12(b).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-truth-in-lending-act-regulation-z"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cfpb-12-cfr-1090-larger-participants-of-consumer-financial-product-or-service-markets",
    "title": "US CFPB Larger Participant Rules - 12 CFR Part 1090 Supervisory Jurisdiction Over Nonbank Larger Participants in Defined Consumer Financial Markets",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "12 CFR Part 1090 defines nonbank covered persons that qualify as larger participants of certain markets for consumer financial products or services pursuant to 12 U.S.C. 5514(a)(1)(B) and (a)(2). A larger participant of a market covered by this part is subject to the supervisory authority of the CFPB under 12 U.S.C. 5514, including examination, recordkeeping, and reporting requirements. The five markets defined by subpart B of Part 1090 are: consumer reporting (§1090.104), consumer debt collection (§1090.105), student loan servicing (§1090.106), international money transfer (§1090.107), and automobile financing (§1090.108). Each market subpart sets a market-specific test (typically an annual receipts threshold or volume threshold) and defines the qualifying activities. Section 1090.102 provides that a person qualifying as a larger participant remains a larger participant until two years from the first day of the tax year in which the person last met the applicable test. Section 1090.103 provides the procedure for assessing larger-participant status, including the ability to respond within 45 days of a written communication initiating a supervisory activity by asserting that the person does not meet the larger-participant definition. Once supervised, a larger participant is subject to the same examination authorities as banks above the asset threshold, including risk-focused exams, examination reports, and authority to require additional records and reporting under 12 U.S.C. 5562.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cfpb-adverse-action-ai-2022",
    "title": "US CFPB - Adverse Action Notification Requirements for AI Credit Decisions (ECOA/FCRA Guidance 2022)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The US Consumer Financial Protection Bureau (CFPB) published guidance in May 2022 clarifying that the adverse action notification requirements under the Equal Credit Opportunity Act (ECOA) and Regulation B apply to credit decisions made using artificial intelligence and complex algorithmic models; key CFPB positions: (1) specificity requirement - ECOA Regulation B (12 CFR Part 1002) requires creditors to state the specific reasons for an adverse credit action (denial, termination, or unfavourable change of credit terms); the CFPB confirmed that creditors using complex AI models cannot satisfy this requirement by providing generic or approximate reasons - the reasons must accurately reflect the specific factors the AI model used to reach the decision for that specific applicant; (2) 'black box' excuse rejected - the CFPB rejected the argument that AI model complexity excuses creditors from providing specific, accurate adverse action reasons; creditors must be able to explain AI credit decisions in terms that meet Regulation B's specificity requirement; (3) sample reason codes insufficient alone - using CFPB sample adverse action reason codes (12 CFR Part 1002 Appendix C) may be insufficient if the specific AI model uses factors not captured by the sample codes; (4) FCRA adverse action requirement - where a credit decision is based wholly or partly on a consumer report, FCRA also requires adverse action notices identifying the consumer reporting agency; when AI models incorporate consumer report data, both ECOA and FCRA requirements apply; (5) disparate impact - AI credit models that result in disparate impact on a prohibited basis (race, color, religion, national origin, sex, marital status, age, receipt of public assistance income) violate ECOA's anti-discrimination provisions; model validation must include disparate impact testing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-cfpb-adverse-action-ai-2022.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-credit-reporting-act-fcra-1970",
      "us-ostp-blueprint-ai-bill-of-rights",
      "us-eeoc-ai-employment-guidance-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cfpb-cfr-12-part-1005-regulation-e-electronic-fund",
    "title": "12 CFR Part 1005 - Electronic Fund Transfers (Regulation E)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes the rights, liabilities, and responsibilities of participants in electronic fund transfer systems, mandating disclosures, error resolution procedures, and limitations on consumer liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cfpb-cfr-12-part-1026-regulation-z-truth-lending",
    "title": "12 CFR Part 1026 - Truth in Lending (Regulation Z)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Organizations must follow specified procedures for accessing, interpreting, and providing feedback on regulatory text published on the eCFR website.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cfpb-circular-2022-03-adverse-action-ai-credit",
    "title": "US CFPB Circular 2022-03 - Adverse Action Notification Requirements in Connection with Credit Decisions Based on Complex Algorithms (May 26, 2022)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "Consumer Financial Protection Bureau Circular 2022-03 (published May 26, 2022) confirms that creditors using complex algorithms - including artificial intelligence and machine learning models - to make credit decisions cannot avoid the Equal Credit Opportunity Act (ECOA) and Regulation B adverse action notification requirements. The Circular addresses the question whether ECOA and Regulation B require creditors that use AI or other complex models to provide statements of specific reasons to applicants against whom adverse action is taken. The CFPB's answer is yes: creditors must provide statements of specific reasons that are accurate and specific even if the decision was made by a complex algorithm, and the reasons must be reflective of the actual basis for the decision. The Circular reiterates that 15 U.S.C. 1691(d) and 12 CFR 1002.9 require adverse action notices to include the specific principal reasons for the action taken; reasons that are overly broad or vague (such as 'purchasing history' or 'income') do not satisfy ECOA. The Circular puts creditors on notice that black-box models that cannot produce accurate, specific reason statements are inconsistent with the law, and instructs supervised institutions to ensure their algorithm-based credit decisioning supports compliant adverse action notification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "nist_framework",
        "regulatory_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cfpb-udaap-dodd-frank-section-1031-unfair-deceptive-abusive",
      "us-eeoc-ai-employment-guidance-2023",
      "us-ostp-blueprint-ai-bill-of-rights",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-cfpb-circular-2022-03-adverse-action-complex-algorithms",
    "title": "CFPB Consumer Financial Protection Circular 2022-03 - Adverse Action Notification for Credit Decisions Based on Complex Algorithms",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "CFPB Consumer Financial Protection Circular 2022-03 (26 May 2022) confirms that creditors using complex algorithms, including artificial intelligence and machine learning models, must comply with the Equal Credit Opportunity Act (ECOA) and its implementing regulation Regulation B (12 CFR 1002) adverse action notice requirements. The Circular states that ECOA and Regulation B require creditors to provide a statement of specific reasons that are the principal reasons for the adverse action; vague references to internal standards, proprietary credit scoring systems, or model complexity are insufficient. Specifically the Circular states: 'a creditor cannot justify noncompliance with ECOA's requirement to provide specific and accurate reasons for adverse actions based on the mere fact that the technology it employs to evaluate applications is too complicated or opaque to understand.' The Circular applies to all creditors subject to ECOA including banks, credit unions, non-bank lenders, and consumer finance companies regardless of the technical complexity of the model used. Enforcement authority rests with the CFPB, FTC, prudential banking regulators, and state attorneys general under ECOA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "frb-sr-11-7-model-risk-management",
      "us-eo-14110-ai-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cfpb-circular-2023-03-adverse-action-ai",
    "title": "US Consumer Financial Protection Bureau - Consumer Financial Protection Circular 2023-03 (September 19, 2023): Adverse Action Notification Requirements and the Proper Use of the CFPB's Sample Forms Provided in Regulation B; AI/Algorithmic Credit Decisioning Has No Special Exemption",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2023-09-19",
    "bluf": "Consumer Financial Protection Circular 2023-03, 'Adverse action notification requirements and the proper use of the CFPB's sample forms provided in Regulation B', was issued on September 19, 2023 by the United States Consumer Financial Protection Bureau (CFPB). The Circular addresses creditors' obligations under the Equal Credit Opportunity Act (ECOA) and Regulation B (12 CFR 1002.9) when issuing adverse action notices, with specific application to credit decisions made or supported by complex algorithms and artificial intelligence. The core holding is twofold. First: 'Creditors that simply select the closest factors from the checklist of sample reasons are not in compliance with the law if those reasons do not sufficiently reflect the actual reason for the action taken' - meaning the CFPB's sample forms in Regulation B are not safe harbours for any creditor that would have to substantively misdescribe the actual basis to fit the sample. Second: 'There is no special exemption for artificial intelligence' - meaning AI/algorithmic credit decisioning is fully within ECOA and Regulation B scope and creditors using such systems must disclose the specific reasons for adverse action even where the underlying model uses inputs that the consumer might not intuitively associate with credit. The Circular states: 'Creditors must disclose the specific reasons, even if consumers may be surprised, upset, or angered to learn their credit applications were being graded on data that may not intuitively relate to their finances.' The Circular thus closes off two creditor defences that had emerged with AI credit-decisioning expansion - (a) reliance on the sample-form checklist as a safe harbour and (b) assertions that AI complexity makes specific-reason disclosure infeasible. The Circular is consequential for fintech lenders, traditional creditors deploying AI underwriting/pricing, and BNPL providers. (The CFPB Circular series provides advisory opinions to staff and the public on consumer financial law; Circulars are persuasive authority and inform CFPB enforcement priorities.)",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us-cfpb-adverse-action-ai-2022",
        "ecoa-equal-credit-opportunity-act",
        "regulation-b-12-cfr-1002-9",
        "fcra-fair-credit-reporting-act",
        "naic-model-bulletin-ai-systems-insurers-2023",
        "us-finra-reg-notice-24-09-ai-2024"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cfpb-adverse-action-ai-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cfpb-circular-2023-03-adverse-action-ai-creditors",
    "title": "CFPB Consumer Financial Protection Circular 2023-03 - Adverse Action Notices When Using AI and Complex Credit Models",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "CFPB Consumer Financial Protection Circular 2023-03 (19 September 2023) builds on the 2022-03 Circular and clarifies that creditors using AI and other complex algorithmic models in credit decisions cannot satisfy the Equal Credit Opportunity Act and Regulation B adverse action notice requirements by relying on a closed list of generic checkbox reasons that do not reflect the actual factors driving the denial. The Circular specifies that creditors must provide accurate and specific reasons, even when those reasons fall outside the standard checklists referenced in the Regulation B model adverse action notice forms. Examples cited include where AI models consider unconventional factors (consumer spending patterns, social media activity, behavioural data, third-party data), the creditor must disclose those factors specifically rather than substitute a generic checkbox. The Circular reinforces that adverse action specificity is a strict legal requirement that does not bend for model complexity, third-party vendor opacity, or proprietary system claims. Enforcement authority is the CFPB and parallel regulators under ECOA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cfpb-circular-2022-03-adverse-action-complex-algorithms",
      "frb-sr-11-7-model-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cfpb-dodd-frank-title-x-consumer-financial-protection",
    "title": "US CFPB Dodd-Frank Title X - Consumer Financial Protection Bureau & UDAAP",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Dodd-Frank Title X (12 USC §§5481-5603) established the Consumer Financial Protection Bureau (CFPB) with broad authority to regulate consumer financial products and services. The CFPB's primary enforcement power is the Unfair, Deceptive, or Abusive Acts or Practices (UDAAP) standard under §1031. The CFPB has exclusive supervisory authority over non-bank financial entities with >$10 billion in assets; it shares authority with prudential regulators for banks/credit unions >$10B. Key rules include the TILA-RESPA Integrated Disclosure (TRID), Qualified Mortgage (QM)/Ability-to-Repay (ATR) rule, and HMDA amendments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dodd-frank-title-vii-otc-derivatives-2010",
      "us-glba-gramm-leach-bliley-act-1999"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cfpb-rule-1033-personal-financial-data-rights-2024",
    "title": "US CFPB Personal Financial Data Rights Rule 12 CFR Part 1033 - Open Banking Implementation Under Dodd-Frank Section 1033, Final Rule 22 October 2024",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "Data providers that are depository institutions, credit card issuers, prepaid account issuers, and digital wallet providers (and similar) covered under the Consumer Financial Protection Bureau's Personal Financial Data Rights final rule (89 FR 90838, 22 October 2024) implementing Dodd-Frank section 1033 must, on the staggered compliance dates beginning with the largest depository institutions on 1 April 2026, make covered data available to consumers and authorised third parties through developer interfaces that meet the standardised technical requirements, provide consumer-facing portals for managing authorisations, comply with the prohibition on screen scraping fees and on use of credentials per 12 CFR 1033.301, and contractually require authorised third parties to comply with the third party obligations including reasonable use, no targeted advertising or sale of data, and data security per 12 CFR 1033.421.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cfpb-udaap-dodd-frank-section-1031-unfair-deceptive-abusive"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-cfr-12-part-30-safety-soundness-standards",
    "title": "12 CFR Part 30 - Safety and Soundness Standards",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes a framework for the Office of the Comptroller of the Currency to identify failures to meet safety and soundness standards, require the submission of compliance plans, and issue and enforce orders to correct deficiencies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-cfr-12-part-364-safety-soundness-fdic",
    "title": "12 CFR Part 364 - Standards for Safety and Soundness",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes interagency standards for safety, soundness, and information security that insured depository institutions must implement and maintain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "eu-ai-act-article-9-risk-management-system"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-cfr-29-part-1910-212-general-machine-guarding",
    "title": "29 CFR 1910.212 - General requirements for all machines.",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must provide and maintain machine guarding to protect operators and other employees from hazards created by points of operation, ingoing nip points, rotating parts, and other machine dangers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cfr-29-part-1910-subpart-o-machinery-guarding",
    "title": "29 CFR Part 1910 Subpart O - Machinery and Machine Guarding",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes general and specific safety requirements for machinery and machine guarding to protect operators and other employees from hazards created by moving parts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cfr-31-part-1020-bank-secrecy-act-banks",
    "title": "31 CFR Part 1020 - Rules for Banks",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes comprehensive anti-money laundering (AML) program, customer identification, record-keeping, and reporting requirements for banks to deter and detect money laundering and terrorist financing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cftc-17-cfr-30-foreign-futures-and-options-transactions",
    "title": "17 CFR Part 30 - Foreign Futures and Foreign Options Transactions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "17 CFR Part 30 governs the offer and sale in the United States of foreign futures and foreign options products, that is, contracts made or to be made on or subject to the rules of a foreign board of trade, by the Commodity Futures Trading Commission. Except as the rules permit, it is unlawful for any person to solicit or accept orders for foreign futures or foreign options transactions from a foreign futures or options customer and, in connection therewith, to accept customer money, securities or property unless that person is appropriately registered or exempt. Persons acting in capacities such as futures commission merchant, introducing broker, commodity pool operator or commodity trading advisor with respect to such customers must be registered, with alternative procedures available for non-domestic persons. Before opening an account, the intermediary must provide the customer with the required risk disclosure. A futures commission merchant must at all times maintain in separate accounts money, securities and property in an amount at least sufficient to cover its obligations to foreign futures and foreign options (Rule 30.7) customers. Fraudulent transactions, including cheating or defrauding customers, making false reports or records, deceiving customers, and bucketing orders, are prohibited. The Commission may grant exemptions by order, including the comparability relief by which firms located in jurisdictions with a comparable regulatory framework may serve United States customers, and direct foreign order transmittal is subject to specific conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_obligations",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-commodity-exchange-act-cftc-crypto-derivatives-regulation",
      "us-cftc-cfr-17-part-23-swap-dealers",
      "us-cftc-cfr-17-part-39-derivatives-clearing-organizations"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cftc-17-cfr-38-designated-contract-markets",
    "title": "17 CFR Part 38 - Designated Contract Markets (CFTC Core Principles)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "17 CFR Part 38 implements the core principles that a board of trade must satisfy to obtain and maintain designation as a contract market (DCM) with the Commodity Futures Trading Commission under section 5(d) of the Commodity Exchange Act, as amended by the Dodd-Frank Act. A DCM must comply with each statutory core principle and any requirement the Commission imposes, with reasonable discretion in how it complies. It must establish, monitor and enforce the rules of the contract market, including access requirements, the terms and conditions of contracts and rules prohibiting abusive trade practices, and have the capacity to detect, investigate and sanction violations. It may list only contracts that are not readily susceptible to manipulation, and must have the capacity and responsibility to prevent manipulation, price distortion and disruption of the delivery or cash-settlement process through market surveillance, including real-time monitoring of trading and comprehensive and accurate trade reconstructions. For each contract, as necessary and appropriate, it must adopt position limitations or position accountability, and it must adopt rules providing for the exercise of emergency authority, including liquidating or transferring positions, suspending or curtailing trading, and imposing special margin requirements. The DCM must establish and enforce rules ensuring the financial integrity of transactions, including clearance and settlement through a derivatives clearing organization, and must maintain a program of system safeguards, including risk analysis and oversight, emergency procedures, backup facilities, a disaster-recovery plan, and periodic testing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "core_principles",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-commodity-exchange-act-cftc-crypto-derivatives-regulation",
      "us-cftc-cfr-17-part-39-derivatives-clearing-organizations",
      "us-cftc-cfr-17-part-23-swap-dealers"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cftc-17-cfr-41-security-futures-products",
    "title": "17 CFR Part 41 - Security Futures Products",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "17 CFR Part 41 sets out the requirements for security futures products, which are jointly regulated by the Commodity Futures Trading Commission and the Securities and Exchange Commission. It governs the securities that may underlie a security future, the determination of whether an index is a narrow-based security index, the listing of security futures products for trading, and conduct on the trading floor. A security future may be based only on securities, or on a narrow-based security index, that meet the requirements for underlying securities, and a designated contract market or registered entity must make the required certifications when it lists a security futures product or amends a product rule. The regulation prescribes the method for determining the market capitalization and the dollar value of average daily trading volume used in applying the definition of a narrow-based security index, including transition rules for indexes that cease to be, or become, narrow-based. Trading in security futures products is subject to additional conditions, and floor brokers are prohibited from dual trading in security futures products except as permitted. Registered entities must keep the required records relating to security futures products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_obligations",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-commodity-exchange-act-cftc-crypto-derivatives-regulation",
      "us-securities-exchange-act-1934",
      "us-cftc-cfr-17-part-39-derivatives-clearing-organizations"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cftc-cfr-17-part-23-swap-dealers",
    "title": "17 CFR Part 23 - Swap Dealers and Major Swap Participants",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes registration, capital, margin, recordkeeping, and reporting requirements for swap dealers and major swap participants to ensure financial stability and market integrity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cftc-cfr-17-part-39-derivatives-clearing-organizations",
    "title": "17 CFR Part 39 - Derivatives Clearing Organizations",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes core principles and compliance obligations for Derivatives Clearing Organizations (DCOs) concerning financial resources, risk management, settlement procedures, default rules, system safeguards, reporting, and governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "us-cftc-digital-asset-guidance",
    "title": "CFTC Virtual Currency Derivatives and Digital Asset Regulatory Framework - Guidance and Enforcement Approach",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This framework clarifies that virtual currencies are commodities under the Commodity Exchange Act (CEA), subjecting derivatives on these assets (futures, swaps, options) and certain leveraged retail transactions to CFTC jurisdiction. Market participants, including exchanges and intermediaries, must comply with applicable registration, reporting, and conduct rules for Designated Contract Markets (DCMs), Swap Execution Facilities (SEFs), and Futures Commission Merchants (FCMs).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dodd-frank-key-provisions",
      "us-sec-digital-asset-framework",
      "fsb-crypto-asset-regulatory-framework-2023",
      "crypto-aml-travel-rule"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cftc-digital-commodities-cea-jurisdiction",
    "title": "US CFTC Jurisdiction Over Digital Commodities Under the Commodity Exchange Act (CEA)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The U.S. Commodity Futures Trading Commission (CFTC) asserts jurisdiction over digital assets such as Bitcoin and Ether as \"commodities\" under the Commodity Exchange Act (CEA), granting it authority to police fraud and manipulation in spot markets and regulate derivatives contracts involving these assets, as defined in Section 1a(9) of the CEA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cftc-digital-asset-guidance",
      "us-sec-digital-asset-framework",
      "crypto-aml-travel-rule",
      "fincen-cvc-business-models"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cftc-event-contracts-prediction-markets-2024",
    "title": "US CFTC Jurisdiction over Event Contracts and Prediction Markets (2024)",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2024-09-12",
    "bluf": "The Commodity Futures Trading Commission (CFTC) regulates event contracts as commodity derivatives under the Commodity Exchange Act of 1936 (CEA) as amended. Section 5c(c)(5)(C) of the CEA gives the CFTC authority to determine that certain event contracts referencing gaming, terrorism, assassination, or activities that are unlawful under any State or Federal law are contrary to the public interest and may not be listed for trading on a registered exchange. On 12 September 2024 the US District Court for the District of Columbia (KalshiEx LLC v. CFTC, No. 23-cv-3257) vacated the CFTC's denial of KalshiEx's congressional control contracts and held that the contracts did not involve gaming under CEA Section 5c(c)(5)(C). The decision opened the door to listed exchange-traded political event contracts on Designated Contract Markets (DCMs) regulated by the CFTC.\n\nThe Court of Appeals for the DC Circuit declined to stay the District Court decision pending appeal in October 2024, and Kalshi commenced trading 2024 US election event contracts on its CFTC-regulated DCM. The CFTC retains broad anti-fraud and anti-manipulation authority over event contracts under CEA sections 4b, 4c, and 9(a)(2). State gambling regulators have asserted that some event contracts marketed as prediction markets constitute sports betting subject to state law (see New Jersey Division of Gaming Enforcement orders against Kalshi in 2025). The Department of Justice has separately asserted concerns under the Wire Act 1961 (18 USC 1084) regarding cross-state event contract activity. The regulatory landscape remains contested with federal-state preemption disputes ongoing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-uigea-2006-unlawful-internet-gambling"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-childrens-online-privacy-protection-act",
    "title": "US Children's Online Privacy Protection Act (15 USC ch 91): Parental Consent for Children's Data",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Children's Online Privacy Protection Act, COPPA (15 U.S.C. ch. 91), regulates the online collection of personal information from children under the age of 13, enforced by the Federal Trade Commission. Section 6501 provides the definitions, including child, operator, personal information and verifiable parental consent. Section 6502 directs the Commission to issue regulations requiring an operator of a website or online service directed to children, or one that has actual knowledge it is collecting personal information from a child, to provide notice of its information practices and to obtain verifiable parental consent for the collection, use or disclosure of personal information from children, subject to limited exceptions such as a one-time response to a specific request or the protection of a child's safety. The operator must also give a parent the ability to review the information collected and to refuse further use or collection, and must establish reasonable procedures to protect the confidentiality, security and integrity of the information. A violation of a regulation prescribed under section 6502 is treated as a violation of a rule defining an unfair or deceptive act or practice under the Federal Trade Commission Act. Section 6505 allocates enforcement among the FTC and other agencies and authorizes State attorneys general to bring actions. The Act is the legal foundation for US children's online privacy compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-chips-and-science-act-2022-pl-117-167",
    "title": "United States CHIPS and Science Act of 2022 (Public Law 117-167): Division A CHIPS Act of 2022 Semiconductor Manufacturing Incentives, CHIPS for America Fund, Semiconductor Incentives with Foreign Manufacturing Expansion Restrictions, Opportunity and Inclusion, Division B Department of Energy Science Programs, and National Science Foundation Technology Innovation and Partnerships",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The CHIPS and Science Act of 2022, Public Law 117-167 of 9 August 2022, is the principal federal statute providing 52 billion dollars in semiconductor manufacturing incentives and authorizing the federal advanced manufacturing investment tax credit at 25 per cent for qualifying semiconductor manufacturing property, with national security guardrails restricting recipients from expanding semiconductor manufacturing capacity in countries of concern, and is administered by the Department of Commerce CHIPS Program Office, the Department of the Treasury Internal Revenue Service, the Department of Energy, and the National Science Foundation. CHIPS and Science Act, Division A (the CHIPS Act of 2022) establishes semiconductor manufacturing incentives through federal financial assistance to covered entities for fabrication, production, and research activities. CHIPS and Science Act, section 102 creates the Creating Helpful Incentives to Produce Semiconductors (CHIPS) for America Fund with 24 billion dollars appropriated for fiscal year 2022, allocated to semiconductor manufacturing incentives, research and development advancement, and workforce development. CHIPS and Science Act, section 103 amends eligibility criteria, adds mature technology node support with 2 billion dollars earmarked, and establishes expansion restrictions on foreign semiconductor manufacturing for recipients including the requirement that recipients enter into agreements not to engage in any significant transaction involving the material expansion of semiconductor manufacturing capacity in countries of concern (including China, Russia, Iran, and North Korea) for 10 years from the date of award. CHIPS and Science Act, section 104 directs the Department of Commerce to establish activities promoting economically disadvantaged individuals, minority-owned, veteran-owned, and women-owned business participation. CHIPS and Science Act, Title I of Division B (Department of Energy Science for the Future) authorizes programs in basic energy sciences, fusion research, physics, and laboratory infrastructure. CHIPS and Science Act, Title III of Division B (National Science Foundation for the Future) establishes STEM education, broadening participation initiatives, research security office, and the new Directorate for Technology, Innovation, and Partnerships. The Act also enacts the Advanced Manufacturing Investment Tax Credit at Internal Revenue Code section 48D. The Act is the controlling federal instrument for semiconductor manufacturing incentives and the foreign manufacturing expansion restrictions on recipients.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-chips-science-act-2022",
    "title": "CHIPS and Science Act of 2022 (Pub.L. 117-167) - $52.7B Semiconductor Manufacturing Incentives, 25% Investment Tax Credit, 10-Year China Guardrails Prohibiting Expansion in Foreign Countries of Concern, National Semiconductor Technology Center, and $200B Science Investment",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The CHIPS and Science Act (Pub.L. 117-167, enacted 9 August 2022) provides approximately $52.7 billion in federal funding for US semiconductor manufacturing, research, and workforce development, plus a 25% Advanced Manufacturing Investment Credit (AMIC, IRC §48D) for construction of semiconductor fabrication facilities; Title I (CHIPS for America) allocates $39 billion in manufacturing incentives (Commerce Department grants), $11 billion for R&D including the National Semiconductor Technology Center (NSTC) and National Advanced Packaging Manufacturing Program (NAPMP), and $2 billion for legacy chips critical to defence and automotive sectors; recipients of CHIPS funding are subject to 10-year 'guardrail' provisions prohibiting material expansion of semiconductor manufacturing capacity in 'foreign countries of concern' (China, Russia, Iran, North Korea), entering into joint research or technology licensing agreements with foreign entities of concern, and engaging in transactions that expand foreign country of concern semiconductor capacity; the Science portion (Titles II-VI) authorises $200 billion over 10 years for National Science Foundation, Department of Energy, NIST, and NASA research programmes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_CHIPS_ACT",
        "US_IRA",
        "US_EXPORT_CONTROLS",
        "OECD_PILLAR_TWO"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-inflation-reduction-act-clean-energy-2022",
      "oecd-beps-pillar-two-global-minimum-tax",
      "ear-dual-use-export"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-circia-cyber-incident-reporting-act-2022",
    "title": "Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-07-03",
    "bluf": "The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) mandates that covered entities in critical infrastructure sectors report covered cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 hours of reasonable belief that an incident has occurred, and report any ransomware payments within 24 hours of making the payment, as required by Section 2242 of the Homeland Security Act of 2002, added by CIRCIA and codified at 6 U.S.C. 681b.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cisa-cross-sector-cybersecurity-goals",
      "cisa-ms-isac-ransomware-guide",
      "nis2-incident-reporting-article-23",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cisa-ai-cybersecurity-collaboration-playbook-2024",
    "title": "CISA AI Cybersecurity Collaboration Playbook 2024 - Compliance Obligations for Critical Infrastructure AI Security, AI Incident Sharing with CISA, and Collaborative AI Threat Intelligence Reporting Requirements",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines obligations for critical infrastructure organizations to secure AI systems, share AI-related cyber incidents with CISA, and engage in collaborative threat intelligence reporting as per the CISA AI Cybersecurity Collaboration Playbook 2024, with overlapping requirements under the EU AI Act 2024, specifically Articles 9 and 13 on risk management and transparency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cisa-ai-cybersecurity-collaboration-playbook-2025",
    "title": "US CISA AI Cybersecurity Collaboration Playbook (January 14, 2025)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On January 14, 2025 the US Cybersecurity and Infrastructure Security Agency (CISA) published the AI Cybersecurity Collaboration Playbook. The Playbook provides operational guidance for AI providers, AI developers, AI integrators, AI deployers, AI operators, and other AI ecosystem participants to share AI cybersecurity information through the CISA Joint Cyber Defense Collaborative (JCDC) and to coordinate AI-related incident response. The Playbook is structured around five collaboration areas: (1) AI cybersecurity information sharing - voluntary sharing of threat intelligence, vulnerabilities, and lessons learned through JCDC channels; (2) Incident reporting - voluntary AI-related incident reporting alongside CIRCIA requirements where applicable; (3) Joint analytic products - collaboration between AI ecosystem participants and CISA on threat analysis, bulletins, and advisories; (4) Operational coordination - joint exercises, tabletop exercises, and incident response coordination; (5) AI-specific Information Sharing and Analysis Capabilities. The Playbook references existing CISA products including the CISA Roadmap for AI (April 2024), the Considerations for Managing AI Cybersecurity Risks in Critical Infrastructure (April 2024), the Joint CSI Deploying AI Systems Securely (NSA-CISA-FBI-NCSC-UK-ACSC-CCCS-NCSC-NZ April 2024), and the CISA-NCSC Guidelines for Secure AI System Development (November 2023). The Playbook is voluntary but is the operational framework CISA uses for AI cybersecurity coordination with industry and allied partners.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "nist_framework",
        "us_federal_alignment",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cisa-roadmap-for-ai-2024",
      "us-cisa-safety-security-ai-critical-infrastructure-2024",
      "us-csi-deploying-ai-systems-securely-2024",
      "cisa-ncsc-guidelines-secure-ai-system-development-2023",
      "nist-ai-100-2-adversarial-ml-taxonomy-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cisa-ai-cybersecurity-guidelines-2023",
    "title": "Guidelines for Secure AI System Development",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2023-11-27",
    "bluf": "This joint guidance from CISA, UK NCSC, and 21 international partners provides a framework for organizations to secure AI systems throughout their lifecycle. It outlines four key areas-Secure Design, Secure Development, Secure Deployment, and Secure Operation-mandating a 'security-by-design' approach for all AI system developers and providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess",
      "nist-ai-100-2-aml-taxonomy",
      "nist-sp-800-160-v2r1"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cisa-circia-cyber-incident-reporting-2022",
    "title": "US Cyber Incident Reporting for Critical Infrastructure Act 2022 (CIRCIA) - 72 Hour Incident and 24 Hour Ransomware Payment Reporting to CISA, Effective on Final Rule",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "Covered entities in 16 critical infrastructure sectors subject to the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA, 6 U.S.C. 681 et seq., enacted as Division Y of the Consolidated Appropriations Act 2022, Pub. L. 117-103) must, upon the effective date of the CISA Final Rule implementing CIRCIA (proposed rule published 4 April 2024 at 89 FR 23644; final rule expected late 2026), report covered cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 hours of reasonable belief that a covered cyber incident has occurred (6 U.S.C. 681b(a)(1)), and report ransom payments made in response to a ransomware attack within 24 hours of the payment (6 U.S.C. 681b(a)(2)), and preserve relevant data per the data preservation requirement at 6 U.S.C. 681b(a)(7).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cisa-cpg-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-cisa-cpg-2022",
    "title": "CISA Cross-Sector Cybersecurity Performance Goals 2022 - Baseline Cybersecurity Practices for Critical Infrastructure",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This voluntary guidance from CISA establishes a common set of baseline cybersecurity goals for critical infrastructure owners and operators to reduce risks across both Information Technology (IT) and Operational Technology (OT) systems. The goals, such as Goal 2.H (Implement Phishing Protection), are designed to be clear, actionable, and prioritized to help organizations focus on the most significant risk reduction measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cis-controls-v8",
      "cyber-nist-800-53-ac2",
      "nist-800-53-au2",
      "cisa-ms-isac-ransomware-guide"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-cisa-critical-infrastructure-16-sectors-cyber-resilience",
    "title": "CISA Critical Infrastructure Cybersecurity - 16 Sector Protection Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "CISA designates 16 critical infrastructure sectors under Presidential Policy Directive 21 (PPD-21). Each sector has a designated Sector Risk Management Agency (SRMA) responsible for coordinating cybersecurity plans, incident response, and resilience activities under 6 U.S.C. § 652 and the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-cybersecurity-framework-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cisa-cybersecurity-information-sharing-6-usc-1501",
    "title": "Cybersecurity Information Sharing Act 2015 - 6 USC 1501 Federal-Private Threat Intelligence",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Sections 1500 through 1525 of title 6 of the United States Code codify the Cybersecurity Information Sharing Act of 2015, enacted as Title I of the Cybersecurity Act of 2015 (Division N of the Consolidated Appropriations Act 2016, Public Law 114-113, signed 18 December 2015). The Act establishes the legal framework for the voluntary sharing of cyber threat indicators and defensive measures between federal entities and non-federal entities (private sector, state, local, tribal, and territorial governments) and among non-federal entities, with statutory liability protection, antitrust protection, and Freedom of Information Act and other federal disclosure exemptions. Section 1501 defines key terms including cyber threat indicator and defensive measure (by cross-reference to section 650 added by Cybersecurity Act 2015 reorganisation). Section 1503 authorises non-federal entities to monitor information systems and operate defensive measures for cybersecurity purposes. Section 1504 governs sharing through the DHS automated sharing capability (Automated Indicator Sharing / AIS) administered by CISA. Sections 1505 through 1507 provide the liability and disclosure protections. The CISA framework operates alongside the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) which adds mandatory reporting; CISA 2015 remains the voluntary sharing baseline. AI-enabled threat detection, security operations centres, and managed detection and response services rely on the CISA 2015 protections to share enriched indicators with federal partners and peer organisations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-stored-communications-act",
      "us-ecpa-1986"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cisa-ics-cert-advisory-framework",
    "title": "Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) Advisory Framework",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "CISA requires owners and operators of industrial control systems to publish, score, and coordinate mitigation of vulnerabilities through formal advisories, including product identification, mitigation guidance, and sector coordination as outlined in the advisory framework clause.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-4-2-component-security-2019",
      "iec-62443-industrial-automation-security-standards",
      "iso-55001-2014-asset-management-industrial"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cisa-kev-catalog",
    "title": "CISA Known Exploited Vulnerabilities Catalog - Binding Operational Directive 22-01 and Mandatory Remediation Timelines",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-11-03",
    "bluf": "Binding Operational Directive (BOD) 22-01 requires U.S. Federal Civilian Executive Branch (FCEB) agencies to remediate vulnerabilities listed in the CISA-managed Known Exploited Vulnerabilities (KEV) catalog within specified, aggressive timeframes to protect federal networks from active threats.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-csf-2",
      "cis-controls-v8",
      "cisa-cross-sector-cybersecurity-goals",
      "nist-800-61-incident-resp"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-cisa-known-exploited-vulnerabilities-bod-22-01",
    "title": "CISA Binding Operational Directive 22-01 - Known Exploited Vulnerabilities Catalog: Federal Agency Mandatory Patch Deadlines (14-Day Critical, 30-Day High), KEV Catalog Methodology, Vendor Coordination, Private Sector Voluntary Adoption and Metrics Reporting",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Federal civilian executive branch agencies must remediate vulnerabilities listed in the CISA Known Exploited Vulnerabilities (KEV) Catalog within 14 days for critical severity and 30 days for high severity per Binding Operational Directive (BOD) 22-01. This directive mandates patching timelines, reporting, and coordination with CISA for exploited vulnerabilities actively used in the wild.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-samm-governance",
      "uk-money-laundering-regulations-2017-amended"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cisa-nsa-nist-quantum-readiness-factsheet",
    "title": "CISA, NSA and NIST Joint Factsheet - Quantum-Readiness: Migration to Post-Quantum Cryptography",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-08-17",
    "bluf": "Quantum-Readiness: Migration to Post-Quantum Cryptography is a joint factsheet created by the Cybersecurity and Infrastructure Security Agency, the National Security Agency and the National Institute of Standards and Technology, marked TLP:CLEAR and dated as of August 17, 2023. It was created to inform organizations, especially those that support Critical Infrastructure, about the impacts of quantum capabilities, and to encourage early planning for migration to post-quantum cryptographic standards by developing a Quantum-Readiness Roadmap. It predates the final standards and states that NIST was working to publish the first set of post-quantum cryptographic standards, to be released in 2024; its algorithm references are therefore to draft standards and must be read as such.\n\nIts contribution is a discovery-and-procurement method rather than an algorithm position. The urgency argument is that early planning is necessary because cyber threat actors could be targeting data today that would still require protection in the future, or in other words has a long secrecy lifetime, using a catch now, break later or harvest now, decrypt later operation, and that many cryptographic products, protocols and services relying on public key algorithms such as RSA, Elliptic Curve Diffie-Hellman and the Elliptic Curve Digital Signature Algorithm will need to be updated, replaced or significantly altered.\n\nThe method has four parts. Establish a quantum-readiness roadmap by first creating a project management team to plan and scope the migration, with that team initiating proactive cryptographic discovery activities and including cybersecurity and privacy risk managers who can prioritise the assets that would be most impacted. Prepare a cryptographic inventory using discovery tools across network protocols, assets on end user systems and servers including applications and associated libraries, and cryptographic code or dependencies in the continuous integration and continuous delivery development pipeline, correlating the result with existing programmes such as Asset Inventory, ICAM, IdAM, EDR and CDM, and feeding it into the risk assessment process. Discuss post-quantum roadmaps with technology vendors, with the factsheet noting that solidly built roadmaps should describe how vendors plan to migrate, charting timelines for testing algorithms and integration into products, and urging organizations to proactively plan for necessary changes to existing and future contracts so that new products are delivered with post-quantum cryptography built in and older products are upgraded to meet transition timelines. Address supply chain quantum-readiness, prioritising high impact systems, industrial control systems and systems with long-term confidentiality or secrecy needs, and treating migration as an IT and OT modernization effort. The factsheet explicitly warns that discovery tools may not be able to identify embedded cryptography used internally within products, and that organizations should ask vendors for lists of embedded cryptography within their products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-8547-pqc-transition",
      "nsa-cnsa-2-0-quantum-resistant-algorithms-2022",
      "fips-203-ml-kem-standard",
      "etsi-tr-103-619-quantum-safe-migration-strategies"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-cisa-roadmap-for-ai-2024",
    "title": "US CISA 2023-2024 Roadmap for Artificial Intelligence",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The US Cybersecurity and Infrastructure Security Agency (CISA) published its 2023-2024 Roadmap for Artificial Intelligence on November 14, 2023. The Roadmap operationalises CISA's mandate under Executive Order 14110 of October 30, 2023 (now rescinded by EO 14148 in January 2025, but the Roadmap continues as CISA's operational AI plan) and the AI in Government Act of 2020. The Roadmap establishes five lines of effort: (1) Responsibly use AI to support CISA's mission - operate AI-enabled software systems with appropriate civil rights and civil liberties considerations; (2) Assure AI systems used by federal civilian executive branch agencies and critical infrastructure - including secure-by-design AI products, AI red teaming, and adversarial machine learning testing; (3) Protect critical infrastructure from malicious use of AI - cyber defence guidance, threat sharing, vulnerability disclosure; (4) Collaborate with and communicate on key AI efforts with the interagency, international partners, and the public; (5) Expand AI expertise in CISA's workforce. The Roadmap is paired with the CISA Joint Cyber Defense Collaborative (JCDC) AI cybersecurity collaboration program and the CISA Considerations for Managing AI Cybersecurity Risks in Critical Infrastructure (April 2024) guidance. CISA continues to operate the Roadmap under the new EO 14179 direction with adjusted emphasis on American AI leadership.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "nist_framework",
        "us_federal_alignment",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cisa-secure-by-design-guidance-2024",
      "nist-ai-rmf-1-0",
      "nist-ai-100-2-adversarial-ml-taxonomy-2024",
      "cisa-ncsc-guidelines-secure-ai-system-development-2023",
      "us-eo-13960-promoting-trustworthy-ai-federal-government-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cisa-safety-security-ai-critical-infrastructure-2024",
    "title": "US CISA Safety and Security Guidelines for Critical Infrastructure Owners and Operators - AI Considerations (April 26, 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On April 26, 2024 the US Cybersecurity and Infrastructure Security Agency (CISA) published Safety and Security Guidelines for Critical Infrastructure Owners and Operators - Considerations for Managing Artificial Intelligence Cybersecurity Risks in Critical Infrastructure. The Guidelines were issued pursuant to Executive Order 14110 of October 30, 2023 (since rescinded by EO 14148 but the Guidelines remain a CISA-issued reference). The Guidelines organise AI cybersecurity risk considerations across three categories: (1) Attacks using AI - the use of AI by adversaries to enhance or automate attacks on critical infrastructure, including social engineering, vulnerability discovery, and novel attack vector creation; (2) Attacks targeting AI systems - adversarial machine learning attacks against AI deployed within critical infrastructure including data poisoning, model evasion, model extraction, and supply chain attacks; (3) Failures in AI design and implementation - reliability failures, unintended consequences, and emergent behaviours of AI deployed in critical infrastructure functions. For each category the Guidelines recommend governance practices (designated accountability, risk register integration, sector coordination), risk management practices (NIST AI RMF alignment, adversarial testing, vendor diligence), and operational practices (continuous monitoring, incident response integration, threat sharing). The Guidelines apply to all 16 critical infrastructure sectors and are operationalised by Sector Risk Management Agencies (SRMAs) in coordination with CISA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "nist_framework",
        "us_federal_alignment",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cisa-roadmap-for-ai-2024",
      "us-csi-deploying-ai-systems-securely-2024",
      "nist-ai-rmf-1-0",
      "nist-ai-100-2-adversarial-ml-taxonomy-2024",
      "cisa-ncsc-guidelines-secure-ai-system-development-2023"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cisa-secure-by-design-principles-2023",
    "title": "CISA Secure by Design Principles 2023 - Product Security Obligations for Software Manufacturers: Default Security Settings, Vulnerability Elimination and Transparency",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This guidance requires software manufacturers to take ownership of customer security outcomes, embrace radical transparency and accountability, and lead from the top by implementing secure-by-design practices. It applies to all software vendors shipping products to U.S. and international customers, with core obligations defined in the three principles: Take Ownership of Customer Security Outcomes, Embrace Radical Transparency and Accountability, and Lead From the Top.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-800-53-ac2",
      "c-scrm-practices-systems-organizations",
      "iso-12207-2017-software-lifecycle-processes",
      "nist-800-53-sc7",
      "cyber-nist-csf-2"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cisada-comprehensive-iran-sanctions-2010-pl-111-195",
    "title": "Comprehensive Iran Sanctions, Accountability, and Divestment Act 2010 (CISADA) - Public Law 111-195",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Comprehensive Iran Sanctions, Accountability, and Divestment Act of 2010 (CISADA, Public Law 111-195, enacted 1 July 2010) substantially expanded the Iran Sanctions Act of 1996 (ISA) framework with broader extraterritorial sanctions on foreign financial institutions and sweeping new mandatory secondary sanctions. Section 102 expanded the menu of available sanctions under ISA from six to nine options and made one or more sanctions mandatory for sanctionable activity. Section 103 added refined petroleum products sales to Iran and provision of goods, services, technology, information, or support that could directly and significantly contribute to Iran's ability to import refined petroleum products as sanctionable activity. Section 104 created the foreign financial institution provision (now Section 1245 NDAA 2012 / Section 1247 NDAA 2019) authorising prohibition of correspondent and payable-through accounts for any foreign financial institution that knowingly facilitates significant transactions or financial services for designated Iranian banks, the Islamic Revolutionary Guard Corps, or proliferation activity. Section 105 created the Special Designated National (SDN) framework for Iranian human rights abusers. Section 202 authorises state and local government divestment from companies investing in Iran's energy sector. Section 203 authorises private fiduciary divestment. Section 302 imposed export controls on sensitive technologies. CISADA is administered by Treasury OFAC under the Iranian Transactions and Sanctions Regulations and continues to shape AI-enabled compliance for global financial institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-iran-sanctions-act-1996-pl-104-172",
      "us-ieepa-1977"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-civil-rights-act-1964-title-vi-42-usc-2000d",
    "title": "Civil Rights Act 1964 Title VI - 42 USC 2000d Federal Financial Assistance Nondiscrimination",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 2000d of title 42 of the United States Code, codifying section 601 of Title VI of the Civil Rights Act of 1964 (Public Law 88-352, enacted 2 July 1964, 78 Stat. 252), prohibits any program or activity receiving federal financial assistance from excluding any person from participation in, denying the benefits of, or subjecting any person to discrimination on the ground of race, color, or national origin. Sections 2000d-1 through 2000d-7 implement and enforce the prohibition by directing every federal agency administering financial assistance to issue rules, regulations, and orders of general applicability subject to presidential approval; conditioning continued federal funding on documented compliance; preserving private rights of action for intentional discrimination; and waiving sovereign immunity for state defendants. The Title VI framework reaches federally funded education, healthcare, housing, transportation, social services, and law-enforcement assistance programs, and is interpreted by the Department of Justice, the Department of Education, the Department of Health and Human Services, and other federal agencies under their respective regulatory codifications (28 CFR Part 42, 34 CFR Part 100, 45 CFR Part 80, and equivalents). For AI systems deployed by federally funded entities, Title VI compliance requires that algorithmic decisions affecting access to benefits or services do not produce disparate impacts on protected groups without legally sufficient justification, and that data governance, model validation, and human review controls evidence the absence of intentional discrimination and the mitigation of unjustified disparate impact.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-housing-act-42-usc-ch45",
      "us-americans-with-disabilities-act"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-civil-rights-act-title-vii",
    "title": "US Civil Rights Act Title VII (42 USC ch 21): Prohibition of Employment Discrimination",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Title VII of the Civil Rights Act of 1964 (42 U.S.C. ch. 21, subchapter VI) prohibits employment discrimination, enforced by the Equal Employment Opportunity Commission. Section 2000e provides the definitions, including employer, which covers employers with fifteen or more employees. Section 2000e-2 sets out the unlawful employment practices: it is unlawful for an employer to fail or refuse to hire, to discharge, or otherwise to discriminate against any individual with respect to compensation, terms, conditions or privileges of employment because of race, color, religion, sex or national origin, and to limit, segregate or classify employees in a way that would deprive them of opportunities because of a protected characteristic; the same section reaches employment agencies, labor organizations and training programs, and recognizes limited exceptions such as a bona fide occupational qualification and bona fide seniority systems. Sex discrimination includes discrimination because of pregnancy and, under controlling precedent, sexual orientation and gender identity. Section 2000e-3 prohibits retaliation against a person who opposes an unlawful practice or participates in a proceeding. Section 2000e-5 sets out enforcement, including the charge process before the Commission and the right to sue, with remedies including reinstatement, back pay and, for intentional discrimination, compensatory and punitive damages. The Act is the legal foundation for US workplace anti-discrimination compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-civil-service-reform-act-5-usc-1101",
    "title": "Civil Service Reform Act 1978 - 5 USC 1101 Merit System Architecture",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 1101 of title 5 of the United States Code, enacted as part of the Civil Service Reform Act of 1978 (Public Law 95-454, signed 13 October 1978) and effected through Reorganization Plan No. 2 of 1978, establishes the Office of Personnel Management (OPM) as an independent establishment in the executive branch. The Act simultaneously replaced the Civil Service Commission with three successor bodies: OPM (positive personnel-management functions including examinations, training, productivity programs, and pay and benefits administration), the Merit Systems Protection Board (hearing, adjudication, and appeals functions protecting federal employee rights, governed by a three-member bipartisan body), and the Federal Labor Relations Authority (central policymaking functions in labor-management relations, three full-time members with Senate confirmation). The Act codifies the nine merit system principles at 5 USC 2301 (recruitment from all segments of society, fair and equitable treatment, equal pay for work of equal value, high standards of integrity and conduct, efficient and effective use of the federal workforce, retention based on performance, education and training, protection from arbitrary action, protection of whistleblowers) and the eleven prohibited personnel practices at 5 USC 2302 (subsequently expanded to thirteen by the Whistleblower Protection Act 1989 and the Whistleblower Protection Enhancement Act 2012). The Act is the constitutional charter of the modern US federal civil service and frames the legal limits on AI-driven federal personnel management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paperwork-reduction-act-44-usc-ch35"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-clarifying-lawful-overseas-use-of-data-cloud-act-2018-v2",
    "title": "US CLOUD Act of 2018 - Lawful Overseas Use of Data and Executive Agreements",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-19",
    "bluf": "The Clarifying Lawful Overseas Use of Data (CLOUD) Act of 2018 was enacted as Division V of the Consolidated Appropriations Act of 2018 (Public Law 115-141), signed into law on 23 March 2018. The Act amends the Stored Communications Act to require that providers of electronic communication services or remote computing services preserve, backup, or disclose the contents of wire or electronic communications and any record or other information within their possession, custody, or control, regardless of whether the data is stored within or outside the United States. Title I includes a comity mechanism allowing a provider to move to quash or modify a warrant if compliance would create a material risk of violating the laws of a qualifying foreign government, but only with respect to data pertaining to a person who is not a US person and who is not located in the US. Title II authorizes the US government to enter into bilateral executive agreements with foreign governments that meet specified privacy, human rights, and rule-of-law standards, enabling those governments to issue lawful orders directly to US-based providers for serious crime investigations. The US Attorney General, with the concurrence of the Secretary of State, certifies before an agreement takes effect that the foreign government's domestic legal framework meets statutory requirements. As of the present knowledge cutoff, executive agreements with the United Kingdom and Australia are in force; negotiation with the European Union is ongoing. The Act does not expand US government surveillance authority beyond what pre-existing law allows, nor does it establish data localization mandates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "nist_framework",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-clayton-act",
    "title": "US Clayton Act (15 USC ch 1): Price Discrimination, Tying, Mergers and Treble Damages",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Clayton Act of 1914 (15 U.S.C. ch. 1, sections 12 onward) supplements the Sherman Act by prohibiting specific practices whose effect may be substantially to lessen competition or tend to create a monopoly, enforced by the Department of Justice Antitrust Division and the Federal Trade Commission. Section 12 supplies definitions and venue rules for antitrust suits. Section 13 (incorporating the Robinson-Patman amendments) prohibits price discrimination between purchasers of commodities of like grade and quality where the effect may be to lessen competition. Section 14 prohibits sales or leases on the condition that the buyer not deal in the goods of a competitor (tying and exclusive dealing) where the effect may be to lessen competition. Section 15 confers a private right of action and allows a successful private plaintiff to recover threefold the damages sustained plus costs and attorney fees. Section 18 prohibits an acquisition of stock or assets where the effect may be substantially to lessen competition or tend to create a monopoly, and is the substantive basis of US merger control (administered with the Hart-Scott-Rodino premerger notification regime). Section 19 prohibits interlocking directorates among competing corporations above statutory thresholds. The Act is the legal foundation of US merger review, price-discrimination law, and private antitrust enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-clayton-act-1914-merger-enforcement",
    "title": "An Act to Amend the Provisions of the Anti-Trust Act Approved July Two, Nineteen Hundred and One, and to Provide for the Enforcement of the Anti-Trust Laws, and for Other Purposes - Section 7: Acquisition of Stock or Assets; Interlocking Directorates",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Prohibits mergers and acquisitions where the effect may be substantially to lessen competition or tend to create a monopoly, as defined under Section 7 of the Clayton Act (15 U.S.C. § 18). Applies to any person, corporation, or entity engaged in commerce that proposes an acquisition meeting the size-of-person and size-of-transaction thresholds under the Hart-Scott-Rodino Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-clayton-act-1914-mergers-tying",
    "title": "US Clayton Act 1914 - Section 7 Mergers, Section 3 Tying Arrangements, Section 8 Interlocking Directorates, Private Rights of Action and Treble Damages for Antitrust Violations",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Clayton Act prohibits mergers and acquisitions that may substantially lessen competition under §7, bans tying arrangements that restrain trade under §3, and forbids interlocking directorates under §8. It applies to corporations, officers, and entities engaged in commerce, with enforcement by the Department of Justice and private parties authorized to sue for treble damages under §15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-merger-regulation-139-2004-ec-thresholds",
      "australia-competition-consumer-act-2010-part-iv",
      "canada-competition-act-2024-amendment-abuse-dominance",
      "eu-foreign-subsidies-regulation-2022-2560-competition"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-clayton-act-1914-section-7-mergers-acquisitions-prohibition",
    "title": "15 U.S. Code § 18 - Acquisition by one corporation of stock of another",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations are prohibited from acquiring the stock or assets of another entity where the effect of such an acquisition may be to substantially lessen competition or tend to create a monopoly.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-clean-air-act",
    "title": "US Clean Air Act (42 USC ch 85): NAAQS, Permits, Emission Standards and Enforcement",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Clean Air Act (CAA), codified at 42 U.S.C. Chapter 85 (sections 7401-7671q), is the principal US statute for controlling air pollution, administered by the US Environmental Protection Agency (EPA) in cooperation with the States. Section 7401 sets the findings and purposes. Section 7409 directs EPA to establish national primary and secondary ambient air quality standards (NAAQS) for criteria pollutants, and section 7410 requires each State to adopt and submit a state implementation plan (SIP) providing for the implementation, maintenance and enforcement of the NAAQS. Section 7411 establishes standards of performance for new stationary sources (NSPS), and section 7412 establishes the program for hazardous air pollutants, including technology-based emission standards (MACT). Section 7475 sets the preconstruction requirements for major emitting facilities in attainment areas under the Prevention of Significant Deterioration (PSD) program, while sections 7502-7503 set the nonattainment area plan and permit requirements (including nonattainment new source review). Section 7521 sets emission standards for new motor vehicles and engines. Sections 7661-7661f establish the Title V operating permit program, under which major sources must obtain and comply with a comprehensive operating permit. Section 7413 provides for federal enforcement: EPA may assess administrative penalties of up to $25,000 per day of violation, may seek civil judicial penalties of not more than $25,000 per day for each violation, and may pursue criminal penalties for knowing violations of a fine under title 18 or imprisonment of not more than five years (with the maximum punishment doubled on a subsequent conviction); a knowing release that places another in imminent danger of death or serious bodily injury (knowing endangerment) is punishable by a fine under title 18 or imprisonment of not more than fifteen years, or both, and an organization by a fine of not more than $1,000,000 for each violation. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-clean-air-act-42-usc-7401-findings-purposes-air-quality",
    "title": "42 U.S. Code § 7401 - Congressional findings and declaration of purpose",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article establishes the foundational goals of U.S. air quality law, emphasizing the protection of public health and welfare, assigning primary responsibility for air pollution control to State and local governments, and encouraging federal support for research, development, and regional programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-clean-air-act-42-usc-7479-prevention-significant-deterioration-permits",
    "title": "42 U.S. Code § 7479 - Definitions",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This article defines key terms such as 'major emitting facility', 'best available control technology', and 'baseline concentration' which establish the criteria for air pollution permitting and control requirements under the Prevention of Significant Deterioration program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-clean-air-act-42-usc-ch85",
    "title": "United States Clean Air Act (Title 42 USC Chapter 85): National Ambient Air Quality Standards, State Implementation Plans, New Source Performance Standards, Hazardous Air Pollutants, Mobile Source Emissions, and Citizen Suits",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Clean Air Act, codified at Title 42 of the United States Code, Chapter 85, is the principal federal statute regulating air pollution in the United States and is administered by the Environmental Protection Agency. Clean Air Act, 42 U.S.C. 7401 contains the Congressional findings and declaration of purpose, opening with the finding that the predominant part of the Nation's population is located in its rapidly expanding metropolitan and other urban areas, generating dangers to public health and welfare from air pollution. Subchapter I covers programs and activities including Clean Air Act, 42 U.S.C. 7409 on national primary and secondary ambient air quality standards (NAAQS) for criteria pollutants, Clean Air Act, 42 U.S.C. 7410 on state implementation plans (SIPs) to achieve and maintain NAAQS, Clean Air Act, 42 U.S.C. 7411 on standards of performance for new stationary sources (NSPS), and Clean Air Act, 42 U.S.C. 7412 on hazardous air pollutants (HAPs) with technology-based and risk-based standards. Subchapter II covers emission standards for moving sources including Clean Air Act, 42 U.S.C. 7521 on emission standards for new motor vehicles and Clean Air Act, 42 U.S.C. 7545 on regulation of fuels. Subchapter III contains general provisions including Clean Air Act, 42 U.S.C. 7602 on definitions and Clean Air Act, 42 U.S.C. 7604 on citizen suits. Subchapter IV addresses noise pollution. Subchapter IV-A covers acid deposition control. Subchapter V covers permits including Title V operating permits for major sources. Subchapter VI covers stratospheric ozone protection. Subchapter VII covers American Innovation and Manufacturing on hydrofluorocarbon phasedown. The Act is the controlling federal instrument for federal air pollution regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-clean-air-act-construction-permits-nsr",
    "title": "US Clean Air Act New Source Review (NSR) - Construction Permit Requirements for Major Stationary Sources and Best Available Control Technology",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The New Source Review (NSR) program under the Clean Air Act requires major stationary sources of air pollution to obtain a pre-construction permit that mandates the installation of state-of-the-art pollution controls and an analysis of air quality impacts. This applies to new facilities or existing facilities making a major modification that significantly increases emissions, as outlined in CAA Sections 165 and 173.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-clean-air-act-mobile-source-emission-standards",
    "title": "Clean Air Act Section 202 - Standards of Performance for New Motor Vehicles or New Motor Vehicle Engines",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The US Clean Air Act Section 202 authorizes the EPA to establish federal emission standards for new light-duty vehicles, light-duty trucks, and medium-duty passenger vehicles to limit greenhouse gases (GHGs) and criteria pollutants. These standards apply to all manufacturers producing or importing such vehicles for sale in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-paris-agreement-ndc-implementation-guidelines",
      "iso-14001-ems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-clean-air-act-naaqs-utilities",
    "title": "US Clean Air Act National Ambient Air Quality Standards (NAAQS) - SO2, NOx, PM2.5 Compliance for Power Plants and State Implementation Plans",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The US Clean Air Act, under Sections 109 and 110, requires the EPA to set National Ambient Air Quality Standards (NAAQS) for criteria pollutants like SO2, NOx, and PM2.5, and mandates that states develop State Implementation Plans (SIPs) to ensure these standards are met and maintained, directly regulating emissions from major sources like power plants.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-clean-air-act-title-iv-acid-rain-so2-nox-epa",
    "title": "US Clean Air Act Title IV - Acid Rain Program SO2 and NOx Cap-and-Trade",
    "domain": "Energy & Utilities",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Clean Air Act Title IV establishes the Acid Rain Program - a mandatory cap-and-trade system for sulfur dioxide (SO2) and nitrogen oxide (NOx) emissions from power plants - requiring annual allowance surrender, CEMS installation, and EPA permit compliance. Penalties up to $25,000 per day per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-clean-water-act",
    "title": "US Clean Water Act: Discharge Prohibition, NPDES Permits, Dredge-and-Fill and Penalties",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Clean Water Act (CWA), formally the Federal Water Pollution Control Act, codified at 33 U.S.C. Chapter 26 (sections 1251-1389), is the principal US statute governing the discharge of pollutants into the waters of the United States and the quality of surface waters, administered by the US Environmental Protection Agency (EPA) together with authorized states and the US Army Corps of Engineers. Section 1311(a) establishes the core prohibition: the discharge of any pollutant by any person is unlawful except in compliance with stated sections, including the effluent limitations (1311, 1312), new source performance standards (1316), toxic and pretreatment standards (1317), the National Pollutant Discharge Elimination System (NPDES) permit program (1342) and the dredged-or-fill material permit program (1344). Section 1313 requires states to adopt water quality standards; section 1318 confers records, reporting, monitoring and inspection authority. Section 1342 authorizes the EPA (or an EPA-approved state program) to issue NPDES permits, for fixed terms not exceeding five years, that impose technology-based and water-quality-based effluent limitations and monitoring conditions. Section 1344 governs permits, issued by the Army Corps of Engineers, for the discharge of dredged or fill material into navigable waters. Section 1321 imposes liability and notification duties for discharges of oil and hazardous substances. Section 1319 sets enforcement and penalties: administrative penalties up to $25,000 (Class I) or $125,000 (Class II); civil penalties up to $25,000 per day per violation; criminal penalties for negligent violations ($2,500-$25,000 per day and up to one year), knowing violations ($5,000-$50,000 per day and up to three years), and knowing endangerment (up to $250,000 and 15 years for individuals, up to $1,000,000 for organizations), with all amounts doubled for subsequent offences. Section 1365 authorizes citizen suits. Section 1362 supplies the key definitions of 'pollutant', 'point source', 'discharge of a pollutant' and 'navigable waters'.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-clean-water-act-1972-epa-corps-engineers",
    "title": "US Clean Water Act 1972 - NPDES Permitting, Section 404 Dredge-Fill and Water Quality Standards Framework",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The US Clean Water Act (CWA, Federal Water Pollution Control Act Amendments of 1972, 33 USC 1251 et seq.) is the principal federal statute governing water pollution. EPA administers Section 402 National Pollutant Discharge Elimination System (NPDES) permits for point source discharges. The Army Corps of Engineers administers Section 404 permits for dredge-and-fill activities in navigable waters and wetlands. Section 303 requires states to set water quality standards and identify impaired water bodies (303(d) list). Section 319 addresses nonpoint source pollution. The WOTUS (Waters of the United States) rule defines federal jurisdiction. CWA enforcement includes civil penalties up to USD 64,618/day and criminal penalties for knowing violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-water-act-2007-murray-darling-basin",
      "us-federal-insecticide-fungicide-rodenticide-act-fifra"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-clean-water-act-33-usc-ch26",
    "title": "United States Clean Water Act (Title 33 USC Chapter 26): National Goal to Restore and Maintain Integrity of Waters, Effluent Limitations, Water Quality Standards, NPDES Permits, Dredged or Fill Material Permits, Citizen Suits, and State Authority",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Federal Water Pollution Control Act, commonly cited as the Clean Water Act and codified at Title 33 of the United States Code, Chapter 26, is the principal federal statute regulating discharges of pollutants into the waters of the United States and is administered by the Environmental Protection Agency in coordination with the United States Army Corps of Engineers. Clean Water Act, 33 U.S.C. 1251 declares the Congressional goals and policy: the objective of this chapter is to restore and maintain the chemical, physical, and biological integrity of the Nation's waters. Subchapter I (sections 1251 through 1276b) covers research and related programs. Subchapter II (sections 1281 through 1302f) covers grants for construction of treatment works. Subchapter III covers standards and enforcement including Clean Water Act, 33 U.S.C. 1311 on effluent limitations and Clean Water Act, 33 U.S.C. 1313 on water quality standards and implementation plans. Subchapter IV covers permits and licenses including Clean Water Act, 33 U.S.C. 1342 on the National Pollutant Discharge Elimination System (NPDES) and Clean Water Act, 33 U.S.C. 1344 on permits for dredged or fill material. Subchapter V covers general provisions including Clean Water Act, 33 U.S.C. 1362 on definitions, Clean Water Act, 33 U.S.C. 1365 on citizen suits, and Clean Water Act, 33 U.S.C. 1370 on state authority. Subchapter VI covers state water pollution control revolving funds. The Act is the controlling federal instrument for water pollution control in the United States and is enforced through administrative orders, civil judicial actions, criminal prosecutions, and citizen suits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-clean-water-act-construction-stormwater",
    "title": "US Clean Water Act - Construction Site Stormwater: NPDES Construction General Permit, SWPPP Requirements, Best Management Practices, Discharge Authorisation and Notice of Termination",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires operators of construction activities that disturb one acre or more, or part of a larger common plan of development, to obtain an NPDES permit before discharging stormwater. Compliance includes developing a Stormwater Pollution Prevention Plan (SWPPP) and implementing best management practices (BMPs) to control pollutants in runoff. Key authority is derived from the NPDES stormwater program as administered by EPA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-section-404-construction",
      "iso-19650-bim-information-management-construction",
      "iso-21500-project-management-construction-guidance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-clean-water-act-section-404-construction",
    "title": "Clean Water Act Section 404 - Discharge of Fill Material into Waters: Corps of Engineers Permit Programme, Wetland Delineation and Mitigation Banking",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The US Clean Water Act Section 404 requires that any discharge of fill material into waters of the United States, including wetlands, must obtain a permit from the US Army Corps of Engineers, as stated in 33 U.S.C. § 1344. This applies to construction projects that involve the discharge of dredged or fill materials into waters of the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-clery-act-34-cfr-668-campus-security-reporting",
    "title": "34 CFR Part 668 Subpart D - Institutional and Financial Assistance Information for Students",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Institutions must collect, maintain, and disclose specific information regarding institutional policies, financial assistance, completion rates, campus security, crime statistics, and fire safety to students and the public.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-clia-laboratory-certification",
    "title": "US Clinical Laboratory Improvement Amendments (42 USC 263a): Laboratory Certification and Quality",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Clinical Laboratory Improvement Amendments, CLIA (42 U.S.C. 263a), require that clinical laboratories examining human specimens for the diagnosis, prevention or treatment of disease, or the assessment of health, hold a certificate issued by the Secretary of Health and Human Services, with the program administered by the Centers for Medicare and Medicaid Services. Section 263a prohibits a laboratory from soliciting or accepting human specimens for examination unless it has a valid certificate applicable to the category of examinations performed. The statute establishes a tiered framework based on test complexity. A certificate of waiver is available for simple laboratory examinations and procedures that have an insignificant risk of an erroneous result, where the methodology is so simple and accurate as to render the likelihood of an erroneous result by the user negligible. Tests of moderate and high complexity are subject to requirements for personnel qualifications, quality control and quality assurance, proficiency testing, and inspection. The Secretary may suspend, revoke or limit a certificate, impose intermediate sanctions and civil money penalties, and cancel approval to receive Medicare payment for a noncompliant laboratory. The Act is the legal foundation for US clinical laboratory quality regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-clinger-cohen-act-40-usc-11101",
    "title": "Clinger-Cohen Act 1996 - 40 USC 11101 Information Technology Management Reform",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 11101 and following of title 40 of the United States Code codify the Clinger-Cohen Act (Information Technology Management Reform Act of 1996, Public Law 104-106 Divisions D and E), the principal federal statute governing acquisition and management of information technology by executive agencies. The Act repealed the Brooks Act centralised IT procurement framework, established the Chief Information Officer role in every covered federal agency (originally section 11315), assigned the Office of Management and Budget responsibility for agency IT investment oversight, required each agency to design an IT capital planning and investment control process linked to performance management, and instituted enterprise architecture as a planning discipline for federal IT. Section 11103 prescribes the application of the Act to executive agencies (excluding national security systems for certain provisions). Section 11315 (since renumbered as relevant) defines the CIO role, including responsibility for advising the head of the agency on IT investment, performance, security, and human capital. The Act underpins every subsequent federal IT-management statute including the E-Government Act of 2002, the Federal Information Security Modernization Act 2014, FITARA 2014, and the Modernizing Government Technology Act 2017. AI procurement, federal cloud authorisation, and federal cybersecurity investment decisions all flow through the Clinger-Cohen capital-planning and investment-control framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paperwork-reduction-act-44-usc-ch35"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cloud-act-2018",
    "title": "Clarifying Lawful Overseas Use of Data (CLOUD) Act 2018",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The CLOUD Act requires U.S.-based communication and cloud service providers to produce user data requested by U.S. law enforcement through a valid legal process (warrant, subpoena), regardless of where the data is stored globally. It also establishes a framework for international agreements to facilitate cross-border data access for law enforcement, as codified in 18 U.S.C. § 2713 and § 2523.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-sp-800-88-media-sanitization"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-cloud-act-2018-clarifying-lawful-overseas-use-of-data",
    "title": "US CLOUD Act 2018 - Government Access to Data Stored Overseas and Provider Obligations",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Clarifying Lawful Overseas Use of Data (CLOUD) Act (18 U.S.C. § 2713) requires US providers to disclose customer data in response to lawful US law enforcement process regardless of where the data is stored. It also establishes a framework for bilateral executive agreements that can override US law enforcement access for foreign nationals' data. Cloud providers must assess the conflict-of-laws risk between CLOUD Act obligations and foreign data protection laws (GDPR, UK GDPR, PIPL).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-data-act-2023-1257-data-sharing-iot-switching"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cloud-act-2018-cross-border-data",
    "title": "Clarifying Lawful Overseas Use of Data (CLOUD) Act - US Provider Obligation to Produce Data Stored Abroad, Executive Agreement Framework for Bilateral Data Access, Comity Challenge Procedure, Conflict of Laws Analysis and DOJ Guidance on Qualifying Executive Agreements",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The CLOUD Act enables the U.S. to enter into bilateral executive agreements with foreign countries that have robust privacy and civil liberties protections, allowing those countries to request electronic data directly from U.S.-based service providers for the purpose of countering serious crime, provided the data is subject to U.S. jurisdiction under the Stored Communications Act. It also clarifies that U.S. providers must comply with lawful orders for data regardless of where the data is stored. See CLOUD Act, March 2018.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-money-laundering-regulations-2017-amended"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cmmc-2-0-defence-contractors-levels",
    "title": "US CMMC 2.0 Cybersecurity Maturity Model Certification",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires US defence contractors to achieve Level 1, 2, or 3 certification, as outlined in FAR 52.204-21, NIST 800-171, and NIST 800-172, with specific requirements detailed in Section 204.75 of the Federal Acquisition Regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-800-53-ac2",
      "nist-800-53-au2",
      "c-scrm-practices-systems-organizations"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cmmc-2-0-defense-industrial-base-2021",
    "title": "Cybersecurity Maturity Model Certification (CMMC) 2.0 - Three-Level Framework for Defense Contractors Handling Controlled Unclassified Information (CUI) and Federal Contract Information (FCI)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The CMMC 2.0 framework mandates that all organizations within the Defense Industrial Base (DIB) implement cybersecurity practices aligned with one of three certification levels (1, 2, or 3) based on the type of information handled; specifically Federal Contract Information (FCI) or Controlled Unclassified Information (CUI); as established by the CMMC Program rule at 32 CFR Part 170 and the corresponding DFARS clauses. Compliance is required for all Department of Defense (DoD) contractors and subcontractors to bid on or perform work under DoD contracts involving CUI or FCI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-800-53-ac2",
      "nist-800-53-au2",
      "nist-800-53-sc7",
      "c-scrm-practices-systems-organizations",
      "assessing-security-privacy-controls"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cmmc-final-rule-32-cfr-170-2024",
    "title": "US Cybersecurity Maturity Model Certification (CMMC) Program Final Rule, 32 CFR Part 170, Effective 16 December 2024 - Three-Tier Certification Framework, Four-Phase Implementation, NIST SP 800-171 R2 / 800-172 Anchored Requirements, C3PAO and DIBCAC Assessment Pathways",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "On 15 October 2024 the Department of Defense published the CMMC Program final rule at 89 FR 83092, codified at 32 CFR Part 170, with an effective date of 16 December 2024. The rule operationalises the Cybersecurity Maturity Model Certification 2.0 framework as binding federal regulation governing how DoD contractors and subcontractors safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The rule establishes three certification levels: Level 1 requires self-assessment and 100% implementation of the 15 security requirements at FAR clause 52.204-21(b)(1)(i)-(xv) for FCI handling (Section 170.15); Level 2 requires implementation of all 110 NIST SP 800-171 Revision 2 security requirements for CUI handling, with the contract specifying either self-assessment (Section 170.16) or C3PAO third-party certification (Section 170.17); Level 3 requires the 110 NIST SP 800-171 R2 requirements plus 24 selected requirements from NIST SP 800-172 (February 2021) per Table 1 to Section 170.14(c)(4), assessed by the DCMA Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) under Section 170.18. Plans of Action and Milestones (POA&M) are permitted at Levels 2 and 3 only when the assessment achieves a minimum passing score of 80 percent and contains only POA&M-permittable requirements as listed in Section 170.21; all NOT MET requirements on a POA&M must be remediated and validated by a closeout assessment within 180 days of the Conditional CMMC Status, after which the Conditional Status expires and standard contractual remedies apply. The rule implements through a four-phase plan over a three-year period (Section 170.3(e)): Phase 1 introduces self-assessment requirements; Phases 2 and 3 progressively add Level 2 and Level 3 certification requirements; Phase 4 represents full implementation. A companion 48 CFR Part 204 CMMC Acquisition rule will amend the DFARS to permit contracting officers to require a specific CMMC level in solicitations; until the acquisition rule is final, DoD may include CMMC requirements on existing contracts only by bilateral modification. CMMC requirements flow down to subcontractors at all tiers when the subcontractor processes, stores, or transmits FCI or CUI. CMMC self-assessment scores and certification credentials are recorded in the Supplier Performance Risk System (SPRS), and contracting officers may not award, exercise an option on, or extend a contract without a current passing score and an affirmation of continuous compliance. DoD estimates approximately 8,350 medium and large entities will require Level 2 C3PAO certification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cmmc-2-0-defence-contractors-levels",
      "us-dod-cybersecurity-maturity-model-cmmc-2-2021",
      "us-fedramp-authorization-moderate",
      "nist-csf-2-0-cybersecurity-framework-2024"
    ],
    "primary_citations_count": 19
  },
  {
    "node_id": "us-cms-42-cfr-411-medicare-secondary-payer",
    "title": "42 CFR Part 411 - CMS Medicare Secondary Payer Rules and Recovery",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "42 CFR Part 411 implements the Medicare Secondary Payer (MSP) rules administered by the U.S. Centers for Medicare & Medicaid Services, and sets out certain exclusions from Medicare coverage. Where another payer is primary to Medicare, that primary payer and entities that received payment from it have reimbursement obligations, and Medicare may make conditional payments that must be repaid. The beneficiary must cooperate in Medicare's recovery, and Medicare may recover conditional payments, including through subrogation and a right to intervene. A primary payer must give notice of its primary payment responsibility, and CMS may waive recovery or compromise claims in defined circumstances. The Part also identifies particular services excluded from Medicare coverage. These rules ensure Medicare pays secondary to liability, no-fault, workers' compensation and group health plan coverage as required by law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-privacy-rule",
      "hipaa-security-rule",
      "hitech-act-2009"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-cms-conditions-participation-hospitals-42-cfr-482-medicare-medicaid",
    "title": "US CMS Conditions of Participation for Hospitals - 42 CFR Part 482 Medicare and Medicaid",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "The Centers for Medicare and Medicaid Services (CMS) Conditions of Participation (CoPs) at 42 CFR Part 482 establish minimum health and safety standards that hospitals must meet to receive Medicare and Medicaid reimbursement. CoPs cover governing body, medical staff, nursing services, pharmaceutical services, radiological services, laboratory services, food and dietetic services, utilization review, physical environment, infection control, discharge planning, and medical records. Compliance is surveyed by accreditation organisations (The Joint Commission, DNV GL) or State survey agencies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-hipaa-hitech-phi-breach-notification-rule-45-cfr-164"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cms-interoperability-prior-auth-2024",
    "title": "CMS Advancing Interoperability and Improving Prior Authorization Processes Final Rule (CMS-0057-F)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-07-22",
    "bluf": "This rule requires impacted payers (Medicare Advantage, Medicaid, CHIP, and QHP issuers) to implement and maintain specific FHIR-based APIs to improve patient data exchange and automate prior authorization processes. Key requirements under 42 CFR § 422.120 mandate the implementation of a Prior Authorization Requirements, Documentation and Decision (PARDD) API and specific decision timeframes by January 1, 2027.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cms-interoperability-rule-2020",
      "hl7-fhir-v4-interop",
      "hipaa-security-rule",
      "us-21st-century-cures-act-2016"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cms-interoperability-rule-2020",
    "title": "Medicare and Medicaid Programs; Patient Protection and Affordable Care Act; Interoperability and Patient Access for Medicare Advantage Organization and Medicaid Managed Care Plans, State Medicaid Agencies, CHIP Agencies and CHIP Managed Care Entities, Issuers of Qualified Health Plans on the Federally-Facilitated Exchanges, and Health Care Providers",
    "domain": "Medical & Healthcare",
    "version": "1.1.0",
    "last_updated": "2026-07-03",
    "bluf": "This rule requires CMS-regulated payers to implement and maintain a secure, standards-based Patient Access API using HL7 FHIR Release 4, enabling patients to access their claims, encounter, and clinical data via third-party applications. The Patient Access API mandate is codified at 42 CFR § 422.119 for Medicare Advantage, 42 CFR § 431.60 for Medicaid, 42 CFR § 457.730 for CHIP, and 45 CFR § 156.221 for QHP issuers on the Federally-Facilitated Exchanges. The rule also includes provisions to prevent information blocking and enhance data exchange between payers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-21st-century-cures-act-2016",
      "hl7-fhir-v4-interop",
      "hipaa-security-rule"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-co-cpa-2021",
    "title": "Colorado Privacy Act 2021 (CPA)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Colorado SB 190 signed July 7, 2021 effective July 1, 2023 (sensitive data provisions January 1, 2024) grants Colorado residents rights to access, correction, deletion, portability, and opt-out of targeted advertising, data sale, and profiling for consequential decisions, applying to controllers processing personal data of 100,000 or more Colorado residents or 25,000 with 50% revenue from data sales, with AG and district attorney enforcement and USD 20,000 per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-co-cpa-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-co-sb205-high-risk-ai",
    "title": "Colorado AI Act (SB 205) - High-Risk Systems",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "US state-level regulatory requirements for developers and deployers of high-risk AI systems making consequential decisions, mandating algorithmic discrimination audits and consumer opt-out rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-iec-24027-bias-fairness"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-coast-guard-vessel-documentation-46-cfr-67-jones-act-cabotage",
    "title": "US Coast Guard Vessel Documentation 46 CFR 67 - Jones Act Cabotage and US Coastwise Trade Restrictions",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "The Jones Act (46 USC Chapter 551) requires that merchandise transported by water between US ports be carried on vessels that are US-built, US-owned, US-registered, and crewed by US citizens or permanent residents, with Coast Guard vessel documentation under 46 CFR Part 67 providing coastwise trade endorsement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fcc-telecommunications-act-1996-47-usc-151-open-access-interoperability",
      "us-nepa-1970-environmental-impact-assessment"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-coastal-barrier-resources-act",
    "title": "US Coastal Barrier Resources Act (16 USC 3501 et seq.): The John H. Chafee System and the Restriction on Federal Expenditures",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Coastal Barrier Resources Act (CBRA), codified at 16 U.S.C. 3501 et seq., protects undeveloped coastal barriers by removing the federal financial incentives that subsidise their development, administered by the U.S. Fish and Wildlife Service within the Department of the Interior. Section 3501 sets out the Congressional findings and purposes: it finds that coastal barriers provide essential habitat, serving as spawning, nursery, nesting and feeding areas for commercially and recreationally important species, and that certain federal actions and programs have subsidised and permitted development on coastal barriers, resulting in the loss of barrier resources and threats to human life, health and property; and it declares the purpose of minimising the loss of human life, the wasteful expenditure of federal revenues and the damage to fish, wildlife and other natural resources by restricting future federal expenditures and financial assistance that have the effect of encouraging development of coastal barriers, through the establishment of the John H. Chafee Coastal Barrier Resources System. Section 3503 establishes the System by designating specific undeveloped coastal barrier units, depicted on official maps. Section 3504 imposes the core mechanism: with limited exceptions, no new federal expenditures or financial assistance may be made available within the System for activities that encourage development, including federal flood insurance under the National Flood Insurance Program. The Act does not prohibit private development; it withdraws the federal subsidy, leaving the cost and risk with those who choose to build. The Act is the federal instrument that uses fiscal restraint, rather than regulation, to discourage development of environmentally sensitive coastal barriers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-coastal-zone-management-act",
    "title": "US Coastal Zone Management Act (16 USC ch 33): State Programs and the Federal Consistency Requirement",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Coastal Zone Management Act of 1972 (CZMA), codified at 16 U.S.C. Chapter 33 (sections 1451-1466), establishes a voluntary federal-state partnership to manage and protect the nation's coastal zone, administered at the federal level by the National Oceanic and Atmospheric Administration (NOAA) Office for Coastal Management. Section 1451 sets the congressional findings, section 1452 declares the national policy to preserve, protect, develop and where possible restore and enhance coastal resources, and section 1453 defines the terms, including the 'coastal zone'. Section 1454 provides for the submittal of a State coastal management program for federal approval, and section 1455 provides administrative grants to States with approved programs. Section 1455b addresses the protection of coastal waters through coastal nonpoint pollution control programs. The central regulatory mechanism is the federal consistency requirement in section 1456(c): each Federal agency activity within or outside the coastal zone that affects any land or water use or natural resource of the coastal zone shall be carried out in a manner which is consistent to the maximum extent practicable with the enforceable policies of approved State management programs; and under section 1456(c)(3), an applicant for a required Federal license or permit to conduct an activity affecting the coastal zone must provide a certification that the activity complies with the State's approved program, with the State having up to six months to concur or object before concurrence is conclusively presumed. Section 1458 provides for periodic review of State performance. The CZMA does not impose civil or criminal penalties on private parties for ordinary noncompliance; its enforcement operates through the consistency review (which can block or condition a federal action, license or permit), the grant conditions, and the federal performance review that can suspend or withdraw program approval and funding.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-coastal-zone-management-act-1972",
    "title": "US Coastal Zone Management Act 1972 - NOAA Federal Consistency Review, State Coastal Programmes and National Estuarine Research Reserves",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Coastal Zone Management Act of 1972 (CZMA, Public Law 92-583, codified at 16 USC 1451-1466, enacted 27 October 1972) is the foundational US federal statute governing land and water use in coastal zones. It is administered by the National Oceanic and Atmospheric Administration (NOAA) Office for Coastal Management within the Department of Commerce. CZMA establishes a voluntary partnership programme under which 34 of 35 eligible coastal states and territories have NOAA-approved coastal management programmes (CMPs); Illinois is the sole eligible non-participant. Section 307 (16 USC 1456) federal consistency review is the principal regulatory teeth: federal agency activities, federal license or permit activities, federal financial assistance, and OCS plans affecting coastal use or resources must be consistent with the enforceable policies of an approved state CMP. Section 315 (16 USC 1461) authorises 30 National Estuarine Research Reserves (NERRS) protecting 1.3 million acres. Section 306A (16 USC 1455a) coastal resource improvement grants and Section 309 (16 USC 1456b) enhancement grants are the primary funding mechanisms. Coastal Nonpoint Pollution Control Program under Section 6217 of the Coastal Zone Act Reauthorisation Amendments 1990 requires states to address coastal water pollution from nonpoint sources.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-colorado-ai-act-sb24-205",
    "title": "Colorado Senate Bill 24-205 - Consumer Protections for Artificial Intelligence Act (2024 Session Laws of Colorado, Effective 1 February 2026) - First US Comprehensive AI Law",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-05-17",
    "bluf": "Colorado Senate Bill 24-205, the 'Consumer Protections for Artificial Intelligence' act, signed by Governor Jared Polis on 17 May 2024 (2024 Session Laws of Colorado), is the first comprehensive United States artificial intelligence law and takes substantive effect on 1 February 2026. The act regulates 'high-risk artificial intelligence systems' (high-risk systems) by imposing distinct duties on two regulated parties: developers (entities that build, intentionally and substantially modify, or make available high-risk systems) and deployers (entities that use high-risk systems). The core duty for both is to use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination. The act creates a rebuttable presumption that reasonable care was used if the regulated party complies with enumerated provisions. For developers these include: (i) making available to deployers a statement disclosing specified information about the high-risk system; (ii) making available information and documentation necessary to complete an impact assessment; (iii) maintaining a publicly available statement summarising the types of high-risk systems developed or substantially modified and how risks are managed; (iv) disclosing to the Colorado Attorney General and known deployers/other developers any known or reasonably foreseeable risks of algorithmic discrimination within 90 days after discovery or receipt of a credible report. For deployers these include: (i) implementing a risk management policy and program; (ii) completing an impact assessment; (iii) annually reviewing each deployment to ensure the system is not causing algorithmic discrimination; (iv) notifying consumers of specified items where the system makes or is a substantial factor in making a consequential decision concerning the consumer; (v) providing consumers an opportunity to correct incorrect personal data processed in a consequential decision; (vi) providing consumers an opportunity to appeal - via human review where technically feasible - an adverse consequential decision; (vii) maintaining a publicly available statement summarising deployments and risk management; (viii) disclosing to the Attorney General any discovery of algorithmic discrimination caused by the high-risk system within 90 days. Any person doing business in Colorado that deploys or makes available an AI system intended to interact with consumers must disclose to each consumer that they are interacting with an AI system. The act provides specified exemptions (compliance with other laws; cooperation with investigations; protection of life or physical safety; research; product recall or technical-error repair) and an affirmative defense for parties in compliance with a nationally or internationally recognised AI risk management framework designated by the act or the Attorney General, provided they take specified discovery-and-correction measures. Insurers, fraternal benefit societies, banks, credit unions and their affiliates are deemed in full compliance under specified circumstances by virtue of existing prudential or insurance-commissioner regimes. Enforcement: the Colorado Attorney General has exclusive enforcement authority and rule-making authority; violations are deceptive trade practices under the Colorado Consumer Protection Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act_high_risk",
        "nist_ai_rmf",
        "iso_iec_42001_2023",
        "colorado_consumer_protection_act",
        "us_state_ai_law_landscape"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-article-6-classification-high-risk",
      "eu-ai-act-article-14-human-oversight",
      "eu-ai-act-article-10-data-governance-training",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-colorado-hb24-1058-2024-neural-data-privacy",
    "title": "US Colorado HB24-1058 (2024) Protect Privacy of Biological Data Including Neural Data",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2024-04-17",
    "bluf": "Colorado House Bill 24-1058 was signed into law by Governor Jared Polis on 17 April 2024 and is the first US state law to expressly protect neural data as sensitive personal information under a consumer privacy framework. The Act amends the Colorado Privacy Act (Title 6 Article 1 Part 13 of the Colorado Revised Statutes) by expanding the definition of sensitive personal information to include biological data and neural data. The Act applies to controllers that conduct business in Colorado or produce or deliver commercial products or services intentionally targeted to Colorado residents and that meet the Colorado Privacy Act's thresholds.\n\nThe Act defines neural data as information that is generated by the measurement of the activity of an individual's central or peripheral nervous system that can be processed by or with the assistance of a device. Sensitive data including neural data may not be processed without the consumer's consent under Colorado Revised Statutes section 6-1-1308. Controllers must conduct data protection impact assessments before processing sensitive data and provide consumers with the rights of access, correction, deletion, data portability, and opt-out of targeted advertising, sale, and profiling. Enforcement is by the Colorado Attorney General with civil penalties up to USD 20,000 per violation under the Colorado Consumer Protection Act and a 60-day right to cure period during the initial period of the Colorado Privacy Act. California and Montana enacted similar neural data protections in 2024 and 2025, signalling an emerging US state legislative trend.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ccpa-cpra"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-colorado-privacy-act-2021",
    "title": "Colorado Privacy Act (CPA) of 2021",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Colorado Privacy Act (CPA) grants Colorado residents rights over their personal data, including access, correction, deletion, and opt-out of targeted advertising, sale of personal data, or profiling. It imposes obligations on data controllers and processors that conduct business in Colorado or target its residents, requiring clear privacy notices, data protection assessments, and adherence to universal opt-out mechanisms as specified in C.R.S. § 6-1-1306(1)(a)(IV).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-colorado-sports-wagering-act-2020",
    "title": "Colorado Sports Betting Act 2020 - Limited Gaming Control Commission Licensing",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Colorado legalised sports betting through Proposition DD (approved November 2019) and implemented through Senate Bill 20-111 and Colorado Revised Statutes 44-30-1501 et seq. The Colorado Limited Gaming Control Commission (LGCC) licenses sports betting operators who must be affiliated with a licensed Colorado casino. A 10% tax applies on net sports betting proceeds. Revenue funds the Colorado Water Plan. Sports betting launched on 1 May 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_paspa_repeal",
        "colorado_limited_gaming",
        "colorado_water_plan",
        "fatf_gambling_guidance",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
      "us-uigea-2006-unlawful-internet-gambling",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-commercial-space-launch-act",
    "title": "US Commercial Space Launch Act (51 USC ch 509): Launch Licensing, Insurance and Liability",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Commercial Space Launch Act (51 U.S.C. ch. 509) governs the licensing and regulation of commercial space launches, reentries and launch and reentry sites in the United States, administered by the Federal Aviation Administration through its Office of Commercial Space Transportation. Section 50901 sets the findings and purposes, including promoting a competitive private launch industry while protecting public health and safety, safety of property, and national security. Section 50902 supplies the definitions, and section 50903 sets the general authority of the Secretary of Transportation. Section 50904 restricts the launch of a launch vehicle, the operation of a launch or reentry site, and a reentry, requiring a license or permit unless an exception applies. Section 50905 sets the license applications and requirements, and section 50906 provides for experimental permits for reusable suborbital rockets. Section 50908 governs the effective periods, modification, suspension and revocation of licenses, and section 50907 provides for monitoring of licensed activities. Section 50914 imposes the liability insurance and financial responsibility requirements: a licensee must obtain insurance or demonstrate financial responsibility to cover claims by third parties and the US Government up to the maximum probable loss, and the section provides for the allocation and cross-waiver of liability. Section 50917 provides for enforcement and penalties. The Act is the legal foundation of US commercial spaceflight licensing and the launch-liability regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-commercial-space-launch-act-1984-amendments",
    "title": "Commercial Space Launch Act of 1984, as Amended by the Commercial Space Launch Competitiveness Act of 2015 (Title IV of H.R. 2262, 114th Congress)",
    "domain": "Space & Satellite Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes licensing requirements for commercial launch, reentry, and operation of launch sites by private entities in the United States, administered by the FAA's Office of Commercial Space Transportation (AST). It mandates financial responsibility for third-party liability up to a maximum probable loss (MPL) determined by the Secretary of Transportation under 51 U.S.C. § 50907, with a learning period moratorium on crew safety regulations under 51 U.S.C. § 50919.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itu-radio-regulations-2020-edition",
      "un-liability-convention-1972-space-objects"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-commercial-space-launch-competitiveness-act-2015",
    "title": "US Commercial Space Launch Competitiveness Act 2015 (CSLCA) - Space Resource Rights and Commercial Space Regulatory Reform",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The US Commercial Space Launch Competitiveness Act (CSLCA, Pub. L. 114-90, enacted 25 November 2015) made three landmark changes to US commercial space law: (1) it extended the regulatory moratorium on FAA regulation of commercial human spaceflight through 2023 (the 'learning period'); (2) it enacted 51 USC Chapter 513 granting US citizens the right to own and sell resources extracted from asteroids and other celestial bodies in outer space; and (3) it directed the President to pursue bilateral and multilateral frameworks recognising space resource rights. The CSLCA did not assert US sovereignty over celestial bodies (consistent with OST Article II) but recognised the right of US citizens to possess, own, transport, use, and sell space resources they obtain. This position has been endorsed by the Artemis Accords (2020).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "outer_space_treaty",
        "artemis_accords_2020",
        "us_faa_part_460"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "artemis-accords-2020-lunar-governance",
      "us-commercial-space-launch-act-1984-amendments",
      "us-faa-part-460-human-space-flight-requirements"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-commercial-space-launch-competitiveness-act-2015-space-resources",
    "title": "US Commercial Space Launch Competitiveness Act 2015 - Title IV Space Resource Rights and Commercial Extraction Framework",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Title IV of the US Commercial Space Launch Competitiveness Act 2015 (CSLCA, also known as the SPACE Act) affirms the right of US citizens engaged in commercial recovery of asteroid or space resources to own, possess, transport, use, and sell any such resources obtained. The Act explicitly disclaims any US claim of sovereignty, national appropriation, or exclusive rights over any celestial body, distinguishing resource ownership from territorial appropriation. Title IV implements a US legal framework for commercial space resource extraction that is consistent with the US interpretation of OST Article 2 (non-appropriation) while providing property rights in extracted materials. The Act also streamlines FAA launch licensing for commercial operators under Title I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "intl-outer-space-treaty-1967-article-2-non-appropriation",
      "un-outer-space-treaty-1967-article-vi-state-responsibility"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-commodity-credit-corporation-charter-act",
    "title": "US Commodity Credit Corporation Charter Act (15 USC ch 15): Federal Financing of Agricultural Price Support",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Commodity Credit Corporation Charter Act (15 U.S.C. ch. 15, subchapter II, sections 714 to 714p) charters the Commodity Credit Corporation, a federally owned corporation within the Department of Agriculture that finances the price support, supply, and income programs of United States agriculture. Section 714 creates the Corporation and states its purpose of stabilizing, supporting, and protecting farm income and prices, assisting in maintaining balanced and adequate supplies of agricultural commodities, and facilitating their orderly distribution. Section 714b sets out the general powers of the Corporation and section 714c its specific powers, which include supporting prices through loans, purchases, payments, and other operations, and acquiring, storing, and disposing of commodities. Section 714e governs the capital stock of the Corporation, section 714f the use of funds, section 714g the Board of Directors, and section 714k records and the annual report. Section 714m defines crimes and offenses relating to the Corporation. The Corporation's authority to borrow is capped by statute, with obligations not exceeding 30,000,000,000 dollars outstanding at any one time under section 713a-4. The Act is the legal and financial backbone of United States commodity price support and farm income programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-commodity-exchange-act",
    "title": "US Commodity Exchange Act (7 USC ch 1): CFTC Jurisdiction, Contract Markets, Fraud and Manipulation",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Commodity Exchange Act (7 U.S.C. ch. 1) is the federal statute regulating the trading of commodity futures, options and swaps in the United States, administered by the Commodity Futures Trading Commission (CFTC). Section 1a supplies the definitions, including the terms commodity, future delivery and swap. Section 2 establishes the jurisdiction of the Commission over commodity-interest transactions, including the swaps jurisdiction added by the Dodd-Frank reforms, and addresses the liability of a principal for the acts of an agent. Section 5 states the findings and purpose. Section 6 governs the regulation of futures trading and foreign transactions, including the requirement that futures be traded on or subject to the rules of a registered entity. Section 6b prohibits contracts and conduct designed to defraud or mislead, and section 6c prohibits specified manipulative and prohibited transactions. Section 7 governs the designation of boards of trade as contract markets and the core principles they must meet. Enforcement is direct: section 9 prohibits manipulation and the delivery of false information and, with section 9a, provides for the assessment of civil money penalties, while section 25 confers private rights of action on persons injured by violations. The Act is the legal foundation of US derivatives market regulation, exchange oversight, and anti-manipulation enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-commodity-exchange-act-cftc-crypto-derivatives-regulation",
    "title": "US Commodity Exchange Act - CFTC Crypto Derivatives Regulation",
    "domain": "Crypto & Sovereign Finance",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Commodity Exchange Act (7 U.S.C. 1 et seq.) grants CFTC jurisdiction over crypto commodity derivatives including Bitcoin and Ether futures; the CFTC asserts that Bitcoin and Ether are commodities; crypto futures exchanges must register as Designated Contract Markets (DCM); retail leveraged crypto trading may require a Retail Foreign Exchange Dealer (RFED) registration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-commodity-promotion-research-information-act",
    "title": "US Commodity Promotion, Research, and Information Act of 1996 (7 USC ch 101): Generic Commodity Order Authority",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Commodity Promotion, Research, and Information Act of 1996 (7 U.S.C. ch. 101, sections 7411 to 7425) provides generic authority for the Secretary of Agriculture to issue orders establishing promotion, research, and information programs for agricultural commodities funded by assessments, administered through the Agricultural Marketing Service. Section 7411 sets out the findings and purpose, including that the maintenance and expansion of existing markets and development of new markets for agricultural commodities are vital to the welfare of persons engaged in production. Section 7412 defines the terms, including agricultural commodity, which encompasses agricultural products, livestock, poultry, forestry products, certified organic products, and processed items the Secretary determines appropriate. Section 7413 authorizes the issuance of orders, section 7414 sets the required terms in orders, including the establishment of a board with members appointed by the Secretary from producers, first handlers, importers, and potentially the general public, and section 7415 sets the permissive terms. Section 7416 sets the assessments, providing that assessments shall be paid by first handlers and by importers with respect to imported agricultural commodities. Section 7417 provides for referenda to determine producer support, section 7418 provides for petition and review of orders, and section 7419 provides for enforcement, including civil penalties of not less than 1,000 dollars nor more than 10,000 dollars for each violation and cease-and-desist authority. Section 7420 provides investigation and subpoena power, and section 7421 provides for suspension or termination. The Act is the federal generic checkoff order regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-common-rule-45-cfr-46-human-subjects-research",
    "title": "Protection of Human Subjects (Common Rule), 45 CFR Part 46",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The US Common Rule mandates that institutions conducting federally-funded human subjects research must protect the rights and welfare of participants through Institutional Review Board (IRB) oversight and by obtaining legally effective informed consent, as detailed in 45 CFR §46.111 and §46.116. This applies to all research involving human subjects conducted or supported by any federal department or agency that has adopted the policy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice",
      "nist-800-171-rev-3"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-communications-act-1934",
    "title": "US Communications Act of 1934 (47 USC ch 5): FCC Authority, Common-Carrier Duties, Radio Licensing and Penalties",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Communications Act of 1934 (47 U.S.C. ch. 5) is the foundational federal statute for the regulation of interstate and foreign wire and radio communication, administered by the Federal Communications Commission (FCC). Section 151 creates the FCC and states the Act's purpose of making available a rapid, efficient, nationwide communication service. Section 152 fixes the application of the chapter to interstate and foreign communication by wire and radio. Section 153 supplies the definitions, including telecommunications, common carrier and information service. For common carriers, section 201 requires service upon reasonable request at just and reasonable charges, and section 202 prohibits unjust or unreasonable discrimination in charges, practices and services. Section 214 requires a certificate of public convenience and necessity before a carrier extends lines or discontinues service. For radio, section 301 prohibits the transmission of energy or communications by radio without a license, section 303 enumerates the powers and duties of the Commission, and sections 307 to 309 govern the grant of, requirements for, and Commission action on license applications. Section 312 authorizes administrative sanctions, including revocation and denial of renewal of a station license. Enforcement is provided by section 501 (general criminal penalty), section 502 (penalties for violating Commission rules and regulations) and section 503 (civil forfeitures). The Act is the legal foundation of US telecommunications and broadcast regulation and the source of the FCC's licensing, common-carrier and enforcement powers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-communications-assistance-for-law-enforcement-act",
    "title": "US Communications Assistance for Law Enforcement Act (CALEA, 47 USC ch 9): Carrier Surveillance Capability",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Communications Assistance for Law Enforcement Act of 1994 (CALEA, 47 U.S.C. ch. 9) requires telecommunications carriers to design their equipment, facilities and services so that they can enable lawfully authorized electronic surveillance, administered by the Federal Communications Commission with the Department of Justice. Section 1001 supplies the definitions, including telecommunications carrier. Section 1002 sets the core assistance capability requirements: a carrier must ensure that its equipment and services are capable of expeditiously isolating and enabling the government, pursuant to a court order or other lawful authorization, to intercept communications and to access call-identifying information, while protecting the privacy of communications not authorized to be intercepted. Section 1003 governs notices of capacity requirements, section 1004 requires systems security and integrity (so that interceptions occur only with appropriate authorization and an officer's involvement), and section 1005 addresses the cooperation of equipment manufacturers and providers of telecommunications support services. Section 1006 provides for industry technical requirements and standards and a safe harbor for carriers that comply with them, and section 1007 provides for enforcement orders by the courts. Section 1008 governs the payment of the costs of compliance. The Act is the legal foundation of lawful-intercept capability in US telecommunications networks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-communications-decency-act-section-230",
    "title": "US Communications Decency Act Section 230 (47 USC 230): Platform Liability Shield and Good Samaritan Moderation",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 230 of the Communications Act (47 U.S.C. 230), enacted as part of the Communications Decency Act of 1996, governs the liability of online intermediaries for third-party content and is the foundational statute of US internet platform law. Subsection 230(a) records the congressional findings about the value of interactive computer services, and subsection 230(b) states the policy of preserving a competitive free market for the Internet with minimal regulation. Subsection 230(c)(1) contains the core shield: no provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider. Subsection 230(c)(2) is the Good Samaritan provision: it protects a provider or user from civil liability for good-faith actions to restrict access to material it considers objectionable, or for providing the technical means to restrict access. Subsection 230(d) requires notice to customers about parental-control protections. Subsection 230(e) sets the effect on other laws, preserving the enforcement of federal criminal law, intellectual property law, communications privacy law, and (under the 2018 FOSTA amendments) sex-trafficking law including civil claims under 18 U.S.C. 1595. Subsection 230(f) supplies the definitions, including interactive computer service and information content provider. The section is the legal foundation of content moderation and intermediary liability in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-community-reinvestment-act",
    "title": "US Community Reinvestment Act (12 USC ch 30): Meeting Community Credit Needs",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Community Reinvestment Act (12 U.S.C. ch. 30) requires that insured depository institutions help meet the credit needs of the communities in which they operate, including low- and moderate-income neighborhoods, consistent with safe and sound operation, enforced by the appropriate Federal financial supervisory agencies, namely the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation and the Federal Reserve. Section 2901 sets the congressional findings and purpose, recording that regulated financial institutions have a continuing and affirmative obligation to help meet the credit needs of their local communities. Section 2903 sets the core duty of the supervisory agency: in connection with its examination of an institution, the agency shall assess the institution's record of meeting the credit needs of its entire community, including low- and moderate-income neighborhoods, consistent with safe and sound operation, and shall take that record into account in evaluating an application for a deposit facility, such as a merger, acquisition or branch opening. Section 2906 requires the agency to prepare a written evaluation with a publicly disclosed rating. The Act does not impose loan quotas, but a poor record can lead to denial or conditioning of an application. It is the legal foundation for US assessment of bank lending to underserved communities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-community-reinvestment-act-cra-1977",
    "title": "US Community Reinvestment Act (CRA) - 12 USC 2901",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "CRA requires federally insured depository institutions to help meet credit needs of their entire communities, including low- and moderate-income (LMI) neighbourhoods, with performance evaluated under a three-tier bank-size framework (2023 final rule): large (≥$2B), intermediate ($600M-$2B), small (<$600M).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cfpb-dodd-frank-title-x-consumer-financial-protection",
      "us-glba-gramm-leach-bliley-act-1999",
      "us-fair-credit-reporting-act-fcra-1970"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-comprehensive-crime-control-act-1984-pl-98-473",
    "title": "US Comprehensive Crime Control Act of 1984 (Public Law 98-473) - Federal Sentencing Reform and Bail Reform",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Comprehensive Crime Control Act of 1984 enacted the Sentencing Reform Act creating the United States Sentencing Commission and the federal sentencing guidelines system, abolished federal parole for offenses committed after the guidelines took effect, enacted the Bail Reform Act of 1984 establishing pretrial detention based on risk to public safety and risk of flight, expanded asset forfeiture authority including civil and criminal forfeiture of proceeds and instrumentalities, established the Armed Career Criminal Act enhancements for repeat firearms offenders, and enacted the Insanity Defense Reform Act narrowing the federal insanity defense.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-rico-organized-crime-control-act-18-usc-1961"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-comprehensive-environmental-response-cercla",
    "title": "Comprehensive Environmental Response, Compensation, and Liability Act (CERCLA)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "CERCLA, also known as Superfund, imposes strict, joint and several liability on potentially responsible parties (PRPs) for the cleanup costs of sites contaminated with hazardous substances. As outlined in 42 U.S.C. § 9607 (Section 107), property owners, operators, generators, and transporters can be held liable regardless of fault, necessitating rigorous environmental due diligence like Phase I/II site assessments for real estate transactions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "us-nepa-1970-environmental-impact-assessment"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-computer-fraud-abuse-act-1986",
    "title": "Computer Fraud and Abuse Act of 1986, 18 U.S.C. § 1030",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The CFAA prohibits unauthorized access to protected computers and obtaining information, committing fraud, or causing damage through such access. It applies to individuals, organizations, and entities accessing computers involved in interstate or foreign commerce, with key enforcement under 18 U.S.C. § 1030(a)(2) and (a)(4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "apec-cbpr-system-2011",
      "au-privacy-act-1988",
      "contingency-planning-federal-information-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-computer-fraud-and-abuse-act",
    "title": "US Computer Fraud and Abuse Act (18 USC 1030): Unauthorized Computer Access Offenses",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Computer Fraud and Abuse Act (18 U.S.C. 1030) is the principal US federal anti-hacking statute, prosecuted by the Department of Justice and supporting a private civil action. Section 1030 criminalizes accessing a computer without authorization or exceeding authorized access. Subsection (a) sets out the offenses: obtaining national defense or restricted data; intentionally accessing a computer without authorization to obtain information from a financial institution, a Federal agency or any protected computer; accessing a nonpublic Federal Government computer; knowingly accessing a protected computer with intent to defraud and obtaining value; knowingly transmitting a program, code or command that intentionally causes damage to a protected computer; trafficking in passwords; and threatening to damage a protected computer for extortion. A protected computer includes a computer used by a financial institution or the Federal Government and a computer used in or affecting interstate or foreign commerce, which in practice reaches most internet-connected systems. Criminal penalties scale with the offense and prior convictions. Subsection (g) provides a civil action for a person who suffers damage or loss, available where the conduct involves at least one of the listed factors, such as loss aggregating at least 5,000 dollars in a one-year period, with a two-year limitation period. The Act is the legal foundation for US computer intrusion enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-congressional-budget-impoundment-control-act-1974-pl-93-344",
    "title": "US Congressional Budget and Impoundment Control Act of 1974 (Public Law 93-344) - Congressional Budget Process and Limits on Presidential Impoundment",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Congressional Budget and Impoundment Control Act of 1974 established the modern congressional budget process by creating the House and Senate Budget Committees, the Congressional Budget Office, and the annual concurrent budget resolution process, introduced statutory budget reconciliation as a tool for binding spending and revenue legislation, restructured the federal fiscal year to begin October 1, and constrained the prior executive practice of impounding appropriated funds by requiring rescission or deferral proposals to be transmitted to Congress with statutory timelines for congressional disapproval.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-anti-deficiency-act-31-usc-1341"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-connecticut-ai-act-sb2-2025",
    "title": "Connecticut SB 2 (2025) - Proposed Artificial Intelligence Act (Not Enacted; Died in the House)",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Connecticut Senate Bill No. 2 of the 2025 regular session was a proposed artificial intelligence bill addressing high-risk AI deployer and developer duties and the prevention of algorithmic discrimination. It is NOT law. SB 2 passed the Connecticut Senate on a 32-4 vote on 14-15 May 2025 but was not called for a vote in the House before the session ended and was recorded as dead on 4 June 2025; a substantially similar 2024 bill also died in the House. Because SB 2 was never enacted, it imposes no binding compliance obligations on any Connecticut entity. This node tracks the bill's proposed structure and status for monitoring purposes only; organisations seeking a binding governance baseline should rely on enacted instruments such as the EU AI Act (Regulation (EU) 2024/1689) for high-risk systems and voluntary frameworks (NIST AI RMF 1.0, ISO/IEC 42001:2023). Treat all references to SB 2 sections below as proposed provisions, not operative law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-connecticut-data-privacy-act-ctdpa-2022",
    "title": "Connecticut Data Privacy Act (CTDPA) - Public Act No. 22-15",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Connecticut Data Privacy Act (CTDPA) grants Connecticut residents rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of the processing of personal data for targeted advertising, sale, or profiling. The act applies to entities conducting business in Connecticut or targeting its residents that, in the preceding calendar year, controlled or processed the personal data of at least 25,000 consumers or controlled/processed the data of 25,000 consumers and derived over 25% of gross revenue from selling personal data (Public Act No. 22-15, Sec. 3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-35-dpia",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-consolidated-farm-and-rural-development-act",
    "title": "US Consolidated Farm and Rural Development Act (7 USC ch 50): Farm Real Estate, Operating and Emergency Loans",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Consolidated Farm and Rural Development Act (7 U.S.C. ch. 50, sections 1921 to 2009dd) is the principal federal statute authorizing direct and guaranteed agricultural credit and rural development lending, administered by the Secretary of Agriculture through the Farm Service Agency. The real estate loan provisions set out who is eligible and for what: section 1922 provides that the Secretary may make and insure farm ownership loans to farmers and ranchers, including entities controlled by farmers and ranchers engaged primarily and directly in farming or ranching, section 1923 sets the purposes, including acquiring or enlarging a farm or ranch, making capital improvements, and paying loan closing costs, and section 1925 limits the amount of farm ownership loans. Section 1926 authorizes loans for the development, use, and control of water and for the installation or improvement of drainage or waste-disposal facilities. The operating loan provisions in section 1941 set eligibility for farmers and ranchers engaged primarily and directly in farming or ranching, section 1942 sets the purposes, and section 1943 limits the amount. Section 1961 authorizes emergency loans to farmers and ranchers who are unable to obtain sufficient credit elsewhere, typically following a natural disaster. Section 1981 addresses the administering agency for the loan programs and section 1987 provides for debt adjustment and credit counseling. The Act is the statutory foundation of federal farm and rural credit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-construction-lien-mechanic-lien-overview",
    "title": "US Construction Lien Laws - Mechanic's Lien Rights, Preliminary Notice Requirements and Foreclosure Procedures by State",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "U.S. state-level statutes grant contractors, subcontractors, and suppliers (claimants) who provide labor or materials to a private construction project the right to file a mechanic's lien against the real property if they are not paid. This statutory right, which varies significantly by state, creates a security interest in the property, allowing the claimant to force its sale to recover the owed debt.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-consumer-product-safety-act",
    "title": "US Consumer Product Safety Act (15 USC ch 47): Product Safety Standards, Recalls and Penalties",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Consumer Product Safety Act (15 U.S.C. ch. 47) is a core US consumer protection statute that establishes the Consumer Product Safety Commission and authorizes it to regulate the safety of consumer products and to address those that present an unreasonable risk of injury. Section 2056 authorizes consumer product safety standards, including performance requirements and warnings, and section 2057 authorizes the banning of a hazardous product where no feasible standard would adequately protect the public. Section 2064 addresses substantial product hazards: a manufacturer, importer, distributor or retailer that obtains information reasonably supporting the conclusion that a product contains a defect that could create a substantial product hazard, or fails to comply with a standard, must immediately notify the Commission, and the Commission may order public notification, repair, replacement or refund. Section 2068 sets out the prohibited acts. Section 2069 sets civil penalties of up to 100,000 dollars for each violation, with a maximum of 15,000,000 dollars for any related series of violations, and section 2070 provides criminal penalties. The Act is the legal foundation for US consumer product safety regulation and recall obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-consumer-review-fairness-act-2016-crfa",
    "title": "Consumer Review Fairness Act",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Consumer Review Fairness Act (15 U.S.C. § 45b) voids form contract provisions that prohibit or restrict consumers from posting reviews of goods, services, or seller conduct, impose penalties for such reviews, or require transfer of intellectual property rights in reviews. It applies to sellers using form contracts with individual consumers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-digital-advertising-disclosures",
      "eu-unfair-commercial-practices-2005-29",
      "ama-ethical-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-contract-disputes-act-1978-federal-construction",
    "title": "Contract Disputes Act of 1978, 41 U.S.C. §§ 7101-7109",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Contract Disputes Act of 1978 governs the resolution of disputes arising under U.S. federal construction contracts, requiring contractors to submit claims exceeding $100,000 in writing to the Contracting Officer for a final decision before appeal to the Boards of Contract Appeals or the U.S. Court of Federal Claims. Applies to all contractors performing under federal construction contracts. Key clause: 41 U.S.C. § 7103(a).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-controlled-substances-act",
    "title": "US Controlled Substances Act (21 USC ch 13): Scheduling, Registration and Trafficking Penalties",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Controlled Substances Act (21 U.S.C. ch. 13) is the federal statute regulating the manufacture, distribution, dispensing and possession of controlled substances, administered by the Drug Enforcement Administration (DEA) with scientific and medical input from the Department of Health and Human Services. Section 801 states the congressional findings. Section 802 supplies the definitions, including controlled substance, manufacture, distribute and dispense. Section 811 grants the authority to control substances and the standards for scheduling, and section 812 establishes the five schedules (I to V) by reference to abuse potential, accepted medical use and dependence liability. Registration is mandatory: section 822 requires persons who manufacture, distribute or dispense controlled substances to register, section 823 sets the registration requirements, and section 824 provides for the denial, revocation or suspension of a registration. Section 841 sets out the principal prohibited acts and trafficking penalties: it is unlawful knowingly to manufacture, distribute or dispense, or possess with intent, a controlled substance, with penalties graduated by drug and quantity, including imprisonment of not less than 10 years up to life and fines up to 10,000,000 dollars for an individual (or 50,000,000 dollars for an entity) for the largest-quantity tier, and lesser tiers of not less than 5 years up to 40 years, up to 20 years, and up to 5 years. The Act is the legal foundation of US drug scheduling, the DEA registration system, and federal drug-trafficking enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-controlled-substances-act-21-usc-ch13",
    "title": "United States Controlled Substances Act (Title 21 USC Chapter 13): Congressional Findings, Schedules of Controlled Substances, Registration of Manufacturers and Distributors, Prescription Requirements, and Penalties",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Controlled Substances Act, codified at Title 21 of the United States Code, Chapter 13, is the principal federal statute governing the manufacture, distribution, dispensing, importation, and exportation of controlled substances in the United States and is administered by the Drug Enforcement Administration in coordination with the Food and Drug Administration. Controlled Substances Act, 21 U.S.C. 801 contains the Congressional findings and declarations, opening with the recognition that many of the drugs included within the subchapter have a useful and legitimate medical purpose. Controlled Substances Act, 21 U.S.C. 802 contains the definitions including addict, controlled substance, and other foundational terms. Controlled Substances Act, 21 U.S.C. 811 governs the authority and criteria for classification of substances. Controlled Substances Act, 21 U.S.C. 812 establishes the schedules of controlled substances (Schedules I through V) based on potential for abuse, accepted medical use, and dependence liability. Controlled Substances Act, 21 U.S.C. 822 governs persons required to register with the DEA to manufacture, distribute, or dispense controlled substances. Controlled Substances Act, 21 U.S.C. 823 sets the registration requirements. Controlled Substances Act, 21 U.S.C. 829 governs prescriptions for controlled substances. Controlled Substances Act, 21 U.S.C. 841 sets out the Prohibited Acts A provisions on manufacture, distribution, and dispensing without authorization. Controlled Substances Act, 21 U.S.C. 844 sets penalties for simple possession. Subchapter I covers control and enforcement, Subchapter II covers import and export. The Act is the controlling federal instrument for federal controlled substances law and operates alongside state controlled substances acts and the Federal Food, Drug, and Cosmetic Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cooperative-forestry-assistance-act",
    "title": "US Cooperative Forestry Assistance Act of 1978 (16 U.S.C. Chapter 41): Federal-State Forestry Assistance, Stewardship and Forest Health",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Cooperative Forestry Assistance Act of 1978, codified at 16 U.S.C. Chapter 41 (sections 2101 through 2114), authorizes the Secretary of Agriculture, through the Forest Service, to provide financial, technical, and related assistance to States, communities, and private landowners for the protection, management, and stewardship of non-Federal forest land. Section 2101 sets the findings, purpose, and policy. Section 2101a requires State-wide assessments and strategies for forest resources as a condition of assistance. Section 2102 authorizes rural forestry assistance, including technical advice on managing and harvesting forest land. Section 2103a establishes the Forest Stewardship Program to encourage the long-term stewardship of non-industrial private forest land. Section 2103c establishes the Forest Legacy Program to protect environmentally important forest areas threatened by conversion to non-forest uses, through conservation easements and land acquisition. Section 2103d establishes the community forest and open space conservation program. Section 2104 authorizes forest health protection against insects, diseases, and invasive species, and section 2105 authorizes the urban and community forestry assistance program. The Act is the foundational statute for Federal-State cooperative forestry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-coordinated-framework-biotechnology-1986",
    "title": "Coordinated Framework for the Regulation of Biotechnology",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "Establishes the jurisdictional roles of the FDA, EPA, and USDA in regulating genetically modified organisms (GMOs) based on product type and intended use, pursuant to existing statutory authorities including the Federal Food, Drug, and Cosmetic Act, the Federal Insecticide, Fungicide, and Rodenticide Act, and the Plant Protection Act. Applies to developers, manufacturers, and importers of biotechnology products in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l3",
      "nist-sp-1800-32-securing-ders"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-coppa-16-cfr-part-312-edtech-school-operators",
    "title": "16 CFR Part 312 - Children's Online Privacy Protection Rule (Coppa Rule)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Operators of online services directed to children under 13 must provide notice, obtain verifiable parental consent before collecting personal information, and uphold parental rights regarding their children's data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-coppa-2-0-proposed-rule-2023",
    "title": "Children’s Online Privacy Protection Rule (COPPA Rule) - 2023 Notice of Proposed Rulemaking",
    "domain": "Data Protection & Privacy",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "The FTC's proposed update to the COPPA Rule (16 C.F.R. Part 312) expands protections by requiring separate, verifiable parental consent for disclosing personal information to third parties for advertising, including for users aged 13-16 (Proposed § 312.5(a)(2)). It also codifies restrictions on data retention, mandates a written children's privacy program, and limits the use of push notifications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-coppa-childrens-online-privacy-education",
    "title": "Children's Online Privacy Protection Act",
    "domain": "Education & Research",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Children's Online Privacy Protection Act (COPPA) requires operators of commercial websites and online services directed to children under 13, or those knowingly collecting personal information from children under 13, to obtain verifiable parental consent before collecting, using, or disclosing such information, and to provide parents with access and control over their child's data as specified in 15 U.S.C. §§ 6501-6506.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-education-action-plan-2021-2027-deap",
      "oecd-principles-ai-in-education-recommendation-2023",
      "iso-21001-2018-educational-organizations-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-coppa-childrens-privacy-education-applications",
    "title": "Children's Online Privacy Protection Act of 1998 (COPPA): Application to Operators of Online Services Used in Schools and Educational Contexts",
    "domain": "Education & Research",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Operators of online services used in K-12 education must comply with COPPA by obtaining verifiable parental consent before collecting personal information from children under 13, unless the school provides consent on behalf of parents under the school-authorized exception in 16 C.F.R. § 312.2. Applies to EdTech platforms, apps, and websites collecting student data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-coppa-education-platforms-compliance",
    "title": "US COPPA Children's Online Privacy Protection Act - Operator Obligations for Educational Platforms Serving Children Under 13",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under the Children's Online Privacy Protection Act (COPPA), operators of online services may rely on a school to provide consent for the collection of personal information from students under 13, provided the data is used solely for a school-authorized educational purpose and not for any other commercial purpose, as outlined in the FTC's guidance, Section M.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ccpa-cpra",
      "nist-sp-1800-28-data-confidentiality"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-copyright-act",
    "title": "US Copyright Act (17 USC ch 1): Subject Matter, Exclusive Rights, Fair Use and Infringement",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Copyright Act of 1976 (17 U.S.C.) is the federal statute governing copyright in the United States, administered for registration and deposit by the United States Copyright Office. Section 101 supplies the definitions. Section 102 sets the subject matter of copyright: original works of authorship fixed in a tangible medium of expression, while excluding ideas, procedures and methods of operation. Section 103 covers compilations and derivative works. Section 106 grants the exclusive rights of the copyright owner: reproduction, preparation of derivative works, distribution, public performance and public display, and section 106A grants certain authors of visual art the rights of attribution and integrity. The exclusive rights are limited: section 107 codifies the fair use defense by reference to the four statutory factors, section 108 permits certain reproduction by libraries and archives, section 109 codifies the first sale doctrine governing the effect of a transfer of a particular copy, and section 110 exempts certain performances and displays. Infringement and remedies are addressed in Chapter 5: section 501 defines infringement of copyright as the violation of any of the exclusive rights, and the following sections provide for injunctions, actual or statutory damages, and, where the work was timely registered, costs and attorney fees. The Act is the legal foundation of US copyright ownership, licensing, and enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-copyright-act-17-usc-512-dmca-safe-harbor-online-service-providers",
    "title": "US Copyright Act 17 USC 512 - DMCA Safe Harbor for Online Service Providers and Takedown Notices",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-06-01",
    "bluf": "Section 512 of the Digital Millennium Copyright Act (DMCA) provides safe harbor protection from copyright liability for online service providers (OSPs) that host, transmit, cache, or link to user-generated content. Safe harbor requires OSPs to: (1) designate an agent for receiving DMCA takedown notices registered with the US Copyright Office, (2) implement a repeat infringer policy, (3) respond expeditiously to valid takedown notices, and (4) not have actual knowledge of or financial benefit from infringement with ability to control it. Safe harbor is lost if OSPs have \"red flag\" knowledge of infringement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-services-act-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-copyright-act-1976-section-107-fair-use",
    "title": "Title 17 United States Code Section 107 - Limitations on Exclusive Rights: Fair Use",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the statutory framework for the fair use of copyrighted works for purposes such as criticism, comment, news reporting, teaching, scholarship, or research. It applies to any individual or entity using copyrighted material without permission under the four-factor test outlined in 17 U.S.C. § 107.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "copyright-fair-use-us",
      "dmca-safe-harbor",
      "iptc-photo-metadata",
      "iptc-video-metadata",
      "exif-standard-metadata"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-copyright-act-section-115-mechanical-licensing",
    "title": "Scope of exclusive rights in nondramatic musical works: Compulsory license for making and distributing phonorecords",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes a compulsory licensing framework under 17 U.S. Code § 115 for the reproduction and distribution of nondramatic musical works via physical phonorecords or digital phonorecord deliveries (DPDs), provided certain conditions are met, including prior distribution by or under authority of the copyright owner and compliance with notice and royalty payment requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dmca-safe-harbor",
      "copyright-fair-use-us",
      "eu-copyright-directive-art-17"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-copyright-office-ai-registration-guidance-2023",
    "title": "Copyright Registration Guidance: Works Containing AI-Generated Material",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The U.S. Copyright Office requires human authorship for copyright protection; AI-generated content lacking human creative control is not protectable. Applicants must disclose AI-generated content in submissions under Section 304 of the Copyright Act and Rule 202.20 of the Compendium of U.S. Copyright Office Practices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iptc-photo-metadata",
      "iptc-video-metadata",
      "exif-standard-metadata",
      "copyright-fair-use-us",
      "dmca-safe-harbor"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-copyright-registration-ai-works-policy-2024",
    "title": "US Copyright Office AI Works Registration Policy 2024 - Human Authorship Requirement: AI-Assisted Works with Sufficient Human Creative Control are Registrable, Disclosure Requirements for AI Use, Prompt Engineering as Non-Copyrightable, Consistent with Thaler v. Vidal",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "AI-assisted works may be registered with the U.S. Copyright Office only if they contain sufficient human creative control; full disclosure of AI-generated content is required. Prompt engineering alone does not constitute copyrightable authorship, consistent with the Office’s guidance and registration decisions including Théâtre D’opéra Spatial (Sept. 5, 2023) and the Policy Statement issued March 16, 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "copyright-fair-use-us",
      "dmca-safe-harbor",
      "berne-convention-1886-2024-literary-artistic-works"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-corporate-alternative-minimum-tax-camt-ira-2022",
    "title": "Corporate Alternative Minimum Tax (CAMT) under the Inflation Reduction Act of 2022 (IRC § 55)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The Corporate Alternative Minimum Tax (CAMT) imposes a 15% minimum tax on the adjusted financial statement income (AFSI) of applicable corporations with average annual AFSI exceeding $1 billion, as established by Section 10101 of the Inflation Reduction Act of 2022, amending Internal Revenue Code § 55.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015",
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-corporate-transparency-act-2020-31-usc-5336",
    "title": "Corporate Transparency Act 2020 - 31 USC 5336 Beneficial Ownership Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 5336 of title 31 of the United States Code, the Corporate Transparency Act of 2020 (CTA, Title LXIV of the National Defense Authorization Act for Fiscal Year 2021, Public Law 116-283 enacted 1 January 2021), requires reporting companies to disclose beneficial ownership information to the Financial Crimes Enforcement Network (FinCEN). A reporting company is defined as a corporation, limited liability company, or similar entity created by filing with a state secretary of state or formed abroad and registered to do business in the United States. The Act enumerates 23 categories of exemption including SEC-registered issuers, banks, credit unions, money services businesses, broker-dealers, registered investment companies, insurance companies, tax-exempt organisations, and large operating companies (more than 20 US employees and 5 million USD gross receipts). A beneficial owner is defined as an individual who either exercises substantial control over the reporting company or owns or controls at least 25 percent of the ownership interests. Reports must include the beneficial owner's full legal name, date of birth, residential or business address, and unique identifying number from acceptable identification (or a FinCEN identifier). Reporting deadlines depend on entity formation date with newly formed entities required to file at formation and existing entities within two years of the effective date (1 January 2024). The 2024 enforcement landscape included Eleventh Circuit litigation (NSBA v Yellen) and Treasury implementation rule changes; ongoing implementation requires close monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bsa-bank-secrecy-act-31-usc-5311",
      "us-money-laundering-control-act-18-usc-1956"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cost-sharing-regulations-treasury-482-7",
    "title": "Methods to Determine Taxable Income in Connection with a Cost Sharing Arrangement",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation requires controlled participants in a Qualified Cost Sharing Arrangement (CSA) to share intangible development costs (IDCs) in proportion to their reasonably anticipated benefits (RAB) and to make arm's length buy-in payments for pre-existing intangibles, known as Platform Contribution Transactions (PCTs), to ensure outcomes are consistent with the arm's length principle under §1.482-7(a)(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015",
      "un-model-double-taxation-convention-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-cotton-research-promotion-act",
    "title": "US Cotton Research and Promotion Act (7 USC ch 53): The Cotton Board and Per-Bale Assessment",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Cotton Research and Promotion Act (7 U.S.C. ch. 53, sections 2101 to 2122) authorizes a coordinated program of research and promotion for cotton funded by assessments, administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 2101 sets out the congressional declaration of policy, providing that the efficient production of cotton and the maintenance and expansion of existing markets and the development of new or improved markets and uses is vital to the welfare of cotton growers. Section 2102 authorizes orders of the Secretary to cotton handlers, section 2103 provides for notice and hearing upon proposed orders, and section 2104 governs the finding and issuance of orders. Section 2106 sets the required terms and conditions in orders, providing for the establishment of the Cotton Board, with representatives of cotton producers and importer representatives where applicable, and fixing the assessment at 1 dollar per bale of cotton handled, supplemented by an additional per-bale amount not to exceed 1 percent of the value of the cotton. Section 2107 sets the referenda, providing that no order shall be effective unless the Secretary determines that it is approved or favored by not less than two-thirds of the producers voting. Section 2108 provides for the suspension and termination of orders, section 2110 provides for the refund of producer assessments, and section 2112 provides for enforcement, including that a handler who willfully violates any provision shall be liable to a penalty of not more than 1,000 dollars. Section 2115 provides investigation and subpoena power, and section 2116 sets the definitions of handler and importer. The Act is the federal checkoff regime for cotton.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cotton-standards-act",
    "title": "US Cotton Standards Act (7 USC ch 2): Official Cotton Standards and Classification",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The United States Cotton Standards Act (7 U.S.C. ch. 2, sections 51 to 65) establishes official standards for the classification of cotton and is administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 51 names the chapter the United States Cotton Standards Act, and section 52 prohibits, in transactions in commerce, the use of any cotton grade or quality designation other than the official cotton standards of the United States. Section 53 authorizes the Secretary to license qualified persons to classify cotton and to sample and certify cotton, and to suspend or revoke a license for incompetency or violation. Section 54 provides for classification of cotton by the Department of Agriculture on submission of samples, and provides that a certificate of classification is binding and is prima facie evidence in the courts of the United States. Section 56 authorizes the Secretary to establish and amend the official cotton standards, with a standard taking effect not less than one year after the order establishing it. Section 59 defines offenses relating to the counterfeiting, alteration, or unauthorized use of the standards, and section 60 makes a violation punishable by a fine not exceeding 1,000 dollars, or imprisonment not exceeding six months, or both. The Act is the federal standardization regime for the cotton trade.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cpra-california-privacy-rights-act-2020",
    "title": "The California Privacy Rights Act of 2020 (CPRA)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The California Privacy Rights Act (CPRA) amends and expands the California Consumer Privacy Act (CCPA), granting California residents new rights over their personal information, including the right to correct inaccurate data and the right to limit the use and disclosure of Sensitive Personal Information (SPI) as defined in Cal. Civ. Code § 1798.140(ae). The Act also establishes the California Privacy Protection Agency (CPPA) to implement and enforce the law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-5-data-principles",
      "nist-privacy-framework-1-0",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-cpsc-16-cfr-1500-hazardous-substances-labeling-fhsa",
    "title": "16 CFR Part 1500 - Hazardous Substances and Articles: Administration and Enforcement Regulations (FHSA)",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "CPSC 16 CFR Part 1500 implements the Federal Hazardous Substances Act, requiring manufacturers and importers of consumer products to classify hazardous substances and hazardous mixtures, apply the cautionary labeling required for hazardous and special-hazard products, avoid distributing banned hazardous substances and banned or misbranded children's articles, use the prescribed test methods for toxicity, irritation, flammability, and mechanical hazards of children's articles, apply exemptions only where their conditions are met, and meet the label prominence, placement, and conspicuousness requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 28
  },
  {
    "node_id": "us-cpsia-consumer-product-safety-improvement-2008-15-usc-2061",
    "title": "Consumer Product Safety Improvement Act 2008 - 15 USC 2061 Imminent Hazards",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 2061 of title 15 of the United States Code, as amended by the Consumer Product Safety Improvement Act of 2008 (CPSIA, Public Law 110-314, enacted 14 August 2008), authorises the Consumer Product Safety Commission (CPSC) to file federal court actions regarding imminently hazardous consumer products defined as products presenting imminent and unreasonable risk of death, serious illness, or severe personal injury. The CPSC may seek seizure of hazardous products, mandatory notification to purchasers, public warnings, recalls, repairs, replacements, or refunds. The CPSIA materially expanded CPSC authority including lower lead and phthalates limits for children's products (15 USC 1278a and 2057c), mandatory third-party testing and certification of children's products (15 USC 2063), Children's Product Safety Certificates and General Certificates of Conformity, the CPSC public reporting database SaferProducts.gov (15 USC 2055a), enhanced civil penalties (up to 100,000 USD per violation and 15 million USD total in fines under section 2069), and the Section 6(b) confidentiality framework for manufacturer-identifying information. The CPSC framework applies to all consumer products other than those expressly excluded (food and drugs regulated by FDA, motor vehicles regulated by NHTSA, firearms, etc.), with particular focus on children's products, electrical safety, choking and entanglement, ATVs, lithium-ion battery safety, and increasingly AI-enabled or internet-connected consumer products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ca-consumer-product-safety-act-2010"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-credit-card-act-2009-pl-111-24",
    "title": "US Credit Card Accountability Responsibility and Disclosure Act of 2009 (Public Law 111-24) - Consumer Credit Card Protections",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Credit Card Accountability Responsibility and Disclosure Act of 2009 amended the Truth in Lending Act to limit retroactive interest rate increases on existing balances, require 45 days advance written notice of significant changes to account terms, restrict over-the-limit fees absent consumer opt-in, prohibit issuing credit cards to consumers under 21 without a cosigner or proof of independent ability to repay, require minimum 21-day payment due windows, restrict late fees to reasonable and proportional amounts, mandate review of recently increased rates every six months, and impose enhanced disclosures on monthly statements including time to repay illustrations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-truth-in-lending-act",
      "us-dodd-frank-act-2010"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-credit-repair-organizations-act-15-usc-1679",
    "title": "US Credit Repair Organizations Act (15 USC 1679) - Consumer Protection for Credit Repair Services",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Credit Repair Organizations Act prohibits credit repair organizations from making untrue or misleading statements about consumer credit standing or capacity to creditors or consumer reporting agencies, prohibits advance payment for services before they are fully performed, requires a written contract signed by the consumer specifying services and price, provides a three-day cancellation right with the cancellation notice as a separate document, and mandates a statutory disclosure entitled Consumer Credit File Rights Under State and Federal Law to be provided to the consumer before any contract is signed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fcra-1970",
      "us-cfpb-12-cfr-1006-reg-f-fair-debt-collection-practices"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-csi-deploying-ai-systems-securely-2024",
    "title": "US Joint Cybersecurity Information Sheet - Deploying AI Systems Securely (NSA-CISA-FBI-NCSC-UK-ACSC-CCCS-NCSC-NZ, April 15 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On April 15, 2024 the US National Security Agency's Artificial Intelligence Security Center (NSA AISC), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the UK National Cyber Security Centre (NCSC-UK), the Australian Signals Directorate's ACSC, the Canadian Centre for Cyber Security (CCCS), and the New Zealand National Cyber Security Centre (NCSC-NZ) jointly published the Cybersecurity Information Sheet Deploying AI Systems Securely - Best Practices for Deploying Secure and Resilient AI Systems. The CSI provides guidance for organisations deploying and operating externally developed AI systems, structured across three areas: (1) Secure the deployment environment - manage governance, ensure a robust IT environment, validate the AI system before and during use, protect APIs and access controls, identify and protect AI assets, and develop incident response procedures; (2) Continuously protect the AI system - validate the AI system, secure exposed APIs, secure deployment infrastructure, harden CI/CD pipelines for the model artifacts; (3) Secure AI operation and maintenance - enforce strict access controls, perform red-team exercises, monitor user behaviour, conduct AI-specific audits, and contribute to the AI vulnerability disclosure community. The CSI is the operational complement to the November 2023 CISA-NCSC Guidelines for Secure AI System Development and forms part of the multilateral allied cyber agency baseline for deployment-time AI security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "nist_framework",
        "iso_standard",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cisa-ncsc-guidelines-secure-ai-system-development-2023",
      "nist-ai-rmf-1-0",
      "nist-ai-100-2-adversarial-ml-taxonomy-2024",
      "us-cisa-roadmap-for-ai-2024"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ct-ctdpa-2023",
    "title": "US Connecticut Data Privacy Act 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Connecticut Data Privacy Act grants consumers rights to access, correct, delete, and port personal data, requires opt-in consent for sensitive data and data sales related to known children under 16, mandates data protection assessments for high-risk processing, and authorises the Connecticut Attorney General to impose civil penalties of up to USD 5,000 per wilful violation with a cure period expiring December 31, 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ct-ctdpa-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ccpa-cpra-2023-marketing-rights"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ctpat-minimum-security-criteria-2021",
    "title": "US C-TPAT Minimum Security Criteria 2021 - Customs-Trade Partnership Against Terrorism: Physical Security, Access Controls, Cybersecurity and Supply Chain Security Plans",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation requires U.S. importers, carriers, manufacturers, and other trade entities to implement comprehensive supply chain security measures aligned with CTPAT’s Minimum Security Criteria to mitigate terrorism risks. Entities must conduct risk assessments, submit a security profile, and maintain ongoing compliance to qualify for reduced CBP examinations and other benefits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cures-act-information-blocking-2021",
    "title": "Information Blocking (45 CFR Part 171) under the 21st Century Cures Act",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This rule, under 45 CFR § 171.103, prohibits practices by healthcare providers, health IT developers, and health information networks/exchanges that are likely to interfere with, prevent, or materially discourage the access, exchange, or use of electronic health information (EHI), unless a specific, defined exception applies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-21st-century-cures-act-2016",
      "hitech-act-2009",
      "hipaa-security-rule",
      "hl7-fhir-v4-interop",
      "us-cms-interoperability-rule-2020"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-customs-trade-partnership-against-terrorism-c-tpat-supply-chain-security",
    "title": "US CBP C-TPAT - Customs-Trade Partnership Against Terrorism Supply Chain Security Criteria and Certification",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2020-06-01",
    "bluf": "CBP C-TPAT certification requires importers, carriers, and brokers to implement minimum supply chain security criteria covering business partner requirements, physical security, personnel security, procedural security, IT security, and security training, in exchange for reduced CBP examination rates and expedited cargo processing through FAST lanes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-15-usc-45-unfair-deceptive-practices",
      "us-hipaa-security-rule-45-cfr-164-technical-safeguards"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-cyber-incident-reporting-critical-infrastructure-act-2022-section-2242-reporting",
    "title": "Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) - Reporting Requirements",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This act requires covered entities to report covered cyber incidents and ransomware payments to the Cybersecurity and Infrastructure Security Agency (CISA) to enable rapid assistance and information sharing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-davis-bacon-act",
    "title": "US Davis-Bacon Act (40 USC ch 31 subch IV): Prevailing Wages on Federal Construction Contracts",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Davis-Bacon Act (40 U.S.C. ch. 31, subchapter IV, sections 3141 to 3148) requires that laborers and mechanics employed on federal and federally assisted construction contracts be paid no less than the locally prevailing wages and fringe benefits, administered by the Wage and Hour Division of the Department of Labor. Section 3141 supplies the definitions, including wages and the components of basic hourly rate and fringe benefits. Section 3142 sets the core requirement: it applies to a contract in excess of 2,000 dollars to which the Federal Government is a party for the construction, alteration or repair of public buildings or public works, and requires that the minimum wages be based on the wages the Secretary of Labor determines to be prevailing for the corresponding classes of laborers and mechanics in the locality. Section 3143 authorizes the termination of the contractor's right to proceed where workers are paid less than the agreed wages. Section 3144 gives the Secretary of Labor authority to pay withheld wages directly to the workers and to maintain a list of contractors found to have violated their obligations (debarment). Section 3145 directs regulations governing contractors and subcontractors, including weekly certified payroll statements. Section 3146 preserves other federal wage authority, and section 3147 allows the President to suspend the requirements during a national emergency. The Act is the legal foundation of federal construction prevailing-wage compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-davis-bacon-act-prevailing-wage-construction",
    "title": "Davis-Bacon Act of 1931",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Davis-Bacon Act requires contractors and subcontractors to pay prevailing wages to laborers and mechanics on federal construction contracts, as stated in 40 U.S.C. §3142. This applies to all contractors and subcontractors performing work on federal construction projects exceeding $2,000.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-davis-bacon-act-prevailing-wages-construction",
    "title": "US Davis-Bacon Act (40 USC 3141) - Prevailing Wage Requirements for Federal and Federally-Assisted Construction Contracts",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Davis-Bacon Act requires contractors and subcontractors on federally funded or assisted contracts over $2,000 for the construction, alteration, or repair of public buildings or public works to pay their laborers and mechanics no less than the locally prevailing wages and fringe benefits for corresponding work on similar projects in the area, as specified under 40 U.S.C. § 3142.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-de-dpdpa-2023",
    "title": "US Delaware Personal Data Privacy Act 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Delaware Personal Data Privacy Act applies the lowest consumer count threshold among US comprehensive state privacy laws at 35,000 Delaware consumers, requires opt-in consent for sensitive data and for processing minor's data for targeted advertising, mandates data protection assessments for high-risk processing, and authorises the Delaware Attorney General to impose civil penalties of up to USD 10,000 per violation with a cure period expiring January 1, 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-de-dpdpa-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ccpa-cpra-2023-marketing-rights"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-dea-21-cfr-1301-1308-controlled-substances-registration-manufacturing",
    "title": "US DEA 21 CFR Parts 1301-1308 - Controlled Substances Registration and Manufacturing Requirements",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "The US Drug Enforcement Administration (DEA) regulations at 21 CFR Parts 1301-1308 implement the Controlled Substances Act (CSA), requiring registration for all manufacturers, distributors, dispensers, and researchers handling Schedule I-V controlled substances. DEA Schedule determines registration type, manufacturing quotas, record-keeping obligations (2-year retention), and reporting requirements including ARCOS (Automation of Reports and Consolidated Orders System) for bulk manufacture and distribution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-210-211-current-good-manufacturing-practice"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dea-21-cfr-1308-controlled-substances-schedules",
    "title": "21 CFR Part 1308 - Schedules of Controlled Substances (DEA)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "DEA 21 CFR Part 1308 lists the schedules of controlled substances established under the Controlled Substances Act, placing each substance in Schedule I through Schedule V according to its abuse potential, accepted medical use, and dependence liability, and providing for exclusion of certain nonnarcotic substances and exemption of specified chemical preparations, so that registrants apply the correct handling, security, and recordkeeping controls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-deep-seabed-hard-mineral-resources-act",
    "title": "US Deep Seabed Hard Mineral Resources Act of 1980 (30 U.S.C. Chapter 26): Licensing of Deep Seabed Mining",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Deep Seabed Hard Mineral Resources Act of 1980, codified at 30 U.S.C. Chapter 26 (sections 1401 through 1473), establishes an interim federal regime for the licensing of exploration and the permitting of commercial recovery of hard mineral resources of the deep seabed by United States citizens, pending an internationally agreed regime, administered by the National Oceanic and Atmospheric Administration. Section 1401 sets out the congressional findings and declaration of purpose, including the policy of encouraging the development of deep seabed mineral resources consistent with the environment. Section 1412 requires a license for exploration and a permit for commercial recovery, prohibiting such activity by United States citizens without authorization. Section 1413 governs license and permit applications, their review, and certification. Section 1415 sets the terms, conditions, and restrictions of licenses and permits and provides for their issuance and transfer. Section 1419 requires the protection of the quality of the environment, including environmental assessment and the prevention of significant adverse effects. Section 1461 sets out the prohibited acts, section 1462 provides for civil penalties, and section 1463 provides for criminal offenses for knowing and willful violations. The Act is the foundational United States statute for deep seabed mining authorization and is administered as an interim measure pending an international agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-deepwater-port-act-33-usc-1501",
    "title": "US Deepwater Port Act of 1974 (33 USC 1501) - Federal Licensing of Deepwater Ports for Oil and Natural Gas",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Deepwater Port Act of 1974 authorises the Secretary of Transportation acting through the Maritime Administration and the United States Coast Guard to issue licenses for the ownership, construction, operation, and decommissioning of deepwater ports located beyond the territorial sea of the United States for the import or export of oil and natural gas, requires environmental review under the National Environmental Policy Act and consultation with adjacent coastal states, authorises a single deepwater port license per project, and provides for civil and criminal penalties for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-defend-trade-secrets-act",
    "title": "US Federal Trade Secret Protection (18 USC ch 90): Economic Espionage, Theft and the DTSA Civil Action",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Chapter 90 of Title 18 (18 U.S.C. ch. 90) is the federal trade-secret protection regime, combining the criminal Economic Espionage Act of 1996 with the civil Defend Trade Secrets Act of 2016 (DTSA), enforced criminally by the Department of Justice and civilly through a federal private action. Section 1831 criminalizes economic espionage, the misappropriation of a trade secret to benefit a foreign government or instrumentality, punishable by a fine of up to 5,000,000 dollars or imprisonment of up to 15 years for an individual, and a fine of the greater of 10,000,000 dollars or three times the value for an organization. Section 1832 criminalizes the theft of trade secrets related to a product or service in interstate or foreign commerce, punishable by imprisonment of up to 10 years for an individual, and a fine of the greater of 5,000,000 dollars or three times the value for an organization. Section 1833 sets out exceptions, including the immunity for confidential disclosures by whistleblowers. Section 1834 provides for criminal forfeiture and section 1835 for orders to preserve the confidentiality of trade secrets in proceedings. Section 1836 contains the DTSA civil action: it allows an owner to sue in federal court for misappropriation, with remedies including injunctions, actual loss and unjust enrichment damages or a reasonable royalty, exemplary damages of up to two times the damages for willful and malicious misappropriation, and, in extraordinary circumstances, civil seizure of the misappropriated trade secret. Section 1837 extends the chapter to certain conduct outside the United States, and section 1839 supplies the definitions of trade secret, misappropriation and improper means. The chapter is the legal foundation of US trade-secret enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-defend-trade-secrets-act-2016",
    "title": "Defend Trade Secrets Act of 2016 (18 U.S.C. § 1836)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The DTSA creates a federal civil cause of action for trade secret misappropriation (18 U.S.C. § 1836(a)), authorizes ex‑parte seizure orders (§ 1836(b)), and provides whistleblower protection (§ 1836(c)) for any person or entity that maintains trade secrets in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-code-ethics",
      "aba-model-rules-conduct",
      "contingency-planning-federal-information-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-defend-trade-secrets-act-2016-18-usc-ch90",
    "title": "United States Defend Trade Secrets Act of 2016 (Title 18 USC Chapter 90): Economic Espionage, Theft of Trade Secrets, Exceptions to Prohibitions, Criminal Forfeiture, Orders to Preserve Confidentiality, Civil Proceedings with Private Right of Action and Civil Seizure, Conduct Outside the United States, and Definitions",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Defend Trade Secrets Act of 2016 (DTSA), Public Law 114-153 of 11 May 2016, codified at Title 18 of the United States Code, Chapter 90, amends the Economic Espionage Act of 1996 to create a federal private right of action for trade secret misappropriation and provides for ex parte civil seizure of property in extraordinary circumstances, and is administered through private federal civil litigation and criminal enforcement by the Department of Justice. DTSA, 18 U.S.C. 1831 contains the economic espionage offence applicable to trade secret theft for the benefit of any foreign government, foreign instrumentality, or foreign agent. DTSA, 18 U.S.C. 1832 contains the theft of trade secrets offence applicable to trade secret theft related to a product or service used in or intended for use in interstate or foreign commerce. DTSA, 18 U.S.C. 1833 contains the exceptions to prohibitions including the whistleblower immunity for disclosures to attorneys, federal, state, or local government officials, or in court filings under seal. DTSA, 18 U.S.C. 1834 provides for criminal forfeiture of any property used or intended to be used to commit or facilitate the offence. DTSA, 18 U.S.C. 1835 provides for orders to preserve confidentiality during proceedings under this chapter. DTSA, 18 U.S.C. 1836 provides the civil proceedings with a private right of action for an owner of a trade secret that is misappropriated to bring a civil action including injunctive relief, damages for actual loss, damages for unjust enrichment, exemplary damages up to two times actual or unjust enrichment damages where misappropriation is wilful and malicious, attorneys' fees, and a civil seizure provision under extraordinary circumstances. DTSA, 18 U.S.C. 1837 governs the application to conduct outside the United States. DTSA, 18 U.S.C. 1838 governs construction with other laws. DTSA, 18 U.S.C. 1839 contains the definitions including trade secret and misappropriation. The Act is the controlling federal instrument for trade secret protection in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-defend-trade-secrets-act-2016-dtsa",
    "title": "Defend Trade Secrets Act of 2016 (18 U.S.C. § 1836) - Federal Private Civil Action for Trade Secret Misappropriation, Ex Parte Seizure, and Exemplary Damages",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Defend Trade Secrets Act (DTSA) of 2016 enables private parties to bring federal civil actions for misappropriation of trade secrets related to products or services in interstate or foreign commerce, under 18 U.S.C. § 1836(b)(1). It authorizes ex parte seizure orders under § 1836(b)(2) and exemplary damages up to two times the actual damages if willful and malicious misappropriation is proven under § 1836(b)(3)(C).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dmca-safe-harbor",
      "iptc-photo-metadata",
      "iptc-video-metadata",
      "exif-standard-metadata",
      "copyright-fair-use-us"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-defense-production-act-50-usc-4501",
    "title": "Defense Production Act 1950 - 50 USC 4501 National Defense Industrial Authority",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 4501 of title 50 of the United States Code provides that chapter 55 may be cited as the Defense Production Act of 1950 (Public Law 81-774, enacted 8 September 1950, 64 Statutes at Large 798). The Defense Production Act is the principal US statute authorising the President to mobilise the domestic industrial base in support of national defense, with current scope extending to homeland security, emergency preparedness, energy, and pandemic response. Title I (50 USC 4511 through 4518) authorises priorities and allocations including the Defense Priorities and Allocations System (DPAS) under Executive Order 13603, allowing the President to require performance of rated orders for goods and services in priority over commercial orders and to allocate scarce materials in the national defense interest. Title III (50 USC 4531 through 4534) authorises industrial base expansion through loans, loan guarantees, purchase commitments, and direct purchases to develop domestic supply chains for critical materials and technologies. Title VII (50 USC 4551 through 4568) covers general provisions including the Voluntary Agreements authority (section 4558), the Committee on Foreign Investment in the United States (section 4565 / section 721 of the Act), antitrust defences for voluntary agreements, employment information sharing, and reporting. The Defense Production Act has been substantially expanded since 9/11 with semiconductor and biotech industrial-base initiatives, COVID-19 PPE and vaccine acceleration, and 2024 amendments addressing AI semiconductor supply chains.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cfius-defense-production-act-50-usc-4565",
      "us-chips-and-science-act-2022-pl-117-167"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-delaware-personal-data-privacy-act-2023",
    "title": "Delaware Personal Data Privacy Act (House Bill 154)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2025-01-01",
    "bluf": "The Delaware Personal Data Privacy Act (DPDPA) establishes rights for consumers to access, correct, delete, and opt-out of the sale of their personal data, and imposes duties on data controllers who conduct business in Delaware and either control/process data of 35,000+ consumers or derive over 20% of gross revenue from selling personal data of 10,000+ consumers, as defined in § 12D-103.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-department-of-agriculture-organic-act",
    "title": "US Department of Agriculture Organic Act (7 USC ch 55): USDA Establishment and the Census of Agriculture",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "Chapter 55 of Title 7 (7 U.S.C. ch. 55, sections 2201 to 2279f) is the Department of Agriculture Organic Act, the body of law establishing the Department of Agriculture, defining the Secretary's authority, and providing for the Census of Agriculture. Section 2201 establishes the Department of Agriculture, with the general design and duties to acquire and to diffuse among the people of the United States useful information on subjects connected with agriculture, rural development, aquaculture, and human nutrition. Section 2202 provides that the Department is an executive department headed by the Secretary of Agriculture. Section 2204 sets the general duties of the Secretary, including to procure and preserve all information concerning agriculture and to advise the President on policies and programs to improve rural and nonmetropolitan regions, and section 2204-1 governs the delegation of regulatory functions of the Secretary and provides definitions. Section 2204b sets the rural development policy. Section 2204g provides for the Census of Agriculture, requiring that in 1998 and every fifth year thereafter the Secretary shall take a census of agriculture, and providing that a person who willfully provides a false answer to a census inquiry shall be fined not more than 500 dollars and a person who refuses to answer shall be fined not more than 100 dollars. Section 2204h provides for local food production and program evaluation. The Act is the foundational charter of the United States Department of Agriculture and the statutory basis of the mandatory Census of Agriculture.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-department-of-education-organization-act-20-usc-ch48",
    "title": "United States Department of Education Organization Act (Title 20 USC Chapter 48): Congressional Findings, Establishment of the Department, Principal Officers, Office for Civil Rights, and Transfer of Functions",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Department of Education Organization Act, codified at Title 20 of the United States Code, Chapter 48 and enacted as Public Law 96-88 on October 17, 1979, is the principal federal statute establishing the United States Department of Education as a Cabinet-level federal department. Department of Education Organization Act, 20 U.S.C. 3401 contains the Congressional findings, opening with the finding that education is fundamental to the development of individual citizens and the progress of the Nation. Department of Education Organization Act, 20 U.S.C. 3402 contains the Congressional declaration of purpose: the Congress declares that the establishment of a Department of Education is in the public interest and will promote the general welfare of the United States. Department of Education Organization Act, 20 U.S.C. 3403 sets out the relationship with States, providing that it is the intention of Congress to protect the rights of State and local governments and public and private educational institutions. Department of Education Organization Act, 20 U.S.C. 3404 contains the definitions. Subchapter II contains the establishment provisions in sections 3411 through 3427, including Department of Education Organization Act, 20 U.S.C. 3411 establishing the Department of Education and appointing the Secretary, Department of Education Organization Act, 20 U.S.C. 3412 establishing the principal officers, and Department of Education Organization Act, 20 U.S.C. 3413 establishing the Office for Civil Rights. Subchapter III governs transfers of agencies and functions in sections 3441 through 3447 including Department of Education Organization Act, 20 U.S.C. 3441 transferring functions from the Department of Health, Education, and Welfare. Subchapter IV contains administrative provisions in sections 3461 through 3490. Subchapter V contains transitional, savings, and conforming provisions in sections 3501 through 3510. The Act is the controlling federal instrument for the structure and authority of the United States Department of Education.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-dhs-h1b-weighted-selection-8-cfr-214-2",
    "title": "DHS Weighted Selection Process for Cap-Subject H-1B Registrations (8 CFR 214.2(h))",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Under the weighted selection process in 8 CFR 214.2(h), when a random selection is necessary to meet the H-1B numerical cap, USCIS assigns each unique beneficiary to the lowest OEWS wage level among all registrations submitted on the beneficiary's behalf and enters each beneficiary into the selection pool a number of times equal to the wage level (level IV four times, level III three times, level II two times, level I one time), increasing the selection probability for higher-wage registrations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ina-admission-of-nonimmigrants-8usc1184",
      "us-immigration-nationality-act-1952-uscis",
      "us-ina-definitions-8usc1101"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-dietary-guidelines-americans-2020-2025",
    "title": "Dietary Guidelines for Americans, 2020-2025",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Provides evidence-based dietary guidance for Americans aged 2 years and older to promote healthy eating patterns, reduce risk of chronic disease, and meet nutrient needs. Key recommendations include limiting added sugars to less than 10% of daily calories, saturated fat to less than 10% of daily calories, sodium to less than 2,300 mg per day, and moderating alcohol intake. Applies to federal nutrition programs, dietary counseling, and public health initiatives. Based on the Scientific Report of the 2020 Dietary Guidelines Advisory Committee and mandated under 7 U.S.C. § 5341.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brc-food-safety-global",
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-food-hygiene-regulation-852-2004",
      "ada-hospitality-access",
      "alcohol-service-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-digital-millennium-copyright-act",
    "title": "US Digital Millennium Copyright Act (17 USC 512 and ch 12): Safe Harbors, Notice-and-Takedown and Anti-Circumvention",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Digital Millennium Copyright Act of 1998 (DMCA) added two pillars to US copyright law: the online service provider safe harbors in 17 U.S.C. 512 and the anti-circumvention regime in 17 U.S.C. ch. 12 (sections 1201 to 1205), administered through the courts and the Copyright Office. Section 512 limits the liability of service providers for infringement: 512(a) covers transitory digital network communications, 512(b) system caching, 512(c) the storage of material at the direction of users (the notice-and-takedown safe harbor, which requires the provider to designate an agent with the Copyright Office and to respond expeditiously to remove material on receipt of a compliant notice), and 512(d) information location tools. Section 512(c)(3) sets the required elements of a takedown notification, section 512(g) provides for counter notification and the replacement of removed material not less than 10 nor more than 14 business days after a counter notice, and section 512(i) conditions eligibility on a reasonably implemented repeat-infringer termination policy. Section 1201 prohibits circumventing a technological measure that controls access to a protected work and trafficking in circumvention devices, and section 1202 protects the integrity of copyright management information. Section 1203 provides civil remedies, including statutory damages of 200 to 2,500 dollars per act under section 1201 and 2,500 to 25,000 dollars under section 1202, and section 1204 provides criminal penalties of up to 500,000 dollars or 5 years for a first willful commercial offense, rising to 1,000,000 dollars or 10 years for a subsequent offense. The DMCA is the legal foundation of US platform liability and digital-rights-management law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-dmca-1201-anti-circumvention-triennial-review",
    "title": "Rulemaking Proceedings Under Section 1201 of Title 17 - Prohibited Circumvention of Technological Protection Measures, Triennial Review Process, and Temporary Exemptions",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation implements Section 1201 of Title 17 of the U.S. Code, which prohibits the circumvention of technological protection measures (TPMs) that control access to copyrighted works. Every three years, the Copyright Office conducts a rulemaking to evaluate and renew temporary exemptions to this prohibition, such as for security research, archiving, and encryption research.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dmca-safe-harbor",
      "copyright-fair-use-us",
      "berne-convention-1886-2024-literary-artistic-works"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dmca-1998-section-512-safe-harbour",
    "title": "Digital Millennium Copyright Act of 1998, Section 512 - Limitations on Liability for Copyright Infringement by Online Service Providers",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes safe harbor protections for online service providers (OSPs) against copyright infringement liability, provided they comply with notice-and-takedown procedures, designate a DMCA agent, adopt a repeat infringer policy, and respond to red flag knowledge of infringement under 17 U.S.C. § 512(c)(1). It applies to hosting providers, platforms, and networks storing user-uploaded content.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "copyright-fair-use-us",
      "iptc-photo-metadata",
      "iptc-video-metadata",
      "exif-standard-metadata",
      "doi-digital-object-id"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-dmca-section-512-safe-harbor-1998",
    "title": "Digital Millennium Copyright Act Section 512 - Limitations on Liability for Copyright Infringement by Online Service Providers",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes safe harbor protections from copyright liability for online service providers that meet specific conditions, including expeditious removal of infringing material upon receiving a valid takedown notice under 17 U.S.C. § 512(c)(3). It applies to internet intermediaries hosting user-generated content who comply with notice-and-takedown procedures and adopt repeat infringer policies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "apec-cbpr-system-2011",
      "ai-ip-copyright"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-dmca-title-ii-safe-harbor-17-usc-512",
    "title": "US DMCA Title II Safe Harbor - 17 USC 512 Online Service Provider Notice-and-Takedown",
    "domain": "Legal & IP Sovereignty",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Section 512 of the DMCA provides conditional safe harbor from copyright infringement liability for online service providers (OSPs) operating notice-and-takedown systems, repeat infringer policies, and DMCA agent registration - foundational compliance for any platform hosting user-generated content.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dna-testing-privacy-genetic-information-nondiscrimination-act-gina",
    "title": "US GINA - Genetic Information Nondiscrimination Act 2008 - Employment and Health Insurance Protections",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2023-06-01",
    "bluf": "The Genetic Information Nondiscrimination Act of 2008 (GINA) prohibits discrimination based on genetic information in health insurance (Title I) and employment (Title II). Title I prohibits health insurers from using genetic information for eligibility, premiums, or coverage. Title II prohibits employers with 15+ employees from using genetic information in hiring, firing, pay, or other employment terms. GINA also prohibits employers from requesting or requiring genetic testing. Exceptions apply for wellness programs meeting specific requirements. EEOC enforces Title II; HHS and DOL enforce Title I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-hipaa-hitech-phi-breach-notification-rule-45-cfr-164",
      "ada-employment-title-1"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dod-5015-02-std-electronic-records-management",
    "title": "DoD 5015.02-STD Electronic Records Management Software Applications Design Criteria Standard (25 April 2007)",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "DoD 5015.02-STD (25 April 2007) sets the mandatory baseline functional requirements for Records Management Application (RMA) software used across the Department of Defense, based on current NARA regulations. Chapter C2 contains the mandatory requirements, split into C2.1 general requirements and C2.2 detailed requirements, with component tables C2.T1 file plan, C2.T2 record folder, C2.T3 record metadata, and C2.T4 transmission and receipt data. C2.2.2 scheduling and C2.2.3 declaring and filing implement disposition, retention, cutoff, and preservation controls tied to NARA and 44 U.S.C. Automated records workflows must enforce file-plan structure, scheduled disposition, immutable filed records, and transmission and receipt capture.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-federal-records-act-44-usc-ch31",
      "us-nara-36-cfr-1234-electronic-records-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-dod-ai-ethical-principles-2020",
    "title": "US Department of Defense AI Ethical Principles (Adopted February 24, 2020)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On February 24, 2020 the US Secretary of Defense adopted five Ethical Principles for the use of Artificial Intelligence in military operations, drawn from the Defense Innovation Board's October 2019 recommendations. The five principles are: (1) Responsible - DoD personnel will exercise appropriate levels of judgment and care while remaining responsible for the development, deployment, and use of AI capabilities; (2) Equitable - the Department will take deliberate steps to minimize unintended bias in AI capabilities; (3) Traceable - AI capabilities will be developed and deployed such that relevant personnel possess an appropriate understanding of the technology, development processes, and operational methods, including transparent and auditable methodologies, data sources, and design procedure and documentation; (4) Reliable - AI capabilities will have explicit, well-defined uses, and the safety, security, and effectiveness of such capabilities will be subject to testing and assurance within those defined uses across their entire life-cycles; (5) Governable - the Department will design and engineer AI capabilities to fulfill their intended functions while possessing the ability to detect and avoid unintended consequences, and the ability to disengage or deactivate deployed systems that demonstrate unintended behaviour. The principles apply to combat and non-combat AI functions and are operationalised by the Chief Digital and AI Office (CDAO, formerly JAIC) Responsible AI Strategy and Implementation Pathway (June 2022) and DoD Directive 3000.09 on Autonomy in Weapon Systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping",
        "iso_standard",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "us-ndaa-2024-artificial-intelligence-defense",
      "us-eo-13960-promoting-trustworthy-ai-federal-government-2020"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-dod-cdao-responsible-ai-strategy-pathway-2022",
    "title": "US DoD Responsible Artificial Intelligence Strategy and Implementation Pathway (Chief Digital and AI Office, June 22, 2022)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The US Department of Defense Responsible AI Strategy and Implementation Pathway was issued by the DoD Chief Digital and AI Office (CDAO, successor to the Joint AI Center) on June 22, 2022. It operationalises the five DoD AI Ethical Principles (adopted February 24, 2020) into a structured strategy with six foundational tenets and 64 lines of effort. The six foundational tenets are: (1) RAI Governance - establish trustworthy AI leadership and ethical AI culture; (2) Warfighter Trust - ensure that DoD personnel trust AI outputs through transparent, testable systems; (3) AI Product and Acquisition Lifecycle - integrate responsible AI into acquisition, development, and lifecycle management; (4) Requirements Validation - ensure AI systems meet validated mission requirements; (5) Responsible AI Ecosystem - build a research and development ecosystem that promotes responsible AI; (6) AI Workforce - develop a workforce that can build, acquire, and operate AI responsibly. Each tenet has explicit goals and lines of effort with assigned responsibilities across DoD components. The Pathway is the operational guide for DoD program managers building or acquiring AI capabilities and is referenced by DoD Directive 3000.09 (Autonomy in Weapon Systems, updated January 25, 2023) and the DoD Test and Evaluation Master Plan AI annex.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "nist_framework",
        "iso_standard",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dod-ai-ethical-principles-2020",
      "us-ndaa-2024-artificial-intelligence-defense",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-dod-cybersecurity-maturity-model-cmmc-2-2021",
    "title": "Cybersecurity Maturity Model Certification (CMMC) 2.0: Three-Level Model for Protecting Controlled Unclassified Information (CUI) and Reducing Cyber Risk in the Defense Industrial Base",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The CMMC 2.0 framework requires defense contractors and subcontractors to implement cybersecurity practices aligned with NIST SP 800-171 for Level 2 to protect Controlled Unclassified Information (CUI) in non-federal systems. Compliance is enforced via DFARS Clause 252.204-7021 and verified through self-assessment (Level 1), third-party assessment (Level 2), or government-led assessment (Level 3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-cui",
      "dfars-7012-defense-cyber",
      "cmmc-2-audit",
      "guide-developing-security-plans-federal-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dod-directive-3000-09-autonomy-weapons-2023",
    "title": "US Department of Defense Directive 3000.09 - Autonomy in Weapon Systems (Updated January 25, 2023)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "US Department of Defense Directive 3000.09 Autonomy in Weapon Systems was reissued on January 25, 2023 as the foundational DoD policy on the design, development, acquisition, testing, fielding, and use of autonomous and semi-autonomous weapon systems. The Directive establishes that autonomous and semi-autonomous weapon systems shall be designed to allow commanders and operators to exercise appropriate levels of human judgment over the use of force. Core requirements include: (1) Senior review and approval of autonomous and semi-autonomous weapon systems before formal development and again before fielding by the Under Secretaries of Defense for Policy, Acquisition and Sustainment, and Research and Engineering, with concurrence from the Vice Chairman of the Joint Chiefs of Staff and the General Counsel of the Department of Defense; (2) Test and evaluation including rigorous hardware and software verification and validation in realistic operating environments; (3) Training and doctrine ensuring system operators understand the system's capabilities and limitations; (4) Compliance with the law of war, applicable treaties, weapon system safety rules, and applicable rules of engagement; (5) Mitigation of failure modes including unintended engagements; (6) Application of the DoD AI Ethical Principles (February 2020) and the CDAO Responsible AI Strategy and Implementation Pathway (June 2022) where AI is involved. The Directive remains the operative DoD framework for governing lethal and non-lethal autonomous weapon capabilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "international_alignment",
        "us_federal_alignment",
        "law_of_war_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dod-ai-ethical-principles-2020",
      "us-dod-cdao-responsible-ai-strategy-pathway-2022",
      "us-ndaa-2024-artificial-intelligence-defense"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-dod-instruction-5000-02-acquisition-defense",
    "title": "US DoD Instruction 5000.02 - Operation of the Defense Acquisition System",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This instruction establishes policy and assigns responsibilities for the operation of the Defense Acquisition System using the Adaptive Acquisition Framework (AAF) pathways. It applies to all DoD components and contractors involved in defense acquisition programs, requiring compliance with milestone decision authority (MDA), test and evaluation (T&E), should-cost management, earned value management (EVM), and digital engineering requirements as defined in Enclosure 2 and 3. Key requirements are outlined in Paragraphs E2.1-E2.7 and E3.1-E3.6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cmmc-2-audit",
      "nist-800-171-cui",
      "dfars-7012-defense-cyber",
      "do-178c-airborne-software-2011",
      "cisa-sbom-minimum-elements-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dod-instruction-5000-85-major-capability-acquisition-defense-programs",
    "title": "US DoD Instruction 5000.85 - Major Capability Acquisition Defense Programs",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2023-08-01",
    "bluf": "DoDI 5000.85 establishes policy and responsibilities for Major Capability Acquisition (MCA) programs - the DoD's primary acquisition pathway for developing and procuring military platforms, weapons systems, and major defense systems. The instruction governs Milestone Decision Authority (MDA) decisions at Milestone A (material solution analysis), Milestone B (engineering and manufacturing development), Milestone C (production and deployment), and Full Rate Production. Programs must comply with Congressional certification requirements, Cost Analysis Requirements Description (CARD), and Independent Cost Estimates (ICE) at each milestone.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dfars-7012-defense-cyber"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dod-rmf-8510-01",
    "title": "DoD Instruction 8510.01 - Risk Management Framework (RMF) for DoD Information Technology (IT)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This instruction establishes the DoD Risk Management Framework (RMF), mandating a six-step lifecycle process for all DoD information systems to manage cybersecurity risk and achieve an Authorization to Operate (ATO). It applies to all DoD-owned or controlled IT that receive, process, store, display, or transmit DoD information, as detailed in Enclosure 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dfars-7012-defense-cyber",
      "nist-800-171-rev-3",
      "guide-mapping-information-types-security"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-dodd-frank-1502-conflict-minerals",
    "title": "Dodd-Frank Wall Street Reform and Consumer Protection Act, Section 1502 - Conflict Minerals Disclosure and Due Diligence Requirements for U.S. Public Companies",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Requires U.S. public companies to conduct supply chain due diligence and file an annual Conflict Minerals Report (Form SD) if they manufacture or contract to manufacture products containing tin, tantalum, tungsten, or gold (3TG) that are necessary to the functionality or production of those products and sourced from the Democratic Republic of the Congo (DRC) or adjoining countries. Mandated under Section 13(p) of the Securities Exchange Act of 1934, as added by Section 1502 of the Dodd-Frank Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cmmi-capability-maturity-model-integration-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dodd-frank-act-2010",
    "title": "US Dodd-Frank Wall Street Reform and Consumer Protection Act 2010 -- Volcker Rule, OTC Derivatives, and CFPB",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "The Dodd-Frank Wall Street Reform and Consumer Protection Act 2010 (Pub. L. 111-203) is the primary US post-financial-crisis regulatory reform legislation. Title I establishes the Financial Stability Oversight Council (FSOC) with authority to designate systemically important financial institutions (SIFIs) for enhanced Federal Reserve prudential supervision under Section 165. Title II creates the Orderly Liquidation Authority (OLA) allowing FDIC-led resolution of systemically important failing financial institutions outside normal bankruptcy. Title IV Volcker Rule (Section 619, codified at 12 USC 1851) prohibits banking entities from engaging in proprietary trading and restricts covered fund sponsorship and investment - banking entities with USD 50 billion or more in total assets must have CEO attestation and a formal Volcker compliance programme; banks with total trading assets and liabilities of USD 1 billion or more face enhanced requirements. Title VII mandates central clearing of standardised OTC derivative contracts through Dodd-Frank-registered Derivatives Clearing Organisations (DCOs), mandatory reporting to Swap Data Repositories (SDRs), and exchange trading on Swap Execution Facilities (SEFs); swap dealers must register with the CFTC or SEC if they exceed the USD 8 billion gross notional threshold. Title X establishes the Consumer Financial Protection Bureau (CFPB) as the primary consumer financial protection regulator. Title XIV establishes the ability-to-repay (ATR) and qualified mortgage (QM) standards for residential mortgage lending, implemented at 12 CFR Part 1026 (Regulation Z). The Economic Growth, Regulatory Relief, and Consumer Protection Act 2018 raised enhanced prudential standard thresholds from USD 50 billion to USD 250 billion for most requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-capital-requirements-regulation-2013-575",
      "us-bank-secrecy-act-1970",
      "eu-markets-crypto-assets-regulation-2023-1114"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-dodd-frank-federal-insurance-office-section-502",
    "title": "Dodd-Frank Act Section 502: Federal Insurance Office Authorities and Data Collection Powers",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "Section 502 of the Dodd-Frank Act establishes the Federal Insurance Office (FIO) within the U.S. Department of the Treasury, granting it authority to monitor all aspects of the insurance industry, identify systemically risky insurers, and compel the submission of data from any insurer or affiliate to inform its analysis and reports to Congress (31 U.S.C. § 313).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts",
      "us-nfip-national-flood-insurance-program-rules"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-dodd-frank-key-provisions",
    "title": "US Dodd-Frank Wall Street Reform and Consumer Protection Act 2010 - Titles I, II, VII, X (Key Provisions)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Dodd-Frank Act establishes a comprehensive regulatory framework to reduce systemic risk in the U.S. financial system, primarily affecting banks, financial institutions, and market participants. Key provisions under Titles I, II, VII, and X mandate enhanced supervision for systemically important financial institutions (SIFIs), create an orderly liquidation authority for failing firms, regulate the over-the-counter swaps market, and establish the Consumer Financial Protection Bureau (CFPB).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dodd-frank-volcker-rule",
      "fsb-key-attributes-res",
      "cftc-part-49-swap-reporting",
      "basel-iii-global-regulatory-framework",
      "principles-effective-risk-data-aggregation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-dodd-frank-sec-13f",
    "title": "US Dodd-Frank Act Section 13F - Large Institutional Investment Manager Reporting (Form 13F)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Under Section 13(f) of the Securities Exchange Act of 1934, institutional investment managers exercising investment discretion over $100 million or more in specified equity securities must file Form 13F quarterly with the SEC to report their holdings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "private-fund-advisers-compliance-reviews"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-dodd-frank-section-922-sec-whistleblower-program",
    "title": "US Dodd-Frank Act Section 922 - SEC Whistleblower Program Protections and Awards",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Section 922 of the Dodd-Frank Wall Street Reform and Consumer Protection Act (2010) establishes the SEC Whistleblower Program: awarding whistleblowers 10-30% of sanctions above $1M for original information leading to successful enforcement, prohibiting retaliation against employees who report securities law violations, allowing anonymous submissions through counsel, and imposing strict anti-retaliation protections enforced by the SEC and through private right of action in federal court.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-whistleblower-directive-2019-1937-reporting-channels-protection"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dodd-frank-stress-testing-dfast-2010",
    "title": "US Dodd-Frank Act Stress Testing (DFAST) and CCAR - 12 USC 5365(i)",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "Dodd-Frank stress testing (DFAST) and the Comprehensive Capital Analysis and Review (CCAR) require bank holding companies with ≥$100B in total consolidated assets to submit annual capital plans and stress tests to the Federal Reserve; Category I firms (≥$250B or G-SIBs) face the most stringent requirements including annual supervisory stress tests under three scenarios (baseline, adverse, severely adverse) over a 9-quarter forward horizon.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-holding-company-act-1956",
      "us-dodd-frank-title-vii-otc-derivatives-2010",
      "us-glba-gramm-leach-bliley-act-1999"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dodd-frank-title-vi-insurance-federal-insurance-office",
    "title": "US Dodd-Frank Title VI - Federal Insurance Office (FIO) Oversight",
    "domain": "Insurance & Risk",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Title VI of the Dodd-Frank Act (2010) establishes the Federal Insurance Office (FIO) within Treasury to monitor the insurance industry for systemic risk, coordinate US insurance policy internationally, and report annually to Congress; FIO has authority to preempt state insurance measures inconsistent with covered agreements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-dodd-frank-title-vii-otc-derivatives-2010",
    "title": "US Dodd-Frank Act Title VII - OTC Derivatives and Swap Dealer Regulation",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Title VII of the Dodd-Frank Wall Street Reform and Consumer Protection Act (Pub. L. 111-203, 21 July 2010) established the comprehensive US regulatory framework for over-the-counter (OTC) derivatives. It requires swap dealers (SDs) and major swap participants (MSPs) to register with the CFTC (commodity swaps) or SEC (security-based swaps), mandates central clearing through CFTC-registered DCOs for standardised swaps, requires trading on SEFs (swap execution facilities) or exchanges, imposes real-time and daily reporting to SDRs (swap data repositories), establishes margin requirements for uncleared swaps (IM/VM), and provides a commercial end-user exception for non-financial firms hedging commercial risk. CFTC and SEC share jurisdiction based on asset class.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-emir-regulation-648-2012",
      "eu-capital-requirements-directive-iv-2013-36-crd4",
      "us-bank-secrecy-act-31-cfr-1010-aml"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dodd-frank-volcker-rule-12-cfr-248-proprietary-trading-prohibition",
    "title": "Dodd-Frank Volcker Rule 12 CFR Part 248 - Proprietary Trading Prohibition for Banking Entities",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Section 619 of the Dodd-Frank Act (12 U.S.C. § 1851), implemented by 12 C.F.R. Part 248, prohibits banking entities from engaging in proprietary trading and from acquiring or retaining ownership interests in covered funds. The rule contains exemptions for market making, underwriting, hedging, and U.S. government obligation trading.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dodd-frank-volcker-rule"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-doe-c2m2-cybersecurity-maturity-model",
    "title": "Cybersecurity Capability Maturity Model (C2M2) Version 2.1",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The C2M2 provides a structured framework for organizations to evaluate and improve cybersecurity capabilities across IT and OT environments using 10 domains and 4 Maturity Indicator Levels (MILs 0-3). It applies to any organization, especially in the energy sector, seeking to benchmark and mature its cybersecurity posture based on industry-vetted practices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-industrial-automation-security-standards",
      "iec-62351-power-systems-cybersecurity",
      "isa-99-iec-62443-industrial-security-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-doj-ada-ai-disability-employment-2022",
    "title": "US Department of Justice Civil Rights Division - Algorithms, Artificial Intelligence, and Disability Discrimination in Hiring (May 12, 2022)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On May 12, 2022 the US Department of Justice Civil Rights Division published a guidance document titled Algorithms, Artificial Intelligence, and Disability Discrimination in Hiring, issued jointly with the companion EEOC ADA AI guidance. The DOJ guidance addresses how the Americans with Disabilities Act applies to employer use of automated decision-making and AI tools in hiring and employment, with specific focus on the obligations of employers receiving federal financial assistance under ADA Title II and other federal civil rights statutes. The guidance identifies three principal areas where AI tools may violate the ADA: (1) Failure to provide reasonable accommodation in the administration of AI assessment tools so that applicants with disabilities are rated fairly and accurately; (2) Use of tools that screen out individuals with disabilities who could perform the job with reasonable accommodation; (3) Use of tools that constitute disability-related inquiries or medical examinations in violation of the ADA's pre-employment restrictions. The DOJ guidance reinforces that vendor responsibility does not displace employer ADA liability and recommends practical steps including accommodation processes, vendor diligence, alternative assessment options, and training of staff. The guidance operates with the EEOC ADA AI guidance (May 12, 2022) and was reinforced by the four-agency Joint Statement on AI civil rights enforcement (April 25, 2023).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "regulatory_overlay",
        "ai_governance_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eeoc-ada-ai-job-applicants-guidance-2022",
      "us-eeoc-ai-employment-guidance-2023",
      "us-doj-eeoc-cfpb-ftc-joint-statement-ai-2023",
      "us-eeoc-29-cfr-1630-ada-employment-provisions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-doj-ai-criminal-enforcement-priority-2026",
    "title": "US DOJ AI Criminal Misuse Enforcement Priority (Sec. 4, EO Promoting Advanced AI Innovation and Security, 2026)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "Section 4 (Protection Against Criminal Actors) of the Executive Order Promoting Advanced Artificial Intelligence Innovation and Security signed June 2, 2026 directs the Attorney General to prioritise enforcement against individuals who use AI to illegally access or damage computer systems, steal data, or facilitate other criminal activity. Section 4 does not create new criminal offences and does not amend existing statutes; it sets a Department of Justice enforcement priority within existing federal criminal law. The statutory perimeter that the Attorney General will use to prosecute AI-enabled misuse remains the unchanged set of federal criminal computer and fraud statutes including 18 USC 1030 (Computer Fraud and Abuse Act covering unauthorised access, obtaining information, damage to protected computers, and trafficking in passwords), 18 USC 1028 and 1028A (identity theft and aggravated identity theft), 18 USC 1343 (wire fraud where AI is used to generate or transmit deceptive communications), 18 USC 875(c) (interstate threats including AI-generated extortion or threats), 18 USC 2261A (cyberstalking including AI-generated harassment), 18 USC 2252 and 2252A (sexual exploitation of minors including AI-generated child sexual abuse material), and 18 USC 1951 (Hobbs Act extortion where AI is the instrumentality). Lead DOJ components are the Computer Crime and Intellectual Property Section (CCIPS) within the Criminal Division, the National Security Cyber Section within the National Security Division, the United States Attorneys' Offices for prosecution, and the FBI Cyber Division for investigation. Section 4 implicitly authorises CCIPS to update prosecutor training materials, charging guidance, and search warrant templates to address AI-as-instrumentality cases; existing precedent under 18 USC 1030 already covers AI-driven unauthorised access without statutory amendment. Section 4 does not displace state criminal jurisdiction over AI-enabled offences and does not affect civil enforcement under Federal Trade Commission Act Section 5 or under sectoral regulators (CFTC, SEC, FCC). The enforcement priority sits alongside but is operationally separate from the Section 2 AI Cybersecurity Clearinghouse and the Section 3 voluntary frontier model framework. There is no Section 4 reporting obligation imposed on private entities; voluntary referral to DOJ for AI misuse incidents remains through pre-existing FBI IC3 and CISA reporting channels.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-promoting-advanced-ai-innovation-security-2026",
      "us-ai-cybersecurity-clearinghouse-2026",
      "us-cisa-circia-cyber-incident-reporting-2022",
      "budapest-convention-cybercrime-2001",
      "us-doj-bulk-sensitive-data-28cfr-202-2025"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-doj-bulk-sensitive-data-28cfr-202-2025",
    "title": "DOJ Final Rule on Bulk US Sensitive Personal Data and Government-Related Data - 28 CFR Part 202 (EO 14117 implementation)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The DOJ Final Rule at 28 CFR Part 202, implementing Executive Order 14117 (\"Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern\"), is effective 8 April 2025. It restricts and prohibits covered data transactions (Section 202.210) involving bulk US sensitive personal data (Section 202.206) and government-related data (Section 202.222) with countries of concern (Section 202.601) or covered persons (Section 202.211). Six categories of sensitive personal data: covered personal identifiers (Section 202.212), precise geolocation data (Section 202.242), biometric identifiers (Section 202.204), human `omic data (Section 202.224), personal financial data (Section 202.240), and personal health data (Section 202.241). Bulk thresholds (Section 202.205): 100 US persons for human genomic data; 1,000 US persons for epigenomic/proteomic/transcriptomic data; 1,000 US devices for precise geolocation; 10,000 US persons for personal financial data, personal health data, biometric identifiers and covered personal identifiers; 100,000 US persons for human `omic data outside genomic. Data brokerage to countries of concern or covered persons is prohibited (Section 202.301). Restricted transactions (vendor agreements Section 202.258, employment Section 202.217, investment agreements Section 202.228) require CISA Security Requirements compliance, due diligence (Section 202.1001) and audits (Section 202.1002). Recordkeeping under Section 202.1101 and rejected-transaction reporting under Section 202.1104.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_eo_14117_data_security_2024",
        "cisa_security_requirements_2024",
        "us_glba_financial_privacy_1999",
        "hipaa_privacy_rule",
        "us_ear_dual_use_export_control"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-glba-gramm-leach-bliley-act-1999",
      "hipaa-privacy-rule",
      "ear-dual-use-export"
    ],
    "primary_citations_count": 27
  },
  {
    "node_id": "us-doj-corporate-leniency-policy-2017-revision",
    "title": "US DOJ Corporate Leniency Policy - Amnesty for First-In Cartel Participants: Automatic and Non-Automatic Amnesty, Individual Leniency and Proffer Process",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The US Department of Justice Antitrust Division grants full corporate amnesty to the first cartel participant that voluntarily discloses illegal anticompetitive conduct, reports it before an investigation is underway, and satisfies ongoing cooperation requirements under the Leniency Program. Applies to corporations involved in hard-core cartel conduct such as price-fixing, bid-rigging, and market allocation under Section 1 of the Sherman Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-doj-eeoc-cfpb-ftc-joint-statement-ai-2023",
    "title": "US DOJ-EEOC-CFPB-FTC Joint Statement on Enforcement Efforts Against Discrimination and Bias in Automated Systems (April 25, 2023)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On April 25, 2023 the heads of four US federal civil rights and consumer protection agencies issued a Joint Statement on Enforcement Efforts Against Discrimination and Bias in Automated Systems. The signatories are the Department of Justice Civil Rights Division (Assistant Attorney General Kristen Clarke), the Equal Employment Opportunity Commission (Chair Charlotte A. Burrows), the Consumer Financial Protection Bureau (Director Rohit Chopra), and the Federal Trade Commission (Chair Lina M. Khan). The Joint Statement makes three principal points: (1) Existing federal laws including the Civil Rights Acts, ADA, Equal Credit Opportunity Act, Fair Credit Reporting Act, FTC Act Section 5, and CFPB UDAAP authority apply to automated systems and AI; (2) Automated systems present challenges including data and design flaws (training data unrepresentative, datasets reflecting historical bias), opaque models making discrimination hard to detect, and design choices that may not account for relevant context; (3) The four agencies pledge to coordinate enforcement against discrimination and bias in automated systems and to use the full range of existing authorities. The Joint Statement remains the operative interagency civil rights enforcement baseline for AI in the US and underpins subsequent enforcement actions including the FTC Rite Aid case (December 2023), EEOC iTutorGroup settlement (2023), and CFPB Circular 2022-03 enforcement posture.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "regulatory_overlay",
        "ai_governance_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eeoc-ai-employment-guidance-2023",
      "us-eeoc-ada-ai-job-applicants-guidance-2022",
      "us-cfpb-circular-2022-03-adverse-action-ai-credit",
      "us-ostp-blueprint-ai-bill-of-rights"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-doj-ftc-horizontal-merger-guidelines-2023",
    "title": "2023 Merger Guidelines",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The 2023 DOJ/FTC Horizontal Merger Guidelines establish a framework for identifying mergers that may substantially lessen competition or tend to create a monopoly under Section 7 of the Clayton Act (15 U.S.C. § 18). The guidelines apply to all non-vertical mergers and acquisitions where market concentration, unilateral effects, coordinated effects, or barriers to entry may harm competition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-competition",
      "us-hart-scott-rodino-hsr-premerger-notification"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-doj-ftc-merger-guidelines-2023",
    "title": "2023 Merger Guidelines",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-12-18",
    "bluf": "The 2023 Merger Guidelines describe how the Department of Justice (DOJ) and Federal Trade Commission (FTC) analyze mergers and acquisitions to determine compliance with U.S. antitrust laws. They establish a structural presumption that mergers resulting in a highly concentrated market (HHI > 1800) with a significant increase in concentration (change in HHI > 100) are illegal, as detailed in Guideline 1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-competition",
      "us-hart-scott-rodino-hsr-premerger-notification"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-doj-nsd-bulk-data-final-rule-28-cfr-202-2024",
    "title": "US DOJ National Security Division Final Rule on Bulk Sensitive Personal Data Transactions - 28 CFR 202 (December 27 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The US Department of Justice National Security Division issued a Final Rule on December 27, 2024 implementing Executive Order 14117 of February 28, 2024 on access by countries of concern to Americans bulk sensitive personal data and US government-related data. The Rule is codified at 28 CFR 202 and took effect April 8, 2025. It implements two regulatory pathways. The first is Prohibited Transactions which are flatly forbidden absent a DOJ licence: data brokerage to a country of concern or covered person; transactions involving bulk human genomic data or biospecimens; and any transaction posing unacceptable national security risk. The second is Restricted Transactions which may proceed only subject to CISA security requirements: vendor agreements (including cloud computing services), employment agreements, and investment agreements involving covered data. The Rule defines bulk thresholds for each covered data category - 100 US persons for genomic data; 1000 US persons for biometric, geolocation, health, or financial data; 10000 US persons for human-derived identifiers - measured over a 12-month period. The Rule defines covered persons as foreign persons primarily resident in a country of concern, foreign entities organised in or majority-owned by a country of concern, certain employees and contractors, and entities designated by the Attorney General. Penalties under IEEPA apply for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "ai_governance_overlay",
        "us_federal_alignment",
        "regulatory_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14117-bulk-data-foreign-adversary-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-dol-29-cfr-541-exemptions-minimum-wage-overtime-white-collar",
    "title": "29 CFR Part 541 - Defining and Delimiting the Exemptions for Executive, Administrative, Professional, Computer and Outside Sales Employees",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must classify employees as exempt or non-exempt from federal minimum wage and overtime pay requirements based on specific salary and duties tests for executive, administrative, professional, computer, and outside sales roles.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "us-dol-ai-worker-principles-2024",
    "title": "US Department of Labor - AI and Worker Well-Being Principles and Best Practices (April 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The US Department of Labor (DOL) published 'Artificial Intelligence and Worker Well-Being: Principles and Best Practices for Developers and Employers' in April 2024, establishing the Biden administration's framework for responsible AI use in the workplace; the DOL principles respond to Section 7.2 of Executive Order 14110 (October 2023) which directed the DOL to develop guidance on AI's impact on workers; the eight DOL AI principles for workplace AI are: (1) Centering worker empowerment - workers and their representatives should have genuine input into the design, development, and deployment of AI systems that affect them; (2) Ethically developing AI - developers must address bias, safety, and responsible data use from the design stage; (3) Establishing AI governance and human oversight - employers must maintain meaningful human oversight of AI-enabled decisions affecting workers; (4) Ensuring transparency and explainability - workers must be informed when AI is used in decisions affecting their employment and receive an explanation of how those decisions are made; (5) Protecting labor and employment rights - AI systems must not undermine workers' rights under the National Labor Relations Act, anti-discrimination laws, or wage and hour laws; (6) Using AI to enable workers - AI should augment workers' capabilities and enhance job quality, not purely displace or surveil workers; (7) Supporting workers impacted by AI - employers should provide training, transition support, and career development for workers affected by AI-driven changes; (8) Ensuring responsible use of worker data - worker data collected through AI systems must be used only for legitimate purposes, stored securely, and not used to undermine worker rights; the DOL principles are non-binding guidance (not regulation) but reflect DOL's enforcement priorities under existing statutes including FLSA, NLRA, Title VII, ADA, and OSHA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-dol-ai-worker-principles-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14110-ai-2023",
      "us-eeoc-ai-employment-guidance-2023",
      "us-ostp-blueprint-ai-bill-of-rights"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dol-cfr-29-part-2550-erisa-fiduciary-rules",
    "title": "29 CFR Part 2550 - Rules and Regulations for Fiduciary Responsibility",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes rules for fiduciary responsibility under the Employee Retirement Income Security Act of 1974 (ERISA), covering the establishment of trusts, investment duties, disclosures, and exemptions for specific transactions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-dol-registered-apprenticeship-education",
    "title": "US DOL Registered Apprenticeship Programme Standards - On-the-Job Learning, Related Technical Instruction, Progressively Increasing Wage Schedule, Apprentice-to-Journeyworker Ratio and EEO Requirements",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes the core requirements for Registered Apprenticeship Programs in the United States, including paid work experience, structured on-the-job learning with mentorship, supplemental classroom instruction, progressive wage increases, and the attainment of a nationally recognized credential. It applies to employers and sponsors seeking to register an apprenticeship program with the U.S. Department of Labor or a State Apprenticeship Agency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dot-49-cfr-40-workplace-drug-alcohol-testing-procedures",
    "title": "49 CFR Part 40 - Procedures for Transportation Workplace Drug and Alcohol Testing Programs (DOT)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "DOT 49 CFR Part 40 prescribes the uniform procedures for drug and alcohol testing across all DOT-regulated transportation industries, covering employer responsibilities and the separation of DOT from non-DOT testing, use and oversight of service agents, previous-employer record checks, collector qualifications and the Federal collection process, specimen integrity and directly observed collections, certified-laboratory testing with fixed cutoff concentrations and validity testing, medical review officer verification of confirmed results, and the employer actions and stand-down rules that follow a verified test result.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 22
  },
  {
    "node_id": "us-dot-phmsa-49-cfr-107-hazardous-materials-program-procedures",
    "title": "49 CFR Part 107 - Hazardous Materials Program Procedures (PHMSA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "PHMSA 49 CFR Part 107 sets the program procedures for the Hazardous Materials Regulations, governing applications for and processing of special permits and party status, the standards and procedures for preemption determinations, the registration of persons who offer or transport hazardous materials and the associated fees and recordkeeping, the processing of applications for approval, and the enforcement process including investigations, warning letters, tickets, notices of probable violation, hearings, and appeals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dot-phmsa-49-cfr-172-hazmat-shipping-marking-labelling"
    ],
    "primary_citations_count": 29
  },
  {
    "node_id": "us-dot-phmsa-49-cfr-172-hazmat-shipping-marking-labelling",
    "title": "US DOT PHMSA 49 CFR Part 172 - Hazardous Materials Shipping Regulations, Marking & Placarding",
    "domain": "Logistics & Supply Chain",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "US DOT PHMSA Hazardous Materials Regulations (49 CFR Parts 171-180) govern classification, packaging, marking, labelling, placarding, and documentation for hazardous materials in US domestic and international transport - civil penalties up to $87,236 per day per violation; criminal penalties for willful violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-dot-phmsa-49-cfr-173-shippers-general-requirements",
    "title": "49 CFR Part 173 - Shippers - General Requirements for Shipments and Packagings (PHMSA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "PHMSA 49 CFR Part 173 sets the shipper requirements of the Hazardous Materials Regulations, requiring offerors to classify each material by hazard class and division, screen out forbidden materials, fulfill the shipper responsibilities to describe, package, mark, label, and certify shipments, meet general and packaging-specific integrity requirements for non-bulk and bulk packagings, use only authorized packagings and overpacks within quantity limitations, meet additional requirements for transport by aircraft, qualify reused, reconditioned, or remanufactured packagings, and handle empty packagings that retain residue.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dot-phmsa-49-cfr-172-hazmat-shipping-marking-labelling"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-dot-phmsa-49-cfr-177-hazmat-carriage-by-public-highway",
    "title": "DOT PHMSA Hazardous Materials Regulations 49 CFR Part 177 - Carriage by Public Highway",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "49 CFR Part 177 prescribes the requirements, in addition to those in parts 171, 172, 173, 178 and 180, applicable to the acceptance and transportation of hazardous materials by motor vehicle on public highways. Carriers must comply with the Federal Motor Carrier Safety Regulations, train hazmat employees, transport shipments without unnecessary delay, secure and segregate packages, and follow class-specific loading, unloading, and emergency-movement rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dot-phmsa-49-cfr-172-hazmat-shipping-marking-labelling",
      "us-dot-phmsa-49-cfr-173-shippers-general-requirements",
      "us-fmcsa-49-cfr-395-hours-of-service-drivers"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-dot-phmsa-49-cfr-178-packaging-specifications",
    "title": "49 CFR Part 178 - Specifications for Packagings (PHMSA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "PHMSA 49 CFR Part 178 sets the specifications for packagings used to transport hazardous materials, requiring manufacturers and offerors to use packagings that meet the applicable DOT specification or performance-oriented packaging standard, mark them with the required specification or United Nations markings, build them to the construction standards for the packaging type, qualify each design type through drop, leakproofness, hydrostatic pressure, and stacking tests, and meet the parallel code, marking, construction, testing, and certification requirements for intermediate bulk containers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dot-phmsa-49-cfr-172-hazmat-shipping-marking-labelling"
    ],
    "primary_citations_count": 25
  },
  {
    "node_id": "us-dot-phmsa-49-cfr-180-packaging-requalification-maintenance",
    "title": "49 CFR Part 180 - Continuing Qualification and Maintenance of Packagings (PHMSA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "PHMSA 49 CFR Part 180 sets the continuing qualification and maintenance requirements for packagings used to transport hazardous materials, requiring periodic requalification, repair, and marking of specification cylinders and UN pressure receptacles, retest and inspection of intermediate bulk containers, qualification and periodic test and inspection of cargo tanks by qualified inspectors, and qualification and inspection of tank cars, together with the associated recordkeeping and reporting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dot-phmsa-49-cfr-172-hazmat-shipping-marking-labelling"
    ],
    "primary_citations_count": 21
  },
  {
    "node_id": "us-dot-v2x-connected-vehicles-policy",
    "title": "US DOT Connected Vehicles V2X Infrastructure Deployment Strategy - DSRC to C-V2X Technology Transition, RSU Deployment Standards and FHWA Safety Application Requirements",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-05-20",
    "bluf": "This US Department of Transportation (DOT) policy mandates that state and local agencies using federal funds for new Vehicle-to-Everything (V2X) infrastructure deployments must use Cellular V2X (C-V2X) technology. As stated in the policy's core message, entities with existing Dedicated Short-Range Communications (DSRC) deployments must develop a transition plan to C-V2X to ensure nationwide interoperability and leverage modern communication standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-57-key-management",
      "nist-sp-800-131a-rev-2-crypto-transitions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-dppa-1994",
    "title": "US Driver's Privacy Protection Act 1994",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Driver's Privacy Protection Act restricts the use and disclosure of personal information from state motor vehicle records, permits disclosure only for fourteen enumerated permissible uses, and provides a private right of action with liquidated damages of USD 2,500 per day and actual damages for unauthorised disclosures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-dppa-1994.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fcra-1970"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-drug-supply-chain-security-act-2023-dscsa",
    "title": "Drug Supply Chain Security Act (DSCSA) - Enhanced Drug Distribution Security Requirements for Interoperable, Electronic Tracing of Products at the Package Level",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The DSCSA requires all pharmaceutical trading partners to implement a fully electronic, interoperable system to trace and verify prescription drugs at the individual package level throughout the U.S. supply chain. As mandated by Section 582 of the FD&C Act, this includes exchanging secure transaction information (TI) and transaction statements (TS) for each product movement and verifying product identifiers upon request or for saleable returns.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-dscsa-2013-drug-supply-chain-security-act",
    "title": "Drug Supply Chain Security Act",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Drug Supply Chain Security Act (DSCSA) requires pharmaceutical manufacturers, wholesalers, and dispensers to implement a system for tracking and tracing certain prescription drugs, as outlined in Section 582 of the Federal Food, Drug, and Cosmetic Act. This applies to all entities involved in the supply chain, including manufacturers, repackagers, wholesale distributors, and dispensers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-e-government-act-2002",
    "title": "United States E-Government Act of 2002 (Title 44 USC Chapter 36): Office of Electronic Government, CIO Council, E-Government Fund, and FedRAMP Cloud Authorization",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The E-Government Act of 2002, codified at Title 44 of the United States Code, Chapter 36, is the principal federal statute establishing the institutional architecture for federal electronic government and is administered through the Office of Electronic Government within the Office of Management and Budget. E-Government Act, 44 U.S.C. 3601 defines electronic Government as the use by the Government of web-based Internet applications and other information technologies to enhance government service delivery and operations. E-Government Act, 44 U.S.C. 3602 establishes in the Office of Management and Budget an Office of Electronic Government headed by a presidential appointee who assists the Director with electronic government implementation. E-Government Act, 44 U.S.C. 3603 establishes in the executive branch a Chief Information Officers Council serving as the principal interagency forum for improving agency practices in managing federal information resources. E-Government Act, 44 U.S.C. 3604 establishes in the Treasury of the United States the E-Government Fund administered by the General Services Administration to fund projects advancing electronic government capabilities. E-Government Act, 44 U.S.C. 3605 establishes a program to encourage innovative solutions to enhance electronic Government services and processes. E-Government Act, 44 U.S.C. 3606 requires the Director to submit an annual E-Government report to Congress on the operation of the Fund and approved projects. E-Government Act, 44 U.S.C. 3608 establishes the Federal Risk and Authorization Management Program (FedRAMP), and E-Government Act, 44 U.S.C. 3609 through 3616 set out roles and responsibilities of the General Services Administration, the FedRAMP Board, independent assessment requirements, foreign interest declarations, agency roles, Office of Management and Budget roles, reports to Congress, and the Federal Secure Cloud Advisory Committee. The Act is the controlling federal instrument for federal electronic government and cloud authorization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-e-rate-schools-libraries-connectivity",
    "title": "Universal Service Program for Schools and Libraries (E-Rate): Category 1 and Category 2 Funding, Priority System, CIPA Compliance, and Annual Discount Rates",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The E-Rate program provides discounted telecommunications, internet access, and internal connections to eligible schools and libraries in the United States, subject to annual funding caps, a two-tier priority system, and compliance with the Children's Internet Protection Act (CIPA) under 47 U.S.C. § 254(h). Eligible entities must file Form 470 and Form 486 and maintain documentation for audit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-education-action-plan-2021-2027-deap",
      "bologna-process-higher-education-area-2020",
      "eu-erasmus-programme-regulation-2021-817"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-e-verify-i9-employment-eligibility-verification",
    "title": "US E-Verify and Form I-9 - Employment Eligibility Verification under INA Section 274A",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Immigration and Nationality Act Section 274A (8 U.S.C. § 1324a) requires all US employers to verify employment eligibility using Form I-9 (Employment Eligibility Verification); E-Verify is the internet-based federal employment eligibility verification system that electronically confirms I-9 data against SSA and DHS databases. E-Verify is mandatory for federal contractors under FAR 22.1800 and in 21 states with state mandates. AI-based HR onboarding platforms, automated I-9 systems, and remote identity document verification tools must comply with DHS electronic I-9 requirements under 8 CFR 274a and face anti-discrimination obligations under INA Section 274B (8 U.S.C. § 1324b).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standards",
        "frameworks",
        "regulations",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric",
      "us-hipaa-privacy-rule-2003"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ear-15-cfr-730-774-ccl-9x515-space-export-controls",
    "title": "US Export Administration Regulations (15 CFR 730-774) CCL Category 9x515 Space Export Controls",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2025-10-01",
    "bluf": "The Export Administration Regulations (EAR) administered by the US Department of Commerce Bureau of Industry and Security (BIS) at 15 CFR Parts 730 to 774 control the export, reexport, and in-country transfer of dual-use commodities, software, and technology including most non-defense space items not subject to the International Traffic in Arms Regulations (ITAR). Category 9 of the EAR Commerce Control List (CCL) at 15 CFR Part 774 Supplement No. 1 covers Aerospace and Propulsion. The 9x515 series Export Control Classification Numbers (ECCNs) (9A515, 9B515, 9C515, 9D515, 9E515) cover spacecraft and related commodities, components, equipment, materials, software, and technology that were transitioned from ITAR jurisdiction to the EAR through the Export Control Reform Initiative completed in 2014.\n\nThe 9x515 ECCN series is controlled for National Security (NS Column 1), Regional Stability (RS Column 1), Anti-Terrorism (AT Column 1), and certain country-specific destinations. License Exception Strategic Trade Authorization (STA) at 15 CFR 740.20 permits export of certain 9x515 items to authorized end users in Country Group A:5 destinations subject to consignee statement and other conditions. License Exception Government and Other Items (GOV) at 15 CFR 740.11 permits exports for US government end use. The EAR applies to US persons abroad through deemed export rules and to foreign-produced items that incorporate controlled US technology under the de minimis and direct product rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-itar-22-cfr-120-130-arms-export",
      "wassenaar-arrangement-1996-dual-use-conventional-arms"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-economic-espionage-act-1996-18-usc-1831",
    "title": "US Economic Espionage Act of 1996 (18 USC 1831) - Federal Criminal Theft of Trade Secrets",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Economic Espionage Act of 1996 criminalised the misappropriation of trade secrets under federal law with two principal offenses: economic espionage benefiting a foreign government, instrumentality, or agent under 18 USC 1831, and theft of trade secrets for the economic benefit of any party other than the owner under 18 USC 1832, defined trade secret broadly to include financial, business, scientific, technical, economic, and engineering information that the owner has taken reasonable measures to protect and that derives independent economic value from secrecy, authorised criminal forfeiture of proceeds and instrumentalities, and was substantially amended by the Defend Trade Secrets Act of 2016 to create a federal civil cause of action for misappropriation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-defend-trade-secrets-act-2016",
      "us-rico-organized-crime-control-act-18-usc-1961"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ecpa-1986",
    "title": "US Electronic Communications Privacy Act 1986",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Electronic Communications Privacy Act establishes a framework governing interception of electronic communications (Wiretap Act), government access to stored electronic communications (Stored Communications Act), and use of pen registers and trap-and-trace devices - forming the primary federal statutory framework for electronic communications privacy in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ecpa-1986.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cloud-act-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-eeoc-29-cfr-1602-recordkeeping-reporting-requirements",
    "title": "29 CFR Part 1602 - Recordkeeping and Reporting Requirements under Title VII, the ADA, GINA, and the PWFA (EEOC)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EEOC 29 CFR Part 1602 sets the recordkeeping and reporting requirements under Title VII, the ADA, GINA, and the Pregnant Workers Fairness Act, requiring covered employers to file the required employer information report, ensure the report contains no willfully false statements, cooperate with the Commission's remedy for failure to file, provide any additional reports required, make and keep the required employment records including records of the racial or ethnic identity of employees, and preserve those records for the required retention period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-eeoc-29-cfr-1620-equal-pay-act",
    "title": "29 CFR Part 1620 - The Equal Pay Act (EEOC)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EEOC 29 CFR Part 1620 interprets the Equal Pay Act, requiring an employer to determine coverage and the relevant establishment and employment relationship, treat all forms of wages including fringe benefits consistently, assess whether jobs constitute equal work requiring equal skill, effort, and responsibility performed under similar working conditions, apply equal wages and equalize rates upward where a violation exists, evaluate any affirmative defense and reject impermissible justifications, and observe the relationship to Title VII and the investigation and compliance provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 20
  },
  {
    "node_id": "us-eeoc-29-cfr-1630-ada-employment-provisions",
    "title": "29 CFR Part 1630 - Regulations to Implement the Equal Employment Provisions of the Americans with Disabilities Act (EEOC)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EEOC 29 CFR Part 1630 implements the employment provisions of the Americans with Disabilities Act, requiring covered employers to determine disability and qualified-individual status, refrain from discrimination and from unlawful limiting, segregating, or classifying of employees, control discrimination through contractual arrangements and methods of administration, protect individuals based on their association with a person with a disability, provide reasonable accommodation absent undue hardship, validate qualification standards and tests, prohibit retaliation and coercion, limit medical examinations and inquiries to those permitted, and rely only on the defenses and specific activities the regulation permits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 16
  },
  {
    "node_id": "us-eeoc-ada-ai-job-applicants-guidance-2022",
    "title": "US EEOC Technical Assistance - The Americans with Disabilities Act and the Use of Software, Algorithms, and AI to Assess Job Applicants and Employees (May 12, 2022)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On May 12, 2022 the US Equal Employment Opportunity Commission issued technical assistance under its AI and Algorithmic Fairness Initiative addressing how the Americans with Disabilities Act (ADA) applies to employer use of software, algorithms, and AI to assess job applicants and employees. The document identifies three principal ways such tools can violate the ADA: (1) failing to provide a reasonable accommodation necessary for an applicant or employee to be rated fairly and accurately by the tool; (2) intentionally or unintentionally screening out an individual with a disability, even though that individual is able to do the job with a reasonable accommodation; (3) violating the ADA's restrictions on disability-related inquiries and medical examinations - including by asking questions that elicit information about a disability or requiring a medical examination before a conditional job offer. The guidance also addresses vendor-employer responsibility: employers are responsible for ADA violations by their AI vendors when the employer adopts the vendor's tool, and the guidance recommends inquiring about whether the vendor designed the tool to be accessible and to avoid screen-outs. Promising practices include training staff on ADA-compliant tool use, providing reasonable accommodations in test administration, and clearly publishing accommodation request procedures. The document is companion guidance to the 2023 EEOC Title VII AI technical assistance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "regulatory_overlay",
        "ai_governance_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eeoc-29-cfr-1630-ada-employment-provisions",
      "us-eeoc-ai-employment-guidance-2023",
      "us-ostp-blueprint-ai-bill-of-rights",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-eeoc-ai-employment-guidance-2023",
    "title": "US EEOC - Artificial Intelligence and Employment Decision-Making: Title VII Adverse Impact Guidance (2023)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The US Equal Employment Opportunity Commission (EEOC) published 'Select Issues: Assessing Adverse Impact in Software, Algorithms, and Artificial Intelligence Used in Employment Selection Procedures' in May 2023, providing technical assistance on how Title VII of the Civil Rights Act of 1964 applies to AI-enabled employment selection tools; key EEOC positions: (1) employer liability - an employer who uses an AI employment selection tool is responsible for Title VII compliance even if the tool was developed by a third-party vendor; if the tool has a disparate impact on a protected group (race, color, religion, sex, national origin), the employer cannot shift liability to the software developer; (2) disparate impact test - AI tools must be assessed for whether they create disparate impact (disproportionate exclusion of a protected class) using the four-fifths (80%) rule or statistical significance tests; (3) job-relatedness and business necessity - if disparate impact is shown, the employer must demonstrate that the tool is job-related and consistent with business necessity (the EEOC's Uniform Guidelines on Employee Selection Procedures 1978 apply); (4) less discriminatory alternatives - even where business necessity is shown, plaintiffs can challenge an AI selection tool if a less discriminatory alternative exists; (5) contractor liability - federal contractors using AI employment tools are also subject to Executive Order 11246 affirmative action obligations; the EEOC's 2023 AI guidance applies to all phases of employment: recruitment, hiring, promotion, pay, performance evaluation, and termination - not just initial hiring; this guidance supplements (but does not replace) the EEOC's 2022 guidance on AI and the Americans with Disabilities Act (ADA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-eeoc-ai-employment-guidance-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ostp-blueprint-ai-bill-of-rights",
      "us-algorithmic-accountability-act-2023",
      "us-il-aivea-2019"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-eesa-tarp-2008-pl-110-343",
    "title": "United States Emergency Economic Stabilization Act of 2008 (EESA) Establishing the Troubled Asset Relief Program (TARP) (Public Law 110-343): Authority to Purchase Troubled Assets, Financial Stability Oversight Board, Reports to Congress, Executive Compensation and Corporate Governance, Minimization of Long-Term Costs, Graduated Authorization, Oversight and Audits, and Special Inspector General for TARP",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Emergency Economic Stabilization Act of 2008 (EESA), Public Law 110-343 of 3 October 2008, is the principal federal statute authorizing the Department of the Treasury to establish the Troubled Asset Relief Program (TARP) to purchase troubled assets from financial institutions in response to the 2008 financial crisis, and is administered by the Department of the Treasury Office of Financial Stability with oversight by the Financial Stability Oversight Board, the Special Inspector General for TARP (SIGTARP), the Government Accountability Office, and the Congressional Oversight Panel. EESA, section 101 authorizes the Secretary of the Treasury to establish the Troubled Asset Relief Program to purchase, and to make and fund commitments to purchase, troubled assets from any financial institution, on such terms and conditions as are determined by the Secretary, and in accordance with this Act and the policies and procedures developed and published by the Secretary. EESA, section 104 establishes the Financial Stability Oversight Board responsible for reviewing the exercise of purchasing authority and reporting any suspected fraud, misrepresentation, or malfeasance. EESA, section 105 requires the Secretary to report to Congress every 30 days on all agreements made or renewed and all insurance contracts entered into. EESA, section 111 mandates executive compensation and corporate governance standards requiring financial institutions to meet appropriate standards for executive compensation including limits on golden parachutes, clawback requirements, and prohibition on incentives for unnecessary risk-taking. EESA, section 113 directs the Secretary to minimize any potential long-term negative impact on the taxpayer while maximizing returns on asset purchases. EESA, section 115 imposes graduated authorization limits: initially 250 billion dollars, expandable to 350 billion dollars with certification, potentially reaching 700 billion dollars with Congressional approval. EESA, section 116 grants the Comptroller General ongoing oversight authority and requires annually audited financial statements. EESA, section 121 establishes the Office of the Special Inspector General for the Troubled Asset Relief Program (SIGTARP) to conduct audits and investigations. The Act is the controlling federal instrument for the TARP framework administered following the 2008 financial crisis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-egg-products-inspection-act",
    "title": "US Egg Products Inspection Act (21 USC ch 15): Inspection of Egg Products, Restricted Eggs and Prohibited Acts",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Egg Products Inspection Act (EPIA), codified at 21 U.S.C. Chapter 15 (sections 1031-1056), provides for the inspection of egg products, regulates the disposition of restricted eggs, and is administered by the USDA Food Safety and Inspection Service (FSIS). Section 1033 defines the regulated terms, including 'egg product', 'restricted egg' (a check, dirty egg, incubator reject, inedible, leaker or loss), 'adulterated' and 'misbranded'. Section 1034 requires continuous inspection of the processing of egg products in official plants, and section 1035 requires sanitary operating practices in those plants. Section 1036 requires the pasteurization and proper labeling of egg products at official plants. Section 1037 sets out the prohibited acts: no person shall buy, sell or transport, or offer to do so, any restricted eggs capable of use as human food except as authorized; no egg handler shall possess with intent to use restricted eggs in the preparation of human food for commerce; and no person shall process any egg products for commerce at any plant except in compliance with the Act, or deal in adulterated or misbranded egg products. Section 1040 imposes recordkeeping requirements, section 1046 governs imports (which must meet standards at least equal to the Act), and sections 1048-1049 provide for administrative detention and for seizure and condemnation of violative articles. Section 1041 sets the penalties: a violation is punishable by imprisonment of not more than one year or a fine of not more than $5,000, or both; but where there is intent to defraud or distribution of an adulterated or misbranded article, by imprisonment of not more than three years or a fine of not more than $10,000, or both; and a civil penalty of not more than $5,000 may be assessed for each violation. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-egg-research-information-act",
    "title": "US Egg Research and Consumer Information Act (7 USC ch 60): Egg Board, Assessments and Consumer Education",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Egg Research and Consumer Information Act (7 U.S.C. ch. 60, sections 2701 to 2718) authorizes a coordinated national program of research, promotion, and consumer information for eggs and egg products, administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 2701 sets out the congressional findings and declaration of policy, and section 2702 defines terms including eggs, egg producer, and handler. Section 2703 authorizes the Secretary to issue orders applicable to egg producers, handlers, and processors, with sections 2704 and 2705 governing notice, hearing, and issuance. Section 2707 prescribes the required terms and conditions of orders, including the establishment of the Egg Board and an assessment mechanism, with the rate of assessment not to exceed 20 cents per case, or the equivalent of a case. Section 2708 requires a referendum among egg producers before an order becomes effective, section 2711 exempts producers with fewer than 75,000 laying hens, and section 2712 provides for refunds of assessments from the Egg Board. Section 2714 provides for civil enforcement, with a civil penalty of not less than 500 dollars and not more than 5,000 dollars per violation, and section 2718 authorizes appropriations. The Act is the federal commodity research and promotion regime for eggs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-electronic-fund-transfer-act",
    "title": "US Electronic Fund Transfer Act (15 USC ch 41 subch VI): Consumer EFT Rights, Error Resolution and Liability Caps",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Electronic Fund Transfer Act (EFTA, 15 U.S.C. ch. 41, subchapter VI) establishes the rights, liabilities and responsibilities of consumers and financial institutions in electronic fund transfers, administered chiefly by the Consumer Financial Protection Bureau. Section 1693 sets the findings and the purpose of providing a basic framework of consumer rights, with the primary objective of protecting individual consumers. Section 1693a supplies the definitions, including electronic fund transfer and accepted card or device. Section 1693c requires the disclosure of the terms and conditions of electronic fund transfers. Section 1693d requires documentation of transfers, including receipts and periodic statements. Section 1693f sets the error-resolution procedure that a financial institution must follow when a consumer asserts an error. Section 1693g limits consumer liability for unauthorized transfers: in no event may a consumer's liability exceed the lesser of 50 dollars or the amount obtained before the institution is notified, with a higher 500-dollar cap where the consumer fails to report within the prescribed period. Section 1693h sets the liability of financial institutions for failures to make transfers. Section 1693m provides civil liability for violations, including actual and statutory damages, and section 1693o provides for administrative enforcement. The Act is the legal foundation of US consumer protection for debit-card, ATM and other electronic transfers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-elementary-secondary-education-act-1965-title-20-ch70",
    "title": "United States Elementary and Secondary Education Act of 1965 (Title 20 USC Chapter 70): Title I Disadvantaged Programs, State and Local Plans, Schoolwide and Targeted Assistance, Accountability, and Federal Compliance",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Elementary and Secondary Education Act of 1965, codified at Title 20 of the United States Code, Chapter 70, is the foundational federal statute governing federal financial assistance to elementary and secondary education and is administered by the United States Department of Education. The Act is most recently reauthorised by the Every Student Succeeds Act of 2015 and replaced the prior reauthorisation under the No Child Left Behind Act of 2001. Subchapter I, Improving the Academic Achievement of the Disadvantaged, contains the principal Title I disadvantaged programs. Elementary and Secondary Education Act, 20 U.S.C. 6301 states that the purpose of this subchapter is to provide all children significant opportunity to receive a fair, equitable, and high-quality education, and to close educational achievement gaps. Elementary and Secondary Education Act, 20 U.S.C. 6311 requires each State desiring to receive a grant under Title I Part A to file with the Secretary a State plan developed with timely and meaningful consultation with the Governor, members of the State legislature, the State board of education, and local educational agencies. Elementary and Secondary Education Act, 20 U.S.C. 6312 requires local educational agency plans. Elementary and Secondary Education Act, 20 U.S.C. 6313 governs eligible school attendance areas. Elementary and Secondary Education Act, 20 U.S.C. 6315 governs targeted assistance schools. Elementary and Secondary Education Act, 20 U.S.C. 6320 requires participation of children enrolled in private schools in Title I Part A services. Subchapter II addresses preparing, training, and recruiting high-quality teachers and school leaders. Subchapter III addresses language instruction for English learners. Subchapter IV covers 21st Century Schools including Charter Schools at Part C. Subchapter V provides flexibility and accountability provisions. Subchapter VIII Part A contains the federal definitions and Part D the waiver authority. The Act is the controlling federal instrument for federally funded elementary and secondary education compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-employee-polygraph-protection-act",
    "title": "US Employee Polygraph Protection Act (29 USC ch 22): Restrictions on Lie Detector Testing",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Employee Polygraph Protection Act (29 U.S.C. ch. 22) restricts the use of lie detector tests by private employers, administered by the Department of Labor. Section 2001 provides the definitions, including lie detector and polygraph. Section 2002 sets the prohibitions: an employer engaged in or affecting commerce may not directly or indirectly require, request, suggest or cause an employee or prospective employee to take or submit to a lie detector test; may not use, accept, refer to or inquire about the results of a test; may not discharge, discipline, discriminate against or deny employment or promotion based on a refusal to take a test or on the results; and may not retaliate against a person for filing a complaint, testifying or exercising rights under the Act. Section 2006 sets out the limited exemptions, including for certain governmental functions, ongoing investigations of economic loss where conditions are met, and security service and controlled substance employers, with strict procedural safeguards for any permitted test. Section 2005 provides enforcement, including a civil penalty of not more than 10,000 dollars assessed by the Secretary and a private right of action with legal and equitable relief. Section 2003 requires the posting of a notice. The Act is the legal foundation for US workplace polygraph protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-employee-retirement-income-security-act",
    "title": "US Employee Retirement Income Security Act (ERISA, 29 USC ch 18): Fiduciary Duties, Disclosure and Enforcement",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Employee Retirement Income Security Act of 1974 (ERISA, 29 U.S.C. ch. 18) sets federal minimum standards for most private-sector employee benefit plans, administered by the Employee Benefits Security Administration of the Department of Labor (with tax aspects under the Internal Revenue Service and pension insurance under the Pension Benefit Guaranty Corporation). Section 1001 states the congressional findings and policy of protecting participants and beneficiaries through disclosure, reporting and fiduciary standards. Section 1002 supplies the definitions, including employee benefit plan and fiduciary. Section 1021 imposes duties of reporting and disclosure to participants. Section 1104 sets the core fiduciary duties: a fiduciary must act solely in the interest of participants and beneficiaries, for the exclusive purpose of providing benefits and defraying reasonable expenses, with the care, skill and diligence of a prudent person, and must diversify investments. Section 1106 prohibits specified transactions between the plan and parties in interest. Section 1109 makes a fiduciary personally liable to make good any losses to the plan resulting from a breach. Section 1132 provides the civil enforcement scheme, including suits by participants, beneficiaries, fiduciaries and the Secretary, and section 1133 requires a full and fair claims and appeals procedure. The Act is the legal foundation of US retirement and welfare plan governance and fiduciary liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-emtala-emergency-treatment",
    "title": "US EMTALA (42 USC 1395dd): Emergency Medical Screening, Stabilization and Transfer",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Emergency Medical Treatment and Labor Act, EMTALA (42 U.S.C. 1395dd), requires Medicare-participating hospitals with an emergency department to screen, stabilize and appropriately transfer individuals with emergency medical conditions regardless of ability to pay, administered by the Centers for Medicare and Medicaid Services. Section 1395dd(a) requires the hospital to provide an appropriate medical screening examination, within the capability of the emergency department, to any individual who comes to the emergency department and a request is made on the individual's behalf, to determine whether an emergency medical condition exists. Section 1395dd(b) requires the hospital, where an emergency medical condition is found, to provide treatment to stabilize the condition or to arrange an appropriate transfer, and to treat a woman in labor through delivery unless transfer is appropriate. Section 1395dd(c) restricts the transfer of an unstabilized patient unless the patient requests transfer in writing after being informed of the risks, or a physician certifies that the medical benefits of transfer outweigh the risks, and the transfer is appropriate. A participating hospital that negligently violates the requirements is subject to a civil money penalty of not more than 50,000 dollars, or not more than 25,000 dollars for a hospital with fewer than 100 beds, per violation, and a responsible physician faces a similar penalty and possible exclusion. The Act is the legal foundation for US emergency care access.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-endangered-species-act",
    "title": "US Endangered Species Act: Listing, Section 7 Consultation, Prohibited Takings and Penalties",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Endangered Species Act of 1973 (ESA), codified at 16 U.S.C. Chapter 35 (sections 1531-1544), is the principal US statute for the conservation of threatened and endangered species and the ecosystems on which they depend, administered by the US Fish and Wildlife Service (USFWS, Department of the Interior) and, for most marine species, the National Marine Fisheries Service (NMFS, NOAA). Section 1531 states the findings, purposes and policy; section 1532 supplies the definitions, including the broad definition of 'take' (to harass, harm, pursue, hunt, shoot, wound, kill, trap, capture, or collect). Section 1533 governs the listing of species as endangered or threatened on the basis of the best scientific and commercial data available and the designation of critical habitat, and requires recovery plans. Section 1536 (Section 7) requires every federal agency, in consultation with the Secretary, to ensure that any action it authorizes, funds or carries out is not likely to jeopardize the continued existence of a listed species or destroy or adversely modify critical habitat. Section 1538 (Section 9) sets the prohibited acts: with respect to endangered species of fish or wildlife it is unlawful to import or export the species, to take it within the United States or its territorial sea or upon the high seas, to possess, sell, deliver, carry, transport or ship a species taken unlawfully, to deliver, receive, carry, transport or ship it in interstate or foreign commerce in the course of a commercial activity, to sell or offer it for sale in interstate or foreign commerce, or to violate any protective regulation. Section 1539 (Section 10) provides exceptions, including incidental take permits supported by an approved habitat conservation plan. Section 1540 sets the penalties and enforcement: civil penalties of up to $25,000 per violation for knowing violations of the principal prohibitions (with lower tiers of $12,000 and $500), and criminal penalties of up to a $50,000 fine and one year's imprisonment for knowing violations of those principal prohibitions, together with forfeiture and citizen-suit provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-energy-independence-security-act-2007-eisa",
    "title": "Energy Independence and Security Act of 2007",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The Energy Independence and Security Act of 2007 (EISA) mandates increased production of renewable fuels, sets new appliance and lighting efficiency standards, and promotes energy efficiency in federal buildings and the development of a smart electricity grid. Key provisions include the expanded Renewable Fuel Standard (RFS) program (Title II, Section 202) requiring 36 billion gallons of renewable fuel use by 2022.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cafe-standards-light-duty-vehicles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-energy-policy-act-2005-42-usc-ch149",
    "title": "United States Energy Policy Act of 2005 (Title 42 USC Chapter 149): Energy Efficiency, Renewable Energy, Federal Purchase Requirement, Hydroelectric Production Incentives, and Incentives for Innovative Technologies",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Energy Policy Act of 2005, codified at Title 42 of the United States Code, Chapter 149, is the principal federal statute setting national energy policy and programs across energy efficiency, renewable energy, oil and gas, coal, Indian energy, nuclear matters, vehicles and fuels, hydrogen, research and development, electricity, ethanol and motor fuels, and incentives for innovative technologies, and is administered primarily by the Department of Energy. Energy Policy Act of 2005, 42 U.S.C. 15801 contains the definitions including Department (Department of Energy), institution of higher education, National Laboratory, Secretary, and small business concern. Energy Policy Act of 2005, Subchapter I covers energy efficiency including Energy Policy Act of 2005, 42 U.S.C. 15812 directing the Secretary to establish an Advanced Building Efficiency Testbed program for the development, testing, and demonstration of advanced engineering systems. Energy Policy Act of 2005, Subchapter II covers renewable energy including Energy Policy Act of 2005, 42 U.S.C. 15852 mandating that the President, acting through the Secretary, shall seek to ensure that of the total amount of electric energy the Federal Government consumes, the specified amounts shall be renewable energy. Energy Policy Act of 2005, 42 U.S.C. 15881 provides for hydroelectric production incentives: for electric energy generated and sold by a qualified hydroelectric facility during the incentive period, the Secretary shall make incentive payments. Subchapter III covers oil and gas. Subchapter IV covers coal. Subchapter VI covers nuclear matters. Subchapter VII covers vehicles and fuels. Subchapter VIII covers hydrogen. Subchapter IX covers research and development. Subchapter XII covers electricity. Subchapter XV covers incentives for innovative technologies including federal loan guarantees. Subchapter XVII covers protecting America's competitive edge through energy. The Act is the controlling federal instrument for national energy policy and programs enacted in 2005.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-energy-policy-act-2005-key-provisions",
    "title": "Energy Policy Act of 2005 (Public Law 109-58)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Energy Policy Act of 2005 establishes a comprehensive U.S. energy strategy, mandating the Renewable Fuel Standard (RFS) under Title XV, Section 1501, which requires transportation fuel producers and importers to blend increasing volumes of renewable fuels. It also authorizes loan guarantees for advanced nuclear and clean coal projects (Title XVII) and promotes electricity grid modernization and demand response programs (Title XII).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-7628-smart-grid-cybersecurity",
      "iso-14064-ghg-reporting-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-energy-policy-and-conservation-act",
    "title": "US Energy Policy and Conservation Act (42 USC ch 77): Strategic Petroleum Reserve and Energy Conservation",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Energy Policy and Conservation Act of 1975 (EPCA, 42 U.S.C. ch. 77) is a foundational US energy-security and conservation statute, administered chiefly by the Department of Energy. Its domestic-supply provisions include section 6212a on oil exports, the safety valve, and maritime security, section 6213 prohibiting certain lease-bidding arrangements, and section 6215 addressing major fuel-burning stationary sources. Part B establishes the Strategic Petroleum Reserve: section 6231 sets the congressional finding and declaration of policy that a reserve will reduce the impact of disruptions in petroleum supply, section 6232 supplies the definitions, section 6234 establishes the Strategic Petroleum Reserve itself, section 6239 governs the development, operation and maintenance of the Reserve, and section 6241 governs the drawdown and sale of petroleum products from the Reserve in the event of a severe energy supply interruption. EPCA is also the statutory basis of the federal energy-conservation program, including the energy efficiency standards and labeling requirements for consumer products and the origin of corporate average fuel economy standards. The Act is a legal foundation of US strategic petroleum stockpiling and energy-efficiency regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-energy-star-commercial-buildings-portfolio",
    "title": "US ENERGY STAR Portfolio Manager - Commercial Building Energy Benchmarking: 1-100 Score, Median Source EUI, Certification Eligibility, State Benchmarking Law Compliance and Reporting",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation standard requires commercial building owners and operators to benchmark energy performance using ENERGY STAR Portfolio Manager, enabling comparison to national medians and similar buildings. Buildings scoring 75 or higher may be eligible for ENERGY STAR certification, supporting compliance with state benchmarking laws and sustainability reporting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-50001-2018-energy-management-systems",
      "icc-700-national-green-building-standard-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-eo-13859-american-ai-initiative-2019",
    "title": "US Executive Order 13859 - Maintaining American Leadership in Artificial Intelligence (February 11, 2019)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "Executive Order 13859 of February 11, 2019 establishes the American AI Initiative as the first federal whole-of-government policy on AI leadership. The Order directs federal departments and agencies to prioritise AI investment, increase access to federal data and computing resources for AI researchers, set AI governance standards through NIST, build the AI workforce, and engage internationally. The Order articulates five strategic objectives: (1) Promote sustained investment in AI R&D in collaboration with industry, academia, international partners, and allies; (2) Enhance access to high-quality and fully traceable federal data, models, and computing resources to increase the value of those resources for AI R&D; (3) Reduce barriers to the use of AI technologies to promote their innovative application while protecting American technology, economic and national security, civil liberties, privacy, and American values; (4) Ensure that technical standards minimise vulnerability to attacks and reflect federal priorities for innovation, public trust, and confidence in AI systems; (5) Train the next generation of American AI researchers and users through apprenticeships, skills programs, and education in STEM, with an emphasis on computer science, to ensure that American workers, including federal workers, are capable of taking full advantage of the opportunities of AI. EO 13859 is the statutory predecessor to the National AI Initiative Act 2020 and the original authority for NIST AI standards work that produced the NIST AI Risk Management Framework. EO 13859 remains in force and has not been rescinded.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_federal_alignment",
        "nist_framework",
        "industry_mapping",
        "regulatory_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-13960-promoting-trustworthy-ai-federal-government-2020",
      "us-ai-in-government-act-2020",
      "us-naiia-national-ai-initiative-act-2020",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-eo-13960-promoting-trustworthy-ai-federal-government-2020",
    "title": "US Executive Order 13960 - Promoting the Use of Trustworthy Artificial Intelligence in the Federal Government (2020)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "Executive Order 13960 of December 3, 2020 directs federal agencies to design, develop, acquire, and use AI in a manner that fosters public trust and confidence while protecting privacy, civil rights, civil liberties, and American values. Section 3 establishes nine Principles for Use of AI in Government: (a) lawful and respectful of national values, (b) purposeful and performance-driven, (c) accurate, reliable, and effective, (d) safe, secure, and resilient, (e) understandable, (f) responsible and traceable, (g) regularly monitored, (h) transparent, and (i) accountable. Section 4 directs agencies to apply common policy guidance for AI implementation. Section 5 requires each agency (excluding national security systems and DoD) to prepare an inventory of its non-classified AI use cases and make it public, with annual updates. Section 6 directs OMB and OSTP, in coordination with the Federal CIO Council and the Federal Privacy Council, to issue implementing guidance. Section 7 requires the AI inventory to be shared across agencies. Section 8 excludes Department of Defense and intelligence community AI from inventory but not from the principles. The order's principles and inventory requirements remain binding federal policy and are operationalized through OMB Memoranda (M-24-10, superseded by M-25-21).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping",
        "iso_standard",
        "us_state_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "us-omb-m-24-10-federal-ai-governance-2024",
      "us-omb-m-24-18-federal-ai-acquisition-guidance",
      "us-ostp-blueprint-ai-bill-of-rights",
      "us-eo-14179-ai-2025"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-eo-13960-trustworthy-ai-federal-2020",
    "title": "Promoting the Use of Trustworthy Artificial Intelligence in the Federal Government",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "Executive Order 13960 requires federal agencies to adopt AI in a manner that fosters public trust, protects civil rights and liberties, and ensures transparency, accountability, and oversight, consistent with Section 1 and Section 2 of the Order. It applies to all executive departments and agencies using AI technologies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-esrs-s1-workforce",
      "iso-42001-transparency",
      "nist-ai-100-4-redteam",
      "australia-ai-ethics-framework-2019",
      "us-fincen-beneficial-ownership-boi-rule-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-eo-14028-cybersecurity-2021-sbom-mfa-zerotrust",
    "title": "Executive Order 14028 on Improving the Nation's Cybersecurity",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Executive Order mandates US federal agencies to modernize their cybersecurity posture by adopting Zero Trust Architecture, implementing stronger multi-factor authentication (MFA) and encryption, and improving software supply chain security. As per Section 4, it requires software providers selling to the federal government to provide a Software Bill of Materials (SBOM) and attest to secure development practices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "c-scrm-practices-systems-organizations",
      "nist-cybersecurity-framework-2-0",
      "fedramp-authorization",
      "nist-800-53-ia2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-eo-14110-ai-2023",
    "title": "Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This Executive Order directs US federal agencies to establish new standards for AI safety and security, requiring developers of powerful foundation models that pose a serious risk to national security, economic security, or public health and safety to notify the federal government of their activities and share the results of all red-team safety tests (Section 4.2). It also mandates the development of guidance for content authentication and watermarking to clearly label AI-generated content (Section 4.5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "oecd-ai-principles",
      "nist-ai-100-2-aml-taxonomy",
      "nist-sp-1270-managing-ai-bias",
      "reducing-risks-posed-by-synthetic-content"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-eo-14110-safe-trustworthy-ai-2023",
    "title": "Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-10-30",
    "bluf": "This Executive Order directs US federal agencies to establish new standards for AI safety and security and requires developers of powerful dual-use foundation models that pose a serious risk to national security to report their AI safety test results and other critical information to the Department of Commerce, as mandated by Section 4.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "us-cisa-ai-cybersecurity-guidelines-2023",
      "g7-hiroshima-ai-process-2023",
      "oecd-ai-principles",
      "nist-ai-100-2-adversarial-ml"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-eo-14117-bulk-data-foreign-adversary-2024",
    "title": "US Executive Order 14117 - Preventing Access to Americans Bulk Sensitive Personal Data and US Government-Related Data by Countries of Concern (February 28, 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "Executive Order 14117 of February 28, 2024 addresses the national security risks posed by access by countries of concern to Americans bulk sensitive personal data and US government-related data, including for use in AI model training and AI-enabled exploitation. EO 14117 directs the Attorney General to issue regulations to prohibit or restrict the transfer of six categories of bulk sensitive personal data and government-related data to countries of concern or covered persons. The six categories are: (1) Human genomic data; (2) Biometric identifiers; (3) Personal health data; (4) Personal financial data; (5) Precise geolocation data; (6) Certain personal identifiers when combined with other categories. The countries of concern initially designated are China (including Hong Kong and Macau), Russia, Iran, North Korea, Cuba, and Venezuela. The Order requires the Department of Justice National Security Division to establish prohibitions on certain transactions and conditional restrictions on others (including data brokerage, vendor agreements, employment agreements, and investment agreements involving covered data). The implementing rule was issued at 28 CFR 202 (December 2024) and took effect April 8, 2025. The Order also coordinates with CISA security requirements for restricted transactions, HHS rules on genomic and health data, and Treasury rules on financial data. EO 14117 remains in force under the Trump administration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "ai_governance_overlay",
        "us_federal_alignment",
        "regulatory_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-doj-ai-criminal-enforcement-priority-2026",
      "us-eeoc-ai-employment-guidance-2023"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-eo-14148-rescissions-harmful-orders-2025",
    "title": "US Executive Order 14148 - Initial Rescissions of Harmful Executive Orders and Actions (January 20, 2025) - Rescinding Biden AI Orders",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "Executive Order 14148 of January 20, 2025 rescinds 78 Biden Administration executive orders and presidential memoranda identified as harmful, including the foundational Biden AI executive order EO 14110 of October 30, 2023 (Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence). Section 2 of EO 14148 lists the rescinded orders. Section 3 directs the heads of agencies to take all necessary steps, consistent with applicable law, to implement the rescissions, including suspending, revising, or rescinding agency actions taken pursuant to the rescinded orders. Section 4 directs the Domestic Policy Council Director and the National Economic Council Director to jointly review additional Biden-era orders and memoranda for further rescission and to deliver recommendations within 45 days. EO 14148 was followed three days later by EO 14179 (Removing Barriers to American Leadership in Artificial Intelligence, January 23, 2025), which established the new federal AI policy direction. The combined effect is to remove EO 14110's whole-of-government AI risk management framework (red-team reporting, watermarking R&D, civil rights guidance) and replace it with a deregulatory direction emphasising American AI leadership and removal of regulatory barriers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_federal_alignment",
        "nist_framework",
        "industry_mapping",
        "regulatory_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14179-ai-2025",
      "us-eo-14110-ai-2023",
      "us-eo-13960-promoting-trustworthy-ai-federal-government-2020",
      "us-ai-in-government-act-2020",
      "us-naiia-national-ai-initiative-act-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-eo-14178-digital-financial-tech-2025",
    "title": "US Executive Order 14178 - Strengthening American Leadership in Digital Financial Technology",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "EO 14178 of 23 January 2025 sets US federal policy on digital assets and blockchain. Section 1 declares it US policy to protect citizens' ability to access open public blockchains for lawful purposes, promote dollar-backed stablecoins globally, ensure fair banking access, establish technology-neutral regulatory frameworks, and prohibit Central Bank Digital Currencies (CBDCs). Section 3 rescinds Executive Order 14067 (March 9, 2022) and Treasury's Framework for International Engagement on Digital Assets (July 7, 2022). Section 4 establishes the Working Group on Digital Asset Markets, chaired by the Special Advisor for AI and Crypto, with deliverables: 30-day regulation inventory, 60-day modification recommendations, 180-day federal regulatory framework and digital asset stockpile criteria. Section 5 prohibits federal agencies from establishing, issuing, or promoting CBDCs domestically or internationally and requires immediate termination of existing CBDC initiatives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_genius_act_stablecoin_2025_framework",
        "us_fit21_financial_innovation_technology_act_2024",
        "fatf_recommendation_15_virtual_assets",
        "mica_eu_markets_in_crypto_assets_2023_1114",
        "us_eo_14179_ai_2025"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-genius-act-stablecoin-2025-framework",
      "us-fit21-financial-innovation-technology-act-2024",
      "us-eo-14179-ai-2025",
      "fatf-virtual-asset-redfl"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-eo-14179-ai-2025",
    "title": "US Executive Order 14179 - Removing Barriers to American Leadership in Artificial Intelligence (2025)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "President Trump's Executive Order 14179, signed January 23, 2025, revokes the Biden Administration's Executive Order 14110 on AI safety and directs federal agencies to eliminate or revise Biden-era AI governance actions deemed to impede AI innovation, mandates the development of a national AI Action Plan within 180 days, and repositions US federal AI policy toward competitiveness and removing regulatory barriers rather than mandatory safety evaluations and reporting obligations for AI developers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-eo-14179-ai-2025.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-eo-14179-removing-barriers-ai-2025",
    "title": "Removing Barriers to American Leadership in Artificial Intelligence",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This executive order revokes Executive Order 14110 and mandates federal agencies to suspend, revise, or rescind AI policies inconsistent with U.S. AI dominance, as defined in Section 2. It requires the development of a new AI action plan within 180 days under Section 4 and revision of OMB Memoranda M-24-10 and M-24-18 within 60 days under Section 5(b).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "anthropic-responsible-scaling-policy-v2-1-2025",
      "uk-national-cyber-strategy-2022-ncsc-baseline"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-eo-14365-national-policy-framework-for-ai-2025",
    "title": "US Executive Order 14365 of 11 December 2025 - Ensuring a National Policy Framework for Artificial Intelligence",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Federal agencies must evaluate, restrict funding for, and act to preempt state laws that the administration views as affecting national AI policy under Executive Order 14365 (signed 11 December 2025; published at 90 Fed. Reg. 58499), the Attorney General must establish an AI Litigation Task Force empowered to challenge state AI laws on grounds such as unconstitutional regulation of interstate commerce, federal preemption, or other legal deficiencies, while preserving state authority in specific areas such as child safety, infrastructure development, and government procurement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14179-ai-2025"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-eo-2026-sec-2a-cnss-national-security-systems-cyber-defence",
    "title": "US CNSS 30-Day Cyber Defence Prioritisation for National Security Systems (Sec. 2(a), EO Promoting Advanced AI Innovation and Security, 2026)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "Sec. 2(a) of the Executive Order Promoting Advanced Artificial Intelligence Innovation and Security signed June 2, 2026 directs the Committee on National Security Systems (CNSS) within 30 days of the order (verbatim deadline: within 30 days of the date of the order) to prioritise the cyber defence of National Security Systems as defined in 44 U.S.C. 3552(b)(6)(A). The verbatim source provides: 'Within 30 days of the date of this order, the Committee on National Security Systems shall prioritize the cyber defense of National Security Systems, as defined in 44 U.S.C. 3552(b)(6)(A), by taking appropriate and expeditious action consistent with the purpose of this order.' National Security Systems under 44 U.S.C. 3552(b)(6)(A) include information systems used or operated by an agency or contractor whose function involves intelligence activities, cryptologic activities related to national security, command and control of military forces, equipment integral to a weapon or weapons system, or critical to the direct fulfilment of military or intelligence missions, excluding routine administrative and business applications. CNSS is the inter-agency forum chaired by the Secretary of Defense that issues policies for the security of national security systems including CNSSP-15 (national information assurance policy on the use of public standards including post-quantum cryptography), CNSSI-1253 (security categorisation and control selection for national security systems), and the CNSS Glossary CNSSI-4009. The 30-day directive does not amend CNSSP-15 or CNSSI-1253 but signals an expedited prioritisation review that may surface in updated CNSS issuances. Operational implications for federal entities operating NSS or NSS-equivalent systems include (a) review and expedite outstanding CNSS-aligned hardening tasks, (b) accelerate any in-flight CNSSP-15 algorithm migrations including post-quantum transition under NSM-10 timelines, (c) refresh CNSSI-1253 control overlays where AI-enabled cyber threats materially change residual risk, and (d) coordinate with the Director of NSA in NSA's role as National Manager for National Security Systems under NSD-42. The directive runs in parallel with Sec. 2(b) Secretary of War directive on Department of War information systems and is structurally distinct from the Sec. 2(c) CISA Binding Operational Directives applicable to civilian federal systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-promoting-advanced-ai-innovation-security-2026",
      "us-nsa-cnss-policy-15-quantum-resistant-2022",
      "nsa-cnsa-2-0-quantum-resistant-algorithms-2022",
      "nist-sp-800-37-rmf",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-eo-2026-sec-2b-secretary-war-dow-information-systems-cyber-defence",
    "title": "US Secretary of War 30-Day Cyber Defence Prioritisation for Department of War Information Systems (Sec. 2(b), EO Promoting Advanced AI Innovation and Security, 2026)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "Sec. 2(b) of the Executive Order Promoting Advanced Artificial Intelligence Innovation and Security signed June 2, 2026 directs the Secretary of War within 30 days of the order (verbatim deadline: within 30 days of the date of the order) to prioritise the cyber defence of Department of War information systems. The verbatim source provides: 'Within 30 days of the date of this order, the Secretary of War shall prioritize the cyber defense of Department of War information systems by taking appropriate and expeditious action consistent with the purpose of this order.' Department of War (DoW) is the renamed Department of Defense following the 2025 executive renaming; the entity retains the full DoD statutory authority and the directive applies to all DoW information systems including the DoD Information Network (DODIN) operated by DISA, the Joint Worldwide Intelligence Communications System (JWICS) for intelligence community use, the Non-classified Internet Protocol Router Network (NIPRNet), the Secret Internet Protocol Router Network (SIPRNet), and combatant command operational networks. The 30-day directive operates within existing DoW cyber defence authority under 10 U.S.C. Chapter 19 (Cyber and Information Operations), DoD Cyber Strategy 2023, DoD Instruction 8500.01 Cybersecurity, DoD Risk Management Framework under DoDI 8510.01, and the Cybersecurity Maturity Model Certification (CMMC) 2.0 framework for defence industrial base contractors. Operational implications include (a) accelerated DODIN hardening review by US Cyber Command and the Service cyber components, (b) prioritised AI-relevant threat scenario testing against DoW systems including AI-enabled lateral movement and AI-driven supply-chain compromise of DoW hardware and software, (c) coordinated engagement with the Defense Industrial Base Cybersecurity Program (DIB CS) on shared threat intelligence and incident reporting, and (d) refresh of DoD Zero Trust strategy implementation timeline per the DoD Zero Trust Strategy 2022 with 2027 target end state. The directive runs in parallel with Sec. 2(a) Committee on National Security Systems directive and is structurally distinct from the Sec. 2(c) civilian CISA Binding Operational Directives, although DoW NSS components (intelligence systems, weapons systems) are also subject to Sec. 2(a) CNSS prioritisation through the layered CNSS / DoD authority structure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-promoting-advanced-ai-innovation-security-2026",
      "us-eo-2026-sec-2a-cnss-national-security-systems-cyber-defence",
      "us-cmmc-2-0-defense-industrial-base-2021",
      "nist-sp-800-171r3-cui-protection-2024",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-eo-2026-sec-2c-cisa-bod-civilian-federal-cyber-defence-covered-frontier-model-access",
    "title": "US CISA 30-Day Binding Operational Directives + Covered Frontier Model Access for Civilian Federal Cyber Defence (Sec. 2(c), EO Promoting Advanced AI Innovation and Security, 2026)",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "Sec. 2(c) of the Executive Order Promoting Advanced Artificial Intelligence Innovation and Security signed June 2, 2026 directs the Secretary of Homeland Security, through the Director of the Cybersecurity and Infrastructure Security Agency (CISA), in consultation with the Director of the Office of Management and Budget (OMB), the Assistant to the President for National Security Affairs, and the National Cyber Director, within 30 days of the order (verbatim deadline: within 30 days of the date of the order), to release Binding Operational Directives addressed to civilian federal agencies. The directive has three explicit operative objectives stated in Sec. 2(c): (i) expedite cyber defence of civilian Federal systems, (ii) establish or expand Federal programs and cybersecurity services that enhance AI-enabled defensive tools, and (iii) facilitate access to cybersecurity tools and services including, where appropriate, covered frontier models for agencies, State and local authorities, and operators of critical infrastructure such as rural hospitals, community banks, and local utilities. The 'covered frontier model' designation under Sec. 3 is set by the Director of NSA in consultation with the National Cyber Director, the Assistant to the President for Science and Technology (APST), and the Director of CISA. Sec. 2(c) is the operational gateway by which covered frontier models reach federal civilian agencies, state and local governments, and critical infrastructure operators - this is a substantive expansion of CISA's facilitation role beyond the pre-existing CISA shared services portfolio (e.g., CDM, EINSTEIN, Joint Cyber Defense Collaborative). CISA's BOD authority derives from 44 U.S.C. 3553(b)(2) and applies to federal civilian Executive Branch agencies; the Sec. 2(c) directive expands the BOD agenda specifically for AI-enabled cyber defence. Operational implications for federal civilian agencies include (a) preparation to receive a new BOD within 30 days and to operationalise the BOD requirements within the BOD-specified compliance window, (b) review of existing CISA shared service consumption to identify AI-defensive expansion candidates, (c) for state/local/critical infrastructure operators, preparation to engage CISA on covered frontier model access through the appropriate CISA Regional Office or sector-specific Information Sharing and Analysis Center (ISAC), (d) coordination with the entity's general counsel on the procurement, classification, and use restrictions accompanying covered frontier model access. The directive runs in parallel with Sec. 2(a) CNSS and Sec. 2(b) DoW directives and operates on the civilian federal track exclusively.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-promoting-advanced-ai-innovation-security-2026",
      "us-frontier-model-voluntary-pre-release-disclosure-2026",
      "us-cisa-known-exploited-vulnerabilities-bod-22-01",
      "us-cisa-circia-cyber-incident-reporting-2022",
      "us-cisa-ai-cybersecurity-collaboration-playbook-2024"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-eo-2026-sec-2f-opm-united-states-tech-force-information-cybersecurity-specialist-hiring",
    "title": "US OPM 60-Day United States Tech Force Information Cybersecurity Specialist Hiring and Placement Pathways Expansion (Sec. 2(f), EO Promoting Advanced AI Innovation and Security, 2026)",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "Sec. 2(f) of the Executive Order Promoting Advanced Artificial Intelligence Innovation and Security signed June 2, 2026 directs the Director of the Office of Personnel Management within 60 days of the order (verbatim deadline: within 60 days of the date of the order) to expand the United States Tech Force Information Cybersecurity Specialist hiring and placement pathways. The verbatim source provides: 'Within 60 days of the date of this order, the Director of the Office of Personnel Management shall expand the United States Tech Force Information Cybersecurity Specialist hiring and placement pathways.' The directive is the workforce-supply counterpart to Sec. 2(c) AI-enabled defensive tool expansion - covered frontier model access and AI-defensive tooling cannot be operationalised without cleared, trained Information Cybersecurity Specialists in federal civilian agencies, and the existing federal cybersecurity workforce gap (well-documented in successive Government Accountability Office reports and the NICE Workforce Framework demand-side analysis) constrains the Sec. 2(c) rollout. OPM hiring authorities in scope of the Sec. 2(f) expansion likely include direct-hire authority under 5 U.S.C. 3304(a)(3) and 5 CFR Part 337 Subpart B (severe candidate shortage / critical hiring need), the Cyber Excepted Service under DoD authority, the Federal Cyber Workforce Apprenticeship Program, the CyberCorps Scholarship for Service (NSF / NICE), and the Tech Force pilot programmes for direct-hire of degreed and credentialed cybersecurity professionals into the 2210 Information Technology Management series and the 2210-Cybersecurity parenthetical specialty. OPM is expected to publish implementation guidance to federal civilian Chief Human Capital Officers and the Chief Information Officers Council within the 60-day window. Operational implications for federal civilian agencies include (a) review of the agency's existing cybersecurity workforce plan and identification of priority hiring slots aligned to the Sec. 2(c) AI-defensive tool expansion, (b) preparation to use expanded OPM hiring authorities for accelerated cybersecurity hiring, (c) coordination with the agency's Chief Human Capital Officer on Tech Force pathway enrolment, (d) alignment with the NICE Workforce Framework work roles for AI-relevant cybersecurity specialties (e.g., Threat/Warning Analyst 141, Cyber Defense Analyst 511, Vulnerability Assessment Analyst 541, Threat Hunter 132A). The directive complements but does not displace existing federal cybersecurity workforce programmes including CISA's Cyber Education and Workforce Initiative, NSA's Centers of Academic Excellence in Cyber Operations, and the National Cybersecurity Strategy Implementation Plan workforce pillar.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-promoting-advanced-ai-innovation-security-2026",
      "us-eo-2026-sec-2c-cisa-bod-civilian-federal-cyber-defence-covered-frontier-model-access",
      "nist-sp-800-181r1-nice-framework",
      "us-national-cybersecurity-strategy-2023",
      "us-cisa-secure-by-design-principles-2023"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-eo-promoting-advanced-ai-innovation-and-security-2026-06",
    "title": "US Executive Order of 2 June 2026 - Promoting Advanced AI Innovation and Security via Frontier Benchmarking and Cybersecurity Clearinghouse",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "within 60 days of the date of the order, the Department of the Treasury, the National Security Agency, and the Cybersecurity and Infrastructure Security Agency, coordinating with the National Cyber Director, the Assistant to the President for Science and Technology, and the National Institute of Standards and Technology, must develop a classified benchmarking process to designate covered frontier models based on advanced cyber capabilities (with the NSA Director making the designation), design a voluntary framework allowing developers to engage the federal government to determine model status with up to 30 days of pre-release access, and within 30 days of the Order the Secretary of the Treasury must form an AI cybersecurity clearinghouse with the AI industry and operators of critical infrastructure to coordinate scanning, discovery, validation, and remediation of software vulnerabilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14028-cybersecurity-2021-sbom-mfa-zerotrust",
      "us-eo-14179-ai-2025"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-eo-promoting-advanced-ai-innovation-security-2026",
    "title": "US Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security (June 2, 2026)",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "Executive Order 'Promoting Advanced Artificial Intelligence Innovation and Security' signed by President Donald J. Trump on June 2, 2026 (originally scheduled May 21, 2026 and postponed) establishes United States policy that 'advanced AI is a strategic technology' and directs federal agencies to secure both government systems and the frontier model development pipeline against advanced cyber threats. The Order is organised in five sections. Section 1 (Purpose) declares the policy of promoting AI innovation while protecting against cyber-enabled harms. Section 2 (Upgrading American Systems for Advanced AI) imposes 30-day directives on the Committee on National Security Systems, the Secretary of War (Department of War information systems), the Secretary of Homeland Security acting through the CISA Director (Binding Operational Directives and guidance to expedite civilian federal cyber defence, establish or expand Federal programs and cybersecurity services that enhance AI-enabled defensive tools, and facilitate access to cybersecurity tools and services including covered frontier models for agencies, States, local authorities and critical infrastructure operators), and the Secretary of the Treasury (in coordination with the NSA Director and CISA Director) to form an AI cybersecurity clearinghouse in voluntary collaboration with the AI industry that coordinates and deconflicts scanning for software vulnerabilities, discovers and validates such vulnerabilities, and coordinates and prioritises remediation and distribution of vulnerability patches. Sec. 2(e) imposes a 30-day directive on the OMB Director (in coordination with the National Cyber Director and the Director of CISA, federal grant funding availability for advanced AI vulnerability detection applicants) and Sec. 2(f) imposes a 60-day directive on the OPM Director (expand United States Tech Force Information Cybersecurity Specialist hiring). Section 3 (Secure Frontier Model Deployment) establishes a voluntary framework permitting frontier-model developers to engage the Federal Government to determine whether models under development meet the 'covered frontier model' designation set by the Director of the National Security Agency, and to provide such models to the Federal Government up to 30 days before they plan to release such models to other trusted partners; Section 3 contains an explicit prohibition stating 'Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.' Section 4 (Protection Against Criminal Actors) directs the Attorney General to prioritise enforcement against individuals who use AI to illegally access or damage computer systems, steal data, or facilitate other criminal activity. Section 5 (General Provisions) contains standard executive-order disclaimers. The Order does not revoke EO 14179 and operates alongside it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14179-removing-barriers-ai-2025",
      "us-eo-14110-safe-trustworthy-ai-2023",
      "nist-ai-rmf-1-0",
      "nist-ai-600-1-generative-ai-profile-2024",
      "us-cisa-ai-cybersecurity-guidelines-2023"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-epa-40-cfr-112-spcc-oil-pollution-prevention",
    "title": "40 CFR Part 112 - Oil Pollution Prevention (Spill Prevention, Control, and Countermeasure)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "EPA 40 CFR Part 112 requires owners or operators of non-transportation-related onshore and offshore facilities that could reasonably discharge oil into navigable waters or adjoining shorelines to prepare and implement a written Spill Prevention, Control, and Countermeasure Plan in accordance with good engineering practice, provide secondary containment, amend the Plan after qualifying discharges or material facility changes, and where the facility could cause substantial harm, prepare a Facility Response Plan with a training and drill program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-oil-pollution-act-1990-opa90",
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-epa-40-cfr-141-national-primary-drinking-water-regulations",
    "title": "40 CFR Part 141 - National Primary Drinking Water Regulations (EPA)",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "EPA 40 CFR Part 141 sets the legally enforceable national primary drinking water regulations for public water systems, fixing maximum contaminant levels and treatment techniques for inorganic, organic, microbial, lead and copper, and per- and polyfluoroalkyl substances, and requiring coliform and source monitoring, surface water filtration and disinfection, ground water corrective action, annual consumer confidence reports, public notification of violations, and reporting of monitoring results to the primacy agency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-safe-drinking-water-act-42-usc-300f-sdwa"
    ],
    "primary_citations_count": 18
  },
  {
    "node_id": "us-epa-40-cfr-261-identification-listing-hazardous-waste",
    "title": "40 CFR Part 261 - Identification and Listing of Hazardous Waste (RCRA)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 261 identifies and lists the wastes regulated as hazardous under RCRA, requiring a generator to determine whether a material is a solid waste and a hazardous waste, confirm exclusions, handle recyclable materials, empty containers, PCB wastes, and universal waste correctly, apply the criteria for identifying characteristics and test for the ignitability, corrosivity, reactivity, and toxicity characteristics, and identify wastes listed from non-specific and specific sources and the discarded commercial chemical products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-epa-cfr-40-part-260-rcra-hazardous-waste"
    ],
    "primary_citations_count": 19
  },
  {
    "node_id": "us-epa-40-cfr-262-hazardous-waste-generator-standards",
    "title": "40 CFR Part 262 - Standards Applicable to Generators of Hazardous Waste",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "EPA 40 CFR Part 262 sets the standards applicable to generators of hazardous waste under RCRA Subtitle C, requiring each generator to make an accurate hazardous waste determination at the point of generation, determine its generator category by monthly quantity, obtain an EPA identification number, meet the accumulation conditions for its category, and prepare and use the uniform hazardous waste manifest when shipping waste off site.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-epa-cfr-40-part-260-rcra-hazardous-waste"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-epa-40-cfr-264-hazardous-waste-tsdf-standards",
    "title": "40 CFR Part 264 - Standards for Owners and Operators of Hazardous Waste Treatment, Storage, and Disposal Facilities",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "EPA 40 CFR Part 264 sets the standards for owners and operators of permitted hazardous waste treatment, storage, and disposal facilities under RCRA, requiring an EPA identification number, detailed waste analysis before management, facility security, regular inspections, personnel training, a written operating record, groundwater monitoring where applicable, and closure that protects human health and the environment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-epa-cfr-40-part-260-rcra-hazardous-waste"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-epa-40-cfr-265-interim-status-tsdf-standards",
    "title": "40 CFR Part 265 - Interim Status Standards for Owners and Operators of Hazardous Waste Treatment, Storage, and Disposal Facilities (RCRA)",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "40 CFR Part 265 sets minimum national standards for the acceptable management of hazardous waste at treatment, storage, and disposal facilities operating under RCRA interim status, until a permit is issued or closure and post-closure responsibilities are fulfilled. It requires an EPA identification number, general waste analysis, personnel training, preparedness and prevention, a written contingency plan, and closure cost estimates with financial assurance. The standards apply to owners and operators who complied with interim status requirements under section 3005(e) of RCRA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-resource-conservation-and-recovery-act",
      "us-epa-40-cfr-264-hazardous-waste-tsdf-standards",
      "us-epa-40-cfr-262-hazardous-waste-generator-standards",
      "us-epa-40-cfr-261-identification-listing-hazardous-waste"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-epa-40-cfr-268-land-disposal-restrictions",
    "title": "40 CFR Part 268 - Land Disposal Restrictions (EPA RCRA)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 268 sets the land disposal restrictions under RCRA Subtitle C, prohibiting land disposal of restricted hazardous wastes until they meet the applicable treatment standards expressed as constituent concentrations, universal treatment standards, or specified technologies; it bars dilution as a substitute for treatment, sets special rules for characteristic wastes, hazardous debris, and contaminated soil, and requires generators, treaters, and disposal facilities to make land disposal restriction determinations and keep notification, certification, and waste-analysis records before any restricted waste is land disposed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-epa-cfr-40-part-260-rcra-hazardous-waste"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "us-epa-40-cfr-273-universal-waste-management",
    "title": "40 CFR Part 273 - Standards for Universal Waste Management (EPA RCRA)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 273 establishes the streamlined universal waste standards under RCRA for batteries, certain pesticides, mercury-containing equipment, lamps, and aerosol cans, allowing small and large quantity handlers, transporters, and destination facilities to manage these wastes under reduced requirements while still meeting prohibitions, container management, labeling, one-year accumulation limits, employee training, release response, off-site shipment tracking, and export controls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-epa-cfr-40-part-260-rcra-hazardous-waste"
    ],
    "primary_citations_count": 17
  },
  {
    "node_id": "us-epa-40-cfr-279-used-oil-management",
    "title": "40 CFR Part 279 - Standards for the Management of Used Oil (EPA RCRA)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 279 governs the management of used oil under RCRA, defining on-specification and off-specification used oil and setting standards for generators, transporters and transfer facilities, processors and re-refiners, burners, and marketers, including storage and labeling, the rebuttable presumption for halogen content, restrictions on burning and on use as a dust suppressant, tracking and recordkeeping, and hazardous waste determinations for used oil and residues destined for disposal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-epa-cfr-40-part-260-rcra-hazardous-waste"
    ],
    "primary_citations_count": 16
  },
  {
    "node_id": "us-epa-40-cfr-280-underground-storage-tanks",
    "title": "40 CFR Part 280 - Technical Standards and Corrective Action Requirements for Underground Storage Tanks (UST)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "EPA 40 CFR Part 280 sets the technical standards and corrective action requirements for underground storage tank systems storing regulated substances under Subtitle I of the Solid Waste Disposal Act, requiring performance standards for new systems, upgrading of existing systems, notification, spill and overfill control, corrosion protection operation and maintenance, release detection, and reporting and recordkeeping with cooperation in agency inspections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-epa-cfr-40-part-260-rcra-hazardous-waste"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-epa-40-cfr-302-cercla-reportable-quantities",
    "title": "40 CFR Part 302 - Designation, Reportable Quantities, and Notification (CERCLA)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 302 designates hazardous substances under CERCLA and sets their reportable quantities, requiring any person in charge of a vessel or facility to immediately notify the National Response Center when a release of a hazardous substance to the environment equals or exceeds its reportable quantity within a 24-hour period, with separate procedures for determining reportable quantities for mixtures and unlisted substances, reduced reporting for qualifying continuous releases, and civil and criminal penalties for failure to notify.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-comprehensive-environmental-response-cercla"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-epa-40-cfr-355-epcra-emergency-planning-notification",
    "title": "40 CFR Part 355 - Emergency Planning and Notification (EPCRA)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 355 implements the emergency planning and emergency release notification provisions of EPCRA, requiring facilities with extremely hazardous substances at or above threshold planning quantities to notify State and local emergency planning authorities, and requiring immediate notification to the community emergency coordinator and State authorities when a release of an extremely hazardous substance or CERCLA hazardous substance equals or exceeds its reportable quantity, with rules for mixtures, aggregation, solids, exemptions, continuous releases, and the relationship to CERCLA reporting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 17
  },
  {
    "node_id": "us-epa-40-cfr-372-toxics-release-inventory-epcra-313",
    "title": "40 CFR Part 372 - Toxic Chemical Release Reporting: Community Right-to-Know (TRI)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "EPA 40 CFR Part 372 implements the Toxics Release Inventory under section 313 of the Emergency Planning and Community Right-to-Know Act, requiring covered facilities with 10 or more employees in designated sectors that manufacture, process, or otherwise use a listed toxic chemical above the reporting threshold to submit an annual Form R release and other waste management report to EPA and the state, to provide supplier notification of listed chemicals in mixtures, and to keep supporting records for three years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-epa-40-cfr-403-general-pretreatment-regulations",
    "title": "40 CFR Part 403 - General Pretreatment Regulations for Existing and New Sources of Pollution",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "EPA 40 CFR Part 403 establishes the general pretreatment regulations under the Clean Water Act, prohibiting industrial users from introducing pollutants that pass through or interfere with a publicly owned treatment works, applying national categorical pretreatment standards, requiring POTWs above the design-flow threshold to develop and implement approved pretreatment programs, and imposing baseline, periodic, and compliance reporting obligations on industrial users and POTWs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-epa-40-cfr-423-steam-electric-effluent-guidelines",
    "title": "40 CFR Part 423 - Steam Electric Power Generating Point Source Category Effluent Guidelines",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 423 sets the effluent limitations guidelines and standards for the steam electric power generating point source category, requiring a facility to determine applicability and definitions, meet the best practicable control technology and best available technology effluent limitations, meet the new source performance standards, meet the pretreatment standards for existing and new sources, incorporate the required permit conditions, and carry out the reporting and recordkeeping requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-epa-40-cfr-503-sewage-sludge-biosolids-standards",
    "title": "40 CFR Part 503 - Standards for the Use or Disposal of Sewage Sludge (Biosolids)",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 503 sets the standards for the use or disposal of sewage sludge, requiring preparers and appliers to meet the general requirements and any exclusions, conduct sampling and analysis, satisfy the pollutant limits, management practices, and operational pathogen and vector attraction reduction standards for land application, carry out the monitoring, recordkeeping, and reporting, meet the surface disposal standards, achieve the required pathogen and vector attraction reduction, and meet the requirements for sewage sludge incineration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 21
  },
  {
    "node_id": "us-epa-40-cfr-51-state-implementation-plan-requirements",
    "title": "40 CFR Part 51 - Requirements for Preparation, Adoption, and Submittal of State Implementation Plans",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 51 sets the requirements for preparation, adoption, and submittal of State Implementation Plans under the Clean Air Act, requiring States to provide for public hearings and submit plans for EPA review and approval, demonstrate attainment and maintenance of the national ambient air quality standards, describe enforceable control measures, supply emissions and air quality data, meet specific provisions for lead, stack height, and oxides of nitrogen, adopt legally enforceable procedures with public availability of information, meet permit and prevention of significant deterioration requirements, and meet ambient air quality monitoring requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-air-act-42-usc-7401-findings-purposes-air-quality"
    ],
    "primary_citations_count": 22
  },
  {
    "node_id": "us-epa-40-cfr-60-nsps-new-source-performance-standards",
    "title": "40 CFR Part 60 - Standards of Performance for New Stationary Sources (NSPS)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "EPA 40 CFR Part 60 sets standards of performance for new and modified stationary sources under section 111 of the Clean Air Act, requiring owners or operators of affected facilities to notify of construction or modification, conduct performance tests, demonstrate continuous compliance with emission and opacity limits, operate continuous monitoring systems, and keep records and submit reports to the Administrator or delegated state agency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-air-act-42-usc-7401-findings-purposes-air-quality"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-epa-40-cfr-63-neshap-hazardous-air-pollutants",
    "title": "40 CFR Part 63 - National Emission Standards for Hazardous Air Pollutants (NESHAP)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "EPA 40 CFR Part 63 establishes national emission standards for hazardous air pollutants under section 112 of the Clean Air Act, requiring owners or operators of affected sources to meet each relevant emission standard by its compliance date, operate and maintain controls to minimise emissions, conduct performance testing, run continuous monitoring systems, submit the required notifications, and keep records and submit periodic compliance reports.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-air-act-42-usc-7401-findings-purposes-air-quality"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-epa-40-cfr-70-state-operating-permit-programs-title-v",
    "title": "40 CFR Part 70 - State Operating Permit Programs (Clean Air Act Title V)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 70 sets the requirements for State and local operating permit programs under Title V of the Clean Air Act, defining which major and other sources must obtain operating permits, the content of complete permit applications, the permit terms that assure compliance including monitoring and compliance certification, the five-year permit term and reopening rules, EPA and affected-State review, emissions-based fees, federal oversight and sanctions, and the public petition process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-air-act-42-usc-7401-findings-purposes-air-quality"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-epa-40-cfr-71-federal-operating-permit-programs-title-v",
    "title": "40 CFR Part 71 - Federal Operating Permit Programs (Clean Air Act Title V)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 71 establishes the Federal operating permit program under Title V of the Clean Air Act that applies where no EPA-approved State program is in effect, covering sources subject to permitting, program implementation, complete permit applications, permit content and compliance terms, the five-year permit term and reopenings, affected-State review, permit fees, delegation to State, local, or Tribal agencies, the administrative record and public participation, and prohibited acts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-air-act-42-usc-7401-findings-purposes-air-quality"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-epa-40-cfr-711-tsca-chemical-data-reporting",
    "title": "40 CFR Part 711 - TSCA Chemical Data Reporting Requirements",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 711 sets the TSCA Chemical Data Reporting requirements, requiring manufacturers and importers of listed chemical substances above the reporting thresholds to report manufacturing, processing, and use information to EPA during the periodic submission period, with defined exclusions, exempt activities, electronic filing, recordkeeping, and confidentiality claim procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-tsca-toxic-substances-chemical-safety-2016"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "us-epa-40-cfr-716-tsca-health-safety-data-reporting",
    "title": "40 CFR Part 716 - Health and Safety Data Reporting (TSCA)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 716 sets the TSCA health and safety data reporting requirements, requiring manufacturers, importers, and processors of listed chemical substances and mixtures to conduct an adequate file search and submit lists and copies of unpublished health and safety studies to EPA, respond to EPA requests for further information, report physical and chemical property studies, and meet the confidentiality, schedule, and reporting period requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-tsca-toxic-substances-chemical-safety-2016"
    ],
    "primary_citations_count": 17
  },
  {
    "node_id": "us-epa-40-cfr-717-tsca-significant-adverse-reactions-records",
    "title": "40 CFR Part 717 - Records and Reports of Allegations of Significant Adverse Reactions (TSCA)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 717 sets the TSCA section 8(c) recordkeeping requirements, requiring manufacturers, importers, and processors of chemical substances to record allegations of significant adverse reactions to health or the environment, determine which allegations and reactions must be recorded, retain the records for the required period, make them available for EPA inspection and reporting, and handle confidentiality claims.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-tsca-toxic-substances-chemical-safety-2016"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-epa-40-cfr-720-tsca-premanufacture-notification",
    "title": "40 CFR Part 720 - Premanufacture Notification (TSCA)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 720 sets the premanufacture notification requirements under TSCA, requiring any person who intends to manufacture or import a new chemical substance not on the TSCA Inventory to submit a Premanufacture Notice to EPA at least 90 days before manufacture, include the required identity, use, production, exposure, and health and environmental effects information, observe the applicable review period and EPA determination, apply the research and development and test marketing exemptions only where their conditions are met, file a notice of commencement, and meet recordkeeping, public file, compliance, and inspection requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-tsca-toxic-substances-chemical-safety-2016"
    ],
    "primary_citations_count": 19
  },
  {
    "node_id": "us-epa-40-cfr-725-microbial-products-biotechnology-tsca",
    "title": "40 CFR Part 725 - Reporting Requirements for Microbial Products of Biotechnology (TSCA)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 725 sets the TSCA reporting requirements for microbial products of biotechnology, requiring submitters to identify intergeneric microorganisms, file a Microbial Commercial Activity Notice (MCAN) before manufacture or import with the required information and health and environmental effects data, file a TSCA Experimental Release Application (TERA) for testing in the environment, undergo EPA review before commencing activity, and meet recordkeeping, exemption, compliance, and inspection requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-tsca-toxic-substances-chemical-safety-2016"
    ],
    "primary_citations_count": 20
  },
  {
    "node_id": "us-epa-40-cfr-761-pcb-management-tsca",
    "title": "40 CFR Part 761 - Polychlorinated Biphenyls (PCBs) Manufacturing, Processing, Distribution, Use, and Disposal (TSCA)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 761 implements the PCB provisions of the Toxic Substances Control Act, governing the manufacture, processing, distribution in commerce, use, marking, storage, and disposal of polychlorinated biphenyls and PCB Items, including prohibitions and authorizations on use, marking requirements and formats, disposal methods for PCB waste, remediation and bulk product waste cleanup options, decontamination standards, the PCB waste manifest system, EPA identification numbers, notification of PCB waste activity, and records and monitoring.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-tsca-toxic-substances-chemical-safety-2016"
    ],
    "primary_citations_count": 20
  },
  {
    "node_id": "us-epa-40-cfr-763-asbestos-ahera",
    "title": "40 CFR Part 763 - Asbestos (AHERA, Worker Protection, and TSCA Prohibitions)",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "EPA 40 CFR Part 763 implements the asbestos provisions of the Toxic Substances Control Act, including the Asbestos Hazard Emergency Response Act (AHERA) requirements for local education agencies to inspect school buildings for asbestos-containing material, sample and analyze suspect materials, assess hazards, select and carry out response actions, run an operations and maintenance program, train staff and conduct periodic surveillance, develop and maintain an asbestos management plan, and post warning labels, together with the asbestos worker protection requirements and the manufacture, processing, and distribution prohibitions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-tsca-toxic-substances-chemical-safety-2016"
    ],
    "primary_citations_count": 17
  },
  {
    "node_id": "us-epa-40-cfr-82-stratospheric-ozone-refrigerant-management",
    "title": "40 CFR Part 82 - Protection of Stratospheric Ozone (ODS phase-out and refrigerant management)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "EPA 40 CFR Part 82 implements the Montreal Protocol and Title VI of the Clean Air Act by limiting production and consumption of ozone-depleting controlled substances and by governing the servicing, recovery, and disposal of refrigerants, prohibiting the knowing venting of refrigerant, requiring proper evacuation before service or disposal, mandating leak repair for larger appliances, requiring technician certification, and imposing recordkeeping and reporting obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-air-act-42-usc-7401-findings-purposes-air-quality"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-epa-40-cfr-part-122-national-pollutant-discharge-elimination",
    "title": "40 CFR Part 122 -- EPA Administered Permit Programs: the National Pollutant Discharge Elimination System",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must obtain and comply with a National Pollutant Discharge Elimination System (NPDES) permit for any discharge of pollutants from a point source into waters of the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-epa-cfr-40-part-122-npdes-permit-program",
    "title": "40 CFR Part 122 - EPA Administered Permit Programs: The National Pollutant Discharge Elimination System",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes the requirements for the National Pollutant Discharge Elimination System (NPDES) permit program, including permit applications, specific discharge categories, and reporting signatories.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-epa-cfr-40-part-260-rcra-hazardous-waste",
    "title": "40 CFR Part 260 - Hazardous Waste Management System: General",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes the general framework, definitions, and petitioning procedures for the hazardous waste management system, including requirements for information availability, manifest submissions, and rulemaking petitions for waste classification and recycling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-epa-clean-water-act-section-402-npdes",
    "title": "US EPA Clean Water Act Section 402 - National Pollutant Discharge Elimination System (NPDES)",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "Clean Water Act Section 402 (33 U.S.C. § 1342) establishes the NPDES permit program administered by EPA and authorized states, requiring any discharge of pollutants from a point source into navigable waters to obtain a permit. AI-based discharge monitoring systems, predictive effluent modeling tools, and automated stormwater management platforms must comply with permit reporting requirements under 40 CFR Part 122. Electronic reporting mandated under EPA's NPDES eReporting Rule (40 CFR Part 127) since December 2016.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standards",
        "frameworks",
        "regulations",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nepa-1970-environmental-impact-assessment",
      "iso-14001-ems"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-epa-greenhouse-gas-reporting-program-40-cfr-98-mandatory-reporting",
    "title": "US EPA Greenhouse Gas Reporting Program - 40 CFR Part 98 Mandatory GHG Reporting",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "The US EPA Mandatory Greenhouse Gas Reporting Program (GHGRP) at 40 CFR Part 98 requires facilities and suppliers in 41 industrial categories that emit 25,000 metric tons of CO2 equivalent or more annually to report GHG emissions to EPA. Covered facilities include power plants, industrial facilities, and suppliers of fossil fuels and industrial gases. Annual reports are due March 31 for the prior calendar year via EPA's electronic Greenhouse Gas Reporting Tool (e-GGRT). Reported data is publicly available at EPA's ghgdata.epa.gov website.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ets-directive-2003-87-emissions-trading-scheme"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-epa-legacy-ccr-surface-impoundments-40-cfr-257-subpart-d",
    "title": "EPA Coal Combustion Residuals - Legacy CCR Surface Impoundments and CCR Management Units (40 CFR Part 257, Subpart D)",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Under 40 CFR Part 257 Subpart D, legacy CCR surface impoundments are subject to the requirements applicable to existing CCR surface impoundments (except the location and certain liner criteria), all CCR units are subject to the groundwater monitoring and corrective action requirements, and owners and operators must identify CCR management units; EPA extended certain compliance deadlines in its 2026 final rule.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-40-cfr-part-261-rcra-hazardous-waste-identification",
      "us-rcra-solid-waste",
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-epa-multi-pollutant-vehicle-standards-2024",
    "title": "Multi-Pollutant Emissions Standards for Model Years 2027 and Later Light-Duty and Medium-Duty Vehicles",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2024-03-20",
    "bluf": "This final rule establishes progressively stringent, performance-based fleet-average emissions standards for greenhouse gases (GHG) and criteria pollutants for light-duty and medium-duty vehicle manufacturers, beginning with model year 2027. The rule, under 40 CFR Part 86, Subpart S, requires manufacturers to meet specific grams/mile targets for CO2 and NOx across their vehicle fleets, with standards tightening annually through model year 2032.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-epa-pfas-strategic-roadmap-2021-2024",
    "title": "US EPA PFAS Strategic Roadmap (2021) and National Primary Drinking Water Regulation for PFAS (2024)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-04-26",
    "bluf": "The US Environmental Protection Agency (EPA) PFAS Strategic Roadmap was released on 18 October 2021 and sets the federal commitment to address per- and polyfluoroalkyl substances (PFAS) across the lifecycle: research, restrict, and remediate. The Roadmap commits EPA to issuing enforceable national drinking water standards, designating certain PFAS as hazardous substances under the Comprehensive Environmental Response, Compensation, and Liability Act (CERCLA), and accelerating science to support regulatory and remedial decisions. On 26 April 2024 EPA finalised the first National Primary Drinking Water Regulation for PFAS under the Safe Drinking Water Act establishing enforceable Maximum Contaminant Levels (MCLs) for six PFAS chemicals.\n\nThe MCLs are: 4.0 parts per trillion (ppt) for perfluorooctanoic acid (PFOA); 4.0 ppt for perfluorooctane sulfonic acid (PFOS); 10 ppt for perfluorohexane sulfonic acid (PFHxS); 10 ppt for perfluorononanoic acid (PFNA); 10 ppt for hexafluoropropylene oxide dimer acid (HFPO-DA, GenX Chemicals); and a Hazard Index of 1.0 for mixtures of PFNA, PFHxS, HFPO-DA, and perfluorobutane sulfonic acid (PFBS). Public water systems must complete initial monitoring by 2027 and implement treatment to meet the MCLs by 2029. The State Revolving Fund and the Bipartisan Infrastructure Law authorise funding for compliance. EPA's separate Designation of PFOA and PFOS as Hazardous Substances under CERCLA was finalised on 8 May 2024 expanding cleanup authority and liability for these substances.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-comprehensive-environmental-response-cercla",
      "us-safe-drinking-water-act-42-usc-300f-sdwa"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-epa-power-plant-ghg-rule-2024",
    "title": "US EPA Power Plant GHG Rule 2024 - Carbon Pollution Standards for New and Existing Power Plants",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "EPA's 2024 Final Rule under Clean Air Act Section 111 sets performance standards for new and existing coal and gas-fired power plants based on carbon capture and storage (CCS) or co-firing with clean fuels. New baseload gas plants must achieve a 90% carbon capture rate. Existing coal plants operating past 2039 must implement CCS. The Rule was finalized in April 2024 and faces legal challenge.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "clean_air_act_111",
        "clean_power_plan",
        "ira_45q_credit",
        "nerc_reliability",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-inflation-reduction-act-clean-energy-2022",
      "us-energy-independence-security-act-2007-eisa",
      "us-ca-sb100-clean-energy-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-epa-risk-management-program-rule-2024",
    "title": "EPA Risk Management Program Rule 2024 (40 CFR Part 68) - Accident Prevention Programme, Emergency Response Co-ordination and Third-Party Compliance Audits",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires owners and operators of stationary sources that handle regulated substances above threshold quantities to develop and implement a Risk Management Program (RMP) that includes hazard assessments, accident prevention programs, and emergency response measures. Key requirements are codified in 40 CFR Part 68, Subpart G (Process Safety Management) and Subpart E (Emergency Response).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-82-r3-ot-ics-security-guide-2023",
      "iec-62443-iacs",
      "iso-iec-27019-energy-utility-information-security",
      "ot-ics-purdue-model-zone-based-security"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-epa-water-sector-cybersecurity-1433",
    "title": "Safe Drinking Water Act (SDWA) Section 1433 - Risk and Resilience Assessments and Emergency Response Plans for Community Water Systems",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Section 1433 of the Safe Drinking Water Act (SDWA), community water systems serving more than 3,300 people must conduct comprehensive Risk and Resilience Assessments (RRAs) that include cyber threats, and develop or update Emergency Response Plans (ERPs) based on these assessments. Systems must certify completion of these activities to the U.S. Environmental Protection Agency (EPA) every five years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cisa-cross-sector-cybersecurity-goals",
      "nist-800-53-cp2",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-epcra",
    "title": "US Emergency Planning and Community Right-To-Know Act (EPCRA, 42 USC ch 116): Release Notification and Reporting",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Emergency Planning and Community Right-To-Know Act of 1986 (EPCRA), codified at 42 U.S.C. Chapter 116 (sections 11001-11050), establishes requirements for emergency planning and for reporting on hazardous and toxic chemicals, administered by the US Environmental Protection Agency (EPA) together with State emergency response commissions and local emergency planning committees (LEPCs). Section 11001 provides for the establishment of State commissions, planning districts and local committees. Section 11002 identifies the extremely hazardous substances and the facilities covered, and requires facilities to notify the State commission. Section 11003 requires the preparation of comprehensive emergency response plans by the LEPCs, with facility cooperation. Section 11004 imposes the emergency release notification duty: the owner or operator of a facility shall immediately provide notice of a release of a reportable quantity of an extremely hazardous substance or CERCLA hazardous substance to the community emergency coordinator for the LEPCs and to the State emergency response commission of any State likely to be affected by the release, followed by a written follow-up notice. Sections 11021 and 11022 require submission of safety data sheets and emergency and hazardous chemical inventory forms (Tier II), and section 11023 requires covered facilities to file annual toxic chemical release forms (the Toxics Release Inventory, Form R). Section 11045 sets the penalties: for failure to provide emergency notification, administrative Class I penalties of up to $25,000 per violation and Class II penalties of up to $25,000 per day (up to $75,000 per day for second and subsequent violations), and judicial penalties of up to $25,000 per day (up to $75,000 per day for subsequent violations); and a person who knowingly and willfully fails to provide the required notice shall be fined not more than $25,000 or imprisoned not more than two years, or both (not more than $50,000 or five years for a subsequent conviction). Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-epcra-1986-emergency-planning-community-right-to-know",
    "title": "US Emergency Planning and Community Right-to-Know Act of 1986 - Chemical Disclosure and Local Emergency Planning",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Emergency Planning and Community Right-to-Know Act of 1986 established federal requirements for state and local emergency planning and reporting of hazardous chemicals by requiring facilities to notify state emergency response commissions of extremely hazardous substances above threshold planning quantities, file material safety data sheets or lists with the local emergency planning committee, file Tier I and Tier II inventory reports annually, report routine emissions of listed toxic chemicals through the Toxics Release Inventory Form R, and immediately notify the National Response Center and the local committee of releases of reportable quantities of extremely hazardous substances.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cercla-superfund"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-equal-credit-opportunity-act",
    "title": "US Equal Credit Opportunity Act (15 USC ch 41): Prohibition of Credit Discrimination",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Equal Credit Opportunity Act (15 U.S.C. ch. 41, subchapter IV) prohibits discrimination in credit transactions, enforced principally by the Consumer Financial Protection Bureau, with other agencies for institutions within their jurisdiction. Section 1691 sets the scope of the prohibition: it is unlawful for any creditor to discriminate against any applicant, with respect to any aspect of a credit transaction, on the basis of race, color, religion, national origin, sex, marital status or age, provided the applicant has the capacity to contract, because all or part of the applicant's income derives from a public assistance program, or because the applicant has in good faith exercised a right under the Consumer Credit Protection Act. Section 1691 also requires a creditor to notify an applicant of action taken and, on request, to provide a statement of reasons for adverse action. Section 1691c provides for administrative enforcement, and section 1691e provides for civil liability, including actual damages, punitive damages up to the statutory cap, and costs and attorney fees. The Act is implemented by Regulation B. It is the legal foundation for fair lending compliance in the United States and underpins adverse action notice requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-equal-credit-opportunity-act-ecoa-1974",
    "title": "US Equal Credit Opportunity Act (ECOA) - Regulation B - 15 USC 1691",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "ECOA (implemented by Regulation B, 12 CFR Part 1002) prohibits credit discrimination on the basis of race, color, religion, national origin, sex, marital status, age, or receipt of public assistance; requires adverse-action notice with specific reasons within 30 days; mandates free appraisal copy delivery; and prohibits spousal co-signature unless applicant individually qualifies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cfpb-dodd-frank-title-x-consumer-financial-protection",
      "us-fair-credit-reporting-act-fcra-1970",
      "us-glba-gramm-leach-bliley-act-1999"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-equal-pay-act-1963-29-usc-206",
    "title": "Equal Pay Act of 1963 (29 U.S.C. § 206(d)) - Prohibition on Sex-Based Wage Discrimination, Equal Work Standard and Permitted Pay Differentials",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Equal Pay Act of 1963 prohibits employers from paying employees of one sex less than those of the opposite sex for equal work requiring substantially equal skill, effort, and responsibility under similar working conditions within the same establishment, as defined in 29 U.S.C. § 206(d)(1). Exceptions are limited to seniority, merit, quantity or quality of production, or any other factor other than sex.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eeoc-employment-rule",
      "ada-employment-title-1",
      "au-fair-work-act-2009"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-erisa-29-usc-1001",
    "title": "Employee Retirement Income Security Act 1974 - 29 USC 1001",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 1001 of title 29 of the United States Code, the congressional findings and declaration of policy of the Employee Retirement Income Security Act of 1974 (ERISA, Public Law 93-406, enacted 2 September 1974), establishes the federal regulatory framework for private-sector employee benefit plans including pension, health, and other welfare plans. ERISA covers four major areas: Title I (Subtitle A subchapter I, fiduciary responsibility, reporting and disclosure, vesting, participation, and funding administered by the Department of Labor), Title II (Internal Revenue Code amendments establishing the tax treatment of pension plans), Title III (jurisdiction and administration), and Title IV (plan termination insurance through the Pension Benefit Guaranty Corporation). ERISA preempts state laws relating to employee benefit plans (subject to the savings clause for insurance, banking, and securities laws and the deemer clause). Section 404 (29 USC 1104) imposes fiduciary duties of loyalty, prudence, diversification, and adherence to plan documents on plan fiduciaries. Section 406 (29 USC 1106) prohibits transactions between plans and parties in interest. The Pension Protection Act of 2006 (Public Law 109-280) materially expanded ERISA including automatic enrolment, qualified default investment alternatives, and the diversification requirements. The SECURE Act of 2019 (Public Law 116-94) and SECURE 2.0 Act of 2022 (Public Law 117-328) further extended ERISA participation, lifetime income, and required minimum distribution rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dol-cfr-29-part-2550-erisa-fiduciary-rules"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-erisa-29-usc-1132-civil-enforcement-beneficiary-rights",
    "title": "29 U.S. Code § 1132 - Civil enforcement",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This section empowers participants, beneficiaries, fiduciaries, and the Secretary of Labor to bring civil actions to recover benefits, enforce plan terms, or seek equitable relief for violations of ERISA provisions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-erisa-employee-benefit-plan-regulation",
    "title": "Employee Retirement Income Security Act of 1974 (ERISA) - Fiduciary Duties, Prohibited Transactions, and Reporting Requirements",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Employee Retirement Income Security Act of 1974 (ERISA) establishes minimum standards for most private industry retirement and health plans, requiring fiduciaries under Title I, Part 4 to act prudently and solely in the interest of plan participants and beneficiaries, and mandating detailed reporting and disclosure to both the government and participants.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-esign-act",
    "title": "US ESIGN Act (15 USC ch 96): Legal Validity of Electronic Signatures and Records",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Electronic Signatures in Global and National Commerce Act, ESIGN (15 U.S.C. ch. 96), establishes the legal validity of electronic signatures, contracts and records in transactions affecting interstate or foreign commerce. Section 7001 sets the general rule of validity: a signature, contract or other record relating to such a transaction may not be denied legal effect, validity or enforceability solely because it is in electronic form, and a contract may not be denied legal effect solely because an electronic signature or electronic record was used in its formation. Section 7001 also sets consumer consent requirements: where a law requires that information be provided to a consumer in writing, an electronic record satisfies that requirement only if the consumer has affirmatively consented and has not withdrawn consent, the consumer is provided a clear statement of rights including the right to receive a paper copy and to withdraw consent, and the consumer consents in a manner that reasonably demonstrates that the consumer can access the information in the electronic form to be used. Section 7002 addresses how a State may modify the operation of section 7001, generally by adopting the Uniform Electronic Transactions Act. Section 7003 sets specific exceptions where electronic form is not sufficient, including wills, codicils and testamentary trusts, certain family law matters, and specified notices such as cancellation of utility service, default or foreclosure, and recall of a product. The Act is the legal foundation for US electronic contracting and e-signature enforceability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-esign-act-2000-electronic-records-signatures",
    "title": "Electronic Signatures in Global and National Commerce Act (E-SIGN Act) of 2000 - Electronic Records and Signatures in Commerce: Legal Equivalence, Consumer Consent, Retention Requirements and Federal Override",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The E-SIGN Act grants legal equivalence to electronic records and signatures in interstate and foreign commerce, provided that consumer consent is obtained and certain disclosure requirements are met under 15 U.S.C. § 7001(c). Applies to any person or entity using electronic records or signatures in transactions in or affecting interstate or foreign commerce.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mcp-enterprise-auth",
      "automation-bpmn-service-task",
      "automation-bpmn-error-boundary"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-esign-act-2000-electronic-signatures",
    "title": "Electronic Signatures in Global and National Commerce Act (ESIGN Act) of 2000",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The ESIGN Act provides that any contract, signature, or record used in interstate or foreign commerce may not be denied legal effect, validity, or enforceability solely because it is in electronic form (15 U.S.C.§ 7001(a)) and mandates clear consumer disclosures and consent for electronic records (15 U.S.C. § 7001(c)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-electronic-commerce-1996",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-essa-every-student-succeeds-act-2015",
    "title": "Every Student Succeeds Act of 2015",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Every Student Succeeds Act (ESSA) of 2015 requires each state educational agency to develop and implement a comprehensive accountability system for public elementary and secondary schools, including those receiving Title I funds, with specific focus on disadvantaged student subgroups, educator effectiveness, and evidence-based interventions. Key requirements are established under Section 1111 of Title I, Part A of the Elementary and Secondary Education Act, as amended.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-eu-data-privacy-framework-2023",
    "title": "EU-US Data Privacy Framework 2023 - Adequacy Decision and Executive Order 14086",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The EU-US Data Privacy Framework (DPF) is the third successor to Safe Harbor (invalidated by Schrems I in 2015) and Privacy Shield (invalidated by Schrems II in 2020), comprising Executive Order 14086 (Enhancing Safeguards for United States Signals Intelligence Activities, signed 7 October 2022), Attorney General Regulation 28 CFR Part 201 (creating the Data Protection Review Court), and the European Commission Adequacy Decision adopted 10 July 2023 (Commission Implementing Decision (EU) 2023/1795). Together these instruments establish a framework whereby US companies that self-certify compliance with the DPF Principles (Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement, and Liability) administered by the Department of Commerce are deemed adequate recipients for personal data transferred from the EU under GDPR Chapter V. The DPF includes redress mechanisms through an independent Civil Liberties Protection Officer at ODNI and the Data Protection Review Court for EU complainants alleging signals intelligence misuse. The DPF also extends to the UK Data Bridge (UK adequacy regulation 2023/2024) and the Swiss-US DPF (Switzerland adequacy decision 2024). Companies must annually re-certify, maintain a DPF privacy program, and accept binding arbitration for unresolved EU complaints. The DPF framework is under ongoing legal challenge (Schrems III) and a successor mechanism is being prepared.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fisa-foreign-intelligence-surveillance-act-50-usc-ch36"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-executive-order-14110-ai-safety-2023",
    "title": "Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This Executive Order establishes binding requirements for federal agencies and contractors to ensure the safe, secure, and trustworthy development and use of AI, including mandatory safety testing for dual-use foundation models exceeding 10^26 FLOPs and watermarking of AI-generated content. It applies to all federal departments, AI developers with access to sensitive data, and critical infrastructure operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bletchley-declaration-ai-safety-2023",
      "anthropic-responsible-scaling-policy-v2-1-2025"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-executive-order-14110-safe-secure-trustworthy-ai-2023",
    "title": "US Executive Order 14110 - Safe, Secure, and Trustworthy AI (October 2023)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Executive Order 14110 (October 30, 2023) directed federal agencies to establish AI safety standards, reporting requirements for frontier AI models, and red-teaming programmes. Federal contractors developing dual-use foundation models must notify the US Government under the Defense Production Act and report results of safety evaluations to NIST. Key provisions include reporting thresholds for models trained with >10^26 FLOP.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0-risk-management-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-executive-order-14110-safe-secure-trustworthy-ai-ai-safety-reporting",
    "title": "US Executive Order 14110 - Safe, Secure, and Trustworthy AI - Dual-Use Foundation Model Reporting",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2023-10-30",
    "bluf": "Executive Order 14110 on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (October 2023) directed federal agencies to implement a broad set of AI safety standards. Key provisions include: Section 4.2 requiring developers of powerful dual-use foundation models to report training compute thresholds (10^26 FLOPS and above) and safety test results to the federal government; Section 4.3 directing NIST to develop AI safety standards; and Sections covering immigration for AI talent, civil rights protections, and worker protections. Executive Order 14176 (January 2025) partially revoked EO 14110 but core safety reporting provisions remain influential.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0-risk-management-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-executive-order-14117-personal-data-2024",
    "title": "US Executive Order 14117 Preventing Access to Americans' Bulk Sensitive Personal Data by Countries of Concern (2024)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-16",
    "bluf": "Executive Order 14117, signed on 28 February 2024 and published in the Federal Register on 1 March 2024, directs the US Department of Justice (DOJ) National Security Division to issue regulations restricting transactions involving bulk sensitive personal data of US persons or US government-related data with countries of concern and covered persons. The DOJ Final Rule was issued in December 2024 and became effective on 8 April 2025, codified at 28 CFR Part 202. The regulation identifies countries of concern as China, Russia, Iran, North Korea, Venezuela, and Cuba. It establishes two tiers of restrictions: prohibited transactions, such as data brokerage to countries of concern, and restricted transactions, including vendor agreements, employment agreements, and investment agreements, which require compliance with CISA Security Requirements. Bulk thresholds vary by data type, covering covered personal identifiers, geolocation, biometric, human genomic, personal health, and personal financial data. Specific thresholds include, for example, 100 US persons for human genomic data, 1,000 for biometric data, 10,000 for precise geolocation data, and 100,000 for personal financial data. The regulation imposes obligations on US persons, including entities organized under US law, to prevent access to such data by countries of concern.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-export-administration-regulations",
    "title": "US Export Administration Regulations (EAR) - Dual-Use Technology Controls, Entity List and AI/Semiconductor Restrictions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Export Administration Regulations (EAR), administered by the Bureau of Industry and Security (BIS), control the export and reexport of most commercial and dual-use items, software, and technology. Organizations must determine if their items are subject to the EAR (Part 734), classify them against the Commerce Control List (CCL) to identify an Export Control Classification Number (ECCN), and screen all transaction parties against restricted lists like the Entity List (Part 744).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itar-compliance-workflow",
      "dfars-7012-defense-cyber",
      "nist-800-171-rev-3",
      "uk-strategic-export-control"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-export-administration-regulations-part-774",
    "title": "The Commerce Control List",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the Commerce Control List (CCL) under the Export Administration Regulations (EAR), specifying licensing requirements for the export, reexport, and transfer of dual-use items. It applies to all persons and entities subject to U.S. jurisdiction involved in the trade of items listed in Supplement No. 1 to Part 774.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-export-apple-act",
    "title": "US Export Apple Act (7 USC ch 25): Mandatory Export Certificate and Grade Standards for Apples",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Export Apple Act (7 U.S.C. ch. 25, sections 581 to 590a) requires that apples shipped from the United States to foreign destinations meet established grade standards and be accompanied by an export certificate, administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 581 provides for the establishment of standards of export and makes it unlawful for any person to ship or offer for shipment to any foreign destination any apples in packages which are not accompanied by a certificate issued under the authority of the Secretary of Agriculture certifying that the apples meet the applicable standards. Section 582 provides for notice of the establishment of standards and the treatment of shipments under contracts made before the adoption of standards. Section 583 addresses foreign standards and certification of compliance, and section 584 provides for exemptions. Section 585 provides for fees for inspection and certification and makes certificates prima facie evidence in court. Section 586 provides that the Secretary may refuse the issuance of certificates for periods not exceeding ninety days to violators and that any person knowingly violating any provision of the chapter shall be fined not less than 100 dollars nor more than 10,000 dollars. Section 589 sets the definitions and section 590a provides for estimates of apple production. The Act is the federal export quality and certification regime for apples.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-export-control-reform-act-2018",
    "title": "US Export Control Reform Act of 2018 (50 U.S.C. Chapter 58): Statutory Authority for Dual-Use Export Controls Administered by the Bureau of Industry and Security",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Export Control Reform Act of 2018 (ECRA), codified at 50 U.S.C. Chapter 58, is the permanent statutory authority for the United States dual-use export control system administered by the Department of Commerce through the Bureau of Industry and Security, and it provides the legal foundation for the Export Administration Regulations after the lapse of the Export Administration Act. Section 4801 sets out the definitions, including the items, the controlled activities of export, reexport, and in-country transfer, and the United States persons subject to the Act. Section 4811 states the policy that export controls are used to restrict the export of items that would make a significant contribution to the military potential of other countries or that would be detrimental to the national security, and only after full consideration of the impact on the economy. Section 4812 vests in the President the authority to control the export, reexport, and in-country transfer of items, an authority delegated to the Secretary of Commerce. Section 4813 sets out the additional authorities, including the establishment and maintenance of the control list and the imposition of license requirements. Section 4815 governs licensing and the conditions and procedures for license applications and decisions. Section 4817 requires the identification and control of emerging and foundational technologies essential to the national security. Section 4819 imposes the penalties, with criminal violations punishable by fines up to 1,000,000 dollars and imprisonment up to 20 years, and civil penalties up to 300,000 dollars or twice the value of the transaction, whichever is greater. Section 4820 provides the enforcement authorities. Subchapter II of the chapter contains the Anti-Boycott Act of 2018. The Act is the foundational statute for United States dual-use export controls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-export-control-reform-eccn-quantum-2023",
    "title": "US Export Administration Regulations - Quantum Technology Export Controls 2023: New ECCNs for Quantum Computers (3E001), Quantum Sensing Equipment, QKD Systems, Foreign Direct Product Rule Application to Quantum Tech and Multilateral Wassenaar Arrangement Coordination",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes export controls on quantum computing, sensing, and quantum key distribution (QKD) systems under new Export Control Classification Numbers (ECCNs), including 3E001, and applies the Foreign Direct Product Rule to quantum technologies in coordination with the Wassenaar Arrangement. It applies to U.S. persons and entities involved in the development, production, or export of quantum technologies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ear-dual-use-export",
      "cmmc-2-audit",
      "nist-800-171-cui",
      "dfars-7012-defense-cyber"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-faa-14-cfr-107-small-unmanned-aircraft-systems-suas",
    "title": "US FAA Small Unmanned Aircraft Systems (Drones) - 14 CFR Part 107 Operating Rules, Remote Pilot Certification, Remote Identification and Waiver Provisions",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "14 CFR Part 107 (Small Unmanned Aircraft Systems) is the FAA's operating rule for civil small unmanned aircraft systems (sUAS) weighing less than 55 pounds, including the unmanned aircraft and its associated elements (communication links and the components controlling the unmanned aircraft). Part 107 was issued in 2016 (81 FR 42064) and significantly amended in 2021 to add operations over people, operations at night, and remote identification (Part 89). Subpart B (operating rules) sets daylight operations or civil twilight (with anti-collision lighting), 400-foot AGL limit (or within 400 feet of a structure), 100 mph maximum ground speed, 3-statute-mile visibility minimum, visual line-of-sight, no operations from a moving vehicle (except in sparsely populated areas), no operations over human beings (unless under §107.39 categories 1-4), and yielding right-of-way to manned aircraft. Subpart C (remote pilot certification) requires either a Remote Pilot Certificate with sUAS rating or operation under direct supervision of a certificate holder. Subpart D (training and testing) sets the initial knowledge test and the recurrent training requirements. Subpart E (waivers) permits §107.200 waivers from many operating rules where the FAA finds the operation can be conducted safely. Section 107.49 requires preflight familiarization, inspection, and notification. Section 107.51 imposes operating limitations. Section 107.65 requires reporting to the FAA of accidents resulting in serious injury, loss of consciousness, or property damage of at least USD 500. Subpart F (general) addresses operations over moving vehicles (§107.145). Part 89 (separate but coordinated with Part 107) establishes Remote ID broadcasting requirements for sUAS.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-faa-14-cfr-121-air-carrier-operations-certification-safety",
    "title": "US FAA 14 CFR Part 121 - Air Carrier Operating Certificate, SMS & Safety Management",
    "domain": "Aviation, Defense & Quantum",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "14 CFR Part 121 establishes US FAA certification and operating standards for scheduled air carriers - including Safety Management System requirements (mandatory from March 2025 for Part 121 carriers), crew qualification, aircraft maintenance, and dispatch procedures - enforced with civil penalties up to $400,000 per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-faa-14-cfr-135-commuter-and-on-demand-operations",
    "title": "US FAA Commuter and On-Demand Air Carrier Operations - 14 CFR Part 135 Operating Certificate, Crew Qualification, Maintenance and Operational Control Requirements",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "14 CFR Part 135 (Operating Requirements: Commuter and On-Demand Operations and Rules Governing Persons On Board Such Aircraft) sets the operating rules for commuter and on-demand operations, which generally include charter operations, fractional ownership programs operating under Part 91 Subpart K with §135 election, helicopter air ambulance, and certain small scheduled-passenger operations. Part 135 applies to operators conducting operations meeting the §110.2 definitions of commuter operation (any scheduled operation with a frequency of operations of at least five round trips per week between two or more points; or any other operation that does not meet the definitions of supplemental operation, scheduled operation requiring an air carrier certificate, or domestic/flag/foreign air operation) and on-demand operation (passenger-carrying operations conducted as a public charter under Part 380, scheduled passenger-carrying operations conducted in airplanes with nine or fewer passenger seats and 7,500 lb payload, scheduled passenger-carrying operations in rotorcraft, on-demand passenger-carrying operations, etc.). Subpart A applies general provisions. Subpart B sets flight operations including weather, takeoff/landing minimums, fuel reserves, and load manifest. Subpart C requires aircraft and equipment including EFB/avionics, weather radar for transport-category aircraft. Subpart D requires VFR/IFR operating limitations including weather, runway requirements, and reserve fuel. Subpart E covers flight crewmember requirements including pilot qualifications and pairing. Subpart F sets crewmember flight time and rest requirements. Subpart G governs crewmember testing including the §135.293 competency check every 12 months. Subpart H covers training. Subpart I covers airplane performance limitations. Subpart J covers maintenance, preventive maintenance, and alterations including the §135.411 maintenance program required for nine-or-more passenger seat aircraft and the §135.419 approved aircraft inspection program (AAIP).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-faa-14-cfr-91-general-operating-and-flight-rules"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-faa-14-cfr-139-certification-of-airports",
    "title": "US FAA Airport Operating Certificate - 14 CFR Part 139 Certification of Airports Serving Scheduled Air Carrier Operations With More Than Nine Passenger Seats",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "14 CFR Part 139 (Certification of Airports) is the FAA's regulation requiring airports serving scheduled and unscheduled air carrier operations with aircraft having more than nine passenger seats to hold an Airport Operating Certificate issued by the FAA. The rule applies to land airports certificated under 49 U.S.C. 44706. Section 139.5 sets the four classes of certificate: Class I (scheduled large-air-carrier service plus unscheduled large-air-carrier service plus scheduled small-air-carrier service); Class II (scheduled small-air-carrier service and unscheduled large-air-carrier service); Class III (scheduled small-air-carrier service only); Class IV (unscheduled large-air-carrier service only). Subpart D sets operational requirements. Section 139.301 requires records to be maintained. Section 139.303 requires personnel training (Aircraft Rescue and Fire Fighting (ARFF), airport operations personnel, snow and ice control personnel). Section 139.305 requires paved areas (runways, taxiways, holding bays) to be maintained in compliance with FAA design and condition standards. Section 139.307 requires unpaved areas. Section 139.309 requires safety areas. Section 139.311 requires marking, signs, and lighting. Section 139.313 requires snow and ice control plan. Section 139.315-321 require Aircraft Rescue and Fire Fighting (ARFF) including index determination, equipment, vehicles, response time, agent quantities, and personnel. Section 139.323 requires traffic and wind direction indicators. Section 139.325 requires Airport Emergency Plan (AEP) covering aircraft accidents, terrorism, fires, structural collapses, hijack, severe weather, etc. Section 139.327 requires self-inspection program. Section 139.329 requires pedestrian and ground vehicle operations including driver training and movement-area access controls. Section 139.331 requires obstruction reporting. Section 139.337 requires wildlife hazard management including Wildlife Hazard Assessment (WHA) and Wildlife Hazard Management Plan (WHMP) if specified events occur. Section 139.339 requires airport condition reporting. Section 139.343 requires noncomplying conditions to be promptly issued by NOTAM. The Airport Certification Manual (ACM) per §139.203 documents how the airport complies with these obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-faa-14-cfr-145-repair-stations",
    "title": "US FAA Repair Station Certification - 14 CFR Part 145 Domestic and Foreign Repair Station Certificate, Quality Control and Recordkeeping Requirements",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "14 CFR Part 145 (Repair Stations) is the FAA's regulation governing the certification and operation of repair stations performing maintenance, preventive maintenance, or alterations on articles (aircraft, airframe, engine, propeller, appliance, or component thereof). Part 145 implements sections of the Federal Aviation Act of 1958 (codified at 49 U.S.C. 44701 et seq.). Section 145.51 sets initial certification requirements; certification is by ratings: airframe (with class), powerplant (with class), propeller (with class), radio (with class), instrument (with class), accessory (with class), and limited rating (article-specific). Section 145.59 sets the issuance of repair station certificate and ratings. Section 145.103 requires personnel including a supervisor for each work shift and a chief inspector. Section 145.109 requires equipment and materials per the manufacturer's recommendation or equivalent. Section 145.151 requires the repair station to provide adequate housing for the work to be performed. Section 145.157 requires personnel records. Section 145.161 requires hangar facility records. Section 145.163 requires the repair station to have a Repair Station Manual (RSM) including the work performed, personnel, and procedures. Section 145.165 requires the Quality Control Manual (QCM) covering quality control procedures, surveillance of supplier organizations, technical data system, and inspection procedures. Section 145.211 requires the chief inspector to ensure compliance. Section 145.217 requires the repair station to contract maintenance functions only to other FAA-approved repair stations or, with FAA approval, to non-certificated sources subject to direct quality control. Section 145.219 requires records to be maintained for 2 years from the date the article was approved for return to service. Foreign repair stations under §145.51(b) require an additional showing that the certificate is necessary for maintaining or altering US-registered aircraft and articles for use on US-registered aircraft, and §145.53 sets the additional duration and renewal requirements for foreign repair stations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-faa-14-cfr-91-general-operating-and-flight-rules"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-faa-14-cfr-450-commercial-space-launch-reentry-license",
    "title": "14 CFR Part 450 - FAA Commercial Space Launch and Reentry Vehicle Operator License",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "14 CFR Part 450 establishes the single, performance-based vehicle operator license under which the U.S. Federal Aviation Administration authorizes commercial launch and reentry operations. An operator must obtain a vehicle operator license, the scope and duration of which are defined by the FAA, and must comply with the license terms and conditions. The FAA conducts a policy review and approval, a payload review and determination, a safety review and approval, and an environmental review of the proposed operation. The operator must meet the safety criteria, implement a system safety program, apply hazard control strategies, and carry out flight hazard analysis, flight abort and physical containment requirements as applicable to the operation. The framework replaces the prior launch- and reentry-specific licensing rules with a consolidated set of requirements for safe commercial spaceflight from U.S. territory or by U.S. operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "intl-outer-space-treaty-1967-article-7-liability-damage",
      "intl-outer-space-treaty-1967-article-8-registration-jurisdiction",
      "new-zealand-outer-space-act-2017"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-faa-14-cfr-61-certification-pilots-flight-instructors",
    "title": "14 CFR Part 61 - Certification of Pilots, Flight Instructors and Ground Instructors",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "14 CFR Part 61 prescribes the FAA requirements for issuing pilot, flight instructor and ground instructor certificates and ratings, the conditions under which those certificates and ratings are necessary, and the privileges and limitations of each. A person may not act as pilot in command or in any other capacity as a required pilot flight crewmember unless he or she holds the appropriate pilot certificate, rating and any required authorization, and a current and appropriate medical certificate where one is required. Certificates and ratings are issued under the part by category (for example student, sport, recreational, private, commercial and airline transport pilot) with associated aircraft category and class ratings. A person must meet the eligibility, aeronautical knowledge, flight proficiency and aeronautical experience requirements for the certificate or rating sought, including the type rating and additional training and authorization requirements for certain aircraft and operations, and the instrument rating requirements where applicable. Pilots must maintain a logbook documenting the training and aeronautical experience used to meet the requirements and to show recent flight experience. To act as pilot in command, a pilot must have completed a flight review within the preceding 24 calendar months and must meet the recent flight experience requirements, including the required takeoffs and landings within the preceding 90 days before carrying passengers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "certificate_levels",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-faa-14-cfr-91-general-operating-and-flight-rules",
      "faa-part-141-pilot-school-certification",
      "us-faa-14-cfr-135-commuter-and-on-demand-operations"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-faa-14-cfr-91-general-operating-and-flight-rules",
    "title": "US FAA General Operating and Flight Rules - 14 CFR Part 91 Operating Rules, Right-of-Way, Airspace Restrictions, Maintenance and Pilot Operational Limits for All Civil Aircraft",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "14 CFR Part 91 (General Operating and Flight Rules) is the FAA's baseline operating regulation for the operation of all civil aircraft in the United States, including private operations, business aviation, and operations under other Parts that incorporate Part 91 by reference. Subpart A sets general provisions including §91.3 (responsibility and authority of the pilot in command), §91.7 (civil aircraft airworthiness), §91.13 (careless or reckless operation). Subpart B sets flight rules including §91.103 (preflight action), §91.107 (use of safety belts, shoulder harnesses, and child restraint systems), §91.111 (operating near other aircraft), §91.113 (right-of-way rules: except water operations), §91.117 (aircraft speed: below 10,000 feet MSL no faster than 250 knots), §91.119 (minimum safe altitudes), §91.121 (altimeter settings), §91.123 (compliance with ATC clearances and instructions), §91.125 (ATC light signals), §91.127-137 (Class C, Class B, Class D, prohibited and restricted areas). Subpart C covers equipment, instrument, and certificate requirements including §91.205 (powered civil aircraft with standard category US airworthiness certificates: instrument and equipment requirements for day VFR, night VFR, and IFR), §91.207 (emergency locator transmitters). Subpart D covers special flight operations. Subpart E covers maintenance, preventive maintenance, and alterations including §91.405 (responsibility of registered owner/operator), §91.407 (operation after maintenance), §91.409 (inspections: annual, 100-hour, progressive, and approved aircraft inspection program), §91.411 (altimeter system and altitude reporting equipment tests every 24 months), §91.413 (ATC transponder tests every 24 months). Subpart F covers large and turbine-powered multiengine airplanes and fractional ownership programs (Subpart K). Subpart H covers foreign aircraft operations and operations of US-registered civil aircraft outside of the United States. Subpart K covers fractional ownership operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-faa-14-cfr-part-415-launch-license-policy-review",
    "title": "US FAA 14 CFR Part 415 Launch License Policy Review and Approval Process Legacy Framework Now Superseded by Part 450 for New Licenses",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "14 CFR Part 415 implements the United States Federal Aviation Administration legacy launch license framework governing launches from federal launch sites and non-federal launch sites organised in operative subparts covering Subpart A General with applicability scope and definitions, Subpart B Policy Review and Approval requiring policy review for foreign policy national security and US international obligations implications, Subpart C Safety Review and Approval establishing system safety analysis maximum probable loss and population protection requirements, Subpart D Payload Review and Determination requiring foreign policy national security and public health and safety reviews of each payload, Subpart E Environmental Review under NEPA including categorical exclusions environmental assessments and environmental impact statements, Subpart F Financial Responsibility Requirements implementing the maximum probable loss insurance regime, and additional subparts on safety system requirements unique to expendable launch vehicles. Operators with existing Part 415 licenses had until March 2026 to transition to the unified Part 450 framework with no new Part 415 licenses being issued post-transition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-faa-14-cfr-part-450-launch-reentry-license-requirements"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-faa-14-cfr-part-450-launch-reentry-license-requirements",
    "title": "US FAA 14 CFR Part 450 Launch and Reentry License Requirements Performance-Based Framework for Commercial Spaceflight Operations",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "14 CFR Part 450 implements the United States Federal Aviation Administration unified performance-based framework for commercial launch and reentry vehicle licensing organised in 3 subparts covering Subpart A General Information establishing foundational definitions scope and what a vehicle operator license authorises and its duration, Subpart B Requirements to Obtain a Vehicle Operator License outlining the approval process applicants must complete encompassing policy review payload determinations safety assessments and environmental compliance, and Subpart C Safety Requirements establishing detailed safety standards that operators must meet including risk criteria system safety programs hazard control strategies and comprehensive flight safety analyses. Part 450 replaced four legacy regulation parts (Parts 415, 417, 431, and 435) that had governed commercial spaceflight since the 1990s with a single performance-based framework that became mandatory in March 2026 with major operators including Blue Origin Firefly SpaceX Rocket Lab and United Launch Alliance completing the mandatory transition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-commercial-space-launch-competitiveness-act-2015-space-resources"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-faa-14-cfr-part-460-human-spaceflight-requirements",
    "title": "US FAA 14 CFR Part 460 Human Space Flight Requirements Crew Spaceflight Participant Informed Consent and Operator Safety Obligations",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "14 CFR Part 460 implements the United States Federal Aviation Administration human spaceflight regulations applicable to launch and reentry operators carrying crew or spaceflight participants organised in operative sections including section 460.1 scope and applicability covering operators with humans onboard, section 460.5 crew qualifications and training requirements for safety-critical roles, section 460.7 crew waiver of claims for fault by the United States, section 460.9 informed consent requirements for spaceflight participants disclosing risks and the absence of US Government certification, section 460.11 security requirements to ensure spaceflight participants do not present a security risk to crew and operations, section 460.13 spaceflight participant informed consent process documentation, section 460.15 environmental control and life support system performance requirements, section 460.17 verification programme requirements, section 460.19 crew waiver and spaceflight participant waiver collection and retention, section 460.51 spaceflight participant training requirements, and section 460.53 spaceflight participant medical and physical qualification requirements. The Part applies as a statutory moratorium on prescriptive safety regulation pending evolution of the industry under the Commercial Space Launch Act framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-commercial-space-launch-competitiveness-act-2015-space-resources",
      "us-faa-14-cfr-part-450-launch-reentry-license-requirements"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-faa-far-part-91-general-aviation-14-cfr",
    "title": "FAR Part 91 - General Operating and Flight Rules (14 CFR Part 91)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Title 14 of the Code of Federal Regulations (CFR) Part 91 - General Operating and Flight Rules - is the foundational Federal Aviation Regulation governing the operation of all civil aircraft within the United States national airspace system (NAS), over the high seas, and to the extent that operations are not covered by more specific regulations (Parts 121, 135, 125). Part 91 applies to all operators not conducting air carrier or commercial operations; it prescribes rules for VFR (Visual Flight Rules) and IFR (Instrument Flight Rules) flight, right-of-way rules (§91.113), minimum safe altitudes (§91.119), aircraft airworthiness (§91.403-§91.417), flight plan requirements, transponder and ADS-B Out requirements (§91.225-§91.227 - ADS-B Out mandatory above FL180 and in Mode C Veil around Class B airports from 1 January 2020), fuel requirements (§91.151 VFR, §91.167 IFR), oxygen requirements (§91.211), and prohibited operations. Part 91 Subpart K establishes a fractional ownership program regime. The FAA reauthorisation (FAA Reauthorization Act 2024, Public Law 118-63) extended the FAA's operating authority through 30 September 2028 and directed new rulemaking on advanced air mobility (AAM), UAS integration, and NextGen NAS modernisation. ADS-B Out compliance remains enforcement priority; violations carry civil penalties up to $50,000 per violation under 49 U.S.C. §46301.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "faa-part-107-uas-2021",
      "faa-part-21-certification",
      "easa-part-145-maintenance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-faa-part-460-human-space-flight-requirements",
    "title": "14 CFR Part 460 - Human Space Flight Requirements",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes safety and training requirements for crew, space flight participants, and government astronauts involved in commercial human space flight operations under an FAA license or permit. Key requirements include crew training under § 460.5, risk disclosure to space flight participants under § 460.45, and waivers of claims against the U.S. Government under § 460.49.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-8374-ransomware-risk-management",
      "iso-15489-1-2016-records-management-workflow"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-faa-sfar-120-powered-lift-14-cfr-194",
    "title": "Integration of Powered-Lift: Pilot Certification and Operations - Special Federal Aviation Regulation No. 120 (14 CFR Part 194)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Special Federal Aviation Regulation No. 120, codified at 14 CFR Part 194, prescribes requirements that may be satisfied in lieu of part 61 for persons seeking a powered-lift pilot certificate and rating, together with alternate qualification, training, and operational provisions for powered-lift, including flight simulation training device qualification; the SFAR remains in effect until 21 January 2035.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-faa-14-cfr-61-certification-pilots-flight-instructors",
      "faa-part-21-certification",
      "us-faa-14-cfr-135-commuter-and-on-demand-operations"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fair-credit-reporting-act",
    "title": "US Fair Credit Reporting Act (15 USC ch 41 subch III): Consumer Reports, Permissible Purposes and Disputes",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Fair Credit Reporting Act (FCRA, 15 U.S.C. ch. 41, subchapter III) regulates the collection, use and disclosure of consumer credit information by consumer reporting agencies, enforced by the Consumer Financial Protection Bureau and the Federal Trade Commission, with a private right of action. Section 1681 states the findings and the purpose of ensuring accuracy and fairness in credit reporting and protecting consumer privacy. Section 1681a supplies the definitions, including consumer report and consumer reporting agency. Section 1681b limits the disclosure of a consumer report to permissible purposes, such as a credit transaction, employment with consent, or a legitimate business need. Section 1681c sets requirements on the information that may be reported, including the time limits after which adverse items become obsolete. Section 1681c-1 provides for identity-theft prevention, including fraud alerts and active-duty alerts. Section 1681i sets the procedure a consumer reporting agency must follow when the accuracy of an item is disputed, including reinvestigation within the statutory period. Section 1681m imposes duties on users of consumer reports, including the obligation to give an adverse action notice. Enforcement is provided by section 1681n (civil liability for willful noncompliance, including statutory and punitive damages) and section 1681o (civil liability for negligent noncompliance). The Act is the legal foundation of US credit-reporting accuracy, permissible-purpose limits and consumer dispute rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fair-credit-reporting-act-fcra-1970",
    "title": "US Fair Credit Reporting Act (FCRA) - 15 USC 1681",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "FCRA governs consumer credit reporting: maximum 7-year (10-year bankruptcy) reporting periods, 30-day dispute investigation, permissible-purpose requirement, adverse-action notice within 30 days, and free annual credit report right.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cfpb-dodd-frank-title-x-consumer-financial-protection",
      "us-glba-gramm-leach-bliley-act-1999"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fair-debt-collection-practices-act",
    "title": "US Fair Debt Collection Practices Act (15 USC ch 41 subch V): Debt Collector Conduct and Civil Liability",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Fair Debt Collection Practices Act (FDCPA, 15 U.S.C. ch. 41, subchapter V, sections 1692 to 1692p) regulates the conduct of third-party debt collectors and is enforced by the Consumer Financial Protection Bureau and the Federal Trade Commission, alongside a private right of action. Section 1692 states the congressional findings and purpose of eliminating abusive debt-collection practices. Section 1692a supplies the definitions, including debt collector and consumer. Section 1692b regulates the acquisition of location information about a consumer. Section 1692c restricts communication in connection with the collection of a debt, including the times, places, and parties a collector may contact and the consumer's right to require that communication cease. Section 1692d prohibits harassment or abuse, section 1692e prohibits false or misleading representations, and section 1692f prohibits unfair practices. Section 1692g requires the collector to send a written validation notice and to cease collection if the consumer disputes the debt until verification is provided. Enforcement runs through section 1692k, which provides civil liability for actual damages plus additional statutory damages of up to 1,000 dollars in an individual action, or in a class action up to the lesser of 500,000 dollars or 1 percent of the collector's net worth, together with costs and attorney fees. The Act is the legal foundation of US consumer debt-collection compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fair-housing-act",
    "title": "US Fair Housing Act (42 USC ch 45): Prohibition of Housing Discrimination",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Fair Housing Act (42 U.S.C. ch. 45, subchapter I) prohibits discrimination in housing and residential real estate transactions, administered by the Department of Housing and Urban Development with enforcement also by the Department of Justice. Section 3604 makes it unlawful to refuse to sell or rent, or to discriminate in the terms, conditions or privileges of sale or rental of a dwelling, or in the provision of services, because of race, color, religion, sex, familial status, national origin or handicap; it also prohibits discriminatory advertising, misrepresenting availability, blockbusting, and, for persons with a handicap, refusing reasonable modifications and accommodations and failing to design covered multifamily dwellings with required accessibility features. Section 3605 prohibits discrimination in residential real estate-related transactions, including the making or purchasing of loans, and section 3606 prohibits discrimination in the provision of brokerage services. Section 3608 assigns administration to the Secretary, section 3610 provides for administrative complaints and investigation, section 3612 provides for enforcement by administrative law judges, and section 3613 provides for enforcement by private civil action with actual and punitive damages. The Act is the legal foundation for US fair housing compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fair-housing-act-42-usc-ch45",
    "title": "United States Fair Housing Act, Title VIII of the Civil Rights Act of 1968 (Title 42 USC Chapter 45): Declaration of Policy, Definitions, Discrimination in Sale or Rental of Housing, Discrimination in Residential Real Estate Transactions, Discrimination in Provision of Brokerage Services, HUD Administration, Enforcement by Private Persons, and Enforcement by the Attorney General",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Fair Housing Act, Title VIII of the Civil Rights Act of 1968 (Public Law 90-284), codified at Title 42 of the United States Code, Chapter 45, is the principal federal statute prohibiting discrimination in the sale, rental, and financing of housing on the basis of race, color, religion, sex, familial status, national origin, or disability, and is administered by the Department of Housing and Urban Development (HUD) Office of Fair Housing and Equal Opportunity and the Department of Justice Civil Rights Division. Fair Housing Act, 42 U.S.C. 3601 declares the policy of the United States to provide, within constitutional limitations, for fair housing throughout the United States. Fair Housing Act, 42 U.S.C. 3602 contains the definitions including Secretary, dwelling, family, handicap, and familial status. Fair Housing Act, 42 U.S.C. 3604 prohibits discrimination in the sale or rental of housing and other prohibited practices including refusal to sell or rent, discriminatory terms or conditions, discriminatory advertising, and discrimination based on protected characteristics. Fair Housing Act, 42 U.S.C. 3605 prohibits discrimination in residential real estate-related transactions including lending discrimination and appraisal practices. Fair Housing Act, 42 U.S.C. 3606 prohibits discrimination in the provision of brokerage services including multiple-listing services and real estate broker organizations. Fair Housing Act, 42 U.S.C. 3608 sets HUD Secretary's administrative authority and responsibility. Fair Housing Act, 42 U.S.C. 3613 provides for enforcement by private persons through civil actions. Fair Housing Act, 42 U.S.C. 3614 provides for enforcement by the Attorney General through pattern or practice litigation. The Act is the controlling federal instrument for fair housing protection in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fair-labor-standards-act",
    "title": "US Fair Labor Standards Act (29 USC ch 8): Minimum Wage, Overtime, Child Labor and Penalties",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Fair Labor Standards Act of 1938 (FLSA, 29 U.S.C. ch. 8) sets the federal floor for wages and hours and restricts child labor, administered by the Wage and Hour Division of the Department of Labor. Section 202 records the congressional finding that substandard labor conditions burden commerce and the policy of eliminating them. Section 203 supplies the definitions, including employer (any person acting directly or indirectly in the interest of an employer), employee and wage. Section 206 sets the federal minimum wage, which the statute fixes at 7.25 dollars an hour. Section 207 requires overtime compensation at one and one-half times the regular rate for hours worked in excess of 40 in a workweek. Section 212 restricts oppressive child labor. Section 213 sets the exemptions, including the executive, administrative and professional exemptions. Section 215 lists the prohibited acts, including shipping goods produced in violation of the wage or child-labor provisions and retaliating against employees who assert their rights. Section 216 provides the penalties and the right of employees to recover unpaid wages and overtime, liquidated damages, and attorney fees, with criminal penalties for willful violations. Section 218 preserves more protective state and local laws. The Act is the legal foundation of US wage-and-hour compliance and the basis of most overtime and minimum-wage litigation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fair-labor-standards-act-flsa",
    "title": "Fair Labor Standards Act (FLSA) - Minimum Wage, Overtime Pay, Recordkeeping and Child Labor Standards",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Fair Labor Standards Act (FLSA) establishes federal minimum wage, overtime pay at 1.5x regular rate for hours over 40 in a workweek, recordkeeping, and youth employment standards affecting employees in the private sector and in Federal, State, and local governments. Key provisions are outlined in 29 U.S.C. §§ 206 (Minimum Wage) and 207 (Maximum Hours/Overtime).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eeoc-employment-rule",
      "fmla-compliance-leave",
      "osha-work-safety-us",
      "ada-employment-title-1",
      "sa8000-social-account"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fair-packaging-and-labeling-act",
    "title": "US Fair Packaging and Labeling Act (15 USC ch 39): Consumer Commodity Labeling",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Fair Packaging and Labeling Act (15 U.S.C. ch. 39) requires that consumer commodities be honestly and informatively labeled to enable value comparison, with authority divided between the Federal Trade Commission for most products and the Food and Drug Administration for foods, drugs, devices and cosmetics. Section 1452 makes it unlawful to distribute in commerce any packaged consumer commodity that is not labeled in conformity with the Act and its regulations. Section 1453 sets the requirements of labeling: the label of a consumer commodity must bear the identity of the commodity, the name and place of business of the manufacturer, packer or distributor, and the net quantity of contents separately and accurately stated in a uniform location on the principal display panel, in both the customary inch-pound and the metric systems, in conspicuous and legible type, and where applicable the net quantity of a serving. Section 1454 authorizes additional regulations to prevent deception or to facilitate value comparisons, including rules on cents-off representations and slack fill. Section 1455 allocates regulatory authority, and section 1456 provides for enforcement, treating a violation as an unfair or deceptive act under the Federal Trade Commission Act or a misbranding under the food and drug law as applicable. The Act is the legal foundation for US consumer commodity quantity and identity labeling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fair-use-17-usc-107-education",
    "title": "US Fair Use Doctrine 17 USC 107 - Educational Copying: Four-Factor Test, Classroom Guidelines, TEACH Act Digital Distance Education, Course Packs and Library Reserves for Educational Institutions",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation outlines the statutory framework for fair use under U.S. copyright law, specifically as it applies to educational institutions, allowing unlicensed use of copyrighted works under certain conditions. Compliance requires evaluation of the four factors in Section 107 of the Copyright Act, including purpose, nature, amount, and market effect.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-copyright-treaty"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-false-claims-act",
    "title": "US False Claims Act (31 USC ch 37): Liability for False Claims and Qui Tam Enforcement",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The False Claims Act (31 U.S.C. ch. 37, subchapter III) is the principal US statute for combating fraud against the Federal Government, enforced by the Department of Justice and through private whistleblower actions. Section 3729 imposes liability on any person who knowingly presents, or causes to be presented, a false or fraudulent claim for payment or approval, who knowingly makes or uses a false record or statement material to a false claim, who conspires to do so, or who knowingly conceals or improperly avoids an obligation to pay money to the Government. Knowing is defined to include actual knowledge, deliberate ignorance and reckless disregard, and no proof of specific intent to defraud is required. A violator is liable for a civil penalty, as adjusted for inflation from the statutory range of not less than 5,000 dollars and not more than 10,000 dollars per claim, plus three times the amount of damages the Government sustains. Section 3730 provides for civil actions, including qui tam actions in which a private relator may sue on behalf of the Government and share in the recovery, and protects relators from retaliation. Section 3731 sets the procedure and burden of proof, and section 3733 provides civil investigative demand authority. The Act is the legal foundation for US fraud recovery across healthcare, defense and procurement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-family-and-medical-leave-act",
    "title": "US Family and Medical Leave Act (29 USC ch 28): 12 Weeks of Job-Protected Leave and Restoration Rights",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Family and Medical Leave Act of 1993 (FMLA, 29 U.S.C. ch. 28) entitles eligible employees of covered employers to unpaid, job-protected leave for specified family and medical reasons, administered by the Wage and Hour Division of the Department of Labor. Section 2601 sets the findings and purposes of balancing the demands of the workplace with the needs of families. Section 2611 supplies the definitions: an eligible employee is one who has been employed for at least 12 months and for at least 1,250 hours of service in the previous 12-month period, a covered employer is one with 50 or more employees for each working day in 20 or more calendar workweeks, and a serious health condition involves inpatient care or continuing treatment by a health care provider. Section 2612 sets the core entitlement to a total of 12 workweeks of leave in any 12-month period for the birth or placement of a child, to care for a family member with a serious health condition, for the employee's own serious health condition, or for a qualifying exigency arising from covered active duty. Section 2613 allows the employer to require medical certification. Section 2614 protects employment and benefits and entitles the employee to restoration to the same or an equivalent position. Section 2615 prohibits interference with FMLA rights and retaliation, and section 2617 provides enforcement and remedies, including lost compensation, liquidated damages and attorney fees. The Act is the legal foundation of US job-protected family and medical leave.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-family-educational-rights-and-privacy-act",
    "title": "US Family Educational Rights and Privacy Act (FERPA, 20 USC 1232g): Education Record Access and Disclosure",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. 1232g) protects the privacy of student education records and is enforced by the Department of Education against educational agencies and institutions that receive federal funds. Subsection 1232g(a)(1) gives parents the right to inspect and review their children's education records, with the institution required to respond within a reasonable time and in no case more than 45 days. Subsection 1232g(a)(2) gives parents the right to a hearing to challenge the content of records that are inaccurate, misleading, or otherwise in violation of privacy rights, and to insert a written explanation. Subsection 1232g(b)(1) prohibits the disclosure of personally identifiable information from education records without the written consent of the parent, subject to enumerated exceptions, including disclosure to school officials with legitimate educational interests, to a school to which the student is transferring, in connection with financial aid, and to comply with a lawful subpoena. Subsection 1232g(a)(5) permits the disclosure of designated directory information after notice and an opportunity to opt out. Subsection 1232g(d) transfers the rights from the parent to the student once the student turns 18 or attends a postsecondary institution. The enforcement mechanism is the withholding of federal funds from a non-compliant institution. The Act is the legal foundation of US student-records privacy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-family-educational-rights-privacy-act-ferpa-1974-doe",
    "title": "US Family Educational Rights and Privacy Act (FERPA) 1974 - Department of Education",
    "domain": "Data Protection & Privacy",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "FERPA (20 U.S.C. 1232g; 34 C.F.R. Part 99) protects the privacy of student education records at institutions receiving federal funding; grants parents rights to inspect, amend, and control disclosure of education records, transferring to students at age 18 or upon post-secondary enrollment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-family-entertainment-copyright-act-2005",
    "title": "17 U.S. Code § 1201 - Circumvention of copyright protection systems",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Prohibits circumvention of technological measures that control access to copyrighted works and bans trafficking in circumvention technologies. Applies to individuals, organizations, and technology providers. Key provisions are in subsections (a)(1)(A) and (a)(2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dmca-safe-harbor",
      "copyright-fair-use-us",
      "eu-copyright-directive-art-17"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-far-far-itar-export-controls-defense-articles-technical-data",
    "title": "US ITAR - International Traffic in Arms Regulations (22 CFR Parts 120-130) Defense Articles Export Controls",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "The International Traffic in Arms Regulations (ITAR) at 22 CFR Parts 120-130, implemented under the Arms Export Control Act (AECA), regulate the export and import of defense articles, defense services, and related technical data listed on the US Munitions List (USML). Any person or organisation that exports ITAR-controlled items must register with the Directorate of Defense Trade Controls (DDTC) and obtain a licence or use an applicable exemption. Violations carry criminal penalties up to $1 million per violation and civil fines up to $1.3 million per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-economic-sanctions-compliance-31-cfr-500"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-far-part-11-describing-agency-needs",
    "title": "FAR Part 11 / 48 CFR Part 11 - Describing Agency Needs",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Federal Acquisition Regulation (FAR) Part 11 / 48 CFR Part 11 establishes policies and procedures for describing agency needs in federal acquisitions across seven subparts: 11.1 Selecting and Developing Requirements Documents (specifications, standards, performance-based descriptions); 11.2 Using and Maintaining Requirements Documents; 11.3 Acceptable Material (recovered materials, energy efficiency); 11.4 Delivery or Performance Schedules; 11.5 Liquidated Damages; 11.6 Priorities and Allocations (Defense Production Act DPAS); 11.7 Variation in Quantity. FAR 11.002 establishes the foundational policy: 'In fulfilling requirements... agencies shall - (1) Specify needs using market research in a manner designed to - (i) Promote full and open competition (see Part 6), or maximum practicable competition when using simplified acquisition procedures, with due regard to the nature of the supplies or services to be acquired; (ii) Only include restrictive provisions or conditions to the extent necessary to satisfy the needs of the agency or as authorized by law'; FAR 11.002(a)(2) provides the performance-based requirements directive: 'State requirements with respect to an acquisition of supplies or services in terms of - (i) Functions to be performed; (ii) Performance required; or (iii) Essential physical characteristics.' FAR 11.101 establishes the order of precedence for requirements documents: (1) Documents mandated for use by law; (2) Performance-oriented documents (e.g., performance work statements); (3) Detailed design-oriented documents; (4) Standards, specifications, and related publications issued by the Government outside the Defense or Federal series; FAR 11.103 establishes market acceptance considerations for restricting to commercially acceptable products; FAR 11.104 governs brand name or equal purchase descriptions; FAR 11.5 Liquidated Damages enables the recovery of monetary damages for breach of delivery or performance terms; FAR 11.6 implements the Defense Production Act priorities and allocations system administered by the Department of Commerce.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "related_far_parts",
        "performance_work_statement_framework",
        "industry_mapping",
        "enforcement_anchors",
        "dpas_priorities_and_allocations_section_11_6",
        "liquidated_damages_section_11_5"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-7-acquisition-planning",
      "us-far-part-6-competition-requirements",
      "us-defense-production-act-50-usc-4501"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-far-part-12-commercial-products-services",
    "title": "FAR Part 12 - Acquisition of Commercial Products and Commercial Services",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 12 implements 41 USC chapter 33 and 10 USC chapter 247 by requiring federal executive agencies to conduct market research, acquire commercial products and commercial services when available, and require prime contractors and subcontractors to incorporate commercial products and services to the maximum extent practicable: Subpart 12.1 establishes the commercial-item preference policy at 12.101 requiring market research and Part 12 takes precedence over inconsistent FAR policies for commercial procurements (12.102); Subpart 12.2 specifies streamlined procedures including firm-fixed-price or fixed-price with economic price adjustment as the default contract type (12.207), with time-and-materials permitted only on competitive determination-and-findings basis; Subpart 12.3 mandates use of the standard commercial clauses 52.212-1 through 52.212-5 to maximum extent practicable, restricting inserted clauses to those required by law or executive order (12.301); the Government acquires only technical data rights customarily provided to the public with the commercial product or process (12.211); Subpart 12.5 lists laws inapplicable to commercial product or service contracts and prohibits use of Part 12 to waive substantive law where the prime is reselling another contractor's products without adding value (12.501).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "contract_clauses_mandatory",
        "data_rights_default",
        "inapplicable_laws_list",
        "commercial_definition_anchor"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-6-competition-requirements",
      "us-fasa-1994-federal-acquisition-streamlining-pl-103-355",
      "us-41-usc-3301-full-open-competition-federal-procurement"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-13-simplified-acquisition-procedures",
    "title": "FAR Part 13 / 48 CFR Part 13 - Simplified Acquisition Procedures",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 13 / 48 CFR Part 13 establishes streamlined procedures for acquiring supplies, services, and construction at or below the Simplified Acquisition Threshold (SAT - currently USD 250,000) and authorizes special simplified procedures under FAR Subpart 13.5 for commercial products and services up to USD 9 million (USD 15 million under contingency operations or major disaster declarations); the foundational policy at FAR 13.003 requires agencies to use simplified acquisition procedures to the maximum extent practicable for purchases within established thresholds, prohibits artificial subdivision to avoid threshold rules, and reserves acquisitions between the micro-purchase threshold (USD 10,000) and the SAT for small business set-asides under FAR 19.502-2; FAR 13.005 identifies certain statutes that do not apply to acquisitions at or below the SAT including examination of contractor records, restrictions on subcontractor direct sales, contingent fee covenant requirements, and certain drug-free workplace provisions (except for individuals); FAR Subpart 13.5 authorizes streamlined procedures for commercial items above the SAT, allowing simplified solicitation and evaluation while maintaining essential documentation; the simplified acquisition regime is the primary federal pathway for routine government purchasing and represents the majority of federal procurement transactions by volume.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "competition_intersection",
        "small_business_intersection",
        "industry_mapping",
        "enforcement_anchors",
        "commercial_item_simplification_subpart_13_5"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-far-part-19-small-business-set-asides",
      "us-41-usc-3304-noncompetitive-procedures-exceptions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-far-part-14-sealed-bidding",
    "title": "FAR Part 14 - Sealed Bidding (Invitation for Bids, Bid Opening, Award)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 14 prescribes the sealed-bidding procedures used when all four FAR 6.401(a) conditions are met (time permits solicitation, award on price and price-related factors, discussions unnecessary, multiple bids expected): Subpart 14.1 requires the contracting officer to prepare Invitations for Bids using the Uniform Contract Format (Table 14-1) with a Schedule, Contract Clauses, Documents and Exhibits, and Representations and Instructions; Subpart 14.2 requires a reasonable bidding time (minimum 30 calendar days where synopsis is required under Subpart 5.2), restricts the use of bid samples and descriptive literature to characteristics that cannot be adequately specified in writing, and prescribes amendment and cancellation rules; Subpart 14.3 imposes the responsiveness test that a bid must comply in all material respects with the IFB to be considered for award; Subpart 14.4 governs bid opening, evaluation, and award - bids are opened publicly, late bids handled under 14.304, and award goes to the responsible bidder whose responsive bid is most advantageous to the Government considering only price and price-related factors; Subpart 14.5 provides the two-step sealed bidding procedure for procurements where complete specifications are not available (step one technical proposal evaluation, step two competitive sealed bidding among technically acceptable offerors). Cancellation after bid opening requires a compelling reason under 14.404-1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "uniform_contract_format",
        "industry_mapping",
        "responsiveness_vs_responsibility",
        "late_bid_rules",
        "two_step_sealed_bidding"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-6-competition-requirements",
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-31-usc-3553-gao-bid-protest-review"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-15-contracting-by-negotiation",
    "title": "FAR Part 15 - Contracting by Negotiation (Source Selection and Best Value Procurement)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 15 governs the negotiated competitive proposal process used when sealed bidding is not appropriate, structuring federal procurement around source selection for best value: Subpart 15.2 requires Requests for Proposals (RFPs) to disclose evaluation factors and significant subfactors that will be used (15.203(a)(4)), with proposals safeguarded from unauthorised disclosure (15.207); Subpart 15.3 establishes the source selection process where price or cost must be evaluated in every selection (15.304(c)(1)), past performance must be considered (15.305(a)(2)), and proposals must be evaluated solely on the factors stated in the solicitation (15.305(a)); FAR 15.306 establishes the structured exchange phases (clarifications, communications, competitive range determination, discussions, final proposal revisions) with mandatory disclosure of deficiencies and significant weaknesses to offerors in the competitive range (15.306(d)(3)) and prohibitions on favouring one offeror or revealing technical solutions or prices (15.306(e)); Subpart 15.4 sets pricing policy requiring certified cost or pricing data above threshold (15.403-4) unless an exception applies. The source selection authority's decision must be a comparative assessment against all stated criteria documented in a Source Selection Decision Document under 15.308.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "exchange_phases",
        "industry_mapping",
        "cost_pricing_data_thresholds",
        "protest_grounds",
        "documentation_chain"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-6-competition-requirements",
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-31-usc-3553-gao-bid-protest-review"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-16-types-of-contracts",
    "title": "FAR Part 16 - Types of Contracts (Fixed-Price, Cost-Reimbursement, IDIQ, and Time-and-Materials Selection)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 16 prescribes the contract types available for federal procurement and the criteria for selecting among them, with the controlling principle at 16.103 that each contract file shall include documentation showing why the particular contract type was selected and (for non-firm-fixed-price contracts) the Government's additional risks, mitigation, and resource requirements: Subpart 16.2 establishes fixed-price types - firm-fixed-price (16.202) with no cost-experience adjustment, fixed-price with economic price adjustment (16.203) for specified contingencies, and fixed-price incentive (16.204); Subpart 16.3 governs cost-reimbursement types limited under 16.301 to circumstances where requirements cannot be defined sufficiently for fixed-price, including cost-plus-fixed-fee (16.306) with completion form preferred over term form; Subpart 16.5 controls indefinite-delivery contracts including indefinite-quantity (16.504) where the contracting officer must give multiple-award preference to the maximum extent practicable and contracts exceeding USD 150 million require head-of-agency single-source determination; Subpart 16.6 governs time-and-materials contracts which are not fixed-price under 16.201(b) and require a ceiling price and competitive determination-and-findings under FAR 12.207 for commercial services or 16.601 for non-commercial. Contract type selection drives risk allocation, oversight intensity, and audit requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "risk_allocation_spectrum",
        "documentation_requirements",
        "industry_mapping",
        "ordering_period_limits",
        "audit_implications"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-6-competition-requirements",
      "us-far-part-15-contracting-by-negotiation",
      "us-31-usc-1341-antideficiency-act"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-17-special-contracting-methods",
    "title": "FAR Part 17 - Special Contracting Methods (Multi-Year Contracts, Options, Interagency Acquisitions / Economy Act, Management and Operating Contracts, Reverse Auctions)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Federal Acquisition Regulation (FAR) Part 17 governs special contracting methods used when standard award structures are inappropriate. Subpart 17.1 (Multi-Year Contracting) implements 41 USC 3903 (civilian) and 10 USC 3501 (DoD) authorising contracts covering more than 1 but not more than 5 program years without separate option exercises; nondefense agencies must determine the need is reasonably firm and continuing and the approach serves the best interests of the United States, while DoD, NASA, and Coast Guard require cost savings, stable design, minimal technical risk, reasonable expectation of continued funding, and realistic estimates. Each program year except the first remains cancellable and the contracting officer establishes a cancellation ceiling excluding amounts for prior years' requirements with nonrecurring costs amortised across program years. Congressional notification thresholds under FAR 17.108 are USD 20 million (nondefense) and USD 200 million (DoD/NASA/Coast Guard) with a 31-day wait period. Clause 52.217-2 (Cancellation Under Multi-year Contracts) is required. Subpart 17.2 (Options) governs unilateral option exercise: the option must be exercised in writing within the period specified in the contract; before exercise the contracting officer must determine in writing that funds are available, the option fulfils an existing Government need, exercise is the most advantageous method considering price and other factors, the option was synopsised under FAR Part 5 (unless exempt), the contractor is not on the SAM exclusion list, past performance has been considered, and current performance is acceptable. Total basic plus option periods for services are limited to 5 years under FAR 17.204(e). Clauses 52.217-3 through 52.217-9 cover evaluation and exercise of options. Subpart 17.5 (Interagency Acquisitions) governs acquisitions where one agency uses another agency's contract or contracting services; the Economy Act at 31 USC 1535 is the default authority requiring a determination and findings (D&F) that interagency acquisition is in the best interest, supplies cannot be obtained as conveniently or economically by direct contracting, and one of three specific circumstances applies; assisted acquisitions require a written interagency agreement before solicitation while direct acquisitions do not. Multi-agency contracts and Government-wide Acquisition Contracts (GWACs) require a business-case analysis by the servicing agency. Subpart 17.6 (Management and Operating Contracts) governs M&O contracts for Government-owned, contractor-operated (GOCO) facilities with prohibited functions specified at 17.603 and 5-year review cycles at 17.605. Subpart 17.7 governs interagency acquisitions for DoD requiring nondefense agency compliance certification under 17.703. Subpart 17.8 (Reverse Auctions) authorises reverse auctions for clearly-defined commercial requirements with multiple offerors and prohibits use for design-build construction, architect-engineer services, sealed bidding, and personal protective equipment per NDAA limits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "key_clauses_taxonomy",
        "multi_year_thresholds",
        "option_exercise_determinations_required",
        "economy_act_d_and_f_requirements",
        "management_operating_contract_indicators",
        "reverse_auction_use_constraints",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-7-acquisition-planning",
      "us-far-part-16-types-of-contracts",
      "us-far-part-15-contracting-by-negotiation",
      "us-far-part-39-acquisition-information-technology"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-far-part-19-small-business-set-asides",
    "title": "FAR Part 19 / 48 CFR Part 19 - Small Business Programs and Set-Asides (Federal Acquisition Regulation)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 19 / 48 CFR Part 19 implements the Small Business Act (15 USC 631 et seq.) across federal agencies, establishing the framework for small business set-asides, partial set-asides, sole-source awards, subcontracting plans, and certificate-of-competency procedures; the foundational mechanism is the 'Rule of Two' at FAR 19.502-2, requiring contracting officers to set aside acquisitions for small business when there is reasonable expectation that offers will be received from at least two responsible small business concerns AND the award will be made at a fair market price; FAR Part 19 covers the 8(a) Business Development Program (FAR Subpart 19.8) for socially and economically disadvantaged small businesses, the HUBZone Program (FAR Subpart 19.13) for historically underutilized business zone concerns, the Service-Disabled Veteran-Owned Small Business (SDVOSB) Program (FAR Subpart 19.14), the Women-Owned Small Business (WOSB/EDWOSB) Program (FAR Subpart 19.15), and small business subcontracting plans (FAR Subpart 19.7); the small business programs are subject to size standards at 13 CFR Part 121 (varying by NAICS code), with SBA Office of Hearings and Appeals jurisdiction for size protests, and they intersect with the Buy American Act preferences and trade agreement waivers at FAR Part 25.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "small_business_act",
        "size_standards_implementing_regulation",
        "competition_in_contracting_act_intersection",
        "industry_mapping",
        "enforcement_anchors",
        "subcontracting_plan_threshold"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-10-usc-3201-dod-competition-requirements",
      "us-41-usc-3304-noncompetitive-procedures-exceptions"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-far-part-22-labor-laws-government-acquisitions",
    "title": "FAR Part 22 / 48 CFR Part 22 - Application of Labor Laws to Government Acquisitions",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 22 / 48 CFR Part 22 codifies the labor law requirements applicable to federal contracts and identifies the FAR clauses implementing each statute: FAR Subpart 22.1 establishes basic labor policies including labor relations and overtime compensation procedures; FAR Subpart 22.2 implements Executive Order restrictions on convict labor; FAR Subpart 22.3 implements the Contract Work Hours and Safety Standards Act (40 USC 3704) requiring overtime at 1.5x for work over 40 hours per week and basic safety standards; FAR Subpart 22.4 implements the Davis-Bacon Act (40 USC 3142) prevailing wage requirements for construction contracts exceeding USD 2,000; FAR Subpart 22.5 governs project labor agreements (PLAs) for federal construction projects; FAR Subpart 22.6 implements the Walsh-Healey Public Contracts Act (41 USC 6502) for supply contracts exceeding USD 10,000; FAR Subpart 22.8 establishes Equal Employment Opportunity (EEO) requirements; FAR Subpart 22.10 implements the Service Contract Act (41 USC 6707) for service contracts exceeding USD 2,500; FAR Subpart 22.13 protects special disabled veterans employment; FAR Subpart 22.19 implements Executive Order 14026 federal contractor minimum wage (USD 15.00/hour with annual adjustments); FAR Subpart 22.21 implements Executive Order 13706 paid sick leave for federal contractors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis_by_subpart",
        "executive_orders_implemented",
        "dol_implementing_regulations",
        "industry_mapping",
        "enforcement_anchors",
        "predecessor_contract_protections"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-40-usc-3142-davis-bacon-prevailing-wage",
      "us-41-usc-6502-walsh-healey-public-contracts-act",
      "us-41-usc-6707-service-contract-act"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-far-part-24-protection-privacy-freedom-information",
    "title": "FAR Part 24 - Protection of Privacy and Freedom of Information (Privacy Act of 1974, FOIA, Privacy Training, System of Records Operation)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Federal Acquisition Regulation (FAR) Part 24 implements two foundational information-rights statutes within federal procurement. Subpart 24.1 applies the Privacy Act of 1974 (5 USC 552a) and OMB Circular A-130 to contractors that design, develop, or operate a system of records on behalf of an agency to accomplish an agency function; contractors and their employees are 'considered employees of the agency for purposes of the criminal penalties' under FAR 24.102, meaning Privacy Act criminal sanctions (knowing and wilful unauthorised disclosure under 5 USC 552a(i)) apply to contractor personnel. Section 24.103 requires contracting officers to identify Privacy Act systems in the work statement, provide the agency's Privacy Act rules of conduct, and ensure the prescribed clauses are inserted. Section 24.104 prescribes clause 52.224-1 (Privacy Act Notification - in solicitations) and 52.224-2 (Privacy Act - in contracts) where contractor operation of a system of records is involved. Subpart 24.2 governs Freedom of Information Act (FOIA, 5 USC 552) interactions with procurement: competitive proposals are not disclosable under FOIA except when incorporated into the resulting contract; information obtained under FAR 15.403-3(b) is exempt; alternative dispute resolution communications are protected under 5 USC 574. Subpart 24.3 (Privacy Training) requires the contractor to provide initial and annual privacy training to any contractor employee who has access to a system of records, handles personally identifiable information, designs, develops, maintains, or operates a system of records, or has access to PII; clause 52.224-3 (Privacy Training, with Alternate I where agency-provided training is required) is prescribed. Training content must address Privacy Act provisions and penalties, appropriate handling and safeguarding practices, authorised use, prohibition on unauthorised disclosure, and breach response procedures per OMB breach response guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "key_clauses_taxonomy",
        "criminal_penalty_extension",
        "training_requirements_taxonomy",
        "foia_procurement_carve_outs",
        "system_of_records_indicators",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-4-administrative-information-matters",
      "us-far-part-39-acquisition-information-technology",
      "us-far-part-7-acquisition-planning",
      "us-far-part-15-contracting-by-negotiation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-far-part-25-foreign-acquisition-buy-american-trade-agreements",
    "title": "FAR Part 25 - Foreign Acquisition (Buy American Act at 41 USC chapter 83, Trade Agreements Act at 19 USC 2511-2518, Domestic Content Thresholds, FTA Partner Treatment, Iran and Sudan Sanctioned Sources)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Federal Acquisition Regulation (FAR) Part 25 implements the Buy American Act at 41 USC chapter 83, the Trade Agreements Act at 19 USC sections 2511-2518, and related foreign-source restrictions. Subpart 25.1 requires agencies to acquire only domestic end products for supply contracts above the micro-purchase threshold for use within the US, applying a two-part test: (i) article manufactured in the United States and (ii) component cost threshold of 65% domestic content during 2024-2028 increasing to 75% from 2029, with COTS items waived from the domestic content test under 41 USC 1907 except for iron and steel products. Unreasonable cost exceptions under FAR 25.106 apply price preference factors when the low offer is foreign: add 20% to the foreign offer when comparing against a large business domestic offer and 30% when comparing against a small business domestic offer. Subpart 25.2 applies the same regime to construction materials with the iron and steel rule that foreign iron and steel must constitute less than 5% of component costs; the trade agreements construction threshold is USD 6,683,000. Subpart 25.4 implements trade agreements (WTO GPA, USMCA, Australia, Chile, Korea, Colombia, Peru, Bahrain, CAFTA-DR, Israeli Trade Act, Caribbean Basin Initiative) - designated country end products receive non-discriminatory treatment when the acquisition exceeds the applicable threshold; small business set-asides, arms and ammunition, resale acquisitions, and Federal Prison Industries and AbilityOne contracts (subparts 8.6 and 8.7) are excluded from trade agreements coverage under 25.401. Subpart 25.3 covers contracts performed outside the US, including 25.302 application of 32 CFR Part 159 to contractor private security functions in areas of combat operations. Subpart 25.7 implements Treasury-administered prohibited sources: 25.701 OFAC list compliance; 25.702 Sudan business operations prohibition with contractor certification; 25.703 Iran Sanctions Act and Iran Divestment List under clauses 52.225-20 and 52.225-21; agency head waiver authority for national security or national defense purposes. Subpart 25.6 implements American Recovery and Reinvestment Act (Pub. L. 111-5) domestic construction material requirements with the iron-and-steel-must-be-US-produced rule when the construction material is wholly or predominantly iron or steel. Subpart 25.11 prescribes the clause matrix: 52.225-1 (Buy American Supplies), 52.225-3 (Buy American Free Trade Agreements), 52.225-5 (Trade Agreements), 52.225-9 / 52.225-10 / 52.225-11 / 52.225-12 (Buy American Construction Materials variants), 52.225-19 (Contractor Personnel in Designated Operational Areas), 52.225-26 (Private Security Functions Outside US), 52.225-20 and 52.225-21 (Iran sanctions representations).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "key_clauses_taxonomy",
        "domestic_content_threshold_schedule",
        "evaluation_factor_taxonomy",
        "trade_agreement_thresholds_2024",
        "trade_agreement_exclusions_under_25_401",
        "prohibited_sources_taxonomy",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-7-acquisition-planning",
      "us-far-part-15-contracting-by-negotiation",
      "us-far-part-19-small-business-set-asides",
      "us-far-part-8-required-sources-supplies-services"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-far-part-27-patents-data-copyrights",
    "title": "FAR Part 27 - Patents, Data, and Copyrights (Bayh-Dole Act at 35 USC 200-212, March-In Rights at 35 USC 203, US Manufacturing Preference at 35 USC 204, Rights in Data under 52.227-14, 28 USC 1498 Infringement Liability)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Federal Acquisition Regulation (FAR) Part 27 governs patent, data, and copyright rights in federal contracts and applies to all executive agencies for patents and copyrights (Subparts 27.2, 27.3, 27.5) and to civilian agencies for rights in data (Subpart 27.4 - DoD uses separate DFARS 252.227-7013, 7014, and 7015 rules). Subpart 27.2 addresses patent and copyright infringement liability under 28 USC 1498 (the exclusive remedy is monetary damages in the Court of Federal Claims, not injunctive relief) and prescribes clauses 52.227-1 (Authorisation and Consent), 52.227-2 (Notice and Assistance), 52.227-3 (Patent Indemnity for commercial products), and 52.227-4 (Construction Patent Indemnity). Subpart 27.3 implements the Bayh-Dole Act at 35 USC 200-212 and 37 CFR Part 401 through FAR Section 27.302. FAR 27.302(b)(1) provides that each contractor may, after required disclosure to the Government, elect to retain title to any subject invention, with five enumerated exceptions at 27.302(b)(2): (i) contractor not located in or lacking US business presence; (ii) exceptional circumstances determined by the agency; (iii) foreign intelligence or counterintelligence security needs; (iv) DOE Government-owned contractor-operated naval nuclear or weapons programs; (v) other statutory or agency regulation authorisation. Small business and nonprofit contractors retain election rights even under exception (ii) or (iii) for inventions that are not classified or are not limited from dissemination by DOE within 6 months. FAR 27.302(f) implements march-in rights under 35 USC 203 - agencies may require the contractor to grant a license to a responsible applicant only on a determination that action is necessary because of contractor failure to achieve practical application, unmet health or safety needs, unmet federal regulatory public-use requirements, or licensee breach of the US manufacturing preference. FAR 27.302(g) implements the US manufacturing preference under 35 USC 204 - no contractor shall grant an exclusive right to use or sell any subject invention in the United States unless the licensee agrees that products embodying the invention will be manufactured substantially in the United States, with agency waiver available on a showing of reasonable but unsuccessful efforts to find domestic manufacturing or commercial infeasibility. FAR 27.302(h) imposes a special obligation on nonprofit organisation contractors to use reasonable efforts to attract small business licensees. Patent clause selection is in FAR 27.303 - small business and nonprofit contractors use 52.227-11 (Patent Rights - Ownership by the Contractor); large business contractors use 52.227-13 (Patent Rights - Ownership by the Government). Subpart 27.4 (Rights in Data and Copyrights) for civilian agencies establishes three categories of Government rights through clause 52.227-14: unlimited rights (data first produced in performance, form-fit-and-function data, instructional materials), limited rights (proprietary trade-secret data developed at private expense - 52.227-14 Alternate II), and restricted rights computer software (commercial software developed at private expense - 52.227-14 Alternate III). FAR 27.404-5 governs marking remedies: data without proper notice is presumed unlimited rights; the Government may cancel or ignore unauthorised markings after a 60-day contractor response period; contractors may request to add omitted notices within 6 months on a demonstration that the omission was inadvertent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "key_clauses_taxonomy",
        "bayh_dole_contractor_categories",
        "far_27_302_g_manufacturing_preference_text",
        "far_27_302_f_march_in_grounds",
        "government_rights_taxonomy_data",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-7-acquisition-planning",
      "us-far-part-15-contracting-by-negotiation",
      "us-far-part-19-small-business-set-asides",
      "us-far-part-39-acquisition-information-technology"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-far-part-31-contract-cost-principles",
    "title": "FAR Part 31 - Contract Cost Principles and Procedures (Allowability, Reasonableness, Allocability)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 31 establishes the cost principles governing allowability of contractor costs charged to federal contracts: Subpart 31.2 (Contracts with Commercial Organizations) sets the foundational five-part allowability test at 31.201-2 (reasonableness, allocability, Cost Accounting Standards or GAAP compliance, terms of the contract, limitations set forth in the subpart); 31.201-3 establishes that a cost is reasonable only if it does not exceed that which would be incurred by a prudent person in the conduct of competitive business with the contractor bearing the burden of proof (no presumption of reasonableness exists for contested costs); 31.201-4 defines allocability as costs incurred specifically for the contract or that benefit both the contract and other work; 31.202 governs direct cost charging (must charge specifically with limited de minimis exception for consistency); 31.203 governs indirect cost pools and allocation bases that distribute on benefits-accruing basis; 31.205-1 through 31.205-52 enumerate specific unallowable cost categories including 31.205-1 (public relations and advertising), 31.205-6 (compensation - reasonableness ceilings, executive compensation cap, stock options), 31.205-22 (lobbying - absolutely unallowable), 31.205-37 (royalties - allowable only if not contractor-owned), 31.205-47 (legal costs - generally allowable except costs of defending against Government enforcement actions when contractor adverse to Government). Subpart 31.1 governs educational and nonprofit institutions (cross-reference to 2 CFR Part 200 Uniform Guidance).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "five_part_allowability_test",
        "industry_mapping",
        "executive_compensation_cap",
        "penalty_for_unallowable_costs",
        "audit_chain"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-15-contracting-by-negotiation",
      "us-far-part-16-types-of-contracts",
      "us-41-usc-4304-specific-costs-not-allowable",
      "us-far-part-42-contract-administration-audit"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-32-contract-financing",
    "title": "FAR Part 32 - Contract Financing (Progress Payments, Performance-Based Payments, Prompt Payment Act)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 32 governs federal contract financing including progress payments, performance-based payments, advance payments, commercial item financing, and the Prompt Payment Act: Subpart 32.1 (General) requires contracting officers to provide financing only as needed and monitor contractor use and financial status; Subpart 32.2 (Commercial Product and Commercial Service Purchase Financing) limits commercial advance payments to 15% of contract price before performance and requires adequate security under 32.202-4; Subpart 32.4 (Advance Payments for Non-Commercial Items) requires determination by head of contracting activity; Subpart 32.5 (Progress Payments Based on Costs) allows progress payments at standard rates (currently 80% for non-small business, 85% for small business) computed on incurred costs less progress payments to subcontractors; Subpart 32.10 (Performance-Based Payments) is the preferred method for non-commercial fixed-price contracts where payments are tied to performance events or milestones; Subpart 32.11 (Electronic Funds Transfer) mandates EFT for contractor payments under 31 USC 3332; Subpart 32.9 implements the Prompt Payment Act (31 USC chapter 39) requiring payment within 30 days of proper invoice receipt (7 days for fast-pay) with interest penalty on late payments under 5 CFR Part 1315.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "financing_method_order_of_preference",
        "industry_mapping",
        "progress_payment_mechanics",
        "prompt_payment_compliance",
        "subcontractor_payment_protection"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-15-contracting-by-negotiation",
      "us-far-part-16-types-of-contracts",
      "us-31-usc-1341-antideficiency-act",
      "us-40-usc-3131-miller-act-federal-construction-bonds"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-33-protests-disputes-appeals",
    "title": "FAR Part 33 - Protests, Disputes, and Appeals (Agency Protests, GAO, COFC, Contract Disputes Act)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 33 governs three protest forums and the Contract Disputes Act framework: Subpart 33.1 covers protests including agency-level protests under 33.103 (filing within 10 days of basis known with continued performance restricted absent written justification above the contracting officer level), GAO protests under 33.104 (10-day post-award or 5-day post-debriefing window triggers automatic stay of performance under 31 USC 3553(d), 100-day GAO decision deadline or 65 days under express option, 1-day requirement for the protester to furnish a complete protest copy to the contracting officer), and Court of Federal Claims protests under 33.105 (procedures per court rules); Subpart 33.2 covers disputes under the Contract Disputes Act (41 USC chapter 71): contracting officer's written decision under 33.211 must include description of the claim, statement of decision with supporting rationale, decisions on claims at or below USD 100,000 due within 60 days of request, larger claims within 60 days of contractor certification or with date by which decision will be issued; mandatory disputes clause 52.233-1 inserted via 33.215 in all solicitations and contracts unless exception applies. The contracting officer must immediately suspend contract performance pending GAO resolution unless written findings under 33.104(c)(2) justify continued performance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "three_protest_forums",
        "industry_mapping",
        "stay_of_performance",
        "claim_certification",
        "appeal_chain"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-6-competition-requirements",
      "us-31-usc-3553-gao-bid-protest-review",
      "us-far-part-15-contracting-by-negotiation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-36-construction-architect-engineer-contracts",
    "title": "FAR Part 36 - Construction and Architect-Engineer Contracts (Including Qualifications-Based Selection)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 36 prescribes specialised acquisition procedures for federal construction and architect-engineer (A-E) contracts that modify the standard FAR competition framework: Subpart 36.1 establishes general provisions including 36.201 (past performance evaluation per 42.1502(e) for construction contracts) and 36.204 (solicitations must state project magnitude using physical characteristics and price ranges such as USD 25,000 to USD 100,000 without disclosing the Government estimate); Subpart 36.2 contains special procedures for sealed bidding in construction (presolicitation notices for projects exceeding the simplified acquisition threshold, sufficient bid preparation time, written notices of award); Subpart 36.3 governs two-phase design-build selection procedures - the contracting officer must determine appropriateness under 36.301 considering anticipated competition (3+ offers), design expense, project definition adequacy, schedule constraints, contractor capability, and agency capacity to manage; Subpart 36.6 implements the qualifications-based selection (QBS) mandate of the Brooks Act (40 USC chapter 11) for architect-engineer services - 36.601 requires public announcement of A-E requirements and selection based on demonstrated competence and qualifications at fair and reasonable prices (this constitutes a competitive procedure under FAR 6.102(d)(1)), 36.602 requires evaluation boards to assess firms on professional qualifications, specialised experience, capacity, past performance, and geographic location, holding discussions with at least three highly qualified firms regarding concepts and alternative methods. Negotiations proceed in order of board preference.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "two_phase_design_build_test",
        "qualifications_based_selection",
        "industry_mapping",
        "bond_requirements",
        "labor_standards_chain"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-40-usc-3142-davis-bacon-prevailing-wage",
      "us-40-usc-3131-miller-act-federal-construction-bonds",
      "us-far-part-6-competition-requirements",
      "us-far-part-14-sealed-bidding"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-39-acquisition-information-technology",
    "title": "FAR Part 39 - Acquisition of Information Technology (Modular Contracting, Section 508 ICT Accessibility, IT Security, Privacy)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Federal Acquisition Regulation (FAR) Part 39 governs federal acquisition of information technology and information and communication technology (ICT), excluding national security systems under 40 USC 11302. Subpart 39.1 (General) requires agencies to identify IT requirements considering security, privacy, accessibility, energy efficiency, NIST common security configurations, and IPv6 compliance under 11.002(g); incorporates supply chain prohibitions on Kaspersky Lab products (4.2002), covered telecommunications equipment under subpart 4.21 (Section 889 NDAA FY2019), covered applications including TikTok (4.2202), and FASCSA-covered articles (4.2303). Section 39.103 requires modular contracting under 41 USC 2308 for major IT systems to the maximum extent practicable, with each increment independently manageable; award is required within 180 days of solicitation issuance and deliveries within 18 months. Section 39.105 requires contracts for system-of-records design and development to include agency rules of conduct, threat and hazard descriptions, required safeguards, and Government inspection program requirements under the Privacy Act 5 USC 552a. Section 39.106 mandates inclusion of clause 52.239-1 (Privacy or Security Safeguards) in solicitations and contracts requiring IT security or system-of-records operations. Subpart 39.2 (ICT) implements Section 508 of the Rehabilitation Act under 29 USC 794d and 36 CFR 1194.1, requiring ICT supplies and services to meet ICT accessibility standards unless an exception (39.204 - national security systems, incidental contract items, maintenance spaces) or exemption (39.205 - undue burden, fundamental alteration, commercial nonavailability) applies. Exemptions require written justification and alternative means of access for individuals with disabilities. Indefinite-quantity contracts identify compliant items and exemption documentation at the contract level; task and delivery orders document exceptions and exemptions at issuance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "supply_chain_prohibitions",
        "section_508_standards_reference",
        "modular_contracting_thresholds",
        "ict_exception_categories",
        "ict_exemption_grounds",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-7-acquisition-planning",
      "us-far-part-11-describing-agency-needs",
      "us-far-part-15-contracting-by-negotiation",
      "us-far-part-16-types-of-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-far-part-4-administrative-information-matters",
    "title": "FAR Part 4 - Administrative and Information Matters (SAM, FPDS, FFATA, Classified Info, CUI/NIST SP 800-171, Section 889 Covered Telecom, FASCSA Orders, Kaspersky and TikTok Prohibitions)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Federal Acquisition Regulation (FAR) Part 4 governs administrative aspects of contract execution, distribution, reporting, retention, and security prohibitions across federal procurements. Subpart 4.4 (Safeguarding Classified Information Within Industry) implements Executive Orders 12829 and 10865 under the National Industrial Security Program Operating Manual (NISPOM) at 32 CFR Part 117, requires DD Form 254 (Contract Security Classification Specification) for any classified contract, and mandates inclusion of clause 52.204-2 (Security Requirements) when access to classified information is required. Subpart 4.6 (Contract Reporting) implements the Federal Funding Accountability and Transparency Act (FFATA, Pub. L. 109-282) requiring contract action reports (CARs) to be completed in the Federal Procurement Data System (FPDS) within 3 business days after award (30 days for FAR 6.302-2 actions). Subpart 4.11 (System for Award Management) requires contractor SAM registration before award; Subpart 4.13 requires acquisition of NIST-approved Personal Identity Verification (PIV) products and services; Subpart 4.14 implements FFATA executive compensation and first-tier subcontract award reporting (FSRS). Subpart 4.19 (Basic Safeguarding of Covered Contractor Information Systems) and clause 52.204-21 require contractors handling Federal Contract Information (FCI) to implement the 15 basic safeguarding controls; broader Controlled Unclassified Information (CUI) handling is governed by NIST SP 800-171 incorporated through agency-specific clauses including DFARS 252.204-7012 and the FAR Council CUI rule. Subpart 4.21 implements Section 889 of the NDAA FY2019 prohibiting agencies from procuring or using covered telecommunications equipment or services from Huawei, ZTE, Hytera, Hikvision, and Dahua and from contracting with entities that use such equipment in any system, with clauses 52.204-24, 52.204-25, and 52.204-26. Subpart 4.20 prohibits Kaspersky Lab products with clause 52.204-23; Subpart 4.22 prohibits the TikTok application and other ByteDance-covered applications on contractor systems. Subpart 4.23 implements Federal Acquisition Security Council Supply Chain Risk Management (FASCSA) orders requiring contracting officers to review and apply exclusion orders before award, with clauses 52.204-27 and 52.204-30, and agency head authorisation required for any waiver.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "key_clauses_taxonomy",
        "section_889_scope",
        "cui_safeguarding_scope",
        "fascsa_order_process",
        "fpds_reporting_thresholds",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-7-acquisition-planning",
      "us-far-part-15-contracting-by-negotiation",
      "us-far-part-19-small-business-set-asides",
      "us-far-part-39-acquisition-information-technology"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-far-part-42-contract-administration-audit",
    "title": "FAR Part 42 - Contract Administration and Audit Services (CAO, DCAA, Indirect Cost Rates, CPARS)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 42 governs contract administration and audit services post-award: Subpart 42.1 designates the Defense Contract Audit Agency (DCAA) as the cognisant audit office for non-educational contractors with other agencies assuming cognisance by mutual agreement; Subpart 42.3 establishes contract administration offices (CAOs) with delegated authority for mandatory and optional functions under 42.302 - mandatory CAO functions include negotiating forward pricing rate agreements, establishing final indirect cost rates for qualifying contractors, determining Cost Accounting Standards adequacy, and determining accounting system adequacy; Subpart 42.5 prescribes postaward orientation - conference or letter format determined by contract complexity, value, and contractor experience, conducted promptly after award without altering negotiated terms; Subpart 42.7 governs indirect cost rates - DCAA audits indirect cost proposals (contractor submits within 6 months of fiscal year end), advance agreements under 31.109 establish cost treatment, billing rates are revised by mutual agreement or unilaterally by contracting officer when agreement cannot be reached, final indirect cost rates are determined by contracting officer for corporate entities or auditor for smaller business units; Subpart 42.13 covers suspension of work, stop-work orders, and Government delay of work with cost consequences flowing to the contractor under standard clauses; Subpart 42.15 implements CPARS (Contractor Performance Assessment Reporting System) under 42.1502 requiring performance evaluations on contracts and orders over USD 1,000,000 (lower for some agencies) submitted within 120 days of contract completion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "cao_function_taxonomy",
        "industry_mapping",
        "indirect_cost_rate_process",
        "cpars_thresholds",
        "suspension_and_stop_work"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-15-contracting-by-negotiation",
      "us-far-part-31-contract-cost-principles",
      "us-far-part-33-protests-disputes-appeals",
      "us-far-part-16-types-of-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-43-contract-modifications",
    "title": "FAR Part 43 - Contract Modifications (Bilateral, Unilateral, Change Orders, Constructive Changes)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 43 governs modifications to federal contracts and prescribes the only authorities by which the Government may alter a contract: Subpart 43.1 defines bilateral modifications (signed by both contractor and contracting officer - used for negotiated equitable adjustments, definitization of letter contracts, and other agreements) and unilateral modifications (signed only by contracting officer - used for administrative changes, change orders, and other authorised modifications); FAR 43.102 establishes that only contracting officers with proper authority may execute contract modifications - other Government personnel must not direct contractors to perform work requiring a modification (preventing the constructive change doctrine from being weaponised by uncoordinated agency personnel); 43.103 categorises modifications and 43.201 prescribes change order authority through the standard Changes clauses (52.243-1 fixed-price supplies, 52.243-2 cost-reimbursement, 52.243-3 time-and-materials, 52.243-4 construction with consolidated change procedures); 43.204 requires the contracting officer to negotiate equitable adjustments in the shortest practicable time considering segregable costs and including complete releases to prevent future disputes; 43.205 prescribes the mandatory changes clauses; 43.301 mandates Standard Form 30 (SF 30) for solicitation amendments, change orders, unilateral contract modifications, administrative changes, supplemental agreements, and fund adjustments. Constructive changes - actions by Government personnel that direct work beyond contract scope without a formal modification - give rise to constructive change claims under the Changes clause.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "modification_types_42.103",
        "industry_mapping",
        "constructive_change_doctrine",
        "changes_clause_taxonomy",
        "equitable_adjustment_components"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-33-protests-disputes-appeals",
      "us-far-part-15-contracting-by-negotiation",
      "us-far-part-49-termination-of-contracts",
      "us-far-part-42-contract-administration-audit"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-44-subcontracting-policies",
    "title": "FAR Part 44 - Subcontracting Policies and Procedures (Consent, CPSR, Make-or-Buy, Commercial Subcontracts)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 44 governs prime contractor subcontracting under federal contracts: Subpart 44.2 (Consent to Subcontracts) requires contracting officer consent under FAR 52.244-2 for subcontracts above the simplified acquisition threshold or 5% of total contract value in cost-reimbursement contracts where the contractor has not received an approved purchasing system; contractors with approved purchasing systems need consent only for subcontracts specifically identified by the contracting officer; the contracting officer evaluates consent requests against criteria in 44.202 including compliance with make-or-buy programs, technical justification, small business requirements, price competition adequacy, subcontractor responsibility, cost analysis, and contract type appropriateness; Subpart 44.3 (Contractor Purchasing System Reviews - CPSR) establishes the CPSR threshold at USD 25 million in annual Government sales (excluding firm-fixed-price commercial item contracts), with reviews conducted at least every three years to determine whether the contractor's purchasing system is adequate to protect Government interests; Subpart 44.4 (Make-or-Buy Programs) requires prime contractors to develop make-or-buy programs for solicitations expected to exceed USD 13.5 million (FAR 44.402), identifying items to be made in-house versus bought from subcontractors with justification; Subpart 44.5 (Subcontracts for Commercial Products or Services) limits required clauses in commercial subcontracts to those required by law or consistent with customary commercial practice.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "consent_thresholds",
        "industry_mapping",
        "cpsr_scope_evaluation",
        "approved_purchasing_system_benefits",
        "commercial_subcontract_clause_limits"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-15-contracting-by-negotiation",
      "us-far-part-12-commercial-products-services",
      "us-far-part-19-small-business-set-asides",
      "us-far-part-42-contract-administration-audit"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-45-government-property",
    "title": "FAR Part 45 - Government Property (Contractor Stewardship of Government-Furnished and Contractor-Acquired Property)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 45 governs Government property in the contractor's possession including Government-furnished property (GFP) provided to the contractor and contractor-acquired property (CAP) titled to the Government: Subpart 45.1 (General) provides definitions and establishes the policy at 45.102 that contracting officers shall provide Government property only when clearly demonstrated to be in the Government's best interest and the overall benefit significantly outweighs increased administration cost; 45.103 requires contractors to use Government property already in their possession to the maximum extent practical and eliminate competitive advantage; 45.104 establishes that contractors are generally not liable for loss of Government property under cost-reimbursement, time-and-materials, or labor-hour contracts unless the contracting officer revokes the assumption of risk due to non-compliant property management practices; 45.106 governs transferring accountability between contracts requiring firm requirements and documentation; 45.107 prescribes the mandatory clause FAR 52.245-1 (Government Property) inserted in solicitations involving GFP or CAP; Subpart 45.2 governs solicitation and contract requirements including item descriptions, quantities, unit acquisition costs, and as-is condition disclosure; the contractor's property management system must be compliant under voluntary consensus standards (typically ASTM E2132 or similar) and is subject to property management system reviews. The clause flows down to subcontractors and applies through contract closeout.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "property_categories",
        "industry_mapping",
        "standard_clause_obligations",
        "liability_default",
        "property_management_standards",
        "subcontract_flow_down"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-31-contract-cost-principles",
      "us-far-part-42-contract-administration-audit",
      "us-far-part-44-subcontracting-policies",
      "us-far-part-16-types-of-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-47-transportation",
    "title": "FAR Part 47 - Transportation (Federal Acquisition Service, Cargo Preference, Government Bills of Lading)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 47 governs federal transportation acquisitions and the transportation aspects of supply contracts: Subpart 47.1 (General) requires agencies to authorise domestic shipments on commercial bills of lading (CBLs) and obtain traffic management advice from the Federal Acquisition Service; commercial carriers are preferred unless specific conditions apply; Subpart 47.2 (Contracts for Transportation or for Transportation-Related Services) prescribes solicitation procedures and contract requirements for freight transportation, household goods, and transportation-related services; Subpart 47.3 (Transportation in Supply Contracts) addresses how transportation factors are applied in supply acquisitions including f.o.b. delivery terms (origin or destination) which determine when title transfers, who bears transportation cost, and who bears risk of loss in transit; FAR 47.104 establishes the Section 1062 of the Energy Independence and Security Act for Government rate tenders under 49 USC 10721 (rail) and 13712 (water) providing reduced rates in non-contiguous domestic trade; Subpart 47.5 (Ocean Transportation by US-Flag Vessels) implements the Cargo Preference Act of 1954 (46 USC 55305) requiring at least 50% of Government-impelled cargo to be carried on privately-owned US-flag commercial vessels where available; the Federal Maritime Commission has jurisdiction over ocean carriage and tariffs. Transportation acquisition planning under 47.105 considers all transportation costs as part of total Government cost.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "fob_terms_taxonomy",
        "industry_mapping",
        "cargo_preference_thresholds",
        "rate_tender_authorities",
        "shipping_documentation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-12-commercial-products-services",
      "us-far-part-15-contracting-by-negotiation",
      "us-far-part-44-subcontracting-policies"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-49-termination-of-contracts",
    "title": "FAR Part 49 - Termination of Contracts (Convenience, Default, and Settlement)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 49 governs the termination of federal contracts for the convenience of the Government or for contractor default and prescribes the settlement framework: Subpart 49.1 (General Principles) requires contracting officers to terminate only when in the Government's interest, prefer no-cost settlements where feasible, avoid unnecessary terminations of contracts under USD 5,000, ensure timely settlements particularly for small businesses, and issue written notices of termination under 49.102 stating the basis, effective date, extent of termination, special instructions, and steps to minimize impact on personnel; the Termination Contracting Officer (TCO) under 49.105 must examine settlement proposals, negotiate promptly, hold conferences with contractors to establish definite settlement programs, and address general settlement principles and accounting practices; Subpart 49.2 (Convenience Termination of Fixed-Price Contracts) and 49.3 (Convenience Termination of Cost-Reimbursement Contracts) govern T4C settlements which compensate the contractor fairly for work done with reasonable allowance for profit, treating fair compensation as business judgment rather than rigid accounting; Subpart 49.4 (Default) prescribes default termination procedures for fixed-price (49.402) and cost-reimbursement (49.403) contracts with mandatory show-cause notices and findings of fact; Subpart 49.5 contains the standard termination clauses (52.249-1 through 52.249-14) inserted under 49.5 based on contract type and termination type. Termination decisions create complex audit and reprocurement exposure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "termination_types",
        "industry_mapping",
        "settlement_framework",
        "default_grounds",
        "appeal_chain"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-33-protests-disputes-appeals",
      "us-far-part-15-contracting-by-negotiation",
      "us-far-part-16-types-of-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-far-part-6-competition-requirements",
    "title": "FAR Part 6 - Competition Requirements (Full and Open Competition Framework)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Federal Acquisition Regulation (FAR) Part 6 implements the Competition in Contracting Act (41 USC 3301) by establishing the procedural framework for federal procurement competition: Subpart 6.1 requires full and open competition as the default through sealed bids, competitive proposals, architect-engineer selection, or other competitive procedures; Subpart 6.2 permits restricting competition to specific source categories (small business, 8(a), HUBZone, SDVOSB, women-owned, disaster relief) while preserving competitive procedures; Subpart 6.3 authorises seven enumerated exceptions to full and open competition (only one responsible source, unusual urgency, industrial mobilization, international agreement, statute, national security, public interest) each requiring written justification and tiered approval based on dollar value; Subpart 6.4 sets criteria for selecting between sealed bidding and competitive proposals. Contracting officers must document the competition method selected and justify any deviation, with approval levels escalating from contracting officer (under USD 900,000) to senior procurement executive (over USD 90 million, USD 150 million for DoD).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "exceptions_chain",
        "industry_mapping",
        "set_aside_authorities",
        "approval_tiering",
        "bid_protest_remedies"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-41-usc-3301-full-open-competition-federal-procurement",
      "us-41-usc-3304-noncompetitive-procedures-exceptions",
      "us-31-usc-3553-gao-bid-protest-review",
      "us-far-part-19-small-business-set-asides"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-far-part-7-acquisition-planning",
    "title": "FAR Part 7 / 48 CFR Part 7 - Acquisition Planning",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Federal Acquisition Regulation (FAR) Part 7 / 48 CFR Part 7 establishes federal acquisition planning procedures across five subparts: 7.1 Acquisition Plans (written plans for major acquisitions per 7.105 enumerated contents); 7.2 Planning for the Purchase of Supplies in Economic Quantities; 7.3 Contractor Versus Government Performance (implementing OMB Circular A-76 public-private competition framework); 7.4 Equipment Lease or Purchase (lease-versus-purchase analysis under 7.401); 7.5 Inherently Governmental Functions (prohibition on contractor performance of inherently governmental functions per 7.503(a), defined in OMB Policy Letter 11-01 and FAR 2.101). FAR 7.102 requires agencies to perform acquisition planning and conduct market research to promote and provide for commercial products and full and open competition; FAR 7.103 enumerates agency head responsibilities including issuing implementing instructions, providing for training in market research and acquisition planning, and establishing agency procedures. FAR 7.104(a) requires acquisition planning begin 'as soon as the agency need is identified, preferably well in advance' of contract award. FAR 7.105 establishes 30+ enumerated written plan contents including statement of need, applicable conditions, cost, capability or performance, delivery requirements, trade-offs, risks, acquisition streamlining, sources, competition, source-selection procedures, contract type, contracting considerations, budgeting and funding, product or service descriptions, priorities allocations and allotments, contractor versus government performance, management information requirements, make or buy considerations, test and evaluation, logistics considerations, government-furnished property, government-furnished information, environmental and energy conservation objectives, security considerations, and contract administration. FAR 7.500-503 defines Inherently Governmental Functions as those 'so intimately related to the public interest as to mandate performance by Government employees' including binding the United States to take or not to take action, determining policy of the United States, determining priorities for use of federal property, and conducting criminal investigations - performance of these functions by contractor is prohibited.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "related_far_parts",
        "inherently_governmental_doctrine",
        "industry_mapping",
        "enforcement_anchors",
        "consolidation_and_bundling_section_7_107",
        "telecommuting_provisions_section_7_108"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-6-competition-requirements",
      "us-far-part-12-commercial-products-services",
      "us-41-usc-3301-full-open-competition-federal-procurement"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-far-part-8-required-sources-supplies-services",
    "title": "FAR Part 8 - Required Sources of Supplies and Services (Mandatory Source Priority Order, Federal Prison Industries / UNICOR, AbilityOne Procurement List, Federal Supply Schedules / GSA MAS, BPA Limitations)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Federal Acquisition Regulation (FAR) Part 8 establishes a hierarchical priority order of mandatory and preferred sources of supplies and services for federal acquisitions. FAR 8.002(a)(1) sets the mandatory priority for supplies in descending order: (i) agency inventories; (ii) excess from other agencies via the GSAXcess surplus property system; (iii) Federal Prison Industries (FPI / UNICOR) for comparable items; (iv) Procurement List items from AbilityOne nonprofit agencies serving blind and severely disabled workers; (v) wholesale supply sources including GSA Stock Programs, Defense Logistics Agency, VA, and military inventory control points. For services under 8.002(a)(2), only the AbilityOne Procurement List qualifies as a mandatory source; other sources are discretionary. Subpart 8.6 governs Federal Prison Industries acquisitions under 18 USC 4124 - FAR 8.602 requires market research to determine whether the FPI item is comparable to private-sector supplies in price, quality, and time of delivery; if comparable, the agency must purchase from FPI unless a waiver is obtained; if not comparable, the agency must include FPI in the competitive solicitation and consider a timely FPI offer. Subpart 8.7 governs AbilityOne acquisitions under 41 USC chapter 85 (the Javits-Wagner-O'Day Act) - the Committee for Purchase from People Who Are Blind or Severely Disabled maintains the Procurement List and items on the list are mandatory sources for federal agencies. Subpart 8.4 governs Federal Supply Schedules (also known as GSA Schedules or Multiple Award Schedule / MAS): under 8.404(a) BPAs and orders placed against a MAS are considered to be issued using full and open competition; under 8.404(d) GSA has already determined that schedule prices for supplies and fixed-price services are fair and reasonable. FAR 8.405 ordering procedures: at or below micro-purchase threshold, the ordering activity may purchase from any qualified schedule contractor; between micro-purchase and the simplified acquisition threshold, the ordering activity must consider at least three schedule contractors; above the simplified acquisition threshold, a competitive RFQ posted on GSA eBuy is required with consideration of at least three contractors. FAR 8.405-2 requires Statements of Work for schedule services with performance-based requirements to the maximum extent practicable and a stated preference for firm-fixed-price orders. FAR 8.405-3 governs Blanket Purchase Agreements (BPAs) with a multiple-award preference; single-award BPAs exceeding USD 150 million require agency head written determination; multiple-award BPAs are generally limited to 5 years and single-award BPAs to a 1-year base plus four 1-year options; annual review is required under 8.405-3(e)(1). FAR 8.405-6 limits sources only on a written justification of an urgent and compelling need, sole-source capability for unique or highly specialised supplies, or a logical follow-on to a properly-competed original schedule order; justifications above the simplified acquisition threshold must be posted at SAM.gov within 14 days (or 30 days for urgent situations) for a minimum 30-day period, with approval authority graduated by dollar value up to a non-delegable senior procurement executive determination above USD 90 million.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "far_8_002_mandatory_supplies_priority",
        "far_8_002_mandatory_services_priority",
        "fpi_unicor_purchase_decision_taxonomy",
        "abilityone_procurement_list_authority",
        "gsa_mas_ordering_thresholds",
        "far_8_405_3_bpa_constraints",
        "far_8_405_6_limited_sources_approval",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-7-acquisition-planning",
      "us-far-part-13-simplified-acquisition-procedures",
      "us-far-part-15-contracting-by-negotiation",
      "us-far-part-19-small-business-set-asides"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-far-part-9-contractor-qualifications",
    "title": "FAR Part 9 / 48 CFR Part 9 - Contractor Qualifications",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-02",
    "bluf": "Federal Acquisition Regulation (FAR) Part 9 / 48 CFR Part 9 establishes the framework for determining contractor responsibility and managing related qualifications across five subparts: 9.1 Responsible Prospective Contractors (substantive responsibility determination criteria); 9.4 Debarment, Suspension, and Ineligibility (system for excluding non-responsible contractors from federal contracting via FAPIIS and SAM exclusions); 9.5 Organizational and Consultant Conflicts of Interest (preventing actual or apparent conflicts that could compromise procurement integrity); 9.6 Contractor Team Arrangements (joint ventures, prime/subcontractor teaming); 9.7 Defense Production Pools and Research and Development Pools. FAR 9.103 requires that 'No purchase or award shall be made unless the contracting officer makes an affirmative determination of responsibility' - the foundational requirement that contracting officers cannot award contracts to non-responsible offerors. FAR 9.104-1 enumerates seven responsibility criteria: (1) adequate financial resources or ability to obtain them; (2) ability to comply with required/proposed delivery or performance schedule considering existing commercial and government commitments; (3) satisfactory performance record (lack of relevant past performance cannot be sole basis for rejection); (4) satisfactory record of integrity and business ethics; (5) necessary organization, experience, accounting and operational controls, and technical capability; (6) necessary production, construction, and technical equipment and facilities; (7) be otherwise qualified and eligible to receive an award under applicable laws and regulations including age requirements, citizenship requirements, security clearance requirements, and parallel statutory eligibility. FAR 9.4 establishes the federal debarment and suspension system - the System for Award Management (SAM) Exclusions database lists excluded entities; debarment under FAR 9.406 typically 3 years for serious violations; suspension under FAR 9.407 pending investigation; FAPIIS Federal Awardee Performance and Integrity Information System captures performance and integrity data. FAR 9.5 Organizational Conflicts of Interest (OCI) regulates impaired objectivity, unequal access to information, and biased ground rules conflicts; the SAIC v United States and FAR 9.5 case law establishes the operational framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "fapiis_sam_exclusions",
        "oci_framework_far_9_5",
        "industry_mapping",
        "enforcement_anchors",
        "constitutional_doctrine",
        "section_9_104_3_subcontractor_responsibility"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-far-part-7-acquisition-planning",
      "us-far-part-15-contracting-by-negotiation",
      "us-41-usc-3301-full-open-competition-federal-procurement"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fara-foreign-agents-registration-act-22-usc-611",
    "title": "Foreign Agents Registration Act - 22 USC 611",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 611 of title 22 of the United States Code, the definitional core of the Foreign Agents Registration Act (FARA) originally enacted in 1938 (Public Law 75-583) and substantially amended through the FARA Amendments Act of 1995 and subsequent amendments, requires agents of foreign principals to register with the Department of Justice and to publicly disclose their activities. Section 611 defines foreign principal to include governments of foreign countries, foreign political parties, persons outside the United States (with US person and entity exceptions), and partnerships, associations, corporations, or organisations organised under the laws of or having the principal place of business in a foreign country. Section 611 defines agent of a foreign principal broadly to capture persons acting at the order, request, or under the direction or control of a foreign principal who engage within the United States in political activities, act as public relations counsel, publicity agent, information-service employee, or political consultant, solicit or handle contributions, or represent foreign interests before US government agencies. Section 612 requires registration with detailed disclosure including identity, financial relationship, activities, and any propaganda disseminated. Section 614 requires informational materials disseminated to be labelled. Section 615 requires public availability of registration statements. Section 618 prescribes criminal penalties up to 5 years imprisonment and 10,000 USD fine. The FARA framework is administered by the FARA Unit in the DOJ National Security Division and is the principal US framework for foreign influence transparency, increasingly applied to influence operations involving AI-generated content and social media.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-lobbying-disclosure-act-2-usc-ch26"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-farmer-direct-marketing-act",
    "title": "US Farmer-to-Consumer Direct Marketing Act (7 USC ch 63): Direct Marketing and Farmers' Markets",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Farmer-to-Consumer Direct Marketing Act of 1976 (7 U.S.C. ch. 63, sections 3001 to 3007) promotes the development and expansion of direct marketing of agricultural commodities from farmers to consumers and is administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 3001 states the congressional purpose of promoting, through appropriate means and on an economically sustainable basis, the development and expansion of direct marketing of agricultural commodities from farmers to consumers. Section 3002 defines direct marketing to include sales by farmers to consumers through roadside stands, city markets, and vehicles and similar means. Section 3003 directs the Secretary to provide an annual survey of existing methods of direct marketing. Section 3004 provides that funds appropriated to carry out the chapter be utilized by State departments of agriculture to develop and expand direct marketing within the States. Section 3007 establishes the seniors farmers' market nutrition program, with funding of 20,600,000 dollars for each of fiscal years 2008 through 2023, to provide low-income seniors with access to locally grown produce through farmers' markets, roadside stands, and community supported agriculture programs. The Act is the federal legal basis for farmers' markets and direct producer-to-consumer sales.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-farmland-protection-policy-act",
    "title": "US Farmland Protection Policy Act (7 USC ch 73): Minimizing Federal Conversion of Farmland",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Farmland Protection Policy Act (7 U.S.C. ch. 73, sections 4201 to 4209) is a United States statute whose purpose is to minimize the extent to which federal programs contribute to the unnecessary and irreversible conversion of farmland to nonagricultural uses, administered by the Secretary of Agriculture through the Natural Resources Conservation Service. Section 4201 sets out the general provisions and purpose and defines farmland to include prime farmland, unique farmland, and farmland of statewide or local importance. Section 4202 directs the Secretary to develop criteria for identifying the effects of federal programs on the conversion of farmland and requires federal agencies, to the extent practicable, to use those criteria to identify and take into account the adverse effects of their programs on the preservation of farmland and to consider alternative actions that could lessen those effects. Section 4203 provides for review of existing federal policies and procedures, section 4204 for technical assistance, section 4205 for farmland resource information, and section 4206 for grants and contracts. Section 4207 imposes a reporting requirement to Congress, and sections 4208 and 4209 set limitations and provide that the chapter creates no private right of action and does not authorize federal regulation of land use. The Act is the principal federal policy instrument for protecting agricultural land from conversion driven by federal programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fasa-1994-federal-acquisition-streamlining-pl-103-355",
    "title": "US Federal Acquisition Streamlining Act of 1994 (Public Law 103-355) - Simplified Acquisition and Commercial Items Procurement",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Federal Acquisition Streamlining Act of 1994 substantially restructured federal procurement law by raising the simplified acquisition threshold to one hundred thousand dollars, creating a preference for commercial item procurement under FAR Part 12 and limiting custom government clauses for commercial items, mandating use of past performance information in source selection, establishing electronic commerce in federal contracting through the Federal Acquisition Computer Network, requiring agency development of contract performance measures, and modernising small business participation in procurement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-small-business-act-15-usc-631",
      "us-federal-property-administrative-services-act-40-usc-101"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fast-act-2015-pl-114-94",
    "title": "Fixing America's Surface Transportation Act 2015 (FAST Act) - Public Law 114-94",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Fixing America's Surface Transportation Act of 2015 (FAST Act, Public Law 114-94, enacted 4 December 2015) was the first long-term surface-transportation authorisation in over a decade, providing approximately 305 billion USD over 5 fiscal years for federal highway, transit, rail, motor carrier safety, hazardous materials, and freight programs. Title I (Federal-Aid Highways) reauthorised the Federal Highway Administration including the National Highway Performance Program, Surface Transportation Block Grant Program, Highway Safety Improvement Program, and Congestion Mitigation and Air Quality Improvement Program. Title II (Innovative Project Finance) expanded TIFIA loans and Build America Bureau. Title III (Public Transportation) reauthorised the Federal Transit Administration. Title IV (Highway and Motor Vehicle Safety) reauthorised NHTSA including new defect notification, recall, and rental car safety provisions. Title V (Motor Carrier Safety) reauthorised FMCSA including drug and alcohol clearinghouse establishment. Title VI (Innovation) included expanded autonomous vehicle research, automated vehicle initiatives, and Smart Cities Challenge framework. Title VII (Hazardous Materials Transportation) extended PHMSA authorities. Title VIII (Multimodal Freight Transportation) established the National Multimodal Freight Policy and freight investment programs. Title XI (Surface Transportation Reauthorization Reform) addressed Bureau of Reclamation, U.S. Coast Guard, and certain financial regulatory amendments (including Federal Reserve Bank dividend rate reduction).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-infrastructure-investment-jobs-act-2021",
      "us-davis-bacon-act"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fatca-foreign-account-tax-compliance",
    "title": "Foreign Account Tax Compliance Act (FATCA)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The Foreign Account Tax Compliance Act (FATCA) requires foreign financial institutions (FFIs) and certain non-financial foreign entities to report information on financial accounts held by U.S. persons, or be subject to a 30% withholding on withholdable payments under Chapter 4 of the Internal Revenue Code. It also requires U.S. persons to report specified foreign financial assets exceeding certain thresholds on Form 8938.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-40-recommendations-2023-consolidated",
      "eu-dac6-mandatory-disclosure-hallmarks-2020",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fatca-foreign-account-tax-compliance-2010",
    "title": "Foreign Account Tax Compliance Act (FATCA)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "FATCA requires foreign financial institutions (FFIs) and certain non-financial foreign entities to report on U.S. account holders' foreign assets or face 30% withholding on withholdable payments. It also mandates U.S. persons to report specified foreign financial assets exceeding certain thresholds on Form 8938.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "eu-dac2-automatic-exchange-financial-info",
      "eu-dac6-mandatory-disclosure-cross-border",
      "us-fda-rwe-framework-real-world-evidence-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fatca-foreign-account-tax-compliance-reporting",
    "title": "US FATCA - Foreign Account Tax Compliance Act: FFI Agreement, FATCA Withholding, and GIIN Registration",
    "domain": "Tax & Transfer Pricing",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "US Foreign Account Tax Compliance Act (FATCA), enacted in the Hiring Incentives to Restore Employment (HIRE) Act 2010 and implemented via IRC Sections 1471-1474, requires foreign financial institutions (FFIs) to report US account holders and US-owned foreign entities to the IRS or face a 30% withholding tax on US-source payments. FFIs may comply via: (1) direct FFI Agreement with IRS (Registered Deemed-Compliant or Participating FFI); (2) Intergovernmental Agreement (IGA) with the US - Model 1 IGA requires the FFI to report to its home jurisdiction, which automatically exchanges with the IRS; Model 2 IGA requires direct FFI reporting to the IRS. FFIs must obtain a Global Intermediary Identification Number (GIIN) and register on the FATCA FFI Registration System. Withholdable payments include US-source dividends, interest, premiums, annuities, and gross proceeds from sale of US securities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatca-iga-compliance",
      "crs-oecd-tax-automatic"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fatca-iga-2010",
    "title": "Foreign Account Tax Compliance Act (FATCA) and Intergovernmental Agreements (IGAs)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Foreign Account Tax Compliance Act (FATCA), under U.S. Internal Revenue Code §§ 1471-1474, requires foreign financial institutions (FFIs) to report information about financial accounts held by U.S. taxpayers to the IRS, or face a 30% withholding tax on certain U.S. source payments. U.S. taxpayers with specified foreign financial assets exceeding certain thresholds must also report these assets on Form 8938.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crs-oecd-tax-automatic",
      "bank-secrecy-act-suspicious"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-fbar-fincen-114-foreign-bank-account-report-31-cfr-1010",
    "title": "US FBAR - FinCEN 114 Foreign Bank Account Report & 31 CFR 1010.350 Filing Requirements",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "2.0",
    "last_updated": "2026-06-15",
    "bluf": "FinCEN Form 114 (FBAR) requires US persons with a financial interest in or signature authority over foreign bank accounts with aggregate value exceeding $10,000 to file annually by April 15 (6-month auto-extension to October 15) - non-willful violations: up to $10,000 per violation; willful violations: up to $100,000 or 50% of account balance per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fbar-fincen-114-foreign-bank-accounts",
    "title": "US FBAR - FinCEN Form 114 Foreign Bank Account Reporting (Bank Secrecy Act)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "US persons (citizens, residents, and entities) with financial interest in or signature authority over foreign financial accounts totalling more than USD 10,000 at any point during the calendar year must file FinCEN Form 114 (FBAR) electronically with FinCEN by April 15, with automatic extension to October 15. Non-wilful FBAR violations carry penalties up to USD 10,000 per violation; wilful violations carry penalties of the greater of USD 100,000 or 50% of account balance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fatca",
        "bank_secrecy_act",
        "irs_form_8938",
        "crs",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fatca-foreign-account-tax-compliance-2010",
      "oecd-crs-common-reporting-standard-2014"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fcc-47-cfr-15-radio-frequency-devices",
    "title": "47 CFR Part 15 - Radio Frequency Devices (FCC)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FCC 47 CFR Part 15 governs radio frequency devices, allowing operation without an individual license provided the device causes no harmful interference and accepts interference, and requiring manufacturers to meet general technical requirements, label devices and inform users, obtain equipment authorization for unintentional radiators, and meet the conducted and radiated emission limits demonstrated through the prescribed measurement standards and procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fcc-telecommunications-act-1996-47-usc-151-open-access-interoperability"
    ],
    "primary_citations_count": 20
  },
  {
    "node_id": "us-fcc-47-cfr-25-satellite-communications",
    "title": "47 CFR Part 25 - Satellite Communications (FCC)",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FCC 47 CFR Part 25 governs satellite communications, requiring a station authorization for space stations and earth stations, meeting citizenship and application requirements, filing space station and earth station applications with the required technical and orbital information, obtaining special temporary authorization where needed, observing license terms and renewals, and meeting construction, deployment, and milestone certification obligations including the streamlined small space station route.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fcc-telecommunications-act-1996-47-usc-151-open-access-interoperability"
    ],
    "primary_citations_count": 14
  },
  {
    "node_id": "us-fcc-47-cfr-54-universal-service-fund",
    "title": "47 CFR Part 54 - Universal Service (FCC)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FCC 47 CFR Part 54 governs the federal universal service support mechanisms administered through USAC, setting the intended use of support, eligible telecommunications carrier designation, high-cost broadband obligations and reporting, the Lifeline low-income program with eligibility verification and the National Lifeline Accountability Database, the Schools and Libraries (E-Rate) program with competitive bidding and CIPA certification, the Rural Health Care program, contributor obligations to the fund, and the prohibition on using support for covered communications equipment subject to removal and replacement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fcc-telecommunications-act-1996-47-usc-151-open-access-interoperability"
    ],
    "primary_citations_count": 25
  },
  {
    "node_id": "us-fcc-47-cfr-73-radio-broadcast-services",
    "title": "47 CFR Part 73 - Radio Broadcast Services (FCC)",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FCC 47 CFR Part 73 governs radio broadcast services and the rules applicable to all broadcast stations, requiring station identification, sponsorship identification, fair conduct of licensee contests, broadcasting of emergency information, compliant transmission system operation and monitoring within power and modulation tolerances, a minimum operating schedule, station logs, a designated chief operator, equal employment opportunity, an online public inspection file, and timely license renewal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fcc-telecommunications-act-1996-47-usc-151-open-access-interoperability"
    ],
    "primary_citations_count": 18
  },
  {
    "node_id": "us-fcc-47-cfr-90-private-land-mobile-radio-services",
    "title": "47 CFR Part 90 - Private Land Mobile Radio Services (FCC)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FCC 47 CFR Part 90 governs the private land mobile radio services, requiring licensees to confirm scope and definitions, establish eligibility in the public safety or industrial/business pools, meet any foreign eligibility limits, file complete applications with the required supplemental information, obtain authorization for license modifications and temporary operations, observe the license term and construction deadlines, complete frequency coordination, use certified equipment, and meet the power, antenna height, and emission limits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fcc-telecommunications-act-1996-47-usc-151-open-access-interoperability"
    ],
    "primary_citations_count": 19
  },
  {
    "node_id": "us-fcc-47-cfr-part-25-satellite-communications",
    "title": "US FCC 47 CFR Part 25 Satellite Communications Earth Station and Space Station Licensing Orbital Debris Mitigation and Spectrum Coordination",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "47 CFR Part 25 implements the United States Federal Communications Commission framework regulating satellite communications including the licensing of earth stations and space stations organised in multiple subparts covering Subpart A General including scope and purpose, Subpart B Applications and Licenses including section 25.114 application requirements for space station authorizations section 25.115 application for earth station authorizations and section 25.156 Two Round Modified Processing rounds, Subpart C Technical Standards including frequency band rules and section 25.146 antenna performance standards, Subpart D Technical Operations including section 25.272 general inter-system coordination procedures and section 25.281 operating provisions, Subpart E Competitive Bidding Procedures for satellite licenses, and Subpart F Application and Licensing Requirements for Personal Communications Services. The Part incorporates the FCC orbital debris mitigation requirements including the 5-year post-mission disposal rule adopted in 2024 requiring satellites operating below 2000 km altitude to be deorbited within 5 years of end of mission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fcc-5-year-deorbit-rule-2024-orbital-debris-mitigation"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fcc-47-cfr-part-8-subpart-b-cyber-trust-mark-consumer-iot-labeling",
    "title": "FCC 47 CFR Part 8 Subpart B - Cybersecurity Labeling Program for IoT Products (US Cyber Trust Mark)",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "47 CFR Part 8 Subpart B (sections 8.201 through 8.222) implements the US Cyber Trust Mark - the voluntary Federal Communications Commission cybersecurity labeling program for consumer Internet of Things products adopted by the Commission in Report and Order FCC 24-26 (March 14, 2024) under authority of section 302 of the Communications Act of 1934 (47 USC 302a). Section 8.203 defines Consumer IoT products as IoT products intended primarily for consumer use, rather than enterprise or industrial use, excluding medical devices regulated by the FDA and motor vehicles or motor vehicle equipment regulated by NHTSA. The same section defines three core administrative roles: the Cybersecurity Label Administrator (CLA), an accredited third-party entity recognized and authorized by the Commission to manage and administer the labeling program; the Cybersecurity Testing Laboratory (CyberLAB), an accredited third-party entity recognized and authorized by a CLA to assess consumer IoT products for compliance; and the Lead Administrator, a CLA selected to carry out additional administrative responsibilities. Section 8.204 prohibits use of the FCC IoT Label by products on the Covered List under 47 CFR 1.50002 (Section 889 NDAA prohibition - Huawei, ZTE, Hytera, Hikvision, Dahua), products containing components from listed entities, products from entities on the Department of Commerce Entity List or DoD's Chinese Military Companies List, and products from federally debarred contractors. Section 8.205 sets the cybersecurity labeling authorization procedure. The technical standard for the program is NIST IR 8425 (Profile of the IoT Core Baseline for Consumer IoT Products, September 2022). Authorized products display the FCC IoT Label with QR code linking to a consumer-readable registry entry including support timelines, security update cadence, and disclosure of cybersecurity capabilities. The program is voluntary but participation is conditioned on continued compliance, with revocation under section 8.220 and enforcement under section 8.222 including civil penalties under section 503 of the Communications Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "covered_list_section_889_prohibitions_section_8_204",
        "nist_ir_8425_technical_baseline",
        "consumer_registry_and_qr_code_disclosure"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "etsi-en-303-645-iot-cybersecurity-2020",
      "uk-psti-act-2022-relevant-connectable-products-security",
      "eu-cyber-resilience-act-2024-iot-products"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fcc-5-year-deorbit-rule-2024-orbital-debris-mitigation",
    "title": "US FCC 5-Year Deorbit Rule (2024) for Orbital Debris Mitigation",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2024-08-09",
    "bluf": "The Federal Communications Commission's 5-Year Deorbit Rule shortens the post-mission disposal timeline for satellites in low-Earth orbit (LEO) from 25 years to 5 years following the end of mission. The rule applies to space stations licensed by the FCC for non-geostationary satellite orbit (NGSO) operations under 47 CFR Part 25 and was adopted by the FCC on 29 September 2022 with the implementing regulation published in the Federal Register on 9 August 2024 (89 FR 65017). The rule is part of the FCC's Space Innovation, Mitigation of Orbital Debris in the New Space Age proceeding (IB Docket No. 18-313) and codifies the post-mission disposal timeline at 47 CFR section 25.114(d)(14)(iii).\n\nThe rule requires applicants for space station authorization to certify that any space stations granted under the authorization will deorbit as soon as practicable after the post-mission disposal phase and no later than five years following the end of mission. Failure to comply may result in enforcement action including monetary forfeiture, license revocation, or denial of future applications. The rule includes a waiver process for operators demonstrating a strong public interest justification. The FCC retains jurisdiction over orbital debris mitigation for FCC-licensed satellites and coordinates with NASA's Orbital Debris Program Office and the Department of Defense for tracking and mitigation. The rule applies to new applications for space station authorization filed on or after the rule's effective date of 29 September 2024.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fcc-cfr-47-part-25-satellite-earth-stations",
      "iadc-space-debris-mitigation-guidelines-2007",
      "un-copuos-space-debris-mitigation-guidelines-2007"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fcc-broadband-consumer-labels-2024",
    "title": "Empowering Broadband Consumers Through Transparency: Broadband Consumer Labels (47 CFR Part 8)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2024-10-16",
    "bluf": "This rule requires U.S. Internet Service Providers (ISPs) to display, at the point of sale, a standardized, easy-to-understand 'Broadband Consumer Label' detailing prices, speeds, data allowances, and network management practices, as mandated by 47 CFR § 8.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fcc-broadband-equity-access-deployment-2024",
    "title": "FCC Broadband Equity Access and Deployment (BEAD) Program Implementation - $42.5B NTIA Grant: Eligible Entity Priority Areas, Covered Broadband Projects, Speed Threshold (100/20 Mbps), Affordability Requirements, Non-Wired Technology Priority and Reporting",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The BEAD Program, administered by NTIA under the Infrastructure Investment and Jobs Act, requires state-identified eligible entities to deploy future-proof broadband infrastructure achieving minimum 100/20 Mbps speeds in unserved and underserved areas, with priority for non-wired solutions where cost-effective, and mandates affordability measures and public reporting. Applies to state-designated lead entities receiving federal grants under 47 U.S.C. § 9401.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eecc-2018-1972-electronic-communications-code",
      "cisa-zero-trust-maturity-model-2-0",
      "guide-computer-security-log-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fcc-cfr-47-part-25-satellite-earth-stations",
    "title": "47 CFR Part 25 - Satellite Communications",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must obtain specific station authorizations from the Federal Communications Commission (FCC) before constructing, deploying, or operating satellite space stations or earth stations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fcc-cfr-47-part-64-cpni-customer-proprietary",
    "title": "47 CFR Part 64 - Miscellaneous Rules Relating to Common Carriers",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes miscellaneous rules for common carriers, including restrictions on indecent telephone messages, procedures for emergency services, and comprehensive standards for providing Telecommunications Relay Services (TRS) for persons with disabilities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fcc-data-breach-rule-2024",
    "title": "FCC Data Breach Notification Rule Amendment (Report and Order FCC 23-111, WC Docket 22-21)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "FCC Report and Order FCC 23-111 (WC Docket 22-21), adopted December 13, 2023, released December 21, 2023, and effective March 13, 2024, updates Part 64 CPNI rules requiring telecommunications carriers, VoIP providers, and TRS providers to notify the FCC, FBI, and Secret Service within 7 business days of a breach affecting 500 or more customers or where harm is reasonably likely, and to notify affected customers without unreasonable delay and in no case later than 30 days after a reasonable determination of a breach, and expands the breach definition to include inadvertent unauthorised access.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-fcc-data-breach-rule-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fcc-part-15-unlicensed-radio-frequency-devices",
    "title": "Title 47 CFR Part 15: Radio Frequency Devices",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes technical standards, certification requirements, and operating conditions for unlicensed radio frequency (RF) devices in the United States to ensure they do not cause harmful interference to authorized radio services. Per §15.5, devices must not cause harmful interference and must accept any interference received, including that which may cause undesired operation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itu-radio-regulations-2020-edition",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fcc-part-25-satellite-earth-station-licensing-spectrum-coordination",
    "title": "US FCC Part 25 - Satellite Earth Station Licensing, Spectrum Coordination, and NGSO Constellation Authorization",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2022-08-01",
    "bluf": "FCC Part 25 rules govern licensing of satellite earth stations and space stations (including NGSO constellations), requiring frequency coordination, power limits, interference protection, technical showings, and compliance with FCC space debris mitigation rules including 5-year post-mission disposal plans for LEO satellites.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fcc-telecommunications-act-1996-47-usc-151-open-access-interoperability",
      "us-nepa-1970-environmental-impact-assessment"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fcc-part-25-satellite-licensing-orbital-debris",
    "title": "US FCC Part 25 - Satellite Earth Stations and Space Stations: Licensing Requirements, Orbital Debris Mitigation, and End-of-Life Disposal",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Title 47 CFR Part 25 governs FCC licensing of satellite earth stations and space stations (satellites) for US operators. Space station licenses require technical showing of orbital debris mitigation compliance per 47 CFR 25.114, including post-mission disposal plans satisfying the 5-year deorbit rule for LEO satellites (updated from 25-year rule effective September 2024 per FCC 22-74). Non-geostationary satellite orbit (NGSO) operators must file a debris mitigation plan with quantified probability of casualty, probability of collision, and disposal orbit parameters. GEO satellite operators must plan for disposal into the graveyard orbit above GEO. The FCC's Mitigation of Orbital Debris in the New Space Age Report and Order (2020) substantially updated Part 25 requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "copuos-lts-guidelines-2019-space-sustainability",
      "intl-outer-space-treaty-1967-article-9-contamination-prevention"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fcc-rdof-rural-broadband-fund-rules",
    "title": "Rural Digital Opportunity Fund (RDOF) Phase I: Auction Eligibility, Build-Out Milestones and Performance Measurement Rules",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The FCC's Rural Digital Opportunity Fund (RDOF) provides subsidies to telecommunications carriers for deploying high-speed broadband networks in unserved rural areas. Winning bidders of the Phase I reverse auction (Auction 904) are legally obligated to meet specific network build-out milestones and performance standards over a 10-year support term, as mandated by 47 C.F.R. § 54.806.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fcc-satellite-licensing-part-25",
    "title": "FCC 47 CFR Part 25 - Satellite Communications",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes licensing, technical, and operational requirements for satellite communications systems in the United States, including geostationary (GSO) and non-geostationary (NGSO) satellite networks. It mandates compliance with construction milestones under §25.164, surety bonding of $3 million under §25.165, and coordination procedures for earth and space stations across designated frequency bands.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "itu-radio-regulations-2020-edition"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fcc-spectrum-frontiers-5g-order-2016",
    "title": "US FCC Spectrum Frontiers Order 2016 - mmWave 5G Spectrum Allocation, LMDS Band Expansion and Licensed Fixed Satellite Service Coordination",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The FCC Spectrum Frontiers First Report and Order (FCC 16-89, released 14 July 2016) established the world's first regulatory framework for the commercial use of millimetre wave (mmWave) spectrum for 5G wireless services, making available approximately 11 GHz of spectrum for flexible use and fixed use above 24 GHz; the Order created three new spectrum categories: licensed flexible-use spectrum in the 28 GHz (27.5-28.35 GHz), 37 GHz (37-38.6 GHz), 39 GHz (38.6-40 GHz), and 47 GHz (47.2-48.2 GHz) bands, which are available for 5G New Radio (NR) deployments under Part 30 rules; unlicensed operations in the 64-71 GHz band using Part 15 rules; and local multipoint distribution service (LMDS) band expansion; the Order establishes Part 30 (Upper Microwave Flexible Use Service - UMFUS) as the governing regulatory framework for licensed mmWave 5G spectrum; in 2019 and 2020 the FCC conducted Auction 101 (28 GHz), Auction 102 (24 GHz), and Auction 103 (37/39/47 GHz) selling approximately USD 7.5 billion in mmWave spectrum licences; licence terms are 10 years with renewal contingent on meeting construction/buildout requirements; interference protection mechanisms for fixed satellite service (FSS) earth stations operating in the same bands are specified through coordination zones and exclusion zones; the National Environmental Policy Act (NEPA) and Section 106 of the National Historic Preservation Act (NHPA) reviews are required for antenna deployments using mmWave spectrum.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fcc-broadband-consumer-labels-2024"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fcc-stir-shaken-robocall-mitigation",
    "title": "US FCC STIR/SHAKEN Framework (TRACED Act) - Call Authentication Standards, Analytics Labelling and Robocall Blocking Obligations",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Mandates that voice service providers implement the STIR/SHAKEN call authentication framework on their IP networks to combat illegal robocalls by digitally signing originating calls, as required by the TRACED Act and codified in FCC rules under 47 CFR § 64.6301.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fcc-tcpa-ai-voice-robocalls-ruling-2024",
    "title": "US FCC Declaratory Ruling - AI-Generated Voices in Robocalls Are Artificial Voices under TCPA (February 8, 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On February 8, 2024 the Federal Communications Commission adopted a unanimous Declaratory Ruling holding that calls made with AI-generated voices are calls made using artificial or prerecorded voice within the meaning of the Telephone Consumer Protection Act (TCPA) of 1991. The Ruling clarifies that the TCPA prior-express-written-consent requirements for telemarketing calls to residential lines and to all calls to mobile phones using an artificial or prerecorded voice apply equally to AI-cloned and AI-synthesised voices. The Ruling is codified in FCC docket CG 02-278 and was prompted by the use of AI voice cloning in a January 2024 New Hampshire primary election robocall impersonating President Biden. The Ruling makes such AI-generated robocalls without consent immediately illegal under longstanding TCPA provisions and exposes callers to TCPA private rights of action including statutory damages of 500 to 1500 USD per call, FCC civil penalties up to 23000 USD per violation under FCC enforcement authority, and state attorney general enforcement under TCPA's parallel state law authorities. The Ruling also enables state AGs to use TCPA tools against AI-generated robocall scams and protects voters during elections from AI voice impersonation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "election_integrity",
        "regulatory_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-ab2655-2024-defending-democracy-deepfake-deception",
      "us-ca-sb942-ai-transparency-act-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fcc-telecommunications-act-1996-47-usc-151-open-access-interoperability",
    "title": "US FCC Telecommunications Act 1996 47 USC 151 - Open Access, Interconnection, and Universal Service Obligations",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "1996-02-08",
    "bluf": "The US Telecommunications Act 1996 (47 USC) requires incumbent local exchange carriers to provide interconnection, network unbundling, and collocation to competitors, mandates universal service fund contributions from carriers, and established the framework for broadcast ownership, spectrum management, and cable access regulation by the FCC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-15-usc-45-unfair-deceptive-practices",
      "us-hipaa-security-rule-45-cfr-164-technical-safeguards"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fcpa-15-usc-78dd-1-anti-bribery-provisions-issuers",
    "title": "15 U.S. Code § 78dd-1 - Prohibited foreign trade practices by issuers",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Prohibits issuers, their officers, directors, employees, agents, or stockholders from corruptly offering or giving anything of value to foreign officials, political parties, or candidates to obtain or retain business.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fcpa-15-usc-78m-books-records-accounting-requirements",
    "title": "15 U.S. Code § 78m - Periodical and other reports",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Issuers of registered securities must file periodical reports with the SEC, maintain accurate books and records, and devise a system of internal accounting controls to ensure authorized transactions and asset accountability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fcpa-foreign-corrupt-practices-act-1977",
    "title": "Foreign Corrupt Practices Act of 1977 (FCPA): Anti-Bribery and Books & Records Provisions",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The FCPA prohibits U.S. persons and entities from offering, paying, or promising anything of value to foreign officials to obtain or retain business (15 U.S.C. §§ 78dd-1, et seq.). It also mandates that issuers maintain accurate books and records and devise a system of internal accounting controls (15 U.S.C. § 78m(b)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sarbanes-oxley-act-sox",
      "iso-37001-anti-bribery-2016",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fcra-15-usc-1681-consumer-credit-report-accuracy-access",
    "title": "US Fair Credit Reporting Act (FCRA) - Consumer Report Accuracy, Access Rights, and Adverse Action",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Fair Credit Reporting Act (15 U.S.C. § 1681) governs consumer reporting agencies (CRAs), furnishers of credit information, and users of consumer reports: mandating accuracy, limiting permissible purposes, granting consumers rights to dispute and correct inaccurate information, requiring adverse action notices when reports influence credit or employment decisions, and imposing civil liability up to $1,000 per wilful violation enforced by the FTC and CFPB.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-glba-safeguards-rule-16-cfr-314-financial-data-security"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fcra-1970",
    "title": "US Fair Credit Reporting Act 1970",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Fair Credit Reporting Act governs the collection, dissemination, and use of consumer credit information by consumer reporting agencies, furnishers, and users of consumer reports, granting consumers rights to access and dispute their credit files and limiting permissible uses of consumer reports to specific enumerated purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-fcra-1970.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-glba-gramm-leach-bliley-act-1999"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fda-21-cfr-101-food-labeling",
    "title": "21 CFR Part 101 - Food Labeling (FDA)",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "FDA 21 CFR Part 101 sets the food labeling requirements under the Federal Food, Drug, and Cosmetic Act, prescribing the principal display panel and information panel, the statement of identity, ingredient declaration, name and place of business, net quantity of contents, mandatory nutrition labeling in the Nutrition Facts format, and the general principles governing nutrient content claims and health claims.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "us-fda-21-cfr-111-dietary-supplement-cgmp",
    "title": "21 CFR Part 111 - Current Good Manufacturing Practice for Dietary Supplements (FDA)",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "FDA 21 CFR Part 111 sets current good manufacturing practice for persons who manufacture, package, label, or hold dietary supplements, requiring written procedures, personnel hygiene controls, suitable equipment, a production and process control system covering all stages, quality control operations, established specifications, identity and specification testing, master and batch production records, and recordkeeping to ensure each supplement meets its specifications and is packaged and labeled as the master manufacturing record requires.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "us-fda-21-cfr-117-cgmp-hazard-analysis-food-safety-modernization-act",
    "title": "US FDA Preventive Controls for Human Food - 21 CFR Part 117 Current Good Manufacturing Practice, Hazard Analysis and Risk-Based Preventive Controls Under FSMA",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "21 CFR Part 117 (Current Good Manufacturing Practice, Hazard Analysis, and Risk-Based Preventive Controls for Human Food) is the FDA's implementing regulation for the Preventive Controls for Human Food rule under the FDA Food Safety Modernization Act (FSMA, Public Law 111-353). Part 117 applies to facilities required to register under section 415 of the Federal Food, Drug, and Cosmetic Act (FFDCA) that manufacture, process, pack, or hold human food, subject to the §117.5 exemptions including qualified facilities, certain dietary supplements, alcoholic beverages, low-acid canned foods (separately regulated under 21 CFR Part 113), juice (Part 120), seafood (Part 123), warehousing of dairy ingredients pending USDA action, and on-farm activities. Subpart A sets general provisions, including §117.1 (applicability) and §117.3 (definitions). Subpart B sets the cGMP standards for personnel, plant and grounds, sanitary operations, sanitary facilities and controls, equipment, processes and controls, warehousing and distribution, and defect action levels. Subpart C requires hazard analysis (§117.130), preventive controls (§117.135), validation (§117.160), monitoring (§117.145), corrective actions and corrections (§117.150), verification (§117.155), and a written food safety plan (§117.126). Subpart D requires a written recall plan when a hazard analysis identifies a hazard requiring a preventive control. Subpart E requires supply-chain program for raw materials and other ingredients for which a hazard requiring a supply-chain-applied control has been identified. Subpart F sets recordkeeping including retention for 2 years (or 1 year past the equipment in use date for equipment records).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-21-cfr-1271-human-cells-tissues-hctps",
    "title": "21 CFR Part 1271 - Human Cells, Tissues, and Cellular and Tissue-Based Products (HCT/Ps)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "FDA 21 CFR Part 1271 governs human cells, tissues, and cellular and tissue-based products, setting the criteria under which an HCT/P is regulated solely under section 361 of the Public Health Service Act, requiring establishments to register and list their products, to determine donor eligibility through screening and testing, and to establish and maintain procedures and current good tissue practice to prevent the introduction, transmission, or spread of communicable disease.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-21-cfr-203-prescription-drug-marketing",
    "title": "21 CFR Part 203 - Prescription Drug Marketing (Samples and Wholesale Distribution)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "21 CFR Part 203 implements the Prescription Drug Marketing Act and governs the sale, purchase, distribution and sampling of prescription drugs. As a general sales restriction, no person may sell, purchase or trade, or offer to sell, purchase or trade, any prescription drug that was purchased by a hospital or other health care entity or donated or supplied at a reduced price to a charitable organization, except as the regulation allows. Prescription drug samples may be distributed only to practitioners licensed to prescribe the drug, or to the pharmacy of a hospital or other health care entity at the written request of a licensed practitioner. Distribution by mail or common carrier requires a written request executed before delivery, verification with the State authority that the requesting practitioner is licensed, a signed receipt on delivery, and return of the receipt to the manufacturer or authorized distributor of record; distribution by a representative or detailer is subject to parallel requirements. Manufacturers and authorized distributors of record must establish policies and procedures and administrative systems for sample distribution, must investigate and notify FDA of falsified sample requests, receipts or records or diversion of samples, and must report significant losses or known thefts. Sample units must bear lot or control numbers and be labeled as required, wholesale distribution by persons other than authorized distributors of record is subject to identification and pedigree requirements, and records of sample distribution and wholesale distribution must be maintained.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_obligations",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-211-cgmp-finished-pharmaceuticals",
      "us-fda-21-cfr-314-nda-application",
      "us-fda-21-cfr-601-biologics-licensing-and-establishment-licensing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-21-cfr-205-wholesale-drug-distribution-licensing",
    "title": "21 CFR Part 205 - FDA Guidelines for State Licensing of Wholesale Prescription Drug Distributors",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "21 CFR Part 205 sets the minimum standards and guidelines for the state licensing of wholesale prescription drug distributors implementing the Prescription Drug Marketing Act. A wholesale distributor of prescription drugs must be licensed in accordance with these requirements, and must provide the minimum information required for licensure and meet the minimum qualifications for the conduct of wholesale distribution. The distributor must ensure that personnel meet the applicable requirements and must satisfy the minimum requirements for the storage and handling of prescription drugs, including appropriate facilities, security against diversion and theft, and proper temperature and conditions. The distributor must establish and maintain the required prescription drug distribution records and make them available for inspection, and must avoid the violations for which penalties are provided. These standards protect the integrity of the U.S. prescription drug distribution chain.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-203-prescription-drug-marketing",
      "us-fda-21-cfr-606-cgmp-blood-and-blood-components",
      "us-fda-21-cfr-801-medical-device-labeling"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-21-cfr-211-cgmp-finished-pharmaceuticals",
    "title": "Current Good Manufacturing Practice for Finished Pharmaceuticals",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes the minimum requirements for methods, facilities, and controls used in the manufacturing, processing, packing, or holding of finished pharmaceuticals to ensure their safety, identity, strength, quality, and purity. It applies to all manufacturers, processors, packers, or holders of finished pharmaceuticals as defined in 21 CFR § 211.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-210-211-current-good-manufacturing-practice",
      "ich-q10-pharmaceutical-quality-system-2008",
      "eu-gmp-annex-1-sterile-manufacture-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-21-cfr-312-ind-application",
    "title": "Investigational New Drug Application",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes the requirements for submitting an Investigational New Drug (IND) application to the FDA, including content, safety reporting, protocol amendments, and annual reports, and applies to sponsors of clinical investigations of new drugs in the United States under 21 CFR Part 312.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-210-211-current-good-manufacturing-practice",
      "canada-food-drug-regulations-division-5-clinical-trials",
      "eu-gmp-annex-1-sterile-manufacture-2022",
      "ich-q10-pharmaceutical-quality-system-2008",
      "fda-21-cfr-part-314-nda-new-drug-application"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-21-cfr-312-ind-application-investigational-new-drug",
    "title": "US FDA 21 CFR Part 312 - Investigational New Drug (IND) Application Requirements",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2024-03-01",
    "bluf": "FDA regulations at 21 CFR Part 312 govern the Investigational New Drug (IND) application process required before conducting clinical studies of unapproved drugs or approved drugs for new indications in the US. Sponsors must submit an IND and await a 30-day review period before initiating Phase 1 trials. Annual reports, safety reports (within 15 days for unexpected serious adverse drug reactions), and protocol amendments are mandatory throughout the IND lifecycle.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-210-211-current-good-manufacturing-practice",
      "us-fda-21-cfr-part-11-electronic-records"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fda-21-cfr-312-ind-clinical-investigations",
    "title": "21 CFR Part 312 - Investigational New Drug Application",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation requires sponsors to submit an Investigational New Drug (IND) application to the U.S. Food and Drug Administration (FDA) before initiating any clinical investigation of a new drug in human subjects. As outlined in § 312.20, the IND process ensures subject safety and that studies are designed to yield scientifically valid data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-21-cfr-312-investigational-new-drug-ind-application",
    "title": "US FDA 21 CFR Part 312 - Investigational New Drug (IND) Application for Clinical Trials",
    "domain": "Biotech & Genomics",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "21 CFR Part 312 requires sponsors to file an Investigational New Drug Application with FDA before initiating Phase I, II, or III clinical trials in the US - covering investigational biologics, gene therapies, cell therapies, and small molecules. Includes safety reporting, protocol amendments, and annual reporting obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fda-21-cfr-314-nda-application",
    "title": "Applications for FDA Approval to Market a New Drug",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes the requirements for submitting a New Drug Application (NDA) to the U.S. Food and Drug Administration (FDA) under 21 U.S.C. 355, including content, format, review timelines, and post-approval obligations. It applies to sponsors seeking marketing approval for new drugs in the United States under 21 CFR Part 314.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-312-ind-investigational-new-drug",
      "fda-21-cfr-210-211-current-good-manufacturing-practice",
      "ich-q10-pharmaceutical-quality-system-2008"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-21-cfr-314-nda-drug-approval",
    "title": "21 CFR Part 314: Applications for FDA Approval to Market a New Drug",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes the comprehensive requirements for submitting a New Drug Application (NDA) to the U.S. Food and Drug Administration (FDA) for marketing approval. It mandates specific content and format for submissions, including clinical data, chemistry, manufacturing, and controls (CMC), labeling, and post-approval reporting, as detailed in Subpart B, § 314.50.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-21-cfr-320-bioavailability-bioequivalence-requirements",
    "title": "21 CFR Part 320 - Bioavailability and Bioequivalence Requirements (FDA)",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FDA 21 CFR Part 320 sets the bioavailability and bioequivalence requirements for drug products, requiring applicants to submit the required data, apply the waiver criteria where appropriate, establish the basis for measuring in vivo bioavailability or demonstrating bioequivalence, select the types of evidence, follow the guidelines for designing and conducting single-dose and multiple-dose in vivo studies, validate the analytical methods, meet the applicable Investigational New Drug requirements, follow the procedures for establishing or amending a bioequivalence requirement, carry out batch and in vitro testing where required, and retain the records and samples.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 17
  },
  {
    "node_id": "us-fda-21-cfr-4-combination-products-cgmp-postmarket-safety",
    "title": "21 CFR Part 4 - FDA Combination Products cGMP and Postmarketing Safety Reporting",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "21 CFR Part 4 sets the current good manufacturing practice (cGMP) requirements and postmarketing safety reporting requirements for combination products regulated by the U.S. Food and Drug Administration. A combination product comprises two or more regulated components (drug, device or biological product), and the manufacturer must determine the scope and applicable definitions before assessing compliance. The cGMP requirements of the constituent parts apply to the combination product, and a co-packaged or single-entity combination product may demonstrate compliance through a streamlined approach that satisfies a base set of one constituent part's cGMP plus specified provisions of the other. The manufacturer must determine the postmarketing safety reporting scope, submit the required reports for the combination product and its constituent parts, share required information with other constituent part applicants, submit reports in the required manner and place, and maintain the postmarketing safety reporting records.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-807-device-establishment-registration-listing-510k",
      "us-fda-21-cfr-801-medical-device-labeling",
      "us-fda-21-cfr-606-cgmp-blood-and-blood-components"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-21-cfr-50-human-subjects-protection-clinical-research",
    "title": "US FDA Protection of Human Subjects - 21 CFR Part 50 Informed Consent and Vulnerable-Population Requirements for FDA-Regulated Clinical Investigations",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "21 CFR Part 50 (Protection of Human Subjects) is issued by the FDA under sections 201, 301, 405, 406, 408, 409, 412, 413, 502, 503, 505, 506, 507, 510, 513-516, 518-520, 528, 706, and 801 of the Federal Food, Drug, and Cosmetic Act, and under sections 351, 354-360F of the Public Health Service Act. It applies to all clinical investigations regulated by the FDA, including studies submitted to support marketing approval of drugs, biologics, and medical devices, and to clinical investigations supporting applications for research or marketing permits. Section 50.20 establishes the general requirement that informed consent be obtained from each human subject (or the subject's legally authorized representative) in compliance with §50.25 (basic elements) and §50.27 (documentation). Section 50.23 narrowly permits an exception to informed consent for emergency situations involving life-threatening conditions; §50.24 permits IRB-approved exception for emergency research. Section 50.25 specifies the 8 basic elements of informed consent (research nature, risks, benefits, alternatives, confidentiality, compensation, contact, voluntary participation) and 6 additional elements when appropriate. Section 50.27 requires written informed consent documented on a form approved by the IRB. Subpart C in the current 21 CFR Part 50 is reserved; the FDA does not maintain a separate prisoner-research subpart (research involving prisoners regulated by HHS at 45 CFR Part 46 Subpart C governs federally supported research, and the FDA defers to IRB review for the protection of prisoner subjects in FDA-regulated investigations). Subpart D (§§50.50-56) provides additional safeguards for children including categorization of permissible research based on risk and direct-benefit analysis (minimal risk per §50.51, greater than minimal with prospect of direct benefit per §50.52, greater than minimal with no direct benefit but generalizable knowledge about the disorder per §50.53, and not otherwise approvable that presents an opportunity to address a serious problem affecting children's welfare per §50.54). Section 50.55 governs assent of children and Section 50.56 governs permissions of parents and guardians. Sponsors and investigators must observe these protections concurrent with 21 CFR Part 56 (Institutional Review Boards) and Part 312 (IND) or 812 (IDE) requirements as applicable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-312-ind-investigational-new-drug"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-21-cfr-54-financial-disclosure-clinical-investigators",
    "title": "21 CFR Part 54 - Financial Disclosure by Clinical Investigators",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "21 CFR Part 54 requires an applicant who submits a marketing application for a human drug, biological product or device, relying on covered clinical studies, to disclose or certify certain financial interests and arrangements of the clinical investigators who conducted those studies, so that FDA can assess the potential for bias affecting the reliability of the data. A covered clinical study is any study of a drug or device in humans, submitted in a marketing application or reclassification petition, that the applicant or FDA relies on to establish that the product is effective or that bears on safety. The applicant must submit a list of all clinical investigators who conducted covered studies, identify those who are full-time or part-time employees of the sponsor, and for the others either certify the absence of, or disclose, the financial arrangements specified. The disclosable arrangements are: compensation made to the investigator that could be affected by the outcome of the study; a significant equity interest in the sponsor; a proprietary interest in the tested product such as a patent, trademark, copyright or licensing agreement; and significant payments of other sorts from the sponsor with a monetary value of more than $25,000 exclusive of the costs of conducting the study. Clinical investigators subject to the investigational new drug or investigational device exemption regulations must provide the sponsor with sufficient accurate information to permit the disclosure or certification. FDA evaluates the disclosed interests and may take action to ensure the reliability of the data, and the applicant must keep complete records for the required retention period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "disclosable_interests",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-50-human-subjects-protection-clinical-research",
      "us-fda-21-cfr-312-ind-application-investigational-new-drug",
      "us-fda-21-cfr-314-nda-application"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fda-21-cfr-58-glp-nonclinical-studies",
    "title": "21 CFR Part 58 - Good Laboratory Practice for Nonclinical Laboratory Studies",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Part 58 mandates that any nonclinical laboratory study supporting FDA product applications must follow Good Laboratory Practice, including qualified personnel (§ 58.29), a designated study director (§ 58.33), a quality assurance unit (§ 58.35), documented SOPs (§ 58.81), calibrated equipment (§ 58.63), and retention of records for the required period (§ 58.195).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-q5a-r2-viral-safety-biotech-2024",
      "ema-guidelines-advanced-therapy-quality-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-21-cfr-600-biological-products-general-standards",
    "title": "21 CFR Part 600 - FDA Biological Products: General Standards, Records and Reporting",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "21 CFR Part 600 sets the general standards applicable to licensed biological products regulated by the U.S. Food and Drug Administration through the Center for Biologics Evaluation and Research. A licensed manufacturer must meet the requirements for personnel and for the physical establishment, equipment, animals and their care, and must keep complete records of the manufacture and distribution of each product. The manufacturer must keep retention samples, must report biological product deviations, and must maintain proper temperatures during shipment. The manufacturer is subject to inspection, must conduct postmarketing reporting of adverse experiences, must submit distribution reports, and must notify the FDA of a permanent discontinuance or an interruption in manufacturing that could lead to a meaningful disruption in supply. These general standards complement the licensing and establishment requirements for biological products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-606-cgmp-blood-and-blood-components",
      "us-fda-21-cfr-203-prescription-drug-marketing",
      "us-fda-21-cfr-807-device-establishment-registration-listing-510k"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-fda-21-cfr-601-biologics-licensing-and-establishment-licensing",
    "title": "US FDA Biologics Licensing - 21 CFR Part 601 Biologics License Application, Establishment Licensing, Post-Approval Reporting and Lot Release Obligations",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "21 CFR Part 601 (Licensing) is the FDA's implementing regulation for the biological product approval and licensing framework under section 351 of the Public Health Service Act (42 U.S.C. 262) and the relevant sections of the Federal Food, Drug, and Cosmetic Act. Part 601 applies to manufacturers of biological products (vaccines, blood and blood components, allergenics, cellular and gene therapy products, certain antibodies, and other biologics not classified as drugs under the FFDCA). Subpart A (§§601.2-601.31) governs the Biologics License Application (BLA) including content, format, fees, and FDA action including approval, complete response, or refuse-to-file. Section 601.4 sets the conditions of license issuance. Section 601.12 governs post-licensure changes including the prior approval supplement (PAS), changes-being-effected (CBE-0, CBE-30), and annual report categories with thresholds based on the potential for adverse impact on product safety, identity, strength, quality, purity, potency, or effectiveness. Section 601.14 requires content and format of labeling. Subpart B (§§601.40-601.41) sets accelerated approval for biological products including the surrogate or intermediate clinical endpoint pathway and the post-marketing study requirement. Subpart C governs biologics license suspension and revocation. Subpart D establishes diagnostic radiopharmaceuticals labeling. Subpart E governs accelerated approval of biological products for serious or life-threatening illnesses. Subpart F governs confidentiality of data. Subpart G governs post-marketing studies including the §601.70 requirement to submit annual progress reports for each post-marketing study commitment. Adverse event reporting for licensed biological products is governed by 21 CFR Part 600 (§600.80 post-marketing reporting of adverse experiences) and Part 314 (§314.80). Lot release per §601.2(c) requires submission of samples and protocols to the FDA Center for Biologics Evaluation and Research (CBER) for release before distribution of certain products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-312-ind-investigational-new-drug"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-21-cfr-606-cgmp-blood-and-blood-components",
    "title": "21 CFR Part 606 - Current Good Manufacturing Practice for Blood and Blood Components",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "21 CFR Part 606 establishes the current good manufacturing practice (CGMP) requirements for the collection, processing, compatibility testing, storage and distribution of blood and blood components for transfusion or further manufacturing. Establishments must employ adequate, qualified personnel and maintain suitable facilities, equipment, and supplies and reagents that meet defined standards. They must establish, maintain and follow written standard operating procedures for all steps in the handling of blood and blood components. Laboratory controls must include scientifically sound specifications, standards and test procedures, monitoring of the reliability and accuracy of test procedures and instruments, and accurate identification and handling of test samples. Blood collection establishments and transfusion services must adequately control the risk of bacterial contamination of platelets using FDA-approved or cleared devices or other adequate methods, and must not release contaminated product. Compatibility testing must be performed as required before transfusion. Records must be maintained concurrently with each significant step so that all steps can be clearly traced, and must be retained for the required periods. Establishments must maintain a file of reports of adverse reactions, investigate complaints of adverse reactions, and report product deviations to FDA in accordance with the regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_obligations",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-601-biologics-licensing-and-establishment-licensing",
      "us-fda-21-cfr-211-cgmp-finished-pharmaceuticals",
      "fda-21-cfr-210-211-current-good-manufacturing-practice"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-21-cfr-801-medical-device-labeling",
    "title": "21 CFR Part 801 - Medical Device Labeling",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "21 CFR Part 801 sets out the FDA labeling requirements for medical devices. The label of a device in package form must conspicuously specify the name and place of business of the manufacturer, packer or distributor, qualified to reveal the connection where the named person is not the manufacturer. The labeling must bear adequate directions for use, meaning directions under which a layman can use the device safely for its intended uses, with intended use determined by the objective intent of the persons responsible for the labeling. Required label statements must appear with the prominence and conspicuousness required by section 502(c) of the Federal Food, Drug, and Cosmetic Act, and where dates are provided they must use the standardized year-month-day format. The label of every medical device, and every device package, must bear a unique device identifier (UDI) that meets the requirements of the subpart and of part 830, unless an exception applies. Prescription devices must be labeled in accordance with the prescription-device rules, including the limitation to use under the supervision of a licensed practitioner, and over-the-counter devices must bear the required statement of identity on the principal display panel. Devices that contain or come into contact with natural rubber latex must bear the required latex caution statement. Labeling that is false or misleading in any particular renders the device misbranded.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_obligations",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-510k-premarket-notification",
      "us-fda-21-cfr-part-820-quality-system-regulation-medical-devices",
      "us-21-cfr-part-803-medical-device-reporting-mdr"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-21-cfr-806-medical-devices-corrections-and-removals",
    "title": "US FDA Medical Device Corrections and Removals - 21 CFR Part 806 Notification, Recordkeeping and Reporting Requirements for Device Manufacturers and Importers",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "21 CFR Part 806 (Medical Devices; Reports of Corrections and Removals) is issued by the FDA under sections 519 and 701(a) of the Federal Food, Drug, and Cosmetic Act (21 U.S.C. 360i, 371(a)) to require medical device manufacturers and importers to report and maintain records of corrections and removals undertaken to reduce a risk to health posed by the device or to remedy a violation of the FFDCA caused by the device that may present a risk to health. Section 806.2 defines key terms including 'correction' (repair, modification, adjustment, relabeling, destruction, or inspection of a device without its physical removal to some other location) and 'removal' (the physical removal of a device from its point of use to some other location for repair, modification, adjustment, relabeling, destruction, or inspection). Section 806.10 requires manufacturers and importers to submit a written report to the FDA within 10 working days of initiating a correction or removal of a device to reduce a risk to health or remedy a violation caused by the device that may present a risk to health. Section 806.20 requires records of corrections and removals not required to be reported under §806.10 (because no risk to health is presented) to be retained at the manufacturer's or importer's establishment. Section 806.30 establishes the FDA's authority to release the reports to the public after appropriate redaction. The reports under Part 806 are separate from but related to Medical Device Reporting under 21 CFR Part 803 and from the Quality System Regulation corrective and preventive action (CAPA) requirements under 21 CFR Part 820.100.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-part-820-quality-system-regulation-medical-devices"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-21-cfr-807-device-establishment-registration-listing-510k",
    "title": "21 CFR Part 807 - Device Establishment Registration, Device Listing and 510(k) Premarket Notification",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "21 CFR Part 807 requires owners and operators of establishments engaged in the manufacture, preparation, propagation, compounding, assembly or processing of devices intended for human use to register their establishments with FDA and to list the devices they market, and it sets out the 510(k) premarket notification requirements. An establishment not otherwise exempt must register within 30 days of first entering into a covered operation, register annually during the period from October 1 to December 31 of each fiscal year, and update registration information within 30 days of any change. Registration and listing information must be submitted through FDA's electronic device registration and listing system unless a waiver is granted, and each owner or operator must maintain a historical file of labeling and advertisements. Foreign establishments that import or offer devices for import into the United States must register and identify importers and a United States agent. Except where exempt, a person required to register must submit a premarket notification (510(k)) to FDA at least 90 days before introducing a device into commercial distribution where the device is new, is being marketed by that person for the first time, or has been significantly changed; the submission must contain the information required, including the comparison establishing substantial equivalence. FDA reviews the submission and issues an order; the device may not be marketed until FDA determines it is substantially equivalent to a legally marketed predicate device.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_obligations",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-510k-premarket-notification",
      "us-fda-21-cfr-part-820-quality-system-regulation-medical-devices",
      "us-21-cfr-part-803-medical-device-reporting-mdr"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-21-cfr-812-investigational-device-exemptions",
    "title": "21 CFR Part 812 - Investigational Device Exemptions (IDE)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "21 CFR Part 812 sets out the FDA Investigational Device Exemption (IDE) requirements that permit a device that would otherwise require marketing clearance or approval to be shipped lawfully for the purpose of conducting a clinical investigation to collect safety and effectiveness data. The requirements turn on whether the device is a significant risk device or a nonsignificant risk device. A sponsor must submit an IDE application to FDA before beginning an investigation that uses a significant risk device, that involves an exception from informed consent, or where FDA requires an application, and must not begin until FDA has approved the application. The application must include an investigational plan stating the purpose, a scientifically sound protocol, a risk analysis, a description of the device, monitoring procedures, labeling and informed-consent materials. A sponsor may not begin an investigation until both the reviewing Institutional Review Board (IRB) and FDA have approved it. Sponsors are responsible for selecting qualified investigators, ensuring proper monitoring, obtaining IRB review, and promptly informing IRBs and FDA of significant new information; on discovering noncompliance or an unanticipated adverse device effect that presents an unreasonable risk, the sponsor must secure compliance or terminate the investigation, terminating within 5 working days of determining unreasonable risk. Investigators are responsible for conducting the investigation according to the signed agreement, the investigational plan and FDA regulations, protecting subjects, obtaining informed consent, and submitting reports, including reporting an unanticipated adverse device effect to the sponsor and reviewing IRB within 10 working days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "device_risk_categories",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-50-human-subjects-protection-clinical-research",
      "us-fda-pma-premarket-approval",
      "us-fda-510k-premarket-notification"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-21-cfr-830-unique-device-identification",
    "title": "21 CFR Part 830 - FDA Unique Device Identification (UDI)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "21 CFR Part 830 establishes the unique device identification (UDI) system administered by the U.S. Food and Drug Administration. A labeler of a medical device that is required to bear a unique device identifier must provide a UDI on the device label and device packages, in the required form, using a device identifier issued under a system operated by an FDA-accredited issuing agency or by the FDA acting as an issuing agency. The labeler must use and discontinue device identifiers correctly, use a new device identifier for changes that require one, and relabel devices that are required to bear a UDI. The labeler must determine which devices are subject to the device identification data submission requirements, submit the required information to the Global Unique Device Identification Database (GUDID), and do so within the required times. The UDI system supports device identification, adverse event reporting, recalls and supply chain traceability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-801-medical-device-labeling",
      "us-fda-21-cfr-807-device-establishment-registration-listing-510k",
      "us-fda-21-cfr-812-investigational-device-exemptions"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-fda-21-cfr-part-11-electronic-records",
    "title": "Title 21 CFR Part 11: Electronic Records; Electronic Signatures",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes the U.S. Food and Drug Administration (FDA) criteria for accepting electronic records and signatures as trustworthy, reliable, and equivalent to paper records for all FDA-regulated industries. It requires controls for closed and open systems, including audit trails, access security, and specific signature standards as detailed in Subparts B and C.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-820-qsr",
      "gxp-clinical-practice",
      "gxp-mfg-practice",
      "iso-13485-medical-qms",
      "iec-62304-medical-software"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-21-cfr-part-11-electronic-records-signatures",
    "title": "US FDA 21 CFR Part 11 - Electronic Records and Electronic Signatures in FDA-Regulated Industries",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "US FDA 21 CFR Part 11 establishes the criteria under which electronic records and electronic signatures are considered trustworthy, reliable, and equivalent to paper records and handwritten signatures for FDA-regulated activities. Applicable to pharmaceutical manufacturers, medical device companies, biologics producers, clinical trial sponsors, and any entity submitting electronic records to FDA. Core requirements include: closed and open system controls; audit trails capturing all record creation, modification, and deletion; computer system validation; access controls and user authentication; and electronic signature requirements including meaning attribution and manifestation. Non-compliance can result in FDA Warning Letters, consent decrees, and product recalls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-210-211-current-good-manufacturing-practice",
      "eu-pharma-gcp-directive-2005-28-clinical-trials-conduct"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-21-cfr-part-16-regulatory-hearing-procedure",
    "title": "21 CFR Part 16 - FDA Regulatory Hearing Procedure (Pre-Decision Hearings, Notices of Opportunity, Presiding Officer, Administrative Decision, Judicial Review)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "21 CFR Part 16 sets the procedural framework for the FDA regulatory hearing - the agency's pre-decision hearing mechanism used either at the Commissioner's discretion to obtain additional information before making a decision or because a statute or another regulation provides a person with an opportunity for a hearing on a regulatory action. Section 16.1 lists the statutory provisions under which Part 16 hearings are available, including section 304(g) of the FD&C Act (administrative detention of devices and drugs), and the regulatory provisions including a long list of cross-references to other 21 CFR Parts. Section 16.5 lists the proceedings to which Part 16 does not apply, including informal presentation of views before a criminal violation report under section 305 of the FD&C Act (governed by 21 CFR Part 7 Subpart E). Section 16.22 governs initiation - a regulatory hearing is initiated by a notice of opportunity for hearing from FDA, sent by mail, telegram, telex, personal delivery, or other mode of written communication, specifying the facts and the action that are the subject of the opportunity, stating the notice is governed by Part 16, stating the time within which a hearing may be requested (not less than 3 working days after receipt), and referring to the FDA electronic media coverage guideline in 21 CFR Part 10 Subpart C; if no response is filed within the time, the offer is deemed refused and no hearing will be held. Section 16.24 governs hearings required by the act or a regulation - the same procedural rules apply but the right to a hearing is statutory or regulatory rather than discretionary. Section 16.40 provides that whenever the Commissioner has delegated authority on a matter for which a regulatory hearing is available, the functions of the Commissioner under Part 16 may be performed by any of the officials to whom the authority has been delegated, including a center director. Section 16.60 governs the hearing procedure - the hearing is public except when the Commissioner determines that all or part of a hearing should be closed to prevent a clearly unwarranted invasion of personal privacy or disclosure of a trade secret or confidential commercial or financial information not available for public disclosure. Section 16.95 governs the administrative decision and record for decision. Section 16.119 permits a party to petition the Commissioner for reconsideration of any part or all of the decision or action after any final administrative action that is the subject of a hearing under Part 16. Section 16.120 provides that Section 10.45 governs the availability of judicial review concerning any regulatory action that is the subject of a hearing under Part 16.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "scope_anchor",
        "statutory_triggers_anchor",
        "inapplicability_anchor",
        "initiation_anchor",
        "presiding_officer_and_delegations_anchor",
        "hearing_procedure_anchor",
        "administrative_decision_anchor",
        "reconsideration_and_judicial_review_anchor",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-part-7-enforcement-policy-recalls",
      "us-fda-21-cfr-part-820-quality-system-regulation-medical-devices",
      "us-fda-21-cfr-part-821-medical-device-tracking-requirements",
      "us-fda-21-cfr-part-808-exemptions-federal-preemption-medical-device",
      "us-fda-510k-premarket-notification"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-fda-21-cfr-part-25-environmental-impact-nepa",
    "title": "21 CFR Part 25 - FDA Environmental Impact Considerations (NEPA Implementation: Environmental Assessments, Categorical Exclusions, Environmental Impact Statements)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "21 CFR Part 25 sets the FDA implementation of the National Environmental Policy Act of 1969 (NEPA) section 102(2) for FDA actions affecting FDA-regulated products including drugs, biologics, medical devices, tobacco products, and animal drugs. Section 25.1 establishes the purpose: NEPA directs that, to the fullest extent possible, the policies, regulations, and public laws of the United States shall be interpreted and administered in accordance with the policies set forth in NEPA; all agencies of the Federal Government shall comply with the procedures in section 102(2) of NEPA except where compliance would be inconsistent with other statutory requirements; the regulations implement section 102(2) of NEPA consistent with FDA's authority under the Federal Food, Drug, and Cosmetic Act and the Public Health Service Act, supplementing the Council on Environmental Quality (CEQ) procedural regulations at 40 CFR Parts 1500 through 1508 and the HHS General Administration Manual Part 30 (45 FR 76519). Section 25.15 sets the general procedures: all applications or petitions requesting agency action require the submission of an Environmental Assessment (EA) or a claim of categorical exclusion; a claim of categorical exclusion must include a statement of compliance with the categorical exclusion criteria and that no extraordinary circumstances exist. Section 25.20 lists FDA actions normally requiring at least an EA. Section 25.21 requires at least an EA where extraordinary circumstances indicate the action may significantly affect the human environment, including actions for which available data show potential for serious environmental harm at the expected exposure level, and actions that adversely affect a species or critical habitat under the Endangered Species Act or CITES, or wild flora or fauna with special Federal protection. Section 25.22 governs Environmental Impact Statements (EISs): there are no categories of agency actions that routinely significantly affect the human environment requiring an EIS; an EIS is prepared when EA evaluation or other information leads the responsible agency official to a finding that the action may significantly affect the human environment. Subpart C lists categorical exclusions: Section 25.31 lists human drug and biologic categorical exclusions including NDA, ANDA, biologic product marketing approval, and OTC monograph actions where the action does not increase use of the active moiety, where the estimated concentration at the point of entry into the aquatic environment will be below 1 part per billion, or where the substance occurs naturally in the environment without significant alteration. Section 25.40 sets the form and content of EAs (drawing on 40 CFR 1508.9 - a concise public document providing evidence and analysis for the agency to determine whether to prepare an EIS or a Finding of No Significant Impact (FONSI), including brief discussions of the need for the proposal, alternatives as required by NEPA section 102(2)(E), environmental impacts of the action and alternatives, and a list of agencies and persons consulted). Section 25.52 governs FDA EISs - if FDA determines that an EIS is necessary for an action involving investigations, approvals, or market authorizations for drugs, animal drugs, biologic products, devices, or tobacco products, an EIS will be prepared but will become available only at the time of approval or market authorization, and otherwise conforms to the requirements at 40 CFR Parts 1502 and 1506.6(f).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "purpose_anchor",
        "general_procedures_anchor",
        "actions_requiring_ea_anchor",
        "extraordinary_circumstances_anchor",
        "eis_requirement_anchor",
        "categorical_exclusions_anchor",
        "ea_form_and_content_anchor",
        "eis_form_and_timing_anchor",
        "industry_mapping",
        "interaction_with_other_environmental_regimes_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-part-820-quality-system-regulation-medical-devices",
      "us-fda-pma-premarket-approval",
      "us-fda-510k-premarket-notification",
      "us-fda-21-cfr-part-7-enforcement-policy-recalls",
      "medical-device-esg-sustainability-2026"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-fda-21-cfr-part-58-good-laboratory-practice-nonclinical",
    "title": "21 CFR Part 58 - Good Laboratory Practice for Nonclinical Laboratory Studies",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This regulation establishes the minimum standards for the conduct of nonclinical laboratory studies that support or are intended to support applications for research or marketing permits for products regulated by the Food and Drug Administration (FDA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-21-cfr-part-7-enforcement-policy-recalls",
    "title": "21 CFR Part 7 - Enforcement Policy: Recalls (Product Corrections), Health Hazard Evaluation, Recall Classification, and Industry Responsibilities",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "21 CFR Part 7 sets the FDA enforcement policy framework for recalls of FDA-regulated products and codifies the recall guidance for industry, health-hazard evaluation, recall classification, recall strategy, FDA-requested recall, firm-initiated recall, recall communications, public notification, recall status reports, and termination of a recall. Section 7.3 defines the operative terms: (g) recall as a firm's removal or correction of a marketed product that the FDA considers to be in violation of the laws it administers and against which the agency would initiate legal action (e.g., seizure); recall does not include a market withdrawal or a stock recovery; (h) correction as repair, modification, adjustment, relabeling, destruction, or inspection (including patient monitoring) of a product without its physical removal; (j) market withdrawal as a firm's removal or correction involving a minor violation not subject to legal action or no violation (e.g., normal stock rotation); (k) stock recovery as a firm's removal or correction of a product that has not been marketed or that has not left the direct control of the firm; (l) recall strategy as a planned specific course of action addressing depth of recall, public warnings, and extent of effectiveness checks; (m) recall classification as the numerical designation (Class I, II, or III) indicating relative degree of health hazard: Class I is a reasonable probability of serious adverse health consequences or death, Class II is temporary or medically reversible adverse health consequences (or remote serious consequences), Class III is unlikely to cause adverse health consequences. Section 7.40 establishes recall as a voluntary action taken by manufacturers and distributors to protect public health. Section 7.41 requires an ad hoc FDA scientist committee to evaluate the health hazard considering occurrences of disease or injuries, existing exposure conditions, hazard assessment to population segments (children, surgical patients, pets, livestock), seriousness, likelihood, and consequences (immediate or long-range). Section 7.42 sets recall strategy elements: depth of recall (consumer/user level, retail level, or wholesale level), public warning (reserved for urgent situations - general public warning, or targeted), effectiveness checks (A=100%, B=2-100%, C=10%, D=2%, E=none), and product disposition. Section 7.45 authorises FDA-requested recall where the product presents risk of illness or injury or gross consumer deception, the firm has not initiated a recall, and agency action is necessary. Section 7.46 governs firm-initiated recalls including the FDA notification within 24 hours and the information to be submitted. Section 7.49 prescribes recall communications (telegrams, mailgrams, first class letters marked 'drug [or food, biologic, etc.] recall [or correction]', and 'urgent' for Class I and II recalls). Section 7.50 publishes recalls in the weekly FDA Enforcement Report. Section 7.53 requires periodic recall status reports (typically every 2-4 weeks) including consignees notified, response rate, products returned or corrected, and effectiveness check results. Section 7.55 terminates a recall when reasonable efforts have been made and proper disposition or correction is complete.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "definitions_anchor",
        "recall_policy_anchor",
        "health_hazard_evaluation_anchor",
        "recall_strategy_anchor",
        "fda_requested_recall_anchor",
        "firm_initiated_recall_anchor",
        "recall_communication_anchor",
        "public_notification_and_status_reports_anchor",
        "criminal_violations_anchor",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-part-803-medical-device-reporting",
      "us-fda-21-cfr-806-medical-devices-corrections-and-removals",
      "us-fda-21-cfr-part-820-quality-system-regulation-medical-devices",
      "us-fda-21-cfr-part-821-medical-device-tracking-requirements",
      "us-drug-supply-chain-security-act-2023-dscsa"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-fda-21-cfr-part-803-medical-device-reporting",
    "title": "21 CFR Part 803 - Medical Device Reporting",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This regulation establishes requirements for medical device user facilities, importers, and manufacturers to report adverse events and other device-related problems to the FDA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-21-cfr-part-808-exemptions-federal-preemption-medical-device",
    "title": "21 CFR Part 808 - Exemptions from Federal Preemption of State and Local Medical Device Requirements (FDA Section 521 Petitions)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "21 CFR Part 808 prescribes the procedures by which a State or political subdivision may apply to the U.S. Food and Drug Administration for an exemption from the Federal preemption of State and local requirements applicable to medical devices under section 521 of the Federal Food, Drug, and Cosmetic Act (21 USC 360k). Section 808.1 provides that the FDA Commissioner may grant an exemption only where the State requirement is more stringent than a requirement under the Federal Food, Drug, and Cosmetic Act applicable to the device, or the State requirement is required by compelling local conditions and compliance with the State requirement would not cause the device to be in violation of any applicable requirement under the Federal Food, Drug, and Cosmetic Act. Section 808.5 authorises any State or interested party to request an advisory opinion from the Commissioner on whether the FDA regards a particular State or local requirement as preempted - the Commissioner may treat the request as an application for exemption from preemption. Section 808.20 sets the application format - a letter to the Commissioner signed by an authorised State or local representative attaching the statute or regulation, the comparison with the analogous Federal requirement, the problem identification, and the basis for exemption on either greater stringency or compelling local conditions. Section 808.25 sets the review procedure - the Commissioner publishes a proposed rule in the Federal Register with notice of opportunity to request an oral hearing, considers comments and any hearing record, and publishes a final rule granting, conditionally granting, or denying the exemption. Section 808.35 sets the revocation criteria - an exemption remains effective until revoked, and may be revoked when new Federal requirements address the objective served by the exempted State requirement, when the conditions underlying the original grant change, when the State fails to meet conditions of the original grant or to submit records the Commissioner requires, when the State requests revocation, or when the Commissioner determines the exemption is no longer in the public health interest. Subpart C codifies the operative grants and denials state by state - Section 808.55 records that specific provisions of the California Sherman Food, Drug, and Cosmetic Law and the California Business and Professions Code are preempted under section 521(a) and have been denied exemption from preemption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "scope_anchor",
        "advisory_opinion_anchor",
        "application_anchor",
        "review_procedure_anchor",
        "exemption_revocation_anchor",
        "state_specific_codification_anchor",
        "industry_mapping",
        "statutory_foundation_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-part-820-quality-system-regulation-medical-devices",
      "us-fda-pma-premarket-approval",
      "us-fda-510k-premarket-notification",
      "eu-mdr-2017-745",
      "us-fda-21-cfr-part-803-medical-device-reporting"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-21-cfr-part-814-subpart-h-humanitarian-device-exemption",
    "title": "21 CFR Part 814 Subpart H - Humanitarian Use Devices (HUDs) and Humanitarian Device Exemption (HDE) Pathway for Rare Disease and Pediatric Subpopulation Medical Devices",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "21 CFR Part 814 Subpart H implements section 515A and section 520(m) of the Federal Food, Drug, and Cosmetic Act (FD&C Act) and creates the Humanitarian Device Exemption (HDE) marketing pathway for devices intended to benefit patients in the treatment or diagnosis of diseases or conditions that affect or are manifested in not more than 8,000 individuals in the United States per year. Section 814.100(a) sets the scope of the subpart as implementing FD&C Act sections 515A and 520(m). Section 814.100(b) defines the purpose of section 520(m) - to encourage the discovery and use of devices intended to benefit patients in the treatment or diagnosis of rare diseases or conditions, subject to the 8,000-individual-per-year threshold; the subpart provides procedures for (1) HUD designation of a medical device and (2) marketing approval for the HUD notwithstanding the absence of reasonable assurance of effectiveness that would otherwise be required under sections 514 and 515 of the FD&C Act. Section 814.100(c) implements section 515A pediatric-subpopulation information requirements. Section 814.102 governs HUD designation - the applicant submits a request to FDA's Office of Orphan Products Development (OOPD) before submitting an HDE, including identification of the rare disease or condition with specificity, a demonstration that any disease subset is medically plausible, a description of the rare disease and proposed indications for use, and the reasons why such therapy is needed. Section 814.104 governs original HDE applications - the applicant or authorized representative signs the HDE; if the applicant does not reside or have a place of business in the United States, the HDE is countersigned by an authorized U.S. representative; the HDE includes a copy of the OOPD HUD determination and the device-specific application content. Section 814.106 permits HDE amendments and resubmissions for the same reasons and in the same manner as PMAs. Section 814.108 governs supplemental applications after FDA approval. Section 814.110 requires a new HUD designation for a new indication for use. Section 814.112 governs filing - FDA decides within 30 days whether the application is sufficiently complete to permit substantive review and may refuse to file an incomplete application. Section 814.116 governs FDA substantive review. Section 814.118 governs denial or withdrawal of HDE approval for failure to meet section 520(m) requirements, Part 814 requirements, IRB approval conditions, or postapproval requirements. Section 814.120 permits temporary suspension. Section 814.122 sets confidentiality requirements for the HDE file.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "scope_and_purpose_anchor",
        "pediatric_subpopulation_anchor",
        "hud_designation_anchor",
        "original_hde_application_anchor",
        "amendments_supplements_and_new_indications_anchor",
        "filing_and_review_anchor",
        "denial_suspension_and_withdrawal_anchor",
        "confidentiality_anchor",
        "industry_mapping",
        "interaction_with_other_regimes_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-21-cfr-part-814-premarket-approval-medical-devices",
      "us-fda-pma-premarket-approval",
      "us-fda-21-cfr-part-820-quality-system-regulation-medical-devices",
      "us-fda-21-cfr-part-803-medical-device-reporting",
      "us-fda-21-cfr-812-investigational-device-exemptions"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-fda-21-cfr-part-820-quality-system-regulation-medical-devices",
    "title": "US FDA 21 CFR Part 820 - Quality System Regulation (QSR) for Medical Device Manufacturers",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "21 C.F.R. Part 820 (Quality System Regulation) establishes Current Good Manufacturing Practice (CGMP) requirements for medical device manufacturers. The FDA amended Part 820 in 2024 to align with ISO 13485:2016, updating design controls, production controls, document management, and complaint handling. Manufacturers must maintain a Quality Management System (QMS) documented through Design History Files and Device Master Records.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-hipaa-security-rule-45-cfr-164-technical-safeguards"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fda-21-cfr-part-821-medical-device-tracking-requirements",
    "title": "21 CFR Part 821 - Medical Device Tracking Requirements (FDA Tracking Orders for Class II and Class III Devices)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "21 CFR Part 821 implements section 519(e) of the Federal Food, Drug, and Cosmetic Act and prescribes the FDA medical device tracking regime applicable to Class II or Class III devices where a failure of the device would be reasonably likely to have serious adverse health consequences, devices intended to be implanted in the human body for more than one year, or devices intended to be a life-sustaining or life-supporting device used outside a device user facility. Section 821.1(c) places the primary burden of ensuring the tracking system works on the manufacturer. Tracking is not automatic by class - under section 821.20(a) a device only becomes a tracked device when the FDA issues a tracking order to the manufacturer in a premarket notification, premarket approval response, or postmarket order. Section 821.25 requires a manufacturer of a tracked device to adopt a tracking system that allows it to provide FDA, within three working days of an FDA request prior to distribution, with the name, address, telephone number, and location of the distributor or multiple distributor holding the device, and within ten working days of an FDA request after distribution to a single-patient device, the unique device identifier (UDI), lot number, batch number, model number, or serial number, the date shipped by the manufacturer, the name, mailing address, telephone number, and social security number of the patient (subject to patient release under section 821.55(a)), the date the device was provided to the patient, the prescribing and following physician details, and where applicable the explant date and explanting physician, the patient death date, or the date the device was returned, retired, or permanently disposed of. Section 821.25(c) requires a written standard operating procedure including a quality assurance audit at not less than six-month intervals for the first three years of distribution and at least once a year thereafter. Section 821.30 places downstream obligations on distributors, final distributors, and multiple distributors to promptly forward identifiers, receipt dates, prescribing physician details, and patient information to the manufacturer; multiple distributors must respond to manufacturer requests within five working days and to FDA requests within ten working days. Section 821.50 makes records available to FDA upon presentation of credentials and FDA Form 482 and requires centralized U.S. recordkeeping. Section 821.55 lets a patient refuse release of identifying information and protects records from public disclosure under 21 CFR Part 20. Section 821.60 requires retention for the useful life of the tracked device. Section 821.2 permits petitions for exemption or variance under the procedures in 21 CFR 10.30.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "scope_anchor",
        "tracking_order_anchor",
        "manufacturer_obligations_anchor",
        "distributor_obligations_anchor",
        "records_confidentiality_retention_anchor",
        "industry_mapping",
        "udi_intersection_anchor",
        "exemption_petition_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-part-803-medical-device-reporting",
      "us-fda-21-cfr-830-unique-device-identification",
      "us-fda-21-cfr-806-medical-devices-corrections-and-removals",
      "us-fda-21-cfr-part-820-quality-system-regulation-medical-devices",
      "udi-system-medical-devices-2026"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-21-cfr-part-99-dissemination-information-unapproved-uses",
    "title": "21 CFR Part 99 - Dissemination of Information on Unapproved/New Uses for Marketed Drugs, Biologics, and Devices (FDA Off-Label Information Regime)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "21 CFR Part 99 governs the dissemination by a manufacturer of written information on a use of an approved or cleared drug, biologic, or device that is not included in the FDA-approved labeling or the cleared statement of intended use (off-label or new-use information), where the information will be disseminated to a health care practitioner, pharmacy benefit manager, health insurance issuer, group health plan, or Federal or State Government agency. Section 99.1 sets the scope (it does not apply to a manufacturer's response to an unsolicited request from a health care practitioner). Section 99.3 defines clinical investigation as an investigation in humans that tests a specific clinical hypothesis, and defines health care practitioner, group health plan, health insurance issuer, and pharmacy benefit manager. Section 99.101 permits dissemination of an unabridged reprint of a peer-reviewed article from a scientific or medical journal about a clinical investigation considered scientifically sound by experts qualified by scientific training or experience, or an unabridged reference publication including information about a clinical investigation, provided the drug or device has been approved, licensed, or cleared by FDA, the dissemination does not pose a significant risk to public health, and is not false or misleading. Section 99.103 requires mandatory statements including a prominently displayed disclosure on the front of each reprint reading 'This information concerns a use that has not been approved by the Food and Drug Administration' (for drugs) or 'This information concerns a use that has not been approved or cleared by the Food and Drug Administration' (for devices), disclosure of manufacturer financial sponsorship, and identification of authors with significant financial ties to the manufacturer during the study and one year post-publication. Section 99.105 limits recipients to health care practitioners, pharmacy benefit managers, health insurance issuers, group health plans, or Federal or State Government agencies. Section 99.201 requires the manufacturer to submit to FDA, sixty days before disseminating any written information, an identical copy of the information, the bibliography, and any required statements. Section 99.203 lets a manufacturer request to extend the time for completing planned studies. Section 99.205 permits an application for exemption from the requirement to file a supplemental application where it would be economically prohibitive or unethical to conduct the studies necessary. Section 99.301 sets FDA agency action on a submission within 60 days, including determining non-compliance, requiring additional information for objectivity and balance, requiring an FDA-prepared objective statement, or requiring records identifying individual recipients. Section 99.401 provides FDA corrective actions and cessation of dissemination, including an order to cease dissemination after notice and opportunity for a meeting when noncompliance is more than minor or when post-dissemination data show ineffectiveness or significant risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "scope_anchor",
        "definitions_anchor",
        "permitted_information_anchor",
        "mandatory_statements_anchor",
        "recipients_anchor",
        "submission_to_fda_anchor",
        "fda_agency_action_anchor",
        "corrective_action_anchor",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-part-820-quality-system-regulation-medical-devices",
      "us-fda-510k-premarket-notification",
      "us-fda-pma-premarket-approval",
      "us-fda-21-cfr-part-7-enforcement-policy-recalls",
      "us-anti-kickback-statute"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-fda-21st-century-cures-act-updates-2026",
    "title": "US 21st Century Cures Act & ONC Information Blocking Final Rule (2026 Enforcement)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The 21st Century Cures Act and ONC Final Rule prohibit information blocking with expanded enforcement in 2026, including civil monetary penalties up to $1 million per violation. Actors must provide API access to electronic health information, support patient access without special effort, and comply with certification updates. Exceptions are narrowly defined and must be documented.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "us-fda-510k-premarket-notification",
    "title": "Premarket Notification 510(k) - Substantial Equivalence Submission for Medical Devices",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Requires medical device manufacturers to submit a Premarket Notification, or 510(k), to the FDA at least 90 days before marketing a device to demonstrate it is substantially equivalent to a legally marketed predicate device, as mandated by Section 510(k) of the Federal Food, Drug, and Cosmetic Act and detailed in 21 CFR Part 807 Subpart E.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-820-qsr",
      "iso-13485-medical-qms",
      "iso-14971-medical-risk",
      "iec-62304-medical-software",
      "fda-cybersecurity-medical-devices-premarket"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-accelerated-approval-subpart-h-e",
    "title": "US FDA Accelerated Approval Pathway (21 CFR Subpart H/E) - Surrogate Endpoint Basis, Confirmatory Trial Requirements, Post-Marketing Conditions and Expedited Withdrawal Procedures Under FDORA 2022",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-12-29",
    "bluf": "The FDA Accelerated Approval Program allows for earlier approval of drugs that treat serious conditions and fill an unmet medical need based on a surrogate endpoint reasonably likely to predict clinical benefit. As mandated by 21 CFR 314.510 and 21 CFR 601.41, sponsors must conduct post-approval confirmatory trials to verify clinical benefit, with the Food and Drug Omnibus Reform Act of 2022 (FDORA) strengthening FDA's authority to enforce these requirements and expedite withdrawal if trials fail.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-ai-ml-action-plan-2021",
    "title": "Artificial Intelligence/Machine Learning (AI/ML)-Based Software as a Medical Device (SaMD) Action Plan",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-01-12",
    "bluf": "This action plan outlines the FDA's multi-pronged approach to regulating AI/ML-based Software as a Medical Device (SaMD), focusing on a total product lifecycle framework that includes a Predetermined Change Control Plan (PCCP) for managing algorithm modifications. It applies to all manufacturers developing and marketing AI/ML-based SaMD in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-software-as-medical-device-2019",
      "good-machine-learning-practice-medical-devices",
      "fda-predetermined-change-control-2024",
      "fda-real-world-evidence-program",
      "iso-13485-medical-qms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-aiml-samd-pccp-final-guidance-2024",
    "title": "US FDA Final Guidance on Predetermined Change Control Plans for AI-Enabled Device Software Functions, December 2024",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Manufacturers of AI-enabled medical devices (Software as a Medical Device and software functions in or as devices) submitting marketing applications to the US FDA should incorporate a Predetermined Change Control Plan (PCCP) under the FDA Final Guidance for Industry on Predetermined Change Control Plans for Artificial Intelligence-Enabled Device Software Functions released 4 December 2024, enabling pre-authorised device modifications during the product lifecycle without filing a new marketing application, with the final guidance expanding scope from machine learning-enabled devices in the draft to all AI-enabled devices, providing additional detail on the interplay between PCCPs and modifications that require new marketing submissions, the content to include in the Description of Modifications section, and labeling considerations, supporting a lifecycle-oriented approach that accommodates the iterative, self-modifying nature of AI while maintaining regulatory control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-samd-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fda-amendments-act-2007-fdaaa-pl-110-85",
    "title": "US FDA Amendments Act 2007 FDAAA Public Law 110-85 REMS Risk Evaluation and Mitigation Strategies Post-Market Safety Authority Clinical Trial Registration and User Fees",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "The Food and Drug Administration Amendments Act of 2007 Public Law 110-85 enacted on 27 September 2007 substantially expands FDA authority to ensure post-market drug safety organised in nine titles covering Title I Prescription Drug User Fee Act IV (PDUFA IV) reauthorising FDA user fees through fiscal year 2012 Title II Medical Device User Fee Act II reauthorising medical device user fees Title III Pediatric Medical Device Safety and Improvement Act establishing pediatric medical device tracking Title IV Pediatric Research Equity Act and Best Pharmaceuticals for Children Act reauthorisation requiring pediatric studies of drugs Title V Reagan-Udall Foundation establishing the public-private foundation for FDA modernisation Title VI Reportable Food Registry Title VII Conflicts of Interest reforms for FDA advisory committees Title VIII Citizen Petitions reforms requiring FDA response within 150 days and Title IX Drug Safety expanding FDA post-market authority including Section 901 establishing Risk Evaluation and Mitigation Strategies (REMS) under section 505-1 of the FD&C Act Section 902 active risk identification and analysis Section 903 labelling changes ordered by FDA Section 904 post-market studies and clinical trials Section 905 FDAAA clinical trial registration in ClinicalTrials.gov Section 906 medication guides Section 907 advisory committee meetings Section 908 pharmacovigilance system and Section 909 enforcement including civil monetary penalties for noncompliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-biologics-bla-351-phsa",
    "title": "Biologics License Applications (BLA) Process (CBER) - Request for Permission to Introduce a Biologic Product into Interstate Commerce under 21 CFR 601.2",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation governs the submission and approval of Biologics License Applications (BLAs) for introducing biologic products into interstate commerce, as required under 21 CFR 601.2. It applies to any legal person or entity engaged in the manufacture or licensing of biologics and mandates compliance with product, manufacturing, pre-clinical, clinical, and labeling requirements specified in 21 CFR 600-680.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-guidance-human-gene-therapy-2020",
      "ich-q5a-r2-viral-safety-biotech-2024",
      "ich-e8-r1-general-considerations-clinical-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fda-biosimilar-351k-regulatory-pathway",
    "title": "US FDA Biosimilar Approval Pathway (Section 351(k) Public Health Service Act): Analytical Similarity, Extrapolation, Interchangeability, and Purple Book Listing",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Section 351(k) of the Public Health Service Act, a biological product may be approved as a biosimilar if data demonstrates it is highly similar to an already FDA-approved biological product (the reference product) with no clinically meaningful differences. This abbreviated pathway applies to pharmaceutical companies seeking to market biosimilar or interchangeable biological products in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-cfr-21-part-11-electronic-records",
    "title": "21 CFR Part 11 - Electronic Records; Electronic Signatures",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation outlines the scope, implementation, definitions, and controls for electronic records and electronic signatures in closed and open systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-cfr-21-part-11-electronic-records-signatures",
    "title": "21 CFR Part 11 - Electronic Records; Electronic Signatures",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes the criteria under which the U.S. Food and Drug Administration considers electronic records, electronic signatures, and handwritten signatures executed to electronic records to be trustworthy, reliable, and generally equivalent to paper records and handwritten signatures executed on paper.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-cfr-21-part-312-ind-application",
    "title": "21 CFR Part 312 - Investigational New Drug Application",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes the requirements for submitting and maintaining an Investigational New Drug Application (IND), detailing the responsibilities of sponsors and investigators in conducting clinical trials.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "us-fda-cfr-21-part-314-new-drug-applications",
    "title": "21 CFR Part 314 - Applications for FDA Approval to Market a New Drug",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation outlines the requirements for submitting, amending, and maintaining applications for FDA approval to market a new drug, including postmarketing reporting obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-cfr-21-part-50-protection-human-subjects",
    "title": "21 CFR Part 50 - Protection of Human Subjects",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations conducting clinical investigations involving human subjects must obtain and document informed consent, adhering to specific required elements and implementing additional safeguards for vulnerable populations such as children.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-cfr-21-part-820-quality-system-regulation",
    "title": "21 CFR Part 820 - Quality Management System Regulation",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Manufacturers of medical devices must establish, document, and maintain a quality management system (QMS) that complies with ISO 13485 and specific FDA requirements for record control, labeling, and packaging.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fda-combination-products-21-cfr-3",
    "title": "US FDA Combination Products - 21 CFR Part 3: Device/Drug/Biologic Combination Classification, Primary Mode of Action (PMOA) Determination, Intercenter Agreement (ICA) Assignment, Integrated Review Process, NDA/PMA/BLA Pathway Selection and Post-Market Surveillance Responsibilities",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation governs the classification, jurisdictional assignment, and regulatory pathway for combination products consisting of drugs, devices, and/or biological products under 21 CFR Part 3. It requires sponsors to determine the primary mode of action (PMOA) and follow Intercenter Agreement (ICA) procedures when multiple FDA centers are involved, as defined in the Combination Product guidance documents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-pma-premarket-approval",
      "canada-food-drug-regulations-division-5-clinical-trials",
      "eu-ema-centralised-procedure-regulation-726-2004",
      "eu-medical-devices-regulation-mdr-2017-745-implementation",
      "eu-atmp-regulation-1394-2007-advanced-therapies"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fda-food-allergen-labelling-consumer-protection-2004",
    "title": "Food Allergen Labeling and Consumer Protection Act of 2004",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "Requires all packaged foods regulated by the FDA to clearly declare the presence of any of the 'Big 9' major food allergens (milk, eggs, fish, crustacean shellfish, tree nuts, peanuts, wheat, soybeans, and sesame) in plain language on the label. Applies to all food manufacturers, packers, and distributors under FDA jurisdiction. Key requirement: FALCPA Section 209, 21 U.S.C. § 343(w).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "brc-food-safety-standard-issue-9",
      "codex-haccp-2022",
      "eu-food-labelling-regulation-1169-2011"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fda-food-facility-registration",
    "title": "Registration of Food Facilities (21 CFR Part 1, Subpart H) under the Public Health Security and Bioterrorism Preparedness and Response Act of 2002",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation requires domestic and foreign facilities that manufacture, process, pack, or hold food for human or animal consumption in the United States to register with the Food and Drug Administration (FDA). As mandated by the Bioterrorism Act of 2002 and codified in 21 CFR § 1.230, this registration must be renewed biennially to ensure the FDA has up-to-date information for emergency response and food safety oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-fsma-compliance",
      "haccp-food-safety",
      "brc-food-safety-global",
      "sqf-edition-9-safety",
      "fda-food-labeling-guide"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-food-facility-registration-bioterrorism-act",
    "title": "US FDA Food Facility Registration - Bioterrorism Act Section 305: Mandatory Registration for Domestic and Foreign Facilities, Biennial Re-Registration, Prior Notice for Imported Food, Suspension of Registration Authority and Voluntary Qualified Importer Program (VQIP)",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The US FDA requires all domestic and foreign facilities that manufacture, process, pack, or hold food for human or animal consumption in the United States to register with the FDA under Section 305 of the Public Health Security and Bioterrorism Preparedness and Response Act of 2002. Registration must be renewed every two years, and failure to comply may result in facility registration suspension and import refusal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-food-hygiene-regulation-852-2004",
      "brc-food-safety-global"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fda-food-safety-modernization-act-21-usc-2201-preventive-controls",
    "title": "US FDA FSMA 21 USC 2201 - Food Safety Modernization Act Preventive Controls for Human Food",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2016-09-17",
    "bluf": "FDA Food Safety Modernization Act (FSMA) requires food facilities to implement written food safety plans with hazard analysis, preventive controls, monitoring, corrective actions, and verification procedures; foreign suppliers must be approved under FSVP; and produce growers must comply with produce safety standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-210-211-current-good-manufacturing-practice",
      "us-ftc-act-section-5-15-usc-45-unfair-deceptive-practices"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fda-food-traceability-rule-21-cfr-1-subpart-s",
    "title": "FDA Food Traceability Rule - Additional Traceability Records for Certain Foods (21 CFR Part 1, Subpart S; FSMA section 204)",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "This FSMA section 204 rule requires persons who manufacture, process, pack, or hold foods on the Food Traceability List to keep additional traceability records: a traceability plan, assignment of traceability lot codes at defined events, and Key Data Elements captured at Critical Tracking Events (harvesting, cooling, initial packing, first land-based receiving, shipping, receiving, and transformation), retrievable within 24 hours; FDA has extended the compliance date to 20 July 2028.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-food-safety-modernization-act-21-usc-2201-preventive-controls",
      "us-fda-fsma-supplier-verification-fsvp-2017",
      "us-21-cfr-part-117-fsma-preventive-controls-human-food"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-fsma-preventive-controls-human-food-2016",
    "title": "FSMA Final Rule for Preventive Controls for Human Food - 21 CFR Part 117: Hazard Analysis, Preventive Controls (Process/Allergen/Sanitation/Supply Chain), Monitoring, Corrective Actions, Verification, Recall Plan and Qualified Facility Exemption",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation requires domestic and foreign food facilities registered under section 415 of the FD&C Act to develop and implement a written food safety plan that includes hazard analysis and risk-based preventive controls to minimize or prevent biological, chemical, and physical hazards. Key requirements include process, allergen, sanitation, and supply-chain controls, monitoring, corrective actions, verification, and a recall plan as specified in the rule.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-food-hygiene-regulation-852-2004",
      "brc-food-safety-standard-issue-9"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fda-fsma-supplier-verification-fsvp-2017",
    "title": "Foreign Supplier Verification Programs (FSVP) for Importers of Food for Humans and Animals - 21 CFR Part 1, Subpart L",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The FSVP rule requires U.S. importers to perform risk-based foreign supplier verification activities to ensure that imported food is produced in a manner providing the same level of public health protection as required under sections 418 or 419 of the FD&C Act, is not adulterated under section 402, and is not misbranded under section 403(w) regarding allergen labeling. This applies to the U.S. owner or consignee of food offered for import.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-food-hygiene-regulation-852-2004",
      "brc-food-safety-global",
      "iso-20022-messaging"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fda-good-machine-learning-practice-2021",
    "title": "FDA / Health Canada / UK MHRA - Good Machine Learning Practice for Medical Device Development - 10 Guiding Principles (October 27, 2021)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On October 27, 2021 the US Food and Drug Administration jointly with Health Canada and the United Kingdom Medicines and Healthcare products Regulatory Agency (MHRA) published the Good Machine Learning Practice (GMLP) for Medical Device Development - 10 Guiding Principles. The Principles establish a tri-national agreed-upon baseline for the development of AI and machine learning medical devices throughout the product lifecycle. The 10 Principles are: (1) Multi-disciplinary expertise is leveraged throughout the total product life cycle; (2) Good software engineering and security practices are implemented; (3) Clinical study participants and data sets are representative of the intended patient population; (4) Training data sets are independent of test sets; (5) Selected reference datasets are based upon best available methods; (6) Model design is tailored to the available data and reflects the intended use of the device; (7) Focus is placed on the performance of the human-AI team; (8) Testing demonstrates device performance during clinically relevant conditions; (9) Users are provided clear, essential information; (10) Deployed models are monitored for performance and re-training risks are managed. The Principles are voluntary international baseline and are operationalised by FDA SaMD action plans, Health Canada AI/ML medical device guidance, and UK MHRA software and AI medical device pre-market guidance. GMLP underpins the FDA Predetermined Change Control Plan (PCCP) framework for AI/ML SaMD.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "nist_framework",
        "iso_standard",
        "regulatory_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-ai-ml-samd-action-plan",
      "us-fda-aiml-samd-pccp-final-guidance-2024",
      "fda-samd-action-plan-2022"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-fda-hazard-analysis-ccp-seafood-21-cfr-123",
    "title": "Hazard Analysis and Critical Control Point (HACCP) Systems for Fish and Fishery Products",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires all processors of fish and fishery products to conduct a hazard analysis, identify critical control points (CCPs), establish critical limits, and implement monitoring, corrective actions, and verification procedures. It applies to all facilities that manufacture, process, pack, or hold fish and fishery products for human consumption in the United States, as mandated under 21 CFR Part 123, Section 123.6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-haccp-2022",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-ldt-final-rule-2024",
    "title": "FDA Final Rule on Laboratory Developed Tests (LDTs) - 21 CFR 809.3 Amendment and 4-Year Phaseout (May 2024)",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "FDA's Final Rule on Medical Devices - Laboratory Developed Tests (89 FR 37286, published 6 May 2024, effective 5 July 2024) amends 21 CFR Section 809.3 to make explicit that in vitro diagnostic products (IVDs) are medical devices under the Federal Food, Drug, and Cosmetic Act (FD&C Act) including when manufactured by a laboratory. The rule phases out FDA's general enforcement discretion for LDTs over five stages: Stage 1 (1 year after publication, ~May 2025) - Medical Device Reporting (MDR), correction and removal reporting, and Quality System (QS) Section 820.198 complaint files; Stage 2 (2 years, ~May 2026) - registration and listing under 21 U.S.C. 360 and 21 CFR Parts 607 and 807; labeling under 21 U.S.C. 352 and 21 CFR Parts 801 and 809 Subpart B; investigational use under 21 U.S.C. 360j(g) and 21 CFR Part 812; Stage 3 (3 years, ~May 2027) - full QS regulation under 21 CFR Part 820; Stage 4 (3.5 years, ~Nov 2027) - premarket review for high-risk IVDs offered as LDTs; Stage 5 (4 years, ~May 2028) - premarket review for moderate-risk and low-risk IVDs requiring premarket submission. Continuing enforcement discretion applies to: currently marketed IVDs offered as LDTs; HCT/P-related LDTs in blood and cell-and-gene therapy laboratories; LDTs for unmet needs; LDTs for rare diseases; public-health surveillance LDTs; forensic LDTs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_fda_21_cfr_part_820_qsr",
        "us_fda_21_cfr_part_812_ide",
        "us_fda_510k_clearance",
        "clia_clinical_laboratory_improvement_amendments",
        "hipaa_privacy_rule"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-820-qsr",
      "us-fda-510k-premarket-notification",
      "fda-21-cfr-part-11-records"
    ],
    "primary_citations_count": 18
  },
  {
    "node_id": "us-fda-modernization-act-1997-pl-105-115",
    "title": "US Food and Drug Administration Modernization Act of 1997 (Public Law 105-115) - FDA Statutory Reform",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Food and Drug Administration Modernization Act of 1997 reauthorised the Prescription Drug User Fee Act, created an accelerated approval pathway for drugs treating serious or life-threatening conditions, codified the fast track designation, authorised dissemination of peer-reviewed information on unapproved uses under specified conditions, established a database of clinical trials for serious or life-threatening diseases that became ClinicalTrials.gov, allowed expanded access for individual patients to investigational drugs, restructured medical device approval pathways, allowed manufacturers to use national consensus standards in 510(k) submissions, and required FDA to issue good guidance practices regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-pdufa-prescription-drug-user-fee-act"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fda-pma-premarket-approval",
    "title": "US FDA Premarket Approval (PMA) - Application Requirements for Class III High-Risk Medical Devices",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Premarket Approval (PMA) is the most stringent marketing application required by the FDA for Class III medical devices, which are those that support or sustain human life, are of substantial importance in preventing impairment of human health, or present a potential, unreasonable risk of illness or injury. As mandated by 21 CFR Part 814, applicants must provide valid scientific evidence demonstrating a reasonable assurance of the device's safety and effectiveness for its intended use.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-820-qsr",
      "iso-14971-medical-risk",
      "gxp-clinical-practice",
      "fda-21-cfr-part-11-records",
      "fda-cybersecurity-medical-devices-premarket"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fda-qmsr-21-cfr-820-technical-amendments-2025",
    "title": "FDA Quality Management System Regulation (QMSR) - 21 CFR Part 820 incorporating ISO 13485:2016, with 2025 Technical Amendments",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-27",
    "bluf": "21 CFR Part 820, the Quality Management System Regulation (QMSR), sets out current good manufacturing practice (CGMP) requirements and requires manufacturers to document a quality management system that complies with the applicable requirements of ISO 13485 (incorporated by reference, see section 820.7) and other applicable requirements of this part; manufacturers engaged in the design, manufacture, packaging, labeling, storage, installation, or servicing of a finished device must establish and maintain a quality management system appropriate for their specific devices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-part-820-quality-system-regulation-medical-devices",
      "iso-13485-2016-medical-devices-quality-management",
      "us-fda-cfr-21-part-820-quality-system-regulation"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fda-real-world-evidence-programme-pharma",
    "title": "US FDA Real-World Evidence Programme 2018 - RWE Framework for Drug and Biological Products: Real-World Data Sources, Study Designs, Data Standards, Regulatory Submissions and Programme Guidance",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation outlines the FDA's framework for using real-world data (RWD) and real-world evidence (RWE) to support regulatory decisions for drugs and biological products, including approval of new indications under section 505(c) of the FD&C Act and post-approval study requirements. It applies to sponsors of drug and biological products seeking to use RWE in submissions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21st-century-cures-act-digital-health-provisions",
      "fda-real-world-evidence-program-guidance-2018",
      "fda-21-cfr-part-314-nda-new-drug-application",
      "fda-21-cfr-part-600-601-biologics-licensing",
      "fda-pdufa-vii-goals-letter-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fda-rwe-framework-real-world-evidence-2023",
    "title": "Considerations for the Use of Real-World Data and Real-World Evidence to Support Regulatory Decision-Making for Drug and Biological Products",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Mandated by the 21st Century Cures Act, Section 505F, this FDA framework outlines requirements for sponsors using Real-World Data (RWD) and Real-World Evidence (RWE) in regulatory submissions, demanding that data be 'fit-for-purpose' and study designs be scientifically robust to support decisions on drug and biologic effectiveness and safety.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice",
      "eu-mdr-2017-745"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fdca-food-drug-cosmetic-act-21-usc-301",
    "title": "Federal Food, Drug, and Cosmetic Act 1938 - 21 USC 301",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 301 of title 21 of the United States Code is the short title provision of the Federal Food, Drug, and Cosmetic Act (FDCA, Public Law 75-717, enacted 25 June 1938), the principal US statute governing the safety and efficacy of food, drugs, medical devices, cosmetics, dietary supplements, tobacco products, and animal drugs. Title 21 Chapter 9 codifies the FDCA across approximately 1,200 sections covering Subchapter II Definitions (sections 321-332), Subchapter III Prohibited Acts and Penalties (sections 331-337a including the central prohibition on misbranding, adulteration, and introduction into interstate commerce), Subchapter IV Food, Subchapter V Drugs and Devices (including IND, NDA, ANDA, BLA, premarket approval, 510(k) for devices, breakthrough designation, accelerated approval, REMS), Subchapter VI Cosmetics (with the 2022 MoCRA modernisation), Subchapter VII General Authority including section 704 inspection, section 705 publicity, and section 708 confidential information. The FDA Modernization Acts (1997 FDAMA, 2007 FDAAA, 2012 FDASIA, 21st Century Cures Act 2016, MoCRA 2022, FDORA 2022) have substantially extended the FDCA. AI-enabled drug discovery, AI-as-medical-device (SaMD), AI-supported clinical decision support, and AI-driven adverse-event detection all operate within the FDCA framework, with the FDA AI/ML Action Plan and Predetermined Change Control Plan framework providing the principal regulatory pathway.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mdr-2017-745-classification-rules",
      "eu-ivdr-2017-746-in-vitro-diagnostic-devices"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fdcpa-fair-debt-collection-practices-act-1977",
    "title": "US Fair Debt Collection Practices Act 1977 (FDCPA) - Collector Conduct and Consumer Rights",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Fair Debt Collection Practices Act (15 USC 1692, 1977) prohibits abusive, unfair, and deceptive practices by third-party debt collectors; requires a written validation notice within 5 days of first contact; restricts calls to 7am-9pm local time; prohibits contacting consumers at their workplace if the employer objects; and is enforced by the CFPB (since Dodd-Frank 2010) and FTC; Regulation F (12 CFR Part 1006, effective November 2021) updated FDCPA for email, text, and social media communications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cfpb-udaap-dodd-frank-section-1031-unfair-deceptive-abusive",
      "us-fair-credit-reporting-act-fcra-1970"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fdic-12-cfr-337-unsafe-and-unsound-banking-practices",
    "title": "12 CFR Part 337 - Unsafe and Unsound Banking Practices (Brokered Deposits, Rate Caps, Insider Credit)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "12 CFR Part 337 sets out FDIC rules that address unsafe and unsound banking practices for FDIC-supervised institutions. Standby letters of credit must be combined with other guarantees and extensions of credit and counted toward the institution's lending and investment limits and recorded so they are subject to the same scrutiny as loans. Extensions of credit to executive officers, directors and principal shareholders are subject to limits consistent with the insider-lending rules. Under section 29 of the Federal Deposit Insurance Act, only a well-capitalized insured depository institution may accept, renew or roll over brokered deposits without restriction; an adequately capitalized institution may do so only with a waiver granted by the FDIC; and an undercapitalized institution may not accept brokered deposits. An institution that is less than well capitalized is also subject to interest rate restrictions and generally may not pay deposit rates that exceed the national rate cap, defined as the higher of the national rate plus 75 basis points or 120 percent of the comparable Treasury yield plus 75 basis points, or, where applicable, the local market rate cap of 90 percent of the highest rate in the institution's local market area. These restrictions are in addition to other applicable banking-practice requirements, and the FDIC sets the frequency of examinations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_obligations",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fed-12-cfr-217-reg-q-capital-adequacy-of-bank-holding-companies",
      "us-fed-12-cfr-252-reg-yy-enhanced-prudential-standards",
      "us-dodd-frank-act-2010"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fdic-12-cfr-348-management-official-interlocks",
    "title": "12 CFR Part 348 - Management Official Interlocks",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "12 CFR Part 348 implements the Depository Institution Management Interlocks Act and restricts a person from serving as a management official of two unaffiliated depository organizations at the same time, in order to foster competition, administered by the FDIC for the institutions it supervises. Under the community prohibition, a management official of a depository organization may not serve at the same time as a management official of an unaffiliated depository organization if the organizations (or a depository institution affiliate) have offices in the same community. Under the RMSA prohibition, the same restriction applies where the organizations have offices in the same relevant metropolitan statistical area and each has total assets of $50 million or more. Under the major assets prohibition, a management official of an organization with total assets exceeding the threshold (currently $10 billion) may not serve at the same time as a management official of an unaffiliated organization above that threshold, regardless of location. Certain interlocks are permitted by statute, such as those involving an organization in liquidation, an Edge or Agreement corporation, a credit union, a foreign organization, or a bankers' bank. A small market share exemption permits an otherwise prohibited interlock (other than a major-assets interlock) where the organizations hold no more than 20 percent of the deposits in each affected RMSA or community, supported by records and annual reconfirmation, and a general exemption is available with FDIC approval. Where a previously permissible interlock becomes prohibited by a change in circumstances, the management official generally has a grace period to terminate it, and the FDIC enforces the part.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dodd-frank-act-2010",
      "us-fed-12-cfr-217-reg-q-capital-adequacy-of-bank-holding-companies",
      "us-fed-12-cfr-252-reg-yy-enhanced-prudential-standards"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fdic-12-cfr-362-activities-of-insured-state-banks",
    "title": "12 CFR Part 362 - Activities and Investments of Insured State Banks and Savings Associations",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "12 CFR Part 362 implements section 24 of the Federal Deposit Insurance Act and limits the activities and equity investments that insured State banks, their subsidiaries, and insured State savings associations may engage in or hold as principal, administered by the FDIC. No insured State bank may directly or indirectly acquire or retain as principal an equity investment of a type that is not permissible for a national bank, unless an exception applies, such as an equity investment in a majority-owned subsidiary engaged in permissible activities or an investment in a qualified housing project within the prescribed limits. An insured State bank may not engage as principal in an activity that is not permissible for a national bank, and a subsidiary of an insured State bank may not engage as principal in an activity that is not of a type permissible for a subsidiary of a national bank, unless the bank obtains the FDIC's prior written consent and meets and continues to meet the applicable capital standards; consent is given only where the FDIC determines the activity poses no significant risk to the Deposit Insurance Fund. An insured State nonmember bank is restricted from affiliating with a securities underwriting affiliate that engages in securities activities not permissible for a national bank unless the prescribed separation and supervision conditions are met. Insured State savings associations are subject to parallel restrictions on equity investments not permissible for a Federal savings association and on the activities of their service corporations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_obligations",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fed-12-cfr-217-reg-q-capital-adequacy-of-bank-holding-companies",
      "us-dodd-frank-volcker-rule-12-cfr-248-proprietary-trading-prohibition",
      "us-dodd-frank-act-2010"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fdic-12-cfr-part-329-liquidity-risk-measurement-standards",
    "title": "12 CFR Part 329 - FDIC Liquidity Risk Measurement Standards (LCR and NSFR for FDIC-Supervised Institutions)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "12 CFR Part 329 is the Federal Deposit Insurance Corporation (FDIC) liquidity risk measurement rule implementing the Basel III Liquidity Coverage Ratio (LCR) and Net Stable Funding Ratio (NSFR) for FDIC-supervised institutions on a consolidated basis. Section 329.1(a) establishes a minimum liquidity standard and a minimum stable funding standard. Section 329.1(b)(1) applies to an FDIC-supervised institution that is (A) a GSIB depository institution supervised by the FDIC, (B) a Category II FDIC-supervised institution, or (C) a Category III FDIC-supervised institution, or where the FDIC has determined that application is appropriate in light of asset size, level of complexity, risk profile, scope of operations, affiliation with foreign or domestic covered entities, or risk to the financial system. Section 329.3 sets the operative definitions in substantive parity with the FRB Regulation WW (12 CFR Part 249) and the OCC LCR rule (12 CFR Part 50) - the LCR, NSFR, HQLA, level 1, level 2A, and level 2B liquid assets, brokered deposit, operational deposit, average weighted short-term wholesale funding (calculated using FR Y-15 data), and other Basel III-aligned operative terms. Section 329.10(a) requires the FDIC-supervised institution to calculate and maintain a liquidity coverage ratio equal to or greater than 1.0 on each business day in accordance with Part 329, with the elected calculation time fixed by written notice to the FDIC prior to December 31, 2019. Section 329.10(b) calculates the LCR as the HQLA amount under subpart C divided by the total net cash outflow amount under subpart D. Section 329.20 sets the HQLA criteria - level 1 includes Reserve Bank balances, foreign withdrawable reserves, US Treasury securities, US government agency securities fully and explicitly guaranteed by the full faith and credit of the US government, and sovereign or BIS/IMF/ECB/European Community/multilateral development bank securities at zero percent risk weight under subpart D of 12 CFR Part 324 (the FDIC capital rule) that are liquid and readily-marketable. Section 329.40 imposes the liquidity coverage shortfall supervisory framework requiring FDIC notification on any business day the LCR falls below the minimum requirement. Subpart K implements the Net Stable Funding Ratio. Part 329 is the FDIC's mirror of the FRB Regulation WW (12 CFR Part 249) and the OCC LCR rule (12 CFR Part 50) - the three rules are substantively identical with agency-specific applicability determined by primary supervisor allocation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "purpose_and_applicability_anchor",
        "definitions_anchor",
        "minimum_lcr_anchor",
        "hqla_criteria_anchor",
        "shortfall_supervisory_framework_anchor",
        "nsfr_anchor",
        "mirror_with_other_banking_agencies_anchor",
        "industry_mapping",
        "interaction_with_other_banking_agencies_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-12-cfr-part-249-federal-reserve-lcr-regulation-ww",
      "us-occ-12-cfr-part-50-liquidity-risk-measurement-standards",
      "basel-iii-liquidity-lcr",
      "bcbs-248-monitoring-tools-intraday-liquidity-management-2013",
      "lcr-disclosure-standards"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "us-fdic-improvement-act-fdicia-1991",
    "title": "US FDIC Improvement Act 1991 (FDICIA) - Prompt Corrective Action & Least-Cost Resolution",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The FDIC Improvement Act of 1991 (Pub. L. 102-242) established Prompt Corrective Action (PCA) - a mandatory five-tier capital classification system for insured depository institutions with escalating regulatory restrictions as capital deteriorates: Well Capitalised, Adequately Capitalised, Undercapitalised, Significantly Undercapitalised, Critically Undercapitalised. FDICIA mandates the least-cost resolution principle (FDIC must use the resolution method that minimises the cost to the deposit insurance fund), annual independent audits for institutions >$500 million, requires safe and sound banking standards, and restricts brokered deposits for less-than-well-capitalised institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-glba-gramm-leach-bliley-act-1999",
      "us-dodd-frank-title-vii-otc-derivatives-2010"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fdii-irc-250-foreign-derived-intangible-income",
    "title": "US Internal Revenue Code Section 250 - Foreign-Derived Intangible Income (FDII) Deduction: Eligible Income, Foreign-Derived Ratio, Documentation Requirements and TCJA Interaction",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under IRC § 250, U.S. C-corporations can claim a deduction equal to 37.5% of their foreign-derived intangible income (FDII), which is designed to incentivize holding intellectual property in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fdii-section-250-foreign-derived-intangible-income",
    "title": "Deduction for Foreign-Derived Intangible Income and Global Intangible Low-Taxed Income (26 U.S.C. § 250)",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This regulation, under 26 U.S.C. § 250, allows eligible U.S. C corporations to claim a deduction on their Foreign-Derived Intangible Income (FDII) and Global Intangible Low-Taxed Income (GILTI). The FDII deduction incentivizes holding intellectual property in the U.S. by providing a lower effective tax rate on income derived from foreign sales, leases, licenses, or services that use domestic IP.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fed-12-cfr-208-regulation-h-state-member-banks",
    "title": "12 CFR Part 208 (Regulation H) - Membership and Requirements of State Member Banks",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Regulation H (12 CFR Part 208) governs the membership of State-chartered banks in the Federal Reserve System and the prudential, securities, real-estate-lending and security requirements that apply to State member banks, administered by the Federal Reserve Board. A State bank must satisfy the application and conditions for membership and, once a member, must maintain capital adequacy and observe the limits on dividends and other distributions. Establishment and maintenance of branches must comply with the regulation, and an interstate branch may not be used primarily for deposit production. For loans secured by buildings located in areas having special flood hazards, the bank must require flood insurance as provided. Under the prompt corrective action framework implementing section 38 of the Federal Deposit Insurance Act, the bank's capital category determines mandatory and discretionary supervisory actions, and an undercapitalized bank must file a capital restoration plan. State member banks must adopt real estate lending standards, maintain bank security procedures to discourage robberies, burglaries and larcenies and to assist in their identification and apprehension, and file suspicious activity reports. The regulation also imposes recordkeeping and confirmation requirements on securities transactions and transfer-agent and reporting obligations for banks subject to the Securities Exchange Act of 1934.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_subparts",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fed-12-cfr-217-reg-q-capital-adequacy-of-bank-holding-companies",
      "us-fed-12-cfr-252-reg-yy-enhanced-prudential-standards",
      "us-dodd-frank-act-2010"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fed-12-cfr-217-reg-q-capital-adequacy-of-bank-holding-companies",
    "title": "US Federal Reserve Regulation Q - 12 CFR Part 217 Capital Adequacy of Bank Holding Companies, Savings and Loan Holding Companies, and State Member Banks (Basel III Implementation)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "12 CFR Part 217 (Regulation Q) establishes minimum capital requirements and overall capital adequacy standards for entities including state member banks, bank holding companies, savings and loan holding companies, and certain other Board-regulated institutions. The Board issued Part 217 to implement the Basel III capital framework in the United States. Section 217.10 sets the minimum capital ratios: common equity tier 1 (CET1) ratio of 4.5%, tier 1 capital ratio of 6%, total capital ratio of 8%, and leverage ratio of 4%; advanced approaches institutions are also subject to a supplementary leverage ratio of 3%. Section 217.11 establishes the capital conservation buffer (composed of CET1), the countercyclical capital buffer amount (subject to Board determination), and the global systemically important bank holding company (GSIB) surcharge calibrated under §217.404 or §217.405. Section 217.12 provides the community bank leverage ratio framework allowing qualifying community banking organizations to use a single-ratio approach. Section 217.20 defines the regulatory capital components (CET1, additional tier 1, tier 2) and the eligibility criteria for capital instruments. Section 217.22 prescribes regulatory capital deductions including goodwill and other intangibles. Subpart D sets the standardized approach risk-weighted assets methodology with risk weights for sovereign, depository institution, corporate, residential mortgage, statutorily defined high-volatility commercial real estate (HVCRE), and securitization exposures. Subpart E governs the advanced internal-ratings-based and advanced measurement approaches for advanced-approaches institutions. Subpart F covers market risk for institutions with significant trading activity. Subpart H sets the GSIB risk-based capital surcharge methodology.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fed-12-cfr-252-reg-yy-enhanced-prudential-standards"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fed-12-cfr-225-regulation-y-bank-holding-companies",
    "title": "12 CFR Part 225 (Regulation Y) - Bank Holding Companies and Change in Bank Control",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Regulation Y (12 CFR Part 225) implements the Bank Holding Company Act and the Change in Bank Control Act and governs the formation, activities and control of bank holding companies (BHCs) and financial holding companies (FHCs), administered by the Federal Reserve Board. Under section 3 of the BHC Act, the Board's prior approval is required for any action that causes a company to become a bank holding company, that causes a bank to become a subsidiary of a BHC, or by which a BHC acquires direct or indirect control of more than 5 percent of a class of voting securities of a bank or BHC, unless an exemption applies. Under section 4 of the Act, a BHC and its subsidiaries may not engage in or acquire control of a company engaged in activities other than banking, managing or controlling banks, or activities the Board has determined to be so closely related to banking as to be a proper incident thereto; the permissible closely-related activities are listed in the regulation and require compliance with its procedures. Any person must give the Board 60 days' prior written notice before acquiring control of a state member bank or bank holding company, unless exempt. A BHC may elect to become a financial holding company by filing a written declaration with the appropriate Reserve Bank, which requires that its depository institutions be and remain well capitalized and well managed, and an FHC may engage only in activities that are financial in nature, incidental, or complementary. BHCs must observe the corporate-practices requirements, including serving as a source of financial and managerial strength to their subsidiary banks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_subparts",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fed-12-cfr-217-reg-q-capital-adequacy-of-bank-holding-companies",
      "us-fed-12-cfr-252-reg-yy-enhanced-prudential-standards",
      "us-dodd-frank-act-2010"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fed-12-cfr-252-reg-yy-enhanced-prudential-standards",
    "title": "US Federal Reserve Regulation YY - 12 CFR Part 252 Enhanced Prudential Standards for Large Bank Holding Companies, IHCs of Foreign Banks, and Nonbank Financial Companies",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "12 CFR Part 252 (Regulation YY) is issued by the Board of Governors of the Federal Reserve System under sections 162, 165, 167, and 168 of Title I of the Dodd-Frank Wall Street Reform and Consumer Protection Act (Public Law 111-203, codified at 12 U.S.C. 5362, 5365, 5367, and 5368) to implement enhanced prudential standards for large U.S. bank holding companies, intermediate holding companies of foreign banking organizations, foreign banking organizations with significant U.S. operations, and nonbank financial companies supervised by the Board. Section 252.5 establishes the four-category framework for tailoring standards based on size, cross-jurisdictional activity, weighted short-term wholesale funding, nonbank assets, and off-balance-sheet exposures. Subparts B and F establish company-run stress test requirements for state member banks above USD 250 billion in assets and for U.S. bank holding companies and nonbank financial companies above USD 100 billion. Subpart D imposes enhanced prudential standards for U.S. bank holding companies above USD 100 billion including liquidity risk management, capital planning, and risk-management requirements. Subpart G establishes the external long-term debt and total loss-absorbing capacity (TLAC) requirements and corporate-practices restrictions for U.S. global systemically important banking organizations (GSIBs). Subpart H imposes single-counterparty credit limits. Subpart I imposes qualified financial contract (QFC) provisions to support orderly resolution of GSIBs. Subparts N and O apply enhanced standards to foreign banking organizations based on their combined U.S. assets. Subpart P imposes covered IHC TLAC. Subpart U imposes debt-to-equity limits when triggered by a Financial Stability Oversight Council determination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fed-12-cfr-217-reg-q-capital-adequacy-of-bank-holding-companies"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-federal-advisory-committee-act-5-usc-ch10",
    "title": "Federal Advisory Committee Act - 5 USC Chapter 10",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Chapter 10 of title 5 of the United States Code (sections 1001 through 1014), as recodified by Public Law 117-286 in December 2022 (formerly 5 USC Appendix), codifies the Federal Advisory Committee Act (FACA) originally enacted as Public Law 92-463 on 6 October 1972. FACA governs the establishment, operation, and termination of advisory committees that provide advice or recommendations to federal officials. Section 1004 requires that no advisory committee be established without specific authorisation by Congress, the President, or a federal agency head determining such establishment is in the public interest. Section 1008 requires advisory committees to be fairly balanced in terms of points of view and not inappropriately influenced by the appointing authority or by any special interest. Section 1009 requires advisory committee meetings to be open to the public with timely public notice in the Federal Register, with closure permitted only consistent with the Government in the Sunshine Act exemptions; section 1009 also requires detailed minutes and a verbatim record of each meeting to be available for public inspection. Section 1011 requires advisory committees to be terminated after two years unless renewed by the appointing authority. The General Services Administration administers FACA through the Committee Management Secretariat. AI use in federal advisory committee analytical support, transcription, or recommendation drafting must operate within FACA's transparency and balance framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-government-in-sunshine-act-5-usc-552b",
      "us-foia-1966",
      "us-federal-records-act-44-usc-ch31"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-agriculture-improvement-reform-act",
    "title": "US Federal Agriculture Improvement and Reform Act of 1996 (7 USC ch 100): Production Flexibility Contracts and Marketing Loans",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Federal Agriculture Improvement and Reform Act of 1996 (7 U.S.C. ch. 100, sections 7201 to 7335) reformed federal farm income and commodity support by replacing target-price deficiency payments with fixed, decoupled production flexibility contract payments and nonrecourse marketing assistance loans, administered by the Secretary of Agriculture through the Farm Service Agency and the Commodity Credit Corporation. Section 7201 sets the short title and purpose, and section 7202 defines the terms, including contract commodity, producer, loan commodity, and oilseed. Section 7211 authorizes the use of production flexibility contracts under which a producer of a contract commodity agrees to comply with conservation and wetland requirements and planting flexibility in exchange for fixed contract payments, and section 7212 sets the elements of contracts. Section 7213 sets the amounts available for contract payments, section 7214 governs the determination of contract payments, and section 7216 addresses violations of contract. Section 7218 provides for planting flexibility, allowing producers to plant any crop on contract acreage subject to limitations. Section 7231 provides for the availability of nonrecourse marketing assistance loans for loan commodities, section 7232 sets the loan rates, section 7234 governs the repayment of loans, and section 7235 provides for loan deficiency payments. The Act is a foundational modern farm-support statute.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-arbitration-act-1925",
    "title": "US Federal Arbitration Act (FAA) 1925 - Validity and Enforcement of Arbitration Agreements in US Federal and State Courts",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The US Federal Arbitration Act (FAA) mandates that written arbitration agreements in contracts involving maritime transactions or interstate/foreign commerce are valid, irrevocable, and enforceable in both federal and state courts. Under Section 2, this establishes a national policy favoring arbitration, preempting state laws that might otherwise invalidate such agreements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-arbitration",
      "icc-arbitration-rules-2021",
      "isds-investor-state-dispute",
      "un-cisg-1980"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-federal-crop-insurance-act",
    "title": "US Federal Crop Insurance Act (7 USC ch 36): Crop Insurance, Covered Causes and Program Integrity",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Federal Crop Insurance Act, codified at 7 U.S.C. Chapter 36 (sections 1501-1524), establishes the federal crop insurance program that protects agricultural producers against crop losses, administered by the USDA Risk Management Agency through the Federal Crop Insurance Corporation (FCIC) and delivered by private approved insurance providers. Section 1501 sets the short title and purpose, and section 1502 contains the definitions, including 'approved insurance provider' (a private insurance provider approved by the Corporation to provide coverage to producers) and 'loss ratio'. Section 1503 creates the Federal Crop Insurance Corporation as a body corporate within the Department, and section 1506 sets out its general powers. Section 1508 is the core crop insurance provision: the Corporation may insure producers of agricultural commodities against loss, where losses of the insured commodity must be due to drought, flood or other natural disaster as determined by the Secretary, and expressly excludes losses due to the neglect or malfeasance of the producer, the failure of the producer to reseed to the same crop where reseeding is customary and feasible, or the failure of the producer to follow good farming practices. Coverage is delivered through approved insurance providers under reinsurance arrangements with the Corporation, with producers electing coverage levels and paying premiums (a portion of which is subsidized). Section 1515 establishes program compliance and integrity, providing controls against fraud, waste and abuse, including civil penalties and disqualification from program benefits for a producer, agent, loss adjuster or other person who willfully and intentionally provides false or inaccurate information to the Corporation or an approved provider, or otherwise fails to comply with program requirements. The Act delivers risk management to the agricultural sector while protecting program integrity through claims controls and the good-farming-practices and natural-cause requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-crop-insurance-act-1938-7-usc-1501",
    "title": "Federal Crop Insurance Act (7 U.S.C. §§ 1501-1524)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-07-18",
    "bluf": "This Act authorizes the Federal Crop Insurance Corporation (FCIC) to provide federally subsidized crop insurance to agricultural producers through approved private insurance providers (AIPs). It mandates specific risk-sharing agreements, premium subsidy levels, and compliance requirements for both producers and insurers to protect against crop losses due to natural causes, as outlined in 7 U.S.C. § 1508.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nfip-national-flood-insurance-program-rules"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-federal-deposit-insurance-act",
    "title": "US Federal Deposit Insurance Act (12 USC ch 16): Deposit Insurance and Bank Enforcement",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Federal Deposit Insurance Act (12 U.S.C. ch. 16) establishes Federal deposit insurance and the supervisory and enforcement framework for insured depository institutions, administered by the Federal Deposit Insurance Corporation together with the other Federal banking agencies. Section 1811 establishes the FDIC. Section 1813 provides the definitions, including insured depository institution and appropriate Federal banking agency. Section 1818 sets the principal enforcement powers: the appropriate agency may issue cease-and-desist orders requiring an institution or an institution-affiliated party to stop a violation or unsafe or unsound practice and to take affirmative corrective action; may remove or prohibit an institution-affiliated party from participation where there is a violation, unsafe practice or breach of fiduciary duty involving personal dishonesty or willful or continuing disregard for safety and soundness; and may assess civil money penalties under a three-tier structure, ranging from up to 5,000 dollars per day for first-tier violations, to 25,000 dollars per day for violations causing more than minimal loss or involving recklessness, to 1,000,000 dollars per day for knowing violations causing substantial loss or gain. Section 1820 provides for examinations and administration. The Act, together with the deposit insurance assessment provisions, is the legal foundation for US bank safety and soundness enforcement and depositor protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-food-drug-and-cosmetic-act",
    "title": "US Federal Food, Drug, and Cosmetic Act (21 USC ch 9): Prohibited Acts, Adulteration, New Drug Approval and Penalties",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Federal Food, Drug, and Cosmetic Act (FD&C Act, 21 U.S.C. ch. 9) is the principal US statute regulating the safety and labeling of food, drugs, medical devices, cosmetics and tobacco, administered by the Food and Drug Administration (FDA). Section 331 lists the prohibited acts, chiefly the introduction or delivery for introduction into interstate commerce of any food, drug, device or cosmetic that is adulterated or misbranded, and related acts. Section 332 authorizes injunction proceedings to restrain violations. Section 333 sets the penalties: a basic violation is punishable by imprisonment for up to one year or a fine of up to 1,000 dollars; a violation committed with the intent to defraud or mislead, or after a prior conviction, is punishable by imprisonment for up to three years or a fine of up to 10,000 dollars; and an adulteration with reasonable probability of serious adverse health consequences is punishable by imprisonment for up to 20 years or a fine of up to 1,000,000 dollars. Section 334 provides for the seizure of an offending article. The substantive standards are set elsewhere in the chapter: section 351 defines when a drug or device is adulterated, section 352 defines misbranding, section 355 requires approval of a new drug application before marketing, and section 360 requires registration of producers and listing of products. The Act is the legal foundation of US food and drug safety regulation and FDA enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-hazardous-substances-act",
    "title": "US Federal Hazardous Substances Act (15 USC ch 30): Hazardous Household Product Labeling and Bans",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Federal Hazardous Substances Act (15 U.S.C. ch. 30) requires precautionary labeling of hazardous household products and authorizes the banning of those too dangerous for household use, administered by the Consumer Product Safety Commission. Section 1261 provides the definitions, including hazardous substance and misbranded hazardous substance, which is a hazardous substance intended for household use that lacks the required cautionary labeling such as the signal word, a statement of the principal hazard, precautionary measures, first aid instructions and the instruction to keep out of the reach of children. Section 1263 sets out the prohibited acts, including the introduction into interstate commerce of a misbranded or banned hazardous substance. Section 1262 authorizes the Commission to issue regulations declaring substances to be hazardous and to require special labeling. Section 1274 authorizes the banning of hazardous substances, including toys and articles intended for children that present an electrical, mechanical or thermal hazard. Section 1264 sets the penalties: a violation of section 1263 is punishable by a fine of not more than 500 dollars or imprisonment for not more than 90 days for a first offense, rising for intent to defraud or mislead or for a repeat offense to imprisonment for not more than 5 years and a fine determined under title 18. The Act is the legal foundation for US hazardous household product labeling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-home-loan-bank-act-fhlb-1932",
    "title": "US Federal Home Loan Bank Act (FHLB Act) - 12 USC 1421 - FHFA Oversight",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "The Federal Home Loan Bank Act establishes the 11-bank FHLB System, a government-sponsored enterprise providing secured advances (loans) to member institutions (commercial banks, savings institutions, credit unions, insurance companies) collateralised by eligible assets; FHLB members receive dividends and must purchase activity-based stock; 10% of net income goes to the Affordable Housing Program (AHP); regulated by the FHFA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-glba-gramm-leach-bliley-act-1999",
      "us-dodd-frank-title-vii-otc-derivatives-2010",
      "us-fdic-improvement-act-fdicia-1991"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-federal-insecticide-fungicide-rodenticide-act",
    "title": "US Federal Insecticide, Fungicide, and Rodenticide Act (7 USC ch 6): Pesticide Registration and Unlawful Acts",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Federal Insecticide, Fungicide, and Rodenticide Act (FIFRA, 7 U.S.C. ch. 6, sections 136 to 136y) is the federal statute governing the registration, distribution, sale, and use of pesticides in the United States, administered by the Administrator of the Environmental Protection Agency. Section 136 sets out the definitions, providing that the term pesticide means any substance or mixture of substances intended for preventing, destroying, repelling, or mitigating any pest, and defining pest, device, and misbranded. Section 136a governs the registration of pesticides and provides that no person in any State may distribute or sell to any person any pesticide that is not registered under the subchapter, with the Administrator registering a pesticide where its composition warrants the proposed claims, its labeling complies, and it will perform its intended function without unreasonable adverse effects on the environment. Section 136j sets out the unlawful acts, including that it is unlawful for any person to distribute or sell any pesticide that is not registered or that is misbranded. Section 136l sets the penalties, providing that a registrant, commercial applicator, wholesaler, dealer, retailer, or distributor who violates the subchapter may be assessed a civil penalty of not more than 5,000 dollars for each offense, and that a registrant, applicant for registration, or producer who knowingly violates the subchapter may be fined not more than 50,000 dollars or imprisoned for not more than one year, or both. The Act is the federal pesticide control regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-insecticide-fungicide-rodenticide-act-fifra",
    "title": "US Federal Insecticide, Fungicide and Rodenticide Act (FIFRA) - EPA Pesticide Registration Framework",
    "domain": "Agriculture & Agritech",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The Federal Insecticide, Fungicide and Rodenticide Act (FIFRA, 7 U.S.C. ss. 136-136y) is the primary US federal law governing the registration, sale, distribution, and use of pesticides. The US Environmental Protection Agency (EPA) administers FIFRA and requires that all pesticides sold or distributed in the United States be registered with EPA unless specifically exempt. Registration requires submission of scientific data demonstrating that, when used according to label directions, the pesticide will not cause unreasonable adverse effects on humans or the environment. Tolerances (maximum residue levels) for pesticides on food are set by EPA under the Federal Food, Drug, and Cosmetic Act (FFDCA) and enforced by FDA and USDA. State lead agencies co-regulate under FIFRA state primary enforcement authority, may impose stricter requirements, and may register additional uses within federal parameters. Certification of pesticide applicators is required for restricted-use pesticides. Penalties for FIFRA violations include fines up to USD 25,000 per violation for commercial registrants.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ffdca_tolerance",
        "codex_alimentarius",
        "worker_protection_standard",
        "state_authority",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-federal-land-policy-and-management-act",
    "title": "US Federal Land Policy and Management Act (43 USC 1701 et seq.): Retention Policy, Multiple Use and Sustained Yield, Land Use Plans and Enforcement",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Federal Land Policy and Management Act of 1976 (FLPMA), codified at 43 U.S.C. 1701 et seq., is the organic statute for the public lands administered by the Bureau of Land Management within the Department of the Interior. Section 1701(a) declares the policy of the United States, including that the public lands be retained in Federal ownership unless, as a result of the land use planning procedure provided for in the Act, it is determined that disposal of a particular parcel will serve the national interest; that the public lands be periodically and systematically inventoried and their present and future use projected through a land use planning process; that goals and objectives be established by law as guidelines for public land use planning and that management be on the basis of multiple use and sustained yield unless otherwise specified by law; and that the United States receive fair market value of the use of the public lands and their resources unless otherwise provided for by statute. Section 1712 requires the Secretary to develop, maintain and, when appropriate, revise land use plans that govern the use of the public lands. Section 1732 governs the management of the use, occupancy and development of the public lands in accordance with the land use plans and on the multiple-use and sustained-yield basis, and requires the Secretary to take action to prevent unnecessary or undue degradation of the lands. Section 1733 confers enforcement authority, including the power to issue regulations the violation of which is punishable, and to enforce the Act against unauthorized use. The Act is the legal foundation on which roughly one-eighth of the land area of the United States is inventoried, planned, managed for multiple use and protected from undue degradation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-meat-inspection-act",
    "title": "US Federal Meat Inspection Act: Mandatory Inspection, Adulteration, Labeling and Prohibited Acts",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Federal Meat Inspection Act (FMIA), codified at 21 U.S.C. Chapter 12 (sections 601-695), is the principal US statute ensuring that meat and meat food products are wholesome, not adulterated, and properly marked, labeled and packaged, administered by the USDA Food Safety and Inspection Service (FSIS). Section 601 supplies the definitions, including 'adulterated' and 'misbranded'. Sections 603-605 require ante-mortem inspection of cattle, sheep, swine, goats and equines before slaughter and post-mortem inspection of their carcasses and parts at establishments preparing products for commerce, and section 606 requires inspection of meat food products. Section 607 governs the marking, labeling and packaging of inspected products, and section 608 requires sanitary conditions at establishments. Section 610 sets the prohibited acts: it is unlawful to slaughter animals or prepare articles capable of use as human food except in compliance with the Act; to fail to handle animals humanely in connection with slaughter as required by the Humane Methods of Slaughter Act; to sell, transport or distribute adulterated or misbranded articles capable of use as human food, or uninspected articles required to be inspected; and to perform any act, while articles are in commerce or held for sale, intended to or having the effect of causing them to be adulterated or misbranded. Section 620 regulates the importation of meat products, which must meet standards at least equal to US requirements. Section 642 imposes recordkeeping duties and section 644 requires registration of certain businesses. Section 676 sets the penalties, including fines and imprisonment, with enhanced penalties where there is intent to defraud or distribution of adulterated articles. The Act is implemented by FSIS regulations in 9 CFR.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-mine-safety-and-health-act",
    "title": "US Federal Mine Safety and Health Act (30 USC ch 22): Mandatory Standards, Inspections and Penalties",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Federal Mine Safety and Health Act of 1977 (the Mine Act, 30 U.S.C. ch. 22) governs the safety and health of workers in coal and other mines, administered by the Mine Safety and Health Administration (MSHA) within the Department of Labor, with adjudication by the Federal Mine Safety and Health Review Commission. Section 801 sets the findings and declaration of purpose, prioritising the protection of the health and safety of miners. Section 802 supplies the definitions, and section 803 sets the mines subject to coverage, reaching every mine whose products enter commerce. Section 811 provides for the development and promulgation of mandatory safety and health standards. Section 813 authorizes regular inspections, investigations and recordkeeping, including the right of miners to request an inspection, and provides for at least four annual inspections of underground mines. Section 814 provides for the issuance of citations and orders, including imminent-danger withdrawal orders, and section 815 sets the procedure for enforcement and contest. Section 818 authorizes injunctions. Section 820 sets the penalties, including mandatory civil penalties for each violation and criminal penalties for willful violations. The Act is the legal foundation of US mine-safety regulation and the strict, inspection-driven enforcement regime for mines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-mine-safety-health-act-1977-msha",
    "title": "Federal Mine Safety and Health Act 1977 - MSHA Compliance Framework",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Federal Mine Safety and Health Act of 1977 (Mine Act) establishes mandatory health and safety standards for all US mines, requiring the Mine Safety and Health Administration (MSHA) to conduct at least four underground mine inspections and two surface mine inspections per year, issue citations and withdrawal orders for violations, impose civil penalties of up to $70,000 per violation (and $250,000 for flagrant violations), mandate miner training under 30 CFR Part 48, and investigate all mine accidents resulting in fatalities or serious injuries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-oil-gas-royalty-management-act",
    "title": "US Federal Oil and Gas Royalty Management Act of 1982 (30 U.S.C. Chapter 29): Royalty Accounting, Inspections and Civil Penalties",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Federal Oil and Gas Royalty Management Act of 1982, codified at 30 U.S.C. Chapter 29 (sections 1701 through 1759) and amended by the Federal Oil and Gas Royalty Simplification and Fairness Act of 1996, establishes a comprehensive system for the collection, accounting, and auditing of royalties, rents, and other payments due from oil and gas leases on federal and Indian lands, administered by the Office of Natural Resources Revenue in the Department of the Interior. Section 1711 sets the duties of the Secretary to establish a royalty management system providing accurate accounting and timely collection. Section 1712 sets the duties of lessees, operators, and transporters, including the duty to make payments and reports. Section 1713 imposes required recordkeeping for the period prescribed. Section 1718 authorizes inspections, audits, and investigations. Section 1719 provides for civil penalties for violations, including for failure to permit inspection, failure to pay, and false reporting, with escalated penalties for knowing or willful violations. Section 1721 sets the royalty terms and conditions, interest on underpayments and overpayments, and assessments. Section 1724 governs Secretarial and delegated States actions and the limitation periods for royalty claims. Section 1734 provides for State suits under federal law. The Act is the foundational federal oil and gas royalty accountability and enforcement statute.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-power-act",
    "title": "US Federal Power Act (16 USC ch 12): FERC Licensing of Hydropower and Regulation of Wholesale Electricity in Interstate Commerce",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Federal Power Act (16 U.S.C. ch. 12) is the foundational federal statute governing the licensing of non-federal hydroelectric projects and the regulation of the transmission and wholesale sale of electric energy in interstate commerce, administered by the Federal Energy Regulatory Commission (FERC). Section 796 supplies the definitions, including electric utility, transmitting utility, and Regional Transmission Organization. Subchapter I governs water power: section 797(e) authorizes the Commission to issue licenses for the construction and operation of dams, conduits and related project works, requiring that equal consideration be given to energy conservation and to the protection, mitigation and enhancement of fish and wildlife; section 802(a) sets the contents of a licence application, including maps, plans, specifications, cost estimates and evidence of compliance with state law; and section 803(a)(1) requires that a licensed project be best adapted to a comprehensive plan for the waterway, including fish and wildlife protection and other beneficial public uses such as irrigation, flood control, water supply and recreation. Subchapter II governs interstate electricity: section 824(a) declares federal regulation of the transmission and wholesale sale of electric energy in interstate commerce; section 824d requires that rates and charges be just and reasonable and that schedules be filed with the Commission; and section 824e empowers the Commission to fix just and reasonable rates and to order refunds where existing rates are found unlawful. Enforcement runs through Subchapter III: section 825o provides criminal penalties for willful violations and section 825o-1 provides civil penalty authority. The Act is the legal basis on which FERC licenses hydropower and polices the rates and reliability of the interstate bulk electricity market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-power-act-16-usc-ch12",
    "title": "United States Federal Power Act (Title 16 USC Chapter 12): Federal Power Commission Authority, Water Power Licensing, Interstate Electric Utility Rates, Interconnection of Facilities, and Electric Reliability",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Federal Power Act, codified at Title 16 of the United States Code, Chapter 12, is the foundational federal statute governing the regulation of the development of hydroelectric power and the regulation of electric utility companies engaged in interstate commerce, and is administered by the Federal Energy Regulatory Commission. Federal Power Act, 16 U.S.C. 791a sets the short title: this chapter may be cited as the Federal Power Act. Federal Power Act, 16 U.S.C. 792 establishes the Federal Power Commission, the predecessor to the Federal Energy Regulatory Commission, composed of five commissioners appointed by the President by and with the advice and consent of the Senate. Federal Power Act, 16 U.S.C. 797 sets out the general powers of the Commission, including the authority to make investigations and to collect and record data concerning the utilization of the water resources of any region. Federal Power Act, 16 U.S.C. 803 establishes the conditions of license generally, providing that all licenses issued under Subchapter I shall be on the conditions that the project adopted shall be such as in the judgment of the Commission will be best adapted to a comprehensive plan. Subchapter II contains Federal Power Act, 16 U.S.C. 824 which sets the declaration of policy and application, Federal Power Act, 16 U.S.C. 824a on interconnection and coordination of facilities, Federal Power Act, 16 U.S.C. 824d on rates and charges, Federal Power Act, 16 U.S.C. 824e on the power of the Commission to fix rates and charges, and Federal Power Act, 16 U.S.C. 824o on electric reliability, including the certification of an Electric Reliability Organization to develop and enforce mandatory reliability standards. Subchapter III contains procedural and administrative provisions. Subchapter IV addresses State and municipal water conservation facilities. The Act is the controlling federal instrument for federal hydropower licensing and federal regulation of interstate wholesale electricity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-property-administrative-services-act-40-usc-101",
    "title": "Federal Property and Administrative Services Act 1949 - 40 USC 101",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 101 of title 40 of the United States Code, derived from the Federal Property and Administrative Services Act of 1949 (Public Law 81-152, enacted 30 June 1949, 63 Statutes at Large 378), declares the policy of Congress to require an economical and efficient system for federal property procurement and supply (including contracting, inspection, storage, transportation, utility services, and regulatory compliance), property utilisation, surplus property disposition, and records management. The Act established the General Services Administration (GSA) as the principal federal civilian property and procurement agency, transferring functions from the Bureau of Federal Supply, the Public Buildings Administration, and the National Archives. The Act is the statutory parent of the Federal Acquisition Regulation (FAR), the Federal Property Management Regulations, and the Federal Travel Regulations. Subtitle II of title 40 (sections 1101 through 1402) covers GSA-administered programs including federal supply schedules, IT acquisition, fleet management, and federal buildings. Subtitle V of title 40 covers wage rate requirements analogous to the Davis-Bacon Act and Service Contract Act. The Act is the constitutional charter of US federal civilian procurement and property management, and operates alongside the Armed Services Procurement Act (10 USC chapter 137) for defense procurement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clinger-cohen-act-40-usc-11101",
      "us-anti-deficiency-act-31-usc-1341"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-records-act-44-usc-ch31",
    "title": "United States Federal Records Act (Title 44 USC Chapter 31): Agency Head Records Duties, Records Management Program, Transfer to Records Centers, Safeguards, and Unlawful Removal",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Federal Records Act, codified at Title 44 of the United States Code, Chapter 31, is the principal federal statute governing records management by federal agencies and is administered in coordination with the National Archives and Records Administration. Federal Records Act, 44 U.S.C. 3101 imposes general duties on the head of each Federal agency to make and preserve records containing adequate and proper documentation of the organization, functions, policies, decisions, procedures, and essential transactions of the agency. Federal Records Act, 44 U.S.C. 3102 requires the head of each Federal agency to establish and maintain an active, continuing program for the economical and efficient management of the records of the agency. Federal Records Act, 44 U.S.C. 3103 authorises the transfer of records to records centers when the head of a Federal agency determines that such action may affect substantial economies or increased operating efficiency. Federal Records Act, 44 U.S.C. 3104 governs certifications and determinations on transferred records. Federal Records Act, 44 U.S.C. 3105 requires the head of each Federal agency to establish safeguards against the removal or loss of records the head of such agency determines to be necessary and required by regulations of the Archivist. Federal Records Act, 44 U.S.C. 3106 requires the head of each Federal agency to notify the Archivist of any actual, impending, or threatened unlawful removal, defacing, alteration, corruption, deletion, erasure, or other destruction of records. Federal Records Act, 44 U.S.C. 3107 confers authority on the Comptroller General to access records for audit purposes. The Act is the controlling federal instrument for federal records management and is the legal substrate for records-keeping workflow automation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-reserve-12-cfr-part-211-regulation-k-international-banking",
    "title": "12 CFR Part 211 - Federal Reserve Regulation K: International Banking Operations (Foreign Branches of U.S. Member Banks, Edge and Agreement Corporations, Foreign Bank Offices in the United States)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "12 CFR Part 211 is the Federal Reserve Regulation K governing the international banking operations of U.S. banking organisations and the U.S. operations of foreign banks. Section 211.1 sets the authority (the Federal Reserve Act under 12 USC 221 et seq., the Bank Holding Company Act of 1956 under 12 USC 1841 et seq., and the International Banking Act of 1978 under 12 USC 3101 et seq.), purpose, and scope - the subpart sets out rules governing the international and foreign activities of U.S. banking organisations including procedures for establishing foreign branches and Edge and agreement corporations and for investments in foreign organisations, applying to member banks (with respect to their foreign branches and investments in foreign banks under section 25 of the FRA 12 USC 601-604a), corporations organised under section 25A of the FRA 12 USC 611-631 (Edge corporations), corporations having an agreement or undertaking with the Board under section 25 of the FRA (agreement corporations), and bank holding companies with respect to the nonbanking-prohibition exemption. Section 211.2 sets operative definitions including affiliate, capital and surplus (tier 1 plus tier 2 capital plus the balance of allowance for loan and lease losses or adjusted allowance for credit losses not included in tier 2 for risk-based capital), subsidiary, and other terms. Section 211.3 governs foreign branches - a banking organisation is considered to operate a branch in a foreign country if it has an affiliate that is a member bank, Edge or agreement corporation, or foreign bank operating an office (other than a representative office) in that country; foreign branches may be established by any member bank having capital and surplus of $1,000,000 or more, an Edge corporation, an agreement corporation, any subsidiary the shares of which are held directly by the member bank, or any other subsidiary held pursuant to this subpart; the Board may modify or suspend branching authority at any time on notice. Section 211.4 sets permissible activities and investments of foreign branches of member banks including guarantees with maximum monetary liability, underwriting and distribution of government obligations, and a long list of other activities so far as is usual in connection with the business of banking in the country where the branch transacts business. Section 211.5 governs Edge and agreement corporations - the Board has the authority to approve the establishment of Edge corporations, investments in agreement corporations, and a member bank's proposal to invest more than 10 percent of its capital and surplus in the aggregate amount of stock held in all Edge and agreement corporations. Subpart B (sections 211.20 onwards) governs foreign banking organisations operating in the United States - Section 211.22 governs the determination of home state and changes to home state; Section 211.24 governs the approval of offices of foreign banks (branches, agencies, commercial lending companies, or representative offices in the United States, with Board approval before establishment except for certain prior-notice categories).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "authority_and_scope_anchor",
        "definitions_anchor",
        "foreign_branch_anchor",
        "foreign_branch_establishment_anchor",
        "foreign_branch_permissible_activities_anchor",
        "edge_and_agreement_corporations_anchor",
        "foreign_bank_us_offices_anchor",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-holding-company-act-1956",
      "us-federal-reserve-act-1913-12-usc-226",
      "us-fed-12-cfr-225-regulation-y-bank-holding-companies",
      "basel-iii-capital",
      "us-12-cfr-part-249-federal-reserve-lcr-regulation-ww"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-federal-reserve-act-1913-12-usc-226",
    "title": "Federal Reserve Act 1913 - 12 USC 226 Establishment of the Federal Reserve System",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 226 of title 12 of the United States Code provides that the short title of the Act of 23 December 1913 (chapter 6, 38 Statutes at Large 251) shall be the Federal Reserve Act. The Federal Reserve Act of 1913 (Public Law 63-43) established the Federal Reserve System as the central banking authority of the United States, organising the Federal Reserve Board (renamed the Board of Governors of the Federal Reserve System in 1935), twelve regional Federal Reserve Banks, the Federal Open Market Committee, and member commercial banks. The Act's provisions are codified principally throughout title 12 of the United States Code, including sections 221 through 522 (organisation, capital, branches, reserves), sections 263 through 265 (Federal Open Market Committee), and many subsequent additions covering monetary policy operations, lender-of-last-resort facilities (section 13(3) emergency lending), bank supervision, payment systems, consumer protection authority, and prudential regulation. Subsequent legislation has materially extended the Act including the Banking Act of 1935, the Bank Holding Company Act of 1956, the Federal Reserve Reform Act of 1977, the Monetary Control Act of 1980, the FIRREA of 1989, FDICIA of 1991, the Gramm-Leach-Bliley Act of 1999, and the Dodd-Frank Act of 2010. The Federal Reserve Act is the constitutional charter of US monetary policy, financial-stability oversight, and bank prudential supervision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-holding-company-act-1956",
      "us-bsa-bank-secrecy-act-31-usc-5311"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-reserve-ccar-comprehensive-capital-analysis-review",
    "title": "US Federal Reserve CCAR - Comprehensive Capital Analysis and Review Framework",
    "domain": "Banking & Global Finance",
    "version": "2024.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The Federal Reserve's Comprehensive Capital Analysis and Review (CCAR) framework requires large bank holding companies (BHCs) with $100+ billion in assets to submit annual capital plans and demonstrate through stress testing that they can maintain minimum capital ratios under severely adverse economic scenarios, with the Fed having authority to object to capital distributions if capital adequacy is found deficient.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "dodd_frank",
        "basel_iii",
        "eu_eba_stress",
        "us_dodd_frank_stress_testing"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dodd-frank-stress-testing-dfast-2010",
      "basel-iii-capital",
      "bcbs-sound-stress-testing-practices"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-federal-reserve-regulation-w-affiliate-transactions",
    "title": "US Federal Reserve Regulation W - Affiliate Transactions (§§23A & 23B)",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation W (12 CFR Part 223) implements Sections 23A and 23B of the Federal Reserve Act, governing transactions between insured depository institutions (IDIs) and their affiliates. Section 23A limits covered transactions with any single affiliate to 10% of the bank's capital stock and surplus, and 20% aggregate with all affiliates. Section 23B requires affiliate transactions be on terms no less favourable than arm's-length market terms. Covered transactions include loans, purchases of assets (including securities), acceptance of affiliates' securities as collateral, and issuance of guarantees. Low-quality assets may not serve as collateral.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dodd-frank-title-vii-otc-derivatives-2010",
      "us-glba-gramm-leach-bliley-act-1999"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-federal-seed-act",
    "title": "US Federal Seed Act (7 USC ch 37): Truthful Seed Labeling, Import Controls and Penalties",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Federal Seed Act, codified at 7 U.S.C. Chapter 37 (sections 1551-1611), regulates the labeling and advertising of agricultural and vegetable seeds in interstate commerce and the importation of seed, and is administered by the USDA Agricultural Marketing Service. Section 1561 defines the regulated terms. Section 1571 sets the prohibitions relating to interstate commerce: it is unlawful to transport or deliver for transportation in interstate commerce any agricultural or vegetable seeds unless each container bears a label giving the prescribed information (including the kind and variety, lot identification, origin where required, percentage of weed seed and other crop seed, percentage of germination with the test date, and the name and percentage of any noxious-weed seed), and it is unlawful to transport seed that is falsely labeled or as to which there has been a false advertisement. Section 1572 requires records, and section 1575 prohibits disseminating any false advertisement concerning seed. Sections 1581-1582 set the prohibitions relating to importations, including the staining or rejection of certain imported seed. Section 1594 prohibits altering or detaching labels in a way that may defeat the purposes of the chapter, and section 1611 addresses illegal sales of uncertified seed represented as certified. Section 1595 authorizes seizure of violative seed, and section 1599 provides for cease-and-desist proceedings. Section 1596 sets the penalties: a person who violates the Act is guilty of a misdemeanor and on conviction shall pay a fine of not more than $1,000 for the first offense and not more than $2,000 for each subsequent offense; and a civil forfeiture of not less than $25 nor more than $500 may be imposed for each violation. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-tort-claims-act-28-usc-1346",
    "title": "US Federal Tort Claims Act (28 USC 1346) - Waiver of Federal Sovereign Immunity for Torts",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Federal Tort Claims Act provides a limited waiver of federal sovereign immunity allowing private parties to sue the United States in federal district court for money damages arising from negligent or wrongful acts or omissions of federal employees acting within the scope of their employment, requires presentment of an administrative claim to the relevant federal agency within two years and final agency denial or six months without action before filing in district court, applies the substantive law of the state where the act or omission occurred, excludes several enumerated categories such as discretionary functions, claims arising in foreign countries, intentional torts subject to a law enforcement exception, and claims arising from combat activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fsia-foreign-sovereign-immunities-act-28-usc-ch97"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-trade-commission-act",
    "title": "US Federal Trade Commission Act (15 USC ch 2): Unfair Methods of Competition and Unfair or Deceptive Acts",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Federal Trade Commission Act (15 U.S.C. ch. 2, subchapter I) creates the Federal Trade Commission (FTC) and prohibits unfair methods of competition and unfair or deceptive acts or practices in or affecting commerce. Section 41 establishes the Commission. Section 44 supplies the definitions, including commerce and corporation. Section 45 is the operative prohibition: it declares unlawful unfair methods of competition and unfair or deceptive acts or practices in or affecting commerce, empowers the Commission to prevent them, and provides for civil penalties of not more than 10,000 dollars for each violation of a final order. Several modern consumer provisions sit alongside it: section 45a addresses Made in the USA labeling, section 45b protects consumers' ability to post honest reviews, and section 45c addresses the circumvention of ticket access controls by bots. Section 46 sets out additional investigative and reporting powers of the Commission, and section 57a authorizes rulemaking to define unfair or deceptive acts or practices with specificity. The Act is the legal foundation for the FTC's dual mission of policing both anticompetitive conduct and consumer deception across the US economy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-federal-trade-commission-crm-data-breach-2024",
    "title": "Health Breach Notification Rule",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The FTC's Health Breach Notification Rule requires vendors of personal health records and related entities to notify consumers, the FTC, and in some cases the media, following a breach of unsecured identifiable health information. Notification must occur without unreasonable delay and no later than 60 days after discovery of the breach, per 16 CFR Part 318.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coppa-marketing-kids",
      "can-spam-act-email",
      "ftc-digital-advertising-disclosures",
      "ccpa-cpra-optout-sale"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fedramp-20x-cloud-authorization-modernization",
    "title": "FedRAMP 20x - Modernized US Federal Cloud Security Assessment and Authorization (Key Security Indicators)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "FedRAMP 20x is the FedRAMP program office modernization of US federal cloud security assessment and authorization, described by the program as a new approach to cloud security assessment and authorization that moves beyond traditional compliance to focus on the security decisions that matter most. Instead of static yearly audits, FedRAMP 20x is built on Key Security Indicators (KSIs): the Phase 1 pilot demonstrated that KSIs can provide near real time security posture validation, and the program position is that once security goals and measures are defined, status, progress, and outcomes should be automatically enforced and validated whenever possible. FedRAMP 20x authorization is organized into certification classes: Class A for mature providers entering the federal marketplace, Class B for small-scale or light-use services, and Class C for common enterprise services are available now, while Class D remains under development for Phase 4. As of mid 2026 the program is in Phase 3, focused on formalizing requirements and wide-scale adoption, with the submission pipeline planned to open in the July to September 2026 window; Phase 2 completed in March 2026. FedRAMP 20x operates alongside the traditional NIST SP 800-53 Rev 5 baseline path, and the statutory footing for FedRAMP is the FedRAMP Authorization Act codified in title 44 of the United States Code. Cloud service providers selling to US federal agencies should map their continuous-monitoring architecture to KSIs and choose between the 20x path and the Rev 5 baseline path based on service maturity and agency demand.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_anchor",
        "rev5_baseline_relationship",
        "ksi_continuous_monitoring",
        "certification_classes",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-44-usc-3614-fedramp-authorization-program",
      "fedramp-moderate-baseline",
      "fedramp-authorization"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fedramp-authorization-framework",
    "title": "US FedRAMP Authorization Framework 2023 - Federal Risk and Authorization Management Program for Cloud",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Federal Risk and Authorization Management Program (FedRAMP) is a U.S. government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. It requires Cloud Service Providers (CSPs) to achieve an Authority to Operate (ATO) from either the Joint Authorization Board (JAB) or a federal agency before providing services to the U.S. Federal Government.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fedramp-moderate-baseline",
      "nist-sp-800-145-cloud-computing",
      "nist-800-61-incident-resp",
      "guide-developing-security-plans-federal-systems"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fedramp-authorization-moderate",
    "title": "US FedRAMP Moderate Baseline - Security Authorisation Requirements for Cloud Service Providers Handling Federal Data",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-05-28",
    "bluf": "The US Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline mandates that Cloud Service Providers (CSPs) handling federal data, specifically Controlled Unclassified Information (CUI), must implement and be independently assessed against 325 specific security controls derived from NIST SP 800-53. Achieving a formal Authorization to Operate (ATO) from a federal agency sponsor is required before providing services to the US government.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fedramp-authorization",
      "fips-199-security-categorization",
      "fips-200-minimum-security-requirements",
      "assessing-security-privacy-controls",
      "developing-security-plans-federal-systems"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fedramp-federal-risk-authorization-management-program-cloud",
    "title": "US FedRAMP - Federal Risk and Authorization Management Program Cloud Security Authorization",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2024-12-19",
    "bluf": "FedRAMP establishes standardized security requirements for cloud services used by US federal agencies, requiring cloud service providers to obtain agency sponsorship, complete security assessment against NIST 800-53 controls at Low/Moderate/High impact levels, and maintain continuous monitoring with monthly vulnerability scanning and annual security assessments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fedramp-nist-sp-800-37-cloud-authorization",
    "title": "US FedRAMP - NIST SP 800-37 Cloud Service Authorization for Federal Use",
    "domain": "Cloud & SaaS",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Federal Risk and Authorization Management Program (FedRAMP) provides a standardised approach for federal agencies to assess, authorise, and monitor cloud services using NIST SP 800-37 Risk Management Framework and NIST SP 800-53 security controls; CSPs serving federal agencies must obtain a FedRAMP Authorization to Operate (ATO) at Low, Moderate, or High impact level.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ferc-form-1-annual-report-electric-utilities",
    "title": "FERC Form 1 Annual Report for Major Electric Utilities - Financial Statements, Rate Base and Operating Statistics Filing Requirements",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Mandates that all major electric utilities, licensees, and others subject to FERC jurisdiction file Form No. 1, a comprehensive annual report detailing financial and operational data, as required by the Federal Power Act and codified in 18 CFR § 141.1. This report provides a detailed basis for regulatory oversight of rates and financial condition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ferc-order-2222-distributed-energy-resource-aggregation-markets",
    "title": "US FERC Order 2222 - Distributed Energy Resource Aggregation in Wholesale Electricity Markets",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "FERC Order No. 2222 (September 2020) requires regional transmission organisations (RTOs) and independent system operators (ISOs) to revise their tariffs to allow distributed energy resource aggregators (DERAs) to participate in wholesale electricity markets. Aggregators may bundle DER assets including batteries, demand response, solar, and electric vehicles to meet minimum offer size thresholds and compete with conventional generation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-air-act-42-usc-7401-findings-purposes-air-quality"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ferc-order-2222-distributed-energy-resources",
    "title": "Participation of Distributed Energy Resource Aggregations in Markets Operated by Regional Transmission Organizations and Independent System Operators",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-09-15",
    "bluf": "This final rule requires Regional Transmission Organizations (RTOs) and Independent System Operators (ISOs) to revise their tariffs to establish Distributed Energy Resource (DER) aggregators as a type of market participant, thereby removing barriers to their participation in wholesale capacity, energy, and ancillary service markets, as mandated under Section 206 of the Federal Power Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ferc-pro-forma-oatt-open-access-transmission",
    "title": "Pro Forma Open Access Transmission Tariff (OATT) - Non-Discriminatory Transmission Access, Ancillary Services and Interconnection Procedures",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-06-11",
    "bluf": "Mandated by the Federal Energy Regulatory Commission (FERC) under Orders No. 888 and 889, the Pro Forma Open Access Transmission Tariff (OATT) requires public utilities that own, control, or operate interstate electricity transmission facilities to provide open, non-discriminatory transmission services to all eligible customers at just and reasonable rates. This ensures that wholesale electricity sellers can access the transmission grid on the same terms and conditions as the transmission-owning utility.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sherman-antitrust-act-sections-1-2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ferpa-34-cfr-99-student-records-privacy-rights",
    "title": "US FERPA (Family Educational Rights and Privacy Act) - 34 CFR Part 99 Student Education Records Privacy",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "FERPA (20 USC 1232g; 34 CFR Part 99) grants parents rights over their minor children's education records at federally-funded educational agencies and institutions; rights transfer to students at age 18 or upon enrollment in post-secondary institution. Institutions must provide annual rights notification, obtain written consent before disclosing records, allow inspection/correction, and maintain disclosure records. Non-compliance risks loss of federal funding.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ferpa-34-cfr-part-99-student-privacy",
    "title": "34 CFR Part 99 - Family Educational Rights and Privacy",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Educational agencies and institutions must protect the privacy of student education records, providing parents and eligible students with rights to inspect, review, amend records, and consent to disclosures of personally identifiable information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ferpa-family-educational-rights-privacy",
    "title": "Family Educational Rights and Privacy Act of 1974, as amended, enacted as section 444 of the General Education Provisions Act, codified at 34 CFR Part 99",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "FERPA protects the privacy of student education records by granting parents and eligible students the right to inspect, review, and request amendment of those records, and by restricting the disclosure of personally identifiable information without prior written consent, subject to specific exceptions under 34 CFR §99.31. It applies to all educational agencies and institutions receiving U.S. Department of Education funding.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-digital-education-action-plan-2021-2027",
      "iso-21001-2018-educational-organizations-management",
      "cis-controls-v8-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ferpa-family-educational-rights-privacy-1974",
    "title": "Family Educational Rights and Privacy Act of 1974 (FERPA)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "FERPA protects the privacy of student education records by granting parents and eligible students (age 18 or enrolled in postsecondary education) the right to inspect, amend, and control disclosure of personally identifiable information, except under specific exceptions such as directory information or school official necessity. Key provisions are defined in 20 U.S.C. § 1232g and 34 CFR Part 99.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ferpa-family-educational-rights-privacy-act",
    "title": "Family Educational Rights and Privacy Act (FERPA) - Education Records, Parental Rights, Directory Information and Disclosure Conditions",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Family Educational Rights and Privacy Act (FERPA) is a U.S. federal law that protects the privacy of student education records and applies to all schools that receive funds under an applicable program of the U.S. Department of Education. Under 20 U.S.C. § 1232g, FERPA gives parents or eligible students rights to inspect and review education records, seek to amend them, and consent to the disclosure of personally identifiable information (PII) from these records.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-rev-3"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ferpa-family-educational-rights-privacy-act-20-usc-1232g",
    "title": "US FERPA - Family Educational Rights and Privacy Act (20 U.S.C. § 1232g) - Student Records Protection",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g) protects the privacy of student education records at institutions receiving federal funds. Students (or parents of students under 18) have rights to inspect records, request corrections, and control disclosure. Institutions must obtain written consent before disclosing personally identifiable information from education records, with limited exceptions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-hipaa-security-rule-45-cfr-164-technical-safeguards"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ffiec-model-risk-management",
    "title": "Federal Reserve SR 11-7 / OCC Bulletin 2011-12 - Supervisory Guidance on Model Risk Management",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-07-03",
    "bluf": "Issued jointly by the Board of Governors of the Federal Reserve System (SR Letter 11-7) and the Office of the Comptroller of the Currency (OCC Bulletin 2011-12) on April 4, 2011, this guidance sets supervisory expectations for U.S. banking organizations to implement a comprehensive Model Risk Management (MRM) framework covering the entire model lifecycle, from development and implementation to use and validation. The framework rests on the guiding principle of effective challenge (Section III), robust development and documentation (Section IV), independent validation (Section V), and governance, policies, and controls (Section VI) to manage the risk of adverse consequences from decisions based on incorrect or misused model outputs. On April 17, 2026, the agencies jointly issued SR 26-2, Revised Guidance on Model Risk Management, which supersedes SR letter 11-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "interagency-guidance-third-party-risk-management",
      "bcbs-principles-sound-management-operational-risk",
      "principles-effective-risk-data-aggregation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fifra-pesticide-control",
    "title": "US FIFRA (7 USC ch 6): Pesticide Registration, Labeling and Penalties",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Federal Insecticide, Fungicide, and Rodenticide Act (7 U.S.C. ch. 6) is the principal US statute governing the sale, distribution and use of pesticides, administered by the Environmental Protection Agency. Section 136 provides the definitions. Section 136a requires every pesticide to be registered with the Administrator before it may be sold or distributed, on a finding that it will perform its intended function without unreasonable adverse effects on the environment. Section 136a also requires approved labeling, and use inconsistent with the labeling is restricted. Section 136j sets out the unlawful acts, including distributing an unregistered or misbranded pesticide and using a registered pesticide in a manner inconsistent with its labeling. Section 136l sets the penalties: a registrant, applicant or distributor is subject to a civil penalty of not more than 5,000 dollars for each offense, and a private applicator to not more than 1,000 dollars; criminal penalties for a knowing violation reach a fine of not more than 50,000 dollars or imprisonment for not more than 1 year for a registrant, and a fine of not more than 1,000 dollars or imprisonment for not more than 30 days for a private applicator. The Act is the legal foundation for US pesticide market authorization and use control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fifra-pesticide-registration",
    "title": "US FIFRA: Pesticide Registration, Labeling, Restricted-Use Certification and Prohibited Acts",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Federal Insecticide, Fungicide, and Rodenticide Act (FIFRA), codified at 7 U.S.C. Chapter 6, subchapter II (sections 136-136y), is the principal US statute regulating the sale, distribution and use of pesticides, administered by the US Environmental Protection Agency (EPA). Section 136 defines the key terms, including 'pesticide', 'misbranded' and 'registrant'. Section 136a requires that, with limited exceptions, no person may sell or distribute a pesticide unless it is registered with the EPA; the Administrator registers a pesticide only where its composition warrants the proposed claims, its labeling complies with the Act, and it will perform its intended function without unreasonable adverse effects on the environment, considering the economic, social and environmental costs and benefits of use. The Administrator classifies each registered use for general use or restricted use; section 136i provides that restricted-use pesticides may be applied only by or under the direct supervision of a certified applicator under an approved certification plan. Section 136e requires the registration of producing establishments, and section 136c provides for experimental use permits. Section 136d authorizes administrative review, including the suspension and cancellation of registrations that cause unreasonable adverse effects. Section 136j sets the unlawful acts, including distributing or selling an unregistered, misbranded or adulterated pesticide, making claims that differ substantially from the registration, using a registered pesticide in a manner inconsistent with its labeling, refusing to keep records or permit inspection, and falsifying applications or test data. Section 136k authorizes stop-sale, use or removal orders and seizure. Section 136l provides the penalties: civil penalties for registrants, applicators and other distributors, and criminal penalties (generally misdemeanors) for knowing violations, with lower maxima for private applicators. Section 136v preserves state authority to regulate the sale or use of pesticides to the extent consistent with the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-filled-milk-act",
    "title": "US Filled Milk Act (21 USC ch 3): Prohibition on Interstate Shipment of Filled Milk",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Filled Milk Act (21 U.S.C. ch. 3, sections 61 to 64) prohibits the interstate and foreign shipment of filled milk, administered by the Secretary of Health and Human Services through the Food and Drug Administration. Section 61 defines filled milk as any milk, cream, or skimmed milk, whether or not condensed, evaporated, concentrated, powdered, dried, or desiccated, to which has been added, or which has been blended or compounded with, any fat or oil other than milk fat so that the resulting product is in imitation or semblance of milk, cream, or skimmed milk, while excluding certain products such as those distinctly labeled and sold for infant feeding. Section 62 declares filled milk to be an adulterated article of food injurious to public health and makes it unlawful for any person to manufacture filled milk within any Territory or possession, or to ship or deliver for shipment in interstate or foreign commerce any filled milk. Section 63 makes a violation punishable by a fine of not more than 1,000 dollars or imprisonment of not more than one year, or both, and provides that the act, omission, or failure of an agent acting within the scope of employment is deemed the act of the principal. Section 64 authorizes and directs the Secretary to make and enforce regulations for the chapter. The Act is a federal food adulteration control on imitation dairy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fincen-31-cfr-part-1022-msb-aml-program-bsa-recordkeeping-reporting",
    "title": "FinCEN 31 CFR Part 1022 - Money Services Business AML Program, BSA Recordkeeping and Reporting (including Virtual Currency MSBs)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "31 CFR Part 1022 contains the rules applicable to Money Services Businesses (MSBs) under the Bank Secrecy Act, including registered convertible virtual currency administrators and exchangers classified as money transmitters under 31 CFR 1010.100(ff)(5) per FinCEN guidance FIN-2019-G001. Subpart B section 1022.210 requires every MSB to develop, implement, and maintain an effective written anti-money laundering program reasonably designed to prevent the MSB from being used to facilitate money laundering and the financing of terrorist activities, commensurate with the location, size, nature, and volume of services - the four-pillar program: (a) policies, procedures, and internal controls reasonably designed to assure compliance including customer identification, filing reports, recordkeeping, and law enforcement cooperation; (b) a designated compliance officer with day-to-day responsibility; (c) ongoing education and training of appropriate personnel; (d) independent review at a frequency and scope commensurate with risk. Subpart C contains the reporting obligations: section 1022.310 requires currency transaction reports (CTRs) on FinCEN Form 112 for cash transactions over USD 10,000 in a single day; section 1022.320 requires suspicious activity reports (SARs) on FinCEN Form 111 within 30 days of detection of any suspicious transaction or pattern of transactions involving USD 2,000 or more conducted or attempted by, at, or through the MSB. Subpart D contains the recordkeeping obligations: section 1022.380 MSB registration; section 1022.410 records of customer identification for funds transfers over USD 3,000 (Recordkeeping and Travel Rule); section 1022.420 records of transmittals of funds with originator and beneficiary information (the BSA Travel Rule for transfers USD 3,000 and above). Subpart E provides for special information sharing under 31 USC 5311 et seq. and section 314 of the USA PATRIOT Act. Civil penalty up to USD 71,945 per BSA violation under 31 USC 5321 (2025 adjustment); willful violations carry criminal penalty up to USD 250,000 and 5 years imprisonment under 31 USC 5322, with patterns of illegal activity up to USD 500,000 and 10 years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "aml_program_four_pillars_section_1022_210",
        "reporting_obligations_sars_and_ctrs",
        "recordkeeping_and_bsa_travel_rule_sections_1022_410_420"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-31-usc-5311-5318-bank-secrecy-act-aml-program",
      "us-ny-dfs-bitlicense-23-nycrr-part-200",
      "fsb-crypto-asset-regulatory-framework-2023"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fincen-beneficial-ownership-boi-rule-2024",
    "title": "Beneficial Ownership Information (BOI) Reporting Rule (31 CFR § 1010.380) under the Corporate Transparency Act (CTA)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This rule, under the Corporate Transparency Act, requires most corporations, LLCs, and other similar entities created in or registered to do business in the United States to report information about their beneficial owners and company applicants to the Financial Crimes Enforcement Network (FinCEN) as specified in 31 CFR § 1010.380.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bank-secrecy-act-suspicious"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fincen-cfr-31-part-1022-money-services-businesses",
    "title": "31 CFR Part 1022 - Rules for Money Services Businesses",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes comprehensive anti-money laundering (AML) program, recordkeeping, reporting, and registration requirements for Money Services Businesses (MSBs).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fincen-investment-adviser-aml-final-rule-2024",
    "title": "US FinCEN Investment Adviser AML/CFT Final Rule - Application of Bank Secrecy Act to Investment Advisers, Compliance Date 1 January 2026",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "SEC-registered investment advisers (RIAs) and exempt reporting advisers (ERAs) subject to the Financial Crimes Enforcement Network (FinCEN) final rule (89 FR 72156, 4 September 2024) applying the Bank Secrecy Act and related AML/CFT provisions to investment advisers must, from the compliance date of 1 January 2026, implement a written AML/CFT program reasonably designed to prevent the investment adviser from being used for money laundering, terrorist financing, or other illicit finance, including a risk-based customer identification program, file suspicious activity reports (SARs) for suspicious transactions of USD 5,000 or more, file currency transaction reports (CTRs) for currency transactions over USD 10,000, comply with the recordkeeping and information sharing provisions under section 314 of the USA PATRIOT Act, and designate an AML/CFT compliance officer.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-1970"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-finra-reg-notice-24-09-ai-2024",
    "title": "FINRA Regulatory Notice 24-09 (June 27, 2024) - FINRA Reminds Members of Regulatory Obligations When Using Generative Artificial Intelligence and Large Language Models",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-06-27",
    "bluf": "FINRA Regulatory Notice 24-09, issued on June 27, 2024 and titled 'FINRA Reminds Members of Regulatory Obligations When Using Generative Artificial Intelligence and Large Language Models', is the Financial Industry Regulatory Authority's principal guidance to its member firms (broker-dealers and associated persons) on regulatory obligations when deploying Generative AI and Large Language Models in member-firm operations. The Notice reminds members that existing FINRA rules apply to GenAI and LLM use without modification - there is no special carve-out for AI - and that members are expected to evaluate AI tools before deployment, ensure continued compliance with existing rules, and address technology governance including model risk management, data privacy and integrity, reliability and accuracy. FINRA emphasises the rules apply 'whether member firms are directly developing Gen AI tools or when leveraging the technology of a third party', and that GenAI use must comply with content standards 'regardless of whether communications are generated by a human or technology tool'. The principal FINRA rules referenced are Rule 3110 (Supervision) - requiring members to have 'a reasonably designed supervisory system tailored to its business', with policies and procedures addressing technology governance where Gen AI tools are part of the supervisory system - and Rule 2210 (Communications with the Public) - requiring all communications to comply with content standards regardless of source. Although Notice 24-09 does not provide detailed prescriptive specifications for model risk management or third-party vendor oversight frameworks, it establishes the regulatory baseline against which FINRA examinations and enforcement actions will assess member-firm Gen AI deployments. The Notice is issued in the context of FINRA's broader AI workstream and complements the SEC's parallel AI rulemaking and enforcement posture under the Investment Advisers Act of 1940 and the Securities Exchange Act of 1934.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "finra-rule-3110-supervision",
        "finra-cybersecurity-practices-2018",
        "us-sec-investment-advisers-act-1940-ai-rulemaking",
        "us-cfpb-circular-2023-03-adverse-action-ai",
        "owasp-llm-top-10-2025"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "finra-3110-supervision"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-finra-rn-24-09-2024-genai-llm-firm-supervision",
    "title": "FINRA Regulatory Notice 24-09 (2024) - Member Firm Obligations on Generative AI and Large Language Models",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "FINRA Regulatory Notice 24-09 (27 June 2024) reminds FINRA member firms that existing FINRA rules continue to apply when firms develop, integrate, or deploy generative AI tools and large language models in their business. The notice covers customer-facing chatbots, employee-facing GenAI assistants, automated content generation for communications with the public, model-assisted surveillance and supervision, and automated trading and order handling. The notice emphasises that member firms must (1) have a reasonably designed supervisory system tailored to the GenAI use case (FINRA Rule 3110), (2) ensure communications with the public comply with content standards and recordkeeping (FINRA Rules 2210 and 4511 plus SEC 17a-4 retention rules), (3) supervise associated persons and third-party vendors providing AI tools (FINRA Rule 3110, SEC OCIE risk alerts on outsourcing), (4) protect customer information and confidentiality (FINRA Rule 4530, SEC Regulation S-P), (5) consider conflicts of interest particularly where GenAI affects investment recommendations (Reg BI), and (6) ensure books and records reflect all communications including AI-generated content (Rule 4511). Notice 24-09 does not create new rules but clarifies the application of existing rules to GenAI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "frb-sr-11-7-model-risk-management",
      "us-eo-14179-ai-2025"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fisa-50-usc-ch36",
    "title": "United States Foreign Intelligence Surveillance Act (Title 50 USC Chapter 36): Electronic Surveillance Definitions, FISA Court, Applications, Issuance of Orders, Section 702 Targeting, and Criminal Sanctions",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Foreign Intelligence Surveillance Act of 1978, codified at Title 50 of the United States Code, Chapter 36, is the principal federal statute governing the acquisition of foreign intelligence information through electronic surveillance, physical searches, and related techniques and is administered by the Department of Justice with judicial oversight by the Foreign Intelligence Surveillance Court. Foreign Intelligence Surveillance Act, 50 U.S.C. 1801 contains the definitions of foreign power, agent of a foreign power, electronic surveillance, and other foundational terms. Foreign Intelligence Surveillance Act, 50 U.S.C. 1802 permits the President, through the Attorney General, to authorize electronic surveillance without a court order in limited circumstances where the surveillance targets only foreign power communications, no substantial likelihood exists of acquiring United States person communications, and minimization procedures meet statutory standards. Foreign Intelligence Surveillance Act, 50 U.S.C. 1803 establishes the Foreign Intelligence Surveillance Court of eleven district court judges publicly designated by the Chief Justice. Foreign Intelligence Surveillance Act, 50 U.S.C. 1804 governs applications for court orders, requiring written application by a Federal officer upon oath or affirmation with Attorney General approval. Foreign Intelligence Surveillance Act, 50 U.S.C. 1805 governs issuance of orders, requiring probable cause that the target is a foreign power or agent thereof and that minimization procedures comply with law. Foreign Intelligence Surveillance Act, 50 U.S.C. 1806 governs use of information acquired. Foreign Intelligence Surveillance Act, 50 U.S.C. 1809 establishes criminal sanctions for violations. Foreign Intelligence Surveillance Act, 50 U.S.C. 1881a, the Section 702 authority, governs procedures for targeting non-United States persons reasonably believed to be located outside the United States for foreign intelligence acquisition. Subchapter II covers physical searches, Subchapter III covers pen registers and trap and trace devices, Subchapter IV covers access to business records, and Subchapter V covers oversight and congressional reporting. The Act is the controlling federal instrument for foreign intelligence surveillance and operates alongside Executive Order 12333.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fisa-foreign-intelligence-surveillance-act-50-usc-ch36",
    "title": "Foreign Intelligence Surveillance Act 1978 - 50 USC Chapter 36",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Chapter 36 of title 50 of the United States Code codifies the Foreign Intelligence Surveillance Act of 1978 (Public Law 95-511, as amended) and subsequent additions including the FISA Amendments Act of 2008 and the USA FREEDOM Act of 2015. Subchapter I (sections 1801 through 1813) governs electronic surveillance: section 1801 supplies definitions, sections 1802 and 1803 establish the Foreign Intelligence Surveillance Court and FISA Court of Review, sections 1804 and 1805 prescribe the application and order procedure for electronic surveillance targeting foreign powers and agents of foreign powers, sections 1806 through 1813 cover use, minimisation, congressional oversight, and emergency procedures. Subchapter II covers physical searches; subchapter III covers pen register and trap-and-trace; subchapter IV covers tangible-things production (Section 215 as amended); subchapter V covers oversight; subchapter VI (sections 1881 through 1881h) covers additional procedures regarding certain persons outside the United States including the Section 702 program; subchapter VII covers protection of persons assisting the government. FISA is the principal statutory framework for US foreign-intelligence collection and is the operative legal authority constraining cybersecurity, signals-intelligence, and counter-terrorism programs that may incidentally collect on US persons. AI systems used in intelligence analysis, target selection, or minimisation review must operate within the FISA framework and document their inputs, outputs, and human-review disposition for IG oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-national-emergencies-act-50-usc-ch34"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fish-and-wildlife-coordination-act",
    "title": "US Fish and Wildlife Coordination Act (16 USC ch 5A): Consultation on Water-Resource Projects",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Fish and Wildlife Coordination Act, codified at 16 U.S.C. Chapter 5A, subchapter I (sections 661-667e), requires federal agencies and federally permitted or licensed projects that modify water bodies to consult wildlife agencies and give wildlife conservation equal consideration with other project purposes, administered through the US Fish and Wildlife Service (Department of the Interior). Section 661 sets the short title and the general policy that wildlife conservation shall receive equal consideration and be coordinated with other features of water-resource development programs. Section 662 contains the core consultation requirement: whenever the waters of any stream or other body of water are proposed or authorized to be impounded, diverted, the channel deepened, or otherwise controlled or modified for any purpose whatever, including navigation and drainage, by any department or agency of the United States, or by any public or private agency under Federal permit or license, that department or agency first shall consult with the US Fish and Wildlife Service and with the head of the State agency exercising administration over the wildlife resources of the State in which the facility is to be constructed, with a view to the conservation of wildlife resources by preventing loss of and damage to those resources and providing for their development and improvement in connection with the project. Section 663 provides for the conservation, maintenance and management of wildlife resources affected by the impoundment or diversion, including the use of project lands and waters and mitigation measures. Section 664 addresses administration and authorizes rules and regulations, and section 665 provides for investigations regarding the effects of sewage and industrial wastes. Section 666a sets out penalties for specified violations, and section 666b contains the definitions. The Act operates principally by requiring early consultation and the incorporation of wildlife conservation and mitigation findings into the planning and reports for federally authorized, permitted or licensed water-resource projects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fisma-2014-federal-information-security-modernization-pl-113-283",
    "title": "US Federal Information Security Modernization Act of 2014 (Public Law 113-283) - Federal Civilian Cybersecurity Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Federal Information Security Modernization Act of 2014 amended the Federal Information Security Management Act of 2002 to clarify operational authority of the Department of Homeland Security over federal civilian executive branch information security, codify continuous monitoring of agency information systems, require major incident reporting to Congress within seven days, require Office of Management and Budget oversight and annual reports, require National Institute of Standards and Technology security standards and guidelines, and authorise the Department of Homeland Security to administer binding operational directives to civilian executive branch agencies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "us-cisa-cybersecurity-information-sharing-6-usc-1501"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fit21-financial-innovation-technology-act-2024",
    "title": "Financial Innovation and Technology for the 21st Century Act (FIT21)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-05-24",
    "bluf": "The FIT21 Act establishes a comprehensive U.S. regulatory framework for digital assets, creating a test under Section 101 to classify them as either 'digital commodities' under CFTC jurisdiction or 'restricted digital assets' (securities) under SEC jurisdiction based on the network's decentralization status, and provides specific registration pathways for market participants.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sec-digital-asset-framework",
      "us-cftc-digital-asset-guidance",
      "eu-mica-regulation-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fl-fdbr-2023",
    "title": "US Florida Digital Bill of Rights 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Florida Digital Bill of Rights establishes consumer privacy rights over personal data, prohibits social media platforms from processing personal data of children under 18 without verifiable parental consent, requires opt-in consent for sensitive data processing, and authorises the Florida Attorney General to impose civil penalties of up to USD 50,000 per violation with a mandatory 45-day cure period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-fl-fdbr-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ccpa-cpra-2023-marketing-rights"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-flammable-fabrics-act",
    "title": "US Flammable Fabrics Act (15 USC ch 25): Flammability Standards for Apparel and Fabrics",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Flammable Fabrics Act (15 U.S.C. ch. 25) prohibits the manufacture for sale, sale and importation of highly flammable wearing apparel and interior furnishings, administered by the Consumer Product Safety Commission. Section 1192 sets out the prohibited transactions: it is unlawful to manufacture for sale, to sell or offer for sale, or to import into the United States, any article of wearing apparel or interior furnishing, or any fabric or related material, that fails to conform to an applicable flammability standard or regulation issued under section 1193, and such conduct is an unfair method of competition and an unfair or deceptive act under the Federal Trade Commission Act. Section 1193 authorizes the Commission to issue flammability standards where needed to protect the public against unreasonable risk of the occurrence of fire leading to death, injury or significant property damage, supporting standards for items such as childrens sleepwear, mattresses and carpets. Section 1194 provides for enforcement, inspection and investigation. Section 1196 sets criminal penalties for a willful violation, and section 1197 provides a guaranty defense for a seller that relies in good faith on a supplier guaranty. The Act is the legal foundation for US textile and apparel flammability compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-florida-digital-bill-rights-fdbr-2023",
    "title": "Florida Digital Bill of Rights (FDBR) (Chapter 501, Part IV, Florida Statutes)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Florida Digital Bill of Rights (FDBR) grants Florida consumers rights to control their personal data held by large for-profit online platforms, defined as 'controllers' with over $1 billion in global gross annual revenue. Per Section 501.705, consumers have the right to access, correct, delete, and obtain a copy of their data, and to opt out of the sale of personal data, targeted advertising, and certain profiling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fluid-milk-promotion-act",
    "title": "US Fluid Milk Promotion Act of 1990 (7 USC ch 93): National Processor Advertising and Promotion Board",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Fluid Milk Promotion Act of 1990 (7 U.S.C. ch. 93, sections 6401 to 6417) authorizes a coordinated program of advertising and promotion for fluid milk funded by assessments on fluid milk processors, administered by the Secretary of Agriculture. Section 6401 sets out the findings and declaration of policy, providing that the purpose of the program is not to compete with or replace individual advertising or promotion efforts and that it constitutes government speech promoting government objectives. Section 6402 defines the terms, providing that fluid milk processor means persons processing more than 3,000,000 pounds of fluid milk products in consumer-type packages per month. Section 6403 sets the authority to issue orders, section 6405 governs the findings and issuance of orders, and section 6407 sets the required terms in orders, providing for the establishment of a National Processor Advertising and Promotion Board. Section 6409 sets the assessments, providing that the rate of assessment prescribed by the order shall be 20 cents per hundredweight. Section 6410 provides for petition and review, section 6411 provides for enforcement, including a civil penalty assessed by the Secretary of not less than 500 dollars nor more than 5,000 dollars for each violation, and section 6412 provides investigations and power to subpoena. Section 6413 requires an initial referendum among fluid milk processors preceding order effectiveness, and section 6414 provides for the suspension or termination of orders. The Act is the federal advertising and promotion regime for fluid milk processors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fmcsa-49-cfr-365-motor-carrier-operating-authority",
    "title": "49 CFR Part 365 - Rules Governing Applications for Operating Authority (FMCSA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FMCSA 49 CFR Part 365 governs applications for motor carrier, broker, and freight forwarder operating authority, requiring an applicant to start the application process with the correct form, select the proper type of application, support FMCSA review, complete the New Entrant Safety Assurance Program, appeal any rejection, file amendments and supplementary evidence correctly, observe the procedures following publication in the FMCSA Register, handle opposed applications and reply statements, and follow the protest procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fmcsa-motor-carrier-safety-regulations-49-cfr"
    ],
    "primary_citations_count": 15
  },
  {
    "node_id": "us-fmcsa-49-cfr-382-controlled-substances-alcohol-testing",
    "title": "49 CFR Part 382 - Controlled Substances and Alcohol Use and Testing (FMCSA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FMCSA 49 CFR Part 382 requires motor carriers to test commercial driver license holders for controlled substances and alcohol, defining prohibited conduct, the testing procedures conducted under 49 CFR 40, and the pre-employment, post-accident, random, reasonable suspicion, return-to-duty, and follow-up testing categories, together with recordkeeping and management information system reporting, removal from safety-sensitive functions, and the requirement to maintain a policy and supervisor training.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fmcsa-motor-carrier-safety-regulations-49-cfr"
    ],
    "primary_citations_count": 22
  },
  {
    "node_id": "us-fmcsa-49-cfr-383-commercial-drivers-license-standards",
    "title": "49 CFR Part 383 - Commercial Driver License Standards; Requirements and Penalties (FMCSA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FMCSA 49 CFR Part 383 sets the commercial driver license standards, requiring a single license, the correct license class and endorsements for the vehicle and cargo, notification of convictions, suspensions, and previous employment, employer responsibilities, disqualification of drivers including for imminent hazards, knowledge and skills testing through approved methods, and the information and security features required on the commercial learner permit and commercial driver license.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fmcsa-motor-carrier-safety-regulations-49-cfr"
    ],
    "primary_citations_count": 26
  },
  {
    "node_id": "us-fmcsa-49-cfr-384-state-cdl-program-compliance",
    "title": "49 CFR Part 384 - State Compliance with Commercial Driver License Program (FMCSA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FMCSA 49 CFR Part 384 sets the standards a State must meet to comply with the commercial driver license program, requiring a conforming testing program and test standards, correct license issuance and CDLIS information, notification of licensing, disqualification, and traffic violations, limitations on licensing and surrender of prior licenses, State penalties and disqualification for serious offenses, enforcement of out-of-service orders and a prohibition on masking convictions, driver record and clearinghouse recordkeeping, examiner training and auditing, and the substantial compliance certifications subject to FMCSA program reviews and withholding of funds.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fmcsa-motor-carrier-safety-regulations-49-cfr"
    ],
    "primary_citations_count": 32
  },
  {
    "node_id": "us-fmcsa-49-cfr-391-qualifications-of-drivers",
    "title": "49 CFR Part 391 - Qualifications of Drivers and Longer Combination Vehicle Driver-Instructors (FMCSA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FMCSA 49 CFR Part 391 sets the qualifications of commercial motor vehicle drivers, requiring carriers to confirm general driver qualifications, apply disqualification rules, obtain an employment application, complete background investigations and annual reviews of the driving record, administer a road test or accepted equivalent, verify physical qualifications through a medical examination and valid medical examiner certificate, and maintain a driver qualification file and driver investigation history file for each driver.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fmcsa-motor-carrier-safety-regulations-49-cfr"
    ],
    "primary_citations_count": 15
  },
  {
    "node_id": "us-fmcsa-49-cfr-393-parts-accessories-safe-operation",
    "title": "49 CFR Part 393 - Parts and Accessories Necessary for Safe Operation (FMCSA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FMCSA 49 CFR Part 393 sets the parts and accessories necessary for safe operation of commercial motor vehicles, requiring operable lamps and reflective devices, service, parking, and emergency brake systems meeting performance and antilock standards, serviceable brake components, compliant glazing and window construction, safe fuel and electrical systems, and operable hazard warning signals and bus emergency exits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fmcsa-motor-carrier-safety-regulations-49-cfr"
    ],
    "primary_citations_count": 20
  },
  {
    "node_id": "us-fmcsa-49-cfr-395-hours-of-service-drivers",
    "title": "49 CFR Part 395 - Hours of Service of Drivers (FMCSA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FMCSA 49 CFR Part 395 sets the hours-of-service rules for commercial motor vehicle drivers, limiting maximum driving time and on-duty windows for property-carrying and passenger-carrying drivers, requiring a record of duty status supported by documents, prohibiting driving after an out-of-service order, and requiring electronic logging devices with defined motor carrier and driver responsibilities, automatic data recording, record submission and retention, and procedures for malfunctions and data diagnostic events.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fmcsa-motor-carrier-safety-regulations-49-cfr"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "us-fmcsa-49-cfr-396-inspection-repair-maintenance",
    "title": "49 CFR Part 396 - Inspection, Repair, and Maintenance (FMCSA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FMCSA 49 CFR Part 396 requires motor carriers to systematically inspect, repair, and maintain commercial motor vehicles and intermodal equipment, prohibit operation of unsafe vehicles, prepare driver vehicle inspection reports, conduct pre-trip driver inspections, perform a periodic (annual) inspection by a qualified inspector, and keep the maintenance and inspection records the rules require.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fmcsa-motor-carrier-safety-regulations-49-cfr"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "us-fmcsa-49-cfr-397-hazmat-driving-parking-routing",
    "title": "49 CFR Part 397 - Transportation of Hazardous Materials; Driving and Parking Rules (FMCSA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FMCSA 49 CFR Part 397 sets the driving, parking, and routing rules for the transportation of hazardous materials, requiring carriers and drivers to comply with the Federal motor carrier safety regulations and applicable State and local laws, maintain attendance and surveillance and observe the parking rules, take precautions against fires and smoking, meet the fueling and tire requirements, carry the required instructions and documents, meet the motor carrier responsibility for routing, observe highway routing designations and Federal standards, satisfy the public information and dispute resolution requirements, and handle preemption and waiver of preemption through to determination.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fmcsa-motor-carrier-safety-regulations-49-cfr"
    ],
    "primary_citations_count": 21
  },
  {
    "node_id": "us-fmcsa-motor-carrier-safety-regulations-49-cfr",
    "title": "US FMCSA Motor Carrier Safety Regulations (49 CFR Parts 390-399) - Hours of Service and ELD Compliance",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The US Federal Motor Carrier Safety Administration (FMCSA) administers 49 CFR Parts 390-399 (Federal Motor Carrier Safety Regulations); mandates Hours of Service (HOS) limits of 11 driving hours within a 14-hour window for property-carrying drivers after 10 consecutive off-duty hours; requires Electronic Logging Device (ELD) use for drivers subject to HOS; establishes the Compliance, Safety, Accountability (CSA) Safety Measurement System; and enforces safety fitness determinations with out-of-service orders for unsatisfactory-rated carriers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mobility-package-i-road-transport-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fmla-1993",
    "title": "The Family and Medical Leave Act of 1993",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Family and Medical Leave Act (FMLA) requires covered employers to provide eligible employees with up to 12 weeks of unpaid, job-protected leave per year for specified family and medical reasons, while maintaining group health benefits. This core entitlement is established under 29 U.S.C. § 2612.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ada-employment-title-1",
      "flsa-coverage",
      "eeoc-employment-rule",
      "shrm-hr-competency"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-fmla-1993-29-usc-ch28",
    "title": "United States Family and Medical Leave Act of 1993 (Title 29 USC Chapter 28): Findings and Purposes, Definitions Including Eligible Employee, 12 Workweeks of Leave Requirement, Employment and Benefits Protection, Prohibited Acts Including Interference and Retaliation, and Enforcement",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Family and Medical Leave Act of 1993 (FMLA), Public Law 103-3 of 5 February 1993, codified at Title 29 of the United States Code, Chapter 28, is the principal federal statute providing eligible employees of covered employers with up to 12 workweeks of unpaid, job-protected leave per year for specified family and medical reasons with continuation of group health insurance, and is administered by the Wage and Hour Division of the Department of Labor and enforced through Department of Labor investigations and private civil actions. FMLA, 29 U.S.C. 2601 contains the Congressional findings and purposes including that the number of single-parent households and two-parent households in which the single parent or both parents work is increasing significantly, and that it is important for the development of children and the family unit that fathers and mothers be able to participate in early childrearing. FMLA, 29 U.S.C. 2611 contains the definitions including eligible employee (an employee who has been employed for at least 12 months and for at least 1,250 hours of service during the previous 12-month period), employer (covered if 50 or more employees within 75 miles), and serious health condition. FMLA, 29 U.S.C. 2612 imposes the leave requirement entitling an eligible employee to a total of 12 workweeks of leave during any 12-month period for the birth of a son or daughter, placement for adoption or foster care, care of a spouse, son, daughter, or parent with a serious health condition, the employee's own serious health condition that makes the employee unable to perform their functions, and qualifying exigencies arising from a covered military member's active duty. FMLA, 29 U.S.C. 2614 governs employment and benefits protection ensuring restoration to position and maintenance of group health benefits during leave. FMLA, 29 U.S.C. 2615 prohibits employer interference with FMLA rights and discrimination or retaliation against employees opposing unlawful practices. FMLA, 29 U.S.C. 2617 governs enforcement through civil action remedies and Department of Labor investigative authority. The Act is the controlling federal instrument for family and medical leave entitlements in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fmla-29-usc-2612-leave-entitlement-requirements",
    "title": "29 U.S. Code § 2612 - Leave requirement",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This regulation requires employers to provide eligible employees with up to 12 workweeks of leave for specified family and medical reasons, and up to 26 workweeks for military caregiver leave, within a 12-month period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fmla-29-usc-2614-restoration-employment-after-fmla-leave",
    "title": "29 U.S. Code § 2614 - Employment and benefits protection",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must restore eligible employees returning from FMLA leave to their original or an equivalent position and maintain their health benefits during the leave, with specific exceptions for highly compensated employees and provisions for recovering premiums if an employee does not return.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fmla-family-medical-leave-act-29-cfr-825-employer-obligations",
    "title": "US Family and Medical Leave Act - 29 CFR Part 825 Employee Leave Rights & Employer Obligations",
    "domain": "Workplace",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The Family and Medical Leave Act (29 CFR Part 825) entitles eligible employees to 12 weeks of unpaid, job-protected leave per year for specified family and medical reasons - employers with 50+ employees must provide FMLA leave, restore employees to their position, and maintain group health benefits during leave.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-fmvss-111-rear-visibility",
    "title": "FMVSS No. 111 Rear Visibility (49 CFR 571.111)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "FMVSS No. 111 (Section 571.111) governs rear visibility, requiring that each applicable vehicle with a GVWR of 4,536 kg or less manufactured on or after May 1, 2018 provide a rear visibility image meeting the S5.5 requirements. Per S5.5.1 the field of view must include a minimum 150 mm wide portion along the circumference of specified test objects; per S5.5.2 the image of test objects A, B, and C must average not less than 5 minutes of arc; and per S5.5.3 the rearview image must be displayed within 2.0 seconds of the start of a backing event.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nhtsa-fmvss-federal-motor-vehicle-safety-standards-49-cfr-571"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fmvss-126-electronic-stability-control",
    "title": "FMVSS No. 126 Electronic Stability Control (49 CFR 571.126)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "FMVSS No. 126 (Section 571.126) requires Electronic Stability Control (ESC) systems on passenger cars, multipurpose passenger vehicles, trucks, and buses with a GVWR of 4,536 kg (10,000 lb) or less. Per S5.1.1 the ESC must apply brake torques individually to all four wheels under a control algorithm, and per S5.1.2 must be operational across all driving phases except below 20 km/h, in reverse, or during initialization. Stability is demonstrated against the yaw-rate criteria of S5.2 using the Sine with Dwell test in S7.9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nhtsa-fmvss-federal-motor-vehicle-safety-standards-49-cfr-571"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fmvss-138-tire-pressure-monitoring-systems",
    "title": "FMVSS No. 138 Tire Pressure Monitoring Systems (49 CFR 571.138)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "FMVSS No. 138 (Section 571.138) requires a Tire Pressure Monitoring System (TPMS) on passenger cars, multipurpose passenger vehicles, trucks, and buses with a GVWR of 4,536 kg (10,000 lb) or less (S2). Per S4.2(a) the low tire pressure telltale must illuminate not more than 20 minutes after one or more tires (up to four) reach a pressure 25 percent or more below the placard cold inflation pressure (or the applicable minimum, whichever is higher). Per S4.4(a) a malfunction telltale must warn the driver not more than 20 minutes after a TPMS malfunction occurs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nhtsa-fmvss-federal-motor-vehicle-safety-standards-49-cfr-571"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fmvss-208-occupant-crash-protection",
    "title": "FMVSS No. 208 Occupant Crash Protection (49 CFR 571.208)",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "FMVSS No. 208 (Section 571.208) specifies occupant crash protection requirements for passenger cars and other vehicles. Per S4.1 passenger cars must provide the specified occupant protection (including frontal and passive restraint requirements that phased in by manufacture date), and per S8.1 the frontal barrier crash test condition is a perpendicular impact into a fixed collision barrier at any speed up to and including 30 mph. Section S9 governs pressure vessels and explosive devices, including inflators used in occupant protection systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nhtsa-fmvss-federal-motor-vehicle-safety-standards-49-cfr-571"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fmvss-49-cfr-571-safety-standards",
    "title": "Federal Motor Vehicle Safety Standards (FMVSS)",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Federal Motor Vehicle Safety Standards (FMVSS) under 49 CFR Part 571 establish minimum safety performance requirements for motor vehicles and related equipment sold in the United States. This regulation, enforced by NHTSA, applies to all manufacturers, assemblers, and importers, mandating specific design, construction, and performance criteria to reduce traffic accidents and the resulting deaths and injuries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fmvss-federal-motor-vehicle-safety-standards",
    "title": "Federal Motor Vehicle Safety Standards (49 CFR Parts 500-599): Crash Avoidance, Crashworthiness, Post-Crash Standards, Brake Systems and Lighting Requirements",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The Federal Motor Vehicle Safety Standards (FMVSS) establish mandatory safety performance requirements for motor vehicles and equipment to reduce crashes, injuries, and fatalities. Applies to all manufacturers, importers, and distributors of motor vehicles and motor vehicle equipment in the United States under 49 U.S.C. § 30111, with key requirements in FMVSS No. 102 (Transmission Shift Position Sequence), FMVSS No. 108 (Lamps, Reflective Devices, and Associated Equipment), FMVSS No. 121 (Air Brake Systems), FMVSS No. 126 (Electronic Stability Control), and FMVSS No. 208 (Occupant Crash Protection).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26262-functional-safety-road-vehicles-2018",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "un-regulation-r156-software-updates-ota",
      "sae-j3016-levels-driving-automation-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-foia-1966",
    "title": "US Freedom of Information Act 1966",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Freedom of Information Act provides any person the right to request access to federal agency records, requires agencies to respond within 20 business days, and establishes nine exemptions protecting national security, internal agency matters, trade secrets, personal privacy, and law enforcement records from mandatory disclosure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-foia-1966.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-privacy-act-1974"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-food-conservation-energy-act-2008",
    "title": "US Food, Conservation, and Energy Act of 2008 (7 USC ch 113): Commodity Payments and Marketing Assistance Loans",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The commodity title of the Food, Conservation, and Energy Act of 2008 (the 2008 Farm Bill, 7 U.S.C. ch. 113, sections 8702 to 8793) provides direct payments, counter-cyclical payments, and nonrecourse marketing assistance loans to producers of covered commodities, administered by the Secretary of Agriculture through the Farm Service Agency and the Commodity Credit Corporation. Section 8702 defines the terms, providing that covered commodity includes wheat, corn, grain sorghum, barley, oats, upland cotton, long grain rice, medium grain rice, pulse crops, soybeans, and other oilseeds, that loan commodity adds extra long staple cotton, wool, mohair, honey, dry peas, lentils, and chickpeas, and that producer means an owner, operator, landlord, tenant, or sharecropper that shares in the risk of producing a crop. Section 8711 governs base acres and provides that a farm with 10 acres or less of base acres is generally ineligible for payments, with exceptions for socially disadvantaged and limited resource farmers. Section 8716 requires a producer agreement, under which the producer must comply with conservation requirements, wetland protection, and planting flexibility rules and must maintain the land for an agricultural or conserving use. Section 8717 sets the planting flexibility, prohibiting the planting of fruits, vegetables other than mung beans and pulse crops, and wild rice on base acres unless destroyed before harvest. Section 8731 provides for the availability of nonrecourse marketing assistance loans for loan commodities, section 8732 sets the loan rates, and section 8734 governs the repayment of loans. Subchapter III provides the peanut program. The Act is a foundational modern farm-support statute.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-foreign-account-tax-compliance-act-fatca-irs",
    "title": "US Foreign Account Tax Compliance Act (FATCA) - IRS",
    "domain": "Tax & Transfer Pricing",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "FATCA (IRC Chapter 4, sections 1471-1474) requires foreign financial institutions (FFIs) to identify and report US account holders to the IRS directly or via intergovernmental agreements (IGAs), withholding 30% on US-source payments to non-compliant FFIs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-foreign-assistance-act-1961-22-usc-2151",
    "title": "Foreign Assistance Act 1961 - 22 USC 2151 Congressional Findings on Development Cooperation",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 2151 of title 22 of the United States Code, the Foreign Assistance Act of 1961 (Public Law 87-195, enacted 4 September 1961), establishes the foundational congressional findings and policy on US development cooperation, declaring that the alleviation of the worst physical manifestations of poverty among the world's poor majority, the promotion of good governance through combating corruption, and the integration of development concerns into US foreign policy are central US objectives. The Act, as substantially amended through the Foreign Assistance Act Reorganization (Subchapter I covers development assistance; Subchapter II covers economic support fund; Subchapter III covers international military education and training; subsequent subchapters cover military assistance and additional programs), is the principal US statutory authority for the United States Agency for International Development (USAID), Foreign Military Financing, International Military Education and Training, and the broader US development cooperation framework. Section 2151n prohibits security assistance to governments engaging in gross violations of internationally recognised human rights (Leahy Law / Leahy Amendment). Section 502B (codified at 22 USC 2304) imposes a similar restriction. Section 620M (Leahy Law expanded restrictions for foreign security forces) and the Brooke Amendment (22 USC 2370(q)) further constrain assistance. The Foreign Assistance Act framework directly informs the State Department's annual Country Reports on Human Rights Practices, the Trafficking in Persons Report, and the Conflict-Affected and High-Risk Areas determinations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fcpa-foreign-corrupt-practices-act-1977",
      "ca-cfpoa-corruption-foreign-public-officials-act"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-foreign-corrupt-practices-act",
    "title": "US Foreign Corrupt Practices Act (15 USC 78dd-1 et seq): Anti-Bribery and Accounting Controls",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Foreign Corrupt Practices Act (15 U.S.C. 78dd-1 et seq.) prohibits the bribery of foreign officials to obtain or retain business and requires accurate books, records and internal accounting controls, enforced jointly by the Department of Justice and the Securities and Exchange Commission. Section 78dd-1 prohibits an issuer, and its officers, directors, employees, agents and stockholders, from corruptly offering, paying, promising or authorizing the giving of anything of value to a foreign official, foreign political party or candidate to influence an official act or to obtain or retain business, directly or through an intermediary where the payer knows the value will reach the official. Section 78dd-2 applies the same prohibition to domestic concerns, and section 78dd-3 to other persons acting in the territory of the United States. A narrow exception exists for facilitating payments for routine governmental action, and affirmative defenses exist for payments lawful under written local law and for reasonable bona fide expenditures. Section 78m(b) requires issuers to keep books and records that accurately reflect transactions and to maintain a system of internal accounting controls. Section 78ff sets the penalties, including substantial criminal fines and imprisonment. The Act is the legal foundation for US anti-corruption compliance programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-forest-rangeland-renewable-resources-planning-act",
    "title": "US Forest and Rangeland Renewable Resources Planning Act (16 U.S.C. Chapter 36): National Forest System Assessment, Programs and Land Management Plans",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Forest and Rangeland Renewable Resources Planning Act of 1974, as amended by the National Forest Management Act of 1976, is codified at 16 U.S.C. Chapter 36 (sections 1600 through 1614) and establishes the framework for the long-range assessment, programming, and land management planning of the renewable resources of the National Forest System, administered by the Secretary of Agriculture through the Forest Service. Section 1600 sets the congressional findings on the need for long-range planning of forest and rangeland renewable resources. Section 1601 requires a Renewable Resource Assessment of the Nation's forest and rangeland resources, updated periodically. Section 1602 requires a Renewable Resource Program prepared by the Secretary and transmitted to the President. Section 1603 requires National Forest System resource inventories. Section 1604 requires land and resource management plans for units of the National Forest System, developed using an interdisciplinary approach and with public participation, and is the core of the National Forest Management Act. Section 1605 addresses the protection, use, and management of renewable resources on non-Federal lands. Section 1607 governs the development and administration of National Forest System renewable resources, and section 1608 governs the National Forest Transportation System. The Act is the foundational planning statute for the National Forest System.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fpco-ferpa-annual-notification-requirements",
    "title": "US FPCO FERPA Annual Notification Requirements - Annual Rights Notice, Directory Information Policy and Student Consent Procedures",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under the Family Educational Rights and Privacy Act (FERPA), educational agencies and institutions must annually notify parents and eligible students of their rights to inspect, review, and seek amendment of education records, as well as their right to consent to disclosures of personally identifiable information, as mandated by 34 CFR § 99.7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-fraud-and-misuse-of-visas-18usc1546",
    "title": "US Fraud and Misuse of Visas, Permits and Other Documents (18 USC 1546): Document Forgery, Possession and Employment-Verification Fraud",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 1546 of Title 18 of the United States Code is the principal federal criminal statute punishing fraud and misuse of immigration documents, prosecuted by the Department of Justice and investigated by the Department of Homeland Security. Section 1546(a) makes it an offence to knowingly forge, counterfeit, alter or falsely make any immigrant or nonimmigrant visa, permit, border crossing card, alien registration receipt card or other document prescribed by statute or regulation for entry into or as evidence of authorized stay or employment in the United States, and equally to utter, use, attempt to use, possess, obtain, accept or receive any such document knowing it to be forged, counterfeited, altered or falsely made, or to have been procured by fraud or unlawfully obtained; it also reaches certain conduct involving blank document forms and impersonation in applications. The penalties under subsection (a) are tiered by purpose: imprisonment of up to twenty-five years if the offence was committed to facilitate an act of international terrorism, up to twenty years if to facilitate a drug-trafficking crime, up to ten years for a first or second offence not so aggravated, and up to fifteen years for other offences, in each case together with a fine. Section 1546(b) punishes the use, for the purpose of satisfying the employment-verification requirement of section 274A(b) of the Immigration and Nationality Act, of an identification document known not to have been lawfully issued for the use of the possessor, of a false identification document, or of a false attestation, by a fine or imprisonment of up to five years, or both. The section is the criminal backbone of the United States immigration-document integrity regime and the principal charge in benefit-fraud and employment-eligibility-fraud cases.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fresh-cut-flowers-greens-promotion-information-act",
    "title": "US Fresh Cut Flowers and Fresh Cut Greens Promotion and Information Act of 1993 (7 USC ch 97): Promotion Council and Assessments",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Fresh Cut Flowers and Fresh Cut Greens Promotion and Information Act of 1993 (7 U.S.C. ch. 97, sections 6801 to 6814) authorizes a coordinated program of generic promotion and information for fresh cut flowers and fresh cut greens funded by assessments, administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 6801 sets out the findings and declaration of policy, providing that it is the policy of Congress to authorize the establishment of an orderly procedure for the development and financing of an effective and coordinated program of generic promotion. Section 6802 defines the terms, providing that cut flowers encompasses all flowers cut from growing plants that are used as fresh cut flowers. Section 6803 authorizes the issuance of orders, and section 6804 sets the required terms, providing for the establishment of a Fresh Cut Flowers and Fresh Cut Greens Promotion Council consisting of 25 members and providing that each qualified handler shall pay an assessment on each sale to a retailer or exempt handler at a rate of one-half of 1 percent initially. Section 6805 provides for exclusion and determinations, section 6806 requires a referendum not later than 3 years after the issuance of an order, and section 6807 provides for petition and review. Section 6808 provides for enforcement, including a civil penalty of not less than 500 dollars nor more than 5,000 dollars for each violation, section 6809 provides investigations and power to subpoena, and section 6811 provides the authority for the Secretary to suspend or terminate an order. The Act is the federal checkoff regime for fresh cut flowers and greens.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-frontier-model-voluntary-pre-release-disclosure-2026",
    "title": "US Voluntary Covered Frontier Model Pre-Release Disclosure Framework (Sec. 3, EO Promoting Advanced AI Innovation and Security, 2026)",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "Section 3 of the Executive Order Promoting Advanced Artificial Intelligence Innovation and Security signed June 2, 2026 establishes a voluntary federal framework under which frontier AI model developers may (i) engage the Federal Government to determine whether models under development meet the 'covered frontier model' designation and (ii) provide such models to the Federal Government up to 30 days before they plan to release such models to other trusted partners. The covered frontier model designation is set by the Director of the National Security Agency in consultation with the National Cyber Director, the APST (Assistant to the President for Science and Technology) and the Director of the Cybersecurity and Infrastructure Security Agency, on the basis of advanced cyber capabilities; the specific designation criteria are classified. The 30-day window is the maximum permitted pre-release period of government access, not a mandatory disclosure floor; participation in the framework is voluntary throughout. Section 3 contains a binding statutory-construction clause: 'Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.' The Sec. 3 framework operates alongside but does not displace voluntary commitments previously made by frontier developers, voluntary engagement with NIST AISI evaluation programmes, and any private contractual arrangements between developers and trusted partners (typically downstream API customers, government users, and enterprise deployers under model availability agreements). Developers electing to participate retain control over (a) timing within the 30-day maximum, (b) the scope of model artifacts shared, (c) the categories of evaluation conducted by government, and (d) the conditions on use of evaluation findings. The framework's enforcement architecture is reputational and contractual, not statutory; there is no civil penalty, criminal penalty, or administrative-licence sanction attached to non-participation or to deviation from the 30-day window.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-promoting-advanced-ai-innovation-security-2026",
      "nist-ai-600-1-generative-ai-profile-2024",
      "nist-ai-rmf-1-0",
      "us-eo-14179-removing-barriers-ai-2025"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-fsia-foreign-sovereign-immunities-act-28-usc-ch97",
    "title": "United States Foreign Sovereign Immunities Act of 1976 (FSIA) (Title 28 USC Chapter 97): Findings and Declaration of Purpose, Definitions of Foreign State and Agency or Instrumentality, Immunity of Foreign State from Jurisdiction, General Exceptions to Jurisdictional Immunity, Terrorism Exception, Counterclaims, Immunity from Attachment and Execution, and Exceptions to Attachment Immunity",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Foreign Sovereign Immunities Act of 1976 (FSIA), Public Law 94-583 of 21 October 1976, codified at Title 28 of the United States Code, Part IV, Chapter 97 (Jurisdictional Immunities of Foreign States), is the principal federal statute providing the sole and exclusive basis for jurisdiction over foreign states in United States courts, and is administered through United States district court jurisdiction over civil actions against foreign states and the State Department's role in litigation involving foreign sovereigns. FSIA, 28 U.S.C. 1602 contains the findings and declaration of purpose providing that the determination by United States courts of the claims of foreign states to immunity from the jurisdiction of such courts would serve the interests of justice and would protect the rights of both foreign states and litigants in United States courts. FSIA, 28 U.S.C. 1603 contains the definitions including foreign state (which includes a political subdivision of a foreign state, or an agency or instrumentality of a foreign state) and agency or instrumentality (any entity which is a separate legal person, corporate or otherwise, and which is an organ of a foreign state or political subdivision thereof, or a majority of whose shares or other ownership interest is owned by a foreign state or political subdivision thereof, and which is neither a citizen of a State of the United States nor created under the laws of any third country). FSIA, 28 U.S.C. 1604 provides that subject to existing international agreements to which the United States is a party at the time of enactment of this Act, a foreign state shall be immune from the jurisdiction of the courts of the United States and of the States except as provided in sections 1605 to 1607. FSIA, 28 U.S.C. 1605 contains the general exceptions to jurisdictional immunity including waiver, commercial activity carried on in the United States, expropriation in violation of international law, rights in property in the United States acquired by succession or gift, noncommercial torts in the United States, agreements to arbitrate, and maritime liens. FSIA, 28 U.S.C. 1605A contains the terrorism exception to jurisdictional immunity. FSIA, 28 U.S.C. 1607 governs counterclaims. FSIA, 28 U.S.C. 1609 provides for immunity from attachment and execution of property of a foreign state. FSIA, 28 U.S.C. 1610 contains the exceptions to immunity from attachment or execution. The Act is the controlling federal instrument for sovereign immunity in United States courts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fsis-9-cfr-381-poultry-products-inspection-regulations",
    "title": "9 CFR Part 381 - Poultry Products Inspection Regulations (Slaughter Inspection, HACCP, Chilling and Contamination Control) (USDA FSIS)",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "9 CFR Part 381 implements the Poultry Products Inspection Act, requiring inspection at every establishment in which poultry is slaughtered or poultry products are processed for use as human food in commerce, and requiring that all poultry and poultry products processed in an official establishment be inspected, handled, processed, marked, and labeled as required. Before being granted Federal inspection, establishments must have written Sanitation SOPs, recall procedures, and a validated HACCP plan, and slaughter establishments must control visible fecal contamination, sample for microbial organisms at prescribed locations and frequencies, and meet chilling and freezing performance standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-poultry-products-inspection-act",
      "us-fsis-9-cfr-416-sanitation-performance-standards",
      "us-fsis-9-cfr-417-haccp-systems-meat-poultry"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fsis-9-cfr-416-sanitation-performance-standards",
    "title": "9 CFR Part 416 - Sanitation (Sanitation Performance Standards and Sanitation Standard Operating Procedures for Meat and Poultry Establishments) (USDA FSIS)",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "9 CFR Part 416 requires every official meat and poultry establishment to be operated and maintained in a manner sufficient to prevent the creation of insanitary conditions and to ensure that product is not adulterated. It sets performance standards for grounds, facilities, equipment, water supply, employee hygiene, and tagging of insanitary equipment, and requires each establishment to develop, implement, and maintain written Sanitation Standard Operating Procedures (Sanitation SOPs) with monitoring, corrective actions, recordkeeping, and FSIS verification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-federal-meat-inspection-act",
      "us-poultry-products-inspection-act",
      "haccp-food-safety"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fsis-9-cfr-417-haccp-systems-meat-poultry",
    "title": "9 CFR Part 417 - Hazard Analysis and Critical Control Point (HACCP) Systems for Meat and Poultry Establishments (USDA FSIS)",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "9 CFR Part 417 requires every official meat and poultry establishment to conduct a hazard analysis to determine the food safety hazards reasonably likely to occur and to develop and implement a written HACCP plan whenever such hazards are identified. The plan must list food safety hazards, critical control points, critical limits, monitoring procedures, corrective actions, recordkeeping, and verification procedures, and must be signed, dated, and reassessed at least annually. Failure to develop and implement a compliant HACCP plan may render the products adulterated.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-federal-meat-inspection-act",
      "us-poultry-products-inspection-act",
      "us-fsis-9-cfr-416-sanitation-performance-standards",
      "haccp-food-safety"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-fsma-2011-produce-safety-rule-21-cfr-112",
    "title": "Standards for the Growing, Harvesting, Packing, and Holding of Produce for Human Consumption (Produce Safety Rule)",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The FSMA Produce Safety Rule (21 CFR Part 112) establishes science-based minimum standards for the safe growing, harvesting, packing, and holding of fruits and vegetables grown for human consumption. It applies to domestic and foreign farms that are covered under the rule and requires compliance with specific provisions on agricultural water, biological soil amendments, health and hygiene, animals in growing areas, and equipment, tools, and buildings.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-haccp-2022",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fsma-21-cfr-part-1-subpart-l-foreign-supplier-verification",
    "title": "US FSMA: 21 CFR Part 1 Subpart L Foreign Supplier Verification Programs (FSVP) for Importers of Food for Humans and Animals",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "21 CFR the relevant part the relevant subpart (Foreign Supplier Verification Programs, FSVP) requires US importers of food for humans and animals to verify that their foreign suppliers produce food in compliance with US food safety requirements offering the same level of protection as FDA-regulated US producers. The FSVP importer (defined per 1.500 as the US owner or consignee at time of US entry, or the US agent of the foreign owner if no US owner) must develop and implement an FSVP for each food/foreign supplier combination. Required activities include hazard analysis (1.504), evaluation of supplier compliance status (1.505), determination of verification activities (1.506), conducting verification (1.508), corrective actions (1.508), and records (1.510). FDA enforces via review at the port of entry (Importer Number / FSVP Importer Number required on US Customs and Border Protection documentation) and on-site inspection of the US importer. Failure triggers refusal of entry, detention, and potential criminal liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fsma_117",
        "fsma_112",
        "codex_haccp",
        "importer_records",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fsma-21-cfr-part-117-preventive-controls-human-food"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fsma-21-cfr-part-1-subpart-o-sanitary-transportation",
    "title": "US FSMA: 21 CFR Part 1 Subpart O Sanitary Transportation of Human and Animal Food",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "21 CFR the relevant part the relevant subpart implements FSMA the relevant section by setting requirements for the sanitary transportation of human and animal food in the United States to prevent food contamination during transport. The rule applies to shippers, loaders, carriers (by motor vehicle or rail) and receivers, with primary responsibility falling on the shipper to specify sanitary requirements (1.908), the carrier to provide cleaned and temperature-suitable vehicles and equipment (1.906), the loader to verify suitability before loading (1.908), and the receiver to assess condition on arrival (1.910). Records of training, written procedures, written agreements assigning responsibility, and temperature monitoring must be retained for minimum 12 months. Violations are prohibited acts under 21 USC 331 and may trigger administrative detention and civil penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fsma_117",
        "fsma_112",
        "fsma_fsvp",
        "codex_haccp",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fsma-21-cfr-part-117-preventive-controls-human-food"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fsma-21-cfr-part-112-produce-safety-rule",
    "title": "US FSMA: 21 CFR Part 112 Standards for the Growing, Harvesting, Packing, and Holding of Produce for Human Consumption (Produce Safety Rule)",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "the US FSMA produce safety rule (Produce Safety Rule) establishes minimum science-based standards for the safe growing, harvesting, packing, and holding of produce for human consumption on farms. the relevant subpart requires personnel qualifications and training; the relevant subpart covers health and hygiene; the relevant subpart sets agricultural water standards including microbial water quality criteria; the relevant subpart addresses biological soil amendments of animal origin; the relevant subpart covers domesticated and wild animals; the relevant subpart covers growing/harvesting/packing/holding activities; the relevant subpart addresses equipment, tools, buildings, and sanitation; the relevant subpart covers sprouts (additional pathogen testing requirements); the relevant subpart requires records retained minimum 2 years. The rule applies to farms growing covered produce with annual food sales above the qualified-exemption threshold. Major industry impact includes mandatory agricultural water testing, training of personnel and supervisors per FDA-recognised curriculum, and recordkeeping aligned with FDA inspection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fsma_117",
        "fsma_fsvp",
        "codex_haccp",
        "eu_852",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fsma-21-cfr-part-117-preventive-controls-human-food"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fsma-21-cfr-part-117-preventive-controls-human-food",
    "title": "US FSMA: 21 CFR Part 117 Current Good Manufacturing Practice, Hazard Analysis, and Risk-Based Preventive Controls for Human Food",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "the US FSMA preventive controls rule is the cornerstone FDA regulation implementing the Food Safety Modernization Act (FSMA) requirement that food facilities subject to registration under 21 USC 350d implement a Food Safety Plan with hazard analysis and risk-based preventive controls. the relevant subpart defines applicability and exemptions; the relevant subpart sets out current Good Manufacturing Practice (CGMP) requirements; the relevant subpart requires hazard analysis (s.117.130), preventive controls (s.117.135), monitoring (s.117.140), corrective actions (s.117.150), verification (s.117.155), recall plan (s.117.139), supply-chain program (s.117.405), and training (s.117.4); the relevant subpart sets recordkeeping requirements (records retained minimum 2 years, immediately available within 24 hours of FDA request). Failure to comply can trigger administrative detention, suspension of facility registration, mandatory recall, and criminal liability under 21 USC 333.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "codex_haccp",
        "sfca_canada",
        "eu_852",
        "fda_fsvp",
        "fda_produce_safety",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-cxc-1-1969-general-principles-food-hygiene"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-fsma-21-cfr-part-121-intentional-adulteration",
    "title": "US FSMA: 21 CFR Part 121 Mitigation Strategies to Protect Food Against Intentional Adulteration",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "the US FSMA intentional adulteration rule implements FSMA the relevant section by requiring registered food facilities to prepare and implement a written Food Defense Plan to identify vulnerabilities to intentional adulteration intended to cause wide-scale public health harm, and to implement mitigation strategies at vulnerable points called Actionable Process Steps. The rule covers vulnerability assessment per 121.130 using the FDA Three Elements Method or another approach, identification of mitigation strategies per 121.135, monitoring per 121.140, corrective actions per 121.145, verification per 121.150, training per 121.4, and recordkeeping per the relevant subpart (records retained minimum 2 years). Compliance applies to large facilities since 2019, small facilities 2020, very small facilities 2021. Failure can trigger administrative actions, civil penalties, and product seizure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fsma_117",
        "bioterrorism_act",
        "codex_food_defense",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fsma-21-cfr-part-117-preventive-controls-human-food"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ftc-16-cfr-436-franchise-disclosure-rule",
    "title": "16 CFR Part 436 - Disclosure Requirements and Prohibitions Concerning Franchising (FTC)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "FTC 16 CFR Part 436 (the Franchise Rule) governs pre-sale franchise disclosure, requiring a franchisor to furnish a Franchise Disclosure Document within the required timeframe with a compliant cover page and table of contents, complete all 23 required disclosure items following the preparation instructions, update the disclosures on the required schedule, apply exemptions only where their conditions are met, observe the additional prohibitions on franchise sales practices, and comply with other applicable laws and rules.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 11
  },
  {
    "node_id": "us-ftc-16-cfr-part-233-deceptive-pricing-guides",
    "title": "FTC 16 CFR Part 233 - Guides Against Deceptive Pricing",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "16 CFR Part 233 contains the Federal Trade Commission's Guides Against Deceptive Pricing, enforced under section 5 of the FTC Act (15 USC 45) against unfair or deceptive pricing practices in the advertising and sale of consumer products and services. Section 233.1 governs former price comparisons - the former price compared in advertising must be an actual, bona fide price at which the article was offered to the public on a regular basis for a reasonably substantial period of time in the recent, regular course of business, honestly and in good faith; fictitious or inflated former prices established solely to enable a subsequent large-reduction claim are prohibited. Section 233.2 governs retail price comparisons and comparable value comparisons - the higher comparison price must be the regular price in the area or a bona fide price for goods of essentially similar quality and comparable value. Section 233.3 governs advertising of retail prices that have been established or suggested by manufacturers or other non-retail distributors - the manufacturer's suggested or list price must be the price at which the goods are regularly sold by a substantial number of principal retailers in the area, not an inflated list price designed to enable apparent reductions. Section 233.4 governs bargain offers based on the purchase of other merchandise (free, half-price, BOGO, 2-for-1) - the price of the article required to be purchased must not have been increased to recover the cost of the article advertised as free or reduced, and the quality must not have been reduced. Section 233.5 covers miscellaneous price comparisons including factory-direct, wholesale, and special sale claims. Violations are pursued under FTC Act section 5 with injunctive relief, consumer redress under section 19, and civil penalties up to USD 51,744 per violation under 16 CFR 1.98 (2025 adjustment).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "former_price_substantiation",
        "msrp_and_list_price_rules",
        "free_bogo_advertising_substantiation"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-deceptive-acts",
      "us-ftc-green-guides-environmental-claims-2012",
      "ftc-endorsement-guides-2023",
      "us-ftc-16-cfr-part-435-mail-internet-telephone-order-merchandise-rule"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ftc-16-cfr-part-254-vocational-distance-education-deceptive-practices",
    "title": "FTC 16 CFR Part 254 - Guides for Private Vocational and Distance Education Schools",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "16 CFR Part 254 contains the Federal Trade Commission's Guides for Private Vocational and Distance Education Schools, enforced under section 5 of the FTC Act (15 USC 45) against unfair or deceptive practices in the marketing, sale and operation of for-profit vocational and distance education programs. Section 254.0 sets scope and application to all industry members offering vocational or distance education for a fee. Section 254.1 defines industry members and recruitment terminology. Section 254.2 prohibits deceptive trade or business names that imply public or non-profit status when none exists. Section 254.3 prohibits misrepresentation of the extent or nature of accreditation, approval, recognition, endorsement or licensing - including misrepresenting state-board licensing as full programmatic accreditation. Section 254.4 prohibits misrepresentation of facilities, services, qualifications of staff, status, and employment prospects for students after training - this is the core prohibition and includes prohibitions on misrepresenting instructor credentials, the availability or type of employment after graduation, financial aid availability, and the conduct of distance education versus in-person instruction. Section 254.5 prohibits misrepresentation of enrollment qualifications or limitations including false claims of selective admission. Section 254.6 prohibits deceptive use of diplomas, degrees or certificates that imply state authorisation or accreditation not held. Section 254.7 prohibits deceptive sales practices including bait-and-switch employment offers, failure to disclose total program cost and refund policy prior to enrollment, and failure to disclose all requirements for successful completion. Violations are pursued under FTC Act section 5 and may result in injunctions, consumer redress, civil penalties up to USD 51,744 per violation (16 CFR 1.98 adjusted), and bans from the education industry under section 19 of the FTC Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "deceptive_practice_taxonomy",
        "substantiation_requirements",
        "enforcement_remedies"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-deceptive-acts",
      "ftc-endorsement-guides-2023",
      "us-ftc-16-cfr-part-323-made-in-usa-labeling-rule",
      "us-ftc-16-cfr-part-435-mail-internet-telephone-order-merchandise-rule"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ftc-16-cfr-part-323-made-in-usa-labeling-rule",
    "title": "US FTC 16 CFR Part 323 Made in USA Labeling Rule - Federal Trade Commission Standard for Unqualified Country-of-Origin Claims on Labeled Products",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Federal Trade Commission Made in USA Labeling Rule codified at 16 CFR Part 323 establishes binding country-of-origin labeling requirements with section 323.1 defining a Made in the United States representation as any unqualified representation about country of origin including the term Made in USA or USA, section 323.2 declaring it an unfair or deceptive act or practice to make such a representation on a product label unless final assembly or processing occurs in the United States, all significant processing has been performed in the United States, and all or virtually all ingredients or components are made and sourced in the United States, section 323.3 extending the same standards to mail order catalogs and promotional materials, and section 323.4 providing that violations are treated as violations of section 18 of the Federal Trade Commission Act with civil penalties of up to $51,744 per violation as of 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-deceptive-acts"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ftc-16-cfr-part-429-cooling-off-rule",
    "title": "US FTC 16 CFR Part 429 Cooling-Off Rule - Three Business Day Cancellation Right for Door-to-Door and Off-Premises Consumer Sales",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Federal Trade Commission Cooling-Off Rule codified at 16 CFR Part 429 establishes a binding three business day right of cancellation for consumer sales of goods or services with a purchase price of $25 or more conducted at the buyer's home, at a temporary place of business, or at any other location that is not the seller's permanent place of business, with section 429.0 defining door-to-door sale and related terms, section 429.1 setting out the substantive rule requiring sellers to furnish a completed receipt or contract, two copies of a Notice of Cancellation on the prescribed form, and a verbal notice of the cancellation right, and prohibiting misrepresentation of cancellation rights, transfer of buyer debt obligations and certain bad faith practices, section 429.2 addressing preemption and the relationship to state laws that provide equal or greater consumer protection, and section 429.3 exempting specific transactions including motor vehicle auctions and arts and crafts fairs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-deceptive-acts"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ftc-16-cfr-part-435-mail-internet-telephone-order-merchandise-rule",
    "title": "US FTC 16 CFR Part 435 Mail Internet or Telephone Order Merchandise Rule - Shipment Timing Delay Notice and Refund Requirements for Distance Sales",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Federal Trade Commission Mail Internet or Telephone Order Merchandise Rule codified at 16 CFR Part 435 governs distance sales by requiring sellers to have a reasonable basis to expect they can ship ordered merchandise within the time stated in the solicitation or within 30 days if no time is stated, to provide a delay notice with an option to consent or cancel if shipment cannot occur within the original time, to provide a renewed delay notice and option whenever a revised shipment date cannot be met, to issue a prompt refund using the same method of payment when the buyer cancels, with section 435.1 setting out definitions of mail Internet or telephone order sales prompt refund shipment and related terms, section 435.2 stating the substantive shipment delay notice and refund obligations, and section 435.3 limiting applicability by excluding subscription shipments after initial shipment seed orders and collect-on-delivery transactions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-deceptive-acts"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ftc-16-cfr-part-436-franchise-rule-disclosure-requirements",
    "title": "FTC 16 CFR Part 436 - Franchise Rule (Disclosure Requirements and Prohibitions Concerning Franchising)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-02T00:00:00Z",
    "bluf": "16 CFR Part 436, the Federal Trade Commission's Franchise Rule, governs the disclosure and prohibited-practice requirements for franchise sales in the United States and is enforced under section 5 of the FTC Act (15 USC 45) and section 19 (15 USC 57b). The rule (current iteration adopted by 72 FR 15544, 30 March 2007, effective 1 July 2008, replacing the original 1979 rule) applies to any franchise sale in or affecting interstate commerce where the franchise satisfies the three-element definition in section 436.1(h): (1) a franchisee will obtain the right to operate a business that is identified or associated with the franchisor's trademark or to offer, sell, or distribute goods or services that are identified or associated with the franchisor's trademark; (2) the franchisor will exert or has authority to exert a significant degree of control over the franchisee's method of operation, or provide significant assistance in the franchisee's method of operation; (3) as a condition of obtaining or commencing operation of the franchise, the franchisee makes a required payment or commits to make a required payment to the franchisor or its affiliate, the total of which (whether in lump-sum or instalments) reaches at least USD 615 within six months of operations (the inflation-adjusted minimum). Section 436.2 requires franchisors to furnish a Franchise Disclosure Document (FDD) at least 14 calendar days before the prospective franchisee signs a binding agreement or makes any payment (the 14-day cooling-off period). Section 436.5 sets out the 23 mandatory FDD disclosure items including the franchisor and parents/predecessors/affiliates, business experience, litigation, bankruptcy, initial fees, other fees, estimated initial investment, restrictions on goods/services, financing, franchisor's assistance, territory, trademarks, patents/copyrights/proprietary info, obligation to participate in operation, restrictions, renewal/termination/transfer, public figures, financial performance representations, outlet activity, franchisee list, financial statements, contracts, receipts. Section 436.8 sets exemptions (large investment USD 1,394,200+ adjusted annually, sophisticated investor, fractional franchise under 20% of revenue, leased department, oil dealer, insider). Section 436.9 prohibits franchisor misrepresentations including financial performance claims without reasonable basis, disclaiming representations contradicting the FDD, and requiring waivers of franchisee rights under state franchise law. Penalties: FTC Act section 5 injunction, section 19 consumer redress, civil penalty up to USD 51,744 per violation under 16 CFR 1.98 (2025 adjustment).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "industry_mapping",
        "fdd_23_disclosure_items_section_436_5",
        "section_436_2_14_day_cooling_off_and_amended_fdd_re_disclosure",
        "section_436_9_prohibited_practices_including_fpr_substantiation_and_anti_waiver"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-deceptive-acts",
      "us-ftc-16-cfr-part-323-made-in-usa-labeling-rule",
      "us-ftc-16-cfr-part-254-vocational-distance-education-deceptive-practices",
      "us-ftc-16-cfr-part-233-deceptive-pricing-guides"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ftc-16-cfr-part-453-funeral-industry-practices",
    "title": "US FTC 16 CFR Part 453 Funeral Industry Practices Rule - Price Disclosure General Price List Casket Handling Embalming Authorization and Itemization Requirements",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Federal Trade Commission Funeral Rule codified at 16 CFR Part 453 binds funeral providers to a comprehensive set of consumer protection obligations including section 453.1 definitions of funeral provider funeral goods funeral services casket alternative container and cremation, section 453.2 price disclosure obligations covering telephone disclosure casket price lists outer burial container price lists and a comprehensive general price list furnished to consumers when arrangements are discussed, section 453.3 prohibitions on misrepresentations about embalming requirements casket and outer burial container claims preservation features and other practices, section 453.4 prohibitions on conditioning the provision of funeral goods or services on purchasing other items except as legally required, section 453.5 prohibitions on embalming without prior approval, section 453.6 record retention obligations of one year for price lists and arrangement statements, section 453.7 clarity and conspicuousness standards for required disclosures, section 453.8 declaration of intent treating omissions as unfair practices, and section 453.9 state exemption procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-deceptive-acts"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ftc-16-cfr-part-460-r-value-home-insulation-labeling",
    "title": "US FTC 16 CFR Part 460 R-Value Rule - Home Insulation Testing Labeling Advertising and Fact Sheet Disclosure Requirements",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "The Federal Trade Commission R-Value Rule codified at 16 CFR Part 460 governs the marketing and labeling of home insulation by setting binding requirements across the supply chain including section 460.1 scope and section 460.2 definitions of insulation types, section 460.3 application to manufacturers distributors installers retailers and advertisers, sections 460.5 and 460.6 mandating ASTM testing protocols and representative thickness testing, section 460.8 R-value tolerance standards, section 460.9 three year record retention for test data, section 460.10 clear and conspicuous disclosure standards, section 460.12 mandatory label content by product type, section 460.13 manufacturer fact sheet requirements, sections 460.14 to 460.15 retailer and installer fact sheet obligations, section 460.16 new home seller disclosure in sales contracts, sections 460.18 to 460.19 advertisement disclosure and fuel savings substantiation, section 460.20 restrictions on R-value per inch claims, section 460.21 prohibitions on false government endorsement, and section 460.24 relationship with other laws including state preemption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-deceptive-acts"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ftc-act-15-usc-ch2-subch-i",
    "title": "United States Federal Trade Commission Act of 1914 (Title 15 USC Chapter 2 Subchapter I): Federal Trade Commission Established, Section 5 Unfair Methods of Competition and Unfair or Deceptive Acts or Practices, Additional Powers, False Advertisements, Consumer Review Protection, Online Marketplace Transparency, and Rulemaking",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Federal Trade Commission Act of 1914, codified at Title 15 of the United States Code, Chapter 2, Subchapter I, is the principal federal statute establishing the Federal Trade Commission and prohibiting unfair methods of competition and unfair or deceptive acts or practices in or affecting commerce, and is administered by the Federal Trade Commission as the consumer protection and competition enforcement agency. Federal Trade Commission Act, 15 U.S.C. 41 establishes the Federal Trade Commission as a five-member body appointed by the President with Senate consent. Federal Trade Commission Act, 15 U.S.C. 42 authorises the FTC to hire employees and manage expenses. Federal Trade Commission Act, 15 U.S.C. 44 contains the definitions including commerce, corporation, and documentary evidence. Federal Trade Commission Act, 15 U.S.C. 45 (Section 5) declares unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, unlawful, and confers on the FTC the authority to prevent persons, partnerships, or corporations from using such methods, acts, or practices. Federal Trade Commission Act, 15 U.S.C. 45b governs consumer review protection including voiding contract clauses prohibiting consumer reviews or imposing penalties for such reviews. Federal Trade Commission Act, 15 U.S.C. 45e establishes the office for the prevention of fraud targeting seniors. Federal Trade Commission Act, 15 U.S.C. 45f governs the collection, verification, and disclosure of information by online marketplaces under the INFORM Consumers Act. Federal Trade Commission Act, 15 U.S.C. 46 confers additional powers including investigatory authority. The Act is the controlling federal instrument for consumer protection and the Section 5 unfair competition and unfair or deceptive acts and practices prohibition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ftc-act-section-5-15-usc-45-unfair-deceptive-practices",
    "title": "US FTC Act Section 5 (15 USC 45) - Unfair or Deceptive Acts or Practices Prohibition and Enforcement",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "FTC Act Section 5 (15 USC 45) prohibits unfair or deceptive acts or practices (UDAP) in or affecting commerce. The FTC applies this authority to data security failures, privacy misrepresentations, AI and algorithmic discrimination, dark patterns, subscription traps, and misleading environmental claims. FTC can seek injunctive relief, disgorgement, and civil penalties for consent order violations up to $51,744 per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ftc-act-section-5-unfair-competition",
    "title": "Federal Trade Commission Act Section 5 (15 U.S.C. § 45): Unfair Methods of Competition, as clarified by the 2022 Policy Statement",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Section 5 of the FTC Act (15 U.S.C. § 45(a)(1)) prohibits \"unfair methods of competition\" in commerce, empowering the FTC to take enforcement action against conduct that is coercive, exploitative, collusive, abusive, or predatory, even if it does not violate the Sherman or Clayton Acts. The 2022 Policy Statement emphasizes its application to modern markets, including digital platforms, labor markets, and nascent competition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sherman-antitrust-act-sections-1-2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ftc-act-section-5-unfair-competition-antitrust",
    "title": "Federal Trade Commission Act Section 5 - Unfair Methods of Competition in or Affecting Commerce",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Prohibits unfair methods of competition in or affecting commerce, granting the FTC standalone authority to challenge anticompetitive conduct beyond the scope of the Sherman Act. Applies to all persons, partnerships, and corporations engaged in commerce. Key clause: 15 U.S.C. § 45(a)(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ftc-act-section-5-unfair-deceptive-acts",
    "title": "Unfair methods of competition unlawful; prevention by Commission",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Prohibits unfair methods of competition and unfair or deceptive acts or practices in or affecting commerce, enforced by the Federal Trade Commission under 15 U.S. Code § 45(a)(1). Applies to persons, partnerships, and corporations except those specifically exempted under subsection (a)(2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-digital-advertising-disclosures",
      "eu-unfair-commercial-practices-2005-29",
      "can-spam-act-email",
      "coppa-marketing-kids",
      "ama-ethical-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ftc-ai-unfair-deceptive-practices-2023",
    "title": "FTC Guidance on AI Unfair and Deceptive Practices - Compliance Obligations for AI Marketing Claims, Prohibition on AI-Enabled Deception, and FTC Section 5 Compliance for AI Product Developers and Deployers",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines FTC obligations under Section 5 to prevent unfair or deceptive AI practices, focusing on truthful marketing claims and prohibiting AI-enabled deception; it aligns with EU AI Act 2024 requirements under Articles 5 and 52 for transparency and accountability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ftc-cfr-16-part-255-endorsement-testimonials-advertising",
    "title": "16 CFR Part 255 - Guides Concerning Use of Endorsements and Testimonials in Advertising",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2023-07-26",
    "bluf": "Organizations must ensure that endorsements and testimonials used in advertising are truthful, not misleading, and that any material connections between the endorser and the advertiser are clearly and conspicuously disclosed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ftc-cfr-16-part-312-coppa-rule",
    "title": "16 CFR Part 312 - Children's Online Privacy Protection Rule (Coppa Rule)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This rule imposes requirements on operators of websites or online services directed to children under 13, or those with actual knowledge of collecting personal information from a child, concerning the collection, use, and disclosure of that information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ftc-cfr-16-part-314-gramm-leach-bliley-safeguards",
    "title": "16 CFR Part 314 - Standards for Safeguarding Customer Information",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Organizations must develop, implement, and maintain a comprehensive written information security program to protect customer information, which includes designating a qualified individual, conducting risk assessments, implementing specific safeguards, and reporting to the board annually.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ftc-com-disclosures-digital-advertising-2013",
    "title": "US FTC '.com Disclosures: How to Make Effective Disclosures in Digital Advertising' Guide (March 2013) - 4P Clear and Conspicuous Standard for Digital Ad Disclosures",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "The Federal Trade Commission's '.com Disclosures: How to Make Effective Disclosures in Digital Advertising' guidance (published March 2013, supplementing the FTC's earlier 2000 Dot Com Disclosures publication) is the principal FTC operational document on how digital advertisers must structure required disclosures to satisfy the 'clear and conspicuous' standard derived from Sec. 5 of the FTC Act (15 USC 45). The guide articulates the 4P clear-and-conspicuous framework: (1) Proximity to the triggering claim (disclosures should be placed near the claim they qualify); (2) Prominence (disclosures must be presented in a manner sufficiently noticeable in terms of size, colour, contrast, and audio or visual presentation); (3) Presentation in understandable language (disclosures must be in unambiguous language understandable to the intended audience); (4) Placement and timing (disclosures should be placed where consumers are reasonably expected to see them, including before a purchase decision). The guide applies to all online advertising channels including websites, search results, social media, mobile apps, banner ads, video, audio (podcasts), connected television (CTV), influencer content and emerging formats. The guide expressly addresses: hyperlinks (a hyperlink alone is generally insufficient to convey a material disclosure unless the hyperlink is conspicuously labelled and placed); space-constrained ads (the FTC analyses whether the small format allows for adequate disclosure or whether the advertiser must avoid the unqualified claim); social media (the disclosure must accompany the post including in retweet, repost or share contexts); video advertising (audio and visual reinforcement preferred for material disclosures); pop-ups and interstitials (generally disfavoured due to ad-blocker bypass and consumer dismissal); deceptive door-openers (an advertiser cannot use one channel to attract attention and bury the disclosure in another). The 4P standard interlocks with the FTC Endorsement Guides at 16 CFR 255 (requiring clear and conspicuous disclosure of material connections between endorser and advertiser), the FTC Green Guides at 16 CFR 260 (substantiation of environmental claims), the FTC Negative Option Rule (Click-to-Cancel Rule, 16 CFR 425, finalised 2024), and the FTC AI Advisory Guidance (2024) on AI-related claims and synthetic content. FTC enforcement is via Sec. 5 unfair-or-deceptive-acts-or-practices actions; civil penalties under Sec. 5(m) reach USD 53,088 per violation (as adjusted to 11 January 2025 by the FTC Inflation Adjustment final rule). The .com Disclosures guide is widely cited in FTC consent orders and is the operational standard adopted by industry self-regulators including the BBB National Programs' National Advertising Division (NAD), the Children's Advertising Review Unit (CARU), and the digital advertising industry through IAB and NAI codes of conduct.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "four_p_framework_anchor",
        "section_5_ftc_act_anchor",
        "hyperlink_guidance_anchor",
        "endorsement_guides_anchor",
        "green_guides_anchor",
        "negative_option_rule_anchor",
        "ai_advisory_guidance_anchor",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-15-usc-45-unfair-deceptive-practices",
      "ftc-endorsement-guides-2023",
      "us-ftc-green-guides-environmental-claims-2012"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ftc-contact-lens-rule-2024",
    "title": "Contact Lens Rule (16 C.F.R. Part 315) as amended 2024",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2024-08-29",
    "bluf": "This rule requires contact lens prescribers to provide patients with a copy of their prescription and obtain a signed acknowledgment of receipt, which must be retained for three years. It also mandates that sellers who verify prescriptions through prescribers must offer a direct, verifiable communication method, such as a dedicated phone number with a live person, and prohibits the use of automated robocalls for verification, as specified in 16 C.F.R. § 315.5 and § 315.6.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-digital-advertising-disclosures",
      "hipaa-security-rule",
      "can-spam-act-email"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ftc-coppa-rule-amendment-2024",
    "title": "US FTC COPPA Rule Amendment 2024",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The FTC's amendment to the Children's Online Privacy Protection Rule was proposed by Notice of Proposed Rulemaking on January 11, 2024 and approved as a final rule on January 16, 2025; it was published in the Federal Register on April 22, 2025, took effect on June 23, 2025, with a general compliance date of April 22, 2026. The amended Rule strengthens children's online privacy by imposing data minimisation and retention limits, requiring fresh parental consent for material changes to data practices, addressing the use of school-collected children's data, requiring separate opt-in parental consent for targeted advertising rather than bundling it with service access, and expanding the definition of personal information (adding biometric identifiers and government identifiers) to better address modern tracking technologies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ftc-coppa-rule-amendment-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ftc-green-guides-environmental-claims-2012",
    "title": "US FTC Green Guides Environmental Marketing Claims (16 CFR Part 260) - Substantiation and Deception Prevention",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The US Federal Trade Commission's Guides for the Use of Environmental Marketing Claims (Green Guides, 16 CFR Part 260, 2012 revision) provide guidance on environmental marketing claims under Section 5 of the FTC Act; address general environmental benefit claims, recyclable, recycled content, biodegradable, compostable, ozone-safe, renewable energy, renewable materials, and carbon offset claims; require substantiation for all environmental claims; the FTC announced a review in 2022 with updated guidance expected; unsubstantiated green claims constitute deceptive acts under 15 USC 45.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-endorsement-guides-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ftc-hbnr-2024",
    "title": "FTC Health Breach Notification Rule Amendment 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The FTC amended its Health Breach Notification Rule effective July 29, 2024 to explicitly cover health apps, fitness trackers, and consumer health technologies not subject to HIPAA, requiring notification to the FTC, affected individuals, and media within 60 days of discovering a breach of unsecured identifiable health information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ftc-hbnr-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ftc-loot-boxes-children-coppa-guidance",
    "title": "FTC Staff Perspective on Loot Boxes in Online Games: Disclosure, Deception, and Children's Privacy Under COPPA",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This FTC guidance clarifies that loot boxes in online games targeted at or likely to be used by children under 13 must comply with the Children's Online Privacy Protection Act (COPPA) and associated disclosure rules. Operators must provide clear, prominent disclosures about randomized rewards, odds of obtaining items, and obtain verifiable parental consent before collecting personal information from children, per COPPA Rule 312.5 and Section 5 of the FTC Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "esrb-entertainment-software-rating-board-us",
      "eu-dsa-platform-obligations-gaming-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ftc-negative-option-rule-2023",
    "title": "US FTC Negative Option Rule 2023 - Subscription Traps: Clear and Conspicuous Disclosure of Recurring Charges, Simple Cancellation Mechanism (Same Ease as Signup), Pre-Sale Disclosure Requirements, Annual Reminders and Civil Penalties for Violations",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The FTC's Negative Option Rule requires sellers using recurring subscription plans to provide clear and conspicuous disclosures before obtaining consumer consent, ensure cancellation is as easy as enrollment, and send annual reminder notices. These requirements are designed to prevent unintended recurring charges and are enforced under 16 CFR Part 425.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-digital-advertising-disclosures",
      "can-spam-act-email",
      "ccpa-cpra-optout-sale"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ftc-operation-ai-comply-2024",
    "title": "US FTC Operation AI Comply - Crackdown on Deceptive AI Claims and Schemes (September 25, 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "On September 25, 2024 the Federal Trade Commission announced Operation AI Comply, an enforcement sweep targeting unfair or deceptive practices involving artificial intelligence. The Operation comprised five law enforcement actions against companies using AI claims to deceive consumers, including: (1) DoNotPay (purportedly the world's first robot lawyer making misleading AI legal services claims); (2) Ascend Ecom (e-commerce AI business opportunity using AI claims to make misleading earnings promises); (3) Ecommerce Empire Builders (similar AI business opportunity scheme); (4) FBA Machine (Amazon FBA AI business opportunity scheme); (5) Rytr (AI writing tool used to mass produce deceptive consumer reviews). The Operation establishes FTC enforcement themes: AI claims must be substantiated like any other product claim; AI products that can be used to deceive (such as deepfake or fake review tools) can themselves be challenged; AI cannot launder business opportunity schemes; AI-powered services need to deliver what is promised. The Operation operationalises the Joint Statement on Enforcement Efforts Against Discrimination and Bias in Automated Systems (April 25 2023) and the FTC published guidance on AI including FTC Business Guidance on AI (multiple posts 2023-2024). Companion FTC actions include Rite Aid facial recognition order (December 2023), Workado AI-content-detection settlement (October 2024), and ongoing scrutiny of AI marketing claims under the FTC Act unfair-or-deceptive-practices authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "regulatory_overlay",
        "ai_governance_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-doj-eeoc-cfpb-ftc-joint-statement-ai-2023",
      "us-ostp-blueprint-ai-bill-of-rights",
      "us-fcc-tcpa-ai-voice-robocalls-ruling-2024",
      "us-cfpb-circular-2022-03-adverse-action-ai-credit"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ftc-robinson-patman-price-discrimination",
    "title": "US Robinson-Patman Act 1936 - Price Discrimination Prohibition: Commodities of Like Grade and Quality, Price Differentials Justification, Brokerage Payments, Promotional Services and Buyer Liability",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation prohibits price discrimination between purchasers of commodities of like grade and quality in commerce where the effect may substantially lessen competition or create a monopoly, as defined in 15 U.S. Code § 13(a). It applies to any person engaged in commerce who sells goods for use, consumption, or resale within U.S. jurisdiction.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-cma-merger-assessment-guidelines-2021",
      "india-competition-act-2002-sections-3-4",
      "eu-state-aid-articles-107-108-tfeu-framework",
      "canada-competition-act-2024-amendment-abuse-dominance",
      "australia-competition-consumer-act-2010-part-iv"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ftc-safeguards-2023",
    "title": "FTC Gramm-Leach-Bliley Safeguards Rule 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The FTC's updated Safeguards Rule under the Gramm-Leach-Bliley Act, fully effective June 9, 2023, requires non-bank financial institutions to implement a comprehensive written information security program with specific technical safeguards including encryption, multi-factor authentication, and a qualified designated security officer reporting annually to the board.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ftc-safeguards-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cpra-california-privacy-rights-act-2020",
      "us-ma-data-security-2010"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ftc-safeguards-rule-16-cfr-314-2024-amendments",
    "title": "US FTC Safeguards Rule 16 CFR Part 314 - Financial Institutions Information Security Program with 30 Day Notification Amendment, Effective 13 May 2024",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "Non-bank financial institutions subject to the Federal Trade Commission's Standards for Safeguarding Customer Information (Safeguards Rule, 16 CFR Part 314) under Gramm-Leach-Bliley Act section 501(b) must develop, implement, and maintain a comprehensive written information security program containing the administrative, technical, and physical safeguards specified in 16 CFR 314.4, designate a qualified individual responsible for overseeing the program, conduct risk assessments and continuous monitoring, and from 13 May 2024 when the amendment finalised on 30 October 2023 (88 FR 77499) became effective, notify the FTC as soon as possible and no later than 30 days after discovery of a notification event involving the unauthorized acquisition of unencrypted customer information of at least 500 consumers, per 16 CFR 314.5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-glba-gramm-leach-bliley-act-1999"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ftc-section-5-unfair-deceptive-acts-ai-digital-advertising",
    "title": "US FTC Section 5 - Unfair or Deceptive Acts in AI-Powered Digital Advertising and Commerce",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Section 5 of the Federal Trade Commission Act (15 U.S.C. § 45) prohibits unfair or deceptive acts or practices in commerce. The FTC has issued specific guidance on AI use in advertising (FTC Guidance 2023) and dark patterns, and brought enforcement actions against misleading AI product claims, fake reviews, and AI-generated endorsements without disclosure. The FTC endorsement guidelines (16 CFR Part 255) were updated in 2023 to address AI-generated content.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-15-usc-45-unfair-deceptive-practices"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ftc-telemarketing-sales-rule-16-cfr-310",
    "title": "US FTC Telemarketing Sales Rule - 16 CFR Part 310 Do-Not-Call & Disclosure Requirements",
    "domain": "Operations & CX",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The FTC Telemarketing Sales Rule (16 CFR Part 310) prohibits deceptive telemarketing, mandates Do-Not-Call compliance, restricts calling hours to 8am-9pm, and requires upfront disclosure of seller identity - violators face civil penalties up to $51,744 per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ftc-telemarketing-sales-rule-1995",
    "title": "US FTC Telemarketing Sales Rule 1995 (as amended 2003/2010/2020) - DNC Registry",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The FTC Telemarketing Sales Rule (TSR, 16 C.F.R. Part 310), promulgated under the Telemarketing and Consumer Fraud and Abuse Prevention Act (15 U.S.C. 6101), prohibits deceptive and abusive telemarketing practices. Telemarketers must check the National Do Not Call (DNC) Registry before calling, are prohibited from calling before 8:00 AM or after 9:00 PM local time, must honour DNC requests within 30 days, may not abandon more than 3% of calls, and must disclose the seller's identity and the nature of the call immediately. Violations are subject to civil penalties of up to $51,744 per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "tcpa_1991",
        "national_dnc_registry",
        "can_spam_act_2003",
        "state_dnc_laws",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-can-spam-act-2003-commercial-email-operations",
      "us-tcpa-telephone-consumer-protection-act-1991",
      "us-ftc-act-section-5-unfair-competition-antitrust"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ftc-telemarketing-sales-rule-2015",
    "title": "US FTC Telemarketing Sales Rule (TSR) - 16 CFR Part 310",
    "domain": "Sales, Marketing & PR",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The FTC Telemarketing Sales Rule (16 CFR Part 310) prohibits abusive and deceptive telemarketing practices, mandates National Do Not Call Registry compliance, restricts robocalls to prior express written consent, limits calling hours to 8 AM-9 PM local time, and imposes civil penalties up to USD 51,744 per violation for sellers and telemarketers engaged in outbound telephone sales.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-deceptive-acts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-gaap-asc-606-revenue",
    "title": "US GAAP ASC 606 Revenue from Contracts with Customers - FASB Revenue Recognition Standard",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard establishes a comprehensive, five-step model for all entities to recognize revenue from contracts with customers, superseding most previous industry-specific guidance. The core principle, outlined in ASC 606-10-05-3, is to recognize revenue depicting the transfer of goods or services in an amount that reflects the consideration the entity expects to be entitled to in exchange for those goods or services.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-15-revenue-contracts",
      "us-sarbanes-oxley-section-302-404",
      "gaap-us-framework"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-gaap-asc-842-leases",
    "title": "US GAAP ASC 842 Leases - FASB Lessee and Lessor Accounting Model (2016)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This standard requires lessees to recognize assets and liabilities for most leases with terms longer than 12 months on their balance sheets. Under ASC 842-20-25-1, a lessee must recognize a right-of-use (ROU) asset and a corresponding lease liability, fundamentally changing the accounting for what were previously off-balance-sheet operating leases.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-16-leases",
      "us-sarbanes-oxley-section-302-404",
      "gaap-us-framework"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-gao-ai-accountability-framework-2021",
    "title": "US GAO Artificial Intelligence Accountability Framework for Federal Agencies and Other Entities (GAO-21-519SP, June 2021)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The Government Accountability Office published the AI Accountability Framework (GAO-21-519SP) in June 2021 to help federal agencies and other entities ensure accountability and responsible AI use. The framework is organised around four complementary principles - Governance, Data, Performance, and Monitoring - and identifies eleven Key Practices supported by 33 Key Questions and 50+ types of supporting evidence. Principle 1 Governance covers structures and processes to manage, operate, and oversee implementation across the AI lifecycle. Principle 2 Data addresses data quality, reliability, and representativeness in both model development and operational data. Principle 3 Performance covers verification, validation, and ongoing assessment that the system meets its intended objectives. Principle 4 Monitoring covers continuous oversight to ensure performance over time and to detect drift, bias, and unintended consequences. The framework targets four audiences: agency officials and policymakers, AI developers, third-party assessors, and oversight bodies including inspectors general. GAO uses it for federal program audits and it has become the de facto US public-sector AI audit standard pending formal codification through OMB memoranda (M-24-10, succeeded by M-25-21).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping",
        "iso_standard",
        "us_state_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "us-eo-13960-promoting-trustworthy-ai-federal-government-2020",
      "us-omb-m-24-10-federal-ai-governance-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-general-mining-law-1872",
    "title": "US General Mining Law of 1872 (30 USC ch 2): Locatable Minerals, Mining Claims and Patents",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The General Mining Law of 1872 (30 U.S.C. ch. 2) governs the location and patenting of claims to locatable hardrock minerals on federal public-domain lands, administered by the Bureau of Land Management within the Department of the Interior. Section 22 opens all valuable mineral deposits in lands belonging to the United States to exploration and purchase by citizens, subject to the law and local rules. Section 23 sets the rules for the length of claims on veins or lodes. Section 26 confers on locators the exclusive right of possession and enjoyment of the surface and of the veins, lodes and ledges within their claim boundaries. Section 28 governs the location, marking and recording of claims and the requirement of annual labor or improvements (assessment work) pending the issue of a patent. Section 29 sets out the procedure to obtain a patent, including the application under oath, the plat and field notes, publication, and payment per acre. Section 30 addresses adverse claims arising during the patent process. Section 35 applies these provisions to placer claims and conforms entries to the legal subdivisions and surveys. Section 38 allows evidence of possession and work to establish a right to a patent. The Act is the legal foundation of the US hardrock mining-claim system on public lands.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-genetic-information-nondiscrimination-act",
    "title": "US Genetic Information Nondiscrimination Act Title II (42 USC ch 21F): Genetic Information in Employment",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Genetic Information Nondiscrimination Act, Title II (42 U.S.C. ch. 21F), prohibits discrimination in employment on the basis of genetic information and restricts the acquisition of such information, enforced by the Equal Employment Opportunity Commission. Section 2000ff defines genetic information to include an individual's genetic tests, the genetic tests of family members, and the manifestation of a disease or disorder in family members, that is, family medical history. Section 2000ff-1 sets out the employer practices: it is unlawful for an employer to fail or refuse to hire, to discharge, or otherwise to discriminate against an employee because of genetic information, and it is unlawful for an employer to request, require or purchase genetic information about an employee or a family member, subject to narrow exceptions for inadvertent requests, voluntary wellness programs, family and medical leave certification, commercially available documents, genetic monitoring of workplace toxic effects, and forensic laboratory functions. Section 2000ff-5 requires that genetic information be maintained on separate forms and in separate medical files and treated as a confidential medical record, with strict limits on disclosure. Section 2000ff-6 provides remedies and enforcement through the powers, procedures and remedies of the Civil Rights Act of 1964, including compensatory and punitive damages and attorney fees. The Act is the legal foundation for US protection of genetic privacy in employment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-genetic-information-nondiscrimination-act-gina-2008",
    "title": "US Genetic Information Nondiscrimination Act of 2008 (GINA): Prohibits health insurers and employers from discriminating based on genetic information",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-16",
    "bluf": "The Genetic Information Nondiscrimination Act of 2008 (GINA) is a United States federal law enacted on 21 May 2008 as Public Law 110-233. It is divided into two titles. Title I, effective 21 May 2009, prohibits group health plans and health insurers from using genetic information to determine eligibility, set premiums, or impose preexisting condition exclusions. It amends ERISA, the Public Health Service Act, and the Internal Revenue Code. Title II, effective 21 November 2009, prohibits employers with 15 or more employees, employment agencies, labor organizations, and training programs from discriminating against individuals based on genetic information in hiring, firing, job assignments, or other terms of employment. Genetic information includes an individual's genetic tests, genetic tests of family members, and family medical history. The law includes limited exceptions: inadvertent acquisition of genetic information; voluntary employer-sponsored wellness programs; requests for family medical history under the Family and Medical Leave Act (FMLA); commercially and publicly available documents (e.g., newspapers); genetic monitoring of biological effects of toxic substances in the workplace with informed consent; and forensic laboratory identification testing for law enforcement. Enforcement of Title II follows the procedures under Title VII of the Civil Rights Act of 1964. The EEOC's implementing regulations for Title II are codified at 29 CFR Part 1635.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-title-vii-civil-rights-1964"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-genius-act-stablecoin-2025-framework",
    "title": "US GENIUS Act 2025 - Stablecoin Regulatory Framework: Payment Stablecoin Issuer Authorisation (Federal/State), 1:1 Reserve Requirement, Permitted Reserve Assets, AML/BSA Obligations, Foreign Stablecoin Registration and Federal Reserve Emergency Powers",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The US GENIUS Act 2025 requires all payment stablecoin issuers to obtain federal or state-level authorization, maintain 1:1 reserves in permitted assets (Section 4(a)), comply with AML/BSA obligations (Section 7), and register foreign-issued stablecoins with the Treasury. It grants the Federal Reserve emergency intervention authority over systemic stablecoin arrangements (Section 12).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "bis-cpmi-cross-border-payments-2023",
      "bis-iosco-pfmi-applied-to-dlt-systems",
      "eu-dlt-pilot-regime-2022-858",
      "us-federal-arbitration-act-1925"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-genius-act-stablecoin-regulation-2025",
    "title": "US GENIUS Act Stablecoin Regulation (2025) - Payment Stablecoin Issuer Registration (Fed/OCC/State), 1:1 Reserve Requirements in US Treasuries/USD, Redemption Rights Within 1 Business Day and OFR Systemic Risk Oversight",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This act requires US payment stablecoin issuers to register with a federal or state banking authority (Section 101), maintain 1:1 reserves consisting solely of US dollars or short-term US Treasuries (Section 201), and provide holders with redemption rights within one business day (Section 203). The Office of Financial Research (OFR) is granted oversight authority to monitor and mitigate systemic risks (Section 301).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bis-crypto-asset-prudential-standards",
      "fsb-crypto-asset-regulatory-framework-2023",
      "crypto-aml-travel-rule",
      "eu-mica-e-money-tokens",
      "us-sec-digital-asset-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-geothermal-steam-act-1970",
    "title": "US Geothermal Steam Act of 1970 (30 U.S.C. Chapter 23): Federal Geothermal Resource Leasing",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Geothermal Steam Act of 1970, codified at 30 U.S.C. Chapter 23 (sections 1001 through 1028), authorizes the Secretary of the Interior to lease federal lands for the development and use of geothermal steam and associated geothermal resources, and is administered by the Bureau of Land Management. Section 1001 defines geothermal steam and associated geothermal resources, byproducts, and known geothermal resources areas. Section 1002 identifies the lands subject to geothermal leasing, and section 1003 sets the leasing procedures, including competitive and noncompetitive leasing. Section 1004 governs the rents and royalties payable to the United States, including a royalty on the amount or value of production. Section 1005 sets the lease term and the work commitment and diligence requirements, and section 1007 provides for the readjustment of lease terms and conditions. Section 1009 provides for the relinquishment of geothermal rights, and section 1011 provides for the termination of leases for failure to comply with the Act, a lease term, or a regulation, after notice and an opportunity to cure. Late payment of rental carries a penalty assessment. The Act is the foundational statute for geothermal resource development on federal lands.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-gilti-code-951a-global-intangible-income",
    "title": "US Internal Revenue Code Section 951A - Global Intangible Low-Taxed Income (GILTI): Net CFC Tested Income Calculation, 10% QBAI Deduction, High-Tax Exception and Section 250 Deduction",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under IRC § 951A, U.S. shareholders of Controlled Foreign Corporations (CFCs) must include their pro rata share of Global Intangible Low-Taxed Income (GILTI) in their gross income annually. This regime targets low-taxed foreign earnings by imposing a U.S. tax on the excess of a CFC's net income over a routine 10% return on its tangible assets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-gilti-high-tax-exclusion-final-regulations-2020",
    "title": "Guidance Related to the High-Tax Exception Under Subpart F and the High-Tax Exclusion for Global Intangible Low-Taxed Income",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "These final regulations permit U.S. shareholders of controlled foreign corporations (CFCs) to elect to exclude items of high-taxed income from their Global Intangible Low-Taxed Income (GILTI) computation on a tested-unit basis. Under §1.951A-2(c)(6), the election applies if the foreign effective tax rate on the income exceeds 90 percent of the maximum U.S. corporate tax rate (currently 18.9%).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-gilti-section-951a-global-intangible-low-taxed-income",
    "title": "US GILTI - IRC Section 951A: Global Intangible Low-Taxed Income Inclusion and High-Tax Exclusion",
    "domain": "Tax & Transfer Pricing",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "US Internal Revenue Code Section 951A (GILTI), enacted by the Tax Cuts and Jobs Act 2017, requires US shareholders of Controlled Foreign Corporations (CFCs) to include in gross income their pro-rata share of GILTI annually. GILTI equals the CFC's net tested income over 10% of the qualified business asset investment (QBAI) - a deemed tangible income return; the excess is treated as a minimum tax on highly mobile intangible income. Corporate US shareholders may deduct 50% of the GILTI inclusion (reduced to 37.5% from 2026) and claim a foreign tax credit (FTC) for 80% of foreign taxes paid on GILTI; the effective US tax rate on GILTI is 10.5% (rising to 13.125% from 2026). The GILTI high-tax exclusion (HTE) election allows US shareholders to exclude from GILTI net tested income that has borne an effective foreign tax rate above 90% of the US corporate rate (currently 18.9% threshold).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-pillar-two-global-minimum-tax-15-percent",
      "oecd-transfer-pricing-guidelines-2022-full-edition"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-gilti-tcja-2017",
    "title": "US GILTI, BEAT, and FDII - Tax Cuts and Jobs Act 2017 International Tax Provisions",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Tax Cuts and Jobs Act (TCJA), signed into law by President Trump on 22 December 2017 (Public Law 115-97), enacted the most comprehensive reform of US international corporate taxation since 1986 and introduced three interconnected regimes that remain the primary US framework for taxing cross-border profits of US multinational enterprises (MNEs) as of April 2026. (1) Global Intangible Low-Taxed Income (GILTI) - IRC Sec. 951A: US shareholders of controlled foreign corporations (CFCs) must include in gross income their GILTI for each taxable year. GILTI equals: net CFC tested income minus the Net Deemed Tangible Income Return (NDTIR), where NDTIR = 10% of QBAI (Qualified Business Asset Investment - the average quarterly adjusted basis of depreciable tangible property used in the CFC's business). Net CFC tested income is the aggregate of each CFC's tested income (gross income less properly allocable deductions, excluding certain categories: effectively connected income, subpart F income, high-tax exception income, foreign oil and gas extraction income, and related-party dividends) reduced by tested losses of other CFCs. Domestic corporations may deduct 50% of their GILTI inclusion under IRC Sec. 250(a)(1)(B) (reducing from 50% to 37.5% after 2025 under TCJA sunset provisions), resulting in an effective GILTI rate of 10.5% at the 21% corporate rate (rising to 13.125% after 2025). A foreign tax credit is available for 80% of the pro-rata share of foreign income taxes paid or accrued by CFCs with respect to tested income - subject to a separate GILTI FTC basket and no carryover. A high-tax exclusion (HTE) election under Treasury Regulations allows exclusion of GILTI tested income from CFCs with an effective tax rate exceeding 90% of the US corporate rate (>18.9% at 21%). (2) Base Erosion and Anti-Abuse Tax (BEAT) - IRC Sec. 59A: an alternative minimum-type tax on large US corporations that make deductible payments to foreign related parties (base erosion payments). BEAT applies to corporations with average annual gross receipts of at least USD 500 million over the 3-year test period and a base erosion percentage of at least 3% (2% for banks and registered securities dealers). BEAT rate: 10% (taxable years beginning 1 January 2019 through 31 December 2025), rising to 12.5% (2026 onwards). BEAT = the excess of (BEAT rate × Modified Taxable Income) over regular tax liability. Modified Taxable Income adds back deductions for base erosion payments - broadly any payment to a foreign related party that is deductible, other than payments for cost of goods sold, certain services at cost or cost-plus margins, and qualified derivative payments. (3) Foreign-Derived Intangible Income (FDII) - IRC Sec. 250: US domestic corporations may deduct 37.5% of FDII (reducing to 21.875% after 2025), achieving an effective rate of approximately 13.125% pre-2026 on income attributable to foreign markets from exploitation of intangibles. FDII equals the portion of deemed intangible income (deduction-eligible income minus 10% of the corporation's QBAI) attributable to foreign-derived sales and services. The FDII deduction provides a tax incentive to locate intellectual property and production in the United States. Pillar Two interaction: the OECD GloBE rules do not treat GILTI as a qualified IIR - US MNEs whose effective GILTI rate falls below 15% may face UTPR charges in EU, UK, and other implementing jurisdictions that have enacted the Undertaxed Profits Rule as of April 2026. US has not enacted domestic Pillar Two legislation as of April 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-cbcr-guidance-2023-update",
      "oecd-globe-undertaxed-profits-rule-utpr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-gina-2008-42-usc-ch21f",
    "title": "United States Genetic Information Nondiscrimination Act of 2008 (GINA) (Title 42 USC Chapter 21F): Definitions Including Genetic Information and Genetic Services, Employer Practices Prohibition, Employment Agency and Labor Organization Practices, Confidentiality of Genetic Information, and Remedies and Enforcement",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Genetic Information Nondiscrimination Act of 2008 (GINA), Public Law 110-233 of 21 May 2008, codified at Title 42 of the United States Code, Chapter 21F (employment provisions in Title II) and other titles for health insurance provisions (Title I), is the principal federal statute prohibiting employment discrimination on the basis of genetic information and restricting the collection, use, and disclosure of genetic information by employers, employment agencies, labor organizations, and joint labor-management training programs, and is administered by the Equal Employment Opportunity Commission. GINA, 42 U.S.C. 2000ff contains the definitions including genetic information (information about an individual's genetic tests, the genetic tests of family members of such individual, and the manifestation of a disease or disorder in family members of such individual), genetic services, and genetic monitoring. GINA, 42 U.S.C. 2000ff-1 contains the employer practices prohibition making it an unlawful employment practice for an employer to fail or refuse to hire, or to discharge, any employee, or otherwise to discriminate against any employee with respect to the compensation, terms, conditions, or privileges of employment of the employee, because of genetic information with respect to the employee; or to limit, segregate, or classify employees in any way that would deprive or tend to deprive any employee of employment opportunities or otherwise adversely affect the status of the employee, because of genetic information; or to request, require, or purchase genetic information except in limited circumstances. GINA, 42 U.S.C. 2000ff-2 contains the employment agency practices prohibition. GINA, 42 U.S.C. 2000ff-3 contains the labor organization practices prohibition. GINA, 42 U.S.C. 2000ff-5 contains the confidentiality of genetic information requiring separate maintenance as a confidential medical record. GINA, 42 U.S.C. 2000ff-6 contains the remedies and enforcement provisions cross-referenced to Title VII of the Civil Rights Act of 1964. The Act is the controlling federal instrument for prohibiting employment discrimination on the basis of genetic information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-gina-genetic-information-nondiscrimination",
    "title": "Genetic Information Nondiscrimination Act of 2008 - Prohibiting Employment Discrimination on the Basis of Genetic Information",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Genetic Information Nondiscrimination Act (GINA) of 2008 prohibits employers with 15 or more employees from using genetic information in employment decisions, including hiring, firing, and promotions, and restricts the acquisition and disclosure of such information under Title II, Section 202. It applies to employers, employment agencies, labor organizations, and training programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-27001-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-glba-gramm-leach-bliley-act-1999",
    "title": "US Gramm-Leach-Bliley Act 1999 (GLBA) - Financial Privacy and Data Protection",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Gramm-Leach-Bliley Act 1999 (GLBA, Pub.L. 106-102) requires financial institutions to protect consumers' nonpublic personal information (NPI). The Financial Privacy Rule (16 CFR Part 313) mandates annual privacy notices and opt-out rights for sharing NPI with nonaffiliated third parties. The Safeguards Rule (16 CFR Part 314), updated in 2023, requires a written information security program with specific technical controls including encryption, access controls, MFA, and penetration testing for covered financial institutions. The Pretexting Rule prohibits social engineering to obtain NPI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-31-cfr-1010-aml",
      "us-investment-advisers-act-1940",
      "us-investment-company-act-1940"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-glba-safeguards-rule-16-cfr-314-financial-data-security",
    "title": "US GLBA Safeguards Rule (16 CFR Part 314) - Information Security Program Requirements for FTC-Regulated Financial Institutions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The FTC's Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (16 CFR Part 314, amended 2023) requires FTC-regulated financial institutions - including fintechs, mortgage lenders, payday lenders, tax preparers, auto dealers, and non-bank financial companies - to implement a comprehensive written information security program (WISP). MFA, encryption, penetration testing, and mandatory FTC breach notification within 30 days for breaches affecting >=500 customers are now required.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-global-magnitsky-pl-114-328-subtitle-f",
    "title": "United States Global Magnitsky Human Rights Accountability Act (Public Law 114-328, Subtitle F of Title XII, 2016): Short Title, Definitions, Authorization of Imposition of Sanctions for Gross Violations of Human Rights and Significant Acts of Corruption, Reports to Congress, and Sunset",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Global Magnitsky Human Rights Accountability Act, enacted as Subtitle F of Title XII of the National Defense Authorization Act for Fiscal Year 2017 (Public Law 114-328 of 23 December 2016), is the principal United States statute authorizing the President to impose targeted sanctions on foreign persons responsible for gross violations of internationally recognized human rights or significant acts of corruption, and is administered by the Department of the Treasury's Office of Foreign Assets Control and the Department of State. Global Magnitsky Human Rights Accountability Act, section 1261 sets the short title. Global Magnitsky Human Rights Accountability Act, section 1262 contains the definitions including admission and admitted, alien, appropriate congressional committees, financial institution, and United States person. Global Magnitsky Human Rights Accountability Act, section 1263 authorizes the imposition of sanctions on foreign persons responsible for or complicit in gross violations of internationally recognized human rights, and on foreign government officials responsible for or complicit in acts of significant corruption, including those who are nationals of countries other than the Russian Federation. Global Magnitsky Human Rights Accountability Act, section 1264 requires reports to Congress including the list of designated persons. Global Magnitsky Human Rights Accountability Act, section 1265 originally contained a sunset provision but the authority was made permanent by section 6 of the Global Magnitsky Human Rights Accountability Act Reauthorization Act of 2022 in section 5587 of Public Law 117-263. The Act is the controlling federal instrument for global targeted human rights and anti-corruption sanctions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-global-privacy-control-legal-status-states",
    "title": "Global Privacy Control (GPC) Legal Status Across US State Privacy Laws - Technical Signal Requirements and Controller Compliance Obligations",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Controllers subject to specific US state privacy laws, such as the California Consumer Privacy Act (CCPA), must treat the browser-based Global Privacy Control (GPC) signal as a valid, legally binding request from a consumer to opt out of the sale or sharing of their personal information, as mandated by regulations like Cal. Code Regs. tit. 11, § 7025(b). This requires technical detection and frictionless processing of the signal without requiring further steps from the user.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-goldwater-nichols-dod-reorganization-10-usc-111",
    "title": "Goldwater-Nichols DoD Reorganization Act 1986 - 10 USC 111",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 111 of title 10 of the United States Code, as substantially amended by the Goldwater-Nichols Department of Defense Reorganization Act of 1986 (Public Law 99-433, enacted 1 October 1986), defines the Department of Defense as an executive department of the United States composed of eleven enumerated elements: the Office of the Secretary of Defense, the Joint Chiefs of Staff, the Joint Staff, the Defense Agencies, the Department of Defense Field Activities, the Department of the Army, the Department of the Navy, the Department of the Air Force, the unified and specified combatant commands, other offices established by law or presidential designation, and all subordinate entities under the control of the foregoing. The Goldwater-Nichols Act fundamentally restructured DoD by strengthening the authority of the Chairman of the Joint Chiefs of Staff (CJCS) as principal military advisor to the President, the National Security Council, and the Secretary of Defense; clarifying that the operational chain of command runs from the President to the Secretary of Defense to the combatant commanders bypassing the service chiefs; creating the Vice Chairman of the Joint Chiefs of Staff position; institutionalising joint operations through joint duty requirements and joint education; and elevating the role of unified combatant commands. The Act remains the constitutional architecture of US military operations and joint warfighting, and its principles inform every contemporary DoD initiative including the Joint All-Domain Command and Control (JADC2) AI integration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-national-security-act-1947-50-usc-3001",
      "us-posse-comitatus-act-18-usc-1385"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-government-employees-training-act-5-usc-4101",
    "title": "US Government Employees Training Act (5 USC 4101) - Federal Employee Training Authority and Programs",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Government Employees Training Act authorises heads of federal agencies to establish, operate, maintain, and evaluate training programs for federal employees, authorises training by, in, and through government facilities and non-government facilities, requires the Office of Personnel Management to coordinate and develop government-wide training policy, authorises payment of expenses including travel and per diem in connection with training, prohibits training that would violate other federal restrictions, and requires service agreements when training expenses exceed a statutory threshold to recover costs if the employee leaves federal service within an agreed period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-civil-service-reform-act-5-usc-1101"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-government-in-sunshine-act-5-usc-552b",
    "title": "Government in the Sunshine Act 1976 - 5 USC 552b Open Meetings of Federal Agencies",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 552b of title 5 of the United States Code, codifying the Government in the Sunshine Act (Public Law 94-409, enacted 13 September 1976), requires that every portion of every meeting of a federal agency headed by a collegial body composed of two or more individuals, the majority of whom are appointed by the President with the advice and consent of the Senate, shall be open to public observation, subject to ten specific exemptions justifying closure. The exemptions cover meetings that would disclose matters specifically authorised under criteria established by Executive Order to be kept secret in the interest of national defense or foreign policy, internal personnel rules and practices, matters specifically exempted from disclosure by statute, trade secrets and commercial or financial information obtained from a person and privileged or confidential, matters that would involve accusing any person of a crime or formally censuring any person, matters of a personal nature whose disclosure would constitute a clearly unwarranted invasion of personal privacy, investigatory records compiled for law enforcement purposes, examination, operating, or condition reports prepared by or for an agency responsible for financial institution regulation or supervision, information that could lead to significant financial speculation or significantly endanger the stability of any financial institution, and information concerning the agency's issuance of subpoenas or its participation in civil action or proceedings. The statute requires public announcement of meetings at least one week in advance including time, place, subject matter, and contact information; majority-vote closure with a written explanation; and preservation of transcripts, recordings, or minutes of every closed meeting. The Sunshine Act is the principal federal transparency framework for multi-member commissions (FCC, FTC, NRC, SEC, CFTC, NLRB, FERC, USITC, EEOC, FMC, MSPB, USPS BOG, CPSC, FEC) and is increasingly tested where multi-member bodies adopt AI-supported decision tools.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-foia-1966",
      "us-federal-records-act-44-usc-ch31",
      "us-paperwork-reduction-act-44-usc-ch35"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-gpra-modernization-act-31-usc-ch11",
    "title": "United States Government Performance and Results Act Modernization Act of 2010 (Title 31 USC Chapter 11): Strategic Plans, Performance Plans, Agency Reporting, Priority Goals, and Quarterly Reviews",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Government Performance and Results Act Modernization Act of 2010, codified at Title 31 of the United States Code, Chapter 11, is the principal federal statute governing federal performance management and is administered through the Office of Management and Budget in coordination with federal agencies. Government Performance and Results Act, 31 U.S.C. 1115 establishes the Federal Government and agency performance plans, requiring each agency to set performance goals against which performance can be measured. Government Performance and Results Act, 31 U.S.C. 1116 governs agency performance reporting against those goals. Government Performance and Results Act, 31 U.S.C. 1117 sets exemptions from certain reporting requirements. Government Performance and Results Act, 31 U.S.C. 1120 establishes Federal Government and agency priority goals, a multi-year strategic management tool for the most significant outcomes the President wants the Government to achieve. Government Performance and Results Act, 31 U.S.C. 1121 requires quarterly priority progress reviews and use of performance information by senior agency officials. Government Performance and Results Act, 31 U.S.C. 1122 requires transparency of programs, priority goals, and results through a publicly accessible website. Government Performance and Results Act, 31 U.S.C. 1123 establishes Chief Operating Officers for each agency. Government Performance and Results Act, 31 U.S.C. 1124 establishes Performance Improvement Officers and the Performance Improvement Council. Government Performance and Results Act, 31 U.S.C. 1125 requires elimination of unnecessary agency reporting. Government Performance and Results Act, 31 U.S.C. 1126 establishes Program Management Improvement Officers and the Program Management Policy Council. The Act, as modernised in 2010, is the controlling federal instrument for performance management across the executive branch.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-grain-standards-act",
    "title": "US Grain Standards Act (7 USC ch 3): Official Grain Standards, Inspection and Weighing",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The United States Grain Standards Act (7 U.S.C. ch. 3, sections 71 to 87k) establishes official United States standards for grain and provides for the official inspection and weighing of grain, administered by the Secretary of Agriculture through the Federal Grain Inspection Service of the Agricultural Marketing Service. Section 71 sets the short title. Section 74 sets out the congressional findings and declaration of policy, declaring it to be the policy of Congress, for the promotion and protection of commerce in grain in the interests of producers, merchandisers, warehousemen, processors, and consumers, to provide for the establishment of official standards and for uniform official inspection. Section 75 defines the terms, and section 76 provides for the establishment, amendment, and revocation of official grain standards. Section 77 sets the official inspection and weighing requirements, including that grain exported from the United States must be officially inspected and weighed, and section 79 governs official inspection while section 84 provides for the licensing of inspectors. Section 86 provides for the refusal of inspection and weighing services and for civil penalties. Section 87b sets out the prohibited acts, and section 87c sets the criminal penalties, providing that a person who knowingly violates a provision prohibited by section 87b shall on conviction be subject to imprisonment for not more than five years, or a fine of not more than 20,000 dollars, or both. The Act is the federal grain quality and inspection regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-gramm-leach-bliley-act",
    "title": "US Gramm-Leach-Bliley Act (15 USC ch 94): Financial Privacy and Safeguarding of Customer Information",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Gramm-Leach-Bliley Act, in its privacy provisions (15 U.S.C. ch. 94), governs how financial institutions handle the nonpublic personal information of their customers, enforced by the Federal Trade Commission, the federal banking agencies, the Consumer Financial Protection Bureau and the Securities and Exchange Commission within their jurisdictions. Section 6801 declares the policy that each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and to protect the security and confidentiality of their nonpublic personal information, and directs the agencies to establish standards for administrative, technical and physical safeguards, the basis of the Safeguards Rule. Section 6802 sets the obligations with respect to disclosures of personal information, including the limits on sharing with nonaffiliated third parties and the customer right to opt out. Section 6803 requires a clear and conspicuous privacy notice at the establishment of the relationship and annually. Section 6804 allocates rulemaking, and section 6805 provides for enforcement. Section 6809 provides the definitions. Section 6821 prohibits obtaining customer information of a financial institution by false pretenses, known as pretexting, and section 6823 sets criminal penalties for pretexting. The Act is the legal foundation for US financial-sector privacy notices and information safeguarding.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-hart-scott-rodino-antitrust-improvements-act-1976-ftc-doj",
    "title": "US Hart-Scott-Rodino Antitrust Improvements Act 1976 - FTC/DOJ Pre-Merger Notification",
    "domain": "Competition & Antitrust",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Hart-Scott-Rodino (HSR) Act (15 U.S.C. 18a) requires parties to reportable acquisitions to file pre-merger notification with the FTC and DOJ Antitrust Division and observe a waiting period before closing; thresholds are indexed annually (2025 size-of-transaction: USD 119.5 million).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-hart-scott-rodino-hsr-premerger-notification",
    "title": "Hart-Scott-Rodino Antitrust Improvements Act of 1976 (15 U.S.C. § 18a) - Premerger Notification Requirements",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-05-29",
    "bluf": "The Hart-Scott-Rodino (HSR) Act requires parties to certain mergers and acquisitions that meet or exceed specific jurisdictional thresholds to file a notification with the Federal Trade Commission (FTC) and the Department of Justice (DOJ) and observe a mandatory waiting period before closing, as mandated by 15 U.S.C. § 18a(a). This allows federal agencies to review the transaction for potential anticompetitive effects.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-doj-ftc-merger-guidelines-2023",
      "us-ftc-act-section-5-unfair-competition"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-hart-scott-rodino-merger-notification",
    "title": "Hart-Scott-Rodino Antitrust Improvements Act of 1976 - Pre-Merger Notification Requirements for Mergers and Acquisitions",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Hart-Scott-Rodino (HSR) Act requires parties to certain large mergers and acquisitions to file premerger notifications with the FTC and DOJ and observe a mandatory waiting period before closing, unless early termination is granted. Applicability is determined by transaction size and entity size thresholds set forth in the Act and updated annually.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uk-cma-merger-assessment-guidelines-2021",
      "eu-state-aid-articles-107-108-tfeu-framework",
      "icn-recommended-practices-merger-notification-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-hart-scott-rodino-premerger-notification-1976",
    "title": "Hart-Scott-Rodino Antitrust Improvements Act of 1976 - Premerger Notification and Waiting Period Requirements",
    "domain": "Competition & Antitrust",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Requires parties to certain mergers, acquisitions, and tender offers to file premerger notifications with the FTC and DOJ and observe a mandatory waiting period before closing, if transaction size and party size thresholds are met under Section 7A of the Clayton Act. Applies to transactions exceeding $119.9 million (as adjusted in 2023) unless an exemption applies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-hass-avocado-promotion-research-information-act",
    "title": "US Hass Avocado Promotion, Research, and Information Act of 2000 (7 USC ch 105): Hass Avocado Board and Assessments",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Hass Avocado Promotion, Research, and Information Act of 2000 (7 U.S.C. ch. 105, sections 7801 to 7813) authorizes a national program of promotion, research, and information for Hass avocados funded by assessments, administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 7801 sets out the findings and declaration of policy, recognizing that Hass avocados are an integral food source in the United States that are a valuable and healthy part of the human diet. Section 7802 defines the terms, including producer, importer, and handler, and section 7803 authorizes the issuance of orders. Section 7804 sets the required terms in orders, providing for the establishment of a Hass Avocado Board consisting of 12 members to administer the order, and fixing the rate of assessment on Hass avocados at 0.025 dollars per pound on fresh avocados or an equivalent rate. Section 7805 sets the referenda, providing that an order shall become effective only if the Secretary determines that the order has been approved by a simple majority of the votes cast. Section 7806 provides for petition and review, section 7807 provides for enforcement, including a civil penalty of not less than 1,000 dollars nor more than 10,000 dollars for each violation, and section 7808 provides investigations and power to subpoena. Section 7810 provides the authority for the Secretary to suspend or terminate an order. The Act is the federal checkoff regime for Hass avocados.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-hatch-act-political-activity-5-usc-7321",
    "title": "Hatch Act 1939 (Reformed 1993) - 5 USC 7321 Federal Employee Political Activity",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 7321 of title 5 of the United States Code, as substantially revised by the Hatch Act Reform Amendments of 1993 (Public Law 103-94, enacted 6 October 1993, effective 4 January 1994), declares the policy that federal employees should be encouraged to exercise fully, freely, and without fear of penalty or reprisal their rights of political participation, subject to the express prohibitions in sections 7323 and 7324 and the related implementing regulations at 5 CFR Part 734. The Hatch Act of 1939 (Public Law 76-252) originally restricted federal employee partisan political activity comprehensively; the 1993 reform liberalised the framework for most federal employees while retaining more stringent restrictions on covered employees in specified law-enforcement, national-security, and intelligence components (including FBI, CIA, NSA, IRS Criminal Investigation, Secret Service, and others enumerated at 5 USC 7323(b)(2)). Section 7323 prohibits all federal employees from using official authority to influence elections, soliciting political contributions outside permitted contexts, soliciting subordinate participation, knowing solicitation of contributions for partisan political purposes, and running for office in partisan elections. Section 7324 restricts political activity while on duty, in federal facilities, in uniform, or using government vehicles. The Office of Special Counsel investigates Hatch Act violations and may seek disciplinary action through the Merit Systems Protection Board.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-civil-service-reform-act-5-usc-1101",
      "us-whistleblower-protection-act-5-usc-2302"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-hazardous-materials-transportation-act",
    "title": "US Hazardous Materials Transportation Act (49 USC ch 51): Hazmat Regulation, Registration and Penalties",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Hazardous Materials Transportation Act (49 U.S.C. ch. 51) governs the transportation of hazardous materials in commerce in the United States, administered by the Pipeline and Hazardous Materials Safety Administration (PHMSA) within the Department of Transportation. Section 5101 states the purpose of protecting against the risks to life, property and the environment inherent in the transportation of hazardous material. Section 5102 supplies the definitions, including hazardous material and the categories of person who offer, transport or package it. Section 5103 grants the general regulatory authority to designate material as hazardous and to prescribe regulations for its safe transportation, including handling, packaging, labeling and placarding. Section 5104 prohibits misrepresentation and the tampering with markings, labels or placards. Section 5106 addresses handling criteria, section 5107 requires hazmat employee training, and section 5108 requires the registration of persons who transport or offer for transport certain hazardous materials. Section 5110 requires shipping papers and disclosure. Enforcement is direct: section 5123 provides for civil penalties for each violation, and section 5124 provides criminal penalties for knowing or willful violations. The Act is the legal foundation of US hazmat transportation safety, the registration regime, and the hazard-communication requirements across all modes of transport.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-hea-34-cfr-668-student-assistance-general-provisions",
    "title": "34 CFR Part 668 - Student Assistance General Provisions",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This regulation establishes the general provisions, standards for participation, and student eligibility requirements for institutions participating in Title IV, Higher Education Act (HEA) student assistance programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-helms-burton-libertad-act-22-usc-ch69a",
    "title": "United States Cuban Liberty and Democratic Solidarity (LIBERTAD) Act of 1996, Commonly Known as the Helms-Burton Act (Title 22 USC Chapter 69A): Congressional Findings, Statement of Policy, Title III Civil Liability for Trafficking in Confiscated Property, and Title IV Exclusion of Aliens",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Cuban Liberty and Democratic Solidarity (LIBERTAD) Act of 1996, commonly known as the Helms-Burton Act, Public Law 104-114 of 12 March 1996, codified at Title 22 of the United States Code, Chapter 69A, is the principal federal statute strengthening sanctions against Cuba including private civil liability for trafficking in property confiscated by the Cuban Government from United States nationals, and is administered by the Department of State and the Office of Foreign Assets Control. Helms-Burton Act, 22 U.S.C. 6021 contains the Congressional findings regarding Cuba's economic decline and human rights violations. Helms-Burton Act, 22 U.S.C. 6022 contains the statement of legislative objectives for assisting Cuban citizens and strengthening sanctions. Helms-Burton Act, 22 U.S.C. 6023 contains the definitions of key terms used throughout the statute. Helms-Burton Act, 22 U.S.C. 6031 contains the Congressional sense regarding Castro government actions as threats to international peace. Helms-Burton Act, 22 U.S.C. 6065 contains the standards for determining whether a transition government exists in Cuba. Helms-Burton Act, 22 U.S.C. 6082 contains Title III, the civil liability framework for persons engaging in commercial dealings with property seized by the Cuban Government, with private right of action for United States nationals against persons who traffic in confiscated property. Helms-Burton Act, 22 U.S.C. 6091 contains Title IV, provisions addressing exclusion from United States entry of foreign nationals involved with confiscated property. The Act is the controlling federal instrument for codified United States sanctions against Cuba and includes the only United States statute providing private extraterritorial civil liability against foreign persons trafficking in confiscated property.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-hhs-405d-healthcare-cybersecurity-practices",
    "title": "Health Industry Cybersecurity Practices (HICP): Managing Threats and Protecting Patients (2023 Edition)",
    "domain": "Cybersecurity",
    "version": "2023.1.0",
    "last_updated": "2024-04-18",
    "bluf": "Mandated by Section 405(d) of the Cybersecurity Act of 2015, the Health Industry Cybersecurity Practices (HICP) are a voluntary set of guidelines from the U.S. Department of Health and Human Services (HHS) to help healthcare organizations mitigate the top five cybersecurity threats through ten core practices, tailored for small, medium, and large organizations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "nist-cybersecurity-framework-2-0",
      "cisa-ms-isac-ransomware-guide",
      "cis-controls-v8",
      "nist-800-53-cp2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-hhs-45-cfr-155-aca-exchange-establishment-standards",
    "title": "US HHS ACA Health Insurance Exchanges - 45 CFR Part 155 Exchange Establishment Standards, Eligibility Determinations and Enrollment in Qualified Health Plans",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "45 CFR Part 155 (Exchange Establishment Standards and Other Related Standards Under the Affordable Care Act) is the HHS regulation implementing the Affordable Care Act (ACA, Public Law 111-148) provisions establishing Health Insurance Exchanges (Marketplaces). Part 155 applies to State Exchanges and to the Federally-facilitated Exchange (FFE) operated by the Centers for Medicare and Medicaid Services (CMS) for states that do not establish their own Exchange. Subpart A (general provisions) sets the regulatory framework. Subpart B (general standards related to the establishment of an Exchange) sets §155.100 Exchange Approval, §155.105 State Exchange standards, §155.110 entities eligible to carry out Exchange functions, §155.120 non-interference with federal law, and §155.130 stakeholder consultation. Subpart C (general functions of an Exchange) sets §155.200 functions of an Exchange (general standards for certification of qualified health plans (QHPs), eligibility determinations, enrollment, and operational management). Subpart D (consumer assistance tools and programs) sets the Navigator and certified application counselor programs at §§155.205-155.225 and the consumer-assistance call center, web portal, and standardized notices. Subpart E (eligibility process) governs eligibility for enrollment in a QHP, advance payments of the premium tax credit (APTC), cost-sharing reductions (CSR), and Medicaid/CHIP at §§155.300-155.355 including verification procedures, eligibility appeals, and special enrollment periods. Subpart F (appeals) governs §§155.500-555 eligibility appeals process; enrollment in QHPs is governed by §155.400 (enrollment of qualified individuals), §155.410 (initial and annual open enrollment periods), §155.420 (special enrollment periods), and §155.430 (termination of coverage or enrollment). Subpart H (Exchange functions: Small Business Health Options Program (SHOP)) covers the SHOP. Subpart K (Exchange functions: certification of QHPs) sets QHP certification standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-hhs-45-cfr-160-hipaa-general-administrative-requirements"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-hhs-45-cfr-156-health-insurance-issuer-qhp-standards",
    "title": "45 CFR Part 156 - Health Insurance Issuer Standards under the Affordable Care Act, Including QHP Standards (HHS)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "HHS 45 CFR Part 156 sets the health insurance issuer standards under the Affordable Care Act, including the qualified health plan certification standards, requiring an issuer to maintain a single risk pool, provide the essential health benefits to the benchmark standard, cover prescription drugs without discrimination, meet the cost-sharing, actuarial value, and coverage level requirements, meet the QHP issuer participation standards, provide rate, benefit, and transparency information, satisfy the network adequacy and essential community provider standards, manage enrollment and termination of coverage, segregate funds for abortion services, and maintain accreditation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 20
  },
  {
    "node_id": "us-hhs-45-cfr-160-hipaa-general-administrative-requirements",
    "title": "US HHS HIPAA General Administrative Requirements - 45 CFR Part 160 Applicability, Definitions, Preemption, Civil Monetary Penalties and Compliance and Enforcement Procedures",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "45 CFR Part 160 (General Administrative Requirements) is the foundational HIPAA Administrative Simplification rule issued by the US Department of Health and Human Services under the Health Insurance Portability and Accountability Act of 1996 (HIPAA, Public Law 104-191), as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH, Public Law 111-5) and the Genetic Information Nondiscrimination Act (GINA, Public Law 110-233). Part 160 sets the scope of HIPAA's substantive rules in Parts 162 (transactions and code sets), 164 Subpart A (general provisions), 164 Subpart C (Security Rule), 164 Subpart D (Breach Notification), and 164 Subpart E (Privacy Rule). Subpart A (§§160.101-160.105) sets applicability and the definition of covered entity (health plan, health care clearinghouse, healthcare provider who transmits any health information in electronic form in connection with a transaction for which HHS has adopted a standard) and business associate. Subpart B (§§160.201-160.205) sets preemption rules: HIPAA preempts contrary state law except where the state law is more stringent (defined in §160.202), provides for the reporting of disease, injury, or vital statistics, or fits other specified categories. Subpart C (§§160.300-160.316) sets compliance and enforcement procedures including the Office for Civil Rights' (OCR) investigation authority, the right to request and provide information, mediation and informal resolution, and formal hearing procedures. Subpart D (§§160.400-160.426) sets civil monetary penalties: four-tier penalty structure based on culpability ranging from no knowledge (USD 100-50,000 per violation, USD 25,000-1,500,000 annual cap) to willful neglect not corrected (USD 50,000 per violation, USD 1,500,000 annual cap), with all amounts subject to annual inflation adjustment per the 1990 Federal Civil Penalties Inflation Adjustment Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-breach-notification"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-hhs-45-cfr-162-hipaa-administrative-simplification-identifiers",
    "title": "45 CFR Part 162 - HIPAA Administrative Simplification: Standard Unique Identifiers",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "HHS 45 CFR Part 162 implements the HIPAA Administrative Simplification standard unique identifiers and electronic transaction standards, requiring covered entities to obtain and use the National Provider Identifier for health care providers and the standard unique employer identifier, and to follow the implementation specifications for providers, health plans, and clearinghouses when conducting standard electronic transactions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-hhs-45-cfr-160-hipaa-general-administrative-requirements"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-hhs-45-cfr-46-common-rule-protection-of-human-subjects-research",
    "title": "US HHS Common Rule - 45 CFR Part 46 Protection of Human Subjects in Federally Conducted, Supported or Otherwise Subject Research Including IRB Review and Informed Consent",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "45 CFR Part 46 (Protection of Human Subjects) is the HHS regulation implementing the Federal Policy for the Protection of Human Subjects (the Common Rule), originally adopted in 1991 and substantially revised by the 2017 Final Rule (commonly referenced as the 2018 Common Rule effective January 21, 2019). Part 46 applies to research conducted, supported, or otherwise subject to regulation by the federal departments and agencies that have adopted the Common Rule, and the Subpart A baseline is recognized by 19 federal departments. Subpart A (§§46.101-46.124) is the Common Rule baseline including general requirements (§46.101), definitions (§46.102), assurances of compliance (§46.103), exempt categories (§46.104), expedited review (§46.110), and Institutional Review Board (IRB) functions, composition, and procedures (§§46.107-109, 111). Section 46.111 sets criteria for IRB approval: risks minimized, risks reasonable in relation to anticipated benefits, equitable selection of subjects, informed consent, documentation of informed consent, data monitoring as required, privacy and confidentiality protections, additional safeguards for vulnerable populations. Section 46.116 sets informed consent requirements with the basic, additional, and key-information elements; §46.117 sets documentation requirements. Subpart B (§§46.201-46.207) provides additional protections for pregnant women, human fetuses, and neonates involved in research. Subpart C (§§46.301-46.306) provides additional protections for prisoners. Subpart D (§§46.401-46.409) provides additional protections for children including the four research-permissibility categories. Subpart E (§§46.501-46.505) governs IRB registration. The HHS Office for Human Research Protections (OHRP) oversees compliance with Part 46 through Federalwide Assurances (FWAs) negotiated with research institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-50-human-subjects-protection-clinical-research"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-hhs-45-cfr-46-common-rule-research",
    "title": "Code of Federal Regulations, Title 45, Part 46 - Protection of Human Subjects",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The Common Rule (45 CFR Part 46) establishes federal policy for the protection of human subjects in research, requiring Institutional Review Board (IRB) review, informed consent, and additional safeguards for vulnerable populations such as children, prisoners, and pregnant women. It applies to all federally funded research involving human subjects under Subpart A and extends specific protections in Subparts B, C, and D.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-e8-r1-general-considerations-clinical-2021",
      "isber-best-practices-biorepositories-2018",
      "oecd-guidelines-human-biobanks-2009",
      "fda-guidance-human-gene-therapy-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-hhs-hipaa-security-rule-nprm-2024",
    "title": "US HHS HIPAA Security Rule Notice of Proposed Rulemaking (Published 6 January 2025) - Modernised Cybersecurity Standards for Electronic Protected Health Information; Proposed Amendments to 45 CFR Parts 160 and 164 Subparts A and C; Mandatory Encryption, Multi-Factor Authentication, Technology Asset Inventory, Patch Management, and Compliance Audit",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "On 6 January 2025 the US Department of Health and Human Services Office for Civil Rights published the HIPAA Security Rule Notice of Proposed Rulemaking (HHS-OCR-2024-0010) at 90 FR 898, proposing the most substantial modernisation of the Security Rule since the 2013 Omnibus Rule. The NPRM proposes to amend 45 CFR Part 160 and subparts A and C of 45 CFR Part 164, restructuring the Security Rule's administrative, physical, and technical safeguards (Sections 164.308, 164.310, 164.312) and the documentation requirements (Section 164.316), strengthening the organisational requirements at Section 164.314, modernising definitions at Section 164.304 (including a new definition of Multi-Factor Authentication), and revising the General Rules at Section 164.306. Among the headline proposals: the longstanding 'addressable' implementation specification for encryption at Section 164.312(a)(2)(iv) becomes a required safeguard with limited exceptions; a new technology asset inventory standard is introduced at Section 164.308(a)(1)(i); risk analysis at Section 164.308(a)(2)(i) is materially upgraded to require an inventory of technology assets, mapping of ePHI flow through information systems, and identification of all locations where ePHI is created, received, maintained, or transmitted; patch management is elevated to a standalone standard at Section 164.308(a)(4)(i); a Compliance Audit standard is added at Section 164.308(a)(14); business associate contract obligations are addressed at Section 164.318 with a transition period beyond the standard 180-day compliance window for business associate agreement renegotiation. Comments were due 7 March 2025; a Tribal consultation meeting was held 6 February 2025. The NPRM applies the standard 60-day post-publication effective date and a 180-day compliance window per Section 160.105 to a future final rule, except where a different period is specified. Regulated entities - covered entities and business associates collectively - would face explicit codification of practices long expected but not previously specified in regulatory text, including written verification of business associate safeguard implementation, inventory and mapping requirements as preconditions to risk analysis, and standardised security incident procedures aligned to current cybersecurity guidance including NIST CSF 2.0 and NIST SP 800-53 Revision 5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "us-hipaa-privacy-rule-2003",
      "nist-csf-2-0-cybersecurity-framework-2024",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 26
  },
  {
    "node_id": "us-hhs-ocr-hipaa-reproductive-health-privacy-final-rule-2024",
    "title": "US HHS HIPAA Privacy Rule to Support Reproductive Health Care Privacy Final Rule - Prohibition on Disclosures for Investigation Purposes, Compliance Date 22 December 2024",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-05",
    "bluf": "Covered entities and business associates under HIPAA must, from the compliance date of 22 December 2024 (with the attestation requirement compliance date of 19 February 2026), comply with the HHS Office for Civil Rights final rule HIPAA Privacy Rule to Support Reproductive Health Care Privacy (89 FR 32976, 22 April 2024) by recognising that the Privacy Rule now prohibits use or disclosure of protected health information (PHI) for purposes of investigating or imposing liability on persons for the mere act of seeking, obtaining, providing, or facilitating reproductive health care that is lawful in the state where the care was provided per 45 CFR 164.502(a)(5)(iii), and by requiring a signed attestation under new 45 CFR 164.509 from any person requesting PHI potentially related to reproductive health care for health oversight, judicial, law enforcement, or coroner purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-hipaa-privacy-rule-2003"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-hhs-oig-42-cfr-1001-program-exclusions",
    "title": "42 CFR Part 1001 - HHS OIG Exclusions from Federal Health Care Programs",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "42 CFR Part 1001 governs the exclusion of individuals and entities from participation in Medicare, Medicaid and other Federal health care programs by the U.S. Department of Health and Human Services Office of Inspector General. The regulations set out the basis for mandatory and permissive exclusion and the factors determining the length of exclusion. Conduct that triggers exclusion includes conviction relating to program or health care fraud, conviction relating to obstruction of an investigation or audit, conviction relating to controlled substances, license revocation or suspension, submission of false or improper claims, and engaging in fraud, kickbacks and other prohibited activities outside the statutory and regulatory exceptions (safe harbors). An entity owned or controlled by a sanctioned person may itself be excluded. Persons must disclose required information, provide payment information, and grant immediate access on request. Exclusion prohibits payment by Federal health care programs for items or services furnished by an excluded person.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-privacy-rule",
      "hitech-act-2009",
      "hipaa-security-rule"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-higher-education-act-1965",
    "title": "US Higher Education Act of 1965 (20 U.S.C. Chapter 28): Federal Student Financial Assistance, Institutional Eligibility and Accountability",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Higher Education Act of 1965, codified at 20 U.S.C. Chapter 28, is the principal federal statute governing United States postsecondary education policy, federal student financial assistance, and the conditions institutions must meet to participate in those programs, administered by the Department of Education. Section 1001 defines an institution of higher education for the chapter generally, requiring State authorization, accreditation by a nationally recognized agency, and award of recognized degrees or credit. Section 1002 sets the broader definition of an eligible institution for purposes of the student assistance programs, including proprietary and postsecondary vocational institutions. Section 1011 sets general provisions including antidiscrimination requirements. Section 1070 states the purpose of and authorizes the Federal Pell Grant and related need-based grant programs. Section 1078 governs federal payments to reduce student interest costs under the Federal Family Education Loan program. Section 1087 governs repayment by the Secretary of loans of bankrupt, deceased, or disabled borrowers and related loan provisions. Section 1092 requires institutions to disclose financial assistance, completion, and campus security information to students, the basis of the Clery Act reporting duties. Section 1094 requires each participating institution to enter a program participation agreement committing to administer Title IV aid in compliance with the Act. The Act is the foundational statute for federal higher education funding and institutional compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-hipaa-45-cfr-164-308-administrative-safeguards",
    "title": "45 CFR 164.308 - Administrative safeguards",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "A covered entity or business associate must implement administrative safeguards, including policies, procedures, and risk management processes, to protect the confidentiality, integrity, and availability of electronic protected health information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-hipaa-45-cfr-164-310-physical-safeguards",
    "title": "45 CFR 164.310 - Physical safeguards.",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must implement policies, procedures, and physical safeguards to control facility access, secure workstations, and manage electronic devices and media containing protected health information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-hipaa-45-cfr-164-312-technical-safeguards",
    "title": "45 CFR 164.312 - Technical safeguards.",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must implement technical policies and procedures, including access controls, audit controls, integrity measures, authentication, and transmission security, to protect electronic protected health information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-hipaa-45-cfr-164-314-business-associate-contracts",
    "title": "45 CFR 164.314 - Organizational requirements.",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation requires covered entities and group health plans to establish contracts or amend plan documents to ensure their business associates and plan sponsors appropriately safeguard electronic protected health information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-hipaa-45-cfr-164-316-documentation-requirements",
    "title": "45 CFR 164.316 - Policies and procedures and documentation requirements.",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Covered entities and business associates must implement and maintain written policies and procedures to comply with HIPAA Security Rule standards, and retain all required documentation for six years.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-30-records-processing",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-hipaa-45-cfr-164-404-breach-notification-covered-entities",
    "title": "45 CFR 164.404 - Notification to individuals.",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This regulation requires covered entities to notify individuals whose unsecured protected health information has been breached without unreasonable delay and no later than 60 days after discovery, specifying the content and methods of notification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-hipaa-45-cfr-164-410-breach-notification-business-associates",
    "title": "45 CFR 164.410 - Notification by a business associate.",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation requires a business associate to provide notification to a covered entity following the discovery of a breach of unsecured protected health information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-hipaa-45-cfr-164-502-uses-disclosures-phi",
    "title": "45 CFR 164.502 -- Uses and disclosures of protected health information: General rules.",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes the general principle that a covered entity or business associate may not use or disclose protected health information (PHI) except as explicitly permitted or required by law, and mandates applying the 'minimum necessary' standard to such uses and disclosures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-hipaa-45-cfr-164-524-right-of-access-phi",
    "title": "45 CFR 164.524 - Access of individuals to protected health information",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes an individual's right to access, inspect, and obtain a copy of their protected health information (PHI) held by a covered entity, and sets requirements for the timely provision or denial of such access.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-hipaa-45-cfr-164-530-administrative-requirements",
    "title": "45 CFR 164.530 - Administrative requirements",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation requires covered entities to implement a set of administrative measures to protect health information, including designating a privacy official, training staff, establishing safeguards, and maintaining written policies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-hipaa-automated-workflow-45-cfr-164-312-access-control",
    "title": "US HIPAA 45 CFR 164.312 - Technical Safeguards for Electronic Protected Health Information in Automated Healthcare Workflows",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Covered entities and business associates operating automated healthcare workflows must implement five technical safeguard standards for electronic protected health information (ePHI): access control (unique user ID, emergency access, automatic logoff, encryption), audit controls (activity logging and examination), integrity (ePHI alteration detection), person or entity authentication (identity verification before access), and transmission security (integrity controls and encryption in transit). Required specifications are mandatory; addressable specifications must be implemented or substituted with documented equivalent alternatives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-govern-function",
      "eu-nis2-directive-2022-2555"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-hipaa-breach-notification-rule",
    "title": "HIPAA Breach Notification Rule (45 CFR Parts 164.400-414) - Unsecured Protected Health Information Breach Response",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-07-10",
    "bluf": "This rule requires HIPAA-covered entities and their business associates to provide notification to affected individuals, the Secretary of Health and Human Services (HHS), and, in some cases, the media following a breach of unsecured Protected Health Information (PHI). As per 45 CFR § 164.404, individual notifications must be provided without unreasonable delay and in no case later than 60 calendar days after discovery of the breach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "hitech-act-2009"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-hipaa-hitech-phi-breach-notification-rule-45-cfr-164",
    "title": "US HIPAA/HITECH PHI Breach Notification Rule - 45 CFR Part 164 Subpart D",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-04-24",
    "bluf": "The HIPAA Breach Notification Rule at 45 CFR Part 164 Subpart D requires covered entities and business associates to notify affected individuals, HHS, and (for large breaches) the media following a breach of unsecured protected health information (PHI). Notification to individuals must occur within 60 days of breach discovery. Breaches affecting 500+ individuals require concurrent HHS notification and media notice in the affected state. The HITECH Act strengthens penalties: up to $1.9 million per violation category per year.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-hipaa-omnibus-rule-2013",
    "title": "US HIPAA Omnibus Rule 2013 - Modifications to Privacy, Security, and Breach Notification Rules",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The HIPAA Omnibus Rule (78 FR 5566) effective March 26, 2013 (compliance date September 23, 2013) implements HITECH Act modifications to HIPAA, extending Privacy and Security Rule obligations directly to business associates and their subcontractors, strengthening the breach notification presumption standard, enhancing patient rights to restrict disclosures to health plans for self-pay services, prohibiting sale of PHI without authorisation, restricting certain marketing authorisations, and adjusting civil monetary penalty tiers to USD 100 to USD 50,000 per violation up to USD 1.9 million per year.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-hipaa-omnibus-rule-2013.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-hitech-act-2009",
      "us-hipaa-breach-notification-rule"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-hipaa-privacy-rule-2003",
    "title": "US HIPAA Privacy Rule 2003 (45 CFR Parts 160 and 164)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The HIPAA Privacy Rule (45 CFR Parts 160 and 164 Subparts A and E) effective April 14, 2003 establishes national standards for the protection of protected health information (PHI) held by covered entities - health plans, health care clearinghouses, and health care providers - requiring minimum necessary use, patient rights to access and amend PHI, notice of privacy practices, authorisation for non-routine disclosures, and HHS OCR enforcement with civil penalties up to USD 1.9 million per violation category per year.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-hipaa-privacy-rule-2003.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-hipaa-privacy-security-rules-1996",
    "title": "US HIPAA Privacy and Security Rules -- Protected Health Information Compliance Framework",
    "domain": "Medical & Healthcare",
    "version": "2024.1.0",
    "last_updated": "2024-04-22",
    "bluf": "The Health Insurance Portability and Accountability Act 1996 (HIPAA), implemented through HHS regulations at 45 CFR Parts 160 and 164, establishes federal standards for the protection of Protected Health Information (PHI). The Privacy Rule (45 CFR Part 164 Subpart E) gives patients rights to access their PHI within 30 days (extendable by 30 additional days). The Security Rule (45 CFR Part 164 Subpart C) requires administrative, physical, and technical safeguards for electronic PHI (ePHI). The Breach Notification Rule (45 CFR Part 164 Subpart D) requires notification to affected individuals and HHS within 60 days of discovery of an unsecured PHI breach. Covered entities must notify HHS of breaches affecting 500 or more individuals simultaneously with individual notice and notify local media. Civil money penalties range from USD 100 to USD 50,000 per violation per category depending on culpability, with a maximum of USD 1,500,000 per violation category per calendar year. Business Associates (BAs) are directly liable for Security Rule and Breach Notification Rule compliance under the HITECH Act 2009.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "related_regulation",
        "industry_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-medical-devices-regulation-2017-745",
      "eu-clinical-trials-regulation-2014-536"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-hipaa-reproductive-health-privacy-2024",
    "title": "US HIPAA Final Rule on Reproductive Health Care Privacy 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The HHS Final Rule on Reproductive Health Care Privacy, published April 26, 2024 and effective June 25, 2024, amends the HIPAA Privacy Rule to prohibit covered entities and business associates from using or disclosing protected health information for the purpose of investigating, identifying, or imposing liability on individuals who seek, obtain, provide, or facilitate lawful reproductive health care - including requiring a signed attestation from parties seeking PHI for reproductive health enforcement purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-hipaa-reproductive-health-privacy-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-hipaa-security-rule-2005",
    "title": "US HIPAA Security Rule 2005 (45 CFR Parts 160 and 164 Subparts A and C)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The HIPAA Security Rule (45 CFR Parts 160 and 164 Subparts A and C) effective April 20, 2005 requires covered entities and business associates to implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of electronic protected health information (ePHI), with required and addressable implementation specifications, mandatory risk analysis and management, and HHS OCR civil monetary penalty enforcement up to USD 1.9 million per violation category per year.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-hipaa-security-rule-2005.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-hitech-act-2009"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-hipaa-security-rule-45-cfr-164-ephi-safeguards",
    "title": "US HIPAA Security Rule (45 CFR Part 164) - Administrative, Physical, and Technical Safeguards for Electronic PHI",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The HIPAA Security Rule (45 CFR §§164.302-318) requires HIPAA-covered entities and their business associates to implement administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic protected health information (ePHI). A documented risk analysis is mandatory; HHS OCR enforces with tiered civil and criminal penalties up to $1.9M per violation category per year.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-hipaa-security-rule-45-cfr-164-technical-safeguards",
    "title": "HIPAA Security Rule 45 CFR § 164 - Technical Safeguards for Electronic Protected Health Information",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-15",
    "bluf": "The HIPAA Security Rule (45 C.F.R. Part 164, Subpart C) requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic protected health information (ePHI). Technical safeguards include access controls, audit controls, integrity verification, and transmission security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-hipaa-privacy-rule-2003"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-hitech-act-2009",
    "title": "Health Information Technology for Economic and Clinical Health (HITECH) Act, Title XIII of the American Recovery and Reinvestment Act of 2009",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The HITECH Act strengthens HIPAA's privacy and security rules by introducing mandatory breach notification requirements for unsecured Protected Health Information (PHI) and establishing increased, tiered civil monetary penalties for violations. It applies to HIPAA Covered Entities and their Business Associates, mandating notification to individuals and HHS following a breach, as detailed in Section 13402.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-security-rule",
      "us-21st-century-cures-act-2016"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-hobbs-act-18-usc-1951",
    "title": "Hobbs Act 1946 - 18 USC 1951 Interference with Commerce by Threats or Violence",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 1951 of title 18 of the United States Code, commonly known as the Hobbs Act, criminalises any obstruction, delay, or affect on commerce by robbery or extortion, and any conspiracy to do so or any threatened or actual physical violence to person or property in furtherance of a plan or purpose to commit robbery or extortion. The statute defines robbery as the unlawful taking or obtaining of personal property from the person or in the presence of another against will by means of actual or threatened force, violence, or fear of injury immediate or future to person or property or to the person or property of a family member or anyone in the company at the time. Extortion is defined as the obtaining of property from another with consent induced by wrongful use of actual or threatened force, violence, or fear, or under colour of official right. The maximum penalty is 20 years imprisonment, a fine, or both. The Hobbs Act has served as the principal federal anti-extortion and anti-corruption statute since enactment by Public Law 79-486 in 1946 (replacing the 1934 Anti-Racketeering Act), with the colour-of-official-right doctrine providing the federal hook for public corruption and bribery prosecutions absent direct federal funding nexus. Hobbs Act prosecutions reach AI-mediated extortion schemes, ransomware-as-extortion, cryptocurrency-paid ransom demands, and AI-orchestrated influence campaigns where the property is paid under colour of official right; compliance programs covering AI agents that interact with state or local officials must integrate Hobbs Act safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-money-laundering-control-act-18-usc-1956"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-home-mortgage-disclosure-act",
    "title": "US Home Mortgage Disclosure Act (12 USC ch 29): Mortgage Lending Data Reporting",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Home Mortgage Disclosure Act (12 U.S.C. ch. 29) requires depository institutions and other mortgage lenders to compile, maintain and disclose data about their home mortgage lending, administered by the Consumer Financial Protection Bureau. Section 2801 sets the findings and purpose, which are to provide the public and officials with information to determine whether institutions are serving the housing needs of their communities and to assist in identifying possible discriminatory lending patterns. Section 2802 provides the definitions. Section 2803 requires covered institutions to maintain and disclose, for each fiscal year, the number and dollar amount of mortgage loans originated, purchased, or for which completed applications were received, itemized by geographic location and by characteristics including the type of loan, the disposition of the application, and borrower information such as income, race, ethnicity, age and sex, together with loan-level data including rate spread, points and fees, and loan term. The data must be retained and made available to the public, with annual disclosure. Section 2804 provides for enforcement, and section 2805 addresses the relationship to State laws. The Act is the legal foundation for US mortgage lending transparency and fair lending analysis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-home-mortgage-disclosure-act-hmda-regulation-c",
    "title": "US Home Mortgage Disclosure Act (HMDA) - Regulation C - 12 CFR Part 1003",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "HMDA (implemented by Regulation C, 12 CFR Part 1003) requires covered financial institutions to collect, record, and submit 48 data points on home mortgage applications and originations; institutional coverage threshold is ≥100 closed-end mortgages per year; data (Loan Application Register) filed with federal regulator by March 1 and published by March 31 for fair-lending analysis.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cfpb-dodd-frank-title-x-consumer-financial-protection",
      "us-equal-credit-opportunity-act-ecoa-1974",
      "us-truth-in-lending-act-regulation-z"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-honey-research-promotion-act",
    "title": "US Honey Research, Promotion, and Consumer Information Act (7 USC ch 77): Honey Board and Assessments",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Honey Research, Promotion, and Consumer Information Act (7 U.S.C. ch. 77, sections 4601 to 4613) authorizes a coordinated national program of research, promotion, and consumer information for honey and honey products, administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 4601 sets out the findings and purposes, and section 4602 defines terms including honey, handler, importer, and producer. Section 4603 authorizes the Secretary to issue and amend an order applicable to persons engaged in the production, sale, or handling of honey. Section 4606 prescribes the required terms of the order, including the establishment of a National Honey Board and the mechanism for collecting assessments, with the default assessment rate set at 0.01 dollars per pound and an alternative rate of 0.015 dollars per pound if approved. Section 4608 governs the collection of assessments and refunds, providing that first handlers collect assessments from producers and that importers remit assessments at the time of entry. Section 4611 requires that an order become effective only on approval by a majority in a referendum of producers, importers, and handlers, and section 4612 provides for termination or suspension of the order and for referenda. The Act is the federal commodity research and promotion regime for honey.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-honeybee-act",
    "title": "US Honeybee Act (7 USC ch 11): Importation Restrictions on Honeybees and Honeybee Semen",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Honeybee Act (7 U.S.C. ch. 11, sections 281 to 286) regulates the importation of honeybees into the United States to prevent the introduction of diseases, parasites, undesirable species or subspecies, and undesirable genetic material, administered by the Animal and Plant Health Inspection Service of the Department of Agriculture. Section 281 authorizes the Secretary of Agriculture, acting through regulations issued jointly with the Secretary of the Treasury for customs purposes, to prohibit or restrict the importation or entry of honeybees and honeybee semen; section 281 defines a honeybee as all life stages and the germ plasm of honeybees of the genus Apis, except honeybee semen. Section 282 makes the unlawful importation of any honeybee or honeybee semen punishable by a fine of not more than 1,000 dollars, or imprisonment for not more than one year, or both, and provides for the seizure and destruction or return of unlawfully imported bees. Section 283 authorizes the Secretary to propagate bee-breeding stock and to release bee germ plasm to the public. Section 284 authorizes the Secretary to carry out operations to eradicate and control undesirable honeybee species and subspecies within the United States, including cooperation with foreign governments. Sections 285 and 286 govern the use of funds and the authorization of appropriations. The Act is the primary federal control on apiary biosecurity at the United States border.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-horse-protection-act",
    "title": "US Horse Protection Act (15 USC ch 44): Prohibition on Soring, Show Duties and Penalties",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Horse Protection Act (HPA), codified at 15 U.S.C. Chapter 44 (sections 1821-1831), prohibits the soring of horses and the showing, sale, auction, exhibition or transport of sored horses, and is administered by the USDA Animal and Plant Health Inspection Service (APHIS). Section 1821 defines the key terms, including 'sore', which broadly covers the application of an irritating or blistering agent, burning, cutting or laceration, the injection of any substance, or the use of any tack, nail, screw or chemical agent on any limb of a horse, where the horse suffers, or can reasonably be expected to suffer, physical pain or distress, inflammation or lameness when walking, trotting or otherwise moving, except where the practice is for therapeutic veterinary treatment. Section 1822 sets out the congressional findings. Section 1823 imposes duties on horse shows, exhibitions, sales and auctions, including the appointment and use of qualified persons to detect and diagnose sored horses (designated qualified persons), disqualification of sored horses, and recordkeeping. Section 1824 sets the unlawful acts: it is unlawful to ship, transport, move, deliver or receive any horse which is sore for the purpose of showing, exhibiting, selling, auctioning or offering it for sale; to show, exhibit, sell, auction or offer for sale any sored horse; and for show management to fail to disqualify a sored horse. Section 1824a addresses the export of horses. Section 1825 sets the penalties: a person who knowingly violates section 1824 is, on conviction, fined not more than $3,000 or imprisoned not more than one year, or both, for a first violation, and not more than $5,000 or imprisoned not more than two years, or both, for a subsequent violation; the Secretary may assess a civil penalty of not more than $2,000 for each violation after notice and an opportunity for a hearing; and the Secretary may disqualify a violator from showing or exhibiting horses or managing shows. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-housing-economic-recovery-act-2008-pl-110-289",
    "title": "US Housing and Economic Recovery Act of 2008 (Public Law 110-289) - Federal Housing Finance Agency and GSE Conservatorship Authority",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Housing and Economic Recovery Act of 2008 created the Federal Housing Finance Agency as the unified safety and soundness regulator for Fannie Mae, Freddie Mac, and the twelve Federal Home Loan Banks, granted the FHFA Director authority to place a regulated entity into conservatorship or receivership, authorised the Treasury Secretary to purchase any obligation or security of the housing government sponsored enterprises during the statutory window, created the HOPE for Homeowners program, authorised first-time homebuyer tax provisions, and enacted the Secure and Fair Enforcement for Mortgage Licensing Act establishing the Nationwide Multistate Licensing System.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-federal-reserve-act-1913-12-usc-226",
      "us-eesa-tarp-2008-pl-110-343",
      "us-dodd-frank-act-2010"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-hud-fair-housing-act-1968-enforcement",
    "title": "US HUD Fair Housing Act 1968 - Prohibited Discrimination, Affirmatively Furthering Fair Housing and Enforcement",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Fair Housing Act (FHA, Title VIII of the Civil Rights Act of 1968, 42 U.S.C. Sections 3601-3619) enforced by the US Department of Housing and Urban Development (HUD) Office of Fair Housing and Equal Opportunity (FHEO) prohibits discrimination in the sale, rental, financing, and advertising of housing on the basis of race, colour, national origin, religion, sex, familial status, and disability; extends to real estate agents, lenders (Fair Housing Act plus Equal Credit Opportunity Act), and property management companies; requires recipients of HUD funding to Affirmatively Further Fair Housing (AFFH); and imposes civil penalties up to USD 21,663 for first violations and USD 108,315 for repeated violations, with unlimited compensatory and punitive damages available in federal court.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ada-title-iii-public-accommodations-buildings"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-humane-methods-of-slaughter-act",
    "title": "US Humane Methods of Slaughter Act (7 USC ch 48): Humane Slaughter Standards and Ritual Exemption",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Humane Methods of Slaughter Act (HMSA), codified at 7 U.S.C. Chapter 48 (sections 1901-1907), establishes the federal policy and standards for the humane slaughter and handling of livestock and is enforced in federally inspected establishments by the USDA Food Safety and Inspection Service (FSIS). Section 1901 declares the policy of the United States that the slaughtering of livestock and the handling of livestock in connection with slaughter shall be carried out only by humane methods. Section 1902 defines the humane methods: under subsection (a), in the case of cattle, calves, horses, mules, sheep, swine and other livestock, all animals must be rendered insensible to pain by a single blow or gunshot or an electrical, chemical or other means that is rapid and effective, before being shackled, hoisted, thrown, cast or cut; and under subsection (b), slaughter in accordance with the ritual requirements of a religious faith whereby the animal suffers loss of consciousness by anemia of the brain caused by the simultaneous and instantaneous severance of the carotid arteries with a sharp instrument, and the handling in connection with such slaughter, is also a humane method. Section 1904 authorizes the Secretary to conduct, assist and foster research to develop and determine humane methods of slaughter and to designate approved methods, with designations becoming effective 180 days after publication in the Federal Register. Section 1906 exempts ritual slaughter and the handling or other preparation of livestock for ritual slaughter from the terms of the chapter, and section 1907 addresses practices involving nonambulatory livestock. The HMSA does not itself impose fines or imprisonment; humane handling and slaughter are enforced through the Federal Meat Inspection Act, under which FSIS inspectors monitor humane handling and slaughter and may take regulatory action, including suspending inspection (which stops slaughter operations), where humane handling requirements are not met.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ia-icdpa-2023",
    "title": "US Iowa Consumer Data Protection Act 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Iowa Consumer Data Protection Act is the most business-friendly US comprehensive state privacy law alongside Utah, providing consumers rights to access, delete, and port personal data and to opt out of targeted advertising and sale, requiring only opt-out for sensitive data rather than opt-in, imposing no data protection assessment obligation, and providing a 90-day cure period - the longest among US state comprehensive privacy laws.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ia-icdpa-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ccpa-cpra-2023-marketing-rights"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-idea-34-cfr-part-300-special-education-iep",
    "title": "Individuals with Disabilities Education Act (IDEA) - 34 CFR Part 300 Assistance to States for Children with Disabilities",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This Individuals with Disabilities Education Act (IDEA) implementing regulation requires states, as a condition of receiving federal assistance, to ensure that a free appropriate public education (FAPE) is available to all eligible children with disabilities through Individualized Education Programs (IEPs).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-idea-individuals-disabilities-education-act",
    "title": "Individuals with Disabilities Education Act (IDEA) - Part B: Assistance for Education of All Children with Disabilities",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Individuals with Disabilities Education Act (IDEA) mandates that public schools provide a Free Appropriate Public Education (FAPE) to eligible children with disabilities, ensuring special education and related services are designed to meet their unique needs through a legally binding Individualized Education Program (IEP) as required by 20 U.S.C. § 1412.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-idea-individuals-disabilities-education-act-2004",
    "title": "Individuals with Disabilities Education Act of 2004",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Individuals with Disabilities Education Act (IDEA) 2004 mandates that all children with disabilities are entitled to a Free Appropriate Public Education (FAPE) designed to meet their unique needs through an Individualized Education Program (IEP), in the Least Restrictive Environment (LRE), with procedural safeguards. Applies to all public schools and state educational agencies receiving federal funding under Part B, Section 612(a).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-idea-individuals-with-disabilities-education-20-usc-1400",
    "title": "US Individuals with Disabilities Education Act (20 USC 1400) - Free Appropriate Public Education and IEP",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Individuals with Disabilities Education Act requires state and local educational agencies receiving federal IDEA funds to provide a free appropriate public education in the least restrictive environment to children with disabilities aged three through twenty-one, develop an Individualized Education Program tailored to each eligible child reviewed annually, conduct child find activities to identify and evaluate children suspected of having disabilities, provide procedural safeguards including written notice and the right to due process hearings and judicial review, support early intervention services for infants and toddlers under Part C, and provide federal funding to assist states in meeting these obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-rehabilitation-act-section-504",
      "us-americans-with-disabilities-act"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ieepa-1977",
    "title": "US International Emergency Economic Powers Act of 1977 (50 U.S.C. Chapter 35): Presidential Authority to Regulate Economic Transactions During a Declared National Emergency",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The International Emergency Economic Powers Act (IEEPA), codified at 50 U.S.C. Chapter 35 (sections 1701 through 1708), authorizes the President to regulate a broad range of economic transactions after declaring a national emergency to deal with an unusual and extraordinary threat, having its source in whole or substantial part outside the United States, to the national security, foreign policy, or economy of the United States. It is the principal statutory authority for United States economic sanctions programs administered by the Department of the Treasury through the Office of Foreign Assets Control. Section 1701 establishes the predicate of an unusual and extraordinary threat and the declaration of a national emergency to deal with it. Section 1702 grants the President authority to investigate, regulate, or prohibit transactions in foreign exchange, transfers of credit, and payments, and to investigate, block during the pendency of an investigation, regulate, or prohibit the acquisition, holding, use, or transfer of any property in which any foreign country or a national thereof has an interest. Section 1703 requires consultation with the Congress and periodic reports. Section 1704 authorizes the President to issue regulations to carry out the granted authorities. Section 1705 sets the penalties, with civil penalties up to 250,000 dollars per violation and criminal penalties of fines up to 1,000,000 dollars and imprisonment up to 20 years. Section 1706 preserves certain pre-existing authorities and obligations. Section 1707 addresses multinational economic embargoes against governments in armed conflict. Section 1708 authorizes actions to address economic or industrial espionage in cyberspace. The Act is the foundational statute for United States sanctions authority short of a state of war.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-iija-grid-modernisation-2021",
    "title": "Infrastructure Investment and Jobs Act (IIJA) - Division D, Title I, Part 4: Grid Infrastructure and Resilience; and Title IV: Energy",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-11-15",
    "bluf": "The Infrastructure Investment and Jobs Act (IIJA) allocates over $65 billion in federal funding through the Department of Energy (DOE) for electric utilities, grid operators, and states to enhance grid resilience, deploy modern technologies, improve cybersecurity, and build out transmission capacity. Key provisions in Division D, Title I, Part 4 (Sections 40101-40125) establish grant programs for preventing outages, hardening the grid, and deploying smart grid technologies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-161r1-csrm-practices"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-il-aivea-2019",
    "title": "Illinois Artificial Intelligence Video Interview Act 2019 (AIVEA)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Illinois AIVEA effective January 1, 2020 requires employers to notify job applicants before using AI to evaluate recorded video interviews, disclose the general types of AI features used in the evaluation, obtain applicant consent, limit video access to necessary parties, and destroy videos within 30 days of an applicant's deletion request.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-il-aivea-2019.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-il-bipa-2008",
    "title": "US Illinois Biometric Information Privacy Act 2008",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Illinois Biometric Information Privacy Act requires written consent and a public retention policy before collecting biometric identifiers or biometric information, prohibits sale or profit from biometric data, mandates destruction within three years of last interaction, and provides a private right of action with statutory damages of USD 1,000 per negligent or USD 5,000 per intentional violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-il-bipa-2008.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-il-bipa-amendment-2023",
    "title": "Illinois Biometric Information Privacy Act Amendment (SB 2979, Public Act 103-0769)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Illinois SB 2979 (Public Act 103-0769), signed August 2, 2024 by Governor J.B. Pritzker and effective immediately, limits BIPA private right of action claims so that repeated collection or disclosure of the same biometric identifier constitutes a single violation for which an aggrieved person is entitled to at most one recovery, significantly reducing per-person litigation exposure under the Illinois Biometric Information Privacy Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-il-bipa-amendment-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-il-bipa-2008"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-illinois-ai-video-interview-act-amendments",
    "title": "Illinois Artificial Intelligence Video Interview Act and 2023 Amendments - Compliance Obligations for AI-Driven Employment Screening, Biometric Data Governance in Hiring, and Candidate Consent Requirements",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations under the Illinois AI Video Interview Act, focusing on candidate consent, transparency in AI-driven hiring tools, and biometric data governance, with overlapping requirements from the EU AI Act 2024 (Regulation (EU) 2024/1689, Article 6 on high-risk AI systems).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-illinois-bipa-biometric-information-privacy",
    "title": "Illinois Biometric Information Privacy Act (740 ILCS 14/15) - Section 15: Written Policy, Retention Schedule, Informed Consent, and Prohibition on Profiting",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Illinois Biometric Information Privacy Act (BIPA) requires private entities to develop a publicly available written policy establishing a data retention schedule and destruction guidelines for biometric information. Per Section 15(b), entities must obtain a written release from an individual before collecting, capturing, purchasing, or otherwise obtaining their biometric identifiers or information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "california-ccpa-v2",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-illinois-sports-wagering-act-2019",
    "title": "Illinois Sports Wagering Act 2019 - In-Person and Online Sports Betting Licensing",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Illinois sports betting operators must hold a master sports wagering licence from the Illinois Gaming Board (IGB). The Sports Wagering Act 2019 (PA 101-0031) requires in-person registration for online accounts (requirement later removed by IGB waiver extended through 2022 and then permanently removed). Tax rate is 15% on adjusted gross sports wagering receipts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "igb_regulations",
        "uigea",
        "murphy_v_ncaa",
        "illinois_gaming_act",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
      "us-uigea-2006-unlawful-internet-gambling",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-immigration-and-nationality-act",
    "title": "US Immigration and Nationality Act (8 USC ch 12): Employment Verification and Immigration Control",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Immigration and Nationality Act (8 U.S.C. ch. 12) is the comprehensive US immigration statute, administered by the Department of Homeland Security through U.S. Citizenship and Immigration Services and Immigration and Customs Enforcement, with the Department of State and the Department of Justice. Section 1101 provides the definitions. Section 1182 sets the grounds of inadmissibility and section 1227 the grounds of deportability. Section 1324 makes it an offense to bring in or harbor aliens unlawfully. Of central importance to employers, section 1324a makes it unlawful to knowingly hire, recruit or refer for a fee an unauthorized alien, or to continue to employ a person known to be unauthorized, and requires every employer to verify employment eligibility through the I-9 process by examining identity and authorization documents and retaining the records for inspection. Civil penalties for knowingly employing an unauthorized worker range from 250 to 10,000 dollars per worker depending on prior violations, paperwork violations carry penalties of 100 to 1,000 dollars per individual, and a pattern or practice of violations carries criminal penalties of up to 3,000 dollars per alien and imprisonment for up to 6 months. Section 1324b prohibits unfair immigration-related employment practices, including citizenship status and national origin discrimination and document abuse. The Act is the legal foundation for US work authorization compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-immigration-nationality-act-1952-uscis",
    "title": "US Immigration and Nationality Act 1952 - USCIS, CBP and ICE Enforcement Framework",
    "domain": "Immigration & Border Control",
    "version": "5.2",
    "last_updated": "2026-05-10",
    "bluf": "The Immigration and Nationality Act (INA, 8 USC ch.12) is the foundational US immigration statute, establishing the legal bases for all visa categories, grounds of inadmissibility (8 USC 1182), deportation (8 USC 1227), and the naturalization process. Administration is split among USCIS (benefits), CBP (border inspection), and ICE (interior enforcement). INA s.274 (8 USC 1324) criminalises alien smuggling with penalties up to life imprisonment where death results. The H-1B specialty occupation visa cap is fixed at 65,000 per year (plus 20,000 for US advanced degree holders) under INA 214(g). Employers of unauthorized aliens face civil fines of USD 2,203-USD 22,016 per violation under 8 USC 1324a. The Diversity Visa Lottery (8 USC 1153(c)) allocates 50,000 immigrant visas annually to underrepresented countries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "unhcr",
        "icao_doc",
        "five_eyes",
        "fatf_recommendation",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric",
      "us-e-verify-i9-employment-eligibility-verification"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-immigration-nationality-act-8-usc-ch12",
    "title": "United States Immigration and Nationality Act (Title 8 USC Chapter 12): Definitions, Worldwide Immigration Levels, Visa Allocation, Asylum, Inadmissibility, Deportability, Removal Proceedings, and Improper Entry",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Immigration and Nationality Act, codified at Title 8 of the United States Code, Chapter 12, is the foundational federal statute governing the admission, presence, removal, and naturalization of aliens in the United States and is administered by the Department of Homeland Security, the Department of Justice, and the Department of State. Immigration and Nationality Act, 8 U.S.C. 1101 contains the definitions, including that the term alien means any person not a citizen or national of the United States. Subchapter I (sections 1101 through 1107) contains general provisions. Subchapter II (sections 1151 through 1372) contains the immigration provisions including Immigration and Nationality Act, 8 U.S.C. 1151 on the worldwide level of immigration, Immigration and Nationality Act, 8 U.S.C. 1153 on the allocation of immigrant visas, Immigration and Nationality Act, 8 U.S.C. 1158 on asylum, Immigration and Nationality Act, 8 U.S.C. 1182 listing classes of aliens inadmissible to the United States, Immigration and Nationality Act, 8 U.S.C. 1227 listing classes of aliens deportable from the United States, Immigration and Nationality Act, 8 U.S.C. 1229a establishing removal proceedings before an immigration judge, Immigration and Nationality Act, 8 U.S.C. 1324 on bringing in and harboring certain aliens, and Immigration and Nationality Act, 8 U.S.C. 1325 on improper entry by an alien. Subchapter III (sections 1401 through 1504) contains the nationality and naturalization provisions. Subchapter IV (sections 1521 through 1524) contains refugee assistance provisions. Subchapter V (sections 1531 through 1537) contains alien terrorist removal procedures. The Act is the controlling federal instrument for United States immigration and nationality compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-import-milk-act",
    "title": "US Import Milk Act (21 USC ch 4): Permit Requirement for Importing Milk and Cream",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Import Milk Act (21 U.S.C. ch. 4, subchapter IV, sections 141 to 149) regulates the importation of milk and cream into the United States to protect public health, administered by the Secretary of Health and Human Services through the Food and Drug Administration. Section 141 prohibits the importation of milk and cream into the United States unless the person importing it holds a valid permit issued by the Secretary. Section 142 sets the circumstances in which milk or cream is unfit for importation, including requirements relating to the health and examination of the cows producing it, tuberculin testing, the sanitary conditions and scoring of the dairies and processing facilities, bacterial counts, and temperature limits. Section 143 provides for inspection of dairies and plants and allows the Secretary to accept a certified statement of a duly authorized foreign official in lieu of inspection and to waive requirements. Section 144 makes it unlawful for any person in the United States to receive milk or cream imported other than in accordance with the subchapter, and section 145 makes a violation punishable by a fine of not less than 50 dollars nor more than 2,000 dollars, or imprisonment for not more than one year. Section 146 authorizes appropriations of 50,000 dollars per annum. The Act is the federal control on the safety of imported dairy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-in-cdpa-2023",
    "title": "US Indiana Consumer Data Protection Act 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Indiana Consumer Data Protection Act grants consumers rights to access, correct, delete, and port personal data and to opt out of targeted advertising, sale, and profiling, requires opt-in consent for sensitive data, mandates data protection assessments for high-risk processing, and authorises the Indiana Attorney General to impose civil penalties of up to USD 7,500 per violation with a mandatory 30-day cure period effective January 1, 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-in-cdpa-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ccpa-cpra-2023-marketing-rights"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ina-adjustment-of-status-8usc1255",
    "title": "US INA Adjustment of Status (8 USC 1255): Becoming a Lawful Permanent Resident from Within the US",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 245 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1255, allows certain aliens already in the United States to adjust status to that of a lawful permanent resident without leaving the country, and is administered by US Citizenship and Immigration Services (USCIS) and, in removal proceedings, the Executive Office for Immigration Review. Section 1255(a) sets the core rule: the status of an alien who was inspected and admitted or paroled into the United States may be adjusted by the Attorney General (now the Secretary of Homeland Security), in his discretion and under such regulations as he may prescribe, to that of an alien lawfully admitted for permanent residence if (1) the alien makes an application for adjustment, (2) the alien is eligible to receive an immigrant visa and is admissible to the United States for permanent residence, and (3) an immigrant visa is immediately available to the alien at the time the application is filed. Section 1255(c) sets the principal bars to adjustment under subsection (a), which apply to alien crewmen, aliens (other than immediate relatives and certain others) who are in unlawful immigration status on the date of filing or who have failed to maintain continuously a lawful status, aliens admitted in transit without a visa, and aliens who have engaged in unauthorized employment. Section 1255(k) provides a limited exemption from certain of those bars for employment-based applicants who have been out of status for no more than an aggregate of 180 days. Section 1255(i) preserves, for a defined class, the ability of certain aliens who entered without inspection or are otherwise barred to adjust on payment of a sum of $1,000, where a qualifying petition or labor certification was filed on or before April 30, 2001 and the alien was physically present on December 21, 2000. The admissibility requirement incorporates the grounds of inadmissibility in 8 U.S.C. 1182(a), and visa availability is governed by the immigrant-visa allocation and priority-date system in 8 U.S.C. 1153. Adjustment is discretionary even where the statutory eligibility requirements are met.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-admission-of-nonimmigrants-8usc1184",
    "title": "US INA Admission of Nonimmigrants (8 USC 1184): Conditions, Presumption of Immigrant Status and Petitions",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 214 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1184, governs the admission of nonimmigrants, administered by the Department of Homeland Security (US Citizenship and Immigration Services and Customs and Border Protection) and the Department of State. Section 1184(a) authorizes the Secretary to prescribe by regulation the time for which, and the conditions under which, a nonimmigrant may be admitted, including the taking of bonds to ensure that the alien departs the United States at the expiration of the authorized period or upon failure to maintain the status under which admitted. Section 1184(b) sets a foundational evidentiary rule: every alien (other than specified categories) is presumed to be an immigrant until the alien establishes, to the satisfaction of the consular officer at the time of visa application and the immigration officer at the time of admission, that the alien is entitled to a nonimmigrant status. Section 1184(c) requires, for certain employment-based nonimmigrant classifications (such as the H, L, O and P categories), that the importing employer first file a petition that is approved before the visa is granted, containing the information the regulations prescribe. The section also sets numerical limits: section 1184(g) caps the H-1B classification at 65,000 per fiscal year (with an exemption for certain advanced-degree holders) and the H-2B classification at 66,000 per fiscal year, and section 1184(f) addresses restrictions on alien crewmen during a labor dispute. Together these provisions establish that nonimmigrant admission is conditional and time-limited, that the burden rests on the alien to overcome the presumption of immigrant intent, and that employer-sponsored categories require an approved petition and may be subject to annual caps.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-apprehension-detention-8usc1226",
    "title": "US INA Apprehension and Detention of Aliens (8 USC 1226): Discretionary Bond and Mandatory Detention",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 236 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1226, governs the apprehension and detention of aliens pending a decision on whether they are to be removed from the United States, and is administered by the Department of Homeland Security (Immigration and Customs Enforcement) with custody determinations reviewable by immigration judges (except as limited by statute). Section 1226(a) provides that, on a warrant issued by the Attorney General (now the Secretary of Homeland Security), an alien may be arrested and detained pending a decision on whether the alien is to be removed; pending that decision, the official may continue to detain the alien, or may release the alien on bond of at least $1,500 with security approved by, and containing conditions prescribed by, the Attorney General, or on conditional parole, but may not provide the alien with work authorization unless the alien is lawfully admitted for permanent residence or otherwise would be eligible. Section 1226(c) requires mandatory detention of criminal aliens: the Attorney General shall take into custody any alien who is inadmissible by reason of having committed an offense covered in 8 U.S.C. 1182(a)(2), or is deportable by reason of having committed an offense covered in the specified criminal and terrorism-related grounds of 8 U.S.C. 1227(a), when the alien is released from criminal custody, and may release such an alien only in narrow witness-protection circumstances. Section 1226(e) limits judicial review: no court may set aside any action or decision by the Attorney General under this section regarding the detention or release of any alien or the grant, revocation or denial of bond or parole. The detention authority in section 1226 (during the pendency of removal proceedings) is distinct from detention after a final order of removal under 8 U.S.C. 1231.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-asylum-8usc1158",
    "title": "US INA Asylum (8 USC 1158): Eligibility, One-Year Deadline and Mandatory Bars",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 208 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1158, governs asylum in the United States and is administered by US Citizenship and Immigration Services (affirmative claims) and the Executive Office for Immigration Review (defensive claims before immigration judges). Section 1158(a)(1) provides that any alien who is physically present in the United States or who arrives in the United States, irrespective of status, may apply for asylum. Section 1158(a)(2)(B) imposes the one-year filing deadline: the alien must demonstrate by clear and convincing evidence that the application was filed within one year after the date of the alien's arrival, subject to the changed-circumstances and extraordinary-circumstances exceptions in 1158(a)(2)(D); sections 1158(a)(2)(A) and (C) bar applications where the alien may be removed to a safe third country or has previously been denied asylum. Section 1158(b)(1)(A) sets the conditions for granting asylum: the applicant must be a refugee within the meaning of 8 U.S.C. 1101(a)(42)(A), and section 1158(b)(1)(B) places the burden of proof on the applicant and requires that race, religion, nationality, membership in a particular social group, or political opinion was or will be at least one central reason for the persecution, with credibility and, where requested, corroboration considered. Section 1158(b)(2)(A) sets the mandatory bars: asylum may not be granted to an applicant who ordered, incited, assisted or otherwise participated in the persecution of others on a protected ground; who was convicted of a particularly serious crime and is a danger to the community; who committed a serious nonpolitical crime outside the United States; who is a danger to the security of the United States; who is described in the terrorism-related grounds; or who was firmly resettled in another country before arriving. Section 1158(c) governs asylum status, employment authorization and termination, and section 1158(d)(6) provides that an alien who knowingly files a frivolous asylum application is permanently ineligible for any benefits under the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-bringing-in-harboring-aliens-8usc1324",
    "title": "US INA Bringing In and Harboring Aliens (8 USC 1324): Smuggling, Transporting and Harboring Offences",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 274 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1324, is the principal federal criminal statute against alien smuggling, transporting, harboring, and inducing unlawful presence, enforced by the Department of Homeland Security (Immigration and Customs Enforcement) and the Department of Justice. Section 1324(a)(1)(A) sets out the prohibited acts: clause (i) makes it an offence to bring or attempt to bring an alien to the United States at a place other than a designated port of entry, knowing or in reckless disregard of the fact that the alien has not received prior official authorization to come to, enter, or reside in the United States; clause (ii) prohibits transporting or moving, within the United States, an alien known to be present unlawfully, in furtherance of that unlawful presence; clause (iii) prohibits concealing, harboring, or shielding from detection such an alien in any place, including any building or means of transportation; clause (iv) prohibits encouraging or inducing an alien to come to, enter, or reside in the United States knowing or in reckless disregard that it is or will be in violation of law; and clause (v) reaches conspiracy and aiding and abetting any of the preceding acts. Section 1324(a)(1)(B) sets the criminal penalties: a standard violation is punishable by a fine and imprisonment for not more than 5 years; a violation done for the purpose of commercial advantage or private financial gain (or a conspiracy) carries imprisonment for not more than 10 years; a violation causing serious bodily injury or placing life in jeopardy carries imprisonment for not more than 20 years; and a violation resulting in death is punishable by death or imprisonment for any term of years or for life. Section 1324(a)(2) separately penalizes bringing aliens in without prior authorization regardless of any later official action, with imprisonment ranges escalating from not less than 3 nor more than 10 years up to not less than 5 nor more than 15 years. This section is the core enforcement instrument for employers, carriers, and any party whose conduct could facilitate unlawful entry or presence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-cancellation-of-removal-8usc1229b",
    "title": "US INA Cancellation of Removal (8 USC 1229b): Relief for Permanent and Nonpermanent Residents",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 240A of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1229b, provides discretionary relief from removal known as cancellation of removal, adjudicated by immigration judges in the Executive Office for Immigration Review. Section 1229b(a) authorizes cancellation of removal for a lawful permanent resident who is inadmissible or deportable if the alien has been an alien lawfully admitted for permanent residence for not less than five years, has resided in the United States continuously for seven years after having been admitted in any status, and has not been convicted of any aggravated felony. Section 1229b(b)(1) authorizes cancellation of removal, and adjustment to lawful permanent resident status, for a nonpermanent resident who is inadmissible or deportable if the alien has been physically present in the United States for a continuous period of not less than ten years immediately preceding the application, has been a person of good moral character during that period, has not been convicted of an offense under the specified inadmissibility and deportability provisions, and establishes that removal would result in exceptional and extremely unusual hardship to the alien's spouse, parent or child who is a citizen of the United States or a lawful permanent resident. Section 1229b(b)(2) provides a special rule for battered spouses and children. Section 1229b(d) sets the stop-time rule: any period of continuous residence or continuous physical presence is deemed to end when the alien is served a notice to appear, or when the alien commits a specified offense that renders the alien inadmissible or removable, whichever is earliest. Section 1229b(e) limits the annual number of cancellation grants for nonpermanent residents. Cancellation is discretionary: meeting the statutory requirements establishes eligibility, but the immigration judge must still grant relief as a matter of discretion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-conditional-permanent-resident-8usc1186a",
    "title": "US INA Conditional Permanent Resident Status for Alien Spouses (8 USC 1186a): Removal of Conditions and Waivers",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 216 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1186a, places permanent resident status obtained through a recent marriage on a conditional basis and sets the procedure for removing those conditions, administered by US Citizenship and Immigration Services. Section 1186a(a) provides that an alien spouse and any alien sons or daughters obtaining permanent residence by reason of a marriage less than two years old at admission obtain that status on a conditional basis, subject to the section. Section 1186a(b) authorizes the Secretary to terminate the conditional status before the second anniversary if the qualifying marriage was entered into for the purpose of procuring the alien's admission as an immigrant or if a fee or other consideration (other than to an attorney for assistance) was given for filing the petition. Section 1186a(c) requires the alien spouse and the petitioning spouse jointly to submit a petition to remove the conditions and to appear for a personal interview, and provides under section 1186a(c)(2) for automatic termination of status where the petition is not filed or the interview is missed without good cause. Section 1186a(c)(4) authorizes the Secretary to waive the joint-petition requirement on a showing of extreme hardship, a good-faith marriage that was terminated other than through the alien's fault, or battery or extreme cruelty in the marriage. Section 1186a(d) specifies the contents of the petition and fixes the filing window during the 90-day period before the second anniversary of obtaining conditional status. The section is the mechanism that tests the bona fides of a marriage-based green card and converts conditional status into unconditional permanent residence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-definitions-8usc1101",
    "title": "US INA Definitions (8 USC 1101): Alien, Immigrant, Nonimmigrant, LPR, Refugee and Aggravated Felony",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 101 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1101, contains the definitions that govern the entire US immigration and nationality system, and the correct classification of a person and a conviction under these definitions controls almost every downstream determination of admissibility, removability and eligibility for relief. Section 1101(a)(3) defines 'alien' as any person not a citizen or national of the United States. Section 1101(a)(13)(A) defines 'admission' and 'admitted' as the lawful entry of the alien into the United States after inspection and authorization by an immigration officer, which is the line that separates the inadmissibility framework (8 U.S.C. 1182) from the deportability framework (8 U.S.C. 1227). Section 1101(a)(15) defines 'immigrant' as every alien except those within the enumerated classes of nonimmigrant aliens (the A through V visa categories, including visitors, students and temporary workers). Section 1101(a)(20) defines 'lawfully admitted for permanent residence', section 1101(a)(21)-(22) define 'national' and 'national of the United States', and section 1101(a)(42) defines 'refugee' as a person who is outside the country of nationality and is unable or unwilling to return because of persecution or a well-founded fear of persecution on account of race, religion, nationality, membership in a particular social group, or political opinion. Section 1101(a)(43) defines 'aggravated felony' across a long list of offenses (beginning with murder, rape, or sexual abuse of a minor, and illicit trafficking in a controlled substance), a classification that carries the most severe immigration consequences and bars most relief. Section 1101(a)(48) defines 'conviction' for immigration purposes, capturing certain dispositions even without a formal judgment. These definitions are interpretive law: they do not themselves impose duties or penalties, but their correct application is dispositive of status and consequences throughout the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-deportability-grounds",
    "title": "US INA Classes of Deportable Aliens (8 USC 1227): Grounds of Removability",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 237 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1227, sets out the classes of aliens, present in the United States after admission, who are deportable (removable), charged by the Department of Homeland Security and adjudicated by immigration judges in removal proceedings under 8 U.S.C. 1229a. Section 1227(a) groups the grounds: (1) inadmissibility at the time of entry or adjustment and status violations (including aliens inadmissible at entry, present in violation of the Act, nonimmigrant status violators, those who failed to maintain conditional permanent residence, smugglers, and persons who committed marriage fraud); (2) criminal offenses (crimes involving moral turpitude, multiple criminal convictions, aggravated felonies, controlled substance offenses, certain firearms offenses, and crimes of domestic violence, stalking, and child abuse); (3) failure to register and falsification of documents (change-of-address and registration violations, document fraud, and false claims to US citizenship); (4) security and related grounds (espionage, sabotage, terrorist activities, adverse foreign policy, participation in Nazi persecution, genocide, torture or extrajudicial killing, and recruitment of child soldiers); (5) public charge (becoming a public charge within five years of entry from causes not affirmatively shown to have arisen since entry); and (6) unlawful voters. The provision includes limited waivers, including for certain battered spouses and children. Deportability is distinct from inadmissibility (8 U.S.C. 1182): the inadmissibility grounds apply to those seeking admission, while the deportability grounds apply to those already admitted. Both interact with the relief-from-removal provisions (such as cancellation of removal and asylum).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-detention-removal-after-final-order-8usc1231",
    "title": "US INA Detention and Removal After a Final Order (8 USC 1231): Removal Period and Withholding",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 241 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1231, governs the detention and removal of aliens who have been ordered removed, administered by the Department of Homeland Security (Immigration and Customs Enforcement). Section 1231(a)(1) sets the removal period: when an alien is ordered removed, the Attorney General (now the Secretary of Homeland Security) shall remove the alien from the United States within a period of 90 days, beginning on the latest of the date the order becomes administratively final, the date of any reviewing court's final order if the removal is stayed, or the date the alien is released from non-immigration detention. Section 1231(a)(2) requires detention during the removal period and provides that under no circumstance shall the alien be released if found inadmissible under 8 U.S.C. 1182(a)(2) (criminal grounds) or 1182(a)(3)(B) (terrorism grounds). Section 1231(a)(3) provides for supervision of aliens not removed within the removal period, and section 1231(a)(6) authorizes continued detention beyond the removal period for aliens who are inadmissible, removable on criminal or security grounds, or determined to be a risk to the community or unlikely to comply with the removal order. Section 1231(b) sets the countries to which an alien may be removed, and section 1231(b)(3) sets the central protection (withholding of removal): the Attorney General may not remove an alien to a country if the Attorney General decides that the alien's life or freedom would be threatened in that country because of the alien's race, religion, nationality, membership in a particular social group, or political opinion, subject to statutory exceptions (such as for persecutors and those convicted of particularly serious crimes). The detention authority after a final order under this section is distinct from the pre-order detention authority under 8 U.S.C. 1226.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-documentary-requirements-8usc1181",
    "title": "US INA Admission of Immigrants and Documentary Requirements (8 USC 1181): Immigrant Visa, Passport, Returning Residents and the Refugee Exception",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 211 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1181, sets the documentary requirements for the admission of immigrants into the United States, administered by US Customs and Border Protection at the port of entry and by US Citizenship and Immigration Services and the Department of State. Section 1181(a) provides that no immigrant shall be admitted into the United States unless at the time of application for admission the immigrant has a valid unexpired immigrant visa, or was born after the issuance of such a visa to an accompanying parent, and presents a valid unexpired passport or other suitable travel document; the documentary requirement is the gateway condition for lawful immigrant admission. Section 1181(b) provides for returning resident immigrants, defined in section 1101(a)(27)(A), who are otherwise admissible and who may be readmitted by the Attorney General in his discretion without being required to obtain a passport, immigrant visa, reentry permit or other documentation, the statutory basis for the readmission of lawful permanent residents and the role of the reentry permit for extended absences. Section 1181(c) provides that the documentary requirements of subsection (a) do not apply to an alien whom the Attorney General admits to the United States under section 1157, the refugee admission provision, recognising that refugees are admitted through a separate statutory channel rather than on an immigrant visa. The section is the documentary backbone of immigrant admission and the provision that distinguishes new immigrants, returning residents and refugees at the border.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-employment-verification",
    "title": "US INA Employment Verification and Employer Sanctions (8 USC 1324a): I-9, Knowing-Hire Prohibition and Penalties",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 274A of the Immigration and Nationality Act, codified at 8 U.S.C. 1324a, makes it unlawful for an employer to employ unauthorized aliens and establishes the federal employment eligibility verification system, enforced by US Immigration and Customs Enforcement (ICE/Homeland Security Investigations) with the Office of the Chief Administrative Hearing Officer adjudicating cases. It is unlawful for a person or entity to hire, or to recruit or refer for a fee, an alien knowing the alien is unauthorized for that employment, and to continue to employ an alien knowing the alien is or has become unauthorized. Every employer must verify the identity and employment authorization of each employee by examining specified documents and completing the verification form (Form I-9): a document is sufficient if it reasonably appears on its face to be genuine. An employer that has complied in good faith with the verification requirement has an affirmative defense to a knowing-hire charge. Section 1324a(b)(5) and (d)(2) restrict use of the verification system and the I-9 to enforcement of the immigration laws and specified criminal provisions. Section 1324a(e) sets civil penalties for hiring violations: $250-$2,000 per unauthorized worker for a first order, $2,000-$5,000 for a second, and $3,000-$10,000 for subsequent orders; paperwork (verification) violations carry $100-$1,000 per individual. Section 1324a(f) makes a pattern or practice of knowing violations a criminal offence punishable by a fine of up to $3,000 per unauthorized alien and up to six months' imprisonment. Section 1324b (a related provision) prohibits unfair immigration-related employment discrimination, so verification must be applied without document abuse or national-origin or citizenship-status discrimination. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-expedited-removal-8usc1225",
    "title": "US INA Inspection and Expedited Removal (8 USC 1225): Applicants for Admission, Credible Fear and Detention",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 235 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1225, governs the inspection of aliens seeking to enter the United States and the expedited removal of certain inadmissible arriving aliens, and is administered by the Department of Homeland Security (Customs and Border Protection and Immigration and Customs Enforcement) with credible-fear screening by USCIS asylum officers. Section 1225(a) provides that an alien present in the United States who has not been admitted, or who arrives in the United States, is deemed an applicant for admission, and that all applicants for admission, including crewmembers, shall be inspected by immigration officers. Section 1225(b)(1) authorizes expedited removal: if an examining officer determines that an arriving alien is inadmissible under 8 U.S.C. 1182(a)(6)(C) (fraud or material misrepresentation) or 1182(a)(7) (lack of valid entry documents), the officer shall order the alien removed without further hearing or review unless the alien indicates either an intention to apply for asylum or a fear of persecution; in that case the officer shall refer the alien for an interview by an asylum officer, and an alien found to have a credible fear of persecution shall be detained for further consideration of the application for asylum. Section 1225(b)(2) provides that, in the case of other applicants who are not clearly and beyond a doubt entitled to be admitted, the alien shall be detained for a proceeding under 8 U.S.C. 1229a before an immigration judge. The statute requires that aliens be detained pending a final determination in these processes. Credible-fear referrals connect this section to the asylum framework in 8 U.S.C. 1158, and expedited-removal determinations are subject to only the limited review provided in 8 U.S.C. 1252(e).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-h2a-agricultural-workers-8usc1188",
    "title": "US INA Admission of Temporary H-2A Agricultural Workers (8 USC 1188): Labor Certification, Recruitment and the 50-Percent Rule",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 218 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1188, governs the admission of temporary H-2A agricultural workers and conditions it on a labor certification from the Secretary of Labor, administered by the Department of Labor (certification), US Citizenship and Immigration Services (petition) and the Department of State (visa). Section 1188(a) provides that an H-2A petition may not be approved unless the petitioner has applied to the Secretary of Labor for a certification that (A) there are not sufficient workers who are able, willing, and qualified, and who will be available at the time and place needed, to perform the labor or services, and (B) the employment of the alien will not adversely affect the wages and working conditions of workers in the United States similarly employed. Section 1188(b) sets out grounds on which certification may be denied, including a strike or lockout in the course of a labor dispute, a prior material violation by the employer, failure to provide the required workers' compensation insurance, and failure to engage in positive recruitment within a multi-state region. Section 1188(c) governs the application process and its strict timelines: the application is filed not more than 45 days before the first date the employer requires the workers; the employer is notified of any deficiencies within seven days of filing; and the Secretary issues the certification not later than 30 days before the date the labor is first required. The same provisions impose the 50-percent rule (the obligation to hire qualified US workers who apply until 50 percent of the work-contract period has elapsed) and positive-recruitment duties, and section 1188(e) requires expedited determinations, in no case later than 72 hours, where certification was denied on worker-availability grounds. The section is the gateway control that ties seasonal agricultural immigration to the protection of the domestic farm labor market.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-immigrant-visa-allocation-8usc1153",
    "title": "US INA Allocation of Immigrant Visas (8 USC 1153): Family, Employment and Diversity Preferences",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 203 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1153, allocates immigrant visas among the preference categories, administered by US Citizenship and Immigration Services (petitions) and the Department of State (visa issuance and the monthly Visa Bulletin). Section 1153(a) sets the family-sponsored preferences within the worldwide level: the first preference covers unmarried sons and daughters of citizens (not to exceed 23,400 plus certain spillover); the second preference covers spouses, children, and unmarried sons and daughters of permanent resident aliens (not to exceed 114,200, divided between the 2A and 2B subcategories); the third preference covers married sons and married daughters of citizens (not to exceed 23,400); and the fourth preference covers brothers and sisters of citizens (not to exceed 65,000). Section 1153(b) sets the employment-based preferences: the first preference covers priority workers (aliens of extraordinary ability, outstanding professors and researchers, and certain multinational executives and managers); the second preference covers members of the professions holding advanced degrees or aliens of exceptional ability; the third preference covers skilled workers, professionals, and other workers; the fourth preference covers certain special immigrants (not to exceed 7.1 percent of the worldwide level); and the fifth preference covers employment creation (the EB-5 investor category) through new commercial enterprises that create the required jobs. Section 1153(c) provides for diversity immigrants selected from low-admission countries, who must have at least a high school education or its equivalent or qualifying work experience. Section 1153(e) sets the order of consideration: within each preference, visas are issued to eligible immigrants in the order in which a petition is filed, except that diversity visas are issued in a strictly random order. Correctly classifying a beneficiary into the right preference category determines eligibility, the controlling priority date, and the wait under the per-category and per-country limits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-improper-entry-and-reentry",
    "title": "US INA Improper Entry and Reentry of Removed Aliens (8 USC 1325-1326): Offences and Penalties",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Sections 275 and 276 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1325 and 1326, create the principal federal criminal offences for unlawful entry and reentry into the United States, enforced by the Department of Homeland Security (CBP and ICE) and prosecuted by the Department of Justice. Section 1325(a) makes it an offence for any alien to (1) enter or attempt to enter at any time or place other than as designated by immigration officers, (2) elude examination or inspection by immigration officers, or (3) attempt to enter or obtain entry by a wilfully false or misleading representation or the wilful concealment of a material fact; a first offence is punishable by a fine under title 18 or imprisonment of not more than six months, or both, and a subsequent offence by a fine or imprisonment of not more than two years, or both. Section 1325(b) imposes a civil penalty of at least $50 and not more than $250 for each entry or attempted entry at an improper time or place, doubled for a subsequent violation, in addition to any criminal penalty. Section 1326(a) makes it an offence for an alien who has been denied admission, excluded, deported or removed to enter, attempt to enter, or be found in the United States without the Attorney General's consent, punishable by a fine under title 18 or imprisonment of not more than two years, or both. Section 1326(b) sets enhanced maximum sentences where the prior removal followed conviction for three or more misdemeanours involving drugs or crimes against the person, or a felony (up to ten years), or an aggravated felony (up to twenty years). The marriage-fraud and entry provisions interact with the inadmissibility grounds in 8 U.S.C. 1182 and the removal framework in 8 U.S.C. 1229a.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-inadmissibility-grounds",
    "title": "US INA Grounds of Inadmissibility (8 USC 1182): Classes of Aliens Ineligible for Admission and Waivers",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 212 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1182, sets out the classes of aliens who are ineligible to receive visas and ineligible to be admitted to the United States, applied by the Department of State (visa issuance) and the Department of Homeland Security (admission and adjustment). Section 1182(a) groups the grounds of inadmissibility: (1) health-related grounds (communicable diseases of public health significance, missing required vaccinations, physical or mental disorders with associated harmful behavior, and drug abuse or addiction); (2) criminal and related grounds (crimes involving moral turpitude, controlled substance violations, multiple convictions, drug trafficking, prostitution, and money laundering); (3) security and related grounds (espionage, sabotage, terrorist activities, and adverse foreign policy consequences); (4) public charge (likely to become primarily dependent on public benefits); (5) labor certification and qualifications (certain workers require Department of Labor certification); (6) illegal entrants and immigration violators (those present without admission, misrepresentation, stowaways, smugglers, and student-visa abusers); (7) documentation requirements (immigrants without valid visas and travel documents, and nonimmigrants without valid passports and visas); (8) ineligibility for citizenship (including draft evaders); (9) aliens previously removed and those unlawfully present (3-year, 10-year and permanent bars); and (10) miscellaneous grounds (polygamists, international child abductors, unlawful voters, and former citizens who renounced to avoid tax). Many grounds are subject to waivers exercised by the Attorney General, Secretary of Homeland Security or Secretary of State, though certain grounds (notably some terrorism grounds) have limited or no waiver. The grounds interact with the removal framework (8 U.S.C. 1229a) and the deportability grounds (8 U.S.C. 1227).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-judicial-review-removal-8usc1252",
    "title": "US INA Judicial Review of Orders of Removal (8 USC 1252): Petition for Review and Jurisdictional Limits",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 242 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1252, governs judicial review of orders of removal and is the central provision determining when, where, and how a removal order may be challenged in the federal courts. Section 1252(a)(1) provides for judicial review of a final order of removal under the framework of chapter 158 of title 28 (the Hobbs Act review provisions). Section 1252(a)(2) carves out matters not subject to judicial review: subparagraph (A) restricts review of expedited-removal determinations under 8 U.S.C. 1225(b)(1), subparagraph (B) bars review of most discretionary relief decisions, and subparagraph (C) bars review of final orders against aliens removable for specified criminal offences, while subparagraph (D) preserves review of constitutional claims and questions of law raised in a petition for review. Section 1252(a)(5) makes a petition for review filed with the appropriate court of appeals the sole and exclusive means for judicial review of a final order of removal, displacing habeas corpus for that purpose. Section 1252(b) sets the requirements for review: section 1252(b)(1) requires that the petition for review be filed not later than 30 days after the date of the final order of removal; section 1252(b)(2) fixes venue in the court of appeals for the judicial circuit in which the immigration judge completed the proceedings; and section 1252(b)(9) consolidates all questions of law and fact arising from the action to remove an alien into review of the final order. Section 1252(d) requires exhaustion of all administrative remedies available to the alien as of right before a court may review a final order. Section 1252(e) provides the limited habeas review available for expedited-removal determinations, and section 1252(g) limits jurisdiction over certain decisions and actions to commence proceedings, adjudicate cases, or execute removal orders. The 30-day deadline and the exclusive petition-for-review channel are the two most consequential procedural rules for any party contesting removal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-loss-of-nationality-8usc1481",
    "title": "US INA Loss of Nationality by Native-Born or Naturalized Citizen (8 USC 1481): Expatriating Acts, Voluntariness and Burden of Proof",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 349 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1481, sets out the acts by which a national of the United States, whether by birth or naturalization, loses nationality, and the standard for proving that loss, administered by the Department of State. Section 1481(a) provides that a person shall lose nationality by voluntarily performing any of the listed acts with the intention of relinquishing United States nationality: (1) obtaining naturalization in a foreign state on his own application after the age of eighteen; (2) taking an oath or making a formal declaration of allegiance to a foreign state after the age of eighteen; (3) entering or serving in the armed forces of a foreign state engaged in hostilities against the United States, or serving as a commissioned or non-commissioned officer; (4) accepting, serving in, or performing the duties of an office, post or employment under the government of a foreign state, under stated nationality and oath conditions; (5) making a formal renunciation of nationality before a United States diplomatic or consular officer abroad; (6) making, in the United States in time of war and with Attorney General approval, a formal written renunciation; and (7) committing an act of treason, or attempting by force to overthrow or bearing arms against the United States, on conviction. Section 1481(b) places the burden of proving loss on the party claiming it, to be established by a preponderance of the evidence, and provides that an expatriating act is presumed voluntary, a presumption rebuttable on a preponderance of the evidence that the act was not done voluntarily. The section is the controlling rule on expatriation and its high evidentiary threshold, shaped by the constitutional requirement of a specific intent to relinquish citizenship.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-nationality-at-birth-8usc1401",
    "title": "US INA Nationals and Citizens at Birth (8 USC 1401): Birthright and Citizenship by Descent",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 301 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1401, sets out the categories of persons who are nationals and citizens of the United States at birth, administered for documentation purposes by the Department of State (passports and Consular Reports of Birth Abroad) and US Citizenship and Immigration Services. Section 1401(a) provides the foundational rule of birthright citizenship (jus soli): a person born in the United States, and subject to the jurisdiction thereof, is a national and citizen of the United States at birth. Section 1401(b) confers citizenship on a person born in the United States to a member of an Indian, Eskimo, Aleutian or other aboriginal tribe. The remaining provisions set out citizenship by descent (jus sanguinis) for persons born outside the United States, each with its own parentage and physical-presence conditions: section 1401(c) covers a person born outside the United States to two citizen parents, one of whom had a prior residence in the United States; section 1401(d) covers a person born outside the United States to one citizen parent and one parent who is a national but not a citizen, where the citizen parent was physically present in the United States or an outlying possession for a continuous period of one year prior to the birth; section 1401(e) covers a person born in an outlying possession to a citizen parent who had the requisite prior presence; and section 1401(g) covers a person born outside the United States to one citizen parent and one alien parent, where the citizen parent was physically present in the United States or its outlying possessions for a period or periods totaling not less than five years, at least two of which were after attaining the age of fourteen years (with allowances for certain periods of US government or armed forces service abroad). Related provisions govern persons who are nationals but not citizens at birth (8 U.S.C. 1408) and the transmission of citizenship to children born out of wedlock (8 U.S.C. 1409). Correctly applying these categories determines, from the moment of birth, whether a person is a US citizen.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-naturalization-8usc1427",
    "title": "US INA Naturalization Requirements (8 USC 1427): Residence, Good Moral Character and Attachment to the Constitution",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 316 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1427, sets the general requirements for naturalization as a US citizen, administered by US Citizenship and Immigration Services (USCIS). Section 1427(a) provides that no person shall be naturalized unless the applicant has resided continuously, after being lawfully admitted for permanent residence, within the United States for at least five years immediately preceding the application; has been physically present in the United States for periods totaling at least half of that time; has resided within the State or Service district in which the application was filed for at least three months; and, during all the periods referred to in the subsection, has been and still is a person of good moral character, attached to the principles of the Constitution of the United States, and well disposed to the good order and happiness of the United States. Section 1427(b) addresses the effect of absences on the continuity of residence: an absence of more than six months but less than one year during the five-year period breaks the continuity of residence unless the applicant establishes that residence was not in fact abandoned, and an absence of one year or more generally breaks the continuity of residence, subject to limited statutory exceptions. Section 1427(c) requires the residence and physical presence to continue to the time of admission to citizenship, and section 1427(e) allows the Service to consider the applicant's conduct and acts at any time prior to the statutory period in determining good moral character. Good moral character is further defined by 8 U.S.C. 1101(f). These requirements operate together with the English-language and civics requirements of 8 U.S.C. 1423, the application requirement of 8 U.S.C. 1445, and the oath of renunciation and allegiance under 8 U.S.C. 1448. Shorter residence periods apply to specific categories (such as spouses of citizens and certain members of the armed forces) under other sections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-naturalization-spouse-of-citizen-8usc1430",
    "title": "US INA Naturalization of the Spouse of a Citizen (8 USC 1430): The Three-Year Residence Rule, Marital Union and Spouses Stationed Abroad",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 319 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1430, provides the modified naturalization route for the spouse of a United States citizen and for certain spouses of citizens employed abroad, administered by US Citizenship and Immigration Services. Section 1430(a) allows a person whose spouse is a citizen of the United States to be naturalized on compliance with all the requirements of the naturalization subchapter except the five-year continuous-residence requirement of section 1427(a)(1): in its place, the applicant must have resided continuously in the United States for at least three years after lawful admission for permanent residence, and must have been living in marital union with the citizen spouse during the three-year period immediately preceding the date of filing the application, the spouse having been a United States citizen throughout that period. Section 1430(b) provides an expedited route for a person whose citizen spouse is regularly stationed abroad in qualifying employment (with the United States Government, certain American research institutions, recognised American firms engaged in foreign trade, certain public international organizations or certain religious denominations or interdenominational missions): such a person, if in the United States at the time of naturalization and declaring an intention to take up residence within the United States immediately upon the termination of the spouse's employment abroad, may be naturalized without the prior-residence or specified-physical-presence requirements that otherwise apply. The other requirements of the naturalization laws, including good moral character and attachment to the Constitution, continue to apply. The section is the legal basis of the three-year marriage-based naturalization track and the accommodation for families serving the United States abroad.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-per-country-immigration-limit-8usc1152",
    "title": "US INA Numerical Limitation to Any Single Foreign State (8 USC 1152): Per-Country Caps and Nondiscrimination",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 202 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1152, limits the number of immigrant visas chargeable to any single foreign state and establishes the rule against discrimination in their issuance, administered by the Department of State and US Citizenship and Immigration Services. Section 1152(a)(1)(A) provides that no person shall receive any preference or priority or be discriminated against in the issuance of an immigrant visa because of the person's race, sex, nationality, place of birth, or place of residence, subject to limited exceptions. Section 1152(a)(2) sets the per-country level: the total number of immigrant visas made available to natives of any single foreign state in the family-sponsored and employment-based categories may not exceed 7 percent of the annual total of those visas, and the limit for a dependent area is 2 percent. Section 1152(a)(3) permits visas that would otherwise go unused in a calendar quarter to be made available without regard to the per-country level, section 1152(a)(4) provides special allocation rules for the spouses and children of lawful permanent residents, and section 1152(a)(5) provides a special rule for employment-based immigrants where demand from a single state is high. Section 1152(b) sets the rules of chargeability, generally charging an applicant to the foreign state of birth but allowing chargeability to a parent's or spouse's state to prevent the separation of family members. Section 1152(e) provides that where the per-country limit is reached, visas are allocated so as to preserve the proportions among the family-sponsored and employment-based categories. The per-country limit is the rule that prevents a few high-demand countries from consuming the entire worldwide level and is the principal driver of the longest priority-date backlogs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-powers-of-immigration-officers-8usc1357",
    "title": "US INA Powers of Immigration Officers and Employees (8 USC 1357): Warrantless Interrogation, Arrest, Border-Area Search and 287(g) Delegation",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 287 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1357, sets out the powers of immigration officers and employees, administered by the Department of Homeland Security through US Immigration and Customs Enforcement and US Customs and Border Protection. Section 1357(a) confers powers exercisable without a warrant: to interrogate any alien or person believed to be an alien as to the right to be or remain in the United States; to arrest an alien who in the officer's presence is entering or attempting to enter unlawfully, or any alien in the United States in violation of law if likely to escape before a warrant can be obtained; within a reasonable distance from any external boundary, to board and search any vessel, railway car, aircraft, conveyance or vehicle for aliens, and within twenty-five miles of that boundary to have access to private lands (but not dwellings) for patrolling the border; and to make felony and in-presence arrests under stated conditions. Section 1357(b) authorises officers to administer oaths and take evidence. Section 1357(c) permits warrantless search of persons and personal effects of applicants for admission on reasonable cause. Section 1357(e) restricts warrantless entry onto the premises of an agricultural operation without the consent of the owner. Section 1357(g) is the 287(g) provision: it authorises the Attorney General to enter written agreements under which qualified State or local officers may perform the functions of an immigration officer, subject to federal direction. The section is the core grant of operational authority for interior and border immigration enforcement and the constitutional pressure point where those powers meet the Fourth Amendment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-procedure-granting-immigrant-status-8usc1154",
    "title": "US INA Procedure for Granting Immigrant Status (8 USC 1154): Petitions, Approval and the Marriage-Fraud Bars",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 204 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1154, sets the procedure for granting immigrant status by petition, the gateway step before an immigrant visa or adjustment of status, administered by US Citizenship and Immigration Services. Section 1154(a) identifies who may file: a citizen or lawful permanent resident may file a petition to classify a qualifying relative under the family-sponsored preferences and for immediate relatives, an employer may file for an employment-based beneficiary, and a battered spouse or child may self-petition under the Violence Against Women Act provisions in section 1154(a)(1)(A) and (a)(1)(B) without the abuser's participation or knowledge. Section 1154(b) requires that, after an investigation of the facts in each case, the Secretary approve the petition if the facts stated in it are true and the beneficiary is an immediate relative or entitled to a preference, and forward the approval to the Department of State. Section 1154(c) is the marriage-fraud bar: no petition may be approved if the alien has previously been accorded, or sought to be accorded, status by reason of a marriage determined to have been entered into for the purpose of evading the immigration laws. Section 1154(g) bars approval of a petition based on a marriage entered into during removal proceedings unless the alien has resided outside the United States for two years after the marriage. Correctly filing the right petition, supporting it with true facts, and clearing the marriage-fraud bars determines whether a beneficiary ever obtains a priority date and proceeds to a visa.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-refugee-admissions-8usc1157",
    "title": "US INA Annual Admission of Refugees (8 USC 1157): Presidential Ceiling, Emergencies and Eligibility",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 207 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1157, governs the admission of refugees to the United States from abroad, administered by US Citizenship and Immigration Services and the Department of State's Bureau of Population, Refugees, and Migration, building on the refugee definition in 8 U.S.C. 1101(a)(42). Section 1157(a) sets the annual framework: beginning in fiscal year 1983, the number of refugees who may be admitted in a fiscal year is such number as the President determines, before the beginning of the fiscal year and after appropriate consultation, is justified by humanitarian concerns or is otherwise in the national interest, and the admissions are allocated among refugees of special humanitarian concern to the United States in accordance with a determination made by the President after appropriate consultation. Section 1157(b) authorizes the admission of emergency situation refugees: where the President determines that an unforeseen emergency refugee situation exists, that the admission of certain refugees is justified by grave humanitarian concerns or is otherwise in the national interest, and that the admissions cannot be accomplished under the normal numerical limitation, the President may fix a number of admissions for the succeeding period not to exceed twelve months. Section 1157(c) sets the eligibility for an individual refugee: the Attorney General (now the Secretary of Homeland Security) may admit a refugee who is determined to be of special humanitarian concern to the United States, is admissible as an immigrant under the chapter (subject to the refugee inadmissibility waiver), and is not firmly resettled in any foreign country, and provides for the admission of the refugee's spouse and children. Section 1157(d) requires consultation with the Congress. A refugee admitted under this section may later adjust to lawful permanent resident status under 8 U.S.C. 1159.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-registration-of-aliens-8usc1302",
    "title": "US INA Registration of Aliens (8 USC 1302, 1304, 1306): The Thirty-Day Duty, the Carry Requirement and the Failure-to-Register Penalties",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Sections 262, 264 and 266 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1302, 1304 and 1306, impose the alien registration and fingerprinting regime and the penalties for non-compliance, administered by the Department of Homeland Security. Section 1302(a) provides that it shall be the duty of every alien fourteen years of age or older who has not already been registered and fingerprinted and who remains in the United States for thirty days or longer to apply for registration and to be fingerprinted before the expiration of those thirty days. Section 1302(b) places a corresponding duty on the parent or legal guardian of an alien under fourteen who remains for thirty days or longer to apply for registration of that alien. Section 1302(c) permits the Attorney General, on the basis of reciprocity and by regulation, to waive the fingerprinting requirement for a nonimmigrant. Section 1304(e) requires that every alien eighteen years of age and over shall at all times carry with him and have in his personal possession any certificate of alien registration or alien registration receipt card issued to him; failure to comply is a misdemeanor punishable on conviction by a fine not exceeding 100 dollars or imprisonment not more than thirty days, or both. Section 1306(a) makes the willful failure or refusal to apply for registration or to be fingerprinted a misdemeanor punishable on conviction by a fine not exceeding 1,000 dollars or imprisonment not more than six months, or both. The provisions are the statutory basis of the alien registration system and the in-person documentary obligations that attach to non-citizens present in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-removal-of-aggravated-felons-8usc1228",
    "title": "US INA Expedited Removal of Aliens Convicted of Aggravated Felonies (8 USC 1228): Correctional-Facility Proceedings, Administrative Removal and the Conclusive Presumption of Deportability",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 238 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1228, provides for the expedited removal of aliens convicted of committing aggravated felonies, administered by the Department of Homeland Security through US Immigration and Customs Enforcement. Section 1228(a) directs the Attorney General to provide for special removal proceedings at certain Federal, State and local correctional facilities for aliens convicted of criminal offences meeting specified criteria; those proceedings are to be conducted in conformity with section 1229a, are designed to eliminate the need for additional detention and to assure expeditious removal following the end of the alien's incarceration, and require that an alien convicted of an aggravated felony who is taken into custody be detained at a facility where other such aliens are held, with reasonable efforts to protect access to counsel. Section 1228(b) authorises administrative removal without referral to an immigration judge for an alien who is not a lawful permanent resident and is deportable under section 1227(a)(2)(A)(iii) for an aggravated felony: the determination of deportability and the order of removal may be made under the procedures set out in that subsection rather than the full section 1229a hearing, subject to the procedural protections the subsection prescribes. Section 1228(c) provides that an alien convicted of an aggravated felony is conclusively presumed to be deportable from the United States. The section is the accelerated track by which the United States removes serious criminal aliens, and the procedural rules in subsection (b) are the constitutional pressure point where speed meets due process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-removal-proceedings-8usc1229a",
    "title": "US INA Removal Proceedings (8 USC 1229a): Immigration Court Procedure, Rights and Burdens of Proof",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 240 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1229a, establishes the procedure for removal proceedings before an immigration judge in the Executive Office for Immigration Review (EOIR), Department of Justice. Section 1229a(a)(1) provides that an immigration judge shall conduct proceedings for deciding the inadmissibility or deportability of an alien, and section 1229a(a)(3) makes a proceeding under this section the sole and exclusive procedure for determining whether an alien may be admitted to the United States or, if already admitted, removed. Section 1229a(b)(4) sets the alien's rights in the proceeding: the alien has the privilege of being represented, at no expense to the Government, by counsel of the alien's choosing; a reasonable opportunity to examine the evidence against the alien, to present evidence on the alien's own behalf, and to cross-examine witnesses presented by the Government; and a complete record is kept of all testimony and evidence. Section 1229a(b)(5) permits an in absentia order of removal where the alien fails to appear after proper written notice, with limited grounds and timeframes for rescission. Section 1229a(c) allocates the burdens of proof: under (c)(2) an alien who is an applicant for admission must establish that he is clearly and beyond doubt entitled to be admitted and is not inadmissible, while under (c)(3) in the case of an alien who has been admitted the Service must establish by clear and convincing evidence, on reasonable, substantial, and probative evidence, that the alien is deportable; and under (c)(4) an alien applying for relief or protection from removal bears the burden of establishing eligibility for that relief. The immigration judge's decision results in an order of removal, a grant of relief, or termination, subject to appeal to the Board of Immigration Appeals and judicial review.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-revocation-of-naturalization-8usc1451",
    "title": "US INA Revocation of Naturalization (8 USC 1451): Illegal Procurement, Concealment or Willful Misrepresentation and the Effect of Denaturalization",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 340 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1451, provides for the revocation of naturalization, the civil process by which a naturalized citizen may be stripped of citizenship, administered by the Department of Justice through the United States attorneys. Section 1451(a) imposes a duty on the United States attorneys for the respective districts, upon affidavit showing good cause, to institute proceedings in any district court of the United States for the purpose of revoking and setting aside the order admitting the person to citizenship and cancelling the certificate of naturalization, on the ground that the order and certificate of naturalization were illegally procured, or were procured by concealment of a material fact or by willful misrepresentation. A revocation on these grounds is effective as of the original date of the order and certificate, so that the person is treated as never having been validly naturalized. The same subsection provides that, where a naturalized person, within ten years following naturalization, refuses to testify before a duly constituted congressional committee concerning the person's subversive activities, and is thereafter convicted of contempt for that refusal, the refusal is a ground for revocation. The section requires court proceedings and proof to a clear, convincing and unequivocal standard developed by the courts, reflecting the gravity of removing citizenship. The section is the legal mechanism by which the United States undoes a naturalization obtained unlawfully or by fraud, and the consequences flow back to the original grant.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-temporary-protected-status-8usc1254a",
    "title": "US INA Temporary Protected Status (8 USC 1254a): Designation, Eligibility and Bars",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 244 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1254a, creates Temporary Protected Status (TPS), under which nationals of a designated foreign state who are in the United States may be protected from removal and authorized to work for the duration of the designation, administered by US Citizenship and Immigration Services. Section 1254a(a) provides that, in the case of an alien who is a national of a designated foreign state and meets the eligibility requirements, the Attorney General (now the Secretary of Homeland Security) may grant the alien temporary protected status, shall not remove the alien from the United States during the period in which such status is in effect, and shall authorize the alien to engage in employment. Section 1254a(b) governs designations: the Secretary may designate a foreign state (or part of a state) for TPS upon finding that there is an ongoing armed conflict within the state that would pose a serious threat to the personal safety of returned nationals, that there has been an environmental disaster (or epidemic) resulting in a substantial but temporary disruption of living conditions such that the state is unable to handle the return of its nationals, or that there exist extraordinary and temporary conditions in the state that prevent its nationals from returning in safety; designations are for a set period and subject to periodic review, extension and termination. Section 1254a(c) sets the eligibility requirements for an individual alien: continuous physical presence in the United States since the effective date of the most recent designation, continuous residence in the United States since a date the Secretary designates, admissibility as an immigrant (with certain waivers), and timely registration. Section 1254a(c)(2)(B) sets the bars: an alien is ineligible if convicted of any felony or two or more misdemeanors committed in the United States, or if subject to the persecutor bar or the security-related grounds. TPS is temporary and does not by itself lead to permanent resident status.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-travel-control-citizens-aliens-8usc1185",
    "title": "US INA Travel Control of Citizens and Aliens (8 USC 1185): Presidential Restrictions on Entry and Departure and the Citizen Passport Requirement",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 215 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1185, provides for travel control of citizens and aliens and confers on the President broad authority to regulate entry into and departure from the United States, administered by the Department of Homeland Security and the Department of State. Section 1185(a) provides that, unless otherwise ordered by the President, it shall be unlawful for any alien to depart from or enter, or attempt to depart from or enter, the United States except under such reasonable rules, regulations and orders, and subject to such limitations and exceptions, as the President may prescribe; the same subsection extends the power to transportation companies and other persons. Section 1185(b) imposes the citizen passport requirement: except as otherwise provided by the President and subject to such limitations and exceptions as the President may authorize and prescribe, it shall be unlawful for any citizen of the United States to depart from or enter, or attempt to depart from or enter, the United States unless he bears a valid United States passport. Section 1185(c) defines the United States and the term person for the purposes of the section. Section 1185(d) clarifies that the possession of an entry document does not entitle a person to enter if that person is otherwise inadmissible, and section 1185(f) provides that passports, visas, reentry permits and other documents required for entry may be considered as permits to enter for the purposes of the section. The section is the statutory foundation of the United States passport and travel-document requirement and the source of the President's standing authority to restrict cross-border travel in the interests of national security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-visa-waiver-program-8usc1187",
    "title": "US INA Visa Waiver Program (8 USC 1187): Eligibility, ESTA and Program Country Designation",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 217 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1187, establishes the Visa Waiver Program (VWP), under which nationals of designated program countries may be admitted to the United States as nonimmigrant visitors for business or pleasure without first obtaining a visa, administered by the Department of Homeland Security in consultation with the Department of State. Section 1187(a) sets the conditions of eligibility: the alien must be applying for admission as a nonimmigrant visitor for a period not exceeding 90 days; must be a national of, and present a valid passport issued by, a country designated as a program country; must present a passport that is machine-readable and, as required, an electronic (e-) passport meeting international standards; must, under section 1187(a)(11), obtain an approved electronic travel authorization through the Electronic System for Travel Authorization (ESTA) before boarding; must have waived any right to review or appeal of an admissibility determination or to contest removal other than on the basis of an application for asylum; and, if a previous participant, must not have failed to comply with the conditions of any previous admission. Section 1187(c) governs the designation (and termination) of program countries, conditioned on factors including a low nonimmigrant visa refusal rate, reciprocal visa-free treatment of US citizens, issuance of machine-readable and electronic passports, and cooperation on security and information-sharing. Section 1187(h) requires the ESTA system to determine, in advance of travel, each applicant's eligibility to travel under the program. The VWP is the framework that governs visa-free business and tourist travel to the United States and the carrier and traveler obligations that attach to it.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ina-worldwide-immigration-level-8usc1151",
    "title": "US INA Worldwide Level of Immigration (8 USC 1151): Family, Employment, Diversity Limits and Immediate Relatives",
    "domain": "Immigration & Border Control",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Section 201 of the Immigration and Nationality Act (INA), codified at 8 U.S.C. 1151, fixes the annual worldwide levels of immigration and identifies the categories that are exempt from those levels, administered by US Citizenship and Immigration Services and the Department of State. Section 1151(a) provides that, exclusive of the immediate relatives and other specified aliens, immigrant visas are made available to family-sponsored immigrants, employment-based immigrants and diversity immigrants subject to the worldwide levels set in the section, with a quarterly limitation on issuance. Section 1151(b) exempts certain aliens from the worldwide levels, most importantly immediate relatives, defined as the children, spouses and parents of a citizen of the United States, except that in the case of parents the citizen son or daughter must be at least 21 years of age. Section 1151(c) sets the worldwide level of family-sponsored immigrants at 480,000 minus the number of immediate relatives and other adjustments computed under the formula, plus any unused employment-based numbers, subject to a statutory floor. Section 1151(d) sets the worldwide level of employment-based immigrants at 140,000 plus any unused family-sponsored numbers from the prior year. Section 1151(e) sets the worldwide level of diversity immigrants at 55,000 for each fiscal year. Correctly applying this section determines how many immigrant visas exist in each category in a given year and which applicants fall outside the numerical caps entirely, which in turn drives the priority-date waits administered through the monthly Visa Bulletin.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-indian-gaming-regulatory-act",
    "title": "US Indian Gaming Regulatory Act (25 U.S.C. Chapter 29): Federal Framework for Gaming on Indian Lands and the Three Classes of Gaming",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Indian Gaming Regulatory Act of 1988 (IGRA), codified at 25 U.S.C. Chapter 29, establishes the federal framework for the conduct and regulation of gaming on Indian lands and creates the National Indian Gaming Commission, balancing tribal self-government and economic development against the need to shield gaming from organized crime. Section 2701 sets out the congressional findings. Section 2702 declares the policy of promoting tribal economic development, self-sufficiency, and strong tribal government through gaming. Section 2703 sets the definitions and divides gaming into three classes: Class I, social games for minimal prizes or traditional ceremonial gaming; Class II, bingo and certain card games, excluding banking card games and slot machines; and Class III, all other forms of gaming. Section 2704 establishes the National Indian Gaming Commission and its composition. Section 2710 governs tribal gaming ordinances, placing Class I under exclusive tribal jurisdiction, Class II under tribal jurisdiction subject to Commission oversight, and Class III conditional on a Tribal-State compact. Section 2711 governs the review and approval of management contracts by the Commission Chairman. Section 2712 governs review of existing ordinances and contracts. Section 2719 restricts gaming on lands acquired by the Secretary in trust for a tribe after October 17, 1988, subject to specified exceptions. The Act is the foundational federal statute for tribal gaming compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-indiana-cdpa-2024",
    "title": "Indiana Consumer Data Protection Act (ICDPA) 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Indiana Consumer Data Protection Act (ICDPA) was enacted as Indiana Senate Bill 5 and signed into law on 1 May 2023, effective 1 January 2026. The ICDPA establishes consumer privacy rights and controller obligations for businesses processing personal data of Indiana residents. The law is modelled closely on the Virginia Consumer Data Protection Act (CDPA) and establishes similar rights and obligations. The ICDPA applies to persons who conduct business in Indiana or produce products or services targeted to Indiana residents and who during a calendar year either control or process personal data of at least 100,000 consumers, or control or process personal data of at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data. The ICDPA grants Indiana consumers the right to access, correct, delete, and obtain a portable copy of their personal data, as well as the right to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of solely automated decisions that produce legal or similarly significant effects. Controllers must provide a privacy notice, establish a lawful purpose for processing sensitive data (including requiring consent for sensitive data processing), conduct and document data protection assessments for high-risk processing activities, and implement reasonable security measures to protect personal data. The Indiana Attorney General has exclusive enforcement authority with civil penalties of up to $7,500 per violation. There is no private right of action. Controllers have a 30-day cure period prior to enforcement action.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-indiana-cdpa-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-indiana-sports-wagering-act-2019",
    "title": "Indiana Lawful Sports Wagering Act 2019 - Gaming Commission Licensing",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Indiana's Lawful Sports Wagering Act (Senate Bill 552, 2019; IC 4-38-1 et seq.) authorises sports betting at licensed casinos and online through affiliated platforms. The Indiana Gaming Commission (IGC) licenses operators and certificated suppliers. A 9.5% tax rate applies on adjusted gross receipts (AGR) for both retail and online sports betting. In-person registration was initially required but was waived and then permanently removed. Sports betting launched 1 September 2019, making Indiana one of the fastest-launching states post-PASPA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_paspa_repeal",
        "indiana_gaming_commission",
        "uigea_2006",
        "fatf_aml_gambling",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
      "us-uigea-2006-unlawful-internet-gambling",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-inflation-reduction-act-clean-energy-2022",
    "title": "Inflation Reduction Act of 2022 (Pub.L. 117-169) - Clean Energy Tax Credits: Investment Tax Credit §48, Production Tax Credit §45, Clean Vehicle Credit §30D, Advanced Manufacturing Credit §45X, Prevailing Wage and Domestic Content Requirements, and $369B Climate Investment",
    "domain": "Energy & Utilities",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Inflation Reduction Act of 2022 (IRA, Pub.L. 117-169, enacted 16 August 2022) is the largest US climate investment in history, allocating approximately $369 billion in climate and clean energy provisions; key mechanisms include: extension and expansion of the Investment Tax Credit (ITC, IRC §48) to include standalone energy storage, offshore wind, and other clean technologies through 2032; the Production Tax Credit (PTC, IRC §45) for qualifying clean electricity generating facilities; a new Clean Electricity Investment Credit (IRC §48E) and Clean Electricity Production Credit (IRC §48E) technology-neutral from 2025 onward; the §30D Clean Vehicle Credit of up to $7,500 for new qualified plug-in vehicles subject to battery component domestic content and North American assembly requirements; the §45X Advanced Manufacturing Production Credit for domestically produced clean energy components; and the §179D Energy Efficient Commercial Buildings Deduction expanded to $5 per square foot; credits are enhanced by 10 percentage point domestic content bonuses and prevailing wage requirements that must be met to access full credit amounts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "EU_RED_III",
        "EU_CBAM",
        "OECD_PILLAR_TWO",
        "SEC_CLIMATE"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sec-climate-disclosure-rule-2024",
      "eu-cbam-carbon-border-adjustment-2023",
      "oecd-beps-pillar-two-global-minimum-tax"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-infrastructure-investment-jobs-act-2021",
    "title": "Infrastructure Investment and Jobs Act of 2021 (IIJA, Pub.L. 117-58) - $1.2 Trillion Bipartisan Infrastructure Law: Buy American Domestic Content Requirements, Davis-Bacon Prevailing Wage, $65B Broadband, $66B Rail, $55B Water, $47.2B Resilience, and Federal Grant Compliance Framework",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Infrastructure Investment and Jobs Act (IIJA, Bipartisan Infrastructure Law, Pub.L. 117-58, enacted 15 November 2021) provides $1.2 trillion in total infrastructure investment ($550 billion in new spending) over 5 years; key allocations include: $110 billion for roads, bridges, and major projects (largest in US history); $66 billion for passenger and freight rail (transformative Amtrak funding); $65 billion for broadband deployment including $42.45 billion in BEAD grants for unserved/underserved areas; $55 billion for water infrastructure (lead pipe replacement, PFAS remediation); $47.2 billion for resilience including coastal resilience, wildfire prevention, and drought mitigation; $39 billion for public transit; $25 billion for airports; $21 billion for environmental remediation and legacy pollution; $17 billion for ports and waterways; $7.5 billion for EV charging infrastructure; all IIJA-funded construction requires: (i) Buy American Act compliance for iron, steel, manufactured products, and construction materials (Buy America Preference enhanced to 100%); (ii) Davis-Bacon Act prevailing wages for all IIJA-funded construction; and (iii) compliance with environmental review streamlining under Title I.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "US_IRA",
        "US_CHIPS_ACT",
        "EU_CONNECTING_EUROPE",
        "US_NEPA"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-inflation-reduction-act-clean-energy-2022",
      "us-chips-science-act-2022",
      "us-nepa-1970-environmental-impact-assessment"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-inspector-general-act-5-usc-ch4",
    "title": "Inspector General Act 1978 - 5 USC Chapter 4",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Chapter 4 of title 5 of the United States Code (sections 401 through 424), as recodified by Public Law 117-286 in December 2022 (formerly 5 USC Appendix), codifies the Inspector General Act of 1978 (Public Law 95-452, enacted 12 October 1978) as substantially amended by the Inspector General Reform Act of 2008 (Public Law 110-409) and the Securing Inspector General Independence Act of 2022 (FY23 NDAA Title LII). Section 402 establishes the Offices of Inspector General as independent and objective units conducting and supervising audits and investigations relating to programs and operations of the federal government, providing leadership and coordination to promote economy, efficiency, and effectiveness, and to prevent and detect fraud, waste, and abuse. Section 404 prescribes the duties and responsibilities of Inspectors General including auditing programs, conducting investigations of suspected misconduct, and reporting findings. Section 405 requires semiannual reports to Congress that summarise IG activities; section 405A requires posting on agency websites. Section 406 grants Inspectors General broad authority to access agency records, subpoena documents, administer oaths, and refer findings for prosecution. Section 414 establishes the Council of the Inspectors General on Integrity and Efficiency (CIGIE). The 2022 Securing Inspector General Independence Act tightened removal protections requiring the President to provide written notice and substantive rationale 30 days before removing an IG.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-whistleblower-protection-act-5-usc-2302",
      "us-civil-service-reform-act-5-usc-1101"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-interstate-land-sales-full-disclosure-act",
    "title": "US Interstate Land Sales Full Disclosure Act (15 USC ch 42): Subdivision Registration, Disclosure and Penalties",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Interstate Land Sales Full Disclosure Act (15 U.S.C. ch. 42) protects purchasers of subdivided land by requiring registration and disclosure for covered interstate land sales, administered by the Consumer Financial Protection Bureau. Section 1701 supplies the definitions, including subdivision and lot. Section 1702 sets the exemptions, including for larger lots and certain improved-lot sales. Section 1703 sets the central requirements respecting the sale or lease of lots: it prohibits selling or leasing a non-exempt lot unless a statement of record is in effect and a printed property report is given to the purchaser in advance, prohibits fraud, and gives the purchaser a right to revoke the contract within the statutory period (and a longer period where the property report was not provided). Section 1704 requires the registration of subdivisions through a statement of record, section 1705 sets the information required in the statement of record, and section 1707 sets the contents of the property report. Section 1709 provides civil liabilities for violations. Section 1717 provides criminal penalties of a fine of not more than 10,000 dollars or imprisonment for not more than 5 years, or both, and section 1717a provides for civil money penalties. The Act is the legal foundation of US disclosure protection in interstate land sales.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-intervention-on-the-high-seas-act-33-usc-1471",
    "title": "Intervention on the High Seas Act, 33 USC 1471-1487",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Intervention on the High Seas Act, codified at 33 USC 1471 and following, implements the 1969 Intervention Convention and its 1973 Protocol in US law. Section 1471 defines the Convention, the Protocol, convention oil, ship and the Secretary (the department in which the Coast Guard is operating). Section 1472 authorises the Secretary, without liability for damage to ship, cargo, crew, underwriters or other interested parties, to take measures on the high seas to prevent, mitigate or eliminate a grave and imminent danger to the US coastline or related interests from pollution or threat of pollution following a maritime casualty, except as provided in Section 1479.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-33-usc-ch26"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-investment-advisers-act-1940",
    "title": "US Investment Advisers Act of 1940 - SEC Registration, Fiduciary Duty, Form ADV, Custody Rule",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-08-23",
    "bluf": "The Investment Advisers Act of 1940 (15 U.S.C. §§ 80b-1 et seq.) imposes a federal fiduciary duty on registered investment advisers and governs their registration with the SEC. SEC registration threshold: advisers with AUM ≥ USD 110M must register with the SEC (Rule 203A-1); advisers with AUM between USD 25M and USD 100M register with state regulators; the USD 100M-110M range is a buffer zone. Advisers must file Form ADV (Part 1: regulatory data; Part 2A: the Brochure; Part 2B: Brochure Supplement for supervised persons) and provide it to clients. Section 206 imposes strict anti-fraud liability: no material misstatement or omission, no conflict of interest without full disclosure and client consent. Section 205 restricts performance fees to 'qualified clients' (AUM with adviser ≥ USD 1.1M or net worth ≥ USD 2.2M). Rule 206(4)-2 (custody rule) requires a qualified custodian, annual surprise examination, and immediate client notification of assets. Rule 206(4)-7 mandates a written compliance program and Chief Compliance Officer (CCO).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "Investment_Company_Act_1940",
        "Dodd_Frank_amendments",
        "BSA_AML_obligations",
        "EU_AIFMD_equivalent",
        "SOX_fiduciary"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-investment-company-act-1940",
      "us-dodd-frank-key-provisions",
      "us-bank-secrecy-act-31-cfr-1010-aml"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-investment-company-act-1940",
    "title": "US Investment Company Act of 1940 - Section 3(c)(1)/(c)(7) Exemptions, Leverage Limits, Affiliated Transaction Restrictions",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Investment Company Act of 1940 (15 U.S.C. §§ 80a-1 et seq.) regulates US investment companies - mutual funds, ETFs, closed-end funds, and money market funds. The two primary exemptions used by private funds are Section 3(c)(1) (fewer than 100 beneficial owners, not publicly offering) and Section 3(c)(7) (investors are solely qualified purchasers - individuals with ≥$5M in investments or institutions with ≥$25M - not publicly offering). Registered investment companies (mutual funds, ETFs) face: a 33.33% leverage ceiling (Section 18 - senior securities may not exceed one-third of total assets), Section 17 affiliated transaction restrictions requiring exemptive orders or board approvals, Rule 22c-1 forward pricing at next computed NAV, Section 12 limits on concentration and cross-fund investments, and SEC annual registration statement filing under Section 30. Money market funds operate under Rule 2a-7.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "Investment_Advisers_Act_1940",
        "Dodd_Frank_amendments",
        "BSA_AML",
        "SEC_cybersecurity_disclosure",
        "EU_AIFMD_equivalent",
        "EU_UCITS_equivalent"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dodd-frank-key-provisions",
      "us-bank-secrecy-act-31-cfr-1010-aml"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-iot-cybersecurity-improvement-act-2020",
    "title": "Internet of Things Cybersecurity Improvement Act of 2020",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The IoT Cybersecurity Improvement Act of 2020 requires federal agencies to only procure IoT devices that comply with minimum security standards developed by NIST and mandates that vendors adopt coordinated vulnerability disclosure policies. It applies to all IoT devices purchased by executive agencies, as defined in Section 3 of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cyber-nist-800-53-ac2",
      "nist-800-53-sc7",
      "c-scrm-practices-systems-organizations",
      "assessing-security-privacy-controls"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-iowa-consumer-data-protection-act-2023",
    "title": "Iowa Consumer Data Protection Act (SF 262)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2025-01-01",
    "bluf": "The Iowa Consumer Data Protection Act (ICDPA) grants Iowa residents rights to access, delete, and obtain a copy of their personal data, and to opt out of the sale of their data or its use for targeted advertising. The Act applies to entities that control or process personal data of at least 100,000 Iowa consumers or derive over 50% of gross revenue from selling the data of at least 25,000 consumers, with enforcement exclusively by the Iowa Attorney General (Section 715D.2, 715D.4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ira-2022-clean-energy-tax-credits",
    "title": "Inflation Reduction Act of 2022 (Public Law 117-169): Clean Energy Tax Credits (ITC, PTC), Domestic Content, and Energy Community Bonus Credit Amounts",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Inflation Reduction Act of 2022 (IRA) provides enhanced tax credits for clean energy projects, including the Investment Tax Credit (ITC) under IRC § 48 and Production Tax Credit (PTC) under IRC § 45, for entities that meet specific prevailing wage and apprenticeship labor requirements. Additional bonus credits are available for projects satisfying domestic content thresholds and those located in designated energy communities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-s2-climate-related-disclosures",
      "iso-14064-ghg-reporting-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ira-energy-tax-credits-2022-sections-45-48",
    "title": "Inflation Reduction Act of 2022: Clean Energy Production Tax Credit (§45) and Investment Tax Credit (§48)",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-08-29",
    "bluf": "The Inflation Reduction Act of 2022 (IRA) modifies and extends the Production Tax Credit (PTC) under IRC §45 and the Investment Tax Credit (ITC) under IRC §48 for qualifying clean energy projects. To receive the full base credit, developers and owners must satisfy specific prevailing wage and apprenticeship labor requirements, with bonus credits available for meeting domestic content thresholds and siting projects in energy communities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "osha-work-safety-us",
      "nist-sp-800-161r1-csrm-practices"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-iran-sanctions-act-1996-pl-104-172",
    "title": "Iran Sanctions Act of 1996 - Public Law 104-172",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Iran Sanctions Act of 1996 (ISA, Public Law 104-172, enacted 5 August 1996, originally the Iran and Libya Sanctions Act and renamed when Libya sanctions were lifted in 2006) authorises the President to impose sanctions on foreign persons that knowingly make significant investments in Iran's petroleum sector or otherwise contribute to Iran's ability to develop petroleum resources. The Act has been extended and substantially amended through the Iran Sanctions, Accountability, and Divestment Act of 2010 (CISADA), the Iran Threat Reduction and Syria Human Rights Act of 2012 (ITRSHRA), the Iran Freedom and Counter-Proliferation Act of 2012, and the Countering America's Adversaries Through Sanctions Act of 2017 (CAATSA). The ISA authorises a menu of sanctions including denial of US Export-Import Bank assistance, denial of US export licences, prohibition on US bank loans exceeding 10 million USD, prohibition on US procurement, and prohibition on certain financial institution transactions. Subsequent amendments expanded coverage to include refined petroleum product sales to Iran, joint ventures with Iran outside Iran, and provision of insurance, financing, or shipping for sanctioned Iran-related activity. The ISA framework is administered by the Treasury Office of Foreign Assets Control (OFAC) under the Iranian Transactions and Sanctions Regulations (31 CFR Part 560) and informs every multinational's Iran-exposure compliance program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ieepa-1977",
      "us-money-laundering-control-act-18-usc-1956"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-irc-482-transfer-pricing-regulations",
    "title": "US Treasury Regulations 26 CFR Section 1.482 Transfer Pricing Rules - Arm's Length Standard, Comparable Uncontrolled Price (CUP), Cost Plus, Resale Price and Profit Split Methods",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under 26 CFR § 1.482-1(b), the U.S. Internal Revenue Service (IRS) requires that transactions between commonly controlled entities must adhere to the 'arm's length standard,' meaning the results of the transaction must be consistent with the results that would have been realized if uncontrolled taxpayers had engaged in the same transaction under the same circumstances.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-dac6-mandatory-disclosure-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-irc-section-482-intercompany-pricing",
    "title": "26 U.S. Code § 482 - Allocation of income and deductions among taxpayers",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation authorizes the Secretary of the Treasury to allocate income, deductions, credits, or allowances between related organizations or businesses to prevent tax evasion or clearly reflect income. It specifically requires that income from transfers or licenses of intangible property be commensurate with the income attributable to the intangible under § 482.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "canada-transfer-pricing-income-tax-act-section-247",
      "eu-transfer-pricing-directive-proposal-2023",
      "eu-global-minimum-tax-directive-2022-2523-pillar-two",
      "fatf-40-recommendations-2023-consolidated"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-irs-digital-asset-broker-1-6045-2024",
    "title": "IRS Final Regulations on Digital Asset Broker Reporting - 26 CFR Section 1.6045-1 (effective 9 September 2024)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Treasury Department and IRS published final regulations under Internal Revenue Code Section 6045 (89 FR 56480, 9 July 2024, effective 9 September 2024) implementing Section 80603 of the Infrastructure Investment and Jobs Act (Pub. L. 117-58). The final rules amend 26 CFR Section 1.6045-1 to require digital asset brokers (custodial brokers and brokers acting as principals) to report gross proceeds and adjusted basis on Form 1099-DA for digital asset sales and exchanges effected for customers, and amend Sections 1.1001-7(c), 1.1012-1(h)(5), 1.1012-1(j)(6), 1.6045-1(q), 1.6045-4(s), 1.6045B-1(j), 1.6050W-1(j), 31.3406(b)(3)-2(c), 31.3406(g)-1(f), 31.3406(g)-2(h), 301.6721-1(j), 301.6722-1(g) accordingly. Digital asset is defined as any digital representation of value recorded on a cryptographically secured distributed ledger or any similar technology, including stablecoins pegged to fiat currency, qualifying stablecoins, and specified non-fungible tokens (specified NFTs). Gross proceeds reporting begins for sales effected on or after 1 January 2025; adjusted basis reporting for digital asset covered securities begins for assets acquired on or after 1 January 2026. Real estate reporting persons must report digital assets used to acquire real estate. Final rules do not finalise non-custodial-broker (DeFi/middleman) provisions - Treasury reserves these and intends a separate rulemaking. Validators, hardware sellers, and software licensors solely permitting private-key control are not brokers (Section 1.6045-1(b)(2)(ix) and (x)). A coordination rule under Section 1.6045-1(c)(8)(iii) excludes from digital-asset Form 1099-DA reporting dual-classification assets cleared on limited-access regulated networks (reportable on Form 1099-B instead).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_eo_14178_digital_financial_tech_2025",
        "us_genius_act_stablecoin_2025_framework",
        "fatf_recommendation_16_travel_rule_crypto",
        "us_fit21_financial_innovation_technology_act_2024",
        "fatf_virtual_asset_red_flags"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14178-digital-financial-tech-2025",
      "us-genius-act-stablecoin-2025-framework",
      "us-fit21-financial-innovation-technology-act-2024",
      "fatf-virtual-asset-redfl"
    ],
    "primary_citations_count": 15
  },
  {
    "node_id": "us-irs-modernized-efile-mef-publication-1345",
    "title": "US IRS Modernized e-File (MeF) Publication 1345 - Authorized e-File Provider Requirements, ERO Obligations and Electronic Signature Compliance",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "IRS Publication 1345 ('Handbook for Authorized IRS e-File Providers of Individual Income Tax Returns') is the primary operational handbook governing the responsibilities of all participants in the IRS Modernized e-File (MeF) system for individual income tax returns; the MeF system, authorized under Internal Revenue Code Section 6011(e) and Treasury Regulation 301.6011-2 which require electronic filing for tax preparers who file 11 or more individual returns per year, processes over 93% of all US individual income tax returns; participants in the IRS e-File programme include Electronic Return Originators (EROs - preparers who submit returns), Transmitters (entities that send returns electronically to IRS), Intermediate Service Providers (entities that process return data between EROs and Transmitters), and Software Developers (entities that build e-File software); all participants must obtain an Electronic Filing Identification Number (EFIN) from the IRS and comply with the e-File Application requirements including fingerprint and credit history checks for principals and responsible officials; all paid tax preparers must obtain a Preparer Tax Identification Number (PTIN) under Treasury Regulation 1.6109-2; the electronic signature process for Form 8879 (IRS e-File Signature Authorization) uses Knowledge-Based Authentication (KBA) as the primary method and must comply with IRS Publication 1345 Chapter 3; data security requirements are governed by IRC Section 7216 (tax return data confidentiality) and the FTC Safeguards Rule (16 CFR Part 314) applicable to tax preparers as financial institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eidas-regulation-910-2014-electronic-identification"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-irs-section-482-transfer-pricing-regulations-arm-length-standard",
    "title": "US IRS Section 482 Transfer Pricing Regulations - Arm's Length Standard for Intercompany Transactions",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Section 482 of the Internal Revenue Code and the accompanying Treasury Regulations (26 C.F.R. § 1.482-1 to -9) require that intercompany transactions between related parties be priced at arm's length - the price that would be charged in an uncontrolled transaction. Taxpayers with controlled transactions of USD 10M+ must maintain contemporaneous documentation under the penalty of gross valuation misstatement penalties (40% on underpayment of tax).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-13-country-by-country-reporting"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-irs-virtual-currency-reporting-guidance-2023",
    "title": "US IRS Virtual Currency Guidance and FAQ 2023 - Cryptocurrency as Property: Capital Gains/Losses, Mining Income Ordinary Treatment, Staking Rewards, Airdrops, Hard Forks and Form 1099-DA Broker Reporting",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The U.S. Internal Revenue Service (IRS) treats virtual currencies as property for federal tax purposes, requiring taxpayers to report capital gains or losses on dispositions and recognize ordinary income from activities like mining, staking, and receiving airdrops, as established in Notice 2014-21 and subsequent guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crypto-aml-travel-rule",
      "fincen-cvc-business-models",
      "us-sec-digital-asset-framework"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-itar-22-cfr-120-130-arms-export",
    "title": "US ITAR 22 CFR Parts 120-130 - International Traffic in Arms Regulations: US Munitions List, Export and Import Licensing, Technical Assistance Agreements, Deemed Export Rule, Broker Registration, and Criminal and Civil Penalty Framework",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The International Traffic in Arms Regulations (ITAR), codified at 22 CFR Parts 120-130, administered by the US Department of State Directorate of Defense Trade Controls (DDTC) under the Arms Export Control Act (AECA) 22 U.S.C. § 2778, controls the export, import, temporary import, and brokering of defense articles and defense services appearing on the United States Munitions List (USML); key obligations include: mandatory DDTC registration for all manufacturers and exporters of USML defense articles (Part 122, Form DS-2032, annual fee); export or temporary import licenses required for all USML defense articles and technical data unless a specific exemption applies (Parts 123-125); Technical Assistance Agreements (TAAs) and Manufacturing License Agreements (MLAs) for defense service provision to foreign persons; the deemed export rule treating disclosure of controlled technical data to foreign nationals in the United States as an export; criminal penalties of up to $1,000,000 per violation and 20 years imprisonment; civil penalties of up to approximately $1,368,490 per violation (inflation-adjusted) assessed by DDTC; voluntary disclosure process offering mitigation for self-reported violations; and country restrictions under 22 CFR 126.1 prohibiting exports to embargoed destinations including Russia, China (arms), Iran, North Korea, Cuba, Syria, and Venezuela.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "US_EAR",
        "US_AECA",
        "EU_DUAL_USE",
        "OECD_ARMS_TRADE"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-chips-science-act-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-itrshra-iran-threat-reduction-2012-pl-112-158",
    "title": "Iran Threat Reduction and Syria Human Rights Act 2012 (ITRSHRA) - Public Law 112-158",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Iran Threat Reduction and Syria Human Rights Act of 2012 (ITRSHRA, Public Law 112-158, enacted 10 August 2012) further expanded the Iran sanctions framework established by the Iran Sanctions Act of 1996 (ISA) and the Comprehensive Iran Sanctions, Accountability, and Divestment Act of 2010 (CISADA). Title II expanded the petroleum sector sanctions under ISA, adding new categories of sanctionable activity including provision of underwriting services, insurance, or reinsurance for ISA-prohibited transactions, joint ventures with the Iranian government for oil and gas resource development outside Iran, and provision of vessels or shipping services for Iranian-origin oil or oil products. Section 218 imposed sanctions on US person subsidiaries of foreign entities for ISA-prohibited transactions. Title III imposed sanctions on Iranian human rights abusers and their support for the Assad regime in Syria. Section 312 imposed sanctions on transfers of goods or technologies likely to be used for human rights abuses by the Iranian or Syrian governments. Title IV implemented diplomatic provisions and divestment requirements. The Act also created the Special Designated National (SDN) framework for Syrian human rights abusers and imposed Section 217 reporting obligations on SEC registrants for Iran-related disclosures. ITRSHRA is administered by Treasury OFAC and remains a core anchor of the US Iran and Syria sanctions framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-iran-sanctions-act-1996-pl-104-172",
      "us-cisada-comprehensive-iran-sanctions-2010-pl-111-195"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-jackson-vanik-amendment-19-usc-2432",
    "title": "Jackson-Vanik Amendment - 19 USC 2432 Trade Act 1974 Title IV",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 2432 of title 19 of the United States Code, the Jackson-Vanik Amendment to Title IV of the Trade Act of 1974 (Public Law 93-618), conditions normal trade relations (NTR, formerly most-favored-nation) treatment and US government credit and credit guarantees for non-market economy countries on those countries' emigration policies and human rights performance. The Amendment was enacted to pressure the Soviet Union and other non-market economies to permit Jewish and other minority emigration. Subsection 2432(a) provides that no non-market economy country shall be eligible to receive NTR treatment, participate in US government credit or credit guarantee programs, or have the President conclude a commercial agreement, with respect to any product, unless the President determines the country does not deny its citizens the right or opportunity to emigrate, does not impose more than a nominal tax on emigration, or does not impose more than a nominal tax, levy, fine, or charge on any citizen as a consequence of the desire of such citizen to emigrate. Subsection 2432(b) authorises the President to recommend annual waivers based on substantial promotion of free emigration. Subsection 2432(c) sets out the congressional joint resolution process for disapproval. Jackson-Vanik has been graduated for most former Soviet-bloc countries and is now narrowly applied; Russia was graduated by the Magnitsky Act in 2012, leaving Belarus, North Korea, Cuba, Turkmenistan, Uzbekistan among the few remaining countries subject to ongoing waiver review.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-trade-act-1974-19-usc-ch12",
      "us-iran-sanctions-act-1996-pl-104-172"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-jobs-act-2012-pl-112-106",
    "title": "JOBS Act 2012 - Public Law 112-106 Jumpstart Our Business Startups",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Jumpstart Our Business Startups Act of 2012 (JOBS Act, Public Law 112-106, enacted 5 April 2012) restructured the US securities-offering regime to lower compliance burdens on small and emerging issuers and to expand access to capital. Title I (Emerging Growth Companies) creates the EGC category defined as an issuer with less than 1 billion USD total annual gross revenues in its most recent fiscal year, with status terminating on the earliest of reaching 1 billion USD in revenues, five years post-IPO, issuing more than 1 billion USD non-convertible debt over three years, or becoming a large accelerated filer; EGCs benefit from reduced disclosure obligations including two years of audited financial statements for IPO, exemption from executive compensation disclosure rules, exemption from Sarbanes-Oxley section 404(b) internal control audits during the EGC window, and confidential submission of draft registration statements. Title II amended Securities Act Rule 506 to permit general solicitation in private offerings provided all purchasers are accredited investors (Rule 506(c)) with verification of accredited status under SEC-determined methods. Title III (CROWDFUND Act) creates an exemption for crowdfunding offerings up to 5 million USD aggregate per twelve-month period (as raised by 2020 amendments) with individual investor limits, mandatory use of registered broker-dealers or funding portals, and one-year transfer restrictions. Title IV (Regulation A+) created a tiered Regulation A framework. Title V raised the Exchange Act Section 12(g) registration threshold. Title VI eased savings-institution issuer requirements. Title VII directed SEC studies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-securities-act-1933",
      "us-securities-exchange-act-1934"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-jones-act-1920",
    "title": "Merchant Marine Act of 1920, Section 27 (Jones Act): Coastwise Trade Laws and US-Flag Vessel Requirements",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Jones Act, codified at 46 U.S.C. § 55102, mandates that all goods transported by water between two points in the United States (coastwise trade) must be carried on vessels that are U.S.-flagged, U.S.-built, U.S.-owned, and U.S.-crewed. This applies to any entity shipping merchandise via maritime routes within the U.S.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "c-tpat-minimum-security",
      "iso-28000-supply-chain",
      "imo-solas-safety-at-sea",
      "imo-stcw-seafarer-training",
      "isps-code-vessel-security"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-jones-act-cabotage-46-usc-55102",
    "title": "46 U.S.C. § 55102 - Vessels Required To Be Built in the United States for Coastwise Trade",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "46 U.S.C. § 55102 mandates that vessels engaged in coastwise trade - the transportation of merchandise or passengers between points in the United States - must be U.S.-built, U.S.-owned, U.S.-flagged, and crewed by U.S. citizens. This applies to domestic routes including those serving Puerto Rico, Hawaii, and Alaska, with limited exemptions for dredges and certain passenger vessels under MARAD-administered waivers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-juvenile-justice-delinquency-prevention-act-34-usc-11101",
    "title": "US Juvenile Justice and Delinquency Prevention Act (34 USC 11101) - Federal Standards and Funding for State Juvenile Justice",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Juvenile Justice and Delinquency Prevention Act establishes federal standards conditioning state receipt of formula grants on compliance with four core protections, namely deinstitutionalisation of status offenders, separation of juveniles from sight and sound contact with incarcerated adults, removal of juveniles from adult jails and lockups absent qualifying exceptions, and reduction of racial and ethnic disparities, creates the Office of Juvenile Justice and Delinquency Prevention within the Department of Justice, authorises research and information dissemination on juvenile justice, and funds prevention and intervention programs to reduce juvenile crime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-civil-rights-act-1964-title-vi-42-usc-2000d"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-kansas-sports-wagering-act-2022",
    "title": "Kansas Sports Wagering Act 2022 (SB 84) - KRGC Licensing and 10% Tax",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Kansas Senate Bill 84 (signed May 12, 2022) enacted the Kansas Sports Wagering Act at K.S.A. 74-9801 et seq., authorising sports wagering regulated by the Kansas Racing and Gaming Commission (KRGC). The tax rate is 10% of adjusted gross sports wagering receipts. The minimum age is 21. Kansas launched retail and online/mobile sports betting simultaneously on September 1, 2022. The Kansas model is built around lottery gaming facilities and management contract companies licensed under the Kansas Expanded Lottery Act. Geolocation, self-exclusion, and responsible gaming controls are mandatory under KRGC licence conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_paspa_repeal",
        "us_uigea_2006",
        "kansas_expanded_lottery_act",
        "fatf_gambling",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
      "us-uigea-2006-unlawful-internet-gambling",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-kentucky-cdpa-2024",
    "title": "Kentucky Consumer Data Protection Act (KY CDPA) 2024",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The Kentucky Consumer Data Protection Act (KY CDPA) was enacted as Kentucky House Bill 15 (HB 15) and signed into law by Governor Andy Beshear on 4 April 2024, effective 1 January 2026. The KY CDPA establishes consumer data privacy rights and controller obligations for businesses processing personal data of Kentucky residents. The law is closely modelled on the Virginia Consumer Data Protection Act (CDPA) and follows a similar structure and threshold-based applicability framework. The KY CDPA applies to persons who conduct business in Kentucky or produce products or services targeted to Kentucky residents and who during a calendar year either control or process personal data of at least 100,000 consumers, or control or process personal data of at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data. The KY CDPA grants Kentucky consumers the right to access, correct, delete, and obtain a portable copy of their personal data, and the right to opt out of processing for targeted advertising, sale of personal data, and profiling in furtherance of solely automated decisions with legal or similarly significant effects. Controllers must provide a privacy notice, obtain consent for sensitive data processing, conduct data protection assessments for high-risk activities, and implement reasonable data security practices. The Kentucky Attorney General has exclusive enforcement authority with civil penalties of up to $7,500 per violation. There is no private right of action. Controllers are entitled to a 30-day cure period following notice of a potential violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-kentucky-cdpa-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-kingpin-act-1999-21-usc-1901",
    "title": "US Foreign Narcotics Kingpin Designation Act (21 USC 1901) - Sanctions on Significant Foreign Narcotics Traffickers",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Foreign Narcotics Kingpin Designation Act authorises the President to designate foreign individuals and entities as significant foreign narcotics traffickers playing a significant role in international narcotics trafficking, blocks all property and interests in property of designated parties within United States jurisdiction, prohibits any transaction or dealing by United States persons with designated parties, authorises civil penalties up to ten million dollars and criminal penalties for willful violations including imprisonment, and is administered by the Office of Foreign Assets Control which maintains the public list of designated parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-31-cfr-598-foreign-narcotics-kingpin-sanctions-regulations",
      "us-bank-secrecy-act-1970"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-kosa-kids-online-safety-act-s-1409",
    "title": "US Kids Online Safety Act (KOSA) - S.1409 118th Congress",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The Kids Online Safety Act (KOSA), S.1409 in the 118th Congress, establishes federal duties for covered online platforms used by minors. Section 2 defines minor as an individual under 17 and child as under 13, and defines covered platform broadly to include social media messaging video-streaming and online-game services with exceptions for common carriers nonprofits schools and B2B software. Section 3 imposes a duty of care requiring platforms to act in the best interests of a user the platform knows or reasonably should know is a minor and to take reasonable measures to prevent and mitigate harms including mental health disorders addictive-feature patterns bullying sexual exploitation and promotion of harmful substances. Section 4 requires accessible safeguards for minors: tools to limit communications restrict data visibility control engagement features manage recommendation systems and control geolocation sharing; parental controls and reporting mechanisms are also required. Section 11 vests enforcement in the Federal Trade Commission under FTC Act unfair-or-deceptive-acts authority with concurrent state attorney general civil-action authority on behalf of residents. KOSA passed the US Senate 91-3 in July 2024 and remains pending House action as of session date.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "coppa_overlap",
        "ftc_act_authority",
        "first_amendment_litigation",
        "state_law_overlap",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-childrens-online-privacy-protection-act"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ky-cdpa-2024",
    "title": "Kentucky Consumer Data Protection Act 2024 (HB 15)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Kentucky HB 15 signed March 24, 2024 effective January 1, 2026 grants Kentucky consumers rights to access, correct, delete, and port personal data, requires opt-in consent for sensitive data processing, and provides a 30-day cure period with civil penalties up to USD 7,500 per violation enforced exclusively by the Attorney General.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ky-cdpa-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-labor-management-relations-act",
    "title": "US Labor Management Relations Act / Taft-Hartley (29 USC ch 7): Union Practices and Boycotts",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Labor Management Relations Act of 1947, the Taft-Hartley Act (29 U.S.C. ch. 7), amended the National Labor Relations Act and added provisions regulating union conduct and labor-management disputes, with unfair labor practice matters before the National Labor Relations Board and certain claims in the Federal courts. Section 141 sets out the findings and policy, balancing the rights of employees, employers and the public. Section 158(b), added by the Act, defines union unfair labor practices, including restraining or coercing employees in their rights, causing an employer to discriminate, refusing to bargain, and engaging in prohibited secondary boycotts and certain strikes. Section 185 authorizes suits in Federal district court for violation of collective bargaining agreements between an employer and a labor organization. Section 186 restricts payments and loans by employers to employee representatives and labor organizations, with exceptions for bona fide arrangements such as trust funds. Section 187 makes it unlawful for a labor organization to engage in the secondary boycott conduct described in section 158(b)(4), and gives any person injured in business or property by such conduct the right to sue in any district court of the United States, without regard to the amount in controversy, and to recover the damages sustained and the cost of the suit. Sections 176 to 180 provide for the handling of national emergency labor disputes. The Act is the legal foundation for US regulation of union conduct and collective agreement enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-labor-management-reporting-and-disclosure-act",
    "title": "US Labor-Management Reporting and Disclosure Act / Landrum-Griffin (29 USC ch 11): Union Democracy and Reporting",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Labor-Management Reporting and Disclosure Act of 1959, the Landrum-Griffin Act (29 U.S.C. ch. 11), protects the rights of union members and imposes reporting and fiduciary duties on labor organizations and their officers, administered by the Department of Labor Office of Labor-Management Standards. Section 411 sets out the bill of rights of members of labor organizations: members have equal rights to nominate candidates, vote and participate in the business of the organization subject to reasonable rules; freedom of speech and assembly; protection against unreasonable increases in dues, which require a secret ballot vote; and safeguards against improper discipline, so that a member may not be fined, suspended, expelled or otherwise disciplined except for nonpayment of dues unless served with written specific charges, given a reasonable time to prepare, and afforded a full and fair hearing. Section 412 allows a member whose rights are infringed to bring a civil action. Section 431 requires labor organizations to file annual financial reports, and section 433 requires reports by employers and labor relations consultants. Section 481 establishes standards for the conduct of union officer elections, and section 501 imposes fiduciary responsibility on union officers, making the embezzlement of union funds a Federal crime. The Act is the legal foundation for US union democracy and financial transparency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-lacey-act",
    "title": "US Lacey Act (16 USC ch 53): Prohibition on Trafficking in Illegally Taken Fish, Wildlife and Plants",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Lacey Act, as amended and codified at 16 U.S.C. Chapter 53 (sections 3371-3378), is the principal US statute combating trafficking in illegally taken fish, wildlife and plants, enforced by the US Fish and Wildlife Service, NOAA Fisheries and (for plants) the USDA Animal and Plant Health Inspection Service. Section 3371 defines the regulated terms, including 'fish or wildlife', 'plant', and 'taken'. Section 3372 sets the prohibited acts: it is unlawful for any person to import, export, transport, sell, receive, acquire or purchase any fish or wildlife or plant taken, possessed, transported or sold in violation of any law, treaty or regulation of the United States or in violation of any Indian tribal law (section 3372(a)(1)); to import, export, transport, sell, receive, acquire or purchase in interstate or foreign commerce any fish or wildlife taken in violation of any State or foreign law, or any plant taken in violation of law or without required authorization or payment of required fees (section 3372(a)(2)); and, under section 3372(d), to make or submit any false record, account or label for, or any false identification of, fish, wildlife or plants that have been or are intended to be imported, exported, transported, sold, purchased or received. Section 3372(f) requires an import declaration for plants and plant products. Section 3373 sets the penalties: a civil penalty of not more than $10,000 for each violation; a criminal felony punishable by a fine of not more than $20,000 or imprisonment of not more than five years, or both, for a knowing violation involving import or export or a sale or purchase of fish, wildlife or plants with a market value in excess of $350; and a criminal misdemeanor punishable by a fine of not more than $10,000 or imprisonment of not more than one year, or both, where the violator in the exercise of due care should have known of the underlying violation. Section 3374 provides for forfeiture of the fish, wildlife or plants and of vessels, vehicles and equipment used, and section 3375 sets out enforcement authority. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-lanham-act",
    "title": "US Lanham Act (15 USC ch 22): Trademark Registration, Infringement and False Designation of Origin",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Lanham Act (15 U.S.C. ch. 22) is the principal US federal trademark statute, governing the registration and protection of trademarks and the law of unfair competition, administered for registration by the United States Patent and Trademark Office (USPTO). Section 1051 sets out how an applicant applies to register a mark, including use-based and intent-to-use applications. Section 1052 states which marks are registrable on the principal register and the bars to registration, such as marks that are merely descriptive or likely to cause confusion. Section 1057 governs certificates of registration and their evidentiary effect, and section 1058 requires maintenance affidavits and fees to keep a registration alive. Section 1064 provides for cancellation of a registration and section 1065 provides for incontestability of a right to use a mark after five years of continuous use. Section 1072 makes registration constructive notice of the registrant's claim of ownership. On enforcement, section 1114 provides remedies for infringement of a registered mark, section 1117 provides for the recovery of profits, damages and costs (and, in exceptional cases, treble damages and attorney fees), and section 1125 addresses false designations of origin, false descriptions, and trademark dilution, including claims available without registration. The Act is the legal foundation of US trademark rights, brand protection and unfair-competition litigation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-lanham-act-15-usc-ch22",
    "title": "United States Lanham Act / Trademark Act of 1946 (Title 15 USC Chapter 22): Principal Register Registration, Cancellation and Opposition, Infringement Remedies, False Designations of Origin and Dilution, and Madrid Protocol",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Lanham Act, also known as the Trademark Act of 1946 and codified at Title 15 of the United States Code, Chapter 22, is the principal federal statute governing trademarks, service marks, and unfair competition in the United States and is administered by the United States Patent and Trademark Office and enforced through the federal courts. Lanham Act, 15 U.S.C. 1051 provides that the owner of a trademark used in commerce may request registration by paying the prescribed fee and filing an application and a verified statement with the Director. Lanham Act, 15 U.S.C. 1052 sets out the grounds for refusal of registration on the principal register and the conditions for concurrent registration. Lanham Act, 15 U.S.C. 1057 provides that certificates of registration of marks registered upon the principal register shall be issued in the name of the United States and shall be signed by the Director. Lanham Act, 15 U.S.C. 1063 governs opposition to registration and Lanham Act, 15 U.S.C. 1064 governs cancellation of registration. Lanham Act, 15 U.S.C. 1114 sets out the remedies for trademark infringement including innocent infringement by printers and publishers. Lanham Act, 15 U.S.C. 1125 prohibits false designations of origin, false descriptions, and dilution by tarnishment or blurring of a famous mark. Lanham Act, 15 U.S.C. 1127 contains the construction and definitions and states the intent of the chapter. Subchapter I covers the Principal Register, Subchapter II the Supplemental Register, Subchapter III general provisions including infringement remedies and international matters, and Subchapter IV the Madrid Protocol international registration framework in sections 1141 through 1141n. The Act is the controlling federal instrument for trademark protection in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-lanham-act-1946-trademark-section-43a",
    "title": "Lanham Act Section 43(a) - False Designation of Origin, False Advertising, and Trade Dress Protection",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "Prohibits false or misleading representations of fact in commercial advertising or promotion that misidentify the source of goods or services or misrepresent their nature, characteristics, or qualities, under 15 U.S.C. § 1125(a). Applies to all entities engaged in interstate commerce using misleading branding, advertising, or trade dress.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dmca-safe-harbor",
      "copyright-fair-use-us",
      "iptc-photo-metadata",
      "iptc-video-metadata",
      "c2pa-content-provenance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-lead-paint-hazard-reduction-renovation-rule",
    "title": "US EPA Lead-Based Paint Renovation, Repair and Painting Rule (40 CFR Part 745, Subpart E)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This rule requires firms performing renovation, repair, and painting projects that disturb lead-based paint in target housing (pre-1978 homes) and child-occupied facilities to be certified by the EPA, use certified renovators, and follow specific lead-safe work practices to prevent lead contamination, as mandated by 40 CFR § 745.81.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-lead-paint-renovation-epa-40-cfr-745",
    "title": "Lead Renovation, Repair and Painting Rule (40 CFR Part 745, Subpart E) - Requirements for Firms, Renovators, and Dust Sampling Technicians in Target Housing and Child-Occupied Facilities",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The EPA's Lead Renovation, Repair and Painting Rule (40 CFR Part 745, Subpart E) requires that all renovation, repair, and painting activities disturbing lead-based paint in pre-1978 housing and child-occupied facilities be performed by EPA-certified firms using lead-safe work practices. The rule mandates firm certification, renovator training, occupant education, containment procedures, and post-renovation cleaning verification, with clearance testing required in certain cases (40 CFR §745.85).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-leed-arc-performance-platform-construction",
    "title": "LEED Arc Performance Platform - Ongoing Building Performance Measurement: Energy, Water, Waste, Transport, Human Experience Data Scoring and Re-Certification Requirements",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation requires building operators to measure, score, and report operational performance across energy, water, waste, transportation, and human experience using the Arc platform to support LEED certification and recertification. Compliance is demonstrated through continuous data input and achievement of performance benchmarks within the Arc Performance Score framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-50001-2018-energy-management-systems",
      "us-ada-accessibility-guidelines-2010-aba",
      "icc-700-national-green-building-standard-2020"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-lifeline-program-low-income-broadband",
    "title": "US FCC Lifeline Program Rules - Affordable Connectivity for Low-Income Consumers and Broadband Benefit Eligibility",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The FCC's Lifeline program requires Eligible Telecommunications Carriers (ETCs) to provide a monthly discount on qualifying broadband or voice services to low-income households. As specified in 47 C.F.R. § 54.409, eligibility is determined by consumer income at or below 135% of the Federal Poverty Guidelines or participation in specific federal assistance programs like SNAP, Medicaid, or Federal Public Housing Assistance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-lilly-ledbetter-fair-pay-act-2009",
    "title": "United States Lilly Ledbetter Fair Pay Act of 2009 (Public Law 111-2): Title VII Amendments Clarifying Discriminatory Compensation Decisions, ADEA Amendments, ADA and Rehabilitation Act Amendments, Effective Date, and Retroactive Application to Pending Cases",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Lilly Ledbetter Fair Pay Act of 2009, Public Law 111-2 of 29 January 2009, is the federal statute restoring the prior law of pay discrimination after the Supreme Court decision in Ledbetter v. Goodyear Tire Rubber Co. (2007) by amending Title VII of the Civil Rights Act of 1964, the Age Discrimination in Employment Act of 1967, the Americans with Disabilities Act of 1990, and the Rehabilitation Act of 1973 to clarify that the time limit for filing a discrimination claim resets with each discriminatory paycheck, and is administered by the Equal Employment Opportunity Commission. Lilly Ledbetter Fair Pay Act, section 3 amends Title VII of the Civil Rights Act of 1964 (42 U.S.C. 2000e-5(e)) by clarifying that an unlawful employment practice occurs, with respect to discrimination in compensation, when a discriminatory compensation decision or other practice is adopted, when an individual becomes subject to a discriminatory compensation decision or other practice, or when an individual is affected by application of a discriminatory compensation decision or other practice, including each time wages, benefits, or other compensation is paid resulting in whole or in part from such a decision or other practice. Lilly Ledbetter Fair Pay Act, section 4 adds identical language to the Age Discrimination in Employment Act (29 U.S.C. 626(d)) for compensation discrimination claims. Lilly Ledbetter Fair Pay Act, section 5(a) extends the Title VII amendments to the Americans with Disabilities Act of 1990 (42 U.S.C. 12117). Lilly Ledbetter Fair Pay Act, section 5(b) extends the Title VII amendments to the Rehabilitation Act of 1973 (29 U.S.C. 791 and 794a). Lilly Ledbetter Fair Pay Act, section 6 provides that the Act takes effect as if enacted on 28 May 2007 and applies to all claims of discrimination in compensation under the affected statutes that are pending on or after that date. The Act is the controlling federal instrument for the limitations period applicable to pay discrimination claims under Title VII, ADEA, ADA, and the Rehabilitation Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-lime-promotion-research-information-act",
    "title": "US Lime Promotion, Research, and Consumer Information Act of 1990 (7 USC ch 91): Lime Board and Assessments",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Lime Promotion, Research, and Consumer Information Act of 1990 (7 U.S.C. ch. 91, sections 6201 to 6212) authorizes a coordinated program of research, promotion, and consumer information for limes funded by assessments, administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 6201 sets out the findings, purposes, and limitations, determining that domestically produced limes are grown by many individual producers and that a coordinated program of research, promotion, and consumer information regarding limes is necessary. Section 6202 defines the terms, providing that lime means the fruit of a citrus latifolia tree for the fresh market, and section 6203 authorizes the issuance of orders. Section 6204 sets the required terms in orders, providing for the establishment of a Board comprising 3 members who are producers, 3 members who are importers, and one member appointed from the general public, and providing that the assessment rate shall not exceed 0.01 dollars per pound of limes. Section 6205 sets the permissive terms, section 6206 provides for petition and review, section 6207 provides for enforcement, including a civil penalty of not less than 500 dollars nor more than 5,000 dollars for each violation, and section 6208 provides investigations and power to subpoena. Section 6209 requires an initial referendum not later than 30 months after the date on which the collection of assessments begins, and section 6210 provides for suspension and termination. The Act is the federal checkoff regime for limes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-lobbying-disclosure-act-2-usc-ch26",
    "title": "Lobbying Disclosure Act 1995 - 2 USC Chapter 26 Disclosure of Lobbying Activities",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Chapter 26 of title 2 of the United States Code (sections 1601 through 1614) codifies the Lobbying Disclosure Act of 1995, as amended by the Honest Leadership and Open Government Act of 2007, requiring registration with the Secretary of the Senate and the Clerk of the House by individuals and entities engaged in lobbying activities directed at covered legislative or executive branch officials. Section 1603 requires lobbyists to register within 45 days of the earlier of when they first make a lobbying contact or are employed to make such contact, with no obligation to register if total income or expenses for lobbying activities fall below the de minimis thresholds prescribed in the Act and inflation-adjusted by the Secretary of the Senate. Section 1604 requires quarterly disclosure reports detailing the issues lobbied, the houses of Congress and federal agencies contacted, the names of any lobbyists who acted on the client's behalf, and a good-faith estimate of total income or expenses. Section 1605 requires semi-annual reports on certain campaign and other contributions. Section 1606 provides civil penalties of up to 200,000 USD and criminal penalties of up to five years imprisonment for knowing and corrupt violations. The Act establishes the official lobbying disclosure regime that supplements the Foreign Agents Registration Act and integrates with House and Senate ethics rules; AI agents that prepare or transmit communications to covered officials must record their lobbying activity inputs and outputs to support accurate quarterly and semi-annual reporting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-stock-act-2012-pl-112-105"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-long-term-care-insurance-rate-stability-model-641",
    "title": "NAIC Long-Term Care Insurance Model Regulation 641 - Rate Stability Standards, Contingent Nonforfeiture and Benefit Triggers",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-10-25",
    "bluf": "This model regulation establishes standards for long-term care insurance rate stability, requiring insurers to submit an actuarial certification with initial filings and justify any subsequent rate increases based on specific loss ratio experience (Section 6). It also mandates offering contingent nonforfeiture benefits to policyholders facing substantial premium increases and standardizes benefit triggers (Sections 8 & 9).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-longshore-and-harbor-workers-compensation-act",
    "title": "US Longshore and Harbor Workers' Compensation Act (33 USC ch 18): Maritime Workers' Compensation",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Longshore and Harbor Workers' Compensation Act (33 U.S.C. ch. 18) provides a no-fault workers' compensation system for maritime workers injured on the navigable waters of the United States and adjoining areas such as piers and terminals, administered by the Department of Labor Office of Workers' Compensation Programs. Section 904 makes every employer liable for and required to secure the payment of compensation to its employees, and provides that compensation is payable irrespective of fault as a cause of the injury; where a subcontractor fails to secure payment, the general contractor is liable. Section 905 makes the compensation liability exclusive and in place of all other liability of the employer to the employee, subject to the employee's right to sue a negligent vessel under section 905(b). Section 908 sets the compensation for disability, including schedules for permanent partial disability, and section 909 covers death benefits. Section 907 provides medical benefits. Section 919 sets the procedure for claims before an administrative law judge, and section 921 provides for review. Section 932 requires the employer to secure compensation through insurance or self-insurance, and section 948a prohibits discrimination against an employee who claims or testifies. The Act is the legal foundation for US maritime workers' compensation, distinct from the Jones Act remedy for seamen.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ma-data-security-2010",
    "title": "Massachusetts Data Security Regulations 201 CMR 17.00",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Massachusetts 201 CMR 17.00 requires any person or entity holding personal information of Massachusetts residents to implement a comprehensive written information security program, mandates encryption of portable devices and transmitted data, and is enforced by the Massachusetts AG with penalties up to USD 5,000 per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ma-data-security-2010.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cpra-california-privacy-rights-act-2020",
      "us-ny-shield-act-2019"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-magnuson-moss-warranty-act",
    "title": "US Magnuson-Moss Warranty Act (15 USC ch 50): Consumer Product Warranties",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Magnuson-Moss Warranty Act (15 U.S.C. ch. 50) governs written warranties on consumer products, administered by the Federal Trade Commission. Section 2302 authorizes rules governing the content and disclosure of warranty terms, requiring that a written warranty fully and conspicuously disclose its terms in simple and readily understood language, and authorizing a pre-sale availability rule. Section 2303 requires a warrantor that gives a written warranty on a consumer product costing more than a threshold amount to designate the warranty conspicuously as full or limited. Section 2304 sets the federal minimum standards a full warranty must meet: the warrantor must remedy a defective product within a reasonable time and without charge, may not impose any limitation on the duration of an implied warranty, may not exclude or limit consequential damages unless the exclusion appears conspicuously on the face of the warranty, and must permit the consumer to elect a refund or replacement after a reasonable number of repair attempts. Section 2308 restricts the disclaimer of implied warranties, and section 2310 provides the remedies, including a private right of action by a consumer damaged by a warrantor's failure to comply, with attorney fees. The Act is the legal foundation for US consumer product warranty disclosure and fairness.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-magnuson-moss-warranty-act-15-usc-ch50",
    "title": "United States Magnuson-Moss Warranty Act (Title 15 USC Chapter 50): Consumer Product Warranties, Federal Minimum Standards, Designation of Full or Limited Warranty, Implied Warranties, and Remedies in Consumer Disputes",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Magnuson-Moss Warranty Act, also titled the Magnuson-Moss Warranty Federal Trade Commission Improvement Act and codified at Title 15 of the United States Code, Chapter 50, is the principal federal statute governing written warranties on consumer products sold for purposes other than resale and is enforced by the Federal Trade Commission. Magnuson-Moss Warranty Act, 15 U.S.C. 2301 contains the definitions, including that the term consumer product means any tangible personal property normally used for personal, family, or household purposes. Magnuson-Moss Warranty Act, 15 U.S.C. 2302 governs the rules governing contents of warranties, requiring warrantors to clearly and conspicuously disclose specified warranty terms in order to improve the adequacy of information available to consumers, prevent deception, and improve competition in the marketing of consumer products. Magnuson-Moss Warranty Act, 15 U.S.C. 2303 requires designation of written warranties as either full or limited. Magnuson-Moss Warranty Act, 15 U.S.C. 2304 sets the federal minimum standards for full warranties. Magnuson-Moss Warranty Act, 15 U.S.C. 2305 governs full and limited warranting of consumer products. Magnuson-Moss Warranty Act, 15 U.S.C. 2306 covers service contracts. Magnuson-Moss Warranty Act, 15 U.S.C. 2307 covers designation of representatives by warrantor. Magnuson-Moss Warranty Act, 15 U.S.C. 2308 prohibits a supplier from disclaiming or modifying any implied warranty to a consumer with respect to a consumer product (except where a written warranty is a limited warranty disclaiming implied warranties for a defined duration consistent with the implied warranty law of the State). Magnuson-Moss Warranty Act, 15 U.S.C. 2310 governs remedies in consumer disputes including the policy to encourage informal dispute settlement procedures. Magnuson-Moss Warranty Act, 15 U.S.C. 2311 provides that nothing contained in this chapter shall be construed to repeal, invalidate, or supersede the Federal Trade Commission Act. The Act is the controlling federal instrument for consumer product warranty obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-magnuson-stevens-fishery-conservation-and-management-act",
    "title": "US Magnuson-Stevens Fishery Conservation and Management Act (16 USC ch 38): Federal Fishery Management and the EEZ",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Magnuson-Stevens Fishery Conservation and Management Act (16 U.S.C. ch. 38) is the primary federal statute governing the management of marine fisheries in US federal waters, administered by the National Marine Fisheries Service of NOAA. Section 1801 sets the findings, purposes and policy, including conserving and managing fishery resources and preventing overfishing while achieving optimum yield. Section 1802 supplies the definitions, including overfishing and optimum yield. Section 1811 declares the sovereign rights of the United States to fish and its fishery-management authority within the exclusive economic zone (generally out to 200 nautical miles). Section 1851 sets the ten national standards for fishery conservation and management, including that conservation measures prevent overfishing, be based on the best scientific information available, and not discriminate among residents of different States. Section 1852 establishes the eight Regional Fishery Management Councils, and section 1853 sets the required and discretionary contents of fishery management plans. Enforcement is direct: section 1857 lists the prohibited acts, section 1858 provides civil penalties for violations, and section 1859 provides criminal offenses. The Act is the legal foundation of US federal fishery management, the prevention of overfishing, and the regional-council planning system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-mail-fraud-18-usc-1341",
    "title": "Mail Fraud - 18 USC 1341 Frauds and Swindles by Postal or Private Carrier",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 1341 of title 18 of the United States Code criminalises any scheme or artifice to defraud or to obtain money or property by means of false or fraudulent pretenses, representations, or promises, where the actor places in any post office or authorised depository for mail matter any matter or thing whatever to be sent or delivered by the Postal Service, or takes or receives such matter, or knowingly causes such matter to be delivered by mail or by any private or commercial interstate carrier, for the purpose of executing the scheme. The standard penalty is up to 20 years imprisonment or a fine, with enhanced penalties of up to 30 years imprisonment or a fine of up to 1,000,000 USD where the violation affects a financial institution or relates to benefits authorised by the President in connection with a declared major disaster or emergency. Section 1341 is the historical anchor of the federal white-collar criminal code, predating the wire-fraud statute by 80 years, and the legal interpretation developed under section 1341 directly informs section 1343 (wire fraud), section 1346 (honest services), and section 1347 (health care fraud). Mail-fraud charging reaches AI-assisted advance-fee fraud, deceptive direct-mail marketing, fraudulent insurance claims, securities-fraud schemes involving printed materials sent through the postal system, and elder-fraud schemes using mailed solicitations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-wire-fraud-18-usc-1343",
      "us-money-laundering-control-act-18-usc-1956"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-maine-isa-2019",
    "title": "Maine Act to Protect the Privacy of Online Consumer Information 2019",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Maine's Act to Protect the Privacy of Online Consumer Information requires internet service providers to obtain opt-in consent before using, selling, or disclosing customer personal information, prohibits ISPs from withholding service based on consent status, and is enforced by the Maine Attorney General.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-maine-isa-2019.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cpra-california-privacy-rights-act-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-manufactured-housing-construction-and-safety-standards-act",
    "title": "US Manufactured Housing Construction and Safety Standards Act (42 USC ch 70): Federal HUD Code and Penalties",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The National Manufactured Housing Construction and Safety Standards Act of 1974 (42 U.S.C. ch. 70) establishes federal construction and safety standards for manufactured homes, administered by the Department of Housing and Urban Development (the HUD Code). Section 5401 sets the findings and purposes of reducing deaths, injuries and property damage and improving the quality and durability of manufactured homes. Section 5402 supplies the definitions, including manufactured home. Section 5403 authorizes the Secretary to establish federal manufactured home construction and safety standards that preempt differing state standards. Section 5404 addresses manufactured home installation standards. Section 5407 provides for research, testing and training, and section 5409 lists the prohibited acts, including the manufacture or sale of a home that fails to conform to an applicable standard. Section 5410 sets the civil and criminal penalties: a civil penalty not to exceed 1,000 dollars for each violation, with a maximum of 1,000,000 dollars for any related series of violations occurring within one year, alongside criminal liability for knowing and willful violations. Section 5412 provides the remedies for noncompliant or defective homes, including repurchase or repair, and section 5414 requires the manufacturer to notify and correct defects. The Act is the legal foundation of the federal HUD Code for manufactured housing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-marine-mammal-protection-act",
    "title": "US Marine Mammal Protection Act (16 USC ch 31): Take Moratorium, Permits and Incidental Take in Fishing",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Marine Mammal Protection Act (MMPA), codified at 16 U.S.C. Chapter 31 (sections 1361-1423h), establishes a moratorium on the taking and importation of marine mammals and marine mammal products, administered by the National Marine Fisheries Service (within NOAA, Department of Commerce) for most species and by the US Fish and Wildlife Service (Department of the Interior) for others. Section 1361 states the findings and policy, and section 1362 defines the regulated terms, including 'take' (to harass, hunt, capture or kill, or attempt to do so) and 'marine mammal product'. Section 1371 establishes the moratorium: there shall be a moratorium on the taking and importation of marine mammals and marine mammal products, subject to enumerated exceptions and authorizations. Section 1372 sets the prohibited acts, making it unlawful to take any marine mammal on the high seas or in waters or on lands under US jurisdiction, to use a vessel or other means under US jurisdiction to take a marine mammal on the high seas, to import any marine mammal or marine mammal product into the United States, or to possess, transport, sell or offer for sale any marine mammal or product taken in violation of the Act. Section 1373 authorizes regulations on taking, and section 1374 governs permits (including for scientific research, public display and enhancing the survival of a species). Section 1387 governs the taking of marine mammals incidental to commercial fishing operations, including the registration and authorization scheme and take-reduction plans. Section 1375 sets the penalties: a person who violates the Act may be assessed a civil penalty of not more than $10,000 for each violation, and a person who knowingly violates the Act shall, on conviction, be fined not more than $20,000 for each violation, or imprisoned for not more than one year, or both. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-marine-protection-research-sanctuaries-act-1972",
    "title": "US Marine Protection Research and Sanctuaries Act 1972 - Ocean Dumping Act EPA Permit Programme and National Marine Sanctuaries",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Marine Protection, Research, and Sanctuaries Act of 1972 (MPRSA, Public Law 92-532, enacted 23 October 1972), commonly known as the Ocean Dumping Act, is the principal US federal statute regulating the transportation and dumping of material into ocean waters. Title I (33 USC 1401-1421) regulates ocean dumping and is administered by the US Environmental Protection Agency (EPA) for non-dredged material and the US Army Corps of Engineers (USACE) for dredged material under EPA criteria. Title II (33 USC 1441-1445) authorises ocean research administered by NOAA. Title III (16 USC 1431-1445c, originally Title III of MPRSA, now restated as the National Marine Sanctuaries Act) authorises the National Marine Sanctuary System administered by NOAA. Section 102 (33 USC 1412) prohibits ocean dumping without permit; Section 104 (33 USC 1414) creates EPA and USACE permit authority; Section 105 (33 USC 1415) provides civil penalties up to USD 50,000 per violation and criminal penalties for knowing violations. EPA Ocean Dumping Criteria at 40 CFR Parts 220-229 govern permit issuance. Dredged material disposal at 103 ocean disposal sites covers most permitted ocean dumping today; industrial waste, sewage sludge and radioactive waste dumping prohibited since 1988.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-maryland-online-data-privacy-act-2024",
    "title": "Maryland Online Data Privacy Act of 2024",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2025-10-01",
    "bluf": "The Maryland Online Data Privacy Act of 2024 requires controllers to limit personal data collection to what is adequate, relevant, and reasonably necessary for disclosed purposes (data minimization and purpose limitation) and strictly prohibits the processing of sensitive data without obtaining the consumer's consent, as mandated by § 14-4505. The Act applies to entities conducting business in Maryland or targeting Maryland residents that control or process personal data of at least 35,000 consumers or derive over 20% of gross revenue from selling personal data of at least 10,000 consumers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "california-ccpa-v2",
      "gdpr-article-35-dpia",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-massachusetts-sports-wagering-act-2022",
    "title": "Massachusetts Sports Wagering Act 2022 - Chapter 23N Mobile and Retail Licensing",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Massachusetts Chapter 126 of the Acts of 2022 (signed August 10, 2022) creates M.G.L. c. 23N and authorises sports wagering regulated by the Massachusetts Gaming Commission (MGC). Tax rates are 15% on retail gross gaming revenue and 20% on mobile/online gross gaming revenue. Minimum wagering age is 21. Retail sports betting launched January 31, 2023; mobile/online launched March 10, 2023. Sports betting is offered at licensed gaming establishments and through licensed mobile operators partnering with those facilities. Self-exclusion is mandatory and operators must maintain geolocation controls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_paspa_repeal",
        "us_uigea_2006",
        "us_arizona_comparable",
        "fatf_gambling",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
      "us-uigea-2006-unlawful-internet-gambling",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-master-file-local-file-oecd-beps-action-13",
    "title": "OECD BEPS Action 13: Transfer Pricing Documentation and Country-by-Country Reporting - Master File, Local File, and CbC Report Requirements",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Multinational enterprises (MNEs) with annual consolidated revenue of EUR 750 million or more must prepare a Master File, Local File, and Country-by-Country Report (CbCR) to demonstrate compliance with the arm’s length principle under transfer pricing rules. These documents must be contemporaneous and available upon request by tax authorities, per Action 13 of the OECD BEPS Project, Chapter II and III.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-global-minimum-tax-directive-2022-2523-pillar-two",
      "eu-transfer-pricing-directive-proposal-2023",
      "canada-transfer-pricing-income-tax-act-section-247",
      "australia-transfer-pricing-laws-amendment-2012",
      "eu-public-cbcr-directive-2021-2101-tax-transparency"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-mccarran-ferguson-act",
    "title": "US McCarran-Ferguson Act (15 USC ch 20): State Regulation of Insurance and the Antitrust Exemption",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The McCarran-Ferguson Act (15 U.S.C. ch. 20) establishes that the regulation and taxation of the business of insurance is primarily a matter for the States, and provides a limited federal antitrust exemption for insurance, applied by the courts and the state insurance commissioners. Section 1011 declares the policy that the continued regulation and taxation by the several States of the business of insurance is in the public interest. Section 1012 implements that policy: subsection 1012(a) provides that the business of insurance is subject to state law, and subsection 1012(b) provides that no federal statute shall be construed to invalidate, impair or supersede a state law regulating insurance unless the federal statute specifically relates to the business of insurance, which is the source of the McCarran-Ferguson reverse-preemption doctrine. Section 1013 sets the antitrust position: subsection 1013(a) makes the Sherman Act, the Clayton Act and the Federal Trade Commission Act applicable to the business of insurance only to the extent that it is not regulated by state law, while subsection 1013(b) provides that the Sherman Act always applies to agreements or acts of boycott, coercion or intimidation, and subsection 1013(c), added by the Competitive Health Insurance Reform Act of 2020, withdraws the exemption for the business of health insurance. Section 1014 addresses the effect on other laws and section 1015 defines State. The Act is the legal foundation of the US state-based insurance regulatory system and its antitrust treatment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-mccarran-ferguson-act-15-usc-ch20",
    "title": "United States McCarran-Ferguson Act (Title 15 USC Chapter 20): Declaration of Policy, State Regulation and Taxation of Insurance, Sherman Act Applicability to Insurance, Effect on Other Laws, and Definitions",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The McCarran-Ferguson Act, codified at Title 15 of the United States Code, Chapter 20, is the foundational federal statute establishing state regulation of the business of insurance as the dominant regulatory regime in the United States and providing limited application of federal antitrust law to insurance. McCarran-Ferguson Act, 15 U.S.C. 1011 declares the policy of Congress that the continued regulation and taxation by the several States of the business of insurance is in the public interest. McCarran-Ferguson Act, 15 U.S.C. 1012 provides that the business of insurance, and every person engaged therein, shall be subject to the laws of the several States which relate to the regulation or taxation of such business, and that no federal Act shall be construed to invalidate, impair, or supersede any law enacted by any State for the purpose of regulating the business of insurance unless such Act specifically relates to the business of insurance, an exception known as the reverse-preemption doctrine. McCarran-Ferguson Act, 15 U.S.C. 1013 originally suspended until June 30, 1948 the application of certain Federal laws to insurance, with continuing relevance in that the Sherman Act applies to agreements to, or acts of, boycott, coercion, or intimidation in the business of insurance. McCarran-Ferguson Act, 15 U.S.C. 1014 provides that nothing contained in the chapter shall be construed to affect in any manner the application to the business of insurance of the National Labor Relations Act, the Fair Labor Standards Act, or the Merchant Marine Act. McCarran-Ferguson Act, 15 U.S.C. 1015 defines the term State as including the several States, Alaska, Hawaii, Puerto Rico, Guam, and the District of Columbia. The Act is the controlling federal instrument for the allocation of regulatory authority between the States and the federal government in the business of insurance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-mccarran-ferguson-act-1945-insurance-regulation",
    "title": "US McCarran-Ferguson Act 1945 - State Primacy in Insurance Regulation and Antitrust Exemption Framework",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-03-09",
    "bluf": "The McCarran-Ferguson Act establishes that the regulation of the business of insurance is primarily the responsibility of individual states, not the federal government. Under 15 U.S.C. § 1012(b), it grants a limited exemption from federal antitrust laws for activities that constitute the 'business of insurance,' are regulated by state law, and do not involve boycott, coercion, or intimidation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sherman-antitrust-act-sections-1-2",
      "us-hart-scott-rodino-hsr-premerger-notification"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-md-online-data-privacy-act-2024",
    "title": "Maryland Online Data Privacy Act 2024 (MODPA)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Maryland MODPA signed May 9, 2024 effective October 1, 2025 prohibits controllers from collecting sensitive personal data beyond what is strictly necessary to provide the requested service, extends children's privacy protections to all consumers under age 18, and bars sale of sensitive data without opt-in consent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-md-online-data-privacy-act-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-me-data-privacy-act-2019",
    "title": "Maine An Act To Protect the Privacy of Online Consumer Information 2019",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Maine LD 946 signed June 6, 2019 effective July 1, 2020 requires broadband internet service providers to obtain explicit opt-in consent before using, selling, or disclosing a customer's personal information, prohibits ISPs from conditioning service or charging higher rates based on consent decisions, and mandates reasonable data security measures for customer information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-me-data-privacy-act-2019.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-merchant-marine-act-1936-46-usc-50101",
    "title": "US Merchant Marine Act of 1936 (46 USC 50101) - National Maritime Policy and Maritime Administration",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Merchant Marine Act of 1936 declared that it is necessary for the national defense and the development of foreign and domestic commerce of the United States to have a merchant marine sufficient to carry waterborne export and import foreign commerce, established the Maritime Administration as the federal agency responsible for the United States maritime industry, authorises construction and operating differential subsidies for US flag carriers in foreign trade, supports the United States Merchant Marine Academy and state maritime academies, and operates the National Defense Reserve Fleet and the Ready Reserve Force to support defense sealift.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-jones-act-1920"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-mhpaea-2008-mental-health-parity-addiction-equity",
    "title": "US Paul Wellstone and Pete Domenici Mental Health Parity and Addiction Equity Act of 2008 - Group Health Plan Parity Requirements",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Mental Health Parity and Addiction Equity Act of 2008 prohibits group health plans and group and individual health insurance coverage that offer mental health and substance use disorder benefits from imposing financial requirements such as copayments, deductibles, and out-of-pocket limits or treatment limitations such as visit limits and prior authorisation requirements on those benefits that are more restrictive than the predominant requirements and limitations applied to substantially all medical and surgical benefits in the same classification, requires nonquantitative treatment limitations to be comparable and applied no more stringently for mental health and substance use disorder benefits, and requires disclosure of medical necessity criteria and reasons for benefit denials.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-aca-ppaca-2010-pl-111-148",
      "us-erisa-29-usc-1001"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-michigan-lawful-sports-betting-act-2019",
    "title": "Michigan Lawful Sports Betting Act 2019 - Online and Retail Sports Wagering Licensing",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Sports betting operators and internet sports betting operators in Michigan must hold licences from the Michigan Gaming Control Board (MGCB). Internet sports betting launched in January 2021. Licensed commercial casinos and tribal gaming facilities may partner with internet sports betting operators. MGCB sets rules on technical standards, responsible gambling tools, and compliance reporting.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "michigan_igaming_act",
        "uigea_2006",
        "michigan_gaming_control_act",
        "compacts",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-uigea-2006-unlawful-internet-gambling",
      "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-migrant-and-seasonal-agricultural-worker-protection-act",
    "title": "US Migrant and Seasonal Agricultural Worker Protection Act (29 USC ch 20): Farmworker Protections",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Migrant and Seasonal Agricultural Worker Protection Act, MSPA (29 U.S.C. ch. 20), establishes employment standards and protections for migrant and seasonal agricultural workers and regulates farm labor contractors, administered by the Department of Labor Wage and Hour Division. Section 1811 requires a farm labor contractor to register with and be certified by the Secretary. Section 1821 sets the information and recordkeeping requirements for migrant agricultural workers: at the time of recruitment the worker must receive written disclosure of the terms of employment, including the place of employment, wage rates, crops and kinds of activities, the period of employment, transportation and other benefits, and the existence of any strike or work stoppage; employers must post a Department of Labor poster of worker rights, must keep payroll records for three years, and must provide each worker with an itemized pay statement; and knowingly providing false or misleading information is prohibited. Section 1822 governs wages, supplies and other working arrangements, requiring timely payment of wages owed. Section 1831 sets parallel disclosure and recordkeeping requirements for seasonal agricultural workers, and section 1841 imposes motor vehicle safety and insurance requirements on transportation of workers. Section 1853 provides civil money penalties and section 1854 a private right of action. The Act is the legal foundation for US farmworker employment protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-migratory-bird-treaty-act",
    "title": "US Migratory Bird Treaty Act: Prohibited Takings, Permits and Penalties",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Migratory Bird Treaty Act (MBTA), codified at 16 U.S.C. Chapter 7, subchapter II (sections 703-712), implements four bilateral conventions for the protection of migratory birds (with Great Britain (for Canada) 1916, Mexico 1936, Japan 1972, and the Soviet Union 1976) and is administered by the US Fish and Wildlife Service (USFWS). Section 703 makes it unlawful at any time, by any means or in any manner, unless and except as permitted by regulations, to pursue, hunt, take, capture, kill, attempt to take, capture or kill, possess, offer for sale, sell, barter, purchase, deliver for shipment, ship, export, import, or transport any migratory bird, or any part, nest or egg of such a bird, or any product composed of such birds, as covered by the conventions. Section 704 authorizes the Secretary of the Interior to determine, consistent with the conventions, when, to what extent and by what means it is compatible to allow hunting, taking, possession and other dealings, and to set the zones, seasons and bag limits by regulation. Section 705 prohibits the transportation or importation of migratory birds taken in violation of any law. Section 706 provides for arrests, searches and seizures, and section 709a for forfeiture. Section 707 sets the penalties: most violations are misdemeanors, while the knowing sale, barter or offer to sell or barter of migratory birds (or their parts, nests or eggs) is a felony. Section 708 preserves the power of states to enact and enforce more restrictive laws. Permits for otherwise-prohibited activities (such as scientific collection, falconry, rehabilitation, depredation control, and certain sales of captive-bred birds) are issued under section 704 and the implementing regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-miller-act-1935-payment-performance-bonds",
    "title": "Miller Act of 1935 (40 U.S.C. §§3131-3134) - Mandatory Payment and Performance Bonds on Federal Construction Contracts Above $150,000",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Miller Act of 1935 requires contractors to provide payment and performance bonds for federal construction contracts exceeding $150,000, as stated in 40 U.S.C. §3131. This applies to all contractors performing work on federal projects above the specified threshold.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-mineral-leasing-act",
    "title": "US Mineral Leasing Act (30 USC ch 3A): Leasing of Federal Coal, Oil, Gas and Mineral Lands",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Mineral Leasing Act (30 U.S.C. ch. 3A) governs the leasing of public domain lands for the development of coal, oil, gas, phosphate, sodium, potassium, sulphur and other leasable minerals, administered by the Bureau of Land Management under the Secretary of the Interior. Section 181 sets out the lands subject to disposition and the persons entitled to take leases, namely citizens, associations and corporations organized under United States law, subject to reciprocal privilege limits on foreign ownership. Section 201 governs coal leases and exploration, and section 211 governs phosphate deposits. Section 226 provides for the lease of oil and gas lands, including competitive and noncompetitive leasing, and section 223 sets the term of a lease, the survey of the land, royalties and annual rental. Section 351 provides the definitions for acquired lands leasing. Lessees must pay royalties on production and comply with diligent development and operating requirements, and the Secretary may cancel a lease for noncompliance. The Act, together with the Federal Oil and Gas Royalty Management Act, is the legal foundation for US Federal mineral leasing and royalty administration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-mineral-leasing-act-1920",
    "title": "US Mineral Leasing Act of 1920 (30 USC ch 3A): Leasing of Coal, Oil, Gas and Other Minerals on Federal Lands",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Mineral Leasing Act of 1920 (30 U.S.C. ch. 3A) is the federal statute governing the leasing of coal, phosphate, sodium, potassium, oil, gas, oil shale and associated minerals on public domain lands, administered by the Bureau of Land Management within the Department of the Interior. Section 181 identifies the lands subject to disposition and the persons entitled to the benefits of the Act. Section 184 imposes acreage limitations on the holdings any one person, association or corporation may control: not more than 75,000 acres of coal leases in any one State and 150,000 acres nationally, not more than 246,080 acres of oil and gas leases in any one State (with a separate 300,000-acre allowance per leasing district in Alaska), and not more than 20,480 acres of phosphate. Section 185 governs rights of way for oil and gas pipelines through Federal lands. Section 187 makes the terms and conditions of a lease binding on assignment or subletting. Coal leasing is governed by sections 201 to 209, including competitive leasing and lease conditions; oil and gas leasing is governed by sections 223 to 236b, including competitive and noncompetitive leases and royalty obligations; oil shale is governed by sections 241 to 242; and section 191 directs the disposition of royalties and rentals between the United States, the States and the Reclamation Fund. The Act is the legal foundation for federal mineral leasing, the acreage and antitrust-style holding limits, and the royalty regime on public-land energy and mineral development.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-mineral-leasing-act-acquired-lands-1947",
    "title": "US Mineral Leasing Act for Acquired Lands of 1947 (30 U.S.C. Chapter 7): Leasing of Mineral Deposits in Acquired Federal Lands",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Mineral Leasing Act for Acquired Lands of 1947, codified at 30 U.S.C. Chapter 7 (sections 351 through 360), extends the federal mineral leasing system to lands acquired by the United States, authorizing the Secretary of the Interior to lease deposits of coal, phosphate, oil, gas, sulfur, sodium, potassium, and other leasable minerals within acquired lands under conditions consistent with the Mineral Leasing Act of 1920, administered by the Bureau of Land Management. Section 351 provides the definitions, including acquired lands and the leasable mineral deposits. Section 352 makes the deposits subject to lease with the consent of the head of the department having jurisdiction over the lands, and excludes deposits in incorporated municipalities, national parks and monuments, and certain tidelands. Section 353 preserves the sale of lands, the reservation of mineral rights, and prior leases, and provides that naval petroleum reserves are unaffected. Section 354 authorizes the lease of partial or future interests in deposits. Section 355 governs the disposition of receipts. Section 356 requires the furnishing of land descriptions and title documents and their recordation. Section 357 preserves State or local government rights and taxation, and section 359 authorizes the rules and regulations. The Act is the foundational statute for mineral leasing on acquired federal lands.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-minnesota-consumer-data-privacy-act-2024",
    "title": "Minnesota Consumer Data Privacy Act (MCDPA)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2025-07-31",
    "bluf": "The Minnesota Consumer Data Privacy Act (MCDPA) grants Minnesota residents rights over their personal data, including access, correction, deletion, and opt-out of sale, profiling, or targeted advertising. Effective July 31, 2025, the Act requires controllers to recognize universal opt-out mechanisms like the Global Privacy Control (GPC) by January 31, 2026, and prohibits discrimination against consumers for exercising their rights, as detailed in Sections 325O.05 and 325O.06.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-5-data-principles",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-mn-mcdpa-2024",
    "title": "US Minnesota Consumer Data Privacy Act 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Minnesota Consumer Data Privacy Act grants consumers rights to access, correct, delete, and port personal data and to opt out of targeted advertising, sale, and profiling, requires opt-in consent for sensitive data, recognises universal opt-out mechanisms such as browser-based signals as valid opt-out, mandates data protection assessments, and authorises the Minnesota Attorney General to impose civil penalties of up to USD 7,500 per violation with a 30-day mandatory cure period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-mn-mcdpa-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ccpa-cpra-2023-marketing-rights"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-money-laundering-control-act-18-usc-1956",
    "title": "Money Laundering Control Act 1986 - 18 USC 1956 Laundering of Monetary Instruments",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 1956 of title 18 of the United States Code criminalises the laundering of monetary instruments where the proceeds derive from a specified unlawful activity (SUA). Enacted as section 1352(a) of Public Law 99-570 (the Money Laundering Control Act of 1986), the statute creates three separate offences: subsection (a)(1) covers domestic financial transactions designed to promote SUA, evade taxes, conceal proceeds, or avoid reporting requirements; subsection (a)(2) covers international transportation, transmission, or transfer of monetary instruments with the same intent; subsection (a)(3) covers sting-style transactions involving property represented to be SUA proceeds. Maximum penalties reach 20 years imprisonment and the greater of 500,000 USD or twice the value of the transaction. Specified unlawful activity is defined at subsection (c)(7) and incorporates RICO predicates, controlled-substances offences, terrorism, fraud against federal programs, and numerous other federal felonies. Section 1956 is the criminal anchor of the US AML regime, complementing the Bank Secrecy Act reporting obligations and FinCEN regulations, and is routinely invoked alongside section 1957 (engaging in monetary transactions in property derived from SUA). Compliance programs must demonstrate that transaction monitoring, customer due diligence, and suspicious activity reporting are calibrated to detect both promotion-intent and concealment-intent typologies; AI agents executing or recommending financial transactions inherit the same scienter analysis and must therefore log knowledge signals, source-of-funds inferences, and the basis for any clearance decision.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-1970",
      "us-bsa-bank-secrecy-act-31-usc-5311",
      "fatf-recommendation-3-money-laundering-offence",
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-montana-consumer-data-privacy-act-2023",
    "title": "Montana Consumer Data Privacy Act",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2025-10-01",
    "bluf": "The Montana Consumer Data Privacy Act (MCDPA) establishes rights for Montana residents to control their personal data and imposes obligations on data controllers and processors. It applies to entities conducting business in Montana or targeting its residents that either control/process personal data of at least 50,000 consumers or derive over 25% of gross revenue from selling personal data of at least 25,000 consumers, as defined in Section 3.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-msha-30-cfr-46-training-surface-miners",
    "title": "30 CFR Part 46 - Training and Retraining of Miners Engaged in Shell Dredging, or Employed at Sand, Gravel, Surface Stone, Surface Clay, Colloidal Phosphate, or Surface Limestone Mines (MSHA)",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "30 CFR Part 46 sets the mandatory MSHA requirements for training and retraining miners at shell dredging, sand, gravel, surface stone, surface clay, colloidal phosphate, and surface limestone mines. Operators must develop and implement a written training plan covering new miner, newly hired experienced miner, new task, annual refresher, and site-specific hazard awareness training. New miners must receive no less than 24 hours of training and each miner no less than 8 hours of annual refresher training, with all training recorded on MSHA Form 5000-23 or an equivalent.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-federal-mine-safety-health-act-1977-msha",
      "us-msha-mine-safety-health-act-1977",
      "us-msha-30-cfr-part-56-surface-mine-safety"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-msha-30-cfr-48-training-underground-miners",
    "title": "30 CFR Part 48 Subpart A - Training and Retraining of Miners Working at Underground Mines (MSHA)",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "30 CFR Part 48 Subpart A sets the mandatory MSHA requirements for submitting and obtaining approval of programs for training and retraining miners working in underground mines, including compensation requirements. Each underground mine operator must have an MSHA-approved plan containing programs for new miner training, experienced miner training, new task training, annual refresher training, and hazard training, filed with the District Manager. Training must be conducted by MSHA-approved instructors except where the regulation expressly allows otherwise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-federal-mine-safety-health-act-1977-msha",
      "us-msha-30-cfr-part-57-underground-mine-safety",
      "us-30-cfr-75-mandatory-safety-underground-coal-mines"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-msha-30-cfr-part-56-surface-mine-safety",
    "title": "US MSHA 30 CFR Part 56 - Safety and Health Standards for Surface Metal and Nonmetal Mines",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "MSHA 30 CFR Part 56 establishes federal safety and health standards for all US surface metal and nonmetal mines including gold, silver, copper, limestone, and phosphate operations, mandating ground control plans, berm heights equal to half the axle height of the largest vehicle, silica PEL of 0.05 mg/m3, 90 dB(A) TWA noise standard, and mandatory emergency response plans inspected twice annually by MSHA inspectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "extractive-industries-transparency-eiti-standard",
      "gri-14-mining-sector-standard-2022",
      "icmm-mining-principles-2020",
      "iso-14001-2015-environmental-mining-operations"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-msha-30-cfr-part-57-underground-mine-safety",
    "title": "US MSHA 30 CFR Part 57 - Safety and Health Standards for Underground Metal and Nonmetal Mines",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "MSHA 30 CFR Part 57 establishes federal safety and health standards for underground metal and nonmetal mines including gold, silver, copper, zinc, and potash operations, mandating refuge chambers or equivalent escape routes, diesel engine emission controls (DPM 160 ug/m3 TC), ventilation minimum 200 CFM per brake horsepower for diesel equipment, silica PEL of 0.05 mg/m3, and mandatory self-contained self-rescuers (SCSR) for all underground workers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks",
        "eu_ai_act_article",
        "primary_regulatory_body",
        "compliance_tier"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-msha-30-cfr-part-56-surface-mine-safety",
      "extractive-industries-transparency-eiti-standard",
      "gri-14-mining-sector-standard-2022",
      "icmm-mining-principles-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-msha-metal-nonmetal-safety-standards",
    "title": "Metal and Nonmetal Mine Safety and Health Standards, 30 CFR Parts 56 and 57",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes mandatory safety and health standards for all surface and underground metal and nonmetal mining operations in the United States, enforced by the Mine Safety and Health Administration (MSHA). It applies to all mine operators and contractors and requires compliance with specific provisions including roof control plans (30 CFR § 56/57.3200), ventilation standards (§ 57.5001), electrical safety (§ 56/57.12000), blasting procedures (§ 56/57.6300), hoisting equipment inspections (§ 56/57.19000), personal protective equipment (§ 56/57.15900), and emergency response planning (§ 56/57.11072).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-conflict-minerals-regulation-2017-821",
      "eiti-standard-2023",
      "canada-national-instrument-43-101",
      "australia-epbc-act-1999-mining-biodiversity",
      "chile-mining-safety-regulations-ds-132-2004"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-msha-mine-safety-health-act-1977",
    "title": "Mine Safety and Health Act of 1977, Public Law 95-164, 30 U.S.C. § 801 et seq.",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Mine Safety and Health Act of 1977 establishes mandatory health and safety standards for all coal and non-coal mines in the United States, requiring mine operators to comply with inspection regimes, hazard reporting, and abatement procedures under 30 U.S.C. § 813 and § 814, enforced by the Mine Safety and Health Administration (MSHA). It applies to all mine operators, contractors, and miners engaged in mining activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-health-safety",
      "ilo-convention-155-occupational-safety-1981"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-mt-mtcdpa-2023",
    "title": "US Montana Consumer Data Privacy Act 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Montana Consumer Data Privacy Act grants consumers rights to access, correct, delete, and port personal data and to opt out of sale and targeted advertising, requires opt-in consent for sensitive data, applies to controllers processing data of 50,000 or more Montana consumers or 25,000 consumers with more than 25 percent revenue from sale, and authorises the Montana Attorney General to impose civil penalties of up to USD 7,500 per violation with a mandatory cure period through October 1, 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-mt-mtcdpa-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ccpa-cpra-2023-marketing-rights"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-mushroom-promotion-research-information-act",
    "title": "US Mushroom Promotion, Research, and Consumer Information Act of 1990 (7 USC ch 90): Mushroom Council and Assessments",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Mushroom Promotion, Research, and Consumer Information Act of 1990 (7 U.S.C. ch. 90, sections 6101 to 6112) authorizes a coordinated program of promotion, research, and consumer information for mushrooms funded by assessments, administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 6101 sets out the findings and declaration of policy, recognizing that mushrooms are an important food that is a valuable part of the human diet and that mushroom production plays a significant role in the Nation's economy, and authorizing an orderly procedure for developing, financing through adequate assessments, and carrying out an effective, continuous, and coordinated program. Section 6102 defines the terms, providing that producer means a person producing over 500,000 pounds of mushrooms per year and that importer means a person importing over 500,000 pounds annually. Section 6103 authorizes the issuance of orders, and section 6104 sets the required terms, providing for the establishment of a Mushroom Council with at least 4 members and not more than 9 members appointed by the Secretary from nominations, and limiting the assessment rate to one-quarter cent per pound in the first year, increasing in steps to one cent per pound thereafter. Section 6105 sets the referenda, providing that an order becomes effective if approved by a majority of producers producing more than 50 percent of the mushrooms voted upon. Section 6106 provides for petition and review, section 6107 provides for enforcement, including a civil penalty of not less than 500 dollars nor more than 5,000 dollars for each violation, and section 6108 provides investigations and power to subpoena. Section 6110 provides for the suspension or termination of orders. The Act is the federal checkoff regime for mushrooms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-music-modernization-act-2018-mma",
    "title": "17 U.S. Code Chapter 8 - PROCEEDINGS BY COPYRIGHT ROYALTY JUDGES",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the procedures and authority for Copyright Royalty Judges to determine royalty rates and terms for compulsory licenses under U.S. copyright law, particularly in disputes involving digital music and other licensed uses. It applies to copyright owners, digital music providers, and other interested parties involved in rate-setting proceedings under § 803.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dmca-safe-harbor",
      "copyright-fair-use-us"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-naic-credit-insurance-model-act",
    "title": "NAIC Credit Insurance Model Act - Consumer Credit Insurance: Eligibility Requirements, Coverage Limits, Premium Rates, Termination Provisions, Claims Procedures, Loss Ratio Standards and Commissioner Review Authority",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This model act establishes uniform standards for credit insurance policies tied to consumer loans, requiring insurers to meet eligibility criteria, adhere to maximum premium rates, maintain minimum loss ratios, and follow prescribed claims and termination procedures. Applies to insurers and creditors offering credit life, disability, accident, health, or unemployment insurance in connection with consumer credit transactions under Section 4 and Section 8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "eu-eiopa-guidelines-orsa-2015"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-naic-cyber-insurance-model-bulletin-2022",
    "title": "US NAIC Cyber Insurance Model Bulletin 2022 - Market Conduct, Data Calls, Coverage Clarity and Systemic Risk Monitoring",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This model bulletin provides guidance for state insurance regulators to enhance oversight of the cyber insurance market, requiring insurers to improve data reporting for solvency and market conduct analysis, clarify policy language to avoid ambiguity, and support systemic risk monitoring, as outlined in the 'Purpose' section.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sec-cybersecurity-disclosure-2023",
      "nist-sp-800-221-ict-risk"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-naic-insurance-holding-company-system-regulatory-act",
    "title": "US NAIC Insurance Holding Company System Regulatory Act - Group Supervision & ORSA",
    "domain": "Insurance & Risk",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "The NAIC Insurance Holding Company System Regulatory Act requires registration, disclosure, and pre-approval of transactions within insurance holding company groups - including ORSA filing for groups with $500M+ premium, change-of-control notifications, and inter-affiliate transaction restrictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-naic-life-insurance-illustrations-model-582",
    "title": "NAIC Life Insurance Illustrations Model Regulation 582",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-07-25",
    "bluf": "This model regulation establishes standards for life insurance policy illustrations to protect consumers from misleading projections of policy performance. It requires insurers, per Section 11, to have an illustration actuary certify annually that the illustrations used are compliant with this regulation and that the underlying assumptions are supportable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-naic-mcas-market-conduct-annual-statement",
    "title": "US NAIC Market Conduct Annual Statement (MCAS) - Data Submission Requirements for P&C and Life Insurers",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Market Conduct Annual Statement (MCAS) requires participating property & casualty and life/annuity insurers to annually submit standardized, company-level data on their market conduct activities, including claims, underwriting, and complaints, to state regulators via the NAIC's centralized data collection system as outlined in the annual MCAS Data Call Instructions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-naic-model-holding-company-act-440",
    "title": "Insurance Holding Company System Model Act (#440) with Annual Financial Reporting Model Regulation (#205)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-10-01",
    "bluf": "This model act requires insurance holding company systems to register with the state insurance commissioner, file an annual Own Risk and Solvency Assessment (ORSA) Summary Report, and provide prior notice of certain material transactions. The core requirements under Section 8 mandate that the ultimate controlling person of an insurer must file an ORSA report, detailing the group's risk management framework and solvency position.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "interagency-guidance-third-party-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-naic-model-law-insurance-data-security",
    "title": "US NAIC Insurance Data Security Model Law (#668) - Cybersecurity Program and Incident Response Requirements",
    "domain": "Insurance & Risk",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The National Association of Insurance Commissioners (NAIC) Insurance Data Security Model Law (Model #668), enacted in 2017 and adopted by over 25 US states (including South Carolina, Michigan, Ohio, Connecticut, and New York's equivalent Cybersecurity Regulation 23 NYCRR 500), requires licensed insurers and producers to: establish and maintain a comprehensive written cybersecurity program based on risk assessment; implement administrative, technical, and physical safeguards for nonpublic information; maintain an incident response plan; conduct annual penetration testing and vulnerability assessments; and notify the state insurance commissioner within 72 hours of a cybersecurity event affecting 250+ consumers. Third-party service providers (TPSPs) must be contractually required to maintain equivalent security standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_taxonomy",
        "sdg_alignment",
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-cybersecurity-framework-2024",
      "hipaa-security-rule"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-naic-model-laws-insurance-data-security-model-law-668",
    "title": "US NAIC Insurance Data Security Model Law 668 - Cybersecurity Program and Breach Notification for Insurers",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2017-10-24",
    "bluf": "NAIC Insurance Data Security Model Law (MDL-668) requires insurance licensees to implement a comprehensive information security program, conduct annual risk assessments, manage third-party service provider security, and notify the insurance commissioner of cybersecurity events affecting 250+ consumers within 72 hours, adopted as law by 22+ US states.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-53-r5",
      "us-hipaa-security-rule-45-cfr-164-technical-safeguards"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-naic-risk-based-capital-framework-insurers",
    "title": "US NAIC Risk-Based Capital (RBC) Framework - Life, P&C and Health RBC Formulas and Company Action Level Triggers",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The NAIC Risk-Based Capital (RBC) Framework requires U.S. insurers (Life, P&C, Health) to maintain capital levels commensurate with their specific risk profiles, calculated via prescribed formulas. As defined in the RBC for Insurers Model Act (#312), falling below four distinct 'Company Action Levels' triggers mandatory, escalating corrective actions by state regulators, from requiring a comprehensive financial plan to placing the insurer under regulatory control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fsb-key-attributes-res",
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-naic-unfair-trade-practices-act-model-880",
    "title": "Unfair Trade Practices Act (Model #880)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This model act prohibits insurers and their agents from engaging in unfair methods of competition or deceptive acts, including misrepresentation, false advertising, rebating, and unfair discrimination in rates and benefits, as defined in Section 4. It also establishes standards for prompt, fair, and equitable settlement of claims under Section 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-naic-unfair-trade-practices-model-act",
    "title": "NAIC Unfair Trade Practices Act Model 880 - Prohibited Insurance Conduct: Misrepresentation, False Advertising, Unfair Discrimination, Rebating, Unfair Claims Settlement Practices, Coercion and Intimidation in Insurance Markets",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This model act prohibits insurers, agents, and brokers from engaging in misrepresentation, false advertising, unfair discrimination, rebating, unfair claims settlement practices, and coercion in insurance markets. It applies to all persons engaged in the business of insurance in the United States, with key prohibitions outlined in Sections 4, 5, 6, 7, 8, and 9.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "eu-eiopa-guidelines-orsa-2015",
      "brazil-susep-solvency-regulation-circular-2021",
      "bermuda-bma-cissa-commercial-insurer-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-naiia-national-ai-initiative-act-2020",
    "title": "US National AI Initiative Act of 2020 (Title LI of NDAA FY2021, Public Law 116-283, codified at 15 USC 9401 et seq.)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The National AI Initiative Act of 2020 (NAIIA) was enacted on January 1, 2021 as Division E of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 (Public Law 116-283), codified at 15 U.S.C. 9401-9462. The Act establishes the National AI Initiative to ensure continued US leadership in AI research, training, and standards. Section 5101 sets out the Initiative's purposes and findings. Section 5102 directs the President to establish the National AI Initiative and coordinate federal AI activities across NIST, NSF, DOE, DARPA, IARPA, NIH, NASA, and other agencies. Section 5103 establishes the National AI Initiative Office in OSTP as the principal point of coordination. Section 5104 establishes the Interagency Committee on AI. Section 5105 establishes the National AI Advisory Committee (NAIAC) to advise the President on AI matters. Section 5106 requires NIST to conduct foundational AI research, develop voluntary risk management frameworks (the basis for NIST AI RMF 1.0), and establish testing infrastructure. Sections 5301-5304 direct NSF research investments. Section 5401 establishes a network of National AI Research Institutes. Section 5501 directs the Department of Energy AI program. The Act provides the statutory backbone for federal AI research investment and explicitly authorises NIST's voluntary risk management framework work that produced the NIST AI Risk Management Framework 1.0 (January 2023).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "research_alignment",
        "naiac_role"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-ai-600-1-gen-ai-profile",
      "us-ai-in-government-act-2020",
      "us-eo-13960-promoting-trustworthy-ai-federal-government-2020"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-nara-36-cfr-1234-electronic-records-management",
    "title": "NARA 36 CFR Part 1234 - Electronic Records Management Standards",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "36 CFR Part 1234 establishes the National Archives and Records Administration (NARA) mandatory standards for managing US federal electronic records, requiring agencies to implement an Electronic Records Management (ERM) system that captures records in context, maintains their authenticity and integrity throughout their lifecycle, implements approved records schedules, ensures permanent records are transferred to NARA in approved formats, and provides legally compliant access to email records, social media records, and records created in cloud environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-national-agricultural-research-extension-teaching-policy-act",
    "title": "US National Agricultural Research, Extension, and Teaching Policy Act of 1977 (7 USC ch 64): USDA Lead Agency for Agricultural Research",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The National Agricultural Research, Extension, and Teaching Policy Act of 1977 (7 U.S.C. ch. 64, sections 3101 onward) sets the federal policy framework for agricultural research, extension, and teaching in the United States, administered by the Secretary of Agriculture. Section 3101 states the purposes of agricultural research, extension, and education, directing that programs enhance the international competitiveness and productivity of United States agriculture, develop new uses and products for agricultural commodities, improve risk management, and strengthen food and agricultural safety. Section 3121 designates the Department of Agriculture as the lead agency of the federal government for agricultural research, extension, and teaching, and makes the Secretary the principal officer responsible for coordinating these activities, including cooperation with the land-grant colleges and universities. Section 3123 establishes the National Agricultural Research, Extension, Education, and Economics Advisory Board, consisting of 15 members, to recommend policies and priorities to the Secretary. Section 3157 authorizes competitive, special, and facilities research grants for agricultural research. The Act is the statutory foundation for the coordination and prioritization of the United States agricultural research enterprise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-national-ai-initiative-act-2020",
    "title": "US National AI Initiative Act 2020 (Division E of the FY2021 NDAA, Public Law 116-283) - National AI Research Resource, Interagency Coordination and International Competitiveness Strategy",
    "domain": "AI Governance & Law",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "This regulation establishes a coordinated federal strategy to accelerate AI innovation, infrastructure, and international leadership under Executive Orders and OMB Memos issued between 2019 and 2025. It applies to all federal agencies and contractors involved in AI development and procurement, with key directives including the prevention of 'woke AI' and the acceleration of data center permitting under Executive Order 7/23/2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-100-4-redteam",
      "iso-42001-risk-assess",
      "iso-42001-transparency"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-national-cybersecurity-strategy-2023",
    "title": "National Cybersecurity Strategy of the United States of America (2023)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This strategy establishes a whole-of-nation approach to US cybersecurity, shifting the burden of defense from end-users to the most capable organizations, including government and technology producers. It is organized around five core pillars, from defending critical infrastructure (Pillar One) to forging international partnerships (Pillar Five), to create a more defensible, resilient, and values-aligned digital ecosystem.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "cisa-cross-sector-cybersecurity-goals",
      "c-scrm-practices-systems-organizations",
      "sec-reg-s-k-106"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-national-emergencies-act-50-usc-ch34",
    "title": "United States National Emergencies Act (Title 50 USC Chapter 34): Termination of Existing Declared Emergencies, Declaration of National Emergency by the President, Termination of National Emergencies, Declaration by Executive Order, Accountability and Reporting Requirements, and Other Emergency Authorities",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The National Emergencies Act, Public Law 94-412 of 14 September 1976, codified at Title 50 of the United States Code, Chapter 34 (National Emergencies), is the principal federal statute providing the procedural framework for the declaration, termination, and oversight of national emergencies by the President of the United States. National Emergencies, 50 U.S.C. 1601 terminated all powers and authorities possessed by the President, any other officer or employee of the Federal Government, or any executive agency, as a result of the existence of any declaration of national emergency in effect on 14 September 1976. National Emergencies, 50 U.S.C. 1621 provides that the President is authorized to declare a national emergency with respect to acts of Congress authorizing the exercise, during the period of a national emergency, of any special or extraordinary power, and requires publication in the Federal Register and immediate transmittal to Congress. National Emergencies, 50 U.S.C. 1622 provides for the termination of national emergencies including by joint resolution of Congress and the automatic termination after one year unless the President publishes in the Federal Register and transmits to the Congress a notice stating that such emergency is to continue in effect. National Emergencies, 50 U.S.C. 1631 provides for the declaration of national emergency by Executive order specifying the provisions of law under which the President or other officer will act. National Emergencies, 50 U.S.C. 1641 imposes accountability and reporting requirements on the President including six-month reports to Congress on expenditures. National Emergencies, 50 U.S.C. 1651 references other emergency authorities. The Act is the controlling federal procedural framework for the exercise of statutory emergency powers including the International Emergency Economic Powers Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-national-environmental-policy-act",
    "title": "US National Environmental Policy Act (42 USC ch 55): Environmental Review of Federal Actions",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The National Environmental Policy Act (42 U.S.C. ch. 55) requires Federal agencies to assess the environmental effects of their proposed actions before deciding to proceed. Section 4331 declares the national environmental policy and the continuing responsibility of the Federal Government to use all practicable means to protect the environment. Section 4332 requires that all agencies of the Federal Government use a systematic, interdisciplinary approach and include in every recommendation or report on proposals for legislation and other major Federal actions significantly affecting the quality of the human environment a detailed statement - the environmental impact statement - addressing the environmental impact of the proposed action, unavoidable adverse effects, alternatives to the proposed action, the relationship between short-term uses and long-term productivity, and irreversible commitments of resources. The responsible official must consult with agencies having jurisdiction or expertise and make the statement available to the President, the Council on Environmental Quality and the public. Section 4342 establishes the Council on Environmental Quality. The Act creates the procedural framework that underpins environmental impact assessment, including categorical exclusions and environmental assessments leading to a finding of no significant impact where appropriate. It is the legal foundation for US Federal environmental review.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-national-flood-insurance-program-nfip-reforms",
    "title": "US National Flood Insurance Program (NFIP) Reforms - Risk Rating 2.0: Individual Property Risk Assessment Replacing Zone-Based Rates, Actuarially Sound Pricing, Rate Increase Caps, Community Rating System, Private Flood Insurance Comparison and FEMA Affordability Study",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The National Flood Insurance Program (NFIP), established by the National Flood Insurance Act (NFIA) of 1968, provides flood insurance to property owners, renters, and businesses in participating communities to reduce the socio-economic impact of floods. Homes and businesses in high-risk flood areas with mortgages from government-backed lenders are required to have flood insurance, as mandated under the NFIA of 1968.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-national-institutes-health-nih-recombinant-dna-guidelines-research",
    "title": "US NIH Recombinant DNA Research Guidelines - Institutional Biosafety Committee Requirements",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "The NIH Guidelines for Research Involving Recombinant or Synthetic Nucleic Acid Molecules (NIH Guidelines) govern laboratory research with recombinant DNA and synthetic nucleic acids at institutions receiving NIH funding. Covered research requires Institutional Biosafety Committee (IBC) registration and approval. The Guidelines specify biosafety levels (BSL-1 through BSL-4) based on risk group of agent, containment requirements, prohibited experiments, and major actions requiring NIH RAC review. Violation of NIH Guidelines can result in suspension of NIH funding.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fda-21-cfr-312-ind-application-investigational-new-drug"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-national-labor-relations-act",
    "title": "US National Labor Relations Act (29 USC ch 7): Collective Bargaining, Unfair Labor Practices and the NLRB",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The National Labor Relations Act (NLRA, 29 U.S.C. ch. 7, subchapter II) guarantees the rights of private-sector employees to organize and bargain collectively and is administered by the National Labor Relations Board (NLRB). Section 151 sets the findings and declaration of policy, recognizing that the denial of the right to organize and the refusal to bargain lead to industrial strife. Section 152 supplies the definitions, including employer, employee and labor organization. Section 157 confers the core rights: employees have the right to self-organization, to form, join or assist labor organizations, to bargain collectively through representatives of their own choosing, and to engage in concerted activities, as well as the right to refrain from such activities. Section 158 defines the unfair labor practices, including, for employers, interfering with section 157 rights, dominating a labor organization, discriminating against employees for union activity, and refusing to bargain in good faith, and, for labor organizations, restraining employees and refusing to bargain. Section 159 governs the selection of bargaining representatives and representation elections. Section 160 gives the NLRB the power to prevent unfair labor practices, including the issuance of cease-and-desist orders and reinstatement with back pay. Section 163 preserves the right to strike. The Act is the legal foundation of US private-sector collective bargaining and labor-relations enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-national-marine-sanctuaries-act",
    "title": "US National Marine Sanctuaries Act (16 U.S.C. Chapter 32): Designation, Protection and Enforcement of Marine Sanctuaries",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The National Marine Sanctuaries Act, codified at 16 U.S.C. Chapter 32 (sections 1431 through 1445c), authorizes the Secretary of Commerce, acting through the National Oceanic and Atmospheric Administration, to designate and manage national marine sanctuaries to protect areas of the marine environment with special national significance. Section 1431 sets the findings, purposes, and policies, and establishes the National Marine Sanctuary System. Section 1432 provides the definitions. Section 1433 sets the sanctuary designation standards, including the requirement that the area be of special national significance. Section 1434 sets the procedures for designation and implementation, including consultation, public comment, and congressional review. Section 1436 sets the prohibited activities, including destroying, causing the loss of, or injuring a sanctuary resource and violating any regulation or permit. Section 1437 provides for enforcement, including civil penalties of up to a specified amount per violation per day, and authorizes the assessment of penalties and the seizure of vessels. Section 1441 authorizes special use permits for the conduct of specific activities. Section 1443 establishes liability for the destruction, loss, or injury of sanctuary resources, including response costs and damages. The Act is the foundational statute for the United States system of marine protected areas.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-national-quantum-initiative-act-2018-pl-115-368",
    "title": "US National Quantum Initiative Act 2018 Public Law 115-368 Federal Coordination of Quantum Information Science Research Workforce and Standards",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "The National Quantum Initiative Act Public Law 115-368 enacted on 21 December 2018 establishes a coordinated US federal programme to accelerate quantum information science and technology organised in three titles covering Title I National Quantum Initiative Program with section 101 program coordination establishing the National Quantum Coordination Office in the Office of Science and Technology Policy section 102 advisory committee creation of the National Quantum Initiative Advisory Committee with industry and academic membership and section 103 subcommittee on quantum information science under the National Science and Technology Council, Title II National Institute of Standards and Technology Quantum Initiative Activities with section 201 NIST quantum information science programme including standards and metrology for quantum technologies section 202 NIST quantum consortium with industry and academia and section 203 NIST workshop on quantum information science workforce, and Title III Department of Energy Quantum Information Science Research Program with sections covering Department of Energy National Quantum Information Science Research Centers and National Science Foundation Multidisciplinary Centers for Quantum Research and Education. The Act has been reauthorised through successive National Defense Authorization Acts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-203-ml-kem-standard"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-national-research-act-1974-irb-belmont",
    "title": "National Research Act of 1974 and The Belmont Report: Ethical Principles and Guidelines for the Protection of Human Subjects of Research",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The National Research Act of 1974 mandates the establishment of Institutional Review Boards (IRBs) to oversee federally funded research involving human subjects. The Belmont Report, issued in 1979 by the National Commission for the Protection of Human Subjects of Biomedical and Behavioral Research, establishes three core ethical principles-Respect for Persons, Beneficence, and Justice-that govern IRB review and informed consent processes under 45 CFR Part 46.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-european-research-area-policy-agenda-2022",
      "oecd-recommendation-responsible-research-innovation-2021",
      "iso-21001-2018-educational-organizations-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-national-security-act-1947-50-usc-3001",
    "title": "National Security Act 1947 - 50 USC 3001 Intelligence and National Security Architecture",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 3001 of title 50 of the United States Code provides the short title of the National Security Act of 1947 (Public Law 80-253, enacted 26 July 1947). The Act fundamentally reorganised US national security architecture by establishing the National Security Council to coordinate foreign-policy, military, and intelligence matters for the President, creating the Central Intelligence Agency as the principal civilian intelligence agency, separating the United States Air Force from the Army as an independent military service under the new Department of the Air Force, and consolidating the previously separate Departments of War and Navy under the new National Military Establishment (renamed the Department of Defense by the National Security Act Amendments of 1949). The Act has been substantially amended including by the Goldwater-Nichols Department of Defense Reorganization Act of 1986 (Public Law 99-433), the Intelligence Reform and Terrorism Prevention Act of 2004 (Public Law 108-458) which transferred intelligence community leadership from the Director of Central Intelligence to the new Director of National Intelligence, and subsequent intelligence authorization acts. Subsequent codification has placed many National Security Act provisions throughout title 50 chapter 44 (sections 3001 through 3236 covering Office of the Director of National Intelligence, Central Intelligence Agency, and accountability). The National Security Act framework continues to govern AI-enabled defense, intelligence collection, and counterintelligence systems within DoD and the Intelligence Community.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fisa-foreign-intelligence-surveillance-act-50-usc-ch36",
      "us-defense-production-act-50-usc-4501"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-national-traffic-motor-vehicle-safety-act-1966-nhtsa",
    "title": "US National Traffic and Motor Vehicle Safety Act 1966 - NHTSA Safety Standards",
    "domain": "Automotive & Mobility",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The National Traffic and Motor Vehicle Safety Act (49 U.S.C. Chapter 301) grants NHTSA authority to set Federal Motor Vehicle Safety Standards (FMVSS) for all motor vehicles and equipment sold in the US; manufacturers must self-certify FMVSS compliance and conduct safety defect recalls under 49 U.S.C. 30118-30120.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-national-trails-system-act",
    "title": "US National Trails System Act of 1968 (16 U.S.C. Chapter 27): Establishment and Administration of National Trails",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The National Trails System Act of 1968, codified at 16 U.S.C. Chapter 27 (sections 1241 through 1251), establishes a national system of recreation, scenic, and historic trails to promote public access to and enjoyment of the outdoor areas and historic resources of the Nation, administered by the Secretary of the Interior and the Secretary of Agriculture. Section 1241 sets the congressional statement of policy and declaration of purpose. Section 1242 establishes the national trails system, comprising national recreation trails, national scenic trails, national historic trails, and connecting or side trails. Section 1243 governs the establishment and designation of national recreation trails and their prerequisites. Section 1244 governs national scenic and national historic trails, including those designated by the Act and the studies for potential additions. Section 1245 governs connecting or side trails. Section 1246 sets the administration and development of the national trails system, including cooperative agreements, rights-of-way, and the uniform marker. Section 1248 governs easements and rights-of-way. Section 1249 authorizes appropriations, and section 1250 provides for volunteer trails assistance. The Act is the foundational statute for the national trails system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-natural-gas-act",
    "title": "US Natural Gas Act (15 USC ch 15B): FERC Jurisdiction over Interstate Gas Transportation, Pipeline Certificates and LNG Terminals",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Natural Gas Act (15 U.S.C. ch. 15B) is the federal statute regulating the transportation and wholesale sale of natural gas in interstate commerce, administered by the Federal Energy Regulatory Commission (FERC). Section 717 fixes the Act's scope to the transportation of natural gas in interstate commerce and to the sale in interstate commerce of natural gas for resale, while expressly leaving intrastate transactions and local distribution to the states. Section 717a supplies the definitions, including natural gas, natural-gas company, interstate commerce and LNG terminal. Section 717b requires Commission authorization for the exportation and importation of natural gas and grants FERC exclusive authority over the siting, construction and operation of LNG terminals. Section 717c requires that all rates and charges be just and reasonable and prohibits undue preference or discrimination, with subsection (f) permitting market-based rates for new storage capacity in defined circumstances. Section 717f requires a certificate of public convenience and necessity before a natural-gas company may construct, extend, acquire or abandon facilities, and confers the right of eminent domain for the acquisition of pipeline rights of way. Section 717g requires regulated companies to keep prescribed accounts and records open to Commission inspection. Enforcement is direct: section 717t imposes criminal penalties of imprisonment for not more than 5 years and a fine of not more than 1,000,000 dollars for a willful violation, plus a fine not exceeding 50,000 dollars for each day a rule or order is violated, and section 717t-1 authorizes a civil penalty of not more than 1,000,000 dollars per day per violation. The Act is the legal foundation for FERC's certification of interstate pipelines and LNG facilities and its policing of interstate gas rates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-natural-gas-act-15-usc-ch15b",
    "title": "United States Natural Gas Act (Title 15 USC Chapter 15B): Public Interest Declaration, Import/Export Authorization, Just and Reasonable Rates, Construction and Abandonment Certificates, and Civil Penalties",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Natural Gas Act, codified at Title 15 of the United States Code, Chapter 15B, is the foundational federal statute governing the interstate transportation and wholesale sale of natural gas and is administered by the Federal Energy Regulatory Commission. Natural Gas Act, 15 U.S.C. 717 declares that the business of transporting and selling natural gas for ultimate distribution to the public is affected with a public interest, and that Federal regulation in matters relating to the transportation of natural gas and the sale thereof in interstate and foreign commerce is necessary in the public interest. Natural Gas Act, 15 U.S.C. 717a contains the definitions used in the chapter. Natural Gas Act, 15 U.S.C. 717b governs exportation or importation of natural gas and LNG terminals: no person shall export any natural gas from the United States to a foreign country or import any natural gas from a foreign country without first having secured an order of the Commission authorizing it to do so. Natural Gas Act, 15 U.S.C. 717c requires that all rates and charges made, demanded, or received by any natural-gas company for or in connection with the transportation or sale of natural gas subject to the jurisdiction of the Commission shall be just and reasonable. Natural Gas Act, 15 U.S.C. 717d authorises the Commission to investigate and determine the cost of production or transportation when it finds rates unjust or unreasonable after hearing. Natural Gas Act, 15 U.S.C. 717f requires that no natural-gas company shall abandon all or any portion of its facilities subject to the jurisdiction of the Commission without the permission and approval of the Commission first had and obtained, after due hearing, and governs certificates of public convenience and necessity for construction and extension of facilities. Natural Gas Act, 15 U.S.C. 717t-1 provides that any person that violates the chapter shall be subject to a civil penalty of not more than one million dollars per day per violation for as long as the violation continues. The Act, alongside the Natural Gas Policy Act and the Natural Gas Wellhead Decontrol Act, is the controlling federal instrument for interstate natural gas regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-natural-gas-act-1938-ferc-jurisdiction",
    "title": "Natural Gas Act of 1938: FERC Jurisdiction over Interstate Transportation, Pipeline Certification, and Rate-Setting",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2024-06-27",
    "bluf": "The Natural Gas Act of 1938 (NGA) grants the Federal Energy Regulatory Commission (FERC) jurisdiction over the transportation of natural gas in interstate commerce, its sale for resale, and natural gas companies engaged in such activities. Key provisions require companies to obtain a certificate of public convenience and necessity before constructing or operating interstate pipelines (Section 7) and mandate that all rates and charges be 'just and reasonable' (Sections 4 & 5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-natural-gas-act-ferc-pipeline-certification",
    "title": "Natural Gas Act Section 7(c): Certificate of Public Convenience and Necessity for Interstate Natural Gas Pipelines",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Under Section 7(c) of the Natural Gas Act (15 U.S.C. § 717f(c)), any entity seeking to construct, extend, acquire, or operate facilities for the transportation or sale of natural gas in interstate commerce must first obtain a Certificate of Public Convenience and Necessity from the Federal Energy Regulatory Commission (FERC), demonstrating the project is required by public need and is environmentally and economically sound.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-natural-gas-pipeline-safety-act",
    "title": "US Pipeline Safety Law (49 USC ch 601): Pipeline Safety Standards and Enforcement",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Federal pipeline safety law (49 U.S.C. ch. 601), originating in the Natural Gas Pipeline Safety Act and the Hazardous Liquid Pipeline Safety Act, governs the safety of gas and hazardous liquid pipeline transportation and facilities, administered by the Pipeline and Hazardous Materials Safety Administration within the Department of Transportation. Section 60101 provides the definitions, including pipeline facility and gas. Section 60102 sets the purpose and general authority: the Secretary shall prescribe minimum safety standards for pipeline transportation and pipeline facilities, which may address the design, installation, inspection, emergency plans and procedures, testing, construction, extension, operation, replacement and maintenance of facilities, must include qualifications for the personnel who operate and maintain facilities and the ability to recognize and react to abnormal operating conditions, and must be practicable and designed to meet the need for pipeline safety and to protect the environment. Section 60108 addresses inspection and maintenance, section 60109 high-density and environmentally sensitive areas, and section 60118 requires compliance with the standards. Section 60122 authorizes civil penalties and section 60123 provides criminal penalties for knowing and willful violations. The law also provides for State certification to assume intrastate safety authority. It is the legal foundation for US pipeline integrity management and enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-naval-stores-act",
    "title": "US Naval Stores Act (7 USC ch 4): Federal Grade Standards for Turpentine and Rosin",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Naval Stores Act (7 U.S.C. ch. 4, sections 91 to 99) establishes federal grade standards for naval stores, principally spirits of turpentine and rosin, and is administered by the Secretary of Agriculture. Section 91 names the chapter the Naval Stores Act, and section 92 defines naval stores, spirits of turpentine, rosin, and related terms. Section 93 directs the establishment of official naval stores standards for grading and classifying these products. Section 94 authorizes the Secretary to supply duplicates of the standards and to examine and certify naval stores, and provides that a certificate issued under the chapter is prima facie evidence in court of the truth of its statements. Section 95 prohibits acts deemed injurious to commerce in naval stores, including selling or offering for sale naval stores under a false or deceptive grade designation or representation, or otherwise contrary to the established standards. Section 96 makes a violation of the prohibition punishable by a fine not exceeding 5,000 dollars or imprisonment for not exceeding one year, or both. Section 97 authorizes the Secretary to purchase and analyze samples of spirits of turpentine to detect violations, section 98 establishes fees and charges for naval stores inspection and related services, and section 99 is a separability clause. The Act is the primary federal standardization regime for the naval stores trade.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-nclb-2001-no-child-left-behind-pl-107-110",
    "title": "US No Child Left Behind Act of 2001 (Public Law 107-110) - Standards-Based K-12 Education Accountability",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The No Child Left Behind Act of 2001 reauthorised the Elementary and Secondary Education Act of 1965 and imposed federal accountability conditions on states receiving Title I funds including adoption of academic content and achievement standards, annual statewide assessments in reading and mathematics in grades three through eight and once in high school, annual measurable objectives leading to one hundred percent proficiency by the 2013-2014 school year, public reporting of disaggregated achievement data, sanctions for schools failing to make adequate yearly progress, highly qualified teacher requirements, and parental notification and choice options for students in low-performing schools. The Act was substantially replaced by the Every Student Succeeds Act of 2015.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-elementary-secondary-education-act-1965-title-20-ch70",
      "us-essa-every-student-succeeds-act-2015"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ndaa-2024-artificial-intelligence-defense",
    "title": "National Defense Authorization Act for Fiscal Year 2024 - Artificial Intelligence Provisions Relating to Department of Defense Strategy, Algorithmic Warfare, Testing and Evaluation, Responsible AI Governance, and Incident Reporting",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "The NDAA 2024 mandates the Department of Defense to update its AI strategy, establish AI testing and evaluation centers, formalize the Algorithmic Warfare Cross-Functional Team, create a Responsible AI Governance Board, and implement AI safety incident reporting and allied interoperability protocols. Key requirements are outlined in Division A, Title L, Subtitle G - Artificial Intelligence, Sections 1051-1059.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cmmc-2-audit",
      "nist-800-171-cui",
      "dfars-7012-defense-cyber",
      "do-178c-airborne-software-2011",
      "iso-27017-cloud-defence"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ne-ndpa-2023",
    "title": "US Nebraska Data Privacy Act 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Nebraska Data Privacy Act grants consumers rights to access, correct, delete, and port personal data and to opt out of targeted advertising, sale, and profiling, requires opt-in consent for sensitive data including children's personal data, mandates data protection assessments for high-risk processing, and authorises the Nebraska Attorney General to impose civil penalties of up to USD 7,500 per violation with a 30-day mandatory cure period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ne-ndpa-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ccpa-cpra-2023-marketing-rights"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-nebraska-data-privacy-act-2024",
    "title": "Nebraska Data Privacy Act (LB 1294)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Nebraska Data Privacy Act (NDPA) grants Nebraska residents rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of the sale of personal data, targeted advertising, and certain profiling. The Act applies to entities conducting business in Nebraska or targeting Nebraska residents that, in a calendar year, control or process personal data of at least 20,000 consumers, or control or process data of at least 10,000 consumers and derive over 25% of gross revenue from selling personal data (Section 3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-nepa",
    "title": "US National Environmental Policy Act (NEPA, 42 USC ch 55): Environmental Impact Statements for Major Federal Actions",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The National Environmental Policy Act of 1969 (NEPA), codified at 42 U.S.C. Chapter 55 (sections 4321-4347), is the foundational US environmental statute establishing a national environmental policy and a procedural duty for federal agencies to assess the environmental effects of their proposed actions before deciding to act; it is overseen by the Council on Environmental Quality (CEQ). Section 4321 declares the purposes of the Act. Section 4331 declares the national environmental policy, directing that the federal government use all practicable means to create and maintain conditions under which man and nature can exist in productive harmony. Section 4332 contains the operative procedural mandate: it directs that, to the fullest extent possible, the policies, regulations and laws of the United States be interpreted and administered in accordance with the Act, and at section 4332(2)(C) requires all agencies of the federal government to include, in every recommendation or report on proposals for legislation and other major federal actions significantly affecting the quality of the human environment, a detailed statement by the responsible official on the environmental impact of the proposed action, any adverse environmental effects which cannot be avoided, alternatives to the proposed action, the relationship between local short-term uses and long-term productivity, and any irreversible and irretrievable commitments of resources. Agencies implement this through the levels of review developed under the CEQ regulations: a categorical exclusion for actions without significant effects, an environmental assessment leading to a finding of no significant impact, or a full environmental impact statement (EIS) for actions with significant effects. Section 4342 establishes the Council on Environmental Quality and section 4344 sets out its duties. NEPA is procedural and imposes no civil or criminal penalties; it is enforced through judicial review under the Administrative Procedure Act, where a court may set aside or enjoin agency action taken without the required environmental review.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-nepa-1970-environmental-impact-assessment",
    "title": "National Environmental Policy Act of 1969, as amended (42 U.S.C. § 4321 et seq.)",
    "domain": "Construction & Real Estate",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The National Environmental Policy Act (NEPA) of 1969 requires federal agencies to prepare an Environmental Impact Statement (EIS) for major federal actions that significantly affect the environment, as stated in 42 U.S.C. § 4332(2)(C).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "un-paris-agreement-ndc-implementation-guidelines"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-nerc-cip-standards-bulk-electric-system",
    "title": "NERC CIP Standards - Bulk Electric System Cybersecurity: CIP-002 through CIP-014, BES Cyber System Classification, Electronic Security Perimeters, Access Management and Incident Reporting",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The NERC CIP Standards mandate cybersecurity protections for the Bulk Electric System (BES) across North America, requiring entities to identify and safeguard critical cyber assets through risk-based classification, access controls, monitoring, and incident reporting. Key obligations are defined in Requirements (R1, R2, etc.) across standards CIP-002 through CIP-014.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "edge-ai-security-nist",
      "api-std-1164-scada-pipeline-security"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-net-act-1997-no-electronic-theft-pl-105-147",
    "title": "US No Electronic Theft Act of 1997 (Public Law 105-147) - Criminal Copyright Infringement Without Commercial Motive",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The No Electronic Theft Act of 1997 amended Title 17 and Title 18 of the United States Code to extend federal criminal copyright infringement to acts undertaken without commercial purpose or private financial gain by including the reproduction or distribution of copyrighted works with a total retail value above statutory thresholds during any 180-day period, extended the statute of limitations for criminal copyright infringement, codified that the term financial gain includes receipt of other copyrighted works through barter or trade, authorised victim impact statements at sentencing, and required the United States Sentencing Commission to amend the federal sentencing guidelines accordingly.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-digital-millennium-copyright-act"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-nevada-gaming-control-act-nrs-463",
    "title": "Nevada Revised Statutes Chapter 463 - Nevada Gaming Control Act",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Nevada Gaming Control Act (NRS Chapter 463) establishes the regulatory framework for all gaming activities in Nevada, granting the Nevada Gaming Commission and Gaming Control Board authority to license, regulate, and investigate gaming operations and participants. It applies to all persons, corporations, and entities engaged in gaming at any level, requiring strict suitability standards under NRS 463.320 and ongoing compliance with financial, operational, and reporting mandates.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nevada-privacy-law-sb-220-2019",
    "title": "Nevada SB 220 (2019) and SB 260 (2021) - Sale of Covered Information Opt-Out Requirements for Operators of Websites",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2024-10-01",
    "bluf": "This law requires operators of websites or online services who collect 'covered information' from Nevada consumers to provide a designated request address for consumers to opt-out of the 'sale' of their information, as defined in NRS 603A.333. Operators must respond to verified opt-out requests within 60 days, with a possible 30-day extension.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-new-hampshire-privacy-act-sb255-2024",
    "title": "New Hampshire Privacy Act (SB 255-FN)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2025-01-01",
    "bluf": "The New Hampshire Privacy Act establishes rights for consumers to access, correct, delete, and obtain a copy of their personal data, and to opt out of the processing of their data for targeted advertising, sale, or certain profiling. The act applies to entities that conduct business in New Hampshire or produce products/services targeted to its residents and, during a one-year period, either control/process data of at least 35,000 consumers or control/process data of at least 10,000 consumers while deriving over 25% of gross revenue from selling personal data, as defined in RSA 507-H:2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-35-dpia",
      "gdpr-article-5-data-principles",
      "california-ccpa-v2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-new-jersey-data-privacy-act-njdpa-2024",
    "title": "New Jersey Data Privacy Act (P.L.2023, c.266)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The New Jersey Data Privacy Act (NJDPA) applies to controllers conducting business in NJ or targeting NJ residents who control or process personal data of at least 100,000 consumers, or 25,000 consumers if they derive revenue from selling data (Section 3). The Act grants consumers rights to access, correct, delete, and opt-out of the processing of their personal data for targeted advertising, sale, or profiling, and mandates recognition of universal opt-out mechanisms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-35-dpia",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-new-york-mobile-sports-wagering-2022",
    "title": "New York Mobile Sports Wagering Act 2021 - PML Article 13-C Highest US Tax Rate",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "New York's mobile sports wagering framework was enacted as Part MM of Chapter 59 of the Laws of 2021, creating Article 13-C of the Racing, Pari-Mutuel Wagering and Breeding Law (PML Section 1367 et seq.). The New York State Gaming Commission (NYSGC) regulates mobile sports betting. The tax rate is 51% of gross gaming revenue on mobile sports wagering - the highest rate of any US state. Minimum age is 21. Mobile sports betting launched January 8, 2022. Platform providers must partner with licensed gaming facilities. Up to 4 mobile sports wagering platform providers are licensed initially.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_paspa_repeal",
        "us_uigea_2006",
        "us_massachusetts_sports_wagering",
        "fatf_gambling",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
      "us-uigea-2006-unlawful-internet-gambling",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-new-york-safe-for-kids-act-2024-addictive-feeds",
    "title": "New York SAFE for Kids Act (S.7694-A 2023-24) - Stop Addictive Feeds Exploitation",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "The New York Stop Addictive Feeds Exploitation (SAFE) for Kids Act, S.7694-A in the 2023-24 legislative session, adds Article 45 (Sections 1500-1508) to the New York General Business Law. The Act defines an addictive feed as a portion of a website or app where multiple pieces of media generated or shared by users are recommended selected or prioritized for display to a user based in whole or in part on information associated with the user or the user's device, with carve-outs for chronological feeds user-requested content and direct messages. A covered minor is a user the operator has actual knowledge is under 18 in New York; a covered operator is an entity operating an addictive social media platform where addictive feeds constitute a significant part of the services provided. Section 1501 prohibits operators from providing addictive feeds to covered minors unless they either (A) use commercially reasonable and technically feasible methods to determine that the covered user is not a covered minor or (B) obtain verifiable parental consent. Section 1502 prohibits sending notifications about addictive feeds to minors between midnight and 6 a.m. Eastern without parental consent. Enforcement is by the New York Attorney General with civil penalties up to $5,000 per violation plus injunctive relief restitution and disgorgement of profits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ca_sb_976_parallel",
        "kosa_federal_floor",
        "nyaag_child_data_protection_act",
        "netchoice_litigation",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nfip-biggert-waters-2012-flood-insurance",
    "title": "Biggert-Waters Flood Insurance Reform Act of 2012 (BW-12)",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2024-07-25",
    "bluf": "The Biggert-Waters Flood Insurance Reform Act of 2012 (BW-12) requires the National Flood Insurance Program (NFIP) to raise insurance rates to reflect true flood risk and phase out most subsidized premium rates to ensure the program's financial solvency. This applies to FEMA, NFIP-participating communities, and property owners in special flood hazard areas, as mandated by sections like Sec. 100205 (Rate Increases) and Sec. 100207 (Elimination of Subsidized Rates).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nfip-national-flood-insurance-program-rules"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-nfip-national-flood-insurance-program-rules",
    "title": "US NFIP National Flood Insurance Program - Policy Coverage, Mandatory Purchase Requirements and Community Rating System",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The National Flood Insurance Program (NFIP) requires the mandatory purchase of flood insurance for properties located in Special Flood Hazard Areas (SFHAs) that have federally backed mortgages, as mandated by the Flood Disaster Protection Act of 1973. The program also offers reduced insurance premiums for communities participating in the Community Rating System (CRS) by exceeding minimum floodplain management requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-nh-privacy-act-2024",
    "title": "New Hampshire Privacy Act 2024 (SB 255)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "New Hampshire SB 255 signed March 6, 2024 effective January 1, 2025 grants consumers rights to access, correct, delete, and port their personal data, requires opt-in consent for sensitive data processing, and provides a 60-day cure period with civil penalties up to USD 10,000 per violation enforced exclusively by the Attorney General.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-nh-privacy-act-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nhtsa-automated-driving-systems-guidance",
    "title": "Automated Driving Systems 2.0: A Vision for Safety",
    "domain": "Aviation, Defense & Quantum",
    "version": "2.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This voluntary guidance from the US National Highway Traffic Safety Administration (NHTSA) encourages developers of Automated Driving Systems (ADS) to submit a Voluntary Safety Self-Assessment (VSSA) demonstrating how they address 12 key safety design elements, including Operational Design Domain, Object and Event Detection and Response, and Validation Methods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-23894-ai-risk-management",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-nhtsa-automated-vehicles-guidance-2021",
    "title": "Ensuring American Leadership in Automated Vehicle Technologies: Automated Vehicles Comprehensive Plan, AV 4.0 - Safety Framework for Automated Driving Systems, Voluntary Guidance, Pre-Market Testing, Cybersecurity and Public Reporting",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The NHTSA AV 4.0 guidance establishes a voluntary safety framework for developers, manufacturers, and operators of Automated Driving Systems (ADS) to ensure pre-deployment safety validation, cybersecurity resilience, and transparent public reporting. It applies to all entities designing, testing, or deploying Level 4 and Level 5 automated vehicles in the United States, with key requirements outlined in the Voluntary Guidance for Safety Self-Assessments (VSSA) and the Federal Automated Vehicles Policy (FAVP).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sae-j3016-levels-driving-automation-2021",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "iso-26262-functional-safety-road-vehicles-2018",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "us-automated-vehicles-comprehensive-plan-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nhtsa-av-test-initiative-reporting",
    "title": "Automated Vehicle Transparency and Engagement for Safe Testing (AV TEST) Initiative: Reporting Framework, Safety Self-Assessment Format and Incident Reporting to NHTSA",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This voluntary initiative by the US National Highway Traffic Safety Administration (NHTSA) encourages participants testing Automated Driving Systems (ADS) on public roads to publicly report safety self-assessments and testing data. The framework, outlined in the AV TEST Initiative, aims to increase public awareness, transparency, and collaboration to improve ADS safety.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "iso-23894-ai-risk-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nhtsa-connected-vehicle-cybersecurity-guidance-2022",
    "title": "NHTSA Cybersecurity Best Practices for the Safety of Modern Vehicles 2022 - Risk Management, Supply Chain Security, OTA Updates and Incident Response",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This guidance requires motor vehicle manufacturers, suppliers, and software developers to implement a comprehensive cybersecurity risk management framework covering design, supply chain, over-the-air (OTA) updates, and incident response. Key requirements are outlined in Section 4 (Risk Management), Section 5 (Supply Chain), Section 6 (OTA), and Section 7 (Incident Response) of the NHTSA 2022 guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cobit-2019-governance-framework",
      "nist-sp-1800-17-mfa-ecommerce",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nhtsa-federal-motor-vehicle-safety-standards-fmvss",
    "title": "Federal Motor Vehicle Safety Standards (FMVSS) - Safety Performance Requirements for Occupant Protection, Lighting, Braking and Electronic Systems",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The FMVSS establishes mandatory safety performance requirements for motor vehicles and equipment related to occupant protection, braking, lighting, and electronic systems. It applies to all manufacturers, importers, and distributors of motor vehicles and motor vehicle equipment in the United States under 49 CFR Part 571, with key provisions in Standard No. 208 (Occupant Crash Protection), Standard No. 102 (Transmission Shift Position Sequence), and Standard No. 126 (Electronic Stability Control Systems).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-1800-17-mfa-ecommerce",
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-nhtsa-fmvss-federal-motor-vehicle-safety-standards-49-cfr-571",
    "title": "US NHTSA FMVSS - Federal Motor Vehicle Safety Standards 49 CFR Part 571 Compliance",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "NHTSA Federal Motor Vehicle Safety Standards (49 CFR Part 571) mandate that all vehicles sold in the US meet minimum safety performance requirements for crash protection, lighting, tires, brakes, and occupant restraints, with manufacturers self-certifying compliance and NHTSA retaining authority to order recalls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-15-usc-45-unfair-deceptive-practices",
      "us-national-traffic-motor-vehicle-safety-act-1966-nhtsa"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nih-genomic-data-sharing-policy-2014-2024-update",
    "title": "US NIH Genomic Data Sharing (GDS) Policy (2014, updated)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2024-01-25",
    "bluf": "The National Institutes of Health (NIH) Genomic Data Sharing (GDS) Policy establishes the expectation that human and non-human genomic data generated from NIH-funded research will be broadly shared in NIH-designated data repositories to enable maximum scientific use. The Policy was issued in 2014 (NOT-OD-14-124) and updated to align with the 2023 NIH Data Management and Sharing (DMS) Policy that requires a Data Management and Sharing Plan with every NIH-funded research project that generates scientific data. The GDS Policy applies to all NIH-funded research that generates large-scale human and non-human genomic data, including whole-genome sequencing, whole-exome sequencing, large-scale single nucleotide polymorphism arrays, and large-scale gene expression datasets.\n\nThe Policy expects investigators to register the study with the dbGaP database, deposit the data in an NIH-designated repository (such as dbGaP, AnVIL, or the Sequence Read Archive), submit institutional certifications confirming compliance with informed consent and data use limitations, and follow data use limitation statements when accessing controlled-access data. Data Access Committees (DACs) review requests for controlled-access data. The Policy requires participant informed consent for broad sharing in unrestricted or controlled-access repositories and applies to data generated on or after the 25 January 2015 effective date. The 21st Century Cures Act 2016 reinforced the federal commitment to broad genomic data sharing while preserving informed consent and privacy protections under the Common Rule and HIPAA where applicable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-privacy-rule",
      "us-common-rule-45-cfr-46-human-subjects-research"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-nih-guidelines-rdna-research-2019",
    "title": "NIH Guidelines for Research Involving Recombinant or Synthetic Nucleic Acid Molecules (2019)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "Institutions conducting recombinant or synthetic nucleic acid research in the U.S. must register with the NIH Office of Science Policy and establish an Institutional Biosafety Committee (IBC) to review and approve all such research, assessing risk groups and containment levels per Section III-D-1 and Appendix G. Applies to all institutions receiving NIH funding for rDNA research.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-guidance-human-gene-therapy-2020",
      "ich-q5a-r2-viral-safety-biotech-2024",
      "cartagena-protocol-biosafety-2000",
      "nagoya-protocol-genetic-resources-2010",
      "isber-best-practices-biorepositories-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nih-guidelines-recombinant-dna-research",
    "title": "NIH Guidelines for Research Involving Recombinant or Synthetic Nucleic Acid Molecules (2019 Revision)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "These guidelines establish biosafety levels, containment practices, and Institutional Biosafety Committee (IBC) review requirements for all research involving recombinant or synthetic nucleic acid molecules conducted at or funded by institutions in the United States. Compliance is required under Section IV-B-2-a of the NIH Guidelines, which mandates IBC registration and approval prior to initiation of research.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "ich-gcp-e6-r3-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nist-ai-600-1-generative-ai-profile-2024",
    "title": "NIST AI 600-1 Generative AI Profile 2024 - Trustworthy AI Implementation Requirements and Compliance Obligations for Managing Risks Unique to Generative AI Systems Across GOVERN, MAP, MEASURE, and MANAGE Functions",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines specific obligations for managing risks in generative AI systems under NIST AI 600-1 across GOVERN, MAP, MEASURE, and MANAGE functions, aligning with NIST AI RMF 1.0 and reinforcing EU AI Act 2024 requirements for high-risk AI systems under Articles 9 and 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "eu-ai-act-2024",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nist-ai-rmf-playbook-generative-ai-2024",
    "title": "NIST GenAI Playbook 2024 - Companion to AI RMF for Generative AI: Suggested Actions for GOVERN/MAP/MEASURE/MANAGE Functions, Generative AI-Specific Risks (Confabulation/CSAM/Homogenisation/Misuse), Evaluator Profiles and Test Sets",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This NIST guidance provides actionable steps for federal agencies and AI developers to govern, map, measure, and manage generative AI systems, with emphasis on mitigating risks such as confabulation, misuse, and homogenisation. Key requirements include robust evaluation frameworks and transparency in deployment, as outlined in the core functions of the AI Risk Management Framework (AI RMF) as applied to generative AI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-600-1-gen-ai-profile",
      "eu-ai-act-2024",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nist-csf-2-0-cybersecurity-framework-2024",
    "title": "NIST Cybersecurity Framework 2.0 (2024) - Six Core Functions: Govern, Identify, Protect, Detect, Respond, Recover",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The NIST Cybersecurity Framework 2.0 provides a policy framework to help organizations manage and reduce cybersecurity risk across six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. It applies to all organizations seeking to improve cybersecurity posture using standardized profiles and risk management practices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "aicpa-soc2-cc-availability",
      "aicpa-soc2-cc-confidentiality",
      "aicpa-soc2-cc-privacy",
      "owasp-samm-governance"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nist-cybersecurity-framework-2-0-csf-identify-protect",
    "title": "NIST Cybersecurity Framework 2.0 - Govern, Identify, Protect, Detect, Respond, Recover",
    "domain": "Cybersecurity",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "NIST CSF 2.0 (February 2024) expands the original five functions with a new Govern function, providing a flexible risk-based framework for managing cybersecurity risk applicable to organizations of all sizes and sectors - widely adopted as the de facto US cybersecurity baseline.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nist-ir-8228-iot-cyber-privacy-risk-considerations-2019",
    "title": "NIST IR 8228 - Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2019-06-25",
    "bluf": "Organisations deploying Internet of Things devices should treat IoT cybersecurity and privacy risk management as a three-tier objective covering Protect Device Security, Protect Data Security, and Protect Individuals' Privacy, address the risk mitigation areas under each goal across the device lifecycle, adjust organisational policies and processes by updating the specific NIST Cybersecurity Framework Subcategories and NIST SP 800-37 Risk Management Framework tasks identified in Section 5.1, and implement updated risk mitigation practices that account for the high variability in IoT device types, capabilities, and usage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-cybersecurity-framework-2024",
      "nist-sp-800-37-rmf",
      "nistir-8259a-iot-device-cybersecurity",
      "nist-ir-8259b-iot-non-technical-baseline"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-nist-ir-8473-csf-profile-ev-extreme-fast-charging-2023",
    "title": "NIST IR 8473 - Cybersecurity Framework Profile for Electric Vehicle Extreme Fast Charging Infrastructure",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2023-10-05",
    "bluf": "Organizations operating in the Electric Vehicle Extreme Fast Charging (EV/XFC) ecosystem - covering the four domains of EVs, XFC/EVSE charging stations, Cloud/Third-Party service providers, and Utilities/Building Management Systems - should apply the NIST Cybersecurity Framework Profile in IR 8473 by aligning four mission objectives (secure communications, infrastructure resilience, trustworthy partner and customer relationships, continuity of operations) with prioritized CSF Subcategories across Identify, Protect, Detect, Respond, and Recover Functions, treating cybersecurity risk management as covering both IT and OT processes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-cybersecurity-framework-2024",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "unece-r155-automotive-cybersecurity-2021",
      "nistir-8259a-iot-device-cybersecurity"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-nist-sp-800-218a-secure-ai-development",
    "title": "NIST SP 800-218A Secure Software Development Practices for Generative AI and Dual-Use Foundation Models",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2024-04-18",
    "bluf": "This publication provides specific secure software development practices for generative AI and dual-use foundation models, extending the NIST Secure Software Development Framework (SSDF, SP 800-218). It requires AI model producers to implement controls against risks like data poisoning, model theft, and malicious outputs, as detailed in the AI-specific considerations within Tables 1-4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "us-eo-14110-ai-2023",
      "nist-ai-100-2-adversarial-ml",
      "us-cisa-ai-cybersecurity-guidelines-2023",
      "eu-ai-act-gpai-obligations-chapter-v"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-nist-sp-800-63-4-2025-digital-identity-guidelines",
    "title": "NIST SP 800-63-4 Digital Identity Guidelines (Revision 4, July 2025)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2025-07-31",
    "bluf": "NIST Special Publication 800-63-4 is the United States federal baseline for digital identity services across enrollment, authentication, and federation. Revision 4 was finalized on 31 July 2025 and replaces SP 800-63-3 as the authoritative US identity assurance framework for federal agencies and the de facto reference for private-sector reliance. The publication is split into a base volume (SP 800-63-4) and three sub-volumes covering identity proofing and enrollment (SP 800-63A-4), authentication and authenticator management (SP 800-63B-4), and federation and assertions (SP 800-63C-4). It introduces Identity Assurance Level (IAL), Authenticator Assurance Level (AAL), and Federation Assurance Level (FAL) as separately selectable risk tiers, replacing the bundled Level of Assurance model from prior versions.\n\nRevision 4 incorporates controls for injection attacks and forged media (deepfakes) at identity proofing, formal recognition of syncable authenticators including synced passkeys, and integration of subscriber-controlled wallets into the federation model. Federal Civil Executive Branch agencies must implement these guidelines for non-national-security systems under OMB Memorandum M-19-17. AAL3 requires hardware-based authenticators that provide verifier impersonation resistance, AAL2 requires multi-factor authentication, and IAL3 requires in-person or supervised remote identity proofing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-sp-800-63b-digital-identity",
      "fips-201-3-piv-federal-employees",
      "w3c-verifiable-credentials-data-model-2-0",
      "w3c-webauthn-level-3-2024-passkeys-fido2"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-nist-sp-800-82-rev-3-ot-security-guide",
    "title": "NIST SP 800-82 Revision 3 - Guide to Operational Technology (OT) Security",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2023-09-28",
    "bluf": "Organizations operating Operational Technology systems must establish an OT cybersecurity program built from the ten program elements in Section 3.3 of NIST SP 800-82 Revision 3 - governance, cross-functional team, OT cybersecurity strategy, OT-specific policies and procedures, OT-tailored awareness training, application of the NIST Risk Management Framework, maintenance tracking, incident response, recovery and restoration, and continuous improvement - and apply the NIST SP 800-53 Rev. 5 OT overlay in Appendix F when selecting and tailoring security controls for industrial control systems, building automation systems, transportation systems, physical access control systems, and other programmable systems that interact with the physical environment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-cybersecurity-framework-2024",
      "nist-sp-800-37-rmf",
      "iec-62443-4-1-product-security-development",
      "isa-99-iec-62443-industrial-security-framework"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-nj-casino-control-act-1977",
    "title": "New Jersey Casino Control Act of 1977 (P.L. 1977, c.110)",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The New Jersey Casino Control Act of 1977 establishes the legal framework for casino gaming in Atlantic City, requiring all casino operators to obtain a license from the New Jersey Division of Gaming Enforcement (DGE) and comply with strict operational, financial, and responsible gambling standards under N.J.S.A. 5:12-1 et seq. It applies to casino licensees, key employees, casino service contractors, and online gaming operators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "owasp-asvs-l3"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nj-dppl-2024",
    "title": "US New Jersey Data Privacy Law 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The New Jersey Data Privacy Law grants consumers rights to access, correct, delete, and port personal data and to opt out of targeted advertising, sale, and profiling, requires opt-in consent for sensitive data, mandates data protection assessments for high-risk processing, and authorises the New Jersey Attorney General to impose civil penalties of up to USD 10,000 per first violation and USD 20,000 per subsequent violation with a 30-day mandatory cure period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-nj-dppl-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ccpa-cpra-2023-marketing-rights"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-nlra-section-7-ai-monitoring",
    "title": "NLRA Section 7 and AI Workplace Monitoring - NLRB Guidance on Algorithmic Management and Collective Bargaining Rights",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Under Section 7 of the National Labor Relations Act (NLRA), employers are prohibited from using AI-driven monitoring, surveillance, or algorithmic management systems in a way that interferes with, restrains, or coerces employees in the exercise of their rights to self-organization, collective bargaining, and other concerted activities for mutual aid or protection. This applies to most private-sector employers, including those whose workplaces are not unionized.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eeoc-employment-rule",
      "ada-employment-title-1",
      "us-osha-ai-ergonomics-guidance",
      "unesco-ai-ethics-work"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-nlra-section-7-employee-rights-concerted-activity-social-media",
    "title": "US NLRA Section 7 - Employee Rights to Concerted Activity Including Social Media and Digital Communications",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "Section 7 of the National Labor Relations Act (29 U.S.C. § 157) protects employees' rights to engage in concerted activity for mutual aid or protection. The NLRB has consistently ruled that overly broad social media policies, non-disparagement clauses, and confidentiality policies that restrict employees from discussing wages, working conditions, or organising are unlawful under the NLRA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-fair-labor-standards-act-flsa"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-no-fakes-act-2023-digital-replicas-ai",
    "title": "NO FAKES Act of 2023 - Preventing Explicit Digital Replication of Individuals Without Consent",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The NO FAKES Act of 2023 prohibits the creation or distribution of digital replicas of an individual’s voice or likeness using generative AI without their consent, with exceptions for expressive, journalistic, or transformative works. Applies to creators, distributors, and platforms hosting AI-generated content under Section 3(a).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iptc-video-metadata",
      "c2pa-content-provenance",
      "copyright-fair-use-us",
      "dmca-safe-harbor"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-noaa-15-cfr-960-commercial-remote-sensing-space-systems",
    "title": "15 CFR Part 960 - NOAA Licensing of Private Remote Sensing Space Systems",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "15 CFR Part 960 governs the licensing of private remote sensing space systems by the U.S. National Oceanic and Atmospheric Administration. A person subject to U.S. jurisdiction must obtain a license from NOAA before operating a private remote sensing space system, and must submit an application that NOAA categorizes into one of three tiers based on the risk that the system's unenhanced data could be obtained from other sources. The licensee must comply with the standard license conditions applicable to all tiers, and with the additional conditions for Tier 2 and Tier 3 systems determined by the categorization. The licensee must maintain routine compliance and permit monitoring, observe the prohibitions in the regulations, and submit to investigations and enforcement. The framework, modernized in 2020, limits conditions to those necessary to address national security, international obligations and foreign policy concerns, and provides procedures for waivers, modifications and administrative appeal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "intl-outer-space-treaty-1967-article-1-exploration-freedom",
      "intl-outer-space-treaty-1967-article-9-contamination-prevention",
      "new-zealand-outer-space-act-2017"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-noaa-15-cfr-part-960-private-remote-sensing-space-systems",
    "title": "US NOAA 15 CFR Part 960 Licensing of Private Remote Sensing Space Systems Tier System Conditions and Reporting Requirements",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "15 CFR Part 960 implements the United States National Oceanic and Atmospheric Administration Commercial Remote Sensing Regulatory Affairs framework licensing operators of private remote sensing space systems organised in 4 subparts covering Subpart A General Provisions with definitions scope and application requirements at section 960.1 through section 960.6, Subpart B Application Process and License Issuance with section 960.7 application requirements section 960.8 environmental review section 960.9 NOAA review timeline of 60 days and section 960.10 license decision, Subpart C License Conditions implementing a three-tier system based on capability and unenhanced data availability with Tier 1 lightest oversight for systems with capabilities equivalent to or less restrictive than available foreign systems Tier 2 standard conditions for systems with capabilities above available foreign systems and Tier 3 enhanced conditions for systems with capabilities exceeding any available foreign systems, and Subpart D Compliance and Enforcement including reporting requirements at section 960.21 inspections at section 960.22 and modification or revocation at section 960.23. The Part implements the Land Remote Sensing Policy Act and the 2020 reform that moved licensing from a default-restrictive to a default-permissive framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-commercial-space-launch-competitiveness-act-2015-space-resources"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-norris-laguardia-act-29-usc-ch6",
    "title": "Norris-LaGuardia Act 1932 - 29 USC Chapter 6 Limits on Federal Court Labor Injunctions",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Chapter 6 of title 29 of the United States Code codifies the Norris-LaGuardia Act of 1932, the foundational federal statute curtailing the jurisdiction of federal district courts to issue restraining orders or injunctions in labor disputes. Section 102 declares the public policy of the United States in favor of full freedom of association, self-organisation, and the right of workers to engage in concerted activity free of employer interference. Section 103 renders unenforceable so-called yellow-dog contracts in which employees promise as a condition of employment not to join a labor organisation. Sections 104 and 107 enumerate the categories of conduct (peaceful picketing, refusal to work, advice and persuasion of others to do the same) that no federal court may enjoin, and prescribe the strict procedural requirements (sworn testimony, opportunity for cross-examination, findings of fact, and security bond) that govern any narrow injunctive remedy that remains available. Sections 108 through 110 add good-faith bargaining and law-compliance prerequisites for any party seeking equitable relief and require a court of appeals review of injunction orders. Although later statutes (NLRA, LMRA, RLA) overlay specific dispute-resolution machinery, Norris-LaGuardia continues to control any federal-court application for injunctive relief touching a labor dispute, and shapes how AI workforce-management platforms must structure decisions affecting concerted activity, union access, and collective bargaining.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-national-labor-relations-act",
      "us-fair-labor-standards-act-flsa",
      "ilo-c087-freedom-of-association-right-to-organise-1948"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-nrc-10-cfr-35-medical-use-byproduct-material",
    "title": "10 CFR Part 35 - NRC Medical Use of Byproduct Material",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "10 CFR Part 35 governs the medical use of byproduct material (radioactive material) administered by the U.S. Nuclear Regulatory Commission and Agreement States. A person must hold a specific license before receiving, possessing, using or administering byproduct material for medical use, and must apply for and maintain that license and any amendments. The licensee must establish a radiation protection program with assigned authority and responsibilities, including a Radiation Safety Officer, and must ensure the required training of the Radiation Safety Officer, authorized users and authorized medical physicists. A written directive must be prepared before administering byproduct material in the cases that require one, and the prescribed procedures for such administrations must be followed. The licensee must supervise individuals working under an authorized user, maintain the required records, make the required notifications and reports including medical events, and comply with the provisions protecting human research subjects and with applicable FDA, other Federal and State requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nrc-10-cfr-50-domestic-licensing-nuclear-facilities",
      "iaea-gsr-part-3-radiation-protection-2014",
      "nrc-10-cfr-73-physical-security-nuclear-plants"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-nrc-10-cfr-50-nuclear-reactor-licensing",
    "title": "10 CFR Part 50: Domestic Licensing of Production and Utilization Facilities",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes the comprehensive requirements for licensing, constructing, and operating nuclear power plants and other production or utilization facilities within the United States. As mandated by § 50.34, applicants must submit a detailed Preliminary Safety Analysis Report (PSAR) and Final Safety Analysis Report (FSAR) demonstrating adherence to the General Design Criteria outlined in Appendix A.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-7628-smart-grid-cybersecurity"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-nsa-ai-security-guidance-2024",
    "title": "NSA Cybersecurity Information Sheet on AI Security - Compliance Obligations for Secure AI Integration, AI Model Hardening Requirements, and NSA Guidance on Adversarial ML Defences for National Security AI Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines NSA guidance on secure AI system development, focusing on model hardening, adversarial ML defenses, and integration obligations, aligning with EU AI Act (Regulation 2024/1689) high-risk system requirements under Articles 9 and 15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nsa-cnss-policy-15-quantum-resistant-2022",
    "title": "CNSS Policy No. 15: National Policy on the Use of Cryptographic Algorithms and Key Sizes for National Security Systems",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Mandates the transition of National Security Systems (NSS) to quantum-resistant cryptography by 2030, requiring the use of approved post-quantum algorithms (CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+) and deprecating RSA and ECC for key establishment after 2030. Applies to all U.S. national security systems as defined in CNSS Instruction No. 4009.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cmmc-2-audit",
      "nist-800-171-cui",
      "dfars-7012-defense-cyber",
      "iso-27017-cloud-defence"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nsf-act-title-42-ch16",
    "title": "United States National Science Foundation Act of 1950 (Title 42 USC Chapter 16): Foundation Functions, National Science Board, Director Authority, Grants, and Equal Opportunity Mandate",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The National Science Foundation Act of 1950, codified at Title 42 of the United States Code, Chapter 16, is the foundational federal statute establishing the National Science Foundation and authorising federal support for basic scientific research and science education across the United States. National Science Foundation Act, 42 U.S.C. 1862 sets out the Foundation's functions and provides that the Foundation is authorized and directed to initiate and support basic scientific research and programs to strengthen scientific research potential and science education programs at all levels in the mathematical, physical, medical, biological, social, and other sciences. National Science Foundation Act, 42 U.S.C. 1863 establishes the National Science Board as the policy-making body of the Foundation. National Science Foundation Act, 42 U.S.C. 1864 establishes the position of Director of the Foundation. National Science Foundation Act, 42 U.S.C. 1869 authorises scholarships and graduate fellowships. National Science Foundation Act, 42 U.S.C. 1870 sets out the general authority of the Foundation including the authority to enter into contracts, make grants, accept gifts, acquire property, and prescribe rules and regulations. National Science Foundation Act, 42 U.S.C. 1873 authorises employment of personnel. National Science Foundation Act, 42 U.S.C. 1874 contains security provisions. National Science Foundation Act, 42 U.S.C. 1885 contains the Congressional statement regarding equal opportunities for women and minorities in science and engineering programs. The Act is the controlling federal instrument for the governance, funding mechanisms, and operations of the National Science Foundation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-nsm-10-quantum-computing-vulnerable-cryptographic-systems-2022",
    "title": "US National Security Memorandum 10 (NSM-10) — Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems (May 4, 2022)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "National Security Memorandum 10 (NSM-10), signed by President Joseph R. Biden Jr. on May 4, 2022, sets two interrelated United States policy goals: (i) 'maintain United States leadership in QIS [Quantum Information Science], through continued investment, partnerships, and a balanced approach to technology promotion and protection' and (ii) 'mitigate the threat of CRQCs [Cryptographically Relevant Quantum Computers] through a timely and equitable transition of the Nation's cryptographic systems to quantum-resistant cryptography'. NSM-10 is the foundational executive instrument for the United States post-quantum cryptography (PQC) migration regime and remains in force notwithstanding subsequent presidential transitions. The memorandum directs federal civilian agencies to inventory vulnerable IT systems within one year and OMB to establish cryptographic system inventory requirements within 180 days (operationalised via OMB Memorandum M-23-02 'Migrating to Post-Quantum Cryptography' November 18, 2022). The memorandum establishes the National Manager for National Security Systems role at NSA for NSS guidance (operationalised via NSA CNSA 2.0 published September 2022, with deprecation timeline extending to 2035) and the National Institute of Standards and Technology lead for federal civilian PQC standards (operationalised via FIPS 203 ML-KEM, FIPS 204 ML-DSA, and FIPS 205 SLH-DSA published August 13, 2024). NSM-10 sets the 2035 government-wide target for completion of migration to quantum-resistant cryptography across both civilian and national security systems, anchored on the initial NIST quantum-resistant cryptography standards expected in 2024 and ratified ahead of schedule on August 13, 2024. The memorandum is structured in six sections: Policy, Promoting United States Leadership, Mitigating the Risks to Encryption, Protecting United States Technology, Definitions, and General Provisions. Operational implications for federal civilian agencies, defence industrial base contractors, critical infrastructure operators, and any organisation handling long-lived sensitive data include (a) immediate cryptographic system inventory in scope of OMB M-23-02 (or sectoral equivalent for non-federal), (b) prioritisation of High Value Assets and High Impact Systems for early migration, (c) vendor engagement on FIPS 203/204/205 readiness, (d) migration plan with milestone alignment to the 2035 government-wide target, and (e) acknowledgement that 'harvest now, decrypt later' adversary collection makes long-lived data confidentiality risk immediate even with the 2035 target.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fips-203-ml-kem-standard",
      "fips-204-ml-dsa-standard",
      "fips-205-slh-dsa-quantum",
      "nsa-cnsa-2-0-quantum-resistant-algorithms-2022",
      "us-nsa-cnss-policy-15-quantum-resistant-2022"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-nuclear-waste-policy-act-1982-repository-program",
    "title": "Nuclear Waste Policy Act of 1982: Subtitle A - Repositories for Disposal of High-Level Radioactive Waste and Spent Nuclear Fuel & Subtitle C - Interim Storage Program",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The Nuclear Waste Policy Act of 1982 establishes the federal responsibility for the permanent disposal of high-level radioactive waste and spent nuclear fuel, requiring the Department of Energy (DOE) to site, construct, and operate a geologic repository. Under Section 302, owners and generators of such waste must enter into contracts with the DOE and pay fees into the Nuclear Waste Fund to finance the program, in exchange for the DOE's obligation to begin accepting waste by January 31, 1998.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-nv-sb220-2019",
    "title": "Nevada Senate Bill 220 Online Privacy Law Amendment 2019",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Nevada SB 220 signed May 29, 2019 effective October 1, 2019 amended Nevada Revised Statutes Chapter 603A to require operators of commercial websites and online services collecting personal information of Nevada residents to honor verified consumer opt-out requests to prohibit the sale of their covered information, with AG enforcement and civil penalties of up to USD 5,000 per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-nv-sb220-2019.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ny-clcpa-2019",
    "title": "New York Climate Leadership and Community Protection Act (CLCPA) 2019",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "New York utilities, generators, and load-serving entities must support state targets of 70% renewable electricity by 2030, 100% zero-emission electricity by 2040, and 85% reduction in statewide greenhouse gas emissions by 2050 from 1990 levels, with at least 35% of clean energy benefits directed to disadvantaged communities. The Climate Action Council enforces scoping plan implementation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ny_environmental_conservation_law",
        "nyserda_programs",
        "climate_action_council",
        "justice40",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-inflation-reduction-act-clean-energy-2022",
      "us-ca-sb100-clean-energy-2018",
      "ferc-order-2222-distributed-energy-resources-2020"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ny-dfs-bitlicense-23-nycrr-part-200",
    "title": "New York State Department of Financial Services - Virtual Currency Business Licensing (BitLicense) under 23 NYCRR Part 200 (Issued June 2015 under the New York Financial Services Law); Plus Alternative Limited Purpose Trust Company Charter Pathway under New York Banking Law",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2025-09-30",
    "bluf": "The New York State Department of Financial Services (DFS) administers the foundational US state-level virtual currency business licensing regime under 23 NYCRR Part 200 (the BitLicense regulation), which was issued in June 2015 under the New York Financial Services Law. The BitLicense regime is the longest-standing comprehensive US state-level virtual currency licensing framework and remains the operative starting point for any entity intending to conduct virtual currency business activity in New York State. To conduct virtual currency business activity in NYS, entities can either apply for a BitLicense under 23 NYCRR Part 200 OR apply for a charter under the New York Banking Law (typically as a New York State limited purpose trust company or New York State bank with approval to conduct virtual currency business). The two pathways are similar but the limited purpose trust company charter offers additional benefits: (i) a limited purpose trust company can exercise fiduciary powers, while a BitLicensee cannot; and (ii) a limited purpose trust company can engage in money transmission in New York without obtaining a separate New York money transmitter license. The BitLicense application is managed via NMLS (Nationwide Multistate Licensing System and Registry, operated by the Conference of State Bank Supervisors with the American Association of Residential Mortgage Regulators) and follows the BitLicense Application Checklist; failure to submit complete documentation is the most common reason for application delays. NYDFS supervisory expectations are operationalised through industry letters, including guidance on the issuance of US dollar-backed stablecoins (June 2022), use of blockchain analytics (April 2022), listing of virtual currencies (November 2023), the general framework for greenlisted coins (September 2023), custodial structures for customer protection in insolvency (most recently updated September 2025, superseding January 2023 guidance), prevention of market manipulation and other wrongful activity (February 2018), and a January 2025 notice regarding rapidly proliferating sentiment-based virtual currencies (memecoins). Cybersecurity obligations on virtual currency licensees are layered with 23 NYCRR Part 500 (Cybersecurity Requirements for Financial Services Companies) and 23 NYCRR Part 504 (Transaction Monitoring and Filtering Program Requirements and Certifications). DFS operationalises supervisory excellence through the VOLT program: Vision, Operations, Leadership, and Technology. Licensed entities include Anchorage Digital NY, Bakkt Crypto Solutions, Bastion Platforms Trust Company, and many others; voluntary surrenders by Cboe Clear Digital, SoFi Digital Assets, Genesis, and Coinsource are publicly tracked. Inquiries: virtualcurrency@dfs.ny.gov.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us-ny-dfs-cybersecurity-regulation-part-500",
        "us-ny-dfs-part-504-aml-transaction-monitoring",
        "uk-mlr-2019-1511-cryptoasset-amendment",
        "eu-mica-regulation-2023",
        "us-genius-act-stablecoin-2025-framework",
        "fatf-recommendation-16-travel-rule-crypto",
        "us-cftc-digital-commodities-cea-jurisdiction",
        "us-sec-digital-asset-framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-genius-act-stablecoin-2025-framework"
    ],
    "primary_citations_count": 18
  },
  {
    "node_id": "us-ny-dfs-cybersecurity-regulation-23-nycrr-part-500",
    "title": "New York State Department of Financial Services - 23 NYCRR Part 500 Cybersecurity Regulation (Enacted 1 March 2017; First Amended April 2020 to Move Annual Certification Filing to 15 April; Second Amended Effective 1 November 2023 with Class A Company Heightened Standards)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2023-11-01",
    "bluf": "23 NYCRR Part 500 - the New York State Department of Financial Services Cybersecurity Regulation - was enacted on 1 March 2017 as the first-in-the-nation comprehensive state-level cybersecurity regulation for financial services companies. The Regulation has been amended twice: first in April 2020 (changing the annual certification filing date from 15 February to 15 April each year) and then in a substantial amendment effective 1 November 2023 (introducing the Class A Company tier with heightened requirements, expanded incident notification obligations, and other enhancements). Part 500 applies to 'Covered Entities' as defined in Section 500.1(e) - entities operating under or required to operate under a 'license, registration, charter, certificate, permit, accreditation or similar authorization' pursuant to New York's Banking, Insurance, or Financial Services Law. This includes BitLicensees, limited purpose trust companies, banks, insurers, mortgage brokers, and other DFS-supervised entities. The Regulation establishes a comprehensive cybersecurity program covering: written cybersecurity policies (Section 500.3); a Chief Information Security Officer with documented qualifications (Section 500.4(a)); CISO annual written reporting to the Senior Governing Body (Section 500.4(b), which is defined in Section 500.1(q) and includes an appropriate committee of the board); risk-based application security procedures reviewed at least annually by the CISO (Section 500.8(b)); a Risk Assessment reviewed and updated as reasonably necessary, but at a minimum annually, and whenever a change in business or technology causes a material change to cyber risk (Section 500.9(a)); third-party service provider security policies and due diligence (Section 500.11(a)(3) and (b)); MFA, encryption, incident response, training, monitoring, and access controls. The November 2023 amendments introduced the Class A Company tier (under Section 500.1(d)) - large Covered Entities subject to heightened requirements including independent audits and weight-of-evidence on tabletop exercises. Affiliates of a Class A Company with NY business operations are themselves subject to Part 500 only if separately Covered Entities. The Regulation has informed federal and other state cybersecurity rulemaking. Annual certification of material compliance is filed via the DFS portal using DFS ID credentials and MFA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us-ny-dfs-bitlicense-23-nycrr-part-200",
        "us-ny-dfs-part-504-aml-transaction-monitoring",
        "us-eu-shield-replacement-data-protection-framework",
        "us-nist-cybersecurity-framework-csf-2-0",
        "us-fed-banking-agencies-computer-security-incident-notification-2022",
        "eu-nis2-essential-important-entities-obligations",
        "uk-fca-cybersecurity-resilience-2024",
        "us-ny-dfs-cybersecurity-regulation-financial-services-companies-amendments-2023"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ny-dfs-bitlicense-23-nycrr-part-200"
    ],
    "primary_citations_count": 17
  },
  {
    "node_id": "us-ny-dfs-insurance-circular-letter-7-ai-2024",
    "title": "NY DFS Insurance Circular Letter No. 7 (2024) - AI Systems and External Consumer Data in Underwriting and Pricing",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "NY DFS Insurance Circular Letter No. 7 (2024), issued 11 July 2024, sets supervisory expectations for the use of Artificial Intelligence Systems (AIS) and External Consumer Data and Information Sources (ECDIS) in underwriting and pricing by insurers authorized in New York, Article 43 corporations, HMOs, fraternal benefit societies and the NY State Insurance Fund. Section II requires a three-step unfair discrimination assessment (Section II three-step assessment): (1) test disproportionate adverse effects on protected classes; (2) assess legitimate business rationales; (3) search for less discriminatory alternatives at least annually. Quantitative metrics under Section II Quantitative Assessment include Adverse Impact Ratio, Denials Odds Ratios, Marginal Effects, Standardized Mean Differences, and statistical significance tests. Section III mandates board strategic oversight (III.A), written policies with annual review (III.B), risk management with independent challenge (III.C) and third-party vendor management with audit rights (III.D). Section IV requires consumer disclosure including notice of AIS use, external data sources, adverse-decision details (Section IV Disclosure) and prohibits reliance on proprietary-nature claims to avoid specificity (Section IV Proprietary). Documentation requirements (Section III Documentation) cover AIS inventory, models, data lifecycle, change approvals, monitoring and drift testing. ECDIS excludes MIB exchanges, motor vehicle reports, prescription drug data and criminal history searches.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "naic_model_bulletin_ai_systems_insurers_2023",
        "us_co_sb24_205",
        "us_eeoc_ai_employment_guidance_2023",
        "ny_dfs_cybersecurity_regulation_23_nycrr_part_500",
        "iso_iec_42001_ai_management_system"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-colorado-ai-act-sb24-205",
      "us-eeoc-ai-employment-guidance-2023",
      "nydfs-part-500-cybersecurity-v2-2023",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-ny-education-law-2d-student-data-privacy",
    "title": "New York Education Law Section 2-d (Unauthorized Release of PII)",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "New York Education Law Section 2-d protects personally identifiable information of students and certain educator data held by educational agencies and their third-party contractors. Section 2-d(3) requires each educational agency to publish a Parents Bill of Rights for Data Privacy and Security, and Section 2-d(4)(f) prohibits selling personally identifiable information or using it for marketing purposes. Sections 2-d(5) and 2-d(6) require data security safeguards and breach notification, and Section 2-d(5)(f) imposes specific obligations on third-party contractors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-34-cfr-part-99-ferpa-student-records",
      "us-coppa-16-cfr-part-312-edtech-school-operators"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ny-raise-act-chapter-699-2025",
    "title": "New York Responsible AI Safety and Education (RAISE) Act - Senate Bill S 6953-B / Chapter 699 of 2025",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "The New York Responsible AI Safety and Education (RAISE) Act, enacted as Chapter 699 of the Laws of 2025 (Senate Bill S 6953-B), was signed by Governor Hochul on 19 December 2025 and adds a new Article 44-B to the New York General Business Law titled 'Artificial Intelligence Frontier Models'. The Act takes effect ninety days after enactment under the bill's effective date clause. Section 1420 defines key terms including frontier model (a model trained using greater than 10^26 computational operations and compute cost exceeding 100 million dollars, or a distillation from a frontier model with compute cost exceeding 5 million dollars), critical harm, large developer (one with at least one frontier model and over 100 million dollars in aggregate compute spend on frontier model training), and safety incident. Section 1421 imposes binding transparency requirements on large developers including: written safety and security protocols implemented before deployment; unredacted retention for the duration of deployment plus five years; publication of a redacted version and transmission to the Attorney General and the State Division of Homeland Security and Emergency Services; testing records sufficient for replication; annual review and update of protocols; and disclosure of safety incidents within 72 hours. Section 1422 establishes civil penalties of up to 10 million dollars for a first violation and 30 million dollars for subsequent violations of Section 1421, plus up to 10,000 dollars per affected employee for retaliation violations, with injunctive and declaratory relief and contractual waivers void as against public policy. Section 1423 makes the duties cumulative with other laws and Section 1424 limits territorial scope to models developed, deployed or operating in New York State. The Attorney General has exclusive enforcement authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-sb53-frontier-ai",
      "us-tx-traiga-hb149-2025-responsible-ai-governance",
      "us-co-sb205-high-risk-ai"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ny-shield-act-2019",
    "title": "New York SHIELD Act 2019",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "New York's Stop Hacks and Improve Electronic Data Security Act expands breach notification obligations and imposes mandatory reasonable data security requirements on any business holding private information of New York residents, enforced by the NYS Attorney General.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ny-shield-act-2019.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cpra-california-privacy-rights-act-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-nyc-ll-144-aedt-2021",
    "title": "New York City Local Law 144 - Automated Employment Decision Tools (Enacted 2021, Effective July 5 2023)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "New York City Local Law 144 of 2021, codified at New York City Administrative Code 20-870 et seq., regulates the use of Automated Employment Decision Tools (AEDTs) by employers and employment agencies in New York City. The Law took effect January 1, 2023 with enforcement deferred to July 5, 2023. Core requirements: (1) Bias audit - an employer or employment agency cannot use an AEDT to screen a candidate or employee for an employment decision unless an independent bias audit of the tool has been conducted within the preceding year and the summary of results is publicly available; (2) Notice to candidates - candidates and employees who reside in New York City must be notified at least 10 business days before the AEDT is used; notice must include the job qualifications and characteristics the tool will use, instructions for requesting an alternative selection process or accommodation, and information on retention and processing of personal information; (3) Bias audit standards - the bias audit must measure selection rates and impact ratios across race, ethnicity, and sex categories and intersectional categories required by EEOC Uniform Guidelines on Employee Selection Procedures; (4) Penalty - civil penalty of USD 500 for a first violation and not less than USD 500 nor more than USD 1500 for each subsequent violation per day. The Law was implemented by NYC Department of Consumer and Worker Protection rules at the Rules of the City of New York at 6 RCNY 5-300 effective July 5, 2023.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "regulatory_overlay",
        "ai_governance_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eeoc-ai-employment-guidance-2023",
      "us-eeoc-ada-ai-job-applicants-guidance-2022",
      "us-doj-ada-ai-disability-employment-2022",
      "us-doj-eeoc-cfpb-ftc-joint-statement-ai-2023"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-nyc-ll144-aedt-bias-audit-2023",
    "title": "NYC Local Law 144 of 2021 - Automated Employment Decision Tool (AEDT) Bias Audit Rules (DCWP Subchapter T, 6 RCNY)",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "NYC Local Law 144 of 2021 (codified at NYC Administrative Code Sections 20-870 through 20-871) and the Department of Consumer and Worker Protection final rules (Subchapter T of Chapter 5 of Title 6 of the Rules of the City of New York, 6 RCNY 5-300 through 5-304, effective 5 July 2023) prohibit employers and employment agencies from using an AEDT to substantially assist or replace discretionary decision making in hiring or promotion decisions for candidates or employees residing in NYC unless: (1) a bias audit by an Independent Auditor has been performed within one year (Section 5-301(a)); (2) the audit calculates the selection rate and impact ratio for each EEOC EEO-1 race/ethnicity, sex and intersectional category (Section 5-301(b)); (3) a summary of audit results and the AEDT distribution date is publicly posted on the employment section of the website for at least 6 months after the latest use of the AEDT (Section 5-303); and (4) candidates and employees are given clear notice - in job posting, written policy, e-mail or US mail - at least 10 business days before AEDT use, including instructions to request an alternative process or reasonable accommodation, plus a written-request channel for AEDT data retention, type and source within 30 days (Section 5-304). The impact ratio is selection rate (or scoring rate) for a category divided by the most-selected (or highest-scoring) category - the EEOC Uniform Guidelines four-fifths analogue (Section 1607.4 of the EEOC Uniform Guidelines).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_eeoc_uniform_guidelines_employee_selection",
        "us_eeoc_ai_employment_guidance_2023",
        "us_co_sb24_205",
        "iso_iec_42001_ai_management_system",
        "eu_ai_act"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eeoc-ai-employment-guidance-2023",
      "us-colorado-ai-act-sb24-205",
      "iso-iec-42001-ai-management-system-2023",
      "eu-ai-act-annex-iii-high-risk-ai-list"
    ],
    "primary_citations_count": 13
  },
  {
    "node_id": "us-nyc-local-law-144-2021",
    "title": "New York City Local Law 144 on Automated Employment Decision Tools 2021",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "NYC Local Law 144 effective July 5, 2023 requires employers using automated employment decision tools to screen NYC-based candidates or employees to conduct annual independent bias audits, publish audit results, and notify candidates at least 10 business days before assessment with civil penalties of up to USD 1,500 per day for non-compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-nyc-local-law-144-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-nyc-local-law-144-aedt-bias-audit",
    "title": "New York City Local Law 144 of 2021 (NYC Admin Code Sections 20-870 to 20-874, Automated Employment Decision Tools, Bias Audit, Candidate Notice, DCWP Enforcement)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "New York City Local Law 144 of 2021, codified at New York City Administrative Code sections 20-870 through 20-874, regulates the use of Automated Employment Decision Tools (AEDTs) by employers and employment agencies that screen candidates for employment or employees for promotion within New York City. The law became effective on 1 January 2023 with enforcement by the New York City Department of Consumer and Worker Protection (DCWP) commencing 5 July 2023 under final rules issued at 6 RCNY Chapter 5 Subchapter T. § 20-870 defines an automated employment decision tool as any computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that produces a simplified output (a score, classification, or recommendation) used to substantially assist or replace discretionary employment decisions, and defines a bias audit as an impartial evaluation by an independent auditor that tests for disparate impact across sex, race, ethnicity, and intersectional categories using selection-rate ratios and impact-ratio metrics. § 20-871 prohibits an employer or employment agency from using an AEDT to screen a candidate or employee for an employment decision in New York City unless (i) a bias audit of the tool has been conducted no more than one year prior to the use, and (ii) a summary of the results of the most recent bias audit and the distribution date of the tool is made publicly available on the employer or employment agency website before the use. § 20-871(b) requires candidates and employees who reside in New York City to be notified of the use of the AEDT at least 10 business days before the use, identifying the job qualifications and characteristics that the tool will assess, and providing on written request within 30 days information about the type of data collected, the source of the data, and the data retention policy. § 20-872 establishes civil penalties of 500 dollars for a first violation and not less than 500 nor more than 1500 dollars for each subsequent violation; each day of non-compliant use constitutes a separate violation. § 20-874 preserves all other civil rights remedies, including those administered by the New York City Commission on Human Rights under Title 8 of the Administrative Code.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_basis",
        "key_institutions",
        "section_20_870_definitions",
        "section_20_871_lawful_use_prerequisites",
        "section_20_871_b_candidate_notice",
        "dcwp_final_rules_6_rcny_5_subchapter_t",
        "section_20_872_penalty_schedule",
        "section_20_874_construction_clause",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-civil-rights-act-title-vii",
      "us-eeoc-29-cfr-1630-ada-employment-provisions",
      "us-eeoc-ai-employment-guidance-2023",
      "us-co-sb205-high-risk-ai"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-occ-12-cfr-part-50-liquidity-risk-measurement-standards",
    "title": "12 CFR Part 50 - OCC Liquidity Risk Measurement Standards (Liquidity Coverage Ratio and Net Stable Funding Ratio for National Banks and Federal Savings Associations)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "12 CFR Part 50 is the Office of the Comptroller of the Currency (OCC) liquidity risk measurement rule implementing the Basel III Liquidity Coverage Ratio (LCR) and Net Stable Funding Ratio (NSFR) for certain national banks and Federal savings associations on a consolidated basis. Section 50.1(a) establishes a minimum liquidity standard and a minimum stable funding standard. Section 50.1(b)(1) applies to a national bank or Federal savings association that is (A) a GSIB depository institution supervised by the OCC, (B) a Category II national bank or Federal savings association, or (C) a Category III national bank or Federal savings association, or where the OCC has determined that application is appropriate. Section 50.1(b)(2) excludes bridge financial companies as defined in 12 USC 5381(a)(3) and their subsidiaries, new depository institutions and bridge depository institutions as defined in 12 USC 1813(i), and Federal branches or agencies as defined by 12 CFR 28.11. Section 50.3 sets the operative definitions in parallel with the FRB Regulation WW (12 CFR Part 249) and the FDIC LCR rule (12 CFR Part 329), including LCR, NSFR, HQLA, level 1, level 2A, and level 2B liquid assets, brokered deposit, operational deposit, average weighted short-term wholesale funding, and other Basel III-aligned operative terms. Section 50.10(a) requires the institution to calculate and maintain a liquidity coverage ratio equal to or greater than 1.0 on each business day in accordance with Part 50, with the elected calculation time fixed by written notice to the OCC prior to December 31, 2019. Section 50.10(b) calculates the LCR as the HQLA amount under subpart C divided by the total net cash outflow amount under subpart D. Section 50.20 sets HQLA criteria - level 1 includes Reserve Bank balances, foreign withdrawable reserves, US Treasury securities, US government agency securities fully and explicitly guaranteed by the full faith and credit of the US government, and sovereign or BIS/IMF/ECB/European Community/multilateral development bank securities at zero percent risk weight under subpart D of 12 CFR Part 3 (the OCC capital rule). Section 50.21 calculates the HQLA amount as level 1 plus 85% of level 2A plus 50% of level 2B less the greater of the unadjusted or adjusted excess HQLA amount. Section 50.22 sets operational requirements including monetisation capability, control under the liquidity management function, and daily fair-value calculation. Section 50.40 imposes the liquidity coverage shortfall supervisory framework requiring OCC notification on any business day the LCR falls below the minimum requirement. The Net Stable Funding Ratio is implemented in Subpart K. Part 50 is the OCC's mirror of the FRB Regulation WW (12 CFR Part 249) and the FDIC LCR rule (12 CFR Part 329) and was issued at 79 FR 61523, 61538, on 10 October 2014.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "purpose_and_applicability_anchor",
        "definitions_anchor",
        "minimum_lcr_anchor",
        "hqla_criteria_anchor",
        "hqla_amount_calculation_anchor",
        "shortfall_supervisory_framework_anchor",
        "nsfr_anchor",
        "mirror_with_other_banking_agencies_anchor",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-12-cfr-part-249-federal-reserve-lcr-regulation-ww",
      "basel-iii-liquidity-lcr",
      "bcbs-248-monitoring-tools-intraday-liquidity-management-2013",
      "us-dodd-frank-stress-testing-dfast-2010",
      "lcr-disclosure-standards"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-occ-bank-charter-national-banks-12-cfr-1-permissible-activities",
    "title": "US OCC National Bank Charter - 12 CFR Part 1 and Permissible Activities for National Banks",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "The Office of the Comptroller of the Currency (OCC) charters, regulates, and supervises national banks and federal savings associations under the National Bank Act (12 USC 1 et seq.) and Home Owners Loan Act. National banks must obtain OCC approval for new activities and expansions. The OCC has affirmed that national banks may provide custody services for cryptocurrency assets (Interpretive Letter 1170, 2020) and participate in blockchain networks. OCC licensing requirements include minimum capital, business plan approval, and ongoing examination programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-31-cfr-1010-aml"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-occ-fintech-charter",
    "title": "OCC Special Purpose National Bank Charter for Fintech Companies - Licensing Framework and Requirements",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-07-31",
    "bluf": "The Office of the Comptroller of the Currency (OCC) provides a framework for financial technology (fintech) companies to apply for a special purpose national bank charter, subjecting them to federal banking supervision and the same safety, soundness, and fairness standards as national banks. Applicants must demonstrate a comprehensive business plan, robust risk management, and a commitment to financial inclusion as detailed in the OCC's \"Licensing Manual: Charters\" booklet.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "interagency-guidance-third-party-risk-management",
      "bank-secrecy-act-suspicious",
      "bcbs-principles-operational-resilience",
      "us-dodd-frank-key-provisions",
      "guidance-on-model-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-occ-model-risk-guidance-2021",
    "title": "OCC Model Risk Management Guidance 2021 - Supervisory Guidance on Model Risk Management for National Banks",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This guidance supplements SR 11-7, requiring national banks and federal savings associations to maintain a robust model risk management (MRM) framework, including effective governance, policies, and controls, particularly for models using artificial intelligence and machine learning (AI/ML). As per Section 1, banks must ensure their MRM framework is commensurate with their risk profile and the complexity of their models.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sr-11-7-model-risk-management",
      "interagency-guidance-third-party-risk-management",
      "bis-ai-financial-services-2023"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-occupational-safety-and-health-act",
    "title": "US Occupational Safety and Health Act (29 USC ch 15): The General Duty Clause, Standards, Inspections and Penalties",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Occupational Safety and Health Act of 1970 (29 U.S.C. ch. 15) establishes the federal framework for workplace safety and health, administered by the Occupational Safety and Health Administration (OSHA) within the Department of Labor, with adjudication by the Occupational Safety and Health Review Commission. Section 651 states the purpose of assuring so far as possible safe and healthful working conditions for every working person. Section 652 supplies the definitions, including employer, employee and occupational safety and health standard. Section 654 imposes the core duties: the general duty clause requires each employer to furnish a place of employment free from recognized hazards likely to cause death or serious physical harm, and to comply with the standards, and requires employees to comply with applicable standards. Section 655 governs the promulgation of standards, including emergency temporary standards. Section 657 authorizes workplace inspections, investigations and recordkeeping. Section 658 provides for citations with a reasonable abatement period, and section 659 sets the enforcement procedure, including the 15 working days an employer has to contest a citation. Section 666 sets the penalties: up to 70,000 dollars for a willful or repeated violation (with a minimum of 5,000 dollars for a willful violation), up to 7,000 dollars for a serious or other-than-serious violation, and, for a willful violation causing death, a fine and imprisonment of up to 6 months (rising on a second conviction), with these civil amounts subject to annual inflation adjustment. Section 660 provides for judicial review. The Act is the legal foundation of US workplace-safety compliance and enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-occupational-safety-health-act-1970",
    "title": "The Occupational Safety and Health Act of 1970",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This US federal law requires most private sector employers to provide their employees with a workplace free from recognized hazards that are causing or are likely to cause death or serious physical harm, as mandated by the General Duty Clause (Section 5(a)(1)). The Act also establishes the Occupational Safety and Health Administration (OSHA) to create and enforce specific safety and health standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-45001-work-safety",
      "osha-hazard-communication-standard",
      "ada-employment-title-1",
      "us-osha-ai-ergonomics-guidance",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ocean-dumping-act",
    "title": "US Ocean Dumping Act / MPRSA Title I (33 USC ch 27): Dumping Permits, Prohibitions and Penalties",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "Title I of the Marine Protection, Research, and Sanctuaries Act of 1972 (the Ocean Dumping Act), codified at 33 U.S.C. Chapter 27 (sections 1401-1445), regulates the transportation and dumping of material into ocean waters and is administered by the US Environmental Protection Agency (EPA), with the US Army Corps of Engineers responsible for permits for the ocean dumping of dredged material. Section 1401 sets the findings, policy and purpose, and section 1402 contains the definitions. Section 1411 sets the prohibited acts: no person shall transport from the United States, and no officer or employee of a department, agency or instrumentality of the United States shall transport from any location, any material for the purpose of dumping it into ocean waters, except as authorized by a permit; and no person shall dump any material transported from a location outside the United States into the territorial sea of the United States or into a zone contiguous to the territorial sea, except as authorized. Section 1412 establishes the EPA dumping permit program, under which EPA may issue permits for dumping where it determines that the dumping will not unreasonably degrade or endanger human health, welfare or the marine environment, applying published criteria and designated disposal sites. Section 1413 establishes the permit program administered by the Corps of Engineers for the dumping of dredged material, using EPA's criteria. Section 1414 sets permit conditions, monitoring and recordkeeping. Section 1415 sets the penalties: a civil penalty of not more than $50,000 for each violation (and not more than $125,000 for dumping medical waste), assessed after notice and an opportunity for a hearing, with each day of a continuing violation a separate offense; and a criminal penalty for a knowing violation of a fine under title 18 or imprisonment of not more than five years, or both, together with forfeiture provisions. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-510-north-korea-sanctions-regulations",
    "title": "31 CFR Part 510 (North Korea Sanctions Regulations) - OFAC Blocking, Trade Prohibitions and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 510, the North Korea Sanctions Regulations, implements the U.S. sanctions on North Korea administered by the Office of Foreign Assets Control under a series of Executive Orders and the North Korea Sanctions and Policy Enhancement Act. All property and interests in property of the Government of North Korea, the Workers' Party of Korea, and persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in. The regulations prohibit the importation into the United States of goods, services or technology from North Korea, the exportation or reexportation of goods, services or technology to North Korea, new investment in North Korea, and certain vessel and aircraft transactions. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments due to blocked persons must be placed in blocked accounts. U.S. persons must report blocked property and rejected transactions to OFAC and file the annual report, maintain records for five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-515-cuban-assets-control-regulations",
    "title": "31 CFR Part 515 (Cuban Assets Control Regulations) - OFAC Cuba Embargo, Travel and Remittances",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 515, the Cuban Assets Control Regulations, administers the comprehensive U.S. embargo on Cuba through the Office of Foreign Assets Control under the Trading With the Enemy Act and later Cuba-specific statutes. As a general matter, all transactions involving property in which Cuba or a Cuban national has an interest are prohibited unless authorized by a general or specific license, and property subject to U.S. jurisdiction in which a designated Cuban national has an interest is blocked. The importation into the United States of merchandise of Cuban origin, or merchandise that has been located in or transported from or through Cuba, is prohibited. Travel-related transactions involving Cuba are authorized only for travelers who fall within one of the categories of authorized travel, and travel for tourist activities is prohibited. Remittances to Cuba and Cuban nationals are permitted only within the authorized categories and limits. A vessel that has entered a port or place in Cuba to engage in the trade of goods or services generally may not, within 180 days, load or unload freight at a U.S. port. Persons subject to U.S. jurisdiction may not engage in certain direct financial transactions with entities and subentities identified on the State Department's Cuba Restricted List. Otherwise-prohibited transactions require an OFAC license, and persons must keep full records for five years and report as required.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-525-burma-sanctions-regulations",
    "title": "31 CFR Part 525 (Burma Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 525, the Burma Sanctions Regulations, implements the U.S. sanctions on Burma (Myanmar) administered by the Office of Foreign Assets Control under Executive Order 14014 (86 FR 9429). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-526-hostages-wrongful-detention-sanctions-regulations",
    "title": "31 CFR Part 526 (Hostages and Wrongful Detention Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 526, the Hostages and Wrongful Detention Sanctions Regulations, implements the U.S. sanctions addressing hostage-taking and the wrongful detention of United States nationals abroad administered by the Office of Foreign Assets Control under Executive Order 14078 (87 FR 43389). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-ofac-31-cfr-528-international-criminal-court-related-sanctions-regulations",
    "title": "31 CFR Part 528 (International Criminal Court-Related Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 528, the International Criminal Court-Related Sanctions Regulations, implements the U.S. sanctions with respect to the International Criminal Court administered by the Office of Foreign Assets Control under Executive Order 14203 (90 FR 9369). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-536-narcotics-trafficking-sanctions-regulations",
    "title": "31 CFR Part 536 (Narcotics Trafficking Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 536, the Narcotics Trafficking Sanctions Regulations, implements the U.S. sanctions targeting significant foreign narcotics traffickers centered in Colombia administered by the Office of Foreign Assets Control under Executive Order 12978 (60 FR 54579). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ofac-31-cfr-546-sudan-stabilization-sanctions-regulations",
    "title": "31 CFR Part 546 (Sudan Stabilization Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 546, the Sudan Stabilization Sanctions Regulations, implements the U.S. sanctions on Sudan administered by the Office of Foreign Assets Control under Executive Order 13067 (62 FR 59989), Executive Order 13400 (71 FR 25483) and Executive Order 14098 (88 FR 29529). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-547-democratic-republic-congo-sanctions-regulations",
    "title": "31 CFR Part 547 (Democratic Republic of the Congo Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 547, the Democratic Republic of the Congo Sanctions Regulations, implements the U.S. sanctions with respect to the Democratic Republic of the Congo administered by the Office of Foreign Assets Control under Executive Order 13413 (71 FR 64105) and Executive Order 13671 (79 FR 39949). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-548-belarus-sanctions-regulations",
    "title": "31 CFR Part 548 (Belarus Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 548, the Belarus Sanctions Regulations, implements the U.S. sanctions on Belarus administered by the Office of Foreign Assets Control under Executive Order 13405 and Executive Order 14038. All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from making or receiving any contribution or provision of funds, goods or services to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-549-lebanon-sanctions-regulations",
    "title": "31 CFR Part 549 (Lebanon Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 549, the Lebanon Sanctions Regulations, implements the U.S. sanctions with respect to Lebanon administered by the Office of Foreign Assets Control under Executive Order 13441 (72 FR 43499). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-550-ethiopia-sanctions-regulations",
    "title": "31 CFR Part 550 (Ethiopia Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 550, the Ethiopia Sanctions Regulations, implements the U.S. sanctions with respect to the conflict in Ethiopia administered by the Office of Foreign Assets Control under Executive Order 14046 (86 FR 52389). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-551-somalia-sanctions-regulations",
    "title": "31 CFR Part 551 (Somalia Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 551, the Somalia Sanctions Regulations, implements the U.S. sanctions with respect to Somalia administered by the Office of Foreign Assets Control under Executive Order 13536 (75 FR 19869) and Executive Order 13620 (77 FR 43483). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-552-yemen-sanctions-regulations",
    "title": "31 CFR Part 552 (Yemen Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 552, the Yemen Sanctions Regulations, implements the U.S. sanctions with respect to Yemen administered by the Office of Foreign Assets Control under Executive Order 13611 (77 FR 29533). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-553-central-african-republic-sanctions-regulations",
    "title": "31 CFR Part 553 (Central African Republic Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 553, the Central African Republic Sanctions Regulations, implements the U.S. sanctions with respect to the Central African Republic administered by the Office of Foreign Assets Control under Executive Order 13667 (79 FR 28387). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-555-mali-sanctions-regulations",
    "title": "31 CFR Part 555 (Mali Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 555, the Mali Sanctions Regulations, implements the U.S. sanctions with respect to Mali administered by the Office of Foreign Assets Control under Executive Order 13882 (84 FR 37055). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-558-south-sudan-sanctions-regulations",
    "title": "31 CFR Part 558 (South Sudan Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 558, the South Sudan Sanctions Regulations, implements the U.S. sanctions with respect to South Sudan administered by the Office of Foreign Assets Control under Executive Order 13664 (79 FR 19283). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-562-iranian-sector-human-rights-abuses-sanctions-regulations",
    "title": "31 CFR Part 562 (Iranian Sector and Human Rights Abuses Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 562, the Iranian Sector and Human Rights Abuses Sanctions Regulations, implements the U.S. sanctions targeting the Iranian financial sector and human rights abuses by the Government of Iran administered by the Office of Foreign Assets Control under Executive Order 12957 (60 FR 14615), Executive Order 13553 (75 FR 60567) and Executive Order 13871 (84 FR 20761). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-ofac-31-cfr-566-hizballah-financial-sanctions-regulations",
    "title": "31 CFR Part 566 (Hizballah Financial Sanctions Regulations) - OFAC Correspondent Account Restrictions, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 566, the Hizballah Financial Sanctions Regulations, implements the Hizballah International Financing Prevention Act of 2015 as amended, administered by the Office of Foreign Assets Control. The program does not block property generally; instead it authorizes the Secretary of the Treasury, on determining that a foreign financial institution knowingly facilitates a significant transaction or transactions for Hizballah or for persons identified on the OFAC Specially Designated Nationals and Blocked Persons List in connection with Hizballah, to impose strict conditions on, or to prohibit the opening or maintaining of, a correspondent account or a payable-through account in the United States for that foreign financial institution. U.S. financial institutions must implement any such strict conditions or prohibition, must not open or maintain a prohibited account, and must not engage in any transaction that evades or avoids the prohibitions. Otherwise-prohibited transactions require an OFAC general or specific license, and U.S. persons must report to OFAC as required, maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-569-promoting-accountability-assad-sanctions-regulations",
    "title": "31 CFR Part 569 (Promoting Accountability for Assad and Regional Stabilization Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 569, the Promoting Accountability for Assad and Regional Stabilization Sanctions Regulations, implements the U.S. sanctions with respect to Syria, promoting accountability for the Assad regime and regional stabilization administered by the Office of Foreign Assets Control under Executive Order 13606 (77 FR 24571), Executive Order 13894 (84 FR 55851), Executive Order 14142 (90 FR 6709) and Executive Order 14312 (90 FR 29395). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-ofac-31-cfr-570-libyan-sanctions-regulations",
    "title": "31 CFR Part 570 (Libyan Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 570, the Libyan Sanctions Regulations, implements the U.S. sanctions with respect to Libya administered by the Office of Foreign Assets Control under Executive Order 13566 (76 FR 11315) and Executive Order 13726 (81 FR 23559). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-576-iraq-stabilization-insurgency-sanctions-regulations",
    "title": "31 CFR Part 576 (Iraq Stabilization and Insurgency Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 576, the Iraq Stabilization and Insurgency Sanctions Regulations, implements the U.S. sanctions with respect to the stabilization of Iraq administered by the Office of Foreign Assets Control under Executive Order 13303 (68 FR 31931), Executive Order 13315 (68 FR 52315), Executive Order 13350 (69 FR 46055), Executive Order 13364 (69 FR 70177), Executive Order 13438 (72 FR 39719) and Executive Order 13668 (79 FR 31019). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. The regulations also prohibit trade in or other dealings involving certain Iraqi cultural property and other items of archaeological, historical, cultural, rare scientific or religious importance illegally removed from Iraq, per § 576.411. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-ofac-31-cfr-578-cyber-related-sanctions-regulations",
    "title": "31 CFR Part 578 (Cyber-Related Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 578, the Cyber-Related Sanctions Regulations, implements the U.S. sanctions targeting significant malicious cyber-enabled activities, administered by the Office of Foreign Assets Control under Executive Order 13694 as amended by Executive Order 13757. All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and any transaction that evades or avoids, or attempts to violate, the prohibitions is itself prohibited. Persons may be designated for cyber-enabled activities that harm critical infrastructure, misappropriate funds or economic resources, or interfere with election processes. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked, interest-bearing account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-ofac-31-cfr-579-foreign-interference-us-elections-sanctions-regulations",
    "title": "31 CFR Part 579 (Foreign Interference in U.S. Elections Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 579, the Foreign Interference in U.S. Elections Sanctions Regulations, implements the U.S. sanctions addressing foreign interference in a United States election administered by the Office of Foreign Assets Control under Executive Order 13848 (83 FR 46843). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-582-nicaragua-sanctions-regulations",
    "title": "31 CFR Part 582 (Nicaragua Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 582, the Nicaragua Sanctions Regulations, implements the U.S. sanctions with respect to Nicaragua administered by the Office of Foreign Assets Control under Executive Order 13851 (83 FR 61505). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-ofac-31-cfr-585-hong-kong-related-sanctions-regulations",
    "title": "31 CFR Part 585 (Hong Kong-Related Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 585, the Hong Kong-Related Sanctions Regulations, implements the U.S. sanctions with respect to Hong Kong administered by the Office of Foreign Assets Control under Executive Order 13936 (85 FR 43413). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-586-chinese-military-industrial-complex-sanctions-regulations",
    "title": "31 CFR Part 586 (Chinese Military-Industrial Complex Sanctions Regulations) - OFAC Securities Investment Prohibitions, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 586, the Chinese Military-Industrial Complex Sanctions Regulations, implements Executive Order 13959 as amended by Executive Order 14032, administered by the Office of Foreign Assets Control. The program does not block property; it prohibits U.S. persons from engaging in the purchase or sale of any publicly traded security, or any security that is derivative of, or is designed to provide investment exposure to, such a security, of any person identified on OFAC's Non-SDN Chinese Military-Industrial Complex Companies List (NS-CMIC List). OFAC sets divestment and wind-down periods for transactions in covered securities, and prohibited transactions must cease after the applicable date. OFAC has advised that the prohibition extends to a subsidiary that OFAC has publicly listed as 50 percent or more owned, individually or in the aggregate, by one or more persons on the NS-CMIC List. Transactions that would otherwise be prohibited require an OFAC general or specific license, and U.S. persons must maintain full records for at least five years, file reports as required, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ofac-31-cfr-588-western-balkans-stabilization-regulations",
    "title": "31 CFR Part 588 (Western Balkans Stabilization Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 588, the Western Balkans Stabilization Regulations, implements the U.S. sanctions with respect to the Western Balkans administered by the Office of Foreign Assets Control under Executive Order 13219 (66 FR 34777), Executive Order 13304 (68 FR 32315) and Executive Order 14033 (86 FR 43905). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-589-ukraine-russia-related-sanctions-regulations",
    "title": "31 CFR Part 589 (Ukraine-/Russia-Related Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 589, the Ukraine-/Russia-Related Sanctions Regulations, implements the U.S. sanctions with respect to the situation in and in relation to Ukraine, including Russia-related sanctions administered by the Office of Foreign Assets Control under Executive Order 13660 (79 FR 13493), Executive Order 13661 (79 FR 15535), Executive Order 13662 (79 FR 16169), Executive Order 13685 (79 FR 77357), Executive Order 13849 and Executive Order 14065 (87 FR 10293). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. In addition to full blocking, the program imposes sectoral sanctions through directives that prohibit dealings in specified new debt, new equity and energy-sector financing of identified persons, separate from blocking, per § 589.202 through § 589.205. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-ofac-31-cfr-590-transnational-criminal-organizations-sanctions-regulations",
    "title": "31 CFR Part 590 (Transnational Criminal Organizations Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 590, the Transnational Criminal Organizations Sanctions Regulations, implements the U.S. sanctions targeting significant transnational criminal organizations, administered by the Office of Foreign Assets Control under Executive Order 13581 as amended by Executive Order 13863. All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, including the property of persons who materially assist, sponsor or support a blocked person or who are owned or controlled by a blocked person. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked, interest-bearing account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-ofac-31-cfr-591-venezuela-sanctions-regulations",
    "title": "31 CFR Part 591 (Venezuela Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 591, the Venezuela Sanctions Regulations, implements the U.S. sanctions on Venezuela administered by the Office of Foreign Assets Control under a series of Executive Orders, including the blocking of the Government of Venezuela. All property and interests in property of persons designated under the program, and of the Government of Venezuela, that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments and transfers to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-592-rough-diamonds-control-regulations",
    "title": "31 CFR Part 592 (Rough Diamonds Control Regulations) - OFAC Kimberley Process Import and Export Controls",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 592, the Rough Diamonds Control Regulations, implements the Clean Diamond Trade Act and Executive Order 13312, administered by the Office of Foreign Assets Control to give effect in the United States to the Kimberley Process Certification Scheme. The importation into, or exportation from, the United States of any rough diamond, from whatever source, is prohibited unless the rough diamond has been controlled through the Kimberley Process Certification Scheme. To be controlled through the Scheme, a shipment of rough diamonds must be accompanied by an original Kimberley Process Certificate, and the original certificate must be presented immediately upon demand to U.S. Customs and Border Protection and retained by the ultimate consignee. An importation from, or exportation to, a non-Participant is not controlled through the Scheme and is therefore prohibited, except where the Secretary of State has granted a country waiver under section 4(b) of the Clean Diamond Trade Act. Persons must not evade or avoid the prohibitions, must maintain full records for at least five years, must file reports as required, and are subject to civil and criminal penalties under the Clean Diamond Trade Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019",
      "us-ofac-sdgt-global-terrorism-sanctions"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ofac-31-cfr-597-foreign-terrorist-organizations-sanctions-regulations",
    "title": "31 CFR Part 597 (Foreign Terrorist Organizations Sanctions Regulations) - OFAC Blocking, Material Support and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 597, the Foreign Terrorist Organizations Sanctions Regulations, implements the blocking provisions tied to the designation of foreign terrorist organizations under section 219 of the Immigration and Nationality Act (8 U.S.C. 1189) and the material-support prohibition of 18 U.S.C. 2339B, administered by the Office of Foreign Assets Control. Upon notification to Congress of the Secretary of State's intent to designate an organization as a foreign terrorist organization, and from and after designation, a U.S. financial institution that receives notice from the Secretary of the Treasury, or that becomes aware that it holds or controls funds or assets in which a designated foreign terrorist organization or its agent has an interest, must block all such financial transactions and assets and retain control of them until a further directive, an Act of Congress, or an order of a court. The blocking extends to agents of a foreign terrorist organization, including persons owned or controlled by or acting for or on behalf of the organization. U.S. persons must not provide material support or resources to a designated foreign terrorist organization, must not engage in evasive or offshore transactions involving blocked assets, must obtain an OFAC license for otherwise-prohibited dealings, must report and keep records as required, and are subject to civil and criminal penalties for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-598-foreign-narcotics-kingpin-sanctions-regulations",
    "title": "31 CFR Part 598 (Foreign Narcotics Kingpin Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 598, the Foreign Narcotics Kingpin Sanctions Regulations, implements the Foreign Narcotics Kingpin Designation Act, administered by the Office of Foreign Assets Control. All property and interests in property that are in the United States, that come within the United States, or that are or come within the possession or control of a U.S. person, of a specially designated narcotics trafficker are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in. The term specially designated narcotics trafficker includes significant foreign narcotics traffickers identified by the President and foreign persons designated by the Secretary of the Treasury for materially assisting, being owned or controlled by, or acting for or on behalf of such a person. No contribution or provision of funds, goods or services, including charitable contributions, may be made by, to or for the benefit of, or received from, a specially designated narcotics trafficker except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, in the aggregate, by one or more specially designated narcotics traffickers is itself blocked. Transactions that would otherwise be prohibited require an OFAC license, payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution, and persons must report and keep records as required and are subject to civil and criminal penalties under the Foreign Narcotics Kingpin Designation Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ofac-31-cfr-599-illicit-drug-trade-sanctions-regulations",
    "title": "31 CFR Part 599 (Illicit Drug Trade Sanctions Regulations) - OFAC Blocking, Licensing and Reporting",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "31 CFR Part 599, the Illicit Drug Trade Sanctions Regulations, implements the U.S. sanctions targeting the international illicit drug trade administered by the Office of Foreign Assets Control under Executive Order 14059 (86 FR 71549). All property and interests in property of persons designated under the program that are in the United States or in the possession or control of a U.S. person are blocked and may not be transferred, paid, exported, withdrawn or otherwise dealt in, and U.S. persons are prohibited from engaging in transactions or dealings in blocked property or by, to or for the benefit of a blocked person except as authorized. Consistent with OFAC's 50 Percent Rule, an entity owned 50 percent or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked. Transactions that would otherwise be prohibited require an OFAC general or specific license, and payments otherwise due to a blocked person must be placed in a blocked account in a U.S. financial institution. U.S. persons must report blocked property and rejected transactions to OFAC within 10 business days and file the annual report of blocked property, must maintain full records for at least five years, and are subject to civil and criminal penalties under the International Emergency Economic Powers Act for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ofac-sdgt-global-terrorism-sanctions",
      "us-ofac-economic-sanctions-compliance-31-cfr-500",
      "us-ofac-sanctions-compliance-programme-2019"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-ofac-economic-sanctions-compliance-31-cfr-500",
    "title": "US OFAC Economic Sanctions Compliance - SDN List, 50% Rule & Civil Penalties",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The US Office of Foreign Assets Control (OFAC) administers economic sanctions programs under 31 CFR Parts 500-599. All US persons (including foreign branches of US banks and US-owned/controlled foreign entities) must block transactions with SDN-listed parties, comply with the 50% ownership rule (entities 50%+ owned by SDNs are treated as SDNs even if not listed), and reject or block transactions involving sanctioned countries or programs. Civil penalties reach the greater of $368,136 per violation (2024, IEEPA/TWEA cap) or twice the transaction value. OFAC's risk-based compliance framework requires a five-element compliance program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bank-secrecy-act-suspicious",
      "fincen-cdd-beneficial-ownership-rule-2016"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ofac-glomag-magnitsky-sanctions",
    "title": "US OFAC Global Magnitsky Sanctions - 31 CFR Part 583 Blocking and Reporting Obligations Under Executive Order 13818 and the Global Magnitsky Human Rights Accountability Act",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "The Global Magnitsky Human Rights Accountability Act (Public Law 114-328, subtitle F of title XII of the National Defense Authorization Act for Fiscal Year 2017, 22 U.S.C. 10101 et seq.) authorizes sanctions against foreign persons responsible for serious human rights abuse and significant corruption anywhere in the world. Executive Order 13818 of December 20, 2017 (Blocking the Property of Persons Involved in Serious Human Rights Abuse or Corruption) declared a national emergency under the International Emergency Economic Powers Act and expanded the statutory authority by removing the requirement that the targeted activity be perpetrated against a person exercising or seeking to expose government corruption or seeking to obtain, exercise, defend, or promote internationally recognized human rights. Implementing regulations at 31 CFR Part 583 prohibit U.S. persons from any transaction involving blocked property of designated persons. Persons designated under the program appear on the SDN List with the GLOMAG program tag. The OFAC 50 Percent Rule extends blocking to entities owned 50 percent or more in aggregate by one or more blocked persons. The program currently contains approximately 740 designations across more than 60 countries including current and former government officials, business executives, and entities involved in major corruption and human rights abuse cases. Reporting cross-references 31 CFR Part 501, including the annual blocked property report (Form TD F 90-22.50) due September 30 and rejected transaction reports within 10 business days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-31-cfr-1010-fincen-aml-ctr",
      "us-fincen-beneficial-ownership-boi-rule-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ofac-ifsr-iran-financial-sanctions",
    "title": "US OFAC Iranian Financial Sanctions Regulations (IFSR) - 31 CFR Part 561 Correspondent and Payable-Through Account Restrictions Under CISADA and NDAA",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "The Iranian Financial Sanctions Regulations (IFSR) at 31 CFR Part 561 implement secondary sanctions against foreign financial institutions that knowingly facilitate certain activities involving Iran. The two principal statutory authorities are the Comprehensive Iran Sanctions, Accountability, and Divestment Act of 2010 (CISADA, Public Law 111-195) and section 1245 of the National Defense Authorization Act for Fiscal Year 2012 (NDAA, Public Law 112-81). Section 561.201 provides that upon a finding by the Secretary of the Treasury that a foreign financial institution knowingly engages in one or more sanctionable activities, the Secretary may prohibit or impose strict conditions on the opening or maintaining in the United States of a correspondent account or payable-through account by that foreign financial institution. Section 561.203 implements the NDAA-based sanctions covering significant financial transactions with the Central Bank of Iran (Bank Markazi) or designated Iranian financial institutions. The U.S. person definition (§561.328) covers U.S. citizens, lawful permanent residents, entities organized under U.S. law including foreign branches, and any person in the United States. The U.S. financial institution definition (§561.327) covers depository institutions, broker-dealers, futures commission merchants, mutual funds, and money services businesses. Persons designated under IFSR appear on the SDN List with the IFSR program tag. The program currently contains approximately 1,500 designations across 42 countries including banks, defense and aerospace entities, and supporting persons. The Iranian Transactions and Sanctions Regulations at 31 CFR Part 560 (the U.S. primary embargo) operate alongside IFSR but cover different prohibitions; both must be complied with concurrently.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-31-cfr-1010-fincen-aml-ctr",
      "wolfsberg-group-aml-principles-correspondent-banking"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ofac-npwmd-wmd-proliferators-sanctions",
    "title": "US OFAC Weapons of Mass Destruction Proliferators Sanctions (NPWMD) - 31 CFR Part 544 Blocking and Reporting Obligations Under Executive Order 13382",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Executive Order 13382 of June 28, 2005 (Blocking Property of Weapons of Mass Destruction Proliferators and Their Supporters) declared a national emergency under the International Emergency Economic Powers Act (IEEPA, 50 U.S.C. 1701-1708), the National Emergencies Act, and section 5 of the United Nations Participation Act of 1945 to address the threat to U.S. national security, foreign policy, and the economy posed by the proliferation of nuclear, chemical, and biological weapons (weapons of mass destruction) and their means of delivery. Implementing regulations at 31 CFR Part 544 prohibit U.S. persons from any transaction involving blocked property of designated proliferators. Section 544.201 incorporates by reference all prohibitions of E.O. 13382. The designation reach extends to foreign persons determined to have engaged or attempted to engage in proliferation activities, to persons owned or controlled by or acting for or on behalf of such persons, and to persons providing financial, material, or technological support for, or financial or other services to or in support of, such proliferation. Persons designated under the program appear on the SDN List with the NPWMD program tag. The OFAC 50 Percent Rule extends blocking to entities owned 50 percent or more in aggregate by one or more blocked persons. The program contains approximately 1,150 designations across more than 30 countries, with significant concentrations in the DPRK and Iran missile, nuclear, and dual-use technology supply chains. Reporting cross-references 31 CFR Part 501, including the annual blocked property report (Form TD F 90-22.50) due September 30 and rejected transaction reports within 10 business days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-31-cfr-1010-fincen-aml-ctr",
      "unscr-1540-2004-wmd-non-proliferation-non-state-actors"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ofac-russia-eo14024-sanctions",
    "title": "US OFAC Russian Harmful Foreign Activities Sanctions - 31 CFR Part 587 Blocking, Designation Screening and Reporting Obligations Under Executive Order 14024",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Executive Order 14024 of April 15, 2021 (Blocking Property With Respect To Specified Harmful Foreign Activities of the Government of the Russian Federation) declared a national emergency under the International Emergency Economic Powers Act (IEEPA, 50 U.S.C. 1701-1708) and the National Emergencies Act (50 U.S.C. 1601 et seq.). Implementing regulations at 31 CFR Part 587 prohibit U.S. persons from any transaction involving blocked property of designated persons. Section 587.201 incorporates by reference all prohibitions of E.O. 14024 and any further Executive Orders issued pursuant to the national emergency. Persons designated pursuant to E.O. 14024 are added to OFAC's Specially Designated Nationals and Blocked Persons List (SDN List) with the identifier prefix RUSSIA-EO14024. The OFAC 50 Percent Rule (§587.406) extends blocking to any entity owned 50 percent or greater, individually or in the aggregate, by one or more blocked persons. Under §587.405, setoffs against blocked accounts are themselves prohibited transfers. The U.S. person definition (§587.314) covers U.S. citizens, lawful permanent residents, entities organized under U.S. law including their foreign branches, and any person in the United States. The program contains the largest single OFAC SDN footprint, with thousands of designations of Russian government officials, military entities, financial institutions, defense contractors, and supporting persons across more than 80 jurisdictions. Reporting and recordkeeping cross-reference 31 CFR Part 501, including the annual blocked property report (TD F 90-22.50) due September 30 and rejected transaction reports within 10 business days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-31-cfr-1010-fincen-aml-ctr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ofac-sanctions-compliance-programme-2019",
    "title": "A Framework for OFAC Compliance Commitments",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This framework from the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) outlines the five essential components of a risk-based sanctions compliance program (SCP): management commitment, risk assessment, internal controls, testing and auditing, and training. It applies to all organizations subject to U.S. jurisdiction and is used by OFAC to evaluate compliance in enforcement actions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bank-secrecy-act-suspicious",
      "interagency-guidance-third-party-risk-management",
      "fatf-travel-rule-v2"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ofac-sanctions-programmes-executive-orders",
    "title": "US OFAC Economic Sanctions Programmes and Specially Designated Nationals (SDN) List Screening",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "U.S. persons and entities are strictly prohibited from engaging in virtually all transactions or dealings with individuals, entities, and governments designated on the Office of Foreign Assets Control's (OFAC) Specially Designated Nationals and Blocked Persons (SDN) List and other sanctions lists, as mandated by various Executive Orders (e.g., E.O. 13224) and statutes, unless authorized by a general or specific OFAC license.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bank-secrecy-act-suspicious",
      "fatf-travel-rule-v2",
      "fatf-pf-risk-assessment-mitigation"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ofac-sdgt-global-terrorism-sanctions",
    "title": "US OFAC Specially Designated Global Terrorist (SDGT) Sanctions - 31 CFR Part 594 Blocking and Reporting Obligations Under Executive Order 13224",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "Executive Order 13224 of September 23, 2001 (Blocking Property and Prohibiting Transactions With Persons Who Commit, Threaten To Commit, or Support Terrorism) declared a national emergency under the International Emergency Economic Powers Act (IEEPA, 50 U.S.C. 1701-1708), the National Emergencies Act, and section 5 of the United Nations Participation Act of 1945. The implementing Global Terrorism Sanctions Regulations at 31 CFR Part 594 prohibit U.S. persons from any transaction involving blocked property of designated Specially Designated Global Terrorists (SDGTs). Section 594.201 incorporates by reference all prohibitions of E.O. 13224. Designation criteria reach persons who commit, threaten to commit, or support terrorism, persons owned or controlled by or acting for or on behalf of such persons, and persons who assist in, sponsor, or provide financial, material, or technological support for, or financial or other services to or in support of, such acts. The OFAC 50 Percent Rule (§594.406) extends blocking to any entity owned 50 percent or greater, individually or in the aggregate, by one or more blocked persons. Under §594.405 setoffs against blocked accounts are themselves prohibited transfers. The U.S. person definition at §594.315 covers U.S. citizens, lawful permanent residents, entities organized under U.S. law including their foreign branches, and any person in the United States. The SDGT program contains approximately 3,000 designations across more than 120 countries and is the primary counter-terrorism sanctions authority for the United States. Reporting cross-references 31 CFR Part 501, including the annual blocked property report (Form TD F 90-22.50) due September 30 and rejected transaction reports within 10 business days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-31-cfr-1010-fincen-aml-ctr"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ofac-sdn-list-50-percent-rule-blocking-property",
    "title": "US OFAC Specially Designated Nationals (SDN) List, the 50 Percent Rule and Blocking of Property under IEEPA and 31 CFR Chap. V (Subchapter B)",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "The Office of Foreign Assets Control (OFAC) of the US Department of the Treasury administers and enforces US economic and trade sanctions based on US foreign policy and national security goals. The Specially Designated Nationals and Blocked Persons List (SDN List) is the central operational list naming individuals, entities, vessels and aircraft whose property and interests in property are blocked under the relevant sanctions authorities (most often the International Emergency Economic Powers Act, IEEPA, codified at 50 USC 1701-1708; the Trading with the Enemy Act, TWEA, at 50 USC 4301-4341 for certain legacy programs including Cuba; the Foreign Narcotics Kingpin Designation Act at 21 USC 1901-1908; the Caesar Syria Civilian Protection Act; and country- or program-specific statutes). All US persons (US citizens and permanent residents wherever located, persons within the United States, and entities organised under US law including their foreign branches) are prohibited from dealing with SDNs and from facilitating transactions by non-US persons that the US person could not engage in directly. OFAC's Revised Guidance on Entities Owned by Persons Whose Property and Interests in Property Are Blocked of 13 August 2014 (the 50 Percent Rule) extends blocking automatically to any entity owned in the aggregate, directly or indirectly, fifty percent or more by one or more blocked persons. Ownership is aggregated across multiple blocked persons, so two SDNs each owning twenty-five percent of an entity automatically block that entity. The 50 Percent Rule applies even if the blocked owner does not have control of the entity, and applies regardless of whether the entity is named on the SDN List. Sanctions are implemented through regulations in 31 CFR Chap. V (Subchapter B) (the OFAC Regulations), supported by general licences (authorising specified categories of dealings without case-by-case approval) and specific licences (case-by-case authorisations). Civil penalties for violations are set by IEEPA Sec. 206 (50 USC 1705), the Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015 and the OFAC Inflation Adjustment final rule (most recent annual adjustment of 11 January 2024 setting the maximum civil penalty per violation at USD 377,700 or twice the value of the transaction giving rise to the violation, whichever is greater). Criminal penalties under 50 USC 1705 include fines up to USD 1,000,000 and imprisonment up to twenty years for wilful violations. Voluntary self-disclosure to OFAC is a substantial mitigating factor under the OFAC Economic Sanctions Enforcement Guidelines at 31 CFR 501 Appx A.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "fifty_percent_rule_anchor",
        "statutory_authority_anchor",
        "regulatory_framework_anchor",
        "civil_penalty_anchor",
        "criminal_penalty_anchor",
        "industry_mapping",
        "general_and_specific_licence_anchor",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ieepa-1977",
      "us-31-cfr-part-501-ofac-reporting-procedures",
      "us-ofac-31-cfr-510-north-korea-sanctions-regulations"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-oh-ocpa-2023",
    "title": "Ohio Consumer Privacy Act 2023",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-07-01",
    "bluf": "Ohio's Consumer Privacy Act (HB 376), signed December 28, 2023 and effective October 23, 2024, grants Ohio residents rights to access, correct, delete, and opt out of targeted advertising, sale of personal data, and profiling, applies to businesses meeting specified consumer threshold and revenue criteria, requires data protection assessments for high-risk processing activities, imposes a 30-day cure period with no sunset date, and is enforced exclusively by the Ohio Attorney General with penalties up to USD 25,000 per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-oh-ocpa-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ohio-sports-gaming-act-2021",
    "title": "Ohio Sports Gaming Act 2021 - HB 29 Sports Wagering via ORC Chapter 3775",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Ohio H.B. 29 (2021), codified at Ohio Revised Code (ORC) Chapter 3775, authorises sports wagering regulated by the Ohio Casino Control Commission (OCCC). A 10% tax applies to gross revenue from sports gaming. The minimum age is 21. Ohio sports betting launched January 1, 2023. Type A licences cover online/mobile operators; Type B licences cover retail sportsbooks at gaming facilities; Type C licences cover high-volume sports betting kiosks. Geolocation and self-exclusion are mandatory. Civil penalties may reach $100,000 per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_paspa_repeal",
        "us_uigea_2006",
        "ohio_casino_control_act",
        "fatf_gambling",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
      "us-uigea-2006-unlawful-internet-gambling",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-oil-pollution-act-1990",
    "title": "US Oil Pollution Act of 1990 (33 USC ch 40): Responsible-Party Liability, Limits and Financial Responsibility",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Oil Pollution Act of 1990 (OPA), codified at 33 U.S.C. Chapter 40 (sections 2701-2762), establishes a comprehensive federal regime of liability and compensation for discharges of oil into navigable waters, adjoining shorelines and the exclusive economic zone, administered primarily by the US Coast Guard (through the National Pollution Funds Center) and the US Environmental Protection Agency. Section 2701 defines the regulated terms, including 'oil', 'vessel', 'facility', 'discharge', 'responsible party' and 'damages'. Section 2702 sets the elements of liability: each responsible party for a vessel or a facility from which oil is discharged, or which poses a substantial threat of a discharge, into or upon navigable waters, adjoining shorelines or the exclusive economic zone is liable for the removal costs and damages that result; the recoverable damages include damages for injury to, destruction of, loss of, or loss of use of natural resources, real or personal property, subsistence use, lost government revenues, lost profits and earning capacity, and the cost of providing increased public services. Section 2703 provides the limited complete defenses (act of God, act of war and certain third-party acts). Section 2704 sets the per-incident limits on liability, which vary by vessel and facility type; under section 2704(c) those limits do not apply where the incident was proximately caused by the gross negligence or willful misconduct of, or the violation of an applicable federal safety, construction or operating regulation by, the responsible party, or where the responsible party fails to report the incident or to cooperate with removal. Section 2706 governs natural resource damage assessment by trustees, section 2712 governs uses of the Oil Spill Liability Trust Fund, section 2713 sets the claims-presentation procedure, and section 2716 requires responsible parties to establish and maintain evidence of financial responsibility sufficient to meet the applicable liability limits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-oil-pollution-act-1990-opa-90",
    "title": "Oil Pollution Act of 1990 (OPA)",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Oil Pollution Act (OPA) of 1990 requires oil storage facilities and vessels to submit response plans for large discharges and mandates the development of Area Contingency Plans for regional oil spill preparedness. It strengthens EPA's authority to prevent and respond to oil spills, with enforcement backed by a trust fund financed by a tax on oil. Key requirement: submission of response plans under 33 U.S.C. §2701 et seq. (1990).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-marpol-pollution"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-oil-pollution-act-1990-opa90",
    "title": "US Oil Pollution Act 1990 (OPA 90) - Spill Prevention, Facility Response Plans, Financial Responsibility and Natural Resource Damages",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Oil Pollution Act of 1990 (OPA 90) establishes a comprehensive federal framework for oil spill prevention, preparedness, and response, imposing strict liability for removal costs and damages on parties responsible for oil discharges into U.S. waters. As mandated by 33 U.S.C. § 1321(j), owners/operators of certain facilities and vessels must develop and submit detailed Facility/Vessel Response Plans (FRPs/VRPs) and demonstrate sufficient financial responsibility to cover potential liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-older-workers-benefit-protection-act-29-usc-626",
    "title": "Older Workers Benefit Protection Act 1990 - 29 USC 626(f) ADEA Waiver Requirements",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 626(f) of title 29 of the United States Code, added by the Older Workers Benefit Protection Act (Public Law 101-433, enacted 16 October 1990), specifies the minimum standards an employer must satisfy for a waiver of rights or claims under the Age Discrimination in Employment Act of 1967 to be considered knowing and voluntary. The statute sets out seven mandatory conditions: (1) the waiver must be in writing and calculated to be understood by the average individual eligible to participate; (2) the waiver must specifically refer to rights or claims arising under the ADEA; (3) the waiver cannot extend to rights or claims that may arise after the date the waiver is executed; (4) the employee must receive consideration in addition to anything to which the individual already is entitled; (5) the employee must be advised in writing to consult with an attorney prior to executing the agreement; (6) the employee must be given a period of at least 21 days within which to consider the agreement (or 45 days where the waiver is requested in connection with an exit incentive or other employment termination program offered to a group or class of employees); and (7) the agreement must provide that for a period of at least seven days following execution the employee may revoke the agreement and the waiver does not become effective or enforceable until the revocation period has expired. For group programs, employers must also disclose in writing the class, unit, or group covered, eligibility factors, applicable time limits, and the job titles and ages of all individuals eligible or selected for the program, and of those not eligible or selected. AI agents involved in workforce reduction recommendations must integrate the OWBPA timing and disclosure rules and preserve evidence supporting each waiver as a defence to subsequent ADEA claims.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-adea-1967-29-usc-ch14",
      "us-warn-act-1988-29-usc-ch23"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-omb-ai-vulnerability-detection-grant-funding-2026",
    "title": "US OMB Advanced AI Vulnerability Detection Grant Funding Availability (Sec. 2(e) 30-Day Directive, EO Promoting Advanced AI Innovation and Security, 2026)",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-06-14",
    "bluf": "Sec. 2(e) of the Executive Order Promoting Advanced Artificial Intelligence Innovation and Security signed June 2, 2026 directs the Director of the Office of Management and Budget, in coordination with the National Cyber Director and the Director of CISA, within 30 days of the Order (verbatim deadline: within 30 days of the date of the order), to determine whether any Federal grant programs have available and relevant funding that can be directed toward applicants developing advanced AI vulnerability detection. The directive is administrative not appropriative: the OMB Director identifies funding opportunities across existing federal grant programmes rather than creating new appropriations. Candidate existing programmes that the OMB Director is expected to inventory include the National Science Foundation Secure and Trustworthy Cyberspace (SaTC) programme, DARPA AI Cyber Challenge (AIxCC), DHS Continuous Diagnostics and Mitigation (CDM) programme, NIST National Initiative for Cybersecurity Education (NICE) grants, NSA Centers of Academic Excellence in Cyber Operations (CAE-CO) grants, and Department of Energy AI for Science and AI for Critical Infrastructure programmes; the operative scoping document will be the OMB output published on or before within 30 days of the date of the order. The funding availability determination feeds into the broader Sec. 2 AI Cybersecurity Clearinghouse coordination by Treasury, NSA and CISA - grant funding is the principal lever the EO uses to incentivise private and academic participation in AI-driven vulnerability discovery and remediation work. Federal grant award rules continue to apply: 2 CFR 200 (Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards), 2 CFR 25 (System for Award Management registration including UEI), 2 CFR 170 (transparency reporting via USAspending.gov), 2 CFR 175 (trafficking in persons), and 2 CFR 180 (suspension and debarment). Foreign applicants and foreign sub-awardees face additional restrictions under National Security Presidential Memorandum 33 (NSPM-33) and disclosure requirements under the CHIPS and Science Act Section 10632. The OMB directive does not waive existing eligibility rules; applicants must continue to meet programme-specific eligibility and the cross-cutting federal grant compliance regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-promoting-advanced-ai-innovation-security-2026",
      "us-ai-cybersecurity-clearinghouse-2026",
      "us-omb-circular-a-130-federal-information-management",
      "us-omb-m-24-10-federal-ai-governance-2024",
      "nist-ai-600-1-generative-ai-profile-2024"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-omb-circular-a-130-federal-information-management",
    "title": "US OMB Circular A-130 - Managing Information as a Strategic Resource: Federal Automated System Governance and Workflow Requirements",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "OMB Circular A-130 (2016 revision) requires federal agencies to manage information as a strategic resource throughout its lifecycle, covering automated system governance, privacy, security, and records management. Agencies must establish information governance programs covering IT planning and capital investment, security and privacy integrated into system development, privacy risk assessments for systems processing personally identifiable information, senior agency officials for both privacy and information security, and records management requirements for automated workflows. Appendix I covers security and privacy controls; Appendix II covers PII management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-govern-function"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-omb-m-23-02-migrating-to-post-quantum-cryptography-2022",
    "title": "US OMB Memorandum M-23-02 — Migrating to Post-Quantum Cryptography (November 18, 2022)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "OMB Memorandum M-23-02 'Migrating to Post-Quantum Cryptography' was issued on November 18, 2022 by Shalanda D. Young, Director of the Office of Management and Budget, to direct federal civilian Executive Branch agencies to comply with National Security Memorandum 10 (NSM-10). The memorandum operationalises NSM-10's 2035 government-wide migration target by establishing the federal civilian cryptographic inventory regime, the funding assessment process, and the testing and working-group infrastructure for the post-quantum cryptography (PQC) transition. The memorandum defines 'cryptographic system' as 'an active software or hardware implementation of one or more cryptographic algorithms that provide one or more of the following services: (1) creation and exchange of encryption keys; (2) encrypted connections; or (3) creation and validation of digital signatures.' The inventory scope encompasses each information system or asset that is (a) a high impact information system (a system in which at least one security objective is assigned a FIPS 199 potential impact value of 'high'), (b) an agency HVA (High Value Asset), or (c) any other system the agency determines is particularly vulnerable to CRQC-based attacks - particularly systems containing data expected to remain mission-sensitive in 2035 (harvest-now-decrypt-later) and logical access control systems based in asymmetric encryption. National Security Systems are explicitly excluded from M-23-02 scope and follow the NSA CNSA 2.0 path. By May 4, 2023 and annually thereafter until 2035, agencies submit prioritised inventories to the Office of the National Cyber Director (ONCD) and CISA with nine specified data points per system including FISMA system identifier, FIPS 199 categorisation, HVA identifier, cryptographic algorithm used with key length, software package source (COTS/GOTS/Other) with vendor name, operating system, hosting type, data lifecycle, and notes. Within 30 days agencies designate a cryptographic inventory and migration lead; within 30 days OMB and ONCD establish the cryptographic migration working group chaired by the Federal Chief Information Security Officer; within 60 days NIST establishes the PQC testing exchange mechanism; within 90 days ONCD releases inventory transmission and funding assessment instructions; within 1 year CISA releases the automated tooling strategy. Funding assessments are submitted 30 days after each annual inventory and inform the NSM-10 Section 3(c)(iv) Government-wide funding picture. Appendix B enumerates the CRQC-vulnerable algorithms requiring migration: Elliptic Curve Diffie-Hellman (ECDH), Menezes-Qu-Vanstone (MQV) Key Exchange, Elliptic Curve Digital Signature Algorithm (ECDSA), Diffie-Hellman (DH) Key Exchange, RSA Signature Algorithm, and the Digital Signature Algorithm (DSA). Implementation guidance is hosted on OMB MAX at community.max.gov/x/tRBwig and inquiries route to NSM10@omb.eop.gov.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nsm-10-quantum-computing-vulnerable-cryptographic-systems-2022",
      "fips-203-ml-kem-standard",
      "fips-204-ml-dsa-standard",
      "fips-205-slh-dsa-quantum",
      "us-eo-14028-cybersecurity-2021-sbom-mfa-zerotrust"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-omb-m-24-10-federal-ai-governance-2024",
    "title": "US OMB Memorandum M-24-10 - Advancing Governance, Innovation, and Risk Management for Agency Use of AI, Executed 28 March 2024",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "US Federal agencies using artificial intelligence must, under OMB Memorandum M-24-10 executed on 28 March 2024, complete an AI impact assessment before using any safety- or rights-impacting AI that states the intended purpose and expected benefit, identifies potential risks and mitigation measures beyond the memo's minimum practices, and evaluates the quality of data used in the AI design and development, conduct ongoing monitoring including human reviews and regular risk evaluations once safety- or rights-impacting AI is in use, submit and publicly release an agency plan for OMB consistency or a written determination of non-use by 23 September 2024, and by 1 December 2024 publish the AI use case inventory and ensure that contracts associated with rights- or safety-impacting AI systems are brought into compliance or terminated.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14179-ai-2025"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-omb-m-24-10-federal-ai-governance-risk-management",
    "title": "OMB Memorandum M-24-10 (2024) - Advancing Governance, Innovation and Risk Management for Agency Use of Artificial Intelligence",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "OMB Memorandum M-24-10 (28 March 2024) implements Section 10.1(b) of Executive Order 14110 and establishes binding governance, innovation, and risk management practices for all civilian executive branch agency use of artificial intelligence. The memorandum requires each Chief Financial Officer Act agency to designate a Chief AI Officer (CAIO), establish an internal AI governance body, and publish an annual public AI use case inventory under 40 USC 11315(f). The memorandum defines and imposes specific minimum practices on (1) safety-impacting AI use cases and (2) rights-impacting AI use cases, including pre-deployment testing, impact assessment, real-world monitoring, mitigation of algorithmic discrimination, public consultation, and opportunity for affected individuals to opt-out or appeal to a human reviewer where applicable. The minimum practices took effect 1 December 2024. M-24-10 also strengthens AI innovation through a federal AI talent surge, AI training, infrastructure investment, and the federal generative AI policy. Although Section 10.1(b) of EO 14110 was rescinded by EO 14179 (January 2025), the binding M-24-10 requirements remain in force pending superseding OMB guidance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14110-ai-2023",
      "us-eo-14179-ai-2025"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-omb-m-24-18-federal-ai-acquisition-guidance",
    "title": "OMB Memorandum M-24-18 (2024) - Advancing the Responsible Acquisition of Artificial Intelligence in Government",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "OMB Memorandum M-24-18 (3 October 2024) implements Section 10.1(d)(ii) of Executive Order 14110 and establishes binding federal AI acquisition guidance for civilian executive branch agencies. The memorandum requires agencies to plan for responsible AI acquisition by aligning with the M-24-10 governance framework, conducting market research, integrating AI use case inventories into the acquisition planning process, and applying acquisition-stage controls for safety-impacting and rights-impacting AI. M-24-18 mandates specific contract terms covering AI risk management, data rights, performance management, transparency, intellectual property, and vendor lock-in mitigation. Agencies must develop AI Acquisition Cross-Functional Teams (AACFTs) that bring together CAIO, contracting officer, program manager, privacy officer, civil rights officer, security officer, and General Counsel. Vendors of safety-impacting or rights-impacting AI must satisfy specific performance, reporting, and incident-disclosure obligations. The memorandum becomes binding 12 months after issuance for new contracts (3 October 2025) and applies to all AI procurements, including AI as a service and AI-enabled systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-omb-m-24-10-federal-ai-governance-risk-management",
      "us-eo-14110-ai-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-omb-m-25-21-accelerating-federal-ai-2025",
    "title": "OMB Memorandum M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "OMB Memorandum M-25-21 (April 3, 2025) implements Executive Order 14179, Removing Barriers to American Leadership in Artificial Intelligence (January 23, 2025), and rescinds and replaces OMB Memorandum M-24-10. It directs Executive Branch agencies to provide improved services to the public while maintaining strong safeguards for civil rights, civil liberties, and privacy. Agencies must identify a Chief AI Officer, and OMB convenes and chairs an interagency council to coordinate AI development and use. Each CFO Act agency must develop an AI Strategy within 180 days; agencies must submit and publicly post compliance plans within 180 days and every two years thereafter until 2036, consistent with Section 104(c) and (d) of the AI in Government Act of 2020; update internal policies within 270 days; and maintain an annual AI use case inventory. For high-impact AI, agencies must implement the minimum risk management practices in the Appendix and document implementation within 365 days; when high-impact AI is not performing at an appropriate level, agencies must have a plan to discontinue its use, and if proper risk mitigation is not possible, agencies must cease the use of the AI.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14179-removing-barriers-ai-2025"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-omb-m-25-22-ai-acquisition-2025",
    "title": "OMB Memorandum M-25-22: Driving Efficient Acquisition of Artificial Intelligence in Government",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "OMB Memorandum M-25-22 (April 3, 2025) provides guidance to Executive Branch agencies to improve their ability to acquire AI responsibly, consistent with the Advancing American AI Act, Executive Order 14179, Removing Barriers to American Leadership in Artificial Intelligence, and OMB Memorandum M-25-21. It rescinds and replaces OMB Memorandum M-24-18, Advancing the Responsible Acquisition of Artificial Intelligence in Government, and is anchored on grounding themes that include ensuring the Government and the public benefit from a competitive American AI marketplace. Agency acquisition processes must address scoping licensing and other IP rights appropriately, based on the intended use of AI, to avoid vendor lock-in; ensuring components necessary to operate and monitor the AI system or service remain available to the acquiring agency for as long as necessary; and providing clear guidance on handling, access, and use of agency data. Within 200 days, GSA, in coordination with OMB, develops a web-based repository available to Executive Branch agencies to share information, knowledge, and resources about AI acquisition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14179-removing-barriers-ai-2025",
      "us-omb-m-25-21-accelerating-federal-ai-2025"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-omb-memorandum-ai-2024",
    "title": "US OMB Memorandum M-24-10 - Advancing Governance, Innovation, and Risk Management for Agency Use of AI",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "US Office of Management and Budget Memorandum M-24-10 (March 28, 2024) establishes minimum governance requirements for federal agency use of artificial intelligence pursuant to Executive Order 14110; the memorandum requires every federal agency to: (1) designate a Chief AI Officer (CAIO) within 60 days; (2) establish an AI Governance Board within 60 days; (3) complete an inventory of AI use cases with a specific focus on rights-impacting and safety-impacting AI; (4) apply minimum risk practices to rights-impacting AI (affecting individual rights, opportunities, or access to government services) and safety-impacting AI (affecting health, safety, critical infrastructure) - these practices include: conducting pre-deployment impact assessments, establishing ongoing monitoring, documenting AI limitations, providing human considerations where practicable, and ensuring fallback procedures; (5) complete the inventory and minimum practices by December 1, 2024; M-24-10 supersedes the 2020 OMB Memorandum M-20-26 and the 2022 Memorandum M-22-06; the minimum practices in M-24-10 Sections 5(b)(i)-(v) apply specifically to rights-impacting AI uses listed in Appendix I (criminal justice, employment, credit, housing, education, healthcare) and safety-impacting AI uses; agencies are required to pause or discontinue rights-impacting or safety-impacting AI use that does not meet the minimum practices unless the agency head grants a waiver; M-24-10 reflects the US government's adoption of a risk-tiered framework aligned with the NIST AI Risk Management Framework and is the federal implementation vehicle for Executive Order 14110 Section 10(b).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-omb-memorandum-ai-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14110-ai-2023",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-omnibus-budget-reconciliation-act-1981-pl-97-35",
    "title": "US Omnibus Budget Reconciliation Act of 1981 (Public Law 97-35) - Federal Spending Reduction and Block Grant Consolidation",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Omnibus Budget Reconciliation Act of 1981 enacted the largest single-year reduction in federal domestic spending in modern US history by consolidating 77 categorical grant programs into nine block grants administered by the states, reducing or limiting program eligibility for Aid to Families with Dependent Children and food stamps, restructuring federal student loan interest subsidies, tightening unemployment compensation extended benefits, modifying Medicare and Medicaid reimbursement rules, and establishing reconciliation as the principal congressional tool for binding spending and revenue changes through the budget process.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-higher-education-act-1965"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-omnibus-trade-competitiveness-act-1988-pl-100-418",
    "title": "Omnibus Trade and Competitiveness Act 1988 - Public Law 100-418",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Omnibus Trade and Competitiveness Act of 1988 (OTCA, Public Law 100-418, enacted 23 August 1988) restructured US trade policy across approximately 12 titles and remains a foundational US trade statute. Title I (Trade, Customs, and Tariff Laws) substantially amended Section 301 of the Trade Act of 1974 (creating Super 301 and Special 301 priority designation procedures for unfair trade practices and intellectual property protection) and codified the Section 232 national security investigation framework with the modern 270-day Commerce investigation and 90-day Presidential decision timeline. Title V (Export Enhancement) established the Export Enhancement Program. Title VII (Buy American Act Amendments) modernised federal Buy American provisions. Title VIII (Small Business International Trade) expanded SBA international trade programs. Title IX (Telecommunications) established the Section 1377 framework for US trade representative annual review of foreign telecommunications barriers. Title X (Tropical Forest Conservation) established environmental trade priorities. Subsequent amendments extended OTCA's framework, but the core Super 301, Special 301, and Section 232 procedural enhancements remain operative. The Act is the principal source of modern US trade enforcement procedures and AI-enabled trade flow analytics must integrate the OTCA's priority designation, retaliation, and enforcement procedures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-trade-act-1974-19-usc-ch12",
      "us-section-301-trade-act-19-usc-2411"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-onc-45-cfr-171-information-blocking",
    "title": "45 CFR Part 171 - ONC Information Blocking and Exceptions",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "45 CFR Part 171 implements the information blocking provisions of the 21st Century Cures Act administered by the Office of the National Coordinator for Health Information Technology. An actor (a health care provider, health IT developer of certified health IT, health information network or health information exchange) must not engage in information blocking, defined as a practice that is likely to interfere with the access, exchange or use of electronic health information except as required by law or covered by an exception. The regulations establish exceptions that, if met, mean a practice will not be treated as information blocking: exceptions for not fulfilling requests (preventing harm, privacy, security, infeasibility, health IT performance and protecting care access) and exceptions for the manner of fulfilling requests (the content and manner, fees and licensing exceptions). An actor must meet all conditions of an applicable exception, and unjustified interference may give rise to penalties or disincentives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_prohibitions",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hipaa-privacy-rule",
      "hipaa-security-rule",
      "hitech-act-2009"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-onc-health-it-certification-2026",
    "title": "US ONC Health IT Certification Program & Cures Act Final Rule (2026 Requirements)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The Office of the National Coordinator for Health Information Technology (ONC) Certification Program requires health IT developers to meet updated criteria for interoperability, information blocking, API access, patient access, and security. The Cures Act Final Rule (with 2026 enforcement) mandates FHIR-based APIs, real-time patient access, and prohibitions on information blocking with significant civil monetary penalties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 4
  },
  {
    "node_id": "us-onc-information-blocking-rule-2020",
    "title": "ONC Information Blocking Final Rule 45 CFR Part 171 (2020) - Definition of Information Blocking, Eight Exceptions and Recognised Health IT Developer Obligations",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation defines information blocking as practices by healthcare providers, health IT developers of certified health IT, and health information exchanges/networks that are likely to interfere with access, exchange, or use of electronic health information (EHI), as specified in 45 CFR 171.103. It establishes exceptions and authorizes disincentives for noncompliant providers under the 21st Century Cures Act, section 4004.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-gdpr-health-data-article-9",
      "dicom-imaging-standard",
      "us-ferpa-family-educational-rights-privacy-1974"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-or-ocpa-2023",
    "title": "US Oregon Consumer Privacy Act 2023",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The Oregon Consumer Privacy Act grants consumers rights to access, correct, delete, and port personal data and to opt out of sale and targeted advertising, requires opt-in consent for sensitive data, mandates data protection assessments for high-risk processing, and authorises the Oregon Attorney General to impose civil penalties of up to USD 7,500 per violation with a mandatory cure period expiring January 1, 2026.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-or-ocpa-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ccpa-cpra-2023-marketing-rights"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-oregon-consumer-privacy-act-2023",
    "title": "Oregon Consumer Privacy Act (SB 619) - Data Protection Assessments, Profiling Restrictions and Non-Discrimination Obligation",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Oregon Consumer Privacy Act (OCPA) requires controllers to conduct and document a Data Protection Assessment (DPA) for any processing that presents a heightened risk of harm to a consumer, including profiling, as specified in Section 8. The Act also mandates non-discrimination against consumers for exercising their rights and provides a right to opt out of certain profiling activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-35-dpia",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-organic-foods-production-act",
    "title": "US Organic Foods Production Act: National Organic Program, Certification, National List and Labeling",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Organic Foods Production Act of 1990 (OFPA), codified at 7 U.S.C. Chapter 94 (sections 6501-6524), establishes national standards for the production, handling and labeling of organically produced agricultural products and creates the National Organic Program (NOP), administered by the USDA Agricultural Marketing Service in consultation with the National Organic Standards Board. Section 6503 directs the Secretary to establish the National Organic Program through which products may be sold or labeled as organically produced. Section 6504 sets the core national standards: to be sold or labeled as organically produced, an agricultural product must have been produced and handled without the use of synthetic chemicals (except as otherwise provided), must not have been produced on land to which prohibited substances were applied during the three years immediately preceding harvest (for crops), and must be produced and handled in compliance with an organic plan agreed to by the producer or handler and the certifying agent. Section 6506 sets general requirements, including organic plan, recordkeeping, and prohibitions on commingling and contact with prohibited substances; sections 6508-6510 set specific requirements for crops, livestock and handling. Section 6513 requires each producer and handler to develop and implement an organic plan. Sections 6514-6515 require certification of operations and accreditation of certifying agents. Section 6517 establishes the National List of allowed synthetic and prohibited natural substances. Section 6519 addresses violations, including a civil penalty for any person who knowingly sells or labels a product as organic when it was not produced and handled in accordance with the Act, and loss of certification. The Act is implemented by the NOP regulations in 7 CFR Part 205.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-orphan-drug-act",
    "title": "US Orphan Drug Act (21 USC ch 9): Incentives for Rare Disease Drugs",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Orphan Drug Act, codified within the Federal Food, Drug, and Cosmetic Act (21 U.S.C. ch. 9, sections 360aa to 360ff), creates incentives to develop drugs for rare diseases or conditions, administered by the Food and Drug Administration. Section 360bb provides for the designation of a drug as an orphan drug where it is intended for a rare disease or condition, generally one affecting fewer than 200,000 persons in the United States or for which there is no reasonable expectation of recovering development costs. Section 360cc provides the central incentive of marketing exclusivity: where the FDA approves an application or licenses an orphan-designated drug, it may not approve another application or license for the same drug for the same disease or condition for a period of seven years from approval, except where the holder cannot assure a sufficient quantity of the drug or consents to approval of another application, or where a subsequent applicant shows that its drug, though otherwise the same, is clinically superior by greater efficacy, greater safety, or a major contribution to patient care. Section 360aa provides for FDA recommendations on investigations, section 360dd for open protocols, and section 360ee for grants and contracts for the development of orphan products. The Act, together with orphan drug tax credits, is the legal foundation for US rare disease drug development incentives.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-orphan-drug-act-1983-rare-diseases",
    "title": "Designating an Orphan Product: Drugs and Biological Products",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the process for sponsors to request orphan drug designation for drugs or biological products intended to prevent, diagnose, or treat rare diseases or conditions, as defined by the Orphan Drug Act. Sponsors must submit a request with supporting data to the FDA, which grants designation independently from approval or licensing, per the Orphan Drug Act and 21 CFR Part 316.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-312-ind-investigational-new-drug",
      "fda-21-cfr-part-314-nda-new-drug-application",
      "fda-21-cfr-part-600-601-biologics-licensing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-orphan-drug-act-1983-section-526-designation",
    "title": "Orphan Drug Act of 1983, Section 526 - Designation of Orphan Drugs",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Orphan Drug Act of 1983, Section 526, requires the FDA to designate a drug as an orphan drug if it is intended for the treatment of a rare disease or condition, defined as one that affects fewer than 200,000 people in the United States, as stated in Section 526(a)(1).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-312-ind-investigational-new-drug"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-osha-1926-construction-standards",
    "title": "29 CFR Part 1926 - Safety and Health Regulations for Construction (Fall Protection, Scaffolding, and Excavation Requirements)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation by the US Occupational Safety and Health Administration (OSHA) establishes mandatory safety and health standards for all construction work in the United States. It specifically requires employers to provide fall protection systems at elevations of 6 feet or more (Subpart M), ensure proper construction and inspection of scaffolding (Subpart L), and implement protective systems for excavations 5 feet or deeper (Subpart P) to prevent worker fatalities and injuries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-osha-29-cfr-1910-1030-bloodborne-pathogens",
    "title": "OSHA General Industry Standard 29 CFR 1910.1030 - Bloodborne pathogens",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "29 CFR 1910.1030 applies to all occupational exposure to blood or other potentially infectious materials and requires employers to protect employees from bloodborne pathogens such as hepatitis B virus (HBV) and human immunodeficiency virus (HIV). Employers must use engineering and work practice controls, provide hepatitis B vaccination and post-exposure evaluation and follow-up, and manage exposure incidents involving needles and other contaminated sharps.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-osha-29-cfr-1910-general-industry",
      "us-occupational-safety-health-act-1970"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-osha-29-cfr-1910-1450-laboratory-hazardous-chemicals",
    "title": "OSHA General Industry Standard 29 CFR 1910.1450 - Occupational exposure to hazardous chemicals in laboratories",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "29 CFR 1910.1450 (the Laboratory Standard) applies to all employers engaged in the laboratory use of hazardous chemicals and, where it applies, supersedes most other OSHA health standards in 29 CFR part 1910 subpart Z for laboratories, subject to specific exceptions. It requires a written Chemical Hygiene Plan and a designated Chemical Hygiene Officer, and defines key terms including laboratory use, hazardous chemical, designated area, and emergency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-osha-29-cfr-1910-general-industry",
      "osha-hazard-communication-standard"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-osha-29-cfr-1910-147-control-hazardous-energy-lockout-tagout",
    "title": "29 CFR § 1910.147 - The control of hazardous energy (lockout/tagout).",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This regulation requires employers to establish a program and utilize procedures for affixing appropriate lockout or tagout devices to energy isolating devices to prevent unexpected energization or start-up of machines during service and maintenance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-osha-29-cfr-1910-178-powered-industrial-trucks",
    "title": "OSHA General Industry Standard 29 CFR 1910.178 - Powered industrial trucks",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "29 CFR 1910.178 sets safety requirements for the fire protection, design, maintenance, and use of fork trucks, tractors, platform lift trucks, motorized hand trucks, and other specialized industrial trucks. New powered industrial trucks must meet the applicable ANSI design and construction requirements, bear approval markings from a nationally recognized testing laboratory, and may not be modified in ways affecting capacity or safe operation without the manufacturer's prior written approval. The standard defines eleven truck designations (D, DS, DY, E, ES, EE, EX, G, GS, LP, LPS) tied to atmosphere and location classification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-osha-29-cfr-1910-general-industry",
      "us-occupational-safety-health-act-1970"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-osha-29-cfr-1910-269-electric-power-generation-transmission-distribution",
    "title": "OSHA General Industry Standard 29 CFR 1910.269 - Electric power generation, transmission, and distribution",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "29 CFR 1910.269 covers the operation and maintenance of electric power generation, control, transformation, transmission, and distribution lines and equipment, including the installations of electric utilities and equivalent installations of industrial establishments. It applies to related communication and metering equipment accessible only to qualified employees, certain generating-station installations, electrical test sites, and line-clearance tree trimming around energized lines, while excluding construction work except as specified.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-osha-29-cfr-1910-general-industry",
      "us-osha-29-cfr-1910-147-control-hazardous-energy-lockout-tagout"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-osha-29-cfr-1910-95-occupational-noise-exposure",
    "title": "OSHA General Industry Standard 29 CFR 1910.95 - Occupational noise exposure",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "29 CFR 1910.95 requires general-industry employers to protect employees against the effects of occupational noise, administer a hearing conservation program whenever exposures equal or exceed an 8-hour time-weighted average of 85 decibels (the action level), monitor exposures, provide audiometric testing at no cost, and make hearing protectors available. Feasible administrative or engineering controls must be used when sound levels exceed the limits in Table G-16, and personal protective equipment supplements those controls where they are insufficient.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-osha-29-cfr-1910-general-industry",
      "us-occupational-safety-health-act-1970"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-osha-29-cfr-1910-general-industry",
    "title": "Occupational Safety and Health Standards for General Industry (29 CFR Part 1910)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes safety and health standards for general industry employers and employees, requiring compliance with provisions such as hazard communication, personal protective equipment, and emergency action planning. Key requirements are found in 1910.120, 1910.132, and 1910.38.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-convention-155-occupational-safety-1981",
      "iso-45001-health-safety"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-osha-29-cfr-1915-shipyard-employment",
    "title": "29 CFR Part 1915 - Occupational Safety and Health Standards for Shipyard Employment (OSHA)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "OSHA 29 CFR Part 1915 sets the occupational safety and health standards for shipyard employment, requiring employers to meet compliance duties owed to each employee, designate a competent person, test confined and enclosed spaces before entry, control cleaning, cold work, hot work, and flammable liquids, maintain safe conditions and warning signs, provide ventilation and protection during welding, cutting, and heating, provide compliant scaffolds, ladders, and guarding, ensure safe access to vessels and confined spaces, and maintain general working conditions including housekeeping, lighting, and working-alone controls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-occupational-safety-health-act-1970"
    ],
    "primary_citations_count": 22
  },
  {
    "node_id": "us-osha-29-cfr-1917-marine-terminals",
    "title": "29 CFR Part 1917 - Marine Terminals (OSHA)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "OSHA 29 CFR Part 1917 sets the safety and health standards for marine terminals, requiring employers to meet compliance duties owed to each employee, control housekeeping and slippery conditions, manage cargo slinging and stacking, address hazardous atmospheres and substances including carbon monoxide and fumigants, provide first aid and lifesaving facilities, train personnel and provide hazard communication, maintain emergency action plans, and safely operate powered industrial trucks, cranes, and derricks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-occupational-safety-health-act-1970"
    ],
    "primary_citations_count": 17
  },
  {
    "node_id": "us-osha-29-cfr-1918-longshoring",
    "title": "29 CFR Part 1918 - Safety and Health Regulations for Longshoring (OSHA)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "OSHA 29 CFR Part 1918 sets the safety and health regulations for longshoring aboard vessels, requiring employers to meet compliance duties owed to each employee, certify vessel cargo handling gear, provide safe means of access including gangways and ladders, secure hatch coverings and open hatches, guard weather deck edges, inspect and rate ship and shore-based cargo handling gear, and safely use rigging, winches, cranes, and auxiliary gear.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-occupational-safety-health-act-1970"
    ],
    "primary_citations_count": 18
  },
  {
    "node_id": "us-osha-29-cfr-1926-451-scaffolds-general-requirements",
    "title": "OSHA Construction Standard 29 CFR 1926.451 - Scaffolds, General requirements (Subpart L)",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "29 CFR 1926.451 sets the general requirements for scaffolds used in construction (Subpart L), excluding aerial lifts. Each scaffold and scaffold component must support at least 4 times its maximum intended load, suspension ropes must support at least 6 times the maximum intended load, and scaffolds must be designed by a qualified person and loaded in accordance with that design. The standard specifies platform construction, planking, and minimum platform width requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-osha-construction-safety-29-cfr-1926",
      "us-osha-1926-construction-standards"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-osha-29-cfr-1926-62-lead-in-construction",
    "title": "OSHA Construction Standard 29 CFR 1926.62 - Lead",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "29 CFR 1926.62 applies to all construction work where an employee may be occupationally exposed to lead, including demolition, removal or encapsulation of lead materials, new construction and renovation, and lead cleanup. It sets a permissible exposure limit of 50 micrograms of lead per cubic meter of air (50 micrograms per cubic meter) as an 8-hour time-weighted average and an action level of 30 micrograms per cubic meter, and requires exposure assessment, engineering and work-practice controls, protective clothing, hygiene facilities, and warning signs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-osha-construction-safety-29-cfr-1926",
      "us-osha-1926-construction-standards"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-osha-29-cfr-1926-construction-safety-fall-hazard-electrical",
    "title": "US OSHA 29 CFR Part 1926 - Construction Industry Safety Standards: Falls, Electrical & PPE",
    "domain": "Construction & Real Estate",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "29 CFR Part 1926 establishes OSHA's comprehensive construction industry safety standards - covering fall protection (leading cause of construction fatalities), electrical safety, scaffolding, personal protective equipment, and excavation safety - enforced with civil penalties up to $156,259 per willful violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-osha-ai-ergonomics-guidance",
    "title": "US OSHA General Duty Clause - Ergonomics, AI-Driven Monitoring and Workplace Hazard Management (29 USC § 654)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Under the General Duty Clause, Section 5(a)(1) of the OSH Act, employers must furnish a place of employment free from recognized hazards causing or likely to cause death or serious physical harm. This includes ergonomic hazards, and requires that any AI-driven monitoring systems used for hazard identification are effective, non-discriminatory, and do not create new hazards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "osha-work-safety-us",
      "iso-45001-work-safety",
      "iso-31000-risk-mgt-std",
      "eeoc-employment-rule",
      "unesco-ai-ethics-work"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-osha-cfr-29-part-1904-recording-reporting",
    "title": "29 CFR Part 1904 - Recording and Reporting Occupational Injuries and Illnesses",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-04",
    "bluf": "This regulation establishes requirements for employers to record, maintain, and report work-related injuries and illnesses to the Occupational Safety and Health Administration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "us-osha-cfr-29-part-1910-general-industry",
    "title": "29 CFR Part 1910 - Occupational Safety and Health Standards",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This regulation establishes the legal authority under various U.S. Code sections and Secretary of Labor's Orders for the promulgation of occupational safety and health standards for general industry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-osha-cfr-29-part-1926-construction-safety-standards",
    "title": "29 CFR Part 1926 - Safety and Health Regulations for Construction",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "Organizations must implement and maintain comprehensive safety and health programs for construction work, covering general provisions, training, first aid, fire protection, personal protective equipment, and emergency action plans.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "us-osha-construction-safety-29-cfr-1926",
    "title": "US OSHA Construction Safety Standards 29 CFR Part 1926 - Fall Protection, Scaffolding, Excavations, Electrical, Cranes, Personal Protective Equipment and Hazard Communication",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This regulation establishes safety and health standards for construction work under the Occupational Safety and Health Act, applying to all employers and employees engaged in construction activities. Key requirements include fall protection in 29 CFR 1926 Subpart M, trenching and excavation protections in Subpart P, and crane safety in Subpart CC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ada-accessibility-guidelines-2010-aba",
      "us-clean-water-act-section-404-construction",
      "iso-19650-bim-information-management-construction"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-osha-process-safety-management-1910-119",
    "title": "Process Safety Management of Highly Hazardous Chemicals",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation requires employers operating processes involving threshold quantities of highly hazardous chemicals to implement a comprehensive process safety management (PSM) program, including process hazard analysis (PHA), operating procedures, incident investigation, and emergency response planning. Key requirements are outlined in 29 CFR 1910.119(a)(1)(i) and (j).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iec-62443-iacs",
      "nist-sp-800-82-r3-ot-ics-security-guide-2023",
      "ot-ics-purdue-model-zone-based-security",
      "iso-iec-27019-energy-utility-information-security"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-osra-2022-ocean-shipping-reform-pl-117-146",
    "title": "US Ocean Shipping Reform Act of 2022 (Public Law 117-146) - Container Shipping Practices and FMC Oversight",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Ocean Shipping Reform Act of 2022 amended the Shipping Act of 1984 to expand Federal Maritime Commission oversight of ocean common carrier practices by prohibiting unreasonable refusal to deal or negotiate with respect to vessel space accommodation, requiring carriers to file annual detention and demurrage rule descriptions, prohibiting unreasonable detention and demurrage charges, requiring the FMC to define unfair or unjustly discriminatory methods, and authorising the FMC to initiate investigations of its own motion, levy civil penalties, and order refunds for violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-shipping-act-1984"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ostp-blueprint-ai-bill-of-rights",
    "title": "US OSTP Blueprint for an AI Bill of Rights - Five Principles for Automated Systems",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-28",
    "bluf": "The White House Office of Science and Technology Policy (OSTP) Blueprint for an AI Bill of Rights (October 2022) establishes five principles and associated practices that should guide the design, development, and deployment of automated systems to protect the rights of the American public; the Blueprint is non-binding guidance (not law or regulation) but provides the foundational US government framework that influenced Executive Order 14110 (2023) and OMB Memorandum M-24-10 (2024); the five principles are: (1) Safe and Effective Systems - automated systems must be developed with consultation and be tested to ensure they are safe and effective for their intended purpose before deployment; (2) Algorithmic Discrimination Protections - automated systems must be designed and used in an equitable way free from algorithmic discrimination based on race, color, ethnicity, sex, religion, age, national origin, disability, veteran status, genetic information, or any other classification protected by law; (3) Data Privacy - individuals should be protected from abusive data practices via built-in protections; data collection must be limited to what is necessary; consent must be meaningful; (4) Notice and Explanation - individuals should know that an automated system is being used and understand how it affects them; explanations must be plain-language and meaningful; (5) Human Alternatives, Consideration, and Fallback - individuals should be able to opt out of automated systems where appropriate and access a human alternative; automated systems must not block access to services; the Blueprint defines specific protected contexts - health, education, criminal justice, employment, housing, finance - where protections are especially important.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ostp-blueprint-ai-bill-of-rights.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14110-ai-2023",
      "us-omb-memorandum-ai-2024",
      "nist-ai-rmf-1-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-outer-continental-shelf-lands-act",
    "title": "US Outer Continental Shelf Lands Act (43 USC ch 29): Offshore Leasing, Exploration and Safety Enforcement",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Outer Continental Shelf Lands Act (OCSLA, 43 U.S.C. ch. 29, subchapter III) governs the leasing of the submerged lands of the outer continental shelf for the development of oil, gas and other minerals, administered by the Department of the Interior through the Bureau of Ocean Energy Management and the Bureau of Safety and Environmental Enforcement. Section 1331 supplies the definitions, including outer Continental Shelf. Section 1332 sets the congressional declaration of policy that the outer continental shelf is a vital national resource to be made available for expeditious and orderly development subject to environmental safeguards. Section 1333 provides for the laws and regulations governing the lands, extending federal law to the structures and devices on the shelf. Section 1334 governs the administration of leasing. Section 1337 governs leases, easements and rights-of-way, including the competitive bidding process for oil and gas leases. Section 1340 governs geological and geophysical explorations. Enforcement is direct: section 1348 provides for the enforcement of safety and environmental regulations, including the duties of lessees and operators and federal inspections, and section 1350 sets out the remedies and penalties for violations, including civil and criminal penalties. The Act is the legal foundation of US offshore energy leasing and the safety and environmental regime for the outer continental shelf.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-pa-gaming-control-board-act-2004",
    "title": "Pennsylvania Race Horse Development and Gaming Act 2004 (4 Pa.C.S.) - PGCB Licensing, Interactive Gaming Permits and Sports Wagering Requirements",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes licensing, operational, and compliance requirements for casino, internet-based gambling, sports wagering, video gaming terminal (VGT) gambling, and fantasy sport games in Pennsylvania under oversight of the Pennsylvania Gaming Control Board (PGCB). Key provisions include enforcement actions for non-compliance such as fines and exclusion, as demonstrated in press releases citing violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-packers-and-stockyards-act",
    "title": "US Packers and Stockyards Act (7 USC ch 9): Fair Competition, Registration, Statutory Trust and Prompt Payment",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Packers and Stockyards Act, 1921, codified at 7 U.S.C. Chapter 9 (sections 181-229c), regulates competition and trade practices in the livestock, meatpacking and poultry industries and is administered by the USDA Agricultural Marketing Service through its Packers and Stockyards Division. Section 182 defines the regulated terms, section 191 defines 'packer', and section 201 defines 'stockyard owner', 'market agency' and 'dealer'. Section 192 makes it unlawful for any packer or swine contractor to engage in or use any unfair, unjustly discriminatory or deceptive practice or device; to make or give any undue or unreasonable preference; to apportion supply among packers in restraint of commerce; to manipulate or control prices; to create a monopoly; or to engage in any course of business for the purpose of those effects. Section 213 imposes the parallel prohibition on stockyard owners, market agencies and dealers: it is unlawful to engage in or use any unfair, unjustly discriminatory or deceptive practice or device. Section 203 requires market agencies and dealers to register with the Secretary, and provides that a person who violates the registration requirement is liable to a penalty of not more than $500 for each offense and not more than $25 for each day it continues. Section 204 requires bonds. Sections 206-208 require reasonable, non-discriminatory rates and charges and prohibit unreasonable or discriminatory practices in stockyard services. Section 196 (livestock) and section 197 (poultry) establish a statutory trust under which commodities, inventories and receivables are held in trust for the benefit of unpaid cash sellers. Section 228b requires prompt payment for livestock purchases. Enforcement under sections 193 and 213(b) allows the Secretary to assess a civil penalty of not more than $10,000 for each violation, and section 195 provides criminal punishment for violating a final order, on conviction, of a fine of not less than $500 nor more than $10,000, or imprisonment of not less than six months nor more than five years, or both. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-paperwork-reduction-act-1995-digital-workflow",
    "title": "Paperwork Reduction Act of 1995 (44 U.S.C. §§3501-3521) - OMB Information Collection Approval, Burden Minimisation and Electronic Submission Standards",
    "domain": "Operations & CX",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Paperwork Reduction Act of 1995 requires federal agencies to minimize the burden of information collection on the public and obtain Office of Management and Budget (OMB) approval before collecting information, including through digital workflows. It applies to all federal agencies and any third-party systems processing federally mandated information collections under 44 U.S.C. §3507.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "automation-bpmn-service-task",
      "automation-bpmn-error-boundary",
      "mcp-enterprise-auth"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-paperwork-reduction-act-44-usc-ch35",
    "title": "United States Paperwork Reduction Act (Title 44 USC Chapter 35): OMB Director Authority, Federal Agency Responsibilities, Information Collection Approval, OMB Control Numbers, and Public Protection",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Paperwork Reduction Act, codified at Title 44 of the United States Code, Chapter 35, is the principal federal statute governing federal information collection from the public and is administered through the Office of Information and Regulatory Affairs within the Office of Management and Budget. Paperwork Reduction Act, 44 U.S.C. 3501 states that the purpose of the chapter is to minimize the paperwork burden for individuals, small businesses, educational and nonprofit institutions, Federal contractors, State, local and tribal governments, and other persons resulting from the collection of information by or for the Federal Government. Paperwork Reduction Act, 44 U.S.C. 3502 contains the definitions including the definition of collection of information. Paperwork Reduction Act, 44 U.S.C. 3503 establishes the Office of Information and Regulatory Affairs. Paperwork Reduction Act, 44 U.S.C. 3504 vests broad authority in the Director of the Office of Management and Budget to oversee information collection and federal information policy. Paperwork Reduction Act, 44 U.S.C. 3506 sets out federal agency responsibilities including compliance with OMB policies. Paperwork Reduction Act, 44 U.S.C. 3507 requires federal agencies to submit information collection requests to the Director, requires Director approval before implementation, and provides that requests cannot proceed without valid OMB control numbers. Paperwork Reduction Act, 44 U.S.C. 3508 governs determinations of necessity for information collections and the right to a hearing. Paperwork Reduction Act, 44 U.S.C. 3512 is the public protection provision: no person is required to comply with any collection of information unless it displays a currently valid OMB control number. Subchapter II covers information security requirements and Subchapter III covers confidential information protection and statistical efficiency. The Act is the controlling federal instrument for clearance of federal information collections.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
    "title": "Murphy v. National Collegiate Athletic Association, 584 U.S. ___ (2018) - Judgment on the Professional and Amateur Sports Protection Act (PASPA) and State Authority to Legalize Sports Betting",
    "domain": "Gaming & Gambling",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The U.S. Supreme Court in Murphy v. NCAA (2018) ruled that the Professional and Amateur Sports Protection Act (PASPA) violates the anti-commandeering doctrine of the Tenth Amendment by prohibiting states from authorizing sports gambling, thereby granting states the sovereign right to legalize, regulate, and tax sports betting. The decision invalidated 28 U.S.C. § 3701-3704, effectively repealing PASPA's core enforcement mechanism.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sherman-antitrust-act-sections-1-2"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-passenger-vessel-services-act-46-usc-55103",
    "title": "Passenger Vessel Services Act, 46 USC 55103",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Passenger Vessel Services Act, codified at 46 USC 55103, restricts the coastwise transportation of passengers. Section 55103(a) prohibits a vessel from transporting passengers between ports or places in the United States to which the coastwise laws apply, directly or via a foreign port, unless the vessel is wholly owned by citizens of the United States for purposes of engaging in the coastwise trade and has been issued a certificate of documentation with a coastwise endorsement. Section 55103(b) sets the penalty at $300 for each passenger transported and landed in violation of subsection (a).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-coast-guard-vessel-documentation-46-cfr-67-jones-act-cabotage"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-patent-act",
    "title": "US Patent Act (35 USC): Patentability, Novelty, Non-Obviousness and Infringement",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Patent Act (35 U.S.C.) governs the grant and enforcement of US patents, administered for examination and grant by the United States Patent and Trademark Office (USPTO). Section 100 supplies the definitions, including invention and effective filing date. Section 101 sets the categories of patentable subject matter: any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement. Section 102 sets the novelty requirement, barring a patent where the claimed invention was patented, described in a printed publication, or otherwise available to the public before the effective filing date, on the first-inventor-to-file basis. Section 103 bars a patent where the differences from the prior art would have been obvious to a person of ordinary skill in the art. On enforcement, section 271 defines infringement: whoever without authority makes, uses, offers to sell, or sells a patented invention within the United States, or imports it, infringes the patent, with separate liability for active inducement and for contributory infringement, and section 273 provides a defense based on prior commercial use. Remedies are in Chapter 29: section 284 provides damages adequate to compensate, no less than a reasonable royalty, with the possibility of enhanced damages, and section 285 allows attorney fees in exceptional cases. The Act is the legal foundation of US patent rights, validity analysis, and infringement litigation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-patriot-act-2001-pl-107-56",
    "title": "USA PATRIOT Act 2001 - Public Law 107-56 Antiterrorism Authorities",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The USA PATRIOT Act (Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001, Public Law 107-56, enacted 26 October 2001) is the omnibus US antiterrorism statute that materially expanded federal investigative, surveillance, financial-intelligence, immigration, and information-sharing authorities. The Act is organised into ten titles. Title I (Enhancing Domestic Security Against Terrorism) authorises counterterrorism funding and condemns discrimination. Title II (Enhanced Surveillance Procedures) expands electronic surveillance, pen register and trap-and-trace authority, foreign intelligence wiretap roving and US person surveillance limits. Title III (International Money Laundering Abatement and Anti-Terrorist Financing Act of 2001) substantially extends the Bank Secrecy Act including section 314(a) and (b) information sharing, section 311 special measures against jurisdictions of primary money-laundering concern, section 326 customer identification programs, and section 352 anti-money-laundering programs. Title IV (Protecting the Border) tightens immigration. Title V (Removing Obstacles to Investigating Terrorism) grants additional investigative authorities. Title VI (Victims of Terrorism). Title VII (Increased Information Sharing for Critical Infrastructure Protection). Title VIII (Strengthening the Criminal Laws Against Terrorism). Title IX (Improved Intelligence). Title X (Miscellaneous including biosecurity). Many surveillance provisions were sunset and then re-enacted via the USA FREEDOM Act of 2015 with materially modified safeguards. The Act remains the operative US framework for AML / counter-terrorism-financing programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bsa-bank-secrecy-act-31-usc-5311",
      "us-money-laundering-control-act-18-usc-1956"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-pdufa-prescription-drug-user-fee-act",
    "title": "Prescription Drug User Fee Amendments",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Prescription Drug User Fee Act (PDUFA) authorizes the FDA to collect user fees from persons submitting certain human drug applications for review or named as sponsors in approved applications. Application fees are required upon submission of a human drug application under section 505(b) of the FD&C Act or section 351(a) of the PHS Act, with full or half fees based on clinical data requirements, and annual program fees are assessed for each eligible prescription drug product as of October 1 of the fiscal year.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-21-cfr-part-314-nda-new-drug-application",
      "fda-21-cfr-part-600-601-biologics-licensing",
      "fda-pdufa-vii-goals-letter-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-pdufa-vii-prescription-drug-user-fee-goals",
    "title": "PDUFA Reauthorization Performance Goals and Procedures Fiscal Years 2023 Through 2027",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "For fiscal years 2023-2027, the U.S. FDA commits to specific performance goals for reviewing new drug applications (NDAs) and biologics license applications (BLAs), requiring review and action on 90% of standard applications within 10 months of filing and priority applications within 6 months, as detailed in Section I.A of the PDUFA VII Commitment Letter.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-pecan-promotion-research-act",
    "title": "US Pecan Promotion and Research Act of 1990 (7 USC ch 89): Pecan Board, Plans and Assessments",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Pecan Promotion and Research Act of 1990 (7 U.S.C. ch. 89, sections 6001 to 6013) authorizes coordinated programs of promotion and research for pecans funded by assessments and implemented through plans, administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 6001 sets out the findings and declaration of policy, declaring it to be the policy of Congress that it is in the public interest to authorize the establishment of coordinated programs for pecan promotion and research financed through assessments. Section 6002 defines the terms, and section 6003 authorizes the issuance of plans. Section 6005 sets the required terms in plans, providing that the Board shall consist of 15 members, including 8 members who are growers, 4 members who are shellers, one first handler, one importer, and one public representative. Section 6006 sets the permissive terms, and section 6007 sets the assessments, providing that assessments shall be levied on all pecans produced in, and all pecans imported into, the United States when marketed. Section 6008 provides for petition and review, section 6009 provides for enforcement, including that a person who willfully violates the chapter may be assessed by the Secretary a civil penalty between 1,000 dollars and 10,000 dollars per violation, and section 6010 provides investigations and power to subpoena. Section 6011 requires a referendum not later than 24 months after the effective date of the plan, and section 6012 provides for the suspension or termination of a plan. The Act is the federal checkoff regime for pecans.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-pen-register-trap-trace-18-usc-3121",
    "title": "Pen Register and Trap and Trace Act - 18 USC 3121",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 3121 of title 18 of the United States Code, the Pen Register and Trap and Trace Devices Act (enacted as Title III of the Electronic Communications Privacy Act of 1986, Public Law 99-508, with subsequent amendments through the USA PATRIOT Act, the USA FREEDOM Act, and the Cyber Incident Reporting for Critical Infrastructure Act 2022), prohibits any person from installing or using a pen register or trap and trace device without first obtaining a court order under section 3123 or under the Foreign Intelligence Surveillance Act. A pen register records the dialing, routing, addressing, or signalling information transmitted by an instrument from which a wire or electronic communication originates; a trap and trace device captures the equivalent incoming-call information. The statute exempts service providers operating these devices for service operation, fraud and abuse prevention, or with the consent of the user. Section 3122 governs the application procedure including identification of the applicant and the agency conducting the investigation. Section 3123 governs court orders including the certification standard, the duration limits, the non-disclosure provisions, and the minimisation requirements. Section 3124 governs assistance from service providers. Knowing violations carry fines and up to one year imprisonment under section 3121(d). Pen register and trap-and-trace authority is the principal procedural framework for non-content metadata collection by federal and state law enforcement in criminal investigations and is central to AI-enabled cybersecurity, fraud detection, and counter-terrorism operations involving network metadata.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ecpa-1986",
      "us-stored-communications-act",
      "us-fisa-foreign-intelligence-surveillance-act-50-usc-ch36"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-pennsylvania-sports-wagering-act-2017",
    "title": "Pennsylvania Sports Wagering Act 2017 (Act 42) - PGCB Licensing and 36% Revenue Tax",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Pennsylvania Act 42 of 2017 amended the Race Horse Development and Gaming Act to add interactive and mobile sports wagering provisions, codified at 4 Pa.C.S. Chapter 13C. The Pennsylvania Gaming Control Board (PGCB) regulates sports wagering. A 36% tax applies to gross sports wagering revenue. The initial Sports Wagering Certificate fee is $10 million. Minimum age is 21. Pennsylvania was the first large US state to legalise sports wagering post-Murphy; retail sports betting launched November 19, 2018, and online/mobile launched in May 2019. Operators must obtain a Sports Wagering Certificate and comply with PGCB technical and responsible gaming standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_paspa_repeal",
        "us_uigea_2006",
        "pa_race_horse_gaming_act",
        "fatf_gambling",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
      "us-uigea-2006-unlawful-internet-gambling",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-pension-protection-act-2006-pl-109-280",
    "title": "Pension Protection Act 2006 - Public Law 109-280",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Pension Protection Act of 2006 (PPA, Public Law 109-280, enacted 17 August 2006) substantially restructured the US private pension and retirement plan framework. Title I (Funding Rules for Single-Employer Defined Benefit Plans) established new minimum funding standards including 7-year amortisation, at-risk plan rules, benefit restrictions for underfunded plans, and revised target normal cost calculations. Title II (Funding Rules for Multiemployer Plans) introduced the endangered, seriously endangered, and critical status zone framework with mandatory funding improvement and rehabilitation plans. Title III (Interest Rate Assumptions) modified PBGC variable-rate premium and interest rate assumptions. Title IV (PBGC Provisions) raised PBGC premiums and reformed liability limits. Title V (Disclosure) enhanced participant and beneficiary disclosure including the annual funding notice. Title VI (Investment Advice; Prohibited Transactions; Fiduciary Rules) established eligible investment advice arrangement (EIAA), expanded permitted statutory exemptions, and codified Qualified Default Investment Alternatives (QDIAs) supporting automatic enrolment. Title VII (Benefit Accrual Standards) clarified cash balance and hybrid plan rules following Cooper v IBM. Title VIII (Pension-related Revenue Provisions) made permanent the Roth 401(k), expanded direct rollovers, and modified IRA limits. Title XII (Other Provisions) created new charitable giving tax incentives and modified college savings plans. The PPA is the principal pension reform of the post-ERISA era and substantially shaped subsequent SECURE Act 2019 and SECURE 2.0 reforms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-erisa-29-usc-1001",
      "us-secure-act-2019-pl-116-94"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-perishable-agricultural-commodities-act",
    "title": "US Perishable Agricultural Commodities Act (PACA, 7 USC ch 20A): Licensing, Fair Conduct and the Statutory Trust",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Perishable Agricultural Commodities Act, 1930 (PACA), codified at 7 U.S.C. Chapter 20A (sections 499a-499t), regulates the marketing of fresh and frozen fruits and vegetables in interstate and foreign commerce and is administered by the USDA Agricultural Marketing Service through its PACA Division. Section 499a defines the regulated terms, including 'commission merchant', 'dealer' and 'broker'. Section 499c requires commission merchants, dealers and brokers to hold a PACA license, and provides that operating without a required license incurs a penalty of not more than $1,000 for each offense and not more than $250 for each day the offense continues. Section 499b sets out the unfair conduct that is unlawful, including using any unfair, unreasonable, discriminatory or deceptive practice in connection with weighing, counting or determining quantity; making, for a fraudulent purpose, any false or misleading statement in connection with a transaction; misrepresenting by word, mark, label or deed the character, kind, grade, quality, quantity, condition, packing or origin of any commodity; and failing or refusing truly and correctly to account and make full payment promptly. Section 499e makes a violator liable to the injured person, and section 499e(c) establishes the PACA statutory trust: perishable agricultural commodities received by a commission merchant, dealer or broker, and all inventories and receivables or proceeds derived from them, are held in trust for the benefit of all unpaid suppliers or sellers until full payment is made, with the seller preserving its trust benefits by giving the prescribed notice. Section 499g provides for reparation orders, section 499i requires accounts and records, and section 499n provides for inspection. Section 499h sets out the grounds for suspension or revocation of a license and authorizes, in lieu of or in addition to suspension, a civil penalty of not more than $2,000 for each violative transaction or each day a violation continues. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-phmsa-49-cfr-192-gas-pipeline-safety",
    "title": "49 CFR Part 192 - Transportation of Natural and Other Gas by Pipeline: Minimum Federal Safety Standards",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "PHMSA 49 CFR Part 192 prescribes minimum federal safety standards for the transportation of natural and other gas by pipeline, requiring operators to classify pipeline locations, control corrosion through qualified personnel and cathodic protection, follow a written manual of operations, maintenance, and emergency procedures reviewed at least annually, run a damage prevention program, maintain emergency plans, conduct leakage surveys on distribution systems, and implement an integrity management program for transmission lines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-phmsa-49-cfr-195-hazardous-liquid-pipeline-safety",
    "title": "49 CFR Part 195 - Transportation of Hazardous Liquids by Pipeline",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "PHMSA 49 CFR Part 195 governs the transportation of hazardous liquids and carbon dioxide by pipeline, holding operators responsible for compliance, requiring accident reporting, a written manual of operations, maintenance, and emergency procedures reviewed at least annually, emergency response training, operation within maximum operating pressure, valve maintenance, an effective leak detection system, integrity management for pipelines that could affect high consequence areas, and external and internal corrosion control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 10
  },
  {
    "node_id": "us-physician-self-referral-stark-law",
    "title": "US Physician Self-Referral Law / Stark Law (42 USC 1395nn): Referral Limits and Payment Denial",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Physician Self-Referral Law, known as the Stark Law (42 U.S.C. 1395nn), prohibits a physician from referring Medicare patients for designated health services to an entity with which the physician, or an immediate family member, has a financial relationship, unless an exception applies, administered by the Centers for Medicare and Medicaid Services. Section 1395nn(a) provides that if a physician has a financial relationship with an entity, the physician may not make a referral to that entity for the furnishing of designated health services, and the entity may not present a claim for such services. The designated health services include clinical laboratory services, physical and occupational therapy, radiology and other imaging, radiation therapy, durable medical equipment, parenteral and enteral nutrients, prosthetics and orthotics, home health services, outpatient prescription drugs, and inpatient and outpatient hospital services. A financial relationship includes both ownership or investment interests and compensation arrangements. Where a referral violates the prohibition, no payment may be made for the service, and amounts collected must be refunded. The statute contains numerous exceptions, including in-office ancillary services, bona fide employment, fair market value compensation and rental of office space or equipment. Unlike the Anti-Kickback Statute, the Stark Law is a strict liability statute that does not require proof of intent. It is the legal foundation for US physician self-referral compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-pipeline-hazardous-materials-safety-act-2011",
    "title": "Pipeline Safety, Regulatory Certainty, and Job Creation Act of 2011",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2025-07-15",
    "bluf": "This Act mandates the Pipeline and Hazardous Materials Safety Administration (PHMSA) to strengthen pipeline safety regulations for gas and hazardous liquid pipeline operators. Key provisions require expanded integrity management programs, verification of Maximum Allowable Operating Pressure (MAOP) for older pipelines (Section 23), and enhanced incident notification requirements (Section 6).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-plant-protection-act",
    "title": "US Plant Protection Act: Plant Pests, Noxious Weeds, Quarantine and Emergency Authority",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Plant Protection Act (PPA), codified at 7 U.S.C. Chapter 104 (sections 7701-7786), is the principal US statute for preventing the introduction and spread of plant pests and noxious weeds, administered by the USDA Animal and Plant Health Inspection Service (APHIS). Section 7701 sets the findings and section 7702 the definitions, including 'plant pest' and 'noxious weed'. Section 7711 establishes the core prohibition: no person may import, enter, export, or move in interstate commerce any plant pest unless authorized under a permit or other authorization issued by the Secretary, subject to regulations. Section 7712 authorizes the Secretary to prohibit or restrict the movement of plants, plant products, biological control organisms, noxious weeds, articles and means of conveyance to prevent the dissemination of plant pests or noxious weeds, with subsection (f) addressing noxious weeds specifically. Section 7713 imposes notification and holding requirements upon the arrival of regulated articles, and section 7714 confers general remedial measures for new plant pests and noxious weeds, including the authority to hold, seize, quarantine, treat, apply other remedial measures to, destroy, or otherwise dispose of articles. Section 7715 provides for the declaration of an extraordinary emergency and the resulting authorities, including action against pests already in the United States and compensation. Section 7731 provides inspection authority, and section 7734 sets the penalties for violations, including civil penalties and criminal penalties. The Act consolidated and replaced earlier plant quarantine statutes and is implemented by APHIS regulations in 7 CFR.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-plant-variety-protection-act",
    "title": "US Plant Variety Protection Act (7 USC ch 57): Breeder Rights, Certification, Infringement and Remedies",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Plant Variety Protection Act (PVPA), codified at 7 U.S.C. Chapter 57 (sections 2321-2583), grants intellectual property protection to breeders of new, sexually reproduced or tuber-propagated plant varieties, administered by the USDA Agricultural Marketing Service through the Plant Variety Protection Office. Section 2402 sets the right to protection: the breeder of a variety (or the successor in interest) is entitled to plant variety protection if the variety is new, in the sense that propagating or harvested material has not been sold or otherwise disposed of for purposes of exploitation beyond the statutory timeframes; distinct, in the sense that it is clearly distinguishable from any other variety the existence of which is publicly known; uniform, in the sense that any variations are describable, predictable and commercially acceptable; and stable, in the sense that the variety when reproduced will remain unchanged with regard to its essential and distinctive characteristics. Section 2422 governs the application, and section 2483 sets the contents and term of protection: the certificate grants the owner the right to exclude others from selling or marketing the variety, offering it for sale, reproducing it, importing or exporting it, or using it in producing a hybrid or different variety, for a term of 20 years from the date of issue (25 years for trees and vines). Section 2541 defines the acts that constitute infringement (including selling, marketing, sexually or asexually multiplying the variety as a step in marketing, using it to produce a hybrid, dispensing it without notice, conditioning it for propagation, and inducing others to do these acts), while section 2543 preserves the right of a farmer to save seed and the research exemption. Sections 2561-2570 set the remedies: section 2564 provides damages adequate to compensate for the infringement but in no event less than a reasonable royalty, which the court may increase up to three times; section 2565 allows reasonable attorney fees in exceptional cases; and section 2568 imposes penalties for false marking (up to $10,000, with a minimum of $500).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-plant-variety-protection-act-1970-usda-pvpo",
    "title": "US Plant Variety Protection Act 1970 - PVPO Certificate and Breeder Rights Framework",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The US Plant Variety Protection Act (PVPA, 7 USC 2321 et seq., enacted 1970 as P.L. 91-577) provides intellectual property protection for sexually reproduced and tuber-propagated plant varieties. The USDA Plant Variety Protection Office (PVPO) examines applications and issues PVP Certificates conferring exclusive rights. Protection lasts 20 years (25 years for trees and vines). Key exemptions include the research exemption (any person may use a protected variety for research) and the crop exemption (farmers may save seed from protected varieties for their own use). However, varieties protected under Section 2541(h) (those marked 'Sold Under Title V...') forfeit the crop exemption. Ornamental varieties may also be protected under utility patent instead. PVPA complements Plant Patent Act (1930) for asexually reproduced varieties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "india-seeds-act-1966-dac-ministry-agriculture"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-poison-prevention-packaging-act",
    "title": "US Poison Prevention Packaging Act (15 USC ch 39A): Child-Resistant Packaging Standards",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Poison Prevention Packaging Act (15 U.S.C. ch. 39A) authorizes the Consumer Product Safety Commission to require special packaging to protect children from serious personal injury or illness from handling, using or ingesting household substances. Section 1471 provides the definitions, including household substance and special packaging, which is packaging designed to be significantly difficult for children under five years of age to open or obtain a toxic or harmful amount within a reasonable time, yet not difficult for normal adults to use properly. Section 1472 authorizes the Commission to establish special packaging standards for a household substance where it determines that the degree or nature of the hazard to children requires it and that special packaging is technically feasible, practicable and appropriate. Section 1473 permits a manufacturer or packer to also market a single size in non-complying packaging for households without young children, provided complying packaging is supplied and the package bears a conspicuous label. Section 1476 addresses preemption and references the penalties, which are enforced through the Federal Hazardous Substances Act, since a substance not packaged in compliance is treated as a misbranded hazardous substance. The Act is the legal foundation for US child-resistant packaging of drugs and hazardous household products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-pollution-prevention-act",
    "title": "US Pollution Prevention Act of 1990 (42 USC ch 133): Source Reduction Hierarchy and Reporting",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Pollution Prevention Act of 1990 (PPA), codified at 42 U.S.C. Chapter 133 (sections 13101-13109), establishes pollution prevention through source reduction as the national environmental policy of first resort and is administered by the US Environmental Protection Agency (EPA). Section 13101 sets the findings and declares the policy that the United States establishes as a national objective the prevention or reduction of pollution at the source, setting out the environmental management hierarchy: pollution should be prevented or reduced at the source whenever feasible; pollution that cannot be prevented should be recycled in an environmentally safe manner whenever feasible; pollution that cannot be prevented or recycled should be treated in an environmentally safe manner whenever feasible; and disposal or other release into the environment should be employed only as a last resort. Section 13102 defines the key terms, including 'source reduction', which means any practice that reduces the amount of any hazardous substance, pollutant or contaminant entering any waste stream or otherwise released into the environment (including fugitive emissions) prior to recycling, treatment or disposal, and reduces the hazards to public health and the environment associated with the release of such substances. Sections 13103-13105 direct EPA to undertake source reduction activities, make grants to States for technical assistance programs, and operate a source reduction clearinghouse. Section 13106 sets the central reporting requirement: an owner or operator of a facility required to file an annual toxic chemical release form under section 11023 (EPCRA) must include with that form a toxic chemical source reduction and recycling report for each listed chemical, reporting the quantity entering the waste stream, the amount recycled, the source reduction practices used, and related production-ratio and projection data. Section 13107 requires EPA to report to Congress. The PPA does not itself impose civil or criminal penalties; the section 13106 report is filed with, and enforced through, the EPCRA toxic chemical release reporting framework (and its penalties under 42 U.S.C. 11045).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-pollution-prevention-act-1990-42-usc-13101",
    "title": "US Pollution Prevention Act of 1990 (42 USC 13101) - Source Reduction Federal Policy",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Pollution Prevention Act of 1990 established federal policy that pollution should be prevented or reduced at the source whenever feasible, pollution that cannot be prevented should be recycled in an environmentally safe manner whenever feasible, pollution that cannot be prevented or recycled should be treated, and disposal or release should be employed only as a last resort, directed the Environmental Protection Agency to establish a source reduction program independent of single medium programs, required facilities reporting under the Emergency Planning and Community Right to Know Act Toxics Release Inventory to file a Form R source reduction and recycling report, and created the Source Reduction Clearinghouse.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-epa-40-cfr-355-epcra-emergency-planning-notification"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-pork-promotion-research-act",
    "title": "US Pork Promotion, Research, and Consumer Information Act of 1985 (7 USC ch 79): National Pork Board and Assessments",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Pork Promotion, Research, and Consumer Information Act of 1985 (7 U.S.C. ch. 79, sections 4801 to 4819) authorizes a coordinated program of promotion, research, and consumer information for pork and pork products funded by assessments, administered by the Secretary of Agriculture. Section 4801 sets out the congressional findings and declaration of purpose, including to strengthen the position of the pork industry in the marketplace and to maintain, develop, and expand markets for pork and pork products. Section 4802 defines the terms, including producer, importer, and the National Pork Board. Section 4803 authorizes pork and pork product orders, section 4805 governs the findings and issuance of orders, and section 4806 provides for the National Pork Producers Delegate Body. Section 4808 provides for the establishment and appointment by the Secretary of a 15-member National Pork Board. Section 4809 sets the assessments, providing that the rate of assessment prescribed by the initial order shall be the lesser of 0.25 percent of the market value or an amount established by the Secretary. Section 4811 requires a referendum among persons who have been pork producers and importers during a representative period, section 4812 provides for the suspension and termination of orders, and section 4813 provides for refunds. Section 4815 provides for enforcement, including a civil penalty assessed by the Secretary of not more than 1,000 dollars for each violation, and section 4816 provides investigation power. The Act is the federal checkoff regime for pork.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-posse-comitatus-act-18-usc-1385",
    "title": "Posse Comitatus Act 1878 - 18 USC 1385 Military in Civilian Law Enforcement",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 1385 of title 18 of the United States Code, the Posse Comitatus Act originally enacted in 1878 and amended subsequently to cover all uniformed services, makes it a federal crime for any person to willfully use any part of the Army, the Navy, the Marine Corps, the Air Force, or the Space Force as a posse comitatus or otherwise to execute the laws, except in cases and under circumstances expressly authorized by the Constitution or Act of Congress. Penalties include a fine under title 18 or imprisonment of not more than two years, or both. The express constitutional and statutory exceptions include the Insurrection Act (10 USC 251-255), the use of the National Guard under Title 32 status under state control, Department of Defense support to civilian law enforcement under 10 USC chapter 18 within the limits established by Department of Defense Directive 5525.5 and DoD Instruction 3025.21, the Coast Guard's law-enforcement authority under 14 USC 522, and specific statutory exceptions for counter-narcotics, counter-terrorism, immigration enforcement, and major disasters. The Posse Comitatus Act framework governs how AI-supported defense systems may be lent to civilian law enforcement (data-sharing limits, surveillance constraints, force-employment prohibitions) and is centrally relevant to homeland security, border security, and disaster response planning involving Department of Defense assets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-potato-research-promotion-act",
    "title": "US Potato Research and Promotion Act (7 USC ch 58): National Potato Promotion Board and Assessments",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Potato Research and Promotion Act (7 U.S.C. ch. 58, sections 2611 to 2627) authorizes a coordinated program of research and promotion for potatoes funded by assessments and implemented through plans, administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 2611 sets out the congressional findings and declaration of policy, declaring it to be the policy of Congress to authorize the establishment of an orderly procedure for the financing of an effective and continuous coordinated program. Section 2612 defines the terms, including Secretary, person, potatoes, handler, producer (a person engaged in the production of five or more acres of potatoes), promotion, and importer. Section 2613 provides the authority for issuance and amendment of a plan, section 2614 provides for notice and hearings, and section 2615 governs the finding and issuance of a plan. Section 2617 sets the required terms and conditions of plans, providing for the National Potato Promotion Board, which administers the plan, makes regulations, investigates violations, and recommends amendments. Section 2619 sets the assessments, providing that handlers collect assessments and importers pay at entry, with the assessment rate capped at 2 cents per 100 pounds or one-half of 1 percent of the ten-year average price. Section 2621 provides for enforcement, including civil penalties of 500 to 5,000 dollars per violation and cease-and-desist orders, section 2622 provides investigations, section 2623 provides for a referendum requiring approval by a majority of producers voting, and section 2624 provides for the suspension or termination of plans. The Act is the federal checkoff regime for potatoes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-poultry-products-inspection-act",
    "title": "US Poultry Products Inspection Act (21 USC ch 10): Mandatory Inspection, Labeling and Prohibited Acts",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Poultry Products Inspection Act (PPIA), codified at 21 U.S.C. Chapter 10 (sections 451-473), requires federal inspection of poultry and poultry products intended for use as human food and is administered by the USDA Food Safety and Inspection Service (FSIS). Section 453 defines the regulated terms, including 'poultry product', 'adulterated' and 'misbranded'. Section 455 requires inspection in official establishments, including post-mortem inspection of the carcasses of poultry and supervision of processing, so that products found unadulterated bear the official inspection mark. Section 456 requires sanitary operation of premises, facilities and equipment, and section 457 sets labeling and container standards, prohibiting false or misleading labeling. Section 458 sets out the prohibited acts: no person shall slaughter any poultry or process any poultry products capable of use as human food except in compliance with the chapter, and no person shall sell, transport, offer for sale or transportation, or receive for transportation in commerce any poultry products that are adulterated or misbranded. Section 459 extends compliance to all establishments, section 466 governs imports (which must meet standards at least equal to the Act), and sections 467a-467b provide for administrative detention, seizure and condemnation of violative articles. Section 461 sets the penalties: a violation is punishable by a fine of not more than $1,000 or imprisonment of not more than one year, or both; but where the violation involves intent to defraud or the distribution or attempted distribution of an adulterated article, the fine is not more than $10,000 or imprisonment of not more than three years, or both. Assaulting or interfering with an inspector is separately punishable, with enhanced penalties where a deadly or dangerous weapon is used. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-pregnant-workers-fairness-act-2022",
    "title": "United States Pregnant Workers Fairness Act of 2022 (PWFA) and PUMP for Nursing Mothers Act of 2022 (Public Law 117-328 Divisions II and KK): Reasonable Accommodations for Pregnancy, Childbirth, and Related Medical Conditions; Title VII Remedies; FLSA Section 7(r) Expansion of Nursing Mother Break Time and Private Space",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Pregnant Workers Fairness Act of 2022 (PWFA) (Division II of Public Law 117-328) and the Providing Urgent Maternal Protections for Nursing Mothers Act of 2022 (PUMP Act) (Division KK of Public Law 117-328) were enacted together on 29 December 2022 in the Consolidated Appropriations Act 2023 and together expand workplace protections for pregnancy, childbirth, related medical conditions, and nursing, administered by the Equal Employment Opportunity Commission (PWFA) and the Wage and Hour Division of the Department of Labor (PUMP Act). Pregnant Workers Fairness Act, codified at 42 U.S.C. 2000gg, applies to covered employers (15 or more employees) and prohibits not making reasonable accommodations to the known limitations related to the pregnancy, childbirth, or related medical conditions of a qualified employee, unless such covered entity can demonstrate that the accommodation would impose an undue hardship on the operation of the business of such covered entity. Pregnant Workers Fairness Act, 42 U.S.C. 2000gg-1 prohibits requiring a qualified employee affected by pregnancy, childbirth, or related medical conditions to accept an accommodation other than any reasonable accommodation arrived at through the interactive process; denying employment opportunities; requiring leave when another reasonable accommodation can be provided; or retaliating against an employee for requesting or using an accommodation. Pregnant Workers Fairness Act, 42 U.S.C. 2000gg-2 provides for remedies and enforcement cross-referenced to Title VII of the Civil Rights Act of 1964 powers, remedies, and procedures. PUMP for Nursing Mothers Act amended the Fair Labor Standards Act section 7(r) (29 U.S.C. 218d) to extend nursing mother break time and private space requirements (originally limited to non-exempt hourly workers under the Affordable Care Act amendment) to nearly all employees, including salaried employees, for up to one year after the child's birth, and added private right of action remedies. The Acts are the controlling federal instruments for workplace pregnancy and nursing accommodations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-presidential-records-act-44-usc-2201",
    "title": "US Presidential Records Act (44 USC 2201) - Public Ownership of Presidential Records",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Presidential Records Act establishes public ownership of records created or received by the President and Vice President in the course of constitutional, statutory, and ceremonial duties, requires the President to take all steps necessary to assure that the activities, deliberations, decisions, and policies that reflect the performance of constitutional, statutory, or other official ceremonial duties are adequately documented, requires preservation and transfer of records to the National Archives and Records Administration on the day a President leaves office, prohibits destruction of presidential records absent specified processes, and establishes timelines for public access through the Freedom of Information Act after a closed period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-foia-1966",
      "us-federal-records-act-44-usc-ch31"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-privacy-act-1974",
    "title": "US Privacy Act of 1974",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Privacy Act of 1974 governs how US federal agencies collect, maintain, use, and disseminate personally identifiable information about individuals, grants individuals rights to access and amend their agency records, and requires agencies to publish system of records notices in the Federal Register.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-privacy-act-1974.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ferpa-family-educational-rights-privacy"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-protecting-right-indigenous-sacred-expression-act",
    "title": "Indian Arts and Crafts Board; creation and composition; per diem payments",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the Indian Arts and Crafts Board within the Department of the Interior, composed of five commissioners appointed by the Secretary of the Interior, serving four-year terms (with initial staggered terms), and authorizes per diem payments for commissioners serving without compensation, as specified in 25 U.S. Code § 305.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-1886-2024-literary-artistic-works",
      "dmca-safe-harbor",
      "copyright-fair-use-us",
      "iptc-photo-metadata",
      "exif-standard-metadata"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-pslra-1995-private-securities-litigation-reform-pl-104-67",
    "title": "US Private Securities Litigation Reform Act of 1995 (Public Law 104-67) - Pleading Standards and Safe Harbor for Forward-Looking Statements",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Private Securities Litigation Reform Act of 1995 amended the Securities Act of 1933 and the Securities Exchange Act of 1934 to impose heightened pleading requirements in private securities fraud actions including a particularised facts pleading standard for scienter, mandate appointment of the most adequate plaintiff as lead plaintiff, stay discovery pending decision on a motion to dismiss, create a safe harbor for forward-looking statements accompanied by meaningful cautionary language, limit recoverable damages to actual loss caused by the misstatement, impose proportionate liability for non-knowing defendants, and require auditor obligations to detect and report illegal acts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-securities-act-1933",
      "us-securities-exchange-act-1934",
      "us-sarbanes-oxley-act"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-public-health-service-act",
    "title": "US Public Health Service Act (42 USC ch 6A): Federal Public Health Authority, Emergencies and Quarantine",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Public Health Service Act (42 U.S.C. ch. 6A) is the principal federal statute organizing the US public health system and conferring the core public-health powers of the federal government, administered by the Department of Health and Human Services, including the Centers for Disease Control and Prevention. Section 201 supplies the definitions used throughout the Act. Section 202 provides for the Surgeon General and section 203 for the organization of the Public Health Service. Section 241 grants broad authority to conduct and support research, investigations, experiments and demonstrations relating to the causes, diagnosis, treatment, control and prevention of disease. Section 243 provides for cooperation with the States in the prevention and suppression of communicable and other diseases. Section 247d authorizes the Secretary to declare a public health emergency and to take responsive action, including making grants and deploying personnel. Section 264 confers the authority to make and enforce regulations necessary to prevent the introduction, transmission or spread of communicable diseases, including the apprehension and examination of individuals (the federal quarantine power), and section 266 provides special quarantine powers in time of war. The Act is the legal foundation of US federal public-health administration, communicable-disease control and emergency response.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-public-utility-regulatory-policies-act",
    "title": "US Public Utility Regulatory Policies Act (PURPA, 16 USC ch 46): Retail Ratemaking Standards and Utility Reform",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Public Utility Regulatory Policies Act of 1978 (PURPA, 16 U.S.C. ch. 46) reformed the regulation of electric and gas utilities to promote energy conservation, efficient use of facilities, and equitable rates, working through state regulatory authorities with oversight by the Federal Energy Regulatory Commission. Section 2601 sets the findings and section 2602 the definitions. Section 2611 states the purposes of the retail regulatory policies, and section 2612 sets their coverage. Subchapter II requires state regulatory authorities and nonregulated utilities to consider and determine federal ratemaking standards: section 2621 requires the consideration and determination of standards such as cost-of-service rates, declining-block rate prohibitions, time-of-day rates, and interruptible rates; section 2623 governs the adoption of certain standards; section 2624 addresses lifeline rates; and section 2625 sets special rules for the standards. Section 2627 preserves more protective state law. Subchapter III provides procedural protections: section 2631 allows intervention in proceedings, section 2632 provides for consumer representation, and section 2633 provides for judicial review and enforcement. PURPA is also the statutory origin of the obligation of utilities to purchase from qualifying cogeneration and small power production facilities, implemented through the Federal Power Act. The Act is a legal foundation of US retail electricity ratemaking reform and the early framework for independent power generation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-puhca-2005-utility-holding-company",
    "title": "Public Utility Holding Company Act of 2005 (PUHCA 2005)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Public Utility Holding Company Act of 2005 grants the Federal Energy Regulatory Commission (FERC) and state utility commissions access to the books and records of holding companies and their affiliates to protect ratepayers. This authority, under Section 1264 of the Energy Policy Act of 2005, ensures that costs from non-utility activities are not improperly allocated to regulated utility customers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-purpa-1978-qualifying-facility-rules",
    "title": "US Public Utility Regulatory Policies Act 1978 (PURPA) - Qualifying Facility Status, Mandatory Purchase Obligations and Avoided Cost Pricing",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The Public Utility Regulatory Policies Act of 1978 (PURPA) requires electric utilities to purchase power from and sell supplementary power to certified Qualifying Facilities (QFs) at rates based on the utility's 'avoided cost', as mandated by Section 210 of the Act, to encourage development of cogeneration and small power production.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 9
  },
  {
    "node_id": "us-quantum-computing-cybersecurity-preparedness-2022",
    "title": "Quantum Computing Cybersecurity Preparedness Act of 2022",
    "domain": "Aviation, Defense & Quantum",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "Requires all federal agencies to inventory cryptographic systems vulnerable to quantum computing attacks, develop a migration plan to NIST Post-Quantum Cryptography (PQC) standards, and submit annual progress reports to the Office of Management and Budget (OMB) with prioritization of high-value assets and associated budget planning. Key requirement under Section 3(a).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-800-171-cui",
      "cmmc-2-audit",
      "us-fedramp-authorization-moderate",
      "guide-developing-security-plans-federal-systems"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-railway-labor-act",
    "title": "US Railway Labor Act (45 USC ch 8): Rail and Air Carrier Labor Relations",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Railway Labor Act (45 U.S.C. ch. 8) governs labor relations in the rail and airline industries, administered by the National Mediation Board and, for minor disputes in rail, the National Railroad Adjustment Board. Section 151a sets out the general purposes, including avoiding interruption to commerce, protecting the right of employees to organize, and providing for the prompt settlement of disputes. Section 152 sets the general duties: carriers and employees must exert every reasonable effort to make and maintain agreements concerning rates of pay, rules and working conditions and to settle disputes; neither party may interfere with, influence or coerce the other in the choice of representatives; and the majority of any craft or class has the right to determine the representative for collective bargaining. Section 156 sets the procedure for changing rates of pay, rules and working conditions, the major dispute process that requires notice and maintenance of the status quo during negotiation and mediation. Section 153 establishes the Adjustment Board for the resolution of minor disputes over the interpretation of agreements, and section 155 provides for mediation. Section 160 allows the President to create an emergency board where a dispute threatens to substantially interrupt interstate commerce. The Act is the legal foundation for US rail and airline collective bargaining and dispute resolution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-rcra-solid-waste",
    "title": "US Resource Conservation and Recovery Act (RCRA, 42 USC ch 82): Cradle-to-Grave Hazardous Waste Management",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Solid Waste Disposal Act, as amended by the Resource Conservation and Recovery Act (RCRA), codified at 42 U.S.C. Chapter 82 (sections 6901-6992k), governs the management of solid and hazardous waste from generation to final disposal and is administered by the US Environmental Protection Agency (EPA), often through authorized State programs. Section 6903 defines the regulated terms, including 'solid waste' and 'hazardous waste'. Subchapter III establishes the cradle-to-grave hazardous waste program: section 6921 directs EPA to identify the characteristics of, and to list, hazardous wastes; section 6922 sets standards applicable to generators (including the manifest, recordkeeping and labeling requirements); section 6923 sets standards for transporters; and section 6924 sets standards for owners and operators of hazardous waste treatment, storage and disposal facilities (TSDFs), including the land disposal restrictions and corrective action. Section 6925 requires a permit for the treatment, storage or disposal of hazardous waste. Section 6926 authorizes EPA to approve State programs to operate in lieu of the federal program, and section 6927 confers inspection authority. Section 6928 provides for federal enforcement: a person who violates any requirement of the subchapter is liable for a civil penalty of not more than $25,000 for each violation, and each day of a continuing violation is a separate violation; a person who knowingly transports, treats, stores or disposes of hazardous waste without a permit or in knowing violation of the requirements is, on conviction, subject to a fine of not more than $50,000 for each day of violation, or imprisonment of not more than two years (five years for the most serious paragraphs), or both; and a person who knowingly places another in imminent danger of death or serious bodily injury (knowing endangerment) is subject to a fine of not more than $250,000 or imprisonment of not more than fifteen years, or both, and an organization to a fine of not more than $1,000,000. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-rcra-solid-waste-management-utilities",
    "title": "Resource Conservation and Recovery Act (RCRA) - Hazardous and Solid Waste Management Obligations for Power Generation and Utility Facilities",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Resource Conservation and Recovery Act (RCRA) Subtitle C establishes a comprehensive 'cradle-to-grave' federal regulatory program for managing hazardous waste, requiring power generation and utility facilities to identify, track, and safely treat, store, and dispose of such wastes as defined in 40 CFR Parts 260-273.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-reporting-2018",
      "ifrs-s2-climate-related-disclosures"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-real-estate-settlement-procedures-act",
    "title": "US Real Estate Settlement Procedures Act (12 USC ch 27): Settlement Disclosures and Kickback Prohibition",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Real Estate Settlement Procedures Act (12 U.S.C. ch. 27) governs the settlement process for federally related mortgage loans, requiring disclosure of settlement costs and prohibiting practices that increase those costs, administered by the Consumer Financial Protection Bureau. Section 2603 requires a uniform settlement statement that itemizes the charges imposed on the borrower and the seller, and section 2604 requires a special information booklet and a good faith estimate of settlement charges. Section 2605 governs the servicing of mortgage loans and the administration of escrow accounts, including notices on the transfer of servicing. Section 2607 prohibits kickbacks and unearned fees: no person may give or accept any fee, kickback or thing of value pursuant to an agreement to refer settlement service business involving a federally related mortgage loan, and no person may split a charge for settlement services other than for services actually performed. A violation of section 2607 is punishable by a fine of not more than 10,000 dollars or imprisonment for not more than 1 year, or both, and exposes the violator to civil liability for three times the amount of the charge. Section 2609 limits the amounts a lender may require to be placed in escrow. The Act is the legal foundation for US mortgage settlement transparency.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-real-id-act-2005-pl-109-13",
    "title": "REAL ID Act 2005 - Public Law 109-13",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The REAL ID Act of 2005 (Public Law 109-13 Division B, enacted 11 May 2005) established federal minimum security standards for state-issued driver's licences and identification cards required for federal purposes including boarding commercial aircraft, accessing federal facilities, and entering nuclear power plants. The Act prohibits federal agencies from accepting non-compliant licences for these purposes after the enforcement deadline (currently 7 May 2025 after multiple extensions). Section 202 sets out the minimum issuance standards including verification of identity source documents, lawful presence verification, mandatory machine-readable zones and physical security features, mandatory state-to-state information sharing through the AAMVA system, and 10-year record retention. Section 203 imposes additional standards on Enhanced Driver's Licences. Section 204 establishes the DHS authority to administer the program. Section 205 codifies that the Act does not establish a national identification card. Section 207 imposes asylum-related amendments. Section 215 modifies the immigration and asylum framework. The REAL ID framework operates alongside Enhanced Driver's Licences (EDL) for land/sea border crossings, TSA PreCheck, and Trusted Traveler Programs (Global Entry, NEXUS, SENTRI). State implementation has been phased through DHS REAL ID Modernization Act of 2020 amendments enabling mobile driver's licence (mDL) compliance pathways.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-privacy-act-1974"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-reg-e-electronic-funds-transfer",
    "title": "Regulation E: Electronic Fund Transfers (12 CFR Part 1005)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "Regulation E, implementing the Electronic Fund Transfer Act (EFTA), establishes the rights, liabilities, and responsibilities of consumers and financial institutions in electronic fund transfers (EFTs). It mandates specific disclosures, error resolution procedures, and limits consumer liability for unauthorized transfers as detailed in § 1005.6 and § 1005.11.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "interagency-guidance-third-party-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-regulation-d-private-placement",
    "title": "US Regulation D - Private Placement Securities Exemptions (Rules 504, 506(b), 506(c))",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Regulation D (17 CFR §§230.501-230.508) provides three safe-harbour exemptions from Securities Act registration for private capital raises: Rule 504 (up to $10M from any investors in 12 months), Rule 506(b) (unlimited capital from up to 35 non-accredited and unlimited accredited investors, no general solicitation), and Rule 506(c) (unlimited capital from verified accredited investors only, general solicitation permitted). A Form D must be filed within 15 days of first sale. Accredited investor status is defined in Rule 501(a) - primarily by net worth ($1M excluding primary residence) or income ($200K individual/$300K joint).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-investment-advisers-act-1940",
      "us-investment-company-act-1940",
      "us-bank-secrecy-act-31-cfr-1010-aml"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-regulatory-flexibility-act-5-usc-ch6",
    "title": "United States Regulatory Flexibility Act (Title 5 USC Chapter 6): Definitions of Small Entity, Regulatory Agenda, Initial and Final Regulatory Flexibility Analyses, Periodic Review, and Judicial Review",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Regulatory Flexibility Act, codified at Title 5 of the United States Code, Part I, Chapter 6 (titled Analysis of Regulatory Functions), is the principal federal statute requiring federal agencies to consider the impact of their regulations on small entities and is administered with oversight from the Chief Counsel for Advocacy of the Small Business Administration. Regulatory Flexibility Act, 5 U.S.C. 601 contains the definitions including agency, rule, small business, small organization, small governmental jurisdiction, small entity, and collection of information. Regulatory Flexibility Act, 5 U.S.C. 602 requires each agency to publish in the Federal Register a regulatory agenda twice a year describing planned rulemakings that are likely to have a significant economic impact on a substantial number of small entities. Regulatory Flexibility Act, 5 U.S.C. 603 requires an initial regulatory flexibility analysis whenever an agency publishes a proposed rule under section 553(b) of the Administrative Procedure Act that is likely to have a significant economic impact on a substantial number of small entities. Regulatory Flexibility Act, 5 U.S.C. 604 requires a final regulatory flexibility analysis when the agency promulgates the final rule. Regulatory Flexibility Act, 5 U.S.C. 605 governs the avoidance of duplicative or unnecessary analyses, including by certification that the rule will not have a significant economic impact on a substantial number of small entities. Regulatory Flexibility Act, 5 U.S.C. 606 governs the effect on other law. Regulatory Flexibility Act, 5 U.S.C. 608 provides procedures for waiver or delay of completion. Regulatory Flexibility Act, 5 U.S.C. 609 provides procedures for gathering comments from small entities. Regulatory Flexibility Act, 5 U.S.C. 610 requires periodic review of rules within ten years of promulgation. Regulatory Flexibility Act, 5 U.S.C. 611 provides for judicial review. The Act, together with the Small Business Regulatory Enforcement Fairness Act, is the controlling federal instrument for small entity impact analysis in federal rulemaking.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-rehabilitation-act-section-504",
    "title": "US Rehabilitation Act Section 504 (29 USC 794): Disability Nondiscrimination in Federally Funded Programs",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Rehabilitation Act of 1973 prohibits disability discrimination by the Federal Government, its contractors and recipients of Federal financial assistance, with Section 504 (29 U.S.C. 794) as its central nondiscrimination mandate. Section 794 provides that no otherwise qualified individual with a disability shall, solely by reason of disability, be excluded from participation in, be denied the benefits of, or be subjected to discrimination under any program or activity receiving Federal financial assistance or conducted by an Executive agency or the United States Postal Service. The standards used to determine an employment violation under Section 504 are the standards of the Americans with Disabilities Act. Section 791 governs the employment of individuals with disabilities by Federal agencies and requires affirmative action. Section 793 requires Federal contractors and subcontractors above a contract threshold to take affirmative action to employ and advance qualified individuals with disabilities. Section 794a provides the remedies and attorney fees, incorporating the remedies of Title VI of the Civil Rights Act of 1964 for Section 504 and of Title VII for Federal employment under section 791. Recipients must provide reasonable accommodation and program and physical accessibility. The Act is the legal foundation for US disability nondiscrimination in federally funded education, healthcare and other programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-reit-rules-irs-revenue-procedures",
    "title": "Real Estate Investment Trust (REIT) Qualification and Taxation Rules under 26 U.S. Code §§ 856-859 and associated IRS Revenue Procedures",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "To qualify for pass-through tax treatment, a Real Estate Investment Trust (REIT) must satisfy strict organizational, asset, income, and distribution requirements, including holding at least 75% of its assets in real estate, deriving at least 75% of its gross income from real property, and distributing at least 90% of its taxable income to shareholders annually, as mandated by 26 U.S.C. § 856.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-resource-conservation-and-recovery-act",
    "title": "US Resource Conservation and Recovery Act (42 USC ch 82): Hazardous Waste Management and Enforcement",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Resource Conservation and Recovery Act, codifying the Solid Waste Disposal Act (42 U.S.C. ch. 82), is the principal US statute governing the management of solid and hazardous waste from generation to disposal, administered by the Environmental Protection Agency with authorized State programs. Section 6921 requires the Administrator to identify and list hazardous waste. Section 6922 sets standards for generators, section 6923 for transporters, and section 6924 for owners and operators of treatment, storage and disposal facilities. Section 6925 requires a permit to treat, store or dispose of hazardous waste, and section 6926 authorizes State hazardous waste programs in lieu of the Federal program. Section 6928 is the federal enforcement section: it authorizes civil penalties of not more than 25,000 dollars for each violation and for each day of continued noncompliance; knowing violations carry a fine of not more than 50,000 dollars for each day of violation and imprisonment of up to 2 years, or up to 5 years for certain violations; and knowing endangerment - placing another in imminent danger of death or serious bodily injury - is punishable by a fine of not more than 250,000 dollars or imprisonment for not more than 15 years for an individual, and a fine of not more than 1,000,000 dollars for an organization. The Act is the legal foundation for US cradle-to-grave hazardous waste compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-respa-real-estate-settlement-procedures",
    "title": "Real Estate Settlement Procedures Act (RESPA) and TILA-RESPA Integrated Disclosure (TRID) Rule",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Real Estate Settlement Procedures Act (RESPA), through its implementing Regulation X and the TILA-RESPA Integrated Disclosure (TRID) rule, requires mortgage lenders and servicers to provide borrowers with standardized disclosures about settlement costs, prohibiting kickbacks and referral fees. Key requirements under 12 CFR § 1026.19 include providing a Loan Estimate (LE) within three business days of application and a Closing Disclosure (CD) at least three business days before consummation to help consumers understand and compare loan terms.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sec-regulation-s-p-safeguarding"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-rhode-island-dtppa-2024",
    "title": "Rhode Island Data Transparency and Privacy Protection Act (DTPPA) 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Rhode Island Data Transparency and Privacy Protection Act (DTPPA) was signed by Governor Daniel McKee on 29 June 2024, effective 1 January 2026. The DTPPA establishes consumer data privacy rights and controller obligations for businesses processing personal data of Rhode Island residents. The DTPPA applies to persons who conduct business in Rhode Island or produce products or services targeted to Rhode Island residents and who during a calendar year either control or process personal data of at least 35,000 consumers (excluding data processed solely for completing a payment transaction), or control or process personal data of at least 10,000 consumers and derive more than 20% of gross revenue from the sale of personal data. The DTPPA grants Rhode Island consumers the right to access, correct, delete, and obtain a portable copy of their personal data. Consumers also have the right to opt out of the processing of their personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of solely automated decisions with legal or similarly significant effects. Controllers must provide a privacy notice, obtain consent before processing sensitive data, conduct data protection assessments for high-risk processing, implement reasonable security measures, and enter into data processing agreements with processors. Controllers who obtain personal data from a data broker must conduct due diligence to verify that the data was obtained lawfully. The Rhode Island Attorney General has enforcement authority. There is no private right of action under the DTPPA. Controllers have a 60-day cure period following notice of a potential violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-rhode-island-dtppa-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-ri-dtppa-2024",
    "title": "Rhode Island Data Transparency and Privacy Protection Act 2024 (HB 7787)",
    "domain": "Cybersecurity",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Rhode Island HB 7787, which became law on June 29, 2024 (taking effect without the Governor's signature) with an effective date of January 1, 2026, grants consumers rights to access, correct, delete, and port personal data, requires opt-in consent for sensitive data, prohibits data processing beyond the stated purpose, and provides a 60-day cure period with civil penalties up to USD 10,000 per violation enforced exclusively by the Attorney General.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ri-dtppa-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-rico-organized-crime-control-act-18-usc-1961",
    "title": "RICO Organized Crime Control Act - 18 USC 1961 Racketeer Influenced and Corrupt Organizations Definitions",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 1961 of title 18 of the United States Code provides the definitional core of the Racketeer Influenced and Corrupt Organizations Act, enacted as Title IX of the Organized Crime Control Act of 1970 (Public Law 91-452). The section defines racketeering activity to include a comprehensive list of state-level felonies (murder, kidnapping, gambling, arson, robbery, bribery, extortion, dealing in obscene matter, dealing in controlled substances) chargeable under state law and punishable by more than one year imprisonment, and an extensive list of federal felonies (mail fraud, wire fraud, money laundering, securities fraud, financial institution fraud, computer fraud, immigration fraud, trafficking in counterfeit goods, copyright infringement, embezzlement of pension or welfare fund assets, and many others). The section defines an enterprise to include any individual, partnership, corporation, association, or other legal entity, and any union or group of individuals associated in fact although not a legal entity. A pattern of racketeering activity requires at least two acts of racketeering activity, one of which occurred after the effective date of the statute, with the last occurring within ten years of a prior act, excluding intervening imprisonment. Sections 1962 (prohibited activities), 1963 (criminal penalties), and 1964 (civil remedies including treble damages and attorney fees) form the operative provisions. RICO is the principal federal statute reaching organised cybercrime, AI-enabled racketeering, transnational fraud rings, and corrupt institutional behaviour where a pattern of predicates can be traced through an enterprise.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-wire-fraud-18-usc-1343",
      "us-mail-fraud-18-usc-1341",
      "us-money-laundering-control-act-18-usc-1956",
      "us-hobbs-act-18-usc-1951"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-riegle-neal-interstate-banking-act-12-usc-1831u",
    "title": "Riegle-Neal Interstate Banking and Branching Efficiency Act 1994 - 12 USC 1831u Interstate Bank Mergers",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 1831u of title 12 of the United States Code, enacted as part of the Riegle-Neal Interstate Banking and Branching Efficiency Act of 1994 (Public Law 103-328), authorises the appropriate federal banking agencies to approve interstate merger transactions between insured banks from different home states beginning 1 June 1997, without regard to state law prohibitions that pre-existed the Act. The statute imposes federal concentration limits prohibiting any approval where the resulting institution would control more than 10 percent of total US insured-deposit balances nationally, or 30 percent or more of insured-deposit balances within any single state in which both merging banks operated immediately before the merger, subject to specific state-law variations. Section 1831u also defines the host-state community reinvestment, consumer protection, and fair lending obligations that follow the resulting bank's interstate branches, and preserves state authority to impose non-discriminatory conditions, age requirements, and filing fees on those branches. The interstate banking framework instituted by Riegle-Neal underpins the modern US banking-merger review process at the OCC, the FDIC, and the Federal Reserve Board, and remains the controlling federal statute for cross-state branch retention, branch expansion, and antitrust deposit-cap calculations in every interstate bank acquisition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-holding-company-act",
      "us-community-reinvestment-act",
      "us-federal-deposit-insurance-act"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-right-to-financial-privacy-act",
    "title": "US Right to Financial Privacy Act (12 USC ch 35): Government Access to Financial Records",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Right to Financial Privacy Act (12 U.S.C. ch. 35) limits the access of Federal Government authorities to the financial records of customers held by financial institutions and requires notice to the customer, enforced through a private right of action. Section 3401 provides the definitions, including financial institution, financial record and Government authority. Section 3402 sets the core prohibition: a Government authority may not have access to, or obtain copies of, the information contained in the financial records of any customer from a financial institution unless the records are reasonably described and access is obtained by one of five means, namely the customer authorizes access, the records are disclosed in response to an administrative subpoena or summons, a search warrant, a judicial subpoena, or a formal written request that meets the requirements of the Act. Section 3403 provides that a financial institution shall maintain the confidentiality of records and limits voluntary disclosure. Sections 3405, 3406, 3407 and 3408 set the specific procedures and customer notice requirements for administrative subpoenas, search warrants, judicial subpoenas and formal written requests. Section 3409 provides for delayed notice in defined circumstances, and section 3417 provides civil penalties and damages against a Government authority or financial institution that violates the Act. The Act is the legal foundation for US procedural protection of bank customer records from Government access.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-rivers-and-harbors-act",
    "title": "US Rivers and Harbors Act of 1899 (33 USC ch 9): Navigable Waters, Corps Permits and the Refuse Act",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Rivers and Harbors Appropriation Act of 1899, codified at 33 U.S.C. Chapter 9 (sections 401 et seq.), is the foundational US statute protecting the navigable capacity of the waters of the United States and is administered by the US Army Corps of Engineers. Section 401 requires the consent of Congress and the approval of plans by the Chief of Engineers and the Secretary of the Army before constructing any bridge, dam, dike or causeway over or in navigable waters. Section 403 (the historic Section 10) provides that the creation of any obstruction not affirmatively authorized by Congress to the navigable capacity of any of the waters of the United States is prohibited, and that it is unlawful to build any wharf, pier, breakwater, bulkhead, jetty or other structure, or to excavate or fill or in any manner alter the course, location, condition or capacity of any navigable water, except on plans recommended by the Chief of Engineers and authorized by the Secretary of the Army. Section 406 sets the penalty for violating section 403 and authorizes the removal of unauthorized structures. Section 407 (the historic Section 13, popularly known as the Refuse Act) makes it unlawful to throw, discharge or deposit any refuse matter of any kind (other than that flowing from streets and sewers in a liquid state) into any navigable water of the United States, or onto its banks where it may be washed into such water, except under a permit. Section 411 sets the penalty for the wrongful deposit of refuse and related offenses: a violation is punishable by a fine of up to $25,000 per day, or by imprisonment (in the case of a natural person) for not less than thirty days nor more than one year, or both. Section 409 addresses obstruction by, and the duty to remove, sunken vessels, and section 413 provides for enforcement. Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-rivers-harbors-act-1899-section-10",
    "title": "US Rivers and Harbors Appropriation Act 1899 Section 10 - Army Corps of Engineers Permit for Obstruction or Alteration of Navigable Waters",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Rivers and Harbors Appropriation Act of 1899 (33 USC 401-467, enacted 3 March 1899, 30 Stat. 1151) is the oldest federal environmental law in the United States and remains the principal statute governing physical alteration of navigable waters. Section 10 (33 USC 403) prohibits the creation of any obstruction not affirmatively authorised by Congress to the navigable capacity of any waters of the United States, and prohibits the building of any wharf, pier, dolphin, boom, weir, breakwater, bulkhead, jetty, or other structure in any port, roadstead, haven, harbor, canal, navigable river, or other water of the United States, or any excavation or fill, without authorisation from the Secretary of the Army acting through the US Army Corps of Engineers (USACE). Section 13 (33 USC 407, the Refuse Act) further prohibits discharge of refuse matter into navigable waters. Permits are administered by USACE district offices via Nationwide Permits (NWP), Regional General Permits (RGP) or Individual Permits (IP). Criminal penalties under Section 12 (33 USC 406) include fines up to USD 25,000/day and imprisonment up to one year for misdemeanour violations. Section 10 remains operative for navigable-in-fact waters even where post-Sackett WOTUS jurisdiction under the Clean Water Act has narrowed.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-robinson-patman-act-1936-15-usc-13",
    "title": "US Robinson-Patman Act of 1936 (15 USC 13) - Price Discrimination Prohibition",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Robinson-Patman Act of 1936 amended Section 2 of the Clayton Act to prohibit sellers from discriminating in price between different purchasers of commodities of like grade and quality where the effect may be to substantially lessen competition or to create a monopoly, and prohibited the receipt of a knowingly induced discriminatory price, the payment of brokerage fees to a buyer or its agent, and the provision of promotional allowances or services on terms not proportionally available to all competing customers, with defenses available for cost justification, meeting competition, and changing market conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clayton-act",
      "us-federal-trade-commission-act",
      "us-ftc-robinson-patman-price-discrimination"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-rural-electrification-act",
    "title": "US Rural Electrification Act of 1936 (7 USC ch 31): Rural Electric and Telephone Loan Authority",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Rural Electrification Act of 1936 (7 U.S.C. ch. 31, sections 901 to 950bb) authorizes federal lending to furnish and improve electric and telephone service in rural areas, administered by the Secretary of Agriculture through the Rural Utilities Service. Section 901 sets the short title and section 902 provides the general authority of the Secretary of Agriculture to make loans for rural electrification. Section 904 authorizes loans for the purpose of financing the construction and operation of generating plants, electric transmission and distribution lines or systems for the furnishing and improving of electric service to persons in rural areas, and section 913 sets the definitions, including that the term Secretary means the Secretary of Agriculture. Subchapter II governs rural telephone service: section 921 declares the policy of Congress that adequate telephone service be made generally available in rural areas through the improvement and expansion of existing telephone facilities, section 922 authorizes loans for the improvement, expansion, construction, acquisition, and operation of telephone lines, facilities, or systems to furnish and improve telephone service in rural areas, and section 924 defines telephone service and rural area. Section 917 provides that assistance may not be conditioned on the acceptance of electric service from a particular utility, and section 918 provides that the Secretary may not deny a loan based on the borrower's general fund levels. Section 931 establishes the Rural Electrification and Telephone Revolving Fund. The Act is the federal rural utility lending regime.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-safe-drinking-water-act",
    "title": "US Safe Drinking Water Act: NPDWRs, Public Water Systems, Underground Injection Control and Enforcement",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Safe Drinking Water Act (SDWA), codified at 42 U.S.C. Chapter 6A, subchapter XII (sections 300f-300j-27), is the principal US statute protecting the quality of drinking water supplied by public water systems and protecting underground sources of drinking water, administered by the US Environmental Protection Agency (EPA) with primary enforcement responsibility (primacy) delegated to approved states. Section 300f supplies the definitions, including 'public water system', 'contaminant', 'maximum contaminant level' (MCL) and 'primary drinking water regulation'. Section 300g-1 directs the Administrator to identify contaminants that may have an adverse effect on health and occur in public water systems at a frequency of public-health concern, and to set a maximum contaminant level goal (MCLG) and a national primary drinking water regulation (NPDWR) for each: the MCL must be set as close to the MCLG as is feasible using the best available technology and treatment techniques (taking cost into consideration), or, where measuring the contaminant level is not economically or technologically feasible, a required treatment technique may be prescribed in lieu of an MCL. Section 300g-2 provides for state primary enforcement responsibility, and section 300g-3 sets out federal enforcement, including notice of violation, administrative orders and civil actions. Sections 300h to 300h-8 establish the Underground Injection Control (UIC) program to prevent endangerment of underground sources of drinking water through well injection. Section 300i confers emergency powers where a contaminant presents an imminent and substantial endangerment to health, and section 300i-1 makes it a criminal offence to tamper, attempt to tamper, or threaten to tamper with a public water system. Section 300j-4 confers records, reporting, monitoring and inspection authority, and public water systems must give public notification of violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-safe-drinking-water-act-42-usc-300f-sdwa",
    "title": "US Safe Drinking Water Act - 42 U.S.C. § 300f - National Primary Drinking Water Regulations",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The Safe Drinking Water Act (42 U.S.C. §§ 300f-300j-26) authorizes EPA to set National Primary Drinking Water Regulations (NPDWRs) for public water systems serving 25 or more persons. EPA has set Maximum Contaminant Levels (MCLs) and treatment techniques for 90+ contaminants at 40 CFR Parts 141-143. AI-based water quality prediction, lead service line detection, PFAS monitoring, and digital twin water distribution systems must operate within SDWA regulatory framework. The 2024 PFAS rule (40 CFR 141.803) established MCLs of 4 ppt for PFOA and PFOS - first new MCLs in 20+ years - directly affecting AI contamination prediction models.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standards",
        "frameworks",
        "regulations",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-epa-clean-water-act-section-402-npdes"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sarbanes-oxley-act",
    "title": "US Sarbanes-Oxley Act (15 USC ch 98): Corporate Responsibility, Internal Controls and Audit Oversight",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Sarbanes-Oxley Act of 2002 (15 U.S.C. ch. 98) reformed the governance, financial reporting and audit of US public companies, administered by the Securities and Exchange Commission with the Public Company Accounting Oversight Board. Section 7211 establishes the Public Company Accounting Oversight Board to oversee the audits of public companies, and section 7213 directs the Board to set auditing, quality control and ethics standards. Sections 7231 and 7232 address auditor independence, including restrictions on non-audit services and audit partner rotation. Section 7241 requires the principal executive officer and principal financial officer to certify, in each annual and quarterly report, that they have reviewed the report, that it contains no material misstatement or omission, that the financial statements fairly present the financial condition, and that they have established and evaluated internal controls and disclosed deficiencies and fraud. Section 7262 requires management to assess and report on the effectiveness of internal control over financial reporting, with auditor attestation. Section 7245 authorizes officer and director bars. The criminal certification requirement, codified at 18 U.S.C. 1350, imposes fines and imprisonment for a knowing or willful false certification. The Act is the legal foundation for US public company internal controls and audit oversight.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-sarbanes-oxley-section-302-404",
    "title": "US Sarbanes-Oxley Act Sections 302 and 404 - Corporate Responsibility for Financial Reports and Internal Controls",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Sarbanes-Oxley Act (SOX) requires principal officers (typically CEO and CFO) of public companies to personally certify the accuracy of financial reports and the effectiveness of disclosure controls (Section 302), and mandates that management and the external auditor report on the adequacy of the company's internal control over financial reporting (ICFR) (Section 404).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-corporate-governance-principles",
      "principles-effective-risk-data-aggregation",
      "soc2-processing-integrity"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-satellite-home-viewer-extension-reauthorization",
    "title": "Limitations on exclusive rights: Secondary transmissions of distant television programming by satellite",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes a statutory license for satellite carriers to retransmit distant television signals for private home or commercial viewing, subject to compliance with FCC rules, royalty payments, and subscriber reporting. Key restrictions apply under § 119(2)(B) for unserved households and § 119(5) for territorial eligibility violations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dmca-safe-harbor",
      "copyright-fair-use-us",
      "eu-copyright-directive-art-17"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-sec-17-cfr-210-regulation-sx-financial-statements",
    "title": "17 CFR Part 210 - Regulation S-X: Form and Content of and Requirements for Financial Statements (SEC)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "SEC 17 CFR Part 210 (Regulation S-X) governs the form and content of and requirements for financial statements filed under the federal securities laws, requiring that financial statements be examined by qualified, independent accountants whose reports and audit-committee communications meet the rules, that consolidated balance sheets, statements of comprehensive income and cash flows, and changes in equity be presented, that financial statements of acquired businesses be provided, that the age of financial statements be observed, that form, terminology, and general notes be followed, and that the smaller reporting company, interim, and pro forma presentation requirements be met.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-securities-exchange-act-1934",
      "us-securities-act-1933"
    ],
    "primary_citations_count": 18
  },
  {
    "node_id": "us-sec-17-cfr-229-regulation-s-k",
    "title": "17 CFR Part 229 - Regulation S-K (Standard Instructions for Filing Forms Under the Securities Acts)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "SEC Regulation S-K sets the standard non-financial disclosure items that registrants must provide in registration statements and periodic reports under the Securities Act and the Securities Exchange Act, covering description of business, property, legal proceedings, mine safety, risk factors, cybersecurity, market price and dividends, management discussion and analysis, and quantitative and qualitative disclosures about market risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sec-17-cfr-240-securities-exchange-act-rules"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-sec-17-cfr-230-securities-act-rules-reg-d-reg-s-reg-a",
    "title": "US SEC Securities Act Rules - 17 CFR Part 230 Registration Exemptions Including Regulation D (Private Placements), Regulation S (Offshore Offerings) and Regulation A+ (Tier 1 and Tier 2)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "17 CFR Part 230 is the SEC's General Rules and Regulations under the Securities Act of 1933 (15 U.S.C. 77a et seq.). Part 230 contains over 200 sections implementing the registration, exemption, and integrity provisions of the Securities Act. Headline rules include: Rule 144 (§230.144, safe harbor for sales of restricted and control securities by non-affiliates after 6 months/1 year holding period and by affiliates subject to volume and manner-of-sale conditions); Rule 144A (§230.144A, safe harbor for resales to qualified institutional buyers (QIBs)); Regulation D (§§230.500-508) including Rule 504 (small offerings up to USD 10 million annually), Rule 506(b) (unlimited amount, no general solicitation, up to 35 non-accredited investors with sophisticated investor and information requirements), and Rule 506(c) (unlimited amount, general solicitation permitted, all purchasers must be accredited and verified); Regulation S (§§230.901-905) for offerings made outside the United States; Regulation A (§§230.251-263) Reg A+ Tier 1 (up to USD 20 million annually with state coordination) and Tier 2 (up to USD 75 million annually with state preemption and ongoing reporting); Regulation Crowdfunding (§§230.300-303 in cross-reference; primary in 17 CFR Part 227) for offerings up to USD 5 million by issuers using SEC-registered funding portals or broker-dealers. Rule 415 (§230.415) shelf registration. Rule 424 (§230.424) prospectus filings. Rule 12g3-2(b) (§230.12g3-2(b) in cross-reference; primary in 17 CFR §240.12g3-2(b)) exemption for foreign private issuers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sec-17-cfr-232-reg-st-edgar-electronic-filing",
    "title": "US SEC Regulation S-T - 17 CFR Part 232 EDGAR Electronic Filing System General Rules, Inline XBRL Requirements and Form/Submission Type Tagging Obligations",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "17 CFR Part 232 (Regulation S-T) sets the SEC's general rules for electronic filings on the Electronic Data Gathering, Analysis, and Retrieval (EDGAR) system. Part 232 applies to all electronic filers including issuers, broker-dealers, investment companies, investment advisers, third-party filers, and others required to file documents with the SEC under the Securities Act of 1933, the Exchange Act of 1934, the Trust Indenture Act of 1939, the Investment Company Act of 1940, the Investment Advisers Act of 1940, or rules thereunder. Section 232.10 sets applicability. Section 232.11 sets the requirement that all submissions be made electronically through EDGAR except for items granted hardship exemption. Section 232.13 sets the official date of filing as the date the SEC receives the electronic submission. Section 232.15 sets the temporary hardship exemption process. Section 232.101 sets mandatory electronic submission, including specific document types and exhibits. Section 232.201 sets the temporary hardship exemption (Form TH). Section 232.202 sets the continuing hardship exemption application. Section 232.301 sets the EDGAR Filer Manual incorporation by reference; the EDGAR Filer Manual specifies technical preparation, the EDGARLink Online and EDGAR API systems, file formats, character encoding, and headers required for each form type. Section 232.302 sets signature requirements: typed signatures on the electronic submission with manually signed authentication documents retained in the filer's records for 5 years per §232.302(b). Section 232.405 sets the Inline XBRL (iXBRL) requirement for financial statements and certain other disclosures filed in the eXtensible Business Reporting Language using the SEC-published taxonomies. Section 232.406 sets phase-in compliance dates for Inline XBRL by form type and filer category.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sec-17-cfr-240-securities-exchange-act-rules"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sec-17-cfr-240-securities-exchange-act-rules",
    "title": "US SEC Securities Exchange Act Rules - 17 CFR Part 240 Anti-Fraud (Rule 10b-5), Broker-Dealer Net Capital, Recordkeeping (17a-3/17a-4) and Reporting Obligations",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "17 CFR Part 240 is the SEC's General Rules and Regulations under the Securities Exchange Act of 1934 (15 U.S.C. 78a et seq.). Part 240 contains over 500 sections implementing the operational, anti-fraud, market structure, broker-dealer, and reporting provisions of the Exchange Act. Headline rules include: Rule 10b-5 (§240.10b-5, anti-fraud rule prohibiting any device, scheme, or artifice to defraud, any untrue statement of material fact or omission, or any act, practice, or course of business that operates as a fraud or deceit in connection with the purchase or sale of any security); Rule 15c3-1 (§240.15c3-1, broker-dealer net capital rule with the alternative standard and the basic method); Rule 15c3-3 (§240.15c3-3, customer protection rule on physical possession or control of customer securities and reserve computation); Rule 17a-3 (§240.17a-3, records required to be made by broker-dealers); Rule 17a-4 (§240.17a-4, records required to be preserved by broker-dealers including the WORM/Audit Trail format requirements for electronic records); Rule 17a-5 (broker-dealer financial reports including FOCUS Report); Rule 17a-8 (anti-money-laundering recordkeeping); Section 13(d)/(g) beneficial ownership rules (§§240.13d-1 to 240.13d-7); Section 14 proxy rules (§§240.14a-1 et seq.); Section 16 insider reporting (§§240.16a-1 to 240.16a-13); Regulation FD (§§240.100-103) on selective disclosure; Regulation M (§§240.100-105 anti-manipulation in connection with offerings); Regulation SHO (§§240.200-204 short sale rule including locate, close-out, and threshold-list provisions); Form 8-K trigger and content rules (§240.13a-11 cross-reference); insider trading rules (Rule 10b5-1 trading plans and Rule 10b5-2 misappropriation theory).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sec-17-cfr-230-securities-act-rules-reg-d-reg-s-reg-a"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sec-17-cfr-242-regulations-sho-ats-nms",
    "title": "17 CFR Part 242 - Regulations M, SHO, ATS, AC, NMS, and SBSR; Securities Market Regulation (SEC)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "SEC 17 CFR Part 242 sets the securities market structure rules, requiring short sales to be marked and to meet the circuit breaker, borrowing, delivery, and close-out requirements under Regulation SHO, alternative trading systems to meet the operating, recordkeeping, and record-preservation requirements under Regulation ATS, and market participants to meet the Regulation NMS requirements for transaction and quotation dissemination, display of customer limit orders, order execution and routing disclosure, national market system plans, access to and protection of quotations, minimum pricing increments, and the consolidated audit trail.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sec-17-cfr-240-securities-exchange-act-rules"
    ],
    "primary_citations_count": 20
  },
  {
    "node_id": "us-sec-17-cfr-243-regulation-fd-fair-disclosure",
    "title": "17 CFR Part 243 (Regulation FD) - Fair Disclosure of Material Nonpublic Information",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "Regulation FD (17 CFR Part 243) prohibits the selective disclosure of material nonpublic information by SEC-reporting issuers. Whenever an issuer, or a person acting on its behalf, discloses material nonpublic information regarding the issuer or its securities to certain persons outside the issuer (in particular brokers or dealers, investment advisers, investment companies, and holders of the issuer's securities where it is reasonably foreseeable they will trade on the information), the issuer must make public disclosure of that same information: simultaneously, in the case of an intentional disclosure, and promptly, in the case of a non-intentional disclosure. A disclosure is intentional when the person making it knows, or is reckless in not knowing, that the information is both material and nonpublic; promptly means as soon as reasonably practicable but no later than the later of 24 hours or the commencement of the next day's trading on the New York Stock Exchange after a senior official learns of the non-intentional disclosure. Public disclosure is made by furnishing or filing a Form 8-K, or by another method reasonably designed to provide broad, non-exclusionary distribution to the public. The duty does not apply to disclosures to a person who owes a duty of trust or confidence to the issuer (such as an attorney, investment banker or accountant), to a person who expressly agrees to maintain the information in confidence, or in connection with most registered securities offerings. A failure to make a public disclosure required solely by Regulation FD is not itself a violation of Rule 10b-5 and does not affect the issuer's Exchange Act reporting status or registration-statement eligibility.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "enforcement",
        "scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-securities-exchange-act-1934",
      "us-sec-rule-10b-5-anti-fraud",
      "us-sec-17-cfr-240-securities-exchange-act-rules"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-sec-17-cfr-248-reg-sp-privacy-of-consumer-financial-information",
    "title": "US SEC Regulation S-P - 17 CFR Part 248 Privacy of Consumer Financial Information, Safeguards Rule, Disposal Rule and Customer Notification Obligations for SEC-Regulated Entities",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "17 CFR Part 248 (Regulation S-P) is the SEC's implementation of Title V of the Gramm-Leach-Bliley Act (15 U.S.C. 6801-6809) and the disposal rule under the Fair and Accurate Credit Transactions Act (FACTA, Public Law 108-159). Part 248 applies to broker-dealers (other than notice-registered broker-dealers), investment companies, and investment advisers registered with the SEC. Subpart A (Privacy Rule, §§248.1-30) requires the delivery of initial and annual privacy notices to consumers and customers (§§248.4, 248.5) describing the categories of nonpublic personal information collected and disclosed, the categories of affiliates and nonaffiliated third parties to which the information is disclosed, and the consumer's right to opt out of certain disclosures (§§248.7-9). Section 248.30(a) is the Safeguards Rule requiring policies and procedures to insure the security and confidentiality of customer records and information, protect against anticipated threats or hazards, and protect against unauthorized access. Section 248.30(b) is the Disposal Rule requiring proper disposal of consumer report information. The May 2024 amendments to Regulation S-P (89 FR 47688, effective Aug. 2024 with phased compliance dates of Dec. 3, 2025 for large entities and June 3, 2026 for small entities) added: (1) an incident response program requirement including written incident response procedures; (2) the data breach customer notification rule requiring written notice to affected individuals within 30 days of the firm becoming aware that customer information has been or is reasonably likely to have been accessed or used without authorization; (3) recordkeeping for the incident response program for 6 years; (4) extension of the Safeguards Rule and Disposal Rule to transfer agents registered with the SEC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sec-17-cfr-240-securities-exchange-act-rules"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sec-17-cfr-270-investment-company-act-rules",
    "title": "US SEC Investment Company Act Rules - 17 CFR Part 270 Mutual Fund Pricing, Custody, Liquidity Risk Management and Affiliated Transaction Restrictions",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-17",
    "bluf": "17 CFR Part 270 is the SEC's Rules and Regulations under the Investment Company Act of 1940 (15 U.S.C. 80a-1 et seq.). Part 270 contains the operational, exemptive, and protective rules applicable to registered investment companies (mutual funds, closed-end funds, ETFs, BDCs) and their advisers, custodians, principal underwriters, and affiliated persons. Headline rules include: Rule 2a-4 (§270.2a-4, computation of NAV using forward pricing); Rule 17a-7 (§270.17a-7, exemption for cross-trades between affiliated funds when prices are independently verifiable); Rule 17e-1 (§270.17e-1, transactions with affiliated brokers); Rule 17f-1 (§270.17f-1, custody of securities with members of a national securities exchange); Rule 17f-5 (§270.17f-5, custody of fund securities in foreign jurisdictions); Rule 17f-7 (§270.17f-7, custody of fund securities with a securities depository in a foreign jurisdiction); Rule 18f-4 (§270.18f-4, derivatives transactions including the derivatives risk management program, value-at-risk based limits on leverage risk, and the limited-derivatives-user exception); Rule 22c-1 (§270.22c-1, sale and redemption of redeemable securities at forward NAV next computed after receipt of request); Rule 22e-4 (§270.22e-4, fund liquidity risk management program with the 15% illiquid investments limit and bucketing into highly liquid, moderately liquid, less liquid, and illiquid); Rule 30a-2 and 30a-3 (certifications by principal executive and financial officers under Sarbanes-Oxley); Rule 38a-1 (§270.38a-1, written compliance program, annual review, chief compliance officer reporting to the board); Rule 12d1-4 (§270.12d1-4, exemption for fund-of-funds arrangements). Other Subpart-level rules implement the Subchapter M tax requirements, names-rule (§270.35d-1), and proxy voting disclosure (§270.30b1-4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-sec-17-cfr-240-securities-exchange-act-rules"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sec-17-cfr-275-investment-advisers-act-rules",
    "title": "17 CFR Part 275 - Rules and Regulations under the Investment Advisers Act of 1940",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-24",
    "bluf": "17 CFR Part 275 contains the SEC rules implementing the Investment Advisers Act of 1940 and governs the registration and conduct of investment advisers. To register with the Commission, an adviser must complete and file Form ADV (Part 1A, the Part 2A firm brochure and the Part 3 Form CRS) electronically through the Investment Adviser Registration Depository. Every registered or required-to-be-registered adviser must make and keep true, accurate and current books and records relating to its advisory business. The adviser must establish, maintain and enforce a written code of ethics that reflects its fiduciary obligations, requires compliance with the Federal securities laws, and requires access persons to report their personal securities transactions and holdings. The marketing rule makes it unlawful to disseminate an advertisement containing untrue or unsubstantiated statements or misleading implications. The custody rule provides that having custody of client funds or securities is a fraudulent practice unless a qualified custodian maintains the assets, clients are notified, account statements are sent, and, where applicable, a surprise examination is performed. The pay-to-play rule bars an adviser from providing advisory services for compensation to a government entity for two years after certain political contributions. The compliance rule requires every adviser to adopt and implement written policies and procedures reasonably designed to prevent violations of the Act, to review them at least annually, and to designate a chief compliance officer.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_primary_law",
        "related_instruments",
        "key_rules",
        "enforcement"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-investment-advisers-act-1940",
      "us-sec-17-cfr-240-securities-exchange-act-rules",
      "us-sec-17-cfr-270-investment-company-act-rules"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-sec-cfr-17-part-230-regulation-a-exemption",
    "title": "17 CFR Part 230 - General Rules and Regulations, Securities Act of 1933",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation establishes general rules under the Securities Act of 1933, detailing requirements for definitions, filing fees, communications, and various offering-related notices and publications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-sec-cfr-17-part-240-general-rules-exchange-act",
    "title": "General Rules and Regulations, Securities Exchange Act of 1934 (17 CFR Part 240)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "This regulation establishes the statutory authority for the General Rules and Regulations under the Securities Exchange Act of 1934, requiring compliance with various provisions of U.S. Code.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-sec-cfr-17-part-248-regulation-s-p-privacy",
    "title": "17 CFR Part 248 - Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Personal Information",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-06",
    "bluf": "This regulation requires financial institutions to provide consumers with privacy notices, offer opt-out mechanisms for information sharing, and establish procedures to safeguard customer information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-sec-climate-disclosure-rule-2024",
    "title": "The Enhancement and Standardization of Climate-Related Disclosures for Investors (Release No. 33-11275)",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2024-03-06",
    "bluf": "This SEC final rule mandates that public companies disclose material climate-related risks, governance strategies, and risk management processes in their registration statements and annual reports. As per Item 1505 of Regulation S-K, Large Accelerated Filers (LAFs) and Accelerated Filers (AFs) must also disclose material Scope 1 and/or Scope 2 greenhouse gas (GHG) emissions, with required third-party attestation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "tcfd-climate-risk",
      "issb-ifrs-s2-climate-2023",
      "iso-14064-ghg-reporting"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sec-climate-disclosure-rule-2024-33-11275-scope-1-2-reporting",
    "title": "US SEC Climate Disclosure Rule 2024 (Release 33-11275) - Scope 1, 2 and Material Climate Risk Reporting",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "SEC Release 33-11275 (March 2024) requires public companies to disclose material climate-related risks and their impact on business strategy, financial condition, and governance. Large accelerated filers must disclose Scope 1 and 2 GHG emissions; Scope 3 reporting is not required. Phase-in schedule applies; accelerated filers begin climate risk disclosure in annual reports for fiscal year 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "frameworks",
        "standards",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sec-reg-s-k-106"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-sec-cybersecurity-disclosure-2023",
    "title": "SEC Cybersecurity Risk Management, Strategy, Governance and Incident Disclosure Rules 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2024-07-26",
    "bluf": "Mandates U.S. public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality (Item 1.05) and to annually disclose their cybersecurity risk management, strategy, and governance processes in their Form 10-K (Item 106 of Regulation S-K).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022",
      "sarbannes-oxley-404",
      "nist-800-61-incident-resp",
      "nist-ir-8286a-cybersecurity-risk"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sec-digital-asset-framework",
    "title": "Framework for 'Investment Contract' Analysis of Digital Assets",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This SEC framework provides guidance on applying the Howey Test to determine if a digital asset is an 'investment contract' and thus a security under U.S. law. It applies to issuers and promoters, focusing on whether a purchaser has a reasonable expectation of profits derived from the essential managerial or entrepreneurial efforts of others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fincen-cvc-business-models",
      "gfsr-crypto-financial-stability-challenges"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sec-digital-assets-securities-framework",
    "title": "Framework for 'Investment Contract' Analysis of Digital Assets",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This U.S. SEC staff guidance provides a framework for analyzing whether a digital asset is an investment contract and therefore a security under federal law, applying the four-prong test established in SEC v. W.J. Howey Co. The framework focuses on whether there is an investment of money in a common enterprise with a reasonable expectation of profits to be derived from the efforts of others.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cftc-digital-asset-guidance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sec-regulation-best-interest-2019",
    "title": "US SEC Regulation Best Interest 2019 - Broker-Dealer Standard of Care",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "SEC Regulation Best Interest (Reg BI, 17 CFR §240.15l-1) requires broker-dealers to act in the best interest of retail customers when making investment recommendations, without placing the broker-dealer's financial interests ahead of the customer's. It imposes four component obligations: disclosure (Form CRS), care, conflicts of interest mitigation, and compliance. Reg BI applies from June 30, 2020. It enhances but does not impose a full fiduciary duty - broker-dealers must act in the customer's best interest but may still recommend proprietary products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-investment-firm-regulation-2019-2033",
      "eu-priips-regulation-1286-2014-kid",
      "eu-aifmd-directive-2011-61"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-sec-regulation-best-interest-reg-bi-broker-dealer-conduct-standard",
    "title": "US SEC Regulation Best Interest (Reg BI) - Broker-Dealer Conduct Standard 17 CFR 240.15l-1",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2024-01-01",
    "bluf": "SEC Regulation Best Interest (Reg BI) at 17 CFR 240.15l-1, effective June 30, 2020, establishes a \"best interest\" conduct standard for broker-dealers when recommending securities transactions or investment strategies to retail customers. Reg BI comprises four obligations: Disclosure (Form CRS), Care (recommendation must be in best interest), Conflict of Interest (identify, disclose, mitigate), and Compliance (written policies and procedures). Reg BI applies to all securities product recommendations including crypto securities and complex products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bank-secrecy-act-31-cfr-1010-aml"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-sec-regulation-sp-2024",
    "title": "Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information (2024 Amendment)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This amendment to SEC Regulation S-P mandates that broker-dealers, investment companies, and registered investment advisers establish a comprehensive incident response program to address unauthorized access to customer information, including a requirement under Rule 248.30(a)(4) to notify affected individuals within 30 days of discovering a data breach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "sec-regulation-s-p-safeguarding",
      "interagency-guidance-third-party-risk-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sec-regulation-sp-2024-amendments",
    "title": "SEC Regulation S-P 2024 Amendments - Privacy of Consumer Financial Information and Safeguarding Customer Information",
    "domain": "Cybersecurity",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The SEC's May 2024 amendments to Regulation S-P (17 CFR 248.1 through 248.100) require broker-dealers, investment companies, registered investment advisers, funding portals, and transfer agents (collectively, covered institutions) to adopt written policies and procedures for an incident response program reasonably designed to detect, respond to, and recover from unauthorised access to or use of customer information. The program must include procedures to assess the nature and scope of any incident, contain and control the incident, and notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorisation. Written notice must be clear and conspicuous and provided as soon as practicable, but not later than 30 days, after the institution becomes aware of the incident. The amendments extend the safeguards and disposal rules under 17 CFR Section 248.30 to information handled or maintained by service providers, broaden coverage to include other financial institutions' customer information held by the covered institution, require written records documenting compliance, and conform annual privacy notice delivery to the GLBA statutory exception. The Attorney General may request a delay if notification poses a substantial risk to national security or public safety. The rule is effective 2 August 2024 (Federal Register Vol. 89, FR 2024-11116).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_glba_financial_privacy_1999",
        "us_fcra_fair_credit_reporting_act",
        "ny_dfs_part_500",
        "us_sec_cybersecurity_disclosure_2023",
        "eu_gdpr_breach_notification"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-glba-gramm-leach-bliley-act-1999",
      "us-fair-credit-reporting-act-fcra-1970",
      "us-sec-cybersecurity-disclosure-2023",
      "nydfs-part-500-cybersecurity-v2-2023"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "us-sec-rule-10b-5-anti-fraud",
    "title": "US SEC Rule 10b-5 - Securities Fraud and Anti-Manipulation",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Rule 10b-5 (17 CFR §240.10b-5) under Securities Exchange Act §10(b) is the primary US anti-fraud provision for securities trading. It prohibits any person from employing a scheme to defraud, making materially false or misleading statements, or engaging in manipulative or deceptive acts in connection with any purchase or sale of any security. Private plaintiffs must prove six elements: (1) material misrepresentation/omission, (2) scienter, (3) connection to purchase or sale, (4) reliance, (5) economic loss, (6) loss causation. Insider trading is prosecuted under Rule 10b-5.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-investment-advisers-act-1940",
      "us-investment-company-act-1940",
      "us-volcker-rule"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-sec-rule-15c3-5-market-access-risk-controls",
    "title": "US SEC Rule 15c3-5 - Market Access Rule: Risk Management Controls and Supervisory Procedures for Broker-Dealer Automated Trading Systems",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Every registered broker-dealer with market access to a national securities exchange or ATS, or that provides such access to customers, must establish, document, and maintain a system of risk management controls and supervisory procedures covering financial risk (pre-set credit and capital thresholds, erroneous order rejection) and regulatory risk (pre-order compliance, restricted person controls, post-trade surveillance). Financial controls must remain under the broker-dealer's direct and exclusive control. Annual effectiveness review and CEO certification are mandatory.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-csf-2-0-govern-function"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-section-230-communications-decency-act-47-usc-230",
    "title": "United States Section 230 of the Communications Decency Act of 1996 (47 USC 230): Findings, Policy, Treatment of Publisher or Speaker, Good Samaritan Civil Liability Protection, Obligations of Interactive Computer Service, Effect on Other Laws, and Definitions",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 230 of the Communications Decency Act of 1996, codified at 47 of the United States Code Section 230 within Title V of the Telecommunications Act of 1996, is the principal federal statute providing legal immunity to interactive computer services and platforms for content posted by third parties and for good-faith content moderation decisions, and is the foundational legal framework for the modern United States internet and platform liability regime. Section 230, 47 U.S.C. 230(a) contains the Congressional findings regarding internet development and regulation. Section 230, 47 U.S.C. 230(b) contains the policy promoting internet development and free markets. Section 230, 47 U.S.C. 230(c) sets out the protection for Good Samaritan blocking and screening of offensive material including Section 230, 47 U.S.C. 230(c)(1) on treatment of publisher or speaker providing that no provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider, and Section 230, 47 U.S.C. 230(c)(2) on civil liability providing that no provider or user of an interactive computer service shall be held liable on account of any action voluntarily taken in good faith to restrict access to or availability of material that the provider or user considers to be obscene, lewd, lascivious, filthy, excessively violent, harassing, or otherwise objectionable, whether or not such material is constitutionally protected. Section 230, 47 U.S.C. 230(d) sets out the obligations of interactive computer service regarding parental control notifications. Section 230, 47 U.S.C. 230(e) sets out the effect on other laws including no effect on criminal law, communications privacy law, intellectual property law, state law, and sex trafficking provisions (FOSTA-SESTA amendment). Section 230, 47 U.S.C. 230(f) contains the definitions including interactive computer service, information content provider, and access software provider. The statute is the controlling federal instrument for platform liability for third-party content.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-section-301-trade-act-19-usc-2411",
    "title": "Section 301 of Trade Act 1974 - 19 USC 2411 USTR Unfair Trade Practice Authority",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 2411 of title 19 of the United States Code, section 301 of the Trade Act of 1974 (Public Law 93-618), authorises the United States Trade Representative to take action against foreign government acts, policies, or practices that violate or are inconsistent with US rights under any trade agreement, that deny benefits to the United States under any trade agreement, that are unjustifiable and burden or restrict US commerce, or that are unreasonable or discriminatory and burden or restrict US commerce. Mandatory action under subsection (a) applies where the USTR determines a trade agreement is being violated or a foreign act is unjustifiable, subject to enumerated exceptions including a dispute-settlement-body determination that the practice is compliant, a satisfactory corrective measure, an undertaking to eliminate the practice, or where action would cause disproportionate harm or threaten national security. Discretionary action under subsection (b) applies where the USTR determines an act is unreasonable or discriminatory. Authorized retaliation includes suspending trade agreement benefits, imposing duties or other import restrictions, withdrawing preferential treatment, negotiating binding agreements, and restricting service-sector authorisations; the action must equal the economic burden the foreign practice imposes. Section 301 was the basis of the 2018-2024 China Section 301 tariff actions targeting forced technology transfer and IP misappropriation, and the 2024 increases targeting strategic-sector imports including semiconductors, electric vehicles, batteries, and critical minerals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-trade-act-1974-19-usc-ch12",
      "us-defend-trade-secrets-act-2016-18-usc-ch90"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-section-482-transfer-pricing-treasury-regulations",
    "title": "Allocation of Income and Deductions Among Taxpayers (Section 482) - Transfer Pricing Methods",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "U.S. Treasury Regulations under Section 482 empower the IRS to reallocate income, deductions, and credits between two or more commonly controlled entities to prevent tax evasion and clearly reflect income. As mandated by § 1.482-1(b), all controlled transactions must adhere to the arm's length standard, meaning they must be priced as if conducted between unrelated parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-beps-action-3-cfc-rules-2015"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-secure-2-0-act-2022-pl-117-328",
    "title": "SECURE 2.0 Act 2022 - Public Law 117-328 Retirement Reform Expansion",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The SECURE 2.0 Act of 2022 (Division T of the Consolidated Appropriations Act 2023, Public Law 117-328, enacted 29 December 2022) is the most significant US retirement reform since the SECURE Act of 2019, containing approximately 90 substantive provisions phased in across 2023 through 2027. Key provisions include section 101 mandatory auto-enrolment and auto-escalation for new 401(k) and 403(b) plans starting plan years 2025, section 107 raising the RMD age to 73 in 2023 and to 75 in 2033, section 109 increasing catch-up contribution limits for ages 60-63, section 115 emergency savings account add-on to 401(k) plans, section 117 enhanced student loan repayment match treatment, section 304 increased Saver's Credit (Saver's Match) refundable for low and moderate income savers starting 2027, section 314 emergency penalty-free withdrawals up to 1,000 USD per year, section 325 emergency savings linked to retirement accounts, section 331 plan loans for victims of domestic abuse, section 350 expanded automatic portability for small balances, section 603 Roth treatment of catch-up contributions for high earners starting 2026. The Act also imposed substantial compliance changes including new mandatory distribution rules for inherited Roth IRAs and updated plan correction procedures. Implementation is being phased through 2027 with extensive IRS and DOL guidance issued via Notice 2024-2 and subsequent notices.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-secure-act-2019-pl-116-94",
      "us-erisa-29-usc-1001"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-secure-act-2019-pl-116-94",
    "title": "SECURE Act 2019 - Public Law 116-94 Retirement Savings Reform",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Setting Every Community Up for Retirement Enhancement Act of 2019 (SECURE Act, Division O of the Further Consolidated Appropriations Act 2020, Public Law 116-94, enacted 20 December 2019) materially reformed the US retirement system through approximately 30 substantive provisions affecting ERISA, the Internal Revenue Code, and the Treasury Department's retirement-plan rules. Key provisions include section 102 raising the required minimum distribution age from 70.5 to 72, section 107 repealing the maximum age for traditional IRA contributions, section 103 enabling small employers to band together in pooled employer plans (PEPs) for 401(k) administration, section 109 facilitating lifetime income products by easing the safe harbour for selecting annuity providers, section 113 enabling participation by long-term part-time employees in 401(k) plans after 3 years of 500+ hours service, section 114 increasing the maximum auto-enrolment default escalation under qualified default investment alternatives, section 401 modifying the stretch IRA rules for non-spouse beneficiaries to a 10-year payout, section 401 expanding penalty-free withdrawals for qualifying birth or adoption expenses up to 5,000 USD, and increased small-employer plan startup credits. The SECURE Act framework was substantially expanded by the SECURE 2.0 Act of 2022 (Division T of Consolidated Appropriations Act 2023, Public Law 117-328).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-erisa-29-usc-1001",
      "us-dol-cfr-29-part-2550-erisa-fiduciary-rules"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-securities-act-1933",
    "title": "US Securities Act 1933 - Registration, Disclosure, and Anti-Fraud for Securities Offerings",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Securities Act of 1933 (15 USC §77a et seq.) requires that securities offerings to the public be registered with the SEC via a prospectus disclosing material information, unless an exemption applies. Section 11 imposes strict liability on issuers for material misstatements in registration statements. Section 12 imposes liability for unregistered offerings. Section 17 prohibits fraud in connection with securities offerings. Key exemptions include Regulation D (private placements), Regulation S (offshore transactions), and Regulation A+ (mini IPO up to $75M).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-investment-advisers-act-1940",
      "us-investment-company-act-1940",
      "us-bank-secrecy-act-31-cfr-1010-aml"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-securities-exchange-act-1934",
    "title": "US Securities Exchange Act of 1934 - Registration, Periodic Reporting, and Market Integrity",
    "domain": "Banking & Global Finance",
    "version": "2024.1.0",
    "last_updated": "2024-01-01",
    "bluf": "The Securities Exchange Act of 1934 (SEA) requires public companies with ≥$10M assets and ≥2,000 shareholders (or ≥500 non-accredited) to register with the SEC (Section 12), file periodic reports (10-K annual, 10-Q quarterly, 8-K current), follow proxy rules (Section 14), and comply with insider reporting (Section 16); it prohibits manipulation, fraud, and insider trading (Section 10(b)/Rule 10b-5) and governs broker-dealer and exchange registration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "other"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-dodd-frank-title-vii-otc-derivatives-2010",
      "us-glba-gramm-leach-bliley-act-1999",
      "us-cfpb-dodd-frank-title-x-consumer-financial-protection"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-securities-investor-protection-act",
    "title": "US Securities Investor Protection Act (15 USC ch 2B-1): Customer Protection in Broker-Dealer Failures",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Securities Investor Protection Act (15 U.S.C. ch. 2B-1) protects customers of failed broker-dealers by establishing the Securities Investor Protection Corporation and a liquidation procedure, overseen by the Securities and Exchange Commission. Section 78ccc establishes the Securities Investor Protection Corporation, a nonprofit membership corporation of which most registered brokers and dealers must be members, funded by member assessments. Section 78eee provides for court action and the issuance of a protective decree where a member is in financial difficulty, placing the broker-dealer into a liquidation proceeding with an appointed trustee. Section 78fff sets the general provisions of a liquidation proceeding, directing that the goal is the prompt return of customer property. Section 78fff-2 governs the satisfaction of customer claims, and section 78fff-3 governs advances by SIPC: where customer property is insufficient, SIPC advances funds to satisfy net equity claims up to 500,000 dollars for each customer, of which not more than the standard maximum cash advance amount of 250,000 dollars may be for claims for cash, with the cash limit adjusted for inflation every five years. SIPC may not advance funds for the claims of insiders such as officers, directors and substantial owners. The Act is the legal foundation for US protection of brokerage customers in a firm failure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-select-agent-program-42-cfr-73",
    "title": "Possession, Use and Transfer of Biological Select Agents and Toxins (42 CFR Part 73 and 9 CFR Part 121)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This regulation establishes requirements for entities possessing, using, or transferring biological select agents and toxins (BSAT) that have the potential to pose a severe threat to public, animal, or plant health. It applies to all U.S. laboratories and institutions registered with the Federal Select Agent Program under 42 CFR Part 73 and 9 CFR Part 121, mandating strict biosafety, security, training, and incident reporting protocols.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-self-drive-act-av-start-act-framework",
    "title": "Federal Framework for the Testing and Deployment of Highly Automated Vehicles - Principles from the SELF DRIVE Act and AV START Act, Including Federal Preemption, Cybersecurity, Privacy, and Exemption Authority",
    "domain": "Automotive & Mobility",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "This framework establishes federal oversight of highly automated vehicle (HAV) safety standards, preempting state-level regulation of HAV design and performance. It mandates that manufacturers submit Safety Evaluation Reports (SERs) including cybersecurity and privacy plans under NHTSA authority, based on principles from the proposed SELF DRIVE Act (H.R. 3388) and AV START Act (S. 1885), particularly Section 5 of the SELF DRIVE Act and Section 7 of the AV START Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-automated-vehicles-comprehensive-plan-2021",
      "sae-j3016-levels-driving-automation-2021",
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "iso-26262-functional-safety-road-vehicles-2018",
      "un-regulation-r155-vehicle-cybersecurity-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-sergei-magnitsky-act-2012-pl-112-208-title-iv",
    "title": "United States Sergei Magnitsky Rule of Law Accountability Act of 2012 (Public Law 112-208, Title IV): Short Title, Findings and Sense of Congress, Definitions, Identification of Persons Responsible for the Detention Abuse and Death of Sergei Magnitsky and Other Gross Violations of Human Rights, Inadmissibility of Certain Aliens, and Financial Measures",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Sergei Magnitsky Rule of Law Accountability Act of 2012, enacted as Title IV of the Russia and Moldova Jackson-Vanik Repeal and Sergei Magnitsky Rule of Law Accountability Act of 2012 (Public Law 112-208 of 14 December 2012), is the principal United States statute authorizing sanctions against persons responsible for the detention, abuse, or death of Russian lawyer Sergei Magnitsky in 2008-2009 and against other persons responsible for gross violations of internationally recognized human rights against individuals in Russia exposing illegal activity by Russian government officials, and is administered by the Department of the Treasury's Office of Foreign Assets Control and the Department of State. Sergei Magnitsky Rule of Law Accountability Act, section 401 sets the short title. Sergei Magnitsky Rule of Law Accountability Act, section 402 contains the findings and sense of Congress. Sergei Magnitsky Rule of Law Accountability Act, section 403 contains the definitions including admitted, alien, appropriate congressional committees, financial institution, and United States person. Sergei Magnitsky Rule of Law Accountability Act, section 404 requires the President to submit a list of persons responsible for the detention, abuse, or death of Sergei Magnitsky and other gross violations of human rights within 120 days of enactment, with subsequent updates. Sergei Magnitsky Rule of Law Accountability Act, section 405 provides for the inadmissibility of certain aliens including visa ineligibility and revocation. Sergei Magnitsky Rule of Law Accountability Act, section 406 provides for financial measures including blocking of assets and enforcement through financial institutions. The Act is the controlling federal instrument for Russia-specific human rights sanctions and is the legislative predecessor of the Global Magnitsky Human Rights Accountability Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-service-contract-act-1965-41-usc-6701",
    "title": "Service Contract Act of 1965 (41 U.S.C. §§ 6701-6707)",
    "domain": "Operations & CX",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Service Contract Act of 1965 (41 U.S.C. §§ 6701-6707) requires federal contractors and subcontractors performing service contracts exceeding $2,500 to pay service employees no less than the prevailing wage rates and fringe benefits determined by the Secretary of Labor. It also mandates successor contractors to offer employment to qualified workers employed by the predecessor under 41 U.S.C. § 6704.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-federal-crop-insurance-act-1938-7-usc-1501"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sheep-promotion-research-information-act",
    "title": "US Sheep Promotion, Research, and Information Act of 1994 (7 USC ch 99): Sheep and Wool Board and Assessments",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Sheep Promotion, Research, and Information Act of 1994 (7 U.S.C. ch. 99, sections 7101 to 7111) authorizes a coordinated program of promotion, research, consumer information, education, and industry information for sheep and sheep products funded by assessments, administered by the Secretary of Agriculture. Section 7101 sets out the findings and declaration of policy, recognizing that sheep and sheep products are important goods that play a significant role in the economy of the United States, and authorizing an orderly procedure for developing, financing, and carrying out an effective, continuous, coordinated program of promotion, research, consumer information, education, and industry information. Section 7102 defines the terms, and section 7103 authorizes the issuance and amendment of orders. Section 7104 sets the required terms in orders, providing for the establishment of a Board and fixing the assessments at 1 cent per pound of live sheep sold and 2 cents per pound of greasy wool, subject to specified adjustment limits. Section 7105 sets the referenda, providing that an order becomes effective only if approved by not less than a majority of those voting in the referendum or by persons voting who represent at least two-thirds of the production. Section 7106 provides for petition and review, section 7107 provides for enforcement, including a civil penalty of not more than 1,000 dollars for each violation, and section 7108 provides investigations and power to subpoena. Section 7109 sets the administrative provisions. The Act is the federal checkoff regime for sheep and wool.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-sherman-act-1890-section-1-restraint-trade-combinations",
    "title": "15 U.S. Code § 1 - Trusts, etc., in restraint of trade illegal; penalty",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must not enter into any contract, combination, or conspiracy that restrains trade or commerce among the several States or with foreign nations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-sherman-antitrust-act",
    "title": "US Sherman Antitrust Act (15 USC ch 1): Restraint of Trade, Monopolization and Criminal Penalties",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Sherman Antitrust Act of 1890 (15 U.S.C. ch. 1, sections 1 to 7) is the foundational US antitrust statute, enforced by the Department of Justice Antitrust Division and, civilly, through private and government suits. Section 1 declares illegal every contract, combination or conspiracy in restraint of trade, and makes a violation a felony punishable by a fine of up to 100,000,000 dollars for a corporation or 1,000,000 dollars for an individual, or imprisonment for up to 10 years. Section 2 makes it a felony to monopolize, attempt to monopolize, or conspire to monopolize any part of trade or commerce, subject to the same penalties. Section 3 extends these prohibitions to restraints of trade in the Territories and the District of Columbia. Section 4 gives the district courts jurisdiction to prevent and restrain violations and directs the United States attorneys to institute proceedings, and section 5 allows additional parties to be brought in. Section 6 provides for the forfeiture of property owned under an unlawful combination and in the course of interstate transport. Section 7 defines person to include corporations and associations. The private treble-damages remedy for antitrust injury, including injury from Sherman Act violations, is provided by section 15 (the Clayton Act). The Act is the legal foundation of US competition enforcement against cartels, bid rigging, and monopolization.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-sherman-antitrust-act-15-usc-ch1",
    "title": "United States Sherman Antitrust Act (Title 15 USC Chapter 1): Restraint of Trade Prohibition (Section 1), Monopolization Felony (Section 2), Territorial Reach, Court Jurisdiction, Forfeiture of Property in Transit, and Definitions",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Sherman Antitrust Act, codified at Title 15 of the United States Code, Chapter 1 (Monopolies and Combinations in Restraint of Trade), is the foundational federal antitrust statute in the United States and is enforced civilly and criminally by the Antitrust Division of the Department of Justice and the Federal Trade Commission and through private treble damages actions. Sherman Antitrust Act, 15 U.S.C. 1 declares: every contract, combination in the form of trust or otherwise, or conspiracy, in restraint of trade or commerce among the several States, or with foreign nations, is declared to be illegal. Sherman Antitrust Act, 15 U.S.C. 2 provides: every person who shall monopolize, or attempt to monopolize, or combine or conspire with any other person or persons, to monopolize any part of the trade or commerce among the several States, or with foreign nations, shall be deemed guilty of a felony. Sherman Antitrust Act, 15 U.S.C. 3 extends the prohibition to trusts in Territories or the District of Columbia. Sherman Antitrust Act, 15 U.S.C. 4 invests the several district courts of the United States with jurisdiction to prevent and restrain violations of sections 1 to 7 and assigns enforcement duties to the United States attorneys. Sherman Antitrust Act, 15 U.S.C. 5 authorises bringing in additional parties whenever the ends of justice require. Sherman Antitrust Act, 15 U.S.C. 6 provides that any property owned under any contract or by any combination or conspiracy and being in the course of transportation between States or to a foreign country shall be forfeited to the United States. Sherman Antitrust Act, 15 U.S.C. 6a addresses conduct involving trade or commerce with foreign nations under the Foreign Trade Antitrust Improvements Act framework. Sherman Antitrust Act, 15 U.S.C. 7 defines the term person to include corporations and associations existing under or authorized by the laws of U.S. jurisdictions or foreign nations. The Act is the controlling federal antitrust statute in the United States and operates alongside the Clayton Act and the Federal Trade Commission Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-sherman-antitrust-act-1890-sections-1-2",
    "title": "An Act to protect trade and commerce against unlawful restraints and monopolies",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The Sherman Antitrust Act of 1890, Sections 1 and 2, prohibits agreements in restraint of trade and monopolization or attempts to monopolize any part of interstate or foreign commerce. It applies to all persons, corporations, and entities engaged in U.S. interstate or foreign commerce and establishes both civil and criminal enforcement mechanisms under U.S. Department of Justice authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-competition"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-sherman-antitrust-act-sections-1-2",
    "title": "Sherman Antitrust Act (15 U.S.C. §§ 1-2)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Sherman Antitrust Act prohibits anticompetitive business practices, making it illegal under Section 1 to form contracts, combinations, or conspiracies in restraint of trade (e.g., price-fixing), and under Section 2 to monopolize, attempt to monopolize, or conspire to monopolize any part of trade or commerce. The law applies to virtually all businesses engaged in interstate or foreign commerce in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-competition"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-ship-mortgage-act-preferred-mortgage-46-usc-31322",
    "title": "Ship Mortgage Act - Preferred Mortgages, 46 USC 31322",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Ship Mortgage Act provision at 46 USC 31322 sets the requirements for a mortgage on a vessel to qualify as a preferred mortgage. Under Section 31322(a), a mortgage is a preferred mortgage if it includes the whole of the vessel (a)(1), is filed in substantial compliance with Section 31321 (a)(2), covers a documented vessel or a vessel for which a documentation application in substantial compliance with chapter 121 is filed (a)(3), and, for a vessel with a fishery endorsement of 100 feet or greater in registered length, has a mortgagee that is an eligible person such as a person eligible to own such a vessel or a qualifying financial institution (a)(4).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-coast-guard-vessel-documentation-46-cfr-67-jones-act-cabotage"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-shipping-act-1984",
    "title": "US Shipping Act of 1984 (46 USC ch 401): Ocean Carrier Agreements, Tariffs and FMC Regulation",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Shipping Act of 1984 (46 U.S.C. ch. 401 and related chapters) regulates the ocean liner shipping trades to and from the United States, administered by the Federal Maritime Commission (FMC). Section 40101 states the purposes, including establishing a nondiscriminatory regulatory process for the common carriage of goods by water in the foreign commerce of the United States with a minimum of government intervention. Section 40102 supplies the definitions, including ocean common carrier, marine terminal operator and service contract. Section 40103 provides for administrative exemptions and section 40104 for reports filed with the Commission. The Act regulates competition among carriers: section 40301 governs agreements among ocean common carriers and marine terminal operators (which, when filed and effective, are granted limited antitrust immunity). Section 40501 governs the publication of tariffs and the use of service contracts. The prohibited-practices provisions are central to enforcement: section 41102 prohibits unjust and unreasonable practices and the failure to establish and observe just and reasonable regulations, and section 41104 prohibits specified acts by common carriers, including unreasonable refusals to deal and undue preference. The FMC enforces these provisions and may impose civil penalties. The Act is the legal foundation of US ocean-shipping regulation and the FMC's oversight of carrier conduct.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-sipa-securities-investor-protection-act-15-usc-ch2b-1",
    "title": "Securities Investor Protection Act 1970 - 15 USC Chapter 2B-1",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Chapter 2B-1 of title 15 of the United States Code codifies the Securities Investor Protection Act of 1970 (Public Law 91-598), establishing the Securities Investor Protection Corporation (SIPC) as a non-profit membership corporation funded by member assessments on registered broker-dealers, and providing a customer-protection framework for failed brokerage firms. Section 78ccc establishes SIPC and its membership requirements covering substantially all registered broker-dealers under section 15(b) of the Securities Exchange Act of 1934 with limited exclusions. Section 78eee establishes the customer-protection procedure invoked when SIPC determines a member firm has failed or is in danger of failure and customers need protection; SIPC may apply to a federal district court for a protective decree appointing a trustee to liquidate the firm's business. Section 78fff governs the liquidation including the customer-property classification, the satisfaction of net equity claims, and SIPC advances up to the statutory limits (currently 500,000 USD per customer including a sub-limit of 250,000 USD for cash claims). Sections 78fff-1 through 78fff-4 govern trustee duties, customer notification, customer claims, distribution, and intercompany claims. Section 78lll provides essential definitions including the customer definition and excluded persons. SIPA is the operative US framework protecting brokerage customers against firm failure (distinct from FDIC deposit insurance) and shapes the cybersecurity, custody, and operational resiliency obligations of any member broker-dealer.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-securities-exchange-act-1934",
      "us-securities-act-1933"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-small-business-act-15-usc-631",
    "title": "Small Business Act - 15 USC 631 Federal Small Business Policy",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 631 of title 15 of the United States Code, the Declaration of Policy of the Small Business Act (Public Law 85-536, enacted 18 July 1958, as substantially amended), establishes the foundational federal policy supporting small business and creates the Small Business Administration (SBA). The statute commits the federal government to aiding, counselling, assisting, and protecting the interests of small business concerns to preserve free competitive enterprise. Section 631(a) declares the federal policy to ensure a fair proportion of federal procurement is awarded to small business, supports access to capital and management assistance, and protects small business from anti-competitive practices. Subsections (b) through (m) extend the policy to socially and economically disadvantaged individuals (including Black Americans, Hispanic Americans, Native Americans, Indian tribes, Asian Pacific Americans, Native Hawaiian Organizations, and other minorities), women-owned businesses, veterans, service-disabled veterans, and HUBZone businesses. Section 632 defines small business concerns by reference to size standards established by the SBA Administrator. Section 644 governs federal procurement set-asides and bundling restrictions. The SBA administers the principal small-business contracting programs (8(a) Business Development, Women-Owned Small Business, Service-Disabled Veteran-Owned Small Business, HUBZone), capital programs (7(a) loans, 504 loans, microloans, SBIC), and counselling programs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-anti-deficiency-act-31-usc-1341"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-smcra-1977-30-usc-ch25",
    "title": "United States Surface Mining Control and Reclamation Act of 1977 (SMCRA) (Title 30 USC Chapter 25): Congressional Findings, Statement of Purpose, Office of Surface Mining Reclamation and Enforcement, Abandoned Mine Reclamation Fund, Environmental Protection Performance Standards, Permits, and Civil and Criminal Penalties",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Surface Mining Control and Reclamation Act of 1977 (SMCRA), Public Law 95-87 of 3 August 1977, codified at Title 30 of the United States Code, Chapter 25, is the principal federal statute regulating the environmental effects of coal mining in the United States and establishing minimum standards for surface coal mining and reclamation, and is administered by the Office of Surface Mining Reclamation and Enforcement within the Department of the Interior with cooperative federalism delegation to states with approved state programs. SMCRA, 30 U.S.C. 1201 contains the Congressional findings regarding the impacts of surface coal mining operations on the environment and the desirability of establishing a nationwide program to protect society and the environment from the adverse effects of surface coal mining operations. SMCRA, 30 U.S.C. 1202 contains the statement of purpose including establishing a nationwide program to protect society and the environment, ensuring that surface coal mining operations are not conducted where reclamation as required is not feasible, and assuring that the rights of surface landowners and other persons are fully protected. SMCRA, 30 U.S.C. 1211 establishes the Office of Surface Mining Reclamation and Enforcement within the Department of the Interior. SMCRA, 30 U.S.C. 1231 establishes the Abandoned Mine Reclamation Fund. SMCRA, 30 U.S.C. 1232 contains the reclamation fee requirements imposed on operators of coal mining operations. SMCRA, 30 U.S.C. 1251 contains the environmental protection standards. SMCRA, 30 U.S.C. 1265 contains the environmental protection performance standards for surface mining operations. SMCRA, 30 U.S.C. 1268 contains the civil and criminal penalties for violations. The Act is the controlling federal instrument for regulating the environmental effects of surface coal mining in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-smith-lever-act",
    "title": "US Smith-Lever Act (7 USC ch 13): Cooperative Agricultural Extension Work by Land-Grant Colleges",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Smith-Lever Act (7 U.S.C. ch. 13, sections 341 onward) establishes the cooperative agricultural extension system of the United States, carried on by the land-grant colleges in cooperation with the Department of Agriculture. Section 341 provides that agricultural extension work shall be carried on in cooperation with the United States Department of Agriculture, and section 342 describes that work as the development of practical applications of research knowledge and the giving of instruction and practical demonstrations in agriculture, home economics, and related subjects to persons not attending the colleges. Section 343 authorizes annual appropriations and prescribes their distribution, allotment, and apportionment among the States: a portion equal to 20 per centum is allotted equally to each State, a further 40 per centum is distributed in the proportion that the rural population of each State bears to the total rural population of the States, and the remaining balance is distributed in the proportion that the farm population of each State bears to the total farm population, with an amount retained by the Secretary of Agriculture for administrative, technical, and coordination services. The Act is the legal foundation of the Cooperative Extension Service operated through the land-grant universities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-soil-conservation-domestic-allotment-act",
    "title": "US Soil Conservation and Domestic Allotment Act (16 USC ch 3B): Soil Erosion Control and Conservation Payments",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Soil Conservation and Domestic Allotment Act (16 U.S.C. ch. 3B, sections 590a to 590q-3) authorizes the federal soil and water conservation program of the United States, administered by the Secretary of Agriculture principally through the Natural Resources Conservation Service. Section 590a authorizes the Secretary to conduct surveys and investigations, to carry out preventive measures including engineering operations and changes in land use, to cooperate with other agencies, and to acquire lands for the control of soil erosion. Section 590b identifies the lands on which preventive measures may be taken, including United States lands and other lands with the consent of the owner. Section 590c sets the conditions under which the benefits of the law are extended to lands not owned or controlled by the United States, allowing the Secretary to require restrictions, covenants, contributions, and conservation planning, with conservation planning fees that may not exceed 150 dollars per conservation plan. Section 590g declares the additional policy of preserving soil and water resources, preventing pollution, protecting rivers and harbors, and maintaining the agricultural supply, while section 590h authorizes payments, grants of aid, and technical assistance, including through state and county committees. Section 590o authorizes appropriations not exceeding 500,000,000 dollars per fiscal year. The Act is a foundational United States conservation statute.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-soil-water-resources-conservation-act",
    "title": "US Soil and Water Resources Conservation Act of 1977 (16 U.S.C. Chapter 40): National Appraisal and Conservation Program",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Soil and Water Resources Conservation Act of 1977, codified at 16 U.S.C. Chapter 40 (sections 2001 through 2009), directs the Secretary of Agriculture to appraise the soil, water, and related resources of the Nation on a continuing basis and to develop a national soil and water conservation program, administered through the Natural Resources Conservation Service in cooperation with State, tribal, and local agencies. Section 2001 sets the congressional findings on the importance of the Nation's soil and water resources. Section 2002 provides the definitions. Section 2003 sets the congressional policy and declaration of purpose, including furthering the conservation of soil, water, and related resources. Section 2004 requires a continuing appraisal of soil, water, and related resources, including data on their quality, quantity, and capability. Section 2005 requires the Secretary to develop and update a national soil and water conservation program setting the direction of conservation activities. Section 2006 requires reports to Congress, including a statement of the Secretary's recommendations. Section 2007 authorizes appropriations, section 2008 requires the utilization of available information and data to avoid duplication, and section 2009 addresses the termination of the program. The Act is the foundational statute for the national appraisal and planning of soil and water conservation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-south-dakota-v-wayfair-economic-nexus-2018",
    "title": "South Dakota v. Wayfair Inc. Supreme Court Decision (2018) - Economic Nexus Standard for Remote Sellers: $100,000 Sales or 200 Transactions Threshold and State Sales Tax Collection Obligations",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Supreme Court's decision in South Dakota v. Wayfair, Inc., 585 U. S. ___ (2018), overturned the physical presence rule, allowing states to require remote sellers to collect and remit sales tax based on a substantial economic nexus. This ruling upheld South Dakota's law (S.B. 106) establishing nexus for sellers with over $100,000 in sales or 200 separate transactions into the state annually.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ftc-act-section-5-unfair-competition"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-sox-15-usc-7241-section-302-ceo-cfo-certifications",
    "title": "15 U.S. Code § 7241 - Corporate responsibility for financial reports",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Requires principal executive and financial officers of public companies to personally certify the accuracy of financial reports and the effectiveness of internal controls in each annual or quarterly filing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-sox-15-usc-7262-section-404-internal-control-assessment",
    "title": "15 U.S. Code § 7262 - Management assessment of internal controls",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Requires management of public companies to establish, maintain, and assess the effectiveness of internal controls for financial reporting in their annual report, which must be attested to by an external auditor for most issuers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sox-18-usc-1350-section-906-criminal-penalties-certifications",
    "title": "18 U.S. Code § 1350 - Failure of corporate officers to certify financial reports",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Requires the CEO and CFO of an issuer to provide a written certification with each periodic financial report filed with the SEC, attesting to the report's compliance and fair presentation of financial condition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-soybean-promotion-research-information-act",
    "title": "US Soybean Promotion, Research, and Consumer Information Act (7 USC ch 92): United Soybean Board and Assessments",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Soybean Promotion, Research, and Consumer Information Act (7 U.S.C. ch. 92, sections 6301 to 6311) authorizes a coordinated program of promotion, research, and consumer information for soybeans funded by assessments, administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 6301 sets out the findings and declaration of policy, recognizing that soybeans are an important source of nutritious foods and an important feedstuff for the livestock industry and move in interstate and foreign commerce, and establishing an orderly procedure for developing and financing through assessments on domestically produced soybeans a program to strengthen the soybean industry's position in the marketplace. Section 6302 defines the terms, and section 6303 authorizes the issuance and amendment of orders. Section 6304 sets the required terms in orders, providing for the establishment of a United Soybean Board to administer the order and fixing the assessment at one-half of 1 percent of the net market price of soybeans sold by the producer. Section 6305 sets the referenda, providing for a referendum among producers to ascertain whether the order then in effect shall be continued. Section 6306 provides for petition and review, section 6307 provides for enforcement, including a civil penalty assessed by the Secretary of not more than 1,000 dollars for each violation, and section 6308 provides investigations and power to subpoena. Section 6309 sets the administrative provisions and section 6310 provides for the suspension or termination of orders. The Act is the federal checkoff regime for soybeans.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-space-force-regulations-dodi-3100-12",
    "title": "DoD Instruction 3100.12, Space Support: Space Force Roles in Space Domain Awareness, Satellite Command and Control, Offensive and Defensive Space Control, and Transfer of Authorities from Air Force to USSF Components, Including Assignment to USINDOPACOM and Space Superiority Operations",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes the roles, responsibilities, and operational authorities of the United States Space Force (USSF) in space support operations, including Space Domain Awareness (SDA), satellite command and control (C2), offensive and defensive space control, and the transfer of space capabilities from the Air Force to USSF components. It applies to all Department of Defense components and Combatant Commands, particularly USINDOPACOM, under DoDI 3100.12, Section 4.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ir-8374-ransomware-risk-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-space-policy-directive-3-2018-stm",
    "title": "US Space Policy Directive-3 (SPD-3) - National Space Traffic Management Policy 2018",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "SPD-3 (signed 18 June 2018) designates the US Department of Commerce (DOC) as the lead civil agency for Space Traffic Management (STM), establishes an open-architecture civil Space Situational Awareness (SSA) data-sharing framework, mandates orbital debris mitigation standards for commercial operators, and initiates international engagement to build a global STM norm framework. DOD retains the authoritative space object catalog via the US Space Surveillance Network (SSN).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iadc_debris_guidelines",
        "fcc_orbital_debris",
        "un_copuos_lts"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "un-registration-convention-1976-space",
      "copuos-lts-guidelines-2019-space-sustainability",
      "iadc-space-debris-mitigation-guidelines-2007",
      "us-commercial-space-launch-act-1984-amendments"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-space-policy-directive-4-2019-space-force",
    "title": "US Space Policy Directive-4 (SPD-4) 2019 - Establishment of the United States Space Force",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "SPD-4 (signed 19 February 2019) directed the Department of Defense to establish the United States Space Force (USSF) as a separate military service branch. The USSF was formally established on 20 December 2019 by the National Defense Authorization Act for Fiscal Year 2020. USSF is responsible for organizing, training, and equipping forces for space operations including space situational awareness, missile warning, satellite communications, GPS, and intelligence surveillance and reconnaissance (ISR).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "spd_3_stm",
        "ndaa_fy2020",
        "usspacecom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-space-policy-directive-3-2018-stm",
      "un-outer-space-treaty-1967",
      "copuos-lts-guidelines-2019-space-sustainability",
      "us-space-force-regulations-dodi-3100-12"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-sr-26-2-revised-model-risk-management-2026",
    "title": "SR 26-2 Revised Interagency Guidance on Model Risk Management (Fed, FDIC, OCC, April 2026)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "On April 17, 2026 the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation and the Office of the Comptroller of the Currency jointly issued SR 26-2, Revised Guidance on Model Risk Management, superseding SR letter 11-7, Guidance on Model Risk Management (April 4, 2011), and SR letter 21-8, Interagency Statement on Model Risk Management for Bank Systems Supporting Bank Secrecy Act/Anti-Money Laundering Compliance (April 9, 2021). The revision clarifies model risk management principles and emphasizes a risk-based approach tailored to a banking organization's model risk profile, reflecting supervisory experience and industry feedback accumulated over the past fifteen years and significant advancements in modeling practices. For the Federal Reserve it applies to banking organizations with over $30 billion in total assets. The attached Supervisory Guidance on Model Risk Management is organised in seven sections covering purpose and scope, model risk overview, model development and use, model validation and monitoring, governance and controls, and vendor and other third-party products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ffiec-model-risk-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-standard-barrel-act",
    "title": "US Standard Barrel Acts (15 USC ch 6): Standard Barrels for Apples, Fruits and Dry Commodities",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Standard Barrel Acts (15 U.S.C. ch. 6, subchapter VI, sections 231 to 242) establish federal standard barrels for apples, other fruits, vegetables, and dry commodities, and for lime, administered by the Secretary of Commerce through the National Institute of Standards and Technology. Section 231 fixes the dimensions of the standard barrel for apples, with a stave length of twenty-eight and one-half inches and a head diameter of seventeen and one-eighth inches, and section 233 makes selling apples in a barrel of less than standard dimensions punishable by a penalty of 1 dollar and costs for each such barrel. Section 234 fixes the standard barrel for fruits, vegetables, and other dry commodities at a capacity of seven thousand and fifty-six cubic inches, with a separate standard for the cranberry barrel. Section 235 prohibits the sale or shipment of a barrel of less capacity than the standard and makes a violation punishable by a fine not to exceed 500 dollars or imprisonment not to exceed six months. Section 237 fixes standard weights for the lime barrel at two hundred and eighty pounds for the large barrel and one hundred and eighty pounds for the small barrel, and section 238 imposes a penalty for selling in unmarked barrels. The Acts are the federal standardization regime for produce barrels in commerce.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-state-california-sb-1001-bot-disclosure-2018",
    "title": "California Bot Disclosure Law - SB 1001 (Effective July 1, 2019)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "California Senate Bill 1001 (Hertzberg, 2018) was signed by Governor Brown on September 28, 2018 and took effect July 1, 2019 as the first US state law requiring bot disclosure in consumer-facing interactions. SB 1001 is codified at California Business and Professions Code 17940-17943. The core prohibition is that it is unlawful for any person to use a bot to communicate or interact with another person in California online, with the intent to mislead the other person about its artificial identity for the purpose of knowingly deceiving the other person about the content of the communication in order to (1) incentivise a purchase or sale of goods or services in a commercial transaction OR (2) influence a vote in an election. The Law defines bot as an automated online account where all or substantially all of the actions or posts of that account are not the result of a person. A person using a bot does not violate the Law if the person discloses that it is a bot in a manner that is clear, conspicuous, and reasonably designed to inform persons with whom the bot communicates or interacts that it is a bot. SB 1001 is the foundational US state law on AI disclosure and informed subsequent state laws including Utah AIPA (2024), California AB 2655 (2024), and the federal AI disclosure proposals.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "regulatory_overlay",
        "ai_governance_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-sb942-ai-transparency-act-2024",
      "us-ca-ab2655-2024-defending-democracy-deepfake-deception"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-state-illinois-hb-3773-ai-employment-2024",
    "title": "Illinois HB 3773 - Amendments to Illinois Human Rights Act for AI in Employment (Signed August 9 2024, Effective January 1 2026)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "Illinois House Bill 3773 was signed by Governor Pritzker on August 9, 2024 and takes effect January 1, 2026. The Bill amends the Illinois Human Rights Act at 775 ILCS 5 to prohibit employer use of artificial intelligence in employment decisions if the use has the effect of subjecting employees or applicants to discrimination on the basis of a protected class. Core provisions: (1) Prohibition on discriminatory AI use - an employer cannot use artificial intelligence that has the effect of subjecting employees or applicants to discrimination on the basis of protected classes (race, colour, religion, sex including pregnancy and sexual orientation, national origin, ancestry, age, marital status, physical or mental disability, military status, sexual harassment, citizenship status, work authorisation status, genetic information, or order of protection status) or that uses zip codes as a proxy for protected class; (2) Notice obligation - an employer must provide notice to employees and applicants that the employer is using AI for the relevant employment purposes including hiring, promotion, renewal of employment, selection for training or apprenticeship, discharge, discipline, tenure, or terms privileges or conditions of employment; (3) Implementing rules - the Illinois Department of Human Rights is directed to adopt rules necessary for implementation and enforcement, with public comment period. Penalties for violation: enforcement under the Illinois Human Rights Act including civil penalties up to USD 5000 per violation, compensatory damages, attorney fees, and injunctive relief. HB 3773 is the broadest US state AI employment discrimination law and expands the Illinois Artificial Intelligence Video Interview Act framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "regulatory_overlay",
        "ai_governance_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-il-aivea-2019",
      "us-illinois-ai-video-interview-act-amendments",
      "us-eeoc-ai-employment-guidance-2023",
      "us-nyc-ll-144-aedt-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-state-michigan-ai-deepfake-pa-264-2023",
    "title": "Michigan Campaign Deepfake Disclosure Law - Public Acts 263-265 of 2023 (Effective February 13, 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "Michigan Public Acts 263, 264, and 265 of 2023 were signed by Governor Gretchen Whitmer on November 30, 2023 and took effect February 13, 2024. The Acts amend the Michigan Campaign Finance Act and the Michigan Penal Code to regulate AI-generated and manipulated media in political campaigns. Public Act 264 prohibits a person, committee, or other entity from distributing materially deceptive media of a candidate or office holder for purposes of harming the reputation or electoral prospects of the candidate or influencing the outcome of an election unless the media includes a clear and conspicuous disclosure. The disclosure must state that the media has been manipulated by technical means and depicts speech or conduct that did not occur. The Acts cover the 90 days immediately preceding an election. Civil remedies include injunctive relief and private rights of action with statutory damages. Criminal penalties apply for knowing violations distributing materially deceptive media within the 90-day window: misdemeanour up to 93 days imprisonment, USD 250 fine, or both for a first violation; felony up to 5 years imprisonment and USD 1000 fine for subsequent violations or violations causing physical injury or death. The Acts are part of a 2023-2024 wave of state campaign deepfake disclosure laws including California AB 730 (2019), Texas SB 751 (2019), Minnesota HF 1370 (2023), Washington SB 5152 (2024), and California AB 2655 (2024).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "regulatory_overlay",
        "election_integrity_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-ab2655-2024-defending-democracy-deepfake-deception",
      "us-fcc-tcpa-ai-voice-robocalls-ruling-2024",
      "us-state-tennessee-elvis-act-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-state-privacy-law-patchwork",
    "title": "US State Privacy Law Framework - CCPA, VCDPA, CPA, CTDPA Comparative Compliance Analysis (2023)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Businesses operating across multiple US states must comply with a patchwork of privacy laws, each granting consumers specific rights such as access, deletion, and opt-out of sale/sharing of personal data, and requiring data protection assessments for high-risk processing. Compliance hinges on identifying applicability thresholds (e.g., CCPA § 1798.140(d)) and implementing a unified rights-response mechanism.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-state-tennessee-elvis-act-2024",
    "title": "Tennessee Ensuring Likeness Voice and Image Security Act (ELVIS Act) - HB 2091 / SB 2096 (Signed March 21 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "Tennessee Ensuring Likeness Voice and Image Security Act (ELVIS Act) was signed by Governor Bill Lee on March 21, 2024 and took effect July 1, 2024. The ELVIS Act amends the Tennessee Personal Rights Protection Act (TPRPA) of 1984 to be the first US state law specifically addressing AI voice cloning and unauthorised AI-generated likenesses of performers and other individuals. The Act establishes: (1) Voice as a protected property right - voice is added to the existing TPRPA protections for name, photograph, and likeness; (2) Right of action against AI voice cloning - any individual whose voice is used in a sound recording without authorisation has a right of action, including against generative AI that simulates voice; (3) Right of action against AI likeness - generation of likenesses (visual or audio) using AI to imitate a person without authorisation creates liability; (4) Liability extension to tool providers - persons or entities that distribute, transmit, or otherwise make available an AI or algorithm whose primary purpose or function is the production of a particular individual's photograph, voice, or likeness may be liable; (5) Remedies - injunctive relief, actual damages, statutory damages, attorneys fees, and exemplary damages where appropriate. The Act creates the first US tool-distributor liability for AI voice cloning systems and is the model for similar state laws and the federal No FAKES Act proposal.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "regulatory_overlay",
        "ai_governance_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-sb942-ai-transparency-act-2024",
      "us-ca-ab2655-2024-defending-democracy-deepfake-deception",
      "us-fcc-tcpa-ai-voice-robocalls-ruling-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-state-utah-ai-policy-act-sb149-2024",
    "title": "Utah Artificial Intelligence Policy Act (SB 149, Signed March 13, 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "Utah Senate Bill 149, the Utah Artificial Intelligence Policy Act, was signed by the Governor on March 13, 2024 and took effect May 1, 2024. The Act was the first US state AI consumer disclosure law of broad application. It contains four principal provisions: (1) Generative AI consumer disclosure - a person that uses, prompts, or otherwise causes a generative AI to interact with a person in connection with the offer, sale, or provision of services regulated by the Utah Division of Consumer Protection must clearly and conspicuously disclose that the person is interacting with generative AI, when verbally or in writing asked or prompted by the person; (2) Regulated occupations clear disclosure - a person providing services in an occupation regulated by the Utah Department of Commerce that uses generative AI in providing those services to a member of the public must prominently disclose the use of generative AI before the person provides services; (3) Liability provision - a person engaged in business in the State cannot use generative AI as a defence for violating any Utah consumer protection statute; (4) Office of Artificial Intelligence Policy - establishing an Office of Artificial Intelligence Policy in the Department of Commerce, an Artificial Intelligence Learning Laboratory Program, and a regulatory mitigation agreement framework for AI sandbox-style temporary operating permits. Penalties: USD 2500 per violation for failure to disclose, plus actual damages.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "us_federal_alignment",
        "regulatory_overlay",
        "ai_governance_overlay"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-tx-hb149-traiga-2025",
      "us-ca-sb942-ai-transparency-act-2024",
      "us-colorado-ai-act-sb24-205"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-stem-education-act-2015-nsf",
    "title": "STEM Education Act of 2015 - National Science Foundation Program Inclusion, Informal STEM Education, Broadening Participation, and Museum/Science Center Expansion",
    "domain": "Education & Research",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Act mandates that the National Science Foundation (NSF) incorporate computer science into its STEM portfolio, allocate funding for informal STEM education, set measurable broadening participation targets, and expand museum/science centre programmes as specified in Section 4(b) and Section 7 of the legislation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-21001-2018-educational-organizations-management",
      "oecd-principles-ai-in-education-recommendation-2023",
      "eu-digcomp-digital-competence-framework-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-stevenson-wydler-tech-innovation-act-1980-pl-96-480",
    "title": "US Stevenson-Wydler Technology Innovation Act of 1980 (Public Law 96-480) - Federal Laboratory Technology Transfer",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Stevenson-Wydler Technology Innovation Act of 1980 made federal laboratories responsible for transferring federally developed technology to state and local governments and the private sector, established Offices of Research and Technology Applications at each federal laboratory, created the Federal Laboratory Consortium for Technology Transfer, authorised the use of Cooperative Research and Development Agreements between federal laboratories and non-federal partners with the Federal Technology Transfer Act of 1986 amendments, and required each laboratory to dedicate a percentage of its research budget to technology transfer activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-bayh-dole-act-1980-technology-transfer"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-stock-act-2012-pl-112-105",
    "title": "United States Stop Trading on Congressional Knowledge (STOCK) Act of 2012 (Public Law 112-105): Definitions, Prohibition of Insider Trading by Members and Employees of Congress, Prompt Reporting of Financial Transactions, Public Disclosure of Financial Forms, Initial Public Offerings Restrictions, Post-Employment Negotiation Disclosure, and Wrongful Influence of Private Employment Decisions",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Stop Trading on Congressional Knowledge (STOCK) Act of 2012, Public Law 112-105 of 4 April 2012, is the principal federal statute affirming that Members of Congress and federal officials are subject to the insider trading prohibitions arising under the securities laws and imposing additional disclosure and ethical requirements on federal officials, administered through the Securities and Exchange Commission, the Department of Justice, the Office of Government Ethics, and the ethics committees of the House and Senate. STOCK Act, section 2 contains the definitions establishing categories for Members of Congress, congressional employees, executive branch employees, judicial officers, and judicial employees for purposes of the Act. STOCK Act, section 4 states that Members of Congress and employees of Congress are not exempt from the insider trading prohibitions arising under the securities laws, including section 10(b) of the Securities Exchange Act of 1934 and Rule 10b-5. STOCK Act, section 6 requires the prompt reporting of financial transactions including the requirement that financial transaction disclosures be filed within 30 to 45 days of occurrence for specified officials. STOCK Act, section 8 mandates that financial disclosure forms be made available online within 30 days of filing, accessible without login requirements (later modified by subsequent legislation). STOCK Act, section 12 restricts covered individuals from purchasing initial public offering securities except in any manner other than is available to members of the public generally. STOCK Act, section 17 requires individuals to file statements within 3 business days of beginning negotiations for future private sector employment. STOCK Act, section 18 extends criminal prohibitions against wrongfully influencing private entity employment decisions to executive branch officers. The Act is the controlling federal instrument affirming insider trading prohibitions on federal officials and imposing transparency on their financial transactions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-stored-communications-act",
    "title": "US Stored Communications Act (18 USC ch 121): Stored Electronic Communications Privacy",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Stored Communications Act, Title II of the Electronic Communications Privacy Act (18 U.S.C. ch. 121), protects the privacy of electronic communications held in storage by service providers and governs both unauthorized access and provider disclosure, enforced criminally by the Department of Justice and through a civil action. Section 2701 makes it an offense to intentionally access without authorization, or exceed authorized access to, a facility through which an electronic communication service is provided and thereby obtain, alter or prevent authorized access to a wire or electronic communication in storage; the penalty is up to 5 years for a first offense committed for commercial advantage, malicious destruction or in furtherance of a crime, and otherwise up to 1 year. Section 2702 governs voluntary disclosure, generally prohibiting a provider to the public from divulging the contents of a stored communication except as permitted. Section 2703 sets the requirements for compelled government disclosure, including warrants for contents and lesser process for records. Section 2705 allows delayed notice, and section 2707 provides a civil action with minimum statutory damages and attorney fees. The Act is the legal foundation for US law enforcement access to and provider handling of stored communications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-surface-mining-control-and-reclamation-act",
    "title": "US Surface Mining Control and Reclamation Act (SMCRA, 30 USC ch 25): Permits, Performance Standards and the Abandoned Mine Reclamation Fund",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Surface Mining Control and Reclamation Act of 1977 (SMCRA, 30 U.S.C. ch. 25) is the federal statute regulating the environmental effects of surface coal mining and the reclamation of mined land, administered by the Office of Surface Mining Reclamation and Enforcement (OSMRE) within the Department of the Interior, with primacy delegable to approved state programs. Section 1201 records the Congressional findings that surface mining can cause erosion, landslides, flooding and water pollution, and section 1202 states the purpose of establishing a nationwide program to protect society and the environment from the adverse effects of surface coal mining. Section 1211 establishes OSMRE. Section 1232 imposes a reclamation fee of 22.4 cents per ton of coal produced by surface mining and 9.6 cents per ton of coal produced underground, paid into the Abandoned Mine Reclamation Fund established by section 1231, and section 1232(d)(1) makes a false statement in connection with the fee punishable by a fine of not more than 10,000 dollars or imprisonment for not more than one year. Subchapter V (sections 1251 to 1279) controls the environmental impacts of active mining: section 1251 provides for approved state regulatory programs, section 1256 requires a permit for surface coal mining operations, section 1265 sets the environmental performance standards a permittee must meet, and the enforcement provisions impose civil and criminal penalties for violations. The Act is the legal basis for permitting active coal mines, enforcing reclamation performance standards and funding the cleanup of abandoned mine lands.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-surface-mining-control-reclamation-act-smcra",
    "title": "Surface Mining Control and Reclamation Act of 1977",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Surface Mining Control and Reclamation Act (SMCRA) establishes permitting, environmental protection, reclamation, and enforcement requirements for coal mining operations in the United States. It applies to all surface coal mining and reclamation activities and mandates compliance with performance standards under 30 U.S.C. §§ 1201-1328, enforced by the Office of Surface Mining Reclamation and Enforcement (OSMRE).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-mining-waste-directive-2006-21-ec",
      "eiti-standard-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-surface-resources-materials-act-1947",
    "title": "US Materials Act of 1947 and Surface Resources Act (30 U.S.C. Chapter 15): Disposal of Mineral Materials and Common Varieties on Public Lands",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Materials Act of 1947, together with the Surface Resources Act of 1955, is codified at 30 U.S.C. Chapter 15 (Surface Resources, sections 601 through 615) and governs the disposal of common mineral materials such as sand, stone, gravel, and vegetative materials on public lands, and the treatment of common varieties under the mining laws, administered by the Bureau of Land Management. Section 601 authorizes the Secretary to dispose of mineral materials and vegetative resources on public lands, on payment of adequate compensation, with provision for free use in defined cases and exclusion of certain lands. Section 602 requires disposal by sale to the highest responsible qualified bidder after advertising, with conditions for negotiated contracts. Section 603 governs the disposition of moneys received from disposal. Section 611 provides that common varieties of sand, stone, gravel, pumice, pumicite, or cinders, and petrified wood, are not locatable under the mining laws and must instead be obtained by purchase under section 601. Section 612 provides that unpatented mining claims are subject to the right of the United States to manage and dispose of surface resources. Section 613 sets the procedure for determining title and surface-use uncertainties on mining claims, section 614 provides for the waiver of rights, and section 615 limits the effect on existing rights. The Act is the foundational statute for the sale of mineral materials and the common-varieties rule on federal lands.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-surplus-lines-reform-nonadmitted-reinsurance-act",
    "title": "Nonadmitted and Reinsurance Reform Act of 2010 (NRRA) - Home State Regulation, Surplus Lines Tax Allocation and Uniform Eligibility Standards",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "The Nonadmitted and Reinsurance Reform Act of 2010 (NRRA), enacted as part of the Dodd-Frank Act, establishes the insured's \"home state\" as the sole jurisdiction for regulating and taxing nonadmitted (surplus lines) insurance transactions. This simplifies compliance by making the home state's laws exclusively applicable to the placement and taxation of a multi-state surplus lines policy, as mandated by 15 U.S.C. § 8201 (Sec. 521).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-swine-health-protection-act",
    "title": "US Swine Health Protection Act (7 USC ch 69): Garbage Feeding Prohibition and Treatment Permits",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Swine Health Protection Act (7 U.S.C. ch. 69, sections 3801 to 3813) regulates the feeding of garbage to swine to prevent the transmission of infectious and communicable diseases, administered by the Secretary of Agriculture through the Animal and Plant Health Inspection Service. Section 3801 sets out the congressional findings and declaration of purpose, finding that raw garbage is one of the primary media through which numerous infectious or communicable diseases of swine are transmitted. Section 3802 defines the terms, providing that garbage means all waste material derived in whole or in part from the meat of any animal resulting from the handling, preparation, cooking, or consumption of food, and defining swine. Section 3803 prohibits the feeding of garbage to swine except in accordance with the Act and provides that garbage may be fed to swine only if it has been treated to kill disease organisms. Section 3804 requires permits to operate a garbage treatment facility, with facilities meeting disease prevention standards and preventing swine access to untreated garbage. Section 3805 sets the civil penalties, providing for a penalty of up to 10,000 dollars for each violation, and section 3806 sets the criminal penalties, providing that a violator shall be fined not more than 10,000 dollars, or imprisoned not more than one year, or both. Section 3807 sets the general enforcement provisions, section 3808 provides for cooperation with the States, and section 3811 requires the issuance of regulations and the maintenance of records. The Act is the federal regime preventing disease transmission through garbage feeding of swine.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-take-it-down-act-2025",
    "title": "TAKE IT DOWN Act - 47 U.S.C. 223(h) and Notice-and-Removal Regime for Nonconsensual Intimate Visual Depictions (Pub. L. 119-12, May 2025)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (TAKE IT DOWN Act, Pub. L. 119-12, signed 19 May 2025) amends Section 223 of the Communications Act of 1934 (47 U.S.C. 223) by adding a new subsection (h) that criminalises the intentional publication of nonconsensual intimate visual depictions over interactive computer services in interstate or foreign commerce. Section 2 covers offences involving authentic intimate visual depictions of adults and minors and digital forgeries (including AI-generated, machine-learning, software-altered or otherwise computer-generated depictions that are indistinguishable from authentic depictions when viewed by a reasonable person). Section 3 (47 U.S.C. 223a note) requires covered platforms to (i) within one year of enactment, establish a notice-and-removal process; (ii) on receipt of a valid removal request, remove the intimate visual depiction and make reasonable efforts to identify and remove identical copies as soon as possible but not later than 48 hours; (iii) provide a clear and conspicuous notice of the process in plain language. A good-faith safe harbour applies to platforms that disable or remove material based on apparent unlawful publishing. The FTC enforces Section 3 under Section 18(a)(1)(B) of the FTC Act (15 U.S.C. 57a(a)(1)(B)) and may pursue non-profit organisations notwithstanding the usual jurisdictional limits in 15 U.S.C. 44, 45(a)(2) and 46. Covered platforms exclude broadband ISPs, email and content services without user-generated content. Restitution under 18 U.S.C. 2264 and forfeiture under 21 U.S.C. 853 apply.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_no_fakes_act_2023_digital_replicas_ai",
        "us_americas_ai_action_plan_2025",
        "us_eo_14179_ai_2025",
        "eu_ai_act",
        "uk_online_safety_act_2023"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-no-fakes-act-2023-digital-replicas-ai",
      "us-americas-ai-action-plan-2025",
      "us-eo-14179-ai-2025",
      "uk-online-safety-act-2023"
    ],
    "primary_citations_count": 16
  },
  {
    "node_id": "us-tariff-act-1930-title-19-chapter-4",
    "title": "United States Tariff Act of 1930 (Title 19 USC Chapter 4): Harmonized Tariff Schedule, Marking of Imports, Entry of Merchandise, Examination, and Penalties for Fraud, Gross Negligence, and Negligence",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Tariff Act of 1930, codified at Title 19 of the United States Code, Chapter 4, is the foundational federal statute governing the assessment and collection of customs duties and the regulation of imported merchandise into the United States and is administered by United States Customs and Border Protection. Subtitle I sets out the Harmonized Tariff Schedule of the United States in Tariff Act 1930, 19 U.S.C. 1202, which is maintained and published periodically by the United States International Trade Commission and is not published in the Code. Subtitle II contains special provisions including Tariff Act 1930, 19 U.S.C. 1304, which requires that every article of foreign origin or its container shall be marked in a conspicuous place as legibly, indelibly, and permanently as the nature of the article permits, to indicate to an ultimate purchaser in the United States the English name of the country of origin, and Tariff Act 1930, 19 U.S.C. 1337, which addresses unfair practices in import trade enforceable through the United States International Trade Commission. Subtitle III contains administrative provisions including Tariff Act 1930, 19 U.S.C. 1481, on the contents of invoices, Tariff Act 1930, 19 U.S.C. 1484, on the entry of merchandise by the importer of record, Tariff Act 1930, 19 U.S.C. 1499, on the examination of merchandise by Customs, and Tariff Act 1930, 19 U.S.C. 1592, which imposes civil penalties on persons who enter, introduce, or attempt to enter or introduce merchandise into the commerce of the United States by means of fraud, gross negligence, or negligence. Subtitle IV addresses countervailing and antidumping duties under Tariff Act 1930, 19 U.S.C. 1671 through 19 U.S.C. 1677. The Act is the controlling federal instrument for the entry, marking, examination, valuation, and lawful importation of merchandise into the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-tax-court-26-usc-ch76-subch-c",
    "title": "United States Tax Court (Title 26 USC Chapter 76 Subchapter C): Article I Court of Record Status, Jurisdiction, Nineteen-Member Composition, Special Trial Judges, Sessions, and Appellate Review",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The United States Tax Court, established by Subchapter C of Chapter 76 of Title 26 of the United States Code, is a court of record under Article I of the Constitution of the United States with jurisdiction conferred on it by the Internal Revenue Code to redetermine federal tax deficiencies and certain other tax-related controversies. Tax Court, 26 U.S.C. 7441 establishes the status: there is hereby established, under article I of the Constitution of the United States, a court of record to be known as the United States Tax Court. Tax Court, 26 U.S.C. 7442 sets the jurisdiction: the Tax Court and its divisions shall have such jurisdiction as is conferred on them by this title and the Internal Revenue Code of 1939. Tax Court, 26 U.S.C. 7443 sets the membership: the Tax Court shall be composed of 19 members. Tax Court, 26 U.S.C. 7443A authorises the chief judge to appoint special trial judges who proceed under such rules and regulations as the Tax Court may establish. Tax Court, 26 U.S.C. 7444 governs the organization of the Court. Tax Court, 26 U.S.C. 7445 governs offices. Tax Court, 26 U.S.C. 7446 governs times and places of sessions: the times and places of the sessions of the Tax Court and of its divisions shall be prescribed by the chief judge. Tax Court, 26 U.S.C. 7447 and 7447A govern retirement, including for special trial judges. Tax Court, 26 U.S.C. 7448 governs annuities to surviving spouses and dependent children. Tax Court decisions are subject to review in the United States Courts of Appeals. The Subchapter is the controlling federal instrument for the Tax Court's status, jurisdiction, and composition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-tax-cuts-jobs-act-international-tax-provisions-2017",
    "title": "An Act to provide for reconciliation pursuant to titles II and V of the concurrent resolution on the budget for fiscal year 2018",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The US Tax Cuts and Jobs Act 2017 requires US shareholders of controlled foreign corporations (CFCs) to include in gross income their GILTI, as defined in Section 951A. This applies to US persons who own, directly or indirectly, at least 10% of the total combined voting power of all classes of stock of a foreign corporation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "oecd-attribution-profits-permanent-establishments-2010"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-tax-reform-act-1986-pl-99-514",
    "title": "US Tax Reform Act of 1986 (Public Law 99-514) - Internal Revenue Code Recodification",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Tax Reform Act of 1986 recodified the Internal Revenue Code as Title 26 USC, broadened the individual income tax base by repealing or limiting many deductions and preferences, lowered the top individual rate from 50 percent to 28 percent and the top corporate rate from 46 percent to 34 percent, equalized the tax treatment of long-term capital gains and ordinary income for individuals, introduced the passive activity loss rules of 26 USC 469, modified the alternative minimum tax for both individuals and corporations, and rewrote the depreciation system as the Modified Accelerated Cost Recovery System.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-tax-cuts-jobs-act-international-tax-provisions-2017",
      "us-tax-court-26-usc-ch76-subch-c"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-taylor-grazing-act",
    "title": "US Taylor Grazing Act (43 USC ch 8A): Grazing Districts and Permits on Public Lands",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Taylor Grazing Act (43 U.S.C. ch. 8A, sections 315 to 316o) authorizes the regulation of livestock grazing on the federal public lands of the United States and is administered by the Secretary of the Interior through the Bureau of Land Management. Section 315 authorizes the Secretary to establish grazing districts of vacant, unappropriated, and unreserved lands of the public domain that are chiefly valuable for grazing and the raising of forage crops, subject to the recognition of valid prior rights and the reservation of rights-of-way. Section 315a directs the Secretary to provide for the protection, administration, regulation, and improvement of the grazing districts and to make rules to accomplish the purposes of the Act and to ensure the orderly use of the range. Section 315b authorizes the Secretary to issue grazing permits to settlers, residents, and other stock owners upon the payment annually of reasonable fees, with a permit not to exceed a period of ten years, and preserves vested water rights. Section 315i provides for the distribution to the States of 12 and one half per centum of the grazing fees collected within their boundaries. The Act ended the unregulated use of the western range, established the permit system that remains the basis of public-land grazing, and is a foundational statute of United States rangeland management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-tcpa-1991-telephone-consumer",
    "title": "Telephone Consumer Protection Act of 1991 (TCPA)",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Telephone Consumer Protection Act (TCPA) restricts telemarketing calls, the use of automated telephone equipment, and unsolicited texts and faxes. As codified in 47 U.S.C. § 227, it requires businesses to obtain prior express written consent from consumers before making autodialed or prerecorded marketing calls or sending marketing texts to wireless numbers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "can-spam-act-email",
      "gdpr-art-21-marketing-optout",
      "ccpa-cpra-optout-sale"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-tcpa-1991-telephone-consumer-protection-act",
    "title": "US TCPA 1991 - Telephone Consumer Protection Act, Auto-Dialer Consent and Do-Not-Call Registry",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Telephone Consumer Protection Act of 1991 (TCPA), codified at 47 U.S.C. 227 and implemented through 47 C.F.R. 64.1200 regulations issued by the Federal Communications Commission (FCC), is the principal federal statute regulating unwanted telephone solicitations, automated telephone calls (robocalls), text messages, and unsolicited faxes in the United States. Section 227(b)(1)(A) prohibits any call (other than a call made for emergency purposes or with prior express consent) to any wireless number using an automatic telephone dialing system (ATDS) or an artificial or prerecorded voice. Section 227(b)(1)(B) restricts prerecorded calls to residential lines. Section 227(c) establishes the National Do-Not-Call Registry maintained by the Federal Trade Commission since 2003 with telemarketers obligated to scrub their call lists. Section 227(c)(5) creates a private right of action with statutory damages of USD 500 per violation (USD 1,500 if willful or knowing) plus injunctive relief. The Supreme Court in Facebook v. Duguid (2021) narrowed the ATDS definition to systems with random or sequential number generation capability, significantly affecting TCPA litigation. The TRACED Act 2019 imposed STIR/SHAKEN call authentication requirements on voice service providers to combat caller ID spoofing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-consumer-rights-directive-2011-83-distance-sales",
      "au-spam-act-2003-commercial-electronic-messages-consent"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-tcpa-47-cfr-64-autodialer-consent-robocall-requirements",
    "title": "US TCPA (Telephone Consumer Protection Act) - 47 CFR Part 64 Autodialer Consent, Do Not Call, and Robocall Restrictions",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "The TCPA (47 USC 227; 47 CFR Part 64) prohibits autodialed or prerecorded calls/texts to mobile numbers and residential lines without prior express consent; marketing calls require prior express written consent. Callers must scrub against the National Do Not Call Registry; time restrictions (8am-9pm) apply. Statutory damages: $500-$1,500 per violation with class action exposure.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "regulation_reference",
        "framework_alignment",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-tcpa-telephone-consumer-protection-act",
    "title": "US TCPA Telephone Consumer Protection Act - Autodialer Restrictions, Prior Express Consent and Do-Not-Call Registry Compliance",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Telephone Consumer Protection Act (TCPA) restricts telemarketing communications, specifically prohibiting the use of automatic telephone dialing systems (autodialers) and artificial or prerecorded voice messages to call cell phones without prior express written consent. As codified in 47 U.S.C. § 227, it also requires entities to maintain an internal do-not-call list and honor the National Do-Not-Call Registry.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-tcpa-telephone-consumer-protection-act-1991",
    "title": "Telephone Consumer Protection Act of 1991, 47 U.S.C. § 227",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The TCPA restricts the use of automatic telephone dialing systems (ATDS), artificial or prerecorded voice messages, and unsolicited text messages to wireless numbers without prior express consent. It applies to all entities conducting telemarketing, informational, or transactional calls or texts to U.S. consumers, with key restrictions under 47 U.S.C. § 227(b)(1)(A)(iii) and (b)(1)(B).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ftc-ai-enforcement-guidance",
      "eu-unfair-commercial-practices-directive",
      "us-federal-crop-insurance-act-1938-7-usc-1501"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-telecommunications-act-1996",
    "title": "Telecommunications Act of 1996",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The US Telecommunications Act of 1996 mandates the opening of local telecommunications markets to competition by requiring incumbent local exchange carriers (ILECs) to interconnect with competitors under Section 251, and establishes the universal service principle under Section 254 to ensure affordable, quality services for all Americans, including those in rural and high-cost areas.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-cybersecurity-framework-2-0",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-telecommunications-act-1996-fcc-broadband-neutrality",
    "title": "US Telecommunications Act 1996 - FCC Common Carrier and Broadband Regulation",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Telecommunications Act of 1996 (Pub.L. 104-104) modernised US communications law, establishing FCC authority over common carriers, interconnection, universal service (USF), and spectrum management; the FCC reclassified broadband as Title II telecommunications service in 2024 (restoring net neutrality), reversing the 2017 reclassification.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-telephone-consumer-protection-act",
    "title": "US Telephone Consumer Protection Act (47 USC 227): Autodialed Calls, the Do-Not-Call Registry and Statutory Damages",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Telephone Consumer Protection Act of 1991 (TCPA, 47 U.S.C. 227) restricts unsolicited automated calls, prerecorded messages, and faxes, and is enforced by the Federal Communications Commission and through a private right of action. Subsection 227(a) supplies the definitions, including automatic telephone dialing system (equipment with the capacity to store or produce numbers using a random or sequential number generator and to dial them). Subsection 227(b) is the core restriction: it is unlawful to make a call using an automatic telephone dialing system or an artificial or prerecorded voice to an emergency line, a hospital room, or a cellular or paging service without the prior express consent of the called party, except for emergencies or limited circumstances, and subsection 227(b)(3) confers a private right of action allowing recovery of actual loss or 500 dollars per violation, whichever is greater, trebled to 1,500 dollars for a willful or knowing violation. Subsection 227(c) directs the establishment of the national Do-Not-Call registry to protect subscriber privacy, with a private action for repeated violations under 227(c)(5). Subsection 227(d) sets technical and procedural standards, including caller identification on prerecorded messages. Subsection 227(e) prohibits the transmission of misleading or inaccurate caller identification information, and subsection 227(g) authorizes enforcement actions by the States. The Act is the legal foundation of US telemarketing and robocall compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-telephone-consumer-protection-act-2024-tcpa-updates",
    "title": "Telephone Consumer Protection Act - 2024 FCC Updates: One-to-One Consent, Revocation Standards, AI Voice Classification, and Predictive Dialer Liability",
    "domain": "Sales, Marketing & PR",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The 2024 FCC updates to the TCPA require prior express written consent for all artificial or prerecorded voice calls, including those using AI-generated voices, with consent limited to a single seller and not transferable among partners. Revocation of consent must be honored via any reasonable method, and willful violations involving predictive dialers or AI voices may incur penalties up to $1,500 per call under 47 U.S.C. § 227(b)(3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "can-spam-act-email",
      "ftc-digital-advertising-disclosures",
      "coppa-marketing-kids",
      "eu-unfair-commercial-practices-2005-29",
      "nist-privacy-framework-1-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-tennessee-information-protection-act-tipa-2023",
    "title": "Tennessee Information Protection Act (TIPA)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2025-07-01",
    "bluf": "The Tennessee Information Protection Act (TIPA) applies to controllers who conduct business in Tennessee or produce products/services for its residents, exceed $25 million in annual revenue, and either control/process personal information of at least 25,000 consumers while deriving over 50% of gross revenue from selling personal information, or control/process personal information of at least 175,000 consumers. The Act, effective July 1, 2025, establishes consumer rights (access, correction, deletion, portability, opt-out) and controller obligations, including conducting data protection assessments for high-risk processing activities per Tenn. Code Ann. § 47-18-3107.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-privacy-framework-1-0",
      "iso-27701-privacy-information-management",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-tennessee-sports-gaming-act-2019",
    "title": "Tennessee Sports Gaming Act 2019 - Online-Only Sports Betting Licensing",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "The Tennessee Sports Gaming Act 2019 (Public Chapter 512; Tenn. Code Ann. 4-40-101 et seq.) established a unique online-only sports betting regime with no retail sportsbooks. The Tennessee Education Lottery Corporation initially administered licensing; a new Sports Wagering Advisory Council was created to oversee the industry. Operators pay a 20% tax on adjusted gross income. A mandatory 10% hold requirement (hold rate of wagering handle) distinguishes Tennessee from all other US sports betting markets. Sports betting launched 1 November 2020.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_paspa_repeal",
        "tennessee_lottery",
        "sports_wagering_advisory_council",
        "fatf_aml_gambling",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
      "us-uigea-2006-unlawful-internet-gambling",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-terrorism-risk-insurance-act-tria-2002",
    "title": "Terrorism Risk Insurance Act of 2002 (TRIA): Federal Backstop, Mandatory Offer Requirements and Programme Trigger Thresholds",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This U.S. federal law requires commercial property and casualty insurers to offer terrorism risk insurance to their policyholders and establishes a federal backstop program to share losses from certified acts of terrorism, as mandated by Section 103(c) of the Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "bcbs-principles-operational-resilience"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-terrorism-risk-insurance-act-tria-2022-extension",
    "title": "Terrorism Risk Insurance Program Reauthorization Act of 2019 - Extension of the Terrorism Risk Insurance Program Through December 31, 2027",
    "domain": "Insurance & Risk",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Terrorism Risk Insurance Act (TRIA), as extended by the Terrorism Risk Insurance Program Reauthorization Act of 2019, mandates that insurers offer terrorism risk coverage in commercial property and casualty policies and establishes a federal backstop for insured losses resulting from a certified act of terrorism, with a program trigger at $200 million in industry losses and a federal share of 80% after insurer retention. This applies to all primary insurers of commercial property and casualty insurance in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "australia-apra-gps-220-risk-management-general-insurers",
      "canada-osfi-e19-own-risk-solvency-2023",
      "eu-delegated-regulation-2016-2067-spread-market-risk",
      "china-cbirc-c-ross-ii-solvency-2022",
      "eu-eiopa-guidelines-orsa-2015"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-texas-data-privacy-security-act-tdpsa-2023",
    "title": "Texas Data Privacy and Security Act (TDPSA)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2024-07-01",
    "bluf": "The Texas Data Privacy and Security Act (TDPSA) requires businesses controlling or processing Texans' personal data to obtain explicit consent before processing sensitive data (Sec. 541.101(b)) and provides specific consumer rights, while exempting small businesses as defined by the U.S. Small Business Administration (Sec. 541.002(a)).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "nist-privacy-framework-1-0",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-texas-hb-1181-2023-age-verification-explicit-content",
    "title": "Texas HB 1181 (88R 2023) - Age Verification for Commercial Entities Publishing Sexual Material Harmful to Minors",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-05-31",
    "bluf": "Texas HB 1181 (88th Legislature Regular Session 2023) added Civil Practice and Remedies Code Chapter 129B requiring any commercial entity that publishes or distributes material on an internet website where more than one-third of the material is sexual material harmful to minors to verify that every person attempting to access the material is 18 or older using reasonable age verification methods. Acceptable methods are digital identification or a commercial age-verification system that uses government-issued identification or a commercially reasonable method relying on public or private transactional data. The commercial entity and any third-party verifier may not retain identifying information of the user. Landing pages must display Texas Health and Human Services warnings about pornography in at least 14-point font and SAMHSA helpline notices on every page. Civil penalties: $10,000 per day of non-compliance, $10,000 per instance of unlawful data retention, and up to $250,000 if a minor accesses material due to the violation. Effective September 1, 2023. The statute was challenged in Free Speech Coalition v Paxton; the US Supreme Court upheld it in 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "free_speech_coalition_v_paxton",
        "miller_test_anchor",
        "samhsa_helpline_anchor",
        "louisiana_act_440_parallel",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "us-tila-fdcpa-ecoa-15-usc-ch41",
    "title": "United States Title 15 USC Chapter 41 - Federal Credit Disclosure Framework: Truth in Lending Act, Equal Credit Opportunity Act, Fair Debt Collection Practices Act, Electronic Fund Transfer Act, and CFPB Rule-Making",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Title 15 of the United States Code, Chapter 41, is the principal federal credit and debt collection statute consolidating the Truth in Lending Act, the Fair Credit Reporting Act, the Equal Credit Opportunity Act, the Fair Debt Collection Practices Act, and the Electronic Fund Transfer Act, and is administered by the Bureau of Consumer Financial Protection (CFPB) and other regulators. Federal Credit Disclosure, 15 U.S.C. 1601 opens Subchapter I (Truth in Lending) declaring that the informed use of credit results from an awareness of the cost thereof by borrowers. Federal Credit Disclosure, 15 U.S.C. 1602 sets out the definitions and rules of construction including that the term Bureau means the Bureau of Consumer Financial Protection. Federal Credit Disclosure, 15 U.S.C. 1604 provides that the Bureau shall prescribe regulations to carry out the purposes of the subchapter, the source of Regulation Z. Federal Credit Disclosure, 15 U.S.C. 1635 governs the right of rescission for certain credit transactions. Federal Credit Disclosure, 15 U.S.C. 1640 sets out civil liability for violations of the Truth in Lending Act. Federal Credit Disclosure, 15 U.S.C. 1666 governs correction of billing errors. Subchapter II addresses restrictions on garnishment. Subchapter II-A addresses credit repair organizations. Subchapter III contains the Fair Credit Reporting Act provisions on credit reporting agencies. Subchapter IV contains the Equal Credit Opportunity Act including Federal Credit Disclosure, 15 U.S.C. 1691 setting the scope of the prohibition on discrimination in any aspect of a credit transaction on a prohibited basis. Subchapter V contains the Fair Debt Collection Practices Act opening with Federal Credit Disclosure, 15 U.S.C. 1692 Congressional findings and declaration of purpose. Subchapter VI contains the Electronic Fund Transfer Act. The Chapter is the controlling federal instrument for federal credit and debt collection law in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-title-ix-34-cfr-part-106-sex-discrimination",
    "title": "34 CFR Part 106 - Nondiscrimination on the Basis of Sex in Education Programs or Activities Receiving Federal Financial Assistance",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-07",
    "bluf": "Recipients of Federal financial assistance must not discriminate on the basis of sex and must implement specific procedural safeguards, including appointing a coordinator, adopting grievance procedures, and providing notice of their nondiscrimination policy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "us-title-ix-sex-discrimination-education-2022",
    "title": "Nondiscrimination on the Basis of Sex in Education Programs or Activities Receiving Federal Financial Assistance (Title IX Final Rule 2024)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This rule requires educational institutions receiving federal funding to promptly and effectively respond to all complaints of sex discrimination, including sexual harassment, with fair and reliable grievance procedures. As specified in 34 C.F.R. Part 106, it expands protections for students and employees based on sexual orientation, gender identity, and pregnancy or related conditions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-title-vii-civil-rights-1964",
    "title": "Title VII of the Civil Rights Act of 1964",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This US federal law prohibits employers with 15 or more employees from discriminating against individuals on the basis of race, color, religion, sex, or national origin in any aspect of employment. Section 703(a) makes it an unlawful employment practice to fail or refuse to hire, to discharge, or otherwise to discriminate against any individual with respect to compensation, terms, conditions, or privileges of employment because of these protected characteristics.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eeoc-employment-rule",
      "ada-employment-title-1",
      "flsa-compliance-labor",
      "fmla-compliance-leave",
      "shrm-hr-competency"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-tn-elvis-act-2024",
    "title": "Tennessee Ensuring Likeness, Voice, and Image Security Act 2024, ELVIS Act HB 2091 / SB 2096 - Right of Publicity for Voice and AI Replicas, Effective 1 July 2024",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Persons publishing, performing, distributing, transmitting, or otherwise making available to the public an individual's voice or likeness in Tennessee without authorization, or distributing, transmitting, or otherwise making available an algorithm, software, tool, or other technology, service, or device to produce a person's voice or likeness without authorization, face liability under the Tennessee ELVIS Act 2024 (HB 2091 / SB 2096, signed by Governor Bill Lee on 21 March 2024, effective 1 July 2024, codified in Tennessee Code Annotated Section 47-25-1101 et seq.), which adds voice as a protected attribute, defines voice as a sound in a medium readily identifiable and attributable to a particular individual including simulated voice, expands liability to any purpose, and restricts the fair use exemption to the extent protected by the First Amendment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ca-ab-853-ai-transparency-act-amendments-2025"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-tn-tipa-2023",
    "title": "US Tennessee Information Protection Act 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Tennessee Information Protection Act grants consumers rights to access, correct, delete, and port personal data and to opt out of targeted advertising, sale, and profiling, requires opt-in consent for sensitive data, mandates data protection assessments for high-risk processing, recognises NIST Privacy Framework compliance as an affirmative defence to enforcement, and authorises the Tennessee Attorney General to impose civil penalties of up to USD 15,000 per violation with a mandatory 60-day cure period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-tn-tipa-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ccpa-cpra-2023-marketing-rights"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-tobacco-statistics-act",
    "title": "US Tobacco Statistics Act (7 USC ch 21): Mandatory Quarterly Reporting of Leaf Tobacco Stocks",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Tobacco Statistics Act (7 U.S.C. ch. 21, sections 501 to 509) requires the collection and publication of statistics on leaf tobacco held in the United States, administered by the Secretary of Agriculture. Section 501 directs the Secretary to collect and publish statistics of the quantity of leaf tobacco in all forms, classified by type, grade, and quality, including deteriorated tobacco, and exempts holders below stated thresholds of 35,000 pounds of leaf tobacco, 185,000 cigars, or 750,000 cigarettes. Section 502 directs the Secretary to establish standards for the classification of leaf tobacco and to furnish report forms. Section 503 requires every dealer and manufacturer to report their tobacco holdings within fifteen days after January 1, April 1, July 1, and October 1 of each year, and makes failure to report, or a false report, punishable by a fine of not less than 300 dollars or more than 1,000 dollars, or imprisonment for not more than one year. Section 504 defines person to include partnerships, corporations, and associations; section 505 authorizes access to internal-revenue records for compliance; section 506 requires returns under oath; and section 507 limits the use of the information to statistical purposes and protects data identifying individual establishments. Section 508 is a separability clause and section 509 has been repealed. The Act is the federal statistical reporting regime for the tobacco trade.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-toxic-substances-control-act",
    "title": "US Toxic Substances Control Act (TSCA, 15 USC ch 53): Premanufacture Notice, Risk Evaluation and Penalties",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Toxic Substances Control Act (TSCA), codified at 15 U.S.C. Chapter 53 (subchapter I, sections 2601-2629), gives the US Environmental Protection Agency (EPA) authority to regulate the manufacture, processing, distribution, use and disposal of chemical substances and mixtures, as substantially amended by the Frank R. Lautenberg Chemical Safety for the 21st Century Act of 2016. Section 2601 states the findings and policy, and section 2602 defines the regulated terms, including 'chemical substance', 'mixture', 'manufacture' and 'new chemical substance'. Section 2603 authorizes EPA to require testing of chemical substances and mixtures. Section 2604 requires premanufacture notification: no person may manufacture a new chemical substance, or manufacture or process a substance for a significant new use, unless that person submits to the Administrator, at least 90 days before such manufacture or processing, a notice of intention to manufacture or process the substance, and EPA reviews it. Section 2605 establishes the framework for prioritizing chemicals, conducting risk evaluations, and regulating substances that present an unreasonable risk of injury to health or the environment, including bans, restrictions and conditions. Section 2606 addresses imminent hazards, and section 2607 imposes reporting and recordkeeping requirements (including the Chemical Data Reporting rule and substantial-risk reporting). Section 2611 governs exports and section 2612 imports. Section 2610 confers inspection and subpoena authority. Section 2614 sets out the prohibited acts, and section 2615 sets the penalties: a civil penalty of not more than $37,500 for each violation, with each day of a continuing violation constituting a separate violation; a criminal penalty for a knowing or willful violation of a fine of not more than $50,000 for each day of violation, or imprisonment of not more than one year, or both; and, for a knowing endangerment placing another in imminent danger of death or serious bodily injury, a fine of not more than $250,000 or imprisonment of not more than fifteen years, or both (and a fine of not more than $1,000,000 for an organization). Penalty figures are subject to inflation adjustment by regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-trade-act-1974-19-usc-ch12",
    "title": "United States Trade Act of 1974 (Title 19 USC Chapter 12): Short Title, Basic Authority for Trade Agreements, Section 301 Actions by the United States Trade Representative, Initiation of Investigations, Implementation of Actions, Generalized System of Preferences, and Designation of Beneficiary Developing Countries",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Trade Act of 1974, Public Law 93-618 of 3 January 1975, codified at Title 19 of the United States Code, Chapter 12 (Trade Act of 1974), is the principal federal statute providing the framework for United States trade negotiations, import relief mechanisms, the Section 301 enforcement tool, the Generalized System of Preferences, and trade adjustment assistance, and is administered by the Office of the United States Trade Representative (USTR), the International Trade Commission, and the Department of Commerce. Trade Act of 1974, 19 U.S.C. 2101 sets the short title. Trade Act of 1974, 19 U.S.C. 2111 sets the basic authority for trade agreements. Trade Act of 1974, 19 U.S.C. 2411 contains Section 301 of the Trade Act of 1974 governing actions by the United States Trade Representative including the mandatory and discretionary action provisions in response to unjustifiable, unreasonable, or discriminatory acts, policies, or practices by foreign governments that burden or restrict United States commerce. Trade Act of 1974, 19 U.S.C. 2412 governs initiation of Section 301 investigations including petition requirements. Trade Act of 1974, 19 U.S.C. 2415 governs implementation of actions including duties, fees, and other import restrictions. Trade Act of 1974, 19 U.S.C. 2461 provides the authority to extend preferences through the Generalized System of Preferences (GSP). Trade Act of 1974, 19 U.S.C. 2462 governs the designation of beneficiary developing countries. The Act is the controlling federal instrument for trade enforcement, trade preferences, and trade adjustment assistance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-trade-agreements-act-1979-19-usc-ch13",
    "title": "United States Trade Agreements Act of 1979 (Title 19 USC Chapter 13): Short Title, Congressional Statement of Purposes, Approval of Trade Agreements, General Authority to Modify Discriminatory Purchasing Requirements, Authority to Encourage Reciprocal Competitive Procurement Practices, Civil Aircraft Waiver, and Standards-Related Activities",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Trade Agreements Act of 1979, Public Law 96-39 of 26 July 1979, codified at Title 19 of the United States Code, Chapter 13, is the principal federal statute providing the framework for implementing trade agreements negotiated under the Trade Act of 1974 with particular emphasis on government procurement practices and technical standards harmonization, and is the source of the Trade Agreements Act country-of-origin rule for United States federal procurement administered by the Office of the United States Trade Representative, the Department of Commerce, and the General Services Administration. Trade Agreements Act of 1979, 19 U.S.C. 2501 sets the short title. Trade Agreements Act of 1979, 19 U.S.C. 2502 contains the Congressional statement of purposes. Trade Agreements Act of 1979, 19 U.S.C. 2503 provides for the approval of trade agreements negotiated under the Trade Act of 1974, including the Tokyo Round Agreements. Trade Agreements Act of 1979, 19 U.S.C. 2511 provides the general authority to modify discriminatory purchasing requirements. Trade Agreements Act of 1979, 19 U.S.C. 2512 provides the authority to deny benefits including the authority to encourage reciprocal competitive procurement practices. Trade Agreements Act of 1979, 19 U.S.C. 2513 provides for the civil aircraft waiver. Trade Agreements Act of 1979, 19 U.S.C. 2531 governs standards-related activities under international obligations. Trade Agreements Act of 1979, 19 U.S.C. 2532 governs federal standards-related activities. The Act is the controlling federal instrument for the country-of-origin rule applicable to United States federal procurement subject to the WTO Government Procurement Agreement and bilateral free trade agreement procurement chapters.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-trade-expansion-act-1962-19-usc-ch7",
    "title": "United States Trade Expansion Act of 1962 (Title 19 USC Chapter 7): Statement of Purposes, Definitions, Basic Authority for Trade Agreements, Section 232 Safeguarding National Security, Establishment of Interagency Trade Organization, Normal Trade Relations, and General Tariff Adjustment Authority",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Trade Expansion Act of 1962, Public Law 87-794 of 11 October 1962, codified at Title 19 of the United States Code, Chapter 7 (Trade Expansion Program), is the principal federal statute establishing the Presidential authority to conduct tariff negotiations and the national security imports safeguard, and is administered by the Office of the United States Trade Representative and the Department of Commerce. Trade Expansion Act of 1962, 19 U.S.C. 1801 sets the statement of purposes including expanding foreign markets for the products of the United States. Trade Expansion Act of 1962, 19 U.S.C. 1806 contains the definitions. Trade Expansion Act of 1962, 19 U.S.C. 1821 confers the basic authority for trade agreements between 1962 and 1967. Trade Expansion Act of 1962, 19 U.S.C. 1862 contains the section 232 national security safeguard providing that upon request of the head of any department or agency, upon application of an interested party, or upon his own motion, the Secretary of Commerce shall immediately initiate an appropriate investigation to determine the effects on the national security of imports of the article which is the subject of such request, application, or motion. Trade Expansion Act of 1962, 19 U.S.C. 1872 provides for the establishment of an interagency trade organization. Trade Expansion Act of 1962, 19 U.S.C. 1881 contains the normal trade relations principle. Trade Expansion Act of 1962, 19 U.S.C. 1981 provides general authority regarding tariff adjustments. The Act and especially the Section 232 authority is the controlling federal instrument for national security tariff investigations and remedies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-trade-expansion-act-section-232-19-usc-1862",
    "title": "Trade Expansion Act 1962 Section 232 - 19 USC 1862 National Security Tariffs",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 1862 of title 19 of the United States Code, section 232 of the Trade Expansion Act of 1962 (Public Law 87-794, enacted 11 October 1962), authorises the Secretary of Commerce to investigate the effect of imports of any article on the national security of the United States, and authorises the President to adjust imports of that article and its derivatives if the President concurs in the Secretary's affirmative finding. The Secretary must consult with the Secretary of Defense on methodology, may hold public hearings, and must submit findings to the President within 270 days of initiation. The President has 90 days to determine whether to adjust imports through tariffs, quotas, tariff-rate quotas, or other measures, and 15 days to implement. For petroleum specifically, Congress may pass a joint resolution of disapproval. The national security definition extends beyond strict military to include domestic production necessary for projected defense requirements, the economic welfare of domestic industries, and the impact of foreign competition. Section 232 was the basis of major recent tariff actions including the 2018 steel and aluminum tariffs (Proclamations 9704 and 9705), the 2020 derivative steel and aluminum tariffs (Proclamation 9980), and the 2025 industry-specific tariff actions. Compliance officers must integrate Section 232 monitoring for any imported article potentially subject to investigation or proclamation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-trade-act-1974-19-usc-ch12",
      "wto-scm-agreement-1994-subsidies-countervailing"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-trading-with-the-enemy-act",
    "title": "US Trading With the Enemy Act (50 U.S.C. Chapter 53): Presidential Authority to Regulate and Prohibit Transactions With Enemy and Foreign Interests During War",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Trading With the Enemy Act (TWEA), originally enacted in 1917 and codified at 50 U.S.C. Chapter 53 (sections 4301 through 4341), authorizes the President during time of war to regulate or prohibit trade and economic transactions with enemy and ally-of-enemy interests, and is the historical predicate for several long-standing United States sanctions programs administered by the Department of the Treasury through the Office of Foreign Assets Control. Section 4302 sets out the definitions, including enemy and ally of enemy. Section 4303 prohibits specified acts of trading with the enemy. Section 4304 governs licenses to enemy or ally-of-enemy insurance or reinsurance companies. Section 4305 authorizes the President, during time of war, to investigate, regulate, or prohibit transactions in foreign exchange and to investigate, regulate, direct, compel, nullify, void, prevent, or prohibit any acquisition, holding, or transfer of property in which any foreign country or a national thereof has an interest. Section 4306 establishes the Alien Property Custodian and the general powers and duties of that office. Section 4311 prohibits specified importations. Section 4312 governs property transferred to the Alien Property Custodian. Section 4315 sets out the offenses, the punishment, and the forfeitures of property. The Act predates and complements the International Emergency Economic Powers Act, which now governs the use of similar economic authorities during a declared national emergency short of a state of war.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-trading-with-the-enemy-act-50-usc-4301",
    "title": "US Trading with the Enemy Act (50 USC 4301) - Wartime Economic Sanctions Authority",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Trading with the Enemy Act of 1917 authorises the President during times of war or declared national emergency to investigate, regulate, or prohibit transactions in foreign exchange, transfers of credit between or payments by banking institutions, and the importing, exporting, hoarding, melting, or earmarking of gold or silver coin or bullion or currency, and to investigate, regulate, direct, compel, nullify, void, prevent, or prohibit any acquisition, holding, withholding, use, transfer, withdrawal, transportation, importation, or exportation of, or dealing in, or exercising any right, power, or privilege with respect to, or transactions involving, any property in which any foreign country or a national thereof has any interest. The Act is the principal source of the long-standing Cuban Assets Control Regulations administered by the Office of Foreign Assets Control.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ieepa-1977",
      "us-helms-burton-libertad-act-22-usc-ch69a"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-trafficking-victims-protection-act-22-usc-7101",
    "title": "Trafficking Victims Protection Act 2000 - 22 USC 7101",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 7101 of title 22 of the United States Code, the Trafficking Victims Protection Act of 2000 (TVPA, Public Law 106-386 Division A, enacted 28 October 2000), establishes the principal US federal anti-trafficking statute with three pillars (prosecution of traffickers, protection of victims, and prevention of trafficking). The TVPA defines severe forms of trafficking in persons to include sex trafficking in which a commercial sex act is induced by force, fraud, or coercion or in which the person induced to perform the act has not attained 18 years of age, and the recruitment, harbouring, transportation, provision, or obtaining of a person for labour or services through force, fraud, or coercion for involuntary servitude, peonage, debt bondage, or slavery. The Act creates federal criminal offences at 18 USC 1581 through 1597 including forced labour, trafficking with respect to peonage, sex trafficking of children, document servitude, and obstruction. It establishes the T-Visa for trafficking victims, the Continued Presence administrative status, and the Office to Monitor and Combat Trafficking in Persons (J/TIP) at the State Department which issues the annual Trafficking in Persons Report ranking countries on Tier 1 through Tier 3. The TVPA is regularly reauthorised including the Justice for Victims of Trafficking Act 2015, the TVPRA 2017, and the FOSTA-SESTA amendments to section 230 of the Communications Decency Act in 2018. Recent enforcement priorities include AI-enabled sextortion, deepfake non-consensual intimate imagery, and labour trafficking in global supply chains.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-section-230-communications-decency-act-47-usc-230",
      "us-foreign-assistance-act-1961-22-usc-2151"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-travel-act-18-usc-1952",
    "title": "Travel Act 1961 - 18 USC 1952 Interstate and Foreign Travel in Aid of Racketeering",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 1952 of title 18 of the United States Code, the Travel Act enacted by Public Law 87-228 on 13 September 1961, criminalises travel in interstate or foreign commerce or use of the mails or any facility in interstate or foreign commerce with intent to (1) distribute the proceeds of any unlawful activity, (2) commit any crime of violence to further any unlawful activity, or (3) otherwise promote, manage, establish, carry on, or facilitate the promotion, management, establishment, or carrying on of any unlawful activity, followed by performance or attempted performance of any of those acts. The statute defines unlawful activity as (A) any business enterprise involving gambling, liquor on which the federal excise tax has not been paid, narcotics or controlled substances, or prostitution offences in violation of state or federal law; (B) extortion, bribery, or arson in violation of state or federal law; (C) any act enumerated in section 1956 or 1957 (money-laundering offences); and (D) any specified anti-arson or anti-killing-of-witness offences. Standard penalty is up to 5 years imprisonment for promotion or distribution variants, with up to 20 years for violent variants and life imprisonment if death results. The Travel Act is the principal federal hook for state-level bribery and gambling enterprises where interstate facilities are used, and serves as a routine charging tool alongside the FCPA, Hobbs Act, and money-laundering statutes. AI agents that orchestrate gambling, payment routing, or counterparty communications across state lines must integrate Travel Act safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-hobbs-act-18-usc-1951",
      "us-money-laundering-control-act-18-usc-1956",
      "us-rico-organized-crime-control-act-18-usc-1961"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-treasury-managing-ai-cyber-risk-financial-2024",
    "title": "US Treasury - Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector (March 2024)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-13",
    "bluf": "The US Department of the Treasury published Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector on March 27, 2024, pursuant to Section 4.3(b) of Executive Order 14110 (since rescinded by EO 14148 but the underlying report remains a Treasury-issued reference). The report identifies AI-specific cybersecurity risks in financial services and recommends operational best practices. Treasury organises the analysis around six themes: (1) AI use cases and trends in financial services - fraud detection, credit, trading, customer service, cybersecurity tools, and emerging generative use; (2) AI-specific cybersecurity risks - data poisoning, model evasion, model extraction, privacy attacks, supply chain attacks on third-party models; (3) Capability gaps and asymmetry between large institutions and smaller firms; (4) Regulatory engagement and best-practice gaps; (5) Recommendations on governance, risk management, and cybersecurity controls; (6) Areas requiring further work including data standards, cross-sector threat sharing, and AI-specific incident reporting. Recommendations align with the NIST AI Risk Management Framework, NIST AI 100-2 adversarial ML taxonomy, NYDFS 23 NYCRR 500 cybersecurity regulation, and CISA AI guidance. The report is the principal Treasury-issued AI cybersecurity reference for US financial institutions and their service providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "nist_framework",
        "regulatory_overlay",
        "international_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-rmf-1-0",
      "nist-ai-100-2-adversarial-ml-taxonomy-2024",
      "us-cfpb-circular-2022-03-adverse-action-ai-credit",
      "us-cisa-roadmap-for-ai-2024"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-treasury-model-income-tax-treaty-2016",
    "title": "US Model Income Tax Convention 2016",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The US Model Income Tax Convention 2016 requires that a resident of a Contracting State be entitled to the benefits of the Convention, subject to the limitations on benefits provisions in Article 22, and that certain types of income be exempt from taxation in the source country, as outlined in Article 21.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-anti-tax-avoidance-directive-atad-2016-1164",
      "oecd-attribution-profits-permanent-establishments-2010"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-truth-in-lending-act",
    "title": "US Truth in Lending Act (15 USC ch 41 subch I): Credit Cost Disclosure, APR and the Right of Rescission",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Truth in Lending Act (TILA, 15 U.S.C. ch. 41, subchapter I) requires the meaningful disclosure of credit terms so that consumers can compare the cost of credit, administered chiefly by the Consumer Financial Protection Bureau. Section 1601 states the findings and the purpose of assuring a meaningful disclosure of credit terms. Section 1602 supplies the definitions, including creditor, consumer credit and finance charge. Section 1603 lists the transactions exempted from the subchapter. Section 1604 directs the issuance of disclosure rules and model forms. Section 1605 governs the determination of the finance charge, the sum of all charges payable as a condition of the extension of credit. Section 1606 governs the determination of the annual percentage rate, the measure that allows consumers to compare credit offers. Section 1607 provides for administrative enforcement by the relevant agencies. The Act also confers substantive rights and remedies: section 1635 gives a consumer the right to rescind certain credit transactions secured by the principal dwelling within three business days, and section 1640 provides civil liability for violations, including actual damages, statutory damages, and costs and attorney fees. The Act is the legal foundation of US consumer-credit cost disclosure and the basis of most lending-disclosure litigation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-truth-in-lending-act-regulation-z",
    "title": "US Truth in Lending Act (TILA) Regulation Z - Credit Disclosure & APR Requirements",
    "domain": "Banking & Global Finance",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Truth in Lending Act (15 USC §1601 et seq.) and its implementing Regulation Z (12 CFR Part 1026, CFPB) require creditors to disclose credit terms in standardised form before extending consumer credit. Core requirements: Annual Percentage Rate (APR) calculation and disclosure, Finance Charge, Total of Payments, and right of rescission for certain home-secured credit. Specialised rules govern open-end credit (credit cards - Reg Z §§1026.6-9), closed-end mortgages (TRID disclosures - §§1026.19, 37-38), private student loans, and high-cost mortgages (HOEPA - §1026.32). Civil liability for material disclosure failures is $100-$1,000 per violation plus actual damages and attorney's fees.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "uk_equivalent",
        "global_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cfpb-dodd-frank-title-x-consumer-financial-protection",
      "us-glba-gramm-leach-bliley-act-1999"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-truth-in-savings-act",
    "title": "US Truth in Savings Act (12 USC ch 44): Deposit Account Rate and Fee Disclosure",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Truth in Savings Act (12 U.S.C. ch. 44) requires depository institutions to disclose the rates, fees and terms of deposit accounts in a uniform manner so that consumers can compare accounts, implemented by the Consumer Financial Protection Bureau through Regulation DD. Section 4301 sets the findings and purpose, which is to enable consumers to make meaningful comparisons through the uniform disclosure of interest rates, expressed as the annual percentage yield, and fees. Section 4302 requires disclosure, when an account is advertised or opened, of the annual percentage yield and the period it applies, the minimum balance and any time requirement to earn the advertised rate, any minimum opening deposit, and a clear statement that fees may reduce the yield and that penalties apply to early withdrawal; it also prohibits describing an account as free or no-cost if a maintenance or activity fee or a minimum balance requirement applies. Section 4305 governs advertising, requiring that advertised rates not be misleading. Section 4307 provides for civil liability for a violation, with actual and statutory damages and attorney fees, although the principal enforcement is administrative. The annual percentage yield is calculated by a prescribed method to ensure comparability. The Act is the legal foundation for US deposit account disclosure and fair comparison.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-tsb-coast-guard-33-cfr",
    "title": "Title 33, Code of Federal Regulations - Navigation and Navigable Waters",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes comprehensive safety and security requirements for vessels, port facilities, and navigable waterways within U.S. jurisdiction, mandating specific security plans, vessel inspection protocols, and dangerous goods handling procedures under key sections like 33 CFR Part 105 (Facility Security) and Part 160 (Ports and Waterways Safety).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "port-facility-security-isps",
      "isps-code-vessel-security",
      "imo-solas-safety-at-sea",
      "imo-marpol-pollution",
      "iata-dangerous-goods"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-tsca-toxic-substances-chemical-safety-2016",
    "title": "Toxic Substances Control Act - Chemical Risk Evaluation, Prioritization, Safety Standards, and Fees for Industrial Chemical Manufacturing (2016 Reform)",
    "domain": "Industrial IoT & Energy",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The 2016 Lautenberg Chemical Safety Act amended the Toxic Substances Control Act (TSCA) to require EPA to evaluate existing chemicals for unreasonable risk, prioritize them as high- or low-priority, and conduct risk evaluations using best available science without consideration of cost. Manufacturers and importers of designated chemical substances must comply with testing requirements, reporting obligations, and fee payments under TSCA Section 26. The rule applies to industrial chemical manufacturers, processors, and importers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-50001-energy",
      "nist-sp-800-82-r3-ot-ics-security-guide-2023",
      "iec-62443-iacs",
      "iso-iec-27019-energy-utility-information-security"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ttb-alcohol-beverage-labelling",
    "title": "Alcohol and Tobacco Tax and Trade Bureau (TTB) Alcohol Beverage Labeling Requirements",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The U.S. Alcohol and Tobacco Tax and Trade Bureau (TTB), under 27 CFR Parts 4, 5, and 7, and the Alcoholic Beverage Labeling Act (ABLA), requires producers, bottlers, and importers to obtain a Certificate of Label Approval (COLA) by ensuring all alcohol beverage labels contain specific mandatory information, including brand name, class/type, alcohol content, and a government health warning, prior to domestic sale or distribution.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fda-food-labeling-guide",
      "food-allergen-label-law",
      "hcll-hospitality-licensing",
      "haccp-food-safety"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-tx-cubi-2009",
    "title": "Texas Capture or Use of Biometric Identifier Act 2009 (CUBI)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Texas Business and Commerce Code Chapter 503 enacted in 2009 prohibits commercial capture of biometric identifiers including fingerprints, voiceprints, retina scans, iris scans, and face geometry without informed written consent, bars disclosure or sale without consent, and authorises the Texas Attorney General to seek civil penalties up to USD 25,000 per violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-tx-cubi-2009.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-tx-education-code-ch32-student-privacy-act",
    "title": "Texas Student Privacy Act, Education Code Chapter 32 Subchapter D",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Texas Student Privacy Act in Education Code Chapter 32, Subchapter D regulates operators of websites, online services, and applications used primarily for a school purpose. Section 32.151 defines operator, covered information, and school purpose, and Section 32.152 prohibits targeted advertising, creating non-school-purpose student profiles, and selling or renting covered information. Section 32.155 requires operators to implement and maintain reasonable security procedures and practices to protect covered information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-34-cfr-part-99-ferpa-student-records",
      "us-coppa-16-cfr-part-312-edtech-school-operators"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-tx-hb149-traiga-2025",
    "title": "Texas HB 149 - Responsible Artificial Intelligence Governance Act (TRAIGA)",
    "domain": "AI Governance & Law",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Texas HB 149 (TRAIGA) takes effect 1 January 2026, creating Chapter 552 of the Business & Commerce Code. It imposes disclosure obligations on government AI use, prohibits AI deployments that intentionally incite self-harm or unlawful discrimination, restricts government social scoring (Section 552.053) and biometric identification (Section 552.054), and authorises the Texas Attorney General to impose civil penalties of $10,000-$12,000 per curable violation and $80,000-$200,000 per uncurable violation, with $2,000-$40,000 daily continuing penalties (Section 552.105). A 60-day cure period applies. There is no private right of action. Enforcement runs through an AG complaint portal due by 1 September 2026 (Section 8). NIST AI RMF compliance is an affirmative safe harbour (Section 552.105(e)). Chapter 553 establishes a 36-month regulatory sandbox; Chapter 554 establishes a 7-member Texas AI Council with advisory authority only.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_iec_42001",
        "nist_ai_rmf",
        "eu_ai_act",
        "us_co_sb24_205",
        "us_ostp_ai_bill_of_rights"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eo-14179-ai-2025",
      "nist-ai-rmf-1-0",
      "us-colorado-ai-act-sb24-205",
      "us-ostp-blueprint-ai-bill-of-rights",
      "iso-iec-42001-ai-management-system-2023"
    ],
    "primary_citations_count": 14
  },
  {
    "node_id": "us-tx-hb2060-ai-advisory-council-2023",
    "title": "Texas House Bill 2060 (88th Legislature, 2023) - Artificial Intelligence Advisory Council and Automated Decision Systems Inventory (Government Code Chapter 2054, Subchapter S, Sections 2054.621-2054.624)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2023-06-13",
    "bluf": "Texas House Bill 2060, enacted by the 88th Legislature (2023), adds Subchapter S to Chapter 2054 of the Texas Government Code (Sections 2054.621 through 2054.624) creating the Texas Artificial Intelligence Advisory Council and an Automated Decision Systems Inventory regime for state agencies. Section 2054.621 defines: 'Algorithm' (a computerized procedure consisting of a set of steps used to accomplish a determined task); 'Artificial intelligence systems' (systems capable of (A) perceiving an environment through data acquisition and processing and interpreting the derived information to take an action or actions or to imitate intelligent behavior given a specific goal, and (B) learning and adapting behavior by analyzing how the environment is affected by prior actions); 'Automated decision system' (an algorithm - including an algorithm incorporating machine learning or other AI techniques - that uses data-based analytics to make or support governmental decisions, judgments, or conclusions); 'Automated final decision system' (an automated decision system that makes final decisions, judgments, or conclusions without human intervention); 'Automated support decision system' (an automated decision system that provides information to inform the final decision, judgment, or conclusion of a human decision-maker). Section 2054.622 establishes the AI Advisory Council with mandate to (1) study and monitor AI systems developed, employed, or procured by state agencies, (2) review automated decision systems inventory reports submitted by state agencies under Section 2054.623, (3) assess the effect of automated decision systems on the constitutional or legal rights, duties, or privileges of residents and (4) make recommendations on automated decision systems. Section 2054.623 imposes the agency-level inventory obligation: each state agency shall submit an inventory report of all automated decision systems being developed, employed, or procured by the agency, with each entry describing (1) the name and vendor of the system, (2) general capabilities including whether it is used for (B) automated final or automated support decision-making, (3) the decisions the system makes or supports, (4)-(5) types of data collected and processed, (6) whether the system has been independently tested, (7) the purpose and proposed use, (8) data security measures, and (9) related contractual or licensing terms. Section 2054.624 sets the council's expiration. Section 3 effective-immediately clause: the Act takes effect immediately if it receives a two-thirds vote, otherwise on 1 September 2023. The Act is the foundational Texas AI governance instrument and a precursor to TRAIGA (Texas Responsible AI Governance Act, HB 1709, introduced for 2025).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_state_ai_landscape",
        "nist_ai_rmf",
        "omb_m_24_10_federal_ai",
        "us_civil_rights"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-eeoc-ai-employment-guidance-2023",
      "nist-ai-rmf-1-0",
      "us-tx-tdpsa-2024"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "us-tx-ramp-texas-cloud-security-certification",
    "title": "TX-RAMP - Texas Risk and Authorization Management Program (Tex. Gov Code 2054.0593)",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-07-10",
    "bluf": "TX-RAMP is the Texas Risk and Authorization Management Program, mandated by Texas Government Code Section 2054.0593, which directs the Texas Department of Information Resources (DIR) to establish a state risk and authorization management program to provide a standardized approach for security assessment, authorization, and continuous monitoring of cloud computing services that process the data of a state agency. The statute requires that a state agency shall require each vendor contracting with the agency to provide cloud computing services for the agency to comply with the requirements of the state risk and authorization management program, and that a state agency may not enter or renew a contract with a vendor to purchase cloud computing services subject to the program unless the vendor demonstrates compliance with program requirements; vendors must maintain program compliance and certification throughout the term of the contract. The statute also permits a vendor to demonstrate compliance by submitting documentation showing compliance with a risk and authorization management program of the federal government or another state that DIR approves. Under the TX-RAMP Program Manual (version 3.1), Level 1 certification is required for cloud computing services categorized by the agency as low-impact information resources and Level 2 certification is required for services categorized as moderate or high impact information resources, as defined by 1 Texas Administrative Code Section 202.1; the state agency determines the required certification level. Provisional certification is achieved after DIR approval of the TX-RAMP Acknowledgment and Inventory Questionnaire and is effective for 18 months, and may also be achieved after a cloud computing service receives an accepted status from StateRAMP or FedRAMP; full certifications are valid for three years subject to compliance with program requirements including required continuous monitoring reports. Section 2054.0593 was added by Acts 2021, 87th Legislature, R.S., Chapter 567 (S.B. 475), Section 2, effective June 14, 2021.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "statutory_anchor",
        "contract_gating",
        "external_ramp_reciprocity",
        "impact_categorization",
        "industry_mapping",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "govramp-state-local-cloud-security-verification",
      "fedramp-authorization",
      "us-44-usc-3614-fedramp-authorization-program"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-tx-sb1188-ehr-data-localization-ai-disclosure-2025",
    "title": "Texas Senate Bill 1188 - Electronic Health Record Requirements (Chapter 183, Health and Safety Code)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-06-28",
    "bluf": "Texas SB 1188 adds Chapter 183 to the Health and Safety Code requiring covered entities to ensure that electronic health records under their control that contain patient information are physically maintained in the United States or a territory of the United States, permitting health care practitioners to use artificial intelligence for diagnostic purposes provided they disclose that use to patients, and adding access controls for minors' records, with a civil penalty; the Act takes effect September 1, 2025.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-45-cfr-part-164-hipaa-security-rule-safeguards",
      "us-45-cfr-part-160-hipaa-general-administrative",
      "us-tx-traiga-hb149-2025-responsible-ai-governance"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-tx-tdpsa-2024",
    "title": "US Texas Data Privacy and Security Act 2024",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Texas Data Privacy and Security Act establishes consumer rights over personal data, requires controllers to conduct data protection assessments for high-risk processing, mandates opt-in consent for sensitive data, and authorises the Texas Attorney General to impose civil penalties of up to USD 7,500 per violation with a mandatory cure period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-tx-tdpsa-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ccpa-cpra-2023-marketing-rights"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-tx-traiga-hb-149-2025",
    "title": "Texas Responsible AI Governance Act 2025, TRAIGA HB 149 - Intent-Based Prohibitions, Governmental Disclosure, and NIST AI RMF Safe Harbour",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Developers and deployers of artificial intelligence systems in or affecting Texas must, from 1 January 2026, refrain from developing or deploying AI systems with the intent to incite or encourage a person to commit physical self-harm including suicide, to harm another person, or to engage in criminal activity, refrain from AI systems developed with the sole intent of infringing constitutional rights, refrain from behavioural manipulation, discrimination, and the creation or distribution of child pornography or unlawful deepfakes, and (for governmental entities) disclose to consumers that they are interacting with an AI system before or at the point of interaction, not deploy AI for social-scoring with detrimental treatment, and not use AI to uniquely identify persons via biometric data obtained from publicly available sources without consent, with TRAIGA enforced solely by the Texas Attorney General and safe harbours available for organisations that discover violations through internal testing including adversarial and red team exercises or that substantially comply with the NIST AI Risk Management Framework or other recognised standards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-colorado-ai-act-sb24-205",
      "us-ca-sb53-frontier-ai"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "us-tx-traiga-hb149-2025-responsible-ai-governance",
    "title": "Texas Responsible Artificial Intelligence Governance Act (TRAIGA) - HB 149 (89R)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-05-14",
    "bluf": "The Texas Responsible Artificial Intelligence Governance Act (HB 149 of the 89th Legislature, Regular Session) adds new Subtitle D (Chapters 551 to 554) to Title 11 of the Texas Business and Commerce Code titled 'Artificial Intelligence Protection'. Chapter 551 contains general provisions and definitions. Chapter 552 establishes the substantive AI duties, prohibitions, and enforcement framework, including civil penalties for violations. Chapter 553 establishes the Texas regulatory sandbox program for limited testing of innovative AI systems without full licensing requirements. Chapter 554 establishes the Texas Artificial Intelligence Council to oversee ethical AI development across state agencies, the regulatory sandbox, and statewide policy coordination. The Act was passed by the Texas House on April 23 2025, passed by the Senate on May 23 2025, with House concurrence in Senate amendments on May 30 2025, and signed by Governor Abbott. The Act takes effect 1 January 2026 (Section 10). Author Capriglione. Civil penalties enforced by the Texas Attorney General. TRAIGA is the first comprehensive AI governance law in a Republican-led state and the first state-level Act to combine substantive AI obligations with a formal regulatory sandbox.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-co-sb205-high-risk-ai",
      "us-ca-sb53-frontier-ai",
      "us-eo-14179-ai-2025"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-uigea-2006-unlawful-internet-gambling",
    "title": "Unlawful Internet Gambling Enforcement Act of 2006 - Prohibitions on Financial Transactions Relating to Unlawful Internet Gambling",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The UIGEA prohibits gambling businesses from accepting payments for unlawful internet gambling and requires financial institutions and payment processors to establish and implement policies to identify and block restricted transactions. This applies to any person or entity engaged in the business of betting or wagering via the internet and to all financial intermediaries involved in processing related transactions, under 31 U.S.C. § 5361-5367.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto",
      "nist-cybersecurity-framework-2-0"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-uigea-unlawful-internet-gambling-2006",
    "title": "Unlawful Internet Gambling Enforcement Act of 2006",
    "domain": "Gaming & Gambling",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "Prohibits gambling businesses from accepting payments in connection with unlawful Internet gambling; requires financial institutions and payment processors to establish and implement policies to block or prevent such transactions. Applies to U.S. financial institutions and payment system operators under 31 U.S.C. § 5362(3).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018",
      "eu-aml-directive-5-gambling-sector",
      "eu-payment-services-directive-2-gaming-deposits"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-uniform-electronic-transactions-act-1999",
    "title": "Uniform Electronic Transactions Act (1999)",
    "domain": "Workflow Automation",
    "version": "1.1.0",
    "last_updated": "2026-07-10",
    "bluf": "The Uniform Electronic Transactions Act (1999) gives electronic records and signatures the same legal effect as paper for transactions where the parties have agreed to proceed electronically. Section 7 establishes legal recognition of electronic records, signatures, and contracts; Section 8 governs provision of information in writing and presentation of records; Section 12 sets retention and original-form requirements for electronic records; and Section 15 fixes the time and place of sending and receipt. Automated transaction workflows must preserve retainability, accurate final-form retention, and deterministic send and receipt rules to keep electronic records enforceable.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-electronic-commerce-1996",
      "us-esign-act-2000-electronic-records-signatures"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-united-states-warehouse-act",
    "title": "US United States Warehouse Act (7 USC ch 10): Licensing of Agricultural Warehouses and Warehouse Receipts",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The United States Warehouse Act (7 U.S.C. ch. 10, sections 241 to 256) authorizes the Secretary of Agriculture to license warehouse operators who store agricultural products for interstate or foreign commerce and to regulate the issuance of warehouse receipts, administered through the Farm Service Agency. Section 241 defines the terms, including warehouse, which means a structure or other approved storage facility in which any agricultural product may be stored or handled for the purposes of interstate or foreign commerce. Section 242 sets out the powers of the Secretary, including the authority to issue a license to a warehouse operator where the warehouse is determined to be suitable for the proper storage of the agricultural product and to inspect any licensed person or warehouse. Section 243 provides for the imposition and collection of fees, section 244 for quality and value standards, and section 245 for bonding and other financial assurance requirements. Section 246 requires the maintenance of records, section 247 requires fair treatment in the storage of agricultural products, and section 248 governs commingling. Section 250 provides that, at the request of the depositor, the warehouse operator shall issue a warehouse receipt as prescribed by the Secretary, and section 251 sets the conditions for delivery. Section 252 authorizes suspension or revocation of a license for a material violation, and section 254 sets the penalties, providing for a civil penalty of not more than 25,000 dollars per violation where no agricultural product is involved, or not more than 100 per centum of the value of the agricultural product where one is involved. The Act is the federal regime for licensed agricultural warehousing and negotiable warehouse receipts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-uscg-33-cfr-104-maritime-security-vessels",
    "title": "33 CFR Part 104 - Maritime Security: Vessels (USCG)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "USCG 33 CFR Part 104 implements the Maritime Transportation Security Act for vessels, requiring covered vessels to complete a Vessel Security Assessment, develop and obtain approval of a Vessel Security Plan, designate a Company Security Officer and Vessel Security Officer, train personnel, conduct drills and exercises, maintain records, implement security measures keyed to MARSEC Levels and MARSEC Directives, enforce access control and restricted area measures, secure cargo handling, vessel stores, and monitoring, and manage security incidents and Declarations of Security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 21
  },
  {
    "node_id": "us-uscg-33-cfr-105-maritime-security-facilities",
    "title": "33 CFR Part 105 - Maritime Security: Facilities (USCG)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "USCG 33 CFR Part 105 implements the Maritime Transportation Security Act for waterfront facilities, requiring covered facilities to complete a Facility Security Assessment, develop and obtain approval of a Facility Security Plan, designate a Facility Security Officer, train personnel, conduct drills and exercises, maintain records, implement security measures keyed to MARSEC Levels and MARSEC Directives, enforce access control and restricted area measures, secure cargo handling, vessel stores, and monitoring, and manage security incidents and Declarations of Security.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 20
  },
  {
    "node_id": "us-uscg-33-cfr-154-marine-oil-transfer-facilities",
    "title": "33 CFR Part 154 - Facilities Transferring Oil or Hazardous Material in Bulk (USCG)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "USCG 33 CFR Part 154 sets the oil pollution prevention requirements for marine transfer facilities, requiring covered facilities to submit a letter of intent and undergo examinations, maintain an approved operations manual, meet equipment standards for hoses, loading arms, and closure devices, provide discharge containment and removal capability, keep emergency shutdown and communications operable, designate qualified persons in charge of transfers, meet safety and recordkeeping requirements, and submit and exercise a facility response plan addressing the worst case discharge.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-oil-pollution-act-1990-opa90",
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 23
  },
  {
    "node_id": "us-uscg-33-cfr-155-vessel-oil-pollution-prevention",
    "title": "33 CFR Part 155 - Oil or Hazardous Material Pollution Prevention Regulations for Vessels (USCG)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "USCG 33 CFR Part 155 sets the oil pollution prevention requirements for vessels, requiring covered vessels to carry discharge removal equipment for their size class, provide emergency control, towing, and damage stability arrangements, protect oil fuel tanks, contain cargo and fuel oil discharges on deck, meet the MARPOL oily mixture discharge limits, use oily water separating equipment, post the oil discharge placard and fit overfill devices, designate a qualified person in charge of transfers, and follow approved transfer procedures with emergency shutdown and communications.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-oil-pollution-act-1990-opa90"
    ],
    "primary_citations_count": 23
  },
  {
    "node_id": "us-uscg-33-cfr-165-regulated-navigation-limited-access-areas",
    "title": "33 CFR Part 165 - Regulated Navigation Areas and Limited Access Areas (USCG)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "USCG 33 CFR Part 165 establishes the framework for regulated navigation areas and limited and controlled access areas, setting the procedures to establish and notify areas, the use of geographic coordinates, and the general regulations governing regulated navigation areas, safety zones, security zones, and restricted waterfront areas, including the vessel operating requirements that mariners must observe within an established area.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 14
  },
  {
    "node_id": "us-uscg-46-cfr-197-commercial-diving-operations",
    "title": "46 CFR Part 197 - General Provisions (Commercial Diving Operations) (USCG)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-05-25",
    "bluf": "USCG 46 CFR Part 197 sets the safety standards for commercial diving operations from vessels and facilities subject to Coast Guard jurisdiction, requiring designation of a person-in-charge and diving supervisor, compliant air compressor, breathing supply, and diver equipment, pressure vessels for human occupancy including closed bells and decompression chambers, oxygen safety, defined responsibilities and dive procedures, an operations manual, mode-specific procedures for SCUBA, surface-supplied, mixed-gas, and liveboating dives, and breathing gas testing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 26
  },
  {
    "node_id": "us-uscg-46-cfr-inspection-certification",
    "title": "US Coast Guard 46 CFR - Vessel Inspection and Certification: COI (Certificate of Inspection) Requirements by Vessel Type, Annual/Drydock/Underwater Surveys, Structural Fire Protection, Life-Saving Appliances, Stability Letters and USCG Alternative Compliance Program",
    "domain": "Maritime & Shipping",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation establishes the requirements for the issuance and maintenance of Certificates of Inspection (COI) for vessels subject to Coast Guard jurisdiction, including mandatory annual, drydock, and underwater inspections, compliance with structural fire protection, lifesaving appliances, and stability standards under 46 CFR Subchapters T, H, K, I, and others. Key provisions are codified in 46 CFR 176.500 and 46 CFR 115.500.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-solas-safety-at-sea",
      "imo-stcw-convention-1978-2010-manila"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-usda-pesticide-mrl-tolerance-regulation-40-cfr-180",
    "title": "US EPA Pesticide Maximum Residue Limits - 40 CFR Part 180 Tolerances for Pesticide Residues",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-10",
    "bluf": "40 CFR Part 180 implements Federal Food, Drug, and Cosmetic Act (FFDCA) Section 408 tolerances, establishing maximum residue limits (MRLs) for pesticide residues on food commodities. EPA sets tolerances based on aggregate exposure assessment; USDA and FDA enforce through domestic market surveillance. AI-driven crop protection advisory platforms, precision application systems, and food safety analytics tools must ensure recommendations do not result in tolerance exceedances. Pesticide registration and tolerance petitions require validated residue trial data; AI-generated application rate recommendations must be constrained to label-rate limits under FIFRA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "standards",
        "frameworks",
        "regulations",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-epa-clean-water-act-section-402-npdes",
      "eu-common-agricultural-policy-regulation-2021-2115"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-userra-uniformed-services-employment",
    "title": "US USERRA (38 USC ch 43): Uniformed Services Employment and Reemployment Rights",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Uniformed Services Employment and Reemployment Rights Act, USERRA (38 U.S.C. ch. 43), protects the employment and reemployment rights of persons who serve in the uniformed services, administered by the Department of Labor with enforcement by the Department of Justice and the Office of Special Counsel. Section 4311 prohibits an employer from denying initial employment, reemployment, retention, promotion or any benefit of employment because of a person's membership, application, performance of service or obligation to serve, and prohibits reprisal against a person who enforces a protection or testifies; a violation occurs where service is a motivating factor unless the employer proves it would have taken the action regardless. Section 4312 establishes reemployment rights for a person who gives notice, whose cumulative service does not exceed the statutory limit, and who reports back or applies within the required time. Section 4313 sets the reemployment position under the escalator principle, placing the person in the position they would have attained had they not served. Section 4316 preserves seniority and other rights on reemployment, and section 4317 addresses health plan continuation. Section 4323 provides enforcement and remedies, including reinstatement, lost wages and benefits, and liquidated damages for a willful violation. The Act is the legal foundation for US military service member employment protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-usml-category-xv-22-cfr-121-spacecraft-systems",
    "title": "US USML Category XV 22 CFR 121.1 Spacecraft Systems and Associated Equipment Defense Trade Controls Under ITAR Including Remote Sensing and Communications Satellites",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "United States Munitions List Category XV at 22 CFR section 121.1 establishes export controls under the International Traffic in Arms Regulations for spacecraft systems and associated equipment with specific paragraph coverage including paragraph (a) covering spacecraft providing electro-optical imaging or remote sensing with capabilities exceeding specified thresholds spacecraft providing radio frequency direction finding or signals intelligence and spacecraft providing space-based ballistic missile warning or detection paragraph (b) ground control stations for telemetry tracking and command of category XV spacecraft paragraph (c) attitude orbit and pointing control systems paragraph (d) propulsion systems with specified performance paragraph (e) thermal control systems for category XV spacecraft paragraph (f) power systems and components paragraph (g) deployable systems including booms hinges and antennas paragraph (h) optical sensors and detectors and paragraph (x) commodities technology and software directly related to spacecraft systems. Export of Category XV items requires Department of State Directorate of Defense Trade Controls authorisation including license registration and brokering requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-itar-22-cfr-120-130-arms-export",
      "us-export-administration-regulations"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-ut-ai-policy-act-2024",
    "title": "Utah Artificial Intelligence Policy Act 2024 (SB 149)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Utah SB 149 signed March 13, 2024 effective May 1, 2024 requires regulated entities in consumer-facing industries including insurance, financial services, and real estate to disclose to consumers when they are interacting with AI-generated content or AI-driven services, and to respond truthfully when a consumer directly asks if they are interacting with a human or an AI system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ut-ai-policy-act-2024.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "nist-ai-600-1-gen-ai-profile",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-ut-ucpa-2022",
    "title": "US Utah Consumer Privacy Act 2022",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Utah Consumer Privacy Act establishes consumer rights to access, delete, and port personal data and to opt out of sale and targeted advertising, applies to businesses with over USD 25 million in annual revenue meeting consumer count thresholds, provides no opt-in requirement for sensitive data, and authorises the Utah Attorney General and Utah Division of Consumer Protection to impose civil penalties of up to USD 7,500 per violation with a mandatory 30-day cure period.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-ut-ucpa-2022.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-ccpa-cpra-2023-marketing-rights"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-utah-consumer-privacy-act-ucpa-2022",
    "title": "Utah Consumer Privacy Act (UCPA)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Utah Consumer Privacy Act (UCPA) grants Utah residents rights to access, delete, and obtain their personal data, and to opt out of the sale of personal data and targeted advertising. The act applies to controllers with $25M+ in annual revenue that either process data of 100,000+ Utah consumers or derive over 50% of revenue from selling personal data of 25,000+ consumers, as defined in Section 13-61-102.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "nist-privacy-framework-1-0",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-uyghur-forced-labor-prevention-act",
    "title": "Uyghur Forced Labor Prevention Act (UFLPA)",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Uyghur Forced Labor Prevention Act (UFLPA) establishes a rebuttable presumption that all goods mined, produced, or manufactured wholly or in part in China's Xinjiang Uyghur Autonomous Region (XUAR) are made with forced labor and are prohibited from importation into the United States under 19 U.S.C. § 1307. Importers must provide clear and convincing evidence to U.S. Customs and Border Protection (CBP) to overcome this presumption.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-28000-supply-chain",
      "supply-chain-risk-triage",
      "c-tpat-minimum-security",
      "iso-26000-social-resp",
      "wco-safe-framework"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-va-cdpa-2021",
    "title": "Virginia Consumer Data Protection Act 2021 (CDPA)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Virginia HB 2307 signed March 2, 2021 effective January 1, 2023 establishes consumer rights (access, correction, deletion, portability, opt-out of targeted advertising/sale/profiling) for controllers processing personal data of 100,000 or more Virginia residents annually or 25,000 residents with 50% revenue from data sales, with AG-only enforcement and USD 7,500 per intentional violation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-va-cdpa-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-vawa-violence-against-women-act-1994-pl-103-322",
    "title": "US Violence Against Women Act of 1994 (Public Law 103-322) - Federal Response to Gender-Based Violence",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-28T00:00:00Z",
    "bluf": "The Violence Against Women Act of 1994 was enacted as part of the Violent Crime Control and Law Enforcement Act and created federal grant programs to support state and local prosecution of crimes of violence against women, encourage arrest policies in domestic violence cases, support shelters, rape prevention education, and the National Domestic Violence Hotline, established federal interstate stalking and domestic violence crimes, required full faith and credit for protection orders across states, created the immigration self-petition for abused spouses and children of US citizens and lawful permanent residents, and authorised the Office on Violence Against Women in the Department of Justice. The Act has been reauthorised multiple times since enactment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-immigration-nationality-act-1952-uscis"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-viatical-life-settlements-model-naic-697",
    "title": "Viatical Settlements Model Act",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-19",
    "bluf": "This model act establishes a comprehensive regulatory framework for viatical and life settlement transactions, requiring the licensing of providers and brokers (Section 3), mandating specific disclosures to consumers before and at the time of contract (Section 8), and establishing standards to prevent fraudulent acts and protect consumer privacy (Sections 11 & 12). It applies to all parties involved in viatical settlement contracts, including providers, brokers, and viators.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-vida-vessel-incidental-discharge-33-usc-1322p",
    "title": "Vessel Incidental Discharge Act 2018 - 33 USC 1322(p)",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "The Vessel Incidental Discharge Act of 2018, codified at 33 USC 1322(p), creates uniform national standards for discharges incidental to the normal operation of vessels. Section 1322(p)(2) sets the applicability of the subsection to discharges incidental to normal vessel operation, Section 1322(p)(4) directs the EPA Administrator, in concurrence with the Secretary of the department in which the Coast Guard is operating, to promulgate Federal standards of performance for marine pollution control devices, and Section 1322(p)(5) directs the Secretary to promulgate the implementation, compliance and enforcement regulations. The statute defines a separate small vessel or fishing vessel category as vessels less than 79 feet in length, or any fishing, fish processing or fish tender vessel regardless of length.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-33-usc-ch26"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-video-privacy-protection-act",
    "title": "US Video Privacy Protection Act (18 USC 2710): Privacy of Video Viewing Records",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Video Privacy Protection Act (18 U.S.C. 2710) protects the privacy of records that identify what video materials a consumer has rented, purchased or requested, and is widely applied to streaming and online video services through a private right of action. Section 2710(b) provides that a video tape service provider who knowingly discloses, to any person, personally identifiable information concerning any consumer of the provider is liable to the aggrieved consumer. Personally identifiable information includes information that identifies a person as having requested or obtained specific video materials or services. Section 2710(b)(2) sets the permitted disclosures, including disclosure to the consumer, disclosure with the informed written consent of the consumer given in a form distinct and at the time the disclosure is sought, disclosure to a law enforcement agency under a warrant or court order, disclosure of only the names and addresses of consumers for marketing where the consumer has been given an opportunity to opt out, and disclosure incident to the ordinary course of business. Section 2710(c) provides the civil remedies: a court may award actual damages but not less than liquidated damages in an amount of 2,500 dollars, punitive damages, reasonable attorney fees and costs, and equitable relief, with a two-year limitation period. The Act is the legal foundation for US video viewing privacy compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-virginia-cdpa-consumer-data-protection-2021",
    "title": "Virginia Consumer Data Protection Act (CDPA)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Virginia Consumer Data Protection Act (CDPA) establishes a framework for controlling and processing personal data in the Commonwealth. It applies to entities that conduct business in Virginia or produce products/services targeted to Virginia residents and either (i) control or process personal data of at least 25,000 consumers or (ii) derive over 50% of gross revenue from the sale of personal data and control or process data of at least 25,000 consumers, granting consumers specific rights and requiring controllers to conduct data protection assessments for high-risk activities per § 59.1-576.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-35-dpia",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-virginia-code-8-01-40-5-age-verification-harmful-minors",
    "title": "Virginia Code § 8.01-40.5 - Civil Action for Unlawful Dissemination of Material Harmful to Minors Online (2023 Chapter 811)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-01",
    "bluf": "Virginia Code § 8.01-40.5 (enacted by 2023 Virginia Acts Chapter 811, effective 1 July 2023) creates a private civil cause of action against any commercial entity that knowingly publishes or distributes material harmful to minors on the Internet to a minor in Virginia without first using either (a) a commercially available database that is regularly used by businesses or governmental entities for age and identity verification, or (b) another commercially reasonable method of age and identity verification, to confirm the user is at least 18 years of age; the statute applies where more than 33-1/3 percent of the website's content meets the definition of material harmful to minors (depicting nudity, sexual conduct, sexual excitement, or sadomasochistic abuse that appeals to prurient interests of minors, is patently offensive to prevailing adult community standards for minors, and lacks serious literary, artistic, political, or scientific value for minors); damages include actual damages plus reasonable attorney fees and costs; the section preserves Section 230-style protections for interactive computer service providers and users (not imposing obligations on such providers), and was the third-wave Virginia statute (after Texas HB 1181 and Louisiana HB 142) in the state-level age-verification movement; the constitutionality of analogous statutes is being tested in Free Speech Coalition v. Paxton currently pending before the US Supreme Court.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "comparable_state_age_verification_statutes",
        "federal_harmful_to_minors_framework",
        "constitutional_challenges_pending",
        "industry_mapping",
        "section_230_carve_out",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-texas-hb-1181-2023-age-verification-explicit-content",
      "us-18-usc-1470-transfer-obscene-material-minors",
      "us-take-it-down-act-2025"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-virginia-sb-1515-age-verification-material-harmful-minors",
    "title": "Virginia SB 1515 (2023) - Civil Liability for Commercial Internet Distribution of Material Harmful to Minors Without Age Verification (Va. Code Section 8.01-40.5)",
    "domain": "Adult Industry & Sexual Content Compliance",
    "version": "1.0.0",
    "last_updated": "2026-06-11",
    "bluf": "Virginia Senate Bill 1515 (2023 Regular Session) enacted Chapter 811 of the Acts of Assembly, creating Virginia Code Section 8.01-40.5 effective 1 July 2023. The statute imposes civil liability on any commercial entity that knowingly or intentionally publishes or distributes on the internet material harmful to minors without performing reasonable age verification to confirm the user is 18 or older. The substantial portion threshold is more than 33 and one-third percent of the total material on a website meeting the harmful material definition (descriptions or representations of nudity or sexual content that appeal to the prurient, shameful, or morbid interest of minors; are patently offensive to prevailing standards in the adult community as a whole with respect to what is suitable material for minors; and, when taken as a whole, lack serious literary, artistic, political, or scientific value for minors). Reasonable age verification is satisfied by either a commercially available database regularly used by businesses or governmental entities for age and identity verification, or another commercially reasonable method of age and identity verification. A violating entity is liable to damaged minors and their parents for damages resulting from the minor's access to the harmful material, plus reasonable attorney fees and costs. The statute expressly does not impose obligations on interactive computer service providers or users (Section 230 safe harbor preserved). The substantive Virginia Code citation 'commercial entity' references the definition in Va. Code Section 8.01-49.1. Virginia is one of approximately twenty US states that have enacted commercial-website age-verification statutes following Louisiana Act 440 of 2022 (the first such state law); the litigation cluster includes the Free Speech Coalition challenges and the Supreme Court's review in FSC v. Paxton (2025). Virginia operators face the additional overlay of the federal 18 U.S.C. Section 2257 record-keeping framework for visual depictions of explicit conduct.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "harmful_to_minors_definition_anchor",
        "verification_methods_anchor",
        "section_230_interaction",
        "first_amendment_litigation_anchor",
        "industry_mapping",
        "federal_overlay_anchors",
        "enforcement_anchors"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-18-usc-2257-record-keeping-explicit-content",
      "us-18-usc-2421a-fosta-promoting-prostitution-online",
      "us-california-sb-976-2024-social-media-addiction-kids"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-virginia-sports-betting-act-2020",
    "title": "Virginia Sports Betting Act 2020 - Online Sports Wagering Licensing and VSA Regulation",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "Virginia online sports betting operators must obtain a permit from the Virginia Lottery Board under Chapter 41 of Title 58.1 of the Code of Virginia. Mobile sports betting launched in January 2021. Operators pay 15% tax on net sports betting revenues. Problem gambling and responsible gaming tools are mandatory, with self-exclusion integrated with the Virginia voluntary self-exclusion programme.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "virginia_lottery_board",
        "uigea",
        "murphy_v_ncaa",
        "virginia_problem_gambling",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
      "us-uigea-2006-unlawful-internet-gambling",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-virus-serum-toxin-act",
    "title": "US Virus-Serum-Toxin Act (21 USC ch 5): Licensing of Veterinary Biological Products",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Virus-Serum-Toxin Act (21 U.S.C. ch. 5, sections 151 to 159) regulates veterinary biological products, including viruses, serums, toxins, antitoxins, and analogous products intended for use in the treatment of domestic animals, and is administered by the Animal and Plant Health Inspection Service of the Department of Agriculture. Section 151 prohibits the preparation, sale, barter, exchange, or shipment of any worthless, contaminated, dangerous, or harmful veterinary biological product, and the preparation of such products at an unlicensed establishment, and authorizes the Secretary of Agriculture to issue regulations and licenses. Section 152 regulates and prohibits importation, and section 153 authorizes the inspection of imports and the denial of entry and destruction of harmful products. Section 154 empowers the Secretary to issue, suspend, and revoke establishment and product licenses, and section 154a provides for special licenses in special circumstances. Section 155 governs permits for importation, section 156 conditions licenses on consent to inspection, and section 157 authorizes officers of the Department to enter and inspect any establishment. Section 158 makes a violation punishable by a fine of not exceeding 1,000 dollars or imprisonment for not exceeding one year, or both, and section 159 governs enforcement, seizure, and condemnation. The Act is the primary federal control on the safety, purity, potency, and efficacy of animal vaccines and biologics.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-volcker-rule",
    "title": "US Volcker Rule - Section 619 of Dodd-Frank: Prohibition on Proprietary Trading and Fund Sponsorship",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Volcker Rule, implemented as Section 619 of the Dodd-Frank Act, prohibits insured depository institutions and their affiliates ('banking entities') from engaging in short-term proprietary trading for their own account and from acquiring or retaining ownership interests in, or sponsoring, hedge funds or private equity funds ('covered funds'), subject to certain exemptions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "fundamental-review-of-the-trading-book",
      "principles-effective-risk-data-aggregation",
      "sr-11-7-model-risk-management",
      "finra-3110-supervision"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-vppa-1988",
    "title": "US Video Privacy Protection Act 1988",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Video Privacy Protection Act prohibits video service providers from knowingly disclosing personally identifiable information about their subscribers' video rental, sale, or streaming history without written consent, provides a private right of action with liquidated damages of USD 2,500 per plaintiff, and has been actively litigated against streaming services using pixel tracking technologies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-vppa-1988.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cpra-california-privacy-rights-act-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-vt-data-broker-2018",
    "title": "Vermont Data Broker Registration Act 2018",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Vermont's Act 171 is the first US state law to specifically regulate data brokers, requiring annual registration with the Vermont AG, mandatory disclosure of data collection practices, a consumer opt-out mechanism for sale of brokered personal data, and a reasonable security program.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-vt-data-broker-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cpra-california-privacy-rights-act-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-wa-biometric-privacy-act-2017",
    "title": "Washington Biometric Privacy Law 2017 (Chapter 19.375 RCW, HB 1493)",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "Washington Chapter 19.375 RCW enacted 2017 prohibits commercial entities from enrolling biometric identifiers from Washington consumers without notice of the purpose and collection method, bars sale or disclosure without consent, requires destruction within three years or when purpose is fulfilled, and is enforced by the Attorney General as an unfair or deceptive act under the Washington Consumer Protection Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-wa-biometric-privacy-act-2017.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-wa-mhmd-2023",
    "title": "US Washington My Health MY Data Act 2023",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Washington My Health MY Data Act extends health data privacy protections beyond HIPAA to any entity collecting consumer health data, requires affirmative authorisation before collection or sharing, prohibits geofencing within 2,000 feet of health facilities, and provides a private right of action under the Washington Consumer Protection Act with triple damages.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-wa-mhmd-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-hipaa-breach-notification-rule"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "us-wa-my-health-data-act-2023",
    "title": "Washington My Health MY Data Act 2023 (SB 5125)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Washington SB 5125 signed April 27, 2023 effective March 31, 2024 requires opt-in consent before collecting or sharing consumer health data not covered by HIPAA, prohibits geofencing within 2,000 feet of healthcare facilities, and authorizes a private right of action alongside Attorney General enforcement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/us-wa-my-health-data-act-2023.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-warn-act-1988-29-usc-ch23",
    "title": "United States Worker Adjustment and Retraining Notification Act of 1988 (WARN Act) (Title 29 USC Chapter 23): Definitions of Loss of Employment, 60-Day Notice Required Before Plant Closings and Mass Layoffs, Exemptions, Administration and Enforcement, Procedures in Addition to Other Rights, and Effect on Other Laws",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Worker Adjustment and Retraining Notification Act of 1988 (WARN Act), Public Law 100-379 of 4 August 1988, codified at Title 29 of the United States Code, Chapter 23, is the principal federal statute requiring covered employers to provide affected employees and units of local government 60 calendar days advance written notice of plant closings and mass layoffs, and is administered by the Wage and Hour Division of the Department of Labor with private civil enforcement. WARN Act, 29 U.S.C. 2101 contains the definitions including loss of employment, employer (an employer of 100 or more employees, excluding part-time employees, or 100 or more employees including part-time employees who in the aggregate work at least 4,000 hours per week), plant closing (the permanent or temporary shutdown of a single site of employment or one or more facilities or operating units within a single site of employment, if the shutdown results in an employment loss at the single site of employment during any 30-day period for 50 or more employees, excluding part-time employees), and mass layoff (a reduction in force which is not the result of a plant closing and results in an employment loss at the single site of employment during any 30-day period for at least 33 per centum of the employees, excluding part-time employees, and at least 50 employees, excluding part-time employees; or at least 500 employees, excluding part-time employees). WARN Act, 29 U.S.C. 2102 provides that an employer shall not order a plant closing or mass layoff until the end of a 60-day period after the employer serves written notice of such an order to each representative of the affected employees as of the time of the notice or, if there is no representative at that time, to each affected employee; and to the State or entity designated by the State and the chief elected official of the unit of local government within which such closing or layoff is to occur. WARN Act, 29 U.S.C. 2103 sets out the exemptions. WARN Act, 29 U.S.C. 2104 sets out the administration and enforcement of the requirements with civil remedies for affected employees. The Act is the controlling federal instrument for advance notice of plant closings and mass layoffs in the United States.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-warn-act-1988-mass-layoffs",
    "title": "Worker Adjustment and Retraining Notification (WARN) Act - 60-Day Advance Notice for Mass Layoffs and Plant Closings, Covered Employers and Exceptions",
    "domain": "Workplace",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The WARN Act requires employers with 100 or more employees to provide at least 60 calendar days of advance written notice to affected workers, unions, and local governments before a plant closing or mass layoff. This obligation is outlined in the WARN Act and regulations at 20 CFR Part 639.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-washington-my-health-my-data-act-2023",
    "title": "Washington My Health My Data Act (MHMDA)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Washington My Health My Data Act (MHMDA) imposes strict obligations on entities collecting or processing 'consumer health data,' requiring separate, explicit consumer consent for collection, sharing, and selling (RCW 19.373.040). It grants consumers rights of access, deletion, and withdrawal of consent, and uniquely establishes a private right of action for violations under Washington's Consumer Protection Act (RCW 19.373.110).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "california-ccpa-v2",
      "gdpr-article-17-right-erasure"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-water-resources-planning-act",
    "title": "US Water Resources Planning Act (42 USC 1962 et seq.): Comprehensive Coordinated Planning, the Water Resources Council and River Basin Commissions",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Water Resources Planning Act, codified at 42 U.S.C. 1962 et seq., establishes the federal framework for comprehensive and coordinated planning of the water and related land resources of the United States. Section 1962 sets the declaration of policy: it is the policy of the Congress to encourage the conservation, development and utilization of water and related land resources of the United States on a comprehensive and coordinated basis by the Federal Government, States, localities and private enterprise, with the cooperation of all affected federal agencies, States, local governments, individuals, corporations, business enterprises and others concerned. The Act creates the institutional machinery to carry out that policy. Section 1962a establishes the Water Resources Council, composed of senior federal officials, with responsibilities including the continuing study of the adequacy of supplies of water necessary to meet the water requirements of each region, the establishment of principles, standards and procedures for federal participants in the preparation of comprehensive regional or river basin plans, and the maintenance of a national assessment of water resources. Section 1962b provides for the establishment of river basin commissions, on the request of the Council or affected States, to serve as the principal agency for the coordination of federal, state, interstate, local and nongovernmental plans for the development of water and related land resources in their areas and to prepare and keep updated comprehensive joint plans. The Act is the legal foundation of coordinated, basin-scale water-resources planning in the United States, designed to replace fragmented single-agency planning with a comprehensive, multi-jurisdictional approach.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-watermelon-research-promotion-act",
    "title": "US Watermelon Research and Promotion Act (7 USC ch 80): The Watermelon Checkoff and National Promotion Board",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Watermelon Research and Promotion Act (7 U.S.C. ch. 80, sections 4901 to 4916) authorizes a national watermelon research and promotion program funded by assessments, administered by the Secretary of Agriculture through the Agricultural Marketing Service. Section 4901 sets out the congressional findings and declaration of policy, authorizing an orderly procedure for developing, financing through assessments on watermelons, and implementing coordinated programs of research, development, advertising, and promotion designed to strengthen watermelon's competitive position and establish domestic and foreign markets. Section 4902 defines the terms, providing that producer means any person engaged in growing 10 or more acres of watermelons, handler means any person who handles watermelons in a manner specified in a plan, and importer means any person who imports watermelons into the United States. Section 4903 authorizes the Secretary to issue plans, and section 4906 prescribes the required terms in a plan, including the establishment of the National Watermelon Promotion Board, composed of representatives of producers, handlers, importers, and one public representative, and the fixing of assessments to cover budgeted costs. Section 4908 sets the assessment procedures, section 4910 provides for enforcement, including civil penalties of not less than 500 dollars nor more than 5,000 dollars per violation and cease-and-desist orders, and section 4911 provides investigation and subpoena power. Section 4912 requires a referendum, providing that a plan shall not take effect unless approved by a majority of producers, handlers, and importers voting, and section 4913 provides for suspension or termination of a plan. The Act is the federal commodity research and promotion regime for watermelons.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-watershed-protection-and-flood-prevention-act",
    "title": "US Watershed Protection and Flood Prevention Act (16 USC 1001 et seq.): Works of Improvement, Local-Organization Assistance and the Conditions for Federal Aid",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Watershed Protection and Flood Prevention Act, codified at 16 U.S.C. 1001 et seq., authorises Federal cooperation with States and local organizations to carry out works of improvement for soil conservation and flood prevention in the watersheds of the rivers and streams of the United States, administered by the Natural Resources Conservation Service of the Department of Agriculture. Section 1001 sets the declaration of policy, finding that erosion, floodwater and sediment damages in watersheds cause loss of life and damage to property and constitute a menace to the national welfare, and declaring that the Federal Government should cooperate with States and their political subdivisions, soil or water conservation districts and other local agencies to prevent such damages and to further the conservation, development, utilization and disposal of water and the conservation and utilization of land. Section 1002 contains the definitions, including works of improvement, watershed or subwatershed area and local organization. Section 1003 authorises the Secretary to provide assistance to local organizations in preparing and carrying out plans for works of improvement. Section 1004 sets the conditions for Federal assistance: before providing assistance the Secretary requires the local organization to acquire the land, easements or rights-of-way needed, to assume the proportionate share of installation costs determined by the Secretary, to make satisfactory arrangements for operating and maintaining the works, to acquire or assure the needed water rights under State law, to obtain soil-conservation agreements from owners of not less than 50 percent of the land in drainage areas above retention reservoirs, and to submit a satisfactory repayment plan for any loan or advancement. The Act is the legal basis of the small-watershed program, the partnership through which local organizations build flood-control and conservation works with Federal support.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-west-virginia-sports-wagering-act-2018",
    "title": "West Virginia Sports Wagering Act 2018 (HB 2751) - Lottery Commission Licensing and 10% Tax",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-02",
    "bluf": "West Virginia House Bill 2751 (signed March 27, 2018) added Article 22D to Chapter 29 of the West Virginia Code, authorising sports wagering regulated by the West Virginia Lottery Commission. West Virginia was among the first states to legalise sports wagering after Murphy v. NCAA (2018) and launched retail sports betting at The Greenbrier on August 30, 2018. The tax rate is 10% of adjusted gross sports wagering revenue for both retail and online/mobile wagering. The minimum age is 21. Licensed lottery facilities may each offer up to three online/mobile sports wagering platform partnerships. West Virginia was also among the earliest states to launch licensed mobile sports betting, with online platforms launching in late 2018.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "us_paspa_repeal",
        "us_uigea_2006",
        "wv_lottery_act",
        "fatf_gambling",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-paspa-repeal-murphy-ncaa-2018-sports-betting",
      "us-uigea-2006-unlawful-internet-gambling",
      "fatf-guidance-rba-gambling-2021"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-whaling-convention-act",
    "title": "US Whaling Convention Act of 1949 (16 U.S.C. Chapter 14): Domestic Implementation of the International Convention for the Regulation of Whaling",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Whaling Convention Act of 1949, codified at 16 U.S.C. Chapter 14, Subchapter II (sections 916 through 916l), implements in United States law the International Convention for the Regulation of Whaling and is administered by the National Oceanic and Atmospheric Administration through the Department of Commerce. Section 916 provides the definitions, including whale, whaling, and the regulations of the International Whaling Commission. Section 916a provides for the United States Commissioner to the International Whaling Commission. Section 916b governs the acceptance or rejection by the United States Government of regulations adopted by the Commission. Section 916c sets the unlawful acts, including engaging in whaling in violation of the Convention, the Act, or any regulation, and the shipping, transporting, or selling of whale products taken in violation. Section 916d provides for licenses to engage in whaling. Section 916e requires the keeping of returns, records, and reports. Section 916f sets the violations, fines, and penalties, including criminal fines and forfeiture. Section 916g provides for enforcement, including powers of search, arrest, and seizure. The Act is the foundational United States statute giving domestic effect to international whaling regulation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-wheat-foods-research-nutrition-education-act",
    "title": "US Wheat and Wheat Foods Research and Nutrition Education Act (7 USC ch 65): Wheat Industry Council and Orders",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Wheat and Wheat Foods Research and Nutrition Education Act (7 U.S.C. ch. 65, sections 3401 to 3417) authorizes orders for wheat and wheat foods research and nutrition education funded by assessments, administered by the Secretary of Agriculture. Section 3401 sets out the congressional findings and declaration of policy, recognizing that wheat and wheat foods are basic and important foods and that research and nutrition education programs are needed to assist in maintaining and expanding domestic and foreign markets and to improve nutrition. Section 3402 defines the terms, and section 3403 authorizes the Secretary to issue orders applicable to persons engaged in the processing of wheat. Section 3404 sets out the permissive terms and conditions of orders, and section 3405 provides for the establishment of the Wheat Industry Council to administer an order, composed of representatives of the wheat industry and a public member. Section 3406 provides an exemption for retail bakers, and section 3407 requires a referendum, providing that an order shall not become effective unless approved by persons voting who represent a specified share of the volume of wheat processed. Section 3408 provides for the refund of the processed wheat assessment, section 3409 provides for petition and review, and section 3410 provides for the enforcement of orders and regulations. Section 3411 provides for the suspension and termination of orders, and section 3412 provides investigation and subpoena power. The Act is the federal research and nutrition education checkoff regime for wheat.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-whistleblower-protection-act-5-usc-2302",
    "title": "Whistleblower Protection Act 1989 (5 USC 2302) and Whistleblower Protection Enhancement Act 2012",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 2302 of title 5 of the United States Code, as enacted by the Whistleblower Protection Act of 1989 (Public Law 101-12) and substantially strengthened by the Whistleblower Protection Enhancement Act of 2012 (Public Law 112-199), prohibits federal personnel actions taken against federal employees and applicants for engaging in protected disclosures and other protected activities. Subsection (b) sets out the thirteen prohibited personnel practices including discrimination on protected grounds, improper soliciting of recommendations, political coercion, deception obstructing competition, improper influence on candidate withdrawals, unauthorised preferences, nepotism, retaliation for protected disclosures under (b)(8), retaliation for protected activities under (b)(9), conduct-based discrimination unrelated to performance, veterans preference violations, merit-system violations, and nondisclosure enforcement restricting protected disclosures. Subsection (b)(8) protects disclosures of any violation of law, rule, or regulation, gross mismanagement, gross waste of funds, abuse of authority, or substantial and specific danger to public health or safety, made to a designated official, Inspector General, Congress, or the public (with restrictions for classified information). The Office of Special Counsel investigates complaints and may seek corrective action through the Merit Systems Protection Board. The 2012 WPEA broadened the definition of disclosure, required specific statutory language in nondisclosure agreements, expanded protected activities, codified mandatory training for new federal employees within 180 days of appointment, and created the Whistleblower Protection Ombudsman role.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-civil-service-reform-act-5-usc-1101",
      "eu-whistleblower-protection-directive-2019-1937"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-wild-and-scenic-rivers-act",
    "title": "US Wild and Scenic Rivers Act (16 USC ch 28): River Designation, Classification and Project Restrictions",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Wild and Scenic Rivers Act, codified at 16 U.S.C. Chapter 28 (sections 1271-1287), establishes a national system to preserve selected rivers with outstandingly remarkable values in their free-flowing condition, administered by the National Park Service, US Forest Service, Bureau of Land Management and US Fish and Wildlife Service depending on the river. Section 1271 declares the policy that certain selected rivers which, with their immediate environments, possess outstandingly remarkable scenic, recreational, geologic, fish and wildlife, historic, cultural or other similar values shall be preserved in free-flowing condition for the benefit and enjoyment of present and future generations. Section 1273 establishes the national wild and scenic rivers system and the three classifications: wild river areas (free of impoundments and generally inaccessible except by trail, with primitive watersheds and unpolluted waters), scenic river areas (free of impoundments, with shorelines or watersheds still largely primitive but accessible in places by road), and recreational river areas (readily accessible by road or railroad, possibly with some development or past impoundment). Section 1274 lists the component rivers and adjacent lands, section 1275 provides for the study of potential additions, and section 1276 lists rivers designated for study. Section 1278 sets the central protection: the Federal Energy Regulatory Commission may not license the construction of any dam, water conduit, reservoir, powerhouse, transmission line or other project works on or directly affecting any river designated as a component of the system, and no federal agency may assist by loan, grant, license or otherwise in the construction of any water resources project that would have a direct and adverse effect on the values for which a designated river was established. Sections 1279 and 1280 withdraw designated public lands from entry and address mining and mineral leasing, and sections 1281 and 1283 set the administration and management policies for designated rivers, including the development of comprehensive management plans. The Act protects rivers chiefly through these designation, licensing and management mechanisms rather than through criminal penalties on private parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-wild-scenic-rivers-act-1968",
    "title": "US Wild and Scenic Rivers Act 1968 - National Wild and Scenic Rivers System Designation, Classification and Section 7 Federal Activity Review",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-15",
    "bluf": "The Wild and Scenic Rivers Act of 1968 (WSRA, Public Law 90-542, codified at 16 USC 1271-1287, enacted 2 October 1968) establishes the National Wild and Scenic Rivers System (NWSRS) protecting selected rivers in their free-flowing condition. As of 2024, the system includes 226 designated river segments totaling approximately 13,467 miles in 41 states and Puerto Rico. The four administering federal agencies are the National Park Service (NPS) and Bureau of Land Management (BLM) within Department of Interior, US Forest Service (USFS) within Department of Agriculture, and US Fish and Wildlife Service (USFWS) within Interior; many designated rivers have multi-agency management. Section 3(a) (16 USC 1274(a)) designates Wild, Scenic and Recreational classifications based on shoreline development, water quality and access. Section 7 (16 USC 1278) prohibits federal agencies from assisting in construction of any water resources project that would have a direct and adverse effect on the values for which a designated river was established, with on-river and off-river analysis. Section 5 (16 USC 1276) authorises study of rivers for potential designation. Section 12 (16 USC 1283) directs federal agencies to consider hydroelectric and water resources project impacts on study and designated rivers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-clean-water-act-1972-epa-corps-engineers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "us-wilderness-act",
    "title": "US Wilderness Act (16 USC 1131-1136): The National Wilderness Preservation System, the Definition of Wilderness and the Use Prohibitions",
    "domain": "Water & Environmental Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Wilderness Act of 1964, codified at 16 U.S.C. 1131 to 1136, establishes the National Wilderness Preservation System and the legal protections that apply to designated wilderness, administered by the federal land-management agencies (the National Park Service, the Forest Service, the Fish and Wildlife Service and the Bureau of Land Management). Section 1131(a) declares the policy of securing for the American people of present and future generations the benefits of an enduring resource of wilderness. Section 1131(c) defines wilderness as an area where the earth and its community of life are untrammeled by man, where man himself is a visitor who does not remain, being an area of undeveloped Federal land retaining its primeval character and influence, without permanent improvements or human habitation, that generally appears to have been affected primarily by the forces of nature, has outstanding opportunities for solitude or a primitive and unconfined type of recreation, and has at least five thousand acres or is of sufficient size to make practicable its preservation. Wilderness areas are designated by Congress. Section 1133(c) sets the core prohibitions: subject to existing private rights, and except as necessary for administration or emergencies, there shall be within any wilderness area no commercial enterprise and no permanent road, and no temporary road, no use of motor vehicles, motorized equipment or motorboats, no landing of aircraft, no other form of mechanical transport, and no structure or installation. Section 1133(d) preserves certain special provisions, including pre-existing grazing where established before 3 September 1964, presidential authorization of water-resource uses in the national interest, and limited mineral provisions. The Act is the strictest federal land-protection regime in the United States, and section 1133(c) is the operative checklist for what may not be done in wilderness.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-wire-act-18-usc-1084",
    "title": "United States Federal Wire Act (Title 18 USC Chapter 50): Wire Communication Facility Prohibition on Interstate Transmission of Wagering Information, Gambling Ships, and Transportation Penalties",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Federal Wire Act and the related federal gambling offences, codified at Title 18 of the United States Code, Chapter 50, are the principal federal criminal statutes governing interstate wagering transmissions and gambling activities by persons engaged in the business of betting or wagering, and are enforced by the Department of Justice. Federal Wire Act, 18 U.S.C. 1081 contains the definitions, including that the term gambling ship means a vessel used principally for the operation of one or more gambling establishments. Federal Wire Act, 18 U.S.C. 1082 makes it unlawful for any citizen or resident of the United States, or any other person who is on an American vessel or is otherwise under or within the jurisdiction of the United States, directly or indirectly to operate a gambling establishment on a gambling ship as defined in section 1081. Federal Wire Act, 18 U.S.C. 1083 prohibits the operation or use, or permitting the operation or use, of a vessel for the carriage or transportation of passengers for hire or otherwise between a point or place within the United States and a gambling ship not within the jurisdiction of any State. Federal Wire Act, 18 U.S.C. 1084 is the central operative provision and provides that whoever being engaged in the business of betting or wagering knowingly uses a wire communication facility for the transmission in interstate or foreign commerce of bets or wagers or information assisting in the placing of bets or wagers on any sporting event or contest commits a federal offence. The 2011 Department of Justice Office of Legal Counsel opinion interpreted Federal Wire Act, 18 U.S.C. 1084 as limited to sports wagering, although that interpretation was reversed in 2018 and partially restored on judicial challenge. The Act is the controlling federal criminal instrument for interstate wagering transmissions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-wire-act-1961-18-usc-1084",
    "title": "Prohibition on the Use of Wire Communication Facilities for Transmitting Wagers or Information Assisting in the Placing of Wagers on Sporting Events or Contests",
    "domain": "Gaming & Gambling",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "18 U.S.C. § 1084 prohibits the use of wire communication facilities to transmit bets or wagers on sporting events or contests across state or international borders. It applies to any person or entity engaged in interstate or foreign wire communications for sports betting operations, with enforcement authority vested in the Department of Justice.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-16-travel-rule-crypto"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-wire-act-1961-doj-online-gambling-interstate",
    "title": "US Wire Act 1961 - DOJ Interstate Online Gambling Prohibition",
    "domain": "Gaming & Gambling",
    "version": "2.0.0",
    "last_updated": "2026-01-01",
    "bluf": "The Interstate Wire Act of 1961 (18 U.S.C. 1084) prohibits the use of wire communications to transmit bets or wagers on sporting events or contests in interstate or foreign commerce; DOJ 2019 opinion restricts the Act to sports betting only, preserving state authority to legalise non-sports online gambling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulation_reference",
        "industry_mapping",
        "iso_standard"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "us-wire-act-1961-online-gambling-doj",
    "title": "Federal Wire Act of 1961 - Prohibition on Interstate Wire Communications for Sports Betting and Related Interpretations by the Department of Justice (2011 and 2019 Opinions)",
    "domain": "Gaming & Gambling",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Wire Act of 1961 prohibits the use of wire communication facilities for transmitting bets or wagers on sporting events across state lines. The Department of Justice's 2011 opinion narrowed its scope to sports gambling, but the 2019 reversal reasserted broader applicability; criminal penalties apply under 18 U.S.C. § 1084 to operators and facilitators of illegal interstate betting systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-5amld-article-2-gambling-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "us-wire-fraud-18-usc-1343",
    "title": "Wire Fraud - 18 USC 1343 Frauds and Swindles by Wire Communication",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "Section 1343 of title 18 of the United States Code criminalises any scheme or artifice to defraud or to obtain money or property by means of false or fraudulent pretenses, representations, or promises, where the actor transmits or causes to be transmitted by means of wire, radio, or television communication in interstate or foreign commerce any writings, signs, signals, pictures, or sounds for the purpose of executing the scheme. The two essential elements are (1) the existence of a scheme to defraud and (2) the use of interstate wire communications in furtherance of that scheme. The general maximum penalty is 20 years imprisonment under the standard wire fraud framework as amended in 2002 by the Sarbanes-Oxley Act, with enhanced penalties of up to 30 years where the violation affects a financial institution or relates to benefits authorised by the President in connection with a declared major disaster or emergency. Section 1343 is the federal government's most flexible white-collar criminal statute and reaches business email compromise, online romance and investment scams, securities fraud schemes communicated by email or chat, AI-generated synthetic-media impersonation scams, cryptocurrency rug pulls, and corporate-revenue manipulation involving interstate-electronic communication. The wire-fraud framework is regularly paired with money-laundering charges under 18 USC 1956 and with RICO predicates under 18 USC 1961.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping",
        "mitre_attack_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-mail-fraud-18-usc-1341",
      "us-money-laundering-control-act-18-usc-1956"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "us-wiretap-act",
    "title": "US Wiretap Act (18 USC ch 119): Interception of Wire, Oral and Electronic Communications",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Wiretap Act, Title III of the Omnibus Crime Control Act as amended by the Electronic Communications Privacy Act (18 U.S.C. ch. 119), prohibits the interception of wire, oral and electronic communications and governs lawful interception by law enforcement, enforced by the Department of Justice and through a civil action. Section 2510 provides the definitions, including wire communication, oral communication, electronic communication and intercept. Section 2511 makes it an offense to intentionally intercept, or to procure another to intercept, any wire, oral or electronic communication, and to disclose or use the contents of a communication known to have been unlawfully intercepted; a violation is generally punishable by a fine and imprisonment for not more than 5 years. The Act recognizes exceptions, including one-party consent under Federal law and provider conduct necessary to render service. Section 2516 identifies the offenses for which an interception order may be sought, and section 2518 sets the strict procedure for a court order, including a showing of probable cause, necessity and minimization. Section 2515 bars the use of unlawfully intercepted communications as evidence, and section 2520 provides a civil action for damages, including statutory damages and attorney fees. The Act is the legal foundation for US electronic surveillance law.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-worker-adjustment-and-retraining-notification-act",
    "title": "US WARN Act (29 USC ch 23): 60-Day Notice of Plant Closings and Mass Layoffs",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-05-26",
    "bluf": "The Worker Adjustment and Retraining Notification Act (WARN Act, 29 U.S.C. ch. 23) requires covered employers to give advance written notice of plant closings and mass layoffs, administered by the Department of Labor with enforcement through the federal courts. Section 2101 supplies the definitions: a covered employer is one with 100 or more employees (excluding part-time employees, or 100 or more employees who in the aggregate work at least 4,000 hours per week), and it defines plant closing, mass layoff and employment loss. Section 2102 sets the core obligation: an employer may not order a plant closing or mass layoff until the end of a 60-day period after serving written notice on affected employees or their representatives, the state dislocated-worker unit, and the appropriate local government, subject to the exceptions in section 2102(b) for a faltering company, unforeseeable business circumstances, or a natural disaster. Section 2103 sets further exemptions, including temporary facilities and strikes or lockouts. Section 2104 sets the enforcement and employer liability: an employer who violates the notice requirement is liable to each affected employee for back pay and benefits for each day of violation, up to a maximum of 60 days, and is subject to a civil penalty of up to 500 dollars per day payable to the local government. Section 2105 preserves other rights and remedies, section 2107 authorizes regulations, and section 2108 addresses the effect on other laws. The Act is the legal foundation of US advance-notice protection in large-scale workforce reductions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "us-wyoming-w-s-17-31-decentralized-autonomous-organization-supplement-2021",
    "title": "Wyoming Decentralized Autonomous Organization Supplement (W.S. 17-31-101 through 17-31-116)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2022-07-01",
    "bluf": "A limited liability company that elects to operate as a Wyoming Decentralized Autonomous Organization under W.S. 17-31-101 et seq. must include the statutory Notice of Restrictions on Duties and Transfers in its articles of organization, register a name containing 'DAO', 'LAO', or 'DAO LLC', file a publicly available identifier of every smart contract used to manage the DAO within thirty days of formation, vest management in its members or in the members and applicable smart contracts that are capable of being updated, recognise that no member has a fiduciary duty other than the implied contractual covenant of good faith and fair dealing unless the articles state otherwise, calculate membership interests by digital-asset contribution unless the articles provide otherwise, accept that smart contracts preempt the articles of organization except as to W.S. 17-31-104 and 17-31-106(a)-(b), and dissolve upon any of the six events listed in W.S. 17-31-114(a) including failure to take any action for one year or loss of natural-person control; the Wyoming Secretary of State will not issue a certificate of authority for a foreign DAO.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-cftc-digital-asset-guidance",
      "us-sec-digital-asset-framework"
    ],
    "primary_citations_count": 12
  },
  {
    "node_id": "usa-21-cfr-part-1271-human-cells-tissues-ctps",
    "title": "USA FDA 21 CFR Part 1271 - Human Cells, Tissues, and Cellular and Tissue-Based Products (HCT/Ps)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "FDA 21 CFR Part 1271 (Human Cells, Tissues, and Cellular and Tissue-Based Products - HCT/Ps) establishes the regulatory framework for human-derived biological materials used in transplantation, therapy, and regenerative medicine. The framework creates a two-tier regulatory approach: (1) HCT/Ps that meet Section 1271.10 criteria (minimal manipulation, homologous use, no systemic effect, not combined with drug/device) are regulated solely under 21 CFR Part 1271 as 361 HCT/Ps (named after the PHS Act Section 351 and 361); (2) HCT/Ps that do not meet all 1271.10 criteria are regulated as drugs, biologics, or devices under PHS Act Section 351 and require BLA, NDA, or PMA approval. Key requirements: donor eligibility determination, current good tissue practice (cGTP), establishment registration, and HCT/P listing with FDA. This regulation governs tissue banks, cord blood banks, reproductive tissue facilities, eye banks, musculoskeletal tissue banks, cardiovascular tissue banks, and manufacturers of advanced cellular therapies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-advanced-therapy-medicinal-products-regulation-1394-2007",
      "eu-gdpr-health-data-article-9"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "usa-commercial-space-launch-act-1984-faa-licensing",
    "title": "USA Commercial Space Launch Act (51 U.S.C. Chapter 509) - FAA Launch and Reentry Licensing",
    "domain": "Space & Satellite Law",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The US Commercial Space Launch Act (originally 1984, recodified at 51 U.S.C. Chapter 509, significantly amended by the Commercial Space Launch Competitiveness Act of 2015 and the FAA Reauthorization Act of 2018) is the primary US legal authority for FAA (Federal Aviation Administration) Office of Commercial Space Transportation (AST) licensing of commercial launch and reentry vehicles, launch sites (spaceports), and reentry sites. Launch operators must obtain an FAA launch license or experimental permit before launching a launch vehicle from US territory or by a US person anywhere. The Act also establishes third-party liability indemnification (cross-waiver) regime requiring all parties to a launch to waive cross-claims and the US government to indemnify above the required insurance level up to a statutory ceiling.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-outer-space-treaty-1967",
      "itu-radio-regulations-2020-edition"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "usa-iecc-2021-international-energy-conservation-code",
    "title": "USA IECC 2021 - International Energy Conservation Code for Commercial and Residential Buildings",
    "domain": "Construction & Real Estate",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The International Energy Conservation Code (IECC) 2021, published by the International Code Council (ICC), establishes minimum energy efficiency requirements for residential (IRC Chapter 11 equivalent) and commercial buildings in the United States. IECC 2021 is adopted (with state and local amendments) as the baseline energy code by most US states and serves as the reference document for federal energy efficiency programs including DOE's Building Energy Codes Program. IECC 2021 contains two compliance paths: prescriptive and performance (energy modeling). The 2021 edition introduced significant updates including: Enhanced Inspection Program (EIP) option, EV-ready requirements, solar-ready zone requirements for residential, and increased insulation requirements over 2018 IECC. Commercial buildings must comply with ANSI/ASHRAE/IES Standard 90.1-2019 (referenced by IECC 2021 for commercial). States establish their own energy code adoption timelines; federal funding (IRA Section 50131) incentivizes states to adopt 2021 IECC or equivalent standard.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-energy-performance-buildings-directive-2024-recast"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "usa-nih-guidelines-recombinant-dna-research-2019",
    "title": "USA NIH Guidelines for Research Involving Recombinant or Synthetic Nucleic Acid Molecules (2019)",
    "domain": "Biotech & Genomics",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The NIH Guidelines for Research Involving Recombinant or Synthetic Nucleic Acid Molecules (NIH Guidelines, first published 1976, comprehensively revised 2019, administered by the NIH Office of Science Policy - OSP) establish biosafety requirements and institutional oversight obligations for all research involving recombinant DNA (rDNA) and synthetic nucleic acid molecules conducted at or supported by institutions receiving NIH funding. The NIH Guidelines require: registration and approval of covered research by Institutional Biosafety Committees (IBC), containment standards by risk group classification (BSL-1 through BSL-4), specific requirements for human gene transfer experiments (formerly requiring RAC review, now IBC-approved protocols with NIH notification), and compliance with the Dual Use Research of Concern (DURC) policy for research creating agents with pandemic potential. Any institution receiving NIH funds for life sciences research must comply with the NIH Guidelines as a condition of funding.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "eu-advanced-therapy-medicinal-products-regulation-1394-2007"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "usa-risk-retention-group-act-1986",
    "title": "Liability Risk Retention Act of 1986 - Risk Retention Groups and Purchasing Groups: Domicile State Regulation, Multi-State Access Without Additional Licensing, Mandatory Disclosures, Solvency Requirements and NAIC Risk Retention Database",
    "domain": "Insurance & Risk",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation establishes the legal framework for risk retention groups (RRGs) and purchasing groups under 15 U.S. Code Chapter 65, allowing them to operate nationwide without needing to be licensed in each state, provided they comply with domicile state regulation and disclosure obligations under § 3902 and § 3903.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bermuda-bma-cissa-commercial-insurer-2023",
      "canada-osfi-e19-own-risk-solvency-2023",
      "eu-delegated-regulation-2016-467-non-life-premium-risk"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ustoa-tour-integrity",
    "title": "USTOA Tour Operator Integrity",
    "domain": "Food & Hospitality",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "USTOA Tour Operator Integrity compliance validates an operator’s adherence to stringent standards for financial stability, consumer protection, and ethical conduct. Verification requires active USTOA membership and confirmed participation within the USTOA $1 Million Travellers Assistance Program. The framework stipulates a minimum operational history of 3 years under consistent ownership. Furthermore, operators must demonstrate financial responsibility by maintaining a valid professional liability insurance policy with coverage meeting a minimum threshold of $1,000,000 USD. Consumer transparency is a critical component, assessed through the clear and conspicuous disclosure of cancellation and refund policies prior to booking. All advertisements and marketing materials are evaluated to ensure they are truthful and accurate, free of any deceptive information regarding services or pricing. Operators must provide clients with comprehensive pre-tour documentation, including detailed itineraries, inclusions, and exclusions. Digital operations are also scrutinized, requiring the use of secure payment processing systems, such as those that are PCI DSS compliant. A publicly accessible data privacy policy governing customer information is mandatory, alongside a formal data breach notification plan to inform affected customers in the event of a security incident.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "pci-dss-hospitality",
      "ccpa-cpra"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "uy-dp-law-2008",
    "title": "Uruguay Personal Data Protection Law No. 18.331 2008 - URCDP",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Uruguay's Ley de Protección de Datos Personales y Acción de Habeas Data (Personal Data Protection and Habeas Data Action Law) - Law No. 18.331, published in the Diario Oficial (official gazette) on 18 August 2008 - is Uruguay's primary personal data protection legislation. Law No. 18.331 is complemented by Decree No. 414/009 of 31 August 2009, which contains the implementing regulation. Uruguay's data protection framework is unique in the Latin American context for two reasons: first, Uruguay obtained European Commission adequacy recognition for personal data protection in 2012 (Commission Decision 2012/484/EU of 21 August 2012, pursuant to EU Directive 95/46/EC), making Uruguay the only country in the Americas (alongside Canada for some data) to hold EU adequacy status as of its adoption, and retaining adequacy recognition under the GDPR era assessments; and second, Uruguay has a dedicated independent supervisory authority - the Unidad Reguladora y de Control de Datos Personales (URCDP - Regulatory and Control Unit for Personal Data), which operates within the Agencia de Gobierno Electrónico y Sociedad de la Información y del Conocimiento (AGESIC - Agency for E-Government and Information and Knowledge Society) as an autonomous and independent unit. Key features of Uruguay's Law No. 18.331: (1) Scope - applies to all processing of personal data by public or private entities, whether automated or manual, within Uruguayan territory; also applies where Uruguayan law governs the processing; (2) Data processing principles - personal data processing must comply with: lawfulness; purpose limitation; proportionality; accuracy; security; confidentiality; data subject participation; and accountability; (3) Sensitive data - the law designates categories of sensitive personal data: racial or ethnic origin; political opinions; moral or religious convictions; trade union affiliation; sexual life; and health or criminal history data; processing of sensitive data is prohibited except where one of the statutory exceptions applies (consent, legal obligation, scientific research, vital interests); (4) ARCO rights - data subjects have the right of access, rectification, updating, inclusion, confidentiality, and suppression (cancelación) of personal data; (5) Habeas data - Law No. 18.331 reinforces the constitutional habeas data action (guaranteed by the Uruguayan Constitution) allowing data subjects to seek judicial protection of their data rights; (6) Registration - data files (archivos, bases de datos) must be registered with the URCDP before processing begins; (7) Cross-border transfer - personal data may only be transferred to countries providing adequate protection or subject to URCDP-approved safeguards; EU adequacy recognition means Uruguay is generally considered an adequate recipient for EU data transfers; (8) URCDP enforcement - the URCDP investigates complaints, conducts audits, issues recommendations and binding decisions, and can impose sanctions; (9) Penalties - administrative sanctions including fines; criminal penalties (imprisonment) for certain wilful violations of the habeas data provisions. Uruguay's EU adequacy status significantly benefits its financial services, technology, and shared services sectors, which frequently receive EU personal data.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-adequacy-decisions-article-45",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "uy-tocaf-decreto-150-012-administracion-financiera-estado-arce",
    "title": "Uruguay TOCAF Decreto 150/012 of 11 May 2012 (Texto Ordenado de Contabilidad y Administracion Financiera del Estado) and ARCE Agencia Reguladora de Compras Estatales",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Uruguayan Texto Ordenado de Contabilidad y Administracion Financiera del Estado (TOCAF, Consolidated Text on State Accounting and Financial Administration) approved by Decreto 150/012 of 11 May 2012 (as substantially amended over time, most recently by Decreto 196/018 and Ley 19.889 of 2020) is the principal Uruguayan regulatory framework governing public procurement and financial administration by entities of the State Public Administration including Central Administration (Administracion Central, ministries and dependencies), Decentralized Services (Servicios Descentralizados), Autonomous Entities (Entes Autonomos), Departmental Governments (Gobiernos Departamentales / Intendencias), and other entities of the public sector. TOCAF consolidates the procurement provisions originally contained in the Ley de Contabilidad and subsequent procurement amendments into a single regulatory text. Title III of TOCAF contains the principal procurement provisions including procurement methods, procedures, and integrity requirements. The Agencia Reguladora de Compras Estatales (ARCE / comprasestatales.gub.uy) under the Office of Planning and Budget (Oficina de Planeamiento y Presupuesto / OPP) is the central procurement policy and operational authority responsible for procurement regulation, central purchasing arrangements, and the State Procurement Information System. The Sistema de Informacion de Compras y Contrataciones Estatales (SICE) operated by ARCE is the federal e-procurement platform for in-scope procurement. Procurement methods established by TOCAF art. 33 to 41 comprise (a) Licitacion Publica (Public Tender, the default open public procedure for prescribed-value acquisitions), (b) Licitacion Abreviada (Abbreviated Tender, for medium-value acquisitions below the Licitacion Publica threshold), (c) Procedimiento de Compra Directa (Direct Procurement, for small-value acquisitions below the Licitacion Abreviada threshold), (d) Pregon (Reverse Auction, for standardised products), (e) Convenio Marco (Framework Agreement), and (f) Excepciones (Exceptions including emergency, sole-source for technical reasons, and prescribed-class exemptions under art. 33 numerals 3 to 4). The Tribunal de Cuentas (Court of Accounts) conducts ex-ante and ex-post procurement audit. Uruguay is NOT a party to the WTO Government Procurement Agreement (GPA) but is an observer. Uruguay is a party to the MERCOSUR Protocol on Public Procurement (signed 2004), the WTO TFA, and UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5",
      "wto-revised-government-procurement-agreement-2012"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uz-law-on-public-procurement-2018-zru-472-uzex",
    "title": "Uzbekistan Law on Public Procurement No. ZRU-472 of 9 April 2018 as amended and Xarid (xarid.uzex.uz) e-procurement platform",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Republic of Uzbekistan Law on Public Procurement No. ZRU-472 (Davlat xaridlari toGrisida qonun) of 9 April 2018 effective 1 January 2019 as substantially amended over time (most recently by Law No. ZRU-684 of 12 April 2021 and Law No. ZRU-799 of 21 December 2022 modernisation amendments), and supplemented by Cabinet of Ministers Resolution No. 1 of 1 January 2020 (Procedure of Public Procurement) and subsequent regulations, is the principal Uzbek statute governing procurement of goods, works, and services by state customers (davlat buyurtmachilari) including the Republican executive bodies (ministries, state committees, agencies), regional and local executive bodies (khokimiyats), state institutions, state-owned enterprises (davlat korxonalari) including national holding companies and major SOEs (Uzbekneftegaz, Uzbekistan Airways, Uzbekenergo etc.), state institutions, and other entities financed by the State budget or off-budget funds. Law ZRU-472 modernised the Uzbek procurement regime aligning with international best practice including the UNCITRAL Model Law on Public Procurement and World Bank procurement principles. The Ministry of Finance of the Republic of Uzbekistan through the Department of Public Procurement is the central regulatory authority responsible for procurement regulation, oversight, and procurement guidance. The Xarid web-portal (xarid.uzex.uz) operated by the Uzbek Republican Currency Exchange (UZEX) is the mandatory federal e-procurement platform for in-scope procurement. The Anti-Monopoly Committee has supplier debarment authority for anti-competitive procurement misconduct. Procurement methods established by Law ZRU-472 art. 32 to 53 comprise (a) Tender (Public Tender, the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Konkurs (Competition for consulting services), (c) Aukcion (Electronic Reverse Auction, for standardised goods), (d) Iz Edinogo Postavshchika (Single Source / sole-source under prescribed exceptions in art. 49 including emergency, sole supplier for technical reasons, prior failed tendering, prescribed-class exemptions, and small-value below thresholds), (e) Zaprashivanie Tsenovykh Predlozheniy (Request for Quotations, for medium-value), (f) Selektivnyy Otbor (Selective Selection, with prequalification), and (g) Sistema Elektronnogo Magazina (Electronic Shop System, for catalogued small-value items). The Chamber of Accounts of the Republic of Uzbekistan conducts ex-post procurement audit. Uzbekistan is NOT a party to the WTO Government Procurement Agreement (GPA) but is in WTO accession process. Uzbekistan is a party to UNCAC and observes the EAEU procurement provisions as a CIS member.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "uz-pdp-law-2019",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "uz-pdp-law-2019",
    "title": "Uzbekistan Law on Personal Data No. UZ-547 of 2019 - ADPD",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Uzbekistan's Law on Personal Data (Закон Республики Узбекистан «О персональных данных» - Qonun 'Shaxsiy ma'lumotlar to'g'risida') - Law No. UZ-547, signed by President Shavkat Mirziyoyev on 2 July 2019 and entering into force on 1 October 2019 - is Uzbekistan's primary personal data protection legislation, establishing a comprehensive framework for the protection of personal data of natural persons in Uzbekistan. The law was enacted as part of Uzbekistan's broader digital economy reforms and New Development Strategy, which includes data localisation requirements and e-government modernisation. The authorised state body for personal data protection is designated by the Cabinet of Ministers of the Republic of Uzbekistan, with oversight functions exercised through the Ministry of Justice and related state bodies. A key feature of Uzbekistan's Law is the data localisation requirement: personal data of Uzbek citizens must be processed and stored using databases located within the territory of the Republic of Uzbekistan, with the registration of cross-border data flows in the State Register of Databases (Uzdataregistr) maintained by the authorised body. Key features of Uzbekistan's Law on Personal Data No. UZ-547: (1) Scope - applies to operators (data controllers) - individuals, legal entities, and government bodies - processing personal data in Uzbekistan; (2) Data localisation - personal data of Uzbek citizens must be processed and stored in databases physically located in Uzbekistan; cross-border transfer of non-localised data requires regulatory compliance; (3) Data processing principles - processing must comply with: lawfulness; purpose limitation; proportionality; accuracy; storage limitation; security; and confidentiality; (4) Sensitive personal data - the law provides enhanced protection for: biometric personal data; medical data; financial data; and other categories designated as restricted data; (5) Data subject rights - right of access; right to rectification; right to erasure; right to object; and right to appeal to the authorised body; (6) Consent - required as the primary lawful basis for personal data processing; must be specific, informed, and voluntary; (7) Operator obligations - operators must register databases containing personal data in the State Register; implement security measures; designate a responsible person for personal data protection; (8) Cross-border transfers - transfers of personal data outside Uzbekistan require compliance with the State Register requirements and must meet the conditions set by the authorised body; (9) Security obligations - operators must implement technical and organisational security measures proportionate to the risk; (10) Enforcement - the authorised body and Ministry of Justice supervise compliance; administrative sanctions and criminal liability apply for serious violations. Uzbekistan's Law is distinctive for its data localisation requirement, making database registration in Uzdataregistr a mandatory prerequisite for cross-border data operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "v2x-communication-ieee-1609-dsrc",
    "title": "IEEE 1609 WAVE - Wireless Access in Vehicular Environments: DSRC, WSMP Protocol, Security Certificates, Certificate Revocation and Resource Manager for V2X Communications",
    "domain": "Automotive & Mobility",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This standard defines the architecture and protocols for Wireless Access in Vehicular Environments (WAVE), enabling secure, low-latency communication between vehicles and infrastructure using DSRC and the WAVE Short Message Protocol (WSMP). It applies to all entities developing, deploying, or operating V2X communication systems and mandates compliance with security certificate management and revocation procedures as specified in IEEE 1609.2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-21434-automotive-cybersecurity-engineering-2021",
      "un-regulation-r155-vehicle-cybersecurity-management",
      "unece-wp29-framework-connected-automated-vehicles"
    ],
    "primary_citations_count": 2
  },
  {
    "node_id": "validating-integrity-of-computing-devices",
    "title": "NIST SPECIAL PUBLICATION 1800-34 Validating the Integrity of Computing Devices",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2022-12-01",
    "bluf": "The supply chains of information and communications technologies are increasingly at risk of compromise from counterfeiting, unauthorized production, tampering, theft, and insertion of unexpected software and hardware. This practice guide demonstrates how organizations can verify that the internal components and system firmware of the computing devices they acquire are genuine and have not been unexpectedly altered during manufacturing, distribution, or operational use. The approach relies on device vendors creating a verifiable artifact within each device that securely binds the device’s attributes to the device’s identity. The customer who acquires the device can then validate the artifact’s source and authenticity, and check the attributes stored in the artifact against the device’s actual attributes to ensure they match.\n\nThis process, a critical foundation of cyber supply chain risk management (C-SCRM), helps organizations avoid using untrustworthy technology components, enable customers to verify product authenticity, and prevent system compromises caused by acquiring compromised technology. It leverages hardware roots of trust as a foundation to maintain trust in a computing device throughout its operational lifecycle. The guide addresses the creation of verifiable descriptions by manufacturers, the verification of devices during acceptance testing, and the continuous verification of components during subsequent stages in the operational environment.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "c-scrm-practices-systems-organizations",
      "nist-sp-800-193-firmware-resiliency",
      "nist-sp-800-53-r5",
      "nist-cybersecurity-framework-2-0",
      "nist-sp-1800-5-it-asset-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "vc-dpa-2021",
    "title": "Saint Vincent and the Grenadines Data Protection Act 2021",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Saint Vincent and the Grenadines enacted the Data Protection Act 2021, a CARICOM and OECS-aligned statute establishing principles for the lawful collection, use, and disclosure of personal information. The Act is administered by a Data Protection Commissioner and confers rights on data subjects including access and correction. Sensitive personal information categories (health, racial origin, political opinions, religious beliefs, criminal history) require explicit consent or a statutory condition. Cross-border transfers require comparable protection or contractual safeguards. Security measures must be implemented to protect personal information against unauthorised access and disclosure. The Act applies to organisations collecting or using personal information of persons in Saint Vincent and the Grenadines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/vc-dpa-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "vclt-vienna-convention-law-of-treaties-1969",
    "title": "Vienna Convention on the Law of Treaties 1969 - VCLT",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Vienna Convention on the Law of Treaties (VCLT, 1969 - 116 Parties, entered into force 1980) is the foundational framework governing the formation, interpretation, amendment, invalidity, and termination of international treaties; although it binds only State parties, its provisions on treaty interpretation (Articles 31-33) are universally recognised as customary international law applicable to all treaties including WTO agreements, bilateral investment treaties, tax treaties, and international commercial conventions - legal practitioners advising on treaty rights and obligations, commercial arbitrators interpreting BITs and trade agreements, and corporate counsel assessing force majeure and treaty-based rights must apply VCLT Articles 31-32 interpretive principles as the controlling methodology, as arbitral tribunals and the ICJ consistently apply these rules even against non-Parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-iccpr-1966-civil-political-rights",
      "rome-statute-1998-international-criminal-court",
      "hague-choice-of-court-convention-2005",
      "un-guiding-principles-business-human-rights"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "vda-6-3-2023-process-audit-standard",
    "title": "VDA 6.3:2023 - Process Audit Standard for Automotive Supply Chain",
    "domain": "Automotive & Mobility",
    "version": "2023 (Edition 3)",
    "last_updated": "2026-05-09",
    "bluf": "VDA 6.3:2023 (Verband der Automobilindustrie Process Audit, Edition 3, 2023) is the German automotive industry's process audit standard used by BMW, Mercedes-Benz, Volkswagen Group, Audi, and Porsche to audit Tier 1 and Tier 2 suppliers; it defines seven process audit question groups (P1-P7) covering potential analysis through customer satisfaction, a 0-10 scoring scale with minimum 80% for series qualification, and the 2023 revision incorporates software-intensive product auditing, cybersecurity (UN R155 alignment), and ESG supply chain considerations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "regulatory_basis",
        "industry_mapping",
        "related_standards",
        "compliance_scope"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iatf-16949-2016-automotive-quality-management-system",
      "automotive-spice-pam-3-1"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "ve-lecdi-2001",
    "title": "Venezuela LECDI 2001 - Habeas Data and Electronic Crimes Law Personal Data Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Venezuela established a constitutional habeas data right through Article 28 of the Bolivarian Constitution of 1999, which guarantees every person the right to access, correct, and request the deletion of personal information held in official or private registries, forming the constitutional foundation of Venezuela's personal data protection framework. Venezuela subsequently enacted the Ley Especial Contra los Delitos Informáticos (LECDI, Special Law Against Computer Crimes) in October 2001, which criminalises unauthorised access to personal data held in computer systems, interception of electronic communications and data transmissions, data sabotage and destruction, computer fraud involving personal data, and the unauthorised seizure or disclosure of personal data obtained from computer systems. The LECDI is administered by the Comisión Nacional de Telecomunicaciones (CONATEL). It establishes criminal penalties including imprisonment and fines for violations of personal data in digital environments. The constitutional habeas data right and LECDI 2001 together constitute Venezuela's primary legal framework for protecting personal data, providing both a fundamental right of access and correction and criminal sanctions for unauthorised processing and disclosure of personal data in information systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ve-lecdi-2001.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "ve-ley-de-contrataciones-publicas-decreto-ley-1399-2014",
    "title": "Venezuela Ley de Contrataciones Publicas (Decreto con Rango, Valor y Fuerza de Ley) Decreto-Ley 1399 of 13 November 2014 and SNCP",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Venezuelan Ley de Contrataciones Publicas (Decreto con Rango, Valor y Fuerza de Ley de Contrataciones Publicas / Law on Public Procurement) issued by Decreto-Ley 1399 of 13 November 2014 (Gaceta Oficial Extraordinaria 6.154 of 19 November 2014, effective 18 November 2014) is the principal Venezuelan statute governing procurement of goods, services, and works by the National Public Administration including the Central Administration (Administracion Central / ministries and dependencies), the Decentralized Functional Administration (autonomous institutes, public-sector enterprises), the National Public Power Branches (Legislative, Judicial, Electoral, Citizen, and Executive), States, Municipalities, autonomous institutes, and other entities financed by the National Treasury. The 2014 Decreto-Ley replaced the prior Ley de Contrataciones Publicas of 14 March 2008 (with intermediate amendments) and remains in force with subsequent supplementary regulation through Reglamento Decreto 2992 of 14 December 2017. The Servicio Nacional de Contrataciones (SNC) operating the Registro Nacional de Contratistas (RNC) at snc.gob.ve is the central regulatory authority responsible for procurement regulation, supplier registration, and supplier debarment. The Sistema de Informacion del Sistema Nacional de Contrataciones Publicas (SISNAC) is the federal procurement information system. Procurement methods established by Ley de Contrataciones Publicas art. 38 to 89 comprise (a) Concurso Abierto (Open Competition, the default open public procedure for high-value acquisitions), (b) Concurso Cerrado (Closed Competition, with prequalification or restricted to pre-approved suppliers), (c) Consulta de Precios (Price Consultation, for medium-value acquisitions), (d) Contratacion Directa (Direct Contracting, sole-source under prescribed exceptions in art. 76 to 78 including emergency, sole supplier for technical reasons, prior failed tendering, and prescribed-class exemptions), (e) Subasta Inversa (Reverse Auction, for standardised products), and (f) Acuerdos Marco (Framework Agreements). The Contraloria General de la Republica conducts ex-post procurement audit. Venezuela is in the MERCOSUR accession process. Venezuela is NOT a party to the WTO Government Procurement Agreement (GPA). Venezuela is a party to ALBA-TCP, the Andean Community (withdrawn 2006), and UNCAC.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "iso-iec-42001-2023-ai-management-system",
      "us-cisa-secure-by-design-principles-2023",
      "nist-sp-800-53-r5",
      "wto-revised-government-procurement-agreement-2012"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "verra-vcs-verification",
    "title": "Verra VCS Carbon Verification",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Verra VCS project verification mandates strict adherence to a comprehensive set of protocols, as stipulated within core VCS Program governance documents, to ensure the integrity of issued Verified Carbon Units (VCUs). Foundational compliance requires that a project possesses a complete description document and exclusively utilizes an approved VCS methodology for quantifying greenhouse gas (GHG) reductions or removals. Procedurally, a mandatory 30-day public comment period is required, affording stakeholders opportunity for review. Projects must substantiate their claims by demonstrating additionality via a Verra-approved tool while also establishing a clearly defined baseline scenario against which performance is measured. All validation and verification activities must be conducted by an independently accredited Validation/Verification Body (VVB) to guarantee impartiality and technical competence. Furthermore, project design must properly account for all relevant GHG scopes and potential leakage emissions, consistent with VCS Standard requirements. A robust monitoring plan must be in place for systematic data collection, and for relevant project types like Agriculture, Forestry, and Other Land Use (AFOLU), a non-permanence risk analysis is obligatory. The project start date must be valid under program rules to be eligible. Successful verification ultimately culminates in VCU issuance directly onto the official Verra Registry, providing a transparent, immutable, and auditable record of generated carbon credits.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14064-ghg-quantify"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "vg-pdpa-2021",
    "title": "British Virgin Islands Data Protection Act 2021",
    "domain": "Data Protection & Privacy",
    "version": "1.1.0",
    "last_updated": "2026-06-29",
    "bluf": "The British Virgin Islands enacted the Data Protection Act, 2021 (No. 3 of 2021), a comprehensive statute aligned with UK and EU data protection standards. Administered by the BVI Information Commissioner, the Act establishes data protection principles, mandates lawful bases for processing, and grants data subjects rights of access, rectification, restriction, erasure, portability, and objection. Controllers must implement data protection by design and by default, conduct Data Protection Impact Assessments for high-risk processing, appoint a Data Protection Officer where required, and report personal data breaches. Cross-border transfers require adequate protection or appropriate safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/vg-pdpa-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "vi-framework",
    "title": "United States Virgin Islands - Federal and Territorial Privacy Rights Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The United States Virgin Islands (USVI) is an unincorporated organised territory of the United States located in the Caribbean Sea. The USVI is governed under the Revised Organic Act of 1954 and has its own legislature (Legislature of the Virgin Islands) and judicial system. US federal law applies to the USVI as a territory. Accordingly, the primary federal privacy statutes - including the Health Insurance Portability and Accountability Act (HIPAA), the Children's Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), the Gramm-Leach-Bliley Act (GLBA), and the Federal Trade Commission Act - apply in the USVI and govern the handling of personal data by organisations operating in the territory. The Federal Trade Commission exercises jurisdiction over unfair or deceptive acts or practices relating to personal data in the USVI. The Virgin Islands Code contains provisions relating to privacy, government records, and electronic transactions applicable in the territory. The USVI does not have a standalone comprehensive personal data protection law equivalent to the GDPR. Organisations processing personal data of individuals in the USVI must comply with all applicable US federal privacy statutes, the Virgin Islands Code provisions, and implement appropriate technical and organisational security measures consistent with the federal privacy regulatory framework.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/vi-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "vienna-convention-consular-relations-1963",
    "title": "Vienna Convention on Consular Relations (VCCR 1963)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Vienna Convention on Consular Relations, done at Vienna on 24 April 1963 and in force since 19 March 1967, governs consular relations between States with 182 parties and codifies the rights and duties of consular posts and officers. Art 5 enumerates 13 consular functions including protection of nationals, passport issuance, and promotion of trade; Art 31 renders consular premises inviolable subject to a narrow fire-or-disaster exception; Art 35 permits inspection of the consular bag on serious grounds (unlike the diplomatic bag); Art 36 - the most operationally significant provision - requires receiving States to notify consular officers without delay when a national is arrested or detained, and to grant access if requested; Art 43 grants only functional immunity (not personal immunity) for official acts; Art 44 allows receiving States to compel consular officers as witnesses (unlike diplomatic agents); and Art 77 provides an Optional Protocol for compulsory ICJ dispute settlement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "hague-judgments-convention-2019",
      "un-iccpr-1966-civil-political-rights",
      "hague-choice-of-court-convention-2005"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "vienna-convention-diplomatic-relations-1961",
    "title": "Vienna Convention on Diplomatic Relations (VCDR 1961)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Vienna Convention on Diplomatic Relations, done at Vienna on 18 April 1961 and in force since 24 April 1964, is the principal multilateral instrument governing diplomatic relations between States, with 193 parties achieving universal ratification. Art 22 renders the premises of a diplomatic mission inviolable; Art 27 protects freedom of official communications and the inviolability of the diplomatic bag; Art 29 renders the person of a diplomatic agent inviolable and not subject to arrest or detention; Art 31 grants immunity from criminal, civil, and administrative jurisdiction of the receiving State subject only to three narrow exceptions; Art 32 provides that immunity may be waived exclusively by the sending State; Art 9 allows the receiving State to declare any mission member persona non grata without giving reasons; and Art 39 governs commencement and termination of privileges and immunities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "hague-judgments-convention-2019",
      "un-iccpr-1966-civil-political-rights",
      "hague-choice-of-court-convention-2005"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "vietnam-ai-law-134-2025-qh15",
    "title": "Vietnam Law on Artificial Intelligence (Law No. 134/2025/QH15)",
    "domain": "AI Governance & Law",
    "version": "1.0.0",
    "last_updated": "2026-06-14",
    "bluf": "Vietnam's Law on Artificial Intelligence No. 134/2025/QH15 was passed by the National Assembly of the Socialist Republic of Vietnam on 10 December 2025 and takes effect on 1 March 2026. It is the first binding national AI law in Southeast Asia and is organised into 8 chapters and 35 articles. The Law establishes a 3-tier risk-based classification system in Article 9 (high-risk, medium-risk, low-risk), a set of prohibited AI practices in Article 7, transparency and labelling obligations for AI-generated audio, image and video content in Article 11, conformity assessment obligations for high-risk systems in Article 13, and detailed provider, deployer and user obligations in Article 14. The Ministry of Science and Technology is the focal state management agency under Chapter VII. Article 35 grants existing AI systems an 18-month grace period for healthcare, education and finance sectors and a 12-month grace period for other sectors from the 1 March 2026 effective date. Article 29 establishes administrative penalties, criminal liability examination and civil compensation obligations for violations, with deployers of high-risk systems liable for damages caused even where they operated in compliance. The Law applies to Vietnamese and foreign entities conducting AI research, development, provision, deployment and use in Vietnam, excluding activities exclusively for national defence, security or cipher purposes.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "asean-guide-ai-governance-ethics-2020",
      "south-korea-ai-basic-act-2024"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "vietnam-electricity-law-2022",
    "title": "Vietnam Electricity Law 2022 (amended Law No. 03/2022/QH15) - Power Market Regulation",
    "domain": "Energy & Utilities",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Vietnam's amended Electricity Law (Law No. 03/2022/QH15), effective January 2023, introduces competitive electricity market reforms including pilot direct power purchase agreements (DPPA) between renewable energy producers and large consumers, competitive wholesale electricity market development, and revised licensing for power generation, transmission, and distribution activities regulated by the Ministry of Industry and Trade (MOIT) and Electricity Regulatory Authority of Vietnam (ERAV).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-electricity-market-reform-regulation-2024-1747",
      "india-electricity-amendment-act-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "vietnam-law-on-entry-exit-47-2019-immigration-department",
    "title": "Vietnam Law on Entry, Exit, Transit and Residence of Foreigners No. 47/2019/QH14 - Immigration Department Framework",
    "domain": "Immigration & Border Control",
    "version": "2.0",
    "last_updated": "2026-05-10",
    "bluf": "Law No. 47/2019/QH14 (Luat Nhap canh, Xuat canh, Qua canh, Cu tru cua nguoi nuoc ngoai tai Viet Nam) governs all aspects of foreign national entry, exit, transit, and residence in Vietnam, replacing Law No. 47/2014/QH13. Administered by the Immigration Management Department (Cuc Quan ly xuat nhap canh) under the Ministry of Public Security (Bo Cong an). Vietnam expanded its e-visa programme to 80+ nationalities in August 2023 (90-day single/multiple entry, extendable once for 90 days). Visa-free entry is extended bilaterally to nationals of 24 countries for stays of 14-45 days. Temporary Residence Cards (TRC) are issued for stays of 1-2 years to workers, investors, and spouses of Vietnamese citizens; a 5-year TRC was introduced in 2023 for investors and skilled workers. The Permanent Residence Card (PRC) pathway exists for long-term residents after 3 years TRC. Work permits (giay phep lao dong) from DOLISA are required for all foreign workers except specific exemptions (managerial representatives, technical specialists under 30 days). Overstay is punishable by administrative fine VND 1,000,000-4,000,000; deportation for overstay over 30 days.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "work_permit_dolisa",
        "asean_framework",
        "investment_law",
        "data_localisation",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icao-doc-9303-travel-document-standards-biometric"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "vietnam-pdp-decree-13-2023",
    "title": "Decree No. 13/2023/ND-CP on the Protection of Personal Data",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "Vietnam's Decree 13/2023/ND-CP establishes a comprehensive data protection framework requiring data controllers and processors to obtain explicit data subject consent for processing personal and sensitive data, conduct impact assessments, and comply with strict cross-border transfer requirements, with oversight by the Ministry of Public Security (MPS) as per Articles 11, 24, and 25.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oecd-privacy-guidelines-2013",
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia",
      "gdpr-article-46-transfer-mechanisms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "virginia-cdpa-health-2026",
    "title": "Virginia Consumer Data Protection Act (CDPA) Health Data Tiering & Telehealth Rules 2026",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-22",
    "bluf": "Virginia CDPA 2026 amendments introduce sensitive data tier for health information with heightened consent, DPIA, and opt-out rights. Telehealth providers must comply with data minimization and cross-border transfer assessments when serving VA patients.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "virginia-consumer-data-protection-act-health-2026",
    "title": "Virginia Consumer Data Protection Act (VCDPA) - Health Data Processing Rules (2026)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "Virginia state-level privacy legislation governing the processing of consumer health data. While entities heavily regulated by HIPAA enjoy entity-level exemptions, non-HIPAA consumer health apps, wearable manufacturers, and wellness platforms must comply with VCDPA mandates including obtaining opt-in consent for sensitive data, conducting Data Protection Assessments, and enabling consumer data rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "vn-cybersecurity-law-2018",
    "title": "Vietnam Law on Cybersecurity 2018 (Law No. 24/2018/QH14)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Vietnam Law No. 24/2018/QH14 on Cybersecurity signed June 12, 2018 effective January 1, 2019 requires enterprises providing services in Vietnam's cyberspace to store Vietnamese user data in Vietnam, verify user identities using phone numbers or identity documents, remove prohibited content within 24 hours of a government request, and provide information and cooperation to the Ministry of Public Security for cybersecurity investigations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/vn-cybersecurity-law-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vn-pdpd-2023"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "vn-decree-13-2023-personal-data-protection",
    "title": "Vietnam Decree 13/2023/ND-CP on Personal Data Protection - Effective 1 July 2023, Three-Type Entity Classification and Cross-Border Impact Assessment",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Domestic and foreign organizations and individuals involved in processing personal data of data subjects in Vietnam, even if processing occurs outside Vietnam, must comply with Decree 13/2023/ND-CP on Personal Data Protection (issued 17 April 2023 by the Government, effective 1 July 2023) as Vietnam's first comprehensive personal data protection instrument, which categorises entities into three types (Personal Data Controller, Personal Data Processor, Personal Data Controller cum Processor), establishes data protection principles, data subject rights, and obligations, requires preparation and submission to the Ministry of Public Security of an impact assessment dossier relating to data processing activities and a separate impact assessment for cross-border transfers of Vietnamese citizens' personal data, places the burden of proving lawful processing on the entity processing the data, and requires Data Controllers and Data Controller cum Processors to notify personal data violations within 72 hours.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "vn-law-on-bidding-22-2023-qh15-effective-2024",
    "title": "Vietnam Law on Bidding (Luat Dau thau) No. 22/2023/QH15 effective 1 January 2024",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Vietnam Law on Bidding No. 22/2023/QH15 (Luat Dau thau) passed by the National Assembly on 23 June 2023 and effective 1 January 2024 is the principal Vietnamese statute governing procurement of goods, services, construction works, and consultancy services by state agencies, state-owned enterprises, and public-investment projects. The 2023 Law replaced the prior Law on Bidding No. 43/2013/QH13 and substantially modernised the Vietnamese procurement regime. The 2023 Law was the first comprehensive procurement reform since the 2013 Law and was driven by Vietnam's accession commitments under the EU-Vietnam Free Trade Agreement (EVFTA, in force August 2020), the UK-Vietnam Free Trade Agreement (UKVFTA), and the CPTPP (Comprehensive and Progressive Agreement for Trans-Pacific Partnership). The 2023 Law introduced key reforms including (a) expanded scope covering state-owned enterprises with majority state capital, (b) mandatory online procurement through the Vietnam National E-Procurement System (Muasamcong / muasamcong.mpi.gov.vn) operated under the Ministry of Finance (Bo Tai chinh) Procurement Management Department following the 2024-25 administrative reform that transferred procurement oversight from the Ministry of Planning and Investment, (c) preferential treatment for domestic goods and small/medium enterprises within Vietnamese constitutional and trade obligations, (d) strengthened anti-corruption and integrity provisions including supplier debarment, (e) procurement methods comprising open bidding (rong rai), limited bidding (han che), direct contracting (chi dinh thau), competitive offer (chao hang canh tranh), self-implementation (tu thuc hien), bid in special cases, and selection of contractor in special cases, and (f) provisions on green public procurement and sustainable procurement criteria. Following Vietnam's 2024-25 administrative reform, the Ministry of Finance (Bo Tai chinh) Procurement Management Department (Cuc Quan ly dau thau) is the principal regulator and operator of the Muasamcong national e-procurement system; the procurement function transferred from the Ministry of Planning and Investment to the Ministry of Finance. The 2023 Law operates within the broader framework of the Vietnamese Civil Code 2015, the Law on Tendering, the Public Investment Law 2019, and the State Budget Law 2015.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "vn-cybersecurity-law-2018",
      "vn-pdpd-2023",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "vn-pdpd-2023",
    "title": "Decree No. 13/2023/ND-CP on Personal Data Protection",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "Vietnam's Decree 13/2023/ND-CP establishes a comprehensive data protection framework requiring explicit consent for processing personal data and mandating impact assessments for cross-border transfers and sensitive data processing. It applies to all domestic and foreign entities processing personal data of individuals in Vietnam, as outlined in Article 2.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "voluntary-principles-security-human-rights",
    "title": "Voluntary Principles on Security and Human Rights (VPSHR) 2000 - Risk Assessment, Public and Private Security Arrangements and Incident Reporting for Extractive Companies",
    "domain": "Mining & Natural Resources",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Voluntary Principles on Security and Human Rights guide extractive companies in conducting security operations while respecting human rights, requiring risk assessments, responsible use of force, and engagement with public and private security providers in line with internationally recognized human rights standards. Key implementation is guided by the principles themselves, though specific articles are not enumerated in the source text.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp",
      "un-guiding-principles-business-hr"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "vu-amlctf-act-13-2014",
    "title": "Vanuatu Anti-Money Laundering and Counter-Terrorism Financing Act No. 13 of 2014",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "Vanuatu's Anti-Money Laundering and Counter-Terrorism Financing Act No. 13 of 2014 (consolidated) defines reporting entities (Section 2), establishes the Financial Intelligence Unit (Section 4), and requires reporting entities to identify customers (Section 12), conduct due diligence (Section 13), maintain business records (Section 14), verify customer identification (Section 16), conduct regular customer due diligence (Section 17), assess money laundering and terrorism financing risk (Section 35), report suspicious transactions (Section 20) and large cash transactions (Section 27) to the Unit.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-10-customer-due-diligence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-3-money-laundering-offence"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "vu-counter-terrorism-act-cap-313",
    "title": "Vanuatu Counter Terrorism and Transnational Organised Crime Act [Cap. 313]",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "Vanuatu's Counter Terrorism and Transnational Organised Crime Act [Cap. 313] defines a terrorist act (Section 3), makes a terrorist act an offence (Section 5) and criminalises terrorism financing (Section 6), the provision of property or services to terrorist groups (Section 7) and dealing with terrorist property (Section 8), provides for regulations specifying terrorist entities (Section 4), and empowers a direction to take control of property of specified entities (Sections 12 and 13) with return of property where appropriate (Section 24).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-3-money-laundering-offence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-10-customer-due-diligence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "vu-eta-2000",
    "title": "Vanuatu Electronic Transactions Act 2000 - Personal Data Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Vanuatu enacted the Electronic Transactions Act No. 24 of 2000, which establishes the legal framework for electronic commerce, digital communications, and electronic transactions in the Republic of Vanuatu. The Act provides legal recognition for electronic records, electronic contracts, and electronic signatures, and establishes baseline obligations for the handling of personal data in electronic transactions. The Department of Information and Communication Technology (ICT Department) within the Government of Vanuatu has oversight of digital infrastructure and electronic transactions. The Act establishes that personal data collected through electronic transactions must be used only for the purposes for which it was collected, that reasonable security measures must be implemented to protect personal data from unauthorised access or disclosure, and that individuals whose personal data is collected through electronic means have the right to access and correct their data. Vanuatu does not have a standalone comprehensive data protection law, and the Electronic Transactions Act 2000 together with constitutional rights and the Telecommunications and Radiocommunications Regulation Act represents the primary legal framework governing the protection of personal data in electronic transactions and digital communications in Vanuatu.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/vu-eta-2000.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "vu-proceeds-of-crime-act-cap-284",
    "title": "Vanuatu Proceeds of Crime Act [Cap. 284]",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-06-19",
    "bluf": "Vanuatu's Proceeds of Crime Act [Cap. 284] defines proceeds of crime (Section 5), creates the money laundering offence (Section 11) and the offence of possessing property suspected of being proceeds of crime (Section 12), and provides for forfeiture orders (Sections 15 and 20), pecuniary penalty orders on conviction (Section 28), restraining orders to preserve property (Sections 50 and 52), and retention of seized property under a restraining order (Section 42).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-recommendation-3-money-laundering-offence",
      "fatf-recommendation-20-reporting-suspicious-transactions",
      "fatf-recommendation-10-customer-due-diligence"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "w3c-activitypub-2018-decentralized-social-protocol",
    "title": "W3C ActivityPub 2018 - Decentralized Social Protocol for Federated Workflow Orchestration",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "W3C ActivityPub (W3C Recommendation, 23 January 2018) is a decentralized social networking and activity distribution protocol that provides server-to-server federation (Article 7) and client-to-server interaction APIs (Article 6). ActivityPub uses ActivityStreams 2.0 vocabulary (W3C Recommendation) to describe activities, actors, and objects, enabling federated workflow orchestration across organizational boundaries without central coordination. ActivityPub underlies Mastodon, Pixelfed, PeerTube, and the broader Fediverse, and is increasingly adopted for decentralized notification workflows, content distribution, and activity logging in enterprise and regulatory reporting contexts.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "w3c-verifiable-credentials-data-model-2-0",
      "w3c-web-annotation-data-model-1-0"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "w3c-did-core-1-0-decentralized-identifiers",
    "title": "W3C DID Core 1.0 - Decentralized Identifiers for Workflow and Identity Automation",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "W3C Decentralized Identifiers (DIDs) v1.0 (W3C Recommendation, 19 July 2022) defines a new type of globally unique identifier that enables verifiable, decentralized digital identity without dependency on centralized registries, identity providers, or certificate authorities. A DID resolves to a DID document containing public keys, authentication methods, and service endpoints. DIDs are controlled by the DID subject (individual, organization, device, or data model) and are independent of any particular ledger or network. Enterprises implementing workflow automation, AI agent orchestration, self-sovereign identity, or cross-organizational trust frameworks must understand DID method selection, DID document lifecycle management, DID resolution protocols, and integration with Verifiable Credentials (VCs) for automated compliance assertion.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "w3c-verifiable-credentials-data-model-2-0",
      "eu-eidas-regulation-910-2014-electronic-identification"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "w3c-json-ld-1-1-linked-data-serialization",
    "title": "W3C JSON-LD 1.1 Linked Data Serialization - Contexts IRIs Node Objects Value Objects Type Coercion Language Maps Framing and Semantic Interoperability for Agent Knowledge Exchange",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "W3C JSON-LD 1.1 is a JSON-based serialization for Linked Data that lets ordinary JSON documents carry unambiguous semantic meaning by mapping JSON keys to IRIs through a context, organised across conformance basic concepts (context IRIs node identifiers JSON object usage and type specification) advanced concepts (context usage value descriptions ordering properties embedding indexing and named graphs) and a data model and grammar covering terms node objects frame objects graph objects value objects and context definitions, with key structural components including the context mechanism for term-to-IRI mapping value objects for typed and language-tagged literals list and set objects for ordered and unordered collections and specialized maps for language index and type organisation, with a complementary JSON-LD API and framing specification for shaping and transforming documents, positioning JSON-LD as the practical vehicle for agent-to-agent knowledge exchange where distributed systems must interoperate across semantic boundaries without centralized schema governance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-9110-http-semantics-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "w3c-json-ld-1-1-linked-data-workflow-standard",
    "title": "W3C JSON-LD 1.1 - Linked Data Format for Machine-Readable Compliance Workflows: Context Definitions, Compact IRIs and Graph Serialisation",
    "domain": "Cloud & SaaS",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "This standard defines a JSON-based serialization format for Linked Data, enabling interoperable data exchange in machine-readable compliance workflows. It requires the use of context definitions (\"@context\"), compact IRIs, and graph serialization mechanisms as specified in Section 4 (Contexts), Section 5 (Compaction), and Section 7 (Graph Serialization) to ensure consistent interpretation of data across systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "mcp-enterprise-auth",
      "automation-bpmn-service-task",
      "automation-bpmn-agent-handover",
      "agent-kill-switch"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "w3c-prov-dm-provenance-data-model-workflow-audit-trail",
    "title": "W3C PROV-DM Provenance Data Model - Workflow Audit Trail Requirements",
    "domain": "Workflow Automation",
    "version": "2.0.0",
    "last_updated": "2026-05-09",
    "bluf": "W3C PROV-DM (April 2013) defines a machine-readable provenance model requiring workflows to record Entity-Activity-Agent triples for every data transformation. Compliance means all workflow steps emit PROV assertions capturing what data was generated (Entity), by which process (Activity), and by whom (Agent), enabling reconstruction of complete audit trails. PROV-O ontology maps to RDF/OWL for interoperable provenance graphs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_framework",
        "regulatory_mapping",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bpmn-2-0-business-process-model-notation",
      "eu-data-governance-act-2022-868"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "w3c-sparql-1-1-query-language",
    "title": "W3C SPARQL 1.1 Query Language - SELECT CONSTRUCT ASK DESCRIBE Query Forms Basic Group Optional Alternative Graph Patterns Property Paths Aggregates Subqueries and Solution Sequence Modifiers for RDF Graph Querying",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "W3C SPARQL 1.1 Query Language is the W3C Recommendation for querying RDF data organised across query forms SELECT for variable bindings CONSTRUCT for RDF graph generation ASK for boolean pattern existence checks and DESCRIBE for resource descriptions, graph pattern types including basic graph patterns as sets of triple patterns matched against RDF data group graph patterns combining patterns within braces optional patterns extending solutions without eliminating results alternative patterns via UNION property paths for compact querying of arbitrary-length connections using star plus question and forward-slash operators, solution sequence modifiers ORDER BY LIMIT OFFSET DISTINCT and REDUCED, advanced features including aggregates COUNT SUM MIN MAX AVG GROUP_CONCAT SAMPLE with GROUP BY and HAVING clauses subqueries enabling complex result processing negation via NOT EXISTS EXISTS filters and MINUS operators, and RDF dataset querying via FROM DEFAULT FROM NAMED and GRAPH keywords, providing the standard interface for knowledge graph workflows.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "w3c-json-ld-1-1-linked-data-serialization"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "w3c-verifiable-credentials-data-model-2-0",
    "title": "W3C Verifiable Credentials Data Model 2.0 - Digital Credential Workflow Standard",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "W3C Verifiable Credentials Data Model 2.0 (VCDM 2.0, W3C Recommendation 2024) defines the data model and proof formats for cryptographically verifiable digital credentials. It underpins EU eIDAS 2.0 digital wallets, digital identity workflows, academic credential automation, regulated professional licence verification, and supply chain compliance attestation systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-eidas-regulation-2014-910",
      "openid-connect-core-1-0-identity-workflow"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "w3c-wcag-2-2-web-content-accessibility-guidelines",
    "title": "W3C WCAG 2.2 Web Content Accessibility Guidelines - Perceivable Operable Understandable Robust Principles 13 Guidelines and Level A AA AAA Success Criteria Including the Nine New 2.2 Criteria",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-29T00:00:00Z",
    "bluf": "W3C WCAG 2.2 is the Web Content Accessibility Guidelines version 2.2 published as a W3C Recommendation organised around four principles Perceivable Operable Understandable and Robust supported by 13 guidelines and conformance levels A AA and AAA, with WCAG 2.2 introducing nine new success criteria including 2.4.11 Focus Not Obscured Minimum at level AA 2.4.12 Focus Not Obscured Enhanced at level AAA 2.4.13 Focus Appearance at level AAA 2.5.7 Dragging Movements at level AA 2.5.8 Target Size Minimum at level AA 3.2.6 Consistent Help at level A 3.3.7 Redundant Entry at level A 3.3.8 Accessible Authentication Minimum at level AA and 3.3.9 Accessible Authentication Enhanced at level AAA, providing the operational floor for digital accessibility compliance under the EU Accessibility Act US Section 508 UK Public Sector Bodies Accessibility Regulations 2018 and Web Accessibility Directive 2016/2102.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-rfc-9110-http-semantics-2022"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "w3c-web-annotation-data-model-1-0",
    "title": "W3C Web Annotation Data Model 1.0 - Structured Annotation Workflow Standard",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The W3C Web Annotation Data Model (WAM, W3C Recommendation February 2017) defines a JSON-LD-based framework for creating, storing, and retrieving structured annotations on web resources. It enables regulatory text markup workflows, legal document annotation pipelines, content review and approval systems, knowledge graph enrichment, and compliance evidence workflows by providing a standardised annotation vocabulary, motivation taxonomy, and body/target structure for attaching structured commentary to any web-addressable resource.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "openid-connect-core-1-0-identity-workflow",
      "cncf-cloudevents-1-0-event-driven-workflow-specification"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "w3c-web-content-accessibility-wcag-2-2-standard",
    "title": "W3C Web Content Accessibility Guidelines (WCAG) 2.2",
    "domain": "Operations & CX",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "WCAG 2.2 requires that digital content be perceivable, operable, understandable, and robust for all users, including people with disabilities. It applies to all public and private sector websites and web applications under conformance levels A, AA, and AAA, with key requirements defined in Success Criteria 1.1.1 through 3.3.8.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "automation-bpmn-service-task",
      "automation-bpmn-error-boundary",
      "mcp-enterprise-auth"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "w3c-webauthn-level-3-2024-passkeys-fido2",
    "title": "W3C Web Authentication (WebAuthn) Level 3 - Passkeys and FIDO2 Phishing-Resistant Authentication",
    "domain": "Workflow Automation",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "W3C Web Authentication (WebAuthn) Level 3 (W3C Recommendation, 2024, building on WebAuthn Level 2 - March 2021) in conjunction with FIDO Alliance FIDO2 Client to Authenticator Protocol (CTAP 2.2) defines the standard for phishing-resistant, hardware-backed authentication using public key cryptography. WebAuthn enables passkeys - discoverable credentials stored in authenticators (device biometrics, hardware security keys) that replace passwords for website and application authentication. NIST SP 800-63-3 classifies FIDO2/WebAuthn at IAL2/AAL2+ (for FIDO2 with hardware authenticators). Organizations implementing WebAuthn for enterprise workflow authentication eliminate credential phishing risk, reduce password management costs, and achieve MFA compliance for frameworks including PCI DSS 4.0, NIS2 Directive, and NIST Cybersecurity Framework. AI agents may use WebAuthn-derived credentials for service authentication in zero-trust workflow environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "eu_ai_act",
        "industry_mapping",
        "iso_standard",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ietf-oauth-2-1-authorization-framework",
      "w3c-did-core-1-0-decentralized-identifiers"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "warehouse-wms-optimization",
    "title": "Warehouse Management (WMS) Logic",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Warehouse Management (WMS) logic must be configured to enforce stringent controls over inventory, operational processes, and system integrity, aligning with governing supply chain regulations and industry best practices. The system mandates First-In, First-Out (FIFO) handling for perishables and First-Expiring, First-Out (FEFO) for goods with expiration dates to prevent spoilage and ensure product safety. Foundational to this control framework is the requirement for complete lot traceability upon receipt, which is further protected by a system-level block on commingling different lots within a single bin location. Physical storage constraints are systematically enforced, validating that location type and dimension matches are correct for stowed goods and that shelf loads do not exceed the 1500 kilogram maximum weight threshold. For operational optimization, velocity codes are subject to a mandatory recalculation every 168 hours, and items must meet a minimum threshold of 50 picks to qualify for a forward picking location. To maintain system governance and auditability, any update to these core logic parameters necessitates a formal change control process. All transactional and configuration changes are captured in immutable audit logs, which must be retained for a period of 3650 days. Access controls are strictly defined, enforcing a separation of duties for inventory adjustments and requiring two-factor authentication for any system override, thereby preserving data integrity and accountability across all warehouse operations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gs1-epcis-transparency",
      "cold-chain-integrity-logic",
      "logistics-jit-inventory",
      "kanban-replenishment",
      "iso-28000-supply-chain",
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wassenaar-arrangement-1996-dual-use-conventional-arms",
    "title": "Wassenaar Arrangement 1996 - Dual-Use Goods and Conventional Arms Export Controls and Initial Elements",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies was established in December 1995 in Wassenaar, the Netherlands and became operational in September 1996. It is a successor to the Cold War-era Coordinating Committee for Multilateral Export Controls (COCOM) which dissolved in 1994. The Arrangement is a voluntary multilateral export control regime with 42 Participating States that contribute to regional and international security and stability by promoting transparency and greater responsibility in transfers of conventional arms and dual-use goods and technologies, thus preventing destabilising accumulations. Initial Elements (revised periodically with latest update December 2023) establish two control lists: the Munitions List (covering conventional military equipment) and the List of Dual-Use Goods and Technologies (covering items with civilian application but potential military use). The List of Dual-Use Goods and Technologies is structured around nine categories (Category 0-8): nuclear materials, materials processing, electronics, computers, telecommunications and information security, sensors and lasers, navigation and avionics, marine, aerospace and propulsion. Participating States report transfers and denials biannually, exchange information on best practices, and review lists annually. The Plenary meeting is held annually in December.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-itar-22-cfr-120-130-arms-export",
      "eu-dual-use-regulation-2021-821"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "wco-revised-kyoto-convention-1999",
    "title": "Revised Kyoto Convention 1999 - WCO International Customs Simplification and Harmonisation",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The Revised Kyoto Convention (RKC) - formally the International Convention on the Simplification and Harmonization of Customs Procedures as amended by the Protocol of Amendment of 26 June 1999 - is the World Customs Organization's (WCO) foundational instrument for modern customs governance. It entered into force 3 February 2006 and has 126 Contracting Parties (WCO Members) as of 2024. The RKC is structured in a Body (general obligations binding on all parties) plus a General Annex (mandatory for all) and Specific Annexes A-K (optional chapters that States select and implement). The General Annex's 10 chapters establish the global customs standards: Chapter 1 (general principles - transparency, predictability), Chapter 3 (clearance formalities - lodgment, acceptance, examination, release), Chapter 4 (duties and taxes), Chapter 5 (guarantees/security), Chapter 6 (customs control - risk management-based selectivity, Chapter 6 Standard 6.2 mandating risk management), Chapter 7 (IT application - electronic filing), Chapter 8 (Customs broker/third party relations), Chapter 9 (information, decisions, advance rulings), and Chapter 10 (appeals). Key innovations: risk management replaces 100% physical examination; advance rulings provide legal certainty; AEO (Authorized Economic Operator) trusted trader programmes; post-clearance audit shifts control after release. The WTO Trade Facilitation Agreement 2017 (TFA) translates core RKC principles into binding WTO treaty obligations, making RKC implementation indirectly WTO-mandatory for 164 WTO Members.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "wto-tbt-agreement-1995-technical-barriers-trade",
      "adr-agreement-1957-dangerous-goods-road",
      "cmr-convention-1956-road-carriage-goods"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "wco-safe-framework",
    "title": "WCO SAFE Framework",
    "domain": "Logistics & Supply Chain",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The SAFE Framework of Standards to Secure and Facilitate Global Trade (SAFE Framework) provides a global standard for supply chain security and trade facilitation, built on three pillars: Customs-to-Customs, Customs-to-Business, and Customs-to-other-Government-Agencies. It is the foundation for the Authorized Economic Operator (AEO) concept.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-28000-supply-chain",
      "c-tpat-minimum-security",
      "port-facility-security-isps"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wco-safe-framework-authorized-economic-operator-aeo-programme",
    "title": "WCO SAFE Framework - Authorized Economic Operator Programme and Mutual Recognition Arrangements",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2021-06-01",
    "bluf": "The WCO SAFE Framework of Standards establishes the Authorized Economic Operator (AEO) concept requiring operators to meet security and compliance standards in exchange for customs facilitation benefits, with mutual recognition arrangements between AEO programs (EU AEO, US C-TPAT, Singapore TradeFIRST) enabling expedited clearance across borders.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_body",
        "instrument_type",
        "jurisdiction",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-customs-trade-partnership-against-terrorism-c-tpat-supply-chain-security",
      "eu-supply-chain-due-diligence-directive-2024-1760-csddd"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "wco-safe-framework-standards",
    "title": "SAFE Framework of Standards",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-04-10",
    "bluf": "The SAFE Framework of Standards to Secure and Facilitate Global Trade, adopted by World Customs Organization (WCO) Members, establishes principles and standards as a minimal threshold for Customs administrations. It aims to secure the movement of global trade in a way that facilitates, rather than impedes, the movement of that trade. This instrument applies to WCO Member Customs administrations, who are in a unique position to provide increased security to the global supply chain and contribute to socio-economic development through revenue collection and trade facilitation. The core obligations are built on five elements: harmonizing advance electronic cargo information requirements for inbound, outbound, and transit shipments; employing a consistent risk management approach to address security threats; performing outbound inspections of high-risk cargo at the request of a receiving nation; providing benefits to businesses that meet minimal supply chain security standards (Authorized Economic Operators); and promoting close cooperation with other government agencies.\n\nThe SAFE Framework rests on three pillars: Customs-to-Customs network arrangements, Customs-to-Business partnerships, and Customs-to-other Government Agencies co-operation. It is designed to enhance world trade, ensure better security against terrorism and other transnational crime, and increase the contribution of Customs and trade partners to the economic and social well-being of nations. By standardizing practices, the Framework improves the ability of Customs to detect high-risk consignments and increases efficiencies, thereby expediting the clearance and release of legitimate goods.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-28000-supply-chain",
      "c-tpat-minimum-security",
      "port-facility-security-isps",
      "icao-annex-17-security",
      "logistics-hs-codes"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "webtrust-for-certification-authorities",
    "title": "WebTrust for Certification Authorities - Trust Services Principles and Criteria for CAs",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-26",
    "bluf": "WebTrust for Certification Authorities is the trust services audit framework, maintained by CPA Canada with the AICPA, used to examine the controls of certificate authorities (CAs) that issue digital certificates underpinning TLS, code signing, and S/MIME. A WebTrust for CA audit is a precondition for inclusion in major browser and operating system root certificate programs, making it foundational public-key-infrastructure assurance. The principles and criteria cover CA business practice disclosure, service integrity, and CA environmental and key management controls.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "soc-2-type-ii-trust-services-criteria-2024",
      "soc2-security-criterion"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "weee-electronic-waste",
    "title": "WEEE: Electronic Waste Recovery",
    "domain": "Sustainability & ESG",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "An entity’s adherence to the Waste Electrical and Electronic Equipment Directive is substantially confirmed, though a critical deficiency exists regarding cross-border commerce obligations. The producer is correctly registered within the relevant EU member state for products falling under WEEE categories and maintains active membership in an approved compliance scheme. Pursuant to producer responsibility requirements, a sufficient financial guarantee is in place, and products display the mandatory WEEE labeling. Comprehensive user information, alongside necessary details for treatment facilities, is provided to end-users and recyclers per statutory instrument. The organization fulfills its reporting duties by submitting annual sales volume data, has documented its data sanitization process, and operates a retail take-back system. A key performance indicator shows the recovery rate target is met at an 85 percent threshold. However, a significant compliance gap is identified through the producer’s failure to appoint an authorized representative for distance selling activities. This absence contravenes specific legal frameworks governing producers selling directly into member states where they do not have a physical establishment, posing a considerable regulatory risk.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "rohs-hazardous-sub",
      "reach-chemical-comp",
      "eu-espr-ecodesign"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wf-lil-framework",
    "title": "Wallis and Futuna - French Data Protection Law (Loi Informatique et Libertés) Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Wallis and Futuna is a French overseas collectivity located in the South Pacific Ocean, comprising the islands of Wallis (Uvea), Futuna, and Alofi. Unlike French overseas departments and EU outermost regions such as Martinique, Guadeloupe, Réunion, Mayotte, French Guiana, and Saint Martin, Wallis and Futuna is not an EU outermost region and the General Data Protection Regulation (GDPR) does not apply there. The applicable data protection framework in Wallis and Futuna is the French Loi Informatique et Libertés (Law on Information Technology and Civil Liberties), which applies in Wallis and Futuna by extension of French sovereignty law. The Commission Nationale de l'Informatique et des Libertés (CNIL) exercises jurisdiction as the supervisory authority for data protection matters in Wallis and Futuna. The territorial administration of Wallis and Futuna is conducted through a Prefect appointed by the French government. Organisations processing personal data of individuals in Wallis and Futuna must comply with the Loi Informatique et Libertés as applicable in French overseas collectivities, implement appropriate technical and organisational security measures, respect individual privacy rights including rights of access and rectification, and limit data collection to specified, legitimate purposes. As a Pacific island territory, Wallis and Futuna is geographically proximate to Pacific Islands Forum member states and regional cybersecurity frameworks inform best practice.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/wf-lil-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "wfa-global-responsible-marketing-principles",
    "title": "Responsible Advertising to Children - WFA Responsible Advertising and Children (RAC) Programme and the ICC Advertising and Marketing Communications Code",
    "domain": "Sales, Marketing & PR",
    "version": "2.0.0",
    "last_updated": "2026-06-29",
    "bluf": "There is no discrete instrument titled the 'WFA Global Responsible Marketing Principles' with numbered Principles 1 to 7. The World Federation of Advertisers (WFA) promotes responsible advertising to children primarily through its Responsible Advertising and Children (RAC) programme and by supporting the self-regulatory framework of the ICC (International Chamber of Commerce) Advertising and Marketing Communications Code, whose Chapter on children and young people sets out the substantive child-advertising provisions. The numbered 'principles' used in this node summarise those ICC Code child-advertising provisions (marketing must be clearly distinguishable as such; must not exploit children's credulity, loyalty, vulnerability or inexperience; must not mislead; must not include a direct appeal to children to persuade parents to buy; and must not undermine parental authority).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coppa-marketing-kids",
      "ftc-endorsement-guides",
      "ama-ethical-marketing",
      "asa-advertising-codes-uk",
      "gdpr-art-21-marketing-optout"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "who-essential-medicines-list-eml-2023",
    "title": "WHO Essential Medicines List (EML) 2023 - 23rd Edition Model List and Selection Criteria",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The World Health Organization Model List of Essential Medicines (WHO EML), 23rd edition (2023), published by the WHO Expert Committee on Selection and Use of Essential Medicines in October 2023, identifies medicines that satisfy the priority health care needs of populations and should be available within functioning health systems at all times in adequate amounts, appropriate dosage forms, assured quality, and at a price individuals and the community can afford. The 23rd EML contains 502 medicines for adults and the complementary list adds 85 additional medicines. The WHO Essential Medicines List is not legally binding but is used globally by governments to develop national essential medicines lists (NEMLs), to set public procurement policies, to guide reimbursement decisions, and to establish formularies for public health programmes. The EML is updated every two years by the WHO Expert Committee; the 2023 update added new cancer medicines, antimicrobials, and treatments for neglected tropical diseases, and adopted the WHO Access, Watch, Reserve (AWaRe) antibiotic classification as an integral part of the list.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "who_gmp_guidelines",
        "who_prequalification_programme",
        "ich_guidelines"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "who-gmp-good-manufacturing-practices-2021",
      "who-prequalification-programme-medicines"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "who-ethics-ai-health-2021",
    "title": "Ethics and Governance of Artificial Intelligence for Health",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This World Health Organization guidance establishes six core principles for the ethical design, deployment, and governance of AI in the health sector, applicable to developers, regulators, and healthcare providers. It mandates that AI for health must protect human autonomy, promote well-being and safety, ensure transparency and intelligibility, foster responsibility and accountability, ensure inclusivity and equity, and be sustainable and responsive (Chapter 2).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-medical-qms",
      "iso-14971-medical-risk",
      "iec-62304-medical-software",
      "good-machine-learning-practice-medical-devices",
      "gdpr-health-data"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "who-ethics-governance-ai-health-2021",
    "title": "WHO Ethics and Governance of Artificial Intelligence for Health 2021 - Compliance Obligations for Health AI Ethical Design, AI in Clinical Decision Support Governance, and WHO Principles for AI Safety in Healthcare Applications",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations for ethical AI design in health under WHO guidelines, focusing on transparency, accountability, and safety in clinical decision support systems. It aligns with EU AI Act 2024 (Regulation (EU) 2024/1689, Article 6) for high-risk AI systems in healthcare.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "iso-42001-risk-assess"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "who-fctc-2003-tobacco-control",
    "title": "WHO Framework Convention on Tobacco Control 2003 - FCTC",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The WHO Framework Convention on Tobacco Control (FCTC, 2003 - 183 Parties as of April 2026, the most widely ratified WHO treaty) establishes binding supply-side and demand-reduction obligations for all aspects of the tobacco product lifecycle; Parties must implement: price and tax measures (Article 6), smoke-free environments (Article 8), tobacco product regulation and disclosure (Articles 9-10), packaging and labelling with pictorial health warnings covering at least 30% of display areas (Article 11), education and public awareness (Article 12), advertising, promotion and sponsorship bans (Article 13), and cessation support (Article 14); the Illicit Trade Protocol 2012 (76 Parties) adds mandatory track-and-trace for cigarettes - tobacco manufacturers, importers, and distributors operating in FCTC Parties must comply with national implementing legislation covering all these obligations or face licence revocation, product seizure, and criminal liability.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "eu_regulation",
        "us_equivalent",
        "global_treaty"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "un-guiding-principles-business-human-rights",
      "eu-csrd-2022-2464",
      "un-convention-against-corruption-uncac-2003",
      "un-iccpr-1966-civil-political-rights"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "who-global-action-plan-antimicrobial-resistance-food",
    "title": "Global action plan on antimicrobial resistance",
    "domain": "Food & Hospitality",
    "version": "1.0.0",
    "last_updated": "2026-04-24",
    "bluf": "This regulation requires nations and food-producing entities to implement a One Health approach to combat antimicrobial resistance by optimizing antimicrobial use in animal health, reducing infection incidence through hygiene, and strengthening surveillance across the food chain, as outlined in the five objectives of the WHA68.7 resolution adopted on 26 May 2015.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "who-global-digital-health-2026",
    "title": "WHO Global Strategy on Digital Health 2020-2025 (2026 Update)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The WHO Global Strategy provides a framework for countries to leverage digital health technologies responsibly, focusing on governance, data standards, interoperability, equity, and ethical use of AI in health systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 2
  },
  {
    "node_id": "who-global-digital-health-strategy-2026",
    "title": "WHO Global Strategy on Digital Health 2020-2025 (2026 Extension) & Governance Framework",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-20",
    "bluf": "The WHO Global Strategy on Digital Health provides a framework for countries to develop and implement digital health technologies responsibly. It emphasises governance, data standards, interoperability, equity, ethics, and the safe use of AI in health systems. The 2026 extension reinforces data protection, cybersecurity, and alignment with national digital health strategies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ehds-regulation-2025",
      "india-abdm-health-data-governance-2026"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "who-global-strategy-digital-health-2020-2025",
    "title": "WHO Global Strategy on Digital Health 2020-2025",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This strategy establishes a global framework for national digital health transformation, requiring Member States to strengthen governance, ensure equitable access to digital health tools, and prioritize interoperability, data privacy, and AI ethics in health systems by 2025. Key actions are outlined in Strategic Objective 2 (Data Access and Interoperability) and Strategic Objective 4 (Innovation and AI).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ehds-regulation-2024",
      "eu-gdpr-health-data-article-9",
      "dicom-imaging-standard"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "who-gmp-good-manufacturing-practices-2021",
    "title": "WHO Good Manufacturing Practices for Pharmaceutical Products: Main Principles",
    "domain": "Pharmaceuticals & Life Sciences",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The WHO Good Manufacturing Practices require pharmaceutical manufacturers to establish a quality management system, as outlined in Section 1.1, and to ensure that personnel are trained and qualified, as stated in Section 2.1.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "who-gmp-pharmaceutical-2022",
    "title": "WHO Good Manufacturing Practices (GMP) for Pharmaceutical Products - Main Principles (WHO Technical Report Series, 2022)",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This regulation establishes the core principles of Good Manufacturing Practices (GMP) for pharmaceutical products, requiring manufacturers to implement a comprehensive quality management system to ensure products are consistently produced and controlled to the quality standards appropriate for their intended use and as required by the marketing authorization (Chapter 1). It applies globally to all entities involved in the manufacturing, packaging, testing, and distribution of pharmaceutical products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-medical-qms",
      "fda-21-cfr-part-11-records",
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "who-gmp-trs-1003-annex-2-manufacturing",
    "title": "WHO Good Manufacturing Practices for Pharmaceutical Products: Personnel, Premises, Equipment, Production, QC and Self-Inspection",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This regulation establishes the minimum Good Manufacturing Practices (GMP) for pharmaceutical product manufacturing, ensuring products are consistently produced and controlled to the quality standards appropriate for their intended use. It mandates specific requirements for personnel, premises, equipment, production processes, and quality control, as detailed in sections 10 through 17, to prevent contamination, mix-ups, and errors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "who-ihr-2005-international-health-regulations-pheic",
    "title": "WHO International Health Regulations (2005) - PHEIC Determination and Core Capacity Obligations",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-05-13",
    "bluf": "The International Health Regulations (2005) are a legally binding instrument adopted under Article 21 of the WHO Constitution that govern the international response to public health risks with potential to spread across borders. The IHR enter into the domestic legal order of 196 States Parties including all WHO Member States. Article 2 sets out the IHR purpose to prevent, protect against, control, and provide a public health response to the international spread of disease in ways commensurate with public health risks. Articles 5 and 13 require States Parties to develop, strengthen, and maintain core public health surveillance and response capacities. Article 6 requires notification of events that may constitute a public health emergency of international concern (PHEIC) using the Annex 2 decision instrument. Articles 7 and 8 cover information sharing about events and consultation. Article 12 grants the WHO Director-General the power to determine that an event constitutes a PHEIC after considering State Party views, the Emergency Committee, and the decision instrument. Articles 15 to 18 enable the Director-General to issue Temporary Recommendations. The 2022 amendments (WHA75.12) reduced the timeline for States to opt out and reduced the IHR entry into force period. The 2024 amendments (WHA77.17) introduce a Pandemic Emergency determination, strengthen equitable access, and refresh core capacities. Implementation is monitored through the State Party Self-Assessment Annual Reporting (SPAR) tool and the Joint External Evaluation (JEE).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "regulatory_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "crpd-un-convention-rights-persons-disabilities-2006",
      "un-icescr-1966-economic-social-cultural-rights",
      "un-iccpr-1966-civil-political-rights"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "who-international-health-regulations-2005-ihr",
    "title": "WHO International Health Regulations 2005 - PHEIC Declaration & Cross-Border Health Emergency Response",
    "domain": "Medical & Healthcare",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The International Health Regulations (2005) (IHR 2005), adopted by the World Health Assembly under WHA58.3, constitute the primary binding international legal framework obligating all 196 States Parties to detect, assess, notify, and respond to public health events of potential international concern. Article 12 empowers the WHO Director-General to declare a Public Health Emergency of International Concern (PHEIC) based on the decision instrument in Annex 2, triggering temporary recommendations under Article 15. States must notify WHO of any PHEIC-qualifying event within 24 hours of assessment (Article 6) and maintain core capacities in surveillance, laboratories, points of entry, and response (Annex 1 minimum requirements). Article 43 restricts States from applying health measures more restrictive than WHO recommendations without scientific justification. The 2024 IHR Amendments (adopted May 2024, WHA77) strengthen Article 12 definitions, add a new 'pandemic emergency' tier above PHEIC, mandate sustainable financing of core capacities, and require equitable access to health products during PHEICs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "who-gmp-pharmaceutical-2022",
      "eu-falsified-medicines-directive-2011-62"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "who-jecfa-food-additive-safety-evaluations",
    "title": "WHO/FAO JECFA Joint Expert Committee on Food Additives - Acceptable Daily Intake (ADI) Methodology: Toxicological Evaluation, NOAEL Determination, Safety Factors, Monograph Publication and Codex GSFA Integration for International Harmonisation",
    "domain": "Food & Hospitality",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulation outlines the scientific methodology used by JECFA to evaluate the safety of food additives, contaminants, and veterinary drug residues, establishing Acceptable Daily Intakes (ADIs) based on toxicological assessments, NOAEL determination, and safety factors. It applies to national food safety authorities, Codex Alimentarius standard-setting bodies, and food industry stakeholders involved in international trade.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "brc-food-safety-global",
      "eu-food-hygiene-regulation-852-2004",
      "codex-haccp-2022",
      "eu-food-law-178-2002"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "who-laboratory-biosafety-manual-4th-edition",
    "title": "WHO Laboratory Biosafety Manual 4th Edition 2020 - Risk Assessment, Biosafety Levels 1-4, Containment Requirements, Personal Protective Equipment, Inactivation and Waste Management",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This manual establishes a risk-based framework for laboratory biosafety, requiring all laboratories handling biological agents to conduct evidence-based risk assessments prior to activities and implement appropriate containment measures, personal protective equipment, and decontamination procedures according to biosafety levels 1-4. Key requirements are structured around the risk assessment monograph and core principles in the LBM4 suite.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "cartagena-protocol-biosafety-2000",
      "cbd-convention-biological-diversity-1992",
      "isber-best-practices-biorepositories-2018"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "who-prequalification-programme-medicines",
    "title": "WHO Prequalification Programme for Medicines - Dossier Submission Requirements (CTD Format), GMP Inspection Criteria, Bioequivalence Studies and Prequalification List for UN Procurement Agencies",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "The WHO Prequalification Programme (PQP) assesses medicines to ensure they meet global standards of quality, safety, and efficacy for procurement by UN agencies and other global health initiatives. Manufacturers must submit a comprehensive product dossier in Common Technical Document (CTD) format, pass a Good Manufacturing Practice (GMP) inspection, and provide evidence of bioequivalence to be included on the WHO List of Prequalified Medicinal Products.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gxp-mfg-practice"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "who-somatic-genome-editing-guidelines-2021",
    "title": "WHO Advisory Committee Human Genome Editing Governance Framework 2021 - Oversight Mechanisms, Registry Requirements and Ethical Principles",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This framework establishes global governance standards for human genome editing, including somatic applications, requiring institutional oversight, registration of research, and adherence to ethical principles as outlined in the nine recommendations of the WHO Expert Advisory Committee. It applies to researchers, institutions, and national regulators involved in human genome editing activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-gcp-e6-r3-2023",
      "iso-13485-qms"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "wipo-berne-article-10-copyright-education-exceptions",
    "title": "WIPO Berne Convention Article 10 and Education Copyright Exceptions - Quotation Rights, Teaching Exemptions and Three-Step Test Application",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Berne Convention, under Article 10, mandates that member countries permit the use of copyrighted works for quotation and for illustration in teaching, provided such use constitutes fair practice and the extent does not exceed that justified by the purpose. This applies to educational institutions, researchers, and publishers operating within signatory nations, establishing a minimum standard for educational exceptions to copyright.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "paris-convention-industrial-property"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wipo-conversation-ai-ip-policy-2020",
    "title": "WIPO Conversation on Intellectual Property and Artificial Intelligence - Compliance Obligations for AI-Generated IP Ownership, AI Inventorship in Patent Law, and Copyright in AI-Assisted Creative Works",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-05-05",
    "bluf": "This node outlines compliance obligations for AI-generated IP ownership, inventorship in patent law, and copyright in AI-assisted works under WIPO frameworks, with overlapping requirements from the EU AI Act (Regulation (EU) 2024/1689, Articles 52-53) for transparency and accountability in high-risk AI systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-ai-act-2024",
      "nist-ai-rmf-1-0",
      "oecd-ai-principles"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "wipo-copyright-digital-agenda",
    "title": "WIPO Copyright Treaty (WCT): Protection of Authors' Rights in the Digital Environment",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The WIPO Copyright Treaty (WCT) requires signatory nations to provide copyright protection for works in the digital environment, mandating legal remedies against the circumvention of Technological Protection Measures (TPMs) under Article 11 and the removal or alteration of Rights Management Information (RMI) under Article 12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-literary-artistic"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wipo-copyright-treaty",
    "title": "WIPO Copyright Treaty",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Organizational alignment with the WIPO Copyright Treaty is achieved through a comprehensive framework addressing digital works, technological safeguards, and rights management integrity. The governing policy affirms that computer programs are protected as literary works, and that the structure of databases qualifies for protection when it constitutes an original intellectual creation. Exclusive control over on-demand digital access is vested in rightholders, necessitating that an explicit license is required for any communication to the public. To enforce these prerogatives, the platform employs effective technical protection measures (TPMs). A stringent internal policy prohibits circumvention of these TPMs and explicitly forbids any trafficking in circumvention-enabling tools or services. In parallel, the system embeds essential digital rights management information (RMI) within protected content. Corporate policy mandates a strict prohibition against the unauthorized removal or alteration of this RMI. Consequently, any distribution of works with modified or stripped RMI is forbidden. Furthermore, all proprietary source code has a registered copyright status, and copyright notice visibility is maintained at a 100 percent level, ensuring full compliance with international digital copyright obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "wipo-copyright-treaty-1996",
    "title": "WIPO Copyright Treaty (WCT)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This international treaty extends copyright protection to the digital environment, requiring contracting parties to provide legal remedies against the circumvention of technological protection measures (TPMs) and the removal or alteration of rights management information (RMI), as mandated by Articles 11 and 12.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-literary-artistic"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wipo-copyright-treaty-wct-1996",
    "title": "WIPO Copyright Treaty (WCT), adopted on December 20, 1996",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The WIPO Copyright Treaty (WCT) establishes international standards for digital copyright protection, requiring contracting parties to provide authors with the exclusive right of communication to the public (Article 8), legal protection against the circumvention of technological protection measures (Article 11), and safeguards for rights management information (Article 12). It applies to all signatory states and their domestic legal frameworks governing copyright in digital environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "dmca-safe-harbor",
      "eu-copyright-directive-art-17",
      "exif-standard-metadata",
      "iptc-photo-metadata",
      "iptc-video-metadata"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "wipo-domain-dispute-udrp",
    "title": "WIPO Domain (UDRP)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "This compliance assessment evaluates disputes under the Uniform Domain Name Dispute Resolution Policy (UDRP), which mandates a complainant satisfy a conjunctive three-part test for a successful domain transfer or cancellation. The initial element requires verifying that the `complainant_has_valid_trademark_rights` and subsequently establishing the `domain_is_identical_or_confusingly_similar` to that protected mark. Second, the complainant must prove the respondent has no legitimate interests in the domain name. A respondent may rebut this by affirmatively showing `respondent_has_demonstrable_legitimate_interest`, which can be evidenced if the domain `is_used_for_bona_fide_offering` of goods or services, if the `is_respondent_commonly_known_by_domain` name, or if it `is_used_for_legitimate_noncommercial_or_fair_use`. The final element necessitates proof that the `domain_registered_in_bad_faith` and also that the `domain_is_being_used_in_bad_faith`. Circumstantial evidence supports a finding of bad faith, including `evidence_intent_to_sell_to_trademark_owner` for profit, `evidence_pattern_of_cybersquatting` to prevent a mark's use, `evidence_intent_to_disrupt_competitor` operations, or `evidence_lure_by_confusion_for_gain` through user misdirection. A complainant's failure to prove any single element results in denial of the remedy.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-trademark-stds"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wipo-hague-design-system",
    "title": "WIPO Hague System (Designs)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "The Hague System (administered by WIPO) allows for the international registration of industrial designs through a single application. It covers up to 100 industrial design-active countries, providing a cost-effective and simplified process for designers to protect their visual innovation across multiple jurisdictions simultaneously.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "paris-convention-industrial-property"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wipo-ict-treaty-standing-committee-sccr-ai-agenda",
    "title": "WIPO Standing Committee on Copyright and Related Rights (SCCR) - Agenda on Artificial Intelligence and Intellectual Property: Member State Positions and Deliberations on AI Training, Authorship, Liability, and Treaty Development",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This regulatory agenda governs international deliberations within WIPO SCCR on the intersection of AI systems and copyright law, focusing on whether AI-generated works qualify for authorship, exceptions for AI training using copyrighted data, liability frameworks for infringing AI outputs, and proposals for equitable remuneration. It applies to member states, rights holders, AI developers, and content platforms engaged in AI model development or deployment involving copyrighted material, based on ongoing discussions under SCCR/44 and related documents.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-1886-2024-literary-artistic-works",
      "eu-copyright-directive-art-17",
      "copyright-fair-use-us",
      "dmca-safe-harbor",
      "eu-data-governance-act-2022"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "wipo-industrial-designs",
    "title": "WIPO Industrial Designs",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with international regulations for industrial designs requires strict adherence to procedural and data formatting standards established under governing treaties and administrative instructions. Each application must provide a valid product indication and present creator identification to be considered complete. Per established data standards, submissions must incorporate a minimum INID code count of five distinct bibliographic data points, all of which require ST.80 INID codes for proper identification. A core component is the mandatory visual representation of the design; applicants must furnish at least one but may not exceed a maximum visual representation count of ten. Crucially, representation format conformance is non-negotiable for all submitted images or drawings. Classification protocols also mandate the use of the Locarno classification system. All designations must specify a locarno class format valid under the 14th edition, which is the locarno edition current for all new filings. The entire application package is evaluated to determine if it is data exchange standard compliant, a fundamental prerequisite for successful international registration and publication according to WIPO procedural guidelines. Failure to satisfy these cumulative requirements will result in processing deficiencies and potential rejection of the design application by the International Bureau.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "hague-system-designs"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "wipo-madrid-system-international-trademark-registration-protocol",
    "title": "WIPO Madrid System - International Trademark Registration Protocol (Madrid Protocol)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2023-07-01",
    "bluf": "The Madrid System for the International Registration of Marks, governed by the Madrid Protocol (1989) and administered by WIPO, allows trademark owners to seek protection in up to 130 countries through a single international application filed in one language with one set of fees. The application must be based on a home registration or application. WIPO notifies designated countries which have 12 or 18 months to refuse protection (depending on the designated country). Once protected, the international registration is managed centrally through WIPO.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "use_cases",
        "related_standards",
        "geographic_scope",
        "compliance_timeline"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-patent-cooperation-treaty-1970"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "wipo-madrid-trademark-system",
    "title": "WIPO Madrid System (Trademarks)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Madrid System (administered by WIPO) is a centrally-managed international trademark registration system. It allows trademark owners to protect their brand in up to 130 countries through a single application, in one language, and by paying a single set of fees, simplifying the process of obtaining and managing international trademark rights.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "paris-convention-industrial-property"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wipo-marrakesh-treaty-2013",
    "title": "Marrakesh Treaty to Facilitate Access to Published Works for Persons Who Are Blind, Visually Impaired or Otherwise Print Disabled",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This treaty requires contracting parties to introduce a standard set of limitations and exceptions to domestic copyright law to permit the reproduction, distribution, and making available of published works in accessible formats for persons who are blind, visually impaired, or otherwise print-disabled, and to permit the cross-border exchange of these accessible format copies (Articles 4 & 5).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-literary-artistic",
      "wipo-copyright-digital-agenda"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "wipo-marrakesh-treaty-visually-impaired-2013",
    "title": "Marrakesh Treaty to Facilitate Access to Published Works for Persons Who Are Blind, Visually Impaired, or Otherwise Print Disabled",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-04-20",
    "bluf": "The WIPO Marrakesh Treaty requires contracting parties to implement exceptions in copyright law allowing authorized entities to create, distribute, and cross-border exchange accessible format copies of published works for beneficiary persons who are blind, visually impaired, or otherwise print disabled, as defined in Article 3. Key obligation: Article 4(1) mandates domestic legal frameworks permitting the creation and sharing of accessible format copies without copyright holder permission.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-2021",
      "cobit-2019-governance-framework"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "wipo-patent-cooperation-pct",
    "title": "WIPO Patent (PCT)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "This international patent application's compliance posture indicates successful completion of initial filing requirements pursuant to the governing legal framework. The application has secured an international filing date, confirmed by its status as Article 11 compliant with a valid receiving office. Administrative prerequisites are satisfied, given that all required fees are paid, the priority claim is valid, and the necessary agent power of attorney has been properly filed. The application has not yet progressed to key intermediate stages. Critically, the international search report is not received, which logically forestalls any opportunity for Article 19 amendment filing. Concurrently, a Chapter II demand for preliminary examination has not been filed, and consequently, the application has not been published. The primary upcoming deadline is national phase entry, for which 900 days remain. To date, national phase entry has not been initiated in any of the 5 designated states. Diligent oversight is imperative for managing forthcoming actions upon receipt of the search report and for making strategic decisions regarding amendments, examination, and the eventual transition into the national stage across all designated jurisdictions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wipo-patent-cooperation-treaty-1970",
    "title": "WIPO Patent Cooperation Treaty (PCT) 1970 - International Patent Application Filing Procedure and National Phase Entry",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Patent Cooperation Treaty (PCT) enables applicants to seek patent protection for an invention in multiple countries simultaneously by filing a single international patent application with a single receiving Office, as outlined in Article 3. This treaty streamlines the initial filing process, establishes a filing date effective in all designated States (Article 11), and centralizes the international search and preliminary examination before the application enters the 'national phase' in individual countries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "paris-convention-industrial-property"
    ],
    "primary_citations_count": 9
  },
  {
    "node_id": "wipo-patents-biotechnology-guidelines-2022",
    "title": "WIPO Patent Protection for Biotechnology Inventions - Patentability Requirements, Morality Exceptions and Sequence Listing Standards",
    "domain": "Biotech & Genomics",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "This WIPO guidance establishes international standards for the patentability of biotechnology inventions, including requirements for industrial applicability, sufficient disclosure, and compliance with morality exclusions under Article 27.2 and 27.3 of the TRIPS Agreement. It applies to patent offices, examiners, and biotech applicants seeking international patent protection.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-patent-cooperation-pct",
      "wipo-copyright-treaty"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "wipo-pct-international-patent",
    "title": "WIPO PCT (International Patents)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Patent Cooperation Treaty (PCT) is an international treaty administered by WIPO. It provides a unified procedure for filing patent applications to protect inventions in each of its contracting states. A single 'international' patent application has the same effect as national applications filed in the designated countries.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "paris-convention-industrial-property"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wipo-pct-patent-rules",
    "title": "WIPO PCT (Patent Rules)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "Compliance with the Patent Cooperation Treaty (PCT) framework mandates strict adherence to procedural and formal requirements for securing an international filing date and facilitating subsequent national phase entry. Governing regulations stipulate that any applicant must be a resident or national of a PCT Contracting State, and the international application must be filed with a competent Receiving Office. A valid priority claim, as per treaty articles, necessitates filing within 12 months of the earliest application date. The submission itself is subject to rigorous content validation; it absolutely must include a formal request, a detailed description of the invention, one or more claims, plus an abstract. Furthermore, if drawings are referenced within the description, then such drawings must be included. The application language also needs to be one accepted by the chosen Receiving Office. Financial obligations are critical; all required fees must be paid on time to avoid negative consequences. Following a successful filing, the process advances toward generating an International Search Report, a key document for assessing patentability. Ultimately, applicants must observe the standard 30-month deadline from the priority date for initiating national phase entry in designated jurisdictions, making procedural precision essential throughout the entire international stage.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "madrid-system-trademarks",
      "hague-system-designs"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "wipo-performances-phonograms",
    "title": "WIPO WPPT (Performances)",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with the WIPO Performances and Phonograms Treaty necessitates stringent verification of fundamental rights and obligations concerning performers and phonogram producers. The framework confirms that performers' moral rights are upheld, requiring clear performer attribution and the existence of an integrity protection mechanism to prevent prejudicial distortion of their work. A central compliance vector involves economic rights, demanding confirmation that a valid reproduction license has been secured from both the performer and the phonogram producer. Similarly, separate authorizations for making works available to the public must be validated for each rights holder. A crucial check verifies that equitable remuneration for broadcasting or any communication to the public has been paid. Furthermore, the platform ensures the asset is within its protection term, which must last for a minimum of fifty years from the date of fixation. The node also enforces modern digital safeguards by validating that the circumvention of technological protection measures is prohibited and that any unauthorized removal or alteration of rights management information is strictly forbidden, thereby protecting the entire rights ecosystem established under the international agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wipo-copyright-treaty"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "wipo-performances-phonograms-treaty-1996",
    "title": "WIPO Performances and Phonograms Treaty (WPPT)",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "This international treaty grants performers (actors, musicians) and producers of phonograms (sound recordings) specific economic and moral rights in the digital environment. It establishes the exclusive right to authorize the making available of their performances and phonograms to the public by wire or wireless means, such as on-demand internet streaming (Articles 10 and 14).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-literary-artistic",
      "wipo-copyright-digital-agenda"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "wipo-performances-phonograms-treaty-wppt-1996",
    "title": "WIPO Performances and Phonograms Treaty (WPPT) (1996)",
    "domain": "Creative, Content & Media IP",
    "version": "1.0.0",
    "last_updated": "2026-04-21",
    "bluf": "The WIPO Performances and Phonograms Treaty (WPPT) establishes minimum rights for performers and producers of phonograms in the digital environment, including rights to authorize broadcasting, fixation, reproduction, distribution, rental, and on-demand communication of performances under Article 6, Article 10, Article 11, and Article 15.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "berne-convention-1886-2024-literary-artistic-works"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "wipo-trade-secret-stds",
    "title": "WIPO Trade Secrets",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "An organizational asset qualifies for robust protection as a trade secret under governing international intellectual property conventions. The information satisfies the fundamental criteria for secrecy, as it is confirmed that the material is not publicly disclosed and is not readily ascertainable by others through legitimate means. Crucially, the asset provides a demonstrable economic advantage, a core component of its value, with its potential compromise presenting a significant financial impact, as indicated by a risk score of 4. The enterprise meets its duty of care by taking reasonable steps to maintain confidentiality, a mandate central to guidance from the World Intellectual Property Organization. This is substantiated through a comprehensive control framework where an implemented confidentiality policy governs conduct, non-disclosure agreements are systematically executed with all third parties, and regular employee training is conducted. A formal data classification scheme underpins the security architecture, ensuring that effective technical access controls are in place and that internal access is restricted based on role-specific necessity. Furthermore, physical security is actively enforced across all relevant facilities. The organization's systematic inventory of this sensitive information establishes a defensible and compliant posture against misappropriation or unfair competition.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wipo-trademark-stds",
    "title": "WIPO Trademark Stds",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.1",
    "last_updated": "2026-04-30",
    "bluf": "Compliance with World Intellectual Property Organization trademark standards mandates strict adherence to data formatting and content protocols for international filings. All transactional data must be structured as valid ST.66 XML, for which `is_st66_xml_valid` is a primary validation checkpoint, with `xml_encoding_is_utf8` as a mandatory specification. The schema enforces that `inid_code_usage_mandatory` for identifying bibliographic data elements is non-negotiable. Specifically, submissions must always contain `has_mandatory_inid_210_application_number` and `has_mandatory_inid_220_filing_date`. Furthermore, comprehensive `has_applicant_information` is required for proper party identification. The framework also `requires_nice_classification` for all goods and services associated with the mark. Critically, the `nice_class_version_specified` must be explicitly declared to ensure contextual accuracy. Each application must designate a `nice_class_count_min` of at least one classification, and the selected class value must conform to the `nice_class_is_numeric_range_1_45`. Submissions lacking `has_mark_representation_data` will be deemed incomplete. Finally, all temporal data points, such as filing or registration dates, must strictly follow the `transaction_date_format_iso8601` standard to guarantee interoperability and prevent ambiguity in official records as established by governing international agreements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "wipo-copyright-treaty"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wipo-traditional-knowledge",
    "title": "WIPO Traditional Knowledge",
    "domain": "Creative, Content & Media IP",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "A `usage_compliance_score` of `0` reflects a complete failure to meet established international norms for the use of traditional knowledge, as articulated within frameworks deliberated by the World Intellectual Property Organization. The subject matter mandates obtaining prior informed consent, a condition registered as `true`, yet no documented PIC from an appropriate authority has been secured; consequently, both the granting authority's verification status and the scope match with intended use are `false`. Furthermore, a critical deficiency exists in the absence of a fair and equitable benefit-sharing agreement, indicated by a `false` status for `has_benefit_sharing_agreement`. While the schema correctly identifies that `is_attribution_to_source_community_required` is `true`, the required attribution is not present. Compounding these fundamental gaps, no `misappropriation_risk_assessment_conducted` has been performed, leaving the organization exposed to significant legal and reputational liabilities. Data governance controls are nonexistent, with the `data_provenance_chain_maintained` and `data_access_restricted_to_authorized_use` parameters both evaluating to `false`. These failures represent a severe deviation from the principles of protecting traditional knowledge from unauthorized appropriation and use, demanding immediate and comprehensive remediation to align with global standards and mitigate potential infringement claims from the source community.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "unesco-cultural-diversity",
      "wipo-copyright-treaty"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "wma-declaration-of-helsinki-2013-research-ethics",
    "title": "WMA Declaration of Helsinki 2013 - Ethical Principles for Medical Research Involving Human Subjects Including Vulnerable Populations",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The WMA Declaration of Helsinki establishes the ethical principles for medical research involving human subjects, mandating that the duty of the physician is to protect the life, health, dignity, integrity, right to self-determination, privacy, and confidentiality of research subjects (Paragraph 9). It applies to all physicians and others involved in medical research on humans, requiring independent ethical review, informed consent, and a favorable risk-benefit assessment before any research can begin.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ich-gcp-e6-r3-2023",
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "woah-aquatic-animal-health-code",
    "title": "WOAH Aquatic Animal Health Code",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "The WOAH Aquatic Animal Health Code complements the Terrestrial Code by setting global standards for the prevention, detection, and control of diseases of fish, molluscs, crustaceans, and amphibians, and for safe international trade in aquatic animals and their products. The Aquatic Code is recognised by the WTO SPS Agreement as the international benchmark for aquatic animal health measures. It covers horizontal standards on risk analysis, surveillance, and certification, and disease-specific chapters for currently listed aquatic diseases including infectious hematopoietic necrosis, white spot syndrome virus, infectious salmon anemia, koi herpesvirus disease, abalone viral ganglioneuritis, and ostreid herpesvirus. Aquaculture compliance is increasingly important given global trade growth and the spread of pathogens via live animal and frozen/chilled product movements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "wto_sps",
        "woah_terrestrial",
        "codex_food",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "woah-terrestrial-animal-health-code"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "woah-terrestrial-animal-health-code",
    "title": "WOAH Terrestrial Animal Health Code",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-30",
    "bluf": "The WOAH Terrestrial Animal Health Code (the Code) is the global reference standard for the prevention, detection, and control of animal diseases affecting terrestrial mammals, birds, and bees, and for the safe international trade of live terrestrial animals and animal products. It is recognised by the WTO SPS Agreement as the international benchmark for animal health measures. The Code is organised into volumes containing horizontal standards (Chapter 1.1-1.6 general provisions; the relevant chapter risk analysis; the relevant chapter quality of veterinary services and aquatic animal health), animal welfare standards (Chapter 7), disease-specific chapters (Chapters 8-15 covering 100+ listed diseases including foot-and-mouth disease, African swine fever, highly pathogenic avian influenza, bluetongue, rabies, BSE, and antimicrobial resistance), and trade-related model certificates. WOAH Members must report disease occurrences via the World Animal Health Information System (WAHIS), and importing countries that impose stricter measures than the Code must justify them via risk assessment under WTO SPS the relevant article.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "wto_sps",
        "woah_aquatic",
        "codex_193",
        "one_health",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 7
  },
  {
    "node_id": "wolfsberg-corresp-bank",
    "title": "Wolfsberg Principles (KYC)",
    "domain": "Banking & Global Finance",
    "version": "1.1.0",
    "last_updated": "2026-04-10",
    "bluf": "The Wolfsberg Anti-Money Laundering (AML) Principles for Correspondent Banking (2022) provide a global standard for the risk-based identification and assessment of correspondent banking clients. it is designed to prevent the misuse of the international financial system by ensuring that banks implement robust due diligence on their respondent institutions.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bank-secrecy-act-suspicious"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wolfsberg-group-aml-principles-correspondent-banking",
    "title": "The Wolfsberg Group Anti-Money Laundering Principles for Correspondent Banking",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This standard requires financial institutions (Correspondent Banks) to conduct risk-based due diligence on their respondent bank clients to prevent money laundering and terrorist financing. Key requirements, detailed in Principles 1-14, include assessing the respondent's AML/CFT controls, ownership structure, customer base, and obtaining senior management approval for high-risk relationships.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "bank-secrecy-act-suspicious"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wolfsberg-group-kyc-questionnaire-2022",
    "title": "Wolfsberg Group KYC Questionnaire (WKQF) 2022 - Standardised Due Diligence Information Framework for Financial Institutions Onboarding Correspondent Banks: Ownership, Controls, Products and AML Governance",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The Wolfsberg Group Correspondent Banking Due Diligence Questionnaire (CBDDQ) provides a standardized framework for Financial Institutions to collect essential information for conducting due diligence on correspondent banking relationships, focusing on assessing AML, CTF, and sanctions risks as required by global standards like the FATF Recommendations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-travel-rule-v2",
      "fatf-pf-risk-assessment-mitigation",
      "bank-secrecy-act-suspicious"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ws-eta-2008",
    "title": "Samoa Electronic Transactions Act 2008 - Personal Data Provisions",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Samoa enacted the Electronic Transactions Act 2008, which establishes the legal framework for electronic commerce and digital transactions in the Independent State of Samoa (Samoa). The Act includes provisions on the legal validity of electronic contracts, electronic signatures, and electronic records, and establishes obligations for the handling of personal data processed through electronic transactions. The Ministry of Communications and Information Technology (MCIT) has administrative oversight of digital infrastructure and electronic transactions in Samoa. The Act requires that personal information collected through electronic transactions be collected only for specified, explicit purposes, that appropriate security measures be implemented to protect personal data from unauthorised access and disclosure, and that individuals be notified of the collection and use of their personal information. Samoa does not have a standalone comprehensive data protection law, and the Electronic Transactions Act 2008 together with constitutional rights of privacy and freedom from unreasonable interference represents the primary legal framework governing the protection of personal data in electronic commerce and digital transactions in Samoa.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ws-eta-2008.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "wto-agreement-government-procurement-2012-gpa",
    "title": "WTO Agreement on Government Procurement 2012 (Revised GPA)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The revised WTO Agreement on Government Procurement (GPA 2012), adopted 30 March 2012 and in force since 6 April 2014, is a plurilateral WTO Annex 4 agreement binding 21 WTO Members collectively covering approximately 48 countries. Art II establishes core principles of non-discrimination, national treatment, and most-favoured-nation treatment for covered procurement; Art I (scope) applies to entities listed in Members' Annexes 1-3 (central government, sub-central government, and other covered entities) for goods, services, and construction above threshold values (SDR 130,000 for central government goods and services; SDR 5,000,000 for construction); Art VII prohibits technical specifications that create unnecessary obstacles to international trade; Art XI mandates minimum tender time limits of 25 calendar days; Art XIV permits limited tendering exceptions including single-source and emergency procurement; Art XV requires public notice and post-award transparency; and Art XIX establishes mandatory domestic review procedures for supplier challenges.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "vclt-vienna-convention-law-of-treaties-1969",
      "wto-tbt-agreement-1995-technical-barriers-trade",
      "wto-anti-dumping-agreement-1994-ada",
      "wto-scm-agreement-1994-subsidies-countervailing"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "wto-agreement-on-agriculture",
    "title": "WTO Agreement on Agriculture (1994): Market Access, Domestic Support and Export Competition",
    "domain": "Agriculture & Agritech",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The Agreement on Agriculture is a Uruguay Round multilateral trade agreement administered by the World Trade Organization that disciplines government support and protection in the agricultural sector across three pillars: market access, domestic support, and export competition. Article 4 governs market access and requires the conversion of non-tariff border measures into ordinary customs duties, a process known as tariffication, and binds those tariffs. Article 5 provides a special safeguard mechanism allowing additional duties in response to import surges or price falls for designated products. Article 6 sets domestic support commitments, providing that a Member shall not provide support to domestic producers in excess of the commitment levels specified in its Schedule as the Total Aggregate Measurement of Support, subject to a de minimis allowance of 5 per cent of the value of production for developed countries and 10 per cent for developing countries, and Article 7 sets general disciplines, with Annex 2 exempting green box measures that have no, or minimal, trade-distorting effects. Articles 8 to 10 discipline export competition, limiting export subsidies to scheduled budgetary outlay and quantity commitments and preventing their circumvention, while Article 12 disciplines export prohibitions and restrictions through notification and consultation. Article 17 establishes the Committee on Agriculture to oversee implementation. The Agreement is the central multilateral framework for agricultural trade.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "wto-agreement-on-rules-of-origin-1994",
    "title": "WTO Agreement on Rules of Origin: Disciplines for Determining the Country of Origin of Goods in Non-Preferential Trade",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The WTO Agreement on Rules of Origin establishes disciplines governing the laws, regulations, and administrative determinations that WTO Members use to determine the country of origin of goods in non-preferential trade, and provides for a long-term harmonization work programme. Article 1 defines rules of origin as those laws, regulations, and administrative determinations of general application applied by any Member to determine the country of origin of goods, excluding rules related to preferential trade regimes. Article 2 sets the disciplines during the transition period, requiring that rules be clearly defined, not used as instruments to pursue trade objectives, not create restrictive or distorting effects, be administered consistently, uniformly, impartially, and reasonably, and be based on a positive standard; origin assessments must be issued within 150 days and remain valid. Article 3 sets the disciplines after the transition period once the harmonized rules take effect. Article 4 establishes the Committee on Rules of Origin and the Technical Committee under the auspices of the World Customs Organization. Article 5 governs notification and the procedures for modification and introduction of new rules of origin. Article 6 provides for review, Article 7 for consultation, and Article 8 for dispute settlement. Article 9 sets the objectives and principles of the harmonization work programme, aiming for harmonized non-preferential rules applied equally for all purposes. Annex I establishes the Technical Committee on Rules of Origin and Annex II contains a common declaration on preferential rules of origin. The Agreement is the foundational instrument for origin determination in trade compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "wto-agreement-on-safeguards-1994",
    "title": "WTO Agreement on Safeguards: Emergency Action on Imports Causing Serious Injury to Domestic Industry",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The WTO Agreement on Safeguards establishes the rules for applying safeguard measures, the emergency import restrictions provided for in Article XIX of GATT 1994, and binds all WTO Members. Article 1 establishes that the Agreement sets the rules for the application of safeguard measures. Article 2 sets the conditions: a Member may apply a safeguard measure to a product only if it has determined that the product is being imported in such increased quantities, absolute or relative to domestic production, and under such conditions as to cause or threaten to cause serious injury to the domestic industry producing like or directly competitive products. Article 3 requires a prior investigation by the competent authorities with public notice and hearings. Article 4 defines serious injury and threat thereof and requires evaluation of all relevant factors. Article 5 limits a measure to the extent necessary to prevent or remedy serious injury and to facilitate adjustment, and disciplines quantitative restrictions. Article 6 permits provisional safeguard measures in critical circumstances for up to 200 days. Article 7 limits the duration of a measure, generally to four years extendable to a maximum of eight, and requires progressive liberalization. Article 8 addresses the maintenance of a substantially equivalent level of concessions. Article 9 provides special treatment for developing country Members. Article 11 prohibits grey-area measures such as voluntary export restraints. Article 12 requires notification to and consultation with the Committee on Safeguards. The Agreement is the foundational instrument for trade-remedy safeguard action in trade compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "wto-anti-dumping-agreement-1994",
    "title": "World Trade Organization Agreement on Implementation of Article VI of GATT 1994 (Anti-Dumping Agreement): Principles, Determination of Dumping, Determination of Injury, Initiation of Investigations, Evidence, Imposition and Collection of Anti-Dumping Duties, Duration and Review, and Dispute Settlement",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Agreement on Implementation of Article VI of the General Agreement on Tariffs and Trade 1994, commonly known as the Anti-Dumping Agreement, is the WTO multilateral instrument implementing the anti-dumping discipline in GATT 1994, Article VI and is administered by the WTO Committee on Anti-Dumping Practices. Anti-Dumping Agreement, Article 1 sets out the principles, providing that an anti-dumping measure shall be applied only under the circumstances provided for in Article VI of GATT 1994 and pursuant to investigations initiated and conducted in accordance with the Agreement. Anti-Dumping Agreement, Article 2 sets out the methodology for the determination of dumping. Anti-Dumping Agreement, Article 3 sets out the process for the determination of injury including positive evidence and an objective examination. Anti-Dumping Agreement, Article 5 governs the initiation and subsequent investigation, including the requirement that an investigation shall be initiated upon a written application by or on behalf of the domestic industry. Anti-Dumping Agreement, Article 6 sets out the evidence requirements. Anti-Dumping Agreement, Article 9 governs the imposition and collection of anti-dumping duties. Anti-Dumping Agreement, Article 11 governs duration and review of anti-dumping duties and price undertakings including the sunset review after five years. Anti-Dumping Agreement, Article 17 governs consultation and dispute settlement. The Agreement is the controlling WTO instrument for anti-dumping measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "wto-anti-dumping-agreement-1994-ada",
    "title": "WTO Anti-Dumping Agreement 1994 - Agreement on Implementation of Article VI of GATT",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-25",
    "bluf": "The WTO Anti-Dumping Agreement (ADA, 1994) governs the conditions under which WTO Members may impose anti-dumping duties (ADDs) on imports sold at less than normal value (dumping margin): investigators must establish (i) dumping margin (export price vs normal value in country of origin - Article 2), (ii) material injury to domestic industry or threat thereof (Article 3), and (iii) causal link (Article 3.5); ADDs are capped at dumping margin (lesser duty rule recommended); sunset after 5 years unless review shows continued necessity (Article 11.3); over 600 ADD measures are currently in force globally - exporters from China, India, South Korea face the highest frequency of ADD investigations; the Agreement applies WTO discipline to national ADD laws including US Tariff Act of 1930, EU Basic AD Regulation 2016/1036, and India Customs Tariff Act 1975.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wto-scm-agreement-1994-subsidies-countervailing",
      "wto-tbt-agreement-1995-technical-barriers-trade",
      "vclt-vienna-convention-law-of-treaties-1969",
      "wto-sps-agreement-food-trade-disputes"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "wto-customs-valuation-agreement-1994",
    "title": "WTO Agreement on Implementation of Article VII of GATT 1994 (Customs Valuation Agreement): The Transaction Value Method and the Valuation Hierarchy",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The WTO Agreement on Implementation of Article VII of the General Agreement on Tariffs and Trade 1994, commonly called the Customs Valuation Agreement, establishes a single international system for determining the customs value of imported goods on which ad valorem duties are assessed, and binds all WTO Members. Article 1 establishes the primary method: the customs value is the transaction value, that is the price actually paid or payable for the goods when sold for export to the country of importation, adjusted in accordance with Article 8. Article 8 specifies the additions to the price actually paid or payable, such as commissions, the cost of containers and packing, and royalties. Where the transaction value cannot be used, the Agreement prescribes a strict sequence of alternative methods that must be applied in order: Article 2 the transaction value of identical goods, Article 3 the transaction value of similar goods, Article 5 the deductive value based on the resale price in the importing country, Article 6 the computed value based on cost of production plus profit and general expenses, and Article 7 the fall-back method using reasonable means consistent with the Agreement. Article 4 allows the importer to request that the order of Articles 5 and 6 be reversed. Article 11 guarantees the importer a right of appeal without penalty against a customs valuation determination. Article 13 permits release of goods against a guarantee where final determination is delayed, and Article 17 preserves the customs administration's right to satisfy itself as to the truth or accuracy of any statement. The Agreement is the foundational instrument for customs valuation in cross-border trade compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "wto-gats-general-agreement-trade-services",
    "title": "WTO General Agreement on Trade in Services (GATS): Most-Favoured-Nation, National Treatment, Market Access, Domestic Regulation, and General Exceptions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The WTO General Agreement on Trade in Services, known as GATS, is the foundational multilateral agreement governing cross-border trade in services and binds all WTO Members across four modes of supply: cross-border supply, consumption abroad, commercial presence, and presence of natural persons. Article I sets the scope and definitions. Article II requires each Member to accord most-favoured-nation treatment, that is treatment no less favourable than that accorded to like services and service suppliers of any other Member. Article III imposes transparency by requiring prompt publication of all relevant measures of general application affecting trade in services. Article VI requires that all measures of general application affecting trade in services are administered in a reasonable, objective and impartial manner. Article VIII requires Members to ensure that monopoly suppliers of a service do not act inconsistently with Article II or with scheduled commitments. Article XIV sets out general exceptions for measures necessary to protect public morals, human, animal or plant life or health, and to secure compliance with laws and regulations not inconsistent with GATS. Article XIV bis preserves security exceptions. Articles XVI and XVII govern the specific commitments scheduled by each Member on market access and national treatment respectively. Article XIX commits Members to successive rounds of negotiations with a view to progressively higher liberalization. Article XXIII establishes the dispute settlement and enforcement framework. The Agreement is the controlling instrument for services trade compliance under the multilateral trading system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "wto-gatt-1994-general-agreement-tariffs-trade",
    "title": "World Trade Organization General Agreement on Tariffs and Trade 1994 (GATT 1994 incorporating GATT 1947): Most-Favoured-Nation Treatment, National Treatment, Schedules of Concessions, Quantitative Restrictions, Anti-Dumping and Countervailing Duties, General Exceptions, Security Exceptions, and Customs Unions",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The General Agreement on Tariffs and Trade 1994 (GATT 1994), which incorporates the provisions of the General Agreement on Tariffs and Trade dated 30 October 1947 (GATT 1947), is the foundational multilateral instrument of the World Trade Organization governing trade in goods and is administered by the WTO Council for Trade in Goods. GATT 1994, Article I sets out the general most-favoured-nation treatment obligation requiring that with respect to customs duties and charges of any kind any advantage favour or privilege granted by any contracting party to any product originating in any other country shall be accorded immediately and unconditionally to the like product originating in or destined for the territories of all other contracting parties. GATT 1994, Article II governs schedules of concessions. GATT 1994, Article III governs national treatment on internal taxation and regulation. GATT 1994, Article VI governs anti-dumping and countervailing duties. GATT 1994, Article XI governs the general elimination of quantitative restrictions. GATT 1994, Article XX sets out the general exceptions including measures necessary to protect public morals, human animal or plant life or health, and the conservation of exhaustible natural resources. GATT 1994, Article XXI sets out the security exceptions. GATT 1994, Article XXIV governs territorial application, frontier traffic, customs unions and free-trade areas. The Agreement is the controlling multilateral instrument for trade in goods under the WTO.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "wto-import-licensing-procedures-agreement-1994",
    "title": "WTO Agreement on Import Licensing Procedures: Neutral, Fair and Non-Burdensome Administration of Import Licences",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-27",
    "bluf": "The WTO Agreement on Import Licensing Procedures disciplines the administrative procedures used by WTO Members to operate import licensing regimes, so that licensing does not itself become a barrier to trade, and binds all Members. Article 1 sets the general provisions: the rules for import licensing procedures shall be neutral in application and administered in a fair and equitable manner, application procedures shall be as simple as possible, and the rules and information must be published. Article 2 governs automatic import licensing, which must not have trade-restrictive effects and must grant approval generally within ten working days. Article 3 governs non-automatic import licensing, used to administer measures such as quotas; such procedures shall correspond in scope and duration to the measure they implement and shall be no more administratively burdensome than absolutely necessary, and the Agreement requires disclosure of quota amounts, opening and closing dates, and allocation among suppliers. Article 4 establishes the Committee on Import Licensing. Article 5 requires Members to notify their licensing procedures to the Committee. Article 6 makes consultation and dispute settlement applicable. Article 7 provides for review of the operation of the Agreement, and Article 8 contains the final provisions. The Agreement is the foundational instrument for the administration of import licences in trade compliance.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "wto-preshipment-inspection-agreement-1994",
    "title": "World Trade Organization Agreement on Preshipment Inspection: Coverage and Definitions, Obligations of User Members, Obligations of Exporter Members, Independent Review Procedures, Notification, Consultation, and Dispute Settlement",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Agreement on Preshipment Inspection is the WTO multilateral instrument adopted as part of the Uruguay Round Agreements governing the activities of preshipment inspection entities mandated by user Members and providing rules governing the obligations of both user Members and exporter Members, administered by the WTO Council for Trade in Goods. Agreement on Preshipment Inspection, Article 1 establishes the coverage and definitions including user Member, exporter Member, preshipment inspection activities, and inspection entities. Agreement on Preshipment Inspection, Article 2 sets out the obligations of user Members including non-discrimination, transparency, protection of confidential information, avoidance of delays, and price verification procedures. Agreement on Preshipment Inspection, Article 3 sets out the obligations of exporter Members including non-discriminatory application of laws and regulations and publication of relevant rules. Agreement on Preshipment Inspection, Article 4 establishes independent review procedures providing a mechanism for resolving disputes between exporters and inspection entities through independent panels. Agreement on Preshipment Inspection, Article 5 governs notification including the requirement that Members submit applicable laws and regulations to the WTO Secretariat. Agreement on Preshipment Inspection, Article 7 provides for consultation among Members regarding matters affecting the Agreement's operation under GATT procedures. Agreement on Preshipment Inspection, Article 8 provides for dispute settlement under GATT 1994 Article XXIII and the Dispute Settlement Understanding. The Agreement is the controlling WTO instrument for preshipment inspection activities.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "wto-revised-government-procurement-agreement-2012",
    "title": "World Trade Organization Revised Agreement on Government Procurement (Revised GPA, as amended on 30 March 2012, in force from 6 April 2014): Definitions, Scope and Coverage, General Principles of National Treatment and Non-Discrimination, Notices of Intended Procurement, Technical Specifications, Treatment of Tenders and Awarding of Contracts, Domestic Review Procedures, and Modifications and Rectifications to Coverage",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Revised Agreement on Government Procurement (Revised GPA), as amended on 30 March 2012 and in force from 6 April 2014, is the WTO plurilateral instrument among 22 parties (including the European Union, the United States, the United Kingdom, Japan, Canada, Australia, South Korea, and Singapore) governing access to government procurement markets above agreed monetary thresholds, administered by the WTO Committee on Government Procurement. Revised GPA, Article I sets the definitions including procuring entity, supplier, covered procurement, and technical specification. Revised GPA, Article II governs scope and coverage and specifies that the Agreement applies to any measure regarding covered procurement for goods and services by government entities above set thresholds. Revised GPA, Article IV establishes the general principles of national treatment and non-discrimination requiring parties to accord treatment no less favourable than the treatment accorded to domestic goods, services and suppliers. Revised GPA, Article VII requires procuring entities to publish notices of intended procurement in designated media remaining readily accessible to the public. Revised GPA, Article X provides that procuring entities shall not adopt or apply any technical specification with the purpose or the effect of creating unnecessary obstacles to international trade. Revised GPA, Article XV governs the treatment of tenders and awarding of contracts. Revised GPA, Article XVIII requires each party to provide a timely, effective, transparent and non-discriminatory administrative or judicial review procedure for supplier challenges. Revised GPA, Article XIX establishes procedures for parties to modify their coverage annexes with notification and consultation requirements. The Agreement is the controlling WTO instrument for plurilateral government procurement disciplines.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "wto-scm-agreement-1994",
    "title": "World Trade Organization Agreement on Subsidies and Countervailing Measures (SCM Agreement): Definition of a Subsidy, Specificity, Prohibited Subsidies, Adverse Effects, Serious Prejudice, Remedies, Investigation Procedures, and Imposition of Countervailing Duties",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Agreement on Subsidies and Countervailing Measures (SCM Agreement) is the WTO multilateral instrument governing subsidies and the use of countervailing measures and is administered by the WTO Committee on Subsidies and Countervailing Measures. SCM Agreement, Article 1 provides that for the purpose of the Agreement a subsidy shall be deemed to exist if there is a financial contribution by a government or any public body within the territory of a Member or any form of income or price support in the sense of Article XVI of GATT 1994, and a benefit is thereby conferred. SCM Agreement, Article 2 sets out the specificity discipline. SCM Agreement, Article 3 prohibits subsidies contingent in law or in fact, whether solely or as one of several other conditions, upon export performance or upon the use of domestic over imported goods. SCM Agreement, Article 5 sets out the adverse effects discipline. SCM Agreement, Article 6 governs serious prejudice. SCM Agreement, Article 7 sets out remedies including consultation and Dispute Settlement Body procedures. SCM Agreement, Article 11 governs the initiation and subsequent investigation of countervailing duty cases. SCM Agreement, Article 19 governs the imposition and collection of countervailing duties. The Agreement is the controlling WTO instrument for subsidies and countervailing measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "wto-scm-agreement-1994-subsidies-countervailing",
    "title": "WTO SCM Agreement 1994 - Subsidies and Countervailing Measures",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-25",
    "bluf": "The WTO Agreement on Subsidies and Countervailing Measures (SCM Agreement, 1994) defines subsidies as financial contributions by governments or public bodies conferring a benefit (Article 1), classifies them as prohibited (export subsidies and import-substitution subsidies - Article 3, actionable per se) or actionable (causing adverse effects - serious prejudice, material injury, nullification and impairment - Articles 5-6), and authorises WTO Members to impose countervailing duties (CVDs) after a domestic investigation establishing (i) existence and specificity of subsidy, (ii) material injury to domestic industry, and (iii) causal link (Articles 10-23); Annex IV defines 'serious prejudice' thresholds (subsidy rate >5% ad valorem, operating losses coverage, debt forgiveness); the Appellate Body has ruled on SCM Agreement interpretation in over 50 disputes - manufacturers, exporters, and state-owned enterprises receiving government support in WTO Members must assess CVD exposure in export markets.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "ISO",
        "NIST",
        "SOC2",
        "GDPR",
        "HIPAA",
        "PCI_DSS",
        "BASEL",
        "FATF",
        "UN_SDG",
        "ILO",
        "UNCITRAL",
        "OECD",
        "WTO",
        "domestic"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wto-tbt-agreement-1995-technical-barriers-trade",
      "vclt-vienna-convention-law-of-treaties-1969",
      "wto-sps-agreement-food-trade-disputes",
      "eu-csrd-2022-2464"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "wto-sps-agreement-1994",
    "title": "World Trade Organization Agreement on the Application of Sanitary and Phytosanitary Measures (SPS Agreement): Scope and Application, Basic Rights and Obligations, Harmonization, Equivalence, Risk Assessment and Appropriate Level of Protection, Transparency, Control Inspection and Approval Procedures, and Dispute Settlement",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Agreement on the Application of Sanitary and Phytosanitary Measures (SPS Agreement) is the WTO multilateral instrument governing measures to protect human, animal or plant life or health from food safety, animal disease and plant pest risks, and is administered by the WTO Committee on Sanitary and Phytosanitary Measures. SPS Agreement, Article 1 sets out the scope and application of the Agreement to all sanitary and phytosanitary measures which may, directly or indirectly, affect international trade. SPS Agreement, Article 2 sets out the basic rights and obligations including the right of Members to take sanitary and phytosanitary measures necessary for the protection of human, animal or plant life or health, provided that such measures are not inconsistent with the provisions of this Agreement. SPS Agreement, Article 3 governs harmonization to international standards, guidelines or recommendations developed by the Codex Alimentarius Commission, the World Organisation for Animal Health, and the Secretariat of the International Plant Protection Convention. SPS Agreement, Article 4 governs equivalence. SPS Agreement, Article 5 governs the assessment of risk and determination of the appropriate level of sanitary or phytosanitary protection. SPS Agreement, Article 7 governs transparency. SPS Agreement, Article 8 governs control, inspection and approval procedures. SPS Agreement, Article 11 governs consultations and dispute settlement. The Agreement is the controlling WTO instrument for sanitary and phytosanitary measures.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "wto-sps-agreement-food-trade-disputes",
    "title": "Agreement on the Application of Sanitary and Phytosanitary Measures (SPS Agreement)",
    "domain": "Food & Hospitality",
    "version": "1.0.2",
    "last_updated": "2026-06-14",
    "bluf": "The SPS Agreement requires WTO members to base food safety, animal, and plant health measures on scientific principles, apply them only to the extent necessary to protect life or health, and avoid arbitrary or unjustifiable discrimination. These obligations are specified under Article 2.2 and Article 5.1 of the SPS Agreement.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "codex-alimentarius-general-principles-hygiene-2020",
      "eu-food-hygiene-regulation-852-2004",
      "brc-food-safety-global",
      "codex-alimentarius-gen",
      "iso-13009-beach-mgmt"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "wto-tbt-agreement-1994",
    "title": "World Trade Organization Agreement on Technical Barriers to Trade (TBT Agreement): General Provisions, Preparation Adoption and Application of Technical Regulations, Conformity Assessment Procedures, Recognition of Conformity Assessment, Information Enquiry Points, Special and Differential Treatment, and Dispute Settlement",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The Agreement on Technical Barriers to Trade (TBT Agreement) is the WTO multilateral instrument governing technical regulations, standards and conformity assessment procedures, and is administered by the WTO Committee on Technical Barriers to Trade. TBT Agreement, Article 1 contains general provisions and confirms that the terms used shall, when used in this Agreement, have the meaning given to them in the United Nations system and by international standardising bodies, and that the Agreement covers all products including industrial and agricultural products but not sanitary and phytosanitary measures as defined in the SPS Agreement. TBT Agreement, Article 2 governs the preparation, adoption and application of technical regulations by central government bodies, including the obligation to ensure that products imported from the territory of any Member shall be accorded treatment no less favourable than that accorded to like products of national origin and to like products originating in any other country, and that technical regulations shall not be more trade-restrictive than necessary to fulfil a legitimate objective. TBT Agreement, Article 5 governs procedures for assessment of conformity by central government bodies. TBT Agreement, Article 6 governs recognition of conformity assessment by central government bodies. TBT Agreement, Article 10 requires Members to establish enquiry points able to answer all reasonable enquiries from other Members and interested parties. TBT Agreement, Article 12 governs special and differential treatment of developing country Members. TBT Agreement, Article 14 governs consultation and dispute settlement. The Agreement is the controlling WTO instrument for technical barriers to trade.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "wto-tbt-agreement-1995-technical-barriers-trade",
    "title": "WTO TBT Agreement 1995 - Technical Barriers to Trade",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The Agreement on Technical Barriers to Trade (TBT Agreement), which entered into force on 1 January 1995 as part of the WTO Marrakesh Agreement, is the primary multilateral rule set governing the use of technical regulations, standards, and conformity assessment procedures (CAPs) in international trade. With 166 WTO Members bound by the Agreement, the TBT Agreement prevents countries from using technical regulations and standards as disguised trade barriers while preserving their right to regulate for legitimate objectives - including human health and safety, animal and plant life, environmental protection, consumer protection, and national security (Article 2.2). The Agreement's key disciplines: (a) Technical regulations must be based on international standards (ISO, IEC, ITU, Codex Alimentarius, OECD) unless inappropriate or ineffective; (b) Technical regulations must not create unnecessary obstacles to trade; (c) Conformity assessment procedures (testing, certification, inspection) must not be more burdensome than necessary; (d) Mutual Recognition Agreements (MRAs) are encouraged; (e) Members must notify the WTO TBT Committee of draft regulations at least 60 days before adoption (with exceptions for urgent situations). The TBT Agreement applies to all products including agricultural and industrial products but excludes services and purchasing specifications in government procurement. The WTO TBT Committee (Annex 1 body) oversees implementation; Members raise Specific Trade Concerns (STCs) against regulations they believe are WTO-inconsistent. Major TBT disputes include: EC - Measures Affecting Asbestos (DS135), EC - Sardines (DS231), US - Clove Cigarettes (DS406), and EC - Seal Products (DS400/401). The EU's CE marking, REACH notification, and product safety regulations are frequently raised as TBT STCs by trading partners.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso",
        "nist",
        "gdpr",
        "sox",
        "hipaa",
        "pci_dss",
        "basel_iii",
        "fatf",
        "custom"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "wto-sps-agreement-food-trade-disputes",
      "eu-reach-regulation-1907-2006",
      "eu-machinery-regulation-2023"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "wto-trade-facilitation-agreement-2017",
    "title": "WTO Trade Facilitation Agreement (TFA) 2017 - Customs Procedures, Border Agency Cooperation, Freedom of Transit and Special Provisions for Developing Countries",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.1",
    "last_updated": "2026-04-30",
    "bluf": "The WTO Trade Facilitation Agreement (TFA), which entered into force on 22 February 2017, requires member countries to expedite the movement, release, and clearance of goods across borders, including goods in transit, through simplified and harmonized customs procedures. Developed countries must apply all substantive provisions immediately, while developing and least-developed countries (LDCs) implement based on self-declared Category A, B, or C notifications indicating readiness and capacity needs.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "vclt-vienna-convention-law-of-treaties-1969"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "wto-trims-trade-related-investment-measures-1994",
    "title": "WTO Agreement on Trade-Related Investment Measures (TRIMS): Coverage, National Treatment and Quantitative Restriction Discipline, Exceptions, Notification, Transparency, Committee, and Dispute Settlement",
    "domain": "Trade Compliance & Export Controls",
    "version": "1.0.0",
    "last_updated": "2026-05-28",
    "bluf": "The WTO Agreement on Trade-Related Investment Measures, known as TRIMS, is a multilateral agreement in Annex 1A to the WTO Agreement that disciplines investment measures by Members where they affect trade in goods. WTO Agreement on Trade-Related Investment Measures, Article 1 sets the coverage of the Agreement as investment measures related to trade in goods only. WTO Agreement on Trade-Related Investment Measures, Article 2 contains the central operative discipline: no Member shall apply any TRIM that is inconsistent with the provisions of Article III or Article XI of GATT 1994. WTO Agreement on Trade-Related Investment Measures, Article 3 provides that all exceptions under GATT 1994 shall apply, as appropriate, to the provisions of this Agreement. WTO Agreement on Trade-Related Investment Measures, Article 4 contains special provisions for developing country Members. WTO Agreement on Trade-Related Investment Measures, Article 5 requires Members to notify non-conforming TRIMs within ninety days of entry into force and to eliminate them within transitional periods of two years for developed countries, five years for developing countries, and seven years for least-developed countries. WTO Agreement on Trade-Related Investment Measures, Article 6 establishes transparency obligations including notification of where TRIMs may be found in domestic publications. WTO Agreement on Trade-Related Investment Measures, Article 7 establishes the Committee on Trade-Related Investment Measures to monitor implementation and report annually to the Council. WTO Agreement on Trade-Related Investment Measures, Article 8 provides that consultation and dispute settlement follow the procedures in Articles XXII and XXIII of GATT 1994. WTO Agreement on Trade-Related Investment Measures, Article 9 requires the Council for Trade in Goods to review the operation of the Agreement within five years of entry into force. The Annex contains the Illustrative List of TRIMs identifying measures that violate national treatment (such as local content requirements) and quantitative restrictions (such as import or export limitations tied to production or foreign exchange). The Agreement is the controlling multilateral instrument for trade-related investment measure discipline under the WTO system.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "related_frameworks"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 8
  },
  {
    "node_id": "xk-pdpl-2019",
    "title": "Kosovo Law No. 06/L-082 on Protection of Personal Data - AIP",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Kosovo's Law No. 06/L-082 on Protection of Personal Data, adopted by the Assembly of Kosovo in 2019 and building upon earlier data protection legislation enacted since Kosovo's Declaration of Independence in 2008, is Kosovo's primary personal data protection legislation establishing a GDPR-aligned rights-based framework for the protection of personal data. Kosovo has pursued EU integration as a central foreign policy objective and has aligned its personal data protection framework with the EU General Data Protection Regulation as part of its broader European integration agenda under the Stabilisation and Association Agreement signed with the EU in 2015. The supervisory authority is the Information and Privacy Agency (Agjencia për Informim dhe Privatësi / Агенција за информације и приватност - AIP), an independent institution whose mandate covers both personal data protection and freedom of information in Kosovo. Key features of Kosovo's Law on Protection of Personal Data: (1) Scope - applies to personal data processing by public authorities, legal entities, and individuals established in Kosovo or processing data of individuals located in Kosovo regardless of the establishment's location; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right to data portability; and right not to be subject to solely automated decisions; (6) Data Protection Officer - required for public authorities and organisations processing personal data on a large scale or systematically; (7) Breach notification - controllers must notify the AIP of personal data breaches likely to result in risk to data subjects, aligned with GDPR breach notification standards; (8) Data Protection Impact Assessment - required for high-risk processing aligned with GDPR standards; (9) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or using AIP-approved safeguards; and (10) Administrative fines - graduated fines for violations imposed by the AIP. Kosovo's data protection framework reflects its European integration trajectory and the influence of the Council of Europe Convention 108+ framework, positioning it as a GDPR-aligned jurisdiction within the Western Balkans.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "yara-virustotal-pattern-matching-malware",
    "title": "YARA Pattern-Matching Language v4.5.5 (Meta, Strings, Condition Blocks; nocase/wide/ascii/fullword/xor/base64 Modifiers; VirusTotal/EDR/Sandbox Adoption; YARA-X Rust Rewrite)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-03",
    "bluf": "YARA is the open-source pattern-matching language for identifying and classifying malware samples and other artifacts, maintained at github.com/VirusTotal/yara by VirusTotal (now part of Google's Threat Intelligence Group). The most recent maintenance release is v4.5.5 dated 30 October 2025; the original C engine is in maintenance mode with new feature development continuing in YARA-X, a Rust rewrite at github.com/VirusTotal/yara-x. A YARA rule contains three primary sections: meta (descriptive metadata such as description, author, threat-level, reference URL, classification), strings (the patterns to match), and condition (the boolean logic that determines when the rule triggers). YARA supports three string types: text strings (literal character sequences), hexadecimal patterns (binary sequences with wildcards and jumps like { 6A 40 68 ?? ?? [4-8] }), and regular expressions (PCRE-style patterns). String modifiers include nocase (case-insensitive), wide (UTF-16 encoded), ascii (force ASCII when also wide), fullword (word-boundary matching), xor (XOR-key brute force across a range), base64 (base64-encoded variants), and private (suppress reporting). The condition section supports comparison and logical operators, file-position references (at, in), file-size and entry-point references, integer functions (uint8, uint16, uint32 with optional endianness), the of operator for selecting subsets of strings, externals for runtime variables, modules (pe, elf, math, hash, cuckoo) extending the language for parsed file formats, and the for ... of and for ... in iteration operators. YARA is the canonical pattern-matching tool used by VirusTotal, malware sandboxes (Cuckoo, ANY.RUN, Joe Sandbox, Hatching Triage), EDR vendors (CrowdStrike Falcon, SentinelOne, Microsoft Defender), and threat intelligence teams worldwide.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "specification_basis",
        "key_institutions",
        "rule_structure_three_sections",
        "meta_section",
        "strings_section_three_types",
        "string_modifiers",
        "condition_section_operators_and_modules",
        "yara_x_rust_rewrite",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "oasis-stix-2-1-structured-threat-information",
      "sigmahq-sigma-detection-rule-format",
      "oasis-cacao-v2-0-security-playbooks",
      "mitre-attack-framework-v14"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "ye-motit-framework",
    "title": "Yemen MOTIT Framework - Arab ICT Organisation and Constitutional Privacy Obligations",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "The Republic of Yemen has established the Ministry of Telecommunications and Information Technology (MOTIT) as the national authority for electronic communications and ICT services. The Constitution of the Republic of Yemen establishes fundamental rights including the right to privacy of private life, freedom from arbitrary surveillance, and the inviolability of personal correspondence and communications. Yemen enacted an Electronic Transactions Law establishing a framework for the legality of electronic commerce and digital transactions, which includes provisions on the protection of personal data in electronic systems. MOTIT and the Telecommunications Regulatory Authority (TRA) of Yemen regulate the telecommunications sector including subscriber data protection obligations. Yemen does not have a standalone comprehensive personal data protection law. As a member of the Arab League and the Organisation of Islamic Cooperation (OIC), Yemen participates in regional frameworks for data protection and cybersecurity including the Arab ICT Organisation guidelines and OIC guidelines on cybersecurity and data protection. The ongoing armed conflict in Yemen since 2015 has created a complex governance environment with dual authority structures, significantly affecting the coherence and enforcement of the regulatory framework. Organisations processing personal data in Yemen should seek current guidance from local legal counsel before commencing operations, given the significant governance and operational risks.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/ye-motit-framework.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "york-antwerp-rules-2016-general-average",
    "title": "York-Antwerp Rules 2016 - International Rules for General Average",
    "domain": "Maritime & Shipping",
    "version": "1.0.0",
    "last_updated": "2026-04-26",
    "bluf": "The York-Antwerp Rules 2016 (YAR 2016) are the internationally accepted standard for adjusting general average - the ancient maritime law principle by which extraordinary sacrifices or expenditures made for the common safety of a ship and its cargo are shared proportionally among all parties to the maritime adventure. YAR 2016 are incorporated by reference into most bills of lading and charterparties and are adjusted by an average adjuster appointed by the parties.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "hague_visby_rules",
        "hamburg_rules",
        "imo_llmc"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "imo-llmc-1976-protocol-1996-limitation-liability",
      "international-salvage-convention-1989",
      "un-hamburg-rules-1978-sea-carriage"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "yt-gdpr-2018",
    "title": "Mayotte - GDPR and French Data Protection Law (Loi Informatique et Libertés)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Mayotte, as a French overseas department and outermost region of the European Union since its departmentalisation in 2011 and EU outermost region status confirmed in 2014, is fully subject to the EU General Data Protection Regulation (GDPR) and the French Loi Informatique et Libertés (Law No. 78-17 of 6 January 1978), as modified by Law No. 2018-493 of 20 June 2018 to implement GDPR obligations in French national law. The supervisory authority for data protection in Mayotte is the Commission Nationale de l'Informatique et des Libertés (CNIL), which exercises full enforcement jurisdiction across all French overseas departments including Mayotte. Organisations processing personal data in Mayotte must comply with all GDPR requirements: documenting a lawful basis for each processing activity and maintaining a Record of Processing Activities (RoPA), implementing data subject rights procedures (access, rectification, erasure, restriction, portability, and objection), notifying personal data breaches to CNIL within 72 hours where the breach poses a risk to individuals, conducting data protection impact assessments (DPIAs) for high-risk processing, appointing a Data Protection Officer (DPO) where required, and applying appropriate safeguards for transfers of personal data to recipients outside the European Economic Area. CNIL may impose administrative fines of up to EUR 20 million or 4% of global annual turnover for material GDPR violations affecting individuals in Mayotte.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/yt-gdpr-2018.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr_equivalent",
        "iso_standard",
        "nist_framework",
        "regional_framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-banks-act-1990",
    "title": "Banks Act 94 of 1990",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This Act provides the legal framework for the regulation and supervision of the business of public companies taking deposits from the public in South Africa. It mandates that no person shall conduct the 'business of a bank' unless such person is a public company and is registered as a bank in terms of this Act (Section 11), and it establishes prudential requirements for capital adequacy, liquidity, and risk management.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-global-regulatory-framework",
      "bcbs-principles-sound-management-operational-risk",
      "bcbs-sound-liquidity-risk-management",
      "bcbs-large-exposures-framework"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-bbbee-act-2003",
    "title": "Broad-Based Black Economic Empowerment Act 53 of 2003",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This Act establishes a legislative framework for promoting black economic empowerment in South Africa, applying to all organs of state, public entities, and private sector enterprises. As per Section 2, its primary objective is to increase the meaningful participation of black people in the economy through a scorecard system measuring ownership, management control, skills development, enterprise and supplier development, and socio-economic development.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-26000-social-resp-mgt",
      "iso-20400-sustainable-procure",
      "sa8000-social-account",
      "shrm-hr-competency",
      "iso-30414-human-capital-rep"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-bbbee-codes-good-practice-2013",
    "title": "Amended Codes of Good Practice on Broad-Based Black Economic Empowerment, 2013 (Generic Scorecard)",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The South African B-BBEE Codes of Good Practice (2013) mandate that large enterprises (turnover > R50 million) must achieve specific targets across five scorecard elements-Ownership, Management Control, Skills Development, Enterprise and Supplier Development, and Socio-Economic Development-to obtain a valid B-BBEE compliance level, as authorized by Section 9 of the B-BBEE Act 53 of 2003.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-bbbee-act-2003",
      "iso-26000-social-resp-mgt",
      "iso-20400-sustainable-procure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-bcea-1997",
    "title": "Basic Conditions of Employment Act 75 of 1997",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This Act establishes and enforces minimum conditions of employment for most employees in South Africa, regulating working time, leave, remuneration, and termination procedures. As per Chapter Two, it sets the maximum ordinary weekly working hours at 45.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "sa8000-social-account",
      "iso-45001-work-safety"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-collective-investment-schemes-control-act-2002",
    "title": "Collective Investment Schemes Control Act 45 of 2002",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Act establishes the legal framework for collective investment schemes (CIS) in South Africa, requiring all schemes to be registered with the Financial Sector Conduct Authority (FSCA) and mandating the appointment of an independent trustee or custodian to safeguard investor assets. It imposes strict duties on scheme managers regarding portfolio management, reporting, and investor protection, as detailed in Part II (Registration) and Part IV (Manager and Trustee Obligations).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-companies-act-2008",
    "title": "Companies Act 71 of 2008",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This Act modernizes and codifies company law in South Africa, governing the incorporation, management, and dissolution of companies, and establishing the duties and liabilities of directors. It applies to all companies registered in South Africa, with Section 76 codifying the standards of directors' conduct, including the duty to act in good faith and for a proper purpose.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std",
      "ilo-core-labour-standards-1998"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-competition-act-89-1998",
    "title": "Competition Act 89 of 1998",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2024-09-20",
    "bluf": "This Act prohibits anti-competitive practices, including cartel conduct (Section 4), abuse of a dominant market position such as excessive or predatory pricing (Section 8), and requires notification and approval for mergers and acquisitions that meet specified thresholds (Section 12). It applies to all economic activity within, or having an effect within, the Republic of South Africa.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "eu-antitrust-competition-law"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-competition-act-89-1998-section-4-prohibited-practices",
    "title": "Competition Act 89 of 1998: Purpose and Scope",
    "domain": "Competition & Antitrust",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This Act establishes the Competition Commission, Tribunal, and Appeal Court to investigate, control, evaluate, and adjudicate on matters concerning restrictive practices, abuse of a dominant position, and mergers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "za-cpa-2008",
    "title": "Consumer Protection Act 68 of 2008",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This Act establishes the fundamental rights of consumers in South Africa, including rights to equality, privacy, choice, disclosure, and fair and honest dealing. As outlined in Section 3, it aims to protect consumers from unconscionable, unfair, or improper trade practices and to provide a consistent, accessible, and efficient system of redress.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-9001-quality-mgt",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-cybercrimes-act-19-of-2020",
    "title": "Cybercrimes Act 19 of 2020 (Republic of South Africa) - Cybercrime Offences, Reporting Obligations, Investigation Powers, and Mutual Assistance (Gazette 45562 of 30 November 2021; Chapters 1-4, 7-9 commenced 1 December 2021)",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2021-12-01",
    "bluf": "The Cybercrimes Act 19 of 2020 of the Republic of South Africa is the country's foundational cybercrime statute. Chapters 1, 2 (excluding Part VI), 3, 4 (excluding sections 38(1)(d), (e) and (f), 40(3) and (4), 41 to 44), 7, 8 (excluding section 54), and 9 commenced on 1 December 2021 by way of Government Gazette 45562 of 30 November 2021. The Act intends, per its long title: to create offences which have a bearing on cybercrime; to criminalise the disclosure of data messages which are harmful and to provide for interim protection orders; to further regulate jurisdiction in respect of cybercrimes; to further regulate the powers to investigate cybercrimes; to further regulate aspects relating to mutual assistance in respect of the investigation of cybercrimes; to provide for the establishment of a designated Point of Contact; to further provide for the proof of certain facts by affidavit; to impose obligations to report cybercrimes; to provide for capacity building; to provide that the Executive may enter into agreements with foreign States to promote measures aimed at the detection, prevention, mitigation and investigation of cybercrimes; and to delete and amend provisions of certain laws. The Act amends eleven prior statutes including the Criminal Procedure Act 51 of 1977, the South African Police Service Act 68 of 1995, the Films and Publications Act 65 of 1996, the Criminal Law Amendment Act 105 of 1997, the National Prosecuting Authority Act 32 of 1998, the Correctional Services Act 111 of 1998, the Financial Intelligence Centre Act 38 of 2001 (FICA), the Electronic Communications and Transactions Act 25 of 2002 (ECTA), the Regulation of Interception of Communications and Provision of Communication-related Information Act 70 of 2002 (RICA), the Criminal Law (Sexual Offences and Related Matters) Amendment Act 32 of 2007, and the Child Justice Act 75 of 2008. The Act establishes mandatory cybercrime reporting obligations on certain entities (per Chapter 7 / Section 54 in the commenced provisions) and creates jurisdictional reach over extraterritorial cybercrimes affecting South Africa. The Designated Point of Contact established under the Act enables 24/7 international cybercrime response coordination consistent with the Budapest Convention model.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "za-popia-2013",
        "za-rica-2002",
        "za-ecta-2002",
        "budapest_convention",
        "fica-1998"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "south-africa-fic-act-amendments-2022",
      "south-africa-consumer-protection-act-marketing-rules"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "za-cybercrimes-act-2020",
    "title": "Cybercrimes Act 19 of 2020",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This Act criminalizes a wide range of cyber offenses in South Africa and imposes a mandatory reporting duty on electronic communications service providers and financial institutions to report specific offenses to the South African Police Service within 72 hours, as stipulated in Chapter 8, Section 54.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "guide-computer-security-log-management",
      "nist-cybersecurity-framework-2-0",
      "cisa-ms-isac-ransomware-guide"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-cybercrimes-act-chapter-4-saps-search-seizure-2021",
    "title": "South Africa Cybercrimes Act 19 of 2020 Chapter 4 - SAPS Powers to Investigate, Search, Access, or Seize Electronic Evidence, Phased Commencement from 1 December 2021",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "South African organisations and individuals subject to investigation of cybercrimes by the South African Police Service (SAPS) must recognise the powers of search, access, and seizure of electronic evidence conferred by Chapter 4 of the Cybercrimes Act 19 of 2020 (commenced on 1 December 2021 by proclamation in Government Gazette 45562, with the exclusion of sections 38(1)(d), (e) and (f), 40(3) and (4), 41, 42, 43, and 44), apply the SAPS Standard Operating Procedures (SOPs) for the investigation, search, access, or seizure of electronic evidence (revised version published with the comment period ending 15 August 2022), and recognise that SAPS may search and seize information held within a private database or network including, in specified circumstances, without a search warrant.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-cybercrimes-act-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-digital-identity-regulations-identification-act-1997-amended-2026",
    "title": "South Africa Digital Identity Draft Regulations Identification Act 68 of 1997 Amended 2026 Smartphone Digital ID Credentials Biometric Verification and POPIA Alignment",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-30T00:00:00Z",
    "bluf": "The South African draft Digital Identity Regulations gazetted in May 2026 under the Identification Act 68 of 1997 administered by the Department of Home Affairs introduce optional smartphone-based Digital Identity credentials co-existing with Smart ID cards organised around digital identity issuance lifecycle covering identity proofing via biometric verification against the National Population Register issuance of digital credentials to the citizen smartphone wallet binding of credentials to user-controlled authentication factors such as PIN biometric or device attestation revocation processes for lost or compromised devices ongoing eligibility checks attribute sharing protocols for relying parties remote identity confirmation use cases including financial services healthcare and government and integration with the South African Smart ID infrastructure. Implementation aligned with the Protection of Personal Information Act 4 of 2013 (POPIA) for special personal information processing and the Electronic Communications and Transactions Act 25 of 2002 (ECTA) electronic signature and trust services framework. Public comment closed in 2026 with operationalisation planned thereafter via Government Gazette publication of final regulations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping",
        "framework_alignment"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-popia-2013"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "za-economic-regulation-of-transport-amendment-act-10-of-2025",
    "title": "South Africa Economic Regulation of Transport Amendment Act 10 of 2025 - Schedule 1 Citation Correction to 2024",
    "domain": "Logistics & Supply Chain",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Regulated transport operators in South Africa, the Transport Economic Regulator, and the Transport Economic Council must apply citations of the Economic Regulation of Transport Act in the form corrected by the Economic Regulation of Transport Amendment Act 10 of 2025 (commencement date 3 March 2026), which corrects the erroneous references in Schedule 1 to the Act by substituting the year 2020 with the year 2024 wherever it appears as part of the citation of the principal Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "south-africa-electricity-regulation-act-2006"
    ],
    "primary_citations_count": 4
  },
  {
    "node_id": "za-ecta-2002",
    "title": "Electronic Communications and Transactions Act (ECTA) 25 of 2002",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This Act provides a legal framework for electronic transactions and communications in South Africa, establishing the legal validity of data messages and electronic signatures under Chapter III. It applies to all entities conducting electronic transactions, with specific consumer protection rules in Chapter VII and provisions against cybercrime in Chapter XIII.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "uncitral-model-law-electronic-commerce-1996"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-electronic-communications-act-36-2005",
    "title": "Electronic Communications Act, 2005 (Act No. 36 of 2005)",
    "domain": "Telecoms & Digital Infrastructure",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Act establishes the regulatory framework for South Africa's electronic communications sector, requiring all providers of electronic communications networks, services, and broadcasting services to be licensed by the Independent Communications Authority of South Africa (ICASA) as stipulated in Chapter 3, Section 5. It governs licensing, radio frequency spectrum management, interconnection, and universal service obligations.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "coe-convention-108-plus"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-fais-2002",
    "title": "Financial Advisory and Intermediary Services Act, 2002 (Act No. 37 of 2002)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This South African act regulates the conduct of all financial services providers (FSPs) by requiring them to obtain a license from the Financial Sector Conduct Authority (FSCA) and adhere to a strict code of conduct to protect consumers, as mandated by Section 7(1). It aims to ensure that financial advice and intermediary services are rendered professionally, honestly, and with due care and diligence.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-fica-2001",
    "title": "Financial Intelligence Centre Act 38 of 2001",
    "domain": "Financial Crime, AML & Sanctions",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Financial Intelligence Centre Act (FICA) is South Africa's primary anti-money laundering (AML) and counter-terrorist financing (CTF) legislation, requiring accountable institutions to implement a risk-based approach, conduct customer due diligence (CDD) as per Section 21, maintain records, and report suspicious and unusual transactions to the Financial Intelligence Centre (FIC).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "fatf-guidance-virtual-assets-vasp",
      "wolfsberg-corresp-bank",
      "fatf-travel-rule-v2"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-financial-sector-regulation-act-2017",
    "title": "Financial Sector Regulation Act 9 of 2017",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Act establishes South Africa's 'Twin Peaks' model of financial regulation, creating the Prudential Authority (PA) within the South African Reserve Bank for prudential supervision and the Financial Sector Conduct Authority (FSCA) for market conduct regulation, applicable to all financial institutions. The core structural mandate is established in Chapter 3 (Prudential Authority) and Chapter 4 (Financial Sector Conduct Authority).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "fatf-recommendation-16-travel-rule-crypto"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-higher-education-act-101-1997",
    "title": "Higher Education Act 101 of 1997",
    "domain": "Education & Research",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This act establishes a unified and nationally planned system of higher education and provides for the establishment, governance, and quality assurance of public and private higher education institutions in South Africa.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "za-identification-act-1997-digital-identity-2026",
    "title": "South Africa Identification Act 1997 and Draft Digital Identity Regulations 2026",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-05-01",
    "bluf": "South Africa's national identity framework is established by the Identification Act 68 of 1997 administered by the Department of Home Affairs (DHA). The Identification Act creates the National Population Register, prescribes the issuance of identity documents and identity numbers, and provides the underlying authority for the Smart ID Card programme rolled out from 2013 onwards. In May 2026 the Minister of Home Affairs published draft regulations under the Identification Act for public comment introducing optional smartphone-based Digital Identity credentials that co-exist with the Smart ID Card. The draft regulations cover biometric enrollment, digital identity wallet issuance, remote identity verification, and the digital document wallet for verifiable government-issued credentials.\n\nThe digital identity framework operates within the data protection obligations of the Protection of Personal Information Act 4 of 2013 (POPIA) which establishes the Information Regulator as the supervisory authority and imposes lawful processing conditions, security safeguards, and data breach notification under Section 22. Special personal information including biometric data is governed by Sections 26 to 33 of POPIA which prohibit processing unless a Section 27 ground applies (typically consent under Section 27(1)(a)). The Electronic Communications and Transactions Act 25 of 2002 (ECTA) provides legal recognition for electronic signatures under Section 13 and authorises advanced electronic signatures under accreditation regulations administered by the South African Accreditation Authority. The Cybercrimes Act 19 of 2020 supplies the offences framework for identity fraud and unauthorised access to identity systems.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "us-nist-sp-800-63-4-2025-digital-identity-guidelines",
      "za-popia-2013",
      "za-cybercrimes-act-19-of-2020"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-insurance-act-18-2017",
    "title": "Insurance Act 18 of 2017",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-08-01",
    "bluf": "This Act establishes a comprehensive legal framework for the prudential regulation and supervision of insurers and insurance groups in South Africa, replacing the previous Long-term and Short-term Insurance Acts. It mandates licensing requirements (Chapter 2), imposes stringent governance, risk management, and internal control standards (Chapter 3), and sets capital adequacy requirements, all under the supervision of the Prudential Authority of the South African Reserve Bank (SARB).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ifrs-17-contracts"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-king-v-tech-gov",
    "title": "King V Corporate Governance: Autonomous Systems",
    "domain": "Legal & IP Sovereignty",
    "version": "1.2.0",
    "last_updated": "2026-06-29",
    "bluf": "Board-level accountability and oversight frameworks for the deployment, ethical monitoring, and risk management of autonomous AI agents within corporate environments.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "ai_overlay_2026",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-national-ai-policy-2026"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-lra-1995",
    "title": "Labour Relations Act 66 of 1995",
    "domain": "Workplace",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This Act governs labour relations in South Africa, giving effect to the constitutional right to fair labour practices by regulating collective bargaining, dispute resolution, strikes, and dismissals for nearly all employees and employers. Its primary purpose, as stated in Section 1, is to advance economic development, social justice, labour peace, and the democratization of the workplace.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "ilo-core-conventions",
      "sa8000-social-account",
      "iso-45001-work-safety",
      "iso-26000-social-resp-mgt"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-medical-schemes-act-131-1998",
    "title": "Medical Schemes Act 131 of 1998",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This South African law mandates that all medical schemes must be registered with the Council for Medical Schemes (CMS), provide open enrolment and apply community rating to prevent unfair discrimination, and cover the full cost of a defined set of Prescribed Minimum Benefits (PMBs) for all members, as stipulated in Section 29.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-13485-qms",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-mineral-petroleum-resources-development-act-2002",
    "title": "South Africa Mineral and Petroleum Resources Development Act 28 of 2002 Mining Rights and Social Obligations",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "South Africa's Mineral and Petroleum Resources Development Act 28 of 2002 (MPRDA) vests all mineral and petroleum resources in the custody of the state and requires mining companies to obtain prospecting rights, mining rights, and environmental authorisations, submit Social and Labour Plans (SLPs) addressing historically disadvantaged South Africans (HDSAs), and rehabilitate mine areas on closure - with the Department of Mineral Resources and Energy (DMRE) as the competent authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 6
  },
  {
    "node_id": "za-national-ai-policy-2026",
    "title": "SA AI Accountability Framework - POPIA §71 + Pending National AI Policy",
    "domain": "AI Governance & Law",
    "version": "1.2.0",
    "last_updated": "2026-04-27",
    "bluf": "Operationalizing POPIA Section 71 automated-decision-making obligations and the forthcoming republished SA National AI Policy. Original April 2026 draft withdrawn by DCDT on 2026-04-26 due to source-integrity failures; node citations independently verified clean and re-anchored on POPIA.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-king-v-tech-gov"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-national-environmental-management-act-107-1998",
    "title": "South Africa National Environmental Management Act (NEMA) 107 of 1998 - Environmental Impact Assessment Obligations, Environmental Management Plans, Principles for Decision-Making and Enforcement",
    "domain": "Sustainability & ESG",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "The South African National Environmental Management Act (NEMA) establishes a framework for environmental governance, requiring any person undertaking activities listed under Section 24(2) to obtain an environmental authorisation, which necessitates conducting a formal Environmental Impact Assessment (EIA) and implementing an Environmental Management Programme (EMPr).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-14001-ems",
      "ifrs-s2-climate-related-disclosures",
      "gri-universal-standards",
      "tnfd-nature-disclosure"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-national-health-act-61-2003",
    "title": "National Health Act 61 of 2003",
    "domain": "Medical & Healthcare",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Act establishes a unified national health system for South Africa, defining the rights and duties of healthcare providers and users, and creating the Office of Health Standards Compliance (OHSC) to ensure health establishments meet prescribed norms and standards. It mandates strict confidentiality for patient information (Section 14) and requires informed consent for treatment (Section 7), applying to all public and private health establishments and providers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27799-health-info-sec"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-national-payment-system-act-1998",
    "title": "National Payment System Act, 1998 (Act No. 78 of 1998)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Act establishes the South African Reserve Bank (SARB) as the overseer of the national payment system, granting it powers to recognize a Payment System Management Body (PSMB) and to approve rules governing payment systems to ensure their safety, efficiency, and integrity as outlined in Section 3 and Section 4.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bis-principles-fmi-2012"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-nca-2005",
    "title": "National Credit Act 34 of 2005",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2024-05-21",
    "bluf": "The National Credit Act (NCA) promotes a fair, transparent, and responsible credit market in South Africa by regulating all credit agreements and requiring credit providers to register with the National Credit Regulator (NCR), conduct comprehensive affordability assessments (Section 81), and prevent the granting of reckless credit (Section 80).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-nca-section-81-reckless-credit",
    "title": "National Credit Act 34 of 2005, section 81: Prevention of reckless credit",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "This section requires credit providers to conduct a thorough affordability assessment before entering into a credit agreement to prevent granting reckless credit to consumers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "primary_citations_count": 5
  },
  {
    "node_id": "za-paia-2000",
    "title": "Promotion of Access to Information Act (PAIA) 2 of 2000",
    "domain": "Legal & IP Sovereignty",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Promotion of Access to Information Act (PAIA) gives effect to the constitutional right of access to any information held by the State and any information held by a private body that is required for the exercise or protection of any rights. It establishes procedures for requesters to obtain records from public (Section 11) and private (Section 50) bodies.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "coe-convention-108-plus",
      "iso-27001-2022"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-pension-funds-act-24-1956",
    "title": "Pension Funds Act 24 of 1956 - Fund Registration, Board of Trustees Fiduciary Duties, Pension Funds Adjudicator Dispute Resolution and Pension Benefit Preservation Rules",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Act governs the registration, management, and operation of pension funds in South Africa, mandating registration with the Financial Sector Conduct Authority (FSCA) under Section 4. It imposes strict fiduciary duties on the board of trustees (Section 7C & 7D) and establishes rules for benefit preservation (Section 37D) and dispute resolution via the Pension Funds Adjudicator (Chapter VA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "bcbs-principles-operational-resilience",
      "iso-31000-risk-mgt-std"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-popia-2013",
    "title": "Protection of Personal Information Act 4 of 2013 (POPIA)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "The Protection of Personal Information Act (POPIA) establishes eight mandatory conditions for the lawful processing of personal information by public and private bodies in South Africa. As outlined in Chapter 3, any 'responsible party' processing personal information within the country must adhere to these conditions, which include accountability, processing limitation, purpose specification, and security safeguards.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-data-protection-officer",
      "brazil-lgpd-compliance",
      "nist-800-122-pii",
      "iso-37301-compliance-ms"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-popia-act-4-2013-personal-information-protection",
    "title": "South Africa POPIA (Act 4 of 2013) - Eight Conditions for Lawful Processing and IO Registration",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-01-01",
    "bluf": "South Africa's Protection of Personal Information Act (POPIA, Act 4 of 2013) sets eight conditions for lawful personal information processing, requires registration of an Information Officer (IO) with the Information Regulator, mandates security breach notification within 72 hours, restricts special personal information (health, criminal, racial origin), limits transborder flows, and imposes penalties up to ZAR 10 million or 10 years imprisonment for serious offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_regulations",
        "industry_mapping",
        "iso_references"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-6-lawful-basis-marketing"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "za-popia-section-11-grounds-processing-personal-information",
    "title": "Protection of Personal Information Act (POPIA), 2013 - Section 11: Consent, justification and objection",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This section establishes the legal grounds under which a responsible party may lawfully process personal information, requiring at least one of six specific justifications to be met for any processing activity.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-popia-section-19-security-measures-controller",
    "title": "Protection of Personal Information Act (Act 4 of 2013): Section 19 - Security measures on integrity and confidentiality of personal information",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "A responsible party must secure the integrity and confidentiality of personal information by implementing appropriate, reasonable technical and organisational measures to prevent its loss, damage, destruction, or unlawful access and processing.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles",
      "gdpr-article-35-dpia"
    ],
    "primary_citations_count": 8
  },
  {
    "node_id": "za-popia-section-22-notification-security-compromises",
    "title": "Protection of Personal Information Act (Act 4 of 2013): Section 22 - Notification of security compromises",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "Organizations must notify the Information Regulator and affected data subjects as soon as reasonably possible after discovering a security compromise involving personal information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-5-data-principles"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-popia-section-57-duties-information-officers",
    "title": "Protection of Personal Information Act (POPIA), 2013 - Section 57: Duties and responsibilities of information officer",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-05-08",
    "bluf": "This section outlines the core duties and responsibilities of the designated Information Officer, including developing a compliance framework, conducting impact assessments, and ensuring the organization lawfully processes personal information.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "gdpr-article-37-dpo",
      "gdpr-article-35-dpia",
      "gdpr-article-30-records-processing"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-preferential-procurement-regulations-2022",
    "title": "South Africa Preferential Procurement Regulations, 2022",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-07",
    "bluf": "The Preferential Procurement Regulations, 2022, promulgated by the Minister of Finance on 4 November 2022 under Government Notice 2721 in Government Gazette 47452 and taking effect on 16 January 2023, were made under section 5 read with sections 2(1)(b)(i), 2(1)(b)(ii) and 2(1)(c) of the Preferential Procurement Policy Framework Act 5 of 2000. They apply to organs of state as defined in section 1 of the Act (Regulation 2) and require contracting organs to stipulate the applicable preference point system in tender documents (Regulation 3), apply the 80/20 system to acquisitions of goods or services with a Rand value at or below R50 million (Regulation 4), apply the 90/10 system above R50 million (Regulation 5), apply the corresponding 80/20 and 90/10 systems to income-generating contracts (Regulations 6 and 7), award contracts to tenderers scoring the highest specific-goal points where total points tie (Regulation 8), and disqualify or terminate where false information on specific goals is established (Regulation 9). The 2017 Regulations published in Government Notice 40553 are repealed by Regulation 10.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-bbbee-act-2003",
      "za-bbbee-codes-good-practice-2013",
      "wto-revised-government-procurement-agreement-2012"
    ],
    "primary_citations_count": 11
  },
  {
    "node_id": "za-public-administration-management-amendment-act-7-of-2025",
    "title": "South Africa Public Administration Management Amendment Act 7 of 2025 - Ethical Standards, Secondment Framework, and National School of Government",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Public administration employees and accounting authorities in South Africa must apply the Public Administration Management Amendment Act 7 of 2025 as published in Government Gazette 54449 on 1 April 2026, including the clarified prohibition against employees conducting business with organs of state, the framework for transfer and secondment of employees across the public administration, the reconstitution of the National School of Government as a national department, and the removal of employment disparities across the public administration.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-paia-2000"
    ],
    "primary_citations_count": 3
  },
  {
    "node_id": "za-rica-2002",
    "title": "Regulation of Interception of Communications and Provision of Communication-related Information Act 70 of 2002",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-16",
    "bluf": "This South African law regulates the interception of communications, requiring telecommunication service providers to verify and record the identity and address of all customers before activating a service, as mandated by Chapter IV, Sections 39 and 40. It also obligates providers to maintain capabilities for lawful interception when directed by a court order.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "nist-800-122-pii"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-sarb-banks-act-94-1990",
    "title": "South Africa Banks Act 94 of 1990 - Prudential Regulation & SARB Supervision",
    "domain": "Banking & Global Finance",
    "version": "2024.1.1",
    "last_updated": "2026-04-30",
    "bluf": "South Africa's Banks Act 94 of 1990, administered by the Prudential Authority within the South African Reserve Bank (SARB), establishes the licensing framework for deposit-taking institutions, prescribes minimum capital and liquidity requirements, and grants the Prudential Authority broad supervisory powers including curatorship and license cancellation.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "basel_iii",
        "fatf",
        "ifrs",
        "king_iv"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "basel-iii-capital",
      "fatf-40-recommendations-2023-consolidated",
      "za-king-v-tech-gov"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-tax-administration-act-28-2011",
    "title": "Tax Administration Act, 2011 (Act No. 28 of 2011)",
    "domain": "Banking & Global Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-18",
    "bluf": "This Act governs the administration of tax laws in South Africa, mandating taxpayers to keep relevant records for a minimum of five years (Section 29), granting the South African Revenue Service (SARS) broad powers for inspection and audit (Chapter 5), and defining the procedures for objections, appeals (Chapter 9), and the imposition of administrative penalties for non-compliance (Chapter 15).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-37301-compliance-mgt"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "za-tax-administration-laws-amendment-act-4-of-2026",
    "title": "South Africa Tax Administration Laws Amendment Act 4 of 2026 - Section 223 Understatement Penalties, Suspension of Payment, and VAT E-Invoicing",
    "domain": "Tax & Transfer Pricing",
    "version": "1.0.0",
    "last_updated": "2026-06-04",
    "bluf": "Taxpayers in South Africa must comply with the amended understatement penalty rules under section 223 of the Tax Administration Act 28 of 2011, may apply for suspension of payment while requesting a reduced assessment under section 95(6), must maintain a continuously filled office for service of SARS notices where required, and adapt VAT systems to the legislative framework for e-invoicing and voluntary e-reporting introduced by this Act.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-tax-administration-act-28-2011"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "za-treasury-capital-flow-mgmt-regs-2026",
    "title": "Republic of South Africa - Draft Capital Flow Management Regulations, 2026 (Government Notice No. 54520, Government Gazette No. 7375 of 17 April 2026; Made under Section 9(1) of the Currency and Exchanges Act 9 of 1933; Repealing the Exchange Control Regulations of 1 December 1961; Public Comment Deadline 18 May 2026)",
    "domain": "Crypto & Sovereign Finance",
    "version": "1.0.0",
    "last_updated": "2026-04-17",
    "bluf": "The Draft Capital Flow Management Regulations, 2026, were published for public comment by the Minister of Finance under section 9(1) of the Currency and Exchanges Act 9 of 1933, in Government Notice No. 54520 in Government Gazette No. 7375 of 17 April 2026, jointly issued by National Treasury and the South African Reserve Bank. The regulations will repeal the Exchange Control Regulations published by Government Notice R.1111 of 1 December 1961 (regulation 32(1)) and modernise South Africa's cross-border capital-flows framework by adopting a 'positive bias' approach with fewer transaction pre-approvals, increased reporting, surveillance of high-impact and high-risk cross-border transactions, and combating of illicit financial flows. The most operationally significant change is the formal incorporation of crypto assets into the capital-flow framework: regulation 3(1) prohibits any person other than an 'authorised crypto asset service provider' from buying, borrowing or otherwise dealing in crypto assets in transactions deemed import/export of capital; the term 'authorised crypto asset service provider' is defined as a crypto asset service provider as defined in item 22 of schedule 1 of the Financial Intelligence Centre Act, 2001, who is authorised by the National Treasury. The definition of 'crypto asset' (regulation 1(1)) covers a digital representation of value that is not issued by a central bank, is capable of being traded/transferred/stored electronically for payment, investment and other utility, applies cryptographic techniques, and uses distributed ledger technology. 'Capital' explicitly includes crypto assets (excluding immovable property); 'currency' and 'foreign currency' explicitly exclude crypto assets. Regulation 10(1) requires every person in the Republic to declare any foreign asset or crypto asset within 30 days of acquiring control/possession or becoming entitled to deal with it, stating when, how and where it was acquired and whether it is held as cover for foreign liability; post-declaration sale/transfer requires Treasury permission (regulation 10(2)-(3)). Regulation 20 grants National Treasury and authorised persons information-furnishing and premises-search powers. Regulation 21 establishes administrative sanctions on authorised dealers and authorised CASPs including financial sanctions, public reprimand, suspension, revocation, director disqualification, transaction restrictions, and remedial-action orders, with up to five-year suspended sanctions. Criminal offences attract a fine not exceeding R1,000,000 or imprisonment up to five years or both; where the offence relates to money, a crypto asset or property, the fine may be R1,000,000 OR a sum equal to the value of the money, crypto asset or property, whichever is the greater. The public comment deadline is 18 May 2026 (Commentdraftlegislation@treasury.gov.za).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "za-fica-2001",
        "za-financial-sector-regulation-act-2017",
        "za-popia-2013",
        "za-cybercrimes-act-2020",
        "fatf-recommendation-16-travel-rule-crypto",
        "us-genius-act-stablecoin-2025-framework"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "za-fica-2001",
      "za-financial-sector-regulation-act-2017"
    ],
    "primary_citations_count": 15
  },
  {
    "node_id": "zambia-mines-minerals-development-act-11-2015",
    "title": "Zambia Mines and Minerals Development Act No. 11 of 2015 - Mining Rights, Safety, and Revenue Framework",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "The Mines and Minerals Development Act No. 11 of 2015 (MMDA) is Zambia's primary mining legislation governing exploration and large-scale mining licences, artisanal and small-scale mining permits, mineral royalties, mining safety and health requirements, environmental obligations, community development agreements, and the mining cadastre administered by the Zambia Environmental Management Agency (ZEMA) and the Zambia Revenue Authority (ZRA); mineral royalties range from 5-10% of gross value depending on mineral type; the Act was amended by the Mines and Minerals Development (Amendment) Act 2023 to strengthen local content and community development requirements.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "iso_standard",
        "industry_mapping",
        "regulatory_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icmm-mining-principles-2020",
      "ilo-c176-safety-health-mines-convention-1995"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "zimbabwe-mines-minerals-act-chapter-21-05-zmdc",
    "title": "Zimbabwe Mines and Minerals Act Chapter 21:05 - Prospecting, Mining Location Registration and ZMDC State Participation",
    "domain": "Mining & Natural Resources",
    "version": "1.0.0",
    "last_updated": "2026-05-09",
    "bluf": "Zimbabwe's Mines and Minerals Act Chapter 21:05 (originally enacted as the Mines and Minerals Act 1961, substantially amended through the Mines and Minerals Amendment Act 2019 and Zimbabwe Mines and Minerals Amendment Act 2023) vests all minerals in the President of Zimbabwe on behalf of the state and establishes the Ministry of Mines and Mining Development (MMMD) with the Mining Commissioner as the licensing authority; the Act creates a mining title system including special grants, prospecting licences, block claims (gold and mineral claims), mining leases, and exclusive prospecting orders; the Zimbabwe Mining Development Corporation (ZMDC) Act Chapter 21:08 established ZMDC as the state mining company with a right to participate in large-scale mining operations through compulsory state participation of up to 51% in certain designated minerals; Statutory Instrument 2021-21 (Minerals Regulations) requires mandatory beneficiation of all platinum group metals (PGMs) and chrome before export; the Environmental Management Act Chapter 20:27 requires an Environmental Impact Assessment (EIA) before any new mine commencement; the Mines and Minerals Amendment Act 2023 introduced a cadastral system upgrade and strengthened beneficiation requirements for lithium as a designated strategic mineral.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "related_frameworks",
        "industry_mapping",
        "eu_ai_act_relevance"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "icmm-mining-principles-2020"
    ],
    "primary_citations_count": 6
  },
  {
    "node_id": "zm-cybersecurity-act-2021",
    "title": "Zambia Cybersecurity and Cybercrimes Act 2021",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Zambia's Cybersecurity and Cybercrimes Act 2021, enacted in 2021, establishes the Zambia Information and Communications Technology Authority as the cybersecurity regulator, designates Critical Information Infrastructure operators required to implement cybersecurity measures and report incidents to ZICTA, criminalises cybercrime offences including unauthorised access, data interference, computer fraud, and child exploitation material, creates a cybersecurity certification scheme for service providers, and imposes penalties including fines and imprisonment up to 25 years for the most serious offences.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/zm-cybersecurity-act-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "zm-dpa-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "zm-dpa-2021",
    "title": "Zambia Data Protection Act No. 3 of 2021 - ODPC",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Zambia's Data Protection Act No. 3 of 2021 - assented to on 23 March 2021 and gazetted in the Zambia Government Gazette on 24 March 2021 - is Zambia's primary personal data protection legislation, establishing a comprehensive rights-based framework for the protection of personal data of natural persons in Zambia. The Act came into force on 8 June 2021, supplementing Zambia's existing Cyber Security and Cyber Crimes Act No. 2 of 2021. The supervisory authority is the Office of Data Protection Commissioner (ODPC), established under the Act as the principal regulatory body responsible for registering data controllers, investigating complaints, and enforcing the Act. Zambia's data protection legislation was developed in the context of the country's Digital Economy Blueprint and ICT policy framework. Key features of Zambia's Data Protection Act No. 3 of 2021: (1) Scope - applies to data controllers established in Zambia or processing personal data of persons in Zambia regardless of where the controller is located; (2) Data processing principles - processing must comply with: lawfulness and fairness; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; physical or mental health; sexual orientation; biometric data; genetic data; and criminal convictions and offences; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restrict processing; right to data portability; right to object; and right not to be subject to solely automated decisions with significant effects; (6) Data controller registration - data controllers must register with the ODPC before collecting or processing personal data; (7) Data Protection Officer - required for data controllers processing personal data on a large scale or systematically monitoring data subjects; (8) Breach notification - data controllers must notify the ODPC of personal data breaches that may adversely affect the rights and freedoms of data subjects; (9) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or subject to ODPC-approved safeguards; (10) Penalties - graduated administrative fines and criminal penalties for contraventions of the Act. Zambia's Data Protection Act 2021 positions Zambia as a data-secure jurisdiction in Central-Southern Africa, supporting the country's mining, agriculture, financial services, and digital economy sectors.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 7
  },
  {
    "node_id": "zm-public-procurement-act-8-2020-zppa-eppx",
    "title": "Zambia Public Procurement Act No. 8 of 2020 effective 1 June 2021 and the Zambia Public Procurement Authority (ZPPA)",
    "domain": "Public Sector & Government Procurement",
    "version": "1.0.0",
    "last_updated": "2026-06-08",
    "bluf": "The Republic of Zambia Public Procurement Act No. 8 of 2020 (Act 8 of 2020) effective 1 June 2021 as supplemented by the Public Procurement Regulations 2022 (SI 32 of 2022) is the principal Zambian statute governing procurement of goods, works, and services by procuring entities including the Government of Zambia (Central Government ministries, departments, and Cabinet Office), the National Assembly, the Judiciary, statutory bodies, public-sector enterprises (Industrial Development Corporation companies), local authorities (City Councils, Municipal Councils, District Councils), public-sector universities, and other entities funded wholly or partly from the Consolidated Fund. The 2020 Act replaced the prior Public Procurement Act No. 12 of 2008 and substantially modernised the Zambian procurement regime aligning with international best practice including the UNCITRAL Model Law on Public Procurement. The Zambia Public Procurement Authority (ZPPA / zppa.org.zm) is the central regulatory authority responsible for procurement regulation, oversight, supplier debarment, complaint resolution, and procurement guidance. The e-Government Procurement (e-GP) system Zambia (eppx.zppa.org.zm) is the federal e-procurement platform. Procurement methods established by Public Procurement Act 2020 sec. 30 to 53 comprise (a) Open Bidding (the default open public procedure for high-value acquisitions above prescribed thresholds), (b) Selective Bidding (with prequalification), (c) Limited Bidding (restricted to invited suppliers under prescribed exceptions), (d) Direct Bidding (sole-source under prescribed exceptions in sec. 42 including emergency, sole supplier for technical reasons, prior failed bidding, and prescribed-class exemptions), (e) Quotations (for medium-value goods and services), (f) Simplified Bidding (for prescribed lower-value contracts), (g) Two-Stage Bidding (for complex acquisitions), (h) Framework Bidding, and (i) Electronic Reverse Auction. The Auditor-General of Zambia conducts ex-post procurement audit. The Anti-Corruption Commission has investigative jurisdiction over procurement-related corruption. Zambia is a party to the Southern African Development Community (SADC), Common Market for Eastern and Southern Africa (COMESA), AfCFTA, and UNCAC. Zambia is NOT a party to the WTO Government Procurement Agreement (GPA).",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "industry_mapping",
        "ai_overlay_2026"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "uncitral-model-law-public-procurement-2011",
      "zm-dpa-2021",
      "zm-cybersecurity-act-2021",
      "iso-iec-42001-2023-ai-management-system",
      "nist-sp-800-53-r5"
    ],
    "primary_citations_count": 10
  },
  {
    "node_id": "zw-cybersecurity-data-protection-act-2021",
    "title": "Zimbabwe Cybersecurity and Data Protection Act 2021 (Chapter 12:07)",
    "domain": "Data Protection & Privacy",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Zimbabwe's Cybersecurity and Data Protection Act 2021 (Chapter 12:07), signed into law in July 2021, establishes a unified framework for both cybersecurity and personal data protection, designates the Postal and Telecommunications Regulatory Authority of Zimbabwe as the cybersecurity regulator and creates the Data Protection Authority for data protection enforcement, criminalises cybercrime offences including unauthorised access, cyber harassment, and electronic fraud, and creates data protection obligations including consent, data subject rights, and breach notification for data controllers.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
      "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/zw-cybersecurity-data-protection-act-2021.json"
    },
    "crosswalks": {
      "_available_keys": [
        "gdpr",
        "iso_27001",
        "nist_csf"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "zw-dpa-2021"
    ],
    "primary_citations_count": 5
  },
  {
    "node_id": "zw-dpa-2021",
    "title": "Zimbabwe Data Protection Act 2021 - POTRAZ Compliance Framework",
    "domain": "Cybersecurity",
    "version": "1.0.0",
    "last_updated": "2026-04-27",
    "bluf": "Zimbabwe Data Protection Act (No. 5 of 2021) establishes comprehensive data subject rights, mandatory data controller registration, consent-based processing obligations, and cross-border transfer controls. The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) serves as the interim supervisory authority pending the establishment of a dedicated Data Protection Authority.",
    "paywall": {
      "status": "LOCKED",
      "unlock_cost_usd": "0.01",
      "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
    },
    "crosswalks": {
      "_available_keys": [
        "nist_framework",
        "iso_standard",
        "nist_ai_rmf_profile",
        "industry_mapping"
      ],
      "_note": "Full crosswalk values included in vault response"
    },
    "dependencies": [
      "iso-27001-2022",
      "iso-27701-privacy-information-management"
    ],
    "primary_citations_count": 5
  }
]